English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14019
À§Çèµµ 40
Æ÷Æ® 514
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù R-Command
»ó¼¼¼³¸í ÆÐ½º¿öµå°¡ ¼³Á¤µÇÁö ¾Ê¾Ò°Å³ª ~/.rhosts ÆÄÀÏ, ȤÀº /etc/hosts.equiv ÆÄÀÏÀÇ ¼³Á¤³»¿ë¿¡ ¹®Á¦°¡ ÀÖ¾î rshÀ» ÅëÇØ ÇØ´ç ½Ã½ºÅÛ³»¿¡ ÀÖ´Â ÀÓÀÇÀÇ ¸í·ÉÀÇ ¼öÇàÀÌ °¡´ÉÇÏ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/677.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ 1. ºÒÇÊ¿äÇÑ ¼­ºñ½º¶ó¸é ¼­ºñ½º¸¦ Disable ½ÃŲ´Ù. (/etc/inetd.conf¿¡¼­ Comment ó¸®, ±×¸®°í inetd µ¥¸óÀ» Revoke ½ÃÅ´)
*Solaris 10, Solaris 11ÀÇ °æ¿ì:
# svcadm disable svc:/network/login:rlogin

*Enterprise Linux 6.4, CentOS 6.4, Fedora 19:
/etc/xinetd.d/rsh¸¦ ¿­¾î disable=yes·Î ¼³Á¤ÇÑ´Ù.

2. ÆÐ½º¿öµå°¡ ¼³Á¤µÇÁö ¾ÊÀº Account¶ó¸é ÆÐ½º¿öµå¸¦ ¼³Á¤ÇÑ´Ù.
3. ~/.rhosts ÆÄÀÏÀ̳ª /etc/hosts.equiv ÆÄÀÏÀÇ ¼³Á¤¿¡¼­ '+'°¡ ÀÖÀ¸¸é Á¦°ÅÇϰí rshÀ» ÅëÇØ TrustÇÒ È£½ºÆ®¸íÀ̳ª IP¸¦ Á÷Á¢ µî·ÏÇÑ´Ù.
°ü·Ã URL CVE-1999-0651 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)