English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14020
À§Çèµµ 20
Æ÷Æ® 514
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù R-Command
»ó¼¼¼³¸í rshd ¼­ºñ½º°¡ OpenµÇ¾î ÀÖ´Ù. rshd´Â ¼­ºñ½ºÀÇ Á߿䵵¿¡ ºñÇØ ÀÎÁõ¼ö´ÜÀÌ ³Ê¹« ½±°Ô ¹«·ÂÈ­µÉ ¼ö ÀÖ´Ù. ¶ÇÇÑ ¼­¹ö°£ R-commandÀÇ Trust °ü°è¸¦ »çÀü¿¡ ¾Ë¾Æ³»¾î IP spoofingµîÀ» ÀÌ¿ë, ¼­¹öÀÇ ÀÎÁõÀ» ¼Ó¿© Target¼­¹öÀÇ ±ÇÇÑÀ» ȹµæÇÒ ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/677.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ °¡´ÉÇÑÇÑ ¼­ºñ½º¸¦ °¡µ¿Áß´Ü ÇÑ´Ù. ¼­ºñ½º¸¦ °¡µ¿Áß´Ü Çϱâ À§Çؼ­´Â /etc/inetd.conf¿¡¼­ rshd ¶óÀÎÀ» comment ó¸®Çϰí inetd µ¥¸óÀ» Restart ½ÃŲ´Ù.

Enterprise Linux 6.4, CentOS 6.4, Fedora 19ÀÇ °æ¿ì
/etc/xinetd.d/rsh ÆÄÀÏÀ» ¿­¾î disableÀ» yes·Î ¼³Á¤ÇÑ´Ù.

Solaris 10, Solaris 11ÀÇ °æ¿ì rsh ¼­ºñ½º ÁßÁö¸¦ À§Çؼ­´Â ´ÙÀ½°ú °°ÀÌ ½ÇÇàÇÑ´Ù.
#svcadm disable svc:/network/login:rlogin
°ü·Ã URL CVE-1999-0651 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)