English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14047
À§Çèµµ 40
Æ÷Æ® 23
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù TELNET
»ó¼¼¼³¸í ÇØ´ç Telnet ¼­¹ö´Â 'USER' ȯ°æ º¯¼ö¸¦ ÅëÇÑ ÀÎÁõ ¿ìȸ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Sun Solaris 10°ú 11¿¡ ÀÖ´Â Telnet µ¥¸ó(in.telnetd)Àº »ç¿ëÀÚ°¡ Á¦°øÇÑ 'USER' ȯ°æ º¯¼ö¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÎÁõÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. Àß Á¶ÀÛµÈ USER ȯ°æ º¯¼ö¸¦ Á¦°øÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÎÁõÀ» ¿ìȸÇÏ¿© ÀÓÀÇÀÇ »ç¿ëÀÚ(È£½ºÆ®°¡ root·Î½á telnet ·Î±×ÀÎÀ» Çã¿ëÇϵµ·Ï ±¸¼ºµÇ¾î ÀÖ´Ù¸é "root" »ç¿ëÀÚ)ÀÇ ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ´Ù.
¿¹¸¦ µé¾î, ´ÙÀ½ ¸í·ÉÀ» ÅëÇؼ­:

telnet -l "-fbin" targethost

'bin' »ç¿ëÀÚÀÇ ±ÇÇÑÀ» °¡Áø ShellÀ» ¾ò¾î³¾ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://http://download.oracle.com/sunalerts/1001064.1.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052358.html
http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052324.html
http://www.kb.cert.org/vuls/id/881872
http://www.securitytracker.com/id?1017625
http://secunia.com/advisories/24120

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Sun Solaris 10
Sun Solaris 11
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡À» À§ÇÑ ÆÐÄ¡(120068-02 (sparc) ȤÀº 120069-02 (i386))¸¦ ¼³Ä¡Çϰųª ȤÀº Á¦¾ÈµÈ Á¶Ä¡¹æ¹ýÀ» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://download.oracle.com/sunalerts/1001064.1.html
°ü·Ã URL CVE-2007-0882 (CVE)
°ü·Ã URL 22512 (SecurityFocus)
°ü·Ã URL 32434 (ISS)