Ãë¾àÁ¡ID |
14047 |
À§Çèµµ |
40 |
Æ÷Æ® |
23 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
TELNET |
»ó¼¼¼³¸í |
ÇØ´ç Telnet ¼¹ö´Â 'USER' ȯ°æ º¯¼ö¸¦ ÅëÇÑ ÀÎÁõ ¿ìȸ Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Sun Solaris 10°ú 11¿¡ ÀÖ´Â Telnet µ¥¸ó(in.telnetd)Àº »ç¿ëÀÚ°¡ Á¦°øÇÑ 'USER' ȯ°æ º¯¼ö¿¡ ´ëÇÑ ºÎÀûÀýÇÑ °ËÁõÀ¸·Î ÀÎÇÏ¿©, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ÀÎÁõÀ» ¿ìȸÇÒ ¼ö ÀÖ°Ô ÇØ ÁÙ ¼ö ÀÖ´Ù. Àß Á¶ÀÛµÈ USER ȯ°æ º¯¼ö¸¦ Á¦°øÇÔÀ¸·Î½á, ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÎÁõÀ» ¿ìȸÇÏ¿© ÀÓÀÇÀÇ »ç¿ëÀÚ(È£½ºÆ®°¡ root·Î½á telnet ·Î±×ÀÎÀ» Çã¿ëÇϵµ·Ï ±¸¼ºµÇ¾î ÀÖ´Ù¸é "root" »ç¿ëÀÚ)ÀÇ ±ÇÇÑÀ» °¡Áö°í ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ¿¡ ´ëÇÑ ºñÀΰ¡µÈ ¾×¼¼½º¸¦ ¾ò¾î³¾ ¼ö ÀÖ´Ù. ¿¹¸¦ µé¾î, ´ÙÀ½ ¸í·ÉÀ» ÅëÇؼ:
telnet -l "-fbin" targethost
'bin' »ç¿ëÀÚÀÇ ±ÇÇÑÀ» °¡Áø ShellÀ» ¾ò¾î³¾ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://http://download.oracle.com/sunalerts/1001064.1.html http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052358.html http://lists.grok.org.uk/pipermail/full-disclosure/2007-February/052324.html http://www.kb.cert.org/vuls/id/881872 http://www.securitytracker.com/id?1017625 http://secunia.com/advisories/24120
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Sun Solaris 10 Sun Solaris 11 |
ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÀÌ Ãë¾àÁ¡À» À§ÇÑ ÆÐÄ¡(120068-02 (sparc) ȤÀº 120069-02 (i386))¸¦ ¼³Ä¡Çϰųª ȤÀº Á¦¾ÈµÈ Á¶Ä¡¹æ¹ýÀ» Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://download.oracle.com/sunalerts/1001064.1.html |
°ü·Ã URL |
CVE-2007-0882 (CVE) |
°ü·Ã URL |
22512 (SecurityFocus) |
°ü·Ã URL |
32434 (ISS) |
|