English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 14068
À§Çèµµ 20
Æ÷Æ® 22
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù LSC
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛÀº su ¸í·É¾î¿¡ Á¦ÇÑÀ» µÎÁö ¾Ê´Â´Ù. su ¸í·É¾î¸¦ ÅëÇØ root °èÁ¤À¸·Î Á¢¼Ó ½Ã ¸ðµç ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖÀ¸¹Ç·Î Çã¿ëÇÏ´Â °èÁ¤¸¸ su ¸í·É¾î¸¦ ÅëÇØ root °èÁ¤À¸·Î Á¢¼Ó ÇÒ ¼ö ÀÖµµ·Ï ÇؾßÇÑ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
UNIX, Linux
ÇØ°áÃ¥ ´ÙÀ½°ú °°ÀÌ su¸í·É¾î »ç¿ëÀÚ¸¦ Á¦ÇÑÇÑ´Ù.
*Linux
1. /etc/pam.d/su ÆÄÀÏÀ» ¿¬ ÈÄ pam_wheel¿¡ ´ëÇÑ ÁÖ¼®ºÎºÐÀ» Á¦°ÅÇÑ´Ù.
auth required pam_wheel.so debug use_uid
(debug´Â ·Î±× È®ÀÎÀ» À§ÇØ Ãß°¡)

¶Ç´Â ´ÙÀ½ÀÇ 2ÁÙÀ» ùÁÙ¿¡ Ãß°¡
auth sufficient /lib/security/pam_rootok.so debug
auth required /lib/security/pam_wheel.so group=wheel

2. /etc/group¾È¿¡ wheel ±×·ìÀÌ ¾øÀ¸¸é ´ÙÀ½°ú °°ÀÌ wheel±×·ìÀ» Ãß°¡ÇÑ´Ù
groupadd wheel
3. /etc/group¾È¿¡ su¸í·ÉÀ» Çã°¡ÇÑ °èÁ¤À» Ãß°¡ÇÑ´Ù.
wheel:x:10:root,user1,user2
4. /etc/login.defs ÆÄÀÏÀÌ Á¸ÀçÇÏ¸é ´ÙÀ½°ú °°ÀÌ ¼öÁ¤ÇÑ´Ù.
SU_WHEEL_ONLY yes

*Solaris
1. ´ÙÀ½°ú °°ÀÌ /etc/group¾È¿¡ wheel ±×·ìÀÌ ¾øÀ¸¸é ´ÙÀ½°ú °°ÀÌ wheel±×·ìÀ» Ãß°¡ÇÑ´Ù
groupadd wheel
2. ´ÙÀ½°ú °°ÀÌ su ¸í·É¾îÀÇ ±×·ì°ú Æ۹̼ÇÀ» º¯°æÇÑ´Ù.
chgrp wheel /usr/bin/su
chmod 4750 /usr/bin/su
3. ´ÙÀ½°ú °°ÀÌ wheel ±×·ì¿¡ su¸í·ÉÀ» Çã°¡ÇÑ °èÁ¤À» Ãß°¡ÇÑ´Ù.
usermod -G wheel user1

¶Ç´Â
/etc/pam.confÆÄÀÏÀ» ¿­¾î ´ÙÀ½°ú °°ÀÌ Ãß°¡ÇÑ´Ù.
su account required pam_sample.so.1 allow=user1, user2

*HP
1. ´ÙÀ½°ú °°ÀÌ /etc/default/security ÆÄÀÏ¿¡¼­ su ¸í·É¾î¸¦ »ç¿ëÇÒ ±×·ìÀ» ÁöÁ¤
SU_ROOT_GROUP=wheel
2. ´ÙÀ½°ú °°ÀÌ su ¸í·É¾îÀÇ ±×·ìÀ» »ý¼ºÇÑ´Ù.
groupadd wheel
3. ´ÙÀ½°ú °°ÀÌ su ¸í·É¾îÀÇ ±×·ì°ú Æ۹̼ÇÀ» º¯°æÇÑ´Ù.
chgrp wheel /usr/bin/su
chmod 4750 /usr/bin/su
4. ´ÙÀ½°ú °°ÀÌ wheel ±×·ì¿¡ su¸í·ÉÀ» Çã°¡ÇÑ °èÁ¤À» Ãß°¡ÇÑ´Ù.
usermod -G wheel user1

*AIX
1. /etc/security/user ÆÄÀÏÀ» ¿¬´Ù.
2. ´ÙÀ½°ú °°ÀÌ default: ·Î Ç¥½ÃµÈ ¶óÀÎ ¾Æ·¡ ´ÙÀ½°ú °°ÀÌ su¸¦ »ç¿ëÇÒ ¼ö ÀÖ´Â group ÁöÁ¤ÇÑ´Ù.
sugroups = [GROUP LIST]
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)