English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 15006
À§Çèµµ 30
Æ÷Æ® 79
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FINGER
»ó¼¼¼³¸í ÇØ´ç ¼­¹ö¿¡ ÀÖ´Â finger ¼­ºñ½º¿¡ Ãë¾àÁ¡ÀÌ Á¸ÀçÇÏ¿© ¼­¹ö³»ÀÇ ÀÓÀÇÀÇ ÆÄÀÏÀ» root ±ÇÇÑÀ¸·Î¼­ Àоî¿Ã ¼ö ÀÖ´Ù. ¿¹¸¦ µé¾î FreeBSD ¼­¹ö¿¡¼­ ´ÙÀ½°ú °°ÀÌ ÇÔÀ¸·Î½á °¡´ÉÇÏ´Ù.

/etc/passwd@target.server

ÀÌ·¸°Ô ÇÔÀ¸·Î½á ¼­¹ö³»ÀÇ passwd ÆÄÀÏÀ» Àоî¿Ã ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/5385.php
http://archives.neohapsis.com/archives/bugtraq/2000-10/0017.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ Finger ¼­ºñ½º¸¦ Áï½Ã °¡µ¿ÁßÁö ÇÑ´Ù. °è¼Ó »ç¿ëÇÏ¿©¾ß ÇÒ Çʿ䰡 ÀÖ´Ù¸é ¹®Á¦°¡ ÇØ°áµÈ ¹öÀüÀ¸·Î ¾÷±×·¹À̵å ÇÏ¿© »ç¿ëÇÑ´Ù.

Finger ¼­ºñ½º ÁßÁö ¹æ¹ýÀº ´ÙÀ½°ú °°´Ù.
*Solaris 10, Solaris 11ÀÇ °æ¿ì:
# svcadm disable svc:/network/finger:default

*Enterprise Linux 6.4, CentOS 6.4, Fedora 19:
/etc/xinetd.d/fingerÀ» ¿­¾î disable=yes·Î ¼³Á¤ÇÑ ÈÄ xinetd¸¦ Àç½ÃÀÛÇÑ´Ù.
°ü·Ã URL CVE-2000-0915 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)