| Ãë¾àÁ¡ID |
15007 |
| À§Çèµµ |
20 |
| Æ÷Æ® |
79 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
FINGER |
| »ó¼¼¼³¸í |
ÇØ´ç ¼¹ö¸¦ ÀÌ¿ëÇÏ¿© Á÷Á¢ÀûÀÎ Access°¡ ºÒ°¡´ÉÇÑ ´Ù¸¥ ¼¹öµéÀÇ Finger Á¤º¸¸¦ º¼ ¼ö ÀÖ´Ù. Áï, ´ÙÀ½°ú °°ÀÌ Command¸¦ Ä£´Ù¸é
finger root@target@victim
Á÷Á¢ Á¢±ÙÀÌ ºÒ°¡´ÉÇÑ targetÀ̶ó´Â ¼¹öÀÇ finger Á¤º¸¸¦ º¼ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/47.php http://www.networkice.com/advice/exploits/services/finger/finger_bomb/default.htm
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux Any version Unix Any version |
| ÇØ°áÃ¥ |
¼¹öÀÇ Account Á¤º¸´Â Cracker¿¡°Ô ¸Å¿ì À¯¿ëÇÑ Á¤º¸·Î »ç¿ëµÇ¾îÁú ¼ö ÀÖ¾î À§ÇèÇÏ´Ù. ¾ò¾îÁø Account Á¤º¸´Â Login try, Spooing ¶Ç´Â ÀÌ¿Í °áºÎÇÑ ¸¹Àº °ø°Ý¹æ¹ýÀÌ ÀÖÀ¸¹Ç·Î ¼ºñ½º¸¦ »ç¿ëÁßÁö Çϰųª PatchÇÏ¿©¾ß ÇÑ´Ù.
´ÙÀ½°ú °°Àº ¹æ¹ýÀ¸·Î fingerd µ¥¸óÀ» ÁßÁö½ÃŲ´Ù. # vi /etc/inetd.conf (finger·Î ½ÃÀ۵Ǵ ºÎºÐÀ» #·Î commentó¸®) # killall -HUP inetd
*Solaris 10, Solaris 11ÀÇ °æ¿ì: # svcadm disable svc:/network/finger:default
*Enterprise Linux 6.4, CentOS 6.4, Fedora 19: /etc/xinetd.d/fingerÀ» ¿¾î disable=yes·Î ¼³Á¤ÇÑ ÈÄ xinetd¸¦ Àç½ÃÀÛÇÑ´Ù. |
| °ü·Ã URL |
CVE-1999-0106 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|