English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 15008
À§Çèµµ 40
Æ÷Æ® 79
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FINGER
»ó¼¼¼³¸í ÇØ´ç ¼­¹öÀÇ Finger µ¥¸óÀÌ ¿ø°Ý ¸í·É½ÇÇà(Remote Execution)À» Çã¿ëÇÑ´Ù. ¿¹µéµé¾î ´ÙÀ½°ú °°ÀÌ Remote¼­¹ö¿¡¼­ ÇØ´ç ¼­¹ö·Î ¸í·ÉÀ» ³»¸°´Ù¸é

finger |command_to_execute@target

ÀÓÀÇÀÇ ¸í·É(command_to_execute) ¼öÇàÀÌ °¡´ÉÇÏ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ Remote¿¡¼­ Cracker°¡ ¿øÇÏ´Â ÀÓÀÇÀÇ ¸í·É ¼öÇàÀÌ °¡´ÉÇÏ¿© ÇØ´ç ¼­¹ö¸¦ Á÷Á¢ÀûÀ¸·Î Àå¾ÇÇÒ ¼ö°¡ ÀÖ´Ù. µû¶ó¼­ ¼­ºñ½º¸¦ Áö±ÝÁï½Ã °¡µ¿Áß´ÜÇÏ°í ¹Ýµå½Ã Finger°¡ ÇÊ¿äÇÑ °æ¿ì Patch Çϰųª UpgradeÇÏ¿© »ç¿ëÇØ¾ß ÇÑ´Ù.

¡Ø /etc/inetd.conf ÆÄÀÏ¿¡¼­ finger ¶óÀÎÀ» Comment Out

*Solaris 10, Solaris 11ÀÇ °æ¿ì:
# svcadm disable svc:/network/finger:default

*Enterprise Linux 6.4, CentOS 6.4, Fedora 19:
/etc/xinetd.d/fingerÀ» ¿­¾î disable=yes·Î ¼³Á¤ÇÑ ÈÄ xinetd¸¦ Àç½ÃÀÛÇÑ´Ù.
°ü·Ã URL CVE-2000-0128 (CVE)
°ü·Ã URL 974 (SecurityFocus)
°ü·Ã URL 4006 (ISS)