English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 15009
À§Çèµµ 30
Æ÷Æ® 79
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù FINGER
»ó¼¼¼³¸í "."¸¦ Àμö·Î ÇÏ¿© Finger Query¸¦ Çϸé ÇØ´ç¼­¹öÀÇ Account Á¤º¸¸¦ º¼ ¼ö ÀÖ´Ù. Áï, "finger 0@target.com"À̶ó°í ÇÏ°Ô µÇ¸é ÇØ´ç¼­¹ö¿¡¼­ µî·Ï¸¸ ÇØ ³õ°í Áö±Ý±îÁö »ç¿ëÇÑ ÀûÀÌ ¾ø´Â UserµéÀÇ List¸¦ º¼ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/46.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ ¼­¹öÀÇ Account Á¤º¸´Â Cracker¿¡°Ô ¸Å¿ì À¯¿ëÇÑ Á¤º¸·Î »ç¿ëµÇ¾îÁú ¼ö ÀÖ¾î À§ÇèÇÏ´Ù. ƯÈ÷ ÀÌ ¹æ¹ýÀ» ÀÌ¿ëÇÑ Query·Î µî·ÏÈÄ »ç¿ëÇÏÁö ¾Ê´Â Account Á¤º¸¸¦ ¾ò¾î¿Ã ¼ö ÀÖ¾î Login try, Spooing ¶Ç´Â ÀÌ¿Í °áºÎÇÑ ¸¹Àº °ø°Ý¹æ¹ýµéÀ» ÀÌ¿ëÇÏ¿© Account¸¦ ȹµæÇÒ ¼ö ÀÖ´Ù. µû¶ó¼­ ¼­ºñ½º¸¦ »ç¿ëÁßÁöÇϰųª PatchÇÏ¿©¾ß ÇÑ´Ù.

¡Ø /etc/inetd.conf ÆÄÀÏ¿¡¼­ finger ¶óÀÎÀ» Comment Out

*Solaris 10, Solaris 11ÀÇ °æ¿ì:
# svcadm disable svc:/network/finger:default

*Enterprise Linux 6.4, CentOS 6.4, Fedora 19:
/etc/xinetd.d/fingerÀ» ¿­¾î disable=yes·Î ¼³Á¤ÇÑ ÈÄ xinetd¸¦ Àç½ÃÀÛÇÑ´Ù.
°ü·Ã URL CVE-1999-0612 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)