| Ãë¾àÁ¡ID |
16001 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
69 |
| ÇÁ·ÎÅäÄÝ |
UDP |
| ºÐ·ù |
TFTP |
| »ó¼¼¼³¸í |
ÇØ´ç ¼¹öÀÇ /etc/passwd ÆÄÀÏÀÌ AccessµÇ¾î Áø´Ù. ÆÐ½º¿öµå ÆÄÀÏÀÌ À¯ÃâµÇ¾î Áø´Ù´Â °ÍÀº ¼¹ö³»ÀÇ World ReadableÇÑ ¸ðµç ÆÄÀÏÀÌ À¯ÃâµÇ¾î Áú ¼ö ÀÖ´Ù´Â °ÍÀ» ÀǹÌÇÑ´Ù. ¶ÇÇÑ ÆÐ½º¿öµå ÆÄÀÏÀº Crack ÇÁ·Î±×·¥¿¡ ÀÇÇØ ÆÐ½º¿öµå°¡ DiscoveryµÇ¾î telnet, rlogin µîÀ» ÅëÇÑ ¼¹ö³» ħÅõµµ °¡´ÉÇØ ÆÐ½º¿öµå ÆÄÀÏÀÇ À¯ÃâÀº ±²ÀåÈ÷ À§ÇèÇÏ´Ù.
* Âü°í »çÀÌÆ®: http://www.cert.org/advisories/CA-1991-18.html http://www.iss.net/security_center/static/308.php |
| ÇØ°áÃ¥ |
1. Áï½Ã, TFTP ¼ºñ½ºÀÇ °¡µ¿À» ÁßÁö½ÃŲ´Ù(/etc/inetd.conf¿¡¼ tftp¶óÀÎÀ» comment ó¸®). ȤÀº ´ÙÀ½°ú °°ÀÌ ¸Ç µÚ¿¡ ¾×¼¼½º °¡´ÉÇÑ µð·ºÅ丮¸¦ ¸í½ÃÇØ¼ ¸í½ÃÇÑ µð·ºÅ丮 ¿Ü ´Ù¸¥ µð·ºÅ丮¸¦ ¾×¼¼½ºÇÏÁö ¸øÇÏ°Ô ÇÑ´Ù.
tftp dgram udp wait root /usr/sbin/tcpd in.tftpd /home/tftpdir
=> /home/tftpdir µð·ºÅ丮¸¸ ¾×¼¼½º
2. Áö±Ý±îÁö µð·ºÅ丮¸¦ Á¦ÇÑÇÏÁö ¾ÊÀº ä ¿î¿µÇØ ¿Ô´Ù¸é µî·ÏµÈ ¸ðµç °èÁ¤¿¡ ´ëÇØ¼ ÆÐ½º¿öµå¸¦ ¹Ù²Ü Çʿ䰡 ÀÖ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|