English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 17009
À§Çèµµ 40
Æ÷Æ® 111
ÇÁ·ÎÅäÄÝ TCP,UDP
ºÐ·ù RPC
»ó¼¼¼³¸í ÇØ´ç Network File System (NFS)Àº Portmapper¸¦ ÅëÇÑ Á¢¼ÓÀÌ °¡´ÉÇÑ °ÍÀ¸·Î ³ªÅ¸³­´Ù.
NFS ¼­¹ö´Â NFS Ŭ¶óÀÌ¾ðÆ®°¡ ¿ø°ÝÀ¸·Î ¼­¹öÀÇ ÆÄÀϽýºÅÛÀ» ¸¶¿îÆ®ÇÏ¿© »ç¿ëÇÒ ¼ö ÀÖµµ·Ï Çã¿ëÇÑ´Ù.
¸¶¿îÆ®¸¦ Çã¿ëÇϴ Ŭ¶óÀÌ¾ðÆ®µéÀÇ ¸ñ·ÏÀº /etc/exports ÆÄÀÏ »ó¿¡ ÀúÀåµÇ°í ÀÌ È­ÀÏ¿¡ Á¸ÀçÇϴ Ŭ¶óÀÌ¾ðÆ®µé¿¡°Ô¸¸ ¸¶¿îÆ® ¼­ºñ½º¸¦ Á¦°øÇÑ´Ù.
±×·¯³ª, /etc/exports ÆÄÀÏ »ó¿¡ Á¸ÀçÇÏÁö ¾Ê´Â Ŭ¶óÀ̾ðÆ®ÀÇ °æ¿ìµµ portmapper¸¦ ÅëÇØ¼­ NFS ¼­¹öÀÇ ÆÄÀϽýºÅÛÀ» ¸¶¿îÆ®ÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù. portmapper´Â poxy¿Í °°ÀÌ µ¿ÀÛÇÏ¿© ¿ø°ÝÁöÀÇ Å¬¶óÀÌ¾ðÆ®·ÎºÎÅÍ Àü´ÞµÈ mount ¿äûÀ» mountd µ¥¸ó¿¡°Ô ÀçÀü¼ÛÇÑ´Ù.
ÀÌ¿Í °°ÀÌ portmapper¸¦ ÅëÇØ ÀçÀü¼ÛµÈ mount ¿äûÀÇ °æ¿ì, ¸¶Ä¡ ·ÎÄà ȣ½ºÆ®¿¡ ÀÇÇØ ¿äûµÈ mount ¿äûó·³ °£ÁÖµÇ¸ç ¸¶¿îÆ®°¡ °¡´ÉÇÏ°Ô µÈ´Ù. ÀÌ·¯ÇÑ portmapper¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀº ÀÎÁõÀýÂ÷¸¦ ¿ìȸÇÏ´Â ¹æ¹ýÀ¸·Î ¾×¼¼½º°¡ Á¦ÇÑµÈ ¼­¹öÀÇ ·ÎÄà ÆÄÀϽýºÅÛÀ» ÀÚÀ¯·Ó°Ô ¸¶¿îÆ®ÇÏ¿© »ç¿ëÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/80.php
http://www.securityfocus.com/bid/422

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ /etc/exports ÆÄÀÏÀÇ ¼³Á¤ÀÌ ´ÙÀ½°ú °°ÀÌ ¼³Á¤µÇ¾î ÀÖ´ÂÁö È®ÀÎÇÑ´Ù.

- NFS ¼­¹ö ÀÚ½ÅÀÇ Exports ÆÄÀÏ¿¡ ÀÚ½ÅÀ» ÂüÁ¶(self-reference)ÇÏ°Ô ÇØ¼­´Â ¾ÈµÈ´Ù.
- exports ÆÄÀÏ¿¡ \localhost\¸¦ Æ÷ÇÔÇÏ´Â ¿£Æ®¸®°¡ Á¸ÀçÇÏÁö ¾Êµµ·Ï ÇÑ´Ù.
- ¼­ºñ½º¸¦ ÇÊ¿ä·ÎÇϴ ȣ½ºÆ®µé¿¡°Ô¸¸ ÆÄÀϽýºÅÛÀ» export ÇØ¾ß ÇÑ´Ù.
- ¿ÏÀüÇÑ(fully qualified) È£½ºÆ®¸íÀ¸·Î¸¸ export ÇØ¾ß ÇÑ´Ù.
- export ¸ñ·ÏÀÌ 256 ¹®ÀÚ¸¦ ³ÑÁö ¾Êµµ·Ï ÇÑ´Ù.
- "showmount" ¸í·É¾î¸¦ »ç¿ëÇÏ¿© ÇöÀç export »óȲÀÌ ¿Ã¹Ù¸¥Áö È®ÀÎÇÑ´Ù.

--- ±×¸®°í ---

Portmapper°¡ Proxy ¾×¼¼½º¸¦ Çã¿ëÇÏÁö ¾Êµµ·Ï ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇØ¾ß ÇÑ´Ù. ÆÐÄ¡¸¦ À§Çؼ­´Â ´ÙÀ½ »çÀÌÆ®µéÀ» ÂüÁ¶ÇÑ´Ù.

* CERT ±Ç°í¾È CA-91:21.SunOS.NFS.Jumbo.and.fsirand
http://www.cert.org/advisories/CA-1991-21.html
* CERT ±Ç°í¾È CA-92:15.Multiple.SunOS.vulnerabilities.patched
http://www.cert.org/advisories/CA-1992-15.html
* CERT ±Ç°í¾È CA-93:15.SunOS.and.Solaris.vulnerabilities
http://www.cert.org/advisories/CA-1993-15.html
* CERT ±Ç°í¾È CA-94:02.REVISED.SunOS.rpc.mountd.vulnerability
http://www.cert.org/advisories/CA-1994-02.html
* CERT ±Ç°í¾È CA-94:15.NFS.Vulnerabilities
http://www.cert.org/advisories/CA-1994-15.html
°ü·Ã URL CVE-1999-0168 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)