| Ãë¾àÁ¡ID |
17015 |
| À§Çèµµ |
20 |
| Æ÷Æ® |
111 |
| ÇÁ·ÎÅäÄÝ |
TCP,UDP |
| ºÐ·ù |
RPC |
| »ó¼¼¼³¸í |
ÇØ´ç ¼¹ö¿¡ bootparamd RPC ¼ºñ½º°¡ °¡µ¿µÇ°í ÀÖ´Ù. ÀÌ ¼ºñ½º´Â NISÀÇ ±¸¼º¿ä¼Ò·Î½á Diskless Ŭ¶óÀÌ¾ðÆ®°¡ bootÇÒ ¶§ ÇÊ¿äÇÑ Á¤º¸¸¦ ¾ò´Âµ¥ »ç¿ëµÈ´Ù. ÇÏÁö¸¸ ¿©·¯°¡Áö TrickÀ» ÀÌ¿ëÇÏ¿© À¯ÃâÇÏÁö ¸»¾Æ¾ß ÇÒ Á¤º¸¸¦ À¯ÃâÇÏ´Â °æ¿ì°¡ ÀÖ¾î º¸¾È¿¡ À¯ÀÇÇØ¼ ¼ºñ½ºÇØ¾ß ÇÑ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux Any version Unix Any version |
| ÇØ°áÃ¥ |
»ç¿ëÇÏÁö ¾Ê´Â´Ù¸é ÀáÀçÀûÀÎ º¸¾È Ãë¾àÁ¡ÀÌ ÀÖÀ» ¼ö ÀÖÀ¸¹Ç·Î ÇØ´ç ¼ºñ½ºÀÇ °¡µ¿À» ÁßÁöÇÑ´Ù. ¹Ýµå½Ã »ç¿ëÇÏ¿©¾ß ÇÑ´Ù¸é º¸¾È¿¡ ¹®Á¦°¡ ¾ø´ÂÁö ÇØ´ç Vendor¿¡ ¹®ÀÇ ÈÄ »ç¿ëÇÑ´Ù. ¶ÇÇÑ °¡´ÉÇÏ´Ù¸é Portmapper·ÎÀÇ Á¢¼ÓÀÌ ¿ÜºÎ·ÎºÎÅÍ Â÷´ÜµÉ ¼ö ÀÖµµ·Ï incomming Æ®·¡ÇÈÀ» ÇÊÅ͸µÇÑ´Ù.
* °¡µ¿ÁßÁö ¹æ¹ý
HP-UX, AIX, Solaris 9 ÀÌÇÏÀÇ °æ¿ì: 1. rootÀÇ ±ÇÇÑÀ¸·Î ´ÙÀ½°ú °°ÀÌ rpcÀÇ °¡µ¿À» ÁßÁö½ÃŲ´Ù.
# rpcinfo -d [program num] [version num]
2. /etc/inetd.conf ÆÄÀÏ¿¡¼ 'bootparam' ¶óÀÎÀ» '#'À» ÀÌ¿ëÇÏ¿© ÁÖ¼®Ã³¸®ÇÑ´Ù. 3. inetd µ¥¸óÀ» Àç±âµ¿½ÃŲ´Ù (kill -HUP [inetd process id]).
Solaris 10, Solaris 11, Enterprise Linux 6.4, CentOS 6.4, Fedora 19 ÀÇ °æ¿ì: 1. rootÀÇ ±ÇÇÑÀ¸·Î ´ÙÀ½°ú °°ÀÌ rpcÀÇ °¡µ¿À» ÁßÁö½ÃŲ´Ù.
# rpcinfo -d [program num] [version num]
2. /etc/rpc ÆÄÀÏ¿¡¼ 'bootparam' ¶óÀÎÀ» '#'À» ÀÌ¿ëÇÏ¿© ÁÖ¼®Ã³¸®ÇÑ´Ù. 3. # pkill -HUP (x)inetd |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|