English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 17032
À§Çèµµ 20
Æ÷Æ® 111
ÇÁ·ÎÅäÄÝ TCP,UDP
ºÐ·ù RPC
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡ rstatd RPC ¼­¹ö½º°¡ °¡µ¿µÇ°í ÀÖ´Ù. ÀÌ ¼­ºñ½º´Â ´ÙÀ½°ú °°Àº Áß¿äÇÑ Á¤º¸¸¦ ¾ÇÀÇÀÇ »ç¿ëÀÚ¿¡°Ô Á¦°øÇÒ ¼ö ÀÖ¾î À§ÇèÇÏ´Ù.

- CPU »ç¿ë·®
- ½Ã½ºÅÛ ±âµ¿½Ã°¢
- ³×Æ®¿öÅ© »ç¿ë·®
- ±×¿Ü ´Ù¼ö

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ »ç¿ëÇÏÁö ¾Ê´Â´Ù¸é ÀáÀçÀûÀÎ º¸¾È Ãë¾àÁ¡ÀÌ ÀÖÀ» ¼ö ÀÖÀ¸¹Ç·Î ÇØ´ç ¼­ºñ½ºÀÇ °¡µ¿À» ÁßÁöÇÑ´Ù.

* °¡µ¿ÁßÁö ¹æ¹ý

rootÀÇ ±ÇÇÑÀ¸·Î ´ÙÀ½°ú °°ÀÌ rpcÀÇ °¡µ¿À» ÁßÁö½ÃŲ´Ù.
# rpcinfo -d [program num] [version num]

±×¸®°í³ª¼­ /etc/inetd.conf ÆÄÀÏ¿¡¼­ 'rstatd' ¶óÀÎÀ» '#'À» ÀÌ¿ëÇÏ¿© ÁÖ¼®Ã³¸®ÇÑ ÈÄ, inetd µ¥¸óÀ» Àç±âµ¿½ÃŲ´Ù (kill -HUP [inetd process id]).

¸¸¾à inetd¿¡ ÀÇÇØ ½ÃÀÛµÇÁö ¾Ê´Â´Ù¸é ÀûÀýÇÑ RC ÆÄÀÏÀ» ã¾Æ ¼öÁ¤ÇÏ¿©¾ß ÇÑ´Ù.

Solaris 10, Solaris 11, Enterprise Linux 6.4, CentOS 6.4, Fedora 19 ÀÇ °æ¿ì:
1. rootÀÇ ±ÇÇÑÀ¸·Î ´ÙÀ½°ú °°ÀÌ rpcÀÇ °¡µ¿À» ÁßÁö½ÃŲ´Ù.

# rpcinfo -d [program num] [version num]

2. /etc/rpc ÆÄÀÏ¿¡¼­ 'rstatd' ¶óÀÎÀ» '#'À» ÀÌ¿ëÇÏ¿© ÁÖ¼®Ã³¸®ÇÑ´Ù.
3. # pkill -HUP (x)inetd
°ü·Ã URL CVE-1999-0624 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)