| Ãë¾àÁ¡ID |
17056 |
| À§Çèµµ |
20 |
| Æ÷Æ® |
111 |
| ÇÁ·ÎÅäÄÝ |
TCP,UDP |
| ºÐ·ù |
RPC |
| »ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡ RPC ypxfrd ¼ºñ½º°¡ °¡µ¿ÁßÀÌ´Ù. ypxfrd µ¥¸óÀº È£½ºÆ®°£¿¡ NIS ¸Ê(map)ÀÇ Àü¼Û È¿À²À» Çâ»ó½Ã۱â À§ÇØ µðÀÚÀÎ µÇ¾ú´Ù. ypxfrd ÇÁ·Î¼¼½º´Â RPC portmapper¿¡ 100069¹øÀ¸·Î µî·ÏµÇ¾î ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/281.php http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/116&type=0&nav=sec.sba
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux Any version Unix Any version |
| ÇØ°áÃ¥ |
³×Æ®¿÷ ü°è°¡ NIS¸¦ »ç¿ëÇÏÁö ¾Ê°Å³ª ȤÀº »ç¿ëÇÏ´õ¶óµµ ¼º´É¿¡ ½É°¢ÇÑ ¿µÇâÀ» ÁÖÁö ¾Ê´Â Á¤µµÀÇ ¼Ò±Ô¸ð map Àü¼Û¿¡¼´Â ÀÌ ¼ºñ½º¸¦ °¡µ¿Áß´Ü ÇÏ´Â °ÍÀÌ ¹Ù¶÷Á÷ÇÏ´Ù.
* °¡µ¿ÁßÁö ¹æ¹ý
1. rootÀÇ ±ÇÇÑÀ¸·Î ´ÙÀ½°ú °°ÀÌ rpcÀÇ °¡µ¿À» ÁßÁö½ÃŲ´Ù.
# rpcinfo -d [program num] [version num]
2. /etc/inetd.conf ÆÄÀÏ¿¡¼ 'ypxfrd' ¶óÀÎÀ» '#'À» ÀÌ¿ëÇÏ¿© ÁÖ¼®Ã³¸®ÇÑ´Ù. 3. inetd µ¥¸óÀ» Àç±âµ¿½ÃŲ´Ù (kill -HUP [inetd process id]).
Solaris 10, Solaris 11, Enterprise Linux 6.4, CentOS 6.4, Fedora 19 ÀÇ °æ¿ì: 1. rootÀÇ ±ÇÇÑÀ¸·Î ´ÙÀ½°ú °°ÀÌ rpcÀÇ °¡µ¿À» ÁßÁö½ÃŲ´Ù.
# rpcinfo -d [program num] [version num]
2. /etc/rpc ÆÄÀÏ¿¡¼ 'ypxfrd' ¶óÀÎÀ» '#'À» ÀÌ¿ëÇÏ¿© ÁÖ¼®Ã³¸®ÇÑ´Ù. 3. # pkill -HUP (x)inetd |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|