English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 17056
À§Çèµµ 20
Æ÷Æ® 111
ÇÁ·ÎÅäÄÝ TCP,UDP
ºÐ·ù RPC
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡ RPC ypxfrd ¼­ºñ½º°¡ °¡µ¿ÁßÀÌ´Ù. ypxfrd µ¥¸óÀº È£½ºÆ®°£¿¡ NIS ¸Ê(map)ÀÇ Àü¼Û È¿À²À» Çâ»ó½Ã۱â À§ÇØ µðÀÚÀÎ µÇ¾ú´Ù.
ypxfrd ÇÁ·Î¼¼½º´Â RPC portmapper¿¡ 100069¹øÀ¸·Î µî·ÏµÇ¾î ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/281.php
http://sunsolve.sun.com/pub-cgi/retrieve.pl?doctype=coll&doc=secbull/116&type=0&nav=sec.sba

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ ³×Æ®¿÷ ü°è°¡ NIS¸¦ »ç¿ëÇÏÁö ¾Ê°Å³ª ȤÀº »ç¿ëÇÏ´õ¶óµµ ¼º´É¿¡ ½É°¢ÇÑ ¿µÇâÀ» ÁÖÁö ¾Ê´Â Á¤µµÀÇ ¼Ò±Ô¸ð map Àü¼Û¿¡¼­´Â ÀÌ ¼­ºñ½º¸¦ °¡µ¿Áß´Ü ÇÏ´Â °ÍÀÌ ¹Ù¶÷Á÷ÇÏ´Ù.

* °¡µ¿ÁßÁö ¹æ¹ý

1. rootÀÇ ±ÇÇÑÀ¸·Î ´ÙÀ½°ú °°ÀÌ rpcÀÇ °¡µ¿À» ÁßÁö½ÃŲ´Ù.

# rpcinfo -d [program num] [version num]

2. /etc/inetd.conf ÆÄÀÏ¿¡¼­ 'ypxfrd' ¶óÀÎÀ» '#'À» ÀÌ¿ëÇÏ¿© ÁÖ¼®Ã³¸®ÇÑ´Ù.
3. inetd µ¥¸óÀ» Àç±âµ¿½ÃŲ´Ù (kill -HUP [inetd process id]).

Solaris 10, Solaris 11, Enterprise Linux 6.4, CentOS 6.4, Fedora 19 ÀÇ °æ¿ì:
1. rootÀÇ ±ÇÇÑÀ¸·Î ´ÙÀ½°ú °°ÀÌ rpcÀÇ °¡µ¿À» ÁßÁö½ÃŲ´Ù.

# rpcinfo -d [program num] [version num]

2. /etc/rpc ÆÄÀÏ¿¡¼­ 'ypxfrd' ¶óÀÎÀ» '#'À» ÀÌ¿ëÇÏ¿© ÁÖ¼®Ã³¸®ÇÑ´Ù.
3. # pkill -HUP (x)inetd
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)