English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 17069
À§Çèµµ 40
Æ÷Æ®
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù RPC
»ó¼¼¼³¸í ÇØ´ç sadmind µ¥¸óÀº Ãë¾àÇÑ ÀÎÁõÀ¸·Î ÀÎÇÑ ¿ø°Ý ¸í·É ½ÇÇà Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù.
Solstice AdminSuite´Â Solaris ¿î¿µÃ¼Á¦¿¡¼­ °ü¸®ÀÚµéÀÌ ½Ã½ºÅÛµé°ú ±× ¼³Á¤ Á¤º¸¸¦ Áß¾Ó¿¡¼­ ¿ø°ÝÀ¸·Î °ü¸®ÇÏ°í ¼ÒÇÁÆ®¿þ¾îÀÇ »ç¿ëÀ» ¸ð´ÏÅÍÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁÖ´Â Sun Microsystems»ç¿¡ ÀÇÇØ ÆÐÅ°ÁöµÈ ÇÑ ¼¼Æ®ÀÇ ÅøÀÌ´Ù. Sadmind µ¥¸óÀº ºÐ»êµÇ¾î ÀÖ´Â ½Ã½ºÅÛ °ü¸®»óÀÇ Á¶ÀÛµéÀ» ¼öÇàÇÒ ¼ö ÀÖµµ·Ï Solstice AdminSuite ¾îÇø®ÄÉÀ̼ǵ鿡 ÀÇÇØ »ç¿ëµÈ´Ù. Sadmind µ¥¸óÀº ÀüÇüÀûÀ¸·Î Solaris ¼³Ä¡ ½Ã¿¡ µðÆúÆ®·Î ¼³Ä¡µÇ¾î ÀÛµ¿µÈ´Ù.
Solaris »óÀÇ SadmindÀÇ µðÆúÆ® ¼³Ä¡ ½Ã, Ãë¾àÇÑ ÀÎÁõ (AUTH_SYS)À» »ç¿ëÇϴµ¥ ÀÌ´Â ·ÎÄà ȤÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ Solstice AdminSuite Ŭ¶óÀ̾ðÆ®µéÀ» ¼ÓÀÌ´Â ¾î¶² RPC ÆÐŶÀ» ÅëÇØ root ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº root ±ÇÇÑÀ» °¡Áö°í ´ë»ó ¼­¹öÀÇ /tmp µð·ºÅ丮¿¡ "sadmind_vulnerable.by_scanner" ¶ó´Â À̸§ÀÇ ÆÄÀÏ »ý¼ºÀ» ½ÃµµÇÑ´Ù. µû¶ó¼­ ¸¸¾à Sadmind µ¥¸óÀÌ °áÇÔ¿¡ Ãë¾àÇÏ´Ù¸é ÆÄÀÏÀÌ »ý¼ºµÇ¾î ÀÖÀ» °ÍÀÌ´Ù.

* Âü°í »çÀÌÆ®:
http://www.securiteam.com/unixfocus/5HP0G1PB6K.html
http://www.securiteam.com/exploits/5WP0M0AB5I.html
http://marc.theaimsgroup.com/?l=bugtraq&m=106391959014331&w=2
http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0115.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
SunOS 5.3¿¡¼­ 5.9±îÁö (Solaris 2.x, 7, 8, 9)
ÇØ°áÃ¥ ´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://download.oracle.com/sunalerts/1000778.1.html

-- ȤÀº --

ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ Â÷¼±Ã¥À¸·Î´Â, ½Ã½ºÅÛ »ó¿¡¼­ sadmind¸¦ ÀÛµ¿ ÁßÁö½ÃÅ°°Å³ª ȤÀº inetd.conf ÆÄÀÏÀÇ sadmind ¿£Æ®¸®¿¡ "-S 2"¸¦ Ãß°¡ÇÔÀ¸·Î½á °­ÇÑ ÀÎÁõ(AUTH_DES)À» ÀÛµ¿½ÃÄÑ ³õÀ» ¼ö ÀÖ´Ù.

Solaris »ó¿¡¼­ sadmind¸¦ ÀÛµ¿ ÁßÁö½ÃÅ°´Â ¹æ¹ý:
1. "/etc/inetd.conf" ÆÄÀÏÀ» ÆíÁýÇÏ¿© ´ÙÀ½°ú °°ÀÌ ¶óÀÎÀÇ ½ÃÀÛÀ§Ä¡¿¡ "#" ¹®ÀÚ¸¦ Ãß°¡ÇÔÀ¸·Î½á ´ÙÀ½ ¶óÀÎÀ» ÁÖ¼® ó¸®ÇÒ ¼ö ÀÖ´Ù:
#100232/10 tli rpc/udp wait root /usr/sbin/sadmind sadmind
2. Hangup ½Ã±×³ÎÀ» º¸³¿À¸·Î½á »õ·Î ¼öÁ¤µÈ "/etc/inetd.conf" ÆÄÀÏÀ» ´Ù½Ã ÀоîµéÀ̵µ·Ï inetd ÇÁ·Î¼¼½º¿¡°Ô ¾Ë·ÁÁØ´Ù:
# kill -HUP <inetd process id>

Solaris »ó¿¡¼­ sadmind¿¡ ´ëÇÑ °­ÇÑ ÀÎÁõ(AUTH_DES)À» ÀÛµ¿½ÃÅ°´Â ¹æ¹ý:
1. "/etc/inetd.conf" ÆÄÀÏÀ» ÆíÁýÇÏ¿© ´ÙÀ½°ú °°ÀÌ sadmind ¶óÀÎÀÇ ³¡¿¡ "-S 2"¸¦ µ¡ºÙÀδÙ:
100232/10 tli rpc/udp wait root /usr/sbin/sadmind sadmind -S 2
2. Hangup ½Ã±×³ÎÀ» º¸³¿À¸·Î½á »õ·Î ¼öÁ¤µÈ "/etc/inetd.conf" ÆÄÀÏÀ» ´Ù½Ã ÀоîµéÀ̵µ·Ï inetd ÇÁ·Î¼¼½º¿¡°Ô ¾Ë·ÁÁØ´Ù:
# kill -HUP <inetd process id>
°ü·Ã URL CVE-2003-0722 (CVE)
°ü·Ã URL 8615 (SecurityFocus)
°ü·Ã URL (ISS)