Ãë¾àÁ¡ID |
17069 |
À§Çèµµ |
40 |
Æ÷Æ® |
|
ÇÁ·ÎÅäÄÝ |
UDP |
ºÐ·ù |
RPC |
»ó¼¼¼³¸í |
ÇØ´ç sadmind µ¥¸óÀº Ãë¾àÇÑ ÀÎÁõÀ¸·Î ÀÎÇÑ ¿ø°Ý ¸í·É ½ÇÇà Ãë¾àÁ¡¿¡ Ãë¾àÇÏ´Ù. Solstice AdminSuite´Â Solaris ¿î¿µÃ¼Á¦¿¡¼ °ü¸®ÀÚµéÀÌ ½Ã½ºÅÛµé°ú ±× ¼³Á¤ Á¤º¸¸¦ Áß¾Ó¿¡¼ ¿ø°ÝÀ¸·Î °ü¸®ÇÏ°í ¼ÒÇÁÆ®¿þ¾îÀÇ »ç¿ëÀ» ¸ð´ÏÅÍÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁÖ´Â Sun Microsystems»ç¿¡ ÀÇÇØ ÆÐÅ°ÁöµÈ ÇÑ ¼¼Æ®ÀÇ ÅøÀÌ´Ù. Sadmind µ¥¸óÀº ºÐ»êµÇ¾î ÀÖ´Â ½Ã½ºÅÛ °ü¸®»óÀÇ Á¶ÀÛµéÀ» ¼öÇàÇÒ ¼ö ÀÖµµ·Ï Solstice AdminSuite ¾îÇø®ÄÉÀ̼ǵ鿡 ÀÇÇØ »ç¿ëµÈ´Ù. Sadmind µ¥¸óÀº ÀüÇüÀûÀ¸·Î Solaris ¼³Ä¡ ½Ã¿¡ µðÆúÆ®·Î ¼³Ä¡µÇ¾î ÀÛµ¿µÈ´Ù. Solaris »óÀÇ SadmindÀÇ µðÆúÆ® ¼³Ä¡ ½Ã, Ãë¾àÇÑ ÀÎÁõ (AUTH_SYS)À» »ç¿ëÇϴµ¥ ÀÌ´Â ·ÎÄà ȤÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ Solstice AdminSuite Ŭ¶óÀ̾ðÆ®µéÀ» ¼ÓÀÌ´Â ¾î¶² RPC ÆÐŶÀ» ÅëÇØ root ±ÇÇÑÀ» ȹµæÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº root ±ÇÇÑÀ» °¡Áö°í ´ë»ó ¼¹öÀÇ /tmp µð·ºÅ丮¿¡ "sadmind_vulnerable.by_scanner" ¶ó´Â À̸§ÀÇ ÆÄÀÏ »ý¼ºÀ» ½ÃµµÇÑ´Ù. µû¶ó¼ ¸¸¾à Sadmind µ¥¸óÀÌ °áÇÔ¿¡ Ãë¾àÇÏ´Ù¸é ÆÄÀÏÀÌ »ý¼ºµÇ¾î ÀÖÀ» °ÍÀÌ´Ù.
* Âü°í »çÀÌÆ®: http://www.securiteam.com/unixfocus/5HP0G1PB6K.html http://www.securiteam.com/exploits/5WP0M0AB5I.html http://marc.theaimsgroup.com/?l=bugtraq&m=106391959014331&w=2 http://archives.neohapsis.com/archives/vulnwatch/2003-q3/0115.html
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: SunOS 5.3¿¡¼ 5.9±îÁö (Solaris 2.x, 7, 8, 9) |
ÇØ°áÃ¥ |
´ÙÀ½ »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://download.oracle.com/sunalerts/1000778.1.html
-- ȤÀº --
ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ Â÷¼±Ã¥À¸·Î´Â, ½Ã½ºÅÛ »ó¿¡¼ sadmind¸¦ ÀÛµ¿ ÁßÁö½ÃÅ°°Å³ª ȤÀº inetd.conf ÆÄÀÏÀÇ sadmind ¿£Æ®¸®¿¡ "-S 2"¸¦ Ãß°¡ÇÔÀ¸·Î½á °ÇÑ ÀÎÁõ(AUTH_DES)À» ÀÛµ¿½ÃÄÑ ³õÀ» ¼ö ÀÖ´Ù.
Solaris »ó¿¡¼ sadmind¸¦ ÀÛµ¿ ÁßÁö½ÃÅ°´Â ¹æ¹ý: 1. "/etc/inetd.conf" ÆÄÀÏÀ» ÆíÁýÇÏ¿© ´ÙÀ½°ú °°ÀÌ ¶óÀÎÀÇ ½ÃÀÛÀ§Ä¡¿¡ "#" ¹®ÀÚ¸¦ Ãß°¡ÇÔÀ¸·Î½á ´ÙÀ½ ¶óÀÎÀ» ÁÖ¼® ó¸®ÇÒ ¼ö ÀÖ´Ù: #100232/10 tli rpc/udp wait root /usr/sbin/sadmind sadmind 2. Hangup ½Ã±×³ÎÀ» º¸³¿À¸·Î½á »õ·Î ¼öÁ¤µÈ "/etc/inetd.conf" ÆÄÀÏÀ» ´Ù½Ã ÀоîµéÀ̵µ·Ï inetd ÇÁ·Î¼¼½º¿¡°Ô ¾Ë·ÁÁØ´Ù: # kill -HUP <inetd process id>
Solaris »ó¿¡¼ sadmind¿¡ ´ëÇÑ °ÇÑ ÀÎÁõ(AUTH_DES)À» ÀÛµ¿½ÃÅ°´Â ¹æ¹ý: 1. "/etc/inetd.conf" ÆÄÀÏÀ» ÆíÁýÇÏ¿© ´ÙÀ½°ú °°ÀÌ sadmind ¶óÀÎÀÇ ³¡¿¡ "-S 2"¸¦ µ¡ºÙÀδÙ: 100232/10 tli rpc/udp wait root /usr/sbin/sadmind sadmind -S 2 2. Hangup ½Ã±×³ÎÀ» º¸³¿À¸·Î½á »õ·Î ¼öÁ¤µÈ "/etc/inetd.conf" ÆÄÀÏÀ» ´Ù½Ã ÀоîµéÀ̵µ·Ï inetd ÇÁ·Î¼¼½º¿¡°Ô ¾Ë·ÁÁØ´Ù: # kill -HUP <inetd process id> |
°ü·Ã URL |
CVE-2003-0722 (CVE) |
°ü·Ã URL |
8615 (SecurityFocus) |
°ü·Ã URL |
(ISS) |
|