English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18017
À§Çèµµ 40
Æ÷Æ® 25
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMTP
»ó¼¼¼³¸í ÇØ´ç Sendmail ¼­¹ö´Â ¸ÞÀÏÀÌ ÇÁ·Î±×·¥À¸·Î ¹Ý¼ÛµÇ´Â(bound) °ÍÀ» Çã¿ëÇÑ´Ù.
ÀϺΠSendmail ¼­¹ö´Â ÆÄÀÌÇÁ ¹®ÀÚ "|" ¸¦ Æ÷ÇÔÇÑ ¿Ã¹Ù¸£Áö ¸øÇÑ ÇüÅÂÀÇ "MAIL FROM" ÁÖ¼Ò¿¡ ´ëÇØ¼­ Á¤»óÀûÀ¸·Î ¹Þ¾ÆµéÀδÙ. À̰ÍÀº ¸ÞÀÏ ¼­¹ö¸¦ ÅëÇØ¼­ ¿Ã¹Ù¸¥ »ç¿ëÀÚ°¡ ¾Æ´Ñ ÀÓÀÇÀÇ ÇÁ·Î±×·¥À¸·Î ¸ÞÀÏÀ» ¹Ý¼Û(bounce)ÇÏ´Â °ÍÀÌ °¡´ÉÇÏ´Ù´Â °ÍÀ» ÀǹÌÇÑ´Ù. À̰ÍÀº °ø°ÝÀÚ·Î ÇÏ¿©±Ý ¼­¹ö »ó¿¡¼­ ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖµµ·Ï Çϱ⠶§¹®¿¡ ¸Å¿ì À§ÇèÇÏ´Ù.
ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© °ø°ÝÀÚµéÀº ´ë°³ ´ÙÀ½°ú °°ÀÌ ¸ÞÀÏÀ» ¹ß¼ÛÇÑ´Ù.

>> telnet [target address] 25
HELO domain.com
MAIL FROM: |/bin/sed '1,/^$/d'|bin/sh
RCPT TO: nosuchuser
DATA
hello!!
my name is test program....

ping test.com
Quit
>>

ÀÌ °æ¿ì, ¸ÞÀÏÀº ¹Ý¼ÛµÇ¾î ¼Û½ÅÀÚ¿¡°Ô µÇµ¹¾Æ°¡°í ¼Û½ÅÀÚ´Â ±×°ÍÀ» ÆÄÀÌÇÁ¸¦ ÅëÇÏ¿© /bin/sh ÇÁ·Î±×·¥¿¡ ³Ñ°ÜÁØ ÈÄ ¸Þ½ÃÁöÀÇ º»¹®(ping test.com)À» ½ÇÇàÇÏ°Ô µÈ´Ù.

¾Ë¸²: ÀÌ Á¡°Ë Ç׸ñÀº "MAIL FROM: |/bin/id>by_scanner.bouncetoprogram.vulnerability" À» »ç¿ëÇÏ¿© Å×½ºÆ®ÇÑ´Ù. Smail, IRIX 6.x sendmail°ú °°Àº ÀϺΠMTA µéÀÌ ÀÌ Å×½ºÆ® ¸í·É¿¡ ´ëÇØ¼­ Á¤»óÀûÀ¸·Î ¹Þ¾ÆµéÀ̱â´Â ÇÏÁö¸¸ ¸Þ½ÃÁö¸¦ ±×´ë·Î Æó±âÇϱ⠶§¹®¿¡ "False Positive"ÀÇ °¡´É¼ºµµ Á¸ÀçÇÑ´Ù. ÀÌ ½ºÄ³³Ê´Â /tmp µð·ºÅ丮¿¡ 'by_scanner.bouncetoprogram.vulnerability'¶ó ºÒ¸®´Â ÆÄÀÏÀÇ »ý¼ºÀ» ½ÃµµÇÑ´Ù. ¸¸¾à ½ºÄµÀÌ ¿Ï·áµÈ ÈÄ ÀÌ ÆÄÀÏÀÌ ´ë»ó È£½ºÆ®¿¡ Á¸ÀçÇÑ´Ù¸é ±× È£½ºÆ®´Â Ãë¾àÇÏ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-1995-08.html
ftp://ciac.llnl.gov/pub/ciac/bulletin/e-fy94/e-03.ciac-unix-sendmail-vulns
ÇØ°áÃ¥ ´ÙÀ½ Sendmail »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å Çϰųª ÀûÀýÇÑ ÆÐÄ¡¸¦ ¼³Ä¡ÇØ¾ß ÇÑ´Ù. : ftp://ftp.sendmail.org/pub/sendmail/

* Silicon Graphics Inc.
Sendmail 8.6.12·Î ¾÷±×·¹À̵å Çϰųª ÀûÀýÇÑ ÆÐÄ¡¸¦ ¼³Ä¡ÇÑ´Ù.
ftp://ftp.sgi.com

º¸´Ù ÀÚ¼¼ÇÑ Á¤º¸´Â ´ÙÀ½ Âü°í»çÀ̺z ÂüÁ¶ÇÑ´Ù.
http://www.cert.org/advisories/CA-1995-08.html
°ü·Ã URL CVE-1999-0203 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)