| Ãë¾àÁ¡ID |
18017 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
25 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
SMTP |
| »ó¼¼¼³¸í |
ÇØ´ç Sendmail ¼¹ö´Â ¸ÞÀÏÀÌ ÇÁ·Î±×·¥À¸·Î ¹Ý¼ÛµÇ´Â(bound) °ÍÀ» Çã¿ëÇÑ´Ù. ÀϺΠSendmail ¼¹ö´Â ÆÄÀÌÇÁ ¹®ÀÚ "|" ¸¦ Æ÷ÇÔÇÑ ¿Ã¹Ù¸£Áö ¸øÇÑ ÇüÅÂÀÇ "MAIL FROM" ÁÖ¼Ò¿¡ ´ëÇØ¼ Á¤»óÀûÀ¸·Î ¹Þ¾ÆµéÀδÙ. À̰ÍÀº ¸ÞÀÏ ¼¹ö¸¦ ÅëÇØ¼ ¿Ã¹Ù¸¥ »ç¿ëÀÚ°¡ ¾Æ´Ñ ÀÓÀÇÀÇ ÇÁ·Î±×·¥À¸·Î ¸ÞÀÏÀ» ¹Ý¼Û(bounce)ÇÏ´Â °ÍÀÌ °¡´ÉÇÏ´Ù´Â °ÍÀ» ÀǹÌÇÑ´Ù. À̰ÍÀº °ø°ÝÀÚ·Î ÇÏ¿©±Ý ¼¹ö »ó¿¡¼ ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇÒ ¼ö ÀÖµµ·Ï Çϱ⠶§¹®¿¡ ¸Å¿ì À§ÇèÇÏ´Ù. ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© °ø°ÝÀÚµéÀº ´ë°³ ´ÙÀ½°ú °°ÀÌ ¸ÞÀÏÀ» ¹ß¼ÛÇÑ´Ù.
>> telnet [target address] 25 HELO domain.com MAIL FROM: |/bin/sed '1,/^$/d'|bin/sh RCPT TO: nosuchuser DATA hello!! my name is test program....
ping test.com Quit >>
ÀÌ °æ¿ì, ¸ÞÀÏÀº ¹Ý¼ÛµÇ¾î ¼Û½ÅÀÚ¿¡°Ô µÇµ¹¾Æ°¡°í ¼Û½ÅÀÚ´Â ±×°ÍÀ» ÆÄÀÌÇÁ¸¦ ÅëÇÏ¿© /bin/sh ÇÁ·Î±×·¥¿¡ ³Ñ°ÜÁØ ÈÄ ¸Þ½ÃÁöÀÇ º»¹®(ping test.com)À» ½ÇÇàÇÏ°Ô µÈ´Ù.
¾Ë¸²: ÀÌ Á¡°Ë Ç׸ñÀº "MAIL FROM: |/bin/id>by_scanner.bouncetoprogram.vulnerability" À» »ç¿ëÇÏ¿© Å×½ºÆ®ÇÑ´Ù. Smail, IRIX 6.x sendmail°ú °°Àº ÀϺΠMTA µéÀÌ ÀÌ Å×½ºÆ® ¸í·É¿¡ ´ëÇØ¼ Á¤»óÀûÀ¸·Î ¹Þ¾ÆµéÀ̱â´Â ÇÏÁö¸¸ ¸Þ½ÃÁö¸¦ ±×´ë·Î Æó±âÇϱ⠶§¹®¿¡ "False Positive"ÀÇ °¡´É¼ºµµ Á¸ÀçÇÑ´Ù. ÀÌ ½ºÄ³³Ê´Â /tmp µð·ºÅ丮¿¡ 'by_scanner.bouncetoprogram.vulnerability'¶ó ºÒ¸®´Â ÆÄÀÏÀÇ »ý¼ºÀ» ½ÃµµÇÑ´Ù. ¸¸¾à ½ºÄµÀÌ ¿Ï·áµÈ ÈÄ ÀÌ ÆÄÀÏÀÌ ´ë»ó È£½ºÆ®¿¡ Á¸ÀçÇÑ´Ù¸é ±× È£½ºÆ®´Â Ãë¾àÇÏ´Ù.
* Âü°í »çÀÌÆ®: http://www.cert.org/advisories/CA-1995-08.html ftp://ciac.llnl.gov/pub/ciac/bulletin/e-fy94/e-03.ciac-unix-sendmail-vulns |
| ÇØ°áÃ¥ |
´ÙÀ½ Sendmail »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© °¡Àå ÃֽйöÀüÀ¸·Î ¾÷±×·¹À̵å Çϰųª ÀûÀýÇÑ ÆÐÄ¡¸¦ ¼³Ä¡ÇØ¾ß ÇÑ´Ù. : ftp://ftp.sendmail.org/pub/sendmail/
* Silicon Graphics Inc. Sendmail 8.6.12·Î ¾÷±×·¹À̵å Çϰųª ÀûÀýÇÑ ÆÐÄ¡¸¦ ¼³Ä¡ÇÑ´Ù. ftp://ftp.sgi.com
º¸´Ù ÀÚ¼¼ÇÑ Á¤º¸´Â ´ÙÀ½ Âü°í»çÀ̺z ÂüÁ¶ÇÑ´Ù. http://www.cert.org/advisories/CA-1995-08.html |
| °ü·Ã URL |
CVE-1999-0203 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|