| Ãë¾àÁ¡ID |
18021 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
25 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
SMTP |
| »ó¼¼¼³¸í |
ÇØ´ç Sendmail ¼¹ö´Â ÆÄÀÌÇÁ ("|") °ø°Ý¿¡ Ãë¾àÇÏ´Ù. ÀϺΠSendmail ¼¹ö´Â ÆÄÀÌÇÁ "|" ¹®ÀÚ°¡ »ðÀÔµÈ "RCPT TO" ¸í·ÉÀ» Á¤»óÀûÀ¸·Î ¹Þ¾ÆµéÀδÙ. À̰ÍÀº ¿ø°Ý È£½ºÆ® »óÀÇ ÇÁ·Î±×·¥¿¡°Ô ¸ÞÀÏÀ» Àü´ÞÇÒ ¼ö ÀÖµµ·Ï ¸ÞÀÏ Àü¼ÛÀÌ °¡´ÉÇÏ´Ù´Â °ÍÀ» ÀǹÌÇϱ⠶§¹®¿¡ ¸Å¿ì À§ÇèÇÏ´Ù. ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ¿ø°ÝÁö °ø°ÝÀÚµéÀº ¸ÞÀÏÀÌ ÇÁ·Î±×·¥ÀÇ ÀÔ·ÂÀ¸·Î Àü´Þ(pipe)µÉ ¼ö ÀÖµµ·Ï "RCPT TO" ¸í·É µÚ¿¡ Àß Á¶ÀÛµÈ ÁÖ¼Ò¸¦ ¸í½ÃÇÔÀ¸·Î½á ¿ø°Ý È£½ºÆ® »ó¿¡¼ ÀÓÀÇÀÇ ¸í·ÉÀ» ½ÇÇàÇϰųª ·çÆ® ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ´Ù. ´ÙÀ½°ú °°Àº ¹æ¹ýÀ¸·Î ÀÌ Ãë¾àÁ¡¿¡ ´ëÇÑ Å×½ºÆ®°¡ °¡´ÉÇÏ´Ù.
>> telnet [´ë»óÈ£½ºÆ®] 25
HELO domain.com MAIL FROM: root@domain.com RCPT TO: |testing
¾Ë¸²: ÀÌ Á¡°Ë Ç׸ñÀº Smail, IRIX 6.x sendmail°ú °°Àº ÀϺΠMTA µéÀÌ ÀÌ Å×½ºÆ® ¸í·É¿¡ ´ëÇØ¼ Á¤»óÀûÀ¸·Î ¹Þ¾ÆµéÀ̱â´Â ÇÏÁö¸¸ ¸Þ½ÃÁö¸¦ ±×´ë·Î Æó±âÇϱ⠶§¹®¿¡ "False Positive"ÀÇ °¡´É¼ºµµ Á¸ÀçÇÑ´Ù. ÀÌ ½ºÄ³³Ê´Â /tmp µð·ºÅ丮¿¡ 'by_scanner.pipetoprogram.vulnerability'¶ó ºÒ¸®´Â ÆÄÀÏÀÇ »ý¼ºÀ» ½ÃµµÇÑ´Ù. ¸¸¾à ½ºÄµÀÌ ¿Ï·áµÈ ÈÄ ÀÌ ÆÄÀÏÀÌ ´ë»ó È£½ºÆ®¿¡ Á¸ÀçÇÑ´Ù¸é ±× È£½ºÆ®´Â Ãë¾àÇÏ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/616.php |
| ÇØ°áÃ¥ |
´ÙÀ½ Sendmail consortium »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÃֽŠSendmail ¹öÀüÀ¸·Î ¾÷±×·¹À̵å Çϰųª ÀûÀýÇÑ ÆÐÄ¡¸¦ ¼³Ä¡ÇØ¾ß ÇÑ´Ù. ftp://ftp.cs.berkeley.edu/ucb/sendmail/ |
| °ü·Ã URL |
CVE-1999-0203,CVE-1999-0565 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|