| Ãë¾àÁ¡ID |
18022 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
25 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
SMTP |
| »ó¼¼¼³¸í |
ÇØ´ç Sendmail ¼¹ö´Â ÀÓÀÇÀÇ ÆÄÀÏ·Î Á÷Á¢ ¸ÞÀÏÀÌ Àü¼ÛµÇ´Â °ÍÀ» Çã¿ëÇÑ´Ù. ÀϺΠSendmail ¼¹ö´Â ´ÙÀ½°ú °°ÀÌ "RCPT TO" ¼ö½Åó¿¡ Á÷Á¢ ÆÄÀÏ À̸§À» ¸í½ÃÇØ¼ ¸ÞÀÏÀ» Àü¼ÛÇÒ °æ¿ì Á¤»óÀûÀ¸·Î ¹Þ¾ÆµéÀδÙ.
MAIL FROM: root@domain.com RCPT TO: /tmp/secuiscan_test
À̰ÍÀº ÆÄÀÏ¿¡ Á÷Á¢ ¸ÞÀÏÀ» Àü¼ÛÇÏ´Â °ÍÀÌ °¡´ÉÇÏ´Ù´Â °ÍÀ» ÀǹÌÇÑ´Ù. ÀÌ °æ¿ì, °ø°ÝÀÚµéÀº SendmailÀ» ÅëÇØ¼ ¿ø°Ý ¼¹ö »ó¿¡ ÆÄÀÏÀ» »ý¼ºÇϰųª Áß¿äÇÑ ÆÄÀϵéÀ» µ¤¾î¾²´Â °ÍÀÌ °¡´ÉÇϱ⠶§¹®¿¡ ¸Å¿ì À§ÇèÇÏ´Ù.
¾Ë¸²: ÀÌ Á¡°Ë Ç׸ñÀº ÀϺΠMTA µéÀÌ ÀÌ Å×½ºÆ® ¸í·É¿¡ ´ëÇØ¼ Á¤»óÀûÀ¸·Î ¹Þ¾ÆµéÀ̱â´Â ÇÏÁö¸¸ ¸Þ½ÃÁö¸¦ ±×´ë·Î Æó±âÇϱ⠶§¹®¿¡ "False Positive" ÀÇ °¡´É¼ºµµ Á¸ÀçÇÑ´Ù. ÀÌ ½ºÄ³³Ê´Â /tmp µð·ºÅ丮¿¡ 'by_scanner.mailingtofiles.vulnerability'¶ó ºÒ¸®´Â ÆÄÀÏÀÇ »ý¼ºÀ» ½ÃµµÇÑ´Ù. ¸¸¾à ½ºÄµÀÌ ¿Ï·áµÈ ÈÄ ÀÌ ÆÄÀÏÀÌ ´ë»ó È£½ºÆ®¿¡ Á¸ÀçÇÑ´Ù¸é ±× È£½ºÆ®´Â Ãë¾àÇÏ´Ù.
* Âü°í »çÀÌÆ®: http://www.cert.org/advisories/CA-1995-08.html http://online.securityfocus.com/bid/2308 |
| ÇØ°áÃ¥ |
´ÙÀ½ Sendmail »çÀÌÆ®¸¦ ÂüÁ¶ÇÏ¿© ÃֽŠSendmail ¹öÀüÀ¸·Î ¾÷±×·¹À̵å Çϰųª ÇØ´ç MTA ¸¦ ±³Ã¼ÇØ¾ß ÇÑ´Ù. ftp://ftp.sendmail.org/pub/sendmail/ |
| °ü·Ã URL |
CVE-1999-0203 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|