| Ãë¾àÁ¡ID |
18039 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
25 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
SMTP |
| »ó¼¼¼³¸í |
ÇØ´ç MS Exchange ¼¹öÀÇ ¹öÀüÀº IMCÀÇ EHLO ÀÀ´ä¿¡ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® Exchange ¼¹ö´Â Exchange ¼¹ö°¡ ¿ø°ÝÁöÀÇ SMTP ¼¹öµé°ú Åë½ÅÇϴµ¥ ÇÊ¿äÇÑ Internet Mail Connector (IMC) ¶ó ºÒ¸®´Â ±¸¼º¿ä¼Ò¸¦ Æ÷ÇÔÇϰí ÀÖ´Ù. ÀÌ ±¸¼º¿ä¼Ò¿¡´Â Ãë¾àÁ¡ÀÌ ÀÖ¾î ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ Æ¯Á¤ ¼³Á¤ ÇÏ¿¡ ÀÖ´Â Exchange ¼¹öµé »óÀÇ ÀÓÀÇÀÇ Äڵ带 ¼öÇàÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. SMTP EHLO(Extended Hello) ¸í·ÉÀº SMTP ¼¹ö°¡ Áö¿øÇÏ´Â SMTP ±â´É(operation)µéÀÇ ¸ñ·ÏÀ» ¾ò±â À§ÇØ ´Ù¸¥ ¼¹ö¿¡ ÁúÀÇÇÒ ¶§ »ç¿ëÇÏ´Â ¸í·ÉÀ¸·Î, IMC ±¸¼º¿ä¼Ò´Â ÀÌ ¸í·É¿¡ ´ëÇÑ ÀÀ´äÀ¸·Î ´ÙÀ½°ú °°ÀÌ ½ÃÀÛÇÏ´Â Status Reply¸¦ ¹ÝȯÇÑ´Ù: 250-<Exchange server ID>Hello<Connecting server ID>
¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÚ½ÅÀÇ DNS ¼¹ö¸¦ ÀÌ¿ëÇÏ¿© Reverse Lookup ÀÀ´äµéÀ» Á¶ÀÛÇϰųª ȤÀº DNS Spoofing ±â¹ýµéÀ» ÀÀ¿ëÇÏ¿© IMC°¡ ¹öÆÛ ¿À¹öÇ÷ο츦 ÀÏÀ¸Å³ ÀÀ´äÀ» »ý¼ºÇÏ°Ô À¯µµÇÒ ¼ö ÀÖ´Â Àß Á¶ÀÛµÈ EHLO ¸í·ÉÀ» º¸³¾ ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© Exchange¸¦ Å©·¡½¬(crash) ½ÃŰ°Å³ª Ãë¾àÇÑ ¼¹ö¿¡ ´ëÇÑ ¿ÏÀüÇÑ Á¦¾î¸¦ ¾òÀ» ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ¿ø°ÝÁö SMTP ¼¹öÀÇ ¹è³Ê¸¸À» ÂüÁ¶ÇÑ´Ù.
* Âü°í »çÀÌÆ®: http://online.securityfocus.com/bid/5306 http://www.microsoft.com/technet/security/bulletin/MS02-037.asp
Ãë¾àÇÑ Ç÷§Æû: * Microsoft Exchange 5.5 |
| ÇØ°áÃ¥ |
Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â MS»ç°¡ Á¦°øÇÏ´Â ¹®¼ Áß Q1920026¿¡ Á¤ÀÇµÈ °Íó·³ ·¹Áö½ºÆ®¸® Ű °ªÀ» ¼³Á¤ÇÏ¿© EHLO ¸í·É¾î¿¡¼ Reverse DNS lookupÀ» ÁßÁö½ÃÄÑ¾ß ÇÑ´Ù: http://support.microsoft.com/default.aspx?scid=kb;EN-US;q190026
Reverse DNS lookupÀ» ÁßÁö½Ã۱â À§Çؼ´Â:
1. ·¹Áö½ºÆ®¸® ÆíÁý±â(Regedt32.exe)¸¦ ½ÇÇàÇÑ´Ù. 2. ·¹Áö½ºÆ®¸® À§Ä¡ HKEY_LOCAL_MACHINE\System|CurrentControlSet\Services\MSExchangeIMC\Parameters\ ¿¡¼ "DisableReverseResolve" º¯¼ö¸¦ ã´Â´Ù. 3. ÆíÁý ¸Þ´º¿¡¼ 2Áø¼ö¸¦ ¼±ÅÃÇÑ ÈÄ '1'°ªÀ» ³Ö°í 'OK' ¹öưÀ» Ŭ¸¯ÇÑ´Ù. 4. ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ Á¾·áÇÑ´Ù.
-- ¶Ç´Â --
¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½ÃÆÇ MS02-037 ·ÎºÎÅÍ Microsoft Exchange 5.5 Service Pack 4 ÀÌ»óÀ» ´Ù¿î¹Þ¾Æ ¼³Ä¡ÇØ¾ß ÇÑ´Ù: http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=15865 |
| °ü·Ã URL |
CVE-2002-0698 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|