English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 18039
À§Çèµµ 40
Æ÷Æ® 25
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMTP
»ó¼¼¼³¸í ÇØ´ç MS Exchange ¼­¹öÀÇ ¹öÀüÀº IMCÀÇ EHLO ÀÀ´ä¿¡ ¹öÆÛ ¿À¹öÇ÷οì Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù.
¸¶ÀÌÅ©·Î¼ÒÇÁÆ® Exchange ¼­¹ö´Â Exchange ¼­¹ö°¡ ¿ø°ÝÁöÀÇ SMTP ¼­¹öµé°ú Åë½ÅÇϴµ¥ ÇÊ¿äÇÑ Internet Mail Connector (IMC) ¶ó ºÒ¸®´Â ±¸¼º¿ä¼Ò¸¦ Æ÷ÇÔÇϰí ÀÖ´Ù. ÀÌ ±¸¼º¿ä¼Ò¿¡´Â Ãë¾àÁ¡ÀÌ ÀÖ¾î ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀÌ Æ¯Á¤ ¼³Á¤ ÇÏ¿¡ ÀÖ´Â Exchange ¼­¹öµé »óÀÇ ÀÓÀÇÀÇ Äڵ带 ¼öÇàÇÒ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù.
SMTP EHLO(Extended Hello) ¸í·ÉÀº SMTP ¼­¹ö°¡ Áö¿øÇÏ´Â SMTP ±â´É(operation)µéÀÇ ¸ñ·ÏÀ» ¾ò±â À§ÇØ ´Ù¸¥ ¼­¹ö¿¡ ÁúÀÇÇÒ ¶§ »ç¿ëÇÏ´Â ¸í·ÉÀ¸·Î, IMC ±¸¼º¿ä¼Ò´Â ÀÌ ¸í·É¿¡ ´ëÇÑ ÀÀ´äÀ¸·Î ´ÙÀ½°ú °°ÀÌ ½ÃÀÛÇÏ´Â Status Reply¸¦ ¹ÝȯÇÑ´Ù:
250-<Exchange server ID>Hello<Connecting server ID>

¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â ÀÚ½ÅÀÇ DNS ¼­¹ö¸¦ ÀÌ¿ëÇÏ¿© Reverse Lookup ÀÀ´äµéÀ» Á¶ÀÛÇϰųª ȤÀº DNS Spoofing ±â¹ýµéÀ» ÀÀ¿ëÇÏ¿© IMC°¡ ¹öÆÛ ¿À¹öÇ÷ο츦 ÀÏÀ¸Å³ ÀÀ´äÀ» »ý¼ºÇÏ°Ô À¯µµÇÒ ¼ö ÀÖ´Â Àß Á¶ÀÛµÈ EHLO ¸í·ÉÀ» º¸³¾ ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â ÀÌ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© Exchange¸¦ Å©·¡½¬(crash) ½ÃŰ°Å³ª Ãë¾àÇÑ ¼­¹ö¿¡ ´ëÇÑ ¿ÏÀüÇÑ Á¦¾î¸¦ ¾òÀ» ¼ö ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº ÀÌ Ãë¾àÁ¡À» Á¡°ËÇϱâ À§ÇØ ¿ø°ÝÁö SMTP ¼­¹öÀÇ ¹è³Ê¸¸À» ÂüÁ¶ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://online.securityfocus.com/bid/5306
http://www.microsoft.com/technet/security/bulletin/MS02-037.asp

Ãë¾àÇÑ Ç÷§Æû:
* Microsoft Exchange 5.5
ÇØ°áÃ¥ Àӽà Á¶Ä¡¹æ¹ýÀ¸·Î´Â MS»ç°¡ Á¦°øÇÏ´Â ¹®¼­ Áß Q1920026¿¡ Á¤ÀÇµÈ °Íó·³ ·¹Áö½ºÆ®¸® Ű °ªÀ» ¼³Á¤ÇÏ¿© EHLO ¸í·É¾î¿¡¼­ Reverse DNS lookupÀ» ÁßÁö½ÃÄÑ¾ß ÇÑ´Ù:
http://support.microsoft.com/default.aspx?scid=kb;EN-US;q190026

Reverse DNS lookupÀ» ÁßÁö½Ã۱â À§Çؼ­´Â:

1. ·¹Áö½ºÆ®¸® ÆíÁý±â(Regedt32.exe)¸¦ ½ÇÇàÇÑ´Ù.
2. ·¹Áö½ºÆ®¸® À§Ä¡ HKEY_LOCAL_MACHINE\System|CurrentControlSet\Services\MSExchangeIMC\Parameters\ ¿¡¼­ "DisableReverseResolve" º¯¼ö¸¦ ã´Â´Ù.
3. ÆíÁý ¸Þ´º¿¡¼­ 2Áø¼ö¸¦ ¼±ÅÃÇÑ ÈÄ '1'°ªÀ» ³Ö°í 'OK' ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
4. ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ Á¾·áÇÑ´Ù.

-- ¶Ç´Â --

¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½ÃÆÇ MS02-037 ·ÎºÎÅÍ Microsoft Exchange 5.5 Service Pack 4 ÀÌ»óÀ» ´Ù¿î¹Þ¾Æ ¼³Ä¡ÇØ¾ß ÇÑ´Ù:
http://www.microsoft.com/download/en/details.aspx?displaylang=en&id=15865
°ü·Ã URL CVE-2002-0698 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)