English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 19001
À§Çèµµ 30
Æ÷Æ® 53
ÇÁ·ÎÅäÄÝ TCP,UDP
ºÐ·ù DNS
»ó¼¼¼³¸í ÇØ´ç ³×ÀÓ ¼­¹ö´Â DNS zone transfer¸¦ Á¦ÇѾøÀÌ Çã¿ëÇϰí ÀÖ´Ù. DNS Zone Tranfer¿¡´Â DNS ¼­¹ö¿¡ µî·ÏµÈ ¸ðµç ÄÄÇ»Å͸¦ ½Äº°ÇÒ ¼ö ÀÖ´Â ¸®½ºÆ®¸¦ Æ÷ÇÔÇϰí ÀÖ´Ù. ÀÌ Á¤º¸´Â Attacker°¡ °ø°Ý¿¡ ¾Õ¼­ ³×Æ®¿öÅ©ÀÇ ±¸¼º°ú »õ·Î¿î ¸ñÇ¥¸¦ Á¤Çϴµ¥ ÀÖ¾î ¸Å¿ì À¯¿ëÇÑ Á¤º¸°¡ µÇ¾îÁØ´Ù. ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® DNS ¼­¹ö´Â µðÆúÆ®·Î ¾î¶² È£½ºÆ®·Î ºÎÅÍ »ý¼ºµÈ zone transfer ¿äûÀ» Çã¿ëÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/3678.php
http://www.iss.net/security_center/static/212.php
http://www.acmebw.com/resources/papers/securing.pdf

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
DNS Any version
ÇØ°áÃ¥ ¹Ýµå½Ã ÇÊ¿äÇÑ ¼­¹öµé¸¸ DNS zone transfer¸¦ Çã¿ëÇϵµ·Ï ÇØ´ç DNS ¼­¹öÀÇ ¼³Á¤À» Á¶Á¤ÇØ¾ß ÇÑ´Ù.

1. Windows ½Ã½ºÅÛµé

¸¶ÀÌÅ©·Î¼ÒÇÁÆ® DNS¼­¹ö¿¡ Primary DNS zoneÀ» »ý¼ºÇÒ ¶§ µðÆúÆ® zone transfer ¿É¼ÇÀº "allowed to any server"·Î ¼ÂµÇ¾î ÀÖ´Ù. ±× µðÆúÆ® ¼¼ÆÃÀº Àΰ¡µÇÁö ¾ÊÀº ½Ã½ºÅ۵鿡°Ô DNS zone Á¤º¸ÀÇ ³ëÃâÀÌ ³ëÃâµÇÁö ¾Êµµ·Ï ¹Ýµå½Ã ¼öÁ¤µÇ¾îÁ®¾ß ÇÑ´Ù. ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® dnsmgmt.msc °ü¸® ÄÜ¼Ö ÅøÀ» ÀÌ¿ëÇϸé DNS ¼­¹ö°¡ zone transfer ¿äûµéÀ» ¹Þ¾ÆÁ٠ȣ½ºÆ®µéÀÇ ¸®½ºÆ®¸¦ ¸í±âÇÒ ¼ö ÀÖ´Ù.

2. UNIX ½Ã½ºÅÛµé

1) BIND 8¿¡¼­´Â, 'allow-transfer' ¹®ÀåÀ» »ç¿ë

options {
allow-transfer { x.x.x.x };
};

ȤÀº, ZoneÀ» ¸í±â:

zone "secui.com" {
type master;
file "db.secui.com";
allow-transfer { x.x.x.x };
};

2) BIND 4.9¿¡¼­´Â 'xfrnets' ¹®ÀåÀ» »ç¿ë
xfrnets 210.168.119.178&255.255.255.255
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)