Ãë¾àÁ¡ID |
22386 |
À§Çèµµ |
30 |
Æ÷Æ® |
80, ... |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
SSL |
»ó¼¼¼³¸í |
ÇØ´ç SSL ¼¹ö´Â SSLv2¸¦ ÀÌ¿ëÇÑ ¾ÏÈ£ÈµÈ Á¢¼ÓµéÀ» ¼ö¿ëÇÑ´Ù. SSL (Secure Sockets Layer)Àº ÀÎÅÍ³Ý »ó¿¡¼ Ŭ¶óÀ̾ðÆ®¿Í ¼¹ö °£¿¡ ¾ÏÈ£ÈµÈ Åë½ÅÀ» Á¦°øÇÏ´Â µ¥ º¸ÆíÀûÀ¸·Î »ç¿ëµÇ´Â ÇÁ·ÎÅäÄÝÀÌ´Ù. º¸°í¿¡ µû¸£¸é SSLv2 ÇÁ·ÎÅäÄÝÀº ´Ù¼öÀÇ ¾ÏÈ£ ±â¹ý »óÀÇ °áÇÔµéÀ» °¡Áö°í ÀÖ´Ù. °ø°ÝÀÚ´Â ÀÌ °áÇÔµéÀ» µµ¿ëÇÏ¿© man-in-the-middle °ø°ÝµéÀ» ¼öÇàÇϰųª ¾ÏÈ£ÈµÈ Åë½ÅµéÀ» ÀÐ¾î ³»°Å³ª ¾ÇÀÇÀûÀ¸·Î ¸Þ½ÃÁöµéÀ» Á¶ÀÛÇÒ ¼ö ÀÖ´Ù. * Âü°í »çÀÌÆ®: http://www.schneier.com/paper-ssl.pdf
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: ¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü |
ÇØ°áÃ¥ |
SSL 2.0À» »ç¿ë ÁßÁöÇÏ°í ´ë½Å SSL 3.0 ȤÀº TLS 1.0À» »ç¿ëÇÔÀ¸·Î½á, ÀÌ Ãë¾àÁ¡°ú °ü·ÃÇÑ À§ÇèÀÇ ¹ß»ý °¡´É¼ºÀ» Á¦°ÅÇÑ´Ù.
Sun Java (Netscape Enterprise) Web Server¿Í Application ServerÀÇ °æ¿ì: ´ÙÀ½ Sun Alert ID: 57632¸¦ ÂüÁ¶ÇÏ¿© °ü¸® ¼¹ö¸¦ ÅëÇØ SSLv2¸¦ »ç¿ë ÁßÁö½ÃŲ´Ù: http://download.oracle.com/sunalerts/1001203.1.html
Apache À¥ ¼¹öÀÇ °æ¿ì: ÀüÇüÀûÀ¸·Î Apache/mod_ssl, httpd.conf ȤÀº ssl.conf ÆÄÀϵéÀÌ ´ÙÀ½ ¶óÀεéÀ» °¡Áöµµ·Ï ÇÑ´Ù: SSLProtocol -ALL +SSLv3 +TLSv1 SSLCipherSuite ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM
Microsoft IISÀÇ °æ¿ì: IIS°¡ SSL 2.0 ÇÁ·ÎÅäÄÝÀ» ÀÌ¿ëÇÏ¿© Åë½ÅÇÏÁö ¾Êµµ·Ï SSL 2.0 ÇÁ·ÎÅäÄÝÀ» »ç¿ë ÁßÁö½ÃÅ°±â À§Çؼ´Â ´ÙÀ½ ´Ü°è¸¦ µû¸¥´Ù: 1. "½ÃÀÛ"À» Ŭ¸¯ÇÏ°í "½ÇÇà"À» Ŭ¸¯ÇÑ ´ÙÀ½, regedt32 ȤÀº regedit¸¦ ŸÀÌÇÎÇÑ ÈÄ "È®ÀÎ"À» ŸÀÌÇÎÇÑ´Ù. 2. ·¹Áö½ºÆ®¸® ÆíÁý±â¿¡¼ ´ÙÀ½ ·¹Áö½ºÆ®¸® Å°·Î À̵¿ÇÑ´Ù: HKey_Local_Machine\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server 3. ÆíÁý ¸Þ´º¿¡¼ "°ª Ãß°¡"¸¦ Ŭ¸¯ÇÑ´Ù. 4. "µ¥ÀÌÅÍ Çü½Ä" ¸ñ·Ï¿¡¼ DWORD¸¦ Ŭ¸¯ÇÑ´Ù. 5. "°ª À̸§" ¹Ú½º¿¡ "Enabled"¸¦ ŸÀÌÇÎÇÏ°í "È®ÀÎ"À» Ŭ¸¯ÇÑ´Ù. 6. »õ·Î¿î Å°ÀÇ °ªÀ» "0"À¸·Î ¼³Á¤Çϱâ À§ÇØ ÀÌÁø ÆíÁý±â¿¡ 00000000À» ŸÀÌÇÎÇÑ´Ù. 7. "È®ÀÎ"À» Ŭ¸¯ÇÏ°í ÄÄÇ»Å͸¦ Àç½ÃÀÛÇÑ´Ù.
±âŸ: ÇØ´ç Á¦Á¶¾÷ü¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù. |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|