English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 22386
À§Çèµµ 30
Æ÷Æ® 80, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SSL
»ó¼¼¼³¸í ÇØ´ç SSL ¼­¹ö´Â SSLv2¸¦ ÀÌ¿ëÇÑ ¾ÏȣȭµÈ Á¢¼ÓµéÀ» ¼ö¿ëÇÑ´Ù. SSL (Secure Sockets Layer)Àº ÀÎÅÍ³Ý »ó¿¡¼­ Ŭ¶óÀ̾ðÆ®¿Í ¼­¹ö °£¿¡ ¾ÏȣȭµÈ Åë½ÅÀ» Á¦°øÇÏ´Â µ¥ º¸ÆíÀûÀ¸·Î »ç¿ëµÇ´Â ÇÁ·ÎÅäÄÝÀÌ´Ù. º¸°í¿¡ µû¸£¸é SSLv2 ÇÁ·ÎÅäÄÝÀº ´Ù¼öÀÇ ¾ÏÈ£ ±â¹ý »óÀÇ °áÇÔµéÀ» °¡Áö°í ÀÖ´Ù. °ø°ÝÀÚ´Â ÀÌ °áÇÔµéÀ» µµ¿ëÇÏ¿© man-in-the-middle °ø°ÝµéÀ» ¼öÇàÇϰųª ¾ÏȣȭµÈ Åë½ÅµéÀ» ÀÐ¾î ³»°Å³ª ¾ÇÀÇÀûÀ¸·Î ¸Þ½ÃÁöµéÀ» Á¶ÀÛÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.schneier.com/paper-ssl.pdf

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
¸ðµç ¿î¿µÃ¼Á¦ ¸ðµç ¹öÀü
ÇØ°áÃ¥ SSL 2.0À» »ç¿ë ÁßÁöÇÏ°í ´ë½Å SSL 3.0 ȤÀº TLS 1.0À» »ç¿ëÇÔÀ¸·Î½á, ÀÌ Ãë¾àÁ¡°ú °ü·ÃÇÑ À§ÇèÀÇ ¹ß»ý °¡´É¼ºÀ» Á¦°ÅÇÑ´Ù.

Sun Java (Netscape Enterprise) Web Server¿Í Application ServerÀÇ °æ¿ì:
´ÙÀ½ Sun Alert ID: 57632¸¦ ÂüÁ¶ÇÏ¿© °ü¸® ¼­¹ö¸¦ ÅëÇØ SSLv2¸¦ »ç¿ë ÁßÁö½ÃŲ´Ù:
http://download.oracle.com/sunalerts/1001203.1.html

Apache À¥ ¼­¹öÀÇ °æ¿ì:
ÀüÇüÀûÀ¸·Î Apache/mod_ssl, httpd.conf ȤÀº ssl.conf ÆÄÀϵéÀÌ ´ÙÀ½ ¶óÀεéÀ» °¡Áöµµ·Ï ÇÑ´Ù:
SSLProtocol -ALL +SSLv3 +TLSv1
SSLCipherSuite ALL:!aNULL:!ADH:!eNULL:!LOW:!EXP:RC4+RSA:+HIGH:+MEDIUM

Microsoft IISÀÇ °æ¿ì:
IIS°¡ SSL 2.0 ÇÁ·ÎÅäÄÝÀ» ÀÌ¿ëÇÏ¿© Åë½ÅÇÏÁö ¾Êµµ·Ï SSL 2.0 ÇÁ·ÎÅäÄÝÀ» »ç¿ë ÁßÁö½ÃÅ°±â À§Çؼ­´Â ´ÙÀ½ ´Ü°è¸¦ µû¸¥´Ù:
1. "½ÃÀÛ"À» Ŭ¸¯ÇÏ°í "½ÇÇà"À» Ŭ¸¯ÇÑ ´ÙÀ½, regedt32 ȤÀº regedit¸¦ ŸÀÌÇÎÇÑ ÈÄ "È®ÀÎ"À» ŸÀÌÇÎÇÑ´Ù.
2. ·¹Áö½ºÆ®¸® ÆíÁý±â¿¡¼­ ´ÙÀ½ ·¹Áö½ºÆ®¸® Å°·Î À̵¿ÇÑ´Ù:
HKey_Local_Machine\System\CurrentControlSet\Control\SecurityProviders\SCHANNEL\Protocols\SSL 2.0\Server
3. ÆíÁý ¸Þ´º¿¡¼­ "°ª Ãß°¡"¸¦ Ŭ¸¯ÇÑ´Ù.
4. "µ¥ÀÌÅÍ Çü½Ä" ¸ñ·Ï¿¡¼­ DWORD¸¦ Ŭ¸¯ÇÑ´Ù.
5. "°ª À̸§" ¹Ú½º¿¡ "Enabled"¸¦ ŸÀÌÇÎÇÏ°í "È®ÀÎ"À» Ŭ¸¯ÇÑ´Ù.
6. »õ·Î¿î Å°ÀÇ °ªÀ» "0"À¸·Î ¼³Á¤Çϱâ À§ÇØ ÀÌÁø ÆíÁý±â¿¡ 00000000À» ŸÀÌÇÎÇÑ´Ù.
7. "È®ÀÎ"À» Ŭ¸¯ÇÏ°í ÄÄÇ»Å͸¦ Àç½ÃÀÛÇÑ´Ù.

±âŸ:
ÇØ´ç Á¦Á¶¾÷ü¿¡ ¹®ÀÇÇÏ¿© ¾÷±×·¹À̵峪 ÆÐÄ¡ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)