English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23003
À§Çèµµ 40
Æ÷Æ® 517,518
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù TALKD
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â talkd µ¥¸óÀÌ ÀÛµ¿ ÁßÀÌ´Ù.
Talkd µ¥¸óÀº ¼­·Î ´Ù¸¥ Å͹̳Π»çÀÌ ¶Ç´Â ¼­·Î ´Ù¸¥ ¿ø°ÝÁöÀÇ ½Ã½ºÅÛ »çÀÌ¿¡¼­ "talk" ¸í·É¾î¸¦ ÅëÇÑ ´ëÈ­(talk conversation) ¼­ºñ½º¸¦ Á¦°øÇÏ´Â ÇÁ·Î±×·¥ÀÌ´Ù.
Talkd µ¥¸óÀº ¾ÇÀÇÀûÀÎ »ç¿ëÀÚµéÀÌ ½ÅºÐÀ» À§ÀåÇÑ Ã¤ ´ëÈ­¸¦ ÇÏ´Â ¹æ¹ý(social engineering)À¸·Î ÇÕ¹ýÀûÀÎ »ç¿ëµéÀ» ¼Ó¿© ÀǵµÇÑ °á°ú¸¦ ¾ò´Âµ¥ À̸¦ »ç¿ëÇÒ ¼ö ÀÖ´Â Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Ù. ¶ÇÇÑ talkdÀÇ °ú°Å ¸î¸î ¹öÀüµé¿¡ ÀÖ´Â º¸¾È °áÇÔÀº talk Á¢¼Ó °úÁ¤ Áß¿¡¼­ È£½ºÆ®¸íÀÌ ÀúÀåµÇ¾î ÀÖ´Â ¹öÆÛ¿¡ ´ëÇÑ ºÒÃæºÐÇÑ °æ°è üŷÀ¸·Î ÀÎÇØ talkd¸¦ ÀÌ¿ëÇÏ¿© ÀÓÀÇÀÇ ¸í·ÉµéÀ» ¼öÇàÇÒ ¼öµµ ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.cert.org/advisories/CA-1997-04.html
http://www.iss.net/security_center/static/2988.php
ÇØ°áÃ¥ ÇÊ¿äÇÏÁö ¾ÊÀ¸¸é °¡µ¿À» Á߽ýÃŲ´Ù.

1. /etc/inetd.conf ÆÄÀÏ¿¡¼­ ¼­ºñ½º À̸§À» ÁÖ¼® ó¸®ÇÑ´Ù.

# grep -i talk /etc/inetd.conf
talk dgram udp wait root /usr/etc/in.talkd in.talkd
=> #talk dgram udp wait root /usr/etc/in.talkd in.talkd

2. HUP ½ÅÈ£¸¦ Àü´ÞÇÏ¿© inetd ´ë¸óÀ» Àç°¡µ¿ÇÑ´Ù.

* SYSV :
# ps -ef | grep inetd | grep -v grep
# kill -HUP {inetd PID}
* BSD :
# ps -aux | grep inetd | grep -v grep
# kill -HUP {inetd PID}


--- ¶Ç´Â ---


¹æÈ­º®¿¡ ÀûÀýÇÑ ±ÔÄ¢À» Àû¿ëÇÏ¿© talkd ¼­ºñ½ºÀÇ Á¢±ÙÀ» Â÷´ÜÇØ¾ß ÇÑ´Ù.
°ü·Ã URL CVE-1999-0048 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)