| Ãë¾àÁ¡ID |
23016 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
389 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
LDAP |
| »ó¼¼¼³¸í |
ÇØ´ç LDAP ¼¹ö´Â ºÎÀûÀýÇÏ°Ô ¼³Á¤µÇ¾î ÀÖÀ¸¸ç Anonymous BASE¸¦ Çã¿ë (µð·ºÅ丮 BASE°¡ NULL·Î ¼ÂµÇ¾î ÀÖÀ½)Çϰí ÀÖ´Ù. LDAPÀÌ LDAP °Ë»ö¿¡¼ NULL base¸¦ Çã¿ëÇØ ÁÖ¸é ÀÓÀÇÀÇ »ç¿ëÀÚ°¡ namingContexts¿¡ ÀÖ´Â Á¤º¸¿Í Áö¿øµÇ´Â ÄÁÆ®·Ñµé¿¡ ´ëÇÑ °Ë»öÀ» ÇØ º¼ ¼ö ÀÖ°Ô µÈ´Ù. Attacker´Â ÀÌ Á¤º¸¸¦ »ç¿ëÇÏ¿© µð·ºÅ丮 ¸®½ºÆÃ°ú °°Àº ¾ÇÀÇÀûÀÎ ÇàÀ§¸¦ ÇÒ ¼ö ÀÖ´Ù. NULL BINDµµ Çã¿ëÇϰí ÀÖ´Ù¸é Anonymous »ç¿ëÀÚ´Â 'LdapMiner'¿Í °°Àº ÅøÀ» ÀÌ¿ëÇÏ¿© LDAP ¼¹ö¿¡°Ô ÁúÀǸ¦ º¸³¾ ¼ö ÀÖ´Ù.
* ¾Ë¸²: rootDSE °Ë»ö ¹× ¹ÙÀεùÀÌ ¾Æ´Ñ Active Directory¿¡ ´ëÇÑ À͸í LDAP(Lightweight Directory Access Protocol) ÀÛ¾÷ÀÌ Microsoft Windows Server 2003¿¡¼ ±âº»ÀûÀ¸·Î Çã¿ëµÇÁö ¾Ê½À´Ï´Ù. http://support.microsoft.com/kb/326690/
LDAP V3 ¿¡¼´Â rootdse °Ë»öÀ» À§ÇØ anonymous/NULL ¸¦ disable ÇÒ¼ö¾ø½À´Ï´Ù. http://tools.ietf.org/html/rfc2251
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/1425.php ftp://ftp.isi.edu/in-notes/rfc2251.txt ftp://ftp.isi.edu/in-notes/rfc2820.txt
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: LDAP Server |
| ÇØ°áÃ¥ |
ÇØ´ç LDAP ¼¹ö»ó¿¡¼ NULL BASE ÁúÀǵéÀ» Disable ½ÃÄÑ¾ß ÇÑ´Ù. ±×¸®°í »ç¿ëÀÚµéÀÌ TreeÀÇ Base¸¦ Dump Çϰųª BaseÀÇ Object¿¡ ´ëÇÑ Áö½Ä¾øÀÌ ¿äûÀ» º¸³»´Â °ÍÀ» ¹æÁöÇϱâ À§ÇØ Á¢±ÙÁ¦¾î(ACL)¸¦ »ç¿ëÇÏ¿©¾ß ÇÑ´Ù.
Windows Ç÷§ÆûµéÀÇ °æ¿ì: "pre-Windows 2000 compatibility"°¡ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ´ÙÀ½°ú °°ÀÌ Á¦°ÅÇÏ¸é µÈ´Ù:
1. cmd.exe¸¦ ½ÃÀÛÇÑ´Ù. (Windows ½Ã½ºÅÛ ½ÃÀÛ ¸Þ´º¿¡¼, ½ÇÇà ¼±ÅÃ, cmd.exe¸¦ ŸÀÌÇÎÇϰí È®ÀÎÀ» Ŭ¸¯ÇÑ´Ù.) 2. ´ÙÀ½ ¸í·ÉÀ» ŸÀÌÇÎÇÏ°í ¿£ÅÍ Å°¸¦ ´©¸¥´Ù: net localgroup 'Pre-Windows 2000 Compatible Access' everyone /delete 3. È£½ºÆ®¸¦ Àç½ÃÀÛ ÇÑ´Ù.
NetWare Ç÷§ÆûµéÀÇ °æ¿ì: ´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¿© ÇÊ¿äÇÏÁö ¾Ê´Ù¸é LDAP¿¡¼ À͸í Bind(anonymous bind)¸¦ ÀÛµ¿ÁßÁö ȤÀº Á¦ÇÑÇÑ´Ù: http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=3932155&sliceId=1&docTypeID=DT_TID_1_1&dialogID=6288673&stateId=0 0 6292116
±âŸ: ÇØ´ç Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ÀÌ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|