English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23016
À§Çèµµ 30
Æ÷Æ® 389
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù LDAP
»ó¼¼¼³¸í ÇØ´ç LDAP ¼­¹ö´Â ºÎÀûÀýÇÏ°Ô ¼³Á¤µÇ¾î ÀÖÀ¸¸ç Anonymous BASE¸¦ Çã¿ë (µð·ºÅ丮 BASE°¡ NULL·Î ¼ÂµÇ¾î ÀÖÀ½)Çϰí ÀÖ´Ù. LDAPÀÌ LDAP °Ë»ö¿¡¼­ NULL base¸¦ Çã¿ëÇØ ÁÖ¸é ÀÓÀÇÀÇ »ç¿ëÀÚ°¡ namingContexts¿¡ ÀÖ´Â Á¤º¸¿Í Áö¿øµÇ´Â ÄÁÆ®·Ñµé¿¡ ´ëÇÑ °Ë»öÀ» ÇØ º¼ ¼ö ÀÖ°Ô µÈ´Ù. Attacker´Â ÀÌ Á¤º¸¸¦ »ç¿ëÇÏ¿© µð·ºÅ丮 ¸®½ºÆÃ°ú °°Àº ¾ÇÀÇÀûÀÎ ÇàÀ§¸¦ ÇÒ ¼ö ÀÖ´Ù. NULL BINDµµ Çã¿ëÇϰí ÀÖ´Ù¸é Anonymous »ç¿ëÀÚ´Â 'LdapMiner'¿Í °°Àº ÅøÀ» ÀÌ¿ëÇÏ¿© LDAP ¼­¹ö¿¡°Ô ÁúÀǸ¦ º¸³¾ ¼ö ÀÖ´Ù.

* ¾Ë¸²: rootDSE °Ë»ö ¹× ¹ÙÀεùÀÌ ¾Æ´Ñ Active Directory¿¡ ´ëÇÑ À͸í LDAP(Lightweight Directory Access Protocol) ÀÛ¾÷ÀÌ Microsoft Windows Server 2003¿¡¼­ ±âº»ÀûÀ¸·Î Çã¿ëµÇÁö ¾Ê½À´Ï´Ù.
http://support.microsoft.com/kb/326690/

LDAP V3 ¿¡¼­´Â rootdse °Ë»öÀ» À§ÇØ anonymous/NULL ¸¦ disable ÇÒ¼ö¾ø½À´Ï´Ù.
http://tools.ietf.org/html/rfc2251

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/1425.php
ftp://ftp.isi.edu/in-notes/rfc2251.txt
ftp://ftp.isi.edu/in-notes/rfc2820.txt

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
LDAP Server
ÇØ°áÃ¥ ÇØ´ç LDAP ¼­¹ö»ó¿¡¼­ NULL BASE ÁúÀǵéÀ» Disable ½ÃÄÑ¾ß ÇÑ´Ù. ±×¸®°í »ç¿ëÀÚµéÀÌ TreeÀÇ Base¸¦ Dump Çϰųª BaseÀÇ Object¿¡ ´ëÇÑ Áö½Ä¾øÀÌ ¿äûÀ» º¸³»´Â °ÍÀ» ¹æÁöÇϱâ À§ÇØ Á¢±ÙÁ¦¾î(ACL)¸¦ »ç¿ëÇÏ¿©¾ß ÇÑ´Ù.

Windows Ç÷§ÆûµéÀÇ °æ¿ì:
"pre-Windows 2000 compatibility"°¡ ÇÊ¿äÇÏÁö ¾Ê´Ù¸é ´ÙÀ½°ú °°ÀÌ Á¦°ÅÇÏ¸é µÈ´Ù:

1. cmd.exe¸¦ ½ÃÀÛÇÑ´Ù. (Windows ½Ã½ºÅÛ ½ÃÀÛ ¸Þ´º¿¡¼­, ½ÇÇà ¼±ÅÃ, cmd.exe¸¦ ŸÀÌÇÎÇϰí È®ÀÎÀ» Ŭ¸¯ÇÑ´Ù.)
2. ´ÙÀ½ ¸í·ÉÀ» ŸÀÌÇÎÇÏ°í ¿£ÅÍ Å°¸¦ ´©¸¥´Ù:
net localgroup 'Pre-Windows 2000 Compatible Access' everyone /delete
3. È£½ºÆ®¸¦ Àç½ÃÀÛ ÇÑ´Ù.

NetWare Ç÷§ÆûµéÀÇ °æ¿ì:
´ÙÀ½ »çÀÌÆ®¸¦ Âü°íÇÏ¿© ÇÊ¿äÇÏÁö ¾Ê´Ù¸é LDAP¿¡¼­ À͸í Bind(anonymous bind)¸¦ ÀÛµ¿ÁßÁö ȤÀº Á¦ÇÑÇÑ´Ù:
http://www.novell.com/support/search.do?cmd=displayKC&docType=kc&externalId=3932155&sliceId=1&docTypeID=DT_TID_1_1&dialogID=6288673&stateId=0 0 6292116

±âŸ:
ÇØ´ç Á¦Á¶»ç¿¡ ¹®ÀÇÇÏ¿© ÀÌ Á¤º¸¿¡ ´ëÇØ ¾Ë¾Æº»´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)