English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 23017
À§Çèµµ 30
Æ÷Æ® 389
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù LDAP
»ó¼¼¼³¸í ÇØ´ç LDAP ¼­¹ö´Â ºÎÀûÀýÇÏ°Ô ¼³Á¤µÇ¾î ÀÖÀ¸¸ç Anonymous BIND¸¦ Çã¿ëÇϰí ÀÖ´Ù. NULL BIND ¿£Æ®¸®´Â ÀÓÀÇÀÇ »ç¿ëÀÚ°¡ Anonymous·Î LDAP µð·ºÅ丮¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. Attacker´Â LDAP µð·ºÅ丮¿¡ ÀÖ´Â ÆÄÀϵéÀ» À͸íÀÇ »ç¿ëÀÚ(NULL BIND)·Î Á¢¼ÓÇÏ¿© º¼ ¼ö ÀÖ°Ô µÈ´Ù.

* ¾Ë¸²: rootDSE °Ë»ö ¹× ¹ÙÀεùÀÌ ¾Æ´Ñ Active Directory¿¡ ´ëÇÑ À͸í LDAP(Lightweight Directory Access Protocol) ÀÛ¾÷ÀÌ Microsoft Windows Server 2003¿¡¼­ ±âº»ÀûÀ¸·Î Çã¿ëµÇÁö ¾Ê½À´Ï´Ù.
http://support.microsoft.com/kb/326690/

LDAP V3 ¿¡¼­´Â rootdse °Ë»öÀ» À§ÇØ anonymous/NULL ¸¦ disable ÇÒ¼ö¾ø½À´Ï´Ù.
http://tools.ietf.org/html/rfc2251

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/1424.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
LDAP Server
ÇØ°áÃ¥ NULL BIND ¿£Æ®¸®¸¦ Disable ½ÃŰ°Å³ª Á¢±ÙÁ¦¾î (ACL)¸¦ ÅëÇØ ¿£Æ®¸®¸¦ Á¦¾îÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)