| Ãë¾àÁ¡ID |
23018 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
389 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
LDAP |
| »ó¼¼¼³¸í |
ÇØ´ç LDAP ¼¹ö´Â ¿ø°ÝÁöÀÇ »ç¿ëÀÚ¿¡°Ô LDAP ¼³Á¤ Á¤º¸¸¦ º¼ ¼ö ÀÖµµ·Ï ÇØÁØ´Ù. ÀÌ ¼³Á¤ Á¤º¸´Â ¾î¶² Á¾·ùÀÇ ¹é¿£µå(backend, LDAP Ŭ¶óÀ̾ðÆ®)°¡ »ç¿ëµÇ°í ÀÖ´ÂÁö¸¦ Æ÷ÇÔÇϰí ÀÖ¾î ³ëÃâµÉ ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â ÀÌ Á¤º¸¸¦ ÀÌ¿ëÇÏ¿© µð·ºÅ丮 ¸®½ºÆÃÀ» °¡Á®°¥ ¼ö ÀÖÀ¸¸ç ´Ù¸¥ °ø°ÝµéÀ» À§ÇÑ ÁÁÀº Á¤º¸·Î Ȱ¿ëÇÒ ¼öµµ ÀÖ´Ù. LDAP (Lightweight Directory Access Protocol)Àº X.500 ¸ðµ¨À» Áö¿øÇÏ´Â µð·ºÅ丮 ¼ºñ½º¸¦ À§ÇØ Áß¼Ò±Ô¸ð¿ëÀÇ ¾×¼¼½º ÇÁ·ÎÅäÄÝ·Î µðÀÚÀεǾúÀ¸¸ç, µð·ºÅ丮 ³»¿ëÀÇ °Ë»ö, ÃßÃ⠱׸®°í Á¶ÀÛÀ» À§ÇÑ ¼ö´ÜÀ» Á¦°øÇÑ´Ù.
* ¾Ë¸²: ÇØ´ç LDAP¼¹ö°¡ anonymous/NULLÀ» Çã¿ëÇÒ °æ¿ì ÀÌÃë¾àÁ¡ÀÌ ¹ß°ßµÉ¼ö ÀÖ½À´Ï´Ù.
rootDSE °Ë»ö ¹× ¹ÙÀεùÀÌ ¾Æ´Ñ Active Directory¿¡ ´ëÇÑ À͸í LDAP(Lightweight Directory Access Protocol) ÀÛ¾÷ÀÌ Microsoft Windows Server 2003¿¡¼ ±âº»ÀûÀ¸·Î Çã¿ëµÇÁö ¾Ê½À´Ï´Ù. http://support.microsoft.com/kb/326690/
LDAP V3 ¿¡¼´Â rootdse °Ë»öÀ» À§ÇØ anonymous/NULL ¸¦ disable ÇÒ¼ö¾ø½À´Ï´Ù. http://tools.ietf.org/html/rfc2251
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/1421.php
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: LDAP Server |
| ÇØ°áÃ¥ |
cn=config ¿£Æ®¸®¸¦ Disable ½ÃŰ°Å³ª, ÀÌ ¿£Æ®¸®¸¦ ÀÎÁõµÈ »ç¿ëÀڵ鸸ÀÌ º¼ ¼ö ÀÖµµ·Ï ¼³Á¤ÇØ¾ß ÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|