| Ãë¾àÁ¡ID |
25002 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
1521 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
DB |
| »ó¼¼¼³¸í |
ÇØ´ç È£½ºÆ®¿¡ Oracle tnslsnr°¡ °¡µ¿µÇ°í ÀÖ´Ù. TNS listener (tnslsnr)´Â µ¥ÀÌÅͺ£À̽º Ŭ¶óÀÌ¾ðÆ®¿Í ¼¹ö°£ÀÇ ³×Æ®¿öÅ© ÀÎÅÍÆäÀ̽ºÀÌ´Ù. tnslsnr´Â 1521/tcp Æ÷Æ®¸¦ »ç¿ëÇÏÁö¸¸ DBA°¡ À̸¦ º¯°æÇÒ ¼öµµ ÀÖ´Ù. ¸ðµç Ç÷§Æû »óÀÇ Oracle ¸±¸®Áî 7.3.4, 8.0.6, ±×¸®°í 8.1.6¿¡ ÀÖ´Â listener ÇÁ·Î±×·¥µéÀº Attacker¿¡°Ô ¿ø°ÝÀ¸·Î Oracle ¼ÒÀ¯ÀÇ ¿î¿µÃ¼Á¦ °èÁ¤À¸·Î ¾×¼¼½º¸¦ Çã¿ëÇÒ ¼ö ÀÖÀ¸¸ç ÀÓÀÇÀÇ ¸í·ÉµéÀ» ¼öÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. µðÆúÆ®·Î ¼³Ä¡µÈ Oracle listener ÇÁ·Î±×·¥Àº ¿ø°ÝÁöÀÇ listener ÄÁÆ®·Ñ·¯·Î ºÎÅÍ ¿ø°Ý ¸í·ÉµéÀ» ¼ö¿ëÇÑ´Ù. ÀûÀýÇÏ°Ô ±¸¼ºµÇ¾î ÀÖ´Ù¸é listener ¸í·ÉÀ» ¹Þ¾ÆµéÀ̱â Àü¿¡ »ç¿ëÀÚ¸¦ ÀÎÁõ¹Þ±â À§ÇØ ÆÐ½º¿öµå¸¦ ¿ä±¸ÇÑ´Ù. ¸¸¾à ÆÐ½º¿öµå°¡ ¼ÂµÇ¾î ÀÖÁö ¾Ê´Ù¸é Oracle listener ÇÁ·Î±×·¥Àº ·Î±×Á¤º¸¸¦ ÆÄÀÏ¿¡ Ãß°¡ÇÒ ¼ö ÀÖµµ·Ï ¸í·ÉÀ» ³»¸± ¼ö ÀÖ´Ù. SET TRC_FILE°ú SET LOG_FILE ¸í·ÉµéÀÇ ¹®Á¦Á¡À¸·Î ÀÎÇØ ÀÌ °ªµéÀº ÀÓÀÇÀÇ ÆÄÀϸíÀ¸·Î º¯°æÀÌ °¡´ÉÇÏ´Ù. À̰ÍÀº tnslsnr°¡ ¾²±â ±ÇÇÑÀ» °¡Áö°í ÀÖ´Â °÷ (.rhosts, .forward µîµî)¿¡ Attacker°¡ ÀÓÀÇÀÇ µ¥ÀÌŸ¸¦ ¾µ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. ¹®Á¦ÀÇ ¹öÀüµéÀº ¶ÇÇÑ listener°¡ ´Ù¿îµÉ ¼ö ÀÖ´Â ¼ºñ½º °ÅºÎ °ø°ÝÀ» ´çÇÒ ¼öµµ ÀÖ´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Oracle Database ¼¹ö |
| ÇØ°áÃ¥ |
1. ´ÙÀ½°ú °°Àº ÀýÂ÷¿¡ ÀÇÇØ listener ÆÐ½º¿öµå¸¦ ¼³Á¤ÇÏ¿©¾ß ÇÑ´Ù.
a) 'lsnrctl' ¸í·ÉÀ» ¼öÇà½ÃŲ´Ù. ±×¸®°í LISTENER ÇÁ·ÒÇÁÆ® »óÅ·Πµé¾î°£´Ù. b) 'change_password'¸¦ ŸÀÌÇÁÇϰí LISTENERÀÇ ÆÐ½º¿öµå¸¦ ¹Ù²Û´Ù. ÀÌ ¸í·ÉÀº listenerÀÇ ÆÐ½º¿öµå¸¦ ¹Ù²Ü ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. c) 'set password'¸¦ ŸÀÌÇÁÇϰí b)¿¡¼ ¼³Á¤ÇÑ ÆÐ½º¿öµå¸¦ ÀÔ·ÂÇÑ´Ù. ÀÌ ¸í·ÉÀº ´ÜÁö ÀÎÁõ ¸ñÀûÀ¸·Î LSNRCTL À¯Æ¿¸®Æ¼¿¡¼ listener ÇÁ·Î¼¼½º¿¡ º¸³»°Ô µÇ´Â ÆÐ½º¿öµå¸¦ ¼³Á¤ÇØ ÁØ´Ù. d) 'save_config'¸¦ ŸÀÌÇÁÇÑ´Ù. ÀÌ ¸í·ÉÀº listener ¼³Á¤ÆÄÀÏÀÇ ¹é¾÷ (LISTENER.BAK ÆÄÀÏ)À» »ý¼ºÇÏ°í ½ÇÁ¦ ¼³Á¤ÆÄÀÏ (LISTERNER.ORA) ÀÚü¿¡ º¯°æµÈ ³»¿ëÀ» ¾÷µ¥ÀÌÆ® ÇÑ´Ù. e) 'exit'¸¦ ŸÀÌÇÁÇÏ¿© ÇÁ·ÒÇÁÆ®¿¡¼ ºüÁ® ³ª¿Â´Ù.
2. OracleÀÇ MetaLink (http://metalink.oracle.com/)·Î ºÎÅÍ ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ Patch¸¦ ¼³Ä¡ÇÑ´Ù (listener ÇÁ·Î±×·¥¿¡ ´ëÇÑ ¹ö±× ¹øÈ£ 1361722 ÂüÁ¶). ¶ÇÇÑ ´ÙÀ½ URL¿¡¼ Oracle Technology Network¿¡ ÀÌ ¹®Á¦¿¡ ´ëÇÑ Security AlertÀ» ±¸ÇÒ ¼ö ÀÖ´Ù. http://www.oracle.com/us/technologies/security/listener-alert-132737.pdf Http://www.oracle.com/ocom/idcplg?IdcService=GET_FILE&dDocName=132737&allowInterrupt=1&Rendition=web&RevisionSelectionMethod=latestReleased |
| °ü·Ã URL |
CVE-2000-0818 (CVE) |
| °ü·Ã URL |
1853 (SecurityFocus) |
| °ü·Ã URL |
5380 (ISS) |
|