English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25002
À§Çèµµ 40
Æ÷Æ® 1521
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í ÇØ´ç È£½ºÆ®¿¡ Oracle tnslsnr°¡ °¡µ¿µÇ°í ÀÖ´Ù. TNS listener (tnslsnr)´Â µ¥ÀÌÅͺ£À̽º Ŭ¶óÀÌ¾ðÆ®¿Í ¼­¹ö°£ÀÇ ³×Æ®¿öÅ© ÀÎÅÍÆäÀ̽ºÀÌ´Ù. tnslsnr´Â 1521/tcp Æ÷Æ®¸¦ »ç¿ëÇÏÁö¸¸ DBA°¡ À̸¦ º¯°æÇÒ ¼öµµ ÀÖ´Ù. ¸ðµç Ç÷§Æû »óÀÇ Oracle ¸±¸®Áî 7.3.4, 8.0.6, ±×¸®°í 8.1.6¿¡ ÀÖ´Â listener ÇÁ·Î±×·¥µéÀº Attacker¿¡°Ô ¿ø°ÝÀ¸·Î Oracle ¼ÒÀ¯ÀÇ ¿î¿µÃ¼Á¦ °èÁ¤À¸·Î ¾×¼¼½º¸¦ Çã¿ëÇÒ ¼ö ÀÖÀ¸¸ç ÀÓÀÇÀÇ ¸í·ÉµéÀ» ¼öÇàÇÒ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
µðÆúÆ®·Î ¼³Ä¡µÈ Oracle listener ÇÁ·Î±×·¥Àº ¿ø°ÝÁöÀÇ listener ÄÁÆ®·Ñ·¯·Î ºÎÅÍ ¿ø°Ý ¸í·ÉµéÀ» ¼ö¿ëÇÑ´Ù. ÀûÀýÇÏ°Ô ±¸¼ºµÇ¾î ÀÖ´Ù¸é listener ¸í·ÉÀ» ¹Þ¾ÆµéÀ̱â Àü¿¡ »ç¿ëÀÚ¸¦ ÀÎÁõ¹Þ±â À§ÇØ ÆÐ½º¿öµå¸¦ ¿ä±¸ÇÑ´Ù. ¸¸¾à ÆÐ½º¿öµå°¡ ¼ÂµÇ¾î ÀÖÁö ¾Ê´Ù¸é Oracle listener ÇÁ·Î±×·¥Àº ·Î±×Á¤º¸¸¦ ÆÄÀÏ¿¡ Ãß°¡ÇÒ ¼ö ÀÖµµ·Ï ¸í·ÉÀ» ³»¸± ¼ö ÀÖ´Ù. SET TRC_FILE°ú SET LOG_FILE ¸í·ÉµéÀÇ ¹®Á¦Á¡À¸·Î ÀÎÇØ ÀÌ °ªµéÀº ÀÓÀÇÀÇ ÆÄÀϸíÀ¸·Î º¯°æÀÌ °¡´ÉÇÏ´Ù. À̰ÍÀº tnslsnr°¡ ¾²±â ±ÇÇÑÀ» °¡Áö°í ÀÖ´Â °÷ (.rhosts, .forward µîµî)¿¡ Attacker°¡ ÀÓÀÇÀÇ µ¥ÀÌŸ¸¦ ¾µ ¼ö ÀÖµµ·Ï ÇØ ÁØ´Ù. ¹®Á¦ÀÇ ¹öÀüµéÀº ¶ÇÇÑ listener°¡ ´Ù¿îµÉ ¼ö ÀÖ´Â ¼­ºñ½º °ÅºÎ °ø°ÝÀ» ´çÇÒ ¼öµµ ÀÖ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Oracle Database ¼­¹ö
ÇØ°áÃ¥ 1. ´ÙÀ½°ú °°Àº ÀýÂ÷¿¡ ÀÇÇØ listener ÆÐ½º¿öµå¸¦ ¼³Á¤ÇÏ¿©¾ß ÇÑ´Ù.

a) 'lsnrctl' ¸í·ÉÀ» ¼öÇà½ÃŲ´Ù. ±×¸®°í LISTENER ÇÁ·ÒÇÁÆ® »óÅ·Πµé¾î°£´Ù.
b) 'change_password'¸¦ ŸÀÌÇÁÇϰí LISTENERÀÇ ÆÐ½º¿öµå¸¦ ¹Ù²Û´Ù. ÀÌ ¸í·ÉÀº listenerÀÇ ÆÐ½º¿öµå¸¦ ¹Ù²Ü ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
c) 'set password'¸¦ ŸÀÌÇÁÇϰí b)¿¡¼­ ¼³Á¤ÇÑ ÆÐ½º¿öµå¸¦ ÀÔ·ÂÇÑ´Ù. ÀÌ ¸í·ÉÀº ´ÜÁö ÀÎÁõ ¸ñÀûÀ¸·Î LSNRCTL À¯Æ¿¸®Æ¼¿¡¼­ listener ÇÁ·Î¼¼½º¿¡ º¸³»°Ô µÇ´Â ÆÐ½º¿öµå¸¦ ¼³Á¤ÇØ ÁØ´Ù.
d) 'save_config'¸¦ ŸÀÌÇÁÇÑ´Ù. ÀÌ ¸í·ÉÀº listener ¼³Á¤ÆÄÀÏÀÇ ¹é¾÷ (LISTENER.BAK ÆÄÀÏ)À» »ý¼ºÇÏ°í ½ÇÁ¦ ¼³Á¤ÆÄÀÏ (LISTERNER.ORA) ÀÚü¿¡ º¯°æµÈ ³»¿ëÀ» ¾÷µ¥ÀÌÆ® ÇÑ´Ù.
e) 'exit'¸¦ ŸÀÌÇÁÇÏ¿© ÇÁ·ÒÇÁÆ®¿¡¼­ ºüÁ® ³ª¿Â´Ù.

2. OracleÀÇ MetaLink (http://metalink.oracle.com/)·Î ºÎÅÍ ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ Patch¸¦ ¼³Ä¡ÇÑ´Ù (listener ÇÁ·Î±×·¥¿¡ ´ëÇÑ ¹ö±× ¹øÈ£ 1361722 ÂüÁ¶). ¶ÇÇÑ ´ÙÀ½ URL¿¡¼­ Oracle Technology Network¿¡ ÀÌ ¹®Á¦¿¡ ´ëÇÑ Security AlertÀ» ±¸ÇÒ ¼ö ÀÖ´Ù.
http://www.oracle.com/us/technologies/security/listener-alert-132737.pdf
Http://www.oracle.com/ocom/idcplg?IdcService=GET_FILE&dDocName=132737&allowInterrupt=1&Rendition=web&RevisionSelectionMethod=latestReleased
°ü·Ã URL CVE-2000-0818 (CVE)
°ü·Ã URL 1853 (SecurityFocus)
°ü·Ã URL 5380 (ISS)