| Ãë¾àÁ¡ID |
25004 |
| À§Çèµµ |
30 |
| Æ÷Æ® |
1521, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
DB |
| »ó¼¼¼³¸í |
Oracle µ¥ÀÌÅͺ£À̽º°¡ »ý¼ºµÉ ¶§ °ü¸® ¸ñÀûÀ̳ª ¿î¿µ ¸ñÀûÀ¸·Î °èÁ¤µéÀÌ »ý¼ºµÈ´Ù. ÀÌµé °èÁ¤µé¿¡ ´ëÇÑ µðÆúÆ® ÆÐ½º¿öµåµéÀº Àß ¾Ë·ÁÁ® ÀÖ¾î¼ µðÆúÆ® ÆÐ½º¿öµåµéÀÌ ³²°ÜÁ® ÀÖ´Ù¸é ÀáÀçÀûÀ¸·Î º¸¾È»ó¿¡ À§ÇèÀÌ µÉ ¼ö ÀÖ´Ù. µðÆúÆ® ÆÐ½º¿öµåµéÀ» °¡Áø °èÁ¤µéÀÇ Á¸Àç´Â ¼³Ä¡µÈ OracleÀÇ ¹öÀüÀ̳ª ¿É¼Çµé¿¡ µû¶ó ´Ù¸¦ ¼ö ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº µðÆúÆ®·Î ´ÙÀ½ °èÁ¤ ID ¹× ÆÐ½º¿öµå Á¶Çյ鿡 ´ëÇØ Á¡°ËÇÑ´Ù: po/po,pubsub/pubsub,sample/sample,event/event,finance/finance,mfg/mfg, modtest/yes,vrr1/vrr1,company/company,mdsys/mdsys,scott/tiger, dbsnmp/dbsnmp,demo/demo,demo8/demo8,po8/po8,rman/rman,tracesrv/trace, applsys/applsys,ctxdemo/ctxdemo,names/names,sysadm/sysadm, ordplugins/ordplugins,outln/outln,adams/wood,blake/paper,jones/steel, clark/cloth,apps/apps,aurora$orb$unauthenticated/invalid
* Âü°í »çÀÌÆ®: http://docs.oracle.com/cd/B10501_01/win.920/a95490/username.htm http://www.vulnerabilityassessment.co.uk/default_oracle_passwords.htm
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Oracle Database ¼¹ö |
| ÇØ°áÃ¥ |
Áï½Ã »ç¿ëÀÚÀÇ ÆÐ½º¿öµå¸¦ µðÆúÆ®°¡ ¾Æ´Ñ ´Ù¸¥ °ÍÀ¸·Î ¹Ù²Ù¾î¾ß ÇÑ´Ù. »ç¿ëÀÚÀÇ ÆÐ½º¿öµå¸¦ ¹Ù²Ù±â À§Çؼ´Â 'sqlplus' ¸í·ÉÀ» ÀÌ¿ëÇØ¼ ÇØ´ç »ç¿ëÀÚ ¸íÀ¸·Î Oracle ¼¹ö¿¡ ·Î±×ÀÎÇÏ¿©¾ß ÇÑ´Ù. ±×¸®°í ´ÙÀ½°ú °°ÀÌ ÆÐ½º¿öµå¸¦ ¹Ù²Ù±â À§ÇÑ ¸í·ÉÀ» ½ÇÇàÇÑ´Ù.
alter user "dbsnmp" identified by "secretpwd";
À§ÀÇ ¸í·ÉÀº "dbsnmp" »ç¿ëÀÚÀÇ ÆÐ½º¿öµå¸¦ "secretpwd"·Î ¹Ù²Û´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|