| Ãë¾àÁ¡ID |
25006 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
1521, ... |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
DB |
| »ó¼¼¼³¸í |
Oracle µ¥ÀÌÅͺ£À̽º°¡ »ý¼ºµÉ ¶§ °ü¸® ¸ñÀûÀ̳ª ¿î¿µ ¸ñÀûÀ¸·Î °èÁ¤µéÀÌ »ý¼ºµÈ´Ù. ÀÌµé °èÁ¤µé¿¡ ´ëÇÑ µðÆúÆ® ÆÐ½º¿öµåµéÀº Àß ¾Ë·ÁÁ® ÀÖ¾î¼ µðÆúÆ® ÆÐ½º¿öµåµéÀÌ ³²°ÜÁ® ÀÖ´Ù¸é ÀáÀçÀûÀ¸·Î º¸¾È»ó¿¡ À§ÇèÀÌ µÉ ¼ö ÀÖ´Ù. ÀÌµé °¡¿îµ¥ °¡Àå °øÅëÀûÀ̰í À§ÇèÇÑ °èÁ¤µéÀÌ SYS¿Í SYSTEM °èÁ¤µéÀÌ´Ù. ÀÌ °èÁ¤µéÀº ¿ÏÀüÇÑ DBAÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÖ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº µðÆúÆ®·Î ´ÙÀ½ °èÁ¤ ID ¹× ÆÐ½º¿öµå Á¶Çյ鿡 ´ëÇØ Á¡°ËÇÑ´Ù: system/manager,sys/mgr,sys/change_on_install,ctxsys/ctxsys,odscommon/odscommon
* Âü°í »çÀÌÆ®: http://docs.oracle.com/cd/B10501_01/win.920/a95490/username.htm http://www.vulnerabilityassessment.co.uk/default_oracle_passwords.htm
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Oracle Database ¼¹ö |
| ÇØ°áÃ¥ |
Áï½Ã »ç¿ëÀÚÀÇ ÆÐ½º¿öµå¸¦ µðÆúÆ®°¡ ¾Æ´Ñ ´Ù¸¥ °ÍÀ¸·Î ¹Ù²Ù¾î¾ß ÇÑ´Ù. »ç¿ëÀÚÀÇ ÆÐ½º¿öµå¸¦ ¹Ù²Ù±â À§Çؼ´Â 'sqlplus' ¸í·ÉÀ» ÀÌ¿ëÇØ¼ ÇØ´ç »ç¿ëÀÚ ¸íÀ¸·Î Oracle ¼¹ö¿¡ ·Î±×ÀÎÇÏ¿©¾ß ÇÑ´Ù. ±×¸®°í ´ÙÀ½°ú °°ÀÌ ÆÐ½º¿öµå¸¦ ¹Ù²Ù±â À§ÇÑ ¸í·ÉÀ» ½ÇÇàÇÑ´Ù.
alter user "sys" identified by "mysecretpwd";
À§ÀÇ ¸í·ÉÀº "sys" »ç¿ëÀÚÀÇ ÆÐ½º¿öµå¸¦ "mysecretpwd"·Î ¹Ù²Û´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|