English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25006
À§Çèµµ 40
Æ÷Æ® 1521, ...
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í Oracle µ¥ÀÌÅͺ£À̽º°¡ »ý¼ºµÉ ¶§ °ü¸® ¸ñÀûÀ̳ª ¿î¿µ ¸ñÀûÀ¸·Î °èÁ¤µéÀÌ »ý¼ºµÈ´Ù. ÀÌµé °èÁ¤µé¿¡ ´ëÇÑ µðÆúÆ® ÆÐ½º¿öµåµéÀº Àß ¾Ë·ÁÁ® À־ µðÆúÆ® ÆÐ½º¿öµåµéÀÌ ³²°ÜÁ® ÀÖ´Ù¸é ÀáÀçÀûÀ¸·Î º¸¾È»ó¿¡ À§ÇèÀÌ µÉ ¼ö ÀÖ´Ù. ÀÌµé °¡¿îµ¥ °¡Àå °øÅëÀûÀ̰í À§ÇèÇÑ °èÁ¤µéÀÌ SYS¿Í SYSTEM °èÁ¤µéÀÌ´Ù. ÀÌ °èÁ¤µéÀº ¿ÏÀüÇÑ DBAÀÇ ±ÇÇÑÀ» °¡Áö°í ÀÖ´Ù.

* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº µðÆúÆ®·Î ´ÙÀ½ °èÁ¤ ID ¹× ÆÐ½º¿öµå Á¶Çյ鿡 ´ëÇØ Á¡°ËÇÑ´Ù:
system/manager,sys/mgr,sys/change_on_install,ctxsys/ctxsys,odscommon/odscommon

* Âü°í »çÀÌÆ®:
http://docs.oracle.com/cd/B10501_01/win.920/a95490/username.htm
http://www.vulnerabilityassessment.co.uk/default_oracle_passwords.htm

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Oracle Database ¼­¹ö
ÇØ°áÃ¥ Áï½Ã »ç¿ëÀÚÀÇ ÆÐ½º¿öµå¸¦ µðÆúÆ®°¡ ¾Æ´Ñ ´Ù¸¥ °ÍÀ¸·Î ¹Ù²Ù¾î¾ß ÇÑ´Ù.
»ç¿ëÀÚÀÇ ÆÐ½º¿öµå¸¦ ¹Ù²Ù±â À§Çؼ­´Â 'sqlplus' ¸í·ÉÀ» ÀÌ¿ëÇØ¼­ ÇØ´ç »ç¿ëÀÚ ¸íÀ¸·Î Oracle ¼­¹ö¿¡ ·Î±×ÀÎÇÏ¿©¾ß ÇÑ´Ù. ±×¸®°í ´ÙÀ½°ú °°ÀÌ ÆÐ½º¿öµå¸¦ ¹Ù²Ù±â À§ÇÑ ¸í·ÉÀ» ½ÇÇàÇÑ´Ù.

alter user "sys" identified by "mysecretpwd";

À§ÀÇ ¸í·ÉÀº "sys" »ç¿ëÀÚÀÇ ÆÐ½º¿öµå¸¦ "mysecretpwd"·Î ¹Ù²Û´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)