English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 25008
À§Çèµµ 40
Æ÷Æ® 1433
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù DB
»ó¼¼¼³¸í È®Àå Stored ProcedureÀÎ xp_cmdshellÀº »ç¿ëÀÚ°¡ ¸í·ÉÇà ¶óÀÎ ÇÁ·ÒÇÁÆ®¿Í °°ÀÌ MS SQL ¼­¹ö¿¡¼­ ¿î¿µÃ¼Á¦ ¸í·ÉµéÀ» ¼öÇà½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
ºñ·Ï ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»ç¿¡¼­´Â ¼³Ä¡ ½Ã¿¡ 'sa' °èÁ¤¿¡ ´ëÇÑ ÆÐ½º¿öµå¸¦ ¼³Á¤Çϵµ·Ï Çϰí ÀÖÁö¸¸ ¸¹Àº ¼­¹öµéÀÌ Ãë¾àÇÑ Ã¤·Î ÀÖ´Ù. MS SQL ¼³Ä¡ ½Ã¿¡ "sa" °èÁ¤ ÆÐ½º¿öµå¸¦ ¼³Á¤ÇÏÁö ¾Ê°Å³ª ÃßÃø °¡´ÉÇÏ°Ô ¼³Ä¡µÈ´Ù¸é Ãë¾àÇÏ´Ù. ÀÏ´Ü Ãë¾àÇÑ ¼­¹ö°¡ ¹ß°ßµÈ´Ù¸é ¿ø°ÝÁöÀÇ °ø°ÝÀÚ´Â MS-SQLÀÇ Stored Procedure "xp_cmdshell"À» »ç¿ëÇÏ¿© ÀÓÀÇÀÇ ¸í·ÉÀ» ¼öÇà½Ãų ¼ö ÀÖ´Ù.
Spida ȤÀº CBlade¿Í °°Àº ´Ù¾çÇÑ ¿úµéÀº ÆÐ½º¿öµå¸¦ °¡ÁöÁö ¾ÊÀº "sa" °èÁ¤µéÀ» °¡Áø Microsoft SQL ¼­¹ö¸¦ ã¾Æ ·Î±×ÀÎÀ» ½ÃµµÇÑ´Ù. ÀÏ´Ü Ãë¾àÇÑ ÄÄÇ»ÅͰ¡ ¹ß°ßµÇ¸é ¿úµéÀº ´ë»óÀ» °¨¿°½ÃŰ°í ¿ÜºÎ È£½ºÆ®·Î ¼³Á¤Á¤º¸¿Í ÆÐ½º¿öµå Á¤º¸¸¦ º¸³»¸ç »õ·Î¿î ´ë»óÀ» ã¾Æ ½ºÄ³´×À» ½ÃÀÛÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://support.microsoft.com/default.aspx?scid=kb;EN-US;q322336
http://www.iss.net/security_center/static/7610.php
http://www.iss.net/security_center/static/9124.php
http://www.iss.net/security_center/alerts/advise118.php
http://www.kb.cert.org/vuls/id/635463
http://www.securiteam.com/windowsntfocus/5BP0L1P7PA.html
http://www.securiteam.com/tools/5GP081P75C.html
http://www.securiteam.com/windowsntfocus/5WP0N0K75U.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft SQL Server Any version
Microsoft Data Engine (MSDE) Any version
ÇØ°áÃ¥ ¸¸¾à 'sa' °èÁ¤ÀÌ ÆÐ½º¿öµå¸¦ °¡Áö°í ÀÖÁö ¾Ê´Ù¸é ÃßÃøÇϱ⠾î·Á¿î °ÍÀ¸·Î ¼³Á¤ÇÏ¿©¾ß ÇÑ´Ù. ÆÐ½º¿öµå¸¦ ¼³Á¤Çϱâ À§Çؼ­´Â SQL Query Window¸¦ ÅëÇÏ¿© sp_password ¶ó´Â Stored Procedure¸¦ »ç¿ëÇÒ ¼ö ÀÖ´Ù. ¿¹¸¦µé¾î, SA ÆÐ½º¿öµå¸¦ NULL¿¡¼­ "complexpwd"·Î ¼³Á¤Çϱâ À§Çؼ­´Â ´ÙÀ½°ú °°ÀÌ ÇÒ ¼ö ÀÖ´Ù:

exec sp_password NULL,'complexpwd','sa'

-- ±×¸®°í --

Trace ÆÄÀϷκÎÅÍ xp_cmdshellÀ» ÅëÇÏ¿© ¼öÇàµÈ ¸í·ÉÀ» Á¶»çÇÑ´Ù. sa °èÁ¤¸¸ÀÌ xp_cmdshell ¹®À» ½ÇÇà½Ãų ¼ö ÀÖµµ·Ï ¼­¹ö¸¦ ¼³Á¤Çϰųª ¾Æ¿¹ xp_cmdshell¸¦ Á¦°ÅÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)