| Ãë¾àÁ¡ID |
26009 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
139,445 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
SMB |
| »ó¼¼¼³¸í |
LPC¿Í LPC Ports¿¡ ÀÖ´Â º¹¼ö°³ÀÇ Ãë¾àÁ¡µé ´ëÇÑ Hotfix (Q266433) °¡ ¼³Ä¡µÇÁö ¾Ê¾Ò´Ù. LPC (Local Procedure Call)Àº Windows NT 4.0¿Í Windows 2000¿¡ ÀÇÇØ Á¦°øµÇ´Â ¾²·¹µå¿Í ÇÁ·Î¼¼½ºµé °£ÀÇ »óÈ£ Åë½ÅÀ» À§ÇÑ ¸Þ½ÃÁö Àü´Þ ¼ºñ½ºÀÌ´Ù. ±×¸®°í ¸ðµç LPC´Â LPC ports¶ó ºÒ¸®´Â Åë½Å ä³ÎÀÇ ÁýÇÕüµé(collection)À» °¡Áö°í ÀÖ´Ù. Windows NT 4.0°ú Windows 2000ÀÇ LPC¿Í LPC ports ±¸Çöµé¿¡¼ ¸î°¡Áö Ãë¾àÁ¡µéÀÌ ¹àÇô Á³À¸¸ç ´ÙÀ½ 4°³ÀÇ Æ¯º°ÇÑ Ãë¾àÁ¡µéÀÌ ¹®Á¦·Î Á¦±â µÇ¾ú´Ù.
- "Invalid LPC Request¡±Ãë¾àÁ¡ - "LPC Memory Exhaustion" Ãë¾àÁ¡ - "Predictable LPC Message Identifier" Ãë¾àÁ¡ - "Spoofed LPC Port Request" Ãë¾àÁ¡
À̵é Ãë¾àÁ¡µéÀº Attacker°¡ ½Ã½ºÅÛ »ó¿¡ »óÀ§ ±ÇÇÑÀ» ÃëµæÇÏ°Ô Çϰųª ¿ø°ÝÀ¸·Î ½Ã½ºÅÛÀ» Á¤Áö½Ãų ¼ö ÀÖ°Ô ÇØ ÁØ´Ù.
* ¾Ë¸²: ÀÌ Á¡°ËÇ׸ñÀº Á¡°ËÇϱâ À§ÇÑ ¿ø°ÝÁö È£½ºÆ®ÀÇ ·¹Áö½ºÆ®¸®¸¦ ¾×¼¼½ºÇÒ ¼ö ÀÖ´Â Guest ȤÀº ±× ÀÌ»óÀÇ ±ÇÇÑÀ» °¡Áø °èÁ¤À» ÇÊ¿ä·Î ÇÑ´Ù. ÀÌ·¯ÇÑ Á¶°ÇÀÌ ¾ÈµÇ¸é Á¡°ËÀ» ¼öÇàÇÒ ¼ö ¾øÀ¸¸ç ¸ðµç Ãë¾àÇÑ È£½ºÆ®µé¿¡ ´ëÇØ¼ °ÅÁþ À½¼º¹ÝÀÀ(False Negative)À» º¸ÀÏ ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/5316.php http://www.microsoft.com/technet/security/bulletin/MS00-070.asp http://www.microsoft.com/technet/security/bulletin/fq00-070.asp
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû Microsoft Windows NT, 2000 |
| ÇØ°áÃ¥ |
Microsoft Security Bulletin MS00-070 (http://www.microsoft.com/technet/security/bulletin/ms00-070.asp) ¿¡ ¼³¸íµÈ ´ë·Î ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ patch¸¦ ¼³Ä¡ÇÏ¿©¾ß ÇÑ´Ù.
* Windows NT 4.0 ¼ºñ½ºÆÑ 6a±îÁöÀÇ ½Ã½ºÅÛ¿¡´Â ÆÐÄ¡¸¦ ¼³Ä¡ÇØ¾ß ÇÑ´Ù. Windows NT 4.0 ¼ºñ½ºÆÑ 7¿¡´Â ÆÐÄ¡°¡ Æ÷ÇԵǾî ÀÖ´Ù. ¶ÇÇÑ Windows 2000 ¼ºñ½ºÆÑ 1±îÁöÀÇ ½Ã½ºÅÛ¿¡´Â ÆÐÄ¡¸¦ ¼³Ä¡ÇØ¾ß ÇÑ´Ù . Windows 2000 ¼ºñ½ºÆÑ 2¿¡´Â ÆÐÄ¡°¡ Æ÷ÇԵǾî ÀÖ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|