English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 28012
À§Çèµµ 30
Æ÷Æ® 139,445
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù SMB
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡´Â NetBIOS ±¸Çö»óÀÇ ¹®Á¦Á¡ ¶§¹®¿¡ MS À©µµ¿ì 95, 98, MEÀÇ °øÀ¯Æú´õ ¾ÏÈ£¸¦ ½±°Ô ¾Ë¾Æ³¾ ¼ö ÀÖ´Â Ãë¾àÁ¡ÀÌ Á¸ÀçÇÑ´Ù.
ÆÄÀÏ, Æú´õ¸¦ °øÀ¯ÇÑ À©µµ¿ì ½Ã½ºÅÛÀÇ °øÀ¯ ÆÐ½º¿ö½º È®ÀÎ ÀýÂ÷°úÁ¤¿¡¼­ "È®ÀÎ password ±æÀÌ"´Â ¿ø·¡ 8 bytesÀÌÁö¸¸ Remote»óÀÇ °ø°ÝÀÚ°¡ °øÀ¯ ÆÐ½º¿öµå È®Àο¡ ÇÊ¿äÇÑ ÆÐŶÀ» º¸³»¸é¼­ "È®ÀÎ password ±æÀÌ"¸¦ 8 bytesº¸´Ù ÀûÀº ±æÀÌ(1 bytes±îÁöµµ °¡´É)·Î °£´ÜÈ÷ ¼¼ÆÃÇÒ ¼ö°¡ ÀÖ´Ù.

¸ÕÀú ÆÐ½º¿öµå ±æÀ̸¦ 1 byte·Î ¼¼ÆÃÇÏ°í ¸ðµç PrintableÇÑ ¹®ÀÚ¸¦ ´ëÀÔÇÏ¿© °øÀ¯ ÆÐ½º¿öµå È®ÀÎ ÆÐŶÀ» º¸³»º»´Ù. ÀÀ´ä ÆÐŶÀ» È®ÀÎÇÏ¿© OK°¡ µÈ ¹®ÀÚ¸¦ ù¹øÂ° ÆÐ½º¿öµå·Î ÁöÁ¤ÇÏ°í °è¼ÓÇØ¼­ ÆÐ½º¿öµå ±æÀ̸¦ 1 bytes¾¿ ´Ã¸®¸é¼­ µ¹¾Æ¿À´Â ÀÀ´ä ÆÐŶÀ» º¸°í ¾ÆÁÖ ½±°Ô Àüü ÆÐ½º¿öµå¸¦ ¾Ë¾Æ³¾ ¼ö ÀÖ°Ô µÈ´Ù. Áï, ÇϳªÇϳª ¹®ÀÚ¸¦ º¸³»¸é¼­ Ʋ¸°Áö ¸Â´ÂÁö È®ÀÎÇÒ ¼ö ÀÖ´Ù.
ÀÌ ¹æ¹ýÀº Àüü 8 byteÀÇ ¾ÏÈ£¸¦ GuessingÇÏ´Â ÀϹÝÀûÀÎ Å©·¢¿¡ ºñÇÏ¸é ¾öû³ª°Ô °£´ÜÇÏ°í ºü¸¥ ¾Ë°í¸®Áò¿¡ ÀÇÇØ ÀÌ·ç¾îÁø´Ù. ÀÌ ±â¹ýÀº ÇÇÇØÁ¤µµ¿Í ±Ô¸ð°¡ ±Þ¼Óµµ·Î È®»êµÉ ¿ì·Á°¡ ÀÖÀ» Á¤µµ·Î Ä¡¸íÀûÀ̹ǷΠ¸ðµç À©µµ 98, 98se, ME »ç¿ëÀÚ´Â ÀÌ ¸ÞÀÏÀ» ¹Þ´Â Áï½Ã ÀÌÇÏÀÇ ÆÐÄ¡¸¦ Àû¿ëÇÒ °ÍÀ» ±Ç°íÇÑ´Ù.

----- Ãë¾àÇÑ ½Ã½ºÅÛ -------

Microsoft Windows ME
Microsoft Windows 98, 98se
Microsoft Windows 95

* Âü°í »çÀÌÆ®:
http://www.microsoft.com/technet/security/bulletin/ms00-072.asp
http://www.iss.net/security_center/static/5395.php
ÇØ°áÃ¥ 1. MS À©µµ¿ì 9x¿¡¼­ Á¦°øÇÏ´Â ÆÄÀÏ, ÇÁ¸°ÅÍ °øÀ¯ ±â´ÉÀ» ²À ÇÊ¿äÇÑ °æ¿ì°¡ ¾Æ´Ï¸é »ç¿ëÇÏÁö ¾Ê´Â´Ù.

2. °øÀ¯±â´ÉÀ» ºÎµæÀÌ »ç¿ëÇØ¾ß ÇÒ °æ¿ì¿¡´Â ´ÙÀ½À» ÆÐÄ¡Çϸé ÀÌ ±Ç°í¹®¿¡¼­ ÁöÀûÇÑ Ãë¾àÁ¡Àº Á¦°ÅµÈ´Ù.

À©µµ¿ì ME:
Microsoft patch 273991USAM
http://download.microsoft.com/download/winme/Update/11958/WinMe/EN-US/273991USAM.EXE

À©µµ¿ì 98se:
Microsoft patch 273991USA8
http://download.microsoft.com/download/win98SE/Update/11958/W98/EN-US/273991USA8.EXE

À©µµ¿ì 98:
Microsoft patch 273991USA8
http://download.microsoft.com/download/win98SE/Update/11958/W98/EN-US/273991USA8.EXE

À©µµ¿ì 95:
À©µµ¿ì 95´Â °øÀ¯Æú´õ Ãë¾àÁ¡ ÆÐÄ¡°¡ ¾ø´Ù. À©µµ¿ì 95¸¦ »ç¿ëÇÒ ¶§¿¡´Â °øÀ¯Æú´õ¸¦ ´õ ÀÌ»ó ¸¸µéÁö ¾Ê´Â ¹æ¹ý¹Û¿¡´Â ¾ø´Ù.
°ü·Ã URL CVE-2000-0979 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)