English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 29149
À§Çèµµ 30
Æ÷Æ® 22
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù CISCO
»ó¼¼¼³¸í ÇØ´ç CISCO IOS´Â VTY Á¢¼Ó ½Ã Telnet Á¢¼ÓÀ» Çã¿ëÇÑ´Ù. ¿ø°Ý Á¢¼Ó ½Ã Æò¹®À¸·Î Á¤º¸°¡ Àü¼ÛµÇ´Â TelnetÀº Æнº¿öµå ÃßÃø °ø°Ý(Password Guessing) ¹× ½º´ÏÇÎ °ø°Ý¿¡ Ãë¾àÇϹǷΠSSH ÇÁ·ÎÅäÄÝ »ç¿ë¸¸À» ±ÇÀåÇÑ´Ù.

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
CISCO IOS
ÇØ°áÃ¥ ´ÙÀ½°ú °°ÀÌ Telnet »ç¿ëÀ» Á¦ÇÑÇÑ´Ù.
Router# config terminal
Router(config)# line vty 0 4
Router(config-line)# transport input ssh <- SSH¸¸ »ç¿ë

¸¸ÀÏ access-list¿¡ ´ÙÀ½°ú °°ÀÌ TelnetÀ» Çã¿ëÇÑ´Ù¸é ÇØ´ç access-list¸¦ »èÁ¦ÇÑ´Ù.
ex) access-list 101 permit tcp 10.10.38.0 0.0.0.255 host 10.10.38.1 eq telnet (or 23)

Router# config terminal
Router(config)# no access-list 101
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)