¡à °³¿ä o Microsoft WindowsÀÇ SMB2 ¸ðµâÀÌ SMB ¿äûÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼ ½Ã½ºÅÛÀÌ ºñÁ¤»óÀûÀ¸·Î Á¾·áµÇ°Å³ª ¿ø°ÝÄڵ尡 ½ÇÇà °¡´ÉÇÑ Ãë¾àÁ¡ [4] o °ø°ÝÀڴ Ư¼öÇÏ°Ô Á¶ÀÛµÈ SMB ÆÐŶÀ» Àü¼ÛÇÏ¿© ½Ã½ºÅÛ ±ÇÇÑÀ¸·Î ÀÓÀÇÀÇ ¿ø°ÝÄÚµå ½ÇÇà°¡´É[1] o Ãë¾àÁ¡À» ¾Ç¿ëÇÑ »ç·Ê°¡ ¹ß»ýÇÒ ¼ö ÀÖÀ¸¹Ç·Î »ç¿ëÀÚÀÇ ÁÖÀÇ°¡ ¿ä±¸µÊ
¡à ÇØ´ç ½Ã½ºÅÛ o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î [4] - Windows Vista, SP1, SP2 - Windows Vista x64 Edition, SP1, SP2 - Windows Server 2008 for 32-bit Systems, SP2 - Windows Server 2008 for x64-based Systems, SP2 - Windows Server 2008 for Itanium-based Systems, SP2
o ¿µÇâ ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î [4] - Microsoft Windows 2000 SP4 - Windows XP SP2, SP3 - Windows XP Professional x64 Edition SP2 - Windows Server 2003 SP2 - Windows Server 2003 x64 Edition SP2 - Windows Server 2003 with SP2 for Itanium-based Systems - Windows 7 for 32-bit Systems - Windows 7 for x64-based Systems - Windows Server 2008 R2 for x64-based Systems - Windows Server 2008 R2 for Itanium-based Systems
¡à Àӽà ÇØ°á ¹æ¾È o ÇöÀç ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È¾÷µ¥ÀÌÆ®´Â ¹ßÇ¥µÇÁö ¾Ê¾ÒÀ½
o SMB2¸¦ ºñÈ°¼ºÈ [4] ¡Ø ·¹Áö½ºÆ®¸® ¼³Á¤À» À߸ø º¯°æÇÒ °æ¿ì ½Ã½ºÅÛ¿¡ ½É°¢ÇÑ ¿À·ù°¡ ¹ß»ýÇÒ ¼ö ÀÖÀ¸¹Ç·Î ÁÖÀÇ
o TCP 139/445 Æ÷Æ®¸¦ ¹æȺ®¿¡¼ ÇÊÅ͸µ [4] - ÀÎÅͳݿ¡¼ À¯ÀԵǴ ¿ÜºÎÀÇ °ø°ÝÀ¸·ÎºÎÅÍ ¹æȺ® µÚÂÊ¿¡ ÀÖ´Â ½Ã½ºÅÛÀ» º¸È£ ¡Ø SMB/CIFS¸¦ »ç¿ëÇÏ´Â ÀÀ¿ëÇÁ·Î±×·¥À̳ª ÆÄÀÏ/ÇÁ¸°ÅÍ °øÀ¯ ±â´É »ç¿ë ºÒ°¡
o KrCERT/CC¿Í MSº¸¾È ¾÷µ¥ÀÌÆ® »çÀÌÆ®[5]¸¦ ÁÖ±âÀûÀ¸·Î È®ÀÎÇÏ¿© ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È ¾÷µ¥ÀÌÆ® ¹ßÇ¥ ½Ã ½Å¼ÓÈ÷ ÃֽŠ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇϰųª ÀÚµ¿ ¾÷µ¥ÀÌÆ®¸¦ ¼³Á¤ ¡Ø ÀÚµ¿¾÷µ¥ÀÌÆ® ¼³Á¤ ¹æ¹ý: ½ÃÀÛ¡æÁ¦¾îÆǡ溸¾È¼¾ÅÍ¡æÀÚµ¿¾÷µ¥ÀÌÆ®¡æÀÚµ¿(±ÇÀå) ¼±ÅÃ
o Ãë¾àÁ¡¿¡ ÀÇÇÑ ÇÇÇظ¦ ÁÙÀ̱â À§ÇÏ¿© »ç¿ëÀÚ´Â ´ÙÀ½°ú °°Àº »çÇ×À» ÁؼöÇؾßÇÔ - ÆÄÀÏ°øÀ¯ ±â´É µîÀ» »ç¿ëÇÏÁö ¾ÊÀ¸¸é ºñÈ°¼ºÈÇÏ°í °³ÀιæȺ®À» ¹Ýµå½Ã »ç¿ë - »ç¿ëÇÏ°í ÀÖ´Â ¹é½ÅÇÁ·Î±×·¥ÀÇ ÃֽŠ¾÷µ¥ÀÌÆ®¸¦ À¯ÁöÇÏ°í, ½Ç½Ã°£ °¨½Ã±â´ÉÀ» È°¼ºÈ - ½Å·ÚµÇÁö ¾Ê´Â À¥ »çÀÌÆ®ÀÇ ¹æ¹® ÀÚÁ¦ - Ãâó°¡ ºÒºÐ¸íÇÑ À̸ÞÀÏÀÇ Ã·ºÎÆÄÀÏ ¿¾îº¸±â ÀÚÁ¦
¡à ¿ë¾î ¼³¸í o Microsoft SMB (Server Message Block): Microsoft Windows¿¡¼ »ç¿ëÇÏ´Â ³×Æ®¿öÅ© ÆÄÀÏ °øÀ¯ ÇÁ·ÎÅäÄÝ [4] o SMB2 : Windows Vista¿Í Windows Server 2008¿¡¼ ³×Æ®¿öÅ© ±â´É Çâ»óÀ» À§ÇØ µµÀÔÇÑ "Â÷¼¼´ë TCP/IP ½ºÅÃ"¿¡ ±¸ÇöµÈ »õ·Î¿î ¹öÀüÀÇ SMB ÇÁ·ÎÅäÄÝ [6, 7]
[Âü°í»çÀÌÆ®] [1] http://www.securityfocus.com/bid/36299/ [2] http://secunia.com/advisories/36623/ [3] http://g-laurent.blogspot.com/2009/09/windows-vista7-smb20-negotiate-protocol.html [4] http://www.microsoft.com/technet/security/advisory/975497.mspx [5] http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=ko [6] http://en.wikipedia.org/wiki/Server_Message_Block [7] http://en.wikipedia.org/wiki/Windows_Vista_networking_technologies#Server_Message_Block_2.0
|
|
|