¡à °³¿ä o Microsoft Windows 7 ¹× Windows Server 2008 R2ÀÇ SMB(Server Message Block) ¸ðµâÀÌ SMB ¿äûÀ» ó¸®ÇÏ´Â °úÁ¤¿¡¼ ½Ã½ºÅÛÀÌ ºñÁ¤»óÀûÀ¸·Î Á¾·áµÇ´Â Ãë¾àÁ¡ [1,2] o °ø°ÝÀڴ Ư¼öÇÏ°Ô Á¶ÀÛµÈ SMB ÆÐŶÀ» Àü¼ÛÇÏ¿© ´ë»ó ½Ã½ºÅÛÀ» Á¾·á½ÃÅ´ [1,2] o Ãë¾àÁ¡À» ¾Ç¿ëÇÑ »ç·Ê°¡ ¹ß»ýÇÒ ¼ö ÀÖÀ¸¹Ç·Î »ç¿ëÀÚÀÇ ÁÖÀÇ°¡ ¿ä±¸µÊ
¡à ÇØ´ç ½Ã½ºÅÛ o ¿µÇâ ¹Þ´Â ¼ÒÇÁÆ®¿þ¾î [3] - Windows 7 for 32-bit Systems - Windows 7 for x64-based Systems - Windows Server 2008 R2 for x64-based Systems - Windows Server 2008 R2 for Itanium-based Systems
o ¿µÇâ ¹ÞÁö ¾Ê´Â ¼ÒÇÁÆ®¿þ¾î [3] - Microsoft Windows 2000 SP4 - Windows XP SP2, SP3 - Windows XP Professional x64 Edition SP2 - Windows Server 2003 SP2 - Windows Server 2003 x64 Edition SP2 - Windows Server 2003 with SP2 for Itanium-based Systems - Windows Vista, Windows Vista SP1, SP2 - Windows Vista x64 Edition, SP1, SP2 - Windows Server 2008 for 32-bit Systems, SP2 - Windows Server 2008 for x64-based Systems, SP2 - Windows Server 2008 for Itanium-based Systems, SP2
¡à Àӽà ÇØ°á ¹æ¾È o ÇöÀç ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È¾÷µ¥ÀÌÆ®´Â ¹ßÇ¥µÇÁö ¾Ê¾ÒÀ½ o TCP 139/445 Æ÷Æ®¸¦ ¹æȺ®¿¡¼ ÇÊÅ͸µ [3] - ÀÎÅͳݿ¡¼ À¯ÀԵǴ ¿ÜºÎÀÇ °ø°ÝÀ¸·ÎºÎÅÍ ¹æȺ® µÚÂÊ¿¡ ÀÖ´Â ½Ã½ºÅÛÀ» º¸È£ ¡Ø SMB/CIFS¸¦ »ç¿ëÇÏ´Â ÀÀ¿ëÇÁ·Î±×·¥À̳ª ÆÄÀÏ/ÇÁ¸°ÅÍ °øÀ¯ ±â´É »ç¿ë ºÒ°¡
o KrCERT/CC¿Í MSº¸¾È ¾÷µ¥ÀÌÆ® »çÀÌÆ®[4]¸¦ ÁÖ±âÀûÀ¸·Î È®ÀÎÇÏ¿© ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ º¸¾È ¾÷µ¥ÀÌÆ® ¹ßÇ¥ ½Ã ½Å¼ÓÈ÷ ÃֽŠ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇϰųª ÀÚµ¿ ¾÷µ¥ÀÌÆ®¸¦ ¼³Á¤ ¡Ø ÀÚµ¿¾÷µ¥ÀÌÆ® ¼³Á¤ ¹æ¹ý: ½ÃÀÛ¡æÁ¦¾îÆǡ溸¾È¼¾ÅÍ¡æÀÚµ¿¾÷µ¥ÀÌÆ®¡æÀÚµ¿(±ÇÀå) ¼±ÅÃ
o Ãë¾àÁ¡¿¡ ÀÇÇÑ ÇÇÇظ¦ ÁÙÀ̱â À§ÇÏ¿© »ç¿ëÀÚ´Â ´ÙÀ½°ú °°Àº »çÇ×À» ÁؼöÇؾßÇÔ - ÆÄÀÏ°øÀ¯ ±â´É µîÀ» »ç¿ëÇÏÁö ¾ÊÀ¸¸é ºñÈ°¼ºÈÇÏ°í °³ÀιæȺ®À» ¹Ýµå½Ã »ç¿ë - »ç¿ëÇÏ°í ÀÖ´Â ¹é½ÅÇÁ·Î±×·¥ÀÇ ÃֽŠ¾÷µ¥ÀÌÆ®¸¦ À¯ÁöÇÏ°í, ½Ç½Ã°£ °¨½Ã±â´ÉÀ» È°¼ºÈ - ½Å·ÚµÇÁö ¾Ê´Â À¥ »çÀÌÆ®ÀÇ ¹æ¹® ÀÚÁ¦ - Ãâó°¡ ºÒºÐ¸íÇÑ À̸ÞÀÏÀÇ Ã·ºÎÆÄÀÏ ¿¾îº¸±â ÀÚÁ¦
¡à ¿ë¾î ¼³¸í o Microsoft SMB (Server Message Block): Microsoft Windows¿¡¼ »ç¿ëÇÏ´Â ³×Æ®¿öÅ© ÆÄÀÏ °øÀ¯ ÇÁ·ÎÅäÄÝ [5]
[Âü°í»çÀÌÆ®] [1] http://www.vupen.com/english/advisories/2009/3216 [2] http://secunia.com/advisories/37347/ [3] http://www.microsoft.com/technet/security/advisory/977544.mspx [4] http://update.microsoft.com/microsoftupdate/v6/default.aspx?ln=ko [5] http://en.wikipedia.org/wiki/Server_Message_Block
|
|
|