°øÁö»çÇ×

ÀÌÀü ÆäÀÌÁö·Î ¸Þ´ºº¸±â

[±ä±Þ °øÁö] Bash Ãë¾àÁ¡ ¾÷µ¥ÀÌÆ®

±è¼±È£ ( se@hhosting.co.kr )  2014-10-02 18:05:13

Á¶È¸¼ö 44,640
¾È³çÇϼ¼¿ä~ Çϳª·ÎÈ£½ºÆÃÀÔ´Ï´Ù

Bash 4.3 version Ãë¾àÁ¡ ¾È³».

°ü·Ã±â»ç : http://www.zdnet.co.kr/news/news_view.asp?artice_id=20140925112954&type=xml

bash°¡ 4.3À̻󿡼­ ÆÐÄ¡µÇ¾ú´Ù°í ÇÏ´øµ¥ 4.3ÀÌ¶óµµ ¿©ÀüÈ÷ Ãë¾àÁ¡¿¡ ³ëÃâµÈ´Ù°í ÇÕ´Ï´Ù.
(6.4¿¡¼­ bash°¡ 4.3¹öÀüÀε¥ Ãë¾àÁ¡ ³ëÃâ»óÅ·ΠȮÀεÊ)

¾Æ·¡ ¸í·É¾î ÀÔ·ÂÇÏ¿© Ãë¾àÁ¡ Á¡°Ë °¡´ÉÇÕ´Ï´Ù.

1. È®Àιý

env x='() { :;}; echo vulnerable' bash -c "echo this is a test"

°á°ú -> Ãë¾à
vulnerable
this is test

°á°ú -> Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë

bash: warning: x: ignoring function definition attempt
bash: error importing function definition for `x'
this is a test

¶Ç´Â

this is a test

2. ¾÷µ¥ÀÌÆ®¹ý

(1) CentOs

yum update bash

(2) Unbuntu

sudo apt-get install --only-upgrade bash

(3) RedHat


´ëü ÈÄ, »ç¿ëÇÒ ¹öÀü ¸Â°Ô ¸í·É¾î ÀÔ·Â
rpm —import http://mirror.centos.org/centos/ (¹öÀü¿¡ µû¶ó ÀÔ·Â)
(ex : rpm —import http://mirror.centos.org/centos/5/os/x86_64/RPM-GPG-KEY-CentOS-5)
yum update bash

(4)debian
sudo apt-get install bash


3.¾÷µ¥ÀÌÆ® ÈÄ ´Ù½Ã Çѹø Ãë¾àÁ¡ Á¡°ËÀ» ÇÏ½Ã¸é µË´Ï´Ù.

°øÁö»çÇ×À» º¸½Ã¸é ¼­¹ö¿¡ Á¢¼ÓÇϼż­ ²À ¾÷µ¥ÀÌÆ® ÇØÁֽñ⠹ٶø´Ï´Ù.

¸¸¾à¿¡ ¾÷µ¥ÀÌÆ®°¡ °¡´ÉÇÏÁö ¾Ê´Ù¸é Áö¿ø¿äû¿¡ ³²°ÜÁֽñ⠹ٶø´Ï´Ù.
Back 4 5 67 8