[±ä±Þ °øÁö] Bash Ãë¾àÁ¡ ¾÷µ¥ÀÌÆ®
±è¼±È£ ( se@hhosting.co.kr ) 2014-10-02 18:05:13
Á¶È¸¼ö 44,640
¾È³çÇϼ¼¿ä~ Çϳª·ÎÈ£½ºÆÃÀÔ´Ï´Ù
Bash 4.3 version Ãë¾àÁ¡ ¾È³».
°ü·Ã±â»ç : http://www.zdnet.co.kr/news/news_view.asp?artice_id=20140925112954&type=xml
bash°¡ 4.3À̻󿡼 ÆÐÄ¡µÇ¾ú´Ù°í ÇÏ´øµ¥ 4.3ÀÌ¶óµµ ¿©ÀüÈ÷ Ãë¾àÁ¡¿¡ ³ëÃâµÈ´Ù°í ÇÕ´Ï´Ù.
(6.4¿¡¼ bash°¡ 4.3¹öÀüÀε¥ Ãë¾àÁ¡ ³ëÃâ»óÅ·ΠȮÀεÊ)
¾Æ·¡ ¸í·É¾î ÀÔ·ÂÇÏ¿© Ãë¾àÁ¡ Á¡°Ë °¡´ÉÇÕ´Ï´Ù.
1. È®Àιý
env x='() { :;}; echo vulnerable' bash -c "echo this is a test"
°á°ú -> Ãë¾à
vulnerable
this is test
°á°ú -> Ãë¾àÁ¡ ÆÐÄ¡ Àû¿ë
bash: warning: x: ignoring function definition attempt
bash: error importing function definition for `x'
this is a test
¶Ç´Â
this is a test
2. ¾÷µ¥ÀÌÆ®¹ý
(1) CentOs
yum update bash
(2) Unbuntu
sudo apt-get install --only-upgrade bash
(3) RedHat
´ëü ÈÄ, »ç¿ëÇÒ ¹öÀü ¸Â°Ô ¸í·É¾î ÀÔ·Â
rpm —import http://mirror.centos.org/centos/ (¹öÀü¿¡ µû¶ó ÀÔ·Â)
(ex : rpm —import http://mirror.centos.org/centos/5/os/x86_64/RPM-GPG-KEY-CentOS-5)
yum update bash
(4)debian
sudo apt-get install bash
3.¾÷µ¥ÀÌÆ® ÈÄ ´Ù½Ã Çѹø Ãë¾àÁ¡ Á¡°ËÀ» ÇÏ½Ã¸é µË´Ï´Ù.
°øÁö»çÇ×À» º¸½Ã¸é ¼¹ö¿¡ Á¢¼ÓÇϼż ²À ¾÷µ¥ÀÌÆ® ÇØÁֽñ⠹ٶø´Ï´Ù.
¸¸¾à¿¡ ¾÷µ¥ÀÌÆ®°¡ °¡´ÉÇÏÁö ¾Ê´Ù¸é Áö¿ø¿äû¿¡ ³²°ÜÁֽñ⠹ٶø´Ï´Ù.