|
 |
[ °ø Áö ] BIND DNS ½Å±Ô Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í |
 |
2017-02-09 |
|
 |
¾È³çÇϽʴϱî. È£½ºÆ®¸ÕÆ®ÀÔ´Ï´Ù.
¸ÕÀú È£½ºÆ®¸ÕÆ®¸¦ ¾Æ²¸ÁÖ½Ã°í »ç¶ûÇØ Áֽô °í°´ ¿©·¯ºÐ²² Áø½ÉÀ¸·Î °¨»çµå¸®¸ç
BIND DNS ½Å±Ô Ãë¾àÁ¡ º¸¾È ¾÷µ¥ÀÌÆ® ±Ç°í°¡ ÀÖ¾î À̸¦ ¾Ë·Áµå¸®°íÀÚ ÇÕ´Ï´Ù.
---------------------------------------------------------------------------
¡à °³¿ä
o ISC´Â BIND ¼ÒÇÁÆ®¿þ¾î¿¡¼ ¹ß»ýÇÏ´Â ¿ø°Ý ¼ºñ½º °ÅºÎ(Denial of Service) Ãë¾àÁ¡À» ÇØ°áÇÑ º¸¾È ¾÷µ¥ÀÌÆ® ¹ßÇ¥ [1]
¡à ³»¿ë
o DNS64¿Í RPZ¸¦ µ¿½Ã¿¡ ¼³Á¤ÇÏ¿© »ç¿ëÇÏ´Â °æ¿ì, ±¸µ¿ Áß ¿À·ù·Î ÀÎÇØ ¼¹ö ±¸µ¿ÀÌ Áß´ÜµÉ ¼ö ÀÖ´Â Ãë¾àÁ¡(CVE-2017-3135)
¡à ¿µÇâÀ» ¹Þ´Â Á¦Ç° ¹× ¹öÀü
o BIND 9.9.3~9.9.9-P5
o BIND 9.9.10b1
o BIND 9.10.0~9.10.4-P5
o BIND 9.10.5b1
o BIND 9.11.0~9.11.0-P2
o BIND 9.11.1b1
¡à ÇØ°á ¹æ¾È
o BIND ¹öÀü ¾÷±×·¹À̵带 ÅëÇÑ Á¶Ä¡
- BIND 9.9.9-P6, 9.10.4-P6, 9.11.0-P3À¸·Î ¾÷±×·¹À̵å
o ¼³Á¤À» ÅëÇÑ Á¶Ä¡
- DNS64¿Í RPZ¸¦ µ¿½Ã¿¡ »ç¿ëÇÏÁö ¾Êµµ·Ï ¼³Á¤
¡à ¿ë¾î Á¤¸®
o DNS64 : IPV4 -> IPv6 Àüȯ±â¼ú Áß ÇϳªÀÎ NAT64(Network Address Translation between IPv6 and IPv4) ¸ÞÄ¿´ÏÁòÀ»
Áö¿øÇϱâ À§ÇÑ DNS Ç¥Áرâ´É
o RPZ(Response Policy Zone) : DNS ÀÀ´ä Áß ÁöÁ¤µÈ Á¶°ÇÀÇ ÁúÀÇ, ÀÀ´äÄÚµå µî¿¡ ÇØ´çÇÏ´Â ÀÀ´äÀÎ °æ¿ì À̸¦ Á¤Ã¥(Policy)À¸·Î
ÁöÁ¤µÈ ÇüÅ·Πº¯ÇüµÈ ÀÀ´ä󸮸¦ ÇÏ´Â ±â´É
¡à ±âŸ ¹®ÀÇ»çÇ×
o Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝÄ§ÇØ´ëÀÀ¼¾ÅÍ: ±¹¹ø¾øÀÌ 118
[Âü°í»çÀÌÆ®]
[1] https://kb.isc.org/article/AA-01453
°¨»çÇÕ´Ï´Ù.
---------------------------------------------------------------------------
Áñ°Å¿òÀÌ Àִ ȣ½ºÆÃ ¼ºñ½º [ È£½ºÆ®¸ÕÆ® ]
|
|
|