[º¸¾È´º½º ±Ç ÁØ] ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®(ÀÌÇÏ MS)´Â MS-CHAP v2 ÇÁ·ÎÅäÄÝÀÇ ¾ÏÈ£È Ãë¾àÁ¡À» ¾Ç¿ëÇÑ °ø°ÝÄڵ尡 °ø°³µÆ´Ù´Â »ç½ÇÀ» È®ÀÎÇß´Ù.
ÀÌ·Î ÀÎÇØ °ø°ÝÀÚ´Â ÇØ´ç Ãë¾àÁ¡À» ¾Ç¿ëÇÑ MITM(Man-In-The-Middle) °ø°Ý µîÀ» ÅëÇÏ¿© »ç¿ëÀÚ ÀÚ°ÝÁõ¸íÀ» ȹµæÇÒ ¼ö ÀÖ´Ù°í Çѱ¹ÀÎÅͳÝÁøÈï¿ø ÀÎÅͳÝħÇØ´ëÀÀ¼¾ÅÍ ÃøÀº ¹àÇû´Ù.
MS-CHAP v2 ÇÁ·ÎÅäÄÝ(Microsoft Challenge Handshake Authentication Protocol version 2)Àº PPTP(Point-to-Point Tunneling Protocol) ±â¹Ý VPN¿¡ ÀϹÝÀûÀ¸·Î »ç¿ëµÇ´Â ÀÎÁõ¹æ¹ýÀ¸·Î, PPTP ±â¹Ý VPNÀÇ ÀÎÁõ¹æ¹ýÀ¸·Î MS-CHAP v2¸¸À» »ç¿ëÇÏ´Â °æ¿ì ÇØ´ç Ãë¾àÁ¡¿¡ ¿µÇâÀ» ¹ÞÀ» ¼ö ÀÖ´Ù.
ÀÌ¿¡ MS´Â PPTP ±â¹Ý VPN ÀÎÁõÀ¸·Î MS-CHAP v2 ´ë½Å PEAP-MS-CHAP v2 ÀÎÁõ¹æ¹ýÀ» ±¸¼ºÇØ »ç¿ëÇÒ °ÍÀ» ±ÇÀåÇß´Ù.
[Âü°í»çÀÌÆ®]
[1] http://technet.microsoft.com/security/advisory/2743314
[2] http://support.microsoft.com/kb/2744850
*MITM(Man-In-The-Middle) °ø°Ý : Åë½ÅÇÏ°í ÀÖ´Â µÎ ´ç»çÀÚ »çÀÌ¿¡ ³¢¾îµé¾î ±³È¯ÇÏ´Â Á¤º¸¸¦ Àڱ⠰Ͱú ¹Ù²Ù¾î¹ö¸²À¸·Î½á µéÅ°Áö ¾Ê°í µµÃ»À» Çϰųª Åë½Å³»¿ëÀ» ¹Ù²Ù´Â ÇØÅ· ±â¹ý
[±Ç ÁØ ±âÀÚ(editor@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>