DNS-over-HTTPS ๊ตฌํ˜„์˜ ์ทจ์•ฝ์ ์„ ์ œ๊ฑฐํ•˜๊ธฐ ์œ„ํ•ด BIND DNS ์„œ๋ฒ„ ์—…๋ฐ์ดํŠธ

BIND DNS ์„œ๋ฒ„ 9.16.28 ๋ฐ 9.18.3์˜ ์•ˆ์ •์ ์ธ ๋ถ„๊ธฐ์— ๋Œ€ํ•œ ์ˆ˜์ • ์—…๋ฐ์ดํŠธ๊ฐ€ ๊ฒŒ์‹œ๋˜์—ˆ์œผ๋ฉฐ ์‹คํ—˜ ๋ถ„๊ธฐ 9.19.1์˜ ์ƒˆ ๋ฆด๋ฆฌ์Šค๋„ ๊ฒŒ์‹œ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๋ฒ„์ „ 9.18.3 ๋ฐ 9.19.1์—์„œ๋Š” ๋ถ„๊ธฐ 2022๋ถ€ํ„ฐ ์ง€์›๋˜์—ˆ๋˜ DNS-over-HTTPS ๋ฉ”์ปค๋‹ˆ์ฆ˜ ๊ตฌํ˜„์˜ ์ทจ์•ฝ์ (CVE-1183-9.18)์ด ์ˆ˜์ •๋˜์—ˆ์Šต๋‹ˆ๋‹ค. HTTP ๊ธฐ๋ฐ˜ ์ฒ˜๋ฆฌ๊ธฐ์— ๋Œ€ํ•œ TLS ์—ฐ๊ฒฐ์ด ์กฐ๊ธฐ์— ์ข…๋ฃŒ๋˜๋Š” ๊ฒฝ์šฐ ์ด ์ทจ์•ฝ์ ์œผ๋กœ ์ธํ•ด ๋ช…๋ช…๋œ ํ”„๋กœ์„ธ์Šค๊ฐ€ ์ค‘๋‹จ๋ฉ๋‹ˆ๋‹ค. ์ด ๋ฌธ์ œ๋Š” DoH(DNS over HTTPS) ์š”์ฒญ์„ ์ œ๊ณตํ•˜๋Š” ์„œ๋ฒ„์—๋งŒ ์˜ํ–ฅ์„ ๋ฏธ์นฉ๋‹ˆ๋‹ค. DoT(DNS over TLS) ์ฟผ๋ฆฌ๋ฅผ ํ—ˆ์šฉํ•˜๊ณ  DoH๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š๋Š” ์„œ๋ฒ„๋Š” ์ด ๋ฌธ์ œ์˜ ์˜ํ–ฅ์„ ๋ฐ›์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

๋ฆด๋ฆฌ์Šค 9.18.3์—๋Š” ๋ช‡ ๊ฐ€์ง€ ๊ธฐ๋Šฅ ๊ฐœ์„  ์‚ฌํ•ญ๋„ ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. IETF ์‚ฌ์–‘์˜ ๋‹ค์„ฏ ๋ฒˆ์งธ ์ดˆ์•ˆ์— ์ •์˜๋œ ์นดํƒˆ๋กœ๊ทธ ์˜์—ญ("์นดํƒˆ๋กœ๊ทธ ์˜์—ญ")์˜ ๋‘ ๋ฒˆ์งธ ๋ฒ„์ „์— ๋Œ€ํ•œ ์ง€์›์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. Zone Directory๋Š” ๋ณด์กฐ ์„œ๋ฒ„์˜ ๊ฐ ๋ณด์กฐ ์˜์—ญ์— ๋Œ€ํ•ด ๋ณ„๋„์˜ ๋ ˆ์ฝ”๋“œ๋ฅผ ์ •์˜ํ•˜๋Š” ๋Œ€์‹  ํŠน์ • ๋ณด์กฐ ์˜์—ญ ์ง‘ํ•ฉ์ด ๊ธฐ๋ณธ ์„œ๋ฒ„์™€ ๋ณด์กฐ ์„œ๋ฒ„ ๊ฐ„์— ์ „์†ก๋˜๋Š” ๋ณด์กฐ DNS ์„œ๋ฒ„๋ฅผ ์œ ์ง€ ๊ด€๋ฆฌํ•˜๋Š” ์ƒˆ๋กœ์šด ๋ฐฉ๋ฒ•์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ์ €๊ฒƒ๋“ค. ๊ฐœ๋ณ„ ์˜์—ญ ์ „์†ก๊ณผ ์œ ์‚ฌํ•œ ๋””๋ ‰ํ„ฐ๋ฆฌ ์ „์†ก์„ ์„ค์ •ํ•˜๋ฉด ๊ธฐ๋ณธ ์„œ๋ฒ„์—์„œ ์ƒ์„ฑ๋˜๊ณ  ๋””๋ ‰ํ„ฐ๋ฆฌ์— ํฌํ•จ๋œ ๊ฒƒ์œผ๋กœ ํ‘œ์‹œ๋œ ์˜์—ญ์ด ๊ตฌ์„ฑ ํŒŒ์ผ์„ ํŽธ์ง‘ํ•  ํ•„์š” ์—†์ด ๋ณด์กฐ ์„œ๋ฒ„์— ์ž๋™์œผ๋กœ ์ƒ์„ฑ๋ฉ๋‹ˆ๋‹ค.

์ƒˆ ๋ฒ„์ „์—๋Š” ์บ์‹œ์—์„œ ์˜ค๋ž˜๋œ ๋‹ต๋ณ€์ด ๋ฐ˜ํ™˜๋  ๋•Œ ๋ฐœ์ƒํ•˜๋Š” ํ™•์žฅ๋œ "Stale Answer" ๋ฐ "Stale NXDOMAIN Answer" ์˜ค๋ฅ˜ ์ฝ”๋“œ์— ๋Œ€ํ•œ ์ง€์›๋„ ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. names ๋ฐ dig์—๋Š” TLS(RFC 9103)๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•˜๋Š” ๊ฐ•๋ ฅํ•œ ์ธ์ฆ ๋˜๋Š” ํ˜‘๋ ฅ ์ธ์ฆ์„ ๊ตฌํ˜„ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์™ธ๋ถ€ TLS ์ธ์ฆ์„œ ํ™•์ธ ๊ธฐ๋Šฅ์ด ๋‚ด์žฅ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : opennet.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€