½Ã½ºÅÛ°ü¸®ÀÚÀÇ ½°ÅÍ Ä¿ÇǴнº Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
 FAQFAQ   °Ë»ö°Ë»ö   ¸â¹ö¸®½ºÆ®¸â¹ö¸®½ºÆ®   »ç¿ëÀÚ ±×·ì»ç¿ëÀÚ ±×·ì   »ç¿ëÀÚ µî·ÏÇϱâ»ç¿ëÀÚ µî·ÏÇϱâ 
 °³ÀÎ Á¤º¸°³ÀÎ Á¤º¸   ºñ°ø°³ ¸Þ½ÃÁö¸¦ È®ÀÎÇÏ·Á¸é ·Î±×ÀÎÇϽʽÿÀºñ°ø°³ ¸Þ½ÃÁö¸¦ È®ÀÎÇÏ·Á¸é ·Î±×ÀÎÇϽʽÿÀ   ·Î±×Àηα×ÀΠ

°¡ÀÔ¾øÀÌ ´©±¸³ª ±ÛÀ» ¾µ ¼ö ÀÖ½À´Ï´Ù. °øÁö»çÇ׿¡ ´ëÇÑ ´ñ±Û±îÁöµµ..




BBS >> ¼³Ä¡, ¿î¿µ Q&A | ³×Æ®¿÷, º¸¾È Q&A | ÀÏ¹Ý Q&A || Á¤º¸¸¶´ç | AWS || ÀÚÀ¯°Ô½ÃÆÇ | ±¸Àα¸Á÷ || °øÁö»çÇ× | ÀÇ°ßÁ¦½Ã
8.20~21 Ä¿ÇǴнº À̾߱â (º¸¾È, Ãë¾àÁ¡, Ç÷¡½¬ ÄíÅ° µî)

 
±Û ¾²±â   ´äº¯ ´Þ±â    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ °Ô½ÃÆÇ À妽º -> *NIX / IT Á¤º¸
ÀÌÀü ÁÖÁ¦ º¸±â :: ´ÙÀ½ ÁÖÁ¦ º¸±â  
±Û¾´ÀÌ ¸Þ½ÃÁö
truefeel
Ä«Æä °ü¸®ÀÚ


°¡ÀÔ: 2003³â 7¿ù 24ÀÏ
¿Ã¸° ±Û: 1277
À§Ä¡: ´ëÇѹα¹

¿Ã¸®±â¿Ã·ÁÁü: 2009.8.21 ±Ý, 10:25 pm    ÁÖÁ¦: 8.20~21 Ä¿ÇǴнº À̾߱â (º¸¾È, Ãë¾àÁ¡, Ç÷¡½¬ ÄíÅ° µî) Àοë°ú ÇÔ²² ´äº¯

°³ÀÎÁ¤º¸ ¾Ïȣȭ, 2009³âµµ »ó¹Ý±â '¾Ç¼ºÄÚµå Á¦°ÅÇÁ·Î±×·¥' ½ÇÅÂÁ¶»ç °á°ú, Ç÷¡½¬ ÄíÅ°ÀÇ Æ¯Â¡°ú »èÁ¦ ¹æ¹ý, ´Ù¾çÇÑ Ãë¾àÁ¡¿¡ ´ëÇÑ °ÍÀ» Á¤¸®Çß´Ù. 8.20(¸ñ)~21(±Ý) Ä¿ÇǴнº À̾߱âÁß¿¡ 'º¸¾È'ºÐ¾ß¸¸ Á¤¸®.

1. °³ÀÎÁ¤º¸ ¾Ïȣȭ¿¡ ´ëÇÑ À̾߱â

    1) DBº¸¾È ¼Ö·ç¼Ç (¾Ïȣȭ + DB Á¢±Ù Á¦¾î)
    2) ÇÁ·Î±×·¥¿¡¼­ ¾Ïȣȭ/º¹È£È­
    3) DB°ÔÀÌÆ®´Ü¿¡¼­ ¾Ïȣȭ/º¹È£È­


2. 09³âµµ »ó¹Ý±â '¾Ç¼ºÄÚµå Á¦°ÅÇÁ·Î±×·¥' ½ÇÅÂÁ¶»ç °á°ú

    http://www.kcc.go.kr/user.do?boardId=1042&page=P05030000&dc=K05030000&boardSeq=26398&mode=view
    http://www.kcc.go.kr/download.do?fileSeq=25897 (hwpÆÄÀÏ ´Ù¿î·Îµå)
    1) 2009. 6¿ù ±âÁØÀ¸·Î ±¹³»¿¡ À¯ÅëµÇ°í ÀÖ´Â 134Á¾ÀÇ ¾Ç¼ºÄÚµå Á¦°Å ÇÁ·Î±×·¥À» ´ë»óÀ¸·Î Ä¡·á¼º´É, ÀÌ¿ë¾à°ü °Ô½Ã, ¹èÆ÷ ¹× °áÁ¦¹æ½Ä, ¼³Ä¡ µ¿ÀÇÈ®ÀÎ µî 38°³ Ç׸ñ¿¡ ´ëÇØ ½ÇŸ¦ Á¶»ç
    2) ¾Ç¼ºÄÚµå Á¦°Å ÇÁ·Î±×·¥ ¿ì¼öÁ¦Ç° 15Á¾À» ¼±Á¤
    - ´Ù¾çÇÑ Á¾·ùÀÇ ¾Ç¼ºÄÚµå »ùÇà 1,500°³¿¡ ´ëÇØ Ä¡·á¼º´É µîÀ» ÃøÁ¤ÇÑ °á°ú, 1,000°³ ÀÌ»óÀÇ ¾Ç¼ºÄڵ带 ŽÁö¡¤Ä¡·áÇÏ°í,
    - ÀÌ¿ë¾à°ü °Ô½Ã µîÀ» ÁؼöÇÑ Á¦Ç°



3. ÄÄÆ®·çÅ×Å©³î·ÎÁö, µðµµ½ºÄ° CCÀÎÁõ °è¾à ü°á

    ÀÌ·± ±â»ç ³ª¿Ã ¶§ '°è¾à ü°á'À̶ó´Â ¸»Àº 'CCÀÎÁõÀ» Åë°úÇß´Ù'´Â Àǹ̰¡ ¾Æ´Ï´Ù.
    CCÀÎÁõÀ» ¹Þ±â À§Çؼ­ ½ÅûÀÌ µÇ¾î¼­ ÀÌÁ¦ ÁøÇàÀÌ µÈ´Ù´Â ÀǹÌÀÌ´Ï Àß ¸ø ÀÌÇØÇÏ´Â ÀÏÀº ¾ø±æ.
    Âü°í·Î 'Æò°¡ ÀÎÁõ Á¦Ç° ( http://www.kisa.or.kr/kisa/kisec/jsp/kisec_3010_04_list.jsp )' ¸ñ·Ï (ÁغñÁ¦Ç°, ÁøÇàÁ¦Ç°, ¿Ï·áÁ¦Ç°)


4. Ãë¾àÁ¡

    1) Squid Infinite Loop in strListGetItem() Lets Remote Users Deny Service
    Squid Ãë¾àÁ¡. ¿ø°Ý À¯Àú°¡ HTTP Çì´õ¸¦ ÀÌ¿ëÇؼ­, ¸ðµç CPU ¸®¼Ò½º¸¦ ¼Ò¸ðÇÒ ¼ö ÀÖ´Ù.
    http://www.securitytracker.com/alerts/2009/Aug/1022757.html
    Àοë:

    A remote user can send specially crafted HTTP header values that use a comma character as a delimiter to cause the strListGetItem() function in 'src/HttpHeaderTools.c' to enter an infinite loop and consume all available CPU resources.


    2) PHP "mail.log" Configuration Option "open_basedir" Restriction Bypass. PHP version 5.3.0 is affected.
    http://www.securityfocus.com/bid/36007

    3) Solaris sendfile and sendfilev Flaw Lets Local Users Deny Service

    4) ÃÖ±Ù milw0rm.com¿¡ µî·ÏµÈ Ãë¾àÁ¡ (ÇöÀç ¹Ð¿ú »çÀÌÆ®°¡ Á¢¼Ó ¾ÈµÈ »óÅÂ¶ó¼­ ´Ù½Ã Çѹø Àû´Â´Ù.)

    Linux Kernel 2.x sock_sendpage() Local Root Exploi... - 2009-08-18
    VUPlayer <= 2.49 (.m3u File) Universal Buffer Over... - 2009-08-18
    asaher pro 1.0.4 Remote Database Backup Vulnerabil... - 2009-08-18
    Traidnt UP 2.0 Remote SQL Injection Exploit - 2009-08-18
    ZTE ZXDSL 831 II Modem Arbitrary Configuration Acc... - 2009-08-18
    Best Dating Script Arbitrary Shell Upload Vulnerab... - 2009-08-18


5. Top websites uing Flash cookies to track user behavior

    http://www.scmagazineus.com/top-websites-using-flash-cookies-to-track-user-behavior/article/141486/

    Àοë:

    Unlike traditional HTTP cookies, Flash cookies are not controlled by the browser, so erasing HTTP cookies does not erase Flash cookies – enabling some websites, particularly advertising networks wishing to track users' browsing habits, to deter users' efforts to avoid being tracked, according to the report.


    Ç÷¡½¬ ÄíÅ°´Â ºê¶ó¿ìÀú¿¡¼­ Á¦¾îÇÒ ¼ö ¾ø°í, HTTP ÄíÅ° »èÁ¦Çصµ Ç÷¡½¬ ÄíÅ°´Â Áö¿öÁö ¾Ê´Â´Ù. ±×·¡¼­, À¥»çÀÌÆ®µéÀº À¯ÀúµéÀÇ ºê¶ó¿ì¡ ½À°üÀ» ÃßÀûÇϱ⸦ ¿øÇϴµ¥, ¹Ù·Î ÀÌ Ç÷¡½¬ ÄíÅ°¸¦ ÀÌ¿ëÇÒ ¼ö ÀÖ´Ù.

    - Ç÷¡½¬ ÄíÅ° »èÁ¦ ( Adobe's Flash Player settings manager
    http://www.macromedia.com/support/documentation/en/flashplayer/help/settings_manager07.html



6. milw0rm.com 21ÀÏ 18½Ã ÇöÀç ¿©ÀüÈ÷ Á¢¼Ó ¾ÈµÅ. (20ÀÏ »õº®¿¡µµ Á¢¼Ó ¾ÈµÆÀ½)

7. CSRF Åø : http://wocares.com/pf3.php


¡Ø Âü¿©ÀÚ : sCag, ÁÁÀºÁøÈ£, Ƽ´Ï, ¿ô´Â³²ÀÚ, ¹ü³ÃÀÌ µî
À§·Î
»ç¿ëÀÚ Á¤º¸ º¸±â ºñ¹Ð ¸Þ½ÃÁö º¸³»±â ±Û ¿Ã¸°ÀÌÀÇ À¥»çÀÌÆ® ¹æ¹®
truefeel
Ä«Æä °ü¸®ÀÚ


°¡ÀÔ: 2003³â 7¿ù 24ÀÏ
¿Ã¸° ±Û: 1277
À§Ä¡: ´ëÇѹα¹

¿Ã¸®±â¿Ã·ÁÁü: 2009.8.23 ÀÏ, 2:18 am    ÁÖÁ¦: Re: milw0rm.com ÀÌÁ¦ Á¢¼ÓµÇ³×¿ä. Àοë°ú ÇÔ²² ´äº¯

truefeel ¾¸:

4) ÃÖ±Ù milw0rm.com¿¡ µî·ÏµÈ Ãë¾àÁ¡ (ÇöÀç ¹Ð¿ú »çÀÌÆ®°¡ Á¢¼Ó ¾ÈµÈ »óÅÂ¶ó¼­ ´Ù½Ã Çѹø Àû´Â´Ù.)

Linux Kernel 2.x sock_sendpage() Local Root Exploi... - 2009-08-18
VUPlayer <= 2.49 (.m3u File) Universal Buffer Over... - 2009-08-18
asaher pro 1.0.4 Remote Database Backup Vulnerabil... - 2009-08-18
Traidnt UP 2.0 Remote SQL Injection Exploit - 2009-08-18
ZTE ZXDSL 831 II Modem Arbitrary Configuration Acc... - 2009-08-18
Best Dating Script Arbitrary Shell Upload Vulnerab... - 2009-08-18 [/list]
... »ý·« ...

6. milw0rm.com 21ÀÏ 18½Ã ÇöÀç ¿©ÀüÈ÷ Á¢¼Ó ¾ÈµÅ. (20ÀÏ »õº®¿¡µµ Á¢¼Ó ¾ÈµÆÀ½)


¿ì¸®½Ã°£À¸·Î ÃÖ¼Ò 20ÀÏ »õº®ºÎÅÍ Á¢¼ÓÀÌ µÇÁö ¾Ê¾Ò´ø, http://www.milw0rm.com/ »çÀÌÆ®°¡ 23(ÀÏ) AM 01:00 ¿¡ Á¢¼ÓÇß´õ´Ï Á¢¼ÓÀÌ µË´Ï´Ù. DDoS °ø°ÝÀ» ¹Þ¾Æ¼­ /24 ³×Æ®¿÷ÀÌ Åëä·Î ¸·Èù °ÍÀ¸·Î º¸ÀÔ´Ï´Ù.

Á¢¼Ó¾È µÉ ¶§ DNS Á¤º¸¸¦ °®°í À־ IP ºñ±³¸¦ Çغôµ¥, IP°¡ º¯°æµÇ¾ú³×¿ä.

* 20ÀÏ~Á¢¼ÓµÇ±â Àü±îÁö IP : 76.74.9.18
* ÇöÀç IP : 66.227.17.18

¹Ð¿ú »çÀÌÆ®°¡ 'ĵĿÇÇ'ÀÇ 7¿ù ÀÏÁ¤( http://can.coffeenix.net/ )¿¡¼­µµ º¸À̵íÀÌ 7¿ù 8ÀÏ¿¡µµ Çѹø ¹®À» ´Ý°í, ´Ù½Ã 10ÀÏ¿¡ Á¤»ó ¿ÀÇÂÇÑ ÀûÀÌ ÀÖ½À´Ï´Ù. ¿äÁò ÀÚÁÖ ÀÌ·¯³×¿ä.
±×¸®°í, ¹Ð¿úÀÌ Á¢¼Ó¾ÈµÉ ¶§´Â Àӽ÷Πinj3ct0r.com ( Æ®À§ÅÍ : http://twitter.com/inj3ct0r )¸¦ ÀÌ¿ëÇϱæ.
À§·Î
»ç¿ëÀÚ Á¤º¸ º¸±â ºñ¹Ð ¸Þ½ÃÁö º¸³»±â ±Û ¿Ã¸°ÀÌÀÇ À¥»çÀÌÆ® ¹æ¹®
ÀÌÀü ±Û Ç¥½Ã:   
±Û ¾²±â   ´äº¯ ´Þ±â    Ä¿ÇǴнº, ½Ã½ºÅÛ ¿£Áö´Ï¾îÀÇ ½°ÅÍ °Ô½ÃÆÇ À妽º -> *NIX / IT Á¤º¸ ½Ã°£´ë: GMT + 9 ½Ã°£(Çѱ¹)
ÆäÀÌÁö 1 Áß 1

 
°Ç³Ê¶Ù±â:  
»õ·Î¿î ÁÖÁ¦¸¦ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù
´ä±ÛÀ» ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù
ÁÖÁ¦¸¦ ¼öÁ¤ÇÒ ¼ö ¾ø½À´Ï´Ù
¿Ã¸° ±ÛÀ» »èÁ¦ÇÒ ¼ö ¾ø½À´Ï´Ù
ÅõÇ¥¸¦ ÇÒ ¼ö ¾ø½À´Ï´Ù


Powered by phpBB © 2001, 2005 phpBB Group