|
Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
|
|
|
|
ÀÌÀü ÁÖÁ¦ º¸±â :: ´ÙÀ½ ÁÖÁ¦ º¸±â |
±Û¾´ÀÌ |
¸Þ½ÃÁö |
truefeel Ä«Æä °ü¸®ÀÚ
°¡ÀÔ: 2003³â 7¿ù 24ÀÏ ¿Ã¸° ±Û: 1277 À§Ä¡: ´ëÇѹα¹
|
¿Ã·ÁÁü: 2004.12.27 ¿ù, 11:25 pm ÁÖÁ¦: Santy.C º¯Á¾ ÁÖÀÇ (PHP ÇÁ·Î±×·¥ °ø°Ý) |
|
|
Ãâó : Çæ·©ÀÌ¿Í ITº¸¾È, http://swbae.egloos.com/851603/
Àοë: |
ÇØ¿Ü º¸¾È ¾÷üÀÎ iMPERVA´Â Ãë¾àÇÑ À¥ ¾îÇø®ÄÉÀ̼ÇÀ» ÅëÇØ ¾Ç¼º ÇÁ·Î±×·¥(¿ú, ¹ÙÀÌ·¯½º)ÀÌ ÆÛÁú °¡´É¼ºÀ» °æ°íÇØ¿ÔÁÒ. - Âü°í ÀÚ·á
Àú´Â ÃæºÐÈ÷ °¡´ÉÇÑ À̾߱â¶ó°í »ý°¢ÇßÀ¸³ª, 3~4³â µÚ¿¡³ª ´Ù°¡¿Ã ÀÏ·Î »ý°¢Çߴµ¥, ¿¹»óº¸´Ù
»¡¸®´Ù°¡¿À³×¿ä.
±âÁ¸ÀÇ Santy ¿úÀº phpBB¶ó´Â °Ô½ÃÆÇ ÇÁ·Î±×·¥À» »ç¿ëÇÏ´Â °÷¸¸À» °ø°ÝÇÏ¿´À¸³ª, »õ·Î³ª¿Â Santy.C º¯ÇüÀº PHP¸¦ »ç¿ëÇÏ´Â ¸ðµç ÇÁ·Î±×·¥À» °ø°ÝÇϵµ·Ï ¼öÁ¤µÇ¾ú½À´Ï´Ù.
PHP ÇÁ·Î±×·¡¸Ó°¡ º¸¾È»óÀÇ °áÇÔÀÌ ÀÖ´Â ÇüÅÂ(include, require ÇÔ¼ö¸¦ Ãë¾àÇÏ°Ô »ç¿ëÇÑ °æ¿ì)·Î ÇÁ·Î±×·¥À» § °æ¿ì, Santy.C ¿ú¿¡ °ø°Ý´çÇÏ°Ô µË´Ï´Ù.
Santy.C´Â ±¸±Û ºê¶óÁú »çÀÌÆ®¸¦ ÀÌ¿ëÇØ °ø°Ý ´ë»óÀ» ã¾Æ³½ ÈÄ ÇØ´ç ÇÁ·Î±×·¥ÀÌ »ç¿ëÇÏ´Â ÀÎÀÚ(parameter)¿¡ ÀÚ½ÅÀÌ ¿øÇÏ´Â ¸í·É¾î¸¦ ´ëÀÔ½ÃŰ´Â ÇüÅ·Π¿ú¿¡ °¨¿°½Ãŵ´Ï´Ù. ÀÌ·± °ø°Ý ±â¹ýÀº ±âÁ¸¿¡ ÇØÄ¿µéÀÌ Áñ°Ü »ç¿ëÇÏ´ø ±â¹ýÀ¸·Î, ¹ÙÀÌ·¯½º, ¿ú, ÇØÅ·ÀÇ °æ°è°¡ ³ª³¯ÀÌ ¸ðÈ£ÇØÁö°í ÀÖÀ½À» Àß º¸¿©ÁÖ°í ÀÖ´Ù°í ÇϰڽÀ´Ï´Ù.
- Âü°í ÀÚ·á : http://www.securityfocus.com/archive/1/385463/2004-12-23/2004-12-29/0
±¹³»¿¡¼ ¸¹ÀÌ »ç¿ëµÇ´Â Á¦·Îº¸µå, ±×´©º¸µå¶ó´Â °Ô½ÃÆÇµµ ¿ª½Ã Santy.CÀÇ °ø°Ý¿¡ Ãë¾àÇÕ´Ï´Ù. ÇØ´ç °Ô½ÃÆÇ »ç¿ëÀÚ´Â ÃÖ±Ù ¹ßÇ¥µÈ Ãë¾àÁ¡ ÆÐÄ¡¸¦ ¹Ýµå½Ã Àû¿ëÇÏ¿©¾ß ÇÕ´Ï´Ù.
Á¦·Îº¸µå º¸¾È Ãë¾àÁ¡ Á¤º¸ : http://www.webappsecure.com/bbs/stories.php?story=04/12/24/0938137
±×´©º¸µå º¸¾È Ãë¾àÁ¡ Á¤º¸ : http://www.securityfocus.com/archive/1/384522/2004-12-13/2004-12-19/0
ÀÌ ¿úÀÇ µ¶Æ¯ÇÑ °ø°Ý ¹æ½ÄÀ¸·Î ÀÎÇØ ±âÁ¸¿¡ Ãë¾àÁ¡ÀÌ ¹ß°ßµÇÁö ¾ÊÀº PHP ¾îÇø®ÄÉÀ̼ÇÀÇ °æ¿ì¿¡µµ °ø°Ý´çÇÒ ¼ö ÀÖÀ¸´Ï ÁÖÀǰ¡ ÇÊ¿äÇÕ´Ï´Ù.
Apache »ç¿ëÀÚ¶ó¸é ´ÙÀ½ÀÇ 2°¡Áö ¹æ¹ý Áß Çϳª¸¦ »ç¿ëÇÏ¿© °ø°Ý¿¡ ´ëóÇÒ ¼ö ÀÖ½À´Ï´Ù.
¹æ¹ý 1. ȯ°æ ¼³Á¤ ÆÄÀÏ(httpd.conf) ¼öÁ¤
ÄÚµå: |
SetEnvIf User-Agent "LWP::" get_lost
SetEnvIf User-Agent "lwp-trivial" get_lost
<Directory /*>
Order Allow,Deny
Deny from env=get_lost
Allow from all
</Directory>
|
¹æ¹ý 2. mod_rewirte »ç¿ë
ÄÚµå: |
<Directory /*>
RewriteEngine On
RewriteCond %{QUERY_STRING} ^(.*)spy\.gif(.*)
RewriteRule ^.*$ - [F]
</Directory>
|
Âü°í·Î ÇØ¿Ü º¸¾È ¾÷ü°¡ ºÐ¼®ÇÑ ¿úÀÇ °³°ýÀûÀÎ ¼Ò½º¸¦ µ¡ºÙÀÔ´Ï´Ù.
K-Otik ÀÇ Santy.C ºÐ¼® ¼Ò½º : http://www.k-otik.com/exploits/20041225.PhpIncludeWorm.php
|
|
|
À§·Î |
|
 |
|
|
»õ·Î¿î ÁÖÁ¦¸¦ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù ´ä±ÛÀ» ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù ÁÖÁ¦¸¦ ¼öÁ¤ÇÒ ¼ö ¾ø½À´Ï´Ù ¿Ã¸° ±ÛÀ» »èÁ¦ÇÒ ¼ö ¾ø½À´Ï´Ù ÅõÇ¥¸¦ ÇÒ ¼ö ¾ø½À´Ï´Ù
|
Powered by phpBB © 2001, 2005 phpBB Group
|