|
ÀÛ¼ºÀÚ : ÁÁÀºÁøÈ£(truefeel, http://coffeenix.net/ )
ÀÛ¼ºÀÏ : 2003.9.21(ÀÏ)
Swen ¿ú(Win32.Swen@mm.worm, ½ºÀ¢ ¿ú)ÀÌ ±¹³»¿¡µµ µé¾î¿Ô´Ù°í Çϴµ¥, ¾ÆÁ÷ ¹Þ¾Æº¸Áö ¸øÇß½À´Ï´Ù.
µû¶ó¼ ¾Æ·¡ ¼³Á¤À» Å×½ºÆ®´Â ¸øÇß½À´Ï´Ù. ¹Ì¸® ÁغñÇÑ´Ù°í ¼ÕÇØº¼ °Íµµ ¾ø°ÚÁÒ?
Swen¿úÀÌ ¸ÞÀϷθ¸ ÀüÆÄµÇ´Â °ÍÀÌ ¾Æ´Ï°í KaZaA P2P ÇÁ·Î±×·¥°ú IRC(mIRC ÀÌ¿ë),
°øÀ¯µÈ ³×Æ®¿öÅ© Æú´õ¸¦ ÅëÇØ¼µµ ÀüÆÄµË´Ï´Ù.
´ÙÀ½Àº ¿Ü±¹ÀÇ ÇÑ ´º½º±×·ì¿¡ Æ÷½ºÆÃµÆ´ø ÇÊÅ͸µ ¼³Á¤ÀÔ´Ï´Ù. (ºóÁÙ Æ÷ÇÔ 11ÁÙ)
/etc/procmailrc ¿¡ Ãß°¡ÇÏ¸é µË´Ï´Ù.
--------------------------------------------------
SPAM_LOG = "/var/log/spam.log"
:0
* > 140000
* < 165000
{
:0 BD
* b3IAAABBZG1pbgAAAEdFVCBodHRwOi8vd3cyLmZjZS52dXRici5jei9iaW4vY291bnRlci5naWYv
$SPAM_LOG
}
--------------------------------------------------
¸ÞÀÏ Å©±â°¡ 140K~165KÀ̰í,
º»¹®¿¡ b3I... °¡ Æ÷ÇÔµÈ °ÍÀº Swen ¿úÀ¸·Î °£ÁÖÇÏ¿© $SPAM_LOG¿¡ ÀúÀåÇØµÓ´Ï´Ù.
¿úÀ» ÀúÀåÇØ µÑ ÇÊ¿ä¾øÀ¸¸é $SPAM_LOG ´ë½Å¿¡ /dev/null·Î.
Swen ¿úÀÌ Á¦¸ñÀ̳ª ÷ºÎÆÄÀϸíÀÌ ÀÏÁ¤ÇÏÁö ¾Ê±â ¶§¹®¿¡ Àú·± Çü½ÄÀ¸·Î ÇÊÅ͸µÇÕ´Ï´Ù¸¸
ÇѰ¡Áö ´Ù¸¥ Ư¡ Áß¿¡ 'subject:'ÀÌ ´ë¹®ÀÚ¶ø´Ï´Ù.
µû¶ó¼ ´ÙÀ½°ú °°Àº ÇüÅ·εµ °¡´ÉÇÕ´Ï´Ù. (ºóÁÙ Æ÷ÇÔ 5ÁÙ)
--------------------------------------------------
SPAM_LOG = "/var/log/spam.log"
:0 D
* ^SUBJECT:
$SPAM_LOG
--------------------------------------------------
Swen ¿úÀÇ »ó¼¼ÇÑ Á¤º¸´Â
http://www.certcc.or.kr/cvirc/Alert/warning/2003/W32_Swen@mm_worm.html
http://home.ahnlab.com/smart2u/virus_detail_1220.html
|