Korea FreeBSD Users Group News, Internal, Projects, Home
Software, Support, Documentation

Re : Ãʺ¸ÀÚÀÇ º¸¾È°ü¸®



[ ³¯Â¥¼ø »öÀÎ ] [ ´ñ±Û¼ø »öÀÎ ] [ ÃÖ»óÀ§ »öÀÎ]

[ÀÌÀü ±Û] [´ÙÀ½ ±Û] [ÀÌÀü ´ñ±Û] [´ÙÀ½ ´ñ±Û]


¾È³çÇϼ¼¿ä~


> °­ÀÇ º¸Á¶¿ëÀ¸·Î À¥¼­¹ö¸¦ ±¸ÃàÇÒ·Á°í ¿Àǹöµå¿¡¼­ 4.4 ¹öÀü ½Ãµð
±¸ÀÔÇÏ¿© »ç¹«½Ç¿¡ ÀÖ´Â ÄÄÇ»ÅÍ¿¡ ÇÁ¸®ºñ¸¦ ±ò°í
> Áý¿¡¼­ ftp¿Í telnetÀ» ÀÌ¿ëÇÏ¿© ȨÆäÀÌÁö Á¦ÀÛÁßÀ̾ú´Âµ¥ ´©±º°¡°¡
ħÀÔÇÏ¿© rootÀÇ ¾ÏÈ£¸¦ ¹Ù²ã³õÀº°Í °°½À´Ï´Ù.  »ç¹«½Ç


¸¸¾à ±×·¸´Ù¸é,

telnet °æ¿ì¿£ »ç¿ëÇÏÁö ¾Ê´Â °ÍÀÌ ¹Ù¶÷Á÷ ÇÕ´Ï´Ù. ½º´ÏÇÎÀÇ ¿ì·Áµµ ÀÖ°í,
BSD°è¿­ÀÇ telnetd¿¡¼­ Ãë¾à¼ºÀÌ
¹ß°ßµÇ¾ú±â ¶§¹®À̱⵵ Çϰí¿ä. °¡±ÞÀûÀ̸é ssh¸¦ »ç¿ëÇÏ´Â °ÍÀÌ
¹Ù¶÷Á÷ÇÕ´Ï´Ù. (¹°·Ð, ssh µ¥¸ó¿¡ ´ëÇÑ
Ãë¾à¼ºÀÌ º¸°íµÇ°í ÀÖÁö¸¸, ÃÖ¼ÒÇÑ ³×Æ®Ÿp ½º´ÏÇο¡¼­´Â ¾ÈÀüÇÒ ¼ö Àְŵç¿ä
^^)

FTP °æ¿ì¿£, »ç¿ëÀ» ÇØ¾ß ÇÑ´Ù¸é Anonymous·Î Á¢±ÙÀ» Çã°¡ ÇØ¼­´Â ¾ÈµË´Ï´Ù.
±×¸®°í ftpº¸´Ù´Â scpµîÀ»
½À°üÈ­ ÇÏ´Â °Íµµ ÁÁÀ» °Í °°½À´Ï´Ù.

±× ¹Û¿¡ ³ª¸ÓÁö ¿ÀÇÂµÈ Æ÷Æ®µµ üũ¸¦ ÇϽô °ÍÀÌ ÁÁÀ» °Í °°½À´Ï´Ù.

±×¸®°í, °­ÀÇ º¸Á¶·Î À¥ ¼­¹ö¸¦ ±¸ÃàÇϰí ÀÖ´Ù¸é, À¥ ¼­¹ö ±¸Ãà½Ã °ø°³µÇ¾î
ÀÖ´Â °Ô½ÃÆÇÀ̳ª ÅøÀ» »ç¿ëÇϰí
ÀÖ´Ù¸é ±× °ø°³µÈ ÅøÀÇ Ãë¾à¼ºµµ °ËÅäÇØ¾ß ÇÕ´Ï´Ù. ¿äÁîÀ½, PHP·Î ±¸ÇöµÈ
°ø°³ Åø(php-nuke)ÀÇ Ãë¾à¼ºÀ»
°ø°ÝÇÏ¿© ¿ø°Ý¿¡¼­ ·çÆ® ±ÇÇÑÀ» ¾òÀ» ¼ö ÀÖ´Â Ãë¾à¼ºÀÌ ¹ß°ßµÇ¾ú±â
¶§¹®ÀÔ´Ï´Ù.


> ÃâÀÔÇÑ »ç¶÷Àº ¾øÀ»°É·Î ¹Ï±â ¶§¹®¿¡ ÇØÄ¿ÀÇ ÁþÀ¸·Î ÁüÀÛÇϰí ÀÖ½À´Ï´Ù.
ÀÌ·± ÀÏÀÌ ¾î¶»°Ô °¡´ÉÇÏ°Ô µÇ¾ú´ÂÁö


-> Ãë¾à¼ºÀ» °ø°ÝÇÒ ¼ö ÀÖ´Â ÀͽºÇ÷ÎÀÕÀ» ÀÌ¿ëÇÏ¸é °¡´É ÇÒ °ÍÀ¸·Î
º¸ÀÔ´Ï´Ù. ±×¸®°í ³»ºÎÀÚÀÇ ¼ÒÇ൵ À½.........

-> Ȥ½Ã ±× ½Ã½ºÅÛ¿¡ ·ÎÄà »ç¿ëÀÚ °èÁ¤ÀÌ ¹ß±ÞµÇ¾î ÀÖ´Ù¸é, ±× ·ÎÄà »ç¿ëÀÚÀÇ
È÷½ºÅ丮µµ °ËÅäÇØ º¼ Çʿ䰡 ÀÖ½À
    ´Ï´Ù. ·ÎÄà ½Ã½ºÅÛ¿¡¼­ ÇØÅ·ÀÌ remote ÇØÅ·º¸´Ù ÈÎ ½±±â ¶§¹®ÀÔ´Ï´Ù.



> ¾Ë°í½Í±º¿ä.  ±×¸®°í ´Ù½Ã ÀÌ·± ÀÏÀ» ´çÇÏÁö ¾Ê±â À§Çؼ­´Â ¾î¶² Á¶Ä¡¸¦
ÇØÇá ÇÏ´ÂÁö ¸»¾¸ÇØ ÁÖ½Ã¸é °¨»çÇϰڽÀ´Ï´Ù.


¸ÕÀú, ÇØÅ· À¯¹«¿¡ ´ëÇØ¼­ ÇÇÇØ Á¶»ç¸¦ ÇØº¼ Çʿ䰡 ÀÖÀ» °Í °°½À´Ï´Ù.

Âü°íÇÒ ¸¸ÇÑ ¹®¼­´Â,

-> http://www.certcc.or.kr/paper/tr2001/tr2001-03/Scene-of-the-Crime.pdf

-> http://www.certcc.or.kr/paper/tr2001/tr2001-05/unix_log_analysis.pdf
->
http://www.certcc.or.kr/paper/tr2001/tr2001-07/Unix_log_analysis_II.pdf

µîÀÌ ÀÖ½À´Ï´Ù. (·çƮŶ ¼³Ä¡µÇ¾î ÀÖÀ» ¼ö Àֱ⠶§¹®¿¡, ÇØÅ·´çÇÏÁö ¾ÊÀº
½Ã½ºÅÛ¿¡¼­ üũ°ü·Ã ÆÄÀÏ(ps,netstat,
find,ls,w µîµî)À» º¹»çÇÏ¿© üũ ÇÏ´Â °ÍÀÌ ÁÁÀ» °Í °°½À´Ï´Ù.)

Á¶»ç °á°ú°¡ ÇØÅ·À¸·Î ÆÇ´ÜµÇ¾ú´Ù¸é, ½Ã½ºÅÛÀ» À缳ġ ÇÏ´Â °ÍÀÌ
¹Ù¶÷Á÷ÇÕ´Ï´Ù. Àç ¼³Ä¡ Çϱâ À§ÇØ µ¥ÀÌŸ¸¦
¹é¾÷ ¹ÞÀ» ¶§ ·çƮŶ¸¶Àú ¹é¾÷À» ¹ÞÀ» ¼ö Àֱ⠶§¹®¿¡ Á¶½ÉÇØ¾ß ÇÕ´Ï´Ù. ƯÈ÷
CGIÇü½ÄÀÇ ·çƮŶÀ» È®ÀÎÇÒ ÇÊ¿ä
°¡ ÀÖÀ» °ÍÀ¸·Î º¸ÀÔ´Ï´Ù.

´ÙÀ½Àº FreeBSD Security How-To °ü·ÃµÈ ¹®¼­ÀÔ´Ï´Ù. Âü°íÇÏ½Ã±æ ¹Ù¶ø´Ï´Ù.
http://people.freebsd.org/~jkb/howto.html

±×¸®°í, rootÀÇ ±ÇÇѵµ Á¦ÇѽÃų ¼ö ÀÖ´Â ¼­¹ö º¸¾È Á¦Ç°À» ¼³Ä¡ÇØ º¸´Â °Íµµ
ÁÁÀ» °Í °°½À´Ï´Ù. FreeBSD¿ë °ø°³¿ë
ÅøÀÌ ÀÖÀ» °Í °°Àºµ¥¿ä, ¸®´ª½º °æ¿ì¿£ LIDS¶ó´Â ¼­¹öº¸¾È Á¦Ç°ÀÌ À־
°ø°´µÈ ¼­¹ö¿¡ ¼³Ä¡Çϸé ÇØÅ· ´çÇØµµ ÇÇÇØ
¸¦ ÃÖ¼ÒÈ­ ½Ãų ¼ö ÀÖ´Â ÀåÁ¡ÀÌ ÀÖ½À´Ï´Ù.



> Âü°í·Î ÀÌ Áú¹®À» Ȥ½Ã °Ô½ÃÆÇ¿¡ ¿Ã¸®½Ã·Á¸é À͸íÀ¸·Î ÇÏ¿© Áֽðí ÀúÀÇ
email ÁÖ¼Òµµ °ø°³ÇÏÁö ¸»¾Æ ÁÖ½Ã±æ ¹Ù¶ø´Ï´Ù.

 ?

> ±×·³ ÁÁÀº ¸»¾¸ °í´ëÇÕ´Ï´Ù.  ¿À¿µ±â ¿Ã¸²

--
To Unsubscribe: send mail to majordomo@kr.FreeBSD.org
with "unsubscribe questions" in the BODY of the message



[ ³¯Â¥¼ø »öÀÎ ] [ ´ñ±Û¼ø »öÀÎ ] [ ÃÖ»óÀ§ »öÀÎ]

Copyright © 1998-2005 Korea FreeBSD Users Group.
All rights reserved. webmaster at kr.FreeBSD.org
$Date: 2002/03/26 13:37:51 $
Powered by FreeBSD