Korea FreeBSD Users Group News, Internal, Projects, Home
Software, Support, Documentation

Re: ¼Ó¼ÓÆí - ÇØÅ·½Ãµµ- Àç¹ß



[ ³¯Â¥¼ø »öÀÎ ] [ ´ñ±Û¼ø »öÀÎ ] [ ÃÖ»óÀ§ »öÀÎ]

[ÀÌÀü ±Û] [´ÙÀ½ ±Û] [ÀÌÀü ´ñ±Û] [´ÙÀ½ ´ñ±Û]


On Fri, Oct 04, 2002 at 03:56:50PM -0700, sammycom wrote:
 >> ¼Ó¼ÓÆí - ÇØÅ·½Ãµµ-Àç¹ß
 >> 
 >> ¹®Á¦µÇ´ø FreeBSD¼­¹ö(66.218.xxx.133)¸¦ ´Ù½Ã ?V¾÷ÇÏ°í³ª¼­ ÀÏÁÖÀϰ£Àº ¸ðµç°Ô Á¤»óÀûÀÎ°Í °°´õ´Ï
 >> ¶È°°Àº ¹®Á¦°¡ ´Ù½Ã °Ô¼ÓÀϾ´Ï´Ù.
 >> ¾ÆÆÄÄ¡+ssl ¹®Á¦ÀÎ°Í °°¾Æ¼­ httpd¸¦ ¾Æ¿¹ Á׿©¹ö¸®°í, named ±îÁö Áö¿öµµ ¸¶Âù°¡Áö¿¡¿ä ÀÌ ¼­¹ö¸¸ ³×Æ®¿ö¿¡ ¹°¸®¸é
 >> ´Ù¸¥ ³ª¸ÓÁöÀÇ ¾ÆÀÌÇÇ ÄÄ(66.218.xx.132) ¿¡¼­µµ default gateway(66.218.xx.1) ±îÁöµµ ÀÎÅͳÝÀÌ ³ª±âÁú ¸øÇÔ´Ï´Ù.
 >> ±×¸®°í ·Î±×ÆÄÀÏ(/var/log/messages)¿¡ ´ÙÀ½°ú °°Àº ·Î±×°¡ 1Ãʰ£°ÝÀ¸·Î ½×ÀÔ´Ï´Ù.
 >> ·Î±×ÆÄÀÏ¿¡¸¸ ½×ÀÌ´Â°Ô ¾Æ´Ï°í Äָܼð´ÏÅÍ¿¡ °Ô¼Ó ³ª¿É´Ï´Ù.
 >> 
 >> Limiging icmp unreach from 204 to 200 packet per second
 >> Limiging icmp unreach from 271to 200 packet per second
 >> Limiging icmp unreach from 231to 200 packet per second
 >> Limiging icmp unreach from 220to 200 packet per second
 >> ...(¾ÆÀÌÇÇ ¹øÈ£°°Àº°Å´Â ¾ø±¸¿ä)
 >> 
½Ã½ºÅÛÀÇ ÇØÅ·ÀÌ Àǽɽº·´½À´Ï´Ù.
1. ICMP port unreachable code´Â UDP·Î Á¢¼Ó½Ãµµ½Ã ÇØ´ç ¼­¹ö¿¡ ¼­ºñ½º°¡
   ¾øÀ» °æ¿ì Á¢¼ÓÇÑ ¼­¹ö¿¡¼­ »ý¼ºÇÕ´Ï´Ù.
   ÇØÅ·µÈ ÈÄ rootkit°°Àº °ÍÀÌ ¼³Ä¡µÇ¾î¼­ ´Ù¸¥ ¿©·¯ ½Ã½ºÅÛÀ» °Ë»çÇϰí ÀÖÀ» °æ¿ì
   ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù.

2. ÀÌ ½Ã½ºÅÛ¸¸ ¿¬°áÇÏ¸é ´Ù¸¥ ½Ã½ºÅÛµµ networkÀÌ µÇÁö ¾Ê´Â´Ù°í Çϴ°ÍÀ» º¸¸é
   ¾Æ¸¶µµ ÀÌ ½Ã½ºÅÛ¿¡¼­ network¿¡ »ó´çÇÑ ºÎÇϸ¦ ÁÖ´Â ÀÏÀ» Çϰí ÀÖÀ» ¼ö ÀÖ½À´Ï´Ù.

°°Àº ¹öÁ¯ÀÇ ±ú²ýÇѽýºÅÛ°ú hash °ªÀ» ºñ±³ÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù.
cksum(1), sum(1)Àº È¿°ú°¡ ¾ø°í ¹Ýµå½Ã Cryptographic HashingÀ» »ç¿ëÇØ¾ß ÇÕ´Ï´Ù.
´ëÇ¥ÀûÀÎ °ÍÀ¸·Î´Â MD5, RIPEMD160 µîÀÌ ÀÖ½À´Ï´Ù.
MD5°ªÀº md5(1)³ª openssl(1)·Î ±¸ÇÒ ¼ö ÀÖ½À´Ï´Ù.
ÃÖ¼ÒÇÑ ´ÙÀ½ÀÇ ÇÁ·Î±×·¥¿¡ ´ëÇØ¼­ ¸ðµÎ °Ë»çÇϰí Çϳª¶óµµ ´Ù¸¥°ÍÀÌ ÀÖ´Ù¸é
µ¥ÀÌŸ ¹é¾÷ÈÄ ½Ã½ºÅÛÀ» »õ·Î ¼³Ä¡Çϼ¼¿ä.

ls, ps, ifconfig, md5, openssl, top, netstat,
sockstat, fstat, sshd, inetd, telnetd, syslogd µî 

 >> 
 >> ¾î´ÀºÐ Á¶¾ð´ë·Î °°Àº ¼­ºê³Ý(66.218.32.0/19 : 66.218.32.0 - 66.218.63.255) 
 >> À» »ç¿ëÇÏ´Â ±× ÁÖº¯µ¿³×(¶Ç´Â) ÀÇ ¹ÙÀÌ·¯½º°¨¿°µÈ Äͧ¹®¿¡ ±×·²¼öµµ ÀÖ´Â°Í °°¾Æ¼­ ISP ¿¡ ¹®ÀÇ, Ç×ÀÇ ÇßÁö¸¸.
 >> 
 >> ISP ¿Ð :  ÁøÂ¥·Î ¾î´À ¾ÆÀÌÇÇÀÇ ¹ÙÀÌ·¯½º¶§¹®ÀÎÁö È®ÀÎÇÒ¼öµµ ¾ø´Â »óȲ¿¡¼­ ·Î±×ÆÄÀϸ¸ °®°í¼­ 
 >> ip¼ÒÀ¯ÇÑ »ç¿ëÀÚ ÀÏÀÏÀÌ ³Ê³× ÄĹÙÀÌ·¯½º¶§¹®¿¡ °°Àº Áö¿ª ´Ù¸¥»ç¿ëÀÚ°¡ ÇÇÇØº»´Ù°í  ÇÒ¼öµµ ¾ø°í ¶Ç °¡°¢ »ç¿ëÀÚÀÇ ¹ÙÀÌ·¯½º ¹®Á¦±îÁö °£¼·Çϰųª È®ÀÎÇÒ¼öÀÖ´Â ¹®Á¦°¡ ¾Æ´Ï¶ó°í ¸¸ ÇÏ´Ï , ±× ¶ÇÇÑ Àϸ®ÀÖ´Â ¸»À̱⵵ ÇÕ´Ï´Ù.
 >> 
¸Â½À´Ï´Ù. ISP°¡ ÃëÇÒ ¼ö ÀÖ´Â Á¶Ä¡¶ó´Â°ÍÀº °ÅÀÇ ¾ø½À´Ï´Ù.
±â²¯ÇØ¾ß ISP°¡ °ü¸®ÇÏ´Â ¼­¹öÁß ¹®Á¦ÀÖ´Â ¼­¹öÀÇ ºÐ¸®Á¤µµ ÀÔ´Ï´Ù.
ÀÌ ¸¶Àúµµ ¸¹ÀÌ ÁÖÀúÇÏ´Â ÆíÀÌÁÒ.

 >> ±×¸®°í httpd ·Î±×ÆÄÀϺ¸´Ï±î 66.218.xxx.yyy: ....scipt/winnt/cmd.exe ¾î¼±¸ ÇÏ´Â ÁÙÀÌ ²À °°Àº ¼­ºê³Ý¿¡¼­
 >> µé¾î¿À´Â°Íµµ ÀÖÁö¸¸ 
 >> 24.xxx.xxx.xxx: : ....scipt/winnt/cmd.exe 
 >> 206.xxx.xxx.xx. : ....scipt/winnt/cmd.exe 
 >> ..
 >> ÀÌ·¸°Ô ÀüÇô ´Ù¸¥ ³×Æ®¿öÅ© ÁÖ¼Ò¿¡¼­µµ µé¾î¿À´õ¶ó±¸¿ä.
 >> 
 >> ÀÌ·²¶§´Â ¾î¶»°Ô ÇØ¾ßÇÒÁö ¸ð¸£°Ú³×¿ä
ÀÌ°Ç ¾î´À¼­¹ö¿¡³ª ÀÖ´Â Á¤»óÀûÀÎ Çö»óÀÔ´Ï´Ù.
ÀÎÅͳݻ󿡼­´Â ¹ÙÀÌ·¯½º³ª ¿ú¿¡ °¨¿°µÈ ¼­¹öµéÀÌ °ø°Ý´ë»óÀ» Ç×»ó ã°í Àְŵç¿ä.
±×¸®°í ÇØÅ°À» °øºÎ(?)ÇÏ´Â Ãʺ¸ÀÚµéÀÌ °ø°ÝÇÁ·Î±×·¥À» ±¸Çؼ­ ½ÃÇèÇϱ⵵ ÇÕ´Ï´Ù.

-- 
============================================================
// Korea Telecom Internet Solutions, Inc.
//   FreeBSD/Linux Professional Consulting/Tech. Support
// 
// Pyun YongHyeon
//
// WWW: http://www.kt-is.co.kr/
// FTP: ftp://ftp.kt-is.co.kr/
//
// TEL: +82-2-364-0400
// FAX: +82-2-364-9119
============================================================
--
Please look and take part in KFUG FAQ: <http://www.kr.freebsd.org/FAQ-kr/>
To Unsubscribe: send mail to majordomo@kr.FreeBSD.org
with "unsubscribe questions" in the BODY of the message



[ ³¯Â¥¼ø »öÀÎ ] [ ´ñ±Û¼ø »öÀÎ ] [ ÃÖ»óÀ§ »öÀÎ]

Copyright © 1998-2005 Korea FreeBSD Users Group.
All rights reserved. webmaster at kr.FreeBSD.org
$Date: 2002/10/31 23:00:24 $
Powered by FreeBSD