|
News,
Internal,
Projects,
Home Software, Support, Documentation |
On Fri, Oct 04, 2002 at 03:56:50PM -0700, sammycom wrote: >> ¼Ó¼ÓÆí - ÇØÅ·½Ãµµ-Àç¹ß >> >> ¹®Á¦µÇ´ø FreeBSD¼¹ö(66.218.xxx.133)¸¦ ´Ù½Ã ?V¾÷ÇÏ°í³ª¼ ÀÏÁÖÀϰ£Àº ¸ðµç°Ô Á¤»óÀûÀÎ°Í °°´õ´Ï >> ¶È°°Àº ¹®Á¦°¡ ´Ù½Ã °Ô¼ÓÀϾ´Ï´Ù. >> ¾ÆÆÄÄ¡+ssl ¹®Á¦ÀÎ°Í °°¾Æ¼ httpd¸¦ ¾Æ¿¹ Á׿©¹ö¸®°í, named ±îÁö Áö¿öµµ ¸¶Âù°¡Áö¿¡¿ä ÀÌ ¼¹ö¸¸ ³×Æ®¿ö¿¡ ¹°¸®¸é >> ´Ù¸¥ ³ª¸ÓÁöÀÇ ¾ÆÀÌÇÇ ÄÄ(66.218.xx.132) ¿¡¼µµ default gateway(66.218.xx.1) ±îÁöµµ ÀÎÅͳÝÀÌ ³ª±âÁú ¸øÇÔ´Ï´Ù. >> ±×¸®°í ·Î±×ÆÄÀÏ(/var/log/messages)¿¡ ´ÙÀ½°ú °°Àº ·Î±×°¡ 1Ãʰ£°ÝÀ¸·Î ½×ÀÔ´Ï´Ù. >> ·Î±×ÆÄÀÏ¿¡¸¸ ½×ÀÌ´Â°Ô ¾Æ´Ï°í Äָܼð´ÏÅÍ¿¡ °Ô¼Ó ³ª¿É´Ï´Ù. >> >> Limiging icmp unreach from 204 to 200 packet per second >> Limiging icmp unreach from 271to 200 packet per second >> Limiging icmp unreach from 231to 200 packet per second >> Limiging icmp unreach from 220to 200 packet per second >> ...(¾ÆÀÌÇÇ ¹øÈ£°°Àº°Å´Â ¾ø±¸¿ä) >> ½Ã½ºÅÛÀÇ ÇØÅ·ÀÌ Àǽɽº·´½À´Ï´Ù. 1. ICMP port unreachable code´Â UDP·Î Á¢¼Ó½Ãµµ½Ã ÇØ´ç ¼¹ö¿¡ ¼ºñ½º°¡ ¾øÀ» °æ¿ì Á¢¼ÓÇÑ ¼¹ö¿¡¼ »ý¼ºÇÕ´Ï´Ù. ÇØÅ·µÈ ÈÄ rootkit°°Àº °ÍÀÌ ¼³Ä¡µÇ¾î¼ ´Ù¸¥ ¿©·¯ ½Ã½ºÅÛÀ» °Ë»çÇϰí ÀÖÀ» °æ¿ì ¹ß»ýÇÒ ¼ö ÀÖ½À´Ï´Ù. 2. ÀÌ ½Ã½ºÅÛ¸¸ ¿¬°áÇÏ¸é ´Ù¸¥ ½Ã½ºÅÛµµ networkÀÌ µÇÁö ¾Ê´Â´Ù°í Çϴ°ÍÀ» º¸¸é ¾Æ¸¶µµ ÀÌ ½Ã½ºÅÛ¿¡¼ network¿¡ »ó´çÇÑ ºÎÇϸ¦ ÁÖ´Â ÀÏÀ» Çϰí ÀÖÀ» ¼ö ÀÖ½À´Ï´Ù. °°Àº ¹öÁ¯ÀÇ ±ú²ýÇѽýºÅÛ°ú hash °ªÀ» ºñ±³ÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù. cksum(1), sum(1)Àº È¿°ú°¡ ¾ø°í ¹Ýµå½Ã Cryptographic HashingÀ» »ç¿ëÇØ¾ß ÇÕ´Ï´Ù. ´ëÇ¥ÀûÀÎ °ÍÀ¸·Î´Â MD5, RIPEMD160 µîÀÌ ÀÖ½À´Ï´Ù. MD5°ªÀº md5(1)³ª openssl(1)·Î ±¸ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÃÖ¼ÒÇÑ ´ÙÀ½ÀÇ ÇÁ·Î±×·¥¿¡ ´ëÇØ¼ ¸ðµÎ °Ë»çÇϰí Çϳª¶óµµ ´Ù¸¥°ÍÀÌ ÀÖ´Ù¸é µ¥ÀÌŸ ¹é¾÷ÈÄ ½Ã½ºÅÛÀ» »õ·Î ¼³Ä¡Çϼ¼¿ä. ls, ps, ifconfig, md5, openssl, top, netstat, sockstat, fstat, sshd, inetd, telnetd, syslogd µî >> >> ¾î´ÀºÐ Á¶¾ð´ë·Î °°Àº ¼ºê³Ý(66.218.32.0/19 : 66.218.32.0 - 66.218.63.255) >> À» »ç¿ëÇÏ´Â ±× ÁÖº¯µ¿³×(¶Ç´Â) ÀÇ ¹ÙÀÌ·¯½º°¨¿°µÈ Äͧ¹®¿¡ ±×·²¼öµµ ÀÖ´Â°Í °°¾Æ¼ ISP ¿¡ ¹®ÀÇ, Ç×ÀÇ ÇßÁö¸¸. >> >> ISP ¿Ð : ÁøÂ¥·Î ¾î´À ¾ÆÀÌÇÇÀÇ ¹ÙÀÌ·¯½º¶§¹®ÀÎÁö È®ÀÎÇÒ¼öµµ ¾ø´Â »óȲ¿¡¼ ·Î±×ÆÄÀϸ¸ °®°í¼ >> ip¼ÒÀ¯ÇÑ »ç¿ëÀÚ ÀÏÀÏÀÌ ³Ê³× ÄĹÙÀÌ·¯½º¶§¹®¿¡ °°Àº Áö¿ª ´Ù¸¥»ç¿ëÀÚ°¡ ÇÇÇØº»´Ù°í ÇÒ¼öµµ ¾ø°í ¶Ç °¡°¢ »ç¿ëÀÚÀÇ ¹ÙÀÌ·¯½º ¹®Á¦±îÁö °£¼·Çϰųª È®ÀÎÇÒ¼öÀÖ´Â ¹®Á¦°¡ ¾Æ´Ï¶ó°í ¸¸ ÇÏ´Ï , ±× ¶ÇÇÑ Àϸ®ÀÖ´Â ¸»À̱⵵ ÇÕ´Ï´Ù. >> ¸Â½À´Ï´Ù. ISP°¡ ÃëÇÒ ¼ö ÀÖ´Â Á¶Ä¡¶ó´Â°ÍÀº °ÅÀÇ ¾ø½À´Ï´Ù. ±â²¯ÇØ¾ß ISP°¡ °ü¸®ÇÏ´Â ¼¹öÁß ¹®Á¦ÀÖ´Â ¼¹öÀÇ ºÐ¸®Á¤µµ ÀÔ´Ï´Ù. ÀÌ ¸¶Àúµµ ¸¹ÀÌ ÁÖÀúÇÏ´Â ÆíÀÌÁÒ. >> ±×¸®°í httpd ·Î±×ÆÄÀϺ¸´Ï±î 66.218.xxx.yyy: ....scipt/winnt/cmd.exe ¾î¼±¸ ÇÏ´Â ÁÙÀÌ ²À °°Àº ¼ºê³Ý¿¡¼ >> µé¾î¿À´Â°Íµµ ÀÖÁö¸¸ >> 24.xxx.xxx.xxx: : ....scipt/winnt/cmd.exe >> 206.xxx.xxx.xx. : ....scipt/winnt/cmd.exe >> .. >> ÀÌ·¸°Ô ÀüÇô ´Ù¸¥ ³×Æ®¿öÅ© ÁÖ¼Ò¿¡¼µµ µé¾î¿À´õ¶ó±¸¿ä. >> >> ÀÌ·²¶§´Â ¾î¶»°Ô ÇØ¾ßÇÒÁö ¸ð¸£°Ú³×¿ä ÀÌ°Ç ¾î´À¼¹ö¿¡³ª ÀÖ´Â Á¤»óÀûÀÎ Çö»óÀÔ´Ï´Ù. ÀÎÅͳݻ󿡼´Â ¹ÙÀÌ·¯½º³ª ¿ú¿¡ °¨¿°µÈ ¼¹öµéÀÌ °ø°Ý´ë»óÀ» Ç×»ó ã°í Àְŵç¿ä. ±×¸®°í ÇØÅ°À» °øºÎ(?)ÇÏ´Â Ãʺ¸ÀÚµéÀÌ °ø°ÝÇÁ·Î±×·¥À» ±¸Çؼ ½ÃÇèÇϱ⵵ ÇÕ´Ï´Ù. -- ============================================================ // Korea Telecom Internet Solutions, Inc. // FreeBSD/Linux Professional Consulting/Tech. Support // // Pyun YongHyeon // // WWW: http://www.kt-is.co.kr/ // FTP: ftp://ftp.kt-is.co.kr/ // // TEL: +82-2-364-0400 // FAX: +82-2-364-9119 ============================================================ -- Please look and take part in KFUG FAQ: <http://www.kr.freebsd.org/FAQ-kr/> To Unsubscribe: send mail to majordomo@kr.FreeBSD.org with "unsubscribe questions" in the BODY of the message
|
Copyright © 1998-2005 Korea FreeBSD Users Group. All rights reserved. webmaster at kr.FreeBSD.org $Date: 2002/10/31 23:00:24 $ |
|