Å×Å©³ë ÄÄÇ»ÅÍ

[¿ø°Ý¿äû] . [ȸ¿øÀÚ·á½Ç] [EDIT]     [Win98] [Win2000] [Win7] [win10] [WinServer] [Linux] [A/SÀÚ·á] [Driver] [UTIL] [º¹Á¦±â] [TC]

__Today: __
Your ip : 3.145.60.29
ȸ¿ø¾ÆÀ̵ð 
Æнº¿öµå
  ÄÄÇ»ÅÍ
  ¸ð´ÏÅÍ
  À×Å©/Åä³Ê-¼Ò¸ðÇ°
  ÄÄÇ»Åͺ»Ã¼ºÎÇ°
  ½ºÄɳÊ
  ÇÁ¸°ÅÍ
  ÄÄÇ»ÅͼҸðÇ°
  ³×Æ®¿öÅ©
  ¼ÒÇÁÆ®¿þ¾î

ÀüÈ­ : 062-224-6450
Æѽº : 062-227-6450

  Å×Å©³ëÄÄÇ»ÅÍ

[ ÀÚ·á½Ç ]

±¤°í¼º ±ÛÀ̳ª ºÒ¹ýÀÚ·á ¾÷·Îµå¸¦ ±ÝÇÕ´Ï´Ù.

sendmail¿¡¼­ sircam virus Â÷´ÜÇϱâ
À̸§ : ÇãÁ¤±Õ     ¹øÈ£ : 42     Á¶È¸ : 75749
¾÷·Îµå : 2001-08-29 17:30:13     ¼öÁ¤ÀÏ : 2002-03-18 14:51:44

ÀÌ ¹ÙÀÌ·¯½º´Â º¸Åë, 'Hi! How are you?' ¶ó´Â ¹®±¸¸¦ Æ÷ÇÔÇÏ°í ÀÖÀ¸¸ç,

ÀϹÝÀûÀÎ ÆÄÀÏÀ» ÷ºÎÇÏ°í ÀÖ´Â Á¤»óÀûÀÎ ¸ÞÀÏó·³ º¸¿©, ¼Ó¾Æ³Ñ¾î°¡±â ½¬¿î ÇüÅÂÀ̸鼭,
½Ã½ºÅÛ¿¡ ÇÇÇظ¦ ÀÔÈ÷¹Ç·Î, ÁÖÀǸ¦ ¿äÇÏ°í ÀÖ½À´Ï´Ù.



¾Æ·¡ ³»¿ëÀº ±è°æ¿í´Ô²²¼­ ÀÛ¼ºÇÑ sendmail 8.9  ÀÌ»ó ¹öÀü¿¡¼­ ÀÌ ¹ÙÀÌ·¯½º¸¦
Â÷´ÜÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ÆÁÀÔ´Ï´Ù.





--------------------------------------------------------------------------------




   
ÀÌ ·ê¼ÂÀº quanta-spam_killer¿¡¼­ Sircam worm Â÷´Ü ·ê¼Â¸¸À» ºÐ¸®ÇÑ
    °ÍÀÔ´Ï´Ù.
   
Sircam worm¿¡ ´ëÇÑ Á¤º¸´Â ¾Æ·¡ URL¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.
   
http://home.ahnlab.com/search/virus_detail.jsp?SEQ_NO=843
   

    w32.sircam.worm@mm.html"
     target="_blank">w32.sircam.worm@mm.html" TARGET=_blank>w32.sircam.worm@mm.html" TARGET=_blank>http://www.symantec.com/avcenter/venc/data/pf/w32.sircam.worm@mm.html
   

         target="_blank">½Ã¸¸ÅØ, ¼­Ä· ¿ú ¹ÙÀÌ·¯½º À§Çèµµ »óÇâ Á¶Á¤ (µðÁöÅ» ŸÀÓ½º,
    2001/07/23)

         target="_blank">[ÄÄÇ»ÅÍ]"How are you" ¹ÙÀÌ·¯½º ±â½Â (µ¿¾ÆÀϺ¸,
    2001/07/20)


   
 
   

º» Â÷´Ü¹ýÀº Sircam worm Á¦ÀÛÀÚÀÇ À߸øµÈ Content-Disposition: »ç¿ë¿¡
    ¹ÙÅÁÀ» µÐ °ÍÀ¸·Î, Content-Disposition: ÀÇ ¿Ã¹Ù¸¥ »ç¿ë¿¹´Â RFC 2183À» ÂüÁ¶ÇϽñâ
    ¹Ù¶ø´Ï´Ù.
   
Áï, º» ·ê¼ÂÀº ¸ÞÀÏ Çì´õ¿¡ ¾Æ·¡¿Í °°Àº header field°¡ ¹ß°ßµÉ °æ¿ì sircam
    worm À¸·Î °£ÁÖÇÏ¿© reject ÇÕ´Ï´Ù. RHSÀÇ ¿Ã¹Ù¸¥ »ç¿ë¿¹´Â, 'inline' ¶Ç´Â 'attachment'
    ÀÔ´Ï´Ù.
   
Content-Disposition: Multipart message
   

sendmail.cf¿¡ ´ÙÀ½ ·ê¼Â¸¸À» Ãß°¡ÇÏ¿© Sircam wormÀ» Â÷´ÜÇÒ ¼ö ÀÖ½À´Ï´Ù.

    ¶ÇÇÑ, ³»ºÎ ³×Æ®¿öÅ©¿¡ ÀÌ¹Ì °¨¿°µÈ PC°¡ ÀÖÀ» °æ¿ì wormÀÇ È®»êÀ» Â÷´ÜÇÔ°ú

    µ¿½Ã¿¡, maillog(¶Ç´Â syslog)¸¦ °Ë»öÇÏ¿© °¨¿°µÈ PC¸¦ ¹ß°ßÇÒ ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù.
   




   
ÀÌ ·ê¼ÂÀÇ »ç¿ëÀº sendmail 8.9 À̻󿡼­¸¸ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.

    ÆĶõ»öÀ¸·Î µÈ ºÎºÐÀÌ Ãß°¡µÉ ºÎºÐÀÔ´Ï´Ù.
   
# check IP address
R$*                     $: $&{client_addr}
R$@                     $@ OK                   originated locally
R0                      $@ OK                   originated locally
R$=R $*                 $@ OK                   relayable IP address
R$*                     $: $>LookUpAddress <$1>  <$1>
R$*                     $@ RELAY                relayable IP address
R<$*> <$*>              $: $2
R$*                     $: [ $1 ]               put brackets around it...
R$=w                    $@ OK                   ... and see if it is local
 
 
# anything else is bogus
R$*                     $#error $@ 5.7.1 $: "550 Relaying denied"
 
 
### Sircam worm filter
 
HContent-Disposition: $>check_sircam
D{SIRCAM}"Your message may contain the Sircam.worm !!! (¾Æ·¡ÁÙ°ú ¿¬°áÇؼ­ ¾²¼¼¿ä.)
See w32.sircam.worm@mm.html" TARGET=_blank>w32.sircam.worm@mm.html" TARGET=_blank>http://www.symantec.com/avcenter/venc/data/pf/w32.sircam.worm@mm.html"
 
Scheck_sircam
RMultipart message $#error $: 550 ${SIRCAM}
 
 
 
#### ÁÖÀÇ: Multimapt message¿Í $#error »çÀÌ´Â [TAB]ÀÔ´Ï´Ù.
 
 
 
######################################################################
######################################################################
#####
#####                   MAILER DEFINITIONS
#####
######################################################################
######################################################################
   

       
Sendmail.cfÀÇ ¼öÁ¤ÀÌ ´Ù ³¡³µÀ¸¸é, sendmailÀ»
        restart Çϱâ Àü¿¡ ruleset ¸ðµå¿¡¼­ Å×½ºÆ®¸¦ ÇØ º¾´Ï´Ù.
   

$ /usr/lib/sendmail -bt
ADDRESS TEST MODE (ruleset 3 NOT automatically invoked)
Enter
               
> check_sircam Multipart message check_sircam input:
                Multipart message check_sircam returns: $# error $: 550 553
                Your message may contain the Sircam . worm ! ! ! See http :
                / / www . symantec . com / avcenter / venc / data / pf / w32
                . sircam . worm @ mm . html > ctrl-D (ºüÁ®³ª¿À±â)
 

   
À§¿Í °°ÀÌ Àß µÇ¾ú´Ù¸é, sendmailÀ» restart
ÇÕ´Ï´Ù.

À­±Û : 2001-08-30 10:00:40,   43¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(rc.deny, 13,233Byte)ÀÌ ÀÖ½À´Ï´Ù. iptables¸¦ ÀÌ¿ëÇÑ ¾ÆÀÌÇÇ Â÷´Ü
¹Ø±Û : 2001-06-08 18:02:22,   41¹ø ±Û ¹Ù·Îº¸±â linux 7.1 kernel 2.4.x iptables se
  Absolute number:72
Ȩ¾²±â°ü·Ã±ÛÀü´Þ¼öÁ¤»èÁ¦¸ñ·Ï
 
¹øÈ£ Á¦¸ñ ÷ºÎÆÄÀÏ Å©±â Àü¼Û À̸§ ¾÷·Îµå
72 2020-11-06 09:48:34,   72¹ø ±Û ¹Ù·Îº¸±â fortigate ¾ÏÈ£ »õ·Î ³Ö±â     0 °ü¸®ÀÚ 11-06
71 2015-05-16 15:39:49,   71¹ø ±Û ¹Ù·Îº¸±â linux ½Ã°£ ¼³Á¤     0 °ü¸®ÀÚ 05-16
70 2007-09-06 10:06:14,   70¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(vsftp.txt, 9,151Byte)ÀÌ ÀÖ½À´Ï´Ù. ftp??? ´Ù¿î·Îµå : vsftp.txt (9,151Byte) vsftp.txt 8KB 11047 °ü¸®ÀÚ 09-06
69 2007-04-07 11:08:32,   69¹ø ±Û ¹Ù·Îº¸±â »ç¼³ ip ´ë¿ª- ¹üÀ§     0 °ü¸®ÀÚ 04-07
60 2004-06-14 12:39:06,   60¹ø ±Û ¹Ù·Îº¸±â ¸ÞÀϼ³Á¤ ¼³¸í     0 °ü¸®ÀÚ 06-14
60¹øÀÇ °ü·Ã±Û 2004-06-14 12:43:40,   60¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: ¸ÞÀϼ³Á¤ ¼³¸í     0 °ü¸®ÀÚ 06-14
59 2004-06-10 19:23:14,   59¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(iptables.ZIP, 383,958Byte)ÀÌ ÀÖ½À´Ï´Ù. iptable ¹®¼­ ´Ù¿î·Îµå : iptables.ZIP (383,958Byte) iptables.ZIP 374KB 6710 Â÷´Ï 06-10
59¹øÀÇ °ü·Ã±Û 2004-07-13 22:21:18,   59¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: iptable ¹®¼­     0 °ü¸®ÀÚ 07-13
59¹øÀÇ °ü·Ã±Û 2004-07-13 22:26:07,   59¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: iptable ¹®¼­     0 °ü¸®ÀÚ 07-13
58 2004-06-07 23:25:44,   58¹ø ±Û ¹Ù·Îº¸±â fedora 2.0 ¼³Ä¡     0 °ü¸®ÀÚ 06-07
57 2004-02-25 11:31:01,   57¹ø ±Û ¹Ù·Îº¸±â ¸®´ª½º Ä¿³Î Ãë¾à¼ºÀÌ     0 °ü¸®ÀÚ 02-25
55 2003-06-24 09:41:39,   55¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(cgitelnet.zip, 6,522Byte)ÀÌ ÀÖ½À´Ï´Ù. telnet for ftp port ´Ù¿î·Îµå : cgitelnet.zip (6,522Byte) cgitelnet.zip 6KB 6212 °ü¸®ÀÚ 06-24
54 2002-11-29 11:00:25,   54¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(hcode_spam_filter.tar.bz2, 93,421Byte)ÀÌ ÀÖ½À´Ï´Ù. filter¸¦ ÀÌ¿ëÇÑ ½ºÆÔÁ¦°Å ´Ù¿î·Îµå : hcode_spam_filter.tar.bz2 (93,421Byte) hcode_spam_fil 91KB 6254 Admin 11-29
53 2002-10-31 12:29:01,   53¹ø ±Û ¹Ù·Îº¸±â Linux/Slapper.worm.B -------.cinik     0 Admin 10-31
52 2002-08-13 17:30:24,   52¹ø ±Û ¹Ù·Îº¸±â ½ºÆÔ¸ÞÀÏ Â÷´Ü¹æ¹ý     0 Admin 08-13
52¹øÀÇ °ü·Ã±Û 2002-08-13 18:47:20,   52¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: ½ºÆÔ¸ÞÀÏ Â÷´Ü¹æ¹ý     0 Admin 08-13
52¹øÀÇ °ü·Ã±Û 2002-11-28 11:59:46,   52¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: ½ºÆÔ¸ÞÀÏ Â÷´Ü¹æ¹ý     0 °ü¸®ÀÚ 11-28
51 2002-05-24 15:19:42,   51¹ø ±Û ¹Ù·Îº¸±â ¸®´ª½º °ü¸®ÀÚ¸¦À§ÇÑ ÆÄ¿ö ÆÁ     0 °ü¸®ÀÚ 05-24
50 2002-05-20 12:31:05,   50¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(Coyote Linux.exe, 4,329,657Byte)ÀÌ ÀÖ½À´Ï´Ù. coyote - last all zip ¸®¶ó ÄÚ¿äÅ× ´Ù¿î·Îµå : Coyote Linux.exe (4,329,657Byte) Coyote Linux.e 4.13MB 8747 °ü¸®ÀÚ 05-20
50¹øÀÇ °ü·Ã±Û 2002-05-22 10:37:51,   50¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(msn-enable.tar, 163,840Byte)ÀÌ ÀÖ½À´Ï´Ù. coyote - last all zip ¸®¶ó ÄÚ¿ä ´Ù¿î·Îµå : msn-enable.tar (163,840Byte) msn-enable.tar 160KB 6527 °ü¸®ÀÚ 05-22
49 2002-05-02 00:02:48,   49¹ø ±Û ¹Ù·Îº¸±â ȨÆäÀÌÁö °Ë»ö»çÀÌÆ® µî·ÏÆÁ     0 °ü¸®ÀÚ 05-02
48 2002-04-12 10:01:40,   48¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(forwarding.txt, 3,347Byte)ÀÌ ÀÖ½À´Ï´Ù. À¯µ¿ ipÀÇ °íÁ¤È­ -forwarding Æ÷¿öµù ´Ù¿î·Îµå : forwarding.txt (3,347Byte) forwarding.txt 3KB 6948 °ü¸®ÀÚ 04-12
47 2002-04-10 11:30:58,   47¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(ProFTPd_Ref-.htm, 142,751Byte)ÀÌ ÀÖ½À´Ï´Ù. Korean ProFTPd Reference ´Ù¿î·Îµå : ProFTPd_Ref-.htm (142,751Byte) ProFTPd_Ref-.h 139KB 109358 °ü¸®ÀÚ 04-10
46 2002-04-10 11:24:50,   46¹ø ±Û ¹Ù·Îº¸±â ftpŬ¶óÀ̾ðÆ® »ç¿ëÇϱâ ÆÁ.     0 °ü¸®ÀÚ 04-10
45 2001-09-05 20:00:34,   45¹ø ±Û ¹Ù·Îº¸±â linux¿¡¼­ À©µµ¿ì °øÀ¯Æú´õ º¸±â     0 ÇãÁ¤±Õ 09-05
44 2001-08-31 12:00:25,   44¹ø ±Û ¹Ù·Îº¸±â ¸®´ª½º¿¡¼­ ¸Þ¸ð¸® ÀνÄÀ» Á¦´ë·Î ¸ø     0 ÇãÁ¤±Õ 08-31
43 2001-08-30 09:59:57,   43¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(rc.firewall.iptables, 1,117Byte)ÀÌ ÀÖ½À´Ï´Ù. iptables sample ´Ù¿î·Îµå : rc.firewall.iptables (1,117Byte) rc.firewall.ip 1KB 5448 ÇãÁ¤±Õ 08-30
43¹øÀÇ °ü·Ã±Û 2001-08-30 10:00:40,   43¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(rc.deny, 13,233Byte)ÀÌ ÀÖ½À´Ï´Ù. iptables¸¦ ÀÌ¿ëÇÑ ¾ÆÀÌÇÇ Â÷´Ü ´Ù¿î·Îµå : rc.deny (13,233Byte) rc.deny 12KB 5166 ÇãÁ¤±Õ 08-30
42 2001-08-29 17:30:13,   42¹ø ±Û ¹Ù·Îº¸±â sendmail¿¡¼­ sircam virus Â÷´ÜÇϱ⠢¸     0 ÇãÁ¤±Õ 08-29
41 2001-06-08 18:02:22,   41¹ø ±Û ¹Ù·Îº¸±â linux 7.1 kernel 2.4.x iptables se     0 Mr heo 06-08
 


Copyright (C) 2001 jog.co.kr All rights reserved.