Å×Å©³ë ÄÄÇ»ÅÍ

[¿ø°Ý¿äû] . [ȸ¿øÀÚ·á½Ç] [EDIT]     [Win98] [Win2000] [Win7] [win10] [WinServer] [Linux] [A/SÀÚ·á] [Driver] [UTIL] [º¹Á¦±â] [TC]

__Today: __
Your ip : 18.223.32.230
ȸ¿ø¾ÆÀ̵ð 
Æнº¿öµå
  ÄÄÇ»ÅÍ
  ¸ð´ÏÅÍ
  À×Å©/Åä³Ê-¼Ò¸ðÇ°
  ÄÄÇ»Åͺ»Ã¼ºÎÇ°
  ½ºÄɳÊ
  ÇÁ¸°ÅÍ
  ÄÄÇ»ÅͼҸðÇ°
  ³×Æ®¿öÅ©
  ¼ÒÇÁÆ®¿þ¾î

ÀüÈ­ : 062-224-6450
Æѽº : 062-227-6450

  Å×Å©³ëÄÄÇ»ÅÍ

[ ÀÚ·á½Ç ]

±¤°í¼º ±ÛÀ̳ª ºÒ¹ýÀÚ·á ¾÷·Îµå¸¦ ±ÝÇÕ´Ï´Ù.

Linux/Slapper.worm.B -------.cinik virus
¾ÆÀ̵ð : admin     À̸§ : Admin techno@jog.co.kr     ¹øÈ£ : 53     Á¶È¸ : 41123
¾÷·Îµå : 2002-10-31 12:29:01
ȨÆäÀÌÁö : http://jog.co.kr http://jog.co.kr

Áõ»ó ¸®´ª½º Ç÷§ÆûÀÇ ¾ÆÆÄÄ¡ À¥ ¼­¹ö¸¦ ´ë»óÀ¸·Î, OpenSSL ÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© È®»êµÈ´Ù.
 
³»¿ë ÀÌ ¿úÀº Linux/Slapper.worm º¯ÇüÀ¸·Î ±âÁ¸ ¿øÇüÀÇ Áõ»ó°ú ºñ½ÁÇϸç, ¸¸µé¾îÁö´Â ÆÄÀÏÀ̸§ÀÇ º¯°æ , CRONTAB ÀÇ µî·Ï, ½Ã½ºÅÛ Á¤º¸ ¸ÞÀÏ¹ß¼Û µîÀÇ ±â´ÉÀ» °¡Áö°í ÀÖ´Ù. CINIK À̸§À¸·Î ºÒ¸®¾îÁö±âµµ ÇÑ´Ù.

±âÁ¸ÀÇ Linux/Slapper.worm ÀÇ Á¤º¸´Â ¿©±â¼­ È®ÀÎÇØ º¼ ¼ö ÀÖÀ¸¸ç Linux/Slapper.worm.B ¿¡¼­ ³ªÅ¸³ª´Â Áõ»óÀº ´ÙÀ½°ú °°´Ù.

OpenSSL ÀÇ Ãë¾àÁ¡À» °¡Áö°í ÀÖ´Â À¥ ¼­¹ö¿¡ °ø°ÝÀ» ¼º°øÇÏ°Ô µÇ¸é,

/tmp/.cinik.uu ¿¡ ¿£ÄÚµù ÇÏ¿© Àü¼ÛÇÑ´Ù. ¸¸¾à ¿£ÄÚµù ÇÏ´Â °úÁ¤¿¡¼­, '/tmp/.cinik.c' ÆÄÀÏÀ» ¿ÀÇÂÇÒ ¼ö ¾ø´Ù¸é, /usr/bin/wget À» ÀÌ¿ëÇÏ¿© "http://Á¦°ÅµÊ.home.ro/0/cinik.c" ¿¡¼­ ÆÄÀÏÀ» ´Ù¿î¹Þ¾Æ ¿À°Ô µÈ´Ù. Àü¼ÛÈÄ À¯´Ð½º ¸í·É¾î uudecode ¸¦ ÀÌ¿ëÇÏ¿© ÇØ´ç ÆÄÀÏÀ» µðÄÚµù ÇÑ ÈÄ, '.cinik' ·Î ÄÄÆÄÀÏ ÇÑ´Ù.

* ÇöÀç À§ À¥»çÀÌÆ®´Â Á¢¼ÓµÇÁö ¾Ê´Â´Ù.

/usr/bin/uudecode -o /tmp/.cinik.c /tmp/.cinik.uu
gcc -o /tmp/.cinik /tmp/.cinik.c -lcrypto

ÄÄÆÄÀÏ µÈ .cinik ÆÄÀÏÀ» ·ÎÄþÆÀÌÇÇ ÁÖ¼Ò·Î ½ÇÇàÇϰԵȴÙ.

/tmp/.cinik LocalIP

/* ÀÌ ¿úÀÌ »ç¿ëÇÏ´Â Æ÷Æ®´Â 1978 UDP ÀÌ´Ù. */

½ÇÇàÈÄ ¿øÇü°ú ´Þ¸® '/tmp/.cinik.go' ½ºÅ©¸³Æ® ÆÄÀÏÀ» ¸¸µç´Ù. ½ºÅ©¸³Æ®ÀÇ ³»¿ëÀº ´ÙÀ½°ú °°´Ù.

1. "/tmp/.font-unix/.cinik" µð·ºÅ丮¸¦ »ý¼ºÇÑ´Ù.

2. ½ºÄÉÁì¿¡ µû¶ó ÆÄÀÏÀ» ½ÇÇàÇÒ ¼ö ÀÖ´Â Crontab ¿¡ Ãʱâ ÀÌ ½ºÅ©¸³Æ®°¡ ½ÇÇàµÈ ½Ã°¢ÀÇ 1ºÐÈÄ¿¡ ¸ÅÀÏ ¿úÀ» ½ÇÇàÇÑ´Ù.

3. 'find' ¸í·ÉÀ» ÀÌ¿ëÇÏ¿© /usr ,/var, /tmp, /home,/mnt µð·ºÅ丮¿¡¼­ ŸÀÔÀÌ ÆÄÀÏÀÌ¸ç ¾²±â¿Í ½ÇÇàÀÌ °¡´ÉÇÑ ÆÄÀÏÀ» ã¾Æ ¿úÀÇ ³»¿ëÀ¸·Î º¹»çÈÄ, Crontab ¿¡ Ãʱâ ÀÌ ½ºÅ©¸³Æ®°¡ ½ÇÇàµÈ ½Ã°¢ÀÇ 2ºÐÈÄ¿¡ ¸ÅÀÏ ½ÇÇàÇϵµ·Ï ÇÑ´Ù.

4. 'find' ¸í·ÉÀ» ÀÌ¿ëÇÏ¿© /usr,/var, /tmp, /home,/mnt µð·ºÅ丮¿¡¼­ ŸÀÔÀÌ µð·ºÅ丮À̸ç À¥ ¼­¹ö°¡ µ¿ÀÛÇÏ°í ÀÖ´ÂUID °ªÀ» °¡Áö°í ÀÖ´Â °÷¿¡ ¿úÀ» º¹»çÇÑ´Ù. ±×¸®°í Contab ¿¡ Ãʱâ ÀÌ ½ºÅ©¸³Æ®°¡ ½ÇÇàµÈ ½Ã°¢ÀÇ 3ºÐÈÄ¿¡ ¸ÅÀÏ ½ÇÇàÇϵµ·Ï ÇÑ´Ù.

5. /tmp/.cinik.status ¿¡ CPU, ¸Þ¸ð¸®, Çϵåµð½ºÅ©, IP Á¤º¸¸¦ ÀÔ·ÂÇÑ´Ù.

6. "cinik_worm@Á¦°ÅµÊ.com" ¸ÞÀÏ ÁÖ¼Ò·Î °¨¿°µÈ ½Ã½ºÅÛÀÇ IP ÁÖ¼ÒÁ¦¸ñÀ¸·Î .cinik.status Á¤º¸¸¦ ¹ß¼ÛÇÑ´Ù.

7. ÃÖÁ¾ÀûÀ¸·Î ¸¸µé¾îÁø /tmp/.cinik.go ÆÄÀÏÀÇ Æ۹̼ÇÀ» º¯°æÇÑÈÄ ½ÇÇàÇÑ´Ù.

ÀÌ Á¤º¸´Â 2002³â 9¿ù 26ÀÏ 17½Ã 32ºÐ¿¡ ÃÖÃÊÀÛ¼º µÇ¾ú´Ù.
 
Ä¡·á¹æ¹ý 1. ¿ú ÇÁ·Î¼¼½º¸¦ Á¾·áÇÑ´Ù.

# killall -9 .cinik

2. ¿ú°ú °ü·ÃÇÑ ¸ðµç ÆÄÀÏÀ» »èÁ¦ÇÑ´Ù.

# rm -rf /tmp/.cinik /tmp/.cinik.c /tmp/.cinik.uu /tmp/.cinik.go
/tmp/.font-unix/.cinik

- Àüü µð·ºÅ丮¸¦ °Ë»çÇÏ¿© .cinik ÆÄÀÏÀ» ã¾Æ »èÁ¦ÇÑ´Ù.

# find / -name '.cinik' -exec rm -rf {} \; -print

3. crontab ¿¡¼­ Slapper.Worm.B ¿Í °ü·ÃÇÑ ³»¿ëÀ» ã¾Æ ¸ðµÎ »èÁ¦ÇÑ´Ù.

- crontab ÀÇ ³»¿ëÀ» È®ÀÎÇØ º»´Ù.
# crontab -l

- ¿ú°ú °ü·ÃÇÑ ³»¿ëÀÌ ÀÖÀ»°æ¿ì '-e' ¸í·É¾î¸¦ »ç¿ëÇÏ¿© ÆíÁýÇÑ´Ù.
# crontab -e
 
Âü°í»çÇ× ÀÌ Ãë¾àÁ¡¿¡ ³ëÃâµÇ¾î ÀÖ´Â »ç¿ëÀÚ´Â ´ÙÀ½°ú °°ÀÌ ±ÇÀåÇÑ´Ù :

1. OpenSSL ÀÇ ¾÷µ¥ÀÌÆ® (mod_ssl »ç¿ëÀÚ)

2. ¾ÆÆÄÄ¡ ¼³Á¤ÆÄÀÏ 'httpd.conf' ÀÇ Á¤º¸³ëÃâ Á¦ÇÑ

ServerTokens ProductOnly
ServerSignature Off

À§¿Í °°ÀÌ µÎ°³ÀÇ Áö½Ã¾î¸¦ ¼³Á¤ÇÑ´Ù.

3. ¾ÆÆÄÄ¡ 1.3.24 ¸¦ Æ÷ÇÔÇÑ ÀÌÇÏÀÇ ¹öÀüÀ» »ç¿ëÇÏ´Â °æ¿ì ÃֽŹöÀüÀ¸·Î ¾÷±×·¹À̵å


CERT Advisory CA-2002-27

http://www.cert.org/advisories/CA-2002-27

OpenSSL :

- Ãë¾àÁ¡ Á¤º¸È®ÀÎ

http://www.openssl.org/news/secadv_20020730.txt

- ÃֽŹöÀü ¹Þ±â

http://www.openssl.org/source/

À­±Û : 2002-11-29 11:00:25,   54¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(hcode_spam_filter.tar.bz2, 93,421Byte)ÀÌ ÀÖ½À´Ï´Ù. filter¸¦ ÀÌ¿ëÇÑ ½ºÆÔÁ¦°Å
¹Ø±Û : 2002-08-13 17:30:24,   52¹ø ±Û ¹Ù·Îº¸±â ½ºÆÔ¸ÞÀÏ Â÷´Ü¹æ¹ý
  From:61.98.172.6 / Absolute number:89
Ȩ¾²±â°ü·Ã±ÛÀü´Þ¼öÁ¤»èÁ¦¸ñ·Ï
 
¹øÈ£ Á¦¸ñ ÷ºÎÆÄÀÏ Å©±â Àü¼Û À̸§ ¾÷·Îµå
72 2020-11-06 09:48:34,   72¹ø ±Û ¹Ù·Îº¸±â fortigate ¾ÏÈ£ »õ·Î ³Ö±â     0 °ü¸®ÀÚ 11-06
71 2015-05-16 15:39:49,   71¹ø ±Û ¹Ù·Îº¸±â linux ½Ã°£ ¼³Á¤     0 °ü¸®ÀÚ 05-16
70 2007-09-06 10:06:14,   70¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(vsftp.txt, 9,151Byte)ÀÌ ÀÖ½À´Ï´Ù. ftp??? ´Ù¿î·Îµå : vsftp.txt (9,151Byte) vsftp.txt 8KB 11037 °ü¸®ÀÚ 09-06
69 2007-04-07 11:08:32,   69¹ø ±Û ¹Ù·Îº¸±â »ç¼³ ip ´ë¿ª- ¹üÀ§     0 °ü¸®ÀÚ 04-07
68 2006-11-27 19:08:25,   68¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(proftpd-postgresql-1.3.0-7.fc6.i386.rpm, 22,574Byte)ÀÌ ÀÖ½À´Ï´Ù. proftpd-postgresql-1.3.0-7.fc6.i386 ´Ù¿î·Îµå : proftpd-postgresql-1.3.0-7.fc6.i386.rpm (22,574Byte) proftpd-postgr 22KB 6187 Â÷´Ï 11-27
67 2006-11-27 19:08:12,   67¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(proftpd-mysql-1.3.0-7.fc6.i386.rpm, 23,428Byte)ÀÌ ÀÖ½À´Ï´Ù. proftpd-mysql-1.3.0-7.fc6.i386 ´Ù¿î·Îµå : proftpd-mysql-1.3.0-7.fc6.i386.rpm (23,428Byte) proftpd-mysql- 22KB 6194 Â÷´Ï 11-27
66 2006-11-27 19:08:01,   66¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(proftpd-ldap-1.3.0-7.fc6.i386.rpm, 27,451Byte)ÀÌ ÀÖ½À´Ï´Ù. proftpd-ldap-1.3.0-7.fc6.i386 ´Ù¿î·Îµå : proftpd-ldap-1.3.0-7.fc6.i386.rpm (27,451Byte) proftpd-ldap-1 26KB 6029 Â÷´Ï 11-27
65 2006-11-27 19:07:47,   65¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(proftpd-1.3.0-7.fc6.i386.rpm, 976,128Byte)ÀÌ ÀÖ½À´Ï´Ù. proftpd-1.3.0-7.fc6.i386 ´Ù¿î·Îµå : proftpd-1.3.0-7.fc6.i386.rpm (976,128Byte) proftpd-1.3.0- 953KB 5879 Â÷´Ï 11-27
64 2006-11-27 18:01:37,   64¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(proftpd-1.3.0kr.tar.bz2, 1,610,284Byte)ÀÌ ÀÖ½À´Ï´Ù. proftpd-1.3.0kr ´Ù¿î·Îµå : proftpd-1.3.0kr.tar.bz2 (1,610,284Byte) proftpd-1.3.0k 1.54MB 5928 Â÷´Ï 11-27
63 2006-11-27 18:01:22,   63¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(proftpd-1.3.0kr1.tar.bz2, 1,610,165Byte)ÀÌ ÀÖ½À´Ï´Ù. proftpd-1.3.0kr1 ´Ù¿î·Îµå : proftpd-1.3.0kr1.tar.bz2 (1,610,165Byte) proftpd-1.3.0k 1.54MB 5671 Â÷´Ï 11-27
62 2006-11-27 17:21:13,   62¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(proftpd-1.2.10-1.fc1.i386.rpm, 715,171Byte)ÀÌ ÀÖ½À´Ï´Ù. proftpd-1.2.10-1.fc1.i386.rpm ´Ù¿î·Îµå : proftpd-1.2.10-1.fc1.i386.rpm (715,171Byte) proftpd-1.2.10 698KB 7640 °ü¸®ÀÚ 11-27
61 2005-10-28 09:54:20,   61¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(SUSELinux10.txt, 250,763Byte)ÀÌ ÀÖ½À´Ï´Ù. Package DescriptionsAll packages i ´Ù¿î·Îµå : SUSELinux10.txt (250,763Byte) SUSELinux10.txt 244KB 369652 °ü¸®ÀÚ 10-28
60 2004-06-14 12:39:06,   60¹ø ±Û ¹Ù·Îº¸±â ¸ÞÀϼ³Á¤ ¼³¸í     0 °ü¸®ÀÚ 06-14
60¹øÀÇ °ü·Ã±Û 2004-06-14 12:43:40,   60¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: ¸ÞÀϼ³Á¤ ¼³¸í     0 °ü¸®ÀÚ 06-14
59 2004-06-10 19:23:14,   59¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(iptables.ZIP, 383,958Byte)ÀÌ ÀÖ½À´Ï´Ù. iptable ¹®¼­ ´Ù¿î·Îµå : iptables.ZIP (383,958Byte) iptables.ZIP 374KB 6692 Â÷´Ï 06-10
59¹øÀÇ °ü·Ã±Û 2004-07-13 22:21:18,   59¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: iptable ¹®¼­     0 °ü¸®ÀÚ 07-13
59¹øÀÇ °ü·Ã±Û 2004-07-13 22:26:07,   59¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: iptable ¹®¼­     0 °ü¸®ÀÚ 07-13
58 2004-06-07 23:25:44,   58¹ø ±Û ¹Ù·Îº¸±â fedora 2.0 ¼³Ä¡     0 °ü¸®ÀÚ 06-07
57 2004-02-25 11:31:01,   57¹ø ±Û ¹Ù·Îº¸±â ¸®´ª½º Ä¿³Î Ãë¾à¼ºÀÌ     0 °ü¸®ÀÚ 02-25
55 2003-06-24 09:41:39,   55¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(cgitelnet.zip, 6,522Byte)ÀÌ ÀÖ½À´Ï´Ù. telnet for ftp port ´Ù¿î·Îµå : cgitelnet.zip (6,522Byte) cgitelnet.zip 6KB 6196 °ü¸®ÀÚ 06-24
54 2002-11-29 11:00:25,   54¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(hcode_spam_filter.tar.bz2, 93,421Byte)ÀÌ ÀÖ½À´Ï´Ù. filter¸¦ ÀÌ¿ëÇÑ ½ºÆÔÁ¦°Å ´Ù¿î·Îµå : hcode_spam_filter.tar.bz2 (93,421Byte) hcode_spam_fil 91KB 6244 Admin 11-29
53 2002-10-31 12:29:01,   53¹ø ±Û ¹Ù·Îº¸±â Linux/Slapper.worm.B -------.cinik ¢¸     0 Admin 10-31
52 2002-08-13 17:30:24,   52¹ø ±Û ¹Ù·Îº¸±â ½ºÆÔ¸ÞÀÏ Â÷´Ü¹æ¹ý     0 Admin 08-13
52¹øÀÇ °ü·Ã±Û 2002-08-13 18:47:20,   52¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: ½ºÆÔ¸ÞÀÏ Â÷´Ü¹æ¹ý     0 Admin 08-13
52¹øÀÇ °ü·Ã±Û 2002-11-28 11:59:46,   52¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: ½ºÆÔ¸ÞÀÏ Â÷´Ü¹æ¹ý     0 °ü¸®ÀÚ 11-28
51 2002-05-24 15:19:42,   51¹ø ±Û ¹Ù·Îº¸±â ¸®´ª½º °ü¸®ÀÚ¸¦À§ÇÑ ÆÄ¿ö ÆÁ     0 °ü¸®ÀÚ 05-24
50 2002-05-20 12:31:05,   50¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(Coyote Linux.exe, 4,329,657Byte)ÀÌ ÀÖ½À´Ï´Ù. coyote - last all zip ¸®¶ó ÄÚ¿äÅ× ´Ù¿î·Îµå : Coyote Linux.exe (4,329,657Byte) Coyote Linux.e 4.13MB 8738 °ü¸®ÀÚ 05-20
50¹øÀÇ °ü·Ã±Û 2002-05-22 10:37:51,   50¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(msn-enable.tar, 163,840Byte)ÀÌ ÀÖ½À´Ï´Ù. coyote - last all zip ¸®¶ó ÄÚ¿ä ´Ù¿î·Îµå : msn-enable.tar (163,840Byte) msn-enable.tar 160KB 6515 °ü¸®ÀÚ 05-22
49 2002-05-02 00:02:48,   49¹ø ±Û ¹Ù·Îº¸±â ȨÆäÀÌÁö °Ë»ö»çÀÌÆ® µî·ÏÆÁ     0 °ü¸®ÀÚ 05-02
48 2002-04-12 10:01:40,   48¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(forwarding.txt, 3,347Byte)ÀÌ ÀÖ½À´Ï´Ù. À¯µ¿ ipÀÇ °íÁ¤È­ -forwarding Æ÷¿öµù ´Ù¿î·Îµå : forwarding.txt (3,347Byte) forwarding.txt 3KB 6938 °ü¸®ÀÚ 04-12
 


Copyright (C) 2001 jog.co.kr All rights reserved.