ARP½ºÇªÇÎ °ø°Ý¿¡ ´ëÇÑ ´ëó¹ý ¼÷Áö...Áß¿ä
ÃÖ±Ù¿¡´Â ARP ½ºÇªÇΰú SQL InjectionÀÇ °ø°Ý¹æ¹ýÀ¸·Î ÀÎÇÑ ÇÇÇØ°¡ ¹ß»ýÇÏ´Â ¼Óµµ°¡ »¡¶óÁö°í ÀÖ´Ù. ÀÌ¿¡µû¶ó Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø(ÀÌÇÏ KISA)´Â ÀÌ´Þ ÃÊ ARP Poisoning [Spoofing] ¾Ç¼ºÄÚµå °¨¿°»ç°í ºÐ¼® º¸°í¼¸¦ ¹ßÇ¥Çß´Ù.
ÀÌ º¸°í¼ ¿Ü¿¡µµ KISA¿¡¼´Â ¸Å³â 'ARP ½ºÇªÇÎ'À» ÀÌ¿ëÇÑ °ø°Ý »ç·Ê¿Í ´ëÃ¥ ¹æ¹ýÀÇ º¸°í¼¸¦ ¹ßÇ¥ÇØ ¿Ô´Ù. ARP ½ºÇªÇÎ °ø°ÝÀÌ Áõ°¡ÇÔ¿¡µû¶ó KISAÀÇ ÇØÅ· ºÐ¼® ¹× ´ëÃ¥ º¸°í¼¸¦ ã´Â »ç¶÷µéÀÌ ºÎ½ ´Ã°í ÀÖ´Ù.
Çѱ¹Á¤º¸º¸È£ÁøÈï¿øÀÇ º¸°í¼¿¡ µû¸£¸é 'ARP Spoofing °ø°Ý'Àº ·ÎÄà ³×Æ®¿öÅ©(LAN)¿¡¼ »ç¿ëÇÏ´Â ARP ÇÁ·ÎÅäÄÝÀÇ ÇãÁ¡À» ÀÌ¿ëÇÏ¿© ÀÚ½ÅÀÇ MAC(Media Access Control) ÁÖ¼Ò¸¦ ´Ù¸¥ ÄÄÇ»ÅÍÀÇ MACÀÎ °Íó·³ ¼ÓÀÌ´Â °ø°ÝÀ̸ç, ARP Cache Á¤º¸¸¦ ÀÓÀÇ·Î ¹Ù²Û´Ù°í ÇÏ¿© "ARP Cache Poisoning °ø°Ý" À̶ó°íµµ ÇÑ´Ù°í Á¤ÀÇÇÏ°í ÀÖ´Ù.
<Ãâó: KISA 07³â 6¿ù ARP Spoofing °ø°Ý ºÐ¼® ¹× ´ëÃ¥ º¸°í¼ ñé>
ÀÌ·¯ÇÑ ÇØÅ· ¹æ¹ýÀº ±âÁ¸¿¡µµ ÀÖ´ø ¹æ¹ýÀ¸·Î °ø°Ý Ƚ¼ö°¡ ÁÙ¾îµéÁö ¾Ê°í ÀÖÀ¸¸ç ¿ÀÈ÷·Á ±× ¹æ¹ýÀ̳ª °ø°ÝÇüÅ°¡ Á¡Á¡ ¹ßÀüÇÏ°í ÀÖ´Ù.
½ÉÁö¾î À̹ø¿¡ ¹ß°ßµÈ ¾Ç¼ºÄÚµå´Â °ø°Ý´ë»ó ¹üÀ§°¡ ·ÎÄà ³×Æ®¿öÅ©(LAN)¸¦ ³Ñ¾î USB À̵¿ÀúÀå ÀåÄ¡ ¹× ³×Æ®¿öÅ© °øÀ¯¸¦ ÅëÇÑ ÀüÆıâ´Éµµ ±¸ÇöÇÏ°í ÀÖ¾î Ÿ ³×Æ®¿öÅ©·Î °¨¿°¹üÀ§¸¦ ³ÐÈú ¼ö ÀÖ´Ù°í Çß´Ù.
<Ãâó : KISA 08³â 7¿ù ARP Spoofing º¸°í¼>
'ARP ½ºÇªÇÎ'À¸·Î ÀÎÇÑ °ø°ÝÀ¸·Î ÃֽŠº¸¾ÈÆÐÄ¡¿Í ¾ÈƼ¹ÙÀÌ·¯½º µî º¸¾È°ü¸®¸¦ Àß ÇÏ°í ÀÖ´Â »ç¿ëÀÚ¶ó ÇÒÁö¶óµµ ARP ½ºÇªÇο¡ °¨¿°µÈ ³×Æ®¿öÅ©¿¡ ÀÖÀ» °æ¿ì ½±°Ô µ¥ÀÌÅÍ°¡ À¯ÃâµÇ°Å³ª º¯Á¶ µÉ ¼öµµ ÀÖ´Ù.
°¨¿°µÈ ³×Æ®¿öÅ©¿¡ ÀÖ´Â ³×Æ®¿öÅ©ÀÇ ¼Óµµ´Â ´À·ÁÁö°Ô µÇ¸ç ARP Å×À̺íÀ» º¯Á¶ÇÑ »óÅ·ΠÀ¯ÁöÇϱâ À§ÇØ º¯Á¶ÇÑ ´Ù·®ÀÇ ARP ÆÐŶÀÌ »ç¿ëÀÚÀÇ ID ¹× Æнº¿öµå¿Í °°Àº °³ÀÎÁ¤º¸¸¦ À¯ÃâÇÏ°Ô µÇ¸ç, ½ÉÁö¾î´Â ±ÝÀ¶±â°ü µîÀ» »çĪÇÏ´Â ÇÇ½Ì ¶Ç´Â ÆÄ¹Ö °ø°Ý¿¡µµ »ç¿ëµÇ¾î °³ÀÎÀÇ ±ÝÀüÀû ¼Õ½ÇÀ» ÃÊ·¡ÇÒ ¼ö ÀÖ´Ù°í ÀüÇÑ´Ù.
ÀÌó·³ ARP Spoofing °ø°ÝÀº ´Ù¾çÇÏ°Ô ¾Ç¿ë°¡´ÉÇÏ°í ÇÇÇصµ ½É°¢ÇÏÁö¸¸ °ø°Ý¿¡ ´ëÇÑ Å½Áö¿Í ´ëÀÀÀº ½±Áö ¾Ê´Ù.
ARP SpoofingÀÇ °ø°Ý´ë»óÀº ÀÚ½ÅÀÇ ½Ã½ºÅÛÀÌ Á÷Á¢ ´çÇÑ °ÍÀÌ ¾Æ´Ï¹Ç·Î ÇÇÇØ »ç½ÇÁ¶Â÷ ÆľÇÇϱ⠾î·Á¿î ½ÇÁ¤ÀÌ´Ù.
»ç¿ëÀÚµé ¹× ³×Æ®¿öÅ© °ü¸®ÀÚµéÀº ARP Spoofing °ø°ÝÀ» ¹æ¾îÇϱâ À§ÇØ KISA¿¡¼ ³»³õÀº ¹æ¹ýÀ» ¼÷ÁöÇØ ÇÇÇظ¦ ÁÙÀÏ ¼ö ÀÖµµ·Ï ÇØ¾ß ÇÑ´Ù.
<Âü°í>
KISA¿¡¼ ¹ßÇ¥ÇÑ ARP Spoofing °ø°Ý ºÐ¼® ¹× ´ëÃ¥ º¸°í¼
[KrCERT/CC 2008.07 - ARP Poisoning [Spoofing] ¾Ç¼ºÄÚµå °¨¿°»ç°í ºÐ¼®]
http://www.krcert.or.kr/unimDocsDownload.do?fileName1=ARP%20Poisoning.pdf&docNo=TR2008005&docKind=2
[KrCERT/CC 2007.06 - ARP Spoofing °ø°Ý ºÐ¼® ¹× ´ëÃ¥]
http://www.krcert.or.kr/unimDocsDownload.do?fileName1=TR20070704_ARP_Spoofing.pdf&docNo=TR2007001&docKind=2
[KrCERT/CC 2007.02 - ARP Spoofing ±â¹ý ÀÌ¿ë À¥ÆäÀÌÁö ¾Ç¼ºÄÚµå »ðÀÔ»ç·Ê]
http://www.krcert.or.kr/unimDocsDownload.do?fileName1=IN2007003.pdf&docNo=IN2007003&docKind=3
[°¼º¹Î °´¿ø±âÀÚ reporter@boannews.com]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(www.boannews.com) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>