¿À´ÃÀÇ Å°¿öµå : Áß±¹, ÄɳÄ, ¹Ù¿îƼ ¹ö±×, ¼Ò´Ï ÇÈó½º
Áß±¹, ÇØÄ¿¿Í ¸Ö¿þ¾îÀÇ ¿Â»óÁöÀΰ¡
¼Ò´Ï ÇÈó½º »çÅ ¼ö»ç °á°ú°¡ ¾ÆÁ÷Àº °¢¾ç°¢»ö
[º¸¾È´º½º ¹®°¡¿ë] ¾Æ½Ã¾Æ¿Í ¾ÆÇÁ¸®Ä«·Î ¼öÃâµÇ´Â Áß±¹»ê Àúºñ¿ë ÇÚµåÆù ±â±âµé¿¡¼ ¸Ö¿þ¾î°¡ ¹ß°ßµÇ°í ÀÖ´Ù´Â º¸µµÀÔ´Ï´Ù. ¾Æ¿¹ Á¦ÀÛ ´Ü°è¿¡¼ºÎÅÍ ½É°ÜÁø °ÍÀ¸·Î º¸À̴µ¥¿ä, ÀÌ·± »ç°ÇÀÌ ÀÚ²Ù¸¸ ¹Ýº¹µÇ´Â °Ç ¾ÆÁ÷±îÁö ½ÃÀåÁÖÀÇ¿¡¼´Â °ª½Ñ °Ô ¡®À嶯¡¯À̱⠶§¹®ÀÔ´Ï´Ù. ±×·± Áß±¹ÀÌ ¾ÆÇÁ¸®Ä« ÄɳĿ¡±îÁö °¡¼ ±â¼÷»ç±îÁö Â÷·Á³õ°í ÇØÅ·À» ½ÃµµÇÏ´Ù°¡ °æÂû¿¡ ÀâÇû½À´Ï´Ù. ÇØÄ¿¿Í »çÀ̹ö ´ã´çÀÚÀÇ ¼û¸·È÷´Â ÃßÀûÀÌ ¹ú¾îÁø °Ô ¾Æ´Ï¶ó, ºÒÀÌ ³ª¼ ÇöÀåÀ» »ìÇÇ´ø °æÂû¿¡ ´ú¹Ì°¡ ÀâÈù ¿ô±ä ÇØÇÁ´×À̱⵵ Çß½À´Ï´Ù. ÀÌÁýÆ®ÀÇ º¸¾È Àü¹®°¡´Â ÆäÀÌÆȷκÎÅÍ µÎµÏÇÑ º¸»óÀ» ¹ÞÀº °¡¿îµ¥, ¹Ì±¹ º¸¾È¾÷°è´Â ¾ÆÁ÷µµ ¼Ò´Ï ÇÈó½º »çÅ·ΠÃʺñ»óÀÔ´Ï´Ù. ÁÖ¸»ÀÌ Áö³ª¸é À±°ûÀÌ Á» ÀâÈú±î¿ä. ¿Ü½Å ±âÀڷμ´Â ÀÏÀÌ ´ú ³¡³ ÁÖ¸»À» ¸ÂÀÌÇÒ °Í °°½À´Ï´Ù.
¡ã ÄɳıîÁö °¬À¸¸é ÁÁÀº °æÄ¡³ª ±¸°æÇÒ °ÍÀÌÁö...
1. Áß±¹»ê ¸Ö¿þ¾î ¡®µ¥¾²¸µ¡¯, ½º¸¶Æ®Æù¿¡ ÇÁ¸®·ÎµåµÈ ä ¹ß°ß(Infosecurity Magazine)
http://www.infosecurity-magazine.com/news/deathring-chinese-trojan-preloaded/
µ¥¾²¸µ : °ª½Ñ ¾Èµå·ÎÀ̵å Àüȱ⿡ ¿Ã¶óź ¸Ö¿þ¾î(The Register)
http://www.theregister.co.uk/2014/12/04/cheapo_androids_prepwned_with_mobile_malware/
¾Æ½Ã¾Æ, ¾ÆÇÁ¸®Ä«¿¡¼ ÆǸŵǰí ÀÖ´Â ¸ð¹ÙÀÏ ÀüÈ¿¡ ¸Ö¿þ¾î žÀç(Security Week)
http://www.securityweek.com/malware-found-pre-loaded-phones-sold-asia-africa-research
¾Æ½Ã¾Æ¿Í ¾ÆÇÁ¸®Ä«¿¡ ºñ±³Àû °ªÀÌ ½Ñ ·Î¿ì¿£µå ½º¸¶Æ®ÆùÀÌ ³Î¸® À¯ÅëµÇ°í Àִµ¥¿ä, ¿©±â¿¡ Áß±¹»ê Æ®·ÎÀ̸ñ¸¶ ¹ÙÀÌ·¯½º°¡ žÀçµÇ¾î ÀÖ´Â °ÍÀ¸·Î µå·¯³µ½À´Ï´Ù. ÀüȺ§ ¼Ò¸®¿Í °ü·ÃµÈ ¾ÖÇø®ÄÉÀ̼Çó·³ À§ÀåµÇ¾î ÀÖÁö¸¸ C&C ¼¹ö·ÎºÎÅÍ SMS¿Í WAP ÄÜÅÙÃ÷¸¦ ´Ù¿î·Îµå ¹Þ¾Æ¼ °³ÀÎ Á¤º¸¸¦ »©µ¹¸°´Ù°í ÇÕ´Ï´Ù. °Ô´Ù°¡ ÀüȱⰡ ²¨Á³´Ù°¡ ÄÑÁö±â¸¦ 5¹ø° ¹Ýº¹ÇÑ ÈĺÎÅÍ È¤Àº ¡®ÀÚ¸®ºñ¿ò¡¯ »óÅ°¡ 50¹ø Áö³ ÈĺÎÅÍ È°¼ºÈµÇ´Â ÁÖµµ¸é¹ÐÇÔ±îÁö °®Ãß°í ÀÖ´Ù°í ÇÕ´Ï´Ù. ÇÏÁö¸¸ ÀÌ·± °æ°í°¡ ´º½º·Î ³ª°¡´õ¶óµµ »ì »ç¶÷Àº Àüȱ⸦ »ì °Ì´Ï´Ù. °ªÀÌ Àú·ÅÇϴϱî¿ä. ½ÃÀå°æÁ¦ üÁ¦¿¡¼ °ªÀÌ ½Î´Ù´Â ÀåÁ¡À» ÀÌ±æ ´ÜÁ¡Àº ¹«¾ùÀÌ ÀÖÀ»±î¿ä?
2. ÄÉ³Ä Á¤ºÎ, Áß±¹ ÇØÄ¿ 77¸í üÆ÷(SC Magazine)
http://www.scmagazine.com/kenyan-authorities-arrest-77-chinese-hackers/article/386776/
Áß±¹ÀÎ ¼ö½Ê ¸í, ÄɳĿ¡ ÀâÇô ¾ï·ù(Security Week)
http://www.securityweek.com/dozens-chinese-held-kenya-cyber-bust-report
ÄÉ³Ä Åë½Å ½Ã½ºÅÛ ÇØÅ·À» ½ÃµµÇÑ °ÍÀ¸·Î ¾Ë·ÁÁø Áß±¹ÀÎ 77¸íÀÌ ÄÉ³Ä °æÂû¿¡ ÀÇÇØ Ã¼Æ÷´çÇß°í ÇöÀç ³ªÀ̷κñ ¹ýÁ¤¿¡ ³Ñ°ÜÁø »óŶó°í ÇÕ´Ï´Ù. Àç¹ÌÀÖ´Â °Ç ÄÉ³Ä °æÂûÀ̳ª »çÀ̹ö ¼ö»ç´ë °°Àº °÷¿¡¼ ÀÌ»ó ¡Èĸ¦ ¹ß°ßÇؼ »çÀ̹ö »óÀÇ ±â¼úÀûÀÌ°í °íµµÈµÈ ÃßÀû ³¡¿¡ ÀâÀº °Ô ¾Æ´Ï¶ó, ¹Ì±¹ ´ë»ç°ü ±Ùó ¾î´À °Ç¹°¿¡¼ ºÒÀÌ ³µ´Ù´Â ½Å°í¸¦ ¹Þ°í Ã⵿Çߴµ¥, ¸¶Ä§ ±×°÷ÀÌ ÀÌ Áß±¹ÀÎ ÇØÄ¿µéÀÇ º»°ÅÁö¿´´Ù°í ÇÕ´Ï´Ù. °¡ºÃ´õ´Ï ÀÌ»óÇÑ Àåºñ°¡ ¸¹¾Æ¼ ¼ö»ç¸¦ ÇÏ´Ù°¡ ¹àÇô³½ »ç½ÇÀ̶ó°í Çϳ׿ä. À̹ø ÀÏ·Î Áß±¹ ´ë»çµµ Á¶»ç¸¦ ¹Þ°í ÀÖ°í Áß±¹ Á¤ºÎ¿¡¼µµ Ãß°¡ ¼ö»ç¸¦ À§ÇØ ÀηÂÀ» ÆÄ°ßÇÑ´Ù°í ÇÕ´Ï´Ù.
3. º¸¾È Àü¹®°¡, ÆäÀÌÆÈ °èÁ¤¿¡¼ ¹ö±× ¹ß°ßÇØ Àϸ¸ ´Þ·¯ º¸»ó±Ý ¹Þ¾Æ(Security Week)
http://www.securityweek.com/researcher-earns-10000-reporting-paypal-account-hijacking-bug
ÀÌÁýÆ®ÀÇ º¸¾ÈÀü¹®°¡ÀÎ ¾ß¼¼¸£ ¾Ë¸®(Yasser Ali)¶ó´Â »ç¶÷ÀÌ ÆäÀÌÆÈ¿¡¼ Àû¿ëÇÏ°í ÀÖ´Â CSRF º¸È£ ¸ÞÄ¿´ÏÁòÀ» ¶Õ¾î³»´Â ¹ýÀ» ¾Ë¾Æ³Â°í, À̸¦ ÆäÀÌÆÈ¿¡ ¾Ë·Á¼ ½ò½òÇÑ º¸»óÀ» ¹Þ¾Ò½À´Ï´Ù. »ç¿ëÀÚ °èÁ¤À» ÈÉÃij»¼ ¸¶À½´ë·Î °áÁ¦¸¦ ÇÒ ¼ö ÀÖ°Ô ÇØÁÖ´Â Ãë¾àÁ¡À̾úÀ¸¸ç, ¾Ë¸®´Â ÀÚ¼¼ÇÑ ½ºÅ©¸³Æ® ¹× µ¿¿µ»ó ½Ã¿¬ Àå¸é±îÁö ÇÔ²² ÆäÀÌÆÈ¿¡ Àü´ÞÇß´Ù°í ÇÕ´Ï´Ù. ÆäÀÌÆÈÀº ±²ÀåÈ÷ ½Å¼ÓÇÏ°Ô ÀÌ ¹®Á¦¸¦ ó¸®Çß°í, ¾Ë¸®¿¡°Ô º¸»ó±Ýµµ ³Ë³ËÇÏ°Ô ÁÖ¾ú´Ù°í ÇÏ´Ï ½É»óÄ¡ ¾ÊÀº ¹®Á¦¿´´ø °Ç È®½ÇÇغ¸ÀÔ´Ï´Ù.
4. ¼Ò´Ï ÇÈó½º »ç°Ç ¼ö»ç Áß µ¥½ºÅä¹ö ¸Ö¿þ¾î ¹ß°ß(Threat Post)
http://threatpost.com/details-emerge-on-sony-wiper-malware-destover/109727
¼Ò´Ï ÇÈó½º ¸Þ°¡ÇÙ : º¸¾È ¾÷üµé Á¶»ç¿¡ ³ª¼(The Register)
http://www.theregister.co.uk/2014/12/04/sony_hack_wiper_malware/
º¸¾È Àü¹®°¡µé, ¼Ò´Ï ÇÈó½º °ø°Ý¿¡ »ç¿ëµÈ ÀÚÆø ¸Ö¿þ¾î ºÐ¼®¿¡ ³ª¼(Security Week)
http://www.securityweek.com/researchers-analyze-data-wiping-malware-used-sony-attack
¼Ò´Ï ÇÙ : µ¥½ºÅä¹ö ¸Ö¿þ¾î ¹ß°ß(CU Infosecurity)
http://www.cuinfosecurity.com/sony-hack-destover-malware-identified-a-7638
¼Ò´Ï ÇÈó½º »çÅ°¡ ¾ÆÁ÷±îÁö ½Ã²ø½Ã²øÇÕ´Ï´Ù. º»Áö¿¡¼´Â Áö³ 6.25Å×·¯ ¶§ »ç¿ëµÇ¾ú´ø ¸Ö¿þ¾î¿Í À̹ø ¼Ò´Ï ÇÈó½º »çÅ¿¡ »ç¿ëµÇ¾ú´ø ¸Ö¿þ¾î°¡ °°Àº °ÍÀ̶ó´Â º¸µµ°¡ ´Üµ¶À¸·Î ³ª°£ °¡¿îµ¥ ¿Ü±¹¿¡¼´Â µ¥½ºÅä¹ö(Destover)¶ó´Â ¸Ö¿þ¾î¸¦ ¹ß°ßÇß´Ù´Â º¸µµ°¡ ³ª¿À°í ÀÖ½À´Ï´Ù. µ¥½ºÅä¹ö ¸Ö¿þ¾îÀÇ ´Ù¸¥ À̸§Àº À§ÆÈ(Wipall)À̶ó°íµµ ÇÕ´Ï´Ù. ¶ÇÇÑ ¹Ì±¹ Á¶Á÷¿¡ ÀÌ·± Á¾·ùÀÇ ¸Ö¿þ¾î·Î °ø°ÝÀÌ ÀÏ¾î³ °Ô À̹øÀÌ Ã³À½À̶ó°íµµ ÇÕ´Ï´Ù. ÀÏ´Ü Áö±Ý ¹Ì±¹ º¸¾È ¾÷üµéÀº ÇÑ ¸¶À½À¸·Î À̹ø »çŸ¦ ºÐ¼® ¹× ¼ö»çÇÏ°í ÀÖ´Â °Í °°¾Æ¼ ¿©·¯ ¸Åü¿¡¼ ÀÌ·± Àú·± ¼Ò¸®°¡ ³ª¿À°í ÀÖ½À´Ï´Ù¸¸, ÅëÀÏµÈ °á°ú´Â ³ª¿À°í ÀÖÁö ¾Ê½À´Ï´Ù.
[±¹Á¦ºÎ ¹®°¡¿ë ±âÀÚ(globoan@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>