[º¸¾È´º½º ±èÁö¾ð] ÃÖ±Ù ¹Ì±¹ ¿µÈ»ç ÇØÅ· »ç°í¿¡¼ SMB ¿ú µµ±¸¸¦ ÀÌ¿ëÇØ °øÀ¯ Æú´õ, ½Ã½ºÅÛ ¾ÆÀ̵ð, ½Ã½ºÅÛ Æнº¿öµå µîÀÌ À¯ÃâµÇ´Â »ç°ÇÀÌ ¹ß»ýÇØ ±¹³»¿¡¼µµ ´ëºñ°¡ ÇÊ¿äÇÏ´Ù.
ÀÌ¿¡ Microsoft Windows ¿î¿µÃ¼Á¦¸¦ »ç¿ëÇÏ´Â °æ¿ì ¹é½ÅÀ» ¼³Ä¡ÇÏ°í Ç×»ó ÃֽŠ¾÷µ¥ÀÌÆ® »óŸ¦ À¯ÁöÇØ¾ß ÇÑ´Ù. ¶Ç Ãë¾àÁ¡À» ÅëÇØ ¾Ç¼ºÄڵ尡 ÀüÆĵǴ °ÍÀ» ¹æÁöÇϱâ À§ÇØ ¿î¿µÃ¼Á¦¿Í ÀÀ¿ë ÇÁ·Î±×·¥À» ÃֽŠ¾÷µ¥ÀÌÆ® »óÅ·ΠÀ¯ÁöÇØ¾ß Çϸç, °øÀ¯ Æú´õ »ç¿ëÀ» ÀÚÁ¦ÇÏ°í Ãë¾àÇÑ Æнº¿öµåº¸´Ù´Â ¿µ¹®, ¼ýÀÚ, Ư¼ö¹®ÀÚ¸¦ Á¶ÇÕÇÑ 8ÀÚ¸® ÀÌ»óÀÇ ºñ¹Ð¹øÈ£¸¦ ¼³Á¤ÇØ¾ß ÇÑ´Ù.
±â¾÷ ½Ã½ºÅÛ °ü¸®ÀÚÀÇ °æ¿ì, 444¹ø°ú 445¹ø Æ÷Æ®ÀÇ ¸ð´ÏÅ͸µÀÌ ÇÊ¿äÇÏ¸ç ´ÙÀ½°ú °°Àº ½º³ëÆ® ·êÀ» Àû¿ëÇØ¾ß ÇÑ´Ù. ¶ÇÇÑ, SMB ¿ú µµ±¸¸¦ ÀÌ¿ëÇØ ÀüÆĵǴ Çϵåµð½ºÅ© Æı«Çü ¾Ç¼ºÄڵ忡 ÀÇÇÑ ½Ã½ºÅÛ Æı«¸¦ ´ëºñÇϱâ À§ÇØ Á¤º¸ÀÚ»ê Á¢±ÙÅëÁ¦, ¸ð´ÏÅ͸µ, º¹±¸ µî ħÇØ»ç°í ¿¹¹æ°ú ´ëÀÀ¹æ¾È ¸¶·ÃÀÌ ÇÊ¿äÇÏ´Ù.
[SMB ¿ú µµ±¸ ½º³ëÆ® ·ê Àû¿ë] alert tcp any any -> any any (msg:"Wiper 2"; sid:42000002; rev:1; flow:established; content:"|c9 06 d9 96 fc 37 23 5a fe f9 40 ba 4c 94 14 98|"; depth:16; classtype:bad-unknown;)
alert tcp any any -> any any (msg:"Wiper 3"; sid:42000003; rev:1; flow:established; content:"|aa 64 ba f2 56|"; depth:50; classtype:bad-unknown;)
alert ip any any -> any any (msg:"Wiper 4"; sid:42000004; rev:1; content:"|aa 74 ba f2 b9 75|"; depth:74; classtype:bad-unknown;)
alert tcp any any -> any [8000,8080] (msg:"Wiper 5"; sid:42000005; rev:1; flow:established,to_server; dsize:42; byte_test:2,=,40,0,little; content:"|04 00 00 00|"; depth:4; offset:38; classtype:bad-unknown;)
[¿ë¾î Á¤¸®]
SMB(Server Message Block) : ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® »çÀÇ À©µµ¿ìÁî ¹× µµ½º ¿î¿µÃ¼Á¦¿¡¼ Æú´õ ¹× ÆÄÀÏ µîÀ» °øÀ¯Çϱâ À§ÇØ »ç¿ëµÇ´Â ¸Þ½ÃÁö Çü½Ä
[±èÁö¾ð ±âÀÚ(boan4@boannews.com)]
<ÀúÀÛ±ÇÀÚ: º¸¾È´º½º(http://www.boannews.com/) ¹«´ÜÀüÀç-Àç¹èÆ÷±ÝÁö>