-------------------------------------------------------------------------------- NAME: Slapper ALIAS: Linux.Slapper-A, Linux.Slapper-Worm, Apache/mod_ssl Worm, Slapper.source ---------------------------------------------------------------------------------
Slapper´Â ¸®´ª½º ¸Ó½Å¿¡¼ °¨¿° ÀüÆÄµÇ´Â ³×Æ®¿öÅ© ¿úÀÔ´Ï´Ù. 2002³â 8¿ù ¹ß°ßµÈ OpenSSL ¶óÀ̺귯¸®¿¡ ´ëÇÑ °áÇÔÀ» ÀÌ¿ëÇÕ´Ï´Ù. ÀÌ ¿úÀº 2002³â 9¿ù 14ÀÏ ±Ý¿äÀÏ Àú³á¿¡ µ¿À¯·´ Áö¿ª¿¡¼ ¹ß°ßµÇ¾ú½À´Ï´Ù.
OpenSSL + Apache À¥ÀÌ µ¿ÀÛÇϰí ÀÖ´Â ¸®´ª½º ¸Ó½ÅÀ» °¨¿°½Ãŵ´Ï´Ù. ÀÎÅÍ³Ý À¥ »çÀÌÆ® Áß 60% ÀÌ»óÀÌ Apache À¥ ¼¹ö¸¦ »ç¿ëÇϰí ÀÖ½À´Ï´Ù. SSLÀº ´ëºÎºÐ ¿Â¶óÀÎ »óǰ ÆÇ¸Å, ÀºÇà ¾îÇø®ÄÉÀ̼ǿ¡¼ ¸¹ÀÌ »ç¿ë Áß¿¡ ÀÖ½À´Ï´Ù.
ÇÑ ½Ã½ºÅÛÀÌ ÀÌ ¿ú¿¡ °¨¿°µÇ°Ô µÇ¸é »õ·Î¿î ½Ã½ºÅÛÀ¸·Î È®»êµË´Ï´Ù. ´õ±¸³ª, ÀÌ ¿úÀº peer-to-peer¿¡ ±â¹ÝÇÑ ³×Æ®¿öÅ© °ø°Ý Äڵ带 °¡Áö°í ÀÖÀ¸¹Ç·Î °¨¿°µÈ ½Ã½ºÅÛÀº ºÐ»ê ¼ºñ½º °ÅºÎ °ø°Ý(DDoS)¿¡ ÀÌ¿ëµÉ ¼öµµ ÀÖ½À´Ï´Ù.
ÀÌ ¿úÀº Red Hat, SuSe, Mandrake, Slackware, Debian »çÀÇ ¸®´ª½º ¹èÆ÷ÆÇÀ» ¿î¿µ ÁßÀÎ ÀÎÅÚ ±â¹Ý ¸Ó½Å »ó¿¡¼ µ¿ÀÛÇÕ´Ï´Ù. Apache¿Í OpenSSLÀÌ È°¼ºÈ µÇ¾î ÀÖ°í OpenSSL ¹öÀüÀÌ 0.96d ÀÌÀü ¹öÀüÀÌ¸é ¿ú¿¡ °¨¿°µË´Ï´Ù.
Slapper´Â 2002³â 6¿ù ¹ß°ßµÇ¾ú´ø Scalper Apache ¿ú°ú ¸Å¿ì Èí»çÇÕ´Ï´Ù. ±âº»ÀûÀÎ µ¿ÀÛ ¹æ½ÄÀº Àü¼¼°èÀûÀ¸·Î ¸¹Àº ÇÇÇØ¸¦ ÀÔÈù Code Red À¥ ¿ú°ú À¯»çÇÕ´Ï´Ù. Code Red´Â 2001³â 7¿ù Microsoft IIS¸¦ ¿î¿µ ÁßÀÎ 350000 ÀÌ»óÀÇ À¥ »çÀÌÆ®¸¦ °¨¿°½ÃŲ ¹Ù ÀÖ½À´Ï´Ù.
------------------------------ UPDATE (2002-09-14 20:30 GMT) ------------------------------ Áö±Ý±îÁö F-Secure´Â ´ÙÀ½ ±¹°¡µé·ÎºÎÅÍ °¨¿°µÈ ÄÄÇ»Å͵鿡 ´ëÇÑ Á÷Á¢ ȤÀº °£Á¢Àû º¸°í¼¸¦ ÀÔ¼öÇÏ¿´½À´Ï´Ù.
Norway Lithuania Romania Portugal Japan The Netherlands China Turkey India USA Taiwan UK
------------------- VARIANT: Slapper.A -------------------
ÀÌ ¿ú¿¡ °¨¿°µÇ°Ô µÇ¸é /tmp/.uubugtraqÀ̶ó´Â À̸§À¸·Î uuencodeµÈ ¿úÀÇ Àڱ⠺¹Á¦º»ÀÌ »ý¼ºµË´Ï´Ù. ¿úÀº ÇØ´ç ÆÄÀÏÀ» /tmp/.bugtraq.cÀ̶ó´Â À̸§À¸·Î µðÄÚµùÇÏ¿© gcc ÄÄÆÄÀÏÇÑ ÈÄ¿¡ /tmp/.bugtraqÀ̶ó´Â À̸§ÀÇ ½ÇÇà ÆÄÀÏÀ» »ý¼ºÇÕ´Ï´Ù. ÀÌ ÆÄÀÏÀÌ ³ªÁß¿¡ ½ÇÇàµÇ°Ô µË´Ï´Ù.
-- Á¦°Å ¹æ¹ý -- '.bugtraq'À̶ó´Â ÇÁ·Î¼¼½º°¡ Ȱ¼ºÈµÇ¾î ÀÖ´Ù¸é ¿ú¿¡ °¨¿°µÈ °ÍÀÔ´Ï´Ù. ÀÌ ÇÁ·Î¼¼½º¸¦ Á¾·á½Ã۰í Àӽà µð·ºÅ丮¿¡ »ý¼ºµÈ ´ÙÀ½ ÆÄÀÏÀ» »èÁ¦ÇÔÀ¸·Î½á ¿úÀ» Á¦°ÅÇÒ ¼ö ÀÖ½À´Ï´Ù.
/tmp/.uubugtraq /tmp/.buqtraq.c /tmp/.bugtraq
Apache À¥ ¼¹ö´Â ¼Ë ´Ù¿î½ÃŲ ÈÄ, Àç°¨¿°À» ¹æÁöÇϱâ À§ÇÏ¿© OpenSSL ¶óÀ̺귯¸®¸¦ 0.9.6e ÀÌÈÄ ¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇÏ¼Å¾ß ÇÕ´Ï´Ù.
------------------ ºÎ°¡Àû °ü·Ã »ó¼¼ Á¤º¸ -------------------
OpenSSL º¸¾È ±Ç°í¹®: http://www.openssl.org/news/secadv_20020730.txt
CERT(r) ±Ç°í¹®: http://www.cert.org/advisories/CA-2002-23.html
°¢Á¾ ¸®´ª½º º¥´õÀÇ º¸¾È ±Ç°í¹®:
Debian: http://www.debian.org/security/2002/dsa-136 Mandrake: http://www.mandrakelinux.com/en/security/2002/MDKSA-2002-046.php RedHat: http://rhn.redhat.com/errata/RHSA-2002-155.html SuSE: http://www.suse.com/de/security/2002_027_openssl.html
[Analysis: Sami Rautiainen and Mikko Hypponen, F-Secure Corporation; September 14th, 2002]
-------------------------------------- (ÁÖ)½Ã¸Ó½º º¸¾È»ç¾÷ÆÀ ¿À °æ ¼¿ï½Ã °³²±¸ ¿ª»ïµ¿ 708-33 ÆÄ¶ó´ÙÀ̽º º¥Ã³Å¸¿ö 2F Tel:82-2-569-8135 Fax:82-2-569-8137 H.P:016-268-1794 ---------------------------------------
--------------------------------------------------------- sec-info Mailing list Å»Å𸦠¿øÇϽôºÐÀº ¸Þ½ÃÁö º»¹®¿¡ ´ÙÀ½°ú °°ÀÌ ¾²½ÅÈÄ <Majordomo@certcc.or.kr>·Î ¸ÞÀÏÀ» º¸³» ÁÖ½Ã¸é µË´Ï´Ù.
unsubscribe sec-info your-mail-address ---------------------------------------------------------
|