๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
โœ’๏ธ Security issues & Technology trends

[Security issues & Technology trends] ๊ตญ์„ธ์ฒญ์„ ์‚ฌ์นญํ•˜์—ฌ ์ „์ž์„ธ๊ธˆ๊ณ„์‚ฐ์„œ๋ฅผ ๋„์šฉํ•˜๊ณ  ์•…์„ฑ์ฝ”๋“œ๋ฅผ ์œ ํฌํ•œ ์ •ํ™ฉ ๋ฐœ๊ฒฌ

by A Lim Han 2022. 9. 12.

 

 

9/12 ) ๊ตญ์„ธ์ฒญ์„ ์‚ฌ์นญํ•˜์—ฌ ์ „์ž์„ธ๊ธˆ๊ณ„์‚ฐ์„œ๋ฅผ ๋„์šฉํ•˜๊ณ  ์•…์„ฑ์ฝ”๋“œ๋ฅผ ์œ ํฌํ•œ ์ •ํ™ฉ ๋ฐœ๊ฒฌ

 

 

์•…์„ฑ์ฝ”๋“œ๊ฐ€ ์ฒจ๋ถ€๋œ ํ”ผ์‹ฑ ๋ฉ”์ผ์˜ ์›๋ณธ [์ž๋ฃŒ=์‹œํ์•„์ด, ๋ณด์•ˆ๋‰ด์Šค]

 

 ์ตœ๊ทผ ๋ˆ„๊ตฐ๊ฐ€๊ฐ€ ๊ตญ์„ธ์ฒญ์„ ์‚ฌ์นญํ•˜์—ฌ ์ „์ž์„ธ๊ธˆ๊ณ„์‚ฐ์„œ๋ฅผ ๋„์šฉํ•˜๊ณ , ์•…์„ฑ์ฝ”๋“œ๋ฅผ ์œ ํฌํ•œ ์ •ํ™ฉ์ด ๋ฐœ๊ฒฌ๋˜์—ˆ๋‹ค. ์‹œํ์•„์ด์˜ ์œ„ํ˜‘๋ถ„์„๊ทธ๋ฃน์€ ๋ฌธ์ œ์˜ ๋ฉ”์ผ์ด ๋ฆฌ๋ˆ…์Šค์˜ ์ด๋ฉ”์ผ ํด๋ผ์ด์–ธํŠธ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์†ก์‹ ์ž์˜ ์ฃผ์†Œ๋ฅผ ์œ„์กฐํ•˜์˜€๊ณ , ์นœํ™˜๊ฒฝ ๊ธฐ๋Šฅ์„ฑ ํ™”ํ•™์ œํ’ˆ์„ ์ œ์กฐํ•˜๋Š” ํšŒ์‚ฌ์˜ ์ง์›๋“ค์„ ๋Œ€์ƒ์œผ๋กœ ๋ฐœ์†ก๋˜์—ˆ์Œ์„ ๋ฐํ˜”๋‹ค. ์œ„์˜ ๋ฉ”์ผ์— ์ฒจ๋ถ€๋œ ํŒŒ์ผ์€ Portable executable ํŒŒ์ผ๋กœ, ํ™•์žฅ์ž๋กœ .pdf.exe๋ผ๋Š” ํ™•์žฅ์ž๋ฅผ ๊ฐ€์ง€๋Š”๋ฐ, ์ด๋กœ ์ธํ•ด ๋ณด๊ธฐ ์˜ต์…˜ ์„ค์ • ์ƒํƒœ์— ๋”ฐ๋ผ PDF ํ™•์žฅ์ž๋กœ ๋ณด์ผ ์ˆ˜ ์žˆ๋‹ค. ํŒŒ์ผ ์† ์•…์„ฑ์ฝ”๋“œ๋Š” Nullsoft Installer๋กœ ์ œ์ž‘๋˜์—ˆ์œผ๋ฉฐ, ๊ณต๊ฒฉ ๊ฒฝ๋กœ๋Š” ์•„๋ž˜์™€ ๊ฐ™๋‹ค.

 

 

1. Installer์„ ํ†ตํ•ด ์•…์„ฑ DLL์ด ํ”„๋ ˆ์ž„์›Œํฌ์˜ ๋ณด์•ˆ ๋„๊ตฌ ์‹คํ–‰

2. ์ฝ”๋“œ ์•ก์„ธ์Šค ๋ณด์•ˆ ๋„๊ตฌ ์‹คํ–‰ ํ›„ ์ถ”๊ฐ€์ ์œผ๋กœ ์•…์„ฑ ๋ฐ”์ด๋„ˆ๋ฆฌ ์ธ์ ์…˜

3. ์ธ์ ์…˜๋œ ์•…์„ฑ ๋ฐ”์ด๋„ˆ๋ฆฌ๊ฐ€ ์•”ํ˜ธํ™” ๋ฐ”์ด๋„ˆ๋ฆฌ ๋ชจ๋“ˆ์„ ๋‹ค์šด๋กœ๋“œ

4. ๋‹ค์šด๋ฐ›์€ ๋ฐ”์ด๋„ˆ๋ฆฌ ๋ณตํ˜ธํ™” ํ›„ ๋ฉ”๋ชจ๋ฆฌ์— ์ ์žฌ

5. ๋ฉ”๋ชจ๋ฆฌ์— ์ ์žฌ๋œ NanoCore ๋ฐฑ๋„์–ด ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์ด์šฉํ•ด ๋ช…๋ น์ œ์–ด(C&C) ์„œ๋ฒ„์— ์—ฐ๊ฒฐ

6. C&C ์„œ๋ฒ„์— ์ ‘์†ํ•˜์—ฌ ๋ช…๋ น์„ ์ˆ˜์‹  ๋ฐ›์•„ ์•…์„ฑํ–‰์œ„ ์ˆ˜ํ–‰

 

 

 ๊ณต๊ฒฉ์ž๋Š” ์•„๋ž˜ ์‚ฌ์ง„๋“ค๊ณผ ๊ฐ™์ด ์›น ๋ธŒ๋ผ์šฐ์ € ๋ฐ ํด๋ผ์ด์–ธํŠธ์˜ ์ธ์ฆ ์ •๋ณด๋ฅผ ๋นผ๋Œ๋ฆฌ๊ฑฐ๋‚˜ ์›น ์„œ๋ฒ„๋ฅผ ๋Œ€์ƒ์œผ๋กœ Slowloris DDoS ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•˜๋Š” ๋“ฑ ๋‹ค์–‘ํ•œ ์•…์„ฑ ํ–‰์œ„๋ฅผ ์ˆ˜ํ–‰ํ•˜์˜€๋‹ค. ์ด์™€ ๊ฐ™์ด ์•…์„ฑ์ฝ”๋“œ๋กœ ์ธํ•œ ํ”ผํ•ด๋ฅผ ์˜ˆ๋ฐฉํ•˜๋Š” ๋ฐ์— ์žˆ์–ด ์‹œํ์•„์ด์˜ ์œ„ํ˜‘๋ถ„์„๊ทธ๋ฃน์€ ์ค‘์•™๊ธฐ๊ด€๊ณผ ๊ด€๋ จ๋˜์–ด ์ˆ˜์‹ ๋œ ๋ฉ”์ผ์ผ์ง€๋ผ๋„ ํŒŒ์ผ์˜ ํ™•์žฅ์ž๊ฐ€ ์˜ฌ๋ฐ”๋ฅธ์ง€์— ๋Œ€ํ•œ ์—ฌ๋ถ€ ํ™•์ธ์˜ ์ค‘์š”์„ฑ์„ ๊ฐ•์กฐํ•˜์˜€๋‹ค.

 

์›น ๋ธŒ๋ผ์šฐ์ € ์ธ์ฆ ์ •๋ณด ํƒˆ์ทจ[์ž๋ฃŒ=์‹œํ์•„์ด,๋ณด์•ˆ๋‰ด์Šค]
ํด๋ผ์ด์–ธํŠธ ์ธ์ฆ ์ •๋ณด ํƒˆ์ทจ[์ž๋ฃŒ=์‹œํ์•„์ด,๋ณด์•ˆ๋‰ด์Šค]
์›น ์„œ๋ฒ„ ๋Œ€์ƒ Slowloris DDoS ๊ณต๊ฒฉ ์‹œ๋„[์ž๋ฃŒ=์‹œํ์•„์ด, ๋ณด์•ˆ๋‰ด์Šค]

 

 

 

# ์–ด๋ ค์šด ์šฉ์–ด ์ •๋ฆฌ

- DLL(Dynamic Link Library = ๋™์  ๋งํฌ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ)

: ์‹คํ–‰ ํŒŒ์ผ์—์„œ ํ•ด๋‹น ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์˜ ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•  ๋•Œ๋งŒ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ ํŒŒ์ผ์„ ์ฐธ์กฐํ•˜์—ฌ ๊ธฐ๋Šฅ์„ ํ˜ธ์ถœํ•˜๋Š” ๋ฐฉ์‹์œผ๋กœ ์“ฐ๋Š” ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ. ํ•œ ์ฝ”๋“œ๋ฅผ ์—ฌ๋Ÿฌ ํ”„๋กœ๊ทธ๋žจ์ด ๋™์‹œ์— ์‚ฌ์šฉํ•˜๊ธฐ์— ์ ์€ ๋ฆฌ์†Œ์Šค๋ฅผ ์‚ฌ์šฉํ•œ๋‹ค๋Š” ์žฅ์ ์ด ์žˆ๋‹ค.

 

- ์ธ์ ์…˜

: ๊ณต๊ฒฉ์ž๊ฐ€ ์‹ ๋ขฐํ•  ์ˆ˜ ์—†๋Š” ์ž…๋ ฅ์„ ํ”„๋กœ๊ทธ๋žจ์— ์ฃผ์ž…ํ•˜๋Š” ๊ณต๊ฒฉ. HTML ์Šคํฌ๋ฆฝํŠธ ์‚ฝ์ž…, PHP ๊ฐ์ฒด ์‚ฝ์ž… ๊ณต๊ฒฉ ๋“ฑ ๋‹ค์–‘ํ•œ ํ™œ์šฉ์ด ๊ฐ€๋Šฅํ•˜๋‹ค.

 

- ๋ฐ”์ด๋„ˆ๋ฆฌ ํŒŒ์ผ(= ์ด์ง„ ํŒŒ์ผ)

: ํ…์ŠคํŠธ ํ˜•์‹์˜ ํŒŒ์ผ์ด ์•„๋‹Œ ์ปดํ“จํ„ฐ ํŒŒ์ผ๋กœ, ์‚ฌ๋žŒ์ด ์ง์ ‘ ์ฝ์„ ์ˆ˜ ์—†๋Š” ํŒŒ์ผ์ด๋‹ค.

 

 

 

์ฐธ๊ณ  ์ž๋ฃŒ :

[๋ณด์•ˆ๋‰ด์Šค] "์นœํ™˜๊ฒฝ ๊ธฐ๋Šฅ์„ฑ ํ™”ํ•™์ œํ’ˆ ์ œ์กฐ์‚ฌ ํƒ€๊นƒ ๊ตญ์„ธ์ฒญ ํ™ˆํƒ์Šค ์‚ฌ์นญ ์•…์„ฑ๋ฉ”์ผ ์œ ํฌ"_๋ณด์•ˆ๋‰ด์Šค ๊น€๊ฒฝ์•  ๊ธฐ์ž_2022-09-08

https://www.boannews.com/media/view.asp?idx=109692&page=1&mkind=1&kind=1

 

[eYewated]"DLL ํŒŒ์ผ์ด๋ž€ ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?"_ํŒ€ ํ”ผ์…”_2019-08

https://ko.eyewated.com/dll-%ED%8C%8C%EC%9D%BC%EC%9D%B4%EB%9E%80-%EB%AC%B4%EC%97%87%EC%9E%85%EB%8B%88%EA%B9%8C/

 

[ScienceDirect]"Injection Vulnerability"_Josh Pauli_2013

https://www.sciencedirect.com/topics/computer-science/injection-vulnerability#:~:text=Injection%20occurs%20when%20a%20hacker,still%20widespread%20and%20very%20damaging.

 

[techopedia]"Binary File"_2013-01-21

https://www.techopedia.com/definition/937/binary-file