ÃÑ ÆäÀÌÁö ¼ö : 3224

Àüü ÇÔ¼ö/¿ë¾î»çÀü
Facebook Joinc ±×·ì   Joinc QA »çÀÌÆ®



joinc´Â Firefox¿Í chrome¿¡¼­ Å×½ºÆ® Çß½À´Ï´Ù. IE¿¡¼­´Â Å×À̺íÀÌ ±úÁö°Å³ª À̹ÌÁö°¡ º¸ÀÌÁö ¾ÊÀ» ¼ö ÀÖ½À´Ï´Ù. ƯÈ÷ ±¸±Û DocsÀ̹ÌÁöÀÇ °æ¿ì ¿¢¹Úó¸®µÉ ¼ö ÀÖ½À´Ï´Ù.

2008 08/08 ±Ý¿äÀÏ

netstat·Î È®ÀÎÇØº» °á°ú SYN_RECV °¡ ºñÁ¤»óÀûÀ¸·Î ´Ã¾î³µ´Ù. DOS°ø°ÝÀ¸·Î ÆÇ´ÜµÇ¾î¼­ ÇØ´ç IP¸¦ Block ½ÃÄ×´Ù.
tcp        0      0 0.0.0.0:80              0.0.0.0:*               LISTEN 
tcp        0      0 218.234.19.87:80        122.152.181.156:11962   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:47119   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:3429    SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:8208    SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:59406   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.155:40277   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.155:35498   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:29028   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:55652   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:42340   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:16741   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.155:26965   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:33807   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:50873   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:38586   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:25274   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.155:48810   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.155:1366    SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.155:9899    SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:64185   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.155:18432   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.155:31744   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.156:20495   SYN_RECV 
tcp        0      0 218.234.19.87:80        122.152.181.155:57343   SYN_RECV 
tcp      567      0 218.234.19.87:36126     121.185.96.43:80        CLOSE_WAIT 
tcp        0      0 218.234.19.87:22        222.119.23.60:2801      ESTABLISHED 
tcp        0      0 218.234.19.87:37489     121.185.96.48:80        ESTABLISHED 
tcp        0      0 218.234.19.87:80        222.231.42.193:34267    TIME_WAIT 
tcp        0      0 218.234.19.87:80        66.249.73.50:63782      ESTABLISHED 
tcp        0      0 218.234.19.87:80        210.116.196.225:39776   FIN_WAIT2 
tcp        0      0 218.234.19.87:80        74.6.27.107:44671       TIME_WAIT 
tcp        0  18981 218.234.19.87:80        141.85.90.195:2982      FIN_WAIT1 
 

2007

/*
joinc¼­¹ö Ãë¾àÁ¡/¹®Á¦ °¡ ÀÖÀ»½Ã ¾Æ·¡·Î ¿¬¶ô ºÎʵ右´Ï´Ù.
mail&msn: hkpco@korea.com
*/

2007Æú´õ°¡ ¾ø¾î ÀÌ·¸°Ô Àӽ÷Π¿Ã¸³´Ï´Ù.

±Ù·¡µé¾î joinc¼­¹ö°¡ ÀÌ»óÇÏ¿© ·Î±×¸¦ Àá½Ãº¸´Ï ¾öû³­ bruteforce°ø°ÝÀÌ µé¾î¿Ô¾ú½À´Ï´Ù.

ÇØ´ç¾ÆÀÌÇÇ´Â º¸½Ã´Â¹Ù¿Í°°ÀÌ 68.187.16.28À̸ç Áß±¹¹ß·Î º¸ÀÔ´Ï´Ù.

Dec 31 06:59:05 ns sshd(pam_unix)5733: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 06:59:11 ns sshd(pam_unix)5737: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 06:59:19 ns sshd(pam_unix)5743: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 06:59:27 ns sshd(pam_unix)5750: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 06:59:33 ns sshd(pam_unix)5755: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 06:59:41 ns sshd(pam_unix)5763: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 06:59:49 ns sshd(pam_unix)5771: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 06:59:57 ns sshd(pam_unix)5777: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:00:05 ns sshd(pam_unix)6024: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:00:13 ns sshd(pam_unix)6178: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:00:19 ns sshd(pam_unix)6183: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:00:27 ns sshd(pam_unix)6190: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:00:35 ns sshd(pam_unix)6197: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:00:41 ns sshd(pam_unix)6202: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:00:51 ns sshd(pam_unix)6212: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:00:59 ns sshd(pam_unix)6218: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:01:06 ns sshd(pam_unix)6224: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:01:14 ns sshd(pam_unix)6233: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:01:22 ns sshd(pam_unix)6240: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:01:28 ns sshd(pam_unix)6245: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:01:36 ns sshd(pam_unix)6256: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:01:45 ns sshd(pam_unix)6263: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:01:51 ns sshd(pam_unix)6268: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:01:59 ns sshd(pam_unix)6276: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:02:07 ns sshd(pam_unix)6283: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:02:13 ns sshd(pam_unix)6289: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:02:21 ns sshd(pam_unix)6295: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:02:29 ns sshd(pam_unix)6302: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:02:35 ns sshd(pam_unix)6311: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:02:43 ns sshd(pam_unix)6319: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:02:51 ns sshd(pam_unix)6330: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:02:58 ns sshd(pam_unix)6336: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:03:06 ns sshd(pam_unix)6342: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:03:14 ns sshd(pam_unix)6349: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:03:20 ns sshd(pam_unix)6355: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:03:29 ns sshd(pam_unix)6362: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:03:37 ns sshd(pam_unix)6369: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:03:43 ns sshd(pam_unix)6373: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:03:51 ns sshd(pam_unix)6382: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:03:59 ns sshd(pam_unix)6388: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:04:05 ns sshd(pam_unix)6393: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:04:13 ns sshd(pam_unix)6399: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:04:21 ns sshd(pam_unix)6406: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:04:27 ns sshd(pam_unix)6411: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:04:35 ns sshd(pam_unix)6417: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:04:44 ns sshd(pam_unix)6424: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:04:50 ns sshd(pam_unix)6429: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:04:58 ns sshd(pam_unix)6440: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:05:06 ns sshd(pam_unix)6510: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:05:12 ns sshd(pam_unix)6515: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
.
.
.
.
.
Dec 31 07:38:20 ns sshd(pam_unix)9649: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:38:32 ns sshd(pam_unix)9662: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=adm
Dec 31 07:38:36 ns sshd(pam_unix)9664: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=gopher
Dec 31 07:38:41 ns sshd(pam_unix)9666: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:38:56 ns sshd(pam_unix)9687: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root
Dec 31 07:39:08 ns sshd(pam_unix)9697: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=nobody
Dec 31 07:39:14 ns sshd(pam_unix)9708: authentication failure; logname= uid=0 euid=0 tty=NODEVssh ruser= rhost=68.187.16.28 user=root

¿ì¼± ±ÞÇÑ´ë·Î ÇØ´ç ¾ÆÀÌÇÇ´Â ¾Æ·¡¿Í °°ÀÌ ¸·¾Æ³õ¾Ò½À´Ï´Ù.

root@ns log# cat /etc/hosts.deny
#
# hosts.deny This file describes the names of the hosts which are
# *not* allowed to use the local INET services, as decided
# by the '/usr/sbin/tcpd' server.
#
# The portmap line is redundant, but it is left to remind you that
# the new secure portmap uses hosts.deny and hosts.allow. In particular
# you should know that NFS uses portmap!

ALL:68.187.16.28

À̿ܿ¡ ´Ù¸¥ ¼ö»óÇÑ ¾ÆÀÌÇǵ鵵 ¸¹ÀÌ º¸ÀÔ´Ï´Ù.

¼­¹öµµ Á» ÀÌ»óÇÕ´Ï´Ù.

½Ã°£³ª´Â´ë·Î ¼ö½Ã·Î ¼­¹ö »ìÆìº¸°í Á¶Ã븦 ÃëÇϰڽÀ´Ï´Ù.

Á¦°¡ ¿äÁò ½Ã°£ÀÌ ¾ø¾î¼­ µû·Î ³¯Àâ°í »ìÆìº¸°í ½ÍÀºµ¥ ±×·¯Áú ¸øÇϳ׿ä.. Á˼ÛÇÕ´Ï´Ù.

p.s
»õÇØ º¹ ¸¹ÀÌ ¹ÞÀ¸¼¼¿ä ^^

Name:  

EmailÀ» ±âÀÔÇϸé, ´ñ±ÛÀÌ ¸ÞÀÏ·Î Àü´ÞµË´Ï´Ù.