{"id":1123,"date":"2006-08-19T20:29:33","date_gmt":"2006-08-19T11:29:33","guid":{"rendered":"http:\/\/pchero21.com\/?p=1123"},"modified":"2006-08-19T20:29:33","modified_gmt":"2006-08-19T11:29:33","slug":"ddos-2","status":"publish","type":"post","link":"http:\/\/pchero21.com\/?p=1123","title":{"rendered":"DDoS #2"},"content":{"rendered":"<p>DoS \uacf5\uaca9\uc774\ub77c\uace0 \ubd88\ub9ac\ub294 \uc77c\ub828\uc758 \uacf5\uaca9 \ud328\ud134\ub4e4\uc740 \uc804\uc790\uc0c1\uac70\ub798\ub098 \uac01\uc885 \ucee8\ud150\uce20\uc640 \uac19\uc740 \uc778\ud130\ub137\uc0c1\uc758 \uadc0\uc911\ud55c \uc790\uc6d0\ub4e4\uc744 \uc704\ud611\ud558\uace0 \uc788\ub2e4. DoS  \uacf5\uaca9\uc740 \uc9c1\uc811\uc801\uc73c\ub85c \uc0ac\uc6a9\uc790 \uacc4\uc815 \ub610\ub294 \uc2dc\uc2a4\ud15c\uc758 \ub370\uc774\ud130\ub97c \uc7a5\uc545\ud558\uae30 \uc704\ud55c \ubc29\ubc95\uc774\ub77c\uae30 \ubcf4\ub2e4\ub294 \uacc4\ud68d\uc801\uc73c\ub85c \ucef4\ud4e8\ud130 \uc790\uc6d0\ub4e4\uc744 \ub2e4\uc6b4\uc2dc\ud0a4\uac70\ub098  ICMP, UDP, TCP\uc758 \ub370\uc774\ud130 \ud328\ud0b7\ub4e4\uc744 \uc0ac\uc6a9\ud574 \uc11c\ubc84\uc5d0 \ub9ce\uc740 \uc591\uc758 \ub124\ud2b8\uc6cc\ud06c \ud2b8\ub798\ud53d\uc744 \uc804\uc1a1\ud568\uc73c\ub85c\uc11c, \uc0ac\uc6a9\uc790\ub4e4\uc774 \uc0ac\uc774\ud2b8\uc5d0 \uc811\uadfc\ud558\uc9c0  \ubabb\ud558\ub3c4\ub85d \uc790\uc6d0\uc744 \uace0\uac08\uc2dc\ud0a4\ub294 \uc720\ud615\uc5d0\uc11c\ubd80\ud130 non-RFC-Compliant \ud328\ud0b7\uc744 \uc774\uc6a9\ud574 \uc6b4\uc601 \uc2dc\uc2a4\ud15c\uc758 \ub3d9\uc791\uc744 \uba48\ucdb0\ubc84\ub9ac\uac8c \ud558\ub294  \uc720\ud615\uae4c\uc9c0 \ub2e4\uc591\ud55c \ubc29\ubc95\uc774 \uc874\uc7ac\ud55c\ub2e4.<\/p>\n<table border=\"0\" cellspacing=\"0\" cellpadding=\"7\" width=\"88%\" align=\"center\">\n<tbody>\n<tr>\n<td bgcolor=\"#f5f5f5\">\n<li>[DoS \ud0d0\uad6c]1.DoS\/DDoS\ub780 \ubb34\uc5c7\uc778\uac00?<\/li>\n<li>[DoS \ud0d0\uad6c]2.DoS \uacf5\uaca9 \uc720\ud615<\/li>\n<li>[DoS \ud0d0\uad6c]3.DoS \ub300\uc751\ubc29\uc548<\/li>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"color: #003399;\">(1) SYN Flood \uacf5\uaca9<\/span><\/p>\n<p>\uae30\ubcf8\uc801\uc73c\ub85c \uc11c\ubc84\uc640 \ud074\ub77c\uc774\uc5b8\ud2b8 \uc0ac\uc774\uc5d0 \ud1b5\uc2e0\uc740 \uc544\ub798 \uadf8\ub9bc\uacfc \uac19\uc740 \uad6c\uc870\ub85c \uc774\ub8e8\uc5b4\uc838 \uc788\ub2e4.<\/p>\n<div><img src=\"http:\/\/image.ahnlab.com\/info\/securityinfo\/upload_\/DoS_3.jpg\" border=\"0\" alt=\"\" \/><br \/>\n\u25b2 3-Way Handshake \uad6c\uc870<\/div>\n<div>1) \ud074\ub77c\uc774\uc5b8\ud2b8\ub294 \uc77c\ub828\ubc88\ud638\uc640 \ud328\ud0b7\ud06c\uae30\ub97c \ud3ec\ud568\ud55c \uc815\ubcf4\ub97c \uc11c\ubc84\uc5d0 \uc804\uc1a1\ud558\uc5ec \uc5f0\uacb0\uc744 \uc2dc\uc791\ud55c\ub2e4.<br \/>\n2) \uc11c\ubc84\ub294 \ud074\ub77c\uc774\uc5b8\ud2b8\uac00 \ubcf4\ub0b8 \uc138\uc158 \uc815\ubcf4\ub85c \uc751\ub2f5\ud55c\ub2e4.<br \/>\n3) \ud074\ub77c\uc774\uc5b8\ud2b8\ub294 \uc11c\ubc84\ub85c\ubd80\ud130 \uc218\uc2e0\ud55c \uc815\ubcf4\uc5d0 \ub3d9\uc758\ud558\uace0 \uc2b9\uc778\ud55c\ub2e4.<\/div>\n<div><img src=\"http:\/\/image.ahnlab.com\/info\/securityinfo\/upload_\/DoS_4.jpg\" border=\"0\" alt=\"\" \/><\/div>\n<p>\uc11c \ubc84\uc5d0 \uc218\ucc9c \uac1c\uc758 TCP \uc811\uc18d(SYN) \uc694\uccad \uba54\uc2dc\uc9c0\ub97c \ubcf4\ub0b8\ub2e4. \uc774 \ub54c \uc774 \ud328\ud0b7\ub0b4\ubd80\uc758 \uc18c\uc2a4 IP \uc8fc\uc18c\ub97c \uc18d\uc774\uac70\ub098, \uc778\ud130\ub137 \uc0c1\uc5d0\uc11c  \uc0ac\uc6a9\ud558\uc9c0 \uc54a\ub294 IP \uc8fc\uc18c\uac12\uc73c\ub85c \ubcc0\ud615\ud55c\ub2e4. \uadf8\ub7ec\uba74 \uc11c\ubc84\ub294 \uc0c8\ub85c\uc6b4 \uc811\uc18d\uc744 \ub9fa\uae30 \uc704\ud574 \uc2e4\uc81c\ub85c\ub294 \uc874\uc7ac\ud558\uc9c0 \uc54a\uac70\ub098 \ub3d9\uc791\ud558\uc9c0 \uc54a\ub294 IP  \uc8fc\uc18c\uac12\uc73c\ub85c SYN\/ACK\ub85c \uc751\ub2f5\uc744 \ud55c\ub2e4.<\/p>\n<p>\uc11c\ubc84\ub294 SYN\/ACK \uc751\ub2f5\uc744 \ubcf4\ub0b8 \ud074\ub77c\uc774\uc5b8\ud2b8\ub85c\ubd80\ud130 ACK\uac00 \uc62c \ub54c\uae4c\uc9c0  \uae30\ub2e4\ub9ac\uac8c \ub418\ub294\ub370, \uc11c\ubc84\ub294 ACK \uba54\uc2dc\uc9c0\ub97c \ubc1b\uc9c0 \ubabb\ud558\uac8c \ub41c\ub2e4. \uc774\ub807\uac8c \ub418\uba74 \uc11c\ubc84\ub294 ACK \ubc1b\uc744 \ub54c\uae4c\uc9c0 \ubc84\ud37c\uc640 \uac19\uc740 \uc790\uc6d0\uc744 \uacc4\uc18d  \uc885\ub8cc\ud558\uc9c0 \uc54a\uace0 \uc5f4\uc5b4\ub450\uac8c \ub418\ub294\ub370, \uacc4\uc18d \ub204\uc801\ub420 \uacbd\uc6b0 \uacb0\uad6d\uc740 \uc2dc\uc2a4\ud15c\uc774 \ub2e4\uc6b4\ub418\uac70\ub098 \uc11c\ube44\uc2a4\ub97c \uc911\ub2e8\ud558\ub294 \uc0ac\ud0dc\uac00 \ubc1c\uc0dd\ud558\ub294 \uac83\uc774\ub2e4.<br \/>\nSyn Flood\uc5d0 \ub300\ud55c \ub300\uc751\uc694\ub839\uc740 \ud6c4\ubc18\ubd80\uc5d0\uc11c \uc54c\uc544\ubcf8\ub2e4.<\/p>\n<div><img src=\"http:\/\/image.ahnlab.com\/info\/securityinfo\/upload_\/DoS_5.jpg\" border=\"0\" alt=\"\" \/><br \/>\n\u25b2 DoS Syn Flood \uacf5\uaca9\uc5d0 \uc0ac\uc6a9\ub418\ub294 \ub3c4\uad6c<\/div>\n<div><img src=\"http:\/\/image.ahnlab.com\/info\/securityinfo\/upload_\/DoS_6.jpg\" border=\"0\" alt=\"\" \/><br \/>\n\u25b2 DDoS Flood\uacf5\uaca9\uc5d0 \uc0ac\uc6a9\ub418\ub294 \ub3c4\uad6c<\/div>\n<div><img src=\"http:\/\/image.ahnlab.com\/info\/securityinfo\/upload_\/button_top.gif\" border=\"0\" alt=\"\" \/><\/div>\n<p><span style=\"color: #003399;\">(2) Smurfing \uacf5\uaca9<\/span><\/p>\n<p>Smurfing  \uacf5\uaca9\uc740 \uadf8 \uad11\ubc94\uc704\ud55c \ud6a8\uacfc\ub85c \uc778\ud558\uc5ec \uac00\uc7a5 \ubb34\uc11c\uc6b4 DoS \ubc29\ubc95 \uc911\uc5d0 \ud558\ub098\uc774\uba70, IP\uc640 ICMP\uc758 \ud2b9\uc9d5\uc744 \uc774\uc6a9\ud55c\ub2e4. \ube0c\ub85c\ub4dc\uce90\uc2a4\ud2b8 \ud551  \uc694\uad6c\ub294 \ub124\ud2b8\uc6cc\ud06c \uc8fc\uc18c\ub098 \ub124\ud2b8\uc6cc\ud06c \ube0c\ub85c\ub4dc\uce90\uc2a4\ud2b8 \uc8fc\uc18c\uc5d0 \uc9c1\uc811 \ubcf4\ub0b4\uc9c8 \uc218 \uc788\ub2e4. \ub9cc\uc57d 192.168.0.0\/24 \ubc94\uc704\ub97c \uac00\uc9c4 \ub124\ud2b8\uc6cc\ud06c\uac00  \uc788\ub2e4\uba74, \ub124\ud2b8\uc6cc\ud06c ID\ub294 192.168.0.0\ub420 \uac83\uc774\uace0 \ube0c\ub85c\ub4dc\uce90\uc2a4\ud2b8\uc6a9 \uc8fc\uc18c\ub294 192.168.0.255\uac00 \ub420 \uac83\uc774\ub2e4.  \ube0c\ub85c\ub4dc\uce90\uc2a4\ud2b8\ub294 \uc804\ud615\uc801\uc73c\ub85c \uc9c0\uc815\ub41c \ubc94\uc704 \ub0b4\uc5d0\uc11c \uc870\uc815\ub41c \uac01\uac01\uc758 \uc8fc\uc18c \uc5c6\uc774 \ubb34\uc5c7\uc774 \ud65c\ub3d9\ud558\ub294\uc9c0 \uc9c4\ub2e8\ud560 \ubaa9\uc801\uc73c\ub85c \uc0ac\uc6a9\ub41c\ub2e4.<\/p>\n<p>Smurfing  \uacf5\uaca9\uc740 \uc9c1\uc811\uc801\uc778 \ube0c\ub85c\ub4dc\uce90\uc2a4\ud2b8\uc640 \uc138 \uac00\uc9c0 \uad6c\uc131\uc694\uc18c\uc778 \uacf5\uaca9\uc790, \uc99d\ud3ed \ub124\ud2b8\uc6cc\ud06c\uc640 \ud45c\uc801\uc744 \ucd5c\ub300\ud55c \uc774\uc6a9\ud55c\ub2e4. \uacf5\uaca9\uc790\ub294 \uc99d\ud3ed \ub124\ud2b8\uc6cc\ud06c\uc758  \ube0c\ub85c\ub4dc\uce90\uc2a4\ud2b8 \uc8fc\uc18c\ub85c \uacf5\uaca9 \uc11c\ubc84\uac00 \uc694\uad6c\ud558\ub294 \uac83\ucc98\ub7fc \ud328\ud0b7\ub4e4\uc758 \uc6d0\ubcf8 \uc8fc\uc18c\ub97c \uc704\uc870\ud558\uc5ec ICMP ECHO \ud328\ud0b7\uc744 \uc804\uc1a1\ud558\uace0, ICMP  ECHO \ud328\ud0b7\uc744 \uc218\uc2e0\ud55c \uc99d\ud3ed \ub124\ud2b8\uc6cc\ud06c \ub0b4\uc758 \ubaa8\ub4e0 \uc2dc\uc2a4\ud15c\uc740 \uacf5\uaca9 \uc11c\ubc84\uc5d0 \uc751\ub2f5\uc744 \ud558\uac8c \ub41c\ub2e4. \ub9cc\uc77c \uacf5\uaca9\uc790\uac00 \ube0c\ub85c\ub4dc\uce90\uc2a4\ud2b8 \ud551\uc5d0 \uc751\ub2f5\ud560  100\uac1c\uc758 \uc2dc\uc2a4\ud15c\uc744 \uac00\uc9c4 \uc99d\ud3ed \ub124\ud2b8\uc6cc\ud06c\uc5d0 \ud558\ub098\uc758 ICMP \ud328\ud0b7\uc744 \ubcf4\ub0b4\uac8c \ub418\uba74, \uacf5\uaca9\uc790\ub294 100\ub9cc\ud07c\uc758 \ud6a8\uacfc\ub85c DoS \uacf5\uaca9\uc744 \ud560 \uc218  \uc788\ub2e4.<\/p>\n<p>\uc774 \uacf5\uaca9\uacfc \uc0c1\uc774\ud55c \ud615\ud0dc\uc758 Fraggle \uacf5\uaca9\uc774\ub77c\ub294 \uac83\uc774 \uc788\ub294\ub370, Fraggle \uacf5\uaca9\uc740 \ubc29\uc2dd\uc740 Smurfing  \uacf5\uaca9\uacfc \ube44\uc2b7\ud558\uc9c0\ub9cc ICMP \ub300\uc2e0 UDP\ub97c \uc0ac\uc6a9\ud55c\ub2e4\ub294 \uac83\uc774 \ub2e4\ub978 \uc810\uc774\ub2e4. \uacf5\uaca9\uc790\ub4e4\uc740 \uc99d\ud3ed \ub124\ud2b8\uc6cc\ud06c \ub0b4\uc758 \ube0c\ub85c\ub4dc\uce90\uc2a4\ud2b8 \uc8fc\uc18c\ub85c  \uc804\ud615\uc801\uc778 \ud3ec\ud2b8 7(Echo)\uc744 \uc774\uc6a9\ud574 \uac00\uc9dc UDP \ud328\ud0b7\uc744 \uc804\uc1a1\ud55c\ub2e4. \uc5d0\ucf54\uac00 \uac00\ub2a5\ud55c \ub124\ud2b8\uc6cc\ud06c \ub0b4\uc758 \uac01\uac01\uc758 \uc2dc\uc2a4\ud15c\uc740 \uc5c4\uccad\ub09c \ud2b8\ub798\ud53d\uc744  \uc0dd\uc131\ud558\uace0 \uacf5\uaca9 \uc11c\ubc84\ub85c \uc751\ub2f5\uc744 \ubcf4\uac8c \ub41c\ub2e4. \ub9cc\uc57d \uc99d\ud3ed\ub41c \ub124\ud2b8\uc6cc\ud06c \ub0b4\uc758 \uc2dc\uc2a4\ud15c\uc5d0\uc11c \uc5d0\ucf54\uac00 \uac00\ub2a5\ud558\uc9c0 \uc54a\ub354\ub77c\ub3c4 ICMP \ub3c4\ub2ec \ubd88\ub2a5  \uba54\uc2dc\uc9c0\uac00 \uc5ec\uc804\ud788 \ub300\uc5ed\ud3ed\uc744 \uc18c\ubaa8\ud558\uac8c \ub420 \uac83\uc774\ub2e4.<\/p>\n<div><img src=\"http:\/\/image.ahnlab.com\/info\/securityinfo\/upload_\/DoS_7.jpg\" border=\"0\" alt=\"\" \/><\/div>\n<p>Smurfing \uacf5\uaca9\uc744 \ubc29\uc5b4\ud558\uae30 \uc704\ud574\uc11c\ub294 \uc9c1\uc811\uc801\uc778 \ube0c\ub85c\ub4dc\uce90\uc2a4\ud2b8\ub97c \uacbd\uacc4 \ub77c\uc6b0\ud130\uc5d0\uc11c \uc0ac\uc6a9\ud560 \uc218 \uc5c6\uac8c \ub9cc\ub4e4\uc5b4\uc57c \ud55c\ub2e4.<\/p>\n<p><span style=\"color: #003399;\">(3) \uc751\uc6a9 \ud504\ub85c\uadf8\ub7a8 \uc11c\ube44\uc2a4 DoS \uacf5\uaca9<\/span><\/p>\n<p>\ub300\ubd80\ubd84\uc758 \uacf5\uaca9\ub4e4\uc740 \ud76c\uc0dd\uc790\uc758 \uc11c\ubc84\uc5d0 \uc788\ub294 \ub0ae\uc740 \ub808\ubca8\uc758 \uc790\uc6d0\uc5d0 \ucd08\uc810\uc744 \ub9de\ucd94\uc9c0\ub9cc, \uac70\uc758 \ubaa8\ub4e0 \ud504\ub85c\uadf8\ub7a8\uc0c1\uc758 \ubc84\uadf8\ub294 DoS \ucde8\uc57d\uc810\uc744 \uc57c\uae30\uc2dc\ud0ac \uc218 \uc788\ub2e4\ub294 \uc0ac\uc2e4\uc744 \uba85\uc2ec\ud574\uc57c\ud55c\ub2e4. IIS\uc640 \uac19\uc740 \uc751\uc6a9\ud504\ub85c\uadf8\ub7a8 \ub3c4\uad6c\ub294 \ud2b9\ud788 \uc774\ub7f0 \uacf5\uaca9\uc5d0 \ucde8\uc57d\ud558\ub2e4.<\/p>\n<p><strong>&#8211; WebDAV Propfind DoS<\/strong><\/p>\n<p>2001\ub144 \uc911\ubc18 IIS 5.0\ub97c \uc0ac\uc6a9\ud558\ub294 \uc2dc\uc2a4\ud15c\uc5d0\uc11c\ub294 WebDAV\uc758 \uc798\ubabb\ub41c \uc694\uccad\uc73c\ub85c \uc778\ud574 IIS\uac00 DoS\ub97c \uc77c\uc73c\ud0ac \uc218 \uc788\ub294 \ucde8\uc57d\uc131\uc774 Georgi Guninski\uc5d0 \uc758\ud574 \ucc98\uc74c \ubc1c\uacac\ub418\uc5c8\ub2e4.<\/p>\n<p>MS\uc5d0\uc11c\ub294 WebDAV Propfind DoS\uc5d0 \ub300\ud55c \ud328\uce58\ub97c \ub9c8\ub828\ud558\uc600\uc9c0\ub9cc, \uae30\ubcf8\uc801\uc73c\ub85c WebDAV\uae30\ub2a5\uc744 \uc0ac\uc6a9\ud558\uc9c0 \uc54a\uc744 \uac83\uc744 \uad8c\ud558\uace0 \uc788\ub2e4. \ubb3c\ub860 WebDAV\ub97c \uc0ac\uc6a9\ud558\uc9c0 \uc54a\ub3c4\ub85d \ud558\uba74 \ub2e4\uc74c\uacfc \uac19\uc740 \uae30\ub2a5\uc744 \uc0ac\uc6a9\ud558\uc9c0 \ubabb\ud560 \uc218 \ub3c4 \uc788\ub2e4.<\/p>\n<div>&#8211; \uc6f9 \ud3f4\ub354<br \/>\n&#8211; \uc624\ud53c\uc2a4\ub97c \uc0ac\uc6a9\ud558\uc5ec \uc6f9\uc0ac\uc774\ud2b8 \ubc1c\uac04<br \/>\n&#8211; Digital Dashboard\ub97c \uc774\uc6a9\ud558\uc5ec IIS 5.0 \uc11c\ubc84 \ubaa8\ub2c8\ud130\ub9c1<\/div>\n<p>\ubc18\ub4dc\uc2dc WebDAV\uac00 \ud544\uc694\ud558\uc9c0 \uc54a\ub2e4\uba74 IIS\uc758 \ubaa8\ub4e0 \ud655\uc7a5\ub41c \uae30\ub2a5\ub4e4\uc744 \uc0ac\uc6a9\ud558\uc9c0 \uc54a\ub3c4\ub85d \ud574\uc57c\ub9cc \ud55c\ub2e4. \uc774\ub7f0 \ud55c\uac00\uc9c0 \uc608\ubc29\ubc95\uc744 \ud1b5\ud574 \ud604\uc7ac \uadf8\ub9ac\uace0 \ub098\uc911\uc5d0 \ubc1c\uc0dd\ud560 \uc218\ub3c4 \uc788\ub294 \ub9ce\uc740 \ubcf4\uc548 \ucde8\uc57d\uc810\ub4e4\ub85c\ubd80\ud130 \uc2dc\uc2a4\ud15c\uc744 \ubcf4\ud638\ud560 \uac83\uc774\ub2e4.<\/p>\n<p>\ucc38\uace0\ub85c \ub204\uad70\uac00 Propfind DoS\ub97c \uc0ac\uc6a9\ud558\uc5ec \uc11c\ubc84\ub97c \uacf5\uaca9\ud558\uace0 \uc788\ub2e4\ub294 \uc0ac\uc2e4\uc744 \uc54c\uae30 \uc704\ud574\uc11c\ub294 PROFIND \/ -500 \uc5d4\ud2b8\ub9ac\uc5d0 \ub300\ud55c IIS\ub85c\uadf8\ub97c \ud655\uc778\ud558\ub3c4\ub85d \ud55c\ub2e4.<\/p>\n<p>\uc790\uc138\ud55c \uc0ac\ud56d\uc740 \uc544\ub798 \uc8fc\uc18c\ub97c \ucc38\uace0\ud55c\ub2e4.<\/p>\n<div>MS01-016 : <a href=\"http:\/\/www.microsoft.com\/korea\/technet\/security\/bulletin\/MS01-016.asp\" target=\"_blank\">http:\/\/www.microsoft.com\/korea\/technet\/security\/bulletin\/MS01-016.asp<\/a><br \/>\nQ241520 : How to Disable WebDAV for IIS 5.0<\/div>\n<div><img src=\"http:\/\/image.ahnlab.com\/info\/securityinfo\/upload_\/button_top.gif\" border=\"0\" alt=\"\" \/><\/div>\n<p><span style=\"color: #003399;\">(4) LAN\uae30\ubc18 DoS \uacf5\uaca9<\/span><\/p>\n<p>\uc5ec \ub7ec\ubd84\uc774 \ub124\ud2b8\uc6cc\ud06c\ub97c \uc6b4\uc601\ud558\uace0 \uc788\ub2e4\uba74 LAN\uae30\ubc18\uc758 DoS \uacf5\uaca9\uc758 \uc704\ud5d8\uc131\ub3c4 \uac04\uacfc\ud574\uc11c\ub294 \uc548 \ub41c\ub2e4. \uc0c1\ub2f9\uc218\uc758 \uc2dc\uc2a4\ud15c\uc774 \uc6f9\uc11c\ube44\uc2a4\ub97c \ud558\uba74\uc11c  \ubd88\ud544\uc694\ud55c \ud504\ub85c\ud1a0\ucf5c \ubc0f \uc11c\ube44\uc2a4\ub97c \uc124\uce58\ud574 \ub193\uc740 \uacbd\uc6b0\uac00 \ub9ce\ub2e4. \uc774\ub294 LAN \uae30\ubc18\uc758 DoS \uacf5\uaca9\ubfd0\ub9cc \uc544\ub2c8\ub77c \ud504\ub85c\ud1a0\ucf5c\uc758 \uace0\uc9c8\uc801\uc778 \ubb38\uc81c\ub85c  \uc778\ud574 \uc678\ubd80\uc758 DoS \uacf5\uaca9 \ubc0f \ub0b4\ubd80 \ub124\ud2b8\uc6cc\ud06c\uc758 \uc815\ubcf4\uac00 \uc678\ubd80\ub85c \uc720\ucd9c\ub420 \uc218 \uc788\ub294 \uc704\ud5d8\uc131\uc774 \uc788\ub2e4.<\/p>\n<p><strong>1) NetBios Name Release DoS<\/strong><\/p>\n<p>\uba87  \uac00\uc9c0 LAN \uae30\ubc18 Windows 2000 DoS \uacf5\uaca9 \uc911\uc5d0\uc11c\ub3c4, \ub300\uccb4\ub85c \uc708\ub3c4\uc6b0 \ub124\ud2b8\uc6cc\ud0b9\uc758 \ud575\uc2ec\uc5ed\ud560\uc744 \ud558\ub294 NetBios  \ud504\ub85c\ud1a0\ucf5c\uc744 \uc0ac\uc6a9\ud55c\ub2e4. NetBios\uc758 \uace0\uc9c8\uc801\uc778 \ubb38\uc81c\uc810\uc740 \uc2e0\ub8b0\uc131\uc774 \uc5c6\uace0, \uc778\uac00\ub418\uc9c0 \uc54a\ub294 \uc11c\ube44\uc2a4\uc5d0 \uc758\uc874\ud55c\ub2e4\ub294 \uc810\uc774\ub2e4.<\/p>\n<p>\uc608 \ub97c \ub4e4\uc5b4, NetBios Name Service(NBNS)\ub294 NetBios \uc774\ub984\uc5d0 \ub300\ud55c IP\uc8fc\uc18c\ub97c \ucc3e\uc544\uc8fc\uc9c0\ub9cc \ubc18\ub300\ub85c \uc27d\uac8c \uc18d\uc77c \uc218  \uc788\uae30 \ub54c\ubb38\uc5d0, NetBios \uc774\ub984\uc5d0 \ub300\ud55c \ub4f1\ub85d\uc744 \uc694\uccad\ud558\uac70\ub098 \ud2b9\uc815 \ud638\uc2a4\ud2b8\uc5d0 name release \ud328\ud0b7\uc744 \ubcf4\ub0b4 \ub124\ud2b8\uc6cc\ud06c \uc0c1\uc5d0\uc11c  \uc801\ubc95\ud55c \ud074\ub77c\uc774\uc5b8\ud2b8\uc758 \uc811\uc18d\uc744 \ub04a\uac8c \ub9cc\ub4e4 \uc218 \uc788\ub2e4. \ub2e4\uc2dc \ub9d0\ud574 \uc774\ub7f0 \ud328\ud0b7\uc744 \uc218\uc2e0\ud55c \ud074\ub77c\uc774\uc5b8\ud2b8\ub294 \uacf5\uc720\uc790\uc6d0 \uc811\uadfc, \ub3c4\uba54\uc778 \uc778\uc99d \ub4f1\uc744  \ud3ec\ud568\ud558\uc5ec NetBios \ub124\ud2b8\uc6cc\ud06c\uc5d0 \ucc38\uc5ec\ud560 \uc218 \uc788\ub294 \ub2a5\ub825\uc744 \uc783\uac8c \ub41c\ub2e4.<\/p>\n<p>\uc544\ub798 \uadf8\ub9bc\uc740 NetBios Name Release DoS \uacf5\uaca9\uc744 \ubc1b\uc740 \uc2dc\uc2a4\ud15c\uc758 NetBios name service \uc0c1\ud0dc\ub97c \ud655\uc778\ud55c \uac83\uc774\ub2e4.<\/p>\n<div><img src=\"http:\/\/image.ahnlab.com\/info\/securityinfo\/upload_\/DoS_8.jpg\" border=\"0\" alt=\"\" \/><\/div>\n<p>\ub300 \ubd80\ubd84\uc758 NetBios \uad00\ub828 \ubb38\uc81c\uc640 \ub9c8\ucc2c\uac00\uc9c0\ub85c, \uc774\ub7f0 \uacf5\uaca9\uc744 \ub9c9\uae30 \uc704\ud574\uc11c\ub294 \uacc4\uce35\uc0c1\uc5d0\uc11c \ubc29\uc5b4\uccb4\uc81c\ub97c \ub9c8\ub828\ud558\ub294 \uac83\uc774 \uc88b\ub2e4. \uc989 \uc6f9\uc11c\ubc84\uc758  \uc131\ub2a5\uc774\ub098 \ubcf4\uc548\uc131\uc744 \uace0\ub824\ud588\uc744 \ub54c \ubd88\ud544\uc694\ud55c \ud504\ub85c\ud1a0\ucf5c \ubc0f \uc11c\ube44\uc2a4(\ud2b9\ud788 NetBios\uc640 \uad00\ub828\ub41c)\ub294 \ubc18\ub4dc\uc2dc \uc81c\uac70\ub418\uc5b4\uc57c \ud55c\ub2e4.<\/p>\n<div><img src=\"http:\/\/image.ahnlab.com\/info\/securityinfo\/upload_\/DoS_9.jpg\" border=\"0\" alt=\"\" \/><\/div>\n<p>\uc704 \ub450 \uba54\ub274\uc758 \uccb4\ud06c\ud45c\uc2dc\ub97c \uc5c6\uc560\uac70\ub098 \uc81c\uac70\ud558\uba74 \uc544\ub798 \uadf8\ub9bc\uacfc \uac19\uc740 \uacb0\uacfc\uac00 \ucd9c\ub825\ub41c\ub2e4.<\/p>\n<div><img src=\"http:\/\/image.ahnlab.com\/info\/securityinfo\/upload_\/DoS_10.jpg\" border=\"0\" alt=\"\" \/><\/div>\n<p>\uc704 \uc640 \uac19\uc774 \ud558\uba74 NetBios\uc758 \uace0\uc9c8\uc801\uc778 \ubb38\uc81c\ub85c \uc778\ud55c \ubcf4\uc548\uc0c1\uc758 \ubb38\uc81c\ub294 \uc5b4\ub290 \uc815\ub3c4 \ud574\uacb0\ub420 \uac83\uc774\ub2e4. \uadf8\ub7ec\ub098 \uaf2d NBNS\/WINS  \uc11c\ube44\uc2a4\ub97c \uc0ac\uc6a9\ud574\uc57c \ud55c\ub2e4\uba74 Windows 2000 IPSec \ud544\ud130\ub97c \ud1b5\ud574 UDP 137\u223c139\uc73c\ub85c \uc1a1\u00b7\uc218\uc2e0\ub418\ub294 \ud2b8\ub798\ud53d\uc744 \uc778\uc99d\ud558\ub3c4\ub85d  \uc124\uc815\ud574\uc57c\ud55c\ub2e4.<\/p>\n<p>\ub610\ud55c \ud638\uc2a4\ud2b8 \ub808\ubca8\uc5d0\uc11c \ub2e4\uc74c\uacfc \uac19\uc740 \ub808\uc9c0\uc2a4\ud2b8\ub9ac \uac12\uc744 \uc124\uc815\ud55c\ub2e4.<\/p>\n<div>HKLM\uff3cSYSTEM\uff3cCurrentControlSet\uff3cServices\uff3cNetBT\uff3cParameters<br \/>\nNoNameReleaseOnDemand<br \/>\nReg_DWORD = 1<\/div>\n<div><img src=\"http:\/\/image.ahnlab.com\/info\/securityinfo\/upload_\/DoS_11.jpg\" border=\"0\" alt=\"\" \/><\/div>\n<p><strong>2) Windows RPC Service DOS<\/strong><\/p>\n<p>RPC(Remote  Procedure Call)\ub780 \ud55c \ud504\ub85c\uadf8\ub7a8\uc774 \ub124\ud2b8\uc6cc\ud06c \uc0c1\uc758 \ub2e4\ub978 \ucef4\ud4e8\ud130\uc5d0 \uc704\uce58\ud558\uace0 \uc788\ub294 \ud504\ub85c\uadf8\ub7a8\uc5d0 \uc11c\ube44\uc2a4\ub97c \uc694\uccad\ud558\ub294\ub370 \uc0ac\uc6a9\ub418\ub294  \ud504\ub85c\ud1a0\ucf5c\ub85c\uc11c, \uc774\ub54c \uc11c\ube44\uc2a4\ub97c \uc694\uccad\ud558\ub294 \ud504\ub85c\uadf8\ub7a8\uc740 \ub124\ud2b8\uc6cc\ud06c\uc5d0 \ub300\ud55c \uc0c1\uc138 \ub0b4\uc6a9\uc744 \uc54c \ud544\uc694\uac00 \uc5c6\ub2e4(\uc808\ucc28 \ud638\ucd9c\uc774\ub780 \ub54c\ub85c \ud568\uc218 \ub610\ub294  \uc11c\ube0c\ub8e8\ud2f4 \ud638\ucd9c\uc758 \uc758\ubbf8\ub85c\ub3c4 \uc0ac\uc6a9\ub41c\ub2e4). RPC\ub294 \ud074\ub77c\uc774\uc5b8\ud2b8\/\uc11c\ubc84 \ubaa8\ub378\uc744 \uc0ac\uc6a9\ud558\ub294\ub370, \uc11c\ube44\uc2a4\ub97c \uc694\uccad\ud558\ub294 \ud504\ub85c\uadf8\ub7a8\uc774 \ud074\ub77c\uc774\uc5b8\ud2b8\uc774\uace0,  \uc11c\ube44\uc2a4\ub97c \uc81c\uacf5\ud558\ub294 \ud504\ub85c\uadf8\ub7a8\uc774 \uc11c\ubc84\uc774\ub2e4. \ub2e4\ub978 \uc815\uc0c1\uc801\uc778 \ub610\ub294 \uc790\uccb4\uc801\uc778 \ud504\ub85c\uc2dc\uc800\uc758 \ud638\ucd9c\uacfc \ub9c8\ucc2c\uac00\uc9c0\ub85c, RPC\ub3c4 \uc694\uccad\ud558\ub294 \ud504\ub85c\uadf8\ub7a8\uc774  \uc6d0\uaca9 \uc808\ucc28\uc758 \ucc98\ub9ac \uacb0\uacfc\uac00 \ubc18\ud658\ub420 \ub54c\uae4c\uc9c0 \uc77c\uc2dc \uc815\uc9c0\ub418\uc5b4\uc57c \ud558\ub294 \ub3d9\uae30 \uc6b4\uc601\uc774\ub2e4. \uadf8\ub7ec\ub098, \uac00\ubcbc\uc6b4 \ud504\ub85c\uc138\uc2a4\uc758 \uc0ac\uc6a9\uc774\ub098, \uac19\uc740 \uc8fc\uc18c\uacf5\uac04\uc744  \uacf5\uc720\ud558\ub294 \uc2a4\ub808\ub4dc \ub4f1\uc740 \uc5ec\ub7ec \uac1c\uc758 RPC\ub4e4\uc744 \ub3d9\uc2dc\uc5d0 \uc218\ud589\ub420 \uc218 \uc788\ub3c4\ub85d \ud5c8\uc6a9\ud55c\ub2e4.<\/p>\n<p>RPC\uc11c\ubc84\ub294 \uc790\uc2e0\uc774 \uc218\uc2e0\ud55c \ub0b4\uc6a9\uc744 \uac80\uc99d\ud558\uc9c0 \uc54a\uae30 \ub54c\ubb38\uc5d0 \ud074\ub77c\uc774\uc5b8\ud2b8\ub85c\ubd80\ud130 \uc798\ubabb\ub41c RPC \ud328\ud0b7\uc744 \uc218\uc2e0\ud560 \uacbd\uc6b0, \uc815\uc0c1\uc801\uc778 RPC \uc694\uccad\uc5d0 \ub300\ud574\uc11c\ub294 \uc751\ub2f5\ud560 \uc218\uac00 \uc5c6\uc73c\ubbc0\ub85c \uc11c\ube44\uc2a4\uac00 \uc911\ub2e8\ub418\ub294 \ubb38\uc81c\uac00 \ubc1c\uc0dd\ud55c\ub2e4.<\/p>\n<p>RPC \uc11c\ube44\uc2a4\uc758 DoS \ucde8\uc57d\uc131\uc740 \ud328\uce58\ub97c \ud558\ub354\ub77c\ub3c4 \uc644\uc804\ud788 \ud574\uacb0\ub41c \uac83\uc774 \uc544\ub2c8\ub2e4. \ucd5c\uadfc\uc5d0 \ubcf4\uace0\ub41c RPC \uc11c\ube44\uc2a4\uc758 DoS \ucde8\uc57d\uc131\uc5d0 \uad00\ud55c \ub0b4\uc6a9\uc744 \ubcf4\uba74 sp3\ub97c \uc801\uc6a9\ud55c \uc708\ub3c4\uc6b0 2000\uc5d0\uc11c\ub3c4 \uc874\uc7ac\ud55c\ub2e4\ub294 \uac83\uc744 \uc54c \uc218\uac00 \uc788\ub2e4.<\/p>\n<p>Windows  2000\uc758 DCE-RPC \uc2a4\ud0dd \ub0b4\uc5d0 \uc874\uc7ac\ud558\ub294 RPC\uc11c\ube44\uc2a4\uc758 DoS\ucde8\uc57d\uc131\uc740 \uacf5\uaca9\uc790\uac00 \ubaa9\ud45c \uc2dc\uc2a4\ud15c\uc758 TCP 135\ubc88 \ud3ec\ud2b8\ub97c \ud1b5\ud574  \uacf5\uaca9\ud568\uc73c\ub85c\uc368 RPC \uc11c\ube44\uc2a4\ub97c \uc911\uc9c0\uc2dc\ud0ac \uc218 \uc788\uac8c \ud55c\ub2e4. RPC \uc11c\ube44\uc2a4\uac00 \uc911\ub2e8\ub41c \uc2dc\uc2a4\ud15c\uc740 \ub354 \uc774\uc0c1 \uc0c8\ub85c\uc6b4 RPC \uc694\uccad\uc5d0 \ub300\ud574\uc11c\ub294  \uc751\ub2f5\ud558\uc9c0 \ubabb\ud558\uba70 \uac70\uc758 \ubaa8\ub4e0 \uae30\ub2a5\uc774 \uc911\ub2e8\ub420 \uc218\ub3c4 \uc788\ub2e4.<\/p>\n<p>RPC \uc11c\ube44\uc2a4\uc758 DoS \ucde8\uc57d\uc131\uc744 \ud574\uacb0\ud558\uae30 \uc704\ud55c \uc81c\uc77c \uc88b\uc740  \ubc29\ubc95\uc740 &#8220;\uc9c1\uc811 RPC \uc11c\ube44\uc2a4\ub97c \uc911\uc9c0\ud558\uba74 \ud574\uacb0\ub418\uc9c0 \uc54a\uc744\uae4c&#8221;\ub77c\uace0 \uc0dd\uac01\ud560 \uc218\ub3c4 \uc788\uaca0\uc9c0\ub9cc, \uc9c1\uc811 RPC \uc11c\ube44\uc2a4\ub97c \uc911\uc9c0\ud558\ub294 \uac83\uc740 \uc88b\uc740  \ubc29\ubc95\uc774 \uc544\ub2c8\ub2e4. \uc65c\ub0d0\uba74 RPC \uc11c\ube44\uc2a4\ub3c4 \uc6b4\uc601\uccb4\uc81c\uc758 \uc77c\ubd80\uc774\uae30 \ub54c\ubb38\uc5d0 \uc911\uc9c0\ud558\uac8c \ub418\uba74 \ub124\ud2b8\uc6cc\ud06c \uc11c\ube44\uc2a4 \ubc0f \uc81c\uc5b4\ud310\uc758 \uc77c\ubd80 \uae30\ub2a5\uc744 \uc0ac\uc6a9\ud560 \uc218  \uc5c6\uac8c \ub41c\ub2e4. \uac00\uc7a5 \uc88b\uc740 \ubc29\ubc95\uc740 \ubc29\ud654\ubcbd\uc744 \uc0ac\uc6a9\ud574 TCP 135\u223c139, 445\ubc88 \ud3ec\ud2b8\ub97c \ub9c9\uc544\ub450\ub294 \uac83\uc774\ub2e4.<\/p>\n<p>RPC\uc11c\ube44\uc2a4\uc758 \ucde8\uc57d\uc131\uad00\ub828 \ub0b4\uc6a9\uc740 \uc544\ub798 \ud398\uc774\uc9c0\ub97c \ucc38\uace0\ud558\uae30 \ubc14\ub780\ub2e4.<\/p>\n<div>\n<li><a href=\"http:\/\/www.microsoft.com\/korea\/technet\/security\/bulletin\/MS00-066.asp\" target=\"_blank\">http:\/\/www.microsoft.com\/korea\/technet\/security\/bulletin\/MS00-066.asp<\/a><\/li>\n<li><a href=\"http:\/\/www.microsoft.com\/korea\/technet\/security\/bulletin\/MS01-041.asp\" target=\"_blank\">http:\/\/www.microsoft.com\/korea\/technet\/security\/bulletin\/MS01-041.asp<\/a><\/li>\n<li><a href=\"http:\/\/www.securiteam.com\/windowsntfocus\/6G00B2K5PM.html\" target=\"_blank\">http:\/\/www.securiteam.com\/windowsntfocus\/6G00B2K5PM.html<\/a><\/li>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>DoS \uacf5\uaca9\uc774\ub77c\uace0 \ubd88\ub9ac\ub294 \uc77c\ub828\uc758 \uacf5\uaca9 \ud328\ud134\ub4e4\uc740 \uc804\uc790\uc0c1\uac70\ub798\ub098 \uac01\uc885 \ucee8\ud150\uce20\uc640 \uac19\uc740 \uc778\ud130\ub137\uc0c1\uc758 \uadc0\uc911\ud55c \uc790\uc6d0\ub4e4\uc744 \uc704\ud611\ud558\uace0 \uc788\ub2e4. DoS \uacf5\uaca9\uc740 \uc9c1\uc811\uc801\uc73c\ub85c \uc0ac\uc6a9\uc790 \uacc4\uc815 \ub610\ub294 \uc2dc\uc2a4\ud15c\uc758 \ub370\uc774\ud130\ub97c \uc7a5\uc545\ud558\uae30 \uc704\ud55c \ubc29\ubc95\uc774\ub77c\uae30 \ubcf4\ub2e4\ub294 \uacc4\ud68d\uc801\uc73c\ub85c \ucef4\ud4e8\ud130 \uc790\uc6d0\ub4e4\uc744 \ub2e4\uc6b4\uc2dc\ud0a4\uac70\ub098 ICMP, UDP, TCP\uc758 \ub370\uc774\ud130 \ud328\ud0b7\ub4e4\uc744 \uc0ac\uc6a9\ud574 \uc11c\ubc84\uc5d0 \ub9ce\uc740 \uc591\uc758 &hellip; <a href=\"http:\/\/pchero21.com\/?p=1123\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[63],"tags":[],"_links":{"self":[{"href":"http:\/\/pchero21.com\/index.php?rest_route=\/wp\/v2\/posts\/1123"}],"collection":[{"href":"http:\/\/pchero21.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/pchero21.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/pchero21.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/pchero21.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1123"}],"version-history":[{"count":0,"href":"http:\/\/pchero21.com\/index.php?rest_route=\/wp\/v2\/posts\/1123\/revisions"}],"wp:attachment":[{"href":"http:\/\/pchero21.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1123"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/pchero21.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1123"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/pchero21.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1123"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}