{"id":1125,"date":"2006-08-19T20:31:09","date_gmt":"2006-08-19T11:31:09","guid":{"rendered":"http:\/\/pchero21.com\/?p=1125"},"modified":"2019-10-07T06:27:36","modified_gmt":"2019-10-06T21:27:36","slug":"ddos-3","status":"publish","type":"post","link":"http:\/\/pchero21.com\/?p=1125","title":{"rendered":"DDoS #3"},"content":{"rendered":"<p>DoS\ub97c \ub9c9\uae30 \uc704\ud574 \uc6b0\uc120\uc801\uc73c\ub85c \ub2f9\ubd80\ud558\uace0 \uc2f6\uc740 \ub9d0\uc740 &#8220;\uc808\ub300\ub85c \ud3ec\uae30\ud558\uc9c0 \ub9d0\ub77c&#8221;\ub294 \uac83\uc774\ub2e4. \ube44\ub85d DoS \uacf5\uaca9\uc744 \uc644\ubcbd\ud558\uac8c \ubc29\uc5b4\ud558\ub294 \uac83\uc740 \uc5b4\ub824\uc6b4 \uc77c\uc774\uc9c0\ub9cc \uac04\ub2e8\ud55c \ub77c\uc6b0\ud130 \ubc0f \ub610\ub294 \ubc29\ud654\ubcbd\uc744 \uad6c\uc131\ud558\uc5ec \uc6f9 \uc0ac\uc774\ud2b8\ub85c \ub4e4\uc5b4\uc624\ub294 \ud2b8\ub798\ud53d \uc885\ub958\uc640 \ubc94\uc704\ub97c \uc81c\ud55c\uc2dc\ucf1c \ud53c\ud574\uc815\ub3c4\ub97c \uc904\uc77c \uc218\uac00 \uc788\ub2e4.<\/p>\n<p>\ubb3c\ub860 \uacf5\uaca9\uc790\ub294 \ub354 \uac15\ub3c4 \ub192\uc740 \uacf5\uaca9\uc744 \ud560\uc9c0\ub3c4 \ubaa8\ub974\uc9c0\ub9cc \uacb0\uad6d \uc5b8\uc820\uac00\ub294 \ub300\uc751\ubc29\uc548\uc774 \uc2b9\ub9ac\ud560 \uac83\uc774\ub2e4. DoS \uacf5\uaca9\uc73c\ub85c \uc778\ud55c \ud53c\ud574\ub97c \uac10\uc18c\uc2dc\ud0a4\uae30 \uc704\ud574 \uba87 \uac00\uc9c0 \uae30\ubcf8\uc6d0\ub9ac\uc640 Windows 2000\uc758 \uad6c\uc131\uc5d0 \ub300\ud574 \uc54c\uc544\ubcf4\uc790.<\/p>\n<table border=\"0\" width=\"88%\" cellspacing=\"0\" cellpadding=\"7\" align=\"center\">\n<tbody>\n<tr>\n<td bgcolor=\"#f5f5f5\">\n<ul>\n<li>[DoS \ud0d0\uad6c]1.DoS\/DDoS\ub780 \ubb34\uc5c7\uc778\uac00?<\/li>\n<li>[DoS \ud0d0\uad6c]2.DoS \uacf5\uaca9 \uc720\ud615<\/li>\n<li>[DoS \ud0d0\uad6c]3.DoS \ub300\uc751\ubc29\uc548<\/li>\n<\/ul>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><span style=\"color: #003399;\">(1) ISP\uc640\uc758 \uacf5\uc870\uccb4\uc81c\uad6c\ucd95<\/span><\/p>\n<p>DoS \uacf5\uaca9\uc744 \ubc29\uc5b4\ud558\uae30 \uc704\ud55c \uac00\uc7a5 \uc911\uc694\ud55c \uccab \ubc88\uc9f8 \ub2e8\uacc4\ub294 ISP\uc640 \uc5f0\ub77d\uc744 \uc720\uc9c0\ud558\uace0 DoS \uacf5\uaca9\uc744 \uc704\ud574 \uc5b4\ub5a4 \ub300\ucc45\uc774 \uc9c0\uc6d0\ub418\uace0 \uc788\ub294\uc9c0 \uc54c\uc544\ubd10\uc57c \ud55c\ub2e4. \uac70\uc758 \ub300\ubd80\ubd84\uc758 \uc0ac\uc6a9\uc790\ub4e4\uc774 ISP\ub97c \ud1b5\ud574 \uc778\ud130\ub137\uc5d0 \uc811\uc18d\ud558\uace0 \uc788\uc73c\uba70, DoS\uc5d0 \uc548\uc804\ud55c \ub300\uc751\uc774 \uc0ac\uc6a9\ub418\uace0 \uc788\ub354\ub77c\ub3c4, ISP\uc640\uc758 \uc5f0\uacb0\uc774 \ub450\uc808\ub418\uac70\ub098 \ud3ec\ud654\uc0c1\ud0dc\uc774\uba74 \uc544\ubb34\ub7f0 \uc18c\uc6a9\uc774 \uc5c6\ub2e4.<\/p>\n<p><span style=\"color: #003399;\">(2) DoS \uacf5\uaca9 \ud0d0\uc9c0\ub294 \uc5b4\ub5bb\uac8c \ud558\ub294\uac00?<\/span><\/p>\n<p>\uacf5 \uaca9\uc744 \ub2f9\ud558\uace0 \uc788\ub2e4\uace0 \uc0dd\uac01\ub418\uba74, \uc6b0\uc120 \uc6b4\uc601\uccb4\uc81c\uc5d0\uc11c netstat \uba85\ub839\uc774 \uc9c0\uc6d0\ub418\ub294\uc9c0\ub97c \ud655\uc778\ud558\uace0 \uc774 \uba85\ub839\uc5b4\ub97c \uc2e4\ud589\ud55c\ub2e4. \ub9cc\uc77c SYN_RECV \uc0c1\ud0dc\uc758 \uc811\uc18d\uc774 \ub9ce\uc774 \ubcf4\uc778\ub2e4\uba74 SYN \uacf5\uaca9\uc774 \uc9c4\ud589\ub418\uace0 \uc788\ub2e4\uace0 \uc758\uc2ec\ud574 \ubcfc \ud544\uc694\uac00 \uc788\ub2e4.(\ub2e8 \ubb34\uc870\uac74 DoS \uacf5\uaca9\uc73c\ub85c \uac04\uc8fc\ud574\uc11c\ub294 \uc548 \ub41c\ub2e4.)<\/p>\n<div><img src=\"http:\/\/image.ahnlab.com\/info\/securityinfo\/upload_\/DoS_12.jpg\" alt=\"\" border=\"0\" \/><\/div>\n<p>\uc708\ub3c4\uc6b0\uc6a9 IDS(\uce68\uc785\ud0d0\uc9c0\uc2dc\uc2a4\ud15c)\uc778 Snort\ub97c \ud65c\uc6a9\ud558\ub294 \uac83\ub3c4 \uc88b\uc740 \ubc29\ubc95\uc774\ub2e4.<\/p>\n<p>Snort : <a href=\"http:\/\/www.snort.org\/\" target=\"_blank\" rel=\"noopener noreferrer\">http:\/\/www.snort.org<\/a><\/p>\n<p>Snort cheat-sheet: <a href=\"https:\/\/comparite.ch\/snort-cs\">https:\/\/comparite.ch\/snort-cs<\/a><\/p>\n<p>\uc0ac\uc6a9\ubc95 : www.certcc.or.kr, http:\/\/www.securitymap.net\/sdm\/sdm_ids.html<\/p>\n<p><span style=\"color: #003399;\">(3) DoS \uacf5\uaca9\uc744 \ub9c9\uae30 \uc704\ud55c TCP\/IP \ud30c\ub77c\ubbf8\ud130 \uad6c\uc131\ud558\uae30<\/span><\/p>\n<p>\uc544\ub798 \ub808\uc9c0\uc2a4\ud2b8\ub9ac \uac12\ub4e4\uc740 Windows2000test.com\uc744 \ud14c\uc2a4\ud305\ud560 \ub54c DoS \uacf5\uaca9\uc744 \ub9c9\uae30 \uc704\ud574 MS\uac00 \uc0ac\uc6a9\ud55c \ud30c\ub77c\ubbf8\ud130\ub4e4\uc774\uba70, \uc544\ub798 \ub0b4\uc6a9\uacfc \ub808\uc9c0\uc2a4\ud2b8\ub9ac\ub97c \ube44\uad50\ud574\uc11c \uc5c6\ub294 \uac12\ub4e4\uc740 \uc9c1\uc811 \uc0dd\uc131\ud574\uc57c \ud55c\ub2e4.<\/p>\n<div><img src=\"http:\/\/image.ahnlab.com\/info\/securityinfo\/upload_\/DoS_13.jpg\" alt=\"\" border=\"0\" \/><\/div>\n<p><strong>HKEY_LOCAL_MACHINE &#8211; SYSTEM &#8211; CurrentControlSet &#8211; Services <\/strong><\/p>\n<table border=\"1\" width=\"400\" cellspacing=\"0\" cellpadding=\"2\">\n<tbody>\n<tr bgcolor=\"#f7f7f7\">\n<td width=\"50%\"><strong>TcpipParameters<\/strong><\/td>\n<td align=\"center\" width=\"25%\">\uc124\uc815 \uad8c\uc7a5\uc0ac\ud56d<\/td>\n<td align=\"center\" width=\"25%\">\uc885 \ub958<\/td>\n<\/tr>\n<tr>\n<td>SynAttackProtect<\/td>\n<td align=\"center\">2<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>TcpMaxHalfOpen<\/td>\n<td align=\"center\">100(Advanced Server : 500)<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>TcpMaxHalfOpenRetried<\/td>\n<td align=\"center\">80(Advanced Server : 400)<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>TcpMaxPortsExhausted<\/td>\n<td align=\"center\">1<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>TcpMaxConnectResponse<\/p>\n<p>Retransmissions<\/td>\n<td align=\"center\">2<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>EnableDeadGWDetect<\/td>\n<td align=\"center\">0<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>EnablePMTUDiscovery<\/td>\n<td align=\"center\">0<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>KeepAliveTime<\/td>\n<td align=\"center\">300,000<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>EnableICMPRedirects<\/td>\n<td align=\"center\">0<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>InterfacesPerformRouterDiscovery<\/td>\n<td align=\"center\">0<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td><strong>NetBtParameters<\/strong><\/p>\n<p>NoNameReleaseOnDemand<\/td>\n<td align=\"center\">1<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<table border=\"1\" width=\"400\" cellspacing=\"0\" cellpadding=\"2\">\n<tbody>\n<tr bgcolor=\"#f7f7f7\">\n<td width=\"50%\"><strong>TcpipParameters<\/strong><\/td>\n<td align=\"center\" width=\"25%\">\uc124\uc815 \uad8c\uc7a5\uc0ac\ud56d<\/td>\n<td align=\"center\" width=\"25%\">\uc885 \ub958<\/td>\n<\/tr>\n<tr>\n<td>EnableSecurityFilters<\/td>\n<td align=\"center\">1<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>DisableIPSourceRouting<\/td>\n<td align=\"center\">1<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>TcpMaxDataRetransmissions<\/td>\n<td align=\"center\">3<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td><strong>AFDParameters<\/strong><\/td>\n<td align=\"center\"><\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>EnableDynamicBacklog<\/td>\n<td align=\"center\">1<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>MinimumDynamicBacklog<\/td>\n<td align=\"center\">20<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<tr>\n<td>DynamicBacklogGrowthDelta<\/td>\n<td align=\"center\">10<\/td>\n<td align=\"center\">REG_DWORD<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>\u25c7 \ucc38\uc870 \ud398\uc774\uc9c0 : <\/strong><\/p>\n<div>\n<ul>\n<li><a href=\"http:\/\/support.microsoft.com\/default.aspx?scid=KB;en-us;142641&amp;\" target=\"_blank\" rel=\"noopener noreferrer\">http:\/\/support.microsoft.com\/default.aspx?scid=KB;en-us;142641&amp;<\/a><\/li>\n<li><a href=\"http:\/\/www.microsoft.com\/technet\/treeview\/default.asp?url=\/technet\/security\/default.asp\" target=\"_blank\" rel=\"noopener noreferrer\">http:\/\/www.microsoft.com\/technet\/treeview\/default.asp?url=\/technet\/se<\/a><\/li>\n<\/ul>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>DoS\ub97c \ub9c9\uae30 \uc704\ud574 \uc6b0\uc120\uc801\uc73c\ub85c \ub2f9\ubd80\ud558\uace0 \uc2f6\uc740 \ub9d0\uc740 &#8220;\uc808\ub300\ub85c \ud3ec\uae30\ud558\uc9c0 \ub9d0\ub77c&#8221;\ub294 \uac83\uc774\ub2e4. \ube44\ub85d DoS \uacf5\uaca9\uc744 \uc644\ubcbd\ud558\uac8c \ubc29\uc5b4\ud558\ub294 \uac83\uc740 \uc5b4\ub824\uc6b4 \uc77c\uc774\uc9c0\ub9cc \uac04\ub2e8\ud55c \ub77c\uc6b0\ud130 \ubc0f \ub610\ub294 \ubc29\ud654\ubcbd\uc744 \uad6c\uc131\ud558\uc5ec \uc6f9 \uc0ac\uc774\ud2b8\ub85c \ub4e4\uc5b4\uc624\ub294 \ud2b8\ub798\ud53d \uc885\ub958\uc640 \ubc94\uc704\ub97c \uc81c\ud55c\uc2dc\ucf1c \ud53c\ud574\uc815\ub3c4\ub97c \uc904\uc77c \uc218\uac00 \uc788\ub2e4. \ubb3c\ub860 \uacf5\uaca9\uc790\ub294 \ub354 \uac15\ub3c4 &hellip; <a href=\"http:\/\/pchero21.com\/?p=1125\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":[],"categories":[63],"tags":[],"_links":{"self":[{"href":"http:\/\/pchero21.com\/index.php?rest_route=\/wp\/v2\/posts\/1125"}],"collection":[{"href":"http:\/\/pchero21.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/pchero21.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/pchero21.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/pchero21.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1125"}],"version-history":[{"count":1,"href":"http:\/\/pchero21.com\/index.php?rest_route=\/wp\/v2\/posts\/1125\/revisions"}],"predecessor-version":[{"id":3951,"href":"http:\/\/pchero21.com\/index.php?rest_route=\/wp\/v2\/posts\/1125\/revisions\/3951"}],"wp:attachment":[{"href":"http:\/\/pchero21.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1125"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/pchero21.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1125"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/pchero21.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1125"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}