´ë·® SQL ÁÖÀÔ
À̹ø ÁÖÃÊ¿¡ ³ª´Â a¸¦ °£ÇàÇß´Ù Microsoft WindowsÀÇ ¸î¸î ¹öÀü¿¡ ÀÖ´Â Ãë¾à¼º¿¡ ´ëÇÏ¿© Æ÷½ºÆ®¡¦
¡¦ ÁÁÀº Ãë¾à¼ºÀº Áö±Ý °¡´Â ´ë·® SQL ÁÖÀÔ IIS Ç÷¡Æ®È¨¿¡ ´Þ¸®´Â ¼öõ ¼ö¹é À¥»çÀÌÆ®¸¦ °¨¿°ÇÑÁö ¾î´À °ÍÀÌ¿¡ÀÌ´ÙÀÇ ´Ù¸¥ ¿ø ¼öÇàµÇ°í ÀÖ´Ù °Å±â.
¾ÇÀÇ ÀÖ´Â ¿øº»ÀÇ ÀÚÃ븦 À§ÇÑ Google °£´ÜÇÑ ¼ö»öÀ» ¹Ì¸® Çü¼ºÇÏ´Â °ÍÀº ³Ñ¾î¼ ¾ÈÀ¸·Î À¯·¡ÇÑ´Ù 510,000´Â ÆäÀÌÁö¸¦ º¯°æÇß´Ù.
Á¡Á¡ ±× µ¥ÀÌŸº£À̽º¿¡°Ô¼ ±×µéÀ» ´õ ºü¸¥°ú µ¿¿¡°Ô, ±×°Í ¹æ¹ý ¶Ç´Â ¿ä±¸ÇÏ´Â ¸¸µå´Â ÈĺΠSQL¸¦ »ç¿ëÇÏ´Â À¥»çÀÌÆ®·Î - ƯÈ÷ ´ç½ÅÀÌ »ç¿ëÀÚ ±×µéÀÚ½ÅÀÌ Åä·Ðȸ, blogs, ÀÇ°ß ¸ð¾ç µîµî¿¡¼ Ç×»ó ÀϾ´Â ³»¿ëÀ» ¿Ã·ÁÁÖ±âÇÏ °ÍÀ» Çã¿ëÇÏ´Â °æ¿ì¿¡ Á¤º¸°¡ ¾ÈÀ¸·Î ÀúÀåÇØ ¾ò´Â ¹«½¼À» È®ÀÎÇÏ´Â °Íµµ °áÁ¤Àû ÀÌ´Ù. À¥»çÀÌÆ®°¡ »ç¿ëÀÚ¿¡°Ô º¸¿©ÁÙ ¹«½¼À» ¾ò±â Àü¿¡ Àú ÀÚ·á°¡ ÀúÀåÇÏ¸é ´ç½ÅÀ» ÅëÁ¦ÇÒ ¼ö ¾øÀ¸¸é À§»ýÀûÀ¸·Î ÇÏ¸é ¾Ê´Â ÇÑ. À̰ÍÀº SQL ÁÖÀÔÀÌÀÎ ÀüºÎ ´ë·« ¹«½¼À̾î, ÀÌ ÅëÁ¦¿¡ ÀÖ´Â ¾àÁ¡À» ÀÌ¿ëÇÑ.
ÇöÀç ÁÖ»çµÇ°í ÀÖ´Â ¾ÇÀÇ ÀÖ´Â ÆÄÀÏÀº 1.jsÀÌ´Ù ±×·¯³ª À̰ÍÀº ¾î¶² ´Ü°è¿¡¼¶óµµ º¯ÈÇÑ´Ù´Â °ÍÀº ¼ö ÀÖ¾ú´Ù´Â °ÍÀº ÁÖÀǵǾî¾ß ÇÏ´Â. ÀÌ À¥»çÀÌÆ®¿¡ ¹æ¹®ÀÚ´Â ¸ñÇ¥¸¦ Æ÷ÇÔÇÏ¿©€ ¸¹Àº€ â¿¡ ±Ù°ÅÇÑ ½ÅûÀ» À§ÇÑ 8°³ÀÇ ´Ù¸¥ À̿뿡 â ©«treatedâ , RealPlayer ¹× iTunesÀÌ´Ù. [[DO NOT]]´ç½ÅÀÌ °¨¿°ÇØ ¾ò°Ô ¾ÆÁÖ ÇÒ °Í °°±â ¶§¹®¿¡ ÀÌ À§Ä¡¿¡ ¿¬°áÇÏ´Â ¹æ¹® À§Ä¡. Trendmicro´Â ¾ÏÈ£¸¦ À§ÇØ º¸°í contollerâ ¢âs IP µîÀ» ¸Â´í ±×µéÀ» Åë°úÇÏ´Â malware€ toj_agent.KAQ¸¦ Áö¸íÇß´Ù.
ÀÌ °æ¿ì¿¡´Â ÁÖÀÔ ºÎÈ£´Â ÀÌ°Í °°ÀÌ ½ÃÀÛÇÑ´Ù (ÁÖ´Â, ÀÌ°Í ¿ÏÀüÇÑ ºÎÈ£°¡ ¾Æ´Ï´Ù):
   DECLARE%20@S%20NVARCHAR (4000); ÇØµ¶µÉ °æ¿ì SET%20@S=CAST (0x440045004300    4C00410052004500200040005400200076006100720063006800610072    00280032003500350029002C0040004300200076006100720063006800    610072002800320035003500290020004400450043004C004100520045    0020005400610062006C0065005F0043007500720073006F0072002000    43005500520053004F005200200046004F0052002000730065006C0065    0063007400200061002E006E0061006D0065002C0062002E006E006100    6D0065002000660072006F006D0020007300790073006F0062006A0065    00630074007300200061002C0073007900730063006F006C0075006D00    6E00730020006200200077006800650072006500200061002E00690064    003D0062002E0069006400200061006E006400200061002E0078007400    7900700065003D00270075002700200061006E0064002000280062002E    00780074007900700065003D003900390020006F007200200062002E00  €  780074007900700065003D003300350020006â´Â ¦ µÈ´Ù:   ´ varchar varchar (255) '@C°¡ (255) sysobjects a'syscolumns b   ¿¡¼ Ãß·Á³½ a.name'b.name¸¦ À§ÇÑ Table_Cursor    Ŀ¼¸¦ °÷¿¡ a.id=b.id¿Í a.xtype='u¿Í ¼±¾ðÇÏ´Â @T¸¦ ¼±¾ðÇÑ´Ù (b.xtype=99 ¶Ç´Â b.xtype=35    ¶Ç´Â b†¦
¹«¾ùÀÌ ±× °á°ú·Î ÀϾ´Â°¡? ±×°ÍÀº µ¥ÀÌŸº£À̽º¿¡ ÀÖ´Â ¸ðµç ¿øº» ºÐ¾ß¸¦ ã¾Æ³»°í ¾ÇÀÇ ÀÖ´Â javascript¿¡ ´ç½ÅÀÇ À¥»çÀÌÆ®¿¡ ±×µéÀ» ÀÚµ¿À¸·Î Ç¥½ÃÇÑ ±×µé °¢ÀÚ¿¡ ¿¬°áÀ» Ãß°¡ÇÑ´Ù. ÀÏ¾î³ ¹«¾ùÀÌ ÀÌ·¸°Ô ±Ùº»ÀûÀ¸·Î ±×µéÀÇ SQL ÁÖÀÔ ºÎÈ£¸¦ ¿Ã·ÁÁÖ±âÇϱâ À§ÇÏ¿© °ø°Ý±â°¡ querystring (±â»ç ID Á¦Ç° ID, µîµî cetera¿Í °°Àº µ¿ÀûÀÎ °¡Ä¡) ¸Å°³º¯¼öÀÇ ¾Æ¹« À¯Çü³ª Æ÷ÇÔÇÏ´Â ASP ¶Ç´Â ASPX ÆäÀÌÁö¸¦ ã°í Àú°ÍÀ» ÀÌ¿ëÇϵµ·Ï´Ù´Â °ÍÀ» ½ÃµµÇß´Ù´Â °ÍÀ» À̾ú´Ù.
ÀÌÁ¦±îÁö´Â 3°³ÀÇ ´Ù¸¥ ¿µ¿ªÀº ¾ÇÀÇ ÀÖ´Â ¸¸Á·ÇÑ â¸¦" Á¢´ëÇÏ´Â ÀÌ¿ëµÇ¾ú´Ù€ nmidahena.com, aspder.com ±×¸®°í nihaorr1.com. ÀÌ À§Ä¡¿¡¼ ÀûÀçÇØ ¾ò´Â ÆÄÀÏÀÇ ¼¼Æ®°¡ ÀÖ´Ù ¿Â¶óÀÎ µµ¹Ú Æ®·ÎÀÌ »ç¶÷À» ¼³Ä¡Çϱâ À§ÇÏ¿© ´Ù¸¥ ÀÌ¿ëÀ» ÀÌ¿ëÇϵµ·Ï ½ÃµµÇÏ´Â.
Áö±Ý ¸ðµç ¿µ¿ª¿¡ óÀ½ ÀÌ¿ë ÆäÀÌÁö´Â Á¢±ÙÇÏ±â ¾î·Æ´Ù ±×·¯³ª Àú°ÍÀº º¯ÈÇÒ ¼ö ÀÖ¾ú´Ù. So if you¡¯re a firewall administrator we recommend you to block access to them.
I would recommend that Administrators block access to hxxp:/www.nihaorr1.com and the IP it resolves to 219DOT153DOT46DOT28 at the edge or border of your network.
Info sourced from f-secure
Written by Patrick S. Read more great feeds at is source WEBSITE
no comments.
Read more articles on otherSoftware and MS News.
- [+] Digg: Feature this article
- [+] Del.icio.us: Bookmark this article
- [+] Furl: Bookmark this article














