Å×Å©³ë ÄÄÇ»ÅÍ

[¿ø°Ý¿äû] . [ȸ¿øÀÚ·á½Ç] [EDIT]     [Win98] [Win2000] [Win7] [win10] [WinServer] [Linux] [A/SÀÚ·á] [Driver] [UTIL] [º¹Á¦±â] [TC]

__Today: __
Your ip : 18.117.91.153
ȸ¿ø¾ÆÀ̵ð 
Æнº¿öµå
  ÄÄÇ»ÅÍ
  ¸ð´ÏÅÍ
  À×Å©/Åä³Ê-¼Ò¸ðÇ°
  ÄÄÇ»Åͺ»Ã¼ºÎÇ°
  ½ºÄɳÊ
  ÇÁ¸°ÅÍ
  ÄÄÇ»ÅͼҸðÇ°
  ³×Æ®¿öÅ©
  ¼ÒÇÁÆ®¿þ¾î

ÀüÈ­ : 062-224-6450
Æѽº : 062-227-6450

  Å×Å©³ëÄÄÇ»ÅÍ

[ ÀÚ·á½Ç ]

±¤°í¼º ±ÛÀ̳ª ºÒ¹ýÀÚ·á ¾÷·Îµå¸¦ ±ÝÇÕ´Ï´Ù.

sendmail¿¡¼­ sircam virus Â÷´ÜÇϱâ
À̸§ : ÇãÁ¤±Õ     ¹øÈ£ : 42     Á¶È¸ : 75744
¾÷·Îµå : 2001-08-29 17:30:13     ¼öÁ¤ÀÏ : 2002-03-18 14:51:44

ÀÌ ¹ÙÀÌ·¯½º´Â º¸Åë, 'Hi! How are you?' ¶ó´Â ¹®±¸¸¦ Æ÷ÇÔÇÏ°í ÀÖÀ¸¸ç,

ÀϹÝÀûÀÎ ÆÄÀÏÀ» ÷ºÎÇÏ°í ÀÖ´Â Á¤»óÀûÀÎ ¸ÞÀÏó·³ º¸¿©, ¼Ó¾Æ³Ñ¾î°¡±â ½¬¿î ÇüÅÂÀ̸鼭,
½Ã½ºÅÛ¿¡ ÇÇÇظ¦ ÀÔÈ÷¹Ç·Î, ÁÖÀǸ¦ ¿äÇÏ°í ÀÖ½À´Ï´Ù.



¾Æ·¡ ³»¿ëÀº ±è°æ¿í´Ô²²¼­ ÀÛ¼ºÇÑ sendmail 8.9  ÀÌ»ó ¹öÀü¿¡¼­ ÀÌ ¹ÙÀÌ·¯½º¸¦
Â÷´ÜÇÏ´Â ¹æ¹ý¿¡ ´ëÇÑ ÆÁÀÔ´Ï´Ù.





--------------------------------------------------------------------------------




   
ÀÌ ·ê¼ÂÀº quanta-spam_killer¿¡¼­ Sircam worm Â÷´Ü ·ê¼Â¸¸À» ºÐ¸®ÇÑ
    °ÍÀÔ´Ï´Ù.
   
Sircam worm¿¡ ´ëÇÑ Á¤º¸´Â ¾Æ·¡ URL¿¡¼­ È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.
   
http://home.ahnlab.com/search/virus_detail.jsp?SEQ_NO=843
   

    w32.sircam.worm@mm.html"
     target="_blank">w32.sircam.worm@mm.html" TARGET=_blank>w32.sircam.worm@mm.html" TARGET=_blank>http://www.symantec.com/avcenter/venc/data/pf/w32.sircam.worm@mm.html
   

         target="_blank">½Ã¸¸ÅØ, ¼­Ä· ¿ú ¹ÙÀÌ·¯½º À§Çèµµ »óÇâ Á¶Á¤ (µðÁöÅ» ŸÀÓ½º,
    2001/07/23)

         target="_blank">[ÄÄÇ»ÅÍ]"How are you" ¹ÙÀÌ·¯½º ±â½Â (µ¿¾ÆÀϺ¸,
    2001/07/20)


   
 
   

º» Â÷´Ü¹ýÀº Sircam worm Á¦ÀÛÀÚÀÇ À߸øµÈ Content-Disposition: »ç¿ë¿¡
    ¹ÙÅÁÀ» µÐ °ÍÀ¸·Î, Content-Disposition: ÀÇ ¿Ã¹Ù¸¥ »ç¿ë¿¹´Â RFC 2183À» ÂüÁ¶ÇϽñâ
    ¹Ù¶ø´Ï´Ù.
   
Áï, º» ·ê¼ÂÀº ¸ÞÀÏ Çì´õ¿¡ ¾Æ·¡¿Í °°Àº header field°¡ ¹ß°ßµÉ °æ¿ì sircam
    worm À¸·Î °£ÁÖÇÏ¿© reject ÇÕ´Ï´Ù. RHSÀÇ ¿Ã¹Ù¸¥ »ç¿ë¿¹´Â, 'inline' ¶Ç´Â 'attachment'
    ÀÔ´Ï´Ù.
   
Content-Disposition: Multipart message
   

sendmail.cf¿¡ ´ÙÀ½ ·ê¼Â¸¸À» Ãß°¡ÇÏ¿© Sircam wormÀ» Â÷´ÜÇÒ ¼ö ÀÖ½À´Ï´Ù.

    ¶ÇÇÑ, ³»ºÎ ³×Æ®¿öÅ©¿¡ ÀÌ¹Ì °¨¿°µÈ PC°¡ ÀÖÀ» °æ¿ì wormÀÇ È®»êÀ» Â÷´ÜÇÔ°ú

    µ¿½Ã¿¡, maillog(¶Ç´Â syslog)¸¦ °Ë»öÇÏ¿© °¨¿°µÈ PC¸¦ ¹ß°ßÇÒ ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù.
   




   
ÀÌ ·ê¼ÂÀÇ »ç¿ëÀº sendmail 8.9 À̻󿡼­¸¸ »ç¿ëÇÒ ¼ö ÀÖ½À´Ï´Ù.

    ÆĶõ»öÀ¸·Î µÈ ºÎºÐÀÌ Ãß°¡µÉ ºÎºÐÀÔ´Ï´Ù.
   
# check IP address
R$*                     $: $&{client_addr}
R$@                     $@ OK                   originated locally
R0                      $@ OK                   originated locally
R$=R $*                 $@ OK                   relayable IP address
R$*                     $: $>LookUpAddress <$1>  <$1>
R$*                     $@ RELAY                relayable IP address
R<$*> <$*>              $: $2
R$*                     $: [ $1 ]               put brackets around it...
R$=w                    $@ OK                   ... and see if it is local
 
 
# anything else is bogus
R$*                     $#error $@ 5.7.1 $: "550 Relaying denied"
 
 
### Sircam worm filter
 
HContent-Disposition: $>check_sircam
D{SIRCAM}"Your message may contain the Sircam.worm !!! (¾Æ·¡ÁÙ°ú ¿¬°áÇؼ­ ¾²¼¼¿ä.)
See w32.sircam.worm@mm.html" TARGET=_blank>w32.sircam.worm@mm.html" TARGET=_blank>http://www.symantec.com/avcenter/venc/data/pf/w32.sircam.worm@mm.html"
 
Scheck_sircam
RMultipart message $#error $: 550 ${SIRCAM}
 
 
 
#### ÁÖÀÇ: Multimapt message¿Í $#error »çÀÌ´Â [TAB]ÀÔ´Ï´Ù.
 
 
 
######################################################################
######################################################################
#####
#####                   MAILER DEFINITIONS
#####
######################################################################
######################################################################
   

       
Sendmail.cfÀÇ ¼öÁ¤ÀÌ ´Ù ³¡³µÀ¸¸é, sendmailÀ»
        restart Çϱâ Àü¿¡ ruleset ¸ðµå¿¡¼­ Å×½ºÆ®¸¦ ÇØ º¾´Ï´Ù.
   

$ /usr/lib/sendmail -bt
ADDRESS TEST MODE (ruleset 3 NOT automatically invoked)
Enter
               
> check_sircam Multipart message check_sircam input:
                Multipart message check_sircam returns: $# error $: 550 553
                Your message may contain the Sircam . worm ! ! ! See http :
                / / www . symantec . com / avcenter / venc / data / pf / w32
                . sircam . worm @ mm . html > ctrl-D (ºüÁ®³ª¿À±â)
 

   
À§¿Í °°ÀÌ Àß µÇ¾ú´Ù¸é, sendmailÀ» restart
ÇÕ´Ï´Ù.

À­±Û : 2001-08-30 10:00:40,   43¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(rc.deny, 13,233Byte)ÀÌ ÀÖ½À´Ï´Ù. iptables¸¦ ÀÌ¿ëÇÑ ¾ÆÀÌÇÇ Â÷´Ü
¹Ø±Û : 2001-06-08 18:02:22,   41¹ø ±Û ¹Ù·Îº¸±â linux 7.1 kernel 2.4.x iptables se
  Absolute number:72
Ȩ¾²±â°ü·Ã±ÛÀü´Þ¼öÁ¤»èÁ¦¸ñ·Ï
 
¹øÈ£ Á¦¸ñ ÷ºÎÆÄÀÏ Å©±â Àü¼Û À̸§ ¾÷·Îµå
41¹øÀÇ °ü·Ã±Û 2001-06-08 18:03:51,   41¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: linux 7.1 kernel 2.4.x iptab     0 Mr heo 06-08
41¹øÀÇ °ü·Ã±Û 2001-06-08 18:05:09,   41¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: linux 7.1 kernel 2.4.x iptab     0 Mr heo 06-08
41¹øÀÇ °ü·Ã±Û 2001-06-08 18:07:50,   41¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: linux 7.1 kernel 2.4.x iptab     0 Mr heo 06-08
41¹øÀÇ °ü·Ã±Û 2001-06-08 18:08:30,   41¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: linux 7.1 kernel 2.4.x iptab     0 Mr heo 06-08
41¹øÀÇ °ü·Ã±Û 2001-08-21 19:39:53,   41¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â Re: linux 7.1 kernel 2.4.x iptab     0 ÇãÁ¤±Õ 08-21
41¹øÀÇ °ü·Ã±Û 2001-08-29 17:53:06,   41¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â iptables¿¡¼­ ´ÙÀ̾ËÆеå»ç¿ëÇÏ±â     0 ÇãÁ¤±Õ 08-29
40 2001-06-07 14:23:36,   40¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(portsentry-1.0.tar.gz, 43,034Byte)ÀÌ ÀÖ½À´Ï´Ù. ÇØÅ·¹æÁö portsentry ´Ù¿î·Îµå : portsentry-1.0.tar.gz (43,034Byte) portsentry-1.0 42KB 3992 Mr heo 06-07
40¹øÀÇ °ü·Ã±Û 2001-06-07 14:24:15,   40¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(logcheck-1.1.1.tar.gz, 30,267Byte)ÀÌ ÀÖ½À´Ï´Ù. log ³»¿ª ºÐ¼® ´Ù¿î·Îµå : logcheck-1.1.1.tar.gz (30,267Byte) logcheck-1.1.1 29KB 3992 Mr heo 06-07
40¹øÀÇ °ü·Ã±Û 2002-02-16 12:25:16,   40¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(portsentry-1.1.tar.gz, 45,871Byte)ÀÌ ÀÖ½À´Ï´Ù. ÇØÅ·¹æÁö portsentry 1.1 -> for l ´Ù¿î·Îµå : portsentry-1.1.tar.gz (45,871Byte) portsentry-1.1 44KB 4342 ÇãÁ¤±Õ 02-16
40¹øÀÇ °ü·Ã±Û 2002-02-16 12:26:32,   40¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(portsentry, 44,654Byte)ÀÌ ÀÖ½À´Ï´Ù. Re: ÇØÅ·¹æÁö portsentry 1.1 -> ´Ù¿î·Îµå : portsentry (44,654Byte) portsentry 43KB 3613 ÇãÁ¤±Õ 02-16
40¹øÀÇ °ü·Ã±Û 2002-02-16 12:26:57,   40¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(portsentry.conf, 11,286Byte)ÀÌ ÀÖ½À´Ï´Ù. Re: ÇØÅ·¹æÁö portsentry 1.1 -> ´Ù¿î·Îµå : portsentry.conf (11,286Byte) portsentry.conf 11KB 8070 ÇãÁ¤±Õ 02-16
40¹øÀÇ °ü·Ã±Û 2002-02-16 12:28:21,   40¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(portsentryd, 671Byte)ÀÌ ÀÖ½À´Ï´Ù. Re: ÇØÅ·¹æÁö portsentry 1.1 -> ´Ù¿î·Îµå : portsentryd (671Byte) portsentryd 671B 4070 ÇãÁ¤±Õ 02-16
39 2001-05-04 16:49:06,   39¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(techupprint.htm, 26,641Byte)ÀÌ ÀÖ½À´Ï´Ù. ÇÑÅëadsl ¼³Á¤Çϱ⠴ٿî·Îµå : techupprint.htm (26,641Byte) techupprint.htm 26KB 4846 ÇãÁ¤±Õ 05-04
39¹øÀÇ °ü·Ã±Û 2001-05-04 17:56:32,   39¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â ÇÑÅë adsl Á¢¼Ó À¯Áö..     0 ÇãÁ¤±Õ 05-04
39¹øÀÇ °ü·Ã±Û 2001-05-15 09:53:36,   39¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â ÇÑÅëadsl Á¢¼ÓÀ¯Áö 2     0 ÇãÁ¤±Õ 05-15
38 2001-05-03 18:29:57,   38¹ø ±Û ¹Ù·Îº¸±â Linux Real IP Forward/Firewall Mac     0 ÇãÁ¤±Õ 05-03
37 2001-05-03 10:48:10,   37¹ø ±Û ¹Ù·Îº¸±â ipchaines,ÆÐŶÇÊÅ͸µ ÀÀ¿ë- ƯÁ¤»çÀÌ     0 ÇãÁ¤±Õ 05-03
37¹øÀÇ °ü·Ã±Û 2001-05-12 10:24:29,   37¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(IPCHAINS-HOWTO[1].txt, 66,678Byte)ÀÌ ÀÖ½À´Ï´Ù. ipchaines ¿¹Á¦ ¹× ¼³¸í¼­ ´Ù¿î·Îµå : IPCHAINS-HOWTO[1].txt (66,678Byte) IPCHAINS-HOWTO 65KB 5685 ÇãÁ¤±Õ 05-12
36 2001-05-03 09:29:29,   36¹ø ±Û ¹Ù·Îº¸±â kernel 2.2.X ÀÇ IP MASQ     0 ÇãÁ¤±Õ 05-03
36¹øÀÇ °ü·Ã±Û 2001-05-15 09:40:06,   36¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(ipmasqadm.rpm, 24,789Byte)ÀÌ ÀÖ½À´Ï´Ù. ipmasqadm.rpm ´ÙÀÌ¾Ë ÆÐµå »ç¿ë½Ã ´Ù¿î·Îµå : ipmasqadm.rpm (24,789Byte) ipmasqadm.rpm 24KB 3668 ÇãÁ¤±Õ 05-15
36¹øÀÇ °ü·Ã±Û 2001-05-19 09:01:25,   36¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(ipmasqadm-0.4.2.tar.gz, 19,035Byte)ÀÌ ÀÖ½À´Ï´Ù. ipmasqadm-0.4.2.rpm ¼³Á¤°ª»çÀÌ ´Ù¿î·Îµå : ipmasqadm-0.4.2.tar.gz (19,035Byte) ipmasqadm-0.4. 18KB 4112 ÇãÁ¤±Õ 05-19
36¹øÀÇ °ü·Ã±Û 2001-09-12 18:32:04,   36¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(rclira.fir, 108Byte)ÀÌ ÀÖ½À´Ï´Ù. ipmasqadm setting °ª - ´ÙÀÌ¾Ë ´Ù¿î·Îµå : rclira.fir (108Byte) rclira.fir 108B 4167 ÇãÁ¤±Õ 09-12
36¹øÀÇ °ü·Ã±Û 2001-09-17 16:43:26,   36¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(ipmasq.txt, 989Byte)ÀÌ ÀÖ½À´Ï´Ù. ipmasqadmÀÇ ¸¶Áö¸· Á¤¸® ´Ù¿î·Îµå : ipmasq.txt (989Byte) ipmasq.txt 989B 3941 ÇãÁ¤±Õ 09-17
35 2001-05-02 14:42:02,   35¹ø ±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(coyote2.zip, 3,827,223Byte)ÀÌ ÀÖ½À´Ï´Ù. ¸®´ª½º ¶ó¿ìÆÃ-ipmasq-µð½ºÄÏ ÇÑÀå ´Ù¿î·Îµå : coyote2.zip (3,827,223Byte) coyote2.zip 3.65MB 3485 ÇãÁ¤±Õ 05-02
35¹øÀÇ °ü·Ã±Û 2001-05-02 16:24:04,   35¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(lira.htm, 128,436Byte)ÀÌ ÀÖ½À´Ï´Ù. ÀüüÀûÀμ³¸é-¸®¶ó ´Ù¿î·Îµå : lira.htm (128,436Byte) lira.htm 125KB 6233 ÇãÁ¤±Õ 05-02
35¹øÀÇ °ü·Ã±Û 2001-05-18 11:53:49,   35¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â ¸®¶ó¿¡¼­ ip¾Ë¾Æ³»±â     0 ÇãÁ¤±Õ 05-18
35¹øÀÇ °ü·Ã±Û 2001-05-02 21:18:32,   35¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â »ç¿ë±â     0 ÇãÁ¤±Õ 05-02
35¹øÀÇ °ü·Ã±Û 2001-05-15 12:32:16,   35¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(ipheo.tar, 71,680Byte)ÀÌ ÀÖ½À´Ï´Ù. ipmasqadm & ipvsadm kernel 2.2.* ´Ù¿î·Îµå : ipheo.tar (71,680Byte) ipheo.tar 70KB 3428 ÇãÁ¤±Õ 05-15
35¹øÀÇ °ü·Ã±Û 2001-09-20 15:10:45,   35¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â,   ÷ºÎÆÄÀÏ(Coyote Linux.rar, 2,575,618Byte)ÀÌ ÀÖ½À´Ï´Ù. ¸®´ª½º ¶ó¿ìÆÃ-ipmasq-µð½ºÄÏ ÇÑÀå ´Ù¿î·Îµå : Coyote Linux.rar (2,575,618Byte) Coyote Linux.r 2.46MB 3397 ÇãÁ¤±Õ 09-20
35¹øÀÇ °ü·Ã±Û 2001-10-05 19:28:04,   35¹øÀÇ °ü·Ã±Û ¹Ù·Îº¸±â echo "1" > /proc/sys/net/ipv4/ip     0 ÇãÁ¤±Õ 10-05
 


Copyright (C) 2001 jog.co.kr All rights reserved.