1581, 1/80 ȸ¿ø°¡ÀÔ  ·Î±×ÀΠ 
   dkdkfjgh
   MS05-027 Ãë¾àÁ¡À» ÀÌ¿ëÇÑ °ø°ÝÀÌ °¡Àå ¸¹Àº °ÍÀ¸·Î Áý°èµÆ´Ù°í ¹ßÇ¥Çß´Ù.

http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=1146 [º¹»ç]


¾Èö¼ö¿¬±¸¼Ò°¡ ¹ßÇàÇÏ´Â ASEC ¸®Æ÷Æ® ÃÖ½ÅÈ£¿¡ µû¸£¸é Áö³­ 8¿ù ÇÑ´Þ µ¿¾È ÀÚ»ç ³×Æ®¿öÅ© ¸ð´ÏÅ͸µ ½Ã½ºÅÛÀ¸·Î ŽÁöµÈ °ø°ÝÀ» ºÐ¼®ÇÑ °á°ú, MS05-027 Ãë¾àÁ¡À» ÀÌ¿ëÇÑ °ø°ÝÀÌ °¡Àå ¸¹Àº °ÍÀ¸·Î Áý°èµÆ´Ù°í ¹ßÇ¥Çß´Ù.

ÀÌ Ãë¾àÁ¡Àº ¼­¹ö ¸Þ½ÃÁö ºí·ÏÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇØ ¿ø°Ý Äڵ带 ½ÇÇàÇÒ ¼ö ÀÖ´Â °ÍÀ¸·Î ÀÌ¹Ì Áö³­ 2005³â 6¿ù ÆÐÄ¡°¡ Á¦°øµÈ °ÍÀÌ´Ù.




2À§¿¡´Â S03-039 Microsoft SQL ¼­¹ö Ãë¾àÁ¡, 3À§¿¡´Â µ¥ÀÌÅͺ£À̽ºÀÇ °ü¸®ÀÚ ±ÇÇÑÀ» ¾ò¾î³»±â À§ÇÑ Æнº¿öµå ´ëÀÔÀ» ½ÃµµÇÏ´Â MS-SQL SA brute force login attempt°¡ Â÷ÁöÇß´Ù. À̾î, »õ¼­(Sssser) ¿ú ÀüÆÄ¿¡ ÀÌ¿ëµÇ´Â MS04-11 LSASS(·ÎÄà º¸¾È ±ÇÇÑ ÇÏÀ§ ½Ã½ºÅÛ ¼­ºñ½º) Ãë¾àÁ¡°ú RPC ÀÎÅÍÆäÀ̽ºÀÇ ¹öÆÛ ¿À¹ö·±À¸·Î ÀÎÇÑ ÄÚµå ½ÇÇà ¹®Á¦¸¦ ¾ß±â½ÃÅ°´Â MS03-026 Buffer Overrun RPC Interface Ãë¾àÁ¡ÀÌ °¢°¢ 4, 5À§·Î µÚ¸¦ À̾ú´Ù.

ÁÖ¸ñÇØ¾ß ÇÒ Á¡Àº ÀÌµé »óÀ§ 5°³ÀÇ °ø°Ý Ãë¾àÁ¡ ¸ðµÎ °ø°³µÈ Áö 3³â ÀÌ»óÀÌ Áö³µ´Ù´Â °ÍÀÌ´Ù. ÀÌ´Â ¿©ÀüÈ÷ ÆÐÄ¡°¡ Àû¿ëµÇÁö ¾ÊÀº ½Ã½ºÅÛÀÌ ¸¹´Ù´Â °ÍÀ» ÀǹÌÇϸç, ÀÌ¿Í °°Àº °ø°Ý À§ÇùÀ» ¹æ¾îÇϱâ À§Çؼ­´Â ¹Ýµå½Ã ÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ ÆÐÄ¡¸¦ Àû¿ëÇØ¾ß ÇÑ´Ù.

À̹ۿ¡ °ø°Ý ¹ß»ýÁöº° ±¹°¡ÇöȲÀ» »ìÆ캸¸é, Àü¼¼°è º¸¾È °ø°ÝÀÇ 48%°¡ ¿ì¸®³ª¶ó¿¡¼­ ¹ß»ýÇÑ °ÍÀ¸·Î Á¶»çµÆ´Ù. ¹Ì±¹Àº 17%·Î 2À§, ÀϺ»ÀÌ 13%·Î 3À§¸¦ Â÷ÁöÇß´Ù. ÀÌ °°Àº °á°ú´Â ¿ì¸®³ª¶ó°¡ ¸¹Àº °ø°ÝÀ» ¹Þ°í ÀÌ·Î ÀÎÇØ ¾Ç¼ºÄڵ忡 °¨¿°µÇ¸é¼­ ´Ù½Ã °ø°ÝÀ» ½ÃµµÇÑ µ¥ µû¸¥ °ÍÀ¸·Î ÃßÁ¤µÈ´Ù.

¢ºÇØ´ç Ãë¾àÁ¡¿¡ ´ëÇÑ MS º¸¾È ÆÐÄ¡ ´Ù¿î·Îµå »çÀÌÆ®

http://www.microsoft.com/korea/technet/security/bulletin/MS05-027.mspx
http://www.microsoft.com/korea/technet/security/bulletin/MS03-039.mspx
http://www.microsoft.com/technet/security/bulletin/MS04-011.mspx
http://www.microsoft.com/korea/technet/security/bulletin/MS03-026.mspx


°ü·Ã±Û Àü¹®º¸±â:¾Èö¼ö¿¬±¸¼Ò ASEC Report 2008³â 8¿ùÈ£


  Hit : 6995     Date : 2008/12/16 05:46



    
     [°øÁö] °­Á¸¦ ¿Ã¸®½Ç ¶§´Â ¸»¸Ó¸®¸¦ ´Þ¾ÆÁÖ¼¼¿ä^¤Ñ^ [29] ¸Û¸Û 02/27 18809
1580   °í¼ö´ÔµéÀÇ µµ¿òÀ» ¹Þ°í ½Í½À´Ï´Ù     vbnm111
02/11 276
1579   ¸®´ª½º Ä¿³Î 2.6 ¹öÀü ÀÌÈÄÀÇ LKM     jdo
07/25 774
1578   ½©ÄÚµå ¸ðÀ½     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/15 1603
1577   Call by value VS Call by Reference     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/15 973
1576   (²Ä¼ö) L.O.B Çѹ濡 Ŭ¸®¾îÇϱâ[2]     ÇØÅ·ÀßÇÏ°í½Í´Ù
01/14 1323
1575   towelroot.c (zip) ÄÚ¸àÆÃ.[1]     scube
08/18 3844
1574   levitator.c (¾Èµå·ÎÀÌµå ·çÆÃ) °ø°Ý ºÐ¼® ¼Ò½º ÄÚµå °øÀ¯.[4]     scube
08/17 3743
1573   ¹«·á Á¤º¸º¸¾È ±â¼úÀÎÀç ¾ç¼º °úÁ¤ ±³À°»ý ¸ðÁý     chanjung111
06/17 4556
1572   K-Shield ÁִϾî 5±â ¸ðÁý     lrtk
06/17 4279
1571   [ÆÁ] ÆÄÀ̽ã 2¼Ò½º¸¦ 3À¸·Î º¯°æÇØÁÖ´Â »çÀÌÆ®[3]     ÇѽÂÀç
05/13 3979
1570   ±¸±Û ¹é¸µÅ© ÀÛ¾÷ Áú¹®¿ä     wkatnxka
03/30 3411
1569   [ÆÁ] ¿ìºÐÅõ ¹Ì·¯¸µ¼­¹ö     ÇѽÂÀç
03/09 4111
1568 ºñ¹Ð±ÛÀÔ´Ï´Ù  °¨À»¸øÀâ°Ú³×¿ä¤Ì¤Ì     À×À×À×
01/15 3
1567   µ¥ºñ¾È °è¿­ ¸®´ª½º ÀÇÁ¸¼º ±úÁ³À»¶§ ÇØ°á¹ý     ÇѽÂÀç
11/27 4602
1566   È«º¸ÇÕ´Ï´Ù. ½Å»ý º¸¾ÈÄ¿¹Â´ÏƼÀÔ´Ï´Ù.     kimwoojin0952
10/26 4321
1565   ½Å±âÇÑ ÇÁ·Î±×·¡¹Ö ¾ð¾î[3]     koreal33t
09/06 4714
1564   À©µµ¿ì,¸®´ª½º¿¡¼­ ³» ip¸¦ È®ÀÎÇØ º¸ÀÚ [1]     koreal33t
09/06 3917
1563   CTF »çÀÌÆ®[1]     koreal33t
09/06 4577
1562   ÀÚ°ÝÁõ (¹®Á¦)»çÀÌÆ® [2]     koreal33t
09/06 4391
1 [2][3][4][5][6][7][8][9][10]..[80]

Copyright 1999-2024 Zeroboard / skin by Hackerschool.org / Secure Patch by Hackerschool.org