<?xml version="1.0" encoding="utf-8" ?>

<rss version="2.0" 
   xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#"
   xmlns:admin="http://webns.net/mvcb/"
   xmlns:dc="http://purl.org/dc/elements/1.1/"
   xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
   xmlns:wfw="http://wellformedweb.org/CommentAPI/"
   xmlns:content="http://purl.org/rss/1.0/modules/content/"
   >
<channel>
    <title>SK Infosec MSS Team Daily Log</title>
    <link>http://mss.skinfosec.co.kr/weblog/</link>
    <description>MSS CIRT Blog</description>
    <dc:language>ko</dc:language>
    <generator>Serendipity 1.2-beta1 - http://www.s9y.org/</generator>
    <pubDate>Fri, 22 Jan 2010 04:05:53 GMT</pubDate>

    <image>
        <url>http://mss.skinfosec.co.kr/weblog/templates/default/img/s9y_banner_small.png</url>
        <title>RSS: SK Infosec MSS Team Daily Log - MSS CIRT Blog</title>
        <link>http://mss.skinfosec.co.kr/weblog/</link>
        <width>100</width>
        <height>21</height>
    </image>

<item>
    <title>가장 흔한 인터넷 비밀번호는 '123456'</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/46-123456.html</link>
            <category>Daily Log</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/46-123456.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=46</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=46</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    http://news.naver.com/main/hotissue/read.nhn?mid=hot&amp;sid1=105&amp;gid=321625&amp;cid=298842&amp;iid=189317&amp;oid=023&amp;aid=0002118234&amp;ptype=011&lt;br /&gt;
&lt;br /&gt;
의외로 사람들은 간단한 패스워드를 사용하는 경우가 많다.&lt;br /&gt;
심지어 기사의 내용과 같이 &#039;123456&#039; 라는 패스워드를 사용하는 사람들도 많이 존재한다.&lt;br /&gt;
이것은 인터넷이 발달한 현대사회에서 방대한 비밀번호의 목록은 기억하기 쉬운것으로 정하는 사람의 성향에서 나타난다. 터무니 없는 비밀번호는 기억하기 힘들기 때문에 모든 인터넷유저들은 &#039;도메인명1234&#039; , &#039;아이디1234&#039; , &#039;아이디생년월일&#039; 와 같은 비밀번호를 많이 선호하는 특성을 가지고 있는 것이다.&lt;br /&gt;
어떻게 보면 인간의 심리를 이용한 사회공학적 해킹 이라고 할 수도 있다. 이렇듯 완벽한 보안을 위해선 어느 한 부분에서 구멍이 발생해도 치명적인 영향력을 미칠수 있으므로 다각도의 시선으로 바라볼 필요성이 있다. 
    </content:encoded>

    <pubDate>Fri, 22 Jan 2010 12:46:15 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/46-guid.html</guid>
    
</item>
<item>
    <title>Iphone 웜바이러스</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/45-Iphone.html</link>
            <category>Daily Log</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/45-Iphone.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=45</wfw:comment>

    <slash:comments>9</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=45</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    손안의 컴퓨터라는 말이 무색할 만큼 요즘 Iphone의 인기와 그 성능은 대단합니다.&lt;br /&gt;
이제 점점 유비쿼터스의 시대가 느껴지는 것 같습니다.&lt;br /&gt;
미래에는 모든 사물에 IP가 부여될 것이고 지금부터 훨씬 더 편리한 생활이 찾아올 것입니다.&lt;br /&gt;
반면 보안의 대상범위도 훨씬 더 광범위해 질것 입니다. Iphone과 같은 기계의 출시가 그 첫걸음인것 같습니다.&lt;br /&gt;
이에 따라 앞으로 나타날 보안에 대한 구성도를 미리 그려 봐야할 것입니다.&lt;br /&gt;
 해외에서는 이미 Iphone관련 웜바이러스까지 발견되었다고 합니다. root 패스워드가 alpine(기본값)일 경우 해당 바이러스에 걸리는가 봅니다.&lt;br /&gt;
&lt;br /&gt;
관련 동영상 :&lt;br /&gt;
http://www.youtube.com/watch?v=RBINaCWgA58&amp;feature=player_embedded&lt;br /&gt;
 
    </content:encoded>

    <pubDate>Wed, 23 Dec 2009 10:55:39 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/45-guid.html</guid>
    
</item>
<item>
    <title>SWF파일의 태그와 AVM2의 취약점을 이용한 Flash Player 공격에 관한 분석</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/40-SWF-AVM2-Flash-Player.html</link>
            <category>Daily Log</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/40-SWF-AVM2-Flash-Player.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=40</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=40</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    &lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;5월 부터 이슈가 되어오던 Flash Player 관련 취약점 분석 보고서 입니다.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;&lt;/font&gt;&lt;/p&gt;&lt;p align=&quot;center&quot;&gt;&lt;a title=&quot;flash_player_with_AVM2_vulnerability_analysis.pdf&quot; href=&quot;http://mss.skinfosec.co.kr/weblog/uploads/DailyLog/flash_player_with_AVM2_vulnerability_analysis.pdf&quot; target=&quot;_blank&quot;&gt;&lt;font size=&quot;3&quot;&gt;&lt;strong&gt;flash_player_with_AVM2_vulnerability_analysis.pdf&lt;/strong&gt;&lt;/font&gt;&lt;/a&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt; 
    </content:encoded>

    <pubDate>Wed, 02 Jul 2008 09:43:57 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/40-guid.html</guid>
    
</item>
<item>
    <title>계속되는 SQL Injection 위협..</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/39-SQL-Injection-...html</link>
            <category>Daily Log</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/39-SQL-Injection-...html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=39</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=39</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    &lt;p&gt;올해 초부터 꾸준히 이어지고 있는 SQL Injection 공격은 그 빈도가 줄지 않고 더욱더 늘어만 가고 있는 것 같습니다. ASP / MSSQL을 통해 DB데이터에 iframe을 삽입하는 이번 공격은 대부분의 IP가 중국에서 발생하고 있는 것으로 파악되고 있습니다. 최근 몇일 사이에 국내에 유입되는 공격의 근원지를 조사해본 결과 주요 공격지 대역이 다음과 같이 집계되었습니다.&lt;/p&gt;&lt;p&gt;&lt;strong&gt;58.208.x.x ~ 58.223.x.x&lt;br /&gt;221.130.176.x ~ 221.130.207.x&lt;/strong&gt;&lt;/p&gt;&lt;p /&gt;&lt;p /&gt; 
    </content:encoded>

    <pubDate>Mon, 26 May 2008 11:12:38 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/39-guid.html</guid>
    
</item>
<item>
    <title>Anti-CNN hacker trophy</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/38-Anti-CNN-hacker-trophy.html</link>
            <category>Daily Log</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/38-Anti-CNN-hacker-trophy.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=38</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=38</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    &lt;p class=&quot;2-12pt&quot; style=&quot;TEXT-INDENT: 15pt&quot; align=&quot;left&quot;&gt;&lt;font size=&quot;2&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt;sports.si.cnn.com &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;이&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;해킹을&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;당했다&lt;/font&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt;. &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;내용인&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;즉슨&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;티벳에&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;대한&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;사이버&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;시위라는&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;것을&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;알&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;수&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;font face=&quot;돋움&quot;&gt;&lt;span style=&quot;COLOR: black&quot;&gt;있었다&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class=&quot;2-12pt&quot; style=&quot;TEXT-INDENT: 15pt&quot;&gt;&lt;font size=&quot;2&quot;&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;&lt;img height=&quot;402&quot; hspace=&quot;0&quot; src=&quot;http://mss.skinfosec.co.kr/weblog/uploads/DailyLog/1.jpg&quot; width=&quot;616&quot; align=&quot;baseline&quot; border=&quot;0&quot; /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class=&quot;2-12pt&quot; style=&quot;TEXT-INDENT: 15pt&quot; /&gt;&lt;p class=&quot;2-12pt&quot; style=&quot;TEXT-INDENT: 15pt&quot;&gt;&lt;font size=&quot;2&quot;&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;하지만&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;왜&lt;/font&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; CNN &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;이&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;타겟이&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;되었을까&lt;/font&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt;? &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;물론&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;대표&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;뉴스&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;사이트라&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;페이지&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;뷰&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;수가&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;엄청난&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;것을&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;노렸을&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;수도&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;있지만&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;이유는&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;다른데&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;있었다&lt;/font&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt;.&lt;/span&gt;&lt;/font&gt;&lt;font size=&quot;2&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt;CNN &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;은&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;계속해서&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;중국에&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;대한&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;부정적인&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;뉴스를&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;내보냈고&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;이에&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;분개한&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;해커들이&lt;/font&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; CNN &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;을&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;타겟으로&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;공격을&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;했던&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;것이다&lt;/font&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt;. &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;핵티비즘에&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;의한&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;공격이라고&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;할&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;수&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;있다&lt;/font&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class=&quot;2-12pt&quot; style=&quot;TEXT-INDENT: 15pt&quot; /&gt;&lt;p class=&quot;2-12pt&quot; style=&quot;TEXT-INDENT: 15pt&quot; align=&quot;left&quot;&gt;&lt;font size=&quot;2&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt;&lt;img hspace=&quot;0&quot; src=&quot;http://mss.skinfosec.co.kr/weblog/uploads/DailyLog/no_cnn.jpg&quot; align=&quot;baseline&quot; border=&quot;0&quot; /&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class=&quot;2-12pt&quot; style=&quot;TEXT-INDENT: 15pt&quot; /&gt;&lt;p class=&quot;2-12pt&quot; style=&quot;TEXT-INDENT: 15pt&quot;&gt;&lt;font size=&quot;2&quot;&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;또&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;중국&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;해커들은&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;span lang=&quot;EN-US&quot;&gt;anticnn.exe &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;라는&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;툴을&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;만들어&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;span lang=&quot;EN-US&quot;&gt;cnn &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;접속&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;시&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;접근이&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;불가능하게&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;브라우져를&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;조정하였다&lt;/font&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt;. &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;왼쪽의&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;작은&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;아이콘을&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;클릭하면&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;span lang=&quot;EN-US&quot;&gt;&lt;a href=&quot;http://www.cnn.com/&quot;&gt;&lt;span&gt;&lt;font face=&quot;돋움&quot;&gt;www.cnn.com&lt;/font&gt;&lt;/span&gt;&lt;/a&gt; &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;을&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;들어갈&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;수&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;가&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;없다&lt;/font&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt;.&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class=&quot;2-12pt&quot; style=&quot;TEXT-INDENT: 15pt&quot;&gt;&lt;font size=&quot;2&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt;&lt;/span&gt;&lt;/font&gt;&lt;/p&gt;&lt;p class=&quot;2-12pt&quot; style=&quot;TEXT-INDENT: 15pt&quot;&gt;&lt;font size=&quot;2&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt;&lt;img src=&quot;http://mss.skinfosec.co.kr/weblog/uploads/DailyLog/2.jpg&quot; /&gt;&lt;/span&gt;&lt;/font&gt;&lt;span lang=&quot;EN-US&quot;&gt;&lt;span&gt;&lt;font face=&quot;바탕&quot; color=&quot;#000000&quot; size=&quot;2&quot;&gt;                             &lt;img style=&quot;WIDTH: 170px; HEIGHT: 155px&quot; height=&quot;155&quot; hspace=&quot;0&quot; src=&quot;http://mss.skinfosec.co.kr/weblog/uploads/DailyLog/3.jpg&quot; width=&quot;170&quot; align=&quot;baseline&quot; border=&quot;0&quot; /&gt;&lt;/font&gt;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;&lt;p class=&quot;2-12pt&quot; style=&quot;TEXT-INDENT: 15pt&quot; /&gt;&lt;p class=&quot;2-12pt&quot; style=&quot;TEXT-INDENT: 15pt&quot;&gt;&lt;font size=&quot;2&quot;&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt;CNN.com &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;은&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;웹&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;변조&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;뿐&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;만&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;아니라&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;span lang=&quot;EN-US&quot;&gt;DDOS &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;공격도&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;들어왔던&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;것으로&lt;/font&gt;&lt;/span&gt;&lt;span style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt; &lt;/span&gt;&lt;span style=&quot;COLOR: black&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;밝혀졌다&lt;/font&gt;&lt;/span&gt;&lt;span lang=&quot;EN-US&quot; style=&quot;COLOR: black; FONT-FAMILY: Arial&quot;&gt;. &lt;/span&gt;&lt;/font&gt;&lt;font size=&quot;2&quot;&gt;&lt;font color=&quot;#000000&quot;&gt;&lt;font face=&quot;돋움&quot;&gt;또한 이번 사건을 돌이 켜 보건 데 그 당시 악명 높았던 &lt;span lang=&quot;EN-US&quot;&gt;POISONBOX &lt;/span&gt;의 귀환이라는 조심스런 예측도 하고 있다&lt;span lang=&quot;EN-US&quot;&gt;. &lt;/span&gt;이는 자칫 &lt;span lang=&quot;EN-US&quot;&gt;sino-us cyber war II (&lt;/span&gt;중미사이버 전쟁&lt;span lang=&quot;EN-US&quot;&gt;)&lt;/span&gt;으로 번져 나갈 조짐이 보이고 있는 것이다&lt;span lang=&quot;EN-US&quot;&gt;.&lt;/span&gt;&lt;/font&gt;&lt;/font&gt;&lt;/font&gt;&lt;/p&gt; 
    </content:encoded>

    <pubDate>Thu, 24 Apr 2008 11:44:20 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/38-guid.html</guid>
    
</item>
<item>
    <title>쉘코드의 대부분을 차지하는 Downloader Shellcode</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/37-Downloader-Shellcode.html</link>
            <category>Daily Log</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/37-Downloader-Shellcode.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=37</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=37</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    &lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;최근에 관제센타를 통해 수집한 악성코드 중 Qvod Player의 URL 프로퍼티 버퍼오버플로우 공격을 수행하는 코드를 수집하게 되었습니다. 실제 코드에서 주목해야 할 부분은 취약점 자체가 아닙니다. 바로 그 공격코드가 무엇을 하는가 라는 점이죠.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;최근에 수집되는 대부분의 버퍼오버플로우 쉘코드는 Downloader 입니다. 과거에 리버스컨넥션을 수행한다거나 시스템 제어권을 획득한다거나 하는 것이 아니죠. Downloader가 주를 이룬다는 것은 아래와 같이 분석해 볼 수 있습니다.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt; 1. 최신 취약점을 이용한 봇넷의 유지 및 봇 전파&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt; 2. 불특정 다수를 타겟으로 하는 Client 공격&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;즉, 최신 취약점을 이용해 수많은 좀비를 생성하거나 원하는 정보를 수집을 하는 것입니다. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;실제로 수집한 악성코드에 포함된 쉘코드를 분석해보면 국내 모 유명 게임회사의 온라인 계정을 탈취하는 프로그램을 원격지에서 다운로드하여 실행하는 코드로 확인이 되었고 발생지는 중국이였습니다.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;참고: &lt;/font&gt;&lt;br /&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;Qvod Player같은 경우는 국내에서는 거의 사용하지 않는 것으로 알고 있습니다. 이런 점을 미뤄봤을 때도 공격자는 일정한 타겟이 있다기 보다는 단순히 자신들의 전파 루틴에 최신 취약점을 추가한 것이라고 밖에 생각할 수 없습니다.&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;&lt;/font&gt;&lt;/p&gt; 
    </content:encoded>

    <pubDate>Wed, 05 Mar 2008 16:04:19 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/37-guid.html</guid>
    
</item>
<item>
    <title>china_bot malware analysis report</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/36-china_bot-malware-analysis-report.html</link>
            <category>Malicious Code</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/36-china_bot-malware-analysis-report.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=36</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=36</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    &lt;p&gt;china bot (가칭) malware 분석 보고서 입니다.&lt;/p&gt;&lt;p&gt;변형된 malware 들의 침입 과정을 분석하고 있습니다.&lt;/p&gt;&lt;p /&gt;&lt;p align=&quot;center&quot;&gt;&lt;a title=&quot;SKINFOSEC_TECH_005_china_bot malware analysis report&quot; href=&quot;http://mss.skinfosec.co.kr/docs/wp-content/uploads/2008/03/skinfosec_tech_005_china-bot_analysis_report.pdf&quot;&gt;&lt;font size=&quot;4&quot;&gt;china_bot malware analysis report&lt;/font&gt;&lt;/a&gt;&lt;/p&gt; 
    </content:encoded>

    <pubDate>Tue, 04 Mar 2008 14:10:55 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/36-guid.html</guid>
    
</item>
<item>
    <title>신년 맞이 Storm Worm에 대한 정적 분석</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/35-Storm-Worm.html</link>
            <category>Malicious Code</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/35-Storm-Worm.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=35</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=35</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    &lt;p&gt;무자년을 맞이해서 Storm Worm님께서 메일로 찾아와 주셨네요. 이번에 수집한 Storm Worm은 Happy_2008.exe라는 이름을 가지고 있습니다. 스톰 웜과 관련 된 많은 자료들이 이미 발표 된 시점이라 더 이상 새로울 것은 없지만 웜의 침입기술과 은폐 및 전파 기술을 눈으로 확인 할 수 있는 좋은 웜입니다. &lt;/p&gt;&lt;p&gt;&lt;font color=&quot;#000000&quot;&gt;&lt;/font&gt;&lt;/p&gt;&lt;p align=&quot;center&quot;&gt;&lt;font color=&quot;#000000&quot; size=&quot;3&quot;&gt;&lt;strong&gt;&lt;a title=&quot;happy_2008_storm-worm_analysis&quot; href=&quot;http://mss.skinfosec.co.kr/docs/wp-content/uploads/2008/01/skinfosec_tech_004_happy_2008_storm-worm_analysis.pdf&quot; target=&quot;_blank&quot;&gt;happy_2008_storm-worm_analysis&lt;/a&gt;&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p /&gt; 
    </content:encoded>

    <pubDate>Thu, 31 Jan 2008 09:35:38 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/35-guid.html</guid>
    
</item>
<item>
    <title>Malware analysis</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/33-Malware-analysis.html</link>
            <category>Malicious Code</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/33-Malware-analysis.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=33</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=33</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    &lt;p&gt;hXXp://lovekr.XXX.com/dd.htm&lt;/p&gt;&lt;p&gt;lovekr? 심상치 않다. 우리나라만 노리고 있는 전문가의 냄새가....&lt;/p&gt;&lt;p&gt;열어보니..&lt;/p&gt;&lt;p /&gt;&lt;p&gt;&lt;img style=&quot;WIDTH: 678px; HEIGHT: 776px&quot; height=&quot;776&quot; hspace=&quot;0&quot; src=&quot;http://mss.skinfosec.co.kr/weblog/uploads/MaliciousCode/mss_1.jpg&quot; width=&quot;678&quot; align=&quot;baseline&quot; border=&quot;0&quot; /&gt;&lt;/p&gt;&lt;p /&gt;&lt;p&gt;변경하여 보니 ~ &lt;/p&gt;&lt;p&gt;&lt;img hspace=&quot;0&quot; src=&quot;http://mss.skinfosec.co.kr/weblog/uploads/MaliciousCode/mss.jpg&quot; align=&quot;baseline&quot; border=&quot;0&quot; /&gt;&lt;/p&gt; 
    </content:encoded>

    <pubDate>Thu, 24 Jan 2008 15:23:30 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/33-guid.html</guid>
    
</item>
<item>
    <title>형변환 함수 CAST</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/32-CAST.html</link>
            <category>Malicious Code</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/32-CAST.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=32</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=32</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    &lt;p&gt;아래와 같은 침해 로그가 남았을때&lt;/p&gt;&lt;p&gt;&lt;img hspace=&quot;0&quot; src=&quot;http://mss.skinfosec.co.kr/weblog/uploads/MaliciousCode/mss3.jpg&quot; align=&quot;baseline&quot; border=&quot;0&quot; /&gt;&lt;/p&gt;&lt;p /&gt;&lt;p&gt;위의 형태는 헥사값 형태로 변환이 되어있는것을 알수 있다.&lt;/p&gt;&lt;p&gt;00 값을 지우고 정리하면&lt;/p&gt;&lt;p&gt;6465636C61726520406D20766172636861722838303030293B73657420406D3D27273B73656C65637420406D3D406D2B277570646174655B272B612E6&lt;/p&gt;&lt;p&gt;.....................&lt;/p&gt;&lt;p /&gt;&lt;p /&gt;&lt;p&gt;이부분만 남았고 ascii 형태로 변경해보자~&lt;/p&gt;&lt;p&gt;&lt;img hspace=&quot;0&quot; src=&quot;http://mss.skinfosec.co.kr/weblog/uploads/33.jpg&quot; align=&quot;baseline&quot; border=&quot;0&quot; /&gt;&lt;/p&gt;&lt;p /&gt;&lt;p /&gt;&lt;p&gt;변경된 형태다.&lt;/p&gt;&lt;p /&gt;&lt;p /&gt;&lt;p&gt;&lt;img hspace=&quot;0&quot; src=&quot;http://mss.skinfosec.co.kr/weblog/uploads/MaliciousCode/mss4.jpg&quot; align=&quot;baseline&quot; border=&quot;0&quot; /&gt;&lt;/p&gt; 
    </content:encoded>

    <pubDate>Wed, 12 Dec 2007 17:43:48 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/32-guid.html</guid>
    
</item>
<item>
    <title>GOMClean.exe BHOClean.exe 스파이웨어</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/30-GOMClean.exe-BHOClean.exe.html</link>
            <category>Daily Log</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/30-GOMClean.exe-BHOClean.exe.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=30</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=30</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    &lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;오늘 스파이웨어 관련 침해위협이 많이 발생하고 있습니다. &lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;침해위협발생보고서에서 샘플링 된 3개의 파일을 분석한 결과 sdaemon.exe의 경우 unpack 시 파일에서 crash가 발생하여 정상적으로 동작을 하지 않습니다. 따라서 실제 환경에서도 동작하지 않을 것으로 판단 됩니다.&lt;br /&gt;&lt;br /&gt;나머지 두개인&lt;/font&gt;&lt;/p&gt;&lt;p&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;&lt;strong&gt;adobeX.exe&lt;br /&gt;bhoinst.exe&lt;/strong&gt;&lt;/font&gt;&lt;/p&gt;&lt;p&gt;의 경우 이름은 다르지만 동일한 동작을 합니다.COMClean 또는 BHOClean이라고 불리며 스파이웨어의 일종입니다. 이것을 실행하였을 때&lt;/font /&gt;&lt;/p&gt;&lt;p&gt;&lt;strong&gt;C:\WINDOWS\GRETECH\GomPlayer\&lt;/strong&gt; &lt;br /&gt;폴더에 스파이웨어를 설치하며 아래의 레지스트리를 수정합니다. &lt;/p&gt;&lt;p&gt;&lt;strong&gt;&amp;quot;HKCU\Software\Microsoft\Windows\CurrentVersion\Run&amp;quot;&lt;/strong&gt; 에 &lt;br /&gt;&lt;strong&gt;&amp;quot;gomclean&amp;quot;=&amp;quot;&amp;quot;GRETECH\GomPlayer\GOMClean.exe&amp;quot;&amp;quot;&lt;/strong&gt;&lt;br /&gt;을 등록합니다. 즉 윈도우즈 시작 시 마다 실행되도록 등록이 됩니다.&lt;/p&gt;&lt;p /&gt;&lt;p&gt;&lt;img style=&quot;BORDER-RIGHT: 0px; PADDING-RIGHT: 5px; BORDER-TOP: 0px; PADDING-LEFT: 5px; BORDER-LEFT: 0px; WIDTH: 682px; BORDER-BOTTOM: 0px; HEIGHT: 175px&quot; height=&quot;175&quot; src=&quot;http://mss.skinfosec.co.kr/weblog/uploads/gomclean1.jpg&quot; width=&quot;682&quot; /&gt; &lt;/p&gt;&lt;p&gt; 스파이웨어가 실행되면 특정 서버로 접속을 하여 스스로를 업데이트합니다. 디스어셈블 코드를 통해 &lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://www.2080815.com/bhoclean.php?VER=20071019&amp;MAC=&amp;ID&quot;&gt;http://www.2080815.com/bhoclean.php?VER=20071019&amp;amp;MAC=&amp;amp;ID&lt;/a&gt;=&lt;/p&gt;&lt;p&gt;라는 주소를 추출할 수 있습니다. 즉, 스파이웨어는 해당 경로를 통해 업데이트를 합니다.&lt;/p&gt;&lt;p&gt;내부적으로 PCFreeMon이라는 안티 스파이웨어 프로그램을 모체로 하고 있는 것 같습니다. &lt;/p&gt;&lt;p /&gt; 
    </content:encoded>

    <pubDate>Tue, 30 Oct 2007 12:53:42 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/30-guid.html</guid>
    
</item>
<item>
    <title>오라클 shell</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/29-shell.html</link>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/29-shell.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=29</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=29</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    &lt;p /&gt;&lt;p align=&quot;left&quot;&gt;자바 프로시져를 이용한 오라클에 쉘 띄우기&lt;/p&gt;&lt;p /&gt;&lt;p align=&quot;center&quot;&gt;&lt;embed pluginspage=&quot;http://www.macromedia.com/go/getflashplayer&quot; src=&quot;http://dory.mncast.com/mncHMovie.swf?movieID=10048903120071015140703&amp;skinNum=1&quot; width=&quot;520&quot; height=&quot;449&quot; type=&quot;application/x-shockwave-flash&quot; /&gt;&lt;/embed /&gt; &lt;/p&gt; 
    </content:encoded>

    <pubDate>Mon, 15 Oct 2007 14:19:34 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/29-guid.html</guid>
    
</item>
<item>
    <title>hackers@microsoft</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/28-hackersmicrosoft.html</link>
            <category>Daily Log</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/28-hackersmicrosoft.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=28</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=28</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    &lt;p&gt;&lt;a href=&quot;http://blogs.msdn.com/hackers/&quot;&gt;http://blogs.msdn.com/hackers/&lt;/a&gt;&lt;/p&gt;&lt;p&gt;공식적인 해커 블로그 라고 마이크로 소프트에서 발표를 했네요&lt;/p&gt;&lt;p&gt;마이크로 소프트가 고용한 해커들이라 어떤 내용들이 포스팅이 될까 사뭇 궁금하네요&lt;/p&gt;&lt;p&gt;&lt;img height=&quot;728&quot; hspace=&quot;0&quot; src=&quot;http://mss.skinfosec.co.kr/weblog/uploads/DailyLog/microsoft.bmp&quot; width=&quot;632&quot; align=&quot;baseline&quot; border=&quot;0&quot; /&gt; . &lt;/p&gt;&lt;p /&gt; &lt;br /&gt;&lt;a href=&quot;http://mss.skinfosec.co.kr/weblog/index.php?/archives/28-hackersmicrosoft.html#extended&quot;&gt;&quot;hackers@microsoft&quot; 계속 읽기&lt;/a&gt;
    </content:encoded>

    <pubDate>Thu, 30 Aug 2007 15:10:13 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/28-guid.html</guid>
    
</item>
<item>
    <title>port 5168 port 스캔</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/27-port-5168-port.html</link>
            <category>Daily Log</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/27-port-5168-port.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=27</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=27</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    &lt;p align=&quot;justify&quot;&gt;최근에 iDefense에서 Trend Micro의 제품인 ServerProtect에 대한 취약점 발표를 한 후 해당 소프트웨어와 관련된 RPC 포트인 5168에 대한 스캔이 증가하고 있습니다. 이미 해외의 유수 기관이나 기업의 관제망이나 허니팟 시스템에서 이와 관련된 흔적이 발표되고 있습니다.&lt;/p&gt;&lt;p /&gt;&lt;p align=&quot;center&quot;&gt;&lt;img style=&quot;BORDER-RIGHT: 0px; PADDING-RIGHT: 5px; BORDER-TOP: 0px; PADDING-LEFT: 5px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px&quot; height=&quot;242&quot; src=&quot;http://mss.skinfosec.co.kr/weblog/uploads/DailyLog/port5168.jpg&quot; width=&quot;617&quot; /&gt;&lt;/p&gt;&lt;p /&gt;&lt;p&gt;저희 회사에서 관제를 하고 있는 한 IDC에서 23일에 발생한 IDS기록을 보면 5168포트에 대한 스캔 기록이 발생하고 있음을 알 수 있습니다. 아직 실질적인 피해사례나 공격코드가 발표되지 않은 상태지만 유심히 관찰해 봐야 할 부분인 것 같습니다.&lt;/p&gt;&lt;p /&gt;&lt;p&gt;관련 자료:&lt;/p&gt;&lt;p&gt;iDefense&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=587&quot;&gt;http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=587&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=588&quot;&gt;http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=588&lt;/a&gt;&lt;/p&gt;&lt;p /&gt;&lt;p&gt;SANS Internet Storm Center&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://isc.sans.org/diary.html?storyid=3306&quot;&gt;http://isc.sans.org/diary.html?storyid=3306&lt;/a&gt;&lt;/p&gt;&lt;p&gt;&lt;a href=&quot;http://isc.sans.org/diary.html?storyid=3309&quot;&gt;http://isc.sans.org/diary.html?storyid=3309&lt;/a&gt;&lt;/p&gt;&lt;p /&gt;&lt;p /&gt;&lt;p /&gt;&lt;p /&gt; 
    </content:encoded>

    <pubDate>Mon, 27 Aug 2007 14:54:44 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/27-guid.html</guid>
    
</item>
<item>
    <title>Phishing Scam</title>
    <link>http://mss.skinfosec.co.kr/weblog/index.php?/archives/26-Phishing-Scam.html</link>
            <category>Daily Log</category>
    
    <comments>http://mss.skinfosec.co.kr/weblog/index.php?/archives/26-Phishing-Scam.html#comments</comments>
    <wfw:comment>http://mss.skinfosec.co.kr/weblog/wfwcomment.php?cid=26</wfw:comment>

    <slash:comments>0</slash:comments>
    <wfw:commentRss>http://mss.skinfosec.co.kr/weblog/rss.php?version=2.0&amp;type=comments&amp;cid=26</wfw:commentRss>
    

    <author>nospam@example.com (weblog)</author>
    <content:encoded>
    &lt;p align=&quot;justify&quot;&gt;&lt;font style=&quot;BACKGROUND-COLOR: #faffff&quot;&gt;요 몇일 사이에 다양한 주제에 관한 피싱메일을 받았습니다. 발신자와 내용은 다 다르나 공통적으로 가지고 있는 링크 주소가 있는데 다음과 같습니다.&lt;/font&gt;&lt;/p&gt;&lt;p align=&quot;justify&quot; /&gt;&lt;p&gt;&lt;a href=&quot;http://xxx.xxx.xxx.xxx/&quot;&gt;http://xxx.xxx.xxx.xxx/&lt;/a&gt;&lt;/p&gt;&lt;p /&gt;&lt;p&gt;링크를 따라가 보면 Secure Login Applet을 다운로드 받으라는 메시지와 함께 다운로드 링크가 존재합니다. 이 링크를 따라가면 applet.exe라는 실행파일을 받을 수 있죠.&lt;/p&gt;&lt;p&gt;이 파일을 norman sandbox를 이용하여 확인해 본 결과는 다음과 같았습니다.&lt;/p&gt;&lt;p /&gt;&lt;pre&gt;applet.exe : Not detected by Sandbox (Signature: NO_VIRUS)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
 [ DetectionInfo ]&lt;br /&gt;
    &lt;strong&gt; Sandbox name: NO_MALWARE&lt;br /&gt;
    &lt;/strong&gt; Signature name: NO_VIRUS&lt;br /&gt;
&lt;br /&gt;
 [ General information ]&lt;br /&gt;
    &lt;strong&gt; File length:       114543 bytes.&lt;br /&gt;
    &lt;/strong&gt; MD5 hash: f362efe5690f2ac36add3f8a4601a132.&lt;br /&gt;
&lt;/pre&gt;&lt;p /&gt;&lt;p&gt;특별한 것을 찾지 못하네요. 하지만 virustotal을 이용해서 확인해보면 이 실행파일이 Zhelatin 계열임을 알 수 있습니다. &lt;/p&gt;&lt;p /&gt;&lt;p align=&quot;center&quot;&gt;&lt;img style=&quot;BORDER-RIGHT: 0px; PADDING-RIGHT: 5px; BORDER-TOP: 0px; PADDING-LEFT: 5px; BORDER-LEFT: 0px; BORDER-BOTTOM: 0px&quot; height=&quot;727&quot; src=&quot;http://mss.skinfosec.co.kr/weblog/uploads/DailyLog/virustotal.jpg&quot; width=&quot;571&quot; /&gt;&lt;/p&gt;&lt;p&gt; &lt;/p&gt;&lt;p&gt; &lt;/p&gt; 
    </content:encoded>

    <pubDate>Wed, 22 Aug 2007 10:20:43 +0900</pubDate>
    <guid isPermaLink="false">http://mss.skinfosec.co.kr/weblog/index.php?/archives/26-guid.html</guid>
    
</item>

</channel>
</rss>
