U E D R , A S I H C RSS

Zero Page Server/About Cracking

Server Cracking ๊€ จ ๊ธฐก. ฃผกœ ‹•œ „œฒ„ ๊€ฆฌž NeoCoin — ˜•œ ง„‹ค˜ ๊ณ ฐฑ ;;
----

1. 2002 …„ ค‘ฐ˜  œ๊ธฐœ •œ Šธž˜”ฝ Cracknig ๊€ จ ๊ณ 

(•‹น ๊ธฐก„  •™••˜๊ฒŒ ‚จ๊ธฐ€ •Š•„, ‹œ๊ฐ„ˆœ ๊ธฐ–ต Œ€กœ ๊ธฐˆ )
  1. ZeroPageServer/set2002_815 กœ„œ debian ๊ณ„—˜ ™˜๊ฒฝ„กœ ZeroPageServer „ธŒ…
  2. ฌธ œ  œ๊ธฐ : •œ‹ฌ›„—  „‚ฐ„ผ„ฐ->šฉฒ  กœ •ˆ ๊ถŒ๊ณ  ip block
  3.  „‚ฐ„ผ„ฐ ฐพ•„๊ฐ€ ™•ธ ipblock ’€๊ณ ,  ๊ฒ€
    • ฆƒ : ZeroPageServer —„œ •œ ฐ„ฐ๊ฐ€ random ip กœ  „†ก. ๊ฐ‹œ ™•ˆ ˆ˜ฒœ packet ƒ †ต๊ณ„ ™•ธ
      • ‰†Œ 16~30% ˜  „‚ฐ„ผ„ฐ ๊ฒŒŠธ ›จ ž› 99% ๊นŒ€ ˜ฌฆฌŠ” ๊ณต—Œ. •™๊ต—„œ ™€ œผกœ๊ฐ€Š” „คŠธ› งˆน„
    •  ๊ฒ€ : ƒ ๊ณ„ • ฐพ๊ธฐ, „คŠธ› ™•ธ, security update

  4. ‹คŒ‚  NeoCoin ˜ ๊ณ„ •—„œ (root ง๊ณ ) •œ Šธž˜”ฝ ฐœƒ ”„กœ๊ทธžจ ฐœ๊ฒฌ
  5. ถ„„ : „ธŒ… ๊ณผ •—„œ „คน˜ฅผ œ„•œ wu-ftp Œจ‚ค€ „œน„Šคฅผ •œ‹ฌ๊ฐ„  œ๊ณต•˜˜€Š”ฐ, „คน˜ ฌธ œกœ ๊ฐ€žฅ žฃผ ‚ฌšฉ•  NeoCoin  ๊ฑธ ค “ ๊ฒƒ ๊ฐ™Œ
  6. •๊ฒฐ : •‹น ”„กœ๊ทธžจ ๊ฐˆฆฌ, NeoCoin ˜ •”˜ธ €๊ฒฝ, wu-ftp „œน„Šค  œ๊ฑฐ. ๊ทธ ›„ ฌธ œ ƒ™‚ฌผง
  7. ฐฐš , •Œ๊ฒŒœ 
    • ๊ต‚˜ ฆฌˆ…Šค, †”ผฆฌŠค „œฒ„ƒ— ฌž˜‚น น„ผน„žฌ •˜‹คŠ” 
    •  „‚ฐ„ผ„ฐ ถ„“ค นœ ˆ•˜‹คŠ”  ๊ณผ, ถˆ–‰žˆ •ˆ— €‹ €กฑ•˜—ฌ ‚ฌ‹คงŒ„ •Œ คฃผ‹คˆ˜ žˆ‹คŠ”  
    • cracking •œ ‚ฌžŒ, „œฒ„ƒ˜ NeoCoin ˜ dataฅผ €š๊ฒƒ •„‹ˆผ„œ, ‹ค–‰ •˜€งŒ —ญ‹œ ถˆ•ˆ.
    • web analizer ฅผ „คน˜•œ ๊ณ„๊ธฐ๊ฐ€ ˜—ˆ‹ค. ( http://zeropage.org/log ) žฌฏธžˆŒ

2. 2002 …„ ง€„ฐ 2003 …„ ˆ  œ๊ธฐœ ŠคŒธ ฉ”ผ ฐœ†ก Cracking ๊€ จ ๊ณ 

2.1. 1ฐจ  œ๊ธฐ, Œ€‘

  • 2002-12-22 ž„๊ตฌ๊ทผ(๊ตฌ๊ทผ 98) žœ ๊ฒŒ‹œŒ Spam ฉ”ผ rely ๊ณ .
    • 2002-12-17 ๊ถŒ๊ณ ฉ”ผ
    • Œ€‘: mail ๊€ จ „œน„Šค port ง‰๊ณ , smtp „œฒ„ —†Š” ๊ฒƒ ™•ธ
  • 2003-12 ง :  „‚ฐ„ผ„ฐ ธก—„œ ip block
  • 2003-01-06 :  „‚ฐ„ผ„ฐ— ฌธ˜•˜—ฌ ip ’€๊ณ , „œฒ„  ๊ฒ€,  •™••œ ฌธ œŠ” ฐพ€ •จ.
    • Œ€‘ : „œฒ„ฅผ rebooting ›„—Š” ฌธ œ๊ฐ€ Šนณ„žˆ ฐœƒ˜€ •ŠŒ

2.2. 2ฐจ  œ๊ธฐ Œ€‘

  • 2003-02-10 : KISA ->  „‚ฐ„ผ„ฐ -> šฉฒ  ->  •ฌก(nautes) ๊ฒฝกœกœ, ฌธ œ  œ๊ธฐ Server shutdown
  • 2003-02-13~15 : ฌธ œ ถ„„, † ก 
    • ZeroPageServer on
    • mail ๊€ จ app „œน„Šค ๊€ จ ง‰๊ธฐ ( ๊ธฐƒ€ app ˜ mail port )
    • 2003-02-08, 09 ฆˆŒ— squid ฅผ šฉ•œ proxy „œน„Šคฅผ  œ๊ณต–ˆ‹คŠ” ๊ฒƒ„ ๊ธฐ–ต. spam ƒ˜”Œ ‡†ตค‘ •‹ค suqid ‚ฌšฉ ๊ณ„ • id๊ฐ€ žˆ—ˆ‹คŠ”   ๊ธฐ–ต -> squid ™ž‘ ›„ spam‹ ๊ณ   ‘ˆ˜ œ ๊ฒƒœผกœ ๊ฐ€ •
      • •‹น ”„กœ๊ทธžจ …ŒŠคŠธ. ฌธ œ ƒ™„กœ Š” ƒƒœ ฐœ๊ฒฌ
      • ฆƒ : ๊ฐœธ ๊ฐœ •— ๊ธฐณธ „ค •˜ „คน˜œ squid 2.4 stable tar ˜ proxy „œน„Šคฅผ ตœˆกœ ‚ฌšฉ•œ ›„ –ผงˆ €‚˜€ •Š•„, •Œˆ˜ —†Š” ฉ”ผ „œฒ„กœ(port 25) ฐ„ฐ๊ฐ€ ‚ •„๊ฐ€Š” mail rely ฆƒ ž„
        • squid ˜ ๊ธฐณธ port ฅผ ฐ”๊พธ Ÿฌ•œ ฆƒ —†– กŒŒ
      • 1002๊ฐ€ squid ๊€ จ ฌธ œกœ ฌธ„œ ฐœ๊ฒฌ. ๊ทธ ™•ˆ Server˜ น„๊ต  žฆ€ rebooting •Œฌธ— ฌธ œ๊ฐ€ “œŸฌ‚˜€ •Š•˜Œ.
  • 2003-02-15~ : squid กœ ๊ฒฐก , ฌธ„œ  •ฆฌ ›„ ๊ฐ‹œ

  • ฐฐš 
    • ŠคŠธ ˆŠค ฐ›€ งž
    • netstat งŒœผกœ„ “ธžˆ๊ฒŒ ฐพ„ ˆ˜ žˆŒ
    • ƒˆกœš ”„กœ๊ทธžจ „คน˜ ›„ ผŠ” ‹œ „ ˜‹ฌ• ž. ๊ฐ€žฅ ๊ธฐณธ ธ „ธŒ…— stable ตœ‹  ฒ„ „ ˜ค”ˆ †ŒŠคผ„ ง‹ค.
    • ๊ฐœธ ฐจ›—„œ˜ ๊€ฆฌž๊ฐ€ Š” €† ธ „œน„Šค˜ œ„—˜„ฑ. งŒ•ฝ, squid ฅผ ž‹ค,  ฌธ œŠ” ‹ค‹œ •œ‘‹ฌ ๊ฐ”„ ๊ฒƒ ๊ฐ™‹ค.
    • „›€ ฃผ‹  ™ฌ”จ „ฒœ(1002), ‹ ๊ฒฝจฃผ‹  šฉฒ  ˜•˜ ๊ฐ‚ฌ “œฆฝ‹ˆ‹ค. --NeoCoin

  • 3. Thread

    4. 2003. 2. 13 …ŒŠคŠธ ›„

    • ฌธ œ : „œฒ„ฅผ ๊ฐ€™•˜๊ณ  ‚˜„œ –ผงˆ ›„— spam ฉ”ผ €† œผกœ ฐœ†กœ‹ค.
      • ˜‹ฌ ˜Š” €ถ„:
        • šŒ› ๊ณ„ •˜ squid ฅผ “คˆ˜ žˆ‹ค. netstat กœ ƒƒœฅผ ‚”ผ, ๊ธฐณธ squid „ธŒ…œผกœ proxy ฅผ šฉ•˜, ƒŒ€˜ smtp portธ 25 ฒˆœผกœ ๊ณ„† ญ๊ฐ€ ฐœ†ก˜—ˆ‹ค. ๊ธฐณธ „ธŒ… €๊ฒฝ›„— ๊ทธ ฐœ†ก˜Š” ƒƒœ๊ฐ€ —†—ˆ‹ค. •˜€งŒ, squid กœ  ‡๊ฒŒ œ‹คŠ” ๊ฒƒ ๊ณ œ ‚ฌ€ฅผ ฐพ€ –ˆ๊ณ , stable ฒ„ „ ž— ๊ทธŸฐ ๊ธฐŠฅ ˆจ– žˆ‹คŠ” ๊ฒƒ€ ƒ๊ฐ•˜๊ธฐ – ต‹ค.
          †ต squidฅผ †ต•œ ŠคŒธ ˆŠ” Šค€“œ 8080 ฌŠธฅผ †ต•„œ •„”ผงŒ ฐ”€Œ๊ณ  ‚Š”๊ฑ ‹คฅธ „œฒ„—„œ ‚Š”ฐ, ง ‘ 25ฒˆ ‚˜๊ฐ„‹คŠ”๊ฑ ฐธ ƒ•˜๊ตฌš”.(žˆ„ˆ˜ —†Š”ผผ ƒ๊ฐ•˜‹œ ผš”. Šค€“œ €˜• ฒ„ „—„œ ๊ทธŸฐ ๊ธฐŠฅ„ ถ”๊ฐ€•˜๊ธฐŠ” •˜Š”ฐ ^^; ) squid๊ฐ€ smtpž‘ ณ„ ƒ๊€ —†Š”ฐ, Šนžˆ ฐน„•ˆ šฐ””(?) ฒ„ „ squidŒจ‚ค€๊ฐ€ 8080 †ต•œ ๊ณ„ •—†Š” ™€  ˆ•˜๊ณ  (›น„†ต•œ)ฉ”ผ ˆ๊ฐ€ ๊ธฐณธ œผกœ •ˆ˜๊ฑฐ“ š”. †ŒŠคกœ „คน˜–ˆ‹ค ๊ฒ „คš” ^^;--™ฌ
          •  œ๊ฐ€ œ„˜ ง„  •™••˜€ •Š๊ฒŒ ผŠต‹ˆ‹ค. ๊ทธฆฌ๊ณ , ™ฌ”จ˜ ง”€Œ€กœ, †ŒŠคกœ „คน˜–ˆ‹ค ๊ฒ „คš”. — •‹น •‹ˆ‹ค. ƒŒ€˜ smtp port 25œผกœ ฐ„ฐ๊ฐ€  „†ก˜๊ณ  žˆ‹คŠ” ๊ฒƒ—ˆŠต‹ˆ‹ค. ๊ทธŸผ –””„ ๊ฐ€  „œฒ„˜ squid ๊ธฐณธ „ธŒ… ฌŠธกœ, relay ฅผ ๊ณ„†•˜๊ณ  žˆ‹คŠ” ˜ฏธ„ ˜Š”๊ฒƒ ๊ฐ™๊ตฐš”. ˜น€, 8080‚˜, 80„ ‚ฌšฉ•œ‹คŠ” ๊ฒƒธฐ ๊ฐ๊ฐ, resin ๊ณผ apache๊ฐ€ ‚ฌšฉ•˜๊ณ  žˆ–„œ ž˜ ๊ฒ Šต‹ˆ‹ค.  œ๊ฐ€ Ÿฐ ถ„•˜ €‹ €กฑ•„œš”. --NeoCoin
            •„ squid๊ฐ€ 3128 ๊ธฐณธ ฌŠธธ๊ฒƒ ๊ฐ™„คš” ^^; –‡๊ฐˆฆฌ—ˆ–š”. (8080„ “ฐ๊ธ •˜€งŒ,) ƒŒ€ฐฉ˜ port 25ฒˆœผกœ ๊ฐ„‹ค, •„งˆ squid„ค •œผกœ ง‰„ ˆ˜ žˆ–š”. ˜ ง˜ •ˆ†“‹œ ipfilter ”„กœ๊ทธžจœผกœ ง‰œผ ™•‹ค•˜ฃ .--™ฌ
            ๊ทธ ‡‹ค,  ฌธ œ๊ฐ€ ›ธ ™•‹ค•œ๊ฒƒ ๊ฐ™๊ตฐš”. …ŒŠคŠธƒ port ฅผ ฐ”๊พธž,  •ƒ œผกœ ™ž‘•˜Š” state ฅผ —ฌฃผ—ˆ๊ฑฐ“ š”. --NeoCoin

      • งŒผ ˜„žฌ˜ squid ๊ฐ€ Crackingƒƒœผ, squid ˜ …‹Œ…„ ˆ˜ ••˜”ผ„ —ฌ „žˆ ˜‘๊ฐ™ ฌธ œ๊ฐ€ ฐœƒ•• •ƒผ ๊ฒƒ‹ค. ๊ทธŸฐฐ …‹Œ… €๊ฒฝ›„ ๊ทธ ฐœ†ก˜Š” ƒƒœ๊ฐ€ ‚ฌผง„‹คŠ”   ”šฑ” ƒ™„ ˜ผž€ŠคŸฝ๊ฒŒ •œ‹ค. žฌฏธžˆŠ”  €, ๊ทธŸผ—„ ๊ฐ€žฅ …™••˜๊ฒŒ ๊ธฐณธ ฌŠธ˜ ƒ™—„œ, ‹คฅธ ฉ”ผ „œฒ„กœ ฉ”ผ„ ๊ฐ€Š” ๊ฒƒ ธ‹คŠ”  ‹ค.

    • „œฒ„๊ฐ€ ‡ฒˆ  • „„ งž€ ›„, squid ฅผ ‹คงˆ œผกœ ‚ฌšฉ•œ ˜ˆŠ”, ผš”ผ ‹ค. spam ฟŒ คง„  •™••œ ‚ งœฅผ •Œ, น„๊ต • ˆ˜ žˆ€ •Š„๊นŒ?
    ----
    ZeroPageServer
    Valid XHTML 1.0! Valid CSS! powered by MoniWiki
    last modified 2021-02-07 05:28:31
    Processing time 0.0815 sec