¼­ºêÀ̹ÌÁö

°øÁö»çÇ×

¿ö³ÊÅ©¶óÀÌ(WannaCry) ·£¼¶¿þ¾î º¸¾ÈÆÐÄ¡

ÀÎÅͳÝÁøÈï¿ø¿¡¼­ ¿ö³ÊÅ©¸³ÅÍ(WannaCryptor), ÀÏ¸í ¿ö³ÊÅ©¶óÀÌ(WannaCry)¿¡ ´ëÇÑ ¿¹¹æ ¿ä·ÉÀ» ¹èÆ÷Çß½À´Ï´Ù.
PC¸¦ ºÎÆÃÇϱâ Àü¿¡ ÀÎÅÍ³Ý ¼±À» »Ì°í, ÆÄÀÏ°øÀ¯¸¦ ÇØÁ¦ÇÏ´Â µî ¿©·¯ ´Ü°è¸¦ °ÅÄ£ ÈÄ º¸¾ÈÆÐÄ¡ÇÒ °ÍÀ» ¿ä±¸ÇÕ´Ï´Ù.
±×·¯³ª ·£¼±À» »Ì±â Àü¿¡ ÀÌ¹Ì ÄÄÇ»Å͸¦ ºÎÆÃÇÑ »óÅ¿¡¼­´Â
ÀÎÅͳÝÁøÈï¿ø ÆÐÄ¡°úÁ¤À» µû¸¦ ÇÊ¿ä¾øÀÌ °ð¹Ù·Î Microsoft Windows ÃֽŠº¸¾È ÆÐÄ¡ÇϽñ⸦ ¹Ù¶ø´Ï´Ù.

1. OSº° ·£¼¶¿þ¾î º¸¾ÈÆÐÄ¡

Windows 7
x86(32ºñÆ®) http://download.windowsupdate.com/d/msdownload/update/software/secu/2017/02/windows6.1-kb4012212-x86_6bb04d3971bb58ae4bac44219e7169812914df3f.msu
x64(64ºñÆ®) http://download.windowsupdate.com/d/msdownload/update/software/secu/2017/02/windows6.1-kb4012212-x64_2decefaa02e2058dcd965702509a992d8c4e92b3.msu

Windows 8, 8.1
x86(32ºñÆ®) http://download.windowsupdate.com/c/msdownload/update/software/secu/2017/02/windows8.1-kb4012213-x86_e118939b397bc983971c88d9c9ecc8cbec471b05.msu
x64(64ºñÆ®) http://download.windowsupdate.com/c/msdownload/update/software/secu/2017/02/windows8.1-kb4012213-x64_5b24b9ca5a123a844ed793e0f2be974148520349.msu

Windows 10
x86(32ºñÆ®) http://download.windowsupdate.com/c/msdownload/update/software/secu/2017/05/windows10.0-kb4016871-x86_5901409e58d1c6c9440e420d99c42b08f227356e.msu
x64(64ºñÆ®) http://download.windowsupdate.com/c/msdownload/update/software/secu/2017/05/windows10.0-kb4016871-x64_27dfce9dbd92670711822de2f5f5ce0151551b7d.msu

Windows ºñ½ºÅ¸
x86(32ºñÆ®) http://download.windowsupdate.com/d/msdownload/update/software/secu/2017/02/windows6.0-kb4012598-x86_13e9b3d77ba5599764c296075a796c16a85c745c.msu
x64(64ºñÆ®) http://download.windowsupdate.com/d/msdownload/update/software/secu/2017/02/windows6.0-kb4012598-x64_6a186ba2b2b98b2144b50f88baf33a5fa53b5d76.msu

Windows XP
SP3¿ë http://download.windowsupdate.com/d/csa/csa/secu/2017/02/windowsxp-kb4012598-x86-custom-kor_b2a6516e2fd541c75ebb4bcaeb15e91846ac90c5.exe

³» ÄÄÇ»ÅÍ À©µµ¿ì OS È®Àιæ¹ý
¹ÙÅÁÈ­¸é 'ÄÄÇ»ÅÍ'¾ÆÀÌÄÜ¿¡¼­ ¸¶¿ì½º ¿ì¹öÆ° Ŭ¸¯ -> '¼Ó¼º'Ŭ¸¯
¹ÙÅÁÈ­¸é¿¡ 'ÄÄÇ»ÅÍ' ¾ÆÀÌÄÜÀÌ ¾øÀ¸¸é:
½ÃÀÛ->ÄÄÇ»ÅÍ: ¸¶¿ì½º ¿ì¹öÆ°->¼Ó¼º ¶Ç´Â
½ÃÀÛ->Á¦¾îÆÇ->½Ã½ºÅÛ ¹× º¸¾È->½Ã½ºÅÛ






2. ÇÁ·Î±×·¥º° ·£¼¶¿þ¾î ÇÇÇØ´ëºñ

´ÜÁ¾µÈ Á¦Ç°ÀÎ Andwin2u´Â Ãʱâ À©µµ¹öÀü¿¡¼­ ¼³°èµÈ Á¦Ç°À¸·Î
1) Ãʱ⠵¥ÀÌÅͺ£À̽º·Î DB±¸Á¶°¡ ·£¼¶¿þ¾î¿¡ Ãë¾àÇϸç,
2) ÀÚµ¿2Áß¹é¾÷À» Áö¿øÇÏÁö ¾Ê½À´Ï´Ù.
·£¼¶¿þ¾î ÇÇÇظ¦ ´ëºñÇϱâ À§ÇØ »óÀ§¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇϽñ⸦ ±ÇÀåÇÕ´Ï´Ù.



½Ã°£Â÷ 2ÁßÀÚµ¿¹é¾÷: ¹é¾÷½Ã°£°ú ¹é¾÷Àå¼Ò¸¦ ´Ù¸£°Ô ÇÏ·ç¿¡ 2¹ø ¿äÀϺ° ºÐ»êÀÚµ¿¹é¾÷

¿äÀϺ° ºÐ»ê¹é¾÷: ¿ù.È­.¼ö.¸ñ.±Ý.Åä 6°³ ÆÄÀÏ·Î ºÐ»ê¹é¾÷(óÀ½ºÎÅÍ ÇØ´ç¿äÀϱîÁö)
========================================================================================

¸ðµç ·£¼¶¿þ¾î¸¦ ¿¹¹æÇÒ ¼ö´Â ¾ø½À´Ï´Ù. ±×·¸´Ù¸é »ç°í°¡ ÅÍÁ³À» ¶§ ´ëÃ¥Àº ÀÖ³ª¿ä?
·£¼¶¿þ¾î´Â ÄÄÇ»ÅÍ¿¡ ÀúÀåµÈ ÀڷḦ ÀÎÁú·Î Àâ°í µ·À» ¿ä±¸ÇÏ´Â ¾Ç¼ºÄڵ带 ¸»Çϴµ¥,
¿ö³ÊÅ©¶óÀÌ ·£¼¶¿þ¾î´Â ÀÎÅÍ³Ý Á¢¼Ó¸¸À¸·Î °¨¿°µÉ ¼ö Àֱ⠶§¹®¿¡ ¾Æ·¡¿Í °°ÀÌ º¸¾ÈÆÐÄ¡ÇÕ´Ï´Ù.

1. ÄÄÇ»Å͸¦ Äѱâ Àü¿¡ ·£¼±(ÀÎÅͳݼ±)À» »Ì°í
2. ·£¼±À» »Ì°í ³ª¼­ ÄÄÇ»Å͸¦ ºÎÆýÃÄÑ ÆÄÀÏ°øÀ¯ ±â´ÉÀ» ÇØÁ¦ÇÑ ÈÄ¿¡
3. ´Ù½Ã ·£¼±À» ²ÅÀº ÈÄ À©µµ¿ì ÃֽŠº¸¾È¾÷µ¥ÀÌÆ®¸¦ ÇÑ´Ù.
4. º¸¾È¾÷µ¥ÀÌÆ®°¡ ³¡³ª¸é ÆÄÀÏ°øÀ¯ ±â´ÉÀ» ´Ù½Ã ¿ø»ó´ë·Î µ¹·Á³ö¾ßÇÕ´Ï´Ù.

±×·¯³ª ÀÌ¹Ì ¾Ë·ÁÁø ·£¼¶¿þ¾î´Â ¿¹¹æÀÌ °¡´ÉÇÏ´Ù ÇÏ´õ¶óµµ
»õ·Î¿î º¯Á¾ÀÌ »ý±â°Å³ª Çϵå¿þ¾îÀûÀÎ ¹®Á¦·Î ÀÚ·á°¡ ±úÁú À§ÇèÀÌ Ç×»ó Á¸ÀçÇÕ´Ï´Ù.
µû¶ó¼­ ¿¹¹æ¸¸ ¹ÏÁö ¸»°í »ç°í°¡ ÅÍÁ³À» °æ¿ì ¾î¶»°Ô ´ëºñÇÒ °ÍÀΰ¡°¡ Áß¿äÇÕ´Ï´Ù.

2015³â¿¡µµ ·£¼¶¿þ¾î °øÁö»çÇ×À» ¿Ã·È½À´Ï´Ù(°øÁö»çÇ×324¹ø: ·£¼¶¿þ¾î¿Í ÀÚµ¿¹é¾÷)
·£¼¶¿þ¾î¸¦ ¿¹¹æÇϱâ À§Çؼ­ ù°´Â ÃֽŠÀ©µµ¿ì·Î ¾÷µ¥ÀÌÆ®ÇÏ´Â °Í¹Ì¸ç, µÑ°´Â ÀÚµ¿È­µÈ ¹é¾÷½Ã½ºÅÛÀ» ±¸ÃàÇÏ´Â °ÍÀÔ´Ï´Ù.
±×·¯³ª ½ÅÁ¾ ·£¼¶¿þ¾î´Â ¹Ì¸® ¿¹¹æÇÒ ¼ö ¾ø±â ¶§¹®¿¡ °É·ÈÀ» ¶§ ´ëóÇÒ ¼ö ÀÖ´Â ÀÚµ¿ ¹é¾÷½Ã½ºÅÛÀÌ ´õ¿í Áß¿äÇÕ´Ï´Ù.

¼öµ¿¹é¾÷Àº ½Ã°£µµ ¸¹ÀÌ °É¸®°í ½ÇõÇϱ⠾î·Æ±â ¶§¹®¿¡ ¾î¼´Ù Çѹø¾¿ ¹é¾÷Çϰųª ÀüÇô ¹é¾÷À» ÇÏÁö ¾Ê°Ô µË´Ï´Ù.
¾Ç¼ºÄڵ忡 °É¸®¸é ¾÷¹«´Â ¸¶ºñµÇ°í, µ¥ÀÌÅÍ º¹±¸´Â ½±Áöµµ ¾Ê°í º¹±¸ºñ¿ëÀº ºÎ¸£´Â °Ô °ªÀÔ´Ï´Ù.
Andwin2u´Â ÇöÀç ´ÜÁ¾µÈ Á¦Ç°À¸·Î º¸Çèû±¸ ±â´É ÀÌ¿Ü¿¡´Â ¾÷µ¥ÀÌÆ®¸¦ Áö¿øÇÏÁö ¾Ê°í ÀÖ½À´Ï´Ù.
ÇÏ·ç¿¡ 2¹ø¾¿ ¿äÀϺ°·Î ºÐ»êÇÏ¿© ¹é¾÷ÇÏ´Â ÀÚµ¿¹é¾÷½Ã½ºÅÛÀ» ÀåÂøÇÑ »óÀ§¹öÀüÀ¸·Î ¾÷±×·¹À̵åÇÏ¿© µ¥ÀÌÅÍÇÇÇØ¿¡ ´ëºñÇÏ½Ã±æ ¹Ù¶ø´Ï´Ù.
=======================================================================================

(Âü°í) ÀÎÅͳÝÁøÈï¿ø ·£¼¶¿þ¾î ¿¹¹æ ¿ä·É
¡Ø À©µµ º¸¾È ÆÐÄ¡°¡ ¿Ï·áµÈ ÈÄ¿¡´Â, ¼³Á¤ÇϽŠ¹æÈ­º® Â÷´Ü Á¤Ã¥À» ÇØÁ¦ ÇÏ¼Å¾ß ÇÕ´Ï´Ù​.

1. ·£¼¶¿þ¾î ¹æÁö ´ë±¹¹Î Çൿ

1) PC¸¦ Äѱâ Àü ³×Æ®¿öÅ© ´ÜÀý
- ·£¼± »Ì±â
- ¿ÍÀÌÆÄÀÌ ²ô±â

2) °¨¿° °æ·Î Â÷´Ü
- ¹æÈ­º® ¼³Á¤ º¯°æ

3) ÀÎÅÍ³Ý À翬°á ÈÄ º¸¾È ¾÷µ¥ÀÌÆ®
- À©µµ¿ì º¸¾È ÆÐÄ¡ ½ÇÇà
- ¹é½Å ÇÁ·Î±×·¥ ¾÷µ¥ÀÌÆ®

2. ÆÄÀÏ °øÀ¯ ±â´É ÇØÁ¦ - ¹æÈ­º® ¼³Á¤

Window ¹æÈ­º®¿¡¼­ SMB¿¡ »ç¿ëµÇ´Â Æ÷Æ® Â÷´Ü

1) Á¦¾îÆÇ -> ½Ã½ºÅÛ ¹× º¸¾È
2) Windows ¹æÈ­º® -> °í±Þ ¼³Á¤
3) Àιٿîµå ±ÔÄ¢ -> »õ±ÔÄ¢ -> Æ÷Æ® -> ´ÙÀ½
4) TCP -> ƯÁ¤ ·ÎÄà Æ÷Æ® -> 139,445 -> ´ÙÀ½
5) ¿¬°á Â÷´Ü -> ´ÙÀ½
6) µµ¸ÞÀÎ, °³ÀÎ, °ø¿ë üũ È®ÀÎ -> ´ÙÀ½
7) À̸§ ¼³Á¤ -> ¸¶Ä§

[KISA Blog ¿ø¹® º¸±â]

ÀÛ¼ºÀÏ2017.05.15

Á¶È¸¼ö11017