์ผ๋‹จ ํ•˜๊ณ  ๋ณด๋Š” ์‚ฌ๋žŒ

๋‚˜์ค‘๋ณด๋‹จ ์ง€๊ธˆ์— ์ง‘์ค‘ํ•˜๋˜, ์ง€๊ธˆ๋ณด๋‹จ ๋‚˜์ค‘์— ์™„๋ฒฝํ•ด์ง€์ž๐Ÿ’ช๐Ÿป

๐Ÿ—ž๏ธ IT ๋™ํ–ฅ ํŒŒ์•… ๋ฐ ๋‚˜์˜ ์ƒ๊ฐ ์ •๋ฆฌ

[RCE] ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ๊ณต๊ฒฉ

JanginTech 2024. 8. 8. 09:14

1. Critical Progress WhatsUp RCE flaw now under active exploitation

https://www.bleepingcomputer.com/news/security/critical-progress-whatsup-rce-flaw-now-under-active-exploitation/

 

Critical Progress WhatsUp RCE flaw now under active exploitation

Threat actors are actively attempting to exploit a recently fixed  Progress WhatsUp Gold remote code execution vulnerability on exposed servers for initial access to corporate networks.

www.bleepingcomputer.com

 

 

[ ์š”์•ฝ ]

1. ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰(RCE) ์ทจ์•ฝ์ ์ธ CVE-2024-4885์ด ์ง„ํ–‰ ์ค‘์ด๋‹ค.

2. ๊ณต๊ฒฉ์ž๋“ค์€  Progress WhatsUp Gold์„ ์ ๊ทน์ ์œผ๋กœ ์•…์šฉํ•˜๊ณ ์ž ํ•œ๋‹ค. ๊ธฐ์—… ๋„คํŠธ์›Œํฌ ์ ‘๊ทผ์„ ์‹œ๋„ํ•˜๊ณ  ์žˆ๋‹ค.

3. ๋ณด์•ˆ ์—ฐ๊ตฌ์› Sina Kheirkhah๊ฐ€ ๋ฐœ๊ฒฌํ•œ ์ด ์ต์Šคํ”Œ๋กœ์ž‡์€ ์กฐ์ž‘๋œ ์š”์ฒญ์„ ํ†ตํ•ด ์•ก์„ธ์Šค ๊ถŒํ•œ์„ ์–ป๋Š”๋‹ค.

4. ์ต์Šคํ”Œ๋กœ์ž‡์˜ ์ตœ์ข… ํŽ˜์ด๋กœ๋“œ๋Š” ๊ณต๊ฒฉ์ž๊ฐ€ ์ œ์–ดํ•˜๋Š” ์„œ๋ฒ„๋กœ๋ถ€ํ„ฐ ์ „๋‹ฌ๋˜์–ด, ํ˜„์žฌ๋กœ์„œ๋Š” ๋Œ€์ƒ ์„œ๋ฒ„์—์„œ ์–ด๋–ค ํŽ˜์ด๋กœ๋“œ๊ฐ€ ์ƒ์„ฑ๋˜๋Š”์ง€ ์•Œ ์ˆ˜ ์—†๋‹ค.

5. ๊ทธ๋งŒํผ ํ™œ๋ฐœํžˆ ์ผ์–ด๋‚˜๋Š” ๊ณต๊ฒฉ์— ๋Œ€ํ•ด,  ๋ฒ„์ „ ์—…๋ฐ์ดํŠธ์™€ ์˜์‹ฌ์Šค๋Ÿฌ์šด ํ™œ๋™์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•  ๊ฒƒ์„ ๊ถŒ์žฅํ•œ๋‹ค.

 

 

โž•

Progress WhatsUp Gold ?

  • ๋„คํŠธ์›Œํฌ ๋ชจ๋‹ˆํ„ฐ๋ง ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜
  • ์ด๋ฅผ ํ†ตํ•ด ์„œ๋ฒ„์™€ ํ•ด๋‹น ์„œ๋ฒ„์—์„œ ์‹คํ–‰๋˜๋Š” ์„œ๋น„์Šค์˜ ๊ฐ€๋™ ์‹œ๊ฐ„ ๋ฐ ๊ฐ€์šฉ์„ฑ์„ ์ถ”์ ํ•  ์ˆ˜ ์žˆ๋‹ค. 

 

RCE ?

  • "์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰". ๊ณต๊ฒฉ์ž๋Š” ์•…์„ฑ ์ฝ”๋“œ๋ฅผ ์›๊ฒฉ์œผ๋กœ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋œ๋‹ค.
  • RCE ์ทจ์•ฝ์„ฑ์€ ๋ฉ€์›จ์–ด ์‹คํ–‰๋ถ€ํ„ฐ ๊ณต๊ฒฉ์ž๊ฐ€ ์†์ƒ๋œ ์‹œ์Šคํ…œ์„ ์™„์ „ํžˆ ์ œ์–ดํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒƒ๊นŒ์ง€ ๋‹ค์–‘ํ•œ ํ”ผํ•ด๋ฅผ ๋ถˆ๋Ÿฌ์ผ์œผํ‚จ๋‹ค.
  • RCE ์ทจ์•ฝ์„ฑ์€ ๊ฐ€์žฅ ์œ„ํ—˜ํ•˜๊ณ  ์˜ํ–ฅ๋ ฅ์ด ํฐ ์ทจ์•ฝ์„ฑ ์ค‘ ํ•˜๋‚˜๋‹ค.
  • Log4j, ์ดํ„ฐ๋„๋ธ”๋ฃจ๊ฐ€ RCE ๊ณต๊ฒฉ์˜ ๋Œ€ํ‘œ ์˜ˆ์‹œ๋‹ค.
  • RCE ๊ณต๊ฒฉ์€ ๋‹ค์–‘ํ•œ ์ทจ์•ฝ์ ์„ ์ด์šฉํ•  ์ˆ˜ ์žˆ์–ด, ์—ฌ๋Ÿฌ ๊ฐ€์ง€ ์ ‘๊ทผ ๋ฐฉ์‹์œผ๋กœ ๋ฐฉ์–ดํ•ด์•ผ ํ•œ๋‹ค.
  • ์‚ฌ์šฉ์ž ์ž…๋ ฅ๊ฐ’ ์œ ํšจ์„ฑ ๊ฒ€์‚ฌ, ์ฒ ์ €ํ•œ ๋ฉ”๋ชจ๋ฆฌ ๊ด€๋ฆฌ, ์ดˆ๊ธฐ ์•ก์„ธ์Šค ๊ถŒํ•œ์€ ๋„คํŠธ์›Œํฌ๋ฅผ ํ†ตํ•ด ๋ฐœ์ƒํ•˜๋Š” ๋งŒํผ ๋„คํŠธ์›Œํฌ ๋ณด์•ˆ์„ ์‹ ๊ฒฝ ์จ์•ผ ํ•œ๋‹ค.

 


 

๐Ÿค” ์ด์— ๋Œ€ํ•œ ๋‚˜์˜ ์ƒ๊ฐ

RCE ๊ฒฐํ•จ์ด ๊ฐ€์žฅ ์ทจ์•ฝํ•˜๊ณ  ์˜ํ–ฅ๋ ฅ์ด ํฐ ์ทจ์•ฝ์ ์ด๋ผ๋Š” ์‚ฌ์‹ค์„ ํ•ด๋‹น ๊ธฐ์‚ฌ๋ฅผ ํ†ตํ•ด ์ฒ˜์Œ ์•Œ๊ฒŒ ๋๋‹ค. ํ•ด๋‹น ์‚ฌ๊ฑด์€ ์ฃผ์‹œ์ ์ธ ๋ฒ„์ „ ์—…๋ฐ์ดํŠธ์™€ ์„ธ์‹ฌํ•œ ๋ณด์•ˆ ๊ด€ํ–‰์˜ ์ค‘์š”์„ฑ์„ ๊ฐ•์กฐํ•œ๋‹ค. 

๋˜, REC ์ทจ์•ฝ์ ์ด ๋น ๋ฅด๊ฒŒ ์•…์šฉ๋  ๊ฒฝ์šฐ๋ฅผ ๋Œ€๋น„ํ•˜์—ฌ ๊ฐ•๋ ฅํ•œ ๋ฐฉ์–ด์™€ ์‚ฌ์ „ ๋ชจ๋‹ˆํ„ฐ๋ง์˜ ํ•„์š”์„ฑ์„ ๊ฐ•์กฐํ•œ๋‹ค.

์ตœ์‹  ์œ„ํ˜‘์— ๋Œ€ํ•ด ์ตœ์‹  ์ •๋ณด๋ฅผ ์œ ์ง€ํ•˜๊ณ  ์‹ ์†ํ•˜๊ฒŒ ๋Œ€์‘ํ•  ์ˆ˜ ์žˆ๋„๋ก ์ค€๋น„ํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•  ๊ฒƒ์œผ๋กœ ๋ณด์ธ๋‹ค.