์ผ๋‹จ ํ•˜๊ณ  ๋ณด๋Š” ์‚ฌ๋žŒ

๋‚˜์ค‘๋ณด๋‹จ ์ง€๊ธˆ์— ์ง‘์ค‘ํ•˜๋˜, ์ง€๊ธˆ๋ณด๋‹จ ๋‚˜์ค‘์— ์™„๋ฒฝํ•ด์ง€์ž๐Ÿ’ช๐Ÿป

๐Ÿ—ž๏ธ IT ๋™ํ–ฅ ํŒŒ์•… ๋ฐ ๋‚˜์˜ ์ƒ๊ฐ ์ •๋ฆฌ

๋ฆฌ๋ˆ…์Šค xz ๊ฒฐํ•จ: ๊ธฐ์ˆ ์  ๋ฌธ์ œ๊ฐ€ ์•„๋‹Œ ์œค๋ฆฌ์  ๋ฌธ์ œ

JanginTech 2024. 8. 30. 10:12

1. Linux xz and the Great Flaws in Open Source

https://thenewstack.io/linux-xz-and-the-great-flaws-in-open-source/

 

Linux xz and the Great Flaws in Open Source

The Linux xz utils backdoor exploit shows how vulnerable open source is to social engineering, said TesitfySec's John Kjell, speaking with Chris Pirillo in this episode of The New Stack Makers.

thenewstack.io

 

 

 

[ ์š”์•ฝ ]

1. Linux xz utils์˜ ์œ ์ง€ ๊ด€๋ฆฌ์ž๊ฐ€ ์ƒˆ๋กœ์šด ๋ฆด๋ฆฌ์Šค์— ์•…์„ฑ ์ฝ”๋“œ๋ฅผ ์ถ”๊ฐ€ํ•˜์—ฌ ํ”„๋กœ์ ํŠธ๋ฅผ ์†์ƒ์‹œ์ผฐ๋‹ค. 

2. ์œ ์ง€ ๊ด€๋ฆฌ์ž์ด์ž, ๊ณต๊ฒฉ์ž๋Š” ์—…์ŠคํŠธ๋ฆผ xz ์ €์žฅ์†Œ์— ๋ฐฑ๋„์–ด ๋งฌ์›จ์–ด๋ฅผ ์‚ฝ์ž…ํ–ˆ๋‹ค. 

3. Microsoft ์—”์ง€๋‹ˆ์–ด๊ฐ€ SSH๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ xz ์œ ํ‹ธ๋ฆฌํ‹ฐ๋ฅผ ๋‹ค์šด๋กœ๋“œํ•˜๋Š” ๊ณผ์ •์—์„œ ์†๋„๊ฐ€ ๋น„์ •์‚ญ์ ์œผ๋กœ ๋А๋ ค์ ธ ์ด๋ฅผ ์กฐ์‚ฌํ•˜๋˜ ์ค‘ ๋งฌ์›จ์–ด๋ฅผ ๋ฐœ๊ฒฌํ–ˆ๋‹ค.

4. ํ•ด๋‹น ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋Š” OpenSSH์™€ ํ•จ๊ป˜ ์‚ฌ์šฉ๋˜๋ฉฐ, ์ผ๋ถ€ ์ฝ”๋“œ์— ๋ฐฑ๋„์–ด๋ฅผ ์ƒ์„ฑํ•˜์—ฌ SSH ์—ฐ๊ฒฐ ์‹œ ๊ณต๊ฒฉ์ž๊ฐ€ ๊ธฐ๋ณธ์ ์œผ๋กœ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ–ˆ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด ์›๊ฒฉ์œผ๋กœ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ•˜๊ฑฐ๋‚˜ ํ•ด๋‹น ์„œ๋ฒ„์— ์ง์ ‘ ๋กœ๊ทธ์ธ์ด ๊ฐ€๋Šฅํ–ˆ๋‹ค.

5. ์˜คํ”ˆ ์†Œ์Šค๋Š” ์ทจ์•ฝํ•˜๋‹ค. CVE ๋Œ€์‘๊ณผ ์—…๋ฐ์ดํŠธ๊ฐ€ ํ•„์š”ํ•˜์ง€๋งŒ, ๊ฒฝ์ œ์  ์š”์ธ์œผ๋กœ ์ธํ•ด ์›ํ™œํ•˜๊ฒŒ ์ด๋ฃจ์–ด์ง€์ง€ ์•Š์€ ๊ฒฝ์šฐ๊ฐ€ ๋งŽ๋‹ค. ๊ณต๊ฒฉ์ž๋Š” ์ด ์ ์„ ์•…์šฉํ–ˆ๋‹ค.

6. ์˜คํ”ˆ ์†Œ์Šค์˜ ์ˆ˜์š”๋Š” ๊ธฐ์ˆ ์  ๋ฌธ์ œ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ๊ฒฝ์ œ์  ๋ฌธ์ œ์™€๋„ ๊นŠ์ด ์—ฐ๊ด€๋˜์–ด ์žˆ๋‹ค. ๋งŽ์€ ๋น„์ฆˆ๋‹ˆ์Šค๊ฐ€ ์˜คํ”ˆ ์†Œ์Šค ์†Œํ”„ํŠธ์›จ์–ด์— ์˜์กดํ•˜๊ธฐ ๋•Œ๋ฌธ์—, ์œ ์ง€ ๊ด€๋ฆฌ์ž์˜ ์—ญํ• ์ด ๋งค์šฐ ์ค‘์š”ํ•˜๋‹ค.

 

 

 

โž•

CVE ์ทจ์•ฝ์ ?

  • Common Vulnerabilities and Exposures์˜ ์•ฝ์ž๋กœ, ์†Œํ”„ํŠธ์›จ์–ด์˜ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ์‹๋ณ„ํ•˜๊ณ  ๊ธฐ๋กํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉ๋˜๋Š” ํ‘œ์ค€ํ™”๋œ ์‹œ์Šคํ…œ
  • ํŠน์ • ๋ณด์•ˆ ์ทจ์•ฝ์ ์— ๋Œ€ํ•ด ๊ณ ์œ ์‹๋ณ„ ๋ฒˆํ˜ธ๋ฅผ ๋ถ€์—ฌํ•˜์—ฌ ์ „ ์„ธ๊ณ„์ ์œผ๋กœ ์ทจ์•ฝ์ ์„ ๋ณด๊ณ ํ•˜๊ณ  ๋Œ€์‘ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ด์คŒ

 


 

๐Ÿค” ์ด์— ๋Œ€ํ•œ ๋‚˜์˜ ์ƒ๊ฐ

์˜คํ”ˆ ์†Œ์Šค ํ”„๋กœ์ ํŠธ์—์„œ ๊ฐ€์žฅ ์‹ ๋ขฐ๋ฐ›๋Š” ์‚ฌ๋žŒ์ด ๋™๋ฃŒ๋“ค์„ ๋ฐฐ์‹ ํ•œ ๊ฒƒ์ด ๋งค์šฐ ์ถฉ๊ฒฉ์ ์ด๋‹ค. ๋ฆฌ๋ˆ…์Šค xz ๋งฌ์›จ์–ด ์ด์Šˆ๋Š” ๋‹จ์ˆœํ•œ ๊ธฐ์ˆ ์  ๋ฌธ์ œ๊ฐ€ ์•„๋‹ˆ๋ผ, ์‹ ๋ขฐ์™€ ์œค๋ฆฌ์— ๊ด€ํ•œ ์‹ฌ๊ฐํ•œ ์‚ฌ๊ฑด์ด๋‹ค. 

์ด๋ฒˆ ์‚ฌ๊ฑด์„ ํ†ตํ•ด, ๊ธฐ์ˆ ์„ ๋‹ค๋ฃจ๋Š” ๋ฐ ์žˆ์–ด ์œค๋ฆฌ์˜์‹์ด ์–ผ๋งˆ๋‚˜ ์ค‘์š”ํ•œ์ง€๋‹ค์‹œ ํ•œ๋ฒˆ ๊นŠ์ด ๋А๋ผ๊ฒŒ ๋˜์—ˆ๋‹ค.