๐Ÿ—ž๏ธ IT ๋™ํ–ฅ ํŒŒ์•… ๋ฐ ๋‚˜์˜ ์ƒ๊ฐ ์ •๋ฆฌ

[๋„๋ฉ”์ธ ํƒˆ์ทจ] ๋‚ด ๋„๋ฉ”์ธ์ด Sitting Duck์ด ๋˜์ง€ ์•Š๋„๋ก

JanginTech 2024. 8. 2. 09:10

1. Don’t Let Your Domain Name Become a “Sitting Duck”

https://krebsonsecurity.com/2024/07/dont-let-your-domain-name-become-a-sitting-duck/#more-68214

 

Don’t Let Your Domain Name Become a “Sitting Duck” – Krebs on Security

More than a million domain names — including many registered by Fortune 100 firms and brand protection companies — are vulnerable to takeover by cybercriminals thanks to authentication weaknesses at a number of large web hosting providers and domain re

krebsonsecurity.com

 

[์š”์•ฝ]

1. Fortune 100 ๊ธฐ์—…๊ณผ ๋ธŒ๋žœ๋“œ ๋ณดํ˜ธ ํšŒ์‚ฌ๊ฐ€ ๋“ฑ๋กํ•œ ์ˆ˜๋งŽ์€ ๋„๋ฉ”์ธ ์ด๋ฆ„์„ ํฌํ•จํ•˜์—ฌ 100๋งŒ ๊ฐœ๊ฐ€ ๋„˜๋Š” ๋„๋ฉ”์ธ์ด ๊ณต๊ฒฉ์ž์—๊ฒŒ ์ธ์ˆ˜๋  ์œ„ํ—˜์ด ์žˆ๋Š” ๊ฒƒ์œผ๋กœ ๋‚˜ํƒ€๋‚ฌ๋‹ค.

2. ์—ฌ๋Ÿฌ ๋Œ€ํ˜• ์›น ํ˜ธ์ŠคํŒ… ์ œ๊ณต์—…์ฒด์™€ ๋„๋ฉ”์ธ ๋“ฑ๋ก๊ธฐ๊ด€์˜ ์ธ์ฆ ์ทจ์•ฝ์ ์ด ๊ทธ ์›์ธ์ด๋‹ค.

3. ๋„๋ฉ”์ธ์˜ DNS ๋ ˆ์ฝ”๋“œ๊ฐ€ ๋ถˆ๋Ÿ‰์ผ ๋•Œ 'DNS ์ œ๊ณต์—…์ฒด๋‚˜ ๋“ฑ๋ก๊ธฐ๊ด€์˜ ์‹ค์ œ ์†Œ์œ ์ž ๊ณ„์ •์— ์•ก์„ธ์Šค ํ•˜์ง€ ์•Š๊ณ ๋„ ๋„๋ฉ”์ธ ์ œ์–ด๊ถŒ์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋˜๋Š”' ๋ฌธ์ œ๋ฅผ ์•ผ๊ธฐํ•  ์ˆ˜ ์žˆ๋‹ค.

4. ์ด๋Ÿฌํ•œ ์“ธ๋ชจ์—†๋Š” ๋„๋ฉ”์ธ์„ "Sitting Ducks"๋ผ๊ณ  ๋ถ€๋ฅธ๋‹ค.

5. Sitting Ducks์˜ ์•…์šฉ ์‚ฌ๋ก€๋“ค์€ ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค.

   5.1. Sitting Duck ๋„๋ฉ”์ธ clickermediacorp[.]com์˜ ๊ฒฝ์šฐ, DNSMadeEasy๋ผ๋Š” ์›น ํ˜ธ์ŠคํŒ… ํšŒ์‚ฌ์˜ ๋„๋ฉ”์ธ์ด ๊ณต๊ฒฉ์ž๋“ค๋กœ๋ถ€ํ„ฐ ํƒˆ์ทจ๋œ ์‚ฌ๋ก€๊ฐ€ ์žˆ๋‹ค.

   5.2. DNSMadeEasy ๋ถ€์‚ฌ์žฅ์€ "์ด ๋ฌธ์ œ๊ฐ€ ์ž์‚ฌ์—์„œ ํ•ด๊ฒฐํ•  ๋ฌธ์ œ๊ฐ€ ์•„๋‹ˆ๋‹ค"๋ฉฐ, "๋„๋ฉ”์ธ ๋“ฑ๋ก๊ธฐ๊ด€์ด ์•„๋‹Œ DNS ์ œ๊ณต์ž๋Š” ํŠน์ • ๊ณ ๊ฐ์ด ์ฃผ์žฅํ•˜๋Š” ๋„๋ฉ”์ธ์˜ ์‹ค์ œ ์†Œ์œ ์ž์ธ์ง€ ๊ฒ€์ฆํ•  ๋ฐฉ๋ฒ•์ด ์—†๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค"๋ผ๋Š” ์˜๊ฒฌ์„ ํ‘œ์‹œํ–ˆ๋‹ค.

 

6. Infoblox์™€ Eclypsium์€ ๋ชจ๋‘ "๊ธ€๋กœ๋ฒŒ DNS์˜ ๋ชจ๋“  ์ดํ•ด ๊ด€๊ณ„์ž์˜ ๋” ๋งŽ์€ ํ˜‘๋ ฅ๊ณผ, ๋น„๋‚œํ•˜์ง€ ์•Š๋Š”๋‹ค๋ฉด ๋ฐฉ์น˜ํ˜• ๋„๋ฉ”์ธ์— ๋Œ€ํ•œ ๊ณต๊ฒฉ์€ ๊ณ„์† ์ฆ๊ฐ€ํ•  ๊ฒƒ์ด๋ฉฐ, ๋„๋ฉ”์ธ ๋“ฑ๋ก์ž์™€ ์ผ๋ฐ˜ ์ธํ„ฐ๋„ท ์‚ฌ์šฉ์ž๊ฐ€ ๊ทธ ์ค‘๊ฐ„์— ๊ฐ‡ํžˆ๊ฒŒ ๋  ๊ฒƒ"์ด๋ผ๊ณ  ๋งํ–ˆ๋‹ค.


 

๐Ÿค” ์ด์— ๋Œ€ํ•œ ๋‚˜์˜ ์ƒ๊ฐ

DNSMadeEasy ์ฐฝ๋ฆฝ์ž์˜ ์˜๊ฒฌ์ฒ˜๋Ÿผ, DNS ์ œ๊ณต์ž๋“ค์ด ๋„๋ฉ”์ธ ์†Œ์œ ์ž๋ฅผ ๊ฒ€์ฆํ•˜๋Š” ๋ฐ ํ•œ๊ณ„๊ฐ€ ์žˆ์„ ์ˆ˜ ์žˆ์ง€๋งŒ, ๊ทธ๋Ÿผ์—๋„ ๋ถˆ๊ตฌํ•˜๊ณ  ์ด๋Ÿฌํ•œ ์ฑ…์ž„์„ ์ผ๋ถ€ ๊ฐ๋‹นํ•ด์•ผ ํ•  ํ•„์š”๊ฐ€ ์žˆ๋‹ค๊ณ  ์ƒ๊ฐํ•œ๋‹ค.

๋„๋ฉ”์ธ ํƒˆ์ทจ์™€ ๊ฐ™์€ ๋ณด์•ˆ ๋ฌธ์ œ๋ฅผ ์˜ˆ๋ฐฉํ•˜๊ธฐ ์œ„ํ•ด ๋” ๊ฐ•๋ ฅํ•œ ๊ฒ€์ฆ ์ ˆ์ฐจ ๋„์ž…์˜ ํ•„์š”์„ฑ์ด ํฌ๋‹ค๊ณ  ์ƒ๊ฐํ•œ๋‹ค.

๋˜ํ•œ, ๋„๋ฉ”์ธ ์†Œ์œ ์ž๋“ค๋„ ์ž์‹ ์˜ ๋„๋ฉ”์ธ ๊ตฌ์„ฑ์„ ์ฒ ์ €ํžˆ ๊ด€๋ฆฌํ•ด์•ผ ํ•œ๋‹ค.

Digital Ocean์˜ ์˜๊ฒฌ์ฒ˜๋Ÿผ, ๋„๋ฉ”์ธ ๊ตฌ์„ฑ ๊ด€๋ฆฌ์˜ ๋ถ€์‹ค์€ ๋„๋ฉ”์ธ ํƒˆ์ทจ์˜ ์ฃผ์š” ์›์ธ ์ค‘ ํ•˜๋‚˜์ด๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค.

 

๋ฌด์—‡๋ณด๋‹ค, ๊ฐ€์žฅ ์ค‘์š”ํ•œ ๊ฒƒ์€ 'ํ˜‘์—…'์ด๋‹ค.

๋ณด์•ˆ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด DNS ์ œ๊ณต์ž์™€ ๋„๋ฉ”์ธ ์†Œ์œ ์ž, ๊ทธ๋ฆฌ๊ณ  ๋ณด์•ˆ ์—ฐ๊ตฌํŒ€ ๋“ฑ ๊ฐ„์˜ ํ˜‘์—…์ด ์ค‘์š”ํ•˜๋‹ค๊ณ  ์ƒ๊ฐํ•œ๋‹ค.

์—ฌ๋Ÿฌ ์ดํ•ด๊ด€๊ณ„์ž๋“ค์ด ํ•จ๊ป˜ ๋…ธ๋ ฅํ•ด์•ผ ํšจ๊ณผ์ ์ธ ๋ณด์•ˆ ์†”๋ฃจ์…˜์„ ์ฐพ์„ ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์ด๋‹ค.

 

๊ทธ๋ฆฌ๊ณ  ๋‚˜๋„, ์ด๋Ÿฌํ•œ ์—ฌ๋Ÿฌ ๋ณด์•ˆ ์ด์Šˆ๋“ค์„ ๊พธ์ค€ํžˆ ์ฑ™๊ฒจ๋ณด๋ฉฐ ๋ณด์•ˆ์˜ ์ค‘์š”์„ฑ์„ ๋” ๊นŠ์ด ์ดํ•ดํ•  ์ˆ˜ ์žˆ๋„๋ก ๋…ธ๋ ฅํ•  ๊ฒƒ์ด๋‹ค!