º»¹®/³»¿ë
-. ¹æ¹ý
- ¼ø¼Á¦¾î¹øÈ£ ÃßÃø(Sequence number guessing)
- ¹Ý(Half)Á¢¼Ó½Ãµµ °ø°Ý(SYN flooding)
- Á¢¼Ó°¡·Îä±â(Connection hijacking)
- RST¸¦ ÀÌ¿ëÇÑ Á¢¼Ó²÷±â(Connection killing by RST)
- FINÀ» ÀÌ¿ëÇÑ Á¢¼Ó²÷±â(Connection killing by FIN)
- SYN/RSTÆÐŶ »ý¼º°ø°Ý(SYN/RST generation)
- ³×Æ®¿öÅ© µ¥¸ó Á¤Áö(killing the INETD)
- TCP À©µµ¿ì À§Àå(TCP window spoofing)
xxxxxx-2. °ø°Ý µµ±¸
xxxxxx. nmap(network mapper)
- ³×Æ®¿öÅ©º¸¾È À¯Æ¿¸®Æ¼·Î ´ë±Ô¸ð ³×Æ®¿öÅ©¸¦ °í¼ÓÀ¸·Î ½ºÄµÇÏ´Â Åø.
- ¾î´À È£½ºÆ®°¡ »ì¾ÆÀÖ°í, ±×µéÀÌ ¾î¶°ÇÑ ¼ºñ½º(Æ÷Æ®)¸¦ Á¦°øÇϸç,
¿î¿µÃ¼Á¦(OS ¹öÀü)°¡ ¹«¾ùÀ̸ç, filter/firewallÀÇ ÆÐŶ ŸÀÔÀÌ ¹«¾ùÀÎÁö µî
³×Æ®¿öÅ©ÀÇ ¼ö¸¹Àº Ư¡µéÀ» Á¡°Ë°¡´É.
2. Neptune
- Á¸ÀçÇÏÁö ¾Ê´Â È£½ºÆ®ÀÇ IP¸¦ »ðÀÔÇÑ ¸¹Àº ¼öÀÇ SYN ÆÐŶÀ» Àü¼ÛÇÔÀ¸·Î½á
half-open TCP ¿¬°áÀ» ½ÃµµÇÏ¿© ¸ñÇ¥ È£½ºÆ®ÀÇ listen queue¸¦ °¡µæ ä¿ì°Ô
ÇÏ´Â µµ±¸
3. mendax
- ½Å·ÚµÈ È£½ºÆ®¿¡ ´ëÇÑ DoS °ø°Ý, Seq Number ÃßÃø, ÀÓÀÇÀÇ ¸í·É ¼öÇà µîÀÇ
¡¦(»ý·«)
Âü°í¹®Çå
http://www.krcert.or.kr/ ( ±â¼ú ¹®¼ )