ÀÌ ÆäÀÌÁö´Â Beist Security Research Group°ú Study GroupÀÇ ¿¬±¸ »êÃâ¹°À» À§ÇÑ °ø°£ÀÔ´Ï´Ù. ¿¬±¸ ºÐ¾ßÀÇ Æ¯¼º»ó ¹ýÀû Á¦µµÀÇ ¹®Á¦³ª ±×·ì »çÁ¤»ó °ø°³ÇÏÁö ¸øÇÏ´Â ¹®¼­µéµµ ÀÖÀ¸´Ï ¾çÇØ¹Ù¶ø´Ï´Ù.









    11-29-2009. USB Keyboard sniffing with Transfer Descriptor (chpie) #source_code -by beistlab
                          (English version)

The standard keyboard interfaces used these days are PS/2 and USB. Almost all desktops rely on USB, and laptops use both. The latest laptops models are internally connected to USB. This document introduces the process of sniffing USB keyboards.
There are 3 major types of USB controllers. UHCI(Universal Host Controller Interface), OHCI(Open Host Controller Interface) and EHCI(Enhanced Host Controller Interface). When some type of USB device is installed on a system, the ones that require fast processing are connected to EHCI, but legacy devices such as keyboards are connected to UHCI.
After the connection is established, the UHCI communicates with the operating system via Shared Memory. This document explains how an attacker can log key inputs by intercepting the UHCI packets that go through Shared Memory, and one kind of defense. This technique enables the attacker to monitor the packets, and also manipulate them. Furthermore, the whole process happens even before the operating system detects the packets, so the USB filter drivers don't stand a chance to such an attack.


º» ¹®¼­´Â USB Űº¸µå¸¦ ´ë»óÀ¸·Î À©µµ¿ì ȯ°æ¿¡¼­ ۷αëÀ» ÇÏ´Â ¹æ½ÄÀ» ¼³¸íÇÕ´Ï´Ù. Universal Host Controller InterfaceÀÇ ÀÛµ¿ ¹æ½ÄÀ» ÀÌ¿ëÇÏ¿© Çϵå¿þ¾îÀûÀÎ Á¢±ÙÀ» ÅëÇØ »ç¿ëÀÚ°¡ ÀÔ·ÂÇÑ Å° µ¥ÀÌÅ͸¦ °¡Á®¿Ã ¼ö ÀÖ´Â ¹æ¹ý¿¡ ´ëÇØ ¾Ë¾Æº¼ °ÍÀÔ´Ï´Ù. ÀÌ ¹æ½ÄÀº Çϵå¿þ¾î µðÀÚÀο¡ ±â¹ÝÇÏ¿´±â ¶§¹®¿¡ À©µµ¿ì »Ó¸¸ ¾Æ´Ï¶ó ´Ù¸¥ ¿î¿µÃ¼Á¦¿¡¼­µµ Àû¿ëµÉ ¼ö ÀÖÀ¸¸ç, ¸¶Áö¸·À¸·Î ÀÌ °ø°ÝÀ» ¹æ¾î±â¹ýÀ¸·Î ¸¸µå´Â ¹æ¹ýÀ» ¼Ò°³ÇÕ´Ï´Ù.





    05-08-2009. CODEGATE 2009 SOLUTIONS (by sexy pandas

CODEGATE 2009 SOLUTIONS by SEXY PANDAS!!





    02-11-2009. SMM sniffing (chpie) #source_code -by beistlab korean english(translated by Godot)

In 2004, Loic duflot released the exploit, which bypasses the protection mechanism in OpenBSD using system management mode, and now in 2008, Blackhat tackled it again with the title 'SMM Rootkit - A New breed of independent malware.' It dealt with how to sniff PS/2 keyboard in Windows using SMM and send it to the hacker using TFTP protocol. This document is about whether the scenario above is possible, and if so, how much power it will have.





    11-20-2008. JFF 2008 Solution

1st - Postech (TEAM PLUS) - solution
2nd - Kaist (TEAM GON) - solution
3rd - TheSexyGuys - solution




    08-11-2008. 1ȸ JFF ¼¼¹Ì³ª, Immunity debugger + python ¹ßÇ¥ ÀÚ·á (Osiris) -by beistlab

2008³â 6¿ù 28ÀÏ Á¦ 1ȸ JFF ¼¼¹Ì³ª¿¡¼­ ¹ßÇ¥ÇÑ OsirisÀÇ ¹ßÇ¥ ÀÚ·áÀÔ´Ï´Ù.



    07-29-2008. Immunity Debugger & Python #Part2 (Osiris) -by beistlab

º» ¹®¼­¿¡¼­´Â Immunity Debugger¿Í ½±°í °­·ÂÇÑ ÇÁ·Î±×·¡¹Ö ¾ð¾î Áß ÇϳªÀÎ PythonÀ» ´Ù·ç°í ÀÖ½À´Ï´Ù. À̹ø ¹®¼­¿¡´Â Part 1¿¡¼­ ´Ù·çÁö ¾Ê¾Ò´ø Immunity Debugger ForumÀÇ f3´ÔÀÌ ¸¸µå½Å ³ª¸ÓÁö 3°³ÀÇ Python Script¸¦ ºÐ¼®ÇϰڽÀ´Ï´Ù. ±×¸®°í Immunity Debugger¿¡ Æ÷ÇÔµÈ À¯¿ëÇÑ PyCommand¸¦ ºÐ¼®ÇÏ¿© Immunity Debugger¿¡ ´ëÇØ¼­ ´õ ¾Ë¾Æº¸µµ·Ï ÇϰڽÀ´Ï´Ù. º» ¹®¼­¸¦ ¾î·Á¿ò ¾øÀÌ Àбâ À§Çؼ­´Â ±âº»ÀûÀÎ ¾î¼Àºí¸®Áö½Ä°ú Python¿¡ ´ëÇØ¼­ ±âÃÊÀûÀÎ ¹®¹ý Á¤µµ´Â ¾Ë°í ÀÖ¾î¾ß ÇÕ´Ï´Ù.



    06-13-2008. Á¦ 1ȸ beist¹è ¹Ì´Ï ÇØÅ· ÄÜÅ×½ºÆ® ¹®Á¦ Ç®ÀÌ -by hahah

Á¦ 1ȸ beist¹è ¹Ì´Ï ÇØÅ· ÄÜÅ×½ºÆ® ¿ì½ÂÀÚÀÎ hahah°¡ ÀÛ¼ºÇÑ Ç®ÀÌ º¸°í¼­ÀÔ´Ï´Ù.



    04-23-2008. 2008 codegate ÇØÅ· ´ëȸ ¿¹¼± ¹®Á¦ Ç®ÀÌ[team root] -by beistlab

2008³â ÄÚµå°ÔÀÌÆ® ÇØÅ·´ëȸ, rootÆÀÀÇ ¿¹¼± Ç®ÀÌ º¸°í¼­ÀÔ´Ï´Ù. ´ç½Ã »çÁ¤ÀÌ ¿©ÀÇÄ¡ ¾Ê¾Æ ¹®¼­°¡ Á¶±Ý ºÎÁ·ÇÕ´Ï´Ù. ¾çÇØ¹Ù¶ó¸ç ÇÊ¿äÇÑ ºÎºÐ¿¡ ´ëÇØ¼­ ÁÁÀº Á¤º¸ ¾ò¾î°¡¼ÌÀ¸¸é ÁÁ°Ú½À´Ï´Ù.



    04-23-2008. micsland.com Web Wargame Ç®ÀÌ (OldZombie) -by beistlab

micsland.com ¿ö°ÔÀÓÀº php Äڵ忡 ´ëÇÑ ÀÌÇØµµ¸¦ Æò°¡ÇÏ´Â ¹®Á¦·Î, php Äڵ带 º¸¿©ÁØ ÈÄ ±× Äڵ忡¼­ ¿øÇÏ´Â °ªÀ» ÀÔ·ÂÇϸé ÇØ°áÄڵ带 ¾òÀ» ¼ö ÀÖ½À´Ï´Ù. ·¹º§Àº 1¿¡¼­ 6±îÁö ÀÖÀ¸¸ç °¢ ·¹º§´ç 4°³ Á¤µµÀÇ ¹®Á¦°¡ ÀÖ½À´Ï´Ù. °¢ ·¹º§ÀÇ ¸ðµç ¹®Á¦¸¦ ¸¶Ä¥ °æ¿ì plus ¹®Á¦°¡ ÁÖ¾îÁö´Âµ¥, ÀÌ ¹®Á¦´Â ±× ·¹º§¿¡¼­ ³ª¿Â ¹®Á¦ÀÇ Á¾ÇÕÀ¸·Î ³­À̵µ°¡ °¡Àå ³ô½À´Ï´Ù.



    04-21-2008. The Art of Unpacking (¿øÀúÀÚ: Mark Vincent Yason) ¹ø¿ª: ashine -by beistlab

ÀÌ ¹®¼­ÀÇ Ã¹ ¹øÂ° ¸ñÀûÀº ¾ÈƼ¸®¹ö½Ì ±â¼úµé°ú ÆÐÄ¿¿Í ÇÁ·ÎÅØÅ͵鿡 ´ëÇØ º¸¿©ÁÝ´Ï´Ù. ±×¸®°í ½±°Ô ±¸ÇÒ ¼ö ÀÖ´Â Åø·Î ÇÁ·ÎÅØÅ͸¦ ¿ìȸÇϰųª ¹«·ÂÇÏ°Ô ¸¸µå´Â °Íµµ ÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ Á¤º¸´Â ƯÈ÷ ¿¬±¸¿øµéÀÌ ÆÐÅ·µÈ ¾Ç¼ºÄÚµåµéÀ» ºÐ¼® ÇÒ ¼ö ÀÖ°Ô ÇØÁÝ´Ï´Ù. ±×¸®°í ´ÙÀ½ Àå¿¡ ³ª¿Ã ¾ÈƼ ¸®¹ö½Ì ±â¼úÀº ¼º°øÀûÀÎ ºÐ¼®À» ¹æÇØÇÕ´Ï´Ù. ±×¸®°í µÎ ¹øÂ° ¸ñÀûÀº ÀÌ Á¤º¸°¡ ¾Ë·ÁÁö¸é¼­ ¿¬±¸¿øµéÀº º¸È£Äڵ带 ³Ö¾î¼­ ¸®¹ö¼­µéÀÌ ¼ÒÇÁÆ®¿þ¾î¸¦ ºÐ¼®ÇÏ´Â ¼Óµµ¸¦ ´ÊÃß´Â °ÍÀ» ÇÒ ¼ö ÀÖ°Ô µË´Ï´Ù.



    04-17-2008. Design and Implementation of Virtualized Code Protection For Anti-Reverse Engineering
                      -by ÀÌ¿ëÀÏ (beistlab friend!)

¹ÙÀ̳ʸ® ÇÁ·Î±×·¥À» ºÐ¼®ÇÏ±â ¾î·Æ°Ô ¸¸µå´Â ±â¼úÀº Å©·¡Ä¿·ÎºÎÅÍ °ø°Ý ¹ÞÀ» È®·üÀ» ÁÙ¿©Áֱ⠶§¹®¿¡ »ó¿ë ÇÁ·Î±×·¥¿¡¼­ ƯÈ÷ Áß¿äÇÏ´Ù. º» ¹®¼­´Â ÇÏÀ̺긮µå ÄÚµå °¡»óÈ­ º¸È£ ±â¹ýÀ» ÀÌ¿ëÇÏ¿© ¿ø·¡ÀÇ ÇÁ·Î±×·¥À» º¸È£ÇÏ´Â ¹æ½Ä¿¡ ´ëÇÑ ¿ø¸® ¹× ±¸Çö ¹æ¹ý¿¡ ´ëÇØ¼­ ´Ù·ç°í ÀÖ´Ù. ÀÌ ±â¼úÀº ÇÁ·Î±×·¥ °³¹ß ´Ü°è¿¡¼­ º¸È£ÇÏ°í ½ÍÀº ƯÁ¤ ¼Ò½º ¿µ¿ªÀ» ÁöÁ¤ÇÑ ÈÄ, ÇØ´ç ¿µ¿ª¿¡ ´ëÇØ¼­ °¡»óÈ­µÈ ¿¡¹Ä·¹À̼ÇÀ» ¼öÇàÇÏ´Â ¹æ½ÄÀ¸·Î ÀÌ·ç¾îÁø´Ù.



    04-01-2008. Immunity Debugger & Python #Part1 (Osiris) -by beistlab

Immunity Debugger´Â PythonÀ» Ç÷¯±×ÀÎ ÇüÅ·ΠÁö¿øÇϰí ÀÖ½À´Ï´Ù. ÀÌ 2°³¸¦ ¿¬µ¿ÇÒ °æ¿ì °­·ÂÇÑ Reverse Engineering ȯ°æÀ» ±¸ÃàÇÒ ¼ö ÀÖ½À´Ï´Ù. º» ¹®¼­¿¡¼­´Â Immunity Debugger + Python ±¸Á¶¿¡ ´ëÇØ¼­ ´Ù·ç°í ÀÖ½À´Ï´Ù. ¸ÕÀú Immunity Debugger¿¡ ´ëÇØ °£´ÜÇÏ°Ô ¼³¸íÇÏ°í ¿¹Á¦ ÇÁ·Î±×·¥ÀÇ ¹®Á¦¸¦ ÇØ°áÇϱâ À§ÇØ ¸¸µé¾îÁø Python script¸¦ ºÐ¼®Çϵµ·Ï ÇϰڽÀ´Ï´Ù. ¿ì¸®´Â scriptºÐ¼®À» ÅëÇØ¼­ scriptÀÛ¼º¹ý°ú module¿¡ µé¾î ÀÖ´Â ¿©·¯ Á¾·ùÀÇ method¿¡ ´ëÇÑ ±âÃÊÀûÀÎ »ç¿ë¹ýÀ» ¹è¿ï ¼ö ÀÖÀ» °ÍÀÔ´Ï´Ù. º» ¹®¼­´Â ¿¬Àç Çü½ÄÀ¸·Î ÁøÇàµÇ¸ç Å« ¾î·Á¿ò ¾øÀÌ Àбâ À§Çؼ­´Â ¾î¼Àºí¸®¿Í Python¿¡ ´ëÇØ¼­ ±âÃÊ Áö½ÄÀº ¾Ë°í ÀÖ¾î¾ß ÇÕ´Ï´Ù.



    03-11-2008. CrackMe 10Á¾ Ç®ÀÌ (Osiris) -by beistlab

º» ¹®¼­¿¡¼­ ´Ù·ç´Â CrackMe ¹®Á¦´Â Key°ª ã±â, Keygen¸¸µé±â, Keyfile¸¸µé±â, °æ¿ìÀǼö ÆÛÁñÇ®±â, ÀÔ·ÂÇÑ °ª¸¶´Ù ´Ù¸¥ Serialã±â µîÀÌ ÀÖ´Ù. ³ª´Â ÀÌ ¹®¼­¿¡¼­ ´Ü¼øÈ÷ ¼º°ø¸Þ½ÃÁö¸¸À» º¸±â À§Çؼ­ CrackMe¸¦ Ç®ÀÌ ÇÏ´Â °ÍÀÌ ¾Æ´Ï¶ó Key°ªÀ» »ý¼ºÇÏ´Â CrackMe¶ó¸é Reverse Engineering(¿ª °øÇÐ)À» ÅëÇØ¼­ ¾î¶² °ø½ÄÀ¸·Î Key°ªÀ» »ý¼ºÇÏ´ÂÁö ã¾Æ³»°í, ±× Key°ªÀ» »ý¼ºÇÏ´Â ÇÁ·Î±×·¥À» µû·Î ¸¸µé¾î, ÀÌ ¹®¼­¸¦ º¸´Â »ç¶÷ÀÌ CrackMe¿¡ ´ëÇØ Á¤È®ÇÑ ÀÌÇØ¸¦ ÇÒ ¼ö ÀÖµµ·Ï ³ë·ÂÇÏ¿´´Ù.



    02-29-2008. Padocon Live Hacking Festival 2008 CTF º»¼± ¹®Á¦ Ç®ÀÌ (ashine, eazy, hahah) -by beistlab

Padocon CTF º»¼± ¹®Á¦ Ç®ÀÌÀÔ´Ï´Ù. Daemon01 ¹®Á¦¿¡ ´ëÇØ¼­¸¸ Ç®À̰¡ ³ª¿ÍÀÖ½À´Ï´Ù. Daemon01 ¹®Á¦´Â Redhat 9.0 ȯ°æ¿¡¼­ Reverse engineeringÀ» ÅëÇØ Buffer Overflow Ãë¾à¼ºÀ» ºÐ¼®ÇÑ ÈÄ °ø·«À» ÇÏ´Â ¹®Á¦¿´½À´Ï´Ù. ÀÌ ¹®Á¦´Â Shellcode¸¦ ¿¬¼ÓÀûÀ¸·Î ÀÔ·ÂÇÒ ¼ö ¾ø´Â ȯ°æ¿¡¼­ ¾î¶°ÇÑ ¹æ¹ýÀ¸·Î ShellÀ» ȹµæÇÒ ¼ö ÀÖ´ÂÁö°¡ ÁÖ¿ä Æ÷ÀÎÆ®ÀÔ´Ï´Ù.



    04-29-2007. ¿¹Á¦·Î »ìÆìº» Ajax º¸¾È ¹®Á¦Á¡ -by Beist Security Research Group

Ajax´Â »õ·Î¿î ¾ð¾î, »õ·Î¿î ±â¼úÀº ¾Æ´Ï´Ù. À̰ÍÀº ¿¹ÀüºÎÅÍ ÃæºÐÈ÷ ±¸Çö °¡´ÉÇÑ ±â¼úÀ̾úÁö¸¸ Google¿¡¼­ À̰ÍÀ» »ç¿ëÇÑ ½ÃÁ¡¿¡¼­ È­Á¦°¡ µÇ¾ú´Ù. ÀÌó·³ Ajax´Â µ¿ÀûÀÎ À¥ ȯ°æÀ» À§ÇØ ÁÖ¸ñ ¹Þ´Â ¹æ½ÄÀÌÁö¸¸, Ç×»ó ±×·¡¿ÔµíÀÌ »õ·Î¿î ±â¼úÀÌ À̽´°¡ µÇ¸é °Å±â¿£ º¸¾ÈÀûÀÎ ¹®Á¦Á¡ÀÌ ÁöÀûµÇ¾ú´Ù. Ajax°¡ º¸¾È°ú °ü·ÃµÇ¾î ÁÖ¸ñ ¹ÞÀº »ç°ÇÀº ´ëÇ¥ÀûÀ¸·Î ¹Ì±¹ÀÇ ½ÎÀÌ¿ùµå¶ó°í ÇÒ ¼ö ÀÖ´Â MySpace ÇØÅ· »ç°ÇÀÌ´Ù. ¶ÇÇÑ ÃÖ±ÙÀÇ °æ¿ì jikto µîÀÇ ÇÁ·Î±×·¥ÀÌ ¹ßÇ¥µÇ¾î ÁÖ¸ñÀ» ¹Þ°í Àִµ¥ º» ¹®¼­´Â °ø°ÝÀÚ°¡ Ajax¸¦ ¾Ç¿ëÇÏ¿© ƯÁ¤ »ç¿ëÀÚ¸¦ °ø°ÝÇÒ °æ¿ì ¾î¶°ÇÑ ÇÇÇØ¸¦ ÀÔÈú ¼ö ÀÖ´ÂÁö ¸î °¡Áö ¿¹Á¦¿¡ ´ëÇØ °£·«È÷ ¾Ë¾Æº¼ °ÍÀÌ´Ù.



    2005. A method in finding out user¡¯s original IP of proxy server on IE using external program -by Beist Security Study Group

The objective of this paper is to present a method about finding out user¡¯s original IP of proxy server on IE. We will study direct network connection method by executing external program without using proxy server.



    2002. Web Hacking Security Mechanism at Kernel Level based on concept of system resource access permit- -by Beist Security Research Group

[¾Ë¸²»çÇ×: º» ¹®¼­´Â beist°¡ 2001³â¿¡ °³³äÀ» ¿Ï¼ºÇÏ¿´°í ³»¿ë ¹× ±¸ÇöÀº 2002³â¿¡ ¿Ï¼ºµÇ¾ú½À´Ï´Ù. ¹®¼­ÀÇ ³»¿ëÀ» ±â¹ÝÀ¸·Î 2002³â¿¡ °í±³»ý °æÁø´ëȸ¿¡ Âü°¡ÇÏ¿´À¸³ª ÀÔ»óÇÏÁö ¸øÇß°í 2004³âµµ¿¡ ±¤ÁÖ°úÇбâ¼ú¿ø °æÁø´ëȸ¿¡¼­ ³í¹® ºÎ¹®¿¡¼­ ¼ö»óÇÏ¿´½À´Ï´Ù. ¼ö»ó ´ç½Ã ¹®¼­°¡ ¿Ïº®ÇÏÁö ¸øÇØ ÃßÈÄ º¸¿Ï ÀÛ¾÷ÀÇ Çʿ伺À» ´À²¼À¸³ª ±×ÈÄ·Î °ü½ÉÀÌ ¾ø¾î ¼öÁ¤ÇÏÁö ¸øÇÑ »óÅÂÀ̰í ÇöÀç º» ¹®¼­´Â ¿ÏÀüÇÏ°Ô Á¤¸®µÇÁö ¾ÊÀº »óÅÂÀÔ´Ï´Ù. ºÎÁ·ÇÑ ºÎºÐÀÌ ¸¹ÀÌ ÀÖ½À´Ï´Ù. ÀÐÀ¸½Ã´Â µµÁß È¥¶õÀ» ´À³¢½Ç ¼ö ÀÖ´Â ºÎºÐÀÌ ÀÖÀ»¼öµµ ÀÖÀ¸´Ï ¾çÇØ ¹Ù¶ó°Ú½À´Ï´Ù. ÇöÀç ÀÌ ¹®¼­´Â ¿µ¹® ¹öÀüÀε¥, Á¦°¡ ¿µÀÛÇÑ °ÍÀº ¾Æ´Õ´Ï´Ù. ÇÑ±Û ¹®¼­¸¦ ¿Ã¸®·Á ÇßÀ¸³ª ÀÚ·á °ü¸®¸¦ Á¦´ë·Î ÇÏÁö ¸øÇØ ºÐ½ÇÇÏ¿´½À´Ï´Ù. Ȥ½Ã ÇÑ±Û ¹öÀüÀÇ ¹®¼­¸¦ °®°í °è½Ã´Ù¸é Àú¿¡°Ô ¿¬¶ôÁÖ½Ã¸é °¨»çÇϰڽÀ´Ï´Ù.]

It has been difficult to counteract against web hacking due to its diversity and complicity. Previously suggested methods were mostly taken at user level and even if it was taken at kernel level, it didn't defend web professionally. This wasn't good in security efficiency. In this paper, we discuss the method that protect the web privilege at kernel level with a method which differs from the previous methods. We discuss a mechanism which monitors attacker's activity by defacing specific system call of the operating system and block the access for request if it matches with web hacking pattern.



    01-31-2007. Ãʺ¸ÀÚ¸¦ À§ÇÑ ¿¹Á¦¿Í ÇÔ²² ¹è¿öº¸´Â OllyDbg »ç¿ë¹ý -2ºÎ- -by Beist Security Study Group

ÀÌ ¹®¼­´Â Ãʺ¸ÀÚ¸¦ À§ÇÑ OllyDbg °­Á 2ȸÀ̸ç OllyDbg PluginÀ» ¸¸µå´Â ¹æ¹ý¿¡ ´ëÇØ¼­ ÁÖ·Î ´Ù·ç°í ÀÖ´Ù. ÇÁ·ÎÁ§Æ® Áغñ¸¦ À§ÇÑ °úÁ¤°ú ½ÇÁ¦ °£´ÜÇÑ PluginÀ» ±¸ÇöÇØº¸¸é¼­ ¼³¸íÀ» Çϰí ÀÖ´Ù.



    01-18-2007. Ãʺ¸ÀÚ¸¦ À§ÇÑ Kernel based windows rootkit -1ºÎ- -by Beist Security Study Group

ÀÌ ¹®¼­´Â À©µµ¿ì2000/XP/2003 ȯ°æ¿¡¼­ÀÇ Ä¿³Î ·çƮŶ¿¡ ´ëÇÑ °³¿ä¿Í À©µµ¿ì¿Í Çϵå¿þ¾î°£ÀÇ Ä¿³Ø¼Ç¿¡ ´ëÇØ ´Ù·ì´Ï´Ù. ±×¸®°í ½Ç½ÀÀ» À§ÇØ Ä¿³Î ·¹º§¿¡¼­ CR0 ·¹Áö½ºÅ͸¦ º¯°æÇÏ¿© SSDTÀÇ read-only ¼Ó¼ºÀ» write ¼Ó¼ºÀ¸·Î ¹Ù²Ù´Â ÇÁ·Î±×·¥À» µð¹ÙÀ̽º µå¶óÀ̹ö¸¦ ÀÌ¿ëÇØ¼­ ÀÛ¼ºÇÒ °ÍÀÔ´Ï´Ù. ÀÌ ±ÛÀ» Àд µ¶ÀÚ°¡ À¯Àú·¹º§¿¡¼­ÀÇ À©µµ¿ì ½Ã½ºÅÛ ÇÁ·Î±×·¡¹Ö °æÇèÀÌ ÀÖ´Ù´Â ÀüÁ¦ÇÏ¿¡ ÁøÇàÇϰڽÀ´Ï´Ù.



    01-18-2007. Ãʺ¸ÀÚ¸¦ À§ÇÑ ¿¹Á¦¿Í ÇÔ²² ¹è¿öº¸´Â OllyDbg »ç¿ë¹ý -1ºÎ- -by Beist Security Study Group

ÀÌ ¹®¼­´Â OllyDbg ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¿© Reverse EngineeringÀ» ÇÏ´Â ¹æ¹ý¿¡ ´ëÇØ¼­ ´Ù·é´Ù. Ãʺ¸ÀÚ¸¦ À§ÇÏ¿© ÀÛ¼ºµÈ ¹®¼­ÀÌ¸ç ¿¹Á¦¿Í ÇÔ²² OllyDbgÀÇ °¢ ±â´É¿¡ ´ëÇØ¼­ ¾Ë¾Æº»´Ù. ÁÖ·Î ±âÃÊÀûÀÎ ³»¿ëÀ» ´Ù·ç°í ÀÖ´Ù.



    03-11-2006. Windows¿¡¼­ Common Internet File System ±â´ÉÀ» ÀÌ¿ëÇÏ¿© ¾ÆÁÖ ÀÛÀº Shellcode ¸¸µé±â -by Beist Security Research Group

Ãë¾à ÇÁ·Î±×·¥À» °ø·«ÇÒ ¶§ Shellcode¸¦ »ðÀÔÇÒ °ø°£ÀÌ ºÎÁ·ÇÒ °æ¿ì¸¦ ´ëºñÇØ ¸¹Àº ÇØÄ¿µéÀÌ ÀÛÀº Å©±âÀÇ Shellcode¸¦ ¸¸µé±â À§ÇØ ³ë·ÂÇϰí ÀÖ´Ù. º» ¹®¼­´Â Windows OSÀÇ CIFS ±â´ÉÀ» ÀÌ¿ëÇÏ¿© Shellcode¸¦ ¸¸µå´Â ¹æ¹ý·ÐÀ» ¼Ò°³Çϰí ÀÖ´Ù. °á·ÐÀûÀ¸·Î Execute FunctionÀ» Çѹø¸¸ È£ÃâÇØµµ ÇØÄ¿°¡ ¿øÇÏ´Â ±â´ÉÀ» ¼öÇàÇÒ ¼ö Àֱ⠶§¹®¿¡ ¸Å¿ì °£´ÜÇϸ鼭 Å©±â°¡ ÀÛ°í ȣȯ¼ºÀÌ ÁÁÀº Shellcode¸¦ ¸¸µé ¼ö ÀÖ´Ù.



    04-01-2006. ¸®´ª½º¿¡¼­ ƯÁ¤ ÇÁ·Î¼¼½º¸¦ ÁöÁ¤ÇÒ ¼ö ÀÖ´Â ÆÐŶ ½º´ÏÇÎ ÇÁ·Î±×·¥ Á¦ÀÛÇϱâ -by Beist Security Study Group

º» ¹®¼­´Â À¯Àú ·¹º§¿¡¼­ ÆÐŶ Çì´õ¸¦ ºÐ¼®ÇÏ´Â ¹æ¹ý°ú ƯÁ¤ ÇÁ·Î¼¼½º¸¦ ÁöÁ¤ÇÏ¿© º¼ ¼ö ÀÖ´Â ÆÐŶ ½º´ÏÇÎ ÇÁ·Î±×·¥À» ±¸ÇöÇÏ´Â ¹æ¹ýÀ» ¼Ò°³ÇÕ´Ï´Ù.



    08-14-2006. [Ä®·³] ÇØÅ· ´ëȸ¿¡ Âü°¡ÇÏ°í ½ÍÀºµ¥.. ¾î¶»°Ô? -by Beist Security Research Group

±× µ¿¾È Á¾Á¾ ÀÌ·± Áú¹®À» ¹Þ¾Ò½À´Ï´Ù. µ¥ÇÁÄÜ Capture the Flag ÇØÅ· ´ëȸ °ü·ÃµÈ À̾߱⵵ ³²±æ °â, À̹ø ±âȸ¿¡ Á¦¸ñ°ú °ü·ÃµÈ Á¦ »ý°¢À» ¸»¾¸ µå¸®°Ú½À´Ï´Ù. Çü½ÄÀ» °®ÃßÁö ¾Ê°í ÀÚÀ¯ Çü½ÄÀ¸·Î ±ÛÀ» ½è´Âµ¥ ¾çÇØ ¹Ù¶ó°Ú½À´Ï´Ù. ¸¶Áö¸·À¸·Î, º» À̾߱â´Â ¾î¶°ÇÑ ÇØ°áÃ¥À» Á¦½ÃÇØÁÖ´Â ±ÛÀÌ ¾Æ´Ï¶ó Á¦ »ý°¢À» Æí¾ÈÇÏ°Ô ÀûÀº ±ÛÀÔ´Ï´Ù.



    11-20-2005. Apache Environment¸¦ »ç¿ëÇÒ ¶§ ¹ß»ýÇÒ ¼ö ÀÖ´Â SQL Injection Ãë¾à¼º¿¡ °üÇÑ ÇÙ½É Á¤¸® -by Beist Security Study Group

º» ¹®¼­´Â [À̽ÂÁø, 'Apache Environment¸¦ »ç¿ëÇÒ ¶§ ¹ß»ýÇÒ ¼ö ÀÖ´Â SQL Injection Ãë¾à¼º', 2003] ¹®¼­¿¡¼­ Á¦½ÃÇÑ ±â¹ýÀ» Beist Security Study Group¿¡¼­ ÇÙ½É ³»¿ë¸¸ °£Ãß·Á Á¤¸®ÇÑ ¹®¼­ÀÌ´Ù. ÀϹÝÀûÀ¸·Î magic_quotes_gpc ¼³Á¤ÀÌ onÀ¸·Î µÇ¾î Àִ ȯ°æ¿¡¼± SQL Injection °ø°ÝÀ» ÇϱⰡ Èûµé´Ù°í »ý°¢µÇ´Âµ¥ À¥ ÇÁ·Î±×·¥¿¡¼­ Apache Environment¸¦ À߸ø »ç¿ëÇÒ °æ¿ì SQL InjectionÀ» ¼º°øÇÒ ¼ö ÀÖ´Â °¡´É¼ºÀÌ ÀÖ´Ù. º» ¹®¼­´Â ÀÌ·¯ÇÑ ¹®Á¦¿¡ ´ëÇØ¼­ ´Ù·ç°í ÀÖ´Ù.



    10-17-2005. ¾²·¹µå¸¦ »ç¿ëÇÑ Æ÷Æ® ½ºÄµ ÇÁ·Î±×·¥ -by Beist Security Study Group

¾²·¹µå¸¦ ÀÌ¿ëÇÏ¿© ÇÁ·Î±×·¥À» º´·ÄÀûÀ¸·Î ÀÛ¼ºÇÒ °æ¿ì ¿øÇÏ´Â ±â´ÉÀ» º¸´Ù ºü¸£°Ô ¼öÇàÇÒ ¼ö ÀÖ½À´Ï´Ù. º» ¹®¼­´Â ¾²·¹µå¸¦ ÀÌ¿ëÇÑ Æ÷Æ® ½ºÄµ ÇÁ·Î±×·¥À» ÀÛ¼ºÇÏ´Â °úÁ¤À» ´ã¾Ò½À´Ï´Ù. À̸¦ Ȱ¿ëÇÒ °æ¿ì ¾²·¹µå¸¦ »ç¿ëÇÏÁö ¾ÊÀº Æ÷Æ® ½ºÄµº¸´Ù ÈξÀ ´õ ºü¸£°Ô ½ºÄµ ÀÛ¾÷À» ¼öÇàÇÒ ¼ö ÀÖ°í Æ¯È÷ ±¤¹üÀ§ÇÑ IP ´ë¿ªÀ» ½ºÄµÇϰųª ÇÒ ¶§ À¯¿ëÇÏ°Ô »ç¿ëµÉ ¼ö ÀÖ½À´Ï´Ù.



    2002. NAT ȯ°æ¿¡¼­ Web Ãë¾à¼ºÀÌ Á¸ÀçÇÒ ¶§ ³»ºÎ ³×Æ®¿öÅ© °ø·«Çϱâ -by Beist Security Research Group

ÀϹÝÀûÀ¸·Î NAT ȯ°æÀº ¼­¹ö°¡ Ãë¾à¼ºÀ» °®´õ¶óµµ ¿ÜºÎ¿¡¼­ ÇØÄ¿°¡ Á¢±ÙÇÒ ¼ö ÀÖ´Â ¹æ¹ýÀÌ ¾ø±â ¶§¹®¿¡ ÇØÅ·ÀÌ ºÒ°¡´ÉÇҰŶó ¾Ë·ÁÁ®ÀÖÁö¸¸ »ç½ÇÀº ±×·¸Áö ¾Ê´Ù. ÇØÄ¿°¡ ¾î¶² ÇÑ ÁöÁ¡¿¡¼­ º¸¾È Ãë¾à¼ºÀ» ã´Â´Ù¸é, NAT¿¡ ¼ÓÇØ ÀÖ´Â ³»ºÎ ³×Æ®¿öÅ© ȯ°æÀÇ ÄÄÇ»Å͵鿡 ÀÚµ¿ÀûÀ¸·Î Á¢¼ÓÇϰí Á¤º¸ Ž»ö, °ø°ÝÀ» ÀÚµ¿ ¼öÇà ÇÏ´Â ÇÁ·Î±×·¥À» ¸¸µé¾î ÀÌ¿ëÇÏ¸é °¡´ÉÇÏ´Ù. º» ¹®¼­´Â ¿ÜºÎ¿¡ ÀÖ´Â Web ¼­¹ö¿¡ Ãë¾à¼ºÀÌ Á¸ÀçÇÑ´Ù°í °¡Á¤ÇÒ ¶§ ³»ºÎ ³×Æ®¿öÅ©±îÁö °ø·«ÇÒ ¼ö ÀÖ´Â ¹æ¹ý¿¡ ´ëÇØ¼­ ´Ù·ç°í ÀÖÀ¸¸ç °¢ ³»ºÎ ³×Æ®¿öÅ©¸¦ °ø·«ÇÏ´Â ¹æ¹ý¿¡ ´ëÇØ¼­ Remote, Local µÎ °¡Áö Á¾·ù·Î ³ª´©¾î ¼³¸íÇÏ¿´´Ù. °ø°Ý¿¡ »ç¿ëÇÑ ¾ð¾î´Â php¿Í expectÀÌ´Ù.



    09-24-2005. ÇÁ·ÎÅäÄÝ ºÐ¼®¿¡ ±â¹ÝÇÑ Æ÷Æ® ½ºÄµ ÇÁ·Î±×·¥ -by Beist Security Study Group

±âÁ¸ÀÇ Æ÷Æ® ½ºÄµ ÇÁ·Î±×·¥Àº ÇØ´ç Æ÷Æ®ÀÇ Open/Close À¯¹«¸¦ ´ë»óÀ¸·Î µ¥¸óÀÇ Á¾·ù¸¦ ÆÄ¾ÇÇÏ¿´´Ù. ±×·¯³ª ÀÌ·¯ÇÑ ¹æ¹ýÀº Á¤È®ÇÑ ºÐ¼®À» ÅëÇÑ °ÍÀÌ ¾Æ´Ï¶ó ´Ü¼øÇÏ°Ô Æ÷Æ®ÀÇ Á¸Àç À¯¹«¸¸À» ÆÄ¾ÇÇϱ⠶§¹®¿¡ ºÎÁ¤È®ÇÑ Á¤º¸¸¦ Á¦°øÇÒ ¼ö ÀÖ´Ù. ƯÈ÷ ±¤´ë¿ªÀÇ Æ÷Æ® ½ºÄµ ÀÛ¾÷À» ¼öÇàÇÒ ¶§ ÀÌ·¯ÇÑ Á¤È®ÇÑ ºÐ¼®Àº ´õ¿í Áß¿äÇØÁø´Ù. º» ¹®¼­´Â ÇØ´ç Æ÷Æ®¿Í ³×Æ®¿öÅ©¸¦ ÅëÇØ µ¥ÀÌÅ͸¦ ÁÖ°í ¹Þ´Â ¹æ½ÄÀ¸·Î, Áï ÇÁ·ÎÅäÄÝ ºÐ¼®À» ±â¹ÝÀ¸·Î ÇÑ Æ÷Æ® ½ºÄµ ÇÁ·Î±×·¥¿¡ ´ëÇÑ ¾ÆÀ̵ð¾î¸¦ ´Ù·ç°í ÀÖ´Ù.



    07-12-2005. Ȱ¿ë ºÐ¾ßº°·Î ºÐ·ùÇÑ ¹«¼± Network ȯ°æÀÇ º¸¾È À§Ç輺 -by Beist Security Study Group

ÀÌ ¹®¼­´Â ¹«¼± ȯ°æ¿¡¼­ ÀϾ ¼ö ÀÖ´Â º¸¾È ¹®Á¦Á¡µé¿¡ ´ëÇØ¼­ »óȲ º°·Î ºÐ·ùÇÏ¿© ¼³¸íÇÏ¿´´Ù. ¹«¼± ȯ°æÀÇ »óȲÀ» Å©°Ô 4°¡Áö·Î ±¸ºÐÇÏ¿´´Âµ¥ ¹«¼± LAN ³×Æ®¿öÅ©, Bluetooth ³×Æ®¿öÅ©, Ȩ ³×Æ®¿öÅ©, »óÁ¡ ³×Æ®¿öÅ©ÀÌ´Ù. °¢°¢ÀÇ ¹«¼± ¸Å°³Ã¼´Â Wireless, Bluetooth, Zigbee, RFID¸¦ ´ë»óÀ¸·Î ´Ù·ç¾ú´Ù. ÀÌ ¹®¼­´Â ¹«¼± ȯ°æ¿¡¼­ÀÇ º¸¾È ¹®Á¦Á¡µé¿¡ ´ëÇØ ¾Ë¸®´Â °Í¿¡ ¸ñÀûÀ» µÎ¾ú´Ù. º¸¾È ´ëÀÀ ¹æ¹ýÀ̳ª Àǰ߿¡ ´ëÇØ¼­´Â ÇâÈÄ ¿¬±¸ °úÁ¦·Î µÎ±â À§ÇØ ÀÌ ¹®¼­¿¡¼­´Â ´Ù·çÁö ¾Ê¾Ò´Ù.



    10-01-2004. FEDORA CORE2¿¡¼­ EXEC-SHIELD¸¦ ¿ìȸÇÏ¿© STACK ±â¹Ý OVERFLOW °ø°Ý ±â¹ý Çѹø¿¡ ¼º°øÇϱâ -by Beist Security Research Group

FEDORA LINUX´Â ÇØÄ¿ÀÇ ½Ã½ºÅÛ ÇØÅ· °ø°ÝÀ» ¸·±â À§ÇØ EXEC-SHIELD¶ó´Â Ä¿³Î ±â¹ÝÀÇ º¸¾È ¼Ö·ç¼ÇÀ» Àû¿ëÇϰí ÀÖ´Ù. º» ¹®¼­´Â GLIBCÀÇ EXEC LIBRARY ÇÔ¼ö¸¦ ÀÌ¿ëÇÏ¿© EXEC-SHIELDÀÇ ¹æ¾î¸¦ ¿ìȸÇÏ´Â ¹æ¹ýÀ» ¼Ò°³Çϰí ÀÖ´Ù. ±âÁ¸ ¹æ¹ýµéÀº ARGUMENT·Î »ç¿ëÇÒ °ªÀ» ÁÖ·Î STACK ¿µ¿ª¿¡¼­ ÀÌ¿ëÇÏ¿´´Âµ¥ º» ¹®¼­¿¡¼­´Â PROGRAM MEMORY MAPPING ¿µ¿ªÀÇ °ªÀ» »ç¿ëÇÏ¿´´Ù. °á·ÐÀûÀ¸·Î ÀÌ ¹®¼­¿¡¼­ »ç¿ëÇÏ´Â ¹æ¹ýÀ» ÀÌ¿ëÇÏ¸é °ø°ÝÀ» ¼öÇàÇϴµ¥ À־ ½ÇÆÐÇϰųª ȤÀº ¿©·¯ ¹øÀ» ½ÃµµÇÏÁö ¾Ê°í Çѹø¿¡ °ø°Ý¿¡ ¼º°øÇÒ ¼ö ÀÖ´Ù. ¶ÇÇÑ ÀÌ ¹æ¹ýÀº EXEC-SHIELD¿¡¸¸ Àû¿ëÇÒ ¼ö ÀÖ´Â °ÍÀº ¾Æ´Ï¸ç ´Ù¸¥ º¸¾È ¼Ö·ç¼Ç¿¡µµ °¡´ÉÇÏ´Ù. ¸¶Áö¸·À¸·Î º» ¹®¼­´Â STACK Overflow ±â¹ÝÀ» ´ë»óÀ¸·Î ½ÇÇèÇÏ¿´Áö¸¸ FRAME POINTER ¿µ¿ª°ú RETURN ADDRESSÀÇ ÁÖ¼Ò¸¦ Á¶ÀÛÇÏ´Â °ÍÀÌ °¡´ÉÇÏ´Ù¸é ´Ù¸¥ Á¾·ùÀÇ OVERFLOW °ø°Ý ±â¹ýÀ̳ª FORMAT STRING °ø°Ý ±â¹ý¿¡µµ Àû¿ë½Ãų¼ö ÀÖ´Ù.



    2003. Cookie Spoofing ¹æÁö CGI ÇÁ·Î±×·¥ ¿ìȸÇϱâ -by Beist Security Research Group

º» ¹®¼­´Â Cookie Spoofing ÇØÅ· ±â¹ýÀ» ¹æÁöÇÏ´Â º¸¾È ¼Ö·ç¼ÇÀ» ¿ìȸÇÏ´Â ±â¹ý¿¡ ´ëÇØ¼­ ¼Ò°³Çϰí ÀÖ´Ù. Cookie Spoofing ¹æÁö¸¦ À§Çؼ­ ±âÁ¸ÀÇ Cookie Á¤º¸¿Í µ¿½Ã¿¡ »ç¿ëÀÚÀÇ ·Î±×ÀÎµÈ IP¸¦ ºñ±³ÇÏ´Â ¹æ¹ýÀ» ¸¹ÀÌ »ç¿ëÇϰí ÀÖ´Ù. ±×·¯³ª ÇØÄ¿°¡ Á÷Á¢ °ø°ÝÀ» ¼öÇàÇÏÁö ¾Ê°í, JavaScript¸¦ ÀÌ¿ëÇÏ¿© À¥ °ü¸®ÀÚ·Î ÇÏ¿©±Ý ½º½º·Î °ø°ÝÀ» ¼öÇàÇϵµ·Ï À¯µµÇÏ´Â ¹æ¹ýÀ¸·Î ¿ìȸÇÒ ¼ö Àִµ¥ ÀÌ·² °æ¿ì IP¸¦ ºñ±³ÇÏ´Â ¹æ½ÄÀÇ º¸¾È ¾Ë°í¸®ÁòÀ» ¿ìȸÇÏ¿© °ø°Ý¿¡ ¼º°øÇÒ ¼ö ÀÖ´Ù.



    2003. CGI ¿¡¼­ ƯÁ¤ ¹®ÀÚ¿­À» »ç¿ë ±ÝÁöÇÑ ¾Ë°í¸®Áò ¿ìȸÇϱâ -by Beist Security Research Group

ÇØÄ¿ÀÇ Cookie Sniffing °ø°ÝÀ» ¸·±â À§ÇØ ¸¹Àº º¸¾È ¾Ë°í¸®ÁòÀÌ ±¸ÇöµÇ°í ÀÖ´Ù. º» ¹®¼­´Â ÇØÄ¿ÀÇ Client Script Language »ç¿ëÀ» Á¦ÇÑÇϱâ À§ÇØ Æ¯Á¤ ¹®ÀÚ ÇÊÅ͸µ ¹æ¹ýÀ» »ç¿ëÇÏ´Â º¸¾È ¾Ë°í¸®ÁòÀ» ¿ìȸÇÏ´Â ¹æ¹ý¿¡ ´ëÇØ¼­ ¼Ò°³Çϰí ÀÖ´Ù. Unicode ¹®ÀÚ¸¦ ÀÌ¿ëÇÏ¿© ƯÁ¤ ¹®ÀÚ ÇÊÅ͸µ ¾Ë°í¸®Áò¿¡ Àû¿ëµÇÁö ¾Ê°í ¿ìȸÇÏ¿© Cookie Sniffing °ø°Ý¿¡ ¼º°øÇÏ´Â ±â¹ý¿¡ ´ëÇØ¼­ ¼Ò°³Çϰí ÀÖ´Ù.



    2003. Cookie Sniffing ¿¡ »ç¿ëµÉ ¼ö ÀÖ´Â ÀÚµ¿ °ø°Ý ÇÁ·Î±×·¥ -by Beist Security Research Group

Cookie SniffingÀº WWW ȯ°æ¿¡¼­ ÇØÄ¿°¡ »ç¿ëÀÚ³ª °ü¸®ÀÚÀÇ Cookie ȤÀº Session°ú °°ÀÌ Áß¿äÇÑ Á¤º¸¸¦ °¡·Îä´Â ±â¹ýÀ» ¸»Çϰí Cookie SpoofingÀº ÀÌ Á¤º¸¸¦ ÀÌ¿ëÇÏ¿© ÇØÄ¿°¡ ÀÚ½ÅÀÇ ½ÅºÐÀ» ¼ÓÀÌ´Â ÇàÀ§¸¦ ÇÏ´Â °ÍÀ» ¸»ÇÑ´Ù. ÀÌ Á¤º¸´Â À¯È¿ ½Ã°£ÀÌ ÀÖÀ»¼ö Àֱ⠶§¹®¿¡ ÇØÄ¿´Â Á¤º¸¸¦ ȹµæÇÑ ÈÄ ºü¸¥ ½Ã°£ ¾È¿¡ Spoofing °ø°ÝÀ» ¼öÇàÇØ¾ß Çϴµ¥ ÀÌ ¹®¼­´Â ÀÌ·¯ÇÑ °ø°ÝÀ» ÀÚµ¿À¸·Î ó¸®ÇÔÀ¸·Î½á À¯È¿ ½Ã°£¿¡ Á¦¾àÀÌ ¾ø´Â °ø°Ý ±â¹ý¿¡ ´ëÇØ¼­ ¼Ò°³ÇÏ¿´´Ù. ÇØÄ¿°¡ ¹Ì¸® ¸¸µé¾îµÐ °ø°Ý ÇÁ·Î±×·¥Àº Cookie¸¦ ¹Þ´Â µ¿½Ã¿¡, ÀÚµ¿È­ °ø°Ý ¾Ë°í¸®ÁòÀ» ÅëÇØ¼­ °ø°ÝÀ» ½ÃµµÇÑ´Ù. °ø°Ý¿¡ ÇÊ¿äÇÑ Á¤º¸¿Í, °ø°Ý¿¡ ¼öÇàÇÒ ÇൿÀ» ¹ÙÅÁÀ¸·Î, ÀÚµ¿À¸·Î Ÿ°Ù ¼­¹ö¿¡ Á¢¼ÓÇÏ¿© ÀÚµ¿È­ µÈ °ø°ÝÀ» ±¸ÇöÇÏ¿´´Ù. ÀÌ·¯ÇÑ °ø°Ý ÀÛ¾÷À¸·Î ÀÎÇØ Cookie³ª SessionÀÇ À¯È¿ ½Ã°£ ¾È¿¡ °ø°ÝÀ» ¼öÇàÇÒ¼ö ÀÖÀ» »Ó¸¸ ¾Æ´Ï¶ó °ü¸®ÀÚÀÇ ¹ß ºü¸¥ º¸¾È ´ëó¸¦ Èûµé°Ô ÇÒ ¼ö ÀÖ´Ù.





Copyright ¨Ï 2010 beistlab. All rights reserved