๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๋ณด์•ˆ/์ทจ์•ฝ์  ๋ถ„์„

ํด๋ผ์šฐ๋“œ ์ทจ์•ฝ์  ์ ๊ฒ€ ๊ฐ€์ด๋“œ - ๊ฐœ์š”, ๊ณ„์ •๊ด€๋ฆฌ

by - ์˜คํŠธ - 2022. 12. 27.

https://isms.kisa.or.kr/main/csap/notice/

 

KISA ์ •๋ณด๋ณดํ˜ธ ๋ฐ ๊ฐœ์ธ์ •๋ณด๋ณดํ˜ธ๊ด€๋ฆฌ์ฒด๊ณ„ ์ธ์ฆ ํด๋ผ์šฐ๋“œ ๋ณด์•ˆ์ธ์ฆ์ œ ์ž๋ฃŒ์‹ค

 

isms.kisa.or.kr

2020๋…„ 12์›”์— ํ•œ๊ตญ์ธํ„ฐ๋„ท์ง„ํฅ์›์ด ๋ฐฐํฌํ•œ 'ํด๋ผ์šฐ๋“œ ์ทจ์•ฝ์  ์ ๊ฒ€ ๊ฐ€์ด๋“œ - ๋ณด์•ˆ์„ค์ •(CCE)' ๋‹ค์šด๋กœ๋“œ ๋งํฌ์ž…๋‹ˆ๋‹ค.

2022๋…„ 12์›” ํ˜„์žฌ๊นŒ์ง€ ์ถ”๊ฐ€๋กœ ๋ฐฐํฌํ•œ ๊ฐ€์ด๋“œ๊ฐ€ ์—†๊ธฐ์— 2020๋…„ 12์›”์— ๋ฐฐํฌ๋œ ๊ฐ€์ด๋“œ๊ฐ€ ์ตœ์‹ ์ž…๋‹ˆ๋‹ค.

 

 

ํ‰์†Œ์— ํด๋ผ์šฐ๋“œ ์„œ๋น„์Šค์— ๊ด€์‹ฌ์ด ์žˆ์–ด ๊ธฐ์—… ๋ฉด์ ‘์— ๋„์›€์ด ๋ ๋งŒํ•œ ๋…ผ๋ฌธ๊ณผ ์ž๋ฃŒ๋ฅผ ์ฐพ์•„๋ณด๋˜ ์ค‘ 'ํด๋ผ์šฐ๋“œ ์„œ๋น„์Šค์˜ ๋ณด์•ˆ ์ทจ์•ฝ์ ๊ณผ ๋Œ€์‘๋ฐฉ์•ˆ' ๋…ผ๋ฌธ๊ณผ 'ํด๋ผ์šฐ๋“œ ์ทจ์•ฝ์  ์ ๊ฒ€ ๊ฐ€์ด๋“œ ์œ ํŠœ๋ธŒ ๊ฐ•์˜'๋ฅผ ํ†ตํ•ด ๊ณต๋ถ€ํ•œ ๋‚ด์šฉ์„ ์ •๋ฆฌํ•ฉ๋‹ˆ๋‹ค.


๊ฐœ์š”

1) ํด๋ผ์šฐ๋“œ ์„œ๋น„์Šค

์ผ๋ฐ˜์ ์œผ๋กœ ์ž์›์„ ์†Œ์œ ํ•˜์ง€ ์•Š๊ณ  On-Demand ํ˜•์‹์œผ๋กœ ์ž์› ๋ฐ ํ™˜๊ฒฝ์„ ์ œ๊ณตํ•˜๋Š” ์„œ๋น„์Šค

 

2) CCE, CVE

CCE(Common Configuration Enumeration) : ์ทจ์•ฝํ•œ ์„ค์ •์— ๋Œ€ํ•œ ์ ๊ฒ€

CVE(Common Vulnerabilities and Exposures) : OS, Application ๊ณ ์œ ์˜ ์ทจ์•ฝ์ 

 

3) ์ฃผ์˜์‚ฌํ•ญ

์ˆ˜๋ก๋œ ์ ๊ฒ€ ๋ฐฉ๋ฒ•์€ ํด๋ผ์šฐ๋“œ ์ธ์ฆ ์‹ฌ์‚ฌ ๊ธฐ์ค€์ด๋ฉฐ ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ์—์„œ ์ ˆ๋Œ€์ ์ด์ง€ ์•Š์Œ

๋ณธ ๊ฐ€์ด๋“œ์˜ ์ˆ˜๋ก๋œ ํŒ๋‹จ๊ธฐ์ค€์€ ํด๋ผ์šฐ๋“œ ์ธ์ฆํ‰๊ฐ€ ์‹œ ์‚ฌ์šฉ๋˜๊ณ  ์žˆ๋Š” ์‚ฌํ•ญ


๊ณ„์ •๊ด€๋ฆฌ

XE-01. Default ๊ณ„์ • ๊ด€๋ฆฌ

๋ถˆํ•„์š”ํ•œ ๊ณ„์ • ์กด์žฌ ์œ ๋ฌด๋ฅผ ๊ฒ€์‚ฌํ•˜์—ฌ ์‚ญ์ œ (์ทจ์•ฝ๋„ ์ค‘)

# userdel lp

# userdel uucp

# userdel nuucp

๋กœ๊ทธ์ธ ์‰˜์„ /bin/false๋กœ ์ˆ˜์ •ํ•˜๋Š” ๊ฒƒ์€ ๋ณด์•ˆ์ƒ ๋ฌธ์ œ๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ ์‚ญ์ œ ๊ถŒ๊ณ 

 

XE-02. ์ผ๋ฐ˜๊ณ„์ • root ๊ถŒํ•œ ๊ด€๋ฆฌ

root ๋ฐ ์‹œ์Šคํ…œ ๊ณ„์ •์˜ ์˜์‹ฌ ๊ฐ€๋Š” ๋””๋ ‰ํ„ฐ๋ฆฌ ๋ฐ ํŒŒ์ผ์„ ์ •๊ธฐ์ ์œผ๋กœ ์กฐ์‚ฌํ•˜์—ฌ ์‚ญ์ œ (์ทจ์•ฝ๋„ ์ƒ)

root ๋ฐ ์‹œ์Šคํ…œ ๊ณ„์ •์„ ์ œ์™ธํ•˜๊ณ  UID๊ฐ€ 0์ธ ๊ณ„์ •์ด ์กด์žฌํ•˜๋Š” ๊ฒฝ์šฐ ์ทจ์•ฝ / ๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด ์–‘ํ˜ธ

(์—ฌ๊ธฐ์„œ UID๋ž€? ํŠน์ • ์ปดํ“จํ„ฐ ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ถ€์—ฌ๋˜๋Š” ์ˆซ์ž ๋˜๋Š” ์ด๋ฆ„์„ ์˜๋ฏธ)

# cat /etc/passwd

๋ช…๋ น์–ด ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ์˜ ํ•„๋“œ 3๋ฒˆ์งธ ๊ฐ’ ํ™•์ธ <- ์ •๋ณด๋ณด์•ˆ๊ธฐ์‚ฌ์— ์ž์ฃผ ์ถœ์ œ

# usermod -u 2002 test

UID ๊ฐ’์„ ๋ณ€๊ฒฝํ•˜๋ฉด ์กฐ์น˜ ๊ฐ€๋Šฅ(์œ„ ๋ช…๋ น์–ด๋Š” test ๊ณ„์ •์˜ UID๋ฅผ 2002๋กœ ๋ฐ”๊พธ๋Š” ๊ฒฝ์šฐ)

 

XE-03. passwd ํŒŒ์ผ ๊ถŒํ•œ ์„ค์ •

/etc/passwd ํŒŒ์ผ์˜ ์ ‘๊ทผ๊ถŒํ•œ์„ ์ œํ•œํ•˜๊ณ  ์žˆ๋Š”์ง€ ์ ๊ฒ€ (์ทจ์•ฝ๋„ ์ƒ)

# ls -al /etc/passwd

chmod, chown ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•˜์—ฌ ํŒŒ์ผ์˜ ๊ถŒํ•œ ๋ณ€๊ฒฝ

# chmod 644 /etc/passwd (777์ผ ๊ฒฝ์šฐ ๋ชจ๋“  ์†Œ์œ ์ž๊ฐ€ ๋†’์€ ๊ถŒํ•œ์„ ๊ฐ€์ง€๊ฒŒ ๋˜์–ด ์œ„ํ—˜)

# chown root /etc/passwd

 

XE-04. group ํŒŒ์ผ ๊ถŒํ•œ ์„ค์ •

/etc/group ํŒŒ์ผ์˜ ์ ‘๊ทผ๊ถŒํ•œ์„ ์ œํ•œํ•˜๊ณ  ์žˆ๋Š”์ง€ ์ ๊ฒ€ (์ทจ์•ฝ๋„ ์ƒ)

์ง„๋‹จ๊ธฐ์ค€, ์ง„๋‹จ๋ฐฉ๋ฒ•, ์กฐ์น˜๋ฐฉ๋ฒ•์€ XE-03๊ณผ ๋™์ผ

 

XE-05. ํŒจ์Šค์›Œ๋“œ ์‚ฌ์šฉ๊ทœ์น™ ์ ์šฉ

ํŒจ์Šค์›Œ๋“œ ์ถ”์ธก๊ณต๊ฒฉ์„ ํ”ผํ•˜๊ธฐ ์œ„ํ•˜์—ฌ ํŒจ์Šค์›Œ๋“œ์˜ ์ตœ์†Œ๊ธธ์ด ์„ค์ • ์ ๊ฒ€ (์ทจ์•ฝ๋„ ์ค‘)

# cat /etc/login.defs | grep -i "PASS_MAX_DAYS" # ์ตœ๋Œ€ ์‚ฌ์šฉ๊ธฐ๊ฐ„ ์„ค์ • ํ™•์ธ (๋‹จ์œ„ : ์ผ)

# cat /etc/login.defs | grep -i "PASS_MIN_DAYS" # ์ตœ์†Œ ์‚ฌ์šฉ๊ธฐ๊ฐ„ ์„ค์ • ํ™•์ธ (๋‹จ์œ„ : ์ผ)

# cat /etc/login.defs | grep -i "PASS_MIN_LEN" # ์ตœ์†Œ๊ธธ์ด ์„ค์ • ํ™•์ธ

/etc/login.defs์—์„œ ํŒจ์Šค์›Œ๋“œ ์ตœ๋Œ€ ์‚ฌ์šฉ๊ธฐ๊ฐ„์€ 90์ผ, ์ตœ์†Œ ์‚ฌ์šฉ๊ธฐ๊ฐ„์€ 1์ผ ์„ค์ •์œผ๋กœ ๋ณ€๊ฒฝ (๋‹จ์œ„ : ์ผ)

# vi /etc/login.defs

PASS_MIN_LEN 8

PASS_MAX_DAYS 90

PASS_MIN_DAYS 1

 

XE-06. ๋กœ๊ทธ์ธ์ด ๋ถˆํ•„์š”ํ•œ ๊ณ„์ • shell ์ œํ•œ

์ ‘๊ทผ์ด ๊ฑฐ์˜ ํ•„์š”ํ•˜์ง€ ์•Š์€ ์‚ฌ์šฉ์ž์—๊ฒŒ ์‰˜ ์ œํ•œํ•˜์—ฌ ์นจํ•ด ๊ฐ€๋Šฅ์„ฑ ์ค„์ž„ (์ทจ์•ฝ๋„ ์ค‘)

- /etc/passwd ํŒŒ์ผ์˜ ๊ณ„์ • ๋ณ„ shell ํ™•์ธ

- ์‹คํ–‰ ์‰˜์ด ๋ถˆํ•„์š”ํ•œ ๊ณ„์ • ๋ฐ ๋กœ๊ทธ์ธ์ด ํ•„์š”ํ•˜์ง€ ์•Š์€ ๊ณ„์ •์— nologin shell ๋ถ€์—ฌ

(daemon, bin, sys, listen, adm, nobody, nobody4, noaccess, diag, operator, games, gopher ๋“ฑ)

๋กœ๊ทธ์ธ์ด ํ•„์š” ์—†๋Š” ๊ณ„์ •์˜ shell ์„ค์ • ๋ณ€๊ฒฝ

# vi /etc/passwd

daemon:x:1:1::/:/sbin/ksh -> daemon:x:1:1::/:/sbin/false

(์œ ๋‹‰์Šค์˜ 3์š”์†Œ๋ž€? ์ปค๋„, ์‰˜, ํŒŒ์ผ์‹œ์Šคํ…œ)

 

XE-07. SU(Select User)์‚ฌ์šฉ ์ œํ•œ

su ๋ช…๋ น์„ ์‚ฌ์šฉํ•œ Password Guessing์„ ํ†ตํ•ด root ๊ถŒํ•œ ํš๋“ ๊ฐ€๋Šฅ (์ทจ์•ฝ๋„ ์ค‘)

/etc/pam.d/su ํŒŒ์ผ์— auth required pam_wheel.so use_uid ๋ผ์ธ์— ์ฃผ์„์ด ์—†๊ณ 

# cat /etc/pam.d/su | grep -v 'trust' | grep 'pam_wheel.so' | grep 'user_uid' : ์ฃผ์„ ์—ฌ๋ถ€ ํ™•์ธ ๋ช…๋ น์–ด

/etc/group ํŒŒ์ผ์˜ wheel ๊ทธ๋ฃน์— ๊ณ„์ •์ด ์ œํ•œ๋˜์–ด ์žˆ๋Š” ๊ฒฝ์šฐ ํ™•์ธ ํ•„์š”

(wheel ๊ทธ๋ฃน์„ ํ™•์ธํ•ด์•ผ ํ•˜๋Š” ์ด์œ ? ๊ด€๋ฆฌ์ž ๊ถŒํ•œ์„ ๋Œ€ํ–‰ํ•˜๋Š” ๊ทธ๋ฃน์„ ์˜๋ฏธํ•˜๊ธฐ ๋•Œ๋ฌธ)

# groupadd wheel

# usermod -G wheel username(์‚ฌ์šฉ์ž)

 

SU ์‚ฌ์šฉ ์ œํ•œ ์„ค์ • (๋ฆฌ๋ˆ…์Šค ์‹œ์Šคํ…œ์—์„œ ์ค‘์š”)

/etc/pam.d/su ํŒŒ์ผ์„ ์•„๋ž˜์™€ ๊ฐ™์ด ์„ค์ •

auto sufficient /lib/security/pam_rootok.so

auto required /lib/security/pam_wheel.so use_uid 


์ฐธ๊ณ  ๊ฐ•์˜https://www.youtube.com/watch?v=hbe2jbOoZWY 

 

์ข€ ๋” ๊ณต๋ถ€ํ•ด์•ผ ํ•  ๋‚ด์šฉ

1) XenServer๋ž€? ํด๋ผ์šฐ๋“œ ์‹œ์Šคํ…œ์—์„œ ๋งŽ์ด ์‚ฌ์šฉํ•˜๋Š” ํ•˜์ดํผ๋ฐ”์ด์ €

2) XenServer ์„ค์น˜ ๋ฐฉ๋ฒ• : ์ง์ ‘ ์‹ค์Šต ํ•„์š”

 

[์„œ๋ฒ„๊ตฌ์ถ•] ํด๋ผ์šฐ๋“œ ๋ง ๊ตฌ์ถ• ๊ธฐ๋ณธ - XenSERVER

์  ์„œ๋ฒ„๋กœ ๊ฐ€์ƒํ™”์˜ ๊ฐ€์ƒํ™” ํ•˜๊ธฐ ์  ์„œ๋ฒ„๋กœ ํด๋ผ์šฐ๋“œ ๊ธฐ๋ณธ ๋ง ๋งŒ๋“ค๊ธฐ ์ง‘์— xenserver๋ฅผ ์‹ค์ œ๋กœ ์˜ฌ๋ฆด ์ปดํ“จํ„ฐ๊ฐ€ ์—†๊ธฐ์—.... VM ware์— xenserver๋ฅผ ์˜ฌ๋ฆฌ๊ณ ์ž ํ•œ๋‹ค. 1. Xen์„œ๋ฒ„ ๋‹ค์šด๋กœ๋“œ ๋ฐ ์„ค์น˜ XenServer 7.0 Standa

imlena94.tistory.com