11
Ʈ Ŀ´Ƽ ڵ ǰ 巯 Ѵٴ Ⱑ Ͼ ֽϴ. ܺ 巯 ʴ ִµ ¿ Ȳ , ű ۿ ٴ ϴ.
ù ְ : http://blog.hksecurity.net/2009/04/1.html
ActiveX ͵ , е Ƿ ˰ ִ ߽ ⸦ ϰڽϴ. ۿ ִ , ϰ , , ٺ ԵǾ 켱 帳ϴ.
[SSL ΰ?]
SSL ͳ ſ ־ ȣ ſ Ǿ ȣȭ ϳԴϴ. ȣ ˰ ǰ, ǰ, ü, Ǹ鼭 Ȯ ǰ Ǿϴ. Դٰ SSL ҽ Ǿ ְ ¼ҽ̱ پ ÷ ϰ ˴ϴ. ̷ ¼ҽ /߾ü Ͽ ֵ ͵ SSL θ ǰ ߿ ϳ ֽϴ.
[SSL ǥΰ?]
SSL ǥ̳ ƴϳĸ ϱ 켱 "ǥ"̶ ΰ ʿ䰡 ֽϴ.
TCP/IP ̱漺 Ǵ ̾ϴ. ó ܺ ʾҾ. "ǥ" ڸ ֽϴ. VLan µ Ǿ VLan Tag Cisco Ǵ ̾ϴ. VLan Tag ǥ Ǿ ֽϴ. ͵ "ǥ" Ǿ? װ ٷ ð ΰ θ Ȯ Ǿ ϴ.
"ð ȸ ⸦ ϰ RFC 縦 ؾߐ ǥ̴" ͺ " Ǹ ǥ ް ȴ" ̰ Դϴ. SSL ѱ Ǹ ȣȭ ǰ ȮǾ װ ǥ ڸ Դϴ.
SSL ȣ о(HTTP over SSL)Ӹ ƴ϶, VoIP о(SIP over TLS), ü ǰ(Network Appliane, C/S Application) Ǿ ֽϴ. SSL "ǥ" Ҹ ڰ ߰ ֽϴ( SSL õ RFC մϴ).
VoIP ſ ǥ 밨 ڸ ִ H323 SIP ڸ ְ ְ ż ϰ ֽϴ. "ǥ"̱ ƴ϶ " "̱ ǥ Ǵ Դϴ.
[SSL ]
" ϸ ϰ ۼ ?" ƴ϶ " ϸ ȣ Ǯ ?" ϴ ݴ 信 SSL Ͽϴ. Ŷ 鼭 ó ׳ "ȣȭ Ǿ ֱ" װ SSL , ð 鼭 װ SSL̾ ˰ Ǿϴ.
SSL θ ۳ ʺͿϴ. ڸ Ʈ ϴ 쿬 SSL ⸦ Ǿµ ˰ SSL ٽ ߾ Ͼ. ª ð̾ å д ͺ ־ϴ. ƹư ؼ SSL ؼ Ǿ θ ϱ Ͽϴ.
"鹮 ҿϰ"ٴ " ҿŸ" ¼ҼҸ ͳݿ ٿƼ ҽ м ϱ Ͽϴ. ̷ API 鼭 SSL ϰ Ǿ, ű "SSL ȸ ִ" ˾ Ǿϴ.
SSLм SSL м(Ͽ ˾ ) ð ɸ ʾҽϴ. α ٷ Ͼ(SSL ) . ̷ ݹ SSL ֳ. ˰ ƴϰ, ܱ ̹ ˷ Ծε .
ķ SSL ȸ α ڷ м ߽ϴ. "SSL Ǹ ȣȭ 100% ŷؼ ȵȴ" Ƚϴ. ٸ ȸ, ǥ ߾ϴ.
ٰ ǥ ȼ ִٴ ٸ ̵ ( http://www.youtube.com/watch?v=tSRtQiDfd90 ) ߰, ڵ Ϻ ־ ͵ Դϴ. ̾ ־ϴ.
, ... ̷ (SSL 100% Ͼ ȵȴٸ ϴ ) 忡 " ǥȭ ̰湮̶ ݴ븦 ϴ " ְڴٴ ϴ. ؼ п ñڽϴ.
[]
۵ ߽ϴ. ǥȭ Ưü ŷϸ鼭 ϻ ִµ, ó Ǿ θ ϴ. Ʈ Ⱑ ̽ȭDZ Ͽ, ش Ʈ Ǿ. ð Ⱦ ɱ⸦ ǵ帱 ִ ڱ ߾, Ⱦ迡 ߰ 忡 ִٰ ϰ ɽ Ǿϴ.
, ̾. Ʊ ؼ ο ߱ϰ ̾ϴ. ۰, ̿ Ͽ ٸ Ʈ鿡 ̽ȭ DZ Ͽ Ͼ ˴ϴ. ÷ Ҹ ִٰ ĵ, ϴ ε ̷ ְ Ÿ Դϴ, ʵ ... Ѵ Ȱϴ. ӿ ϰڽϴ. ̷ ͵ Դϴ.
ᱹ ߸ Ǿ ִ ٷ ۿ Ǿϴ. 㳪 (߸ κ ٷ ) " ǥȭ ϴ " ۿ Դϴ. ؾ ڱ. ϳϳ 並 Ⱦ , ¿ Դϴ.
---------------------------------------- Ϻι ----------------------------------------
Ⱦü ظؾ ѱͳ ŷ Ư
http://openweb.or.kr/?p=1073
3.
https ӿ ɼ ִٴ Ǵ ϵ ο ƴմϴ. , ̷ , Ŭ̾Ʈ, Ͻ ϳ Ǵ ̻ ̹ ڿ Ϻϰ ǵ Ȳ ó Ұմϴ. 쿡, ణ ڰ о ִٴ ƴϰ, Ʈ ߴٰ ϰ Էϴ ڰ ִٴ Դϴ. йȣ Էϰ ȮΡ , ڿ ǰ, ȭ鿡 ŷ ַ ְ ֽϴ١ ȳ ߵ ִٴ Դϴ.
, ̷ ó Ұմϴ. δ https ȸϱ Ͽ ARP Spoofing ̴, MIM ̴ Ϻη ( ߰ ū ݹ) ä ʿ䰡 , ξ ȿ ŵ ֽϴ.
, ѱ ÷ ̷ ư https ȸϴ ʿ ϴ. ణ ׳ http ̷ Դϴ.
https ִٰ ¼ ¼ ش Ⱦü ڴ ġ ڱ 빮 Ȱ¦ ΰ, ̿ â ź â 100% ʴٰ ϴ Ͱ ϴ.
---------------------------------------- Ϻι鳡 ----------------------------------------
>> ̷ , Ŭ̾Ʈ, Ͻ ϳ Ǵ ̻ ̹ ڿ Ϻϰ ǵ Ȳ ó Ұմϴ.
SSL MITM Attack Ư ȣƮ ϴ ƴմϴ. "" ڳ. DNS spoofing ϱ ȣƮ host ϴ ֱ ѵ, 帰 SSL MITM Attack Ͱ , Ʈũ ϴ Դϴ. Attacker ü(, Ŭ̾Ʈ) ǵ帮 ʰ ̷ ִٴ ̰, ǰ ֽô ʽϴ.
>> ణ ڰ о ִٴ ƴϰ, Ʈ ߴٰ ϰ Էϴ ڰ ִٴ Դϴ.
̽? SSL MITM Attack ȣƮ ۼ ˾ Դϴ. ǽ(¥ Ʈ )̳ Űΰſ ȵ˴ϴ. ü Ʋϴ.
>> йȣ Էϰ ȮΡ , ڿ ǰ, ȭ鿡 ŷ ַ ְ ֽϴ١ ȳ ߵ ִٴ Դϴ.
ϴ. ϰ ִ ͵ ǽ ϰ ֱ. SSL MITM Attack ظ ϰ ִٴ ְ ִ Դϴ. http://snoopspy.springnote.com/pages/589686 "sniffing - cipher text login" ϰ "funny story by changing packet" Ͻñ ٶϴ.
>> ARP Spoofing ̴, MIM ̴ Ϻη ( ߰ ū ݹ) ä ʿ䰡 ,
ARP spoofing ȣ Դϴ. ARP spoofing ߰ ũٴ ٰŴ ΰ? ǽ ߰DZ . ȵ˴ϴ.
>> https ִٰ ¼ ¼ ش Ⱦü
յ Ȳ ΰ ̱. ִ ⸦ Ϸ ߴ 鿴ٸ ¿ ڱ, "¼ ¼", " " ϴ ˴ϴ.
ǵ ģа ְ ǥϷ ߾ ۿ ؼ, â ؼ 亯 , αڰ ƴ ̻ Ż Ǹ ۿ ̿ 亯 ϴ.
---------------------------------------- Ϻι ----------------------------------------
http://openweb.or.kr/?p=1061#comment-24018
By ̰湮 — 2009.04.01 @ am8:17
youknowit / PKCS ־. ϴ( , ߸(ڸ) Ѿ ̶ ʰ մϴ) մϴ. ð ѹ ϰڽϴ. ׳ ø а ϴ ٵ ֹ̳ ڳ.
http://openweb.or.kr/?p=1073#comment-24033
By youknowit ? 2009.04.01 @ pm12:58
̰湮/
PKCS ־. ϴ١ ¾Ƽ 㡱̶ մϴ.
, û, ü, IT е ߿ PKCS е鵵 ֽϴ.
, ssl ϴ١ (κ ڸ Ѿ ) ۶߸ е, ü ϴ ÷ ߿ ssl ϴ ǰ ټ ִٴ ǵ ϰ ƹԳ Ͻôµ Ұմϴ.
, ̰ ѱ Դϴ.
---------------------------------------- Ϻι ----------------------------------------
PKCS Դϴ. PKCS ּ ϳ ʰ ٴ ߾ϴ. ƳɰŸų ϴ. Դϴ.
ڸ ˼ϱ, å ɾƼ ϴ Ÿ ƴϰ ٴϸ鼭 鼭 ϴ ŸԴϴ. ֽñ ٶϴ.
÷θ ѽŰ ñ ٶϴ. Web(HTTP, Բ ϴ ÷̶ ϴ ), VoIP(SIP), Ʈũ ǰ... оߴ ùԴϴ.
ϴ ϳ Ư ü SSL(or TLS) ǰ м(û) ִ ϰ, ÿ ش ǰ SSL ùٸ ֵ Ȼ ϴ Ϸ Ƿڸ ް ִ Դϴ. м(û) ϴ ༭ ϴ(ҹ Ƿڳ ܰ Ʈ ).
ٴ ƴ κ м(û) ߾ϴ. Ȯ ġ ʾƼ ո 찡 ֽϴ. SSL Ǵ Ȱȴٸ մ ſ , SSL öϰ ̿ϴ ϴ. case by case "ͻ ǰ SSL Ǵ ȰϽô մϴ" ݴϴ. Ŭ̾Ʈ Ǵ Ϲ SSL (SSL ϰ ߴ) ߰ ˴ϴ. ̰ ǴԴϴ.
ƹư SSL ǰ ִ 翬 ˰ ֱ, α ȿ SSL ֽϴ. ˾Ƶ 翬 дϴ. ̷ ϰ ϴ κ "SSL ̴ְ" ⸦ ۿ 翬 ? ʽÿ.
ó ؼ ַ ߾µ, ᱹ ȳ. ֽô ~ ۿ ϴ. ǵ ǰ ǥ ϰ ϴ , ̷ ʴ ̻ 忡 Ѵٰ Ǵ ؼԴϴ.
ѹα ͳ ̷ ϴ ̵ ϴ ƴ ˾ ּ ڽϴ.
|
|