Log17j 4 ์ทจ์•ฝ์ ์˜ ์˜ํ–ฅ์„ ๋ฐ›๋Š” 2๊ฐœ Apache ํ”„๋กœ์ ํŠธ

Apache Software Foundation์€ ์„œ๋ฒ„์—์„œ ์ž„์˜์˜ ์ฝ”๋“œ ์‹คํ–‰์„ ํ—ˆ์šฉํ•˜๋Š” Log4j 2์˜ ์‹ฌ๊ฐํ•œ ์ทจ์•ฝ์ ์— ์˜ํ•ด ์˜ํ–ฅ์„ ๋ฐ›๋Š” ํ”„๋กœ์ ํŠธ์— ๋Œ€ํ•œ ์š”์•ฝ ๋ณด๊ณ ์„œ๋ฅผ ๋ฐœํ‘œํ–ˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ Apache ํ”„๋กœ์ ํŠธ๋Š” ์ด ๋ฌธ์ œ์˜ ์˜ํ–ฅ์„ ๋ฐ›์Šต๋‹ˆ๋‹ค: Archiva, Druid, EventMesh, Flink, Fortress, Geode, Hive, JMeter, Jena, JSPWiki, OFBiz, Ozone, SkyWalking, Solr, Struts, TrafficControl ๋ฐ Calcite Avatica. ์ด ์ทจ์•ฝ์ ์€ GitHub.com, GitHub Enterprise Cloud, GitHub Enterprise Server๋ฅผ ํฌํ•จํ•œ GitHub ์ œํ’ˆ์—๋„ ์˜ํ–ฅ์„ ๋ฏธ์ณค์Šต๋‹ˆ๋‹ค.

Log4j 2 ์ทจ์•ฝ์ ์˜ ์˜ํ–ฅ์„ ๋ฐ›์ง€ ์•Š๋Š” Apache ํ”„๋กœ์ ํŠธ: Apache Iceberg, Guacamole, Hadoop, Log4Net, Spark, Tomcat, ZooKeeper ๋ฐ CloudStack.

๋ฌธ์ œ๊ฐ€ ์žˆ๋Š” ํŒจํ‚ค์ง€ ์‚ฌ์šฉ์ž๋Š” ๋ฆด๋ฆฌ์Šค๋œ ์—…๋ฐ์ดํŠธ๋ฅผ ๊ธด๊ธ‰ํ•˜๊ฒŒ ์„ค์น˜ํ•˜๊ฑฐ๋‚˜, โ€‹โ€‹Log4j 2 ๋ฒ„์ „์„ ๋ณ„๋„๋กœ ์—…๋ฐ์ดํŠธํ•˜๊ฑฐ๋‚˜, Log4j2.formatMsgNoLookups ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ true๋กœ ์„ค์ •ํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค(์˜ˆ: ์‹œ์ž‘ ์‹œ "-DLog4j2.formatMsgNoLookup=True" ํ‚ค ์ถ”๊ฐ€). . ์ง์ ‘ ์ ‘๊ทผ์ด ๋ถˆ๊ฐ€๋Šฅํ•œ ์‹œ์Šคํ…œ์˜ ์ทจ์•ฝ์ ์„ ์ฐจ๋‹จํ•˜๊ธฐ ์œ„ํ•ด ๊ณต๊ฒฉ์„ ํ†ตํ•ด Java ์„ค์ •์„ โ€œlog4j4.formatMsgNoLookups = trueโ€, โ€œcom.sun.jndi.rmi.objectโ€๋กœ ์„ค์ •ํ•˜๋Š” Logout2Shell ์ต์Šคํ”Œ๋กœ์ž‡ ๋ฐฑ์‹ ์ด ์ œ์•ˆ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. trustURLCodebase = falseโ€ ๋ฐ โ€œcom.sun.jndi.cosnaming.object.trustURLCodebase = falseโ€๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ œ์–ด๋˜์ง€ ์•Š๋Š” ์‹œ์Šคํ…œ์—์„œ ์ทจ์•ฝ์ ์ด ๋” ์ด์ƒ ๋‚˜ํƒ€๋‚˜์ง€ ์•Š๋„๋ก ์ฐจ๋‹จํ•ฉ๋‹ˆ๋‹ค.

์ตœ๊ทผ ์ทจ์•ฝ์  ์•…์šฉ ๊ด€๋ จ ํ™œ๋™์ด ํฌ๊ฒŒ ์ฆ๊ฐ€ํ–ˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, ์ฒดํฌํฌ์ธํŠธ๋Š” ์ž์‚ฌ์˜ ๊ฐ€์งœ ์‹œ์Šคํ…œ์— ๋Œ€ํ•œ ์•…์šฉ ์‚ฌ๋ก€๋ฅผ ๊ธฐ๋กํ–ˆ์Šต๋‹ˆ๋‹ค. ์„œ๋ฒ„ ์ตœ๊ณ ์กฐ์— ๋‹ฌํ–ˆ์„ ๋•Œ๋Š” ๋ถ„๋‹น ์•ฝ 100๊ฑด์˜ ๊ณต๊ฒฉ ์‹œ๋„๊ฐ€ ๋ฐœ์ƒํ–ˆ์œผ๋ฉฐ, Sophos๋Š” Log4j 2์˜ ํŒจ์น˜๋˜์ง€ ์•Š์€ ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ํ˜•์„ฑ๋œ ์ƒˆ๋กœ์šด ์•”ํ˜ธํ™”ํ ์ฑ„๊ตด ๋ด‡๋„ท์„ ๋ฐœ๊ฒฌํ–ˆ๋‹ค๊ณ  ๋ณด๊ณ ํ–ˆ์Šต๋‹ˆ๋‹ค.

์ถ”๊ฐ€ :

  • Couchbase, Elasticsearch, flink, solr, storm ๋“ฑ์„ ํฌํ•จํ•œ ๋งŽ์€ ๊ณต์‹ Docker ์ด๋ฏธ์ง€์—์„œ ์ทจ์•ฝ์ ์ด ํ™•์ธ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • ์ทจ์•ฝ์ ์€ MongoDB Atlas Search ์ œํ’ˆ์— ์กด์žฌํ•ฉ๋‹ˆ๋‹ค.
  • ์ด ๋ฌธ์ œ๋Š” Cisco Webex Meetings Server, Cisco CX Cloud Agent, Cisco ๊ณ ๊ธ‰ ์›น ๋ณด์•ˆ ๋ณด๊ณ , Cisco FTD(Firepower Threat Defense), Cisco ISE(Identity Services Engine), Cisco CloudCenter, Cisco DNA Center, Cisco BroadWorks๋ฅผ ํฌํ•จํ•œ ์—ฌ๋Ÿฌ Cisco ์ œํ’ˆ์— ์˜ํ–ฅ์„ ๋ฏธ์นฉ๋‹ˆ๋‹ค. ๋“ฑ.
  • ์ด ๋ฌธ์ œ๋Š” IBM WebSphere Application Server๋ฟ๋งŒ ์•„๋‹ˆ๋ผ OpenShift, OpenShift Logging, OpenStack Platform, Integration Camel, CodeReady Studio, Data Grid, Fuse ๋ฐ AMQ Streams์™€ ๊ฐ™์€ Red Hat ์ œํ’ˆ์—๋„ ์กด์žฌํ•ฉ๋‹ˆ๋‹ค.
  • Junos Space ๋„คํŠธ์›Œํฌ ๊ด€๋ฆฌ ํ”Œ๋žซํผ, Northstar Controller/Planner, Paragon Insights/Pathfinder/Planner์—์„œ ํ™•์ธ๋œ ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.
  • ๋งŽ์€ Oracle, vmWare, Broadcom ๋ฐ Amazon ์ œํ’ˆ๋„ ์˜ํ–ฅ์„ ๋ฐ›์Šต๋‹ˆ๋‹ค.

    ์ถœ์ฒ˜ : opennet.ru
DDoS ๋ณดํ˜ธ, VPS VDS ์„œ๋ฒ„๊ฐ€ ์žˆ๋Š” ์‚ฌ์ดํŠธ๋ฅผ ์œ„ํ•œ ์•ˆ์ •์ ์ธ ํ˜ธ์ŠคํŒ… ๊ตฌ์ž… ๐Ÿ”ฅ DDoS ๊ณต๊ฒฉ ๋ฐฉ์ง€ ๊ธฐ๋Šฅ์ด ํƒ‘์žฌ๋œ ์•ˆ์ •์ ์ธ ์›น์‚ฌ์ดํŠธ ํ˜ธ์ŠคํŒ…, VPS ๋ฐ VDS ์„œ๋ฒ„๋ฅผ ๊ตฌ๋งคํ•˜์„ธ์š” | ProHoster