๋ฌด๋ฃŒ ๋ฐ”์ด๋Ÿฌ์Šค ๋ฐฑ์‹  ํŒจํ‚ค์ง€ ClamAV 0.103.3 ์—…๋ฐ์ดํŠธ

๋ฌด๋ฃŒ ๋ฐ”์ด๋Ÿฌ์Šค ๋ฐฑ์‹  ํŒจํ‚ค์ง€ ClamAV 0.103.3์˜ ๋ฆด๋ฆฌ์Šค๊ฐ€ ์ƒ์„ฑ๋˜์—ˆ์œผ๋ฉฐ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์„ ์ œ์•ˆํ•ฉ๋‹ˆ๋‹ค.

  • ClamAV๊ฐ€ ๋ฏธ๋Ÿฌ ๋„คํŠธ์›Œํฌ ๋Œ€์‹  CDN(์ฝ˜ํ…์ธ  ์ „์†ก ๋„คํŠธ์›Œํฌ)์„ ์‚ฌ์šฉํ•˜๋„๋ก ๋ณ€ํ™˜๋˜์—ˆ๊ณ  dat ํŒŒ์ผ์— ๋” ์ด์ƒ ๋ฏธ๋Ÿฌ ์ •๋ณด๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์— mirrors.dat ํŒŒ์ผ ์ด๋ฆ„์ด freshclam.dat๋กœ ๋ณ€๊ฒฝ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. Freshclam.dat๋Š” ClamAV ์‚ฌ์šฉ์ž ์—์ด์ „ํŠธ์— ์‚ฌ์šฉ๋˜๋Š” UUID๋ฅผ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค. ์ด๋ฆ„์„ ๋ฐ”๊ฟ”์•ผ ํ•˜๋Š” ์ด์œ ๋Š” FreshClam ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒํ•œ ๊ฒฝ์šฐ ์ผ๋ถ€ ์‚ฌ์šฉ์ž์˜ ์Šคํฌ๋ฆฝํŠธ๊ฐ€ Mirrors.dat๋ฅผ ์‚ญ์ œํ–ˆ์ง€๋งŒ ์ด์ œ ์ด ํŒŒ์ผ์—๋Š” ์‹๋ณ„์ž๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์–ด ์†์‹ค์ด ํ—ˆ์šฉ๋˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค.
  • ENGINE_OPTIONS_FORCE_TO_DISK ์˜ต์…˜์ด ํ™œ์„ฑํ™”๋œ ๊ฒฝ์šฐ ํŒŒ์ผ ๊ฒ€์ƒ‰ ์„ฑ๋Šฅ์ด ์ €ํ•˜๋˜๋˜ ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • clamd ๊ตฌ์„ฑ ํŒŒ์ผ์˜ ExcludePath ์„ค์ •๊ณผ ํ•จ๊ป˜ "--fdpass --multiscan" ์˜ต์…˜์„ ์‚ฌ์šฉํ•  ๋•Œ ClamDScan ํ”„๋กœ์„ธ์Šค์˜ ์ถฉ๋Œ์ด ์ˆ˜์ •๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • clamav๋ฅผ ๋ฃจํŠธ๋กœ ์‹คํ–‰ํ•  ๋•Œ DatabaseOwner ์„ค์ •์— ์ •์˜๋œ ์‚ฌ์šฉ์ž ๋Œ€์‹  ๋ฃจํŠธ๋ฅผ mirrors.dat ํŒŒ์ผ์˜ ์†Œ์œ ์ž๋กœ ์„ค์ •ํ•˜๋Š” ๋ฌธ์ œ๋ฅผ ์ˆ˜์ •ํ–ˆ์Šต๋‹ˆ๋‹ค.
  • ์‹ค์ˆ˜๋กœ ์ฐจ๋‹จ๋˜๋Š” ๊ฒƒ์„ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•ด DatabaseMirror๊ฐ€ clamav.net์„ ์‚ฌ์šฉํ•  ๋•Œ HTTPUserAgent ์„ค์ •์ด ๋น„ํ™œ์„ฑํ™”๋˜๋„๋ก ํ™œ์„ฑํ™”ํ–ˆ์Šต๋‹ˆ๋‹ค.
  • ์ทจ์•ฝ์  CVE-2010-1205(Heuristics.PNG.CVE-2010-1205)๋ฅผ ์•…์šฉํ•˜๋ ค๋Š” ์‹œ๋„๋ฅผ ํƒ์ง€ํ•˜๋ ค๋ฉด ์ด์ œ ClamScan ๋งค๊ฐœ๋ณ€์ˆ˜ โ€œโ€”alert-broken-mediaโ€ ๋˜๋Š” โ€œAlertBrokenMediaโ€ ์„ค์ •์„ ๋ช…์‹œ์ ์œผ๋กœ ํ™œ์„ฑํ™”ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ทจ์•ฝ์ ์€ ์˜ค๋žซ๋™์•ˆ ๋ชจ๋“  ๊ณณ์—์„œ ํ•ด๊ฒฐ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • Cloudflare๊ฐ€ ์ฟ ํ‚ค "__cfduid"๋ฅผ ๋ณ€๊ฒฝํ•œ ํ›„ ClamSubmit์ด ์ถฉ๋Œํ•˜๋Š” ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ–ˆ์Šต๋‹ˆ๋‹ค.

์ถœ์ฒ˜ : opennet.ru

์ฝ”๋ฉ˜ํŠธ๋ฅผ ์ถ”๊ฐ€