Nginx 1.29.7 ๋ฐ 1.28.3 ์—…๋ฐ์ดํŠธ์—์„œ 6๊ฐ€์ง€ ์ทจ์•ฝ์ ์ด ์ˆ˜์ •๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

์ƒˆ๋กœ์šด ๊ธฐ๋Šฅ ๊ฐœ๋ฐœ์ด ๊ณ„์† ์ง„ํ–‰ ์ค‘์ธ nginx 1.29.7 ๋ฉ”์ธ ๋ธŒ๋žœ์น˜๊ฐ€ ์ถœ์‹œ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์‹ฌ๊ฐํ•œ ๋ฒ„๊ทธ ๋ฐ ์ทจ์•ฝ์  ์ˆ˜์ • ๊ด€๋ จ ๋ณ€๊ฒฝ ์‚ฌํ•ญ๋งŒ ํฌํ•จ๋œ ๋ณ‘๋ ฌ ์•ˆ์ • ๋ธŒ๋žœ์น˜์ธ nginx 1.28.3๋„ ํ•จ๊ป˜ ์ถœ์‹œ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฒˆ ์—…๋ฐ์ดํŠธ๋Š” 6๊ฐœ์˜ ์ทจ์•ฝ์ ์„ ํ•ด๊ฒฐํ•˜๋ฉฐ, ๊ทธ์ค‘ 3๊ฐœ๋Š” ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ์šฐ๋ฅผ ์œ ๋ฐœํ•ฉ๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์  ์ค‘ 4๊ฐœ๋Š” ์‹ฌ๊ฐ๋„๊ฐ€ ๋†’์€ ์ˆ˜์ค€(10์  ๋งŒ์ ์— 8.8 ๋˜๋Š” 8.5์ )์œผ๋กœ ํ‰๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.

  • CVE-2026-27654 โ€” ngx_http_dav_module ๋ชจ๋“ˆ์—์„œ WebDAV COPY ๋ฐ MOVE ์š”์ฒญ์„ ์ฒ˜๋ฆฌํ•  ๋•Œ "location" ๋ธ”๋ก์— alias ์ง€์‹œ์–ด๊ฐ€ ์‚ฌ์šฉ๋˜๋Š” ๊ฒฝ์šฐ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์„ ์ด์šฉํ•˜๋ฉด ํŒŒ์ผ ๊ฒฝ๋กœ๋ฅผ ๋ณ€๊ฒฝํ•˜์—ฌ ๊ธฐ๋ณธ ๋””๋ ‰ํ„ฐ๋ฆฌ ์™ธ๋ถ€์˜ ํŒŒ์ผ์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๋ฌธ์ œ๋Š” Claude AI ๋ชจ๋ธ์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ฐœ๊ฒฌ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • CVE-2026-27784, CVE-2026-32647 โ€” ngx_http_mp4_module ๋ชจ๋“ˆ์—์„œ ํŠน์ˆ˜ํ•˜๊ฒŒ ์กฐ์ž‘๋œ mp4 ํŒŒ์ผ์„ ์ฒ˜๋ฆฌํ•  ๋•Œ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ์šฐ๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์„ ์•…์šฉํ•˜๋ฉด ๋‹จ์ˆœํ•œ ์‹œ์Šคํ…œ ์ถฉ๋Œ ์ด์ƒ์˜ ๊ฒฐ๊ณผ๊ฐ€ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • CVE-2026-27651 - ์ž˜๋ชป๋œ CRAM-MD5 ๋˜๋Š” APOP ์ธ์ฆ ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•  ๋•Œ NULL ํฌ์ธํ„ฐ ์—ญ์ฐธ์กฐ ์˜ค๋ฅ˜.
  • CVE-2026-28753 โ€” DNS์˜ PTR ๋ ˆ์ฝ”๋“œ๋ฅผ ์กฐ์ž‘ํ•˜์—ฌ ๊ณต๊ฒฉ์ž ๋ฐ์ดํ„ฐ๋ฅผ auth_http ์š”์ฒญ ๋ฐ ๋ฐฑ์—”๋“œ์™€์˜ SMTP ์—ฐ๊ฒฐ์—์„œ XCLIENT ๋ช…๋ น์— ์‚ฝ์ž…ํ•  ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์ .
  • CVE-2026-28755 - ์ŠคํŠธ๋ฆผ ๋ชจ๋“ˆ์—์„œ OCSP ์ธ์ฆ์„œ ํ™•์ธ ๊ฒฐ๊ณผ ์šฐํšŒ ์ทจ์•ฝ์ .

nginx 1.29.7์˜ ๋ณด์•ˆ ๊ด€๋ จ ๋ณ€๊ฒฝ ์‚ฌํ•ญ ์™ธ์— ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

  • ํŒจํ‚ท์„ ์—ฌ๋Ÿฌ ๊ฒฝ๋กœ์™€ ์„œ๋กœ ๋‹ค๋ฅธ ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ํ†ตํ•ด ๋™์‹œ์— ์ „๋‹ฌํ•  ์ˆ˜ ์žˆ๋Š” ๋ฉ€ํ‹ฐํŒจ์Šค TCP(MPTCP) ํ”„๋กœํ† ์ฝœ์— ๋Œ€ํ•œ ์ง€์›์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. "listen" ์ง€์‹œ๋ฌธ์— "multipath" ๋งค๊ฐœ๋ณ€์ˆ˜๊ฐ€ ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • "upstream" ๋ธ”๋ก์—์„œ ์‚ฌ์šฉ๋˜๋Š” "keepalive" ์ง€์‹œ๋ฌธ์— ์ด์ œ "local" ๋งค๊ฐœ๋ณ€์ˆ˜๊ฐ€ ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ด ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์ง€์ •ํ•˜๋ฉด, ์„œ๋กœ ๋‹ค๋ฅธ ์œ„์น˜ ๋ฐ ์„œ๋ฒ„ ๋ธ”๋ก์—์„œ ์ฐธ์กฐ๋˜๋Š” ๊ณตํ†ต ์—…์ŠคํŠธ๋ฆผ ์„œ๋ฒ„์— ๋Œ€ํ•œ ๋‹จ์ผ ์—ฐ๊ฒฐ์„ ๊ณต์œ ํ•˜๋Š” ๋Œ€์‹ , ๊ฐ ๋ธ”๋ก์ด ๋ณ„๋„์˜ ์—…์ŠคํŠธ๋ฆผ ์—ฐ๊ฒฐ์„ ์œ ์ง€ํ•ฉ๋‹ˆ๋‹ค.
  • "์—…์ŠคํŠธ๋ฆผ" ๋ธ”๋ก์—์„œ "keepalive" ์ง€์‹œ๋ฌธ์€ ๊ธฐ๋ณธ์ ์œผ๋กœ ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.
  • ํ”„๋ก์‹œ ๋ชจ๋“œ์—์„œ ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ ๊ธฐ๋ณธ ํ”„๋กœํ† ์ฝœ ๋ฒ„์ „์€ keep-alive๊ฐ€ ํ™œ์„ฑํ™”๋œ HTTP/1.1์ž…๋‹ˆ๋‹ค(keep-alive ์ง€์›์€ ngx_http_proxy_module ๋ชจ๋“ˆ์—์„œ ๊ธฐ๋ณธ์ ์œผ๋กœ ํ™œ์„ฑํ™”๋˜์–ด ์žˆ์œผ๋ฉฐ, "proxy_http_version" ์ง€์‹œ๋ฌธ์— "1.1" ๊ฐ’์ด ์„ค์ •๋˜์–ด ์žˆ๊ณ , "Connection" ํ—ค๋”์˜ ๊ธฐ๋ณธ ์ „์†ก์ด ์ค‘์ง€๋ฉ๋‹ˆ๋‹ค). HTTP/1.0๋งŒ ์ง€์›ํ•˜๋Š” ๋ฐฑ์—”๋“œ์— ๋Œ€ํ•œ ์•ก์„ธ์Šค๋ฅผ ํ—ˆ์šฉํ•˜๋Š” ์ด์ „ ๋™์ž‘์œผ๋กœ ๋˜๋Œ๋ฆฌ๋ ค๋ฉด ๋‹ค์Œ ์„ค์ •์„ ์ง€์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. proxy_http_version 1.0; proxy_set_header Connection "Close";

์ถœ์ฒ˜ : opennet.ru

DDoS ๋ณดํ˜ธ, VPS VDS ์„œ๋ฒ„๊ฐ€ ์žˆ๋Š” ์‚ฌ์ดํŠธ๋ฅผ ์œ„ํ•œ ์•ˆ์ •์ ์ธ ํ˜ธ์ŠคํŒ… ๊ตฌ์ž… ๐Ÿ”ฅ DDoS ๊ณต๊ฒฉ ๋ฐฉ์ง€ ๊ธฐ๋Šฅ์ด ํƒ‘์žฌ๋œ ์•ˆ์ •์ ์ธ ์›น์‚ฌ์ดํŠธ ํ˜ธ์ŠคํŒ…, VPS ๋ฐ VDS ์„œ๋ฒ„๋ฅผ ๊ตฌ๋งคํ•˜์„ธ์š” | ProHoster