Microsoft º¸¾È ¾÷µ¥ÀÌÆ®°¡ Àû¿ëµÇÁö ¾ÊÀº Ãë¾àÇÑ Windows ½Ã½ºÅÛÀ» °Ü³É ÇÑ ¡®WannaCry(¿ö³ÊÅ©¶óÀÌ) ·£¼¶¿þ¾î¡¯ÀÇ °ø°ÝÀÌ Àü¼¼°èÀûÀ¸·Î ÁøÇàµÇ°í ÀÖ½À´Ï´Ù.
·£¼¶¿þ¾î¶õ ÄÄÇ»ÅÍ »ç¿ëÀÚÀÇ ÆÄÀÏÀ» ÀÎÁú·Î ±ÝÀüÀ» ¿ä±¸ÇÏ´Â ¾Ç¼º ÇÁ·Î±×·¥À¸·Î ¸ö°ªÀ» ¶æÇÏ´Â ·£¼¶(Ransom)°ú ¼ÒÇÁ¿þ¾î(Software)ÀÇ ÇÕ¼º¾îÀÔ´Ï´Ù.
WannaCry ·£¼¶¿þ¾î °¨¿° ½Ã ¹®¼ ÆÄÀÏ, DBÆÄÀϵîÀ» ¾ÏÈ£ÈÇϸç, ¾ÏÈ£¸¦ Ǫ´Â ´ë°¡·Î ºñÆ® ÄÚÀÎÀ» ¿ä±¸ÇÕ´Ï´Ù.
WannaCry ·£¼¶¿þ¾î ´Â Microsoft º¸¾È ¾÷µ¥ÀÌÆ®¸¦ Àû¿ëÇÏÁö ¾ÊÀº ȯ°æÀÇ Windows Ãë¾àÁ¡À» ¾Ç¿ëÇÑ °ÍÀ¸·Î, 2017³â 3¿ù ¹ßÇ¥µÈ Microsoft º¸¾È ¾÷µ¥ÀÌÆ® [MS17-010 Microsoft Windows SMB ¼¹ö¿ë º¸¾È ¾÷µ¥ÀÌÆ®(4013389)]¿¡¼ ÀÌ¹Ì ÀÌ Ãë¾àÁ¡ÀÌ ÇØ°áµÇ¾ú½À´Ï´Ù. MS17-010 º¸¾È ¾÷µ¥ÀÌÆ® Àû¿ëÇÏ¿© °ø°ÝÀ» ¿¹¹æÇÒ ¼ö ÀÖÀ¸¸ç, ¶ÇÇÑ ÇØ´ç ¾÷µ¥ÀÌÆ®°¡ ÀÌ¹Ì Àû¿ëµÈ Windows ½Ã½ºÅÛÀº À̹ø °ø°Ý¿¡¼ ¾ÈÀüÇÕ´Ï´Ù.
¾Æ·¡ÀÇ ´ëÀÀ ¹æ¹ýÀ» Àû¿ëÇÏ¿© À̹ø ·£¼¶¿þ¾î °¨¿°À¸·Î ÀÎÇÑ ÇÇÇØ°¡ ¾øÀ¸½Ã±â¸¦ ¹Ù¶ø´Ï´Ù.
[WannaCry ·£¼¶¿þ¾î ´ëÀÀ ¹æ¹ý]
l Á¶Ä¡ ¹æ¹ý
¨ç »ç¿ëÇÏ°í ÀÖ´Â ¹é½Å ¼ÒÇÁÆ®¿þ¾î¸¦ ÃÖ½ÅÀ¸·Î ¾÷µ¥ÀÌÆ®ÇÏ°í ½Ã½ºÅÛÀ» °Ë»çÇÕ´Ï´Ù.
¸¸ÀÏ ¼³Ä¡µÈ ¹é½Å ¼ÒÇÁÆ®¿þ¾î°¡ ¾ø´Ù¸é Microsoft ¹é½Å ¼ÒÇÁÆ®¿þ¾î¸¦ ÀÌ¿ëÇϽʽÿÀ.
Windows Defender ¿Í Microsoft Anti-Malware Á¦Ç°ÀÇ ÃֽŠ¿£Áø ¹öÀü 1.243.290.0 ¿¡¼ Ransom:Win32/WannaCrypt ·Î ÇØ´ç ¸È¿þ¾î°¡ Â÷´ÜµË´Ï´Ù.
- Windows 8.1 ¹× Windows 10 : Windows Defender ÀÌ¿ë
- Windows 7, Windows Vista: Microsoft Security Essentials ÀÌ¿ë
- Microsoft ¹«·á PCº¸¾È °Ë»ç : Microsoft Safety Scanner ÀÌ¿ë
¨è Windows Update ¶Ç´Â WSUSµîÀ» ÀÌ¿ëÇÏ¿© ½Ã½ºÅÛÀ» ÃÖ½ÅÀ¸·Î º¸¾È ¾÷µ¥ÀÌÆ® ÇÕ´Ï´Ù.
WUÀ» »ç¿ëÇÒ ¼ö ¾ø´Â °æ¿ì, Microsoft º¸¾È ¾÷µ¥ÀÌÆ® MS17-010 ¸¦ ¼öµ¿ ¼³Ä¡ÇÕ´Ï´Ù. OSº° ¼³Ä¡ °æ·Î´Â ¾Æ·¡¿Í °°½À´Ï´Ù.
Microsoft º¸¾È °øÁö MS17-010 – ±ä±Þ Microsoft Windows SMB ¼¹ö¿ë º¸¾È ¾÷µ¥ÀÌÆ®(4013389)
https://technet.microsoft.com/
Á¦Ç°¸í |
ÆÐÄ¡ ¹ßÇ¥ÀÏ |
MS17-010 º¸¾È ¾÷µ¥ÀÌÆ® ´Ù¿î·Îµå ¸µÅ© |
Windows XP |
||
Windows XP SP3¿ë º¸¾È ¾÷µ¥ÀÌÆ®(KB4012598) - Çѱ¹¾î |
5/13/2017 |
|
Security Update for Windows XP SP3 (KB4012598) - ¿µ¾î |
5/13/2017 |
|
Security Update for Windows XP SP2 for x64-based Systems (KB4012598) - ¿µ¾î |
5/13/2017 |
|
Windows Server 2003 |
||
Windows Server 2003¿ë º¸¾È ¾÷µ¥ÀÌÆ®(KB4012598) - Çѱ¹¾î |
5/13/2017 |
|
Security Update for Windows Server 2003 for x64-based Systems (KB4012598) - ¿µ¾î |
5/13/2017 |
|
x64 ±â¹Ý ½Ã½ºÅÛ¿ë Windows Server 2003 º¸¾È ¾÷µ¥ÀÌÆ®(KB4012598) - Çѱ¹¾î |
5/13/2017 |
|
Security Update for Windows Server 2003 (KB4012598) - ¿µ¾î |
5/13/2017 |
|
Windows Vista |
||
Windows Vista¿ë º¸¾È ¾÷µ¥ÀÌÆ®(KB4012598) - Çѱ¹¾î |
3/14/2017 |
|
Security Update for Windows Vista (KB4012598) - Windows Vista - ¿µ¾î |
3/14/2017 |
|
x64 ±â¹Ý ½Ã½ºÅÛ¿ë Windows Vista º¸¾È ¾÷µ¥ÀÌÆ®(KB4012598) - Çѱ¹¾î |
3/14/2017 |
|
Security Update for Windows Vista for x64-based Systems (KB4012598) - Windows Vista - ¿µ¾î |
3/14/2017 |
|
Windows Server 2008 |
||
Windows Server 2008¿ë º¸¾È ¾÷µ¥ÀÌÆ®(KB4012598) - Çѱ¹¾î |
3/14/2017 |
|
Security Update for Windows Server 2008 (KB4012598) - Windows Server 2008 - ¿µ¾î |
3/14/2017 |
|
x64 ±â¹Ý ½Ã½ºÅÛ¿ë Windows Server 2008 º¸¾È ¾÷µ¥ÀÌÆ®(KB4012598) - Çѱ¹¾î |
3/14/2017 |
|
Security Update for Windows Server 2008 for x64-based Systems (KB4012598) - Windows Server 2008 ¿µ¾î |
3/14/2017 |
|
Security Update for Windows Server 2008 for Itanium-based Systems (KB4012598) - Windows Server 2008 ¿µ¾î |
3/14/2017 |
|
Windows 8 |
||
Windows 8 ¿ë º¸¾È ¾÷µ¥ÀÌÆ®(KB4012598) - Çѱ¹¾î |
5/13/2017 |
|
Security Update for Windows 8 (KB4012598) - ¿µ¾î |
5/13/2017 |
|
x64 ±â¹Ý ½Ã½ºÅÛ¿ë Windows 8 º¸¾È ¾÷µ¥ÀÌÆ®(KB4012598) - Çѱ¹¾î |
5/13/2018 |
|
Security Update for Windows 8 for x64-based Systems (KB4012598) - ¿µ¾î |
5/13/2017 |
|
Windows Embedded |
||
March, 2017 Security Only Quality Update for Windows Embedded 8 Standard (KB4012214) |
3/14/2017 |
|
March, 2017 Security Only Quality Update for Windows Embedded 8 Standard for x64-based Systems (KB4012214) |
3/14/2017 |
|
XPe¿ë Windows XP SP3¿¡ ´ëÇÑ º¸¾È ¾÷µ¥ÀÌÆ®(KB4012598) »ç¿ëÀÚ ÁöÁ¤ Áö¿ø - Çѱ¹¾î |
5/13/2017 |
|
Security Update for Windows XP SP3 for XP embedded (KB4012598) - ¿µ¾î |
5/13/2017 |
|
WES09 ¹× POSReady 2009¿ë º¸¾È ¾÷µ¥ÀÌÆ®(KB4012598) - Çѱ¹¾î |
3/14/2017 |
|
Security Update for WES09 and POSReady 2009 (KB4012598) - Windows XP Embedded - ¿µ¾î |
3/14/2017 |
|
March, 2017 Security Only Quality Update for Windows Embedded Standard 7 (KB4012212) |
3/14/2017 |
|
March, 2017 Security Only Quality Update for Windows Embedded Standard 7 for x64-based Systems (KB4012212) |
3/14/2017 |
|
Windows 7 |
||
2017³â 3¿ù, x64 ±â¹Ý ½Ã½ºÅÛ¿ë Windows 7¿¡ ´ëÇÑ º¸¾È Àü¿ë Ç°Áú ¾÷µ¥ÀÌÆ®(KB4012212) |
3/14/2017 |
|
2017³â 3¿ù Windows 7 SP1 ¹× Windows Server 2008 R2 SP1¿ë º¸¾ÈÀü¿ë Ç°Áú ¾÷µ¥ÀÌÆ® (KB4012212) |
3/14/2017 |
|
Windows Server 2008 R2 |
||
2017³â 3¿ù, x64 ±â¹Ý ½Ã½ºÅÛ¿ë Windows Server 2008 R2¿¡ ´ëÇÑ º¸¾È Àü¿ë Ç°Áú ¾÷µ¥ÀÌÆ®(KB4012212) |
3/14/2017 |
|
March, 2017 Security Only Quality Update for Windows Server 2008 R2 for Itanium-based Systems (KB4012212) |
3/14/2017 |
|
Windows 8.1 |
||
2017³â 3¿ù, Windows 8.1¿¡ ´ëÇÑ º¸¾È Àü¿ë Ç°Áú ¾÷µ¥ÀÌÆ®(KB4012213) |
3/14/2017 |
|
2017³â 3¿ù, x64 ±â¹Ý ½Ã½ºÅÛ¿ë Windows 8.1¿¡ ´ëÇÑ º¸¾È Àü¿ë Ç°Áú ¾÷µ¥ÀÌÆ®(KB4012213) |
3/14/2017 |
|
Windows Server 2012 R2 |
||
2017³â 3¿ù, Windows Server 2012 R2¿¡ ´ëÇÑ º¸¾È Àü¿ë Ç°Áú ¾÷µ¥ÀÌÆ®(KB4012213) |
3/14/2017 |
|
Windows Server 2012 |
||
2017³â 3¿ù, Windows Server 2012¿¡ ´ëÇÑ º¸¾È Àü¿ë Ç°Áú ¾÷µ¥ÀÌÆ®(KB4012214) |
3/14/2017 |
|
|
|
|
ÃÖ½ÅÀÇ Windows 10 ´©Àû ¾÷µ¥ÀÌÆ® - 2017³â 5¿ù |
|
|
Windows 10 |
||
2017-05 Cumulative Update for Windows 10 for x64-based Systems (KB4019474) |
5/9/2017 |
|
2017-05 Cumulative Update for Windows 10 for x86-based Systems (KB4019474) |
5/9/2017 |
|
|
|
|
Windows 10 Version 1511 |
||
2017-05 Cumulative Update for Windows 10 Version 1511 (KB4019473) |
5/9/2017 |
|
2017-05 Cumulative Update for Windows 10 Version 1511 for x64-based Systems (KB4019473) |
5/9/2017 |
|
|
|
|
Windows 10 Version 1607 & Windows Server 2016 |
||
2017-05 Cumulative Update for Windows Server 2016 for x64-based Systems (KB4019472) |
5/9/2017 |
|
2017-05 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4019472) |
5/9/2017 |
|
2017-05 Cumulative Update for Windows 10 Version 1607 for x86-based Systems (KB4019472) |
5/9/2017 |
|
|
|
|
Windows 10 Version 1703 |
||
2017-05 Cumulative Update for Windows 10 Version 1703 for x64-based Systems (KB4016871) -Windows 10 |
5/9/2017 |
|
2017-05 Cumulative Update for Windows 10 Version 1703 for x86-based Systems (KB4016871) -Windows 10 |
5/9/2017 |
¨é º¸¾È ¾÷µ¥ÀÌÆ® MS17-010À» Àû¿ëÇÒ ¼ö ¾ø´Ù¸é, ¡®Microsoft SMBv1 »ç¿ë ¾ÈÇÔ¡¯À¸·Î ¼³Á¤ÇÕ´Ï´Ù.
WannaCry ·£¼¶¿þ¾î´Â Microsoft SMBv1 ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾àÁ¡(CVE-2017-0145) À» ÀÌ¿ëÇÕ´Ï´Ù. ÆÐÄ¡¸¦ ¼³Ä¡ÇÏÁö ¸øÇÏ´Â °æ¿ì SMBv1 »ç¿ëÀ» ÇØÁ¦ÇÏ¿© ÀÌ Ãë¾àÁ¡ ¾Ç¿ëÀ» ÇÇÇÒ ¼ö ÀÖÀ¸³ª °¡´ÉÇÑ ºü¸¥ ½ÃÀϳ»¿¡ ÆÐÄ¡¸¦ Àû¿ëÇÒ °ÍÀ» ±ÇÀåÇÕ´Ï´Ù.
[SMBv1 »ç¿ë ¾È ÇÔ]
Windows Vista ÀÌ»óÀ» ½ÇÇàÇÏ´Â °í°´
Microsoft ±â¼ú ÀÚ·á ¹®¼ 2696547À» ÂüÁ¶ÇϽʽÿÀ.
Windows 8.1 ¶Ç´Â Windows Server 2012 R2 ÀÌ»óÀ» ½ÇÇàÇÏ´Â °í°´ÀÇ ´ë¾È ¹æ¹ý
Ŭ¶óÀ̾ðÆ® ¿î¿µ üÁ¦:
1. Á¦¾îÆÇÀ» ¿°í ÇÁ·Î±×·¥À» Ŭ¸¯ÇÑ ÈÄ Windows ±â´É »ç¿ë/»ç¿ë ¾È ÇÔÀ» Ŭ¸¯ÇÕ´Ï´Ù.
2. Windows ±â´É â¿¡¼ SMB1.0/CIFS ÆÄÀÏ °øÀ¯ Áö¿ø È®ÀζõÀÇ ¼±ÅÃÀ» ÇØÁ¦ÇÏ°í È®ÀÎÀ» Ŭ¸¯ÇØ Ã¢À» ´Ý½À´Ï´Ù.
3. ½Ã½ºÅÛÀ» ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
¼¹ö ¿î¿µ üÁ¦:
4. ¼¹ö °ü¸®ÀÚ¸¦ ¿°í °ü¸® ¸Þ´º¸¦ Ŭ¸¯ÇÑ ÈÄ ¿ªÇÒ ¹× ±â´É Á¦°Å¸¦ ¼±ÅÃÇÕ´Ï´Ù.
5. ±â´É â¿¡¼ SMB1.0/CIFS ÆÄÀÏ °øÀ¯ Áö¿ø È®ÀζõÀÇ ¼±ÅÃÀ» ÇØÁ¦ÇÏ°í È®ÀÎÀ» Ŭ¸¯ÇØ Ã¢À» ´Ý½À´Ï´Ù.
6. ½Ã½ºÅÛÀ» ´Ù½Ã ½ÃÀÛÇÕ´Ï´Ù.
ÇØ°á ¹æ¹ýÀÇ ¿µÇâ. ´ë»ó ½Ã½ºÅÛ¿¡¼ SMBv1 ÇÁ·ÎÅäÄÝÀÌ »ç¿ëµÇÁö ¾Êµµ·Ï ¼³Á¤µË´Ï´Ù.
ÇØ°á ¹æ¹ýÀ» ½ÇÇà Ãë¼ÒÇÏ´Â ¹æ¹ý. ¹®Á¦ ÇØ°á ´Ü°è¸¦ ´Ù½Ã ¼öÇàÇÏ¸é¼ SMB1.0/CIFS ÆÄÀÏ °øÀ¯ Áö¿ø ±â´ÉÀ» È°¼º »óÅ·Πº¹¿øÇÕ´Ï´Ù.
¨ê ³×Æ®¿öÅ© ¹æȺ® ¹× Windows ¹æȺ®À» ÀÌ¿ëÇÏ¿© SMB °ü·Ã Æ÷Æ® Â÷´Ü
- SMB °ü·Ã Æ÷Æ® : 137(UDP), 138(UDP), 139(TCP), 445(TCP)
¡Ø SMB ¼ºñ½º Æ÷Æ® Â÷´Ü ½Ã °øÀ¯ ¹× ±âŸ °ü·Ã ¼ºñ½º°¡ ÁßÁöµÉ ¼ö ÀÖÀ¸´Ï Àû¿ë Àü ¹Ýµå½Ã ¿µÇâÀÌ ¾ø´ÂÁö Á¡°ËÇϽŠÈÄ Àû¿ëÇϽñ⠹ٶø´Ï´Ù.
- °ü·Ã ¹®¼ : KB 3185535 - ƯÁ¤ ¹æȺ® Æ÷Æ®¸¦ Â÷´ÜÇÏ¿© SMB Æ®·¡ÇÈÀÌ È¸»ç ȯ°æÀ» ºüÁ®³ª°¡Áö ¸øÇϵµ·Ï Çϱâ À§ÇÑ Áöħ
¾Æ·¡ ÆÄÀÏ È®ÀåÀÚ¸¦ °¡Áø ÆÄÀϵéÀ» ¾ÏÈ£È ÇÕ´Ï´Ù.
.123 |
.jpeg |
.rb |
.accdb |
.m3u |
.sln |
.avi |
.mov |
.stw |
.602 |
.jpg |
.rtf |
.aes |
.m4u |
.snt |
.backup |
.mp3 |
.suo |
.doc |
.js |
.sch |
.ai |
.max |
.sql |
.bak |
.mp4 |
.svg |
.3dm |
.jsp |
.sh |
.ARC |
.mdb |
.sqlite3 |
.bat |
.mpeg |
.swf |
.3ds |
.key |
.sldm |
.asc |
.mdf |
.sqlitedb |
.bmp |
.mpg |
.sxc |
.3g2 |
.lay |
.sldm |
.asf |
.mid |
.stc |
.brd |
.msg |
.sxd |
.3gp |
.lay6 |
.sldx |
.asm |
.mkv |
.std |
.bz2 |
.myd |
.sxi |
.7z |
.ldf |
.slk |
.asp |
.mml |
.sti |
.c |
.myi |
.sxm |
.cgm |
.nef |
.sxw |
.cmd |
.odg |
.tbk |
.cs |
.odt |
.tiff |
.class |
.odb |
.tar |
.cpp |
.odp |
.tgz |
.csr |
.onetoc2 |
.txt |
.dbf |
.otp |
.vb |
.crt |
.ods |
.tif |
.csv |
.ost |
.uop |
.dch |
.ots |
.vbs |
.dip |
.PAQ |
.vmdk |
.db |
.otg |
.uot |
.der" |
.ott |
.vcd |
.djvu |
.pas |
.vmx |
.docm |
.pem |
.vsd |
.dif |
.p12 |
.vdi |
.docb |
|
.vob |
.docx |
.pfx |
.vsdx |
.dot |
.php |
.wav |
.flv |
.pps |
.xlm |
.ibd |
.psd |
.xltx |
.dotm |
.pl |
.wb2 |
.frm |
.ppsm |
.xls |
.iso |
.pst |
.xlw |
.dotx |
.png |
.wk1 |
.gif |
.ppsx |
.xlsb |
.jar |
.rar |
.zip |
.dwg |
.pot |
.wks |
.gpg |
.ppt |
.xlsm |
.edb |
.potm |
.wma |
.gz |
.pptm |
.xlsx |
.eml |
.potx |
.wmv |
.h |
.pptx |
.xlt |
.fla |
.ppam |
.xlc |
.hwp |
.ps1 |
.xltm |
.java |
.raw |
|
l Ãß°¡ Á¤º¸
- Microsoft Security Response Center Blog, Customer Guidance for WannaCrypt attacks : https://blogs.technet.
- Microsoft Malware Protection Center Blog, WannaCrypt ransomware worm targets out-of-date systems: https://blogs.technet.
- Microsoft º¸¾È °øÁö MS17-010 – ±ä±Þ Microsoft Windows SMB ¼¹ö¿ë º¸¾È ¾÷µ¥ÀÌÆ®(4013389) : https://technet.microsoft.com/
- CVE-2017-0145 | Windows SMB ¿ø°Ý ÄÚµå ½ÇÇà Ãë¾à¼º : https://portal.msrc.microsoft.