²Ä0039´Á¡E2016.12.20 µo¦æ
ISSN 2077-8813

­º­¶ >±MÃD³ø¾É

WordPress Pingback DDoS§ðÀ»¤ÀªR

§@ªÌ¡G§õ¬ü¶² / »OÆW¤j¾Ç­pºâ¾÷¤Î¸ê°Tºô¸ô¤¤¤ßµ{¦¡³]­p®v
¥»¤åÂà¸ü¦Û»OÆW¤j¾Ç­p¸ê¤¤¤ß¥_°Ï¾Ç³N¸ê°T¦w¥þºû¹B¤¤¤ß

±Ð¨|³¡©ó103¦~ªì±À°Ê°ª¤¤½Òºõ·L½Õ¡A¥Ñ©ó¬ÛÃö¸ê°T¥¼¤½¶}¡A¥[¤W³¡¤À¤º®e¤Þµoª§Ä³¡A¤Ï¹ï¾Ç¥Íµo°_¤Ï½Òºõ·L½Õ§Üij¦æ°Ê¡A¨Ã¤Þ°_ª¾¦WÀb«È¹ÎÅé¡u°Î¦WªÌ¡]Anonymous¡^¡vªºÃöª`¡C¡u°Î¦WªÌ¡v¬°Án´©¤Ï½Òºõ·L½Õ¦æ°Ê¡A¦bµoªíÁn©ú«á¡A±µµÛ¹ï¦h­Ó¬F©²³¡ªùºô¯¸µo°Êºô¸ô§ðÀ»¡AÅõºÈ¦h­Óºô¯¸¡A¸Ó¦¸§ðÀ»°£¤F¸û¬°ª¾¦WªºTorshammer¥H¥~¡A¤]°ÑÂø¤F§Q¥Î°Ñ¦Ò©Î³s½uWordPressºô¯¸¦^³øªºPingback¥\¯à¶i¦æDDoS§ðÀ»¡C¥»¤å±N¹ï¦¹¶i¦æ¤ÀªR»¡©ú¡A¨Ã´£¨Ñ¸ê¦w«Øij¡C

°ª¤¤½Òºõ·L½Õ¤Þµo±Ð¨|³¡ºô¯¸¾DDDOS§ðÀ»
±Ð¨|³¡©ó103¦~ªì±À°Ê°ª¤¤½Òºõ·L½Õ¡A­pµe104¦~8¤ë1¤é¥¿¦¡¤W¸ô¡A¥Ñ©ó°ª¤¤½Òºõ·L½Õ¤§¬ÛÃö¸ê°T¥¼¤½¶}¡A¥[¤W³¡¤À¤º®e¤Þµoª§Ä³¡C¤Ï¹ï½Òºõ·L½Õªº¾Ç¥Í¦b±Ð¨|³¡¡B¥ßªk°|«e§Üij¡A¨Ã­n¨D¬F©²¬ÛÃö¤H­û¥X­±»¡©ú¡C
»OÆW¤Ï½Òºõ·L½Õ§Üij¦æ°Ê¤]¤Þ°_ª¾¦WÀb«È¹ÎÅé¡u°Î¦WªÌ¡]Anonymous¡^¡vªºÃöª`¡A¡u°Î¦WªÌ¡v¨È¬w¤ä³¡¡]Anonymous Asia¡^©ó104¦~7¤ë30¤é¦bªÀ¸sºô¯¸¤W¡]¥Ø«e¤w¾DÃö³¬¡A¤U¹Ï¤@©Ò¥Ü¡^µo¤åÁn©ú±N¤ä«ù»OÆWªº¤Ï½Òºõ·L½Õ§Üª§¦æ°Ê¡A¹ï¬ÛÃöªº¬F©²¾÷Ãö²Õ´¶i¦æºô¸ô§ðÀ»¡C
¡u°Î¦WªÌ¡v¬°Án´©¤Ï½Òºõ·L½Õ¦æ°Ê¡A¦bµoªíÁn©ú«á¡A±µµÛ¹ï¦h­Ó¬F©²³¡ªùºô¯¸µo°Êºô¸ô§ðÀ»¡A¦¹¦¸§ðÀ»¦æ°ÊÅõºÈ¤F¥]§t±Ð¨|³¡¡B¸gÀÙ³¡¡B°ê¥ÁÄÒµ¥¦h­Ó¬F©²³¡ªù¦b¤ºªººô¯¸¡A¥D­n¥Øªº­n¼vÅTºô¯¸¥¿±`¹B§@¡AÅý³o¨Çºô¯¸µLªk¥¿±`¹ï¥~´£¨ÑªA°È¡C


¹Ï¤@ 

¤À´²¦¡ªýÂ_ªA°È§ðÀ»(DDoS, Distributed Denial Of Service)
DDoS¡]Distributed Denial of Service¡^¤À´²¦¡ªýÂ_ªA°È§ðÀ»¬ODoS¡]Denial of Service¡^ªýÂ_ªA°È§ðÀ»ªº¶i¶¥ª©¡CDoS¬O¤@ºØ©ú½T¥B´c·Nªººô¸ô§ðÀ»¤â¬q¡A§ðÀ»ªÌ§Q¥Î¦UºØ¤è¦¡¹ï¥Ø¼Ð¥D¾÷µo°e¤j¶q«Ê¥]¡A¨Ã­n¨D¥Ø¼Ð¥D¾÷¶Ç°e¦^ÂаT®§¡A¨Ï±o¥Ø¼Ð¥D¾÷ªººô¸ô¸ê·½©Î¨t²Î¸ê·½¯ÓºÉ¡A¶i¦Ó¨Ï±o¥Ø¼Ð¥D¾÷µLªk´£¨ÑªA°È©Î¥D¾÷ºÞ²zªÌµLªk¦s¨ú¨Ï¥Îºô¸ô¸ê·½¡C
¦ÓDDoS«h¬O«ü¤À´²¦¡ªºDoS¦æ¬°ªº¶°¦X¡A¦¹ºØ§ðÀ»¤â¬q«Ø¥ß¦bDoSªº°ò¦¤W¡A¦P®É§Q¥Î¤F¤À´²©ó¦U¦aªº¥D¾÷¡]³o¨Ç¥D¾÷³\¤j¦h³£¬O³Q§ðÀ»ªÌ§ð³´ªº¹q¸£¡A³qºÙ¬°¡u¦×Âû¡v©Î¡uíL«Í¡v¥D¾÷¡^¨Ó²Õ¦¨©Ò¿×ªºíL«Íºô¸ô¥Hµo°Ê¤j³W¼ÒªºDDoS§ðÀ»¡A³oºØ§ðÀ»°£¤F¥i¥HÅõºÈ¥Ø¼Ð¥D¾÷ªººô¸ô¡A¦³¤ß¤H¤h¬Æ¦Ü¥i¥H§Q¥Î¥¦¶i¦æ´c·Nªº°Ó·~¬¡°Ê©Î¬O¬Fªv¦æ¬°¡A¹³¬O§ðÀ»°Ó·~¤WªºÄvª§¹ï¤â¡BÅõºÈ§ë²¼ºô­¶µ¥µ¥¡C
²¦Ó¨¥¤§¡ADoSÄÝ©ó¤@ºØ§Q¥Î¦Û¨­¥D¾÷§ðÀ»¥Ø¼Ð¥D¾÷¡]¤@¹ï¤@©Î¤@¹ï¦h¡^ªº´c·N¦æ¬°¡A¦ÓDDoS§ðÀ»«h¬O¤@ºØ¨Ï¥Î¦UºØ¤è¦¡¾Þ§@¤Î§Q¥Î¦h¥x¥D¾÷§ðÀ»ÅõºÈ¥Ø¼Ð¥D¾÷¡]¦h¹ï¤@©Î¦h¹ï¦h¡^ªº´c·N¦æ¬°¡C
Á|¨Ò¨Ó»¡¡A¬Y®aÀ\¶¼·~ªÌ¥u¦³¹q¸Ü¥~°eªºªA°È¡A¦P¦æ¬°¤F¥´À»¦¹Ävª§¹ï¤â¡A©ó¬O­t³d¤HºÆ¨g¼·¥´¦¹À\¶¼·~ªÌªº­qÀ\¹q¸Ü¡]§Y¬°DoS¦æ¬°¡^¡A³y¦¨¨ä¥L«È¤HµLªk¼·¥´¹q¸Ü¶i¨Ó¶i¦æ­qÀ\ªºªA°È¡AÀ\¶¼·~ªÌ¤]µLªk¹ï¤W´å¼t°Ó¼·¥´¹q¸Ü­qÁʭ쪫®Æ¡A¦¹®É³o®aÀ\¶¼·~ªÌ´N¦³¥i¯à³Q»~¥H¬°¤w¸g¨S¦³Àç·~©Î¬O¨ä¥L­ì¦]¦Ó´c©Ê­Ë³¬¡]DoS¥Øªº¡^¡C¦P¤W­±ªºª¬ªp¡A­Y¬O­t³d¤H¶±¥Î¤F¦h¦W¤H¤â¶i¦æ¦P¼Ë¼·¥´¹q¸Üªº´c·N¦æ¬°¡A«h©µ¦ù¬°©Ò¿×ªºDDoS¦æ¬°¡C
«e­±©Ò´£¨ìªºDDoS§ðÀ»¤âªkÄÝ©ó¦­´Á±`¨£ªºª½±µ©ÊªºDDoS§ðÀ»¡A¦ýÀHµÛ§ðÀ»¤âªkªººtÅÜ¡A²{¦b¤]¥X²{¤F©Ò¿×ªº¤Ï®g©ÊªºDDoS§ðÀ»¡C
ª½±µ©Êªº§ðÀ»³Ì¬°±`¨£¥B©ú½T¡A¥D­n´N¬O§Q¥Î®ø¯ÓÀW¼e©Î¸ê·½ªº¤â¬q¡A¨Ó¹F¦¨¨Ï¥ÎªÌµLªk¦s¨úºô¸ô¸ê·½ªº¥Øªº¡C¦Ó¤Ï®g©Êªº§ðÀ»¡A«h¬O§ðÀ»ªÌ§Q¥Î¤w¸g³Q±±¨îªº¦h¥xíL«Í¹q¸£¡A¦b°°³y¥Ø¼Ð¥D¾÷ªºIP¦ì§}«á¡A¹ï¦h¥xºÞ²z¤£°÷ÄYÂÔ¤§¥D¾÷µo¥X¸ß°Ý«Ê¥]¨Ã­n¨D¦^ÂСA¦Ó³o¨Ç³Q¸ß°Ýªº¥D¾÷¸s¦^ÂФj¶q«Ê¥]µ¹°°³yIP¦ì§}®É¡A³y¦¨¯u¥¿ªº¥Ø¼Ð¥D¾÷±µ¦¬¨ì¨Ó¦Û¥|­±¤K¤è¤j¶qªº¦^ÂЫʥ]¡A¶i¦Ó³y¦¨©ñ¤j¥B¤Ï®gªº§ðÀ»®ÄªG¡C³oºØ¤è¦¡¤]¯à¹F¨ìDDoS©ñ¤j§ðÀ»ªº®ÄªG¡A³y¦¨¥Ø¼Ð¥D¾÷µLªk¥¿±`¦s¨úºô¸ô¸ê·½¡A¨Ã¼W¥[§ðÀ»ªÌ³Q°l¬d¨ìªºÃø«×¡C

DDoS¤âªk-WordPress Pingback
³o¦¸¤Ï½Òºõ·L½Õ¤Þµoªº§ðÀ»¡A°£¤F¸û¬°ª¾¦WªºTorshammer¥H¥~¡A¤]°ÑÂø¤F§Q¥Î°Ñ¦Ò©Î³s½uWordPressºô¯¸¦^³øªºPingback¥\¯à¶i¦æDDoS§ðÀ»¡C
Pingback¬OWordPress¤¤¤º«Øªº¥\¯à¤§¤@¡A·í¦³¤H¤Þ¥Î¤å³¹®É¡A¦¹¥\¯à¥i¥H¥Î¨Ó³qª¾§@ªÌ¬ÛÃö¸ê°T¡C¦b¦¹¦¸ªº±Ð¨|³¡§ðÀ»¨Æ¥ó¤¤¡A¦¹¥\¯à«o¾D¦³¤ß¤HÀݥΦ¨¬°DDoSªº§ðÀ»¤âªk¡C
Pingbackªº¥\¯à¥»·N¤W¬O§Æ±æ·íºô¸ô¤Wªº¤å³¹©¼¦¹¥æ¬y®É¡A¯à¦³¤@­Ó¤¬¬Û§iª¾ªº¾÷¨î¡A¦ý¬O´c·N§ðÀ»ªÌ§Q¥Î¦¹¾÷¨î¡A°°³y¨ü®`¥D¾÷ªºIP¡A¨Ã°w¹ï¤j¶q¹w³]¶}±ÒPingbackªºWordPress¥D¾÷¡A³z¹L¯S»sªºXML-RPC¤º®eµo°e½Ð¨D¡]¹Ï¤G½s¸¹1¡^¡A§Q¥ÎPingbackªº¥\¯à¹ï¨ü®`¥D¾÷µo¥X¤j¶qHTTP Request«Ê¥]¡]¹Ï¤G½s¸¹2¡^¡AÂǦ¹¹F¨ìDDoSªº§ðÀ»®ÄªG¡C


¹Ï¤G 

¬°¤F²`¤J¤F¸Ñ¨ä¹B§@¾÷¨î¡A§Ú­Ì°¼¿ýWordPress¨Ï¥ÎPingback¥\¯à®É±o¨ìªº«Ê¥]¸ê°T(¦p¹Ï¤T©Ò¥Ü)¨Ã»¡©ú¦p¤U¡C´c·N§ðÀ»ªÌ·|¸m´«½s¸¹1¤¤¶À©³¼Ð°OªºIP¡A¨Ã¦V¤@²Õ©Î¦h²Õªº¬õ©³¼Ð°OIP¡]¶}±ÒPingback¥\¯àªºWPºô¯¸¡^µo°e¤Þ¥Î¤å³¹ªº½Ð¨D¡]¯S»sªºXML-RPC¤º®e¡^¡C¦¹®É¡A¬õ©³¼Ð°OIPªºWP¥D¾÷«K·|¹ï¨ü®`¥D¾÷µo¥X¤j¶qHTTP Request«Ê¥]¡A¹F¨ìDDoSªº§ðÀ»®ÄªG¡C
¹ï©óºô¸ôºÞ²zªÌ¦Ó¨¥¡A»Ý¯S§Oª`·N«Ê¥]¤¤½s¸¹2ºñ©³¼Ð°Oªº¡uPingback.ping¡v¦r¦ê¡A¦¹¦r¦ê¬O°w¹ï¦¹Ãþ«¬§ðÀ»¶i¦æ«Ê¥]¹LÂoªº³Ì¨Î§PÂ_¨Ì¾Ú¡C°£¤F³o³¡¤À¡A½s¸¹3ÂÅ©³¼Ð°O³¡¤À«h¬O¦³Ãö¤Þ¥Îºô¯¸¡]¨ü®`¥D¾÷¡^ªº¤å³¹ºô§}¸ê°T¡F¾ï©³¼Ð°O³¡¤À«h¬O¦³Ãö³Q¤Þ¥Îºô¯¸¡]WP¥D¾÷¡^ªº¤å³¹ºô§}¸ê°T¡Aºô¸ôºÞ²zªÌ¹ï©ó¦¹Ãþ«¬¤§§ðÀ»¨¾¿m®É¡A¥i¯S§Oª`·N³o¨Ç²Ó³¡¸ê°T¡A¥H½T»{¨ä§ðÀ»Ãþ«¬¶i¦Ó±Ä¨ú¦³®Ä¨¾¿m±¹¬I¡C


¹Ï¤T 

ºÞ²zªÌªº¾ãÅé¸ê¦w«Øij
²{¤µ«Ü¦h¤u¨ã³£¥i¥H´ú¸Õºô¯¸¬O§_§t¦³Pingbackªº¬ÛÃöº|¬}¡A«Øij¨Ï¥ÎWordPressªººÞ²zªÌ¡A­Y¬O­nÁקK²_¬°DDoSªº¤@­û¡A½Ð±Ä¨ú¤U¦C±¹¬I¡G
1. Ãö³¬ºô¯¸ªºPingback¥\¯à¡C


¹Ï¥| 

2. §R°£xmlrpc.php¡C
3. ¤U¸üWordPress©x¤èºô¯¸©Ò´£¨Ñªº­×¸É®M¥ó¡Ghttps://wordpress.org/plugins/disable-xml-rpc-pingback/¡C
4. ¤É¯ÅWordPress¦Ü³Ì·sª©¥»¡C

°w¹ïªýÂ_¦¡ªA°È§ðÀ»ªº¨¾¿m¤è¦¡¡A³q±`³z¹L«Ê¥]²`¤JÀË´ú¡AÅý¥¿±`¦Xªkªº«Ê¥]³q¹L¡A¨Ãªý¾×«Dªkªººô¸ô¬y¶q¡C³q±`¦b±oª¾§ðÀ»¤è¦¡«á¡A¥i¥H¹Á¸ÕÁA¸Ñ§Q¥Î¦óºØÃþ«¬ªº¨ó©w§ðÀ»¡A¨Ã«ÊÂê¬ÛÃö°ð¸¹¡AÂÇ¥H¹F¨ìªý¹j§ðÀ»¬y¶q¤§¥Øªº¡A¦¹ºØ¤è¦¡Áö¸û²ÊÁW¦ý«o¬O°ò¥»³B²z­ì«h¡C¦³¤u¨ã¤¬¬Û·f°t¬°¨Î¡A¬ÛÃö¤u¨ã¦CÁ|¦p¤U¡G
1. ¨¾¤õÀð(Firewall)
¨¾¤õÀð¥i¥H³]¸m¤@¨Ç²³æªº³W«h¨Óªý¾×©Î¤¹³\¯S©wªº³q°T¨ó©w¡BIP¤ÎPort¡C¦ý¨¾¤õÀð³W«h³q±`¸û¬°Â²³æ¡AµLªk¨¾¿m¸û¬°½ÆÂøªº§ðÀ»¤è¦¡¡A¦pªG³]©w±o¤£«ê·í¡A¤]¦³¥i¯àªý¾×¥¿±`ªº¬y¶q¡A³y¦¨ªA°ÈµLªk¥¿±`¹B§@¡C
2. ¥æ´«¾¹(Switch)¡B¸ô¥Ñ¾¹(Router)
¤@¯ë¨Ó»¡¡A¦h¼Æªº¥æ´«¾¹»P¸ô¥Ñ¾¹³£¦³¤@©wªºACL¤Î³t²vªº­­¨î¥\¯à¡A¦ý¬O´¶³qªº¸ô¥Ñ¾¹«o«Ü®e©ö¦]¬°DDoSªº§ðÀ»¦Ó¼vÅT®Ä¯à¡C³o®É¥i¥H¨Ï¥Î¨¾¤õÀð©Î¬ORouter¤Wªº¤J¤f¹LÂo¥\¯à¡A§Q¥Î¦¹¥\¯à¡A¥i¥H±N¤£²Å¦X³W«hªº«Ê¥]ªý¾×¦bRouter¤§¥~¡C³oºØ¤èªk©Î³\¥i¥H­­¨î¦Û¨­¥D¾÷¹ï¥~³s½uªº¯à¤O¡A¥HÁקK¦¨¬°¹ï¥~µo°_¶¡±µ§ðÀ»ªº¥D¾÷¡A¦ý«o¸ûÃøªý¾×¤ººôµo°_ªº¶¡±µ§ðÀ»¡C
3. ªýÂ_ªA°È¨¾¿m¨t²Î(DDS Based Defense)
ªýÂ_ªA°È¨¾¿m¨t²Î(DDS¡ADoS Defense System)°£¤F¥i¥H¿ëÃѨêý¾×¥H³s½u¤è¦¡¶i¦æªºDDoS§ðÀ»¡A¥¦¤]¥i¥H¿ëÃÑ¥H³q°T¨ó©w¦¡(¹³¬OPing of death)¤ÎÀW²v¦¡(Rate-based)ªº§ðÀ»¡C
4. ²§±`ºô¸ô¬y¶q²M¬~¨t²Î
³oºØ¨¾¿m¤è¦¡¬O±N¥iºÃªº²§±`ºô¸ô¬y¶q¾É¤J¡u¬~º°¤¤¤ß¡v©Î¬O¡u²M¬~¤¤¤ß¡v¡A¸g¹LÀ³¥Î¼hªº¶i¶¥Àˬd«á¡A³z¹LGRE Tunnels©ÎBGP FlowSpecµ¥¤è¦¡±N¬y¶q°Ï¤À¥X¥¿±`¤Î²§±`ªººô¸ô¬y¶q¡A±N²§±`ªº«Ê¥]¥á±ó¡A¦A±N¥¿±`ªººô¸ô¬y¶q¾É¦^¥Øªº¦a¡C
°£¤F¤W­z©Ò±Ä¨úªº¨¾½d¤è¦¡¡A¤]«Øij¦øªA¾¹ªº¬ÛÃöºÞ²zªÌ¥i¥H¶i¦æ¤@¨Ç¹w¨¾©Ê±¹¬I¡C°£¤FÃö³¬¦øªA¾¹¨S¦³¨Ï¥Î¨ìªºPort¥Hªý¾×¤£¥²­nªº³s½u¥~¡A¤]¥i¥HºÞ±±¤º³¡¹ï¥~¥i¥Î¤§ºô¸ô¬y¶q¡A¨Ã¹w¯d¤@¨Çºô¸ôÀW¼e¥H«Kµo¥Íºô¸ô§ðÀ»®É¥i½Õ°t¨Ï¥Î©ÎÀ³Åܱ¹¬I¡C

DDoS§ðÀ»¯A¤Îªk«ß¬ÛÃö°ÝÃD
¡m¦Dªk¡n²Ä358±ø³W©w¡G¡uµL¬G¿é¤J¥L¤H±b¸¹±K½X¡B¯}¸Ñ¨Ï¥Î¹q¸£¤§«OÅ@±¹¬I©Î§Q¥Î¹q¸£¨t²Î¤§º|¬}¡A¦Ó¤J«I¥L¤H¤§¹q¸£©Î¨ä¬ÛÃö³]³ÆªÌ¡A³B3¦~¥H¤U¦³´Á®{¦D¡B©ë§Ð©Î¬ì©Î¨Ö¬ì10¸U¤¸¥H¤U»@ª÷¡C¡v
®Ú¾Ú¡m¦Dªk¡n²Ä359±ø³W©w¡A¤J«I«á¦p¡u¨ú±o¡B§R°£©ÎÅܧó¥L¤H¹q¸£©Î¨ä¬ÛÃö³]³Æ¤§¹qºÏ¬ö¿ý¡A­P¥Í·l®`©ó¤½²³©Î¥L¤H®É¡A¥i³B5¦~¥H¤U¦³´Á®{¦D¡B©ë§Ð©Î¬ì©Î¨Ö¬ì20¸U¤¸¥H¤U»@ª÷¡C¡v
¤J«I¹q¸£©ÎÅõºÈºô¯¸¡]¦p¥»¦¸¦h­Ó¬F©²ºô¯¸¾DÅõºÈ¡^ªº¦æ¬°¡A¥i¯àIJ¤Î¦D¨Æ¹Hªk¡A§Y¨Ï¤£¦b§Ú°êµo°Ê§ðÀ»¡A¥u­n¨ü®`ªº¹q¸£©Îºô¯¸¦b§Ú°ê¹Ò¤º¡A¬Ò¦³Ä²ªkªººÃ¼{¡C

°Ñ¦Ò¸ê®Æ
1. Ĭ¤å±l¡C2015-08-03¡C¡u°Î¦WªÌ¡vÁn´©¤Ï½Òºõ·L½Õ¦æ°Ê¡A±Ð¨|³¡¡B°ê¨¾³¡¡B¸gÀÙ³¡µ¥ºô¯¸³°Äò¾D§ðÀ»¡CiThome¡Cºô§}¡Ghttp://www.ithome.com.tw/news/97854¡C¤Wºô¤é´Á¡G2015-12-28¡C
2. §õ¶Q±Ó¡C2015-08-04¡C¶Q¦b¥ßªk¡n°ê¤ººô¯¸¾D¤J«I¡@°ê»ÚÀb«È¤]¦³¸o¡C¥dÀu·s»Dºô¡Cºô§}¡Ghttp://www.cardu.com.tw/news/detail.php?nt_pk=22&ns_pk=27000¡C¤Wºô¤é´Á¡G2015-12-28¡C
3. ¬x®ü¡A±ä§ÓµØ¡AÀj¦°µØ¡]2014.07¡^¡CDDoS¤À´²¦¡ªýÂ_ªA°È§ðÀ»²`«×¸ÑªR¡]ªìª©¡^¡C»O¥_¥«¡GùÖ®p¸ê°T¡C