백신 관리 서버 취약점 조치 안내

2024-08-14 Hauri PortDeny.sh deny 18607

https://hauri.co.kr/security/notice_view.html?intSeq=548&page=1

Thumbnail for 백신 관리 서버 취약점 조치 안내

Hauri's advisory provides defensive checks for suspected exploitation or misuse of vaccine management servers. It instructs administrators to query management-server logs for suspicious program execution strings such as PowerShell, cmd, mshta, winhost, taskcm, and external URLs, and to apply firewall blocking guidance for affected server operating systems. The report is operationally useful for incident responders because it focuses on post-compromise evidence and hardening steps around centralized antivirus management infrastructure that could be abused for broad endpoint impact.

« Back