English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24064
À§Çèµµ 40
Æ÷Æ® 4444
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç Windows ½Ã½ºÅÛ¿¡´Â MS Blast ¿úÀÇ ¹éµµ¾î°¡ ¼³Ä¡µÇ¾î ÀÖ´Â °ÍÀ¸·Î º¸ÀδÙ.
MS Blast ¿úÀº 2003³â 7¿ù 16ÀÏÀÚ·Î °ø½ÃµÈ "Buffer Overrun In RPC Interface Could Allow Code Execution"¶ó´Â Á¦¸ñÀÇ Microsoft º¸¾È °Ô½ÃÆÇ MS03-026¿¡ ¼³¸íµÇ¾î ÀÖ´Â Ãë¾àÁ¡À» µµ¿ëÇÔÀ¸·Î½á ÀüÆÄµÈ´Ù. ÀÌ ¿úÀº Àüü ¼­ºê³Ý(subnet)À» ´ë»óÀ¸·Î 135 Æ÷Æ®ÀÇ ¿ÀÇÂ(open) À¯¹«¸¦ ½ºÄµÇÔÀ¸·Î½á Ȱµ¿À» ½ÃÀÛÇÑ´Ù. ±×·±´ÙÀ½ ½ºÄµ ÀÛ¾÷Àº ÀÓÀÇ·Î ¼±ÅÃÇÑ Å¬·¡½º B ¼­ºê³Ý (255.255.0.0)µé¿¡ ´ëÇÑ ½ºÄµÀ¸·Î ¿Å°Ü°£´Ù. 135¹ø Æ÷Æ®°¡ ¿­·Á ÀÖ´Â °ÍÀ¸·Î ¹ß°ßµÇ¸é Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ¿ø°Ý ShellÀ» »ý¼ºÇϱâ À§ÇØ À§¿¡ ¾ð±ÞÇÑ µµ¿ë¹æ¹ýÀ» »ç¿ëÇÑ´Ù. ±×¸®°í ³ª¼­ µµ¿ë(exploit)ÀÌ ¼º°øÇÔÀ» °¡Á¤ÇÏ°í ¿ø°ÝÁö ½Ã½ºÅÛÀÇ Æ÷Æ® 4444¿¡ Á¢¼ÓÀ» ½ÃµµÇÑ´Ù. ¸¸¾à ¼º°øÀûÀ¸·Î Á¢¼ÓµÇ¸é ¿ø°ÝÁöÀÇ ½Ã½ºÅÛ¿¡ TFTP.EXE¸¦ ÀÌ¿ëÇÏ¿© ÆÄÀÏÀü¼Û ¼­ºñ½º¸¦ ÅëÇØ MSBLAST.EXE (»çÀÌÁî: 6,176 bytes, UPX packed) ÆÄÀÏÀÇ ´Ù¿î·Îµå ¸í·ÉÀ» ³»¸°´Ù; TFTP.EXE´Â Windows 2000°ú ÀÌÈÄ ¹öÀüµéÀÇ Windows ¼³Ä¡ ½Ã µðÆúÆ®·Î Æ÷ÇԵǴ À¯Æ¿¸®Æ¼ÀÌ´Ù. ±×¸®°í ³ª¼­ ¿ø°ÝÁöÀÇ ½Ã½ºÅÛ »ó¿¡ MSBLAST.EXEÀÇ ¼öÇà ¸í·ÉÀ» º¸³½´Ù.
ÀÏ´Ü ½ÇÇàµÇ¸é ¿úÀº ·¹Áö½ºÆ®¸® ۸¦ »ý¼ºÇÑ´Ù (´ÙÀ½ µÑ ÁßÀÇ ÇϳªÀÏ ¼ö ÀÖÀ½):
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"windows auto update" = msblast.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"windows auto update" = msblast.exe I just want to say LOVE YOU SAN!! bill

* Âü°í »çÀÌÆ®:
http://www.datafellows.com/v-descs/msblast.shtml
http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100547
http://www.sarc.com/avcenter/venc/data/w32.blaster.worm.html
http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MSBLAST.A
http://www.sophos.com/virusinfo/analyses/w32blastera.html
http://vil.nai.com/vil/content/v_100547.htm
http://www.cert.org/advisories/CA-2003-19.html
http://www.microsoft.com/technet/security/bulletin/MS03-026.asp

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows Any version
ÇØ°áÃ¥ ¹é½Å ÇÁ·Î±×·¥ (¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© °¨¿°µÈ ÄÄÇ»ÅͷκÎÅÍ ¹ÙÀÌ·¯½ºµéÀ» Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù. ¸¸¾à ¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥ÀÌ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é ´ÙÀ½ ¹«·á ¿ú Á¦°Å±â ÁßÀÇ Çϳª¸¦ ´Ù¿î·ÎµåÇÏ¿© ¼³Ä¡ÇÑ´Ù:
1. Norton AntiVirus:
http://www.symantec.com/security_response/definitions/download/detail.jsp?gid=n95
2. McAfee VirusScan:
http://www.mcafee.com
3. Trend Micro Internet Security:
http://downloadcenter.trendmicro.com/index.php?regs=NABU&clk=latest&clkval=280&lang_loc=1
4. Symantec DCOM Cleaner:
http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html

-- ȤÀº --

´ÙÀ½ ÀýÂ÷¸¦ µû¶ó ¼öÀÛ¾÷À¸·Î ¿úÀ» Á¦°ÅÇÑ´Ù:

1. ¸Þ¸ð¸®·ÎºÎÅÍ ¿ú ÇÁ·Î¼¼½ºÀÇ ÀÛµ¿À» Á¾·á½ÃŲ´Ù.

1) CTRL+SHIFT+ESC¸¦ ´©¸¥ ´ÙÀ½ À©µµ¿ìÁî ÀÛ¾÷ °ü¸®ÀÚ¸¦ Ŭ¸¯ÇÑ´Ù. ±×¸®°í ÇÁ·Î¼¼½º ÅÇÀ» Ŭ¸¯ÇÑ´Ù.
2) ÀÛµ¿ÁßÀÎ ÇÁ·Î±×·¥µéÀÇ ¸®½ºÆ®¿¡¼­ ÇÁ·Î¼¼½º MSBLAST.EXE¸¦ ã´Â´Ù.
3) ¿ú ÇÁ·Î¼¼½º¸¦ ¼±ÅÃÇϰí ÇÁ·Î¼¼½º ³¡³»±â ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
4) ÀÛ¾÷ °ü¸®ÀÚ¸¦ ´Ý´Â´Ù.

¾Ë¸²: À§ÀÇ ÀýÂ÷¿¡ ÀÇÇØ ¸Þ¸ð¸®·ÎºÎÅÍ ¿ú ÇÁ·Î¼¼½º°¡ Á¾·áµÇÁö ¾Ê´Â´Ù¸é ½Ã½ºÅÛÀ» Àç½ÃÀÛ ÇÏ¿©¾ß ÇÑ´Ù.

2. ½Ã½ºÅÛ ½ÃÀÛ°ú ÇÔ²² ÀÚµ¿ ½ÇÇàµÇÁö ¾Êµµ·Ï ·¹Áö½ºÆ®¸®·ÎºÎÅÍ ÀÚµ¿½ÃÀÛ ¿£Æ®¸®¸¦ Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù:

1) ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ ¿¬´Ù. À̸¦ À§ÇØ ½ÃÀÛ>½ÇÇàÀ» Ŭ¸¯, regedit¸¦ ŸÀÌÇÎ, ±×¸®°í ³ª¼­ ¿£Æ®Å°¸¦ ´©¸¥´Ù.
2) ÁÂÃø À©µµ¿ì·ÎºÎÅÍ ´ÙÀ½À» ´õºíŬ¸¯ÇÑ´Ù:
HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>CurrentVersion>Run
3) ¿ÀÃø À©µµ¿ì¿¡¼­ ´ÙÀ½ ¿£Æ®¸®¸¦ ã¾Æ »èÁ¦ÇÑ´Ù:
"windows auto update" = MSBLAST.EXE
4) ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ ´Ý´Â´Ù.

-- ±×¸®°í --

´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®ÀÇ º¸¾È °Ô½ÃÆÇ MS03-026¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù:
http://www.microsoft.com/technet/security/bulletin/ms03-026.asp
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)