Ãë¾àÁ¡ID |
24064 |
À§Çèµµ |
40 |
Æ÷Æ® |
4444 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
BackDoor |
»ó¼¼¼³¸í |
ÇØ´ç Windows ½Ã½ºÅÛ¿¡´Â MS Blast ¿úÀÇ ¹éµµ¾î°¡ ¼³Ä¡µÇ¾î ÀÖ´Â °ÍÀ¸·Î º¸ÀδÙ. MS Blast ¿úÀº 2003³â 7¿ù 16ÀÏÀÚ·Î °ø½ÃµÈ "Buffer Overrun In RPC Interface Could Allow Code Execution"¶ó´Â Á¦¸ñÀÇ Microsoft º¸¾È °Ô½ÃÆÇ MS03-026¿¡ ¼³¸íµÇ¾î ÀÖ´Â Ãë¾àÁ¡À» µµ¿ëÇÔÀ¸·Î½á ÀüÆÄµÈ´Ù. ÀÌ ¿úÀº Àüü ¼ºê³Ý(subnet)À» ´ë»óÀ¸·Î 135 Æ÷Æ®ÀÇ ¿ÀÇÂ(open) À¯¹«¸¦ ½ºÄµÇÔÀ¸·Î½á Ȱµ¿À» ½ÃÀÛÇÑ´Ù. ±×·±´ÙÀ½ ½ºÄµ ÀÛ¾÷Àº ÀÓÀÇ·Î ¼±ÅÃÇÑ Å¬·¡½º B ¼ºê³Ý (255.255.0.0)µé¿¡ ´ëÇÑ ½ºÄµÀ¸·Î ¿Å°Ü°£´Ù. 135¹ø Æ÷Æ®°¡ ¿·Á ÀÖ´Â °ÍÀ¸·Î ¹ß°ßµÇ¸é Ãë¾àÇÑ ½Ã½ºÅÛ »ó¿¡ ¿ø°Ý ShellÀ» »ý¼ºÇϱâ À§ÇØ À§¿¡ ¾ð±ÞÇÑ µµ¿ë¹æ¹ýÀ» »ç¿ëÇÑ´Ù. ±×¸®°í ³ª¼ µµ¿ë(exploit)ÀÌ ¼º°øÇÔÀ» °¡Á¤ÇÏ°í ¿ø°ÝÁö ½Ã½ºÅÛÀÇ Æ÷Æ® 4444¿¡ Á¢¼ÓÀ» ½ÃµµÇÑ´Ù. ¸¸¾à ¼º°øÀûÀ¸·Î Á¢¼ÓµÇ¸é ¿ø°ÝÁöÀÇ ½Ã½ºÅÛ¿¡ TFTP.EXE¸¦ ÀÌ¿ëÇÏ¿© ÆÄÀÏÀü¼Û ¼ºñ½º¸¦ ÅëÇØ MSBLAST.EXE (»çÀÌÁî: 6,176 bytes, UPX packed) ÆÄÀÏÀÇ ´Ù¿î·Îµå ¸í·ÉÀ» ³»¸°´Ù; TFTP.EXE´Â Windows 2000°ú ÀÌÈÄ ¹öÀüµéÀÇ Windows ¼³Ä¡ ½Ã µðÆúÆ®·Î Æ÷ÇԵǴ À¯Æ¿¸®Æ¼ÀÌ´Ù. ±×¸®°í ³ª¼ ¿ø°ÝÁöÀÇ ½Ã½ºÅÛ »ó¿¡ MSBLAST.EXEÀÇ ¼öÇà ¸í·ÉÀ» º¸³½´Ù. ÀÏ´Ü ½ÇÇàµÇ¸é ¿úÀº ·¹Áö½ºÆ®¸® ۸¦ »ý¼ºÇÑ´Ù (´ÙÀ½ µÑ ÁßÀÇ ÇϳªÀÏ ¼ö ÀÖÀ½): HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "windows auto update" = msblast.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "windows auto update" = msblast.exe I just want to say LOVE YOU SAN!! bill
* Âü°í »çÀÌÆ®: http://www.datafellows.com/v-descs/msblast.shtml http://us.mcafee.com/virusInfo/default.asp?id=description&virus_k=100547 http://www.sarc.com/avcenter/venc/data/w32.blaster.worm.html http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_MSBLAST.A http://www.sophos.com/virusinfo/analyses/w32blastera.html http://vil.nai.com/vil/content/v_100547.htm http://www.cert.org/advisories/CA-2003-19.html http://www.microsoft.com/technet/security/bulletin/MS03-026.asp
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Windows Any version |
ÇØ°áÃ¥ |
¹é½Å ÇÁ·Î±×·¥ (¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© °¨¿°µÈ ÄÄÇ»ÅͷκÎÅÍ ¹ÙÀÌ·¯½ºµéÀ» Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù. ¸¸¾à ¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥ÀÌ ¼³Ä¡µÇ¾î ÀÖÁö ¾Ê´Ù¸é ´ÙÀ½ ¹«·á ¿ú Á¦°Å±â ÁßÀÇ Çϳª¸¦ ´Ù¿î·ÎµåÇÏ¿© ¼³Ä¡ÇÑ´Ù: 1. Norton AntiVirus: http://www.symantec.com/security_response/definitions/download/detail.jsp?gid=n95 2. McAfee VirusScan: http://www.mcafee.com 3. Trend Micro Internet Security: http://downloadcenter.trendmicro.com/index.php?regs=NABU&clk=latest&clkval=280&lang_loc=1 4. Symantec DCOM Cleaner: http://securityresponse.symantec.com/avcenter/venc/data/w32.blaster.worm.removal.tool.html
-- ȤÀº --
´ÙÀ½ ÀýÂ÷¸¦ µû¶ó ¼öÀÛ¾÷À¸·Î ¿úÀ» Á¦°ÅÇÑ´Ù:
1. ¸Þ¸ð¸®·ÎºÎÅÍ ¿ú ÇÁ·Î¼¼½ºÀÇ ÀÛµ¿À» Á¾·á½ÃŲ´Ù.
1) CTRL+SHIFT+ESC¸¦ ´©¸¥ ´ÙÀ½ À©µµ¿ìÁî ÀÛ¾÷ °ü¸®ÀÚ¸¦ Ŭ¸¯ÇÑ´Ù. ±×¸®°í ÇÁ·Î¼¼½º ÅÇÀ» Ŭ¸¯ÇÑ´Ù. 2) ÀÛµ¿ÁßÀÎ ÇÁ·Î±×·¥µéÀÇ ¸®½ºÆ®¿¡¼ ÇÁ·Î¼¼½º MSBLAST.EXE¸¦ ã´Â´Ù. 3) ¿ú ÇÁ·Î¼¼½º¸¦ ¼±ÅÃÇϰí ÇÁ·Î¼¼½º ³¡³»±â ¹öưÀ» Ŭ¸¯ÇÑ´Ù. 4) ÀÛ¾÷ °ü¸®ÀÚ¸¦ ´Ý´Â´Ù.
¾Ë¸²: À§ÀÇ ÀýÂ÷¿¡ ÀÇÇØ ¸Þ¸ð¸®·ÎºÎÅÍ ¿ú ÇÁ·Î¼¼½º°¡ Á¾·áµÇÁö ¾Ê´Â´Ù¸é ½Ã½ºÅÛÀ» Àç½ÃÀÛ ÇÏ¿©¾ß ÇÑ´Ù.
2. ½Ã½ºÅÛ ½ÃÀÛ°ú ÇÔ²² ÀÚµ¿ ½ÇÇàµÇÁö ¾Êµµ·Ï ·¹Áö½ºÆ®¸®·ÎºÎÅÍ ÀÚµ¿½ÃÀÛ ¿£Æ®¸®¸¦ Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù:
1) ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ ¿¬´Ù. À̸¦ À§ÇØ ½ÃÀÛ>½ÇÇàÀ» Ŭ¸¯, regedit¸¦ ŸÀÌÇÎ, ±×¸®°í ³ª¼ ¿£Æ®Å°¸¦ ´©¸¥´Ù. 2) ÁÂÃø À©µµ¿ì·ÎºÎÅÍ ´ÙÀ½À» ´õºíŬ¸¯ÇÑ´Ù: HKEY_LOCAL_MACHINE>Software>Microsoft>Windows>CurrentVersion>Run 3) ¿ÀÃø À©µµ¿ì¿¡¼ ´ÙÀ½ ¿£Æ®¸®¸¦ ã¾Æ »èÁ¦ÇÑ´Ù: "windows auto update" = MSBLAST.EXE 4) ·¹Áö½ºÆ®¸® ÆíÁý±â¸¦ ´Ý´Â´Ù.
-- ±×¸®°í --
´ÙÀ½ ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®ÀÇ º¸¾È °Ô½ÃÆÇ MS03-026¸¦ ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù: http://www.microsoft.com/technet/security/bulletin/ms03-026.asp |
°ü·Ã URL |
(CVE) |
°ü·Ã URL |
(SecurityFocus) |
°ü·Ã URL |
(ISS) |
|