Ãë¾àÁ¡ID |
24077 |
À§Çèµµ |
40 |
Æ÷Æ® |
139,445 |
ÇÁ·ÎÅäÄÝ |
TCP |
ºÐ·ù |
BackDoor |
»ó¼¼¼³¸í |
ÇØ´ç È£½ºÆ®¿¡´Â ÆÐ½º¿öµå°¡ ¾ø°Å³ª ÆÐ½º¿öµå 'X'¸¦ °¡Áø »ç¿ëÀÚ 'X'°¡ Á¸ÀçÇÑ´Ù. À̰ÍÀº ¿ø°ÝÁöÀÇ °ø°ÝÀÚ°¡ ±¤¹üÀ§ÇÏ°Ô µµ¿ë ÇÁ·Î±×·¥À» °¡Áö°í Microsoft Security Bulletin MS04-028¿¡ ¼³¸íµÈ GDI+ Á¤¼ö ¿À¹öÇ÷οì Ãë¾àÁ¡À» µµ¿ëÇÑ °ÍÀÏ ¼öµµ ÀÖ´Ù. ÀÌ °áÇÔÀ» µµ¿ëÇÏ¿© °ø°ÝÀÚ´Â µµ¿ë ÇÁ·Î±×·¥°ú ½©(shell) Äڵ带 Æ÷ÇÔÇÏ´Â Àß Á¶ÀÛµÈ JPEG À̹ÌÁö¸¦ ¸¸µé ¼ö ÀÖ´Ù. °ø°ÝÀÚ´Â ´ë°³ JPEG À̹ÌÁö ÆÄÀÏÀ» ´ÙÀ½ ¸Å°³Ã¼¸¦ ÅëÇØ È®»ê½ÃŲ´Ù: 1. À¥ »çÀÌÆ® 2. Email 3. MS Office ¹®¼ 4. P2P
Èñ»ýÀÚ°¡ JPEG ÆÄÀÏÀ» ¿ ¶§ ¹öÆÛ ¿À¹öÇ÷ο찡 ¹ß»ýÇÏ¸ç °ø°ÝÀÚ¿¡°Ô ¿µÇâÀ» ¹Þ´Â ½Ã½ºÅÛ »ó¿¡¼ ÀÓÀÇÀÇ ÄÚµåÀÇ ½ÇÇàÀ» Çã¿ëÇÑ´Ù. "°ü¸®ÀÚ ±×·ì¿¡ »ç¿ëÀÚ X¸¦ »ý¼º"ÇÒ ¼ö ÀÖ´Â µµ¿ë ÇÁ·Î±×·¥ÀÌ ±¤¹üÀ§ÇÏ°Ô È®»êµÇ¾ú´Ù.
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Windows Any version
* Âü°í »çÀÌÆ®: http://seclists.org/lists/fulldisclosure/2004/Sep/0840.html http://www.kb.cert.org/vuls/id/297462 |
ÇØ°áÃ¥ |
Windows È£½ºÆ®·ÎºÎÅÍ »ç¿ëÀÚ °èÁ¤ X¸¦ Á¦°ÅÇÏ¿©¾ß ÇÑ´Ù.
-- ±×¸®°í --
¸¸¾à MS04-028 ÆÐÄ¡°¡ Àû¿ëµÇÁö ¾Ê¾Ò´Ù¸é Microsoft Security Bulletin MS04-028À» ÂüÁ¶ÇÏ¿© ½Ã½ºÅÛ¿¡ ÀûÀýÇÑ ÆÐÄ¡¸¦ Àû¿ëÇÏ¿©¾ß ÇÑ´Ù. http://www.microsoft.com/technet/security/bulletin/MS04-028.mspx
±×¸®°í http://isc.sans.org/gdiscan.php ¿¡¼ ±¸ÇÒ ¼ö ÀÖ´Â gdiscan.exeÀ» ÀÌ¿ëÇÏ¿© ½Ã½ºÅÛ ³»¿¡ ÀÖ´Â Ãß°¡ÀûÀÎ .dllÀÇ Ãë¾àÇÑ ¹öÀüµéÀ» ã¾Æ³¾ Çʿ䰡 ÀÖ´Ù. Ãë¾àÇÑ .dll ÆÄÀϵéÀÌ Ã£¾ÆÁö¸é ±×·¯ÇÑ ÆÄÀϵéÀº ¼öµ¿À¸·Î ¾÷±×·¹À̵å ÇÏ¿©¾ß ÇÑ´Ù. |
°ü·Ã URL |
CVE-2004-0200 (CVE) |
°ü·Ã URL |
1503,11173 (SecurityFocus) |
°ü·Ã URL |
16304 (ISS) |
|