English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 15003
À§Çèµµ 40
Æ÷Æ® 79
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ¼­¹öÀÇ Finger µ¥¸óÀÌ Backdoor·Î ÃßÁ¤µÈ´Ù. ¿Ö³ÄÇϸé

cmd_rootsh@target

¶ó´Â Command¿¡ ¹ÝÀÀÀ» Çϱ⠶§¹®ÀÌ´Ù.
´ë°Ô ÀÌ ¹éµµ¾î´Â Root ShellÀÌ /tmp/.sh·Î ÀνºÅçµÇ¾î ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.sans.org/resources/idfaq/fingerd.php
http://www.iss.net/security_center/static/7269.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ ½Ã½ºÅÛÀÌ Cracker¿¡ ÀÇÇØ Àå¾Ç ´çÇßÀ¸¹Ç·Î ½Ã½ºÅÛÀÇ ¹«°á¼º(Integrety)À» Å×½ºÆ®ÇÏ¿© ´Ù¸¥ BackdoorÀÇ À¯¹«¸¦ Á¡°ËÇϰí Finger µ¥¸óÀ» ¿ø·¡ÀÇ °ÍÀ¸·Î ±³Ã¼ÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)