English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24003
À§Çèµµ 40
Æ÷Æ® 30100
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ¹éµµ¾î NetSphere°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. ÀÌ ¹éµµ¾î´Â ´©±º°¡¿¡ ÀÇÇØ ½Ã½ºÅÛÀÇ ºÎºÐÀûÀÎ Á¦¾î±ÇÀ» °¡Áö°í °¥ ¼ö ÀÖ°Ô ÇØ ÁØ´Ù. NetSphere´Â À©µµ¿ìÁî 95, 98, ±×¸®°í À©µµ¿ìÁî NT¿¡¼­ ÀÛµ¿ÇÑ´Ù. NetSphere´Â TCP Æ÷Æ® 30100°ú 30102 Æ÷Æ®¸¦ »ç¿ëÇÑ´Ù.

NetSphere ¹éµµ¾î¸¦ °¡Áö°í Attacker´Â ´ÙÀ½°ú °°Àº ÀϵéÀ» ÇÒ ¼ö ÀÖ´Ù:
- »ç¿ëÀÚ°¡ ŸÀÌÇÁÇÑ Å°¸¦ ·Î±×ÇÑ´Ù
- »ç¿ëÀÚ ÄÄÇ»Å͸¦ °æÀ¯Çϵµ·Ï Æ®·¡ÇÈÀ» ÀçÀü¼Û½ÃÄÑ ÁÖ´Â port redirector¸¦ ¼Â¾÷ÇÑ´Ù.
- »ç¿ëÀÚ È­¸éÀÇ À̹ÌÁö¸¦ ĸÃÄÇÑ´Ù.
- »ç¿ëÀÚ ÄÄÇ»ÅÍ¿¡ ¼³Ä¡µÇ¾î ÀÖ´Ù¸é Mirabilis ICQ¸¦ ÀÛµ¿½Ãų ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://xforce.iss.net/alerts/advise30.php
http://www.iss.net/security_center/static/2321.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows Any version
ÇØ°áÃ¥ NetSphere ¹éµµ¾î¸¦ Á¦°ÅÇϱâ À§Çؼ­´Â:

¼³Ä¡µÈ ÄÄÇ»ÅÍÀÇ 30100 Æ÷Æ®¿¡ Telnet ÇÑ ÈÄ, ÀοëºÎÈ£ ¾øÀÌ '<KillServer>'¸¦ ŸÀÌÇÁÇÑ´Ù. ±×¸®°í ¿£ÅÍ۸¦ Ä£´Ù.

ȤÀº,

´ÙÀ½°ú °°Àº ÀýÂ÷¿¡ ÀÇÇØ ¼Õ¼ö Á¦°ÅÇÒ ¼öµµ ÀÖ´Ù:
1. Regedit¸¦ »ç¿ëÇÏ¿© HKLM\Software\Microsoft\Windows\CurrentVersion\Run ·¹Áö½ºÆ®¸® ۸¦ ã´Â´Ù.
2. C:\Windows\System\nssx.exeÀÇ µ¥ÀÌŸ °ªÀ» °®´Â NSSX¶ó´Â À̸§ÀÇ ·¹Áö½ºÆ®¸® ¿£Æ®¸®¸¦ ã´Â´Ù.
3. ±× ·¹Áö½ºÆ®¸® ¿£Æ®¸®¸¦ »èÁ¦ÇÑ´Ù.
4. ÄÄÇ»Å͸¦ Àç½ÃÀÛÇÑ´Ù.
5. À©µµ¿ìÁî ½Ã½ºÅÛ µð·ºÅ丮·Î ºÎÅÍ nssx.exe¸¦ ã¾Æ »èÁ¦ÇÑ´Ù.
°ü·Ã URL CVE-1999-0660 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)