| Ãë¾àÁ¡ID |
24004 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
31785 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
BackDoor |
| »ó¼¼¼³¸í |
¹éµµ¾î Hack'a'Tack°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. ÀÌ ¹éµµ¾î´Â ħÀÔÀÚ°¡ ½Ã½ºÅÛÀÇ Á¦¾î±ÇÀ» °¡Áö°í °¥ ¼ö ÀÖ°Ô ÇØÁØ´Ù. Hack'a'Tack´Â TCP Æ÷Æ® 31785¿Í UDP Æ÷Æ® 31789¿Í 31791¸¦ »ç¿ëÇÑ´Ù. Hack'a'Tack´Â À©µµ¿ìÁî 95¿Í 98¿¡¼¸¸ ÀÛµ¿ÇÑ´Ù. Hack'a'Tack ¹éµµ¾î¸¦ °¡Áö°í Attacker´Â ´ÙÀ½°ú °°Àº ÀϵéÀ» ÇÒ ¼ö ÀÖ´Ù:
- »ç¿ëÀÚ ÄÄÇ»ÅÍ »ó¿¡ ÀÖ´Â À©µµ¿ìµéÀ» ¿Å±â°Å³ª ´ÝÀ» ¼ö ÀÖ´Ù. - »ç¿ëÀÚ ÄÄÇ»ÅÍ »ó¿¡ FTP ¼¹ö¸¦ ¶ç¿ö ³õÀ» ¼ö ÀÖ´Ù. - »ç¿ëÀÚ°¡ ŸÀÌÇÁÇÑ Å°¸¦ ·Î±×ÇÒ ¼ö ÀÖ´Ù. - ÄÄÇ»Å͸¦ ¼Ë´Ù¿î ÇÒ ¼ö ÀÖ´Ù. - ÇÁ·Î±×·¥À» ½ÇÇà½Ãų ¼ö ÀÖ´Ù.
* Âü°í »çÀÌÆ®: http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?id=advise30 http://www.iss.net/security_center/static/2325.php
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Windows Any version |
| ÇØ°áÃ¥ |
Hack'a'Tack ¹éµµ¾î¸¦ Á¦°ÅÇϱâ À§Çؼ´Â:
1. Regedit¸¦ ÀÌ¿ëÇÏ¿© HKLM\Software\Microsoft\Windows\CurrentVersion\Run ·¹Áö½ºÆ®¸® ۸¦ ã´Â´Ù. 2. Explorer32¶ó°í À̸§Áö¾îÁø ·¹Áö½ºÆ®¸® ¿£Æ®¸®¸¦ ã´Â´Ù. ±× ¿£Æ®¸®ÀÇ µ¥ÀÌŸ´Â Hack'a'Tack ÇÁ·Î±×·¥ ÆÄÀÏÀÎ Expl32.exe ·ÎÀÇ °æ·Î¸íÀ» °¡Áö°í ÀÖ´Ù. ±× ÆÄÀÏÀÇ À§Ä¡¸¦ ±â¾ïÇØ µÎ¾î¾ß ÇÑ´Ù. 3. MS-DOS ¸ðµå·Î ÄÄÇ»Å͸¦ Àç½ÃÀÛÇÑ´Ù. 4. Expl32.exe ÆÄÀÏÀ» ·¹Áö½ºÆ®¸® ۰ª¿¡ ÀÖ´Â °æ·Î¸íÀ¸·Î ºÎÅÍ »èÁ¦ÇÑ´Ù. 5. Regedit¸¦ ÀÌ¿ëÇÏ¿© HKLM\Software\Microsoft\Windows\CurrentVersion\Run ·¹Áö½ºÆ®¸® Ű¿¡¼ Expl32.exe ¿£Æ®¸®¸¦ »èÁ¦ÇÑ´Ù. |
| °ü·Ã URL |
CVE-1999-0660 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|