English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24007
À§Çèµµ 40
Æ÷Æ® ¡¦
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í Back Orifice 2000ÀÌ ¼³Ä¡µÇ¾î ÀÖ´Ù. Back Orifice 2000Àº À¯¸íÇÑ ¹é¿ÀÇǸ®½º ¹éµµ¾î (hackerÀÇ ¿ø°Ý Á¢¼Ó Åø)ÀÇ »õ·Î¿î ¹öÀüÀ¸·Î 'Cult of Dead Cow' ¶ó´Â ÇØÄ¿½º ±×·ì¿¡ ÀÇÇØ 1999³â 7¿ù¿¡ ¸¸µé¾î Á³´Ù. Microsoft Windows ½Ã½ºÅÛ¿¡ ¼³Ä¡µÉ ¶§ ÀÌ ¹éµµ¾î Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥Àº ³×Æ®¿öÅ© Á¢¼ÓÀ» ÅëÇÏ¿© ½Ã½ºÅÛÀ¸·ÎÀÇ ¿ÏÀüÇÑ ¾×¼¼½º ±ÇÇÑÀ» ¾òµµ·Ï ÇØ ÁØ´Ù. ¿ø·¡ ¹é¿À¸®Çǽº¿Í ¸¶Âù°¡Áö·Î µÎ ºÎºÐ, Áï ¼­¹ö¿Í Ŭ¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥À¸·Î ±¸¼ºµÇÁö¸¸ ±× µÎ ÇÁ·Î±×·¥µéÀº Windows NT¿¡¼­µµ ÀÛµ¿ÀÌ °¡´ÉÇÏ´Ù.
ÆÐŰÁö ³»¿¡´Â BO2K ¼­¹öÀÇ È¯°æÀ» ¼³Á¤Çϴµ¥ »ç¿ëµÇ´Â ¼³Á¤ À¯Æ¿¸®Æ¼°¡ µþ·Á ÀÖ´Ù. ¼³Á¤ À¯Æ¿¸®Æ¼´Â ¼­¹öÀÇ È¯°æÀ» ¼³Á¤À» µ½±â À§ÇÑ ¼³Á¤ ¸¶¹ý»ç¸¦ °¡Áö°í ÀÖ´Ù. ±×·¡¼­ »ç¿ëÀÚ´Â ³×Æ®¿öÅ· Á¾·ù (TCP or UDP), Æ÷Æ®¹øÈ£ (1-65535), Á¢¼Ó ¾Ïȣȭ Á¾·ù - XOR ȤÀº 3DES, ±×¸®°í ¼­¹ö Á¢¼ÓÀ» À§ÇÑ ÆÐ½º¿öµå¸¦ ¼³Á¤ÇÒ ¼ö ÀÖ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/2343.php
http://www.norton.com/avcenter/venc/data/back.orifice.2000.trojan.html
http://www.nsclean.com/psc-bo2k.html

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows Any version
ÇØ°áÃ¥ ¹é¿À¸®Çǽº 2000 ¹éµµ¾î´Â ¼³Á¤¹æ¹ýÀÌ ³Ê¹« ´Ù¾çÇÏ¿© ½Äº°ÀÌ ¾î·Æ°í ÀÌ·Î ÀÎÇÏ¿© ¼öÀÛ¾÷À¸·Î Á¦°ÅÇϱâ´Â »ó´çÈ÷ ¾î·Æ´Ù. µðÆúÆ®·Î ¹é¿À¸®Çǽº 2000 ¹éµµ¾î´Â UMGR32.EXE ÆÄÀϷνá À©µµ¿ìÀÇ ½Ã½ºÅÛ µð·ºÅ丮¿¡ ¼³Ä¡µÈ´Ù. Windows NT¿¡¼­´Â "Remote Administration Service"·Î ¸®½ºÆ®µÇ´Â ¼­ºñ½º°¡ ¼³Ä¡µÈ´Ù. ¾î·µç ÀÌ µðÆúÆ®¸íÀº ÃæºÐÈ÷ ¹Ù²ð ¼ö ÀÖ´Ù. µû¶ó¼­ ´ÙÀ½ »çÀÌÆ®µéÀ» ÂüÁ¶ÇÏ¿© ¾ÈƼ ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥À» »ç¿ëÇÏ¿© ¹éµµ¾î¸¦ Á¦°ÅÇÏ´Â °ÍÀÌ ÁÁ´Ù.

- Norton AntiVirus:
http://www.symantec.com/security_response/definitions/download/detail.jsp?gid=n95

- McAfee VirusScan: http://www.mcafee.com

- Trend Micro Internet Security:
http://downloadcenter.trendmicro.com/index.php?regs=NABU&clk=latest&clkval=280&lang_loc=1

- Comodo BOClean 4.02: http://www.comodo.com/home/internet-security/anti-malware.php
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)