English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24012
À§Çèµµ 40
Æ÷Æ® 23456
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ¹éµµ¾î EvilFTP°¡ ¼³Ä¡µÇ¾î ÀÖ´Ù. EvilFTP´Â ´Ü¼øÈ÷ ½Ã½ºÅÛ »ó¿¡ FTP ¼­¹ö¸¦ ¼Â¾÷ÇØ ÁÖ´Â ¹éµµ¾îÀÌ´Ù. ±× ¼­¹ö´Â 23456 Æ÷Æ®¸¦ »ç¿ëÇÏ¸ç »ç¿ëÀÚ¸í 'yo'¿Í 'connect' ÆÐ½º¿öµå¸¦ °®´Â´Ù. EvilFTP ¹éµµ¾î¸¦ °¡Áö°í Attacker´Â ±× ¹éµµ¾î°¡ ¼³Ä¡µÈ ½Ã½ºÅÛ¿¡ ÆÄÀϵéÀ» ¾÷·ÎµåÇϰųª ´Ù¿î·ÎµåÇÒ ¼ö ÀÖ´Ù. EvilFTP´Â À©µµ¿ìÁî 95, 98, ±×¸®°í À©µµ¿ìÁî NT ½Ã½ºÅ۵鿡¼­ ÀÛµ¿ÇÑ´Ù.

* Âü°í »çÀÌÆ®:
http://bvlive01.iss.net/issEn/delivery/xforce/alertdetail.jsp?id=advise30
http://www.iss.net/security_center/static/2310.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows Any version
ÇØ°áÃ¥ ÇØ´ç ÄÄÇ»ÅÍ·Î ºÎÅÍ EvilFTP¸¦ Á¦°ÅÇϱâ À§Çؼ­´Â:

À©µµ¿ìÁî 95¿Í 98ÀÇ °æ¿ì:
1. win.ini¿¡¼­ run=c:\windows\system\msrun.exe ¶óÀÎÀ» »èÁ¦ÇÑ´Ù.
2. À©µµ¿ìÁî ½Ã½ºÅÛ µð·ºÅ丮¿¡¼­ Msrun.exeÀ» »èÁ¦ÇÑ´Ù.

À©µµ¿ìÁî NTÀÇ °æ¿ì:
1. Regedit¸¦ »ç¿ëÇÏ¿© HKCU\Software\Microsoft\Windows NT\Windows\run=msrun.exe ·¹Áö½ºÆ®¸® ۸¦ ã¾Æ¼­ »èÁ¦ÇÑ´Ù.
2. À©µµ¿ìÁî ½Ã½ºÅÛ µð·ºÅ丮¿¡¼­ Msrun.exeÀ» »èÁ¦ÇÑ´Ù.
°ü·Ã URL CVE-1999-0660 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)