| Ãë¾àÁ¡ID |
24022 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
10167 |
| ÇÁ·ÎÅäÄÝ |
UDP |
| ºÐ·ù |
BackDoor |
| »ó¼¼¼³¸í |
Portal of Doom (PoD) ¹éµµ¾î´Â AttackerµéÀÌ ´ë»ó ½Ã½ºÅÛÀÇ »ç¿ëÀÚ°¡ ¸ð¸£°Ô ½Ã½ºÅÛÀ» ¾×¼¼½ºÇϴµ¥ »ç¿ëÇÒ ¼ö ÀÖ´Â ¸¹Àº ¹éµµ¾î ÇÁ·Î±×·¥µé ÁßÀÇ ÇϳªÀÌ´Ù. ÀÌ ¹éµµ¾î´Â ÀüÈÁ¢¼Ó ÆÐ½º¿öµå ÈÉÃij»±â¿Í °°Àº Áøº¸µÈ Ư¡ »Ó¸¸ ¾Æ´Ï¶ó ¸Þ½ÃÁö º¸³»±â, ÆÄÀÏ Àбâ, ȸ麸ȣ±â ½ÃÀÛ, ¸¶¿ì½º ¹öưÀÇ Á¶ÀÛ¿Í °°Àº ÀϹÝÀûÀÎ ¹éµµ¾îÀÇ Æ¯Â¡À» °¡Áö°í ÀÖ´Ù. Portal of DoomÀº Windows 95³ª 98 ½Ã½ºÅ۵鿡 ÀÖ´Â C:\Windows\System µð·ºÅ丮¿¡ ¼³Ä¡µÈ´Ù. C:\Windows\System µð·ºÅ丮°¡ µðÆúÆ® Windows NT µð·ºÅ丮´Â ¾Æ´ÏÁö¸¸ ÀÌ µð·ºÅ丮°¡ Á¸ÀçÇÑ´Ù¸é ÀÌ ¹éµµ¾î´Â ½º½º·Î ¼³Ä¡µÇ°í Windows NT ÇÏ¿¡¼µµ ÀÛµ¿ÇÑ´Ù. Portal of DoomÀº UDP 10067°ú 10167 Æ÷Æ®¸¦ ListenÇÑ´Ù. 10167 Æ÷Æ®·Î "pod" ¶ó´Â 3 ¹ÙÀÌÆ®ÀÇ µ¥ÀÌŸ¸¦ º¸³»¸é ¹éµµ¾î´Â '[@]xforce' ¸¦ º¸³»ÁØ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/2323.php http://xforce.iss.net/alerts/advise30.php
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Microsoft Windows Any version |
| ÇØ°áÃ¥ |
°¨¿°µÈ ½Ã½ºÅÛÀ¸·Î ºÎÅÍ Portal of Doom ¹éµµ¾î¸¦ Á¦°ÅÇϱâ À§Çؼ´Â ´ÙÀ½°ú °°ÀÌ ÇÑ´Ù.
1. Portal of Doom ÇÁ·Î±×·¥ (ljgz.exe)À» ÀÛµ¿ÁßÁö ½ÃŲ´Ù. ÀÌ ÇÁ·Î¼¼½º´Â ÀϹÝÀûÀÎ Windows ¹öÀü°ú´Â ´Ù¸£´Ù. - Windows 95/98: MS-DOS ¸ðµå·Î ½Ã½ºÅÛÀ» Àç°¡µ¿½ÃŲ´Ù. ¸í·É ÇÁ·ÒÇÁÆ®¿¡¼ C:\Windows\System\ljsgz.exeÀ» »èÁ¦ÇÑ´Ù. - Windows NT: CTRL+ALT+DEL ۸¦ ´©¸¥ÈÄ, NT ÀÛ¾÷ °ü¸®ÀÚ¸¦ ¶ç¿î´Ù. ÇÁ·Î¼¼½º ÅÇÀ» Ŭ¸¯Çϰí ljgz.exeÀ» ã¾Æ¼ ÇÁ·Î¼¼½º¸¦ Á¾·á½ÃŲ´Ù. 2. Regedit¸¦ »ç¿ëÇÏ¿© HKLM\Software\Microsoft\Windows\CurrentVersion\Run ·¹Áö½ºÆ®¸® ۸¦ ã´Â´Ù. 3. C:\Windows\System\lgsgz.exeÀÇ µ¥ÀÌŸ °ªÀ» °¡Áø ·¹Áö½ºÆ®¸® ¿£Æ®¸®ÀÇ ¹®ÀÚ¿À» ã¾Æ¼ ·¹Áö½ºÆ®¸® ¿£Æ®¸®¸¦ »èÁ¦ÇÑ´Ù. |
| °ü·Ã URL |
CVE-1999-0660 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|