English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24022
À§Çèµµ 40
Æ÷Æ® 10167
ÇÁ·ÎÅäÄÝ UDP
ºÐ·ù BackDoor
»ó¼¼¼³¸í Portal of Doom (PoD) ¹éµµ¾î´Â AttackerµéÀÌ ´ë»ó ½Ã½ºÅÛÀÇ »ç¿ëÀÚ°¡ ¸ð¸£°Ô ½Ã½ºÅÛÀ» ¾×¼¼½ºÇϴµ¥ »ç¿ëÇÒ ¼ö ÀÖ´Â ¸¹Àº ¹éµµ¾î ÇÁ·Î±×·¥µé ÁßÀÇ ÇϳªÀÌ´Ù. ÀÌ ¹éµµ¾î´Â ÀüÈ­Á¢¼Ó ÆÐ½º¿öµå ÈÉÃij»±â¿Í °°Àº Áøº¸µÈ Ư¡ »Ó¸¸ ¾Æ´Ï¶ó ¸Þ½ÃÁö º¸³»±â, ÆÄÀÏ Àбâ, È­¸éº¸È£±â ½ÃÀÛ, ¸¶¿ì½º ¹öưÀÇ Á¶ÀÛ¿Í °°Àº ÀϹÝÀûÀÎ ¹éµµ¾îÀÇ Æ¯Â¡À» °¡Áö°í ÀÖ´Ù. Portal of DoomÀº Windows 95³ª 98 ½Ã½ºÅ۵鿡 ÀÖ´Â C:\Windows\System µð·ºÅ丮¿¡ ¼³Ä¡µÈ´Ù. C:\Windows\System µð·ºÅ丮°¡ µðÆúÆ® Windows NT µð·ºÅ丮´Â ¾Æ´ÏÁö¸¸ ÀÌ µð·ºÅ丮°¡ Á¸ÀçÇÑ´Ù¸é ÀÌ ¹éµµ¾î´Â ½º½º·Î ¼³Ä¡µÇ°í Windows NT ÇÏ¿¡¼­µµ ÀÛµ¿ÇÑ´Ù.
Portal of DoomÀº UDP 10067°ú 10167 Æ÷Æ®¸¦ ListenÇÑ´Ù. 10167 Æ÷Æ®·Î "pod" ¶ó´Â 3 ¹ÙÀÌÆ®ÀÇ µ¥ÀÌŸ¸¦ º¸³»¸é ¹éµµ¾î´Â '[@]xforce' ¸¦ º¸³»ÁØ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/2323.php
http://xforce.iss.net/alerts/advise30.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Microsoft Windows Any version
ÇØ°áÃ¥ °¨¿°µÈ ½Ã½ºÅÛÀ¸·Î ºÎÅÍ Portal of Doom ¹éµµ¾î¸¦ Á¦°ÅÇϱâ À§Çؼ­´Â ´ÙÀ½°ú °°ÀÌ ÇÑ´Ù.

1. Portal of Doom ÇÁ·Î±×·¥ (ljgz.exe)À» ÀÛµ¿ÁßÁö ½ÃŲ´Ù. ÀÌ ÇÁ·Î¼¼½º´Â ÀϹÝÀûÀÎ Windows ¹öÀü°ú´Â ´Ù¸£´Ù.
- Windows 95/98: MS-DOS ¸ðµå·Î ½Ã½ºÅÛÀ» Àç°¡µ¿½ÃŲ´Ù. ¸í·É ÇÁ·ÒÇÁÆ®¿¡¼­ C:\Windows\System\ljsgz.exeÀ» »èÁ¦ÇÑ´Ù.
- Windows NT: CTRL+ALT+DEL ۸¦ ´©¸¥ÈÄ, NT ÀÛ¾÷ °ü¸®ÀÚ¸¦ ¶ç¿î´Ù. ÇÁ·Î¼¼½º ÅÇÀ» Ŭ¸¯Çϰí ljgz.exeÀ» ã¾Æ¼­ ÇÁ·Î¼¼½º¸¦ Á¾·á½ÃŲ´Ù.
2. Regedit¸¦ »ç¿ëÇÏ¿© HKLM\Software\Microsoft\Windows\CurrentVersion\Run ·¹Áö½ºÆ®¸® ۸¦ ã´Â´Ù.
3. C:\Windows\System\lgsgz.exeÀÇ µ¥ÀÌŸ °ªÀ» °¡Áø ·¹Áö½ºÆ®¸® ¿£Æ®¸®ÀÇ ¹®ÀÚ¿­À» ã¾Æ¼­ ·¹Áö½ºÆ®¸® ¿£Æ®¸®¸¦ »èÁ¦ÇÑ´Ù.
°ü·Ã URL CVE-1999-0660 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)