| Ãë¾àÁ¡ID |
24025 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
6723, ¡¦ |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
BackDoor |
| »ó¼¼¼³¸í |
ÇØ´ç ¼¹ö¿¡ mstream handler°¡ °¡µ¿µÇ°í ÀÖ´Ù. ÀÌ ÇÁ·Î±×·¥Àº ½Ã½ºÅÛÀ» Á¦¾îÇÏ¸é¼ ¶Ç´Ù¸¥ ³×Æ®¿öÅ©¸¦ °ø°ÝÇϴµ¥ »ç¿ëµÇ´Â ¹éµµ¾îÀÌ´Ù. Mstream ÇÁ·Î±×·¥Àº "stream.c" °ø°Ý¿¡ ±â¹ÝÀ» µÐ ºÐ»ê ¼ºñ½º °ÅºÎ °ø°Ý¿ë Åø·Î "handler"¿Í "agent"·Î ±¸¼ºµÈ´Ù. Handler´Â ¸ðµç agentµé¿¡ ´ëÇÑ Á¦¾î±ÇÀ» °®°í ÀÖ´Â ÅøÀÇ ºÎºÐÀÌ´Ù. Attacker´Â agentµéÀ» Á¦¾îÇϱâ À§ÇØ telnetÀ» ÀÌ¿ëÇÏ¿© handler¿¡ Á¢¼ÓÇϸç client, handler, ±×¸®°í agent °£ÀÇ Åë½ÅÀº ¾ÏȣȵÇÁö ¾Ê´Â´Ù. ÀÌ ºÐ»ê °ø°Ý ¹æ¹ýÀº ³×Æ®¿öÅ© bandwidthÀÇ »ç¿ëÀ²À» ¾öû³ª°Ô Áõ°¡½ÃŰ¸ç µ¿½Ã¿¡ CPU »ç¿ëÀ²µµ Áõ°¡½ÃŲ´Ù.
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/static/4370.php http://www.iss.net/security_center/alerts/advise48.php
* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû: Linux Any version Unix Any version |
| ÇØ°áÃ¥ |
ÇØ´ç ¼¹ö´Â ÀÌ¹Ì ÇØÄ¿¿¡ ÀÇÇØ ħÅõ ´çÇßÀ¸¹Ç·Î ¹éµµ¾î Á¦°Å ¹× ½Ã½ºÅÛÀÇ º¸¾È»óŸ¦ ÀüüÀûÀ¸·Î Á¡°ËÇÒ Çʿ䰡 ÀÖ´Ù. ¹éµµ¾î Á¦°Å¸¦ À§Çؼ ¸ÕÀú lsof¸¦ ÀÌ¿ëÇÏ¿© ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â Mstream handler ȤÀº agentÀÇ À§Ä¡¸¦ ã¾Æ¾ß ÇÑ´Ù. secuiSCAN¿¡ ÀÇÇØ ŽÁöµÈ Æ÷Æ®´Â lsof¸¦ ÀÌ¿ëÇÏ¿© ½ÇÇàÆÄÀÏÀÇ À§Ä¡¸¦ ãÀ» ¼ö ÀÖ´Â ´Ü¼°¡ µÈ´Ù. Mstream handler ȤÀº agentÀÇ À§Ä¡¸¦ ãÀº ÈÄ¿¡´Â ±× ÇÁ·Î¼¼½ºµéÀ» kill ½ÃŰ°í ½ÇÇàÆÄÀϵéÀº »èÁ¦ÇØ¾ß ÇÑ´Ù. ¶ÇÇÑ Ä§Åõ´çÇÑ ³ª¸ÓÁö agent ½Ã½ºÅÛµéÀ» ã±â À§Çؼ handler¿¡ µî·ÏµÈ agent ½Ã½ºÅÛµéÀÇ À§Ä¡¸¦ ã¾Æ¾ß ÇÑ´Ù.
1. Lsof¸¦ ÀÌ¿ëÇÏ¿© ½Ã½ºÅÛ »óÀÇ mstream handler ȤÀº agentÀÇ À§Ä¡ ã±â
¨ç handler ½ÇÇàÆÄÀÏ »ç¿ëÇϰí ÀÖ´Â port ¹øÈ£("6723")·Î ´ÙÀ½°ú °°ÀÌ ¸í·ÉÀ» ŸÀÌÇÎÇÑ´Ù.
[root@mars]# lsof -i TCP:6723 COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME master 7731 root 3u IPv4 343643 TCP *:6723 (LISTEN)
¨è 1¹ø¿¡¼ ã¾ÆÁø ÇÁ·Î¼¼½º¸í("master")À¸·Î ´ÙÀ½°ú °°ÀÌ ¸í·ÉÀ» ŸÀÌÇÎÇÑ´Ù.
[root@mars]# lsof -c master -a -d txt COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME master 7731 root txt REG 3,5 66221 2334456 /home/hero/mstream/master
2. ÇÁ·Î¼¼½º¸¦ kill ½ÃŰ°í ½ÇÇàÆÄÀÏ »èÁ¦
¨ç 'kill' ¸í·É¾î¿Í ÇÁ·Î¼¼½º ID ("7731")À» ÀÌ¿ëÇÏ¿© ÇÁ·Î¼¼½º¸¦ kill ½ÃŲ´Ù. ¨è mstream ½ÇÇàÆÄÀÏ ("master")À» »èÁ¦ÇÑ´Ù.
3. Handler¿¡ µî·ÏµÈ ¸ðµç agent ½Ã½ºÅÛÀÇ À§Ä¡ ÆÄ¾Ç
¨ç AgentµéÀÇ ¸ðµç IP ÁÖ¼ÒÀÇ ¾ÏÈ£ÈµÈ ¸®½ºÆ®¸¦ °¡Áö°í ÀÖ´Â "..." ȤÀº ".sr" ÆÄÀÏÀÇ À§Ä¡¸¦ ã´Â´Ù. ¨è ´ÙÀ½°ú °°ÀÌ shell ¸í·ÉÀ» ÀÌ¿ëÇÏ¿© ÆÄÀÏÀ» º¹È£ÈÇÑ´Ù.
[root@mars]# cat ... | tr 'b-k`' '0-9.' | sed 's/<$//'
4. °ø°Ý¿¡ ´ëÇÑ È®»êÀ» ¸·±â À§ÇÏ¿© CERT³ª °ü·Ã ±â°ü¿¡ ½Å°íÇÏ¿©¾ß ÇÑ´Ù. |
| °ü·Ã URL |
CVE-2000-0138 (CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|