English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24025
À§Çèµµ 40
Æ÷Æ® 6723, ¡¦
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ¼­¹ö¿¡ mstream handler°¡ °¡µ¿µÇ°í ÀÖ´Ù. ÀÌ ÇÁ·Î±×·¥Àº ½Ã½ºÅÛÀ» Á¦¾îÇϸ鼭 ¶Ç´Ù¸¥ ³×Æ®¿öÅ©¸¦ °ø°ÝÇϴµ¥ »ç¿ëµÇ´Â ¹éµµ¾îÀÌ´Ù. Mstream ÇÁ·Î±×·¥Àº "stream.c" °ø°Ý¿¡ ±â¹ÝÀ» µÐ ºÐ»ê ¼­ºñ½º °ÅºÎ °ø°Ý¿ë Åø·Î "handler"¿Í "agent"·Î ±¸¼ºµÈ´Ù. Handler´Â ¸ðµç agentµé¿¡ ´ëÇÑ Á¦¾î±ÇÀ» °®°í ÀÖ´Â ÅøÀÇ ºÎºÐÀÌ´Ù. Attacker´Â agentµéÀ» Á¦¾îÇϱâ À§ÇØ telnetÀ» ÀÌ¿ëÇÏ¿© handler¿¡ Á¢¼ÓÇϸç client, handler, ±×¸®°í agent °£ÀÇ Åë½ÅÀº ¾ÏȣȭµÇÁö ¾Ê´Â´Ù. ÀÌ ºÐ»ê °ø°Ý ¹æ¹ýÀº ³×Æ®¿öÅ© bandwidthÀÇ »ç¿ëÀ²À» ¾öû³ª°Ô Áõ°¡½ÃŰ¸ç µ¿½Ã¿¡ CPU »ç¿ëÀ²µµ Áõ°¡½ÃŲ´Ù.

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/4370.php
http://www.iss.net/security_center/alerts/advise48.php

* ¿µÇâÀ» ¹Þ´Â Ç÷§Æû:
Linux Any version
Unix Any version
ÇØ°áÃ¥ ÇØ´ç ¼­¹ö´Â ÀÌ¹Ì ÇØÄ¿¿¡ ÀÇÇØ ħÅõ ´çÇßÀ¸¹Ç·Î ¹éµµ¾î Á¦°Å ¹× ½Ã½ºÅÛÀÇ º¸¾È»óŸ¦ ÀüüÀûÀ¸·Î Á¡°ËÇÒ Çʿ䰡 ÀÖ´Ù. ¹éµµ¾î Á¦°Å¸¦ À§Çؼ­ ¸ÕÀú lsof¸¦ ÀÌ¿ëÇÏ¿© ½Ã½ºÅÛ »ó¿¡ ÀÖ´Â Mstream handler ȤÀº agentÀÇ À§Ä¡¸¦ ã¾Æ¾ß ÇÑ´Ù. secuiSCAN¿¡ ÀÇÇØ ŽÁöµÈ Æ÷Æ®´Â lsof¸¦ ÀÌ¿ëÇÏ¿© ½ÇÇàÆÄÀÏÀÇ À§Ä¡¸¦ ãÀ» ¼ö ÀÖ´Â ´Ü¼­°¡ µÈ´Ù. Mstream handler ȤÀº agentÀÇ À§Ä¡¸¦ ãÀº ÈÄ¿¡´Â ±× ÇÁ·Î¼¼½ºµéÀ» kill ½ÃŰ°í ½ÇÇàÆÄÀϵéÀº »èÁ¦ÇØ¾ß ÇÑ´Ù. ¶ÇÇÑ Ä§Åõ´çÇÑ ³ª¸ÓÁö agent ½Ã½ºÅÛµéÀ» ã±â À§Çؼ­ handler¿¡ µî·ÏµÈ agent ½Ã½ºÅÛµéÀÇ À§Ä¡¸¦ ã¾Æ¾ß ÇÑ´Ù.

1. Lsof¸¦ ÀÌ¿ëÇÏ¿© ½Ã½ºÅÛ »óÀÇ mstream handler ȤÀº agentÀÇ À§Ä¡ ã±â

¨ç handler ½ÇÇàÆÄÀÏ »ç¿ëÇϰí ÀÖ´Â port ¹øÈ£("6723")·Î ´ÙÀ½°ú °°ÀÌ ¸í·ÉÀ» ŸÀÌÇÎÇÑ´Ù.

[root@mars]# lsof -i TCP:6723
COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME
master 7731 root 3u IPv4 343643 TCP *:6723 (LISTEN)

¨è 1¹ø¿¡¼­ ã¾ÆÁø ÇÁ·Î¼¼½º¸í("master")À¸·Î ´ÙÀ½°ú °°ÀÌ ¸í·ÉÀ» ŸÀÌÇÎÇÑ´Ù.

[root@mars]# lsof -c master -a -d txt
COMMAND PID USER FD TYPE DEVICE SIZE NODE NAME
master 7731 root txt REG 3,5 66221 2334456 /home/hero/mstream/master

2. ÇÁ·Î¼¼½º¸¦ kill ½ÃŰ°í ½ÇÇàÆÄÀÏ »èÁ¦

¨ç 'kill' ¸í·É¾î¿Í ÇÁ·Î¼¼½º ID ("7731")À» ÀÌ¿ëÇÏ¿© ÇÁ·Î¼¼½º¸¦ kill ½ÃŲ´Ù.
¨è mstream ½ÇÇàÆÄÀÏ ("master")À» »èÁ¦ÇÑ´Ù.

3. Handler¿¡ µî·ÏµÈ ¸ðµç agent ½Ã½ºÅÛÀÇ À§Ä¡ ÆÄ¾Ç

¨ç AgentµéÀÇ ¸ðµç IP ÁÖ¼ÒÀÇ ¾ÏȣȭµÈ ¸®½ºÆ®¸¦ °¡Áö°í ÀÖ´Â "..." ȤÀº ".sr" ÆÄÀÏÀÇ À§Ä¡¸¦ ã´Â´Ù.
¨è ´ÙÀ½°ú °°ÀÌ shell ¸í·ÉÀ» ÀÌ¿ëÇÏ¿© ÆÄÀÏÀ» º¹È£È­ÇÑ´Ù.

[root@mars]# cat ... | tr 'b-k`' '0-9.' | sed 's/<$//'

4. °ø°Ý¿¡ ´ëÇÑ È®»êÀ» ¸·±â À§ÇÏ¿© CERT³ª °ü·Ã ±â°ü¿¡ ½Å°íÇÏ¿©¾ß ÇÑ´Ù.
°ü·Ã URL CVE-2000-0138 (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)