English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24035
À§Çèµµ 40
Æ÷Æ® 20001
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡¼­ Millenium ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.

MilleniumÀº 1998³â 11¿ù¿¡ ºñÁê¾óº£ÀÌÁ÷À¸·Î ÀÛ¼ºµÈ °£´ÜÇÑ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº client.exe(¿¡ÀÌÀüÆ® ÇÁ·Î±×·¥), server.exe(¼­¹ö ÇÁ·Î±×·¥) ÆÄÀÏ·Î ±¸¼ºµÇ¾î ÀÖÀ¸¸ç µðÆúÆ® Æ÷Æ®·Î º¯°æÀÌ ºÒ°¡´ÉÇÑ 20001 TCP Æ÷Æ®¸¦ »ç¿ëÇÑ´Ù. ¸¸¾à, ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥ÀÌ ½Ã½ºÅÛ¿¡ µ¿ÀÛÇϰí ÀÖ´Ù¸é 'HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run' À§Ä¡¿¡¼­ C:\Windows\System\Reg66.exe °ªÀ» °¡Áø "Millenium" ۰¡ ¹ß°ßµÈ´Ù.

¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ millenium ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼­ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

- ¼­¹ö(target system)¿Í äÆÃ
- ¼­¹ö ¼³Á¤
- NetBus Á¦¾î
- Alt-Ctrl-Del Çã¿ë/±ÝÁö
- ÆÄÀÏ °ü¸®
- ¿¬°á ÇØÁ¦
- CD-ROM ¿­±â/´Ý±â
- ½ºÅ©¸° À̹ÌÁö ĸÃç
- Ű Àü´ÞÇϱâ
- ¸Þ½ÃÁö º¸³»±â
- ½Ã½ºÅÛ Á¾·á, ½Ã½ºÅÛ ´Ù½Ã ½ÃÀÛ, ·Î±×¿ÀÇÁ, MS-DoS ¸ðµå¿¡¼­ ´Ù½Ã ½ÃÀÛ

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/reference/vulntemp/backdoor-millenium.htm
http://www.iss.net/security_center/static/3111.php

* Ãë¾àÇÑ Ç÷§Æû :
Microsoft Windows Any version
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡¼­ ´ÙÀ½°ú °°Àº ¹æ¹ýÀ¸·Î ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.

1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ 'Millenium' ۸¦ Á¦°ÅÇÑ´Ù.
2. win.ini ÆÄÀÏÀÇ [windows]¿¡¼­ run=c:\windows\system\reg66.exe ¸¦ Á¦°ÅÇÑ´Ù.
3. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª reg66.exe Á¾·áÇÑ´Ù.
4. À©µµ¿ìÁî ½Ã½ºÅÛ µð·ºÅ丮·ÎºÎÅÍ reg66.exe ÆÄÀÏÀ» Á¦°ÅÇÑ´Ù.

-- ¶Ç´Â --

¹é½Å ÇÁ·Î±×·¥À» »ç¿ëÇÏ¿© Ä¡·áÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)