| Ãë¾àÁ¡ID |
24036 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
10607 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
BackDoor |
| »ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡¼ Coma ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.
Coma´Â 1999³â 3¿ù¿¡ ºñÁê¾óº£ÀÌÁ÷ 5(Visual Basic 5)À¸·Î ÀÛ¼ºµÈ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥À¸·Î ¿À·¡µÇ¾î ÇöÀç¿¡´Â ´ëºÎºÐ »ç¿ëÇÏÁö ¾Ê´Â´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº comaclient.exe(¿¡ÀÌÀüÆ® ÇÁ·Î±×·¥), comserv.exe(¼¹ö ÇÁ·Î±×·¥) ÆÄÀÏ·Î ±¸¼ºµÇ¾î ÀÖÀ¸¸ç µðÆúÆ® Æ÷Æ®·Î º¯°æÀÌ ºÒ°¡´ÉÇÑ 10607 TCP Æ÷Æ®¸¦ »ç¿ëÇÑ´Ù. ÀÌ ¹éµµ¾î°¡ µ¿ÀÛÇϱâ À§Çؼ´Â Msvbvm50.dll and Mswinsck.ocx ÆÄÀÏÀÌ ÇÊ¿äÇÏ´Ù. ¸¸¾à, ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥ÀÌ ½Ã½ºÅÛ¿¡ µ¿ÀÛÇϰí ÀÖ´Ù¸é 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' À§Ä¡¿¡¼ C:\Windows\Msgsrv36.exe °ªÀ» °¡Áø "RunTime" ۰¡ ¹ß°ßµÈ´Ù.
¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Coma ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ´ë»ó½Ã½ºÅÛ¿¡¼ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.
- ¼¹ö ½Ã½ºÅÛ°ú äÆÃ - ¼¹ö ÇÁ·Î±×·¥ Á¾·á - ÀÓÀÇÀÇ ÇÁ·Î±×·¥ ½ÇÇà - FTP¸¦ ÅëÇØ¼ ÆÄÀÏ Àü¼Û - ½Ã½ºÅÛ Á¤º¸ À¯Ãâ - Listen (?) - ¸Þ½ÃÁö Àü¼Û - CD-ROM ¿±â/´Ý±â - ¸Þ½ÃÁö Ãâ·Â - ¼¹ö ÇÁ·Î±×·¥ Á¦°ÅÇϱâ - ¸í·É¾î Àü´Þ
* Ãë¾àÇÑ Ç÷§Æû: Microsoft Windows Any version
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/reference/vuln/Coma_Response.htm http://www.dark-e.com/archive/trojans/coma/index.shtml http://www.iss.net/security_center/static/2386.php |
| ÇØ°áÃ¥ |
½Ã½ºÅÛ¿¡¼ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼ 'RunTime' ۸¦ Á¦°ÅÇÑ´Ù. 2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Msgsrv36.exe Á¾·áÇÑ´Ù. 4. À©µµ¿ìÁî ½Ã½ºÅÛ µð·ºÅ丮·ÎºÎÅÍ Msgsrv36.exe ÆÄÀÏÀ» Á¦°ÅÇÑ´Ù.
-- ¶Ç´Â --
¹é½Å ÇÁ·Î±×·¥À» »ç¿ëÇÏ¿© Ä¡·áÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|