English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24038
À§Çèµµ 40
Æ÷Æ® 16969
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡¼­ Priority ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.

Priority´Â 1999³â 2¿ù¿¡ ºñÁê¾óº£ÀÌÁ÷ 5(Visual Basic 5)À¸·Î ÀÛ¼ºµÈ °£´ÜÇÑ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº PRIORITY.exe(¿¡ÀÌÀüÆ® ÇÁ·Î±×·¥), PSERVER.exe(¼­¹ö ÇÁ·Î±×·¥) ÆÄÀÏ·Î ±¸¼ºµÇ¾î ÀÖÀ¸¸ç µðÆúÆ® Æ÷Æ®·Î º¯°æÀÌ ºÒ°¡´ÉÇÑ 16969 TCP Æ÷Æ®¸¦ »ç¿ëÇÑ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº PingPong ¹ÙÀÌ·¯½º¸¦ Â÷´ÜÇÒ ¼ö ÀÖ´Ù. ¸¸¾à, ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥ÀÌ ½Ã½ºÅÛ¿¡ µ¿ÀÛÇϰí ÀÖ´Ù¸é 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices' À§Ä¡¿¡¼­ C:\Windows\System\PServer.exe °ªÀ» °¡Áø "PServer" ۰¡ ¹ß°ßµÈ´Ù.

¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Priority ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼­ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

- °æÀû ¿ï¸®±â
- ºí·¢ ½ºÅ©¸° ¸¸µé±â
- ¼­¹ö/Ŭ¶óÀÌ¾ðÆ® Ã¤ÆÃ
- ¼­¹ö ÇÁ·Î±×·¥ Á¾·á
- ÇöÀç Á¢¼Ó ÁßÀΠŬ¶óÀÌ¾ðÆ® ¼ö °Ë»ö
- ÀÛ¾÷ Ç¥½ÃÁÙ ¼û±è
- ICQ ÆÐ½º¿öµå °¡·Îä±â
- ¸¶¿ì½º Àá±Ý
- ¾îÇø®ÄÉÀÌ¼Ç À©µµ¿ì â ÃÖ¼ÒÈ­
- À¥ÆäÀÌÁö ¿­±â
- CD-ROM ¿­±â/´Ý±â
- pingpong Çã¿ë/±ÝÁö
- ¾îÇø®ÄÉÀÌ¼Ç ½ÇÇà
- ¸Þ½ÃÁö º¸³»±â
- À̹ÌÁö º¸±â
- ½Ã½ºÅÛ Á¾·á
- ¸¶¿ì½º ¹öư ¹Ù²Ù±â
- ÀÛ¾÷ °ü¸®
- À©µµ¿ìÁî ÆÐ½º¿öµå °¡·Îä±â

* Ãë¾àÇÑ Ç÷§Æû :
Microsoft Windows Any version

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/static/3585.php
http://www.dark-e.com/archive/trojans/priority/beta/index.shtml
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡¼­ ¹éµµ¾î¸¦ Á¦°ÅÇϱâ À§Çؼ­´Â

1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ 'PServer' ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª PServer.exe Á¾·áÇÑ´Ù.
4. À©µµ¿ìÁî ½Ã½ºÅÛ µð·ºÅ丮·ÎºÎÅÍ PServer.exe ÆÄÀÏÀ» Á¦°ÅÇÑ´Ù.

-- ¶Ç´Â --

¹é½Å ÇÁ·Î±×·¥À» »ç¿ëÇÏ¿© Ä¡·áÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)