English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24039
À§Çèµµ 40
Æ÷Æ® 1441
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡¼­ Remote Storm ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.

Remote StormÀº 2000³â 2¿ù¿¡ ºñÁê¾óº£ÀÌÁ÷(Visual Basic)À¸·Î ÀÛ¼ºµÈ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº Remote Storm.exe(¿¡ÀÌÀüÆ® ÇÁ·Î±×·¥), Extract.exe(¼­¹ö ÇÁ·Î±×·¥) ÆÄÀÏ·Î ±¸¼ºµÇ¾î ÀÖÀ¸¸ç µðÆúÆ® Æ÷Æ®·Î º¯°æÀÌ ºÒ°¡´ÉÇÑ 1441 TCP Æ÷Æ®¸¦ »ç¿ëÇÑ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥ÀÌ µ¿ÀÛÇϱâ À§Çؼ­´Â 'Mswinsck.ocx' ÆÄÀÏÀÌ ÇÊ¿äÇÏ´Ù. ¸¸¾à, ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥ÀÌ ½Ã½ºÅÛ¿¡ µ¿ÀÛÇϰí ÀÖ´Ù¸é 'HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run' À§Ä¡¿¡¼­ C:\WINDOWS\System\DllRun.exe °ªÀ» °¡Áø "WinManager" ۰¡ ¹ß°ßµÈ´Ù.

¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Remote Storm ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼­ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

- ¿Àµ¿ÀÛ(illegal operation) ¸Þ½ÃÁö Ç¥½Ã
- Ŭ¸³º¸µå Çã¿ë/±ÝÁö
- ´õºíŬ¸¯ Çã¿ë/±ÝÁö
- À©µµ¿ìÁî Á¾·á
- °ÅÁþ Æ÷¸ËÇϱâ(fake format)
- ÆÄÀÏ °ü¸®
- ¸ðµç ¾îÇø®ÄÉÀÌ¼Ç À©µµ¿ì â ÃÖ¼ÒÈ­
- CD-ROM ¿­±â/´Ý±â
- ¸Þ½ÃÁö/ÅØ½ºÆ® º¸³»±â
- À¥ÆäÀÌÁö ¿­±â
- ¼­¹ö ȯ°æ¼³Á¤(Á¾·á, Á¦°Å, ÆÐ½º¿öµå ¼³Á¤)
- È£½ºÆ®À̸§ ¼³Á¤
- ÇØ»óµµ ¼³Á¤
- È­¸éº¸È£±â ½ÃÀÛ
- ¸¶¿ì½º ¹öư ¹Ù²Ù±â
- ÇöÀç µ¿ÀÛÇÏ´Â ÇÁ·Î±×·¥ º¸±â/Á¾·á

Remote Storm¿¡´Â ½Ã½ºÅÛÀ» ÆÄ±«ÇÏÁø ¾ÊÁö¸¸ ¸Å¿ì À§ÇùÀûÀÎ ÀϺΠ¼û°ÜÁø ±â´ÉµéÀÌ Á¸ÀçÇÑ´Ù. ±× Áß °ÅÁþ Æ÷¸Ë(fake formatting) ±â´ÉÀº ½ÇÁ¦·Î ½Ã½ºÅÛÀ» Æ÷¸ËÇÏ´Â °ÍÀÌ ¾Æ´Ï¶ó ´ÜÁö µð½ºÅ© Æ÷¸Ëó·³ °¡ÀåÇÏ´Â °ÍÀÌ´Ù. ¶ÇÇÑ, °ÅÁþ ¿Àµ¿ÀÛ(fake illegal operation) ¸Þ½ÃÁö Ç¥½ÃÇϱâ´Â ¿Àµ¿ÀÛÀÌ ¹ß»ýÇß´Ù´Â ¿À·ù ¸Þ½ÃÁö¸¦ Ãâ·ÂÇÏ°í ¸¸¾à, ÇØ´ç ÇÁ·Î±×·¥ÀÌ ½ÇÇà ÁßÀ̶ó¸é ½ÇÁ¦·Î ÇÁ·Î±×·¥ ÀÚü¸¦ Á¾·áÇÑ´Ù.

* Ãë¾àÇÑ Ç÷§Æûµé :
Microsoft Windows Any version

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/reference/vuln/RemoteStorm.htm
http://www.iss.net/security_center/static/5362.php
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡¼­ ¹éµµ¾î¸¦ Á¦°ÅÇϱâ À§Çؼ­´Â

1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ 'WinManagerr' ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª DllRun.exe Á¾·áÇÑ´Ù.
4. À©µµ¿ìÁî ½Ã½ºÅÛ µð·ºÅ丮·ÎºÎÅÍ DllRun.exe, DllCount.sys ÆÄÀÏÀ» Á¦°ÅÇÑ´Ù.

-- ¶Ç´Â --

¹é½Å ÇÁ·Î±×·¥À» »ç¿ëÇÏ¿© Ä¡·áÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)