English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24040
À§Çèµµ 40
Æ÷Æ® 36794
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í BugBear ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù. BugBear ¹éµµ¾î´Â BugBear ¿úÀÇ ÇÑ ºÎºÐÀ¸·Î key logger¸¦ Æ÷ÇÔÇϰí ÀÖÀ¸¸ç ¾ÈƼ¹ÙÀÌ·¯½º³ª °³ÀÎ¿ë ¹æÈ­º® ¼ÒÇÁÆ®¿þ¾îµéÀ» Á׿© ¹ö¸°´Ù. BugBear ¿úÀº ÷ºÎµéÀ» Æ÷ÇÔÇÑ EmailµéÀ» º¸³¿À¸·Î½á È®»êÇϸç, ³×Æ®¿öÅ© »óÀÇ °øÀ¯ ÀÚ¿øµéÀ» ã¾Æ ÀÚ±âÀÚ½ÅÀ» º¹Á¦ÇÒ ¼öµµ ÀÖ´Ù. ¾ÈƼ¹ÙÀÌ·¯½º º¥´õ¿¡ µû¸£¸é W32/Bugbear-A [Sophos], WORM_BUGBEAR.A [Trend], Win32.Bugbear [CA], W32/Bugbear@MM [McAfee], I-Worm.Tanatos [AVP], W32/Bugbear [Panda], Tanatos [F-Secure], µîµîÀÇ À̸§À¸·Î ¾Ë·ÁÁ® ÀÖ´Ù.

BugBear ¹éµµ¾î´Â 36794 Æ÷Æ®¸¦ ¿ÀÇÂÇÏ°í ¿ø°ÝÁö ¸Ó½ÅÀ¸·ÎºÎÅÍ ¸í·ÉÀ» ±â´Ù¸°´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀº Èñ»ýÀÚÀÇ ÄÄÇ»ÅÍ¿¡ ´ÙÀ½°ú °°Àº ÀϵéÀ» ÇÒ ¼ö ÀÖ´Â ¸í·ÉµéÀ» º¸³¾ ¼ö ÀÖ´Ù:

- ¾ÏȣȭµÈ ÇüÅ·Πij½¬¿¡ ÀúÀåµÈ ÆÐ½º¿öµåµéÀ» °Ë»öÇÑ´Ù.
- ÆÄÀϵéÀ» ´Ù¿î·ÎµåÇÏ°í ½ÇÇàÇÑ´Ù.
- ÆÄÀϵéÀ» ã´Â´Ù.
- ÆÄÀϵéÀ» »èÁ¦ÇÑ´Ù.
- ÆÄÀϵéÀ» º¹»çÇÑ´Ù.
- ÆÄÀϵéÀ» »ý¼ºÇÑ´Ù.
- ÇÁ·Î¼¼½ºÀÇ ¸®½ºÆ®¸¦ º»´Ù.
- ÇÁ·Î¼¼½ºµéÀ» Á¾·á½ÃŲ´Ù.
- »ç¿ëÀÚ¸í, ÇÁ·Î¼¼½ºÀÇ ÇüÅÂ, À©µµ¿ìÁî ¹öÀü, ¸Þ¸ð¸® Á¤º¸ (»ç¿ë·®, °¡¿ë·® µî), µå¶óÀ̺ê Á¤º¸ (°¡¿ëÇÑ ·ÎÄà µå¶óÀ̺êÀÇ ÇüÅÂ, ÀÌµé µå¶óÀ̺꿡 ÀÖ´Â ³²Àº ¿ë·® µî)°ú °°Àº Á¤º¸¸¦ °Ë»öÇÑ´Ù.

Ãë¾àÇÑ Ç÷§Æû:
Microsoft Windows Any version

* Âü°í »çÀÌÆ®:
http://www.sophos.com/virusinfo/analyses/w32bugbeara.html
http://www.ealaddin.com/news/2002/esafe/bugbear.asp
http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbear@mm.html
ÇØ°áÃ¥ 1. ¾ÈƼ ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥µéÀ̳ª ¹«·á °¨¿°Á¦°Å ÅøµéÀ» ÀÌ¿ëÇÏ¿© ¿úÀ» Á¦°ÅÇÑ´Ù.
2. °¨¿°µÈ ÄÄÇ»ÅÍÀÇ À©µµ¿ìÁî °øÀ¯µéÀ» ¾ø¾Ø´Ù.
3. °¨¿°µÈ ÄÄÇ»ÅÍ¿¡ ÀÖ´Â Outlook, ÀÎÅÍ³Ý ÀͽºÇ÷η¯ ºê¶ó¿ìÀú ±×¸®°í Outlook Express¸¦ ¾÷µ¥ÀÌÆ®ÇÑ´Ù. ÆÐÄ¡´Â ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½ÃÆÇ MS01-027 ·ÎºÎÅÍ ´Ù¿î·Îµå ¹ÞÀ» ¼ö ÀÖ´Ù. (ÀÌ ÆÐÄ¡´Â ÀÌ ¿ú¿¡ ÀÇÇØ µµ¿ëµÇ´Â °ÍµéÀ» Æ÷ÇÔÇÏ¿© ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®ÀÇ ¼ÒÇÁÆ®¿þ¾î¿¡ ÀÖ´Â ´Ù¼öÀÇ Ãë¾àÁ¡µéÀ» Á¦°ÅÇØ ÁØ´Ù): http://www.microsoft.com/technet/security/bulletin/MS01-027.asp

¹«·á BugBear ¿ú °¨¿°Á¦°Å Åø:
- ¼³¸íÀÌ Æ÷ÇÔµÈ Self-extracting ½ÇÇàÆÄÀÏ: http://www.sophos.com/tools/bearsfx.exe
- ¼³¸íÀÌ Æ÷ÇÔµÈ Zip ¹öÀü: http://www.sophos.com/tools/bear.zip
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)