| Ãë¾àÁ¡ID |
24040 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
36794 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
BackDoor |
| »ó¼¼¼³¸í |
BugBear ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù. BugBear ¹éµµ¾î´Â BugBear ¿úÀÇ ÇÑ ºÎºÐÀ¸·Î key logger¸¦ Æ÷ÇÔÇϰí ÀÖÀ¸¸ç ¾ÈƼ¹ÙÀÌ·¯½º³ª °³ÀÎ¿ë ¹æÈº® ¼ÒÇÁÆ®¿þ¾îµéÀ» Á׿© ¹ö¸°´Ù. BugBear ¿úÀº ÷ºÎµéÀ» Æ÷ÇÔÇÑ EmailµéÀ» º¸³¿À¸·Î½á È®»êÇϸç, ³×Æ®¿öÅ© »óÀÇ °øÀ¯ ÀÚ¿øµéÀ» ã¾Æ ÀÚ±âÀÚ½ÅÀ» º¹Á¦ÇÒ ¼öµµ ÀÖ´Ù. ¾ÈƼ¹ÙÀÌ·¯½º º¥´õ¿¡ µû¸£¸é W32/Bugbear-A [Sophos], WORM_BUGBEAR.A [Trend], Win32.Bugbear [CA], W32/Bugbear@MM [McAfee], I-Worm.Tanatos [AVP], W32/Bugbear [Panda], Tanatos [F-Secure], µîµîÀÇ À̸§À¸·Î ¾Ë·ÁÁ® ÀÖ´Ù.
BugBear ¹éµµ¾î´Â 36794 Æ÷Æ®¸¦ ¿ÀÇÂÇÏ°í ¿ø°ÝÁö ¸Ó½ÅÀ¸·ÎºÎÅÍ ¸í·ÉÀ» ±â´Ù¸°´Ù. ¿ø°ÝÁöÀÇ °ø°ÝÀÚµéÀº Èñ»ýÀÚÀÇ ÄÄÇ»ÅÍ¿¡ ´ÙÀ½°ú °°Àº ÀϵéÀ» ÇÒ ¼ö ÀÖ´Â ¸í·ÉµéÀ» º¸³¾ ¼ö ÀÖ´Ù:
- ¾ÏÈ£ÈµÈ ÇüÅ·Πij½¬¿¡ ÀúÀåµÈ ÆÐ½º¿öµåµéÀ» °Ë»öÇÑ´Ù. - ÆÄÀϵéÀ» ´Ù¿î·ÎµåÇÏ°í ½ÇÇàÇÑ´Ù. - ÆÄÀϵéÀ» ã´Â´Ù. - ÆÄÀϵéÀ» »èÁ¦ÇÑ´Ù. - ÆÄÀϵéÀ» º¹»çÇÑ´Ù. - ÆÄÀϵéÀ» »ý¼ºÇÑ´Ù. - ÇÁ·Î¼¼½ºÀÇ ¸®½ºÆ®¸¦ º»´Ù. - ÇÁ·Î¼¼½ºµéÀ» Á¾·á½ÃŲ´Ù. - »ç¿ëÀÚ¸í, ÇÁ·Î¼¼½ºÀÇ ÇüÅÂ, À©µµ¿ìÁî ¹öÀü, ¸Þ¸ð¸® Á¤º¸ (»ç¿ë·®, °¡¿ë·® µî), µå¶óÀ̺ê Á¤º¸ (°¡¿ëÇÑ ·ÎÄà µå¶óÀ̺êÀÇ ÇüÅÂ, ÀÌµé µå¶óÀ̺꿡 ÀÖ´Â ³²Àº ¿ë·® µî)°ú °°Àº Á¤º¸¸¦ °Ë»öÇÑ´Ù.
Ãë¾àÇÑ Ç÷§Æû: Microsoft Windows Any version
* Âü°í »çÀÌÆ®: http://www.sophos.com/virusinfo/analyses/w32bugbeara.html http://www.ealaddin.com/news/2002/esafe/bugbear.asp http://securityresponse.symantec.com/avcenter/venc/data/w32.bugbear@mm.html |
| ÇØ°áÃ¥ |
1. ¾ÈƼ ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥µéÀ̳ª ¹«·á °¨¿°Á¦°Å ÅøµéÀ» ÀÌ¿ëÇÏ¿© ¿úÀ» Á¦°ÅÇÑ´Ù. 2. °¨¿°µÈ ÄÄÇ»ÅÍÀÇ À©µµ¿ìÁî °øÀ¯µéÀ» ¾ø¾Ø´Ù. 3. °¨¿°µÈ ÄÄÇ»ÅÍ¿¡ ÀÖ´Â Outlook, ÀÎÅÍ³Ý ÀͽºÇ÷η¯ ºê¶ó¿ìÀú ±×¸®°í Outlook Express¸¦ ¾÷µ¥ÀÌÆ®ÇÑ´Ù. ÆÐÄ¡´Â ¸¶ÀÌÅ©·Î¼ÒÇÁÆ® º¸¾È °Ô½ÃÆÇ MS01-027 ·ÎºÎÅÍ ´Ù¿î·Îµå ¹ÞÀ» ¼ö ÀÖ´Ù. (ÀÌ ÆÐÄ¡´Â ÀÌ ¿ú¿¡ ÀÇÇØ µµ¿ëµÇ´Â °ÍµéÀ» Æ÷ÇÔÇÏ¿© ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®ÀÇ ¼ÒÇÁÆ®¿þ¾î¿¡ ÀÖ´Â ´Ù¼öÀÇ Ãë¾àÁ¡µéÀ» Á¦°ÅÇØ ÁØ´Ù): http://www.microsoft.com/technet/security/bulletin/MS01-027.asp
¹«·á BugBear ¿ú °¨¿°Á¦°Å Åø: - ¼³¸íÀÌ Æ÷ÇÔµÈ Self-extracting ½ÇÇàÆÄÀÏ: http://www.sophos.com/tools/bearsfx.exe - ¼³¸íÀÌ Æ÷ÇÔµÈ Zip ¹öÀü: http://www.sophos.com/tools/bear.zip |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|