English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24042
À§Çèµµ 40
Æ÷Æ® 1020,6669
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡¼­ Vampire ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.
Vampire ¹éµµ¾î´Â 1999³â 6¿ù¿¡ ºñÁê¾óº£ÀÌÁ÷(Visual Basic)À¸·Î ÀÛ¼ºµÈ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº ¿ø°Ý Á¦¾î°¡ °¡´ÉÇÑ ¿¡ÀÌÀüÆ® ÇÁ·Î±×·¥ÀÎ Vampire.exe¿Í ´ë»ó ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ´Â ¼­¹öÇÁ·Î±×·¥ÀÎ server.exeÀ¸·Î ±¸¼ºµÇ¾î ÀÖ´Ù. ÀÌ ÇÁ·Î±×·¥Àº ±âº»ÀûÀ¸·Î º¯°æ ºÒ°¡´ÉÇÑ 6669(¹öÀü 1.0), 1020(¹öÀü 1.2) TCP Æ÷Æ®¸¦ »ç¿ëÇÑ´Ù. ÇÁ·Î±×·¥ÀÌ µ¿ÀÛÇϱâ À§Çؼ­´Â µÎ °³ÀÇ ÆÄÀÏ msvbvm60.dll, mswinsck.ocx ÀÌ ÇÊ¿äÇÏ´Ù. ¸¸¾à, ½Ã½ºÅÛ¿¡ ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥ÀÌ µ¿ÀÛÇϰí ÀÖ´Ù¸é, 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run' À§Ä¡¿¡¼­ c:\windows\system\Winboot.exe °ªÀ» °¡Áø "WindowsBootFile" ۰¡ ¹ß°ßµÈ´Ù.

¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Vampire ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼­ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

- ÀÛ¾÷ Ç¥½ÃÁÙ °¨Ãã/º¸ÀÓ
- äÆÃ
- ÇöÀç µ¥½ºÅ©Å¾ È­¸é ĸÃç(screehshot)
- ¸Þ½ÃÁö Àü¼Û
- ALT+CTRL+DEL Çã¿ë/±ÝÁö
- CD-ROM ¿­±â/´Ý±â
- ½Ã½ºÅÛ Á¤º¸ ȹµæ(Çϵåµå¶óÀ̺ê, ¼­¹ö°æ·Î, ¿î¿µÃ¼Á¦, ½Ã½ºÅÛ ¼ÒÀ¯ÀÚ, µð½ºÅ© ½Ã¸®¾ó ¹øÈ£, ...)
- ÆÄÀÏ °ü¸®(µð·ºÅ丮 »ý¼º/»èÁ¦, ÆÄÀÏ Ã£±â/»èÁ¦/ÆÄ±«, ...)
- ¼­¹ö ÇÁ·Î±×·¥ Á¾·á
- ¾îÇø®ÄÉÀÌ¼Ç À©µµ¿ì â Á¾·á
- ·¹Áö½ºÆ®¸® ÆÄ±«
- µå¶óÀÌºê Æ÷¸Ë
- ½Ã½ºÅÛ Á¾·á/ÀçºÎÆÃ
- ·Î±× ¿Â/¿ÀÇÁ
- À¥ ÆäÀÌÁö ¿­±â
- ÇÁ·Î±×·¥ ½ÇÇà
- È£½ºÆ®À̸§/º¼·ý ·¹À̺í(volume label) ¼³Á¤
- À©µµ¿ìÁî Á¾·á
- ¸ð´ÏÅÍ ¿Â/¿ÀÇÁ

* Ãë¾àÇÑ Ç÷§Æû :
Microsoft Windows Any version

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/reference/vuln/Vampire_TCP_Response.htm
http://www.microsoft.com/security/portal/Threat/Encyclopedia/Entry.aspx?Name=Backdoor%3AWin32%2FVampire&ThreatID=24889
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡¼­ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.

1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ 'WindowsBootFile' ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Winboot.exeÀ» Á¾·áÇÑ´Ù.
3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼­ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Winboot.exeÀ» Á¦°ÅÇÑ´Ù.

-- ¶Ç´Â --

¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)