| Ãë¾àÁ¡ID |
24043 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
666 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
BackDoor |
| »ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡¼ Satan's BackDoor ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù. Satan's BackDoor´Â 1999³â 2¿ù¿¡ ºñÁê¾óº£ÀÌÁ÷ 6(Visual Basic 6)À¸·Î ÀÛ¼ºµÈ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº ¿ø°Ý Á¦¾î°¡ °¡´ÉÇÑ ¿¡ÀÌÀüÆ® ÇÁ·Î±×·¥ÀÎ SBD2 Client BETA.exe(¶Ç´Â, Client.exe)¿Í ´ë»ó ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ´Â ¼¹öÇÁ·Î±×·¥ÀÎ winvmm32.exeÀ¸·Î ±¸¼ºµÇ¾î ÀÖ´Ù. ÀÌ ÇÁ·Î±×·¥Àº ±âº»ÀûÀ¸·Î º¯°æ ºÒ°¡´ÉÇÑ 666 TCP Æ÷Æ®¸¦ »ç¿ëÇÑ´Ù. ÇÁ·Î±×·¥ÀÌ µ¿ÀÛÇϱâ À§Çؼ´Â ¼¼ °³ÀÇ ÆÄÀÏ mswinsck.ocx, msvbvm60.dll, Comdlg32.ocx°¡ ÇÊ¿äÇÏ´Ù. ¸¸¾à, ½Ã½ºÅÛ¿¡ ¹öÀü 2.0beta °¡ ¼³Ä¡µÇ¾î ÀÖ´Ù¸é auload Á¤º¸´Â ãÀ» ¼ö ¾ø´Ù. ±×·¯³ª, ¹öÀü 1.0ÀÇ °æ¿ì¿¡´Â'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runservices' À§Ä¡¿¡¼ C:\\windows\\sysprot.exe °ªÀ» °¡Áø "sysprot Protection" ۰¡ ¹ß°ßµÈ´Ù.
¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Satan's BackDoor ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.
- °ÅÁþ(fake) ´ÙÀ̾ó·Î±× âÀ» ¶ç¿ö »ç¿ëÀÚ¸í°ú ÆÐ½º¿öµå¸¦ ÀԷ¹ޱâ. - ¸Þ½ÃÁö ¹Ú½º ¶ç¿ì±â - ½Ã½ºÅÛ¿¡ ÀúÀåµÈ ÆÐ½º¿öµå ȹµæÇϱâ - Ŭ¸³º¸µå¿¡ ÀúÀåµÈ ÅØ½ºÆ® ȹµæÇϱâ - ³¯Â¥/½Ã°£ ȹµæ ¹× º¯°æÇϱâ - ¸Þ½ÃÁö ¹Ú½º ÆøÅº º¸³»±â(¿¬¼ÓÀûÀÎ ¸Þ½ÃÁö ¹Ú½º ¶ç¿ì±â : ÀçºÎÆÃ ¿ä±¸) - ½Ã½ºÅÛ Á¤º¸ ȹµæÇϱâ - ÇÁ·Î±×·¥ ½ÇÇàÇϱâ - ¾×ƼºêµÈ À©µµ¿ì·Î Key Stroke º¸³»±â - Ű ·Î±ë(key logging)
* Ãë¾àÇÑ Ç÷§Æû : Microsoft Windows Any version
* Âü°í »çÀÌÆ®: http://www.iss.net/security_center/reference/vuln/SatansBackdoor.htm http://xforce.iss.net/xforce/xfdb/4149 |
| ÇØ°áÃ¥ |
½Ã½ºÅÛ¿¡¼ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.
* ¹öÀü 2.0beta : 1. ½Ã½ºÅÛ ÀçºÎÆÃÇϰųª winvmm32.exe ¸¦ Á¾·áÇÑ´Ù. 2. Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ winvmm32.exe¸¦ Á¦°ÅÇÑ´Ù.
* ¹öÀü 1.0 : 1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Runservices À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼ 'sysprot Protection' ۸¦ Á¦°ÅÇÑ´Ù. 2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª sysprot.exe¸¦ Á¾·áÇÑ´Ù. 3. À©µµ¿ìÁî µð·ºÅ丮¿¡¼ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ sysprot.exe¸¦ Á¦°ÅÇÑ´Ù.
-- ¶Ç´Â --
¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|