English
¢¸¢· µÚ·Î
Ãë¾àÁ¡ID 24044
À§Çèµµ 40
Æ÷Æ® 21,5400,5401,5402
ÇÁ·ÎÅäÄÝ TCP
ºÐ·ù BackDoor
»ó¼¼¼³¸í ÇØ´ç ½Ã½ºÅÛ¿¡¼­ Blade Runner ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù.
Blade Runner´Â 1999³â 3¿ù¿¡ µ¨ÆÄÀÌ 3(Delphi 3)·Î ÀÛ¼ºµÈ ¿ÀÇ ¼Ò½º Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº ¿ø°Ý Á¦¾î°¡ °¡´ÉÇÑ ¿¡ÀÌÀüÆ® ÇÁ·Î±×·¥ÀÎ Client.exe¿Í ´ë»ó ½Ã½ºÅÛ¿¡ ¼³Ä¡µÇ´Â ¼­¹ö ÇÁ·Î±×·¥ÀÎ Server.exeÀ¸·Î ±¸¼ºµÇ¾î ÀÖ´Ù. ÀÌ ÇÁ·Î±×·¥Àº ±âº»ÀûÀ¸·Î º¯°æÀÌ ºÒ°¡´ÉÇÑ 21(FTP), 5400, 5401, 5402 TCP Æ÷Æ®¸¦ »ç¿ëÇÑ´Ù. ¸¸¾à, ½Ã½ºÅÛ¿¡ ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥ÀÌ µ¿ÀÛÇϰí ÀÖ´Ù¸é, 'HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run' À§Ä¡¿¡¼­ "System-Tray" ۰¡ ¹ß°ßµÈ´Ù.

¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Blade Runner ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼­ ´ÙÀ½°ú °°Àº ÀϵéÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.

- äÆÃ
- ÆÄÀÏ °ü¸®(Ž»ö, ¾÷·Îµå/´Ù¿î·Îµå, µð·ºÅ丮 »ý¼º/Á¦°Å,....)
- FTP ¼­ºñ½º Çã¿ë/±ÝÁö
- ICQ uin ȹµæ
- ½Ã½ºÅÛ Á¤º¸(»ç¿ëÀÚ, ¿î¿µÃ¼Á¦, ÇÁ·Î¼¼¼­, ÇØ»óµµ,...) ȹµæ
- ½Ã½ºÅÛ ½Ã°£ ȹµæ
- ¸¶¿ì½º Ä¿¼­ °¨Ãã/º¸ÀÓ
- ¼­¹ö ÇÁ·Î±×·¥ Á¾·á
- CD-ROM ¿­±â/´Ý±â
- ÆË¾÷ ¸Þ½ÃÁö ¶ç¿ì±â
- ÆÄÀÏ ½ÇÇà
- À̹ÌÁö º¸À̱â
- ½ÃÀÛ ¹öư °¨Ãã/º¸ÀÓ
- ¾îÇø®ÄÉÀÌ¼Ç º¸±â/ Á¾·á

* Ãë¾àÇÑ Ç÷§Æû :
Microsoft Windows Any version

* Âü°í »çÀÌÆ®:
http://www.iss.net/security_center/reference/vuln/BladeRunner_TCP_Request.htm
http://www.dark-e.com/archive/trojans/blade/index.shtml
ÇØ°áÃ¥ ½Ã½ºÅÛ¿¡¼­ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.

1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼­ HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼­ 'System-Tray' ۸¦ Á¦°ÅÇÑ´Ù.
2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Server.exe¸¦ Á¾·áÇÑ´Ù.
4. 'System-Tray' Ű¿¡ Á¤ÀÇµÈ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Server.exe¸¦ Á¦°ÅÇÑ´Ù.

-- ¶Ç´Â --

¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù.
°ü·Ã URL (CVE)
°ü·Ã URL (SecurityFocus)
°ü·Ã URL (ISS)