| Ãë¾àÁ¡ID |
24045 |
| À§Çèµµ |
40 |
| Æ÷Æ® |
666,5401,5402 |
| ÇÁ·ÎÅäÄÝ |
TCP |
| ºÐ·ù |
BackDoor |
| »ó¼¼¼³¸í |
ÇØ´ç ½Ã½ºÅÛ¿¡¼ Back Construction ¹éµµ¾î°¡ ¹ß°ßµÈ´Ù. Back ConstructionÀº 1999³â 6¿ù¿¡ ÀÛ¼ºµÈ °£´ÜÇÑ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ÀÌ´Ù. ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥Àº client.exe(¿¡ÀÌÀüÆ® ÇÁ·Î±×·¥), Server.exe(¼¹ö ÇÁ·Î±×·¥) ÆÄÀÏ·Î ±¸¼ºµÇ¾î ÀÖ´Ù. ÀÌ ÇÁ·Î±×·¥Àº FTP ¼¹ö¸¦ »ç¿ëÇϱâ À§ÇØ 21 TCP Æ÷Æ®¸¦ ¿ÀÇÂ(open)ÇÏ°í ¶ÇÇÑ, ¿ø°ÝÁö °ø°ÝÀÚ°¡ Ŭ¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥À» »ç¿ëÇÒ ¶§, 666, 5401, 5402 TCP Æ÷Æ®¸¦ ¿ÀÇÂ(open)ÇÑ´Ù. ÀÌ·¯ÇÑ Æ÷Æ®µéÀº ÀÓÀÇ·Î º¯°æÀÌ ºÒ°¡´ÉÇÏ´Ù. ¸¸¾à, ÀÌ ¹éµµ¾î ÇÁ·Î±×·¥ÀÌ ½Ã½ºÅÛ¿¡ µ¿ÀÛÇϰí ÀÖ´Ù¸é 'HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Run' À§Ä¡¿¡¼ Cmctl32.exe °ªÀ» °¡Áø "Shell" ۰¡ ¹ß°ßµÈ´Ù.
¿ø°ÝÁö °ø°ÝÀÚµéÀº ÀÌ Back Construction ¹éµµ¾î¸¦ ÀÌ¿ëÇÏ¿© ¿ø°ÝÀ¸·Î ´ë»ó½Ã½ºÅÛ¿¡¼ ´ÙÀ½°ú °°Àº µ¿ÀÛÀ» ¼öÇàÇÒ ¼ö ÀÖ´Ù.
- äÆÃ - victim ½Ã½ºÅÛÀ» ÅëÇØ ÀüÀÚ¿ìÆí ¹ß¼Û - ÆÄÀÏ °ü¸®(¾÷·Îµå, ´Ù¿î·Îµå, µð·ºÅ丮 »ý¼º..) - ij½¬µÈ(cashed) ÆÐ½º¿öµå ȹµæ - ½ÃÀÛ ¸Þ´º Çã¿ë/±ÝÁö - ¾îÇø®ÄÉÀÌ¼Ç º¸±â/Á¾·á
* Ãë¾àÇÑ Ç÷§Æû : Microsoft Windows Any version
* Âü°í »çÀÌÆ®: http://www.dark-e.com/archive/trojans/backc/21/index.shtml http://www.glocksoft.com/trojan_list/Back_Construction.htm http://www.iss.net/security_center/static/3222.php |
| ÇØ°áÃ¥ |
½Ã½ºÅÛ¿¡¼ ¹éµµ¾î¸¦ Á¦°ÅÇØ¾ß ÇÑ´Ù.
1. 'regedit' À̳ª ±âŸ ·¹Áö½ºÆ®¸® ÆíÁý ÇÁ·Î±×·¥À» ÅëÇØ¼ HKEY_USERS\.Default\Software\Microsoft\Windows\CurrentVersion\Run À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼ 'Shell' Ű¿Í HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\General\Settings À§Ä¡ÀÇ ·¹Áö½ºÆ®¸®¿¡¼ 'P23H' ۸¦ Á¦°ÅÇÑ´Ù. 2. ÄÄÇ»Å͸¦ ÀçºÎÆÃÇϰųª Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Cmctl32.exe Á¾·áÇÑ´Ù. 4. À©µµ¿ìÁî ½Ã½ºÅÛ µð·ºÅ丮·ÎºÎÅÍ Æ®·ÎÀÌ ¸ñ¸¶ ÇÁ·Î±×·¥ Cmctl32.exe ÆÄÀÏÀ» Á¦°ÅÇÑ´Ù.
-- ¶Ç´Â --
¹é½Å ÇÁ·Î±×·¥(¾ÈƼ¹ÙÀÌ·¯½º ÇÁ·Î±×·¥)À» ÀÌ¿ëÇÏ¿© Ä¡·áÇØ¾ß ÇÑ´Ù. |
| °ü·Ã URL |
(CVE) |
| °ü·Ã URL |
(SecurityFocus) |
| °ü·Ã URL |
(ISS) |
|