¿¡ºê¸®Á¸¼Ò°³ | Á¦Ç°¼Ò°³ | °í°´¼¾ÅÍ | »çÀÌÆ®¸Ê | Home
°³ÀÎ°í°´ ¿©¼º°í°´ eº¸¾È¸¶ÄÏ À̺¥Æ®
°³ÀÎ°í°´±â¾÷°í°´
º¸¾ÈÁ¢¼Ó IDÀúÀå
AD ¹«·á·Î Ã¥¹Þ¾Æ°¡¼¼¿ä!


 ¸ñ·Ï |  À­±Û |  ¾Æ·§±Û  
Backdoor-W32/RBot.71148
 ¹ÙÀÌ·¯½º Á¾·ù
Backdoor
 ½ÇÇàȯ°æ
Windows
 ¹ß°ßÀÏ
2005³â10¿ù02ÀÏ
 Á¦ÀÛÁö
ºÒºÐ¸í
 À§Çèµî±Þ
º¸Åë
 È®»ê¹æ¹ý
³×Æ®¿öÅ©, º¸¾ÈÃë¾à¼º
 ¹ÙÀÌ·¯½º Å©±â
71,148 Byte
 Ã·ºÎÆÄÀÏ
 ¸ÞÀÏÁ¦¸ñ
  
 Áõ»ó¿ä¾à
  ·¹Áö½ºÆ®¸® º¯°æ, ÆÄÀÏ »ý¼º
 Ä¡·á¹æ¹ý

Åͺ¸¹é½Å Á¦Ç°±ºÀ¸·Î Áø´Ü/Ä¡·á °¡´ÉÇÕ´Ï´Ù.



  
 
»ó¼¼¼³¸í
ÀÌ ¿úÀº À©µµ¿ì º¸¾ÈÇêÁ¡°ú ³×Æ®¿÷ °øÀ¯ Æú´õ¸¦ ÅëÇÏ¿© ÀüÆĵǸç,

°¨¿°µÈ ¸ÞÀÏÀ̳ª ÆÄÀÏÀ» ƯÁ¤ ¼­¹ö·ÎºÎÅÍ ¹ÞÀ»¼ö ÀÖ´Ù.


[Ư¡]

¹éµµ¾î°¡ ½ÇÇàµÇ¸é ´ÙÀ½°ú °°ÀÌ À©µµ¿ì ½Ã½ºÅÛ Æú´õ(win 2000, NT : c:\Wint\system32, win XP : c:\windows\system32)
¿¡ svchoes.exe(71,148 Byte) ÆÄÀÏÀ» »ý¼ºÇÑ´Ù.

¶ÇÇÑ, ´ÙÀ½Ã³·³ ·¹Áö½ºÆ®¸¦ ¼öÁ¤ÇÏ¿© ´ÙÀ½ ºÎÆýà ½ÇÇàµÇµµ·Ï Á¶ÀÛÇÑ´Ù.

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run
Ç׸ñ¿¡

System Updated = "svchoes.exe"

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices
Ç׸ñ¿¡

System Updated = "svchoes.exe"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Ç׸ñ¿¡

System Updated = "svchoes.exe"

HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunServices
Ç׸ñ¿¡

System Updated = "svchoes.exe"

HKEY_LOCAL_MACHINE\System\CurrentControlSet\Control\Lsa
Ç׸ñ¿¡

System Updated = "svchoes.exe"

HKEY_CURRENT_USER\Software\Microsoft\OLE
Ç׸ñ¿¡

System Updated = "svchoes.exe"

HKEY_CURRENT_USER\System\CurrentControlSet\Control\Lsa
Ç׸ñ¿¡

System Updated = "svchoes.exe"

À» »ý¼ºÇÑ´Ù.

±×¸®°í ´ÙÀ½°ú °°Àº Á¤º¸¸¦ ÀÌ¿ëÇÏ¿© ½Ã½ºÅÛ ±ÇÇÑ ¾ò±â¸¦ ½Ãµµ ÇÑ´Ù.

12345
123456
1234567
12345678
123456789
1234567890
access
accounting
accounts
admin
administrador
administrat
administrateur
administrator
admins
backup
bitch
blank
brian
changeme
chris
cisco
compaq
computer
control
database
databasepass
databasepassword
db1234
dbpass
dbpassword
default
domain
domainpass
domainpassword
exchange
george
guest
hello
homeuser
internet
intranet
katie
linux
login
loginpass
nokia
oeminstall
oemuser
office
oracle
orainstall
outlook
owner
pass1234
passwd
password
password1
peter
qwerty
server
siemens
sqlpassoainstall
staff
student
susan
system
teacher
technical
win2000
win2k
win98
windows
winnt
winpass
winxp
wwwadmin

¹éµµ¾î·Î¼­ µ¿ÀÛ ÇϰԵǸé, ´ÙÀ½°ú °°Àº ½Ã½ºÅÛ ¿Àµ¿ÀÛÀÌ ÀϾ ¼ö ÀÖ´Ù.

1. ÆÄÀÏ ½ÇÇà¹× »èÁ¦
2. Æ÷Æ®°¨½Ã
3. Å°º¸µå ŸÀÌÇÎ ³»¿ë ÀúÀå
4. ÆÄÀÏ ´Ù¿î·Îµå
5. ftp¹× IRC ¼­¹ö·Î µ¿ÀÛ°¡´É
6. ½Ã½ºÅÛ Çϵå¿þ¾î Á¤º¸ ¼öÁý
7. ¿ø°ÝÁ¢¼Ó¹× ·Î±× ¿ÀÇÁ ±â´É


±×¸®°í ÀÌ ¹éµµ¾î´Â RPCSS ¿ø°ÝÄÚµå ½ÇÇà À§Çè, ASN .1ÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ÄÚµå ½ÇÇà ¹®Á¦ µîÀ»

ÀÌ¿ëÇϹǷÎ, ´ÙÀ½ º¸¾ÈÆÐÄ¡¸¦ ±Ç°íÇÑ´Ù.

*MS03-039 RPCSS ¼­ºñ½ºÀÇ ¹öÆÛ ¿À¹ö·±
http://www.microsoft.com/korea/technet/security/bulletin/MS03-039.asp

*MS04-007 ASN .1ÀÇ Ãë¾àÁ¡À¸·Î ÀÎÇÑ ÄÚµå ½ÇÇà ¹®Á¦
http://www.microsoft.com/korea/technet/security/bulletin/MS04-007.asp
 
¿¹¹æ ¹× ¼öµ¿Á¶Ä¡¹æ¹ý
¹«´ÜÀüÀç¤ý¹èÆ÷±ÝÁö
¿¡ºê¸®Á¸¿¡¼­ Á¦°øÇÏ´Â ¸ðµç ÄÁÅÙÃ÷ Á¤º¸¿¡ ´ëÇÑ ÀúÀÛ±ÇÀº ¿¡ºê¸®Á¸ÀÇ ¼ÒÀ¯ÀÌ¸ç °ü·Ã¹ýÀÇ º¸È£¸¦ ¹Þ½À´Ï´Ù.
¿¡ºê¸®Á¸ÀÇ »çÀü Çã°¡ ¾øÀÌ ¿¡ºê¸®Á¸ ÄÁÅÙÃ÷¸¦ ¹«´ÜÀ¸·Î ÀüÀç, ¹èÆ÷¸¦ ±ÝÁöµÇ¾î ÀÖ½À´Ï´Ù.
À̸¦ À§¹ÝÇÏ´Â °æ¿ì ¼ÕÇعè»óÀÇ ´ë»ó ¶Ç´Â ¹Î.Çü»ç»óÀÇ ¹ýÀû ¼Ò¼Û ´ë»óÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
                                                                 * ¿¡ºê¸®Á¸ Á¤º¸ ÀÌ¿ë ¹®ÀÇ : greenking@everyzone.com
 ¸ñ·Ï