|
ºñÁÖ¾ó C++·Î ÀÛ¼ºµÇ¾úÀ¸¸ç, Worm-W32/Blaster ¿Í °°Àº NT °è¿ÀÇ
DCOM RPC º¸¾ÈÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© °¨¿° ÀüÆĵȴÙ.
±×·¯³ª À©µµ¿ìÁî ¾÷µ¥ÀÌÆ® »çÀÌÆ®¿¡¼ ÇØ´ç OS ¾ð¾îº° DCOM RPC ÆÐÄ¡¸¦
´Ù¿î¹Þ¾Æ ¼³Ä¡ÇÑ ÈÄ¿¡ ÀçºÎÆÃÈÄ Worm-W32/Blaster°¡ Á¸ÀçÇÏ¸é »èÁ¦½Ãµµ¸¦ ÇÑ´Ù.
¿úÀÌ ½ÇÇà µÇ¸é À©µµ¿ì ½Ã½ºÅÛ ÇÏÀ§ winsÆú´õ(c:\winnt\system32\wins)¿¡
dllhost.exe(10,240 byte)¿Í svchost.exe(19,728 byte)¸¦ »ý¼ºÇÑ´Ù.
svchost.exe ÆÄÀÏÀº ½Ã½ºÅÛ Æú´õÀÇ dllcacheÆú´õ(c:\winnt\system32\dllcache)¿¡¼ Á¤»óÆÄÀÏÀÎ tftpd.exeÀ» º¹»çÇÑ ÈÄ À̸§À» º¯°æÇÑ°ÍÀ¸·Î, ½Ã½ºÅÛ Æú´õ(c:\winnt\system32)ÀÇ svchost.exe¿Í ´Ù¸¥ ÆÄÀÏÀÌ´Ù.
¶ÇÇÑ ÀÚ½ÅÀ» ½ÇÇàÇÒ¼ö ÀÖ°Ô ¾Æ·¡ÀÇ ³»¿ëÀÌ ·¹Áö½ºÆ®¸®¿¡ Ãß°¡ µÈ´Ù.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RpcPatch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\RpcTftpd
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RpcPatch
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\RpcTftpd
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcPatch
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\RpcTftpd
±×¸®°í °¨¿° ´ë»ó ½Ã½ºÅÛÀ» ã±â À§ÇØ ICMP ¶Ç´Â, PING ½ÅÈ£¸¦ º¸³»°Ô µÇ¸ç, ÀÌ °úÁ¤¿¡¼ ³×Æ®¿÷ Æ®·¡ÇÈÀÌ Áõ°¡ÇÏ°Ô µÈ´Ù.
ÀÌ¿úÀº µÎ°¡Áö Æ÷Æ®¸¦ ÀÌ¿ëÇÏ¿© ½Ã½ºÅÛ ÀÌ»óÀ» ÀÏÀ¸Å°´Âµ¥, 135¹ø Æ÷Æ®¸¦
ÅëÇؼ´Â DCOM RPC Ãë¾àÁ¡À», ¶ÇÇÑ 80¹ø Æ÷Æ®¸¦ ÅëÇؼ´Â WebDav Ãë¾àÁ¡
(http://www.microsoft.com/korea/technet/security/bulletin/MS03-007.asp)À» ÀÌ¿ëÇÏ¿© IIS 5.0 ½Ã½ºÅÛÀ» °ø°ÝÇÑ´Ù.
¿ú ³»ºÎ¿¡´Â ´ÙÀ½°ú °°Àº ¹®ÀÚ¿ÀÌ Á¸Àç ÇÑ´Ù.
=========== I love my wife & baby :-)~~~ Welcome Chian~~~ Notice: 2004 will remove myself:-)~~ sorry zhongli~~~=========== wins
¶ÇÇÑ 2004³âÀÌ µÇ¾î ½ÇÇà µÇ¸é ÀÚ½ÅÀ» »èÁ¦ÇÏ°Ô µÈ´Ù.
|
|
|