ÀúÀÚ |
msgfix ¿¡ ´ëÇÑ Ä¡·á¹ý. |
Anonymous (0) ºñȸ¿ø
| °Ô½ÃÀÏ: 2005-03-12 12:16|| ¾È³çÇϼ¼¿ä.
Àú´Â win 2000 server¸¦ °³Àοë PC·Î »ç¿ëÇÏ°í ÀÖ´Â »ç¶÷ÀÔ´Ï´Ù.
ÀÌ·¸°Ô »ç¿ëÇÏ°í ÀÖ´Â ÀÌÀ¯´Â asp¸¦ ±â¹ÝÀ¸·Î ÇÏ¿© À¥¸¶½ºÅ͸¦ °øºÎÇÏ°í ÀÖ³¢ ¶§¹®ÀÔ´Ï´Ù.
ÀÌ·¸°Ô Áú¹®À» ¿Ã¸®´Â ÀÌÀ¯´Â ´Ù¸§ÀÌ ¾Æ´Ï¶ó ¾ó¸¶ÀüºÎÅÍ ÄÄÇ»ÅÍ°¡ ´À·ÁÁö±â ½ÃÀÛÇؼ ºÎ·ªºÎ·ª È®ÀÎÀ» Çغôõ´Ï
C:\winnt\system32\¿¡ msgfix.exe, payload.dat µîµîÀÇ ÆÄÀϵéÀÌ µ¹¾Æ´Ù´Ï±â ½ÃÀÚÇß½À´Ï´Ù.
¹ÙÀÌ·¯½º °æ°í°¡ ¶ß´Â´ë·Î Ä¡·á´Â ÇÏ°í ÀÖ½À´Ï´Ù¸¸, ±Ùº»ÀûÀÎ ¿øÀÎÀ» ÇØ°áÇÏÁö ¸øÇÏ´Â °Í °°½À´Ï´Ù.
Á¦°¡ ¾Æ´Â°Ô ¾ø¾î Á¤È®ÇÑ ¼³¸íÀ» µå¸®Áö ¸øÇÔÀ» ¿ë¼ÇØ ÁÖ½Ã°í ºÎµð ÇØ°á¹æ¾ÈÀ» ¾Ë·ÁÁÖ½Ã¸é °¨»çµå¸®°Ú½À´Ï´Ù.
1. O/S : Win 2000 Server (SP4)
2. »ç¿ëÁßÀÎ ¹é½Å ÇÁ·Î±×·¥ : Virobot Expert 4.0 (Á¤Ç°ÀÔ´Ï´Ù. Á¦°¡ °®°í ÀÖ´Â°Ô ÀÌ°Å ¹Û¿¡ ¾ø¾î¼ ´Ù¸¥ ½¦¾î¹öÀüÀÇ ¹é½ÅÀº »ç¿ëÇϱⰡ Á» ±×·¸´õ¶ó±¸¿ä)
3. Áõ»óµé
(1) Root µð·ºÅ丮³ª System32¿¡ ¾Æ·¡¿Í °°Àº ÆÄÀϵéÀÌ »ý¼ºµË´Ï´Ù.
skssve.exe, msgfix.exe, payload.dat µîµî
(2) ·¹Áö½ºÆ®¸®¿¡ Run, RunOnce µî¿¡ À§ÀÇ ÆÄÀϵéÀ» ½ÇÇàÇϵµ·Ï ³ª¿É´Ï´Ù.
-------------------------
ÀÌ°ÍÀÌ ¸¸¾à ¹éµµ¾î¶ó¸é ¾î¶»°Ô ¸·À»¼ö ÀÖ³ª¿ä? ¾î¶»°Ô Ä¡·áÇÒ ¼ö ÀÖ´Â °ÍÀϱî¿ä?
ÀÌ·±°É ¿¹¹æÇϱâ À§Çؼ´Â ¾î¶»°Ô ÇÏ´Â °ÍÀÌ °¡Àå ÁÁÀ»±î¿ä?
|
|
Anonymous (0) ºñȸ¿ø
| °Ô½ÃÀÏ: 2005-03-12 13:19|| ÀÏ´Ü Áú¹®Çϱâ Àü¿¡ Áú¹®½Ã À¯ÀÇ »çÇ×À» Àаí Áú¹®ÇϽñ⠹ٶø´Ï´Ù. ¾Æ¿ï·¯ °Ô½ÃÆÇÀ» °Ë»öÇغ¸¸é ¾Ë ¼ö ÀÖÁö¸¸ ´Ô°ú ºñ½ÁÇÑ Áú¹®À» ¿Ã¸®´Â »ç¶÷µéÀÌ ²Ï µË´Ï´Ù. ¾Æ¿ï·¯ ±×·± °Ô½Ã¹° ¸¶³ª HijackLog¸¦ ¿äûÇÏ´Â ±Ûµµ ÇÔ²² º¼ ¼ö ÀÖÀ» °Ì´Ï´Ù.
´Ôó·³ ¹éµµ¾î³ª ¾Ç¼º ½ºÅ©¸³Æ®°¡ ¼³Ä¡µÈ °æ¿ì ¹Ýµå½Ã ÇÊ¿äÇÑ ÃÖ¼Ò Á¤º¸°¡ HiJack LogÀÔ´Ï´Ù. Hijack Log¸¦ ÀÛ¼ºÇÒ ÁÙ ¸ð¸£´Ù´Â ±Ûµµ ¿Ã¶ó¿Í ÀÛ¼ºÇÏ´Â ¹æ¹ý±îÁö ÀÌ¹Ì ÆÁÀ¸·Î ¿Ã·ÁµÐ »óÅÂÀÔ´Ï´Ù.
µû¶ó¼ Áú¹®Çϱâ Àü¿¡ ¸ÕÀú °Ë»öÀ» Çغ¸½Ã°í, ÇÊ¿äÇÑ Á¤º¸¸¦ Á¦°øÇØ¾ß ´äº¯ÀÌ °¡´ÉÇÕ´Ï´Ù.
ÀÏ´Ü ´ÔÀÇ HijackLog°¡ ¾ø±â¶§¹®¿¡ ¸ðµç ½ÇÇàÅ°¸¦ ¹é¾÷ÇÏ°í, »èÁ¦ÇÏ´Â °ÍÀ¸·Î ÁøÇàÇÏ°Ú½À´Ï´Ù. ÀÌ ¹æ¹ýÀ¸·Î Á¤»óÀûÀ¸·Î »èÁ¦µÈ´Ù¸é ½ÇÇà Å°¸¦ º¹±¸ÇÏ°í, msgfix.exe¿¡ °ü·ÃµÈ ½ÇÇàÅ°(Configuration Loader)¸¸ »èÁ¦ÇϸéµË´Ï´Ù.
1. ½Ã½ºÅÛÀ» Á¾·áÇÏ°í F8¸¦ ´·¯ OS ¸Þ´º È£Ãâ
2. ¾ÈÀü ¸ðµå(¸í·É ÇÁ·ÒÇÁÆ® »ç¿ë)·Î ·Î±×ÀÎ
3. ¸í·ÉÇà¿¡¼ ´ÙÀ½ ¸í·É ½ÇÇà
dir /s C:\msgfix.exe
4. ¹ß°ßµÈ ¸ðµç msgfix.exe »èÁ¦
5. ¸í·ÉÇà¿¡¼ ´ÙÀ½ ¸í·É ½ÇÇà
dir /s C:\skssve.exe
6. ¹ß°ßµÈ ¸ðµç skssve.exe »èÁ¦
7. ±×¿Ü dir ¸í·ÉÀ¸·Î msgfix.exe °ü·Ã ÆÄÀÏÀ» ã¾Æ¼ »èÁ¦
8. ¸í·ÉÇà¿¡¼ ´ÙÀ½ ¸í·É ½ÇÇà
reg save HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run LRun.hiv
reg save HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce LRunOnce.hiv
reg save HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx LRunOnceEx.hiv
reg save HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices LRunServices.hiv
reg save HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce LRunServicesOnce.hiv
reg save HKCU\Software\Microsoft\Windows\CurrentVersion\Run CRun.hiv
reg save HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce CRunOnce.hiv
reg save HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx CRunOnceEx.hiv
reg save HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices CRunServices.hiv
reg save HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce CRunServicesOnce.hiv
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnceEx
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices
reg delete HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServicesOnce
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\RunServices
reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
°ªÀ» »èÁ¦ÇÏÁö ¾Ê°í Å°¸¦ »èÁ¦ÇÑ ÀÌÀ¯´Â ´ÔÀÇ Hijack Log°¡ ¾ø±â¶§¹®ÀÔ´Ï´Ù.
P.S. 1. ÆÁÀ» ÁøÇàÇϱâÀü¿¡ HiJack Log¸¦ ¸ÕÀú ÀÛ¼ºÇÑ ÈÄ HiJack ·Î±×¸¦ Á¦ ¸ÞÀÏ·Î º¸³»Áֱ⠹ٶø´Ï´Ù.
P.S. 2. msgfix.exe¿Í skssve.exe°¡ ¹ß°ßµÈ Æú´õ¸¦ ¾Ë·ÁÁֱ⠹ٶø´Ï´Ù. |
Anonymous (0) ºñȸ¿ø
| °Ô½ÃÀÏ: 2005-03-15 11:08|| payload.dat ´Â agobotÀ̳ª sdbot °ú °°Àº bot·ùÀÇ backdoor¿¡ °¨¿°µÇ¾úÀ»¶§ »ý¼ºµÇ´Â trojanÀÇ »çº»ÀÔ´Ï´Ù.
¹éµµ¾î°¡ ÀÌ¹Ì µé¾î¿Í¼ µ¹¾Æ´Ù´Ï±â ½ÃÀÛÇß´Ù¸é ±¸¼®¿¡ ¼û¾îÀÖ´Â °ÍµéÀÌ ¸»¾¸ ÇϽŰŠ¿Ü¿¡µµ ´õ ÀÖÀ» È®·üÀÌ ³ô½À´Ï´Ù.
Á¦ÀÏ ¸ÕÀú
1. º¸¾È ÆÐÄ¡°¡ Àß µÇ¾ú´ÂÁö È®ÀÎÇϽðí
2. °ü¸®ÀÚ °èÁ¤¿¡ º»ÀÎÀÌ ±â¾ï ÇÒ ¼ö ÀÖ´Â ¾î·Á¿î ¾ÏÈ£¸¦ °É¾îÁÝ´Ï´Ù.
3. ÀÎÅÍ³Ý ÀÓ½ÃÆÄÀÏ, %TEMP%Æú´õ µî¿¡ ³²¾ÆÀÖ´Â ºÒÇÊ¿äÇÑ ÆÄÀϵéÀ» ¸ðµÎ Á¦°ÅÇÏ°í
4. ¹é½ÅÀ» ÀÌ¿ëÇÏ¿© Çϵåµð½ºÅ© Àüü ÆÄÀÏÀ» °Ë»çÇϼ¼¿ä.
Âü°í·Î bot·ù¿¡ ´ëÇÑ Áø´ÜÀ²Àº ¿Ü»ê¹é½ÅÀÌ ³ôÀº Æí ÀÔ´Ï´Ù.
¹ÙÀ̷κ¿µµ À̹ø´ÞºÎÅÍ ºñÆ®µðÆæ´õ ¿£ÁøÀ» Àû¿ëÇؼ »ó´çÇÑ ¼º´É Çâ»óÀÌ ÀÖ´Ù°í Çϳ׿ä. ÃֽŠ¹öÁ¯À¸·Î ¾÷µ¥ÀÌÆ® Çؼ »ç¿ëÇØ º¸½Ã±â ¹Ù¶ø´Ï´Ù. |
|
| |