*°¨¿° °æ·Î
À©µµ¿ì º¸¾È Ãë¾àÁ¡À» ÅëÇØ °¨¿° , À©µµ¿ì NT°è¿(À©µµ¿ì NT,2000,XP)ÀÇ °ü¸® ¸ñÀû °øÀ¯ Æú´õ¿¡ ´ëÇÑ »ç¿ëÀÚ ·Î±×ÀÎ °èÁ¤ÀÇ ¾ÏÈ£°¡ Ãë¾àÇÑ °æ¿ì ½Ã½ºÅÛ¿¡ Á¢¼ÓÇØ Backdoor
¸¦ ½ÇÇàÇÑ´Ù.
Ex) 00000, GEUST, PASSWORD, admin, admins,
adminstrator µîµî..
*Áõ»ó À©µµ¿ì ½Ã½ºÅÛ Æú´õ¿¡ winded.exe ¶ó´Â ÆÄÀÏÀ» »ý¼ºÇÑ´Ù.
À©µµ¿ì ½Ã½ºÅÛ Æú´õ |
95/98/ME |
C:\Windows\System |
NT/2000 |
C\WinNT\System32 |
XP |
Windows\System32 |
.
±×¸®°í ·¹Áö½ºÆ®¸®¿¡ ´ÙÀ½ value¸¦ µî·ÏÇØ À©µµ¿ì ±¸µ¿½Ã ÀÚµ¿ ½ÇÇàµÇµµ·Ï ¸¸µç´Ù.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\OLE ¡°Microsoft System Debug¡± = winded.exe HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
¡°Microsoft System Debug¡± = winded.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices ¡°Microsoft System Debug¡± = winded.exe
°¨¿°µÈ ½Ã½ºÅÛÀº TCP ÀÓÀÇÀÇ Æ÷Æ®¸¦ LISTENING »óÅ·Π¿¾îµÐ´Ù. (»ó´ë·ÎºÎÅÍ Á¢¼ÓÀ» ±â´Ù¸®´Â »óÅÂ)
±× ÈÄ »ç¿ëÀÚ ¸ô·¡ Á¢¼Ó ÇØ ½ºÆÔ ¸ÞÀÏ ¹ß¼Û, ¾Öµå¿þ¾î ¼³Ä¡, µ¥ÀÌÅÍ »èÁ¦, ±×¸®°í °³ÀÎÀÇ ÄÄÇ»ÅÍ »ç¿ë ³»¿ªÀ» ÈÉÃĺ¸°Å³ª °¢Á¾ ÆÄÀÏ(°³ÀÎ ¹®¼, ±â¹Ð ¹®¼ µî)À» ¿ÜºÎ·Î »©°¡´Â º¸¾È»ó ¹®Á¦µµ ¹ß»ýÇÒ ¼ö ÀÖÀ½
±×¸®°í ½Ã½ºÅÛ¿¡ ½ÇÇàÁßÀÎ ÇÁ·Î¼¼½ºµéÀ» °Á¦ Á¾·á ½ÃŲ´Ù
-¹ÂÅؽº »ý¼º
´ÙÀ½ ¹ÂÅؽº(Mutex)¸¦ »ý¼ºÇØ Áߺ¹ ½ÇÇàÀ» ¹æÁöÇÑ´Ù.
-
.:H:. |