Remote Procedure CallÀ» »ç¿ëÇϽÃÁö ¾ÊÀº °æ¿ì¿¡ ÀϾ½Å°ÅÁö¿ä?
//www.microsoft.com/korea/technet/security/bulletin/MS03-026.asp
¿¡ °¡¼Å¼ º¸¾ÈÆÐÄ¡¸¦ ¹Þ¾ÆÁֽñ⠹ٶø´Ï´Ù.
*º¸¾ÈÆÐÄ¡¸¦ ±òÀ¸½ÅÈÄ¿¡ ¹®Á¦°¡ ÇØ°áµÇ¼Ì´Ù¸é ´Ù¸¥ ¼³Á¤À» °Çµå½Ç Çʿ䰡 ¾ø½À´Ï´Ù.
º¸¾ÈÆÐÄ¡ ¼³Ä¡¿¡ ¾î·Á¿òÀÌ ÀÖÀ¸½Ã°Å³ª ÇØ°áÀÌ ¾ÈµÇ¼ÌÀ»¶§ ´Ù¸¥ ¼³Á¤À» ¹Ù²Ù¾î ÁÖ¼¼¿ä.*
»ó´çÈ÷ ¸¹Àº ºÐµéÀÌ ÇÇÇØ¸¦ ÀÔÀ¸½Å °Í °°³×¿ä.^^;
½ÇÇà¿¡¼ shutdown -a À» ÀÔ·ÂÇÏ½Ã¸é °Á¦Á¾·á´Â ÀÏ´Ü ¸·½À´Ï´Ù.
(shutdown ±â´ÉÀº ÄÄÇ»ÅÍÀÇ ±â´É¼Õ»óÀ» ÃÊ·¡ÇÒ ¼ö ÀÖ½À´Ï´Ù. ±×·¯¹Ç·Î ¾ÈÀü¸ðµå·Î ºÎÆÃÇÏ´Â °ÍÀÌ
´õ ¹Ù¶÷Á÷ÇÕ´Ï´Ù. ¾Æ´Ï½Ã¸é ÀÛ¾÷Ç¥½ÃÁÙ ¿ìÃøÇÏ´Ü¿¡ ÀÖ´Â ½Ã°£À» 1³âÀüÀ¸·Î µÇµ¹¸®½Ã¸é
°Á¦Á¾·á¸¦ ¸·À¸½Ç¼ö ÀÖ½À´Ï´Ù.)
À̹ø ¿úÀÇ Á÷Á¢ÀûÀ¸·Î °ü¿©ÇÏ´Â ÆÄÀÏÀÎ
windowÆú´õ - system32 - msblast.exe »èÁ¦ÇØ Áֽñâ¹Ù¶ø´Ï´Ù.(´Ù¸¥ ¿î¿µÃ¼Á¦¿¡µµ ÇØ´ç)
-º¸¾ÈÆÐÄ¡¸¦ ¼³Ä¡ÇϼÌÀ¸¸é ²À Áö¿ìÁö ¾ÊÀ¸¼Åµµ µË´Ï´Ù. & º¸¾ÈÆÐÄ¡¸¸ ¼³Ä¡ÇÏ½Ã¸é ´Ù¸¥ °ÍÀº ÇÏÁö
¾Ê¾Æµµ µË´Ï´Ù.-
msblastÆÄÀÏ Áö¿ì´Â¹ý
¿ì¼± ctrl+alt+del Ű ´©¸£½Ã°í ÅÇÁß¿¡¼ ÇÁ·Î¼¼¼¸¦
¼±ÅÃÇÕ´Ï´Ù.
±×°÷ ÇÁ·Î¼¼¼¿¡¼ msblast¸¦ Á¾·á½Ãŵ´Ï´Ù.
±×´ÙÀ½ ÆÄÀÏã±â¿¡¼ msblast¸¦ °Ë»öÈÄ¿¡
³ª¿À´Â µÎ°³ÀÇ ÆÄÀÏÀ» »èÁ¦ÇÕ´Ï´Ù.^^
¾Æ! ±×¸®°í ÆÐÄ¡¸¦ ±òÀ¸½Ç¶§
update.inf ÆÄÀÏÀÇ ¹«°á¼ºÀ» È®ÀÎÇÏÁö ¸øÇß´Ù´Â ¸Þ½ÃÁöÇϰí cryptographic¼ºñ½º»ç ÄÄÇ»ÅÍ¿¡¼ ½ÇÇàÁßÀÎ
Áö È®ÀÎÇ϶ó°í ÇÕ´Ï´Ù. ÀÎÅͳݼ±À» »ÌÀº ÈÄ ºÎÆÃ -> ÆÐÄ¡ ¼³Ä¡ÆÄÀÏ ½ÇÇàÇØ¼
µ¿ÀÇÇÏ°í ¼³Ä¡ -> ¸¶Ä§ -> ÀçºÎÆÃ -> ÀçºÎÆÃÈÄ ´Ù½Ã Á¾·á -> ÀÎÅÍ³Ý ¿¬°á -> À©µµ¿ì ºÎÆÃ
ÀÌ·¸°Ô ÇϽñ¸¿ä.
v3ÃֽůÇÀ» ´Ù¿î¹ÞÀ¸½ÅÈÄ¿¡ Ä¡·á¸¦ ÇØµµ Ä¡·á°¡ µÉ °ÍÀ¸·Î ÃßÃøµË´Ï´Ù.
xp¿ë º¸¾ÈÆÐÄ¡ ÁÖ¼Òµµ ¾Ë·Áµå¸®°Ú½À´Ï´Ù.
//download.microsoft.com/download/e/3/1/e31b9d29-f650-4078-8a76-3e81eb4554f6/WindowsXP-KB823980-x86-KOR.exe
¾Æ·¡ÀÇ ÁÖ¼Ò´Â 2000¿ë º¸¾ÈÆÐÄ¡ ÁÖ¼ÒÀÔ´Ï´Ù.
//download.microsoft.com/download/6/9/5/6957d785-fb7a-4ac9-b1e6-cb99b62f9f2a/Windows2000-KB823980-x86-KOR.exe
¶ÇÇÑ msblast.exe°¡ µÎ°³À̽ŠºÐµéÁß¿¡ Çϳª°¡ ¿¢¼¼½º°¡ ¾ÈµÇ½Å´Ù´Â ºÐµéÀÌ °è½Åµ¥¿ä
ÇÁ·Î¼¼¼¿¡¼ µÎ°³ÀÎÁö È®ÀÎÇØº¸½Ã°í µÎ°³¸¦ ´Ù Á¾·áÇÕ´Ï´Ù.
±×´ÙÀ½ ½ÉÆÄÀÏ¿¡¼ ad-ware¸¦ °Ë»öÈÄ ´Ù¿î¹ÞÀ¸¼Å¼ ºÒ·®¼½Å͸¦ Àâ¾Æ³»½Ã¸é
msblast.exeÆÄÀÏÀÌ °É·Á ÀâÈù´Ù°í ÇÕ´Ï´Ù.
¾Æ¹«Æ° ºÒöÁÖ¾ß ³ë·ÂÇϰí ÀÖÀ¸´Ï ÇØ°áÇÏ½Ã±æ ¹Ù¶ó°Ú½À´Ï´Ù..¤Ð_¤Ð
¾Æ ±×¸®°í ¹«°á¼º ¹®Á¦ÀÇ ´Ù¸¥ ¹æ¹ýÀÔ´Ï´Ù.
¼³Á¤->Á¦¾îÆÇ->°ü¸®µµ±¸->¼ºñ½º->cryptographic service ¸¦ Ŭ¸¯ÇÑ´ã¿¡ ¼Ó¼º¿¡¼ ÀÚµ¿¼±Åà ÇϽÅÈÄ
ÀçºÎÆÃ ÇØÁֽñæ¹Ù¶ø´Ï´Ù.
-------ÇÊ¿äÇÑ ±â´É ¼öÁØ¿¡ µû¶ó »ç¿ë ÇÒ ¼ö ÀÖ´Â ÇØ°á¹æ¹ý°ú ¿¹¹æ¹ý-------
¹æÈº®¿¡¼ RPC ÀÎÅÍÆäÀ̽º Æ÷Æ®¸¦ Â÷´ÜÇÕ´Ï´Ù.
135¹ø Æ÷Æ®´Â ¿ø°Ý ÄÄÇ»ÅÍ¿¡ RPC¸¦ ¿¬°áÇÏ´Â µ¥ »ç¿ëµË´Ï´Ù. ±×¸®°í ÀÌ Ãë¾àÁ¡À» ¿ø°ÝÀ¸·Î °ø°ÝÇϱâ À§
ÇØ °ø°ÝÀÚ°¡ »ç¿ëÇÒ ¼ö ÀÖ´Â Ãß°¡ÀûÀÎ RPC ÀÎÅÍÆäÀ̽º Æ÷Æ®µéÀÌ ÀÖ½À´Ï´Ù. ¹æÈº®¿¡¼ ´ÙÀ½ Æ÷Æ®¸¦ Â÷´Ü
Çϸé ÀÌ Ãë¾àÁ¡À» ¾Ç¿ëÇÏ¿© ¹æÈº® µÚÀÇ ½Ã½ºÅÛÀÌ °ø°Ý ¹Þ´Â °ÍÀ» ¿¹¹æÇÒ ¼ö ÀÖ½À´Ï´Ù.
TCP/UDP Æ÷Æ® 135
TCP/UDP Æ÷Æ® 139
TCP/UDP Æ÷Æ® 445
Ãß°¡·Î, RPC¸¦ »ç¿ëÇÏ´Â ¼ºñ½º³ª ÇÁ·ÎÅäÄÝÀÌ ÀÎÅͳݿ¡¼ ¾×¼¼½ºµÉ ¼ö ÀÖµµ·Ï »ç¿ëÀÚ°¡ ¼³Á¤ÇßÀ» ¼öµµ ÀÖ
½À´Ï´Ù. ½Ã½ºÅÛ °ü¸®ÀÚ´Â ¹Ýµå½Ã ÀÎÅͳݿ¡ ³ëÃâµÈ RPC Æ÷Æ®°¡ ÀÖ´ÂÁö Á¡°ËÇÏ¿© ¹æÈº®¿¡¼ ÀÌ Æ÷Æ®µéÀ»
Â÷´ÜÇϵçÁö Áï½Ã ÆÐÄ¡¸¦ ¼³Ä¡ÇϵçÁö ÇØ¾ßÇÕ´Ï´Ù.
ÀÎÅÍ³Ý ¿¬°á ¹æÈº®
ÀÎÅÍ³Ý ¿¬°áÀ» º¸È£Çϱâ À§ÇØ Windows XP ¶Ç´Â Windows Server 2003¿¡¼ ÀÎÅÍ³Ý ¿¬°á ¹æÈº®À» »ç¿ëÇÏ´Â
°æ¿ì ÀÎÅͳÝÀÇ Àιٿîµå RPC Æ®·¡ÇÈÀÌ ±âº»ÀûÀ¸·Î Â÷´ÜµË´Ï´Ù.
¿µÇâ ¹Þ´Â ¸ðµç ½Ã½ºÅÛ¿¡¼ DCOM ±â´É ÇØÁ¦
ÄÄÇ»ÅͰ¡ ³×Æ®¿öÅ©ÀÇ ÀϺÎÀÏ °æ¿ì ÇØ´ç ÄÄÇ»ÅÍÀÇ COM °³Ã¼°¡ DCOM Wire ProtocolÀ» »ç¿ëÇÏ¿© ´Ù¸¥ ÄÄÇ»ÅÍ
ÀÇ COM °³Ã¼¿Í Åë½ÅÇÒ ¼ö ÀÖ½À´Ï´Ù. ÀÌ Ãë¾àÁ¡À¸·ÎºÎÅÍ º¸È£Çϱâ À§ÇØ Æ¯Á¤ ÄÄÇ»ÅÍÀÇ DCOM ±â´ÉÀ» ÇØÁ¦
ÇÒ ¼ö ÀÖÁö¸¸ ÀÌ·¸°Ô Çϸé ÇØ´ç ÄÄÇ»ÅÍÀÇ °³Ã¼¿Í ´Ù¸¥ ÄÄÇ»ÅÍÀÇ °³Ã¼ °£ÀÇ ¸ðµç Åë½ÅÀÌ ÇØÁ¦µË´Ï´Ù.
¿ø°Ý ÄÄÇ»ÅÍ¿¡¼ DCOM ±â´ÉÀ» ÇØÁ¦Çϸé DCOMÀ» ´Ù½Ã ¼³Á¤ÇÑ ÈÄ¿¡ ÇØ´ç ÄÄÇ»ÅÍ¿¡ ¿ø°ÝÀ¸·Î ¾×¼¼½ºÇÏÁö ¸ø
ÇÒ ¼ö ÀÖ½À´Ï´Ù. DCOMÀ» ´Ù½Ã ¼³Á¤ÇÏ·Á¸é ÇØ´ç ÄÄÇ»ÅÍ¿¡ ½ÇÁ¦·Î ¾×¼¼½ºÇØ¾ß ÇÕ´Ï´Ù.
ÄÄÇ»ÅÍ¿¡¼ DCOMÀ» ¼öµ¿À¸·Î ¼³Á¤Çϰųª ÇØÁ¦ÇÏ·Á¸é
1. Dcomcnfg.exe¸¦ ½ÇÇàÇÕ´Ï´Ù.
Windows XP ¶Ç´Â Windows Server 2003À» ½ÇÇàÇÏ´Â °æ¿ì ´ÙÀ½°ú °°Àº Ãß°¡ ´Ü°è¸¦ ¼öÇàÇÕ´Ï´Ù.
ÄÜ¼Ö ·çÆ®¿¡¼ ±¸¼º ¿ä¼Ò ¼ºñ½º ³ëµå¸¦ Ŭ¸¯ÇÕ´Ï´Ù.
ÄÄÇ»ÅÍ ÇÏÀ§ Æú´õ¸¦ ¿±´Ï´Ù.
·ÎÄà ÄÄÇ»ÅÍÀÎ °æ¿ì ³» ÄÄÇ»Å͸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÏ°í ¼Ó¼ºÀ» ¼±ÅÃÇÕ´Ï´Ù.
¿ø°Ý ÄÄÇ»ÅÍÀÎ °æ¿ì ÄÄÇ»ÅÍ Æú´õ¸¦ ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÏ°í »õ·Î ¸¸µé±â¸¦ Ŭ¸¯ÇÑ ´ÙÀ½ ÄÄÇ»Å͸¦
Ŭ¸¯ÇÕ´Ï´Ù. ÄÄÇ»ÅÍ À̸§À» ÀÔ·ÂÇÕ´Ï´Ù. ÇØ´ç ÄÄÇ»ÅÍ À̸§À» ¸¶¿ì½º ¿À¸¥ÂÊ ´ÜÃ߷ΠŬ¸¯ÇÏ°í ¼Ó¼ºÀ» ¼±ÅÃ
ÇÕ´Ï´Ù.
2. ±âº» ¼Ó¼º ÅÇÀ» ¼±ÅÃÇÕ´Ï´Ù.
3. ÀÌ ÄÄÇ»ÅÍ¿¡¼ DCOM »ç¿ë È®ÀζõÀ» ¼±ÅÃÇϰųª ¼±ÅÃÀ» Ãë¼ÒÇÕ´Ï´Ù.
4. ½Ã½ºÅÛ¿¡ ´ëÇÑ ¼Ó¼ºÀ» Ãß°¡·Î ¼³Á¤ÇÏ·Á¸é Àû¿ë ´ÜÃ߸¦ Ŭ¸¯ÇÏ¿© DCOMÀ» ¼³Á¤Çϰųª ÇØÁ¦ÇÕ´Ï´Ù. ±×·¸
Áö ¾ÊÀ¸¸é È®ÀÎÀ» Ŭ¸¯ÇÏ¿© º¯°æ »çÇ×À» Àû¿ëÇϰí Dcomcnfg.exe¸¦ ³¡³À´Ï´Ù.
---------8¿ù 14ÀÏ am 2:10ÇöÀç----------
ÇöÀç ¼Ó¼ºÀ» ¹Ù²Ù½Å ºÐµéÁß¿¡ ¿¡·¯°¡ ³ª´Â ºÐµéÀÌ ¸¹À¸¼Å¼ ¼Ó¼ººÎºÐ ³»¿ëÀ» »èÁ¦ÇÏ¿´½À´Ï´Ù.
ÀÛ¾÷Ç¥½ÃÁÙÀÌ »ç¶óÁö°Å³ª ÀÎÅͳÝÀÌ Á¦´ë·Î ¾ÈµÇ´Â ºÐµîµî ¿©·¯ ¹®Á¦´Â
¼ºñ½ºÁß´ÜÀ¸·Î ÀÎÇÑ ´Ù¸¥ ¼ºñ½º¿ÍÀÇ Á¾¼ÓÁß´ÜÀ̶ó°í ¿©°ÜÁý´Ï´Ù.
¿î¿µÃ¼Á¦¿¡ ¸Â´Â º¸¾ÈÆÐÄ¡¸¦ Á¤È®È÷ ¼³Ä¡ÇØÁֽñ⠹ٶø´Ï´Ù.
¸¹Àº ºÐµéÀÌ ÂÊÁö¸¦ º¸³»Á̴ּµ¥ ¸ðµç ¿À·ù¿¡ ´ëÇÑ ´äº¯À» Á¤È®È÷ ÇØµå¸®Áö ¸øÇؼ Á˼ÛÇϱ¸¿ä.
Á¶±Ý ´Ê´õ¶óµµ ´äÂÊÀº ²À º¸³»µå¸®°Ú½À´Ï´Ù..
--------8¿ù 14ÀÏ am 2:30ÇöÀç-----------
RPC¼Ó¼ºÀ» ¹Ù²Ù½Å ºÐµéÁß¿¡ ÄÄÇ»ÅÍ ºÎÆÃ½Ã°£ÀÌ ´Ã¾î³ª°í ÀÎÅͳÝÀÌ À߾ȵǸç
ÀÛ¾÷Ç¥½ÃÁÙÀÌ »ç¶óÁö°Å³ª »õâÀÌ ³»·Á°¡´Â ¹®Á¦ µî.. RPC¼³Á¤Áß¿¡ ÀÏ¾î³ ¿¡·¯¿¡ ´ëÇÑ
ÇØ°á¹ýÀÔ´Ï´Ù.
Á¦¾îÆÇ->°ü¸®µµ±¸->¼ºñ½º¿¡ °¡¼Å¼ ¾Æ·¡ Á¦°¡ Á¦½ÃÇÑ ¼ºñ½ºÁß¿¡
Áß´ÜµÈ ¼ºñ½º°¡ ÀÖ´Ù¸é ±×°ÍÀ» ½ÃÀÛÀ¸·Î ¹Ù²ãÁֽñ⠹ٶø´Ï´Ù.
±×´ÙÀ½ RPC¼ºñ½º¿¡¼ ÁߴܹöưÀ» ½ÃÀÛÀ¸·Î ¹Ù²ãÁÖ½Ã¸é µË´Ï´Ù.
Á¾¼ÓÁß´ÜÀ¸·Î ¾î·Á¿ò °ÞÀ¸½Å ºÐµé¿¡°Ô Á˼ÛÇÕ´Ï´Ù. ±×·³ ¾Æ·¡ ¼ºñ½º¿¡¼
ÇØ´ç ¼ºñ½º°¡ µÇ´ÂÁö È®ÀÎÇØº¸¼¼¿ä
background lntelligent transfer service
COM+ Event System
COM+ System Application
Cryptographic Services
Distributed Link Tracking Client
Distributed Transaction Coordinator
Error Reporting Service
Help and Support
Human Interface Device Access
IIS Admin
Indexing Service
IPSEC Services
Logical Disk Manager
Logical Disk Manager Administrative Service
Messenger
MS Software Shadow Copy Provider
Network Connections
Print Spooler
Protected Storage
QoS RSVP
Remote Desktop Help Session Manager
Remote Registry
Removable Storage
Routing and Remote Access
Security Accounts Manager
Shell Hardware Detection
System Restore Service
Task Scheduler
Telephony
Telnet
Terminal Services
Upload Manager
Volume Shadow Copy
Windows Audio
Windows Image Acquisition (WIA)
Windows Installer
Windows Management Instrumentation
Wireless Zero Configuration
WMI Performance Adapter
--------ÀÌ·¸°Ô Çϼŵµ ÇØ°áÀÌ ¾ÈµÇ´Â °æ¿ì--------
XP»ç¿ëÀÚ ºÐµéÀ̶ó¸é ´Ù¸¥ XPÄÄÇ»ÅÍ¿¡ °¡¼Å¼
RPC ·¹Áö½ºÆ®¸®¸¦ ã¾Æ º¹»çÇϽÅÈÄ¿¡
ÇØ´çÄÄ¿¡ ´Ù½Ã µ¤¾î¾º¿ì½Ã°í »ç¿ëÇÔÀ¸·Î ´Ù½Ã µÇ´ÂÁö È®ÀÎÇØº¸¼¼¿ä.
±×·³ Áñ°Å¿î ÇÏ·ç µÇ½Ã±â ¹Ù¶ø´Ï´Ù.^^