*°¨¿°
°æ·Î
³×Æ®¿öÅ©
°øÀ¯
Æú´õ¿Í,
À©µµ¿ì
º¸¾ÈÆÐÄ¡
ÇêÁ¡µîÀ»
ÀÌ¿ëÇؼ
ÀüÆĹ×
¼³Ä¡µÈ´Ù.
MS03-039 RPC
DCOM2 Ãë¾àÁ¡
http://www.microsoft.com/korea/technet/security/bulletin/MS03-039.asp
MS04-011 Microsoft Windows¿ë º¸¾È ¾÷µ¥ÀÌÆ® Áß LSASS Ãë¾àÁ¡ http://www.microsoft.com/korea/technet/security/bulletin/ms04-011.asp
»ç¿ëÀÚ
°èÁ¤ÀÇ
Ãë¾àÇÑ
¾ÏÈ£¿¡
ÀÇÇØ
°¨¿°
À©µµ¿ì
NT°è¿(À©µµ¿ì
NT,2000,XP)ÀÇ
°ü¸®
¸ñÀû
°øÀ¯Æú´õ¿¡
´ëÇÑ
»ç¿ëÀÚ
·Î±×ÀÎ
°èÁ¤ÀÇ
¾ÏÈ£°¡
Ãë¾àÇÑ
°æ¿ì
½Ã½ºÅÛ¿¡
Á¢¼Ó
ÈÄ
½ÇÇà.
»ç¿ëÀÚ
·Î±×ÀÎ
°èÁ¤¿¡
´ëÀÔÇÏ´Â
¾ÏÈ£
¸®½ºÆ®´Â
¾Æ·¡¿Í
°°´Ù.
intranet winpass blank office control nokia
siemens compaq cisco orainstall sqlpassoainstall db1234
databasepassword databasepass dbpassword dbpass access
domainpassword domainpass domain hello bitch exchange
backup technical loginpass login katie george chris
brian susan peter win2000 winnt winxp win2k
win98 windows oeminstall oemuser homeuser accounting
accounts internet outlook qwerty server system
changeme linux 1234567890 123456789 12345678 1234567
123456 12345 pass1234 passwd password password1
oracle database default guest wwwadmin teacher
student owner computer staff admins administrat
administrateur administrador administrator
*Áõ»ó
À©µµ¿ì
½Ã½ºÅÛ
Æú´õ¿¡
plscdksx.exe ¶ó´Â
ÆÄÀÏÀ»
»ý¼ºÇÑ´Ù.
À©µµ¿ì
½Ã½ºÅÛ
Æú´õ |
95/98/ME |
C:\Windows\System |
NT/2000 |
C\WinNT\System32 |
XP |
Windows\System32 |
.
±×¸®°í
·¹Áö½ºÆ®¸®¿¡
´ÙÀ½
value¸¦
µî·ÏÇØ
À©µµ¿ì
±¸µ¿½Ã
ÀÚµ¿
½ÇÇàµÇµµ·Ï
¸¸µç´Ù.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
¡°program
access ¡° = plscdksx.exe
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices ¡°program
access ¡° = plscdksx.exe
°¨¿°µÈ
½Ã½ºÅÛÀº
TCP ÀÓÀÇÀÇ
Æ÷Æ®¸¦
LISTENING »óÅ·Î
¿¾îµÐ´Ù.
(»ó´ë·ÎºÎÅÍ
Á¢¼ÓÀ»
±â´Ù¸®´Â
»óÅÂ)
±×
ÈÄ
»ç¿ëÀÚ
¸ô·¡
Á¢¼Ó
ÇØ
½ºÆÔ
¸ÞÀÏ
¹ß¼Û,
¾Öµå¿þ¾î
¼³Ä¡,
µ¥ÀÌÅÍ
»èÁ¦,
±×¸®°í
°³ÀÎÀÇ
ÄÄÇ»ÅÍ
»ç¿ë
³»¿ªÀ»
ÈÉÃĺ¸°Å³ª
°¢Á¾
ÆÄÀÏ(°³ÀÎ
¹®¼,
±â¹Ð
¹®¼
µî)À»
¿ÜºÎ·Î
»©°¡´Â
º¸¾È»ó
¹®Á¦µµ
¹ß»ýÇÒ
¼ö
ÀÖÀ½
-¹ÂÅؽº
»ý¼º
´ÙÀ½
¹ÂÅؽº(Mutex)¸¦
»ý¼ºÇØ
Áߺ¹
½ÇÇàÀ»
¹æÁöÇÑ´Ù.
-
idksx
- °¨¿°µÈ ½Ã½ºÅÛÀº ½ÇÇàÁßÀΠƯÁ¤ ÇÁ·Î¼¼½º¸¦
°Á¦ Á¾·ù ½ÃŲ´Ù.
ssate.exe winsys.exe winupd.exe SysMonXP.exe
bbeagle.exe Penis32.exe mscvb32.exe sysinfo.exe
µîµî.. |