|
|
|
|
|
 |
 |
 |
| Ãֽо÷µ¥ÀÌÆ® ÇöȲ
document.write("2018.07.06.0");
|
|
 |
|
 |
 |
 |
|
| VBS/Redlof@mm |
| ¹ÙÀÌ·¯½º Á¾·ù |
Script Virus |
½ÇÇàȯ°æ |
Win9x, Win2000, NT |
| ¹ß°ßÀÏ |
2002³â04¿ù16ÀÏ |
Á¦ÀÛÁö |
ºÒºÐ¸í |
| À§Çèµî±Þ |
|
È®»ê¹æ¹ý |
|
| ¹ÙÀÌ·¯½º Å©±â |
11,160 Bytes |
÷ºÎÆÄÀÏ |
¾øÀ½ |
| ¸ÞÀÏÁ¦¸ñ |
¾øÀ½ |
| Áõ»ó¿ä¾à |
|
| Ä¡·á¹æ¹ý |
Åͺ¸¹é½Å Ai, Åͺ¸¹é½Å 2001 ¶Ç´Â Åͺ¸¹é½Å OnlineÀ¸·Î Ä¡·á°¡´ÉÇÕ´Ï´Ù.
Ä¡·áÈÄ http://www.microsoft.com/technet/treeview/default.asp?
url=/technet/security/bulletin/MS00-075.asp
¸¦ ÅëÇÏ¿© °¡»ó¸Ó½ÅÀÇ º¸¾È ÆÐÄ¡¸¦ ¹Þµµ·Ï ÇÑ´Ù.
 |
 |
ºñÁÖ¾ó º£ÀÌÁ÷À¸·Î ¸¸µé¾î Á³À¸¸ç ÷ºÎÆÄÀÏÀÌ ¾ø´Â ¸ÞÀÏÀ» ÅëÇØ ÀüÆÄµÈ´Ù.
C:\Program Files\Common Files\Microsoft Shared\Stationery Æú´õ¿¡
blank.htm ¹ÙÀÌ·¯½º ÆÄÀÏÀ» »ý¼º ÇÏ¿©, À̸¦ ÀÌ¿ëÇÑ ¸ÞÀÏÀÇ HTMLÄڵ带
ÅëÇØ Microsoft VM ActiveX component vulnerability ÀÇ Ãë¾à¼ºÀ» ÀÌ¿ëÇÏ
¿© ÀÚµ¿À¸·Î .html, .htm, .asp, .php, .jsp, and .vbs ÆÄÀÏÀ» °¨¿°½ÃŲ´Ù.
¹ÙÀÌ·¯½º°¡ ½ÇÇà µÇ¸é °¨¿°½Ã ½Ã½ºÅÛ Æú´õ(Win9x : C:\windows\system,
Win2000, NT, XP : C:\Winnt\system32)¿¡
¿¡ kernel.dll¶Ç´Â Kernel32.dll¸¦ »ý¼º ÇÏ°Ô µÇ´Âµ¥ ÀÌ´Â À©µµ¿ì Æú´õ¿¡
WSCRIP.exeÆÄÀÏÀÇ Á¸Àç ¿©ºÎ¿¡ µû¶ó ¼±Åà µÇ¾î Áø´Ù.
´ÙÀ½À¸·Î HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\
Run Ç׸ñ¿¡ Kernel32¸¦ »ý¼ºÇÏ°í ´ÙÀ½°ú °°Àº °ªÀ» Ãß°¡ ÇÑ´Ù.
c:\window\SYSTEM\Kernel32.dll ¶Ç´Â c:\window\SYSTEM\Kernel.dll
¶ÇÇÑ ´ÙÀ½ÀÇ ·¹Áö½ºÆ®¸® °ªÀ» ¼³Á¤ÇÑ´Ù.
HKEY_CLASSES_ROOT\.dll\
(±âº»°ª)  dllfile
Content Type  application/x-msdownload ·Î ¼ÂÆÃ(´ëºÎºÐ ½Ã½ºÅÛÀÇ µðÆúÆ®
°ª)
HKEY_CLASSES_ROOT\dllfile\
DefaultIcon À» HKEY_CLASSES_ROOT\vxdfile\DefaultIcon °ªÀ¸·Î º¯°æ
ScriptEngine À» VBScript·Î º¯°æ
ShellEx\PropertySheetHandlers\WSHProps\ {60254CA5-953B-11CF-8C96-
00AA00B8708C}·Î ¼³Á¤
ScriptHostEncode À» {85131631-480C-11D2-B1F9-00C04F86C324} ·Î ¼³Á¤
HKEY_CLASSES_ROOT\dllFile\Shell\Open\Command\
WScript.exe ÆÄÀÏÀÌ Á¸ÀçÇÏ´Â °æ¿ì
(±âº»°ª) c:\Windows\WScript.exe "%1" %*
¾ø´Â °æ¿ì
(±âº»°ª) c:\Windows\system32\WScript.exe "%1" %* °ª º¯°æ
|
 |
|
|
 |
| ¹«´ÜÀüÀç¤ý¹èÆ÷±ÝÁö |
- ¿¡ºê¸®Á¸¿¡¼ Á¦°øÇÏ´Â ¸ðµç ÄÁÅÙÃ÷ Á¤º¸¿¡ ´ëÇÑ ÀúÀÛ±ÇÀº ¿¡ºê¸®Á¸ÀÇ ¼ÒÀ¯ÀÌ¸ç °ü·Ã¹ýÀÇ º¸È£¸¦ ¹Þ½À´Ï´Ù.
- ¿¡ºê¸®Á¸ÀÇ »çÀü Çã°¡ ¾øÀÌ ¿¡ºê¸®Á¸ ÄÁÅÙÃ÷¸¦ ¹«´ÜÀ¸·Î ÀüÀç, ¹èÆ÷¸¦ ±ÝÁöµÇ¾î ÀÖ½À´Ï´Ù.
- À̸¦ À§¹ÝÇÏ´Â °æ¿ì ¼ÕÇØ¹è»óÀÇ ´ë»ó ¶Ç´Â ¹Î.Çü»ç»óÀÇ ¹ýÀû ¼Ò¼Û ´ë»óÀÌ µÉ ¼ö ÀÖ½À´Ï´Ù.
* ¿¡ºê¸®Á¸ Á¤º¸ ÀÌ¿ë ¹®ÀÇ : greenking@everyzone.com |
|
|