|
1. Back Orifice ¶õ ¹«¾ùÀΰ¡ ?
cDc(Cult Dead Cow)¶ó´Â ´Üü¿¡¼ ¸¸µç ÇÁ·Î±×·¥À¸·Î
Server ÇÁ·Î±×·¥°ú Client ÇÁ·Î±×·¥À¸·Î ±¸¼ºµÇ¾î ÀÖÀ¸¸ç
ÀνºÅçÇÑÈÄ client¿¡¼ Server(Windows 95/98)¸¦ Á¦¾îÇÒ¼ö ÀÖ´Ù.
2. ¾î´ÀÁ¤µµ ±îÁö Á¦¾î°¡ °¡´ÉÇѰ¡?
´ÙÀ½°ú °°Àº ÀÛ¾÷µéÀ» ÇÒ¼öÀÖ½À´Ï´Ù.
Application Ãß°¡/»èÁ¦/¸®½ºÆ®º¸±â
Directory Ãß°¡/»èÁ¦/¸®½ºÆ®º¸±â
File º¹»ç/»èÁ¦/ã±â/¾ÐÃà/ÇØÁ¦/º¸±â
HTTP¼¹ö ½ÃÀÛ/¸ØÃã
Keyboard ÀԷ¿¡ ´ëÇÑ ·Î±×°¡´É
Play sound
Network ¿¬°á Ãß°¡/»èÁ¦/º¸±â
Ping Host
Process ½ÇÇà/¸ØÃã/º¸±â
Registry ¼öÁ¤
Resolve Host
System Á¤º¸º¸±â/lock°É±â/¸®ºÎÆÃ
File ¼Û¼ö½Å
±âŸ
3. Back Orifice¸¦ »ç¿ëÇÒ¶§ ¹®Á¦°¡ µÇ´Â°ÍÀº ¹«¾ùÀΰ¡?
Back Orifice´Â ¹ÙÀÌ·¯½º°¡ ¾Æ´Ï¸ç, ¸®¸ðÆ®¿¡¼ ¿ø°ÝÁ¦¾î¸¦
ÇϱâÀ§ÇÑ ÇÁ·Î±×·¥ÀÌ´Ù.
ÇÏÁö¸¸, ÇϳªÀÇ ÆÄÀϸ¸ ½ÇÇàµÇ¸é ÀνºÅçÀÌ °¡´ÉÇϱ⠶§¹®¿¡
´Ù¸¥ ½ÇÇàÆÄÀÏ¿¡ µ¡ºÙ¿© ½ÇÇàÀÌ °¡´ÉÇϸç ÀÌ °æ¿ì ¸®¸ðÆ®¿¡¼
¼¹öÀÇ Çã¶ô¾øÀÌ À§¿Í °°Àº ÀÛ¾÷ÀÌ °¡´ÉÇϱ⠶§¹®¿¡ ¹®Á¦°¡
µÉ¼ö ÀÖ´Ù.
±×·¯¹Ç·Î, ¿ÜºÎ¿¡¼ ´Ù¿î¹ÞÀº ÆÄÀÏ ¶Ç´Â ¸ÞÀÏ·Î ¿Â ÆÄÀÏÀº
¹ÙÀÌ·¯½º¹× Back Orifice°¡ Ãß°¡µÇ¾î ÀÖÀ»¼öµµ ÀÖÀ¸¹Ç·Î
½ÇÇàÀ» ÇÒ¶§ È®ÀÎÀ» ÇØºÁ¾ß ÇÑ´Ù.
4. Back Orifice°¡ ÀνºÅçµÇ¾ú´ÂÁö È®ÀÎÇÏ´Â ¹æ¹ýÀº ?
BO v1.20Àº ¿©·¯°³ÀÇ ÆÄÀÏ·Î ±¸¼ºÀÌ µÇ¾îÀÖÀ¸¸ç, ±×Áß boserve.exe¶ó´Â
ÇϳªÀÇ ÆÄÀϸ¸ ½ÇÇà½ÃŰ¸é °£´ÜÇÏ°Ô ¼¹ö·Î ÀνºÅçÀÌ µÈ´Ù.
½ÇÇàÈÄ¿¡´Â boserve.exe°¡ ÀÚµ¿ÀûÀ¸·Î Áö¿öÁö°ÔµÇ°í, È¸é¾Æ·¡ÀÇ
»óŹٿ¡µµ ½ÇÇà»óŰ¡ ³ªÅ¸³ªÁö ¾Ê°í ·¹Áö½ºÆ®¸®¿Í ½Ã½ºÅÛÆú´õ
(/windows/system)¿¡¸¸ ÆÄÀÏÀÌ ³²°ÔµÈ´Ù.
·¹Áö½ºÆ®¸® ¿¡¼ È®ÀÎ
1) ½ÃÀÛ -> ½ÇÇà -> regedit ½ÇÇà
2) HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/
CurrentVersion/RunServices ·Î À̵¿
3) ¿À¸¥ÂÊ Ã¢¿¡ µ¥ÀÌÅͰ¡ ".exe"·Î ³ª¿ÍÀÖ´Ù.
½Ã½ºÅÛ Æú´õ ¿¡¼ È®ÀÎ
1) /windows/system/windll.dll ÆÄÀÏÀÌ ÀÖ´Ù
5. ¾î¶»°Ô »èÁ¦ÇØ¾ß Çϴ°¡ ?
»ç¿ëÀÚ°¡ ¿øÇؼ ÀνºÅçÀÌ µÈ°æ¿ì°¡ ¾Æ´Ò°æ¿ì »èÁ¦¸¦ ÇØ¾ßÇϴµ¥
À̶§ ´ÙÀ½ÀÇ ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¸é µÈ´Ù.
1) BODetect 1.5 ÀÌ¿ë
ÆÄÀÏÀ» ´Ù¿î¹Þ¾Æ ÀÓÀÇÀÇ µð·ºÅ丮¿¡ ¾ÐÃàÀ» ǬÈÄ BoDetect.exe¸¸
½ÇÇà½Ã۸é ÀÚµ¿ÀûÀ¸·Î °Ë»öÀ» ÇØ¼ Back Orifice¸¦ »èÁ¦ÇÒ¼ö
ÀÖ½À´Ï´Ù.
2) BOShield ÀÌ¿ë
bs120.exe ÇϳªÀÇ ÆÄÀÏÀÌ¸ç ½ÇÇà½Ã۸é ÀÚµ¿ÀûÀ¸·Î »èÁ¦µË´Ï´Ù.
À§ÀÇ ÇÁ·Î±×·¥Àº ´ÙÀ½ »çÀÌÆ®¿¡¼ ´Ù¿î¹ÞÀ¸½Ç¼ö ÀÖ½À´Ï´Ù.
http://www.cs.nuri.net/ -> °í°´Àǹæ -> special ÀÚ·á¹æ ->
BODelete
( À§ÀÇ 2°³ÀÇ ÆÄÀÏÀ» ¹¾î¼ ¾ÐÃà½ÃÄÑ ³õ¾Ò½À´Ï´Ù. )
http://www.ozemail.com.au/~dwarren/backorifice/removal.html
6. °è¼ÓÇØ¼ »ç¿ëÇϱâ À§Çؼ´Â ¾î¶»°Ô ÇØ¾ßÇϴ°¡ ?
Back Orifice ¿ø·¡ÀÇ ¸ñÀûÀÎ ¸®¸ðÆ®¾×¼¼½º¸¦ ÇØÅ·ÀÇ ¿°·Á¾øÀÌ »ç¿ëÇϱâ À§ÇØ ´ÙÀ½°ú
°°Àº ¼³Á¤À» ÇØÁÖ¸é µË´Ï´Ù.
1) Back OrificeÀÇ ¾ÐÃàÀ» Ǭ´Ù.
2) µµ½ºÃ¢À» ¿°í ¾ÐÃàÀ» Ǭ Æú´õ¿¡¼ c:>boconfig.exe boserv.exe
¶ó°í
½ÇÇà½Ãŵ´Ï´Ù.
3) boserv.exe ¸¸ ½ÇÇà½Ã۸é port ¹øÈ£ 31337, ÆÐ½º¿öµå ¾øÀÌ ¼³Á¤ÀÌ
µÇ¹Ç·Î boconfig¸¦ ÀÌ¿ëÇØ ÆÐ½º¿öµå¸¦ ¼³Á¤ÇÕ´Ï´Ù. À̰æ¿ì ¿ÜºÎ¿¡¼ ¿¬°á½Ã ÆÐ½º¿öµå¸¦
¾Ë¾Æ¾ß ¾×¼¼½º°¡ °¡´ÉÇÕ´Ï´Ù.
* Âü°í : Back Orifice¾È¿¡ ÀÖ´Â ÅØ½ºÆ®¹®¼ÂüÁ¶ (bo.txt)
7. Âü°í»çÀÌÆ®
1) http://www.ozemail.com.au/~dwarren/backorifice/index.html
2) http://www.iss.net/xforce/alerts/advise5.html
|