1. Back Orifice ¶õ ¹«¾ùÀΰ¡ ?

cDc(Cult Dead Cow)¶ó´Â ´Üü¿¡¼­ ¸¸µç ÇÁ·Î±×·¥À¸·Î
Server ÇÁ·Î±×·¥°ú Client ÇÁ·Î±×·¥À¸·Î ±¸¼ºµÇ¾î ÀÖÀ¸¸ç
ÀνºÅçÇÑÈÄ client¿¡¼­ Server(Windows 95/98)¸¦ Á¦¾îÇÒ¼ö ÀÖ´Ù.


2. ¾î´ÀÁ¤µµ ±îÁö Á¦¾î°¡ °¡´ÉÇѰ¡?

´ÙÀ½°ú °°Àº ÀÛ¾÷µéÀ» ÇÒ¼öÀÖ½À´Ï´Ù.

Application Ãß°¡/»èÁ¦/¸®½ºÆ®º¸±â
Directory Ãß°¡/»èÁ¦/¸®½ºÆ®º¸±â
File º¹»ç/»èÁ¦/ã±â/¾ÐÃà/ÇØÁ¦/º¸±â
HTTP¼­¹ö ½ÃÀÛ/¸ØÃã
Keyboard ÀԷ¿¡ ´ëÇÑ ·Î±×°¡´É
Play sound
Network ¿¬°á Ãß°¡/»èÁ¦/º¸±â
Ping Host
Process ½ÇÇà/¸ØÃã/º¸±â
Registry ¼öÁ¤
Resolve Host
System Á¤º¸º¸±â/lock°É±â/¸®ºÎÆÃ
File ¼Û¼ö½Å
±âŸ


3. Back Orifice¸¦ »ç¿ëÇÒ¶§ ¹®Á¦°¡ µÇ´Â°ÍÀº ¹«¾ùÀΰ¡?

Back Orifice´Â ¹ÙÀÌ·¯½º°¡ ¾Æ´Ï¸ç, ¸®¸ðÆ®¿¡¼­ ¿ø°ÝÁ¦¾î¸¦
ÇϱâÀ§ÇÑ ÇÁ·Î±×·¥ÀÌ´Ù.

ÇÏÁö¸¸, ÇϳªÀÇ ÆÄÀϸ¸ ½ÇÇàµÇ¸é ÀνºÅçÀÌ °¡´ÉÇϱ⠶§¹®¿¡
´Ù¸¥ ½ÇÇàÆÄÀÏ¿¡ µ¡ºÙ¿© ½ÇÇàÀÌ °¡´ÉÇϸç ÀÌ °æ¿ì ¸®¸ðÆ®¿¡¼­
¼­¹öÀÇ Çã¶ô¾øÀÌ À§¿Í °°Àº ÀÛ¾÷ÀÌ °¡´ÉÇϱ⠶§¹®¿¡ ¹®Á¦°¡
µÉ¼ö ÀÖ´Ù.

±×·¯¹Ç·Î, ¿ÜºÎ¿¡¼­ ´Ù¿î¹ÞÀº ÆÄÀÏ ¶Ç´Â ¸ÞÀÏ·Î ¿Â ÆÄÀÏÀº
¹ÙÀÌ·¯½º¹× Back Orifice°¡ Ãß°¡µÇ¾î ÀÖÀ»¼öµµ ÀÖÀ¸¹Ç·Î
½ÇÇàÀ» ÇÒ¶§ È®ÀÎÀ» ÇØºÁ¾ß ÇÑ´Ù.


4. Back Orifice°¡ ÀνºÅçµÇ¾ú´ÂÁö È®ÀÎÇÏ´Â ¹æ¹ýÀº ?

BO v1.20Àº ¿©·¯°³ÀÇ ÆÄÀÏ·Î ±¸¼ºÀÌ µÇ¾îÀÖÀ¸¸ç, ±×Áß boserve.exe¶ó´Â
ÇϳªÀÇ ÆÄÀϸ¸ ½ÇÇà½ÃŰ¸é °£´ÜÇÏ°Ô ¼­¹ö·Î ÀνºÅçÀÌ µÈ´Ù.

½ÇÇàÈÄ¿¡´Â boserve.exe°¡ ÀÚµ¿ÀûÀ¸·Î Áö¿öÁö°ÔµÇ°í, È­¸é¾Æ·¡ÀÇ
»óŹٿ¡µµ ½ÇÇà»óŰ¡ ³ªÅ¸³ªÁö ¾Ê°í ·¹Áö½ºÆ®¸®¿Í ½Ã½ºÅÛÆú´õ
(/windows/system)¿¡¸¸ ÆÄÀÏÀÌ ³²°ÔµÈ´Ù.

·¹Áö½ºÆ®¸® ¿¡¼­ È®ÀÎ
1) ½ÃÀÛ -> ½ÇÇà -> regedit ½ÇÇà
2) HKEY_LOCAL_MACHINE/SOFTWARE/Microsoft/Windows/
CurrentVersion/RunServices ·Î À̵¿
3) ¿À¸¥ÂÊ Ã¢¿¡ µ¥ÀÌÅͰ¡ ".exe"·Î ³ª¿ÍÀÖ´Ù.

½Ã½ºÅÛ Æú´õ ¿¡¼­ È®ÀÎ
1) /windows/system/windll.dll ÆÄÀÏÀÌ ÀÖ´Ù


5. ¾î¶»°Ô »èÁ¦ÇØ¾ß Çϴ°¡ ?

»ç¿ëÀÚ°¡ ¿øÇؼ­ ÀνºÅçÀÌ µÈ°æ¿ì°¡ ¾Æ´Ò°æ¿ì »èÁ¦¸¦ ÇØ¾ßÇϴµ¥
À̶§ ´ÙÀ½ÀÇ ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¸é µÈ´Ù.

1) BODetect 1.5 ÀÌ¿ë
ÆÄÀÏÀ» ´Ù¿î¹Þ¾Æ ÀÓÀÇÀÇ µð·ºÅ丮¿¡ ¾ÐÃàÀ» ǬÈÄ BoDetect.exe¸¸
½ÇÇà½Ã۸é ÀÚµ¿ÀûÀ¸·Î °Ë»öÀ» ÇØ¼­ Back Orifice¸¦ »èÁ¦ÇÒ¼ö
ÀÖ½À´Ï´Ù.

2) BOShield ÀÌ¿ë
bs120.exe ÇϳªÀÇ ÆÄÀÏÀÌ¸ç ½ÇÇà½Ã۸é ÀÚµ¿ÀûÀ¸·Î »èÁ¦µË´Ï´Ù.


À§ÀÇ ÇÁ·Î±×·¥Àº ´ÙÀ½ »çÀÌÆ®¿¡¼­ ´Ù¿î¹ÞÀ¸½Ç¼ö ÀÖ½À´Ï´Ù.

http://www.cs.nuri.net/ -> °í°´Àǹæ -> special ÀÚ·á¹æ -> BODelete
( À§ÀÇ 2°³ÀÇ ÆÄÀÏÀ» ¹­¾î¼­ ¾ÐÃà½ÃÄÑ ³õ¾Ò½À´Ï´Ù. )
http://www.ozemail.com.au/~dwarren/backorifice/removal.html


6. °è¼ÓÇØ¼­ »ç¿ëÇϱâ À§Çؼ­´Â ¾î¶»°Ô ÇØ¾ßÇϴ°¡ ?

Back Orifice ¿ø·¡ÀÇ ¸ñÀûÀÎ ¸®¸ðÆ®¾×¼¼½º¸¦ ÇØÅ·ÀÇ ¿°·Á¾øÀÌ »ç¿ëÇϱâ À§ÇØ ´ÙÀ½°ú °°Àº ¼³Á¤À» ÇØÁÖ¸é µË´Ï´Ù.

1) Back OrificeÀÇ ¾ÐÃàÀ» Ǭ´Ù.
2) µµ½ºÃ¢À» ¿­°í ¾ÐÃàÀ» Ǭ Æú´õ¿¡¼­ c:>boconfig.exe boserv.exe ¶ó°í
½ÇÇà½Ãŵ´Ï´Ù.
3) boserv.exe ¸¸ ½ÇÇà½Ã۸é port ¹øÈ£ 31337, ÆÐ½º¿öµå ¾øÀÌ ¼³Á¤ÀÌ µÇ¹Ç·Î boconfig¸¦ ÀÌ¿ëÇØ ÆÐ½º¿öµå¸¦ ¼³Á¤ÇÕ´Ï´Ù. À̰æ¿ì ¿ÜºÎ¿¡¼­ ¿¬°á½Ã ÆÐ½º¿öµå¸¦ ¾Ë¾Æ¾ß ¾×¼¼½º°¡ °¡´ÉÇÕ´Ï´Ù.

* Âü°í : Back Orifice¾È¿¡ ÀÖ´Â ÅØ½ºÆ®¹®¼­ÂüÁ¶ (bo.txt)


7. Âü°í»çÀÌÆ®

1) http://www.ozemail.com.au/~dwarren/backorifice/index.html
2) http://www.iss.net/xforce/alerts/advise5.html






Copyright(c) 2001, ¼öÆÛÀ¯ÀúÄÚ¸®¾Æ All Rights Reserved.
¼­¹ö±¸Ãà(¿î¿ë)»ó´ã : e-mail : webmaster@superuser.co.kr