PC ´º½º Ȩ Àαâ PC ´º½º

»õ·Î¿î º¸¾ÈÃë¾àÁ¡ ÀÌ¿ëÇÑ Æ®·ÎÀ̸ñ¸¶ µîÀå

2007-03-30 11:51
ÀåÈ«½Ä ´ëÇ¥±âÀÚ potatotree´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â potatotree@bodnara.co.kr

2007³â 3¿ù 29ÀÏ »õ·Î¿î º¸¾ÈÃë¾àÁ¡À» ÀÌ¿ëÇÑ Æ®·ÎÀ̸ñ¸¶°¡ Áß±¹ µîÁö¿¡¼­ ¹ß°ßµÇ¾î ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»çÀÇ ±ä±ÞÇÑ ÆÐÄ¡°¡ ÇÊ¿äÇÑ »óȲÀ̶ó°í À×Ä«ÀÎÅͳÝÀº ¹àÇû´Ù.

À̹ø¿¡ ¹ß°ßµÈ Á¾·ù´Â Animated Cursor ÆÄÀÏÀÇ ¡®Zero-Day Attack¡¯À̸ç, ¾ÆÀÌÄÜ ¹× Ä¿¼­ Çü½Ä ÆÄÀÏÀÇ Ã³¸® ¹®Á¦·Î ÀÎÇÑ ¿ø°ÝÄÚµå ½ÇÇà °¡´É Ãë¾àÁ¡ÀÌ´Ù. Áö±Ý±îÁö URL ÁÖ¼Ò¸¸ ´Ù¸¥ 3°³ÀÇ »ùÇÃÀÌ ÀÔ¼öµÈ »óȲÀÌ´Ù.



ANI ÆÄÀÏÀº RIFF(Resource Interchange File Format) Çü½ÄÀ¸·Î À©µµ¿ì¿¡¼­ ¸ÖƼ¹Ìµð¾î °ü·Ã µ¥ÀÌÅÍ µîÀ» ÀúÀåÇϱâ À§ÇØ ¸¸µé¾îÁø ÆÄÀÏ Æ÷¸ËÀ¸·Î AVI, WAV µîÀÇ ¹Ìµð¾î ÆÄÀÏ¿¡¼­µµ ´Ù¾çÇÏ°Ô »ç¿ëµÇ°í ÀÖ´Ù.

¾ÇÀÇÀûÀÎ ANI ÆÄÀÏÀº Ãë¾àÇÑ À¥ »çÀÌÆ®¿Í ÀüÀÚ¿ìÆí ¸Þ½ÃÁö µîÀ» ÅëÇؼ­ À¯Æ÷µÇ¸ç, ÀÎÅÍ³Ý »ç¿ëÀÚ°¡ ÇØ´ç À¥ ÆäÀÌÁö³ª »çÀÌÆ®¸¦ ¹æ¹® ½Ã Exploit Äڵ尡 Æ÷ÇÔµÈ ANI ÆÄÀÏÀÌ ½ÇÇàµÇ°í, ÄÚµå ³»ºÎ¿¡ Æ÷ÇÔÇÏ°í ÀÖ´Â URL¿¡ ÀÇÇÏ¿© ¶Ç ´Ù¸¥ ¾Ç¼ºÄڵ带 »ç¿ëÀÚ ¸ô·¡ ¼³Ä¡ÇÏ°Ô µÇ´Â ¹æ½ÄÀ» ÀÌ¿ëÇÏ°Ô µÈ´Ù.

ÇöÀç ¸¶ÀÌÅ©·Î¼ÒÇÁÆ®»ç¿¡¼­´Â ¾Æ·¡¿Í °°ÀÌ 2007³â 3¿ù 29ÀÏÀÚ·Î Security Advisory¸¦ ¹ßÇ¥ÇÑ »óÅÂÀÌ´Ù.


Microsoft Security Advisory (935423)
Vulnerability in Windows Animated Cursor Handling
http://www.microsoft.com/technet/security/advisory/935423.mspx

¿µÇâÀ» ¹Þ´Â ¿î¿µÃ¼Á¦´Â ¾Æ·¡¿Í °°ÀÌ ¹ßÇ¥µÇ¾ú´Ù.

Microsoft Windows 2000 Service Pack 4
Microsoft Windows XP Service Pack 2
Microsoft Windows XP 64-Bit Edition Version 2003 (Itanium)
Microsoft Windows XP Professional x64 Edition
Microsoft Windows Server 2003
Microsoft Windows Server 2003 for Itanium-based Systems
Microsoft Windows Server 2003 Service Pack 1
Microsoft Windows Server 2003 with SP1 for Itanium-based Systems
Microsoft Windows Server 2003 x64 Edition
Microsoft Windows Vista

¹ß°ßµÈ ANI ÆÄÀÏ·Î ÀÎÇÏ¿© ´Ù¿î·Îµå°¡ ½ÃµµµÇ´Â ÆÄÀÏÀº Áß±¹ÀÇ Æ¯Á¤ »çÀÌÆ®¿¡ Á¸ÀçÇϸç, Viking º¯Á¾ ¹ÙÀÌ·¯½º¿¡ ÀÇÇØ ÆÄÀÏÀÌ °¨¿°µÈ´Ù.

ÀÌ ±â»çÀÇ ÀÇ°ß º¸±â
zstaiji (ID) / 07-03-30 12:06/ ½Å°í
Àü °³ÀÎÀûÀ¸·Î ³×À̹ö ¹«·áÄ¡·á¸¦ ÃßõÇÕ´Ï´Ù ¹«·áÄ¡·á+PCÇÁ¸®
ÀÌ·¸°Ô Á¶ÇÕÇؼ­ ½áº¸¼¼¿ä^^
jin2006 (ID) / 07-03-30 12:20/ ½Å°í
»ç¿ëÇÏ°í ÀÖ´Â v3 2007 ÀÌ ÇØ°áÇØ ÁÙ·ÃÁö...
dafcvzz (ID) / 07-03-30 14:34/ ½Å°í
Àü¿©Å½ÉÇѹÙÀÌ·¯½º¸¦¾È°É·ÁºÁ¼­ ¤Ñ¤Ñ;

Á¦´ë·Î°É¸®¸é ¾Æ¿¹Çϵå¿þ¾î¹ö¸±Á¤µ·°¡¿ä?
ohhobod (ID) / 07-03-30 16:14/ ½Å°í
¿ª½Ã µû¶ó¼­ ¹ßÀüÇϴ°ÍÀÌ Æ®·ÎÀ̸ñ¸¶±º¿ä.´ë´ÜÇÏ´Ù´Â ¸» ¹Û¿¡´Â
kama136 (ID) / 07-03-30 19:54/ ½Å°í
¹ÙÀÌ·¯½º ³Ê¹« ¹«¼·ÁÒ...
oakim704 (ID) / 07-03-31 0:11/ ½Å°í
¤¾..µÎ´ÞÀü¿¡ Áö¿öµµ Áö¿öµµ »ý±â´Â
¹ÙÀÌ·¯½º¶§¹®¿¡ Çϵ带 Æ÷¸äÇÑ
¾ÆDZâ¾ïÀÌ »ý°¢³ª´Â±º¿ä...¤¾
pmicro (ID) pmicro´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  / 07-03-31 19:19/ ½Å°í
¾Ë·ÁÁø º¸¾ÈÃë¾àÁ¡Àº ´ëºñÇÒ ¼ö ÀÖÁö¸¸ ºñ°ø°³µÈ º¸¾ÈÃë¾àÁ¡Àº ´ëºñÇÒ ¼ö ¾ø´Ù´Â...-_-;;
gimjeong (ID) / 07-03-31 23:42/ ½Å°í
¿©·¯ »çÀÌÆ®¿¡¼­ ¹«·á·Î V3Áö¿øÇØ ÁÖÁÒ
medkwon (ID) / 07-04-01 0:55/ ½Å°í
Æ®·ÎÀ̸ñ¸¶´Â ²÷ÀÓ¾øÀÌ ¹ßÀüÇϴ°¡ º¸±º¿ä. ¸¶Ä¡ ½ÇÁ¦ ¹ÙÀÌ·¯½º°¡ º¯Á¾À» Çؼ­ »ýÁ¸·ÂÀ» À¯ÁöÇϵíÀÌ..
ljhhjw (ID) ljhhjw´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  / 07-04-01 11:58/ ½Å°í
²ÙÁØÈ÷ ¶Õ°í ¸·°í..
yakpkb (ID) yakpkb´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  / 07-04-01 12:35/ ½Å°í
Á¤¸» ¹ÙÀÌ·¯½º ¶§¹®¿¡ ½É°¢ÇÏ°Ô ´çÇÑÀûÀÌ Àִµ¥...
asuea (ID) asuea´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  / 07-04-01 14:05/ ½Å°í
Áö±ßÁö±ßÇÑ ¹ÙÀÌ·¯½º ¤Ñ¤Ñ Àú°Å ¸¸µå´Â ½Ã°£¿¡ Á» ´õ °Ç¼³ÀûÀÎ ÀϵéÀ» Çϸé ÁÁÀ»ÅÙµ¥...
godanhan (ID) / 07-04-01 16:04/ ½Å°í
Æ®·ÎÀ̸ñ¸¶ÇÏ´Ï 300ÀÌ »ý°¢³ª´Â±º¿ä.
ceoh (ID) / 07-04-01 16:05/ ½Å°í
´ëü ¹ÙÀÌ·¯½º ¸¸µå´Â »ç¶÷µé ½É¸®»óÅ´ ¾î¶³±î¿ä? ¿À´Ã NTSYS.exe °ü·ÃµÈ ¿ú¿¡ °É·Á¼­ ÇØ°áÇÑ´Ù°í »ðÁúÇÑ »ý°¢ÇÏ¸é ¿­¹Þ½À´Ï´Ù T_T
bluemun (ID) bluemun´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  / 07-04-01 16:51/ ½Å°í
ºñ½ºÅ¸µµ º°¼ö ¾ø±º¿ä
jlee95 (ID) jlee95´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  / 07-04-01 19:18/ ½Å°í
À̹ø °ÍÀº Á» ½É°¢Çϱº¿ä
sky0734 (ID) sky0734´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  / 07-04-01 23:51/ ½Å°í
Áß±¹¾ÖµéÀÌ Àß ¸¸µå³×
saddj (ID) saddj´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  / 07-04-02 10:18/ ½Å°í
Áß±¹Àº Áö±¸¾Ç
blasty (ID) blasty´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  / 07-04-02 19:47/ ½Å°í
ºñ½ºÅ¸µµ Æ÷ÇԵǾî Àֳ׿ä
guru (ID) / 07-04-03 19:25/ ½Å°í
ÆÐÄ¡ ¾÷µ¥ÀÌÆ®ÇØ¾ß °Ú±º¿ä..
postdada (ID) postdada´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  / 07-04-04 10:13/ ½Å°í
¿ª½Ã Áß±¹À̳׿ä
y20303 (ID) y20303´ÔÀÇ ¹Ìµð¾î·Î±× °¡±â  / 07-04-06 6:30/ ½Å°í
Á¤½Å ¾ø´øµ¥..
´Ð³×ÀÓ
ºñȸ¿ø

º¸µå³ª¶ó ¸¹ÀÌ º» ´º½º
º¸µå³ª¶ó ¸¹ÀÌ º» ±â»ç
·Î±×ÀÎ | ÀÌ ÆäÀÌÁöÀÇ PC¹öÀü
Copyright NexGen Research Corp. 2010