๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
728x90
๋ฐ˜์‘ํ˜•

๐Ÿ”’์ •๋ณด๋ณด์•ˆ/๋„คํŠธ์›Œํฌ ๋ณด์•ˆ24

๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - HTTP ํŠธ๋ž˜ํ”ฝ ๋ถ„์„ ํ”„๋ก์‹œ(mitmproxy) mitmproxy๋Š” ๋””๋ฒ„๊น…, ํ…Œ์ŠคํŠธ, ๊ฐœ์ธ์ •๋ณด ๋ณดํ˜ธ ์ธก์ •, ์นจํˆฌ ํ…Œ์ŠคํŠธ๋ฅผ ์œ„ํ•œ ์Šค์œ„์Šค ๊ตฐ์šฉ ์นผ์ž…๋‹ˆ๋‹ค. HTTP/1, HTTP/2, WebSockets ๋˜๋Š” ๊ธฐํƒ€ SSL/TLS ๋ณดํ˜ธ ํ”„๋กœํ† ์ฝœ๊ณผ ๊ฐ™์€ ์›น ํŠธ๋ž˜ํ”ฝ์„ ๊ฐ€๋กœ์ฑ„๊ณ , ๊ฒ€์‚ฌํ•˜๊ณ , ์ˆ˜์ •ํ•˜๊ณ , ์žฌ์ƒํ•˜๋Š” ๋ฐ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. HTML์—์„œ Protobuf์— ์ด๋ฅด๋Š” ๋‹ค์–‘ํ•œ ๋ฉ”์‹œ์ง€ ์œ ํ˜•์„ ์˜ˆ์˜๊ฒŒ ๋ณ€ํ™˜ ๋ฐ ๋””์ฝ”๋”ฉํ•˜๊ณ , ํŠน์ • ๋ฉ”์‹œ์ง€๋ฅผ ์ฆ‰์‹œ ๊ฐ€๋กœ์ฑ„๊ณ , ๋ชฉ์ ์ง€์— ๋„๋‹ฌํ•˜๊ธฐ ์ „์— ์ˆ˜์ •ํ•˜๊ณ , ๋‚˜์ค‘์— ํด๋ผ์ด์–ธํŠธ๋‚˜ ์„œ๋ฒ„๋กœ ์žฌ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. https://mitmproxy.org/ mitmproxy - an interactive HTTPS proxyMitmproxy has a vibrant ecosystem of addons and tools building on it:mi.. 2024. 5. 4.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - WebRTC(IP leak issue), NAT, ICE, STUN, TURN Web Real-Time Communication ์›น/์•ฑ์—์„œ ๋ณ„๋‹ค๋ฅธ ์†Œํ”„ํŠธ์›จ์–ด ์—†์ด ์นด๋ฉ”๋ผ, ๋งˆ์ดํฌ ๋“ฑ์„ ์‚ฌ์šฉํ•˜์—ฌ ์‹ค์‹œ๊ฐ„ ์ปค๋ฎค๋‹ˆ์ผ€์ด์…˜์„ ์ œ๊ณตํ•ด ์ฃผ๋Š” ๊ธฐ์ˆ  ํ™”์ƒํ†ตํ™”, ํ™”์ƒ ๊ณต์œ  ๋“ฑ์„ ๊ตฌํ˜„ํ•  ์ˆ˜ ์žˆ๋Š” ์˜คํ”ˆ์†Œ์Šค P2P๋ฐฉ์‹์œผ๋กœ Peer๊ฐ„์˜ ์ „์†ก๋˜๋„๋ก ์ง€์› JavaScript API๋กœ ์ œ๊ณต Peer to Peer ํ†ต์‹ ์„ ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ์‚ฌ์šฉ์ž IP ์ฃผ์†Œ๋ฅผ ์•Œ์•„์•ผ ํ•˜๋Š”๋ฐ ์ด๋•Œ ๋ฐฉํ™”๋ฒฝ ๋“ฑ์˜ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด STUN/TURN ์„œ๋ฒ„๋กœ ์ด๋ฅผ ํ•ด๊ฒฐ WebRTC IP Leak Test P2P ๋ฐฉ์‹์ด๋‹ค ๋ณด๋‹ˆ WebRTC API๋ฅผ ์ด์šฉํ•ด ์•„์ดํ”ผ๊ฐ€ ๋…ธ์ถœ๋˜๋Š” ๊ฒฝ์šฐ๋„ ์ƒ๊ธด๋‹ค. ๋‚ด ์•„์ดํ”ผ๊ฐ€ ๋…ธ์ถœ๋˜๋Š”์ง€ ํ™•์ธํ•˜๋Š” ์‚ฌ์ดํŠธ๊ฐ€ ์กด์žฌํ•œ๋‹ค. https://browserleaks.com/webrtc WebRTC Leak Test The WebRT.. 2024. 4. 5.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - NAC ์šฐํšŒ ๊ด€๋ จ Cheat Sheet https://redteam.coffee/woot/nac-bypass-cheatsheet NAC Bypass Cheatsheet | Ikigai This post lists down a few of the techniques which can be used to bypass Network Access Control solutions(NAC). redteam.coffee macchanger macchanger -m XX:XX:XX:XX:XX:XX randommac.py #!/usr/bin/python import subprocess import sys import threading import time class MyThread (threading.Thread): die = False def __init_.. 2024. 3. 28.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - Snort ๋ช…๋ น์–ด ๋ชจ์Œ rules ๊ฒฝ๋กœ ls -l /etc/snort/rules/ ICMP ๊ฐ์ง€ ๋ฃฐ # vi /etc/snort/rules/local.rules alert icmp any any -> any any (msg:"ICMP Detected";sid:1000001;) Snort ์‹คํ–‰(Linux) snort -c /etc/snort/rules/local.rules -i eth0 Snort ์‹คํ–‰(Windows) snort -c c:\Snort\rules\local.rules -l C:\Snort\log\ ๋กœ๊ทธ(alert) ํ™•์ธ tail -f /var/log/snort/alert ์ฐธ๊ณ : https://net123.tistory.com/580 Snort - 04. Snort ๋ฃฐ ๊ตฌ์„ฑ ๋ฐ ํ…Œ์ŠคํŠธ Snort - 04. Snort.. 2024. 3. 17.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - Snort ์นผ๋ฆฌ๋ฆฌ๋ˆ…์Šค 1.0 ์„ค์น˜ 1. ์—…๋ฐ์ดํŠธ๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค. # apt-get update 2. ๋งŒ์•ฝ ์—…๋ฐ์ดํŠธ๊ฐ€ ๋˜์ง€ ์•Š๋Š”๋‹ค๋ฉด ์—…๋ฐ์ดํŠธ ์ฃผ์†Œ๋ฅผ /etc/apt/sources.list ์—์„œ ๋‹ค์Œ๊ณผ ๊ฐ™์ด ๋ณ€๊ฒฝํ•ฉ๋‹ˆ๋‹ค. deb http://http.kali.org/kali kali-rolling main non-free contrib ๋˜๋Š” deb http://old.kali.org/kali moto main non-free contrib 2. ์—…๋ฐ์ดํŠธ ํ›„ Snort ๋ฅผ ์„ค์น˜ํ•ฉ๋‹ˆ๋‹ค. # apt-get install snort Y ๋ฅผ ๋ˆŒ๋Ÿฌ ์„ค์น˜๋ฅผ ์ง„ํ–‰ํ•ฉ๋‹ˆ๋‹ค. 3. ์„ค์น˜๊ฐ€ ์™„๋ฃŒ๋˜๋ฉด Snort ์ •์ฑ…์„ ํŽธ์ง‘ํ•ฉ๋‹ˆ๋‹ค. # vi /etc/snort/rules/local.rules 4. ์ •์ฑ… ํŽธ์ง‘ ํ›„ ๋ฐ๋ชฌ์„ ํ™œ์„ฑํ™” ํ•ฉ๋‹ˆ๋‹ค. # snort -v -c /etc/.. 2023. 11. 17.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - Snort ์œˆ๋„์šฐ ์„ค์น˜ Snort ์„ค์น˜ ์ฐธ๊ณ : https://m.blog.naver.com/limhojin123/221779047954 Snort ์œˆ๋„์šฐ๋ฒ„์ „ ์„ค์น˜์™€ ์‚ฌ์šฉํ•˜๊ธฐ 2ํƒ„(์ •๋ณด๋ณด์•ˆ๊ธฐ์‚ฌ ํ•„๊ธฐ, ์ •๋ณด๋ณด์•ˆ์‚ฐ์—…๊ธฐ์‚ฌ) ์ €๋ฒˆ #Snort 1ํƒ„์€ ๋ฆฌ๋ˆ…์Šค ๋ฒ„์ „์„ ์„ค์น˜ํ•ด์„œ ์‚ฌ์šฉํ–ˆ๋‹ค. ์ด๋ฒˆ์—๋Š” ์œˆ๋„์šฐ ๋ฒ„์ „ Snort๋ฅผ ์„ค์น˜ํ•˜๊ณ  ์‚ฌ์šฉ ํ•ด๋ณด... blog.naver.com https://www.snort.org/downloads# Snort Rules and IDS Software Download Security Onion is a Linux distro for intrusion detection, network security monitoring, and log management. It's based on Ubuntu and contai.. 2023. 11. 17.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - FTP ํŒจ์‹œ๋ธŒ ๋ชจ๋“œ(PASV EPSV) FTP ์ˆ˜๋™ ๋ชจ๋“œ(Passive mode)๋ž€? FTP ํŒจ์‹œ๋ธŒ(PASSIVE) ๋ชจ๋“œ๋ž€ ๊ธฐ์กด ์•กํ‹ฐ๋ธŒ ๋ชจ๋“œ์— ํด๋ผ์ด์–ธํŠธ์˜ ๋ฐฉํ™”๋ฒฝ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด ๊ณ ์•ˆ๋œ "ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์„œ๋ฒ„์˜ ๋žœ๋ค ํ•œ ํฌํŠธ(1024~65535)์— ์ ‘์†ํ•˜๋Š” ๋ฐฉ์‹"์„ ๋งํ•œ๋‹ค. 1. ํด๋ผ์ด์–ธํŠธ๋Š” ์„œ๋ฒ„์˜ ์ œ์–ด ์ฑ„๋„์ธ 21๋ฒˆ ํฌํŠธ๋กœ ์ ‘์†์„ ํ•˜๊ณ  "PASV" ํ˜น์€ "EPSV"๋ฅผ ๋ณด๋‚ธ๋‹ค. ์ด๋Š” ์•ž์œผ๋กœ ์ˆ˜๋™ ๋ชจ๋“œ(Passive Mode)๋ฅผ ์ง„ํ–‰ํ•จ์„ ์•Œ๋ฆฌ๋Š” ์˜๋ฏธ 2. ์„œ๋ฒ„๊ฐ€ ์ž์‹ ์ด ์—ด์–ด๋‘” ๋ฐ์ดํ„ฐ ์ฑ„๋„์ธ ๋žœ๋คํ•œ ํฌํŠธ(1024~65535) ๋ฒˆํ˜ธ๋ฅผ ํด๋ผ์ด์–ธํŠธ์—๊ฒŒ ์•Œ๋ ค์ฃผ๊ณ  ๋ฐ์ดํ„ฐ๋ฅผ ์„œ๋กœ ์ฃผ๊ณ ๋ฐ›๊ฒŒ ๋œ๋‹ค. PASV์™€ EPSV ์ฐจ์ด PASV๋Š” IPv4 ํ”„๋กœํ† ์ฝœ๋งŒ ์ง€์›ํ•˜๋ฉฐ ํด๋ผ์ด์–ธํŠธ์—๊ฒŒ ๋ฐ์ดํ„ฐ ์ฑ„๋„ ํฌํŠธ๋ฅผ ์•Œ๋ฆฌ๊ฒŒ ๋  ๋•Œ ์ž์‹ ์˜ ์•„์ดํ”ผ๋ฅผ ์•Œ๋ฆฌ๊ฒŒ ๋˜๋Š” ๋“ฑ ๋ณด์•ˆ์„ฑ์ด ๋–จ์–ด์ง„๋‹ค.. 2023. 10. 12.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - ํฌํŠธ ์Šค์บ”(port scan) with Wireshark, nmap ๊ฐœ์š” ํฌํŠธ ์Šค์บ”(port scan)์€ ์šด์˜ ์ค‘์ธ ์„œ๋ฒ„์—์„œ ์—ด๋ ค ์žˆ๋Š” TCP/UDP ํฌํŠธ๋ฅผ ๊ฒ€์ƒ‰ํ•˜๋Š” ๊ฒƒ์„ ์˜๋ฏธํ•œ๋‹ค. ์‹ค์Šต ์‚ฌ์ „ ์ค€๋น„ Windows ํ™˜๊ฒฝ์— ์™€์ด์–ด์ƒคํฌ์™€ ํŒŒ์ด์ฌ์„ ์ค€๋น„ํ•œ๋‹ค. ํฌํŠธ ์Šค์บ๋‹ ๋„๊ตฌ์ธ nmap์ด ์„ค์น˜๋ผ ์žˆ์–ด์•ผ ํ•œ๋‹ค. ์™€์ด์–ด์ƒคํฌ ์„ธํŒ… ์™€์ด์–ด์ƒคํฌ๋ฅผ ์‹คํ–‰์‹œํ‚ค๊ณ  "Adapter for loopback traffic capture"๋ฅผ ๋ˆŒ๋Ÿฌ ๋กœ์ปฌ ๋‚ด์—์„œ ์ผ์–ด๋‚˜๋Š” ํŠธ๋ž˜ํ”ฝ๋“ค์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•œ๋‹ค. ๋‹ค์Œ ์•„๋ž˜์— ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์ž‘์„ฑํ•ด ๊ฐ๊ฐ TCP, UDP ์„œ๋ฒ„๋ฅผ ์—ด์–ด์ค€๋‹ค. tcp_server.py import socket def start_tcp_server(host, port): server_socket = socket.socket(socket.AF_INET, socket.SOCK_STREAM) server_s.. 2023. 6. 21.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - ๋ฌด์„  ๋„คํŠธ์›Œํฌ ๊ด€๋ จ CheatSheet https://github.com/V0lk3n/WirelessPentesting-CheatSheet GitHub - V0lk3n/WirelessPentesting-CheatSheet: This repository contain a CheatSheet for OSWP & WiFi Cracking.This repository contain a CheatSheet for OSWP & WiFi Cracking. - GitHub - V0lk3n/WirelessPentesting-CheatSheet: This repository contain a CheatSheet for OSWP & WiFi Cracking.github.com 2023. 6. 14.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - ์ธก๋ฉด ์ด๋™(Lateral Movement) ์ธก๋ฉด ์ด๋™(Lateral Movement)์€ ๊ณต๊ฒฉ์ž๊ฐ€ ์ฒ˜์Œ์— ๋„คํŠธ์›Œํฌ ๋ฐฉ์–ด ์ฒด๊ณ„๋ฅผ ์นจํˆฌํ•œ ํ›„ ์ถ”๊ฐ€ ์ž์‚ฐ์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉํ•˜๋Š” ์ผ๋ จ์˜ ๊ธฐ๋ฒ•์ž…๋‹ˆ๋‹ค. ์‚ฌ์ด๋ฒ„ ๋ฒ”์ฃ„์ž๋“ค์€ ๋ฐ์ดํ„ฐ์„ผํ„ฐ๋‚˜ IT ํ™˜๊ฒฝ์— ์ฒ˜์Œ ์ ‘์†ํ•˜์—ฌ ๋“ค์–ด์˜จ ํ›„ ์ค‘์š”ํ•œ ๋ฐ์ดํ„ฐ, ์ง€์‹ ์žฌ์‚ฐ ๋ฐ ๊ธฐํƒ€ ๊ณ ๊ฐ€์น˜ ์ž์‚ฐ์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•ด ํƒˆ์ทจํ•œ ๋กœ๊ทธ์ธ ์ธ์ฆ์ •๋ณด(์ธ์ฆ์ •๋ณด ๋„์šฉ ๋˜๋Š” ํ”ผ์‹ฑ ๊ณต๊ฒฉ์„ ํ†ตํ•ด ์–ป์€)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์‹œ์Šคํ…œ ์•ˆ์œผ๋กœ ๋ณด๋‹ค ๊นŠ์ด ์ด๋™ํ•ฉ๋‹ˆ๋‹ค. ์ถœ์ฒ˜: https://www.akamai.com/ko/our-thinking/zero-trust/lateral-movement ์ธก๋ฉด ์ด๋™ ๋ณด์•ˆ์ด๋ž€ ๋ฌด์—‡์ธ๊ฐ€์š”? | Akamai ์ธก๋ฉด ์ด๋™์€ ๊ณต๊ฒฉ์ž๊ฐ€ ์ฒ˜์Œ์— ๋„คํŠธ์›Œํฌ ๋ฐฉ์–ด ์ฒด๊ณ„๋ฅผ ์นจํˆฌํ•œ ํ›„ ์ถ”๊ฐ€ ์ž์‚ฐ์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉํ•˜๋Š” ์ผ๋ จ์˜ ๊ธฐ๋ฒ•์ž…๋‹ˆ๋‹ค. www.akamai.com 2023. 5. 14.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - FTP ์ ‘๊ทผ ์ œ์–ด ์„ค์ •(/etc/ftpusers) ๋ณด์•ˆ์— ์ทจ์•ฝํ•œ FTP๋Š” Bounce Attack, Anonymous FTP ๊ณต๊ฒฉ ๋“ฑ์— ์œ„ํ—˜ํ•จ์œผ๋กœ /etc/ftpusers์— root๋‚˜ daemon ๊ฐ™์€ ์ค‘์š” ๊ณ„์ •์€ FTP ์ง์ ‘ ์ ‘์†์— ์ œํ•œ์„ ํ•˜๋Š” ๊ฒƒ์ด ํ•„์š”ํ•˜๋‹ค. /etc/ftpusers # /etc/ftpusers: list of users disallowed FTP access. See ftpusers(5). root daemon bin sys sync games man lp mail news uucp nobody ์ ‘๊ทผ์„ ์ œํ•œ์‹œํ‚ฌ ์‚ฌ์šฉ์ž ์ด๋ฆ„์„ ์„ค์ • ํŒŒ์ผ์—๋‹ค ์ ์–ด์ค€๋‹ค. 2023. 4. 17.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - Mullvad VPN ํฌํŠธํฌ์›Œ๋”ฉ์œผ๋กœ ์›น ์„œ๋ฒ„ ์™ธ๋ถ€์—์„œ ์ ‘์† Mullvad VPN ์‚ฌ์ดํŠธ: ๊ณ„์ • > ์žฅ์น˜ ํƒญ์—์„œ ๋‚ด ์žฅ์น˜ ํ™•์ธ ์ฃผ์†Œ: https://mullvad.net/ko/account/#/devices ๋‚ด ์žฅ์น˜์—์„œ "ํฌํŠธ ์ถ”๊ฐ€" ํด๋ฆญ ํฌํŠธํฌ์›Œ๋”ฉ ์„ค์ • ๋ฐฐ์ •๋œ ํฌํŠธ ๋ฒˆํ˜ธ ํ™•์ธ ๋‚˜๋ผ-๋„์‹œ-ํฌํŠธ๋ฒˆํ˜ธ ํ˜•์‹์ด๋ฉฐ ๋’ค์— ์ˆซ์ž ๋ฒˆํ˜ธ๊ฐ€ ์ง€์ •๋ฐ›์€ ๋‚ด ํฌํŠธ ๋ฒˆํ˜ธ์ด๋‹ค. Mullvad VPN ํ”„๋กœ๊ทธ๋žจ์—์„œ ํ†ฑ๋‹ˆ๋ฐ”ํ€ด(์„ค์ •) ํด๋ฆญ "VPN ์„ค์ •" ํด๋ฆญ ํ„ฐ๋„ ํ”„๋กœํ† ์ฝœ ํ•ญ๋ชฉ์—์„œ "OpenVPN"์„ ์„ ํƒ ๋ฐ˜๋“œ์‹œ VPN ์„œ๋ฒ„์˜ ์—ฐ๊ฒฐ๋œ ์œ„์น˜๊ฐ€ ํฌํŠธํฌ์›Œ๋”ฉ ํŽ˜์ด์ง€์—์„œ ์„ค์ •ํ•œ ์œ„์น˜๋ž‘ ์ผ์น˜ํ•˜๋Š”์ง€ ํ™•์ธ Mullvad VPN ์‚ฌ์ดํŠธ์—์„œ ํฌํŠธ ์ ‘์† ํ™•์ธํ•˜๊ธฐ ์ฃผ์†Œ: https://mullvad.net/ko/check ์ž์‹ ์˜ IPv4 ์ฃผ์†Œ๋ฅผ ์šฐ์„  ํ™•์ธ ๋ฐ”๋กœ ํ•˜๋‹จ์— "ํฌํŠธ ํ™•์ธ" ํƒญ์œผ๋กœ ๋“ค์–ด๊ฐ€ ๋ฐฉ๊ธˆ ์ „์— ํ™•์ธํ•œ ํฌ.. 2023. 3. 19.
728x90
๋ฐ˜์‘ํ˜•