๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
728x90

์ „์ฒด ๊ธ€720

๋ฆฌ๋ˆ…์Šค - ssh ์—ฐ๊ฒฐ์‹œ tor socks5 ๊ฒฝ์œ ํ•˜๊ธฐ ํ•„์š” ํŒจํ‚ค์ง€ ์„ค์น˜ apt install tor apt install connect # nc(netcat)์ด ์„ค์น˜๋˜์–ด ์žˆ๋‹ค๋ฉด ๋ฌด์‹œ ์„ค์น˜ ํ›„์—๋Š” tor๋ฅผ ์‹คํ–‰์‹œ์ผœ์ค€๋‹ค. ์‚ฌ์šฉ ๋ช…๋ น์–ด connect ProxyCommand ์‚ฌ์šฉ ๋ฐฉ๋ฒ• ssh -o "ProxyCommand connect -5 -S localhost:9050 %h %p" user@123.123.123.123 nc ProxyCommand ์‚ฌ์šฉ ๋ฐฉ๋ฒ• ssh -o ProxyCommand="nc -x localhost:9050 %h %p" user@123.123.123.123 ํ”„๋ก์‹œ ์„ฑ๊ณต ํ™•์ธ ๋ช…๋ น์–ด Windows netstat -n | findstr 22 Linux/macOS who am i ์œ„์˜ ๋ช…๋ น์–ด ์‹คํ–‰์‹œ์— ๋‚ด ์ ‘์† ์•„์ดํ”ผ๊ฐ€ tor IP ์ฃผ์†Œ๋กœ ๋œฌ๋‹ค.. 2022. 8. 1.
๋ฆฌ๋ˆ…์Šค - ssh ๋™์ž‘ ์›๋ฆฌ ๋””ํ”ผ-ํ—ฌ๋จผ ํ‚ค ๊ตํ™˜(Diffie–Hellman key exchange) ์•”ํ˜ธ ํ‚ค๋ฅผ ๊ตํ™˜ํ•˜๋Š” ํ•˜๋‚˜์˜ ๋ฐฉ๋ฒ•์œผ๋กœ, ๋‘ ์‚ฌ๋žŒ์ด ์•”ํ˜ธํ™”๋˜์ง€ ์•Š์€ ํ†ต์‹ ๋ง์„ ํ†ตํ•ด ๊ณตํ†ต์˜ ๋น„๋ฐ€ ํ‚ค๋ฅผ ๊ณต์œ ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•œ๋‹ค. ์„œ๋ฒ„ ์ธ์ฆ 1. ์„œ๋ฒ„์— ์ƒ์„ฑ๋œ ๊ณต๊ฐœํ‚ค๋ฅผ ํด๋ผ์ด์–ธํŠธ์˜ know_host ํŒŒ์ผ์— ์ €์žฅ 2. ํด๋ผ์ด์–ธํŠธ๊ฐ€ ๋‚œ์ˆ˜ ๊ฐ’์„ ์ƒ์„ฑํ•ด ๋‚œ์ˆ˜ ๊ฐ’์˜ ํ•ด์‹œ๊ฐ’์„ ์ €์žฅ ํ›„ ๋‚œ์ˆ˜ ๊ฐ’์„ ์„œ๋ฒ„์—๊ฒŒ ๊ณต๊ฐœํ‚ค๋กœ ์•”ํ˜ธํ™”ํ•ด ์ด๋ฅผ ์ „๋‹ฌ 3. ์„œ๋ฒ„๊ฐ€ ์•”ํ˜ธํ™”ํ•œ ๋‚œ์ˆ˜ ๊ฐ’์„ ๊ฐœ์ธํ‚ค๋กœ ๋ณตํ˜ธํ™”, ์ด ๋‚œ์ˆ˜์˜ ํ•ด์‹œ๊ฐ’์„ ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์ „๋‹ฌ๋ฐ›์•„ ์„œ๋ฒ„๊ฐ€ ์ •์ƒ์ ์ธ ์„œ๋ฒ„์ธ์ง€๋ฅผ ๊ฒ€์ฆ ์‚ฌ์šฉ์ž ์ธ์ฆ 1. ์ด๋ฒˆ์—” ํด๋ผ์ด์–ธํŠธ๊ฐ€ ๋น„๋Œ€์นญํ‚ค(๊ณต๊ฐœํ‚ค, ๋น„๊ณต๊ฐœ ํ‚ค)๋ฅผ ์ƒ์„ฑํ•ด ์„œ๋ฒ„์—๊ฒŒ ๊ณต๊ฐœํ‚ค(id_rsa.pub) ์ „๋‹ฌ 2. ์ „๋‹ฌ๋ฐ›์€ ๊ณต๊ฐœํ‚ค๋Š” ์„œ๋ฒ„์˜ authorized_keys์— ๋”ฐ๋กœ ๋ณด๊ด€ 3. ์„œ๋ฒ„.. 2022. 8. 1.
์ •๋ณด์ฒ˜๋ฆฌ๊ธฐ์‚ฌ - ์„œ๋ธŒ๋„ท ๋งˆ์Šคํฌ ์„œ๋ธŒ ๋„คํŒ…(Subnetting)๊ณผ ์„œ๋ธŒ๋„ท ๋งˆ์Šคํฌ ์„œ๋ธŒ ๋„คํŒ…์ด๋ž€ ํ• ๋‹น๋œ ๋„คํŠธ์›Œํฌ ์ฃผ์†Œ๋ฅผ ๋‹ค์‹œ ์—ฌ๋Ÿฌ ๊ฐœ์˜ ์ž‘์€ ๋„คํŠธ์›Œํฌ๋กœ ๋‚˜๋ˆ„์–ด ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์„ ๋งํ•œ๋‹ค. 4๋ฐ”์ดํŠธ์˜ IP ์ฃผ์†Œ ์ค‘ ๋„คํŠธ์›Œํฌ ์ฃผ์†Œ์™€ ํ˜ธ์ŠคํŠธ ์ฃผ์†Œ๋ฅผ ๊ตฌ๋ถ„ํ•˜๊ธฐ ์œ„ํ•œ ๋น„ํŠธ๋ฅผ ์„œ๋ธŒ๋„ท ๋งˆ์Šคํฌ๋ผ๊ณ  ํ•˜๋ฉฐ, ์ด๋ฅผ ๋ณ€๊ฒฝํ•˜์—ฌ ๋„คํŠธ์›Œํฌ ์ฃผ์†Œ๋ฅผ ์—ฌ๋Ÿฌ ๊ฐœ๋กœ ๋ถ„ํ• ํ•˜์—ฌ ์‚ฌ์šฉํ•œ๋‹ค. ๊ธฐ์กด์˜ ๋น„ํšจ์œจ์ ์ธ ํ• ๋‹น ๋ฐฉ์‹์„ ํ•ด๊ฒฐํ•˜๊ธฐ ์œ„ํ•ด์„œ ๋“ฑ์žฅํ–ˆ๋‹ค. (๋„คํŠธ์›Œํฌ ์˜์—ญ๊ณผ ํ˜ธ์ŠคํŠธ ์ฃผ์†Œ๋ฅผ ์ ์ ˆํ•˜๊ฒŒ ๋‚˜๋ˆ„์–ด IP ์ฃผ์†Œ๋ฅผ ์•„๋‚„ ์ˆ˜๊ฐ€ ์žˆ์Œ) ์„œ๋ธŒ๋„ท ๋งˆ์Šคํฌ ์„œ๋ธŒ๋„ท ๋งˆ์Šคํฌ์—์„œ 1์€ ๋„คํŠธ์›Œํฌ ์ฃผ์†Œ๋ฅผ ๋œปํ•˜๊ณ  0์€ ํ˜ธ์ŠคํŠธ ์ฃผ์†Œ๋ฅผ ์˜๋ฏธํ•œ๋‹ค. ํด๋ž˜์Šค ๋ณ„๋กœ ์„œ๋ธŒ๋„ท ๋งˆ์Šคํฌ ํ‘œ๊ธฐ๋ฒ•์ด ๋‹ฌ๋ผ์ง„๋‹ค. ํด๋ž˜์Šค ๋ฒ”์œ„ ํ‘œ๊ธฐ๋ฒ• A ํด๋ž˜์Šค 11111111.00000000.00000000.00000000 0.0.0.0/8 ํ˜น์€ 255.0.. 2022. 7. 31.
์ •๋ณด์ฒ˜๋ฆฌ๊ธฐ์‚ฌ - IP ์ฃผ์†Œ ํด๋ž˜์Šค(A Class, B Class, C Class, D Class, E Class) IP ์ฃผ์†Œ(IPv4) IP ์ฃผ์†Œ๋Š” ์ธํ„ฐ๋„ท์— ์—ฐ๊ฒฐ๋œ ๋ชจ๋“  ์ปดํ“จํ„ฐ ์ž์›์„ ๊ตฌ๋ถ„ํ•˜๊ธฐ ์œ„ํ•œ ๊ณ ์œ ํ•œ ์ฃผ์†Œ์ด๋‹ค. 8๋น„ํŠธ์”ฉ 4๋ถ€๋ถ„, ์ด 32๋น„ํŠธ๋กœ ๊ตฌ์„ฑ๋˜์–ด ์žˆ๋‹ค. ์ฃผ์†Œ๋Š” xxx.xxx.xxx.xxx๋ผ๋Š” ์‹์˜ ์˜ฅํ…Ÿ(Octet) ํ‘œ๊ธฐ๋ฅผ ์‚ฌ์šฉํ•ด ํ‘œํ˜„๋œ๋‹ค. ์˜ฅํ…Ÿ์€ 8๊ฐœ์˜ ๋น„ํŠธ(0~255)๋ฅผ ๋งํ•œ๋‹ค. ์•ฝ 40์–ต๊ฐœ(255^4)์˜ ์ฃผ์†Œ๋ฅผ ์“ธ ์ˆ˜ ์žˆ์ง€๋งŒ ์ถฉ๋ถ„ํ•˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์— 128๋น„ํŠธ ๋ฐฉ์‹์„ ์‚ฌ์šฉํ•˜๋Š” IPv16์„ ์ถ”์ง„ํ•˜๊ณ  ์žˆ๋‹ค. IP ์ฃผ์†Œ ํด๋ž˜์Šค A Class ๊ตญ๊ฐ€๋‚˜ ๋Œ€ํ˜• ํ†ต์‹ ๋ง์— ์‚ฌ์šฉ(0~127๋กœ ์‹œ์ž‘) *์‹ค์ œ๋Š” 1~126์œผ๋กœ ์‚ฌ์šฉํ•จ B Class ์ค‘๋Œ€ํ˜• ํ†ต์‹ ๋ง์— ์‚ฌ์šฉ(128~191๋กœ ์‹œ์ž‘) C Class ์†Œ๊ทœ๋ชจ ํ†ต์‹ ๋ง์— ์‚ฌ์šฉ(192~223์œผ๋กœ ์‹œ์ž‘) D Class ๋ฉ€ํ‹ฐ์บ์ŠคํŠธ์šฉ์œผ๋กœ ์‚ฌ์šฉ(224~239๋กœ ์‹œ์ž‘) E Class ์‹คํ—˜.. 2022. 7. 31.
๋ฆฌ๋ˆ…์Šค - ํŒŒ์ผ์˜ ๋‚ด์šฉ ์ง€์šฐ๊ธฐ cat /dev/null > file.txt 2022. 7. 30.
CSS - ์ธ๋ผ์ธ ์ฝ”๋“œ ๋ธ”๋Ÿญ ๋Œ€์ถฉ ์ด๋Ÿฐ๊ฒƒ์ž…๋‹ˆ๋‹ค. /* ์ธ๋ผ์ธ ์ฝ”๋“œ ๋ธ”๋Ÿญ */ code { padding: 0.25rem; background-color: #F1F1F1; border-radius: 5px; box-shadow: 0.25px 0.25px 10px rgb(156, 156, 156); font-family: "Consolas", "Sans Mono", "Courier", "monospace"; font-size: 1.0rem; } ์ฐธ๊ณ : https://wordbe.tistory.com/entry/%EC%9D%B8%EB%9D%BC%EC%9D%B8-%EC%BD%94%EB%93%9C%EB%B8%94%EB%9F%AD-%EC%BD%94%EB%93%9C-%EA%B0%95%EC%A1%B0-%EC%BD%94%EB%93%9C-%EB%B0.. 2022. 7. 30.
์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ - for in๊ณผ for of ์ฐจ์ด์  ์ƒ๊น€์ƒˆ var arr = [2, 5, 7, 9, 12]; // for in for(const item in arr){ console.log(item); } // for of for(const item of arr){ console.log(item) } ์ƒ๊น€์ƒˆ๋Š” ์ด๋ ‡๊ฒŒ ์ƒ๊ฒผ์Šต๋‹ˆ๋‹ค. ๋‘˜ ๋‹ค ๋„ˆ๋ฌด ๋˜‘๊ฐ™์ด ์ƒ๊ฒจ์„œ ๊ฐ€๋” ์‚ฌ์šฉํ•˜๋ ค๊ณ  ํ•  ๋•Œ๋งˆ๋‹ค ํ˜ผ๋ž€์ด ์ƒ๊น๋‹ˆ๋‹ค. ์ง€๊ธˆ๋ถ€ํ„ฐ ์ด๋Ÿฐ ์‹์œผ๋กœ ์™ธ์šฐ์‹œ๋ฉด ๋ฉ๋‹ˆ๋‹ค. for in์€ ๊ฐ์ฒด(ํ‚ค ๊ฐ’) ์ˆœํ™˜ for of์€ ๋ฐฐ์—ด ์ˆœํ™˜ ์ฐธ๊ณ ๋กœ ์ƒ๋‹จ ์ฝ”๋“œ์˜ ์‹คํ–‰ ๊ฒฐ๊ณผ๋Š” ์ด๋ ‡์Šต๋‹ˆ๋‹ค. // for in 0 1 2 3 4 // for of 2 5 7 9 12 for of๋Š” ๋ฐฐ์—ด์˜ ๊ฐ’์„ ์ˆœ์„œ๋Œ€๋กœ ์ž˜ ์ถœ๋ ฅํ•˜๋Š” ๋ฐ˜๋ฉด์— for in์€ 0, 1, 2, 3 ๊ฐ™์€ ์ˆซ์ž์˜ ์ˆœํ™˜์„ ๋ฐ˜ํ™˜ํ•ฉ๋‹ˆ๋‹ค. ๋ฐ”๋กœ ๋ˆˆ์น˜์ฑˆ ์‚ฌ๋žŒ๋„ ์žˆ.. 2022. 7. 30.
์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ - map์™€ forEach์˜ ์ฐจ์ด์  Array.prototype.map() map() ๋ฉ”์„œ๋“œ๋Š” ๋ฐฐ์—ด ๋‚ด์˜ ๋ชจ๋“  ์š”์†Œ ๊ฐ๊ฐ์— ๋Œ€ํ•˜์—ฌ ์ฃผ์–ด์ง„ ํ•จ์ˆ˜๋ฅผ ํ˜ธ์ถœํ•œ ๊ฒฐ๊ณผ๋ฅผ ๋ชจ์•„ ์ƒˆ๋กœ์šด ๋ฐฐ์—ด์„ ๋ฐ˜ํ™˜ํ•ฉ๋‹ˆ๋‹ค. ์‹œ๋„ํ•ด๋ณด๊ธฐ Array.prototype.forEach() forEach() ๋ฉ”์„œ๋“œ๋Š” ์ฃผ์–ด์ง„ ํ•จ์ˆ˜๋ฅผ ๋ฐฐ์—ด ์š”์†Œ ๊ฐ๊ฐ์— ๋Œ€ํ•ด ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค. ์‹œ๋„ํ•ด๋ณด๊ธฐ map ๋ฉ”์„œ๋“œ์™€ forEach ๋ฉ”์„œ๋“œ์˜ ์ฐจ์ด์  ํฐ ์ฐจ์ด์ ์€ return ๊ฐ’์„ ๋ฐ˜ํ™˜ํ•˜๋ƒ ์•ˆ ํ•˜๋ƒ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. const map1 = array1.map(x => x * 2); console.log(map1); // [2, 8, 18, 32] ์šฐ์„  map ๊ฐ™์€ ๊ฒฝ์šฐ๋Š” ์ฝœ๋ฐฑ ํ•จ์ˆ˜์˜ ์‹คํ–‰ ๊ฒฐ๊ณผ๋ฅผ return์„ ๊ทธ ๊ฒฐ๊ณผ๋“ค์„ ๋ฐฐ์—ด ํ˜•ํƒœ๋กœ ๋ณ€์ˆ˜์— ์ €์žฅํ•ฉ๋‹ˆ๋‹ค. array1.forEach(element => console.l.. 2022. 7. 30.
macOS - Metasploit Framework ์„ค์น˜ ๋ฉ”ํƒ€์Šคํ”Œ๋กœ์ž‡ ํ”„๋ ˆ์ž„์›Œํฌ ์„ค์น˜ http://osx.metasploit.com/ Directory Tree osx.metasploit.com ์œ„์˜ ๋งํฌ๋กœ ๊ฐ€์„œ "metasploitframework-latest.pkg"๋ฅผ ๋ฐ›์•„์„œ ์„ค์น˜ ํ™˜๊ฒฝ ๋ณ€์ˆ˜ ์ถ”๊ฐ€ nano ~/.zshrc ๋งจ ์•„๋ž˜์— ์•„๋ž˜์˜ ํ™˜๊ฒฝ ๋ณ€์ˆ˜ ์ž‘์„ฑ export PATH="$PATH:/opt/metasploit-framework/bin/ ๊ทธ๋ฆฌ๊ณ  ํ„ฐ๋ฏธ๋„์„ ๊ป๋‹ค ์ผœ์„œ msfconsole๋ฅผ ์‹คํ–‰์‹œ์ผœ์„œ ์ž‘๋™์ด ๋˜๋ฉด ์„ค์น˜ ์™„๋ฃŒ. ์ฐธ๊ณ : https://scytalezz.tistory.com/94 Mac OS์— Metasploit Framework ์„ค์น˜ ๋ฐฉ๋ฒ• msfvenom์€ Msfpayload์™€ Msfencode๊ฐ€ ๊ฒฐํ•ฉ๋œ ๋„๊ตฌ์ด๋‹ค. -h ์˜ต์…˜์„ ํ†ตํ•ด ์„ธ๋ถ€ ์˜ต์…˜ .. 2022. 7. 29.
ํŒŒ์ด์ฌ - ์นด์นด์˜คํ†ก smtp(๋ฉ”์ผ ์ „์†ก) ๊ธฐ๋Šฅ ์‚ฌ์šฉํ•˜๊ธฐ ์ž์‹ ์˜ ์›น ์นด์นด์˜ค ๋ฉ”์ผ ํŽ˜์ด์ง€๋กœ ๊ฐ€์…”์„œ ํ™˜๊ฒฝ์„ค์ •์—์„œ "IMAP / SMTP ์‚ฌ์šฉ"์„ ์‚ฌ์šฉํ•จ์œผ๋กœ ์„ค์ • ํ•ด์ค๋‹ˆ๋‹ค. # -*- coding:utf-8 -*- import smtplib from email.mime.text import MIMEText def sendMail(me, you, msg): smtp = smtplib.SMTP_SSL('smtp.kakao.com', 465) smtp.login(me, '์ž์‹ ์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ') msg = MIMEText(msg) msg['Subject'] = 'TEST' msg['From'] = me msg['To'] = you smtp.sendmail(me, you, msg.as_string()) smtp.quit() if __name__ == "__main__": sen.. 2022. 7. 29.
CCTV์˜ rtsp ์ฃผ์†Œ๋ฅผ ๋ชจ๋ฅด๋Š” ๊ฒฝ์šฐ ์ฃผ์†Œ๋ฅผ ์ฐพ๋Š” ๋ฐฉ๋ฒ• ๋‚ด CCTV์—๋Š” rtsp ์ŠคํŠธ๋ฆฌ๋ฐ ๊ธฐ๋Šฅ์ด ์žˆ๋Š” ๊ฒƒ์€ ์•Œ๊ฒ ์ง€๋งŒ ๊ทธ ์ฃผ์†Œ๋ฅผ ์ž˜ ๋ชจ๋ฅด๋Š” ๊ฒฝ์šฐ(๊ธฐ๊ธฐ๋งˆ๋‹ค ์ฃผ์†Œ๊ฐ€ ๋‹ค๋ฅด๋‹ค 192.168.0.5/{???})์— ์ฃผ์†Œ๋ฅผ ์ฐพ์•„๋‚ด๋Š” ํ•ด๊ฒฐ ๋ฐฉ๋ฒ•์œผ๋กœ CCTV์˜ onvif ๊ธฐ๋Šฅ์„ ์ด์šฉํ•˜๋ฉด ์‰ฝ๊ฒŒ ํ•ด๊ฒฐ์ด ๊ฐ€๋Šฅํ•˜๋‹ค. onvif๋ž€? onvif๋Š” Open Network Video Interface Forum์˜ ์•ฝ์ž๋กœ ์ด๋Ÿฐ CCTV ๊ฐ™์€ ๋น„๋””์˜ค ์ถœ๋ ฅ ์žฅ์น˜์— ๋Œ€ํ•œ ๋„คํŠธ์›Œํฌ๋ฅผ ํ‘œ์ค€์œผ๋กœ ์ง€์ •ํ•˜๋Š” ํฌ๋Ÿผ์ด๋ผ๊ณ  ํ•œ๋‹ค. ์ด๋Ÿฐ ๋‹จ์ฒด ๋•๋ถ„์— ๋งŽ์€ ๊ธฐ์—…๋“ค์˜ cctv ์žฅ์น˜๋“ค์„ ํ•˜๋‚˜๋กœ ํ†ตํ•ฉํ•˜์—ฌ ๋น„๋””์˜ค ์†ก์ถœ์ด ๊ฐ€๋Šฅํ•œ ๊ฒƒ์ด๋‹ค. ์•„๋ฌดํŠผ rtsp์˜ ์ฃผ์†Œ๋ฅผ ์ฐพ๊ณ  ์‹ถ์„ ๊ฒฝ์šฐ ๋‹ค๋ฅธ ์•ฑ์„ ์ด์šฉํ•ด์„œ ์ฐพ๋Š” ๋ฐฉ๋ฒ•์ด ์žˆ๋Š”๋ฐ 1. ๊ตฌ๊ธ€ ํ”Œ๋ ˆ์ด์Šคํ† ์–ด์— Onvier๋ผ๋Š” ์•ฑ์„ ๊ฒ€์ƒ‰ ๋ฐ ์„ค์น˜ 2. ์•ฑ์—๋‹ค ์ž์‹ ์˜ cctv๋ฅผ ์šฐ์„  ์ €์žฅ ์‹œ์ผœ์คŒ.. 2022. 7. 28.
Scapy - ํŒŒ์ด์ฌ Scapy๋กœ ์•„์ดํ”ผ ์Šคํ‘ธํ•‘ from scapy.all import * A = "192.168.1.254" # spoofed source IP address B = "192.168.1.105" # destination IP address C = RandShort() # source port D = 80 # destination port payload = "yada yada yada" # packet payload while True: spoofed_packet = IP(src=A, dst=B) / TCP(sport=C, dport=D) / payload send(spoofed_packet) ์ถœ์ฒ˜: https://stackoverflow.com/questions/38956401/ip-spoofing-in-python-3 IP Spoo.. 2022. 7. 27.
728x90