๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
728x90

์ „์ฒด ๊ธ€720

๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - Snort ์œˆ๋„์šฐ ์„ค์น˜ Snort ์„ค์น˜ ์ฐธ๊ณ : https://m.blog.naver.com/limhojin123/221779047954 Snort ์œˆ๋„์šฐ๋ฒ„์ „ ์„ค์น˜์™€ ์‚ฌ์šฉํ•˜๊ธฐ 2ํƒ„(์ •๋ณด๋ณด์•ˆ๊ธฐ์‚ฌ ํ•„๊ธฐ, ์ •๋ณด๋ณด์•ˆ์‚ฐ์—…๊ธฐ์‚ฌ) ์ €๋ฒˆ #Snort 1ํƒ„์€ ๋ฆฌ๋ˆ…์Šค ๋ฒ„์ „์„ ์„ค์น˜ํ•ด์„œ ์‚ฌ์šฉํ–ˆ๋‹ค. ์ด๋ฒˆ์—๋Š” ์œˆ๋„์šฐ ๋ฒ„์ „ Snort๋ฅผ ์„ค์น˜ํ•˜๊ณ  ์‚ฌ์šฉ ํ•ด๋ณด... blog.naver.com https://www.snort.org/downloads# Snort Rules and IDS Software Download Security Onion is a Linux distro for intrusion detection, network security monitoring, and log management. It's based on Ubuntu and contai.. 2023. 11. 17.
์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ - XPATH ๋ฌธ๋ฒ•์œผ๋กœ DOM ELEMENT ๊ฐ€์ ธ์˜ค๊ธฐ XPATH ๋ฌธ๋ฒ•์œผ๋กœ ๋‹จ์ผ ์š”์†Œ ๊ฐ€์ ธ์˜ค๊ธฐ function getElementByXpath(path){ return document.evaluate(path, document, null, XPathResult.FIRST_ORDERED_NODE_TYPE, null).singleNodeValue; } console.log( getElementByXpath("//html[1]/body[1]/div[1]")); XPATH ๋ฌธ๋ฒ•์œผ๋กœ ๋‹ค์ค‘ ์š”์†Œ ๊ฐ€์ ธ์˜ค๊ธฐ function getElementsByXPath(xpath, parent) { let results = []; let query = document.evaluate(xpath, parent || document, null, XPathResult.ORDERED_NODE.. 2023. 11. 12.
์‹œ์Šคํ…œ ๋ณด์•ˆ - SSH root ์›๊ฒฉ ์ ‘์† ์ฐจ๋‹จ ์ •์ฑ… ์„ค์ •(/etc/ssh/sshd_config) SSH root ์›๊ฒฉ ์ ‘์† ์ฐจ๋‹จ ์ •์ฑ… ์„ค์ •(/etc/ssh/sshd_config) ๊ธฐ์กด "PermitRootLogin yes"๋ฅผ "PermitRootLogin no"๋กœ ์ˆ˜์ •ํ•œ๋‹ค. # vim /etc/ssh/sshd_config # Authentication PermitRootLogin no ์„ค์ •์ด ์™„๋ฃŒํ•˜์˜€๋‹ค๋ฉด ์„œ๋น„์Šค๋ฅผ ์žฌ์‹œ์ž‘ํ•œ๋‹ค. service ssh restart ์ •์ฑ…์„ ์„ค์ •ํ•˜๊ธฐ ์ด์ „(PermitRootLogin yes) root@kali:~/Desktop# ssh root@localhost root@localhost's password: Linux kali 3.14-kali1-686-pae #1 SMP Debian 3.14.5-1kali1 (2014-06-07) i686 The programs inc.. 2023. 11. 10.
์‹œ์Šคํ…œ ๋ณด์•ˆ - ๋ฆฌ๋ˆ…์Šค ์ปค๋„ ASLR ๋ฉ”๋ชจ๋ฆฌ ๋ณดํ˜ธ ๊ธฐ๋ฒ• ์„ค์ •(randomize_va_space) ASLR(Address Space Layout Randomization)์ด๋ž€? ๋ฉ”๋ชจ๋ฆฌ ๊ณต๊ฒฉ์„ ๋ฐฉ์–ดํ•˜๊ธฐ ์œ„ํ•ด ์ฃผ์†Œ ๊ณต๊ฐ„ ๋ฐฐ์น˜๋ฅผ ๋‚œ์ˆ˜ ํ™”ํ•˜๋Š” ๊ธฐ๋ฒ•์œผ๋กœ ์‹คํ–‰ ์‹œ๋งˆ๋‹ค ๋ฉ”๋ชจ๋ฆฌ ์ฃผ์†Œ๋ฅผ ๋ณ€๊ฒฝ์‹œ์ผœ ์•…์„ฑ์ฝ”๋“œ์— ์˜ํ•œ ํŠน์ •์ฃผ์†Œ ํ˜ธ์ถœ์„ ๋ฐฉ์ง€ํ•œ๋‹ค. ๋ฆฌ๋ˆ…์Šค ASLR ์ ์šฉ (/proc/sys/kernel/randomize_va_space ์ˆ˜์ •) echo 0 > /proc/sys/kernel/randomize_va_space # ASLR ๋ฏธ์„ค์ • echo 1 > /proc/sys/kernel/randomize_va_space # ASLR ๋ถ€๋ถ„์„ค์ •(heap๋งŒ ๋ฏธ์„ค์ •) echo 2 > /proc/sys/kernel/randomize_va_space # ASLR ๋ชจ๋‘์„ค์ •(stack, heap, library ๋“ฑ) sysctl ๋ช…๋ น์–ด๋กœ ๋ฆฌ๋ˆ….. 2023. 11. 9.
๋ฆฌ๋ˆ…์Šค - ํŠน์ • ์‚ฌ์šฉ์ž sudo ๊ถŒํ•œ ์ถ”๊ฐ€ํ•˜๋Š” ๋ฐฉ๋ฒ•๋“ค(sudoers) ํŠน์ • ์‚ฌ์šฉ์ž์—๊ฒŒ sudo ๊ถŒํ•œ์„ ์ฃผ๋Š” ๋Œ€ํ‘œ์ ์ธ ๋ฐฉ๋ฒ•๋“ค 1. /etc/sudoers ์„ค์ • ํŒŒ์ผ ์ˆ˜์ • 2. sudo ๊ทธ๋ฃน์— ์‚ฌ์šฉ์ž ์ถ”๊ฐ€ ์‚ฌ์ „ ์ค€๋น„ - ์ƒˆ๋กœ์šด ์‚ฌ์šฉ์ž ๋งŒ๋“ค๊ธฐ janger@desktop:~$ sudo useradd -m dummy janger@desktop:~$ echo "dummy:dummy" | sudo chpasswd -m : ํ™ˆ ๋””๋ ‰ํ„ฐ๋ฆฌ ์ž๋™ ์ƒ์„ฑ janger@desktop:~$ cat /etc/passwd | grep dummy dummy:x:1001:1001::/home/dummy:/bin/sh ์ƒˆ๋กœ ์ƒ๊ธด ์œ ์ € ์ •๋ณด๋ฅผ ํ™•์ธ 1. /etc/sudoers ์„ค์ • ํŒŒ์ผ ์ˆ˜์ • sudoers ์„ค์ • ํŒŒ์ผ์„ ์ˆ˜์ •ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ์šฐ์„  ์“ฐ๊ธฐ ์˜ต์…˜์„ ์ถ”๊ฐ€ํ•ด์•ผ ํ•œ๋‹ค. ์•„๋ž˜๋Š” sudoers์˜ ๊ธฐ๋ณธ ์†์„ฑ ์ •๋ณด์ด.. 2023. 11. 9.
์œˆ๋„์šฐ - ์ด๋”๋„ท ๋„คํŠธ์›Œํฌ ์ธํ„ฐํŽ˜์ด์Šค ๊ป๋‹ค ์ผœ๊ธฐ ๋ฐฐ์น˜ ํŒŒ์ผ ์ด๋”๋„ท ๊ป๋‹ค์ผœ๊ธฐ.bat (๊ด€๋ฆฌ์ž ๊ถŒํ•œ ํ•„์š”) netsh interface set interface "์ด๋”๋„ท" admin=disable netsh interface set interface "์ด๋”๋„ท" admin=enable 2023. 11. 9.
์œˆ๋„์šฐ - ์ƒŒ๋“œ๋ฐ•์Šค ์„ค์น˜์™€ ์‹คํ–‰ ๋ฐ ์„ค์ • ํŒŒ์ผ๋กœ ์ปค์Šคํ„ฐ๋งˆ์ด์ง• (Windows Sandbox) Windows ์ƒŒ๋“œ๋ฐ•์Šค๋ž€? Windows ์ƒŒ๋“œ๋ฐ•์Šค๋Š” Windows 10๊ณผ 11์— ํฌํ•จ๋œ ๊ฐ€์ƒํ™” ๊ธฐ์ˆ ๋กœ, ์•ˆ์ „ํ•œ ํ™˜๊ฒฝ์—์„œ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ฉ๋‹ˆ๋‹ค. ์ƒŒ๋“œ๋ฐ•์Šค ๋‚ด์—์„œ ์‹คํ–‰๋˜๋Š” ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์€ ํ˜ธ์ŠคํŠธ ์‹œ์Šคํ…œ๊ณผ ๊ฒฉ๋ฆฌ๋˜์–ด ์žˆ์œผ๋ฏ€๋กœ, ์•…์„ฑ์ฝ”๋“œ๋‚˜ ๋ณด์•ˆ ์ทจ์•ฝ์ ์ด ์‹œ์Šคํ…œ์— ์˜ํ–ฅ์„ ๋ฏธ์น  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. Windows ์ƒŒ๋“œ๋ฐ•์Šค ์„ค์น˜ (์‹ค์Šต ํ™˜๊ฒฝ : Windows 10) ์ƒŒ๋“œ๋ฐ•์Šค ๊ธฐ๋Šฅ์„ ์ง€์› ๊ฐ€๋Šฅํ•œ Windows ๋ฒ„์ „๋“ค 1. Windows ๊ธฐ๋Šฅ ์ผœ๊ธฐ/๋„๊ธฐ ์ด๋™ 2. Windows ์ƒŒ๋“œ๋ฐ•์Šค ์ฒดํฌ ํ›„ ์‹œ์Šคํ…œ ์žฌ๋ถ€ํŒ… 3. Windows ์ƒŒ๋“œ๋ฐ•์Šค ์‹คํ–‰ ์‹คํ–‰ ์‹œ ๋ณ„๋„์˜ ์ฐฝ์œผ๋กœ ์ดˆ๊ธฐ ์ƒํƒœ์˜ Windows๊ฐ€ ์‹คํ–‰์ด ๋˜๊ณ  ๋งŒ์•ฝ ์ƒŒ๋“œ๋ฐ•์Šค๋ฅผ ์ข…๋ฃŒํ•˜๊ฒŒ ๋˜๋ฉด ๋ณ€๊ฒฝ ๋‚ด์šฉ์ด ๋ชจ๋‘ ์‚ฌ๋ผ์ง„๋‹ค. ํŒŒ์ผ๊ณผ ํ…์ŠคํŠธ๋Š” ํด๋ฆฝ๋ณด๋“œ์— ๋ณต์‚ฌ to ๋ถ™์—ฌ ๋„ฃ๊ธฐ .. 2023. 11. 6.
์•ˆ๋“œ๋กœ์ด๋“œ - ์นด๋ฉ”๋ผ, ์Œ์„ฑ ์ฐจ๋‹จํ•˜๊ธฐ ๋ฐ ๋ฌด์„  ๋””๋ฒ„๊น… ๋น ๋ฅธ ์„ค์ •(๋น ๋ฅธ ์„ค์ • ๊ฐœ๋ฐœ์ž ํƒ€์ผ) 1. ์„ค์ •์—์„œ "๊ฐœ๋ฐœ์ž ์˜ต์…˜" ํด๋ฆญ 2. ๊ฐœ๋ฐœ์ž ์˜ต์…˜์—์„œ "๋น ๋ฅธ ์„ค์ • ๊ฐœ๋ฐœ์ž ํƒ€์ผ" ํด๋ฆญ 3. ์›ํ•˜๋Š” ๊ธฐ๋Šฅ ํ™œ์„ฑํ™” ๋ฌด์„  ๋””๋ฒ„๊น… : ํƒ€์ผ์— ๋ฌด์„  ๋””๋ฒ„๊น…์„ ์ผœ๊ธฐ/๋„๊ธฐ๋ฅผ ์ถ”๊ฐ€ Sensors Off : ํƒ€์ผ์— ์นด๋ฉ”๋ผ, ๋งˆ์ดํฌ ์„ผ์„œ ๋“ฑ์„ ๋น„ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ํƒ€์ผ์„ ์ถ”๊ฐ€ 4. ์ถ”๊ฐ€๋œ ๋น ๋ฅธ ํƒ€์ผ ํ™•์ธ ์นด๋ฉ”๋ผ ๋ฐ ๋งˆ์ดํฌ ์ž‘๋™ ํ™•์ธํ•˜๊ธฐ ์นด๋ฉ”๋ผ ์•ฑ์„ ์‹คํ–‰ ์‹œ ๋ณด์•ˆ์ •์ฑ…์œผ๋กœ ์ธํ•ด ์ œ๋Œ€๋กœ ์ž‘๋™ํ•˜์ง€ ์•Š๊ณ  ๋ฐ”๋กœ ๊บผ์ง„๋‹ค. ๋…น์Œ๊ธฐ ์•ฑ์œผ๋กœ ๋…น์Œ์„ ์‹œ์ž‘ํ•˜๋ฉด ์ง„ํ–‰์€ ํ•˜์ง€๋งŒ ๋ชฉ์†Œ๋ฆฌ๊ฐ€ ์ œ๋Œ€๋กœ ๋…น์Œ์ด ๋˜์ง€ ์•Š๋Š”๋‹ค. 2023. 11. 3.
๋””์ง€ํ„ธ ํฌ๋ Œ์‹ - ํ…์ŠคํŠธ/ํ—ฅ์Šค ์—๋””ํ„ฐ (010 Editor) https://www.sweetscape.com/010editor/ 010 Editor - Pro Text/Hex Editor | Edit 250+ Formats | Fast & Powerful | Reverse Engineering 010 Editor: Pro Text Editor Edit text files, XML, HTML, Unicode and UTF-8 files, C/C++ source code, PHP, etc. Unlimited undo and powerful editing and scripting tools. Huge file support (50 GB+). Column mode editing. Analysis Tools - Drill into your Data A www.sweetsc.. 2023. 11. 3.
๋ฆฌ๋ˆ…์Šค - ์•„์ดํ”ผ ๋ณ€๊ฒฝํ•˜๋Š” ๋ฐฉ๋ฒ•(/etc/network/interfaces) ์˜ˆ์‹œ) ์‚ฌ์„ค ์•„์ดํ”ผ 192.168.57.10์„ 192.168.57.30์œผ๋กœ ๋ณ€๊ฒฝํ•˜๊ณ  ์‹ถ์„ ๊ฒฝ์šฐ ํŽธ์ง‘๊ธฐ(vi, nano)๋กœ /etc/network/interfaces ์—ด๊ธฐ nano /etc/network/interfaces ์ˆ˜์ • ์ „ /etc/network/interfaces # This file describes the network interfaces available on your system # and how to activate them. For more information, see interfaces(5). # The loopback network interface auto lo iface lo inet loopback # The primary network interface #allow-hot.. 2023. 10. 31.
์œˆ๋„์šฐ - RDP ์—ฐ๊ฒฐ ๊ธฐ๋ก ์‚ญ์ œํ•˜๊ธฐ(Clear RDP Connection History) Clear RDP Connection History.bat @echo off reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Default" /va /f reg delete "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" /f reg add "HKEY_CURRENT_USER\Software\Microsoft\Terminal Server Client\Servers" attrib -s -h %userprofile%\documents\Default.rdp del %userprofile%\documents\Default.rdp del /f /s /q /a .. 2023. 10. 30.
์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ - GET ํŒŒ๋ผ๋ฏธํ„ฐ ์ถ”์ถœํ•˜๊ธฐ let url = new URL("https://www.google.com/webhp?sourceid=chrome-instant&ion=1&espv=2&ie=UTF-8&q=mdn%20query%20string") let params = new URLSearchParams(url.search); let sourceid = params.get('sourceid') // 'chrome-instant' let q = params.get('q') // 'mdn query string' let ie = params.has('ie') // true params.append('ping','pong') console.log(sourceid) console.log(q) console.log(ie) console.log(p.. 2023. 10. 26.
728x90