๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
  • Tried. Failed. Logged.
728x90

๐Ÿ”’์ •๋ณด๋ณด์•ˆ122

๋””์ง€ํ„ธ ํฌ๋ Œ์‹ - FTK Imager ์‚ญ์ œ๋œ ํŒŒ์ผ ๋ณต๊ตฌํ•˜๊ธฐ ๋ฐ ํŒŒ์ผ ์†Œ๊ฑฐํ•˜๊ธฐ ์‹ค์Šต ํ™˜๊ฒฝ ์šด์˜์ฒด์ œ: Windows 10(๊ฐ€์ƒ๋จธ์‹ ) ๋ณต๊ตฌ ํŒŒ์ผ ๋Œ€์ƒ: owasp-top-10.pdf ์‚ฌ์šฉ ๋„๊ตฌ: FTK Imager ์•„๋ž˜์™€ ๊ฐ™์ด ์ž˜ ์—ด๋ฆฌ๊ฒŒ ๋˜๋Š” pdf ํŒŒ์ผ์ด ์žˆ๋‹ค. ์šฐ์„  ์ด๊ฒƒ์„ ์“ฐ๋ ˆ๊ธฐํ†ต์— ๋ฒ„๋ฆฐ๋‹ค. ๊ทธ๋‹ค์Œ ํŒŒ์ผ์ด ๋ณต๊ตฌ๊ฐ€ ์•ˆ๋˜๊ฒŒ ํœด์ง€ํ†ต์„ ๋น„์›Œ์ค€๋‹ค. ์ด์ œ FTK Imager๋ฅผ ์‹คํ–‰์‹œ์ผœ "Add All Attached Devices"๋ฅผ ๋ˆŒ๋Ÿฌ ํ˜„์žฌ ์ปดํ“จํ„ฐ์— ์—ฐ๊ฒฐ๋œ ๋ชจ๋“  ์žฅ์น˜๋“ค์„ ๋ถˆ๋Ÿฌ์™€์ค€๋‹ค. ์—ฐ๊ฒฐ๋œ ์žฅ์น˜๋“ค ์ค‘ C:\๋ฅผ ์„ ํƒํ•˜๊ณ  "C:\NONAME [NTFS]\root\$Recycle.Bin\" ๊ฒฝ๋กœ๋กœ ์ด๋™ํ•ด์„œ ์ฐพ๊ณ ์ž ํ•˜๋Š” pdf ํŒŒ์ผ์„ ํƒ์ƒ‰ํ•œ๋‹ค. ํŒŒ์ผ์„ ์ œ๊ฑฐํ•˜๋ฉด ๋ฉ”ํƒ€ ๋ฐ์ดํ„ฐ ์ •๋ณด๊ฐ€ ์‚ญ์ œ๋˜๋ฏ€๋กœ ๊ธฐ์กด์˜ ์ด๋ฆ„(owasp-top-10.pdf)์€ ์ง€์›Œ์กŒ์ง€๋งŒ ๋ฐ์ดํ„ฐ ๋ถ€๋ถ„์€ ์•„์ง ๋‚จ์•„ ์žˆ๊ฒŒ ๋œ๋‹ค. ๋ณต๊ตฌ๋ฅผ ์œ„ํ•ด.. 2023. 9. 24.
์›น ๋ณด์•ˆ - CSP ํ™•์ธ ์‚ฌ์ดํŠธ(CSP Evaluator) https://csp-evaluator.withgoogle.com/ CSP Evaluator csp-evaluator.withgoogle.com 2023. 9. 11.
๋””์ง€ํ„ธ ํฌ๋ Œ์‹ - ์ด๋ฏธ์ง€์™€ ์••์ถ• ํŒŒ์ผ(zip)์„ ๊ฒฐํ•ฉํ•˜๋Š” ๊ฐ„๋‹จํ•œ ์Šคํ…Œ๊ฐ€๋…ธ๊ทธ๋ž˜ํ”ผ ์‚ฌ์ „ ์ค€๋น„ ์ƒ๋Œ€๋ฐฉ์„ ์†์ผ ์ด๋ฏธ์ง€์™€ ์ˆจ๊ธฐ๊ณ  ์‹ถ์€ ํŒŒ์ผ์„ ์••์ถ•ํ•œ zip์„ ์ค€๋น„ํ•œ๋‹ค. cmd ์ฐฝ์„ ์—ด์–ด "copy /B ์ด๋ฏธ์ง€+์••์ถ•ํŒŒ์ผ ์ถœ๋ ฅ์ด๋ฆ„"์„ ์ž…๋ ฅํ•œ๋‹ค. (/B๋Š” ์ด์ง„ ํŒŒ์ผ ์˜ต์…˜์ด๋‹ค.) ์ถœ๋ ฅ๋œ ๊ฒฐ๊ณผ(output.zip)๋Š” ์ผ๋ฐ˜ ์ด๋ฏธ์ง€์™€ ๋˜‘๊ฐ™์•„ ๋ณด์ธ๋‹ค. ๋”๋ธ” ํด๋ฆญ์„ ํ•˜๋ฉด ์ด๋ฏธ์ง€ ๋ทฐ๋„ ์ •์ƒ์ ์œผ๋กœ ๋ถˆ๋Ÿฌ์˜จ๋‹ค. ํ•˜์ง€๋งŒ ์›๋ณธ๊ณผ ๋น„๊ตํ•˜๋ฉด ์šฉ๋Ÿ‰์ด ํ›จ์”ฌ ์ฆ๊ฐ€ํ•œ ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค. ์—ฌ๊ธฐ์„œ ์ž ๊น ํ™•์žฅ์ž๋ฅผ .zip์œผ๋กœ ๋ณ€๊ฒฝํ•˜๋ฉด ํŒŒ์ผ ์•„์ด์ฝ˜์ด ๊นจ์ ธ ๋ณด์ด์ง€๋งŒ ๋”๋ธ” ํด๋ฆญ์„ ํ•˜๋ฉด ์••์ถ• ํ”„๋กœ๊ทธ๋žจ์ด ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ ์ •์ƒ์ ์œผ๋กœ ์—ด๋ฆฐ๋‹ค. ํ’€๊ธฐ๋„ ๊ฐ€๋Šฅํ•˜๊ณ  ํŒŒ์ผ ์ฝ˜ํ…์ธ ๋„ ๊ทธ๋Œ€๋กœ ์••์ถ• ํ•ด์ œ๊ฐ€ ๊ฐ€๋Šฅํ•˜๋‹ค. ๋‹ค์Œ์€ image.jpg์™€ output.zip์˜ ์‹œ์ž‘๊ณผ ์ค‘๊ฐ„ ์ชฝ์˜ ๋ฐ”์ด๋„ˆ๋ฆฌ๊ฐ€ ์ผ์น˜ํ•˜๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ์ด๋ฏธ์ง€ ๋ทฐ์–ด ํ”„๋กœ๊ทธ๋žจ์€ ์ด๋ ‡๊ฒŒ ํŒŒ์ผ์˜ ์‹œ.. 2023. 8. 10.
์›น ๋ณด์•ˆ - OSINT ๋„๊ตฌ ๋ชจ์Œ ํ”„๋ ˆ์ž„์›Œํฌ(OSINT Framework) https://osintframework.com/ OSINT Framework (T) - Indicates a link to a tool that must be installed and run locally (D) - Google Dork, for more information: Google Hacking (R) - Requires registration (M) - Indicates a URL that contains the search term and the URL itself must be edited manually I ori osintframework.com ๋ฌด๋ฃŒ ๋„๊ตฌ๋‚˜ ๋ฆฌ์†Œ์Šค์—์„œ ์ •๋ณด๋ฅผ ์ˆ˜์ง‘ํ•˜๋Š” ๋ฐ ์ค‘์ ์„ ๋‘” OSINT ํ”„๋ ˆ์ž„์›Œํฌ์ž…๋‹ˆ๋‹ค. ์‚ฌ๋žŒ๋“ค์ด ๋ฌด๋ฃŒ OSINT ๋ฆฌ์†Œ์Šค๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ๋„๋ก ๋•๋Š” ๊ฒƒ.. 2023. 7. 13.
์›น ๋ณด์•ˆ - OSINT ์›น์‚ฌ์ดํŠธ ์ •๋ณด ์ˆ˜์ง‘ ๋„๊ตฌ(urlscan.io) https://urlscan.io/ URL and website scanner - urlscan.io User Agent Default - Latest Google Chrome Stable on Windows 10 Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/92.0.4515.131 Safari/537.36 Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) C urlscan.io urlscan.io๋Š” (ํ˜„์žฌ๊นŒ์ง€๋Š”) ๋ฌด๋ฃŒ๋กœ ์›น์‚ฌ์ดํŠธ๋ฅผ ์Šค์บ”ํ•˜๊ณ  ๋ถ„์„ํ•  ์ˆ˜ ์žˆ๋Š” OSINT ์„œ๋น„์Šค๋‹ค. ๊ฒ€์ƒ‰๋ž€์— URL ์ฃผ์†Œ๋ฅผ ๋„ฃ๊ณ  ์Šค.. 2023. 7. 13.
๋ฆฌ๋ฒ„์‹ฑ - Bush hid the facts, ์œˆ๋„์šฐ XP ๋ฉ”๋ชจ์žฅ ๋ฒ„๊ทธ ๋ฌธ์ œ ํ™•์ธ 1. ๋ฉ”๋ชจ์žฅ์„ ์ƒˆ๋กœ ๋งŒ๋“ค์–ด์„œ ์•ˆ์— "Bush hid the facts"๋ฅผ ์ž…๋ ฅํ•œ๋‹ค. "๋ถ€์‹œ ๋Œ€ํ†ต๋ น์€ ์ง„์‹ค์„ ์ˆจ๊ธฐ๊ณ  ์žˆ๋‹ค"๋ผ๋Š” ๋œป์˜ ์‹ฌ์˜คํ•œ(?) ๋‚ด์šฉ์ด๋‹ค. 2. ๋ฉ”๋ชจ์žฅ์„ ์ €์žฅํ•œ ํ›„์— ๋‹ค์‹œ ํŒŒ์ผ์˜ ๋‚ด์šฉ์„ ๋“ค์—ฌ๋‹ค๋ณธ๋‹ค. ๊ทธ๋Ÿฌ์ž ๋ณธ๋ž˜ ๋‚ด์šฉ์ด ์—†์–ด์ง€๊ณ  ๊ธ€์ž๊ฐ€ ๊นจ์ ธ์„œ ๋‚˜์˜จ๋‹ค. ๋ฌธ์ œ ๋ถ„์„ 1. ํ˜น์‹œ๋‚˜ ๋ฉ”๋ชจ์žฅ์—์„œ ๋ฐœ์ƒํ•˜๋Š” ์˜ค๋ฅ˜ ์•„๋‹๊นŒ ํ•˜๊ณ  cmd ์ฐฝ์—์„œ type ๋ช…๋ น์–ด๋กœ ํŒŒ์ผ์˜ ๋‚ด์šฉ์„ ํ™•์ธํ•ด ๋ณด์•˜๋‹ค. ํ™•์ธํ•ด๋ณธ ๊ฒฐ๊ณผ ์‹ค์ œ ํŒŒ์ผ์˜ ๋‚ด์šฉ์€ ๊ทธ๋Œ€๋กœ์ธ๊ฑธ ๋ณด์•„ ๋ฉ”๋ชจ์žฅ์—์„œ ์ƒ๊ธฐ๋Š” ์˜ค๋ฅ˜์ธ ๊ฒƒ์ด๋‹ค. 2. ๊นจ์ง„ ํŒŒ์ผ์„ (B.txt๋กœ) ์ €์žฅํ•˜๊ณ  ํ—ฅ์Šค ์—๋””ํ„ฐ๋กœ ๋ถ„์„ํ•ด๋ณธ๋‹ค. ๋ถ„์„์„ ํ•ด๋ณด๋ฉด ์›๋ณธ์ธ A.txt๋Š” ๋‚ด์šฉ์ด ์ž˜ ์ €์žฅ๋˜์žˆ๋Š” ๋ฐ˜๋ฉด B.txt๋Š” ๋‚ด์šฉ ์•ž์— FF FE๋ผ๋Š” ํŒŒ์ผ ํ—ค๋”๊ฐ€ ๋“ค์–ด๊ฐ€๊ฒŒ ๋œ๋‹ค. ํ™•์ธํ•ด ๋ณธ ๊ฒฐ๊ณผ FF FE๋Š” UT.. 2023. 7. 12.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - ํฌํŠธ ์Šค์บ”(port scan) with Wireshark, nmap ๊ฐœ์š” ํฌํŠธ ์Šค์บ”(port scan)์€ ์šด์˜ ์ค‘์ธ ์„œ๋ฒ„์—์„œ ์—ด๋ ค ์žˆ๋Š” TCP/UDP ํฌํŠธ๋ฅผ ๊ฒ€์ƒ‰ํ•˜๋Š” ๊ฒƒ์„ ์˜๋ฏธํ•œ๋‹ค. ์‹ค์Šต ์‚ฌ์ „ ์ค€๋น„ Windows ํ™˜๊ฒฝ์— ์™€์ด์–ด์ƒคํฌ์™€ ํŒŒ์ด์ฌ์„ ์ค€๋น„ํ•œ๋‹ค. ํฌํŠธ ์Šค์บ๋‹ ๋„๊ตฌ์ธ nmap์ด ์„ค์น˜๋ผ ์žˆ์–ด์•ผ ํ•œ๋‹ค. ์™€์ด์–ด์ƒคํฌ ์„ธํŒ… ์™€์ด์–ด์ƒคํฌ๋ฅผ ์‹คํ–‰์‹œํ‚ค๊ณ  "Adapter for loopback traffic capture"๋ฅผ ๋ˆŒ๋Ÿฌ ๋กœ์ปฌ ๋‚ด์—์„œ ์ผ์–ด๋‚˜๋Š” ํŠธ๋ž˜ํ”ฝ๋“ค์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•œ๋‹ค. ๋‹ค์Œ ์•„๋ž˜์— ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์ž‘์„ฑํ•ด ๊ฐ๊ฐ TCP, UDP ์„œ๋ฒ„๋ฅผ ์—ด์–ด์ค€๋‹ค. tcp_server.py import socket def start_tcp_server(host, port): server_socket = socket.socket(socket.AF_INET, socket.SOCK_STREAM) server_s.. 2023. 6. 21.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - ๋ฌด์„  ๋„คํŠธ์›Œํฌ ๊ด€๋ จ CheatSheet https://github.com/V0lk3n/WirelessPentesting-CheatSheet GitHub - V0lk3n/WirelessPentesting-CheatSheet: This repository contain a CheatSheet for OSWP & WiFi Cracking.This repository contain a CheatSheet for OSWP & WiFi Cracking. - GitHub - V0lk3n/WirelessPentesting-CheatSheet: This repository contain a CheatSheet for OSWP & WiFi Cracking.github.com 2023. 6. 14.
์›น ๋ณด์•ˆ - PHP ๋งค์ง ํ•ด์‹œ(Magic Hashes) ์ทจ์•ฝ์  ํƒ€์ž… ์ €๊ธ€๋ง(Type Juggling) PHP๋Š” ํƒ€์ž… ๊ฐ•๋„๊ฐ€ ์•ฝํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์ƒํ™ฉ์— ๋”ฐ๋ผ ํƒ€์ž…์ด ๋™์ ์œผ๋กœ ๋ณ€ํ•˜๊ฒŒ ๋˜๋Š”๋ฐ ์ด๋ฅผ ํƒ€์ž… ์ €๊ธ€๋ง(Type Juggling)์ด๋ผ๊ณ  ํ•œ๋‹ค. ํƒ€์ž… ์บ์ŠคํŒ…๊ณผ ๋‹ค๋ฅธ ์ ์€ ํ”„๋กœ๊ทธ๋ž˜๋จธ๊ฐ€ ๋ช…์‹œ์ ์œผ๋กœ ์ง€์ • ex) (float) a ํ•˜๋Š” ๊ฒƒ์„ ํƒ€์ž… ์บ์ŠคํŒ…์ด๊ณ , ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์–ธ์–ด๊ฐ€ ์ž๋™์ ์œผ๋กœ ๋ณ€ํ™˜ํ•ด์ฃผ๋Š” ๊ฒƒ์„ ํƒ€์ž… ์ €๊ธ€๋ง์ด๋ผ๊ณ  ํ•˜๋Š” ๊ฒƒ ๊ฐ™๋‹ค. php > var_dump(5 * "2"); int(10) ์ •์ˆ˜ํ˜•(int) 5์™€ ๋ฌธ์žํ˜•(string) 2๋ฅผ ์—ฐ์‚ฐ์‹œํ‚ค๋ฉด ์ •์ˆ˜ํ˜•(int) 10์ด ๋ฐ˜ํ™˜๋œ๋‹ค. ๋งˆ์ฐฌ๊ฐ€์ง€๋กœ $a == $b๋ฅผ ๋น„๊ตํ•  ๋•Œ ๋˜ํ•œ ํƒ€์ž… ์ €๊ธ€๋ง์„ ๊ฑฐ์น˜๊ฒŒ ๋œ๋‹ค. php > var_dump('1234'==1234); bool(true) php > var_dump("123" == "123... 2023. 5. 24.
๋„คํŠธ์›Œํฌ ๋ณด์•ˆ - ์ธก๋ฉด ์ด๋™(Lateral Movement) ์ธก๋ฉด ์ด๋™(Lateral Movement)์€ ๊ณต๊ฒฉ์ž๊ฐ€ ์ฒ˜์Œ์— ๋„คํŠธ์›Œํฌ ๋ฐฉ์–ด ์ฒด๊ณ„๋ฅผ ์นจํˆฌํ•œ ํ›„ ์ถ”๊ฐ€ ์ž์‚ฐ์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉํ•˜๋Š” ์ผ๋ จ์˜ ๊ธฐ๋ฒ•์ž…๋‹ˆ๋‹ค. ์‚ฌ์ด๋ฒ„ ๋ฒ”์ฃ„์ž๋“ค์€ ๋ฐ์ดํ„ฐ์„ผํ„ฐ๋‚˜ IT ํ™˜๊ฒฝ์— ์ฒ˜์Œ ์ ‘์†ํ•˜์—ฌ ๋“ค์–ด์˜จ ํ›„ ์ค‘์š”ํ•œ ๋ฐ์ดํ„ฐ, ์ง€์‹ ์žฌ์‚ฐ ๋ฐ ๊ธฐํƒ€ ๊ณ ๊ฐ€์น˜ ์ž์‚ฐ์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•ด ํƒˆ์ทจํ•œ ๋กœ๊ทธ์ธ ์ธ์ฆ์ •๋ณด(์ธ์ฆ์ •๋ณด ๋„์šฉ ๋˜๋Š” ํ”ผ์‹ฑ ๊ณต๊ฒฉ์„ ํ†ตํ•ด ์–ป์€)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์‹œ์Šคํ…œ ์•ˆ์œผ๋กœ ๋ณด๋‹ค ๊นŠ์ด ์ด๋™ํ•ฉ๋‹ˆ๋‹ค. ์ถœ์ฒ˜: https://www.akamai.com/ko/our-thinking/zero-trust/lateral-movement ์ธก๋ฉด ์ด๋™ ๋ณด์•ˆ์ด๋ž€ ๋ฌด์—‡์ธ๊ฐ€์š”? | Akamai ์ธก๋ฉด ์ด๋™์€ ๊ณต๊ฒฉ์ž๊ฐ€ ์ฒ˜์Œ์— ๋„คํŠธ์›Œํฌ ๋ฐฉ์–ด ์ฒด๊ณ„๋ฅผ ์นจํˆฌํ•œ ํ›„ ์ถ”๊ฐ€ ์ž์‚ฐ์— ์ ‘์†ํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉํ•˜๋Š” ์ผ๋ จ์˜ ๊ธฐ๋ฒ•์ž…๋‹ˆ๋‹ค. www.akamai.com 2023. 5. 14.
๋””์ง€ํ„ธ ํฌ๋ Œ์‹ - PowerShell ๋ช…๋ น์–ด ๊ธฐ๋ก ์ €์žฅ ๊ฒฝ๋กœ(ConsoleHost_history.txt) ๋กœ๊ทธ ํŒŒ์ผ ๊ฒฝ๋กœ $env:APPDATA\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadLine\ConsoleHost_history.txt ์ฐธ๊ณ ๋กœ powershell -c ๋ช…๋ น์–ด ๊ฐ™์€ ๋ผ์ธ ์‹คํ–‰ ๋ช…๋ น์–ด๋Š” ๊ธฐ๋ก์ด ์•ˆ ๋˜๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์ธ๋‹ค. ์ถœ์ฒ˜: https://www.reddit.com/r/computerforensics/comments/gqjhhw/does_windows_log_the_cmd_history/ r/computerforensics on Reddit: Does windows log the cmd histo.. 2023. 5. 12.
OSINT ๊ด€๋ จ ๋„๊ตฌ ๋ชจ์Œ(API, ๊ฒ€์ƒ‰ ์—”์ง„ ๋“ฑ) https://github.com/cipher387 cipher387 - OverviewHello, I am cipher387 (aka @cyb_detective). I am very passionate about OSINT (Open Source INTelligence) and everything related to it. - cipher387github.com 2023. 4. 28.
728x90