728x90
๋ฐ˜์‘ํ˜•

nikto ์‚ฌ์šฉ๋ฒ•๊ณผ ์•ฝ๊ฐ„์˜ ์˜๋ฌธ์ ?

ํ•ด๋‹น ๋ธ”๋กœ๊ทธ๋Š” ํ•ดํ‚น ๋ฐ ๋ณด์•ˆ ๋ธ”๋กœ๊ทธ๋กœ ๊ณต๋ถ€ ๋ฐ ์—ฐ๊ตฌ์šฉ์œผ๋กœ ์ž‘์„ฑ๋˜์–ด์ง€๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์•„๋ž˜์˜ ๋‚ด์šฉ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•ดํ‚น ์‹œ๋„ ๋ฐ ์‹ค์ œ ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•˜์—ฌ ์ผ์–ด๋‚˜๋Š” ๋ชจ๋“  ์ฑ…์ž„์€ ๋ณธ์ธ(๋”ฐ๋ผํ•œ์ž)์—๊ฒŒ ์žˆ์Œ์„ ์•Œ๋ ค๋“œ๋ฆฌ๋ฉฐ, ๊ธ€์“ด์ด๋Š” ์•„๋ฌด๋Ÿฐ ์ฑ…์ž„์„ ์ง€์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ผญ ๊ณต๋ถ€ ๋ฐ ์—ฐ๊ตฌ์šฉ์œผ๋กœ๋งŒ ์‚ฌ์šฉํ•˜์—ฌ ์ฃผ์‹œ๊ธธ ๋ฐ”๋ž๋‹ˆ๋‹ค. ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ์š”์ฆ˜ nikto๋ฅผ ๋งŽ์ด ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ๊ฐ™๋‹ค. ๊ฐ„๋‹จํ•˜๊ฒŒ ์‚ฌ์šฉํ•˜๊ธฐ ์ข‹์•„์„œ ์กฐ๊ธˆ์”ฉ ์‚ฌ์šฉํ•œ๋‹ค. web์ทจ์•ฝ์ ์„ ์ฐพ๊ธฐ์œ„ํ•ด ์‚ฌ์šฉ์„ ํ•˜๋Š”๊ฒƒ๋ณด๋‹จ backupํŒŒ์ผ ๋“ฑ์„ ์ฐพ๊ธฐ์— ํŽธ๋ฆฌํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉ์„ ๋งŽ์ด ํ•˜๊ณคํ•œ๋‹ค. nikto๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๋ช…๋ น์–ด๋Š” ๋‹จ์ˆœํ•˜๊ฒŒ ์ž…๋ ฅ์„ ํ•ด๋„๋œ๋‹ค. ๋จผ์ € ์‚ฌ์šฉํ•˜๋Š” ๋ฒ•์€ ์•„๋ž˜์™€ ๊ฐ™๋‹ค.nikto -h domain -C all ์ด๋ ‡๊ฒŒ ๊ฐ„๋‹จํ•œ ์˜ต์…˜์„ ์ฃผ๊ณ  ํ•˜๋ฉด ๋œ๋‹ค. delay ๋“ฑ ์˜ต์…˜๋“ค์ด ์—ฌ๋Ÿฌ๊ฐœ๊ฐ€ ์žˆ๋Š”๋ฐ ์ฐจ์ฐจ์“ฐ๋ฉด..

kali setoolkit์„ ์ด์šฉํ•œ ํ”ผ์‹ฑ ์‚ฌ์ดํŠธ ๋งŒ๋“ค๊ธฐ

ํ•ด๋‹น ๋ธ”๋กœ๊ทธ๋Š” ํ•ดํ‚น ๋ฐ ๋ณด์•ˆ ๋ธ”๋กœ๊ทธ๋กœ ๊ณต๋ถ€ ๋ฐ ์—ฐ๊ตฌ์šฉ์œผ๋กœ ์ž‘์„ฑ๋˜์–ด์ง€๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์•„๋ž˜์˜ ๋‚ด์šฉ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•ดํ‚น ์‹œ๋„ ๋ฐ ์‹ค์ œ ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•˜์—ฌ ์ผ์–ด๋‚˜๋Š” ๋ชจ๋“  ์ฑ…์ž„์€ ๋ณธ์ธ(๋”ฐ๋ผํ•œ์ž)์—๊ฒŒ ์žˆ์Œ์„ ์•Œ๋ ค๋“œ๋ฆฌ๋ฉฐ, ๊ธ€์“ด์ด๋Š” ์•„๋ฌด๋Ÿฐ ์ฑ…์ž„์„ ์ง€์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ผญ ๊ณต๋ถ€ ๋ฐ ์—ฐ๊ตฌ์šฉ์œผ๋กœ๋งŒ ์‚ฌ์šฉํ•˜์—ฌ ์ฃผ์‹œ๊ธธ ๋ฐ”๋ž๋‹ˆ๋‹ค. ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. kali๋ฅผ ์‚ฌ์šฉํ•˜๋‹ค ๋ณด๋ฉด ํ”ผ์‹ฑ์‚ฌ์ดํŠธ๋ฅผ ๋งŒ๋“ค๊ฑฐ๋‚˜ ํ…Œ์ŠคํŠธ ์šฉ์œผ๋กœ ๊ฐ€์งœ ์‚ฌ์ดํŠธ๋ฅผ ๋งŒ๋“ค์–ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค. ์ด๋•Œ ์ฃผ๋กœ ์‚ฌ์šฉํ•˜๋Š” ๋„๊ตฌ๊ฐ€ setoolkit ์ด๋ผ๋Š” ๋„๊ตฌ์ธ๋ฐ ํ”ผ์‹ฑ ์‚ฌ์ดํŠธ๋ฅผ ๋งŒ๋“œ๋Š” ๊ฒƒ ๋ฟ์•„๋‹Œ ์ŠคํŒธ๋ฉ”์ผ ๋“ฑ ์‚ฌํšŒ๊ณตํ•™ ๊ธฐ๋ฒ•์—์„œ ์‚ฌ์šฉํ•˜๋Š” ๊ณต๊ฒฉ๊ธฐ๋ฒ•๋“ค์ด ๋‹ค์–‘ํ•˜๊ฒŒ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋‹ค. setoolkit์„ ์‚ฌ์šฉํ•˜๊ธฐ ์œ„ํ•ด์„  ๋จผ์ € msfdb์™€ postgresql์„ ์‹คํ–‰ ํ•ด์•ผํ•œ๋‹ค. sudo service postgresql..

๋ชจ์˜ํ•ดํ‚น์„ ํ•ด๋ณด์ž! -armitage 2ํŽธ

ํ•ด๋‹น ๋ธ”๋กœ๊ทธ๋Š” ํ•ดํ‚น ๋ฐ ๋ณด์•ˆ ๋ธ”๋กœ๊ทธ๋กœ ๊ณต๋ถ€ ๋ฐ ์—ฐ๊ตฌ์šฉ์œผ๋กœ ์ž‘์„ฑ๋˜์–ด์ง€๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์•„๋ž˜์˜ ๋‚ด์šฉ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•ดํ‚น ์‹œ๋„ ๋ฐ ์‹ค์ œ ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•˜์—ฌ ์ผ์–ด๋‚˜๋Š” ๋ชจ๋“  ์ฑ…์ž„์€ ๋ณธ์ธ(๋”ฐ๋ผํ•œ์ž)์—๊ฒŒ ์žˆ์Œ์„ ์•Œ๋ ค๋“œ๋ฆฌ๋ฉฐ, ๊ธ€์“ด์ด๋Š” ์•„๋ฌด๋Ÿฐ ์ฑ…์ž„์„ ์ง€์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ผญ ๊ณต๋ถ€ ๋ฐ ์—ฐ๊ตฌ์šฉ์œผ๋กœ๋งŒ ์‚ฌ์šฉํ•˜์—ฌ ์ฃผ์‹œ๊ธธ ๋ฐ”๋ž๋‹ˆ๋‹ค. ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. 2023.08.18 - [Metasploit/Kali & Backtrack] - ๋ชจ์˜ํ•ดํ‚น์„ ํ•ด๋ณด์ž!-armitageํŽธ ๋ชจ์˜ํ•ดํ‚น์„ ํ•ด๋ณด์ž!-armitageํŽธ ํ•ด๋‹น ๋ธ”๋กœ๊ทธ๋Š” ํ•ดํ‚น ๋ฐ ๋ณด์•ˆ ๋ธ”๋กœ๊ทธ๋กœ ๊ณต๋ถ€ ๋ฐ ์—ฐ๊ตฌ์šฉ์œผ๋กœ ์ž‘์„ฑ๋˜์–ด์ง€๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์•„๋ž˜์˜ ๋‚ด์šฉ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•ดํ‚น ์‹œ๋„ ๋ฐ ์‹ค์ œ ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•˜์—ฌ ์ผ์–ด๋‚˜๋Š” ๋ชจ๋“  ์ฑ…์ž„์€ ๋ณธ์ธ(๋”ฐ๋ผํ•œ์ž)์—๊ฒŒ ์žˆ์Œ blog.z3alous.xyz ๋ช‡์ผ ์ „์— ์œ„์˜ ๊ธ€์„ ์ž‘์„ฑํ•˜์˜€๋‹ค. ์ด..

๋ชจ์˜ํ•ดํ‚น์„ ํ•ด๋ณด์ž!-armitageํŽธ

ํ•ด๋‹น ๋ธ”๋กœ๊ทธ๋Š” ํ•ดํ‚น ๋ฐ ๋ณด์•ˆ ๋ธ”๋กœ๊ทธ๋กœ ๊ณต๋ถ€ ๋ฐ ์—ฐ๊ตฌ์šฉ์œผ๋กœ ์ž‘์„ฑ๋˜์–ด์ง€๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์•„๋ž˜์˜ ๋‚ด์šฉ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•ดํ‚น ์‹œ๋„ ๋ฐ ์‹ค์ œ ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•˜์—ฌ ์ผ์–ด๋‚˜๋Š” ๋ชจ๋“  ์ฑ…์ž„์€ ๋ณธ์ธ(๋”ฐ๋ผํ•œ์ž)์—๊ฒŒ ์žˆ์Œ์„ ์•Œ๋ ค๋“œ๋ฆฌ๋ฉฐ, ๊ธ€์“ด์ด๋Š” ์•„๋ฌด๋Ÿฐ ์ฑ…์ž„์„ ์ง€์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ผญ ๊ณต๋ถ€ ๋ฐ ์—ฐ๊ตฌ์šฉ์œผ๋กœ๋งŒ ์‚ฌ์šฉํ•˜์—ฌ ์ฃผ์‹œ๊ธธ ๋ฐ”๋ž๋‹ˆ๋‹ค. ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค. ์•ฝ 1๋‹ฌ ์ „์ฏค toss์—์„œ ๋งŒ๋“ค์–ด์ง„ ์˜์ƒ์„ ๋ณด์•˜๋‹ค. ํ•ด๋‹น์˜์ƒ์ด๋‹ค. https://youtu.be/tAqgvP07RnQ ํ•ด๋‹น ์˜์ƒ์„ ๋ณด๋Š”๋™์•ˆ ์‹œ๊ฐ„ ๊ฐ€๋Š”์ค„ ๋ชจ๋ฅด๊ณ  ๊ณ„์† ๋ณด๊ณ ์žˆ์—ˆ๋‹ค. ํ•ด๋‹น ๋™์˜์ƒ์— ๋‚˜์˜ค๋Š” ๋ถ„๋“ค์„ ์‹ค์ œ๋กœ ์•„๋Š” ๋ถ„๋“ค์ด์ง€๋งŒ ์ด๋ ‡๊ฒŒ ๋ณด๋‹ˆ ๋”๋”์šฑ ๋ฉ‹์žˆ์–ด ๋ณด์˜€๋‹ค. 'ํ† ์Šค๋ฅผ ํ•ดํ‚นํ•˜๋Š” ์ž' ๋ผ๋Š” ์˜์ƒ์„ ๋ณด๊ณ  ์—ฌ๋Ÿฌ๊ฐ€์ง€์— ํฅ๋ฏธ๋ฅผ ๊ฐ€์กŒ๋‹ค. forensic์„ ์ฃผ๋กœ ํ•˜๋˜ ๋‚˜์˜€๋Š”๋ฐ ์—…๋ฌด๋ฅผ ํ•˜๋ฉด์„œ ์กฐ๊ธˆ์”ฉ ์ทจ์•ฝ์ ๊ณผ ๋ชจ์˜ํ•ดํ‚น..

netool ์„ค์น˜๋ฐฉ๋ฒ•(how to install netool)

netool = script project ๋„ทํˆด์„ ์„ค์น˜ํ•˜๊ธฐ ์œ„ํ•ด https://sourceforge.net/projects/netoolsh/ ๋“ค์–ด๊ฐ€๋ฉด ๋ฐ‘์—์™€ ๊ฐ™์€ ์ฐฝ์ด ๋œฌ๋‹ค. :) Git -> opensource-kali ๋ฅผ ํด๋ฆญํ•˜๊ฒŒ ๋˜๋ฉด ๋ฐ‘์œผ๋กœ ์ญ‰์ญ‰ ๋‚ด๋ฆฌ๋ฉด ์„ค์น˜๋ฐฉ๋ฒ•์ด ๋œฌ๋‹น :) ์ž์„ธํ•œ๊ฑด ์œ ํŠœ๋ธŒ๋กœ

kali linux 2.0 apt-get

/etc/apt/sources.list deb http://http.kali.org/kali sana main non-free contrib deb http://security.kali.org/kali-security/ sana/updates main contrib non-free

Reading package lists Error

Reading package lists... Done Building dependency tree Reading state information... Done Calculating upgrade... Note, selecting 'Package' for regex 'Package' Done < == error vi /etc/apt/sources.list # Regular repositories deb http://http.kali.org/kali sana main non-free contrib deb http://security.kali.org/kali-security sana/updates main contrib non-free # Source repositories deb-src http://http..

sqlmap

SQLMAP ๊ฐ์ง€ ๋ฐ SQL ์ฃผ์ž… ์ทจ์•ฝ์ ์„ ์ด์šฉํ•˜์—ฌ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์„œ๋ฒ„์˜ ์ธ๊ณ„ ๊ณผ์ •์„ ์ž๋™ํ™”ํ•˜๋Š” ์˜คํ”ˆ ์†Œ์Šค ์นจ์ž… ํ…Œ์ŠคํŠธ ๋„๊ตฌ์ž…๋‹ˆ๋‹ค. ,์ด๊ฒƒ์€ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์—์„œ ๊ธฐ๋ณธ ํŒŒ์ผ ์‹œ์Šคํ…œ์— ์•ก์„ธ์Šคํ•˜๊ณ  ๋ฐ–์„ ํ†ตํ•ด ์šด์˜ ์ฒด์ œ์—์„œ ๋ช…๋ น์„ ์‹คํ–‰ํ•˜๋Š” ํŽ˜์น˜ ๋ฐ์ดํ„ฐ์— ๊ถ๊ทน์  ์ธ ์นจ์ž… ํ…Œ์Šคํ„ฐ ๋ฐ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์ง€๋ฌธ์—์„œ ์ง€์† ์Šค์œ„์น˜์˜ ๋„“์€ ,๋ฒ”์œ„์— ๋Œ€ํ•œ ๋งŽ์€ ํ‹ˆ์ƒˆ ๊ธฐ๋Šฅ,โ€‹โ€‹ ๊ฐ•๋ ฅํ•œ ๊ฒ€์ƒ‰ ์—”์ง„์ด ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค . root@kali:~# sqlmap = automatic SQL injection tool ๋„์›€๋ง root@kali:~# sqlmap -h Usage: python sqlmap [options] Options: -h, --help Show basic help message and exit -hh Show advanced he..

SSLsplit

SSLsplit ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ์„ ์•”ํ˜ธํ™” SSL / TLS์— ๋Œ€ํ•œ man-in-the-middle ๊ณต๊ฒฉํ•˜๊ธฐ์œ„ํ•œ ๋„๊ตฌ์ž…๋‹ˆ๋‹ค. ์ฃผ์†Œ ๋ณ€ํ™˜ ์—”์ง„์„ ํ†ตํ•ด ์ฐจ๋‹จํ•˜์—ฌ SSLsplit๋กœ ๋ฆฌ๋””๋ ‰์…˜๋ฉ๋‹ˆ๋‹ค. SSLsplit๋Š” SS L / TLS๋ฅผ ์ข…๋ฃŒํ•˜๊ณ  ์ „์†ก ๋œ ๋ชจ๋“  ๋ฐ์ดํ„ฐ๋ฅผ ๊ธฐ๋ก ํ•  ๋•Œ ์›๋ž˜์˜ ๋ชฉ์ ์ง€ ์ฃผ์†Œ์— ์ƒˆ๋กœ์šด SSL / TLS ์—ฐ๊ฒฐ์„ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค. SSLsplit๋Š” ๊ณต๊ฐœ ํ‚ค ํ•€ ๊ณ ์ •์„ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•ด HPKP ์‘๋‹ต ํ—ค๋”๋ฅผ ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค. ๋„์›€๋ง root@kali:~# sslsplit -h Usage: sslsplit [options...] [proxyspecs...] -c pemfile use CA cert (and key) from pemfile to sign forged certs -k pemfile use CA ke..

how to hack wifi using backtrack

What You'll NeedUnless you're a computer security and networking ninja, chances are you don't have all the tools on hand to get this job done. Here's what you'll need:A compatible wireless adapter—This is the biggest requirement. You'll need a wireless adapter that's capable of packet injection, and chances are the one in your computer is not. After consulting with my friendly neighborhood secur..
728x90
๋ฐ˜์‘ํ˜•