å®éšå®€ã«ã€ããŠã®äžèš
ãTest lab v.7ãã¯ãWindowsããã³Linuxã«åºã¥ãä»®æ³äŒç€ŸãSecureSoft LLCãã®äŒæ¥ãããã¯ãŒã¯ã§ãã ä»®æ³äŒç€Ÿã¯ãœãããŠã§ã¢éçºãå°éãšããŠãããããã€ãã®ã»ãã¥ãªãã£äžã®æ¬ é¥ããããŸãã çºèŠãããè匱æ§ã䜿çšããŠãåå è ãæåŸ ããŠããããã¯ãŒã¯ã«äŸµå ¥ãããã¹ãŠã®SecureSoft LLCããŒãã«ã¢ã¯ã»ã¹ããŸããåããŒãã«ã¯ã·ãŒã¯ã¬ããããŒã¯ã³ãå«ãŸããŠããŸãïŒ10åã®ã¿ïŒã
ã¿ã€ã ã©ã€ã³
ãã®ç 究æã¯ã2015幎5æ1æ¥ãã¢ã¹ã¯ã¯æéã®22:00ã«éå§ãããä»æ¥ãŸã§å©çšå¯èœã§ãã éå§æã«ã¯ãããŸããŸãªåœããçŽ1200人ã®åå è ãç»é²ãããŠããŸããã ã³ãã¥ãã±ãŒã·ã§ã³ãšåé¡è§£æ±ºã®äŸ¿å®ã®ããã«ããã·ã¢èªãšè±èªã§ãã©ãŒã©ã ãæºåãããŸããã åå è ã®è¡åã¯ããµã€ããŒæ»æã®äžçå°å³ã§èŠ³å¯ã§ããŸãã
å®éšå®€ã®ãã¹ãŠã®ããŒãã§æåã«æåããæ»æã¯ãOmar GanievïŒBechedïŒã§ããã 6æ¥éã®æ¿ããæ»æã®åŸãOmarã¯æåŸã®ããŒã¯ã³ãååŸãããã¹ãã©ãã®ã©ãã§3åé£ç¶ã§ãã£ã³ããªã³ã«ãªããŸããã
ãã®ç 究宀ã§ã¯ã以åã®ãã®ãšåãããã«ãç§ã¯å€ããæ®å¿ã«ãããæšæž¬ãããããå¿ èŠããããšäžå¹³ãèšããŸããããããã§ãç§ã¯èªåèªèº«ã®ããã«æçšãªãã®ãåŒãåºããŸãã=ïŒã æãéèŠãªã¿ã¹ã¯ã®1ã€ã¯ãMSEãŠã€ã«ã¹å¯Ÿçããã€ãã¹ããŠDLLãã€ãžã£ãã¯ãè¡ãå¿ èŠãããã¿ãŒããã«ãµãŒããŒã®è匱æ§ãæªçšããããšã§ããã ãŸããåœã®ãã¹ããããããšã«ãé¢ãããããã©ãŒã©ã ã®ã¿ã¹ã¯ã¯éç«ã£ãŠããŸããããã®ã¿ã¹ã¯ã§ã¯ãè匱æ§ãæåã§æªçšããå¿ èŠããããBurp Suiteã«ãã¡ãžã³ã°èŸæžãããã©ã«ãã§çµã¿èŸŒãŸããŠããŸããã ä»ã®ã¿ã¹ã¯ã¯ãæšæºçãªã¹ãã«ãšããŸããŸãªæ€çŽ¢çµæã«äžèŽããèœåãéçºããã®ã«åœ¹ç«ã¡ãŸãã ãã¬ãŒãã³ã°ãµã€ãã®äž»å¬è ã«æè¬ããŸããOmarã«ç¶ããŠããã°ããããŠãMERRONãDarkCatãAV1ct0rã®åå è ããã¹ãŠã®ããŒã¯ã³ãåéããããšãã§ããŸããã å®éšå®€ã¯åæ Œãšã¿ãªãããŠãããšããäºå®ã«ãããããããæ¬è³ªã倱ãããšã¯ãããŸãããã€ãŸããå šå¡ã«å®è·µçãªãã³ãã¹ãã®ã¹ãã«ã匷åããæ©äŒãäžããæ°ãããã³ãã¹ããååŸããããšã§ãã ã¿ã¹ã¯ã®è€éããèæ ®ããŠãç 究宀ãéšåçã«ééããæºåãããŸããã
ãªããŒã«ã¬ããšãïŒBechedïŒã incsecurity.ru
è©äŸ¡
ã泚æ ãã®ã»ã¯ã·ã§ã³ã«ã¯ãå®éšå®€ã®äžéšãééããæé ãå«ãŸããŠããŸãã
ãã¹ãŠã®ããã¹ãã©ããã©ãã®ç¹åŸŽã¯ãäŒæ¥ãããã¯ãŒã¯ã®å®éã®æ¡ä»¶ã«è¿æ¥ããŠããããšãããã³å®éã«ééãããã¯ãã«ãšæ»æã·ããªãªã®ã¢ããªã³ã°ã§ãã ãã®èšäºã§ã¯ãå®éšå®€ã®æåã®ã¿ã¹ã¯ãšæ¬¡ã®åæ Œã®æ¹åæ§ã«ã€ããŠèª¬æããŸãã ã¿ã¹ã¯ãå®äºããåã«ãã©ãã®Webãµã€ãã«ç»é²ãããã£ã¹ããªãã¥ãŒã·ã§ã³ãæ§æããå¿ èŠããããŸãããã£ã¹ããªãã¥ãŒã·ã§ã³ã䜿çšããŠãä»®æ³ãããã¯ãŒã¯ãã³ãã¹ããå®è¡ããŸãã Kali Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã®äœ¿çšããå§ãããŸãã ããã¯ãæ å ±ã»ãã¥ãªãã£ã®å°é家åãã«èšèšãããå°éã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã§ãããäŸµå ¥ãã¹ãçšã®å€æ°ã®ããŒã«ãå«ãŸããŠããŸãã ç»é²ããŠVPNçµç±ã§å®éšå®€ã«æ¥ç¶ãããšã次ã®æ å ±ãå ¥æã§ããŸãã
åææ
å ±
- ãã¹ãæžã¿ã®äŒæ¥ãããã¯ãŒã¯ïŒSecureSoft LLCã
- ãµãŒããŒã®IPã¢ãã¬ã¹ïŒ192.168.101.5
- ãããã¯ãŒã¯ããã
ç 究æã®ã³ã³ããã¹ãã§ã¯ãäŸµå ¥ãã¹ãã¯GrayBoxã¢ãŒãã§è¡ãããŸã-æ»æãããã€ã³ãã©ã¹ãã©ã¯ãã£ã«é¢ããéšåçãªæ å ±ãããã£ãŠããå Žåã ãã®å ŽåãããŒããšãã®ããŒã«ã瀺ããããããã¯ãŒã¯ãããããããŸãã
äŸµå ¥ãã¹ããè¡ãããã«æåã«å¿ èŠãªããšã¯ãæ å ±åéã§ãã äžè¬çãªããŒãã¹ãã£ã³ãŠãŒãã£ãªãã£ã§ããnmapã䜿çšããŸãã ãã®åŸãåãåã£ãæ å ±ãæåã§ç¢ºèªããŸããã€ãŸããtelnetã䜿çšããŠéããŠããããŒãã«æ¥ç¶ãããšãã®å¿çã確èªããçæãããhtmlããŒãžã®ã³ãŒãã確èªããŸãã
æ
å ±åé
ãŠãŒãã£ãªãã£ãnmap 192.168.101.5ããå®è¡ãããšã次ã®æ
å ±ãåŸãããŸããã
éããŠããããŒã22ã¯SSHã¢ã¯ã»ã¹ãæäŸããŸãã ä»ã®ãšããããããèŠããŠãããŠãã ããã
ã¡ãŒã«ãµãŒããŒã®ããŒã25ãéããŠããããšããããã¹ã¯ãŒãïŒBruteForceïŒãïŒweb-bruteforceãšã¯ç°ãªãïŒããªãé«éã§éžæã§ããããšã瀺åããŠãããããHydraã¯ãã«ãŒããã©ãŒã¹æ»æã«é©ããããŒã«ã§ãã ããŒã80ã§Webãµã€ãã確èªãããšã䜿çšãããã¢ã«ãŠã³ããã°ã€ã³ã«ãŒã«ã«é¢ããæ å ±ãåŸãããŸããã WebããŒãžã®ãœãŒã¹ã³ãŒãã§ãäŒç€Ÿã®åŸæ¥å¡ã®1人ã®é»åã¡ãŒã«ãèŠã€ããããšãã§ããŸãã
éããŠããããŒã22ã¯SSHã¢ã¯ã»ã¹ãæäŸããŸãã ä»ã®ãšããããããèŠããŠãããŠãã ããã
ã¡ãŒã«ãµãŒããŒã®ããŒã25ãéããŠããããšããããã¹ã¯ãŒãïŒBruteForceïŒãïŒweb-bruteforceãšã¯ç°ãªãïŒããªãé«éã§éžæã§ããããšã瀺åããŠãããããHydraã¯ãã«ãŒããã©ãŒã¹æ»æã«é©ããããŒã«ã§ãã ããŒã80ã§Webãµã€ãã確èªãããšã䜿çšãããã¢ã«ãŠã³ããã°ã€ã³ã«ãŒã«ã«é¢ããæ å ±ãåŸãããŸããã WebããŒãžã®ãœãŒã¹ã³ãŒãã§ãäŒç€Ÿã®åŸæ¥å¡ã®1人ã®é»åã¡ãŒã«ãèŠã€ããããšãã§ããŸãã
ååŸããæ
å ±ã䜿çšããŠæ»æããŸã
ããŒã8100ã§Webãµã€ãã確èªãããšãããã¯ããŒã25ã®ã¡ãŒã«ãµãŒããŒãžã®Webã€ã³ã¿ãŒãã§ã€ã¹ã§ããããšãããããŸãã ãã®æ
å ±ã¯åŸã§äœ¿çšããŸãããçŸæç¹ã§ã¯ãæ€åºãããã¢ã«ãŠã³ãã®ãã¹ã¯ãŒããéžæããŸãã
èŠã€ãã£ããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã¯ãWebã€ã³ã¿ãŒãã§ã€ã¹çµç±ã§SecureSoft LLCã®åŸæ¥å¡angela.allardã®ã¡ãŒã«ãžã®ã¢ã¯ã»ã¹ãæäŸããŸãã
angela.allardã®ã¡ãŒã«ãèŠããšãSecureSoft LLCã®åŸæ¥å¡ã®ãªã¹ããèŠã€ãããŸãã
ããã§ãäŒç€Ÿã®åŸæ¥å¡ã®å€§èŠæš¡ãªãªã¹ããèªç±ã«äœ¿çšã§ããããã«ãªããã¢ã«ãŠã³ããã°ã€ã³<name>ã<name>ãäœæããããžãã¯ã«ããããããããŸãã
çµæã®ãªã¹ããHydraã«ãã£ãŒããã...å°ãåŸ ã¡ãŸãã ãã°ããããŠãã¢ã«ãŠã³ãpauline.newmanãããã¹ã¯ãŒããååŸããŸãã ãã«ãŒããã©ãŒã¹æ»æïŒãã¹ã¯ãŒãæšæž¬ïŒã§ã¯ãGoogleãªã¯ãšã¹ãã§èŠã€ãã£ã人æ°ã®2014ãã¹ã¯ãŒãã§æ§æãããèŸæžã䜿çšãããŸããïŒèŸæžã®æºåã«5åããããŸããïŒã
2人ç®ã®åŸæ¥å¡ã®æçš¿ã¯ãããèå³æ·±ãæ å ±ãæäŸããŠãããŸããã æåã«ãMailã¿ã¹ã¯ããåæãããããŒã¯ã³ãåãåãã次ã«ãå®éšå®€ãééããããã®è¿œå æ å ±ãåãåããŸããã
èŠã€ãã£ããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã¯ãWebã€ã³ã¿ãŒãã§ã€ã¹çµç±ã§SecureSoft LLCã®åŸæ¥å¡angela.allardã®ã¡ãŒã«ãžã®ã¢ã¯ã»ã¹ãæäŸããŸãã
angela.allardã®ã¡ãŒã«ãèŠããšãSecureSoft LLCã®åŸæ¥å¡ã®ãªã¹ããèŠã€ãããŸãã
ããã§ãäŒç€Ÿã®åŸæ¥å¡ã®å€§èŠæš¡ãªãªã¹ããèªç±ã«äœ¿çšã§ããããã«ãªããã¢ã«ãŠã³ããã°ã€ã³<name>ã<name>ãäœæããããžãã¯ã«ããããããããŸãã
çµæã®ãªã¹ããHydraã«ãã£ãŒããã...å°ãåŸ ã¡ãŸãã ãã°ããããŠãã¢ã«ãŠã³ãpauline.newmanãããã¹ã¯ãŒããååŸããŸãã ãã«ãŒããã©ãŒã¹æ»æïŒãã¹ã¯ãŒãæšæž¬ïŒã§ã¯ãGoogleãªã¯ãšã¹ãã§èŠã€ãã£ã人æ°ã®2014ãã¹ã¯ãŒãã§æ§æãããèŸæžã䜿çšãããŸããïŒèŸæžã®æºåã«5åããããŸããïŒã
2人ç®ã®åŸæ¥å¡ã®æçš¿ã¯ãããèå³æ·±ãæ å ±ãæäŸããŠãããŸããã æåã«ãMailã¿ã¹ã¯ããåæãããããŒã¯ã³ãåãåãã次ã«ãå®éšå®€ãééããããã®è¿œå æ å ±ãåãåããŸããã
è¿œå ã®æ»æãã¯ãã«ãå®è£
ããŸã
ããã¯ãç 究宀ãééããããã®å
¥ééšåã§ããã¿ã¹ã¯ã®ããžãã¯ãç解ããæ®ãã®ã¿ã¹ã¯ãèªåã§è§£æ±ºããã®ã«åœ¹ç«ã€ããšãé¡ã£ãŠããŸãã
å®éã®äŸµå
¥ãã¹ããšåæ§ã«ãæ»æè
ã¯ãã¢ã¯ã»ã¹å¯èœãªããããå Žæã§æ»æãããã·ã¹ãã ã«é¢ããæ
å ±ãåéããŸãã
IT / ISæ åœè åãã«èšèšããããªãœãŒã¹ãæãèå³æ·±ãå ŽåããããŸãããããã¯ãŒã¯å šäœãžã®ã¢ã¯ã»ã¹ã«åœ¹ç«ã€éåžžã«éèŠãªæ å ±ãå«ãŸããŠããå ŽåããããŸãã èå³æ·±ããªãœãŒã¹ã¯ãæäŸãããå³-管çããŒã«ã«ããŒã¯ãããŠããŸãã nmapã䜿çšããŠãé¢å¿ã®ãããªãœãŒã¹ã®ããŒã1ã10000ã®ç¯å²ãã¹ãã£ã³ããŸãã
ã
äžéšã®ã¢ããªã±ãŒã·ã§ã³ãéæšæºããŒã3121ã§ãã³ã°ããŠããããšãããããŸãã çµéšçã«ã管çããŒã«ã®Webãµã€ããããã§èµ·åããããšå€æããŸãã
ãã®ãµã€ãã®æ©èœã¯åäœããŠããŸããã§ããã ã·ã¹ãã 管çè ã®äœæ¥ã容æã«ãããŠãŒãã£ãªãã£ãå«ãŸããŠããŸããã æåºãã©ãŒã ã®ããŒã«ãããã§ãSSHããŒãããŒããããŠããããšã瀺ããããã®ãã¡ã€ã«ããã®ãµãŒããŒã«ããããšã瀺åãããŸããã ãµã€ãã®æ§é ãšhtmlã³ãŒãã調ã¹ããšãããæçšãªãã®ã¯èŠã€ãããªãã£ããããdirbãŠãŒãã£ãªãã£ã䜿çšããŠãµã€ããã£ã¬ã¯ããªãã¹ãã£ã³ããããšã«ããŸããã
.bash_historyãã¡ã€ã«ãæ€åºãããŸããã ãã®ãã¡ã€ã«ã«ã¯ãããšãã°SSHãä»ããŠã³ã³ãœãŒã«ã§å®è¡ãããã³ãã³ãã®å±¥æŽãå«ãŸããŸãã ãã®ãã¡ã€ã«ã§ãSSHç§å¯éµã®åå-ssh_key.privãèŠã€ãããŸãããããã¯ããã«ãµã€ãããããŠã³ããŒããããŸããã
ããã§ãsshã䜿çšããŠããŒã22ããSecureSoft LLCã®å éšãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããããã®ããŒã¿ãåŸãããŸããã ãŸããssh_key.privãã¡ã€ã«ã§ã管çããŒã«ã¿ã¹ã¯ã®ããŒã¯ã³ãèŠã€ããããšãã§ããŸãã
IT / ISæ åœè åãã«èšèšããããªãœãŒã¹ãæãèå³æ·±ãå ŽåããããŸãããããã¯ãŒã¯å šäœãžã®ã¢ã¯ã»ã¹ã«åœ¹ç«ã€éåžžã«éèŠãªæ å ±ãå«ãŸããŠããå ŽåããããŸãã èå³æ·±ããªãœãŒã¹ã¯ãæäŸãããå³-管çããŒã«ã«ããŒã¯ãããŠããŸãã nmapã䜿çšããŠãé¢å¿ã®ãããªãœãŒã¹ã®ããŒã1ã10000ã®ç¯å²ãã¹ãã£ã³ããŸãã
ã
äžéšã®ã¢ããªã±ãŒã·ã§ã³ãéæšæºããŒã3121ã§ãã³ã°ããŠããããšãããããŸãã çµéšçã«ã管çããŒã«ã®Webãµã€ããããã§èµ·åããããšå€æããŸãã
ãã®ãµã€ãã®æ©èœã¯åäœããŠããŸããã§ããã ã·ã¹ãã 管çè ã®äœæ¥ã容æã«ãããŠãŒãã£ãªãã£ãå«ãŸããŠããŸããã æåºãã©ãŒã ã®ããŒã«ãããã§ãSSHããŒãããŒããããŠããããšã瀺ããããã®ãã¡ã€ã«ããã®ãµãŒããŒã«ããããšã瀺åãããŸããã ãµã€ãã®æ§é ãšhtmlã³ãŒãã調ã¹ããšãããæçšãªãã®ã¯èŠã€ãããªãã£ããããdirbãŠãŒãã£ãªãã£ã䜿çšããŠãµã€ããã£ã¬ã¯ããªãã¹ãã£ã³ããããšã«ããŸããã
.bash_historyãã¡ã€ã«ãæ€åºãããŸããã ãã®ãã¡ã€ã«ã«ã¯ãããšãã°SSHãä»ããŠã³ã³ãœãŒã«ã§å®è¡ãããã³ãã³ãã®å±¥æŽãå«ãŸããŸãã ãã®ãã¡ã€ã«ã§ãSSHç§å¯éµã®åå-ssh_key.privãèŠã€ãããŸãããããã¯ããã«ãµã€ãããããŠã³ããŒããããŸããã
ããã§ãsshã䜿çšããŠããŒã22ããSecureSoft LLCã®å éšãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããããã®ããŒã¿ãåŸãããŸããã ãŸããssh_key.privãã¡ã€ã«ã§ã管çããŒã«ã¿ã¹ã¯ã®ããŒã¯ã³ãèŠã€ããããšãã§ããŸãã
ãµã€ããŒæ»æã®äžçå°å³
ç¹ã«ç¬¬7ç 究æã®ç«ã¡äžãã®ããã«ãæ»æã®äžçå°å³ãå®è£ ãããŸããã æ»æã®èŠèŠåã«ãããåå è ã®å°çãèŠãããšãã§ããŸããã å·çæç¹ã®ããŒã¿ã«ãããšã63ãåœãš194ã®éœåžã®å°é家ãç 究宀ã«åå ããŸããã åå è ã®æ倧æ°ã¯ãã·ã¢ïŒ322 IPïŒã§ãããç±³åœïŒ64 IPïŒãç¶ãããŠã¯ã©ã€ããäžäœ3äœïŒ37 IPïŒãç· ãåããŸããã ã¢ã¹ã¯ã¯ã¯ãéœåžå¥ã®åºæIPã®ã©ã³ãã³ã°ïŒ242ã¢ãã¬ã¹ïŒã§éŠäœã«ãããããšãã¯2äœïŒ25ã¢ãã¬ã¹ïŒããããã¶ãŽã©ãŒãã¯ïŒ18ã¢ãã¬ã¹ïŒã¯3äœã§ãã
åå åœã®å šãªã¹ãïŒã¢ã«ãžã§ãªã¢ãã¢ã³ãã©ãã¢ã«ã¡ãã¢ããªãŒã¹ãã©ãªã¢ããªãŒã¹ããªã¢ãã¢ãŒã«ãã€ãžã£ã³ããã©ã«ãŒã·ããã«ã®ãŒããã¹ãã¢ããã³ãã«ãã§ãŽããããã©ãžã«ããã«ã¬ãªã¢ãã«ãããããªãäžåœãã¯ãã¢ãã¢ããããã¹ããã§ã³å ±ååœããã³ããŒã¯ããšãžããããšã¹ããã¢ããã£ã³ã©ã³ãããã©ã³ã¹ããžã§ãŒãžã¢ããã€ããã®ãªã·ã£ãéŠæž¯ïŒSARïŒããã³ã¬ãªãŒãã€ã³ããã€ã³ããã·ã¢ãã€ã©ã³ãã¢ã€ã«ã©ã³ããã€ã¹ã©ãšã«ãã€ã¿ãªã¢ãæ¥æ¬ãã«ã¶ãã¹ã¿ã³ãéåœåéšããã«ã®ã¹ã¿ã³ãã©ããã¢ããªãã¢ãã¢ãã¡ãã·ã³ãã¢ã«ããããªã©ã³ãããã«ãŠã§ãŒãããã¹ã¿ã³ããããããã£ãªãã³ãããŒã©ã³ãããã«ãã¬ã«ãã«ãŒããã¢ããã·ã¢ãã¹ãããã¢ãã¹ãã€ã³ãã¹ãŠã§ãŒãã³ãã¹ã€ã¹ãã·ãªã¢ãã¿ã€ããã«ã³ããŠã¯ã©ã€ããã¢ã©ãéŠé·åœé£éŠãè±åœãç±³åœããŠãºããã¹ã¿ã³ãã¶ã³ãã¢ã
ããªã±ãŒãã®å察åŽã äž»å¬è ã³ã¡ã³ã
æ¢ã«æ¡çšããŠããããã«ãç 究宀ã§ã®äœæ¥ã¯ããã€ãã®æ®µéã§è¡ãããŸãã
1.課é¡ã®ã¢ã€ãã¢ã®ææ¡ãšè°è«ã
2.ã¿ã¹ã¯ã®ãã¹ã¿ãŒçã®å®è£ ãæ€èšŒã
3.æçµããŒãžã§ã³ã«ãä»äžãããŸãã
4.äžè¬çãªã·ããªãªãžã®çµ±åã
ã©ãã®ç«ã¡äžãæã®åé¡ãåé¿ããããã«ãã¿ã¹ã¯ãå®è£ ããéã«ã¯æ¬¡ã®ã¿ã¹ã¯ãèæ ®ããå¿ èŠããããŸãã
-è€æ°ã®åå è ã«ãã課é¡ã®åæå®äºã®äºå®ã
-ãã¹ãŠã®åå è ããçœããŠãµããµããã§ã¯ãããŸããã ç Žå£è¡çºãä»ã®åå è ãžã®ã¢ã¯ã»ã¹ã劚ããè©Šã¿ã®å¯èœæ§ãæé€ããå¿ èŠããããŸãã
å Žåã«ãã£ãŠã¯ãã¿ã¹ã¯ãã·ã¹ãã ãå®å šã«å¶åŸ¡ããå¿ èŠãããããåæã«éåžžã«èå³æ·±ããããã©ãã«å«ããå¿ èŠãããå Žåã¯ã劥åããå¿ èŠããããŸãã 次ã«ããªã¹ã¯ãæå°éã«æããŸãã ããšãã°ãäžåºŠã«æå°æ°ã®åå è ã«ã¢ã¯ã»ã¹ãå¶éããã·ããªãªãæäŸããŸãã
ãã¡ãããæ»æããªã¢ã«ã¿ã€ã ã§ãå察åŽã«ãèŠãã®ã¯éåžžã«èå³æ·±ãã§ãã ãã®ç 究宀ã§ã¯ãäŸµå ¥æ€ç¥ã·ã¹ãã ã䜿çšããŠããªãã£ãããããã®ç¹ã«é¢ããŠåå è ã«ã¯å¶éããããŸããã§ããã ãããã芳å¯ã«åºã¥ããŠããã®ãããªã·ã¹ãã ã®ååšã¯ã»ãšãã©ã®æ»æãåæ ããŸãã ãããã次ã®ã©ãã§ã¯ãIDS / IPSã®åé¿çãå«ããŸãã
ã»ãšãã©ã®ããŒãã¹ãã£ã³ããã«ãŒããã©ãŒã¹ã¹ãã£ã³ããã£ã¬ã¯ããªã¹ãã£ã³ãªã©ã nmapã¹ã¯ãªãããšã³ãžã³ãUser-Agentã®DirBusterãªã©ãããã©ã«ãèšå®ã§ãããªãã¯ãŠãŒãã£ãªãã£ã«ãªããŸããã 課é¡ã®1ã€ã§ã¯ãåæ Œã®ããã«2ã€ã®ãªãã·ã§ã³ãæ®ããŸãããã2çªç®ã®ãªãã·ã§ã³ã§ã¯ä»ã®äººãå¹²æžããããšãèš±å¯ãããŠããã®ã§ãåå è ã奜ããªãã·ã§ã³ã確èªããããšã«ããŸããã æ®å¿µãªãããäºæ³ã©ããããã°ãããããšç Žå£è¡çºãå§ãŸããŸãã:)
æåã«ãäœãèµ·ãã£ãŠããã®ããææ¡ããç©Žãå¡ãããšãè©Šã¿ãŠãã管çè ã®ååšãè©ŠããŠãã·ãã¥ã¬ãŒãããããšã«ããŸããã çŽ1æéã圌ãã¯ã·ã§ã«ãžã®æ¥ç¶ãåæããããããé€å»ããããããæ¹æ³ã§å¹²æžããŸããããæªçšã®å¯èœæ§ãé®æããããšã¯ãããŸããã§ããã ããã«ãããããããç§ã¯ä»£æ¿ãªãã·ã§ã³ãéããªããã°ãªããŸããã§ããããªããªããæªæã®ãªãåå è ã®äžã«ã¯ãããŒã¯ã³èªäœã絶ããåé€ããããšãããããä»ã®äººããã®ã¿ã¹ã¯ãå®äºããã®ã劚ããŠããããã§ããæããã«ããã®ã¬ãã¹ã³ã¯ãã©ãèªäœãééãããããåã³ãäžããŸãã
åå è ã®ã³ã¡ã³ã
å®éšå®€ãäœæããŠããã ããããããšãããããŸãã äžéšã®ãœãªã¥ãŒã·ã§ã³ã¯æããã§ã¯ãããŸããã§ãããããã¹ãŠã®ã¿ã¹ã¯ã¯èå³æ·±ããã®ã§ããã äœããããsshããšããã¿ã¹ã¯ã奜ãã§ãããè匱æ§ãäœã§ããããç解ããããšããã®ã¯éåžžã«åºæ¿çã§ããã ãã®çµæãç 究宀ã¯æ°ããç¥èãç²åŸããæ¢åã®ç¥èãå®è·µãã絶奜ã®æ©äŒã§ãã
ã¡ãã³
ç 究宀ã«ã€ããŠã¯ãéåžžã«é¢çœããããã€ãã®ã¿ã¹ã¯ã¯éåžžã«å°é£ã ã£ããšèšããŸãã ç§ã¯ãŠã§ããäœããã奜ããªã®ã§ãããã©ãŒã©ã ããšåŒã°ããã¿ã¹ã¯ãããªãèå³æ·±ãã¢ã€ãã¢ãéåžžã«ã¯ãŒã«ãªå®è£ ã«èšåããããšæããŸãïŒç§ã¯ããŒã å šäœã«å¹žéãšçºå±ãé¡ã£ãŠããŸãããããŠå®éšå®€ã«æè¬ããŸããç§ã¯æ¬¡ã®å®éšå®€ãåŸ ã¡ãŸã
ããŒã¯ãã£ãã
ãã®èšäºã®èè ã®å ±åäœæ¥ãç¡é§ã«ãªãããæçšã§ããããšãå€æããããšãé¡ã£ãŠããŸãã PMã®ãã¹ãŠã®èŠæãšã³ã¡ã³ããæ€èšãããŠããã ããŸãã ã¿ãªãããè¯ãäžæ¥ãïŒ