ãŸããã
ãã®èšäºã¯ãç¹å®ã®åœã®ã€ã³ã¿ãŒãããã®ã¹ãã£ã³ã«ã€ããŠä»¥åã«å ¬éãããèšäºãšããŸãé¡äŒŒããŠããŸããããªããªããç§ã¯ã€ã³ã¿ãŒãããã®ç¹å®ã®ã»ã°ã¡ã³ããéããŠããŒããã¹ãã£ã³ããæã人æ°ã®ããè匱æ§ã®ååšã倧éã«ã¹ãã£ã³ãããšããç®æšãè¿œæ±ããŠããªãããã§ãã
ç§ã¯ãããå°ãç°ãªãé¢å¿ãæã£ãŠããŸãã-ããŸããŸãªæ¹æ³ã䜿çšããŠBYãã¡ã€ã³ãŸãŒã³å ã®ãã¹ãŠã®é¢é£ãµã€ããç¹å®ããShodanãVirusTotalãªã©ã®ãµãŒãã¹ãéããŠãIPããã³ãªãŒãã³ããŒããä»ããååçåµå¯ãå®è¡ããä»å±è³æã§ãã®ä»ã®æçšãªæ å ±ãåéããããã«ã䜿çšãããŠããæè¡ã®ã¹ã¿ãã¯ã決å®ããŸããµã€ãããã³ãŠãŒã¶ãŒã«é¢ããã»ãã¥ãªãã£ã¬ãã«ã«é¢ããããã€ãã®äžè¬çãªçµ±èšã®åœ¢æã«é¢ããæ å ±ã
å ¥éæžãšããŒã«ããã
æåã®èšç»ã¯ç°¡åã§ãããçŸåšã®ç»é²ãã¡ã€ã³ã®ãªã¹ãã«ã€ããŠã¯å°å ã®ã¬ãžã¹ãã©ã«åãåãããŠããããã¹ãŠã®å¯çšæ§ã確èªããæ©èœããŠãããµã€ãã®æ¢çŽ¢ãéå§ããŠãã ããã å®éã«ã¯ããã¹ãŠãã¯ããã«è€éã§ããããšãå€æããŸãã-BYãŸãŒã³ïŒçŽ13äžãã¡ã€ã³ïŒã«å®éã«ç»é²ãããŠãããã¡ã€ã³åã®å ¬åŒçµ±èšããŒãžãé€ãããã®çš®ã®æ å ±ã¯èªç¶ã§ããã誰ãæäŸããããããŸããã§ããã ãã®ãããªæ å ±ããªãå Žåã¯ãèªåã§åéããå¿ èŠããããŸãã
å®éãããŒã«ã®ç¹ã§ã¯ããã¹ãŠãéåžžã«ã·ã³ãã«ã§ãããªãŒãã³ãœãŒã¹ã«ç®ãåãããã€ã§ãäœããè¿œå ããæå°éã®æŸèæãä»äžããããšãã§ããŸãã æãäžè¬çãªãã®ã®ãã¡ã次ã®ããŒã«ã䜿çšãããŸããã
- Whatweb
- ã«ãŒã«
- æã
- wafw00f
- ãµãŒãããŒãã£APIïŒ VirusTotal ã Google SafeBrwosing ã Shodan ã Vulners ïŒ
ã¢ã¯ãã£ããã£ã®éå§ïŒåºçºç¹
ã¯ããã«ãå ã»ã©èšã£ãããã«ãçæ³çã«ã¯ãã¡ã€ã³åãé©åã§ããããã©ãã§å ¥æã§ããŸããïŒ ããåçŽãªãã®ããå§ããå¿ èŠããããŸãããã®å Žåã¯IPã¢ãã¬ã¹ãé©ããŠããŸãããéåŒãæ€çŽ¢ã§ã¯ãã¹ãŠã®ãã¡ã€ã³ããã£ããããããšã¯åžžã«å¯èœãšããããã§ã¯ãªãããã¹ãåãåéãããšãã«åžžã«æ£ãããã¡ã€ã³ãšã¯éããŸããã ãã®æ®µéã§ãç§ã¯åã³ãã®çš®ã®æ å ±ãåéããããã®å¯èœãªã·ããªãªã«ã€ããŠèãå§ããŸãã-ç§ãã¡ã®äºç®ãVPSã¬ã³ã¿ã«ã®5ãã«ã ã£ããšããäºå®ãèæ ®ãããæ®ãã¯ç¡æã§ãªããã°ãªããŸããã
æœåšçãªæ å ±æºïŒ
- IPã¢ãã¬ã¹ïŒ ip2locationãµã€ãïŒ
- ã¡ãŒã«ã¢ãã¬ã¹ã®2çªç®ã®éšåã«ãããã¡ã€ã³æ€çŽ¢ïŒãã ããã©ãã§å ¥æã§ããã®ãã以äžã§å°ã調ã¹ãŠã¿ãŸãããïŒ
- äžéšã®ã¬ãžã¹ãã©/ãã¹ãã£ã³ã°ãããã€ããŒã¯ããã®ãããªæ å ±ããµããã¡ã€ã³ã®åœ¢ã§æäŸããå ŽåããããŸã
- ãµããã¡ã€ã³ãšãã®åŸã®ãªããŒã¹ïŒSublist3rãšAquatoneãããã§åœ¹ç«ã¡ãŸãïŒ
- ãã«ãŒããã©ãŒã¹ãšæåå ¥åïŒé·ããéå±ã§ãããå¯èœã§ããããã®ãªãã·ã§ã³ã¯äœ¿çšããŸããã§ããïŒ
å°ãå ã«é²ã¿ããã®ã¢ãããŒãã§ããããçŽ5äžã®äžæã®ãã¡ã€ã³ãšãµã€ããåéã§ãããšèšããŸãïŒãã¹ãŠãåŠçããããšã¯ã§ããŸããã§ããïŒã 圌ãç©æ¥µçã«æ å ±ãåéãç¶ããŠããã°ã1ãææªæºã®äœæ¥ã§ç¢ºå®ã«ç§ã®ã³ã³ãã€ãŒãããŒã¿ããŒã¹å šäœããŸãã¯ãã®ã»ãšãã©ããã¹ã¿ãŒã§ããã§ãããã
ããžãã¹ã«åãæããã
以åã®èšäºã§ã¯ãIPã¢ãã¬ã¹ã«é¢ããæ å ±ã¯IP2LOCATIONãµã€ãããååŸãããŸããããæãããªçç±ã«ããããããã®èšäºã«åºãããããšã¯ãããŸããã§ããïŒãã¹ãŠã®ã¢ã¯ã·ã§ã³ããã£ãšæ©ãè¡ãããããïŒã 確ãã«ãç§ã®å Žåãã¢ãããŒãã¯ç°ãªã£ãŠããŸãã-ç§ã¯ããŒã¿ããŒã¹ãèªåã§ããŒã«ã«ã«ååŸãããCSVããæ å ±ãæœåºããªãããšã決ããŸããããç¶ç¶çã«ãµã€ãã§çŽæ¥å€æŽãç£èŠããåŸç¶ã®ãã¹ãŠã®ã¹ã¯ãªãããç®æšãåãäž»ãªããŒã¹ãšããŠ-ããŒãã«ãäœæããŸããããŸããŸãªåœ¢åŒã®IPã¢ãã¬ã¹ïŒCIDRããfromãããã³ãtoããªã¹ããåœã®ããŒã¯ïŒå¿µã®ããïŒãASçªå·ãASã®èª¬æã
ãã®åœ¢åŒã¯æé©ã§ã¯ãããŸãããããã¢ãš1åéãã®ããã¢ãŒã·ã§ã³ã§ã¯éåžžã«æºè¶³ããŠããŸãããASNã®ãããªè¿œå æ å ±ã絶ããæ±ããªãããã«ãèªå® ã§è¿œå ã§èšé²ããããšã«ããŸããã ãã®æ å ±ãååŸããããã«ãç§ã¯IpToASNãµãŒãã¹ã«ç®ãåããŸãããIpToASNãµãŒãã¹ã«ã¯äŸ¿å©ãªAPIïŒå¶éä»ãïŒããããå®éã«ã¯èªåã«çµ±åããã ãã§ãã
IP解æã³ãŒã
function ipList() { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "https://lite.ip2location.com/belarus-ip-address-ranges"); curl_setopt($ch, CURLOPT_HEADER, 0); curl_setopt($ch, CURLOPT_USERAGENT,'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.13) Gecko/20080311 Firefox/2.0.0.13'); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false); $ipList = curl_exec($ch); curl_close ($ch); preg_match_all("/(\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\<\/td\>\s+\<td\>\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3})/", $ipList, $matches); return $matches[0]; } function iprange2cidr($ipStart, $ipEnd){ if (is_string($ipStart) || is_string($ipEnd)){ $start = ip2long($ipStart); $end = ip2long($ipEnd); } else{ $start = $ipStart; $end = $ipEnd; } $result = array(); while($end >= $start){ $maxSize = 32; while ($maxSize > 0){ $mask = hexdec(iMask($maxSize - 1)); $maskBase = $start & $mask; if($maskBase != $start) break; $maxSize--; } $x = log($end - $start + 1)/log(2); $maxDiff = floor(32 - floor($x)); if($maxSize < $maxDiff){ $maxSize = $maxDiff; } $ip = long2ip($start); array_push($result, "$ip/$maxSize"); $start += pow(2, (32-$maxSize)); } return $result; } $getIpList = ipList(); foreach($getIpList as $item) { $cidr = iprange2cidr($ip[0], $ip[1]); }
IPãèŠã€ããåŸãããŒã¿ããŒã¹å šäœãéã«ãã¯ã¢ãããµãŒãã¹ã§å¶éãªãã§å®è¡ããå¿ èŠããããŸããããã¯ãéãé€ããŠäžå¯èœã§ãã
ããã«æé©ã§äœ¿ãããããµãŒãã¹ã®ãã¡ã次ã®2ã€ã«èšåããŸãã
- VirusTotal-1ã€ã®APIããŒããã®åŒã³åºãé »åºŠã®å¶é
- Hackertarget.comïŒAPIïŒ-1ã€ã®IPããã®ãããæ°ã®å¶é
å¶éããã€ãã¹ããŠã次ã®ãªãã·ã§ã³ãååŸãããŸããã
- æåã®ã±ãŒã¹ã§ã¯ãã·ããªãªã®1ã€ã¯15ç§ã®ã¿ã€ã ã¢ãŠãã«èããããšã§ãããåèšã§1åéã«4åã®åŒã³åºãããããé床ã«å€§ãã圱é¿ããå¯èœæ§ãããããã®ãããªå Žåã¯2ã3åã®ããŒã䜿çšãããšäŸ¿å©ã§ãããŠãŒã¶ãŒãšãŒãžã§ã³ãããããã·ããŠå€æŽããŸãã
- 2çªç®ã®ã±ãŒã¹ã§ã¯ãå ¬éãããŠããæ å ±ãæ€èšŒãããã³ãã®åŸã®äœ¿çšã«åºã¥ããŠãããã·ããŒã¿ããŒã¹ãèªå解æããããã®ã¹ã¯ãªãããäœæããŸããïŒãã ããVirusTotalã§ãååã ã£ããããåŸã§ãªãã·ã§ã³ãæ®ããŸããïŒ
ããã«é²ãã§ãã¡ãŒã«ã¢ãã¬ã¹ã«ã¹ã ãŒãºã«ç§»åããŸãã ãããã¯æçšãªæ å ±ã®ãœãŒã¹ã«ããªããŸãããã©ãã§ããããåéããã®ã§ããããïŒ è§£æ±ºçãèŠã€ããã®ã«é·ãæéã¯ããããŸããã§ãããã ãŠãŒã¶ãŒã¯ç§ãã¡ã®å人ãµã€ãã®ã»ã°ã¡ã³ããã»ãšãã©æããããããã®ã»ãšãã©ã¯çµç¹ã§ãããªã³ã©ã€ã³ã¹ãã¢ãã£ã¬ã¯ããªããã©ãŒã©ã ãæ¡ä»¶ä»ãããŒã±ãããã¬ã€ã¹ãªã©ã®ãããã¡ã€ã«Webãµã€ããç§ãã¡ã«åã£ãŠããŸãã
ããšãã°ããããã®ãµã€ãã®1ã€ãç°¡åã«ç¢ºèªãããšãããå€ãã®ãŠãŒã¶ãŒãèªåã®ãããªãã¯ãããã¡ã€ã«ã«çŽæ¥é»åã¡ãŒã«ãè¿œå ããŠãããããå°æ¥ã®äœ¿çšã«åããŠãã®ããžãã¹ãæ éã«è§£æã§ããŸãã
ããŒãµãŒã®1ã€
#!/usr/bin/env python3 import sys, threading, time, os, urllib, re, requests, pymysql from html.parser import HTMLParser from urllib import request from bs4 import BeautifulSoup # HEADERS CONFIG headers = { 'User-Agent': 'Mozilla/5.0 (Macintosh; Intel Mac OS X 11.9; rv:42.0) Gecko/20200202 Firefox/41.0' } file = open('dat.html', 'w') def parseMails(uid): page = 'https://profile.onliner.by/user/'+str(uid)+'' cookie = {'onl_session': 'YOUR_SESSION_COOOKIE_HERE'} r = requests.get(page, headers = headers, cookies = cookie) data = BeautifulSoup(r.text) userinfo = data.find_all('dl', {'class': 'uprofile-info'}) find_email = [] for item in userinfo: find_email += str(item.find('a')) get_mail = ''.join(find_email) detect_email = re.compile(".+?>(.+@.+?)</a>").search(get_mail) file.write("<li>('"+detect_email.group(1)+"'),</li>") for uid in range(1, 10000): t = threading.Thread(target=parseMails, args=(uid,)) t.start() time.sleep(0.3)
åãµã€ãã®è§£æã®è©³çŽ°ã«ã€ããŠã¯èª¬æããŸãããã©ããã§ç·åœããã§ãŠãŒã¶ãŒIDãæšæž¬ããæ¹ã䟿å©ãªå Žåãã©ãã§ãµã€ããããã解æããããããäŒæ¥ã®ããŒãžã«é¢ããæ å ±ãååŸããããããã¢ãã¬ã¹ãåéããæ¹ãç°¡åãªå Žåã§ãã ã¢ãã¬ã¹ãåéããåŸãããã€ãã®ç°¡åãªæäœãå®è¡ããŠãã¡ã€ã³ãŸãŒã³ã§ããã«äžŠã¹æ¿ãããããŒã«ããä¿æããŠæ¢åã®ããŒã¿ããŒã¹ããéè€ãé€å€ããŸãã
ãã®æ®µéã§ãã¹ã³ãŒãã®åœ¢æã«ãããç§ãã¡ã¯çµãããç¥æ§ã«é²ãããšãã§ãããšä¿¡ããŠããŸãã ã€ã³ããªãžã§ã³ã¹ã¯ãæ¢ã«ç¥ã£ãŠããããã«ãã¢ã¯ãã£ããšããã·ãã®2ã€ã®ã¿ã€ãããããŸãããã®å Žåãããã·ãã¢ãããŒããæãéèŠã§ãã ããããæªæã®ããè² è·ããããã«ããŒã80ãŸãã¯443ã§ãµã€ãã«ã¢ã¯ã»ã¹ããã ãã§ãè匱æ§ãæªçšããããšã¯éåžžã«æ£åœãªã¢ã¯ã·ã§ã³ã§ãã ç§ãã¡ã®é¢å¿ã¯ãåäžã®ãªã¯ãšã¹ãã«å¯ŸãããµãŒããŒã®å¿çã§ããå Žåã«ãã£ãŠã¯ã2ã€ã®ãªã¯ãšã¹ãïŒhttpããhttpsãžã®ãªãã€ã¬ã¯ãïŒãããããŸããªã±ãŒã¹ã§ã¯3ã€ïŒwwwã䜿çšãããå ŽåïŒããããŸãã
ç¥èœ
ãã¡ã€ã³ãªã©ã®æ å ±ã䜿çšããŠã次ã®ããŒã¿ãåéã§ããŸãã
- DNSã¬ã³ãŒãïŒNSãMXãTXTïŒ
- åçããããŒ
- 䜿çšãããŠããæè¡ã¹ã¿ãã¯ãç¹å®ãã
- ãµã€ããæ©èœãããããã³ã«ãç解ããŸãã
- çŽæ¥ã¹ãã£ã³ããã«ïŒShodan / CensysããŒã¿ããŒã¹ã«åºã¥ããŠïŒéããŠããããŒããç¹å®ããŠãã ãã
- Shodan / Censysããã®æ å ±ãšVulnersããŒã¿ããŒã¹ã®çžé¢é¢ä¿ã«åºã¥ããŠè匱æ§ãç¹å®ããŠãã ãã
- Googleã»ãŒããã©ãŠãžã³ã°ãã«ãŠã§ã¢ããŒã¿ããŒã¹ã«ããã
- ãã¡ã€ã³ããšã«é»åã¡ãŒã«ã¢ãã¬ã¹ãåéããæ¢ã«èŠã€ãã£ããã®ãšäžèŽãããç§ã¯PwnedãããŠããŸããã§ç¢ºèªããŸããããã«ããœãŒã·ã£ã«ãããã¯ãŒã¯ã«ãªã³ã¯ããŸãã
- ãã¡ã€ã³ã¯ãå Žåã«ãã£ãŠã¯äŒç€Ÿã®é¡ã ãã§ãªãããã®æŽ»åã®è£œåããµãŒãã¹ãžã®ç»é²çšã®é»åã¡ãŒã«ã¢ãã¬ã¹ãªã©ã§ããããŸã-GitHubãPastebinãGoogle DorksïŒGoogle CSEïŒãªã©ã®ãªãœãŒã¹ã§ãããã«é¢é£ä»ããããæ å ±ãæ€çŽ¢ã§ããŸãïŒ
ãã€ã§ãå ã«é²ã¿ããªãã·ã§ã³ã®masscanãŸãã¯nmapãzmapãå©çšããŠãã©ã³ãã ãªæéãŸãã¯ããã€ãã®ã€ã³ã¹ã¿ã³ã¹ããã§ãèµ·åããŠTorãä»ããŠæåã«èšå®ããããšãã§ããŸãããä»ã®ç®æšããããååã¯ç§ãçŽæ¥ã¹ãã£ã³ãè¡ããªãã£ãããšãæå³ããŸã
DNSã¬ã³ãŒããåéããã¯ãšãªãšAXFRãªã©ã®æ§æãšã©ãŒãå¢å¹ ããå¯èœæ§ã確èªããŸãã
NSãµãŒããŒã¬ã³ãŒããåéããäŸ
dig ns +short $domain | sed 's/\.$//g' | awk '{print $1}'
MXã¬ã³ãŒãã³ã¬ã¯ã·ã§ã³ã®äŸïŒNSãåç §ããnsãããmxãã«çœ®ãæããŠãã ããïŒ
AXFRã確èªããŸãïŒããã«ã¯å€ãã®è§£æ±ºçããããŸããããã«ã¯å¥ã®æŸèæããããŸãããã»ãã¥ãªãã£ã§ã¯ãªããåºåã衚瀺ããããã«äœ¿çšããŸããïŒ
$digNs = trim(shell_exec("dig ns +short $domain | sed 's/\.$//g' | awk '{print $1}'")); $ns = explode("\n", $digNs); foreach($ns as $target) { $axfr = trim(shell_exec("dig -t axfr $domain @$target | awk '{print $1}' | sed 's/\.$//g'")); $axfr = preg_replace("/\;/", "", $axfr); if(!empty(trim($axfr))) { $axfr = preg_replace("/\;/", "", $axfr); $res = json_encode(explode("\n", trim($axfr)));
DNSå¢å¹
ã確èªãã
ç§ã®å ŽåãNSãµãŒããŒã¯ããŒã¿ããŒã¹ããååŸãããã®ã§ãå€æ°ã®æåŸã«ãå®éã«ã¯ä»»æã®ãµãŒããŒã ãã眮ãæããããšãã§ããŸãã ãã®ãµãŒãã¹ã®çµæã®æ£ç¢ºæ§ã«é¢ããŠãããã§ãã¹ãŠãã¹ã ãŒãºã«æ©èœããçµæãåžžã«æå¹ã§ããããšã確信ã§ããŸããããçµæã®ã»ãšãã©ãæ¬ç©ã§ããããšãæã¿ãŸãã
dig +short test.openresolver.com TXT @$dns
ç§ã®å ŽåãNSãµãŒããŒã¯ããŒã¿ããŒã¹ããååŸãããã®ã§ãå€æ°ã®æåŸã«ãå®éã«ã¯ä»»æã®ãµãŒããŒã ãã眮ãæããããšãã§ããŸãã ãã®ãµãŒãã¹ã®çµæã®æ£ç¢ºæ§ã«é¢ããŠãããã§ãã¹ãŠãã¹ã ãŒãºã«æ©èœããçµæãåžžã«æå¹ã§ããããšã確信ã§ããŸããããçµæã®ã»ãšãã©ãæ¬ç©ã§ããããšãæã¿ãŸãã
äœããã®ç®çã§ããµã€ããžã®å®å šãªæçµURLãä¿æããå¿ èŠãããå Žåããã®ããã«cURLã䜿çšããŸããã
curl -I -L $target | awk '/Location/{print $2}'
圌èªèº«ããªãã€ã¬ã¯ãå šäœãå®è¡ããæåŸã®ãªãã€ã¬ã¯ãã衚瀺ããŸãã çŸåšã®ãµã€ãã®URLã ç§ã®å Žåãããã¯WhatWebãªã©ã®ããŒã«ã®ãã®åŸã®äœ¿çšã«éåžžã«åœ¹ç«ã¡ãŸããã
ãªãããã䜿çšããå¿ èŠããããŸããïŒ OSãWebãµãŒããŒãCMSãµã€ããäžéšã®ããããŒãJS / HTMLã©ã€ãã©ãª/ãã¬ãŒã ã¯ãŒã¯ãªã©ã®è¿œå ã¢ãžã¥ãŒã«ãããã³åãã¢ã¯ãã£ããã£ãã£ãŒã«ãã§åŸã§ãã£ã«ã¿ãªã³ã°ãè©Šã¿ãããšãã§ãããµã€ãã¿ã€ãã«ã決å®ããããã
ãã®å Žåã®éåžžã«äŸ¿å©ãªãªãã·ã§ã³ã¯ãããŒã«ã®çµæãXML圢åŒã§ãšã¯ã¹ããŒãããŠåŸç¶ã®åæãè¡ããåŸã§åŠçããç®æšãããå Žåã¯ããŒã¿ããŒã¹ã«ã€ã³ããŒãããããšã§ãã
whatweb --no-errors https://www.mywebsite.com --log-xml=results.xml
ç§èªèº«ã¯ãåºåã®çµæãšããŠJSONãäœæãããããããŒã¿ããŒã¹ã«å ¥ããŸããã
ããããŒã«ã€ããŠèšãã°ã次ã®åœ¢åŒã®ã¯ãšãªãå®è¡ããããšã«ãããéåžžã®cURLã§ã»ãŒåãããšãå®è¡ã§ããŸãã
curl -I https://www.mywebsite.com
ããããŒã§ãããšãã°æ£èŠè¡šçŸã䜿çšããŠCMSããã³WebãµãŒããŒã®æ å ±ããã£ããããŸãã
æçšãªãã®ã«å ããŠãShodanã䜿çšããŠéããŠããããŒãã«é¢ããæ å ±ãåéããæ¢ã«ååŸããããŒã¿ã䜿çšããŠãAPIã䜿çšããŠVulnersããŒã¿ããŒã¹ã確èªããããšãã§ããŸãïŒãµãŒãã¹ãžã®ãªã³ã¯ã¯ããããŒã«ãããŸãïŒã ãã¡ããããã®ã·ããªãªã§ã¯æ£ç¢ºæ§ã«åé¡ããããããããŸããããããã¯æåæ€èšŒã«ããçŽæ¥ã¹ãã£ã³ã§ã¯ãªãããµãŒãããŒãã£ã®ãœãŒã¹ããã®ããŒã¿ã®åãªãããžã£ã°ãªã³ã°ãã§ãããå°ãªããšãäœããªãããã¯ãŸãã§ãã
Shodanã®PHPé¢æ°
function shodanHost($host) { $ch = curl_init(); curl_setopt($ch, CURLOPT_URL, "https://api.shodan.io/shodan/host/".$host."?key=<YOUR_API_KEY>"); curl_setopt($ch, CURLOPT_HEADER, 0); curl_setopt($ch, CURLOPT_USERAGENT,'Mozilla/5.0 (Windows; U; Windows NT 5.1; en-US; rv:1.8.1.13) Gecko/20080311 Firefox/2.0.0.13'); curl_setopt($ch, CURLOPT_RETURNTRANSFER, true); curl_setopt($ch, CURLOPT_SSL_VERIFYPEER, false); curl_setopt($ch, CURLOPT_SSL_VERIFYHOST, false); $shodanResponse = curl_exec($ch); curl_close ($ch); return json_decode($shodanResponse); }
ãã®ãããªæ¯èŒåæã®äŸïŒ1
äŸ2
ã¯ãã圌ãã¯APIã«ã€ããŠè©±ãå§ããã®ã§ãVulnersã«ã¯å¶éããããæãæé©ãªè§£æ±ºçã¯Pythonã¹ã¯ãªããã䜿çšããããšã§ããPHPã®å Žåãããã€ãã®å°ããªå°é£ã«ééããŸããïŒåã³è¿œå ããŸãïŒã¿ã€ã ã¢ãŠãã¯ç¶æ³ãä¿åããŸããïŒã
ææ°ã®ãã¹ãã®1ã€-ãwafw00fããªã©ã®ã¹ã¯ãªããã§äœ¿çšããããã¡ã€ã¢ãŠã©ãŒã«ã«é¢ããæ å ±ã調æ»ããŸãã ãã®ãã°ãããããŒã«ããã¹ããããšãã1ã€ã®èå³æ·±ãããšã«æ°ã¥ããŸããã䜿çšãããŠãããã¡ã€ã¢ãŠã©ãŒã«ã®ã¿ã€ããå€å¥ã§ããã®ã¯å¿ ãããåããŠã§ã¯ãããŸããã§ããã
wafw00fãæœåšçã«æ€åºã§ãããã¡ã€ã¢ãŠã©ãŒã«ã®ã¿ã€ãã確èªããã«ã¯ã次ã®ã³ãã³ããå ¥åã§ããŸãã
wafw00f -l
ãã¡ã€ã¢ãŠã©ãŒã«ã®ã¿ã€ãã決å®ããããã«ãwafw00fã¯ãµã€ãã«æšæºãªã¯ãšã¹ããéä¿¡ããåŸããµãŒããŒã®ã¬ã¹ãã³ã¹ããããŒãåæããŸãããã®è©Šè¡ãååã§ãªãå Žåãè¿œå ã®ç°¡åãªãã¹ããªã¯ãšã¹ããçæããŸãã ã
ãªããªã çµ±èšã«ã€ããŠã¯ãå®éããã¹ãŠã®åçã¯å¿ èŠãããŸãããæ£èŠè¡šçŸã䜿çšããŠäœåãªéšåããã¹ãŠåé€ãããã¡ã€ã¢ãŠã©ãŒã«ãšããååã®ã¿ãæ®ããŸãã
/is\sbehind\sa\s(.+?)\n/
ããŠãå ã»ã©æžããããã«ããã¡ã€ã³ãšãµã€ãã«é¢ããæ å ±ã«å ããŠãé»åã¡ãŒã«ã¢ãã¬ã¹ãšãœãŒã·ã£ã«ãããã¯ãŒã¯ã«é¢ããæ å ±ãããã·ãã¢ãŒãã§æŽæ°ãããŸããã
ã¡ãŒã«ãã¡ã€ã³åºæã®çµ±èš
ãœãŒã·ã£ã«ãããã¯ãŒã¯ã®ã¡ãŒã«ã¢ãã¬ã¹ãžã®ãã€ã³ãã決å®ããäŸ
æãç°¡åãªæ¹æ³ã¯ãTwitterïŒ2ã€ã®æ¹æ³ïŒã§ã¢ãã¬ã¹æ€èšŒãåŠçããããšã§ãããããã®ç¹ã§FacebookïŒ1ã€ã®æ¹æ³ïŒã¯ãå®éã®ãŠãŒã¶ãŒã»ãã·ã§ã³ãçæããããã®ããè€éãªã·ã¹ãã ã®ãããå°ãè€éã«ãªããŸããã
ãã©ã€çµ±èšã«ç§»ããŸãããã
DNSçµ±èš
ãããã€ããŒ-ãµã€ãæ°
ns1.tutby.comïŒ10899
ns2.tutby.comïŒ10899
ns1.neolocation.comïŒ4877
ns2.neolocation.comïŒ4873
ns3.neolocation.comïŒ4572
ns1.activeby.netïŒ4231
ns2.activeby.netïŒ4229
u1.hoster.byïŒ3382
u2.hoster.byïŒ3378
èŠã€ãã£ãäžæã®DNSïŒ2462
äžæã®MXïŒã¡ãŒã«ïŒãµãŒããŒïŒ9175ïŒäžè¬çãªãµãŒãã¹ã«å ããŠãç¬èªã®ã¡ãŒã«ãµãŒãã¹ã䜿çšãã管çè ãååãªæ°ããŸãïŒ
DNSãŸãŒã³è»¢éã®åœ±é¿ïŒ1011
DNSå¢å¹ ã®åœ±é¿ïŒ531
å°æ°ã®CloudFlareãã¡ã³ïŒ375ïŒäœ¿çšãããŠããNSã¬ã³ãŒãã«åºã¥ãïŒ
CMSçµ±èš
CMS-æ°é
ã¯ãŒããã¬ã¹ïŒ5118
JoomlaïŒ2722
BitrixïŒ1757
DrupalïŒ898
OpenCartïŒ235
ããŒã¿ã©ã€ãïŒ133
MagentoïŒ32
- æœåšçã«è匱ãªWordPressã€ã³ã¹ããŒã«ïŒ2977
- Joomlaã®æœåšçã«è匱ãªã€ã³ã¹ããŒã«ïŒ212
- Google SafeBrowsingãµãŒãã¹ã䜿çšããŠãæœåšçã«å±éºãªãµã€ããŸãã¯ææãããµã€ããç¹å®ããããšãã§ããŸããïŒçŽ10,000ïŒããŸããŸãªæç¹ã§ã誰ããä¿®æ£ãããæããã«å£ãããçµ±èšã¯å®å šã«å®¢èŠ³çã§ã¯ãããŸããïŒ
- HTTPããã³HTTPSã«ã€ããŠ-èŠã€ãã£ãããªã¥ãŒã ã®ååæªæºã®ãµã€ããåŸè ã䜿çšããŠããŸãããããŒã¿ããŒã¹ãå®å šã§ã¯ãªããç·æ°ã®40ïŒ ã«ãããªããšããäºå®ãèæ ®ãããšãåŸåã®ã»ãšãã©ã®ãµã€ããHTTPSãä»ããŠéä¿¡ã§ããå¯èœæ§ã¯ååã«ãããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«çµ±èšïŒ
ãã¡ã€ã¢ãŠã©ãŒã«-çªå·
ModSecurityïŒ4354
IBM Webã¢ããªã®ã»ãã¥ãªãã£ïŒ126
ããè¯ãWPã»ãã¥ãªãã£ïŒ110
CloudFlareïŒ104
Imperva SecureSphereïŒ45
ãžã¥ãããŒWebAppã»ãã¥ã¢ïŒ45
WebãµãŒããŒã®çµ±èš
WebãµãŒããŒ-çªå·
NginxïŒ31752
ApacheïŒ4042
IISïŒ959
Nginxã®å€ããæœåšçã«è匱ãªã€ã³ã¹ããŒã«ïŒ20966
Apacheã®å€ããæœåšçã«è匱ãªã€ã³ã¹ããŒã«ïŒ995
hoster.byã¯ãã¡ã€ã³ãšãã¹ãã£ã³ã°ã®ãªãŒããŒã§ãããšããäºå®ã«ãããããããããšãã°ãäžè¬ã«Open Contactãéç«ã£ãŠããŸããããçå®ã¯1ã€ã®IPäžã®ãµã€ãã®æ°ã«ãããŸãã
IP-ãµã€ã
93.84.119.243ïŒ556
93.125.99.83ïŒ399
193.232.92.25ïŒ386
é»åã¡ãŒã«ã§ã詳现ãªçµ±èšæ å ±ãååŸããããã¡ã€ã³ãŸãŒã³ã§äžŠã¹æ¿ããããšã«æ±ºããŸãããããããç¹å®ã®ãã³ããŒã«å¯ŸãããŠãŒã¶ãŒã®å Žæã確èªããããšã¯èå³æ·±ããã®ã§ããã
- TUT.BYãµãŒãã¹ïŒ38282
- YandexãµãŒãã¹ã§ïŒby | ruïŒïŒ28127
- GmailãµãŒãã¹ïŒ33452
- Facebookã«æ¥ç¶ïŒ866
- Twitterã«çžãããïŒ652
- HIBPã«ãããªãŒã¯ã§ã®æ³šç®ïŒ7844
- ããã·ãã€ã³ããªãžã§ã³ã¹ã«ããã13,000以äžã®ã¡ãŒã«ã¢ãã¬ã¹ãèå¥ã§ããŸãã
ã芧ã®ãšãããäžè¬çã«ããã®æ§å³ã¯éåžžã«å¥œæçã§ãããç¹ã«ãã¹ãã£ã³ã°ãããã€ããŒã®äžéšããã®nginxã®ç©æ¥µçãªäœ¿çšã¯åã°ããŸããã ãããããããã¯äžè¬çãªãŠãŒã¶ãŒã®éã§äººæ°ã®ãããã¹ãã£ã³ã°ã¿ã€ããã€ãŸãå ±æãã¹ãã£ã³ã°ã¿ã€ãã«ãããã®ã§ãã
ç§ã¯ãããæ¬åœã«å¥œãã§ã¯ãªãã£ããšããäºå®ãã-AXFRã®ãããªãšã©ãŒã«æ°ã¥ããå€ãããŒãžã§ã³ã®SSHãšApacheã䜿çšããããã«ãã³ãã®ãã¹ãã£ã³ã°ãããã€ããŒãååãªæ°ãããŸãã ããã§ã¯ããã¡ãããç¶æ³ã«ã€ããŠã®ããå€ãã®å ãã¢ã¯ãã£ããªãã§ãŒãºã«ãã£ãŠè±èœããå¯èœæ§ããããŸãããçŸæç¹ã§ã¯ãç§ãã¡ã®æ³åŸã«ãããããã¯ç§ã«ã¯äžå¯èœã«æããŸããç§ã¯ãã®ãããªåé¡ã®ããã«å®³è«ã®ã©ã³ã¯ã«åå ããããããŸããã
ããªãããããåŒã³åºãããšãã§ããã°ãé»åã¡ãŒã«ã®ç»åã¯äžè¬çã«ããªããã©è²ã§ãã ãããTUT.BYãããã€ããŒã瀺ãããŠããå Žæ-ããã¯ãã¡ã€ã³ã䜿çšããããšãæå³ããŸãã ãã®ãµãŒãã¹ã¯ãYandexã«åºã¥ããŠæ©èœããŸãã
ãããã«
çµè«ãšããŠãç§ã¯1ã€ã®ããšãèšãããšãã§ããŸã-å©çšå¯èœãªçµæã§ãã£ãŠããããªãã¯ãŠã€ã«ã¹ãããµã€ãããããã«ããWAFãèšå®ããç°ãªãCMSãèšå®/è¿œå ããããšã«é¢äžããŠããå°é家ã®ããã«å€§éã®ä»äºãããããšãããã«ç解ã§ããŸãã
ãŸããçå£ã«ãåã®2ã€ã®èšäºã®ããã«ãåé¡ã¯ã€ã³ã¿ãŒããããšåœã®ãã¹ãŠã®ã»ã°ã¡ã³ãã§ãŸã£ããç°ãªãã¬ãã«ã«ååšããæ»æçãªæ¹æ³ãªã©ã䜿çšããã«åé¡ããªã¢ãŒãã§èª¿æ»ããå Žåã§ããããã€ãã®åé¡ãçºçããããšãããããŸãeã å ¬çã«å ¥æå¯èœãªæ å ±ã䜿çšããŠãã©ã®ç¹å¥ãªã¹ãã«ãäžèŠããåéããŸãã