๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ

์ „์ฒด ๊ธ€37

๋ฉ”์ผ์— ์ˆจ๊ฒจ์ง„ ์ •๋ณด ํ™•์ธํ•˜๊ธฐ ์˜ค๋Š˜์€ E-mail์— ๋‹ด๊ฒจ์žˆ๋Š” ์ •๋ณด๋ฅผ ํ™•์ธ ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ณด๊ณ ์ž ํ•ฉ๋‹ˆ๋‹ค ์ด๋ฒˆ์— ํ™œ์šฉํ•  ๋ฉ”์ผ์„ ๋‹ค์šด ๋ฐ›๊ธฐ ์œ„ํ•ด ์ƒ˜ํ”Œ์„ ๋งŒ๋“ค์–ด ๋ด…๋‹ˆ๋‹ค 1. ๋‹ค์Œ ๋ฉ”์ผ์—์„œ --> ์ €์˜ ๊ตฌ๊ธ€ ๊ณ„์ •์œผ๋กœ ํ…Œ์ŠคํŠธ ๋ฉ”์ผ ํ•œํ†ต์„ ๋ณด๋‚ธ ํ›„ ๊ตฌ๊ธ€์˜ ๋ฉ”์ผํ•จ์˜ ๋ฉ”์ผ์„ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค 2. ๋ฉ”์ผ์˜ ์›๋ณธ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œ ํ•ฉ๋‹ˆ๋‹ค 3. ๋‹ค์šด๋กœ๋“œ ํ›„ ํ•ด๋‹น ํŒŒ์ผ์„ ๋ฉ”๋ชจ์žฅ์œผ๋กœ ์—ด์–ด์„œ ๊ด€๋ จ ์ •๋ณด๋ฅผ ํ™•์ธ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค - X-Originating-IP : ๋ฉ”์ผ ๋ฐœ์†ก์ž์˜ PC IP - Return-Path : ๋ฉ”์ผ ๋ฐœ์†ก์— ์‹คํŒจ ํ–ˆ์„ ๋•Œ ๋ฐ˜์†ก๋˜๋Š” ์ฃผ์†Œ - Authentication : ๋ฉ”์ผ์„ ์ฃผ๊ณ  ๋ฐ›๊ธฐ ์œ„ํ•œ ์•”ํ˜ธํ™” ๊ด€๋ จ ์ •๋ณด - Received : ๋ฉ”์ผ์ด ์–ด๋””๋ฅผ ๊ฑฐ์ณ์„œ ๋„์ฐฉํ•˜๊ฒŒ ๋˜์—ˆ๋Š”์ง€ ๊ฒฝ๋กœ๋ฅผ ํ™•์ธ ๊ฐ€๋Šฅ ( ์•„๋ž˜์„œ ๋ถ€ํ„ฐ ์œ„๋กœ ์ง€๋‚˜์˜จ ๊ฒฝ๋กœ๊ฐ€ ์Œ“์ธ๋‹ค ) Delivered-.. 2021. 9. 26.
๋ฐฉํ™”๋ฒฝ, DMZ ๋ž€? DMZ ๋‚ด·์™ธ๋ถ€ ๋„คํŠธ์›Œํฌ ๊ตฌ๊ฐ„ ์‚ฌ์ด์— ์œ„์น˜ํ•œ ์ค‘๊ฐ„์ง€์ ์œผ๋กœ, ์นจ์ž…์ฐจ๋‹จ์‹œ์Šคํ…œ ๋“ฑ์œผ๋กœ ์ ‘๊ทผ ์ œํ•œ ๋“ฑ์„ ์ˆ˜ํ–‰ํ•˜์ง€๋งŒ ์™ธ๋ถ€ ๋„คํŠธ์›Œํฌ์—์„œ ์ง์ ‘ ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•œ ์˜์—ญ ๋ฐฉํ™”๋ฒฝ ๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ, ์™ธ๋ถ€ ๋„คํŠธ์›Œํฌ, DMZ ๊ตฌ๊ฐ„์„ ์‚ฌ์ด์—์„œ ์ž์›์„ ๋ณดํ˜ธํ•˜๋Š” ์—ญํ• ์„ ํ•œ๋‹ค. 1. ๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ - ์™ธ๋ถ€์˜ ๋„คํŠธ์›Œํฌ๊ฐ€ ์•„๋‹Œ ๋‚ด๋ถ€์—์„œ PC ์™€ PC ์‚ฌ์ด์—์„œ ์ž์›์„ ๊ณต์œ  ํ•˜๊ฑฐ๋‚˜ ํšŒ์‚ฌ์˜ ERP ์‹œ์Šคํ…œ, ๊ทธ๋ฃน์›จ์–ด... ๋“ฑ์„ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•˜๋„๋ก ํ•˜๋Š” ํ†ต์‹ ๋ง์„ ์˜๋ฏธํ•œ๋‹ค. 2. ์™ธ๋ถ€ ๋„คํŠธ์›Œํฌ - ์™ธ๋ถ€ ๋„คํŠธ์›Œํฌ๋Š” ๋‚ด๋ถ€๊ฐ€ ์•„๋‹Œ ์™ธ๋ถ€์˜ ๋‹ค๋ฅธ ์„œ๋น„์Šค์—๋„ ์ ‘๊ทผ ๊ฐ€๋Šฅํ•œ ๋„คํŠธ์›Œํฌ ์ฆ‰ www๋ฅผ ๋œปํ•œ๋‹ค. 3. DMZ - ์‹œ์Šคํ…œ์—์„œ ์‚ฌ๋‚ด๊ฐ€ ์•„๋‹Œ ์™ธ๋ถ€๋กœ ์„œ๋น„์Šค ์ œ๊ณต์ด ํ•„์š”ํ•œ ๊ฒฝ์šฐ ๊ตฌ์„ฑํ•˜๋Š” ๋ฐฉ์‹ - ๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ ๊ตฌ๊ฐ„๊ณผ ์™ธ๋ถ€ ๋„คํŠธ์›Œํฌ ๊ตฌ๊ฐ„ ์‚ฌ์ด์—์„œ ์ ‘๊ทผ ์ œํ•œ(๋ฐฉํ™”๋ฒฝ)์„ ์ˆ˜ํ–‰ํ•œ.. 2021. 6. 28.
IP ์™ธ๋ถ€ ํ‰ํŒ ์กฐํšŒ - AbuseIPDB ์•ˆ๋…•ํ•˜์„ธ์š” ๐Ÿ˜Š ์˜ค๋Š˜ ์†Œ๊ฐœํ•ด๋“œ๋ฆด ์‚ฌ์ดํŠธ๋Š” IP์˜ ํ‰ํŒ์„ ์กฐํšŒ ํ•  ์ˆ˜ ์žˆ๋Š” ๊ณณ ์ž…๋‹ˆ๋‹ค. ์•„๋ž˜์™€ IP ๊ฒ€์ƒ‰์œผ๋กœ ๊ฐ™์ด ํ•ด๋‹น IP์˜ ๋“ฑ๋ก ๊ตญ๊ฐ€, Hostname, ISP ์—…์ฒด๋ฅผ ํ™•์ธ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค ๋˜ํ•œ ์•„๋ž˜ ์ฒ˜๋Ÿผ AbuseIPDB์€ ๋‹ค์–‘ํ•œ ์‚ฌ์šฉ์ž๋“ค์ด ํ•ด๋‹น IP์— ๋Œ€ํ•ด์„œ Report๋ฅผ ์ œ์ถœํ•˜๋ฉฐ ํ•ด๋‹น IP์— ๋Œ€ํ•œ ๋‹ค์–‘ํ•œ ์˜๊ฒฌ์„ ํ™•์ธ ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. www.abuseipdb.com/ AbuseIPDB - IP address abuse reports - Making the Internet safer, one IP at a time Check an IP Address, Domain Name, or Subnet e.g. 211.249.218.4, microsoft.com, or 5.188.10.0/24 www.abuseipd.. 2021. 4. 25.
Web Browser ๋กœ๊ทธ ๋ถ„์„ / Browser History Examiner Windows ์ธํ„ฐ๋„ท ๋ธŒ๋ผ์šฐ์ € ๋กœ๊ทธ๋ฅผ ์กฐํšŒ ํ•  ์ˆ˜ ์žˆ๋Š” ํ”„๋กœ๊ทธ๋žจ์ž…๋‹ˆ๋‹ค IE ๊ธฐ์ค€ Browser ์˜ Log File ์ˆ˜์ง‘ ๊ฒฝ๋กœ๋Š” ์•„๋ž˜์™€ ๊ฐ™์Šต๋‹ˆ๋‹ค ํ•ด๋‹น ํˆด์€ ๋ฌด๋ฃŒ์ธ ์ค„ ์•Œ์•˜๋Š”๋ฐ ์ตœ๊ทผ์— ๋‹ค์‹œ ๋‹ค์šด๋ฐ›์•„์„œ ์‚ฌ์šฉํ•˜๋ ค ํ•˜๋‹ˆ ์œ ๋ฃŒ๋„ค์š”...ใ…  25์ผ๊ฐ„์€ ๋ฌด๋ฃŒ๋กœ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. 1. ๋‹ค์šด๋กœ๋“œ ํŽ˜์ด์ง€ https://www.foxtonforensics.com/browser-history-examiner/ Browser History Examiner - Analyse & report on web browser activity Cached Image Gallery Browse the images a user has viewed online using the built-in image gallery. www.foxton.. 2020. 12. 7.
Buffer Over Flow - Protostar ๋ฌธ์ œ ์ด๋ฒˆ์— Buffer Over Flow ๊ด€๋ จ ๋ฌธ์ œ๋ฅผ ํ•œ๋ฒˆ ํ’€์–ด๋ณด์•˜๋‹ค. ์šฐ์„  Buffer Over Flow์˜ ์˜๋ฏธ๋Š” ์•„๋ž˜์™€ ๊ฐ™๋‹ค. ํ”„๋กœ๊ทธ๋žจ์ด ์‹คํ–‰๋  ๋•Œ ์ž…๋ ฅ ๋ฐ›๋Š” ๊ฐ’์ด ๋ฒ„ํผ๋ฅผ ๊ฐ€๋“ ์ฑ„์šฐ๋‹ค ๋ชปํ•ด ๋„˜์ณํ˜๋Ÿฌ ๋ฒ„ํผ ์ดํ›„์˜ ๊ณต๊ฐ„์„ ์นจ๋ฒ”ํ•˜๋Š” ํ˜„์ƒ. ์ด๋ ‡๊ฒŒ ๊ธ€๋กœ๋งŒ ๋ด์„œ๋Š” ๋น„์ „๊ณต์ž์ธ ๋‚˜๋Š” ์ดํ•ด ํ•˜๊ธฐ๊ฐ€ ์ข€ ํž˜๋“ค์—ˆ๋‹ค... Youtube์—์„œ ์•„๋ž˜์™€ ๊ฐ™์ด ์‰ฝ๊ฒŒ ์„ค๋ช… ํ•ด์ฃผ๋Š” ์˜์ƒ์ด ์žˆ์–ด์„œ ์ฐธ๊ณ  ์šฐ์„  Protostar์— ์žˆ๋Š” Bufferoverflow ๋ฌธ์ œ๋ฅผ ํ’€์–ด ๋ณด์•˜๋‹ค ์ฒซ๋ฒˆ์งธ๋Š” Stack0 ์ด๋‹ค ์•„๋ž˜์™€ ๊ฐ™์€ ์ฝ”๋“œ๋กœ ๋˜์–ด ์žˆ๋‹ค. 1. ๋จผ์ € ํ•ด๋‹น ์ฝ”๋“œ๋ฅผ kali ์—์„œ ์ปดํŒŒ์ผ ์ง„ํ–‰ ํ–ˆ๋‹ค --> ํ•˜์ง€๋งŒ ์ผ๋ฐ˜์ ์ธ ๋ฐฉ๋ฒ•์œผ๋กœ ์ง„ํ–‰ํ•˜๋ฉด ์ทจ์•ฝ์ (Bufferoverflow)์ด ๋‚˜ํƒ€๋‚˜์ง€ ์•Š๊ธฐ ๋•Œ๋ฌธ์— ์•„๋ž˜์˜ ๋ช…๋ น์–ด๋กœ ์ปดํŒŒ์ผ --> ์Šคํƒ ๊ณต๊ฒฉ์— ์ทจ์•ฝํ•œ .. 2020. 10. 18.
Process Monitor / ๋™์  ๋ถ„์„ ํˆด https://docs.microsoft.com/en-us/sysinternals/downloads/procmon Process Monitor - Windows Sysinternals Monitor file system, Registry, process, thread and DLL activity in real-time. docs.microsoft.com 2020. 8. 23.
Bin Text / ๋™์  ๋ถ„์„ ํˆด ํŒŒ์ผ์— ์žˆ๋Š” String ์ •๋ณด๋ฅผ ํ™•์ธ ๊ฐ€๋Šฅํ•˜๋‹ค. https://www.aldeid.com/wiki/BinText 2020. 8. 23.