Home
Today : 2026-06-15 14:36:40
 
ikjinan.kro.kr
local IP address is: 216.73.217.46  public IP address is: 112.175.185.138 [ LOG IN ]  [ SIGN UP]
Bulletin Board(to Db)
mpm์ด์ฃผ์‚ฌ๋ชฉ  
์ด์žฌ๋ช…  
Science  
Island-monkey-disaster  
Great-korea  
health  
k-culture  
office-file  
Catholic  
freeboard  
windog  
linux-bsd  
apm  
linux-bsd
Title ์ž์‹ ์ด ๊ด€๋ฆฌํ•˜๋Š” ์‹œ์Šคํ…œ์— ๋Œ€ํ•ด ์ทจ์•ฝ์  ์ ๊ฒ€์ด๋‚˜ ๋ณด์•ˆ ํ…Œ์ŠคํŠธ
File
Name admin | 2026-06-14 | Views: 1
Content
Kali๋กœ ํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒƒ 1. ์—ด๋ฆฐ ํฌํŠธ ํ™•์ธ ย  ย  nmap -sV ์„œ๋ฒ„IP ย 

๊ฒฐ๊ณผ ์˜ˆ:

ย  ย  22/tcp open ssh 80/tcp open http 443/tcp open https 993/tcp open imaps ย 

์˜ˆ์ƒํ•˜์ง€ ๋ชปํ•œ ํฌํŠธ๊ฐ€ ์—ด๋ ค ์žˆ์œผ๋ฉด ํ™•์ธ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

2. ์ทจ์•ฝํ•œ ์„œ๋น„์Šค ํ™•์ธ ย  ย  nmap --script vuln ์„œ๋ฒ„IP ย 

์•Œ๋ ค์ง„ ์ทจ์•ฝ์ ์ด ์žˆ๋Š”์ง€ ๊ฒ€์‚ฌํ•ฉ๋‹ˆ๋‹ค.

3. SSL/TLS ๊ฒ€์‚ฌ

์˜ˆ๋ฅผ ๋“ค์–ด HTTPS ์„ค์ • ๊ฒ€์‚ฌ:

ย  ย  sslscan ์„œ๋ฒ„์ฃผ์†Œ ย 

๋˜๋Š”

ย  ย  nmap --script ssl-enum-ciphers -p443 ์„œ๋ฒ„์ฃผ์†Œ ย  4. ์›น์„œ๋ฒ„ ์ ๊ฒ€ ย  ย  nikto -h https://ikjinan.kro.kr ย 

ํ™•์ธ ๊ฐ€๋Šฅํ•œ ๊ฒƒ:

  • ์œ„ํ—˜ํ•œ ์„ค์ •
  • ๋…ธ์ถœ๋œ ํŒŒ์ผ
  • ์˜ค๋ž˜๋œ ๋ฒ„์ „
  • ์ž˜๋ชป๋œ ๊ถŒํ•œ
5. SSH ์ ๊ฒ€ ย  ย  nmap --script ssh2-enum-algos -p22 ์„œ๋ฒ„IP ย 

์•ฝํ•œ ์•”ํ˜ธํ™” ๋ฐฉ์‹ ์‚ฌ์šฉ ์—ฌ๋ถ€ ํ™•์ธ

ํ•˜์ง€๋งŒ Kali๋กœ ์•Œ ์ˆ˜ ์—†๋Š” ๊ฒƒ

๋‹ค์Œ์€ Kali๋งŒ์œผ๋กœ ํ™•์ธํ•˜๊ธฐ ์–ด๋ ต์Šต๋‹ˆ๋‹ค.

๋ฐฑ๋„์–ด

์˜ˆ:

ย  ย  /usr/local/bin/evil.sh ย 

๊ฐ™์ด ์„œ๋ฒ„ ๋‚ด๋ถ€์— ์ˆจ์–ด ์žˆ๋Š” ์•…์„ฑ ์Šคํฌ๋ฆฝํŠธ

๋ฃจํŠธํ‚ท

์ปค๋„ ์ˆ˜์ค€์—์„œ ์ˆจ์€ ์•…์„ฑ์ฝ”๋“œ

๊ณ„์ • ํƒˆ์ทจ ย  ย  /home/admin/.ssh/authorized_keys ย 

์— ๋ˆ„๊ตฐ๊ฐ€์˜ SSH ํ‚ค๊ฐ€ ์ถ”๊ฐ€๋œ ๊ฒฝ์šฐ

์›น์‰˜

์˜ˆ:

ย  ย  shell.php cmd.php upload.php ย 

๊ฐ™์€ ์•…์„ฑ PHP ํŒŒ์ผ

๋ฆฌ๋ˆ…์Šค ๋‚ด๋ถ€ ์ ๊ฒ€ ๋„๊ตฌ

์„œ๋ฒ„ ๋‚ด๋ถ€์—์„œ๋Š” ์ด๋Ÿฐ ๋„๊ตฌ๊ฐ€ ๋” ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค.

Rootkit ๊ฒ€์‚ฌ

rkhunter ๊ณต์‹ ์‚ฌ์ดํŠธ

ย  ย  sudo rkhunter --check ย  ํŒŒ์ผ ๋ฌด๊ฒฐ์„ฑ ๊ฒ€์‚ฌ

AIDE ๊ณต์‹ ์‚ฌ์ดํŠธ

ย  ย  sudo aide --check ย 

ํŒŒ์ผ์ด ๋ชฐ๋ž˜ ๋ณ€๊ฒฝ๋˜์—ˆ๋Š”์ง€ ํ™•์ธ

๋กœ๊ทธ์ธ ๊ธฐ๋ก ํ™•์ธ ย  ย  last ย  ย  ย  lastb ย  SSH ํ‚ค ํ™•์ธ ย  ย  cat ~/.ssh/authorized_keys ย  ์‚ฌ์šฉ์ž๋‹˜ ์„œ๋ฒ„๋ผ๋ฉด

ํ˜„์žฌ ๊ธฐ์–ต๋‚˜๋Š” ๊ตฌ์„ฑ๋งŒ ํ•ด๋„:

  • Fedora ์„œ๋ฒ„
  • Nginx
  • Postfix
  • Dovecot
  • Roundcube
  • PHP

์ด๋ฏ€๋กœ,

Kali๋ฅผ ์„ค์น˜ํ•˜๋Š” ๊ฒƒ๋ณด๋‹ค ๋จผ์ € ์•„๋ž˜ ์ ๊ฒ€์ด ํšจ๊ณผ์ ์ž…๋‹ˆ๋‹ค.

ย  ย  sudo dnf install rkhunter aide sudo rkhunter --check sudo aide --check ย 

๊ทธ๋ฆฌ๊ณ  ์™ธ๋ถ€์—์„œ:

ย  ย  nmap -sV ikjinan.kro.kr nikto -h https://ikjinan.kro.kr ย 

์ •๋„๋ฉด ๊ฝค ๊ดœ์ฐฎ์€ 1์ฐจ ๋ณด์•ˆ ์ ๊ฒ€์ด ๋ฉ๋‹ˆ๋‹ค.

์ค‘์š”ํ•œ ์ ์€, ๋ณธ์ธ์ด ์†Œ์œ ํ•˜๊ฑฐ๋‚˜ ๊ด€๋ฆฌ ๊ถŒํ•œ์ด ์žˆ๋Š” ์‹œ์Šคํ…œ์—๋งŒ ํ…Œ์ŠคํŠธํ•ด์•ผ ํ•œ๋‹ค๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๋‹ค๋ฅธ ์‚ฌ๋žŒ์˜ ์„œ๋ฒ„๋‚˜ ๋„คํŠธ์›Œํฌ์— ํ—ˆ๊ฐ€ ์—†์ด ์Šค์บ”์„ ์ˆ˜ํ–‰ํ•˜๋ฉด ๋ฒ•์  ๋ฌธ์ œ๊ฐ€ ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ทธ๋ฆฌ๊ณ  ์†”์งํžˆ ๋ง์”€๋“œ๋ฆฌ๋ฉด, ์‚ฌ์šฉ์ž๋‹˜ ์ •๋„๋ฉด Kali Linux๋ฅผ ์„ค์น˜ํ•ด์„œ "ํ•ดํ‚น"์„ ๋ฐฐ์šฐ๊ธฐ๋ณด๋‹ค, ์ง€๊ธˆ ์šด์˜ ์ค‘์ธ Fedora ๋ฉ”์ผ ์„œ๋ฒ„์™€ ์›น ์„œ๋ฒ„๋ฅผ ๋Œ€์ƒ์œผ๋กœ ๋ณด์•ˆ ์ ๊ฒ€ํ•˜๋Š” ์ชฝ์ด ํ›จ์”ฌ ์‹ค์šฉ์ ์ธ ๊ณต๋ถ€๊ฐ€ ๋  ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. Nginx, Postfix, Dovecot ์„ค์ •์„ ๋ถ„์„ํ•˜๋Š” ๊ณผ์ •์—์„œ ์‹ค์ œ ์„œ๋ฒ„ ๋ณด์•ˆ ์ง€์‹์„ ๋งŽ์ด ์–ป์„ ์ˆ˜ ์žˆ๊ฑฐ๋“ ์š”.

God Bless & Peace Be with You
Visitors For today : ( 9 )
2026-06-15