FootPrinting

์ธํ”„๋ผ ๊ธฐ๋ฐ˜ ์—ด๊ฑฐ

๋ช…๋ น

์„ค๋ช…

curl -s https://crt.sh/\?q\=<target-domain>\&output\=json | jq .

์ธ์ฆ์„œ ํˆฌ๋ช…์„ฑ.

for i in $(cat ip-addresses.txt);do shodan host $i;done

Shodan์„ ์‚ฌ์šฉํ•˜์—ฌ ๋ชฉ๋ก์˜ ๊ฐ IP ์ฃผ์†Œ๋ฅผ ๊ฒ€์ƒ‰ํ•ฉ๋‹ˆ๋‹ค.


ํ˜ธ์ŠคํŠธ ๊ธฐ๋ฐ˜ ์—ด๊ฑฐ

FTP

๋ช…๋ น

์„ค๋ช…

ftp <FQDN/IP>

๋Œ€์ƒ์˜ FTP ์„œ๋น„์Šค์™€ ์ƒํ˜ธ ์ž‘์šฉํ•ฉ๋‹ˆ๋‹ค.

nc -nv <FQDN/IP> 21

๋Œ€์ƒ์˜ FTP ์„œ๋น„์Šค์™€ ์ƒํ˜ธ ์ž‘์šฉํ•ฉ๋‹ˆ๋‹ค.

telnet <FQDN/IP> 21

๋Œ€์ƒ์˜ FTP ์„œ๋น„์Šค์™€ ์ƒํ˜ธ ์ž‘์šฉํ•ฉ๋‹ˆ๋‹ค.

openssl s_client -connect <FQDN/IP>:21 -starttls ftp

์•”ํ˜ธํ™”๋œ ์—ฐ๊ฒฐ์„ ์‚ฌ์šฉํ•˜์—ฌ ๋Œ€์ƒ์˜ FTP ์„œ๋น„์Šค์™€ ์ƒํ˜ธ ์ž‘์šฉํ•ฉ๋‹ˆ๋‹ค.

wget -m --no-passive ftp://anonymous:anonymous@<target>

๋Œ€์ƒ FTP ์„œ๋ฒ„์—์„œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๋ชจ๋“  ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค.

smb

๋ช…๋ น

์„ค๋ช…

smbclient -N -L //<FQDN/IP>

SMB์—์„œ Null ์„ธ์…˜ ์ธ์ฆ.

smbclient //<FQDN/IP>/<share>

ํŠน์ • SMB ๊ณต์œ ์— ์—ฐ๊ฒฐํ•ฉ๋‹ˆ๋‹ค.

rpcclient -U "" <FQDN/IP>

RPC๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋Œ€์ƒ๊ณผ ์ƒํ˜ธ ์ž‘์šฉํ•ฉ๋‹ˆ๋‹ค.

samrdump.py <FQDN/IP>

Impacket ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‚ฌ์šฉํ•œ ์‚ฌ์šฉ์ž ์ด๋ฆ„ ์—ด๊ฑฐ.

smbmap -H <FQDN/IP>

SMB ๊ณต์œ ๋ฅผ ์—ด๊ฑฐํ•ฉ๋‹ˆ๋‹ค.

crackmapexec smb <FQDN/IP> --shares -u '' -p ''

๋„ ์„ธ์…˜ ์ธ์ฆ์„ ์‚ฌ์šฉํ•˜์—ฌ SMB ๊ณต์œ ๋ฅผ ์—ด๊ฑฐํ•ฉ๋‹ˆ๋‹ค.

enum4linux-ng.py <FQDN/IP> -A

enum4linux๋ฅผ ์‚ฌ์šฉํ•œ SMB ์—ด๊ฑฐ.

NFS

๋ช…๋ น

์„ค๋ช…

showmount -e <FQDN/IP>

์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ NFS ๊ณต์œ ๋ฅผ ํ‘œ์‹œํ•ฉ๋‹ˆ๋‹ค.

mount -t nfs <FQDN/IP>:/<share> ./target-NFS/ -o nolock

ํŠน์ • NFS share.umount ./target-NFS๋ฅผ ๋งˆ์šดํŠธํ•ฉ๋‹ˆ๋‹ค.

umount ./target-NFS

ํŠน์ • NFS ๊ณต์œ ๋ฅผ ๋งˆ์šดํŠธ ํ•ด์ œํ•ฉ๋‹ˆ๋‹ค.

DNS

๋ช…๋ น

์„ค๋ช…

dig ns <domain.tld> @<nameserver>

ํŠน์ • ๋„ค์ž„์„œ๋ฒ„์— ๋Œ€ํ•œ NS ์š”์ฒญ์ž…๋‹ˆ๋‹ค.

dig any <domain.tld> @<nameserver>

ํŠน์ • ๋„ค์ž„์„œ๋ฒ„์— ๋Œ€ํ•œ ๋ชจ๋“  ์š”์ฒญ.

dig axfr <domain.tld> @<nameserver>

ํŠน์ • ๋„ค์ž„์„œ๋ฒ„์— ๋Œ€ํ•œ AXFR ์š”์ฒญ์ž…๋‹ˆ๋‹ค.

dnsenum --dnsserver <nameserver> --enum -p 0 -s 0 -o found_subdomains.txt -f ~/subdomains.list <domain.tld>

ํ•˜์œ„ ๋„๋ฉ”์ธ ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž….

SMTP

๋ช…๋ น

์„ค๋ช…

telnet <FQDN/IP> 25

IMAP/POP3

๋ช…๋ น

์„ค๋ช…

curl -k 'imaps://<FQDN/IP>' --user <user>:<password>

cURL์„ ์‚ฌ์šฉํ•˜์—ฌ IMAPS ์„œ๋น„์Šค์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.

openssl s_client -connect <FQDN/IP>:imaps

IMAPS ์„œ๋น„์Šค์— ์—ฐ๊ฒฐํ•ฉ๋‹ˆ๋‹ค.

openssl s_client -connect <FQDN/IP>:pop3s

POP3 ์„œ๋น„์Šค์— ์—ฐ๊ฒฐํ•ฉ๋‹ˆ๋‹ค.

SNMP

๋ช…๋ น

์„ค๋ช…

snmpwalk -v2c -c <community string> <FQDN/IP>

snmpwalk๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ OID๋ฅผ ์ฟผ๋ฆฌํ•ฉ๋‹ˆ๋‹ค.

onesixtyone -c community-strings.list <FQDN/IP>

SNMP ์„œ๋น„์Šค์˜ ๋ฌด์ฐจ๋ณ„ ์ปค๋ฎค๋‹ˆํ‹ฐ ๋ฌธ์ž์—ด์ž…๋‹ˆ๋‹ค.

braa <community string>@<FQDN/IP>:.1.*

๋ฌด์ฐจ๋ณ„ SNMP ์„œ๋น„์Šค OID.

MySQL

๋ช…๋ น

์„ค๋ช…

mysql -u <user> -p<password> -h <FQDN/IP>

MySQL ์„œ๋ฒ„์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.

MSSQL

๋ช…๋ น

์„ค๋ช…

mssqlclient.py <user>@<FQDN/IP> -windows-auth

Windows ์ธ์ฆ์„ ์‚ฌ์šฉํ•˜์—ฌ MSSQL ์„œ๋ฒ„์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.

IPMI

๋ช…๋ น

์„ค๋ช…

msf6 auxiliary(scanner/ipmi/ipmi_version)

IPMI ๋ฒ„์ „ ๊ฐ์ง€.

msf6 auxiliary(scanner/ipmi/ipmi_dumphashes)

IPMI ํ•ด์‹œ๋ฅผ ๋คํ”„ํ•ฉ๋‹ˆ๋‹ค.

๋ฆฌ๋ˆ…์Šค ์›๊ฒฉ ๊ด€๋ฆฌ

๋ช…๋ น

์„ค๋ช…

ssh-audit.py <FQDN/IP>

๋Œ€์ƒ SSH ์„œ๋น„์Šค์— ๋Œ€ํ•œ ์›๊ฒฉ ๋ณด์•ˆ ๊ฐ์‚ฌ.

ssh <user>@<FQDN/IP>

SSH ํด๋ผ์ด์–ธํŠธ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ SSH ์„œ๋ฒ„์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.

ssh -i private.key <user>@<FQDN/IP>

๊ฐœ์ธ ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ SSH ์„œ๋ฒ„์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.

ssh <user>@<FQDN/IP> -o PreferredAuthentications=password

๋น„๋ฐ€๋ฒˆํ˜ธ ๊ธฐ๋ฐ˜ ์ธ์ฆ์„ ์‹œํ–‰ํ•ฉ๋‹ˆ๋‹ค.

Windows ์›๊ฒฉ ๊ด€๋ฆฌ

๋ช…๋ น

์„ค๋ช…

rdp-sec-check.pl <FQDN/IP>

RDP ์„œ๋น„์Šค์˜ ๋ณด์•ˆ ์„ค์ •์„ ํ™•์ธํ•˜์‹ญ์‹œ์˜ค.

xfreerdp /u:<user> /p:"<password>" /v:<FQDN/IP>

Linux์—์„œ RDP ์„œ๋ฒ„์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.

evil-winrm -i <FQDN/IP> -u <user> -p <password>

WinRM ์„œ๋ฒ„์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.

wmiexec.py <user>:"<password>"@<FQDN/IP> "<system command>"

WMI ์„œ๋น„์Šค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ช…๋ น์„ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค.

์˜ค๋ผํด TNS

๋ช…๋ น

์„ค๋ช…

./odat.py all -s <FQDN/IP>

๋‹ค์–‘ํ•œ ์Šค์บ”์„ ์ˆ˜ํ–‰ํ•˜์—ฌ Oracle ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์„œ๋น„์Šค ๋ฐ ํ•ด๋‹น ๊ตฌ์„ฑ ์š”์†Œ์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์ˆ˜์ง‘ํ•ฉ๋‹ˆ๋‹ค.

sqlplus <user>/<pass>@<FQDN/IP>/<db>

Oracle ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ๋กœ๊ทธ์ธํ•ฉ๋‹ˆ๋‹ค.

./odat.py utlfile -s <FQDN/IP> -d <db> -U <user> -P <pass> --sysdba --putFile C:\\insert\\path file.txt ./file.txt

Oracle RDBMS๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ์„ ์—…๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค.

Last updated