sshã®ãã¼ããããã©ã«ãã®22/tcpããå¤ããã¹ããè«äºã«ãçµæ¢ç¬¦ãæã¡ã¾ãã
ã¾ãéãéãã¾ãããããã¿ã ã»ãã¥ãªãã£åå¼·ä¼2015#2ãéå¬ãã¾ãããçºè¡¨ãã¦ããã ãã@inaz2ããã@yasulibããããããã¨ããããã¾ããã彿¥ã®çºè¡¨è³æã¯ä¸è¨ã®åå¼·ä¼ããã°ãããªã³ã¯ãã¦ãã¾ãã
ä»åã®ç§ã®çºè¡¨ã¯ããæ»æããé ããã»æ»æãããé ããããããã¼ãã¹ãã£ã³ãããã¨sshã100åç¾ãããsshå身ã®è¡ããã¡ã¤ã³(?)ã§ãã
å½åã¯ããã±ãããããããããã³ã«ã®ããéã«ã¡ãã»ã¼ã¸ãé ãããããã¡ã¤ã«ãé ããªã©ãèãã¦ããã®ã§ããâ¦â¦ããã¾ãã«çãã ãããã«ãªãããã ã£ãã®ã§ãããã¼ãã¹ãã£ã³ãããã«é ãã¦å®è¡ãããã»ãã¼ãã¹ãã£ã³ããã©ããã£ã¦é ããããã¨ããã¼ãã¹ãã£ã³ã¨nmapã«çµã£ã¦çºè¡¨ãã¾ããã
çºè¡¨è³æ
ç§ã®çºè¡¨è³æã¯ä»¥ä¸ã§ãã
çºè¡¨ãã¼ãä»ããªã®ã§PDFã§ãã以ä¸ãè½ç©ã²ãããªã©ã
ã¹ãã£ã³ãããã¼ãæ°ã¨ã«ãã¬ãã¸
åå¼·ä¼ã§ã¯ã«ãã¬ãã¸ã¨ããè¨èã使ãã¾ããããå ãã¿ã®nmapå ¬å¼ã¬ã¤ãããã¯(ç®ã³çæ¬)ã§ã¯ã"Effectiveness"ã¨æ¸ããã¦ãã¾ããã¡ãã£ã¨åããã«ããã®ã§ãåå¼·ä¼ã§ã¯Coverageã¨ããè¨èã«ãã¾ããã
10ãã¼ãã¹ãã£ã³ããã°Effectivenessã50%ã¨ããã®ã¯ãåãã¦èªãã ã¨ãã«ã¯ããã£ãã®10ãã¼ãã§ãããªã«ã«ãã¼ã§ããã®!?ãã¨ã¡ãã£ã¨ããã¯ãªãã¾ããããå·éã«èãã¦ã¿ãã°æè¦çã«ã¯ã¾ããããªããããªã¨ããå°è±¡ã§ãã
ãã ããã®å¤ã¯ã¤ã³ã¿ã¼ãããè¶ãã«ã¹ãã£ã³ãè¡ã£ãå ´åã§ããããã¼ã¿ã»ã³ã¿ã¼ãªã©ã§åä¸ã»ã°ã¡ã³ããããã¼ãã¹ãã£ã³ãè¡ãå ´åã¯ããã£ã¨ããããã®éæ¾ãã¼ããè¦ããã®ã§è©±ã¯éã£ã¦ããã¨æãã¾ãã
sshã®ãã¼ãã¯ããã£ã±ã22/tcpããå¤ãã¾ããã
ãsshã®ãã¼ããããã©ã«ãã®22/tcpããå¤ãã¦ãæå³ãªãããã¨ããããã°è¨äºã¯ãã¯ã¦ãªããã¯ãã¼ã¯ãããã§å®æçã«çä¸ãããã¼ãã§ãã以åãããããã³ãã³ããã·ã¥ãæ¿æ¸ãããã ãããã´ãã£ã´ãã£è¨ã£ã¦ãªãã§å¤ããã¹ããæ´¾ã ã£ãç§ã¯ãå¤ããªãã¦ãããæ´¾ã®ããã¼ãã¹ãã£ã³ããã°ä¸çºã§åããããããã¨ããæè¦ã«æççã§ãããä»åã®ãã¿ã¯ãã®è¾ºãåºçºç¹ã«ãªã£ã¦ãã¾ãã
ä»åããããã¦å ·ä½çã«ãã¼ãã¹ãã£ã³ä¸çºã§ã¯åãããªãææ³ããã£ã±ããããã¨ç¤ºããã¨ã§ããsshã®ãã¼ããããã©ã«ãã®22/tcpããå¤ããã»ããããã?ãã®è°è«ãçµçµããããã¨ãã§ããã®ã§æºè¶³ã§ã(ãã¶ã)ã
ãã³ã¤ã«ã¤ãã¦
彿¥ã¯C-130ã®ãã¬ã¢ã ã示ãã¾ããããç¬¬äºæ¬¡ä¸ç大æ¦ã§ã®ããªããæ¦è»ã®ãã³ã¤ãªã©ãé¢ç½ã話ã¯è²ã 転ãã£ã¦ãã¾ãããè¿ãã®è»äºãªã¿ã«èãã¦ã¿ãã¨è¯ãã§ãããã
kippoã®ããã¼ã«ã¤ãã¦
彿¥ã«wakatonoããããããkippoã¯pythonã§æ¸ããã¦ããã®ã§ãè¿ãããã¼ãã©ã³ãã åããã°ãããã¨ã³ã¡ã³ãããããã¾ããã確ãã«ç°¡åã§ãããé¢ç½ãã¨æãã¾ãã
ããããã¤ã¡ã¼ã¸ãâ
root@kali:~# nmap -sV -p0-65535 192.168.2.66 ....(snip).... PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 5.3 (protocol 2.0) 2200/tcp open ssh OpenSSH 5.1p1 Debian 5 (protocol 2.0) 2201/tcp open ssh Sun_SSH 1.1 (protocol 2.0) 2202/tcp open ssh OpenSSH 5.3 (protocol 2.0) 2203/tcp open ssh OpenSSH 5.1p1 Debian 5 (protocol 2.0) 2204/tcp open ssh OpenSSH 4.6 (protocol 2.0) 2205/tcp open ssh OpenSSH 5.3p1 Debian-3ubuntu7 (protocol 2.0) 2206/tcp open ssh OpenSSH 5.1p1 FreeBSD-20080901 (protocol 2.0) 2207/tcp open ssh Sun_SSH 1.1 (protocol 2.0) 2208/tcp open ssh OpenSSH 5.5p1 Debian-6+squeeze2 (protocol 2.0) 2209/tcp open ssh OpenSSH 5.3 (protocol 2.0) ....(snip)....
ãããªããã©ãããã³ã¢ãã®sshãã®æ¨å®ã¯å°é£ã ããé¢åã§ãããã¾ããã
Port Knockingã«ã¤ãã¦
彿¥è³ªåãããã ãã¾ããããäºåã«ç¹å®ã®ãã¼ãã«ã¢ã¯ã»ã¹ããªãã¨å¯¾è±¡ãã¼ãã«å°éã§ããªãããã«ããPort Knockingã¨ããã¢ããã¼ããããã¾ãã
ç§ã¯knockdã¯ãã¡ãã¨éç¨ãããã¨ãç¡ãã®ã§(rsyncã¨ãã§ã®é£æºãã¹ããããå ´åãéç¨ãã¡ã³ãããããã ãªãããã¨æã£ã¦ãã)ããã£ã½ã話é¡ã¨ãã¦æãã¡ããã¾ãããã¡ãã£ã¨ãã¸ã¡ã«è§¦ã£ã¦ã¿ã¦ãä½ãããã°å¾æ¥æ¸ãããã
宣ä¼
6æã«Linuxã®å ¥éæ¸ãåºãã¾ãããLinuxåå¿è ã«ããæ¬ã ãªãã¨æãªããæã£ã¦ããã®ã§ããã²ããã£ã¨ãã¦ãè²·ãæ±ããã ãã!

- ä½è : ä¸å® è±æ,大è§ç¥ä»
- åºç社/ã¡ã¼ã«ã¼: SBã¯ãªã¨ã¤ãã£ã
- çºå£²æ¥: 2015/06/06
- ã¡ãã£ã¢: åè¡æ¬
- ãã®ååãå«ãããã° (6ä»¶) ãè¦ã