ããã¾ã§ã¯ãããããã³ã°ã»ã©ãã®ã¤ãããã å®å
¨ç ä»®æ³ç°å¢ã«ãããããã«ã¼ä½é¨å¦ç¿ããåèã«ããã¦ããã£ã¦ãç解ãé²ãã¦ãã¾ãããä»åããã¯ã並è¡ãã¦ãä½ç³»çã«å¦ã¶ å®å
¨ãªWebã¢ããªã±ã¼ã·ã§ã³ã®ä½ãæ¹ ç¬¬2ç èå¼±æ§ãçã¾ããåçã¨å¯¾çã®å®è·µãï¼é称ï¼å¾³ä¸¸æ¬ï¼ãåèã«ãåå¼·ãé²ãã¦ããããã¨æãã¾ãã
ãã®å¾³ä¸¸æ¬ã¨ã¯ãèå¼±æ§ã®ããä»®æ³ãã·ã³ãæºåãã¦ããã¦ãã¦ï¼VirtualBox 㨠Docker ãæºåããã¦ããï¼ããã®ä»®æ³ãã·ã³ã«å¯¾ãã¦ãå®éã«æ»æãä½é¨ãããã¨ã§ãèå¼±æ§ã®ç解ãæ·±ãããã¨ãã§ããã¨ãããã®ã§ãã
ä»åã¯ã徳丸æ¬ã®å®ç¿ç°å¢ã®æ§ç¯ãé²ãã¦ããã¾ãã
ããã§ã¯ããã£ã¦ããã¾ãã
åèæç®
ã¯ããã«
ãã»ãã¥ãªãã£ãã®è¨äºä¸è¦§ã§ããè¯ãã£ããåèã«ãã¦ãã ããã
ã»ãã¥ãªãã£ã®è¨äºä¸è¦§
ããã§ã¯ããã£ã¦ããã¾ãã
徳丸æ¬ã®å®ç¿ç°å¢ã®æ§ç¯ã®å
¨ä½å
徳丸æ¬ã®å®ç¿ç°å¢ã«ã¤ãã¦ã§ããã以ä¸ã®éç´«ã®èæ¯è²ã®2ã¤ã®ãã·ã³ãæ³å®ãã¦ãã¾ããwasbook ãèå¼±æ§ã®ããä»®æ³ãã·ã³ã§ãå®éã«æ»æãè¡ãã®ã¯ Windows ãæ³å®ãã¦ãã¾ãã
å³ã® DHCP-server ã¯ãVirtualBox ãç¨æãã¦ããããã®ã§ã192.168.56.x/24 ã®ã¢ãã¬ã¹ãé
å¸ãã¦ãã¾ããParrotOS ã¯ãããã¾ã§ä½¿ã£ã¦ãã VirtualBox ã®ä»®æ³ãã·ã³ã§ãã
æ»æãããã·ã³ã Windows10 ã¨ãã¦ãããããããããã¤ã³ã¹ãã¼ã«ãããã¨ã«ãªãã¾ãããã¡ãã£ã¨æ°ãé²ã¾ãªãã®ã§ãå¯è½ãªéããParrotOS ãæ»æãã·ã³ã¨ãããã¨æãã¾ãã以ä¸ã®ããã«ãªãã¾ãã
PlantUML ã¯ãä»ã¾ã§ä½åã使ã£ã¦ãã¾ãããããããã¯ã¼ã¯å³ã¯åãã¦ä½ãã¾ããããªããªãããæãã«ä½å³ãã¦ããã¾ãããã½ã¼ã¹ãè²¼ã£ã¦ããã¾ãã
@startuml
title 徳丸æ¬ã®å®ç¿ç°å¢
nwdiag {
network home {
address = "192.168.11.x/24";
win10 [ address = 192.168.11.13 ];
}
network VirtualBox {
address = "192.168.56.x/24";
win10 [ address = 192.168.56.1 ];
DHCP-server [ address = 192.168.56.100 ];
group {
color = "#aaaaFF";
wasbook [ address = 192.168.56.101 ];
ParrotOS [ address = 192.168.56.105 ];
}
}
}
@enduml
徳丸æ¬ã®å®ç¿ç°å¢ã®æ§ç¯ã¯ã大ããåãã¦ãèå¼±æ§ä»®æ³ãã·ã³ï¼wasbookï¼ã®ã»ããã¢ããã¨ãæ»æå´ã® ParrotOS ã®è¨å®ã«ãªãã¾ãã
èå¼±æ§ä»®æ³ãã·ã³ï¼wasbookï¼ã®ã»ããã¢ãã
ç°å¢æ§ç¯ã«ããããå¿
è¦ãªã½ãããªã©ã¯ã以ä¸ã®å¾³ä¸¸æ¬ã®ãµãã¼ããµã¤ããããã¦ã³ãã¼ããã¾ãã
wasbook.org
èå¼±æ§ä»®æ³ãã·ã³ï¼wasbookï¼ã®ã¤ã³ã¹ãã¼ã«
ãµãã¼ããµã¤ãã®ãã¦ã³ãã¼ããã¼ã¸ããããå®ç¿ç¨ä»®æ³ãã·ã³ï¼VirtualBoxç¨ Ver 1.0.4ï¼ãããã¦ã³ãã¼ããã¾ãã
ãã¦ã³ãã¼ããããã¡ã¤ã«ã¯ OVAãã¡ã¤ã«ãªã®ã§ãããã«ã¯ãªãã¯ããã¨ãVirtualBox ã«ã¤ã³ãã¼ãã§ãã¾ãã
CPU ã 1ã¤ãRAM 㯠512MBãGUI ç¡ããã¨ãããã¨ã§ã軽ãä»®æ³ãã·ã³ã®ããã§ãã
ã¤ã³ãã¼ããå®äºãããããããã¯ã¼ã¯ãã¯ãªãã¯ãã¦ãããã©ã«ãã® NAT ã«å ãã¦ããã¹ããªã³ãªã¼ã¢ããã¿ã追å ãã¦ããã¾ãã
ã§ã¯ãèµ·åãã¾ãã
CUI ã®ãã°ã¤ã³ç»é¢ã«ãªãã®ã§ãã¦ã¼ã¶åï¼wasbookããã¹ã¯ã¼ãï¼wasbook ã§ãã°ã¤ã³ãã¾ãã
SSHãµã¼ããããã©ã«ãã§èµ·åãã¦ããã®ã§ãTeraTerm ã§æ¥ç¶ã§ãã¾ãã
æ
å ±åéã¨ãParrotOS ã«æ¥ç¶ã§ãããã¨ã確èªãã¾ãã
$ cat /etc/issue
Debian GNU/Linux 9 \n \l
$ ip a
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
2: enp0s3: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UNKNOWN group default qlen 1000
link/ether 08:00:27:92:63:9e brd ff:ff:ff:ff:ff:ff
inet 10.0.2.15/24 brd 10.0.2.255 scope global enp0s3
valid_lft forever preferred_lft forever
3: enp0s8: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether 08:00:27:5b:4c:dc brd ff:ff:ff:ff:ff:ff
inet 192.168.56.101/24 brd 192.168.56.255 scope global enp0s8
valid_lft forever preferred_lft forever
$ ping 192.168.56.105
PING 192.168.56.105 (192.168.56.105) 56(84) bytes of data.
64 bytes from 192.168.56.105: icmp_seq=1 ttl=64 time=2.07 ms
64 bytes from 192.168.56.105: icmp_seq=2 ttl=64 time=1.13 ms
^C
--- 192.168.56.105 ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1001ms
rtt min/avg/max/mdev = 1.130/1.601/2.073/0.473 ms
ãã®æç¹ã§ãParrotOS ãã wasbook ã® Webãµã¼ãã«ã¢ã¯ã»ã¹ã§ãã¾ããhosts ã®è¨å®ãã¾ã ãªã®ã§ãIPã¢ãã¬ã¹ã§ãhttp://192.168.56.101
ã§ãwasbook ã®ããããã¼ã¸ã表示ããã¾ããããã¾ã§ã§ãèå¼±æ§ä»®æ³ãã·ã³ï¼wasbookï¼ã®ã¤ã³ã¹ãã¼ã«ã¯å®äºã§ãã
èå¼±æ§ä»®æ³ãã·ã³ï¼wasbookï¼ã®è¨å®
ããããã¯ãå¿
é ã§ã¯ãªãã§ãããwasbook ã使ããããããè¨å®ãè¡ãã¾ãã
visudo
sudo ãä»ãããã³ã«ãæ¯åãã¹ã¯ã¼ããèãããã®ã¯é¢åãªã®ã§ãvisudo ã§ãã¹ã¯ã¼ããå
¥åããªãã§ããããã«è¨å®ãã¾ããã
$ sudo visudo
wasbook ALL=(ALL:ALL) NOPASSWD: ALL
sambaãµã¼ã
ã½ã¼ã¹ã³ã¼ããç·¨éãããããã®ã«ä¾¿å©ãªã®ã§ãsambaãµã¼ããã¤ã³ã¹ãã¼ã«ãã¾ãã
$ sudo apt install samba
Reading package lists... Done
Building dependency tree
Reading state information... Done
Some packages could not be installed. This may mean that you have
requested an impossible situation or if you are using the unstable
distribution that some required packages have not yet been created
or been moved out of Incoming.
The following information may help to resolve the situation:
The following packages have unmet dependencies:
samba : Depends: python-dnspython but it is not installable
Depends: python-samba but it is not going to be installed
Depends: samba-common-bin (= 2:4.5.12+dfsg-2+deb9u2) but it is not going to be installed
Depends: tdb-tools but it is not installable
Depends: update-inetd but it is not installable
Depends: libldb1 (>= 0.9.21) but it is not installable
Depends: libpython2.7 (>= 2.7) but it is not installable
Depends: libtalloc2 (>= 2.0.4~git20101213) but it is not installable
Depends: libtdb1 (>= 1.2.7+git20101214) but it is not installable
Depends: libtevent0 (>= 0.9.16) but it is not installable
Depends: samba-libs (= 2:4.5.12+dfsg-2+deb9u2) but it is not going to be installed
Recommends: attr but it is not installable
Recommends: samba-dsdb-modules but it is not going to be installed
Recommends: samba-vfs-modules but it is not going to be installed
E: Unable to correct problems, you have held broken packages.
Debian 9 ã¯å¤ãã®ã§ããã¾ãå
¥ããªãã§ããDocker ã¸ã®ç§»è¡ãèããæ¹ãããããããã¾ããã
ParrotOSã®è¨å®
ããããã¯ãæ»æå´ã® ParrotOS ã®è¨å®ã«ãªãã¾ãã
ParrotOSã®hostsãã¡ã¤ã«ã®è¨å®
ååã§ã¢ã¯ã»ã¹ã§ããããã«ãParrotOS ã® hosts ãã¡ã¤ã«ã« wasbook ã® IPã¢ãã¬ã¹ã¨ååãç»é²ãã¾ãã以ä¸ã®ããã«ã/etc/hosts ãã¡ã¤ã«ã« 1è¡è¿½å ãã¾ãã
ping ã§ç¢ºèªããã¨ãã¡ããã¨ã¢ã¯ã»ã¹ã§ãã¦ãã¾ãã
$ sudo nano /etc/hosts
192.168.56.101 example.jp api.example.net trap.example.com
$ sudo ping example.jp
PING example.jp (192.168.56.101) 56(84) bytes of data.
64 bytes from example.jp (192.168.56.101): icmp_seq=1 ttl=64 time=1.04 ms
64 bytes from example.jp (192.168.56.101): icmp_seq=2 ttl=64 time=1.12 ms
^C
--- example.jp ping statistics ---
2 packets transmitted, 2 received, 0% packet loss, time 1004ms
rtt min/avg/max/mdev = 1.044/1.079/1.115/0.035 ms
OWASP ZAPã®ã»ããã¢ãã
youtube ã§ãæµ·å¤ã®ãµã¤ãã§ãOWASP ZAP ã®è§£èª¬ããã¦ããã®ãèããã¨ãããæ®éã«ããªã¯ã¹ãã¶ããã¨å¼ãã§ãããããªæ°ããã¾ãã
ããããã³ã°ã»ã©ãã®ã¤ãããã å®å
¨ç ä»®æ³ç°å¢ã«ãããããã«ã¼ä½é¨å¦ç¿ãã§ã¯ãHTTPéä¿¡ã®ã¢ãã©ã¤ã¶ï¼ã¨ãã¦ãBurp Suite ã使ã£ã¦ãã¾ããã徳丸æ¬ã§ã¯ãå種ã®ãã¼ã«ã§ãã OWASP ZAP ã使ãããã§ãã
ParrotOS ã«ã¯ãæåãã OWASP ZAP ãã¤ã³ã¹ãã¼ã«ããã¦ãã¾ããã§ã¯ãèµ·åãã¦ã¿ã¾ãã
èµ·åå®äºããã¨ã以ä¸ã®ãããªç»é¢ã«ãªãã¾ããä¸çªä¸ã®ã¿ã¤ã ã¹ã¿ã³ããã¼ã¹ãé¸ãã§ãStart ãã¯ãªãã¯ãã¾ãã
ãã®å¾ãã¢ãããã¼ãã§ããç»é¢ã«ãªãã¾ãããã¾ãå¿
è¦ã«ãªã£ããã¢ãããã¼ããããã¨ã«ãã¦ãClose ãã¯ãªãã¯ãã¾ããOWASP ZAP ãèµ·åãã¾ããã
ç¶ãã¦ããããã·ã®è¨å®ãè¡ãã¾ããOWASP ZAP ããBurp Suite 㯠HTTP ã®ãã¼ã«ã«ãããã·ã¨ãã¦åãã¾ããWebãã©ã¦ã¶ããWebãµã¼ãã«ã¢ã¯ã»ã¹ããéããã®éä¿¡ã仲ä»ããWebãã©ã¦ã¶ã®è¦æ±ã確èªããããå
容ãå¤æ´ãããã§ãã¾ãã
Tool â Options... ãã¯ãªãã¯ãã¾ãã
ããããè¨å®é
ç®ãããã¾ãããå·¦å´ã®é
ç®ãããNetwork â LocalServers/Proxies ãé¸ã³ã¾ãããã¼ãçªå·ã 8080çªã«ãªã£ã¦ãã¾ãããä»ã¨ç«¶åããããã¨ãããã¨ã§ã58888 ã«å¤æ´ãã¾ãã
OK ãæ¼ãã¦éããã«ãå·¦å´ã®é
ç®ãã Breakpoints ãé¸ã³ã¾ããBreak Buttons Mode ã Separate Request and Response Buttons ã«å¤æ´ãã¾ãã
â»2024/8/11ï¼è¿½è¨ãã¾ãã
æ¥æ¬èªã«å¯¾å¿ãã¦ããã®ã§ãæ¥æ¬èªåãã¾ãã
åãããTool â Options... ã® Language ãã¯ãªãã¯ãã¦ãå³ä¸ã®ã¨ããããããæ¥æ¬èªããé¸æãã¾ããæ¥æ¬èªåãããã«ã¯ãOWASP ZAP ã®åèµ·åãå¿
è¦ã§ããã
Firefox ã§ãhttps://example.jp/
ã«ã¢ã¯ã»ã¹ããã¨ããè¦åï¼æ½å¨çãªã»ãã¥ãªãã£ãªã¹ã¯ãããã¨è¡¨ç¤ºããã¦ãå±éºãæ¿ç¥ã§é²ãã¨ãä¸å¿è¡¨ç¤ºãããã®ã§ãããç®æ¬¡ãã¼ã¸ãããã®ã»ãã®ãã¼ã¸ãã以ä¸ã®ãããªæãã§ãå·¦å³ã«è¦åãåºãã¾ã¾ã«ãªããã¨ãããã¾ãã
ããã¯ãOWASP ZAP ãã¢ãããã¼ãããã¦ãæ©è½è¿½å ããããã¨ãåå ã¨ãããã¨ã§ãã以ä¸ã®ããã«ãTool â Options... ã® HUD ã§ãEnable when using the ZAP Desktop ã®é
ç®ã®ãã§ãã¯ãå¤ãã¨è§£æ±ºãã¾ãã
Firefoxã«æ¡å¼µæ©è½ã®FoxyProxy-Standardãã¤ã³ã¹ãã¼ã«ãã
Firefox ãèµ·åãã¾ãã
次㮠URL ã«ã¢ã¯ã»ã¹ãã¾ããhttps://addons.mozilla.org/ja/firefox/addon/foxyproxy-standard/
ããã¤ã確èªç»é¢ãåºã¾ãããOKï¼Okeyï¼ãã¯ãªãã¯ãã¾ãã
FoxyProxy-Standard ã®è¨å®ãè¡ãã¾ãã
ãµãã¼ããµã¤ãã«ãææ°ï¼ã®ãFoxyproxyã®è¨å®ãã¡ã¤ã«ããããã®ã§ãã¦ã³ãã¼ããã¾ãããã¡ã¤ã«åã¯ãfoxyproxy7.jsonãã§ãããããããFoxyProxy-Standard ã®ãã¼ã¸ã§ã³ 7 ç¨ã®è¨å®ãã¡ã¤ã«ãªãã ã¨æãã¾ãããä»åã¤ã³ã¹ãã¼ã«ãã FoxyProxy ã¯ããã¼ã¸ã§ã³ 8.9 ã§ããã
Firefox ã®æ¡å¼µæ©è½ã®ã¢ã¤ã³ã³ãã¯ãªãã¯ãã¦ãFoxyProxy ãã¯ãªãã¯ãã¾ããããã¨ãOptions ãããã®ã§ã¯ãªãã¯ãã¾ããImport ã¿ããéããImport from older versions ãã¯ãªãã¯ãã¾ããImport ãã¿ã³ãããã®ã§ãã¯ãªãã¯ããã¨ããã¡ã¤ã«ãéããã¤ã¢ãã°ãåºãã®ã§ãå
ã»ã©ãã¦ã³ãã¼ããããfoxyproxy7.jsonããéãã¾ããããã§è¨å®ãèªã¿è¾¼ã¾ãã¾ããã
Proxies ã¿ããéãã¾ããZAP ãéããä¸ã®æ¹ã« Pattern ã¨ããã®ãããã¾ãããããããã¾ãåããªãã£ãã®ã§ä¿®æ£ãã¾ãããä¸å³ã®ããã«è¨å®ãããã¨ã§åãã¾ããã
- *example.jp*
- *api.example.net*
- *trap.example.com*
ã¡ãã£ã¨åããã«ããã£ãã®ã§ãããFoxyProxy ãæå¹ã«ããã«ã¯ãä¸å³ã®ã¨ãããã¯ãªãã¯ãã¦è¨å®ãã¦ããå¿
è¦ãããã¾ããã
åä½ç¢ºèªãã¦ã¿ã¾ãã
https://example.jp/ ã«ã¢ã¯ã»ã¹ããã¨ãã¯ãOWASP ZAP ãèªèãã¾ãããæ®éã® Webãµã¤ãï¼Googleã¨ãï¼ã«ã¢ã¯ã»ã¹ãã¦ã OWASP ZAP ãèªèããªããã°æ£ããè¨å®ã§ãã¦ãããã ã¨æãã¾ãã
å½é¢ã®ç°å¢æ§ç¯ã¯ããã§å®äºã§ããèå¼±æ§ä»®æ³ãã·ã³ã¯ãwasbook ã®ä»ã«ãç¨æããã¦ãããããªã®ã§ãããæ¸ç±ã®å¾åã«åºã¦ãããããªã®ã§ãä»åã¯ããã¾ã§ã«ãããã¨æãã¾ãã
ãããã«
ä»åã¯ããä½ç³»çã«å¦ã¶ å®å
¨ãªWebã¢ããªã±ã¼ã·ã§ã³ã®ä½ãæ¹ ç¬¬2ç èå¼±æ§ãçã¾ããåçã¨å¯¾çã®å®è·µãï¼é称ï¼å¾³ä¸¸æ¬ï¼ã®ç°å¢æ§ç¯ãè¡ãã¾ããã
次åããã¯ã徳丸æ¬ã«æ²¿ã£ã¦ãé²ãã¦ããããã¨æãã¾ãã
æå¾ã«ãªãã¾ããããã¨ã³ã¸ãã¢ã°ã«ã¼ãã®ã©ã³ãã³ã°ã«åå ä¸ã§ãã
æ°æ¥½ã«ãããã¨ãããããé¡ããããã¾ãð
ä»åã¯ä»¥ä¸ã§ãï¼
æå¾ã¾ã§ãèªã¿ããã ãããããã¨ããããã¾ããã