nmapã®ã¯ãªã¹ãã¹ã¹ãã£ã³(-xS)ããã£ã¨ãã©ãã©ãããã
ãã¾ãã«é·ãããã ãã®ããã°ãæ¾ç½®ãã¦ãã¾ãããã大ä¸å¤«ã§ããçãã¦ãã¾ãã
ãã ãã¡ãã£ã¨ã¡ã³ã¿ã«çã«è²ã ããããã¦æ¾ç½®ãã¦ãã¾ããããããããã«1年以ä¸ãæ´æ°ããªãã¨ãã©ãã®ã§ãã¡ããã©ã¯ãªã¹ãã¹ã¨ãããã¨ã§ããã¼ãã¹ãã£ããã¼ã«Nmapã®ãã¯ãªã¹ãã¹ã¹ãã£ã³ã«ã¤ãã¦è»½ãæ¸ãã¦ã¿ããã¨ã«ãã¾ããã
Nmapã¨ã¯ãªã¹ãã¹
ä»æ¥ã¯12æ25ãã¯ãªã¹ãã¹ã§ããã»ãã¥ãªãã£è¨ºæã®æ¥çã§ã¯æåã§ããã12æ25æ¥ã«nmapã§-vãªãã·ã§ã³ãä»ãã¦ãã¼ãã¹ãã£ã³ãããã¨ãnmapãã
"Nmap wishes you a merry Christmas!"
ã¨ããã¡ãã»ã¼ã¸ãåºãã¦ã¯ãªã¹ãã¹ãç¥ã£ã¦ããã¾ãã
診ææ¥çã®çã¯ãã¯ãªã¹ãã¹ã«èå¼±æ§è¨ºæãããã¨ãããã®ã¡ãã»ã¼ã¸ãè¦ãã¨ã¿ããªã»ãããã¨ããæ°åã«ãªã£ããã®ã§ãâ¦â¦(ããªãããã¼ã ã! ã¨ãã誰ãã®å£°ãèããã)
ãã®éNmapã¯ãã¤ãã§ã«ã"Specify -sX for Xmas Scan"ã¨ãã¯ãªã¹ãã¹ã¹ãã£ã³ã®ããæ¹ãæãã¦ããã¾ããã¯ãªã¹ãã¹ã¹ãã£ã³ã¨ã¯ãé常ã®SYNã¹ãã£ã³ã¨éããTCP Flagsã®URG/PSH/FINããããç«ã¦ã¦ã¹ãã£ã³ãããã®ã§ããä¸å¿nmapã®ããã¥ã¢ã«ã«ã¯ãããããç¹æ®ãªã¹ãã£ã³ããããã¨ã§ä¸é¨ã®ãã¡ã¤ã¢ã¦ã©ã¼ã«ãééã§ããå ´åãããâ¦â¦ã¨ãããã¨ãæ¸ãã¦ããã¾ãããã¾ãããã¤ãã§ãå®è·µã§ãã®ã¹ãã£ã³ã使ããã¨ã¯ã¾ãç¡ãããããããããããããã£ã±ãç«ã£ã¦ãã¦ãã«ãã«ãã¦ããããã¯ãªã¹ãã¹ããªã¼ã®ããã â¦â¦ã¨ãããã¨ã§ã¯ãªã¹ãã¹ã¹ãã£ã³ã¨å¼ã°ãã説ãæåã§ãã
ã¯ãªã¹ãã¹ã¹ãã£ã³ããã£ã¨ãã«ãã«ããã
ãã¦ããããªãã¨ãããã£ãã®3bitãããã®è¶³ãããTCP Flagsã®å ¨bitãç«ã¦ã¦ãã£ã¨ãã«ãã«ãããããã¨æãã®ã人æ ã¨ãããã®ã§ããnmapã§ã¯--scanflagsãªãã·ã§ã³ãä»ããã¨ãããå®ç¾ã§ãã¾ãã
ããæ¹ã¯2ã¤ãã£ã¦ãä¸ã¤ã¯TCP Flagsã¯6bitãªã®ã§ãã--scanflags 63ãã¨æå®ããã°å ¨ãããèµ·ç«ãããã±ãããé£ã³ã¾ããããä¸ã¤ã¯æååæå®ã§ãã--scanflags URGACKPSHRSTSYNFINãã¨ãURGããFINã¾ã§å ¨é¨ä¸¦ã¹ãã¨ããããå ¨TCP Flagsã®ããããç«ã£ããã±ãããé£ã³ã¾ãã
# nmap -v --scanflags 63 -p 22 10.5.17.208 ã¾ã㯠# nmap -v --scanflags URGACKPSHRSTSYNFIN -p 22 10.5.17.208
ããã§ã6bitç«ã¡ã¾ããããã©ãã©ãã¦ã¾ããã
TCP Flagsã¯9bit
ã¨ãããã¾ã§æ¸ãã¦ãã? ã¨æã£ãæ¹ãããã§ãããããããå®ã¯TCP Flagsã¯å¾å¹´ããã«æ¡å¼µããã¦ãããç¾å¨ã¯6bitã§ã¯ããã¾ããï¼ç§ã大å¦ã§å¦ãã ã¨ãã¯ãã¾ã 6bitã ã£ããã ãã©ãªãï¼ã
å ã äºåã«ç¨æããã¦ããäºç´ãããã使ãå½¢ã§ãã¾ãRFC 3168ã§ãECN-Echo(ECE)ã¨Congestion Window Reduced(CWR)ã®2bitã追å ããã¾ãããããã«RFC 3540ã§ãECN-nonce(NS)ã®1bitã追å ããã¾ãããã¨ããããã§ããã§ãã£ã¨ãã«ãã«ãã©ãã©ããã¹ãã£ã³ãã§ããã! ã¨ããããã§ãããã¡ãã£ã¨è©¦ããéãã--scanflagsã¯255ã¾ã§ããæå®ã§ããªãã®ã§9bitãããã©ãã©ããããã¨ãã§ãã¾ããã§ãããæ¬å½ã¯ã§ããã®ããããã¾ãããã©ãç§ã®ç¥èä¸è¶³ï¼æéåãã§ãã
# nmap -v --scanflags 255 -p 22 192.168.2.9 ã¾ã㯠# nmap -v --scanflags CWRECEURGACKPSHRSTSYNFIN -p 22 192.168.2.9
ããã§ã8bitãã©ãã©ããããã¨ãã§ãã¾ãã! ãããªãããããã¯ãªã¹ãã¹ããªã¼ã¨è¨ããã§ããã(ãã¶ã)ããªãããã®ã¹ãã£ã³ã®å®ç¨æ§ã¯ãã¾ããèªå·±æºè¶³ã ããªã®ã§ã¼ãã§ããâ¦â¦ã
è£è¶³ããã¨ãscanflagsãªãã·ã§ã³ã¯å¥¥ãæ·±ããããã®çµã¿åããã§OSæ¤åºãã§ããã!ãã¨ãããã¯ãªã¹ãã¹ã¹ãã£ã³ã§ç¹å®ã®ACLãåé¿ã§ããã!ãã¨ãè²ã ã¨è°è«ã»ç 究ãããã¦ããã®ã§ãããã¡ãã£ã¨ããã¾ã§è©³ãã調ã¹ã¦ãªãï¼ããç¥ããªãã®ã§ããã§ã¯ã¤ã£ãã¾ãªããã¨ã«ãã¾ãã
ã¨ãããã¨ã§ä¸éå端ã§ãããããã¾ãã
åèãªã³ã¯
- Nmapの真実
- abendããã«ããNmapé¢ç½ãã¿ãã¯ãªã¹ãã¹ã¹ãã£ã³ã®è©±ãåºã¦ãã¾ããããããã