Practical Tools

1๏ธโƒฃ Practical Tools ๐Ÿ“œNetcat tcp , udp protocol ์‚ฌ์šฉ Connecting tcp/udp port nc -nv 10.11.0.22 4444 Listening on a TCP/UDP Port nc -nlvp 4444 Transferring Files w/ Netcat nc -nlvp 4444 > incoming.exe nc -nv 10.11.0.22 4444 < /usr/share/windows-resources/binaries/wget.exe ๐Ÿ“œSocat Connecting socat - TCP4:<remote serverโ€™s ip address>:80 Listening sudo socat TCP4-LISTEN:443 STDOUT File Transfers sudo socat TCP4-LISTEN:443,fork file:secret_passwords.txt ๐Ÿ“œPowershell and powercat ๐Ÿ“œWireshark ๐Ÿ“œTcpdump

September 20, 2023 ยท CrackerNote

linux ํ•„์ˆ˜ command

1๏ธโƒฃ linux ํ•„์ˆ˜ Command ๐Ÿ“œMan Pages man ๐Ÿ“œapropos apropos ๐Ÿ“œListing Files ls -al ๐Ÿ“œMoving Around cd pwd ๐Ÿ“œCreating Directories mkdir mkdir module one cd module\ one/ mkdir -p ๐Ÿ“œFinding Files echo which locate find ๐Ÿ“œManaging Kali Linux Services systemctl SSH Service sudo systemctl start ssh (ssh ์‹œ์ž‘) sudo ss -antlp | grep sshd (ssh ๊ตฌ๋™ ํ™•์ธ) sudo systemctl enable ssh (๋ถ€ํŒ…์‹œ ssh ์‹คํ–‰) HTTP service sudo systemctl start apache2 sudo ss -antlp | grep apache...

August 20, 2023 ยท CrackerNote

Assembly ๊ธฐ์ดˆ

1๏ธโƒฃ Assembly ๊ธฐ์ดˆ ๐Ÿ“œํ”„๋กœ๊ทธ๋žจ๊ณผ ๋ฉ”๋ชจ๋ฆฌ - ํ”„๋กœ์„ธ์Šค : ๋ฉ”๋ชจ๋ฆฌ์— ๋กœ๋“œ๋œ ํ”„๋กœ๊ทธ๋žจ - ํ”„๋กœ๊ทธ๋žจ์€ ํฌ๊ฒŒ ์ฝ”๋“œ, ๋ฐ์ดํ„ฐ๋กœ ๋‚˜๋ˆ„์–ด ๋ณผ ์ˆ˜ ์žˆ์Œ - ํ”„๋กœ๊ทธ๋žจ์—์„œ ์‚ฌ์šฉํ•˜๋Š” ์ฝ”๋“œ์™€ ๋ฐ์ดํ„ฐ๋Š” ๋ฉ”๋ชจ๋ฆฌ์— ๋กœ๋“œ๋˜๋ฉฐ, ์ฝ”๋“œ ์‹คํ–‰ ํ๋ฆ„์— ๋”ฐ๋ผ ๋ณ€ํ™”ํ•˜๋Š” ๊ฐ’๋“ค์€ ์Šคํƒ ๋˜๋Š” ํž™์— ์Œ“์ด๊ฒŒ๋จ - ์šด์˜์ฒด์ œ๋Š” ํ”„๋กœ์„ธ์Šค๋“ค์˜ ๋…๋ฆฝ์ ์ธ ๊ณต๊ฐ„์„ ๋ณด์žฅํ•จ - ๋‹ค๋ฅธ ํ”„๋กœ์„ธ์Šค์˜ ์˜์—ญ์„ ํ•จ๋ถ€๋กœ ์ ‘๊ทผํ•˜๋Š” ๊ฒƒ์„ ๋ง‰๋Š” ๋งค์ปค๋‹ˆ์ฆ˜์ด ์กด์žฌ - ํ”„๋กœ์„ธ์Šค์™€ ๋ฉ”๋ชจ๋ฆฌ ๊ด€๋ฆฌ๋Š” ์šด์˜์ฒด์ œ์— ์˜ํ•ด์„œ ์ด๋ฃจ์–ด์ง ๐Ÿ“œ์Šคํƒ(Stack) - LIFO ๊ตฌ์กฐ : Last In - First Out, ๊ฐ€์žฅ ์ฒ˜์Œ์— ๋“ค์–ด๊ฐ„ ๋ฐ์ดํ„ฐ๊ฐ€ ๊ฐ€์žฅ ๋‚˜์ค‘์— ์˜ด...

August 3, 2023 ยท CrackerNote

SQL Injection ์ทจ์•ฝ์  ์ ๊ฒ€

1๏ธโƒฃ SQL Injection ์ทจ์•ฝ์  ์ ๊ฒ€ ๐Ÿ“œSQL Injection ์—๋Ÿฌ ์œ /๋ฌด ํ™•์ธ ์ทจ์•ฝ์  ์œ /๋ฌด ํ™•์ธ ๊ฒ€์ƒ‰๋ž€์˜ ๊ฒฝ์šฐ, ์—ฐ๊ฒฐ์—ฐ์‚ฐ์ž ์‚ฌ์šฉ a. โ€™ โ€™ ๋กœ ์‚ฌ์šฉํ•˜์—ฌ ์ •์ƒ์ž‘๋™ ํ•œ๋‹ค๋ฉด (teโ€™ โ€˜st), Mysql b. โ€˜+โ€™ ๋กœ ์‚ฌ์šฉํ•˜์—ฌ ์ •์ƒ์ž‘๋™ ํ•œ๋‹ค๋ฉด (teโ€™+โ€˜st), Mssql c. โ€˜||โ€™ ๋กœ ์‚ฌ์šฉํ•˜์—ฌ ์ •์ƒ์ž‘๋™ ํ•œ๋‹ค๋ฉด (teโ€™||โ€˜st), Oracle ์กฐ๊ฑด ๊ตฌ๋ฌธ ์™„์„ฑ ๐Ÿ“œ๋ฐฉ๋ฒ•๋ก  1) ๊ฒ€์ƒ‰๊ธฐ๋Šฅ์— ๋Œ€ํ•œ ์ทจ์•ฝ์  ์ ๊ฒ€ a. select * from board where title like โ€˜% โ€˜||(case when 1=1 then โ€™testโ€™ else โ€˜aaaaโ€™ end)||โ€™ %โ€™...

July 20, 2023 ยท CrackerNote

SQL Injection ์šฐํšŒ๊ธฐ๋ฒ•

1๏ธโƒฃ SQL Injection ์šฐํšŒ๊ธฐ๋ฒ• ๐Ÿ“œSQL Injection ๊ณต๊ฒฉ์‹œ ๊ณต๋ฐฑ ๋ฌธ์ž ํ•„ํ„ฐ๋ง์‹œ ์šฐํšŒ ๋ฐฉ๋ฒ• Tab : %09 - no=1%09or%09id=โ€˜adminโ€™ Line Feed (\n): %0a - no=1%0aor%0aid=โ€˜adminโ€™ Carrage Return(\r) : %0d - no=1%0dor%0did=โ€˜adminโ€™ ์ฃผ์„ : /**/ - no=1//or//id=โ€˜adminโ€™ ๊ด„ํ˜ธ : () - no=(1)or(id=โ€˜adminโ€™) ๋”ํ•˜๊ธฐ : + - no=1+or+id=โ€˜adminโ€™

July 19, 2023 ยท CrackerNote