๐Ÿ’ญ Minji's Archive

Latest Updates

Dev Log

Velog์—์„œ ์ž‘์„ฑํ•œ ๋ชจ๋“  ํฌ์ŠคํŠธ๋ฅผ ์นด๋“œ ํ˜•ํƒœ๋กœ ๋ชจ์•˜์Šต๋‹ˆ๋‹ค.

[๊ธฐํƒ€] ๋„คํŠธ์›Œํฌ ๊ธฐ์ดˆ ๋ณต์Šต!

์ •๋ณด์ฒ˜๋ฆฌ๊ธฐ์‚ฌ๋ฅผ ๊ณต๋ถ€ํ•˜๋Š” ์ค‘์ธ๋ฐ, ๋ถ„๋ช… ํ•™๋ถ€ ๋•Œ ์ „๋ถ€ ์™ธ์› ๋˜ ๊ธฐ์–ต์€ ์žˆ๋Š” ๋‚ด์šฉ๋“ค์ดโ€ฆ ์ œ๋Œ€๋กœ ๊ธฐ์–ต์€ ํ•˜๋‚˜๋„ ๋‚˜์ง€ ์•Š๋Š”๋‹ค. ๋„คํŠธ์›Œํฌ๋Š” ๊ธฐ๋ณธ ์ค‘์˜ ๊ธฐ๋ณธ์ด๋ผ ์™ธ์›Œ์งˆ ๋•Œ๊นŒ์ง€ ๋ด์•ผ ํ•จ. ์ด ํฌ์ŠคํŠธ๋ฅผ ๊ณ„์† ์ˆ˜์ •ํ•ด ๊ฐ€๋ฉด์„œ ๊ธฐ๋ณธ๋ถ€ํ„ฐ ๋ณด์•ˆ+์‹ฌํ™”๊นŒ์ง€ ์ด์ •๋ฆฌ๋ฅผ ํ•ด๋ณด๋ ค๊ณ ...

kt cloud techup

[kt cloud techup] ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ vs ์ด๋ฏธ์ง€ / ์ปจํ…Œ์ด๋„ˆ / ํ…Œ๋ผํผ vs ํดํผ

1. ์ด๋ฏธ์ง€๋ž€? ์ปจํ…Œ์ด๋„ˆ๋ฅผ ์‹คํ–‰ํ•˜๊ธฐ ์œ„ํ•œ ์„ค๊ณ„๋„ (ํŒจํ‚ค์ง€) ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ์ฝ”๋“œ ์‹คํ–‰ ํ™˜๊ฒฝ(OS ๋ ˆ์ด์–ด, ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ) ์„ค์ •๊ฐ’, ์‹คํ–‰ ๋ช…๋ น์–ด(CMD/ENTRYPOINT) ์ด ๋ชจ๋“  ๊ฒƒ์ด ๋ถˆ๋ณ€ ํ˜•ํƒœ๋กœ ๋ฌถ์—ฌ ์žˆ์Œ ์ง์ ‘ ์‹คํ–‰๋˜์ง€ ์•Š์Œ ...

2SeC

[2SeC] SIEM์—์„œ Detection์„ Sigma๋กœ ์˜ฎ๊ธด ์ด์œ 

โ€” Sigma Rule๊ณผ OpenSearch Security Analytics ์™„์ „ ๊ธฐ์ดˆ ์ •๋ฆฌ 1. ์ด ๊ธ€์˜ ๋ชฉ์  SIEM์„ ๋งŒ๋“ค๊ฑฐ๋‚˜ ์šด์˜ํ•˜๋‹ค ๋ณด๋ฉด โ€œํƒ์ง€(detection)๋ฅผ ์–ด๋””์„œ, ์–ด๋–ป๊ฒŒ ํ•  ๊ฒƒ์ธ๊ฐ€?โ€๋ผ๋Š” ์งˆ๋ฌธ์„ ํ”ผํ•  ์ˆ˜ ์—†์Šต๋‹ˆ๋‹ค. ์ด ๊ธ€...

2SeC

[2SeC] CTI ๊ฐœ๋… ๋ฐ ํ”„๋กœ์ ํŠธ ์ ์šฉ ๋ฐฉ์•ˆ ์ •๋ฆฌ

1. CTI๋ž€ ๋ฌด์—‡์ธ๊ฐ€ 1.1 CTI์˜ ์ •์˜ ๋‹จ์ˆœํ•œ ๊ณต๊ฒฉ ๋กœ๊ทธ๋‚˜ ์ด๋ฒคํŠธ๊ฐ€ ์•„๋‹ˆ๋ผ, ๊ณต๊ฒฉ์ž์˜ ์˜๋„, ์ „์ˆ ยท๊ธฐ๋ฒ•ยท์ ˆ์ฐจ(TTPs), ์บ ํŽ˜์ธ, ์ธํ”„๋ผ, ํ”ผํ•ด ๋Œ€์ƒ์„ ๋งฅ๋ฝ(Context)๊ณผ ํ•จ๊ป˜ ๋ถ„์„ยท๊ตฌ์กฐํ™”ํ•œ ์ •๋ณด ๋‹จ์ˆœ โ€œSQL Injection...

2SeC

[2SeC] AWS ๋ ˆ์ด์–ด ์ดํ•ดํ•˜๊ธฐ + 2SeC ๊ตฌ์กฐ ์ดํ•ดํ•˜๊ธฐ

๊ฐœ์š” ์šฐ๋ฆฌ ํ”„๋กœ์ ํŠธ๋Š” EC2์—์„œ ๋ฐœ์ƒํ•œ ์›น ๊ณต๊ฒฉ/์ ‘๊ทผ ๋กœ๊ทธ๋ฅผ CloudWatch -> Kinesis -> ECS(Fargate) ์œ„์˜ Logstash๋กœ ์‹ค์‹œ๊ฐ„ ์ฒ˜๋ฆฌ -> OpenSearch์— ์ ์žฌ + S3์—๋Š” ์›๋ณธ ์žฅ๊ธฐ ๋ณด๊ด€ ์ด๋ ‡...

2SeC

[2SeC] ํŠธ๋Ÿฌ๋ธ”์ŠˆํŒ…: Logstash -> Opensearch ๋กœ๊ทธ๊ฐ€ ์•ˆ ๋“ค์–ด๊ฐ€๋Š” ์ด์Šˆ...

ECS ํ™˜๊ฒฝ๊ณผ ๋กœ์ปฌ Docker ํ…Œ์ŠคํŠธ์˜ ๊ฒฐ์ •์ ์ธ ์ฐจ์ด 0. ๋ฌธ์ œ ์ƒํ™ฉ ์š”์•ฝ 2SeC-SIEM ํ”„๋กœ์ ํŠธ์—์„œ Kinesis โ†’ Logstash(ECS Fargate) โ†’ OpenSearch ํŒŒ์ดํ”„๋ผ์ธ์„ ๊ตฌ์ถ•ํ•˜๋˜ ์ค‘, Logstash ์ปจํ…Œ์ด๋„ˆ๋Š” ...

2SeC

[2SeC] AWS OpenSearch ๋Œ€์‹œ๋ณด๋“œ ์ ‘์† ํŠธ๋Ÿฌ๋ธ”์ŠˆํŒ…

๊ฐœ์š” aws-es-proxy๋Š” ์™œ ๋‚ด ์ž๊ฒฉ์ฆ๋ช…์„ ๋ชป ์ฐพ์•˜์„๊นŒ? ์˜ค๋Š˜ ์˜คํ”ˆ์„œ์น˜ ๋Œ€์‹œ๋ณด๋“œ์— ์ ‘์†ํ•˜๋ ค๋‹ค๊ฐ€ ๋ชจ๋ฅด๋Š” ๊ฐœ๋…์„ ๋งˆ์ฃผํ•˜๊ฒŒ ๋˜์–ด์„œ ์ด๋ ‡๊ฒŒ ๋ธ”๋กœ๊ทธ๋ฅผ ์ž‘์„ฑํ•œ๋‹ค. export AWS_SDK_LOAD_CONFIG=1 ์ด๋ผ๋Š” ๋ช…๋ น์–ด๊ฐ€ ํ•ต์‹ฌ์ด์—ˆ๋Š”๋ฐ, ์ด ์•ˆ...

2SeC

[2SeC] Terraform + GitHub Actions ๊ธฐ๋ฐ˜ SIEM ์ธํ”„๋ผ ๊ตฌ์ถ• ์‚ฝ์งˆ๊ธฐ (OpenSearch, ECS, SSM)

Terraform์œผ๋กœ SIEM ์‹ค์Šต ์ธํ”„๋ผ๋ฅผ ๊ตฌ์ถ•ํ•˜๋ฉด์„œ ์‹ค์ œ๋กœ ๊ฒช์€ ๋ฌธ์ œ๋“ค๊ณผ ํ•ด๊ฒฐ ๊ณผ์ •์„ ์ •๋ฆฌํ•ด๋ณด๊ณ ์ž ํ•œ๋‹ค. ์€๊ทผ ์‚ฝ์งˆ์„ ๋งŽ์ด ํ•ด์„œ ์™œ ๋ง‰ํ˜”๊ณ , ์–ด๋–ป๊ฒŒ ํ’€์—ˆ๋Š”์ง€๋ฅผ ์œ„์ฃผ๋กœ ์ž‘์„ฑํ•ด๋ณผ๋ ค๊ณ  ํ•œ๋‹ค. 1. ๋ชฉํ‘œ: โ€œ๋กœ๊น… ๊ฐ€๋Šฅํ•œ SIEM ๋ฒ ์ด์Šค๋ผ์ธโ€ ๋งŒ๋“ค๊ธฐ...

2SeC

[2SeC] ECS EC2 Launch Type์—์„œ ์˜๋„์น˜ ์•Š์€ AMI ํ”„๋กœ๋น„์ €๋‹ ์ด์Šˆ ๋ถ„์„

1. ์‚ฌ๊ฑด ๊ฐœ์š” CloudTrail ์ด๋ฒคํŠธ๋ฅผ ํ™•์ธํ•œ ๊ฒฐ๊ณผ, admin-02 ์‚ฌ์šฉ์ž์— ์˜ํ•ด RunInstances ์ด๋ฒคํŠธ๊ฐ€ ๋ฐ˜๋ณต์ ์œผ๋กœ ๋ฐœ์ƒํ–ˆ๊ณ , ๊ทธ ๊ณผ์ •์—์„œ ์•„๋ž˜ AMI๊ฐ€ ์ง€์†์ ์œผ๋กœ EC2 ์ธ์Šคํ„ด์Šค๋กœ ์ƒ์„ฑ๋˜์—ˆ๋‹ค. AMI ID: ami-0d1...

2SeC

[2SeC] Terraform? OpenSearch?

Terraform IaC ๋„๊ตฌ๋กœ, ์ฝ”๋“œ๋ฅผ ์‚ฌ์šฉํ•ด ์ธํ”„๋ผ๋ฅผ ์ •์˜ํ•˜๊ณ  ํ”„๋กœ๋น„์ €๋‹ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•œ๋‹ค. 1. ์ฃผ์š” ๊ฐœ๋… Provider: Terraform์ด ํด๋ผ์šฐ๋“œ(AWS, Azure ๋“ฑ) ๋˜๋Š” ์„œ๋น„์Šค API์™€ ํ†ต์‹ ํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉํ•˜๋Š” ํ”Œ๋Ÿฌ...

2SeC

[2SeC] Terraform? OpenSearch? + ํŒŒ์ดํ”„๋ผ์ธ ๊ตฌ์กฐ

Terraform IaC ๋„๊ตฌ๋กœ, ์ฝ”๋“œ๋ฅผ ์‚ฌ์šฉํ•ด ์ธํ”„๋ผ๋ฅผ ์ •์˜ํ•˜๊ณ  ํ”„๋กœ๋น„์ €๋‹ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•œ๋‹ค. 1. ์ฃผ์š” ๊ฐœ๋… Provider: Terraform์ด ํด๋ผ์šฐ๋“œ(AWS, Azure ๋“ฑ) ๋˜๋Š” ์„œ๋น„์Šค API์™€ ํ†ต์‹ ํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉํ•˜๋Š” ํ”Œ๋Ÿฌ...

2SeC

[2SeC] SIEM ๊ตฌ์„ฑ ์ „ ๋ฐฐ๊ฒฝ์ง€์‹

2SeC ํ”„๋กœ์ ํŠธ์—์„œ๋Š” IaC ๊ธฐ๋ฐ˜ AWS ์ธํ”„๋ผ ์œ„์— ์‹ค์Šต์šฉ ์›น ์„œ๋น„์Šค(DVWA/Juice Shop)๋ฅผ ๊ตฌ์„ฑํ•˜๊ณ , ๋‹ค์–‘ํ•œ ๋ณด์•ˆ ๋กœ๊ทธ๋ฅผ ์ˆ˜์ง‘ยท์ €์žฅยท๋ชจ๋‹ˆํ„ฐ๋งํ•  ์ˆ˜ ์žˆ๋Š” SIEM ํ™˜๊ฒฝ์„ ๊ตฌ์ถ•ํ•˜๋Š” ๊ฒƒโ€์ด 1์ฐจ ๋ชฉํ‘œ์ด๋‹ค. ์ดํ›„ 2์ฐจ ํ™•์žฅ ๋ชฉํ‘œ๋กœ LLM...

s2n

[s2n] yaml ์•ˆ์—์„œ ๋ถ„๊ธฐ์ฒ˜๋ฆฌํ•˜๊ธฐ +CloudFormation์ด๋ž€?

dev.yml ํŒŒ์ผ์€ โ€œ๋ฐฑ์—”๋“œ Docker ์ด๋ฏธ์ง€ ๋นŒ๋“œ ํ›„ GHCR์— pushโ€๊นŒ์ง€๋งŒ ์ฒ˜๋ฆฌํ•˜๊ณ  ์žˆ์Œ. ๋ถ„๊ธฐ์ฒ˜๋ฆฌ (yaml ์•ˆ์—์„œ), ๋ณ€๊ฒฝ๋œ ํŒŒ์ผ์ด ํŠน์ • ๋””๋ ‰ํ† ๋ฆฌ์ผ ๋•Œ๋งŒ ๋นŒ๋“œ/๋ฐฐํฌ๋ฅผ ํ•  ๊ฒƒ. CloudFormation AWS์—์„œ...

s2n

[s2n] (๋‚ด๊ฐ€ ํ—ท๊ฐˆ๋ ธ๋˜) AWS ์ธํ”„๋ผ + Docker ๋„คํŠธ์›Œํฌ + RDS ๋„คํŠธ์›Œํฌ ์ „์ฒด ํ๋ฆ„ ์ •๋ฆฌ

์ง€๊ธˆ ๊ตฌ์กฐ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™๋‹ค. EC2 ์•ˆ์— ๋„์ปค๋ฅผ ์˜ฌ๋ฆฌ๊ณ , ์ด ๋„์ปค๊ฐ€ RDS์— ์ ‘์†ํ•˜๋ฉด, โ€œ์ปจํ…Œ์ด๋„ˆ์˜ IPโ€๊ฐ€ ์•„๋‹ˆ๋ผ โ€œEC2์˜ IPโ€(์˜ˆ: 10.0.0.0)๋กœ ์ ‘์†ํ•˜๊ฒŒ ๋œ๋‹ค. ๊ทธ๋ž˜์„œ RDS์—๊ฒŒ ์ปจํ…Œ์ด๋„ˆ๋Š” ๋”ฐ๋กœ ์กด์žฌํ•˜์ง€ ์•Š๊ณ , ๋ชจ๋“  ์š”์ฒญ์„ EC2๊ฐ€ ...

s2n

[s2n] CI/CD ํŒŒ์ดํ”„๋ผ์ธ + AWS ํ†ตํ•ฉ

์‚ฌ์ „ ์ˆ˜์ • ์‚ฌํ•ญ dev.yml์—์„œ ๋นŒ๋“œํ•  ๋•Œ ๋ฐฑ์—”๋“œ ๊ฒฝ๋กœ์˜ Dockerfile์„ ๋ช…์‹œํ•ด์„œ ๋นŒ๋“œํ•ด์•ผ ํ•œ๋‹ค. Dockerfile ๋‚ด๋ถ€์—์„œ๋„ ๋ถˆํ•„์š”ํ•œ ํŒŒ์ผ ์ „์ฒด๋ฅผ COPYํ•˜์ง€ ์•Š๊ณ  ๋ฐฑ์—”๋“œ ์•ฑ ๊ด€๋ จ ํŒŒ์ผ๋งŒ ์ด๋ฏธ์ง€์— ํฌํ•จ์‹œํ‚ค๊ธฐ => dev....

s2n

[s2n] EC2 + Docker + GitHub Actions๋กœ Flask ๋ฐฐํฌํ•˜๊ธฐ

1๋‹จ๊ณ„: ๊ธฐ์ดˆ ์„ธํŒ… 1. Flask ์›น์•ฑ ์‹คํ–‰ ๊ตฌ์กฐ ์ ๊ฒ€ ํ˜„์žฌ ํŒŒ์ผ ๊ตฌ์กฐ๋Š” ์œ„์™€ ๊ฐ™๋‹ค. ์ผ๋‹จ ๋ฐฑ์—”๋“œ Flask๋งŒ ์‹คํ–‰๋˜๋ฉด ๋˜๊ธฐ ๋•Œ๋ฌธ์— Flask ์„œ๋ฒ„๋ฅผ backend/app.py์—์„œ ์‹คํ–‰ํ•œ๋‹ค. ํ˜„์žฌ๋Š” ํ…Œ์ŠคํŠธ๊ฐ€ ๊ฐ€๋Šฅํ•œ ์ƒํ™ฉ์ด ์•„๋‹ˆ๊ธฐ ๋•Œ๋ฌธ์— ํŒจ์Šค....

s2n

[s2n] EC2 + Docker + GitHub Actions๋กœ Flask ๋ฐฐํฌ ์„ค๊ณ„ํ•˜๊ธฐ

s2n ์Šค์บ๋„ˆ์˜ MVP ๊ฐœ๋ฐœ์€ ์–ผ์ถ” ๋๋‚ฌ๊ณ , ์ด ์Šค์บ๋„ˆ๋ฅผ ํ…Œ์ŠคํŠธํ•˜๊ธฐ ์œ„ํ•ด ๊ฐ„๋‹จํ•œ Flask ๊ธฐ๋ฐ˜ ์ต๋ช… ์ฑ„ํŒ… ์›น์•ฑ์„ AWS์— ๋ฐฐํฌํ•˜๋Š” ์ž‘์—…์„ ์ง„ํ–‰ํ• ๋ ค๊ณ  ํ•œ๋‹ค. s2n ์Šค์บ๋„ˆ ์ž์ฒด๋Š” ์ด๋ฏธ dev/main ๋ธŒ๋žœ์น˜ ๊ธฐ์ค€์œผ๋กœ GHCR์— ๋„์ปค ์ด๋ฏธ์ง€๋ฅผ ์˜ฌ...

Side Project

[side project] Sprint 0: EDR/APT ํƒ์ง€ ์šฐํšŒ ์‹œ๋ฎฌ๋ ˆ์ด์…˜ ํ”„๋กœ์ ํŠธ

๊ฐœ์š” ์‹ค๋ฌด ์—ญ๋Ÿ‰์„ ์ข€ ๋” ๊ฐ•ํ™”ํ•˜๊ณ ์ž ์‚ฌ์ด๋“œ ํ”„๋กœ์ ํŠธ๋ฅผ ์ง„ํ–‰ํ•˜๊ธฐ๋กœ ๊ฒฐ์‹ฌํ–ˆ๋‹ค. ์ฒซ ๋ฒˆ์งธ ์ฃผ์ œ๋กœ ์ •ํ•œ ๊ฒƒ์€ EDR์„ ํ™œ์šฉํ•œ APT ๊ณต๊ฒฉ ๊ทธ๋ฃน์˜ TTP ๋ชจ๋ฐฉ ๋ฐ ํƒ์ง€ ์šฐํšŒ ์‹œ๋ฎฌ๋ ˆ์ด์…˜์ด๋‹ค. ์ด ํ”„๋กœ์ ํŠธ๋ฅผ ํ†ตํ•ด EDR ์†”๋ฃจ์…˜์˜ ์ž‘๋™ ์›๋ฆฌ๋ฅผ ์ œ๋Œ€๋กœ ์ดํ•ดํ•˜๊ณ ,...

s2n

[s2n] ํ…Œ์ŠคํŠธ์šฉ ์›น + AWS ์•„ํ‚คํ…์ฒ˜ ๊ตฌ์กฐ ์„ค๊ณ„

ํ˜„์žฌ ํŒ€์›๋“ค์ด ์„ค๊ณ„ํ•œ ์›น์„œ๋น„์Šค ์š”๊ฑด React ํ”„๋ก ํŠธ์—”๋“œ ์›น์†Œ์ผ“ ์‹ค์‹œ๊ฐ„ ์ฑ„ํŒ… Python(Flask/FastAPI) ๋ฐฑ์—”๋“œ ๋ฉ”์‹œ์ง€ ์ €์žฅ (DB) XSS ๋“ฑ ๊ธฐ๋ณธ ๋ณด์•ˆ ์ฒ˜๋ฆฌ -> ํด๋ผ์ด์–ธํŠธ/์„œ๋ฒ„ ๊ตฌ์กฐ๋กœ ๋ฐ˜๋“œ์‹œ ์กด์žฌํ•ด์•ผ ํ•จ ...

s2n

[s2n] โญ๏ธโญ๏ธโญ๏ธโญ๏ธโญ๏ธ ๋„์ปค ์ด๋ฏธ์ง€ ๋นŒ๋“œ/๋“ฑ๋ก ๊ณต๋ถ€ + ๋กœ์ง ์„ค๊ณ„

1. ๋ฐฐ๊ฒฝ์ง€์‹ ๊ณต๋ถ€ ๐Ÿณ 1. DockerFile ์ž‘์„ฑ (DEV/PROD ๋ถ„๋ฆฌ) ๋‘ ๊ฐœ์˜ ์ด๋ฏธ์ง€๋ฅผ ํ•˜๋‚˜์˜ DockerFile๋กœ ๊ด€๋ฆฌํ•˜๊ฑฐ๋‚˜, ๋ช…ํ™•ํžˆ ๋ถ„๋ฆฌ๋œ ๋‘ ๊ฐœ์˜ ํŒŒ์ผ๋กœ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๋‹ค. ๋ฉ€ํ‹ฐ ์Šคํ…Œ์ด์ง€ ๋นŒ๋“œ ํ•˜๋‚˜...

s2n

[s2n] ๋„์ปค ๊ธฐ๋ฐ˜ ๋Ÿฐํƒ€์ž„ ์•„ํ‚คํ…์ฒ˜ ์„ค๊ณ„ + ๋ฐฐ๊ฒฝ์ง€์‹ ๊ณต๋ถ€

์ด๋ฒˆ์— ๋‚ด๊ฐ€ ๋‹ด๋‹นํ•œ ํ‹ฐ์ผ“์€ โ€œ์Šค์บ๋„ˆ๊ฐ€ ์‹คํ–‰๋˜๋Š” ํƒ€์ž„ ํ™˜๊ฒฝ ์ „์ฒด ์„ค๊ณ„โ€ํ•˜๊ธฐ์ด๋‹ค. ์ฆ‰ PyPI ํŒจํ‚ค์ง€๋กœ ๋ฐฐํฌ๋œ s2n์ด ์–ด๋””์„œ, ์–ด๋–ค ํ™˜๊ฒฝ์—์„œ, ์–ด๋–ค ๋ฐฉ์‹์œผ๋กœ ๋™์ž‘ํ• ์ง€๋ฅผ ๊ฒฐ์ •ํ•˜๊ณ  ๊ตฌํ˜„ํ•˜๋Š” ๊ฒƒ์ด๋‹ค. ํ•ต์‹ฌ ์ž‘์—… 1) prod/dev Docker ์ด๋ฏธ์ง€...

s2n

[s2n] ๋Ÿฐํƒ€์ž„ ํ™˜๊ฒฝ ๊ฒฉ๋ฆฌํ™” vs ๊ฐœ๋ฐœ ํ™˜๊ฒฝ ๊ฒฉ๋ฆฌํ™”

1) ๋Ÿฐํƒ€์ž„ ํ™˜๊ฒฝ ๊ฒฉ๋ฆฌ ๋ชฉ์  ํŒจํ‚ค์ง€๊ฐ€ ์‹ค์ œ๋กœ ๋ฐฐํฌ๋œ ๋’ค, ์‚ฌ์šฉ์ž ์‹œ์Šคํ…œ์—์„œ ์•ˆ์ „ํ•˜๊ณ  ์ผ๊ด€๋˜๊ฒŒ ์‹คํ–‰๋˜๋„๋ก ๋ณด์žฅํ•˜๋Š” ๊ฒƒ -> ์ฆ‰ PyPI์— ์˜ฌ๋ผ๊ฐ„ s2n์ด ํ˜„์—…์—์„œ ์ถฉ๋Œ ์—†์ด ๋™์ž‘ํ•ด์•ผ ํ•˜๋Š” ํ™˜๊ฒฝ ์ตœ์ข… ์‚ฌ์šฉ์ž์—๊ฒŒ ๋ฌธ์ œ๊ฐ€ ์ƒ๊ธฐ์ง€ ์•Š๊ฒŒ ๋ฐฐํฌ...

Side Project

[side project] ๐Ÿงจ Mac์—์„œ Wazuh Docker๋กœ ๋Œ๋ฆฌ๋ ค๋‹ค๊ฐ€ ์‚ฝ์งˆํ•œ ๊ธฐ๋ก

1๋‹จ๊ณ„. ํ”„๋กœ์ ํŠธ ๋””๋ ‰ํ„ฐ๋ฆฌ ๋งŒ๋“ค๊ธฐ ์ด๋ฒˆ ํ”„๋กœ์ ํŠธ์—์„œ๋Š” mini-soc-lab ํด๋” ์•„๋ž˜์— wazuh/, dvwa/, notes/ ๊ตฌ์กฐ๋กœ ํด๋”๋ฅผ ๊ตฌ์„ฑํ–ˆ๋‹ค. wazuh/์—๋Š” SIEM ํ™˜๊ฒฝ ๊ตฌ์„ฑ์„ ์œ„ํ•œ docker-compose ํŒŒ์ผ๋“ค, dv...

[๊ธฐํƒ€] Wazuh ์™„์ „์ •๋ณต: ์˜คํ”ˆ์†Œ์Šค SIEM + XDR ํ”Œ๋žซํผ์ด๋ž€?

Wazuh๋Š” ๋ณด์•ˆ ๋กœ๊ทธ๋ฅผ ์ˆ˜์ง‘ํ•˜๊ณ , ํƒ์ง€ ๊ทœ์น™์„ ์ ์šฉํ•˜๊ณ , ์‹ค์‹œ๊ฐ„์œผ๋กœ ์•Œ๋ฆผ์„ ๋ฐ›์œผ๋ฉฐ, ์—”๋“œํฌ์ธํŠธ๊นŒ์ง€ ํ†ตํ•ฉ์ ์œผ๋กœ ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๋Š” ์˜คํ”ˆ์†Œ์Šค ํ”Œ๋žซํผ์ด๋‹ค. EDR/XDR, SIEM ์‹ค์Šต์„ ํ•˜๊ณ  ์‹ถ์ง€๋งŒ ์ƒ์šฉ ์†”๋ฃจ์…˜์€ ๋„ˆ๋ฌด ๋น„์‹ธ ํ˜„์‹ค์ ์œผ๋กœ ์™€์ฃผ๋ฅผ ํƒํ•˜๊ฒŒ ๋˜...

s2n

[s2n] cli - runner ํ…Œ์ŠคํŠธ ์ฝ”๋“œ ์ž‘์„ฑ

์ด์ œ ์Šฌ์Šฌ ๊ทœ๋ชจ๊ฐ€ ์ปค์ง„๋‹คโ€ฆ runner์—์„œ ๋ชจ๋“  ํ”Œ๋Ÿฌ๊ทธ์ธ์„ ๋ชจ์•„์„œ ์‹คํ–‰ํ•˜๊ณ  output๊นŒ์ง€ ๋ณด์—ฌ์ค˜์•ผ ํ•˜๋Š”๋ฐ, ํ˜„์žฌ plugin๋“ค์—์„œ ์–ด๋งˆ์–ด๋งˆํ•˜๊ฒŒ ๋งŽ์€ ์—๋Ÿฌ๊ฐ€ ๋ฐœ์ƒํ•œ๋‹ค. ์ด ๋ถ€๋ถ„์€ ์ฝ”์–ดํŒ€์ด ํ•ด๊ฒฐํ•ด์•ผ ํ•  ์ผ์ด๋ผ ์ด ๋ถ€๋ถ„์„ ์ œ์™ธํ•˜๊ณ , ๋Ÿฌ๋„ˆ ์ž์ฒด๊ฐ€ ์ž˜ ...

s2n

[s2n] python venv ์™„์ „์ •๋ณต

์ด๋ฒˆ ํ”„๋กœ์ ํŠธ์—์„œ๋„ venv๋ฅผ ์‚ฌ์šฉํ–ˆ๋Š”๋ฐ ์ด๊ฒŒ ๋ญ”์ง€, ์™œ ์“ฐ๋Š”์ง€ ์ž˜ ๋ชจ๋ฅด๊ฒ ์–ด์„œ ๊ฐœ๋…์„ ์ •๋ฆฌํ•ด ๋ณด๊ณ ์ž ์ด ํฌ์ŠคํŒ…์„ ์ž‘์„ฑํ•˜๊ฒŒ ๋˜์—ˆ๋‹ค. 1. venv๋ž€? = virtual environment ์ฆ‰, ํ”„๋กœ์ ํŠธ๋งˆ๋‹ค ๋…๋ฆฝ๋œ ํŒŒ์ด์ฌ ํ™˜๊ฒฝ(ํŒŒ์ด์ฌ ๋ฒ„์ „ + ํŒจ...

s2n

[s2n] devlog - CLI ์ž…๋ ฅ ๋ฐ์ดํ„ฐ ๊ตฌ์กฐ ๋ฆฌํŒฉํ† ๋ง (CLIArguments -> ScanRequest)

1. ๊ฐœ์š” cli.py์—์„œ ๊ฐœ๋ณ„์ ์œผ๋กœ ์ฒ˜๋ฆฌ๋˜๊ณ  ์žˆ๋Š” CLI ์˜ต์…˜๋“ค์„ ๊ณตํ†ต ์ธํ„ฐํŽ˜์ด์Šค ๊ณ„์ธต์˜ ํƒ€์ž… ๊ตฌ์กฐ๋ฅผ ํ™œ์šฉํ•ด ํ†ตํ•ฉ๋œ ์ž…๋ ฅ ๋ฐ์ดํ„ฐ ํ”Œ๋กœ์šฐ๋กœ ์ •๋ฆฌํ•œ๋‹ค. ๊ธฐ์กด: click -> dict -> Scanner ๋ณ€๊ฒฝ: click -&g...

s2n

[s2n] CLI ์‹คํ–‰ ์ง„์ž…์  ๋งŒ๋“ค๊ธฐ (cli.py)

1. ๋ฌธ์ œ ๋ถ„ํ•ด CLI ๊ธฐ๋Šฅ์„ ๋ณด๋ฉด 4๊ฐ€์ง€ ๋ช…๋ น์–ด๋กœ ๋‚˜๋ˆ ์ง„๋‹ค. (1) scan - ์‹ค์ œ ์ทจ์•ฝ์  ์Šค์บ” ์‹คํ–‰ URL ์ž…๋ ฅ, ํ”Œ๋Ÿฌ๊ทธ์ธ ์ง€์ •, ์ธ์ฆ ์˜ต์…˜, ๊ฒฐ๊ณผ ์ถœ๋ ฅ (2) crawl - ์‚ฌ์ดํŠธ ๋งํฌ ํƒ์ƒ‰ URL ์ž…๋ ฅ, ๊นŠ์ด ์„ค์ •, ์—”๋“œํฌ์ธํŠธ ์ˆ˜์ง‘ ...

s2n

[s2n] ์Šค์บ๋„ˆ ๋ฉ”์ธ ์—”์ง„ scanner.py ๊ตฌํ˜„ํ•˜๊ธฐ

1. ์„ค๊ณ„ ๊ฐœ์š” ๋ชฉํ‘œ: CLI๋‚˜ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋กœ Scanner๋ฅผ ํ˜ธ์ถœํ•˜๋ฉด (์„ ํƒ) DVWA Adapter๋กœ ๋กœ๊ทธ์ธ/์ธ์ฆ ์ˆ˜ํ–‰ (์„ ํƒ) httpClient๋ฅผ ๊ณต์œ  ์„ธ์…˜์œผ๋กœ ๋งŒ๋“ค์–ด์„œ ํ”Œ๋Ÿฌ๊ทธ์ธ์— ์ „๋‹ฌ ํ”Œ๋Ÿฌ๊ทธ์ธ๋“ค์„ ์ˆœ์ฐจ๋กœ ์‹คํ–‰ํ•ด Finding๋“ค...

s2n

[s2n] ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ CLI + import๊ฐ€ ๊ฐ€๋Šฅํ•˜๊ฒŒ ๊ตฌ์กฐํ™”ํ•˜๊ธฐ

1. ๋ฌธ์ œ ์ •์˜ s2n ์Šค์บ๋„ˆ๋ฅผ ํ„ฐ๋ฏธ๋„์—์„œ๋„, ํŒŒ์ด์ฌ ์ฝ”๋“œ์—์„œ๋„ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•  ๊ฒƒ ์ฆ‰, ํ•˜๋‚˜์˜ ์—”์ง„ (Scanner)์„ CLI, import ๋‘ ๊ฒฝ๋กœ๋กœ ๋ชจ๋‘ ์ ‘๊ทผ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•ด์•ผ ํ•จ. 2. ์š”๊ตฌ์‚ฌํ•ญ ๋„์ถœ (1) ๊ณตํ†ต ์—”์ง„์ด ํ•„์š”ํ•จ...

s2n

[s2n] OS Command Injection ์Šค์บ๋„ˆ ๊ฐœ๋ฐœ ์ผ์ง€

s2n ์Šค์บ๋„ˆ์— ๋“ค์–ด๊ฐˆ OS Command Injection ์Šค์บ๋„ˆ ๊ธฐ๋Šฅ์„ ๊ฐœ๋ฐœํ–ˆ์Šต๋‹ˆ๋‹ค. ์ด ํ”Œ๋Ÿฌ๊ทธ์ธ์€ base URL์—์„œ ์‹œ์ž‘ํ•ด ๋‚ด๋ถ€ ๋งํฌ๋ฅผ ์žฌ๊ท€ ํฌ๋กค๋งํ•˜๊ณ  (HTML ํŒŒ์‹ฑ ๊ธฐ๋ฐ˜), ๋ฐœ๊ฒฌํ•œ ํŽ˜์ด์ง€์˜ ํŒŒ๋ผ๋ฏธํ„ฐ๋ฅผ ์ž๋™ ์ถ”์ถœํ•ด OS Command I...

s2n

[s2n] DVWA Adapter & Selenium ์ž๋™ ๋กœ๊ทธ์ธ CLI ๊ตฌ์ถ•๊ธฐ

ํ”Œ๋Ÿฌ๊ทธ์ธ ๊ธฐ๋ฐ˜ ์›น ์ทจ์•ฝ์  ์Šค์บ๋„ˆ(PyPI ๋ฐฐํฌ ๋ชฉํ‘œ) ํ”„๋กœ์ ํŠธ s2n์˜ ์ธ์ฆ/์„ธ์…˜ ๊ด€๋ฆฌ ๊ตฌ์กฐ๋ฅผ ํ†ตํ•ฉํ•˜๊ธฐ ์œ„ํ•œ DVWAAdapter ๊ฐœ๋ฐœ๊ธฐ ๐ŸŽฏ ๋ฐฐ๊ฒฝ ์šฐ๋ฆฌ ํŒ€(503+1)์€ โ€œ์›น ์ทจ์•ฝ์  ์Šค์บ๋„ˆ ํŒŒ์ด์ฌ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌโ€๋ฅผ ๊ฐœ๋ฐœ ์ค‘์ด๋‹ค. ๊ฐ ํ”Œ๋Ÿฌ๊ทธ์ธ...

s2n

[s2n] GitHub Actions๋กœ CI/CD ํŒŒ์ดํ”„๋ผ์ธ ๊ตฌ์ถ•ํ•˜๊ธฐ (feat. ์  ํ‚จ์Šค)

Chapter 1 (์‹œํ–‰์ฐฉ์˜ค) ์  ํ‚จ์Šค๋งŒ์„ ์œ„ํ•œ ์„œ๋ฒ„๋ฅผ ๊ตฌ์ถ•ํ•˜๋Š” ๊ฑด ์šฐ๋ฆฌ ํ”„๋กœ์ ํŠธ์— ๋„ˆ๋ฌด ์˜ค๋ฒ„์ŠคํŽ™์ด๊ธฐ๋„ ํ•˜๊ณ , ๋น„์šฉ ๋ฌธ์ œ๋„ ์žˆ์–ด์„œ GitHub Actions ์œ„์— Jenkins๋ฅผ Docker์œผ๋กœ ์˜ฌ๋ ค์„œ ์‚ฌ์šฉํ•˜๊ธฐ๋กœ ํ–ˆ๋‹ค. ํ•ญ์ƒ ํ”„๋ก ํŠธ์—”๋“œ ๊ฐœ๋ฐœ๋งŒ ํ•˜๋‹ค...

s2n

[s2n] Python Package ์ƒ์„ฑ ๋ฐ ๋ฐฐํฌ ๊ณต๋ถ€

Python์„ ์ด์šฉํ•˜๋ฉด์„œ pip install ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด์„œ ํŒจํ‚ค์ง€๋ฅผ ๋“ฑ๋กํ•˜๋Š” ๊ฒŒ ๊ตญ๋ฃฐ. ๊ทธ๋Ÿผ ์ด ํŒจํ‚ค์ง€๋Š” ์–ด๋–ป๊ฒŒ ๋งŒ๋“œ๋Š” ๊ฑธ๊นŒ? ๊ทธ๋ฆฌ๊ณ  Pip install์„ ์ด์šฉํ•ด์„œ ํŒŒ์ด์ฌ ํŒจํ‚ค์ง€๋ฅผ ์„ค์น˜ํ•˜๋Š” ๊ฒƒ์€ ์–ด๋–ป๊ฒŒ ๋งŒ๋“ค๊นŒ? ์ง„ํ–‰๊ณผ์ • PyPI์— ์ ‘...

s2n

[s2n] PyPI ๋ฐฐํฌ์šฉ Python ํŒจํ‚ค์ง€ + Jenkins ๊ธฐ๋ฐ˜ CI/CD ๊ตฌ์กฐ ์ดํ•ดํ•˜๊ธฐ

1. ์šฉ์–ด ์ •๋ฆฌ venv ๋กœ์ปฌ (ํ˜น์€ CI)์—์„œ ํ”„๋กœ์ ํŠธ ์ „์šฉ ํŒŒ์ด์ฌ ๊ฐ€์ƒํ™˜๊ฒฝ์„ ๋งŒ๋“œ๋Š” ๊ฒƒ. ์‹œ์Šคํ…œ ํŒŒ์ด์ฌ๊ณผ ๊ฒฉ๋ฆฌํ•ด์„œ ํŒจํ‚ค์ง€๋ฅผ ์„ค์น˜/๊ด€๋ฆฌํ•จ. ์™œ ํ•„์š”? -> ์„œ๋กœ ๋‹ค๋ฅธ ํ”„๋กœ์ ํŠธ๊ฐ€ ์„œ๋กœ ๋‹ค๋ฅธ ๋ฒ„์ „...

Side Project

[Side Project] ๐Ÿช„ Velog ๊ธ€์„ ์ž๋™์œผ๋กœ GitHub Pages ๋ธ”๋กœ๊ทธ๋กœ ๋™๊ธฐํ™”ํ•˜๊ธฐ (with Jekyll + GitHub Actions) + Discord ์•Œ๋ฆผ๊นŒ์ง€ ์ „์†กํ•˜๊ธฐ!

๋‚ด๊ฐ€ ์ง€๊ธˆ๊นŒ์ง€ ์ž‘์„ฑํ•œ ๊ฐœ๋ฐœ ๋ธ”๋กœ๊ทธ + ํฌํŠธํด๋ฆฌ์˜ค + ๊ธฐํƒ€ ๋‚ด ์†Œ๊ฐœ๋ฅผ ํ•œ ๊ณณ์—์„œ ๋ณด์—ฌ์ฃผ๊ณ  ์‹ถ์–ด์„œ Jekyll ๋ธ”๋กœ๊ทธ๋ฅผ ๋งŒ๋“ค์–ด์•ผ๊ฒ ๋‹ค๋Š” ์ƒ๊ฐ์ด ๋“ค์—ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  Velog์— ์˜ฌ๋ฆฐ ๊ธ€์ด ์ž๋™์œผ๋กœ ๋‚ด ๊ฐœ์ธ ๋ธ”๋กœ๊ทธ(GitHub Pages)์— ๋ฐ˜์˜๋œ๋‹ค๋ฉด ์–ด๋–จ๊นŒ...

wargame

[Webhacking.kr] old-12 Javascript challenge

script ์ƒ๊ธด ๊ฑธ ๋ณด์•„ํ•˜๋‹ˆ ์›๋ž˜ ์ฝ”๋“œ๋ฅผ ์ด๋ชจํŠธ์ฝ˜์œผ๋กœ ๋Œ€์ฒดํ•œ ๊ฒƒ ๊ฐ™์€๋ฐโ€ฆ javascript ์•”ํ˜ธํ™”๋กœ ์„œ์น˜ํ•ด๋ณด๋‹ˆ๊นŒ https://cat-in-136.github.io/2010/12/aadecode-decode-encoded-as-aaencod...

wargame

[Webhacking.kr] old-20 ์ž๋™ ๊ณต๊ฒฉ ์Šคํฌ๋ฆฝํŠธ

๋ฌธ์ œ ์ž์ฒด๋Š” ๊ต‰์žฅํžˆ ๋‹จ์ˆœํ•˜๋‹ค. ๋‹‰๋„ค์ž„์— ๋ฌด์ž‘์œ„, ์ฝ”๋ฉ˜ํŠธ์— ๋ฌด์ž‘์œ„ ๊ฐ’์„ ๋„ฃ๊ณ , ์บก์ฑ  ๊ฐ’๋งŒ html์—์„œ ๋”ฐ์™€์„œ ๋ณต๋ถ™ํ•ด์„œ ์ด ๋ชจ๋“  ๊ฑธ 2์ดˆ ์•ˆ์— ์ œ์ถœํ•˜๋ฉด ๋œ๋‹ค. <form name="lv5frm" method="post"> <inp...

kt cloud techup

[KT Cloud TechUp] ํŒŒ์ผ ์—…๋กœ๋“œ ์ทจ์•ฝ์  ํ™˜๊ฒฝ ๊ตฌํ˜„ ๋ฐ ์นจํˆฌ ์‹ค์Šต

Part 1: Python์œผ๋กœ ์›น์„œ๋ฒ„์— ํŒŒ์ผ ์—…๋กœ๋“œํ•˜๊ธฐ ํŒŒ์ผ ์—…๋กœ๋“œ ์ทจ์•ฝ์ ์˜ ์‹ฌ๊ฐ์„ฑ - ๋‹ค๋ฅธ ์ทจ์•ฝ์  10๊ฐœ๋ฅผ ํ•ฉ์นœ ๊ฒƒ๋ณด๋‹ค ์›น์…ธ ์ทจ์•ฝ์  1๊ฐœ๊ฐ€ ๋” ์น˜๋ช…์ ์ด๋‹ค! ์ด์œ  - ์ฆ‰์‹œ ์‹œ์Šคํ…œ ๋ช…๋ น์–ด ์‹คํ–‰ ๊ฐ€๋Šฅ, ํŒŒ์ผ ์‹œ์Šคํ…œ ์™„์ „ ์ ‘๊ทผ, ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค ์ง์ ‘ ์กฐ์ž‘...

wargame

[Webhacking.kr] old-39

$_POST[โ€˜idโ€™] = str_replace(โ€œ\โ€,โ€โ€,$_POST[โ€˜idโ€™]); $_POST[โ€˜idโ€™] = str_replace(โ€œโ€™โ€,โ€โ€™โ€™โ€,$_POST[โ€˜idโ€™]); $_POST[โ€˜idโ€™] = substr($_POST[โ€˜idโ€™...

wargame

[Webhacking.kr] old-16

๊ฐœ๋ฐœ์ž๋„๊ตฌ์—์„œ ํ™•์ธํ•ด ๋ณด๋‹ˆ๊นŒ ๋น„๊ต์  ์‰ฌ์›Œ ๋ณด์ธ๋‹ค. ์ž๋ฐ”์Šคํฌ๋ฆฝํŠธ cd ํ‚ค์›Œ๋“œ๋กœ ์„œ์น˜ํ•ด ๋ณด๋‹ˆ๊นŒ 100, 97, 118, 115๋Š” wasd๋ฅผ ์˜๋ฏธํ•˜๋Š” ํ‚ค๋ณด๋“œ ์ฝ”๋“œ๋ผ๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ์—ˆ๋‹ค. (https://blog.outsider.ne.kr/322)...

kt cloud techup

[KT Cloud TechUp] ๋ณด์•ˆ๋‰ด์Šค ํฌ๋กค๋ง - requests ์‚ฌ์šฉ

์ง€๊ธˆ๊นŒ์ง€๋Š” selenium์„ ์‚ฌ์šฉํ•ด์„œ ํฌ๋กค๋ง์„ ์ง„ํ–‰ํ–ˆ๋Š”๋ฐ, ์…€๋ ˆ๋‹ˆ์›€๋ณด๋‹ค ์ข€ ๋” ๋น ๋ฅธ ๋ฐฉ์‹์ธ requests๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ํฌ๋กค๋ง ์‹ค์Šต์„ ์ง„ํ–‰ํ•œ๋‹ค. def extract_title_from_html(html_content, idx): try:...

kt cloud techup

[KT Cloud TechUp] expoid_db ๋ฐ์ดํ„ฐ ์‹œ๊ฐํ™” ๋Œ€์‹œ๋ณด๋“œ ์ œ์ž‘

์šฐ์„ ์€ phpmyadmin์—์„œ ํ…Œ์ด๋ธ”์„ ์ œ์ž‘ํ•˜๊ณ  ๊ฐ„๋‹จํ•œ ํ…Œ์ŠคํŠธ ๋ฐ์ดํ„ฐ๋“ค์„ ๋„ฃ์–ด๋‘์—ˆ๋‹ค. [php๋ž€?] ์˜คํ”ˆ์†Œ์Šค ์–ธ์–ด๋กœ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์™€ ์—ฐ๋™์ด ๊ฐ„ํŽธํ•œ ์–ธ์–ด์ด๋‹ค.<?php echo "Hello, World!"; $name = "ํ™๊ธธ๋™"; echo...

wargame

[Webhacking.kr] old-10

O๋ฅผ goal์— ๋„ฃ์œผ๋ฉด ๋  ๊ฒƒ ๊ฐ™์€ ๋А๋‚Œ์ด ๋“œ๋Š” ๋ฌธ์ œ์ด๋‹ค. O์— mouseover/mouseout ์†์„ฑ์ด ์žˆ์–ด ๋งˆ์šฐ์Šค๋ฅผ ์˜ฌ๋ ค๋ดค๋”๋‹ˆ ์ปค์„œ๋ฅผ ์˜ฌ๋ ค๋†“์œผ๋ฉด O๊ฐ€ yOu๋กœ ๋ฐ”๋€Œ๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ์—ˆ๋‹ค. ๊ทธ๋ฆฌ๊ณ  ํด๋ฆญํ•  ๋•Œ๋งˆ๋‹ค ์˜ค๋ฅธ์ชฝ์œผ๋กœ ์กฐ๊ธˆ์”ฉ ์ด๋™ํ•œ๋‹ค. ...

kt cloud techup

[KT Cloud TechUp] exploit-db ํฌ๋กค๋งํ•˜๊ธฐ

https://www.exploit-db.com/ ์ด ์‚ฌ์ดํŠธ์˜ ์ทจ์•ฝ์  ์ œ๋ชฉ๋“ค์„ ํฌ๋กค๋งํ•ด csv ํ˜•ํƒœ๋กœ ์ €์žฅํ•˜๋Š” ๊ฒƒ์ด ๊ณผ์ œ์˜€๋‹ค. ์ œ๋ชฉ ํฌ๋กค๋ง 1๋‹จ๊ณ„ ์•„์นจ 9์‹œ๋ผ ์•„๋ฌด ์ƒ๊ฐ ์—†์ด request๋กœ HTML ๋ฐ›์•„์™€์„œ ํŒŒ์‹ฑํ•˜๋Š” ๋ฐฉ๋ฒ•์œผ๋กœ ํฌ๋กค๋ง ํ•˜๋‹ค๊ฐ€ ...

wargame

[Webhacking.kr] old-2

์ฃผ๋ง๋™์•ˆ https://webhacking.kr/challenge/web-02/๋ฅผ ํ‘ธ๋Š” ๊ฒƒ์ด ๊ณผ์ œ์˜€๋‹ค. ์‚ฌ์‹ค ์ง€๋‚œ ์ฃผ ๋ชฉ์š”์ผ~๊ธˆ์š”์ผ๋ถ€ํ„ฐ ์ฐ”๋”์ฐ”๋” ํ•ด๋ณธ ๊ฒƒ๋ถ€ํ„ฐ ํ•˜๋ฉด ๊ฑฐ์˜ 4์ผ? ๋™์•ˆ ์ด ๋ฌธ์ œ๋งŒ ํ‘ผ ๊ฒƒ ๊ฐ™๋‹คโ€ฆ ํ’€๊ณ  ํ’€์ด ์ž‘์„ฑ์€ ๋ฏธ๋ค„๋’€๋‹ค๊ฐ€ ์ด์ œ์„œ์•ผ ์ž‘...

kt cloud techup

[KT Cloud TechUp] xampp mysql ์‹ค์Šต (์ž‘์„ฑ์ค‘)

xampp๋ฅผ ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  ์„ค์ •ํ•˜๋ฉด ์ด๋Ÿฐ ์ปจํŠธ๋กค ํŒจ๋„์ด ๋œฌ๋‹ค. ์—ฌ๊ธฐ์„œ mysql์„ startํ•˜๊ณ  ์˜ค๋ฅธ์ชฝ์˜ shell์„ ๋ˆŒ๋Ÿฌ ์‰˜์œผ๋กœ ์ง„์ž…ํ•œ๋‹ค. mysql -u root -p๋ฅผ ํ†ตํ•ด mysql์— ์ ‘์†ํ•œ๋‹ค. ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค๋ฅผ ์ƒ์„ฑํ•˜๊ณ  ์„ ํƒํ•œ๋‹ค. ...

kt cloud techup

[KT Cloud TechUp] CVE-2003-0127 ptrace-kmod ์ปค๋„ ์ต์Šคํ”Œ๋กœ์ž‡ ๋ถ„์„: Race Condition์„ ์ด์šฉํ•œ ๊ถŒํ•œ ์ƒ์Šน ๊ณต๊ฒฉ

์˜ค๋ž˜๋œ ์ทจ์•ฝ์ ์ด๊ธด ํ•˜์ง€๋งŒ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ๊ฐœ๋…์„ ํ•™์Šตํ•  ์ˆ˜ ์žˆ๋‹ค. Race Condition ๊ณต๊ฒฉ ์ปค๋„ ๊ถŒํ•œ ์ƒ์Šน ๊ธฐ๋ฒ• ptrace ์‹œ์Šคํ…œ ์ฝœ ์•…์šฉ ํ”„๋กœ์„ธ์Šค ๋ฉ”๋ชจ๋ฆฌ ์กฐ์ž‘ ์ทจ์•ฝ์  ์š”์•ฝ ๊ณต๊ฒฉ์ž -> AF_SECURITY ์†Œ์ผ“ ์ƒ...

kt cloud techup

[KT Cloud TechUp] heartbleed ์‹ค์Šต

Heartbleed 2014๋…„ 4์›”์— ๋ฐœ์ƒํ•œ OpenSSL ๋ฒ„๊ทธ CVE-2014-0160 OpenSSL 1.0.1 ๋ฒ„์ „์—์„œ ๋ฐœ๊ฒฌ๋œ ๋งค์šฐ ์œ„ํ—˜ํ•œ ์ทจ์•ฝ์ . TLS/DTLS์˜ HeartBeat ํ™•์žฅ๊ทœ๊ฒฉ์—์„œ ๋ฐœ๊ฒฌ๋œ ์ทจ์•ฝ์ ์œผ๋กœ, OpenSSL์€ ...

kt cloud techup

[KT Cloud TechUp] NESSUS, Web Shell, Reverse Telnet, OWASP ZAP

NESUS ์‹œ์Šคํ…œ/๋„คํŠธ์›Œํฌ/์›น์„œ๋ฒ„/ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ๊นŒ์ง€ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ์ž๋™์œผ๋กœ ์ ๊ฒ€ํ•˜๊ณ  ๋ฆฌํฌํŒ…ํ•ด์ฃผ๋Š” ์ทจ์•ฝ์  ์Šค์บ๋„ˆ Terrascan by tenable: ์ •์  ์ฝ”๋“œ ๋ถ„์„๊ธฐ. IAC (Infrastructure as Code)์˜ ๋ณด์•ˆ ์ •์ฑ… ์ค€์ˆ˜ ์—ฌ...

kt cloud techup

[KT Cloud TechUp] Metasploit ์‹ค์Šต โญโญ

์ด ๊ธ€์€ Kali Linux ํ™˜๊ฒฝ์—์„œ Metasploit๊ณผ nmap์„ ์ด์šฉํ•ด ๋„คํŠธ์›Œํฌ ํƒ์ง€ โ†’ ์„œ๋น„์Šค ํ™•์ธ โ†’ MySQL ๊ด€๋ จ ์—ด๊ฑฐ ๋ฐ ๋ธŒ๋ฃจํŠธํฌ์Šค ๊ณผ์ •์„ ์‹ค์Šตํ•˜๋Š” ๊ณผ์ •์„ ๊ธฐ๋กํ•ฉ๋‹ˆ๋‹ค. ํ•™์Šต ๋ชฉ์ ์˜ ๊ฐ€์ƒํ™˜๊ฒฝ์—์„œ๋งŒ ์‹คํ–‰ํ–ˆ์œผ๋ฉฐ, ๊ฐ ๋‹จ๊ณ„๋ณ„ ๋ช…๋ นยท์ถœ๋ ฅยท...

[KT Cloud TechUp] nmap

nmap์ด๋ž€? ๋„คํŠธ์›Œํฌ ๋ณด์•ˆ ์ง„๋‹จ/๊ด€๋ฆฌ๋ฅผ ์œ„ํ•ด ์‚ฌ์šฉ๋˜๋Š” ๋„๊ตฌ ๋„คํŠธ์›Œํฌ์— ์—ฐ๊ฒฐ๋œ ํ˜ธ์ŠคํŠธ/์„œ๋น„์Šค ํƒ์ƒ‰ + ๋ณด์•ˆ ์ทจ์•ฝ์  ์‚ฌ์ „ ์ ๊ฒ€ live host์˜ list ์ œ๊ณต ์—ด๋ ค์žˆ๋Š” ํฌํŠธ ํƒ์ƒ‰ OS scanning ์‹ค์Šต kali์—์„œ nmap -sn 192....

[KT Cloud TechUp] AWS KMS / S3 / Kinesis / SHIELD

KMS Key Management Service ๊ฐœ๋ฐœ์„ ํ•˜๋‹ค ๋ณด๋ฉด ํ™˜๊ฒฝ๋ณ€์ˆ˜/์„ค์ • ํŒŒ์ผ์— ๋น„๋ฐ€๋ฒˆํ˜ธ, API ํ‚ค, DB ๋น„๋ฐ€๋ฒˆํ˜ธ ๋“ฑ ์ค‘์š”ํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ๋„ฃ์–ด์•ผ ํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ์žˆ์Œ ์—ฌ๋Ÿฌ ๋ช…๊ณผ ํ˜‘์—…ํ•˜๊ฑฐ๋‚˜ ๋ฐฐํฌ ์‹ค์ˆ˜ํ•˜์—ฌ ๋ณด์•ˆ ๊ด€๋ จ ๋ฌธ์ œ ๋ฐœ์ƒํ•˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์Œ ...

[๊ธฐํƒ€] Splunk SIEM

SIEM์„ ๊ตฌ์„ฑํ•˜๋Š” ๋Œ€ํ‘œ์ ์ธ ๋ฐฉ๋ฒ•์€ AWS์ด๋‹ค. ํ•˜์ง€๋งŒ ํด๋ผ์šฐ๋“œ ๋‚ด๋ถ€ ์„œ๋น„์Šค๊ฐ€ ์•„๋‹Œ ์™ธ๋ถ€ SIEM์œผ๋กœ Splunk, Datadog๋„ ์กด์žฌํ•œ๋‹ค. Splunk๋Š” machine data๋ฅผ ์ˆ˜์ง‘/์ €์žฅ/๊ฒ€์ƒ‰/์‹œ๊ฐํ™”ํ•ด์„œ ์šด์˜ ์ƒํƒœ๋ฅผ ๋ถ„์„ํ•˜๊ณ  ๋ณด์•ˆ ์œ„ํ˜‘์„ ...

[๊ธฐํƒ€] ์›น ์ทจ์•ฝ์  ์Šค์บ” ๋„๊ตฌ Acunetix

์‹ค์Šต์šฉ์œผ๋กœ ๊ตฌ์ถ•ํ•œ DVWA๋ฅผ ์Šค์บ” ๋Œ๋ ค๋ณด์•˜๋”ฐ SQL Injection ์ทจ์•ฝ์ ์€ ์—†๋Š” ๊ฒƒ์œผ๋กœ ๋ณด์ธ๋‹ค. ์›Œ๊ฒŒ์ž„ ์‚ฌ์ดํŠธ๋“ค์—๋„ ๋Œ๋ ค๋ณด๊ณ  ์‹ถ์ง€๋งŒ ์Šค์บ” ์ž์ฒด๊ฐ€ DoS์˜ ๊ณต๊ฒฉ์„ ๋„๊ณ  ์žˆ๋‹ค๊ณ  ํ•ด์„œ... ๋‚˜์ค‘์— ์นผ๋ฆฌ์— ํ™˜๊ฒฝ์„ ๊ตฌ์ถ•ํ•ด์„œ ์ œ๋Œ€๋กœ ์Šค์บ”ํ•ด๋ด์•ผ ํ•  ๊ฒƒ...