å°ãåã«æžããŸãããã ããããå°ãè²§åŒ±ã§æ··æ²ãšããŠããŸãã ãã®åŸãã¬ãã¥ãŒã®ããŒã«ã®ãªã¹ããæ¡åŒµããèšäºã«æ§é ã远å ããæ¹å€ãèæ ®ããããšã«ããŸãã (ããããšãããããŸãã) ã¢ããã€ã¹ãæ±ããŠ)ãããã SecLab ã®ã³ã³ãã¹ãã«éããŸãã (ãããŠå ¬éãããŸãã) ããããããã¹ãŠã®æçœãªçç±ããã誰ã圌女ãèŠãŠããŸããã§ããïŒã ã³ã³ãã¹ãã¯çµäºããçµæã¯çºè¡šãããŸãããç§ã¯æç¢ºãªè¯å¿ãæã£ãŠãããïŒèšäºïŒãããã¬ã«æ²èŒããããšãã§ããŸãã
ç¡æã® Web ã¢ããªã±ãŒã·ã§ã³ Pentester ããŒã«
ãã®èšäºã§ã¯ãããã©ã㯠ããã¯ã¹ãæŠç¥ã䜿çšãã Web ã¢ããªã±ãŒã·ã§ã³ã®ãããã¬ãŒã·ã§ã³ ãã¹ã (䟵å
¥ãã¹ã) ã«æã人æ°ã®ããããŒã«ã«ã€ããŠèª¬æããŸãã
ãããè¡ãããã«ããã®çš®ã®ãã¹ãã«åœ¹ç«ã€ãŠãŒãã£ãªãã£ãèŠãŠãããŸãã æ¬¡ã®è£œåã«ããŽãªãèæ
®ããŠãã ããã
- ãããã¯ãŒã¯ã¹ãã£ããŒ
- Web ã¹ã¯ãªãã䟵害ã¹ãã£ããŒ
- æŸå
- 泚å°ã®èªåå
- ãããã¬ãŒ (ã¹ããã¡ãŒãããŒã«ã« ãããã·ãªã©)
ååã«ãã£ãŠã¯æ®éçãªãåæ§ããæã£ãŠãããã®ããããŸãã®ã§ããã®ã«ããŽãªãŒã«åé¡ãããŠããã ããŸããПããè¯ãçµæãåŸãããŸãïŒäž»èгçãªæèŠïŒã
ãããã¯ãŒã¯ã¹ãã£ããŒã
äž»ãªã¿ã¹ã¯ã¯ãå©çšå¯èœãªãããã¯ãŒã¯ ãµãŒãã¹ãæ€åºãããã®ããŒãžã§ã³ãã€ã³ã¹ããŒã«ããOS ãæ±ºå®ããããšãªã©ã§ãã
Nmapã®
ã¯ããããã¯ãŒã¯åæãšã·ã¹ãã ã»ãã¥ãªãã£ç£æ»ã®ããã®ç¡æã®ãªãŒãã³ ãœãŒã¹ ãŠãŒãã£ãªãã£ã§ãã ã³ã³ãœãŒã«ã®æŽåçãªæµå¯Ÿè
ã¯ãNmap ã® GUI ã§ãã Zenmap ã䜿çšã§ããŸãã
ããã¯åãªããã¹ããŒããã¹ãã£ãã§ã¯ãªããæ¬æ Œçãªæ¡åŒµå¯èœãªããŒã«ã§ã (ãçããæ©èœãã® XNUMX ã€ã¯ãããŒãã«ã¯ãŒã ãååšãããã©ããããã§ãã¯ããã¹ã¯ãªããã®ååšã§ãã" ïŒèšåããã ïŒã å
žåçãªäœ¿çšäŸ:
nmap -A -T4 localhost
-A OS ããŒãžã§ã³ã®æ€åºãã¹ã¯ãªããã®ã¹ãã£ã³ããã³ãã¬ãŒã¹çš
-T4 æéå¶åŸ¡èšå® (0 ãã 5 ãŸã§ãå€ãã»ã©éããªããŸã)
localhost - ã¿ãŒã²ãããã¹ã
ãã£ãšå³ãããã®ã¯ãããŸããïŒ
nmap -sS -sU -T4 -A -v -PE -PP -PS21,22,23,25,80,113,31339 -PA80,113,443,10042 -PO --script all localhost
ããã¯ãZenmap ã®ãäœéå
æ¬ã¹ãã£ã³ããããã¡ã€ã«ã®ãªãã·ã§ã³ã®ã»ããã§ãã å®äºãŸã§ã«ããªãã®æéãããããŸãããæçµçã«ã¯ã¿ãŒã²ãã ã·ã¹ãã ã«ã€ããŠç¥ãããšãã§ããããè©³çŽ°ãªæ
å ±ãåŸãããŸãã ãããã«è©³ãã調ã¹ããå Žåã¯ãèšäºã翻蚳ããããšããå§ãããŸã .
Nmapã¯ã以äžã®ãããªéèªãå£äœããã幎éæåªç§ã»ãã¥ãªãã£è£œåãã®ç§°å·ãæäžãããŠããŸãã Linux ãžã£ãŒãã«ãã€ã³ãã©ã¯ãŒã«ãã LinuxQuestions.OrgãšCodetalker Digestã
è峿·±ãç¹ãšããŠãNmap ã¯æ ç»ããããªãã¯ã¹ ãªããŒããããããã〠ããŒã 4ãããããŒã³ ã¢ã«ãã£ã¡ã€ã¿ã ãããããã¿ããããã .
IP-ããŒã«
- ããŸããŸãªãããã¯ãŒã¯ ãŠãŒãã£ãªãã£ã®ã»ããã®äžçš®ã§ãWindows ãŠãŒã¶ãŒå°çšã® GUI ãä»å±ããŠããŸãã
ããŒã ã¹ãã£ããŒãå
±æãªãœãŒã¹ (å
±æããªã³ã¿ãŒ/ãã©ã«ããŒ)ãWhoIs/Finger/LookupãTelnet ã¯ã©ã€ã¢ã³ããªã©ã 䟿å©ã§é«éãªæ©èœçãªããŒã«ã§ãã
ãã®åéã«ã¯å€ãã®ãŠãŒãã£ãªãã£ãããããããã¯ãã¹ãŠåæ§ã®åäœåçãšæ©èœãåããŠãããããä»ã®è£œåãæ€èšããããšã«ç¹ã«æå³ã¯ãããŸããã ããã§ããnmap ãäŸç¶ãšããŠæãäžè¬çã«äœ¿çšãããŠããŸãã
Web ã¹ã¯ãªãã䟵害ã¹ãã£ããŒ
äžè¬çãªèåŒ±æ§ (SQL injãXSSãLFI/RFI ãªã©) ãŸãã¯ãšã©ãŒ (åé€ãããŠããªãäžæãã¡ã€ã«ããã£ã¬ã¯ããªã®ã€ã³ããã¯ã¹äœæãªã©) ãèŠã€ããããšããŠããŸãã
AcunetixWebè匱æ§ã¹ãã£ããŒ
â ãªã³ã¯ãããããã xss ã¹ãã£ããŒã§ããããšãããããŸãããããã¯å®å
šã«çå®ã§ã¯ãããŸããã ããããå
¥æã§ããç¡æçã§ã¯ãéåžžã«å€ãã®æ©èœãæäŸãããŸãã éåžžããã®ã¹ãã£ããŒãåããŠå®è¡ãããªãœãŒã¹ã«é¢ããã¬ããŒããåããŠåãåã人ã¯è»œãã·ã§ãã¯ãçµéšããŸãããäžåºŠãããè¡ããšããã®çç±ãããããŸãã ããã¯ãWeb ãµã€ãäžã®ããããçš®é¡ã®è匱æ§ãåæããããã®éåžžã«åŒ·åãªè£œåã§ãããéåžžã® PHP Web ãµã€ãã ãã§ãªããä»ã®èšèªã§ãæ©èœããŸã (ãã ããèšèªã®éãã¯ææšã§ã¯ãããŸãã)ã ã¹ãã£ããŒã¯ãŠãŒã¶ãŒã®ã¢ã¯ã·ã§ã³ãåã«ãæŸããã ããªã®ã§ãæç€ºã説æããããšã«ç¹å¥ãªæå³ã¯ãããŸããã äžè¬çãªãœãããŠã§ã¢ã®ã€ã³ã¹ããŒã«ã«ããããæ¬¡ãæ¬¡ãæ¬¡ãæºåå®äºãã«äŒŒãŠããŸãã
ã ãã
ããã¯ãªãŒãã³ãœãŒã¹ (GPL) Web ã¯ããŒã©ãŒã§ãã æ¥åžžçãªæäœæ¥ãæé€ããŸãã ã¿ãŒã²ãã ãµã€ãã§åé€ãããŠããªãã¹ã¯ãªãã (äžéšã® test.phpãindex_.php ãªã©)ãããŒã¿ããŒã¹ç®¡çããŒã« (/phpmyadmin/ã/pma ãªã©) ãªã©ãæ€çŽ¢ããŸããã€ãŸããæãäžè¬çãªãšã©ãŒã«ã€ããŠãªãœãŒã¹ããã§ãã¯ããŸããéåžžã¯äººçèŠå ã«ãã£ãŠåŒãèµ·ããããŸãã
ããã«ã人æ°ã®ããã¹ã¯ãªãããèŠã€ããå Žåã¯ããªãªãŒã¹ããããšã¯ã¹ããã€ã (ããŒã¿ããŒã¹å
ã«ãã) ããªããã©ããããã§ãã¯ããŸãã
PUT ã TRACE ãªã©ãå©çšå¯èœãªãäžèŠãªãã¡ãœãããã¬ããŒãããŸã
çã
ã ç£æ»å¡ãšããŠåããŠããŠãWeb ãµã€ããæ¯æ¥åæããŠããå Žåãããã¯éåžžã«äŸ¿å©ã§ãã
ãã€ãã¹ç¹ã®äžã§ã誀æ€ç¥ã®å²åãé«ãããšã«æ³šç®ããããšæããŸãã ããšãã°ããµã€ãã§ 404 ãšã©ãŒãçºçããã¯ãã®ä»£ããã«åžžã«ã¡ã€ã³ ãšã©ãŒã衚瀺ãããå Žåãã¹ãã£ãã¯ãµã€ãã«ããŒã¿ããŒã¹ã®ãã¹ãŠã®ã¹ã¯ãªãããšãã¹ãŠã®è匱æ§ãå«ãŸããŠãããšå€æããŸãã å®éã«ã¯ãããã¯ããã»ã©é »ç¹ã«ã¯èµ·ãããŸããããå®éã«ã¯ããµã€ãã®æ§é ã«å€§ããäŸåããŸãã
å€å
žçãªäœ¿çšæ³:
./nikto.pl -host localhost
ãµã€ãäžã§èªèšŒãå¿ èŠãªå Žåã¯ãnikto.conf ãã¡ã€ã«ã® STATIC-COOKIE 倿°ã« Cookie ãèšå®ã§ããŸãã
ãŠã£ã¯ã
- ãã¯ãã¢ã³ã㌠Windowsãã ãããšã©ãŒãã§ãã¯ã®ããã®ãã¡ãžãŒããžãã¯ãGHDBã®äœ¿çšããªãœãŒã¹ãªã³ã¯ãšãã©ã«ãã®ååŸãHTTPãªã¯ãšã¹ã/ã¬ã¹ãã³ã¹ã®ãªã¢ã«ã¿ã€ã ç£èŠãªã©ãããã€ãã®æ©èœã远å ãããŠããŸããWiktoã¯C#ã§èšè¿°ãããŠããã.NETãã¬ãŒã ã¯ãŒã¯ãå¿
èŠã§ãã
ã¹ããããã£ãã·ã¥
- Web è匱æ§ã¹ãã£ããŒãã (lcamtââuf ãšããŠç¥ãããŠããŸã)ã C ã§æžãããŠãããã¯ãã¹ãã©ãããã©ãŒã ã§ã (Win ã«ã¯ Cygwin ãå¿
èŠã§ã)ã ååž°çã« (ãããŠéåžžã«é·ãæéãçŽ 20 ïœ 40 æéããã ããç§ãæåŸã«æ©èœããã®ã¯ 96 æéã§ãã) ãµã€ãå
šäœãå·¡åããŠãããããçš®é¡ã®ã»ãã¥ãªã㣠ããŒã«ãèŠã€ããŸãã ãŸãã倧éã®ãã©ãã£ã㯠(æ° GB ã®åä¿¡/éä¿¡) ãçæãããŸãã ããããç¹ã«æéãšãªãœãŒã¹ãããå Žåã¯ãããããææ®µãæå¹ã§ãã
äžè¬çãªçšé:
./skipfish -o /home/reports www.example.com
ãreportsããã©ã«ãã«ã¯HTML圢åŒã®ã¬ããŒããååšããŸãã .
w3af 
â Web ã¢ããªã±ãŒã·ã§ã³æ»æããã³ç£æ»ãã¬ãŒã ã¯ãŒã¯ããªãŒãã³ãœãŒã¹ã® Web è匱æ§ã¹ãã£ããŒã GUI ãåããŠããŸãããã³ã³ãœãŒã«ããäœæ¥ã§ããŸãã ããæ£ç¢ºã«ã¯ã次ã®ãããªãã¬ãŒã ã¯ãŒã¯ã§ãã .
ãã®ã¡ãªããã«ã€ããŠèªãå§ãããšããªããªãã®ã§ãããå®éã«è©ŠããŠã¿ãã®ãäžçªã§ã :]
äžè¬çãªäœæ¥æé ãšããŠã¯ããããã¡ã€ã«ãéžæããã¿ãŒã²ãããæå®ããå®éã«èµ·åãããšããæµãã«ãªããŸãã
Mantra ã»ãã¥ãªã㣠ãã¬ãŒã ã¯ãŒã¯
å¶ã£ã倢ã§ãã Web ãã©ãŠã¶ã«çµã¿èŸŒãŸãããç¡æã§ãªãŒãã³ãªæ
å ±ã»ãã¥ãªã㣠ããŒã«ã®ã³ã¬ã¯ã·ã§ã³ã
Web ã¢ããªã±ãŒã·ã§ã³ããã¹ãŠã®æ®µéã§ãã¹ãããå Žåã«éåžžã«åœ¹ç«ã¡ãŸãã
äœ¿çšæ¹æ³ã¯ããã©ãŠã¶ã®ã€ã³ã¹ââããŒã«ãšèµ·åã«èŠçŽãããŸãã
å®éããã®ã«ããŽãªã«ã¯å€æ°ã®ãŠãŒãã£ãªãã£ãããããã®äžããç¹å®ã®ãŠãŒãã£ãªãã£ãéžæããã®ã¯éåžžã«å°é£ã§ãã ã»ãšãã©ã®å Žåãåãã³ãã¹ã¿ãŒèªèº«ãå¿ èŠãªããŒã«ã®ã»ãããæ±ºå®ããŸãã
æŸå
è匱æ§ã®æªçšãèªååããããã䟿å©ã«è¡ãããã«ãæªçšã¯ãœãããŠã§ã¢ãšã¹ã¯ãªããã§èšè¿°ãããã»ãã¥ãªã㣠ããŒã«ãæªçšããã«ã¯ãã©ã¡ãŒã¿ãæž¡ãã ãã§æžã¿ãŸãã ãŸãããšã¯ã¹ããã€ããæåã§æ€çŽ¢ããå¿ èŠããªããããã®å Žã§é©çšãã補åããããŸãã ãã®ã«ããŽãªãŒã«ã€ããŠã¯ãããã説æããŸãã
ã¡ã¿ã¹ã³ã€ããã¬ãŒã ã¯ãŒã¯ 
- ç§ãã¡ã®ããžãã¹ã«ãããäžçš®ã®ã¢ã³ã¹ã¿ãŒã§ãã 圌ã¯éåžžã«å€ãã®ããšãè¡ãããšãã§ãããããèª¬ææžã«ã¯è€æ°ã®èšäºãå«ãŸããŸãã èªåæªçš (nmap + metasploit) ã«ã€ããŠèŠãŠãããŸãã çµè«ã¯æ¬¡ã®ãšããã§ããNmap ã¯å¿
èŠãªããŒããåæãããµãŒãã¹ãã€ã³ã¹ããŒã«ããmetasploit ã¯ãµãŒãã¹ ã¯ã©ã¹ (ftpãssh ãªã©) ã«åºã¥ããŠãšã¯ã¹ããã€ããé©çšããããšããŸãã ããã¹ãã«ãã説æã®ä»£ããã«ãautopwn ãšãããããã¯ã§éåžžã«äººæ°ã®ãããããªãæ¿å
¥ããŸãã

ãããã¯ãå¿ èŠãªãšã¯ã¹ããã€ãã®æäœãåçŽã«èªååããããšãã§ããŸãã äŸãã°ïŒ
msf > use auxiliary/admin/cisco/vpn_3000_ftp_bypass
msf auxiliary(vpn_3000_ftp_bypass) > set RHOST [TARGET IP]
msf auxiliary(vpn_3000_ftp_bypass) > run
å®éããã®ãã¬ãŒã ã¯ãŒã¯ã®æ©èœã¯éåžžã«åºç¯å²ã«ããããããããã«è©³ããç¥ãããå Žåã¯ã次ã®ãµã€ãã«ã¢ã¯ã»ã¹ããŠãã ããã
ã¢ãŒãããŒãž
â Metasploit çšã®ãµã€ããŒãã³ã¯ ãžã£ã³ã« GUI ã® OVAã ã¿ãŒã²ãããèŠèŠåãããšã¯ã¹ããã€ããæšå¥šãããã¬ãŒã ã¯ãŒã¯ã®é«åºŠãªæ©èœãæäŸããŸãã äžè¬ã«ããã¹ãŠãçŸããå°è±¡çã«èŠããã®ã奜ããªäººåãã§ãã
ã¹ã¯ãªãŒã³ãã£ã¹ã:

Tenable Nessus®
- å€ãã®ããšãã§ããŸãããããã«å¿
èŠãªæ©èœã® XNUMX ã€ã¯ãã©ã®ãµãŒãã¹ã«ãšã¯ã¹ããã€ãããããã倿ããããšã§ãã 補åã®ç¡æçãå®¶åºå°çšã
ÐÑпПлÑзПваМОеïŒ
- ããŠã³ããŒã (ã·ã¹ãã çš)ãã€ã³ã¹ããŒã«ãç»é² (ããŒã¯é»åã¡ãŒã«ã«éä¿¡ãããŸã)ã
- ãµãŒããŒãèµ·åãããŠãŒã¶ãŒã Nessus Server Manager ã«è¿œå ããŸãã (ããŠãŒã¶ãŒã®ç®¡çããã¿ã³)
- äœæã«è¡ããŸã
https://localhost:8834/
ãã©ãŠã¶ã§ Flash ã¯ã©ã€ã¢ã³ããååŸããŸã
- [ã¹ãã£ã³] -> [远å ] -> ãã£ãŒã«ãã«å ¥åã (é©åãªã¹ãã£ã³ ãããã¡ã€ã«ãéžæããŠ)ã[ã¹ãã£ã³] ãã¯ãªãã¯ããŸãã
ãã°ãããããšãã¹ãã£ã³ ã¬ããŒãã [ã¬ããŒã] ã¿ãã«è¡šç€ºãããŸãã
ãšã¯ã¹ããã€ãã«å¯ŸãããµãŒãã¹ã®å®è³ªçãªè匱æ§ã確èªããã«ã¯ãäžèšã® Metasploit ãã¬ãŒã ã¯ãŒã¯ã䜿çšãããããšã¯ã¹ããã€ã (ããšãã°ã , , ãªã©) ã«å¯ŸããŠæåã§äœ¿çšããŸãã ãã®ã·ã¹ãã
ç§èŠïŒããã°ããããŸãã ç§ã¯åœŒããœãããŠã§ã¢æ¥çã®ãã®æ¹åã®ãªãŒããŒã®äžäººãšããŠè¿ãå
¥ããŸããã
泚å°ã®èªåå
Web ã¢ããªã®ã»ãã¥ãªã㣠ã¹ãã£ããŒã®å€ãã¯ã€ã³ãžã§ã¯ã·ã§ã³ãæ€çŽ¢ããŸãããããã§ãåãªãäžè¬çãªã¹ãã£ããŒã§ãã ãŸããã€ã³ãžã§ã¯ã·ã§ã³ã®æ€çŽ¢ãšæªçšã«ç¹åãããŠãŒãã£ãªãã£ããããŸãã ãããããããã«ã€ããŠè©±ããŠãããŸãã
sqlmap
â SQL ã€ã³ãžã§ã¯ã·ã§ã³ãæ€çŽ¢ããã³æŽ»çšããããã®ãªãŒãã³ãœãŒã¹ ãŠãŒãã£ãªãã£ã MySQLãOracleãPostgreSQLãMicrosoft SQL ServerãMicrosoft AccessãSQLiteãFirebirdãSybaseãSAP MaxDB ãªã©ã®ããŒã¿ããŒã¹ ãµãŒããŒããµããŒãããŸãã
äžè¬çãªäœ¿çšæ³ã¯æ¬¡ã®è¡ã«èŠçŽãããŸãã
python sqlmap.py -u "http://example.com/index.php?action=news&id=1"
ãã·ã¢èªãå«ãååãªããã¥ã¢ã«ããããŸãã ãã®ãœãããŠã§ã¢ã¯ããã³ãã¹ã¿ãŒããã®åéã§äœæ¥ããéã®äœæ¥ã倧å¹
ã«å®¹æã«ããŸãã
å
¬åŒã®ãããªãã¢ã远å ããŸãã

bsqlbf-v2
â Perl ã¹ã¯ãªãããããã©ã€ã³ããSQL ã€ã³ãžã§ã¯ã·ã§ã³ã®ãã«ãŒããã©ãŒãµãŒã URL ã®æŽæ°å€ãšæååå€ã®äž¡æ¹ã§æ©èœããŸãã
ãµããŒããããŠããããŒã¿ããŒã¹:
- MS SQL
- MySQL
- PostgreSQL
- ãªã©ã¯ã«
䜿çšäŸïŒ
./bsqlbf-v2-3.pl -url www.somehost.com/blah.php?u=5 -blind u -sql "select table_name from imformation_schema.tables limit 1 offset 0" -database 1 -type 1
-url â ãã©ã¡ãŒã¿ãšãªã³ã¯ãã
-ç²ç®ã®ããªã â æ³šå
¥çšã®ãã©ã¡ãŒã¿ (ããã©ã«ãã§ã¯ãæåŸã®ãã©ã¡ãŒã¿ãã¢ãã¬ã¹ããŒããååŸãããŸã)
-sql "imformation_schema.tables ãã table_name ãéžæãå¶é 1ããªãã»ãã 0" â ããŒã¿ããŒã¹ã«å¯Ÿããä»»æã®ãªã¯ãšã¹ã
-ããŒã¿ããŒã¹1 â ããŒã¿ããŒã¹ãµãŒããŒ: MSSQL
-ã¿ã€ã1 â æ»æã®çš®é¡ãããã©ã€ã³ããã€ã³ãžã§ã¯ã·ã§ã³ãTrue ããã³ Error (æ§æãšã©ãŒãªã©) å¿çã«åºã¥ã
ãããã¬
ãããã®ããŒã«ã¯ãäž»ã«éçºè ãã³ãŒãã®å®è¡çµæã«åé¡ãããå Žåã«äœ¿çšãããŸãã ãããããã®æ¹åæ§ã¯ãå¿ èŠãªããŒã¿ããã®å Žã§çœ®ãæããããå ¥åãã©ã¡ãŒã¿ãŒã«å¿çããŠäœãè¿ãããããåæãããããããšãã§ããå Žå (ããšãã°ããã¡ãžã³ã°äž) ãªã©ããããã¬ãŒã·ã§ã³ãã¹ãã«ã圹ç«ã¡ãŸãã
ãã£ã·ã¹ã€ãŒã
â 䟵å
¥ãã¹ãã«åœ¹ç«ã€äžé£ã®ãŠãŒãã£ãªãã£ã ã€ã³ã¿ãŒãããäžã«ãããŸã Raz0r ãããã·ã¢èªã§ (ãã ã 2008 幎ã®)ã
ç¡æçã«ã¯ä»¥äžãå«ãŸããŸã:
- Burp ãããã·ã¯ããã©ãŠã¶ãããã§ã«çæããããªã¯ãšã¹ãã倿Žã§ããããŒã«ã« ãããã·ã§ãã
- Burp Spider - ã¹ãã€ããŒãæ¢åã®ãã¡ã€ã«ãšãã£ã¬ã¯ããªãæ€çŽ¢ããŸã
- Burp Replyer - HTTP ãªã¯ãšã¹ããæåã§éä¿¡ãã
- Burp Sequencer - ãã©ãŒã å ã®ã©ã³ãã å€ãåæãã
- Burp Decoder ã¯æšæºã®ãšã³ã³ãŒã/ãã³ãŒã (htmlãbase64ãhex ãªã©) ã§ããããã®æ°ã¯æ°åãããã©ã®èšèªã§ãããã«äœæã§ããŸãã
- Burp Comparer - æå忝èŒã³ã³ããŒãã³ã
ååãšããŠããã®ããã±ãŒãžã¯ãã®åéã«é¢é£ããã»ãŒãã¹ãŠã®åé¡ã解決ããŸãã
ãã€ãªãªã³åŒŸã
â Fiddler ã¯ããã¹ãŠã® HTTP(S) ãã©ãã£ãã¯ããã°ã«èšé²ãããããã° ãããã·ã§ãã ãã®ãã©ãã£ãã¯ã調ã¹ããã¬ãŒã¯ãã€ã³ããèšå®ããåä¿¡ãŸãã¯éä¿¡ããŒã¿ããåçãããããšãã§ããŸãã
ãããŸã ã ã¢ã³ã¹ã¿ãŒ ãªã©ãéžæã¯ãŠãŒã¶ãŒæ¬¡ç¬¬ã§ãã
ãŸãšã
åœç¶ã®ããšãªãããåãã³ãã¹ã¿ãŒã¯ç¬èªã®æŠåšåº«ãšç¬èªã®ãŠãŒãã£ãªãã£ãæã£ãŠããŸãããªããªãããããã¯åçŽã«ããããããããã§ãã æã䟿å©ã§äººæ°ã®ãããã®ãããã€ããªã¹ãããŠã¿ãŸããã ãã ãã誰ãããã®æ¹åã®ä»ã®ãŠãŒãã£ãªãã£ã«æ £ããããšãã§ããããã«ã以äžã«ãªã³ã¯ãæäŸããŸãã
ã¹ãã£ããŒããŠãŒãã£ãªãã£ã®åçš®ããã/ãªã¹ã
- .
ååž Linuxãã§ã«ãããã¬ãŒã·ã§ã³ãã¹ãçšã®ããŸããŸãªãŠãŒãã£ãªãã£ãå«ãŸããŠãã
æŽæ°ãã: ãHack4SecãããŒã ã«ãããã·ã¢èªïŒè¿œå )
PSpider ã«ã€ããŠé»ã£ãŠããããã«ã¯ãããŸããã ã·ã§ã¢ãŠã§ã¢ã§ãããã¬ãã¥ãŒã«ã¯åå ããŠããŸããïŒèšäºã SecLab ã«éã£ããšãã«ç¥ããŸããããå®éã«ã¯ãããåå ã§ïŒç¥èããªããææ°ããŒãžã§ã³ 7.8 ããªãããïŒãèšäºã«ã¯å«ããŸããã§ããïŒã ãããŠçè«çã«ã¯ããã®ã¬ãã¥ãŒãèšç»ãããŠããŸã (ç§ã¯ãã®ããã«é£ãããã¹ããçšæããŠããŸã) ãããããäžçã«æ³šç®ããããã©ããã¯ããããŸããã
PPS èšäºã®äžéšã®å
容ã¯ã次ã®ã¬ããŒãã§æå³ãããç®çã§äœ¿çšãããŸãã 2012 幎㮠QA ã»ã¯ã·ã§ã³ã«ã¯ãããã§èšåãããŠããªãããŒã« (ãã¡ããç¡æ) ã®ã»ããã¢ã«ãŽãªãºã ãäœã䜿çšããé åºãæåŸ
ãããçµæã䜿çšããæ§æãããã³äœ¿çšããéã®ããããçš®é¡ã®ãã³ãããã¯ããã¯ãå«ãŸããŸããäœæ¥äžïŒã»ãŒæ¯æ¥ã¬ããŒãã®ããšãèããŠããŸãããããã¯ã®ãããã¯ã«ã€ããŠæåãå°œãããŠãäŒãããŸãïŒ
ã¡ãªã¿ã«ããã®èšäºã«é¢ããæèšã¯æ¬¡ã®ãšããã§ãã InfoSec ãªãŒãã³ã㌠(, ïŒã ã§ãã ããã»ã³ããã³ãº ã芧ãã ãã .
åºæïŒ habr.com
