INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-1

Ngoku siza kuzama enye indlela yenaliti yeSQL. Makhe sibone ukuba i-database iyaqhubeka nokuphosa imiyalezo yempazamo. Le ndlela ibizwa ngokuba "ukulinda ukulibaziseka", kwaye ukulibaziseka ngokwayo kubhalwe ngolu hlobo: waitfor delay 00:00:01'. Ndikopa oku kwifayile yethu kwaye ndiyincamathisele kwibar yedilesi yesikhangeli.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Konke oku kubizwa ngokuba yi "blind temporary SQL injection". Konke esikwenzayo apha kukuba, "linda ukulibaziseka kwemizuzwana eyi-10." Ukuba uqaphele, phezulu ngasekhohlo sinombhalo othi "ukudibanisa ...", oko kukuthi, lenza ntoni iphepha lethu? Ilinda uqhagamshelo, kwaye emva kwemizuzwana eyi-10 iphepha elichanekileyo liyavela kwimonitha yakho. Ukusebenzisa le ndlela, siqhagamshelana ne-database ukwenzela ukuba isivumele ukuba siyibuze imibuzo embalwa, umzekelo, ukuba umsebenzisi nguJoe, ngoko kufuneka silinde imizuzwana eyi-10. Icacile? Ukuba umsebenzisi yi-dbo, linda kwakhona imizuzwana eyi-10. Le yindlela yokutofa ye-SQL eyimfama.

Ndicinga ukuba abaphuhlisi abalulungisi obu buthathaka xa besenza iipetshi. Le yinaliti ye-SQL, kodwa inkqubo yethu ye-IDS ayiboni, njengeendlela zangaphambili zenaliti ye-SQL.
Makhe sizame enye into enomdla ngakumbi. Masikope lo mgca ngedilesi ye-IP kwaye uyincamathisele kwisikhangeli. Isebenzile! Ibar ye-TCP kwiprogram yethu yajika yabomvu, inkqubo yaphawula izisongelo ezi-2 zokhuseleko.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Kulungile, makhe sibone ukuba kwenzeka ntoni emva koko. Sinesoyikiso esinye kwiqokobhe le-XP, kunye nesinye isoyikiso - umzamo wenaliti yeSQL. Lilonke, iinzame ezimbini zaphawulwa ukuhlasela isicelo sewebhu.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Kulungile, ngoku ndincede ngengqiqo. Sinepakethi yedatha yokungena apho i-IDS ithi iphendule ngokungena ngeendlela ezahlukeneyo kwiqokobhe le-XP.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Ukuba siskrolela ezantsi, sibona itafile yeekhowudi ze-HEX, ekunene kukho iflegi enomyalezo xp_cmdshell + &27ping, kwaye ngokucacileyo oku kubi.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Makhe sibone ukuba kwenzeka ntoni. Wenza ntoni umncedisi we SQL?

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Umncedisi we-SQL uthe: "unokuba negama eliyimfihlo kwisiseko sedatha yam, unokufumana zonke iirekhodi kwisiseko sam sedatha, kodwa mfo, andifuni ukuba uqhube imiyalelo yakho kum, ayipholile kwaphela"!

Into ekufuneka siyenzile kukuqinisekisa ukuba nokuba i-IDS ibika isoyikiso kwiqokobhe le-XP, isoyikiso asihoywa. Ukuba usebenzisa i-SQL Server 2005 okanye iSQL Server 2008, ukuba umzamo wokutofa weSQL uchongiwe, iqokobhe lomyalelo wenkqubo yokusebenza liya kutshixwa, likuthintele ekubeni uqhubeke nomsebenzi wakho. Oku kuyacaphukisa kakhulu. Ngoko ke kufuneka senze ntoni? Kuya kufuneka uzame ukubuza umncedisi ngobubele kakhulu. Ngaba ungatsho oku: “nceda, tata, ndingawafumana la maqebengwana”? Yiloo nto endiyenzayo, ngokunyanisekileyo, ndibuza umncedisi ngokuzithoba kakhulu! Ndicela iinketho ezongezelelweyo, ndicela uqwalaselo ngokutsha, kwaye ndicela useto lweqokobhe le XP litshintshwe ukwenza iqokobhe lifikeleleke kuba ndiyalidinga!

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Siyabona ukuba i-IDS iyibhaqile le nto - uyabona, izoyikiso ezi-3 sele ziqatshelwe apha.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Jonga nje apha - siqhume iinkuni zokhuseleko! Kubonakala ngathi ngumthi weKrisimesi, kuninzi okujingayo apha! Kangange 27 izoyikiso zokhuseleko! Hurray guys, sibambe le hacker, simfumene!

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Asinaxhala lokuba uya kuyiba idatha yethu, kodwa ukuba unako ukwenza imiyalelo yenkqubo "kwibhokisi" yethu - oku sele kunzulu! Ungazoba indlela yeTelnet, iFTP, ungayithatha idatha yam, ipholile, kodwa andinaxhala ngayo, andifuni ukuba uthathe iqokobhe le "bhokisi" yam.

Ndifuna ukuthetha ngezinto ezindifumeneyo. Ndisebenzela imibutho, ndibasebenzele iminyaka emininzi, kwaye ndikuxelela oku kuba intombi yam icinga ukuba andiphangeli. Ucinga ukuba konke endikwenzayo kukuma eqongeni ndincokole, oku akunakuthathwa njengomsebenzi. Kodwa ndithi: "hayi, uvuyo lwam, ndingumcebisi"! Nantso ke umahluko-ndithetha ingqondo yam kwaye ndiyahlawulwa ngayo.

Ndiza kuthetha oku - thina, njengabaduni, siyathanda ukuqhekeza iqokobhe, kwaye kuthi akukho lonwabo lukhulu emhlabeni kunokuginya iqokobhe. Xa abahlalutyi be-IDS bebhala imithetho yabo, uyabona ukuba bayibhala ukukhusela ekungcolisweni kweqokobhe. Kodwa ukuba uthetha neCIO malunga nengxaki yokukhutshwa kwedatha, uya kukucela ukuba ucinge ngeendlela ezimbini. Masithi ndinesicelo esenza 100 "amaqhekeza" ngeyure. Yintoni ebaluleke ngakumbi kum: ukuqinisekisa ukhuseleko lwazo zonke iinkcukacha kwesi sicelo okanye ukhuseleko lweqokobhe "lebhokisi"? Lo ngumbuzo obalulekileyo! Yintoni ofanele ukhathazeke ngayo ngakumbi?

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Ngenxa yokuba iqokobhe lakho "lebhokisi" lonakele ayithethi ukuba umntu ufumene ufikelelo ekusebenzeni kwangaphakathi kwezicelo. Ewe, oku kunokwenzeka ngakumbi, kwaye ukuba akukenzeki, kunokwenzeka kungekudala. Kodwa qaphela ukuba iimveliso ezininzi zokhuseleko zakhiwe kwingcinga yokuba umhlaseli uhamba ngenethiwekhi yakho. Ngoko ke banikele ingqalelo ekwenzeni imiyalelo, ekuphumezeni imiyalelo, yaye nize niphawule ukuba le nto ibubunzulu. Banike ingqwalasela kubuthathaka obungenamsebenzi, kwi-scripting elula kakhulu ye-cross-site, kwiinaliti ezilula kakhulu ze-SQL. Abakhathali malunga nezoyikiso eziphambili okanye imiyalezo efihliweyo, abakhathali ngezo ntlobo zezinto. Unokuthi zonke iimveliso zokhuseleko zijonge ingxolo, zikhangela yap, zijonge ukumisa into ekuluma iqatha. Nantsi into endiyifundileyo ngokusebenza neemveliso zokhuseleko. Akunyanzelekanga ukuba uthenge iimveliso zokhuseleko, akunyanzelekanga ukuba uqhube ilori umva. Ufuna abantu abanobuchule, abanezakhono ababuqondayo ubuchwephesha. Ewe, Thixo wam, abantu kanye! Asifuni ukuphosa izigidi zeedola kule miba, kodwa abaninzi benu baye basebenza kule ntsimi kwaye bayazi ukuba ngokukhawuleza nje ukuba umphathi wakho ebone isikhangiso, ubalekela evenkileni ekhwaza, "Kufuneka siyifumane le nto! " Kodwa akuyomfuneko ukuba siyenze, kufuneka silungise nje ubuxelegu obusemva kwethu. Leyo yayiyisiseko salo msebenzi.

Indawo yokhuseleko yinto apho ndichithe ixesha elininzi ndiqonda ukuba iindlela zokhuseleko zisebenza njani. Nje ukuba uqonde iindlela zokukhusela, ukudlula ukhuseleko akukho nzima. Umzekelo, ndinesicelo sewebhu esikhuselweyo yifirewall yayo. Ndikopa idilesi yepaneli yokuseta, ndiyincamathisele kwibar yedilesi yesikhangeli kwaye uye kwiseto kwaye uzame ukubhalwa kwe-cross-site.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Ngenxa yoko, ndifumana umyalezo we-firewall malunga nesoyikiso-ndivaliwe.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Ndicinga ukuba oku kubi, uyavumelana? Udibene nemveliso yokhuseleko. Kodwa kuthekani ukuba ndizama into enje: Ndifaka ipharamitha Joe'+OR+1='1

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Njengoko ubona, yasebenza. Ndilungise ukuba andilunganga, kodwa siyibonile inaliti ye-SQL yoyisa i-firewall yesicelo. Ngoku masenze ngathi sifuna ukuqalisa inkampani yokuphumeza ukhuseleko, ngoko ke siya kunxiba umnqwazi wethu wokwenza isoftware. Ngoku siqulathe ububi kuba ngumnqwazi omnyama. Ndingumcebisi, ngoko ke ndingenza okufanayo nabavelisi besoftware.

Sifuna ukuyila kunye nokusebenzisa indlela entsha yokufumanisa i-tamper, ngoko ke siza kuqalisa inkampani yokubona i-tamper. I-Snort, njengemveliso yomthombo ovulekileyo, iqulethe amakhulu amawaka eesayino zoyikiso eziphazamisayo. Kufuneka senze ngokweenqobo ezisesikweni, ke ngoko asiyi kuba ezi zisayino kwezinye izicelo kwaye sizifake kwinkqubo yethu. Siza kuhlala phantsi sizibhale kwakhona zonke - hey, Bob, Tim, Joe, yiza apha, ngokukhawuleza utyhutyhe zonke ezi 100 zityikityo!

Kufuneka kwakhona senze iskena sobuthathaka. Uyazi ukuba i-Nessus, inkqubo yokukhangela ngokuzenzekelayo ubuthathaka, ine-80 yamawaka esayinwe kunye nezikripthi ezijonga ukuba semngciphekweni. Siza kwenza ngokweenqobo ezisesikweni kwakhona kwaye sizibhale kwakhona zonke kwinkqubo yethu ngokwethu.
Abantu bayandibuza, "Joe, uzenza zonke ezi mvavanyo usebenzisa isoftware yomthombo ovulekileyo njengeMod Security, Snort kunye nokunye, zifana kangakanani nezinye iimveliso zabanye abavelisi?" Ndiyabaphendula ndisithi: “Abafani kwaphela!” Kuba abavelisi bengazibi izinto kwiimveliso zokhuseleko ezivulelekileyo, bahlala phantsi bazibhale ngokwabo yonke le migaqo.

Ukuba unokwenza utyikityo lwakho kunye neentambo zokuhlasela zisebenze ngaphandle kokusebenzisa iimveliso zomthombo ovulekileyo, eli lithuba elihle kuwe. Ukuba awukwazi ukukhuphisana neemveliso zorhwebo, uhamba ngendlela efanelekileyo, kufuneka ufumane ingcamango eya kukunceda ukuba ube nodumo kwintsimi yakho.

Wonke umntu uyazi ukuba ndiyasela. Makhe ndikubonise ukuba kutheni ndisela. Ukuba ukhe wenza uphicotho lwekhowudi yomthombo ebomini bakho, uya kusela ngokuqinisekileyo, undithembe, emva koko uya kuqala ukusela.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Ke, ulwimi lwethu esiluthandayo yiC++. Makhe sijonge le nkqubo-Web Knight, sisicelo somlilo kwiiseva zewebhu. Inezinxaxhi ngokungagqibekanga. Oku kunomdla- ukuba ndisasaza le firewall, ayizukundikhusela kuFikelelo lweWebhu ye-Outlook.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Iyamangalisa! Oku kungenxa yokuba abathengisi abaninzi besoftware batsala imithetho kwisicelo esinye kwaye bayincamathisele kwimveliso yabo ngaphandle kokwenza uphando oluninzi. Ngoko xa ndihambisa isicelo se-firewall yewebhu, ndifumanisa ukuba yonke into malunga ne-webmail yenziwe ngokungalunganga! Kuba phantse nayiphi na i-webmail iphula ukhuseleko ngokungagqibekanga. Unekhowudi yewebhu ephumeza imiyalelo yenkqubo kunye nemibuzo ye-LDAP okanye nawuphi na omnye uvimba wedatha wabasebenzisi ngqo kwi-Intanethi.

Ndixelele, kweyiphi iplanethi enokuthi into enje igqalwe njengekhuselekile? Khawucinge nje ngako: uvula uFikelelo lweWebhu ye-Outlook, cinezela ctrl +K, khangela abasebenzisi nayo yonke loo nto, ulawula i-Active Directory ngqo kwi-Intanethi, uphumeza imiyalelo yenkqubo kwi-Linux, ukuba usebenzisa i-Squirrel Mail, okanye iHorde okanye nantoni na. enye into. Ukhupha zonke ezi evals kunye nezinye iintlobo zokusebenza ezingakhuselekanga. Ke ngoko, uninzi lweefirewall azibandakanyi kuluhlu lweengozi zokhuseleko, zama ukubuza umenzi wesoftware malunga noku.

Masibuyele kwisicelo seWeb Knight. Ibile imithetho emininzi yokhuseleko kwiskena se-URL, esiskena zonke ezi ntlobo zeedilesi ze-IP. Ke, ngaba zonke ezi dilesi zoluhlu azibandakanywanga kwimveliso yam?

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Ngaba ukhona kuni ofuna ukufaka ezi dilesi kumsebenzi womnatha wakho? Ngaba uyafuna inethiwekhi yakho isebenze kwezi dilesi? Ewe, iyamangalisa. Kulungile, masikrole ezantsi le nkqubo kwaye sijonge ezinye izinto le firewall engafuni ukuzenza.

Babizwa ngokuba yi "1999" kwaye bafuna iseva yabo yewebhu ibuyele umva ngexesha! Ngaba ukho kuni oyikhumbulayo le nkunkuma: /scripts, /iishelp, msads? Mhlawumbi abantu abambalwa baya kukhumbula nge-nostalgia ukuba kwakumnandi kangakanani ukukhwabanisa izinto ezinjalo. Uyakhumbula, mfo, ukuba kwakudala kangakanani "sasibulala" iiseva, bekupholile!"

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Ngoku, ukuba ujonga ezi ngaphandle, uya kubona ukuba ungenza zonke ezi zinto - msads, printers, iisadmpwd - zonke ezi zinto akukho mntu uzidingayo namhlanje. Kuthekani ngemiyalelo ongavumelekanga ukuba uyenze?

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Ezi zi-arp, e, cacls, chkdsk, cipher, cmd, com. Njengoko uzidwelisa, woyiswa ziinkumbulo zemihla yakudala, “mfondini, khumbula xa sasithatha lo mncedisi, ukhumbule ezo ntsuku”?

Kodwa nantsi eyona nto inika umdla- ngaba ukhona umntu oyibonayo i-WMIC okanye mhlawumbi i-PowerShell apha? Khawufane ucinge ukuba unesicelo esitsha esisebenza ngokubhala izikripthi kwinkqubo yendawo, kwaye ezi zizikripthi zangoku kuba ufuna ukusebenzisa iWindows Server 2008, kwaye ndiza kwenza into enkulu ngokuyikhusela ngemithetho eyilelwe Windows 2000. Ukuze kwixesha elizayo umthengisi esiza kuwe kunye nesicelo sakhe sewebhu, babuze: "Hey ndoda, ukhe wagubungela izinto ezifana ne-bits admin, okanye ukusebenzisa imiyalelo ye-powershell, ukhangele zonke ezinye izinto, kuba siza kuhlaziya kwaye usebenzise inguqulelo entsha yeDotNET"? Kodwa zonke ezi zinto kufuneka zibekho kwimveliso yokhuseleko ngokungagqibekanga!

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Into elandelayo endifuna ukuthetha nawe ngayo ziimpazamo ezisengqiqweni. Makhe siye ku-192.168.2.6. Oku kumalunga nesicelo esifanayo nesidlulileyo.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Unokuqaphela into enomdla ukuba uskrolela ezantsi iphepha kwaye ucofe ikhonkco Qhagamshelana nathi.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Ukuba ujonga ikhowudi yomthombo wethebhu ethi "Qhagamshelana nathi", yenye yeendlela zokuvavanya endizenzayo ngalo lonke ixesha, uya kuwuqaphela lo mgca.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Ycinge! Ndiva ukuba xa bebona oku, abaninzi bathi: “Wow”! Ndakhe ndenza uvavanyo lokungena, ndithi, ibhanki ye-billionaire, kwaye ndabona into efanayo. Ngoko ke, asifuni naliphi na inaliti ye-SQL okanye i-scripting yesayithi - sineziseko, le bha yedilesi.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Ngoko, ngaphandle kokugqithisa - ibhanki yasitshela ukuba bobabini ingcali yenethiwekhi kunye nomhloli wewebhu, kwaye abazange benze naziphi na izimvo. Oko kukuthi, bajonga njengento eqhelekileyo ukuba ifayile yombhalo inokuvulwa kwaye ifundwe ngesikhangeli.

Oko kukuthi, unokufunda ngokulula ifayile ngqo kwindlela yefayile. Intloko yeqela labo lezokhuseleko yandixelela oku: “Ewe, omnye wabahloli bafumanisa ukuba lo mngcipheko wawusesichengeni, kodwa wawuthatha njengento encinane.” Ndiye ndaphendula, kulungile, ndinike umzuzu. Ndichwetheze igama lefayile=../../../../boot.ini kwibar yedilesi kwaye ndakwazi ukufunda indlela yefayile yokuqalisa ifayile!

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Kule nto bandixelela oku: “hayi, hayi, hayi, ezi asizofayile zigxekayo”! Ndaphendula - kodwa le Server 2008? Bathi ewe, nguye. Ndithi-kodwa lo mncedisi unefayile yoqwalaselo ebekwe kulawulo lweengcambu zomncedisi, akunjalo? “Kulungile,” baphendula ngelitshoyo. “Kuhle,” ndithi, “ukuba umhlaseli wenza oku,” kwaye ndichwetheza filename=web.config kwibar yedilesi. Bathi-ke yintoni, awuboni nto esweni?

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Ndithi- kuthekani ukuba ndicofa-ekunene kwimonitha kwaye ndikhethe ukhetho lweMthombo wePhepha lokuBonisa? Kwaye ndiza kufumana ntoni apha? “Akukho nto ibalulekileyo”? Ndiza kubona igama eligqithisiweyo lomlawuli weseva!

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Kwaye uthi akukho ngxaki apha?

Kodwa eyona nto ndiyithandayo yile ilandelayo. Awundivumeli ukuba ndenze imiyalelo kwibhokisi, kodwa ndiyakwazi ukweba igama eligqithisiweyo lomlawuli weseva yewebhu kunye nedathabheyisi, ndijonge kuyo yonke isiseko sedatha, ndikrazule yonke imathiriyeli malunga nesiseko sedatha kunye nokusilela kwenkqubo, kwaye ndihambe nayo yonke. Le yimeko yomfo ombi esithi, "Hey man, namhlanje yimini enkulu"!

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Musa ukuvumela iimveliso zokhuseleko zikwenze ugule! Musa ukuvumela iimveliso zokhuseleko zikwenze ugule! Fumana ama-Nerds, ubanike zonke ezo memorabilia ze-Star Trek, ubenze babe nomdla, bakhuthaze ukuba bahlale nawe, kuba abo banuka kakubi abangazihlambi yonke imihla ngabo benza uthungelwano lwakho lusebenze. Aba ngabantu abaza kunceda iimveliso zakho zokhuseleko zisebenze njengoko kufanele.

Ndixelele, bangaphi kuni abakwaziyo ukuhlala kwigumbi elinye ixesha elide kunye nomntu ohlala esithi: "Owu, ndifuna ngokukhawuleza ukuchwetheza le script!", Kwaye ngubani oxakeke ngale nto ngamaxesha onke? Kodwa ufuna abantu abenza iimveliso zakho zokhuseleko zisebenze.

Ndiza kuphinda ndiyithethe-iimveliso zokhuseleko ziziyatha kuba izibane zihlala zenza iimpazamo, zihlala zisenza izinto ezimdaka, aziboneleli ngokhuseleko. Andizange ndibone imveliso yokhuseleko elungileyo engazange ifune umntu one-screwdriver ukuba ayiqinise apho kuyimfuneko ukuze isebenze ngakumbi okanye ngaphantsi kwesiqhelo. Luluhlu nje olukhulu lwemithetho ethi kubi, kuphelele apho!

Ke ndifuna nina bafana nijonge imfundo, izinto ezifana nokhuseleko, uqeqesho lwepolytechnic, kuba zininzi iikhosi zasimahla ze-Intanethi kwimiba yokhuseleko. Funda iPython, funda iNdibano, funda uvavanyo lwesicelo sewebhu.

INkomfa ye-HACKTIVITY ka-2012. Ithiyori ye-Big Bang: Ukuzivelela kwePentesting yoKhuseleko. Icandelo lesi-2

Oku kuya kukunceda ngokwenene ukukhusela inethiwekhi yakho. Abantu abahlakaniphile bakhusela amanethiwekhi, iimveliso zenethiwekhi azenzi! Buyela emsebenzini kwaye uxelele umphathi wakho ukuba ufuna uhlahlo lwabiwo-mali oluthe kratya lwabantu abakrelekrele ngakumbi, ndiyazi ukuba le yingxaki, kodwa mxelele nokuba kunjalo - sifuna imali eninzi ebantwini, ukuze sibaqeqeshe. Ukuba sithenga imveliso kodwa singayithengi ikhosi yokuba isetyenziswa njani kuba iyabiza, kutheni le nto siyithengayo ukuba asizukufundisa abantu indlela yokuyisebenzisa?

Ndisebenzele uninzi lwabathengisi bemveliso yokhuseleko, ndichithe ubomi bam bonke ndiphumeza ezo mveliso, kwaye ndiyagula lulo lonke ulawulo lofikelelo lwenethiwekhi kunye nezinto kuba ndifakile kwaye ndiqhuba zonke ezo mveliso zecrap. Ndakhe ndafika kumxhasi, bafuna ukuphumeza umgangatho we-802.1x weprotocol ye-EAP, ngoko babe needilesi ze-MAC kunye needilesi zesibini kwi-port nganye. Ndafika ndabona ukuba konakele, ndajika ndaqalisa ukucofa amaqhosha eprinta. Uyazi, umshicileli unokuprinta iphepha lovavanyo lwezixhobo zenethiwekhi nazo zonke iidilesi ze-MAC kunye needilesi ze-IP. Kodwa kwavela ukuba umshicileli akawuxhasi umgangatho we-802.1x, ngoko kufuneka ukhutshelwe ngaphandle.

Emva koko ndakhupha umshicileli kwinethiwekhi kwaye ndatshintsha idilesi yeMAC yelaptop yam kwidilesi yeMAC yomshicileli kwaye ndaqhagamshela ilaptop yam, ngaloo ndlela ndigqitha esi sisombululo sibizayo seMAC, cinga ngayo! Ke yintoni enokunceda esi sicombululo se-MAC sindenzele sona ukuba umntu unokudlula nje nayiphi na intwana yesixhobo njengomshicileli okanye ifowuni yeVoIP?

Ke namhlanje, ukundimangalela kukuba ndichitha ixesha ndizama ukuqonda nokuqonda imveliso yokhuseleko ethengwe ngumxhasi wam. Kule mihla ibhanki nganye endiyenza kuvavanyo lokungena kuyo inazo zonke ezi HIPS, NIPS, LAUGTHS, MACS kunye neqela elipheleleyo lezinye iiakhronimi ezipheleleyo. Kodwa ndizama ukufumanisa ukuba ezi mveliso zizama ukwenza ntoni kwaye zizama ukwenza njani. Ke, nje ukuba ndifumanise ukuba luhlobo luni lwendlela kunye nengqiqo abayisebenzisayo ukubonelela ngokhuseleko, akubi nzima kwaphela ukuyigqitha.

Imveliso yam endiyithandayo endiza kukushiya nayo ibizwa ngokuba yi-MS 1103. Lusetyenziso olusekwe kwisikhangeli "esitshiza" i-HIPS, iSiginitsha yokuThintelwa koMmkeli, okanye isiginitsha yokuthintela ukungenela. Ngapha koko, yenzelwe ukugqitha utyikityo lwe-HIPS. Andifuni ukubonisa indlela esebenza ngayo kuba andifuni ixesha lokuyibonisa, kodwa yenza umsebenzi omkhulu wokudlula olo khuseleko kwaye ndifuna ukuba uzame.
OK guys, ndiyahamba ngoku.

Dlala ividiyo

Ezinye iintengiso 🙂

Enkosi ngokuhlala nathi. Ngaba uyawathanda amanqaku ethu? Ngaba ufuna ukubona umxholo onomdla ngakumbi? Sixhase ngokufaka iodolo okanye ngokucebisa abahlobo, ifu VPS kubaphuhlisi ukusuka $4.99, i-analogue eyodwa yeeseva zomgangatho wokungena, eyenzelwe wena: Inyaniso yonke malunga neVPS (KVM) E5-2697 v3 (6 Cores) 10GB DDR4 480GB SSD 1Gbps ukusuka kwi-$ 19 okanye indlela yokwabelana ngomncedisi? (ifumaneka nge-RAID1 kunye ne-RAID10, ukuya kuthi ga kwi-24 cores kunye ne-40GB DDR4).

Dell R730xd 2x ngexabiso eliphantsi kwiziko ledatha le-Equinix Tier IV eAmsterdam? Kuphela apha 2 x Intel TetraDeca-Core Xeon 2x E5-2697v3 2.6GHz 14C 64GB DDR4 4x960GB SSD 1Gbps 100 TV ukusuka $199 eNetherlands! Dell R420 - 2x E5-2430 2.2Ghz 6C 128GB DDR3 2x960GB SSD 1Gbps 100TB - ukusuka $99! Funda malunga Ulwakha njani umbutho weziseko zophuhliso. iklasi ngokusetyenziswa kwe-Dell R730xd E5-2650 iiseva ze-v4 ezixabisa i-9000 yee-euro ngepeni?

umthombo: www.habr.com