I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 1

Manje sizozama enye indlela yokujova i-SQL. Ake sibone ukuthi isizindalwazi siyaqhubeka yini nokuphonsa imilayezo yamaphutha. Le ndlela ibizwa ngokuthi "ukulinda ukubambezeleka", futhi ukubambezeleka ngokwakho kubhalwe kanje: waitfor delay 00:00:01'. Ngikopisha lokhu kufayela lethu futhi ngikunamathisele kubha yekheli yesiphequluli.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Lokhu konke kubizwa ngokuthi "umjovo we-SQL wesikhashana oyimpumputhe". Esikwenzayo lapha ukuthi, "linda ukulibaziseka kwamasekhondi angu-10." Uma uqaphele, phezulu kwesokunxele sinombhalo othi "ukuxhuma ...", okungukuthi, lenzani ikhasi lethu? Ilinda uxhumano, futhi ngemva kwemizuzwana eyi-10 ikhasi elilungile livela kumonitha yakho. Sisebenzisa le nqubo, sithinta i-database ukuze isivumele ukuthi siyibuze eminye imibuzo embalwa, isibonelo, uma umsebenzisi enguJoe, ngakho-ke sidinga ukulinda imizuzwana eyi-10. Kuyabonakala? Uma umsebenzisi eyi-dbo, linda futhi imizuzwana eyi-10. Lena indlela yokujova ye-SQL eyimpumputhe.

Ngicabanga ukuthi onjiniyela abalungisi lobu bungozi lapho bedala amapeshi. Lona umjovo we-SQL, kodwa uhlelo lwethu lwe-IDS aluboni, njengezindlela zangaphambilini zokujova i-SQL.
Ake sizame okuthile okuthakaselekayo. Masikopishe lo mugqa ngekheli lasesizindeni se-inthanethi futhi siwunamathisele esipheqululini. Kwasebenza! Ibha ye-TCP kuhlelo lwethu ibe bomvu, uhlelo luphawule izinsongo ezi-2 zokuphepha.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Kuhle, ake sibone ukuthi kwenzekani ngokulandelayo. Sinosongo olulodwa kugobolondo le-XP, kanti olunye usongo - umzamo womjovo we-SQL. Sekukonke, kwaphawulwa imizamo emibili yokuhlasela uhlelo lokusebenza lewebhu.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Kulungile, manje ngisize nge-logic. Sinephakethe ledatha yokungenela lapho i-IDS ithi iphendule ekungeneni okuhlukahlukene kugobolondo le-XP.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Uma siskrolela phansi, sibona ithebula lamakhodi e-HEX, kwesokudla lapho kukhona ifulegi elinomlayezo othi xp_cmdshell + &27ping, futhi ngokusobala lokhu kubi.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Ake sibone lapha ukuthi kwenzekeni. Yenzeni iseva ye-SQL?

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Iseva ye-SQL yathi: "ungaba nephasiwedi kusizindalwazi sami, ungathola wonke amarekhodi ku-database yami, kodwa mfo, angifuni ukuthi usebenzise imiyalo yakho kimi, lokho akulungile neze"!

Okufanele sikwenze ukuqinisekisa ukuthi noma ngabe i-IDS ibika usongo kugobolondo le-XP, usongo alunakwa. Uma usebenzisa i-SQL Server 2005 noma i-SQL Server 2008, uma-ke umzamo womjovo we-SQL utholwa, igobolondo lomyalo wesistimu yokusebenza lizokhiywa, likuvimbele ukuthi uqhubeke nomsebenzi wakho. Kuyacasula kakhulu lokhu. Ngakho yini okufanele siyenze? Kufanele uzame ukubuza iseva ngomusa omkhulu. Ingabe kufanele usho lokhu: “ngicela, baba, ngingawathola la makhukhi”? Yilokho engikwenzayo, ngokungathí sina, ngibuza iseva ngokukhulu ukuzithoba! Ngicela izinketho ezengeziwe, ngicela ukulungiswa kabusha, futhi ngicela izilungiselelo zegobolondo le-XP zishintshwe ukuze ngenze igobolondo lifinyeleleke ngoba ngiyalidinga!

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Siyabona ukuthi i-IDS ihlonze lokhu - uyabona, izinsongo ezi-3 seziphawuliwe lapha.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Bheka nje lapha - siqhumise izingodo zokuphepha! Kubukeka sengathi isihlahla sikaKhisimusi, kuningi okulenga lapha! Izinsongo zezokuphepha ezingaba ngu-27! Hurray guys, sibambe lesi sigebengu, simtholile!

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Asikhathazeki ukuthi uzontshontsha idatha yethu, kodwa uma ekwazi ukwenza imiyalo yesistimu "ebhokisini" lethu - lokhu sekuvele kubi kakhulu! Ungadweba umzila we-Telnet, i-FTP, ungathatha idatha yami, lokho kuhle, kodwa angikhathazeki ngakho, angifuni nje ukuthi uthathe igobolondo "lebhokisi" lami.

Ngifuna ukukhuluma ngezinto ezingitholile. Ngisebenzela izinhlangano, ngizisebenzele iminyaka eminingi, futhi lokhu ngikutshela ngoba intombi yami icabanga ukuthi angisebenzi. Ucabanga ukuthi engikwenzayo nje ukuma esiteji ngixoxe, lokhu ngeke kuthathwe njengomsebenzi. Kodwa ngithi: "Cha, injabulo yami, ngingumxhumanisi"! Yilowo umehluko - ngikhuluma ingqondo yami futhi ngiyakhokhelwa ngakho.

Ngizokusho lokhu - thina, njengabaduni, siyathanda ukuqhekeza igobolondo, futhi kithi ayikho intokozo enkulu emhlabeni njengoku "gwinya igobolondo." Uma abahlaziyi be-IDS bebhala imithetho yabo, uyabona ukuthi bayibhala ukuze bavikeleke ekuphazanyisweni kwamagobolondo. Kodwa uma ukhuluma ne-CIO ngenkinga yokukhishwa kwedatha, uzokucela ukuthi ucabange ngezinketho ezimbili. Ake sithi nginesicelo esenza "izingcezu" eziyi-100 ngehora. Yini ebaluleke kakhulu kimina: ukuqinisekisa ukuphepha kwayo yonke idatha kulolu hlelo lokusebenza noma ukuphepha kwegobolondo "lebhokisi"? Lona umbuzo obalulekile! Yini okufanele ukhathazeke ngayo kakhulu?

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Ngenxa yokuthi igobolondo lakho "lebhokisi" lonakele akusho ukuthi umuntu usethole ukufinyelela ekusebenzeni kwangaphakathi kwezinhlelo zokusebenza. Yebo, lokhu kungaphezu kwamandla, futhi uma kungenzeki okwamanje, kungenzeka maduzane. Kodwa qaphela ukuthi imikhiqizo eminingi yokuvikela yakhelwe ekucabangeni ukuthi umhlaseli uhamba ngenethiwekhi yakho. Ngakho-ke bayakunaka ukukhishwa kwemiyalo, nasekusetshenzisweni kwemiyalo, futhi kumelwe uqaphele ukuthi lokhu kuyinto engathi sína. Banaka ubungozi obuncane, imibhalo elula ye-cross-site, imijovo ye-SQL elula kakhulu. Abanandaba nezinsongo ezithuthukile noma imilayezo efihliwe, abanandaba nalezo zinhlobo zezinto. Ungathi yonke imikhiqizo yonogada ifuna umsindo, ifuna yap, ifuna ukumisa into ekuluma iqakala. Nakhu engikufundile lapho ngisebenzelana nemikhiqizo yezokuphepha. Akudingeki uthenge imikhiqizo yokuphepha, awudingi ukushayela iloli ngokuhlehla. Udinga abantu abanekhono, abanamakhono abaqonda ubuchwepheshe. Yebo, Nkulunkulu wami, impela abantu! Asifuni ukuphonsa izigidi zamaRandi kulezi zinkinga, kodwa abaningi benu bake basebenza kulo mkhakha futhi bayazi ukuthi ngokushesha nje lapho umphathi wakho ebona isikhangiso, ugijimela esitolo ememeza, "Kufanele siyithole le nto! " Kodwa empeleni asikho isidingo, kufanele silungise umonakalo osemuva kwethu. Lokho bekuyisisekelo salokhu kusebenza.

Indawo yokuphepha yinto lapho ngachitha khona isikhathi esiningi ngiqonda ukuthi izindlela zokuphepha zisebenza kanjani. Uma usuziqonda izindlela zokuvikela, ukweqa isivikelo akunzima. Isibonelo, nginohlelo lokusebenza lwewebhu oluvikelwe i-firewall yalo. Ngikopisha ikheli lephaneli yezilungiselelo, nginamathisele kubha yekheli yesiphequluli bese ngiya kuzilungiselelo bese ngizama ukubhala phansi kwesayithi.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Ngenxa yalokho, ngithola umlayezo we-firewall mayelana nosongo - ngivinjiwe.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Ngicabanga ukuthi kubi lokhu, uyavuma? Uhlangabezane nomkhiqizo wokuvikela. Kodwa kuthiwani uma ngizama into efana nale: Ngifaka ipharamitha Joe'+OR+1='1

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Njengoba ubona, kwasebenza. Ngilungise uma nginephutha, kodwa sibone umjovo we-SQL wehlula i-firewall yohlelo lokusebenza. Manje asenze sengathi sifuna ukuqala inkampani yokusebenzisa ezokuphepha, ngakho-ke sizofaka isigqoko sethu sokwenza isoftware. Manje sihlanganisa ububi ngoba yisigqoko esimnyama. Ngingumxhumanisi, ngakho-ke ngingenza okufanayo nabakhiqizi bezinhlelo zokusebenza.

Sifuna ukudala futhi sikhiphe isistimu entsha yokuthola ama-tamper, ngakho-ke sizoqala inkampani ehlonza ama-tamper. I-Snort, njengomkhiqizo womthombo ovulekile, iqukethe amakhulu ezinkulungwane zamasiginesha aphazamisayo. Kufanele senze izinto ngendlela efanele, ngakho-ke ngeke sintshontshe lawa masignesha kwezinye izinhlelo zokusebenza bese siwafaka ohlelweni lwethu. Sizovele sihlale phansi sizibhale kabusha zonke - hey, Bob, Tim, Joe, woza lapha, ngokushesha uhlole wonke lawa masignesha angu-100!

Sidinga futhi ukudala iskena esisengozini. Uyazi ukuthi i-Nessus, uhlelo lokusesha ngokuzenzakalelayo ubungozi, inamasiginesha ayizinkulungwane ezingama-80 nemibhalo ehlola ubungozi. Sizophinda senze izinto ngendlela efanele futhi sizibhale kabusha zonke ohlelweni lwethu ngokwethu.
Abantu bayangibuza, “Joe, wenza zonke lezi zivivinyo usebenzisa isofthiwe yomthombo ovulekile njenge-Mod Security, Snort nokunye okunjalo, zifana kangakanani nemikhiqizo yabanye abakhiqizi?” Ngiyabaphendula: “Abafani nhlobo!” Ngenxa yokuthi abakhiqizi abazibi izinto emikhiqizweni yokuphepha yomthombo ovulekile, bahlala phansi bazibhalele yonke le mithetho.

Uma ukwazi ukwenza amasiginesha akho kanye nezintambo zokuhlasela zisebenze ngaphandle kokusebenzisa imikhiqizo yomthombo ovulekile, leli yithuba elihle kuwe. Uma ungakwazi ukuncintisana nemikhiqizo yezohwebo, uhamba ngendlela efanele, kufanele uthole umqondo ozokusiza ukuthi udume emkhakheni wakho.

Wonke umuntu uyazi ukuthi ngiyaphuza. Ake ngikubonise ukuthi kungani ngiphuza. Uma uke wenza ukuhlolwa kwekhodi yomthombo empilweni yakho, uzophuza nakanjani, ungithembe, emva kwalokho uzoqala ukuphuza.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Ngakho-ke, ulimi lwethu esiluthandayo yi-C++. Ake sibheke lolu hlelo - I-Web Knight, iwuhlelo lokusebenza lokuvikela amaseva ewebhu. Inokuhlukile ngokuzenzakalelayo. Lokhu kuyathakazelisa - uma ngiphakela lolu hlelo lokuvikela, ngeke lungivikele ku-Outlook Web Access.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Kuyamangalisa! Lokhu kungenxa yokuthi abathengisi abaningi be-software badonsa imithetho kuhlelo lokusebenza olulodwa futhi bayinamathisele emkhiqizweni wabo ngaphandle kokwenza ucwaningo oluningi. Ngakho-ke lapho ngiphakela uhlelo lokusebenza lwewebhu lokuvikela, ngithola ukuthi yonke into nge-webmail yenziwe ngokungalungile! Ngoba cishe noma iyiphi i-webmail iphula ukuphepha ngokuzenzakalelayo. Unekhodi yewebhu esebenzisa imiyalo yesistimu nemibuzo ye-LDAP noma esinye isitolo sesizindalwazi somsebenzisi ngokuqondile ku-inthanethi.

Ngitshele, kuyiphi iplanethi into efana nalena engabhekwa njengephephile? Cabanga nje ngakho: uvula i-Outlook Web Access, cindezela u-ctrl +K, ukucinga abasebenzisi nakho konke lokho, uphatha i-Active Directory ngokuqondile kwi-Inthanethi, ukhipha imiyalo yesistimu ku-Linux, uma usebenzisa i-Squirrel Mail, noma i-Horde nanoma yini enye. okunye. Ukhipha wonke lawa ma-eval nezinye izinhlobo zokusebenza okungaphephile. Ngakho-ke, ama-firewall amaningi awafaki ohlwini lwezingozi zokuphepha, zama ukubuza umenzi wesofthiwe yakho ngalokhu.

Masibuyele kuhlelo lokusebenza lwe-Web Knight. Intshontshe imithetho eminingi yokuphepha kusikena se-URL, esiskena zonke lezi zigaba zamakheli e-IP. Ngakho-ke, ingabe zonke lezi zigaba zamakheli azifakiwe emkhiqizweni wami?

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Ingabe ukhona kini ofuna ukufaka lawa makheli kunethiwekhi yakho? Uyafuna ukuthi inethiwekhi yakho isebenze kulawa makheli? Yebo, kuyamangalisa. Kulungile, ake sihlehle lolu hlelo sibheke ezinye izinto lolu hlelo lokuvikela olungafuni ukuzenza.

Babizwa ngokuthi "1999" futhi bafuna iseva yabo yewebhu ukuthi ibuyele emuva ngesikhathi! Ingabe ukhona kini okhumbula lo doti: /scripts, /iishelp, msads? Mhlawumbe abantu abambalwa bazokhumbula nge-nostalgia ukuthi kwakumnandi kangakanani ukugebenga izinto ezinjalo. Uyakhumbula, bakwethu, ukuthi kudala kanjani “sabulala” amaseva, bekupholile!”

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Manje, uma ubheka lokhu okuhlukile, uzobona ukuthi ungenza zonke lezi zinto - msads, printers, iisadmpwd - zonke lezi zinto ezingadingi muntu namuhla. Kuthiwani ngemiyalo ongavunyelwe ukuyenza?

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Lezi yi-arp, at, cacls, chkdsk, cipher, cmd, com. Njengoba ubala, uhlulwa yizinkumbulo zezinsuku zakudala, "mfo, khumbula ngenkathi sithatha leyo seva, khumbula lezo zinsuku"?

Kodwa nakhu okuthakazelisa ngempela - ingabe ukhona obona i-WMIC noma mhlawumbe i-PowerShell lapha? Cabanga ukuthi unohlelo olusha olusebenza ngokusebenzisa imibhalo kusistimu yendawo, futhi lezi izikripthi zesimanje ngoba ufuna ukusebenzisa iWindows Server 2008, futhi ngizokwenza into enhle ngokuyivikela ngemithetho eklanyelwe iWindows 2000. Ukuze ngokuzayo uma umthengisi eza kuwe nesicelo sakhe sewebhu, umbuze: “hey man, ufake izinto ezifana ne-bits admin, noma ukusebenzisa imiyalo ye-powershell, uzihlolile zonke ezinye izinto, ngoba sizobuyekeza futhi usebenzise inguqulo entsha ye-DotNET"? Kodwa zonke lezi zinto kufanele zibe khona emkhiqizweni wokuvikela ngokuzenzakalelayo!

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Into elandelayo engifuna ukukhuluma nawe ngayo amaphutha anengqondo. Ake siye ku-192.168.2.6. Lokhu kumayelana nohlelo lokusebenza olufanayo nolwedlule.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Ungase uqaphele okuthile okuthakazelisayo uma uskrolela phansi ekhasini bese uchofoza isixhumanisi esithi Xhumana nathi.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Uma ubheka ikhodi yomthombo yethebhu ethi “Xhumana nathi”, okungenye yezindlela zokuhlola engizenza ngaso sonke isikhathi, uzowuqaphela lo mugqa.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Cabanga ngakho! Ngizwa kuthiwa uma bekubona lokhu abaningi bathi: “Hawu”! Ngake ngenza ukuhlolwa kokungena, ngithi, ibhange lezigidigidi, futhi ngabona into efanayo. Ngakho-ke, asidingi noma yimuphi umjovo we-SQL noma umbhalo we-cross-site - sinezisekelo, le bha yamakheli.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Ngakho-ke, ngaphandle kokweqisa - ibhange lisitshele ukuthi linabo bobabili uchwepheshe wenethiwekhi kanye nomhloli wewebhu, futhi abazange baphawule. Okusho ukuthi, bakubheka njengokujwayelekile ukuthi ifayela lombhalo lingavulwa futhi lifundwe ngesiphequluli.

Okusho ukuthi, ungakwazi ukufunda ifayela ngokuqondile ohlelweni lwefayela. Umphathi wethimba labo lezokuphepha wangitshela: “yebo, esinye sezithwebuli sithole lobu bungozi, kodwa sakubona kuncane.” Ngaphendula ngathi, kulungile, nginike umzuzu. Ngithayiphe igama lefayela=../../../../boot.ini kubha yekheli futhi ngakwazi ukufunda ifayela lokuqalisa isistimu yefayela!

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Kulokhu bangitshela: “cha, cha, cha, lawa akuwona amafayela abucayi”! Ngiphendule - kodwa lena yi-Server 2008? Bathi yebo, nguye. Ngithi - kodwa le seva inefayela lokumisa elitholakala kumkhombandlela wezimpande weseva, akunjalo? “Kulungile,” bephendula. “Kuhle,” ngithi, “kuthiwani uma umhlaseli enza lokhu,” bese ngithayipha filename=web.config kubha yekheli. Bathi - ngakho-ke, awuboni lutho ku-monitor?

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Ngithi - kuthiwani uma ngichofoza kwesokudla kumonitha bese ngikhetha inketho ethi Bonisa Umthombo Wekhasi? Futhi yini engizoyithola lapha? “Akukho okugxekayo”? Ngizobona iphasiwedi yomphathi weseva!

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Futhi uthi ayikho inkinga la?

Kodwa ingxenye engiyithandayo yile elandelayo. Awungivumeli ukuthi ngikhiphe imiyalo ebhokisini, kodwa ngingakwazi ukweba iphasiwedi yomphathi weseva yewebhu kanye nesizindalwazi, ngibheke yonke imininingwane egciniwe, ngiklebhule yonke imininingwane emayelana nokwehluleka kwesizindalwazi kanye nesistimu, futhi ngibaleke nakho konke. Nansi indaba yomuntu omubi ethi, "hey man, today is the big day"!

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Ungavumeli imikhiqizo yezokuphepha ikugulise! Ungavumeli imikhiqizo yezokuphepha ikugulise! Thola izihlakaniphi, ubanike zonke lezo zikhumbuzo ze-Star Trek, ubenze babe nesithakazelo, ubakhuthaze ukuthi bahlale nawe, ngoba labo bantu abanuka kabi abangagezi nsuku zonke yibo abenza amanethiwekhi akho asebenze. Laba ngabantu abazosiza imikhiqizo yakho yezokuphepha isebenze ngendlela okufanele isebenze ngayo.

Ngitshele, bangaki kini abakwazi ukuhlala ekamelweni elilodwa isikhathi eside nomuntu ohlala ethi: "O, ngidinga ngokuphuthumayo ukuthayipha lesi script!", Futhi ubani omatasa ngalokhu ngaso sonke isikhathi? Kodwa udinga abantu abenza imikhiqizo yakho yokuvikela isebenze.

Ngizophinda futhi - imikhiqizo yezokuphepha iyiziphukuphuku ngoba izibani zihlala zenza amaphutha, zihlale zenza izinto ezingcolile, azinikezi ukuphepha. Angikaze ngiwubone umkhiqizo omuhle wokuvikela owawungadingi ukuthi umuntu one-screwdriver awuqinise lapho kudingekile ukuze usebenze ngokujwayelekile noma kancane kancane. Kumane kuwuhlu olukhulu lwemithetho ethi kubi, yilokho kuphela!

Ngakho-ke ngifuna nina madoda nibheke imfundo, izinto ezifana nokuphepha, ukuqeqeshwa kwe-polytechnic, ngoba kunezifundo eziningi zamahhala eziku-inthanethi eziphathelene nezindaba zokuphepha. Funda iPython, funda i-Assembly, funda ukuhlolwa kwesicelo sewebhu.

I-HACKTIVITY Conference 2012. I-Big Bang Theory: I-Evolution of Security Pentesting. Ingxenye 2

Yilokhu okuzokusiza ngempela ukuvikela inethiwekhi yakho. Abantu abahlakaniphile bavikela amanethiwekhi, imikhiqizo yenethiwekhi ayiwavikeli! Buyela emsebenzini futhi utshele umphathi wakho ukuthi udinga isabelomali esengeziwe sabantu abahlakaniphile, ngiyazi ukuthi lokhu kuyinkinga, kodwa mtshele noma kunjalo - sidinga imali eningi yabantu, ukuze sibaqeqeshe. Uma sithenga umkhiqizo kodwa singawuthengi izifundo zokuwusebenzisa ngoba uyabiza, pho kungani siwuthenga nhlobo uma singazofundisa abantu ukuwusebenzisa?

Ngisebenzele abathengisi abaningi bemikhiqizo yokuphepha, ngachitha impilo yami yonke ngisebenzisa leyo mikhiqizo, futhi ngiyagula yikho konke ukulawulwa kokufinyelela kwenethiwekhi nezinto ngoba ngifake futhi ngasebenzisa yonke leyo mikhiqizo ye-crap. Ngake ngafika kuklayenti, bafuna ukusebenzisa indinganiso engu-802.1x yephrothokholi ye-EAP, ngakho babe namakheli e-MAC namakheli esibili echwebeni ngalinye. Ngafika ngabona ukuthi konakele, ngaphenduka ngaqala ngokucindezela izinkinobho zephrinta. Uyazi, iphrinta ingaphrinta ikhasi lokuhlola lezinto zenethiwekhi ngawo wonke amakheli e-MAC namakheli e-IP. Kodwa kwavela ukuthi iphrinta ayisekeli izinga le-802.1x, ngakho-ke kufanele likhishwe.

Ngabe sengikhipha iphrinta futhi ngashintsha ikheli le-MAC lekhompuyutha yami ephathekayo ekhelini le-MAC lephrinta futhi ngaxhuma i-laptop yami, ngaleyo ndlela ngeqa lesi sixazululo esibizayo se-MAC, cabanga ngakho! Ngakho-ke lesi sixazululo se-MAC singangisiza ngani uma umuntu engase adlulise noma iyiphi ingxenye yesisetshenziswa njengephrinta noma ifoni ye-VoIP?

Ngakho-ke namuhla, okungikhathazayo ukuthi ngichitha isikhathi ngizama ukuqonda nokuqonda umkhiqizo wokuvikela othengwe yiklayenti lami. Kulezi zinsuku wonke amabhange engihlola ukungena kuwo anawo wonke lawa ma-HIPS, ama-NIPS, i-LAUGTHS, ama-MACS kanye nenqwaba yamanye ama-acronyms angenangqondo ngokuphelele. Kodwa ngizama ukuthola ukuthi le mikhiqizo izama ukwenzani nokuthi izama ukukwenza kanjani. Bese-ke, uma sengithole ukuthi hlobo luni lwendlela yokusebenza kanye nengqondo abayisebenzisayo ukunikeza isivikelo, akuba nzima nakancane ukukweqa.

Umkhiqizo wami oyintandokazi engizokushiya nawo ubizwa ngokuthi i-MS 1103. Kungumsebenzi osuselwe kusiphequluli "ofutha" ama-HIPS, Isignesha Yokuvinjelwa Kokungeniswa Komsingathi, noma amasiginesha abamba ukuvimbela ukungena. Eqinisweni, yakhelwe ukweqa amasiginesha e-HIPS. Angifuni ukukhombisa ukuthi isebenza kanjani ngoba angifuni isikhathi sokuyikhombisa, kodwa yenza umsebenzi omuhle kakhulu wokudlula lokho kuvikela futhi ngifuna ukuthi uyizame.
Kulungile bafo, ngiyahamba manje.

Ezinye izikhangiso 🙂

Siyabonga ngokuhlala nathi. Uyazithanda izindatshana zethu? Ufuna ukubona okuqukethwe okuthakaselayo okwengeziwe? Sisekele ngokufaka i-oda noma ngokuncoma kubangani, I-VPS yefu yonjiniyela kusuka ku-$4.99, i-analogue ehlukile yamaseva ezinga lokungena, esungulwe yithi ngenxa yakho: Lonke iqiniso nge-VPS (KVM) E5-2697 v3 (6 Cores) 10GB DDR4 480GB SSD 1Gbps kusuka ku-$19 noma ukwabelana ngeseva? (itholakala nge-RAID1 kanye ne-RAID10, kufika kuma-cores angu-24 kuze kufike ku-40GB DDR4).

I-Dell R730xd 2x ishibhile esikhungweni sedatha se-Equinix Tier IV e-Amsterdam? Lapha kuphela 2 x Intel TetraDeca-Core Xeon 2x E5-2697v3 2.6GHz 14C 64GB DDR4 4x960GB SSD 1Gbps 100 TV kusukela ku-$199 eNetherlands! I-Dell R420 - 2x E5-2430 2.2Ghz 6C 128GB DDR3 2x960GB SSD 1Gbps 100TB - isuka ku-$99! Funda mayelana Indlela yokwakha ingqalasizinda corp. ikilasi ngokusetshenziswa kwe-Dell R730xd E5-2650 v4 amaseva abiza u-9000 euros ngepeni?

Source: www.habr.com

Engeza amazwana