
ãŸããã
ãã€ãŠ2000幎代ååã«ãå€ãã®äººã¯ãèªã¿åãïŒæžã蟌ã¿ïŒãããWindowsãã·ã³ãšãªãœãŒã¹ïŒSMBïŒãæ€åºããããã«ããããã€ããŒã®ãããã¯ãŒã¯ãããã«é ãã®ã¿ãŒã²ãããå®æçã«ãã¹ãã£ã³ããããšããäºå®ã«æ¥œããŸããŠããŸããã æ€çŽ¢ããã»ã¹ã¯åºæ¬çãªãã®ã§ãããIPã¢ãã¬ã¹ã®ç¯å²ãŸãã¯ãããã¯ãŒã¯ãã¹ã¯ãèšå®ãããããŸããŸãªããŒã«ïŒLANguardãããã¯ãŒã¯ã¹ãã£ããŒãxIntruderãªã©ïŒãéããŠã¢ãã¬ã¹ãã¹ãã£ã³ããããµãŒããŒãç¹å®ãããŸããã å€ãã®å Žåãæ€åºããããã·ã³ã§ã¯ãããŸããŸãªãããã¯ãŒã¯ãªãœãŒã¹ïŒãã£ã¹ã¯ãããªã³ã¿ãŒããã£ã¬ã¯ããªïŒãèªã¿åãã«äœ¿çšã§ããæžã蟌ã¿ã«ã¯ããŸã䜿çšãããŠããŸããã§ããã IPC $ãšãŠãŒã¶ãŒãGuestãã䜿çšããå¿åã»ãã·ã§ã³ãéããŠããã·ã³äžã®ãªãœãŒã¹ã転éããããšãã§ããŸããããã¹ã¯ãŒãã®ãªããAdministratorsãã®ã¡ã³ããŒãããããšããããŸãããŸããæ€åºããããã·ã³ã«å¯Ÿãããã¢ã¯ãã£ããªãå¹æã®åŸãWindows NT 4.0ãŸãã¯Windowsãå®è¡ããŠãããµãŒããŒãèŠã€ããããšãã§ããŸãã2000ãµãŒããŒã åœæã®Windows 98ãæèŒããããã·ã³ãèŠã€ããããšãéããããã°ãããã¯ç°¡åã«ãªããŸãã-åœæãæå®ãããOSã«ã¯SMBã§ã®äœæ¥ã®å®è£
ãªã©ãããŸããŸãªè匱æ§ãå«ãŸããŠããŸããããªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããã®ãã«ãŒããã©ãŒã¹ã¯ããã€ã€ã«ã¢ããã§ãæ°åã§å®è¡ãããŸããæ¥ç¶ã æã«çªå
¥ããã人ã®ããã«ãWindows 9xãžã®ãã¢ã¯ã»ã¹ã- ãããã³ã°å
¬éïŒãããã¯ãŒã¯ã»ãã¥ãªãã£ã®ç§å¯ãšãœãªã¥ãŒã·ã§ã³ã«ã€ããŠè©³ããæžãããŠããŸãã 第4ç« ïŒWindows 95/98ãšMeã®ãããã³ã° ã ããããèšäºã®æ®ãã®éšåã¯ããã«ã€ããŠã§ã¯ãããŸããã
2019幎ã«ããã®ãããªããšã³ã¿ãŒãã€ã¡ã³ãããå¯èœã«ãªããšã¯æããããŸããã§ããã 䌌ãŠããã®ã¯ãä»ã®äººãå©çšã§ãããã¹ãŠã®å¥œå¥å¿ãããããªãœãŒã¹ãèŠã€ããããããšã§ãã ããã«ãéå»2幎éã§äººæ°ã®ãããã¬ã³ãïŒMongoDBãŸãã¯ElasticsearchããŒã¿ããŒã¹ã®æ€çŽ¢ãã¢ã¯ã»ã¹ã§ããããã«ãªã£ãŠããïŒã§ã¯ãªããå°ãçŸå®çãªãµãŒãã¹ã«çŠç¹ãåœãŠãŸãã
ããã«ãç§ã¯æé å
šäœã圌ãã®å«çèŠç¯ãè©äŸ¡ããªãããšãææ¡ããŸãããã®æçš¿ã¯ããã·ã¢é£éŠåæ³ã®äžéšã®èšäºãŸãã¯ä»ã®å·ã®æ³åŸããã®åæ§ã®èŠç¯ã«èµ·å ããè¡åã®åŒã³ããã§ã¯ãªãããšã«æ³šæããŠãã ããã
ãããã¯ãŒã¯ãã¡ã€ã«ã·ã¹ãã ïŒNFSïŒ
ãããã¯ãŒã¯ãã¡ã€ã«ã·ã¹ãã ïŒNFSïŒ -ãã¡ã€ã«ã·ã¹ãã ãžã®ãããã¯ãŒã¯ã¢ã¯ã»ã¹ã®ããã®ãããã³ã«ã§ããããã¯ãŒã¯ãä»ããŠãªã¢ãŒããã¡ã€ã«ã·ã¹ãã ã«æ¥ç¶ïŒããŠã³ãïŒã§ããããã«ãããŠãŒã¶ãŒããã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããããã«ããããŒã«ã«ãã¡ã€ã«ãšåãããã«ãããã®ãã¡ã€ã«ãæäœã§ããããã«ããŸãã
ãã¡ãããåžå Žã§å
¥æå¯èœãªã»ãšãã©ã®ãããã¯ãŒã¯æ¥ç¶ã¹ãã¬ãŒãžïŒNASïŒã¯NFSããµããŒãããNFSãµãŒãã¹ãå±éã§ãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãåãããµãŒããŒã ãã§ãªããããŒã«ã«ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãæäŸããŸãã
Ubuntu OSããã³IPã¢ãã¬ã¹192.168.1.1ãããµãŒããŒãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããããã®èšå®ã¯ã/ etc / exportsãã¡ã€ã«ã«å«ãŸããŠããã次ã®åœ¢åŒã®ãšã³ããªã§ãã
- / data / place1 192.168.1.0/255.255.255.0(rw,no_subtree_check,nohide,asyncïŒ192.168.101.0/255.255.255.0(rw,no_subtree_check,nohide,asyncïŒ
- data / place2 192.168.1.0/255.255.255.0(rw,no_subtree_check,nohide,asyncïŒ192.168.101.0/255.255.255.0(rw,no_subtree_check,nohide,asyncïŒ
ãã®å Žåããããã¯ãŒã¯192.168.1.0/255.255.255.0ã192.168.101.0/255.255.255.0ã®IPã¢ãã¬ã¹ãæã€ã¯ã©ã€ã¢ã³ãã«å¯ŸããŠããµãŒããŒãšãã®ãªãœãŒã¹/ããŒã¿/ place1ãžã®NFSã¢ã¯ã»ã¹ãå¯èœã§ãã
/ home / user / exampleãªã©ã®ããŒã«ã«ãã£ã¬ã¯ããªã«ãªã¢ãŒããªãœãŒã¹ãããŠã³ãããŸããã¯ã©ã€ã¢ã³ããèš±å¯ããããµããããäžã«ãããNFSã¯ã©ã€ã¢ã³ããã€ã³ã¹ããŒã«ãããŠããå ŽåãïŒUbuntuïŒã³ãã³ãã䜿çšããŠå¯èœã§ãã
mount -t nfs 192.168.1.1:/data/place1 /home/user/example
IPã¢ãã¬ã¹ã®ä»£ããã«*ãŸãã¯ïŒå
šå¡ïŒãæå®ãããŠããå Žåãå€ãã®å Žåãã¯ã©ã€ã¢ã³ãã¯ã·ã¹ãã ã«ãªã¢ãŒããªãœãŒã¹ãããŠã³ãã§ããŸãã
ãŠãŒã¶ãŒïŒããšãã°ãUbuntuã®äžïŒã¯ãã¿ãŒããã«ã«å
¥åããã ãã§ãïŒshowmount -e ip-targetãšããµãŒããŒïŒãµãŒããŒã®ãšã¯ã¹ããŒããªã¹ãïŒã§å©çšå¯èœãªãªãœãŒã¹ã«é¢ããæ
å ±ãååŸããŸãã
äŸïŒ
showmount -e 81.24..
Export list for 81.24..:
/home/admin 192.168.52.1/24
ãããã£ãŠã次ã®ã·ããªãªã圢æãããŸããNFSãå®è¡ããŠãããµãŒããŒãæ€åºãããµãŒããŒäžã®äœ¿çšå¯èœãªãªãœãŒã¹ã決å®ããçµæãåäžã®åºåãã©ãŒã ã«çµ±åããŠãç¶æ³ã«å¿ããŠç¶è¡ããŸãã
ãªãœãŒã¹ã«äœãã§ããã-æããã«ãäœã§ãïŒ
- ããšãã°ãããªãŒãã³ãNASããã€ã¹ã®å Žåã®ã€ã³ã¿ãŒããããŠãŒã¶ãŒã®å人ãã¡ã€ã«ã
- äŒæ¥å
šäœãããŒã¿ããŒã¹ãããŒã¿ããŒã¹ã¢ãŒã«ã€ãã®ãã¡ã€ã«ãå«ããã£ã¬ã¯ããªã
- å€ãã®å Žåãã¢ãã¬ã¹ã/ home / *ã®ãã£ã¬ã¯ããªïŒ.sshã«ããŒããããæžã蟌ã¿å¯èœïŒ
- ãããªç£èŠã·ã¹ãã ã®ãã¡ã€ã«ãå«ããã£ã¬ã¯ããªã
- ãã®ä»...
IPã¢ãã¬ã¹ãååŸãã
ã°ããŒãã«ã€ã³ã¿ãŒãããäžã®NFSã䜿çšãããµãŒããŒã®æ€åºã«é¢ããŠã¯ã2ã€ã®æ¹æ³ããããŸããç¬ç«ããæ¹æ³ãããŸããŸãªããŒã«ã䜿çšããæ¹æ³ãæ¢è£œã®ãµãŒãããŒãã£ã¹ãã£ã³çµæãããŒã¿ããŒã¹ããµãŒãã¹ã§ãã å®éããã¹ãŠIPã¢ãã¬ã¹ã®ãªã¹ããååŸããããšã«ãªããŸãã ããŒã«ã«ãããã¯ãŒã¯ã§ã¯ããªãã·ã§ã³ã¯æçœã ãšæããŸã-ç¬ç«ããŠè¡åããŸãã
éããŠããTCPããŒã111ã2049ã¯ãNFSãµãŒãã¹ãæ©èœããŠãã蚌æ ãšããŠåœ¹ç«ã¡ãŸãã
ãµãŒããŒIPã¢ãã¬ã¹ã®ãªã¹ããç¬ç«ããŠååŸããã«ã¯ãã¢ãã¬ã¹ç¯å²ãŸãã¯ãµããããå
šäœãã¹ãã£ã³ããŠãæå®ãããéããŠããããŒãã®ååšã確èªããã ãã§ååã§ãã ããã«ã¯ãnmapãmasscanãªã©ã®ããŒã«ãé©ããŠããŸãã
ããšãã°ãã³ãã³ãmasscan -p111,2049 200.26.1XX.0/24 ârate=10000
éããŠããããŒã111ã2049 masscan -p111,2049 200.26.1XX.0/24 ârate=10000
ãããã¯ãŒã¯200.26.1XX.0 / 24ãæ°ç§éã¹ãã£ã³ãããŸãã
Scanning 256 hosts [2 ports/host]
Discovered open port 2049/tcp on 200.26.1XX.28
Discovered open port 111/tcp on 200.26.1XX.15
Discovered open port 111/tcp on 200.26.1XX.20
Discovered open port 111/tcp on 200.26.1XX.28
æ€åºãããåIPã¢ãã¬ã¹ã«å ããŠã次ã®ã³ãã³ããé©çšã§ããŸãã
showmount --no-headers -e 200.26.1XX.28
çµæïŒ
/usr/common *
æããã«ãèªåã§ã€ã³ã¿ãŒããã空éã®äœçŸäžãã®IPã¢ãã¬ã¹ãã¹ãã£ã³ããããšã¯å¯èœã§ãããããã¯æéã®æ¹æ³ã§ã¯ãªããçŽ æŽãããShodanãµãŒãã¹ã¯ãµãã¿ã¹ã¯ã®ãœãªã¥ãŒã·ã§ã³ã«ãªãå¯èœæ§ããããŸãããã¡ããä»ã«ããããŸãããããã«ã¯éåžžã«äŸ¿å©ãªæ§æãšAPIããããŸã ã ãµãŒãã¹ã®æ©èœã®èª¬æãæãäžããããšã¯ããã®èšäºã®ç®çã§ã¯ãããŸããã ç°¡åã«èª¬æãããšããã®ãµãŒãã¹ã¯ã€ã³ã¿ãŒãããã«æ¥ç¶ãããããã€ã¹ã®é«åºŠãªæ€çŽ¢ãæäŸããŸãã æ€çŽ¢æ¡ä»¶ã¯ããããã¯ãŒã¯èå¥åããã³ãã®ä»ã®ã¡ã¿ããŒã¿ïŒèšŒææžã®ã·ãªã¢ã«çªå·ãªã©ïŒã«ããããšãã§ããŸãã Shodanã«ã¯ã¿ãŒã²ãããçµã£ãæ€çŽ¢ã®ããã®å€ãã®æ©èœããããŸãããããšãã°ãmongodbãelasticããŸãã¯apacheãšãã補ååã®è£œååºæºããããããNFSã§åå¥ã®æ€çŽ¢ã¯èŠã€ãããŸããã§ããã ãããã£ãŠãWeb NFSã䜿çšãããšã次ã®ã¯ãšãªãæ€çŽ¢ã§ããŸãïŒnfsãtcp 2049ãtcp 111ã PortmapïŒ2049ãªã©ã

ãŸãã¯ãShodanã¯ã©ã€ã¢ã³ãïŒCLIïŒãã€ã³ã¹ããŒã«ãããµãŒãã¹ã«å¯ŸããKEY APIãåæåããŠãã³ãã³ãã©ã€ã³ããæ€çŽ¢ãåŒã³åºããŸããäŸïŒ
- shodan search --fields ip_strãããŒãPortmapïŒ2049
- shodan search --fields ip_strãport --separatorãnfs
çµæïŒ
139.196.154.23,111ã
198.27.116.37,111ã
95.211.192.96,111ã
80.23.66.122,111ã
210.116.82.97,111ã
192.198.82.3,111ã
165.227.67.242,111ã
116.12.48.9,111ã
85.34.250.102,111ã
182.75.249.197,111ã
192.151.212.175,111ã
119.216.107.127,111ã
217.59.68.2,111ã
178.159.12.97,111ã
...
ãããã£ãŠãæå¹ãªNFSãµãŒãã¹ãæã€ããã€ã¹ã®IPã¢ãã¬ã¹ã®ãªã¹ããååŸããæ¹æ³ã¯ç解ã§ããŸãã
ãã®åé¡ããŸãšããŠè§£æ±ºããæ¹æ³ã¯å€æ°ãããŸããbashã¹ã¯ãªãããäœæãããshowmountãåŒã³åºããŠäžé£ã®ã³ãã³ãããããªãããŒãªãã€ãã©ã€ã³ãç·šæããããã®ä»ã®ãªãã·ã§ã³-奜ããªäººã
ç§ã®ç 究ã§ã¯ãPythonã§ãã®åé¡ã2ã€ã®ç°ãªãæ¹æ³ã§è§£æ±ºããŸããã æåã®æ¹æ³ã¯ãsshãä»ããŠNFSã¯ã©ã€ã¢ã³ãã䜿çšããŠUbuntuã®ããŒãœãã«ãµãŒããŒã«æ¥ç¶ããç®çã®IPã¢ãã¬ã¹ã®ããŒã«ã䜿çšããŠshowmountã³ãã³ããåŒã³åºããŸãã 2çªç®ã®è§£æ±ºçã¯ãçŽç²ãªPythonã§ãã
ç§ã¯çåãçãããããããªããšæãïŒãªãããããããªã«é£ããã®ãããªãPythonã§ã¯ïŒ
以åã®Habrã«é¢ããèšäºã®ããã«ãLampyreããŒã«ã䜿çšããã®ã§ã2æ26æ¥ã«åœŒãã¯Pythonã§ãã©ãããã©ãŒã ã«ã¢ãžã¥ãŒã«ãæžã蟌ãããšãã§ããAPIãå
¬ââéããŸããã
ã©ã³ãã¬Lampyreã«ã€ããŠç°¡åã«èª¬æããŸããããã¯ãåãç®çã§ããç¥ããã人æ°ã®ããããŒã«ã§ããMaltegoã«é¡äŒŒãããWindowsçšã®ãåããã¯ã©ã€ã¢ã³ãã䜿çšããOSINTããã³ããŒã¿åæçšã®ãœãããŠã§ã¢ãã©ãããã©ãŒã ã§ãã Maltegoãšåæ§ãLampyreã¯ãããã«äœ¿ãããããŸããŸãªãµãŒãã¹ã«å¯Ÿããäžé£ã®ãªã¯ãšã¹ããæäŸããŸãã ã¯ãšãªã¯ãæŠå¿µçã«ã¯ãæ¢ç¥ã®è£œåããã®å€æãšåçã§ãã äœãã足ããªãå Žåãç¬èªã®ãªã¯ãšã¹ããæžãããšãå¯èœã«ãªããŸããã Lampyreã§æäŸããããªã¯ãšã¹ãã¯ãç¬ç«ããŠèšè¿°ããããã©ãããã©ãŒã ã€ã³ãã©ã¹ãã©ã¯ãã£ã§å®è¡ãããŸã-ãã·ã³äžã§ã ã€ãŸãããŠãŒã¶ãŒã¯Pythonãã€ã³ã¹ããŒã«ããå¿
èŠãªãã¹ãŠã®ã©ã€ãã©ãªãã³ãŒãã§äœ¿çšããå¿
èŠããããŸãã
APIã®æ©èœããã¹ãããããšã«ããŸããã éèŠãªç¹ã¯ãç¹ã«ãŠãŒã¶ãŒããµãŒãã¹ããç¬èªã®KEY APIãæã€å¿
èŠããªããããLampyreã¯Shodanãžã®ããã€ãã®ããªã¯ãšã¹ãããæ¢ã«æã£ãŠãããšããããšã§ãã ãããã£ãŠã1åã®ãªã¯ãšã¹ãã§ãNFSãµãŒãã¹ãäžããIPã¢ãã¬ã¹ã®ãªã¹ããååŸã§ããŸãã2åç®ã®ãªã¯ãšã¹ãã§ãç§ãæžããã¢ãžã¥ãŒã«ã¯å©çšå¯èœãªãªãœãŒã¹ããã§ãã¯ããåãã°ã©ãäžã§ãªãœãŒã¹ã®ç¹æ§ã§çµæãèŠèŠåããŸãã
ãããŠããéåœ
Shodanããæ€çŽ¢ããŠã¢ãžã¥ãŒã«ããã¹ããããšãã¢ãžã¢è«žåœã®ShodanãµãŒãã¹ã«ããã¹ãã£ã³çµæã®å質ãšéãç¶æ³ãäžå®å®ãªãªãœãŒã¹ã«ã©ã®ããã«é¢ä¿ããããèŠãããšãèå³æ·±ããã®ã«ãªããŸããã éžæã¯å€§éæ°åœã«ããã£ããç§ã¯éåœãéåžžã«æè¡çã«å
é²åœã§ãããšèšãå¿
èŠã¯ãªããšæãããããŠç§ã¯ããªãããã®ãããã¯ãŒã¯ã§é¢çœãäœããèŠã€ããããšãã§ããããšãææ¡ããã
Shodanã«ããæ€çŽ¢ãã¯ãšãªïŒ nfs ãåœïŒå€§éæ°åœã³ãŒãã kr

çµæã¯ããã«æ¥ãŸããïŒäžã®ç»åã§ã¯ãäžè¬çãªã¹ããŒã ã®äžéšã®ã¿ã§ãïŒã

ãã¹ããªã¹ãïŒ
- psi.kaist.ac.kr
- hulk.kaist.ac.kr
- messi.kaist.ac.kr
- marvel.kaist.ac.kr
- kaist.ac.kr
- ai1.kaist.ac.kr
- jarvis3.kaist.ac.kr
- baraddur.kaist.ac.kr
- rho.kaist.ac.kr
- jarvis.kaist.ac.kr
ãããã®ãã¹ãŠã¯ãã°ã©ããšååã®äž¡æ¹ã§èŠãããšãã§ããããã«ãAS1781ãšããŠãªã¹ããããŠããŸã- éåœç§åŠæè¡é¢

éåœå
端æè¡ç 究æ -倧ç°ã«ããéåœã代衚ããåŠè¡ç 究倧åŠã¯ãéåœã®å
šåœã©ã³ãã³ã°ã®2çªç®ã®è¡ã«ãããŸãã 倧åŠã¯äžè²«ããŠéåœã®ãããæè²æ©é¢ã®5ïŒ
ã«å«ãŸããŠããŸãã
æå®ãããIPã¢ãã¬ã¹ããèšè¿°ãããã¢ãžã¥ãŒã«ãExploreïŒNFSïŒSSHïŒããžã®å
¥ååŒæ°ãšããŠäœ¿çšããŸãããã®çµæã

ã°ã©ãã«è¡šã®çµæã衚瀺ããããã®ãã®ãããªã¹ããŒã ãããã«äœæããŸããïŒãã®èšäºã®åŸåã§ã°ã©ããæ§ç¯ããããã®ã¹ããŒã ãšååã«ã€ããŠïŒã

Shodanã¹ããŒããšçµåããçµæ

ã°ã©ãã®é ç¹ãšé¢ä¿ãåæãããšãã誰ãã¢ã¯ã»ã¹ã§ããã/ homeãªãœãŒã¹ãã©ã®ã¢ãã¬ã¹ã«ããããæããã«ãªããŸãïŒ*ïŒã
èŠèŠçèªèãæ¹åããã«ã¯ãã°ã©ããªããžã§ã¯ãã®ããããã£ãšãã€ã¢ã°ã©ã ã®ä»ã®èšå®ãå€æŽããŸãã

ãã¡ããããµãŒããŒã®1ã€ã«ãªãœãŒã¹ã®äžéšã亀äºã«ããŠã³ãããŠãå匷ãå§ããŸããã ã©ãã§ãã»ãŒåãã§ãã-ãŠãŒã¶ãŒãã£ã¬ã¯ããªïŒasmãhooãhyshinãjayãjiwonãjkhee110ãjokangjinãkmh603ãksm782ãleeãlinusãlost + foundãmarvel_guestãpieãqweãscloudãseokminãsgimãthrlekã yoosjãyshaãzinnia7ã
ãã¡ã€ã«ãå«ãã»ãšãã©ãã¹ãŠã®ãã£ã¬ã¯ããªãèªã¿æžããããŸããã .sshã®äžéšã®ãŠãŒã¶ãŒã«ã¯ãããããžã®æžã蟌ã¿ã¢ã¯ã»ã¹æš©ãæã€authorized_keysãã¡ã€ã«ããããŸããã
ããŒãçæãããŠãŒã¶ãŒã®1人ã®authorized_keysã«ã³ããŒããããŒã2222ã§sshãä»ããŠãµãŒããŒã«æ¥ç¶ããShodanããããŒã¿ããããŒãçªå·ãåãåããŸããã
ãŠãŒã¶ãŒããããã¯ãŒã¯èšå®ïŒ

ãããã¯ãŒã¯äžã®ãã¹ãïŒ

ãã¡ã€ã«/ etc /ãšã¯ã¹ããŒãããã³ãã©ã€ãïŒ

ãã¡ã€ã«/ etc / fstabããã³OSïŒ

ããã¯å€§åŠé¢çãåŠçã®ããã®ããåŠéšã®ãããã¯ãŒã¯ã§ãããå€ãã®ç°ãªãPythonãœãŒã¹ãGPUãAnacondaãã£ã¹ããªãã¥ãŒã·ã§ã³ãªã©ã«é¢é£ãããã®ãããããããµãŒããŒäžã§äœããã®èšç®ãå®è¡ãããšèããŠããŸãã ç§ã¯ãã¹ãŠãå匷ããããã§ã¯ãªããããã§äœãããã¹ããèãå§ããŸããããã¡ãããã»ãšãã©ã®ããŒãã§ãæ©ããããšãã§ããŸããïŒãã£ãšãšããŸããã¯ãªäœããèãããããããããŸããïŒããããã¯ããŸãèå³ãæ¹ããŸããã§ããã ãããŠãç§ã¯æ¬¡ã®ããšãèããŸããïŒç 究æã¯ç§åŠçã§å
é²çã§ãããããæ
å ±ã»ãã¥ãªãã£ã®åéãããã¯ãã§ãã å®éãå®éšå®€å
šäœã§ããïŒ ãœãããŠã§ã¢ã»ãã¥ãªãã£ã©ããšãã®ãããSang Kil Cha
ç§ã¯åœŒã«æçŽãæžãããšã«æ±ºããã®ã§ã圌ãã¯èšããã€ã³ã¿ãŒãããäžã®ãã¹ãŠã®äººãNFSãªãœãŒã¹ãèªã¿åãããã³æžã蟌ã¿èš±å¯ã§æ¥ç¶ã§ããããã«ããããšã¯éåžžã«å±éºã§ããæããã«ããªãã¯äœããä¿®æ£ããã¹ã¯ãªãŒã³ã·ã§ãããæ·»ä»ããŠéä¿¡ããå¿
èŠããããŸã
æçŽ1芪æãªããµã³ãã«ãã£ã
kaist.ac.krã®ãŠã§ããµã€ãã§ãKAISTã®äž»èŠãªSoftSec LabãšåŒã°ããŠããããã«ãç§ã¯ããªãã«æçŽãæžããŠããŸãã
æ
å ±ã»ãã¥ãªãã£ã®åéã§ã®èª¿æ»äžã«ãæå³ãããå¶ç¶ã«ã次ã®ãµãŒããŒãæ€åºãããŸããã
143.248.247.131-psi.kaist.ac.kr
143.248.247.4-jarvis3.kaist.ac.kr
143.248.247.169
143.248.247.223
143.248.247.235
143.248.247.251-marvel.kaist.ac.kr
143.248.247.239-jarvis.kaist.ac.kr
143.248.247.194-hulk.kaist.ac.kr
143.248.2.23
ãããã®ãµãŒããŒã¯ãã¹ãŠãNFSïŒNetwork File SystemïŒãµãŒãã¹ã皌åããŠããŸãã
ãããã®ãµãŒããŒãžã®ã¢ã¯ã»ã¹ã®ã»ãã¥ãªãã£ã¬ãã«ã¯éåžžã«äœãã§ãã
ãã¹ãŠã®ã³ã³ãã³ããå«ããããã®ãµãŒããŒã®ããŒã ãã£ã¬ã¯ããªã«ã¯ãã€ã³ã¿ãŒãããã䜿çšãã誰ã§ãã¢ã¯ã»ã¹ã§ããŸãã
ããšãã°ãèšå®nfs-/ etc / exports 143.248.247.251-> / home ãŸãã¯143.248.247.239
showmount -e 143.248.247.239
143.248.247.239ã®ãšã¯ã¹ããŒããªã¹ãïŒ
/ããŒã¿
/ home / appl
ã»ãšãã©ã®ãµãŒããŒã®ãŠãŒã¶ãŒãã£ã¬ã¯ããªã¯ããããªãã¯ããã³ãã©ã€ããŒãsshã¢ã¯ã»ã¹ããŒãå«ããµããã£ã¬ã¯ããªãå«ããèªã¿åãããã³æžã蟌ã¿ã®ããã«ã¢ã¯ã»ã¹ã§ããŸãã
ãã¡ã€ã«ãç·šéãããšãæ°ããã¢ã¯ã»ã¹ããŒãè¿œå ãããµãŒããŒãžã®ãªã¢ãŒãsshã¢ã¯ã»ã¹ãååŸããŠãããããã€ãã®å
éšKAISTãµããããã«ã¢ã¯ã»ã¹ã§ããŸãã
ãã®ãããªæµ
ãã¢ã¯ã»ã¹ããã¹ãããããã ãã«ãå€æŽã¯è¡ããããããŒã¿ã®ç·šéãã³ããŒãåé€ãè¡ããããã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®å®³ããããŸããã§ããã
äœããã®è¬èŸãšèšŒæ ã«ã€ããŠã¯ãæ·»ä»ãã¡ã€ã«ãã芧ãã ããã
èŠä»¶ãã¯ã¬ãŒã ã¯ãããŸãããããããã¯ãŒã¯ã»ãã¥ãªãã£ã¬ãã«ã倧å¹
ã«åŒ·åããããšããå§ãããŸãã
ããã«åœŒãã¯ç§ã«çããŸãããç¡æ翻蚳ïŒããããšããç§ãã¡ã¯èª°ã«ã§ã転éããŸãã
åç1æããŠãããŠããããšãïŒ ãã®ã¡ãŒã«ããããã¯ãŒã¯ãšã»ãã¥ãªãã£ã®æ
åœè
ã«è»¢éããŸãã ãã¹ãããµã³ãã«
ãã®èšäºãå
¬éããåã«ãäœãå€æŽããããã確èªããããšã«ããŸããã

å®éããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã¯å
éšãããã¯ãŒã¯äžã®ãã·ã³ããã®ã¿èš±å¯ãããŠããŸãããããµãŒããŒ143.248.247.251ã«ã€ããŠã¯ã©ãã§ãããã è¡šã®ãšã³ããªã«ãããšãNFSèšå®ã®ãã¹ããªãœãŒã¹ã¯*ã®ãŸãŸã§ãã ããŒãã«ã®ããããã³ã°ãã®å¥ã®ããŒãžã§ã³ãã°ã©ãã«ã¹ã±ããããŸããã

ããããã³ã°ãã®å€æŽç¹ïŒNFSãªããžã§ã¯ãã¯ãIPãšNFSãã¹ãšãã2ã€ã®åäžã®å±æ§ã§ãæ¥çããããŠããŸãã Statusãªããžã§ã¯ãã¯ãçã¬ã³ãŒãåã®å
容ãå«ãvalueå±æ§ã«å€ã * ããå«ãŸããå Žåã«ã®ã¿äœæãããŸã
ãããŠãããŒãã«ã®ã°ã©ãã¯æ°ãããã©ãŒã ã«è¡šç€ºãããŸãïŒ

ããŠããšããã§ãå
éšãããã¯ãŒã¯ã®ã¢ãã¬ã¹æå®ãã¯ã£ãããšèŠããããã«ãªããŸããããµãŒããŒ143.248.247.251ã§ã¯ããŠãŒã¶ãŒãã£ã¬ã¯ããªããã¡ã€ã«ã®å
容ãç·šéããããšãã§ããŸãã ååãšããŠãå¯èœæ§ã¯ä»¥åãšåããŸãŸã§ããã
ãããŠãç§ã¯ãµã³ãã«ãã£æ°ã«2çªç®ã®æçŽãæžããŠããŸããåæ§ã®æåã®å
容ã§ã人æ°ã®ããhabr.comãªãœãŒã¹ã®èšäºã«ããã€ãã®ã€ãã³ããæ²èŒãããããšã«æ³šæããŠãã ããã
æçŽ2芪æãªããµã³ãã«ãã£ãããªãã«è¯ãäžæ¥ãã
ã¡ãŒã«ãåãåã£ãåŸã«äœãå€æŽããã£ããã©ããã確èªããå®éã«ã¢ã¯ã»ã¹èšå®ãå€æŽããŸããã ããããæããã«ã»ãã¥ãªãã£ãšã³ãžãã¢ã¯143.248.247.251 IPã¢ãã¬ã¹ãé€å€ãããã®èšå®ã¯åããŸãŸã§ããã èŠç¥ãã¬äººãã¢ã¯ã»ã¹ã§ããªãããã«ããã®IPãä¿è·ããŠãã ããã
æ
å ±ã»ãã¥ãªãã£ã®ããŒãã«é¢ããèšäºãæžããŠããã®ã§ã https://habr.comã«æçš¿ããŸã ã ããã¯ãã·ã¢ã§éåžžã«äººæ°ã®ãããŠã§ããµã€ãã§ãã ãã®èšäºã«ã¯ãNFSã¢ã¯ã»ã¹èšå®ã®è³ªã®äœãã«é¢ããããã€ãã®æç« ãšããµãŒããŒã®äºäŸã®ããã€ããå«ãŸããŸãã èšäºãæ²èŒããããããã®èšäºãžã®ãªã³ã¯ããéãããŸãã
Lampyre APIã®äœ¿çšæ¹æ³ãšã¢ãžã¥ãŒã«ã®äœææ¹æ³
ã¢ãžã¥ãŒã«ã¯ãIPã¢ãã¬ã¹ã®ãªã¹ããŸãã¯192.168.0 / 24ã®åœ¢åŒã®ãµããããã®ãªã¹ããå
¥åãšããŠåãå
¥ããå¿
èŠããããŸã-ãã®æ®µéã§ã¯ããµããããã®å Žåãã³ãŒãå
ã§IPã¢ãã¬ã¹ã®æååã®é¢äžã«é¢ããå
¥åããŒã¿ãåå¥ã«æ€èšŒããå¿
èŠããããŸã- IPãªã¹ãã«å€æããŸãã
次ã®ã¹ãããã¯ãPython paramikoã©ã€ãã©ãªãä»ããŠãããŒãœãã«sshãµãŒããŒãšã·ãªã¢ã«ïŒã¢ãžã¥ãŒã«ã³ã³ã»ããã³ãŒãã«éåæã®è©Šã¿ãååšããïŒã³ãã³ãåŒã³åºãã«ã¢ã¯ã»ã¹ããŸãã
timeout {timeouts} showmount --no-headers -e {ip}
çµæã®åºåã¯ãPythonã³ãŒããä»ããŠãPythonã®èŸæžã®ãªã¹ãã§ããåºåæ§é ã«è§£æãããŸãã
èŸæžã®ããŒïŒ
- current_day-ãŠãŒã¶ãŒèŠæ±æ¥
- host_query-æ
å ±ãåä¿¡ãããIP
- shared_paââth-NFSãªãœãŒã¹
- status_ip-ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã«é¢ããæ
å ±ãIPã¢ãã¬ã¹ãããããä»ããŠãªã¹ããããŠããå ŽåãèŸæžæååã¯ãªã¹ãå
ã§è€è£œãããŸãã
ããã«ããã®æŠå¿µã®æŠå¿µã«ããã°ãstatus_ipããŒã®å€ããµããžã§ã¯ãã«è§£æããããšããããªããã£ããªè©Šã¿ãè¡ãããŸãïŒIPã¢ãã¬ã¹ããã¹ãã¬ã³ãŒããã*ããŸãã¯ãeveryoneãå€
APIã®ããã¥ã¡ã³ããšãµããŒãLampyre.ioã®èª¬æã«ãããšãåã¢ãžã¥ãŒã«ã¯1ã€ä»¥äžã®ããŒãã«ã«ããŒã¿ãè¿ãå¿
èŠããããŸãããããŒãã«ã¯APIã®äžéšãšããŠèšè¿°ãããå¿
èŠããããŸãïŒã¿ã¹ã¯ããããŒãããŒãã«ããããŒïŒã å®éããããã¢ãžã¥ãŒã«ã®äž»ãªçµæã§ãã
ãããã£ãŠãèŸæžããŒãèæ
®ããæçµçµæã¯è¡šã«ãªããŸãã
class NFSHeader(metaclass=Header): display_name = 'Search data from NFS services' current_day = Field('Date', ValueType.Datetime) host_query = Field('Search ip', ValueType.String) shared_path = Field('NFS path', ValueType.String) ip = Field('ip address', ValueType.String) network = Field('network address', ValueType.String) host = Field('host', ValueType.String) status = Field('raw record', ValueType.String)
ãµãŒããŒã§ã®showmountã³ãã³ãã®çµæã®åæããã®å€ïŒãããã«å€æŽãããïŒãããŒãã«ã«æžã蟌ãŸããŸãã ã¯ã©ã¹å
ã®ãã£ãŒã«ãã®ååã¯ããèªäœãè¡šããŠãããçã®ã¬ã³ãŒãåã«ã¯ããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ã«é¢ããæ
å ±ãæ ŒçŽãããŸãã ããæå³ã§ãNFSãªãœãŒã¹äžã®ããŒã¿ã®ãã®åæã¯OSINTãšèŠãªãããšãã§ããŸããããŸããŸãªIPã¢ãã¬ã¹ããã®ã¢ã¯ã»ã¹ã®å¯èœæ§ã«é¢ããæ
å ±ã¯ããªãœãŒã¹ã®ææè
ãŸãã¯ãªãœãŒã¹ãããã¯ãŒã¯å
ã®ã¢ãã¬ã¹æå®ã®ã¢ã€ãã¢ãæäŸããŸãã ããšãã°ãNFSãµãŒãã¹ãåãããµãŒããŒã®IPã¢ãã¬ã¹ã¯ãŠã¯ã©ã€ãã«ãããã¢ã¯ã»ã¹ãèš±å¯ãããŠããIPã¢ãã¬ã¹ã¯ãã€ãã«ãããŸãã

ãŸãããã®äŸã®èª¿æ»ãå±éãããšãNFSã ãã§ãªããã¢ãã¬ã¹77.120.103.9ã138.201.202.135ããã³ãã¡ã€ã³* .aniart.com.uaã®1ã€ã®èšŒææžãéããŠããµãŒããŒã®æ¥ç¶ãããã«ç¢ºèªãããŸãã

ããŒã¿ãã¢ãžã¥ãŒã«ã«è»¢éããŠããŒãã«ã«æžã蟌ãæ¹æ³ïŒ
Taskã¯ã©ã¹ããç¬èªã®SearchDataNFSã¯ã©ã¹ãäœæããŸãã
class SearchDataNFS(Task)
get_id
ã¡ãœããã§get_id
ãäžæã®ã©ã³ãã UUID get_id
è¿ããŸãã
def get_id(self): return 'bf51fd57-3fec-4416-9d07-905935a484b4'
get_display_name
ã¡ãœããget_display_name
ã¯ãã¿ã¹ã¯ã®get_display_name
æ¹æ³get_display_name
æå®ãã get_description
ã¡ãœããã§ã¯ãååã«å¿ããŠã¿ã¹ã¯ã®èª¬æãæå®ããŸãã
def get_display_name(self): return 'Explore: NFS(SSH)' def get_description(self): return 'Explore NFS resourses'
get_headers
ã¡ãœããã§get_headers
䜿çšããããŒãã«ãæå®ããŸãã
def get_headers(self): return NFSHeader
get_enter_paramsã¡ãœããã¯ãå
¥åãŠã£ã³ããŠã®ã¿ã€ãã決å®ããŸãã ã³ãŒããããæååã®ãªã¹ããå
¥åã«æäŸãããåŸã§ç¬ç«ããŠIPã¢ãã¬ã¹ã«å€æãããããšãæããã§ãã
def get_enter_params(self): ep_coll = EnterParamCollection() ep_coll.add_enter_param('ips', 'IP', ValueType.String, is_array=True, value_sources=[Attributes.System.IPAddress], description='IPs, networks') return ep_coll
executeã¡ãœããã§ã¯ãã¿ã¹ã¯ã®ã¡ã€ã³å®è¡ãçºçããŸãã
ips = [] for input_ip in set(map(lambda z: z.strip(), enter_params.ips)): ips.extend(reparse_ip_hosts(input_ip))
å
¥åãã©ã¡ãŒã¿ãŒã«ã¯ãenter_params.ipsããã¢ã¯ã»ã¹ããŸãã reparse_ip_hosts
ã¡ãœããã§ã¯ãIPã¢ãã¬ã¹ãžã®æååã®èªå·±å®è£
æ€èšŒãè¡ãããŸãã
targets = ((ip, port) for ip in ips for port in ports) lines = thread_async_nfs_one_client(targets) info = reparse_result_rows(lines) fields_table = NFSHeader.get_fields() for data_id in info: tmp = NFSHeader.create_empty() for field in fields_table: if field in data_id: tmp[fields_table[field]] = data_id[field] result_writer.write_line(tmp, header_class=NFSHeader)
thread_async_nfs_one_client
é¢æ°ã§ã¯ãsshã䜿çšããŠãµãŒããŒã«æ¥ç¶ãïŒIPã¢ãã¬ã¹ããŠãŒã¶ãŒåãããã³ãã¹ã¯ãŒãã¯ããŒãã³ãŒãã§èšå®ãããŸãïŒãåè¿°ã®ããã«showmountãå®è¡ãããçµæã解æããã reparse_result_rows
é¢æ°ã§å床å€æŽãããŸãã infoã¯èŸæžã§æ§æããããªã¹ãã§ããããšã«æ³šæããããšãéèŠã§ããåèŸæžã§ã¯ãããŒã¯NFSHeaderã¯ã©ã¹ã®ãã£ãŒã«ããšããŠååãä»ããããŸãã ã€ãŸããèŸæžã¯æ¬¡ã®ããã«ãªããŸãã
{ 'current_day': datetime.datetime(2019, 3, 6, 16, 48, 17), 'host_query': '192.168.1.1', 'shared_path': '/volume1/workspace', 'ip': '192.168.10.10', 'network': '', 'host': '', 'status': '192.168.10.10' }
ãã£ã¯ã·ã§ããªå
ã®ããŒã¿åã芳å¯ããããšã¯éèŠã§ãããããã¯ããŒãã«ã®èª¬æãšåãã§ãªããã°ãªããŸããã
次ã«ãã«ãŒãå
ã§ããªã¹ãèŠçŽ ãå埩åŠçããAPIã¡ãœããïŒ result_writer.write_line ïŒãä»ããŠç¹å®ã®NFSHeaderããŒãã«ã«æžã蟌ã¿ãŸãã
詳现ã«ã€ããŠã¯ãããã¥ã¡ã³ããåç
§ããŠãã ããã
åºæ¬çã«ãã¢ãžã¥ãŒã«ã¯Lampyreã«è¿œå ããæºåãã§ããŠããŸãã
Lampyreã§ã¢ãžã¥ãŒã«ã䜿çšãã
sshã䜿çšãããŠãããšããäºå®ãšshowmountã³ãã³ãã®å®è¡ã«ããããã¡ãããsshãä»ããŠãµãŒããŒã«ã¢ã¯ã»ã¹ã§ããå¿
èŠããããŸãã ç§ã®ãã¹ãã§ã¯ããã®åœ¹å²ã¯UbuntuãšNFSã¯ã©ã€ã¢ã³ããã€ã³ã¹ããŒã«ãããVirtualboxã®ä»®æ³ãã·ã³ã«ãã£ãŠæããããŸããã
ãŠãŒã¶ãŒã®ãã·ã³ã§ãã€ãã£ãã¢ãžã¥ãŒã«ãæäœããã«ã¯ãPython 3.6ãå¿
èŠã§ããã€ã³ã¿ãŒããªã¿ãŒãžã®ãã¹ãã·ã¹ãã å€æ°ã«å«ãŸããŠãããããã®ãã¹ãLampyre\config\appSettings.config
ã§æå®ãããŠããå¿
èŠãããLampyre\config\appSettings.config
ã ããã©ã«ãã§ã¯ãpythonPathããŒã¯èšå®ã§ã³ã¡ã³ãåãããŠããŸãã
Lampyreãžã®ã¢ãžã¥ãŒã«ã®ããŒãã¯ã次ã®æé ã§å®è¡ãããŸãã
- ã¹ã¯ãªãããŠã£ã³ããŠã§ããã¡ã€ã«Lampyre \ user_tasks \ ontology.pyïŒã¢ããªã±ãŒã·ã§ã³ã«ä»å±ïŒãããŒãããŸãã
- åããŠã£ã³ããŠã§ãã¢ãžã¥ãŒã«ïŒãã®å Žåã¯nfs_via_ssh.pyïŒãããŒãããŸãã äœãåé¡ãçºçããå Žåã 詳现ãã¿ã³ã圹ç«ã¡ãŸã
- èªã¿èŸŒã¿åŸã [ã¿ã¹ã¯ ]ã¿ãã®[ èŠæ±ã®äžèŠ§ ]ãŠã£ã³ããŠã«[ ããŒã«ã« ã¿ã¹ã¯ ]ã»ã¯ã·ã§ã³ã衚瀺ãããŸãïŒã¢ãžã¥ãŒã«ã®ã³ãŒãã§ã¯å¥ã®æ¹æ³ã§åŒã³åºãããšãã§ããŸãïŒãååã¯ExploreïŒNFSïŒSSHïŒã§ãã

æŽæ°ããããªã¯ãšã¹ããªã¹ããŠã£ã³ããŠïŒ

- åè¿°ããããã«ãNFSã䜿çšãããµãŒããŒã®IPã¢ãã¬ã¹ã¯ãæåã«QueryïŒtcp 2049ãã©ã¡ãŒã¿ãŒïŒåã«nfsãæå®ã§ããŸãïŒã䜿çšããŠShodanæ€çŽ¢ã¯ãšãªãå®è¡ããããšã§æé©ã«ååŸã§ããŸãã ããã©ã«ãã§1ã«èšå®ãããŠããPageãŸãã¯rangeãã©ã¡ãŒã¿ãŒã¯ãShodanãµãŒãã¹ãã1ããŒãžã®åçãè¿ãããããšãæå³ããŸããããŒãžã«ã¯éåžž100ã®çµæïŒè¡ïŒããããŸãã
Shodanã®å®è¡ã®çµæïŒ

- IPã¢ãã¬ã¹ãããŒãã«ãŸãã¯å³ããã¯ãªããããŒãã«ã³ããŒããŠãIP ExploreïŒNFSïŒSSHïŒã¢ãžã¥ãŒã«ãŠã£ã³ããŠã«è²Œãä»ããŸãã å®è¡ããŠçµæãæåŸ
ããŸãïŒ

ãã¡ãããç¬èªã®å€éšãµãŒããŒããã®åž¯åå¹
ãšãã¢ãžã¥ãŒã«ã³ãŒãã§å³å¯ã«èšå®ãããŠããã¿ã€ã ã¢ãŠããèæ
®ããå¿
èŠããããŸãã
çµæã¯è¡šã®åœ¢åŒã§ååŸãããŸãããç¶è¡ããŠè¡šã®çµæãShodanæ€çŽ¢ã®å®è¡çµæã®ã°ã©ããšçµåã§ããŸãã æåã¯ç¥èŠããã®ãå°ãé£ããã§ãããã
çµæãå«ãããŒãã«ã®èŠèŠå
å§ããŸãããã ãŠãŒã¶ãŒã¢ãžã¥ãŒã«ã®å®è¡ããã®å€ãæã€åã®ã»ãããæã€ããŒãã«ããããŸãã ãã ãã[ãªã¯ãšã¹ã]ãŠã£ã³ããŠã®[ã¹ããŒã]ãã¿ã³ã«æ³šæãæããšãéã¢ã¯ãã£ãã«ãªããŸãã ããŒãã«ã®ã°ã©ããžã®ãããã³ã°ã¯èšå®ãããŠããããèšå®ããå¿
èŠãããããã§ãã
ã¹ããŒã 1ïŒæè¯ã§ã¯ãªãïŒ
ã¢ãžã¥ãŒã«çµæããããŒãã«ãéããç¶æ
ã§ãå³äžé
ã«ãäœæãã³ãã¬ãŒãã®è¿œå ãã€ã³ã¿ãŒãã§ãŒã¹èŠçŽ ããããã¯ãªãã¯ãããšãäœæãã³ãã¬ãŒãããŠã£ã³ããŠã衚瀺ãããŸãã ããã§ã¯ãããŒãã«è¡ã®ã°ã©ããªããžã§ã¯ããžã®ãããã³ã°ãæå®ããããšãã§ããŸããèšäºã§ã¯ããã»ã¹ã詳现ã«èª¬æããŸãããYoutube ã®ãã©ãããã©ãŒã ãã£ãã«ã®ãªã³ã¯ã¯ãããè¡ãæ¹æ³ã瀺ããŸãã

ã°ã©ãã®ãã³ãã¬ãŒãïŒ

IPãDomainãªããžã§ã¯ãã¯Lampyreã«ãããNFSããã³Networkãªããžã§ã¯ããäœæããããšã«æ³šæããããšãéèŠã§ããåãªããžã§ã¯ãã«ã¯ããŠãŒã¶ãŒãããŒãã«ã®åããããããããå±æ§ããããŸããããã«ããªããžã§ã¯ãã¯ããã€ãã®å±æ§ãæã€ããšãã§ããŸããã°ã©ãã®é ç¹ãªããžã§ã¯ãã®ååã衚瀺ããããã«ãããã€ãã®å±æ§ïŒé ç¹ãã°ã©ãäžã§ããã£ã€ããïŒãéèŠã§ããããšãã°ãNFSãªããžã§ã¯ãã®å ŽåãNFSãã¹ãšã¹ããŒã¿ã¹ãšãã2ã€ã®å±æ§ãäœæãããããŒå±æ§ã¯NFSãã¹ã§ããå³åŽã®ãªããžã§ã¯ãã®ç»åãã¯ãªãã¯ããŠããªããžã§ã¯ãã«ã¢ã€ã³ã³ãå²ãåœãŠãããšãã§ããŸãããªããžã§ã¯ãã®å±æ§ãžã®åã®ããããã³ã°ããå®äºãããšãã¹ããŒã ãæ§ç¯ã§ããŸã-äžèšã®[ ã¹ããŒã ]ãã¿ã³ãã¢ã¯ãã£ãã«ãªããŸãã
ãã³ãã¬ãŒãããããŸããïŒ

è¡šã®ã°ã©ãã®ãã³ãã¬ãŒãã¯æ¬¡ã®ããã«æ§æãããŠããŸãã

«» â i2 (IBM i2 Analyst's Notebook) :

«» , : IP- IP- , , NFS , IP. ( ).
2

ãã§ã«è¯ãã â , IP- :

, , (csv) . , «» . «» , .
Shodan NFS Shodan search, add to active tab â :

:

Lampyre , ssh.
çµè«ã®ä»£ããã«-ååãå®æçã«NFSã®èšå®ã®æ£ç¢ºãã ãããã§ãã¯ããŠãã ããã