Beginner Pentester ToolkitïŒå
éšãããã¯ãŒã¯Pentestã§åœ¹ç«ã€äž»èŠããŒã«ã®çãèŠçŽã玹ä»ããŸãã ãããã®ããŒã«ã¯ãã§ã«ããŸããŸãªå°é家ã«ãã£ãŠç©æ¥µçã«äœ¿çšãããŠããããã誰ããèªåã®èœåãç¥ããå®å
šã«ç¿åŸããã®ã«åœ¹ç«ã¡ãŸãã

å
容ïŒ
Nmap
Nmap-ãããã¯ãŒã¯ãã¹ãã£ã³ããããã®ãªãŒãã³ãœãŒã¹ãŠãŒãã£ãªãã£ã¯ãã»ãã¥ãªãã£ã¬ãŒããšã·ã¹ãã 管çè
ã®éã§æã人æ°ã®ããããŒã«ã®1ã€ã§ãã äž»ã«ããŒãã¹ãã£ã³ã«äœ¿çšãããŸãããããã«ã倧éã®æçšãªæ©èœãåããŠãããããæ¬è³ªçã«ãNmapã¯ãããã¯ãŒã¯ç 究ã®
ã¹ãŒããŒããŒãã¹ã¿ãŒã«ãªããŸãã
Nmapã¯ãéããŠãã/éããŠããããŒãããã§ãã¯ããã ãã§ãªããéããŠããããŒããšãã®ããŒãžã§ã³ã§ãªãã¹ã³ããŠãããµãŒãã¹ãèå¥ã§ããŸãããŸããOSãç¹å®ããã®ã«åœ¹ç«ã€å ŽåããããŸãã Nmapã¯ãã¹ãã£ã³çšã®ã¹ã¯ãªãããµããŒããåããŠããŸãïŒNSE-Nmap Scripting EngineïŒã ã¹ã¯ãªããã䜿çšãããšãããŸããŸãªãµãŒãã¹ã®è匱æ§ã確èªããããšãã§ããŸãïŒãã¡ããããããã®ã¹ã¯ãªãããããå ŽåããŸãã¯ãã€ã§ãç¬èªã®ã¹ã¯ãªãããäœæã§ããå Žåãé€ãïŒããŸãã¯ãããŸããŸãªãµãŒãã¹ã®ãã¹ã¯ãŒãã調æŽã§ããŸãã
ãããã£ãŠãNmapã䜿çšãããšããããã¯ãŒã¯ã®è©³çŽ°ãªããããäœæãããããã¯ãŒã¯äžã®ãã¹ãã§å®è¡äžã®ãµãŒãã¹ã«é¢ããæ倧ã®æ
å ±ãååŸããããã€ãã®è匱æ§ãäºåã«ç¢ºèªã§ããŸãã Nmapã«ã¯æè»ãªã¹ãã£ã³èšå®ããããã¹ãã£ã³é床ãã¹ããªãŒã æ°ãã¹ãã£ã³ããã°ã«ãŒãæ°ãªã©ãèšå®ã§ããŸãã
å°èŠæš¡ãããã¯ãŒã¯ã®ã¹ãã£ã³ã«äŸ¿å©ã§ãåã
ã®ãã¹ãã®ã¹ãããã¹ãã£ã³ã«äžå¯æ¬ ã§ãã
é·æïŒ
- å°æ°ã®ãã¹ãã§è¿
éã«åäœããŸãã
- èšå®ã®æè»æ§-劥åœãªæéã§æãæçãªããŒã¿ãååŸã§ããããã«ãªãã·ã§ã³ãçµã¿åãããããšãã§ããŸãã
- 䞊åã¹ãã£ã³-ã¿ãŒã²ãããã¹ãã®ãªã¹ããã°ã«ãŒãã«åå²ãããåã°ã«ãŒãã1ã€ãã€ã¹ãã£ã³ãããã°ã«ãŒãå
ã§äžŠåã¹ãã£ã³ã䜿çšãããŸãã ãŸããã°ã«ãŒããžã®åå²ã¯å°ããªæ¬ ç¹ã§ãïŒä»¥äžãåç
§ïŒã
- ããŸããŸãªã¿ã¹ã¯çšã®å®çŸ©æžã¿ã®ã¹ã¯ãªããã»ãã-ç¹å®ã®ã¹ã¯ãªããã®éžæã«å€ãã®æéãè²»ããããšã¯ã§ããŸããããã¹ã¯ãªããã®ã°ã«ãŒããæå®ããŸãã
- åºåã¯ãXMLãå«ã5ã€ã®ç°ãªã圢åŒã§ãä»ã®ããŒã«ã«ã€ã³ããŒãã§ããŸãã
çæïŒ
- ãã¹ãã®ã°ã«ãŒãã®ã¹ãã£ã³-ãã¹ãã«é¢ããæ
å ±ã¯ãã°ã«ãŒãå
šäœã®ã¹ãã£ã³ãå®äºãããŸã§å©çšã§ããŸããã ããã¯ãè©Šè¡ãåæ¢ãããå¥ã®è©Šè¡ãè¡ãåã«èŠæ±ãžã®å¿çãäºæ³ããããªãã·ã§ã³ã§æ倧ã°ã«ãŒããµã€ãºãšæ倧æéééãèšå®ããããšã§è§£æ±ºãããŸãã
- ã¹ãã£ã³æã«ãNmapã¯SYNãã±ãããã¿ãŒã²ããããŒãã«éä¿¡ããå¿çããªãå Žåãå¿çãã±ãããŸãã¯ã¿ã€ã ã¢ãŠããåŸ
ã¡ãŸãã ããã¯ãéåæã¹ãã£ããŒïŒZmapãmasscanãªã©ïŒãšæ¯èŒããŠãã¹ãã£ããŒå
šäœã®ããã©ãŒãã³ã¹ã«æªåœ±é¿ãåãŒããŸãã
- ã¹ãã£ã³ãé«éåããããã«ãã©ã°ã䜿çšããŠå€§èŠæš¡ãªãããã¯ãŒã¯ãã¹ãã£ã³ããå ŽåïŒ--min-rateã-min-parallelismïŒããã¹ãäžã®éããŠããããŒããã¹ãããããŠãåœé°æ§ã®çµæãããããå¯èœæ§ããããŸãã ãŸãããã±ããã¬ãŒãã倧ãããšæå³ããªãDoSãçºçããå¯èœæ§ãããããããããã®ãªãã·ã§ã³ã¯æ³šæããŠäœ¿çšããŠãã ããã

Zmap
Zmap ïŒ
ZenMapãšæ··åããªãã§ãã ããïŒã¯ãNmapã®é«éãªä»£æ¿ãšããŠäœæããããªãŒãã³ãœãŒã¹ã®ã¹ãã£ããŒã§ããããŸãã
Nmapãšã¯ç°ãªã-SYNãã±ãããéä¿¡ãããšãã®Zmapã¯ãå¿çãè¿ããããŸã§åŸ
æ©ããŸãããããã¹ãŠã®ãã¹ãããã®å¿çãåŸ
æ©ããªããã¹ãã£ã³ãç¶è¡ãããããå®éã«ã¯æ¥ç¶ã¹ããŒã¿ã¹ããµããŒãããŸããã SYNãã±ãããžã®å¿çãå°çãããšãZmapã¯ãã±ããã®å
容ã«ãã£ãŠãã©ã®ããŒãããã³ã©ã®ãã¹ãã§éãããŠããããç解ããŸãã ããã«ãZmapã¯1ã€ã®SYNãã±ããã®ã¿ãã¹ãã£ã³å¯Ÿè±¡ã®ããŒãã«éä¿¡ããŸãã çªç¶10ã®ã¬ãããã€ã³ã¿ãŒãã§ã€ã¹ãšäºææ§ã®ãããããã¯ãŒã¯ã«ãŒããæå
ã«ããå ŽåãPF_RINGã䜿çšããŠå€§èŠæš¡ãªãããã¯ãŒã¯ããã°ããã¹ãã£ã³ããããšãã§ããŸãã
é·æïŒ
- ã¹ãã£ã³é床ã
- Zmapã¯ãTCP / IPã·ã¹ãã ã¹ã¿ãã¯ããã€ãã¹ããŠã€ãŒãµããããã¬ãŒã ãçæããŸãã
- PF_RINGã䜿çšããæ©èœã
- ZMapã¯ãã¹ãã£ã³ãããåŽã®è² è·åæ£ãåçã«ããããã«ã¿ãŒã²ãããã©ã³ãã åããŸãã
- ZGrabïŒã¢ããªã±ãŒã·ã§ã³ã¬ãã«L7ã§ãµãŒãã¹ã«é¢ããæ
å ±ãåéããããã®ããŒã«ïŒãšçµ±åããæ©èœã
çæïŒ
- ãã¹ãŠã®ãã±ããã1ã€ã®ã«ãŒã¿ãŒãééãããããåæ£è² è·ã«ããããããããããã¯ãŒã¯æ©åšã®ãµãŒãã¹æåŠãåŒãèµ·ããå¯èœæ§ããããŸããããšãã°ãäžéã«ãŒã¿ãŒãç¡å¹ã«ããŸãã

ãã¹ã«ã³
Masscan- é©ãã¹ãããšã«ãã€ã³ã¿ãŒããããããã«é«éã«ã¹ãã£ã³ããããã«äœæããããªãŒãã³ãœãŒã¹ã¹ãã£ããŒã§ããããŸãïŒ6åæªæºã§æ倧1,000äžãã±ãã/ç§ã®é床ïŒã å®éãZmapãšã»ãŒåãããã«åäœããŸãããããã«é«éã§ãã
é·æïŒ
- æ§æã¯Nmapã«äŒŒãŠãããããã°ã©ã ã¯Nmapäºæã®ãªãã·ã§ã³ããµããŒãããŠããŸãã
- é床ã¯æéã®éåæã¹ãã£ããŒã®1ã€ã§ãã
- æè»ãªã¹ãã£ã³ã¡ã«ããºã -äžæãããã¹ãã£ã³ã®åéãè€æ°ã®ããã€ã¹ãžã®è² è·ã®åæ£ïŒZmapãªã©ïŒã
çæïŒ
- Zmapãšåæ§ã«ããããã¯ãŒã¯èªäœã®è² è·ã¯éåžžã«é«ããDoSã«ã€ãªããå¯èœæ§ããããŸãã
- ããã©ã«ãã§ã¯ãã¢ããªã±ãŒã·ã§ã³ã¬ãã«L7ã§ã¹ãã£ã³ããããšã¯ã§ããŸããã

ãããœã¹
Nessusã¯ãã·ã¹ãã å
ã®æ¢ç¥ã®è匱æ§ã®æ€èšŒãšæ€åºãèªååããããã®ã¹ãã£ããŒã§ãã ãœãŒã¹ã³ãŒãã¯éããããŠããŸããNessusHomeã®ç¡æããŒãžã§ã³ããããææããŒãžã§ã³ãšåãé床ãšè©³çŽ°ãªåæã§æ倧16åã®IPã¢ãã¬ã¹ãã¹ãã£ã³ã§ããŸãã
ãµãŒãã¹ãŸãã¯ãµãŒããŒã®è匱ãªããŒãžã§ã³ãç¹å®ããã·ã¹ãã æ§æã®ãšã©ãŒãæ€åºãããã«ãŒããã©ãŒã¹èŸæžã®ãã¹ã¯ãŒããå®è¡ã§ããŸãã PCI DSSç£æ»ã®æºåãšåæ§ã«ããµãŒãã¹èšå®ïŒã¡ãŒã«ãæŽæ°ãªã©ïŒã®æ£ç¢ºããå€æããããã«äœ¿çšã§ããŸãã ããã«ãNessusã¯ãã¹ãè³æ Œæ
å ±ïŒSSHãŸãã¯Active Directoryã®ãã¡ã€ã³ã¢ã«ãŠã³ãïŒã転éã§ããã¹ãã£ããŒã¯ãã¹ãã«ã¢ã¯ã»ã¹ãããã¹ãã§çŽæ¥ãã§ãã¯ãå®è¡ããŸãããã®ãªãã·ã§ã³ã¯
è³æ Œæ
å ±ã¹ãã£ã³ãšåŒã°ã
ãŸã ã èªç€Ÿã®ãããã¯ãŒã¯ã®ç£æ»ãè¡ãäŒæ¥ã«ãšã£ãŠäŸ¿å©ã§ãã
é·æïŒ
- ããŒã¹ã絶ããæŽæ°ãããè匱æ§ããšã«åå¥ã®ã·ããªãªã
- åºå-ãã¬ãŒã³ããã¹ããXMLãHTMLãããã³LaTeXã
- API Nessus-ã¹ãã£ã³ããã³çµæååŸã®ããã»ã¹ãèªååã§ããŸãã
- è³æ Œæ
å ±ã¹ãã£ã³ïŒWindowsãŸãã¯Linuxã®è³æ Œæ
å ±ã䜿çšããŠãæŽæ°ããã°ã©ã ããã®ä»ã®è匱æ§ã確èªã§ããŸãã
- ç¬èªã®çµã¿èŸŒã¿ã»ãã¥ãªãã£ã¢ãžã¥ãŒã«ãäœæããæ©èœ-ã¹ãã£ããŒã«ã¯ç¬èªã®ã¹ã¯ãªããèšèªNASLïŒNessus Attack Scripting LanguageïŒããããŸãã
- ããŒã«ã«ãããã¯ãŒã¯ã®å®æã¹ãã£ã³ã®æéãèšå®ã§ããŸããããã«ãããæ
å ±ã»ãã¥ãªãã£ãµãŒãã¹ã¯ãã»ãã¥ãªãã£æ§æã®ãã¹ãŠã®å€æŽãæ°ãããã¹ãã®åºçŸãèŸæžãã¹ã¯ãŒããŸãã¯ããã©ã«ããã¹ã¯ãŒãã®äœ¿çšãèªèããŸãã
çæïŒ
- ã¹ãã£ã³ãããã·ã¹ãã ã®åäœã«ç°åžžãããå¯èœæ§ããããŸã-ã»ãŒããã§ãã¯ãªãã·ã§ã³ãç¡å¹ã«ããå Žåãæ
éã«äœæ¥ããå¿
èŠããããŸãã
- åçšçã¯ç¡æã§ã¯ãããŸããã

Netcreds
Net-Credsã¯ããã¹ã¯ãŒããšããã·ã¥ãããã³èšªåããURLãããŠã³ããŒããããã¡ã€ã«ããã®ä»ã®äº€éæ
å ±ãªã©ã®æ
å ±ããMiTMæ»æäžã«ãªã¢ã«ã¿ã€ã ã§ãããã³ä»¥åã«ä¿åããPCAPãã¡ã€ã«ããåéããããã®PythonããŒã«ã§ãã æéãéãããŠããMiTMãããã¯ãŒã¯æ»ææãªã©ã倧éã®ãã©ãã£ãã¯ã®è¿
éãã€è¡šé¢çãªåæã«é©ããŠãããWiresharkã䜿çšããæååæã«ã¯å€ãã®æéãå¿
èŠã§ãã
é·æïŒ
- ãµãŒãã¹ã®èå¥ã¯ã䜿çšãããããŒãã®æ°ã«ãã£ãŠãµãŒãã¹ã決å®ãã代ããã«ããã±ããã®åæã«åºã¥ããŠããŸãã
- 䜿ããããã
- FTPãPOPãIMAPãSMTPãNTLMv1 / v2ãããã³ã«ã®ãã°ã€ã³ãšãã¹ã¯ãŒããããã³ãã°ã€ã³ãã©ãŒã ãåºæ¬èªèšŒãªã©ã®HTTPãªã¯ãšã¹ãããã®æ
å ±ãå«ããå¹
åºãååŸããŒã¿ã

ãããã¯ãŒã¯ãã€ããŒ
network-minerã¯ãåäœåçã«ããNet-Credsã®é¡äŒŒç©ã§ãããåªããæ©èœãåããŠããŸããããšãã°ãSMBãããã³ã«çµç±ã§éä¿¡ããããã¡ã€ã«ãæœåºã§ããŸãã Net-Credsãšåæ§ã«ã倧éã®ãã©ãã£ãã¯ããã°ããåæããå¿
èŠãããå Žåã«äŸ¿å©ã§ãã 䟿å©ãªã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ãåããŠããŸãã
é·æïŒ
- ã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ã
- ã°ã«ãŒãã«ããããŒã¿ã®èŠèŠåãšåé¡-ãã©ãã£ãã¯åæãç°¡çŽ åããé«éåããŸãã
çæïŒ
- è©Šçšçã«ã¯ããã€ãã®æ©èœããããŸãã

mitm6
mitm6ã¯ãIPv6ïŒSLAACæ»æïŒã«å¯Ÿããæ»æãå®è¡ããããã®ããŒã«ã§ãã IPv6ã¯WindowsïŒäžè¬çã«ã¯ä»ã®OSã§ãïŒã®åªå
é äœã§ãããIPv6ã€ã³ã¿ãŒãã§ã€ã¹ã¯ããã©ã«ãæ§æã§æå¹ã«ãªã£ãŠããŸããããã«ãããæ»æè
ã¯ã«ãŒã¿ãŒã¢ããã¿ã€ãºã¡ã³ããã±ããã䜿çšããŠè¢«å®³è
ã«ç¬èªã®DNSãµãŒããŒãèšå®ã§ããŸãããã®åŸãæ»æè
ã¯è¢«å®³è
ã®DNSã亀æã§ããŸãã ntlmrelayxãŠãŒãã£ãªãã£ã䜿çšããŠãªã¬ãŒæ»æãè¡ãã®ã«æé©ã§ããããã«ãããWindowsãããã¯ãŒã¯ãæ£åžžã«æ»æã§ããŸãã
é·æïŒ
- Windowsãã¹ããšãããã¯ãŒã¯ã®æšæºæ§æã®ããã«ãå€ãã®ãããã¯ãŒã¯ã§ããŸãæ©èœããŸãã
å¿ç
ã¬ã¹ãã³ããŒã¯ããããŒããã£ã¹ãåå解決ãããã³ã«ïŒLLMNRãNetBIOSãMDNSïŒãã¹ããŒãã£ã³ã°ããããã®ããŒã«ã§ãã Active Directoryãããã¯ãŒã¯ã«äžå¯æ¬ ãªããŒã«ã ãªãããŸãã«å ããŠãNTLMèªèšŒãååã§ããŸãããŸããæ
å ±ãåéããNTLMãªã¬ãŒæ»æãå®è£
ããããã®ããŒã«ã»ãããä»å±ããŠããŸãã
é·æïŒ
- ããã©ã«ãã§ã¯ãNTLMèªèšŒããµããŒãããå€ãã®ãµãŒããŒãçºçããŸãïŒSMBãMSSQLãHTTPãHTTPSãLDAPãFTPãPOP3ãIMAPãSMTPã
- MITMæ»æïŒARPã¹ããŒãã£ã³ã°ãªã©ïŒã®å Žåã«DNSã眮ãæããããšãã§ããŸãã
- ãããŒããã£ã¹ããªã¯ãšã¹ããè¡ã£ããã¹ãã®æçŽã
- åæã¢ãŒã-èŠæ±ã®ååçãªç£èŠçšã
- NTLMèªèšŒããã·ã¥ã€ã³ã¿ãŒã»ãã圢åŒã¯ãJohn the Ripperããã³Hashcatãšäºææ§ããããŸãã
çæïŒ
- Windowsã§å®è¡ããå ŽåãããŒã445ãã€ã³ãïŒSMBïŒã«ã¯ããã€ãã®å°é£ã䌎ããŸãïŒå¯Ÿå¿ãããµãŒãã¹ãåæ¢ããŠåèµ·åããå¿
èŠããããŸãïŒã


Evil_Foca
Evil Focaã¯ãIPv4ããã³IPv6ãããã¯ãŒã¯ã«å¯ŸããããŸããŸãªãããã¯ãŒã¯æ»æããã§ãã¯ããããã®ããŒã«ã§ãã ããŒã«ã«ãããã¯ãŒã¯ãã¹ãã£ã³ããããã€ã¹ãã«ãŒã¿ãŒãããã³ãããã®ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ãèå¥ããŸãããã®åŸããããã¯ãŒã¯åå è
ã«å¯ŸããŠããŸããŸãªæ»æãå®è¡ããããšãå¯èœã§ãã
é·æïŒ
- MITMæ»æïŒARPã¹ããŒãã£ã³ã°ãDHCP ACKã€ã³ãžã§ã¯ã·ã§ã³ãSLAACæ»æãDHCPã¹ããŒãã£ã³ã°ïŒã«äŸ¿å©ã
- DoSæ»æãè¡ãããšãã§ããŸã-IPv4ãããã¯ãŒã¯ã®ARPã¹ããŒãã£ã³ã°ãIPv6ãããã¯ãŒã¯ã®SLAAC DoSã
- DNSãã€ãžã£ãã¯ãå®è£
ã§ããŸãã
- 䜿ããããããŠãŒã¶ãŒãã¬ã³ããªãŒãªã°ã©ãã£ã«ã«ã€ã³ã¿ãŒãã§ã€ã¹ã
çæïŒ
- Windowsã§ã®ã¿æ©èœããŸãã

ãã¿ãŒãã£ãã
Bettercapã¯ããããã¯ãŒã¯ãåæããŠæ»æããããã®åŒ·åãªãã¬ãŒã ã¯ãŒã¯ã§ããããã§ã¯ãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãžã®æ»æãBLEïŒBluetooth Low EnergyïŒãããã«ã¯ã€ã€ã¬ã¹HIDããã€ã¹ãžã®MouseJackæ»æã«ã€ããŠã説æããŠããŸãã ããã«ããã©ãã£ãã¯ããæ
å ±ãåéããæ©èœãå«ãŸããŠããŸãïŒnet-credsãšåæ§ïŒã äžè¬çã«ãã¹ã€ã¹ã®ãã€ãïŒ1ã€ã«ãã¹ãŠïŒã æè¿ã§ã¯ã
ã°ã©ãã£ã«ã«ãªWebããŒã¹ã®ã€ã³ã¿ãŒãã§ã€ã¹ããŸã ãã
ãŸã ã
é·æïŒ
- è³æ Œæ
å ±ã¹ããã¡ãŒ-蚪åããURLãšHTTPSãã¹ããHTTPèªèšŒãããŸããŸãªãããã³ã«ã䜿çšããè³æ Œæ
å ±ããã£ããã§ããŸãã
- å€ãã®çµã¿èŸŒã¿MITMæ»æã
- ã¢ãžã¥ã©ãŒHTTPïŒSïŒééãããã·-ããŒãºã«å¿ããŠãã©ãã£ãã¯ãå¶åŸ¡ã§ããŸãã
- ãã«ãã€ã³HTTPãµãŒããŒ
- capletsã®ãµããŒã-ã¹ã¯ãªããèšèªã§è€éã§èªååãããæ»æãèšè¿°ããããšãã§ãããã¡ã€ã«ã
çæïŒ
- äžéšã®ã¢ãžã¥ãŒã«ïŒããšãã°ãble.enumïŒã¯macOSããã³Windowsã§éšåçã«ãµããŒããããŠããŸãããäžéšã®ã¢ãžã¥ãŒã«ã¯Linuxå°çšã«èšèšãããŠããŸã-packet.proxy

gateway_finder
ã²ãŒããŠã§ã€ãã¡ã€ã³ã㌠-ãããã¯ãŒã¯äžã®ã²ãŒããŠã§ã€ã®å¯èœæ§ãèå¥ããã®ã«åœ¹ç«ã€Pythonã¹ã¯ãªããã ã»ã°ã¡ã³ããŒã·ã§ã³ããã§ãã¯ããããå¿
èŠãªãµãããããŸãã¯ã€ã³ã¿ãŒãããã«ã«ãŒãã£ã³ã°ã§ãããã¹ããæ€çŽ¢ããã®ã«äŸ¿å©ã§ãã äžæ£ãªã«ãŒããŸãã¯ä»ã®å
éšLANãžã®ã«ãŒãããã°ãããã§ãã¯ããå¿
èŠãããå Žåãå
éšã®ãã³ãã¹ãã«é©ããŠããŸãã
é·æïŒ
- 䜿ãããããã«ã¹ã¿ãã€ãºããŸãã

mitmproxy
mitmproxyã¯ãSSL / TLSã§ä¿è·ããããã©ãã£ãã¯ãåæããããã®ãªãŒãã³ãœãŒã¹ããŒã«ã§ãã mitmproxyã¯ãä¿è·ããããã©ãã£ãã¯ãååããã³å€æŽããã®ã«äŸ¿å©ã§ãããããã€ãã®æ³šæäºé
ããããŸãã ãã®ããŒã«ã¯ãSSL / TLSã®åŸ©å·åã«å¯Ÿããæ»æãå®è¡ããŸããã SSL / TLSã§ä¿è·ããããã©ãã£ãã¯ã®å€åãååããŠèšé²ããå¿
èŠãããå Žåã«äœ¿çšãããŸãã ããã¯ãMitmproxy-ãã©ãã£ãã¯ãããã·çšãmitmdump-tcpdumpã«äŒŒãŠããŸãããHTTPïŒSïŒãã©ãã£ãã¯çšãããã³mitmweb-Mitmproxyçšã®Webã€ã³ã¿ãŒãã§ã€ã¹ã§æ§æãããŠããŸãã
é·æïŒ
- ããŸããŸãªãããã³ã«ã§åäœããHTMLããProtobufãŸã§ã®ããŸããŸãªåœ¢åŒã®å€æŽããµããŒãããŠããŸãã
- API for Python-éæšæºã¿ã¹ã¯çšã®ã¹ã¯ãªãããäœæã§ããŸãã
- ãã©ãã£ãã¯ä»£è¡åä¿¡ã䜿çšããééãããã·ã¢ãŒãã§åäœã§ããŸãã
çæïŒ
- ãã³ã圢åŒã¯äœãšãäºææ§ããããŸãã-grepã䜿çšããã®ã¯é£ãããã¹ã¯ãªãããäœæããå¿
èŠããããŸãã


ã·ãŒã
SIETã¯ãCisco Smart Installãããã³ã«ã®æ©èœã掻çšããããã®ããŒã«ã§ãã èšå®ãååŸããã³å€æŽããããCiscoããã€ã¹ãå¶åŸ¡ãããããããšãã§ããŸãã Ciscoããã€ã¹ã®æ§æãååŸã§ããå Žåã
CCATã䜿çšããŠæ€èšŒã§ããŸãããã®ããŒã«ã¯ãCiscoããã€ã¹ã®æ§æã®ã»ãã¥ãªãã£ãåæããã®ã«åœ¹ç«ã¡ãŸãã
é·æïŒ
Cisco Smart Installãããã³ã«ã䜿çšãããšã次ã®ããšãã§ããŸãã
- 1ã€ã®æªãã TCPãã±ãããéä¿¡ããŠãã¯ã©ã€ã¢ã³ãããã€ã¹äžã®tftpãµãŒããŒã®ã¢ãã¬ã¹ãå€æŽããŸãã
- ããã€ã¹æ§æãã¡ã€ã«ãã³ããŒããŸãã
- ããã€ã¹æ§æã眮ãæããŸããããšãã°ãæ°ãããŠãŒã¶ãŒãè¿œå ããŸãã
- ããã€ã¹ã®iOSã€ã¡ãŒãžãæŽæ°ããŸãã
- ããã€ã¹ã§ã³ãã³ãã®ä»»æã®ã»ãããå®è¡ããŸãã ããã¯ãããŒãžã§ã³3.6.0Eããã³15.2ïŒ2ïŒE iOSã§ã®ã¿æ©èœããæ°ããæ©èœã§ãã
çæïŒ
- éãããã·ã¹ã³ããã€ã¹ã®ã»ããã§åäœããŸãããŸããããã€ã¹ããå¿çãåä¿¡ããã«ã¯ããã¯ã€ããIPãå¿
èŠã§ãããŸãã¯ãããã€ã¹ãšåããããã¯ãŒã¯äžã«ããå¿
èŠããããŸãã

ãšã«ã·ãã¢
yersiniaã¯ãããŸããŸãªL2ãããã¯ãŒã¯ãããã³ã«ã®ã»ãã¥ãªãã£äžã®æ¬ é¥ãæªçšããããã«èšèšãããL2æ»æã®ãã¬ãŒã ã¯ãŒã¯ã§ãã
é·æïŒ
- ãããã³ã«STPãCDPãDTPãDHCPãHSRPãVTPãªã©ã«å¯Ÿããæ»æãèš±å¯ããŸãã
çæïŒ
- æã䟿å©ãªã€ã³ã¿ãŒãã§ã€ã¹ã§ã¯ãããŸããã

ãããã·ãã§ãŒã³
proxychainsã¯ãæå®ããSOCKSãããã·ãä»ããŠã¢ããªã±ãŒã·ã§ã³ãã©ãã£ãã¯ããªãã€ã¬ã¯ãã§ããããŒã«ã§ãã
é·æïŒ
- ããã©ã«ãã§ã¯ããããã·ã®æäœæ¹æ³ãããããªãäžéšã®ã¢ããªã±ãŒã·ã§ã³ã«ãã©ãã£ãã¯ããªãã€ã¬ã¯ãã§ããŸãã

ãã®èšäºã§ã¯ãPentestå
éšãããã¯ãŒã¯ã®åºæ¬ããŒã«ã®é·æãšçæãç°¡åã«èª¿ã¹ãŸããã ãŠã§ããããŒã¿ããŒã¹ãã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ãªã©ã®ã³ã¬ã¯ã·ã§ã³ãããã«ã¢ããããŒãããäºå®ã§ããããã«ã€ããŠã説æããŸãã
ã³ã¡ã³ãã§ãæ°ã«å
¥ãã®ãŠãŒãã£ãªãã£ãå
±æããŠãã ããïŒ