|
Ä¿ÇÇÇâÀÌ ³ª´Â *NIX
Ä¿ÇǴнº
½Ã½ºÅÛ/³×Æ®¿÷/º¸¾ÈÀ» ´Ù·ç´Â °÷
|
|
|
|
ÀÌÀü ÁÖÁ¦ º¸±â :: ´ÙÀ½ ÁÖÁ¦ º¸±â |
±Û¾´ÀÌ |
¸Þ½ÃÁö |
truefeel Ä«Æä °ü¸®ÀÚ
°¡ÀÔ: 2003³â 7¿ù 24ÀÏ ¿Ã¸° ±Û: 1277 À§Ä¡: ´ëÇѹα¹
|
¿Ã·ÁÁü: 2005.10.15 Åä, 2:50 pm ÁÖÁ¦: ²Ï³ª ±¦ÂúÀº OS fingerprinting Åø Xprobe2 |
|
|
Xprobe2´Â nmap ó·³ ¿ø°ÝÁö¿¡¼ OSÀÇ Á¾·ù¸¦ ¾Ë¾Æ³»´Â OS fingerprinting ÅøÀÔ´Ï´Ù.
Ofir ArkinÀÇ 'ICMP Usage In Scanning Research project' ¸¦ ±â¹ÝÀ¸·Î ÇØ¼ ¸¸µé¾îÁ³À¸¸ç
ping(ICMP, TCP, UDP), TTL°ª, Æ÷Æ®½ºÄµ, ICMP ÇÁ·ÎÅäÄÝ, SMB, SNMP ¸ðµâÀ» »ç¿ëÇÏ¿© OS¸¦ ÃßÁ¤ÇÕ´Ï´Ù.
¸®´ª½ºÀÇ Ä¿³Î¹öÀüÀÌ Æ²¸®°Å³ª, °°Àº ¼¹ö¿¡ ´ëÇØ¼µµ ´Ù¸¥ OS·Î Ç¥½ÃÇÏ´Â °æ¿ì µîÀÇ ¹®Á¦µµ ÀÖ¾úÁö¸¸
nmap°ú º¸¿ÏÀûÀ¸·Î »ç¿ëÇϸé ÁÁÀ» µí ½Í½À´Ï´Ù.
±×¸®°í, nmap °³¹ßÀÚ Fyodor¿Í Xprobe2 °³¹ßÀÚ Áß ÇѸíÀÎ Fyodor´Â µ¿¸íÀÌÀÎÀΰɷΠ¾Ð´Ï´Ù.
Àοë: |
# xprobe2 ????.???
Xprobe2 v.0.3 Copyright (c) 2002-2005 fyodor_o0o.nu, ofir_sys-security.com, meder_o0o.nu
[+] Target is ????.???
[+] Loading modules.
[+] Following modules are loaded:
[x] [1] ping:icmp_ping - ICMP echo discovery module
[x] [2] ping:tcp_ping - TCP-based ping discovery module
[x] [3] ping:udp_ping - UDP-based ping discovery module
[x] [4] infogather:ttl_calc - TCP and UDP based TTL distance calculation
[x] [5] infogather:portscan - TCP and UDP PortScanner
[x] [6] fingerprint:icmp_echo - ICMP Echo request fingerprinting module
[x] [7] fingerprint:icmp_tstamp - ICMP Timestamp request fingerprinting module
[x] [8] fingerprint:icmp_amask - ICMP Address mask request fingerprinting module
[x] [9] fingerprint:icmp_port_unreach - ICMP port unreachable fingerprinting module
[x] [10] fingerprint:tcp_hshake - TCP Handshake fingerprinting module
[x] [11] fingerprint:tcp_rst - TCP RST fingerprinting module
[x] [12] fingerprint:smb - SMB fingerprinting module
[x] [13] fingerprint:snmp - SNMPv2c fingerprinting module
[+] 13 modules registered
[+] Initializing scan engine
[+] Running scan engine
[-] ping:tcp_ping module: no closed/open TCP ports known on xxx.yyy.zz.???. Module test failed
[-] ping:udp_ping module: no closed/open UDP ports known on xxx.yyy.zz.???. Module test failed
[-] No distance calculation. xxx.yyy.zz.??? appears to be dead or no ports known
[+] Host: xxx.yyy.zz.??? is up (Guess probability: 50%)
[+] Target: xxx.yyy.zz.??? is alive. Round-Trip Time: 0.00758 sec
[+] Selected safe Round-Trip Time value is: 0.01517 sec
[-] fingerprint:tcp_hshake Module execution aborted (no open TCP ports known)
[-] fingerprint:smb need either TCP port 139 or 445 to run
[-] fingerprint:snmp: need UDP port 161 open
[+] Primary guess:
[+] Host xxx.yyy.zz.??? Running OS: "Linux Kernel 2.6.11" (Guess probability: 96%)
[+] Other guesses:
[+] Host xxx.yyy.zz.??? Running OS: "Linux Kernel 2.6.10" (Guess probability: 96%)
[+] Host xxx.yyy.zz.??? Running OS: "Linux Kernel 2.6.9" (Guess probability: 96%)
[+] Host xxx.yyy.zz.??? Running OS: "Linux Kernel 2.6.8" (Guess probability: 96%)
[+] Host xxx.yyy.zz.??? Running OS: "Linux Kernel 2.6.7" (Guess probability: 96%)
[+] Host xxx.yyy.zz.??? Running OS: "Linux Kernel 2.6.6" (Guess probability: 96%)
[+] Host xxx.yyy.zz.??? Running OS: "Linux Kernel 2.6.5" (Guess probability: 96%)
[+] Host xxx.yyy.zz.??? Running OS: "Linux Kernel 2.6.4" (Guess probability: 96%)
[+] Host xxx.yyy.zz.??? Running OS: "Linux Kernel 2.6.3" (Guess probability: 96%)
[+] Host xxx.yyy.zz.??? Running OS: "Linux Kernel 2.6.2" (Guess probability: 96%)
[+] Cleaning up scan engine
[+] Modules deinitialized
[+] Execution completed.
|
xprobe2´Â http://www.sys-security.com/ ¿¡¼ ¹ÞÀ» ¼ö ÀÖ½À´Ï´Ù.
[ °ü·Ã Á¤º¸ ]
- http://coffeenix.net/?cata_code=123 ( º¸¾È(security) > ¿ø°Ý OS ŽÁö / OS ÇΰÅÇÁ¸°ÆÃ )
- http://coffeenix.net/board_view.php?bd_code=111 (Æ÷Æ® ½ºÄ³´× °¨½Ã ¹× OS Á¤º¸ ¼û±â±â, ±Û ÁÁÀºÁøÈ£)
- http://www.insecure.org/nmap/ (nmap) |
|
À§·Î |
|
 |
|
|
»õ·Î¿î ÁÖÁ¦¸¦ ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù ´ä±ÛÀ» ¿Ã¸± ¼ö ÀÖ½À´Ï´Ù ÁÖÁ¦¸¦ ¼öÁ¤ÇÒ ¼ö ¾ø½À´Ï´Ù ¿Ã¸° ±ÛÀ» »èÁ¦ÇÒ ¼ö ¾ø½À´Ï´Ù ÅõÇ¥¸¦ ÇÒ ¼ö ¾ø½À´Ï´Ù
|
Powered by phpBB © 2001, 2005 phpBB Group
|