Start Nessus on Linux โ€“ 2 Nessus Scanning ๐Ÿ•ต๐Ÿปโ€โ™‚๏ธ

2023-03-20ยท1๋ถ„ ์ฝ๊ธฐยท

Start Nessus on Linux โ€“ 2 Nessus Scanning ๐Ÿ•ต๐Ÿปโ€โ™‚๏ธ

Start Nessus on Linux โ€“ 2 Nessus Scanning ๐Ÿ•ต๐Ÿปโ€โ™‚๏ธ ์Šค์บ๋‹ ํ…œํ”Œ๋ฆฟ Target ์ง€์ • ์Šค์บ” ์‹œ์ž‘ ๋กœ๊ทธ ํ™•์ธ ๊ฒฐ๊ณผ ํ™•์ธ Nessus ์ทจ์•ฝ์  ์Šค์บ๋„ˆ ๋‹ค์šด๋กœ๋“œ ์ดํ›„ ์ทจ์•ฝ์  ์Šค์บ๋‹ ๋ฐฉ๋ฒ•์„ ๊ณต์œ ํ•ฉ๋‹ˆ๋‹ค. ! ์ฃผ์˜ Scanning ์‹œ๋„๋Š” ํ—ˆ๊ฐ€๋˜์ง€ ์•Š์€ ์‹œ์Šคํ…œ์—์„œ ์ง„ํ–‰ํ•˜๋ฉด ์•ˆ๋˜๋ฉฐ, Scan ๊ฐ„ ํŠธ๋ž˜ํ”ฝ ๋ฐœ์ƒ์ด ๊ฐ€๋Šฅํ•ด ์‚ฌ์ „์— ํ—ˆ๊ฐ€ ๋ฐ›์€ ์‹œ์Šคํ…œ

Start Nessus on Linux โ€“ 2 Nessus Scanning ๐Ÿ•ต๐Ÿปโ€โ™‚๏ธ

Nessus ์ทจ์•ฝ์  ์Šค์บ๋„ˆ ๋‹ค์šด๋กœ๋“œ ์ดํ›„ ์ทจ์•ฝ์  ์Šค์บ๋‹ ๋ฐฉ๋ฒ•์„ ๊ณต์œ ํ•ฉ๋‹ˆ๋‹ค.

! ์ฃผ์˜

Scanning ์‹œ๋„๋Š” ํ—ˆ๊ฐ€๋˜์ง€ ์•Š์€ ์‹œ์Šคํ…œ์—์„œ ์ง„ํ–‰ํ•˜๋ฉด ์•ˆ๋˜๋ฉฐ,

Scan ๊ฐ„ ํŠธ๋ž˜ํ”ฝ ๋ฐœ์ƒ์ด ๊ฐ€๋Šฅํ•ด ์‚ฌ์ „์— ํ—ˆ๊ฐ€ ๋ฐ›์€ ์‹œ์Šคํ…œ ํ˜น์€ ์ž์ฒด ์‹œ์Šคํ…œ์—์„œ ์ง„ํ–‰ํ•ด์•ผ ํ•œ๋‹ค.

  • Nessus ๋กœ๊ทธ์ธ

๋กœ๊ทธ์ธ -> ํŽ˜์ด์ง€ ์šฐ์ธก ์ƒ๋‹จ New Scan ๋ฒ„ํŠผ ํด๋ฆญ (์‹ ๊ทœ ์Šค์บ๋‹ ๊ทœ์น™ ์ƒ์„ฑ)

  • ํƒ์ง€ ๊ทœ์น™ ์„ ํƒ

New Scan์—์„œ๋Š” ์Šค์บ๋‹ ๋Œ€์ƒ์— ๋”ฐ๋ฅธ ์ทจ์•ฝ์  ์Šค์บ๋‹์ด ๊ฐ€๋Šฅํ•˜๋ฉฐ ๊ธฐ๋ณธ์œผ๋กœ ์ œ๊ณต๋˜๋Š” ์ทจ์•ฝ์  ์Šค์บ๋‹ ํ…œํ”Œ๋ฆฟ์€ ์•„๋ž˜์™€ ๊ฐ™๋‹ค.

  • ์Šค์บ๋‹ ํ…œํ”Œ๋ฆฟ
  1. Basic Network Scan
  2. Advanced Scan
  3. Advanced Dynamic Scan
  4. Malware Scan
  5. Web Application Tests
  6. Credentialed Patch Audit
  7. Intel AMT Security Bypass
  8. Spectre and Meltdown
  9. WannaCry Ransomware
  10. Ripple20 Remote Scan
  11. Zerologon Remote Scan
  12. Soloriagte
  13. ProxyLogon : MS Exchange
  14. PrintNightmare
  15. Active Directory Starter Scan
  16. Log4Shell
  17. Log4Shell Remote Checks
  18. Log4Shell Vulnerability Ecosystem
  19. 2021 Threat Landscape Retrospective (TLR)
  20. CISA Alerts AA22-011A and AA22-047A
  21. ContiLeaks
  22. Ransomware Ecosystem

๋‹ค์–‘ํ•œ ์ทจ์•ฝ์  ์Šค์บ๋‹ ํ…œํ”Œ๋ฆฟ์„ ํ™œ์šฉํ•˜์—ฌ ์Šค์บ๋‹ ์ง„ํ–‰์ด ๊ฐ€๋Šฅํ•˜๋ฉฐ ๊ฐ๊ฐ์˜ ํ…œํ”Œ๋ฆฟ ๋‚ด ํ”Œ๋Ÿฌ๊ทธ์ธ์„ ์„ค์น˜ํ•˜์—ฌ ์ƒ์„ธํ•œ ์Šค์บ๋‹์ด ๊ฐ€๋Šฅํ•˜๋‹ค.

  • Target ์ง€์ •

ํ•„์ž๋Š” VMํ™˜๊ฒฝ๋‚ด Apache Server๋ฅผ ๋„์›Œ ๋†“์€ ์ƒํƒœ๋กœ Basic Network Scan ํ…œํ”Œ๋ฆฟ์„ ํ™œ์šฉํ•˜์—ฌ ์Šค์บ๋‹์„ ์‹œ๋„ํ•˜์˜€๋‹ค.

Name, Description, Target IP๋ฅผ ๋„ฃ์–ด์ฃผ๊ณ  ํ•„์š” ์‹œ ๋ณด์ด๋Š” ์ถ”๊ฐ€ ์„ค์ •์„ ํ™œ์šฉํ•ด ๊ณ ๊ธ‰ ์„ค์ •, ํ”Œ๋Ÿฌ๊ทธ์ธ ํ™œ์šฉ ๋“ฑ์˜ ์‚ฌ์šฉ์ด ๊ฐ€๋Šฅํ•˜๋‹ค.

์„ค์ •์„ ์ €์žฅํ•˜์—ฌ ์Šค์บ๋‹ ์ค€๋น„๊ฐ€ ๋๋‚ฌ๋‹ค. Launch (โ–น) ๋ฒ„ํŠผ์„ ํด๋ฆญํ•˜์—ฌ ์Šค์บ๋‹์„ ์‹œ์ž‘ํ•˜์ž.

  • Scanning

์Šค์บ” ์‹œ์ž‘

์Šค์บ” ์‹œ์ž‘ ์‹œ Attacker IP์ธ 192.168.35.141 ์—์„œ ๋‹ค์–‘ํ•œ ์ทจ์•ฝ์  ์Šค์บ๋‹ ์‹œ๋„๊ฐ€ Victim (192.168.35.133) Apache VM Server ์„œ๋ฒ„์˜ Apache log ์—์„œ ํƒ์ง€๋Š” ๊ฒƒ์„ ํ™•์ธ ํ•  ์ˆ˜ ์žˆ๋‹ค.

code
# tail - f /var/log/apache2/access.log

์Šค์บ๋‹ ๋กœ๊ทธ ํ™•์ธ

  • Directory Listing Scan

  • Apache log4j Scan

์ด ๋ฐ–์—๋„ ๋‹ค์–‘ํ•œ ์Šค์บ๋‹ ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•˜์—ฌ ์„œ๋ฒ„ ๋‚ด ์ทจ์•ฝ์ ์ด ์กด์žฌํ•˜๋Š”์ง€ ์—ฌ๋ถ€๋ฅผ ์Šค์บ”ํ•˜๋Š” ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

  • ์Šค์บ” ๊ฒฐ๊ณผ ํ™•์ธ

์Šค์บ”์ด ๋๋‚˜๋ฉด ํ•ด๋‹น host๋กœ ๋‚˜์˜จ ๋ณด๊ณ ์„œ๋ฅผ ํด๋ฆญํ•˜์—ฌ ์ทจ์•ฝํ•œ ํ•ญ๋ชฉ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•œ๋‹ค.

๊ฐ๊ฐ์˜ ์ทจ์•ฝ์  ๋ชฉ๋ก์„ ์„ ํƒํ•˜์—ฌ ํ•ด๋‹น ์ทจ์•ฝ์ ์— ๋Œ€ํ•œ ๋ณด๊ณ ์„œ๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. ํ•ด๋‹น ์•„ํŒŒ์น˜ ์„œ๋ฒ„๋Š” ํฌ๋ฆฌํ‹ฐ์ปฌํ•œ ์ทจ์•ฝ์ ์ด ๋ฐœ๊ฒฌ๋˜์ง€ ์•Š์•˜์ง€๋งŒ ๋งŒ์•ฝ ํฌ๋ฆฌํ‹ฐ์ปฌํ•œ ์ทจ์•ฝ์ ์ด ๋ฐœ๊ฒฌ๋œ๋‹ค๋ฉด ํ•ด๋‹น ์ทจ์•ฝ์ ์„ ์•…์šฉํ•˜์—ฌ ๊ณต๊ฒฉ ์ˆ˜ํ–‰์ด ๊ฐ€๋Šฅํ•˜๋‹ค.

  • ์ทจ์•ฝ์  ๋ถ„์„ ๋ณด๊ณ ์„œ

์Šค์บ๋‹์ด ์ •์ƒ์ ์œผ๋กœ ์ˆ˜ํ–‰๋˜์—ˆ๋‹ค.

ShareX

์ด ๊ธ€์ด ๋„์›€์ด ๋๋‚˜์š”?

Related

๊ด€๋ จ ๊ธ€

3๊ฐœ
Start Nessus on Linux - 1 Nessus install ๐Ÿ•ต๐Ÿปโ€โ™‚๏ธ
blog

Start Nessus on Linux - 1 Nessus install ๐Ÿ•ต๐Ÿปโ€โ™‚๏ธ

Start Nessus on Linux - 1 Nessus install ๐Ÿ•ต๐Ÿปโ€โ™‚๏ธ 1. Download Nessus 2. Install Nessus ์„ฑ๊ณต์ ์ธ Penetration Testing์„ ์ˆ˜ํ–‰ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๋จผ์ € ๊ณต๊ฒฉ ๋Œ€์ƒ์˜ ์ •๋ณด๋ฅผ ์ˆ˜์ง‘ํ•˜๋Š” ๋‹จ๊ณ„์ธ Footpringing, Passive Scanning ๋‹จ๊ณ„๊ฐ€ ์ด๋ฃจ์–ด์ ธ์•ผ ํ•œ๋‹ค. ์Šค์บ๋‹์„ ํ†ตํ•œ ์ •๋ณด๋“ค
#hacking#nessus#nessus install+1
2021-09-02Blog
Linux Kernel โ€“ 1 Linux Kernel Overview ๐Ÿง 
blog

Linux Kernel โ€“ 1 Linux Kernel Overview ๐Ÿง 

Linux Kernel โ€“ 1 Linux Kernel Overview ๐Ÿง  ๋ฆฌ๋ˆ…์Šค๋ฅผ ์•Œ์•„์•ผ ํ•˜๋Š” ์ด์œ  ๋ฆฌ๋ˆ…์Šค๊ฐ€ ์ธ๊ธฐ ์žˆ๋Š” ์ด์œ  ์“ฐ์ด๋Š” ๊ณณ ์ปค๋„๊ณผ ์šด์˜์ฒด์ €์™€์˜ ์ฐจ์ด ์ปค๋„์€ ์™œ ์กด์žฌ ํ•˜๋Š”๊ฐ€? ์ปค๋„ ๋‚ด๋ถ€์— ์‹ค์ œ๋กœ ๊ตฌํ˜„๋œ ์ฃผ์š” ๊ธฐ๋Šฅ ํ•ญ๋ชฉ ์ปค๋„ ์‹œ์Šคํ…œ ๊ตฌ์กฐ ์ปค๋„์˜ ์ •์˜์™€ ์—ญํ•  ์ปค๋„์€ ์šด์˜์ฒด์ œ์˜ ํ•ต์‹ฌ ๋ถ€๋ถ„ ์ค‘ ํ•˜๋‚˜๋‹ค. ํ•ญ์ƒ ๋ฉ”๋ชจ๋ฆฌ์— ์ƒ์ฃผํ•˜๋ฉด์„œ ํ•˜๋“œ์›จ์–ด์™€ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ
#EmbeddedAndIoTwithLinux#KernelArchitecture#LinuxAutomationAndOps+3
2025-05-14Blog
Install Oracle DB 12 ON Radhat Linux 7.7 ๐Ÿ”ฎ
blog

Install Oracle DB 12 ON Radhat Linux 7.7 ๐Ÿ”ฎ

Install Oracle DB 12 ON Radhat Linux 7.7 ๐Ÿ”ฎ Oracle Down ๊ธฐ๋ณธ ์„ค์น˜ ์‚ฌ์šฉ์ž, ๊ทธ๋ฃน ์ƒ์„ฑ Bash profile ์ปค๋„ ์„ค์ • Oracle Install 1. ํ™ˆํŽ˜์ด์ง€ ์ ‘์† ํ›„ ์›ํ•˜๋Š” ๋ฒ„์ „์˜ Oracle DB ๋‹ค์šด๋กœ๋“œ Oracle DB Download link https://www.oracle.com/database/te
#oracle db#oracle db install#redhat+1
2021-10-14Blog