๐Ÿค–์ •๋ณด๋ณด์•ˆ

๐Ÿค–์ •๋ณด๋ณด์•ˆ/โค๏ธ๋ ˆ๋“œํŒ€

[ํŒŒ์ด์ฌ] ๊ถŒํ•œ ์ƒ์Šน ๋ช…๋ น์–ด(๊ฐ„๋‹จ ์ตœ์ข…)

ํ•ด๋‹น ํŒŒ์ด์ฌ ํ•จ์ˆ˜๋กœ ์•„๋ž˜์™€ ๊ฐ™์ด ์ตœ๊ณ  ๊ถŒํ•œ์˜ ํ”„๋กœ๊ทธ๋žจ ์‹คํ–‰์„ ํ•  ์ˆ˜ ์žˆ๋‹ค. os.system(f'SCHTASKS /Create /TN {SVC_NAME} /SC ONLOGON /TR {SVC_PROG_PATH} /RL HIGHEST') ๋˜๋Š” ์ผ๋ฐ˜ ๋ช…๋ น์–ด๋กœ SCHTASKS /Create /TN "Go" /SC ONSTART /TR "C:\Users\AidenLee\Downloads\go.exe" /RL HIGHEST /RU "SYSTEM" ์‘์šฉ os.system()์„ ์‚ฌ์šฉํ•˜์—ฌ Windows์—์„œ ๊ถŒํ•œ ์ƒ์Šน์„ ์š”์ฒญํ•˜๋Š” ๋ฐฉ๋ฒ• ์ค‘ ํ•˜๋‚˜๋Š” ์ž‘์—… ์Šค์ผ€์ค„๋Ÿฌ(Task Scheduler)๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์ด๋ฏธ ์‚ฌ์šฉํ•˜๊ณ  ๊ณ„์‹  SCHTASKS ๋ช…๋ น์€ ์ด ๋ฐฉ๋ฒ• ์ค‘ ํ•˜๋‚˜์ž…๋‹ˆ๋‹ค. ์•„๋ž˜๋Š” ๋‹ค๋ฅธ ๋ช‡ ๊ฐ€์ง€ ๋ฐฉ๋ฒ•์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ru..

๐Ÿค–์ •๋ณด๋ณด์•ˆ/โค๏ธ๋ ˆ๋“œํŒ€

[ํŒŒ์ด์ฌ] ๊ถŒํ•œ ์ƒ์Šน ์š”์ฒญ ์ฝ”๋“œ(2022 ์ตœ์‹ )

์˜จ๋ผ์ธ์—์„œ ๋ฐœ๊ฒฌ๋˜๋Š” ๊ธฐ์กด ํŒŒ์ด์ฌ ๊ถŒํ•œ ์ƒ์Šน ์š”์ฒญ ์ฝ”๋“œ์˜ ๊ฒฝ์šฐ ํŒจํ‚ค์ง€ ์ด๋ฆ„์ด win32com์—์„œ shell์„ ์š”์ฒญํ•˜์ง€๋งŒ 2022๋…„ ๊ธฐ์ค€ win32comext์— ์กด์žฌํ•œ๋‹ค. import os import sys # win32com.shell์ด ์•„๋‹Œ win32comext ์ด๋‹ค from win32comext.shell import shell ASADMIN = 'asadmin' print(sys.argv) if sys.argv[-1] != ASADMIN: script = os.path.abspath(sys.argv[0]) params = ' '.join([script] + sys.argv[1:] + [ASADMIN]) shell.ShellExecuteEx(lpVerb='runas', lpFile=sys.execut..

๐Ÿค–์ •๋ณด๋ณด์•ˆ/๐Ÿ’™๋ธ”๋ฃจํŒ€

[ํŒŒ์ด์ฌ] ๋Œ€์™ธ ์„œ๋น„์Šค ์‹คํ–‰ ์œ ๋ฌด ์ฒดํฌ ํ”„๋กœ๊ทธ๋žจ(๋ฉ”์ผ๋ณด๊ณ  ๊ธฐ๋Šฅ)

๋Œ€์™ธ๋กœ ์„œ๋น„์Šค๋˜๋Š” ํ™ˆํŽ˜์ด์ง€์˜ ๋‹ค์šด ์—ฌ๋ถ€ ๋ฐ ์ ‘๊ทผ ๋ถˆ๊ฐ€ ์ƒํƒœ๋ฅผ ํŒ๋ณ„ํ•ด์ฃผ๋Š” ํ”„๋กœ๊ทธ๋žจ์ด๋‹ค. ์‹คํ–‰ ํ›„ ๋ฉ”์ผ ๋ฐœ์†กํ•˜๋Š” ๊ธฐ๋Šฅ๊นŒ์ง€ ์žˆ๋‹ค. ๋ฉ”์ผ ๋ณธ๋ฌธ์€ OX ์ƒํƒœ์œ ๋ฌด๋งŒ ๋‚ ๋ผ๊ฐ„๋‹ค. ์„œ๋น„์Šค ์Šค์ผ€์ค„๋Ÿฌ๋กœ ๋“ฑ๋กํ•˜์—ฌ ํ—ฌ์Šค์ฒดํฌ๋ฅผ ํ•  ์ˆ˜ ์žˆ๋‹ค. ๋Œ€์™ธ์„œ๋น„์Šค ๋Œ€์ƒ์ด๋ฏ€๋กœ ํšŒ์‚ฌ ๋‚ด๋ถ€๋ง์—์„œ ์‹คํ–‰ํ•˜๋ฉด ๊ฒฐ๊ณผ๊ฐ’์ด ๋‹ฌ๋ผ์ง„๋‹ค. ํšŒ์‚ฌ๋‚ด๋ถ€๋ง์—์„œ VPN ์‚ฌ์ดํŠธ์— ์ ‘์†ํ•˜๋ ค๊ณ  ํ•œ๋‹ค๋˜๊ฐ€ ๊ทธ๋Ÿฌ๋ฉด ์ƒํƒœ๋Š” X๊ฐ€ ๋œฐ ์ˆ˜๋„ ์žˆ๋‹ค. ์™ธ๋ถ€์‚ฌ์ดํŠธ ์ ‘๊ทผ์ œํ•œ์ด ๋˜๋ฉด X๊ฐ€ ๋œฐ ์ˆ˜๋„ ์žˆ๋‹ค. import sys from PyQt5.QtWidgets import (QApplication, QWidget, QGridLayout, QLabel, QLineEdit, QTextEdit) import requests as r import socket import smtplib r.package..

๐Ÿค–์ •๋ณด๋ณด์•ˆ/๐Ÿ’™๋ธ”๋ฃจํŒ€

[ํŒŒ์ด์ฌ] ์›น์„œ๋น„์Šค IP ์ ‘๊ทผ ๋…ธ์ถœ ํ™•์ธ ์†Œ์Šค์ฝ”๋“œ(๋ณด์•ˆ์ •์ฑ…)

IP๋กœ ์„œ๋น„์Šค๋ฅผ ์ ‘๊ทผํ•˜์˜€์„๋•Œ ์ ‘๊ทผ ๊ฐ€๋Šฅํ•œ ๊ฒƒ์„ ์ทจ์•ฝ์œผ๋กœ ํŒ๋‹จํ•˜๋Š” ๋ถ„๋ฅ˜ ์†Œ์Šค์ฝ”๋“œ์ด๋‹ค. ์ ๊ฒ€ ๊ฒฐ๊ณผ๋Š” Excel๋กœ ํ™•์ธ ๊ฐ€๋Šฅํ•˜๋‹ค ์‚ฌ์ดํŠธ์— ์ง์ ‘ ์ ‘๊ทผํ•˜์—ฌ ํ™•์ธํ•ด์•ผํ•˜๋Š” ์ˆ˜๋™์ ๊ฒ€ ํ•ญ๋ชฉ์ด ์žˆ๋‹ค. ์ฝ˜์†”&์—‘์…€ ๋ฒ„์ „ import requests from openpyxl import Workbook requests.packages.urllib3.disable_warnings(requests.packages.urllib3.exceptions.InsecureRequestWarning) class bcolors: HEADER = "\033[95m" OKBLUE = "\033[94m" OKCYAN = "\033[96m" OKGREEN = "\033[92m" WARNING = "\033[93m" FAIL = "\033[91m" EN..

๐Ÿค–์ •๋ณด๋ณด์•ˆ/๐Ÿ’™๋ธ”๋ฃจํŒ€

[ํŒŒ์ด์ฌ3.x] nslookup ์ž๋™ํ™” ํˆด

import os import socket from urllib.parse import urlparse def nslookup(DOMAIN): try: ip_list = [] ais = socket.getaddrinfo(DOMAIN, 0, 0, 0, 0) for result in ais: ip_list.append(result[-1][0]) ip_list = list(set(ip_list)) return (',').join(ip_list) except: return "N/A" def getDomain(PATH, FNAME): # print PATH + '\\' + FNAME with open(PATH + '\\' + FNAME, 'r') as f: maldomain = f.readlines() if le..

๐Ÿค–์ •๋ณด๋ณด์•ˆ/โค๏ธ๋ ˆ๋“œํŒ€

[ํŒŒ์ด์ฌ] WebGoat Brute Force ํŒŒ์ด์ฌ ์ฝ”๋“œ

import requests password = str() cre = "created" url = "http://localhost:8080/WebGoat/SqlInjection/challenge" cookie = {'JSESSIONID':'8B10E84050C998DD12174E500DBA38F6'} print ('[*] Get password length...') password_length = int() for length in range(1,30): datas = {'username_reg' : "tom' and length(password) = %d and '1'='1" % length, 'email_reg' : 'test@test.com', 'password_reg' : '1111', 'conf..

TwoIceFish
'๐Ÿค–์ •๋ณด๋ณด์•ˆ' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๊ธ€ ๋ชฉ๋ก (4 Page)