³×Æ®¿öÅ© Á¤º¸ È®ÀÎÇϱâ
ÃÑ ÆäÀÌÁö ¼ö : 3224

Àüü ÇÔ¼ö/¿ë¾î»çÀü
Facebook Joinc ±×·ì   Joinc QA »çÀÌÆ®



joinc´Â Firefox¿Í chrome¿¡¼­ Å×½ºÆ® Çß½À´Ï´Ù. IE¿¡¼­´Â Å×À̺íÀÌ ±úÁö°Å³ª À̹ÌÁö°¡ º¸ÀÌÁö ¾ÊÀ» ¼ö ÀÖ½À´Ï´Ù. ƯÈ÷ ±¸±Û DocsÀ̹ÌÁöÀÇ °æ¿ì ¿¢¹Úó¸®µÉ ¼ö ÀÖ½À´Ï´Ù.

½Ã½ºÅÛ È¤Àº ³×Æ®¿öÅ© °ü¸®¸¦ À§Çؼ­ ³» ÁÖº¯ÀÇ ³×Æ®¿öÅ© Á¤º¸¸¦ ¾Ë¾Æ¾ß ÇÒ Çʿ䰡 ÀÖ½À´Ï´Ù. ÁÖº¯¿¡ ¾î¶² ¼­¹öµéÀÌ ¾î¶² ¾ÆÀÌÇǸ¦ °¡Áö°í ÀÛµ¿Çϰí ÀÖ´ÂÁö, ³×Æ®¿öÅ© ¼º´ÉÀº ¾î¶²Áö, ¾î¶² Æ÷Æ®°¡ ¿­·ÁÀÖ´ÂÁö µîÀÌÁÒ. À̵é Á¤º¸´Â °ü¸® Ãø¸é¿¡¼­ »Ó¸¸ ¾Æ´Ï¶ó, ƯÈ÷ ³×Æ®¿öÅ© ÇÁ·Î±×·¥ÀÇ °³¹ß¿¡ ¸¹Àº µµ¿òÀ» ÁÝ´Ï´Ù.

³» ³×Æ®¿öÅ© ÁÖº¯ »óȲ »ìÇDZâ ?

nmap´Â ³×Æ®¿öÅ© »óȲÀ» ÆÄ¾ÇÇϱâ À§ÇÑ ÃÖ°íÀÇ µµ±¸ÁÒ. nmapÀº ¸Å¿ì °­·ÂÇÑ ÅøÀ̱⠶§¹®¿¡ »ç¿ë¹æ¹ýÀ» ¼÷ÁöÇØ¼­ ÁÖÀDZí°Ô »ç¿ëÇÏ´Â °Ô ÁÁ½À´Ï´Ù. ±×·¸Áö ¾ÊÀ¸¸é, ³×Æ®¿öÅ© °ø°Ý ¡ÈÄ·Î ÆÇ´ÜÇØ¼­ Áö¿ª ³×Æ®¿öÅ©¿¡¼­ °í¸³µÇ´Â µî ¹®Á¦°¡ »ý±æ ¼ö Àֱ⠶§¹®ÀÔ´Ï´Ù. ´ÙÀ½Àº nmapÀ» ÀÌ¿ëÇØ¼­ LAN ¼­ºê³ÝÀÇ ¸ðµç È£½ºÆ®ÀÇ Á¤º¸¸¦ °¡Á®¿À´Â ¹æ¹ýÀÔ´Ï´Ù.

# nmap -sP 192.168.0.0/24 
 
Starting Nmap 4.03 ( http://www.insecure.org/nmap/ ) at 2011-08-06 23:36 KST 
Host 192.168.0.1 appears to be up. 
MAC Address: 00:D0:63:4D:A0:00 (Cisco Systems) 
Host 192.168.0.3 appears to be up. 
MAC Address: 00:0E:0C:3C:DD:A7 (Intel) 
Host 192.168.0.8 appears to be up. 
MAC Address: 00:A0:D1:E0:9D:B0 (Inventec) 
... 
Host test.ppp.com (192.168.0.246) appears to be up. 
MAC Address: 00:16:46:43:91:C0 (Cisco Systems) 
Nmap finished: 256 IP addresses (133 hosts up) scanned in 12.378 seconds 
 
È£½ºÆ®ÀÇ IP¿Í MAC Address Á¤º¸¸¦ È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù. ARP¸¦ ºê·Îµå ij½ºÆÃ ÇØ¼­ Á¤º¸¸¦ ¼öÁýÇÕ´Ï´Ù.

-sS ¿É¼ÇÀ» ÀÌ¿ëÇϸé TCP SYN scanÀ» ÇÒ ¼ö ÀÖ½À´Ï´Ù. ´ë»ó È£½ºÆ®ÀÇ ¿­¸° Æ÷Æ®¸¦ È®ÀÎÇÕ´Ï´Ù. TCP SYN scanÀº Half-open scan ȤÀº Stealth scanÀ¸·Î ºÒ¸®±âµµ Çϴµ¥¿ä. ¿ÏÀüÇÑ TCP ¿¬°áÀ» ¸ÎÁö´Â ¾Ê½À´Ï´Ù. ¾Æ½Ã´Ù ½ÃÇÇ ¿ÏÀüÇÑ ¿¬°áÀ» ¸ÎÀ¸·Á¸é 3¹øÀÇ ÆÐŶ ±³È¯ÀÌ ÀÖ¾î¾ß Çϴµ¥¿ä. ÀÌ ¹æ¹ýÀº SYN ÆÐŶÀ» º¸³½ ÈÄ¿¡ SYN/ACK¸¦ ¹ÞÀ¸¸é open µÈ °Í ±îÁö¸¸ È®ÀÎÇϰí, ACK¸¦ º¸³»Áö ¾Ê½À´Ï´Ù. ±×·¯´Ï ¿ÏÀüÇÑ ¿¬°áÀÌ ¸¸µé¾îÁöÁö ¾Ê´Â °ÅÁÒ. ¸¸¾à RST/ACK¸¦ ¹ÞÀ¸¸é close »óÅ·ΠÆÇ´ÜÇÕ´Ï´Ù.

SYN scanÀº half-open Áï ¿ÏÀüÇÑ ¿¬°áÀÌ ÀÌ·ïÁöÁö ¾Ê±â ¶§¹®¿¡ ½Ã½ºÅÛ ·Î±×µî¿¡ ±â·ÏµÇÁö ¾Ê°í, µû¶ó¼­ ¾ÖÇø®ÄÉÀ̼ǿ¡ ¿µÇâÀ» Áְųª ·Î±×¸¦ ³²±âÁö ¾Ê°í scanningÀÌ °¡´ÉÇÕ´Ï´Ù. ¼Óµµ ¶ÇÇÑ ºü¸£°í¿ä. ÷¾ðÇÏÀÚ¸é, Ŭ¶óÀÌ¾ðÆ®°¡ ¿¬°á¿äûÀ» Çϸé ThreeWay Handshake °úÁ¤À» °ÅÄ¡°í, ÀÌ °úÁ¤ÀÌ ³¡³ª¸é listen ´ë±â¿­¿¡ µé¾î°©´Ï´Ù. ±×·¯¸é ¼­¹ö ÇÁ·Î±×·¥Àº acceptÇÔ¼ö·Î ¿¬°á ¼ÒÄÏÀ» °¡Á®¿À´Â °ÅÁÒ. Threeway handshake °úÁ¤ÀÌ ³¡³ªÁö ¾ÊÀ¸¸é listen ´ë±â¿­¿¡ µé¾î°¡Áö ¾Ê±¸¿ä. ±×·¯´Ï ÀÀ¿ë ÇÁ·Î±×·¥Àº ¿¬°á¿äûÀÌ ÀÖ¾ú´ÂÁö ¾Ë¼öµµ ¾ø°í, ±â·ÏÀ» ³²±âÁöµµ ¸øÇÏ´Â °ÅÁÒ.

#nmap  -sS www.test.co.kr  
 
Starting Nmap 4.03 ( http://www.insecure.org/nmap/ ) at 2011-08-07 00:21 KST 
Interesting ports on joinc (218.234.19.87): 
(The 1668 ports scanned but not shown below are in state: closed) 
PORT     STATE SERVICE 
22/tcp   open  ssh 
53/tcp   open  domain 
80/tcp   open  http 
110/tcp  open  pop3 
111/tcp  open  rpcbind 
3306/tcp open  mysql 
 
www.test.co.krÀº SSH ¼­ºñ½º¿Í À¥ ¼­ºñ½º, mysql, pop3µîÀÇ ¼­ºñ½ºÇϰí ÀÖ´Â °É È®ÀÎÇÒ ¼ö ÀÖ½À´Ï´Ù.


nmapÀ» ÀÌ¿ëÇÑ ³×Æ®¿öÅ© Æ÷Æ® ½ºÄ³´× ¹üÀ§ ÁöÁ¤ ¹æ¹ý Á¤¸®ÇغýÀ´Ï´Ù.
´ÜÀÏ È£½ºÆ® ½ºÄµ nmap 192.168.1.1
¿©·¯ È£½ºÆ® ½ºÄµ nmap 192.168.1.1, 192.168.1.2
¸ñ·Ï ½ºÄµ nmap -iL targets.txt
È£½ºÆ® ¹üÀ§ ½ºÄµ nmap 192.168.1.1-10
Ipv6 ½ºÄµ nmap -6 2001:db8:85a3:8d3:1319:8a2e:370:7348

nmap ½ºÄµ ¹æ¹ýÀ» Á¤¸®Çß½À´Ï´Ù.
  • -sT : ÀϹÝÀûÀÎ TCP Æ÷Æ® ½ºÄµ
  • -sS : half-open ½ºÄµ
    TCP ¿¬°áÀ» ³¡³»Áö ¾Ê±â ¶§¹®¿¡, ¸Å¿ì ºü¸£°Ô Æ÷Æ®¸¦ ½ºÄµÇÒ ¼ö ÀÖ´Ù. ¿¬°áÀ» ³¡³»Áö ¾Ê±â ¶§¹®¿¡ ¾ÖÇø®ÄÉÀÌ¼Ç ·Î±×¸¦ ³²±âÁö ¾Ê´Â´Ù´Â ÀåÁ¡µµ ÀÖ´Ù. TCP´Â ¿¬°áÀ» ¸ÎÀ» ¶§ 3¹øÀÇ ÆÐŶ ±³È¯À» ÇÑ´Ù. - Threeway Handsahke -. nmapÀº °Ë»çÇÏ·Á´Â ¿ø°Ý È£½ºÆ®¿¡ SYN ÆÐŶÀ» Àü¼ÛÇϴµ¥, ¿ø°Ý È£½ºÆ®·Î ºÎÅÍ SYN/ACK°¡ Àü¼ÛµÇ¸é, Æ÷Æ®°¡ ¿­¸° °ÍÀ¸·Î °£ÁÖÇÑ´Ù. Æ÷Æ®°¡ ´ÝÇô ÀÖ´Ù¸é RSTÆÐŶÀÌ Àü¼ÛµÈ´Ù.
  • -sP : ICMP¸¦ ÀÌ¿ëÇÑ ½ºÄµ
  • -sU : UDP Scan
  • -sA : TCP ACK ½ºÄµ
  • -sO : IP Protocol ½ºÄµ
    ¸ñÇ¥ Host°¡ ¾î¶² IP ÇÁ·ÎÅäÄÝÀ» Áö¿øÇÏ´ÂÁö °Ë»çÇÑ´Ù. TCP, ICMP, IGMP µîÀ» °Ë»çÇÑ´Ù.

·ÎÄà ȣ½ºÆ®¶ó¸é netstat¸¦ ÀÌ¿ëÇØ¼­ ¿­¸° Æ÷Æ®¸¦ °Ë»çÇÒ ¼öÀÖ½À´Ï´Ù.
# netstat -untap 
Active Internet connections (servers and established) 
Proto Recv-Q Send-Q Local Address           Foreign Address         State       PID/Program name    
tcp        0      0 0.0.0.0:3306            0.0.0.0:*               LISTEN      3906/mysqld          
tcp        0      0 0.0.0.0:110             0.0.0.0:*               LISTEN      2197/xinetd          
tcp        0      0 0.0.0.0:111             0.0.0.0:*               LISTEN      2041/portmap         
tcp        0      0 0.0.0.0:80              0.0.0.0:*               LISTEN      6746/httpd           
tcp        0      0 218.234.19.87:53        0.0.0.0:*               LISTEN      19501/named          
tcp        0      0 127.0.0.1:53            0.0.0.0:*               LISTEN      19501/named          
tcp        0      0 0.0.0.0:22              0.0.0.0:*               LISTEN      2183/sshd            
tcp        0      0 127.0.0.1:953           0.0.0.0:*               LISTEN      19501/named          
tcp        0      0 218.234.19.87:22        121.135.216.122:49161   ESTABLISHED 10271/sshd           
tcp        0      0 127.0.0.1:3306          127.0.0.1:42309         TIME_WAIT   -                    
tcp        0      0 127.0.0.1:3306          127.0.0.1:42310         TIME_WAIT   -                    
tcp        0      0 218.234.19.87:80        220.255.2.28:23554      TIME_WAIT   -                    
tcp        0      0 127.0.0.1:42311         127.0.0.1:3306          TIME_WAIT   -                    
tcp        0      0 127.0.0.1:42308         127.0.0.1:3306          TIME_WAIT   -                    
tcp        0  14770 218.234.19.87:80        66.249.67.75:64588      ESTABLISHED 13391/httpd          
tcp        0      0 218.234.19.87:80        61.247.204.37:54360     TIME_WAIT   -                    
 

È£½ºÆ® ã±â¿Í ¼º´É ÃøÁ¤

fpingÀ̶ó´Â ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¸é ¿øÇÏ´Â ³×Æ®¿öÅ© ¿µ¿ªÀÇ È£½ºÆ®¸¦ ãÀ» ¼ö ÀÖÀ¸¸ç, °£´ÜÇÏ°Ô ¼º´Éµµ ÃøÁ¤ÇÒ ¼ö ÀÖ½À´Ï´Ù.
$ fping -c1 -gds 172.30.1.0/24 2>&1 | egrep -v "ICMP|xmt" 
172.30.1.254 : [0], 84 bytes, 2.57 ms (2.57 avg, 0% loss) 
172.30.1.1   : [0], 84 bytes, 0.10 ms (0.10 avg, 0% loss) 
 
 
     256 targets 
       2 alive 
     256 unreachable 
       0 unknown addresses 
 
       0 timeouts (waiting for response) 
 
 0.10 ms (min round trip time) 
 1.33 ms (avg round trip time) 
 2.57 ms (max round trip time) 
       10.671 sec (elapsed real time) 
 

´ÜÀÏ È£½ºÆ®¿¡ ´ëÇÑ Å×½ºÆ®µµ °¡´ÉÇÕ´Ï´Ù.
# fping joinc 
joinc is alive 
 

È£½ºÆ®ÀÇ ¸ñ·ÏÀ» ÆÄÀÏ·Î ÀúÀåÇØ¼­ ÃøÁ¤ÇÒ ¼ö ÀÖ½À´Ï´Ù. ¸ð´ÏÅ͸µ ÇÁ·Î±×·¥À» ¸¸µé ¶§ À¯¿ëÇϰÚÁÒ.
# fping -c1 < filename 
 

󸮷® ÃøÁ¤

fping °°Àº ÇÁ·Î±×·¥À¸·Îµµ ¼º´ÉÀ» ÃøÁ¤ÇÒ ¼ö ÀÖ±â´Â ÇÕ´Ï´Ù¸¸ ICMP¸¦ ÀÌ¿ëÇϱ⠶§¹®¿¡ Á¦ÇÑÀûÀÏ ¼ö ¹Û¿¡ ¾øÁÒ. º»°ÝÀûÀ¸·Î 󸮷®À» (Throughput) ÃøÁ¤Çϱ⸦ ¿øÇÑ´Ù¸é iperf¸¦ »ç¿ëÇÏ¸é µË´Ï´Ù. ÀÌ ÇÁ·Î±×·¥Àº Ŭ¶óÀ̾ðÆ®/¼­¹ö ȯ°æÀ¸·Î ÀÛµ¿À» Çϴµ¥¿ä. ¼­¹ö¿Í Ŭ¶óÀÌ¾ðÆ®°¡ µ¥ÀÌÅ͸¦ ÁÖ°í ¹Þ´Â °ÍÀ» ÃøÁ¤ÇÏ´Â ¹æ½ÄÀ¸·Î ÀÛµ¿ÇÕ´Ï´Ù.

¿¹Àü¿¡´Â iperf¸¦ »ç¿ëÇÏÁö ¾Ê°í, Á÷Á¢ ¼­¹ö/Ŭ¶óÀÌ¾ðÆ® ÇÁ·Î±×·¥À» ¸¸µé¾î¼­ »ç¿ëÇß½À´Ï´Ù. read, write ¹öÆÛÀÇ Å©±â¸¦ ´Ã·Á°¡¸é¼­ Å×½ºÆ®¸¦ ÇÏ´Â ¹æ½ÄÀ̾ú½À´Ï´Ù. ±»ÀÌ Á÷Á¢ ¸¸µé¾î¼­ »ç¿ëÇÒ ÇÊ¿ä´Â ¾øÀ» °Í °°½À´Ï´Ù. iperf·Îµµ ¹öÆÛÅ©±â º¯°æ, UDP/TCP, window size º¯°æµîÀ» Á¶ÀýÇϸ鼭 Å×½ºÆ® ÇÒ ¼ö ÀÖÀ¸´Ï±î¿ä.

iperf¸¦ ¼­¹ö ¸ðµå·Î ½ÇÇàÇÑ ´ÙÀ½
$ iperf -s 
------------------------------------------------------------ 
Server listening on TCP port 5001 
TCP window size: 85.3 KByte (default) 
------------------------------------------------------------ 
 

iperf¸¦ Ŭ¶óÀÌ¾ðÆ® ¸ðµå·Î ½ÇÇàÇϸé Å×½ºÆ®°¡ ÁøÇàµË´Ï´Ù.
------------------------------------------------------------ 
Client connecting to host1, TCP port 5001 
TCP window size: 16.0 KByte (default) 
------------------------------------------------------------ 
 

Å×½ºÆ® °á°ú´Â ´ÙÀ½°ú °°½À´Ï´Ù.
[  3] local 192.168.10.25 port 40245 connected with 192.168.20.25 port 5001 
[ ID] Interval       Transfer     Bandwidth 
[  3]  0.0-10.0 sec  8.18 MBytes  6.85 Mbits/sec 
 

³» ¼­¹ö¿¡ ´©°¡ ÀÖ´ÂÁö

w ¸í·ÉÀ» ÀÌ¿ëÇØ¼­ ³» ¼­¹ö¿¡ Á¢±ÙÇÑ À¯ÀúÀÇ ÇൿÀ» È®ÀÎÇÒ ¼ö ÀÖ´Ù´Â °Í ¾Ë°í °è½Ç°Ì´Ï´Ù. Àúµµ w ¿Ü¿¡´Â »ç¿ëÇÑÀûÀÌ ¾ø´Âµ¥¿ä. whowatch ¶ó´Â ÇÁ·Î±×·¥µµ ÀÖ½À´Ï´Ù.
7 users: (1 local, 0 telnet, 1 ssh, 5 other)                            load: 0.05, 0.10, 0.13 
                                                                                                        
(init)         yundream  pts/0  :0                  -                                                   
(konsole)      yundream  pts/5  :0                  ssh kknd@172.30.1.1                                 
(sshd)         kknd      pts/6  172.30.1.1          -                                                   
 
½áº¸±ä Çߴµ¥, w¿¡ ºñÇØ¼­ µüÈ÷ ÁÁ´Ù´Â ´À³¦Àº ¾ø½À´Ï´Ù. Á» ¿¹»Ú°Ô Á¤º¸¸¦ º¸¿©ÁÖ±ä ÇÕ´Ï´Ù¸¸..

history

  1. ÀÛ¼ºÀÏ : 2011³â 8¿ù 27ÀÏ
EmailÀ» ±âÀÔÇϸé, ´ñ±ÛÀÌ ¸ÞÀÏ·Î Àü´ÞµË´Ï´Ù.