bn2019_2

Similar documents
TCP.IP.ppt

Network seminar.key

Microsoft Word doc

1217 WebTrafMon II

Subnet Address Internet Network G Network Network class B networ

SMB_ICMP_UDP(huichang).PDF

[ 네트워크 1] 3 주차 1 차시. IPv4 주소클래스 3 주차 1 차시 IPv4 주소클래스 학습목표 1. IP 헤더필드의구성을파악하고요약하여설명할수있다. 2. Subnet ID 및 Subnet Mask 를설명할수있고, 각클래스의사용가능한호스트수와사설 IP 주소및네트

제20회_해킹방지워크샵_(이재석)

PowerPoint 프레젠테이션

Microsoft PowerPoint - 06-IPAddress [호환 모드]

hd1300_k_v1r2_Final_.PDF

untitled

1. GigE Camera Interface를 위한 최소 PC 사양 CPU : Intel Core 2 Duo, 2.4GHz이상 RAM : 2GB 이상 LANcard : Intel PRO/1000xT 이상 VGA : PCI x 16, VRAM DDR2 RAM 256MB

[ tcpdump 패킷캡처프로그램 ] tcpdump란? tcpdump 버전확인 tcpdump 플래그 (flags) tcpdump 사용법 tcpdump의사용예제 telnet을활용해 root와 passwd 암호알아내기 [01] tcpdump란? tcpdump는 Lawren


Chapter11OSPF

UDP Flooding Attack 공격과 방어

3ÆÄÆ®-11

슬라이드 1

Network Security - Wired Sniffing 실습 ICNS Lab. Kyung Hee University

PowerPoint 프레젠테이션

TTA Verified : HomeGateway :, : (NEtwork Testing Team)

슬라이드 제목 없음

ARMBOOT 1

시스코 무선랜 설치운영 매뉴얼(AP1200s_v1.1)

USB USB DV25 DV25 REC SRN-475S REC SRN-475S LAN POWER LAN POWER Quick Network Setup Guide xdsl/cable Modem PC DVR 1~3 1.. DVR DVR IP xdsl Cable xdsl C

歯최덕재.PDF

PWR PWR HDD HDD USB USB Quick Network Setup Guide xdsl/cable Modem PC DVR 1~3 1.. DVR DVR IP xdsl Cable xdsl Cable PC PC DDNS (



슬라이드 1

chapter4

Microsoft Word - KPMC-400,401 SW 사용 설명서

<C0CCBCBCBFB52DC1A4B4EBBFF82DBCAEBBE7B3EDB9AE2D D382E687770>

PowerPoint 프레젠테이션

6강.hwp

The Pocket Guide to TCP/IP Sockets: C Version

SRC PLUS 제어기 MANUAL

IP 주소란? 네트워크상에존재하는컴퓨터들을구분하고, 서로를인식하기위해사용하는특수한번호. 32-bit 체계의 IPv4 와, 128-bit 체계의 IPv6 가있다. About IPv4 32-bit 의길이로이루어지는 IPv4 는 1 byte (= 8-bit) 씩 4 개로나누

자바-11장N'1-502

Microsoft PowerPoint - 04-UDP Programming.ppt

Microsoft PowerPoint - ch02_인터넷 이해와 활용.ppt

untitled

0. 들어가기 전

Microsoft PowerPoint - 2.Catalyst Switch Intrastructure Protection_이충용_V1 0.ppt [호환 모드]

KISA-GD

PowerPoint 프레젠테이션

Assign an IP Address and Access the Video Stream - Installation Guide

SYN flooding

일반적인 네트워크의 구성은 다음과 같다

Microsoft PowerPoint - IPv6-세미나.ppt

Microsoft Word - ZIO-AP1500N-Manual.doc

Microsoft PowerPoint - IPv6-세미나.ppt

Microsoft PowerPoint - L4-7Switch기본교육자료.ppt

Microsoft Word - Tcpdump 사용설명서.doc

개요 IPv6 개요 IPv6 주소 IPv4와공존 IPv6 전환기술 (Transition Technologies)

4.18.국가직 9급_전산직_컴퓨터일반_손경희_ver.1.hwp

Chapter 18 - William Stallings, Data and Computer Communications, 8/e

Microsoft PowerPoint _TCP_IP

<4D F736F F D FB1E2BCFAB5BFC7E2BAD0BCAE2DB8F0B9D9C0CF20B3D7C6AEBFF6C5A92DC3D6BFCF2E646F6378>

歯Cablexpert제안서.PDF

歯김병철.PDF

Secure Programming Lecture1 : Introduction

Interstage5 SOAP서비스 설정 가이드

(Asynchronous Mode) ( 1, 5~8, 1~2) & (Parity) 1 ; * S erial Port (BIOS INT 14H) - 1 -

rmi_박준용_final.PDF

Cisco SDN 3.0 DDoS DDoS Cisco DDoS Real Demo 2008 Cisco Systems, Inc. All rights reserved. 2

VZ94-한글매뉴얼

Microsoft PowerPoint - ch13.ppt

MITSUBISHI

1. What is AX1 AX1 Program은 WIZnet 사의 Hardwired TCP/IP Chip인 iinchip 들의성능평가및 Test를위해제작된 Windows 기반의 PC Program이다. AX1은 Internet을통해 iinchip Evaluation

歯Enet_목차_.PDF

Sena Device Server Serial/IP TM Version

[ R E P O R T ] 정보통신공학전공 김성태

歯T1-4김병철2.PDF

2005년 6월 고1 전국연합학력평가

The Pocket Guide to TCP/IP Sockets: C Version

歯규격(안).PDF

Wireshark Part 2 1

KAA2005.9/10 Ãâ·Â

untitled

API STORE 키발급및 API 사용가이드 Document Information 문서명 : API STORE 언어별 Client 사용가이드작성자 : 작성일 : 업무영역 : 버전 : 1 st Draft. 서브시스템 : 문서번호 : 단계 : Docum

PowerPoint 프레젠테이션

歯A1.1함진호.ppt

Microsoft Word - access-list.doc

Microsoft PowerPoint - MobileIPv6_김재철.ppt


BGP AS AS BGP AS BGP AS 65250

<4D F736F F F696E74202D E20C0CEC5CDB3DD20C0C0BFEB20B9D720BCADBAF1BDBA20B1E2BCFA E >

untitled

*****

PowerPoint 프레젠테이션

PowerPoint 프레젠테이션

9

Microsoft PowerPoint - Supplement-03-TCP Programming.ppt [호환 모드]

歯2019

Microsoft PowerPoint - tem_5

Analytics > Log & Crash Search > Unity ios SDK [Deprecated] Log & Crash Unity ios SDK. TOAST SDK. Log & Crash Unity SDK Log & Crash Search. Log & Cras

歯설명서_020925_.PDF

OSI 참조 모델과 TCP/IP

Transcription:

arp -a

Packet Logging/Editing Decode Buffer Capture Driver Logging: permanent storage of packets for offline analysis Decode: packets must be decoded to human readable form. Buffer: packets must temporarily buffered prior to storage or processing. Capture driver: software driver to capture and filter network traffic.

Router Attacker

root@kali:/home/bungae# arpspoof -t 172.16.181.144 172.16.181.2 0:c:29:12:d:cd 0:c:29:4b:3a:ad 0806 42: arp reply 172.16.181.2 is-at 0:c:29:12:d:cd 0:c:29:12:d:cd 0:c:29:4b:3a:ad 0806 42: arp reply 172.16.181.2 is-at 0:c:29:12:d:cd 0:c:29:12:d:cd 0:c:29:4b:3a:ad 0806 42: arp reply 172.16.181.2 is-at 0:c:29:12:d:cd 0:c:29:12:d:cd 0:c:29:4b:3a:ad 0806 42: arp reply 172.16.181.2 is-at 0:c:29:12:d:cd

root@kali:~# tcpdump -v -XX arp tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes 20:57:41.840307 ARP, Ethernet (len 6), IPv4 (len 4), Reply _gateway is-at 00:0c:29:12:0d:cd (oui Unknown), length 28 0x0000: 000c 294b 3aad 000c 2912 0dcd 0806 0001..)K:...)... 0x0010: 0800 0604 0002 000c 2912 0dcd ac10 b502...)... 0x0020: 000c 294b 3aad ac10 b590..)k:... 20:57:43.840542 ARP, Ethernet (len 6), IPv4 (len 4), Reply _gateway is-at 00:0c:29:12:0d:cd (oui Unknown), length 28 0x0000: 000c 294b 3aad 000c 2912 0dcd 0806 0001..)K:...)... 0x0010: 0800 0604 0002 000c 2912 0dcd ac10 b502...)... 0x0020: 000c 294b 3aad ac10 b590..)k:...

root@kali:~# tcpdump -n -v icmp tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes 21:35:47.815183 IP (tos 0x0, ttl 64, id 43041, offset 0, flags [DF], proto ICMP (1), length 1500) 172.16.181.141 > 210.89.160.88: ICMP echo request, id 6076, seq 1, length 1480 root@kali:~# tcpdump -n -v icmp tcpdump: listening on eth0, link-type EN10MB (Ethernet), capture size 262144 bytes 21:35:14.377091 IP (tos 0x0, ttl 64, id 19232, offset 0, flags [+], proto ICMP (1), length 1500) 172.16.181.141 > 210.89.164.90: ICMP echo request, id 6071, seq 1, length 1480 21:35:14.377174 IP (tos 0x0, ttl 64, id 19232, offset 1480, flags [none], proto ICMP (1), length 21) 172.16.181.141 > 210.89.164.90: ip-proto-1

Class A 0 1 2... 8 16 24 31 [bit]] 0 netid hostid Class B 1 0 netid hostid Class C 1 1 0 netid hostid Class D 1 1 1 0 Multicast address 11111111 11111111 11111111 00000000 255 255 255 0 Class C 주소 Subnet mask 11111111 11111111 11111111 11 000000 서브네트로 2bit 사용 255 255 255 0 Subnet mask

Reserved address blocks CIDR address block Description Reference 0.0.0.0/8 Current network (only valid as source address) RFC 1700 10.0.0.0/8 Private network RFC 1918 14.0.0.0/8 Public data networks RFC 1700 127.0.0.0/8 Loopback RFC 3330 128.0.0.0/16 Reserved (IANA) RFC 3330 169.254.0.0/16 Link-Local RFC 3927 172.16.0.0/12 Private network RFC 1918 191.255.0.0/16 Reserved (IANA) RFC 3330 192.0.0.0/24 Reserved (IANA) RFC 3330 192.0.2.0/24 Documentation and example code RFC 3330 192.88.99.0/24 IPv6 to IPv4 relay RFC 3068 192.168.0.0/16 Private network RFC 1918 198.18.0.0/15 Network benchmark tests RFC 2544 223.255.255.0/24 Reserved (IANA) RFC 3330 224.0.0.0/4 Multicasts (former Class D network) RFC 3171 240.0.0.0/4 Reserved (former Class E network) RFC 1700 255.255.255.255 Broadcast

void main() { unsigned int i; int c; i=0x4500+0x002c+0x02e4+0x8006+0x4a7d+0x8268+0xac10+0xb58d; if (i>0xffff) { }

08:16:48.095814 IP (tos 0x0, ttl 53, id 61092, offset 0, flags [none], proto TCP (6), length 60) 172.217.24.36.80 > 192.168.0.89.57664: Flags [S.], cksum 0xba9f (correct), seq 3366308004, ack 710814350, win 42408, options [mss 1380,sackOK,TS val 3588274860 ecr 1194836588,nop,wscale 7], length 0 0x0000: 4500 003c eea4 0000 3506 1119 acd9 1824 E..<...5...$ 0x0010: c0a8 0059 0050 e140 c8a5 c8a4 2a5e 2a8e...Y.P.@...*^*. 0x0020: a012 a5a8 ba9f 0000 0204 0564 0402 080a...d... 0x0030: d5e0 baac 4737 c26c 0103 0307...G7.l...

Packet Logging/Editing Decode Buffer Capture Driver Media Logging: permanent storage of packets for offline analysis Decode: packets must be decoded to human readable form. Buffer: packets must temporarily buffered prior to storage or processing. Capture driver: software driver to capture and filter network traffic. Media: usually an Ethernet card but could also be a wireless card or anything else.

FTP Mail http Etc 응용 프로그램 소켓 소켓 소켓 소켓 소켓 Port 21 번 Port 25 번 Port 80 번 Port 1025 번 Port IP :1.2.3.4

A B SEQ ACK SEQ ACK A0 0 -> SYN <-SYN,ACK B0 A1 A1 B1 -> ACK A1 B1 ->PSH,ACK 데이터 21B <-ACK B1 A22 <-PSH,ACK 데이터 1068B A22 B1069 ->ACK B1 A22 <- FIN, ACK B1069 A22 A22 B1070 -> ACK A22 B1070 -> FIN, ACK <-ACK B1070 A23

4XX ( 클라이언트에러 ) 400 bad request 401 unauthorized 403 forbidden 404 not found 5XX ( 서버에러 ) 500 int. server error 501 not impl. 502 bad gateway 503 svc not avail