|
Nessus
ºÐ¼®º¸°í¼
update : 2001.07
ÀåÀ±¼÷/CERTCC-KR jys@certcc.or.kr
1. °³¿ä
Nessus´Â http://www.nessus.org¿¡¼ ¹«·á·Î ´Ù¿î¹Þ¾Æ »ç¿ëÇÒ ¼ö ÀÖ´Â º¸¾ÈÃë¾àÁ¡ Á¡°Ëµµ±¸·Î local°ú remote
½Ã½ºÅÛ º¸¾È Ãë¾àÁ¡ ã¾ÆÁÖ´Â µµ±¸ÀÌ´Ù.
»ç¶÷µéÀÌ ¾î¶² º¸¾ÈÅøÀ» ¼±È£ÇÏ´ÂÁö ¾Ë¾Æº¸±â À§ÇØ 2000³â 5¿ù°ú 6¿ù¿¡ 1200¸íÀÇ Nmap»ç¿ëÀÚµéÀ» ´ë»óÀ¸·Î ¼±È£ÇÏ´Â º¸¾ÈÅø Áß 5°³ÀÇ
Åø(NmapÀº Á¦¿Ü)À» ÅÃÇϵµ·Ï ÇÏ´Â ¼³¹®Á¶»ç¸¦ ÇØº» °á°ú(http://www.insecure.org/tools.html) Nessus°¡ 1À§¸¦
Â÷ÁöÇÒ Á¤µµ·Î Nessus´Â º¸¾È Ãë¾àÁ¡ Á¡°Ë±â´ÉÀÌ ¶Ù¾î³ª´Ù.
Nessus´Â Renaud Deraison¿¡ ÀÇÇØ ¸¸µé¾îÁö±â ½ÃÀÛÇÏ¿© 1998³â 4¿ù óÀ½ ¹öÀüÀÌ ¹ßÇ¥µÇ¾ú°í, 2001³â 7¿ù ÇöÀç
1.0.8 ¹öÀüÀÌ ¹ßÇ¥µÈ »óÅ´Ù.
NessusÀÇ Æ¯¼ºÀ» »ìÆìº¸¸é ´ÙÀ½°ú °°´Ù.
¡á Nessus´Â »ç¿ëÀÌ ÀÚÀ¯·Ó°í, up-to-date°¡ °£ÆíÇÏ´Ù Nessus´Â GNU General Public
License(GPL)ÇÏ¿¡ ¸ðµç »ç¶÷ÀÌ ÀÚÀ¯·Ó°Ô Àаí code¸¦ ¼öÁ¤ÇÒ ¼ö ÀÖ´Ù.
¡á sever/client±¸Á¶·Î µ¿ÀÛÇÑ´Ù. server daemonÀÎ nessusd´Â º¸Åë UNIX machine(Linux,
*BSD, Solaris)¿¡¼ ¼öÇàµÇ¾î¾ß Çϰí client´Â Windows 95/98/NT ´Ù¸¥ UNIXÄÄÇ»ÅÍ·Î ¼öÇàµÉ ¼ö ÀÖ´Ù. (GIMP°¡
¼³Ä¡µÇ¾î ÀÖ¾î¾ß¸¸ ÇÔ.)
¡á nmap°ú gtk¸¦ ±â¹ÝÀ¸·Î ÇÑ´Ù. Nessus´Â nmapº¸´Ù ´õ¿í Á¤±³Çϰí GUIȯ°æÀ» Á¦°øÇÏ¿© ½±°Ô »ç¿ëÇÒ¼ö ÀÖ´Ù.
¡á plug-in·Î ÀÚ¼¼ÇÑ ºÎºÐ±îÁö Á¡°ËÇÒ ¼ö ÀÖ°í plug-in ¾÷µ¥ÀÌÆ®µµ °£´ÜÈ÷ ÇÒ ¼ö ÀÖ´Ù. Nessus´Â 2001³â 7¿ù ÇöÀç
18°³ÀÇ family, 679°³ÀÇ library¸¦ Á¦°øÇØ ÀÚ¼¼ÇÑ ºÎºÐ±îÁö Á¡°ËÇØÁÙ ¼ö ÀÖ°Ô ÇÏ°í °£´ÜÈ÷ plug-inÀ» ¾÷µ¥ÀÌÆ® ÇÒ ¼ö ÀÖ´Â
À¯Æ¿¸®Æ¼¸¦ Á¦°øÇÑ´Ù. ¸ðµç ¼³Ä¡°¡ ³¡³ª¸é /usr/local/sbin/nessus-update-pluginsÆÄÀÏÀÌ »ý±â´Âµ¥ root±ÇÇÑÀ¸·Î
ÀÌ ÆÄÀÏÀ» ½ÇÇàÇϸé ÀÌ À¯Æ¿¸®Æ¼°¡ ¾Ë¾Æ¼ ¸ðµç pluginÀ» ¹Þ¾Æ¼ ¼³Ä¡ÇØÁØ´Ù.
¡á °á°ú º¸°í¼¸¦ HTML, ASCIIµî ¿©·¯ °¡Áö ÇüÅ·Π·¹Æ÷ÆÃ ÇØÁØ´Ù.
Top
2. NessusÀÇ º¸¾È Ãë¾àÁ¡ Á¡°Ë Ç׸ñ
NessusÀÇ º¸¾È Á¡°ËÀº plug-inÇ׸ñÀ» ÅëÇØ ÀÌ·ç¾îÁö´Âµ¥ 2001³â 7¿ù ÇöÀç 18°³ÀÇ family, 679°³ÀÇ library¸¦
Á¦°øÇÑ´Ù. ÀÌ·¯ÇÑ plug-in familyµéÀº ³Ð°í ´Ù¾çÇÏ°Ô security hole(Ãë¾àÁ¡)¿¡ ´ëÇØ test ÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù. ¿¹¸¦ µé¾î
Backdoors family´Â BackOrifice, NetBus, SubSeven, trin00µî 27°³ÀÇ Ç׸ñÀÌ runningµÇ´ÂÁö
Á¡°ËÇØÁØ´Ù.
Nessus¿¡¼ Á¦°øÇÏ´Â plug- in Ç׸ñÀ» »ìÆìº¸¸é ´ÙÀ½°ú °°´Ù.
|
Family |
plug- in ¼ö |
Family Member ¿¹ |
|
Backdoors |
27 |
BackOrifice, NetBus, SubSeven, trin00 |
|
CGI abuses |
208 |
cgi, Overflows |
|
Denial of Service |
88 |
teardrop, buffer overflow,WINS UDP flood denial, SunKill |
|
Finger abuses |
8 |
in.fingerd |command@host bug |
|
Firewalls |
12 |
Proxy accepts CONNECT requests
Usable remote proxy on any port |
|
FTP |
38 |
Anonymous FTP enabled
wu-ftpd SITE EXEC vulnerability |
|
Gain a shell remotely |
19 |
SSH Overflow, rsh on finger output |
|
Gain root remotely |
47 |
BIND vulnerable to overflows,
Imap buffer overflow, |
|
General |
26 |
Determine which version of BIND name daemon is running
FTP Server type and version |
|
Misc. |
35 |
Services,Default accounts |
|
NIS |
2 |
NIS server, bootparamd service |
|
Port scanners |
6 |
Ping the remote host, TCP SYN scan |
|
Remote file access |
33 |
NFS export, Check for Apache Multiple / vulnerability |
|
RPC |
38 |
RPC portmapper, statd service |
|
SMTP problems |
21 |
EXPN and VRFY commands,
Mail relaying |
|
SNMP |
8 |
Default community names of the SNMP Agent, An SNMP Agent is running |
|
Useless services |
12 |
Telnet, Echo port open, rlogin |
|
Windows |
51 |
Using NetBIOS to retrieve information from a Windows host
SMB log in |
Top
3. Nessus¼³Ä¡
Nessus´Â server-client ±¸Á¶·Î µ¿À۵ȴÙ.
UNIX°è¿¿¡¼´Â Nessus¼¹ö¸¦ ±¸ÃàÇÒ ¼ö ÀÖÁö¸¸ Win32°è¿¿¡¼´Â Nessus¼¹ö¸¦ ±¸ÃàÇÒ ¼ö ¾ø°í, Ŭ¶óÀÌ¾ðÆ®¸¦ ¼³Ä¡ÇÏ¿©
UNIX°è¿ Nessus¼¹ö¿¡ Á¢¼ÓÇÏ¿© ½ÇÇàÇÒ ¼ö ÀÖ´Ù.
Nessus´Â http://www.nessus.org/¿¡¼ ´Ù¿î¹Þ¾Æ ¼³Ä¡ÇÒ ¼ö Àִµ¥,
·Posix download page : Unix°è¿ÀÇ ½Ã½ºÅÛ (Solaris, FreeBSD, GNU/Linuxµî) ·Win32
download page : Microsoft Windows »ç¿ëÀÚµé ·Java download page : ÀÚ¹Ù±â¹Ý NessusŬ¶óÀ̾ðÆ®
¼³Ä¡½Ã
À§ÀÇ ¼¼°¡Áö °æ¿ìÁß Àڽſ¡°Ô ¸Â´Â Nessus¸¦ ´Ù¿î¹Þ¾Æ ¼³Ä¡ÇÏ¸é µÈ´Ù.
Nessus¼¹ö¸¦ ¼³Ä¡Çϱâ À§Çؼ´Â ¿ì¼± ¾Æ·¡ÀÇ »çÀüµµ±¸µéÀÌ ¼³Ä¡µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù.
·GTK : GTK´Â GIMP¸¦ ¸¸µé±â À§ÇÑ ÅøÅ¶À¸·Î Nessus Ŭ¶óÀÌ¾ðÆ®¸¦ »ç¿ëÇϱâ À§Çؼ´Â »çÀü¿¡ ¼³Ä¡µÇ¾î¾ß ÇÑ´Ù. ´Ù¿î¹ÞÀ» ¼ö
ÀÖ´Â °÷ : ftp://ftp.gimp.org/pub/gtk/v1.2 ·Nmap : Nmap´Â ÇöÀç °¡Àå ¸¹ÀÌ ¾²À̰í ÀÖ´Â ¶Ù¾î³ Æ÷Æ®
½ºÄ³³Ê(port scanner)·Î ´Ù¾çÇÑ ½ºÄ³´×À» Á¦°øÇÑ´Ù. ´Ù¿î¹ÞÀ» ¼ö ÀÖ´Â °÷ :
http://www.insecure.org/nmap/ ·m4 : gmp library°¡ ¼³Ä¡µÇ¾î ÀÖÀ¸¸é ¼±ÅûçÇ×À¸·Î libgmp°¡ ¼³Ä¡µÇ¾î
ÀÖÀ¸¸é ÇÊ¿ä¾ø´Ù. ´Ù¿î¹ÞÀ»¼ö ÀÖ´Â °÷ : ftp.gnu.org/pub/gnu/m4
1) Nessus ¼¹ö ¼³Ä¡
¨ç ÇÁ·Î±×·¥ ÆÄÀÏ ´Ù¿î·Îµå
http://www.nessus.org/posix.html¿¡ °¡¸é ´Ù¿î ¹ÞÀ»¼ö ÀÖ´Â ¹Ì·¯ »çÀÌÆ®µéÀÌ ÀÖ´Ù.
2001³â 7¿ù ÇöÀç ¾ÈÁ¤ÀûÀ¸·Î ³ª¿Â Nessus ¹öÀüÀº 1.0.8·Î ´ÙÀ½ 4°³ÀÇ fileÀ» ´Ù¿î¹Þ°í ¾ÐÃàÀ» Ǭ´Ù.
¦¹nessus-libraries-1.0.8.tar.gz ¦¹libnasl-1.0.8.tar.gz ¦¹nessus-core-1.0.8.tar.gz ¦¹nessus-plugins-1.0.8.tar.gz
Top
¨è Compile Çϱâ
À§¿¡¼ ´Ù¿î¹ÞÀº 4°³ÀÇ ÆÄÀϵéÀÇ ¾ÐÃàÀ» Ç®¸é ´ÙÀ½ 4°³ÀÇ µð·ºÅ丮°¡ »ý¼ºµÈ´Ù.
drwxr-xr-x 7 root kong 4096 7¿ù 20 10:33 nessus-plugins drwxr-xr-x 7 root
kong 4096 7¿ù 20 10:32 nessus-libraries drwxr-xr-x 7 root kong 4096 7¿ù 20
10:32 nessus-core drwxr-xr-x 5 root kong 4096 7¿ù 20 10:31 libnasl
¿ì¼± nessus-libraries¸¦ ¼³Ä¡ÇÏ´Â °úÁ¤À» º¸µµ·ÏÇÏÀÚ.
# cd nessus-libraries # ./configure ====>
nessus-libraries¸¦ ¼³Ä¡Çϱâ Àü¿¡ ¸ÕÀú configure ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÑ´Ù. # make ====>
ÄÄÆÄÀÏÇÑ´Ù. # make install
À§ÀÇ ¼ø¼´ë·Î libnasl , nessus-core , nessus-pluginsµµ ¼³Ä¡ÇÏ¸é µÇ´Âµ¥ À̶§´Â root±ÇÇÑÀ¸·Î ÇÏ¿©¾ß ÇÑ´Ù.
¡Ø ¸®´ª½º »ç¿ëÀÚ¶ó¸é /etc/ld.so.conf¿¡ °¡¼ /usr/local/lib¸¦ Ãß°¡ÇØÁÖ°í ldconfig¸¦ ½ÇÇàÇÑ´Ù.
# vi
/etc/ld.so.conf /usr/X11R6/lib /usr/lib /usr/kerberos/lib /usr/lib/gconv /usr/local/lib ========> À̺κÐÀ» Ãß°¡ÇØÁÖ¾î¾ß ÇÔ. #
ldconfig -v
Solaris »ç¿ëÀÚ¶ó¸é
export LD_LIBRARY_PATH=$LD_LIBRARY_PATH:/usr/local/lib (¶Ç´Â ~/.profile¿¡ Ãß°¡ÇØÁÖ¾î¾ß
ÇÑ´Ù.)
Top
¨é »ç¿ëÀÚ Ãß°¡
nessusd¼¹ö´Â »ç¿ëÀÚµéÀÇ database¸¦ °¡Áö°í ÀÖ°í, /usr/local/sbin¹ØÀÇ nessus-adduser utility¸¦
ÅëÇØ »õ·Î¿î »ç¿ëÀÚ¸¦ Ãß°¡ ÇÒ ¼ö ÀÖ´Ù.
|
# ls -alct|more -rwxr-xr-x 1 root root 7920 3¿ù 18 04:42
nessus-adduser* -rwxr-xr-x 1 root root 258684 3¿ù 18 04:42
nessusd* -r-xr-xr-x 1 root root 3700 3¿ù 18 04:33 nessus-update-plugins*
|
¾Æ·¡´Â test¶ó´Â user¸¦ Ãß°¡ÇÏ´Â ¿¹Á¦ÀÌ´Ù.
|
# ./nessus-adduser Add a new nessusd
user ---------------------- Login : test Authentication method
(cipher/plaintext) [cipher] : Is "test" a local user on this machine [
|n]? Ok, treating user "test" as a local user. User
rules ---------- nessusd has a rules system which allows you to restrict
the hosts that test has the right to test. For instance, you may want him
to be able to scan his own host only. Please see the nessus-adduser(8) man
page for the rules syntax Enter the rules for this user, and hit ctrl-D once
you are done : (the user can have an empty rules set) Login :
test Auth. method : cipher, local user connecting from 127.0.0.1 Rules
: Is that ok ? (y/n) [y] y Generating the user key for "test" (please be
patient) Generating primes: ......q............................; Retrying:
...................q...........pg To protect your private key just generated,
enter your personal pass phrase, now. Keep that pass phrase secret. And each
time when you restart nessus, re-enter that pass phrase when you
are asked, for. This prevents anybody else from logging in to the nessus
server using your account. The drawback of a pass phrase is that it will
prevent you from being able to use nessus(1) in a cron job or in a quiet
script. If you do not want to use a pass phrase, enter a blank one. To
change or remove the pass phrase, later on read in the manual page nessus(1)
about the -C option. New pass phrase: Repeat : Pass phrase: + kill
-1 4416 user added. |
Top
¨ê Nessus µ¥¸óÀ» ½ÇÇàÇÑ´Ù.
# ./nessusd -D
2) Client ±¸¼º
nessus µ¥¸óÀ» ±¸µ¿±îÁö ÇÔÀ¸·Î½á ¼¹ö¿¡¼ÀÇ ¼³Á¤Àº ³¡³µ°í, client ºÎºÐÀ» º¸µµ·Ï ÇϰڴÙ. client´Â nessus¸¦
¼³Ä¡ÇÑ ¼¹ö¿¡¼ »ç¿ëÇÒ ¼öµµ ÀÖ°í, À©µµ¿ìµîÀÇ ¿ø°Ý½Ã½ºÅÛ¿¡¼ nessus°¡ ¼³Ä¡µÈ ¼¹ö·Î Á¢¼ÓÇÏ¿© »ç¿ëÇÒ ¼öµµ ÀÖ´Ù. ¼¹ö¿¡¼
client¸¦ ½ÇÇàÇÏ´Â °ÍÀº ¾Æ·¡¿Í °°´Ù.
# nessus
À©µµ¿ì½Ã½ºÅÛ¿¡ nessus client¸¦ ¼³Ä¡Çϱâ À§Çؼ´Â ¿ì¼± http://www.nessus.org/win32.html¿¡¼ À©µµ¿ì
»ç¿ëÀÚ¿ë nessus(WinNessus.zip)¸¦ ´Ù¿î¹Þ°í ¾ÐÃàÀ» Ǭ´Ù. ¾ÐÃàÀ» Ç®°í³ÈÄ Nessus/binÆú´õ ¹Ø¿¡ ¸¸µé¾îÁø
nessus.exe¸¦ ½ÇÇà½Ã۸éµÈ´Ù. Á¦´ë·Î ¼³Ä¡°¡ µÆÀ¸¸é ´ÙÀ½°ú °°Àº ȸéÀÌ ¶á´Ù.
¿©±â¼ Çѹø Passphrase¸¦ ÀÔ·ÂÇÏ¸é ´ÙÀ½¹ø Á¢¼ÓºÎÅÍ´Â °£´ÜÈ÷ password¸¸ ¹¯´Â ȸéÀÌ ³ª¿Â´Ù. ¿©±â¼ Ok¸¦ Ŭ¸¯ÇÏ¸é »ç¿ëÀÚÀÇ
°èÁ¤À» ÀÔ·ÂÇÏ´Â loginâÀÌ ¶á´Ù.
¨ç Login in
login in ȸéÀÌ ¶ß¸é Á¢¼ÓÇÒ nessus ¼¹öÀÇ ipÁÖ¼Ò¿Í »ç¿ëÇÒ °èÁ¤À» ÀÔ·ÂÇÑ ÈÄ Login in ¹öưÀ» Ŭ¸¯ÇÑ´Ù.
¨è Plugins ¼±ÅÃ
½ºÄ³´×ÇÒ plug -inÀ» ¼±ÅÃÇÑ´Ù.
nessusÀÇ º¸¾ÈÃë¾àÁ¡ Á¡°ËÀº plug-in Ç׸ñÀ» ÅëÇØ ÀÌ·ç¾îÁö´Âµ¥ 2001³â 7¿ù ÇöÀç´Â 18°³ÀÇ family, 679°³ÀÇ
library¿¡ ´ëÇØ Á¡°ËÇÒ¼ö ÀÖÀ¸¸ç http://cgi.nessus.org/plugins¿¡¼ ÀÚ¼¼ÇÑ ³»¿ëÀ» º¼ ¼ö ÀÖ´Ù.
Plugin selection¿¡¼ Á¡°ËÇÒ ºÎºÐÀ» Á¤ÇØÁÖ¸é µÇ´Âµ¥ Á¦°øÇÏ´Â Plugin Áß Denial of Service ¿¡ ´ëÇØ üũÇÏ´Â
ºÎºÐÀº ÀÚ½ÅÀÇ ½Ã½ºÅÛÀÌ ¾Æ´Ñ ´Ù¸¥ ¼¹ö¸¦ ½ºÄ³´×ÇÒ °æ¿ì ½ÇÁ¦ °ø°ÝÀ¸·Î ¿ÀÀιÞÀ»¼ö ÀÖÀ¸¹Ç·Î ÁÖÀÇÇÏ¿©¾ß ÇÑ´Ù.
¨é Plugin prefernces
Plugin preferncesºÎºÐÀº º¸¾ÈÁ¡°ËÀ» ÇÒ ¶§ ÇÊ¿äÇÑ ¸î¸îÀÇ argument¿¡ ´ëÇØ Ã¼Å©ÇØÁÖ´Â ºÎºÐÀÌ´Ù. ¿¹¸¦ µé¾î pop2
overflow Á¡°ËÀº °¡´ÉÇÑ pop °èÁ¤ÀÌ ÀÖ¾î¾ß Çϰí, queso pluginÀº configuration ÆÄÀÏÀÇ °æ·Î¸¦ ÁöÁ¤ÇØ¾ß ÇϴµîÀÇ
¼³Á¤À» ÇØÁÖ´Â ºÎºÐÀÌ´Ù.
¨ê scan option
scan optionÀº »ç¿ëÇÒ port scanner¸¦ ¼±ÅÃÇÏ´Â Ç׸ñÀ¸·Î °¡Àå ºü¸£°Ô Á¡°ËÇÒ ¼ö ÀÖ´Â Nmap tcp connect
scanÇ׸ñÀ» ¼±ÅÃÇÏ´Â °ÍÀÌ ÁÁ´Ù.
¨ë target ÁöÁ¤
ÀÌ ºÎºÐÀº ½ºÄµÇÒ È£½ºÆ®¸¦ Á¤ÇÏ´Â ºÎºÐÀ¸·Î local networkÀÇ È£½ºÆ®¿¡ ´ëÇØ¼´Â »ç¼³ ipÁÖ¼Ò¸¦ »ç¿ëÇÒ ¼ö ÀÖÀ¸¸ç ¿©·¯ °³ÀÇ
È£½ºÆ®¸¦ Á¡°ËÇϰíÀÚ ÇÒ ¶§´Â ÄÞ¸¶(,)¸¦ »ç¿ëÇØ È£½ºÆ®¸¦ ±¸ºÐÇϰí 172.16.2.0/24 °°Àº Æ÷¸ËÀ¸·Î ¿©·¯ È£½ºÆ®µéÀ» ÁöÁ¤ÇÒ ¼ö ÀÖ´Ù.
¨ì user
ÀÌ ºÎºÐÀº rules sectionºÎºÐÀ¸·Î Á¡°ËÇÒ ¶§ÀÇ rule¸¦ Á¤ÇØÁÖ´Â ºÎºÐÀÌ´Ù. ¿¹¸¦ µé¾î 172.16.2.0/24 Á¡°ËÇÒ ¶§
172.16.2.152¸¸ Á¦¿ÜÇÏ´Â µîÀÇ ¼³Á¤À» ÇÒ ¶§ »ç¿ëÇÑ´Ù.
start the scan ¹öưÀ» Ŭ¸¯Çϸé target hostµé¿¡ ´ëÇØ ½ºÄ³´×À» ½ÃÀÛÇÑ´Ù.
¨í report
nessus´Â ½ºÄ³´×ÀÌ ³¡³ª¸é ¸ðµç Á¤º¸¸¦ Á¾ÇÕÇØ¼ ¸®Æ÷Æ®¸¦ ÀÛ¼ºÇØ º¸¿©ÁÖ°í ÆÐÄ¡¹æ¹ýµîÀ» ¾È³»ÇØ Áִµ¥ °á°úº¸°í¼´Â HTML, ASC¥±µî
¿øÇÏ´Â ´ë·Î ¼±ÅÃÇÒ ¼ö ÀÖ´Ù.
<Âü°íÀÚ·á>
·http://nessus.org ·http://www.sans.org./infosecFAQ/audit/nessus.htm
Top |