Nessus ºÐ¼®º¸°í¼­

update : 2001.07

ÀåÀ±¼÷/CERTCC-KR jys@certcc.or.kr

1. °³¿ä

Nessus´Â http://www.nessus.org¿¡¼­ ¹«·á·Î ´Ù¿î¹Þ¾Æ »ç¿ëÇÒ ¼ö ÀÖ´Â º¸¾ÈÃë¾àÁ¡ Á¡°Ëµµ±¸·Î local°ú remote ½Ã½ºÅÛ º¸¾È Ãë¾àÁ¡ ã¾ÆÁÖ´Â µµ±¸ÀÌ´Ù.

»ç¶÷µéÀÌ ¾î¶² º¸¾ÈÅøÀ» ¼±È£ÇÏ´ÂÁö ¾Ë¾Æº¸±â À§ÇØ 2000³â 5¿ù°ú 6¿ù¿¡ 1200¸íÀÇ Nmap»ç¿ëÀÚµéÀ» ´ë»óÀ¸·Î ¼±È£ÇÏ´Â º¸¾ÈÅø Áß 5°³ÀÇ Åø(NmapÀº Á¦¿Ü)À» ÅÃÇϵµ·Ï ÇÏ´Â ¼³¹®Á¶»ç¸¦ ÇØº» °á°ú(http://www.insecure.org/tools.html) Nessus°¡ 1À§¸¦ Â÷ÁöÇÒ Á¤µµ·Î Nessus´Â º¸¾È Ãë¾àÁ¡ Á¡°Ë±â´ÉÀÌ ¶Ù¾î³ª´Ù.

Nessus´Â Renaud Deraison¿¡ ÀÇÇØ ¸¸µé¾îÁö±â ½ÃÀÛÇÏ¿© 1998³â 4¿ù óÀ½ ¹öÀüÀÌ ¹ßÇ¥µÇ¾ú°í, 2001³â 7¿ù ÇöÀç 1.0.8 ¹öÀüÀÌ ¹ßÇ¥µÈ »óÅ´Ù.

NessusÀÇ Æ¯¼ºÀ» »ìÆìº¸¸é ´ÙÀ½°ú °°´Ù.

¡á Nessus´Â »ç¿ëÀÌ ÀÚÀ¯·Ó°í, up-to-date°¡ °£ÆíÇÏ´Ù
Nessus´Â GNU General Public License(GPL)ÇÏ¿¡ ¸ðµç »ç¶÷ÀÌ ÀÚÀ¯·Ó°Ô Àаí code¸¦ ¼öÁ¤ÇÒ ¼ö ÀÖ´Ù.

¡á sever/client±¸Á¶·Î µ¿ÀÛÇÑ´Ù.
server daemonÀÎ nessusd´Â º¸Åë UNIX machine(Linux, *BSD, Solaris)¿¡¼­ ¼öÇàµÇ¾î¾ß Çϰí client´Â Windows 95/98/NT ´Ù¸¥ UNIXÄÄÇ»ÅÍ·Î ¼öÇàµÉ ¼ö ÀÖ´Ù. (GIMP°¡ ¼³Ä¡µÇ¾î ÀÖ¾î¾ß¸¸ ÇÔ.)

¡á nmap°ú gtk¸¦ ±â¹ÝÀ¸·Î ÇÑ´Ù.
Nessus´Â nmapº¸´Ù ´õ¿í Á¤±³Çϰí GUIȯ°æÀ» Á¦°øÇÏ¿© ½±°Ô »ç¿ëÇÒ¼ö ÀÖ´Ù.

¡á plug-in·Î ÀÚ¼¼ÇÑ ºÎºÐ±îÁö Á¡°ËÇÒ ¼ö ÀÖ°í plug-in ¾÷µ¥ÀÌÆ®µµ °£´ÜÈ÷ ÇÒ ¼ö ÀÖ´Ù.
Nessus´Â 2001³â 7¿ù ÇöÀç 18°³ÀÇ family, 679°³ÀÇ library¸¦ Á¦°øÇØ ÀÚ¼¼ÇÑ ºÎºÐ±îÁö Á¡°ËÇØÁÙ ¼ö ÀÖ°Ô ÇÏ°í °£´ÜÈ÷ plug-inÀ» ¾÷µ¥ÀÌÆ® ÇÒ ¼ö ÀÖ´Â À¯Æ¿¸®Æ¼¸¦ Á¦°øÇÑ´Ù.
¸ðµç ¼³Ä¡°¡ ³¡³ª¸é /usr/local/sbin/nessus-update-pluginsÆÄÀÏÀÌ »ý±â´Âµ¥ root±ÇÇÑÀ¸·Î ÀÌ ÆÄÀÏÀ» ½ÇÇàÇϸé ÀÌ À¯Æ¿¸®Æ¼°¡ ¾Ë¾Æ¼­ ¸ðµç pluginÀ» ¹Þ¾Æ¼­ ¼³Ä¡ÇØÁØ´Ù.

¡á °á°ú º¸°í¼­¸¦ HTML, ASCIIµî ¿©·¯ °¡Áö ÇüÅ·Π·¹Æ÷ÆÃ ÇØÁØ´Ù.

Top

2. NessusÀÇ º¸¾È Ãë¾àÁ¡ Á¡°Ë Ç׸ñ

NessusÀÇ º¸¾È Á¡°ËÀº plug-inÇ׸ñÀ» ÅëÇØ ÀÌ·ç¾îÁö´Âµ¥ 2001³â 7¿ù ÇöÀç 18°³ÀÇ family, 679°³ÀÇ library¸¦ Á¦°øÇÑ´Ù. ÀÌ·¯ÇÑ plug-in familyµéÀº ³Ð°í ´Ù¾çÇÏ°Ô security hole(Ãë¾àÁ¡)¿¡ ´ëÇØ test ÇÒ ¼ö ÀÖ°Ô ÇÑ´Ù. ¿¹¸¦ µé¾î Backdoors family´Â BackOrifice, NetBus, SubSeven, trin00µî 27°³ÀÇ Ç׸ñÀÌ runningµÇ´ÂÁö Á¡°ËÇØÁØ´Ù.

Nessus¿¡¼­ Á¦°øÇÏ´Â plug- in Ç׸ñÀ» »ìÆìº¸¸é ´ÙÀ½°ú °°´Ù.

Family

plug- in ¼ö

Family Member ¿¹

Backdoors

27

BackOrifice, NetBus, SubSeven, trin00

CGI abuses

208

cgi, Overflows

Denial of Service

88

teardrop, buffer overflow,WINS UDP flood denial, SunKill

Finger abuses

8

in.fingerd |command@host bug

Firewalls

12

Proxy accepts CONNECT requests

Usable remote proxy on any port

FTP

38

Anonymous FTP enabled

wu-ftpd SITE EXEC vulnerability

Gain a shell remotely

19

SSH Overflow, rsh on finger output

Gain root remotely

47

BIND vulnerable to overflows,

Imap buffer overflow,

General

26

Determine which version of BIND name daemon is running

FTP Server type and version

Misc.

35

Services,Default accounts

NIS

2

NIS server, bootparamd service

Port scanners

6

Ping the remote host, TCP SYN scan

Remote file access

33

NFS export, Check for Apache Multiple / vulnerability

RPC

38

RPC portmapper, statd service

SMTP problems

21

EXPN and VRFY commands,

Mail relaying

SNMP

8

Default community names of the SNMP Agent, An SNMP Agent is running

Useless services

12

Telnet, Echo port open, rlogin

Windows

51

Using NetBIOS to retrieve information from a Windows host

SMB log in

Top

3. Nessus¼³Ä¡

Nessus´Â server-client ±¸Á¶·Î µ¿À۵ȴÙ.

UNIX°è¿­¿¡¼­´Â Nessus¼­¹ö¸¦ ±¸ÃàÇÒ ¼ö ÀÖÁö¸¸ Win32°è¿­¿¡¼­´Â Nessus¼­¹ö¸¦ ±¸ÃàÇÒ ¼ö ¾ø°í, Ŭ¶óÀÌ¾ðÆ®¸¦ ¼³Ä¡ÇÏ¿© UNIX°è¿­ Nessus¼­¹ö¿¡ Á¢¼ÓÇÏ¿© ½ÇÇàÇÒ ¼ö ÀÖ´Ù.

Nessus´Â http://www.nessus.org/¿¡¼­ ´Ù¿î¹Þ¾Æ ¼³Ä¡ÇÒ ¼ö Àִµ¥,

·Posix download page : Unix°è¿­ÀÇ ½Ã½ºÅÛ (Solaris, FreeBSD, GNU/Linuxµî)
·Win32 download page : Microsoft Windows »ç¿ëÀÚµé
·Java download page : ÀÚ¹Ù±â¹Ý NessusŬ¶óÀÌ¾ðÆ® ¼³Ä¡½Ã

À§ÀÇ ¼¼°¡Áö °æ¿ìÁß Àڽſ¡°Ô ¸Â´Â Nessus¸¦ ´Ù¿î¹Þ¾Æ ¼³Ä¡ÇÏ¸é µÈ´Ù.

Nessus¼­¹ö¸¦ ¼³Ä¡Çϱâ À§Çؼ­´Â ¿ì¼± ¾Æ·¡ÀÇ »çÀüµµ±¸µéÀÌ ¼³Ä¡µÇ¾î ÀÖ¾î¾ß ÇÑ´Ù.

·GTK : GTK´Â GIMP¸¦ ¸¸µé±â À§ÇÑ ÅøÅ¶À¸·Î Nessus Ŭ¶óÀÌ¾ðÆ®¸¦ »ç¿ëÇϱâ À§Çؼ­´Â »çÀü¿¡ ¼³Ä¡µÇ¾î¾ß ÇÑ´Ù.
´Ù¿î¹ÞÀ» ¼ö ÀÖ´Â °÷ : ftp://ftp.gimp.org/pub/gtk/v1.2
·Nmap : Nmap´Â ÇöÀç °¡Àå ¸¹ÀÌ ¾²À̰í ÀÖ´Â ¶Ù¾î³­ Æ÷Æ® ½ºÄ³³Ê(port scanner)·Î ´Ù¾çÇÑ ½ºÄ³´×À» Á¦°øÇÑ´Ù.
´Ù¿î¹ÞÀ» ¼ö ÀÖ´Â °÷ : http://www.insecure.org/nmap/
·m4 : gmp library°¡ ¼³Ä¡µÇ¾î ÀÖÀ¸¸é ¼±ÅûçÇ×À¸·Î libgmp°¡ ¼³Ä¡µÇ¾î ÀÖÀ¸¸é ÇÊ¿ä¾ø´Ù.
´Ù¿î¹ÞÀ»¼ö ÀÖ´Â °÷ : ftp.gnu.org/pub/gnu/m4

1) Nessus ¼­¹ö ¼³Ä¡

¨ç ÇÁ·Î±×·¥ ÆÄÀÏ ´Ù¿î·Îµå

http://www.nessus.org/posix.html¿¡ °¡¸é ´Ù¿î ¹ÞÀ»¼ö ÀÖ´Â ¹Ì·¯ »çÀÌÆ®µéÀÌ ÀÖ´Ù.

2001³â 7¿ù ÇöÀç ¾ÈÁ¤ÀûÀ¸·Î ³ª¿Â Nessus ¹öÀüÀº 1.0.8·Î ´ÙÀ½ 4°³ÀÇ fileÀ» ´Ù¿î¹Þ°í ¾ÐÃàÀ» Ǭ´Ù.

¦¹nessus-libraries-1.0.8.tar.gz
¦¹libnasl-1.0.8.tar.gz
¦¹nessus-core-1.0.8.tar.gz
¦¹nessus-plugins-1.0.8.tar.gz

Top

¨è Compile Çϱâ

À§¿¡¼­ ´Ù¿î¹ÞÀº 4°³ÀÇ ÆÄÀϵéÀÇ ¾ÐÃàÀ» Ç®¸é ´ÙÀ½ 4°³ÀÇ µð·ºÅ丮°¡ »ý¼ºµÈ´Ù.

drwxr-xr-x 7 root kong 4096 7¿ù 20 10:33 nessus-plugins
drwxr-xr-x 7 root kong 4096 7¿ù 20 10:32 nessus-libraries
drwxr-xr-x 7 root kong 4096 7¿ù 20 10:32 nessus-core
drwxr-xr-x 5 root kong 4096 7¿ù 20 10:31 libnasl

¿ì¼± nessus-libraries¸¦ ¼³Ä¡ÇÏ´Â °úÁ¤À» º¸µµ·ÏÇÏÀÚ.

# cd nessus-libraries
# ./configure ====> nessus-libraries¸¦ ¼³Ä¡Çϱâ Àü¿¡ ¸ÕÀú configure ½ºÅ©¸³Æ®¸¦ ½ÇÇàÇÑ´Ù.
# make ====> ÄÄÆÄÀÏÇÑ´Ù.
# make install

À§ÀÇ ¼ø¼­´ë·Î libnasl , nessus-core , nessus-pluginsµµ ¼³Ä¡ÇÏ¸é µÇ´Âµ¥ À̶§´Â root±ÇÇÑÀ¸·Î ÇÏ¿©¾ß ÇÑ´Ù.

¡Ø ¸®´ª½º »ç¿ëÀÚ¶ó¸é /etc/ld.so.conf¿¡ °¡¼­ /usr/local/lib¸¦ Ãß°¡ÇØÁÖ°í ldconfig¸¦ ½ÇÇàÇÑ´Ù.

# vi /etc/ld.so.conf
/usr/X11R6/lib
/usr/lib
/usr/kerberos/lib
/usr/lib/gconv
/usr/local/lib ========> À̺κÐÀ» Ãß°¡ÇØÁÖ¾î¾ß ÇÔ.
# ldconfig -v

Solaris »ç¿ëÀÚ¶ó¸é

export LD_LIBRARY_PATH=$LD_LIBRARY_PATH:/usr/local/lib (¶Ç´Â ~/.profile¿¡ Ãß°¡ÇØÁÖ¾î¾ß ÇÑ´Ù.)

Top

¨é »ç¿ëÀÚ Ãß°¡

nessusd¼­¹ö´Â »ç¿ëÀÚµéÀÇ database¸¦ °¡Áö°í ÀÖ°í, /usr/local/sbin¹ØÀÇ nessus-adduser utility¸¦ ÅëÇØ »õ·Î¿î »ç¿ëÀÚ¸¦ Ãß°¡ ÇÒ ¼ö ÀÖ´Ù.

# ls -alct|more
-rwxr-xr-x 1 root root 7920 3¿ù 18 04:42 nessus-adduser*
-rwxr-xr-x 1 root root 258684 3¿ù 18 04:42 nessusd*
-r-xr-xr-x 1 root root 3700 3¿ù 18 04:33 nessus-update-plugins*

¾Æ·¡´Â test¶ó´Â user¸¦ Ãß°¡ÇÏ´Â ¿¹Á¦ÀÌ´Ù.

# ./nessus-adduser
Add a new nessusd user
----------------------
Login : test
Authentication method (cipher/plaintext) [cipher] :
Is "test" a local user on this machine [ |n]?
Ok, treating user "test" as a local user.
User rules
----------
nessusd has a rules system which allows you to restrict the hosts
that test has the right to test. For instance, you may want
him to be able to scan his own host only.
Please see the nessus-adduser(8) man page for the rules syntax
Enter the rules for this user, and hit ctrl-D once you are done :
(the user can have an empty rules set)
Login : test
Auth. method : cipher, local user connecting from 127.0.0.1
Rules :
Is that ok ? (y/n) [y] y
Generating the user key for "test" (please be patient)
Generating primes: ......q............................;
Retrying: ...................q...........pg
To protect your private key just generated, enter your personal
pass phrase, now. Keep that pass phrase secret. And each time
when you restart nessus, re-enter that pass phrase when you are
asked, for. This prevents anybody else from logging in to the
nessus server using your account.
The drawback of a pass phrase is that it will prevent you from being
able to use nessus(1) in a cron job or in a quiet script.
If you do not want to use a pass phrase, enter a blank one.
To change or remove the pass phrase, later on read in the manual
page nessus(1) about the -C option.
New pass phrase:
Repeat :
Pass phrase:
+ kill -1 4416
user added.

Top

¨ê Nessus µ¥¸óÀ» ½ÇÇàÇÑ´Ù.

# ./nessusd -D

2) Client ±¸¼º

nessus µ¥¸óÀ» ±¸µ¿±îÁö ÇÔÀ¸·Î½á ¼­¹ö¿¡¼­ÀÇ ¼³Á¤Àº ³¡³µ°í, client ºÎºÐÀ» º¸µµ·Ï ÇϰڴÙ.
client´Â nessus¸¦ ¼³Ä¡ÇÑ ¼­¹ö¿¡¼­ »ç¿ëÇÒ ¼öµµ ÀÖ°í, À©µµ¿ìµîÀÇ ¿ø°Ý½Ã½ºÅÛ¿¡¼­ nessus°¡ ¼³Ä¡µÈ ¼­¹ö·Î Á¢¼ÓÇÏ¿© »ç¿ëÇÒ ¼öµµ ÀÖ´Ù.
¼­¹ö¿¡¼­ client¸¦ ½ÇÇàÇÏ´Â °ÍÀº ¾Æ·¡¿Í °°´Ù.

# nessus

À©µµ¿ì½Ã½ºÅÛ¿¡ nessus client¸¦ ¼³Ä¡Çϱâ À§Çؼ­´Â ¿ì¼± http://www.nessus.org/win32.html¿¡¼­ À©µµ¿ì »ç¿ëÀÚ¿ë nessus(WinNessus.zip)¸¦ ´Ù¿î¹Þ°í ¾ÐÃàÀ» Ǭ´Ù.
¾ÐÃàÀ» Ç®°í³­ÈÄ Nessus/binÆú´õ ¹Ø¿¡ ¸¸µé¾îÁø nessus.exe¸¦ ½ÇÇà½Ã۸éµÈ´Ù.
Á¦´ë·Î ¼³Ä¡°¡ µÆÀ¸¸é ´ÙÀ½°ú °°Àº È­¸éÀÌ ¶á´Ù.

¿©±â¼­ Çѹø Passphrase¸¦ ÀÔ·ÂÇÏ¸é ´ÙÀ½¹ø Á¢¼ÓºÎÅÍ´Â °£´ÜÈ÷ password¸¸ ¹¯´Â È­¸éÀÌ ³ª¿Â´Ù. ¿©±â¼­ Ok¸¦ Ŭ¸¯ÇÏ¸é »ç¿ëÀÚÀÇ °èÁ¤À» ÀÔ·ÂÇÏ´Â loginâÀÌ ¶á´Ù.

¨ç Login in

login in È­¸éÀÌ ¶ß¸é Á¢¼ÓÇÒ nessus ¼­¹öÀÇ ipÁÖ¼Ò¿Í »ç¿ëÇÒ °èÁ¤À» ÀÔ·ÂÇÑ ÈÄ Login in ¹öưÀ» Ŭ¸¯ÇÑ´Ù.

¨è Plugins ¼±ÅÃ

½ºÄ³´×ÇÒ plug -inÀ» ¼±ÅÃÇÑ´Ù.

nessusÀÇ º¸¾ÈÃë¾àÁ¡ Á¡°ËÀº plug-in Ç׸ñÀ» ÅëÇØ ÀÌ·ç¾îÁö´Âµ¥ 2001³â 7¿ù ÇöÀç´Â 18°³ÀÇ family, 679°³ÀÇ library¿¡ ´ëÇØ Á¡°ËÇÒ¼ö ÀÖÀ¸¸ç http://cgi.nessus.org/plugins¿¡¼­ ÀÚ¼¼ÇÑ ³»¿ëÀ» º¼ ¼ö ÀÖ´Ù.

Plugin selection¿¡¼­ Á¡°ËÇÒ ºÎºÐÀ» Á¤ÇØÁÖ¸é µÇ´Âµ¥ Á¦°øÇÏ´Â Plugin Áß Denial of Service ¿¡ ´ëÇØ üũÇÏ´Â ºÎºÐÀº ÀÚ½ÅÀÇ ½Ã½ºÅÛÀÌ ¾Æ´Ñ ´Ù¸¥ ¼­¹ö¸¦ ½ºÄ³´×ÇÒ °æ¿ì ½ÇÁ¦ °ø°ÝÀ¸·Î ¿ÀÀιÞÀ»¼ö ÀÖÀ¸¹Ç·Î ÁÖÀÇÇÏ¿©¾ß ÇÑ´Ù.

¨é Plugin prefernces

Plugin preferncesºÎºÐÀº º¸¾ÈÁ¡°ËÀ» ÇÒ ¶§ ÇÊ¿äÇÑ ¸î¸îÀÇ argument¿¡ ´ëÇØ Ã¼Å©ÇØÁÖ´Â ºÎºÐÀÌ´Ù.
¿¹¸¦ µé¾î pop2 overflow Á¡°ËÀº °¡´ÉÇÑ pop °èÁ¤ÀÌ ÀÖ¾î¾ß Çϰí, queso pluginÀº configuration ÆÄÀÏÀÇ °æ·Î¸¦ ÁöÁ¤ÇØ¾ß ÇϴµîÀÇ ¼³Á¤À» ÇØÁÖ´Â ºÎºÐÀÌ´Ù.

¨ê scan option

scan optionÀº »ç¿ëÇÒ port scanner¸¦ ¼±ÅÃÇÏ´Â Ç׸ñÀ¸·Î °¡Àå ºü¸£°Ô Á¡°ËÇÒ ¼ö ÀÖ´Â Nmap tcp connect scanÇ׸ñÀ» ¼±ÅÃÇÏ´Â °ÍÀÌ ÁÁ´Ù.

¨ë target ÁöÁ¤

ÀÌ ºÎºÐÀº ½ºÄµÇÒ È£½ºÆ®¸¦ Á¤ÇÏ´Â ºÎºÐÀ¸·Î local networkÀÇ È£½ºÆ®¿¡ ´ëÇØ¼­´Â »ç¼³ ipÁÖ¼Ò¸¦ »ç¿ëÇÒ ¼ö ÀÖÀ¸¸ç ¿©·¯ °³ÀÇ È£½ºÆ®¸¦ Á¡°ËÇϰíÀÚ ÇÒ ¶§´Â ÄÞ¸¶(,)¸¦ »ç¿ëÇØ È£½ºÆ®¸¦ ±¸ºÐÇϰí 172.16.2.0/24 °°Àº Æ÷¸ËÀ¸·Î ¿©·¯ È£½ºÆ®µéÀ» ÁöÁ¤ÇÒ ¼ö ÀÖ´Ù.

¨ì user

ÀÌ ºÎºÐÀº rules sectionºÎºÐÀ¸·Î Á¡°ËÇÒ ¶§ÀÇ rule¸¦ Á¤ÇØÁÖ´Â ºÎºÐÀÌ´Ù.
¿¹¸¦ µé¾î 172.16.2.0/24 Á¡°ËÇÒ ¶§ 172.16.2.152¸¸ Á¦¿ÜÇÏ´Â µîÀÇ ¼³Á¤À» ÇÒ ¶§ »ç¿ëÇÑ´Ù.

start the scan ¹öưÀ» Ŭ¸¯Çϸé target hostµé¿¡ ´ëÇØ ½ºÄ³´×À» ½ÃÀÛÇÑ´Ù.

¨í report

nessus´Â ½ºÄ³´×ÀÌ ³¡³ª¸é ¸ðµç Á¤º¸¸¦ Á¾ÇÕÇØ¼­ ¸®Æ÷Æ®¸¦ ÀÛ¼ºÇØ º¸¿©ÁÖ°í ÆÐÄ¡¹æ¹ýµîÀ» ¾È³»ÇØ Áִµ¥ °á°úº¸°í¼­´Â HTML, ASC¥±µî ¿øÇÏ´Â ´ë·Î ¼±ÅÃÇÒ ¼ö ÀÖ´Ù.

<Âü°íÀÚ·á>

·http://nessus.org
·http://www.sans.org./infosecFAQ/audit/nessus.htm

Top

 

ÀÚ·áÁ¦°ø : CERTCC-KR : Çѱ¹Á¤º¸º¸È£ÁøÈï¿ø