( ) (5/5)
$ sudo apt install git nmap john
git
nmap
“Matrix Reloaded” (https://nmap.org/images/matrix/matrix-hack-screen3.png)
SSH
john (John the Ripper)
bob
(1.9.0)
2024 7-8 — 2024-07-01 – p.26/46
Slide 27
Slide 27 text
I
. . .
. . .
^^;
2024 7-8 — 2024-07-01 – p.27/46
Slide 28
Slide 28 text
Tor (The Onion Router)
→
( )
1
Tor : https://www.torproject.org
Tor
( )
2024 7-8 — 2024-07-01 – p.28/46
Slide 29
Slide 29 text
I
malissa
$ passwd
ESC (GRUB normal + ESC)
recovery mode
root
# mount -o remount,rw /
# passwd malissa
# exit
malissa
Ubuntu OS ( )
2024 7-8 — 2024-07-01 – p.29/46
Slide 30
Slide 30 text
(1)
I ( )
malissa bob
22 SSH
$ nmap -sV -p 22 IP
$ git clone https://github.com/danielmiessler/SecLists.git
bob
malissa bob
“/etc/ssh/sshd_config”
#PasswordAuthentication yes
# ( ) no
$ sudo systemctl restart ssh SSH
malissa bob
2024 7-8 — 2024-07-01 – p.30/46
Slide 31
Slide 31 text
SSH
alice = malissa alice bob “authorized_keys”
bob
$ sudo -s
# cd ../bob/.ssh
# nano authorized_keys
( malissa )
bob
alice
(bob )
malissa bob
2024 7-8 — 2024-07-01 – p.31/46
Slide 32
Slide 32 text
(bob )
alice = malissa
$ sudo usermod -aG sudo bob
sudo malissa bob
2024 7-8 — 2024-07-01 – p.32/46
Slide 33
Slide 33 text
(2)
“/etc/shadow” “/etc/passwd”
alice
malissa
$ unshadow passwdfile.txt shadowfile.txt > crackfile.txt
$ john --wordlist=SecLists/Passwords/Common-Credentials/10-million-password-list-top-100000.txt crackfile.txt
.
.
.
quicksand (bob)
.
.
.
5
bob “10-million-password-list-top-100000.txt”
bob
bob
John the Ripper
2024 7-8 — 2024-07-01 – p.33/46