<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0">
  <channel>
    <title>보안지식꾼</title>
    <link>https://securitymax.tistory.com/</link>
    <description>그냥 합니다.</description>
    <language>ko</language>
    <pubDate>Tue, 23 Jun 2026 15:44:09 +0900</pubDate>
    <generator>TISTORY</generator>
    <ttl>100</ttl>
    <managingEditor>보안보</managingEditor>
    <image>
      <title>보안지식꾼</title>
      <url>https://tistory1.daumcdn.net/tistory/2961933/attach/3dd6fdb2634a4ad3b1e6e40617b90a4c</url>
      <link>https://securitymax.tistory.com</link>
    </image>
    <item>
      <title>[bWAPP-Low] HTML Injection - Reflected (GET)</title>
      <link>https://securitymax.tistory.com/146</link>
      <description>&lt;p data-ke-size=&quot;size18&quot;&gt;&lt;b&gt;HTML Injection 이란?&amp;nbsp;&lt;/b&gt;&lt;/p&gt;
&lt;blockquote data-ke-style=&quot;style2&quot;&gt;사용자가 연결요청한 페이지에 악의적인 HTML 태그를 삽입하여 의도하지 않은 내용을 보게 하거나 악의적인 사이트에 연결되도록 하는 공격기법&lt;/blockquote&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size18&quot;&gt;&lt;b&gt;HTML Injection - Reflected (GET)&lt;/b&gt;&lt;/p&gt;
&lt;blockquote data-ke-style=&quot;style2&quot;&gt;HTML 태그로 악성 파일을 다운로드하도록 링크 또는 이미지를 &lt;b&gt;URL에 삽입&lt;/b&gt;하여 악의적인 사이트로 실행되게 하는 공격&lt;/blockquote&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;HTML Injection - Reflected (GET) / 문제 &lt;span&gt;난이도 : Low&amp;nbsp;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1158&quot; data-origin-height=&quot;1007&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/PIocS/btrIddpglVJ/b44D13MPUrJkvisa9FvYDk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/PIocS/btrIddpglVJ/b44D13MPUrJkvisa9FvYDk/img.png&quot; data-alt=&quot;htmli_get.php&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/PIocS/btrIddpglVJ/b44D13MPUrJkvisa9FvYDk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FPIocS%2FbtrIddpglVJ%2Fb44D13MPUrJkvisa9FvYDk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;637&quot; height=&quot;554&quot; data-origin-width=&quot;1158&quot; data-origin-height=&quot;1007&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;htmli_get.php&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;ㅇ 아이디와 패스워드를 임의로 bee, box로 입력해서 burp suite 데이터 확인&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1192&quot; data-origin-height=&quot;420&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/u57XQ/btrH76ryVv2/NhyVrmYRTkAli9TtqfC7h0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/u57XQ/btrH76ryVv2/NhyVrmYRTkAli9TtqfC7h0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/u57XQ/btrH76ryVv2/NhyVrmYRTkAli9TtqfC7h0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fu57XQ%2FbtrH76ryVv2%2FNhyVrmYRTkAli9TtqfC7h0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;800&quot; height=&quot;282&quot; data-origin-width=&quot;1192&quot; data-origin-height=&quot;420&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;ㅇ 입력받는 변수 ID = firstname, PW = lastname&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1216&quot; data-origin-height=&quot;129&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/EekC9/btrIbM6YiOd/GczHe077Kra4YJmTFdwZUk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/EekC9/btrIbM6YiOd/GczHe077Kra4YJmTFdwZUk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/EekC9/btrIbM6YiOd/GczHe077Kra4YJmTFdwZUk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FEekC9%2FbtrIbM6YiOd%2FGczHe077Kra4YJmTFdwZUk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;1216&quot; height=&quot;129&quot; data-origin-width=&quot;1216&quot; data-origin-height=&quot;129&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;ㅇ 난이도 Low는 URL 인코딩 없이 그대로 입력값이 삽입됨&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1187&quot; data-origin-height=&quot;396&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/vy7iT/btrIfRTgFCT/Tup9B8IPAnU8TLlClJliW0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/vy7iT/btrIfRTgFCT/Tup9B8IPAnU8TLlClJliW0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/vy7iT/btrIfRTgFCT/Tup9B8IPAnU8TLlClJliW0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fvy7iT%2FbtrIfRTgFCT%2FTup9B8IPAnU8TLlClJliW0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;785&quot; height=&quot;262&quot; data-origin-width=&quot;1187&quot; data-origin-height=&quot;396&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;ㅇ 그렇다면, 내용을 응용하여 위대한 개츠비 이미지태그와 네이버 링크를 삽입 해보자&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;First name : &amp;lt;h1&amp;gt;The&amp;nbsp;Great&amp;nbsp;Gatsby&amp;lt;/h1&amp;gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;Last name : &amp;lt;a href = &quot;https://www.naver.com&quot;&amp;gt;&amp;lt;img&amp;nbsp;src=&quot;그림URL&quot;&amp;gt;&amp;lt;/a&amp;gt;&lt;/b&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1214&quot; data-origin-height=&quot;1129&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/kZSmR/btrIdePeX5h/SGu11aeGp2FeDa08EC6Fp0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/kZSmR/btrIdePeX5h/SGu11aeGp2FeDa08EC6Fp0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/kZSmR/btrIdePeX5h/SGu11aeGp2FeDa08EC6Fp0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FkZSmR%2FbtrIdePeX5h%2FSGu11aeGp2FeDa08EC6Fp0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;644&quot; height=&quot;599&quot; data-origin-width=&quot;1214&quot; data-origin-height=&quot;1129&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;ㅇ HTML Injection - Reflected(GET) 공격을 활용한 개츠비 띄우기 성공&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;fileblock&quot; data-ke-align=&quot;alignCenter&quot;&gt;&lt;a href=&quot;https://blog.kakaocdn.net/dn/oetcE/btrIdxut43W/i11W8HxTIF1WIL6Qr0l5hK/htmli_get.php?attach=1&amp;amp;knm=tfile.php&quot; class=&quot;&quot;&gt;
    &lt;div class=&quot;image&quot;&gt;&lt;/div&gt;
    &lt;div class=&quot;desc&quot;&gt;&lt;div class=&quot;filename&quot;&gt;&lt;span class=&quot;name&quot;&gt;htmli_get.php&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;size&quot;&gt;0.01MB&lt;/div&gt;
&lt;/div&gt;
  &lt;/a&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;ㅇ 참고용 웹 코드 php 파일 첨부합니다. (bee-box 경로 : /var/www/bWAPP/htmli_get.php)&lt;/p&gt;</description>
      <category>HTML Injection #bWAPP</category>
      <category>Injection #Reflected #웹취약점</category>
      <author>보안보</author>
      <guid isPermaLink="true">https://securitymax.tistory.com/146</guid>
      <comments>https://securitymax.tistory.com/146#entry146comment</comments>
      <pubDate>Tue, 16 Aug 2022 00:00:41 +0900</pubDate>
    </item>
    <item>
      <title>비박스(bee-box) 설치 방법 (웹 취약점 분석/bWAPP)</title>
      <link>https://securitymax.tistory.com/145</link>
      <description>&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;간만에 블로깅을 하면서.. 웹 취약점 분석부터 시작해서 초심으로 공부하고자 합니다!&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;오늘 설치할 웹 모의해킹 실습 도구 비박스(bee-box) &lt;b&gt;bWAPP란?&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;1460&quot; data-origin-height=&quot;971&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/Pqvv4/btrH6IpqKti/RwG8lM5zZXTARvaAETGfv0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/Pqvv4/btrH6IpqKti/RwG8lM5zZXTARvaAETGfv0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/Pqvv4/btrH6IpqKti/RwG8lM5zZXTARvaAETGfv0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FPqvv4%2FbtrH6IpqKti%2FRwG8lM5zZXTARvaAETGfv0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;635&quot; height=&quot;971&quot; data-origin-width=&quot;1460&quot; data-origin-height=&quot;971&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;&amp;lt;번역&amp;gt;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;bWAPP 또는 버그가 있는 웹 애플리케이션은 의도적으로 안전하지 않은 자유 및 오픈 소스 웹 애플리케이션입니다.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;보안 마니아, 개발자, 학생이 웹 취약점을 발견하고 예방할 수 있도록 돕는다.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;bWAPP는 성공적인 침투 테스트와 윤리적인 해킹 프로젝트를 수행할 수 있도록 준비됨.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;무엇이 bWAPP를 그렇게 독특하게 만드는가? 흠, 그것은 100개가 넘는 웹 취약점을 가지고 있음&amp;nbsp;&lt;/span&gt;&lt;b&gt;(약 300개 정도)&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;OWASP Top 10 프로젝트의 모든 위험을 포함하여 알려진 모든 주요 웹 버그를 다룬다.&lt;/span&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;&lt;b&gt;bWAPP는 MySQL 데이터베이스를 사용하는 PHP 응용 프로그램입니다.&lt;/b&gt; Linux/Windows(Apache/)에서 호스팅할 수 있다.&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;IIS 및 MySQL입니다. WAMP 또는 XAMPP와 함께 설치할 수도 있다.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;bWAPP가 미리 설치된 사용자 지정 Linux VM인 bee-box를 다운로드할 수도 있다.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;무료 연습을 포함한 bWAPP란? 소개 튜토리얼 다운로드...&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;bWAPP는 웹 애플리케이션 보안 테스트 및 교육 목적으로만 사용됩니다.&lt;/span&gt;&lt;br /&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;이 무료 오픈 소스 프로젝트로 즐거운 시간을 보내십시오!&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;치어스, 말리크 메젤름&lt;/span&gt;&lt;span style=&quot;background-color: #fdfdfd; color: #000000;&quot;&gt;&lt;/span&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;본 Site: &lt;a href=&quot;http://www.itsecgames.com/index.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;http://www.itsecgames.com/index.htm&lt;/a&gt;&lt;/p&gt;
&lt;figure id=&quot;og_1658676210567&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;opengraph&quot; data-ke-align=&quot;alignCenter&quot; data-og-type=&quot;website&quot; data-og-title=&quot;bWAPP, a buggy web application!&quot; data-og-description=&quot;Home bWAPP, or a buggy web application, is a free and open source deliberately insecure web application. It helps security enthusiasts, developers and students to discover and to prevent web vulnerabilities. bWAPP prepares one to conduct successful penetra&quot; data-og-host=&quot;www.itsecgames.com&quot; data-og-source-url=&quot;http://www.itsecgames.com/index.htm&quot; data-og-url=&quot;http://www.itsecgames.com/index.htm&quot; data-og-image=&quot;&quot;&gt;&lt;a href=&quot;http://www.itsecgames.com/index.htm&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; data-source-url=&quot;http://www.itsecgames.com/index.htm&quot;&gt;
&lt;div class=&quot;og-image&quot; style=&quot;background-image: url();&quot;&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;og-text&quot;&gt;
&lt;p class=&quot;og-title&quot; data-ke-size=&quot;size16&quot;&gt;bWAPP, a buggy web application!&lt;/p&gt;
&lt;p class=&quot;og-desc&quot; data-ke-size=&quot;size16&quot;&gt;Home bWAPP, or a buggy web application, is a free and open source deliberately insecure web application. It helps security enthusiasts, developers and students to discover and to prevent web vulnerabilities. bWAPP prepares one to conduct successful penetra&lt;/p&gt;
&lt;p class=&quot;og-host&quot; data-ke-size=&quot;size16&quot;&gt;www.itsecgames.com&lt;/p&gt;
&lt;/div&gt;
&lt;/a&gt;&lt;/figure&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;이어서 웹 취약점 분석 모의해킹 도구, 아래의 그림과 같이 &lt;span style=&quot;color: #0593d3;&quot;&gt;bee-box_v1.6.7z&lt;/span&gt; 다운로드&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;985&quot; data-origin-height=&quot;597&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/Rkw8n/btrIaPOTa8z/ZmoWad6K37LAijlWNLW2Z1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/Rkw8n/btrIaPOTa8z/ZmoWad6K37LAijlWNLW2Z1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/Rkw8n/btrIaPOTa8z/ZmoWad6K37LAijlWNLW2Z1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FRkw8n%2FbtrIaPOTa8z%2FZmoWad6K37LAijlWNLW2Z1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;560&quot; height=&quot;339&quot; data-origin-width=&quot;985&quot; data-origin-height=&quot;597&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;비박스 Download URL : &lt;a href=&quot;https://sourceforge.net/projects/bwapp/files/bee-box/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot;&gt;https://sourceforge.net/projects/bwapp/files/bee-box/&lt;/a&gt;&lt;/p&gt;
&lt;figure id=&quot;og_1658677000980&quot; contenteditable=&quot;false&quot; data-ke-type=&quot;opengraph&quot; data-ke-align=&quot;alignCenter&quot; data-og-type=&quot;website&quot; data-og-title=&quot;bWAPP -  Browse /bee-box at SourceForge.net&quot; data-og-description=&quot;&quot; data-og-host=&quot;sourceforge.net&quot; data-og-source-url=&quot;https://sourceforge.net/projects/bwapp/files/bee-box/&quot; data-og-url=&quot;https://sourceforge.net/projects/bwapp/files/bee-box/&quot; data-og-image=&quot;&quot;&gt;&lt;a href=&quot;https://sourceforge.net/projects/bwapp/files/bee-box/&quot; target=&quot;_blank&quot; rel=&quot;noopener&quot; data-source-url=&quot;https://sourceforge.net/projects/bwapp/files/bee-box/&quot;&gt;
&lt;div class=&quot;og-image&quot; style=&quot;background-image: url();&quot;&gt;&amp;nbsp;&lt;/div&gt;
&lt;div class=&quot;og-text&quot;&gt;
&lt;p class=&quot;og-title&quot; data-ke-size=&quot;size16&quot;&gt;bWAPP - Browse /bee-box at SourceForge.net&lt;/p&gt;
&lt;p class=&quot;og-desc&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p class=&quot;og-host&quot; data-ke-size=&quot;size16&quot;&gt;sourceforge.net&lt;/p&gt;
&lt;/div&gt;
&lt;/a&gt;&lt;/figure&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;972&quot; data-origin-height=&quot;523&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/kVn2W/btrH3blzNdn/wSUtGoZACdDho624xOuXE0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/kVn2W/btrH3blzNdn/wSUtGoZACdDho624xOuXE0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/kVn2W/btrH3blzNdn/wSUtGoZACdDho624xOuXE0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FkVn2W%2FbtrH3blzNdn%2FwSUtGoZACdDho624xOuXE0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;493&quot; height=&quot;265&quot; data-origin-width=&quot;972&quot; data-origin-height=&quot;523&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;압축을 풀고&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-filename=&quot;blob&quot; data-origin-width=&quot;700&quot; data-origin-height=&quot;472&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bm7EEa/btrH5alGJf0/eokF00rUbgFGuNpaqKtXYk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bm7EEa/btrH5alGJf0/eokF00rUbgFGuNpaqKtXYk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bm7EEa/btrH5alGJf0/eokF00rUbgFGuNpaqKtXYk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fbm7EEa%2FbtrH5alGJf0%2FeokF00rUbgFGuNpaqKtXYk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;647&quot; height=&quot;437&quot; data-filename=&quot;blob&quot; data-origin-width=&quot;700&quot; data-origin-height=&quot;472&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;VM에 bee-box 세팅하고 메모리는 2GB 정도, 웹서비스를 해야하니&lt;b&gt; NAT 설정까지.&lt;/b&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-filename=&quot;blob&quot; data-origin-width=&quot;500&quot; data-origin-height=&quot;411&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/ognit/btrH9HKkU9j/jEh8qLbNej4eLWS6XzsLr1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/ognit/btrH9HKkU9j/jEh8qLbNej4eLWS6XzsLr1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/ognit/btrH9HKkU9j/jEh8qLbNej4eLWS6XzsLr1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fognit%2FbtrH9HKkU9j%2FjEh8qLbNej4eLWS6XzsLr1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;500&quot; height=&quot;411&quot; data-filename=&quot;blob&quot; data-origin-width=&quot;500&quot; data-origin-height=&quot;411&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;VM부팅, 비박스 웹서버 실행 완료!&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;598&quot; data-origin-height=&quot;405&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bI6m16/btrH1cr3gmW/1I85PuAX0i6XnEkookjkK0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bI6m16/btrH1cr3gmW/1I85PuAX0i6XnEkookjkK0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bI6m16/btrH1cr3gmW/1I85PuAX0i6XnEkookjkK0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbI6m16%2FbtrH1cr3gmW%2F1I85PuAX0i6XnEkookjkK0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;598&quot; height=&quot;405&quot; data-origin-width=&quot;598&quot; data-origin-height=&quot;405&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;웹 서버 IP확인&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-ke-mobileStyle=&quot;widthOrigin&quot; data-origin-width=&quot;480&quot; data-origin-height=&quot;363&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bkkhFY/btrH3cdKswx/9DkyV2qz0XhTSQ3aoG8N21/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bkkhFY/btrH3cdKswx/9DkyV2qz0XhTSQ3aoG8N21/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bkkhFY/btrH3cdKswx/9DkyV2qz0XhTSQ3aoG8N21/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbkkhFY%2FbtrH3cdKswx%2F9DkyV2qz0XhTSQ3aoG8N21%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;480&quot; height=&quot;363&quot; data-origin-width=&quot;480&quot; data-origin-height=&quot;363&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot; data-ke-size=&quot;size16&quot;&gt;칼리에서 비박스 웹 사이트 접속 확인&lt;/p&gt;</description>
      <category>비박스 #웹취약점분석 #버그바운티 #bee-box #웹 #모의해킹</category>
      <author>보안보</author>
      <guid isPermaLink="true">https://securitymax.tistory.com/145</guid>
      <comments>https://securitymax.tistory.com/145#entry145comment</comments>
      <pubDate>Mon, 15 Aug 2022 00:00:11 +0900</pubDate>
    </item>
    <item>
      <title>블록체인 (block chain)</title>
      <link>https://securitymax.tistory.com/144</link>
      <description>&lt;p data-ke-size=&quot;size18&quot;&gt;&lt;b&gt;암호화폐? 블록체인?&amp;nbsp;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignLeft&quot; data-origin-width=&quot;1013&quot; data-origin-height=&quot;318&quot; width=&quot;507&quot; data-ke-mobilestyle=&quot;widthOrigin&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/c0rfNT/btrhykOIypj/c6WHmCEBOPQFq7dqUg4fEk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/c0rfNT/btrhykOIypj/c6WHmCEBOPQFq7dqUg4fEk/img.png&quot; data-alt=&quot;출처: 피넥터&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/c0rfNT/btrhykOIypj/c6WHmCEBOPQFq7dqUg4fEk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fc0rfNT%2FbtrhykOIypj%2Fc6WHmCEBOPQFq7dqUg4fEk%2Fimg.png&quot; data-origin-width=&quot;1013&quot; data-origin-height=&quot;318&quot; width=&quot;507&quot; data-ke-mobilestyle=&quot;widthOrigin&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;출처: 피넥터&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;암호화폐 (cryptocurrency)&lt;/b&gt;&lt;/h4&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;암호화폐&lt;/b&gt;(暗號貨幣, cryptocurrency)는&amp;nbsp;&lt;b&gt;암호 기술을 이용하여 만든 디지털 화폐&lt;/b&gt;이다. 암호화폐는 네트워크로 연결된 인터넷 공간에서 암호화된 데이터 형태로 사용된다.&amp;nbsp;&lt;b&gt;(누구나 자유롭게 설계, 발행할 수 있음)&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;대부분의 암호화폐는&amp;nbsp;&lt;b&gt;탈중앙화된 피투피(P2P) 방식의 블록체인(blockchain) 기술을 이용&lt;/b&gt;하여 가치를&amp;nbsp;&lt;b&gt;저장&amp;middot;전송&lt;/b&gt;한다.&lt;br /&gt;&lt;br /&gt;암호화폐는&amp;nbsp;&lt;b&gt;해시(hash)라는 암호화 기술을 이용&lt;/b&gt;하여 만든 전자화폐의 일종으로서, 가치를 보증하는&lt;b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;중앙은행이 없이도 거래의 신뢰성과 안전성을 보장&lt;/b&gt;받을 수 있다.&amp;nbsp;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;블록체인 (Block chain)&lt;/b&gt;&lt;/h4&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignLeft&quot; data-origin-width=&quot;600&quot; data-origin-height=&quot;300&quot; width=&quot;538&quot; height=&quot;269&quot; data-ke-mobilestyle=&quot;widthOrigin&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/G0NLK/btrhy2G5Mqn/zkEfA1aTMBX0TWiMrInLik/img.jpg&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/G0NLK/btrhy2G5Mqn/zkEfA1aTMBX0TWiMrInLik/img.jpg&quot; data-alt=&quot;https://medium.com/@elamachain&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/G0NLK/btrhy2G5Mqn/zkEfA1aTMBX0TWiMrInLik/img.jpg&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FG0NLK%2Fbtrhy2G5Mqn%2FzkEfA1aTMBX0TWiMrInLik%2Fimg.jpg&quot; data-origin-width=&quot;600&quot; data-origin-height=&quot;300&quot; width=&quot;538&quot; height=&quot;269&quot; data-ke-mobilestyle=&quot;widthOrigin&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;https://medium.com/@elamachain&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&lt;b&gt;블록체인&lt;/b&gt;(blockchain)은&amp;nbsp;분산&amp;nbsp;컴퓨팅&amp;nbsp;기술&amp;nbsp;기반의&amp;nbsp;&lt;b&gt;데이터&amp;nbsp;위변조&amp;nbsp;방지&amp;nbsp;기술&lt;/b&gt;이며,&amp;nbsp;&lt;span style=&quot;color: #323232;&quot;&gt;비즈니스 네트워크에서 트랜잭션을&lt;span&gt;&amp;nbsp;&lt;/span&gt;기록하고 자산을 추적하는 프로세스를 효율화하는&lt;b&gt;&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;background-color: #ffc1c8;&quot;&gt;불변의 공유 원장&lt;/span&gt;&lt;/b&gt;이다.&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;P2P 방식을 기반으로 소규모 데이터들이 체인 형태로 무수히 연결되어 형성된 '&lt;b&gt;블록&lt;/b&gt;'이라는&amp;nbsp;&lt;b&gt;분산 데이터 저장 환경에&amp;nbsp;관리 대상 데이터를 저장함으로써 누구도 임의로 수정할 수 없고 누구나 변경의 결과를 열람할 수 있게끔 만드는 기술&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;자산&lt;span style=&quot;color: #323232;&quot;&gt;은 유형 자산(주택, 자동차, 현금, 토지) 또는 무형 자산(지적 재산권, 특허, 저작권, 브랜드)등 사실상&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;b&gt;가치를 지닌 모든 것&lt;/b&gt;들이 블록체인 네트워크 상에서 추적되고 거래됨으로써, 연루된 모든 것들에 대한 리스크를 줄이고 비용을 절감&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;블록에는 해당 블록이 발견되기 이전에 사용자들에게 전파되었던 모든 거래 내역이 기록되어 있고, 이것은 P2P 방식으로 모든 사용자에게 똑같이 전송되므로 거래 내역을 임의로 수정하거나 누락시킬 수 없다.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;블록은 발견된 날짜와 이전 블록에 대한 연결고리를 가지고 있으며 이러한 &lt;span style=&quot;background-color: #ffc1c8;&quot;&gt;블록들의 집합을 블록체인&lt;/span&gt;이라 칭한다.&amp;nbsp;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;기존에&amp;nbsp;전자화폐로&amp;nbsp;거래할&amp;nbsp;때&amp;nbsp;중앙&amp;nbsp;서버에&amp;nbsp;거래&amp;nbsp;기록을&amp;nbsp;보관하는&amp;nbsp;것과는&amp;nbsp;달리,&amp;nbsp;블록체인은&amp;nbsp;모&lt;b&gt;든 사용자에게 거래 기록을&lt;br /&gt;보여주며 서로 비교해 위조를 막는다.&lt;/b&gt;&lt;/p&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style6&quot; /&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;블록체인의 핵심요소&lt;/b&gt;&lt;/h4&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;2395&quot; data-origin-height=&quot;742&quot; data-ke-mobilestyle=&quot;widthOrigin&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/w0HI4/btrhjWuP5ZP/ukQS6jzDL0XozfwK9HXSqk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/w0HI4/btrhjWuP5ZP/ukQS6jzDL0XozfwK9HXSqk/img.png&quot; data-alt=&quot;https://www.ibm.com/kr-ko/topics/what-is-blockchain&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/w0HI4/btrhjWuP5ZP/ukQS6jzDL0XozfwK9HXSqk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fw0HI4%2FbtrhjWuP5ZP%2FukQS6jzDL0XozfwK9HXSqk%2Fimg.png&quot; data-origin-width=&quot;2395&quot; data-origin-height=&quot;742&quot; data-ke-mobilestyle=&quot;widthOrigin&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;https://www.ibm.com/kr-ko/topics/what-is-blockchain&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p data-ke-size=&quot;size18&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;블록체인 종류와 특징&amp;nbsp;&lt;/b&gt;&lt;/h4&gt;
&lt;table style=&quot;border-collapse: collapse; width: 98.3723%; height: 442px;&quot; border=&quot;1&quot; data-ke-align=&quot;alignLeft&quot;&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 10px;&quot;&gt;
&lt;td style=&quot;width: 9.53494%; height: 10px; text-align: center;&quot;&gt;&lt;b&gt;구분&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 29.0697%; height: 10px; text-align: center;&quot;&gt;&lt;b&gt;Public Blockchain&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 10px; text-align: center;&quot;&gt;&lt;b&gt;Consortium Blockchain&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 10px; text-align: center;&quot;&gt;&lt;b&gt;Private Blockchain&lt;/b&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 9.53494%; height: 20px; text-align: center;&quot;&gt;&lt;b&gt;관리자&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 29.0697%; height: 20px; text-align: center;&quot;&gt;모든 거래 참여자&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 20px; text-align: center;&quot;&gt;컨소시엄에 소속된 참여자&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 20px; text-align: center;&quot;&gt;한 중앙 기관이 모든 권한 보유&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 9.53494%; height: 20px; text-align: center;&quot;&gt;&lt;b&gt;거버넌스&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 29.0697%; height: 20px; text-align: center;&quot;&gt;한번 정해진 법칙을 바꾸기 &lt;br /&gt;매우 어려움&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 20px; text-align: center;&quot;&gt;컨소시엄 참여자들의 합의에 따라 법칙을 바꿀 수 있음&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 20px; text-align: center;&quot;&gt;중앙 기관의 의사결정에 따라 &lt;br /&gt;용의하게 법칙을 바꿀 수 있음&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 9.53494%; height: 20px; text-align: center;&quot;&gt;&lt;b&gt;거래속도&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 29.0697%; height: 20px; text-align: center;&quot;&gt;네트워크 확장이 어렵고 &lt;br /&gt;거래 속도가 &lt;b&gt;느림&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 20px; text-align: center;&quot;&gt;네트워크 확장이 쉽고 &lt;br /&gt;거래 속도가 &lt;b&gt;빠름&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 20px; text-align: center;&quot;&gt;네트워크 확장이 매우 쉽고 &lt;br /&gt;거래 속도가 &lt;b&gt;빠름&lt;/b&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 10px;&quot;&gt;
&lt;td style=&quot;width: 9.53494%; height: 10px; text-align: center;&quot;&gt;&lt;b&gt;데이터 접근&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 29.0697%; height: 10px; text-align: center;&quot;&gt;누구나 접근 가능&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 10px; text-align: center;&quot;&gt;하가 받은 사용자만 접근 가능&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 10px; text-align: center;&quot;&gt;허가 받은 사용자만 접근 가능&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 9.53494%; height: 20px; text-align: center;&quot;&gt;&lt;b&gt;식별성&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 29.0697%; height: 20px; text-align: center;&quot;&gt;익명성&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 20px; text-align: center;&quot;&gt;식별 가능&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 20px; text-align: center;&quot;&gt;식별 가능&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 9.53494%; height: 20px; text-align: center;&quot;&gt;&lt;b&gt;거래증명&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 29.0697%; height: 20px; text-align: center;&quot;&gt;PoW, PoS 등 알고리즘에 따라 거래 증명자가 결정됨, 거래 증명자가 누구인지 사전에 알 수 없음&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 20px; text-align: center;&quot;&gt;거래 증명자가 인증을 거쳐 알려진 상태 사전에 합의된 규칙에 따라 거래 검증 및 블록 생성이 이루어짐&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 20px; text-align: center;&quot;&gt;중앙 기관에 의하여 거래 증명이 &lt;br /&gt;이루어짐&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 9.53494%; height: 20px; text-align: center;&quot;&gt;&lt;b&gt;활용사례&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 29.0697%; height: 20px; text-align: center;&quot;&gt;비트코인&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 20px; text-align: center;&quot;&gt;R3 CEV&lt;/td&gt;
&lt;td style=&quot;width: 30.6977%; height: 20px; text-align: center;&quot;&gt;비상장 주식 거래소 플랫폼 '링크'&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;p data-ke-size=&quot;size16&quot;&gt;&amp;nbsp;&lt;/p&gt;</description>
      <category>블록체인</category>
      <category>evm</category>
      <category>분산원장</category>
      <category>블록체인</category>
      <category>비트코인</category>
      <category>암호화폐</category>
      <category>이더리움</category>
      <category>탈중화</category>
      <author>보안보</author>
      <guid isPermaLink="true">https://securitymax.tistory.com/144</guid>
      <comments>https://securitymax.tistory.com/144#entry144comment</comments>
      <pubDate>Tue, 12 Oct 2021 16:40:57 +0900</pubDate>
    </item>
    <item>
      <title>[제 14회] 정보보안 산업기사 (실기)합격후기</title>
      <link>https://securitymax.tistory.com/142</link>
      <description>&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/ceVeyd/btqAqhgNNNE/ASc0mdolUdpWe5BOBQkyF1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/ceVeyd/btqAqhgNNNE/ASc0mdolUdpWe5BOBQkyF1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/ceVeyd/btqAqhgNNNE/ASc0mdolUdpWe5BOBQkyF1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FceVeyd%2FbtqAqhgNNNE%2FASc0mdolUdpWe5BOBQkyF1%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size18&quot;&gt;(11월 9일) 14회 정보보안 산업기사 실기를 응시하여 12월 6일에 결과 발표가 나왔습니다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size18&quot;&gt;다행히 &quot;합격&quot;통보를 받았습니다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size18&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size18&quot;&gt;평균적으로 정보보안 산업기사&amp;amp;기사 시험자체 합격률이 약 10% 안팎이라 그만큼 자격증 취득에 신경을 많이 쓴 자격증입니다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size18&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size18&quot;&gt;확실한 것은, 정보처리 산업기사 자격증과는 비교되지 않는 난이도를 자랑하는 시험입니다.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; width=&quot;816&quot; height=&quot;642&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/5SEjC/btqArTlZNli/XFqPmtieLaGQJ9koJdIQNk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/5SEjC/btqArTlZNli/XFqPmtieLaGQJ9koJdIQNk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/5SEjC/btqArTlZNli/XFqPmtieLaGQJ9koJdIQNk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2F5SEjC%2FbtqArTlZNli%2FXFqPmtieLaGQJ9koJdIQNk%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; width=&quot;816&quot; height=&quot;642&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size18&quot;&gt;자격증 신청 후 약 일주일 정도 지난 뒤, 등기우편으로 배달되어 수령합니다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size18&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; width=&quot;462&quot; height=&quot;590&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/RVzGK/btqAsk4IEXY/Ug16cVmYstkjTzh2HAhltK/img.jpg&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/RVzGK/btqAsk4IEXY/Ug16cVmYstkjTzh2HAhltK/img.jpg&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/RVzGK/btqAsk4IEXY/Ug16cVmYstkjTzh2HAhltK/img.jpg&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FRVzGK%2FbtqAsk4IEXY%2FUg16cVmYstkjTzh2HAhltK%2Fimg.jpg&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; width=&quot;462&quot; height=&quot;590&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size18&quot;&gt;저는 위의 정보보안 기사 책으로 학습하였는데요, 실기 학습하면서 이 책이 정말 많은 도움을 줬던 것 같습니다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size18&quot;&gt;(하지만 시험은 정말 랜덤 범위인지라 얼마만큼 많이 봐야 하는지는 알아서...)&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size18&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size18&quot;&gt;다만, 1 회독은 필수이며 2 회독부터는 눈으로 보며 다시 학습하였습니다.&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style5&quot; /&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;2020년도 정보보안 기사 시험일정&lt;/b&gt;&lt;/h4&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bB19zB/btqAsTFOsqe/f1wNFkFc5zTAbwhKstYwz0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bB19zB/btqAsTFOsqe/f1wNFkFc5zTAbwhKstYwz0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bB19zB/btqAsTFOsqe/f1wNFkFc5zTAbwhKstYwz0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbB19zB%2FbtqAsTFOsqe%2Ff1wNFkFc5zTAbwhKstYwz0%2Fimg.png&quot; data-origin-width=&quot;0&quot; data-origin-height=&quot;0&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;</description>
      <category>정보보안</category>
      <category>정보보안기사 #정보보안산업기사 #2020년 정보보안기사 #시험일정</category>
      <author>보안보</author>
      <guid isPermaLink="true">https://securitymax.tistory.com/142</guid>
      <comments>https://securitymax.tistory.com/142#entry142comment</comments>
      <pubDate>Fri, 13 Dec 2019 20:57:34 +0900</pubDate>
    </item>
    <item>
      <title>안드로이드 - 스레드와 핸들러 예제실습</title>
      <link>https://securitymax.tistory.com/141</link>
      <description>&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;스레드란&lt;/b&gt;&lt;/h4&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size20&quot;&gt;- 스레드는 하나의 프로세스 내에서 실행되는 작업의 단위를 말하며, 하나의 운영 체계에서 여러 개의 프로세스가 동시에 실행되는 환경이 멀티태스킹이고, 하나의 프로세스 내에서 다수의 스레드가 동시에 수행되는 것이 멀티스레딩이다. &lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;br /&gt;&lt;b&gt;핸들러란&lt;/b&gt;&lt;/h4&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&lt;br /&gt;- 안드로이드에서는 화면UI에 접근하는 것을 막아두고 실행 시 생성되는 메인 스레드를&amp;nbsp;&amp;nbsp;통해서만 화면 UI를 변경할 수 있기 때문에 핸들러를 통해서 메인 스레드에 접근하여 UI를 수정한다. &lt;br /&gt;&lt;br /&gt;- 핸들러는 &lt;b&gt;메시지처리 방식&lt;/b&gt;과 &lt;b&gt;Runable객체 실행방식&lt;/b&gt;이 있다. &lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style6&quot; /&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;안드로이드 핸들러 (예제)&lt;/b&gt;&lt;/h4&gt;
&lt;p&gt;&lt;figure class=&quot;imagegridblock&quot;&gt;
  &lt;div class=&quot;image-container&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/NHW44/btqzOWjLjm7/eeWXeVIRBQn0SNG1nFYIHk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/NHW44/btqzOWjLjm7/eeWXeVIRBQn0SNG1nFYIHk/img.png&quot; style=&quot;width: 49.6783%;&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/NHW44/btqzOWjLjm7/eeWXeVIRBQn0SNG1nFYIHk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FNHW44%2FbtqzOWjLjm7%2FeeWXeVIRBQn0SNG1nFYIHk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;&quot; height=&quot;&quot;/&gt;&lt;/span&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cmwrtJ/btqzR3g00W5/BDNVX4C54lILppxThbMjuk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cmwrtJ/btqzR3g00W5/BDNVX4C54lILppxThbMjuk/img.png&quot; style=&quot;width: 47.9962%;&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cmwrtJ/btqzR3g00W5/BDNVX4C54lILppxThbMjuk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FcmwrtJ%2FbtqzR3g00W5%2FBDNVX4C54lILppxThbMjuk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;&quot; height=&quot;&quot;/&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&amp;nbsp;&lt;/h4&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style5&quot; /&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;메시지 처리 방식&lt;span&gt;&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/h4&gt;
&lt;pre id=&quot;code_1574087786744&quot; class=&quot;java&quot; data-ke-language=&quot;java&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;public class MainActivity extends AppCompatActivity {
    Button btnStart;
    TextView tvResult;
    int value=0;
    MainHandler handler;

    @Override
    protected void onCreate(Bundle savedInstanceState) {
        super.onCreate(savedInstanceState);
        setContentView(R.layout.activity_main);

        btnStart = findViewById(R.id.btnStart);
        tvResult = findViewById(R.id.tvResult);

        btnStart.setOnClickListener(new View.OnClickListener() {
            @Override
            public void onClick(View v) {
                BackgroundThread thread = new BackgroundThread();
                thread.start();

            }
        });
        handler = new MainHandler();
    }


    class BackgroundThread extends Thread{

        public void run() {
            for (int i=0; i&amp;lt;10; i++){
                try {
                    Thread.sleep(1000);
                }catch (Exception e){}

                value += 1;
                Log.d(&quot;Thread&quot;, &quot;value: &quot; + value);

                Message message = handler.obtainMessage();
                Bundle bundle = new Bundle();
                bundle.putInt(&quot;value&quot;,value);
                message.setData(bundle);

                handler.sendMessage(message);

            }

        }
    }

    class MainHandler extends Handler{
        @Override
        public void handleMessage(@NonNull Message msg) {
            super.handleMessage(msg);

            Bundle bundle = msg.getData();
            int value = bundle.getInt(&quot;value&quot;);
            tvResult.setText(&quot;value: &quot;+value);
        }
    }
}
&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style6&quot; /&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;Runable 객체&amp;nbsp; 실행방식&lt;/b&gt;&lt;/h4&gt;
&lt;pre id=&quot;code_1574087979368&quot; class=&quot;java&quot; data-ke-language=&quot;java&quot; data-ke-type=&quot;codeblock&quot;&gt;&lt;code&gt;public class MainActivity extends AppCompatActivity {
    Button btnStart;
    TextView tvResult;
    int value=0;
    Handler handler = new Handler();

    @Override
    protected void onCreate(Bundle savedInstanceState) {
        super.onCreate(savedInstanceState);
        setContentView(R.layout.activity_main);

        btnStart = findViewById(R.id.btnStart);
        tvResult = findViewById(R.id.tvResult);

        btnStart.setOnClickListener(new View.OnClickListener() {
            @Override
            public void onClick(View v) {
                BackgroundThread thread = new BackgroundThread();
                thread.start();
            }
        });

    }

    class BackgroundThread extends Thread{

        public void run() {
            for (int i=0; i&amp;lt;10; i++){
                try {
                    Thread.sleep(1000);
                }catch (Exception e){}

                value += 1;
                Log.d(&quot;Thread&quot;, &quot;value: &quot; + value);

                handler.post(new Runnable() {
                    @Override
                    public void run() {
                        tvResult.setText(&quot;value 값: &quot;+value);
                    }
                });

            }
        }
    }
}&lt;/code&gt;&lt;/pre&gt;</description>
      <category>안드로이드 #스레드 #핸들러 #예제</category>
      <author>보안보</author>
      <guid isPermaLink="true">https://securitymax.tistory.com/141</guid>
      <comments>https://securitymax.tistory.com/141#entry141comment</comments>
      <pubDate>Mon, 18 Nov 2019 23:43:08 +0900</pubDate>
    </item>
    <item>
      <title>[Linux] 파일 접근 권한</title>
      <link>https://securitymax.tistory.com/140</link>
      <description>&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/zklFf/btqzM1lb8xT/dK0KmXgF6epsZI51vIGNsK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/zklFf/btqzM1lb8xT/dK0KmXgF6epsZI51vIGNsK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/zklFf/btqzM1lb8xT/dK0KmXgF6epsZI51vIGNsK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FzklFf%2FbtqzM1lb8xT%2FdK0KmXgF6epsZI51vIGNsK%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&lt;b&gt;파일 권한&lt;/b&gt;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;ls -al 명령 또는 stat [File name] 명령을 실행하면 파일의 자세하 정보를 볼 수 있는데, 위의 그림처럼 가장 왼쪽에 파일 접근 권한이 나타난다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;예) &lt;span style=&quot;background-color: #f3c000;&quot;&gt;d&lt;/span&gt; &lt;span style=&quot;background-color: #f89009;&quot;&gt;rwx&lt;/span&gt; &lt;span style=&quot;background-color: #99cefa;&quot;&gt;r-x&lt;/span&gt; &lt;span style=&quot;background-color: #9feec3;&quot;&gt;---&lt;/span&gt;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&lt;b&gt;1 필드&amp;nbsp;:&amp;nbsp;타입&amp;nbsp;&lt;/b&gt; &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;-&amp;nbsp;인&amp;nbsp;경우&amp;nbsp;:&amp;nbsp;파일 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;d&amp;nbsp;인&amp;nbsp;경우&amp;nbsp;:&amp;nbsp;디렉터리 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;|&amp;nbsp;인&amp;nbsp;경우&amp;nbsp;:&amp;nbsp;다른&amp;nbsp;파일을&amp;nbsp;가리키는&amp;nbsp;링크 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;p&amp;nbsp;인&amp;nbsp;경우&amp;nbsp;:&amp;nbsp;pipe.&amp;nbsp;두&amp;nbsp;개의&amp;nbsp;프로그램을&amp;nbsp;연결하는&amp;nbsp;파이프&amp;nbsp;파일. &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;b&amp;nbsp;인&amp;nbsp;경우&amp;nbsp;:&amp;nbsp;block&amp;nbsp;device.&amp;nbsp;블록&amp;nbsp;단위로&amp;nbsp;하드웨어와&amp;nbsp;반응하는&amp;nbsp;파일 &lt;br /&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;c&amp;nbsp;인&amp;nbsp;경우&amp;nbsp;:&amp;nbsp;character&amp;nbsp;device.&amp;nbsp;스트림&amp;nbsp;단위로&amp;nbsp;하드웨어와&amp;nbsp;반응하는&amp;nbsp;파일 &lt;br /&gt;&lt;br /&gt;&lt;b&gt;2~4 필드&lt;/b&gt;&amp;nbsp;:&amp;nbsp;소유주&amp;nbsp;(USER)&amp;nbsp;권한 &lt;br /&gt;&lt;b&gt;5~7 필드&amp;nbsp;&lt;/b&gt;:&amp;nbsp;그룹&amp;nbsp;(Group)&amp;nbsp;권한 &lt;br /&gt;&lt;b&gt;8~10 필드&lt;/b&gt;&amp;nbsp;:&amp;nbsp;나머지&amp;nbsp;(Others)&amp;nbsp;권한 &lt;br /&gt;&lt;br /&gt;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&lt;b&gt;권한을 나타내는 알파벳&amp;nbsp;&lt;/b&gt;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;r : 읽기 권한(read) = 4&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;w: 쓰기 권한(write) = 2&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;x: 실행 권한(excute) = 1&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;-: 권한 없음 = 0&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style6&quot; /&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;chmod 명령어 (접근 권한 변경)&lt;/b&gt;&lt;/h4&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp; &amp;nbsp; - 기존 파일 또는 디렉터리에 대한 접근 권한을 변경하는 명령어&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp; &amp;nbsp; - 파일 권한의 변경은 파일 소유자나 슈퍼 유저만 가능하다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;blockquote style=&quot;font-size: 1.25em;&quot; data-ke-style=&quot;style2&quot;&gt;명령: chmod [옵션] [접근 권한] [파일명]&lt;/blockquote&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&lt;b&gt;chmod 옵션&lt;/b&gt;&lt;/p&gt;
&lt;table style=&quot;border-collapse: collapse; width: 65.6181%; height: 235px;&quot; border=&quot;1&quot; data-ke-style=&quot;style6&quot;&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 18.8197%; height: 20px;&quot;&gt;&lt;b&gt;옵션&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 81.1803%; height: 20px;&quot;&gt;&lt;b&gt;설명&lt;/b&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 18.8197%; height: 20px;&quot;&gt;-R&lt;/td&gt;
&lt;td style=&quot;width: 81.1803%; height: 20px;&quot;&gt;지정한 디렉터리 아래 있는 모든 파일에 대한 접근 권한을 변경&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 18.8197%; height: 20px;&quot;&gt;&lt;b&gt;대상&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 81.1803%; height: 20px;&quot;&gt;&lt;b&gt;설명&lt;/b&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 21px;&quot;&gt;
&lt;td style=&quot;width: 18.8197%; height: 21px;&quot;&gt;u&lt;/td&gt;
&lt;td style=&quot;width: 81.1803%; height: 21px;&quot;&gt;소유자&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 21px;&quot;&gt;
&lt;td style=&quot;width: 18.8197%; height: 21px;&quot;&gt;g&lt;/td&gt;
&lt;td style=&quot;width: 81.1803%; height: 21px;&quot;&gt;그룹&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 21px;&quot;&gt;
&lt;td style=&quot;width: 18.8197%; height: 21px;&quot;&gt;o&lt;/td&gt;
&lt;td style=&quot;width: 81.1803%; height: 21px;&quot;&gt;그 외 사용자&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 21px;&quot;&gt;
&lt;td style=&quot;width: 18.8197%; height: 21px;&quot;&gt;a&lt;/td&gt;
&lt;td style=&quot;width: 81.1803%; height: 21px;&quot;&gt;모든 사용자&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table style=&quot;border-collapse: collapse; width: 52.093%; height: 137px;&quot; border=&quot;1&quot; data-ke-style=&quot;style1&quot;&gt;
&lt;tbody&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 21.9179%;&quot;&gt;&lt;b&gt;조작&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 78.0821%;&quot;&gt;&lt;b&gt;설명&lt;/b&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 21.9179%;&quot;&gt;+&lt;/td&gt;
&lt;td style=&quot;width: 78.0821%;&quot;&gt;권한을 추가&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 21.9179%;&quot;&gt;-&lt;/td&gt;
&lt;td style=&quot;width: 78.0821%;&quot;&gt;권한을 삭제&lt;/td&gt;
&lt;/tr&gt;
&lt;tr&gt;
&lt;td style=&quot;width: 21.9179%;&quot;&gt;=&lt;/td&gt;
&lt;td style=&quot;width: 78.0821%;&quot;&gt;권한을 지정&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;table style=&quot;border-collapse: collapse; width: 51.5116%; height: 120px;&quot; border=&quot;1&quot; data-ke-style=&quot;style1&quot;&gt;
&lt;tbody&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 23.3032%; height: 20px;&quot;&gt;&lt;b&gt;허용 종류&lt;/b&gt;&lt;/td&gt;
&lt;td style=&quot;width: 76.6968%; height: 20px;&quot;&gt;&lt;b&gt;설명&lt;/b&gt;&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 23.3032%; height: 20px;&quot;&gt;r&lt;/td&gt;
&lt;td style=&quot;width: 76.6968%; height: 20px;&quot;&gt;읽기 가능&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 23.3032%; height: 20px;&quot;&gt;w&lt;/td&gt;
&lt;td style=&quot;width: 76.6968%; height: 20px;&quot;&gt;쓰기 가능&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 23.3032%; height: 20px;&quot;&gt;x&lt;/td&gt;
&lt;td style=&quot;width: 76.6968%; height: 20px;&quot;&gt;실행 가능&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 23.3032%; height: 20px;&quot;&gt;s&lt;/td&gt;
&lt;td style=&quot;width: 76.6968%; height: 20px;&quot;&gt;SUID 혹은 SGID&lt;/td&gt;
&lt;/tr&gt;
&lt;tr style=&quot;height: 20px;&quot;&gt;
&lt;td style=&quot;width: 23.3032%; height: 20px;&quot;&gt;t&lt;/td&gt;
&lt;td style=&quot;width: 76.6968%; height: 20px;&quot;&gt;스티키 비트&lt;/td&gt;
&lt;/tr&gt;
&lt;/tbody&gt;
&lt;/table&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style5&quot; /&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;umask 명령어 (접근 권한 마스크)&lt;/b&gt;&lt;/h4&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp; &amp;nbsp; - 앞으로 만들어질 파일에 미치는 명령으로써, 새로 만들어질 파일에서 제거될 권한을 설정한다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp; &amp;nbsp; - 보편적으로 쓰기 권한에 제한을 두는 022를 많이 사용한다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;blockquote style=&quot;font-size: 1.25em;&quot; data-ke-style=&quot;style2&quot;&gt;user&amp;nbsp;umask&amp;nbsp;값&amp;nbsp;확인:&amp;nbsp;umask&lt;/blockquote&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;파일: 666 - umask = 디폴트 권한 값 &lt;br /&gt;폴더:&amp;nbsp;777&amp;nbsp;-&amp;nbsp;umask &lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;blockquote style=&quot;font-size: 1.25em;&quot; data-ke-style=&quot;style2&quot;&gt;umask 값 변경: umask [숫자] &lt;/blockquote&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;ex) umask 022&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style5&quot; /&gt;
&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;chown 명령어 (소유자, 소유 그룹 변경)&lt;/b&gt;&lt;/h4&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp; &amp;nbsp; - 파일 또는 디렉터리의 소유자, 소유 그룹 수정에 사용&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp; &amp;nbsp; - 명령 실행 시 슈퍼유저 권한 필요&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;blockquote style=&quot;font-size: 1.25em;&quot; data-ke-style=&quot;style2&quot;&gt;&lt;b&gt;명령: chown [옵션] [변경 유저명:변경 그룹명] [파일명]&lt;/b&gt;&lt;/blockquote&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&lt;b&gt;[변경 유저명:변경 그룹명] 상세 설명&lt;br /&gt;&lt;/b&gt;&amp;nbsp; &amp;middot; 소유자만 바꿀 경우 - [ 소유자 ] &lt;br /&gt;&amp;nbsp; &amp;middot; 그룹만 바꿀 경우 - [ :그룹명 ] &lt;br /&gt;&amp;nbsp; &amp;middot; 모두 똑같이 바꿀 경우 - [ 소유자: ] &lt;br /&gt;&amp;nbsp; &amp;middot; 따로따로 바꿀 경우 - [ 소유자:그룹명 ] &lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;b&gt;&lt;/b&gt;&lt;/p&gt;</description>
      <category>Linux</category>
      <category>파일 접근 권한 #linux #chown #chmond #umask #명령어</category>
      <author>보안보</author>
      <guid isPermaLink="true">https://securitymax.tistory.com/140</guid>
      <comments>https://securitymax.tistory.com/140#entry140comment</comments>
      <pubDate>Sat, 16 Nov 2019 14:09:00 +0900</pubDate>
    </item>
    <item>
      <title>Codegate 2012 F100 : Disk Forensic</title>
      <link>https://securitymax.tistory.com/139</link>
      <description>&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;[시나리오]&lt;/b&gt;&lt;/h4&gt;
&lt;p style=&quot;font-size: 1.12em;&quot;&gt;X&amp;nbsp;회사의&amp;nbsp;재정&amp;nbsp;정보를&amp;nbsp;훔치기&amp;nbsp;위해서&amp;nbsp;IU는&amp;nbsp;비밀리에&amp;nbsp;직장을&amp;nbsp;구했다.&amp;nbsp;그녀는&amp;nbsp;CFO의&amp;nbsp;컴퓨터를&amp;nbsp;공격하기로&amp;nbsp;결정한&amp;nbsp;후&amp;nbsp;사회&amp;nbsp;공학적&amp;nbsp;방법으로&amp;nbsp;악의적인&amp;nbsp;악성코드를&amp;nbsp;자신의&amp;nbsp;컴퓨터로&amp;nbsp;삽입하기로&amp;nbsp;결정했다.&amp;nbsp;그녀는&amp;nbsp;CFO가&amp;nbsp;퇴근할&amp;nbsp;때&amp;nbsp;컴퓨터를&amp;nbsp;끄지&amp;nbsp;않는다는&amp;nbsp;것을&amp;nbsp;알아냈다.&amp;nbsp;CFO가&amp;nbsp;사무실에서&amp;nbsp;나간&amp;nbsp;후,&amp;nbsp;그녀는&amp;nbsp;CFO의&amp;nbsp;컴퓨터에서&amp;nbsp;재무자료를&amp;nbsp;얻고&amp;nbsp;EXCEL&amp;nbsp;파일을&amp;nbsp;검색한다.&amp;nbsp;그녀는&amp;nbsp;설치된&amp;nbsp;응용&amp;nbsp;프로그램을&amp;nbsp;확인해서&amp;nbsp;파일에서&amp;nbsp;정보를&amp;nbsp;찾을&amp;nbsp;수&amp;nbsp;있었다.&amp;nbsp;모든&amp;nbsp;추적을&amp;nbsp;제거하기&amp;nbsp;위해&amp;nbsp;그녀는&amp;nbsp;악성코드,&amp;nbsp;이벤트&amp;nbsp;로그&amp;nbsp;및&amp;nbsp;최근&amp;nbsp;파일&amp;nbsp;목록을&amp;nbsp;지웠다.&amp;nbsp;X&amp;nbsp;회사는&amp;nbsp;적절한&amp;nbsp;조치를&amp;nbsp;취하기&amp;nbsp;위해&amp;nbsp;그녀가&amp;nbsp;어떤&amp;nbsp;정보를&amp;nbsp;훔쳤는지&amp;nbsp;밝혀야&amp;nbsp;한다.&amp;nbsp;이&amp;nbsp;파일들은&amp;nbsp;CFO의&amp;nbsp;컴퓨터에서&amp;nbsp;공격받은&amp;nbsp;파일들이다.&amp;nbsp;그녀가&amp;nbsp;훔친&amp;nbsp;파일의&amp;nbsp;전체&amp;nbsp;경로와&amp;nbsp;파일의&amp;nbsp;크기를&amp;nbsp;찾아라.&amp;nbsp;그&amp;nbsp;날&amp;nbsp;CFO는&amp;nbsp;14:00시에&amp;nbsp;사무실을&amp;nbsp;떠났다.&amp;nbsp;시간은&amp;nbsp;한국&amp;nbsp;표준시&amp;nbsp;(UTC&amp;nbsp;+&amp;nbsp;09:00)를&amp;nbsp;기준으로&amp;nbsp;한다. &lt;br /&gt;&lt;br /&gt;KEY&amp;nbsp;Format&amp;nbsp;:&amp;nbsp;strupr(md5(full_path|file_size))&amp;nbsp;(&amp;lsquo;|&amp;rsquo;&amp;nbsp;는&amp;nbsp;문자일&amp;nbsp;뿐이다.) &lt;/p&gt;
&lt;p style=&quot;font-size: 1.12em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.12em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.12em;&quot;&gt;&lt;b&gt;[풀이 도구]&lt;/b&gt;(아티펙트 분석용)&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;fileblock&quot; data-ke-align=&quot;alignCenter&quot;&gt;&lt;a href=&quot;https://blog.kakaocdn.net/dn/opjFJ/btqzOXnKHeD/ycrX0DktKdfJQ7YltGJPo1/WFA.exe?attach=1&amp;amp;knm=tfile.exe&quot; class=&quot;&quot;&gt;
    &lt;div class=&quot;image&quot;&gt;&lt;/div&gt;
    &lt;div class=&quot;desc&quot;&gt;&lt;div class=&quot;filename&quot;&gt;&lt;span class=&quot;name&quot;&gt;WFA.exe&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;size&quot;&gt;4.30MB&lt;/div&gt;
&lt;/div&gt;
  &lt;/a&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style5&quot; /&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/77G6u/btqzM0sWHye/yDHSy2Rli7QRIncewXcDsK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/77G6u/btqzM0sWHye/yDHSy2Rli7QRIncewXcDsK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/77G6u/btqzM0sWHye/yDHSy2Rli7QRIncewXcDsK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2F77G6u%2FbtqzM0sWHye%2FyDHSy2Rli7QRIncewXcDsK%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center; font-size: 1.25em;&quot;&gt;주어진 문제 파일은 확장자 유형이 주어지지 않아서 Hex Editor를 이용하여 파일 시그니처를 확인한다.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/sniUZ/btqzOwjRhTN/aQU0XRUffv7s56Pyu80kZ0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/sniUZ/btqzOwjRhTN/aQU0XRUffv7s56Pyu80kZ0/img.png&quot; data-alt=&quot;파일 시그니처&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/sniUZ/btqzOwjRhTN/aQU0XRUffv7s56Pyu80kZ0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FsniUZ%2FbtqzOwjRhTN%2FaQU0XRUffv7s56Pyu80kZ0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;파일 시그니처&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center; font-size: 1.25em;&quot;&gt;Hex Editor로 열어본 결과 해당 파일은 7z로 압축된 파일임을 확인할 수 있다.&lt;/p&gt;
&lt;p style=&quot;text-align: center; font-size: 1.25em;&quot;&gt;확장자를 변경하고 그 내용을 확인한다.&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/vJZ0Q/btqzOmu0oUc/QOXPk3XTge7RqNMA2eV8L1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/vJZ0Q/btqzOmu0oUc/QOXPk3XTge7RqNMA2eV8L1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/vJZ0Q/btqzOmu0oUc/QOXPk3XTge7RqNMA2eV8L1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FvJZ0Q%2FbtqzOmu0oUc%2FQOXPk3XTge7RqNMA2eV8L1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center; font-size: 1.25em;&quot;&gt;압축 파일을 확인한 결과, 윈도우 운영체제의 사용자 폴더의 구조와 동일한다. 따라서 해당 파일은 윈도우 운영체제의 사용자 폴더를 압축한 파일임을 알 수 있다.&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;text-align: center; font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;text-align: center; font-size: 1.25em;&quot;&gt;범인이 열어본 EXCEL 파일의 흔적을 찾기위해 문서 파일의 링크 파일 정보가 담긴 폴더를 확인한다.&lt;/p&gt;
&lt;p style=&quot;text-align: center; font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/Ql0B4/btqzNA8paZ3/eiPQOnPUrUnDQLvB1Zbnak/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/Ql0B4/btqzNA8paZ3/eiPQOnPUrUnDQLvB1Zbnak/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/Ql0B4/btqzNA8paZ3/eiPQOnPUrUnDQLvB1Zbnak/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FQl0B4%2FbtqzNA8paZ3%2FeiPQOnPUrUnDQLvB1Zbnak%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;blockquote style=&quot;text-align: left; font-size: 1.25em;&quot; data-ke-style=&quot;style2&quot;&gt;링크 파일 경로: Users\proneer\AppData\Roaming\Microsoft\Office\Recent&lt;/blockquote&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;재무정보 문서로 의심되는 &quot;[Top-Secret]_2011_Financial_deals.LNK&quot; 링크 파일이 존재한다. 해당 링크 파일 분석을 위해 WFA(Windows File Analyzer) 프로그램을 실행하여 해당 링크 파일을 담고 있는 폴더를 찾아낸다.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/entYnH/btqzOdLTusJ/QAeZk1qvup0JJamUeU1akk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/entYnH/btqzOdLTusJ/QAeZk1qvup0JJamUeU1akk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/entYnH/btqzOdLTusJ/QAeZk1qvup0JJamUeU1akk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FentYnH%2FbtqzOdLTusJ%2FQAeZk1qvup0JJamUeU1akk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;위의 그림과같이 재무정보 문서 링크 파일의 파일크기와 전체 경로를 알 수 있다.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;blockquote style=&quot;font-size: 1.25em;&quot; data-ke-style=&quot;style2&quot;&gt;경로: C:\INSIGHT\Accounting\Confidential\[Top-Secret]_2011_Financial_deals.xlsx&lt;br /&gt;크기: 9296 Byte&lt;/blockquote&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cFsqcq/btqzOxJRO60/egeLMTVWKJCvxA5okb2vl0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cFsqcq/btqzOxJRO60/egeLMTVWKJCvxA5okb2vl0/img.png&quot; data-alt=&quot;md5 값 계산 python 코드&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cFsqcq/btqzOxJRO60/egeLMTVWKJCvxA5okb2vl0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FcFsqcq%2FbtqzOxJRO60%2FegeLMTVWKJCvxA5okb2vl0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;md5 값 계산 python 코드&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center; font-size: 1.25em;&quot;&gt;Flag key = d3403b2653dbc16bbe1cfce53a417ab1&lt;/p&gt;</description>
      <category>포렌식/CTF</category>
      <category>Forensic CTF #disk Forensic #windows file analyzer #WFA #Codegate 2012 F100</category>
      <author>보안보</author>
      <guid isPermaLink="true">https://securitymax.tistory.com/139</guid>
      <comments>https://securitymax.tistory.com/139#entry139comment</comments>
      <pubDate>Sat, 16 Nov 2019 00:37:13 +0900</pubDate>
    </item>
    <item>
      <title>디지털포렌식 연구회 워크샵 2019 후기</title>
      <link>https://securitymax.tistory.com/138</link>
      <description>&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/boKDGX/btqzIAOPQuY/tdtvQNt1zX3EK7zs1RU4f0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/boKDGX/btqzIAOPQuY/tdtvQNt1zX3EK7zs1RU4f0/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/boKDGX/btqzIAOPQuY/tdtvQNt1zX3EK7zs1RU4f0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FboKDGX%2FbtqzIAOPQuY%2FtdtvQNt1zX3EK7zs1RU4f0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot; data-ke-size=&quot;size20&quot;&gt;디지털 포렌식 워크샵에 다녀왔습니다. 워크샵 장소가 생각보다 멀어서 고단했지만, 포렌식에 대해서 폭넓은 지식을 햠양할 수 있었던 좋은 시간이였습니다.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;iframe mapdata=&quot;addr=%EC%84%9C%EC%9A%B8%20%EC%84%9C%EC%B4%88%EA%B5%AC%20%EC%96%91%EC%9E%AC%EB%8F%99%20202%20&amp;amp;addtype=1&amp;amp;confirmid=7941550&amp;amp;docid=&amp;amp;idx=1&amp;amp;ifrH=362px&amp;amp;ifrW=490px&amp;amp;mapHeight=362&amp;amp;mapInfo=%7B%22version%22%3A2%2C%22mapWidth%22%3A490%2C%22mapHeight%22%3A362%2C%22mapCenterX%22%3A507250%2C%22mapCenterY%22%3A1101873%2C%22mapLevel%22%3A4%2C%22coordinate%22%3A%22wcongnamul%22%2C%22markInfo%22%3A%5B%7B%22markerType%22%3A%22standPlace%22%2C%22coordinate%22%3A%22wcongnamul%22%2C%22x%22%3A507253%2C%22y%22%3A1101878%2C%22clickable%22%3Atrue%2C%22draggable%22%3Atrue%2C%22icon%22%3A%7B%22width%22%3A35%2C%22height%22%3A56%2C%22offsetX%22%3A17%2C%22offsetY%22%3A56%2C%22src%22%3A%22%2F%2Ft1.daumcdn.net%2Flocalimg%2Flocalimages%2F07%2F2012%2Fattach%2Fpc_img%2Fico_marker2_150331.png%22%7D%2C%22content%22%3A%22%EB%8D%94%EC%BC%80%EC%9D%B4%ED%98%B8%ED%85%94%20%EC%84%9C%EC%9A%B8%22%2C%22confirmid%22%3A7941550%7D%5D%2C%22graphicInfo%22%3A%5B%5D%2C%22roadviewInfo%22%3A%5B%5D%7D&amp;amp;mapWidth=490&amp;amp;mapX=507250&amp;amp;mapY=1101873&amp;amp;map_hybrid=false&amp;amp;map_level=4&amp;amp;map_type=TYPE_MAP&amp;amp;rcode=1165065200&amp;amp;tel=02-571-8100&amp;amp;title=%EB%8D%94%EC%BC%80%EC%9D%B4%ED%98%B8%ED%85%94%20%EC%84%9C%EC%9A%B8&quot; src=&quot;/proxy/plusmapViewer.php?id=maps_1573659646485&quot; id=&quot;maps_1573659646485&quot; width=&quot;540px&quot; height=&quot;350px&quot; frameborder=&quot;0&quot; scrolling=&quot;no&quot; data-ke-type=&quot;map&quot; data-maps-data=&quot;addr=%EC%84%9C%EC%9A%B8%20%EC%84%9C%EC%B4%88%EA%B5%AC%20%EC%96%91%EC%9E%AC%EB%8F%99%20202%20&amp;amp;addtype=1&amp;amp;confirmid=7941550&amp;amp;docid=&amp;amp;idx=1&amp;amp;ifrH=362px&amp;amp;ifrW=490px&amp;amp;mapHeight=362&amp;amp;mapInfo=%7B%22version%22%3A2%2C%22mapWidth%22%3A490%2C%22mapHeight%22%3A362%2C%22mapCenterX%22%3A507250%2C%22mapCenterY%22%3A1101873%2C%22mapLevel%22%3A4%2C%22coordinate%22%3A%22wcongnamul%22%2C%22markInfo%22%3A%5B%7B%22markerType%22%3A%22standPlace%22%2C%22coordinate%22%3A%22wcongnamul%22%2C%22x%22%3A507253%2C%22y%22%3A1101878%2C%22clickable%22%3Atrue%2C%22draggable%22%3Atrue%2C%22icon%22%3A%7B%22width%22%3A35%2C%22height%22%3A56%2C%22offsetX%22%3A17%2C%22offsetY%22%3A56%2C%22src%22%3A%22%2F%2Ft1.daumcdn.net%2Flocalimg%2Flocalimages%2F07%2F2012%2Fattach%2Fpc_img%2Fico_marker2_150331.png%22%7D%2C%22content%22%3A%22%EB%8D%94%EC%BC%80%EC%9D%B4%ED%98%B8%ED%85%94%20%EC%84%9C%EC%9A%B8%22%2C%22confirmid%22%3A7941550%7D%5D%2C%22graphicInfo%22%3A%5B%5D%2C%22roadviewInfo%22%3A%5B%5D%7D&amp;amp;mapWidth=490&amp;amp;mapX=507250&amp;amp;mapY=1101873&amp;amp;map_hybrid=false&amp;amp;map_level=4&amp;amp;map_type=TYPE_MAP&amp;amp;rcode=1165065200&amp;amp;tel=02-571-8100&amp;amp;title=%EB%8D%94%EC%BC%80%EC%9D%B4%ED%98%B8%ED%85%94%20%EC%84%9C%EC%9A%B8&quot; data-maps-mapx=&quot;1101873&quot; data-maps-mapy=&quot;1101873&quot; data-maps-thumbnail=&quot;https://ssl.daumcdn.net/map3/staticmap/image?center=507250%2C1101873&amp;amp;lv=4&amp;amp;size=540x350&amp;amp;srs=WCONGNAMUL&amp;amp;markers=symbol%3Asc_marker%7Clocation%3A507253%2C1101878&quot;&gt;&lt;/iframe&gt;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;워크샵 장소: The K Hotel&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imagegridblock&quot;&gt;
  &lt;div class=&quot;image-container&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/SKdIr/btqzLlbr7VR/10PbVVjCCb7UoEDETmrAv1/img.jpg&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/SKdIr/btqzLlbr7VR/10PbVVjCCb7UoEDETmrAv1/img.jpg&quot; data-filename=&quot;KakaoTalk_20191114_003341220_22.jpg&quot; width=&quot;556&quot; height=&quot;741&quot; style=&quot;width: 35.1628%;&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/SKdIr/btqzLlbr7VR/10PbVVjCCb7UoEDETmrAv1/img.jpg&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FSKdIr%2FbtqzLlbr7VR%2F10PbVVjCCb7UoEDETmrAv1%2Fimg.jpg&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;&quot; height=&quot;&quot;/&gt;&lt;/span&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/p4PBp/btqzLkDADen/x7bLR2KrTKWXpDvnrWxTW0/img.jpg&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/p4PBp/btqzLkDADen/x7bLR2KrTKWXpDvnrWxTW0/img.jpg&quot; data-filename=&quot;KakaoTalk_20191114_003341220_21.jpg&quot; width=&quot;673&quot; height=&quot;505&quot; style=&quot;width: 62.5116%;&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/p4PBp/btqzLkDADen/x7bLR2KrTKWXpDvnrWxTW0/img.jpg&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fp4PBp%2FbtqzLkDADen%2Fx7bLR2KrTKWXpDvnrWxTW0%2Fimg.jpg&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot; loading=&quot;lazy&quot; width=&quot;&quot; height=&quot;&quot;/&gt;&lt;/span&gt;&lt;/div&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center; font-size: 1.25em;&quot;&gt;양재 시민의숲역에서 나와 길을 쭉 걷다보면 큰 호텔이 하나가 떡하니 나타납니다.&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-filename=&quot;KakaoTalk_20191114_003341220_02.jpg&quot; width=&quot;566&quot; height=&quot;566&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bPEryx/btqzKHTyIgs/9Ykss2XhK6kpdfayuTI0M0/img.jpg&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bPEryx/btqzKHTyIgs/9Ykss2XhK6kpdfayuTI0M0/img.jpg&quot; data-alt=&quot;워크숍 입간판&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bPEryx/btqzKHTyIgs/9Ykss2XhK6kpdfayuTI0M0/img.jpg&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbPEryx%2FbtqzKHTyIgs%2F9Ykss2XhK6kpdfayuTI0M0%2Fimg.jpg&quot; data-filename=&quot;KakaoTalk_20191114_003341220_02.jpg&quot; width=&quot;566&quot; height=&quot;566&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;워크숍 입간판&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot; data-filename=&quot;KakaoTalk_20191114_003341220_06.jpg&quot; width=&quot;757&quot; height=&quot;568&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cB9HxC/btqzKejOP42/f4kjRMSKrKbDxk3YVp95I1/img.jpg&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cB9HxC/btqzKejOP42/f4kjRMSKrKbDxk3YVp95I1/img.jpg&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cB9HxC/btqzKejOP42/f4kjRMSKrKbDxk3YVp95I1/img.jpg&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FcB9HxC%2FbtqzKejOP42%2Ff4kjRMSKrKbDxk3YVp95I1%2Fimg.jpg&quot; data-filename=&quot;KakaoTalk_20191114_003341220_06.jpg&quot; width=&quot;757&quot; height=&quot;568&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;워크숍 내용들이 나에겐 너무 이해하기 어려웠던 부분이 많았습니다. 그중에서 인상 깊었던 내용은 첫째날, 한신대학교에서 OOXML office forensic에 대해서 연구하신 내용은 디지털 포렌식 챌린지 대회를 하면서 공부를 했던 내용이라 인상깊게 들었습니다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bhGbyP/btqzI4WxdW2/uF0T5k2QYxkk1kqwGiGqT1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bhGbyP/btqzI4WxdW2/uF0T5k2QYxkk1kqwGiGqT1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bhGbyP/btqzI4WxdW2/uF0T5k2QYxkk1kqwGiGqT1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbhGbyP%2FbtqzI4WxdW2%2FuF0T5k2QYxkk1kqwGiGqT1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;2020년도 디지털포렌식연구회의 계획입니다. 멀리서 촬영하여 화질이 나쁘네요.. 내년에도 디지털 포렌식 챌린지를 개최 하니 많은 참여 부탁드립니다!&lt;/p&gt;</description>
      <category>포렌식/디지털 포렌식</category>
      <category>디지털포렌식 연구회 워크샵 #디지털포렌식 #디지털포렌식챌린지 #Forensic #ctf #정보보호학회</category>
      <author>보안보</author>
      <guid isPermaLink="true">https://securitymax.tistory.com/138</guid>
      <comments>https://securitymax.tistory.com/138#entry138comment</comments>
      <pubDate>Thu, 14 Nov 2019 01:11:01 +0900</pubDate>
    </item>
    <item>
      <title>EnCase - 이미지(E01)파일 마운트방법</title>
      <link>https://securitymax.tistory.com/137</link>
      <description>&lt;h4 data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;[EnCase Image Mount]&lt;/b&gt;&lt;/h4&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/SuiRQ/btqzHa9g3oG/SDkfkUYImr6BSB7aVQrjUk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/SuiRQ/btqzHa9g3oG/SDkfkUYImr6BSB7aVQrjUk/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/SuiRQ/btqzHa9g3oG/SDkfkUYImr6BSB7aVQrjUk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FSuiRQ%2FbtqzHa9g3oG%2FSDkfkUYImr6BSB7aVQrjUk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center; font-size: 1.25em;&quot;&gt;&lt;b&gt;대상 Evidence 이미지 파일 선택 &amp;gt; 우클릭 &amp;gt; Device &amp;gt; Share &amp;gt; Mount as Emulated Disk 선택&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/poV3h/btqzIg1ZIdt/tWeocgvcdcTsDpejcPIVkK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/poV3h/btqzIg1ZIdt/tWeocgvcdcTsDpejcPIVkK/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/poV3h/btqzIg1ZIdt/tWeocgvcdcTsDpejcPIVkK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FpoV3h%2FbtqzIg1ZIdt%2FtWeocgvcdcTsDpejcPIVkK%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center; font-size: 1.12em;&quot;&gt;이미지(E01) 파일이 &lt;b&gt;volume: F&lt;/b&gt;로 마운트 된다.&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bmjyFI/btqzFzBXBYd/RE61OHLvyrGeNpwCjf0BP0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bmjyFI/btqzFzBXBYd/RE61OHLvyrGeNpwCjf0BP0/img.png&quot; data-alt=&quot;마운트 된 이미지&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bmjyFI/btqzFzBXBYd/RE61OHLvyrGeNpwCjf0BP0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbmjyFI%2FbtqzFzBXBYd%2FRE61OHLvyrGeNpwCjf0BP0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;마운트 된 이미지&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style5&quot; /&gt;
&lt;h4 style=&quot;text-align: left;&quot; data-ke-size=&quot;size20&quot;&gt;&lt;b&gt;[EnCase Image UnMount]&lt;/b&gt;&lt;/h4&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/cf7EPS/btqzE16Kx5y/V6xFPG5lDsbzik6dkJuWk1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/cf7EPS/btqzE16Kx5y/V6xFPG5lDsbzik6dkJuWk1/img.png&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/cf7EPS/btqzE16Kx5y/V6xFPG5lDsbzik6dkJuWk1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fcf7EPS%2FbtqzE16Kx5y%2FV6xFPG5lDsbzik6dkJuWk1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center; font-size: 1.25em;&quot;&gt;&lt;b&gt;[Physical Disk Emulator] &lt;/b&gt;더블클릭&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bQa9D8/btqzGp6DUIY/VZFRAh1qLzesW4Us6ryqbk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bQa9D8/btqzGp6DUIY/VZFRAh1qLzesW4Us6ryqbk/img.png&quot; data-alt=&quot;예(Y)&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bQa9D8/btqzGp6DUIY/VZFRAh1qLzesW4Us6ryqbk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbQa9D8%2FbtqzGp6DUIY%2FVZFRAh1qLzesW4Us6ryqbk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;예(Y)&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description>
      <category>포렌식/EnCase</category>
      <category>EnCase #mount #Forensic #image mount</category>
      <author>보안보</author>
      <guid isPermaLink="true">https://securitymax.tistory.com/137</guid>
      <comments>https://securitymax.tistory.com/137#entry137comment</comments>
      <pubDate>Mon, 11 Nov 2019 21:00:31 +0900</pubDate>
    </item>
    <item>
      <title>ASIS Quals CTF : 파일에서 플래그를 찾아라.</title>
      <link>https://securitymax.tistory.com/136</link>
      <description>&lt;p style=&quot;text-align: center;&quot;&gt;&lt;b&gt;[ 문제 파일 Download ]&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;fileblock&quot; data-ke-align=&quot;alignCenter&quot;&gt;&lt;a href=&quot;https://blog.kakaocdn.net/dn/m8xeG/btqzFWW5ZzQ/nc3V94DtLGrcPmAwBEhow1/keka_bomb_9e0f1863259c578f3231b5cfbc10e258?attach=1&amp;amp;knm=tfile.dat&quot; class=&quot;&quot;&gt;
    &lt;div class=&quot;image&quot;&gt;&lt;/div&gt;
    &lt;div class=&quot;desc&quot;&gt;&lt;div class=&quot;filename&quot;&gt;&lt;span class=&quot;name&quot;&gt;keka_bomb_9e0f1863259c578f3231b5cfbc10e258&lt;/span&gt;&lt;/div&gt;
&lt;div class=&quot;size&quot;&gt;0.01MB&lt;/div&gt;
&lt;/div&gt;
  &lt;/a&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style5&quot; /&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bU0bJV/btqzGrCyGgr/uBI1JnnQdLbuisCFOZR6cK/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bU0bJV/btqzGrCyGgr/uBI1JnnQdLbuisCFOZR6cK/img.png&quot; data-alt=&quot;문제파일&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bU0bJV/btqzGrCyGgr/uBI1JnnQdLbuisCFOZR6cK/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbU0bJV%2FbtqzGrCyGgr%2FuBI1JnnQdLbuisCFOZR6cK%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;문제파일&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;주어진 문제 파일에 확장자가 존재하지 않기 때문에 어떤 유형의 파일인지 알 수 없다. 그렇기 때문에 Linux의 &lt;b&gt;file 명령어&lt;/b&gt;를 사용하여 파일의 확장자를 확인한다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/buR79u/btqzFdydzWc/KZeQELswFaa76ZeRPG5dk0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/buR79u/btqzFdydzWc/KZeQELswFaa76ZeRPG5dk0/img.png&quot; data-alt=&quot;파일 유형 확인하기&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/buR79u/btqzFdydzWc/KZeQELswFaa76ZeRPG5dk0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbuR79u%2FbtqzFdydzWc%2FKZeQELswFaa76ZeRPG5dk0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;파일 유형 확인하기&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;위의 그림과 같이 문제 파일이 &lt;b&gt;XZ 확장자&lt;/b&gt;를 가진 압축파일임을 알 수 있다. 파일명의 확장자를 .xz 로 변경한 뒤 &lt;b&gt;unxz 명령어&lt;/b&gt;를 사용하여 압축을 풀어 확인한다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bfqqpA/btqzE0lzdXT/5ZWMZ908Yrm62wXxFuyFkk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bfqqpA/btqzE0lzdXT/5ZWMZ908Yrm62wXxFuyFkk/img.png&quot; data-alt=&quot;unxz 압축해제 명령&amp;amp;amp;nbsp;&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bfqqpA/btqzE0lzdXT/5ZWMZ908Yrm62wXxFuyFkk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbfqqpA%2FbtqzE0lzdXT%2F5ZWMZ908Yrm62wXxFuyFkk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;unxz 압축해제 명령&amp;nbsp;&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;압축을 해제하면 다시 한번 똑같은 파일이 나타난다. 한번더 file 명령어를 사용하여 파일의 유형을 확인한다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/xA7Ay/btqzE1x4p4x/7mRv71ovLqVUXR4bjOxev1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/xA7Ay/btqzE1x4p4x/7mRv71ovLqVUXR4bjOxev1/img.png&quot; data-alt=&quot;7zip으로 압축된 파일&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/xA7Ay/btqzE1x4p4x/7mRv71ovLqVUXR4bjOxev1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FxA7Ay%2FbtqzE1x4p4x%2F7mRv71ovLqVUXR4bjOxev1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;7zip으로 압축된 파일&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;파일 확장자를 확인해보니 7zip으로 압축된 파일인 것을 알 수 있다. 데이터를 &lt;b&gt;windows&lt;/b&gt; 운영체제로 옮겨 분석해보자.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/dklkn6/btqzFdE0HGk/P0TEhqRLHfm3CMDnKqXHS0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/dklkn6/btqzFdE0HGk/P0TEhqRLHfm3CMDnKqXHS0/img.png&quot; data-alt=&quot;압축된 파일들&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/dklkn6/btqzFdE0HGk/P0TEhqRLHfm3CMDnKqXHS0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fdklkn6%2FbtqzFdE0HGk%2FP0TEhqRLHfm3CMDnKqXHS0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;압축된 파일들&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;압축파일을 실행하면 위의 그림과 같이 &lt;b&gt;16개의&lt;/b&gt; 파일들이 압축되어 있다. 그 중 특이한 점은 문제 파일로 제공된 파일의 용량은 10MB가 채 되지 않는 파일이었지만, 현재 위의 그림과 같이 압축된 파일들이 모두 동일하게 파일 용량이 4.2GB나 되어 해당 파일은&lt;b&gt; ZipBomb&lt;/b&gt;으로 예상된다.&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.12em;&quot;&gt;&amp;nbsp; &amp;nbsp;&lt;/p&gt;
&lt;blockquote style=&quot;font-size: 1.25em;&quot; data-ke-style=&quot;style2&quot;&gt;&lt;b&gt;ZipBomb&lt;/b&gt;&amp;nbsp;&lt;br /&gt;압축이 풀릴 때 엄청난 양의 하드디스크와 메모리의 용량을 고갈시키는 악성 파일이다.&lt;/blockquote&gt;
&lt;p style=&quot;font-size: 1.12em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;특이한 점은, 위의 그림의 내용과 같이 압축 파일들이 이름, 크기, 압축된 크기, CRC, 수정한 날자 등의 정보를 볼 수 있다. 이 중에서 013.7z이 다른 파일들과 다르게 압축된 크기와 CRC 정보가 다른 것을 볼 수 있다. 따라서 013.7z파일을 압축 해제한 후 확인해본다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/dCobjo/btqzFzOBD94/9iqOr2htXjkNWrEyezXuU0/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/dCobjo/btqzFzOBD94/9iqOr2htXjkNWrEyezXuU0/img.png&quot; data-alt=&quot;013.7z 압축파일 내용&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/dCobjo/btqzFzOBD94/9iqOr2htXjkNWrEyezXuU0/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FdCobjo%2FbtqzFzOBD94%2F9iqOr2htXjkNWrEyezXuU0%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;013.7z 압축파일 내용&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;이번에도 다른 파일들과는 다른 압축된 크기, CRC 정보를 갖는 파일이 존재한다. 이전 압축파일과 동일한 방법으로 CRC 정보가 다른 압축파일 0009.7z를 압축해제하여 확인한다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/xTKSN/btqzEhn46W3/mk0Ag0JCJOsQssjglrtFCk/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/xTKSN/btqzEhn46W3/mk0Ag0JCJOsQssjglrtFCk/img.png&quot; data-alt=&quot;0009.7z 압축파일 내용&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/xTKSN/btqzEhn46W3/mk0Ag0JCJOsQssjglrtFCk/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FxTKSN%2FbtqzEhn46W3%2Fmk0Ag0JCJOsQssjglrtFCk%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;0009.7z 압축파일 내용&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&lt;span style=&quot;color: #333333;&quot;&gt;이번에도 다른 파일들과는 다른 압축된 크기, CRC 정보를 갖는 파일이 존재한다. 이전 압축파일과 동일한 방법으로 CRC 정보가 다른 압축파일 0000007.7z를 압축해제 하여 확인한다.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/z69n4/btqzEtIwUUI/d7i1TCPOeX9AGBUuFelXg1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/z69n4/btqzEtIwUUI/d7i1TCPOeX9AGBUuFelXg1/img.png&quot; data-alt=&quot;0000007.7z 압축파일 내용&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/z69n4/btqzEtIwUUI/d7i1TCPOeX9AGBUuFelXg1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2Fz69n4%2FbtqzEtIwUUI%2Fd7i1TCPOeX9AGBUuFelXg1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;0000007.7z 압축파일 내용&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&lt;span style=&quot;color: #333333;&quot;&gt;이번에도 다른 파일들과는 다른 압축된 크기, CRC 정보를 갖는 파일이 존재한다. 이전 압축파일과 동일한 방법으로 CRC 정보가 다른 압축파일 0000000008.7z를 압축해제 하여 확인한다.&lt;/span&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/dcUbL1/btqzFWpf4b9/hmxYQLUW6BlMcvV6sLqZok/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/dcUbL1/btqzFWpf4b9/hmxYQLUW6BlMcvV6sLqZok/img.png&quot; data-alt=&quot;폭탄 등장!&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/dcUbL1/btqzFWpf4b9/hmxYQLUW6BlMcvV6sLqZok/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FdcUbL1%2FbtqzFWpf4b9%2FhmxYQLUW6BlMcvV6sLqZok%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;폭탄 등장!&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;위의 그림과 같이 bomb로 시작하는 파일들의 용량은 모두 같지만 이전과 다르게 파일 유형이 압축파일이 아니다. 위의 파일들 중 &lt;b&gt;bomb_08&lt;/b&gt; 파일이 다른 압축된 크기, CRC 정보를 가지고 있기 때문에 bomb_08 파일을 압축해제하고 &lt;b&gt;Hex Editor&lt;/b&gt;로 확인한다.&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/Oiy30/btqzEiAwgi2/WODscZ7C6V9EoC1Sl7lBz1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/Oiy30/btqzEiAwgi2/WODscZ7C6V9EoC1Sl7lBz1/img.png&quot; data-alt=&quot;bomb_08&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/Oiy30/btqzEiAwgi2/WODscZ7C6V9EoC1Sl7lBz1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FOiy30%2FbtqzEiAwgi2%2FWODscZ7C6V9EoC1Sl7lBz1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;bomb_08&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;Hex Editor로 파일을 불러오면 위의 그림과 같이 0 값으로 파일이 구성되어 Flag와 관련된 문자열을 찾을 수 없다. 파일에서 문자열이 있는지 &lt;b&gt;strings&lt;/b&gt;를 사용하여 Flag를 확인한다.&lt;/p&gt;
&lt;p style=&quot;font-size: 1.25em;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock alignCenter&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/Jok2b/btqzEgWWRGR/Rn7C1jHjNkr0bkaunc9dK1/img.png&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/Jok2b/btqzEgWWRGR/Rn7C1jHjNkr0bkaunc9dK1/img.png&quot; data-alt=&quot;Flag!&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/Jok2b/btqzEgWWRGR/Rn7C1jHjNkr0bkaunc9dK1/img.png&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FJok2b%2FbtqzEgWWRGR%2FRn7C1jHjNkr0bkaunc9dK1%2Fimg.png&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;figcaption&gt;Flag!&lt;/figcaption&gt;
&lt;/figure&gt;
&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;ASIS{f974da3203d15582697f4a66735a20b}&lt;/p&gt;
&lt;p style=&quot;text-align: center;&quot;&gt;&amp;nbsp;&lt;/p&gt;
&lt;hr contenteditable=&quot;false&quot; data-ke-type=&quot;horizontalRule&quot; data-ke-style=&quot;style6&quot; /&gt;
&lt;p&gt;&lt;figure class=&quot;imageblock floatLeft&quot; width=&quot;133&quot;&gt;&lt;span data-url=&quot;https://blog.kakaocdn.net/dn/bkIpuK/btqzE2jpiOw/lAztRKEQsjrfo1BWaV29K1/img.jpg&quot; data-phocus=&quot;https://blog.kakaocdn.net/dn/bkIpuK/btqzE2jpiOw/lAztRKEQsjrfo1BWaV29K1/img.jpg&quot;&gt;&lt;img src=&quot;https://blog.kakaocdn.net/dn/bkIpuK/btqzE2jpiOw/lAztRKEQsjrfo1BWaV29K1/img.jpg&quot; srcset=&quot;https://img1.daumcdn.net/thumb/R1280x0/?scode=mtistory2&amp;amp;fname=https%3A%2F%2Fblog.kakaocdn.net%2Fdn%2FbkIpuK%2FbtqzE2jpiOw%2FlAztRKEQsjrfo1BWaV29K1%2Fimg.jpg&quot; width=&quot;133&quot; onerror=&quot;this.onerror=null; this.src='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png'; this.srcset='//t1.daumcdn.net/tistory_admin/static/images/no-image-v1.png';&quot;/&gt;&lt;/span&gt;&lt;/figure&gt;
&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #333333;&quot;&gt;문제 출처: 디지털 포렌식 with CTF&amp;nbsp;&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&lt;b&gt;&lt;span style=&quot;color: #333333;&quot;&gt;책을 참고하여 풀이 및 작성하였습니다.&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;
&lt;p&gt;&amp;nbsp;&lt;/p&gt;</description>
      <category>포렌식/CTF</category>
      <category>Forensic #CTF #디지털포렌식 #disk forensic</category>
      <author>보안보</author>
      <guid isPermaLink="true">https://securitymax.tistory.com/136</guid>
      <comments>https://securitymax.tistory.com/136#entry136comment</comments>
      <pubDate>Mon, 11 Nov 2019 01:56:13 +0900</pubDate>
    </item>
  </channel>
</rss>