当前位置:网站首页>6K6w5LiA5qyh5pS75Ye75YiG5p6Q
6K6w5LiA5qyh5pS75Ye75YiG5p6Q
2022-07-28 20:46:00 【sec0nd_】
前言
为了帮助大家理解掌握知识,幻想的公司和黑客,以下故事均为虚构,如有雷同,纯属巧合。
蜜罐感知
某天我在办公室摸鱼,突然发现蜜罐平台有一条扫描感知信息(192.168.10.78主机扫描同网段其他主机),我心里一惊,正常人都不会知道蜜罐的地址,更不会扫描蜜罐的端口。
日志分析
跟师傅说后越发越觉得不对劲,马上将192.168.10.78主机进行了下线隔离,然后起身跟大师傅去看这个机子的日志记录。
找到的日志记录大致如下:
nginx的日志格式见这位大师傅的文章:https://blog.csdn.net/LJFPHP/article/details/78484889
大致可以读出以下信息:
客户端ip:192.168.10.5
请求方式:GET
请求路径:/xxx/xxxxxxxx?
返回码:200
返回包字节:23143
X_Forwarded-For IP 地址:1.2.3.4
这个地址猜测是黑客真实ip
waf拦截记录分析
看到客户ip是192.168.10.5,猜测这个是一台反向代理,黑客打了反向代理的机子,被反向代理映射到了192.168.10.78的机子上。
然后去waf上面查询了192.168.10.5的被攻击的记录,下面比如是一个waf界面(虚构),大概有两千多条记录,各种攻击方法都尝试了……
攻击者ip也确实为1.2.3.4
反向代理文章:https://blog.csdn.net/zhanjie2009/article/details/122763758
攻击链分析
黑客发现了公司的一个对外服务网站,对其进行测试,尝试了2k次之后根据某一篇漏洞复现文章打进来了,达到了内网的192.168.10.78的机子上,然后提权、内网横移、域控
可惜在内网横移的过程中不小心扫到了蜜罐,导致被发现
边栏推荐
- HCIP(8)
- Ruiji takeout project - development of business development function Day2
- HCIP第七次实验
- [Ruiji takeout] day05 package management business development
- Desai wisdom number - line chart (stacking area chart): ranking of deposits of different occupational groups in the proportion of monthly income in 2022
- 软考网络工程师
- What testing services do third-party software testing institutions provide? Charging standard of software test report
- Differences of display values
- HCIP(12)
- 乌官员:乌克兰一半农产品经多瑙河港口出口
猜你喜欢
Part 8: creating camera classes
什么是时间复杂度
Record the fluent to solve the problem of a renderflex overflowed by 7.3 pixels on the bottom
Overall introduction of Ruiji takeout project
Win11 how to open software notification
XXX port is already in use
Soft exam network engineer
Sword finger offer II 054. Sum of all values greater than or equal to nodes (medium binary search tree DFS)
Day3 classification management of Ruiji takeout project
想要快速成长,先要经历重大打击!
随机推荐
Differences of display values
静态成员static详解
gprs网络指的是什么
If you want to grow rapidly, you must first experience a major blow!
容器化配置启动redis集群 单机6节点 3主3从
[CVPR 2021] cylinder3d: cylindrical asymmetric 3D convolution network for LIDAR point cloud segmentation
[CS231N]Lecture_2:Image Classification pipelin
ECMASript 5/6 笔记
纪念一下第一次写的线段树了喽(对应洛谷3372)
[Ruiji takeout] day05 package management business development
Necessary for in-depth learning: split the data set, split the labels according to the split pictures, and check the interval of all marked labels
What is time complexity
Sword finger offer II 063. replacement word (medium prefix tree string)
Kali source solution software cannot be installed correctly
深度学习必备:对数据集的拆分、根据拆分图片拆分labels、对全部标注标签进行区间检查
Openresty request authentication
105. Construct binary tree from preorder and inorder traversal sequence (medium binary tree DFS hash table binary tree)
Win11 how to open software notification
Jianzhi offer II 062. implement prefix tree (medium design dictionary tree prefix tree string)
tutorial/detailed_ workflow. Ipynb quantitative finance qlib Library