๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๐Ÿ’ ๋ณด์•ˆ·์ทจ์•ฝ์ /๐Ÿ”ธ์‹œ์Šคํ…œ·์šด์˜์ฒด์ œ

nc ๋ช…๋ น์–ด ์‚ฌ์šฉ๋ฒ•

by Jenny:! 2022. 8. 12.

netcat

netcat(์ดํ•˜ nc)์€ TCP๋‚˜ UDP ํ”„๋กœํ† ์ฝœ์„ ์‚ฌ์šฉํ•˜๋Š” ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ์—์„œ ๋ฐ์ดํ„ฐ๋ฅผ ์ฝ๊ณ  ์“ฐ๋Š” ๊ฐ„๋‹จํ•œ ํ”„๋กœ๊ทธ๋žจ์ด๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ๋Š” UNIX์˜ cat๊ณผ ์‚ฌ์šฉ๋ฒ•์ด ๋น„์Šทํ•˜์ง€๋งŒ cat์ด ํŒŒ์ผ์— ์“ฐ๊ฑฐ๋‚˜ ์ฝ๋“ฏ์ด nc๋Š” network connection์— ์ฝ๊ฑฐ๋‚˜ ์“ด๋‹ค. ์ด๊ฒƒ์€ ์Šคํฌ๋ฆฝํŠธ์™€ ๋ณ‘์šฉํ•˜์—ฌ network์— ๋Œ€ํ•œ debugging, testing tool๋กœ์จ ๋งค์šฐ ํŽธ๋ฆฌํ•˜์ง€๋งŒ ํ•ดํ‚น์—๋„ ์ด์šฉ ๋ฒ”์œ„๊ฐ€ ๋„“๋‹ค.

 

๋ฆฌ๋ˆ…์Šค์šฉ nc : http://netcat.sourceforge.net 

 

The GNU Netcat -- Official homepage

Welcome to the official GNU Netcat project homepage The GNU Netcat project What is Netcat? Netcat is a featured networking utility which reads and writes data across network connections, using the TCP/IP protocol. It is designed to be a reliable "back-end"

netcat.sourceforge.net

์œˆ๋„์šฐ์šฉ nc : http://www.securityfocus.com/tools/139/scoreit 

 

Bugtraq

 

bugtraq.securityfocus.com

 

์‚ฌ์šฉ๋ฒ•

$ yum install nc #์„ค์น˜
$ nc [OPTIONS] [TARGET HOST] [PORT]

 

์˜ต์…˜ ์„ค๋ช…
-u TCP ๋Œ€์‹  UDP ์—ฐ๊ฒฐ
-n ํ˜ธ์ŠคํŠธ ๋„ค์ž„๊ณผ ํฌํŠธ๋ฅผ ์ˆซ์ž๋กœ๋งŒ ์ž…๋ ฅ๋ฐ›์Œ
-o  [filename] ์ฃผ๊ณ  ๋ฐ›๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ํ—ฅ์Šค๋คํ”„ํ•˜์—ฌ ํŒŒ์ผ์— ์ €์žฅ
-s [ip address or DNS] local ip address๋ฅผ ์ง€์ • (์ผ๋ถ€ ํ”Œ๋žซํผ ์ง€์› X)
-e [filename] DGAPING_SECURITY_HOLE ์˜ต์…˜์œผ๋กœ Make๋˜์—ˆ์„ ๋•Œ ์‚ฌ์šฉ ๊ฐ€๋Šฅ
-p [port number or name] ์†Œ์Šค ํฌํŠธ ์ง€์ • (์ฃผ๋กœ -l ๊ณผ ํ•จ๊ป˜ ์‚ฌ์šฉ)
-l LISTEN ๋ชจ๋“œ๋กœ ํฌํŠธ ๋„์›€ (nc๊ฐ€ ์„œ๋ฒ„์ผ ๋•Œ, ์ฃผ๋กœ -p์™€ ํ•จ๊ป˜ ์‚ฌ์šฉ)
-i [interval time]  nc๋Š” ์ผ๋ฐ˜์ ์œผ๋กœ 8K ์”ฉ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณด๋‚ด๊ณ  ๋ฐ›๋Š”๋ฐ, ๊ทธ๋ ‡๊ฒŒ Standard input์˜ ํ•œ ๋ผ์ธ์”ฉ interval time๋งˆ๋‹ค ๋ณด๋‚ด๊ฒŒ ๋จ
-t DTELNET ์˜ต์…˜์œผ๋กœ ์ปดํŒŒ์ผ ๋˜์—ˆ์„ ๋•Œ ์‚ฌ์šฉ ๊ฐ€๋Šฅ, telnetd์— ์ ‘์†์ด ๊ฐ€๋Šฅํ•˜๋„๋ก ์ ‘์†์‹œ telnet๊ณผ ๊ฐ™์€ ํ˜‘์ƒ ๊ณผ์ •์„ ๊ฑฐ์นจ
-r ํฌํŠธ ์ง€์ •์ด ์—ฌ๋Ÿฌ ๊ฐœ๋กœ ๋˜์–ด ์žˆ์œผ๋ฉด scanning ์ˆœ์„œ๋ฅผ randomizeํ•˜๊ณ , -p ์˜ต์…˜์—์„œ ์ง€์ •๊ฐ€๋Šฅํ•œ local port๋„ randomize (์ฃผ์˜ ํ•  ๊ฒƒ์€ -p๊ฐ€ -r์„ override)
-z ๋‹จ์ˆœ ํฌํŠธ ์Šค์บ”๋งŒ ์ง„ํ–‰ (์ตœ์†Œํ•œ์˜ ๋ฐ์ดํ„ฐ๋กœ ์—ฐ๊ฒฐ ์ด๋ฃธ)
-v ๋” ๋งŽ์€ ์ •๋ณด๋ฅผ ํ™•์ธ (verbosity๋ฅผ ์ฆ๊ฐ€)

 

 

์ฐธ๊ณ 

https://htst.tistory.com/61

https://sh-safer.tistory.com/74