º£Æü¡¢»ä¤¿¤Á¤Ï¤¢¤Ê¤¿¤Î¥í¡¼¥«¥ë¥Í¥Ã¥È¥ï¡¼¥¯¾å¤ÎFacebook¥×¥í¥Õ¥£¡¼¥ë¤ò¥Ï¥Ã¥¯¤·¤Þ¤¹¡£¡Ö¤³¤ì¤Ï¤É¤¦Ìò¤ËΩ¤Ä¤Î¡©»ä°Ê³°¤Ïï¤â»ä¤Î¥Í¥Ã¥È¥ï¡¼¥¯¤ò»È¤ï¤Ê¤¤¤¸¤ã¤Ê¤¤¤«¡£¡×¤È»×¤¦¤«¤â¤·¤ì¤Þ¤»¤ó¡£¤¢¤Ê¤¿¤Ï̵ÎÁ¤ÇÍøÍѲÄǽ¤Ê¾¤ÎWi-Fi¥Í¥Ã¥È¥ï¡¼¥¯¾å¤Ç¤³¤ì¤ò»ÈÍѤ·¤Æ¡¢µ®½Å¤ÊFacebook¤Î¥×¥í¥Õ¥£¡¼¥ë¤ò¥¯¥é¥Ã¥¯¤¹¤ë¤³¤È¤¬¤Ç¤¤Þ¤¹¡ª
¥¯¥¤¥Ã¥¯¥á¥â¡§¤¢¤Ê¤¿¤Î¥¿¡¼¥²¥Ã¥È¤¬±ÜÍ÷¤·¤Æ¤ë¾ì¹çư¤¤Þ¤¹¡£¤½¤Î»þ¤Îhttp¡Êhttps¤Ç¤Ï¤¢¤ê¤Þ¤»¤ó¡Ë¤Î¾å¤ÎFacebook¤Ë¤è¤Ã¤Æ¥Ï¥Ã¥¯¤ò¹Ô¤Ã¤Æ¤¤¤Þ¤¹¡£
¤É¤¦¤ä¤Ã¤Æ¡©»ä¤¿¤Á¤Ï¡Öcookie injection method¡×¤È¸Æ¤Ð¤ì¤ëÍ̾¤ÊÊýË¡¤ò»ÈÍѤ¹¤ë¤Ä¤â¤ê¤Ç¤¹¡£¤³¤ì¤Ï¡¢¡Ö¥¨¥ê¡¼¥È¡×¤«¤é±ó¤¯¤Ê¤ë¤Î¤«¤â¤·¤ì¤Þ¤»¤ó¤¬¡¢¤¢¤Ê¤¿¤ÏºÇ½é¤Ë¡¢Linux¥Ç¥£¥¹¥È¥ê¥Ó¥å¡¼¥·¥ç¥ó¤ËÀºÄ̤·¤Æ¼èÆÀ¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£
¥¹¥Æ¥Ã¥×1¡§Àµ¤·¤¤ºàÎÁ¤ò¥²¥Ã¥È¤³¤Î¥Ï¥Ã¥¯¤Ç¤Ï¡¢¤¤¤¯¤Ä¤«¤Î¤³¤È¤¬É¬Íפˤʤê¤Þ¤¹¡£Èà¤é¤Ï»ä¤¿¤Á¤¬É¬ÍפȤ¹¤ë¤Û¤È¤ó¤É¤¹¤Ù¤Æ¤ò»ý¤Ã¤Æ¤¤¤ë¤Î¤Ç»ä¤«¤é¤ÎºÇ¹â¤ÎÄó°Æ¤Ï¤¢¤Ê¤¿¤¬ºÇ½é¤ËBacktrack¡¢Kali¡¡Linux¡¢¤Þ¤¿¤ÏBugtraq¤ò¥¤¥ó¥¹¥È¡¼¥ë¤¹¤ë¤³¤È¤Ç¤¹¡£
¤³¤Î¾®¤µ¤Ê¼êÉʤ¿¤á¤Ë¡¢»ä¤¿¤Á¤ÏɬÍפˤʤê¤Þ¤¹¡§
¤½¤ì¤Ç¤Ï¡¢¤¤¤¯¤Ä¤«¤Î¥Þ¥¸¥Ã¥¯¤ò¤ä¤Ã¤Æµ¯Æ°¤·¤Þ¤·¤ç¤¦¡ª¡§D *
¥¹¥Æ¥Ã¥×2¡§¥Í¥Ã¥È¥ï¡¼¥¯¥¹¥¥ã¥ó¤Þ¤º¡¢¼ÂºÝ¤Ë¥¿¡¼¥²¥Ã¥È¤ËÀܳ¤¹¤ë¤Ë¤Ï¡¢IP¥¢¥É¥ì¥¹¤¬É¬Íפˤʤê¤Þ¤¹¡£¤½¤ì¤òÆÀ¤ë¤¿¤á¤Ë¤Ï¡¢Nmap¤Ï¡¢¥Í¥Ã¥È¥ï¡¼¥¯¥¹¥¥ã¥ó¤ò¹Ô¤¦É¬Íפ¬¤¢¤ê¤Þ¤¹¡£¤À¤«¤éÀè¤Ë¹Ô¤¯¤È¡¢¥¿¡¼¥ß¥Ê¥ë¤òµ¯Æ°¤·¡¢¼¡¤Î¥³¥Þ¥ó¥É¤òÆþÎϤ·¤Þ¤¹¡£
nmap -F 192.168.xx.xx/24 ¤³¤Î¥³¥Þ¥ó¥É¤Ï¡¢¤½¤ì¤ËÀܳ¤µ¤ì¤¿Ç¤°Õ¤ÎIP¥¢¥É¥ì¥¹¤Ë¤Ä¤¤¤Æ¤Ï¡¢¥Í¥Ã¥È¥ï¡¼¥¯¤ò¥¹¥¥ã¥ó¤·¤Þ¤¹¡£-F¤Ï¡Ö¹â®¥â¡¼¥É¡×¥³¥ó¥½¡¼¥ë¤ò»ÈÍѤ¹¤ë¤è¤¦¤Ë»Ø¼¨¤Ç¤¤Þ¤¹¡£Àµ¤·¤¯¤Ç¤¤Æ¤¤¤ì¤Ð¡¢¤³¤Î¤è¤¦¤Ê¤â¤Î¤¬É½¼¨¤µ¤ì¤ë¤Ï¤º¤Ç¤¹¡£
¥¹¥Æ¥Ã¥×3¡§man-in-the-middle¹¶·â¤Î³«»Ïº£¡¢»ä¤¿¤Á¤Ï¡¢man-in-the-middle¹¶·â¡¢Î¬¤·¤ÆMITM¤ò³«»Ï¤¹¤ë¤Ä¤â¤ê¤À¡£
MITM¹¶·â¤Ï¡¢¹¶·â¤¬»ä¤¿¤Á¤ÎMAC¥¢¥É¥ì¥¹¤òµ¶Áõ¤·¤¿¤¢¤ë¥µ¡¼¥Ð¡¼/±þÅú¼Ô¤¬Áê¸ß¤Ë¥á¥Ã¥»¡¼¥¸¤òÁ÷¿®¤·¤¿¤È¤¤Ë¡¢ Èà¤Ï¡¢¤½¤Î¥á¥Ã¥»¡¼¥¸¤ò¼õ¿®¤·¤¿¤³¤È¤Ï¤¢¤ê¤Þ¤»¤ó Èà¤Ï»ä㤬man-in-the-middle¹¶·â¤·¤Æ»ä¤¿¤Á¤Ï¡¢Á÷¿®¤·¤¿¥á¥Ã¥»¡¼¥¸¤ò¼õ¿®¤·¤Þ¤¹¡£ man-in-the-middle¹¶·â¡ª
¹¶·â¤Î³«»Ï³«»Ï¤¹¤ë¤Ë¤Ï¡¢¿·¤·¤¤¥¿¡¼¥ß¥Ê¥ë¥¦¥£¥ó¥É¥¦¤Ç¼¡¤Î¥³¥Þ¥ó¥É¤òÆþÎϤ·¤Þ¤¹¡£
sudo echo 1 >> /proc/sys/net/ipv4/ip_forward ¤³¤ì¤Ï¤¢¤Ê¤¿¤ÎIP¥¢¥É¥ì¥¹¤òžÁ÷¤·¤Þ¤¹¡£º£¡¢»ä¤¿¤Á¤Ï¡¢¿·¤·¤¤Ã¼Ëö¥¦¥£¥ó¥É¥¦¤ò³«¤¡¢¼¡¤Î¥³¥Þ¥ó¥É¤òÆþÎϤ·¤ÆMITM¤ò³«»Ï¤·¤Þ¤¹¡£
sudo arpspoof -i [Interface] -t [target] [default gateway] ¤¢¤Ê¤¿¤Î¥¤¥ó¥¿¡¼¥Õ¥§¥¤¥¹¤È¥Ç¥Õ¥©¥ë¥È¥²¡¼¥È¥¦¥§¥¤¤¬¤ï¤«¤é¤Ê¤¤¾ì¹ç¤Ï¡¢¿·¤·¤¤Ã¼Ëö¤òµ¯Æ°¤·¡¢¼¡¤Î¤è¤¦¤ËÆþÎϤ·¤Þ¤¹¡£
¿·¤·¤¤Ã¼Ëö¥¦¥£¥ó¥É¥¦¤ò³«¤¤¤Æ¡Ê¤â¤¦°ìÅÙ-_-¡Ë¤Ï¡¢¼¡¤Î¥³¥Þ¥ó¥É¤òÆþÎϤ·¤Þ¤¹¡£
sudo arpspoof -i [interface] -t [default gateway] [target] ![]() Ãí¡§Î¾Êý¤Îarpspoof¤Î¥³¥Þ¥ó¥É¤¬ÆþÎϤµ¤ì¤¿¸å¡¢¥¿¡¼¥ß¥Ê¥ë¤òÊĤ¸¤Ê¤¤¤Ç¤¯¤À¤µ¤¤¡£
¥¹¥Æ¥Ã¥×4¡§Firefox¤ÈWireshark¤Î¡Ê¤Û¤Ü´°Î»¡ª¡Ë»ä¤¿¤Á¤Ï¡¢¤³¤Î¥Ï¥Ã¥¯¤ò´°Î»¤¹¤ë¤¿¤á¤Ë¤¤¤¯¤Ä¤«¤Î¤è¤ê¿¤¯¤Î¤â¤Î¤¬É¬ÍפǤ¹¡ª
¤½¤Î¸åGreasemonkey¤È¥¯¥Ã¥¡¼¥¤¥ó¥¸¥§¥¯¥¿¥¹¥¯¥ê¥×¥È¡£¤½¤Î¸å¡¢Wireshark¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤Þ¤¹¡£¥¿¡¼¥ß¥Ê¥ë¥¦¥£¥ó¥É¥¦¤Ë¼¡¤Î¥³¥Þ¥ó¥É¤òÆþÎϤ¹¤ë¤³¤È¤Ë¤è¤Ã¤Æ¹Ô¤¦¤³¤È¤¬¤Ç¤¤Þ¤¹¡£
sudo apt-get install wireshark ¤½¤Î¸å¡¢¤¢¤Ê¤¿¤Î¥¤¥ó¥¿¡¼¥Õ¥§¥¤¥¹¤òÁªÂò¤·¤Æ¡¢¥¥ã¥×¥Á¥ã¤ò³«»Ï¡£¾åÉô¤Ë¤Ï¡¢¤¢¤Ê¤¿¤¬¥Õ¥£¥ë¥¿¤òÄɲ乤뤳¤È¤¬¤Ç¤¤Þ¤¹ÆþÎϥܥ寥¹¤¬É½¼¨¤µ¤ì¤ë¤Ï¤º¤Ç¤¹¡£º£¡¢¤³¤Î¥Õ¥£¥ë¥¿¤òÆþÎϤ·¤Þ¤¹¡£
http.cookie contains DATR ¤³¤ì¤Ç¡¢Wireshark¤Î¥ê¥¹¥È¤ò¼èÆÀ¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£¥Æ¥¥¹¥ÈGET¤¬´Þ¤Þ¤ì¤Æ¤¤¤ë¥¯¥Ã¥¡¼¤ò¸¡º÷¤·¤Þ¤¹¡£¤½¤ì¤ò¸«¤Ä¤±¤Æ¡¢¥Þ¥¦¥¹¤Îº¸¥Ü¥¿¥ó¤ÇÁªÂò¤·¤Æ¥³¥Ô¡¼¤ò¥¯¥ê¥Ã¥¯¤·¤Æ¡¢¥Ð¥¤¥È¤òÁªÂò¤·¡¢°õºþ²Äǽ¤Ê¥Æ¥¥¹¥È¤òÁªÂò¤·¤Þ¤¹¡£
º£Wireshark¤Î¤Ë¹Ô¤¯¤ÈFacebook¤Ë¥¢¥¯¥»¥¹¤·¤Æ¤¯¤À¤µ¤¤¡£¤¢¤Ê¤¿¤¬¥í¥°¥¤¥ó¤·¤Æ¤¤¤Ê¤¤¤³¤È¤ò³Îǧ¤·¤Æ¤¯¤À¤µ¤¤¡£¼¡¤Ë¡¢Facebook¥í¥°¥¤¥ó¥Ú¡¼¥¸¤ËÌá¤Ã¤Æ¡¢[ALT]+C¤ò²¡¤·¤Æ¡¢¥¯¥Ã¥¡¼¤òŽ¤Ã¤Æ¤¯¤À¤µ¤¤¡£
»ä¤ÎºÇ½ªÅª¤Ê¥³¥á¥ó¥È¤³¤Î¥Ï¥Ã¥¯¤Ï¡¢¹âÅ٤˸«¤¨¤ë¤«¤â¤·¤ì¤Þ¤»¤ó¤¬¡¢¤½¤ì¤Ï¼ÂºÝ¤Ë¤ÏËÜÅö¤Ë´Êñ¤Ç¤¹¡£¤¢¤Ê¤¿¤Ï¤¹¤Ù¤Æ¤Î¼ê½ç¤òÂÇÇˤ¹¤ë¤È¡¢¤½¤ì¤Ï¥±¡¼¥¤Î°ìÉô¤Ç¤¹¡ª¡§D
Facebook¤Î¥»¥¥å¥ê¥Æ¥£¤¬Èó¾ï¤Ë¶¯ÎϤǤϤʤ¤¤³¤È¤ÏÌÀ¤é¤«¤Ç¤¹¡£:P
Á°¥Ö¥í¥°¤è¤ê |
¤³¤Îµ»ö¤Ë
>
- ¼ñÌ£¤È¥¹¥Ý¡¼¥Ä
>
- ¼ñÌ£
>
- ¤½¤Î¾¼ñÌ£