社内勉強会 20120518

Embed Size (px)

DESCRIPTION

社内勉強会で発表したやつ

Citation preview

  • 1. 20125181

2. 2 3. 3 4. 4 5. 5 6. 6 7. 7 8. (: Honeypot) Wikipedia8 9. 9 10. 10 11. 11 12. 12 13. 13 14. 23 http://www.npa.go.jp/cyberpolice/detect/pdf/H23_betsu.pdf 14 15. 15 16. 16 17. 17 18. 18 19. Dionaea Nepenthes 19 20. Dionaea?? 20 21. Nepenthes?? 21 22. 122 23. Dionaea http, ftp, VoIP, SQL Sqlite 23 24. VPS VPS ( Virtual Private Server ) root Web/ 24 25. IP http://www.onamae-server.com/compare/25 26. SSH26 27. libev >=4.04, schmorp.de libglib >=2.20 libssl, openssl.org liblcfg, liblcfg.carnivore.it libemu, libemu.carnivore.it python >=3.2, python.org sqlite >=3.3.6 sqlite.org readline >=3 cnswww.cns.cwru.edu cython >0.14.1, cython.org libudns, corpit.ru libcurl >=7.18, curl.haxx.se libpcap >=1.1.1, tcpdump.org libnl from git, infradead.org (optional) libgc >=6.8, hp.com (optional) 27 28. 28 29. 20124 3933 4 29 30. 30 31. IP IP 31 32. IP WebAPI GETIP XML 32 33. China 62United States33Japan 8Korea, Republic of 7 Germany 7 Netherlands6 Australia 5 India 5Mexico 5 France 4Israel 3Brazil 3 33 34. 34 35. 35 36. httpd:80 654mssqld:1433 448smbd:445 419mysqld:3306 115 epmapper:135 10236 37. 80 654 HTTP1433448 MS SQL Server 445419 Windows 3306115 MySQL 135102 Windows 37 38. 38 39. 39 40. @#$% 11123abcInternetmanagersecurity!@#$%^ 110 123asdabc monitorserver!@#$%^&111 123qweabc123networksql!@#$%^&* 111111147258abcdoracle super!@#$%^&*(11111111147258369 admin pass sybase!@#$%^&*() 1212122009administrator passwd system%null% 123 2600alpha password telnet*12312354321 asdfprivatetest0123321654321asdfghpublic tivoli0000 1234666666computerreal user000000 12345 741852databaseroot xp00000000 123456741852963 debug sa0071234567 888 default sa123010101 123456788888enablesasa0147852123456789 888888godblessyou sasql11234qwer88888888ihavenopass secret 40 41. 441 42. 42 43. 43 44. Clamscan OK 44 45. Virustotal 45 46. PE_SALITY.JER 24 TROJ_DRPR.DEJ 18 PE_SALITY.RL 14PE_SALITY.JER12TROJ_INJECTO.VY 11 46 47. 1 PE_SALITY.JER : Web "AUTORUN.INF" WebHOSTS 47 48. 2 TROJ_DRPR.DEJ Web48 49. 3 PE_SALITY.RL "AUTORUN.INF" 49 50. 4 PE_SALITY.JER : Web "AUTORUN.INF" WebHOSTS 50 51. 5TROJ_INJECT.VY Web 51 52. 52 53. 53