Security Study/System

์นด์นด์˜คํ†ก ๋น„๋ฐ€๋Œ€ํ™” ๋ถ„์„

๐“›๐“พ๐“ฌ๐“ฎ๐“ฝ๐“ฎ_๐“ข๐“ฝ๐“ฎ๐“ต๐“ต๐“ช 2015. 9. 3.
728x90
๋ฐ˜์‘ํ˜•

Certificate Pinning; SSL Pinning

End-to-end Encryption

Perfect Forward Secrecy


Cain & Abel์„ ํ†ตํ•œ MITM ๊ณต๊ฒฉ

Certificate Pinning

RSA ์•Œ๊ณ ๋ฆฌ์ฆ˜, AES๋ฅผ ํ†ตํ•˜์—ฌ ํ‚ค๋ฅผ ์ฃผ๊ณ ๋ฐ›์Œ

์†ก์‹ ์ž-> AES ํ‚ค๋กœ ์•”ํ˜ธํ™”๋œ ๋‚ด์šฉ์„ ์„œ๋ฒ„์— ๋ณด๋ƒ„

์„œ๋ฒ„์—์„œ ๋ณตํ˜ธํ™”ํ•˜์—ฌ ๋‚ด์šฉ์„ ์ €์žฅ, AES ํ‚ค๋กœ ์•”ํ˜ธํ™” ํ›„ ์ˆ˜์‹ ์ž์—๊ฒŒ ๋ณด๋ƒ„

End-to-end Encryption

Handshake ํ›„ ๊ฐ์ž์˜ ์ •๋ณด๋ฅผ ์ด์šฉํ•˜์—ฌ ๋ณตํ˜ธํ™”

Perfect Forward Secrecy

SSL Pinning, ํ‚ค๊ฐ’๋งŒ ์•Œ๋ฉด ๋šซ๋ฆฐ๋‹ค!

์‹ค์‹œ๊ฐ„ ๋„/๊ฐ์ฒญ์€ ๋ถˆ๊ฐ€

์ •๋ถ€์˜ ์ •์ฑ…์œผ๋กœ ์ธํ•ด์„œ์˜ ๋ฐ์ดํ„ฐ ์ˆ˜์ง‘์ด ์žˆ๋‹ค๋ฉด ๋˜ ๋ชจ๋ฅผ๊นŒ.

์นดํ†ก ์„œ๋ฒ„์— ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๋Š” ์ด์œ ?

- 3์ผ ~ ์ผ์ฃผ์ผ; ์ƒ๋Œ€๋ฐฉ์ด ๋ฐ›์ง€ ๋ชปํ–ˆ์„ ๋•Œ๋ฅผ ๋Œ€๋น„ํ•˜์—ฌ ์ €์žฅ.


A-------------->B

|

| (intercept!)

A(with encryption)------------------------>B

์•”ํ˜ธํ™”

A------------------------------(decoding)->B

๋ณตํ˜ธํ™”


์ฆ‰, ๋ณผ์ˆ˜๋„ ๋“ค์„์ˆ˜๋„ ์—†๋‹ค...

728x90
๋ฐ˜์‘ํ˜•

'Security Study > System' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

system /bin/sh ์ฃผ์†Œ ์ฐพ๊ธฐ  (0) 2015.09.15
system 2  (0) 2015.09.13
system 1์ผ์ฐจ  (0) 2015.09.12
system shellcode  (0) 2015.09.10
BOF(buffer overflow)  (0) 2015.09.03

๋Œ“๊ธ€