Security Study/Docker

theHarvester๋ฅผ ํ†ตํ•œ ์ด๋ฉ”์ผ ๋ฐ ๋„๋ฉ”์ธ ์ •๋ณด ์ˆ˜์ง‘

๐“›๐“พ๐“ฌ๐“ฎ๐“ฝ๐“ฎ_๐“ข๐“ฝ๐“ฎ๐“ต๐“ต๐“ช 2022. 12. 1.
728x90
๋ฐ˜์‘ํ˜•

ํ•ด๋‹น ๋ธ”๋กœ๊ทธ๋Š” ํ•ดํ‚น ๋ฐ ๋ณด์•ˆ ๋ธ”๋กœ๊ทธ๋กœ ๊ณต๋ถ€ ๋ฐ ์—ฐ๊ตฌ์šฉ์œผ๋กœ ์ž‘์„ฑ๋˜์–ด์ง€๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์•„๋ž˜์˜ ๋‚ด์šฉ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•ดํ‚น ์‹œ๋„ ๋ฐ ์‹ค์ œ ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•˜์—ฌ ์ผ์–ด๋‚˜๋Š” ๋ชจ๋“  ์ฑ…์ž„์€ ๋ณธ์ธ(๋”ฐ๋ผํ•œ์ž)์—๊ฒŒ ์žˆ์Œ์„ ์•Œ๋ ค๋“œ๋ฆฌ๋ฉฐ, ๊ธ€์“ด์ด๋Š” ์•„๋ฌด๋Ÿฐ ์ฑ…์ž„์„ ์ง€์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ๊ผญ ๊ณต๋ถ€ ๋ฐ ์—ฐ๊ตฌ์šฉ์œผ๋กœ๋งŒ ์‚ฌ์šฉํ•˜์—ฌ ์ฃผ์‹œ๊ธธ ๋ฐ”๋ž๋‹ˆ๋‹ค. ๊ฐ์‚ฌํ•ฉ๋‹ˆ๋‹ค.

์—…๋ฌด ๋ฐ ๊ณต๋ถ€ ๋“ฑ์„ ํ•˜๋‹ค๋ณด๋ฉด OSINT(Open Source INTelligence) ๊ณต๊ฐœ์ถœ์ฒ˜์ •๋ณด๊ฐ€ ๋งŽ์ด ํ•„์š”ํ•œ ๊ฒฝ์šฐ๊ฐ€ ์žˆ๋‹ค.

๊ทธ๋Ÿฌ๋‹ค ๋ณด๋‹ˆ ํ•˜๋‚˜ํ•˜๋‚˜ ๊ฒ€์ƒ‰์„ ํ•ด๊ฐ€๋ฉด์„œ ๋งŽ์€ ์ •๋ณด๋ฅผ ์ฐพ์„ ์ˆ˜๊ฐ€ ์—†๋‹ค. ์‚ฌ์‹ค๋Œ€๋กœ ๋งํ•˜๋ฉด ์ฐพ์„ ์ˆ˜๋Š” ์žˆ๋‹ค. ์‹œ๊ฐ„์ด ๋งค์šฐ ๋งŽ์ด ๊ฑธ๋ ค์„œ ๋ฌธ์ œ์ง€...

 

๊ทธ๋ž˜์„œ ์—ฌ๋Ÿฌ๊ฐ€์ง€ online์œผ๋กœ ์ œ๊ณต๋˜๋Š” OSINT์™€ maltego, theHarvester ๋“ฑ ํ”„๋กœ๊ทธ๋žจ๋“ค ๋˜ํ•œ ๋งŽ์ด ์ œ๊ณต๋˜์–ด์ง€๊ณ  ์žˆ๋‹ค.

๊ทธ ์ค‘์—์„œ theHarvester์— ๋Œ€ํ•ด์„œ ์˜ค๋Š˜์€ ์ž‘์„ฑํ•ด๋ณด๋ ค๊ณ  ํ•œ๋‹ค.

 

theHarvester์˜ ๊ฒฝ์šฐ ์นจํˆฌํ…Œ์ŠคํŠธ์˜ ์ดˆ๊ธฐ ๋‹จ๊ณ„์—์„œ ์ •๋ณด์ˆ˜์ง‘ ๋“ฑ์„ ํ•˜๊ธฐ์œ„ํ•ด ์‚ฌ์šฉ๋˜๋ฉฐ, ์ด๋ฉ”์ผ ๊ณ„์ •, ํ•˜์œ„ ๋„๋ฉ”์ธ ์ด๋ฆ„, ๊ฐ€์ƒ ํ˜ธ์ŠคํŠธ ๋“ฑ์˜ ์ •๋ณด๋ฅผ ๊ฒ€์ƒ‰์—”์ง„์„ ํ†ตํ•ด ์ˆ˜์ง‘ํ•œ๋‹ค.

 

kali linux๋ฅผ ์‚ฌ์šฉํ•˜๊ฒŒ ๋˜๋ฉด ๊ธฐ๋ณธ์ ์œผ๋กœ theHarvester๊ฐ€ ์„ค์น˜๋˜์–ด ์žˆ์–ด์„œ theHarvester -h ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด ํ™•์ธํ•˜๊ณ  ์‚ฌ์šฉํ•จ์— ํฐ ๋ฌธ์ œ๊ฐ€ ์—†๋‹ค.

์ตœ๊ทผ์— ์‚ฌ์šฉ์„ ํ•ด์•ผํ•˜๋‹ค๋ณด๋‹ˆ ์„ค์น˜๋ฅผ ํ•ด์•ผํ•˜๋Š” ์ฒ˜์ง€๊ฐ€ ์™”๋‹ค. ๊ทธ๋ž˜์„œ ์„ค์น˜๋ฅผ ํ•ด๋ณด์•˜๋Š”๋ฐ github์—์„œ ์„ค์น˜๋ฅผ ์ง„ํ–‰ํ•ด๋ณด์•˜์ง€๋งŒ ์ •์ƒ์ ์œผ๋กœ ์•ˆ๋˜๋”๋ผ.... ๊ทธ๋ž˜์„œ docker๋ฅผ ์ด์šฉํ•˜์—ฌ ์„ค์น˜ํ•ด๋ณด์•˜๋Š”๋ฐ ๊ณต์‹ github๋Š” ์—ฌ๊ธฐ๋‹ค.

https://github.com/laramies/theHarvester

 

GitHub - laramies/theHarvester: E-mails, subdomains and names Harvester - OSINT

E-mails, subdomains and names Harvester - OSINT . Contribute to laramies/theHarvester development by creating an account on GitHub.

github.com

์„ค์น˜๋ฅผ ํ•˜๊ธฐ์œ„ํ•ด์„œ requirements.txt ํŒŒ์ผ์„ ์„ค์น˜๋ฅผ ํ•ด์•ผํ•˜๋Š”๋ฐ ์ผ๋‹จ ๋ฒ„์ „๋“ค๋„ ์•ˆ๋งž๋Š” ๊ฒƒ์ด ๋งŽ์•„์„œ ์ˆ˜์ •์„ ํ•ด์•ผํ•œ๋‹ค.

๋ญ ๋งž๋Š” ๋ฒ„์ „ ์ฐพ์•„์„œ ์„ค์น˜๋ฅผ ํ•ด๋„ ์•ˆ๋œ๋‹ค... ๊ทธ๋ž˜์„œ ๊ฒฐ๊ตญ docker๋ฅผ ํƒํ•˜์˜€๋˜๊ฒƒ์ด๋‹ค...:D

 

Docker๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„ค์น˜ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ณด์ž

git clone https://github.com/laramies/theHarvester

cd theHarvester // git clone์œผ๋กœ ๋ฐ›์€ theHarvester ํด๋”๋กœ ์ด๋™

mkdir ~/.theHarvester // home ๊ฒฝ๋กœ์— .theHarvester ํด๋” ์ƒ์„ฑ(.์œผ๋กœ ์ˆจ๊น€ํด๋”๊ฐ€ ๋˜์–ด ํ™•์ธ ํ•˜๊ธฐ์œ„ํ•ด ls -al์ž…๋ ฅ)

cp api-keys.yaml ~/.theHarvester // ๊ธฐ์กด์˜ theHarvester ํด๋”์—์„œ api-keys.yaml ํŒŒ์ผ์„ ์ƒˆ๋กœ๋งŒ๋“  .theHarvester ํด๋”๋กœ ๋ณต์‚ฌ

docker build -t theharvester . // build ์ง„ํ–‰

๊ทผ๋ฐ build๋ฅผ ์‹œํ‚ค๊ธฐ์ „์— api-keys.yamlํŒŒ์ผ์ด ๋ญ”์ง€ ๊ถ๊ธˆํ• ์ˆ˜๋„ ์žˆ๋‹ค.

yamlํŒŒ์ผ์˜ ๊ฒฝ์šฐ ์—ด์–ด๋ณด๋ฉด ๊ฒ€์ƒ‰์—”์ง„๋“ค์˜ apiํ‚ค๋ฅผ ์ž…๋ ฅํ•˜๋„๋ก ๋˜์–ด์žˆ๋‹ค. ํ•„์š”์—๋”ฐ๋ผ api ํ‚ค๋ฅผ ์ž…๋ ฅํ•˜์—ฌ ๋”๋งŽ์€ ์ •๋ณด๋ฅผ ๋ฐ›์•„ ์˜ฌ์ˆ˜ ์žˆ๋‹ค.

apikeys:
  bevigil:
   key:

  binaryedge:
    key:

  bing:
    key:

  bufferoverun:
    key:
    
    ...

์ด๋Ÿฐ์‹์œผ๋กœ ๊ตฌ์„ฑ๋˜์–ด์žˆ์–ด apiํ‚ค๋ฅผ ์ž…๋ ฅํ•˜๋ฉด๋œ๋‹ค.

๋นŒ๋“œ๋ฅผ ์‹œ์ž‘ํ•˜๋ฉด ๋œ๋‹ค.

 

๊ทธ๋Ÿผ docker images ๋ฅผ ์ž…๋ ฅํ•ด๋ณด๋ฉด ์ด๋ฏธ์ง€๊ฐ€ ์ƒ์„ฑ๋œ ๊ฒƒ์„ ํ™•์ธํ• ์ˆ˜์žˆ๋‹ค.

docker run --rm -it --mount type=bind,source="$HOME/.theHarvester/api-keys.yaml",target="/app/api-keys.yaml" --entrypoint "/app/theHarvester.py" theharvester -h // help๋ช…๋ น์–ด

docker run --rm -it --mount type=bind,source="$HOME/.theHarvester/api-keys.yaml",target="/app/api-keys.yaml" --entrypoint "/app/theHarvester.py" theharvester -d ๋„๋ฉ”์ธ(example.com) -l 500 -b all

๋„๋ฉ”์ธ์„ ๊ธฐ๋ฐ˜์œผ๋กœ ๊ฒ€์ƒ‰์„ ํ•˜๊ธฐ์œ„ํ•ด์„  ๋‘๋ฒˆ์งธ ์ค„์„ ์ž…๋ ฅํ•˜๋ฉด๋œ๋‹ค. -d๋ช…๋ น์–ด๋Š” ๋„๋ฉ”์ธ์„ ์ž…๋ ฅํ•˜๋Š” ๊ฒƒ์ด๊ณ  -l๋ช…๋ น์–ด๋Š” 500๊ฐœ์˜ ๊ฒ€์ƒ‰๊ฐ’ -b๋Š” ๊ฒ€์ƒ‰์—”์ง„์„ ์„ ํƒํ•˜๋Š”๊ฒƒ์ด๋‹ค. ์ž์„ธํ•œ๊ฒƒ์€ -h๋ช…๋ น์–ด๋ฅผ ํ†ตํ•˜์—ฌ ํ™•์ธ๊ฐ€๋Šฅํ•˜๋‹ค.

728x90
๋ฐ˜์‘ํ˜•

๋Œ“๊ธ€