20 Ekim 2019 Pazar

unzip komutu

Giriş
.zip uzantılı dosyası oluşturup açmak içindir. .gz uzantılı dosyalar için gunzip komutu kullanılır. Eğer unzip komutu kurulu değilse, alternatif olarak şöyle yapabiliriz
jar xvf file.zip 
-o seçeneği
Zip dosyasının açılacağı dizini belirtir.

Örnek
Şöyle yaparız
PACKAGE_PATH="/opt/installtools/"
PACKAGE_FILE="foo.zip"

unzip -o $PACKAGE_FILE -d $PACKAGE_PATH; 
-q seçeneği
Açıklaması şöyle. Açma işlemini gerçekleştirirken dosya isimlerini ekrana yazmaz
-q     perform  operations  quietly  (-qq  = even quieter).  Ordinarily
       unzip prints the names of the files it's extracting or  testing,
       the extraction methods, any file or zipfile comments that may be
       stored in the archive, and possibly a summary when finished with
       each  archive.   The -q[q] options suppress the printing of some
       or all of these messages.
Şöyle yaparız.
unzip -q filename.zip

16 Ekim 2019 Çarşamba

nmap komutu

Giriş
Açıklaması şöyle.
Nmap provides a number of features for probing computer networks, including host discovery and service and operating system detection. These features are extensible by scripts that provide more advanced service detection, vulnerability detection, and other features.
Kullanım
Şöyle yaparız
$ nmap server.lan
Starting Nmap 7.80 ( https://nmap.org ) at 2020-10-11 22:55 AEDT
Nmap scan report for server.lan (192.168.0.15)
Host is up (0.00024s latency).
Not shown: 997 closed ports
PORT     STATE SERVICE
22/tcp   open  ssh
5432/tcp open  postgresql
9090/tcp open  zeus-admin

Nmap done: 1 IP address (1 host up) scanned in 0.05 seconds
-p seçeneği - Açık portları arar
Örnek
ssh portlarını taramak için şöyle yaparız. -oG ile grep yapılabilecek çıktı verir.
nmap -oG - -p 22 192.168.1.0/24  | grep /open/
-PR seçeneği - ARP Discovery
ARP Ping (arping) yapar. Böylece sadece ARP'a cevap veren makineler bulunabilir.
Örnek
Şöyle yaparız
nmap -SP -PR 192.168.3.*
-sL seçeneği - List Scan Yani IP Aralığı İle Çalışmak
Açıklaması şöyle
By default, Nmap does host discovery and then performs a port scan against each host it determines is online.
...
The list scan is a degenerate form of host discovery that simply lists each host of the network(s) specified, without sending any packets to the target hosts. By default, Nmap still does reverse-DNS resolution on the hosts to learn their names.
Örnek
Maalesef nmap iki tane IP aralığını açıkça yazılınca kabul etmiyor. Eğer yaparsak şu hatayı alırız
$ nmap -sL 10.1.1.1-10.1.1.3
Starting Nmap
Failed to resolve "10.1.1.1-10.1.1.3".
WARNING: No targets were specified, so 0 hosts scanned.
Nmap done: 0 IP addresses (0 hosts up) scanned in 0.04 seconds
Sadece bitiş IP adresinin son kısmını vermek gerekiyor. Yani şöyle yaparız
$ nmap -sL 10.1.1.1-3

-sC seçeneği
Örnek
Şöyle yaparız
$ nmap --top-ports 1000 -T4 -sC http://example.com
Nmap scan report for example.com {redacted}
Host is up (0.077s latency).
rDNS record for {redacted}: {redacted}
Not shown: 972 filtered ports
PORT      STATE  SERVICE
21/tcp    open   ftp
22/tcp    open   ssh
| ssh-hostkey: 
|   {redacted}
80/tcp    open   http
| http-methods: 
|_  Potentially risky methods: TRACE
|_http-title: Victim Site
139/tcp   open   netbios-ssn
443/tcp   open   https
| http-methods: 
|_  Potentially risky methods: TRACE
|_http-title: Site doesn't have a title (text/html; charset=UTF-8).
|_{redacted}
445/tcp   open   microsoft-ds
5901/tcp  open   vnc-1
| vnc-info: 
|   Protocol version: 3.8
|   Security types: 
|_    VNC Authentication (2)
8080/tcp  open   http-proxy
|_http-title: 400 Bad Request
8081/tcp  open   blackice-icecap

Açıklaması şöyle
--top-ports 1000: This option tells Nmap to only scan the top 1000 most common ports. This can save time if you are scanning a large network.
-T4: This option tells Nmap to use a more aggressive scanning technique. This will increase the speed of the scan, but it may also make it more noticeable to the target.
-sC: This option tells Nmap to perform a comprehensive scan of the target host. This includes scanning for open ports, services, and operating system information.

-sn seçeneği - no port scan (Disable port scanning. Host discovery only)
Ping'leyerek scan yapar.
Örnek
Şöyle yaparız.
nmap -oG - -sn 192.168.3.2-254
Örnek
Şöyle yaparız
nmap -sn 192.168.1.0/24  # Ping scan
-sP seçeneği - no port scan
Sadece "up" olan bilgisayarları görmek için kullanılır. Yeni sürümde -sn seçeneği oldu
Şöyle yaparız.
nmap -sP 192.168.3.0/24
-sS seçeneği - stealth syn scan (TCP SYN port scan (Default))
stealth syn scan anlamına gelir.

-sT seçeneği - standart TCP scan
standart tcp scan anlamına gelir. Bu seçenek eğer root değilsek kullanılır. Şöyle yaparız.
nmap -sT google.com
-sV seçeneği
Açıklaması şöyle.
-sV will probe open ports to determine service/version info
-T4 seçeneği
Açıklaması şöyle.
-T4 this setting is required to set up scan speed (T5 is the maximum, most aggressive scan)


15 Ekim 2019 Salı

objdump komutu

Giriş
elf dosyasının veya .o dosyasının sembollerine objdump ile bakılabilir. Komutun bir çok seçeneği var.

Diğer Araçlar
Bu araç ile ilgili diğer araçların açıklaması şöyle.
ar: creates static libraries.

objdump: this is the most important binary tool; it can be used to display all the information in an object binary file.

strings: list all the printable strings in a binary file.

nm: lists the symbols defined in the symbol table of an object file.

ldd: lists the shared libraries on which the object binary is dependent.

strip: deletes the symbol table information.
-d disassamble seçeneği
Assembly kodunu çıkartır.
Örnek
Şöyle yaparız.
objdump -d a.o
veya şöyle yaparız
objdump -d foo.exe
Örnek
Şöyle derlenmiş bir .o dosyası olsun
gcc -c test.c
Bu dosyanın tamamına şöyle bakarız.
objdump -D test.o
Çıktı olarak şuna benzer bir şey görürüz.
0:   14 00                   adc    $0x0,%al
--disassembler-options seçeneği
Üretilen assembly kodunun att veya intel formatında olmasını sağlar. Bu seçenek sanırım -M intel ile aynı. Şöyle yaparız.
$ objdump -d --disassembler-options=att code.c
  ...
 080483c4 :
 80483c4:   8d 4c 24 04           lea    0x4(%esp),%ecx
 80483c8:   83 e4 f0              and    $0xfffffff0,%esp
 80483cb:   ff 71 fc              pushl  -0x4(%ecx)
 80483ce:   55                    push   %ebp
 80483cf:   89 e5                 mov    %esp,%ebp
 80483d1:   51                    push   %ecx
 80483d2:   83 ec 04              sub    $0x4,%esp
 80483d5:   c7 04 24 b0 84 04 08  movl   $0x80484b0,(%esp)
 80483dc:   e8 13 ff ff ff        call   80482f4 
 80483e1:   b8 00 00 00 00        mov    $0x0,%eax
 80483e6:   83 c4 04              add    $0x4,%esp 
 80483e9:   59                    pop    %ecx
 80483ea:   5d                    pop    %ebp
 80483eb:   8d 61 fc              lea    -0x4(%ecx),%esp
 80483ee:   c3                    ret
 80483ef:   90                    nop
veya şöyle yaparız.
$ objdump -d --disassembler-options=intel code.c
  ...
 080483c4 :
 80483c4:   8d 4c 24 04           lea    ecx,[esp+0x4]
 80483c8:   83 e4 f0              and    esp,0xfffffff0
 80483cb:   ff 71 fc              push   DWORD PTR [ecx-0x4]
 80483ce:   55                    push   ebp
 80483cf:   89 e5                 mov    ebp,esp
 80483d1:   51                    push   ecx
 80483d2:   83 ec 04              sub    esp,0x4
 80483d5:   c7 04 24 b0 84 04 08  mov    DWORD PTR [esp],0x80484b0
 80483dc:   e8 13 ff ff ff        call   80482f4 
 80483e1:   b8 00 00 00 00        mov    eax,0x0
 80483e6:   83 c4 04              add    esp,0x4
 80483e9:   59                    pop    ecx
 80483ea:   5d                    pop    ebp
 80483eb:   8d 61 fc              lea    esp,[ecx-0x4]
 80483ee:   c3                    ret

 80483ef:   90                    nop
-f seçeneği - file-headers
.so dosyasının hangi ABI türünü kullandığını gösterir.
% objdump -f /lib/ld-linux.so.2 
             /lib64/ld-linux-x86-64.so.2  
             /libx32/ld-linux-x32.so.2

/lib/ld-linux.so.2:     file format elf32-i386
architecture: i386, flags 0x00000150:
HAS_SYMS, DYNAMIC, D_PAGED
start address 0x00000a90


/lib64/ld-linux-x86-64.so.2:     file format elf64-x86-64
architecture: i386:x86-64, flags 0x00000150:
HAS_SYMS, DYNAMIC, D_PAGED
start address 0x0000000000000c90


/libx32/ld-linux-x32.so.2:     file format elf32-x86-64
architecture: i386:x64-32, flags 0x00000150:
HAS_SYMS, DYNAMIC, D_PAGED
start address 0x00000960
-S seçeneği
Açıklaması şöyle. -d seçeği ile birlikte kullanılır
>objdump --help
[...]
-S, --source             Intermix source code with disassembly
-l, --line-numbers       Include line numbers and filenames in output
Örnek
Şöyle yaparız.
> objdump -d -M intel -S test.o

test.o:     file format elf32-i386


Disassembly of section .text:

00000000 <main>:
#include <stdio.h>

int main(void)
{
   0:   55                    push   ebp
   1:   89 e5                 mov    ebp,esp
   3:   83 e4 f0              and    esp,0xfffffff0
   6:   83 ec 10              sub    esp,0x10
    puts("test");
   9:   c7 04 24 00 00 00 00  mov    DWORD PTR [esp],0x0
  10:   e8 fc ff ff ff        call   11 <main+0x11>

    return 0;
  15:   b8 00 00 00 00        mov    eax,0x0
}
  1a:   c9                    leave  
  1b:   c3                    ret
-t seçeneği
Sembolleri gösterir

Örnek
Şöyle yaparız
objdump -t x.sm
Örnek
Elimizde şöyle bir kod olsun.
#include <stdio.h>
int g_a;
int g_b;
int g_c;

int main()
{
    printf("Hello world\n");
    return 0;
}
Şöyle yaparız.
objdump -t myapp
Çıktı olarak şunu alırız.
00004020 g_b
00004024 g_a
00004028 g_c
Örnek
Sembollerin hangi elf bölümüne geldiği görmek için şöyle yaparız. .text ve .rodata bölümlerinde tanımlı semboller görülebilir.
$ objdump -T /usr/lib/arm-linux-gnueabihf/libstdc++.so.6 | grep "chrono"
00080828 g    DF .text      0000002a  GLIBCXX_3.4.11 _ZNSt6chrono12system_clock3nowEv
0008ae38 g    DO .rodata    00000001  GLIBCXX_3.4.11 _ZNSt6chrono12system_clock12
Örnek
Eğer bir sembol yoksa undefined olarak belirtilir.
$ objdump -T myapp | grep "GLIBCXX_3.4.19"
00000000      DF *UND*  00000000  GLIBCXX_3.4.19 _ZNSt6chrono3_V212system_clock3n
-x seçeneği
Elimizde şöyle bir kod olsun.
// main.c
extern int x;
static int *y = &x;
int main() { 
  return *y;
}
Şöyle yaparız
objdump -x main.o
Çıktı olarak şunu alırız.
RELOCATION RECORDS FOR [.data]:
OFFSET           TYPE              VALUE
0000000000000000 R_X86_64_64       x