API๊ฐ€ ์žˆ๋Š” ์˜จ๋ผ์ธ ํ”Œ๋žซํผ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

ProjectHoneypot

IP๊ฐ€ ์˜์‹ฌ์Šค๋Ÿฌ์šด/์•…์˜์ ์ธ ํ™œ๋™๊ณผ ๊ด€๋ จ์ด ์žˆ๋Š”์ง€ ๋ฌผ์–ด๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์™„์ „ํžˆ ๋ฌด๋ฃŒ์ž…๋‹ˆ๋‹ค.

BotScout

IP ์ฃผ์†Œ๊ฐ€ ๊ณ„์ •์„ ๋“ฑ๋กํ•˜๋Š” ๋ด‡๊ณผ ๊ด€๋ จ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž ์ด๋ฆ„๊ณผ ์ด๋ฉ”์ผ๋„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ฒ˜์Œ์—๋Š” ๋ฌด๋ฃŒ์ž…๋‹ˆ๋‹ค.

Hunter

์ด๋ฉ”์ผ์„ ์ฐพ๊ณ  ๊ฒ€์ฆํ•ฉ๋‹ˆ๋‹ค.
์ผ๋ถ€ ๋ฌด๋ฃŒ API ์š”์ฒญ์ด ์žˆ์œผ๋ฉฐ, ๋” ๋งŽ์€ ์š”์ฒญ์€ ์œ ๋ฃŒ์ž…๋‹ˆ๋‹ค.
์ƒ์—…์ ?

AlientVault

IP ๋ฐ ๋„๋ฉ”์ธ๊ณผ ๊ด€๋ จ๋œ ์•…์˜์ ์ธ ํ™œ๋™์„ ์ฐพ์Šต๋‹ˆ๋‹ค. ๋ฌด๋ฃŒ์ž…๋‹ˆ๋‹ค.

Clearbit

์ด๋ฉ”์ผ(๋‹ค๋ฅธ ํ”Œ๋žซํผ์˜ ํ”„๋กœํ•„), ๋„๋ฉ”์ธ(๊ธฐ๋ณธ ํšŒ์‚ฌ ์ •๋ณด, ์ด๋ฉ”์ผ ๋ฐ ๊ทผ๋ฌดํ•˜๋Š” ์‚ฌ๋žŒ๋“ค) ๋ฐ ํšŒ์‚ฌ(์ด๋ฉ”์ผ์—์„œ ํšŒ์‚ฌ ์ •๋ณด ๊ฐ€์ ธ์˜ค๊ธฐ)์™€ ๊ด€๋ จ๋œ ๊ฐœ์ธ ๋ฐ์ดํ„ฐ๋ฅผ ์ฐพ์Šต๋‹ˆ๋‹ค.
๋ชจ๋“  ๊ฐ€๋Šฅ์„ฑ์— ์ ‘๊ทผํ•˜๋ ค๋ฉด ๋น„์šฉ์„ ์ง€๋ถˆํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
์ƒ์—…์ ?

BuiltWith

์›น์‚ฌ์ดํŠธ์—์„œ ์‚ฌ์šฉ๋˜๋Š” ๊ธฐ์ˆ . ๋น„์Œ‰๋‹ˆ๋‹คโ€ฆ
์ƒ์—…์ ?

Fraudguard

ํ˜ธ์ŠคํŠธ(๋„๋ฉ”์ธ ๋˜๋Š” IP)๊ฐ€ ์˜์‹ฌ์Šค๋Ÿฌ์šด/์•…์˜์ ์ธ ํ™œ๋™๊ณผ ๊ด€๋ จ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. ์ผ๋ถ€ ๋ฌด๋ฃŒ API ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.
์ƒ์—…์ ?

FortiGuard

ํ˜ธ์ŠคํŠธ(๋„๋ฉ”์ธ ๋˜๋Š” IP)๊ฐ€ ์˜์‹ฌ์Šค๋Ÿฌ์šด/์•…์˜์ ์ธ ํ™œ๋™๊ณผ ๊ด€๋ จ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. ์ผ๋ถ€ ๋ฌด๋ฃŒ API ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

SpamCop

ํ˜ธ์ŠคํŠธ๊ฐ€ ์ŠคํŒธ ํ™œ๋™๊ณผ ๊ด€๋ จ์ด ์žˆ๋Š”์ง€ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. ์ผ๋ถ€ ๋ฌด๋ฃŒ API ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

mywot

์˜๊ฒฌ ๋ฐ ๊ธฐํƒ€ ๋ฉ”ํŠธ๋ฆญ์Šค๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ๋„๋ฉ”์ธ์ด ์˜์‹ฌ์Šค๋Ÿฌ์šด/์•…์˜์ ์ธ ์ •๋ณด์™€ ๊ด€๋ จ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.

ipinfo

IP ์ฃผ์†Œ์—์„œ ๊ธฐ๋ณธ ์ •๋ณด๋ฅผ ์–ป์Šต๋‹ˆ๋‹ค. ์›” ์ตœ๋Œ€ 100K๊นŒ์ง€ ํ…Œ์ŠคํŠธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

securitytrails

์ด ํ”Œ๋žซํผ์€ IP ๋‚ด์˜ ๋„๋ฉ”์ธ ๋˜๋Š” ๋„๋ฉ”์ธ ์„œ๋ฒ„ ๋‚ด์˜ ๋„๋ฉ”์ธ, ์ด๋ฉ”์ผ๋กœ ์†Œ์œ ๋œ ๋„๋ฉ”์ธ(๊ด€๋ จ ๋„๋ฉ”์ธ ์ฐพ๊ธฐ), ๋„๋ฉ”์ธ์˜ IP ๊ธฐ๋ก(CloudFlare ๋’ค์˜ ํ˜ธ์ŠคํŠธ ์ฐพ๊ธฐ), ๋ชจ๋“  ๋„๋ฉ”์ธ์ด ์‚ฌ์šฉํ•˜๋Š” ๋„ค์ž„์„œ๋ฒ„์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹คโ€ฆ.
์ผ๋ถ€ ๋ฌด๋ฃŒ ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

fullcontact

์ด๋ฉ”์ผ, ๋„๋ฉ”์ธ ๋˜๋Š” ํšŒ์‚ฌ ์ด๋ฆ„์œผ๋กœ ๊ฒ€์ƒ‰ํ•˜๊ณ  ๊ด€๋ จ๋œ โ€œ๊ฐœ์ธโ€ ์ •๋ณด๋ฅผ ๊ฒ€์ƒ‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฉ”์ผ ๊ฒ€์ฆ๋„ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ์ผ๋ถ€ ๋ฌด๋ฃŒ ์ ‘๊ทผ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

RiskIQ

๋„๋ฉ”์ธ ๋ฐ IP์— ๋Œ€ํ•œ ๋งŽ์€ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. ๋ฌด๋ฃŒ/์ปค๋ฎค๋‹ˆํ‹ฐ ๋ฒ„์ „์—์„œ๋„ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

_IntelligenceX

๋„๋ฉ”์ธ, IP ๋ฐ ์ด๋ฉ”์ผ์„ ๊ฒ€์ƒ‰ํ•˜๊ณ  ๋คํ”„์—์„œ ์ •๋ณด๋ฅผ ์–ป์Šต๋‹ˆ๋‹ค. ์ผ๋ถ€ ๋ฌด๋ฃŒ ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

IBM X-Force Exchange

IP๋กœ ๊ฒ€์ƒ‰ํ•˜๊ณ  ์˜์‹ฌ์Šค๋Ÿฌ์šด ํ™œ๋™๊ณผ ๊ด€๋ จ๋œ ์ •๋ณด๋ฅผ ์ˆ˜์ง‘ํ•ฉ๋‹ˆ๋‹ค. ์ผ๋ถ€ ๋ฌด๋ฃŒ ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

Greynoise

IP ๋˜๋Š” IP ๋ฒ”์œ„๋กœ ๊ฒ€์ƒ‰ํ•˜๊ณ  ์ธํ„ฐ๋„ท์„ ์Šค์บ”ํ•˜๋Š” IP์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์–ป์Šต๋‹ˆ๋‹ค. 15์ผ ๋ฌด๋ฃŒ ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

Shodan

IP ์ฃผ์†Œ์˜ ์Šค์บ” ์ •๋ณด๋ฅผ ์–ป์Šต๋‹ˆ๋‹ค. ์ผ๋ถ€ ๋ฌด๋ฃŒ API ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

Censys

Shodan๊ณผ ๋งค์šฐ ์œ ์‚ฌํ•ฉ๋‹ˆ๋‹ค.

buckets.grayhatwarfare.com

ํ‚ค์›Œ๋“œ๋กœ ๊ฒ€์ƒ‰ํ•˜์—ฌ ์—ด๋ฆฐ S3 ๋ฒ„ํ‚ท์„ ์ฐพ์Šต๋‹ˆ๋‹ค.

Dehashed

์ด๋ฉ”์ผ ๋ฐ ๋„๋ฉ”์ธ์˜ ์œ ์ถœ๋œ ์ž๊ฒฉ ์ฆ๋ช…์„ ์ฐพ์Šต๋‹ˆ๋‹ค.
์ƒ์—…์ ?

psbdmp

์ด๋ฉ”์ผ์ด ๋‚˜ํƒ€๋‚œ pastebin์„ ๊ฒ€์ƒ‰ํ•ฉ๋‹ˆ๋‹ค. ์ƒ์—…์ ?

emailrep.io

๋ฉ”์ผ์˜ ํ‰ํŒ์„ ์–ป์Šต๋‹ˆ๋‹ค. ์ƒ์—…์ ?

ghostproject

์œ ์ถœ๋œ ์ด๋ฉ”์ผ์—์„œ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์–ป์Šต๋‹ˆ๋‹ค. ์ƒ์—…์ ?

Binaryedge

IP์—์„œ ํฅ๋ฏธ๋กœ์šด ์ •๋ณด๋ฅผ ์–ป์Šต๋‹ˆ๋‹ค.

haveibeenpwned

๋„๋ฉ”์ธ ๋ฐ ์ด๋ฉ”์ผ๋กœ ๊ฒ€์ƒ‰ํ•˜๊ณ  pwned ์—ฌ๋ถ€์™€ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. ์ƒ์—…์ ?

IP2Location.io

IP ์ง€๋ฆฌ ์œ„์น˜, ๋ฐ์ดํ„ฐ ์„ผํ„ฐ, ASN ๋ฐ VPN ์ •๋ณด๋ฅผ ๊ฐ์ง€ํ•ฉ๋‹ˆ๋‹ค. ์›” 30K ์ฟผ๋ฆฌ๋ฅผ ๋ฌด๋ฃŒ๋กœ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

IPQuery.io

IP ์ง€๋ฆฌ ์œ„์น˜ ๋ฐ OISNT์™€ ํ•จ๊ป˜ ํƒ€๊ฒŸ ๋ฐ์ดํ„ฐ ํฌ์ธํŠธ. ๋น„์ƒ์—…์ ์ž…๋‹ˆ๋‹ค.

https://dnsdumpster.com/(์ƒ์—…์  ๋„๊ตฌ์ธ๊ฐ€์š”?)

https://www.netcraft.com/ (์ƒ์—…์  ๋„๊ตฌ์ธ๊ฐ€์š”?)

https://www.nmmapper.com/sys/tools/subdomainfinder/ (์ƒ์—…์  ๋„๊ตฌ์ธ๊ฐ€์š”?)

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ