97, 1/4 회원가입  로그인  
   stardung86
   2번 파트 리스닝&번역입니다.

http://www.hackerschool.org/HS_Boards/zboard.php?AllArticle=true&no=15 [복사]


than you going to detailed code analysi
이제 코드 아날리시스를 세세하게 분석해야하구요,

and for that you sould 디피컬리 have a common *******, that you need to review.
그것을 위해서 **** 당신이 리뷰를 해야하는 *******에 대해 알아야 합니다.

And every one should be ****** the same *******.
그리고 모두가 같은 *******를 ******해야 합니다.

we all are export in diffrent ****.
우리는 모두, 다른 ****로 추가해야합니다.

so you shuold try it complie it a huge list, and understand that list.
즉, 당신은 큰 리스트로 컴파일한후, 그 리스트를 이해해야만 합니다.

so that everyone as looking as a same *******.
그래서 모두들 같은 *******를 바라보고 있는 것이죠.

Than **** on the line,
그리고, 라인위에 ****를 해야만,

are can ******** line defending on whice were and some one else comes review
*****************************************************************************

the same ***** thier should be a methoded and thier should be some documented that he or she shuold be ***************.
*************** 한 그나 그녀는 같은 *****를 체계화해야하고, 문서화 해야 할 것 입니다.

OK, these other knows this is what the application is doing,
그래요, 이 들은, 어플리케이션이 무엇을 하는지,

this is what the what are they review. oh, there is a new type of exploit.
무엇을 리뷰하는지알죠. 오, 저기 새로운 타입의 익스플로잇이 있네요.

for match string exploit for example of course it is pretty or not.
매치 스트링 익스플로잇을 예로들어서요. 설사 그게 아니더라도요.

but over here that taking ********** let's go and look over there they don't have to spend too much time trying to go to all the **** look for some new *****.
하지만, 여기에 그들은 ****에 대한 모든것을 가질 시간을 같지 않습니다. 새로운 *****을 찾아가죠.

Threat Analysys. Let's get trying to it.
트릿 아날리시스. 이제 이것을 알아보도록 하겠습니다.

I'll be talk review about what is Treat Analysis. when why who and how.
저는 트릿아날리시스가 무엇인지, 언제, 왜, 누가 그리고 어떻게 사용되는지 말씀드리겠습니다.

acroding to C/C++ Languege ******.
C와 C++ ******언어를 에 따라 말씀드리겠습니다.

this part are *** will be like a intresting apply.
이 부분은 흥미로운 것들로 *** 차있을 것입니다.
and i have put in a lot of note here simply.
그리고 전 이곳에 간단한 노트들을 많이 넣었죠.
because you can report to a lot of this **** after it is well.
왜냐하면, 당신은 이 많은 것들을 잘 마친후, 이 ****들에 대하여 발표 할 수 있거든요.

This is the very greatfulist.
이것들은 매우 훌륭합니다.

**** my example i'm gonna cover these example very fast ***** very long day.(?)
*******************************************************************************

so and that why i think you can download most of this stop from recon site and you can review it again.
그것이이 바로 당신이 이 많은 것들은 레콘 사이트에서 다운로드하고, 리뷰할 수 있는 이유 입니다.

so Threat Modeling.
트릿 모델링에 대해 알아보겠습니다.

What is Threat Modeling.
트릿 모델링 이란,

it is not but an organized method of attaking an application.
******* 하지만 어플리케이션을 공격하는 조직된 체계입니다.

so, when you decide that you want actually attack an appliation whether is developer whether is attacker.
즉, 당신이 개발자나 공격자의 어플리케이션을 공격하는것을 결정 할때는,

You Just try to figured out.
당신은 그냥 계산 하면 되는 것입니다.

OK, what is the ***** application. you have ***** diagram. you have the hole a ********* the application.
자, *****어플리케이션을 *****다이어그램화 하거나 어플리케이션을 ******** 해야합니다.

you should try it figured out intel applications floor before you even try to look at the core.
당신이 인텔 어플리케이션층을 계산하기 전에 당신은 코어를 보아야합니다.

before you go to the core level think about that.
코어 레벨로 가기전에는 저것에대해 한번 더 생각 해보시구요.

ok, hmmm. it, a
그래요, 음... 그... 아.

threat analysys is 디피컬리 consider as a systematic method of finding diffrent type, so wonderfulist.
트릿 아날리시스는 ****, 다른 타입을 찾는 시스템적인 체계로 여깁니다. 매우 훌륭하죠.

and how do you figured out diffrent type of *****.
그리고, 당신은 다른 타입의 *****를 어떻게 계산합니까?

that what we were going to detail of what we should be looking at that. how do we seperate.
이제, 우리는 그것에 대해서 세세하게 보아야합니다. 어떻게 나누는지요.

than we do ****.
그리고 우리는 ****해야죠.

so has threat modeling been are all for a while, i think so. ammm...
그래서, 트릿 모델링은 ********합니다. 제 생각에는요.

i mean just **** secury people have formalized **** threat modeling. but, if you ******* a Attackers and Hackers have been actually thinking from ****.
제 말은, 안전한 ****사람들은 ****를 트릿 모델링으로 공식화 하려고 합니다만, 당신이 ************************.


they think where the ********** input. and they trying an attack does pacific area they mind are be thinking from the big picture going a ***,
그들은 입력된 ********* 를 생각하죠. 그리고 그들은 평화로운 곳을 공격하려고 생각 할 것입니다. 큰 ****이 가는 곳에서 부터 말이죠.

but they are actually they have been focusing for major area already.
하지만 사실상 그들은 이미 중요한 부분에 중심을 두고있죠.

so it not a really an new *****.
즉 이것은 새로운 *****는 아니죠.

so can Threat Model are really help and who does really help. diffculy would help develop countermeasures.
그래서, 트릿 모델링은 정말도움이 필요한 사람에게 정말 도움이 됩니다. 어렵게도 개발대책에도 도움이 될것입니다.

how did help develop countermeasures? ones you know what the major area *****.
어떻게 개발대책에 도움이 되냐구요? 먼저 당신은 중요한부분이 *****를 하는지 알아야 합니다.

developer don't made realize a diffrent types of tricks that could access.
개발자들이 접근할 수 있는 다른 타입의 트릭은 만들수 없으니까요.

and that is one of major problem that, the actally in the ********. one ablilty is a *** in there applications.
그리고 중요한 부분에는 한가지 문제점을 가지고 있습니다. ********에 말이죠. 한가지 능력은 ***입니다. 그들의 어플리케이션에서 말이죠.

so you should can educate the developer is well, ******** you can either fix at the project architecture level it self.
그러므로, 당신은 개발자가 잘 하기위한 교육을 할 수 있습니다. ******** 당신이 스스로  프로젝트의 레벨 구성을 고칠수 있든 아니든 말이죠.

or you can educate ************. aaa,****
또는 당신은 ************를 교육 할 수도 있습니다. 아, ****

you can also weigh each threat and figured out. how much value to assign to them.
당신은 또 각각의 트릿을 따져보고, 계산 할 수도 있습니다. 가치를 그들에게 맡기는 만큼요.

by weigh each treat you wanna know. if is it a local type of exploit is it a remote exploit, is it ****** is something that a required the ****** and a admin.
트릿을 따져볼때, 당신이 알아야 할 점이 있습니다. 그것이 로컬 익스플로잇이든, 리모트 익스플로잇이든, ******이든, ****나 어드민의 필수조건이든요.


you are *** assign value accroding to them. and then say.
당신은 맡긴 가치를 ***해야합니다. 그들을 따라서요. ********

OK, if is there a remote exploit is something that you wanna fixing ****,
그래요, 만약 당신 고칠 수 있는 리모트 익스플로잇이 있으면요

**** local exploit, it could problem delay you know for *****.
. ****한 로컬 익스플로잇도 말이죠. 그것은 딜레이 문제를 가지고 있죠.
*********

and the most important part is.... do understand risks, and threat to the applications.
그리고 제일 중요한 부분 입니다. 어플리케이션을 리스크하는것과 트릿하는것을 이해하는 것이죠.

there is a *** diffrent between risks and threats... 이 둘 사이엔 약간의 차이점이 있습니다.

threats is basicaly something that, could access in an applications.
트릿은 어플리케이션에 접근 할 수 있게 만드는 것입니다.

risks is trying to assign a value to that treats. and figuring that out.
리스크는 트릿된 것에 가치를 맡기는 것을 말합니다. 그리고 그들을 계산 하죠.

we going to actually definition ********, also what dictionary and other web site.
우리는 ********를 정의 할 것입니다. 또 ******과 다른 웹사이트에 대해서도 말이죠.


우... 많이 어렵군요...
모르는 부분도 많았습니다만, 고수 분들 께서 도와주셨으면 합니다.

  Hit : 2185     Date : 2011/05/09 06:21



    
W.H. 수고하셧습니다~ ^^ 2011/05/10  
멍멍 고생하셨습니다!! 2011/05/11