http://www.hackerschool.org/HS_Boards/zboard.php?id=Free_Lectures&no=1322 [º¹»ç]
netstat¶õ?
ÇöÀç ÀÚ½ÅÀÇ ½Ã½ºÅÛ¿¡ ¿·ÁÁø Åë½ÅÆ÷Æ®¿Í
¿¬°áµÈ ´Ù¸¥ ½Ã½ºÅÛÀÇ Á¤º¸¸¦ È®ÀÎÇÒ ¼ö ÀÖ´Â ¸í·É¾îÀÔ´Ï´Ù.
Windows XP¸¦ ±âÁØÀ¸·Î ¼³¸íÇÏ°Ú½À´Ï´Ù.
½ÃÀÛ - ½ÇÇà - "cmd" ÀÔ·Â ¡ç ÀÌ·¸°Ô ½ÇÇàÇÏ½Ã¸é µµ½º Ä¿¸ÇµåâÀÌ ¶å´Ï´Ù.
°Å±â¼ netstat¶ó°í ¸í·É¾î¸¦ Ä¡¸é ¾Æ·¡¿Í ºñ½ÁÇÏ°Ô ³ª¿Ã°Ì´Ï´Ù.
Active Connections
Proto Local Address Foreign Address State
TCP mainpc:2135 pz-in-f104.google.com:http ESTABLISHED
.
.
.
(»ý·«)
±¸±Û(google)¿¡ Á¢¼ÓÇÑ µÚ netstat¸¦ ÀÔ·ÂÇÑ°Ì´Ï´Ù.
Proto´Â ÀÚ½ÅÀÇ ½Ã½ºÅÛ°ú ¿¬°áµÈ ½Ã½ºÅÛ(¼¹ö³ª Ŭ¶óÀ̾ðÆ®)ÀÇ µ¥ÀÌÅÍ Àü¼Û ŸÀÔÀÔ´Ï´Ù.
¿©±â¼ TCP¿Í UDP·Î ³ª´²Áö´Âµ¥...
TCP(Transmission Control Protocol)´Â Àü¼Û Á¦¾î ÇÁ·ÎÅäÄÝÀ» ÀǹÌÇÕ´Ï´Ù.
°£´ÜÈ÷ ¸»Çؼ µ¥ÀÌÅÍÀÇ Àü´ÞÀ» º¸ÁõÇÏ°í º¸³½ ¼ø¼´ë·Î ¹Þ°Ô ÇØ ÁÖ´Â ÇÁ·ÎÅäÄÝÀÔ´Ï´Ù.
UDP(User Datagram Protocol)´Â ÀÎÅͳݿ¡¼ Á¤º¸¸¦ ÁÖ°í¹ÞÀ» ¶§,
¼·Î ÁÖ°í¹Þ´Â Çü½ÄÀÌ ¾Æ´Ñ ÇÑÂÊ¿¡¼
ÀϹæÀûÀ¸·Î º¸³»´Â ¹æ½ÄÀÇ Åë½Å ÇÁ·ÎÅäÄÝÀÔ´Ï´Ù.
TCP´Â ¼·Î Çü½ÄÀ» ÁÖ°í ¹Þ´Â ±×·± ÇÁ·ÎÅäÄÝÀε¥ ºñÇØ
UDP´Â Åë½Å ¹æ¹ýÀÌ TCP¿¡ ºñÇØ °£´ÜÇÕ´Ï´Ù.
¼Óµµµµ ±×¸¸Å ºü¸£±¸¿ä.
ÇÏÁö¸¸ TCP¿¡ ºñÇØ º¸¾ÈÀÌ ¾àÇÕ´Ï´Ù.
ÀÚ¼¼ÇÑ ³×Æ®¿öÅ© ÀÌ·ÐÀº µÎ²¨¿î Ã¥À̳ª ÀÎÅͳÝÀ» Âü°íÇϽñæ... '¤µ';;
Local Address´Â ÀÚ½ÅÀÇ ½Ã½ºÅÛ¿¡ ¿·ÁÁø Æ÷Æ® Á¤º¸¸¦ ÀǹÌÇÕ´Ï´Ù.
Æ÷Æ®´Â 0~65535¹ø±îÁö Àִµ¥¿ä.
Æ÷Æ® ¹øÈ£ ÇÒ´ç¿¡ °ü·ÃµÈ µ¥ÀÌÅÍ Å¸ÀÔÀÌ unsigned short°¡ ¾Æ´Ò±î Á¶½É½º·´°Ô ÃßÃøÀ» Çغ¾´Ï´Ù.
mainpc´Â IPÁÖ¼Ò¸¦ ¹®ÀڷΠǥ½ÃµÇ°í µÚ¿¡ ºÙÀº 2135´Â Æ÷Æ® ¹øÈ£ÀÔ´Ï´Ù.
Æ÷Æ®´Â ÀÏÁ¾¿¡ ·£Ä«µå¿Í ½Ã½ºÅÛ »çÀÌ¿¡ µ¥ÀÌÅ͸¦ ÁÖ°í ¹Þ´Â Åë·ÎÀÔ´Ï´Ù.
´Ù¸¥ °É·Î ºñÀ¯ÇÏÀÚ¸é... ¼Ò¸Á¾ÆÆÄÆ®°¡ ÀÖ°í µé¾î°¡´Â ÀÔ±¸°¡ 6°³°¡ ÀÖÀ¸¸é
¼Ò¸Á¾ÆÆÄÆ®´Â ½Ã½ºÅÛÀÌ µÇ°í ÀÔ±¸´Â Æ÷Æ®°¡ µÇ°ÚÁÒ.
Foreign Address´Â Local Address°ú Åë½ÅÇÏ´Â »ó´ë ½Ã½ºÅÛÀÇ IP,
Æ÷Æ® Á¤º¸¸¦ Ç¥½ÃÇÕ´Ï´Ù.
State´Â ÇöÀç »óŸ¦ ÀǹÌÇÕ´Ï´Ù.
Áï, mainpc:2135¿Í pz-in-f104.google.com:http´Â TCP·Î Åë½ÅÇÑ´Ù´Â ÀǹÌÀÔ´Ï´Ù.
state´Â ÇöÀç µÎ ½Ã½ºÅÛÀÇ Åë½Å »óÅÂÀÔ´Ï´Ù.
ESTABLISHED : ¿¬°á »óÅÂ
TIME_WAIT : ´ë±â »óÅÂ
CLOSE_WAIT : ´ÝÈù »óÅÂ
netstat µÚ¿¡ Á¢¹Ì»ç(ïÈÚÞö)ó·³ ºÙ´Â ¸í·É¾î°¡ Àִµ¥
Á¦°¡ ¾Æ´Â ¸í·É¾î´Â 3°¡Áö°¡ Àֳ׿ä.
±×°ÍÀ» Á¤¸®ÇÏÀÚ¸é...
-a : ¸ðµç ¿¬°á ¹× ¼ö½Å ´ë±â Æ÷Æ®¸¦ Ç¥½ÃÇÕ´Ï´Ù.
-n : ÁÖ¼Ò ¹× Æ÷Æ® ¹øÈ£¸¦ ¼ýÀÚ Çü½ÄÀ¸·Î Ç¥½ÃÇÕ´Ï´Ù.
-e : ÀÌ´õ³Ý Ä«µå°¡ µ¿ÀÛÇÑ ³»¿ëÀ» Ãâ·ÂÇÕ´Ï´Ù.
±×·³ À§¿¡ ³»¿ëÀ» Çѹø Å×½ºÆ®Çغ¸ÁÒ.
netstat -na¸¦ ÀÔ·ÂÇÏ¸é ¾Æ·¡¿Í °°ÀÌ ¶å´Ï´Ù.
Active Connections
Proto Local Address Foreign Address State
TCP 192.168.0.8:2135 74.125.127.104:http ESTABLISHED
.
.
.
(»ý·«)
¹º°¡ ¹Ù²î¾ú´Ù´Â °É º¼ ¼ö Àִµ¥¿ä.
-na´Â ¸ðµç ¿¬°á ¹× ¼ö½Å ´ë±â Æ÷Æ®¿Í ÁÖ¼Ò ¹× Æ÷Æ® ¹øÈ£¸¦
¼ýÀÚ Çü½ÄÀ¸·Î Ç¥½ÃÇÕ´Ï´Ù.
192.168.8ÀÌ ¶¹´Âµ¥ 192.168.0.X´Â ÀϹÝÀûÀ¸·Î
°øÀ¯±âÀÇ ÁÖ¼Ò·Î »ç¿ëµÇ´Â »ç¼³ IPÁÖ¼ÒÀÔ´Ï´Ù.
Á¦°¡ °øÀ¯±â¸¦ ¾´´Ù´Â °ÍÀ» ¾Ë ¼öÀÖ´Â ³»¿ëÀ̳׿ä.
74.125.127.104´Â ¿¬°áµÈ ±¸±Û ¼¹öÀÇ IPÁÖ¼ÒÀÔ´Ï´Ù.
µÚ¿¡ http´Â hypertext transport protocol·Î ÀÎÅͳݿ¡¼
À¥ ¼¹ö¿Í ÀÎÅÍ³Ý ºê¶ó¿ìÀú »çÀÌÀÇ µ¥ÀÌÅ͸¦ Àü¼ÛÇÏ´Â ÇÁ·ÎÅäÄÝÀÔ´Ï´Ù.
¾î¶´ø ÀÎÅͳÝÀ¸·Î À¥À» Á¢¼ÓÇϽøé ÀÚ½ÅÀÇ ½Ã½ºÅÛÀº ±× À¥ ¼¹ö¿¡ Á¢¼ÓÇÏ°í
http·Î Åë½ÅÀ» ÇÏ°Ô µÇ¸ç ¼¹ö¿¡¼ ¿À´Â µ¥ÀÌÅÍ°¡ ÀÚ½ÅÀÇ ½Ã½ºÅÛ¿¡ µµÂøÇÏ°í
±× µ¥ÀÌÅ͸¦ ½Ã½ºÅÛÀÌ Çؼ®Çؼ ¸ð´ÏÅÍ¿¡ Ãâ·ÂÀ» Çϴ°̴ϴÙ.
0~1023¹øÀº well known port¶ó°í "³Î¸® ¾Ë·ÁÁø(?)" Æ÷Æ®·Î Çؼ®µÇ´Âµ¥
°ø½ÄÀûÀ¸·Î ÁöÁ¤µÈ Æ÷Æ® ¹øÈ£¶ó°í ¾Ë¸é µÇ°Ú½À´Ï´Ù.
1 TCP Port Service Multiplexer (TCPMUX)
5 Remote Job Entry (RJE)
7 ECHO
18 Message Send Protocol (MSP)
20 FTP -- Data
21 FTP -- Control
22 SSH Remote Login Protocol
23 Telnet
25 Simple Mail Transfer Protocol (SMTP)
29 MSG ICP
37 Time
42 Host Name Server (Nameserv)
43 WhoIs
49 Login Host Protocol (Login)
53 Domain Name System (DNS)
69 Trivial File Transfer Protocol (TFTP)
70 Gopher Services
79 Finger
80 HTTP
103 X.400 Standard
108 SNA Gateway Access Server
109 POP2
110 POP3
115 Simple File Transfer Protocol (SFTP)
118 SQL Services
119 Newsgroup (NNTP)
137 NetBIOS Name Service
139 NetBIOS Datagram Service
143 Interim Mail Access Protocol (IMAP)
150 NetBIOS Session Service
156 SQL Server
161 SNMP
179 Border Gateway Protocol (BGP)
190 Gateway Access Control Protocol (GACP)
194 Internet Relay Chat (IRC)
197 Directory Location Service (DLS)
389 Lightweight Directory Access Protocol (LDAP)
396 Novell Netware over IP
443 HTTPS
444 Simple Network Paging Protocol (SNPP)
445 Microsoft-DS
458 Apple QuickTime
546 DHCP Client
547 DHCP Server
563 SNEWS
569 MSN
1080 Socks
"º¹»ç-ºÙ¿©³Ö±â" ½Å°øÀ» ½è½À´Ï´Ù.
¿©±â±îÁö netstat ¸í·É¾î °Á¿´½À´Ï´Ù.
±×·³ ÁÁÀº ÇÏ·çµÇ¼¼¿ä. |
Hit : 7429 Date : 2009/10/14 05:42
|