Reverse Shell: Aniqlash + Himoya + Lab Sozlash & Monitoring (0 dan)
Bu sahifa hujum qilishni oârgatmaydi. Maqsad â ruxsatli lab muhitida xavfni aniqlash, oldini olish va kuzatish.
1) Aniqlash (Detection)
Reverse shell odatda tashqi IPâga chiqadigan (outbound) shubhali ulanish + shubhali jarayon kombinatsiyasi bilan bilinadi. Sizning vazifangiz: (a) ulanishni koârish, (b) qaysi jarayon ekanini topish, (c) loglarda iz qoldimi tekshirish.
Linuxâda tezkor tekshiruv
Ulanishlar:
Qaysi jarayon ulangan?
Shubhali jarayonlar:
SSH / autentifikatsiya loglari:
Windowsâda tezkor tekshiruv
Ulanishlar + PID:
PID â qaysi dastur?
PowerShell orqali:
Event Log (Security):
Shubhali belgilar (red flags)
- Nomaâlum IPâga muntazam outbound ulanishlar
- Gâalati portlar (odatdagi 80/443/22 boâlmagan) va uzoq âESTABLISHEDâ sessiya
/tmp,/dev/shmkabi joylardan ishlayotgan fayl (Linux)- PowerShellâda gâalati command line, nomaâlum process parent-child zanjiri
- Koâp marta muvaffaqiyatsiz login urinishlari (bruteforce izlari)
2) Himoyalanish (Hardening)
Himoya doim 3 qatlam: tarmoq (firewall), hisoblar (ruxsatlar), nazorat (log/monitoring).
Linux: bazaviy hardening
- Keraksiz servislarni oâchirish:
systemctl - SSHâni xavfsizlash: root loginâni yopish, kuchli parol/kalit
- Firewall (UFW) yoqish
- Fail2ban (bruteforceâga qarshi)
Windows: bazaviy hardening
- Firewall yoqilgan boâlsin
- Keraksiz âRemoteâ funksiyalarni cheklash
- Defender real-time himoya
- Admin huquqlarini minimallashtirish
3) Lab sozlash (Xavfsiz oâquv muhit)
Lab â oârganish uchun eng yaxshi usul. Ammo u izolyatsiya qilingan boâlishi shart.
- 2 ta VM: (1) Kali Linux, (2) Windows yoki Ubuntu âVictimâ
- Network: VirtualBoxâda Internal Network yoki Host-only
- Snapshot: har katta oâzgarishdan oldin snapshot oling
- Loglar: Linuxâda
journald, Windowsâda Event Log yoqilgan boâlsin
4) Monitoring (Kuzatish)
Linux monitoring
Windows monitoring
- Task Manager â Details (PIDâlar)
- Resource Monitor â Network
- Event Viewer â Security/System
5) Incident Response (Hujum boâlsa)
Hujum boâldi deganda âpanicâ emas â tartib boâyicha ishlang:
- Izolyatsiya: tarmoqdan uzing (agar kerak boâlsa)
- Dalil: loglar, ulanishlar, jarayonlar haqida maâlumot saqlang
- Tozalash: shubhali jarayon/faylni aniqlang, servislarni tekshiring
- Recovery: parollarni almashtiring, patch qiling, konfiguratsiyani mustahkamlang
Linuxâda tezkor âdalilâ yigâish (minimal)
Eslatma: bu minimal tekshiruv. Katta incidentâlarda forensics alohida jarayon boâladi.
Aloqa
đ +998 90 459 94 09  |  đŹ t.me/otabekie