<feed xmlns="http://www.w3.org/2005/Atom"> <id>https://yee-yore.github.io/</id><title>yee-yore</title><subtitle>A minimal, responsive and feature-rich Jekyll theme for technical writing.</subtitle> <updated>2026-10-11T00:54:44+09:00</updated> <author> <name>yee-yore</name> <uri>https://yee-yore.github.io/</uri> </author><link rel="self" type="application/atom+xml" href="https://yee-yore.github.io/feed.xml"/><link rel="alternate" type="text/html" hreflang="en" href="https://yee-yore.github.io/"/> <generator uri="https://jekyllrb.com/" version="4.4.1">Jekyll</generator> <rights> © 2026 yee-yore </rights> <icon>/assets/img/favicons/favicon.ico</icon> <logo>/assets/img/favicons/favicon-96x96.png</logo> <entry><title>네이버 PER 제도 후기 (2025)</title><link href="https://yee-yore.github.io/posts/naver-per-2025/" rel="alternate" type="text/html" title="네이버 PER 제도 후기 (2025)" /><published>2026-10-10T23:57:00+09:00</published> <updated>2026-10-10T23:57:00+09:00</updated> <id>https://yee-yore.github.io/posts/naver-per-2025/</id> <content type="text/html" src="https://yee-yore.github.io/posts/naver-per-2025/" /> <author> <name>yee-yore</name> </author> <category term="Review" /> <summary>PER(Privacy Enhancement Reward) 제도는 네이버가 국내 최초로 도입한 개인정보보호 신고포상제다. 버그바운티보다 상대적으로 경쟁력이 낮고, 범위도 네이버 서비스 전체라 도전해볼 만하다. 어떤 걸 제보해야 하는지는 공개할 수 없지만, 검색해보면 직접 공개한 사람들도 있으니 참고하면 좋을 것 같다. 참여하면서 좋았던 점을 정리해보면 1. 보상금 경쟁력이 낮아 열심히 하는 만큼 받아갈 수 있다. 중복되는 경우도 간혹 있으나 버그바운티보다는 덜하다(버그바운티 중복됐을 때의 스트레스보다도 덜하다). 등급에 따라 보상금에 추가 금액이 더해지기 때문에 다이아몬드를 달성하면 보상금이 꽤 달달하다. 간혹 2배 이벤트를 하는데 이슈 모아놨다가 이벤트 때 제보하는 방법도 노려볼만한 것 같다....</summary> </entry> <entry><title>URL Enumeration</title><link href="https://yee-yore.github.io/posts/url-enumeration/" rel="alternate" type="text/html" title="URL Enumeration" /><published>2026-10-10T23:09:00+09:00</published> <updated>2026-10-10T23:09:00+09:00</updated> <id>https://yee-yore.github.io/posts/url-enumeration/</id> <content type="text/html" src="https://yee-yore.github.io/posts/url-enumeration/" /> <author> <name>yee-yore</name> </author> <category term="Red Team" /> <category term="Reconnaissance" /> <summary>URL enumeration은 Wayback Machine, Common Crawl, AlienVault OTX 같은 크롤링 데이터 소스를 활용해서, 특정 도메인의 과거·현재 URL을 수집하는 과정이다. 정찰에서 juicy한 데이터를 많이 얻을 수 있는 과정으로, 다양한 공격 표면을 식별할 수 있다. 버그바운티에서는 XSS oneliner나 JS recon oneliner에도 사용된다. 대표적인 URL enumeration 도구는 아래와 같으며, 파이프라이닝이 편한 Project Discovery의 urlfinder나 여러 소스로부터 많은 URL을 수집해주는 waymore를 주로 사용한다. 도구별 옵션을 이용해 수집 기간, 확장자, 출력 형태 등을 설정할 수 있으며 용도에 맞게 설정하면 된다. ...</summary> </entry> <entry><title>SMB 취약점 진단</title><link href="https://yee-yore.github.io/posts/smb_pentest/" rel="alternate" type="text/html" title="SMB 취약점 진단" /><published>2026-10-07T23:17:00+09:00</published> <updated>2026-10-08T00:17:21+09:00</updated> <id>https://yee-yore.github.io/posts/smb_pentest/</id> <content type="text/html" src="https://yee-yore.github.io/posts/smb_pentest/" /> <author> <name>yee-yore</name> </author> <category term="Red Team" /> <category term="Vulnerability Assessment" /> <summary>네트워크 모의해킹을 위해 포트스캐닝을 하다보면 tcp/445의 SMB가 거의 항상 보인다. SMB는 다른 컴퓨터의 파일/프린터/폴더를 네트워크 너머로 쓰게 해주는 프로토콜이다. (e.g. \\서버\공유폴더로 접근하는 네트워크 드라이브나 공용 프린터) 공유 폴더나 프린터뿐 아니라, Active Directory에서 로그인하고 그룹 정책을 뿌리는 작업 등 SMB를 탄다. 따라서 Windows가 있는 내부망은 445가 거의 항상 있고, Linux도 Samba를 깔면 SMB 공유를 열 수 있다. SMB는 주로 아래와 같이 악용된다. 파일 공유 공유 폴더 내 중요 파일 등 노출 인증 탈취한 NTLM 해시를 이용한 Pass-the-Hash ...</summary> </entry> <entry><title>Google Dorking</title><link href="https://yee-yore.github.io/posts/google-dorking/" rel="alternate" type="text/html" title="Google Dorking" /><published>2026-10-05T22:27:00+09:00</published> <updated>2026-10-05T22:44:31+09:00</updated> <id>https://yee-yore.github.io/posts/google-dorking/</id> <content type="text/html" src="https://yee-yore.github.io/posts/google-dorking/" /> <author> <name>yee-yore</name> </author> <category term="Red Team" /> <category term="Reconnaissance" /> <summary>Google Dorking(=Google Hacking)은 Google 검색엔진에서 필터와 연산자를 이용해 원하는 정보를 체계적으로 검색하는 OSINT 기법이다. 개인적으로 느끼기에 Google Dorking은 알아두면 업무 외에도 요긴하게 써먹을 때가 많다. (e.g. 정확한 키워드가 포함된 검색, 게재된 논문과 같은 이력 검색) 아래와 같은 필터와 연산자를 주로 사용하며, 이를 조합하면 내가 원하는 정보를 구체적으로 탐색할 수 있다. 연산자 설명 예시 site: 특정 도메인 내에서만 검색 site:example.com inurl: URL에 특정 문...</summary> </entry> <entry><title>레드라쿤 인프런 멘토링 후기</title><link href="https://yee-yore.github.io/posts/inflearn-mentoring-review/" rel="alternate" type="text/html" title="레드라쿤 인프런 멘토링 후기" /><published>2026-10-04T21:00:00+09:00</published> <updated>2026-10-04T22:41:01+09:00</updated> <id>https://yee-yore.github.io/posts/inflearn-mentoring-review/</id> <content type="text/html" src="https://yee-yore.github.io/posts/inflearn-mentoring-review/" /> <author> <name>yee-yore</name> </author> <category term="Review" /> <summary>정보보안 업무를 하면서 모의해킹이나 레드팀 같은 Offensive 쪽으로 가고 싶다는 생각이 점점 커졌는데 막상 뭘 준비해야 할지, 지금까지의 내 경력에서 보완할 것은 무엇인지 방향이 잡히지 않았다. 레드라쿤 디스코드는 예전부터 계속 보고 있었는데, groot님이 멘토링도 진행한다는 것을 알게 됐다. 멘토링은 2시간 반 정도 진행되었다. 우선 우리가 왜 이 업무를 해야 하는지, 공부 방식, 기업에서 원하는 것 등 전반적인 것을 설명해주셨다. 이후에 내가 궁금했던 것들, 모의해킹/레드팀 쪽으로 가려면 무엇을 준비해야 하는지, 그리고 내 경력에서 보완해야 할 부분은 무엇인지 여쭤봤다. 멘토링을 통해 내가 가진 고민거리도 해결됐고 앞으로 어떻게 준비하면 좋을지 방향이 잡힌 것 같다. 그리고 실무 역...</summary> </entry> </feed>
