๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๐ŸดCTF/TryHackMe

TryHackMe - Simple CTF (1)

by Janger 2023. 2. 14.
728x90
๋ฐ˜์‘ํ˜•

 

 

 

1๋ฒˆ ์งˆ๋ฌธ. 1000๋ฒˆ ํฌํŠธ ์•„๋ž˜์—์„œ ์‹คํ–‰ ์ค‘์ธ ์„œ๋น„์Šค๋Š” ๋ชจ๋‘ ๋ช‡ ๊ฐœ์ž…๋‹ˆ๊นŒ?

 

 

sudo nmap -sS -sV -T4 -p 1-1000 <Target IP>

Nmap ๋ช…๋ น์–ด๋กœ 1~1000 ํฌํŠธ์—์„œ ์‹คํ–‰๋˜๋Š” ์„œ๋น„์Šค๋ฅผ ์Šค์บ”ํ•ด ๋ณธ๋‹ค. 

 

 

21/tcp (FTP)

80/tcp (HTTP)

์ด๋ ‡๊ฒŒ ๋‘ ๊ฐœ๊ฐ€ ๋‚˜์™”์œผ๋ฏ€๋กœ ์ •๋‹ต์œผ๋กœ "2"๋ฅผ ์ž…๋ ฅ

 

 

 

2๋ฒˆ ์งˆ๋ฌธ. ์ƒ์œ„ ํฌํŠธ์—์„œ ์‹คํ–‰๋˜๋Š” ๊ฒƒ์€ ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?

 

๋†’์€ ํฌํŠธ๋ฒˆํ˜ธ์—์„œ ์‹คํ–‰๋˜๊ณ  ์žˆ๋Š” ์„œ๋น„์Šค๋ฅผ ๋ฌป๋Š”๋‹ค. ๋ฐฉ๊ธˆ์€ 1000๊นŒ์ง€ ์Šค์บ๋‹์„ ํ•ด์ฃผ์—ˆ์œผ๋‹ˆ 1001๋ถ€ํ„ฐ ์ด๋ฒˆ์—” 3000๊นŒ์ง€ ์Šค์บ”

 

sudo nmap -sS -sV -T4 -p 1001-3000 <Target IP>

 

 

2222/tcp (SSH)

๊ทธ๋žฌ๋”๋‹ˆ 2222๋ฒˆ ํฌํŠธ๋กœ ์šด์˜ ์ค‘์ธ OpenSSH๊ฐ€ ๋ฐœ๊ฒฌ

 

์ •๋‹ต์œผ๋กœ "ssh"๋ฅผ ์ž…๋ ฅ

 

 

3๋ฒˆ ์งˆ๋ฌธ. ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ๋Œ€ํ•ด ์‚ฌ์šฉ ์ค‘์ธ CVE๋Š” ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?

์ด์ œ ๊ณต๊ฒฉํ•  ํƒ€๊ฒŸ์˜ CVE(Common Vulnerabilities and Exposure)๋ฅผ ์ž…๋ ฅํ•ด์•ผ ํ•˜๋Š” ์ƒํ™ฉ์ด๋‹ค. 

ํ˜น์‹œ๋‚˜ ํ•˜๊ณ  OpenSSH 7.2p2 ๋“ฑ SSH์™€ ๊ด€๋ จ๋œ CVE๋“ค์„ ์ž…๋ ฅํ•ด ๋ณด์•„๋„ ์ •๋‹ต์œผ๋กœ ์ธ์ •ํ•˜์ง€ ์•Š์•„ ssh๊ฐ€ ์•„๋‹Œ ์›น์„œ๋ฒ„์˜ ์ทจ์•ฝ์ ์„ ๊ฒ€์ƒ‰์„ ํ•ด๋ณด๊ธฐ๋กœ ํ•œ๋‹ค. 

 

 

 

๋ชฉํ‘œ์˜ ์•„์ดํ”ผ๋กœ ๋ธŒ๋ผ์šฐ์ €๋ฅผ ํ†ตํ•ด ์ ‘์†ํ•ด ๋ดค๋”๋‹ˆ ์•„ํŒŒ์น˜ ์„œ๋ฒ„๊ฐ€ ์—ด๋ ค์žˆ์—ˆ๋‹ค. 

 

์ด์ œ ์‹ค์ œ ์šด์˜๋˜๊ณ  ์žˆ๋Š” ๋ฉ”์ธ ํŽ˜์ด์ง€๋กœ ์ ‘์†์„ ์œ„ํ•œ ๊ฒฝ๋กœ๋ฅผ ์•Œ์•„๋‚ด๊ธฐ ์œ„ํ•ด gobuster๋ผ๋Š” URIs, ๋””๋ ‰ํ† ๋ฆฌ ์Šค์บ” ๋„๊ตฌ๋ฅผ ์“ฐ๊ธฐ๋กœ ํ•œ๋‹ค. 

 

gobuster์˜ ๊ด€๋ จ ๋ช…๋ น์–ด ์˜ต์…˜๋“ค์€ ์•„๋ž˜์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค. 

https://www.kali.org/tools/gobuster/

 

gobuster | Kali Linux Tools

Video gobuster Usage Examples Scan a website (-u http://192.168.0.155/) for directories using a wordlist (-w /usr/share/wordlists/dirb/common.txt) and print the full URLs of discovered paths (-e): root@kali:~# gobuster -e -u http://192.168.0.155/ -w /usr/s

www.kali.org

 

gobuster dir -u http://10.10.164.52 -w /usr/share/wordlists/dirb/common.txt -t 100

dir: ๋””๋ ‰ํ„ฐ๋ฆฌ/ํŒŒ์ผ ์—ด๊ฑฐ ๋ชจ๋“œ ์‚ฌ์šฉ

-u: url

-w: ์‚ฌ์ „ ํŒŒ์ผ ๊ฒฝ๋กœ

-t: ๋ฉ€ํ‹ฐ ์Šค๋ ˆ๋“œ ๊ฐœ์ˆ˜(๊ธฐ๋ณธ 10)

 

 

/simple์ด๋ผ๋Š” ๊ฒŒ ๊ฐ€์žฅ ๋ˆˆ์— ๋ณด์ด๋Š”๋ฐ ๋ธŒ๋ผ์šฐ์ €๋กœ ์ง์ ‘ ์ด๋™ํ•ด๋ณธ๋‹ค. 

 

 

์‹ค์ œ /simple ๊ฒฝ๋กœ ํŽ˜์ด์ง€ ํ™”๋ฉด์ด๋‹ค. "CMS Made Simple" CMS(Content Management System)์˜ ํ•œ ์ข…๋ฅ˜๋กœ ๋ณด์ด๋ฉฐ, 

์‹ค์ œ๋กœ ์ธํ„ฐ๋„ท์— ์˜คํ”ˆ์†Œ์Šค๋กœ ๊ณต์œ ํ•˜๊ณ  ์žˆ๋Š” CMS๋ผ๊ณ  ํ•จ

 

์ด์ œ ์ง„์งœ ๋ชฉํ‘œ๋ฌผ์„ ์ฐพ์€ ๊ฒƒ ๊ฐ™์•„์„œ searchsploit์œผ๋กœ CVE๋ฅผ ์ฐพ์•„๋ณด๋ ค๊ณ  "cmd made simple"์„ ๊ฒ€์ƒ‰ํ•ด ๋ณด์•˜๋”๋‹ˆ

 

๊ด€๋ จ๋œ ๊ฒฐ๊ณผ๋ฌผ์ด ์ˆ˜๋‘๋ฃฉํ•˜๊ฒŒ ๋‚˜์˜จ๋‹ค. ๋ฒ„์ „๋„ ํฌํ•จํ•ด ๊ฒ€์ƒ‰์„ ํ•  ์ˆ˜ ์žˆ์œผ๋‹ˆ ์‚ฌ์ดํŠธ์—์„œ CMS์˜ ๋ฒ„์ „์„ ์ฐพ์•„๋ณธ๋‹ค. 

 

 

์ฐพ๋Š” ๊ฑด ์–ด๋ ต์ง€ ์•Š๊ฒŒ ํŽ˜์ด์ง€์˜ ๊ฐ€์žฅ ํ•˜๋‹จ์— 2.2.8์ด๋ผ ๋Œ€๋†“๊ณ  ์ ํ˜€ ์žˆ์—ˆ์Œ

 

 

searchsploit CMS Made Simple 2.2.8

 

๊ฒฐ๊ณผ๊ฐ€ ๋”ฑ ํ•˜๋‚˜ ๋‚˜์˜ด

 

ํ•ด๋‹น ์ทจ์•ฝ์ ์˜ ์ž์„ธํ•œ ์ •๋ณด๋ฅผ ์ฐพ๊ธฐ ์œ„ํ•ด์„œ๋Š” -p ์˜ต์…˜์„ ์‚ฌ์šฉํ•ด์•ผ ํ•œ๋‹ค. 

 

 

searchsploit -p php/webapps/46635.py

 

  Exploit: CMS Made Simple < 2.2.10 - SQL Injection
      URL: https://www.exploit-db.com/exploits/46635
     Path: /usr/share/exploitdb/exploits/php/webapps/46635.py
    Codes: CVE-2019-9053
 Verified: False
File Type: Python script, ASCII text executable

 

 

 

 

์•„๋ฌดํŠผ CVE๋ฅผ ์ฐพ์•˜์œผ๋‹ˆ ์ •๋‹ต ์ž…๋ ฅ๋ž€์— ํ•œ๋ฒˆ ์ž…๋ ฅ์„ ์‹œ๋„ ๋์— ์ •๋‹ต์œผ๋กœ ์ธ์ •๋ฐ›์•˜๋‹ค.

 

 

 

4๋ฒˆ ์งˆ๋ฌธ. ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์€ ์–ด๋–ค ์ข…๋ฅ˜์˜ ์ทจ์•ฝ์„ฑ์— ์ทจ์•ฝํ•ฉ๋‹ˆ๊นŒ?

 

์ต์Šคํ”Œ๋กœ์ž‡ ์ด๋ฆ„์ด "CMS Made Simple < 2.2.10 - SQL Injection"์ด๋‹ˆ๊น SQLI๊ฐ€ ์ •๋‹ต์ด๋‹ค. 

 

 

 

5๋ฒˆ ์งˆ๋ฌธ. ํŒจ์Šค์›Œ๋“œ๊ฐ€ ๋ฌด์—‡์ž…๋‹ˆ๊นŒ?

 

๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์•Œ์•„๋‚ด๊ธฐ ์œ„ํ•ด ๋ฐฉ๊ธˆ ์ฐพ์€ CVE์˜ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์ง์ ‘ ์‹คํ–‰ํ•ด ๋ณธ๋‹ค. 

 

"/usr/share/exploitdb/exploits/php/webapps/46635.py"์— ์žˆ๋Š” ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‹คํ–‰ํ•˜์˜€๋Š”๋ฐ 

์š”๋Ÿฐ print๊ฐ€ ๊ด„ํ˜ธ๋ฅผ ์“ฐ์ง€ ์•Š์€ ๋ฌธ๋ฒ•์—๋Ÿฌ๊ฐ€ ๋œจ๋ฏ€๋กœ, ๋”ฐ๋กœ ํ…์ŠคํŠธ ์—๋””ํ„ฐ๋กœ print๋ฅผ print()๋กœ ์ˆ˜์ •ํ•ด ์ฃผ์—ˆ์Œ 

 

 

์ด ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‚ฌ์šฉํ•˜๋ ค๋ฉด -u ์˜ต์…˜์œผ๋กœ ํƒ€๊ฒŸ์„ ์ง€์ •ํ•ด ์ค„ ํ•„์š”๊ฐ€ ์žˆ๋‹ค. 

 

 

python3 46635.py -u http://10.10.164.52/simple/

 

 

์‹คํ–‰ํ•˜๋‹ˆ๊น ํ•˜๋‚˜ํ•˜๋‚˜์”ฉ ๋ฌธ์ž๋ฅผ ๋Œ€์ž…ํ•ด ๋ณด๋ฉด์„œ ์ •๋ณด๋“ค์„ ์œ ์ถ”ํ•ด๋‚ด๊ณ  ์žˆ๋‹ค. ์—ฌ๊ธฐ์„œ๋Š” ์‹œ๊ฐ„์ด ์ข€ ๊ฑธ๋ฆฌ๋‹ˆ ์—ฌ์œ ๋ฅผ ๊ฐ€์ง€๊ณ  ๊ธฐ๋‹ค๋ ค๋ณธ๋‹ค. 

 

๋‚˜์˜จ ๊ฒฐ๊ณผ๋ฅผ ์–ด๋“œ๋ฏผ ๋กœ๊ทธ์ธ ํŽ˜์ด์ง€์—์„œ ์‹œ๋„๋ฅผ ํ•ด๋ณด์•˜๋Š”๋ฐ ๋กœ๊ทธ์ธ์ด ์•ˆ ๋๋‹ค. ์•„๋งˆ ์œ„์—์„œ ์ฐพ์€ ํŒจ์Šค์›Œ๋“œ๋Š” ํ•ด์‹œํ™”๋œ ๊ฒฐ๊ณผ๋ผ์„œ ๋”ฐ๋กœ ํŒจ์Šค์›Œ๋“œ ๋ฆฌ์ŠคํŠธ์—์„œ ์œ„์™€ ์ผ์น˜ํ•œ ํ•ด์‹œ๋ฅผ ๊ฐ–๋Š” ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ฐพ์•„๋‚ด์•ผ ํ•˜๋Š” ๋ชจ์–‘์ด์—ˆ๋‹ค.

 

 

python3 46635.py -u http://10.10.164.52/simple/ --crack -w /usr/share/wordlists/rockyou.txt.

๋‹ค์‹œ ์›Œ๋“œ๋ฆฌ์ŠคํŠธ ์˜ต์…˜ ๊ฒฝ๋กœ(--crack -w <path>)๋ฅผ ์ถ”๊ฐ€ํ•˜๊ณ  ์‹คํ–‰ ์‹œ๋„

 

 

๊ทผ๋ฐ ์ด ๊ณผ์ •์—์„œ ์ธ์ฝ”๋”ฉ ์—๋Ÿฌ๋ฉฐ, ์˜ค๋ฅ˜๋กœ ์‹คํ–‰์ด ์ค‘๋‹จ๋˜๋ฉด ์ฒ˜์Œ๋ถ€ํ„ฐ ์‹œ์ž‘ํ•˜๋Š” ๋“ฑ ์—ฌ๋Ÿฌ ๊ฐ€์ง€ ๋ถˆํŽธ์š”์†Œ๋“ค์ด ๋‚œ๋ฌดํ•˜์—ฌ์„œ ๊ฒฐ๊ตญ ์†Œ์Šค๋ฅผ ๋‚ด๊ฐ€ ์ง์ ‘ ์ˆ˜์ •ํ•ด ์ฃผ์—ˆ๋‹ค..

 

 

๊ทธ๋ ‡๊ฒŒ ์šฐ์—ฌ๊ณก์ ˆ ๋์— ์ฐพ์•„๋‚ธ ํฌ๋ž™๋œ ๋น„๋ฐ€๋ฒˆํ˜ธ์˜ ์ •๋‹ต์€ "secret"

 

 

์–ด๋“œ๋ฏผ ๋กœ๊ทธ์ธ ํŽ˜์ด์ง€์— ์ ‘๊ทผ(http://<target>/simple/admin) ํ•ด์„œ "mitch"์™€ "secret"์„ ๋„ฃ๊ณ  ์ œ์ถœ์„ ํ•ด๋ณธ๋‹ค. 

 

 

๋“œ๋””์–ด ๋กœ๊ทธ์ธ์— ์„ฑ๊ณตํ•ด ๊ด€๋ฆฌ์ž ํŽ˜์ด์ง€ ์ ‘์† ์„ฑ๊ณต

 

 

5๋ฒˆ ์งˆ๋ฌธ(๋น„๋ฐ€๋ฒˆํ˜ธ๋Š” ๋ฌด์—‡์ธ๊ฐ€์š”?)์˜ ์ •๋‹ต์€ "secret"์ด๋‹ค. 

 

 

 

์ด์ œ ์ง„ํ–‰๋„ 50%๊ฐ€ ๋๋‚ฌ๊ณ  ๋‚˜๋จธ์ง€ 50%๋Š” ๋‹ค์Œ์— ํ•ด๋ด์•ผ๊ฒ ๋‹ค. ์Šคํฌ๋ฆฝํŠธ๋ฅผ ๊ณ ์น˜๋Š”๋ฐ๋งŒ ๋งŽ์€ ์‹œ๊ฐ„๊ณผ ์—ด์ •์„ ๋นผ์•—๊ฒจ๋ฒ„๋ ธ๋‹ค.. 

 

 

์ฐธ๊ณ : 

https://highon.coffee/blog/nmap-cheat-sheet/

 

Nmap Cheat Sheet: Commands & Examples (2022)

Nmap (network mapper), the god of port scanners used for network discovery and the basis for most security enumeration during the initial stages of a penetration test. The tool was written and maintained by Fyodor AKA Gordon Lyon. Nmap displays exposed ser

highon.coffee

 

https://www.kali.org/tools/

 

Kali Tools | Kali Linux Tools

Home of Kali Linux, an Advanced Penetration Testing Linux distribution used for Penetration Testing, Ethical Hacking and network security assessments.

www.kali.org

 

 

728x90
๋ฐ˜์‘ํ˜•

'๐ŸดCTF > TryHackMe' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

TryHackMe - Pickle Rick  (1) 2023.05.20
TryHackMe - Simple CTF (2)  (1) 2023.03.18
TryHackMe - OpenVPN ์—๋Ÿฌ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ• (Failed to open tun/tap interface)  (0) 2023.02.12