๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
728x90
๋ฐ˜์‘ํ˜•

๐ŸดCTF/TryHackMe4

TryHackMe - Pickle Rick ๊ฐœ์š” ๋ฏธ๊ตญ ์ธ๊ธฐ ์• ๋‹ˆ ๋ฆญ์•ค ๋ชจํ‹ฐ ํŒจ๋Ÿฌ๋”” CTF ๋ฌธ์ œ์ด๋‹ค. ์›ƒ๊ธฐ๊ฒŒ๋„ ์ด๋ฒˆ ๋ฌธ์ œ์—๋Š” ์Šคํ† ๋ฆฌ๊ฐ€ ์กด์žฌํ•˜๋Š”๋ฐ, ํ”ผํด(?)๋กœ ๋ณ€ํ•œ ๋ฆญ์ด ๋‹ค์‹œ ์‚ฌ๋žŒ์œผ๋กœ ๋Œ์•„์˜ค๋ ค๋ฉด 3๊ฐ€์ง€์˜ ์–ด๋–ค ์žฌ๋ฃŒ๊ฐ€ ํ•„์š”ํ•œ๋ฐ ๋ฌธ์ œ ํ’€์ด์ž์ธ ์šฐ๋ฆฌ๊ฐ€(์ž‘์ค‘์˜ ๋ชจํ‹ฐ๊ฐ€ ๋˜์–ด์„œ) CTF ๋ฌธ์ œ๋ฅผ ํ’€๋ฉด์„œ ์žฌ๋ฃŒ๋“ค์„ ์ฐพ๋Š” ๊ฒƒ์ด ๋ชฉ์ ์ด๋‹ค. Question 1. What is the first ingredient that Rick needs? nmap ๋ช…๋ น์–ด๋กœ ๋ฆญ์˜ ์ปดํ“จํ„ฐ์— ์—ด๋ ค์žˆ๋Š” ์„œ๋น„์Šค๋“ค์„ ์Šค์บ๋‹ํ•˜๋ฉด ๋‹ค์Œ๊ณผ ๊ฐ™์ด 2๊ฐœ๊ฐ€ ๋‚˜์˜จ๋‹ค. (ssh์™€ http) $ sudo nmap -sS -sV -T4 -p 1-100 10.10.232.99 22/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.6 (Ubuntu Linux; protocol 2.0).. 2023. 5. 20.
TryHackMe - Simple CTF (2) 6๋ฒˆ ์งˆ๋ฌธ. ํš๋“ํ•œ ์„ธ๋ถ€ ์ •๋ณด๋กœ ์–ด๋””์—์„œ ๋กœ๊ทธ์ธํ•  ์ˆ˜ ์žˆ๋‚˜์š”? ํš๋“ํ•œ ๊ณ„์ •์œผ๋กœ ๋‹ค๋ฅธ ์„œ๋น„์Šค ์–ด๋””์— ๋กœ๊ทธ์ธ์ด ๊ฐ€๋Šฅํ•˜๋ƒ๋Š” ์งˆ๋ฌธ ๊ฐ™์•˜๋‹ค. ์šฐ์„  ์•Œ๊ณ  ์žˆ๋Š” ๊ณ„์ •์€ mitch:secret์ด์—ˆ์œผ๋ฉฐ ์›น ์„œ๋ฒ„์˜ SSH์—๋„ ๋กœ๊ทธ์ธ ๊ฐ€๋Šฅํ•œ์ง€ ํ™•์ธํ•ด ๋ณธ๋‹ค. nmap์œผ๋กœ ์›น ์„œ๋ฒ„์˜ ssh ํฌํŠธ ๋ฒˆํ˜ธ๋ฅผ ์ฐพ์•„์ค€๋‹ค. (result: 2222/tcp) ssh ๋กœ๊ทธ์ธ ๋‹จ๊ณ„์—์„œ ์›น ์‚ฌ์ดํŠธ ๊ด€๋ฆฌ์ž์ธ mitch ๊ณ„์ •์„ ๋˜‘๊ฐ™์ด ์ž…๋ ฅํ•˜๋‹ˆ ๋กœ๊ทธ์ธ์ด ์„ฑ๊ณตํ–ˆ๋‹ค. 6๋ฒˆ ์ •๋‹ต์€ "ssh" 7๋ฒˆ ์งˆ๋ฌธ. ์‚ฌ์šฉ์ž์˜ ํ”Œ๋ž˜๊ทธ๋Š” ๋ฌด์—‡์ž…๋‹ˆ๊นŒ? ์ฐพ๋Š” ๊ฑด ๊ฐ„๋‹จํ•˜๋‹ค. ์‰˜์— ๋“ค์–ด๊ฐ€์ž๋งˆ์ž ls๋ฅผ ์น˜๋ฉด user.txt๋ž€ ํŒŒ์ผ์ด ํ•˜๋‚˜ ์žˆ๋Š”๋ฐ ๊ทธ ๋‚ด์šฉ๋ฌผ์ด ๋ฐ”๋กœ ํ”Œ๋ž˜๊ทธ์ด๋‹ค. 7๋ฒˆ ์ •๋‹ต์€ "G00d j0b, keep up!" 8๋ฒˆ ์งˆ๋ฌธ. ํ™ˆ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ๋‹ค๋ฅธ ์‚ฌ์šฉ์ž๊ฐ€ ์žˆ๋‚˜์š”? ์ด๋ฆ„์ด.. 2023. 3. 18.
TryHackMe - Simple CTF (1) 1๋ฒˆ ์งˆ๋ฌธ. 1000๋ฒˆ ํฌํŠธ ์•„๋ž˜์—์„œ ์‹คํ–‰ ์ค‘์ธ ์„œ๋น„์Šค๋Š” ๋ชจ๋‘ ๋ช‡ ๊ฐœ์ž…๋‹ˆ๊นŒ? sudo nmap -sS -sV -T4 -p 1-1000 Nmap ๋ช…๋ น์–ด๋กœ 1~1000 ํฌํŠธ์—์„œ ์‹คํ–‰๋˜๋Š” ์„œ๋น„์Šค๋ฅผ ์Šค์บ”ํ•ด ๋ณธ๋‹ค. 21/tcp (FTP) 80/tcp (HTTP) ์ด๋ ‡๊ฒŒ ๋‘ ๊ฐœ๊ฐ€ ๋‚˜์™”์œผ๋ฏ€๋กœ ์ •๋‹ต์œผ๋กœ "2"๋ฅผ ์ž…๋ ฅ 2๋ฒˆ ์งˆ๋ฌธ. ์ƒ์œ„ ํฌํŠธ์—์„œ ์‹คํ–‰๋˜๋Š” ๊ฒƒ์€ ๋ฌด์—‡์ž…๋‹ˆ๊นŒ? ๋†’์€ ํฌํŠธ๋ฒˆํ˜ธ์—์„œ ์‹คํ–‰๋˜๊ณ  ์žˆ๋Š” ์„œ๋น„์Šค๋ฅผ ๋ฌป๋Š”๋‹ค. ๋ฐฉ๊ธˆ์€ 1000๊นŒ์ง€ ์Šค์บ๋‹์„ ํ•ด์ฃผ์—ˆ์œผ๋‹ˆ 1001๋ถ€ํ„ฐ ์ด๋ฒˆ์—” 3000๊นŒ์ง€ ์Šค์บ” sudo nmap -sS -sV -T4 -p 1001-3000 2222/tcp (SSH) ๊ทธ๋žฌ๋”๋‹ˆ 2222๋ฒˆ ํฌํŠธ๋กœ ์šด์˜ ์ค‘์ธ OpenSSH๊ฐ€ ๋ฐœ๊ฒฌ ์ •๋‹ต์œผ๋กœ "ssh"๋ฅผ ์ž…๋ ฅ 3๋ฒˆ ์งˆ๋ฌธ. ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์— ๋Œ€ํ•ด ์‚ฌ์šฉ ์ค‘์ธ CVE๋Š” .. 2023. 2. 14.
TryHackMe - OpenVPN ์—๋Ÿฌ ํ•ด๊ฒฐ ๋ฐฉ๋ฒ• (Failed to open tun/tap interface) ์ž์‹ ์˜ *.ovpn ํŒŒ์ผ์„ ์—ด์–ด์„œ "cipher AES-256-CBC"๋ฅผ "data-ciphers AES-256-CBC:AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305"๋กœ ์ˆ˜์ •ํ•˜๊ณ  ์ €์žฅํ•˜๊ณ  ์‹คํ–‰ํ•œ๋‹ค. data-ciphers AES-256-CBC:AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305 vim์œผ๋กœ ์ˆ˜์ •ํ•˜๊ธฐ :%s/cipher AES-256-CBC/data-ciphers AES-256-CBC:AES-256-GCM:AES-128-GCM:CHACHA20-POLY1305/g ์ถœ์ฒ˜: https://tryhackme.com/forum/thread/62bb0daf19e588005b7b1739 TryHackMe | Cyber Security Training A.. 2023. 2. 12.
728x90
๋ฐ˜์‘ํ˜•