Home [Wargame] Webhacking.kr old-31 (nc)
Post
Cancel

[Wargame] Webhacking.kr old-31 (nc)

๐Ÿšฉ ๋ฌธ์ œ ํŒŒ์•…


1
2
3
4
5
$port = rand(10000,10100);
$socket = fsockopen($_GET['server'],$port,$errno,$errstr,3) or die("error : {$errstr}");

Warning: fsockopen(): unable to connect to {๊ณต์ธ ip ์ฃผ์†Œ}:10029 (Connection timed out) in /var/www/html/challenge/web-16/index.php on line 23
error : Connection timed out

๋ฌธ์ œ ํŽ˜์ด์ง€์— ๋“ค์–ด๊ฐ€๋ฉด ์œ„์˜ ๋ฌธ๊ตฌ๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.


์œ„์˜ ๋‘ ์ค„์€ php๋กœ ์ž‘์„ฑ๋œ ์ฝ”๋“œ๋กœ, 10000๋ถ€ํ„ฐ 10100๊นŒ์ง€์˜ ๋žœ๋คํ•œ ์ˆ˜๋ฅผ port๋กœ ํ•˜๊ณ  server ์ธ์ž ๊ฐ’์˜ ip ์ฃผ์†Œ์™€ ์†Œ์ผ“ ํ†ต์‹ ์„ ํ•˜๋Š” ๊ตฌ๋ฌธ์ด๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ ํ•ด๋‹น ip ์ฃผ์†Œ๋Š” ๋‚ด๊ฐ€ ์ ‘์†ํ•œ ์ปดํ“จํ„ฐ์˜ ๊ณต์ธ ip ์ฃผ์†Œ์ด๊ธฐ์— 10000๋ฒˆ๋ถ€ํ„ฐ 10100๋ฒˆ๊นŒ์ง€์˜ ํฌํŠธ๊ฐ€ ์—ด๋ ค์žˆ์ง€ ์•Š์„ ๊ฒƒ์ด๊ธฐ์— ํ†ต์‹ ํ•  ์ˆ˜ ์—†์„ ๊ฒƒ์ด๋‹ค. ๋”ฐ๋ผ์„œ ํ•ด๋‹น ip๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ์ปดํ“จํ„ฐ์˜ 10000๋ฒˆ๋ถ€ํ„ฐ 10100๊นŒ์ง€์˜ ํฌํŠธ๋ฅผ ์—ด์–ด๋‘๋ฉด ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์„ ๊ฒƒ์ด๋‹ค.



๐Ÿšฉ ๋ฌธ์ œ ํ’€์ด


์ด ๋ฌธ์ œ๋Š” ๋‘ ๊ฐ€์ง€ ๋ฐฉ๋ฒ•์œผ๋กœ ํ’€์ดํ•  ์ˆ˜ ์žˆ๋‹ค. ์ฒซ ๋ฒˆ์งธ๋Š” ํฌํŠธํฌ์›Œ๋”ฉ์„ ์ด์šฉํ•˜๋Š” ๊ฒƒ์ด๊ณ , ๋‘ ๋ฒˆ์งธ๋Š” ๊ฐœ์ธ ์„œ๋ฒ„๋ฅผ ์ด์šฉํ•˜๋Š” ๊ฒƒ์ด๋‹ค.


1. ํฌํŠธํฌ์›Œ๋”ฉ

image

๊ณต์œ ๊ธฐ ์„ค์ • ํŽ˜์ด์ง€๋กœ ์ด๋™ํ•˜์—ฌ ์œ„์™€ ๊ฐ™์ด ํฌํŠธํฌ์›Œ๋”ฉ์„ ์„ค์ •ํ•˜๋Š” ๊ณณ์„ ์ฐพ๋Š”๋‹ค. ์„œ๋ฒ„์—์„œ๋Š” ๋žœ๋คํ•˜๊ฒŒ 10000๋ฒˆ์—์„œ 10100๋ฒˆ์˜ ํฌํŠธ๋ฅผ ๋ฌด์ž‘์œ„ํ•˜๊ฒŒ ์ ‘์† ์‹œ๋„ํ•  ์˜ˆ์ •์ด๊ธฐ์— ํ•ด๋‹นํ•˜๋Š” ๋ชจ๋“  ํฌํŠธ๋กœ ๋“ค์–ด์˜ค๋Š” ์ ‘์†์„ ๋‚ด๋ถ€ํฌํŠธ 10000๋ฒˆ์œผ๋กœ ํฌ์›Œ๋”ฉํ•  ์ˆ˜ ์žˆ๋„๋ก ์„ค์ •ํ•œ๋‹ค. ์—ฌ๊ธฐ์„œ IP ์ฃผ์†Œ๋Š” cmd > ipconfig > ์ด๋”๋„ท ์–ด๋Œ‘ํ„ฐ ์ด๋”๋„ท > IPv4 ์ฃผ์†Œ์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.


์ด์ œ ๋‚ด๋ถ€์—์„œ 10000๋ฒˆ ํฌํŠธ๋ฅผ ์„œ๋น„์Šคํ•ด์•ผ ํ•œ๋‹ค. ์ด๋ฅผ ์œ„ํ•ด์„œ ์œˆ๋„์šฐ์šฉ netcat(nc) ํ”„๋กœ๊ทธ๋žจ์„ ์„ค์น˜ํ•˜์ž.


1
nc64.exe -lvp 10000

ํ„ฐ๋ฏธ๋„ ์ฐฝ์—์„œ netcat์ด ์„ค์น˜๋œ ๊ฒฝ๋กœ์—์„œ ์œ„์˜ ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜์—ฌ 10000๋ฒˆ ํฌํŠธ๋ฅผ ์—ด์–ด๋ณด์ž. ์—ฌ๊ธฐ์„œ -l ์˜ต์…˜์€ ๋ฆฌ์Šค๋‹, -v ์˜ต์…˜์€ ์ž์„ธํ•œ ์ •๋ณด ์ถœ๋ ฅ, -p ์˜ต์…˜์€ ํฌํŠธ ์ง€์ •์ด๋‹ค.


image

๋งˆ์ง€๋ง‰์œผ๋กœ ๋ฌธ์ œ ํŽ˜์ด์ง€๋ฅผ ์žฌ์ ‘์†ํ•˜๋ฉด ํ•ด๋‹น ip ์ฃผ์†Œ์˜ ๋žœ๋คํ•œ ํฌํŠธ๋กœ ์†Œ์ผ“ ํ†ต์‹ ์„ ์‹œ๋„ํ•  ๊ฒƒ์ด๊ณ , nc๋กœ ์—ด์–ด๋‘” 10000๋ฒˆ ํฌํŠธ๊ฐ€ ํ†ต์‹ ์„ ์ง„ํ–‰ํ•˜๊ฒŒ ๋˜์–ด Flag ๊ฐ’์„ ์–ป๊ฒŒ ๋  ๊ฒƒ์ด๋‹ค.



2. ๊ฐœ์ธ ์„œ๋ฒ„ ์ด์šฉ

aws์™€ ๊ฐ™์€ ๊ฐœ์ธ ํด๋ผ์šฐ๋“œ ์„œ๋ฒ„๊ฐ€ ์žˆ๋‹ค๋ฉด ๊ณต์œ ๊ธฐ๋ฅผ ํฌํŠธ ํฌ์›Œ๋”ฉํ•˜๋Š” ๋ฐฉ์‹๋ณด๋‹ค ํ›จ์”ฌ ์‰ฝ๊ฒŒ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ๋‹ค. ๋‚˜๋Š” aws์˜ ec2๋ฅผ ์ด์šฉํ•˜๊ณ  ์žˆ์–ด ์†์‰ฝ๊ฒŒ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.


image

์šฐ์„ , ํ•ด๋‹น ํด๋ผ์šฐ๋“œ์˜ ๋ณด์•ˆ ๊ทœ์น™์„ ์ˆ˜์ •ํ•˜์—ฌ 10000๋ฒˆ ํฌํŠธ๋ถ€ํ„ฐ 10100๋ฒˆ ํฌํŠธ๊นŒ์ง€ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜์ž.


1
for i in {10000..10100}; do (nc -kl $i &); done

๊ทธ ๋‹ค์Œ์œผ๋กœ ์œ„์™€ ๊ฐ™์ด nc์™€ ์‰˜ ์ฝ”๋“œ๋ฅผ ์ž‘์„ฑํ•˜์—ฌ 100๊ฐœ์˜ ํฌํŠธ๋ฅผ ๋ชจ๋‘ listen ํ•˜์ž.


image

์ด์ œ ๋ฌธ์ œ ํŽ˜์ด์ง€๋ฅผ ์žฌ์ ‘์†ํ•˜์—ฌ ์†Œ์ผ“ ํ†ต์‹ ์„ ์‹œ๋„ํ•˜๋ฉด ์œ„์™€ ๊ฐ™์ด Flag๋ฅผ ํš๋“ํ•  ์ˆ˜ ์žˆ๋‹ค.

[Wargame] Webhacking.kr old-58 (Javascript)

[PortSwigger] Academy: Server-side vulnerabilities