# Description
Are you just another customer here , or do you have in you, what it takes to see beyond the ordinary?
Things might look ordinary on the outside , but inside, lies a mangled web of shocking secrets.
Should you choose to take the quest and discover what others can't , follow along, and what you are seeking , shall be revealed .
Plain Text
๋ณต์ฌ
# ๋ถ์
์ฒ์๋ณด๋ ์ ํ์ ๋ฌธ์ ์๋ค.
์ ๊ทผํ๋ ๋ฐฉ๋ฒ๊ณผ ์๊ฐํ๋ ๋ด์ฉ ๋ชจ๋๋ฅผ ๊ธฐ์ ํด๋ณด๊ฒ ๋ค.
๋ฌธ์ ๋ฅผ ๋ค์ด๋ฐ๊ณ ์์ถ์ ํ์ด๋ณด๋ฉด .ova ํ์ฅ์๋ฅผ ๊ฐ์ง๋ ํ์ผ์ ํ๋ ๋์ ธ์ค๋ค.
์ผ๋จ HxD๋ก ๊น๋ณด๋ฉด ovf๋ผ๋ ๋ฐ์ดํฐ๊ฐ ์๋๊ฑธ ๋ณผ ์ ์๊ณ ํ์ผ ํ์ฅ์ ์ ๋ณด๋ฅผ ์ผ๋จ ๋จผ์ ์ฐพ์๋ณด์.
1.
.ova
๊ฐ๋ฐฉํ ๊ฐ์ ์ดํ๋ผ์ด์ธ์ค(OVA) ์ ๋จ์ผ ํ์ผ ์์นด์ด๋ธ์ OVF ํจํค์ง
2.
ovf
๊ฐ์ ์์คํ
์ ์ค๋ช
ํ๋ XML, ์ด๋ฆ, ํ๋์จ์ด, ํจํค์ง ์ค๋ช
๋ฑ๋ฑโฆ
๋ผ๊ณ ๋์ด ์๊ณ ์์นด์ด๋ธ๋ผ๋ ์ ๊ณผ ์ฌ๋ฌ ์ ๋ณด๋ฅผ ๋ด๊ณ ์๋ ๊ฒ์ผ๋ก ๋ณด์ ์ผ๋จ ZIP ํ์ผ๋ก ํ์ฅ์๋ฅผ ๋ณ๊ฒฝํด๋ณธ๋ค.
์ฌ๊ธฐ์ ์ฃผ๋ชฉํด์ผํ๋ ๋ถ๋ถ์ vmdk ํ์ผ์ด๋ค.
vmdk ํ์ผ์ ํํ VMWare, Virtual Box๋ฑ ๊ฐ์ํ ์ํํธ์จ์ด์์ ๊ฐ์ ํ๋ ๋์คํฌ๋ฅผ ๋ด๋ณด๋ด๋ ๋ฐฉ์์ด๋ค.
์ ์ด์ ํด๋น ํ์ผ์ VMWare์์ ์ด์ด๋ณด์.
VMWare Open
Open a Virtual Machine์ ํด๋ฆญํด์ ์คํํ๋ค.
๋์ถฉ ์ค์ ํด์ฃผ๊ณ Import ์ค์ ํด์ค๋ค.
์์ฑ ์๋ฃ๋๋ฉด ์คํํด์ค๋ค.
๋ฆฌ๋
์ค๊ฐ ์คํ๋๋ ๊ฒ์ ๋ณผ ์ ์๋ค.
File System ๋ถ์
์คํํ๋ฉด Alice ๋ผ๋ User๋ก ๋ก๊ทธ์ธํ๊ฒ ์ค์ ๋์ด ์๋ค.
๋น๋ฐ๋ฒํธ๋ฅผ ๋ชจ๋ฅด๋ ์ผ๋จ File System ๋จผ์ ํ์ธํ๊ธฐ ์ํด VM์ Shutdown ํ ๋ค FTK Imager๋ฅผ ์คํํ๋ค.
Add Evidence Item... ํด๋ฆญ, Image File ํด๋ฆญ
Browse๋ก ์๊น ๋ง๋ vmdk ํ์ผ ์คํ ๋ค Finish ํด๋ฆญ
์ด๋ฆฐ ํ์ผ์ ์ฑ ๋ณด๋ค alice ํ์ผ ์์คํ
์ Export Files...๋ฅผ ๋๋ฌ alice ์์ฒด๋ฅผ ์ถ์ถํ๋ค.
๊ทธ๋ฆฌ๊ณ /etc/passwd์ /etc/shadow๋ฅผ ๋ค์ด๊ฐ๋ค.
Login
/etc/passwd
/etc/shadow
root๋ alice์ password๋ฅผ crackํ๋ ค๊ณ ํ์ง๋ง ์คํจํ๋ค.
Password Reset
FTK Imager๋ก ํ์ํ ํ์ผ์ ์ผ๋จ ๋ค ์ถ์ถํ๋ค.
์ด์ FTK๋ฅผ ๊บผ์ฃผ๊ณ VM์ ์คํํ๊ณ Shift + E๋ฅผ ์ฐํํ๋ค.
๋ถ๋ฅดํ ๋์ ์ง์
ํ ๋ค e๋ฅผ ๋๋ฌ์ค๋ค.
์ต์
ํธ์ง ํ์ด์ง๊ฐ ๋์ค๋ฉด ๋ฐ์ผ๋ก ์ญ ๋ด๋ฆฐ๋ค.
๋ฐ์ linux์ ์ธ์๋ฅผ ro๋ฅผ rw๋ก ๋ณ๊ฒฝํ๊ณ quite splash $vt_hadnoff๋ฅผ init=/bin/bash๋ก ๋ณ๊ฒฝํ๋ค.
์์ ํ ๋ค Crtl + X๋ฅผ ๋๋ฌ์ ์คํํ๋ค.
bash๋ก ์ ์ํ๋ฉด passwd ๋ช
๋ น์ด๋ฅผ ํตํด์ ๋น๋ฐ๋ฒํธ๋ฅผ ๋ณ๊ฒฝํด์ค๋ค.
passwd root
1234
1234
passwd alice
1234
1234
Bash
๋ณต์ฌ
๋ณํ ํ ๋ค reboot -f๋ฅผ ์
๋ ฅํด ์ฌ๋ถํ
ํ๋ค.
์ฌ๋ถํ
๋๋ฉด ๋น๋ฐ๋ฒํธ๋ฅผ ์
๋ ฅํ์ฌ ๋ก๊ทธ์ธํ๋ฉด ๋ฌธ์ ๋ฅผ ํ๊ธฐ์ํ 1์ฐจ์ ์ค๋น๋ ๋๋ฌ๋ค.
# ๋ฌธ์ ๋ถ์
ํด๋น ๋ฌธ์ ๋ฅผ ๋ถ์ํด๋ณธ nc๋ก ํน์ ๊ฐ์ ์๋ฒ์ ์ ์ํ์ฌ ์ง๋ฌธ์ ํด๋นํ๋ ๋ต์ VM์์ ๋ถ์ํด์ ๋ฃ์ผ๋ฉด๋๋ค.
Q1) ํ์ฑํ ๋ ํฌํธ
Q1) Which ports are open (Answer in ascending order of port numbers , separated by commas)?
Format: XX,..
Plain Text
๋ณต์ฌ
ํ์ธ์ ์ํด netstat๋ฅผ ์ค์นํด์ค๋ค.
Answer: 22, 80
Plain Text
๋ณต์ฌ
Q2) ์์ ์ด๋ฆ
Q2) ํด๋น ๋๋ฉ์ธ์ ํธ์คํ
๋ ์์ ์ ์ด๋ฆ์ ๋ฌด์์
๋๊น? (๊ณต๋ฐฑ์ผ๋ก ๊ตฌ๋ถ๋ ์นด๋ฉ ์ผ์ด์ค)
ํ์: Abcd Efgh Ijklmno
Plain Text
๋ณต์ฌ
http๋ก 80 port๊ฐ ์ด๋ ค์๋ ๊ฒ์ผ๋ก ๋ณด์ ์น ์๋ฒ๊ฐ ์ด๋ ค์๋ ๊ฑธ ๋ณผ ์ ์๋ค.
http://127.0.0.1๋ก ์ ์ํ๋ฉด ๋์จ๋ค.
Answer: Donut Heaven
Plain Text
๋ณต์ฌ
Q3) API ์ฃผ์
Q3) Which endpoint helped you find the user credentials?
Format: /path/to/the/endpoint
Plain Text
๋ณต์ฌ
์น ์๋ฒ์ API์์ผ๋ก /var/www๋ก ์ ๊ทผํ์ฌ tree ๋ช
๋ น์ด๋ฅผ ์
๋ ฅํ๋ค.
Answer : /cgi-bin/test.cgi
Plain Text
๋ณต์ฌ
Q4) CVE ๋ฒํธ
Q4) What vulnerability seems to affect the kernel of the target system? (Enter a CVE number,Bash version number) ?
Plain Text
๋ณต์ฌ
์ ์ฌ๊ธฐ์ ๋ถํฐ ์ถ์ธก์ ํ๋ฉด์ ๋ถ์์ ํด์ผํ๋ค.
kernel์ ์ํฅ์ ๋ฏธ์น๋ CVE๋ฅผ ์ ์ถํ๋ ๊ฒ + access.log์ error.log๊ฐ ์กด์ฌํ๋ ๊ฒ์ผ๋ก ๋ณด์ web server์ test.cgi์ ์ทจ์ฝ์ ์ exploitํ๋ค๊ณ ์๊ฐํ ์ ์๊ณ bash version number์ ๋ฃ์ด๋ผ๋ ๊ฒ์ ํตํด bash๊ฐ ์ทจ์ฝ์ ์ ์ํฅ์ ๋ฏธ์น๋ค๊ณ ๋ณผ ์ ์๋ค.
access.log
access.log ํ์ผ์์ test.cgi๋ฅผ ๊ฒ์ํ๋ฉด ์๋์ ๊ฐ์ด 68 line์์ ํน์ ์ ์คํฌ๋ฆฝํธ๋ฅผ ์คํํ ๊ฒ์ ๋ณผ ์ ์๋ค.
127.0.0.1 - - [20/Sep/2024:01:16:16 +0530] "GET /cgi-bin/test.cgi HTTP/1.1" 500 803 "-" "() { :; }; echo; echo; /bin/bash -c 'echo vulnerable'"
Plain Text
๋ณต์ฌ
ํด๋น ๊ณต๊ฒฉ๊ตฌ๋ฌธ์ ๋ณต์ฌํด์ ๊ทธ๋๋ก ๊ฒ์ํ๋ฉด Shellshock ์ทจ์ฝ์ ์์ ์ ์ ์๊ณ , CVE-2014-6271์์ ์ ์ ์๋ค.
์ด์ bash version์ ํ์ธํ๋ฉด 4.3.0์ด๋ค.
Answer : CVE-2014-6271,4.3.0
Plain Text
๋ณต์ฌ
Q5) ํธ์คํธ ์ด๋ฆ
Q5) What is the hostname of the target system ? (Complete domain name in lowercase)
Format: domain.name
Plain Text
๋ณต์ฌ
hostname ๋ช
๋ น์ด๋ฅผ ํตํด์ ํธ์คํธ ์ด๋ฆ์ ๊ฐ์ ธ์ต๋๋ค.
Answer : domain1.com
Plain Text
๋ณต์ฌ
Q6) alice ์ ์ ์ ๋ณด ๋ ธ์ถ ์์คํ ๋ช ๋ น์ด
Q6) Which system command exposes the credentials for alice user?
Format: command
Plain Text
๋ณต์ฌ
ํด๋น ๋ถ๋ถ์ ์ดํดํ๊ธฐ ์ํด์๋ ShellShock ์ทจ์ฝ์ ์ ๋จผ์ ์ดํดํด์ผํ๋ค. ์์ธํ ๋ด์ฉ์ ์๋ Reference ์ฐธ๊ณ
๊ฐ๋จํ๊ฒ ์ค๋ช
ํ๋ฉด ์๋์ ๊ฐ๋ค.
1.
cgi-bin์ ํตํด ์น ์๋ฒ๊ฐ Bash ๊ธฐ๋ฐ ์คํฌ๋ฆฝํธ ์คํ ํ client์ ์ ๋ฌ
2.
์กฐ์๋ ํ๊ฒฝ๋ณ์ ์ฝ์
์ ์๋ฒ๋ ํ๊ฒฝ ๋ณ์์ ์ ๋ฌ๋ ๋ช
๋ น์ด ์คํ
3.
์ธ์ฆ ์์ด ์๊ฒฉ์์ ์์ ๋ช
๋ น์ด ์คํ
์ด์ ๋ ์๋๋ฆฌ์ค๋ฅผ ๋จผ์ ์ธ์ฐ๊ณ ๋ถ์์ ์งํํด์ผํ๋ค.(์นจํด ๋ถ์์ ์ฒ์ํด๋ด์ ์๋๋ฆฌ์ค ๊ธฐ๋ฐ์ผ๋ก ์ ๊ทผ)
์ผ๋จ ์์ ํ๋ํ ๊ฒ์ ์๋ช
ํ๋ค. ๊ทธ๋ผ bash์ ์ ๊ทผํ๋ค๋ ๊ฒ์ด๊ณ .bash_history๋ฅผ ๋ณด์
๋์ถฉ ๊ณต๊ฒฉ์๊ฐ ์นจ์
ํ ๊ฒ ๊ฐ์ ์์ ๋ถํฐ ๋ณด๋ฉด env ๋ช
๋ น์ด๋ฅผ ๊ฐ์ฅ ๋จผ์ ์คํํ ๊ฒ์ ๋ณผ ์ ์๋ค.
cd /usr/lib/cgi-bin/
ls
./vuln.sh
./test.cgi
ls -al
env x='() { :;}; echo Oh No!' bash_shellshock -c "echo Testing!"
Plain Text
๋ณต์ฌ
ShellShock ์ทจ์ฝ์ ์ ํ๊ฒฝ ๋ณ์์ ๊ด๋ จ๋ ์ทจ์ฝ์ ์์ผ๋ก ๋ฃ์ด๋ณด๋ฉด ์ ๋ต์ด๋ค.
Answer : env
Plain Text
๋ณต์ฌ
Q7) Privilege Escalate Binary
Q7) Which binary had the SUID bit set that helped you escalate to root and under which directory ? ( Path to binary and directory separated by comma)
Format: /path/to/binary/with/suid,/directoryname
Plain Text
๋ณต์ฌ
๊ถํ ์์นํ Binary๋ฅผ ์ฐพ์๋ณด์ ์ฌ์ค ์ฌ๊ธฐ์ ์ ์ผ ๋ง์ด ์๊ฐ์ด ์์๋ ๊ฒ ๊ฐ๋ค.
์ผ๋จ ๊ถํ ์์น์ ํ๋ Binary ๋จผ์ ์ฐพ์๋ณด์
find / -perm -4000 -type f 2>/dev/null
Plain Text
๋ณต์ฌ
์ ๊ธฐ ์๋ ๋ชจ๋ binary์ ๋ํด์ ๋ถ์ํ์ง๋ง ์ผ๋จ ์ ๋ต๋ง ์์ฑํด๋ณธ๋คโฆ
์ผ๋จ .bash_history๋ก ๋์์์ ์ฌ์ฉํ command๋ฅผ ๋ถ์ํด๋ณด์
์ผ๋จ ํด์ปค ๊ด์ ์ผ๋ก ์๊ฐํด๋ดค์ ๋ bash โversion์ ํตํด์ version์ ํ์ธํ ๋ค์ ShellShock ์ทจ์ฝ์ ์ ์ด์ฉํ์ ๊ฒ์ด๋ค.
์ค์ ๋ก 245line์ ๋ณด๋ฉด version์ ํ์ธํ๋ค.
๋ค์์ผ๋ก vi๋ก /root/root.txt์ ์ ๊ทผํ๊ณ cat์ผ๋ก ์ฝ์ง๋ง ์ค์ ๋ก ๋ช
๋ น์ด๋ฅผ ์คํํด๋ณด๋ฉด vi๋ก๋ ์ ๊ทผ๋์ง๋ง cat์ผ๋ก๋ ์ฝ์ ์ ์๋ค.
์ ๋ฆฌํด๋ณด๋ฉด ์ฌ๋ณผ๋ฆญ ๋งํฌ๋ก vi๊ฐ vim.tiny์ ๊ฑธ๋ ค์๋๊ฑธ ๋ณผ ์ ์๊ณ vi๋ ๋ฃจํธ ๊ถํ์ ์์๋ฐ๋๋ค.
vi๋ฅผ ํตํด ์ ์ฐ๊ฐ ์ฐ๊นํด์ ๊ณต๊ฒฉ์ ๊ด์ ์์ ์์ ํ๋ํ๋ ์๋๋ฆฌ์ค๋ฅผ ์๊ฐํด๋ดค๋ค.
which vi
/usr/bin/vi
ls -al /usr/bin/vi
/usr/bin/vi -> /etc/alternatives/vi
ls -al /etc/alternatives/vi
/etc/alternatives/vi -> /usr/bin/vim.tiny
Plain Text
๋ณต์ฌ
.bash_history๋ฅผ ๋ค ๋ถ์ํ๋ฉด์ vi๋ฅผ ํตํด์ ๋ญ ์์ ํ๋์ง ๋ฐ๋ผ๊ฐ๋ณด๋ฉด
/etc/sudoers.d/newrules๋ฅผ ์ ๊ทผํ๋๋ฐ ํ์ผ๋ก ์กด์ฌํ์ง๋ ์๋๋ค.
๋ ๋ฐ์ผ๋ก ์ญ ๋ถ์ํด๊ฐ๋ฉด /etc/sudoers.d/alice์ ์ ๊ทผํ๋ค.
root passwd๋ฅผ 1234๋ก ๋ณ๊ฒฝํ๊ธฐ ๋๋ฌธ์ su๋ฅผ ํตํด์ root๋ก ๋ณ๊ฒฝํ ๋คcat /etc/sudoers.d/alice๋ก ํ์ผ์ ์ฝ์ด๋ณธ๋ค.
์ ๋ด์ฉ์ ํด์ํด๋ณด๋ฉด vi๋ฅผ ํตํด์ /tmp์์ ์คํํ๋ ํ์ผ์ root ๊ถํ์ ์์ํ๋ค๋ ๋ป์ด๋ค.
์ ๋ช
๋ น์ด๋ก root ๊ถํ ํ์ทจ๊ฐ ๊ฐ๋ฅํ๋ค.
sudo /usr/bin/vi /tmp/test -c '!sh'
Plain Text
๋ณต์ฌ
Answer : /usr/bin/vi,/tmp
Plain Text
๋ณต์ฌ
Q8) webserver name
Q8) Which webserver is running on port 80?
Format: Webservername
Plain Text
๋ณต์ฌ
curl์ ํตํด Server Header๋ฅผ ๋ณธ๋ค.
Answer : Apache2
Plain Text
๋ณต์ฌ
Q9) ํ์ผ ๋ด์ฉ
Q9) What are the contents of the file1.txt for alice ?
Format: contentofthefile
Plain Text
๋ณต์ฌ
file1.txt๋ง ์ฝ์ผ๋ฉด ๋๋ค.
Answer : ff3a265203a475f18d12baeab71b9a00
Plain Text
๋ณต์ฌ
Q10) ๋ฃจํธ ํ์ผ ๋ด์ฉ
Q10) What are the contents of the root flag file ?
Format: contentofthefile
Answer: $
Plain Text
๋ณต์ฌ
๋ค์ ๊ถํ ์์น ์ทจ์ฝ์ ์ ํตํด ์ฝ๋๋ค.
Answer: 172346606e1d24062e891d537e917a90
Plain Text
๋ณต์ฌ
# Payload
from pwn import *
p = remote("43.205.113.100", 8901)
p.sendline("22,80")
p.sendline("Donut Heaven")
p.sendline("/cgi-bin/test.cgi")
p.sendline("CVE-2014-6271,4.3.0")
p.sendline("domain1.com")
p.sendline("env")
p.sendline("/usr/bin/vi,/tmp")
p.sendline("Apache2")
p.sendline("ff3a265203a475f18d12baeab71b9a00")
p.sendline("172346606e1d24062e891d537e917a90")
p.interactive()
Python
๋ณต์ฌ
# Flag
ShaktiCTF{$H0CK!ng_8uT_YoU_H4CK3D_7h3_boXx!!}
Plain Text
๋ณต์ฌ





































