๋ฐฐ์—ด ์ธ๋ฑ์‹ฑ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๊ธฐ๋ณธ ์ •๋ณด

์ด ์นดํ…Œ๊ณ ๋ฆฌ๋Š” ๋ฐฐ์—ด์˜ ์ธ๋ฑ์Šค ์ฒ˜๋ฆฌ ์˜ค๋ฅ˜๋กœ ์ธํ•ด ํŠน์ • ๋ฐ์ดํ„ฐ๋ฅผ ๋ฎ์–ด์“ธ ์ˆ˜ ์žˆ๋Š” ๋ชจ๋“  ์ทจ์•ฝ์ ์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” ์ทจ์•ฝ์ ์˜ ์กฐ๊ฑด์— ์™„์ „ํžˆ ์˜์กดํ•˜๊ธฐ ๋•Œ๋ฌธ์— ํŠน์ • ๋ฐฉ๋ฒ•๋ก ์ด ์—†๋Š” ๋งค์šฐ ๋„“์€ ์นดํ…Œ๊ณ ๋ฆฌ์ž…๋‹ˆ๋‹ค.

ํ•˜์ง€๋งŒ ์—ฌ๊ธฐ์—์„œ ๋ช‡ ๊ฐ€์ง€ ๋ฉ‹์ง„ ์˜ˆ์ œ๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

  • https://guyinatuxedo.github.io/11-index/swampctf19_dreamheaps/index.html
  • ์ฃผ์†Œ์— ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๋Š” ๋ฐฐ์—ด๊ณผ ๊ทธ ๋ฐ์ดํ„ฐ์˜ ํฌ๊ธฐ๋ฅผ ๊ฐ€์ง„ ๋ฐฐ์—ด์ด 2๊ฐœ ์ถฉ๋Œํ•ฉ๋‹ˆ๋‹ค. ํ•˜๋‚˜์—์„œ ๋‹ค๋ฅธ ๊ฒƒ์œผ๋กœ ๋ฎ์–ด์“ธ ์ˆ˜ ์žˆ์–ด ์ž„์˜์˜ ์ฃผ์†Œ๋ฅผ ํฌ๊ธฐ๋กœ ์ง€์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด GOT ํ…Œ์ด๋ธ”์—์„œ free ํ•จ์ˆ˜์˜ ์ฃผ์†Œ๋ฅผ ์“ฐ๊ณ , ์ด๋ฅผ system์˜ ์ฃผ์†Œ๋กœ ๋ฎ์–ด์“ด ๋‹ค์Œ /bin/sh๋กœ ๋ฉ”๋ชจ๋ฆฌ์—์„œ free๋ฅผ ํ˜ธ์ถœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • https://guyinatuxedo.github.io/11-index/csaw18_doubletrouble/index.html
  • 64๋น„ํŠธ, nx ์—†์Œ. ํฌ๊ธฐ๋ฅผ ๋ฎ์–ด์จ์„œ ๋ชจ๋“  ๊ฒƒ์ด ๋‘ ๋ฐฐ์˜ ์ˆซ์ž๋กœ ์‚ฌ์šฉ๋˜๊ณ  ๊ฐ€์žฅ ์ž‘์€ ๊ฒƒ๋ถ€ํ„ฐ ๊ฐ€์žฅ ํฐ ๊ฒƒ๊นŒ์ง€ ์ •๋ ฌ๋˜๋Š” ์ผ์ข…์˜ ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ์šฐ๋ฅผ ๋ฐœ์ƒ์‹œํ‚ต๋‹ˆ๋‹ค. ๋”ฐ๋ผ์„œ ๊ทธ ์š”๊ตฌ ์‚ฌํ•ญ์„ ์ถฉ์กฑํ•˜๋Š” ์‰˜์ฝ”๋“œ๋ฅผ ์ƒ์„ฑํ•ด์•ผ ํ•˜๋ฉฐ, ์นด๋‚˜๋ฆฌ๊ฐ€ ์ž์‹ ์˜ ์œ„์น˜์—์„œ ์ด๋™ํ•˜์ง€ ์•Š์•„์•ผ ํ•˜๊ณ , ๋งˆ์ง€๋ง‰์œผ๋กœ RIP๋ฅผ ret ์ฃผ์†Œ๋กœ ๋ฎ์–ด์จ์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” ์ด์ „ ์š”๊ตฌ ์‚ฌํ•ญ์„ ์ถฉ์กฑํ•˜๊ณ  ๊ฐ€์žฅ ํฐ ์ฃผ์†Œ๋ฅผ ์Šคํƒ์˜ ์‹œ์ž‘์„ ๊ฐ€๋ฆฌํ‚ค๋Š” ์ƒˆ๋กœ์šด ์ฃผ์†Œ๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค(ํ”„๋กœ๊ทธ๋žจ์— ์˜ํ•ด ์œ ์ถœ๋จ) ๊ทธ๋ž˜์„œ ret๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ทธ๊ณณ์œผ๋กœ ์ ํ”„ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • https://faraz.faith/2019-10-20-secconctf-2019-sum/
  • 64๋น„ํŠธ, relro ์—†์Œ, ์นด๋‚˜๋ฆฌ, nx, pie ์—†์Œ. ์Šคํƒ์˜ ๋ฐฐ์—ด์—์„œ ์˜คํ”„ ๋ฐ”์ด ์›์ด ์žˆ์–ด ํฌ์ธํ„ฐ๋ฅผ ์ œ์–ดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. WWW๋ฅผ ๋ถ€์—ฌํ•ฉ๋‹ˆ๋‹ค(๋ฐฐ์—ด์˜ ๋ชจ๋“  ์ˆซ์ž์˜ ํ•ฉ์„ ์˜คํ”„ ๋ฐ”์ด ์›์œผ๋กœ ๋ฎ์–ด์“ด ์ฃผ์†Œ์— ์”๋‹ˆ๋‹ค). ์Šคํƒ์ด ์ œ์–ด๋˜๋ฏ€๋กœ GOT์˜ exit ์ฃผ์†Œ๊ฐ€ pop rdi; ret๋กœ ๋ฎ์–ด์“ฐ์—ฌ์ง€๊ณ , ์Šคํƒ์— main์˜ ์ฃผ์†Œ๊ฐ€ ์ถ”๊ฐ€๋ฉ๋‹ˆ๋‹ค(๋‹ค์‹œ main์œผ๋กœ ๋ฃจํ”„). ๊ทธ๋Ÿฐ ๋‹ค์Œ puts๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ GOT์— ์žˆ๋Š” put์˜ ์ฃผ์†Œ๋ฅผ ์œ ์ถœํ•˜๋Š” ROP ์ฒด์ธ์ด ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค(exit๊ฐ€ ํ˜ธ์ถœ๋˜๋ฏ€๋กœ pop rdi; ret๊ฐ€ ํ˜ธ์ถœ๋˜์–ด ์Šคํƒ์—์„œ ์ด ์ฒด์ธ์ด ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค). ๋งˆ์ง€๋ง‰์œผ๋กœ ret2lib๋ฅผ ์‹คํ–‰ํ•˜๋Š” ์ƒˆ๋กœ์šด ROP ์ฒด์ธ์ด ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.
  • https://guyinatuxedo.github.io/14-ret_2_system/tu_guestbook/index.html
  • 32๋น„ํŠธ, relro ์—†์Œ, ์นด๋‚˜๋ฆฌ ์—†์Œ, nx, pie ์—†์Œ. ์ž˜๋ชป๋œ ์ธ๋ฑ์‹ฑ์„ ์•…์šฉํ•˜์—ฌ ์Šคํƒ์—์„œ libc์™€ ํž™์˜ ์ฃผ์†Œ๋ฅผ ์œ ์ถœํ•ฉ๋‹ˆ๋‹ค. ๋ฒ„ํผ ์˜ค๋ฒ„ํ”Œ๋กœ์šฐ๋ฅผ ์•…์šฉํ•˜์—ฌ system('/bin/sh')๋ฅผ ํ˜ธ์ถœํ•˜๋Š” ret2lib๋ฅผ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค(์ฒดํฌ๋ฅผ ์šฐํšŒํ•˜๊ธฐ ์œ„ํ•ด ํž™ ์ฃผ์†Œ๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค).

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ