iOS Burp Suite ๊ตฌ์„ฑ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

iOS ๊ธฐ๊ธฐ์— Burp ์ธ์ฆ์„œ ์„ค์น˜ํ•˜๊ธฐ

์•ˆ์ „ํ•œ ์›น ํŠธ๋ž˜ํ”ฝ ๋ถ„์„ ๋ฐ iOS ๊ธฐ๊ธฐ์—์„œ SSL ํ•€๋‹์„ ์œ„ํ•ด Burp Suite๋Š” Burp Mobile Assistant๋ฅผ ํ†ตํ•ด ๋˜๋Š” ์ˆ˜๋™ ๊ตฌ์„ฑ์œผ๋กœ ํ™œ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์•„๋ž˜๋Š” ๋‘ ๋ฐฉ๋ฒ•์— ๋Œ€ํ•œ ์š”์•ฝ ๊ฐ€์ด๋“œ์ž…๋‹ˆ๋‹ค:

Burp Mobile Assistant๋ฅผ ํ†ตํ•œ ์ž๋™ ์„ค์น˜

Burp Mobile Assistant๋Š” Burp ์ธ์ฆ์„œ, ํ”„๋ก์‹œ ๊ตฌ์„ฑ ๋ฐ SSL ํ•€๋‹ ์„ค์น˜ ๊ณผ์ •์„ ๊ฐ„์†Œํ™”ํ•ฉ๋‹ˆ๋‹ค. ์ž์„ธํ•œ ์•ˆ๋‚ด๋Š” PortSwigger์˜ ๊ณต์‹ ๋ฌธ์„œ์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ˆ˜๋™ ์„ค์น˜ ๋‹จ๊ณ„

  1. ํ”„๋ก์‹œ ๊ตฌ์„ฑ: iPhone์˜ Wi-Fi ์„ค์ •์—์„œ Burp๋ฅผ ํ”„๋ก์‹œ๋กœ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค.
  2. ์ธ์ฆ์„œ ๋‹ค์šด๋กœ๋“œ: ๊ธฐ๊ธฐ์˜ ๋ธŒ๋ผ์šฐ์ €์—์„œ http://burp๋กœ ์ด๋™ํ•˜์—ฌ ์ธ์ฆ์„œ๋ฅผ ๋‹ค์šด๋กœ๋“œํ•ฉ๋‹ˆ๋‹ค.
  3. ์ธ์ฆ์„œ ์„ค์น˜: ๋‹ค์šด๋กœ๋“œํ•œ ํ”„๋กœํ•„์„ ์„ค์ • > ์ผ๋ฐ˜ > VPN ๋ฐ ๊ธฐ๊ธฐ ๊ด€๋ฆฌ๋ฅผ ํ†ตํ•ด ์„ค์น˜ํ•œ ํ›„, ์ธ์ฆ์„œ ์‹ ๋ขฐ ์„ค์ •์—์„œ PortSwigger CA์— ๋Œ€ํ•œ ์‹ ๋ขฐ๋ฅผ ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค.

์ธํ„ฐ์…‰์…˜ ํ”„๋ก์‹œ ๊ตฌ์„ฑ

์ด ์„ค์ •์€ Burp๋ฅผ ํ†ตํ•ด iOS ๊ธฐ๊ธฐ์™€ ์ธํ„ฐ๋„ท ๊ฐ„์˜ ํŠธ๋ž˜ํ”ฝ ๋ถ„์„์„ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•˜๋ฉฐ, ํด๋ผ์ด์–ธํŠธ ๊ฐ„ ํŠธ๋ž˜ํ”ฝ์„ ์ง€์›ํ•˜๋Š” Wi-Fi ๋„คํŠธ์›Œํฌ๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ์‚ฌ์šฉ ๋ถˆ๊ฐ€๋Šฅํ•  ๊ฒฝ์šฐ, usbmuxd๋ฅผ ํ†ตํ•œ USB ์—ฐ๊ฒฐ์ด ๋Œ€์•ˆ์ด ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. PortSwigger์˜ ํŠœํ† ๋ฆฌ์–ผ์€ ๊ธฐ๊ธฐ ๊ตฌ์„ฑ ๋ฐ ์ธ์ฆ์„œ ์„ค์น˜์— ๋Œ€ํ•œ ์‹ฌ์ธต ์ง€์นจ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

ํƒˆ์˜ฅ ๊ธฐ๊ธฐ๋ฅผ ์œ„ํ•œ ๊ณ ๊ธ‰ ๊ตฌ์„ฑ

ํƒˆ์˜ฅ๋œ ๊ธฐ๊ธฐ๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒฝ์šฐ, USB๋ฅผ ํ†ตํ•œ SSH( iproxy ์‚ฌ์šฉ)๋Š” ํŠธ๋ž˜ํ”ฝ์„ Burp๋ฅผ ํ†ตํ•ด ์ง์ ‘ ๋ผ์šฐํŒ…ํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค:

  1. SSH ์—ฐ๊ฒฐ ์„ค์ •: iproxy๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ SSH๋ฅผ ๋กœ์ปฌํ˜ธ์ŠคํŠธ๋กœ ํฌ์›Œ๋”ฉํ•˜์—ฌ iOS ๊ธฐ๊ธฐ๊ฐ€ Burp๋ฅผ ์‹คํ–‰ํ•˜๋Š” ์ปดํ“จํ„ฐ์— ์—ฐ๊ฒฐํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ฉ๋‹ˆ๋‹ค.
iproxy 2222 22
  1. ์›๊ฒฉ ํฌํŠธ ํฌ์›Œ๋”ฉ: iOS ๊ธฐ๊ธฐ์˜ ํฌํŠธ 8080์„ ์ปดํ“จํ„ฐ์˜ ๋กœ์ปฌํ˜ธ์ŠคํŠธ๋กœ ํฌ์›Œ๋”ฉํ•˜์—ฌ Burp์˜ ์ธํ„ฐํŽ˜์ด์Šค์— ์ง์ ‘ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ฉ๋‹ˆ๋‹ค.
ssh -R 8080:localhost:8080 root@localhost -p 2222
  1. ์ „์—ญ ํ”„๋ก์‹œ ์„ค์ •: ๋งˆ์ง€๋ง‰์œผ๋กœ, iOS ๊ธฐ๊ธฐ์˜ Wi-Fi ์„ค์ •์„ ์ˆ˜๋™ ํ”„๋ก์‹œ๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ๊ตฌ์„ฑํ•˜์—ฌ ๋ชจ๋“  ์›น ํŠธ๋ž˜ํ”ฝ์ด Burp๋ฅผ ํ†ตํ•ด ํ๋ฅด๋„๋ก ํ•ฉ๋‹ˆ๋‹ค.

์ „์ฒด ๋„คํŠธ์›Œํฌ ๋ชจ๋‹ˆํ„ฐ๋ง/์Šค๋‹ˆํ•‘

๋น„HTTP ๊ธฐ๊ธฐ ํŠธ๋ž˜ํ”ฝ ๋ชจ๋‹ˆํ„ฐ๋ง์€ Wireshark๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํšจ์œจ์ ์œผ๋กœ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์ด ๋„๊ตฌ๋Š” ๋ชจ๋“  ํ˜•ํƒœ์˜ ๋ฐ์ดํ„ฐ ํŠธ๋ž˜ํ”ฝ์„ ์บก์ฒ˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. iOS ๊ธฐ๊ธฐ์˜ ๊ฒฝ์šฐ, ์›๊ฒฉ ๊ฐ€์ƒ ์ธํ„ฐํŽ˜์ด์Šค ์ƒ์„ฑ์„ ํ†ตํ•ด ์‹ค์‹œ๊ฐ„ ํŠธ๋ž˜ํ”ฝ ๋ชจ๋‹ˆํ„ฐ๋ง์ด ๊ฐ€๋Šฅํ•˜๋ฉฐ, ์ด ๊ณผ์ •์€ ์ด Stack Overflow ๊ฒŒ์‹œ๋ฌผ์—์„œ ์ž์„ธํžˆ ์„ค๋ช…๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ์‹œ์ž‘ํ•˜๊ธฐ ์ „์— macOS ์‹œ์Šคํ…œ์— Wireshark๋ฅผ ์„ค์น˜ํ•˜๋Š” ๊ฒƒ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค.

์ด ์ ˆ์ฐจ๋Š” ์—ฌ๋Ÿฌ ์ฃผ์š” ๋‹จ๊ณ„๋ฅผ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค:

  1. USB๋ฅผ ํ†ตํ•ด iOS ๊ธฐ๊ธฐ์™€ macOS ํ˜ธ์ŠคํŠธ ๊ฐ„์˜ ์—ฐ๊ฒฐ์„ ์‹œ์ž‘ํ•ฉ๋‹ˆ๋‹ค.
  2. ํŠธ๋ž˜ํ”ฝ ๋ชจ๋‹ˆํ„ฐ๋ง์— ํ•„์š”ํ•œ iOS ๊ธฐ๊ธฐ์˜ UDID๋ฅผ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” macOS ํ„ฐ๋ฏธ๋„์—์„œ ๋ช…๋ น์„ ์‹คํ–‰ํ•˜์—ฌ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:
$ rvictl -s <UDID>
Starting device <UDID> [SUCCEEDED] with interface rvi0
  1. UDID ์‹๋ณ„ ํ›„, Wireshark๋ฅผ ์—ด๊ณ  ๋ฐ์ดํ„ฐ ์บก์ฒ˜๋ฅผ ์œ„ํ•ด โ€œrvi0โ€ ์ธํ„ฐํŽ˜์ด์Šค๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  2. ํŠน์ • IP ์ฃผ์†Œ์™€ ๊ด€๋ จ๋œ HTTP ํŠธ๋ž˜ํ”ฝ ์บก์ฒ˜์™€ ๊ฐ™์€ ๋ชฉํ‘œ ๋ชจ๋‹ˆํ„ฐ๋ง์„ ์œ„ํ•ด Wireshark์˜ ์บก์ฒ˜ ํ•„ํ„ฐ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

์‹œ๋ฎฌ๋ ˆ์ดํ„ฐ์—์„œ Burp Cert ์„ค์น˜

  • Burp ์ธ์ฆ์„œ ๋‚ด๋ณด๋‚ด๊ธฐ

Proxy โ€“> Options โ€“> Export CA certificate โ€“> Certificate in DER format

  • ์ธ์ฆ์„œ๋ฅผ ์—๋ฎฌ๋ ˆ์ดํ„ฐ ์•ˆ์œผ๋กœ ๋“œ๋ž˜๊ทธ ์•ค ๋“œ๋กญํ•ฉ๋‹ˆ๋‹ค.
  • ์—๋ฎฌ๋ ˆ์ดํ„ฐ ์•ˆ์—์„œ Settings โ€“> General โ€“> Profile โ€“> _PortSwigger CA_๋กœ ๊ฐ€์„œ ์ธ์ฆ์„œ๋ฅผ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • ์—๋ฎฌ๋ ˆ์ดํ„ฐ ์•ˆ์—์„œ Settings โ€“> General โ€“> About โ€“> _Certificate Trust Settings_๋กœ ๊ฐ€์„œ PortSwigger CA๋ฅผ ํ™œ์„ฑํ™”ํ•ฉ๋‹ˆ๋‹ค.

์ถ•ํ•˜ํ•ฉ๋‹ˆ๋‹ค, iOS ์‹œ๋ฎฌ๋ ˆ์ดํ„ฐ์—์„œ Burp CA ์ธ์ฆ์„œ๋ฅผ ์„ฑ๊ณต์ ์œผ๋กœ ๊ตฌ์„ฑํ–ˆ์Šต๋‹ˆ๋‹ค.

Note

iOS ์‹œ๋ฎฌ๋ ˆ์ดํ„ฐ๋Š” MacOS์˜ ํ”„๋ก์‹œ ๊ตฌ์„ฑ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

MacOS ํ”„๋ก์‹œ ๊ตฌ์„ฑ

Burp๋ฅผ ํ”„๋ก์‹œ๋กœ ๊ตฌ์„ฑํ•˜๋Š” ๋‹จ๊ณ„:

  • System Preferences โ€“> Network โ€“> _Advanced_๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  • Proxies ํƒญ์—์„œ Web Proxy (HTTP) ๋ฐ _Secure Web Proxy (HTTPS)_๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  • ๋‘ ์˜ต์…˜ ๋ชจ๋‘ _127.0.0.1:8080_์œผ๋กœ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค.

  • _Ok_๋ฅผ ํด๋ฆญํ•œ ํ›„ _Apply_๋ฅผ ํด๋ฆญํ•ฉ๋‹ˆ๋‹ค.

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ