113 - Pentesting Ident

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

Basic Information

Ident Protocol๋Š” ์ธํ„ฐ๋„ท์„ ํ†ตํ•ด TCP ์—ฐ๊ฒฐ์„ ํŠน์ • ์‚ฌ์šฉ์ž์™€ ์—ฐ๊ฒฐํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. ์›๋ž˜๋Š” ๋„คํŠธ์›Œํฌ ๊ด€๋ฆฌ ๋ฐ ๋ณด์•ˆ์„ ๋•๊ธฐ ์œ„ํ•ด ์„ค๊ณ„๋˜์—ˆ์œผ๋ฉฐ, ์„œ๋ฒ„๊ฐ€ ํฌํŠธ 113์—์„œ ํด๋ผ์ด์–ธํŠธ์—๊ฒŒ ์ฟผ๋ฆฌํ•˜์—ฌ ํŠน์ • TCP ์—ฐ๊ฒฐ์˜ ์‚ฌ์šฉ์ž์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์š”์ฒญํ•  ์ˆ˜ ์žˆ๋„๋ก ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค.

๊ทธ๋Ÿฌ๋‚˜ ํ˜„๋Œ€์˜ ๊ฐœ์ธ ์ •๋ณด ๋ณดํ˜ธ ๋ฌธ์ œ์™€ ์˜ค์šฉ ๊ฐ€๋Šฅ์„ฑ์œผ๋กœ ์ธํ•ด ์‚ฌ์šฉ์ด ๊ฐ์†Œํ•˜์˜€์œผ๋ฉฐ, ์ด๋Š” ๋ฌด์‹ฌ์ฝ” ์‚ฌ์šฉ์ž ์ •๋ณด๋ฅผ ๋ฌด๋‹จ ๋‹น์‚ฌ์ž์—๊ฒŒ ๋…ธ์ถœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์œ„ํ—˜์„ ์™„ํ™”ํ•˜๊ธฐ ์œ„ํ•ด ์•”ํ˜ธํ™”๋œ ์—ฐ๊ฒฐ ๋ฐ ์—„๊ฒฉํ•œ ์ ‘๊ทผ ์ œ์–ด์™€ ๊ฐ™์€ ๊ฐ•ํ™”๋œ ๋ณด์•ˆ ์กฐ์น˜๋ฅผ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค.

๊ธฐ๋ณธ ํฌํŠธ: 113

PORT    STATE SERVICE
113/tcp open  ident

Enumeration

Manual - Get user/Identify the service

๋งŒ์•ฝ ๋จธ์‹ ์ด ident์™€ samba (445) ์„œ๋น„์Šค๋ฅผ ์‹คํ–‰ ์ค‘์ด๊ณ , ํฌํŠธ 43218์„ ์‚ฌ์šฉํ•˜์—ฌ samba์— ์—ฐ๊ฒฐ๋˜์–ด ์žˆ๋‹ค๋ฉด, samba ์„œ๋น„์Šค๋ฅผ ์‹คํ–‰ ์ค‘์ธ ์‚ฌ์šฉ์ž๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

์„œ๋น„์Šค์— ์—ฐ๊ฒฐํ•  ๋•Œ ๊ทธ๋ƒฅ Enter๋ฅผ ๋ˆ„๋ฅด๋ฉด:

๋‹ค๋ฅธ ์˜ค๋ฅ˜๋“ค:

Nmap

๊ธฐ๋ณธ์ ์œผ๋กœ (`-sC``) nmap์€ ์‹คํ–‰ ์ค‘์ธ ๋ชจ๋“  ํฌํŠธ์˜ ๋ชจ๋“  ์‚ฌ์šฉ์ž๋ฅผ ์‹๋ณ„ํ•ฉ๋‹ˆ๋‹ค:

PORT    STATE SERVICE     VERSION
22/tcp  open  ssh         OpenSSH 4.3p2 Debian 9 (protocol 2.0)
|_auth-owners: root
| ssh-hostkey:
|   1024 88:23:98:0d:9d:8a:20:59:35:b8:14:12:14:d5:d0:44 (DSA)
|_  2048 6b:5d:04:71:76:78:56:96:56:92:a8:02:30:73:ee:fa (RSA)
113/tcp open  ident
|_auth-owners: identd
139/tcp open  netbios-ssn Samba smbd 3.X - 4.X (workgroup: LOCAL)
|_auth-owners: root
445/tcp open  netbios-ssn Samba smbd 3.0.24 (workgroup: LOCAL)
|_auth-owners: root

Ident-user-enum

Ident-user-enum์€ ๋Œ€์ƒ ์‹œ์Šคํ…œ์˜ ๊ฐ TCP ํฌํŠธ์—์„œ ์ˆ˜์‹  ๋Œ€๊ธฐ ์ค‘์ธ ํ”„๋กœ์„ธ์Šค์˜ ์†Œ์œ ์ž๋ฅผ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด ident ์„œ๋น„์Šค(113/TCP)๋ฅผ ์ฟผ๋ฆฌํ•˜๋Š” ๊ฐ„๋‹จํ•œ PERL ์Šคํฌ๋ฆฝํŠธ์ž…๋‹ˆ๋‹ค. ์ˆ˜์ง‘๋œ ์‚ฌ์šฉ์ž ์ด๋ฆ„ ๋ชฉ๋ก์€ ๋‹ค๋ฅธ ๋„คํŠธ์›Œํฌ ์„œ๋น„์Šค์— ๋Œ€ํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ ์ถ”์ธก ๊ณต๊ฒฉ์— ์‚ฌ์šฉ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. apt install ident-user-enum์œผ๋กœ ์„ค์น˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

root@kali:/opt/local/recon/192.168.1.100# ident-user-enum 192.168.1.100 22 113 139 445
ident-user-enum v1.0 ( http://pentestmonkey.net/tools/ident-user-enum )

192.168.1.100:22  root
192.168.1.100:113 identd
192.168.1.100:139 root
192.168.1.100:445 root

Shodan

  • oident

Files

identd.conf

HackTricks Automatic Commands

Protocol_Name: Ident    #Protocol Abbreviation if there is one.
Port_Number:  113     #Comma separated if there is more than one.
Protocol_Description: Identification Protocol         #Protocol Abbreviation Spelled out

Entry_1:
Name: Notes
Description: Notes for Ident
Note: |
The Ident Protocol is used over the Internet to associate a TCP connection with a specific user. Originally designed to aid in network management and security, it operates by allowing a server to query a client on port 113 to request information about the user of a particular TCP connection.

https://book.hacktricks.wiki/en/network-services-pentesting/113-pentesting-ident.html

Entry_2:
Name: Enum Users
Description: Enumerate Users
Note: apt install ident-user-enum    ident-user-enum {IP} 22 23 139 445 (try all open ports)

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ