Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๊ธฐ๋ณธ ์ •๋ณด

From Wikipedia:

Squid๋Š” ์บ์‹ฑ ๋ฐ ํฌ์›Œ๋”ฉ HTTP ์›น ํ”„๋ก์‹œ์ž…๋‹ˆ๋‹ค. ๋ฐ˜๋ณต ์š”์ฒญ์„ ์บ์‹ฑํ•˜์—ฌ ์›น ์„œ๋ฒ„์˜ ์†๋„๋ฅผ ๋†’์ด๊ณ , ๋„คํŠธ์›Œํฌ ๋ฆฌ์†Œ์Šค๋ฅผ ๊ณต์œ ํ•˜๋Š” ์‚ฌ๋žŒ๋“ค ๊ทธ๋ฃน์„ ์œ„ํ•œ ์›น, DNS ๋ฐ ๊ธฐํƒ€ ์ปดํ“จํ„ฐ ๋„คํŠธ์›Œํฌ ์กฐํšŒ๋ฅผ ์บ์‹ฑํ•˜๋ฉฐ, ํŠธ๋ž˜ํ”ฝ ํ•„ํ„ฐ๋ง์„ ํ†ตํ•ด ๋ณด์•ˆ์„ ์ง€์›ํ•˜๋Š” ๋“ฑ ๋‹ค์–‘ํ•œ ์šฉ๋„๋กœ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. ์ฃผ๋กœ HTTP์™€ FTP์— ์‚ฌ์šฉ๋˜์ง€๋งŒ, Squid๋Š” Internet Gopher, SSL, TLS ๋ฐ HTTPS๋ฅผ ํฌํ•จํ•œ ์—ฌ๋Ÿฌ ๋‹ค๋ฅธ ํ”„๋กœํ† ์ฝœ์— ๋Œ€ํ•œ ์ œํ•œ๋œ ์ง€์›์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค. Squid๋Š” Privoxy์™€ ๋‹ฌ๋ฆฌ SOCKS ํ”„๋กœํ† ์ฝœ์„ ์ง€์›ํ•˜์ง€ ์•Š์œผ๋ฉฐ, SOCKS ์ง€์›์„ ์ œ๊ณตํ•˜๊ธฐ ์œ„ํ•ด Squid์™€ ํ•จ๊ป˜ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ธฐ๋ณธ ํฌํŠธ: 3128

PORT     STATE  SERVICE      VERSION
3128/tcp open   http-proxy   Squid http proxy 4.11

์—ด๊ฑฐ

์›น ํ”„๋ก์‹œ

๋ฐœ๊ฒฌ๋œ ์ด ์„œ๋น„์Šค๋ฅผ ๋ธŒ๋ผ์šฐ์ €์—์„œ ํ”„๋ก์‹œ๋กœ ์„ค์ •ํ•ด ๋ณผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ HTTP ์ธ์ฆ์œผ๋กœ ๊ตฌ์„ฑ๋œ ๊ฒฝ์šฐ ์‚ฌ์šฉ์ž ์ด๋ฆ„๊ณผ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•˜๋ผ๋Š” ๋ฉ”์‹œ์ง€๊ฐ€ ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค.

# Try to proxify curl
curl --proxy http://10.10.11.131:3128 http://10.10.11.131

Nmap proxified

ํ”„๋ก์‹œ๋ฅผ ์•…์šฉํ•˜์—ฌ nmap์œผ๋กœ ๋‚ด๋ถ€ ํฌํŠธ๋ฅผ ์Šค์บ”ํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค.
proxychains๋ฅผ ๊ตฌ์„ฑํ•˜์—ฌ squid ํ”„๋ก์‹œ๋ฅผ ์‚ฌ์šฉํ•˜๋„๋ก ํ•˜๋ ค๋ฉด proxichains.conf ํŒŒ์ผ์˜ ๋์— ๋‹ค์Œ ์ค„์„ ์ถ”๊ฐ€ํ•˜์„ธ์š”: http 10.10.10.10 3128
์ธ์ฆ์ด ํ•„์š”ํ•œ ํ”„๋ก์‹œ์˜ ๊ฒฝ์šฐ, ์‚ฌ์šฉ์ž ์ด๋ฆ„๊ณผ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ๋์— ํฌํ•จ์‹œ์ผœ ์ž๊ฒฉ ์ฆ๋ช…์„ ๊ตฌ์„ฑ์— ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค: http 10.10.10.10 3128 username passw0rd.

๊ทธ๋Ÿฐ ๋‹ค์Œ proxychains๋กœ nmap์„ ์‹คํ–‰ํ•˜์—ฌ ๋กœ์ปฌ์—์„œ ํ˜ธ์ŠคํŠธ๋ฅผ ์Šค์บ”ํ•ฉ๋‹ˆ๋‹ค: proxychains nmap -sT -n -p- localhost

SPOSE Scanner

๋Œ€์•ˆ์œผ๋กœ, Squid Pivoting Open Port Scanner (spose.py)๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

python spose.py --proxy http://10.10.11.131:3128 --target 10.10.11.131

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ