3702/UDP - Pentesting WS-Discovery

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๊ธฐ๋ณธ ์ •๋ณด

**Web Services Dynamic Discovery Protocol (WS-Discovery)**๋Š” ๋ฉ€ํ‹ฐ์บ์ŠคํŠธ๋ฅผ ํ†ตํ•ด ๋กœ์ปฌ ๋„คํŠธ์›Œํฌ ๋‚ด์—์„œ ์„œ๋น„์Šค ๋ฐœ๊ฒฌ์„ ์œ„ํ•ด ์„ค๊ณ„๋œ ํ”„๋กœํ† ์ฝœ๋กœ ์‹๋ณ„๋ฉ๋‹ˆ๋‹ค. ์ด๋Š” Target Services์™€ Clients ๊ฐ„์˜ ์ƒํ˜ธ์ž‘์šฉ์„ ์ด‰์ง„ํ•ฉ๋‹ˆ๋‹ค. Target Services๋Š” ๋ฐœ๊ฒฌ ๊ฐ€๋Šฅํ•œ ์—”๋“œํฌ์ธํŠธ์ด๋ฉฐ, Clients๋Š” ์ด๋Ÿฌํ•œ ์„œ๋น„์Šค๋ฅผ ์ ๊ทน์ ์œผ๋กœ ๊ฒ€์ƒ‰ํ•˜๋Š” ์ฃผ์ฒด์ž…๋‹ˆ๋‹ค. ํ†ต์‹ ์€ ๋ฉ€ํ‹ฐ์บ์ŠคํŠธ ์ฃผ์†Œ 239.255.255.250์™€ UDP ํฌํŠธ 3702๋กœ ์ „์†ก๋˜๋Š” SOAP ์ฟผ๋ฆฌ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„ค์ •๋ฉ๋‹ˆ๋‹ค.

๋„คํŠธ์›Œํฌ์— ์ฐธ์—ฌํ•˜๋ฉด Target Service๋Š” multicast Hello๋ฅผ ๋ฐฉ์†กํ•˜์—ฌ ์ž์‹ ์˜ ์กด์žฌ๋ฅผ ์•Œ๋ฆฝ๋‹ˆ๋‹ค. ์ด๋Š” ์„œ๋น„์Šค ์œ ํ˜•์— ๋”ฐ๋ผ Clients๋กœ๋ถ€ํ„ฐ multicast Probes๋ฅผ ์ˆ˜์‹ ํ•  ์ค€๋น„๊ฐ€ ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ์„œ๋น„์Šค ์œ ํ˜•์€ ์—”๋“œํฌ์ธํŠธ์— ๊ณ ์œ ํ•œ ์‹๋ณ„์ž์ž…๋‹ˆ๋‹ค(์˜ˆ: IP ์นด๋ฉ”๋ผ์˜ ๊ฒฝ์šฐ NetworkVideoTransmitter). ์ผ์น˜ํ•˜๋Š” Probe์— ์‘๋‹ตํ•˜์—ฌ Target Service๋Š” unicast Probe Match๋ฅผ ๋ณด๋‚ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์œ ์‚ฌํ•˜๊ฒŒ, Target Service๋Š” ์ด๋ฆ„์œผ๋กœ ์„œ๋น„์Šค๋ฅผ ์‹๋ณ„ํ•˜๊ธฐ ์œ„ํ•œ multicast Resolve๋ฅผ ์ˆ˜์‹ ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ๋งŒ์•ฝ ๊ทธ๊ฒƒ์ด ์˜๋„๋œ ๋Œ€์ƒ์ด๋ผ๋ฉด unicast Resolve Match๋กœ ์‘๋‹ตํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋„คํŠธ์›Œํฌ๋ฅผ ๋– ๋‚  ๊ฒฝ์šฐ, Target Service๋Š” ์ž์‹ ์˜ ํ‡ด์žฅ์„ ์•Œ๋ฆฌ๊ธฐ ์œ„ํ•ด multicast Bye๋ฅผ ๋ฐฉ์†กํ•˜๋ ค๊ณ  ์‹œ๋„ํ•ฉ๋‹ˆ๋‹ค.

๊ธฐ๋ณธ ํฌํŠธ: 3702

PORT     STATE         SERVICE
3702/udp open|filtered unknown
| wsdd-discover:
|   Devices
|     Message id: 39a2b7f2-fdbd-690c-c7c9-deadbeefceb3
|     Address: http://10.0.200.116:50000
|_    Type: Device wprt:PrintDeviceType

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ