Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๊ธฐ๋ณธ ์ •๋ณด

Kibana๋Š” ์ผ๋ฐ˜์ ์œผ๋กœ ํฌํŠธ 5601์—์„œ ์‹คํ–‰๋˜๋Š” Elasticsearch ๋‚ด์—์„œ ๋ฐ์ดํ„ฐ๋ฅผ ๊ฒ€์ƒ‰ํ•˜๊ณ  ์‹œ๊ฐํ™”ํ•˜๋Š” ๋Šฅ๋ ฅ์œผ๋กœ ์•Œ๋ ค์ ธ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” Elastic Stack ํด๋Ÿฌ์Šคํ„ฐ์˜ ๋ชจ๋‹ˆํ„ฐ๋ง, ๊ด€๋ฆฌ ๋ฐ ๋ณด์•ˆ ๊ธฐ๋Šฅ์„ ์œ„ํ•œ ์ธํ„ฐํŽ˜์ด์Šค ์—ญํ• ์„ ํ•ฉ๋‹ˆ๋‹ค.

์ธ์ฆ ์ดํ•ดํ•˜๊ธฐ

Kibana์—์„œ์˜ ์ธ์ฆ ๊ณผ์ •์€ ๋ณธ์งˆ์ ์œผ๋กœ Elasticsearch์—์„œ ์‚ฌ์šฉ๋˜๋Š” ์ž๊ฒฉ ์ฆ๋ช…๊ณผ ์—ฐ๊ฒฐ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. Elasticsearch์—์„œ ์ธ์ฆ์ด ๋น„ํ™œ์„ฑํ™”๋œ ๊ฒฝ์šฐ, Kibana๋Š” ์ž๊ฒฉ ์ฆ๋ช… ์—†์ด ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ฐ˜๋Œ€๋กœ, Elasticsearch๊ฐ€ ์ž๊ฒฉ ์ฆ๋ช…์œผ๋กœ ๋ณดํ˜ธ๋˜๋Š” ๊ฒฝ์šฐ, Kibana์— ์ ‘๊ทผํ•˜๊ธฐ ์œ„ํ•ด ๋™์ผํ•œ ์ž๊ฒฉ ์ฆ๋ช…์ด ํ•„์š”ํ•˜๋ฉฐ, ๋‘ ํ”Œ๋žซํผ ๊ฐ„์— ๋™์ผํ•œ ์‚ฌ์šฉ์ž ๊ถŒํ•œ์ด ์œ ์ง€๋ฉ๋‹ˆ๋‹ค. ์ž๊ฒฉ ์ฆ๋ช…์€ /etc/kibana/kibana.yml ํŒŒ์ผ์—์„œ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์ž๊ฒฉ ์ฆ๋ช…์ด kibana_system ์‚ฌ์šฉ์ž์™€ ๊ด€๋ จ์ด ์—†๋‹ค๋ฉด, ๋” ๋„“์€ ์ ‘๊ทผ ๊ถŒํ•œ์„ ์ œ๊ณตํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. kibana_system ์‚ฌ์šฉ์ž์˜ ์ ‘๊ทผ์€ ๋ชจ๋‹ˆํ„ฐ๋ง API ๋ฐ .kibana ์ธ๋ฑ์Šค๋กœ ์ œํ•œ๋ฉ๋‹ˆ๋‹ค.

์ ‘๊ทผ ์‹œ ์กฐ์น˜

Kibana์— ๋Œ€ํ•œ ์ ‘๊ทผ์ด ํ™•๋ณด๋˜๋ฉด, ๋ช‡ ๊ฐ€์ง€ ์กฐ์น˜๋ฅผ ์ทจํ•˜๋Š” ๊ฒƒ์ด ๋ฐ”๋žŒ์งํ•ฉ๋‹ˆ๋‹ค:

  • Elasticsearch์˜ ๋ฐ์ดํ„ฐ๋ฅผ ํƒ์ƒ‰ํ•˜๋Š” ๊ฒƒ์ด ์šฐ์„  ์‚ฌํ•ญ์ด์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.
  • ์‚ฌ์šฉ์ž ๊ด€๋ฆฌ ๊ธฐ๋Šฅ, ์ฆ‰ ์‚ฌ์šฉ์ž, ์—ญํ•  ๋˜๋Š” API ํ‚ค์˜ ํŽธ์ง‘, ์‚ญ์ œ ๋˜๋Š” ์ƒ์„ฑ์„ ํฌํ•จํ•œ ๊ธฐ๋Šฅ์€ Stack Management -> Users/Roles/API Keys์—์„œ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • ์•Œ๋ ค์ง„ ์ทจ์•ฝ์ , ์˜ˆ๋ฅผ ๋“ค์–ด 6.6.0 ์ด์ „ ๋ฒ„์ „์—์„œ ํ™•์ธ๋œ RCE ์ทจ์•ฝ์ ์— ๋Œ€ํ•ด Kibana์˜ ์„ค์น˜๋œ ๋ฒ„์ „์„ ํ™•์ธํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค (์ž์„ธํ•œ ์ •๋ณด).

SSL/TLS ๊ณ ๋ ค ์‚ฌํ•ญ

SSL/TLS๊ฐ€ ํ™œ์„ฑํ™”๋˜์ง€ ์•Š์€ ๊ฒฝ์šฐ, ๋ฏผ๊ฐํ•œ ์ •๋ณด๊ฐ€ ์œ ์ถœ๋  ๊ฐ€๋Šฅ์„ฑ์„ ์ฒ ์ €ํžˆ ํ‰๊ฐ€ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์ฐธ์กฐ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ