Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๊ธฐ๋ณธ ์ •๋ณด

**Trivial File Transfer Protocol (TFTP)**๋Š” UDP ํฌํŠธ 69์—์„œ ์‚ฌ์šฉ๋˜๋Š” ๊ฐ„๋‹จํ•œ ํ”„๋กœํ† ์ฝœ๋กœ, ์ธ์ฆ ์—†์ด ํŒŒ์ผ ์ „์†ก์„ ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค. RFC 1350์— ๊ฐ•์กฐ๋˜์–ด ์žˆ์œผ๋ฉฐ, ๊ทธ ๋‹จ์ˆœ์„ฑ์œผ๋กœ ์ธํ•ด ์ฃผ์š” ๋ณด์•ˆ ๊ธฐ๋Šฅ์ด ๋ถ€์กฑํ•˜์—ฌ ๊ณต์šฉ ์ธํ„ฐ๋„ท์—์„œ์˜ ์‚ฌ์šฉ์ด ์ œํ•œ์ ์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ TFTP๋Š” VoIP ํ•ธ๋“œ์…‹๊ณผ ๊ฐ™์€ ์žฅ์น˜์— ๊ตฌ์„ฑ ํŒŒ์ผ ๋ฐ ROM ์ด๋ฏธ์ง€๋ฅผ ๋ฐฐํฌํ•˜๋Š” ๋ฐ ํšจ์œจ์ ์ด๊ธฐ ๋•Œ๋ฌธ์— ๋Œ€๊ทœ๋ชจ ๋‚ด๋ถ€ ๋„คํŠธ์›Œํฌ์—์„œ ๊ด‘๋ฒ”์œ„ํ•˜๊ฒŒ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.

TODO: Bittorrent-tracker์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•˜์‹ญ์‹œ์˜ค (Shodan์€ ์ด ํฌํŠธ๋ฅผ ๊ทธ ์ด๋ฆ„์œผ๋กœ ์‹๋ณ„ํ•ฉ๋‹ˆ๋‹ค). ์ด์— ๋Œ€ํ•œ ์ถ”๊ฐ€ ์ •๋ณด๊ฐ€ ์žˆ์œผ๋ฉด HackTricks ํ…”๋ ˆ๊ทธ๋žจ ๊ทธ๋ฃน ๋˜๋Š” PEASS์˜ GitHub ์ด์Šˆ์—์„œ ์•Œ๋ ค์ฃผ์‹ญ์‹œ์˜ค.

๊ธฐ๋ณธ ํฌํŠธ: 69/UDP

PORT   STATE SERVICE REASON
69/udp open  tftp    script-set

Enumeration

TFTP๋Š” ๋””๋ ‰ํ† ๋ฆฌ ๋ชฉ๋ก์„ ์ œ๊ณตํ•˜์ง€ ์•Š์œผ๋ฏ€๋กœ nmap์˜ ์Šคํฌ๋ฆฝํŠธ tftp-enum์€ ๊ธฐ๋ณธ ๊ฒฝ๋กœ๋ฅผ ๋ฌด์ž‘์œ„๋กœ ์‹œ๋„ํ•ฉ๋‹ˆ๋‹ค.

nmap -n -Pn -sU -p69 -sV --script tftp-enum <IP>

๋‹ค์šด๋กœ๋“œ/์—…๋กœ๋“œ

Metasploit ๋˜๋Š” Python์„ ์‚ฌ์šฉํ•˜์—ฌ ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œ/์—…๋กœ๋“œํ•  ์ˆ˜ ์žˆ๋Š”์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

msf5> auxiliary/admin/tftp/tftp_transfer_util
import tftpy
client = tftpy.TftpClient(<ip>, <port>)
client.download("filename in server", "/tmp/filename", timeout=5)
client.upload("filename to upload", "/local/path/file", timeout=5)

Shodan

  • port:69

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ