5800,5801,5900,5901 - Pentesting VNC

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๊ธฐ๋ณธ ์ •๋ณด

**Virtual Network Computing (VNC)**๋Š” Remote Frame Buffer (RFB) ํ”„๋กœํ† ์ฝœ์„ ํ™œ์šฉํ•˜์—ฌ ์›๊ฒฉ ์ œ์–ด ๋ฐ ๋‹ค๋ฅธ ์ปดํ“จํ„ฐ์™€์˜ ํ˜‘์—…์„ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•˜๋Š” ๊ฐ•๋ ฅํ•œ ๊ทธ๋ž˜ํ”ฝ ๋ฐ์Šคํฌํƒ‘ ๊ณต์œ  ์‹œ์Šคํ…œ์ž…๋‹ˆ๋‹ค. VNC๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์‚ฌ์šฉ์ž๊ฐ€ ํ‚ค๋ณด๋“œ ๋ฐ ๋งˆ์šฐ์Šค ์ด๋ฒคํŠธ๋ฅผ ์–‘๋ฐฉํ–ฅ์œผ๋กœ ์ „์†กํ•˜์—ฌ ์›๊ฒฉ ์ปดํ“จํ„ฐ์™€ ์›ํ™œํ•˜๊ฒŒ ์ƒํ˜ธ์ž‘์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋ฅผ ํ†ตํ•ด ์‹ค์‹œ๊ฐ„ ์•ก์„ธ์Šค๊ฐ€ ๊ฐ€๋Šฅํ•˜๋ฉฐ ๋„คํŠธ์›Œํฌ๋ฅผ ํ†ตํ•œ ํšจ์œจ์ ์ธ ์›๊ฒฉ ์ง€์› ๋˜๋Š” ํ˜‘์—…์„ ์ด‰์ง„ํ•ฉ๋‹ˆ๋‹ค.

VNC๋Š” ์ผ๋ฐ˜์ ์œผ๋กœ 5800 ๋˜๋Š” 5801 ๋˜๋Š” 5900 ๋˜๋Š” 5901 ํฌํŠธ๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

PORT    STATE SERVICE
5900/tcp open  vnc

์—ด๊ฑฐ

nmap -sV --script vnc-info,realvnc-auth-bypass,vnc-title -p <PORT> <IP>
msf> use auxiliary/scanner/vnc/vnc_none_auth

๋ธŒ๋ฃจํŠธ ํฌ์Šค

์นผ๋ฆฌ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ vnc์— ์—ฐ๊ฒฐํ•˜๊ธฐ

vncviewer [-passwd passwd.txt] <IP>::5901

VNC ๋น„๋ฐ€๋ฒˆํ˜ธ ๋ณตํ˜ธํ™”

๊ธฐ๋ณธ ๋น„๋ฐ€๋ฒˆํ˜ธ๋Š” ์ €์žฅ๋ฉ๋‹ˆ๋‹ค: ~/.vnc/passwd

VNC ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ์žˆ๊ณ  ์•”ํ˜ธํ™”๋œ ๊ฒƒ์ฒ˜๋Ÿผ ๋ณด์ธ๋‹ค๋ฉด(๋ช‡ ๋ฐ”์ดํŠธ, ์•”ํ˜ธํ™”๋œ ๋น„๋ฐ€๋ฒˆํ˜ธ์ผ ์ˆ˜ ์žˆ๋Š” ๊ฒฝ์šฐ), ์•„๋งˆ๋„ 3des๋กœ ์•”ํ˜ธํ™”๋œ ๊ฒƒ์ž…๋‹ˆ๋‹ค. https://github.com/jeroennijhof/vncpwd๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ํ‰๋ฌธ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

make
vncpwd <vnc password file>

์ด๊ฒƒ์€ 3des ๋‚ด์—์„œ ํ‰๋ฌธ VNC ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์•”ํ˜ธํ™”ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋œ ๋น„๋ฐ€๋ฒˆํ˜ธ๊ฐ€ ๋ช‡ ๋…„ ์ „์— ์—ญ์„ค๊ณ„๋˜์—ˆ๊ธฐ ๋•Œ๋ฌธ์— ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.
Windows์˜ ๊ฒฝ์šฐ ์ด ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค: https://www.raymond.cc/blog/download/did/232/
์ ‘๊ทผ์„ ์šฉ์ดํ•˜๊ฒŒ ํ•˜๊ธฐ ์œ„ํ•ด ์ด ๋„๊ตฌ๋ฅผ ์—ฌ๊ธฐ์—๋„ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค:

Shodan

  • port:5900 RFB

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ