tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

CONNECT ๋ฐฉ๋ฒ•

Go ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์–ธ์–ด์—์„œ HTTP ์š”์ฒญ์„ ์ฒ˜๋ฆฌํ•  ๋•Œ, ํŠนํžˆ net/http ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ๋ฅผ ์‚ฌ์šฉํ•  ๋•Œ, ์š”์ฒญ ๊ฒฝ๋กœ๋ฅผ ํ‘œ์ค€ํ™”๋œ ํ˜•์‹์œผ๋กœ ์ž๋™ ๋ณ€ํ™˜ํ•˜๋Š” ๊ฒƒ์ด ์ผ๋ฐ˜์ ์ธ ๊ด€ํ–‰์ž…๋‹ˆ๋‹ค. ์ด ๊ณผ์ •์€ ๋‹ค์Œ์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค:

  • /๋กœ ๋๋‚˜๋Š” ๊ฒฝ๋กœ(flag/)๋Š” ์Šฌ๋ž˜์‹œ๊ฐ€ ์—†๋Š” ๋Œ€์‘ ๊ฒฝ๋กœ์ธ /flag๋กœ ๋ฆฌ๋””๋ ‰์…˜๋ฉ๋‹ˆ๋‹ค.
  • /../flag์™€ ๊ฐ™์€ ๋””๋ ‰ํ† ๋ฆฌ ํƒ์ƒ‰ ์‹œํ€€์Šค๋ฅผ ํฌํ•จํ•˜๋Š” ๊ฒฝ๋กœ๋Š” ๋‹จ์ˆœํ™”๋˜์–ด /flag๋กœ ๋ฆฌ๋””๋ ‰์…˜๋ฉ๋‹ˆ๋‹ค.
  • /flag/.์™€ ๊ฐ™์ด ํ›„ํ–‰ ๋งˆ์นจํ‘œ๊ฐ€ ์žˆ๋Š” ๊ฒฝ๋กœ๋„ ๊นจ๋—ํ•œ ๊ฒฝ๋กœ์ธ /flag๋กœ ๋ฆฌ๋””๋ ‰์…˜๋ฉ๋‹ˆ๋‹ค.

๊ทธ๋Ÿฌ๋‚˜ CONNECT ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•  ๋•Œ ์˜ˆ์™ธ๊ฐ€ ๊ด€์ฐฐ๋ฉ๋‹ˆ๋‹ค. ๋‹ค๋ฅธ HTTP ๋ฐฉ๋ฒ•๊ณผ ๋‹ฌ๋ฆฌ CONNECT๋Š” ๊ฒฝ๋กœ ์ •๊ทœํ™” ํ”„๋กœ์„ธ์Šค๋ฅผ ํŠธ๋ฆฌ๊ฑฐํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ด ๋™์ž‘์€ ๋ณดํ˜ธ๋œ ๋ฆฌ์†Œ์Šค์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ๋Š” ์ž ์žฌ์ ์ธ ๊ฒฝ๋กœ๋ฅผ ์—ด์–ด์ค๋‹ˆ๋‹ค. curl์—์„œ --path-as-is ์˜ต์…˜๊ณผ ํ•จ๊ป˜ CONNECT ๋ฐฉ๋ฒ•์„ ์‚ฌ์šฉํ•˜๋ฉด ํ‘œ์ค€ ๊ฒฝ๋กœ ์ •๊ทœํ™”๋ฅผ ์šฐํšŒํ•˜๊ณ  ์ œํ•œ๋œ ์˜์—ญ์— ๋„๋‹ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋‹ค์Œ ๋ช…๋ น์€ ์ด ๋™์ž‘์„ ์•…์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค:

bash
curl --path-as-is -X CONNECT http://gofs.web.jctf.pro/../flag

https://github.com/golang/go/blob/9bb97ea047890e900dae04202a231685492c4b18/src/net/http/server.go#L2354-L2364

tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ