728x90

1. ์ •๋ณดํ™” ์‚ฌํšŒ์˜ ์ •๋ณด๋ณดํ˜ธ

(1) ์ •๋ณด๋ณดํ˜ธ(Information Security)

1) ์ •๋ณด๋ณดํ˜ธ์˜ ๋ชฉํ‘œ

  • ๊ธฐ๋ฐ€์„ฑ(๋น„๋ฐ€์„ฑ, Confidentiality)
    • ์˜ค์ง ์ธ๊ฐ€๋œ ์‚ฌ๋žŒ, ํ”„๋กœ์„ธ์Šค, ์‹œ์Šคํ…œ์— ๊ทผ๊ฑฐํ•˜์—ฌ ์‹œ์Šคํ…œ์— ์ ‘๊ทผํ•ด์•ผ ํ•œ๋‹ค
    • ์ •๋ณด๋Š” ์†Œ์œ ์ž์˜ ์ธ๊ฐ€๋ฅผ ๋ฐ›์€ ์‚ฌ๋žŒ๋งŒ์ด ์ ‘๊ทผ ๊ฐ€๋Šฅ
    • ์ ‘๊ทผ์ œ์–ด, ์•”ํ˜ธํ™”
  • ๋ฌด๊ฒฐ์„ฑ(Integrity)
    • ์ •๋ณด๋Š” ์ฃผ์–ด์ง„ ๊ถŒํ•œ์— ์˜ํ•ด์„œ๋งŒ ๋ณ€๊ฒฝ๋˜์–ด์•ผ ํ•œ๋‹ค..
    • ์ •ํ™•์„ฑ์„ ์ผ์ •ํ•˜๊ฒŒ ์œ ์ง€, ์ธ๊ฐ€๋ฐ›์€ ๋ฐฉ๋ฒ•์— ์˜ํ•ด์„œ๋งŒ ๋ณ€๊ฒฝ
    • ์ ‘๊ทผ์ œ์–ด, ๋ฉ”์‹œ์ง€ ์ธ์ฆ, ์นจ์ž… ํƒ์ง€, ๋ฐฑ์—…
  • ๊ฐ€์šฉ์„ฑ(Availability)
    • ์ •๋‹นํ•œ ๋ฐฉ๋ฒ•์œผ๋กœ ๊ถŒํ•œ์ด ์ฃผ์–ด์ง„ ์‚ฌ๋ฃก์ž์—๊ฒŒ ์ •๋ณด ์„œ๋น„์Šค๋ฅผ ๊ฑฐ๋ถ€ํ•˜์—ฌ์„œ๋Š” ์•ˆ ๋œ๋‹ค
    • ์ ์‹ฑ์— ์ ์ ˆํ•˜๊ฒŒ ์‚ฌ์šฉ ๊ฐ€๋Šฅ
    • ๋ฐ์ดํ„ฐ์˜ ๋ฐฑ์—…, ์ค‘๋ณต์„ฑ์˜ ์œ ์ง€, ๋ฌผ๋ฆฌ์  ์œ„ํ˜‘์š”์†Œ๋กœ๋ถ€ํ„ฐ์˜ ๋ณดํ˜ธ
  • ์ธ์ฆ์„ฑ(์ธ์ฆ, Authenticity, Authentication)
    • ์ง„์งœ๋ผ๋Š” ์„ฑ์งˆ์„ ํ™•์ธ, ํ™•์ธ ๋ฐ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ๊ฒƒ์„ ์˜๋ฏธ
  • ์ฑ…์ž„์ถ”์ ์„ฑ(์ฑ…์ž„์„ฑ, Accounability)
    • ๋ณด์•ˆ ์นจํ•ด์— ๋Œ€ํ•œ ์ฑ…์ž„์ด ์žˆ๋Š” ๊ณณ๊นŒ์ง€ ์ถ”์ ํ•  ์ˆ˜ ์žˆ์–ด์•ผ ํ•œ๋‹ค.
    • ๋ถ€์ธ ๋ด‰์‡„, ์–ต์ œ, ๊ฒฐํ•จ ๋ถ„๋ฆฌ, ์นจ์ž… ํƒ•์ง€ ์˜ˆ๋ฐฉ, ์‚ฌํ›„ ๋ณต๊ตฌ์™€ ๋ฒ•์ ์ธ ์กฐ์น˜

2. ์ •๋ณด๋ณดํ˜ธ ๊ด€๋ฆฌ

1) ์ •๋ณด๋ณดํ˜ธ ๊ด€๋ฆฌ์˜ ๊ฐœ๋…

  • ์ •๋ณด๋ณดํ˜ธ: ์ •๋ณด์˜ ํ›ผ์†/๋ณ€์กฐ/์œ ์ถœ ๋“ฑ์„ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•œ ๊ด€๋ฆฌ์ /๊ธฐ์ˆ ์  ์ˆ˜๋‹จ

2) ์ •๋ณด๋ณดํ˜ธ ๊ด€๋ฆฌ์™€ ์ •๋ณด๋ณดํ˜ธ ๋Œ€์ฑ…

  • ์ •๋ณด๋ณดํ˜ธ ๊ด€๋ฆฌ๋Š” ๊ธฐ์ˆ ์  ๋ณดํ˜ธ๋Œ€์ฑ…, ๋ฌผ๋ฆฌ์  ๋ณดํ˜ธ๋Œ€์ฑ…, ๊ด€๋ฆฌ์  ๋ณดํ˜ธ๋Œ€์ฑ…์œผ๋กœ ๊ตฌ๋ถ„ํ•˜์—ฌ ๊ณ„์ธต์ ์œผ๋กœ ํ‘œํ˜„
    • ๊ธฐ์ˆ ์  ๋ณดํ˜ธ๋Œ€์ฑ…: ์ ‘๊ทผํ†ต์ œ, ์•”ํ˜ธ๊ธฐ์ˆ , ๋ฐฑ์—… ์ฒด์ œ
    • ๋ฌผ๋ฆฌ์  ๋ณดํ˜ธ๋Œ€์ฑ…: ํ™”์žฌ, ์ˆ˜ํ•ด, ์ง€์ง„, ํƒœํ’
    • ๊ด€๋ฆฌ์  ๋ณดํ˜ธ๋Œ€์ฑ…: ๋ฒ•, ์ œ๋„, ๊ทœ์ •, ๊ต์œก

3. OSI ๋ณด์•ˆ ๊ตฌ์กฐ

(1) ๊ฐœ์š”

1) ๊ธฐ๋ณธ ๊ฐœ๋…

  • ๋ณด์•ˆ ๊ณต๊ฒฉ: ๊ธฐ๊ด€์ด ์†Œ์œ ํ•œ ์ •๋ณด์˜ ์•ˆ์ „์„œ์„ ์นจํ•ดํ•˜๋Š” ์ œ๋ฐ˜ ํ–‰์œ„
  • ๋ณด์•ˆ ๋ฉ”์ปค๋‹ˆ์ฆ˜: ๋ณด์•ˆ ๊ณต๊ฒฉ์„ ํƒ์ง€, ์˜ˆ๋ฐฉํ•˜๊ฑฐ๋‚˜ ๊ณต๊ฒฉ์œผ๋กœ ์ธํ•ด ์นจํ•ด๋ฅผ ๋ณต๊ตฌํ•˜๋Š” ์ ˆ์ฐจ
  • ๋ณด์•ˆ ์„œ๋น„์Šค: ๋ณด์•ˆ์„ ๊ฐ•ํ™”ํ•˜๊ธฐ ์œ„ํ•œ ์ฒ˜๋ฆฌ ๋˜๋Š” ํ†ต์‹  ์„œ๋น„์Šค, ํ•˜๋‚˜ ๋˜๋Š” ๊ทธ ์ด์ƒ์˜ ๋ณด์•ˆ ๋ฉ”์ปค๋‹ˆ์ฆ˜์„ ์‚ฌ์šฉํ•ด ์„œ๋น„์Šค๋ฅผ ์ œ๊ณต

(2) ๋ณด์•ˆ ๊ณต๊ฒฉ

  • ๋ณด์•ˆ์˜ ์„ธ ๊ฐ€์ง€ ๋ชฉํ‘œ(๊ธฐ๋ฐ€์„ฑ, ๋ฌด๊ฒฐ์„ฑ, ๊ฐ€์šฉ์„ฑ)์™€ ๊ด€๋ จํ•˜์—ฌ ์„ธ ๊ฐœ์˜ ๊ทธ๋ฃน์œผ๋กœ ๋จผ์ € ๋‚˜๋ˆ„๊ณ , ๋‹ค์‹œ ๊ทธ ๊ณต๊ฒฉ์„ ์‹œ์Šคํ…œ์— ๋ฏธ์น˜๋Š” ์˜ํ–ฅ์— ๋”ฐ๋ผ ๋‘ ๊ฐœ์˜ ์œ ํ˜•์œผ๋กœ ๋‚˜๋ˆˆ๋‹ค.

1) ๊ธฐ๋ฐ€์„ฑ์„ ์œ„ํ˜‘ํ•˜๋Š” ๊ณต๊ฒฉ

  • ์Šค๋ˆ„ํ•‘(Snooping): ๋ฐ์ดํ„ฐ์— ๋Œ€ํ•œ ๋น„์ธ๊ฐ€ ์ ‘๊ทผ ๋˜๋Š” ํƒˆ์ทจ
  • ํŠธ๋ž˜ํ”ฝ ๋ถ„์„(Traffic Analysis): ์˜จ๋ผ์ธ ํŠธ๋ž˜ํ”ฝ ๋ถ„์„ํ•ด ๋‹ค๋ฅธ ํ˜•ํƒœ์˜ ์ •๋ณด ํš๋“

2) ๋ฌด๊ฒฐ์„ฑ์„ ์œ„ํ˜‘ํ•˜๋Š” ๊ณต๊ฒฉ

  • ๋ณ€๊ฒฝ(๋ฉ”์‹œ์ง€ ์ˆ˜์ •, Modification): ๋ฉ”์‹œ์ง€ ์ผ๋ถ€๋ฅผ ๋ถˆ๋ฒ•์œผ๋กœ ์ˆ˜์ •, ์ „์†ก ์ง€์—ฐ, ์ˆœ์„œ ์žฌ๋ฐฐ์—ด
  • ๊ฐ€์žฅ(Masquerading): ํ•œ ๊ฐœ์ฒด๊ฐ€ ๋‹ค๋ฅธ ๊ฐ์ฒด์˜ ํ–‰์„ธ๋ฅผ ํ•˜๋Š” ๊ฒƒ, ๋‹ค๋ฅธ ํ˜•ํƒœ์˜ ์ ๊ทน์  ๊ณต๊ฒฉ๊ณผ ๋ณ‘ํ–‰
  • ์žฌ์—ฐ(์žฌ์ „์†ก, Replaying): ์ ๊ทน์  ๊ณต๊ฒฉ, ํš๋“ํ•œ ๋ฐ์ดํ„ฐ ๋‹จ์œ„๋ฅผ ๋ณด๊ด€ ํ›„ ์žฌ์ „์†ก
  • ๋ถ€์ธ(Repudiation): ์†ก์‹ ์ž๋Š” ์ž์‹ ์ด ๋ฉ”์‹œ์ง€๋ฅผ ๋ณด๋‚ธ ๊ฒƒ์— ๋ถ€์ธ, ์ˆ˜์‹ ์ž๋Š” ๋ฉ”์‹œ์ง€๋ฅผ ๋ฐ›์•˜๋‹ค๋Š” ๊ฒƒ์„ ๋ถ€์ธ
    • ๋ถ€์ธ๋ฐฉ์ง€: ๋ฉ”์‹œ์ง€ ์ „์†ก ๋ฐ ์ˆ˜์‹ ํ•œ ์‚ฌ์‹ค ์ž์ฒด๋ฅผ ๋ถ€์ธํ•˜์ง€ ๋ชปํ•˜๋„๋ก ๋ง‰๋Š” ๊ฒƒ

3) ๊ฐ€์šฉ์„ฑ์„ ์œ„ํ˜‘ํ•˜๋Š” ๊ณต๊ฒฉ

  • ์„œ๋น„์Šค ๊ฑฐ๋ถ€(Denial of Service): ์‹œ์Šคํ…œ์˜ ์„œ๋น„์Šค๋ฅผ ๋А๋ฆฌ๊ฒŒ ํ•˜๊ฑฐ๋‚˜ ์™„์ „ํžˆ ์ฐจ๋‹จ

4) ์†Œ๊ทน์  ๊ณต๊ฒฉ๊ณผ ์ ๊ทน์  ๊ณต๊ฒฉ 

  • ์†Œ๊ทน์  ๊ณต๊ฒฉ: ๋‹จ์ง€ ์ •๋ณด๋ฅผ ํš๋“, ์‹œ์Šคํ…œ ์˜ํ–ฅ X
    • ์Šค๋ˆ„ํ•‘, ํŠธ๋ž˜ํ”ฝ ๋ถ„์„
    • ํƒ์ง€๋ณด๋‹ค๋Š” ์˜ˆ๋ฐฉ
  • ์ ๊ทน์  ๊ณต๊ฒฉ: ๋ฐ์ดํ„ฐ๋ฅผ ๋ฐ”๊พธ๊ฑฐ๋‚˜ ์‹œ์Šคํ…œ์— ํ•ด๋ฅผ ๋ผ์นจ
    • ๋ฌด๊ฒฐ์„ฑ๊ณผ ๊ฐ€์šฉ์„ฑ์„ ์œ„ํ˜‘
    • ์˜ˆ๋ฐฉ๋ณด๋‹ค๋Š” ํƒ์ง€

4. ๊ธฐ๋ณธ ๋ณด์•ˆ์šฉ์–ด ์ •๋ฆฌ

  • ์ž์‚ฐ(Asset): ์กฐ์ง์ด ๋ณดํ˜ธํ•ด์•ผ ํ•  ๋Œ€์ƒ, ๋ฐ์ดํ„ฐ ํ˜น์€ ์ž์‚ฐ ์†Œ์œ ์ž๊ฐ€ ๊ฐ€์น˜๋ฅผ ๋ถ€์—ฌํ•œ ์‹ค์ฒด
  • ์ทจ์•ฝ์ (์ทจ์•ฝ์„ฑ, Vulnerability): ์ปดํ“จํ„ฐ, ๋„คํŠธ์›Œํฌ์— ์นจ์ž…ํ•˜์—ฌ ํ—ˆ๊ฐ€๋˜์ง€ ์•Š์€ ์ ‘๊ทผ์„ ์‹œ๋„ํ•˜๋ ค๋Š” ๊ณต๊ฒฉ์ž์—๊ฒŒ ์—ด๋ฆฐ ๋ฌธ์„ ์ œ๊ณตํ•  ์ˆ˜ ์žˆ๋Š” ์•ฝ์ 
  • ์œ„ํ˜‘(Threat): ๋ณด์•ˆ์— ํ•ด๋ฅผ ๋ผ์น˜๋Š” ํ–‰๋™์ด๋‚˜ ์‚ฌ๊ฑด
    • ๊ฐ€๋กœ์ฑ„๊ธฐ: ์ž์‚ฐ์œผ๋กœ์˜ ์ ‘๊ทผ์„ ํš๋“(๊ธฐ๋ฐ€์„ฑ์— ์˜ํ–ฅ)
    • ๊ฐ€๋กœ๋ง‰์Œ: ์‹œ์Šคํ…œ ์ž์‚ฐ ์†์‹ค, ์‚ฌ์šฉ ๋ถˆ๊ฐ€(๊ฐ€์šฉ์„ฑ์— ์˜ํ–ฅ)
    • ๋ณ€์กฐ: ๋‚ด์šฉ์„ ๋ณ€๊ฒฝ(๋ฌด๊ฒฐ์„ฑ์— ์˜ํ–ฅ)
    • ์œ„์กฐ: ์ปดํ“จํŒ… ์‹œ์Šคํ…œ์ƒ์— ๋ถˆ๋ฒ• ๊ฐœ๊ฒŒ์˜ ์œ„์กฐ ์ •๋ณด๋ฅผ ์ƒ์„ฑ(๋ฌด๊ฒฐ์„ฑ, ์ธ์ฆ์— ์˜ํ–ฅ)
  • ์œ„ํ—˜(Risk): ์ทจ์•ฝ์ ์„ ํ™œ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐ€๋Šฅ์„ฑ, ์ž์‚ฐX์œ„ํ˜‘X์ทจ์•ฝ์ 
  • ๋…ธ์ถœ(Exposure): ์œ„ํ˜‘ ์ฃผ์ œ์ดˆ ์ธํ•ด์„œ ์†์‹ค์ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒฝ์šฐ
  • ๋Œ€์ฑ…/์•ˆ์ „์žฅ์น˜: ์ทจ์•ฝ์ ์„ ์ œ๊ฑฐ, ์ทจ์•ฝ์ ์„ ์ด์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๊ฐ€๋Šฅ์„ฑ์„ ๊ฐ์†Œ
  • ๋‹ค๊ณ„์ธต ๋ณด์•ˆ/์‹ฌ์ธต ๋ฐฉ์–ด: ์—ฌ๋Ÿฌ ๊ณ„์ธต์˜ ๋ณด์•ˆ๋Œ€์ฑ…์ด๋‚˜ ๋Œ€์‘์ˆ˜๋‹จ์„ ๊ตฌ์„ฑ
  • Due: ํŠน์ • ๋ชฉ์ ์„ ์œ„ํ•ด ํ•„์š”ํ•˜๊ฑฐ๋‚˜ ์š”๊ตฌ๋˜๋Š” ์ ์ ˆํ•˜๊ณ  ์ถฉ๋ถ„ํ•œ ์˜๋ฌด
  • Due Care: ํŠน์ • ๋ชฉ์ ์„ ์œ„ํ•ด ํ•„์š”ํ•˜๊ฑฐ๋‚˜ ์š”๊ตฌ๋˜๋Š” ์ถฉ๋ถ„ํ•œ ์ฃผ์˜
  • Due Diligence: ํŠน์ • ๋ชฉ์ ์„ ์œ„ํ•ด ํ•„์š”ํ•˜๊ฑฐ๋‚˜ ์š”๊ตฌ๋˜๋Š” ์ถฉ๋ถ„ํ•œ ๋…ธ๋ ฅ
  • ์‚ฌํšŒ๊ณตํ•™: ์ธ๊ฐ„ ์ƒํ˜ธ ์ž‘์šฉ์˜ ๊นŠ์€ ์‹ ๋ขฐ๋ฅผ ๋ฐ”ํƒ•์œผ๋กœ ๋ณด์•ˆ ์ ˆ์ฐจ๋ฅผ ๊นจํŠธ๋ฆฌ๊ธฐ ์œ„ํ•œ ์นจ์ž… ์ˆ˜๋‹จ

 

728x90

[๋ฌธ์ œ]

https://dreamhack.io/wargame/challenges/876

 

Exercise: Docker

Description Docker ์‹ค์Šต์„ ์œ„ํ•œ ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค. ์ฃผ์–ด์ง„ Dockerfile์„ ๋นŒ๋“œํ•˜์—ฌ ์ด๋ฏธ์ง€๋ฅผ ์ƒ์„ฑํ•˜๊ณ  ์ปจํ…Œ์ด๋„ˆ๋ฅผ ์‹คํ–‰ํ•ด ๋ณด์„ธ์š”! ํ”Œ๋ž˜๊ทธ์˜ ํ˜•์‹์€ DH{...} ์ž…๋‹ˆ๋‹ค.

dreamhack.io


[๋ฌธ์ œ ํ’€์ด]

https://velog.io/@minkoong/docker%EC%97%90-kali-%EC%84%A4%EC%B9%98%ED%95%98%EA%B8%B0

 

docker์— kali ์„ค์น˜ํ•˜๊ธฐ

docker์— kali ์„ค์น˜ํ•˜๊ธฐ

velog.io

  • ์šฐ์„  ๋จผ์ € ์œ„ ์‚ฌ์ดํŠธ๋ฅผ ์ฐธ๊ณ ํ•ด์„œ kali์— docker๋ฅผ ์„ค์น˜ํ•ด ์ฃผ์—ˆ๋‹ค.
    • sudo apt install docker.io

  • ๊ทธ๋‹ค์Œ ๋ฌธ์ œํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œ ํ•œ ๋‹ค์Œ ๋ฌธ์ œ ํŒŒ์ผ์— dockerfile๊ณผ deploy๊ฐ€ ์กด์žฌํ•œ๋‹ค.
  • ํด๋” ์ „์ฒด๋ฅผ ๋ฆฌ๋ˆ…์Šค VM์œผ๋กœ ์˜ฎ๊ฒจ์ฃผ์—ˆ๋‹ค.

  • ๊ทธ๋‹ค์Œ, dockerfile์ด ์žˆ๋Š” ๋””๋ ‰ํ„ฐ๋ฆฌ์—์„œ ๋„์ปค ๋นŒ๋“œ ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•ด ๋นŒ๋“œ๋ฅผ ์‹œ๋„ํ–ˆ๋‹ค.
    • sudo docker build .

  • ๊ทธ๋Ÿฌ๋‚˜, ๊ถŒํ•œ ์˜ค๋ฅ˜๋กœ ๋– ์„œ ๋ฐ‘์— ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ•ด์„œ ๋‹ค์‹œ ๋„์ปค ๋นŒ๋“œ๋ฅผ ํ•ด์ฃผ์—ˆ๋‹ค.
    • sudo usermod -aG docker $USER: ๋„์ปค๊ทธ๋ฃน์— ํ˜„์žฌ์‚ฌ์šฉ์ž๋ฅผ ์ถ”๊ฐ€
    • newgrp docker: ๊ทธ๋ฃน ์ถ”๊ฐ€๋ฅผ ํ˜„์žฌ ์ฝ˜์†”์— ๋ฐ˜์˜

  • ๊ถŒํ•œ์„ ์ถ”๊ฐ€ํ•ด ์ฃผ๊ณ  ๋„์ปค ์ด๋ฏธ์ง€๋ฅผ ํ™•์ธํ•˜๋‹ˆ ๋ฌธ์ œ ํŒŒ์ผ์— ๋Œ€ํ•œ ์ด๋ฏธ์ง€ ์•„์ด๋””๋ฅผ ์•Œ์•„๋‚ผ ์ˆ˜ ์žˆ์—ˆ๋‹ค.
    • docker images : ๋„์ปค ์ด๋ฏธ์ง€ ํ™•์ธ

  • ์•Œ์•„๋‚ธ ์•„์ด๋””๋ฅผ ์ด์šฉํ•ด ์ด๋ฏธ์ง€๋กœ ์ปจํ…Œ์ด๋„ˆ๋ฅผ ์ƒ์„ฑํ•˜๊ณ  ์‹คํ–‰ํ•˜์˜€๋‹ค.
    • docker run -it [image id] /bin/bash : ๋„์ปค ์‹คํ–‰
  • ์‹คํ–‰ ํ›„ ls๋กœ ํŒŒ์ผ ๋ชฉ๋ก์„ ํ™•์ธํ•˜๋‹ˆ flag ํŒŒ์ผ์„ ๋ฐœ๊ฒฌํ•ด์„œ cat ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•ด ํŒŒ์ผ ๋‚ด์šฉ์„ ํ™•์ธํ•จ์œผ๋กœ์จ ํ”Œ๋ž˜๊ทธ๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ์—ˆ๋‹ค.

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

natas3 write-up  (0) 2025.02.16
[๋“œ๋ฆผํ•ต] baby-linux  (0) 2025.02.16
[๋“œ๋ฆผํ•ต] 64se64  (0) 2025.02.16
natas0 write-up  (0) 2025.02.10
[๋ชจ์˜์นจํˆฌ] | [RCity] 1.Linux ๋ช…๋ น์–ด - Operation RCity7  (0) 2025.02.02
728x90

[๋ฌธ์ œ]

https://overthewire.org/wargames/natas/natas3.html

 

OverTheWire

We're hackers, and we are good-looking. We are the 1%. <!-- Please read and accept the Rules! --> Username: natas3 URL: http://natas3.natas.labs.overthewire.org

overthewire.org


[๋ฌธ์ œ ํ’€์ด]

  • ์ด๋ฒˆ์—๋„ ์‚ฌ์ดํŠธ๋ฅผ ์ ‘์†ํ•˜๋‹ˆ ์ €๋ฒˆ์ฒ˜๋Ÿผ ํŽ˜์ด์ง€์—์„œ ์•„๋ฌด๋Ÿฐ ์ •๋ณด๋ฅผ ์–ป์„ ์ˆ˜ ์—†์—ˆ๋‹ค.

  • ๊ทธ๋ž˜์„œ, F12๋กœ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•ด ๋ณด๋‹ˆ ์ฃผ์„์ฒ˜๋ฆฌ๋กœ ์ •๋ณด๊ฐ€ ์ƒˆ์ง€ ์•Š์•˜๊ณ  ๊ตฌ๊ธ€๋„ ์ฐพ์„ ์ˆ˜ ์—†๋‹ค๋Š” ์ด์•ผ๊ธฐ๊ฐ€ ๋‚˜์˜จ๋‹ค.
  • ๊ตฌ๊ธ€์ด ์ฐพ์„ ์ˆ˜ ์—†๋‹ค๊ณ  ํ•ด์„œ ์ฐพ์•„๋ณด๋‹ˆ ๊ตฌ๊ธ€์—”์ง„ ๋ด‡์€ ์ธํ„ฐ๋„ท์„ ๋Œ์•„๋‹ค๋‹ˆ๋ฉด์„œ ํ•ญ์ƒ ์ •๋ณด๋ฅผ ์ˆ˜์ง‘ํ•œ๋‹ค.
    • ๊ทธ๋Ÿฌ๋‚˜, robots.txt์— disallow ๋˜์–ด์žˆ๋Š” ๊ณณ์€ ๊ตฌ๊ธ€์ด ์ •๋ณด ์ˆ˜์ง‘์ด ๋ถˆ๊ฐ€๋Šฅํ•˜๋‹ค.

  • ๊ทธ๋ž˜์„œ, ์œ„ ์ •๋ณด๋ฅผ ์ด์šฉํ•˜์—ฌ robots.txt๋ฅผ url์— ์ถ”๊ฐ€ํ•ด์„œ ๊ฒ€์ƒ‰ํ•ด๋ณด๋‹ˆ /s3cr3t/๊ฐ€ disallow ๋˜์–ด ์žˆ๋Š” ๊ฒƒ์„ ํ™•์ธํ–ˆ๋‹ค.

  • ๊ทธ๋‹ค์Œ, /s3cr3t/์— ๋“ค์–ด๊ฐ€ ๋ณด๋‹ˆ users.txt ํŒŒ์ผ์„ ๋ฐœ๊ฒฌํ–ˆ๋‹ค.

  • users.txt ํŒŒ์ผ์„ ํ†ตํ•ด password๋ฅผ ์–ป์—ˆ๋‹ค!

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[๋“œ๋ฆผํ•ต] Exercise: Docker  (0) 2025.02.23
[๋“œ๋ฆผํ•ต] baby-linux  (0) 2025.02.16
[๋“œ๋ฆผํ•ต] 64se64  (0) 2025.02.16
natas0 write-up  (0) 2025.02.10
[๋ชจ์˜์นจํˆฌ] | [RCity] 1.Linux ๋ช…๋ น์–ด - Operation RCity7  (0) 2025.02.02
728x90

[๋ฌธ์ œ]


[๋ฌธ์ œ ํ’€์ด]

  • ๋จผ์ € ์‚ฌ์ดํŠธ์— ์ ‘์†ํ•˜๋‹ˆ ์ด ํŽ˜์ด์ง€๋Š” ๋ฆฌ๋ˆ…์Šค ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•˜๋Š” ํŽ˜์ด์ง€์˜€๋‹ค.
  • ๋จผ์ € ํŒŒ์ผ ๋ชฉ๋ก์„ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด ls ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ–ˆ๋”๋‹ˆ hint.txt๋ฅผ ๋ฐœ๊ฒฌํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.

  • hint.txt ํŒŒ์ผ์˜ ๋‚ด์šฉ์„ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด cat ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ–ˆ๊ณ  ํžŒํŠธ๋ฅผ ํ†ตํ•ด flag.txt ํŒŒ์ผ์˜ ์œ„์น˜๋ฅผ ์•Œ์•„๋ƒˆ๋‹ค.

  • flat.txt ํŒŒ์ผ์˜ ๋‚ด์šฉ์„ ์•Œ์•„๋‚ด๊ธฐ ์œ„ํ•ด cat ./dream/hack/hello/flag.txt๋ฅผ ์ž…๋ ฅํ–ˆ๋”๋‹ˆ No!๋ผ๋Š” ๊ฒฐ๊ณผ๊ฐ€ ๋‚˜์™”๋‹ค.

  • ๊ทธ๋ž˜์„œ, ์†Œ์Šค ์ฝ”๋“œ๋ฅผ ํ™•์ธํ•ด๋ณด๋‹ˆ ๋งˆ์ง€๋ง‰ ์ค„์— cmd์— 'flag'๋ฌธ์ž์—ด์ด ํฌํ•จ๋˜์–ด ์žˆ๋‹ค๋ฉด No! ๋ฅผ ์ถœ๋ ฅํ•˜๋ผ๋Š” ์‚ฌ์‹ค์„ ์•Œ์•„๋ƒˆ๋‹ค.

  • ๊ทธ๋ž˜์„œ, ๋ช…๋ น์–ด์— flag๋ฅผ ํฌํ•จํ•˜์ง€ ์•Š๊ณ  flag.txt ํŒŒ์ผ ๋‚ด์šฉ์„ ์ฝ๊ธฐ ์œ„ํ•ด ์™€์ผ๋“œ์นด๋“œ๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ๋กœ ํ–ˆ๋‹ค.
  • ๋ช…๋ น์–ด์— cat ./dream/hack/hello/f*ag.txt๋ฅผ ์ž…๋ ฅํ–ˆ๋”๋‹ˆ flag๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ์—ˆ๋‹ค.

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[๋“œ๋ฆผํ•ต] Exercise: Docker  (0) 2025.02.23
natas3 write-up  (0) 2025.02.16
[๋“œ๋ฆผํ•ต] 64se64  (0) 2025.02.16
natas0 write-up  (0) 2025.02.10
[๋ชจ์˜์นจํˆฌ] | [RCity] 1.Linux ๋ช…๋ น์–ด - Operation RCity7  (0) 2025.02.02
728x90

[๋ฌธ์ œ]

https://dreamhack.io/wargame/challenges/872

 

64se64

Description "Welcome! ๐Ÿ‘‹"์„ ์ถœ๋ ฅํ•˜๋Š” html ํŽ˜์ด์ง€์ž…๋‹ˆ๋‹ค. ์†Œ์Šค ์ฝ”๋“œ๋ฅผ ํ™•์ธํ•˜์—ฌ ๋ฌธ์ œ๋ฅผ ํ’€๊ณ  ํ”Œ๋ž˜๊ทธ๋ฅผ ํš๋“ํ•˜์„ธ์š”. ํ”Œ๋ž˜๊ทธ ํ˜•์‹์€ DH{...} ์ž…๋‹ˆ๋‹ค.

dreamhack.io


[๋ฌธ์ œ ํ’€์ด]

  • ๋จผ์ € ์‚ฌ์ดํŠธ์— ์ ‘์†ํ•˜๋‹ˆ "Welcome!"์ด ์ถœ๋ ฅ๋˜๋Š” ๊ฑธ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.

  • f12๋ฅผ ์ด์šฉํ•ด ๊ด€๋ฆฌ์ž ๋ชจ๋“œ๋ฅผ ํ†ตํ•ด (์ƒ‰์ธ) ์†Œ์Šค์ฝ”๋“œ์—์„œ flag๋ฅผ ๋ณด์ด๋Š” value๋ฅผ ๋ฐœ๊ฒฌํ–ˆ๋‹ค.
  • name์„ ํ†ตํ•ด base64๋กœ ์ธ์ฝ”๋”ฉ ๋๋‹ค๋Š” ๊ฒƒ์„ ์œ ์ถ”ํ–ˆ๋‹ค.

https://www.base64decode.org/ko/

 

Base64 ๋””์ฝ”๋”ฉ ๋ฐ ์ธ์ฝ”๋”ฉ - ์˜จ๋ผ์ธ

Base64 ํ˜•์‹์—์„œ ๋””์ฝ”๋”ฉํ•ด๋ณด์„ธ์š”. ์•„๋‹ˆ๋ฉด ๋‹ค์–‘ํ•œ ๊ณ ๊ธ‰ ์˜ต์…˜์œผ๋กœ ์ธ์ฝ”๋”ฉํ•ด๋ณด์„ธ์š”. ์ €ํฌ ์‚ฌ์ดํŠธ์—๋Š” ๋ฐ์ดํ„ฐ ๋ณ€ํ™˜ํ•˜๊ธฐ์— ์‚ฌ์šฉํ•˜๊ธฐ ์‰ฌ์šด ์˜จ๋ผ์ธ ๋„๊ตฌ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.

www.base64decode.org

  • ๊ทธ๋ž˜์„œ, ์œ„ ์‚ฌ์ดํŠธ๋ฅผ ์ด์šฉํ•ด value๊ฐ’์„ ํ‹ฐ์ฝ”๋”ฉํ–ˆ๋”๋‹ˆ ํŒŒ์ด์ฌ ์ฝ”๋“œ๋ฅผ ์•Œ์•„๋ƒˆ๋‹ค.

  • ์œ„ ํŒŒ์ด์ฌ ์ฝ”๋“œ๋ฅผ ์‹คํ–‰ํ–ˆ๋”๋‹ˆ ํ”Œ๋ž˜๊ทธ๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ์—ˆ๋‹ค.

728x90

[๋ฌธ์ œ]

https://overthewire.org/wargames/natas/natas2.html

 

OverTheWire

We're hackers, and we are good-looking. We are the 1%. <!-- Please read and accept the Rules! --> Username: natas2 URL: http://natas2.natas.labs.overthewire.org

overthewire.org


[๋ฌธ์ œ ํ’€์ด]

  • ์ด์ „๊ณผ ๋‹ค๋ฅด๊ฒŒ ์•„๋ฌด๊ฒƒ๋„ ์กด์žฌํ•˜์ง€ ์•Š๋Š”๋‹ค๋Š” ๋ฌธ๊ตฌ๊ฐ€ ๋‚˜์™€์žˆ๋‹ค.

  • ์†Œ์Šค์ฝ”๋“œ๋ฅผ ๋ด๋„ ์ €๋ฒˆ์ฒ˜๋Ÿผ ์ฃผ์„์ฒ˜๋ฆฌ๋œ password๊ฐ€ ๋‚˜์™€์žˆ์ง€ ์•Š๊ณ  ์ด๋ฒˆ์—๋Š” img๊ฐ€ ์กด์žฌํ•˜๋Š” ๊ฒƒ์„ ํ™•์ธํ–ˆ๋‹ค.

  • ๊ทธ๋ž˜์„œ url์— ์ € img src๋ฅผ ์ถ”๊ฐ€๋ฅผ ํ•ด์คฌ๋”๋‹ˆ ๊ฒ€์€ ํ™”๋ฉด๋งŒ ๋‚˜์™”๋‹ค..

  • ์—ฌ๊ธฐ์„œ ์–ด๋–ป๊ฒŒ ํ•ด์•ผ ํ•˜๋‚˜ ์•Œ์•„๋ณด๋‹ˆ files ์ƒ์œ„ ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ์ด๋™ํ•  ์ˆ˜ ์žˆ๋‹ค๋Š” ์‚ฌ์‹ค์„ ์•Œ์•„๋ƒˆ๋‹ค.
  • ๊ทธ๋ž˜์„œ files ๋””๋ ‰ํ† ๋ฆฌ๋กœ ์ด๋™ํ–ˆ๋”๋‹ˆ users.txt๋ผ๋Š” ํŒŒ์ผ์ด ์กด์žฌํ•˜๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ๋‹ค.

  • ๊ทธ file์„ ์—ด์—ˆ๋”๋‹ˆ password๋ฅผ ์•Œ์•„๋‚ผ ์ˆ˜ ์žˆ์—ˆ๋‹ค.
728x90

[๋ฌธ์ œ]

https://overthewire.org/wargames/natas/natas1.html

 

OverTheWire

We're hackers, and we are good-looking. We are the 1%. <!-- Please read and accept the Rules! --> Username: natas1 URL: http://natas1.natas.labs.overthewire.org

overthewire.org


[๋ฌธ์ œ ํ’€์ด]

  • ์ด๋ฒˆ์—๋„ ๋ฌธ์ œ์— ์ฃผ์–ด์ง„ url์— ์ ‘์†์„ ํ–ˆ๊ณ  password๋Š” Level0์—์„œ ์–ป์€ password๋ฅผ ์ž…๋ ฅํ•ด ์ฃผ์—ˆ๋‹ค.
  • ์ด๋ฒˆ์—๋Š” password๋ฅผ ์ฐพ์•„์•ผ ํ•˜๋Š”๋ฐ ์šฐํด๋ฆญ์„ ๋ง‰์•„๋†“์•˜๋‹ค๊ณ  ํ•œ๋‹ค.

  • ์šฐ์„  ๋จผ์ € level0์ฒ˜๋Ÿผ F12๋ฅผ ๋ˆŒ๋Ÿฌ ํ•ด๋‹น ํŽ˜์ด์ง€์˜ html ์†Œ์Šค์ฝ”๋“œ๋ฅผ ํ™•์ธํ–ˆ๋‹ค.
  • 17๋ฒˆ ๋ผ์ธ์—์„œ ์ฃผ์„์ฒ˜๋ฆฌ ๋œ password๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.
  • ๋‹ค๋ฅธ ๋ธ”๋กœ๊ทธ๋ฅผ ์ฐธ๊ณ ํ•ด ๋ณด๋‹ˆ ๋‹ค๋ฅธ ๋ฐฉ๋ฒ•์œผ๋กœ url ์ฃผ์†Œ ์•ž์— view-source: ์ž…๋ ฅํ•ด์„œ ์†Œ์Šค๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค๊ณ  ํ•œ๋‹ค.

Flag: TguMNxKo1DSa1tujBLuZJnDUlCcUAPlI

728x90

[๋ฌธ์ œ]

[๋ฌธ์ œ ํ’€์ด]

  • ํ•ด๋‹น ๋ฌธ์ œ์—์„œ url๋ฅผ ์ ‘์†ํ•˜๋‹ˆ ํŒจ์Šค์›Œ๋“œ๋ฅผ ํŽ˜์ด์ง€์—์„œ ์ฐพ์œผ๋ผ๋Š” ๋ฌธ๊ตฌ๋ฅผ ํ™•์ธํ–ˆ๋‹ค.
  • ๊ทธ๋ž˜์„œ f12๋ฅผ ๋ˆŒ๋Ÿฌ ์ฒ˜์Œ์— ์ฟ ํ‚ค๋ฅผ ๋ดค๋‹ค๊ฐ€ ๊ทธ๋‹ค์Œ์— ํ•ด๋‹น ํŽ˜์ด์ง€์— ๋Œ€ํ•œ ์†Œ์Šค์ฝ”๋“œ๋ฅผ ๋ดค๋‹ค.

  • ์†Œ์Šค์ฝ”๋“œ๋ฅผ ์ž์„ธํžˆ ๋ณด๋‹ˆ 16๋ผ์ธ์—์„œ ์ฃผ์„๋ฌธ์œผ๋กœ password๊ฐ€ ๋‚˜์™€์žˆ๋Š” ๊ฒƒ์„ ํ™•์ธํ–ˆ๋‹ค.
728x90

[๋ฌธ์ œ]

 

๊ฐ ์ฑŒ๋ฆฐ์ง€ SSH ์ ‘๊ทผ๋ฒ•: ssh rcity<๋ฒˆํ˜ธ>@ctf.redraccoon.kr -p 31338

https://ctf.redraccoon.kr/challenges#Operation%20RCity7-10

 

RCity

 

ctf.redraccoon.kr

 

 


[๋ฌธ์ œ ํ’€์ด]

  • ๋ฌธ์ œ์—์„œ ๋„คํŠธ์›Œํฌ ํฌํŠธ์— ์—ฐ๊ฒฐํ•ด์„œ ํ”Œ๋ž˜๊ทธ๋ฅผ ์ „์†ก๋ฐ›๊ธฐ ์œ„ํ•ด gpt ๋„์›€์„ ๋ฐ›์•„ ์—ฌ๋Ÿฌ๊ฐ€์ง€ ์‹œ๋„๋ฅผ ํ•ด๋ณด์•˜๋Š”๋ฐ ๋ฌธ์ œ๊ฐ€ ํ•ด๊ฒฐ๋˜์ง€ ์•Š์•˜๋‹ค...
  • ์šฐ์„  ps ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•ด์„œ flag.py๋ฅผ ๋ฐœ๊ฒฌํ•ด์„œ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ๋‚˜ ํ–ˆ๋Š”๋ฐ password๋ฅผ ๋ชฐ๋ผ ์‹คํŒจํ–ˆ๋‹ค.
  • ๊ทธ๋Ÿฌ๋‹ค nmap localhost ๋ช…๋ น์–ด๋ฅผ ์‹คํ–‰ํ•ด์„œ ํ˜„์žฌ ์„œ๋ฒ„(๋กœ์ปฌํ˜ธ์ŠคํŠธ)์—์„œ ์—ด๋ ค ์žˆ๋Š” ๊ธฐ๋ณธ ํฌํŠธ๋ฅผ ํ™•์ธํ–ˆ๋Š”๋ฐ ๊ฑฐ๊ธฐ์„œ 9999๋ฒˆ ํฌํŠธ๋ฅผ ๋ฐœ๊ฒฌํ–ˆ๋‹ค.
  • ๊ทธ๋ž˜์„œ ํฌํŠธ์— ์—ฐ๊ฒฐํ•˜๊ฑฐ๋‚˜ ๋ฐ์ดํ„ฐ๋ฅผ ์ฃผ๊ณ ๋ฐ›์„ ๋•Œ ์‚ฌ์šฉํ•˜๋Š” ๋ช…๋ น์–ด์ธ nc ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•ด์„œ 9999๋ฒˆ ํฌํŠธ์— ์ ‘์†์„ ์‹œ๋„ํ–ˆ๋Š”๋ฐ ์‹œ๋„๋ฅผ ํ–ˆ๋”๋‹ˆ ๊ธ€์”จ๊ฐ€ ๊นจ์ง„ ๋ฌธ์ž์—ด์ด ๋‚˜์™€ ์–ด๋–ป๊ฒŒ ํ•ด์•ผ ํ• ์ง€... ๋‹ค๋ฅธ ๋ธ”๋กœ๊ทธ๋ฅผ ์ฐธ๊ณ ํ•˜๋‹ˆ ํ˜„์žฌ ์œ ์ €์˜ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ•˜๋ผ๋Š” ๋ฌธ์žฅ์ด์–ด์„œ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์ž…๋ ฅํ–ˆ๋”๋‹ˆ ํ”Œ๋ž˜๊ทธ๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ์—ˆ๋‹ค.
728x90

[๋ฌธ์ œ]

๊ฐ ์ฑŒ๋ฆฐ์ง€ SSH ์ ‘๊ทผ๋ฒ•: ssh rcity<๋ฒˆํ˜ธ>@ctf.redraccoon.kr -p 31338

https://ctf.redraccoon.kr/challenges#Operation%20RCity6-9

 

RCity

 

ctf.redraccoon.kr


[๋ฌธ์ œ ํ’€์ด]

  • ๋จผ์ € ์„œ๋ฒ„์— ์ ‘์†ํ•ด์„œ ํŒŒ์ผ ๋ชฉ๋ก์„ ํ™•์ธํ•˜๋‹ˆ flag ํŒŒ์ผ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.
  • ๊ทธ๋ž˜์„œ cat ๋ช…๋ น์–ด๋ฅผ ์ด์šฉํ•ด์„œ ํŒŒ์ผ ๋‚ด์šฉ์„ ํ™•์ธํ•ด๋ณด๋‹ˆ ์ฝ์„ ์ˆ˜๊ฐ€ ์—†์—ˆ๋‹ค..
  • ๊ทธ๋ž˜์„œ ์ด ํŒŒ์ผ์„ ์–ด๋–ป๊ฒŒ ์ฝ์–ด์•ผ ํ•˜๋‚˜ ํžŒํŠธ๋ฅผ ๋ณด๋‹ˆ  ์–ด๋–ค ํƒ€์ž…์˜ "file" ์ผ๊นŒ์š”? ๊ทธ๋ฆฌ๊ณ  ๊ทธ ํŒŒ์ผ ํƒ€์ž… "strings"๋ฅผ ์ฝ๊ธฐ ์œ„ํ•œ ์ปค๋งจ๋“œ๋Š” ๋ฌด์—‡์ผ๊นŒ์š”?๋ผ๊ณ  ํ•ด์„œ strings ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•ด ๋ณด๊ธฐ๋กœ ํ–ˆ๋‹ค.

  • strings flag๋ฅผ ์ž…๋ ฅํ•ด์ฃผ์—ˆ๊ณ  ์—ฌ๋Ÿฌ ๋ฌธ์ž์—ด ์ค‘์— ํ”Œ๋ž˜๊ทธ๋กœ ๋ณด์ด๋Š” ๋ฌธ์ž์—ด์„ ๋ฐœ๊ฒฌํ•ด์„œ ๋‹ต์„ ์ž…๋ ฅํ–ˆ๋”๋‹ˆ ๋ฌธ์ œ๋ฅผ ํ•ด๊ฒฐํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค!

+ Recent posts