Jastes 2022. 4. 6. 20:00

Level 1 ๋ฌธ์ œ ํ’€์ด

Keyword : find Backdoor Exploit

๋ฌธ์ œ ํŒŒ์•…

์œ„์™€ ๊ฐ™์ด hint๋ฅผ ํ™•์ธํ•˜๋ฉด setuid๊ฐ€ ์žˆ๋Š” backboor๋ฅผ ํ™•์ธ ํ•  ์ˆ˜ ์žˆ์ฃ 

setuid๋Š” ์ผ์‹œ์ ์œผ๋กœ ๊ถŒํ•œ์„ ๋ถ€์—ฌํ•˜๋Š” ์—ญํ• ์œผ๋กœ์จ, ์ด ๊ฒƒ์„ ํ™œ์šฉํ•ด ์ต์Šคํ”Œ๋กœ์ž‡์„ ํ•  ์ˆ˜ ์žˆ์–ด์š”

find ๋ช…๋ น์–ด๋ฅผ ํ™œ์šฉํ•ด ํŒŒ์ผ์„ ์ฐพ์•„์•ผํ•˜๋Š” ๋ฌธ์ œ์ž…๋‹ˆ๋‹ค.

find๋ช…๋ น์–ด ํ™œ์šฉ
๐Ÿ’กfind / -perm -4000 -user level2

์—ฌ๊ธฐ์„œ Tip
๐Ÿ’ก๋‚˜์ค‘์— ๋ฐฐ์šฐ๊ฒ ์ง€๋งŒ Permission denied๋ผ๋Š” ์—๋Ÿฌ๋ฅผ ์—†์ด ์ถœ๋ ฅํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์•Œ์•„๋ณด๋ฉด
$ find / -perm -4000 -user level2
์œ„์™€ ๊ฐ™์€ ๋ฐฉ๋ฒ•์œผ๋กœ ํ•˜๋ฉด ์—๋Ÿฌ๊ฐ€ ๋งŽ์ด ๋ฐœ์ƒํ•˜๋ฏ€๋กœ ์ด ์—๋Ÿฌ๋ฅผ ์ƒ๋žตํ•˜๋ ค๋ฉด
๋ช…๋ น์–ด ๋งจ ๋’ค์— 2>/dev/null ์ด๋ผ๋Š” ๋ช…๋ น์–ด๋ฅผ ๋„ฃ์–ด์ฃผ๋ฉด ๋œ๋‹ค

โ€ป ์œ ๋‹‰์Šค/๋ฆฌ๋ˆ…์Šค ์‹œ์Šคํ…œ์€ std(์ž…์ถœ๋ ฅ)์ด 0(์ž…๋ ฅ), 1(์ถœ๋ ฅ), 2(์—๋Ÿฌ)๋กœ ํ‘œํ˜„

์ฆ‰, ์‹œ์Šคํ…œ์— ์—๋Ÿฌ ๋ฐœ์ƒ์„ /dev/null๋กœ ๋ณด๋‚ด๋Š” ๋œป์œผ๋กœ(/dev/null โ‰’ ํœด์ง€ํ†ต)
$ find / -perm +4000 -user level2 2>/dev/null

์‰˜๋กœ ๋“ค์–ด๊ฐ€๊ธฐ ์œ„ํ•œ ๋ช…๋ น์–ด๋กœ ํฌ๊ฒŒ 4๊ฐ€์ง€ ์ •๋„ ์žˆ์–ด์š”

bin/shโ”‚bin/bashโ”‚shโ”‚bash

Tip Setuid
๐Ÿ’กํ•ด๊น”๋ฆฌ๊ธฐ ์‰ฌ์šด ๋น„์Šทํ•œ ์šฉ์–ด๋“ค ์ •๋ฆฌ
โ€ป์˜๋ฏธ
- SetUID : ์ผ๋ฐ˜์ ์œผ๋กœ ํŒŒ์ผ ์‹คํ–‰ ์‹œ ์‹คํ–‰์‹œํ‚จ ์‚ฌ์šฉ์ž์˜ ๊ถŒํ•œ์œผ๋กœ ์‹คํ–‰์ด ๋˜์ง€๋งŒ,
SetUID๊ฐ€ ์„ค์ •ํ•œ ํŒŒ์ผ๋กœ ์‹คํ–‰ํ•˜๋ฉด ์ผ์‹œ์ ์œผ๋กœ ํŒŒ์ผ์˜ ์†Œ์œ ์ž ๊ถŒํ•œ์œผ๋กœ ์‹คํ–‰๋จ

- SetGID : SetGID๊ฐ€ ์„ค์ •๋œ ํŒŒ์ผ์„ ์‹คํ–‰ํ•˜๋ฉด ํŒŒ์ผ์˜ ์†Œ์œ /๊ทธ๋ฃน๊ถŒํ•œ์„ ๊ฐ€์ง€๊ฒŒ ๋จ

- StickyBit : ๊ณต์œ ๋””๋ ‰ํ„ฐ๋ฆฌ์˜ ์˜๋ฏธ๋กœ ํŒŒ์ผ์„ ์ƒ์„ฑํ•˜๋ฉด ์ƒ์„ฑํ•œ ์‚ฌ๋žŒ์˜ ์†Œ์œ ๋กœ ์ƒ์„ฑ๋˜๋ฉฐ,
์‚ญ์ œ ๋˜ํ•œ ์ƒ์„ฑํ•œ ์‚ฌ๋žŒ๊ณผ root๋งŒ์ด ๊ฐ€๋Šฅ ํ•œ๋งˆ๋””๋กœ ๊ณต์œ ๋ฅผ ์ค‘์ ์ธ ์šฉ๋„


โ€ป์„ค์ • ๋ฐฉ๋ฒ•
- SetUID(SetGID, StickyBit)์€ ์ผ๋ฐ˜ perm๊ณผ๋Š” ๋ณ„๋„๋กœ ๊ทธ ๊ถŒํ•œ์ž๋ฆฌ๊ฐ€ ์กด์žฌํ•จ

- SetUID ์„ค์ • : chmod 4xxx ํŒŒ์ผ๋ช… (xxx๋Š” ์ผ๋ฐ˜ ๊ถŒํ•œ)
- SetGID ์„ค์ • : chmod 2xxx ํŒŒ์ผ๋ช… (xxx๋Š” ์ผ๋ฐ˜ ๊ถŒํ•œ)
- StickyBit ์„ค์ • : chmod 1xxx ๋””๋ ‰ํ† ๋ฆฌ๋ช… (xxx๋Š” ์ผ๋ฐ˜ ๊ถŒํ•œ)
* SetUID์™€ SetGID๋ฅผ ๋™์‹œ ์„ค์ • : chmod 6xxx ํŒŒ์ผ๋ช… (xxx๋Š” ์ผ๋ฐ˜ ๊ถŒํ•œ)

โ€ป์„ค์ • ํ™•์ธ ๋ฐฉ๋ฒ•(ls -al)
-rwsr-xr-x 1 root root 42972 Jan 10 10:45 FILE1
-rwxr-sr-x 1 root root 1422 Jan 10 10:45 FILE2
-rwsr-sr-x 1 root root 142972 Jan 10 10:45 FILE3
drwxrwxrwt 10 root root 4096 Feb 8 16:48 tmp


โ€ป ์ฐธ๊ณ ์‚ฌํ•ญ
- SetUID, SetGID, StickyBit๋Š” ํ•ด๋‹น ์ž๋ฆฌ์˜ ์ผ๋ฐ˜ ๊ถŒํ•œ์— ์‹คํ–‰ ๊ถŒํ•œ์ด ์žˆ์–ด์•ผ๋งŒ ์ ์šฉ๋จ
- SetUID(SetGID, StickyBit)๋Š” ๋Œ€๋ถ€๋ถ„ ์†Œ๋ฌธ์ž๋กœ ํ‘œ๊ธฐ
- ๋งŒ์•ฝ ๋Œ€๋ฌธ์ž๋กœ ํ‘œ๊ธฐ๋œ๋‹ค๋ฉด ์„ค์ •์€ ๋˜์–ด ์žˆ์ง€๋งŒ, ์ผ๋ฐ˜ ๊ถŒํ•œ์— ์‹คํ–‰ ๊ถŒํ•œ์ด ์„ค์ •์ด ์•ˆ๋ฌ๊ธฐ ๋•Œ๋ฌธ

์ •๋‹ต์˜ ๊ฒฐ๋ก ์€ level2 : hacker or cracker ์ด๋‹ค!

์ฐธ๊ณ ๋กœ ๊ฟ€ํŒ์œผ๋กœ ๋‹ค๋ฅธ ์‚ฌ์šฉ์ž ๋„˜์–ด๊ฐˆ๋• sudo level2์ด๋Ÿฐ ์‹์œผ๋กœ ํ•ด์š”


์ฐธ๊ณ  ์ž๋ฃŒ

 

PHP MYSQL ๋ฆฌ๋ˆ…์Šค ์„œ๋ฒ„ ๋ณด์•ˆ ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์ „๋ฌธ ์ปค๋ฎค๋‹ˆํ‹ฐ

๊ฐœ๋ฐœ์ž ์ปค๋ฎค๋‹ˆํ‹ฐ,PHP,MYSQL,๋ฆฌ๋ˆ…์Šค,์„œ๋ฒ„,๋ณด์•ˆ,ํ•ดํ‚น,์†Œ์Šค์ฝ”๋“œ,๊ฐœ๋ฐœ์ •๋ณด,๊ณต๊ฐœ์†Œ์Šค,ํ”„๋กœ๊ทธ๋ž˜๋ฐ ์ „๋ฌธ ์ปค๋ฎค๋‹ˆํ‹ฐ

howcode.co.kr

์ฐธ๊ณ  ์ด๋ฏธ์ง€

 

Sign free icons designed by amonrat rungreangfangsai

Download now this vector icon in SVG, PSD, PNG, EPS format or as webfonts. Flaticon, the largest database of free icons.

www.flaticon.com