STUDY.md
  • ๋ฆฌ๋ˆ…์Šค ์ทจ์•ฝ์  ์ง„๋‹จ ์‹ค์Šต metasploitable2 - VNC(5900)
    2024๋…„ 05์›” 16์ผ 14์‹œ 25๋ถ„ 35์ดˆ์— ์—…๋กœ๋“œ ๋œ ๊ธ€์ž…๋‹ˆ๋‹ค.
    ์ž‘์„ฑ์ž: ๋ฐฉ์„ธ์—ฐ

    ๐Ÿณ๏ธ

    metasploitable2 ์ทจ์•ฝ์  - VNC (5900) 

     

    ๋ณธ ๊ฒŒ์‹œ๊ธ€์˜ ์‹ค์Šต์€ ํ•ด๋‹น ์‚ฌ์ดํŠธ๋ฅผ ์ฐธ๊ณ ํ•˜์˜€๋‹ค.

    https://github.com/Milkad0/Metasploitable-2

     

    ์ทจ์•ฝ์ ์— ๋Œ€ํ•œ ์ถ”๊ฐ€์ ์ธ ์กฐ์‚ฌ :

    https://www.rapid7.com/db/modules/auxiliary/scanner/vnc/vnc_login/

     

     


     

     

    ์‹ค์Šต ๋ชฉ์ .
    metasploitable2 ๊ฐ€์ƒ๋จธ์‹ ์˜ ์Šค์บ๋‹์„ ํ†ตํ•ด VNC ์ทจ์•ฝ์ ์„ ์•Œ์•„๋‚ด๊ณ , ์ด๋ฅผ exploit ํ•ด๋ณธ๋‹ค.

     

    ํ™˜๊ฒฝ์„ค์ •.
    ๊ณต๊ฒฉ์ž : kali linux
    ํ”ผํ•ด์ž : metasploitable2 (192.168.132.131)

     

    ํฌํŠธ ์Šค์บ๋‹

     

    ํฌํŠธ ์Šค์บ๋‹์„ ํ†ตํ•ด VNC (protocol 3.3)์— ์—ด๋ ค์žˆ๋Š” 5900 ํฌํŠธ๋ฅผ ํ™•์ธํ•˜์˜€๋‹ค.

     

     

     

     

     

      ์ƒ์„ธ ์Šค์บ๋‹ ๋ฐ Exploit  

     

    kali linux๋ฅผ ํ†ตํ•ด metasploit framework๋ฅผ ์‹คํ–‰ํ•ด์ฃผ์–ด ํ„ฐ๋ฏธ๋„ ์ฐฝ์„ ์ƒ์„ฑํ•œ๋‹ค.

     

    search vnc๋ฅผ ํ†ตํ•ด vnc์— ๊ด€ํ•œ ์ •๋ณด๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ์—ˆ๋Š”๋ฐ,

    ์ด ์ค‘ auxiliary/scanner/vnc/vnc_login์„ ํ™•์ธํ–ˆ๋‹ค.

    search vnc

     

     

     

     

    use auxiliary/scanner/vnc/vnc_login

    ์ด์ œ use ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด auxiliary/scanner/vnc/vnc_login ๋ชจ๋“ˆ์„ ์žฅ์ฐฉํ•ด์ค€๋‹ค.

     

     

    set rhosts 192.168.132.131

    rhosts์— ์‚ฌ์šฉ์ž์˜ ip ์ฃผ์†Œ๋ฅผ ์ ์šฉํ•ด์ฃผ์—ˆ๋‹ค.

     

     

     

    ๊ทธ๋ฆฌ๊ณ  ๊ณต๊ฒฉ์„ ์‹œ๋„ํ•œ๋‹ค.

    exploit

     

     

     

     

    exploit์— ์„ฑ๊ณตํ•˜๋ฉด ํ•ด๋‹น ๋‚ด์šฉ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

     

    [+] 192.168.132.131 : 5900 - 192.168.132.131 : 5900 - Login Successful: :password

     

    ๋กœ๊ทธ์ธ์ด ์ •์ƒ์ ์œผ๋กœ ์ˆ˜ํ–‰๋œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋‹ค.

     

     

     

    vncviewer 192.168.132.131

    ์ด์ œ metasploit framework๋ฅผ exitํ•ด ๋น ์ ธ๋‚˜์™€์ฃผ๊ณ ,

    vncviewer rhost ์ž…๋ ฅ์„ ํ†ตํ•ด vncviewer์— ์ ‘๊ทผํ•œ๋‹ค.

     

    ์ดํ›„ ๋น„๋ฐ€๋ฒˆํ˜ธ๋กœ password ๋ฅผ ์ž…๋ ฅํ•ด์ค€๋‹ค.

    exploit์„ ํ†ตํ•ด ์ทจ๋“ํ•œ password๋ฅผ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ž…๋ ฅํ•˜๋ฉด ๊ทธ๋ž˜ํ”ฝ ์ธํ„ฐํŽ˜์ด์Šค ์ฐฝ์„ ์–ป๋Š”๋‹ค.

     

     

     

     


     

     ์‹ค์Šต ๊ฒฐ๊ณผ 

     

     

    VNCํฌํŠธ์˜ root์— ์ •์ƒ์ ์œผ๋กœ ๋กœ๊ทธ์ธ๋œ ๊ฒƒ์ด ํ™•์ธ๋˜์—ˆ๋‹ค.

    whoami ๋ช…๋ น์–ด๋ฅผ ์ž…๋ ฅํ–ˆ์„ ๋•Œ root(๊ด€๋ฆฌ์ž)๋กœ ์ ‘์†๋˜์—ˆ์Œ์„ ํ™•์ธํ•˜์˜€๋‹ค.

     

    ํ•ด๋‹น ์ทจ์•ฝ์ ์ด ๋ฐœ์ƒํ•œ ์ด์œ ๋Š” ์ทจ์•ฝํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ ๋•Œ๋ฌธ์ด๋‹ค.

    ์ด๋ฅผ ๋ฐฉ์ง€ํ•˜๊ธฐ ์œ„ํ•˜์—ฌ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ๋”์šฑ ๊ฐ•๋ ฅํ•œ ๋น„๋ฐ€๋ฒˆํ˜ธ๋กœ ๋ณ€๊ฒฝํ•ด์•ผ ํ•œ๋‹ค.

     

     

     

     

     

     

     

    ๋Œ“๊ธ€