๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
๋ณด์•ˆ/CTF

W@S 2023 CTF Write-up ๋ฌธ์ œํ’€์ด

by - ์˜คํŠธ - 2023. 4. 9.

W@S 2023 CTF ๋ผ์—… ๋ฌธ์ œ ํ’€์ด

 

1๋ฒˆ ~ 6๋ฒˆ๊นŒ์ง€์˜ ๋ฌธ์ œ ํ’€์ด์ž…๋‹ˆ๋‹ค.

(์„œ์ˆ ํ˜• ๋ฌธ์ œ๋„ ์žˆ๊ธฐ ๋•Œ๋ฌธ์— ์ •๋‹ต์ผ์ˆ˜๋„ ์•„๋‹์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค)

 

QR ์ฝ”๋“œ ์‚ฌ์ง„์„ ๋ฆฌ๋”๊ธฐ๋ฅผ ํ†ตํ•ด ์ธ์‹ํ•˜๋ฉด ‘aHR0cHM6Ly9uYXZlci5tZS94TTJ1c3luSQ==’ ๋ฌธ์ž์—ด ์ถœ๋ ฅ

ํ•ด๋‹น ๋ฌธ์ž์—ด์ด Base 64 ์ธ์ฝ”๋”ฉ๋œ ๊ฒƒ์ด๋ผ ์ƒ๊ฐ๋˜์–ด ๋””์ฝ”๋”ฉ (๋ณดํ†ต == ๋กœ ๋๋‚˜๋Š” ๊ฒฝ์šฐ Base 64 ์ธ์ฝ”๋”ฉ๋œ ๋ฌธ์ž์—ด์ด๊ธฐ ๋•Œ๋ฌธ)

https://naver.me/xM2usynl

-> ํ•ด๋‹น ๋งํฌ๋กœ ๊ตฌ๊ธ€์— ๊ฒ€์ƒ‰ํ•œ ๊ฒฐ๊ณผ ‘ํ•œ๊ตญ์—ฌ์„ฑ๊ณผํ•™๊ธฐ์ˆ ์ธ์œก์„ฑ์žฌ๋‹จ’ ๋„ค์ด๋ฒ„ ์ง€๋„๊ฐ€ ๋‚˜์˜ด

 


 

1) 3.39.31.69 ์ง์ ‘ ์ ‘์†

-> https://3.39.31.69/ ์ธํ„ฐ๋žฉ ์›น ์‚ฌ์ดํŠธ ์ฃผ์†Œ(https://interlab.or.kr/)

 

Interlab ์ธํ„ฐ๋žฉ | Between Technology and Society

์ธํ„ฐ๋žฉ์€ ๋””์ง€ํ„ธ ๋ณด์•ˆ ์ปจ์„คํŒ…, ๊ต์œก, ์—ฐ๊ตฌ, ์˜ˆ๋ฐฉ๊ฐ€์ด๋“œ ์ถœํŒ ๋“ฑ์„ ํ†ตํ•ด, ๋””์ง€ํ„ธ ํ™˜๊ฒฝ์„ ํ†ตํ•œ ์ธ๊ถŒ ๋ฐ ๊ณต์ตํ™œ๋™๋“ค์ด ์ง€์†๊ฐ€๋Šฅํ•  ์ˆ˜ ์žˆ๋„๋ก ๋•์Šต๋‹ˆ๋‹ค.

interlab.or.kr

2) OSINT ํ™œ์šฉ (https://ipinfo.io/3.39.31.69 / KISA WHOIS ๊ฒ€์ƒ‰)

-> ํ˜ธ์ŠคํŠธ ๋ช… : ec2-3-39-31-69.ap-northeast-2.compute.amazonaws.com

๋„๋ฉ”์ธ์ด amazon.com ์ธ ๊ฒƒ์„ ํ™•์ธ ๊ฐ€๋Šฅ / ์„œ์šธ ๋ฆฌ์ „(AWS Asia Pacific (Seoul) Region)

 

* Passive Scanning ๊ณต๋ถ€ ํ•„์š”

 


 

ํ—ค๋” ๋ฐ ์›๋ณธ๋‚ด์šฉ ํŒŒ์ผ๋งํฌ๋กœ ๋“ค์–ด๊ฐ€ ํ™•์ธ ํ•„์š”

 

1) ํ”ผ์‹ฑ ์ด๋ฉ”์ผ ์—ฌ๋ถ€ : O

2) ํ”ผ์‹ฑ ์ด๋ฉ”์ผ ์‚ฌ์œ  : ‘daemon@maryknoll.localdomain์˜ ๋„๋ฉ”์ธ์ด ํ—ˆ์šฉ๋œ ๋ณด๋‚ธ ์‚ฌ๋žŒ ํ˜ธ์ŠคํŠธ๋ฅผ ์ง€์ •ํ•˜์ง€ ์•Š์Œ’ -> ์ฆ‰, ๊ณต๊ฒฉ์ž๊ฐ€ ๋ณธ์ธ์˜ ์ฃผ์†Œ๋ฅผ ์ˆจ๊น€

3) ๊ณต๊ฒฉ์ž : daemon@maryknoll.localdomain (IP ์ฃผ์†Œ : 218.154.164.104)

4) ์–ด๋–ค ์•…์„ฑ ํŒŒ์ผ ๋˜๋Š” ๋งํฌ๊ฐ€ ์‚ฝ์ž…๋˜์–ด ์žˆ๋Š”์ง€ : ‘๋น„์ •์ƒ์ ์ธ ์ฟ ๊ธฐ ๋ชจ๋‘ ์‚ญ์ œ >’ ๋ฅผ ๋ˆ„๋ฅด๋ฉด ํ•ด๋‹น ๋งํฌ๋กœ ์ด๋™ํ•˜๊ฒŒ ๋งŒ๋“ฆ

ํ•ด๋‹น๋งํฌ: http://www.udcontest.com/bbs/login/verify.php?lxne=71b1x35&nh6p=51frgzmuk&2um6y=zzh&13ka1pkl=QwFMHwMREQNSBgELdgQEQQsDWRUVFFBQCRIaWFcLVhgUBVsWFhFQCUQeQgRYWQ8HEgRXMj9qJk8PWg8XQ0gfAx8eREcPVFpdAFNVA1s&3x7p1qcpt=7nqwvzyv9gbn6je&vb9b4ft0qf=cAUDEgFDSxB9ISUZRRwB

์ฐธ๊ณ  ๋งํฌ) https://www.linux.co.kr/bbs/board.php?bo_table=lecture&wr_id=3235 

 


 

Wireshark pcap ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œ ๋ฐ›์•„ ํ™•์ธ ๊ฐ€๋Šฅ

 

1) ๊ณต๊ฒฉ์ž : 192.168.56.101

2) ๊ณต๊ฒฉ์ •ํ™ฉ : ์„œ๋น„์Šค ๊ฑฐ๋ถ€ ๊ณต๊ฒฉ์œผ๋กœ ์ถ”์ • -> TCP ํ”„๋กœํ† ์ฝœ ๋‚ด ‘Dup ACK’ , ‘Retransmission’, ‘Out-of-Order’ ํŒจํ‚ท ํ™•์ธ

 

* Dup ACK : ์ถœ๋ฐœ์ง€(192.168.56.101)์—์„œ ๋งŽ์€ ์–‘์˜ ๋ฐ์ดํ„ฐ๋ฅผ ์š”์ฒญํ•ด์„œ ๋ชฉ์ ์ง€(192.168.56.1)์—์„œ ์„ธ๊ทธ๋จผํŠธ ์ˆœ์„œ๋ฅผ ๋‹ค๋ฅด๊ฒŒ ๋ฐ›์•„๋“ค์ž„

* Retransmission : Dup ACK ์‹คํŒจ ์‹œ TCP ํŒจํ‚ท ์žฌ์ „์†ก์„ ์š”๊ตฌํ•˜์—ฌ ๋ฐœ์ƒํ•จ

* Out-of-Order : ๋ชฉ์ ์ง€๊นŒ์ง€ ๋ฐ์ดํ„ฐ๋ฅผ ์ „์†กํ•˜๋Š” ๋„์ค‘์— ์ƒˆ ๊ฒฝ๋กœ๋กœ ์ „์†ก๋˜๋Š” ๊ฒฝ์šฐ์— ๋ฐœ์ƒํ•จ

(์ถœ์ฒ˜ : https://blog.innern.net/69)

 

-> Wireshark ๋‚ด ์บก์ฒ˜ ํ™”๋ฉด์„ ๋ณด๋ฉด ‘Dup ACK’ , ‘Retransmission’, ‘Out-of-Order’ ํ•ด๋‹น ํŒจํ‚ท๋“ค์€ ๋ชจ๋‘ 192.168.56.101(๊ณต๊ฒฉ)์—์„œ 192.168.56.1๋กœ ๋ณด๋‚ด๋Š” ๊ฒƒ์„ ์•Œ ์ˆ˜ ์žˆ์Œ

 


 

 

* ์ด๋ฏธ์ง€ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ : ๋””์ง€ํ„ธ ์นด๋ฉ”๋ผ์˜ ์ด๋ฏธ์ง€ ํŒŒ์ผ ์•ˆ์— ์ €์žฅ๋˜์–ด ์žˆ๋Š” ํŒŒ์ผ ํ˜•์‹ (https://www.sony.co.kr/electronics/support/articles/S500078506)

 

Exitftool ๋‹ค์šด๋กœ๋“œ (https://exiftool.org/)

exiftool ๋ช…๋ น์–ด๋ฅผ ํ†ตํ•ด ๋ฉ”ํƒ€ ๋ฐ์ดํ„ฐ ํ™•์ธ (exiftool 2.jpg)

 

์‚ฌ์šฉ๋œ ์นด๋ฉ”๋ผ(Device Model) : sRGB

์ •ํ™•ํ•œ ์ดฌ์˜์‹œ๊ธฐ(Profile Date Time) : 1998:02:09 06:49:00

 


 

 

any.run ์‚ฌ์ดํŠธ ๋‚ด Process Graph ํ™•์ธ

๊ฐ์—ผ๋œ ๊ณผ์ •์—์„œ ๋ถˆ๋Ÿฌ์˜จ ํŒŒ์ผ ์ด๋ฆ„ : server.exe

๊ฐ์—ผ๋œ ๊ณผ์ •์—์„œ ๋ถˆ๋Ÿฌ์˜จ ํŒŒ์ผ ์œ„์น˜ : C:\Users\admin\AppData\Local\Temp\server.exe

 

์ฐธ๊ณ  ๋งํฌ) https://malwareanalysis.tistory.com/73

'๋ณด์•ˆ > CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[HackCTF] Welcome_Forensics, Question? (forensics)  (0) 2021.05.29
[HackCTF] Who Am I?, QRCODE (misc)  (0) 2021.05.29
[N0Named] RE: xeh_desrev  (0) 2021.05.24
[N0Named] magicIMAGE  (0) 2021.05.24
[ctf-d] woodstock-1  (0) 2020.12.07