[UMassCTF2025] forensic_No Updates

2025. 4. 21. 09:55ยทCTF

๐Ÿ›ก๏ธ UMassCTF2025

UMass Amhers(๋งค์‚ฌ์ถ”์„ธ์ธ  ๋Œ€ํ•™๊ต ์• ๋จธ์ŠคํŠธ ์บ ํผ์Šค)์˜ 2025๋…„ CTF์ด๋‹ค.

๋Œ€ํšŒ๊ฐ€ ๋๋‚œ ํ›„์— Write-Up ์ž‘์„ฑ์ด ํ—ˆ์šฉ๋œ๋‹ค.

 

 

๐Ÿ” ๋ฌธ์ œ

๋‚˜๋Š” ์ปดํ“จํ„ฐ๋ฅผ ์—…๋ฐ์ดํŠธํ•˜๋Š” ๊ฑธ ๋ฏฟ์ง€ ์•Š์•„.
์‹œ๊ฐ„๋งŒ ๋„ˆ๋ฌด ์˜ค๋ž˜ ๊ฑธ๋ฆฌ์ž–์•„!
๊ฒŒ๋‹ค๊ฐ€ ์•„๋ฌด๋„ ๋‚  ํ•ดํ‚น ๋ชป ํ•ด — ๋‚˜ ์ข‹์€ ๋น„๋ฐ€๋ฒˆํ˜ธ ์“ฐ๊ฑฐ๋“ !

 

 

โœ๏ธ Write-Up

๋ฌธ์ œ ๋‚ด์šฉ์„ ํ†ตํ•ด ๋‹ค์Œ์„ ์ถ”๋ก ํ•  ์ˆ˜ ์žˆ๋‹ค.

  • ์—…๋ฐ์ดํŠธ ํ•˜์ง€ ์•Š์€ ์‹œ์Šคํ…œ ์‚ฌ์šฉ
  • ์ข‹์€ ๋น„๋ฐ€๋ฒˆํ˜ธ ์‚ฌ์šฉํ•œ๋‹ค๊ณ  ์ž๋ถ€ → pcap ํŒŒ์ผ ๋‚ด์— ๋น„๋ฐ€๋ฒˆํ˜ธ ๋…ธ์ถœ ๊ฐ€๋Šฅ์„ฑ ๆœ‰

 

์ผ๋‹จ pcapํŒŒ์ผ์„ wireshark๋กœ ์—ด์–ด๋ณด์ž.

 

๋จผ์ €, ์–ด๋–ค ํ”„๋กœํ† ์ฝœ์ด ์‚ฌ์šฉ๋˜์—ˆ๋Š”์ง€ [ํ†ต๊ณ„] - [ํ”„๋กœํ† ์ฝœ ๊ณ„์ธต ๊ตฌ์กฐ] ๋กœ ํ™•์ธํ•ด๋ณด์•˜๋‹ค.

๊ทธ๋žฌ๋”๋‹ˆ FTP๊ฐ€ ๋ˆˆ์— ๋„์—ˆ๋‹ค. FTP๋Š” ํ‰๋ฌธ์œผ๋กœ ํ†ต์‹ ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ๋ฐ์ดํ„ฐ๊ฐ€ ๊ทธ๋Œ€๋กœ ๋…ธ์ถœ๋˜์—ˆ์„ ๊ฐ€๋Šฅ์„ฑ์ด ํฌ๋‹ค.

 

ํ•„ํ„ฐ์— `ftp` ๋ฅผ ์ ์šฉ์‹œ์ผœ๋ดค๋”๋‹ˆ `Please specify the password` ๋ผ๋Š” ์ˆ˜์ƒํ•œ ๋ฌธ์ž์—ด์„ ๋ฐœ๊ฒฌํ•˜์˜€๋‹ค.

 

ํ•ด๋‹น ํŒจํ‚ท์„ ์šฐํด๋ฆญ ํ•˜์—ฌ [๋”ฐ๋ผ๊ฐ€๊ธฐ] - [TCP ์ŠคํŠธ๋ฆผ]์„ ๋ˆŒ๋Ÿฌ ํ™•์ธํ•ด๋ณด์•˜๋”๋‹ˆ `vsFTPd 2.3.4` ์—์„œ `VTVM` ์ด๋ผ๋Š” user๋ช…์œผ๋กœ ๋กœ๊ทธ์ธ์„ ์‹œ๋„ํ•œ ๊ฒƒ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์—ˆ๋‹ค.

 

vsFTPd 2.3.4์˜ ์ทจ์•ฝ์ ์„ ๊ตฌ๊ธ€๋ง ํ•ด๋ดค๋”๋‹ˆ CVE-2011-2523์œผ๋กœ ์œ ๋ช…ํ•œ ๊ฒƒ ๊ฐ™์•˜๋‹ค.

ํ•ด๋‹น CVE๋ฅผ ๊ฒ€์ƒ‰ํ•ด๋ดค๋”๋‹ˆ ํฌํŠธ 6200์— ์‰˜์„ ์—ด์–ด์ฃผ๋Š” ๋ฐฑ๋„์–ด ์ทจ์•ฝ์ ์ด๋ผ๊ณ  ํ•œ๋‹ค.

๋”ฐ๋ผ์„œ 6200 ํฌํŠธ๋ฅผ ๊ฒ€์ƒ‰ํ•ด๋ณด์ž

https://nvd.nist.gov/vuln/detail/CVE-2011-2523

 

NVD - CVE-2011-2523

CVE-2011-2523 Detail Modified This CVE record has been updated after NVD enrichment efforts were completed. Enrichment data supplied by the NVD may require amendment due to these changes. Description vsftpd 2.3.4 downloaded between 20110630 and 20110703 co

nvd.nist.gov

 

`tcp.port == 6200` ์œผ๋กœ ํ•„ํ„ฐ๋ฅผ ๊ฑธ์–ด์„œ ๊ฒ€์ƒ‰ํ•ด๋ดค๋‹ค. 

 

๊ทธ๋ฆฌ๊ณ  tcp ์ŠคํŠธ๋ฆผ ๋”ฐ๋ผ๊ฐ€๊ธฐ๋ฅผ ํ•˜๋ฉด ๊ณต๊ฒฉ์ž๊ฐ€ ์ˆ˜ํ–‰ํ•œ ๋ช…๋ น์–ด๋ฅผ ๋ณผ ์ˆ˜ ์žˆ๊ณ , ๋งจ ๋งˆ์ง€๋ง‰์— ํ”Œ๋ž˜๊ทธ๊ฐ€ ํ‰๋ฌธ์œผ๋กœ ๋…ธ์ถœ๋˜์–ด ์žˆ๋Š” ๊ฒƒ์„ ๋ณผ ์ˆ˜ ์žˆ๋‹ค.

 

 

๐Ÿšฉ ํ”Œ๋ž˜๊ทธ

UMASS{n07_ag41n_d4mn_y0u_m3t4spl017}

์ €์ž‘์žํ‘œ์‹œ ๋น„์˜๋ฆฌ (์ƒˆ์ฐฝ์—ด๋ฆผ)

'CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€

[Blue team CTF] Yellow RAT Lab  (0) 2025.05.28
[UMassCTF2025] forensic_Mascrotrace  (1) 2025.04.21
picoCTF 2021 | information  (0) 2022.06.22
picoCTF 2021 | Mod 26  (0) 2022.06.22
picoCTF 2021 | Wave a flag  (0) 2022.06.22
'CTF' ์นดํ…Œ๊ณ ๋ฆฌ์˜ ๋‹ค๋ฅธ ๊ธ€
  • [Blue team CTF] Yellow RAT Lab
  • [UMassCTF2025] forensic_Mascrotrace
  • picoCTF 2021 | information
  • picoCTF 2021 | Mod 26
602zzang
602zzang
  • 602zzang
    yks_STUDY
    602zzang
  • ์ „์ฒด
    ์˜ค๋Š˜
    ์–ด์ œ
    • ๋ถ„๋ฅ˜ ์ „์ฒด๋ณด๊ธฐ (77)
      • Programming Language (36)
        • C (15)
        • PYTHON (9)
        • RUST (12)
      • Reverse Engineering (3)
      • OS (17)
        • LINUX (17)
      • ๋ณด์•ˆ ์ด์Šˆ (6)
      • Digital Forensics (1)
      • CTF (8)
      • ๊ธฐํƒ€ (6)
  • ๋ธ”๋กœ๊ทธ ๋ฉ”๋‰ด

    • ํ™ˆ
    • ํƒœ๊ทธ
    • ๋ฐฉ๋ช…๋ก
  • ๋งํฌ

  • ๊ณต์ง€์‚ฌํ•ญ

  • ์ธ๊ธฐ ๊ธ€

  • ํƒœ๊ทธ

    python
    ํŒŒ์ด์ฌ
    rust
    rustling
    ๋“œ๋ฆผํ•ต
    ๋ณด์•ˆ๋™ํ–ฅ
    ๋ณด์•ˆ์ด์Šˆ
    ์†Œ์ผ“ ํ†ต์‹ 
    cyberdefenders
    bandit
    ๋ฐฑ์ค€
    Rocky Linux
    c
    TeamH4C
    ์ฝ”๋“œ์—…
    ๋นก๊ณตํŒŸ
    umassctf2025
    P4C
    ๊ณต๊ธ‰๋ง
    picoCTF
  • ์ตœ๊ทผ ๋Œ“๊ธ€

  • ์ตœ๊ทผ ๊ธ€

  • hELLOยท Designed By์ •์ƒ์šฐ.v4.10.0
602zzang
[UMassCTF2025] forensic_No Updates
์ƒ๋‹จ์œผ๋กœ

ํ‹ฐ์Šคํ† ๋ฆฌํˆด๋ฐ”