[Cullinan #38] Add Metasploit โ˜ ๏ธ and 3 Injections ๐Ÿ’‰

Cullinan ๋กœ๊ทธ #38์ž…๋‹ˆ๋‹ค.

Change Log

New

Metasploit

๋“œ๋””์–ด Metasploit์— ๋Œ€ํ•œ ํ•ญ๋ชฉ์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์ œ ๋ธ”๋กœ๊ทธ ์ „์ฒด ๊ธ€์—์„œ๋„ ๋งŽ์€ ๋น„์ค‘์„ ์ฐจ์ง€ํ•˜๊ณ  ์žˆ์–ด์„œ ์•„์ง ๋ชจ๋“  ๋‚ด์šฉ์ด ๊ธฐ๋ก๋œ๊ฑด ์•„๋‹ˆ์ง€๋งŒ ์–ด๋Š์ •๋„ ํ‹€์€ ๊ฐ–์ถฐ์ง„ ์ƒํƒœ์ž…๋‹ˆ๋‹ค. ์ด์ œ ๋ˆ„๋ฝ๋œ ๋‚ด์šฉ๋“ค ์ฐพ์œผ๋ฉด์„œ ํฌํ•จ ์‹œํ‚ค๋„๋ก ํ• ๊ฒŒ์š”.

3 Injections

NoSQL, OGNL, EL์— ๋Œ€ํ•œ Injection์ด ์ถ”๊ฐ€๋˜์—ˆ์Šต๋‹ˆ๋‹ค. NoSQL์ด ์ฐจ์ง€ํ•˜๋Š” ๋น„์ค‘์ด ๊ต‰์žฅํžˆ ์ปค์„œ ์ƒ์„ธํ•˜๊ฒŒ ๋‚˜๋ˆŒ๊นŒ ํ•˜๋‹ค๊ฐ€ ๊ฐ€๊ธ‰์  ํ•œ ๋ฌธ์„œ์— ์ •๋ฆฌ๋˜๋Š”๊ฒŒ ์ข‹์„ ๊ฒƒ ๊ฐ™์•„ NoSQL ๋‹จ๊ฑด์œผ๋กœ ์ •๋ฆฌํ•˜์˜€์Šต๋‹ˆ๋‹ค. ์•„๋งˆ ๊ฐ NoSQL ์„œ๋น„์Šค์— ๋Œ€ํ•œ Injection ๋ฐฉ๋ฒ•๋“ค์€ ์ฐจ์ฐจ ์ถ”๊ฐ€ํ•ด์•ผํ•  ๊ฒƒ ๊ฐ™์Šต๋‹ˆ๋‹ค. (์ง€๊ธˆ์€ MongoDB, Redis, Memcached ์ •๋„๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค)

Update

XSS

SSXSS(Server-Side XSS) ๋‚ด์šฉ์ด ์ „์ฒด์ ์œผ๋กœ ๋ถ„์‚ฐ๋˜์–ด ์ž‘์„ฑ๋˜์—ˆ์—ˆ๋Š”๋ฐ, ์ด๋ฒˆ์— ํ•˜๋‚˜์˜ XSS ํƒ€์ž…์œผ๋กœ ์ถ”๊ฐ€ํ•˜๊ณ  ์ „์ฒด์ ์œผ๋กœ ๋‚ด์šฉ ๋ณด๊ฐ•ํ•˜์—ฌ ์ถ”๊ฐ€ํ•˜์˜€์Šต๋‹ˆ๋‹ค. ์ตœ๊ทผ์— ์ผํ•˜๋‹ค ๋งŒ๋‚œ ์ทจ์•ฝ์ ์ด๋ผ ๋ฐ˜๊ฐ‘๋„ค์š” :D

Others

๋‚˜๋จธ์ง€๋Š” ์ƒ๊ฐ๋‚˜๋Š”๋Œ€๋กœ ์—…๋ฐ์ดํŠธํ•œ ๋‚ด์šฉ๋“ค์ž…๋‹ˆ๋‹ค.

Conclusion

๋งค๋ฒˆ ๋Š๋ผ์ง€๋งŒ Injection ์ข…๋ฅ˜๊ฐ€ ์ •๋ง ๋ฌดํ•œํ•˜๋‹จ ๋Š๋‚Œ์„ ๋ฐ›์Šต๋‹ˆ๋‹ค. ๋ฌผ๋ก  ๋ญ ํ•˜๋‚˜ํ•˜๋‚˜ ์ถ”๊ฐ€ํ•˜๋ฉด์„œ ์ €๋„ ๋†“์ณค๋˜ ๋ถ€๋ถ„๋„ ๊ฐ™์ด ์ •๋ฆฌ๋˜๊ณ  ํ•˜๊ธฐ ๋–„๋ฌธ์— ์•ž์œผ๋กœ๋„ ๊ณ„์† ์ถ”๊ฐ€ํ•  ์ƒ๊ฐ์ด์—์š”.

Metasploit์€ ์ œ๊ฐ€ ์˜ˆ์ „์— ์—„์ฒญ๋‚œ ์• ์ •์„ ์คฌ์—ˆ๋˜ ๋„๊ตฌ๋ผ ๋ณด์—ฌ๋“œ๋ฆฌ๊ณ  ์‹ถ์€ ๋‚ด์šฉ์ด ๋งŽ์€๋ฐ ์นดํ…Œ๊ณ ๋ฆฌ๋ฅผ ๋‚˜๋ˆ„๊ธฐ ์ข€ ์• ๋งคํ•œ ๊ฒƒ๋“ค์ด ์žˆ์–ด ์ •๋ฆฌ๊ฐ€ ๋ฒ„๊ฒ๋„ค์š”. ๊ทธ๋ž˜๋„ ์ž˜ ์ตํ˜€๋‘๋ฉด Pentest์—์„  ์ข…์ข… ํ™œ์•ฝํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์ด์ฐธ์— ๋‚ด์šฉ์„ ์ข€ ๋งŽ์ด ๋ณด๊ฐ•ํ•ด๋ณผ ์ƒ๊ฐ์ž…๋‹ˆ๋‹ค ๐Ÿ˜Š

Metasploit์ด ๋ณดํ†ต Pentest ๋„๊ตฌ๋กœ ์•Œ๋ ค์ ธ ์žˆ๊ณ  ์ €๋„ ์ด๋Ÿฐ์ €๋Ÿฐ Pentest์—์„œ ์ตœ๋Œ€ํ•œ ์‚ฌ์šฉํ•˜๋Š” ํŽธ์ธ๋ฐ, ๊ผญ Pentest๊ฐ€ ์•„๋‹ˆ๋”๋ผ๋„ ์ผ๋ฐ˜์ ์ธ AppSec, Bugbounty์—์„œ๋„ ์ถฉ๋ถ„ํžˆ ํ™œ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ฌผ๋ก  Nuclei๋ผ๋Š” ๊ฐ•๋ ฅํ•œ ๋„๊ตฌ ๋•Œ๋ฌธ์— ์ด์ œ ์ทจ์•ฝ์  ์Šค์บ” ์„ฑ๋Šฅ์œผ๋กœ๋Š” ์•„๋งˆ ๋ฐ€๋ฆด ๊ฒƒ ๊ฐ™๊ธด ํ•˜์ง€๋งŒ ์ž์ฒด์ ์œผ๋กœ ์ œ๊ณตํ•˜๋Š” ๊ธฐ๋Šฅ๋“ค์ด ์›Œ๋‚™ ๊ฐ•๋ ฅํ•ด์„œ ๋Œ€๊ทœ๋ชจ ๋Œ€์ƒ์œผ๋กœ ํ…Œ์ŠคํŒ… ์ง„ํ–‰ํ•  ๋• ์•„์ง๊นŒ์ง€ ์ •๋ง ์ข‹์Šต๋‹ˆ๋‹ค.