๐Ÿ’ญ Minji's Archive

[KT Cloud TechUp] NESSUS, Web Shell, Reverse Telnet, OWASP ZAP

October 14, 2025

NESUS

  • ์‹œ์Šคํ…œ/๋„คํŠธ์›Œํฌ/์›น์„œ๋ฒ„/ํด๋ผ์šฐ๋“œ ํ™˜๊ฒฝ๊นŒ์ง€ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ์ž๋™์œผ๋กœ ์ ๊ฒ€ํ•˜๊ณ  ๋ฆฌํฌํŒ…ํ•ด์ฃผ๋Š” ์ทจ์•ฝ์  ์Šค์บ๋„ˆ
  • Terrascan by tenable: ์ •์  ์ฝ”๋“œ ๋ถ„์„๊ธฐ. IAC (Infrastructure as Code)์˜ ๋ณด์•ˆ ์ •์ฑ… ์ค€์ˆ˜ ์—ฌ๋ถ€๋ฅผ ์ ๊ฒ€ํ•˜๋Š” ๋„๊ตฌ
  • ์ž๋™ํ™”๋œ ํŒŒ์ดํ”„๋ผ์ธ์—์„œ ๋™์ž‘ (๋ณด์•ˆ ์œ„๋ฐ˜ ์‚ฌํ•ญ์„ ํƒ์ง€ํ•˜์—ฌ ์•ˆ์ „ํ•˜์ง€ ์•Š์€ ์ธํ”„๋ผ๊ฐ€ ๋ฐฐํฌ๋˜๊ธฐ ์ „์— ๋ฌธ์ œ ํ•ด๊ฒฐ)
  • ์ทจ์•ฝ์  ์Šค์บ” ์ „์— ์ตœ๋Œ€ํ•œ ๋งŽ์€ ํƒ์ƒ‰์„ ํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•จ
  • ์˜ˆ์‹œ: Cookies.txt์˜ ์ž˜๋ชป๋œ ์˜ˆ์‹œ (cookies.txt๋Š” netscape ํ˜•ํƒœ๋กœ ์ถ”์ถœํ•ด์•ผ ํ•จ)
    let cookies = document.cookie.split(";").map(c => c.trim());
    let content = cookies.join("\n");
    console.log(content);
    - ์ทจ์•ฝ์ ์„ ๋ฐœ๊ฒฌํ•˜๊ณ  ๋‚˜๋ฉด ๋ฐœ๊ฒฌ๋œ ์ทจ์•ฝ์  CVE ๋ฒˆํ˜ธ๋ฅผ ๋Œ€์ƒ์œผ๋กœ ์กฐ์‚ฌํ•ด๋ณด๋ฉด ์ข‹์Œ
    • exploit-db์™€ ๊ฐ™์€ ์‚ฌ์ดํŠธ์—์„œ exploit์„ ๋‹ค์šด๋ฐ›์•„์„œ ๊ณต๊ฒฉ
    • metasploit์— payload ๋“ฑ ์„ธํŒ…๋œ exploit ๊ฒ€์ƒ‰ํ•ด๋ณด๊ณ  ๊ณต๊ฒฉ

Web Shell

  • ์›น ํŽ˜์ด์ง€์—์„œ ํ•ด๋‹น ์›น ์„œ๋ฒ„์—์„œ ๋‹ค์–‘ํ•œ ๋ช…๋ น์„ ์‹คํ–‰์‹œํ‚ฌ ์ˆ˜ ์žˆ๋Š” ์Šคํฌ๋ฆฝํŠธ ํŒŒ์ผ
  • ๋ณดํ†ต ๊ณต๊ฒฉ์ž๊ฐ€ ์›น ์„œ๋ฒ„์˜ ์ทจ์•ฝ์ ์„ ์ด์šฉํ•ด ์—…๋กœ๋“œํ•˜๊ณ  ์›น ์„œ๋ฒ„์— ์ œ์–ด๊ถŒ์„ ํš๋“ํ•˜๊ธฐ ์œ„ํ•ด ์‚ฌ์šฉ๋จ
  • ์ผ๋ฐ˜์ ์ธ ์‚ฌ์šฉ์ž๋“ค๊ณผ ๋™์ผํ•œ ์›น ์„œ๋น„์Šค ํฌํŠธ๋ฅผ ํ†ตํ•ด ์›น ์‰˜ ์—…๋กœ๋“œ ๋ฐ ๊ณต๊ฒฉ์ด ์ด๋ฃจ์–ด์ง€๊ธฐ ๋•Œ๋ฌธ์— ํƒ์ง€ ๋ฐ ์ฐจ๋‹จ์ด ๊นŒ๋‹ค๋กœ์›€
  • ์›น ์„œ๋ฒ„์—์„œ ์›น ์‰˜์„ ์‹คํ–‰์‹œ์ผœ์•ผ ํ•˜๊ธฐ ๋•Œ๋ฌธ์— ์„œ๋ฒ„ ์‚ฌ์ด๋“œ ์Šคํฌ๋ฆฝํŠธ (asp, jsp, php ๋“ฑ)์œผ๋กœ ์ œ์ž‘๋˜๊ณ  ์‚ฌ์šฉ๋˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์Œ.

Reverse Telnet

Telnet์ด๋ž€?

  • ์ธํ„ฐ๋„ท์ด๋‚˜ ๋กœ์ปฌ ์˜์—ญ ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ์— ์“ฐ์ด๋Š” ๋„คํŠธ์›Œํฌ ํ”„๋กœํ† ์ฝœ

Reverse Telnet์ด๋ž€?

  • ๋ณดํ†ต ๋„คํŠธ์›Œํฌ๋ฅผ ํ†ตํ•ด ๊ณต๊ฒฉ์„ ํ•˜๊ธฐ ์œ„ํ•ด์„œ๋Š” ๋ฐฉํ™”๋ฒฝ ๋“ฑ์„ ํ†ต๊ณผํ•ด์•ผ ํ•˜๋Š”๋ฐ inbound ํŒจํ‚ท์— ๋Œ€ํ•œ ์ •์ฑ…์ด ๊ฑธ๋ ค์žˆ๋Š” ์‹œ์Šคํ…œ์„ ๋šซ๊ธฐ๋Š” ์‰ฝ์ง€ ์•Š๋‹ค. (๋Œ€๋ถ€๋ถ„ ์›น์—์„œ ์‚ฌ์šฉํ•˜๋Š” 80๋ฒˆ ํฌํŠธ ์™ธ์—๋Š” ๋Œ€๋ถ€๋ถ„ ๋ง‰์•„๋‘ ) ํ•˜์ง€๋งŒ outbound ํŒจํ‚ท์— ๋Œ€ํ•ด์„œ๋Š” ๋ณดํ†ต ํŠน๋ณ„ํ•œ ์ •์ฑ…์„ ์„ค์ •ํ•ด์ฃผ์ง€ ์•Š๋Š”๋‹ค๋Š” ์ ์„ ์ด์šฉํ•œ๋‹ค.
  • ์ฆ‰ ๋ฐฉํ™”๋ฒฝ ๋‚ด์— ์กด์žฌํ•˜๋Š” ๋Œ€์ƒ์ž์—์„œ ๋ฐฉํ™”๋ฒฝ ์™ธ๋ถ€์˜ ๊ณต๊ฒฉ์ž ์ปดํ“จํ„ฐ๋กœ ํ…”๋„ท์„ ์ด์šฉํ•ด ์ ‘์†ํ•˜๋Š” ๊ธฐ์ˆ ์ด๋‹ค.
  • netcat(nc)๋ฅผ ์ด์šฉํ•˜๋Š”๋ฐ, netcat์ด๋ž€ tcp/udp๋ฅผ ์‚ฌ์šฉํ•ด ๋„คํŠธ์›Œํฌ ์—ฐ๊ฒฐ์„ ์ฝ๊ณ  ์“ฐ๋Š” ๋ฐ ์‚ฌ์šฉ๋˜๋Š” ์ปดํ“จํ„ฐ ๋„คํŠธ์›Œํ‚น ์œ ํ‹ธ๋ฆฌํ‹ฐ์ด๋‹ค. -l์€ listen mode, -p๋Š” ์—ด์–ด๋†“์„ ํฌํŠธ ์ง€์ •์ด๋‹ค.

๊ฐ„๋‹จ ์‹ค์Šต

  • victim, attacker: kali linux ํ™˜๊ฒฝ์œผ๋กœ ์ง„ํ–‰
  • ๊ณต๊ฒฉ์ž ip: 172.30.1.77
  • victim ip: 172.30.1.88

attacker pc์—์„œ nc -lvnp 8888์œผ๋กœ 8888๋ฒˆ ํฌํŠธ๋ฅผ ์—ด์—ˆ๋‹ค.

victim pc์—์„œ nc -vz 172.~~ 8888์œผ๋กœ ์›๊ฒฉ ์ ‘์†. ๊ทธ ํ›„ attacker pc์—์„œ ifconfig๋ฅผ ํ•˜๋ฉด victim pc์˜ ip๊ฐ€ ๋œฌ๋‹ค. (์œ„ ์‚ฌ์ง„ ์ฐธ๊ณ )

OWASP ZAP

  • OWASP: ๊ตญ์ œ ์›น ๋ณด์•ˆ ํ”„๋กœ์ ํŠธ
  • ZAP(Zed Attack Proxy)
    • ์›น ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์˜ ๋ณด์•ˆ ์ทจ์•ฝ์ ์„ ์ž๋™์œผ๋กœ ๊ฒ€์‚ฌํ•ด์ฃผ๋Š” ์˜คํ”ˆ์†Œ์Šค ๋„๊ตฌ
    • ๋ณด์•ˆ ๊ฒ€์‚ฌ๋ฅผ ์ˆ˜๋™์œผ๋กœ ํ•˜๋ฉด ์žŠ์–ด๋ฒ„๋ฆฌ๊ฑฐ๋‚˜, ๋ฐฐํฌ ์ดํ›„ ๋”ฐ๋กœ ํ•ด์•ผ ํ•˜๋ฏ€๋กœ ์ผ๊ด€์„ฑ์„ ์œ ์ง€ํ•˜๊ธฐ ์–ด๋ ค์›€
    • Github Actions๋ฅผ ํ™œ์šฉํ•˜๋ฉด ์ฝ”๋“œ๋ฅผ ๋ฐฐํฌํ•  ๋•Œ๋งˆ๋‹ค ์ž๋™์œผ๋กœ ์ทจ์•ฝ์  ์ ๊ฒ€์„ ์ˆ˜ํ–‰ํ•˜๊ณ , ๋ฆฌํฌํŠธ๋ฅผ ์ƒ์„ฑํ•ด ํ™•์ธํ•  ์ˆ˜ ์žˆ์–ด ์‹ค๋ฌด์—์„œ ๋งค์šฐ ์œ ์šฉํ•จ
    • ๋‹ค์šด๋กœ๋“œ ๋งํฌ: https://www.zaproxy.org/download/ (java.exe ํŒŒ์ผ ํ•„์š”) ์›นํ•ดํ‚น ์›Œ๊ฒŒ์ž„ ์‚ฌํ‹ฐ์œผ๋ฅผ ์Šค์บ”ํ•ด๋ณด์•˜๋‹ค.

dvwa ํ™˜๊ฒฝ์—์„œ๋Š” ์ด๋Ÿฐ ์‹์˜ ์‹ค์Šต๋„ ๊ฐ€๋Šฅํ•จ