LINEä¹ã£åãè©æ¬ºãæ¥ãã®ã§ã¢ã¯ã»ã¹å ãç¹å®ãã¦ã¿ã
2014å¹´08æ04æ¥18ï¼30é ã次ã®æ¥ã®è©¦é¨åå¼·ããã¦ããã¨ä¸éã®DMãè±ç°ããï¼@decoy_serviceï¼ããå±ãã¾ããã
ï¼ï¼
ã¨ãããã¨ã§ããã£ã¦ã¿ã¾ããã
å æ¥SECCON Onlineã§ã½ã¼ã·ã£ã«ããã¯ã¨ããåé¡ãããã¾ããããã¾ãããããªå½¢ã§å®è·µãããã¨ã«ãªãã¨ã¯ã
LINEã®ããã¨ãã確èªãã
ä»åã¯WebMoneyã®è¦æ±ã§ã¯ãªããiTunesã«ã¼ãã®è¦æ±ã ã£ãããã§ããã©ãã©ã¤ãã¼ããï¼
ããã¾ã§ã®ãä½ãã¦ã¾ããï¼å¿ããã§ããï¼æä¼ã£ã¦ããã£ã¦ããã§ããï¼ãã§ã¯ãªããã¡ãã£ã¨éãæ§åãã¡ãªã¿ã«æç« ã¯è±ç°ããï¼@decoy_serviceï¼ã§ãã
ã¨ããã20000Pt à 3ã£ã¦ãªããªãã«ã¬ã¡ã¤ã奴ã§ããã
ãµã¼ãã¼ãç¨æãã
ãµã¼ãã¼ã¯VPSãµã¼ãã¼ã使ç¨ãã¾ãããã¨ããããNetcatã§tcpæ¥ç¶ãå¾ ã¡åããã¾ãã
$ mkdir web $ cd web $ sudo nc -l 80
rootã§èµ·åããã®ã¯å°ã ä¸å®ã§ããããã¼ãã80çªãããªãã¨æªãã¾ãã¡ããã®ã§80çªã§å¾ ã¡åããã¾ãã
ã¨ããããæ¥ç¶ããããã°ä½ã§ãè¯ãã£ãã®ã§ãã¬ã¹ãã³ã¹ã¯ä½ããã¦ãã¾ããã
ãã±ããããã£ããã£ãã
ncã®ã¿ã ã¨ãããã¯åå¾åºæ¥ã¾ãããæ¥ç¶å IPãä¸æãªã®ã§tcpdumpã§ãã±ããã®ãã£ããã£ããããã¨ã«ãã¾ãããX-Forwarded-forã«è¨è¿°ããã¦ããå ´åãããã¾ããããªãã£ãæã®ããã«ã
$ sudo tcpdump -n -i eth0 -s 0 -w dump.cap
wiresharkã§éããå½¢å¼ã§ä¿åãã¦ãã¾ããããã§IPã¢ãã¬ã¹ã¨ãããæ å ±ãåå¾ã§ãã¾ãã
ã²ãããå¾ ã¤
è±ç°ããã«URLãéä¿¡ããå¾ ã¤ã
webmoneyãã¨ããååã«ãã¦ãã¾ã£ãã®ã¯ã¡ãã£ã¨ãã¹ã ã£ãããã
ç¯äººãè¸ãã§ãããã®ãå¾ ã¡ã¾ã
ç¯äººããã®ã¢ã¯ã»ã¹ï¼
80çªãã¼ã(ãããWebãµã¼ãã¼ãåãã¦ãããµã¼ãã¼)ã§ãã£ã¦ããã®ã§ãéä¸botãã訪åè ãããã¢ã¯ã»ã¹ãã¦ãã¦ããã¡ããã¡ãã«ãªã£ã¦ãã¾ã£ã¦ã¾ããããç¯äººã¨æãããIPããã¢ã¯ã»ã¹ãããã¾ããã
ããï¼ããã¯ï¼
/ï¼ã«ã¼ãï¼ã¸ã®ã¢ã¯ã»ã¹ãªã®ã§æåã¯botããªã¨æã£ãã®ã§ãããRefererãbaido/s?=wwwã¨ãªã£ã¦ãã¦UAãMozilla/4.0ãªã®ã§ã人åã§ã®å ¥åã£ã½ããbaidoãå©ç¨ãã¦ããã¨ãããã¨ã¯ä¸å½ããã®ã¢ã¯ã»ã¹ããªã
ã¡ãã£ã¨ã ã調ã¹ã¦ã¿ãã
ping
$ ping 61.135.***.*** PING 61.135.***.*** (61.135.***.***) 56(84) bytes of data. ^C --- 61.135.***.*** ping statistics --- 5 packets transmitted, 0 received, 100% packet loss, time 4717ms
å±ãã¾ããã§ããã
DNSã«åãåãã
$ dig @8.8.8.8 -x 61.135.***.*** ; <<>> DiG 9.8.2rc1-RedHat-9.8.2-0.23.rc1.el6_5.1 <<>> @8.8.8.8 -x 61.135.***.*** ; (1 server found) ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NXDOMAIN, id: 35183 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0 ;; QUESTION SECTION: ;***.***.135.61.in-addr.arpa. IN PTR ;; AUTHORITY SECTION: 135.61.in-addr.arpa. 645 IN SOA ns.bta.net.cn. root.ns.bta.net.cn. 2014032601 28800 7200 604800 28800 ;; Query time: 49 msec ;; SERVER: 8.8.8.8#53(8.8.8.8) ;; WHEN: Tue Aug 5 23:01:28 2014 ;; MSG SIZE rcvd: 99
[08/05追è¨]
$ dig -xã§æ¤ç´¢ãã¦ããªãã£ãã®ã§ä¿®æ£ãã¾ããã
è¦ã¤ãããªãã£ãã
whois
$ whois 61.135.***.*** [Querying whois.apnic.net] [whois.apnic.net] % [whois.apnic.net] % Whois data copyright terms   http://www.apnic.net/db/dbcopyright.html % Information related to '61.135.0.0 - 61.135.255.255' inetnum:       61.135.0.0 - 61.135.255.255 netname:       UNICOM-BJ descr:         China Unicom Beijing province network descr:         China Unicom country:       CN admin-c:       CH1302-AP tech-c:        SY21-AP mnt-by:        APNIC-HM mnt-lower:     MAINT-CNCGROUP-BJ mnt-routes:    MAINT-CNCGROUP-RR status:        ALLOCATED PORTABLE mnt-irt:       IRT-CU-CN changed:       [email protected] 20031112 changed:       [email protected] 20040927 changed:       [email protected] 20050112 changed:       [email protected] 20060124 changed:       [email protected] 20090507 changed:       [email protected] 20090508 source:        APNIC irt:           IRT-CU-CN address:       No.21,Jin-Rong Street address:       Beijing,100140 address:       P.R.China e-mail:        [email protected] abuse-mailbox: [email protected] admin-c:       CH1302-AP tech-c:        CH1302-AP auth:          # Filtered mnt-by:        MAINT-CNCGROUP changed:       [email protected] 20101110 changed:       [email protected] 20101116 source:        APNIC person:        ChinaUnicom Hostmaster nic-hdl:       CH1302-AP e-mail:        [email protected] address:       No.21,Jin-Rong Street address:       Beijing,100033 address:       P.R.China phone:         fax-no:        country:       CN changed:       [email protected] 20090408 mnt-by:        MAINT-CNCGROUP source:        APNIC person:        sun ying address:       fu xing men nei da jie 97, Xicheng District address:       Beijing 100800 country:       CN phone:         fax-no:        e-mail:        [email protected] nic-hdl:       SY21-AP mnt-by:        MAINT-CNCGROUP-BJ changed:       [email protected] 19980824 changed:       [email protected] 20060717 changed:       [email protected] 20090630 source:        APNIC % This query was served by the APNIC Whois Service version 1.69.1-APNICv1r0 (WHOIS3)
China Unicom Beijing province networkãææãã¦ãã模æ§ãå京ã®ãããã¤ãã£ã½ãã
webmoneyãã«ã¢ã¯ã»ã¹ããªãã£ãã®ã¯ãè¦æãã¦ãã¨ãããã¨ãªãã ãããï¼
確å®ã£ã½ãããã©ãæ®éã®è¨ªåè ã®å¯è½æ§ããããããã£ã¨è©³ãã調ã¹ã¦ã¿ãã
å¥ã®ãã¡ã¤ã³ã§ãã£ã¦ã¿ãã
zipsan.pwã§è¸ã¾ãã¾ããããç»åãè¦ããªãã®ã§åéããã¨è¨ã£ã¦ããä¸ã¤ã®ãã¡ã¤ã³ãè¸ã¾ããã
ç¯äººã¯/ã¸ã®ã¢ã¯ã»ã¹ããã¦ãããããªã®ã§ãä»åã¯/ã¸ã®ã¢ã¯ã»ã¹ããã¦ãæªãã¾ããªãããã«ãUploaderãè£ ã£ã¦ã¿ãã
$ python3 -c 'import http.server; http.server.HTTPServer((&quot;&quot;, 80), http.server.CGIHTTPRequestHandler).serve_forever()'
ncããã¡ãã£ã¨ç¡çããã ã£ãã®ã§pythonã§WebServerãã¦ã¾ããã
URLã¯http://sukumizu.moe/upload/142775/webmoney-2342.jpgã«ãã¾ããã
ãã¡ã¤ã«ã¢ãããã¼ãã¼ : KENT-WEB CGI/Perl ããªã¼ã½ãããåèã«ããã¦ãããã¾ãããï¼é©å½ããï¼
tcpdumpããã¤ã¤ãå¾ æ©
ã¾ãå¾ ã¤
botãªã®ãã人ããã£ã¦ããã®ãããããªãããã©è¡åãé ãç¯äººã
ããã¨ã»ã»ã»
éåºããã¦ãã¾ãã¾ããã
ã¢ã¯ã»ã¹ãããã¾ããã§ãããæ²ãã¿ã
èå¯ãªã©
ä»åã¯å¤å°ä¸ç¢ºå®ã§ããç¯äººã¨æãããIPãåå¾åºæ¥ãã®ã§ååããªã¨æãã¾ãã確å®ã§ã¯ãªããã©ã
確å®ãããããã«ã¯ã¢ã¯ã»ã¹ããã£ãæã«ããéåºãããããã«ã天å®éäºä»¶ãã¨æ¸ãã¦ããã®ãããã®ãããããªããæ¢èªã«ãªã£ãã¿ã¤ãã³ã°ã¨æ¯è¼ããã°è¯ãããã
ãã¨ã¯ãæªãã¾ããªããããªURLãéããã¨ãéè¦ãªã®ãããä»åã¯ãªãã¡ã©ã«baido/s?=wwwã¨ã¤ãã¦ããï¼wwwã®æ¤ç´¢ã¯ã¼ãã§ã¯http://zipsan.pw/ã¯è¡¨ç¤ºãããªãï¼ã®ã§ãããã¥ã¡ã³ãã«ã¼ãã¢ã¯ã»ã¹ã§ãç¯äººã®ç·ãæ¿åã¨ãã¾ãããããããããªãå ´åã¯/webmoneyï½ã§å¤å¥ããå¿ è¦ãããã®ã§ç¢ºå®ã«ç¸æãè¸ãã ã¨åãããããªURLã«ããªãã¨ãããªãã§ããã
éã«èªåãæ»æè ã®ç«å ´ï¼ã¨ãããããä¸è¬ã¦ã¼ã¶ã¼ã®ç«å ´ï¼ã«ç«ã£ã¦èããã¨ãæªãããªURLãè¸ãéã¯Aguse, AguseGatewayãªã©ã®ã¦ã§ãæ¢æ»ãµã¼ãã¹ããã¼ã«ã使ã£ã¦ç¢ºèªãã¦ããã«ããã¨ãã¸ã£ã³ãå ãå±éºãµã¤ãã§ãå®å¿ã§ãã
ãã¨ãIPã¢ãã¬ã¹ã®èª¿æ»ã¯ping, DNSæ¤ç´¢, whoisãããã«ãã¦ããã¾ãããï¼ã³ã¬ä»¥ä¸ã¯ä¸æ£ã¢ã¯ã»ã¹æ³ã«æµè§¦ããï¼ãã®ãããã®ç·å¼ãã¯ããããããªãã調ã¹ã¦ããã...ï¼80çªãã¼ãã¨22çªãã¼ãã«ã¯æ¥ç¶ãã¦ã¿ã¾ãããã¾ããéãã¦ãªãã§ãããã
é常ã«æ¥½ãããã®ã§è¯ãã£ãã
ä»åº¦ãããããæã®ããã«Uploaderãè£ ã£ãå½ãµã¤ãã§ãä½ã£ã¦æºåãã¦ããã