[WarGame] Bandit, Level 13 → Level 14
실제 사내에서 운영 경험하면서, 방화벽 확인할때를 생각해보면 쉽다.
su가 아니라 ssh localhost로 들어가면 땡
→ sshkey를 이래서 보관 잘 해야하는 듯 했다.
Solving
bandit13@bandit:~$ ls -rtl
total 4
-rw-r----- 1 bandit14 bandit13 1679 Feb 21 22:02 sshkey.private # 키파일 확인
bandit13@bandit:~$ cat sshkey.private
-----BEGIN RSA PRIVATE KEY-----
MIIEpAIBAAKCAQEAxkkOE83W2cOT7IWhFc9aPaaQmQDdgzuXCv+ppZHa++buSkN+
... 중략 ...
/+aLoRQ0yBDRbdXMsZN/jvY44eM+xRLdRVyMmdPtP8belRi2E2aEzA==
-----END RSA PRIVATE KEY-----
bandit13@bandit:~$ telnet localhost 2220 # 방화벽 확인
Trying 127.0.0.1...
Connected to localhost.
Escape character is '^]'.
SSH-2.0-OpenSSH_8.9p1
Invalid SSH identification string.
Connection closed by foreign host.
bandit13@bandit:~$ ssh bandit14@localhost -p 2220 -i ./sshkey.private # ssh 접속
bandit14@bandit:~$ cat /etc/bandit_pass/bandit14
Refer