Microservices (200)

Bร i nร y chแป cho ta ARN Role, ฤแป tรฌm hiแปu ARN Role lร gรฌ vร cรกch dรนng nรณ nhฦฐ thแบฟ nร o, cรกc bแบกn cรณ thแป tham khแบฃo:
ฤแป sแปญ dแปฅng ฤฦฐแปฃc ARN Role mรฌnh sแบฝ assume role vแปi mแปt credentials bแบฅt kแปณ, mรฌnh sแบฝ sแปญ dแปฅng credentials ฤรฃ cรณ tแปซ bร i trฦฐแปc
Ta sแบฝ cรณ file configure nhฦฐ sau

Tแปซ config nร y mรฌnh sแบฝ assume role cho cloud1 cรณ thแป truy cแบญp ฤฦฐแปฃc resources mร role cho phรฉp vแปi cmd sau:

Khi cรณ ฤฦฐแปฃc key rแปi thรฌ configure nhฦฐ bร i 1 lร ฤฦฐแปฃc

ฤแบงu tiรชn mรฌnh check policy ฤแป xem mรฌnh cรณ thแป lร m ฤฦฐแปฃc gรฌ vแปi role ฤแป cho

Nhรฌn แป trรชn thรฌ ta biแบฟt ฤฦฐแปฃc:
Ta cรณ thแป thแปฑc thi RunTask vแปi ECS
Ta cรณ thแป enum IAM vร EC2
Ta cรณ thแป thแปฑc hiแปn PassRole. Passrole lร tรญnh nฤng cho phรฉp cแบฅp quyแปn cho user truy cแบญp ฤแบฟn role mร cแปฅ thแป แป ฤรขy lร 2 role
role/TetCtf2Stack-EcsExecutionRoleFD93B7A2-O8bY2QagMK25vรrole/TetCtf2Stack-CtfTaskDefTaskRoleD17F896A-vJxGKfIFhChHCuแปi cรนng ta cรณ thแป check logs (lรบc nร y mรฌnh khรดng rรต log nร y lร log gรฌ)
Note: ฤแป รฝ kแปน thรฌ mแปi action mร ta cรณ quyแปn thแปฑc hiแปn ฤแปu cรณ region lร eu-west-2 . Do ฤรณ ta phแบฃi configure region lแบกi thร nh eu-west-2
Mรฌnh sแบฝ ฤi vร o tแปซng chแปฉc nฤng tแปซ trรชn xuแปng.
ฤแบงu tiรชn ta cรณ thแป thแปฑc thi ecs:Runtask, cรกc bแบกn cรณ thแป tรฌm hiแปu thรชm vแป ecs service trong aws tแบกi ฤรขy
Nรณi cho dแป hiแปu thรฌ ecs lร service cho phรฉp quแบฃn lรฝ cรกc docker container trรชn amazon cloud, mแปi container sแบฝ cรณ nhiแปm vแปฅ riรชng, ta gแปi lร task, nhiแปu container sแบฝ ฤฦฐแปฃc sแปญ dแปฅng kแบฟt hแปฃp vแปi nhau ฤแป cแบฅu thร nh service (ฤรณ cลฉng chรญnh lร lรฝ do vรฌ sao bร i nร y tรชn lร Microservices)
ร tฦฐแปng ฤแบงu tiรชn cแปงa mรฌnh lร gแปi ฤฦฐแปฃc task vร tรฌm hiแปu hร nh vi cแปงa nรณ ฤแป lแปฃi dแปฅng. Vแปi chall nร y ฤแป gแปi ฤฦฐแปฃc task thรฌ ta cแบงn
--task-definition : ฤรฃ biแบฟt
--cluster : cรณ thแป lแบฅy bแบฑng
ecs:ListClusters(cluster cรณ thแป hiแปu ฤฦกn giแบฃn lร mแปt goup cแปงa cรกc containers)--network-configuration : ta cลฉng cรณ ฤแปง thรดng tin cho options nร y
Lแบฅy Cluster name

Format cแปงa --network-configuration cรณ dแบกng nhฦฐ sau:

Ta dแป
dร ng lแบฅy ฤฦฐแปฃc qua ec2:DescribeSecurityGroups vร ec2:DescribeSubnets
GroupId
Lฦฐu รฝ: ta sแบฝ dรนng GroupID cแปงa GroupName TetCTF-GETFLAG lร sg-0636ad23bae6f21e7 . Lรฝ do thรฌ sแบฝ biแบฟt sau
SubnetId

Thแปฑc thi ecs:RunTask

Tuy nhiรชn vแบซn chฦฐa ฤฦฐแปฃc vรฌ cรฒn thiแบฟu gรฌ ฤรณ, sau mแปt hแปi search gg thรฌ mรฌnh biแบฟt cรณ 3 mode ฤแป tแบกo instance cho container lร EC2, FARGATE vร EXTERNAL. ฤแปi vแปi bร i nร y thรฌ chแป cรณ FARGATE lร cรณ thแป run task
Sau khi gแปi ฤฦฐแปฃc task thรฌ mรฌnh bรญ hoร n toร n khรดng biแบฟt lร m gรฌ tiแบฟp theo
Nhแป lแบกi ฤแป cรฒn cho phรฉp mรฌnh PassRole vร xem logs, nรชn mรฌnh check lแบกi cแบฃ 2, thรฌ kแบฟt quแบฃ tแปซ logs cรณ vแบป khรก khแบฃ quan

Mรฌnh nhแบญn thแบฅy sแบฝ cรณ logs ฤแปi vแปi /ecs/tet-ctf:* , hay chรญnh lร task mร mรฌnh thแปฑc thi, thแปญ thแปฑc thi task vร check logs ta sแบฝ ฤฦฐแปฃc (nแบฟu ta gแปi task khรดng phแบฃi bแบฑng GroupID cแปงa TetCTF-GETFLAGthรฌ ta sแบฝ khรดng thแบฅy logs)

ฤแบฟn ฤรขy mรฌnh tiแบฟp tแปฅc bรญ vร khรดng biแบฟt phแบฃi lร m gรฌ vแปi ฤแปng logs nร y
Quay trแป lแบกi vแปi hร nh vi run-task, mรฌnh thแบฏc mแบฏc khรดng biแบฟt liแปu cรณ mแปt tรญnh nฤng nร o ฤรณ cรณ thแป giรบp thแปฑc thi command hay khรดng. Search cแบฃ ngร y trแปi khรดng ra kแบฟt quแบฃ, nhฦฐng khi hแปi ChatGPT thรฌ mรฌnh cรณ cรขu trแบฃ lแปi ๐ข๐ข๐ข

Options --overide sแบฝ cho phรฉp ta ghi ฤรจ command sแบฝ thแปฑc thi kรจm vแปi quรก trรฌnh khแปi tแบกi cแปงa container. Tuy nhiรชn cmd thแปฑc thi khรดng trแบฃ vแป output
Mรฌnh check thแปญ OutBound thรฌ cลฉng khรดng cรณ kแบฟt quแบฃ (quรก dแป ฤoรกn)
Lรบc nร y thรฌ logs phรกt huy cรดng dแปฅng, mรฌnh thแปญ check logs vร cรณ ฤฦฐแปฃc output
Viแปc bรขy giแป chแป lร tรฌm flag thรดi

Last updated
