æ
å ±åéãšå€éšãããã¯ãŒã¯ç®¡ç
ç§ã¯é
ããŠèµ·ããã®ã§.ç§ã¯æåã®ãããã¯ãèããŠããŸããã§ãããç§ã¯å°ãåŸæããŸããç§ã¯åçã远å ããŸã
ã€ã³ãã©ã¹ãã©ã¯ãã£ã¢ãŒããã¯ãã£ã®èšèšãšå±é
éåžžã®ã¢ãŒããã¯ãã£ïŒã¬ããããŒã æ
åœè
- ãããŒã ãµãŒããŒCS-ãã¿ãŒã²ãããã·ã³ã®æ¬ ç¹ïŒåé¢ãããŠããªãæ©èœãæœåšãã£ãã«ãªããæ¥ç¶ããããã«å€ãã®ãã°ãæ»ããæè»æ§ãäœã
é²åã¢ãŒããã¯ãã£ïŒDNS/HTTP/HTTPSåé¢ãµãŒããŒã®ãã³ãïŒ1ã2CPU 2Gã¡ã¢ãª10GããŒããã£ã¹ã¯ã5åã®åæ¥ç¶ãæœåšãã£ãã«ïŒå®éã®ã¿ãŒã²ããç°å¢ã«åºã¥ãåªå
床ïŒ
å®å
šãªã¢ãŒããã¯ãã£ïŒãã¡ã€ã³åãšIPïŒVPSïŒTeamServerïŒCSïŒããã³ããšã³ããã·ã³ïŒRedictorïŒCS-ã TeamServers 1/2/3/.ãã¬ã¬ãã«ã¬ã€ã€ãŒïŒSMTP/ãã€ããŒã/C2/é ãC2ïŒ
ãã¡ã€ã³åãéžæããŸã
expedDomains.net delete domainãç»é²ããŸã
TIPS1:ã«ã¯ãäžçã¡ãŒã«ãŒããŠã€ã«ã¹å¯Ÿçã¡ãŒã«ãŒã«é¢é£ãããã¡ã€ã³åãããã³ã¿ãŒã²ããã«é¢é£ãããã¡ã€ã³åã¯å«ãŸããŠããŸããã
TIPS2ïŒã¿ãŒã²ããé¢é£é åã«å
±éãã¡ã€ã³åãç»é²ããŠãã ããããã©ã€ãã·ãŒä¿è·ãæå¹ã«ããããšãå¿ããªãã§ãã ãã
ãã®ä»ïŒwww.freshdrop.comwww.domcop.com
TIPS3ïŒãã¡ã€ã³åãåé¡ãããŠãããã©ããã確èªãã財åãå»çãeã³ããŒã¹ãèªç©ºãæ
è¡
TIPS4ïŒVTãšãã€ã¯ãã¹ãããã«ç§»åããŠããã¡ã€ã³åãé»ãšããŠããŒã¯ãããŠãããã©ããã確èªããŸã
TIPS5ïŒèåŸ
ãå ±åããããã®ã«ãŒã«ãæ³šææ·±ãèªãïŒæ³šæããŠäœ¿çšããïŒ
ãã¡ã€ã³åïŒã¢ã«ãŠã³ãã®ç¶æïŒãæ œå¹ããŠéåžžã®ãã¡ã€ã³åãäœæããåã»ãã¥ãªãã£ã¡ãŒã«ãŒã«æåºããŠãµã€ããåé¡ããŸã
TIPS1ïŒãã¡ã€ã³åãå€§èŠæš¡ãªå·¥å ŽIPã«åé¡ãã䜿çšãããšãã«C2ã«è§£æãã䜿çšããŠããªããšãã«å€§èŠæš¡ãªå·¥å ŽIPã«è§£æããŸãã
TIPS2ïŒVTèªå·±è©äŸ¡ãã¢ã¬ãã¯ã¹ã®èªå·±è©äŸ¡
ãã¡ã€ã³åã®è§£å床æ€åº
DomainCheckå顿€åºãã¡ã€ã³åïŒ
IPã¯å€éšãããã¯ãŒã¯IPãæ€åºããã€ã³ããªãžã§ã³ã¹ã¹ããŒã·ã§ã³ãä»ããŠé»ãšããŠããŒã¯ãããŠãããã©ããã確èªããŸãã
CDNã䜿çšããŠå®éã®IPãé衚瀺ã«ããŸãïŒäžéšã®ã»ãã¥ãªãã£ãã³ããŒã¯CDN IPãååããŸãïŒ
åµãç£ãããã«é¶ãåããããµããã¡ã€ã³ãã€ã¯ãªãŒããŒïŒé«è¡šçŸãã¡ã€ã³ã®åæa b -ã
ãã¬ãªãªãŒã¹ã®ããã®é«ç¹°ãè¿ãããã€ã©ãŒ
C2ããŒã«CS 3.14
ã«ã¹ã¿ã ãã©ãã£ãã¯ç¹æ§ïŒDNS/HTTP/HTTPS/SMBããã³TCP
ãã€ããŒãèªã¿èŸŒã¿ããã»ã¹ïŒã·ã§ã«ã³ãŒã/ããŒããŒ/éåŒ/ããŒã³ã³
DNSïŒDNSãã£ãã«ã®ããã©ã«ããã©ã¡ãŒã¿ãŒã倿Žããå¿
èŠãããå ŽåïŒããã€ã¹ã§ç°¡åã«æ€åºã§ããŸãïŒãDNSãããŒã¿ãã£ãã«ãšããŠäœ¿çšããªãã§ãã ããã
HTTPïŒSïŒïŒURIã®ãã¡ã€ã«ãµãã£ãã¯ã¹ã«JSãCSSãªã©ã®éçãã¡ã€ã«ãèšå®ããªãã§ãã ãããå¹æïŒææèšŒææžç¡æèšŒææžèªå·±çœ²åèšŒææžïŒLet's Encryptã¯ç¡æã§ã3ãæéæéåããèªåçã«æŽæ°ãããŸãïŒ
Redirectordns socat | iptables | sshïŒtmuxãšç»é¢ã®ãããããéžæïŒ
Apache | nginx
ãã³ãïŒ
è€æ°ã®å€æã䜿çšããŠèŠæ±ããããã©ã«ãã®URIã®äœ¿çšãæåŠãããããã¯ãŒã¯å
šäœã§C2ã¹ãã£ã³ãšæŠãããšããå§ãããŸãã
ã¿ãŒã²ããé¢é£ã®IPã¢ã¯ã»ã¹ã®ã¿ãã¯ã©ãŠããµã³ãããã¯ã¹ãšæŠãããšãã§ããŸã
ã¢ã¯ã»ã¹æéãå¶éãããç¹å®ã®æéã®ãã€ããŒãã®ã¿ãèŠæ±ãã
Googleãªã©ã®é«è¡šçŸå¯èœãªãã¡ã€ã³ã«éæ¯æããŒãURIããªãã€ã¬ã¯ãããªãã§ãã ãã
ææ¡ïŒwww.aaa.comã§ãã¡ã€ã³åãäœæããc2.aaa.comã®ç¬¬2ã¬ãã«ã®ãã¡ã€ã³åã䜿çšããŠC2ãå®è¡ããŸã
ãã¡ã€ã³ããã³ã°ïŒIPããã³ãã¡ã€ã³åãé衚瀺ã«ããæ¹æ³ïŒ
Googleã¢ããªãšã³ãžã³| Amazon | Azure | Aliyun CDN
å¯èŠå±€ïŒDNSãTLS
ç®ã«èŠããªãã¬ã€ã€ãŒïŒhttps
URLïŒé«ãè©å€ïŒSNIïŒé«ãè©å€ïŒãã¹ãïŒC2ïŒ
https://github.com/vysecurity/domainfrontinglists
代æ¿ãœãªã¥ãŒã·ã§ã³ïŒHTTPãã€ãã©ã€ã³ïŒHTTP 1.1ïŒ
ãã¡ã€ã³ããã³ãã£ã³ã°ãšåã广
åãTCPæ¥ç¶ã䜿çšããŠãããŸããŸãªãã¹ãã®HTTPãã±ãããéä¿¡ããŸã
ãã³ãïŒåªãããã¡ã€ã³ +ããããã¡ã€ã³ããã±ãŒãž1ã€ã®ã¬ã€ã€ãŒãšåæã«éä¿¡ãã
ãµãŒãããŒãã£ãµãŒãã¹ã¯C2ãšããŠäœ¿çšãããŸã
Office365ãPastebinãSlackãFacebookãDropboxãGmailãTwitterã
ãµãŒãããŒãã£ãµãŒãã¹ã«ããŒãã³ãŒãããå¿
èŠããããŸã
ã¡ãŒã«ãã£ãã·ã³ã°ïŒSMTPïŒãã¡ã€ã³åïŒåãC2ãã¡ã€ã³åãéžæããŸã
éåžžã«è©å€ã®è¯ãé»åã¡ãŒã«éä¿¡è
ïŒMailChimpãSendGrid
SPFãdkim \ dmarcãæ£ããæ§æããŸã
SSLèšŒææž
æéãšé »åºŠãéä¿¡ããŸã
ã¯ã³ã¯ãªãã¯å±é
ãã£ãã·ã³ã°ã¡ãŒã«ãã¬ãŒã ã¯ãŒã¯ïŒgophishïŒhttps://github.com/gophish/gophishïŒ
é èœãšã»ãã¥ãªãã£ã®æš©éãæå°åããïŒIPTALBESã䜿çšããŠã³ã³ããŒãã³ãéä¿¡ãå¶éããããŒã転éã®SSH
TeamServerïŒããŒããå¶éããŠããŒã«ã«ã¢ã¯ã»ã¹ã®ã¿ãå¶éããããŒã³ã³ãªã¹ãã³ã°ããŒãã®ã¿ãªãã€ã¬ã¯ã¿ãŒã¢ã¯ã»ã¹ãå¶éããŸã
ãã³ãïŒVPSã¯GFWã§ç°¡åã«ååã§ããŸããïŒ
解決çïŒV*2r a y + nginx + cloudflare + freenom + websocketã»ããã¢ãããšãŒãžã§ã³ã
ã€ã³ãã©ã¹ãã©ã¯ãã£ç£èŠã·ã¹ãã ã¯ãå®å
šãªãã°ãèšé²ããã¢ã©ãŒã ãèšå®ããŸã
èªåå±éluwuïŒhttps://github.com/qax-a-team/luwuïŒ
ãã°ã»ã³ã¿ãŒ
äºåemailãã£ãã·ã³ã°æ
å ±ã®åéãšèª¿æ»
æè¡ç課é¡ïŒ
ã¡ãŒã«ã²ãŒããŠã§ã€ã¡ãŒã«ã²ãŒããŠã§ã€
ãã©ãŠã¶
EDRãIDS
ã¡ãŒã«ã²ãŒããŠã§ã€
ã¹ãã ã¢ã³ãã¹ãã
SPF
dkim
æ°ããç»é²ããããã¡ã€ã³å
çãããã¡ã€ã³åã®æ¥å°ŸèŸ
æ©å¯ããŒã¯ãŒã
ç¹æ§ïŒ
é»åã¡ãŒã«ãªããŒãã¯ããã©ã«ãã§æå¹ã«ãªããŸã
MTAã¯ãããã©ã«ãã§ã¯åä¿¡è
ã®æ€èšŒããªã³ã«ããŸãã
çµè«ïŒãã£ãã·ã³ã°ã¡ãŒã«ãååšããªãã¡ãŒã«ããã¯ã¹ã¢ã«ãŠã³ãã«éä¿¡ãããšãNDRãåä¿¡ã§ããå Žåããã£ãã·ã³ã°ã¡ãŒã«ãé»åã¡ãŒã«ã²ãŒããŠã§ã€ã»ãã¥ãªãã£ã¬ãã¥ãŒïŒåŸæ¹æ£ä¹±æ»æïŒã«åæ Œããããšã蚌æãããŠããŸãã
ã¹ãã ããã€ãã¹ããŸã
äžèšã®çµè«ãæ€åºããã¡ãžã³ã°ã¢ã³ãã¹ãã ãšã³ãžã³ã«ãŒã«
NDRãå®å®ã«ããªã¬ãŒããæ¹æ³ïŒ
10mãè¶
ããããã¹ã
5,000人以äžã®åä¿¡è
ã¢ã³ããã«ãŠã§ã¢ããã€ãã¹ããŸã
ndr
èŠçŽããŸã
é£ããµã³ãã«ã®çç£
ãã£ãã·ã³ã°é»åã¡ãŒã«ã¿ã€ãã®æªæã®ããCHMããã¥ã¡ã³ãïŒç°¡åã«äœ¿çšããŸãããçŸåšãœãããæ®ºãããšã¯å°é£ã§ãããæ®ºå®³ãåé¿ãã广ã¯è²§åŒ±ã§ã
æªæã®ãããã¯ãã³ãŒãã䜿çšãããªãã£ã¹ããã¥ã¡ã³ãïŒæ··ä¹±ããããïŒãŒãããåçãªã©ãšçµã¿åãããŠïŒãããã¯ããæåã§éãå¿
èŠããããããã»ã¹ãã§ãŒã³ã¯çãããã§ã
ãã¯ã€ããã©ã¹ãã©ãã¯ãã£ãã·ã³ã°ïŒçœ²åä»ããã¯ã€ãããã°ã©ã ã䜿çšããŠãDLLãã€ãžã£ãã¯ã¹ããŒã ãä»ããŠæªæã®ããDLLãããŒãããŸãã AVã«åæ Œããæ¹ãç°¡åã§ãããæžå§ããã³å®è¡ããå¿
èŠããããŸãã
LNKãã¡ã€ã«ãã£ãã·ã³ã°ïŒãªã³ã¯ãªããžã§ã¯ãã¯PowerShellãããã»ã¹ãã§ãŒã³ã¯å®ç§ã§ã
PPTãã£ãã·ã³ã°ãµã³ãã«ïŒPPTãã€ããŒãªã³ã¯ããå®å
šå£°æãããããã¢ãããããã¯ããéå§ããå¿
èŠã¯ãããŸãããããã«ã¹ã¯ãªãŒã³ã§åçããå®è¡åã«æå¹ã«ããå¿
èŠããããŸãã䜿çšããããšã¯ãå§ãããŸãã
æªçšãããã£ãã·ã³ã°ã¡ãŒã«ïŒé«å¹çãšé«ã³ã¹ã
æžã蟌ã¿ããŒã«ã¯èªåçã«æªæã®ããLNKãçæããŸããããŒé¢æ°ïŒishelllink:SeticOnlocationïŒïŒ
ishelllink:setshowcmdïŒïŒãŠã£ã³ããŠãã£ã¹ãã¬ã€
ishelllink:setargumentsïŒïŒ
ishelllink:setpathïŒïŒ
.
LNKãã£ãã·ã³ã°ã®é»åã¡ãŒã«ãã£ãã·ã³ã°å±¥æŽæžã®å·çïŒã³ã³ãã³ããéžæããŠèªåŒµããããšãã§ããŸãããã®ãã
LNKã¢ã€ã³ã³ã®è¡šç€ºïŒåã·ã¹ãã ã«ããã©ã«ãã§è¡šç€ºã§ããäžè¬çãªã¢ã€ã³ã³ã«å€æŽ
åäœãé衚瀺ã«ããæ¹æ³ïŒsetShowcmdïŒïŒãŠã£ã³ããŠãæå°åããŸã
Word Documentã¹ãã¬ãŒãžïŒ
ãªã³ã©ã€ã³ã§åèªææžãããŠã³ããŒãããŠãã ãã
ïŒnew-Object System.net.WebClientïŒ.DownLoadFileïŒurlãfile_pathïŒ;
ããŒã¿ã¯ãšã³ãžã³ã埩å
ããŸã
ãããã³ã«ã³ã³ãã³ãã®åŸ©å
ïŒTCPãHTTPãSMTP
ãã¡ã€ã«ã³ã³ãã³ãã®åŸ©å
ïŒOfficeãPDFãZIP
ç ²æããã°ã©ã ã®åŸ©å
ïŒUPX
æå·åã¢ã«ãŽãªãºã ããŒã¿åŸ©å
ïŒbase64
åèªææžãããŒã«ã«ã«ãªãªãŒã¹ããŸã
command_line_argumentsã«åèªãæŒããŸã
åŒæ°ã¯ãLNKã«ã³ãã³ãã©ã€ã³ãã©ã¡ãŒã¿ãŒãä¿åããããã«äœ¿çšãããŸã
StringDataæ§é ãã«ãŠã³ããã£ãŒãžã£ãŒ
ishelllink:setargumentsïŒïŒ
è©°ã蟌ãŸããããŒã¿ã®æå€§å€ã¯ãã³ãã³ãã©ã€ã³ãã©ã¡ãŒã¿ãŒã®é·ãã®å¶éã§ã
å®éã®æž¬å®å€ã¯0x7FC2ïŒ31kbïŒã§ããããšãããããŸãã
LNKãã¡ã€ã«ã®æåŸã«åèªãæŒããŸãïŒæšå¥šïŒ
WordãPEããããããµã€ãºã®PowerShellã¯å°Ÿã«è¿œå ã§ããŸã
-last 1ãéžæããæåŸã®ãªããžã§ã¯ããé
眮ãããªããžã§ã¯ããã\ nããšé€ç®ããŸã
-index 1ãéžæããŠãã ãã
ãœãããã«ã®å¯Ÿç«
çããã¡ã€ã«åã®ãã¯ãŒã1.exe
ã³ãŒãé£èªååç
§Symantecã®è«æ
ã»ãã¥ãªãã£ããã»ã¹ã®æ€åº
ä»®æ³ãã·ã³ - åè§ã®ããŒã«ãœãããœã«ããŒæ€åºè±bugger
åŸæ¥ã®ãã¯ããã¯
ããã»ã¹åã®æ€åº
ãŠã£ã³ããŠã®ã¿ã€ãã«æ€åº
æ°ããããŒãº
ããã»ã¹ã暪æããããã»ã¹ã®å¯Ÿå¿ããèäœæš©æ
å ±ãååŸãããã©ãã¯ãªã¹ããªã¹ããšæ¯èŒããŸã
å©ç¹ïŒã¢ããã°ã¬ãŒããããããŒãžã§ã³ã倿ŽãããŠããããæ®éçã§ã
PIDã«åºã¥ããŠããã»ã¹ã®å®å
šãªãã¹ãååŸããæ¹æ³ïŒProcessExplorer
x86ã¯å®è¡äžå¯èœã§ãx64ã¯åé¡ãããŸãã
Pchunter 0ringããã¯ããã€ãã¹ããŸã
æ€åºåŸãæ»æè
ã«éç¥ããäœæ³¢ã«ã¿ã€ã ãªãŒã«å¯ŸåŠããŸã
ã€ã³ãã©ãããæ°Žå¹³ã ãŒãã¡ã³ã
ã€ã³ãã©ããã調æ»
å€å
žçãªã¢ã¯ãã£ãããã³ããã·ãã€ã³ãã©ãããèª¿æ»æ¹æ³
ã¢ã¯ãã£ããªã¹ãã£ã³
æ©åšè³ç£ã®èå¥
å©çšå¯èœãªãµãŒãã¹ã³ã¬ã¯ã·ã§ã³
ã¹ã¯ãªããæ€åº
ããã·ãã³ã¬ã¯ã·ã§ã³
ãããŒããã£ã¹ãã¡ãã»ãŒãžãèããŠãã ãã
é±å±±èŠå
ãªã¹ã¯åŽïŒãããã¯ãŒã¯ACLå°éãå¶åŸ¡ãã¹ãHIDSããããŒããããNIDS
ã¡ãœããæ¯èŒ
ãã¡ã€ã³å
æ
å ±æ€åº*ã¯ã©ã¹ãã¡ã€ã³ * * nix * Windowsåºå
ããžã·ã§ãã³ã°ãã¡ã€ã³ã³ã³ãããŒã«ïŒãã¡ã€ã³ãã¹ãïŒ
ã¿ã€ã ãµãŒããŒ
æ£å³æé/ãã¡ã€ã³
W32TM /ã¯ãšãª
DNSãµãŒããŒ
get-dnsclientserveraddressãã€ãã£ãDNSãµãŒããŒã®èšå®ãã¯ãšãªããŸã
ãã¡ã€ã³ã®å¯Ÿå¿ããã¢ãã¬ã¹ã¯ãDNSãµãŒããŒããã¬ã³ãŒããç
§äŒããŸã
ãã¡ã€ã³å¶åŸ¡ãã±ãŒã¿ãŒ
DCãã±ãŒã¿ãŒããã»ã¹
DNSã¯ãšãªãçæããDCãã±ãŒã¿ãŒã¡ã«ããºã ã«åŸãããšã¯éåžžã«å®å
šã§ã
Kerberosèªå®ãKDC
GC
ã¯ãšãªããŒã«
ãã¡ã€ã³å¶åŸ¡æ
å ±ãæœåºããNLTESTããã»ã¹
ããã
dsquery query ldap
dsquery/adsisearcherã¯Plantext LDAPãããã³ã«ã䜿çšããIDSã«ãã£ãŠç°¡åã«ãã£ããã£ãããŸã
ããžã·ã§ãã³ã°ãã¡ã€ã³ã³ã³ãããŒã«ïŒå±å€ãã¹ãïŒ
DNSãã©ãã«ã·ã¥ãŒãã£ã³ã°
UDP/53ãã¹ãã£ã³ããŸã
DNSããDNS FQDNãã¯ãšãªããŸã
DNSã®ã¯ãšãªãã±ãŒã¿ãŒ
ldapïŒsïŒgcïŒsïŒ
ããŒããã¹ãã£ã³ããæ©èœã䜿çšããŠãã¡ã€ã³åããã£ã«ã¿ãªã³ã°ããŸã
å¿åã§LDAPã¡ã¿ããŒã¿ã®äžéšãèªã¿ãŸã
LDAPèšŒææžæ
å ±ããèªã¿ãã ãã
GCãµãŒãã¹ã¯ãšãªTCP/3268 TCP/3269
é²åŸ¡ïŒå¿åã®ãã€ã³ãã£ã³ã°ããªãã«ããããšãã§ããŸã
ã¯ãšãªLDAPïŒSïŒãµãŒãã¹
adexplorerïŒguiãããã€ãã®cmdlets
Get-Aduser
PowerViewïŒå€æ°ã®cmdlets
Kerberos
as-req as-rep
KDC TGTãã±ãã
ASãããã³ã«ã«åºã¥ããŠãŒã¶ãŒã®åæ
kerberosuserenumïŒa-team githubïŒ
MSFã¢ãžã¥ãŒã«
asReproast
ãŠãŒã¶ãŒã®nthashæå·åã䜿çšããã»ãã·ã§ã³ããŒ
John/Hashcatã¯ãªãã©ã€ã³ã§å²ããããšãã§ããŸã
SPNïŒãµãŒãã¹ããªã³ã·ãã«åïŒãã¡ã€ã³ãªããžã§ã¯ãã®ããããã£ããªããžã§ã¯ãã¯ãã·ã³/ãŠãŒã¶ãŒã§ãããèšå®ããå¿
èŠããããŸã
TGS-REQ TGS-REP
ãµãŒãã¹ãã±ãã
ãµãŒãã¹ãã±ãã
çµè«ïŒéåžžã®ãã¡ã€ã³ã¢ã«ãŠã³ãã®ãµãŒãã¹ãã±ãããç³è«ããåŸãã¢ã«ãŠã³ãããªãã©ã€ã³ã§ã¯ã©ãã¯ã§ããŸã
Kerberoastæ»æïŒäžèšã®çµè«ã«åºã¥ãïŒ
rubeus.exe
PowerView
ãã³ããã¡ã€ã³ç®¡çè
ç¹å®ã®ãŠãŒã¶ãŒãã°ã€ã³ã»ãã·ã§ã³
ãªã¢ãŒãã»ãã·ã§ã³ã®åæ
netSessionEnumïŒSMBã»ãã·ã§ã³ïŒ
NetwkstauserenumïŒã€ã³ã¿ã©ã¯ãã£ããã°ã€ã³ã»ãã·ã§ã³ïŒã·ã¹ãã ã®æ°ããããŒãžã§ã³ã«ã¯ã管çç¹æš©ãå¿
èŠã§ã
ãªã¢ãŒããŠãŒã¶ãŒã®åæ
ã·ããªãªïŒåãååã®åããã¡ã€ã³ç®¡çã¢ã«ãŠã³ããæã€äžéšã®ããŒã«ã«ã¢ã«ãŠã³ãã¯ãåã人ãäœæããããšãã§ããŸã
SAMRã¯ãšãªã°ã«ãŒããšã¡ã³ããŒæ
å ±ïŒæ³šïŒWIN 10ã¯ç®¡çãªãã§ã¯åæã§ããŸããïŒ
LSARPCã¯ãšãªSIDé¢é£
ãªã¢ãŒããã°ã€ã³åæ
ã€ã³ã¿ã©ã¯ãã£ããã°ã€ã³ïŒäž»ã«ã³ã³ãœãŒã«ãšRDPã®ãã°ã€ã³æ¹æ³ãæããŸã
ãã¹ãèš±å¯ãååŸããïŒVUL RBCD RPRN
ã¬ã¬ã·ãŒè³æ Œæ
å ±: PowerView MimikatzãæœåºããŸã
ãŠãŒã¶ãŒèš±å¯ãååŸããŸã
æ°Žå¹³ã«ç§»åããŸã
MS-RPC
WMIïŒDCOM TCP/135ããŒã¹ã®ãã¬ãŒã³ããã¹ããã©ã³ã¹ããã·ã§ã³
PSEXEC ïŒïŒãã³ãïŒImpacket Tool Psexec.pyã䜿çšããŸããéãã¯ãã¿ãŒã²ãããSMB3.0ããµããŒãããŠããã©ã«ãã§æå·åãæå¹ã«ããããšã§ãïŒ
ãªã¢ãŒãã§ã¿ã¹ã¯ãã¹ã±ãžã¥ãŒã«ããŸã
DCOMïŒãªã¢ãŒãã§TCP/445 +ã©ã³ãã ããŒãDComexec.pyãšåŒã°ããCOMã³ã³ããŒãã³ã
Kerberosã¯å§èšãããŸãã
æŠå¿µïŒããã¯ããµãŒãã¹ããŠãŒã¶ãŒã®IDã«ã¢ã¯ã»ã¹ããŠä»ã®ãµãŒãã¹ã«ã¢ã¯ã»ã¹ã§ããããã«ããèªèšŒã¡ã«ããºã ã§ãã
ç¡å¶éã®å§ä»»ïŒããã©ã«ãèšå®ãã¡ã€ã³ã³ã³ãããŒã«ã®ã¿ãç¡å¶éã®å§ä»»ã§ãã
S4U2Self
ããªã³ã¿ãŒãã°ïŒããªã³ã¿ãŒã¹ããŒã©ãŒãµãŒãã¹SSRF
ç¡å¶éã®å§ä»»+ S4U2Self +ããªã³ã¿ãŒä»»æã®ãã¡ã€ã³ã³ã³ãããŒã«
å¶çŽå§ä»»
S4U2Proxy
ãªãœãŒã¹ããŒã¹ã®ä»£è¡šå£ïŒRBCDïŒçŸåšæãèŽåœçãªä»£è¡šå£
S4U2SelfãS4U2Proxyãç¶æ¿ããŸã
ãã¡ã€ã³æš©éã¡ã³ããã³ã¹
ãã¹ãæš©éãç¶æãããŠããïŒäžè¬çãªã¿ã€ããæ¡åŒµãããŠããªãïŒ
ãã¡ã€ã³æš©éã¡ã³ããã³ã¹
SPN
ã¢ã«ãŠã³ãã«ã€ããŠã¯ãåã®ã¢ã«ãŠã³ããåç
§ããŠãã ãã
ãŽãŒã«ãã³ããŒã
KRBTGTã䜿çšããŠTGTãæå·åãããšãTGTæå·åã¯ã¢ã«ãŠã³ãã®ããŒãããŒãšããŠäœ¿çšããŸã
ããã©ã«ãã®ãã©ã¡ãŒã¿ãŒã§äœæããããŽãŒã«ããã±ããã¯é·ãé倱å¹ããŸããMimikatz
DCSYNCã¯ããã¡ã€ã³å
ã®ã¢ã«ãŠã³ãã®ããã·ã¥/ããŒããã«ããŸã
æ€åºãã€ã³ãïŒ
KRBTGTããŒãKRBTGTãã¹ã¯ãŒãã2å倿Žãã4769ãã°ãåæããŸã
ãã°åæ
IDSã«ãŒã«ãæå¹æéãã¢ã«ãŽãªãºã ãªã©ã
ã·ã«ããŒããŒã
SRVSé¢é£ã®ããŒæå·å
æ€åºãã€ã³ãïŒ
PACæ
å ±ç¢ºèª
å¶éãããå§ä»»
RBCD
ãã¡ã€ã³ã°ã«ãŒãããªã·ãŒ
ã©ãã
ãã¡ã€ã«ææãšæ°Žå¹³æ¹åã®åã
ãã¡ã€ã«ææ
æçŸ©
ã·ãŒã³
å瀟ã®ãœãããŠã§ã¢ã©ã€ãã©ãªãµãã©ã€ãã§ãŒã³ã¯ãã©ã€ãã®é§åãã«äŒŒãŠããŸã
ãªã¢ãŒãå
±æãã¡ã€ã«ã«ææããŸã
USBãã©ã€ããã¢ãã€ã«ããŒããã©ã€ããªã©ã®å€éšããã€ã¹ã®ææ
3389ãã£ã¹ã¯ããµãŒããŒã«ããŠã³ãããŸã
ã¡ãŒã«ææãæªæã®ãããã¯ããæ¿å
¥ããŸã
ãã©ãã£ãã¯ãã€ãžã£ãã¯ã茞éäžã®ãã¡ã€ã«ã«ææããŸã
æ¹æ³
PEææ
LNKææ
ãªãã£ã¹ææ
æ¥åžžçãªPEææ
exeã«ã€ã³ããŒã颿°ã远å ããdllmainã§æªæã®ããã³ãŒããäœæããŸããããŒã«ã¹ã¿ãžãã
æªæã®ããã³ãŒããPEã«æ¿å
¥ããOEPã倿ŽããPEãåæ§ç¯ããŸã
OEPã®ã©ããã§æªæã®ããã³ãŒãã«ãžã£ã³ãããŸã
OEPã倿ŽããŠãæªæã®ããã³ãŒããæãããã«ããŸã
察ç«çãªã¢ã€ãã¢
DLLããŒã
OEPãžã£ã³ã
TLSïŒã¹ã¬ããããŒã«ã«ã¹ãã¬ãŒãžïŒã³ãŒã«ããã¯ã䜿çšããŸã
TLSææ
TLSã³ãŒã«ããã¯ãæbug; OEPã倿Žããã«æªæã®ããã³ãŒããTLSã«å
¥ããŸã
TLSããŒã¿æ§é
TLSææã®å
šäœçãªããã»ã¹ïŒã»ã¯ã·ã§ã³éã®ã®ã£ããã®æ€çŽ¢- ãã£ã¬ã¯ããªããŒã¿ãã£ã¬ã¯ããªã®å€æŽ- TLSãã£ã¬ã¯ããªTLSã³ãŒã«ããã¯é¢æ°ã®æ§ç¯-PEã®åæ§ç¯- æªæã®ãããã¡ã€ã«ã®ãªãªãŒã¹
LNKãã¡ã€ã«
ã¢ã€ã³ã³ã倿Žããã«ä¿ã€ã«ã¯ã©ãããã°ããã§ããïŒ
iShelllink:SeticOnLocationïŒïŒã¯ãçŸåšã®LNKã®ã¢ã€ã³ã³ã«exeãèšå®ããŸã
æªæã®ããã³ãŒãã¯ãæ£åžžã«å
ã®ããã°ã©ã ãåŒãäžããŸã
rundll32.exeã§
ã·ããªãªïŒèš±å¯ã¡ã³ããã³ã¹ãæ°Žå¹³æ¹åã®åã
ãªãã£ã¹ãã¡ã€ã«ææ
.docx .docmïŒãã¯ããã¡ã€ã«ïŒã¯.docã«å€æŽã§ããŸã
ã¿ãŒã²ããïŒdocxãæªæã®ãããã¯ãã§.docmãŸãã¯.docã«å€æããŸã
ãœãããã«ã®å¯Ÿç«
ãã¡ã€ã«é¢é£ã倿ŽããŸã
.docmã¯.docã«å€æŽãããæ¥å°ŸèŸ.docmãšã®æŠéæ€åº
ãã¯ãé¢é£ãã¡ã€ã«ã倿ŽããŠãäŸåé¢ä¿ãã¡ã€ã«åãŸãã¯ã¿ã€ãã®æ€åºãšæŠã
from:https://github.com/backlion/redteam-bcs