ããŒãã£ã·ã§ã³/ãã¡ã€ã«ã·ã¹ãã /ã«ãŒãã³ã°
Tip
AWSãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training AWS Red Team Expert (ARTE)
GCPãããã³ã°ãåŠã³ãå®è·µããïŒHackTricks Training GCP Red Team Expert (GRTE)
Azureãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training Azure Red Team Expert (AzRTE)
HackTricksããµããŒããã
- ãµãã¹ã¯ãªãã·ã§ã³ãã©ã³ã確èªããŠãã ããïŒ
- **ð¬ Discordã°ã«ãŒããŸãã¯ãã¬ã°ã©ã ã°ã«ãŒãã«åå ããããTwitter ðŠ @hacktricks_liveããã©ããŒããŠãã ããã
- HackTricksããã³HackTricks Cloudã®GitHubãªããžããªã«PRãæåºããŠãããã³ã°ããªãã¯ãå ±æããŠãã ããã
ããŒãã£ã·ã§ã³
ããŒããã©ã€ããŸãã¯SSDãã£ã¹ã¯ã¯ãããŒã¿ãç©ççã«åé¢ããç®çã§ç°ãªãããŒãã£ã·ã§ã³ãå«ãããšãã§ããŸãã
ãã£ã¹ã¯ã®æå°åäœã¯ã»ã¯ã¿ãŒïŒéåžžã¯512Bã§æ§æãããŠããŸãïŒã§ãããããã£ãŠãåããŒãã£ã·ã§ã³ã®ãµã€ãºã¯ãã®ãµã€ãºã®åæ°ã§ããå¿
èŠããããŸãã
MBRïŒãã¹ã¿ãŒããŒãã¬ã³ãŒãïŒ
ããã¯ããŒãã³ãŒãã®446Bã®åŸã®ãã£ã¹ã¯ã®æåã®ã»ã¯ã¿ãŒã«å²ãåœãŠãããŠããŸãããã®ã»ã¯ã¿ãŒã¯ãPCã«ã©ã®ããŒãã£ã·ã§ã³ãã©ãããããŠã³ããããã瀺ãããã«äžå¯æ¬ ã§ãã
æå€§ã§4ã€ã®ããŒãã£ã·ã§ã³ãèš±å¯ããŸãïŒã¢ã¯ãã£ã/ããŒãå¯èœãªã®ã¯æå€§ã§1ã€ã®ã¿ïŒããã ããããå€ãã®ããŒãã£ã·ã§ã³ãå¿
èŠãªå Žåã¯ãæ¡åŒµããŒãã£ã·ã§ã³ã䜿çšã§ããŸãããã®æåã®ã»ã¯ã¿ãŒã®æçµãã€ãã¯ããŒãã¬ã³ãŒã眲å0x55AAã§ããã¢ã¯ãã£ããšããŠããŒã¯ã§ããããŒãã£ã·ã§ã³ã¯1ã€ã ãã§ãã
MBRã¯æå€§2.2TBãèš±å¯ããŸãã
.png)
.png)
MBRã®ãã€ã440ãã443ã®éã«ã¯Windowsãã£ã¹ã¯çœ²åãèŠã€ãããŸãïŒWindowsã䜿çšãããŠããå ŽåïŒãããŒããã£ã¹ã¯ã®è«çãã©ã€ãã¬ã¿ãŒã¯Windowsãã£ã¹ã¯çœ²åã«äŸåããŸãããã®çœ²åã倿ŽãããšãWindowsãèµ·åããªããªãå¯èœæ§ããããŸãïŒããŒã«: Active Disk Editor)ã
.png)
ãã©ãŒããã
| ãªãã»ãã | é·ã | ã¢ã€ãã |
|---|---|---|
| 0 (0x00) | 446(0x1BE) | ããŒãã³ãŒã |
| 446 (0x1BE) | 16 (0x10) | æåã®ããŒãã£ã·ã§ã³ |
| 462 (0x1CE) | 16 (0x10) | 2çªç®ã®ããŒãã£ã·ã§ã³ |
| 478 (0x1DE) | 16 (0x10) | 3çªç®ã®ããŒãã£ã·ã§ã³ |
| 494 (0x1EE) | 16 (0x10) | 4çªç®ã®ããŒãã£ã·ã§ã³ |
| 510 (0x1FE) | 2 (0x2) | 眲å 0x55 0xAA |
ããŒãã£ã·ã§ã³ã¬ã³ãŒããã©ãŒããã
| ãªãã»ãã | é·ã | ã¢ã€ãã |
|---|---|---|
| 0 (0x00) | 1 (0x01) | ã¢ã¯ãã£ããã©ã° (0x80 = ããŒãå¯èœ) |
| 1 (0x01) | 1 (0x01) | éå§ããã |
| 2 (0x02) | 1 (0x01) | éå§ã»ã¯ã¿ãŒ (ããã0-5); ã·ãªã³ãã®äžäœããã (6-7) |
| 3 (0x03) | 1 (0x01) | éå§ã·ãªã³ãã®æäžäœ8ããã |
| 4 (0x04) | 1 (0x01) | ããŒãã£ã·ã§ã³ã¿ã€ãã³ãŒã (0x83 = Linux) |
| 5 (0x05) | 1 (0x01) | çµäºããã |
| 6 (0x06) | 1 (0x01) | çµäºã»ã¯ã¿ãŒ (ããã0-5); ã·ãªã³ãã®äžäœããã (6-7) |
| 7 (0x07) | 1 (0x01) | çµäºã·ãªã³ãã®æäžäœ8ããã |
| 8 (0x08) | 4 (0x04) | ããŒãã£ã·ã§ã³åã®ã»ã¯ã¿ãŒ (ãªãã«ãšã³ãã£ã¢ã³) |
| 12 (0x0C) | 4 (0x04) | ããŒãã£ã·ã§ã³å ã®ã»ã¯ã¿ãŒ |
Linuxã§MBRãããŠã³ãããã«ã¯ããŸãéå§ãªãã»ãããååŸããå¿
èŠããããŸãïŒfdiskãšpã³ãã³ãã䜿çšã§ããŸãïŒ
 (3) (3) (3) (2) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1) (1).png)
ãã®åŸã次ã®ã³ãŒãã䜿çšããŸãã
#Mount MBR in Linux
mount -o ro,loop,offset=<Bytes>
#63x512 = 32256Bytes
mount -o ro,loop,offset=32256,noatime /path/to/image.dd /media/part/
LBA (è«çãããã¯ã¢ãã¬ãã·ã³ã°)
è«çãããã¯ã¢ãã¬ãã·ã³ã° (LBA) ã¯ãã³ã³ãã¥ãŒã¿ã¹ãã¬ãŒãžããã€ã¹ã«ä¿åãããããŒã¿ãããã¯ã®äœçœ®ãæå®ããããã«äœ¿çšãããäžè¬çãªã¹ããŒã ã§ãããäžè¬çã«ã¯ããŒããã£ã¹ã¯ãã©ã€ããªã©ã®äºæ¬¡ã¹ãã¬ãŒãžã·ã¹ãã ã§äœ¿çšãããŸããLBAã¯ç¹ã«ã·ã³ãã«ãªç·åœ¢ã¢ãã¬ãã·ã³ã°ã¹ããŒã ã§ããããããã¯ã¯æŽæ°ã€ã³ããã¯ã¹ã«ãã£ãŠäœçœ®ä»ããããæåã®ãããã¯ã¯LBA 0ã2çªç®ã¯LBA 1ããšããããã«ç¶ããŸãã
GPT (GUIDããŒãã£ã·ã§ã³ããŒãã«)
GUIDããŒãã£ã·ã§ã³ããŒãã«ãéç§°GPTã¯ãMBRïŒãã¹ã¿ãŒããŒãã¬ã³ãŒãïŒãšæ¯èŒããŠãã®åŒ·åãããæ©èœã®ããã«å¥œãŸããŠããŸããGPTã¯ãããŒãã£ã·ã§ã³ã®ããã®ã°ããŒãã«ã«äžæã®èå¥åãæã€ããšãç¹åŸŽã§ãããã€ãã®ç¹ã§éç«ã£ãŠããŸãïŒ
- äœçœ®ãšãµã€ãº: GPTãšMBRã¯äž¡æ¹ãšãã»ã¯ã¿ãŒ0ããå§ãŸããŸããããããGPTã¯64ãããã§åäœããMBRã®32ããããšã¯å¯Ÿç §çã§ãã
- ããŒãã£ã·ã§ã³å¶é: GPTã¯Windowsã·ã¹ãã ã§æå€§128ããŒãã£ã·ã§ã³ããµããŒãããæå€§9.4ZBã®ããŒã¿ãå容ã§ããŸãã
- ããŒãã£ã·ã§ã³å: æå€§36ã®Unicodeæåã§ããŒãã£ã·ã§ã³ã«ååãä»ããããšãã§ããŸãã
ããŒã¿ã®èé害æ§ãšå埩:
- åé·æ§: MBRãšã¯ç°ãªããGPTã¯ããŒãã£ã·ã§ãã³ã°ãšããŒãããŒã¿ãåäžã®å Žæã«å¶éããŸããããã£ã¹ã¯å šäœã«ãã®ããŒã¿ãè€è£œããããŒã¿ã®æŽåæ§ãšèé害æ§ãåäžãããŸãã
- 埪ç°åé·æ€æ» (CRC): GPTã¯ããŒã¿ã®æŽåæ§ã確ä¿ããããã«CRCã䜿çšããŸããããŒã¿ã®ç Žæãç©æ¥µçã«ç£èŠããæ€åºãããå ŽåãGPTã¯å¥ã®ãã£ã¹ã¯äœçœ®ããç ŽæããããŒã¿ãå埩ããããšããŸãã
ä¿è·MBR (LBA0):
- GPTã¯ä¿è·MBRãéããŠåŸæ¹äºææ§ãç¶æããŸãããã®æ©èœã¯ã¬ã¬ã·ãŒMBRã¹ããŒã¹ã«ååšããŸãããå€ãMBRããŒã¹ã®ãŠãŒãã£ãªãã£ã誀ã£ãŠGPTãã£ã¹ã¯ãäžæžãããã®ãé²ãããã«èšèšãããŠããããããã£ãŠGPTãã©ãŒãããã®ãã£ã¹ã¯äžã®ããŒã¿ã®æŽåæ§ãä¿è·ããŸãã
.png)
ãã€ããªããMBR (LBA 0 + GPT)
EFIã§ã¯ãªãBIOSãµãŒãã¹ãä»ããŠGPTããŒã¹ã®ããŒãããµããŒããããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã¯ãæåã®ã»ã¯ã¿ãŒã¯ããŒãããŒããŒã³ãŒãã®æåã®ã¹ããŒãžãä¿åããããã«ã䜿çšãããå¯èœæ§ããããŸãããGPT ããŒãã£ã·ã§ã³ãèªèããããã«ä¿®æ£ãããŠããŸããMBRã®ããŒãããŒããŒã¯ã512ãã€ãã®ã»ã¯ã¿ãŒãµã€ãºãä»®å®ããŠã¯ãªããŸããã
ããŒãã£ã·ã§ã³ããŒãã«ããã㌠(LBA 1)
ããŒãã£ã·ã§ã³ããŒãã«ããããŒã¯ããã£ã¹ã¯äžã®äœ¿çšå¯èœãªãããã¯ãå®çŸ©ããŸãããŸããããŒãã£ã·ã§ã³ããŒãã«ãæ§æããããŒãã£ã·ã§ã³ãšã³ããªã®æ°ãšãµã€ãºãå®çŸ©ããŸãïŒããŒãã«å ã®ãªãã»ãã80ããã³84ïŒã
| ãªãã»ãã | é·ã | å 容 |
|---|---|---|
| 0 (0x00) | 8ãã€ã | ã·ã°ãã㣠(âEFI PARTâ, 45h 46h 49h 20h 50h 41h 52h 54h ãŸã㯠0x5452415020494645ULL ãªãã«ãšã³ãã£ã¢ã³ãã·ã³äž) |
| 8 (0x08) | 4ãã€ã | ããŒãžã§ã³ 1.0 (00h 00h 01h 00h) for UEFI 2.8 |
| 12 (0x0C) | 4ãã€ã | ããããŒãµã€ãºïŒãªãã«ãšã³ãã£ã¢ã³ããã€ãåäœãéåžžã¯5Ch 00h 00h 00hãŸãã¯92ãã€ãïŒ |
| 16 (0x10) | 4ãã€ã | ããããŒã®CRC32ïŒãªãã»ãã +0ããããããŒãµã€ãºãŸã§ïŒãªãã«ãšã³ãã£ã¢ã³ã§ããã®ãã£ãŒã«ãã¯èšç®äžã«ãŒãã«èšå®ãããŸã |
| 20 (0x14) | 4ãã€ã | äºçŽ; ãŒãã§ãªããã°ãªããªã |
| 24 (0x18) | 8ãã€ã | çŸåšã®LBAïŒãã®ããããŒã³ããŒã®äœçœ®ïŒ |
| 32 (0x20) | 8ãã€ã | ããã¯ã¢ããLBAïŒä»ã®ããããŒã³ããŒã®äœçœ®ïŒ |
| 40 (0x28) | 8ãã€ã | ããŒãã£ã·ã§ã³ã®ããã®æåã®äœ¿çšå¯èœLBAïŒãã©ã€ããªããŒãã£ã·ã§ã³ããŒãã«ã®æåŸã®LBA + 1ïŒ |
| 48 (0x30) | 8ãã€ã | æåŸã®äœ¿çšå¯èœLBAïŒã»ã«ã³ããªããŒãã£ã·ã§ã³ããŒãã«ã®æåã®LBA â 1ïŒ |
| 56 (0x38) | 16ãã€ã | ãã£ã¹ã¯GUIDïŒæ··åãšã³ãã£ã¢ã³ïŒ |
| 72 (0x48) | 8ãã€ã | ããŒãã£ã·ã§ã³ãšã³ããªã®é åã®éå§LBAïŒåžžã«ãã©ã€ããªã³ããŒã§2ïŒ |
| 80 (0x50) | 4ãã€ã | é åå ã®ããŒãã£ã·ã§ã³ãšã³ããªã®æ° |
| 84 (0x54) | 4ãã€ã | åäžã®ããŒãã£ã·ã§ã³ãšã³ããªã®ãµã€ãºïŒéåžžã¯80hãŸãã¯128ïŒ |
| 88 (0x58) | 4ãã€ã | ããŒãã£ã·ã§ã³ãšã³ããªé åã®ãªãã«ãšã³ãã£ã¢ã³ã§ã®CRC32 |
| 92 (0x5C) | * | äºçŽ; ãããã¯ã®æ®ãã®éšåã¯ãŒãã§ãªããã°ãªããªãïŒ512ãã€ãã®ã»ã¯ã¿ãŒãµã€ãºã®å Žå420ãã€ã; ãã ãããã倧ããªã»ã¯ã¿ãŒãµã€ãºã§ã¯ããå€ããªãå¯èœæ§ããããŸãïŒ |
ããŒãã£ã·ã§ã³ãšã³ã㪠(LBA 2â33)
| GUIDããŒãã£ã·ã§ã³ãšã³ããªåœ¢åŒ | ||
|---|---|---|
| ãªãã»ãã | é·ã | å 容 |
| 0 (0x00) | 16ãã€ã | ããŒãã£ã·ã§ã³ã¿ã€ãGUIDïŒæ··åãšã³ãã£ã¢ã³ïŒ |
| 16 (0x10) | 16ãã€ã | äžæã®ããŒãã£ã·ã§ã³GUIDïŒæ··åãšã³ãã£ã¢ã³ïŒ |
| 32 (0x20) | 8ãã€ã | æåã®LBAïŒãªãã«ãšã³ãã£ã¢ã³ïŒ |
| 40 (0x28) | 8ãã€ã | æåŸã®LBAïŒå«ããéåžžã¯å¥æ°ïŒ |
| 48 (0x30) | 8ãã€ã | 屿§ãã©ã°ïŒäŸïŒããã60ã¯èªã¿åãå°çšã瀺ãïŒ |
| 56 (0x38) | 72ãã€ã | ããŒãã£ã·ã§ã³åïŒ36 UTF-16LEã³ãŒããŠãããïŒ |
ããŒãã£ã·ã§ã³ã¿ã€ã
.png)
ããå€ãã®ããŒãã£ã·ã§ã³ã¿ã€ãã¯https://en.wikipedia.org/wiki/GUID_Partition_Tableã«ãããŸãã
æ€æ»
ArsenalImageMounterã䜿çšããŠãã©ã¬ã³ãžãã¯ã€ã¡ãŒãžãããŠã³ãããåŸãWindowsããŒã«Active Disk Editorã䜿çšããŠæåã®ã»ã¯ã¿ãŒãæ€æ»ã§ããŸããæ¬¡ã®ç»åã§ã¯ãã»ã¯ã¿ãŒ0ã§MBRãæ€åºãããè§£éãããŸããïŒ
.png)
ãããMBRã®ä»£ããã«GPTããŒãã«ã§ãã£ãå Žåãã»ã¯ã¿ãŒ1ã«_EFI PART_ãšããã·ã°ããã£ã衚瀺ãããã¯ãã§ãïŒåã®ç»åã§ã¯ç©ºã§ãïŒã
ãã¡ã€ã«ã·ã¹ãã
Windowsãã¡ã€ã«ã·ã¹ãã ãªã¹ã
- FAT12/16: MSDOS, WIN95/98/NT/200
- FAT32: 95/2000/XP/2003/VISTA/7/8/10
- ExFAT: 2008/2012/2016/VISTA/7/8/10
- NTFS: XP/2003/2008/2012/VISTA/7/8/10
- ReFS: 2012/2016
FAT
FAT (ãã¡ã€ã«ã¢ãã±ãŒã·ã§ã³ããŒãã«)ãã¡ã€ã«ã·ã¹ãã ã¯ããã®ã³ã¢ã³ã³ããŒãã³ãã§ãããã¡ã€ã«ã¢ãã±ãŒã·ã§ã³ããŒãã«ãããªã¥ãŒã ã®éå§äœçœ®ã«é 眮ããããã«èšèšãããŠããŸãããã®ã·ã¹ãã ã¯ã2ã€ã®ã³ããŒã®ããŒãã«ãç¶æããããšã«ãã£ãŠããŒã¿ãä¿è·ãã1ã€ãç ŽæããŠãããŒã¿ã®æŽåæ§ã確ä¿ããŸããããŒãã«ãšã«ãŒããã©ã«ããŒã¯åºå®äœçœ®ã«ååšããå¿ èŠããããã·ã¹ãã ã®èµ·åããã»ã¹ã«ãšã£ãŠéèŠã§ãã
ãã¡ã€ã«ã·ã¹ãã ã®åºæ¬çãªã¹ãã¬ãŒãžåäœã¯ã¯ã©ã¹ã¿ãŒãéåžžã¯512Bã§ãããè€æ°ã®ã»ã¯ã¿ãŒã§æ§æãããŠããŸããFATã¯ããŒãžã§ã³ãéããŠé²åããŠããŸããïŒ
- FAT12ã¯ã12ãããã®ã¯ã©ã¹ã¿ãŒã¢ãã¬ã¹ããµããŒãããæå€§4078ã¯ã©ã¹ã¿ãŒïŒUNIXã§ã¯4084ïŒãåŠçããŸãã
- FAT16ã¯ã16ãããã¢ãã¬ã¹ã«æ¡åŒµãããæå€§65,517ã¯ã©ã¹ã¿ãŒãå容ããŸãã
- FAT32ã¯ã32ãããã¢ãã¬ã¹ã§ããã«é²åããããªã¥ãŒã ããšã«é©ç°çãª268,435,456ã¯ã©ã¹ã¿ãŒãèš±å¯ããŸãã
FATããŒãžã§ã³å šäœã«å ±éããéèŠãªå¶éã¯ã4GBã®æå€§ãã¡ã€ã«ãµã€ãºã§ãããããã¯ãã¡ã€ã«ãµã€ãºã¹ãã¬ãŒãžã«äœ¿çšããã32ããããã£ãŒã«ãã«ãã£ãŠèª²ããããŠããŸãã
ç¹ã«FAT12ããã³FAT16ã®ã«ãŒããã£ã¬ã¯ããªã®äž»èŠãªã³ã³ããŒãã³ãã«ã¯ä»¥äžãå«ãŸããŸãïŒ
- ãã¡ã€ã«/ãã©ã«ããŒåïŒæå€§8æåïŒ
- 屿§
- äœæã倿Žãæçµã¢ã¯ã»ã¹æ¥
- FATããŒãã«ã¢ãã¬ã¹ïŒãã¡ã€ã«ã®éå§ã¯ã©ã¹ã¿ãŒã瀺ãïŒ
- ãã¡ã€ã«ãµã€ãº
EXT
Ext2ã¯ããžã£ãŒããªã³ã°ããªãããŒãã£ã·ã§ã³ïŒããŸã倿ŽãããªãããŒãã£ã·ã§ã³ïŒã«æãäžè¬çã«äœ¿çšããããã¡ã€ã«ã·ã¹ãã ã§ããExt3/4ã¯ãžã£ãŒããªã³ã°ãè¡ããéåžžã¯æ®ãã®ããŒãã£ã·ã§ã³ã«äœ¿çšãããŸãã
ã¡ã¿ããŒã¿
äžéšã®ãã¡ã€ã«ã«ã¯ã¡ã¿ããŒã¿ãå«ãŸããŠããŸãããã®æ å ±ã¯ãã¡ã€ã«ã®å 容ã«é¢ãããã®ã§ããããã¡ã€ã«ã¿ã€ãã«ãã£ãŠã¯ã¢ããªã¹ãã«ãšã£ãŠè峿·±ãæ å ±ãæã£ãŠããå ŽåããããŸããäŸãã°ã以äžã®ãããªæ å ±ãå«ãŸããããšããããŸãïŒ
- ã¿ã€ãã«
- 䜿çšãããMS OfficeããŒãžã§ã³
- èè
- äœææ¥ããã³æçµå€æŽæ¥
- ã«ã¡ã©ã®ã¢ãã«
- GPS座æš
- ç»åæ å ±
exiftoolãMetadiverã®ãããªããŒã«ã䜿çšããŠããã¡ã€ã«ã®ã¡ã¿ããŒã¿ãååŸã§ããŸãã
åé€ãã¡ã€ã«ã®å埩
ãã°ãããåé€ãã¡ã€ã«
åè¿°ã®ããã«ããã¡ã€ã«ããåé€ããããåŸã§ãããã¡ã€ã«ããŸã ä¿åãããŠããå Žæãããã€ããããŸããããã¯ãéåžžããã¡ã€ã«ã·ã¹ãã ãããã¡ã€ã«ãåé€ããããšã¯åã«åé€ããããšããŒã¯ããã ãã§ãããŒã¿ã¯è§Šããããªãããã§ãããããã£ãŠããã¡ã€ã«ã®ã¬ãžã¹ããªïŒMFTã®ãããªïŒãæ€æ»ããåé€ããããã¡ã€ã«ãèŠã€ããããšãå¯èœã§ãã
ãŸããOSã¯éåžžããã¡ã€ã«ã·ã¹ãã ã®å€æŽãããã¯ã¢ããã«é¢ããå€ãã®æ å ±ãä¿åããŠããããããããã䜿çšããŠãã¡ã€ã«ãå埩ããããã§ããã ãå€ãã®æ å ±ãååããããšãå¯èœã§ãã
File/Data Carving & Recovery Tools
ãã¡ã€ã«ã«ãŒãã³ã°
ãã¡ã€ã«ã«ãŒãã³ã°ã¯ãããŒã¿ã®å¡ã®äžãããã¡ã€ã«ãèŠã€ããããšããæè¡ã§ãããã®ãããªããŒã«ãæ©èœããäž»ãªæ¹æ³ã¯3ã€ãããŸãïŒãã¡ã€ã«ã¿ã€ãã®ããããŒãšããã¿ãŒã«åºã¥ãããã¡ã€ã«ã¿ã€ãã®æ§é ã«åºã¥ããããã³ã³ã³ãã³ãèªäœã«åºã¥ãã
ãã®æè¡ã¯æçåããããã¡ã€ã«ãååããããã«ã¯æ©èœããªãããšã«æ³šæããŠãã ããããã¡ã€ã«ãé£ç¶ããã»ã¯ã¿ãŒã«ä¿åãããŠããªãå Žåããã®æè¡ã¯ãããèŠã€ããããšãã§ããªãããå°ãªããšããã®äžéšãèŠã€ããããšãã§ããŸããã
ãã¡ã€ã«ã«ãŒãã³ã°ã«äœ¿çšã§ããããŒã«ã¯ããã€ããããæ€çŽ¢ããããã¡ã€ã«ã¿ã€ããæå®ã§ããŸãã
File/Data Carving & Recovery Tools
ããŒã¿ã¹ããªãŒã Carving
ããŒã¿ã¹ããªãŒã ã«ãŒãã³ã°ã¯ãã¡ã€ã«ã«ãŒãã³ã°ã«äŒŒãŠããŸãããå®å
šãªãã¡ã€ã«ãæ¢ãã®ã§ã¯ãªããè峿·±ãæ
å ±ã®æçãæ¢ããŸãã
äŸãã°ããã°ãããURLãå«ãå®å
šãªãã¡ã€ã«ãæ¢ãã®ã§ã¯ãªãããã®æè¡ã¯URLãæ€çŽ¢ããŸãã
File/Data Carving & Recovery Tools
ã»ãã¥ã¢åé€
æããã«ããã¡ã€ã«ãããã«é¢ãããã°ã®äžéšã**ãå®å
šã«ãåé€ããæ¹æ³ããããŸããäŸãã°ããã¡ã€ã«ã®å
容ããžã£ã³ã¯ããŒã¿ã§äœåºŠãäžæžããããã®åŸ$MFTã$LOGFILEãããã¡ã€ã«ã«é¢ãããã°ãåé€**ããããªã¥ãŒã ã·ã£ããŠã³ããŒãåé€ããããšãå¯èœã§ãã
ãã®æäœãè¡ã£ãŠãããã¡ã€ã«ã®ååšããŸã ãã°ãããŠããä»ã®éšåããããããããªãããšã«æ°ä»ããããããŸããããããã¯çå®ã§ããããã©ã¬ã³ãžãã¯å°éå®¶ã®ä»äºã®äžéšã¯ããããèŠã€ããããšã§ãã
åèæç®
- https://en.wikipedia.org/wiki/GUID_Partition_Table
- http://ntfs.com/ntfs-permissions.htm
- https://www.osforensics.com/faqs-and-tutorials/how-to-scan-ntfs-i30-entries-deleted-files.html
- https://docs.microsoft.com/en-us/windows-server/storage/file-server/volume-shadow-copy-service
- iHackLabs Certified Digital Forensics Windows
Tip
AWSãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training AWS Red Team Expert (ARTE)
GCPãããã³ã°ãåŠã³ãå®è·µããïŒHackTricks Training GCP Red Team Expert (GRTE)
Azureãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training Azure Red Team Expert (AzRTE)
HackTricksããµããŒããã
- ãµãã¹ã¯ãªãã·ã§ã³ãã©ã³ã確èªããŠãã ããïŒ
- **ð¬ Discordã°ã«ãŒããŸãã¯ãã¬ã°ã©ã ã°ã«ãŒãã«åå ããããTwitter ðŠ @hacktricks_liveããã©ããŒããŠãã ããã
- HackTricksããã³HackTricks Cloudã®GitHubãªããžããªã«PRãæåºããŠãããã³ã°ããªãã¯ãå ±æããŠãã ããã


