๋ธŒ๋ผ์šฐ์ € ์•„ํ‹ฐํŒฉํŠธ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๋ธŒ๋ผ์šฐ์ € ์•„ํ‹ฐํŒฉํŠธ

๋ธŒ๋ผ์šฐ์ € ์•„ํ‹ฐํŒฉํŠธ๋Š” ๋‚ด๋น„๊ฒŒ์ด์…˜ ๊ธฐ๋ก, ์ฆ๊ฒจ์ฐพ๊ธฐ, ์บ์‹œ ๋ฐ์ดํ„ฐ ๋“ฑ ์›น ๋ธŒ๋ผ์šฐ์ €๊ฐ€ ์ €์žฅํ•˜๋Š” ๋‹ค์–‘ํ•œ ์œ ํ˜•์˜ ๋ฐ์ดํ„ฐ๋ฅผ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์•„ํ‹ฐํŒฉํŠธ๋Š” ์šด์˜์ฒด์ œ ๋‚ด์˜ ํŠน์ • ํด๋”์— ๋ณด๊ด€๋˜๋ฉฐ, ๋ธŒ๋ผ์šฐ์ €๋งˆ๋‹ค ์œ„์น˜์™€ ์ด๋ฆ„์ด ๋‹ค๋ฅด์ง€๋งŒ ์ผ๋ฐ˜์ ์œผ๋กœ ์œ ์‚ฌํ•œ ์œ ํ˜•์˜ ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

๋‹ค์Œ์€ ๊ฐ€์žฅ ์ผ๋ฐ˜์ ์ธ ๋ธŒ๋ผ์šฐ์ € ์•„ํ‹ฐํŒฉํŠธ์˜ ์š”์•ฝ์ž…๋‹ˆ๋‹ค:

  • Navigation History: ์‚ฌ์šฉ์ž์˜ ์›น์‚ฌ์ดํŠธ ๋ฐฉ๋ฌธ์„ ์ถ”์ ํ•˜๋ฉฐ, ์•…์„ฑ ์‚ฌ์ดํŠธ ๋ฐฉ๋ฌธ ์‹๋ณ„์— ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค.
  • Autocomplete Data: ์ž์ฃผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒ€์ƒ‰์„ ๊ธฐ๋ฐ˜์œผ๋กœ ํ•œ ์ œ์•ˆ์œผ๋กœ, ๋‚ด๋น„๊ฒŒ์ด์…˜ ๊ธฐ๋ก๊ณผ ๊ฒฐํ•ฉํ•˜๋ฉด ์œ ์šฉํ•œ ํ†ต์ฐฐ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
  • Bookmarks: ์‚ฌ์šฉ์ž๊ฐ€ ๋น ๋ฅด๊ฒŒ ์ ‘๊ทผํ•˜๊ธฐ ์œ„ํ•ด ์ €์žฅํ•œ ์‚ฌ์ดํŠธ๋“ค์ž…๋‹ˆ๋‹ค.
  • Extensions and Add-ons: ์‚ฌ์šฉ์ž๊ฐ€ ์„ค์น˜ํ•œ ๋ธŒ๋ผ์šฐ์ € ํ™•์žฅ ๋˜๋Š” ์• ๋“œ์˜จ์ž…๋‹ˆ๋‹ค.
  • Cache: ์›น ์ฝ˜ํ…์ธ (์˜ˆ: ์ด๋ฏธ์ง€, JavaScript ํŒŒ์ผ)๋ฅผ ์ €์žฅํ•˜์—ฌ ์›น์‚ฌ์ดํŠธ ๋กœ๋”ฉ ์‹œ๊ฐ„์„ ๊ฐœ์„ ํ•˜๋ฉฐ, ํฌ๋ Œ์‹ ๋ถ„์„์— ๊ฐ€์น˜๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Logins: ์ €์žฅ๋œ ๋กœ๊ทธ์ธ ์ž๊ฒฉ ์ฆ๋ช…์ž…๋‹ˆ๋‹ค.
  • Favicons: ํƒญ๊ณผ ์ฆ๊ฒจ์ฐพ๊ธฐ์— ํ‘œ์‹œ๋˜๋Š” ์›น์‚ฌ์ดํŠธ ์•„์ด์ฝ˜์œผ๋กœ, ์‚ฌ์šฉ์ž์˜ ๋ฐฉ๋ฌธ์— ๋Œ€ํ•œ ์ถ”๊ฐ€ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Browser Sessions: ์—ด๋ฆฐ ๋ธŒ๋ผ์šฐ์ € ์„ธ์…˜๊ณผ ๊ด€๋ จ๋œ ๋ฐ์ดํ„ฐ์ž…๋‹ˆ๋‹ค.
  • Downloads: ๋ธŒ๋ผ์šฐ์ €๋ฅผ ํ†ตํ•ด ๋‹ค์šด๋กœ๋“œํ•œ ํŒŒ์ผ์˜ ๊ธฐ๋ก์ž…๋‹ˆ๋‹ค.
  • Form Data: ์›น ํผ์— ์ž…๋ ฅ๋œ ์ •๋ณด๋กœ, ์ดํ›„ ์ž๋™ ์™„์„ฑ ์ œ์•ˆ์„ ์œ„ํ•ด ์ €์žฅ๋ฉ๋‹ˆ๋‹ค.
  • Thumbnails: ์›น์‚ฌ์ดํŠธ์˜ ๋ฏธ๋ฆฌ๋ณด๊ธฐ ์ด๋ฏธ์ง€์ž…๋‹ˆ๋‹ค.
  • Custom Dictionary.txt: ์‚ฌ์šฉ์ž๊ฐ€ ๋ธŒ๋ผ์šฐ์ € ์‚ฌ์ „์— ์ถ”๊ฐ€ํ•œ ๋‹จ์–ด๋“ค์ž…๋‹ˆ๋‹ค.

Firefox

Firefox๋Š” ํ”„๋กœํŒŒ์ผ ๋‚ด์— ์‚ฌ์šฉ์ž ๋ฐ์ดํ„ฐ๋ฅผ ๊ตฌ์„ฑํ•˜๋ฉฐ, ์šด์˜์ฒด์ œ์— ๋”ฐ๋ผ ํŠน์ • ์œ„์น˜์— ์ €์žฅ๋ฉ๋‹ˆ๋‹ค:

  • Linux: ~/.mozilla/firefox/
  • MacOS: /Users/$USER/Library/Application Support/Firefox/Profiles/
  • Windows: %userprofile%\AppData\Roaming\Mozilla\Firefox\Profiles\

์ด ๋””๋ ‰ํ„ฐ๋ฆฌ๋“ค ์•ˆ์˜ profiles.ini ํŒŒ์ผ์€ ์‚ฌ์šฉ์ž ํ”„๋กœํŒŒ์ผ์„ ๋‚˜์—ดํ•ฉ๋‹ˆ๋‹ค. ๊ฐ ํ”„๋กœํŒŒ์ผ์˜ ๋ฐ์ดํ„ฐ๋Š” profiles.ini ๋‚ด Path ๋ณ€์ˆ˜์— ๋ช…์‹œ๋œ ์ด๋ฆ„์˜ ํด๋”์— ์ €์žฅ๋˜๋ฉฐ, ํ•ด๋‹น ํด๋”๋Š” profiles.ini๊ฐ€ ์žˆ๋Š” ๋™์ผํ•œ ๋””๋ ‰ํ„ฐ๋ฆฌ์— ์œ„์น˜ํ•ฉ๋‹ˆ๋‹ค. ํ”„๋กœํŒŒ์ผ ํด๋”๊ฐ€ ์—†์œผ๋ฉด ์‚ญ์ œ๋˜์—ˆ์„ ๊ฐ€๋Šฅ์„ฑ์ด ์žˆ์Šต๋‹ˆ๋‹ค.

๊ฐ ํ”„๋กœํŒŒ์ผ ํด๋” ๋‚ด์—์„œ ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ค‘์š”ํ•œ ํŒŒ์ผ๋“ค์„ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

  • places.sqlite: ๊ธฐ๋ก, ์ฆ๊ฒจ์ฐพ๊ธฐ, ๋‹ค์šด๋กœ๋“œ๋ฅผ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค. Windows์—์„œ BrowsingHistoryView ๊ฐ™์€ ๋„๊ตฌ๋กœ ๊ธฐ๋ก ๋ฐ์ดํ„ฐ๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • ํŠน์ • SQL ์ฟผ๋ฆฌ๋ฅผ ์‚ฌ์šฉํ•ด ๊ธฐ๋ก ๋ฐ ๋‹ค์šด๋กœ๋“œ ์ •๋ณด๋ฅผ ์ถ”์ถœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • bookmarkbackups: ์ฆ๊ฒจ์ฐพ๊ธฐ ๋ฐฑ์—…์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค.
  • formhistory.sqlite: ์›น ํผ ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.
  • handlers.json: ํ”„๋กœํ† ์ฝœ ํ•ธ๋“ค๋Ÿฌ๋ฅผ ๊ด€๋ฆฌํ•ฉ๋‹ˆ๋‹ค.
  • persdict.dat: ์‚ฌ์šฉ์ž ์ง€์ • ์‚ฌ์ „ ๋‹จ์–ด๋“ค์ž…๋‹ˆ๋‹ค.
  • addons.json ๋ฐ extensions.sqlite: ์„ค์น˜๋œ ์• ๋“œ์˜จ ๋ฐ ํ™•์žฅ์— ๋Œ€ํ•œ ์ •๋ณด์ž…๋‹ˆ๋‹ค.
  • cookies.sqlite: ์ฟ ํ‚ค ์ €์žฅ์†Œ๋กœ, Windows์—์„œ๋Š” MZCookiesView๋กœ ๊ฒ€์‚ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • cache2/entries ๋˜๋Š” startupCache: ์บ์‹œ ๋ฐ์ดํ„ฐ๋กœ, MozillaCacheView ๊ฐ™์€ ๋„๊ตฌ๋กœ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • favicons.sqlite: ํŒŒ๋น„์ฝ˜์„ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.
  • prefs.js: ์‚ฌ์šฉ์ž ์„ค์ • ๋ฐ ํ™˜๊ฒฝ์„ค์ •์ž…๋‹ˆ๋‹ค.
  • downloads.sqlite: ์ด์ „์˜ ๋‹ค์šด๋กœ๋“œ ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค๋กœ, ํ˜„์žฌ๋Š” places.sqlite์— ํ†ตํ•ฉ๋˜์—ˆ์Šต๋‹ˆ๋‹ค.
  • thumbnails: ์›น์‚ฌ์ดํŠธ ์ธ๋„ค์ผ์ž…๋‹ˆ๋‹ค.
  • logins.json: ์•”ํ˜ธํ™”๋œ ๋กœ๊ทธ์ธ ์ •๋ณด์ž…๋‹ˆ๋‹ค.
  • key4.db ๋˜๋Š” key3.db: ๋ฏผ๊ฐํ•œ ์ •๋ณด๋ฅผ ๋ณดํ˜ธํ•˜๊ธฐ ์œ„ํ•œ ์•”ํ˜ธํ™” ํ‚ค๋ฅผ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค.

๋˜ํ•œ, ๋ธŒ๋ผ์šฐ์ €์˜ ์•ˆํ‹ฐ ํ”ผ์‹ฑ ์„ค์ •์€ prefs.js์—์„œ browser.safebrowsing ํ•ญ๋ชฉ์„ ๊ฒ€์ƒ‰ํ•˜์—ฌ ์•ˆ์ „ํ•œ ๋ธŒ๋ผ์šฐ์ง• ๊ธฐ๋Šฅ์ด ํ™œ์„ฑํ™”๋˜์—ˆ๋Š”์ง€ ์—ฌ๋ถ€๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋งˆ์Šคํ„ฐ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ๋ณตํ˜ธํ™”ํ•˜๋ ค ์‹œ๋„ํ•˜๋ ค๋ฉด https://github.com/unode/firefox_decrypt\
๋‹ค์Œ ์Šคํฌ๋ฆฝํŠธ์™€ ํ˜ธ์ถœ๋กœ ๋ธŒ๋ฃจํŠธํฌ์Šค์— ์‚ฌ์šฉํ•  ๋น„๋ฐ€๋ฒˆํ˜ธ ํŒŒ์ผ์„ ์ง€์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

#!/bin/bash

#./brute.sh top-passwords.txt 2>/dev/null | grep -A2 -B2 "chrome:"
passfile=$1
while read pass; do
echo "Trying $pass"
echo "$pass" | python firefox_decrypt.py
done < $passfile

Google Chrome

Google Chrome๋Š” ์šด์˜์ฒด์ œ์— ๋”ฐ๋ผ ์‚ฌ์šฉ์ž ํ”„๋กœํ•„์„ ๋‹ค์Œ ์œ„์น˜์— ์ €์žฅํ•ฉ๋‹ˆ๋‹ค:

  • Linux: ~/.config/google-chrome/
  • Windows: C:\Users\XXX\AppData\Local\Google\Chrome\User Data\
  • MacOS: /Users/$USER/Library/Application Support/Google/Chrome/

์ด ๋””๋ ‰ํ„ฐ๋ฆฌ ๋‚ด์—์„œ ๋Œ€๋ถ€๋ถ„์˜ ์‚ฌ์šฉ์ž ๋ฐ์ดํ„ฐ๋Š” Default/ ๋˜๋Š” ChromeDefaultData/ ํด๋”์—์„œ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ ํŒŒ์ผ๋“ค์ด ์ค‘์š”ํ•œ ๋ฐ์ดํ„ฐ๋ฅผ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค:

  • History: URL, ๋‹ค์šด๋กœ๋“œ ๋ฐ ๊ฒ€์ƒ‰ ํ‚ค์›Œ๋“œ๋ฅผ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค. Windows์—์„œ๋Š” ChromeHistoryView๋ฅผ ์‚ฌ์šฉํ•ด ๊ธฐ๋ก์„ ์ฝ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. โ€œTransition Typeโ€ ์—ด์€ ๋งํฌ ํด๋ฆญ, ์ง์ ‘ ์ž…๋ ฅํ•œ URL, ํผ ์ œ์ถœ, ํŽ˜์ด์ง€ ์ƒˆ๋กœ๊ณ ์นจ ๋“ฑ ๋‹ค์–‘ํ•œ ์˜๋ฏธ๋ฅผ ๊ฐ€์ง‘๋‹ˆ๋‹ค.
  • Cookies: ์ฟ ํ‚ค๋ฅผ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค. ๊ฒ€์‚ฌํ•˜๋ ค๋ฉด ChromeCookiesView๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
  • Cache: ์บ์‹œ๋œ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณด๊ด€ํ•ฉ๋‹ˆ๋‹ค. ๊ฒ€์‚ฌํ•˜๋ ค๋ฉด Windows ์‚ฌ์šฉ์ž๋Š” ChromeCacheView๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Electron ๊ธฐ๋ฐ˜ ๋ฐ์Šคํฌํ†ฑ ์•ฑ(์˜ˆ: Discord)๋„ Chromium Simple Cache๋ฅผ ์‚ฌ์šฉํ•˜๋ฉฐ ํ’๋ถ€ํ•œ ๋””์Šคํฌ ์ƒ์˜ ์•„ํ‹ฐํŒฉํŠธ๋ฅผ ๋‚จ๊น๋‹ˆ๋‹ค. ์ฐธ์กฐ:

Discord Cache Forensics

  • Bookmarks: ์‚ฌ์šฉ์ž ์ฆ๊ฒจ์ฐพ๊ธฐ.
  • Web Data: ํผ ํžˆ์Šคํ† ๋ฆฌ ํฌํ•จ.
  • Favicons: ์›น์‚ฌ์ดํŠธ ํŒŒ๋น„์ฝ˜ ์ €์žฅ.
  • Login Data: ์‚ฌ์šฉ์ž ์ด๋ฆ„๊ณผ ๋น„๋ฐ€๋ฒˆํ˜ธ ๊ฐ™์€ ๋กœ๊ทธ์ธ ์ž๊ฒฉ ์ฆ๋ช…์„ ํฌํ•จํ•ฉ๋‹ˆ๋‹ค.
  • Current Session/Current Tabs: ํ˜„์žฌ ๋ธŒ๋ผ์šฐ์ง• ์„ธ์…˜๊ณผ ์—ด๋ฆฐ ํƒญ์— ๋Œ€ํ•œ ๋ฐ์ดํ„ฐ.
  • Last Session/Last Tabs: Chrome ์ข…๋ฃŒ ์ง์ „ ๋งˆ์ง€๋ง‰ ์„ธ์…˜ ๋™์•ˆ ํ™œ์„ฑํ™”๋œ ์‚ฌ์ดํŠธ ์ •๋ณด.
  • Extensions: ๋ธŒ๋ผ์šฐ์ € ํ™•์žฅ ๋ฐ ์• ๋“œ์˜จ ๋””๋ ‰ํ„ฐ๋ฆฌ.
  • Thumbnails: ์›น์‚ฌ์ดํŠธ ์ธ๋„ค์ผ ์ €์žฅ.
  • Preferences: ํ”Œ๋Ÿฌ๊ทธ์ธ, ํ™•์žฅ, ํŒ์—…, ์•Œ๋ฆผ ๋“ฑ ์„ค์ •์„ ํฌํ•จํ•œ ๋งŽ์€ ์ •๋ณด๋ฅผ ๋‹ด๊ณ  ์žˆ๋Š” ํŒŒ์ผ์ž…๋‹ˆ๋‹ค.
  • Browserโ€™s built-in anti-phishing: ์•ˆํ‹ฐ ํ”ผ์‹ฑ ๋ฐ ๋งฌ์›จ์–ด ๋ณดํ˜ธ๊ฐ€ ํ™œ์„ฑํ™”๋˜์—ˆ๋Š”์ง€ ํ™•์ธํ•˜๋ ค๋ฉด grep 'safebrowsing' ~/Library/Application Support/Google/Chrome/Default/Preferences๋ฅผ ์‹คํ–‰ํ•˜์„ธ์š”. ์ถœ๋ ฅ์—์„œ {"enabled: true,"}๋ฅผ ์ฐพ์œผ์„ธ์š”.

SQLite DB Data Recovery

์•ž์˜ ์„น์…˜์—์„œ ์•Œ ์ˆ˜ ์žˆ๋“ฏ์ด Chrome๊ณผ Firefox๋Š” ๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•˜๊ธฐ ์œ„ํ•ด SQLite ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. sqlparse ๋˜๋Š” sqlparse_gui ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์‚ญ์ œ๋œ ํ•ญ๋ชฉ์„ ๋ณต๊ตฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Internet Explorer 11

Internet Explorer 11์€ ๋ฐ์ดํ„ฐ์™€ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋ฅผ ์—ฌ๋Ÿฌ ์œ„์น˜์— ๊ฑธ์ณ ๊ด€๋ฆฌํ•˜์—ฌ ์ €์žฅ๋œ ์ •๋ณด์™€ ํ•ด๋‹น ์„ธ๋ถ€ ์ •๋ณด๋ฅผ ๋ถ„๋ฆฌํ•ด ์‰ฝ๊ฒŒ ์ ‘๊ทผํ•˜๊ณ  ๊ด€๋ฆฌํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•ฉ๋‹ˆ๋‹ค.

Metadata Storage

Internet Explorer์˜ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋Š” %userprofile%\Appdata\Local\Microsoft\Windows\WebCache\WebcacheVX.data์— ์ €์žฅ๋ฉ๋‹ˆ๋‹ค (VX๋Š” V01, V16 ๋˜๋Š” V24). ์ด์™€ ํ•จ๊ป˜ V01.log ํŒŒ์ผ์€ WebcacheVX.data์™€ ์ˆ˜์ • ์‹œ๊ฐ„์— ๋ถˆ์ผ์น˜๊ฐ€ ๋ณด์ผ ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์ด ๊ฒฝ์šฐ esentutl /r V01 /d๋กœ ๋ณต๊ตฌ๊ฐ€ ํ•„์š”ํ•จ์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. ์ด ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋Š” ESE ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ์ €์žฅ๋˜์–ด ์žˆ์œผ๋ฉฐ photorec ๋ฐ ESEDatabaseView ๊ฐ™์€ ๋„๊ตฌ๋กœ ๋ณต๊ตฌ ๋ฐ ๊ฒ€์‚ฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Containers ํ…Œ์ด๋ธ”์—์„œ๋Š” ๊ฐ ๋ฐ์ดํ„ฐ ์กฐ๊ฐ์ด ์ €์žฅ๋œ ํŠน์ • ํ…Œ์ด๋ธ”์ด๋‚˜ ์ปจํ…Œ์ด๋„ˆ(์˜ˆ: Skype์™€ ๊ฐ™์€ ๋‹ค๋ฅธ Microsoft ๋„๊ตฌ์˜ ์บ์‹œ ์„ธ๋ถ€์‚ฌํ•ญ)๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Cache Inspection

IECacheView ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•˜๋ฉด ์บ์‹œ๋ฅผ ๊ฒ€์‚ฌํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์บ์‹œ ๋ฐ์ดํ„ฐ ์ถ”์ถœ ํด๋” ์œ„์น˜๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ์บ์‹œ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์—๋Š” ํŒŒ์ผ ์ด๋ฆ„, ๋””๋ ‰ํ„ฐ๋ฆฌ, ์ ‘๊ทผ ํšŸ์ˆ˜, URL ์ถœ์ฒ˜ ๋ฐ ์บ์‹œ ์ƒ์„ฑ, ์ ‘๊ทผ, ์ˆ˜์ •, ๋งŒ๋ฃŒ ์‹œ๊ฐ„์„ ๋‚˜ํƒ€๋‚ด๋Š” ํƒ€์ž„์Šคํƒฌํ”„๊ฐ€ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค.

Cookies Management

์ฟ ํ‚ค๋Š” IECookiesView๋กœ ํƒ์ƒ‰ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์—๋Š” ์ด๋ฆ„, URL, ์ ‘๊ทผ ํšŸ์ˆ˜ ๋ฐ ๋‹ค์–‘ํ•œ ์‹œ๊ฐ„ ๊ด€๋ จ ์ •๋ณด๊ฐ€ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. ์˜๊ตฌ ์ฟ ํ‚ค๋Š” %userprofile%\Appdata\Roaming\Microsoft\Windows\Cookies์— ์ €์žฅ๋˜๋ฉฐ ์„ธ์…˜ ์ฟ ํ‚ค๋Š” ๋ฉ”๋ชจ๋ฆฌ์— ์กด์žฌํ•ฉ๋‹ˆ๋‹ค.

Download Details

ESEDatabaseView๋กœ ๋‹ค์šด๋กœ๋“œ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ํŠน์ • ์ปจํ…Œ์ด๋„ˆ์—๋Š” URL, ํŒŒ์ผ ํ˜•์‹, ๋‹ค์šด๋กœ๋“œ ์œ„์น˜ ๊ฐ™์€ ๋ฐ์ดํ„ฐ๊ฐ€ ๋“ค์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ์‹ค์ œ ํŒŒ์ผ์€ %userprofile%\Appdata\Roaming\Microsoft\Windows\IEDownloadHistory์— ์žˆ์Šต๋‹ˆ๋‹ค.

Browsing History

๋ธŒ๋ผ์šฐ์ง• ๊ธฐ๋ก์„ ๊ฒ€ํ† ํ•˜๋ ค๋ฉด BrowsingHistoryView๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์ถ”์ถœํ•œ ํžˆ์Šคํ† ๋ฆฌ ํŒŒ์ผ์˜ ์œ„์น˜์™€ Internet Explorer ๊ตฌ์„ฑ์„ ์ง€์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์˜ ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ์—๋Š” ์ˆ˜์ • ๋ฐ ์ ‘๊ทผ ์‹œ๊ฐ„๊ณผ ์ ‘๊ทผ ํšŸ์ˆ˜๊ฐ€ ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. ํžˆ์Šคํ† ๋ฆฌ ํŒŒ์ผ์€ %userprofile%\Appdata\Local\Microsoft\Windows\History์— ์žˆ์Šต๋‹ˆ๋‹ค.

Typed URLs

์ž…๋ ฅ๋œ URL๊ณผ ์‚ฌ์šฉ ์‹œ๊ฐ„์€ NTUSER.DAT์˜ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ•˜์œ„ ํ‚ค Software\Microsoft\InternetExplorer\TypedURLs ๋ฐ Software\Microsoft\InternetExplorer\TypedURLsTime์— ์ €์žฅ๋˜๋ฉฐ, ์‚ฌ์šฉ์ž๊ฐ€ ์ž…๋ ฅํ•œ ๋งˆ์ง€๋ง‰ 50๊ฐœ์˜ URL๊ณผ ๋งˆ์ง€๋ง‰ ์ž…๋ ฅ ์‹œ๊ฐ„์„ ์ถ”์ ํ•ฉ๋‹ˆ๋‹ค.

Microsoft Edge

Microsoft Edge๋Š” ์‚ฌ์šฉ์ž ๋ฐ์ดํ„ฐ๋ฅผ %userprofile%\Appdata\Local\Packages์— ์ €์žฅํ•ฉ๋‹ˆ๋‹ค. ๋‹ค์–‘ํ•œ ๋ฐ์ดํ„ฐ ์œ ํ˜•์˜ ๊ฒฝ๋กœ๋Š” ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค:

  • Profile Path: C:\Users\XX\AppData\Local\Packages\Microsoft.MicrosoftEdge_XXX\AC
  • History, Cookies, and Downloads: C:\Users\XX\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
  • Settings, Bookmarks, and Reading List: C:\Users\XX\AppData\Local\Packages\Microsoft.MicrosoftEdge_XXX\AC\MicrosoftEdge\User\Default\DataStore\Data\nouser1\XXX\DBStore\spartan.edb
  • Cache: C:\Users\XXX\AppData\Local\Packages\Microsoft.MicrosoftEdge_XXX\AC#!XXX\MicrosoftEdge\Cache
  • Last Active Sessions: C:\Users\XX\AppData\Local\Packages\Microsoft.MicrosoftEdge_XXX\AC\MicrosoftEdge\User\Default\Recovery\Active

Safari

Safari ๋ฐ์ดํ„ฐ๋Š” /Users/$User/Library/Safari์— ์ €์žฅ๋ฉ๋‹ˆ๋‹ค. ์ฃผ์š” ํŒŒ์ผ์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค:

  • History.db: history_visits ๋ฐ history_items ํ…Œ์ด๋ธ”์— URL๊ณผ ๋ฐฉ๋ฌธ ํƒ€์ž„์Šคํƒฌํ”„๊ฐ€ ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. ์ฟผ๋ฆฌํ•˜๋ ค๋ฉด sqlite3๋ฅผ ์‚ฌ์šฉํ•˜์„ธ์š”.
  • Downloads.plist: ๋‹ค์šด๋กœ๋“œ๋œ ํŒŒ์ผ์— ๋Œ€ํ•œ ์ •๋ณด.
  • Bookmarks.plist: ์ฆ๊ฒจ์ฐพ๊ธฐ URL ์ €์žฅ.
  • TopSites.plist: ๊ฐ€์žฅ ์ž์ฃผ ๋ฐฉ๋ฌธํ•œ ์‚ฌ์ดํŠธ.
  • Extensions.plist: Safari ๋ธŒ๋ผ์šฐ์ € ํ™•์žฅ ๋ชฉ๋ก. ๊ฒ€์ƒ‰ํ•˜๋ ค๋ฉด plutil ๋˜๋Š” pluginkit์„ ์‚ฌ์šฉํ•˜์„ธ์š”.
  • UserNotificationPermissions.plist: ์•Œ๋ฆผ์„ ๋ณด๋‚ผ ์ˆ˜ ์žˆ๋„๋ก ํ—ˆ์šฉ๋œ ๋„๋ฉ”์ธ. plutil๋กœ ํŒŒ์‹ฑํ•˜์„ธ์š”.
  • LastSession.plist: ๋งˆ์ง€๋ง‰ ์„ธ์…˜์˜ ํƒญ ์ •๋ณด. plutil๋กœ ํŒŒ์‹ฑํ•˜์„ธ์š”.
  • Browserโ€™s built-in anti-phishing: defaults read com.apple.Safari WarnAboutFraudulentWebsites๋ฅผ ์‚ฌ์šฉํ•ด ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. ์ถœ๋ ฅ์ด 1์ด๋ฉด ๊ธฐ๋Šฅ์ด ํ™œ์„ฑํ™”๋œ ๊ฒƒ์ž…๋‹ˆ๋‹ค.

Opera

Opera์˜ ๋ฐ์ดํ„ฐ๋Š” /Users/$USER/Library/Application Support/com.operasoftware.Opera์— ์ €์žฅ๋˜๋ฉฐ ํžˆ์Šคํ† ๋ฆฌ ๋ฐ ๋‹ค์šด๋กœ๋“œ ํ˜•์‹์€ Chrome๊ณผ ๋™์ผํ•ฉ๋‹ˆ๋‹ค.

  • Browserโ€™s built-in anti-phishing: Preferences ํŒŒ์ผ์—์„œ fraud_protection_enabled๊ฐ€ true๋กœ ์„ค์ •๋˜์–ด ์žˆ๋Š”์ง€ grep์œผ๋กœ ํ™•์ธํ•˜์„ธ์š”.

์ด ๊ฒฝ๋กœ๋“ค๊ณผ ๋ช…๋ น๋“ค์€ ๋‹ค์–‘ํ•œ ์›น ๋ธŒ๋ผ์šฐ์ €๊ฐ€ ์ €์žฅํ•˜๋Š” ๋ธŒ๋ผ์šฐ์ง• ๋ฐ์ดํ„ฐ๋ฅผ ์ ‘๊ทผํ•˜๊ณ  ์ดํ•ดํ•˜๋Š” ๋ฐ ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค.

References

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ