ํ”ผ์‹ฑ ํƒ์ง€

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

์†Œ๊ฐœ

ํ”ผ์‹ฑ ์‹œ๋„๋ฅผ ํƒ์ง€ํ•˜๋ ค๋ฉด ์˜ค๋Š˜๋‚  ์‚ฌ์šฉ๋˜๋Š” ํ”ผ์‹ฑ ๊ธฐ์ˆ ๋“ค์„ ์ดํ•ดํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ฒŒ์‹œ๋ฌผ์˜ ์ƒ์œ„ ํŽ˜์ด์ง€์—์„œ ํ•ด๋‹น ์ •๋ณด๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ, ํ˜„์žฌ ์–ด๋–ค ๊ธฐ์ˆ ์ด ์‚ฌ์šฉ๋˜๋Š”์ง€ ๋ชจ๋ฅธ๋‹ค๋ฉด ์ƒ์œ„ ํŽ˜์ด์ง€๋กœ ๊ฐ€์„œ ์ ์–ด๋„ ๊ทธ ์„น์…˜์„ ์ฝ์–ด๋ณด์‹œ๊ธธ ๊ถŒํ•ฉ๋‹ˆ๋‹ค.

์ด ๊ฒŒ์‹œ๋ฌผ์€ ๊ณต๊ฒฉ์ž๊ฐ€ ํ”ผํ•ด์ž์˜ ๋„๋ฉ”์ธ ์ด๋ฆ„์„ ์–ด๋–ป๊ฒŒ๋“  ๋ชจ๋ฐฉํ•˜๊ฑฐ๋‚˜ ์‚ฌ์šฉํ•  ๊ฒƒ์ด๋ผ๋Š” ์•„์ด๋””์–ด์— ๊ธฐ๋ฐ˜ํ•ฉ๋‹ˆ๋‹ค. ๋งŒ์•ฝ ์—ฌ๋Ÿฌ๋ถ„์˜ ๋„๋ฉ”์ธ์ด example.com์ด๊ณ  ๊ณต๊ฒฉ์ž๊ฐ€ ์–ด๋–ค ์ด์œ ๋กœ ์™„์ „ํžˆ ๋‹ค๋ฅธ ๋„๋ฉ”์ธ ์ด๋ฆ„(youwonthelottery.com)์„ ์‚ฌ์šฉํ•ด ํ”ผ์‹ฑ์„ ์‹œ๋„ํ–ˆ๋‹ค๋ฉด, ์•„๋ž˜ ๊ธฐ์ˆ ๋“ค์€ ์ด๋ฅผ ๋ฐํ˜€๋‚ด์ง€ ๋ชปํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋„๋ฉ”์ธ ์ด๋ฆ„ ๋ณ€ํ˜•

์ด๋ฉ”์ผ ๋‚ด๋ถ€์—์„œ ์œ ์‚ฌํ•œ ๋„๋ฉ”์ธ์„ ์‚ฌ์šฉํ•˜๋Š” ํ”ผ์‹ฑ ์‹œ๋„๋Š” ์ฐพ์•„๋‚ด๊ธฐ ์ƒ๋‹นํžˆ ์‰ฝ์Šต๋‹ˆ๋‹ค.
๊ณต๊ฒฉ์ž๊ฐ€ ์‚ฌ์šฉํ•  ๊ฐ€๋Šฅ์„ฑ์ด ๋†’์€ ํ”ผ์‹ฑ ์ด๋ฆ„๋“ค์˜ ๋ชฉ๋ก์„ ์ƒ์„ฑํ•˜๊ณ , ํ•ด๋‹น ๋„๋ฉ”์ธ์ด ๋“ฑ๋ก๋˜์–ด ์žˆ๋Š”์ง€ ๋˜๋Š” ์–ด๋–ค IP์— ์‚ฌ์šฉ๋˜๊ณ  ์žˆ๋Š”์ง€ ํ™•์ธํ•˜๋ฉด ๋ฉ๋‹ˆ๋‹ค.

์˜์‹ฌ์Šค๋Ÿฌ์šด ๋„๋ฉ”์ธ ์ฐพ๊ธฐ

์ด๋ฅผ ์œ„ํ•ด ๋‹ค์Œ ๋„๊ตฌ๋“ค ์ค‘ ํ•˜๋‚˜๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๋„๊ตฌ๋“ค์€ ๋„๋ฉ”์ธ์— ํ• ๋‹น๋œ IP๊ฐ€ ์žˆ๋Š”์ง€ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด ์ž๋™์œผ๋กœ DNS ์š”์ฒญ๋„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค:

ํŒ: ํ›„๋ณด ๋ชฉ๋ก์„ ์ƒ์„ฑํ–ˆ๋‹ค๋ฉด DNS ๋ฆฌ์กธ๋ฒ„ ๋กœ๊ทธ์— ํˆฌ์ž…ํ•˜์—ฌ ์กฐ์ง ๋‚ด๋ถ€์—์„œ์˜ NXDOMAIN lookups(์‚ฌ์šฉ์ž๊ฐ€ ๊ณต๊ฒฉ์ž๊ฐ€ ์‹ค์ œ๋กœ ๋“ฑ๋กํ•˜๊ธฐ ์ „์— ์˜คํƒ€ ๋„๋ฉ”์ธ์— ์ ‘์†์„ ์‹œ๋„ํ•จ)์„ ํƒ์ง€ํ•˜์„ธ์š”. ์ •์ฑ…์ด ํ—ˆ์šฉํ•œ๋‹ค๋ฉด ์ด๋Ÿฌํ•œ ๋„๋ฉ”์ธ์„ Sinkhole ๋˜๋Š” ์‚ฌ์ „ ์ฐจ๋‹จํ•˜์„ธ์š”.

Bitflipping

์ด ๊ธฐ์ˆ ์— ๋Œ€ํ•œ ์งง์€ ์„ค๋ช…์€ ์ƒ์œ„ ํŽ˜์ด์ง€์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋˜๋Š” ์›๋ณธ ์—ฐ๊ตฌ๋ฅผ ์ฝ์–ด๋ณด์„ธ์š”: https://www.bleepingcomputer.com/news/security/hijacking-traffic-to-microsoft-s-windowscom-with-bitflipping/

์˜ˆ๋ฅผ ๋“ค์–ด, ๋„๋ฉ”์ธ microsoft.com์—์„œ 1๋น„ํŠธ๋งŒ ๋ณ€๊ฒฝํ•˜๋ฉด _windnws.com._์œผ๋กœ ๋ณ€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
๊ณต๊ฒฉ์ž๋“ค์€ ํ”ผํ•ด์ž์™€ ๊ด€๋ จ๋œ ๊ฐ€๋Šฅํ•œ ํ•œ ๋งŽ์€ bit-flipping ๋„๋ฉ”์ธ์„ ๋“ฑ๋กํ•˜์—ฌ ์ •๋‹นํ•œ ์‚ฌ์šฉ์ž๋ฅผ ์ž์‹ ์˜ ์ธํ”„๋ผ๋กœ ๋ฆฌ๋””๋ ‰์…˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋ชจ๋“  ๊ฐ€๋Šฅํ•œ bit-flipping ๋„๋ฉ”์ธ ์ด๋ฆ„๋„ ๋ชจ๋‹ˆํ„ฐ๋งํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

๋™์ผ๋ฌธ์ž(์˜ˆ: Latin/Cyrillic ํ˜ผํ•ฉ) ๊ธฐ๋ฐ˜์˜ homoglyph/IDN lookalikes๋„ ๊ณ ๋ คํ•ด์•ผ ํ•œ๋‹ค๋ฉด, ๋‹ค์Œ์„ ํ™•์ธํ•˜์„ธ์š”:

Homograph Attacks

๊ธฐ๋ณธ ๊ฒ€์‚ฌ

์ž ์žฌ์ ์œผ๋กœ ์˜์‹ฌ์Šค๋Ÿฌ์šด ๋„๋ฉ”์ธ ๋ชฉ๋ก์„ ํ™•๋ณดํ–ˆ๋‹ค๋ฉด ํ•ด๋‹น ๋„๋ฉ”์ธ๋“ค์„ ํ™•์ธํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค(์ฃผ๋กœ HTTP ๋ฐ HTTPS ํฌํŠธ). ์ด๋Š” ํ•ด๋‹น ๋„๋ฉ”์ธ๋“ค์ด ํ”ผํ•ด์ž ๋„๋ฉ”์ธ์˜ ๋กœ๊ทธ์ธ ํผ๊ณผ ์œ ์‚ฌํ•œ ๋กœ๊ทธ์ธ ํผ์„ ์‚ฌ์šฉํ•˜๊ณ  ์žˆ๋Š”์ง€ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•จ์ž…๋‹ˆ๋‹ค.
ํฌํŠธ 3333์ด ์—ด๋ ค ์žˆ๊ณ  gophish ์ธ์Šคํ„ด์Šค๊ฐ€ ์‹คํ–‰ ์ค‘์ธ์ง€๋„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
๋ฐœ๊ฒฌ๋œ ์˜์‹ฌ ๋„๋ฉ”์ธ๋“ค์ด ์–ธ์ œ ์ƒ์„ฑ๋˜์—ˆ๋Š”์ง€(๋“ฑ๋ก ์—ฐ์›”) ์•„๋Š” ๊ฒƒ๋„ ํฅ๋ฏธ๋กœ์šด๋ฐ, ์ƒ์„ฑ์ผ์ด ์ตœ์‹ ์ผ์ˆ˜๋ก ์œ„ํ—˜์ด ํฝ๋‹ˆ๋‹ค.
์˜์‹ฌ์Šค๋Ÿฌ์šด HTTP ๋ฐ/๋˜๋Š” HTTPS ์›นํŽ˜์ด์ง€์˜ ์Šคํฌ๋ฆฐ์ƒท์„ ๋ฐ›์•„ ๋ณด๊ณ  ์˜์‹ฌ์Šค๋Ÿฌ์šฐ๋ฉด ์ ‘์†ํ•˜์—ฌ ๋” ์ž์„ธํžˆ ์กฐ์‚ฌํ•˜์„ธ์š”.

๊ณ ๊ธ‰ ๊ฒ€์‚ฌ

ํ•œ ๋‹จ๊ณ„ ๋” ๋‚˜์•„๊ฐ€๋ ค๋ฉด ์˜์‹ฌ์Šค๋Ÿฌ์šด ๋„๋ฉ”์ธ๋“ค์„ ์ฃผ๊ธฐ์ ์œผ๋กœ(๋งค์ผ?) ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๊ณ  ์ถ”๊ฐ€๋กœ ๊ฒ€์ƒ‰ํ•  ๊ฒƒ์„ ๊ถŒํ•ฉ๋‹ˆ๋‹ค(์†Œ์š” ์‹œ๊ฐ„์€ ๋ช‡ ์ดˆ/๋ถ„์— ๋ถˆ๊ณผํ•ฉ๋‹ˆ๋‹ค). ๊ด€๋ จ IP์˜ ์—ด๋ฆฐ ํฌํŠธ๋ฅผ ํ™•์ธํ•˜๊ณ  gophish ๋˜๋Š” ์œ ์‚ฌ ๋„๊ตฌ์˜ ์ธ์Šคํ„ด์Šค ์กด์žฌ ์—ฌ๋ถ€๋ฅผ ๊ฒ€์ƒ‰ํ•˜์„ธ์š”(๋„ค, ๊ณต๊ฒฉ์ž๋“ค๋„ ์‹ค์ˆ˜๋ฅผ ํ•ฉ๋‹ˆ๋‹ค). ๋˜ํ•œ ์˜์‹ฌ ๋„๋ฉ”์ธ ๋ฐ ์„œ๋ธŒ๋„๋ฉ”์ธ์˜ HTTP ๋ฐ HTTPS ์›นํŽ˜์ด์ง€๋ฅผ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜์—ฌ ํ”ผํ•ด์ž์˜ ์›นํŽ˜์ด์ง€์—์„œ ๋ณต์ œํ•œ ๋กœ๊ทธ์ธ ํผ์ด ์žˆ๋Š”์ง€ ํ™•์ธํ•˜์„ธ์š”.
์ด๋ฅผ ์ž๋™ํ™”ํ•˜๋ ค๋ฉด ํ”ผํ•ด์ž ๋„๋ฉ”์ธ์˜ ๋กœ๊ทธ์ธ ํผ ๋ชฉ๋ก์„ ๋ณด์œ ํ•˜๊ณ , ์˜์‹ฌ์Šค๋Ÿฌ์šด ์›นํŽ˜์ด์ง€๋ฅผ ํฌ๋กค๋งํ•˜์—ฌ ๋ฐœ๊ฒฌ๋œ ๊ฐ ๋กœ๊ทธ์ธ ํผ์„ ssdeep ๊ฐ™์€ ๋„๊ตฌ๋กœ ํ”ผํ•ด์ž ๋„๋ฉ”์ธ์˜ ๊ฐ ๋กœ๊ทธ์ธ ํผ๊ณผ ๋น„๊ตํ•˜๋Š” ๋ฐฉ์‹์„ ๊ถŒ์žฅํ•ฉ๋‹ˆ๋‹ค.
์˜์‹ฌ ๋„๋ฉ”์ธ์˜ ๋กœ๊ทธ์ธ ํผ์„ ์ฐพ์•˜๋‹ค๋ฉด, ์ž„์˜์˜(์“ธ๋ฐ์—†๋Š”) ์ž๊ฒฉ์ฆ๋ช…(junk credentials)์„ ์ „์†กํ•ด ๋ณด๊ณ  ํ”ผํ•ด์ž ๋„๋ฉ”์ธ์œผ๋กœ ๋ฆฌ๋””๋ ‰์…˜๋˜๋Š”์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.


favicon ๋ฐ ์›น ์ง€๋ฌธ์œผ๋กœ ํ—ŒํŒ…ํ•˜๊ธฐ (Shodan/ZoomEye/Censys)

๋งŽ์€ ํ”ผ์‹ฑ ํ‚คํŠธ๋Š” ์‚ฌ์นญํ•˜๋Š” ๋ธŒ๋žœ๋“œ์˜ favicon์„ ์žฌ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ์ธํ„ฐ๋„ท ์ „์ฒด ์Šค์บ๋„ˆ๋Š” base64๋กœ ์ธ์ฝ”๋”ฉ๋œ favicon์˜ MurmurHash3๋ฅผ ๊ณ„์‚ฐํ•ฉ๋‹ˆ๋‹ค. ํ•ด์‹œ๋ฅผ ์ƒ์„ฑํ•˜๊ณ  ์ด๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ”ผ๋ฒ—ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

Python ์˜ˆ์ œ (mmh3):

import base64, requests, mmh3
url = "https://www.paypal.com/favicon.ico"  # change to your brand icon
b64 = base64.encodebytes(requests.get(url, timeout=10).content)
print(mmh3.hash(b64))  # e.g., 309020573
  • Shodan ์ฟผ๋ฆฌ: http.favicon.hash:309020573
  • ๋„๊ตฌ ์‚ฌ์šฉ: favfreak ๊ฐ™์€ ์ปค๋ฎค๋‹ˆํ‹ฐ ๋„๊ตฌ๋ฅผ ํ™•์ธํ•˜์—ฌ Shodan/ZoomEye/Censys์šฉ hashes ๋ฐ dorks๋ฅผ ์ƒ์„ฑํ•˜์„ธ์š”.

Notes

  • Favicons์€ ์žฌ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค; ์ผ์น˜ ํ•ญ๋ชฉ์„ ๋‹จ์„œ๋กœ ์ทจ๊ธ‰ํ•˜๊ณ  ์กฐ์น˜ํ•˜๊ธฐ ์ „์— ์ฝ˜ํ…์ธ ์™€ certs๋ฅผ ๊ฒ€์ฆํ•˜์„ธ์š”.
  • ๋” ๋†’์€ ์ •ํ™•๋„๋ฅผ ์œ„ํ•ด domain-age ๋ฐ keyword heuristics์™€ ๊ฒฐํ•ฉํ•˜์„ธ์š”.

URL ํ…”๋ ˆ๋ฉ”ํŠธ๋ฆฌ ํ—ŒํŒ… (urlscan.io)

urlscan.io๋Š” ์ œ์ถœ๋œ URL์˜ ๊ณผ๊ฑฐ ์Šคํฌ๋ฆฐ์ƒท, DOM, ์š”์ฒญ ๋ฐ TLS ๋ฉ”ํƒ€๋ฐ์ดํ„ฐ๋ฅผ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค. ๋ธŒ๋žœ๋“œ ๋‚จ์šฉ ๋ฐ ํด๋ก ์„ ์ฐพ์•„๋‚ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

Example queries (UI or API):

  • ์ •์‹ ๋„๋ฉ”์ธ์„ ์ œ์™ธํ•œ ์œ ์‚ฌ ์‚ฌ์ดํŠธ ์ฐพ๊ธฐ: page.domain:(/.*yourbrand.*/ AND NOT yourbrand.com AND NOT www.yourbrand.com)
  • ์ž์‚ฐ์„ hotlinkingํ•˜๋Š” ์‚ฌ์ดํŠธ ์ฐพ๊ธฐ: domain:yourbrand.com AND NOT page.domain:yourbrand.com
  • ์ตœ๊ทผ ๊ฒฐ๊ณผ๋กœ ์ œํ•œ: AND date:>now-7d๋ฅผ ๋ง๋ถ™์ด์„ธ์š”

API ์˜ˆ์‹œ:

# Search recent scans mentioning your brand
curl -s 'https://urlscan.io/api/v1/search/?q=page.domain:(/.*yourbrand.*/%20AND%20NOT%20yourbrand.com)%20AND%20date:>now-7d' \
-H 'API-Key: <YOUR_URLSCAN_KEY>' | jq '.results[].page.url'

JSON์—์„œ pivotํ•  ํ•ญ๋ชฉ:

  • page.tlsIssuer, page.tlsValidFrom, page.tlsAgeDays โ€” ์œ ์‚ฌ ๋„๋ฉ”์ธ ํƒ์ง€๋ฅผ ์œ„ํ•ด ๋งค์šฐ ์ƒˆ๋กœ ๋ฐœ๊ธ‰๋œ ์ธ์ฆ์„œ๋ฅผ ์ฐพ์•„๋ณด์„ธ์š”
  • task.source ๊ฐ’(์˜ˆ: certstream-suspicious) โ€” ๋ฐœ๊ฒฌ์„ CT ๋ชจ๋‹ˆํ„ฐ๋ง๊ณผ ์—ฐ๊ณ„ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ

RDAP๋กœ ๋„๋ฉ”์ธ ์—ฐ๋ น ํ™•์ธ (์Šคํฌ๋ฆฝํŠธ ๊ฐ€๋Šฅ)

RDAP๋Š” ๊ธฐ๊ณ„ ํŒ๋… ๊ฐ€๋Šฅํ•œ ์ƒ์„ฑ ์ด๋ฒคํŠธ๋ฅผ ๋ฐ˜ํ™˜ํ•ฉ๋‹ˆ๋‹ค. ์ƒˆ๋กœ ๋“ฑ๋ก๋œ ๋„๋ฉ”์ธ (NRDs) ๋ฅผ ํ‘œ์‹œํ•˜๋Š” ๋ฐ ์œ ์šฉํ•ฉ๋‹ˆ๋‹ค.

# .com/.net RDAP (Verisign)
curl -s https://rdap.verisign.com/com/v1/domain/suspicious-example.com | \
jq -r '.events[] | select(.eventAction=="registration") | .eventDate'

# Generic helper using rdap.net redirector
curl -s https://www.rdap.net/domain/suspicious-example.com | jq

ํŒŒ์ดํ”„๋ผ์ธ์„ ๋ณด๊ฐ•ํ•˜๋ ค๋ฉด ๋„๋ฉ”์ธ์„ ๋“ฑ๋ก ์—ฐ๋ น ๊ตฌ๊ฐ„(์˜ˆ: <7 days, <30 days)์œผ๋กœ ํƒœ๊ทธํ•˜๊ณ  ํŠธ๋ฆฌ์•„์ง€ ์šฐ์„ ์ˆœ์œ„๋ฅผ ์กฐ์ •ํ•˜์„ธ์š”.

TLS/JAx fingerprints๋กœ AiTM ์ธํ”„๋ผ ํƒ์ง€

Modern credential-phishing์€ ์„ธ์…˜ ํ† ํฐ ํƒˆ์ทจ๋ฅผ ์œ„ํ•ด Adversary-in-the-Middle (AiTM) ๋ฆฌ๋ฒ„์Šค ํ”„๋ก์‹œ(์˜ˆ: Evilginx)๋ฅผ ์ ์  ๋” ๋งŽ์ด ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค. ๋„คํŠธ์›Œํฌ ์ธก ํƒ์ง€๋ฅผ ์ถ”๊ฐ€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

  • Egress์—์„œ TLS/HTTP ์ง€๋ฌธ(JA3/JA4/JA4S/JA4H)์„ ๋กœ๊ทธํ•˜์„ธ์š”. ์ผ๋ถ€ Evilginx ๋นŒ๋“œ์—์„œ๋Š” ์•ˆ์ •์ ์ธ JA4 ํด๋ผ์ด์–ธํŠธ/์„œ๋ฒ„ ๊ฐ’์ด ๊ด€์ฐฐ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์•Œ๋ ค์ง„ ์•…์„ฑ ์ง€๋ฌธ์— ๋Œ€ํ•ด์„œ๋งŒ ์•ฝํ•œ ์‹ ํ˜ธ๋กœ ๊ฒฝ๋ณด๋ฅผ ์„ค์ •ํ•˜๊ณ  ํ•ญ์ƒ ์ฝ˜ํ…์ธ  ๋ฐ domain intel๋กœ ํ™•์ธํ•˜์„ธ์š”.
  • CT ๋˜๋Š” urlscan์„ ํ†ตํ•ด ๋ฐœ๊ฒฌ๋œ ์œ ์‚ฌ ํ˜ธ์ŠคํŠธ์— ๋Œ€ํ•ด TLS certificate metadata(issuer, SAN count, wildcard ์‚ฌ์šฉ ์—ฌ๋ถ€, validity)๋ฅผ ์„ ์ œ์ ์œผ๋กœ ๊ธฐ๋กํ•˜๊ณ  DNS age ๋ฐ ์ง€๋ฆฌ์  ์œ„์น˜์™€ ์ƒ๊ด€๊ด€๊ณ„๋ฅผ ๋ถ„์„ํ•˜์„ธ์š”.

Note: ์ง€๋ฌธ์„ enrichment๋กœ ์ทจ๊ธ‰ํ•˜๊ณ  ๋‹จ๋… ์ฐจ๋‹จ ๊ทผ๊ฑฐ๋กœ ๋ณด์ง€ ๋งˆ์„ธ์š”; ํ”„๋ ˆ์ž„์›Œํฌ๋Š” ์ง„ํ™”ํ•˜๋ฉฐ ๋ฌด์ž‘์œ„ํ™”ํ•˜๊ฑฐ๋‚˜ ๋‚œ๋…ํ™”ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Domain names using keywords

์ƒ์œ„ ํŽ˜์ด์ง€๋Š” ๋˜ํ•œ victimโ€™s domain name inside a bigger domain ๊ธฐ๋ฒ•์„ ์–ธ๊ธ‰ํ•ฉ๋‹ˆ๋‹ค(์˜ˆ: paypal-financial.com์€ paypal.com์„ ๊ฒจ๋ƒฅ).

Certificate Transparency

์ด์ „์˜ โ€œBrute-Forceโ€ ์ ‘๊ทผ๋ฒ•์€ ๋ถˆ๊ฐ€๋Šฅํ•  ์ˆ˜ ์žˆ์ง€๋งŒ, Certificate Transparency ๋•๋ถ„์— ์ด๋Ÿฌํ•œ ํ”ผ์‹ฑ ์‹œ๋„๋ฅผ ์ฐพ์•„๋‚ด๋Š” ๊ฒƒ์ด ์‹ค์ œ๋กœ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. CA๊ฐ€ ์ธ์ฆ์„œ๋ฅผ ๋ฐœํ–‰ํ•  ๋•Œ๋งˆ๋‹ค ์„ธ๋ถ€ ์ •๋ณด๊ฐ€ ๊ณต๊ฐœ๋ฉ๋‹ˆ๋‹ค. ์ฆ‰, certificate transparency๋ฅผ ์ฝ๊ฑฐ๋‚˜ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๋ฉด ์ด๋ฆ„ ์•ˆ์— ํ‚ค์›Œ๋“œ๋ฅผ ํฌํ•จํ•œ ๋„๋ฉ”์ธ์„ ์ฐพ์•„๋‚ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด ๊ณต๊ฒฉ์ž๊ฐ€ https://paypal-financial.com์˜ ์ธ์ฆ์„œ๋ฅผ ์ƒ์„ฑํ•˜๋ฉด, ์ธ์ฆ์„œ๋ฅผ ํ†ตํ•ด โ€œpaypalโ€œ์ด๋ผ๋Š” ํ‚ค์›Œ๋“œ๋ฅผ ์ฐพ์•„ ์˜์‹ฌ์Šค๋Ÿฌ์šด ์‚ฌ์šฉ์„ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ฒŒ์‹œ๋ฌผ https://0xpatrik.com/phishing-domains/์€ Censys๋ฅผ ์‚ฌ์šฉํ•ด ํŠน์ • ํ‚ค์›Œ๋“œ๊ฐ€ ํฌํ•จ๋œ ์ธ์ฆ์„œ๋ฅผ ๊ฒ€์ƒ‰ํ•˜๊ณ  ๋‚ ์งœ(์‹ ๊ทœ ์ธ์ฆ์„œ๋งŒ)์™€ CA ๋ฐœ๊ธ‰์ž(โ€œLetโ€™s Encryptโ€)๋กœ ํ•„ํ„ฐ๋งํ•  ์ˆ˜ ์žˆ๋‹ค๊ณ  ์ œ์•ˆํ•ฉ๋‹ˆ๋‹ค:

https://0xpatrik.com/content/images/2018/07/cert_listing.png

๊ทธ๋Ÿฌ๋‚˜ ๋ฌด๋ฃŒ ์›น crt.sh๋ฅผ ์‚ฌ์šฉํ•ด๋„ โ€œ๋™์ผํ•œโ€ ์ž‘์—…์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ํ‚ค์›Œ๋“œ๋ฅผ ๊ฒ€์ƒ‰ํ•˜๊ณ  ์›ํ•˜๋ฉด ๊ฒฐ๊ณผ๋ฅผ ๋‚ ์งœ์™€ CA๋กœ ํ•„ํ„ฐ๋งํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ๋งˆ์ง€๋ง‰ ์˜ต์…˜์„ ์‚ฌ์šฉํ•˜๋ฉด Matching Identities ํ•„๋“œ๋ฅผ ์ด์šฉํ•ด ์‹ค์ œ ๋„๋ฉ”์ธ์˜ ์–ด๋–ค identity๊ฐ€ ์˜์‹ฌ ๋„๋ฉ”์ธ๊ณผ ์ผ์น˜ํ•˜๋Š”์ง€ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค(์˜์‹ฌ ๋„๋ฉ”์ธ์€ false positive์ผ ์ˆ˜ ์žˆ์Œ์— ์œ ์˜).

Another alternative๋Š” CertStream์ด๋ผ๋Š” ํ›Œ๋ฅญํ•œ ํ”„๋กœ์ ํŠธ์ž…๋‹ˆ๋‹ค. CertStream์€ ์ƒˆ๋กœ ์ƒ์„ฑ๋œ ์ธ์ฆ์„œ์˜ ์‹ค์‹œ๊ฐ„ ์ŠคํŠธ๋ฆผ์„ ์ œ๊ณตํ•˜๋ฉฐ, ์ด๋ฅผ ์ด์šฉํ•ด ์ง€์ •ํ•œ ํ‚ค์›Œ๋“œ๋ฅผ (๊ฑฐ์˜) ์‹ค์‹œ๊ฐ„์œผ๋กœ ํƒ์ง€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์‹ค์ œ๋กœ phishing_catcher๋ผ๋Š” ํ”„๋กœ์ ํŠธ๊ฐ€ ๋ฐ”๋กœ ์ด๋ฅผ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.

์‹ค์šฉ ํŒ: CT ํžˆํŠธ๋ฅผ ํŠธ๋ฆฌ์•„์ง€ํ•  ๋•Œ๋Š” NRDs, ์‹ ๋ขฐ๋˜์ง€ ์•Š๊ฑฐ๋‚˜ ์•Œ ์ˆ˜ ์—†๋Š” ๋ ˆ์ง€์ŠคํŠธ๋ผ, privacy-proxy WHOIS, NotBefore ์‹œ๊ฐ„์ด ๋งค์šฐ ์ตœ๊ทผ์ธ ์ธ์ฆ์„œ๋ฅผ ์šฐ์„ ์ˆœ์œ„๋กœ ๋‘์„ธ์š”. ์†Œ์Œ์„ ์ค„์ด๋ ค๋ฉด ์†Œ์œ ํ•œ ๋„๋ฉ”์ธ/๋ธŒ๋žœ๋“œ์˜ allowlist๋ฅผ ์œ ์ง€ํ•˜์„ธ์š”.

New domains

One last alternative๋Š” ์ผ๋ถ€ TLD์— ๋Œ€ํ•ด newly registered domains ๋ชฉ๋ก์„ ์ˆ˜์ง‘ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค(Whoxy๊ฐ€ ์ด๋Ÿฐ ์„œ๋น„์Šค๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค) ๊ทธ๋ฆฌ๊ณ  ์ด๋Ÿฌํ•œ ๋„๋ฉ”์ธ์—์„œ ํ‚ค์›Œ๋“œ๋ฅผ ํ™•์ธํ•˜์„ธ์š”. ๋‹ค๋งŒ, ๊ธด ๋„๋ฉ”์ธ์€ ๋ณดํ†ต ํ•˜๋‚˜ ์ด์ƒ์˜ ์„œ๋ธŒ๋„๋ฉ”์ธ์„ ์‚ฌ์šฉํ•˜๋ฏ€๋กœ ํ‚ค์›Œ๋“œ๊ฐ€ FLD ์•ˆ์— ๋‚˜ํƒ€๋‚˜์ง€ ์•Š์•„ ํ”ผ์‹ฑ ์„œ๋ธŒ๋„๋ฉ”์ธ์„ ์ฐพ์ง€ ๋ชปํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ถ”๊ฐ€ ํœด๋ฆฌ์Šคํ‹ฑ: ํŠน์ • file-extension TLDs(์˜ˆ: .zip, .mov)๋Š” ๊ฒฝ๋ณด ์‹œ ์ถ”๊ฐ€ ์˜์‹ฌ ๋Œ€์ƒ์œผ๋กœ ์ฒ˜๋ฆฌํ•˜์„ธ์š”. ์ด๋Š” ๋ฏธ๋ผ์—์„œ ํŒŒ์ผ๋ช…์œผ๋กœ ํ˜ผ๋™๋˜๋Š” ๊ฒฝ์šฐ๊ฐ€ ๋งŽ์œผ๋ฏ€๋กœ TLD ์‹ ํ˜ธ๋ฅผ ๋ธŒ๋žœ๋“œ ํ‚ค์›Œ๋“œ ๋ฐ NRD age์™€ ๊ฒฐํ•ฉํ•˜๋ฉด ์ •ํ™•๋„๋ฅผ ๋†’์ผ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

References

  • urlscan.io โ€“ Search API reference: https://urlscan.io/docs/search/
  • APNIC Blog โ€“ JA4+ network fingerprinting (includes Evilginx example): https://blog.apnic.net/2023/11/22/ja4-network-fingerprinting/

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ