macOS μ¬μ©μ λ° μΈλΆ κ³μ
Tip
AWS ν΄νΉ λ°°μ°κΈ° λ° μ°μ΅νκΈ°:
HackTricks Training AWS Red Team Expert (ARTE)
GCP ν΄νΉ λ°°μ°κΈ° λ° μ°μ΅νκΈ°:HackTricks Training GCP Red Team Expert (GRTE)
Azure ν΄νΉ λ°°μ°κΈ° λ° μ°μ΅νκΈ°:
HackTricks Training Azure Red Team Expert (AzRTE)
HackTricks μ§μνκΈ°
- ꡬλ κ³ν νμΈνκΈ°!
- **π¬ λμ€μ½λ κ·Έλ£Ή λλ ν λ κ·Έλ¨ κ·Έλ£Ήμ μ°Έμ¬νκ±°λ νΈμν° π¦ @hacktricks_liveλ₯Ό νλ‘μ°νμΈμ.
- HackTricks λ° HackTricks Cloud κΉνλΈ λ¦¬ν¬μ§ν 리μ PRμ μ μΆνμ¬ ν΄νΉ νΈλ¦μ 곡μ νμΈμ.
μΌλ° μ¬μ©μ
- Daemon: μμ€ν λ°λͺ¬μ μν μ¬μ©μ. κΈ°λ³Έ λ°λͺ¬ κ³μ μ΄λ¦μ λ³΄ν΅ β_βλ‘ μμν©λλ€:
_amavisd, _analyticsd, _appinstalld, _appleevents, _applepay, _appowner, _appserver, _appstore, _ard, _assetcache, _astris, _atsserver, _avbdeviced, _calendar, _captiveagent, _ces, _clamav, _cmiodalassistants, _coreaudiod, _coremediaiod, _coreml, _ctkd, _cvmsroot, _cvs, _cyrus, _datadetectors, _demod, _devdocs, _devicemgr, _diskimagesiod, _displaypolicyd, _distnote, _dovecot, _dovenull, _dpaudio, _driverkit, _eppc, _findmydevice, _fpsd, _ftp, _fud, _gamecontrollerd, _geod, _hidd, _iconservices, _installassistant, _installcoordinationd, _installer, _jabber, _kadmin_admin, _kadmin_changepw, _knowledgegraphd, _krb_anonymous, _krb_changepw, _krb_kadmin, _krb_kerberos, _krb_krbtgt, _krbfast, _krbtgt, _launchservicesd, _lda, _locationd, _logd, _lp, _mailman, _mbsetupuser, _mcxalr, _mdnsresponder, _mobileasset, _mysql, _nearbyd, _netbios, _netstatistics, _networkd, _nsurlsessiond, _nsurlstoraged, _oahd, _ondemand, _postfix, _postgres, _qtss, _reportmemoryexception, _rmd, _sandbox, _screensaver, _scsd, _securityagent, _softwareupdate, _spotlight, _sshd, _svn, _taskgated, _teamsserver, _timed, _timezone, _tokend, _trustd, _trustevaluationagent, _unknown, _update_sharing, _usbmuxd, _uucp, _warmd, _webauthserver, _windowserver, _www, _wwwproxy, _xserverdocs
- Guest: λ§€μ° μ νλ κΆνμ κ°μ§ κ²μ€νΈ κ³μ
state=("automaticTime" "afpGuestAccess" "filesystem" "guestAccount" "smbGuestAccess")
for i in "${state[@]}"; do sysadminctl -"${i}" status; done;
- Nobody: μ΅μ κΆνμ΄ νμν λ μ΄ μ¬μ©μλ‘ νλ‘μΈμ€κ° μ€νλ©λλ€.
- Root
μ¬μ©μ κΆν
- νμ€ μ¬μ©μ: κ°μ₯ κΈ°λ³Έμ μΈ μ¬μ©μμ λλ€. μ΄ μ¬μ©μλ μννΈμ¨μ΄λ₯Ό μ€μΉνκ±°λ λ€λ₯Έ κ³ κΈ μμ μ μνν λ κ΄λ¦¬μ μ¬μ©μλ‘λΆν° κΆνμ λΆμ¬λ°μμΌ ν©λλ€. μ€μ€λ‘λ μ΄λ₯Ό μνν μ μμ΅λλ€.
- κ΄λ¦¬μ μ¬μ©μ: λλΆλΆμ κ²½μ° νμ€ μ¬μ©μλ‘ μλνμ§λ§ μννΈμ¨μ΄ μ€μΉ λ° κΈ°ν κ΄λ¦¬ μμ κ³Ό κ°μ λ£¨νΈ μμ μ μνν μ μλ κΆνμ΄ λΆμ¬λ μ¬μ©μμ λλ€. κ΄λ¦¬μ κ·Έλ£Ήμ μν λͺ¨λ μ¬μ©μλ sudoers νμΌμ ν΅ν΄ 루νΈμ μ κ·Όν μ μμ΅λλ€.
- Root: Rootλ κ±°μ λͺ¨λ μμ μ μνν μ μλ μ¬μ©μμ λλ€(μμ€ν λ¬΄κ²°μ± λ³΄νΈμ κ°μ 보νΈμ μν΄ μ νμ΄ μμ΅λλ€).
- μλ₯Ό λ€μ΄, rootλ
/Systemλ΄λΆμ νμΌμ λ°°μΉν μ μμ΅λλ€.
μΈλΆ κ³μ
MacOSλ FaceBook, Google λ±κ³Ό κ°μ μΈλΆ μ μ μ 곡μλ₯Ό ν΅ν΄ λ‘κ·ΈμΈνλ κ²λ μ§μν©λλ€. μ΄ μμ
μ μννλ μ£Όμ λ°λͺ¬μ accountsd (/System/Library/Frameworks/Accounts.framework//Versions/A/Support/accountsd)μ΄λ©°, μΈλΆ μΈμ¦μ μ¬μ©λλ νλ¬κ·ΈμΈμ /System/Library/Accounts/Authentication/ ν΄λ λ΄μμ μ°Ύμ μ μμ΅λλ€.
λν, accountsdλ /Library/Preferences/SystemConfiguration/com.apple.accounts.exists.plistμμ κ³μ μ ν λͺ©λ‘μ κ°μ Έμ΅λλ€.
Tip
AWS ν΄νΉ λ°°μ°κΈ° λ° μ°μ΅νκΈ°:
HackTricks Training AWS Red Team Expert (ARTE)
GCP ν΄νΉ λ°°μ°κΈ° λ° μ°μ΅νκΈ°:HackTricks Training GCP Red Team Expert (GRTE)
Azure ν΄νΉ λ°°μ°κΈ° λ° μ°μ΅νκΈ°:
HackTricks Training Azure Red Team Expert (AzRTE)
HackTricks μ§μνκΈ°
- ꡬλ κ³ν νμΈνκΈ°!
- **π¬ λμ€μ½λ κ·Έλ£Ή λλ ν λ κ·Έλ¨ κ·Έλ£Ήμ μ°Έμ¬νκ±°λ νΈμν° π¦ @hacktricks_liveλ₯Ό νλ‘μ°νμΈμ.
- HackTricks λ° HackTricks Cloud κΉνλΈ λ¦¬ν¬μ§ν 리μ PRμ μ μΆνμ¬ ν΄νΉ νΈλ¦μ 곡μ νμΈμ.


