macOS μ‚¬μš©μž 및 μ™ΈλΆ€ 계정

Tip

AWS ν•΄ν‚Ή 배우기 및 μ—°μŠ΅ν•˜κΈ°:HackTricks Training AWS Red Team Expert (ARTE)
GCP ν•΄ν‚Ή 배우기 및 μ—°μŠ΅ν•˜κΈ°: HackTricks Training GCP Red Team Expert (GRTE) Azure ν•΄ν‚Ή 배우기 및 μ—°μŠ΅ν•˜κΈ°: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks μ§€μ›ν•˜κΈ°

일반 μ‚¬μš©μž

  • Daemon: μ‹œμŠ€ν…œ 데λͺ¬μ„ μœ„ν•œ μ‚¬μš©μž. κΈ°λ³Έ 데λͺ¬ 계정 이름은 보톡 β€œ_β€œλ‘œ μ‹œμž‘ν•©λ‹ˆλ‹€:
_amavisd, _analyticsd, _appinstalld, _appleevents, _applepay, _appowner, _appserver, _appstore, _ard, _assetcache, _astris, _atsserver, _avbdeviced, _calendar, _captiveagent, _ces, _clamav, _cmiodalassistants, _coreaudiod, _coremediaiod, _coreml, _ctkd, _cvmsroot, _cvs, _cyrus, _datadetectors, _demod, _devdocs, _devicemgr, _diskimagesiod, _displaypolicyd, _distnote, _dovecot, _dovenull, _dpaudio, _driverkit, _eppc, _findmydevice, _fpsd, _ftp, _fud, _gamecontrollerd, _geod, _hidd, _iconservices, _installassistant, _installcoordinationd, _installer, _jabber, _kadmin_admin, _kadmin_changepw, _knowledgegraphd, _krb_anonymous, _krb_changepw, _krb_kadmin, _krb_kerberos, _krb_krbtgt, _krbfast, _krbtgt, _launchservicesd, _lda, _locationd, _logd, _lp, _mailman, _mbsetupuser, _mcxalr, _mdnsresponder, _mobileasset, _mysql, _nearbyd, _netbios, _netstatistics, _networkd, _nsurlsessiond, _nsurlstoraged, _oahd, _ondemand, _postfix, _postgres, _qtss, _reportmemoryexception, _rmd, _sandbox, _screensaver, _scsd, _securityagent, _softwareupdate, _spotlight, _sshd, _svn, _taskgated, _teamsserver, _timed, _timezone, _tokend, _trustd, _trustevaluationagent, _unknown, _update_sharing, _usbmuxd, _uucp, _warmd, _webauthserver, _windowserver, _www, _wwwproxy, _xserverdocs
  • Guest: 맀우 μ œν•œλœ κΆŒν•œμ„ κ°€μ§„ 게슀트 계정
state=("automaticTime" "afpGuestAccess" "filesystem" "guestAccount" "smbGuestAccess")
for i in "${state[@]}"; do sysadminctl -"${i}" status; done;
  • Nobody: μ΅œμ†Œ κΆŒν•œμ΄ ν•„μš”ν•  λ•Œ 이 μ‚¬μš©μžλ‘œ ν”„λ‘œμ„ΈμŠ€κ°€ μ‹€ν–‰λ©λ‹ˆλ‹€.
  • Root

μ‚¬μš©μž κΆŒν•œ

  • ν‘œμ€€ μ‚¬μš©μž: κ°€μž₯ 기본적인 μ‚¬μš©μžμž…λ‹ˆλ‹€. 이 μ‚¬μš©μžλŠ” μ†Œν”„νŠΈμ›¨μ–΄λ₯Ό μ„€μΉ˜ν•˜κ±°λ‚˜ λ‹€λ₯Έ κ³ κΈ‰ μž‘μ—…μ„ μˆ˜ν–‰ν•  λ•Œ κ΄€λ¦¬μž μ‚¬μš©μžλ‘œλΆ€ν„° κΆŒν•œμ„ λΆ€μ—¬λ°›μ•„μ•Ό ν•©λ‹ˆλ‹€. μŠ€μŠ€λ‘œλŠ” 이λ₯Ό μˆ˜ν–‰ν•  수 μ—†μŠ΅λ‹ˆλ‹€.
  • κ΄€λ¦¬μž μ‚¬μš©μž: λŒ€λΆ€λΆ„μ˜ 경우 ν‘œμ€€ μ‚¬μš©μžλ‘œ μž‘λ™ν•˜μ§€λ§Œ μ†Œν”„νŠΈμ›¨μ–΄ μ„€μΉ˜ 및 기타 관리 μž‘μ—…κ³Ό 같은 루트 μž‘μ—…μ„ μˆ˜ν–‰ν•  수 μžˆλŠ” κΆŒν•œμ΄ λΆ€μ—¬λœ μ‚¬μš©μžμž…λ‹ˆλ‹€. κ΄€λ¦¬μž 그룹에 μ†ν•œ λͺ¨λ“  μ‚¬μš©μžλŠ” sudoers νŒŒμΌμ„ 톡해 λ£¨νŠΈμ— μ ‘κ·Όν•  수 μžˆμŠ΅λ‹ˆλ‹€.
  • Root: RootλŠ” 거의 λͺ¨λ“  μž‘μ—…μ„ μˆ˜ν–‰ν•  수 μžˆλŠ” μ‚¬μš©μžμž…λ‹ˆλ‹€(μ‹œμŠ€ν…œ 무결성 λ³΄ν˜Έμ™€ 같은 λ³΄ν˜Έμ— μ˜ν•΄ μ œν•œμ΄ μžˆμŠ΅λ‹ˆλ‹€).
  • 예λ₯Ό λ“€μ–΄, rootλŠ” /System 내뢀에 νŒŒμΌμ„ λ°°μΉ˜ν•  수 μ—†μŠ΅λ‹ˆλ‹€.

μ™ΈλΆ€ 계정

MacOSλŠ” FaceBook, Google λ“±κ³Ό 같은 μ™ΈλΆ€ 신원 제곡자λ₯Ό 톡해 λ‘œκ·ΈμΈν•˜λŠ” 것도 μ§€μ›ν•©λ‹ˆλ‹€. 이 μž‘μ—…μ„ μˆ˜ν–‰ν•˜λŠ” μ£Όμš” 데λͺ¬μ€ accountsd (/System/Library/Frameworks/Accounts.framework//Versions/A/Support/accountsd)이며, μ™ΈλΆ€ 인증에 μ‚¬μš©λ˜λŠ” ν”ŒλŸ¬κ·ΈμΈμ€ /System/Library/Accounts/Authentication/ 폴더 λ‚΄μ—μ„œ 찾을 수 μžˆμŠ΅λ‹ˆλ‹€.
λ˜ν•œ, accountsdλŠ” /Library/Preferences/SystemConfiguration/com.apple.accounts.exists.plistμ—μ„œ 계정 μœ ν˜• λͺ©λ‘μ„ κ°€μ Έμ˜΅λ‹ˆλ‹€.

Tip

AWS ν•΄ν‚Ή 배우기 및 μ—°μŠ΅ν•˜κΈ°:HackTricks Training AWS Red Team Expert (ARTE)
GCP ν•΄ν‚Ή 배우기 및 μ—°μŠ΅ν•˜κΈ°: HackTricks Training GCP Red Team Expert (GRTE) Azure ν•΄ν‚Ή 배우기 및 μ—°μŠ΅ν•˜κΈ°: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks μ§€μ›ν•˜κΈ°