SMTP Smuggling

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๊ธฐ๋ณธ ์ •๋ณด

This type of vulnerability was originally discovered in this post were itโ€™s explained that Itโ€™s possible to exploit discrepancies in how the SMTP protocol is interpreted when finalising an email, allowing an attacker to smuggle more emails in the body of the legit one, allowing to impersonate other users of the affected domain (such as admin@outlook.com) bypassing defenses such as SPF.

์ด์œ 

์ด๊ฒƒ์€ SMTP ํ”„๋กœํ† ์ฝœ์—์„œ ์ด๋ฉ”์ผ๋กœ ์ „์†ก๋˜๋Š” ๋ฉ”์‹œ์ง€์˜ ๋ฐ์ดํ„ฐ๊ฐ€ ์‚ฌ์šฉ์ž(๊ณต๊ฒฉ์ž)์— ์˜ํ•ด ์ œ์–ด๋˜๋ฉฐ, ํŒŒ์„œ ๊ฐ„์˜ ์ฐจ์ด๋ฅผ ์•…์šฉํ•ด ์ˆ˜์‹ ์ž์— ์ถ”๊ฐ€ ์ด๋ฉ”์ผ์„ ์Šค๋จธ๊ธ€๋งํ•  ์ˆ˜ ์žˆ๋Š” ํŠน์ˆ˜ ์ œ์ž‘๋œ ๋ฐ์ดํ„ฐ๋ฅผ ๋ณด๋‚ผ ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ์ž…๋‹ˆ๋‹ค. ์›๋ฌธ ๊ฒŒ์‹œ๋ฌผ์˜ ๋‹ค์Œ ์˜ˆ์‹œ๋ฅผ ๋ณด์„ธ์š”:

https://sec-consult.com/fileadmin/user_upload/sec-consult/Dynamisch/Blogartikel/2023_12/SMTP_Smuggling-Overview__09_.png

๋ฐฉ๋ฒ•

์ด ์ทจ์•ฝ์ ์„ ์•…์šฉํ•˜๋ ค๋ฉด ๊ณต๊ฒฉ์ž๋Š” Outbound SMPT server๊ฐ€ ์ด๋ฅผ ๋‹จ์ผ ์ด๋ฉ”์ผ๋กœ ์ธ์‹ํ•˜๋Š” ๋ฐ˜๋ฉด Inbound SMTP server๋Š” ์—ฌ๋Ÿฌ ์ด๋ฉ”์ผ๋กœ ์ธ์‹ํ•˜๋Š” ์ผ๋ถ€ ๋ฐ์ดํ„ฐ๋ฅผ ์ „์†กํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

์—ฐ๊ตฌ์ž๋“ค์€ ์„œ๋กœ ๋‹ค๋ฅธ Inboud servers๊ฐ€ ์ด๋ฉ”์ผ ๋ฉ”์‹œ์ง€์˜ ๋ฐ์ดํ„ฐ ์ข…๋ฃŒ๋ฅผ ์„œ๋กœ ๋‹ค๋ฅธ ๋ฌธ์ž๋กœ ์ธ์‹ํ•œ๋‹ค๋Š” ์ ์„ ๋ฐœ๊ฒฌํ–ˆ์Šต๋‹ˆ๋‹ค(Outbound servers๋Š” ๊ทธ๋ ‡์ง€ ์•Š์Œ).
์˜ˆ๋ฅผ ๋“ค์–ด, ์ผ๋ฐ˜์ ์ธ ๋ฐ์ดํ„ฐ ์ข…๋ฃŒ๋Š” \r\n.\r์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ Inbound SMTP server๊ฐ€ \n.๋„ ํ—ˆ์šฉํ•œ๋‹ค๋ฉด, ๊ณต๊ฒฉ์ž๋Š” ๋‹จ์ˆœํžˆ ์ด๋ฉ”์ผ์— ํ•ด๋‹น ์‹œํ€€์Šค๋ฅผ ์ถ”๊ฐ€ํ•˜๊ณ  ๊ทธ ๋ฐ์ดํ„ฐ๋ฅผ ์ด๋ฉ”์ผ์— ๋„ฃ์€ ๋’ค ์ƒˆ๋กœ์šด SMTP ๋ช…๋ น๋“ค์„ ์‹œ์ž‘ํ•˜์—ฌ ์•ž์˜ ๊ทธ๋ฆผ์ฒ˜๋Ÿผ ์Šค๋จธ๊ธ€๋งํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋ฌผ๋ก , ์ด ๋ฐฉ๋ฒ•์€ Outbound SMTP server๊ฐ€ ์ด ๋ฐ์ดํ„ฐ๋„ ๋ฉ”์‹œ์ง€ ์ข…๋ฃŒ๋กœ ์ฒ˜๋ฆฌํ•˜์ง€ ์•Š์„ ๊ฒฝ์šฐ์—๋งŒ ์ž‘๋™ํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด Outbound๊ฐ€ 2๊ฐœ์˜ ์ด๋ฉ”์ผ๋กœ ์ธ์‹ํ•˜๊ฒŒ ๋˜์–ด ์ด ์ทจ์•ฝ์ ์ด ์•…์šฉ๋˜๋Š” ๋น„๋™๊ธฐํ™”๊ฐ€ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค.

์ž ์žฌ์  ๋™๊ธฐํ™” ๋ถˆ์ผ์น˜ ์‹œํ€€์Šค:

  • \n.
  • \n.\r

๋˜ํ•œ, SPF๋Š” ์šฐํšŒ๋ฉ๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด user@outlook.com์—์„œ admin@outlook.com์„ ์Šค๋จธ๊ธ€๋งํ•˜๋ฉด, **๋ฐœ์‹ ์ž๋Š” ์—ฌ์ „ํžˆ outlook.com**์ž…๋‹ˆ๋‹ค.


๊ณต๊ฒฉ์ž ์ฒดํฌ๋ฆฌ์ŠคํŠธ (์–ด๋–ค ์กฐ๊ฑด์ด ์ถฉ์กฑ๋˜์–ด์•ผ ํ•˜๋‚˜?)

์„ฑ๊ณต์ ์œผ๋กœ ๋‘ ๋ฒˆ์งธ ์ด๋ฉ”์ผ์„ ์Šค๋จธ๊ธ€ํ•˜๋ ค๋ฉด ์ผ๋ฐ˜์ ์œผ๋กœ ๋‹ค์Œ์ด ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค:

  • ์ „์†กํ•  ์ˆ˜ ์žˆ๋Š” outbound ์„œ๋ฒ„ A(์ข…์ข… ์œ ํšจํ•œ ์ธ์ฆ ์ •๋ณด๊ฐ€ ํ•„์š”)๋กœ, ๋น„ํ‘œ์ค€ endโ€‘ofโ€‘DATA ์‹œํ€€์Šค๋ฅผ ๋ณ€๊ฒฝ ์—†์ด ์ „๋‹ฌํ•˜๋Š” ์„œ๋ฒ„. ๋งŽ์€ ์„œ๋น„์Šค๊ฐ€ ์—ญ์‚ฌ์ ์œผ๋กœ \n.\r\n ๋˜๋Š” \n.\n ๊ฐ™์€ ๋ณ€ํ˜•์„ ์ „๋‹ฌํ–ˆ์Šต๋‹ˆ๋‹ค.
  • ํ•ด๋‹น ๋น„ํ‘œ์ค€ ์‹œํ€€์Šค๋ฅผ endโ€‘ofโ€‘DATA๋กœ ํ•ด์„ํ•˜๊ณ  ์ดํ›„ ๋‚ด์šฉ์„ ์ƒˆ๋กœ์šด SMTP ๋ช…๋ น(MAIL/RCPT/DATAโ€ฆ)์œผ๋กœ ํŒŒ์‹ฑํ•˜๋Š” ์ˆ˜์‹  ์„œ๋ฒ„ B.
  • Outbound๋Š” ์‹ค์ œ๋กœ DATA๋กœ ์ „์†กํ•ด์•ผ ํ•จ (BDAT์ด ์•„๋‹˜). A๊ฐ€ CHUNKING/BDAT๋ฅผ ์ง€์›ํ•˜๋ฉด, ์Šค๋จธ๊ธ€๋ง์€ A๊ฐ€ DATA๋กœ ํด๋ฐฑํ•  ๋•Œ๋งŒ ์ž‘๋™(์˜ˆ: B๊ฐ€ CHUNKING์„ ๊ด‘๊ณ ํ•˜์ง€ ์•Š๋Š” ๊ฒฝ์šฐ). ๊ทธ๋ ‡์ง€ ์•Š์œผ๋ฉด ๊ธธ์ด ๊ธฐ๋ฐ˜ BDAT๊ฐ€ ๋ชจํ˜ธ์„ฑ์„ ๋ฐฉ์ง€ํ•ฉ๋‹ˆ๋‹ค.
  • PIPELINING์€ ํ•„์ˆ˜๋Š” ์•„๋‹ˆ์ง€๋งŒ, ์ฃผ์ž…๋œ ๋ช…๋ น์„ ๋‹จ์ผ TCP write์— ์ˆจ๊ฒจ ์ค‘๊ฐ„ ์žฅ์น˜๋“ค์ด ๋‹ค์‹œ ๋™๊ธฐํ™”ํ•˜์ง€ ๋ชปํ•˜๊ฒŒ ํ•˜๋Š” ๋ฐ ๋„์›€์ด ๋ฉ๋‹ˆ๋‹ค.

์ˆ˜์‹ ์ž์— ๋”ฐ๋ผ ํ…Œ์ŠคํŠธํ•ด๋ณผ ๋งŒํ•œ ์ผ๋ฐ˜์ ์ธ endโ€‘ofโ€‘DATA ๋ณ€ํ˜•:

  • \n.\n
  • \n.\r\n
  • \r.\r\n
  • \r\n.\r (๋์— bare CR)

์ฐธ๊ณ : ์‹ค์ œ๋กœ ์ž‘๋™ํ•˜๋Š” ๊ฒƒ์€ โ€œA๊ฐ€ ์ „๋‹ฌํ•˜๋Š” ๊ฒƒโ€ โˆฉ โ€œB๊ฐ€ ์ˆ˜์šฉํ•˜๋Š” ๊ฒƒโ€์˜ ๊ต์ง‘ํ•ฉ์ž…๋‹ˆ๋‹ค.


์ˆ˜๋™ ์ต์Šคํ”Œ๋กœ์ž‡ ์˜ˆ์‹œ (๋‹จ์ผ ์„ธ์…˜)

๋‹ค์Œ์€ raw STARTTLS SMTP ์„ธ์…˜์„ ์‚ฌ์šฉํ•œ ์•„์ด๋””์–ด๋ฅผ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค. ์ฒซ ๋ฒˆ์งธ DATA ๋ธ”๋ก ๋’ค์— ๋น„ํ‘œ์ค€ ์ข…๋ฃŒ์ž๋ฅผ ์‚ฝ์ž…ํ•œ ํ›„, ์ˆ˜์‹  ์„œ๋ฒ„๊ฐ€ ์ƒˆ ๋ฉ”์‹œ์ง€๋กœ ์ฒ˜๋ฆฌํ•  ์ˆ˜ ์žˆ๋Š” ๋˜ ๋‹ค๋ฅธ SMTP ๋Œ€ํ™”๋ฅผ ๋„ฃ์Šต๋‹ˆ๋‹ค.

Manual smuggling session (STARTTLS) ``` $ openssl s_client -starttls smtp -crlf -connect smtp.example.com:587 EHLO a.example AUTH PLAIN MAIL FROM: RCPT TO: DATA From: User To: victim Subject: legit

hello A \n.\r\nMAIL FROM:admin@target.com RCPT TO:victim@target.com DATA From: Admin admin@target.com To: victim victim@target.com Subject: smuggled

hello B \r\n.\r\n

</details>

A๊ฐ€ `\n.\r\n`์„ ํฌ์›Œ๋“œํ•˜๊ณ  B๊ฐ€ ์ด๋ฅผ endโ€‘ofโ€‘DATA๋กœ ์ˆ˜์šฉํ•˜๋ฉด, ๋ฉ”์‹œ์ง€ โ€œhello Bโ€๊ฐ€ `admin@target.com`์œผ๋กœ๋ถ€ํ„ฐ ๋‘ ๋ฒˆ์งธ ์ด๋ฉ”์ผ๋กœ ์ˆ˜๋ฝ๋˜๋ฉด์„œ SPF( A์˜ IP์™€ ์ •๋ ฌ๋จ)๋ฅผ ํ†ต๊ณผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Tip: ๋Œ€ํ™”ํ˜•์œผ๋กœ ํ…Œ์ŠคํŠธํ•  ๋•Œ๋Š” OpenSSL์ด ์ž…๋ ฅํ•œ CRLF๋ฅผ ๋ณด์กดํ•˜๋„๋ก `-crlf`๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

---

## Automation and scanners

- hannob/smtpsmug: ์ˆ˜์‹ ์ž๊ฐ€ ์–ด๋–ค ๊ฒƒ์„ ์ˆ˜์šฉํ•˜๋Š”์ง€ ํ™•์ธํ•˜๊ธฐ ์œ„ํ•ด ์—ฌ๋Ÿฌ ๊ฐœ์˜ ์ž˜๋ชป๋œ endโ€‘ofโ€‘DATA ์‹œํ€€์Šค๋กœ ๋๋‚˜๋Š” ๋ฉ”์‹œ์ง€๋ฅผ ๋ณด๋ƒ…๋‹ˆ๋‹ค.
- Example: `./smtpsmug -s mail.target.com -p 25 -t victim@target.com`
- Theโ€‘Login/SMTPโ€‘Smugglingโ€‘Tools: inbound ๋ฐ outbound ์–‘์ชฝ์„ ์Šค์บ”ํ•˜๋Š” ์Šค์บ๋„ˆ์™€ ์†ก์‹ ์ž๊ฐ€ ์–ด๋–ค ์‹œํ€€์Šค๋ฅผ ํ†ต๊ณผ์‹œํ‚ค๋Š”์ง€ ์ •ํ™•ํžˆ ํ™•์ธํ•  ์ˆ˜ ์žˆ๋Š” ๋ถ„์„์šฉ SMTP ์„œ๋ฒ„๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.
- Inbound quick check: `python3 smtp_smuggling_scanner.py victim@target.com`
- Outbound via a relay: `python3 smtp_smuggling_scanner.py YOUR@ANALYSIS.DOMAIN --outbound-smtp-server smtp.relay.com --port 587 --starttls --sender-address you@relay.com --username you@relay.com --password '...'
`

์ด ๋„๊ตฌ๋“ค์€ smuggling์ด ์‹ค์ œ๋กœ ๋™์ž‘ํ•˜๋Š” Aโ†’B ์Œ์„ ๋งคํ•‘ํ•˜๋Š” ๋ฐ ๋„์›€์„ ์ค๋‹ˆ๋‹ค.

---

## CHUNKING/BDAT vs DATA

- DATA๋Š” ์ข…๊ฒฐ์ž `<CR><LF>.<CR><LF>`๋ฅผ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค; CR/LF๊ฐ€ ์–ด๋–ป๊ฒŒ ์ •๊ทœํ™”๋˜๊ฑฐ๋‚˜ dotโ€‘stuffing ๋˜๋Š”์ง€์— ๋Œ€ํ•œ ๋ชจํ˜ธ์„ฑ์€ desync๋ฅผ ์ดˆ๋ž˜ํ•ฉ๋‹ˆ๋‹ค.
- CHUNKING(BDAT)๋Š” ๋ฐ”๋””๋ฅผ ์ •ํ™•ํ•œ ๋ฐ”์ดํŠธ ๊ธธ์ด๋กœ ํ”„๋ ˆ์ด๋ฐํ•˜๋ฏ€๋กœ ๊ณ ์ „์ ์ธ smuggling์„ ๋ฐฉ์ง€ํ•ฉ๋‹ˆ๋‹ค. ๋‹ค๋งŒ ์†ก์‹ ์ž๊ฐ€ ์ˆ˜์‹ ์ž๊ฐ€ CHUNKING์„ ๊ด‘๊ณ ํ•˜์ง€ ์•Š์•„ DATA๋กœ ํด๋ฐฑํ•˜๋ฉด ๊ณ ์ „์  smuggling์ด ๋‹ค์‹œ ๊ฐ€๋Šฅํ•ด์ง‘๋‹ˆ๋‹ค.

---

## Notes on affected software and fixes (for targeting)

- Postfix: 3.9 ์ด์ „์—๋Š” ๊ธฐ๋ณธ์ ์œผ๋กœ bare LF๋ฅผ ํ—ˆ์šฉํ–ˆ์œผ๋ฉฐ; 3.5.23/3.6.13/3.7.9/3.8.4๋ถ€ํ„ฐ ๊ด€๋ฆฌ์ž๋Š” `smtpd_forbid_bare_newline`์„ ํ™œ์„ฑํ™”ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ํ˜„์žฌ ๊ถŒ์žฅ ์„ค์ •์€ `smtpd_forbid_bare_newline = normalize`(3.8.5+/3.7.10+/3.6.14+/3.5.24+)์ด๋ฉฐ, ์—„๊ฒฉํ•œ RFC ์ ์šฉ์„ ์›ํ•˜๋ฉด `reject`๋กœ ์„ค์ •ํ•˜์‹ญ์‹œ์˜ค.
- Exim: DATA ์‚ฌ์šฉ ์‹œ ํ˜ผํ•ฉ๋œ endโ€‘ofโ€‘DATA ์‹œํ€€์Šค์— ์˜์กดํ•˜๋Š” ๋ณ€์ข…์€ 4.97.1(๋ฐ ์ดํ›„ ๋ฒ„์ „)์—์„œ ์ˆ˜์ •๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ์˜ค๋ž˜๋œ 4.97/4.96์€ PIPELINING/CHUNKING์— ๋”ฐ๋ผ ์ทจ์•ฝํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
- Sendmail: 8.18์—์„œ ์ˆ˜์ •๋˜์—ˆ๊ณ , ์ด์ „์˜ 8.17.x๋Š” ์ผ๋ถ€ ๋น„ํ‘œ์ค€ terminator๋ฅผ ์ˆ˜์šฉํ–ˆ์Šต๋‹ˆ๋‹ค.
- ๋‹ค์–‘ํ•œ ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ/์„œ๋ฒ„(์˜ˆ: aiosmtpd 1.4.5 ์ด์ „, ์ผ๋ถ€ ๋ฒค๋” ๊ฒŒ์ดํŠธ์›จ์ด, ํŠน์ • SaaS relays ๋“ฑ)๋„ ์œ ์‚ฌํ•œ ๋ฌธ์ œ๊ฐ€ ์žˆ์—ˆ์œผ๋ฉฐ; ์ตœ์‹  ๋ฒ„์ „๋“ค์€ ๋ณดํ†ต DATA๋ฅผ ์—„๊ฒฉํ•œ `<CR><LF>.<CR><LF>`๋งŒ ์ˆ˜์šฉํ•ฉ๋‹ˆ๋‹ค.

์œ„์˜ ์Šค์บ๋„ˆ๋“ค์„ ์‚ฌ์šฉํ•ด ํ˜„์žฌ ๋™์ž‘์„ ํ™•์ธํ•˜์‹ญ์‹œ์˜ค; ๋งŽ์€ ๋ฒค๋”๊ฐ€ 2024โ€“2025๋…„ ์ดˆ์— ๊ธฐ๋ณธ๊ฐ’์„ ๋ณ€๊ฒฝํ–ˆ์Šต๋‹ˆ๋‹ค.

---

## Tips for red team ops

- A๋กœ๋Š” ๋Œ€ํ˜•์˜ ์ผ๋ฐ˜์ ์ธ ๋ฐœ์‹ ์ž(์—ญ์‚ฌ์ ์œผ๋กœ๋Š” Exchange Online, ๊ณต์œ  ํ˜ธ์ŠคํŒ… ์ œ๊ณต์ž ๋“ฑ)๋ฅผ ์„ ํ˜ธํ•˜์„ธ์š”. ์ด๋“ค์ด ์—ฌ์ „ํžˆ ์ผ๋ถ€ ๋น„ํ‘œ์ค€ EOM์„ ํฌ์›Œ๋“œํ•˜๊ณ  ํ”ผํ•ด์ž์˜ SPF์— ํฌํ•จ๋˜์–ด ์žˆ๋‹ค๋ฉด, ๋‹น์‹ ์ด smuggleํ•œ MAIL FROM์€ ๊ทธ๋“ค์˜ ํ‰ํŒ์„ ์ƒ์†๋ฐ›์Šต๋‹ˆ๋‹ค.
- B์˜ SMTP ํ™•์žฅ ๊ธฐ๋Šฅ์„ ์—ด๊ฑฐํ•˜์„ธ์š”: PIPELINING/CHUNKING ์—ฌ๋ถ€๋Š” `EHLO` ๋ฐฐ๋„ˆ๋กœ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค; CHUNKING์ด ์—†์œผ๋ฉด BDATโ€‘first ์†ก์‹ ์ž์—์„œ ์„ฑ๊ณตํ•  ๊ฐ€๋Šฅ์„ฑ์ด ๋” ๋†’์Šต๋‹ˆ๋‹ค. ์ž˜๋ชป๋œ EOM๊ณผ ๊ฒฐํ•ฉํ•ด ์ˆ˜์šฉ ์—ฌ๋ถ€๋ฅผ ํƒ์ง€ํ•˜์„ธ์š”.
- ํ—ค๋”๋ฅผ ์ฃผ์‹œํ•˜์„ธ์š”: smuggle๋œ ๋ฉ”์‹œ์ง€๋Š” ๋ณดํ†ต B์—์„œ ์‹œ์ž‘ํ•˜๋Š” ๋ณ„๋„์˜ Received ์ฒด์ธ์„ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค. MAIL FROM์ด A์˜ IP ๊ณต๊ฐ„๊ณผ ์ •๋ ฌ๋˜๋ฏ€๋กœ DMARC๋Š” ์ข…์ข… ํ†ต๊ณผ๋ฉ๋‹ˆ๋‹ค.

---

## **์ฐธ๊ณ  ์ž๋ฃŒ**

- [https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/](https://sec-consult.com/blog/detail/smtp-smuggling-spoofing-e-mails-worldwide/)
- [https://www.postfix.org/smtp-smuggling.html](https://www.postfix.org/smtp-smuggling.html)

> [!TIP]
> AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:<img src="../../../../../images/arte.png" alt="" style="width:auto;height:24px;vertical-align:middle;">[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)<img src="../../../../../images/arte.png" alt="" style="width:auto;height:24px;vertical-align:middle;">\
> GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: <img src="../../../../../images/grte.png" alt="" style="width:auto;height:24px;vertical-align:middle;">[**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte)<img src="../../../../../images/grte.png" alt="" style="width:auto;height:24px;vertical-align:middle;">
> Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: <img src="../../../../../images/azrte.png" alt="" style="width:auto;height:24px;vertical-align:middle;">[**HackTricks Training Azure Red Team Expert (AzRTE)**](https://training.hacktricks.xyz/courses/azrte)<img src="../../../../../images/azrte.png" alt="" style="width:auto;height:24px;vertical-align:middle;">
>
> <details>
>
> <summary>HackTricks ์ง€์›ํ•˜๊ธฐ</summary>
>
> - [**๊ตฌ๋… ๊ณ„ํš**](https://github.com/sponsors/carlospolop) ํ™•์ธํ•˜๊ธฐ!
> - **๐Ÿ’ฌ [**๋””์Šค์ฝ”๋“œ ๊ทธ๋ฃน**](https://discord.gg/hRep4RUj7f) ๋˜๋Š” [**ํ…”๋ ˆ๊ทธ๋žจ ๊ทธ๋ฃน**](https://t.me/peass)์— ์ฐธ์—ฌํ•˜๊ฑฐ๋‚˜ **ํŠธ์œ„ํ„ฐ** ๐Ÿฆ [**@hacktricks_live**](https://twitter.com/hacktricks_live)**๋ฅผ ํŒ”๋กœ์šฐํ•˜์„ธ์š”.**
> - **[**HackTricks**](https://github.com/carlospolop/hacktricks) ๋ฐ [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) ๊นƒํ—ˆ๋ธŒ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์— PR์„ ์ œ์ถœํ•˜์—ฌ ํ•ดํ‚น ํŠธ๋ฆญ์„ ๊ณต์œ ํ•˜์„ธ์š”.**
>
> </details>