mirror of
https://github.com/HackTricks-wiki/hacktricks.git
synced 2025-10-10 18:36:50 +00:00
106 lines
2.6 KiB
Markdown
106 lines
2.6 KiB
Markdown
# macOS Varsayılan Sandbox Hatası Ayıklama
|
||
|
||
{{#include ../../../../banners/hacktricks-training.md}}
|
||
|
||
Bu sayfada, varsayılan macOS sandbox'ından içeriye rastgele komutlar gönderen bir uygulama nasıl oluşturulacağını bulabilirsiniz:
|
||
|
||
1. Uygulamayı derleyin:
|
||
```objectivec:main.m
|
||
#include <Foundation/Foundation.h>
|
||
|
||
int main(int argc, const char * argv[]) {
|
||
@autoreleasepool {
|
||
while (true) {
|
||
char input[512];
|
||
|
||
printf("Enter command to run (or 'exit' to quit): ");
|
||
if (fgets(input, sizeof(input), stdin) == NULL) {
|
||
break;
|
||
}
|
||
|
||
// Remove newline character
|
||
size_t len = strlen(input);
|
||
if (len > 0 && input[len - 1] == '\n') {
|
||
input[len - 1] = '\0';
|
||
}
|
||
|
||
if (strcmp(input, "exit") == 0) {
|
||
break;
|
||
}
|
||
|
||
system(input);
|
||
}
|
||
}
|
||
return 0;
|
||
}
|
||
```
|
||
`clang -framework Foundation -o SandboxedShellApp main.m` komutunu çalıştırarak derleyin.
|
||
|
||
2. `.app` paketini oluşturun.
|
||
```bash
|
||
mkdir -p SandboxedShellApp.app/Contents/MacOS
|
||
mv SandboxedShellApp SandboxedShellApp.app/Contents/MacOS/
|
||
|
||
cat << EOF > SandboxedShellApp.app/Contents/Info.plist
|
||
<?xml version="1.0" encoding="UTF-8"?>
|
||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||
<plist version="1.0">
|
||
<dict>
|
||
<key>CFBundleIdentifier</key>
|
||
<string>com.example.SandboxedShellApp</string>
|
||
<key>CFBundleName</key>
|
||
<string>SandboxedShellApp</string>
|
||
<key>CFBundleVersion</key>
|
||
<string>1.0</string>
|
||
<key>CFBundleExecutable</key>
|
||
<string>SandboxedShellApp</string>
|
||
</dict>
|
||
</plist>
|
||
EOF
|
||
```
|
||
3. Yetkilileri tanımlayın
|
||
|
||
{{#tabs}}
|
||
{{#tab name="sandbox"}}
|
||
```bash
|
||
cat << EOF > entitlements.plist
|
||
<?xml version="1.0" encoding="UTF-8"?>
|
||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||
<plist version="1.0">
|
||
<dict>
|
||
<key>com.apple.security.app-sandbox</key>
|
||
<true/>
|
||
</dict>
|
||
</plist>
|
||
EOF
|
||
```
|
||
{{#endtab}}
|
||
|
||
{{#tab name="sandbox + downloads"}}
|
||
```bash
|
||
cat << EOF > entitlements.plist
|
||
<?xml version="1.0" encoding="UTF-8"?>
|
||
<!DOCTYPE plist PUBLIC "-//Apple//DTD PLIST 1.0//EN" "http://www.apple.com/DTDs/PropertyList-1.0.dtd">
|
||
<plist version="1.0">
|
||
<dict>
|
||
<key>com.apple.security.app-sandbox</key>
|
||
<true/>
|
||
<key>com.apple.security.files.downloads.read-write</key>
|
||
<true/>
|
||
</dict>
|
||
</plist>
|
||
EOF
|
||
```
|
||
{{#endtab}}
|
||
{{#endtabs}}
|
||
|
||
4. Uygulamayı imzalayın (anahtar zincirinde bir sertifika oluşturmanız gerekiyor)
|
||
```bash
|
||
codesign --entitlements entitlements.plist -s "YourIdentity" SandboxedShellApp.app
|
||
./SandboxedShellApp.app/Contents/MacOS/SandboxedShellApp
|
||
|
||
# An d in case you need this in the future
|
||
codesign --remove-signature SandboxedShellApp.app
|
||
```
|
||
{{#include ../../../../banners/hacktricks-training.md}}
|