Infrastructure

1. AD ์„ค์ •

  1. AD Machine

    • AD DS(Domain Server ๋ฐ Main Domain Controller) ECAMAZ-6E3DNME

      • Domain์€ pbl-waffle.swu (AD-WAFFLE)

      • AD CS(Certificate Services)์˜ ์—ญํ• ๋„ ๊ฒธํ•จ

    • AD FS(Fedestration Services) adfs2

    • Victim Client client

    โš ๏ธ ๋ชจ๋“  Instance๋Š” ๊ฐ™์€ Subnet์— ์žˆ์–ด์•ผ ํ•œ๋‹ค.

  2. AD Account(User)

    • DS Administrator

    • fsadmin@pbl-waffle.swu

    • aws.admin@pbl-waffle.swu

    โœ… ๊ณ„์ •๋“ค์€ ๊ฐ Host์—์„œ ๋กœ์ปฌ ๊ด€๋ฆฌ์ž ๊ถŒํ•œ์„ ๊ฐ–๊ณ ์žˆ์Œ


2. ์ทจ์•ฝํ•œ ๋ณด์•ˆ ์„ค์ •

ํ•œ ๋ฒˆ์— ๋ชจ๋“  ์„ค์ •์„ ํ’€๊ธฐ๋ณด๋‹ค, ๊ณต๊ฒฉ ์ค‘ ๋ง‰ํžˆ๋Š” ๋ถ€๋ถ„์ด ์žˆ์œผ๋ฉด ํ’€์–ด๋‚ด๋Š” ์‹์œผ๋กœ ์ง„ํ–‰ํ•˜์˜€๋‹ค. ์•„๋ž˜๋Š” ๊ณต๊ฒฉ ์ˆ˜ํ–‰ ๊ณผ์ • ์ค‘ ํ’€์–ด๋‚ธ ๋ชจ๋“  ์„ค์ •์„ ์ข…ํ•ฉํ•˜์—ฌ ์ž‘์„ฑํ•˜์˜€๋‹ค.

์‹ค์ œ๋กœ ์‚ฌ์šฉ๋˜๋Š” ์ธํ”„๋ผ๋ณด๋‹ค ์•„๋ฌด๊ฒƒ๋„ ์—†๋Š” ์ธํ”„๋ผ์—์„œ ๊ณต๊ฒฉํ•˜๋Š” ๊ฒŒ ๋” ์–ด๋ ต๋‹ค๋Š” ๊ฒƒ์„ ์ฒดํ—˜ํ•  ์ˆ˜ ์žˆ๋‹ค.

  1. [Victim] [AD FS] Windows Defender - Real-time protection Off

  2. [AD FS] WMI ์„œ๋น„์Šค ๋ฐฉํ™”๋ฒฝ Open

  3. [AD FS] WMI ๊ด€๋ จ ๋กœ์ปฌ ๋ฐฉํ™”๋ฒฝ ํ•ด์ œ

  4. [AD FS] WMI ๊ถŒํ•œ ๋ถ€์—ฌ

    wmimgmt.msc ์œ ํ‹ธ๋ฆฌํ‹ฐ๋ฅผ ์‹คํ–‰ํ•˜๊ณ  WMI ๋„๋ฉ”์ธ์— ๋ณด์•ˆ ์„ค์ •์„ ํ•œ๋‹ค.

    ๋„๋ฉ”์ธ์— ๋‹ค์Œ ์œ„์น˜์— ๋Œ€ํ•œ ์‚ฌ์šฉ ๊ถŒํ•œ์„ ํ• ๋‹นํ•œ๋‹ค.

    • root/CIMv2

    • root/Default

    • root/SecurityCenter

    • root/SecurityCenter2

    ๊ฐ ๋„๋ฉ”์ธ์— ๋‹ค์Œ ์‚ฌ์šฉ ๊ถŒํ•œ์„ ํ• ๋‹นํ•œ๋‹ค.

    • Execute Methods

    • Enable Account

    • Remote Enable

    • Read Security

    ์ฐธ๊ณ : https://docs.genians.com/release/ko/authentication/enabling-authentication/sso/ms-wmi.htmlarrow-up-right

  5. [AD FS] DCOM ์›๊ฒฉ ์ ‘๊ทผ ๊ถŒํ•œ ์ถ”๊ฐ€

  6. [AD CS] ์ธ์ฆ์„œ: Private Key Exportable ์„ค์ •ํ•˜์—ฌ ๋ฐœ๊ธ‰ [AD FS] ํ•ด๋‹น ์ธ์ฆ์„œ ๋“ฑ๋ก โ†’ ADFSDump ์‹œ dkm๊ณผ tks๊ฐ€ ์ œ๋Œ€๋กœ ์ถœ๋ ฅ๋˜๊ธฐ ์œ„ํ•จ


3. ์ž์„ธํ•œ ๋กœ๊น… ์„ค์ •

โ€ป ์‹ค์ œ๋กœ ๋ชจ๋“  Audit ๋กœ๊น…์„ ํ™œ์„ฑํ™”ํ•˜๋ฉด ์ปดํ“จํ„ฐ์˜ ์„ฑ๋Šฅ์ด ์ €ํ•˜๋  ์ˆ˜ ์žˆ์œผ๋‹ˆ ํ•„์š”์— ๋”ฐ๋ผ ํ™œ์šฉํ•ด์•ผํ•œ๋‹ค.

  1. [AD DS] HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NTDS\Diagnostics ๋ชจ๋“  ๊ฐ’ 5๋กœ ๋ณ€๊ฒฝ

  2. [AD DS] gpmc.msc ๋ชจ๋“  Categories Configure

  3. [AD DS] AD Management - Domain - Properties - Security - Auditing ๋ชจ๋‘ ํ™œ์„ฑํ™”

  4. [AD FS] SSMS(SQL Server Management Studio)์—์„œ Audit Log ํ™œ์„ฑํ™”

  5. [AD FS][Victim Client] Local Security Policy - Audiot Policy ์ „์ฒด ํ™œ์„ฑํ™”


4. ์ž๋™ํ™” ๋ฐฐํฌ ์„ค์ •

ํŠน์ • BR์„ ๋‹ค์ˆ˜ ํ˜ธ์ŠคํŠธ์— ํ•œ๋ฒˆ์— ๋ฐฐํฌํ•˜๊ธฐ ์œ„ํ•ด์„œ ํŒŒ์›Œ์‰˜ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‚ฌ์šฉํ•˜์˜€๋‹ค.

์ด ๋•Œ, ์Šคํฌ๋ฆฝํŠธ๋ฅผ ๋ฐฐ์น˜ํŒŒ์ผ ์—†์ด ์‹คํ–‰์‹œํ‚ค๊ธฐ ์œ„ํ•ด์„œ๋Š” ๋ณ„๋„์˜ ์„ค์ •์ด ํ•„์š”ํ•˜๋‹ค.

[์ปดํ“จํ„ฐ ๊ตฌ์„ฑ โ†’ ์ •์ฑ… โ†’ ๊ด€๋ฆฌ ํ…œํ”Œ๋ฆฟ โ†’ Windows ๊ตฌ์„ฑ์š”์†Œ โ†’ Windows Power Shell] ๊ฒฝ๋กœ์—์„œ "์Šคํฌ๋ฆฝํŠธ ์‹คํ–‰ ํ™œ์„ฑํ™”"๋ฅผ ์‚ฌ์šฉ์œผ๋กœ ์„ค์ •ํ•˜๊ณ , "๋ชจ๋“  ์Šคํฌ๋ฆฝํŠธ ํ—ˆ์šฉ"์„ ์„ ํƒํ•œ๋‹ค.

Last updated