ããã«ã¡ã¯ïŒ
ããã¯ãKerberosãããã³ã«æ»æããŒã«ã§ããRubeusã®æ©èœã«é¢ããèšäºã®2çªç®ã®éšåã§ããæåã¯ããã§èªãããšãã§ããŸããä»åã¯ããã®ããŒã«ã䜿çšããŠæ¬¡ã®æ»æãå®è£ ããæ¹æ³ãèŠãŠãããŸããâš
- Overpass The Hash / Pass The KeyïŒPTKïŒ;
- ãã±ãããæž¡ã;
- å¶çŽã®ãªãå§ä»»;
- å¶çŽä»ãå§ä»»ã
ãããã®æ»æãå¯èœã§ããçç±ããããã®å®è£ ã®ã¡ã«ããºã ãååšããåçãKerberosã®äžå¿ã«ããåçïŒããšãã°ãJet Infosystemã®ååãåæããåªããèšäºãå ¬éããŠãããªã©ïŒã«ã€ããŠã¯ãã§ã«å€ãã®èšäºãæžãããŠããã®ã§ãç§ã®è³æã§ã¯ãæ»æã®å®è£ ã«çŠç¹ãåœãŠãŸãRubeusã䜿çšããŸãã
Rubeusã¯ãæ»æãå®è¡ããŠKerberosãšå¯Ÿè©±ããããã®ãã¢ã¯ã·ã§ã³ãã«å ããŠãã¯ãªã¢ããã¹ãã®ãã¹ã¯ãŒãã«åºã¥ããŠNTLMããã·ã¥ãèšç®ã§ãããããéåžžã«äŸ¿å©ã§äŸ¿å©ãªå ŽåããããŸãã
ããã§å°ããªåæ çãªäœè«ãçµãããŸãããæ¬é¡ã«æ»ããŸããããèšäºã®æåã®éšåãå ¬éãããŠ
以æ¥ãæ»æãå®è¡ããããã®ãã¹ããã³ãã¯å€æŽãããŠããŸããã
Overpass The Hash / Pass The KeyïŒPTKïŒ
âãããããããã¯ãŒã¯ã§NTLMãŸãã¯LMèªèšŒãç¡å¹ã«ãªã£ãŠããŠãKerberosèªèšŒã®ã¿ã䜿çšãããŠããããã¹ã¯ãŒãããã·ã¥ãããå Žåã¯ã©ãã§ããããããããOverpass-the-hashã®åºçªã§ãããŠãŒã¶ãŒã®ãã¹ã¯ãŒãããã·ã¥ã䜿çšããŠãRubeusã¯ãã®ã¢ã«ãŠã³ãã®TGTãèŠæ±ã§ããŸãã
Pass-the-hash â . , NTLM LM.
Barsikãæ å ±ã»ãã¥ãªãã£ã®åé¡ã調æ»ããããšã決ãããã¡ã€ã³ãŠãŒã¶ãŒã¯æ¬¡ã®ãšããã§ããADadminãã¡ã€ã³ç®¡çè ãã¹ã¯ãŒãã®ããã·ã¥ãå ¥æããRubeusãããŠã³ããŒãããã¹ããŒããªèšäºãèªãã§ããããå®è·µããããšããŠããŸãã
ãã£ãã·ã¥ããããã±ããããã¡ã€ã³ã³ã³ãããŒã©ãŒãžã®ã¢ã¯ã»ã¹æš©ããªãããšãããããŸãããBarsikã¯ADubeã¢ã«ãŠã³ãã®æ¢åã®ãã¹ã¯ãŒãããã·ã¥ã«åºã¥ããŠæå¹ãªTGTãã±ãããååŸããããã«
DC-16.meow.local
ããã¢ã¯ã·ã§ã³ãasktgt
ãšåŒæ°/domain, /user, /rc4, /ptt
ã§Rubeusãèµ·åããŸãã/ptt
åä¿¡ãããã±ãããããã«BarsikãŠãŒã¶ãŒã®çŸåšã®ã»ãã·ã§ã³ã«ã¢ããããŒãããŸãã
ãã±ãããåä¿¡ããŠââã¢ããããŒããããšãBarsikã¯AdadminãšããŠãã¡ã€ã³ã³ã³ãããŒã©ãŒã«å床ãã°ã€ã³ããããšããŸãã
ãããŠä»åã¯åœŒã¯ãããæåãããŠããŸãã
ãã±ãããæž¡ãïŒPTTïŒ
ãã®æ»æã¯Overpass-the-hash / Pass-the-keyã«äŒŒãŠãããæ»æè ã¯ãã¡ã€ã³ãŠãŒã¶ãŒãã±ããïŒã§ããã°ãã¡ã€ã³ã§æ倧ã®æš©éãæã€ïŒãååŸããŠçŸåšã®ã»ãã·ã§ã³ã«ããŒãããããšããŸãã TGTãã±ãããååŸãã1ã€ã®æ¹æ³ã¯ãããã»ã¹
lsass.exe
ïŒããŒã«ã«ã»ãã¥ãªãã£èªèšŒãµãŒããŒïŒããçŸåšã®ãã¡ã€ã³ãã·ã³ã®ããŒã«ã«ã«ãã±ããããã³ãããããšã§ãããããè¡ãã«ã¯ãããŒã«ã«ç®¡çè
ç¹æš©ããŸãã¯NT AUTHORITY / SYSTEMãå¿
èŠã§ãã Rubeusã¯lsassã«ä¿åãããŠãããã±ããããã³ãã¢ã¯ã·ã§ã³ã§ãã³ãã§ããŸããããªã¢ãŒãžã¢ã¯ã·ã§ã³ã¯ãçŸåšã·ã¹ãã ã«ä¿åãããŠãããã±ããã瀺ããŸãã
Rubeusã¯
lsass
ãšã³ã³ãŒãããããã±ãããã¢ã³ããŒããbase64
ãŸãããããŒã«èªäœã¯åä¿¡ããbase64
ãã±ãããã«ä¿åããæ¹æ³ã«é¢ããã¡ã¢ãæã£ãŠã.kirbi
ãŸãã
ãã±ãããä¿åããŠçŸåšã®ãŠãŒã¶ãŒã»ãã·ã§ã³ã«ã€ã³ããŒãããŸãã
ã¹ã¯ãªãŒã³ã·ã§ãããããããããã«ãADadminãã±ããã¯æ£åžžã«èªã¿èŸŒãŸããADadmin
DC-16.meow.local
ã«ä»£ãã£ãŠãã¡ã€ã³ã³ã³ãããŒã©ãŒã®Cãã©ã€ãã®å
容ã衚瀺ã§ããŸãã
å¶çŽã®ãªãå§ä»»
å¶çŽã®ãªãå§ä»»ã¯ããŠãŒã¶ãŒãŸãã¯ã³ã³ãã¥ãŒã¿ãŒã¢ã«ãŠã³ãã«ä»äžã§ãããã¡ã€ã³æš©éã§ããããã«ãããã¢ã«ãŠã³ãã¯ãããã¯ãŒã¯äžã®ãµãŒãã¹ã«å¯ŸããŠå¥ã®ã¢ã«ãŠã³ããšããŠèªèšŒã§ããŸãã
次ã«ããã¹ããã³ããå°ã調æŽããŠãç¡å¶éã®å§ä»»ãæå¹ã«ããŸããBARSCOMPã³ã³ãã¥ãŒã¿ã«ç¡å¶éã®å§ä»»ã®ç¹æš©ãäžããŸãããã
Active Directoryãã¡ã€ã³ã®ã»ãã¥ãªãã£ãã¹ããå®æœãã段éã®1ã€ã¯ãå§ä»»ãæå¹ã«ãªã£ãŠããã¢ã«ãŠã³ããæ€çŽ¢ããããšã§ããéåžžããããã®ç®çã«ã¯Powerviewã䜿çšãããŸãããæšæºã®ActiveDirectoryã¢ãžã¥ãŒã«ã䜿çšããŠæåã§è¡ãããšãã§ããŸãã
ãã®æ»æãå®è¡ããããã«ãPrinter Bugã䜿çšããŸãSpecterOpsã®Lee Christensenã«ãã£ãŠè©³çŽ°ã«èª¬æãããŸãããèªèšŒããããŠãŒã¶ãŒã¯ããã¡ã€ã³ã³ã³ãããŒã©ã®ããªã³ããµãŒããŒã«ãªã¢ãŒãã§æ¥ç¶ããç¡å¶éã®å§ä»»ã¢ã«ãŠã³ãã«éç¥ãéä¿¡ããããã«æ瀺ããããšã§ãæ°ããå°å·ãžã§ãã®æŽæ°ãèŠæ±ã§ããŸãã Lee Christensenã¯ãMS-RPRNãããã³ã«ã䜿çšããŠCDå°å·ãµãŒãã¹ãåŒã³åºãSpoolSampleã¢ããªã±ãŒã·ã§ã³ãäœæããŸããã
æ»æãå®è¡ãããã³ã³ãã¥ãŒã¿ãŒïŒBARSCOMP.meow.localïŒã§ããã¢ã¯ã·ã§ã³ãã䜿çšããŠç£èŠã¢ãŒãã§Rubeusãèµ·åããå¿ èŠããããŸã
monitoring
ããã®ã¢ãŒãã¯NT ATHORITY / SYSTEMç¹æš©ãå¿
èŠãšããlsassããã»ã¹ã§æ°ããTGT / TGSãã±ãââãããªãã¹ã³ããŸãã/interval:1
æ°ãããã±ããã®lsassãããŒãªã³ã°ããééïŒç§ïŒãšåŒæ°ãèšå®ããŸã/filteruser:DC-16$
DC-16 $ãã±ããã®ã¿ã衚瀺ãããã£ã«ã¿ãŒãèšå®ããŸãã
Rubeusãå®è¡ãããŠãããå¥ã®ã»ãã·ã§ã³ã§äžŠè¡ããŠãåŒæ°
dc-16.meow.local
ïŒæ»æããããã·ã³ïŒãšbarscomp.meow.local
ïŒãåŸ
æ©ããã¹ãïŒãæå®ããŠSpoolSample.exeãèµ·åããŸãã
Rubeusããç£èŠãããå 容ãèŠãŠã¿ãŸãããã
TGTãã¡ã€ã³ã³ã³ãããŒã©ãŒã¢ã«ãŠã³ããã±ããããã£ããããŸãããããã§ãæ¢ç¥ã®Pass-the-Ticketæ»æã䜿çšããŠããã±ãããã€ã³ããŒãããmimikatzã䜿çšããŠDCSyncæ»æãå®è¡ããŠãkrbtgtã¢ã«ãŠã³ãã®NTLMããã·ã¥ãååŸã§ããŸãïŒèšäºã®æåã®éšåã§ãã§ã«ç¥ã£ãŠããããã«ããã®ã¢ã«ãŠã³ãã®ããã·ã¥ã䜿çšããŠäœæã§ããŸãïŒãŽãŒã«ãã³ãã±ãããšå®å šãªADãã¡ã€ã³ã®ãã£ããã£ïŒã
Rubeusã¯.kirbiãã¡ã€ã«ã®åœ¢åŒãšbase64ãšã³ã³ãŒããããæååã®äž¡æ¹ã§ãã±ãããç解ããããšã«æ³šæããŠãã ããã
å¶çŽä»ãå§ä»»
æ»æè ãå¶çŽä»ãå§ä»»ãæå¹ã«ãªã£ãŠãããŠãŒã¶ãŒãŸãã¯ã³ã³ãã¥ãŒã¿ãŒã¢ã«ãŠã³ãã®äŸµå®³ã«æåãããšãä»»æã®ãã¡ã€ã³ãŠãŒã¶ãŒã«ãªãããŸããŠãå§ä»»ãèš±å¯ãããŠãããµãŒãã¹ã«å¯ŸããŠèªèšŒãè¡ãããšãã§ããŸãã
ãã¹ã¯ãŒãB @ ckup1234ã§æ°ãããã¡ã€ã³ãŠãŒã¶ãŒBackupãäœæãããã¡ã€ã³ã³ã³ãããŒã©ãŒäžã®cifsãµãŒãã¹ã®SPNãå²ãåœãŠãŸãã
ããã§ããã®ã¢ã«ãŠã³ããèšå®ããŠãLDAPããã³CIFSãµãŒãã¹ãDC-16.meow.localãã¡ã€ã³ã³ã³ãããŒã©ãŒã«å§ä»»ã§ããããã«ãªããŸããã
ãŸããPowerviewãŸãã¯ActiveDirectoryã¢ãžã¥ãŒã«ã䜿çšããŠãå¶éä»ãå§ä»»ãèš±å¯ãããŠããã¢ã«ãŠã³ããç¹å®ããããšãã§ããŸãã
meow.local \ Backupã¢ã«ãŠã³ãã®ãã¹ã¯ãŒããŸãã¯NTLMããã·ã¥ãããã£ãŠããã®ã§ãRubeusã䜿çšããŠTGTãã±ãããèŠæ±ã§ããŸãã
ããã§ãRubeusã®ãã¢ã¯ã·ã§ã³ãs4uã䜿çšããŠãcifs \ dc-16.meow.localãµãŒãã¹ã§ã®èªèšŒãèš±å¯ãããŠãããŠãŒã¶ãŒïŒããšãã°ãADadminãã¡ã€ã³ã®ç®¡çè ïŒã«TGSãèŠæ±ã§ããŸãã
ããã§ã¯ã以åã«ååŸããããã¯ã¢ããã¢ã«ãŠã³ããã±ããã瀺ããŸãã / impersonateuser-æš©å©ãååŸããããŠãŒã¶ãŒã /ãã¡ã€ã³-ãã¹ãŠãçºçãããã¡ã€ã³ã / msdsspn / asltservice-TGSãå¿ èŠãšãããµãŒãã¹ã / ptt-åä¿¡ãããã±ãããçŸåšã®ã»ãã·ã§ã³ã«ããã«ã€ã³ããŒãããŸãã
Rubeusã§äœãèµ·ãããã
次ã«ç€ºããŸããå¶çŽä»ãå§ä»»2ã§Kerberosæ¡åŒµãæå¹ã«ãªã£ãŠããããšãããããŸãããããã¯S4U2selfãšS4U2proxyã§ãã
S4U2selfã䜿çšãããšããµãŒãã¹ã®åå è ã¯ãç¹å®ã®ãŠãŒã¶ãŒã«ä»£ãã£ãŠãFORWARDABLEãã©ã°ä»ãã®ç¹å¥ãªTGSãèªåèªèº«ã«èŠæ±ã§ããŸããããã¯ããã®ãã±ãããåŸã§S4U2proxyæ¡åŒµæ©èœã§äœ¿çšã§ããããã«ããããã«å¿ èŠã§ãã
S4U2proxyã«ãããåŒã³åºãå ã¯ãã®ç¹å¥ãªãã±ããã䜿çšããŠãå§ä»»ãèš±å¯ãããŠãããµãŒãã¹ïŒãã®å Žåã¯ãcifs \ dc-16.meow.localïŒã®ãŠãŒã¶ãŒã®TGSãèŠæ±ã§ããŸããããªãã¯ãããšããã§ããã«ã€ããŠãã£ãšèªãããšãã§ããŸãã
ãã®æç¹ã§ãRubeusã¯ãã§ã«æçµãã±ãããåãåããçŸåšã®ã»ãã·ã§ã³ã«ã€ã³ããŒãããŸããã
åä¿¡ãããã±ããã䜿çšããŠããã¡ã€ã³ã³ã³ãããŒã©ãŒã®Cãã©ã€ãã確èªã§ãããã©ããã確èªããŸãã
ã¯ãããã¹ãŠããŸããããŸããã
ããã§ããã®ããŒã«ã®ã¬ãã¥ãŒã¯çµããã§ããäžè¬çã«ãç§ã¯ãããæ°ã«å ¥ã£ãŠããã䜿ãããããæ©èœãåªããŠããŸãããããã®èšäºãèªãã åŸãããªãããããå®éã«åœ¹ç«ãŠãŠãããããšãé¡ã£ãŠããŸãã
ããªãã®æ³šæãããããšãã誰ããè¯ãã§ããç æ°ã«ãªããªãã§ãã ããïŒ