RPC

RPCclient

realblackcat@htb[/htb]$ rpcclient -U "" - N 10.129.14.128

Enter WORKGROUP\'s password:
rpcclient $> 
  • rpcclien๋Š” smb ์„œ๋ฒ„์—์„œ ํŠน์ • ํ•จ์ˆ˜๋ฅผ ์‹คํ–‰ํ•˜์—ฌ ์ •๋ณด๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ๋Š” ๋‹ค์–‘ํ•œ ์š”์ฒญ์„ ์ œ๊ณต

์ฟผ๋ฆฌ
์„ค๋ช…

srvinfo

์„œ๋ฒ„ ์ •๋ณด

enumdomains

๋„คํŠธ์›Œํฌ์— ๋ฐฐํฌ๋œ ๋ชจ๋“  ๋„๋ฉ”์ธ ์—ด๊ฑฐ

querydominfo

๋ฐฐํฌ๋œ ๋„๋ฉ”์ธ์˜ ๋„๋ฉ”์ธ, ์„œ๋ฒ„ ๋ฐ ์‚ฌ์šฉ์ž ์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

netshareenumall

์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๋ชจ๋“  ๊ณต์œ ๋ฅผ ์—ด๊ฑฐํ•ฉ๋‹ˆ๋‹ค.

netsharegetinfo <share>

ํŠน์ • ๊ณต์œ ์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

enumdomusers

๋ชจ๋“  ๋„๋ฉ”์ธ ์‚ฌ์šฉ์ž๋ฅผ ์—ด๊ฑฐํ•ฉ๋‹ˆ๋‹ค.

queryuser <RID>

ํŠน์ • ์‚ฌ์šฉ์ž์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

RPCclient โ€“ Enumeration

rpcclient $> srvinfo #์„œ๋ฒ„ ์ •๋ณด 

        DEVSMB         Wk Sv PrQ Unx NT SNT DEVSM
        platform_id     :       500
        os version      :       6.1
        server type     :       0x809a03
		
		
rpcclient $> enumdomains #๋„คํŠธ์›Œํฌ์— ๋ฐฐํฌ๋œ ๋ชจ๋“  ๋„๋ฉ”์ธ ์—ด๊ฑฐ 

name:[DEVSMB] idx:[0x0]
name:[Builtin] idx:[0x1]


rpcclient $> querydominfo #๋ฐฐํฌ๋œ ๋„๋ฉ”์ธ์˜ ๋„๋ฉ”์ธ, ์„œ๋ฒ„ ๋ฐ ์‚ฌ์šฉ์ž ์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

Domain:         DEVOPS
Server:         DEVSMB
Comment:        DEVSM
Total Users:    2
Total Groups:   0
Total Aliases:  0
Sequence No:    1632361158
Force Logoff:   -1
Domain Server State:    0x1
Server Role:    ROLE_DOMAIN_PDC
Unknown 3:      0x1


rpcclient $> netshareenumall #์‚ฌ์šฉ ๊ฐ€๋Šฅํ•œ ๋ชจ๋“  ๊ณต์œ ๋ฅผ ์—ด๊ฑฐํ•ฉ๋‹ˆ๋‹ค.

netname: print$
        remark: Printer Drivers
        path:   C:\var\lib\samba\printers
        password:
netname: home
        remark: INFREIGHT Samba
        path:   C:\home\
        password:
netname: dev
        remark: DEVenv
        path:   C:\home\sambauser\dev\
        password:
netname: notes
        remark: CheckIT
        path:   C:\mnt\notes\
        password:
netname: IPC$
        remark: IPC Service (DEVSM)
        path:   C:\tmp
        password:
		
		
rpcclient $> netsharegetinfo notes #ํŠน์ • ๊ณต์œ ์— ๋Œ€ํ•œ ์ •๋ณด๋ฅผ ์ œ๊ณตํ•ฉ๋‹ˆ๋‹ค.

netname: notes
        remark: CheckIT
        path:   C:\mnt\notes\
        password:
        type:   0x0
        perms:  0
        max_uses:       -1
        num_uses:       1
revision: 1
type: 0x8004: SEC_DESC_DACL_PRESENT SEC_DESC_SELF_RELATIVE 
DACL
        ACL     Num ACEs:       1       revision:       2
        ---
        ACE
                type: ACCESS ALLOWED (0) flags: 0x00 
                Specific bits: 0x1ff
                Permissions: 0x101f01ff: Generic all access SYNCHRONIZE_ACCESS WRITE_OWNER_ACCESS WRITE_DAC_ACCESS READ_CONTROL_ACCESS DELETE_ACCESS 
                SID: S-1-1-0
  • ์ด ์˜ˆ๋Š” ์ต๋ช… ์‚ฌ์šฉ์ž์—๊ฒŒ ์–ด๋–ค ์ •๋ณด๊ฐ€ ์œ ์ถœ๋  ์ˆ˜ ์žˆ๋Š”์ง€ ๋ณด์—ฌ์คŒ

  • ๊ฐ€์žฅ ์ค‘์š”ํ•œ ๊ฒƒ์€ ์ด๋Ÿฌํ•œ ์„œ๋น„์Šค์— ์ต๋ช…์œผ๋กœ ์•ก์„ธ์Šคํ•˜๋ฉด ๋‹ค๋ฅธ ์‚ฌ์šฉ์ž๊ฐ€ ๋ฐœ๊ฒฌ๋  ์ˆ˜ ์žˆ์œผ๋ฉฐ, ๊ฐ€์žฅ ๊ณต๊ฒฉ์ ์ธ ๊ฒฝ์šฐ ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž… ๊ณต๊ฒฉ์„ ๋ฐ›์„ ์ˆ˜ ์žˆ์Œ.

    • rpcclient๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์‚ฌ์šฉ์ž๋ฅผ ์—ด๊ฑฐํ•˜๋Š” ๋ฐฉ๋ฒ•์„ ์‚ดํŽด๋ณด์ž

Rpcclient โ€“ ์‚ฌ์šฉ์ž ์—ด๊ฑฐํ˜•

  • ์ด์ œ ์ด ๊ฒฐ๊ณผ๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๊ทธ๋ฃน์˜ RID๋ฅผ ์‹๋ณ„ํ•œ ๋‹ค์Œ ์ „์ฒด ๊ทธ๋ฃน์—์„œ ์ •๋ณด๋ฅผ ๊ฒ€์ƒ‰ํ•˜๋Š”๋ฐ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Œ

Rpcclient โ€“ ๊ทธ๋ฃน ์ •๋ณด

  • ์ด ๋ชจ๋“  ๋ช…๋ น์„ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ๋Š” ๊ฒƒ์€ ์•„๋‹˜, ์‚ฌ์šฉ์ž์— ๋”ฐ๋ผ ํŠน์ • ์ œํ•œ์ด ์žˆ์„ ์ˆ˜ ์ž‡์Œ but user<RID>์— ๋Œ€ํ•œ ์ฟผ๋ฆฌ๋Š” ๋Œ€๋ถ€๋ถ„ RID๋ฅผ ๊ธฐ๋ฐ˜์œผ๋กœ ํ—ˆ์šฉ๋˜๋ฏ€๋กœ rcpclient๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ๋ฌด์ฐจ๋ณ„ ๋Œ€์ž…์„ ํ†ตํ•ด ์ •๋ณด๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ์Œ.

    • ์ด๋ฅผ ์‚ฌ์šฉํ•˜๊ธฐ ์œ„ํ•œ ๋„๊ตฌ๋Š” ์—ฌ๋Ÿฌ๊ฐ€์ง€๊ฐ€ ์กด์žฌ, ์ด๋Ÿฐ ๋„๊ตฌ๋ฅผ ๊ณ„์† ์‚ฌ์šฉํ•˜๋ ค๋ฉด bash๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ for ๋ฃจํ”„๋ฅผ ๋งŒ๋“ค์–ด์„œ rcpclient๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ ์„œ๋น„์Šค์— ๋ช…๋ น์„ ์ „์†กํ•˜๊ณ  ๊ฒฐ๊ณผ๋ฅผ ํ•„ํ„ฐ๋งํ•  ์ˆ˜ ์žˆ์Œ

๋ฌด์ฐจ๋ณ„ ์‚ฌ์šฉ์ž RID ๊ฐ•์ œ ์ ์šฉ

์ด์— ๋Œ€ํ•œ ๋Œ€์•ˆ์œผ๋กœ samrdump.pyarrow-up-right๋ฅผ ์‚ฌ์šฉํ•  ์ˆ˜ ์žˆ์Œ

Samrdump.py

  • rpcclient๋กœ ์–ป์€ ์ •๋ณด๋Š” SMBMap ํ˜น์€ CrackMapExec ๋„๊ตฌ๋กœ๋„ ์–ป์„ ์ˆ˜ ์žˆ์Œ

SMBmap

CrackMapExec

  • ๋˜ ๋‹ค๋ฅธ ๋„๊ตฌ๋กœ๋Š” enum4linux-ng๊ฐ€ ์žˆ์Œ. ์ด ๋„๊ตฌ๋Š” ์ „๋ถ€๋Š” ์•„๋‹ˆ์ง€๋งŒ ๋งŽ์€ ์ฟผ๋ฆฌ๋ฅผ ์ž๋™ํ™”ํ•˜๋ฉฐ ๋งŽ์€ ์–‘์˜ ์ •๋ณด๋ฅผ ๋ฐ˜ํ™˜ํ•  ์ˆ˜ ์žˆ์Œ

Enum4Linux-ng-์—ด๊ฑฐํ˜•

  • ์—ด๊ฑฐ๋ฅผ ์œ„ํ•ด ๋‘ ๊ฐœ ์ด์ƒ์˜ ๋„๊ตฌ๋ฅผ ์‚ฌ์šฉํ•ด์•ผ ํ•จ. ๋„๊ตฌ์˜ ํ”„๋กœ๊ทธ๋ž˜๋ฐ์œผ๋กœ ์ธํ•ด ์ˆ˜๋™์œผ๋กœ ํ™•์ธํ•ด์•ผ ํ•˜๋Š” ๋‹ค๋ฅธ ์ •๋ณด๋ฅผ ์–ป์„ ์ˆ˜ ์žˆ๊ธฐ ๋•Œ๋ฌธ -> ๋”ฐ๋ผ์„œ ๋„๊ตฌ๊ฐ€ ์–ด๋–ป๊ฒŒ ์ž‘์„ฑ๋˜์—ˆ๋Š”์ง€ ์ •ํ™•ํžˆ ์•Œ ์ˆ˜ ์—†๋Š” ์ž๋™ํ™”๋œ ๋„๊ตฌ(autorecon ๊ฐ™์€)์—๋งŒ ์˜์กดํ•ด์„  ์•ˆ๋จ

Last updated