기본 콘텐츠로 건너뛰기

패스워드 크래킹 smbexec 정리

smbexec 툴소개


Smbexec는 hash 또는 일반 평문 텍스트 패스워드가 있는 윈도우 시스템을 exploit 할 수 있는 툴로 타겟 머신에 backdoor를 만들어 업로드하여 쉘을 따낼 수 있는 툴이다. 실제 Anti-Virus(V3와 같은 백신 툴)에 걸릴 위험도 적다.


Smbexec is a pass the hash tool if you have the hash or plain text password so you can exploit the windows system using this tool. This tool will generate a backdoor and uploading on a victim machine and running it so other side you will get the meterpreter shell. Av Detection chances are low.


참조링크




smbexec 설치


설치환경 : Kali Linux



# cd /opt
# git clone https://github.com/brav0hax/smbexec.git
# cd smbexec
# ./install.sh

************************************************************

                    smbexec installer       
        A rapid psexec style attack with samba tools              
      Original Concept and Script by Brav0Hax & Purehate    
                    PurpleTeam Smash!
************************************************************

Please choose your OS to install smbexec

1.  Debian/Ubuntu and derivatives
2.  Red Hat or Fedora
3.  Microsoft Windows
4.  Compile smbexec binaries
5.  Exit
Choice: 1
...
...
Making all in msvscpp
make[1]: Entering directory `/tmp/smbexec-inst/libesedb-20120102/msvscpp'
make[1]: Nothing to be done for `all'.
make[1]: Leaving directory `/tmp/smbexec-inst/libesedb-20120102/msvscpp'
make[1]: Entering directory `/tmp/smbexec-inst/libesedb-20120102'
make[1]: Nothing to be done for `all-am'.
make[1]: Leaving directory `/tmp/smbexec-inst/libesedb-20120102'

[+] esedbtools have been installed...

[+] I found nmap installed on your system
[+] I found metasploit installed on your system
[*] Running 'updatedb' again because we installed some new stuff


...happy hunting!      // 설치가 완료되면 "즐겁게 사냥" 하라고 나온다. ;)




설치가 완료되면 /opt 디렉토리 밑에 아래와 같이 4개의 폴더가 생성되 있음을 알 수 있다.


root@kali:/opt# ll
total 36
drwxr-xr-x  9 root root 4096 Oct 16 16:34 .
drwxr-xr-x 23 root root 4096 Oct 16 15:39 ..
drwxr-xr-x  3 root root 4096 Oct 16 16:33 creddump
drwxrwxr-x  4  500  500 4096 Oct 16 16:34 esedbtools
drwxr-xr-x  3 root root 4096 Oct 14 11:11 firmware-mod-kit
drwxr-xr-x  6 root root 4096 Oct 14 13:07 metasploit
drwxr-xr-x  4 root root 4096 Dec 14  2011 NTDSXtract
drwxr-xr-x  6 root root 4096 Oct 16 16:15 smbexec
drwxr-xr-x  7 root root 4096 Oct 14 11:10 Teeth


윈도우용 바이너리 파일 컴파일


smbexec 바이너리 컴파일을 한다. ./install.sh를 다시 실행하여 해당 메뉴를 선택하고엔터.



Please choose your OS to install smbexec
1.  Debian/Ubuntu and derivatives
2.  Red Hat or Fedora
3.  Microsoft Windows
4.  Compile smbexec binaries
5.  Exit

Choice: 4


This script will compile your smbexec binaries


Press any key to continue
...
...
Compiling ../nsswitch/winbind_nss_linux.c
Linking bin/shared/libnss_winbind.so
Linking bin/shared/libsamba-hostconfig.so.0.0.1

[+] smbwinexe has been compiled and moved to the progs folder...


************************************************************

                    smbexec installer       
        A rapid psexec style attack with samba tools              
      Original Concept and Script by Brav0Hax & Purehate    
                    PurpleTeam Smash!
************************************************************

Please choose your OS to install smbexec

1.  Debian/Ubuntu and derivatives
2.  Red Hat or Fedora
3.  Microsoft Windows
4.  Compile smbexec binaries

5.  Exit


컴파일이 완료되면 progs 폴더로 이동하라라고 나온다. 디렉토리를 확인해보면 아래와 같이 컴파일된 파일들을 볼 수 있다.


root@kali:/opt/smbexec/progs# ll
drwxr-xr-x 2 root root     4096 Oct 16 17:01 .
drwxr-xr-x 6 root root     4096 Oct 16 16:15 ..
-rwxr-xr-x 1 root root    27858 Oct 16 16:15 cachedump.rb
-rwxr-xr-x 1 root root     1648 Oct 16 16:15 ntdspwdump.py
-rwxr-xr-x 1 root root  6656780 Oct 16 16:54 smbexeclient
-rwxr-xr-x 1 root root 10031583 Oct 16 16:58 smbwinexe
-rwxr-xr-x 1 root root   691199 Oct 16 16:15 wce.exe


smbexec를 이용한 윈도우 해킹

smbexec를 이용한 윈도우 시스템을 해킹하기 전에 먼저 윈도우 SMB 해킹부터 해야 한다.

BT5 또는 Kali에 이러한 툴이 있다. 

acccheck 툴 사용
acccheck 툴은 SMB 프토로콜을 이용하여 타겟 윈도우 시스템에 인증을 받기 위한 패스워드 사전공격 툴로 고안되어졌다.

아래 내용을 보자.


root@kali:/usr/share/doc/acccheck# more README.TXT 
acccheck.pl - Windows SMB Password Dictionary Attack Tool
Copyright (C) 2008 Faisal Dean (Faiz)

The tool is designed as a password dictionary attack tool that targets windows authentication via the SMB protocol. It is really a wrapper script around the 'smbclient' binary, and as a result is dependent on it for its execution.

The simplest way to run the tool is as follows:

./acccheck.pl -t 10.10.10.1

This mode of execution attempts to connect to the target ADMIN$ share with the username 'Administrator' and a [BLANK] for the password.

./acccheck.pl -t 10.10.10.1 -u test -p test

This mode of execution attempts to connect to the target IPC$ share with the username 'test' and a password 'test'.

Each -t, -u and -p flags can be substituted by -T, -U and -P, where each represents an input file rather than a single input from standard in.

E.g.
./acccheck.pl -T iplist -U userfile -P passwordfile

Only use -v mode on very small dictionaries, otherwise, this has the affect of slowing the scan down to the rate the system writes to standard out.

Any username/password combinations found are written to a file called 'cracked' in the working directory.

Any comments can be emailed to me at:

fmd@portcullis-security.com








smb 접속 방어
http://computer-forensics.sans.org/blog/2012/03/21/protecting-privileged-domain-accounts-access-tokens

댓글

이 블로그의 인기 게시물

보안 공부 링크

SSLsplit - SSL/TLS기반의 네트워크 포렌식 및 침투테스트(중간자공격) 도구 http://www.roe.ch/SSLsplit 가상화 서버운영 및 구축을 위한 Xenserver가 오픈소스로 공개 http://www.xenserver.org/ Python과 Fabric를 사용한 SSH 봇넷 C&C 구축 예제 http://raidersec.blogspot.kr/2013/07/building-ssh-botnet-c-using-python-and.html 파워쉘을 이용한 비밀번호 정보 획득 http://www.obscuresecurity.blogspot.kr/2013/07/get-gpppassword.html niktoHelper - Nmap의 Grepable형식을 Nikito와 연동하기 위한 파이썬 스크립트 http://milo2012.wordpress.com/2013/07/07/niktohelper-bridge-between-nmap-grepable-output-and-nikto/ 루비를 통한 심도있는 XSS 방어 방법 http://homakov.blogspot.com.es/2013/07/xss-defense-in-depth-with-rackrails-demo.html IT관련 E-Book 모음 http://www.cyberhades.com/2013/07/04/unos-libritos-tecnicos-para-el-veranito JJEncode 스크립트 분석 http://www.kahusecurity.com/2013/jjencode-script-leads-to-drive-by/ 웹브라우저 호환성 검증 및 분석결과 제공 http://www.modern.ie/ko-kr/ http://browsershots.org/ html 색상 선택 도구 https://kuler.adobe.com/create/color-wheel/ Windows 메모리 보호 메커니즘 http://resources.infosecinstitute.com/window...

dns2proxy 해킹툴

dns2proxy Offensive DNS server This tools offer a different features for post-explotation once you change the DNS server to a Victim. <Referer to help (-h) to new params options> Feature 1 Traditional DNS Spoof adding to the response the original IP address. Using spoof.cfg file: hostname ip.ip.ip.ip root@kali:~/dns2proxy# echo " www.s21sec.com  1.1.1.1" > spoof.cfg // launch in another terminal dns2proxy.py root@kali:~/dns2proxy# nslookup  www.s21sec.com  127.0.0.1 Server: 127.0.0.1 Address: 127.0.0.1#53 Name:  www.s21sec.com Address: 1.1.1.1 Name:  www.s21sec.com Address: 88.84.64.30 or you can use domains.cfg file to spoof all host of a same domain: root@kali:~/demoBH/dns2proxy# cat dominios.cfg .domain.com 192.168.1.1 root@kali:~/demoBH/dns2proxy# nslookup aaaa.domain.com 127.0.0.1 Server: 127.0.0.1 Address: 127.0.0.1#53 Name: aaaa.domain.com Address: 192.168.1.1 Hostnames at nospoof.cfg will no be spoofed. Featu...

어셈블리어(Assembly) 기초

0x01.  어셈블리 언어란 ? &  배우는 목적 CPU  에는 해당 프로세서에 명령을 내리기 위해 고유의 명령어 세트가 마련되어 있는데 이  명령어 세트를 기계어라고 한다 .  이 기계어는 숫자들의 규칙조합임으로 프로그래밍에 상당 히 난해하다 .  그래서 이 기계 명령어를 좀더 이해하기 쉬운 기호 코드로 나타낸것 ( 기계어와  1:1 로 대응된 명령을 기술하는 언어 ) 이 어셈블리어이다 .  어셈블리 언어는 그 코드가 어떤  일을 할지를 추상적이 아닌 ,  직접적으로 보여준다 .  논리상의 오류나 ,  수행 속도 ,  수행 과정 에 대해 명확히 해준다는 점에서 직관적인 언어이다 .  어셈블리 언어를 사용하면 메모리에 대한 이해도도 높아진다 .  어셈블리를 익히고 ,  배우는데 있어서는 여러 가지 목적이 있을 수 있다 .  컴퓨터 시스템 & 구조를 좀 더 깊게 이해하고 ,  메모리상의 데이터나  I/O 기기를 직접 액 세스 하는등의 고급언어에서는 할 수 없는 조작을위해서이다 .  프로그램의 최적화 및 리버 스 엔지니어링을 위해서도 필요하다 . + 2 줄 요약  + -  어셈블리 언어는 기계어와  1:1  대응을 하는 언어이다 . -  어셈블리 언어를 배우면 시스템을 이해하는데 도움이 된다 . 0x02.  어셈블리를 위한 기본 지식 (1)  기본적인 하드웨어 1) CPU -  메모리에 있는 내용을 읽고 ,  쓰고 데이터를 메모리와 각 레지스터로 보낸다 . 프로그램의 명령을 해석하고 실행한다 . 하나의 프로세서는  12~14 개의 레지스터를 가 지고 있으며 , CPU 의 연산 ,  논리 장치는 숫자와 기호에 관한 연산자를...