ืคืึทืจื‘ืึธืจื’ืŸ ืคึผืึทืจืึธืœ ื›ืึทืงื™ื ื’ ืžื™ื˜ Smbexec

ืคืึทืจื‘ืึธืจื’ืŸ ืคึผืึทืจืึธืœ ื›ืึทืงื™ื ื’ ืžื™ื˜ Smbexec

ืžื™ืจ ืฉืจื™ื™ึทื‘ืŸ ืงืขืกื™ื™ื“ืขืจ ื•ื•ืขื’ืŸ ื•ื•ื™ ื›ืึทืงืขืจื– ืึธืคื˜ ืคืึทืจืœืึธื–ื  ืื•ื™ืฃ ืขืงืกืคึผืœื•ื™ื˜ื™ื ื’ ื›ืึทืงื™ื ื’ ืžืขื˜ื”ืึธื“ืก ืึธืŸ ื‘ื™ื™ื–ืข ืงืึธื“ืฆื• ื•ื™ืกืžื™ื™ื“ืŸ ื“ื™ื˜ืขืงืฉืึทืŸ. ื–ื™ื™ ื–ืขื ืขืŸ ืžืžืฉ "ืœืขื‘ืŸ ืื•ื™ืฃ ืคึผืึทืกื˜ืฉืขืจ", ื ื™ืฆืŸ ื ืึธืจืžืึทืœ Windows ืžื›ืฉื™ืจื™ื, ื“ืขืจืžื™ื˜ ื‘ื™ื™ืคึผืึทืกื™ื ื’ ืึทื ื˜ื™ื•ื•ื™ืจื•ืก ืื•ืŸ ืื ื“ืขืจืข ื™ื•ื˜ื™ืœืึทื˜ื™ื– ืคึฟืึทืจ ื“ื™ื˜ืขืงื˜ื™ื ื’ ื‘ื™ื™ื–ืข ื˜ืขื˜ื™ืงื™ื™ื˜. ืžื™ืจ, ื•ื•ื™ ื“ื™ืคืขื ื“ืขืจื–, ื–ืขื ืขืŸ ืื™ืฆื˜ ื’ืขืฆื•ื•ื•ื ื’ืขืŸ ืฆื• ื”ืึทื ื“ืœืขืŸ ืžื™ื˜ ื“ื™ ื ืขื‘ืขืš ืงืึทื ืกืึทืงื•ื•ืขื ืกืึทื– ืคื•ืŸ ืึทื–ืึท ืงืœื•ื’ ื›ืึทืงื™ื ื’ ื˜ืขืงื ื™ืงืก: ืึท ื’ืขื–ื•ื ื˜-ื’ืขืฉื˜ืขืœื˜ ืึธื ื’ืขืฉื˜ืขืœื˜ืขืจ ืงืขื ืขืŸ ื ื•ืฆืŸ ื“ื™ ื–ืขืœื‘ืข ืฆื•ื’ืึทื ื’ ืฆื• ื’ืขื”ื™ื™ื ื’ืึทื ื•ื•ืขื ืขืŸ ื“ืึทื˜ืŸ (ืคึฟื™ืจืžืข ืื™ื ื˜ืขืœืขืงื˜ื•ืึทืœ ืคืึทืจืžืึธื’, ืงืจืขื“ื™ื˜ ืงืึทืจื˜ืœ ื ื•ืžืขืจืŸ). ืื•ืŸ ืื•ื™ื‘ ืขืจ ื•ื•ืขื˜ ื ื™ืฉื˜ ืงืึทืžื™ืฉ, ืึธื‘ืขืจ ืึทืจื‘ืขื˜ ืคึผืึทืžืขืœืขืš ืื•ืŸ ืฉื˜ื™ืœ, ืขืก ื•ื•ืขื˜ ื–ื™ื™ืŸ ื’ืึธืจ ืฉื•ื•ืขืจ - ืึธื‘ืขืจ ื ืึธืš ืžืขื’ืœืขืš ืื•ื™ื‘ ืขืจ ื ื™ืฆื˜ ื“ื™ ืจืขื›ื˜ ืฆื•ื’ืึทื ื’ ืื•ืŸ ื“ื™ ืฆื•ื ืขืžืขืŸ ืžื›ืฉื™ืจื™ื, โ€” ืฆื• ืื™ื“ืขื ื˜ื™ืคื™ืฆื™ืจืŸ ืื–ื ื˜ืขื˜ื™ืงืฒื˜.

ืื•ื™ืฃ ื“ื™ ืื ื“ืขืจืข ื”ืึทื ื˜, ืื™ืš ื•ื•ืึธืœื˜ ื ื™ืฉื˜ ื•ื•ืขืœืŸ ืฆื• ื“ืขืžืึธื ื™ื–ื™ืจืŸ ืขืžืคึผืœื•ื™ื™ื– ื•ื•ื™ื™ึทืœ ืงื™ื™ืŸ ืื™ื™ื ืขืจ ื•ื•ื™ืœ ืฆื• ืึทืจื‘ืขื˜ืŸ ืื™ืŸ ืึท ื’ืขืฉืขืคื˜ ืกื•ื•ื™ื•ื•ืข ื’ืœื™ื™ืš ืคึฟื•ืŸ ืึธืจื•ื•ืขืœ ืก 1984. ืฆื•ืž ื’ืœื™ืง, ืขืก ื–ืขื ืขืŸ ืึท ื ื•ืžืขืจ ืคื•ืŸ ืคึผืจืึทืงื˜ื™ืฉ ืกื˜ืขืคึผืก ืื•ืŸ ืœืขื‘ืŸ ื›ืึทืงืก ื•ื•ืึธืก ืงืขื ืขืŸ ืžืึทื›ืŸ ืœืขื‘ืŸ ืคื™ืœ ืžืขืจ ืฉื•ื•ืขืจ ืคึฟืึทืจ ื™ื ืกื™ื“ืขืจื–. ืžื™ืจ ื•ื•ืขืœืŸ ื‘ืึทื˜ืจืึทื›ื˜ืŸ ื’ืขื”ื™ื™ื ื‘ืึทืคืึทืœืŸ ืžืขื˜ื”ืึธื“ืก, ื’ืขื ื™ืฆื˜ ื“ื•ืจืš ื›ืึทืงืขืจื– ื“ื•ืจืš ืขืžืคึผืœื•ื™ื™ื– ืžื™ื˜ ืขื˜ืœืขื›ืข ื˜ืขื›ื ื™ืฉ ื”ื™ื ื˜ืขืจื’ืจื•ื ื˜. ืื•ืŸ ืึท ื‘ื™ืกืœ ื•ื•ื™ื™ึทื˜ืขืจ ืžื™ืจ ื•ื•ืขืœืŸ ื“ื™ืกืงื•ื˜ื™ืจืŸ ืึธืคึผืฆื™ืขืก ืคึฟืึทืจ ืจื™ื“ื•ืกื™ื ื’ ืึทื–ืึท ืจื™ืกืงืก - ืžื™ืจ ื•ื•ืขืœืŸ ืœืขืจื ืขืŸ ื‘ื™ื™ื“ืข ื˜ืขื›ื ื™ืฉ ืื•ืŸ ืึธืจื’ืึทื ืึทื–ื™ื™ืฉืึทื ืึทืœ ืึธืคึผืฆื™ืขืก.

ื•ื•ืึธืก ืื™ื– ืคืึทืœืฉ ืžื™ื˜ PsExec?

ืขื“ื•ื•ืึทืจื“ ืกื ืึธื•ื•ื“ืขืŸ, ืจืขื›ื˜ ืึธื“ืขืจ ืจืึธื ื’ืœื™, ืื™ื– ื’ืขื•ื•ืืจืŸ ืกืึทื ืึทื ืึทืžืึทืก ืžื™ื˜ ื™ื ืกื™ื™ื“ืขืจ ื“ืึทื˜ืŸ ื’ื ื™ื™ื•ื•ืข. ื“ื•ืจืš ื“ืขื ื•ื•ืขื’, ื˜ืึธืŸ ื ื™ื˜ ืคืึทืจื’ืขืกืŸ ืฆื• ื ืขืžืขืŸ ืึท ืงื•ืง ืื™ืŸ ื“ืขื ืฆืขื˜ืœ ื•ื•ืขื’ืŸ ืื ื“ืขืจืข ื™ื ืกื™ื“ืขืจื– ื•ื•ืึธืก ืื•ื™ืš ืคืึทืจื“ื™ื ืขืŸ ืขื˜ืœืขื›ืข ืจื•ื ืกื˜ืึทื˜ื•ืก. ืื™ื™ืŸ ื•ื•ื™ื›ื˜ื™ืง ืคื•ื ื˜ ื•ื•ืึธืก ืื™ื– ื•ื•ืขืจื˜ ืื•ื ื˜ืขืจืฉื˜ืจื™ื™ื›ืŸ ื•ื•ืขื’ืŸ ื“ื™ ืžืขื˜ื”ืึธื“ืก ื•ื•ืึธืก Snowden ื’ืขื•ื•ื™ื™ื ื˜ ืื™ื– ืึทื–, ืœื•ื™ื˜ ืื•ื ื“ื–ืขืจ ื‘ืขืกื˜ืขืจ ื•ื•ื™ืกืŸ, ืขืจ ื”ืื˜ ื ื™ืฉื˜ ืื™ื ืกื˜ืึทืœื™ืจืŸ ืงื™ื™ืŸ ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ื‘ื™ื™ื–ืข ื•ื•ื™ื™ื›ื•ื•ืืจื’!

ืึทื ืฉื˜ืึธื˜, Snowden ื’ืขื•ื•ื™ื™ื ื˜ ืึท ื‘ื™ืกืœ ืคื•ืŸ ื’ืขื–ืขืœืฉืึทืคื˜ืœืขืš ื™ื ื–ืฉืขื ื™ืขืจื™ืข ืื•ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ื–ื™ื™ืŸ ืฉื˜ืขืœืข ื•ื•ื™ ืึท ืกื™ืกื˜ืขื ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจ ืฆื• ื–ืึทืžืœืขืŸ ืคึผืึทืกื•ื•ืขืจื“ื– ืื•ืŸ ืฉืึทืคึฟืŸ ืงืจืึทื“ืขื ื˜ืฉืึทืœื–. ื’ืึธืจื ื™ืฉื˜ ืงืึธืžืคึผืœื™ืฆื™ืจื˜ - ื’ืึธืจื ื™ื˜ ืžื™ืžื™ืงืื˜ื–, ืื ืคืืœืŸ ืžืขื ื˜ืฉ-ืื™ืŸ-ื“ืขื-ืžื™ื˜ืŸ ืึธื“ืขืจ ืžืขื˜ืึทืกืคึผืœืึธื™ื˜.

ืึธืจื’ืึทื ืึทื–ื™ื™ืฉืึทื ืึทืœ ืขืžืคึผืœื•ื™ื™ื– ื–ืขื ืขืŸ ื ื™ืฉื˜ ืฉื˜ืขื ื“ื™ืง ืื™ืŸ ืกื ืึธื•ื•ื“ืขืŸ ืก ื™ื™ื ืฆื™ืง ืฉื˜ืขืœืข, ืึธื‘ืขืจ ืขืก ื–ืขื ืขืŸ ืึท ื ื•ืžืขืจ ืคื•ืŸ ืœืขืงืฆื™ืขืก ืฆื• ื–ื™ื™ืŸ ื’ืขืœืขืจื ื˜ ืคื•ืŸ ื“ืขื ื‘ืึทื’ืจื™ืฃ ืคื•ืŸ "ื ื™ืฆื•ืœ ื“ื•ืจืš ื’ืจื™ื™ื–ื™ื ื’" ืฆื• ื–ื™ื™ืŸ ืึทื•ื•ืขืจ ืคื•ืŸ - ื ื™ืฉื˜ ืฆื• ืึธื ื˜ื™ื™ืœ ื ืขืžืขืŸ ืื™ืŸ ืงื™ื™ืŸ ื‘ื™ื™ื–ืข ื˜ืขื˜ื™ืงื™ื™ื˜ ื•ื•ืึธืก ืงืขื ืขืŸ ื–ื™ื™ืŸ ื“ื™ื˜ืขืงื˜ืึทื“, ืื•ืŸ ืฆื• ื–ื™ื™ืŸ ืกืคึผืขืฆื™ืขืœ ืึธืคึผื’ืขื”ื™ื˜ ืžื™ื˜ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ืงืจืึทื“ืขื ื˜ืฉืึทืœื–. ื’ืขื“ืขื ืงื˜ ื“ืขื ื’ืขื“ืึทื ืง.

ืคึผืกืขืงืกืขืง ืื•ืŸ ื–ื™ื™ืŸ ืงื•ื–ื™ืŸ ืงืจืึทืงืžืึทืคึผืขืงืกืขืง ื”ืึธื‘ืŸ ื™ืžืคึผืจืขืกื˜ ืงืึทื•ื ื˜ืœืึทืก ืคึผืขื ื˜ืขืกื˜ืขืจืก, ื›ืึทืงืขืจื– ืื•ืŸ ืกื™ื™ื‘ืขืจืกืขืงื•ืจื™ื˜ื™ ื‘ืœืึธื’ื’ืขืจืก. ืื•ืŸ ื•ื•ืขืŸ ืงืึทืžื‘ื™ื™ื ื“ ืžื™ื˜ ืžื™ืžื™ืงืึทื˜ื–, ืคึผืกืขืงืกืขืง ืึทืœืึทื•ื– ืึทื˜ืึทืงืขืจื– ืฆื• ืจื™ืจืŸ ืื™ืŸ ืึท ื ืขืฅ ืึธืŸ ื“ืึทืจืคึฟืŸ ืฆื• ื•ื•ื™ืกืŸ ื“ื™ ืงืœืึธืจ ื˜ืขืงืกื˜ ืคึผืึทืจืึธืœ.

ืžื™ืžื™ืงืึทืฅ ื™ื ื˜ืขืจืกืขืคึผื˜ ื“ื™ NTLM ื”ืึทืฉ ืคื•ืŸ ื“ื™ LSASS ืคึผืจืึธืฆืขืก ืื•ืŸ ื“ืขืจื ืึธืš ืคืึธืจืŸ ื“ื™ ื˜ืึธืงืขืŸ ืึธื“ืขืจ ืงืจืึทื“ืขื ื˜ืฉืึทืœื– - ื“ื™ ืึทื–ื•ื™ ื’ืขืจื•ืคืขื ืข. "ืคืึธืจืŸ ื“ื™ ื”ืึทืฉ" ื‘ืึทืคืึทืœืŸ - ืื™ืŸ ืคึผืกืขืงืกืขืง, ืึทืœืึทื•ื™ื ื’ ืึท ืึทื˜ืึทืงืขืจ ืฆื• ืงืœืึธืฅ ืื™ืŸ ืืŸ ืื ื“ืขืจ ืกืขืจื•ื•ืขืจ ื•ื•ื™ ืคื•ืŸ ืื ื“ืขืจืŸ ื‘ืึทื ื™ืฆืขืจ. ืื•ืŸ ืžื™ื˜ ื™ืขื“ืขืจ ืกืึทื‘ืกืึทืงื•ื•ืึทื ื˜ ืžืึทืš ืฆื• ืึท ื ื™ื™ึท ืกืขืจื•ื•ืขืจ, ื“ื™ ืึทื˜ืึทืงืขืจ ืงืึทืœืขืงืฅ ื ืึธืš ืงืจืึทื“ืขื ื˜ืฉืึทืœื–, ื™ืงืกืคึผืึทื ื“ื™ื“ ื“ื™ ืงื™ื™ื˜ ืคื•ืŸ ื–ื™ื™ึทืŸ ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื– ืื™ืŸ ื–ื•ื›ืŸ ืคึฟืึทืจ ื‘ื ื™ืžืฆื ืื™ื ื”ืึทืœื˜.

ื•ื•ืขืŸ ืื™ืš ืขืจืฉื˜ืขืจ ืกื˜ืึทืจื˜ืขื“ ืืจื‘ืขื˜ืŸ ืžื™ื˜ ืคึผืกืขืงืกืขืง, ืขืก ื’ืขื•ื•ืขืŸ ืžืึทื“ื–ืฉื™ืงืึทืœ ืฆื• ืžื™ืจ - ื“ืึทื ืงืขืŸ ื“ื™ืจ ืžืืจืง ืจื•ืกืกื™ื ืื•ื•ื™ื˜ืฉ, ื“ื™ ื‘ืจื™ืœื™ืึทื ื˜ ื“ืขื•ื•ืขืœืึธืคึผืขืจ ืคื•ืŸ ืคึผืกืขืงืกืขืง - ืึธื‘ืขืจ ืื™ืš ืื•ื™ืš ื•ื•ื™ืกืŸ ื•ื•ืขื’ืŸ ื–ื™ื™ืŸ ื˜ื•ืžืœื“ื™ืง ืงืึทืžืคึผืึธื•ื ืึทื ืฅ. ืขืจ ืื™ื– ืงื™ื™ื ืžืึธืœ ืกื•ื“!

ื“ืขืจ ืขืจืฉื˜ืขืจ ื˜ืฉื™ืงืึทื•ื•ืข ืคืึทืงื˜ ื•ื•ืขื’ืŸ ืคึผืกืขืงืกืขืง ืื™ื– ืึทื– ืขืก ื ื™ืฆื˜ ื’ืึธืจ ืงืึธืžืคึผืœืขืงืก ืกืžื‘ ื ืขืฅ ื˜ืขืงืข ืคึผืจืึธื˜ืึธืงืึธืœ ืคึฟื•ืŸ ืžื™ื™ืงืจืึธืกืึธืคึฟื˜. ื ื™ืฆืŸ SMB, ืคึผืกืขืงืกืขืง ื˜ืจืึทื ืกืคืขืจืก ืงืœื™ื™ืŸ ื‘ื™ื™ื ืขืจื™ ื˜ืขืงืขืก ืฆื• ื“ื™ ืฆื™ืœ ืกื™ืกื˜ืขื, ืคึผืœื™ื™ืกื™ื ื’ ื–ื™ื™ ืื™ืŸ ื“ื™ C: Windows ื˜ืขืงืข.

ื“ืขืจื ืึธืš, ืคึผืกืขืงืกืขืง ืงืจื™ื™ื™ืฅ ืึท Windows ื“ื™ื ืกื˜ ื ื™ืฆืŸ ื“ื™ ืงืึทืคึผื™ื“ ื‘ื™ื™ื ืขืจื™ ืื•ืŸ ืœื•ื™ืคื˜ ืขืก ืื•ื ื˜ืขืจ ื“ื™ ื’ืึธืจ "ืื•ืžื’ืขืจื™ื›ื˜" ื ืึธืžืขืŸ PSEXECSVC. ืื™ืŸ ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืฆื™ื™ื˜, ืื™ืจ ืงืขื ืขืŸ ืึทืงื˜ืฉืึทื•ื•ืึทืœื™ ื–ืขืŸ ืึทืœืข ื“ืขื, ื•ื•ื™ ืื™ืš ื”ืึธื‘, ื“ื•ืจืš ื•ื•ืึทื˜ืฉื™ื ื’ ืึท ื•ื•ื™ื™ึทื˜ ืžืึทืฉื™ืŸ (ื–ืขืŸ ื•ื•ื™ื™ื˜ืขืจ).

ืคืึทืจื‘ืึธืจื’ืŸ ืคึผืึทืจืึธืœ ื›ืึทืงื™ื ื’ ืžื™ื˜ Smbexec

Psexec ืก ืคืึทืš ืงืึธืจื˜: "PSEXECSVC" ื“ื™ื ืกื˜. ืขืก ืœื•ื™ืคื˜ ืึท ื‘ื™ื™ื ืขืจื™ ื˜ืขืงืข ื•ื•ืึธืก ืื™ื– ื’ืขืฉื˜ืขืœื˜ ื“ื•ืจืš SMB ืื™ืŸ ื“ื™ C: Windows ื˜ืขืงืข.

ื•ื•ื™ ืึท ืœืขืฆื˜ ืฉืจื™ื˜, ื“ื™ ืงืึทืคึผื™ื“ ื‘ื™ื™ื ืขืจื™ ื˜ืขืงืข ืึธืคึผืขื ืก RPC ืงืฉืจ ืฆื• ื“ื™ ืฆื™ืœ ืกืขืจื•ื•ืขืจ ืื•ืŸ ืึทืงืกืขืคึผืฅ ืงืึธื ื˜ืจืึธืœ ืงืึทืžืึทื ื“ื– (ื“ื•ืจืš ื“ื™ Windows cmd ืฉืึธืœ ื“ื•ืจืš ืคืขืœื™ืงื™ื™ึทื˜), ืงืึทื˜ืขืจ ื–ื™ื™ ืื•ืŸ ืจื™ื“ืขืจืขืงื˜ื™ื ื’ ืึทืจื™ื™ึทื ืฉืจื™ื™ึทื‘ ืื•ืŸ ืจืขื–ื•ืœื˜ืึทื˜ ืฆื• ื“ื™ ืึทื˜ืึทืงืขืจ ืก ื”ื™ื™ื ืžืึทืฉื™ืŸ. ืื™ืŸ ื“ืขื ืคืึทืœ, ื“ื™ ืึทื˜ืึทืงืขืจ ื–ืขื˜ ื“ื™ ื™ืงืขืจื“ื™ืง ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื” - ื“ื™ ื–ืขืœื‘ืข ื•ื•ื™ ืื•ื™ื‘ ืขืจ ืื™ื– ื’ืขื•ื•ืขืŸ ืงืึธื ื ืขืงื˜ืขื“ ื’ืœื™ื™ึทืš.

ืคื™ืœืข ืงืึทืžืคึผืึธื•ื ืึทื ืฅ ืื•ืŸ ืึท ื–ื™ื™ืขืจ ื˜ื•ืžืœื“ื™ืง ืคึผืจืึธืฆืขืก!

ื“ื™ ืงืึธืžืคึผืœืขืงืก ื™ื ื˜ืขืจื ืึทืœืก ืคื•ืŸ ืคึผืกืขืงืกืขืง ื“ืขืจืงืœืขืจืŸ ื“ืขื ืึธื ื–ืึธื’ ื•ื•ืึธืก ืคึผืึทื–ืึทืœื“ ืžื™ืจ ื‘ืขืฉืึทืก ืžื™ื™ืŸ ืขืจืฉื˜ืขืจ ื˜ืขืกืฅ ืขื˜ืœืขื›ืข ื™ืึธืจ ืฆื•ืจื™ืง: "ืกื˜ืึทืจื˜ื™ื ื’ PSEXECSVC ..." ื ืื›ื’ืขื’ืื ื’ืขืŸ ื“ื•ืจืš ืึท ืคึผื•ื™ื–ืข ืื™ื™ื“ืขืจ ื“ื™ ื‘ืึทืคึฟืขืœ ืคึผื™ื ื˜ืœืขืš.

ืคืึทืจื‘ืึธืจื’ืŸ ืคึผืึทืจืึธืœ ื›ืึทืงื™ื ื’ ืžื™ื˜ Smbexec

Impacket's Psexec ืึทืงื˜ืฉืึทื•ื•ืึทืœื™ ื•ื•ื™ื™ึทื–ืŸ ื•ื•ืึธืก ืื™ื– ื’ืขืฉืขืขื ื™ืฉ ืื•ื ื˜ืขืจ ื“ื™ ืงืึทืคึผื˜ืขืจ.

ื ื™ื˜ ื—ื™ื“ื•ืฉ: ืคึผืกืขืงืกืขืง ื”ืื˜ ืึท ืจื™ื–ื™ืง ืกื•ืžืข ืคื•ืŸ โ€‹โ€‹ืึทืจื‘ืขื˜ ืื•ื ื˜ืขืจ ื“ื™ ืงืึทืคึผื˜ืขืจ. ืื•ื™ื‘ ืื™ืจ ื–ืขื ื˜ ืื™ื ื˜ืขืจืขืกื™ืจื˜ ืื™ืŸ ืึท ืžืขืจ ื“ื™ื˜ื™ื™ืœื“ ื“ืขืจืงืœืขืจื•ื ื’, ื˜ืฉืขืง ืื•ื™ืก ื“ืึธ ื“ื•ืจืš ื“ืขื ื•ื•ื•ื ื“ืขืจืœืขืš ื‘ืึทืฉืจื™ื™ึทื‘ื•ื ื’.

ื“ืึธืš, ื•ื•ืขืŸ ื’ืขื•ื•ื™ื™ื ื˜ ื•ื•ื™ ืึท ืกื™ืกื˜ืขื ืึทื“ืžื™ื ื™ืกื˜ืจืึทืฆื™ืข ื’ืขืฆื™ื™ึทื’, ื•ื•ืึธืก ืื™ื– ื’ืขื•ื•ืขืŸ ืึธืจื™ื’ื™ื ืขืœ ืฆื™ืœ ืคึผืกืขืงืกืขืง, ืขืก ืื™ื– ื’ืึธืจื ื™ืฉื˜ ืคืึทืœืฉ ืžื™ื˜ ื“ื™ "ื‘ืึทื–ื™ื ื’" ืคื•ืŸ ืึทืœืข ื“ื™ Windows ืžืขืงืึทื ื™ื–ืึทืžื–. ืคึฟืึทืจ ืึทืŸ ืึทื˜ืึทืงืขืจ, ืึธื‘ืขืจ, ืคึผืกืขืงืกืขืง ื•ื•ืึธืœื˜ ืžืึทื›ืŸ ืงืึทืžืคึผืœืึทืงื™ื™ืฉืึทื ื–, ืื•ืŸ ืคึฟืึทืจ ืึท ืึธืคึผื’ืขื”ื™ื˜ ืื•ืŸ ื›ื™ื˜ืจืข ื™ื ืกื™ื™ื“ืขืจ ื•ื•ื™ ืกื ืึธื•ื•ื“ืขืŸ, ืคึผืกืขืงืกืขืง ืึธื“ืขืจ ืึท ืขื ืœืขืš ื ื•ืฆืŸ ื•ื•ืึธืœื˜ ื–ื™ื™ืŸ ืฆื• ืคื™ืœ ืคื•ืŸ ืึท ืจื™ื–ื™ืงื™ืจืŸ.

ืื•ืŸ ื“ืขืจื ืึธืš ืงื•ืžื˜ ืกืžื‘ืขืงืกืขืง

SMB ืื™ื– ืึท ืงืœื•ื’ ืื•ืŸ ื’ืขื”ื™ื™ื ื•ื•ืขื’ ืฆื• ืึทืจื™ื‘ืขืจืคื™ืจืŸ ื˜ืขืงืขืก ืฆื•ื•ื™ืฉืŸ ืกืขืจื•ื•ืขืจืก, ืื•ืŸ ื›ืึทืงืขืจื– ื”ืึธื‘ืŸ ื™ื ืคื™ืœื˜ืจื™ื™ื˜ื™ื“ SMB ื’ืœื™ื™ึทืš ืคึฟืึทืจ ืกืขื ื˜ืฉืขืจื™ื–. ืื™ืš ื˜ืจืึทื›ื˜ืŸ ืึทืœืขืžืขืŸ ืฉื•ื™ืŸ ื•ื•ื™ืกืŸ ืึทื– ืขืก ืื™ื– ื ื™ืฉื˜ ื•ื•ืขืจื˜ ืขืก ืขืคืขื ืขืŸ ืกืžื‘ ืคึผืึธืจืฅ 445 ืื•ืŸ 139 ืฆื• ื“ื™ ืื™ื ื˜ืขืจื ืขื˜, ืจืขื›ื˜?

ืื™ืŸ Defcon 2013, Eric Millman (brav0hax) ื“ืขืจืœืื ื’ื˜ smbexec, ืึทื–ื•ื™ ืึทื– ืคึผืขื ื˜ืขืกื˜ืขืจืก ืงืขื ืขืŸ ืคึผืจื•ื‘ื™ืจืŸ ืกื˜ืขืœื˜ ืกืžื‘ ื›ืึทืงื™ื ื’. ืื™ืš ื•ื•ื™ื™ืก ื ื™ืฉื˜ ื“ื™ ื’ืื ืฆืข ืžืขืฉื”, ืื‘ืขืจ ื“ืืŸ ื”ืื˜ Impacket ื•ื•ื™ื™ื˜ืขืจ ืคืืจืคื™ื ืฆื˜ืขืจื˜ ืกืžื‘ืขืงืกืขืง. ืื™ืŸ ืคืึทืงื˜, ืคึฟืึทืจ ืžื™ื™ืŸ ื˜ืขืกื˜ื™ื ื’, ืื™ืš ื“ืึทื•ื ืœืึธื•ื“ื™ื“ ื“ื™ ืกืงืจื™ืคึผืก ืคึฟื•ืŸ Impacket ืื™ืŸ Python ืคึฟื•ืŸ ื’ื™ื˜ื”ื•ื‘.

ื ื™ื˜ ืขื ืœืขืš ืคึผืกืขืงืกืขืง, smbexec ืึทื•ื•ื•ื™ื“ื– ื˜ืจืึทื ืกืคืขืจื™ื ื’ ืึท ืคึผืึทื˜ืขื ื˜ืฉืึทืœื™ ื“ื™ื˜ืขืงื˜ืึทื“ ื‘ื™ื™ื ืขืจื™ ื˜ืขืงืข ืฆื• ื“ื™ ืฆื™ืœ ืžืึทืฉื™ืŸ. ืึทื ืฉื˜ืึธื˜, ื“ื™ ื ื•ืฆืŸ ืœืขื‘ืŸ ืœืขื’ืึทืžืจืข ืคื•ืŸ โ€‹โ€‹ืคึผืึทืกื˜ืฉืขืจ ืฆื• ืงืึทื˜ืขืจ ื”ื™ื’ืข Windows ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื”.

ื“ืึธ ืก ื•ื•ืึธืก ืขืก ื˜ื•ื˜: ืขืก ืคึผืึทืกื™ื– ืึท ื‘ืึทืคึฟืขืœ ืคื•ืŸ ื“ื™ ืึทื˜ืึทืงื™ื ื’ ืžืึทืฉื™ืŸ ื“ื•ืจืš SMB ืฆื• ืึท ืกืคึผืขืฆื™ืขืœ ืึทืจื™ื™ึทื ืฉืจื™ื™ึทื‘ ื˜ืขืงืข, ืื•ืŸ ื“ืขืžืึธืœื˜ ืงืจื™ื™ื™ืฅ ืื•ืŸ ืœื•ื™ืคื˜ ืึท ืงืึธืžืคึผืœืขืงืก ื‘ืึทืคึฟืขืœ ืฉื•ืจื” (ื•ื•ื™ ืึท Windows ื“ื™ื ืกื˜) ื•ื•ืึธืก ื•ื•ืขื˜ ื•ื™ืกืงื•ืžืขืŸ ื‘ืึทืงืึทื ื˜ ืคึฟืึทืจ ืœื™ื ื•ืงืก ื™ื•ื–ืขืจื–. ืื™ืŸ ืงื•ืจืฅ: ืขืก ืœืึธื ื˜ืฉื™ื– ืึท ื’ืขื‘ื•ื™ืจืŸ Windows cmd ืฉืึธืœ, ืจื™ื“ืขืจืขืงืฅ ื“ื™ ืจืขื–ื•ืœื˜ืึทื˜ ืฆื• ืืŸ ืื ื“ืขืจ ื˜ืขืงืข ืื•ืŸ ืกืขื ื“ื– ืขืก ื“ื•ืจืš SMB ืฆื•ืจื™ืง ืฆื• ื“ื™ ืึทื˜ืึทืงืขืจ ืก ืžืึทืฉื™ืŸ.

ื“ืขืจ ื‘ืขืกื˜ืขืจ ื•ื•ืขื’ ืฆื• ืคึฟืึทืจืฉื˜ื™ื™ืŸ ื“ืขื ืื™ื– ืฆื• ืงื•ืงืŸ ืื™ืŸ ื“ื™ ื‘ืึทืคึฟืขืœืŸ ืฉื•ืจื”, ื•ื•ืึธืก ืื™ืš ืื™ื– ื’ืขื•ื•ืขืŸ ื‘ื™ื›ื•ืœืช ืฆื• ื‘ืึทืงื•ืžืขืŸ ืžื™ื™ืŸ ื”ืขื ื˜ ืื•ื™ืฃ ืคึฟื•ืŸ ื“ื™ ื’ืขืฉืขืขื ื™ืฉ ืงืœืึธืฅ (ื–ืขืŸ ื•ื•ื™ื™ื˜ืขืจ).

ืคืึทืจื‘ืึธืจื’ืŸ ืคึผืึทืจืึธืœ ื›ืึทืงื™ื ื’ ืžื™ื˜ Smbexec

ืื™ื– ื“ืึธืก ื ื™ืฉื˜ ื“ืขืจ ื‘ืขืกื˜ืขืจ ื•ื•ืขื’ ืฆื• ืจื™ื“ืขืจืขืงื˜ I/O? ื“ื•ืจืš ื“ืขื ื•ื•ืขื’, ื“ื™ ืฉืึทืคื•ื ื’ ืคื•ืŸ ื“ื™ ืกืขืจื•ื•ื™ืก ื”ืื˜ ืึท ื’ืขืฉืขืขื ื™ืฉ ืฉื™ื™ึทืŸ 7045.

ื•ื•ื™ ืคึผืกืขืงืกืขืง, ืขืก ืื•ื™ืš ืงืจื™ื™ื™ืฅ ืึท ื“ื™ื ืกื˜ ื•ื•ืึธืก ื˜ื•ื˜ ืึทืœืข ื“ื™ ืึทืจื‘ืขื˜, ืึธื‘ืขืจ ื“ื™ ื“ื™ื ืกื˜ ื ืึธืš ืื•ื™ืกื’ืขืžืขืงื˜ - ืขืก ืื™ื– ื’ืขื ื™ืฆื˜ ื‘ืœื•ื™ื– ืึทืžืึธืœ ืฆื• ืœื•ื™ืคืŸ ื“ื™ ื‘ืึทืคึฟืขืœ ืื•ืŸ ื“ืขืžืึธืœื˜ ืคืืจืฉื•ื•ื™ื ื“ื˜! ืึทืŸ ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื–ื™ื›ืขืจื”ื™ื™ื˜ ืึธืคื™ืฆื™ืจ ืžืึธื ื™ื˜ืึธืจื™ื ื’ ื“ื™ ืžืึทืฉื™ืŸ ืคื•ืŸ ืึท ืงืึธืจื‘ืŸ ื•ื•ืขื˜ ื ื™ืฉื˜ ืงืขื ืขืŸ ืฆื• ื“ืขื˜ืขืงื˜ ืงืœืึธืจ ื•ื•ื™ ื“ืขืจ ื˜ืึธื’ ื™ื ื“ื™ืงืึทื˜ืึธืจืก ืคื•ืŸ ื‘ืึทืคืึทืœืŸ: ืขืก ืื™ื– ืงื™ื™ืŸ ื‘ื™ื™ื–ืข ื˜ืขืงืข ืื™ื– ืœืึธื ื˜ืฉื˜, ืงื™ื™ืŸ ืคึผืขืจืกื™ืกื˜ืขื ื˜ ื“ื™ื ืกื˜ ืื™ื– ืื™ื ืกื˜ืึทืœื™ืจืŸ, ืื•ืŸ ืขืก ืื™ื– ืงื™ื™ืŸ ื–ืึธื’ืŸ ืคื•ืŸ RPC ืื™ื– ื’ืขื ื™ืฆื˜ ื–ื™ื ื˜ SMB ืื™ื– ื“ืขืจ ื‘ืœื•ื™ื– ืžื™ื˜ืœ ืคื•ืŸ ื“ืึทื˜ืŸ ืึทืจื™ื‘ืขืจืคื™ืจืŸ. ื‘ืจื™ืœื™ืึทื ื˜!

ืคึฟื•ืŸ ื“ื™ ืึทื˜ืึทืงืขืจ ืก ื–ื™ื™ึทื˜, ืึท "ืคึผืกืขื•ื•ื“ืึธ-ืฉืึธืœ" ืื™ื– ื‘ื ื™ืžืฆื ืžื™ื˜ ื“ื™ืœื™ื™ื– ืฆื•ื•ื™ืฉืŸ ืฉื™ืงืŸ ื“ื™ ื‘ืึทืคึฟืขืœ ืื•ืŸ ื‘ืึทืงื•ืžืขืŸ ื“ื™ ืขื ื˜ืคืขืจ. ืึธื‘ืขืจ ื“ืึธืก ืื™ื– ื’ืึทื ืฅ ื’ืขื ื•ื’ ืคึฟืึทืจ ืึท ืึทื˜ืึทืงืขืจ - ืึธื“ืขืจ ืึทืŸ ื™ื ืกื™ื™ื“ืขืจ ืึธื“ืขืจ ืึท ืคื•ื ื“ืจื•ื™ืกื ื“ื™ืง ื”ืขืงืขืจ ื•ื•ืึธืก ื”ืื˜ ืฉื•ื™ืŸ ืึท ืคื•ื˜ื›ืึธื•ืœื“ - ืฆื• ืึธื ื”ื™ื™ื‘ืŸ ืงื•ืงืŸ ืคึฟืึทืจ ื˜ืฉื™ืงืึทื•ื•ืข ืื™ื ื”ืึทืœื˜.

ืคืึทืจื‘ืึธืจื’ืŸ ืคึผืึทืจืึธืœ ื›ืึทืงื™ื ื’ ืžื™ื˜ Smbexec

ืฆื• ืจืขื–ื•ืœื˜ืึทื˜ ื“ืึทื˜ืŸ ืฆื•ืจื™ืง ืคื•ืŸ ื“ื™ ืฆื™ืœ ืžืึทืฉื™ืŸ ืฆื• ื“ื™ ืึทื˜ืึทืงืขืจ ืก ืžืึทืฉื™ืŸ, ืขืก ืื™ื– ื’ืขื ื™ืฆื˜ ืกืžื‘ืงืœื™ืขื ื˜. ื™ืึธ, ื“ืึธืก ืื™ื– ื“ืขืจ ื–ืขืœื‘ื™ืงืขืจ ืกืึทืžื‘ืึท ื ื•ืฆืŸ, ืึธื‘ืขืจ ื‘ืœื•ื™ื– ืงืึธื ื•ื•ืขืจื˜ืขื“ ืฆื• ืึท ืคึผื™ื˜ื”ืึธืŸ ืฉืจื™ืคื˜ ื“ื•ืจืš Impacket. ืื™ืŸ ืคืึทืงื˜, smbclient ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืงืึธื•ื•ืขืจืก ืคื˜ืคึผ ื˜ืจืึทื ืกืคืขืจืก ืื™ื‘ืขืจ ืกืžื‘.

ืœืึธืžื™ืจ ื ืขืžืขืŸ ืึท ืฉืจื™ื˜ ืฆื•ืจื™ืง ืื•ืŸ ื˜ืจืึทื›ื˜ืŸ ื•ื•ืขื’ืŸ ื•ื•ืึธืก ื“ืึธืก ืงืขืŸ ื˜ืึธืŸ ืคึฟืึทืจ ื“ืขืจ ืึธื ื’ืขืฉื˜ืขืœื˜ืขืจ. ืื™ืŸ ืžื™ื™ืŸ ืคื™ืงื˜ื™ืฉืึทืก ืกืฆืขื ืึทืจ, ืœืึธื–ืŸ ืก ื–ืึธื’ืŸ ืึท ื‘ืœืึธื’ื’ืขืจ, ืคื™ื ืึทื ืฆื™ืขืœ ืึทื ืึทืœื™ืกื˜ ืึธื“ืขืจ ื”ืขื›ืกื˜ ื‘ืึทืฆืึธืœื˜ ื–ื™ื›ืขืจื”ื™ื™ื˜ ืงืึธื ืกื•ืœื˜ืึทื ื˜ ืื™ื– ืขืจืœื•ื™ื‘ื˜ ืฆื• ื ื•ืฆืŸ ืึท ืคึผืขืจื–ืขื ืœืขืš ืœืึทืคึผื˜ืึทืคึผ ืคึฟืึทืจ ืึทืจื‘ืขื˜. ื•ื•ื™ ืึท ืจืขื–ื•ืœื˜ืึทื˜ ืคื•ืŸ ืึท ืžืึทื“ื–ืฉื™ืงืึทืœ ืคึผืจืึธืฆืขืก, ื–ื™ ื ืขืžื˜ ื”ืขื˜ ืื™ืŸ ื“ื™ ืคื™ืจืžืข ืื•ืŸ "ื’ื™ื™ื˜ ืึทืœืข ืฉืœืขื›ื˜." ื“ืขืคึผืขื ื“ื™ื ื’ ืื•ื™ืฃ ื“ื™ ืœืึทืคึผื˜ืึทืคึผ ืึธืคึผืขืจื™ื™ื˜ื™ื ื’ ืกื™ืกื˜ืขื, ืขืก ื ื™ืฆื˜ ื“ื™ Python ื•ื•ืขืจืกื™ืข ืคึฟื•ืŸ ื™ืžืคึผืึทืงื˜, ืึธื“ืขืจ ื“ื™ Windows ื•ื•ืขืจืกื™ืข ืคื•ืŸ โ€‹โ€‹smbexec ืึธื“ืขืจ smbclient ื•ื•ื™ ืึทืŸ. ืขืงืกืข ื˜ืขืงืข.

ืื–ื•ื™ ื•ื•ื™ ืกื ืึธื•ื•ื“ืขืŸ, ื“ืขืจืคื™ื ื˜ ื–ื™ ืืŸ ืื ื“ืขืจ ื‘ืื ื•ืฆืขืจ'ืก ืคึผืึทืจืึธืœ ืึธื“ืขืจ ื“ื•ืจืš ืงื•ืงืŸ ืื™ื‘ืขืจ ืื™ืจ ืึทืงืกืœ, ืึธื“ืขืจ ื–ื™ ื”ืึธื˜ ืžืึทื–ืœื“ื™ืง ืื•ืŸ ื˜ืจืขืคื˜ ืื•ื™ืฃ ืึท ื˜ืขืงืกื˜ ื˜ืขืงืข ืžื™ื˜ ื“ืขื ืคึผืึทืจืึธืœ. ืื•ืŸ ืžื™ื˜ ื“ื™ ื”ื™ืœืฃ ืคื•ืŸ ื“ื™ ืงืจืึทื“ืขื ื˜ืฉืึทืœื–, ื–ื™ ื”ื™ื™ื‘ื˜ ืฆื• ื’ืจืึธื‘ืŸ ืึทืจื•ื ื“ื™ ืกื™ืกื˜ืขื ืื™ืŸ ืึท ื ื™ื™ึทืข ืžื“ืจื’ื” ืคื•ืŸ ืคึผืจื™ื•ื•ื™ืœืึทื“ื–ืฉืึทื–.

ื›ืึทืง ื“ืงืง: ืžื™ืจ ื“ืึทืจืคึฟืŸ ื ื™ืฉื˜ ืงื™ื™ืŸ "ื ืึทืจื™ืฉ" ืžื™ืžื™ืงืึทืฅ

ืื™ืŸ ืžื™ื™ื ืข ืคืจื™ืขืจื“ื™ืงืข ืึทืจื˜ื™ืงืœืขืŸ ืื•ื™ืฃ ืคึผืขื ื˜ืขืกื˜ื™ื ื’, ืื™ืš ื’ืขื•ื•ื™ื™ื ื˜ Mimikaz ื–ื™ื™ืขืจ ืึธืคื˜. ื“ืึธืก ืื™ื– ืึท ื’ืจื•ื™ืก ื’ืขืฆื™ื™ึทื’ ืคึฟืึทืจ ื™ื ื˜ืขืจืกืขืคึผื˜ื™ื ื’ ืงืจืึทื“ืขื ื˜ืฉืึทืœื– - NTLM ื”ืึทืฉืขืก ืื•ืŸ ืืคื™ืœื• ืงืœืึธืจ ื˜ืขืงืกื˜ ืคึผืึทืกื•ื•ืขืจื“ื– ืคืึทืจื‘ืึธืจื’ืŸ ื™ืŸ ืœืึทืคึผื˜ืึทืคึผืก, ื ืึธืจ ื•ื•ืืจื˜ืŸ ืฆื• ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜.
ืฆื™ื™ื˜ืŸ ื”ืึธื‘ืŸ ื’ืขื‘ื™ื˜ืŸ. ืžืึธื ื™ื˜ืึธืจื™ื ื’ ืžื›ืฉื™ืจื™ื ื”ืึธื‘ืŸ ื‘ืึทืงื•ืžืขืŸ ื‘ืขืกืขืจ ืื™ืŸ ื“ื™ื˜ืขืงื˜ื™ื ื’ ืื•ืŸ ื‘ืœืึทืงื™ื ื’ ืžื™ืžื™ืงืึทื˜ื–. ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื–ื™ื›ืขืจื”ื™ื™ื˜ ืึทื“ืžื™ื ื™ืกื˜ืจืึทื˜ืึธืจืก ืื•ื™ืš ืื™ืฆื˜ ื”ืึธื‘ืŸ ืžืขืจ ืึธืคึผืฆื™ืขืก ืฆื• ืจืขื“ื•ืฆื™ืจืŸ ื“ื™ ืจื™ืกืงืก ืคึฟืึทืจื‘ื•ื ื“ืŸ ืžื™ื˜ ื“ื™ ื”ืึทืฉ (PtH) ืื ืคืืœืŸ.
ืึทื–ื•ื™ ื•ื•ืึธืก ื–ืึธืœ ืึท ืงืœื•ื’ ืึธื ื’ืขืฉื˜ืขืœื˜ืขืจ ื˜ืึธืŸ ืฆื• ื–ืึทืžืœืขืŸ ื ืึธืš ืงืจืึทื“ืขื ื˜ืฉืึทืœื– ืึธืŸ ื ื™ืฆืŸ ืžื™ืžื™ืงืึทื˜ื–?

ื™ืžืคึผืึทืงืงืขื˜ ืก ื™ื ื•ื•ืขื ื˜ืึทืจ ื›ื•ืœืœ ืึท ื ื•ืฆืŸ ื’ืขืจื•ืคืŸ secretsdump, ื•ื•ืึธืก ืจื™ื˜ืจื™ื•ื•ื– ืงืจืึทื“ืขื ื˜ืฉืึทืœื– ืคื•ืŸ ื“ื™ ืคืขืœื“ ืงืจืขื“ืขื ืฉืึทืœ ืงืึทืฉ, ืึธื“ืขืจ DCC ืคึฟืึทืจ ืงื•ืจืฅ. ืžื™ื™ืŸ ืคืืจืฉื˜ืื ื“ ืื™ื– ืึทื– ืื•ื™ื‘ ืึท ืคืขืœื“ ื‘ืึทื ื™ืฆืขืจ ืœืึธื’ืก ืื™ืŸ ื“ื™ ืกืขืจื•ื•ืขืจ ืึธื‘ืขืจ ื“ื™ ืคืขืœื“ ืงืึทื ื˜ืจืึธื•ืœืขืจ ืื™ื– ืึทื ืึทื•ื•ื™ื™ืœืึทื‘ืึทืœ, DCC ืึทืœืึทื•ื– ื“ื™ ืกืขืจื•ื•ืขืจ ืฆื• ืึธื˜ืขื ื˜ืึทืงื™ื™ื˜ ื“ืขื ื‘ืึทื ื™ืฆืขืจ. ืกื™ื™ึท ื•ื•ื™ ืกื™ื™ึท, secretsdump ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื“ืึทืžืคึผ ืึทืœืข ื“ื™ ื”ืึทืฉืขืก ืื•ื™ื‘ ื–ื™ื™ ื–ืขื ืขืŸ ื‘ื ื™ืžืฆื.

DCC ื”ืึทืฉืขืก ื–ืขื ืขืŸ ื ื™ืฉื˜ ื ื˜ืžืœ ื”ืึทืฉืขืก ืื•ืŸ ื–ื™ื™ ืงืขื ืขืŸ ื ื™ื˜ ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืคึฟืึทืจ PTH ื‘ืึทืคืึทืœืŸ.

ื ื•, ืื™ืจ ืงืขื ืขืŸ ืคึผืจื•ื‘ื™ืจืŸ ืฆื• ื›ืึทืง ื–ื™ื™ ืฆื• ื‘ืึทืงื•ืžืขืŸ ื“ื™ ืึธืจื™ื’ื™ื ืขืœ ืคึผืึทืจืึธืœ. ืึธื‘ืขืจ, ืžื™ื™ืงืจืึธืกืึธืคึฟื˜ ืื™ื– ื’ืขื•ื•ืืจืŸ ืกืžืึทืจื˜ืขืจ ืžื™ื˜ DCC ืื•ืŸ DCC ื”ืึทืฉืขืก ื”ืึธื‘ืŸ ื•ื•ืขืจืŸ ื’ืึธืจ ืฉื•ื•ืขืจ ืฆื• ืคึผืœืึทืฆืŸ. ื™ื ืื™ืš ื”ืื‘ ื”ืึทืฉืงืึทื˜, "ื“ื™ ื•ื•ืขืœื˜ 'ืก ืคืึทืกื˜ืึทืกื˜ ืคึผืึทืจืึธืœ ื’ืขืกืขืจ," ืึธื‘ืขืจ ืขืก ืจื™ืงื•ื•ื™ื™ืขืจื– ืึท ื’ืคึผื• ืฆื• ืœื•ื™ืคืŸ ื™ืคืขืงื˜ื™ื•ื•ืœื™.

ืึทื ืฉื˜ืึธื˜, ืœืึธืžื™ืจ ืคึผืจื•ื‘ื™ืจืŸ ืฆื• ื˜ืจืึทื›ื˜ืŸ ื•ื•ื™ ืกื ืึธื•ื•ื“ืขืŸ. ืึทืŸ ืึธื ื’ืขืฉื˜ืขืœื˜ืขืจ ืงืขื ืขืŸ ืึธื ืคื™ืจืŸ ื’ืขื–ืขืœืฉืึทืคื˜ืœืขืš ื™ื ื–ืฉืขื ื™ืขืจื™ืข ืคึผื ื™ื-ืฆื•-ืคึผื ื™ื ืื•ืŸ ืขืคืฉืขืจ ื’ืขืคึฟื™ื ืขืŸ ืขื˜ืœืขื›ืข ืื™ื ืคึฟืึธืจืžืึทืฆื™ืข ื•ื•ืขื’ืŸ ื“ืขื ืžืขื ื˜ืฉ ื•ื•ืขืžืขื ืก ืคึผืึทืจืึธืœ ื–ื™ ื•ื•ื™ืœ ืฆื• ืคึผืœืึทืฆืŸ. ืคึฟืึทืจ ื‘ื™ื™ึทืฉืคึผื™ืœ, ื’ืขืคื™ื ืขืŸ ืื•ื™ืก ืื•ื™ื‘ ื“ืขืจ ืžืขื ื˜ืฉ ืก ืึธื ืœื™ื™ืŸ ื—ืฉื‘ื•ืŸ ืื™ื– ืืœืฅ ื›ืึทืงื˜ ืื•ืŸ ื•ื ื˜ืขืจื–ื•ื›ืŸ ื–ื™ื™ืขืจ ืงืœืขืจื˜ืขืงืกื˜ ืคึผืึทืจืึธืœ ืคึฟืึทืจ ืงื™ื™ืŸ ืงืœื•ื–.

ืื•ืŸ ื“ืึธืก ืื™ื– ื“ืขืจ ืกืฆืขื ืึทืจ ื•ื•ืึธืก ืื™ืš ื‘ืึทืฉืœืึธืกืŸ ืฆื• ื’ื™ื™ืŸ ืžื™ื˜. ืœืึธืžื™ืจ ื™ื‘ืขืจื ืขืžืขืŸ ืึทื– ืึทืŸ ื™ื ืกื™ื™ื“ืขืจ ื’ืขืœืขืจื ื˜ ืึทื– ื–ื™ื™ืŸ ื‘ืึทืœืขื‘ืึธืก, Cruella, ืื™ื– ื’ืขื•ื•ืขืŸ ื›ืึทืงื˜ ืขื˜ืœืขื›ืข ืžืึธืœ ืื•ื™ืฃ ืคืึทืจืฉื™ื“ืขื ืข ื•ื•ืขื‘ ืจืขืกื•ืจืกืŸ. ื ืึธืš ืึทื ืึทืœื™ื™ื–ื™ื ื’ ืขื˜ืœืขื›ืข ืคื•ืŸ โ€‹โ€‹โ€‹โ€‹ื“ื™ ืคึผืึทืกื•ื•ืขืจื“ื–, ืขืจ ืจื™ืึทืœื™ื™ื–ื™ื– ืึทื– Cruella ืคึผืจืึทืคืขืจื– ืฆื• ื ื•ืฆืŸ ื“ื™ ืคึฟืึธืจืžืึทื˜ ืคื•ืŸ ื“ื™ ื‘ื™ื™ืกื‘ืึธืœ ืžืึทื ืฉืึทืคึฟื˜ ื ืึธืžืขืŸ "Yankees" ื ืื›ื’ืขื’ืื ื’ืขืŸ ื“ื•ืจืš ื“ื™ ืงืจืึทื ื˜ ื™ืึธืจ - "Yankees2015".

ืื•ื™ื‘ ืื™ืจ ื–ืขื ื˜ ืื™ืฆื˜ ื˜ืจื™ื™ื ื’ ืฆื• ืจืขืคึผืจืึธื“ื•ืฆื™ืจืŸ ื“ืขื ืื™ืŸ ืฉื˜ื•ื‘, ืื™ืจ ืงืขื ืขืŸ ืืจืืคืงืืคื™ืข ืึท ืงืœื™ื™ืŸ "C" ืงืึธื“ืขืงืก, ื•ื•ืึธืก ื™ืžืคึผืœืึทืžืึทื ืฅ ื“ื™ DCC ื›ืึทืฉื™ื ื’ ืึทืœื’ืขืจื™ื“ืึทื, ืื•ืŸ ืฆื•ื ื•ื™ืคื ืขืžืขืŸ ืขืก. ื™ื•ื—ื ืŸ ื“ื™ ืจื™ืคึผืขืจ, ื“ื•ืจืš ื“ืขื ื•ื•ืขื’, ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ DCC, ืึทื–ื•ื™ ืขืก ืงืขื ืขืŸ ืื•ื™ืš ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜. ืœืึธืžื™ืจ ื™ื‘ืขืจื ืขืžืขืŸ ืึทื– ืึท ื™ื ืกื™ื™ื“ืขืจ ื•ื•ื™ืœ ื ื™ืฉื˜ ืึทืจืŸ ืœืขืจื ืขืŸ ื™ื•ื—ื ืŸ ื“ื™ ืจื™ืคึผืขืจ ืื•ืŸ ืœื™ื™ืงืก ืฆื• ืœื•ื™ืคืŸ "gcc" ืื•ื™ืฃ ืœืขื’ืึทื˜ C ืงืึธื“.

ืื™ืš ื”ืึธื‘ ื’ืขืžืึทื›ื˜ ื“ื™ ืจืึธืœืข ืคื•ืŸ โ€‹โ€‹ืึทืŸ ื™ื ืกื™ื™ื“ืขืจ, ืื™ืš ื’ืขืคืจื•ื•ื•ื˜ ืขื˜ืœืขื›ืข ืคืึทืจืฉื™ื“ืขื ืข ืงืึทืžื‘ืึทื ื™ื™ืฉืึทื ื– ืื•ืŸ ื™ื•ื•ืขื ื˜ืฉืึทื•ื•ืึทืœื™ ืงืขื ืขืŸ ืฆื• ืึทื ื˜ื“ืขืงืŸ ืึทื– ื“ื™ ืคึผืึทืจืึธืœ ืคื•ืŸ Cruella ืื™ื– "Yankees2019" (ื–ืขืŸ ื•ื•ื™ื™ื˜ืขืจ). ืžื™ืกื™ืข ื’ืขืขื ื“ื™ื’ื˜!

ืคืึทืจื‘ืึธืจื’ืŸ ืคึผืึทืจืึธืœ ื›ืึทืงื™ื ื’ ืžื™ื˜ Smbexec

ื ื‘ื™ืกืœ ื’ืขื–ืขืœืฉืึทืคื˜ืœืขืš ื™ื ื–ืฉืขื ื™ืขืจื™ืข, ืึท ืœืึธืš ืคื•ืŸ ืžืึทื–ืœ ื–ืึธื’ืŸ ืื•ืŸ ืึท ืงื ื™ืคึผ ืคื•ืŸ Maltego ืื•ืŸ ืื™ืจ ื–ืขื ื˜ ื’ืขื–ื•ื ื˜ ืื•ื™ืฃ ื“ื™ื™ืŸ ื•ื•ืขื’ ืฆื• ืงืจืึทืงื™ื ื’ ื“ื™ DCC ื”ืึทืฉ.

ืื™ืš ืคึฟืึธืจืฉืœืึธื’ืŸ ืžื™ืจ ืขื ื“ื™ืงืŸ ื“ืึธ. ืžื™ืจ ื•ื•ืขืœืŸ ืฆื•ืจื™ืงืงื•ืžืขืŸ ืฆื• ื“ืขื ื˜ืขืžืข ืื™ืŸ ืื ื“ืขืจืข ื”ื•ื“ืขื•ืช ืื•ืŸ ืงื•ืง ืื™ืŸ ืืคื™ืœื• ืžืขืจ ืคึผืึทืžืขืœืขืš ืื•ืŸ ืกื˜ืขืœื˜ื™ ื‘ืึทืคืึทืœืŸ ืžืขื˜ื”ืึธื“ืก, ืคืึธืจื–ืขืฆืŸ ืฆื• ื‘ื•ื™ืขืŸ ืื•ื™ืฃ ื“ื™ ื•ื™ืกื’ืขืฆื™ื™ื›ื ื˜ ื’ืึทื ื’ ืคื•ืŸ ื™ื•ื˜ื™ืœืึทื˜ื™ื– ืคื•ืŸ Impacket.

ืžืงื•ืจ: www.habr.com

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’