17 KiB
macOS MDM
âïž HackTricks Cloud âïž -ðŠ Twitter ðŠ - ðïž Twitch ðïž - ð¥ Youtube ð¥
- ããªãã¯ãµã€ããŒã»ãã¥ãªãã£äŒæ¥ã§åããŠããŸããïŒ HackTricksã§ããªãã®äŒç€Ÿã宣äŒãããã§ããïŒãŸãã¯ãPEASSã®ææ°ããŒãžã§ã³ã«ã¢ã¯ã»ã¹ããããHackTricksãPDFã§ããŠã³ããŒããããã§ããïŒSUBSCRIPTION PLANSããã§ãã¯ããŠãã ããïŒ
- The PEASS FamilyãçºèŠããŸããããç§ãã¡ã®ç¬å çãªNFTã®ã³ã¬ã¯ã·ã§ã³
- å ¬åŒã®PEASSïŒHackTricks swagãæã«å ¥ããŸããã
- ð¬ Discordã°ã«ãŒããŸãã¯telegramã°ã«ãŒãã«åå ããããTwitterã§ãã©ããŒããŠãã ããðŠ@carlospolopm.
- ãããã³ã°ã®ããªãã¯ãå ±æããããã«ãhacktricks repo ããã³ hacktricks-cloud repoã«PRãæåºããŠãã ããã
åºæ¬
MDMïŒã¢ãã€ã«ããã€ã¹ç®¡çïŒãšã¯äœã§ããïŒ
ã¢ãã€ã«ããã€ã¹ç®¡çïŒMDMïŒã¯ãã¢ãã€ã«é»è©±ãããŒãããœã³ã³ããã¹ã¯ããããã¿ãã¬ãããªã©ã®ãšã³ããŠãŒã¶ãŒã³ã³ãã¥ãŒãã£ã³ã°ããã€ã¹ã管çããããã«äžè¬çã«äœ¿çšãããæè¡ã§ããAppleã®iOSãmacOSãtvOSãªã©ã®ãã©ãããã©ãŒã ã®å Žåãç¹å®ã®æ©èœãAPIãããã³æè¡ãæãã管çè ããããã®ããã€ã¹ã管çããããã«äœ¿çšããŸããMDMãä»ããããã€ã¹ã®ç®¡çã«ã¯ãåçšãŸãã¯ãªãŒãã³ãœãŒã¹ã®äºææ§ã®ããMDMãµãŒããŒãå¿ èŠã§ãMDMãããã³ã«ã®ãµããŒããå®è£ ããŠããŸãã
- éäžçãªããã€ã¹ç®¡çãå®çŸããæ¹æ³
- MDMãããã³ã«ã®ãµããŒããå®è£ ããMDMãµãŒããŒãå¿ èŠ
- MDMãµãŒããŒã¯ããªã¢ãŒãã¯ã€ããããã®èšå®ãã€ã³ã¹ããŒã«ããããšãã£ãMDMã³ãã³ããããã€ã¹ã«éä¿¡ã§ãã
åºæ¬ DEPïŒããã€ã¹ç»é²ããã°ã©ã ïŒãšã¯äœã§ããïŒ
ããã€ã¹ç»é²ããã°ã©ã ïŒDEPïŒã¯ãAppleãæäŸãããµãŒãã¹ã§ãiOSãmacOSãtvOSããã€ã¹ã®ã¢ãã€ã«ããã€ã¹ç®¡çïŒMDMïŒç»é²ããŒãã¿ããæ§æã§ç°¡çŽ åããŸããããã€ã¹ãæ§æããããã«ãšã³ããŠãŒã¶ãŒãŸãã¯ç®¡çè ãã¢ã¯ã·ã§ã³ãèµ·ããå¿ èŠãããåŸæ¥ã®å±éæ¹æ³ãšã¯ç°ãªãããŸãã¯MDMãµãŒããŒã«æåã§ç»é²ããå¿ èŠãããå Žåãšã¯ç°ãªããDEPã¯ãã®ããã»ã¹ãããŒãã¹ãã©ããããæ°ããAppleããã€ã¹ãéå°ããŠããã«çµç¹ã§äœ¿çšã§ããããã«ããŸãã
管çè ã¯DEPã掻çšããŠãããã€ã¹ãçµç¹ã®MDMãµãŒããŒã«èªåçã«ç»é²ã§ããŸããããã€ã¹ãç»é²ããããšãå€ãã®å Žåãçµç¹ãææãããä¿¡é Œããããããã€ã¹ãšããŠæ±ããã蚌ææžãã¢ããªã±ãŒã·ã§ã³ãWiFiãã¹ã¯ãŒããVPNèšå®ãªã©ã®ããããã®æ°ãåãåãããšãã§ããŸãã
- ããã€ã¹ãåããŠé»æºãå ¥ãããšãã«èªåçã«äºåã«èšå®ãããMDMãµãŒããŒã«ç»é²ããããšãã§ãã
- ããã€ã¹ãæ°åã®å Žåã«æãæçš
- OSã®æ°èŠã€ã³ã¹ããŒã«ã§æ¶å»ãããå Žåã«ãæçš
{% hint style="danger" %} æ®å¿µãªãããçµç¹ãMDMç»é²ãä¿è·ããããã®è¿œå ã®æé ãèžãã§ããªãå ŽåãDEPãä»ããç°¡çŽ åããããšã³ããŠãŒã¶ãŒã®ç»é²ããã»ã¹ã¯ãæ»æè ãçµç¹ã®MDMãµãŒããŒã«éžæããããã€ã¹ãç»é²ããããã®ç°¡çŽ åãããããã»ã¹ãæå³ããããšãã§ããŸãã {% endhint %}
åºæ¬ SCEPïŒã·ã³ãã«èšŒææžç»é²ãããã³ã«ïŒãšã¯äœã§ããïŒ
- TLSãšHTTPSãæ®åããåã«äœæãããæ¯èŒçå€ããããã³ã«
- ã¯ã©ã€ã¢ã³ãã蚌ææžãååŸããããã®èšŒææžçœ²åãªã¯ãšã¹ãïŒCSRïŒãéä¿¡ããããã®æšæºåãããæ¹æ³ãæäŸããŸããã¯ã©ã€ã¢ã³ãã¯ããµãŒããŒã«çœ²åããã蚌ææžãäžããããã«äŸé ŒããŸãã
èšå®ãããã¡ã€ã«ïŒmobileconfigsïŒãšã¯äœã§ããïŒ
- Appleã®å ¬åŒãªæ¹æ³ã§ãã·ã¹ãã ã®èšå®/匷å¶ãè¡ãæ¹æ³ã§ãã
- è€æ°ã®ãã€ããŒããå«ããã¡ã€ã«åœ¢åŒã§ãã
- ããããã£ãªã¹ãïŒXML圢åŒïŒã«åºã¥ããŠããŸãã
- ããã®èµ·æºãæ€èšŒããæŽåæ§ã確ä¿ããå 容ãä¿è·ããããã«çœ²åãšæå·åããããšãã§ããŸãããBasics â Page 70, iOS Security Guide, January 2018.
ãããã³ã«
MDM
- APNsïŒAppleãµãŒããŒïŒ+ RESTful APIïŒMDMãã³ããŒãµãŒããŒïŒã®çµã¿åãã
- ããã€ã¹ãšããã€ã¹ç®¡ç補åã«é¢é£ãããµãŒããŒéã®éä¿¡
- MDMããããã€ã¹ã«plistãšã³ã³ãŒããããèŸæžåœ¢åŒã®ã³ãã³ããéä¿¡
- ãã¹ãŠHTTPSã§è¡ãããŸããMDMãµãŒããŒã¯ïŒéåžžïŒãã³çããããŠããŸãã
- Appleã¯MDMãã³ããŒã«APNs蚌ææžãçºè¡ããŸãïŒèªèšŒã«äœ¿çšïŒ
DEP
- 3ã€ã®APIïŒãªã»ã©ãŒçšãMDMãã³ããŒçšãããã€ã¹IDçšïŒéå ¬éïŒïŒ
- ããããDEPãã¯ã©ãŠããµãŒãã¹ãAPIãããã¯ãMDMãµãŒããŒãDEPãããã¡ã€ã«ãç¹å®ã®ããã€ã¹ã«é¢é£ä»ããããã«äœ¿çšãããŸãã
- Appleèªå®ãªã»ã©ãŒã䜿çšããDEP APIãããã€ã¹ã®ç»é²ãç»é²ç¶æ³ã®ç¢ºèªããã©ã³ã¶ã¯ã·ã§ã³ç¶æ³ã®ç¢ºèªã«äœ¿çšãããŸãã
- éå ¬éã®ãã©ã€ããŒãDEP APIãããã¯ãAppleããã€
ã·ãªã¢ã«çªå·
2010幎以éã«è£œé ãããAppleããã€ã¹ã¯ãäžè¬çã«ã¯12æåã®è±æ°åã®ã·ãªã¢ã«çªå·ãæã¡ãŸããæåã®3æ¡ã¯è£œé å Žæãè¡šããç¶ã2æ¡ã¯è£œé 幎ãšé±ã瀺ãã次ã®3æ¡ã¯äžæã®èå¥åãæäŸããæåŸã®4æ¡ã¯ã¢ãã«çªå·ãè¡šããŸãã
{% content-ref url="macos-serial-number.md" %} macos-serial-number.md {% endcontent-ref %}
ç»é²ãšç®¡çã®æé
- ããã€ã¹ã¬ã³ãŒãã®äœæïŒè²©å£²æ¥è ãAppleïŒïŒæ°ããããã€ã¹ã®ã¬ã³ãŒããäœæãããŸãã
- ããã€ã¹ã¬ã³ãŒãã®å²ãåœãŠïŒé¡§å®¢ïŒïŒããã€ã¹ãMDMãµãŒããŒã«å²ãåœãŠãããŸãã
- ããã€ã¹ã¬ã³ãŒãã®åæïŒMDMãã³ããŒïŒïŒMDMã¯ããã€ã¹ã¬ã³ãŒããåæããDEPãããã¡ã€ã«ãAppleã«ããã·ã¥ããŸãã
- DEPãã§ãã¯ã€ã³ïŒããã€ã¹ïŒïŒããã€ã¹ãDEPãããã¡ã€ã«ãååŸããŸãã
- ãããã¡ã€ã«ã®ååŸïŒããã€ã¹ïŒ
- ãããã¡ã€ã«ã®ã€ã³ã¹ããŒã«ïŒããã€ã¹ïŒa. MDMãSCEPãããã³ã«ãŒãCAã®ãã€ããŒããå«ã
- MDMã³ãã³ãã®çºè¡ïŒããã€ã¹ïŒ
/Library/Developer/CommandLineTools/SDKs/MacOSX10.15.sdk/System/Library/PrivateFrameworks/ConfigurationProfiles.framework/ConfigurationProfiles.tbd
ãã¡ã€ã«ã¯ãç»é²ããã»ã¹ã®**é«ã¬ãã«ãªãã¹ãããã**ãšèŠãªãããšãã§ããé¢æ°ããšã¯ã¹ããŒãããŠããŸãã
ã¹ããã4ïŒDEPãã§ãã¯ã€ã³ - ã¢ã¯ãã£ããŒã·ã§ã³ã¬ã³ãŒãã®ååŸ
ãã®ããã»ã¹ã®ãã®éšåã¯ããŠãŒã¶ãŒãMacãåããŠèµ·åãããšãïŒãŸãã¯å®å šãªã¯ã€ãåŸïŒã«çºçããŸãã
ãŸãã¯ãsudo profiles show -type enrollment
ãå®è¡ãããšã
- ããã€ã¹ãDEP察å¿ãã©ãããå€æãã
- ã¢ã¯ãã£ããŒã·ã§ã³ã¬ã³ãŒãã¯ãDEPã®ããããã¡ã€ã«ãã®å éšåã§ãã
- ããã€ã¹ãã€ã³ã¿ãŒãããã«æ¥ç¶ããããšããã«éå§ãããŸãã
- **
CPFetchActivationRecord
**ã«ãã£ãŠé§åãããŸãã - **
cloudconfigurationd
ã«ãã£ãŠå®è£ ãããŸããããã€ã¹ãåããŠèµ·åããããšãã®ãã»ããã¢ããã¢ã·ã¹ã¿ã³ãããŸãã¯profiles
**ã³ãã³ãã¯ããã®ããŒã¢ã³ã«æ¥è§ŠããŠã¢ã¯ãã£ããŒã·ã§ã³ã¬ã³ãŒããååŸããŸãã - LaunchDaemonïŒåžžã«rootãšããŠå®è¡ïŒ
**MCTeslaConfigurationFetcher
**ã«ãã£ãŠå®è¡ãããã¢ã¯ãã£ããŒã·ã§ã³ã¬ã³ãŒãã®ååŸã«ã¯ãAbsintheãšåŒã°ããæå·åã䜿çšãããŸãã
- 蚌ææžã®ååŸ
- https://iprofiles.apple.com/resource/certificate.cerã«GETãªã¯ãšã¹ããéä¿¡
- 蚌ææžããç¶æ
ãåæåïŒ
NACInit
ïŒ - IOKitãä»ããããã€ã¹åºæã®ããŒã¿ïŒäŸïŒã·ãªã¢ã«çªå·ïŒã䜿çš
- ã»ãã·ã§ã³ããŒã®ååŸ
- https://iprofiles.apple.com/sessionã«POSTãªã¯ãšã¹ããéä¿¡
- ã»ãã·ã§ã³ã®ç¢ºç«ïŒ
NACKeyEstablishment
ïŒ - ãªã¯ãšã¹ãã®äœæ
- https://iprofiles.apple.com/macProfileã«ããŒã¿
{ "action": "RequestProfileConfiguration", "sn": "" }
ãéä¿¡ããPOSTãªã¯ãšã¹ã - JSONãã€ããŒãã¯Absintheã䜿çšããŠæå·åãããŸãïŒ
NACSign
ïŒ - ãã¹ãŠã®ãªã¯ãšã¹ãã¯HTTPsçµç±ã§è¡ãããçµã¿èŸŒã¿ã®ã«ãŒã蚌ææžã䜿çšãããŸã
å¿çã¯ã以äžã®ãããªéèŠãªããŒã¿ãå«ãJSONèŸæžã§ãã
- urlïŒã¢ã¯ãã£ããŒã·ã§ã³ãããã¡ã€ã«ã®MDMãã³ããŒãã¹ãã®URL
- anchor-certsïŒä¿¡é Œãããã¢ã³ã«ãŒãšããŠäœ¿çšãããDER蚌ææžã®é å
ã¹ããã5ïŒãããã¡ã€ã«ã®ååŸ
- DEPãããã¡ã€ã«ã§æäŸãããURLã«ãªã¯ãšã¹ããéä¿¡ãããŸãã
- ã¢ã³ã«ãŒèšŒææžãæäŸãããå Žåãä¿¡é Œæ§ãè©äŸ¡ããããã«äœ¿çšãããŸãã
- ãªãã€ã³ããŒïŒDEPãããã¡ã€ã«ã®anchor_certsããããã£
- ãªã¯ãšã¹ãã¯ãããã€ã¹ã®èå¥æ å ±ïŒäŸïŒUDIDãOSããŒãžã§ã³ïŒãå«ãåçŽãª.plistã§ãã
- CMSã§çœ²åãããDERã§ãšã³ã³ãŒããããŠããŸãã
- ããã€ã¹ã®ã¢ã€ãã³ãã£ãã£èšŒææžïŒAPNSããïŒã䜿çšããŠçœ²åãããŠããŸãã
- 蚌ææžãã§ãŒã³ã«ã¯ãæéåãã®Apple iPhone Device CAãå«ãŸããŠããŸãã
ã¹ããã6ïŒãããã¡ã€ã«ã®ã€ã³ã¹ããŒã«
- ååŸãããããã¡ã€ã«ã¯ãã·ã¹ãã ã«ä¿åãããŸãã
- ãã®ã¹ãããã¯èªåçã«éå§ãããŸãïŒã»ããã¢ããã¢ã·ã¹ã¿ã³ãã®å ŽåïŒã
- **
CPInstallActivationProfile
**ã«ãã£ãŠé§åãããŸãã - mdmclientãä»ããŠå®è£ ãããŸãïŒXPCã䜿çšïŒã
- LaunchDaemonïŒrootãšããŠå®è¡ïŒãŸãã¯LaunchAgentïŒãŠãŒã¶ãŒãšããŠå®è¡ïŒã«ãã£ãŠå®è¡ãããå ŽåããããŸãã
- æ§æãããã¡ã€ã«ã«ã¯ãè€æ°ã®ãã€ããŒããã€ã³ã¹ããŒã«ããããã®ãã©ã°ã€ã³ããŒã¹ã®ã¢ãŒããã¯ãã£ããããŸãã
- åãã€ããŒãã¿ã€ãã¯ãã©ã°ã€ã³ã«é¢é£ä»ããããŠããŸãã
- XPCïŒãã¬ãŒã ã¯ãŒã¯å ïŒãŸãã¯ã¯ã©ã·ãã¯ãªCocoaïŒManagedClient.appå ïŒã§ããå ŽåããããŸãã
- äŸïŒ
- 蚌ææžãã€ããŒãã¯CertificateService.xpcã䜿çšããŸãã
éåžžãMDMãã³ããŒã«ãã£ãŠæäŸãããã¢ã¯ãã£ããŒã·ã§ã³ãããã¡ã€ã«ã«ã¯ã次ã®ãã€ããŒããå«ãŸããŠããŸãã
com.apple.mdm
ïŒããã€ã¹ãMDMã«ç»é²ããããã®ãã®com.apple.security.scep
ïŒããã€ã¹ã«ã¯ã©ã€ã¢ã³ã蚌ææžãå®å šã«æäŸããããã®ãã®ãcom.apple.security.pem
ïŒããã€ã¹ã®ã·ã¹ãã ããŒãã§ãŒã³ã«ä¿¡é ŒãããCA蚌ææžãã€ã³ã¹ããŒã«ããããã®ãã®ã- ããã¥ã¡ã³ãã®MDMãã§ãã¯ã€ã³ã«çžåœããMDMãã€ããŒãã®ã€ã³ã¹ããŒã«
- ãã€ããŒãã«ã¯ä»¥äžã®ããŒã®ããããã£ãå«ãŸããŸãïŒ
- MDMãã§ãã¯ã€ã³URLïŒ
CheckInURL
ïŒ - MDMã³ãã³ãããŒãªã³ã°URLïŒ
ServerURL
ïŒ+ ããªã¬ãŒããããã®APNsããã㯠- MDMãã€ããŒããã€ã³ã¹ããŒã«ããããã«ããªã¯ãšã¹ãã¯**
CheckInURL
**ã«éä¿¡ãããŸãã - **
mdmclient
**ã§å®è£ ãããŠããŸãã - MDMãã€ããŒãã¯ä»ã®ãã€ããŒãã«äŸåããããšãã§ããŸãã
- ç¹å®ã®èšŒææžã«ãªã¯ãšã¹ããåºå®ããããšãã§ããŸãïŒ
- ããããã£ïŒ
CheckInURLPinningCertificateUUIDs
- ããããã£ïŒ
ServerURLPinningCertificateUUIDs
- PEMãã€ããŒããä»ããŠé ä¿¡ãããŸã
- ããã€ã¹ã«ã¢ã€ãã³ãã£ã
ã¹ããã7: MDMã³ãã³ãã®åä¿¡
- MDMã®ãã§ãã¯ã€ã³ãå®äºããåŸããã³ããŒã¯APNsã䜿çšããŠããã·ã¥éç¥ãçºè¡ã§ãã
- åä¿¡åŸã**
mdmclient
**ãåŠçãã - MDMã³ãã³ããããŒãªã³ã°ããããã«ãServerURLã«ãªã¯ãšã¹ããéä¿¡ããã
- 以åã«ã€ã³ã¹ããŒã«ãããMDMãã€ããŒãã䜿çšãã:
- ãªã¯ãšã¹ãã®ãã³çãã«ã¯**
ServerURLPinningCertificateUUIDs
**ãäœ¿çš - TLSã¯ã©ã€ã¢ã³ã蚌ææžã«ã¯**
IdentityCertificateUUID
**ã䜿çš
æ»æ
ä»ã®çµç¹ã«ããã€ã¹ãç»é²ãã
以åã«ã³ã¡ã³ãããããã«ãããã€ã¹ãçµç¹ã«ç»é²ããããã«ã¯ããã®çµç¹ã«æå±ããã·ãªã¢ã«çªå·ã®ã¿ãå¿
èŠã§ããããã€ã¹ãç»é²ããããšãè€æ°ã®çµç¹ãæ°ããããã€ã¹ã«æ©å¯ããŒã¿ãã€ã³ã¹ããŒã«ããŸã: 蚌ææžãã¢ããªã±ãŒã·ã§ã³ãWiFiãã¹ã¯ãŒããVPNã®èšå®ãªã©ã
ãããã£ãŠãç»é²ããã»ã¹ãæ£ããä¿è·ãããŠããªãå Žåãããã¯æ»æè
ã«ãšã£ãŠå±éºãªãšã³ããªãŒãã€ã³ããšãªãåŸãŸãã
{% content-ref url="enrolling-devices-in-other-organisations.md" %} enrolling-devices-in-other-organisations.md {% endcontent-ref %}
åèæç®
âïž HackTricks Cloud âïž -ðŠ Twitter ðŠ - ðïž Twitch ðïž - ð¥ Youtube ð¥
- ãµã€ããŒã»ãã¥ãªãã£äŒæ¥ã§åããŠããŸããïŒ HackTricksã§ããªãã®äŒæ¥ã宣äŒãããã§ããïŒãŸãã¯ãPEASSã®ææ°ããŒãžã§ã³ãHackTricksã®PDFãããŠã³ããŒããããã§ããïŒSUBSCRIPTION PLANSããã§ãã¯ããŠãã ããïŒ
- The PEASS FamilyãèŠã€ããŠãã ãããç¬å çãªNFTã®ã³ã¬ã¯ã·ã§ã³ã§ãã
- å ¬åŒã®PEASSïŒHackTricksã°ããºãæã«å ¥ããŸãããã
- ð¬ Discordã°ã«ãŒããŸãã¯Telegramã°ã«ãŒãã«åå ããããTwitter ðŠ@carlospolopmããã©ããŒããŠãã ããã
- ãããã³ã°ã®ããªãã¯ãå ±æããã«ã¯ãhacktricks repo ãš hacktricks-cloud repo ã«PRãæåºããŠãã ããã