## https://sploitus.com/exploit?id=KITPLOIT:TOOLS-GITHUB-LAZAARS-ULTRAREALY_WITH_CVE-2019-1040
# Lazaar Sami๊ฐ CVE-2019-1040 ์ต์คํ๋ก์์ ์ํด ์
๋ฐ์ดํธํ UltraRelay
UltraRelay๋ LLMNR ์ค๋
๋ฐ NTLM ์๊ฒฉ ์ฆ๋ช
๋ฆด๋ ์ด๋ฅผ ์ํ ๋๊ตฌ์
๋๋ค. Responder์ impack์ ๊ธฐ๋ฐ์ผ๋ก ํฉ๋๋ค.
์๋ณธ ๋ฒ์ (https://github.com/5alt/ultrarelay)์ CVE-2019-1040 ์ต์คํ๋ก์์ ์ํด ์
๋ฐ์ดํธํ์ต๋๋ค. Dirk-jan Mollema๋ ntlmrelayx(https://github.com/CoreSecurity/impacket์ ์ผ๋ถ)๋ฅผ ์
๋ฐ์ดํธํ์ฌ --remove-mic ํ๋๊ทธ๋ฅผ ์ถ๊ฐํ์ต๋๋ค. ์ด ํ๋๊ทธ๋ Preempt ์ฐ๊ตฌ์๋ค์ ๊ธฐ์ ์ค๋ช
(https://blog.preempt.com/drop-the-mic)์ ๊ธฐ๋ฐ์ผ๋ก CVE-2019-1040์ ์ต์คํ๋ก์ํฉ๋๋ค. ์ฐธ์กฐ: https://dirkjanm.io/exploiting-CVE-2019-1040-relay-vulnerabilities-for-rce-and-domain-admin/ ํนํ, ์ด ๋๊ตฌ๋ JAVA HTTP ์์ฒญ์์ ๋ก์ปฌ SMB ์๋ฒ๋ก ์๊ฒฉ ์ฆ๋ช
์ ๋ฆด๋ ์ดํ์ฌ RCE๋ฅผ ๋ฌ์ฑํ๋ ๋ฐ ์ฌ์ฉํ ์ ์์ต๋๋ค.
## ์ข
์์ฑ
* Responder
* impack
## ์ฌ์ฉ๋ฒ
์๋ณธ ๋ฒ์ https://github.com/5alt/ultrarelay ์์ Jianing Wang๊ณผ Junyu Zhou์๊ฒ ๊ฐ์ฌ๋๋ฆฝ๋๋ค. `python ultrarelay.py -ip 192.168.1.100`
ip ์ธ์ ๊ฐ์ ๊ณต๊ฒฉ์์ IP ์ฃผ์์
๋๋ค.
CVE-2019-1040 ์ต์คํ๋ก์์ ์ํด --remove-mic ํ๋๊ทธ(์ต์ NTLM ์ํ๋ฅผ ์ฐํํ๊ธฐ ์ํด MIC ์ ๊ฑฐ, https://blog.preempt.com/drop-the-mic ์ฐธ์กฐ)์ -remove-target ํ๋๊ทธ(์ฑ๋ฆฐ์ง ๋ฉ์์ง์์ ๋์์ ์ ๊ฑฐ, CVE-2019-1019 ํจ์น๊ฐ ์ค์น๋์ง ์์ ๊ฒฝ์ฐ)๋ฅผ ์ถ๊ฐํ์ต๋๋ค. ์ด๋ Dirk-jan Mollema๊ฐ ์
๋ฐ์ดํธํ ์๋ก์ด ntlmrelayx ๋ฒ์ (https://github.com/CoreSecurity/impacket)์์ ์๊ฐ์ ๋ฐ์์ต๋๋ค. ์: python ultrarelay.py -ip 192.168.1.3 --remove-mic --escalate-user ntu -t ldap://s2016dc.testsegment.local -smb2support
## ๋ฐ๋ชจ ๋น๋์ค
https://www.youtube.com/watch?v=VyoyA2GgKck
## ์ฐ๋ฝ์ฒ
Lazaar sami, some-email@example.com
# UltraRealy_with_CVE-2019-1040