ããããããŒãçªå·81ã䜿çšããŠç¹å¥ãªãã€ããªãããã³ã«ã®åœ¢åŒã§CïŒCãµãŒããŒãšäº€æããä»ã®ã¡ãã»ãŒãžãšã¯ç°ãªããåãããŒãã®æšæºHTTPãããã³ã«ã䜿çšããŠãèŠã€ãã£ãææã¿ãŒã²ããããµãŒããŒã«éç¥ããŸãã 以äžã¯ããã®ãããªã¡ãã»ãŒãžã®ã¹ã¯ãªãŒã³ã·ã§ããã§ãã
å³ ãããã¯ãææã®ã¿ãŒã²ããã®æ€åºã«é¢ããã¡ãã»ãŒãžãCïŒCãµãŒããŒã«éä¿¡ããŸãã
ããããéä¿¡ããæååã®åœ¢åŒã以äžã«ç€ºããŸãã
ãã©ãŒãããæååã«ã¯æ¬¡ã®3ã€ã®éšåãããããšãããããŸãã
- é£èªåãããIPã¢ãã¬ã¹ã
- OSã§äœ¿çšããããã€ãé ïŒããã°ãšã³ãã£ã¢ã³ã®å Žåã¯0ããªãã«ãšã³ãã£ã¢ã³ã®å Žåã¯1ïŒã
- ãã¹ããæ€åºãããIPã¢ãã¬ã¹ã¹ãã£ã³ã®ã¿ã€ãïŒã«ãŒã¿ãŒã®å€éšIPã¢ãã¬ã¹ã«é£æ¥ããã¢ãã¬ã¹ãã¹ãã£ã³ããå Žåã¯0ãã©ã³ãã ã«éžæãããã¢ãã¬ã¹ã¯1ã§ãïŒã
ãã©ãŒãããæååã§ã¯ãåºå®ããŒã䜿çšããŠXORæäœãé©çšããããšã«ãããIPã¢ãã¬ã¹ãé£èªåãããŸãã Pythonã³ãŒãã®æ¬¡ã®ã¹ããããã䜿çšããŠãéåžžã«åŸ©å ã§ããŸãïŒpã¯GETãªã¯ãšã¹ãæååãã©ã¡ãŒã¿ãŒã§ãïŒã
ãªãŒãã³ããŒãã¹ãã£ããŒã¹ã¬ããã¯ããªã¢ãŒãã·ã¹ãã ã§ãªãŒãã³ãª10073rdããŒããèŠã€ããããšãã§ããªãå ŽåãåãIPã¢ãã¬ã¹ã®TelnetããŒãïŒ23rdããŒãïŒãžã®æ¥ç¶ãè©Šã¿ãŸãã ããã«ãéããŠããããŒããããå Žåã圌ã¯æ§æCïŒCãµãŒããŒããåãåã£ããã¹ã¯ãŒãã®ããŸããŸãªçµã¿åããããã«ãŒããã©ãŒã¹ã§ãã°ã€ã³ããããšããŸãã ãã°ã€ã³ã«æåããå Žåã圌ã¯ãããã¬ããŒãCïŒCãµãŒããŒã«å ±åããŸãã ãã以å€ã®å Žåã¯ã次ã®IPã¢ãã¬ã¹ã«é²ã¿ãŸãã
ãã°ã€ã³ã«æåãããšãMooseã¯æ¬¡ã®åœ¢åŒã§ã¬ããŒãããµãŒããŒã«éä¿¡ããŸãã
å³ CïŒCãµãŒããŒã«éä¿¡ãããå®éã®ã¡ãã»ãŒãžã®äŸã
ãã®ã¬ããŒãã«å¯ŸãããµãŒããŒã®å¿çã¯æ¬¡ã®ãšããã§ãã
Telnetãä»ããŠæ£åžžã«ãã°ã€ã³ãããšãææããã»ã¹ãéå§ãããŸãã 次ã®å³ã¯ããã®ããã»ã¹ã®äžè¬çãªãã¥ãŒã瀺ããŠããŸãã
å³ Linux / Mooseããã€ã¹ã®ææããã»ã¹ã®æŠèŠã
- Telnetæ¥ç¶ã䜿çšããŠãMooseã¯è¢«å®³è æ å ±ãåéããŸãã
- ãã®æ å ±ã¯ããã€ããªãããã³ã«ïŒ1ïŒã䜿çšããŠã¬ããŒãCïŒCãµãŒããŒã«éä¿¡ãããŸãã
- ã¬ããŒãCïŒCãµãŒããŒã¯ãé£èªåãããã³ãã³ãã®ã»ããããããã«è¿ããŸãïŒ2ïŒã
- ãããã¯ãCïŒCãµãŒããŒããåä¿¡ããã³ãã³ãã解èªãïŒ3ïŒãTelnetæ¥ç¶ãä»ããŠè¢«å®³è ã®ããã€ã¹ã§å®è¡ããŸãã
éåžžãã³ãã³ãã¯ãããŒãããŠå®è¡ããªã©ã®æ©èœãå®è¡ããããã«äœ¿çšãããŸãã ã³ãã³ããå®è¡ãããåŸã«è¢«å®³è ã·ã¹ãã ãè¿ãã¹ããŒã¿ã¹ã«å¿ããŠãã¹ããŒã¿ã¹ãOKã«ãªããŸã§ã³ãã³ããåå®è¡ãããå ŽåããããŸãã ãã®ãããªã³ãã³ããåä¿¡ãããšããªã¢ãŒãããã€ã¹ã§æªæã®ããããã°ã©ã ãæ£åžžã«èµ·åãããããšã瀺ããŸãã 以äžã¯ãTelnetãä»ããããããšææããããã€ã¹ãšã®ããåãã®äžéšã§ãã ã³ãã³ãã¯ããããããããªãã¬ãŒã¿ãŒã®åå ãªãã«ãããã«ãã£ãŠèªåçã«éä¿¡ãããŸãã
å³ ææããã·ã¹ãã ã§ãããã«ãã£ãŠå®è¡ãããã³ãã³ãã
ãããã¯æ¬¡ã®ã³ãã³ããå®è¡ããŸãã
- ææããããã€ã¹ã®ã³ãã³ãã©ã€ã³ïŒã·ã§ã«ïŒã«ã¢ã¯ã»ã¹ããŸãã
- echoã³ãã³ãã®å®è¡ã確èªããŸãã
- å®è¡äžã®ããã»ã¹ïŒ ps ïŒã®ãªã¹ããååŸããŠãã·ã¹ãã å ã§ã®ååšããã³ä»ã®æªæã®ããããã°ã©ã ã®ååšã確èªããŸãã
- chmodã³ãã³ãã®ååšã確èªããŸãã
- / proc / cpuinfoã®å 容ãååŸããŸãã
ãã®æç¹ã§ã¯ãMooseã¯ãŸã ãªã¢ãŒãã·ã¹ãã ã«ææããŠããŸããã ã¬ããŒãCïŒCãµãŒããŒã«ã¡ãã»ãŒãžãéä¿¡ããŸãããã®ãµãŒããŒã«ã¯ã被害è ã«é¢ããTelnetã§åä¿¡ããæ å ±ãå«ãŸããŠããŸãã
以äžã¯ãææããã·ã¹ãã ã®ç¶æ ãç¹åŸŽä»ããããããã£ãŒã«ãïŒäžèšã®è¡šãåç §ïŒã§ãïŒè¢«å®³è ã«é¢ããæ å ±ïŒã
ã¬ããŒãCïŒCãµãŒããŒã¯ã被害è ã®ã·ã¹ãã ã§å®è¡ããããã®é£èªåãããã³ãã³ãã§å¿çããŸãã
ã·ã¹ãã ææã®ç¬¬2段éã§ã¯ãLinux / Mooseã¯CïŒCãµãŒããŒã¡ãã»ãŒãžããã³ãã³ãããã±ãŒãžã解èªããTelnetã§å®è¡ããããšããŸãã ãããŒãããŠå®è¡ããªã©ã®ã³ãã³ãã®ã¿ã䜿çšããããšã確èªããŸããããã¢ãŒããã¯ãã£èªäœã¯æè»æ§ããããæ»æè ãå¿ èŠãªã³ãã³ããå®è¡ã§ããŸãã ãããã®ã³ãã³ãã®1ã€ã以äžã«ç€ºããŸããwgetããŒã«ã¯ãæªæã®ããã³ã³ãã³ããããã€ã¹ã«ããŠã³ããŒãããããã«äœ¿çšãããŸãã
å³ è¢«å®³è ã®ã³ã³ãã¥ãŒã¿ãŒã«æªæã®ãããã¡ã€ã«ãããŠã³ããŒãããŠå®è¡ããŸãã
æ»æè ã¯å¥ã®ã¢ãããŒãã䜿çšããŠã·ã¹ãã ã§æªæã®ããã³ãŒããå®è¡ããŸã;ãã®ããã ãšã³ãŒã³ãã³ãã®åºåã¯ç¹å®ã®ãã¡ã€ã«ã«æžã蟌ãŸããå ¥åãšããŠãã€ããªããŒã¿ïŒå®è¡å¯èœã³ãŒãïŒãåãåããŸããã
å³ è¢«å®³è ã®ã³ã³ãã¥ãŒã¿ãŒã«æªæã®ãããã¡ã€ã«ãããŠã³ããŒãããŠå®è¡ããŸãã
ãã®æç¹ã§ãããã€ã¹ã¯æ¢ã«ãã«ãŠã§ã¢ã«ææããŠããŸãã ããã«ãLinux / Mooseã¯CïŒCãµãŒããŒããè¿œå ã®æ§æãã©ã¡ãŒã¿ãŒãååŸããããã€ã¹äžã§æªæã®ãã掻åãç¶ç¶ã§ããŸãã
ãã®ãããª2段éã®ææã¡ã«ããºã ã«ãããã¬ããŒãCïŒCãµãŒããŒã¯ãããããããã€ã¹ã®ç°å¢ã¿ã€ãã«é¢ããæ å ±ããµãŒããŒã«éä¿¡ãããããææããã¢ãŒããã¯ãã£ã®ã¿ã€ãã«å¯Ÿå¿ããELFå®è¡å¯èœãã¡ã€ã«ã®ã¿ã€ããæ£ç¢ºã«ãããã«è»¢éã§ããŸãã ãŸããããããããå šäœãæŽæ°ããããšãªããæ°ãããã©ãããã©ãŒã ã䟵害ããæ©èœãè¿œå ãããšããå©ç¹ããããŸãã ãããè¡ãã«ã¯ãCïŒCãµãŒããŒã¯å¿ èŠãªãã¡ã€ã«ãæå®ããã ãã§ãã
以äžã¯ãCïŒCãµãŒããŒãããããæ§æã§ããæ§æãã©ã°ã§ãã
ããã«è©³çŽ°ãªèª¬æãå¿ èŠãª3ã€ã®ãã©ã¡ãŒã¿ãŒïŒ cnccfg_flag_hijackdns ã cnccfg_hijackdns1_ip ã cnccfg_hijackdns2_ip ã æªæã®ããDNSã«ãŒã¿ãŒæ§æãã€ã³ã¹ããŒã«ããããã«äœ¿çšãããŸãã æåã®ãã©ã°ãæå¹ã«ãªã£ãŠããå Žåãã·ã§ã«ã«å ¥ãåã«ãTelnetã³ã³ãœãŒã«ã§ãããã«ãã£ãŠæ¬¡ã®ã³ãã³ããå®è¡ãããŸãã
ãã«ãŠã§ã¢ã¯ãã«ãŒã¿ãŒã䜿çšããæ£åœãªDNSãµãŒããŒã®ã¢ãã¬ã¹ãæªæã®ããã¢ãã¬ã¹ã«æžãæããããšããŠããããšãããããŸãã ããŸããŸãªçš®é¡ã®ã«ãŒã¿ãŒãããŸããŸãªãŠãŒã¶ãŒã€ã³ã¿ãŒãã§ã€ã¹ãŸãã¯ã³ãã³ãïŒ ããã¹ãããŒã¹ã®ãŠãŒã¶ãŒã€ã³ã¿ãŒãã§ã€ã¹ ïŒ ããµããŒãããŠããããããããã¯ãã®ãããªã³ãã³ããããã€ãå®è¡ããŸãã TP-LinkãZyxelãZhoneãNetgearãªã©ã®ã«ãŒã¿ãŒã¡ãŒã«ãŒã¯ããããã®ããŒã ã®å°ãªããšã1ã€ããµããŒãããŠããŸãã ãããã¯ãã³ãã³ãã®å®è¡æã«ããŸããŸãªç¶æ³ãåŠçããããšãæäŸããŸãããã代ããã«ãäžèšã®DNSãã€ãžã£ãã¯æäœã®æåã«é¢ä¿ãªãå®è¡ãç¶ç¶ããŸãã
ãã¡ã€ã¢ãŠã©ãŒã«ãã€ãã¹
Linux / Mooseã®æãèå³æ·±ãåŽé¢ã®1ã€ã¯ãã¬ã¬ã·ãŒãã¡ã€ã¢ãŠã©ãŒã«ã®ä¿è·ããã€ãã¹ããªããããããã¯ãŒã¯å ã®ã³ã³ãã¥ãŒã¿ãŒã«ææããèœåã§ãã ããã«ã¯2ã€ã®ç°ãªãã¡ã«ããºã ã䜿çšãããŸãã1ã€ç®ã¯åŒ±ããã¡ã€ã¢ãŠã©ãŒã«èšå®ã«äŸåãã2ã€ç®ã¯NATãã©ããŒãµã«ã«äŸåããŸã ã
åã«ç€ºããããã«ããããã¯äŸµå®³ãããã«ãŒã¿ãŒã®ãããªãã¯IPã¢ãã¬ã¹ãç¥ã£ãŠããŸãã 次ã«ããã®IPã¢ãã¬ã¹ã¯ãåããµããããäžã®ããã€ã¹ã«ææããããã«ãè¿ãã«éããŠããTelnetããŒãã§IPã¢ãã¬ã¹ãããã«ã¹ãã£ã³ããããã®åºç€ãšããŠäœ¿çšãããŸãã ãããã¯ã/ 15ãã¹ã¯ã䜿çšããŠãã«ãŒã¿ãŒã®å€éšã¢ãã¬ã¹ã®åããµããããå ã®ããŸããŸãªIPã¢ãã¬ã¹ãåæããŸãã ããã«ããããããã¯ãã¡ã€ã¢ãŠã©ãŒã«ãå¹æçã«ãã€ãã¹ããã¯ãŒã ããã®æ¬äœã®ã³ããŒãé åžã§ããããã«ãªããŸãã
å³ åããµãããããŸãã¯ã€ã³ã¿ãŒãããäžã®ããã€ã¹äŸµå®³ã¹ããŒã ã
äžã®å³ã¯ããªãã¬ãŒã¿ãŒãã«ãŒã¿ãŒã®ã¢ãã¬ã¹ã«è¿ãIPã¢ãã¬ã¹ã®ç¯å²ãã¹ãã£ã³ããããšã«çŠç¹ãåãããŠããããšã瀺ããŠããŸãã é»ã®ç·ã¯ãããã¯ãŒã¯æ¥ç¶ã瀺ããé»è²ã®ç·ã¯ãããã¯ãŒã¯æ¥ç¶ã瀺ããŸãã æ瀺ãããæé ã以äžã«èª¬æããŸãã
- ææããã«ãŒã¿ãŒã®ãããã¯ãã°ããŒãã«ãããã¯ãŒã¯äžã®å¥ã®ããã€ã¹ã«ææããããšããŸããããã®è©Šã¿ã¯ãã¡ã€ã¢ãŠã©ãŒã«ã«ãã£ãŠãããã¯ãããŸãã
- ææããã«ãŒã¿ãŒã®ãããã¯ãã°ããŒãã«ãããã¯ãŒã¯äžã®ããã€ã¹ã«ææããããšãã䜿çšãããŠããã»ãã¥ãªãã£èšå®ã匱ãããããã¡ã€ã¢ãŠã©ãŒã«ãæ£åžžã«ãã€ãã¹ããŸãã
- ãã¡ã€ã¢ãŠã©ãŒã«ãåããµããããããã®Telnetãä»ããã«ãŒã¿ãŒãžã®æ¥ç¶ãèš±å¯ããŠããå Žåãææããã«ãŒã¿ãŒã®ãããã¯ãåãISPãµããããããä»ã®ã«ãŒã¿ãŒã«ææããå¯èœæ§ãé«ããªããŸãã
ææããã«ãŒã¿ãŒã®ç£èŠäžãããããã°ããŒãã«ãããã¯ãŒã¯äžã®ä»»æã®ã¢ãã¬ã¹ãã¹ãã£ã³ããå Žåãããã«ãŒã¿ãŒã¢ãã¬ã¹ã«è¿ãIPã¢ãã¬ã¹ãã¹ãã£ã³ããæ¹ããæ°ããããã€ã¹ãžã®Telnetã¢ã¯ã»ã¹ã3åæåããããšã«æ°ä»ããŸããã ç§ãã¡ã®æèŠã§ã¯ããã®åŸåã¯NATã®äœ¿çšãšåŒ±ãèšå®ã®ã«ãŒã¿ãŒã®ååšã«ãã£ãŠèª¬æãããŸãã ããã¯ãææ°ã®ãããã¯ãŒã¯ã®è€éããšãããããæäŸãããã¡ã€ã¢ãŠã©ãŒã«ã«å¯ŸããŠèšå®ããå¿ èŠã®ããã«ãŒã«ã®æ°ãèãããšãé©ãããšã§ã¯ãããŸããã ããã«ãAvishai Wool ãšããå°é家ã«ãããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®èª¿æ»ã§ã¯ããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã®è€éããšæ°ãããã³èšå®æã«èš±å¯ããããšã©ãŒã®æ°ãšã®æ確ãªçžé¢é¢ä¿ã瀺ãããŠããŸãã ãã®èª¿æ»ã¯ãTelnetãä»ãããªãŒãã³ã¢ã¯ã»ã¹ã®æäŸãããããééãã®1ã€ã§ããããšã瀺ããŠããŸãã
æªæã®ããããã°ã©ã ã¯ã/ 32ãµããããã®ã¢ãã¬ã¹ãšã«ãŒãããã¯ïŒ127.0.0.1ïŒãªã©ã®ç¹å¥ãªã¢ãã¬ã¹ãåé¿ããªãããã·ã¹ãã ã«æ瀺ãããåIPã€ã³ã¿ãŒãã§ãŒã¹ã®ã¢ãã¬ã¹ç¯å²ãã¹ãã£ã³ããè¿œå ã®ã¹ã¬ãããèµ·åããŸãã
å³ ã«ãŒãããã¯ã¢ãã¬ã¹ã確èªããŠãã ããã
å³ ãµãããããã¹ã¯ã確èªããŸãã
äžã®å³ã«ç€ºãããŠããããã«ãããŒã«ã«ISPãããã¯ãŒã¯ïŒLANïŒãžã®å ¥ãå£ãå¶åŸ¡ãããã¡ã€ã¢ãŠã©ãŒã«ãæ£ããæ§æãããŠããªãå ŽåãMooseã¯ãã®ãããã¯ãŒã¯äžã®ã«ãŒã¿ãŒã®1ã€ã«ææããå¯èœæ§ããããŸãã ææãæåãããšããã®æ°ããææããã«ãŒã¿ãŒã¯æ°ãã被害è ã®ã¹ãã£ã³ããã»ã¹ãéå§ããŸããããã«ããããã©ãã£ãã¯ã«é¢ãããã¡ã€ã¢ãŠã©ãŒã«ã«ãŒã«ã¯å€éšã®ã«ãŒã«ãããã¯ããã«äœãããããã®ãããã¯ãŒã¯ã§æåããå¯èœæ§ãå€§å¹ ã«é«ãŸããŸãã
ãã®ã¿ã€ãã®èªåãããã¯ãŒã¯äŸµå ¥ïŒ ãããã ïŒã¯ã次ã®çç±ã§éåžžã«èå³æ·±ããã®ã§ãã
- äžéšã®ãããã¯ãŒã¯ã¯ãå€éšã§äœæ¥ããå Žåã®èšå®ãšã¯ç°ãªãããããã¯ãŒã¯å ã®ãã¡ã€ã¢ãŠã©ãŒã«ã«åŒ±ãã»ãã¥ãªãã£èšå®ãæ®ããŠããŸãã
- ã«ãŒã¿ãŒã¯ãã€ã³ã¿ãŒãããã®ã°ã©ãã®ããŒããŸãã¯é ç¹ãšããŠè¡šãããšãã§ããŸãã 1ã€ã®é ç¹ã«ã¢ã¯ã»ã¹ãããšãåŸç¶ã®å€ãã®é ç¹ãžã®éãéãããŸãã
- ãã¹ãŠã®ã¿ã€ãã®ãããã¯ãŒã¯ã¯ããããããããªãã¬ãŒã¿ãŒã«ãã£ãŠèå¥ã§ããŸãïŒããŸããŸãªãµãŒãããŒãã£ã¡ãŒã«ãŒãããžãã¹ããŒãããŒããã©ã€ããŒãã¯ã©ãŠãããšã¯ã¹ãã©ããããªã©ã
- ãããã¯ãŒã¯æ©åšãã³ããŒã®ãµãŒããŒããäŒçµ±çã«Telnetã§ç®¡çãããŠããŸãã
- ããŒã ã«ãŒã¿ãŒããã®ä»ã®ããã€ã¹ã¯éåžžããŠãŒã¶ãŒèªèº«ãå·¥å Žèšå®ã«æ»ããŸããããã«ãããISPãã¯ã©ã€ã¢ã³ãã«éä¿¡ããåã«å¿ èŠãªãã®ã«å€æŽããå Žåã§ããããã©ã«ãã®ã»ãã¥ãªãã£èšå®ã§è匱ã«ãªããŸãã
NATãã©ããŒãµã«
ãããã¯ãŒã¯äŸµå ¥ã«é¢é£ããæªæã®ããããã°ã©ã ã®ãã1ã€ã®èå³æ·±ãæ©èœã¯ã NATãã©ããŒãµã«æ©èœã®å®è£ ã§ãã ãã®ããããããã¯NAT ïŒ STUN ïŒããã³NATã®åšãã®ãªã¬ãŒã䜿çšãããã©ããŒãµã« ïŒ TURN ïŒãããã³ã«ã®ã»ãã·ã§ã³ãã©ããŒãµã«ãŠãŒãã£ãªãã£ã 䜿çšããŸããããã«ãããå€éšã®NATã®èåŸã«ããããŒã«ã«ãããã¯ãŒã¯ãããããã¯ãŒã¯ãã±ããããããŒããã£ã¹ãã§ããŸãã
æ§æCïŒCãµãŒããŒã¯ããããã«NATã®å€éšã«ãããã¯ãŒã¯ãã±ãããéä¿¡ããããã«å¿ èŠãªæ å ±ãæäŸããŸããã«ãŒã¿ãŒã®ãããªãã¯ã¢ãã¬ã¹ãšãªã¬ãŒãµãŒããŒïŒãªã¬ãŒCïŒCãµãŒããŒïŒã®ã¢ãã¬ã¹ã§ãã 調æ»å šäœãéããŠããªã¬ãŒãµãŒããŒã®IPã¢ãã¬ã¹ã¯åžžã«93.190.140.221ã§ããã 以äžã¯ãNAT Traversalæ©èœã®å®è¡ã«åœ±é¿ãããããã®æ§æå€ã§ãã
ããããNATãã©ããŒãµã«æ©èœã䜿çšããå ŽåãCïŒCãªã¬ãŒãµãŒããŒãšå¯Ÿè©±ãã2ã€ã®å®è¡ã¹ã¬ãããäœæããŸãã ãã±ããéä¿¡æäœïŒäžç¶ïŒã¯ããããã«ãã£ãŠCïŒCãµãŒããŒããçãééã§èŠæ±ãããŸãïŒ cnccfg_relaycnc_sleepãã©ã¡ãŒã¿ãŒïŒã ãµãŒããŒã¯ããã®ãããªèŠæ±ã«1çµãŸãã¯IP_address-portã®ãã¢ã®ã»ããã§å¿çããŸãã
ããããCïŒCãªã¬ãŒãµãŒããŒã«éä¿¡ããæåã®ãã±ããã¯ãæªæã®ããããã°ã©ã ã®æ¬äœã«çµã¿èŸŒãŸããŠããŸãã
ãµãŒããŒå¿çã«ã¯æ¬¡ã®æ§é ããããŸãã
以äžã¯ãããããåŠçã§ããNATãã©ããŒãµã«æäœã³ãã³ãã§ãã
以äžã¯ãã®ãããªçãã®äŸã§ãã
- TCPãã³ããªã³ã°ïŒTCPãã³ãã«ïŒã0ãªã©ãCïŒCãªã¬ãŒãµãŒããŒã«ãã£ãŠèŠæ±ãããåäœã¢ãŒãã
- ãªã¢ãŒããã³ãã«ããŒãïŒãããã¯ãŒã¯ãã€ãé ïŒã80ã
- ãªã¢ãŒãIPãã³ãã«ã¢ãã¬ã¹ïŒãããã¯ãŒã¯ãã€ãé ïŒã192.168.1.1ã
次ã«ããããã¯ãã³ãã«ã®å®å ã¢ãã¬ã¹ã«æ¥ç¶ããŸãã æ¥ç¶ã«æåãããšããããã¹ããªãŒã ã®1ã€ã2ã€ã®ãœã±ããããµããŒãããCïŒCãªã¬ãŒãµãŒããŒãšã®éã®ãã©ãã£ãã¯ã®äŒéãè¡ããŸãã
å³ åäœäžã®ãã³ããªã³ã°NATãã©ããŒãµã«ã
ãã®ãããªãã³ããªã³ã°ã«ããããããããããªãã¬ãŒã¿ãŒã¯ããã¡ã€ã¢ãŠã©ãŒã«ãŸãã¯NATèšå®ã«ããã°ããŒãã«ãããã¯ãŒã¯ããã¢ã¯ã»ã¹ã§ããªãå Žåã§ããææããã«ãŒã¿ãŒã«ã¢ã¯ã»ã¹ã§ããŸãã ãã®è åšã®èª¿æ»ã§ã¯ãåè¿°ã®ããã«ããœãŒã·ã£ã«ãããã¯ãŒã¯ã§ã®äžæ£è¡çºã«ãããããã³ããªã³ã°ã¡ã«ããºã ã䜿çšããŠããããšã瀺ãããŸããã Sleepã®ãããªã³ãã³ãã ãã§ãªããTCPãªã»ããïŒRSTïŒã¹ããŒã¿ã¹ã®ãµãŒããŒããã®å¿çããã芳å¯ããŸããã
代ççµç¹
Linux / Mooseãæåã«è¡ãããšã®1ã€ã¯ãçä¿¡ããŒã10073ãäœæããŠçä¿¡ãããã·æ¥ç¶ãåä¿¡ããããšã§ãã ã«ãŒã¿ãŒäžã®ãã®ãããªéããŠããããŒãã®ååšã¯ãããã€ã¹ã®äŸµå®³ã瀺ããŠãããããããæ°ããããã€ã¹ãèŠã€ããŠææããããšãã«äœ¿çšããŸãã ããããå¥ã®ããã€ã¹ã®ãã®éããŠããããŒãã«ã¢ã¯ã»ã¹ãããšãæçšãªããŒã¿ãéä¿¡ããã«TCPãã³ãã·ã§ã€ã¯ã«ã€ãªãããŸãã 以äžã¯ãçä¿¡æ¥ç¶ã®åŠçãšãæ¥ç¶ãèš±å¯ããããã¯ã€ããªã¹ãã®ã¡ã³ããŒã·ããã®IPã¢ãã¬ã¹ã®ãã§ãã¯ã«ç¹åããMooseã³ãŒãã§ãã
å³ èš±å¯ãããæ¥ç¶ã®ãªã¹ãã§IPã¢ãã¬ã¹ã確èªããŸãã
is_in_whitelisté¢æ°ã¯ãCïŒCãµãŒããŒã«ãã£ãŠä»¥åã«æäŸãããããã¯ã€ããªã¹ããå ã®æ¥ç¶ãœãŒã¹ã®IPã¢ãã¬ã¹ããã§ãã¯ããŸãã ã¢ãã¬ã¹ããã®ãªã¹ãã«ããå Žåããã©ã¡ãŒã¿ãŒãå«ããœã±ããèšè¿°åã¯ãããã«åŠçããããã«å¥ã®ã¹ã¬ããã«æž¡ãããŸãã
ãããã·ãµãŒããŒã¯ãŒã¯ãããŒã¯ããã¯ã€ããªã¹ãã«ç»é²ãããIPã¢ãã¬ã¹ã®ãããã·æ¥ç¶ãåŠçããŸãã æ¥ç¶åŸããããã·ãµãŒããŒïŒãããïŒã¯ãœã±ãããã1ãã€ããèªã¿åãã䜿çšãããããã³ã«ãŸãã¯æ©èœã調æŽããŸãã
ãããã®ãããã³ã«ã¯ãã¹ãŠããããã·æ¥ç¶ãæŽçããããã®å€å žçãªãã®ã§ããã€ãŸãã誰ãã䟵害ãããããã€ã¹ãŸãã¯ã³ã³ãã¥ãŒã¿ãŒã®ãªãœãŒã¹ãå¯ãã«äœ¿çšããŠãã©ãã£ãã¯ãçæããããšããŠããç¶æ³ã§ãã ãã®å Žåãããã€ã¹ã®IPã¢ãã¬ã¹ã¯è©å€ãè¯ããããæ»æè ã¯ããã䜿çšããŠãåºåã®ã¯ãªãã¯ã®çæãã¹ãã ã®éä¿¡ããœãŒã·ã£ã«ãµãŒãã¹ã§ã®äžæ£è¡çºã®å®è¡ãªã©ã®æäœãå®è¡ããŸãã æçµçã«ããã®IPã¢ãã¬ã¹ã¯è¯å®çãªè©å€ã倱ãããã©ãã¯ãªã¹ãã«ç»é²ããããã®ç¶æ³ã®èª¿æ»ã«ã€ãªãããŸãã
æªæã®ããããã°ã©ã ã¯ãSOCKS 4ãããã³ã«ã®æšæºå®è£ ã䜿çšããŠãããææããããã€ã¹ããæ§æãã©ã¡ãŒã¿ãŒã§æå®ããããã¹ããžã®ãã©ãã£ãã¯ã®TCPãã³ããªã³ã°ãç·šæã§ããŸãã æåã®ãã³ãã·ã§ã€ã¯åŸããã©ãã£ãã¯ã¯ãææããã€ã¹ãšãµãŒããŒïŒãã¹ãïŒã®éã§åæ¹åã«ééçã«éä¿¡ãããŸãã
å³ SOCKS 4ãã³ããªã³ã°ã®äŸã
æåã®æ®µéïŒ1ïŒã§ã¯ããããã SOCKS亀æã䜿çšããããããã³ã«ã«ã€ããŠãããã«éç¥ãããŸãã ãããïŒãããã·ãµãŒããŒïŒãæ£åžžãªæ¥ç¶ïŒ0x5AïŒã®ã¹ããŒã¿ã¹ã§å¿çãããšããããã·ã¯ã©ã€ã¢ã³ãïŒãããããããªãã¬ãŒã¿ãŒïŒã¯ã¿ãŒã²ãããµãŒããŒïŒ2ïŒã«HTTPãªã¯ãšã¹ããéä¿¡ããææããã«ãŒã¿ãŒã§åæãããã·ãå®è¡ããŸãã ãã®èŠæ±ãžã®å¿çã§ããããã¯å®å ãµãŒããŒïŒInstagramïŒããåä¿¡ããå¿çãè¿ããŸãïŒ3ïŒã ãã®å ŽåãèŠæ±ã¯HTTPãããã³ã«ã®Locationãã£ãŒã«ããä»ããŠæ¥ç¶ãHTTPSã»ãŒãã¢ãŒãã«ããããšã§ããã
SOCKS 4ãããã³ã«ã¯ãæ»æè ã«ãã£ãŠæãé »ç¹ã«äœ¿çšãããŸããã
ãããã³ã«ã®å¥ã®ããŒãžã§ã³ã§ããSOCKS 5ãããµãŒããŒãšãã¹ãéã®TCPãã³ãã«ãç·šæããããã«äœ¿çšãããŸãã Mooseã¯ãã®ããŒãžã§ã³ã®ãããã³ã«ãå®å šã«ã¯å®è£ ããããèªèšŒãªãããšåŒã°ãã1ã€ã®èªèšŒæ¹æ³ã®ã¿ããµããŒãããŸãã ãã®ãããªéšåçãªãããã³ã«ãµããŒãã¯ãäžèŠãªã¯ã©ã€ã¢ã³ãããããã«æ¥ç¶ããã®ãé²ãããã«ãã§ã«ãã¯ã€ããªã¹ãæ¹åŒã䜿çšããŠããããããªãã¬ãŒã¿ãŒã«ãšã£ãŠã¯ååã§ãã ãã®ã¢ãããŒãã䜿çšãããšãããŸããŸãªã¯ã©ã€ã¢ã³ãã¢ããªã±ãŒã·ã§ã³ããµããŒãã§ããŸãã
ãããã«ã¯ããããã·çšã®å¥ã®ãããã³ã«-HTTP / 1.1ã®å®è£ ãå«ãŸããŠããŸãã ãã®ãããã³ã«ã®å®è£ ã³ãŒãã¯ãHTTPããããŒã調ã¹ãå®å ãã¹ãã«æ¥ç¶ããŠæ¥ç¶ããåä¿¡ããããŒã¿ãã¯ã©ã€ã¢ã³ãã«éãè¿ããŸãã ãŸããã»ãã¥ã¢ãªãããã³ã«ããŒãžã§ã³ã§ããHTTPSã䜿çšããŠãããšãã«ãCONNECTã¡ãœãããååšããå Žåã¯ãCONNECTã¡ãœãããåŠçããŸãã
å³ CONNECTã¡ãœããã®ç¢ºèªã
CïŒCæ§æãµãŒããŒã¯ãããã«IPã¢ãã¬ã¹æ§æã®ãã¯ã€ããªã¹ããéä¿¡ããŸãããã®ãªã¹ãã«ã¯ç¹å¥ãªãã©ã°ãå«ãŸãããã®ãã©ã°ãèšå®ãããšIPã¢ãã¬ã¹ãããŒã25ïŒSMTPïŒã465ïŒSMTPSïŒã587ãžã®ãããã·æ¥ç¶ã䜿çšã§ããããã«ãªããŸãïŒæåºïŒã ã»ãšãã©ã®IPã¢ãã¬ã¹ã§ã¯ããã®ãã©ã°ã¯ãªãã«ãªã£ãŠããŸãã
æããã«ãäžèšã®ã¡ã«ããºã ã«ããããããããããªãã¬ãŒã¿ã¯ã䟵害ãããããã€ã¹ã®IPã¢ãã¬ã¹ã®å¥œè©ãéåžžã«æè»ã§ç®ç«ããªãæ¹æ³ã§äœ¿çšã§ããŸãã
ã¹ããã¡ãŒé¢æ°
Linux / Mooseã«ã¯ã¹ããã¡ãŒæ©èœãå«ãŸããŠããŸããã€ãŸããã«ãŒã¿ãŒãééãããã©ãã£ãã¯ããªãã¹ã³ã§ããŸãã ãã®ãããªæ©èœã¯ã cnccfg_flag_scanner_snifferãšcnccfg_flag_thd_snifferã® 2ã€ã®ç°ãªãæ§æãã©ã°ã«ãã£ãŠæå¹ã«ãªããŸãã ãããã®ãã©ã°ãã¢ã¯ãã£ããªå Žåãæªæã®ããããã°ã©ã ã¯ãå°ãªããšã101ãã±ãããåä¿¡ãããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ããšã«åå¥ã®å®è¡ã¹ã¬ãããäœæããŸãã ãã®ãã§ãã¯ã¯ããã©ãã£ãã¯ãééããªãã€ã³ã¿ãŒãã§ã€ã¹ã®ã¹ã¬ããã®äœæãåé¿ããããã«å®è¡ãããŸãã
ãã©ãã£ãã¯ããªãã¹ã³ããäœæ¥ãè¡ãã¹ã¬ããã¯éåžžã«åçŽã§ãã çã®ãœã±ãããäœæãããããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ããã¹ãŠã®ãã±ããã®ãããã¹ãã£ã¹ãã£ããã£ã¢ãŒãã«èšå®ããŸãã ãã®åŸããœã±ããããããŒã¿ãèªã¿åãããã«recvfromé¢æ°ãã«ãŒãã§å®è¡ãããŸãã
å³ ãããã¯ãŒã¯ãã©ãã£ãã¯ãèããŸãã
æªæã®ããããã°ã©ã ã¯TCPãã±ããã®ã¿ã«é¢å¿ããããCïŒCæ§æãµãŒããŒã«ãã£ãŠãããã«éä¿¡ãããsnfcfg_id_needleæ§æãã©ã¡ãŒã¿ãŒãä»ããŠãªãã¬ãŒã¿ãŒã«ãã£ãŠæå®ãããããŸããŸãªè¡ãæ€çŽ¢ããŸãã åæãããµã³ãã«ã¯ã次ã®è¡ãæ€çŽ¢ããããã«æ§æãããŸããã
- twll =
- twid =
- LOGIN_INFO =
- c_user =
- ds_user_id =
- SAPISID =
- APISID =
- PLAY_ACTIVE_ACCOUNT =
åè¿°ã®ããã«ããããã®è¡ã¯ããœãŒã·ã£ã«ãµãŒãã¹Webãµã€ããåç §ããHTTP CookieããŒã¿ã§ãã
ããããæå®ãããããŒã¿ãæ€åºãããšããã«ãã€ãŒãµããããIPãTCPããããŒãããã³ãã±ããããŒã¿ãå«ããããã¯ãŒã¯ãã±ããå šäœããé£èªåããã圢åŒã§ã¬ããŒãCïŒCãµãŒããŒã«éä¿¡ãããŸãã ãã®ãããªã¡ãã»ãŒãžã®åœ¢åŒã以äžã«ç€ºããŸãã
ãµãŒããŒã¯ã次ã®æ§é ã®ãã±ããã§å¿çããŸãã