ä»æ¥ãç¬ã§ããã圌ã㯠ãªã¢ãŒãã³ã³ãããŒã«ãæãã€ããŸãã ã
ã管çã®æŠèŠãã·ãªãŒãºã«æ»ã£ãŠããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒã§å®è¡å¯èœããã°ã©ã ãå®è¡ããããã®ãªãã·ã§ã³ã«ã€ããŠã話ããããšæããŸãã ãã®èšäºã¯ãéäžç®¡çã·ã¹ãã ããŸã æã£ãŠããªãããã¯ãŒã¯ã¹ããŒã·ã§ã³ãšãµãŒããŒãæåã§ãã€ãã¹ããããšã®éå±ãããã§ã«ç解ããŠãã人ã«ãšã£ãŠèå³æ·±ããã®ã§ãã ãŸãã¯ãã¹ããŒããã³ããããªãããã«ã¿ãŒã³ããŒãœãªã¥ãŒã·ã§ã³ã«èå³ããªã人ã
ãã®ãããªããã°ã©ã ã®èµ·åãå¿ èŠãªçç±ãšããŠã誰ããSMBv1ããã§ãã¯ããæŽæ°ãããŠã³ããŒãããããã«æ¥ãã ãšããPetya \ Non-Petyaã§æè¿ã®ãã¹ããªãŒãåŒçšããããšãã§ããŸãã ã¯ãããã®æ¹æ³ã䜿çšããŠãã€ã³ãã³ããªãååŸããããç·æ¥ããããã€ã³ã¹ããŒã«ãããããããšãã§ããŸãã
ããããããã æšæž\ Confickerã®æµè¡ã®éã«çµç¹ã§ä»äºãåŸãã äŒç€Ÿã®IPã®ãã¹ãŠãåé¡ãªããã©ããã確èªããæãç°¡åãªæ¹æ³ã¯ã Kido KillerãšåŒã°ããã«ã¹ãã«ã¹ããŒã®äŸ¿å©ãªãŠãŒãã£ãªãã£ã§ãããããã¯ããŠã€ã«ã¹ããã§ãã¯ããŠé€å»ããŸããã æã§æ°çŸå°ã®è»ã§ããã°ã©ã ãå®è¡ããã®ã¯é¢çœããªãã®ã§ãèªååã«ç²Ÿéããªããã°ãªããŸããã§ããã
* nixãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯éåžžããªã¢ãŒãã¹ã¿ãŒãã«SSHã䜿çšããŸãããWindowsã«ã¯ç æŒ ã§ç ã®ãããªããã°ã©ã ãã¹ã¯ãªãããå®è¡ããæ¹æ³ããããŸãã ããç¥ãããŠãããšããŸããã¯ãªäž»ãªãªãã·ã§ã³ãåæããŸãã ç¹ã«Microsoftããã§ã«ææ°ã®OSããåé€ããŠãããããtelnetãµãŒããŒã®ãããªæçœãªãã®ã«ã¯è§ŠããŸããã
æãªããã®ãå®çžŸã®ããæ¹æ³
Psexec
ããããããã¯ãããã°ã©ã ã®ãªã¢ãŒãèµ·åã«é¢ããŠæåã«é ã«æµ®ãã¶ãã®ã§ãã Mark Russinovich ã®ãŠãŒãã£ãªãã£ã¯ãWindows NTã®æ代ãã䜿çšãããŠãããçŸåšã䜿çšãããŠããŸãã ã¡ã€ã³é¢æ°ã«å ããŠãRunasãšããŠäœ¿çšããããšããã¿ãŒããã«ãµãŒããŒã®ãŠãŒã¶ãŒã»ãã·ã§ã³ã§ããã°ã©ã ãå®è¡ããããšãã§ããŸãã Psexecã䜿çšãããšãããã°ã©ã ãå®è¡ããããã»ããµã³ã¢ãšãã·ã¹ãã ã§ã®ãã®åªå 床ãæå®ããããšãã§ããŸãã
äŸãšããŠãã³ã³ãã¥ãŒã¿ãŒã®ãªã¹ãã«ããã»ã³ã»ãŒã·ã§ãã«ãªSMBã®è匱æ§ãã«ããŒããã¢ããããŒããã€ã³ã¹ããŒã«ãããŠãããã©ãããèŠãŠã¿ãŸãããã
psexec @computers.txt /u USER /p PASS cmd.exe /v /c ""systeminfo | find "KB4012212" || echo !computername! >> \\server\share\log.txt"""
computers.txtãã¡ã€ã«ã«ã¯ãã³ã³ãã¥ãŒã¿ãŒã®ãªã¹ããå«ãŸããŠããŸãã \\ *ã䜿çšããŠããã¡ã€ã³å šäœã§å®è¡ã§ããŸãã ã¯ãŒã¯ã¹ããŒã·ã§ã³ãŸãã¯ãµãŒããŒã®ååã¯ãæŽæ°ããã«ãã¡ã€ã«\\ server \ share \ log.txtã«è¡šç€ºãããŸãã ãã¡ã€ã³å ã«* nixãæèŒãããã³ã³ãã¥ãŒã¿ãŒãããå ŽåããŸãã¯Admin $管çãããã¯ãŒã¯ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ããªãå Žåããã®ã³ã³ãã¥ãŒã¿ãŒã§ã³ãã³ãã¯å®è¡ãããŸããããåŠçã¯ç¶è¡ãããŸãã æ¥ç¶ãè©Šè¡ããããã³ã«ã¹ã¯ãªãããããªãŒãºããªãããã«ããã«ã¯ã -nã¹ã€ããã䜿çšããŠã¿ã€ã ã¢ãŠããèšå®ã§ããŸãã
ã³ã³ãã¥ãŒã¿ãŒã®é»æºããªãã«ãªã£ãŠããå Žåãããã¯ããããŸããã ãããã£ãŠããã·ã³ã®å¯çšæ§ãäºåã«ç¢ºèªãããããã¡ã€ã«ã®å®è¡ã®æåãŸãã¯å€±æã«é¢ããæ å ±ãåéããããšããå§ãããŸãã
Psexecã®æ¬ ç¹ã«ã¯ããã®äŸ¿å©ããšäººæ°ã®ããã«ããŠã€ã«ã¹äœæè ããã䜿çšãããšããäºå®ãå«ãŸããŸãã ãã®ããããŠã€ã«ã¹å¯Ÿçã·ã¹ãã ã¯ããŠãŒãã£ãªãã£ããªã¢ãŒã管çã¿ã€ãã®å±éºãšããŠæ€åºããå ŽåããããŸãã
ããã©ã«ãã§ã¯ããªã¢ãŒããã·ã³äžã®ããã»ã¹ã¯Psexecãèµ·åãããŠãŒã¶ãŒãšããŠå®è¡ãããŸãã å¿ èŠã«å¿ããŠããŠãŒã¶ãŒåãšãã¹ã¯ãŒããæ瀺çã«èšå®ããããSYSTEMã¢ã«ãŠã³ãã䜿çšã§ããŸãã
WMIC
ãªããžã§ã¯ãæåWBEM管çæšæºã®å®è£ ã§ããWindows Management InstrumentationïŒ WMI ïŒã¯ãããŸããŸãªã°ã©ãã£ã«ã«ãŠãŒãã£ãªãã£ã䜿çšããŠWindowsã·ã¹ãã ã管çããããã«ãã䜿çšãããŸãã wbemtest.exeã¯ãWMIãæäœããããã®GUIãŠãŒãã£ãªãã£ãšããŠäœ¿çšã§ããŸãã
WMIã䜿çšããããã«ãã³ã³ãœãŒã«ããwmic.exeãäœæãããŸããã ããšãã°ãåã®äŸã®äžæ°å³ãªæ§é ã®ä»£ããã«ãã€ã³ã¹ããŒã«ãããæŽæ°ã確èªããã«ã¯ã次ã®ç°¡åãªã³ãã³ãã䜿çšã§ããŸãã
wmic /node:"servername" qfe get hotfixid | find "KB4012212"
/node:"@computers.txt "ã³ãã³ãã§ã³ã³ãã¥ãŒã¿ãŒã®ãªã¹ãã䜿çšããããšãã§ããŸãã
WMIã䜿çšããŠããã°ã©ã ãå®è¡ããããšãã§ããŸã-æ§æã¯éåžžã«ç°¡åã§ãã
wmic /node:"servername" process call create "cmd /c somecommands"
æ®å¿µãªãããPsexecãšã¯ç°ãªããã³ã³ãœãŒã«ã§åºåãååŸããããšã¯ã§ããŸãããã³ãã³ãã®çµæããã¡ã€ã«ã«åºåããå¿ èŠããããŸãã
ããã©ã«ãã§ã¯ããªã¢ãŒããã·ã³äžã®ããã»ã¹ã¯ãwmicãå®è¡ããŠãããŠãŒã¶ãŒãšããŠå®è¡ãããŸãã å¿ èŠã«å¿ããŠããŠãŒã¶ãŒåãšãã¹ã¯ãŒããæ瀺çã«èšå®ã§ããŸãã
ã°ã«ãŒãããªã·ãŒãšã¹ã¯ãªãã
åã®ãªãã·ã§ã³ããã¡ã€ã³ç°å¢ãå¿ èŠãšããªãã£ãå Žåããã¡ã€ã³ãå¿ èŠã§ãã ã¹ã¯ãªããã¯ããŠãŒã¶ãŒãã·ã¹ãã ã«ãã°ã€ã³ããã³ãã°ã¢ãŠããããšããããã³ã·ã¹ãã ã®ãªã³ãšãªããåãæ¿ãããšãã«ãµããŒããããŸãã ãã¹ãŠã®Windows管çè ããããã«åºããããã®ã§ããããã®äœ¿çšæ¹æ³ã«ã€ããŠã¯è©³ãã説æããŸãããããããæ¢ãå ŽæãæãåºãããŸãã
èµ·åããã³ã·ã£ããããŠã³æã«å®è¡ãããã¹ã¯ãªããã
ãŠãŒã¶ãŒãã·ã¹ãã ã«ãã°ã€ã³ããã³ãã°ã¢ãŠããããšãã«å®è¡ãããã¹ã¯ãªããã
ãŠãŒã¶ãŒã»ã¯ã·ã§ã³ã§æ§æãããã¹ã¯ãªããã¯ããŠãŒã¶ãŒã®ä»£ããã«ãã³ã³ãã¥ãŒã¿ãŒã»ã¯ã·ã§ã³ã§-SYSTEMã¢ã«ãŠã³ãã®äžã§å®è¡ãããŸãã
å²ãåœãŠãããã¿ã¹ã¯
ããªãèå³æ·±ãæ¹æ³ã§ãçããæš©å©ã«å€ããŸãã ã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ã¯ã schtasks.exeãŠãŒãã£ãªãã£ã䜿çšããŠã³ãã³ãã©ã€ã³ããäœæããå®è¡ããŠããåé€ã§ããŸãã ããã¥ã¡ã³ãã§æ§æã®è©³çŽ°ãèªãããšãã§ããŸããããã¡ã€ã³ç°å¢ã§ã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ã䜿çšããäŸãåæããŸãã ã³ã³ãã¥ãŒã¿ãŒã®é»æºããªãã«ãªã£ãŠãããã©ããã«é¢ä¿ãªããã³ãã³ããã§ããã ãæ©ãå®è¡ããå¿ èŠããããšããŸãã ãããè¡ãã«ã¯ãããããã°ã«ãŒãããªã·ãŒèšå®ã䜿çšããŸãã
ã³ã³ãã¥ãŒã¿ãŒãŸãã¯ãŠãŒã¶ãŒã®æ§æã§ãã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ã®ã€ã³ã¹ããŒã«ãæ¢ããŸã-ãèšå®-ã³ã³ãããŒã«ããã«ã®èšå®-ã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ãã
æ°ããã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ãäœæããŸãã
ASAPã³ãã³ããŸãã¯ã¹ã¯ãªãããå®è¡ããã«ã¯ããå³æã¿ã¹ã¯ïŒWindows 7以éïŒããäœæããå¿ èŠããããŸãã ã€ã³ãã©ã¹ãã©ã¯ãã£ã§Windows XPãå®è¡ããŠãããã·ã³ãçªç¶ãã£ãå Žåãã次ã®ã¿ã¹ã¯ïŒWindows XPïŒããå®è¡ãããŸãã
察å¿ããWMIãã£ã«ã¿ãŒã䜿çšããŠããã€ãã®ããªã·ãŒãäœæããããã¿ãŒã²ãã£ã³ã°ã䜿çšããŠïŒããšãã°ãåãWMIãã£ã«ã¿ãŒã䜿çšããŠïŒåãããªã·ãŒã§2ã€ã®ç°ãªãã¹ã±ãžã¥ãŒã«æžã¿ã¿ã¹ã¯ãäœæããããšã¯äŸ¡å€ããããŸãã ããã«ãããå€ãWindowsãšæ°ããWindowsãæ··åšããç°çš®ç°å¢ã§ã®ç«¶åãåé¿ã§ããŸãã
Windows XPãå®è¡ããŠããã³ã³ãã¥ãŒã¿ãŒã«ã®ã¿ããªã·ãŒãé©çšããWMIãã£ã«ã¿ãŒã®äŸïŒ
SELECT * FROM Win32_OperatingSystem WHERE Version LIKE "5.1%" AND ProductType = "1"
ãã以å€ã®å Žåãå²ãåœãŠãããã¿ã¹ã¯ãäœæããæé ã¯ç°¡åã§ãã å¯äžã®ããšã¯ãã¿ã¹ã¯ãåèµ·åãå¿ èŠãšããªãå ŽåããäžåºŠé©çšããŠåé©çšããªããé ç®ããã§ãã¯ããããšãå¿ããªãã§ãã ããã
å³æã¿ã¹ã¯ã¯äžåºŠã ãéå§ããŸãã
ãããã®ã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ã䜿çšããå Žåãã³ã³ãã¥ãŒã¿ãŒãã°ã«ãŒãããªã·ãŒã®æŽæ°ãåä¿¡ãããšããã«ããã°ã©ã ãéå§ãããŸãã ããã¯äŸ¿å©ã§ããPsexecãšwmicã®å Žåã¯ã³ã³ãã¥ãŒã¿ãŒã®å¯çšæ§ã確èªããå¿ èŠã¯ãªããã°ã«ãŒãããªã·ãŒã¹ã¯ãªããã®å Žåã®ããã«ãŠãŒã¶ãŒã«ãã·ã³ã®åèµ·åã匷å¶ããå¿ èŠã¯ãããŸããã å¿ èŠã«å¿ããŠããèšå®-Windowsæ§æ-ãã¡ã€ã«ãã»ã¯ã·ã§ã³ã§ã¹ã¯ãªãããã¡ã€ã«ãããŒã«ã«ã«ã³ããŒã§ããŸãã
ã¹ã±ãžã¥ãŒã«ãããã¿ã¹ã¯ã«ãããSYSTEMãå«ããããã°ã©ã ãå®è¡ããããã®ãŠãŒã¶ãŒåãæ瀺çã«èšå®ã§ããŸãã
ã¬ãžã¹ããªãéããŠ
ç·æ¥ã®å Žåã«åããŠããŠãŒã¶ãŒãã·ã³ã®ã¬ãžã¹ããªãå€æŽããã®ã¯å¥åŠãªãªãã·ã§ã³ã§ãã RunãŸãã¯RunOnceãã©ã³ãã䜿çšã§ããŸãã ãããã®è©³çŽ°ã«ã€ããŠã¯ã ããã¥ã¡ã³ããåç §ããŠãã ãã ã ã¬ãžã¹ããªèªäœã®å€æŽã¯ãã°ã«ãŒãããªã·ãŒãŸãã¯ã³ãã³ãã©ã€ã³ããå®è¡ã§ããŸããããšãã°ã次ã®ã³ãã³ãã䜿çšããŸãã
reg add \\COMPUTER\HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce /v script /t Reg_SZ /d "script.cmd"
ã¬ãžã¹ããªãã©ã³ãã«å¿ããŠãããã»ã¹ã¯ãã°ã€ã³ããŠãããŠãŒã¶ãŒãŸãã¯SYSTEMã¢ã«ãŠã³ãã䜿çšããŠå®è¡ãããŸãã
ã¹ã¿ãŒãã¢ãããã©ã«ããŒå ã®ã·ã§ãŒãã«ããã®ç·šéã人æ°ã®ãã&& script.cmdããã°ã©ã ãžã®ã·ã§ãŒãã«ããã®è¿œå ãªã©ãä»ã®æ¹æ³ããããŸããããããã®æ¹æ³ã¯æ¢ã«ãå¯èœã§ããå¿ èŠã§ã¯ãªããã·ãªãŒãºã«å«ãŸããŠããŸãã
ããã§ã¯ãæ°ããããŒã«ã«ç§»ããŸãããã
PowerShellãªãã®æ°ããæ¹æ³ãŸãã¯å Žæ
PowerShellã¯ããã®ååãæ£åœåããŠãWMIãRPCãWS-ManagementïŒWSManïŒã䜿çšããŠãªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒã«æ¥ç¶ã§ããŸãã åŸè ã®æ¹æ³ã䜿çšããã«ã¯ãäºåèšå®ãå¿ èŠã§ãã
äºåæ§æãå¿ èŠãšããªãã³ãã³ãã¬ããã«ã¯ãéåžžComputerNameãã©ã¡ãŒã¿ãŒããããŸãããSessionãã©ã¡ãŒã¿ãŒã¯ãããŸããã ãã®ãããªã³ãã³ãã¬ããã®ãªã¹ãã衚瀺ããã«ã¯ã次ã®ã³ãã³ãã䜿çšããŸã
Get-Command | where { $_.parameters.keys -contains "ComputerName" -and $_.parameters.keys -notcontains "Session"}
äžè¬çã«WSManãæ§æããã«ã¯ã Enable-PSRemoting-Forceã³ãã³ããå®è¡ããã ãã§ãã WinRMãªã¢ãŒã管çãµãŒãã¹ãéå§ãããã¡ã€ã¢ãŠã©ãŒã«ã«äŸå€ãç»é²ããŸã-ååãšããŠãããã¯ã°ã«ãŒãããªã·ãŒã䜿çšããŠãã¡ã€ã³å šäœã«å¯ŸããŠå®è¡ã§ããŸãã 詳现ã«ã€ããŠã¯ã ããã¥ã¡ã³ããåç §ããŠãã ããã
ãã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒãèŠæ±ãåãå ¥ããæºåãã§ããããé©åãªPowerShellã³ãã³ãã¬ããã䜿çšããŠæ¥ç¶ã§ããŸãã æ¥ç¶ããã¹ãããã«ã¯ã Test-WSManã³ãã³ãã¬ããã䜿çšããŸãã
æ¥ç¶ã確èªããŠãã ããã
ç¹å®ã®ã³ãã³ããŸãã¯ã¹ã¯ãªãããå®è¡ããã«ã¯ã Invoke-Commandã³ãã³ãã¬ããã次ã®æ§æã§äœ¿çšããŸãã
Invoke-Command -ComputerName COMPUTER -ScriptBlock { COMMAND } -credential USERNAME
COMPUTERã¯ã³ã³ãã¥ãŒã¿ãŒã®ååãCOMMAND âã¯ã³ãã³ãã®ååãUSERNAMEã¯å¿ èŠã«å¿ããŠãŠãŒã¶ãŒåã§ãã
ãªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒãããã£ã¹ã¯ã®å
容ã確èªããŸãã
èªååã®ããã§ã¯ãªããç¹å®ã®ã³ã³ãã¥ãŒã¿ãŒãå¶åŸ¡ããããã«æ¬æ Œçãªã³ã³ãœãŒã«ãååŸããå¿ èŠãããå Žåã¯ã Enter-PSSessionã³ãã³ãã¬ããã䜿çšã§ããŸãã
ãªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒã®ã³ã³ãœãŒã«ã§äœæ¥ããŸãã
JEAã䜿çšãããšããã®ãããªã»ãã·ã§ã³ã§äœ¿çšã§ããã³ãã³ãã¬ãããå¶éãããã管çè æš©éãªãã§å¿ èŠãªã³ãã³ãã¬ããã«ã¢ã¯ã»ã¹ãããã§ããããšãæãåºããŠãã ããã
ãã¡ãããçµã¿èŸŒã¿ããŒã«ãšå°ããªãŠãŒãã£ãªãã£ã«å ããŠãæ§é ã管çããããã®å€ãã®ããã°ã©ã ããããŸãã ã¢ãã«ããœãªã¥ãŒã·ã§ã³ã«å ããŠãZabbixãªã©ã®ç£èŠããŒã«ãKaspersky Anti-Virus管çã³ã³ãœãŒã«ã䜿çšããŠãChefãAnsibleãMS SCCMãªã©ã®æ§æã管çã§ããŸãã
ç°è³ªãªæ§é ã®æ代ã«ã¯ãWindowsãšLinuxã®çµ±å管çæ©èœãããã°ãããšæããŸãã ããã¯ãPowerShellã䜿çšããŠè¡ãããšãã§ããŸããPowerShellèªäœã¯å¥ã®èšäºã«å€ããŸãããããè¡ã䟡å€ã¯ãããŸããããããšãäžèŠã§ããã
ã¡ãªã¿ã«ããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒäžã§ç§å¯ã®ããã°ã©ã ãããŸãèµ·åããªãããã°ã©ã ã®æ¹æ³ãå ±æããŠãã ããã ããŠããšã¯ã¹ããã€ããé€ããŸãã