성태의 닷넷 이야기
홈 주인
모아 놓은 자료
프로그래밍
질문/답변
사용자 관리
사용자
메뉴
아티클
외부 아티클
유용한 코드
온라인 기능
MathJax 입력기
최근 덧글
[정성태] Reordering on an Alpha processor ;...
[정성태] 공유 감사합니다. ^^ 참고로, WPF에서 WindowsF...
[Tom Lee] 답변 감사합니다. 나름의 해결책 연구해보고 여기에도 공유해봅니다...
[정성태] 아래의 글을 보면, MoveWindow 하면 될 듯한데요. ^^...
[Tom Lee] 안녕하세요 올려주신 글 참고하여 WPF 어플리케이션 안에 Uni...
[정성태] A graphical depiction of the steps ...
[정성태] 질문을 주셔서 출판사 측에 문의를 했습니다. 약 한 달 정도 후...
[Thorondor
] @정성태 개인 블로그인데도 거의 커뮤니티 급 인 것 같아요. 요...
[정성태] Roll A Lisp In C - Reading ; https...
[정성태] Java - How to use the Foreign Funct...
글쓰기
제목
이름
암호
전자우편
HTML
홈페이지
유형
제니퍼 .NET
닷넷
COM 개체 관련
스크립트
VC++
VS.NET IDE
Windows
Team Foundation Server
디버깅 기술
오류 유형
개발 환경 구성
웹
기타
Linux
Java
DDK
Math
Phone
Graphics
사물인터넷
부모글 보이기/감추기
내용
<div style='display: inline'> <h1 style='font-family: Malgun Gothic, Consolas; font-size: 20pt; color: #006699; text-align: center; font-weight: bold'>windbg - 필터 드라이버 확인하는 확장 명령어(!fltkd)</h1> <p> 아래의 글을,<br /> <br /> <pre style='margin: 10px 0px 10px 10px; padding: 10px 0px 10px 10px; background-color: #fbedbb; overflow: auto; font-family: Consolas, Verdana;' > 윈도우즈 룻킷 - 윈도우즈 디펜더 무력화 ; <a target='tab' href='https://learn.darungrim.com/contents/windows10-rootkits-disabling-windows-defender.html'>https://learn.darungrim.com/contents/windows10-rootkits-disabling-windows-defender.html</a> </pre> <br /> 실습해 봤는데요. ^^ 이를 위해 우선 Local Kernel Debug 모드로 windbg를 연결하고,<br /> <br /> <pre style='margin: 10px 0px 10px 10px; padding: 10px 0px 10px 10px; background-color: #fbedbb; overflow: auto; font-family: Consolas, Verdana;' > Windbg - Local Kernel Debug 모드 ; <a target='tab' href='https://www.sysnet.pe.kr/2/0/934'>https://www.sysnet.pe.kr/2/0/934</a> </pre> <br /> 심벌을 먼저 로드해봤는데,<br /> <br /> <pre style='margin: 10px 0px 10px 10px; padding: 10px 0px 10px 10px; background-color: #fbedbb; overflow: auto; font-family: Consolas, Verdana;' > 0: kd> <span style='color: blue; font-weight: bold'>.reload /f</span> Loading Kernel Symbols .... Press ctrl-c (cdb, kd, ntsd) or ctrl-break (windbg) to abort symbol loads that take too long. Run !sym noisy before .reload to track down problems loading symbols. ........*** ERROR: Symbol file could not be found. Defaulted to export symbols for clipsp.sys - ..................................*** ERROR: Module load completed but symbols could not be loaded for WdFilter.sys ................. ....*** WARNING: Unable to verify timestamp for dump_msrpc.sys *** ERROR: Module load completed but symbols could not be loaded for dump_msrpc.sys ......*** WARNING: Unable to verify timestamp for Null.SYS *** ERROR: Module load completed but symbols could not be loaded for Null.SYS ..................*** ERROR: Module load completed but symbols could not be loaded for MpKslDrv.sys .................................... ...............*** ERROR: Module load completed but symbols could not be loaded for peauth.sys .............*** ERROR: Module load completed but symbols could not be loaded for WdNisDrv.sys .... Loading User Symbols Loading unloaded module list ........ ************* Symbol Loading Error Summary ************** Module name Error clipsp The system cannot find the file specified : srv*e:\symbols*http://msdl.microsoft.com/download/symbols WdFilter The system cannot find the file specified : srv*e:\symbols*http://msdl.microsoft.com/download/symbols dump_msrpc No data is available : srv*e:\symbols*http://msdl.microsoft.com/download/symbols Null No data is available : srv*e:\symbols*http://msdl.microsoft.com/download/symbols MpKslDrv The system cannot find the file specified : srv*e:\symbols*http://msdl.microsoft.com/download/symbols peauth The system cannot find the file specified : srv*e:\symbols*http://msdl.microsoft.com/download/symbols WdNisDrv The system cannot find the file specified : srv*e:\symbols*http://msdl.microsoft.com/download/symbols You can troubleshoot most symbol related issues by turning on symbol loading diagnostics (!sym noisy) and repeating the command that caused symbols to be loaded. You should also verify that your symbol search path (.sympath) is correct. </pre> <br /> 아쉽게도 WdFilter에 대한 심벌 파일을 내려받지 못하고 있습니다. 어쨌든, 이 상태에서 "fltkd.filters" 확장 명령어와,<br /> <br /> <pre style='margin: 10px 0px 10px 10px; padding: 10px 0px 10px 10px; background-color: #fbedbb; overflow: auto; font-family: Consolas, Verdana;' > 0: kd> <span style='color: blue; font-weight: bold'>!fltkd.filters</span> Filter List: ffffc60fe0bca0c0 "Frame 0" FLT_FILTER: <span style='color: blue; font-weight: bold'>ffffc60fe066aad0</span> "WdFilter" "328010" FLT_INSTANCE: ffffc60fe40ebb30 "WdFilter Instance" "328010" FLT_INSTANCE: ffffc60fe423e8a0 "WdFilter Instance" "328010" FLT_INSTANCE: ffffc60fe43df9a0 "WdFilter Instance" "328010" FLT_INSTANCE: ffffc60fe42df8a0 "WdFilter Instance" "328010" FLT_INSTANCE: ffffc60fe54a67e0 "WdFilter Instance" "328010" FLT_FILTER: ffffc60fe67b9c30 "storqosflt" "244000" FLT_FILTER: ffffc60fe65d3a10 "wcifs" "189900" FLT_FILTER: ffffc60fe668f920 "CldFlt" "180451" FLT_FILTER: ffffc60fe42968a0 "FileCrypt" "141100" FLT_FILTER: ffffc60fe6795010 "luafv" "135000" FLT_INSTANCE: ffffc60fe67b2010 "luafv" "135000" FLT_FILTER: ffffc60fe42c48a0 "npsvctrig" "46000" FLT_INSTANCE: ffffc60fe42c4c10 "npsvctrig" "46000" FLT_FILTER: ffffc60fe064e240 "Wof" "40700" FLT_INSTANCE: ffffc60fe43d3b20 "Wof Instance" "40700" </pre> <br /> 출력 결과 중 WdFilter 항목만 상세 보기를 하면 이런 결과가 나옵니다.<br /> <br /> <pre style='margin: 10px 0px 10px 10px; padding: 10px 0px 10px 10px; background-color: #fbedbb; overflow: auto; font-family: Consolas, Verdana;' > 0: kd> <span style='color: blue; font-weight: bold'>!fltkd.filter ffffc60fe066aad0</span> FLT_FILTER: ffffc60fe066aad0 "WdFilter" "328010" FLT_OBJECT: ffffc60fe066aad0 [02000000] Filter RundownRef : 0x000000000000f476 (31291) PointerCount : 0x00000006 PrimaryLink : [ffffc60fe67b9c40-ffffc60fe0bca0c0] Frame : ffffc60fe0bca010 "Frame 0" Flags : [00000032] FilteringInitiated +30!! DriverObject : ffffc60fe064d740 FilterLink : [ffffc60fe67b9c40-ffffc60fe0bca0c0] *** ERROR: Module load completed but symbols could not be loaded for WdFilter.sys PreVolumeMount : fffff8070daba090 WdFilter+0x2a090 PostVolumeMount : fffff8070da945b0 WdFilter+0x45b0 FilterUnload : fffff8070dabc930 WdFilter+0x2c930 InstanceSetup : fffff8070dabcc40 WdFilter+0x2cc40 InstanceQueryTeardown : fffff8070dabce30 WdFilter+0x2ce30 InstanceTeardownStart : 0000000000000000 (null) InstanceTeardownComplete : fffff8070dabce90 WdFilter+0x2ce90 ActiveOpens : (ffffc60fe066ac88) mCount=0 Communication Port List : (ffffc60fe066acd8) mCount=5 Client Port List : (ffffc60fe066ad28) mCount=5 VerifierExtension : 0000000000000000 <span style='color: blue; font-weight: bold'>Operations : ffffc60fe066ad80</span> OldDriverUnload : 0000000000000000 (null) SupportedContexts : (ffffc60fe066ac00) ************************************************************************* *** *** *** *** *** Either you specified an unqualified symbol, or your debugger *** *** doesn't have full symbol information. Unqualified symbol *** *** resolution is turned off by default. Please either specify a *** *** fully qualified symbol module!symbolname, or enable resolution *** *** of unqualified symbols by typing ".symopt- 100". Note that *** *** enabling unqualified symbol resolution with network symbol *** *** server shares in the symbol path may cause the debugger to *** *** appear to hang for long periods of time when an incorrect *** *** symbol name is typed or the network symbol server is down. *** *** *** *** For some commands to work properly, your symbol path *** *** must point to .pdb files that have full type information. *** *** *** *** Certain .pdb files (such as the public OS symbols) do not *** *** contain the required information. Contact the group that *** *** provided you with these symbols if you need this command to *** *** work. *** *** *** *** Type referenced: PVOID *** *** *** ************************************************************************* VolumeContexts : (ffffc60fe066ac00) InstanceContexts : (ffffc60fe066ac00) FileContexts : (ffffc60fe066ac00) StreamContexts : (ffffc60fe066ac00) StreamHandleContexts : (ffffc60fe066ac00) TransactionContext : (ffffc60fe066ac00) (null) : (ffffc60fe066ac00) InstanceList : (ffffc60fe066ab38) FLT_INSTANCE: ffffc60fe40ebb30 "WdFilter Instance" "328010" FLT_INSTANCE: ffffc60fe423e8a0 "WdFilter Instance" "328010" FLT_INSTANCE: ffffc60fe43df9a0 "WdFilter Instance" "328010" FLT_INSTANCE: ffffc60fe42df8a0 "WdFilter Instance" "328010" FLT_INSTANCE: ffffc60fe54a67e0 "WdFilter Instance" "328010" </pre> <br /> "<a target='tab' href='https://learn.darungrim.com/contents/windows10-rootkits-disabling-windows-defender.html'>윈도우즈 룻킷 - 윈도우즈 디펜더 무력화</a>" 글의 내용에 따라 Operations에 대한 포인터를 덤프해 보면,<br /> <br /> <pre style='margin: 10px 0px 10px 10px; padding: 10px 0px 10px 10px; background-color: #fbedbb; overflow: auto; font-family: Consolas, Verdana;' > 0: kd> <span style='color: blue; font-weight: bold'>dqs ffffc60fe066ad80</span> ffffc60f`e066ad80 00000009`00000003 ffffc60f`e066ad88 fffff807`0da963b0 WdFilter+0x63b0 ffffc60f`e066ad90 fffff807`0da96650 WdFilter+0x6650 ffffc60f`e066ad98 00000000`00000000 ffffc60f`e066ada0 00000000`00000000 ffffc60f`e066ada8 fffff807`0dab18b0 WdFilter+0x218b0 ffffc60f`e066adb0 fffff807`0dab3fa0 WdFilter+0x23fa0 ffffc60f`e066adb8 00000000`00000000 ffffc60f`e066adc0 00000000`00000012 ffffc60f`e066adc8 fffff807`0daaa810 WdFilter+0x1a810 ffffc60f`e066add0 fffff807`0daac0b0 WdFilter+0x1c0b0 ffffc60f`e066add8 00000000`00000000 ffffc60f`e066ade0 00000000`00000006 ffffc60f`e066ade8 fffff807`0dab8920 WdFilter+0x28920 ffffc60f`e066adf0 fffff807`0dab8f60 WdFilter+0x28f60 ffffc60f`e066adf8 00000000`00000000 </pre> <br /> 심벌 파일이 없어 "WdFilter!MpAmPreCreate" 등의 명확한 함수명 대신 "WdFilter+0x63b0"와 같은 식으로 나오고 있지만, 어쨌든 덤프해 보면 관련 인스트럭션은 확인할 수 있고,<br /> <br /> <pre style='margin: 10px 0px 10px 10px; padding: 10px 0px 10px 10px; background-color: #fbedbb; overflow: auto; font-family: Consolas, Verdana;' > 0: kd> <span style='color: blue; font-weight: bold'>u fffff807`0da963b0</span> WdFilter+0x63b0: fffff807`0da963b0 48895c2410 mov qword ptr [rsp+10h],rbx fffff807`0da963b5 55 push rbp fffff807`0da963b6 56 push rsi fffff807`0da963b7 57 push rdi fffff807`0da963b8 4156 push r14 fffff807`0da963ba 4157 push r15 fffff807`0da963bc 488bec mov rbp,rsp fffff807`0da963bf 4883ec50 sub rsp,50h </pre> <br /> 그러니까... 저곳의 진입을 이런 식으로 바꾸면,<br /> <br /> <pre style='margin: 10px 0px 10px 10px; padding: 10px 0px 10px 10px; background-color: #fbedbb; overflow: auto; font-family: Consolas, Verdana;' > WdFilter+0x63b0: mov eax,1 ret ...[생략]... </pre> <br /> 윈도우 디펜더로 인한 DKOM 무력화를 막을 수 있다는 겁니다. 오호~~~ 언제 심심하면 아래의 글에 썼던,<br /> <br /> <pre style='margin: 10px 0px 10px 10px; padding: 10px 0px 10px 10px; background-color: #fbedbb; overflow: auto; font-family: Consolas, Verdana;' > C# - KernelMemoryIO 드라이버를 이용해 실행 프로그램을 숨기는 방법(DKOM: Direct Kernel Object Modification) ; <a target='tab' href='https://www.sysnet.pe.kr/2/0/12111'>https://www.sysnet.pe.kr/2/0/12111</a> </pre> <br /> 커널 메모리 변조로 인한 BSOD의 발생 여부를 한번 테스트해봐야겠군요. ^^<br /> </p><br /> <br /><hr /><span style='color: Maroon'>[이 글에 대해서 여러분들과 의견을 공유하고 싶습니다. 틀리거나 미흡한 부분 또는 의문 사항이 있으시면 언제든 댓글 남겨주십시오.]</span> </div>
첨부파일
스팸 방지용 인증 번호
2851
(왼쪽의 숫자를 입력해야 합니다.)