Showing posts with label windows. Show all posts
Showing posts with label windows. Show all posts

2017-02-28

보안 윈도우 기본 공유 폴더 제거하기


한가정 2~3대의 pc는 기본인 시대다 스마트폰도 이제는 거의 pc의 영역에 도달했으니,
누군가 악의적인 생각만한다면 타인의 정보를 쉽게 얻을수 있다.

그런차원에서, 윈도우에서보안을 위한 설정을 알아보자.
윈도우는 xp부터 최신 윈도우10버전에 이르기까지 기본적인 관리자 공유기능을 열어놓고 사용한다.

별거아닌것 같지만, 운영체제가 설치된 c드라이브부터 모든 드리이브의 루트,즉 모든 폴더를 기본공유한다는것은 심직힌 문제다.

기업에서 관리목적으로 사용한디면 편리한 기능이지만 개인 데스크탑 사용자에게는 불필요한기능이다.
사실 윈도우에는 이런 불필요한 관리자옹 기능들이 싱당히 많다.
분산처리리나 ,서비스용IIS등 나중에 이런 서비스들을 딛고 최적화 하는 방법을 알아보자.

우선 관리자 권한으로 로그인하다.

우선 windows key + r을 누른후 cmd를 입력하여, 명렁창을 실힝한다.
명령창에서 "net share"를 입력하면 다음과같이 현재 윈도우가 공유하고 있는폴더들을 볼수있다



자신이 공유한 폴더 이외에도 기본적으로 많은 공유폴더가 공유되어있는것을 확인할수있다.
다음명령줄을 사용하여 모근 공유를 삭제할수있다.
이 명령줄을 윈도우 배치 파일로 작성하여, "시작 프로그램" 폴더에 등록하면 부팅시마다 실행하여 기본폴더를 삭제해준다.

net share d:\ /delete
net share c:\ /delete
net share c:\windows /delete
net share e:\ /delete
net share f:\ /delete
net share admin$ /delete



참고로, 위의 관리자 공유에 접근하는 방법은 다음과같다.
windows key + r키를 누른후 실행창에

\\[컴퓨터이름]\[공유 이름]

으로 접근하면된다.




2017-02-21

Debugview를 사용하여 원격 커널 로그 보기


원격호스트의 커널로그를 보기 위해서는  다음과 같은 방법이 있다.
  1. Windbg 를 사용하여 커널 디버깅 설정
  2. Debugview를  원격 로그 설정
1번의 Windbg를 통해 디버깅을 하면 브레이트 포인트/로컬 변수확인 등 여러가지가 가능하지만 무겁고 설정또한 쉽지 않다. (Windbg를 통한 디버깅 바로가기)

따라서 로그만을 확인할 경우는 Debugview를 사용하여 원격 호스트의 로그만을 확인하는 것이 좋다.

Debugview는 서버- 에이전트 방식으로 뷰어에 원격지 로그 정보를 제공한다.
  1. 우선 debugview를 다운 받는다.(바로가기)
  2.  다운받은 debugview를 로그를 확인할 호스트와, 디버깅할 호스트에 각각 설치한다.
  3. 디버깅할 호스트에서 cmd 창을 열어 ,다음 명령을 실행한다.
    (windows key+r 입력후 cmd를 입력한후 엔터를 치면 cmd창이 실행된다)

    dbgview /a /k /v
    * 각 옵션은 agent 모드 실행,  커널로그 캡처, 상세로그출력이며 상세한 사항은 다음과 같다.


    명령이 정상 실행 되면 조그만 debugview 창이 뜨면서 접속을 대기한다는 메세지가 나온다, 창을 출력하고 싶지 않을경우 /t 옵션을 추가 하면 된다.
  4. 로그를 출력할 호스트에서 dbgview를 더블 클릭하여 실행한다.
    프로그램 화면의 메뉴에서 COMPUTER> CONNECT를 선택한후,  호스트의 호스트 이름 혹은 IP를 입력한다. 
  5. 로그를 출력할 호스트의  화면에서는 메뉴의 CAPTURE>CAPTURE KERNEL이 꺼져 있으므로 켜준다.

     위 과정을  완료하면  커널 로그가 출력된다.
     하지만 windbg보다 빠를 뿐, 만족할 만한 속도가 나오지 않는다.

애매한 사용성이지만  누구가 쉽게 접근하여 설정/사용이 가능하다는 장점이 있다.



2016-11-24

윈도우 레지스트리 MountedDevices 키 갱신 시점

윈도우즈 에서 디스크 관리자를 통해 기존 볼륨을 삭제후에,
같은 레터를 사용해 볼륨을 재 생성하게 되면
밑의 키에 해당 볼륨에 대한 정보가 갱신된다.

HKEY_LOCAL_MACHINE\SYSTEM\MountedDevices

regedit를 실행하여 해당 키를 보면 다음과 같이 레터에 대한 정보들을 볼수 있다.






단, 볼륨 정보 변경시 , 갱신 시점이 약간 다르다.

  •  볼륨 삭제시 에는 바로 반영된다.
  •  볼륨 추가시는 새로운 볼륨이 최초 마운트 된 후에 갱신된다.

따라서 윈도우 드라이버에서 볼륨의 심볼릭 링크인 볼륨 레터를 기준으로 무었인가 작업을 수행하면, 해당 볼륨을 삭제하고 재생하면 사용자의 의도와 제어에서 볼륨이 벗어 날수 있다.

그러므로, 가능하면 변경되는 심볼릭링크를 사용하지 말고 볼륨에 고유한  guid 를 사용하는 것이 좋다.


windbg를 사용해 디버깅 중에는 다음과 같은 확장 명령으로 레지스트리 상태를 확인 하여
MountedDevices키가 갱신 되는 부분을 확인할수 있다.

함정은 regedit로 확인 하는 FULL_KEY_PATH와 확장 명령으로 조회하는 FULL_KEY_PATH 가 약간 틀리다!

!reg q \REGISTRY\MACHINE\SYSTEM\MountedDevices





2016-07-26

VM Disk CID MISMATCH after remove snapshot

If you got a message like following..

2016-07-27T13:34:33.894+09:00| vmx| I125: [msg.disklib.CID_MISMATCH] The parent virtual disk has been modified since the child was created. The content ID of the parent virtual disk does not match the corresponding parent content ID in the child
2016-07-27T13:34:33.894+09:00| vmx| I125: [msg.disk.noBackEnd] Cannot open the disk 'F:\one\one-000003.vmdk' or one of the snapshot disks it depends on.
2016-07-27T13:34:33.894+09:00| vmx| I125: [msg.moduletable.powerOnFailed] Module 'Disk' power on failed.
2016-07-27T13:34:33.894+09:00| vmx| I125: [msg.vmx.poweron.failed] Failed to start the virtual machine.

In the virtual machine of the Vmware, the disk is stored on local host PC as a number of seperated files numbered sequentially.

like this..

F:\one>dir | findstr one
2016-07-27   01:34         7,929,856 one-000003.vmdk
2016-07-27   11:19             8,684 one.nvram
2016-07-27   11:19    30,642,339,840 one.vmdk
2016-07-27   11:04                 0 one.vmsd
2016-07-27   11:19             5,045 one.vmx
2016-07-27   11:36    <DIR>          one.vmx.lck
2016-07-08   03:29               258 one.vmxf

A vmdk , the file extention ,  which means virtual disk of the VM.

As you open the last file 'one-000003.vmdk' , you can see CID and parent CID.

※ parentCID=fffffff means it is a root disk file.

In this case, CID and parentCID has exactly same value.


So, you have to fill up the value of the parentCID  correctly.
If the root vmdk file is so huge size that can not  open file, try to type this.

F:\one>type one.vmdk | findstr CID
CID=3c0de770
ddb.longContentID = "84db3daa23d4babb81c98b613c0de770"
FINDSTR: 26row so long.
FINDSTR: 114326row so long.
FINDSTR: 114326row so long.
FINDSTR: 114326row so long.

After you got a CID of root disk file, Edit parentCID value of the 'one-000003.vmdk' with given CID. then , try to power on the vm.



if it does not work, and if you don't care a losing of data, rollback the disk file to root disk file.

Open vmx file of VM and edit it . then power on. 
it might be powered on...  but anyone knows how much of data losing.

scsi0:0.present = "TRUE"
scsi0:0.fileName = "one.vmdk"
sata0:1.present = "TRUE"



2016-07-24

Windows Executive component function prefix

Windows Executive component function prefix


Pattern

<Prefix><Operation><Object>

ex. ExAllocatePoolWithTag

Prefix

Alpc = Advanced Local Inter-Process Communication
Cc = Common Cache
Cm = Configuration Manager
Dbgk = Debugging Framework for User-Mode
Em = Errata Manager
Etw = Event Tracing for Windows
Ex = Executive support routines
FsRtl = File System driver Run-Time Library 
Hal = Hardware Abstraction Layer
Hvl = Hyper visor Library
Io = I/O Manager
Kd = Kernel Debugger
Ke = Kernel
Lsa = Local Security Authority
Mm = Memory Manager
Nt = NT System Services
Ob = Object Manager
Pf = Prefetcher
Po = Power Manager
Pp = PnP Manager
Ps = Process Support
Rtl = Run-time Library
Se = Security
Tm = Transaction Manager
Vf = Verifier (Driver Verifier)
Whea = Windows Hardware Error Architecture
Wmi = Windows Management Instrumentation
Wdi = Windows Diagnostic Infrastructure
Zw = The mirror entry point for system service , similar to NT, but sets access mode to Kernel, which in turn eliminates any parameter validation. because, Only In the user mode, Nt system service validate parameters.


2016-07-13

Basis of windows kernel debugging

Windows Driver Debugging with WinDbg.



Window Memory architecure

<fig  32 bit windows memory archtecture>

windows kernel debugging model


<fig  windows kernerl debugging model>



Debugging types

User mode debugging
It is debugging a process that is started on user mode.
by visual studio , windbg

Kernel mode debugging
It is debugging a process that is started on Kernel mode.
by windbg

live debugging
it is debugging a process that is running step by step each line of source.

dump debugging
It is a analying dump when is created at the system crash or blue screen.

Terms

user dump
It is a dump on the user mode.

kernel dump
It is a dump on the kernel mode.

the debugger
It means  a something installed tools for debugging.

the debugee
it means  target like  processes or drivers will be  debugged.

Debug Symbols
such as a  pdb files
it includes function, variablable’s name and location and source line.

Stack
In x86 arch , The register ESP, EBP invloves meaning of the stack’s start and stop address.

Command Prompt

0:000>  - The first part of ‘0’ being means process number. and, The left ‘000’  part is thread number

kd> - The kernel mode command prompt.

0: kd >  The front ‘0’ is the Processor( means cpu ) number. and ‘kd’ means being that is in kernel mode.

windbg commands

Debugger Commands
  • r - register - Display cpu resister information.
  • k - call stack - Show call stack backtrace
  • g - go - keep going kernel
  • p - pause - pause step
  • pc - - Step to next call
  • t - trace -
  • tb - - trace to next branch
  • tc - - trace to next call
  • wt - - Trace and watch data
  • a - assemble
  • u - unassemble
  • bc - breakpoint cleaar
  • bd - breakpoit disable
  • be - breakpoit enable
  • bl - breakpoit list
  • ba - break on access
  • d , da, db, dw, dd - display - display memory
  • dds - - display word and symbol
  • dl - - display linked list
  • ds - - Display string
  • dt - - Display type
  • dv - - Display local variable
  • s - - Search memory
  • ls - - load symbol
  • lm - - list loaded symbol
  • ln - - list nearest symbol
  • k, kb, kd, kp, kv - - display stack backtrace
  • e, ea, ed, ed, ew, eu - enter - enter values
  • etc...
Meta Commands
  • .sympath - Set symbol path
  • .reload - Reload module
  • .srcpath - set source path
  • .exepath - Set executable path
  • .trap - Display trap frame
  • .ecxr - Display exception context record
  • .exr - Display exception record
  • .cxr - Display context record
  • .reboot - reboot target compter
  • .dump - Create dump file
  • .enable_uncode - Enable unicode display
  • .ofilter - Filter target output
  • .cls - clear screen
  • .bugcheck - Display bug check data
  • .context - Set user mode address context
  • .process -Set process context
  • .thread - Set register context
  • .tss - display Task stte segment
  • .load - Load extension dll
  • etc...
Extension Commands
  • !anlyze - Displays information about the current bug check
  • !cpuid - Displays information about the prosessors on the system
  • !error - Decodes and displays information about an error value
  • !gle - Displays the last error value for the current thread
  • !obja - Displays the attributes of an oobject in the object manager
  • !peb - D!peb - Display a fomattes view of the information in the processs environment block (PEB)
  • !teb - Display a fomatted view of the information in the thread environment block (PEB)
  • !token - Display a formatted view of a security token object
  • !process - Displays information about the specified process or all
  • !stacks - Display a information about a current kernel stacks
  • !thread - Displays summary information about a thread
  • !zombies - Displays all dead “zombie”  processes or thread
  • !drivers - Displays  list of all drivers loaded
  • !devnote - Displays a formatted view of the device stack
  • !devobj -Displays detailed information about a DEVICE_OBJECT
  • !devstack - Displays a formatted view of the device stack
  • !drvobj -Displays detailed information about a DRIVER_OBJET
  • etc..