ç¡æã®Pentester Webã¢ããªã±ãŒã·ã§ã³ããŒã«
ãã®èšäºã§ã¯ãããã©ãã¯ããã¯ã¹ãæŠç¥ã«åŸã£ãŠWebã¢ããªã±ãŒã·ã§ã³ã®ãã³ãã¹ãïŒäŸµå ¥ãã¹ãïŒãè¡ãããã®æãäžè¬çãªããŒã«ã«ã€ããŠèª¬æããŸãã
ãããè¡ãããã«ããã®ã¿ã€ãã®ãã¹ãã«åœ¹ç«ã€ãŠãŒãã£ãªãã£ãæ€èšããŸãã 次ã®è£œåã«ããŽãªãæ€èšããŠãã ããã
- ãããã¯ãŒã¯ã¹ãã£ããŒ
- Web Scripting Scanner
- æªçš
- èªååã€ã³ãžã§ã¯ã·ã§ã³
- ãããã¬ãŒïŒã¹ããã¡ãŒãããŒã«ã«ãããã·ãªã©ïŒ
äžéšã®è£œåã«ã¯æ®éçãªãç¹æ§ãããããããããè¯ãçµæãåŸãããã«ããŽãªïŒäž»èŠ³çæèŠïŒã«é¢é£ä»ããŸãã
ãããã¯ãŒã¯ã¹ãã£ããŒã
äž»ãªã¿ã¹ã¯ã¯ãå©çšå¯èœãªãããã¯ãŒã¯ãµãŒãã¹ã®å ¬éãããŒãžã§ã³ã®ã€ã³ã¹ããŒã«ãOSã®æ±ºå®ãªã©ã§ãã
Nmap

NmapïŒããããã¯ãŒã¯ããããŒãïŒã¯ããããã¯ãŒã¯åæãšã·ã¹ãã ã»ãã¥ãªãã£ç£æ»ã®ããã®ç¡æã®ãªãŒãã³ãœãŒã¹ãŠãŒãã£ãªãã£ã§ãã ã³ã³ãœãŒã«ã®æ¿ããçžæã¯Zenmapã䜿çšã§ããŸããããã¯Nmapã®GUIã§ãã
ããã¯åãªããã¹ããŒããã¹ãã£ããŒã§ã¯ãªããæ·±å»ãªæ¡åŒµå¯èœãªããŒã«ã§ãïŒãç°åžžãªãããã -Stuxnetã¯ãŒã ã®ååšãããŒãã§ç¢ºèªããã¹ã¯ãªããã®ååšïŒ ããã§èª¬æ ïŒã
nmap -A -T4 localhost
-A OSããŒãžã§ã³ã®å€å¥ãã¹ã¯ãªããããã³ãã¬ãŒã¹ã䜿çšããã¹ãã£ã³
-T4æé管çèšå®ïŒããå€ã-é«éã0ã5ïŒ
localhost-ã¿ãŒã²ãããã¹ã
ãã£ãšé£ãããã®ã¯ãããŸããïŒ
nmap -sS -sU -T4 -A -v -PE -PP -PS21,22,23,25,80,113,31339 -PA80,113,443,10042 -PO --script all localhost
ããã¯ãZenmapã®ãäœéç·åã¹ãã£ã³ããããã¡ã€ã«ã®ãªãã·ã§ã³ã»ããã§ãã ããªãé·ãæéãããããŸãããæçµçã«ã¯ã¿ãŒã²ããã·ã¹ãã ã«ã€ããŠåŠç¿ã§ãããã詳现ãªæ å ±ãæäŸããŸãã ãã·ã¢èªã®ãªãã¡ã¬ã³ã¹ã¬ã€ã ãããã«è©³ãã説æããå Žåã¯ã åå¿è ã¬ã€ããNmapã«ç¿»èš³ããããšããå§ãããŸã ã
Nmapã¯ãLinux JournalãInfo WorldãLinuxQuestions.OrgãCodetalker Digestãªã©ã®éèªãã³ãã¥ããã£ããã幎éæåªç§ã»ãã¥ãªãã£è£œåãã¹ããŒã¿ã¹ãç²åŸããŠããŸãã
èå³æ·±ãç¬éãNmapã¯æ ç»ãMatrixïŒReloadedãããDie Hard 4ãããBourne UltimatumãããHottabychããªã©ã§èŠãããšãã§ããŸãã
IPããŒã«

IP-Tools-ç°ãªãçš®é¡ã®ãããã¯ãŒã¯ãŠãŒãã£ãªãã£ã®äžçš®ã§ãWindowsãŠãŒã¶ãŒå°çšã®GUIãä»å±ããŠããŸãã
ããŒãã®ã¹ãã£ããŒãå ±æãªãœãŒã¹ïŒå ±æããªã³ã¿ãŒ/ãã©ã«ããŒïŒãWhoIs / Finger / Lookupãtelnetã¯ã©ã€ã¢ã³ããªã©ã 䟿å©ã§é«éãæ©èœçãªããŒã«ã§ãã
ãã®åéã«ã¯å€ãã®ãŠãŒãã£ãªãã£ãããããããã¯ãã¹ãŠåæ§ã®åäœåçãšæ©èœãæã£ãŠãããããä»ã®è£œåãæ€èšããããšã¯ã»ãšãã©æå³ããããŸããã ããããæãäžè¬çã«äœ¿çšãããã®ã¯nmapã§ãã
Web Scripting Scanner
äžè¬çãªè匱æ§ïŒSQL injãXSSãLFI / RFIãªã©ïŒãŸãã¯ãšã©ãŒïŒåé€ãããäžæãã¡ã€ã«ãã€ã³ããã¯ã¹ãã£ã¬ã¯ããªãªã©ïŒãèŠã€ããããšãã
Acunetix Webè匱æ§ã¹ãã£ããŒ

Acunetix Web Vulnerability Scanner-ãªã³ã¯ã¯ããããxssã¹ãã£ããŒã§ããããšã瀺ããŠããŸãããããã¯
æ¥æ±

Niktoã¯ããªãŒãã³ãœãŒã¹ïŒGPLïŒWebã¹ãã£ããŒã§ãã æ¥åžžçãªæäœæ¥ãæé€ããŸãã ã¿ãŒã²ãããµã€ãïŒäžéšã®test.phpãindex_.phpãªã©ïŒãããŒã¿ããŒã¹ç®¡çããŒã«ïŒ/ phpmyadmin /ã/ pmaãªã©ïŒã§åé€ãããŠããªãã¹ã¯ãªãããæ€çŽ¢ããŸããã€ãŸããæãé »ç¹ã«ãªãœãŒã¹ããã§ãã¯ããŸããéåžžã人çèŠå ãåå ã§çºçãããšã©ãŒã
ããã«ã人æ°ã®ããã¹ã¯ãªãããèŠã€ãããšããªãªãŒã¹ããããšã¯ã¹ããã€ãïŒããŒã¿ããŒã¹ã«ããïŒããã§ãã¯ããŸãã
PUTãTRACEãªã©ã®å©çšå¯èœãªãäžèŠãªãæ¹æ³ãå ±åãã
ãŸããªã©ã ããªããç£æ»åœ¹ãšããŠåããŠãæ¯æ¥ãŠã§ããµã€ãåæãè¡ããªãã°ãããã¯éåžžã«äŸ¿å©ã§ãã
ãã€ãã¹ã®ãã¡ã誀æ€ç¥ã®å²åãé«ãããšã«æ³šæããŠãã ããã ããšãã°ã404ãšã©ãŒã®ä»£ããã«ïŒçºçããã¯ãã®ïŒãµã€ããåžžã«äž»èŠãªæ å ±ãæäŸããå Žåãã¹ãã£ããŒã¯ããŒã¿ããŒã¹ã®ãã¹ãŠã®ã¹ã¯ãªãããšãã¹ãŠã®è匱æ§ããµã€ãã«ãããšèšããŸãã å®éã«ã¯ãããã¯ããã»ã©äžè¬çã§ã¯ãããŸããããå®éã«ã¯ãå€ãã¯ãµã€ãã®æ§é ã«äŸåããŸãã
å€å žçãªäœ¿çšïŒ
./nikto.pl -host localhost
ãµã€ãã§èªèšŒãåããå¿ èŠãããå Žåã¯ãnikto.confãã¡ã€ã«ã§STATIC-COOKIEå€æ°ã«Cookieãèšå®ã§ããŸãã
ãŠã£ã¯ã

Wikto -Windowsã§ã®Niktoããã ãããšã©ãŒããã§ãã¯ããéã®ããã¡ãžãŒãããžãã¯ãGHDBã®äœ¿çšããªãœãŒã¹ã®ãªã³ã¯ãšãã©ã«ããŒã®ååŸãHTTPãªã¯ãšã¹ã/ã¬ã¹ãã³ã¹ã®ãªã¢ã«ã¿ã€ã ã¢ãã¿ãªã³ã°ãªã©ã®è¿œå ã Wiktoã¯CïŒã§èšè¿°ãããŠããã.NETãã¬ãŒã ã¯ãŒã¯ãå¿ èŠã§ãã
ã¹ããããã£ãã·ã¥

skipfishã¯ã Michal ZalewskiïŒlcamtââufãšããŠç¥ãããïŒã«ããWebè匱æ§ã¹ãã£ããŒã§ãã ã¯ãã¹ãã©ãããã©ãŒã ã®Cã§æžãããŠããŸãïŒWinã®å Žåã¯Cygwinãå¿ èŠã§ãïŒã ååž°çã«ïŒãããŠéåžžã«é·ãæéãçŽ20ã40æéãååã¯96æéåããŠããŸãããïŒãµã€ãå šäœãå·¡åããããããçš®é¡ã®ã»ãã¥ãªãã£ããŒã«ãèŠã€ããŸãã ãŸãã倧éã®ãã©ãã£ãã¯ãçæããŸãïŒæ°GBã®ã€ã³ããŠã³ã/ã¢ãŠãããŠã³ãïŒã ããããç¹ã«æéãšãªãœãŒã¹ãããå Žåã¯ããã¹ãŠã®æ段ãåªããŠããŸãã
å žåçãªäœ¿çšæ³ïŒ
./skipfish -o /home/reports www.example.com
ãã¬ããŒãããã©ã«ããŒã«ã¯ãhtmlã®ã¬ããŒãïŒ äŸïŒããããŸãã
w3af

w3af-ãªãŒãã³ãœãŒã¹ã®Webè匱æ§ã¹ãã£ããŒã§ããWeb Application Attack and Audit Frameworkã GUIããããŸãããã³ã³ãœãŒã«ã®äžããäœæ¥ã§ããŸãã ããæ£ç¢ºã«ã¯ãããã¯å€ãã®ãã©ã°ã€ã³ãæã€ãã¬ãŒã ã¯ãŒã¯ã§ãã
ããªãã¯é·ãéãã®å©ç¹ã«ã€ããŠè©±ãããšãã§ããŸãããããè©ŠããŠã¿ãããšããå§ãããŸãïŒ]
å žåçãªäœæ¥ã¯ããããã¡ã€ã«ãéžæããç®æšãæå®ããå®éã«ãããèµ·åããããšã§ãã
Mantraã»ãã¥ãªãã£ãã¬ãŒã ã¯ãŒã¯

ãã³ãã© ã¯å®çŸãã倢ã§ã ã Webãã©ãŠã¶ã«åã蟌ãŸããç¡æã®ãªãŒãã³ãªã»ãã¥ãªãã£ããŒã«ã®ã³ã¬ã¯ã·ã§ã³ã
ãã¹ãŠã®æ®µéã§Webã¢ããªã±ãŒã·ã§ã³ããã¹ããããšãã«éåžžã«äŸ¿å©ã§ãã
䜿çšæ³ã¯ããã©ãŠã¶ã®ã€ã³ã¹ââããŒã«ãšèµ·åã«åž°çããŸãã
å®éããã®ã«ããŽãªã«ã¯å€ãã®ãŠãŒãã£ãªãã£ãããããããããç¹å®ã®ãªã¹ããéžæããããšã¯éåžžã«å°é£ã§ãã ã»ãšãã©ã®å Žåãå5åŠæèªäœãå¿ èŠãªããŒã«ã®ã»ããã決å®ããŸãã
æªçš
ãœãããŠã§ã¢ããã³ã¹ã¯ãªããã®è匱æ§ã®èªååããã䟿å©ãªæªçšã®ããã«ãã»ãã¥ãªãã£éåãæªçšããããã«ãã©ã¡ãŒã¿ãæž¡ãã ãã§ããæªçšãäœæããŸãã ãŸãããšã¯ã¹ããã€ãã®æåæ€çŽ¢ãæé€ãããã®å Žã§ãããã䜿çšãã補åããããŸãã ãã®ã«ããŽãªã«ã€ããŠèª¬æããŸãã
Metasploitãã¬ãŒã ã¯ãŒã¯

Metasploit®ãã¬ãŒã ã¯ãŒã¯ã¯ãåœç€Ÿã®ããžãã¹ã«ãããäžçš®ã®ã¢ã³ã¹ã¿ãŒã§ãã 圌ã¯å€ãã®ããšãç¥ã£ãŠããã®ã§ããã®æ瀺ã¯ããã€ãã®èšäºã§å ¬éãããŸãã èªåæŸåïŒnmap + metasploitïŒãæ€èšããŸãã èŠããã«ãNmapã¯å¿ èŠãªããŒããåæãããµãŒãã¹ãã€ã³ã¹ããŒã«ããmetasploitã¯ãµãŒãã¹ã¯ã©ã¹ïŒftpãsshãªã©ïŒã«åºã¥ããŠãšã¯ã¹ããã€ããé©çšããããšããŸãã ããã¹ãã®èª¬æã®ä»£ããã«ãautopwnã®ãããã¯ã§éåžžã«äººæ°ã®ãããããªãæ¿å ¥ããŸã
ãŸãã¯ãå¿ èŠãªãšã¯ã¹ããã€ãã®æäœãåçŽã«èªååããããšãã§ããŸãã äŸïŒ
msf > use auxiliary/admin/cisco/vpn_3000_ftp_bypass
msf auxiliary(vpn_3000_ftp_bypass) > set RHOST [TARGET IP]
msf auxiliary(vpn_3000_ftp_bypass) > run
å®éããã®ãã¬ãŒã ã¯ãŒã¯ã®æ©èœã¯éåžžã«åºç¯ãªãããããã«æ·±ãããããšã«ããå Žåã¯ã ãªã³ã¯ãã¯ãªãã¯ããŠãã ããã
ã¢ãŒãããŒãž

ã¢ãŒãããŒãž-Metasploit
ã¹ã¯ãªãŒã³ãã£ã¹ãïŒ
TenableNessus®

TenableNessus®è匱æ§ã¹ãã£ã㌠-å€ãã®ããšãã§ããŸããããã®æ©èœã®1ã€ãå¿ èŠã§ã-ã©ã®ãµãŒãã¹ã«ãšã¯ã¹ããã€ããããããå€å¥ããŸãã 補åã®ç¡æçãããŒã ãªã³ãªãŒã
䜿çšæ³ïŒ
- ããŠã³ããŒãïŒã·ã¹ãã çšïŒãã€ã³ã¹ããŒã«ãç»é²ïŒããŒãã¡ãŒã«ã«æ·»ä»ãããŸãïŒã
- ãµãŒããŒãèµ·åããNessus Server Managerã«ãŠãŒã¶ãŒãè¿œå ããŸããïŒãŠãŒã¶ãŒã®ç®¡çãã¿ã³ïŒ
- äœæã«è¡ã
httpsïŒ// localhostïŒ8834 /
ãã©ãŠã¶ã§ãã©ãã·ã¥ã¯ã©ã€ã¢ã³ããååŸããŸã - [ã¹ãã£ã³]-> [è¿œå ]->ãã£ãŒã«ãã«å ¥åãïŒé©åãªã¹ãã£ã³ãããã¡ã€ã«ãéžæïŒã[ã¹ãã£ã³]ãã¯ãªãã¯ããŸãã
ãšã¯ã¹ããã€ãã«å¯ŸãããµãŒãã¹ã®å®çšçãªè匱æ§ã確èªããã«ã¯ãäžèšã®Metasploit Frameworkã䜿çšãããããšã¯ã¹ããã€ãïŒ Explot-db ã ãã±ããã¹ããŒã ã explot searchãªã©ïŒãèŠã€ã㊠ã ã·ã¹ãã ã«å¯ŸããŠæåã§äœ¿çšããŸãã
ç§èŠïŒããã°ãã 圌ã¯åœŒããœãããŠã§ã¢æ¥çã®ãã®åéã®ãªãŒããŒã®äžäººãšããŠé£ããŠããŸããã
å°åºèªåå
å€ãã®Webã¢ããªsecã¹ãã£ããŒã¯ã€ã³ãžã§ã¯ã·ã§ã³ãæ€çŽ¢ããŸããããŸã äžè¬çãªã¹ãã£ããŒã§ãã ãŸããã€ã³ãžã§ã¯ã·ã§ã³ã®æ€çŽ¢ãšæäœã«ç¹ã«é¢ä¿ãããŠãŒãã£ãªãã£ããããŸãã ãããã¯ä»è°è«ãããŸãã
sqlmap

sqlmapã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³ãèŠã€ããŠæäœããããã®ãªãŒãã³ãœãŒã¹ãŠãŒãã£ãªãã£ã§ãã MySQLãOracleãPostgreSQLãMicrosoft SQL ServerãMicrosoft AccessãSQLiteãFirebirdãSybaseãSAP MaxDBãªã©ã®ããŒã¿ããŒã¹ãµãŒããŒããµããŒãããŠããŸãã
å žåçãªäœ¿çšæ³ã¯æ¬¡ã®ããã«ãªããŸãã
python sqlmap.py -u "http://example.com/index.php?action=news&id=1"
ãã·ã¢èªãå«ãååãªããã¥ã¢ã«ã ãœããã£ãã¯ããã®åéã§äœæ¥ãããšããäºå¹Žçã®ä»äºã倧ãã«ä¿é²ããŸãã
å ¬åŒãããªãã¢ãè¿œå ããŸãã
bsqlbf-v2
bsqlbf-v2 -perlã¹ã¯ãªãããããã©ã€ã³ããSQLã€ã³ãžã§ã¯ã·ã§ã³ã®ãã«ãŒããã©ãŒãµãŒ ã URLã®æŽæ°å€ãšæååïŒæååïŒã®äž¡æ¹ã§æ©èœããŸãã
DBããµããŒãïŒ
- MS-SQL
- MySQL
- PostgreSQL
- ãªã©ã¯ã«
./bsqlbf-v2-3.pl -url www.somehost.com/blah.php?u=5 -blind u -sql "select table_name from imformation_schema.tables limit 1 offset 0" -database 1 -type 1
-url www.somehost.com/blah.php?u=5-ãã©ã¡ãŒã¿ãŒãšã®ãªã³ã¯
-blind u-ã€ã³ãžã§ã¯ã·ã§ã³ã®ãã©ã¡ãŒã¿ãŒïŒããã©ã«ãã§ã¯ãã¢ãã¬ã¹ããŒã®æåŸã®ãã©ã¡ãŒã¿ãŒãååŸãããŸãïŒ
-sql "imformation_schema.tables limit 1 offset 0ããtable_nameãéžæ" -ããŒã¿ããŒã¹ã«å¯Ÿããä»»æã®ãªã¯ãšã¹ã
-ããŒã¿ããŒã¹1-ããŒã¿ããŒã¹ãµãŒããŒïŒMSSQL
-type 1-æ»æã®ã¿ã€ããTrueããã³ErrorïŒæ§æãšã©ãŒãªã©ïŒã®åçã«åºã¥ãããã©ã€ã³ããã€ã³ãžã§ã¯ã·ã§ã³
ãããã¬ãŒ
ãããã®ããŒã«ã¯ãäž»ã«éçºè ãã³ãŒãå®è¡ã®çµæã«é¢ããåé¡ã®ããã«äœ¿çšããŸãã ãããããã®æ¹åã¯ãå¿ èŠãªããŒã¿ããã®å Žã§çœ®æããããå ¥åãã©ã¡ãŒã¿ãŒã«å¿çãããã®ãåæãããïŒãã¡ãžã³ã°ãªã©ã䜿çšïŒã§ãããªã©ããã³ãã¹ãã§ã圹ç«ã¡ãŸãã
ãã£ã·ã¹ã€ãŒã
Burp Suiteã¯ãäŸµå ¥ãã¹ãã«åœ¹ç«ã€äžé£ã®ãŠãŒãã£ãªãã£ã§ãã Webã¯ãRaz0rã®ãã·ã¢èªã®è¯ãã¬ãã¥ãŒã§ãïŒ2008幎ã«åœãŠã¯ãŸããŸãïŒã
ç¡æçã«ã¯ä»¥äžãå«ãŸããŸãã
- Burp Proxy-ããŒã«ã«ãããã·ããã©ãŠã¶ããæ¢ã«çæããããªã¯ãšã¹ããå€æŽã§ããŸãã
- Burp Spider-æ¢åã®ãã¡ã€ã«ãšãã£ã¬ã¯ããªãæ¢ããŠããã¯ã¢
- Burp Repeater-HTTPèŠæ±ãæåã§éä¿¡ããŸã
- Burp Sequencer-ãã©ãŒã å ã®ã©ã³ãã å€ã®åæ
- Burp Decoder-æšæºã³ãŒããã¯ïŒhtmlãbase64ãhexãªã©ïŒããã®äžã«ã¯ãä»»æã®èšèªã§ãã°ããèšè¿°ã§ããæ°åãã®ãã®ããããŸãã
- Burp Comparer-æååç §åã³ã³ããŒãã³ã
ãã£ãã©ãŒ

Fiddler -Fiddlerã¯ããã¹ãŠã®HTTPïŒSïŒãã©ãã£ãã¯ãèšé²ãããããã°ãããã·ã§ãã ãã®ãã©ãã£ãã¯ãæ¢çŽ¢ãããã¬ãŒã¯ãã€ã³ããèšå®ããçä¿¡ããŒã¿ãŸãã¯çºä¿¡ããŒã¿ã§ãåçãã§ããŸãã
Firesheep ãã¢ã³ã¹ã¿ãŒWiresharkãªã©ããããŸããéžæã¯ãŠãŒã¶ãŒã§ãã
ãããã«
åœç¶ã®ããšãªããããããã®å€ãã¯åçŽã«ååšãããããåäºåæã«ã¯ç¬èªã®æŠåšåº«ãšç¬èªã®ãŠãŒãã£ãªãã£ã»ããããããŸãã ç§ã¯æã䟿å©ã§äººæ°ã®ãããã®ãæã£ãŠããŠã¿ãŸããã ãããããã®æ¹åã§èª°ããä»ã®ãŠãŒãã£ãªãã£ã«ç²Ÿéã§ããããã«ã以äžã®ãªã³ã¯ãæäŸããŸãã
ã¹ãã£ããŒãšãŠãŒãã£ãªãã£ã®ããŸããŸãªããã/ãªã¹ã
- ã»ãã¥ãªãã£ããã³ãããã³ã°ããŒã«
- ããã100ãããã¯ãŒã¯ã»ãã¥ãªãã£ããŒã«
- ããã10 Webè匱æ§ã¹ãã£ã㌠ã
- ããã10è匱æ§ã¹ãã£ããŒ
- OWASPããã10ããŒã«ãšæŠè¡
- WebããŒã¹ã®ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã¹ãã£ããŒ
- WebAppSecã«ããWebã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã¹ãã£ããŒãªã¹ã
- RDotãã©ãŒã©ã ã®Infosec Utilities
- è匱æ§ã¹ãã£ããŒïŒWikipediaïŒ
Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ããã§ã«å€ãã®ç°ãªããã³ãã¹ããŠãŒãã£ãªãã£ãå«ãŸããŠããŸã
upd ïŒ Hack4SecããŒã ã«ãããã·ã¢èªã®BurpSuiteããã¥ã¡ã³ã ïŒ AntonKuzminãè¿œå ïŒ
PSããªãã¯XSpiderã«ã€ããŠæ²é»ããããšã¯ã§ããŸããã 圌ã¯ã¬ãã¥ãŒã«åå ããŸããããããã¯ã·ã§ã¢ãŠã§ã¢ã§ãïŒãã®ããïŒåœŒã¯ç¥èããªããææ°ããŒãžã§ã³7.8ããªãããïŒèšäºãSecLabã«éä¿¡ãããšãã«ããããèšäºã«ãããå«ããŸããã§ããïŒã ãããŠçè«çã«ã¯åœŒã®ã¬ãã¥ãŒã¯èšç»ãããŠããŸããïŒç§ã¯åœŒã®ããã«é£ãããã¹ããçšæããŠããŸããïŒããäžçã圌ãèŠããã©ããã¯ããããŸããã
PPSèšäºã®äžéšã®è³æã¯ãQAã»ã¯ã·ã§ã³ã®CodeFest 2012ã®ä»åŸã®ã¬ããŒãã§æå³ãããç®çã«äœ¿çšãããŸããããã§ã¯ãããã§èšåãããŠããªãããŒã«ïŒç¡æãessnoïŒãããã³äœ¿çšããé åºãæåŸ ãããçµæãæ§æã®ã¢ã«ãŽãªãºã ããããŸãäœæ¥äžã«ããããçš®é¡ã®ãã³ããã³ãã䜿çšããŸãïŒã¬ããŒãã«ã€ããŠã»ãŒæ¯æ¥èããŠããŸãããããã¯ã«ã€ããŠæé«ã®ããšãèªåã§äŒããããšããŸãïŒ
ã¡ãªã¿ã«ããã®èšäºã«ãããšã Open InfoSec Days ïŒ Habréã®ã¿ã° ã ãµã€ã ïŒã§ã¬ãã¹ã³ãããã