5æ30æ¥ãš31æ¥ã«ãDigital Octoberãã¯ãããžãŒã»ã³ã¿ãŒã¯ãå®çšçãªå®å šæ§åé¡ã«é¢ããPositive Hack Days 2012åœéãã©ãŒã©ã ãéå¬ããŸããã 1500人ãå€æ°ã®ã¬ããŒããšã¯ãŒã¯ã·ã§ããã倧èŠæš¡ãªCTF競æãè±å¯ãªç«¶æããã°ã©ã -ãããã¯ãã¹ãŠPHDaysã§ãã ããã§ãã€ã³ã¿ãŒãããã³ãã¥ããã£ã®ä»£è¡šè ãã»ãã¥ãªãã£ã®å°é家ãäžçäžã®ããã«ãŒããã®ç¹å¥ãªã«ã¯ãã«ãäœãšãæ··åããã«ã¯ãã«ãçŸå³ãããªã£ãããšãå šè²¬ä»»ã§å®£èšã§ããŸãã
ä»æ¥ãçŽæã©ãããPHDays 2012ã®ã¬ããŒããšã¯ãŒã¯ã·ã§ããã®èšé²ãå ¬éããŸããæ å ±ã»ãã¥ãªãã£ã«é¢ããã®ã¬ãã€ãã®ãããªã®äžã«ã¯ãã²ãŒãã®ããã¡ãŠã¹ããããã匷åãªãã®ããããŸã-ãã«ãŒã¹ã·ã¥ãã€ã¢ãŒãäžçæå·ã®äŒèª¬ã çŽ æµãªæ¯è²ãïŒ
äž»èŠè«æ
Bruce Schneierã«ãããããªã¬ããŒãã¯ã ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ13:00ããïŒã æå·åŠã®ç¬¬äžäººè ã¯åœŒã®ã»ãã¥ãªãã£å²åŠã«ã€ããŠèªããå€ãã®äººãé©ãããŸããã æ³ã®éåè ïŒããã«ãŒïŒã¯ã圌ã®æèŠã§ã¯ãæ害ã§ããã ãã§ãªãæçšã§ããããŸãã
Datuk Mohd Nur Aminã¯ããµã€ããŒè åšãšã®éããç®æããåœé£ã®å°éæ©é¢ã§ããåœéé»æ°éä¿¡é£åïŒITUïŒãšååãããåœé£äžã§ã®æåã®å ¬çæ©é¢ã§ããåœéãµã€ããŒè åšã«å¯ŸããåœéããŒãããŒã·ããïŒIMPACTïŒã®è°é·ã§ãã ã€ã³ãã¯ãã¯ããµã€ããŒã¹ããŒã¹ã®äžçæ倧ã®ã»ãã¥ãªãã£åäŒãšããŠèªèãããŠããŸãã 137ãåœã§æ§æãããŠããŸã[ ãã㪠]ã
ãã¬ã³ã
ã¬ããŒãïŒ Sergey Gordeychikãããã¬ã³ã ãããã¯ããŠçãç¶ããæ¹æ³-2.è«æ±ã«æãå·®ã䌞ã¹ãã[ ãã㪠]ã
æè¡ãããã¯ãŒã¯ã®éµã¯ã©ãã«ä¿åãããŠããŸããïŒ äŒç€Ÿã®äžæ žäºæ¥ã«åé¡ãçããããã«è«æ±æžãå ¥æããæ¹æ³ ããã«ã€ããŠãããã³éä¿¡ãããã¯ãŒã¯ã®äŸµå ¥ããã¹ãããæ°ãã瀺åçã§æ¥œããã±ãŒã¹ã«ã€ããŠãã»ã«ã²ã€ã¯åœŒã®ã¬ããŒãã§è¿°ã¹ãã
ã»ã¯ã·ã§ã³ïŒ Eugene KlimovããRISSPAã ãã¬ã³ã 察äžæ£ïŒèª°ãåã¡ãŸããïŒã ãããªã¯ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ12:15ããïŒã
å ¬å ±éšé
å ±åæžïŒããã€ã«ã»ãšã¡ãªã¢ãã³ãããå人ããŒã¿ã«é¢ãããã·ã¢ã®æ³åŸã«éåããªãããšã¯äžå¯èœãªå Žåãšçç±ã[ åç» ]ã
ã¬ããŒãïŒãã·ã¢ã®FSTECã®ã¢ã³ãã¬ã€V.ãã§ãã£ãã§ããããªãåœå®¶ã®ç§å¯ãã€ã³ã¿ãŒãããã«çŸããã®ãïŒã[ ãã㪠]ã
ã¬ããŒãïŒã¢ã¬ã¯ã»ã€ã»ã«ã«ãããŒãããã·ã¢ã®å€§çµ±é éžæã¯æ å ±ã»ãã¥ãªãã£åžå Žã«ã©ã®ããã«åœ±é¿ããŸããããŸãã¯èŠå¶ã¯ã©ãã«åãã£ãŠããŸããïŒããããªã¯ãã®ãªã³ã¯ã§å©çšã§ããŸãïŒååŸ4æããïŒã
ãããã¯ãŒã¯ã»ãã¥ãªãã£
ã¬ããŒãïŒãŠã©ãžããŒã«ã»ã¹ã¿ã€ã©ã³ããèåœã«ã€ããŠã®çå®ïŒã»ãã¥ãªãã£ã®ããã®ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã[ åç» ]ã
ãã¹ã¿ãŒã¯ã©ã¹ïŒã¢ã³ãã¬ã€ããµããããããã€ã³ã¿ãŒãããäžã®ç«¶äºçæ å ±ãã ãããªã¯ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ16:08以éïŒã
ãã¹ã¿ãŒã¯ã©ã¹ã®åå è ã¯ãå®éã®ç«¶åã€ã³ããªãžã§ã³ã¹ã®äŸã䜿çšããŠãåææè¡ãç¹ã«æ©å¯æ å ±ã®æŒæŽ©ãè¿ éã«æ€åºããæè¡ãããã³ãµãŒããŒã®ã»ã¯ã·ã§ã³ãéãæ¹æ³ãã»ãã¥ãªãã£ãç Žããã«FTPãµãŒããŒã«äŸµå ¥ããŠãã¹ã¯ãŒããªãŒã¯ãæ€åºããæ¹æ³ãããã³ã¢ã¯ã»ã¹ããæ¹æ³ã«ç²ŸéããŸããDLPããã€ãã¹ãã察å¿ããæš©éãªãã§ããŒãã£ã·ã§ã³ã«äŸµå ¥ããæ©å¯ææžïŒãšã©ãŒ403ïŒã ãã¢ã¯ãååã«ä¿è·ãããäŒæ¥ïŒITããã³æ å ±ã»ãã¥ãªãã£åžå Žã®ãªãŒããŒã倧èŠæš¡ãªæ¿åºæ©é¢ãç¹å¥ãµãŒãã¹ïŒã®ããŒã¿ã«ã®äŸã§å®æœãããŸããã
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Dmitry Ryzhavskyããã¯ã€ã€ã¬ã¹LANã»ãã¥ãªãã£ïŒãããã¯ãŒã¯ãžã®äŸµå ¥æ¹æ³ãšåé¿æ¹æ³ã[ ãã㪠]ã
ãã¬ãŒã³ããŒã·ã§ã³äžã«ãWi-Fiãããã¯ãŒã¯ãžã®äžæ£ã¢ã¯ã»ã¹ãååŸããããã®æãé©åãªæ¹æ³ãæ€èšããã説æãããæ»æããä¿è·ããããã®Cisco Unified Wireless Networkã®å æ¬çãªãœãªã¥ãŒã·ã§ã³ãæäŸããã¡ã«ããºã ãå®èšŒãããŸããã
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Sergey Lozhkinããã³ã³ãã¥ãŒã¿ãŒã€ã³ã·ãã³ãã®èª¿æ»ãã ãããªã¯ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ14:00ããïŒã
ãã®ã¯ãŒã¯ã·ã§ããã¯ãã€ã³ã¿ãŒããããªãœãŒã¹ãžã®äžæ£ã¢ã¯ã»ã¹ã«é¢é£ããã€ã³ã·ãã³ãã®èª¿æ»å°çšã§ããã ãã¹ãã¯ãªã¹ããŒã«çŸä»£ã®ããã«ãŒã®å¿ççãªèåã玹ä»ããäŸµå ¥è ã®çš®é¡ã«ã€ããŠè©±ããŸããã æªæã®ããè¡çºã®çè·¡ãæ€åºãããããã³ã°ä¿¡å·ã«å¿çããããšãããæ³å·è¡æ©é¢ãšååããŠæ»æè ãæ¢ãããšãŸã§ãã€ã³ã·ãã³ãã«åãçµãããã»ã¹ã調æ»ããŸããã ããã«ããã©ãŒã©ã ã®ã²ã¹ãã¯ãå®éã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«é¢ããèå³æ·±ã話ãèããŸããã
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Nikhil Mittalããå ¥åºåããã€ã¹ã®å©ããåããŠã«ãªã¹ãäœæããã[ ãã㪠]ã
ãã®ã¯ãŒã¯ã·ã§ããã§ã¯ãéåžžã«éèŠã§ãããæ®éçã«ç¡èŠãããŠããã³ã³ãã¥ãŒã¿ãŒã»ãã¥ãªãã£ã®åŽé¢ãã€ãŸã人éãšã®å¯Ÿè©±çšã«èšèšãããããã€ã¹ïŒHuman Interface DevicesãHIDïŒã®è匱æ§ã«ã€ããŠèª¬æããŸããã
ã¬ããŒãïŒ Sylvain Munotãããµã€ããŒç¯çœªè ã«ããã«ãªããœé»è©±ã®äœ¿çšã[ ãã㪠]ã
ã¬ããŒãïŒ Andrey KostinãPostScriptïŒå±éºïŒ MFPãPCãªã©ã®ãããã³ã°â [ ãã㪠]ã
ã¬ããŒãïŒã»ã«ã²ã€ã¯ã¬ãã®ã³ããCEHã å«ççãªãããã³ã°ãšäŸµå ¥ãã¹ãã[ ãã㪠]ã
ã¯ãŒã¯ã·ã§ããã®åå è ã¯ããããã¯ãŒã¯ãããã³ã«ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãããã³ã¢ããªã±ãŒã·ã§ã³ã®å žåçãªè匱æ§ã«ã€ããŠåŠã³ãŸããã ã¹ããŒãã®éçšã§ãé²è¡åœ¹ã¯ã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ããã³ãããã¯ãŒã¯ã«å¯ŸããããŸããŸãªçš®é¡ã®æ»æã®ã·ãŒã±ã³ã¹ã説æããã»ãã¥ãªãã£ã匷åããããã®æšå¥šäºé ãäœæããŸããã ãªã¹ããŒã¯å®éã®ç°å¢ã«é£ã³èŸŒã¿ãã·ã¹ãã ãå®éã«ãããã³ã°ããæ¹æ³ã確èªããŸããããã®åŸãããã«ãŒã®è¡åãäºæž¬ãããããã«ããŸã察åŠããããã§ãã
ãã¬ãŒã³ããŒã·ã§ã³ïŒ Travis GoodspeedããPackets-in-Packets Technologyã䜿çšããç¡ç·å¹²æžã®æäœããããªã¯ã ãã®ãªã³ã¯ã§å©çšã§ããŸãïŒ15:10ããéå§ïŒã
è¬æŒè ã¯ãPIPãšã¯ã¹ããã€ãã®æ©èœã«ã€ããŠèª¬æããIEEE 802.15.4ãããã¯ãŒã¯ãšå欧RFäœé»åç¡ç·ã¢ãžã¥ãŒã«ã®äŸã瀺ããŸããã
SAPãSCADAãERP
å ±åïŒãŠãã£ã³ã»ã¢ã¬ã¯ã»ã€ããæ»æè ã®ç®ããèŠãERPãã ãããªã¯ãã®ãªã³ã¯ã§å©çšã§ããŸãïŒ15:00ããïŒã
å ±åïŒã¢ã³ãã¬ã€ã»ããããŽã£ããã»ãã¥ã«ããããç£æ¥æ å ±ã·ã¹ãã ã®ä¿è·-人é¡ã®çåèŠå ã[ ãã㪠]ã
ã¬ããŒãïŒ Evgenia Schumacherããè·å Žãé¢ããã«ååã®çµŠäžã調ã¹ãæ¹æ³ããŸãã¯SAP HR Securityã[ ãã㪠]ã
å ±åïŒã¢ã¬ã¯ãµã³ããŒã»ããã€ããŽã£ãã»ããªã€ã³ãããSAPã®äžå®å®æ§ ïŒæ°ãããŠããè¯ãã[ ã€ã㪠]
ãã®ã¬ããŒãã¯ãæå·åã®åé¡ããèªèšŒã®ãã€ãã¹ãããããªãšã©ãŒããè€éãªæ»æãã¯ãã«ãŸã§ãSAPã·ã¹ãã ã§æãèå³æ·±ã10ã®è匱æ§ãšæ»æãã¯ãã«ã«å°å¿µããŸããã åããŠãäžè¬å€§è¡ã¯ãã¬ããŒãã«ç€ºãããè匱æ§ã®ããªãã®éšåã«ç²ŸéããŸããã
ã¯ãŒã¯ã·ã§ããïŒ Alexei Yudinããèªåã®æã§ã®SAPã»ãã¥ãªãã£ã[ ãã㪠]ã
ãã®ã¯ãŒã¯ã·ã§ããã®åå è ã¯ãå©çšå¯èœãªããŒã«ã䜿çšããŠãSAP R / 3ããã³NetWeaverã·ã¹ãã ïŒã¢ããªã±ãŒã·ã§ã³ãµãŒããŒãšã€ã³ãã©ã¹ãã©ã¯ãã£ãå«ãïŒã®åºæ¬çãªã»ãã¥ãªãã£åæãè¡ãæ¹æ³ãåŠã³ãŸããã
ãŠã§ãã»ãã¥ãªãã£
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Vladimir LepikhinãWebã¢ããªã±ãŒã·ã§ã³ãžã®æ»æã åºæ¬ã ãããªã¯ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ09:00ããïŒã
ãã®ã¬ããŒãã¯ãäŸµå ¥è ã®Webã¢ããªã±ãŒã·ã§ã³ãããªãã¯ãããã³ããŒã«ïŒæååæäžã®äœæ¥çµæã䜿çšããç¹æ®ãªã»ãã¥ãªãã£ã¹ãã£ããŒããŠãŒãã£ãªãã£ïŒã«å¯Ÿããæ»æãå®è£ ããã¡ã«ããºã ãäœç³»çã«æ瀺ããŸããã æ»æã®å®è¡ãå¯èœã«ããWebã¢ããªã±ãŒã·ã§ã³ã®å®éçãªåŒ±ç¹ã¯ãå®éã®äŸãšã䜿çšãããä¿è·ããŒã«ã®æ¬ ç¹ããã³ããããåé¿ããæ¹æ³ã«ãã£ãŠç€ºãããŸããã
ã¬ããŒãïŒ Miroslav StamparããDNSãä»ããããŒã¿æŒæŽ©ïŒsqlmapã®äœ¿çšã[ ãã㪠]ã
ã¹ããŒã«ãŒã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³ã䜿çšããDNSæœåºæè¡ã玹ä»ãããã®é·æãšçæã«ã€ããŠè©±ããèŠèŠçãªãã¢ã³ã¹ãã¬ãŒã·ã§ã³ãè¡ããŸããã
ã¬ããŒãïŒ Vladimir VorontsovããMicrosoftãããã¯ãŒã¯ã®Webã¯ã©ã€ã¢ã³ããžã®æ»æã[ ãã㪠]ã
ãã®ã¬ããŒãã§ã¯ããŠãŒã¶ãŒãMicrosfotãããã¯ãŒã¯å ã§Internet Explorerãæ»æã§ããæ¹æ³ã«ã€ããŠèª¬æãããªã¢ãŒããµãŒããŒïŒã¢ã¯ã»ã¹ããªã·ãŒã®å¶éãåé¿ïŒãšããŒã«ã«PCã®äž¡æ¹ã«ããæ©å¯ãŠãŒã¶ãŒããŒã¿ã®ååŸãç®çãšããæ»æãæ€èšããŸããã
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Andres RyanchoããSecurity Web 2.0ã é«åºŠãªãã¯ããã¯â [ ãã㪠]ã
ãã¹ã¿ãŒã¯ã©ã¹ã¯ãXMLãHPP / HPCã䜿çšããæ»æãããã³ã¯ãªãã¯ãžã£ããã³ã°ãã»ãã·ã§ã³ããºã«ãªã©ã®æ»æããä¿è·ããããã®ææ³ãæ€èšããŸããã
ã¬ããŒãïŒ Sergey Shcherbelãããã¹ãŠã®PHPãåãããã«åœ¹ç«ã€ããã§ã¯ãããŸãããã ãããªã¯ãã®ãªã³ã¯ã§å©çšã§ããŸãïŒ16:00ããïŒã
ã¬ããŒãã§ã¯ããŒããã€è匱æ§ã®äŸãšåæ§ã«ããµãŒãããŒãã£ã®PHPå®è£ ã䜿çšããå Žåã®Webã¢ããªã±ãŒã·ã§ã³ã®åäœã®ç¹å®ãããã»ãã¥ãªãã£åé¡ãšæ©èœã調ã¹ãŸããã
ã¬ããŒãïŒ ThibaultKöhlenããNaxsiã¯ããžãã£ãã»ãã¥ãªãã£ã¢ãã«ã«åºã¥ãããªãŒãã³ãœãŒã¹ã®Webã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ã§ãã[ ãã㪠]ã
ã¬ããŒãïŒ Alexey MoskvinããPHPã©ãããŒã®å®å šãªäœ¿çšã«ã€ããŠã[ ãã㪠]ã
ã¬ããŒãïŒ Vladimir KochetkovããASP.NETã®ãµã€ãããããã³ã°ããŸããïŒ é£ããããå¯èœã ïŒã[ ãã㪠]ã
ãã®ã¬ããŒãã§ã¯ãæ ¹æ¬çã«æ°ããã¿ã€ãã®ãã³ãŒãã€ã³ãžã§ã¯ã·ã§ã³ãæ»æãå«ããæ°ãããŒããã€è匱æ§ã®äŸãšãã®æªçšã®å¯èœãªãã¯ããã¯ãæ€èšŒããŸããã
ã¢ãã€ã«ã»ãã¥ãªãã£
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Manish ChastaããAndroidã®ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã[ åç» ]ã
ãã®ã¬ããŒãã§ã¯ãAndroidã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ãæ€åºããã³æé€ããããã®ææ³ã«ã€ããŠç°¡åã«èª¬æããŸããã ããã«ããã®ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ãAndroidãã©ãããã©ãŒã ã§å®è¡ãããŠããããã€ã¹ã®ç®¡çè æš©éãååŸããåé¡ïŒAndroidã«ãŒãã£ã³ã°ïŒãSQLiteããŒã¿ããŒã¹ã®åæãAndroid Debug BridgeïŒADBïŒã®ã¢ããªã±ãŒã·ã§ã³ãã¢ãã€ã«ãµãŒããŒã«é¢é£ããè åšã«å¯ŸåŠããŸããã Open Web Application Security ProjectïŒOWASPïŒã³ãã¥ããã£ã«ãã£ãŠå ¬éãããã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿãã10ã®æãå±éºãªè åšã®ãªã¹ããèŽè¡ã«æ瀺ãããŸããã
ã¬ããŒãïŒ Marcus NimitzããAndroidã®ãŠãŒã¶ãŒã€ã³ã¿ãŒãã§ã€ã¹ã®ååã[ ãã㪠]ã
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Sergey Nevstroyevããã¢ãã€ã«ã»ãã¥ãªãã£ã®å®çšçåŽé¢ã[ ãã㪠]ã
ããããããã®æŠã
ã¬ããŒãïŒ Maria Garnayevaããããããã¹ã¿ãŒã®ãã€ãŒã«ã«ã¹ãã£ãã¯ãæ¿å ¥ããæ¹æ³ïŒKelihosãããããããã ãããªã¯ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ09:10以éïŒã
å ±åïŒã¢ã¬ã¯ãµã³ããŒã»ãŽã¹ããã ãã®å ±åæžã¯ããšããšãThe Secret of DuQuããšåŒã°ããŠããŸãããããã®åŸãçºèšè ã¯FlameãšåŒã°ããæ°ããè åšã«çŠç¹ãåãããããšã«ããŸããã ãããªã¯ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ14:00ããïŒã
å ±åïŒã¢ã¬ã¯ãµã³ãã«ã»ãªã¢ãã³ãDDosïŒãµãã€ãã«ã®å®è·µã¬ã€ãã ããŒã2ãã ãããªã¯ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ17:03ããïŒã
ã¬ããŒãïŒ Fedor YarochkinãVladimir Kropotovããããããããã®ã©ã€ããµã€ã¯ã«ãšãããã¯ãŒã¯ãã©ãã£ãã¯ã®åæã«ããããããããã®æ€åºã[ ãã㪠]ã
ãã¹ã¿ãŒã¯ã©ã¹ïŒããšãŒã«ãã«ã¯ãã¥ãŒããŒã ãWin32 / Georbotã ãã«ãŠã§ã¢ã®æ©èœãšãã®èªååæâ [ ãã㪠]ã ãã®ããããããäžã®äžçåã®ãã¹ã¿ãŒã¯ã©ã¹ã
ãã¹ã¯ãŒãä¿è·ã®åé¡
ã¬ããŒãïŒ Aleksey Evgenievich Zhukovãã軜éæå·åïŒãªãœãŒã¹ã«å¯ŸããèŠæ±ãå³ãããªããæ»æã«åŒ·ãã ãããªã¯ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ12:00ããïŒã
ã¬ããŒãïŒ Dmitry SklyarovãAndrey Belenkoããã¹ããŒããã©ã³çšã®å®å šãªãã¹ã¯ãŒããããŒãžã£ãŒãšè»çšã°ã¬ãŒãã®æå·åïŒãCheãseriouslyïŒ..ããã ãããªã¯ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ10:15ããïŒã
ãã¬ãŒã³ããŒã·ã§ã³ïŒ AlexanderïŒSolar DesignerïŒPeslyakãããã¹ã¯ãŒãä¿è·ïŒéå»ãçŸåšãæªæ¥ã[ ãã㪠]ã
ãã¬ãŒã³ããŒã·ã§ã³ã®äžç°ãšããŠããã¹ã¯ãŒãä¿è·ã®åé¡ãéçºå±¥æŽãããã³èªèšŒæè¡ã®åœé¢ã®èŠéããæ€èšãããŸããã
å ±åïŒãã³ãžã£ãã³ã»ãã«ããŒããããã«ããã Windows 8ã®ãã¹ã¯ãŒããå埩ããŸããã[ ãã㪠]ã
ããã«ãŒãšãé
ã»ã¯ã·ã§ã³ïŒ Artyom Sychevãã圌ãã¯ã©ã®ããã«ãéãä¿è·ããŸããïŒã[ ãã㪠]ã
ã¬ããŒãïŒ Dmitry Gorelovãããã·ã¢ã®ã¹ããŒãã«ãŒãïŒå ¬è¡é»è©±ããUECãžãã ãããªã¯ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ10:00ããïŒã
ã¬ããŒãïŒ Alexander MatrosovãEvgeny Rodionovããææ°ã®ãã³ãã³ã°ãã«ãŠã§ã¢ã«é¢ããã¹ããŒãã«ãŒãã®è匱æ§ã ãããªã¯ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ11:07ããïŒã
ãææ°ã®ãã³ãã³ã°ãã«ãŠã§ã¢ã«é¢ããã¹ããŒãã«ãŒãã®è匱æ§ããšããã¬ããŒããäœæããã«ããããã¹ããŒã«ãŒã¯ãã®ãããªããã°ã©ã ã®æãäžè¬çãªãã®ã調æ»ãã2èŠçŽ èªèšŒãšã¹ããŒãã«ãŒãã䜿çšããå Žåã®èå³æ·±ãè匱æ§ãæããã«ããŸããã ããã«ããã®ã¬ããŒãã§ã¯ãæ³å»åŠçæ€æ»ã®å®æœã劚ããæªæã®ããèŠå ãããªãã¯ã«ã€ããŠã説æããŠããŸãã
å ±åïŒãã«ã»ããŒãã³ãããªã³ã©ã€ã³ã§ã¯ã¬ãžããã«ãŒãã§æ¯æããŸããïŒã é çã«åããŸãããã[ ãã㪠]ã
å®çšçãªå®å šæ§
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Boris RyutinãããŠã€ã«ã¹å¯Ÿçãªãã®ã»ãã¥ãªãã£ã[ åç» ]ã
ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ããã€ã®æšéŠ¬ãæ€åºããåºæ¬çãªã¹ãã«ãç¿åŸãã4æéã®ãã¹ã¿ãŒã¯ã©ã¹ã¯ãWindowsçšã®ããã€ã®æšéŠ¬ïŒSpyEyeãCarberpãDuquïŒãéçºããããã®æãé«åºŠãªæè¡ãç 究ããAndroidçšã®ããã€ã®æšéŠ¬ã調ã¹ãçŸåšã®ãšã¯ã¹ããã€ãïŒPDFãJavaïŒã®åæã«ã粟éããŸããã
ã¬ããŒãïŒãŠãŒãªã»ã°ãããããå¹²ãèã®å±±ã§è±¡ãèŠã€ããæ¹æ³ã[ ãã㪠]ã
ã¬ããŒãïŒ Dmitry Evdokimovããã³ãŒãåæããŒã«ïŒæããé¢ãšæãé¢ã[ ãã㪠]ã
Dmitryã¯ããœãŒã¹ã³ãŒãããã€ãã³ãŒãããã€ããªã³ãŒããã€ã³ã¹ãã«ã¡ã³ãããæ¹æ³ãæ€èšããŸããã
ã¬ããŒãïŒ Nikita TarakanovãAlexander Bazhanyukããèªåè匱æ§æ€çŽ¢ããŒã«ãã ãããªã¯ãã®ãªã³ã¯ã§å©çšã§ããŸãïŒ17:00ããïŒã
ã¬ããŒãïŒ Igor KotenkoãããœãããŠã§ã¢ãšãŒãžã§ã³ãã®ãµã€ããŒæŠäºïŒã€ã³ããªãžã§ã³ããšãŒãžã§ã³ãã®ããŒã ã¯ãŒã¯ã®çè«ãå¿çšãããµã€ããŒè»éã®æ§ç¯ã[ ãã㪠]ã
ã¬ããŒãïŒ Ulrich FleckãMartin Eisnerãã人æ°ã®ãããã¬ãŒã ã¯ãŒã¯ã®äŸã§0æ¥ããAPTãžã®æ»æã[ ãã㪠]ã
ã»ã¯ã·ã§ã³ïŒãã¢ã»ã¯ã·ã§ã³ãäžåºŠèŠãã»ããããã ãããªã¯ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ17:10以éïŒã
å¿åããã³LulZ
ã¬ããŒãïŒãžã§ãªãŒã¬ã³ããªã³ããLulzSecã¹ããŒãªãŒããäœãåŠã¶ããšãã§ããŸãïŒãŸãããããã¹ããïŒã[ ãã㪠]ã
è¬æŒäžããžã§ãªãŒã¯äººã ã®ã°ã«ãŒãã«ããããããŒãªã³ã°ãã®å¯Ÿè±¡ã«ãªããŸããããé©ããããªãŠãŒã¢ã¢ã®ã»ã³ã¹ã«åå¿ããŸãã[ ãã㪠]ã
å ±åïŒãã€ãŒã ã»ãšã«ã»ããŒã«ãããã¥ããžã¢ã¯ã©ã®ããã«å¿åã«çŽé¢ãããã ãããªã¯ãã®ãªã³ã¯ããå ¥æã§ããŸãïŒ14:10ããïŒã
ãã®ä»ã®ãããã¯
å ±åïŒã¢ã¬ã¯ã»ã€ã»ã¢ã³ãã¬ãŒãšãïŒããŒã·ãŒã»ã·ã§ãªãŒïŒãããµã€ããŒãã³ã¯ã®éå»ãšæªæ¥ã[ åç» ]ã
ã¢ã¬ã¯ã»ã€ã¯ããã·ã¢ã®ãµã€ããŒãã³ã¯ã®çºå±ã«é¢ãã圌ã®èŠè§£ãå ±æããŸããã
å ±é ¬ïŒåè³è ã«ã¯è³å[ ãã㪠]ãèŽãããŸãã
ã³ã³ãµãŒãïŒãã©ãŒã©ã çµäºæã®Underwoodã°ã«ãŒã[ ãã㪠]ã
PS以äžã§ã¯ãPositive Hack Days 2012ãã©ãŒã©ã ã«é¢ããã¬ãã¥ãŒãå«ãããŸããŸãªããã°ã®ãšã³ããªãžã®ãªã³ã¯ãå ¬éããŠããŸãã
sgordey.blogspot.com/2012/06/phdays.html
andreicostin.com/index.php/brain/2012/06/08/phdays_2012_overview
sgordey.blogspot.com/2012/06/blog-post_07.html
www.itsec.pro/2012/06/phdays.html#more
blog.eset.com/2012/06/05/smartcard-vulnerabilities-in-modern-banking-malware
alekskrasnov.blogspot.com/2012/06/phdays-everywhere.html
hashcat.net/forum/thread-1246.html
xanadrel.blogspot.fr/2012/06/phd-hash-runner-contest.html
forum.insidepro.com/viewtopic.php?p=95655#95655
lexa.livejournal.com/47491.html
devteev.blogspot.com/2012/06/phdays-2012.html
amatrosov.blogspot.com/2012/06/phdays2012.html
c3ret.wordpress.com/2012/06/04/positive-hack-days-2012
blog.scrt.ch/2012/06/04/ctf-phdays-2012
ax330d.blogspot.de/2012/06/positive-hack-days-2012-moscow.html asintsov.blogspot.de/2012/06/phdays-write-up.html
toxa.livejournal.com/549105.html
oxod.ru/?p=367
scii.ru/_shr/2012/06/phdays-2012-%D0%B2%D0%BF%D0%B5%D1%87%D0%B0%D1%82%D0%BB%D0%B5%D0%BD ïŒ D0ïŒ B8ïŒ D1ïŒ 8F
vkochetkov.blogspot.de/2012/06/phdays-2012.html
jerrygamblin.com/post/24221592284/phdays
jerrygamblin.com/post/24165573828/trolled-in-russia
www.tsarev.biz/informacionnaya-bezopasnost/positive-hack-days-2012-poslevkusie
raz0r.name/other/phdays-snatch-writeup
i-business.ru/blogs/20371
www.securitylab.ru/blog/personal/secinsight/22549.php
securegalaxy.blogspot.com/2012/06/dery.html
Twitterã§ãã©ãŒã©ã ããŒããèªã¿ããïŒãŸãã¯TwitterãããŒããã£ã¹ããèªã¿çŽããã ïŒå Žåã¯ãããã·ã¥ã¿ã°#PHDaysã䜿çšããŠãã ããã