å人ãä»å¹Žã®äŒè°ã®äž»èŠãªãããã¯ã®1ã€ã¯ä»®æ³åã§ãã æçµçã«åºèª¿è¬æŒè ã®äžäººã決å®ããŸããã ããã¯ãé·å¹Žãã®ãããã¯ã«åãçµãã§ããã©ãã¡ã«ã»ãŽã©ã€ãã¥ã¯ã§ãã
ç¥ããªã人ã®ããã«ïŒRafal Wojtczuk-ã¡ã¬ã¯ãŒã«ã¹ãã·ã£ã«ïŒ 圌ã¯Invisible Things Labsã®å åŸæ¥å¡ã§ãããJoanna Rutkowskaã§é·ãéåããŠããããXen Hypervisor Subversionsã®æ€åºãšé²æ¢ãããXen 0wning TrilogyïŒcode and demosãããAttacking Intel Trusted Execution Technologyããªã©ã®ç 究ã«åå ããŸããããæéã®ç¯çŽã§9ãç¯çŽïŒè€æ°ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®è匱æ§ã®äºäŸããªã©ã æè¿ã圌ã¯é«åºŠãªIntelã»ãã¥ãªãã£æè¡ãç¹ã«TXTãšVTdãç 究ããŸããã ãŸããäœã¬ãã«ã®ããã±ãŒãžåã¢ã»ã³ããªã©ã€ãã©ãªã§ããlibnidsã®äœæè ã§ããããŸãã äžè¬çã«ãããã¯ãµã³ãããã¯ã¹ãšä»®æ³åã·ã¹ãã ãã©ã®ããã«æ©èœããã©ã®ããã«æ©èœããããçŽæ¥ç¥ã£ãŠãã人ã§ãã 圌ã¯ã¯ã©ãŠãã«é¢ããããŒã±ãã£ã³ã°ã®ã§ããããé§ãç«ãŠãã€ããã¯ãããŸããããä»®æ³åãå®éã«ã©ã®ããã«æ©èœãããã説æããŸãã
ãŸããç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®å®å šæ§ã«ã€ããŠã詳ãã説æããŸãã ç¹ã«ãZeroNights 2013ã§ã¯ãããžã¿ã«ã»ãã¥ãªãã£ãªãµãŒãã»ã³ã¿ãŒããICSã®å®å šæ§ã«é¢ãã2ã€ã®ææ°ã®ç 究ãHARTïŒinïŒã»ãã¥ãªãã£ããšãAVRããã³MSPãã€ã¯ããããã®åäœãã®çµæãåããŠçŽ¹ä»ããŸãã
ãããã£ãŠã ã¡ã€ã³ããã°ã©ã ã§ã®ã¬ããŒãïŒ
1.ãä»®æ³åãµã³ãããã¯ã¹ã«ããã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ä¿è·ïŒéå»ãçŸåšãæªæ¥ããã¹ããŒã«ãŒRafal WojtczukïŒããŒã©ã³ãïŒ
ã¬ããŒãã®èª¬æ
ãã©ãŠã¶ãŒãªã©ã®çŸä»£ã®å€§èŠæš¡ãªã¢ããªã±ãŒã·ã§ã³ã¯éåžžã«è€éã§ãããããè匱æ§ãªãã§ãªãªãŒã¹ããããšãæããã®ã¯ãããŸããã ãã®ãããå€ãã®éçºè
ã¯ä»£æ¿ã¢ãããŒãã䜿çšããŸã-䟵害ãããã¢ããªã±ãŒã·ã§ã³ãæ®ãã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããéé¢ããããã«èšèšãããã³ã³ããã§å®è¡ããŸãã ãã®ãããªã³ã³ããã¯ãã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã§ã®ãµã³ãããã¯ã¹ã®äœ¿çšãOSå
šäœã®ä»®æ³åãéããŠäœæã§ããŸãã åé¡ã¯ããã®åé¢æ¹æ³ãã©ãã»ã©å®å
šã§ä¿¡é Œã§ãããã§ãã
ãã®ã¬ããŒãã§ã¯ãäž¡æ¹ã®åé¢æ¹æ³ã®é·æãšçæããŸãšããŠæ¯èŒããŸãã å ·äœäŸã«ã€ããŠèª¬æããŸãïŒSandboxieãGoogle ChromeãQubes OSãBromium vââSentryã ãããã®æ±ºå®ã®é²åãèŠãŠãå°æ¥ããããåŸ ã£ãŠãããã®ãäºæž¬ããããšããŸãã
ãã®ã¬ããŒãã§ã¯ãäž¡æ¹ã®åé¢æ¹æ³ã®é·æãšçæããŸãšããŠæ¯èŒããŸãã å ·äœäŸã«ã€ããŠèª¬æããŸãïŒSandboxieãGoogle ChromeãQubes OSãBromium vââSentryã ãããã®æ±ºå®ã®é²åãèŠãŠãå°æ¥ããããåŸ ã£ãŠãããã®ãäºæž¬ããããšããŸãã
2.ãJSMVCOMFG-JavaScript MVCããã³ãã³ãã¬ãŒããã¬ãŒã ã¯ãŒã¯ã®è©³çŽ°ããã¹ããŒã«ãŒMario HeiderichïŒãã€ãïŒ
ã¬ããŒãã®èª¬æ
éåžžã®ã¯ã©ã·ãã¯Webã¢ããªã±ãŒã·ã§ã³ãéçºã§ããŸãã ãµãŒããŒãããŒã¿ããŒã¹ãå°ãã®HTMLãå°ãã®JavaScriptãç¥ã£ãŠããŸãã ãã¶ããããªãã®ç¥æ¯ãããããèšèšããŸããã ãŸããçŸãããŠãããã§ã軜ããŠã¢ãã³ã§ãæè»ã§ã¹ã±ãŒã©ãã«ãªã¯ã©ã€ã¢ã³ãWebã¢ããªã±ãŒã·ã§ã³ãéçºã§ããŸãã æã
ãããã®åŸãã«ãµãŒããŒãæã«ã¯ããŒã¿ããŒã¹ããããŸããããã¹ãŠã®æ°ããæ©èœã®ã»ãšãã©ãèããŠããŸã-ãã¢ãã«-ãã¬ãŒã³ããŒã·ã§ã³-ã³ã³ãããŒã©ãŒãã®ååã«åºã¥ããŠæ§ç¯ãããJavaScriptãã¬ãŒã ã¯ãŒã¯ã
AngularãEmberãCanJSãKnockoutãHandlebarsãUnderscore ...ãããã¯æåãªãã¡ã€ã¿ãŒã®ååã§ã¯ãªãããã©ãŠã¶ãŒã§å€ãã®ããšãçŽæ¥åŠçããéæ³ã®èœåã«ãããããçç£çã§çç£çãªçŸä»£ã®JSãã¬ãŒã ã¯ãŒã¯ã®ååã§ãã ããå€ãã®äººã ããã¡ãã·ã§ããã«ã§ãããååã«åŸã£ãŠããããã®ãã¬ãŒã ã¯ãŒã¯ãã€ã³ã¹ããŒã«ããŠå€§æåãåããŠããŸãã èŠåå¡ã®å³ããè¡šæ ã§ãã®ç§æããã£ã¹ãããæã§ãããïŒ
ãã®ã¬ããŒãã§ã¯ãããããã¹ãŠã®ãã¬ãŒã ã¯ãŒã¯ãã©ã®ããã«æ©èœããããã³ã¢ã®å®å šæ§ããã®ãã«æ©èœã®å®åº«ãã泚ãããã»ãã¥ãªãã£åé¡ãåŠç¿ããŸãã èè ã¯DOMãååã«ç 究ããŠãæ°åå±€ã®æœè±¡åã§DOMãå å®ãããŸãããïŒ ãããã¯ãæ°ããã€ã³ãžã§ã¯ã·ã§ã³ã®è匱æ§ãšææªã®ããã°ã©ãã³ã°æ £è¡ã§æº¢ããŠããJavaScriptã®å°çãžã®æãéããã®ã§ããããïŒ ãã®ã¬ããŒãã®åŸãç解ã§ããŸãã ããªãã¯ãã¹ãŠãç解ããŸã...
AngularãEmberãCanJSãKnockoutãHandlebarsãUnderscore ...ãããã¯æåãªãã¡ã€ã¿ãŒã®ååã§ã¯ãªãããã©ãŠã¶ãŒã§å€ãã®ããšãçŽæ¥åŠçããéæ³ã®èœåã«ãããããçç£çã§çç£çãªçŸä»£ã®JSãã¬ãŒã ã¯ãŒã¯ã®ååã§ãã ããå€ãã®äººã ããã¡ãã·ã§ããã«ã§ãããååã«åŸã£ãŠããããã®ãã¬ãŒã ã¯ãŒã¯ãã€ã³ã¹ããŒã«ããŠå€§æåãåããŠããŸãã èŠåå¡ã®å³ããè¡šæ ã§ãã®ç§æããã£ã¹ãããæã§ãããïŒ
ãã®ã¬ããŒãã§ã¯ãããããã¹ãŠã®ãã¬ãŒã ã¯ãŒã¯ãã©ã®ããã«æ©èœããããã³ã¢ã®å®å šæ§ããã®ãã«æ©èœã®å®åº«ãã泚ãããã»ãã¥ãªãã£åé¡ãåŠç¿ããŸãã èè ã¯DOMãååã«ç 究ããŠãæ°åå±€ã®æœè±¡åã§DOMãå å®ãããŸãããïŒ ãããã¯ãæ°ããã€ã³ãžã§ã¯ã·ã§ã³ã®è匱æ§ãšææªã®ããã°ã©ãã³ã°æ £è¡ã§æº¢ããŠããJavaScriptã®å°çãžã®æãéããã®ã§ããããïŒ ãã®ã¬ããŒãã®åŸãç解ã§ããŸãã ããªãã¯ãã¹ãŠãç解ããŸã...
3.ãã€ã³ã¿ãŒããããã³ãã³ã°ã¢ããªã±ãŒã·ã§ã³ã§ã®äžžãã®è匱æ§ã®å®éçãªå©çšããã¹ããŒã«ãŒAdrian FurtunaïŒã«ãŒããã¢ïŒ
ã¬ããŒãã®èª¬æ
ãã®ã¬ããŒãã§ã¯ãã€ã³ã¿ãŒããããã³ãã³ã°ã¢ããªã±ãŒã·ã§ã³ã§äžè¬çãªäžžãã®è匱æ§ã«ã€ããŠèª¬æããŸãã èªèšŒããŒã¯ã³ïŒããšãã°ãDigipassïŒãæ»æããŠãæ»æè
ãçæéã§å€æ°ã®ãã©ã³ã¶ã¯ã·ã§ã³ãèªåçã«å®è¡ã§ããããã«ããã¡ã«ããºã ãªã©ãæäœã®å€ãã®æ¹æ³ãæ瀺ãããŸãã
4.ãã ãŸãããæ©æ¢°ãã¹ããŒã«ãŒGlenn WilkinsonïŒãã©ã³ã¹ïŒ
ã¬ããŒãã®èª¬æ
ç§ãã¡ã«é䌎ããããã€ã¹ã¯ãäžæã«èå¥å¯èœãªä¿¡å·ãçºä¿¡ãããããç§ãã¡ã®ç§å¯ãæããã«ããŸãã ãã®ãããªä¿¡å·ã¯ãããªãã®äœçœ®ã远跡ããããã«äœ¿çšããããšãã§ããŸãã ãã®ã¬ããŒãã§ã¯ã埩å
åãã¢ãžã¥ãŒã«æ§ãä¿¡é Œæ§ãåæ£æ§ãè¿œè·¡å Žæãã€ã³ã¿ãŒã»ãããããã³ãããã¡ã€ã«ããŒã¿ã§ãããã¬ãŒã ã¯ãŒã¯ãäœæããããã«èè
ãåã£ããã¹ã«ã€ããŠèª¬æããŸãã
5.ãHARTïŒinïŒsecurityããã¹ããŒã«ãŒã®Alexander BolshevãšAlexander MalinovskyïŒãã·ã¢ïŒ
ã¬ããŒãã®èª¬æ
é»æµã«ãŒããšãããä»ããŠããŒã¿ãéä¿¡ããç£æ¥çšãããã³ã«ã«ã€ããŠäœãç¥ã£ãŠããŸããïŒ ãã®ã¬ããŒãã¯ãHARTãããã³ã«ã調ã¹ããããæ»æããããŸããŸãªæ¹æ³ãšãããã䜿çšãããœãããŠã§ã¢ããã³ããŒããŠã§ã¢ã瀺ããŸãã ãã±ãããèªã¿åããçŸåšã®ã«ãŒãã«æ¿å
¥ããæ¹æ³ãšãããã«ããSCADAãOPCãããã³PASã·ã¹ãã ãã¯ã©ãã·ã¥ããåå ãæããŸãïŒãããŠè¡šç€ºããŸãïŒïŒã 1ã€ã®æž©åºŠã»ã³ãµãŒãACS / TPã®è€åäœå
šäœãããŠã³ãããæ¹æ³ãç¥ãããå Žåã¯ãããã«ããŸãã
6.ãAVRããã³MSPãã€ã¯ããããã®åäœããã¹ããŒã«ãŒVadim BardakovïŒãã·ã¢ïŒ
ã¬ããŒãã®èª¬æ
ãã€ã¯ãã³ã³ãããŒã©ã䜿çšããå Žåã®ã»ãã¥ãªãã£åé¡ã¯ãéåžžãè匱æ§ã®æªçšã«å¯Ÿããä¿è·ã®ãããã¯ã«åœ±é¿ãäžããããšãªãããã€ã¯ãã³ã³ãããŒã©ã«åã蟌ãŸãããœãããŠã§ã¢ã®ä¿è·ã®åŽé¢ããèæ
®ãããŸãã ãã®ã¬ããŒãã§ã¯ãAVRãšMSPãäŸãšããŠäœ¿çšããŠããã€ã¯ãã³ã³ãããŒã©ãŒåºæã®è匱æ§ãæªçšããæ©èœãæ€èšŒããŸãã
ãããŠä»ãç§ãã¡ã®ã¯ãŒã¯ã·ã§ããã«ã€ããŠïŒ
1.ãPeach Fuzzingãã¯ãAdam CecchettiïŒã¢ã¡ãªã«ïŒã«ãã£ãŠéå¬ãããŸã
ã¬ããŒãã®èª¬æ
ãã®ã¯ãŒã¯ã·ã§ããã¯ãPeach 3.0ã§ã®ãã¡ãžã³ã°ã®æŠèŠã§ãã åå è
ã¯ãPeachã®å€ãã®æ©èœã®æŠèŠãšããããã®æ©èœãèªåã®ãã¹ãç°å¢ã«çµã¿èŸŒãæ¹æ³ãåŠã³ãŸãã ããŒã¿ãç¶æ
ããã¹ãã¢ãã«ã®ãã©ãã€ã ãããã³ãããã®çµã¿åããã®çµæãšããŠã«ã¹ã¿ã ãã¡ã¶ãŒã®çµã¿åãããã©ã®ããã«ä¿é²ããããã«ã€ããŠã®çã話ããããŸãã æåŸã«ããã£ãŒãããã¯ãç£èŠããŠé害ããŒã¿ãåéããããã«ãPeachããã¹ã察象ã®ã·ã¹ãã ã«æ¥ç¶ããæ¹æ³ã瀺ããŸãã
2.ãæ å ±ã»ãã¥ãªãã£ã®åé¡ã«å¯ŸããSMTãœã«ããŒã®äœ¿çšã®æŠèŠãã¯ãGeorgy NosenkoïŒãã·ã¢ïŒã«ãã£ãŠå®æœãããŸãã
ã¬ããŒãã®èª¬æ
ãã®ã¯ãŒã¯ã·ã§ããã§ã¯ãSMTãœã«ããŒã䜿çšãããœãããŠã§ã¢ã³ãŒãã®åæåéã«ãããè¿å¹Žã®çµæãåŠçã«çŽ¹ä»ããŸãã
ãã¬ãŒãã³ã°äžãåŠçã¯ãç 究è ãè匱æ§ã®æ€çŽ¢ããšã¯ã¹ããã€ãã®éçºããªããŒã¹ãšã³ãžãã¢ãªã³ã°ã«äœ¿çšããææ³ã®åºç€ãšãªãåçã«é¢ããçè«çç¥èã身ã«ã€ããŸãã ãã®åŸãååŸããç¥èãå®éã«çµ±åãããŸãã
ç®æšã¯ãSMTãœã«ããŒã䜿çšããããŒã«ã®å¹æçãªé©çšã«å¿ èŠãªåæç¥èãæäŸããããã«ããããã¯ã®åå è ã«èå³ãæãããããšã§ãã
ã¯ãŒã¯ã·ã§ããã®ãããã¯ïŒ
â¢SMTãœã«ããŒã®äœ¿çšã®åºæ¬ãå©ç¹ãæ¬ ç¹ãå¶éã
â¢è匱æ§ãæ€çŽ¢ããŸãã
â¢èªåãšã¯ã¹ããã€ãçæã®ã¿ã¹ã¯ã
â¢ã·ã³ããªãã¯\ã³ã³ã³ãªãã¯å®è¡ã
â¢äžéèšèªïŒäžéèšèªïŒã
åå è ã¯ä»¥äžãåãåããŸãïŒ
-Z3 SMTãœã«ããŒã®äœ¿çšã®åºæ¬ïŒ
â¢SMTåé¡ãSMTãœã«ããŒãšã¯äœãããããã©ã®ããã«æ©èœããããSMTãœã«ããŒãéžæããéã«èæ ®ãã¹ãç¹æ§ã«é¢ããçè«çç¥èã
â¢SMT-LIBèšèªã§è«çåŒãè¡šçŸããã¹ãã«ã
-è匱æ§ã®æ€çŽ¢ïŒ
â¢æŽæ°ãªãŒããŒãããŒã¯ã©ã¹ã®è匱æ§ãèŠã€ããããã®SMTãœã«ããŒã®äœ¿çšãã©ã®ããã«åœ¹ç«ã€ãã«é¢ããç¥èã
â¢åŠçã¯ãå®éã®è匱æ§ãäŸãšããŠäœ¿çšããŠãSMTã®æå¹æ§ãç¬èªã«æ€èšŒããŠãã®åé¡ã解決ã§ããŸãã
â¢SMTãœã«ããŒã«ãã£ãŠå¶åŸ¡ãããã·ã³ããªãã¯\ã³ã³ã³ãªãã¯å®è¡ææ³ã䜿çšãããã¡ãžã³ã°ã®åçãç解ããã ãããã®ææ³ã®å®è£ ã«é¢é£ããå©ç¹ãå¶éããã¬ãŒããªãã«ã€ããŠåŠã³ãŸãã
-ã¿ã¹ã¯ã®èªåãšã¯ã¹ããã€ãçæïŒ
â¢ROPã³ã³ãã€ã©ããã³ãã®ä»ã®ããŒã«ã®åºç€ãšãªãæŠå¿µã®ç解ã
â¢ROPãã§ãŒã³ãæ§ç¯ããããã®ãã¢ã·ã¹ã¿ã³ãããšããŠSMTã䜿çšããã¹ãã«ã
-ãœãããŠã§ã¢ä¿è·ã¡ã«ããºã ã®åæïŒ
â¢åèªåkeygenäœæã®ã¿ã¹ã¯ã®äŸã䜿çšããŠããã€ããªåæãã©ãããã©ãŒã ããŒã«ãããã§äœæ¥ããã¹ãã«ïŒãã€ããªã³ãŒããSMTåŒã«å€æïŒã
ãã¬ãŒãã³ã°äžãåŠçã¯ãç 究è ãè匱æ§ã®æ€çŽ¢ããšã¯ã¹ããã€ãã®éçºããªããŒã¹ãšã³ãžãã¢ãªã³ã°ã«äœ¿çšããææ³ã®åºç€ãšãªãåçã«é¢ããçè«çç¥èã身ã«ã€ããŸãã ãã®åŸãååŸããç¥èãå®éã«çµ±åãããŸãã
ç®æšã¯ãSMTãœã«ããŒã䜿çšããããŒã«ã®å¹æçãªé©çšã«å¿ èŠãªåæç¥èãæäŸããããã«ããããã¯ã®åå è ã«èå³ãæãããããšã§ãã
ã¯ãŒã¯ã·ã§ããã®ãããã¯ïŒ
â¢SMTãœã«ããŒã®äœ¿çšã®åºæ¬ãå©ç¹ãæ¬ ç¹ãå¶éã
â¢è匱æ§ãæ€çŽ¢ããŸãã
â¢èªåãšã¯ã¹ããã€ãçæã®ã¿ã¹ã¯ã
â¢ã·ã³ããªãã¯\ã³ã³ã³ãªãã¯å®è¡ã
â¢äžéèšèªïŒäžéèšèªïŒã
åå è ã¯ä»¥äžãåãåããŸãïŒ
-Z3 SMTãœã«ããŒã®äœ¿çšã®åºæ¬ïŒ
â¢SMTåé¡ãSMTãœã«ããŒãšã¯äœãããããã©ã®ããã«æ©èœããããSMTãœã«ããŒãéžæããéã«èæ ®ãã¹ãç¹æ§ã«é¢ããçè«çç¥èã
â¢SMT-LIBèšèªã§è«çåŒãè¡šçŸããã¹ãã«ã
-è匱æ§ã®æ€çŽ¢ïŒ
â¢æŽæ°ãªãŒããŒãããŒã¯ã©ã¹ã®è匱æ§ãèŠã€ããããã®SMTãœã«ããŒã®äœ¿çšãã©ã®ããã«åœ¹ç«ã€ãã«é¢ããç¥èã
â¢åŠçã¯ãå®éã®è匱æ§ãäŸãšããŠäœ¿çšããŠãSMTã®æå¹æ§ãç¬èªã«æ€èšŒããŠãã®åé¡ã解決ã§ããŸãã
â¢SMTãœã«ããŒã«ãã£ãŠå¶åŸ¡ãããã·ã³ããªãã¯\ã³ã³ã³ãªãã¯å®è¡ææ³ã䜿çšãããã¡ãžã³ã°ã®åçãç解ããã ãããã®ææ³ã®å®è£ ã«é¢é£ããå©ç¹ãå¶éããã¬ãŒããªãã«ã€ããŠåŠã³ãŸãã
-ã¿ã¹ã¯ã®èªåãšã¯ã¹ããã€ãçæïŒ
â¢ROPã³ã³ãã€ã©ããã³ãã®ä»ã®ããŒã«ã®åºç€ãšãªãæŠå¿µã®ç解ã
â¢ROPãã§ãŒã³ãæ§ç¯ããããã®ãã¢ã·ã¹ã¿ã³ãããšããŠSMTã䜿çšããã¹ãã«ã
-ãœãããŠã§ã¢ä¿è·ã¡ã«ããºã ã®åæïŒ
â¢åèªåkeygenäœæã®ã¿ã¹ã¯ã®äŸã䜿çšããŠããã€ããªåæãã©ãããã©ãŒã ããŒã«ãããã§äœæ¥ããã¹ãã«ïŒãã€ããªã³ãŒããSMTåŒã«å€æïŒã
3.ããã¡ãžã³ã°ïŒå®çšçãªã¢ããªã±ãŒã·ã§ã³ãã¯OmairïŒã€ã³ãïŒã«ãã£ãŠå®æœãããŸã
ã¬ããŒãã®èª¬æ
ããã¯ããã¡ãžã³ã°ãéå§ãã人åãã®ã¯ãŒã¯ã·ã§ããã§ãã
ãã¡ãžã³ã°ã䜿çšããè匱æ§ã®æ€çŽ¢ã¯éåžžã«åçŽã§ãããé«åºŠãªã¹ãã«ãå¿ èŠãšããªãããšã匷調ããŠããŸãã
ããæå³ã§ã¯ããã¡ãžã³ã°ãæ®åãããŠããœãããŠã§ã¢ãæ¹åããããšãç®æããŠããŸãïŒãããŠäœãïŒïŒ
-ã€ã³ãã©ã¹ãã©ã¯ãã£ãæ§æãã
â¢æã蟌ããŠã¢ã€ãã³ãããã
â¢äžé©åãªã³ã³ãã¥ãŒã¿ãŒã®åäœã®åé¡
â¢-Windows-æŽæ°ãšãã£ãã«å¹
-ãã ãã¡ãžã³ã°ïŒXLS / DOCïŒ
â¢ãµã³ãã«ã®åéãšå·®å¥å
â¢å¹ç
â¢ééã£ã圢åŒã®ãã¹ã
â¢ç·Žç¿-10è¡ã®ãã¡ã¶ãŒãšæªçšãããé害
-ã¹ããŒããã¡ãžã³ã°ïŒHTMLïŒ
â¢éå»ã®èå¯
â¢ç§ãã¡ãç¥ã£ãŠãããã¡ã¶ãŒãšãã°
â¢IE察 Firefox vs. ã¯ãã
â¢ç·Žç¿-HTMLãã¡ã¶ãŒãšã°ã©ã€ã³ããŒãã¬ãŒã ã¯ãŒã¯
-ãã¡ãžãŒããžãã¯ãšåæã®éå§
â¢éåžžã«å€ãã®å€±æãéåžžã«å€ãã®ç¹°ãè¿ã
ãã¡ãžã³ã°ã䜿çšããè匱æ§ã®æ€çŽ¢ã¯éåžžã«åçŽã§ãããé«åºŠãªã¹ãã«ãå¿ èŠãšããªãããšã匷調ããŠããŸãã
ããæå³ã§ã¯ããã¡ãžã³ã°ãæ®åãããŠããœãããŠã§ã¢ãæ¹åããããšãç®æããŠããŸãïŒãããŠäœãïŒïŒ
-ã€ã³ãã©ã¹ãã©ã¯ãã£ãæ§æãã
â¢æã蟌ããŠã¢ã€ãã³ãããã
â¢äžé©åãªã³ã³ãã¥ãŒã¿ãŒã®åäœã®åé¡
â¢-Windows-æŽæ°ãšãã£ãã«å¹
-ãã ãã¡ãžã³ã°ïŒXLS / DOCïŒ
â¢ãµã³ãã«ã®åéãšå·®å¥å
â¢å¹ç
â¢ééã£ã圢åŒã®ãã¹ã
â¢ç·Žç¿-10è¡ã®ãã¡ã¶ãŒãšæªçšãããé害
-ã¹ããŒããã¡ãžã³ã°ïŒHTMLïŒ
â¢éå»ã®èå¯
â¢ç§ãã¡ãç¥ã£ãŠãããã¡ã¶ãŒãšãã°
â¢IE察 Firefox vs. ã¯ãã
â¢ç·Žç¿-HTMLãã¡ã¶ãŒãšã°ã©ã€ã³ããŒãã¬ãŒã ã¯ãŒã¯
-ãã¡ãžãŒããžãã¯ãšåæã®éå§
â¢éåžžã«å€ãã®å€±æãéåžžã«å€ãã®ç¹°ãè¿ã
4.ãã¿ã€ãã³ã°åæãã¯ãRoman KorkikyanïŒã¹ã€ã¹ïŒãå®æœããŸãã
ã¬ããŒãã®èª¬æ
ãã®ã¯ãŒã¯ã·ã§ããã§ã¯ãå®è¡æéã枬å®ããããšã«ãããDESããã³AESãœãããŠã§ã¢å®è£
ã®ç§å¯éµãèšç®ããŸãã ãã®æå·è§£æææ³ã¯ãã¿ã€ãã³ã°è§£æãšåŒã°ããŸãã ããã¯ããµã€ããã£ãã«æ»æãåæããæãç°¡åãªæ¹æ³ã®1ã€ã§ãã ãã®æ¹æ³ãææãããšãæå·åã¢ã«ãŽãªãºã ã®æ»æã®ããè€éãªæ¹æ³ãç解ããã®ã«åœ¹ç«ã¡ãŸããããã«ã¯ãé»ç£æŸå°åæïŒé»ç£åæïŒãå
åæŸå°ã®åæïŒåŸ®åãã©ãããã¯æŸå°åæïŒãããã³æ¶è²»é»åã®åæïŒåŸ®åé»ååæïŒãå«ãŸããŸãã
ã¯ãŒã¯ã·ã§ããã®äž»èŠãããã¯ïŒ
-æå·ã®å®è£ ã®ããã°ã©ã å®è¡æéã¯äœã«äŸåããŸããïŒ
-ã©ã®å Žåãæå·ã®æéã䜿çšããŠããŒãèšç®ã§ããŸããïŒ
-ããŒèšç®ã¯å®éã«ã©ã®ããã«è¡ãããŸããïŒ
ã¯ãŒã¯ã·ã§ããã®äž»èŠãããã¯ïŒ
-æå·ã®å®è£ ã®ããã°ã©ã å®è¡æéã¯äœã«äŸåããŸããïŒ
-ã©ã®å Žåãæå·ã®æéã䜿çšããŠããŒãèšç®ã§ããŸããïŒ
-ããŒèšç®ã¯å®éã«ã©ã®ããã«è¡ãããŸããïŒ
5.ãiOSã¢ããªã®BlackBoxåæãã¯ãDmitry 'D1g1' Evdokimovã«ãã£ãŠå®æœãããŸãã
ã¬ããŒãã®èª¬æ
ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®äººæ°ãé«ãŸã£ãŠããäžæ¹ã§ãã»ãã¥ãªãã£ã®è©äŸ¡ãšè匱æ§ã®çºèŠã®å¿
èŠæ§ãåæã«é«ãŸã£ãŠããŸãã iOSãå®è¡ããŠããApple補åã¯ãåžå Žã§æã人æ°ã®ãã補åã§ãã ãããã®ããã€ã¹ã«ã¯ãé¢çœãããã¡ãããéè¡ãããžãã¹ã¢ããªã±ãŒã·ã§ã³ãŸã§ãããŸããŸãªãœãããŠã§ã¢ãäœæãããŠããŸãã
ãã®ã¯ãŒã¯ã·ã§ããã®ãã¬ãŒã ã¯ãŒã¯å ã§ãiOSã¢ããªã±ãŒã·ã§ã³ã®ããã€ã¹ã«ç²ŸéãããœãŒã¹ã³ãŒãããããæ¯æŽããããŒã«ãªãã§è匱æ§ãèŠã€ããã¢ãããŒããè¡ããŸãã
ããã°ã©ã ã«å«ãŸãããã®ïŒ
-iOSããã€ã¹ïŒããã€ã¹ãObjective-CãARMãã¡ã«ããºã ãã»ãã¥ãªãã£ããžã§ã€ã«ãã¬ã€ã¯ã...ïŒ;
-iOSã¢ããªã±ãŒã·ã§ã³ïŒMach-O圢åŒãã¢ããªã±ãŒã·ã§ã³æ§é ã...ïŒ;
-iOSã¢ããªã±ãŒã·ã§ã³ã®äž»ãªè匱æ§ã
-iOSã¢ããªã±ãŒã·ã§ã³ã®éçããã³åçåæã®ããã®ããŒã«ã
åå è ã¯ä»¥äžãåãåããŸãïŒ
-iOSããã³iOSã¢ããªã±ãŒã·ã§ã³ã®åäœã®ã¢ã€ãã¢ã
-iOSã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ã«é¢ããåºæ¬çãªç¥èã
-iOSã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ãèŠã€ããããã®åºæ¬çãªããŒã«ã䜿çšããã¹ãã«ã
ãã®ã¯ãŒã¯ã·ã§ããã®ãã¬ãŒã ã¯ãŒã¯å ã§ãiOSã¢ããªã±ãŒã·ã§ã³ã®ããã€ã¹ã«ç²ŸéãããœãŒã¹ã³ãŒãããããæ¯æŽããããŒã«ãªãã§è匱æ§ãèŠã€ããã¢ãããŒããè¡ããŸãã
ããã°ã©ã ã«å«ãŸãããã®ïŒ
-iOSããã€ã¹ïŒããã€ã¹ãObjective-CãARMãã¡ã«ããºã ãã»ãã¥ãªãã£ããžã§ã€ã«ãã¬ã€ã¯ã...ïŒ;
-iOSã¢ããªã±ãŒã·ã§ã³ïŒMach-O圢åŒãã¢ããªã±ãŒã·ã§ã³æ§é ã...ïŒ;
-iOSã¢ããªã±ãŒã·ã§ã³ã®äž»ãªè匱æ§ã
-iOSã¢ããªã±ãŒã·ã§ã³ã®éçããã³åçåæã®ããã®ããŒã«ã
åå è ã¯ä»¥äžãåãåããŸãïŒ
-iOSããã³iOSã¢ããªã±ãŒã·ã§ã³ã®åäœã®ã¢ã€ãã¢ã
-iOSã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ã«é¢ããåºæ¬çãªç¥èã
-iOSã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ãèŠã€ããããã®åºæ¬çãªããŒã«ã䜿çšããã¹ãã«ã
CFPã¯2013幎10æ1æ¥ãŸã§åç¶ããŸããç³è«ã®åçãå®äºãããŸã§ã®æéã¯ã»ãšãã©ãããŸããã
FastTrackãå¿ããªãã§ãã ãããããã¯ãæ å ±ã»ãã¥ãªãã£ã®æåãªå°é家ãšåããã©ãããã©ãŒã ã§ããªãã®å°ããªç 究ãšè©±ããå人ãå¿ãåãããã人ã ãšãã£ãããããŠããŒã¯ãªæ©äŒã§ãã
ãã®ã»ã¯ã·ã§ã³ã®æåã®ã¹ããŒã«ãŒãããŸãã FastTrackã§ã¯ãVictor AlyushinïŒãã·ã¢ïŒããAndroid Master Keyè匱æ§ã®é«åºŠãªæªçšïŒãã°8219321ïŒããšãããããã¯ã«é¢ããã¬ããŒããæ瀺ããŸãã
ã¬ããŒãã®èª¬æ
Blackhat USA 2013ã«ã³ãã¡ã¬ã³ã¹ïŒhttps://media.blackhat.com/us-13/US-13-Forristal-Android-One-Root-to-Own-Them-All-Slides.pdfïŒã®Jeff Forristalã¯ãããžã¿ã«ããã€ãã¹ããæ¹æ³ã玹ä»ããŸããAndroidã¢ããªã±ãŒã·ã§ã³ã®çœ²åãšãã¢ããªã±ãŒã·ã§ã³ã®ãã¡ã€ã«ã®äžéšãç¬èªã®ãã®ã«çœ®ãæããã ãã®è匱æ§ã¯ãã¢ããªã±ãŒã·ã§ã³ããŒã¿ã®ååŸãšå€æŽãç¹ã«ä¿åããããã°ã€ã³ãšãã¹ã¯ãŒãã®èªã¿åãïŒrootãªãã§ããããã£ãŠã¹ããŒããã©ã³ã®ä¿èšŒã倱ãããšãªãïŒãã²ãŒã ã®ä¿åã®å€æŽïŒrootãªãã®ã²ãŒã ã§ã®äžæ£è¡çºïŒãã·ã¹ãã æš©éã®ååŸïŒifã·ã¹ãã ã¢ããªã±ãŒã·ã§ã³ã®çœ®ãæãïŒãããã³ãããã®å©ããåããŠãã«ãŒãæš©éïŒãro.kernel.qemu = 1 \ r \ nãè¡ããã¡ã€ã«/data/local.propã«è¿œå ããããšã«ããïŒã ãã ããææ¡ãããæäœæ¹æ³ã«ã¯ããã€ãã®å¶éããããå Žåã«ãã£ãŠã¯é倧ãªåé¡ãåŒãèµ·ããå¯èœæ§ããããŸãã ãã®è匱æ§ãæªçšããæ°ããæ¹æ³ãçºèŠãããããžã¿ã«çœ²åããã°ã©ã ã®æ€èšŒããã€ãã¹ããæ©äŒãå¢ããŸããã ããã«ãBluebox Security Scannerã¯ããã®è匱æ§ãæªçšããapkãã¡ã€ã«ãæ€åºããŸããã æ°ããæäœæ¹æ³ãGoogleã»ãã¥ãªãã£ããŒã ã«å ±åãããŸããã ãã°8219321ã®ãããããã®è匱æ§ã解決ããããšãå€æããŸããããGoogle PlayããŒã±ããã®ãã«ãŠã§ã¢ãã£ã«ã¿ãŒã¯æŽæ°ãããŸããã 1æ¥éã®è匱æ§ãæªçšããæ°ããæ¹æ³ãæ瀺ãããŸãããããŸã§ã«ã¬ããŒãã¯æåºãããŠããŸããã
è¿œå æ©èœãã ïŒZeroNightsã®ãã¬ãŒã ã¯ãŒã¯å ã§ã ããŒããŠã§ã¢ãã¬ããžãæ¡åŒµããŸãã äœã¬ãã«ã§ããŒããŠã§ã¢ã®ãããã³ã°ã奜ãã§ãããŒããä¿¡å·ãå°ç¡ãã«ããããšããããããªã人ã®ããã®çŽ æŽããããããžã§ã¯ãã ããã§ã¯ãçµã¿èŸŒã¿ã·ã¹ãã ããããã³ã°ããããã ãã§ãªããããŸããŸãªæ¹æ³ãããã€ã¹ã確èªããŠè©Šãããšãã§ããŸãã åºã䜿çšãããŠããTeensy HIDãšãã¥ã¬ãŒã¿ãšãæé·ãç¶ãããœãããŠã§ã¢ã®å®çŸ©ãããç¡ç·ãã©ãããã©ãŒã ã«ã€ããŠèª¬æããŸãã
ããŒããŠã§ã¢ãã¬ããžã«åå ããã«ã¯ãç¹å¥ãªç¥èãšã¹ãã«ã¯å¿ èŠãããŸããã å®éã«ãã¹ãŠãèŠããŠèª¬æããŸãã
ããã°ã©ã ã«ã¯ä»¥äžãåå ããŸãã
â¢HackRF
â¢BladeRF
â¢Facedancer
â¢ãã€ãã³ã¯ã©ã±
â¢JTAGulator
â¢Proxmark3
â¢ãããªãªFGPA
â¢ã¡ã£ã¡ãã
â¢*ãã¥ã€ã
â¢ã©ãºããªãŒãã€
ã¢ã€ãã³ãæã£ãŠããŠãäžç·ã«å£ããŸãããïŒ
Nuandã®å人ã®ãµããŒãã«ãããããŒããŠã§ã¢ã³ã³ãã¹ããéå¬ããããã®å ±é ¬ã¯BladeRF SDR nuand.comã«ãªããŸãã
ç»é²ã¯æ¬æ Œçã§ãïŒ æ¥ãïŒ 2013.zeronights.ru/ç»é²