
Androidçšã®ãŠã€ã«ã¹ãšãããããããäœæããæ¹æ³ã¯ïŒ EBayã§ããŒããã©ã€ããè³Œå ¥ãããšãäœãåŠã¶ããšãã§ããŸããïŒ SIMã«ãŒããææè ãè ãããã®ã¯äœã§ããïŒ ã¯ã³ã¿ã€ã ãã¹ã¯ãŒãããŒã¯ã³ãã³ããŒããæ¹æ³ã¯ïŒ 2æ17æ¥ã«ã Call For Papers ïŒã¹ããŒã«ãŒããã®ç³è«ããã»ã¹ïŒã®æçµæ®µéãå§ãŸããŸãããããã¯3æ31æ¥ãŸã§ç¶ããçŸåšãPositive Hack Days IVåœéå®çšã»ãã¥ãªãã£ãã©ãŒã©ã ã®ã¡ã€ã³ãã¯ãã«ã«ããã°ã©ã ã«åå ããæåã®åå è ã°ã«ãŒããçºè¡šããŠããŸãã
ãµã€ããŒå µåšãšã¢ãã€ã«ãããã¯ãŒã¯
çæ³çã«ã¯ãã¢ãã€ã«ãããã¯ãŒã¯ã¯äžåºŠã«è€æ°ã®é¢ã§ãŠãŒã¶ãŒãä¿è·ããå¿ èŠããããŸããé話ãæå·åãããŠãŒã¶ãŒããŒã¿ãä¿è·ããSIMã«ãŒãããã«ãŠã§ã¢ããä¿è·ããå¿ èŠããããŸãã ãã ããå€ãã®äŒæ¥ã¯ã»ãã¥ãªãã£æ©èœã®å®è£ ã«éåžžã«æ¶æ¥µçã§ãã ãããŠããã®æ¹åã«é²ãã§ãã人ã§ãããæ»æãå®å šã«æéããããšã¯ã§ããŸããã圌ãã®å¯Ÿçã¯ãåé¡ã解決ããããšã§ã¯ãªããçç¶ãåãé€ãããšãç®çãšããŠããŸãã ãã®ã¬ããŒãã§ã¯ãã¢ãã€ã«ãããã¯ãŒã¯ãšSIMã«ãŒãã«å¯Ÿããæãé«åºŠãªæ»æãé¡åŸ®é¡ã§èª¿ã¹ãŠãåŸæ¥ã®ã»ãã¥ãªãã£å¯Ÿçãåé¿ã§ããããã«ããŸãã
Karsten Nohlã¯ãæå·åãšããŒã¿ã»ãã¥ãªãã£ã®å°é家ã§ãã 圌ã¯ã»ãã¥ãªãã£ã®åé¡ã«ã€ããŠç¬èªã®ã·ã¹ãã ããã¹ãããŸã-ãããŠéåžžããããã¯ã©ãã¯ããããšã«æåããŸãã
ã°ãªãŒã³ããããã®å åã®äžã§ã®ãã«ãŠã§ã¢ã®çç£
Googleã¯çŸåšãã¢ãã€ã«ãã©ãããã©ãŒã ã®åéã®ãªãŒããŒã§ããã ãã§ãªããæãè匱ãªOSã®äœæè ã§ããããŸãã Good Corporationã®ãã¹ãŠã®åªåã«ãããããããããã€ã®æšéŠ¬ã¯æ°çŸäžäººã®AndroidãŠãŒã¶ãŒãæ»æããŸããSMSã¯çãçªå·ã«éä¿¡ããéè¡ã«ãŒããããéãçã¿ãå人ããŒã¿ãçã¿ãå¯ãã«æ®åœ±ããŸãã 4æéã®ãã³ãºãªã³ã©ããOperating Androidãã§ã¯ãAndroidçšã®æªæã®ããããã°ã©ã ãæºåããŠãããããã³ãèŠãããšãã§ããŸãã
ã¬ãã¹ã³ã¯ãAttifyã®åµèšè ã§ãããIndian Nullã³ãã¥ããã£ã®ã¡ã³ããŒã§ããAditya Guptaãå®æœããŸãã Androidåãã®ãªããŒã¹ãšã³ãžãã¢ãªã³ã°ãšãã«ãŠã§ã¢ã®èª¿æ»ãã¢ããªã±ãŒã·ã§ã³ã®æåãã¹ããšèªååããŒã«ã®äœ¿çšãDexãšSmaliã®äœ¿çšãWebkitãšARMã®ãšã¯ã¹ããã€ãã®äœæãªã©ã®ãããã¯ãåãäžããŸãã
ãµã€ããŒãŠã©ãã·ã¥ã§ã®ãµã€ããŒæå
ãããã³ã°ããšã¯ã¹ããã€ããã«ã€ããŠæ¯æ¥è³ã«ããŸãã圌ãã¯å€§äŒæ¥ã®ãŠã§ããµã€ããæ¿åºã®ããŒã¿ããŒã¹ãæ°çŸäžã®å人ã¢ã«ãŠã³ãããããã³ã°ããŸãã ããããæ¬åœã®å±éºã¯æ»æè ã«ããã®ã§ã¯ãªããé²åŸ¡è ã«ãããå人æ å ±ãåãåãããã«ã¯ãååãšããŠãã³ã³ãã¥ãŒã¿ã®å€©æã§ããå¿ èŠã¯ãªãã ãGive me your dataïŒããšããã¿ã€ãã«ã®è¬çŸ©ã§ã Dave Chronisterã¯ãéèŠãªããŒã¿ããã°ãã°äžæ³šæã«ä¿åãããŠããããã®ããŒã¿ã«ã¢ã¯ã»ã¹ããã«ã¯ååã§ããããšã蚌æããããšããŠããŸãã å®éšäžãäœæè ã¯äœã解èªããŸããããå¿ èŠãªãã¹ãŠã®æ å ±ãåæ³çã«åãåããŸãã EBayãªãŒã¯ã·ã§ã³ã§FacebookãããŒããã©ã€ããä»ããŠã¬ãžã§ãããè³Œå ¥ããããšããããããªãã¯ãã¡ã€ã«å ±æã远跡ããããšãŸã§ãããŸããŸãªæ å ±ååŸæ¹æ³ã玹ä»ããŸãã 圌ã®å®éšã®çµæã¯å°è±¡çã§ãïŒ
Daveã¯ãParameter Securityã®åµèšè ã§ããã管çããŒãããŒã®1人ã§ãã 圌ã¯ã€ã³ã¿ãŒããããçºå±ãå§ãã80幎代ã«æé·ããæåããããã«ãŒãèŠãŠãã®æ¹æ³ãç 究ããŠããŸããã 圌ã¯ãäžçäžã®ã¯ã©ã€ã¢ã³ãã®ç£æ»ãã€ã³ã·ãã³ã調æ»ãããã³ãã¬ãŒãã³ã°ã«åŸäºããŠããŸãã 圌ã®æåã¯ãCNBCãCNN Headline NewsãABC World News TonightãBloomberg TVãCBSãFOX Business NewsãComputer WorldãPopular ScienceãInformation Security Magazineãªã©ãå€ãã®äž»èŠã¡ãã£ã¢ã§æ³šç®ãããŸããã
åå©çšå¯èœãªã¯ã³ã¿ã€ã ãã¹ã¯ãŒãããŒã¯ã³
ãµã€ããã£ãã«æ»æåæã¯ãã¿ãŒã²ããããã€ã¹ã®ç©ççç¹æ§ïŒããšãã°ãæ¶è²»é»åã®ã¬ãã«ïŒã調ã¹ãããšã«ãããé ãããæå·åãããããŒã¿ãååŸããããã®éåžžã«åŒ·åãªããŒã«ã§ãã David OswaldãSCAãã¯ãããžãŒãšããã«é¢é£ããæ¹æ³ã«ã€ããŠèªã£ãŠããŸãã èŽè¡ã¯ã2ã€ã®äŸã䜿çšããŠSCAã䜿çšãããã¢ãæ瀺ãããŸãïŒæåã«ãç 究è ã¯ãSCAã䜿çšããŠFPGAã®IPä¿è·ïŒãããã¹ããªãŒã æå·åïŒããã€ãã¹ããæ¹æ³ã瀺ãã次ã«ãã¯ã³ã¿ã€ã ãã¹ã¯ãŒãããŒã¯ã³ã®AESããŒãååŸããæ¹æ³ã瀺ããŸãã
David Oswaldã¯2013幎ã«æ å ±æè¡ã®å士å·ãååŸããçŸåšã¯ããŒãã ã®ã«ãŒã«å€§åŠçµã¿èŸŒã¿ã»ãã¥ãªãã£éšéã§åããŠããŸãã 圌ã¯ãŸããKasperïŒOswaldã®åµèšè ã®äžäººã§ãã
ãçãäžã®ããªãã®ç·ãã¯ããªãã®ããªã³ã¿ãŒã奜ã
倧äŒæ¥ãéèæ©é¢ã§ã¯ã匷åãªæå·åãã¢ã«ãŠã³ãã£ã³ã°ãã¢ã¯ã»ã¹å¶åŸ¡ãæäŸã§ããå°å·ãœãªã¥ãŒã·ã§ã³ãå¿ èŠã§ãã 人æ°ãã³ããŒã®çµã¿èŸŒã¿ãœãããŠã§ã¢ãåããå€æ©èœããã€ã¹ïŒMFPïŒã®ç 究ãç®çãšããŠããäžéè ãã¿ã€ãïŒè±åœã®äžéè ãMitMæ»æïŒã®æ»æãè¡ãããŸããã çµæã¯è¡æçã§ãããå€ãã®ããã°ã©ã ã§ãæå·åããã€ãã¹ãããµãŒããŒããå°å·ã«éä¿¡ãããããŒã¿ãåéããäžæ£ãªå°å·ãå¯èœã«ããè匱æ§ãèŠã€ãããŸããã
ãã©ãŒã©ã ã§ã¬ããŒããçºè¡šããJakubKaÅuÅŒny㯠ã SecuRingã®æ å ±ã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ããšããŠãäŸµå ¥ãã¹ããè匱æ§åæãããã³Webã¢ããªã±ãŒã·ã§ã³ãšãããã¯ãŒã¯ç°å¢ã®ã»ãã¥ãªãã£è åšã®ã¢ããªã³ã°ãè¡ã£ãŠããŸãã 2013幎ã圌ã¯Googleã®æ®¿å å ¥ãããŸããã
ããžãã¹ããžãã¯ã®è匱æ§ã®æ€åºãšæŽ»çš
è«ççè匱æ§ã¯æãç 究ãããŠããªãã¯ã©ã¹ã§ãããå€ãã®å Žåãç 究è ããã³ãã¹ã¿ãŒã«ââãã£ãŠç¡èŠãããŸãã å€ãã®çç±ããããŸãïŒæ€åºãšæäœã®ããã®èªååããŒã«ã®æ¬ åŠã確ç«ããããã¹ãæ¹æ³ãåé¡ã容æã«ããæ確ãªçè«çæ ¹æ ã åæã«ãããžãã¯ãžã®æ»æã¯ãä»»æã®ã³ãŒãã®ãªã¢ãŒãå®è¡ã®ãªã¹ã¯ã«å¹æµãããªã¹ã¯ã䌎ãããšãå€ããããããžãã¹ã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ãåæããã¿ã¹ã¯ã¯ãè«ççãªè匱æ§ããã³ãã¹ã¿ãŒã®åªå äºé ã«ããŸãã ãã®ã¬ããŒãã§ã¯ãè«ççãªè匱æ§ã®æ ¹åºã«ããããžãã¹ã¢ããªã±ãŒã·ã§ã³ã®çè«çç¹åŸŽãšãããžãã¹ããžãã¯ã®æœåšçãªåé¡é åãè¿ éã«ç¹å®ããæ»æãå±éããå¯èœæ§ã®ããæ¹æ³ãç¹å®ã§ããéšåãã¡ã€ã³ã¢ããªã³ã°ã®æ¹æ³è«ã«ã€ããŠèª¬æããŸãã ãã®ææ³ã®å®éã®å¿çšã¯ãå®éã®å¿çšã«ãããå€ãã®è«ççè匱æ§ã®äŸã§æ€èšãããŸãã
Vladimir Kochetkovã¯ãPositive TechnologiesãªãµãŒãã»ã³ã¿ãŒã®å°é家ã§ãã 圌ã¯ãWebã¢ããªã±ãŒã·ã§ã³ã®ãœãŒã¹ã³ãŒãã®ã»ãã¥ãªãã£ã®åæãšãæ å ±ã·ã¹ãã ã®ã»ãã¥ãªãã£ã®çè«çåºç€ã®åéã®ç 究ãå°éãšããŠããŸãã SCADA Strangeloveãããžã§ã¯ãããã³PT Application InspectoréçºããŒã ã®ã¡ã³ããŒã rsdn.ruãå«ããªãŒãã³ãœãŒã¹ãããžã§ã¯ãã®ãµããŒãã«å€ãã®æ³šæãæã£ãŠããŸãã
æ»æäžã®åäœæ¹æ³
æ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ããžã®å¯Ÿå¿ã¯ãã°ãã°æ··ããšããŠããããããã¯ã§ã¯ã人ã ã¯éèŠãªèšŒæ ãç Žå£ããŸãã ãã€ã³ã·ãã³ããžã®å¯Ÿå¿ãšãµã€ããŒæ»æã®èª¿æ»ãã«é¢ãã4æéã®ã¯ãŒã¯ã·ã§ããã¯ã蚌æ 調æ»ãã·ã¹ãã ãã°ãã¡ã¢ãªãšãã£ã¹ã¯ã®åæããµã€ããŒç¯çœªã®å åã®æ€çŽ¢ãªã©ãã€ã³ã·ãã³ã調æ»ã®ååãšè¿ éã§èœã¡çãã察å¿ã¹ãã«ã®éçºã«é¢ããå®è·µçãªç 究ãç®çãšããŠããŸãã åå è ã¯ãç¹å¥ãªãã¬ãŒãã³ã°è³æãåæçšã®ä»®æ³ãã·ã³ãåãåããããŸããŸãªã€ã³ã·ãã³ãã®ã·ãã¥ã¬ãŒã·ã§ã³ãäŸãšããŠäœ¿çšããŠãå¹æçãªå¯Ÿå¿ã·ããªãªãç解ããŸãã
ãã¹ã¿ãŒã¯ã©ã¹ã®ãªãŒããŒã¯ããã«ã¬ãªã¢ã®ã¹ãã·ã£ãªã¹ãã§ããAlexander Sverdlov㧠ãProCredit Bank Bulgariaã§ITã»ãã¥ãªãã£æ åœè ãšããŠåããŠããŸãã ã¢ã¬ã¯ãµã³ããŒãPHDaysã«åå ããã®ã¯ãããåããŠã§ã¯ãããŸãããæšå¹Žã圌ã¯ãµã€ããŒãã©ã¬ã³ãžãã¯ãã¹ã¿ãŒã¯ã©ã¹ãéå¬ããŸããã
Intercepter-NGïŒæ¬¡äžä»£ã¹ããã¡ãŒ
ãã®ã¬ããŒãã¯ãéèŠãªããŒã«ã§ããIntercepter-NGå°çšã§ãã ä»æ¥ã§ã¯ãå€ãã®æ©èœãåãããã³ãã¹ã¿ãŒåãã®æãé²æ©çãªã¹ããã¡ãŒã§ãã
é説çã«ã¯ããã·ã¢ãããæµ·å€ã§ããç¥ãããŠããŸãã ãŠãŒãã£ãªãã£ã®äž»ãªæ©èœã®æŠèŠã«å ããŠãèè ã¯ããã䜿çšããæ»æã®ããã€ãã®å®çšçãªäŸã詳现ã«èª¿ã¹ãŸãã äŸïŒæè¿ãChaosonstructionsMySQL LOAD DATA LOCALã€ã³ãžã§ã¯ã·ã§ã³ã§ã©ã€ãã¢ãããããããŸãç¥ãããŠããªããéåžžã«å¹æçãªICMPçµç±ã®DNSæ»æã
ãã®äœåã¯ãPentestITã®ãã¬ãŒãã³ã°éšéã®è²¬ä»»è ã§ããããã¯ãããžãŒããã°ãHabrahabrãããã³ãžã£ãŒãã«ãHackerãã®èšäºã®åžžé£èè ã§ããããã§ã«ããŽãã®Alexander Dmitrenko ïŒ sinist3r ïŒã«ãã£ãŠçºè¡šãããŸãã å瀟ã¯ãIntercepter-NGã®äœæè ã§ããPentestITã®å°é家ã§ããAresã«ãã£ãŠæ§æãããŸãã
ãµãŒãããŒãã£ã®ãã£ãã«åæïŒå®è·µãšå°ãã®çè«
ãã®ãããã¯ã¯ã³ã³ãã¥ãŒã¿ã»ãã¥ãªãã£äŒè°ã§é »ç¹ã«è°è«ãããªãããã2ã€ã®èŠ³ç¹ãæ€èšããããšã«ããŸããã David Oswaldã«å ããŠãIlya Kizhvatovã¯Side Channel Attackã®èª¿æ»ãå®æœããŸãã 圌ã¯ãµãŒãããŒãã£ã®ãã£ãã«ã«é¢ããäžè¬çãªæ å ±ãæäŸããçŸåšã®åé¡ã«ã€ããŠè©±ããå®è·µããäŸãæããŸãã ãªã¹ããŒã¯ããã®ããã€ã¹ã®ãµãŒãããŒãã£ãã£ãã«ã«æ»æã®ãªã¹ã¯ããããã©ãããå€æããæ¹æ³ããã®ã¿ã€ãã®æ»æã«æµæããæ¹æ³ãããã³ãµãŒãããŒãã£ãã£ãã«ãåå¥ã«åæããæ¹æ³ãåŠç¿ããŸãã
Ilya Kizhvatov ïŒIlya KizhvatovïŒ-ãªã©ã³ãã®äŒç€ŸRiscureã®ã·ãã¢ã¢ããªã¹ãã çµã¿èŸŒã¿ã»ãã¥ãªãã£ã·ã¹ãã ã§6幎ã®çµéšãæã¡ïŒå€§åŠé¢ã§3幎ãéçºã§3幎ïŒãæå·ã·ã¹ãã ã®å®è£ ã®è匱æ§ã«åºã¥ããµãŒãããŒãã£ã®æ»æãå°éãšããŠããŸãã
äºæ ã¯ãããŸãããïŒ
ææ°ã®ã¢ããªã±ãŒã·ã§ã³ã¯ãã»ãã¥ãªãã£é¢é£ã®ã¿ã¹ã¯ïŒæå·åããŒãã»ãã·ã§ã³èå¥åããã£ããã£ããã¹ã¯ãŒãïŒã解決ããããã«ä¹±æ°ã·ãŒã±ã³ã¹ãåºç¯å²ã«äœ¿çšããŸãã ãã®ãããªããã°ã©ã ã®èã¯ã©ãã¯æ§ã¯ãã©ã³ãã ã·ãŒã±ã³ã¹ãžã§ãã¬ãŒã¿ãŒã®å質ã«å€§ããäŸåããŸãã ç 究è ã¯ãæ¬äŒŒä¹±æ°ãžã§ãã¬ãŒã¿ãŒã䜿çšããJavaã¢ããªã±ãŒã·ã§ã³ã§çºèŠãããè匱æ§ã«ã€ããŠè©±ããŸãã ãã®ãããªã¢ããªã±ãŒã·ã§ã³ãžã®æ»æãæåããã·ããªãªã«å ããŠãäœæè ã¯ããžã§ãã¬ãŒã¿ãŒã®å éšã¹ããŒã¿ã¹ïŒããããã·ãŒãïŒãããã³ååŸã®å€ãååŸã§ããããŒã«ã玹ä»ããŸãã ããã«ããã®ããŒã«ã䜿çšããŠå®éã®Javaã¢ããªã±ãŒã·ã§ã³ãæ»æããæ¹æ³ã瀺ããŸãã
Mikhail Egorovã¯ç¬ç«ããç 究è ã§ãããè³æ Œã®ããããã°ã©ããŒïŒJavaãPythonïŒã§ããããã¡ãžã³ã°ããªããŒã¹ãšã³ãžãã¢ãªã³ã°ãWebã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãããã³ãããã¯ãŒã¯ã»ãã¥ãªãã£ãå°éãšããŠããŸãã Sergey Soldatovã¯ã10幎以äžã«ããã£ãŠå®çšçãªãããã¯ãŒã¯ã»ãã¥ãªãã£ã«æºãã£ãŠãããISPã«é¢é£ããããŸããŸãªãããžã§ã¯ãã«åå ããŠããŸãã
OS Xãã©ã€ããŒããªããŒã¹ããæ¹æ³
MacBookãšMacã¯ãWindowsãå®è¡ããŠããã³ã³ãã¥ãŒã¿ãŒãããã¯ããã«ä¿è·ãããŠããããšãäžè¬ã«åãå ¥ããããŠããŸãã ããããå èµã®iSightã«ã¡ã©ãžã®åŠšå®³ãããªãæ¥ç¶ã®ã±ãŒã¹ãå«ããæè¿ã®æåãªèšäºã¯ããããçã£ãŠããŸãã PHDays IVã§ã®è¬æŒãReverse OS X Driver Developmentãã§ã¯ãEgor FedoseevãOS Xãã©ã€ããŒã®åææ¹æ³ãä»éããå°é£ãããã³äººä»¶è²»ãæå°éã«æããæ¹æ³ã«ã€ããŠèª¬æããŸãã åŠçã¯ãMacçšãã©ã€ããŒã®æ©èœãããããåæããããã®ããŒã«ãIDAã®éã¢ã»ã³ãã©ãŒã§å転ããæ¢åã®åé¡ãããã³å¯èœãªè§£æ±ºçã«ã€ããŠåŠã³ãŸãã ãã®ã¬ããŒãã¯ããŠã€ã«ã¹ã¢ããªã¹ããšOS Xã»ãã¥ãªãã£ç 究è ã«ãšã£ãŠèå³æ·±ããã®ã§ãã
Yegor Fedoseyevã¯ãšã«ããªã³ãã«ã¯ã«äœãã§ããããã·ã¢ã®æåã®å€§çµ±é B.N. Yeltsinã«ã¡ãªãã§åä»ãããããŠã©ã«é£éŠå€§åŠã§åããŠããŸãã 圌ã¯ã2005幎ç§ã«UrFUã®æ°åŠãšååŠã®åŠéšã§çµæãããåŠçã°ã«ãŒãã Hackerdom ãã®é·ã§ãã 2004幎ãããªããŒã¹ãšã³ãžãã¢ãªã³ã°ã«åŸäºã
3æ31æ¥ãŸã§ãæ å ±ã»ãã¥ãªãã£ã®åéã§æ°å人ã®äž»èŠãªäžçã®å°é家ã®åã§ç 究ãæåºã ãPHDays IVã§è©±ãæéãããããšãæãåºããŠãã ããã ãŸããã¡ã³ããŒã«ãªãæ¹æ³ã¯ä»ã«ããããŸãã Positive Hack Daysã§2014幎5æ21æ¥ãš22æ¥ã«éå¬ãããããã©ãŒãã³ã¹ã®å šãªã¹ãã¯ã4æã«ãã©ãŒã©ã ã®å ¬åŒWebãµã€ãã§å ¬éãããŸãã