äžçäžã®4200人ã®äººã ããããžãã£ãããã¯ã®æ¥VIãšåŒã°ããã掻æ°ã«æºã¡ãããçã£ãäŒæ¥ãç®æããŸããã 2æ¥ã§ããµã€ãã§æ°çŸã®ã€ãã³ããçºçããŸããã äžèŠãããã«ãŒã¯ç¶æ³ãå®å šã«ææ¡ããŠããããã«æããŸããã å®éãæ倧éã®ä¿è·ç¶æ ã§ã¯ãDMZã®å¢çãè¶ããŠèª°ã移åããŠããŸããã
ãããããæ°é±éãŸãã¯æ°ã¶æã§è¡ã¯åããã§ãããã ãã®ãããªä¿è·ã¯éšå µéã®çªæã«ãã£ãŠãããã³ã°ãããŸããã ããããèŠèŽè ã¯ãæéããããŠæšçãçµã£ãæ»æãèŠãããšãã§ããŸããã§ããã 圌ãã¯ã©ã®ããã«æãdræ»ãããéé»ç·ã®ç·ãçãããããèŠããã£ãã ãšã³ã¿ãŒãã€ã³ã¡ã³ããåäžãããããã«ãäžéšã®ã·ã¹ãã ããªãã«ããããšã§ã»ãã¥ãªãã£ã®ã¬ãã«ããããã«äžããããšã決å®ãããŸããã ãããŠãããã§ã¯èª°ããæ å ±ã»ãã¥ãªãã£ã«å¯Ÿããäžååãªæ³šæãèŠãŠããã ããã«ãŒã¯ãã¹ãç¯ããŸãããGSM/ SS7ãæ»æããã¹ããŒãããŒã ã·ã¹ãã ããªãã«ããéèŠãªã·ã¹ãã ã®ããã¯ã¢ãããåé€ãããªã¢ãŒããã³ãã³ã°ãããéãåé€ããŸããã
ãã©ãŒã©ã ã¯ãä¿è·ãããŠããªãéèŠãªã€ã³ãã©ã¹ãã©ã¯ãã£ã«äœãèµ·ããããæ確ã«ç€ºããŠããŸãã æ å ±ã»ãã¥ãªãã£ã®å°é家ã¯ãããã»ã¹ãäžæããããšãªãéåžžã«é«ãã¬ãã«ã®ä¿è·ãæäŸã§ããŸãããPHDaysã®ããã«å±éããæ©äŒãäžããããããšã¯ã»ãšãã©ãããŸããã ä¿è·è£ 眮ãåæããåŸãæ»æè ã¯äŒæ¥ãããã¯ãŒã¯ãä»ããŠèªåå¶åŸ¡ã·ã¹ãã ã®æè¡ãããã¯ãŒã¯ã«å ¥ããã·ã¹ãã ã®ç©ççè£ çœ®ãæ»æããæ°Žåçºé»æã«äŸµå ¥ããæŸæ°Žãè¡ããé»åç·ãåæããŸããã
ãããã«ãããããã«ãŒã®ããŒã ãCityFåžå šäœãå é ãã競äºã«åã€ããšã¯ã§ããŸããã§ããã 詳现ãªã¬ã€ãã£ã³ã°ãšç«¶æçµæãããã«äºæ³ãããŸãããããŠã2æ¥ç®ã®ããã€ãã®ããã©ãŒãã³ã¹ã«ã€ããŠã話ããŸãïŒ1æ¥ç®ã®æé«ã®ç¬éã«ã€ããŠã¯ãã¡ããã芧ãã ãã ïŒã
æŠäºã®ã«ãŒã«
ãããžãã£ãããã¯ãã€ãºã«ã¯çŽ æŽããããªãŒãã£ãšã³ã¹ãããŸãã ç§ã¯éåžžã«æéãåããŸããããã¢ã¹ã¯ã¯ã®ãµã€ããŒã»ãã¥ãªãã£æ åœãã€ã¯ããœãããšãŒããããã£ã¬ã¯ã¿ãŒã®Jan Neutzeãã¢ã¹ã¯ã¯ã«å°çããåœéçãªãµã€ããŒçŽäºã®åéã§ã®å®å šåºæºã®éçºã«ã€ããŠè©±ããŸããããšã¬ããŒããå§ãŸããŸããã ãã€ã¯ããœããã¯ãããµã€ã¬ã³ããæŠäºã®åé¡ã«é¢ããŠåœ¢æãããç«å Žãæã£ãŠããããšãããããŸããããããã¯é©ãã¹ãããšã§ã¯ãããŸãããå瀟ã®äºç®ã¯ãããã€ãã®åœã®ç·çç£ã«å¹æµããŸãã Neutzeã«ãããšããµã€ããŒæ»æã¯äŒæ¥ã«3å ãã«ã®è²»çšãããããŸãã æšå¹Žã®ãããã³ã°ã®æ°ã¯78ïŒ å¢å ãã1å6åäžäººã®ãŠãŒã¶ãŒã®ããŒã¿ãçãŸããŸããã ãããã³ã°ã®å¹³åæ€åºæéã¯229æ¥ã§ããã
Neutzeã«ãããšã16ãåœã®æ¿åºã¯ãã§ã«ãµã€ããŒæ»æå µåšã®äœ¿çšã宣èšããŠããã45ã¯ç©æ¥µçãªãµã€ããŒé²è¡çãçºè¡šããŠããŸãã çŸåšãçŽ100ãåœããµã€ããŒã¹ããŒã¹ã«é¢ããæ³åŸãçå®ããŠããŸãã ãéèŠãªã€ã³ãã©ã¹ãã©ã¯ãã£ã¯éèŠã§ãããšNeutzeæ°ã¯èšããŸãã -ååœã®æ³åŸã¯ãç¹æ®éšéãšè»éããã®å°åãæ»æããæš©å©ãæããªãããšãæ確ã«è¿°ã¹ãã¹ãã§ãã ããã¯äžççãªå€§æšäºã§ããã
äŒæ¥ã¡ãŒã«ãžã®æ»æã¯270ïŒ å¢å ããŸãã
ã»ã¯ã·ã§ã³ãDefense and Attack Technologies 2016ïŒWho Who Breaks Breakãã§ã¯ãäž»èŠãªPositive Technologies Expert Security Centerã®å°é家ããé²è¡ãšæ»æã®åéã«ãããææ°ã®éèŠãªéçºã«ã€ããŠè©±ããŸããã
Dmitry Sklyarovã¯ããªããŒã¹ãšã³ãžãã¢ãªã³ã°ã®äžçããã®ãã¥ãŒã¹ãå ±æããŸããã ãšãããã圌ã¯Secret Net Studioæ å ±ä¿è·ã·ã¹ãã ã«èŠãããè匱æ§ã«ã€ããŠè©±ããŸããã ãã®æªçšã«ãããæ»æè ã¯ã²ã¹ãã¢ã¯ã»ã¹ãã管çè ãžã®ç¹æš©ãå¢ããããšãã§ããŸãã Sklyarovã¯ãçŸæç¹ã§ã¯èªèšŒè£œåã®æ¬æ Œçãªèª¿æ»ã¯è¡ãããŠããªããããã¡ãŒã«ãŒãFSTECèªèšŒã«éãããç¬ç«ããç 究è ã«ãã¹ãçšã®ãœãããŠã§ã¢ãæäŸãããã奚å±ããå¿ èŠããããšææããŸããã
Dmitry Kurbatovã¯ãã¢ãã€ã«éä¿¡ã«é Œãã¹ãã§ã¯ãªããšèããŠããŸãã 圌ã¯ãPositive Technologiesã2015幎ã«å®æœããSS7ãããã¯ãŒã¯ã»ãã¥ãªãã£èª¿æ»ã®çµæãçºè¡šããŸããã çµ±èšã¯æåŸ ã¯ããã§ãããã¹ãŠã®ã¢ãã€ã«ãããã¯ãŒã¯ã¯è匱ã§ãã 89ïŒ ã®ã±ãŒã¹ã§ã¯ãçä¿¡SMSã¡ãã»ãŒãžãã€ã³ã¿ãŒã»ããããããšãå¯èœã§ããã58ïŒ ã®ã±ãŒã¹ã§ã¯-å å ¥è ã®äœçœ®ãå€å¥ãã50ïŒ ã§ã¯-é話ãèãããšãã§ããŸãã ãã®ãããçä¿¡SMSã¡ãã»ãŒãžã®ååã䜿çšããŠãã¡ãã»ã³ãžã£ãŒã¢ã«ãŠã³ããšé»åãŠã©ã¬ããã«ã¢ã¯ã»ã¹ã§ããŸãã
æšå¹Žã®åŸåã®1ã€ã¯ã䟵害ãããäŒæ¥ã¡ãŒã«ã«ããæ»æã§ãã FBIã«ãããšããã®æ°ã¯270ïŒ å¢å ããŠããŸãã å¹³åããŠã被害è ãžã®æ»æã«ããæ害ã¯25ã75åãã«ã§ãPositive Technologiesãåæ§ã®æ»æãåããŸããã äºä»¶ã®è©³çŽ°ã¯ãŠã©ãžããŒã«ã»ã¯ããããã«ãã£ãŠäŒããããã
ãéè¡ã¯ã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ãå®æçã«åæããå¿ èŠããããŸãããšArtem Chaykinæ°ã¯èšããŸãã ãå€ãã®ã¢ãã€ã«ãã³ãã³ã°ã¢ããªã±ãŒã·ã§ã³ã¯ãåä¿¡ããããŒã¿ãé©åã«åŠçããŸãããã 圌ã¯ããã«ãŠã§ã¢ã®é²åãšéè¡æ¥åã¢ããªã±ãŒã·ã§ã³ã®ãŠãŒã¶ãŒãä¿è·ããããã®ã¡ã«ããºã ã®ãã¥ã¢ã³ã¹ã«ã€ããŠèŽè¡ã«èªããŸããã
HeartbleedãShellshockãGhostãBadlockã¯ããã©ã³ãã«ãªã£ãè匱æ§ã®äžå®å šãªãªã¹ãã§ãã éçºè ã ãããã¹ã³ãã®æ³šç®ã«èå³ãããããã§ã¯ãããŸããã ç 究è ãçºèŠãããè匱æ§ã«ã€ããŠè©±ãããã«PRäŒç€Ÿå šäœãæãä»ããšãããçš®ã®åŸåãçŸããŸããã ããããã©ããæ¬åœã«å±éºãªã®ãããããŠãäœããªãããå€ãã®ãã€ãºããšèšããã®ã¯ã©ãã§ããïŒ ãã®åé¡ã§ã¢ãŒã»ããŒã»ãã€ãããç解ããŸããã
ãè匱ãªãœãããŠã§ã¢ã䜿çšãããšãããŒã¿ã¯ã»ãšãã©ç¡æã§æŒæŽ©ããå¯èœæ§ããããŸãããšããŠãªã¢ããããã¯ç¢ºä¿¡ããŠããŸãã å°é家ã«ãããšãæ»æè ã¯ç¹å®ã®é¡§å®¢ãæ»æããããšã¯ãã£ãã«ãªããäž»ã«è£œåã®è匱æ§ã«åçºãããŸãã ããã«ãŒã¯è匱æ§ãèŠã€ãããšã¯ã¹ããã€ãã䜿çšããŠãããè匱ãªè£œåã®ãŠãŒã¶ãŒãæ¢ããŠæ»æããã ãã§ãã ããããããã¹ãŠã以åã»ã©æªãããã§ã¯ãããŸããã ä¿è·ã¯è¿œãã€ããªããªããäºå®ããæ©ããªããŸãããšãžã¥ãªã¢ã¯èŠçŽããŸãã
SIEMãŸãã¯SIEMã§ã¯ãªãããããåé¡ã§ã
Alexey Lukatskyã¯ããã®ã¯ã©ã¹ã®è£œåã®ç®çãç解ããããã«ãSIEMã·ã¹ãã ã®äž»èŠãªéçºè ã®ä»£è¡šè ãéããŸããã 質åã¯å¯èœãªéãå³ãããã®ã§ããã SIEMã¯æ¬åœã«æçã§ããããããšã顧客ããã®ãã1ã€ã®ããã«ãã§ããïŒ ãããŠã圌ãã®è£œåã®éãã¯äœã§ããã ã»ã¯ã·ã§ã³ã«ã¯ããšãã²ããŒã»ã¢ãã©ãã³ïŒHP ArcSightïŒããªã¬ã·ã¢ã»ã·ã§ã¬ã¹ããŽã¡ïŒRUSIEMã®åµèšè ïŒããŠã©ãžããŒã«ã»ãã³ã®ã³ïŒMaxPatrol SIEMïŒããŠã©ãžããŒã«ã»ã¹ã«ã¯ããïŒSplunkïŒãããŒãã³ã»ã¢ã³ãã¬ãŒãšãïŒIBM QRadarïŒãéãŸããŸããã
Alexey Lukatskyã¯ã2014幎ã®èª¿æ»ããããŒã¿ãåŒçšããŸãããããã¯ãSIEMãå®è£ ãã30ã®æ¥çã®äžçäžã®800瀟ã§å®æœãããŸããã 74ïŒ ã®äŒæ¥ã¯ãSIEMãã»ãã¥ãªãã£ã«åœ±é¿ãäžããªãã£ããšçããŠããŸããã€ã³ã·ãã³ãã®æ°ã¯æžããŸããã§ããã ãã客æ§ã¯ãSIEMãéã®åŒŸäžžã®ããã«æ©èœããããšããã°ãã°æåŸ ããŸããã€ã³ã¹ããŒã«ãããšãã·ã¹ãã ã¯äœãããã£ããããŸãããšãRoman Andreevã¯ã³ã¡ã³ãããŸããã ãåçè ã®4åã®3ãããã£ããã«å¿ èŠãªãã®ãç解ããŠããªãå¯èœæ§ããããŸããã èŽè¡ã¯ãSIEMã®ã¿ã¹ã¯ã«ã¯ãå±éºãªã€ãã³ãã®æ°ã«åœ±é¿ãäžããã®ã§ã¯ãªããã€ã³ã·ãã³ããç¹å®ããŠèª¿æ»ããããšãå«ãŸããŠããããšã«æ°ä»ããŸããã IBMã®Eugene Shumskyã¯ããã®ã¯ã©ã¹ã®è£œåã®è€éããå¢ãããšã«ãã£ãŠçããäžå¯é¿ã®æªãšããŠããããã®æ°åãåãå ¥ããããšãææ¡ããŸããããSIEMã·ã¹ãã ã¯éåžžã«å€æ§ãªçç©ã§ãããå顧客ãç¬èªã«äœ¿çšããŠããŸãã äžæ£é²æ¢ã·ã¹ãã ãšããŠäœ¿çšãããKPIã»ãã¥ãªãã£ãµãŒãã¹ãèšç®ãããã€ã³ã·ãã³ãæ€åºãèªååãããŸãã äžéšã®äŒæ¥ã§ã¯ãSIEMã¯æã«äžåºŠããã·ã¥ããŒãã«ã¢ã¯ã»ã¹ããŠãã«ãŒã¿ãŒã§äœãèµ·ãã£ããã確èªããå¿ èŠãããã ãã§ãã
ã調æ»ã®æ°å€ã«ã¯åæããŸããããšãŠã©ãžããŒã«ã»ãã³ã®ã³ïŒããžãã£ããã¯ãããžãŒãºïŒã¯è¿°ã¹ãŸããã -ç¶æ³ã¯ããã«æªãã éå»6ãæã«ããã£ãŠã15ã®MaxPatrol SIEMãããžã§ã¯ããå®è£ ããæ°åã®ãã€ããããããžã§ã¯ããå®æœããäœããã®åœ¢ã§äœçŸãã®é¡§å®¢ãšè©±ããŸããã ãããŠãã»ãšãã©ãã¹ãŠã®SIEMããã§ã«ãããæã£ãŠããããšã«æ³šæãã¹ãã§ãã ãããããæ£ã«ããããšããèšèã®æåéãã®æå³ã§ã¯ãçµ±èšã«ãããšããã®ã¯ã©ã¹ã®ã·ã¹ãã ã®ã¡ãŒã«ãŒã¯æ©èœã®ã¿ã販売ããŠããããã10åã®1ã®SIEMã·ã¹ãã ãå¹æçã«æ©èœããŸãã æ¯èŒè¡šã«ãã£ãšãã§ãã¯ããŒã¯ããã人-圌ãåã¡ãŸããã 圌ãã®äž»ãªééãã¯ãå°éç¥èã売ã£ãŠããªãããšã§ãã å®éã«ã¯ãSIEMã·ã¹ãã ã¯ã10人ã®ã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ããããªãéšéã圢æãããŠããäŒæ¥ïŒããã³å€ãã¯ãããŸããïŒã§ã®ã¿æ©èœããŸãã ç§ãã¡ã¯ãã®ã¢ãããŒãã奜ãã§ã¯ãããŸãã-ããã¯æ©èœããŸããã ãããã£ãŠãPositive Technologiesã¯å¥ã®éãæ©ã¿ãã»ãšãã©ããã«äœ¿çšã§ããã·ã¹ãã ãäœæããŸããã ç§ãã¡ã®ãã©ãã€ã ã§ã¯ãSIEMã¯å°æ¥ã®ãã©ãããã©ãŒã ã®ã¬ã³ã¬ã®1ã€ã«ãããŸãããã
ç¯çœªè ã¯ãã¡ã€ã³ããšã«èšç®ã§ããŸã
Fidelis Cyberââsecurity Information Security Threat Analystã®John Bambenekã¯ããã©ãŒã©ã ã§ãæ»æã€ã³ãã©ã¹ãã©ã¯ãã£ã®åŸ©å æ©èœãå©çšããã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®ç¹å®ãã§è¬æŒããŸããã 圌ã¯ããµã€ããŒç¯çœªè ã䜿çšããæè¡ã®äŸãåŒçšãããã¡ã€ã³åçæã¢ã«ãŽãªãºã ã«ã€ããŠè©±ããŸããã æ»æè ãå€æ°ã®ãã¡ã€ã³ãŸãã¯ãµãŒãã¹ãäœåºŠãç»é²ããå Žåããã®ãããªãã¿ãŒã³ããããŸãã 調æ»ã®æèã§ã圌ãã®è¡åã®æ³åãç¥ã£ãŠããã°ãç¯äººãééããããŸã§è¿œè·¡ã§ããŸãã ãç¯çœªè ã¯åžžã«å¹žéã§ãªããã°ãªããŸããã é·æçã«ã¯ãããã¯å°é£ã§ãã 圌ããè¡åããã°ããã»ã©ãééãã®å¯èœæ§ã¯å€§ãããªããŸãããšãžã§ã³ã¯èšããŸãã Habréã®ããã°Positive Technologies ã§ãåæ§ã®ãããã¯ãåãäžããŸããã
ã¢ã³ãã¬ã€ã»ããµãããããææ¯ãªããããã«ã€ããŠ
éåžžã«èå³æ·±ãã®ã¯ãã¢ã³ãã¬ã€ã»ããµããããããµãã€ããŒãã®å ±åã§ããã 圌ã¯æ å ±æ»æãã©ã®ããã«æºåãããŠããããèªã£ãã æ å ±ãžã®åœ±é¿ã®æ段ã¯ããè³ã®ããã®æŠäºãã§äœ¿çšãããŸãã ç¹ã«ããããŒã«ãšãããã®ãã¥ãšããã§ã¯ãæ°ãããã¬ã€ã€ãŒããããããæã€åŠç²Ÿã«ãªããŸããã åŸæ¥ã®åžå Žã¯ã3次å ççºã®ã¢ãã«ã«äŸåããŠããŸãã 人工æ å ±ã®ããŒã¹ãã¯ã2次å ã®æ³¢ãšåæ§ã«æ©èœããŸããæ°Žã«èœã¡ã氎滎ã¯åãæããé©åãªå Žæã«å°éãããšå€§ããªæ³¢ãäžããŸãã æ¯ã®æ»Žãé©åãªå Žæã«æ»ŽäžãããããããåããåŠç²Ÿãåæ§ã§ãã
ãããããã¹ããŒãã®æãèå³æ·±ãéšåã¯ãæ¿æ²»å®¶ãã¡ãã£ã¢é¢ä¿è ãäžè¬ãŠãŒã¶ãŒãæ¡çšæ åœè ãããã³è¢«å®³è ãªã©ããã¹ãã£ã¹ã«ãã·ã§ã³ã®åå è ã®ç€ŸäŒçèåã®äŸã®ãã¢ã³ã¹ãã¬ãŒã·ã§ã³ã§ããã ãããã®ã«ãŒããèŠããšãæãã身éãããŸããããšãèªåã®ã¢ã«ãŠã³ãã§èªåã®æ å ±ãé瀺ããŠããªããŠããç¥ãåãã®2çªç®ã®ãµãŒã¯ã«ã調ã¹ãã ãã§èšç®ã§ããŸãã åœç¶ã®ããšãªããã瀟äŒçèåã®åæ§ã®æ瀺çåææ¹æ³ãã»ãã¥ãªãã£ç®çã§äœ¿çšãããŠãããããµããããã¯éæ¿æŽŸã®èåã®äŸã§ç€ºããŸããã
è匱æ§å£²ãæå«ç
Alfonso de Gregorioã®ã¹ããŒãã¯ããšã¯ã¹ããã€ãåžå Žããã®åå è ããŒããã€è匱æ§ãããŒã«ãŒã®æŽ»åãããã³ããžãã¹å«çã®é¢é£ããåŽé¢ã«æ§ããããŸããã
ããã€ãŠæ¥æ¬äººã®ååãç§ã«1ã€ã®åŸ®åŠãªè³ªåãããŸããããšã¢ã«ãã©ã³ãœã¯èšããŸãã ããŒããã€è匱æ§ããšã¯ã¹ããã€ãã«é¢ããæ å ±ãååŒãããããªããã»ã¹ã®é埳çåŽé¢ã«ã€ããŠã©ãæããŸããïŒã èªããã«ããã®ç¬éãå«ççåŽé¢ã¯çµæžçåŽé¢ãããç§ãããã»ã©å¿é ããŸããã§ããã ãç§ã«ãšã£ãŠããèå³æ·±ã質åã¯ã誰ããã£ãšè²¬ä»»ãè² ãã¹ãããšããããšã§ãããè匱æ§ãæªçšãã人ããŸãã¯äœå質ãœãããŠã§ã¢ã®éçºè ã§ããïŒã
ã¢ã«ãã©ã³ãœã¯ãè匱æ§ãã¬ãŒããŒã®å«çãçå®ããŸããã æåã®ã«ãŒã«ïŒäººæš©äŸµå®³ã§èŠãããäŒæ¥ãšååããªãã§ãã ããã 2çªç®ã®ã«ãŒã«ïŒäººã®å¥åº·ãè ãããªãã§ãã ãããããšãã°ãå»çæ©åšã®è匱æ§ã販売ããªãã§ãã ããã åæ§ã«ãçãŸããã€ã³ãµã€ããŒæ å ±ãååŒããããšã¯ã§ããŸããã 3çªç®ã®ã«ãŒã«ïŒå©ççžåãåé¿ããŸãã å¥ã®çŠæ¢äºé ã¯ãä¹±çšã«é¢ãããã®ã§ãã売ãæã¯ãæ»æãŸãã¯ã¿ãŒã²ããã®æ倧æ°ãæå®ããå¿ èŠããããŸãã ããã«ãAlfonso de Gregorioã®å«ççèšèšã«ããã°ãåãè©Šåã§äž¡æ¹ã®ããŒã ã§ãã¬ãŒããããšã¯ã§ããŸãããã€ãŸããæ»æè ãšé²åŸ¡è ã®äž¡æ¹ãå©ããããšãã§ããŸãã
1åããã200ãã«
Kaspersky Labã®Sergei Golovanovã¯ãã»ãã¥ãªãã£äŒç€Ÿã®ã»ãã¥ãªãã£å°é家ããŒã ããããã«æ»ã£ãŠããŠãã ããã æéã¯å¯å®¹ã§ã¯ãããŸããã 1åããšã«200ãã«ããããŸããã
éè¡ã«è¡ãéäžãç§ãã¡ã¯å°ãç·åŒµããŠãæžæ»ãæåããŠããŸããã ããçš®ã®ãããŒã±ãã£ã³ã°ã®åŒŸäžžããèãããšããçãããããŸãã-çºè¡šãããæ°åã¯ãç§ãã¡ã«ãšã£ãŠèžè¡çãªèªåŒµã®ããã§ããã å°çãããšãcrontabãã·ã¹ãã ã«å ¥ã£ãããšãå€æããŸããã ãã¹ãŠãããã§ããïŒæ¯å200ãã«ãæªç¥ã®å®å ã«é£ã³ãŸããã ãããŠããã®ãããªååŒã¯æ°é±éã«ããã£ãŠè¡ãããŸããã
ãã®åŸãäœæ¥ãå§ãŸããŸããã éè¡ã«ã¯ãSSHçµç±ã®ãªãŒãã³ã¢ã¯ã»ã¹ãåããLinuxãµãŒããŒããããŸããã ãµãŒããŒã¯åŠçãçŽæ¥èŠãŸããã éè¡ãšåŠçã®éã®éä¿¡ã¯ãPOSTèŠæ±ã䜿çšããŠHTTPçµç±ã§è¡ãããŸããã ãããã®èŠæ±ã¯ãã©ãã«ãéã転éããããã©ã®å£åº§ãããªã©ã決å®ããŸããã éè¡ã¯ééã£ãååŒã«ã©ã®ããã«æ°ã¥ããŸãããïŒ æ³åããŠã¿ãŠãã ããããã®ãããªåŠçã»ã³ã¿ãŒã®å°é家ãå€ã«åº§ã£ãŠããŸãã éãã§ã¹ã ãŒãºããã©ã³ã¶ã¯ã·ã§ã³ãªãã ãããŠãæ¯å200ãã«ãéãéè¡ã¯1ã€ã ãã§ãã åŠçã»ã³ã¿ãŒããã圌ãã¯éè¡ãšåŒã°ããŸããã åãã¡ã¯äœãããŠããã®ïŒ éè¡å¡ã¯ãã§ãã¯ããéåžžã«é©ââããã 圌ãã¯ãããããŸããã§ããã crontabã¹ã¯ãªããã¯ããã«ãŒã«ãã§ééããŸããã
圌ãã¯ç®¡çè ã«é»è©±ããSSHã®ãã¹ã¯ãŒããå°ããŸããã ãã¹ã¯ãŒãã¯Sonic17ã§ããããšãå€æããŸããã èªèšŒãã°ã調ã¹ããšãããé±ã«3åã®è©Šè¡ã§ãã¹ã¯ãŒããç·åœããæ»æãããŠããããšãããããŸããã 圌ãã¯2ã¶æããããŸããïŒ æ»æè ã¯ãã¹ã¯ãŒãã®åºæ¬èªãææ¡ããæ°åã®åé¡ãå§ããŸããã 圌ãã¯åææ¥ã«ãããããã®ã§ã圌ãã¯ãŠãã€äººã§ã¯ãªãããšãç¥ã£ãŠããŸããã ãšã³ããªãŒãã€ã³ããæ¢ãå§ããŸããã èŠã€ããã æ å ±â .aspã¹ã¯ãªããã¯ãæ³äººããµãŒãã¹ãããªã³ã©ã€ã³ãã³ã¯ã®Webãµã€ãã§èŠã€ãããŸããã info.aspãšéãã¯ãããŸããã§ããã å¯äžã®éãã¯ãSQLã¯ãšãªãéä¿¡ããæçµè¡ã§ããããã¯ãéè¡ã®ããŒã¿ããŒã¹ã§ããã«å®è¡ãããŸãã æåã¯ãéçºè ãééã£ãŠãããšå€æãããŸããã ã»ãã¥ãªãã£ãµãŒãã¹ã¯æ¢ã«ã¯ãã ããŠãåãããããæ¢ãå§ããŸããã ããããç§ãã¡ã¯åœŒãã«åŸ ã€ããã«é Œã¿ããªã³ã©ã€ã³ãã³ãã³ã°ããŒã¿ããŒã¹ã«ãªã¯ãšã¹ããè¡ãã¹ã¯ãªããã®åŠçãéå§ããŸããã ãã®åŸããã³ãã«ãäœæããŠããexeãã¡ã€ã«ããã®ããŒã¹ã§æ©èœãå§ããŸããã ãã®ãã¹ãèŠããšã䜿çšãããŠããããã€ã®æšéŠ¬ã®å šãªã¹ããèŠã€ããããšãã§ããŸããPowerShellã®MeterpreterãšMimikatzãæçœãªPowerpreterããã¯ã€ããªã¹ãã«èšèŒãããPuTTY plinkã§ãã èŠæ±ã¯ãäŒæ¥ãããã¯ãŒã¯å šäœãä»ããWebã¢ããªã±ãŒã·ã§ã³ããéä¿¡ãããŸããã
Sergeyã«ããã¬ããŒãå šäœãCopycatãšãã§ã¯ãã ãµã€ããŒã€ã³ããªãžã§ã³ã¹ããè¡é çé£ãŸã§ãããã³ä»ã®å€æ°ã®åºçŸã¯www.phdays.ru/broadcastã§èŠãããšãã§ããŸãã
Positive Hack Days VIã®è©³çŽ°ã¯ããã©ãŒã©ã ã®ãŠã§ããµã€ããšTwitterã®ããã·ã¥ã¿ã°ïŒphdaysã§ç¢ºèªã§ããŸãã