Positive Hack Days VIãæ»äº¡ããŸããã 圌ã®ã€ãã³ããéå»ã®ããŒãžã«ãªã£ãã®ã§ã次ã®å¹Žã«åããŠåšåº«ãåããã³ãŒã¹ã®ãã£ãŒããäœæããŸãã 第6åPHDaysã®ã©ã€ãã¢ããŒãã¯å¯Ÿç«ã§ãããPHDaysã®äœæã®æåã®æ¥ããäž»å¬è ã®å¿ã®äžãæ©ãåããæçµçã«ã PHDays VI CityFïŒConfrontation ãã®åœ¢ã§ãã®å ·çŸåãçºèŠãããšããèãã§ã ã ãã©ãŒã©ã ã®äž»èŠãªç«¶äºã¯ãé«åºŠã«å°éåãããããã«ãŒã²ãŒã ãã2æ¥éã®ã¡ã¬ãã€ãã«é²åããŸããã
åžãå€ããŠå®éã®ç«¶æäŒãå®éã®ç掻ã«è¿ã¥ããæåã®è©Šã¿ã¯ãæšå¹Žã®ç¬¬5åPHDaysã§è¡ãããŸããã ã¹ããŒãªãŒã§ã¯ãåCTFããŒã ã¯æ¶ç©ºã®ç¶æ ã§æŽ»åããŠãã掟factã§ããã ãã¹ãŠã®ã€ãã³ãã¯å°äžåŽåè 亀æã«çµã³ä»ããããåå è ã¯ç¹å®ã®ãªããžã§ã¯ãããããã³ã°ããåœä»€ãåãåããŸããã ä»å¹Žããã©ãŒã©ã ã®äœæè ã¯ããã«é²ãã§ãããã«ãŒã®å£è«ããã£ãã§ã³ããŒãšãšãã¹ããŒãã»ãã¥ãªãã£ã»ã³ã¿ãŒïŒSOCïŒã®ããŒã ã§åžéããŸããã ã²ãŒã ã®ãªãŒã¬ãã€ã¶ãŒã¯ãæ å ±ã»ãã¥ãªãã£ã®äžçã®æ¬åœã®ä»£è¡šè ãæã«åããŸããã人çã®ã»ãã¥ãªãã£ã·ã¹ãã ãæ§ç¯ããæ»æã«å¯Ÿæããã€ã³ã·ãã³ãã調æ»ãã人ãã¡ã§ãã
ãååãšããŠãããã«ãŒããŒã ã®ã¿ãCTFã«åå ããŠããŸãã ã€ã³ãã°ã¬ãŒã¿ãSOCãæ å ±ã»ãã¥ãªãã£ã®å°é家ãªã©ãå®éã®ãªããžã§ã¯ãã®ã»ãã¥ãªãã£ãæ åœãã人ã ã¯ããã®ç«¶äºã«ã¯åå ããŸããã æ å ±ã»ãã¥ãªãã£æ¥çã®ã»ãšãã©ã¯ãªããµã€ãã§ããã PHDays VI CityFã®ç®æšïŒå¯Ÿæ±ºã¯ãã§ããã ãå€ãã®äººã ã«ã»ãã¥ãªãã£ã®å®éçãªåŽé¢ãèªèãããããšã§ããã é«åºŠã«å°éåãããé²è¡ããã³æ»æããŒã ãçç·Žããããšãè¡ããšããã®åœ¢åŒãéåžžã«èå³æ·±ãããšãããããŸãããé²åŸ¡ããŒã ãšSOCã®ããŒã ãé²åŸ¡ã·ã¹ãã ãæ§ç¯ããæ»æãæéããããã«ãŒãæ»æããŸãã
ã·ã¹ã³ã»ãã¥ãªãã£ã³ã³ãµã«ã¿ã³ãã®ã¢ã¬ã¯ã»ã€ã«ã«ãããŒã¯ããã®ã€ãã³ãã¯äžçš®ã®ãå®éã®ãµã€ããŒã»ãã¥ãªãã£ã€ãã³ãã®éå¬ã«ãããæ°ããèšèãã§ãããšææããŠããŸãã ãCityFã¯ãåæ¹ã察ç«ã«åå ãããšããç¹ã§ãç¹å®ã®ã·ããªãªã®äžã§ç掻ããåŸæ¥ã®ãµã€ããŒä»€ç¶ãCTFãšã¯ç°ãªããŸãã å®éãäžæ¹ã®ããŒã ãäŒç€Ÿãæ»æããããäžæ¹ã®ããŒã ãäŒç€Ÿãé²åŸ¡ããå Žåãèµ€ããŒã ãšéããŒã ã®ååã«ã€ããŠè©±ããŸãã CityFã®å Žåãæ§ç¯ãããããã·ãã£ããã®ãããªäŒç€ŸãšããŠéžã°ããæ å ±ã»ãã¥ãªãã£åžå Žã®ä»£è¡šè ãå®éã«æ å ±ã»ãã¥ãªãã£ã確ä¿ããèœåãå®èšŒããèšèã§ã¯ãªããèµ€ãšéã®ããŒã ãšããŠéžã°ããŸããããšåœŒã¯èª¬æããŸãã
ã¢ã¹ã¯ã¯ã¯ããã«ã¯å»ºãŠãããŸããã§ãã...
ãã¹ãŠã®ã€ãã³ãã¯éœåžFã§å±éãããŸããããæ©èœçã«ã¯å®éã«ã¯æ®éã®åäžé·è ãšéãã¯ãããŸããã§ããã éè¡ãé»æ°éä¿¡äºæ¥è ãé»åäŒç€Ÿã倧èŠæš¡ææ ªäŒç€Ÿã®ãªãã£ã¹ãã¹ããŒãããŒã ãåããŠããŸããã åžã®é åã«ã¯ããã¥ãŒã¹ããã³ãšã³ã¿ãŒãã€ã¡ã³ããµã€ããšãœãŒã·ã£ã«ãããã¯ãŒã¯ãåããç¬èªã®ã€ã³ã¿ãŒããããå±éãããŠããŸãã
äœæè ã¯6æ¥éã§äžçãåµé ããŸããããéœåžFã®å»ºèšã«ã¯ããã«æéããããã建èšè ã¯6ãæãããããŸããã äž»å¬è ãšããŒãããŒãèšé²çãªéãã§å ±åäœæ¥ãè¡ã£ããããã§ãæè¡çã«ã¯ç掻ã«å¯èœãªéãè¿ããã¹ãŠã®ã¢ãã¯ã¢ãããšã¹ã¿ã³ããå±éããããšãã§ããŸããã æ å ±ã»ãã¥ãªãã£ã®ç¹ã§é©ãã»ã©è€éãªã€ã³ãã©ã¹ãã©ã¯ãã£ã§ããããšãå€æããŸããã
Positive Technologies補åããã¢ãŒã·ã§ã³ãããŒãžã£ãŒãPHDaysã®çµç¹å§å¡äŒã®ã¡ã³ããŒãPHDaysã®çµç¹å§å¡äŒã®ã¡ã³ããŒãããã€ã«ã¬ãã³ã¯æ¬¡ã®ããã«è¿°ã¹ãŠããŸãã ãããã¯ãŒã¯ããµãŒããŒããœãããŠã§ã¢ãªã©ãèšå€§ãªãªãœãŒã¹ãå¿ èŠã§ããã ç§ãã¡ã¯èªåã§éœåžã建èšããŸãããããã¡ãããå¿ èŠãªæ©åšãæäŸããèšçœ®ãšæ§æãç©æ¥µçã«æ¯æŽããŠãããããŒãããŒã§ããã·ã¹ã³ãšãã§ãã¯ãã€ã³ãã¯ãç§ãã¡ã«å€§ããªãµããŒããæäŸããŠãããŸããã
ç¹ã«ãæ°ãããœãªã¥ãŒã·ã§ã³ã䜿çšãããŸããïŒCisco APICïŒCisco Application Policy Infrastructure ControllerïŒãCisco Nexus 9000ã¹ã€ãããCisco ASA 5585ãã¡ã€ã¢ãŠã©ãŒã«ãCheck Point Next Generation Firewallã
ãç§ãã¡ã¯ãããžãã£ããã¯ãããžãŒãšé·å¹Žã®é¢ä¿ãæã£ãŠããŸã-ããã ãã§ãªãããã¬ã³ããªãŒã§ããããŸãã ãããã£ãŠãç§ãã¡ã¯äœå¹Žãã®éPHDaysã®æè¡ã€ã³ãã©ã¹ãã©ã¯ãã£ãæŽçããã®ãæäŒã£ãŠåãã§ããŸãã ä»å¹Žã¯ã以åããã¯ããã«å€ãã®ãããã¯ãŒã¯æ©åšãšãµãŒããŒãå¿ èŠã«ãªã£ãããããã®ã¿ã¹ã¯ã¯ããéå¿çã«ãªããŸããã ããããæã ã¯ããããã£ãã ç¹å¥ãªç®æšãåæ¥çãªç®æšãè¿œæ±ãããšã¯èšããŸããã è¯ã人ã ãè¯ãããžãã¹ãçµç¹ããã®ãå©ããããšããé¡æã§ããããšã¢ã¬ã¯ã»ã€ã»ã«ã«ãããŒã¯èšããŸãã
倧äŒæ¥ã ãã競äºã®æºåã«åå ããããã§ã¯ãªãããšã«æ³šæãã¹ãã§ã-åå è ã®éã§æ¬åœã®ã¹ã¿ãŒãã¢ãããããŸããã ããšãã°ãLoomoonã¯CityFã·ã¹ãã ãCityBankã·ã¹ãã ã«æäŸããŸããã ãã¹ããŒãããŒã ãã¬ã€ã¢ãŠãã®ã»ãšãã©ã¯ãã¢ããã³ããã¯ãšPROSOFTã«ãã£ãŠæºåãããŸããã
察ç«ã®çŽæ¥ã®è±éãã¡ã¯ããŸããã«æºåãããŠããŸããã ã²ãŒã ã®æ¡ä»¶ã§ã¯ãé²åŸ¡ããŒã ã¯äºåã«ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã¢ã¯ã»ã¹ããŠãæœèšã®ä¿è·æ段ãèšå®ããŸããããå¶éã¯ãããŸããã§ããã é²åŸ¡è ã®äž»èŠãªããŒã«ã¯ãå®éã«ãã¹ãããã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®ãã¡ã€ã¢ãŠã©ãŒã«ããããã¯ãŒã¯å¢çä¿è·ããŒã«ãæ»æã®æ€åºãšé²æ¢ãçžé¢åæããŒã«ãããã«ã¯SIEMã§ããã 圌ããèšãããã«ããã³ããŒã¯ãHP ArcSightãIBM QRadar SIEMãMicrosoft Operations Management SuiteãQualysãBot-Trek TDSãSecurity Onionã«åºã¥ãã·ã¹ãã ãBalabit Shell Control BoxãWindows Server Update ServicesãããŸããŸãªIDSã䜿çšããŸããIPS
ããããé²åŸ¡ããŒã ã®äžéšãšSOCã¯ãCityFã®æŠéæ¡ä»¶ã§éæšæºçãªãœãªã¥ãŒã·ã§ã³ãäœéšããåã³ãåŠå®ã§ããŸããã§ããã ããšãã°ãFalse PositiveããŒã ã¯ããã€ãã®ç¬èªéçºã䜿çšããŠã€ã³ã·ãã³ãã調æ»ããYou Shall Not PassããŒã ã¯GSMãããã¯ãŒã¯ãç£èŠããããã«å€ãMotorola C118é»è©±ãšUbuntuä»®æ³ãã·ã³ãèæ¡ããŸããã
é²åŸ¡åŽãçå£ã«æŠè£ ããå Žåãå察ã«ãæ»æè ã¯ã©ããããããšæšæºçãªããã«ãŒãããã§æŠè£ ããã»ãŒçŽ æã§æŠéã«çªå ¥ããŸããã ãããã¯äž»ã«ãBurp Suite Webã¢ããªã±ãŒã·ã§ã³ã®æ»æãNmap IPãããã¯ãŒã¯ã®ã¹ãã£ã³ãWiresharkãããã¯ãŒã¯ãã©ãã£ãã¯ã®ãã£ããã£ãšåæãCainïŒAbelãã¹ã¯ãŒãã®å埩ãMetasploitãšã¯ã¹ããã€ãã®äœæãšãããã°ã®ããã®ããŒã«ã§ããã
ã©ã€ãéå ±
察ç«ã¯äž»å¬è ã ãã§ãªããã«ãŒã«ãšã²ãŒã ã®äžçã«æ £ããŠããªãåå è ã«ãšã£ãŠãææŠã§ããã æœè±¡ã¿ã¹ã¯ã¯éå»ã«æ®ã£ãããä»åã¯åå è ãæ¬åœã®ç®æšãæã£ãŠããã PHDaysçµç¹å§å¡äŒã®ã¡ã³ããŒã§ããPositive Technologiesã®éè¡ã·ã¹ãã ã»ãã¥ãªãã£éšéã®è²¬ä»»è ã§ããTimur Yunusovæ°ã«ãããšããåŸæ¥ã®CTFã¯ããã¹ãŠã®å©ç¹ã«ãããããããçŸå®ãšã¯é¢å©ããŠããããã¹ãŠã¯ãããºã«ã解ãã人工çãªã¿ã¹ã¯ãå®äºããã ãªãŒã¬ãã€ã¶ãŒãè¿œæ±ããäž»ãªã¿ã¹ã¯ã¯ãçããŠããã·ã¹ãã ãå®éã«ç Žå£ããŠä¿è·ããæ¹æ³ãæ確ã«ç€ºãããšã§ããïŒããã§ããããã«ãŒã®äžçã«ç²ŸéããŠããªã人ã«ãšã£ãŠã¯äœãèµ·ãã£ãŠããã®ãç解ã§ããŸãïŒã ã¿ã¹ã¯ãšããŠãããã«ãŒã¯éè¡ãããéãçã¿ãç¡å¶éã®ã¢ãã€ã«éä¿¡ãæäŸããæ°Žåçºé»æã§äºæ ãæé ããå ã®ãªãã¹ããŒããªå®¶ãåºãŠãé²åŸ¡è ãšSOCããŒã ãæ»æè ã«æµæããããã«ææ¡ãããŸããã å®éããã¹ãŠã人çã®ããã§ãã
ãã¡ããããã®ãããªã€ãã³ãã«ã¯å°é£ã䌎ããŸãã 幞ããªããšã«ãç§ãã¡ã¯çããå°é£ãå æããããšãã§ãããã¹ãŠã®æµ®ãæ²ã¿ã«ãããããããã»ãšãã©ã®åå è ã¯ç«¶æäžã«åŸãããçµéšãç©æ¥µçã«è©äŸ¡ããŸããã
ãã€ãã³ãã®èŠæš¡ãšãã©ãŒãããã®å€æŽã®äž¡æ¹ã«é¢é£ããçµç¹å ã®æ··ä¹±ã«ããããããã1幎åã«ãã©ã€ããè«æ±ãããŸããã CityFã®ããã»ã¹ã§ã¯ãã¢ã«ãŠã³ãã決å®ããããã®ã«ãŒã«ãšååã«ããã€ãã®éè€ãšèª€è§£ããããŸãããããã®è³ã¯ãã¹ãŠã®è³ªåãåé€ããŸããããšã³ã¡ã³ãããŸããã ïŒãã£ãã§ã³ããŒãšSOCïŒã
ãã ãããŸã ååãªæããââãæã£ãŠããªãã£ã人ãããŸãããããã«ãŒã ãã§ãªããåºå ã®ååãšã競äºããã人ãããŸããã ãã¡ãããå€ãè¯ãCTFã®ååã«è¿ã人ãããŸããã
ãã²ãŒã ã®å°è±¡ã¯ãããŸãã§ããèå³æ·±ãã¢ã€ãã¢ãå®çšçãªã¿ã¹ã¯ãçšæãããŠããŸãããã²ãŒã ã®çžäºäœçšãšãã€ã³ããšããã«ãã£ã®ã·ã¹ãã ã¯ç¢ºç«ãããŠããŸããïŒç¹ã«ãã£ãã§ã³ããŒã«ãšã£ãŠïŒã ãšRdotããŒã ã®ã¡ã³ããŒã§ããOmar Ganievã¯èšããŸãã ã 圌ã¯äžæœãªthr33åå è Kirill Shilimanovã«ãã£ãŠãµããŒããããŠããŸãã ãµãŒãã¹ãã¢ã¯ã»ã¹ã§ããªãã£ããããæ»æè ã«ãšã£ãŠåæ¥ã¯å®è³ªçã«ç¡é§ã§ããã 圌ããéããŠãããã³ã°ãå§ãŸã£ããšããããã¯ã¯ããã«æ¥œãããªããŸããã ãµãŒãã¹ã¯è€éã§é¢çœãæºåãããŠããããšã«æ³šæããŠãã ãããäž»å¬è ã«æè¬ããŸããã
30æéã®æŠã
察ç«ã¯çŽ30æéç¶ãã倧èŠæš¡ãªæ»æã«å¯Ÿæããããã®æ¬åœã®ãã©ãœã³ã§ããã åå è ã«ã¯5ã€ã®ãªããžã§ã¯ããããã5ã€ã®é²åŸ¡ããŒã ãš3ã€ã®SOCããŒã ãé²åŸ¡ããŸããã 2æ¥éã§ãè£å€å®ã¯åé²è¡ãªããžã§ã¯ãã§3ã2äžä»¶ã®ã»ãã¥ãªãã£ã€ãã³ããèšé²ããçŽ200件ã®é倧ãªæ»æã®ã¿ãèšé²ããŸããã
99ïŒ ã®ã±ãŒã¹ã§ãæ»æã¯ä¿è·ããããªããžã§ã¯ãã®å¢çã«éäžããŠããŸããã å®ç掻ãšåæ§ã«ãWebãžã®æ»æã¯æãäžè¬çãªãã¯ãã«ã«ãªã£ãŠããŸãã ããããããã¯ãã£ãã§ã³ããŒã«ãšã£ãŠé©ãã§ã¯ãããŸããã§ãã;圌ãã¯äºåã«ãã®ãããªäžé£ã®ã€ãã³ããäºæ³ããŠããããã£ãã§ã³ã¹ã®æºåãã§ããŠããŸããã
ãWebãµãŒããŒã®ä¿è·ã«ç¹ã«éç¹ã眮ããŠããªãã£ã¹ã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããŸããã çµå±ã®ãšãããããã¯ç¡é§ã§ã¯ãããŸããã§ããïŒããã«ãŒã¯ãã³ãã¹ãã«å€ãã®ããŒã«ã䜿çšãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã IPSã®ãšã¯ã¹ããã€ãã«å¯ŸåŠããå ŽåãWebãµãŒããŒã«å¯Ÿããé«åºŠãªæ»æãšã¢ããªã±ãŒã·ã§ã³ããžãã¯ã«å¯Ÿããæ»æã¯ãWAFãã°ãWebãåæããæåã¢ãŒãã§ã®ã¿æ€åºã§ããŸãããµãŒããŒãšãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®é«åºŠãªãã°ããšãã°ãªãŒã³ããŒã ã®ã¡ã³ããŒã§ããCROCã®æ å ±ã»ãã¥ãªãã£ã®å°é家ã§ããDmitry Berezinã¯è¿°ã¹ãŠããŸãã
é²åŸ¡åŽã®æåŸ ã«åããŠãå®éã®å¥ã®äžè¬çãªãã¯ãã«-ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã䜿çšããæ»æ-ã¯ã察ç«ã®åå è ã«ãã£ãŠç©æ¥µçã«é¢äžããŠããŸããã§ããã ããã«ãŒã®1ã€ã®ããŒã ã®ã¿ãæµã®é倱ãå©çšãããã£ãã§ã³ããŒã®ããŒã ã®å éšãã©ãŒã©ã ãããã°ã€ã³ãšãã¹ã¯ãŒããæ®åœ±ããŸããã ãã ãããããã®ããŒã¿ã¯é倧ãªã€ã³ã·ãã³ãã«ã¯ã€ãªãããŸããã§ããã ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®é©çšãæ¬åœã«æ¥œãã¿ã«ããŠããŸããããæ»æè ã¯å®éã«ãã®ãããªæè¡ã䜿çšããŠããŸããã§ããããšãFalse PositiveããŒã ã®ã¡ã³ããŒã§ããSolar Securityã®Solar JSOCãã£ã¬ã¯ã¿ãŒVladimir Dryukovã¯åããŸããã
åŸã«ããã£ãã§ã³ããŒã¯ææªã®äºæ ã«åããŠããããšãèªãããããæ¯ã«æŠè£ ããŠtrapãçšæããã ã¢ããªã±ãŒã·ã§ã³ãWebã¢ããªã±ãŒã·ã§ã³ãOSããã³ãµãŒãã¹ã®è匱æ§ã®æªçšãæ§æãšã©ãŒãªã©ã絶察ã«ãã¹ãŠãæåŸ ãããŸãã å®éããã¹ãŠãç°ãªã£ãŠå€æããŸããã
ãåœç€Ÿã®ããŒã ã¯ããã¹ãŠã®ãªããžã§ã¯ããä¿è·ããŸãã-ãªãã¬ãŒã¿ãŒã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ããµãŒããŒãäŒæ¥ã®ã¡ãŒã«ããã¡ã€ã³ãRBSããããªäŒè°ã·ã¹ãã ãé»åææžç®¡çãã€ã³ã¹ã¿ã³ãã¡ãã»ãŒãžã³ã°ã æºåãããé²è¡ç·ã®å€§éšåã¯åœ¹ã«ç«ããªãã£ããããã«ãŒã¯å éšãããã¯ãŒã¯ã«äŸµå ¥ããªãã£ãã Golden TicketãPass-the-Hashãªã©ã®Kerberosãããã¯ãŒã¯èªèšŒãããã³ã«ã«å¯Ÿããæ»æãããã€ã®æšéŠ¬ãããã¯ãã¢ãä»ããæ»æã¯èŠãããŸããã§ããã ãŸããããã«ãŒã¯æºåããããããŒãããã«ç»ããŸããã§ããã ããã«ãŒã®èª°ãè匱ãªproFTPDãµãŒããŒãç Žå£ããããšããŸããã§ããããšãACTããŒã ã®ã¡ã³ããŒã§ããASTã°ã«ãŒãã®è²¬ä»»è ã§ããInna Sergienkoæ°ã¯èšããŸãã
False PositiveããŒã ã¯ãæ»æè ãããã«ãã£ãŠä¿è·ãããŠããã€ã³ãã©ã¹ãã©ã¯ãã£ã§ãã©ã°ã1ã€ããååŸã§ããªãã£ãããšãèªæ ¢ããŸããã ããããæ»æè ã¯é·ãéåå©ãç¥ããŸããã§ãããæ°åã§ãã·ã¹ãã ã®ç¶æ ãšãã®å®å šæ§ãå埩ããããšãã§ããŸãããã
ã¡ãªã¿ã«ãã²ãŒã ã®ãã¬ãŒã ã¯ãŒã¯ã§ã¯ããã£ãã§ã³ããŒãšSOCã®ããŒã ã®å ±åäœæ¥ããã®æå¹æ§ã瀺ããŠããŸãã è£å€å®ã«ãããšããã¹ãŠã®SOCããŒã ã¯æœèšã§èµ·ãã£ãŠããããšã®æãå®å šãªç¶æ³ãåéããäžæ¹ãé²åŸ¡åŽã¯äºä»¶ã«è¿ éã«å¯Ÿå¿ããããšãäœåãªããããŸããã ããšãã°ãã²ãŒã ã®æ¡ä»¶äžã§ãç£æ¥ã·ã¹ãã ã®é²åŸ¡è ãé²åŸ¡ããªãã«ããç¶æ³ã§ã¯ãç£æ¥ã·ã¹ãã ãç£èŠããSOCããŒã ã¯ãæ»æè ã®è¡åãæ»æã®éå§ããã®å®è£ ã詳现ã«èª¿æ»ããŸããã å®éã«ã¯ãããã¯é²åŸ¡ããŒã«ã®ä»å ¥ãªãã§ãæ»æãæå¶ããããã®è¿ éãªã¢ã¯ã·ã§ã³ã®å¯èœæ§ã«å¯Ÿå¿ããŸãã
ãæ å ±ä¿è·ããŒã ã¯ãæ°Žåçºé»æãš500ããã³10 kVã®å€é»æãæè·ããŸããã ã²ãŒã ã®ã·ããªãªã«ãããšã競æåæ¥ã®å€æ¹ãé²åŸ¡ã匱ãå§ããŸããããã®æ¥ã®çµããã«ã¯ãã»ãšãã©ãã¹ãŠã®SPIããªãã«ãªããŸããã SOCã®ã¿ãç£èŠãããŸãã ãªããžã§ã¯ããä¿è·ãããŠããéãã€ã³ãã©ã¹ãã©ã¯ãã£ã«å¯Ÿããåäžã®æåããæ»æã¯å®è¡ãããŸããã§ããã ä»ã®ãã¹ãŠã®ãããã³ã°ãšæŽªæ°Žã¯ãã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ãããŠããªããšãã«çºçããŸããããšãåå è ã®Ivan Melekhinãã³ã¡ã³ãããŠããŸãã
æåããããã«ãŒã®ç·æ°ïŒ
- è€æ°ã®ãã¡ã€ã³ã®ãã®ãå«ãã¢ã«ãŠã³ãããã€ãžã£ãã¯ããŸãã
- èªåå¶åŸ¡ã·ã¹ãã ã®ç©ççæ©åšãžã®æ»æãå®è¡ããŸãïŒæ°Žãæåºãããã©ã€ã³ãåæãããéé»ç·ã®é ç·ãçŒããŸããïŒã
- äŒæ¥ãããã¯ãŒã¯ã®è匱æ§ãä»ããŠæè¡å¶åŸ¡ã·ã¹ãã ãããã¯ãŒã¯ã«äŸµå ¥ããã
- ã¹ããŒãããŒã ã·ã¹ãã ã«å¯ŸããŠãããã¯ãŒã¯æ»æãå®è¡ããŸãïŒæ©åšããããã¯ãŒã¯ããåæããŸãïŒã
- éè¡ãããéãçã¿ïŒçŽ22,000ã«ãŒãã«ïŒãéè¡ã«ãŒãã®ããŒã¿ãåãåããŸãã
- CorpFãªãã£ã¹ã«å±ããã·ã¹ãã ãã¡ã€ã«ããã£ã¹ã¯ãã¢ãŒã«ã€ãã®ããã¯ã¢ããã³ããŒãçã¿ãå Žåã«ãã£ãŠã¯åé€ããŸãã
- USSDãªã¯ãšã¹ããåœé ããããšã«ãããGSM / SS7ã«å¯ŸããŠééã®çé£ã䌎ãæ»æãå®è¡ããã
- é²è¡ããŒã ã®åŸæ¥å¡ãšæ»æããŒã ã®äž¡æ¹ã«å¯ŸããŠçžäºæ»æãå®è¡ããïŒããã«ãŒããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ææ³ã䜿çšããŠããã£ãã§ã³ããŒãã©ãŒã©ã ãããã¹ã¯ãŒããçã¿ãVulnersãã£ãã§ã³ããŒããŒã ãããã«ãŒã³ã³ãã¥ãŒã¿ãŒããããã³ã°ãã ïŒã
- CorpFãªãã£ã¹ãµã€ããå«ãè€æ°ã®WebãªãœãŒã¹ãæ¹ããããã
- ã€ã³ãµã€ããŒã1人çºèŠããŸã-CorpFã®ãªãã£ã¹åŸæ¥å¡
ãŸãšã
ãã©ãŒã©ã ã¯ãæ å ±ã»ãã¥ãªãã£ã®å°é家ãããã»ã¹ãäžæããããšãªãéåžžã«é«ãã¬ãã«ã®ä¿è·ãæäŸã§ããããšãæ確ã«ç€ºããŸããã æçµç®æš-éœåžã®ãã¡ã€ã³ãç²åŸãã競äºã«åã€-ããã«ãŒã®åäžã®ããŒã ãéæããããšã¯ã§ããŸããã§ããã ãã®çµæã¯äž»å¬è ã«ãšã£ãŠã¯äºæ³å€ã®ããšã§ããïŒåœŒãã¯ããã«ãŒã®åå©ãäºæž¬ããŸããã ã²ãŒã ã®çµæãju審å¡ã¯æãããªåè ã«ååãä»ããããšãã§ããŸããã§ããããè³ã®å Žæã¯ããã«ãŒããŒã ã«ãã£ãŠéžã°ããã²ãŒã äžã«æé«ã§ããããšãå€æããŸããã Defenderããã³SOCããŒã ã¯ã ããŸããŸãªã«ããŽãªã§æäžãããŠããŸã ã
PHDaysã®çµç¹å§å¡äŒã®ã¡ã³ããŒã§ãããã·ã¢ã®Positive Technologiesã®ããžãã¹éçºæ åœå¯ãã£ã¬ã¯ã¿ãŒã§ããAlexey Kachalinã¯ã察ç«ã®çµæã«ã€ããŠæ¬¡ã®ããã«ã³ã¡ã³ãããŠããŸãããäž»å¬è ãšåå è ã®äž¡æ¹ãåã¡ãŸããã ããã¯ãŠããŒã¯ãªã€ãã³ãã§ããããã¬ã€ããã«æ確ãªã«ãŒã«ãéçºããããšã¯å°é£ã§ãã ä»å¹Žåå ãã人ãæ¥å¹Žç§ãã¡ã®ãšããã«æ¥ãŠãã²ãŒã ã®æºåãæäŒã£ãŠãããããšãé¡ã£ãŠããŸãã é²è¡ããŒã ãšæ»æããŒã ã«é¢äžããŠãã«ãŒã«ãšãã©ãŒããããäœæããŸããã
PHDays VIã¯æåãããšæèšã§ããŸããPHDaysãã©ãŒã©ã ã®ãã£ã¬ã¯ã¿ãŒã§ããVictoria Alekseevaã¯ããã«åæããŸãã
ãPHDaysã¯äœããããŸãããã®ã€ãã³ããè¡ãããç±æãæã€äººã ã§ãã ãã©ãŒã©ã ãåãªããã€ãã³ããã§ã¯ãªããæ¬åœã®äŒæ¥ã«ãªãããã«ã1幎ã«ããã£ãŠ100人以äžãããããããšãè¡ããŸããã æ¯åãç§ãã¡ãäž»å¬è ã¯ãèªåèªèº«ãå æããäžæ©åé²ããæ°ããèšé²ãæš¹ç«ããŸãã ç§ã¯ãã¹ãŠãæåãããšä¿¡ããŠããŸãïŒ4200人ã®åå è ã¯ããã®èšŒæ ã§ãã ãPHDaysã®éå¬ãæäŒã£ãŠãããã¿ããªã«æè¬ãããïŒã
ãã©ãŒã©ã ãšã³ã³ãã¹ããæ¥å¹Žéå¬ãããã¹ããŒã¬ã³ã®äžã§äºæž¬ããããšã¯äŸç¶ãšããŠå°é£ã§ãããäž»å¬è ã¯å¯Ÿç«ã®æŠå¿µãéçºããã€ããã§ãã 圌ãã¯ãã²ãŒã ããããã®éçºãç§ãã¡ãåŸ ã£ãŠãããšèšããŸããããšãã°ãåŸæ¥å¡ã®è§£éã«é¢é£ããã¢ã¯ã·ã§ã³ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãã€ãã³ããå¢ããããžãã¹ããã»ã¹ãæŒå€ã®ã·ããªãªãããã«å€åããŸãã ãããŠããã¡ãããå°æ¥çã«ã¯CityFã¯ããã«ã人å£ãå¢ãããããšãçŽæããŸãã
ãç§ãã¡ã¯ãç§ãã¡ã®åšãã®äžçãè¿å¹Žæ¥éã«å€åããŠããã®ãèŠãŠããŸãã ãµã€ããŒã»ãã¥ãªãã£ã¯ããŸããŸãæ¥åžžæè¡ã«æµžéããŠããŸãã è åšã¯ããè€éã«ãªããæ»æã¯ããé«åºŠã«ãªããè åšã¯ããé¡èã«ãªããŸãã å€ãæ¹æ³ã§ã»ãã¥ãªãã£ã·ã¹ãã ãæ§ç¯ããããšã¯ã§ããªããªããŸãããã»ãã¥ãªãã£ã¡ãœãããè¿ éã«æ¹åããå¿ èŠããããŸãããç§ãã¡èªèº«ã¯ããã«é«éã«éçºããå¿ èŠããããŸãã ããã«åãããŠãPHDaysãå€æŽãããŠããŸãã ä»å¹Žãç§ãã¡ã®äŒè°ãå¥ã®æå³ãèŠåºããããšãããããæããŸããããŸããŸãªæ¥çã®ä»£è¡šè ã察ç«ã«åå ããéèŠãªã€ã³ãã©æœèšãä¿è·ããçã®çµéšãåŸãæ©äŒãäžããããšã ãããŠã30æéã®æŠãã®åŸã®ç·ãã¡ã®çãããããªç®ã¯ãç§ãã¡ã«ãšã£ãŠæé«ã®å ±é ¬ã§ãã ããããç§ãã¡ã¯æ å ã«ãšã©ãŸããããããŸãããæ¥å¹Žãããã®ãã³ãã¹ã¿ãŒãITéšéã®ãã®ä»ã®ä»£è¡šè ãšã®å¯Ÿç«ã®åå è ãªã¹ããæ¡å€§ããŸã ããšèªãã®ã¯ã ããžãã£ããã¯ãããžãŒãºCEOã® ãŠãŒãªãã¯ã·ã¢ãã§ãã
ãã§ã«ãå€ãã®ããŒãããŒãšããŒã ã次ã®ã³ã³ãã¹ãã«åå ããæ欲ãè¡šæããŠããŸãã ããšãã°ãã¢ã¬ã¯ã»ã€ã»ã«ã«ãããŒã¯ãPHDays VIIã«å¯Ÿããã·ã¹ã³ã®èšç»ã軜èŠããªãããšãææ¡ããŠããŸããããã®åœ¢åŒã«ã¯çŽ æŽãããèŠéãããããCityFã¯CTFã«éåžžã«é«ãæ°Žæºãèšå®ããŠãããšæããŸãã ãããŠãäžçã®å°æ¿åŠçç¶æ³ãæªåããªããã°ãã·ã¹ã³ã¯åã³PHDaysã®ãã¯ãããžãŒããŒãããŒã«ãªããŸãã ãã¡ãããç§ãã¡ãå°æ¥ã®ã€ãã³ãã®ã¹ããŒã«ãŒãšããŠããããŠãããããCityFã®ããããã»ã°ã¡ã³ãã®ãã£ãã§ã³ããŒãšããŠèããããšã¯äŸ¡å€ããããŸãã ãã ãããã®ã¢ã€ãã¢ã«ã€ããŠã¯ç€Ÿå ã§æ€èšããå¿ èŠããããŸããã
PHDays VIIã¯ã©ããªãããæéã¯ããããŸãã ããããä»ãç§ãã¡ã¯èªä¿¡ãæã£ãŠç¬¬7åã®ãã©ãŒã©ã ãã§ãããšèšãããšãã§ããŸãïŒ