
2013幎ã«ããŠããŒã¯ãªäŸµå ¥ãã¹ãã©ããããã¹ãã©ãããéå§ããŸããã å®éãç 究æã¯ãããŸããŸãªè匱æ§ãšæ§æãšã©ãŒãå«ãå®éã®äŒæ¥ãããã¯ãŒã¯ïŒCTFã§ã¯ãªãïŒã®ã³ããŒã§ãããããæ»æè ã¯äŒæ¥ãããã¯ãŒã¯ã«å¯Ÿããå®éã®æ»æã®çºçæ¹æ³ãç解ããããŒã«ãšæ¹æ³è«ãç¿åŸããããŸããŸãªæ»æãã¯ãã«ãæ§ç¯ããæ¹æ³ãåŠã¶ããšãã§ããŸãã ãã®ãããªç¥èããªããã°ãæ å ±ã»ãã¥ãªãã£ã®å°é家ã¯é«å質ã®ä¿è·æ段ãéçºã§ããŸããã
4幎åŸããã¹ãã©ãã¯ç¬èªæ§ã倱ãããšãªããäžçäžãã18500人以äžã®åå è ãéããŸããã ãã®ãããªãªãŒãã£ãšã³ã¹ãšæ¯æ¥äœæ¥ããäŸµå ¥ãã¹ãããã©ã¬ã³ãžãã¯ããµã€ããŒæ»æã«å¯Ÿæããå®è·µçãªã¹ãã«ã身ã«ã€ãã Pentestit Corporate Laboratoriesã®æ§æãå®è·µçãªIBãã¬ãŒãã³ã°ã³ãŒã¹ããŠããŒã¯ãªãã®ã«ããŸãã
äŸµå ¥ãã¹ãã©ããã¹ãã©ã
æåã®ãã¹ãã©ãã©ãã¯ãå°èŠæš¡äŒæ¥ã®ãããã¯ãŒã¯ïŒãã¡ã€ã³ãã¡ãŒã«ããã¡ã€ã«ãµãŒããŒãªã©ïŒã®ã³ããŒã§ãããè€éã§åæ£ãããéäžåãããã¯ãŒã¯ïŒãã¡ã€ã³ãVPNãã³ãã«ããã©ã³ããµãŒããŒãªã©ïŒã«ãªããŸããããã®æ¬è³ªã倱ãããšãªã-æ»æãã¯ãã«ãæ£ããæ§ç¯ããããšã«ãããç 究æã®ITæ§é ãå®å šã«äŸµå®³ããå¿ èŠããããŸãã ããã¯ããã¹ãã©ããã®ç¬èªæ§ã§ããCTFãšã¯ç°ãªããã©ãå ã®ããŒãã¯çžäºæ¥ç¶ãããŠããããã®ãã¡ã®1ã€ã䟵害ããããšã§ãä»ã«å¯Ÿããæ»æãã¯ãã«ãéçºã§ããŸãã äžéšã®ç 究宀ã§ã¯ãçŸå®æãé«ããããã«ã瀟äŒæè¡çãªæ»æãã¯ãã«ïŒããšãã°ããªãã£ã¹ãããŒãžã£ãŒãä»ã®ç 究宀ã®åŸæ¥å¡ïŒãå®ããŠããŸãã
ã¢ã€ãã¢ãå®è£ ããåã«ãã¿ãŒã²ãããªãŒãã£ãšã³ã¹ãããç解ããå¿ èŠããããŸãã å¥ã®ã©ããç«ã¡äžãããã³ã«ãç§ãã¡ã¯éåžžã«è²Žéãªå®åçµéšãç²åŸããè匱æ§ãèŠã€ããŠæªçšããã¹ãã«ãšãšãã«ãPentestit Corporate Laboratoriesã«ç§»è¡ããããããå°é家åãã®æ å ±ã»ãã¥ãªãã£ã®åéã§è¿ éãã€é«å質ã®å®è·µãã¬ãŒãã³ã°ã®ããã®åªãããã¹ãå Žã«ããŸãæ å ±ããã³ãã¹ã¿ãŒãéçºè ãã·ã¹ãã 管çè ãä¿è·ããŸãã

ãŠã©ãŒã ã¢ãã-ããŒãã»ãã¥ãªãã£ïŒAã
ãäŒæ¥ç 究æãã§ã®æè²ã«ã¯ã質ã®é«ãäºåãã¬ãŒãã³ã°ãå¿ èŠã§ãã ãã®ãããªãã¬ãŒãã³ã°ã¯ããZero SecurityïŒAãã³ãŒã¹ã§ååŸã§ããŸãããã®ã³ãŒã¹ã§ã¯ããã¥ã¬ãŒã¿ãŒã®æå°ã®äžã§ãæšæºã®Kali Linux Rolling Edition 2017ããŒã«ã調æ»ããåµå¯ãæ å ±åéããè匱æ§ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãèŠã€ããŠæªçšããæ¹æ³ã«è³ããŸã§ãäŸµå ¥ãã¹ãã®ãã¹ãŠã®æ®µéã«ã€ããŠåŠã³ãŸãã äŒæ¥ç 究æãšåæ§ã«ãã³ãŒã¹ã®70ïŒ ã¯å°éç 究æã§ã®å®ç¿ã§ãã
ãŒãã»ãã¥ãªãã£ïŒã³ãŒã¹ããã°ã©ã
- æ å ±æè¡ã®åéã«ãããåæ³ãšç¯çœª
- è åšã¢ãã«ããã®çš®é¡ãç 究察象
- Linuxã«ç²ŸéããŠããã Kali Linux Rolling Edition 2017.1ã®æŠèŠãšæšæºããŒã«ã®æŠèŠ
- ã€ã³ããªãžã§ã³ã¹ãšæ å ±åé
- ãããã¯ãŒã¯ã¹ãã£ã³
- Webè匱æ§ã®æªçšãBurp Suiteã®çŽ¹ä»ãOWASP Top-10ã®ç¥è
- ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã»ãã¥ãªãã£
- ã¯ã€ã€ã¬ã¹ã»ãã¥ãªãã£åæ
- Metasploitãã¬ãŒã ã¯ãŒã¯ã®çŽ¹ä»
- ããã¢ã¯ãã£ããªé²åŸ¡ã·ã¹ãã ã®ãã€ãã¹æ¹æ³ã®åæ
- ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®æŠèŠ
ãŒãã»ãã¥ãªãã£ã®ã¯ãšã¹ãã®1ã€ïŒA-ããŒã«ã«ãã¡ã€ã«ã€ã³ã¯ã«ãŒãžã§ã³
Webã¢ããªã±ãŒã·ã§ã³ã®ãã³ãã¹ããå®æœããå ŽåãããŸããŸãªãªã¯ãšã¹ãã«å«ãŸãããã©ã¡ãŒã¿ãŒã«ç¹ã«æ³šæãæãå¿
èŠããããŸãããããã®ãããã§ãWebã¢ããªã±ãŒã·ã§ã³ã®åå¿ã«åœ±é¿ãäžããããšãã§ããŸãã GETãªã¯ãšã¹ãã«ã¯ãã©ã¡ãŒã¿ãŒã1ã€ãããããŸããããã®å€ã¯phpæ¡åŒµåãæã€ãã¡ã€ã«ã§ãããããã«ãããããšãã°includeïŒïŒé¢æ°ã䜿çšããŠãããŸããŸãªããŒãžãWebã¢ããªã±ãŒã·ã§ã³ã®ãœãŒã¹ã³ãŒãã«å«ãŸããŠãããšçµè«ä»ããããšãã§ããŸãã
ãã¹ããå§ããŸãããã æåã«ãååšããªãããŒãžãè¿œå ããããããã©ã¡ãŒã¿ãŒå€ãä»»æã®ã©ã³ãã ãªè¡-website /ïŒPage = abc.phpã«å€æŽããŠãããŒãžã®æ å ±ã®ã©ã®éšåãæ¶ããããè©ŠããŠã¿ãŸãããã
Webã¢ããªã±ãŒã·ã§ã³ãLocal File Includeã«å¯ŸããŠè匱ã§ããããšã確èªããŸããã
ãã®è匱æ§ã¯èå³æ·±ããã®ã§ãããªããªãããã®å©ãã«ãããæ»æè ã¯Webã¢ããªã±ãŒã·ã§ã³ã«ã³ãŒããå«ããããšã«ãããè匱ãªãã·ã³äžã§ä»»æã®ã³ãŒããå®è¡ã§ããããã§ãã ããã¯ãããšãã°ãããŸããŸãªãã°ãã¡ã€ã«ã䜿çšããŠå®è¡ã§ããŸããããŒãžãã©ã¡ãŒã¿ã§/var/log/apache2/access.logãæå®ãããšããã°ãã¡ã€ã«ã®å 容ãååŸãããŸãã
ããã§ããŠãŒã¶ãŒãšãŒãžã§ã³ãããããŒãã·ã§ã«ã«çœ®ãæããããšãã§ããã³ãŒããå®è£ ããå¿ èŠããããŸãã
User Agentãã£ãŒã«ãã«ãã€ããŒããå®è£ ããåŸãWebãµãŒããŒãã°ããWebã·ã§ã«ãåŒã³åºãããšãã§ããŸãã
URIã§ã³ãã³ããçæããããšã«ãããWebãµãŒããŒã§ã³ãã³ããå®è¡ããç®çã®ããŒã¯ã³ãèŠã€ããããšãã§ããŸãã
ãã¹ããå§ããŸãããã æåã«ãååšããªãããŒãžãè¿œå ããããããã©ã¡ãŒã¿ãŒå€ãä»»æã®ã©ã³ãã ãªè¡-website /ïŒPage = abc.phpã«å€æŽããŠãããŒãžã®æ å ±ã®ã©ã®éšåãæ¶ããããè©ŠããŠã¿ãŸãããã
Webã¢ããªã±ãŒã·ã§ã³ãLocal File Includeã«å¯ŸããŠè匱ã§ããããšã確èªããŸããã

ãã®è匱æ§ã¯èå³æ·±ããã®ã§ãããªããªãããã®å©ãã«ãããæ»æè ã¯Webã¢ããªã±ãŒã·ã§ã³ã«ã³ãŒããå«ããããšã«ãããè匱ãªãã·ã³äžã§ä»»æã®ã³ãŒããå®è¡ã§ããããã§ãã ããã¯ãããšãã°ãããŸããŸãªãã°ãã¡ã€ã«ã䜿çšããŠå®è¡ã§ããŸããããŒãžãã©ã¡ãŒã¿ã§/var/log/apache2/access.logãæå®ãããšããã°ãã¡ã€ã«ã®å 容ãååŸãããŸãã
ããã§ããŠãŒã¶ãŒãšãŒãžã§ã³ãããããŒãã·ã§ã«ã«çœ®ãæããããšãã§ããã³ãŒããå®è£ ããå¿ èŠããããŸãã

User Agentãã£ãŒã«ãã«ãã€ããŒããå®è£ ããåŸãWebãµãŒããŒãã°ããWebã·ã§ã«ãåŒã³åºãããšãã§ããŸãã

URIã§ã³ãã³ããçæããããšã«ãããWebãµãŒããŒã§ã³ãã³ããå®è¡ããç®çã®ããŒã¯ã³ãèŠã€ããããšãã§ããŸãã
ããŒãã³ã¢-Pentestit Corporate Labs
ã³ãŒã¹ã®å®æœã«ã€ããŠã¯ç¬èªã®èŠè§£ãããããããŠã§ãããŒã¯ããã30ïŒ ã§ãæ®ãã®70ïŒ ã¯éäžçãªç·Žç¿ã§ããããããã«äœ¿ãããç¥èãæ®ããŠããŸãã ãã®ãããªãã¬ãŒãã³ã°ã¹ããŒã ã«ã¯ãæ倧éã®é¢äžãšç®èº«ãå¿ èŠã§ãããŠã§ãããŒã¯ãæ€çŽ¢æ¹æ³ãè匱æ§ã®æªçšãæ»æãžã®å¯ŸåŠæ¹æ³ãã€ã³ã·ãã³ãã®åææ¹æ³ãç解ã§ããŸãããæ£ããèãæ¹ãæããããšã¯ã§ããŸããã ãã®ãããªçµéšã¯å®è·µã«ãã£ãŠã®ã¿äžããããŸãã ããã€ãã®ã±ãŒã¹ãèŠãŠã¿ãŸãããã
ã±ãŒã¹1-ã·ã¹ãã 管çè
ãšã©ãŒ
ããWebãµãŒããŒã¯ãã·ã¹ãã 管çè
ãé
åžãããŠã³ããŒãããããã«ããŒã«ã«ãããã¯ãŒã¯ã«ã€ã³ã¹ããŒã«ãããŸãã ãã¡ã€ã«ã®ãªã¹ãã«ã¯ãWindowsãµãŒããŒäžã®å®è¡ãã¹ã瀺ãããã¯ã¢ããã¹ã¯ãªããããããŸãã WebãµãŒããŒã«ã¯ãã£ã¬ã¯ããªãã©ããŒãµã«ã®è匱æ§ãå«ãŸããŠãããç¹å®ã®ãã¡ã€ã«ãååŸããããšãã§ããŸãïŒååãããã£ãŠããŠããã®ãµãŒããŒäžã«ããå ŽåïŒã æ»æè
ã¯ãRadminãŠãŒãã£ãªãã£ãšã¢ã³ããŒããããpasswords.regã¬ãžã¹ããªãã©ã³ããå«ãããã¯ã¢ãããã©ã«ããŒãçºèŠããŸãã ãã©ã¡ãŒã¿ãã£ãŒã«ãã«ã¯ã管çè
ãã¹ã¯ãŒãã®ããã·ã¥ãå«ãŸããŠããŸãã ãããéžæããWindowsãµãŒããŒã«æ¥ç¶ããæ©äŒãåŸãŸãã

ã±ãŒã¹2-ãã©ã¬ã³ãžãã¯ïŒãã©ãã£ãªãã£ãWireshark
ãããã¯ãŒã¯äžã®ãã·ã³ã®1ã€ã§ç°åžžãªåäœãæ€åºãããŸããã ã¡ã¢ãªãã³ããšãããã¯ãŒã¯ãã©ãã£ãã¯ããã°ããåé€ããããšãã§ããŸããã
Volatility Frameworkã䜿çšããŠã¡ã¢ãªãã³ããåæããŸãã ãã³ãã«é¢ããæ å ±ã衚瀺ããŸãã
ã¡ã¢ãªãã³ãã§ã¯ãMovie_HD720pãPIDïŒ198ã®éæšæºåã®ããã»ã¹ã«æ°ã¥ããŸããMovie_HD720p.torrent.exeããã»ã¹ã®å®è¡å¯èœãã¡ã€ã«ã¯ããããä»ããŠææãçºçããããšãããããŸãã
PID 198ããã»ã¹ïŒMovie_HD720pïŒããªãã¹ã³ããããŒã7337ã§ãã¢ãã¬ã¹XXX.XXX.XXX.XXXããæ¥ç¶ã確ç«ãããŸããã
Wiresharkã§ãã£ã«ã¿ãŒãèšå®ãããšãæ»æè ã®ãããã¯ãŒã¯ã¢ã¯ãã£ããã£ã確èªã§ããŸããæ»æè ã¯æå·åã䜿çšããªãã£ããããã³ãã³ãã¯ã¯ãªã¢ããã¹ãã§éä¿¡ãããŸããã
Volatility Frameworkã䜿çšããŠã¡ã¢ãªãã³ããåæããŸãã ãã³ãã«é¢ããæ å ±ã衚瀺ããŸãã

ã¡ã¢ãªãã³ãã§ã¯ãMovie_HD720pãPIDïŒ198ã®éæšæºåã®ããã»ã¹ã«æ°ã¥ããŸããMovie_HD720p.torrent.exeããã»ã¹ã®å®è¡å¯èœãã¡ã€ã«ã¯ããããä»ããŠææãçºçããããšãããããŸãã
PID 198ããã»ã¹ïŒMovie_HD720pïŒããªãã¹ã³ããããŒã7337ã§ãã¢ãã¬ã¹XXX.XXX.XXX.XXXããæ¥ç¶ã確ç«ãããŸããã

Wiresharkã§ãã£ã«ã¿ãŒãèšå®ãããšãæ»æè ã®ãããã¯ãŒã¯ã¢ã¯ãã£ããã£ã確èªã§ããŸããæ»æè ã¯æå·åã䜿çšããªãã£ããããã³ãã³ãã¯ã¯ãªã¢ããã¹ãã§éä¿¡ãããŸããã

ã±ãŒã¹3-Webã¢ããªã±ãŒã·ã§ã³ïŒãã©ã€ã³ãSQLi
ããŒã«ã«ãããã¯ãŒã¯ã§ã¯ãèªåããã»ã¹å¶åŸ¡ã·ã¹ãã ã«é¢é£ããSCADA WebãµãŒããŒãå²ã¿ãŸãã
Webã¢ããªã±ãŒã·ã§ã³ã®ããŒãžã³ãŒãã調ã¹ããšãPOSTã¡ãœããã«ãã£ãŠéä¿¡ãããé衚瀺ã®å€ãèŠã€ãããŸãã
ã»ãšãã©ã®å Žåããã®æ å ±ã¯ãã§ã«å€ããªã£ãŠããŸããããŒã¿ãå ¥åãããšãçŠæ¢ãããŠãããšããã¡ãã»ãŒãžã衚瀺ãããŸãã
burpã¹ã€ãŒãã䜿çšããŠãµãŒããŒã®å¿çã調æ»ããããšããŠããŸãã
ãŠãŒã¶ãŒããããã¯ããããšãæ°ãããã©ã¡ãŒã¿ãŒurl =ããã«ãè¿œå ããããã©ã¡ãŒã¿ãŒãå€æŽããéã®ãµãŒããŒã®åäœã調æ»ããããšããŸãã
SQLã€ã³ãžã§ã¯ã·ã§ã³ãèå¥ããããã«ããã€ãã®ã¯ãšãªãéä¿¡ãããšãã¹ãªãŒãå€ã眮æãããšãã«ãWebã¢ããªã±ãŒã·ã§ã³ãã¹ãªãŒããã©ã¡ãŒã¿ãŒã®å€ãšã»ãŒçããé 延ïŒãšã©ãŒïŒã§å¿çãè¿ãããšãããããŸãã ããã¯ãæéããŒã¹ã®SQLã€ã³ãžã§ã¯ã·ã§ã³ã瀺ããŠããŸãã
sqlmapã¯ãšãªã§èå¥ããããã©ã¡ãŒã¿ãŒã䜿çšããŠãããŒã¿ããŒã¹ã®å 容ãæããã«ããç®çã®ããŒã¯ã³ãååŸããŸãã

Webã¢ããªã±ãŒã·ã§ã³ã®ããŒãžã³ãŒãã調ã¹ããšãPOSTã¡ãœããã«ãã£ãŠéä¿¡ãããé衚瀺ã®å€ãèŠã€ãããŸãã

ã»ãšãã©ã®å Žåããã®æ å ±ã¯ãã§ã«å€ããªã£ãŠããŸããããŒã¿ãå ¥åãããšãçŠæ¢ãããŠãããšããã¡ãã»ãŒãžã衚瀺ãããŸãã

burpã¹ã€ãŒãã䜿çšããŠãµãŒããŒã®å¿çã調æ»ããããšããŠããŸãã

ãŠãŒã¶ãŒããããã¯ããããšãæ°ãããã©ã¡ãŒã¿ãŒurl =ããã«ãè¿œå ããããã©ã¡ãŒã¿ãŒãå€æŽããéã®ãµãŒããŒã®åäœã調æ»ããããšããŸãã

SQLã€ã³ãžã§ã¯ã·ã§ã³ãèå¥ããããã«ããã€ãã®ã¯ãšãªãéä¿¡ãããšãã¹ãªãŒãå€ã眮æãããšãã«ãWebã¢ããªã±ãŒã·ã§ã³ãã¹ãªãŒããã©ã¡ãŒã¿ãŒã®å€ãšã»ãŒçããé 延ïŒãšã©ãŒïŒã§å¿çãè¿ãããšãããããŸãã ããã¯ãæéããŒã¹ã®SQLã€ã³ãžã§ã¯ã·ã§ã³ã瀺ããŠããŸãã
sqlmapã¯ãšãªã§èå¥ããããã©ã¡ãŒã¿ãŒã䜿çšããŠãããŒã¿ããŒã¹ã®å 容ãæããã«ããç®çã®ããŒã¯ã³ãååŸããŸãã
ã³ãŒã¹ããã°ã©ã Corporate Labs
ã¢ãžã¥ãŒã«ãProfiã -䟵å
¥ãã¹ãã®åéã«ãããå°éçã¹ãã«ã®éçºãšçŸä»£ã®ã·ã¹ãã ã䟵害ããå®éçãªçµéšã
Expertã¢ãžã¥ãŒã«ã¯ãäŸµå ¥ãã¹ããã·ã¹ãã ä¿è·ãæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ã調æ»ã®å°é家ã®å®è·µã¹ãã«ãéçºããããã«èšèšãããŠããŸã ã
RedTeamã¢ãžã¥ãŒã« -äŸµå ¥ãã¹ããæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ã調æ»ã®åéã§ã®ããŒã ã¯ãŒã¯ã®ãã¬ãŒãã³ã°ãç®çãšããŠããŸã
- ãã·ã¢ããã³æµ·å€ã®æ å ±ã»ãã¥ãªãã£æ³ã
- äŸµå ¥ãã¹ãïŒæ¹æ³è«ãæ¹æ³ãçš®é¡ãããŒã«ã
- ãããã¯ãŒã¯ã»ãã¥ãªãã£ïŒã¹ãã£ã³ãæ§æãšã©ãŒãæäœãããã³æäœåŸ;
- Webã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ïŒSQLã€ã³ãžã§ã¯ã·ã§ã³ã®æ§è³ªãXSSã®åºæ¬ãããã³Webã®è匱æ§ãæªçšããããã®ããŒã«ã
- å¹æçãªæ å ±ã»ãã¥ãªãã£ã·ã¹ãã ã®æ§ç¯ïŒèæ¯æ å ±ãšæ¢åã®IDSã®æŠèŠã
- MITMæ»æããã³é²åŸ¡æ¹æ³ã
- SQLiã«é¢ããé«åºŠãªã¯ãŒã¯ã·ã§ããïŒäžè¬çãªããŒã¿ããŒã¹ãžã®æ»æã
- XSSã«é¢ããé«åºŠãªã¯ãŒã¯ã·ã§ããã
- ææ°ã®Webã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ã
- ãããã¯ãŒã¯ã»ãã¥ãªãã£ã®åŒ·åïŒãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®è匱æ§ãæ€çŽ¢ããŸãã
- äŸµå ¥ãã¹ãã§ã®Pythonã®äœ¿çšã
- å¹æçãªæ å ±ã»ãã¥ãªãã£ã·ã¹ãã ã®æ§ç¯ã
- ã¯ã€ã€ã¬ã¹ã»ãã¥ãªãã£ã
- å°éç 究æã§ã®å®åã
Expertã¢ãžã¥ãŒã«ã¯ãäŸµå ¥ãã¹ããã·ã¹ãã ä¿è·ãæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ã調æ»ã®å°é家ã®å®è·µã¹ãã«ãéçºããããã«èšèšãããŠããŸã ã
- Windowsã·ã¹ãã ã§ã®æŸååŸã
- Linuxã·ã¹ãã ã§ã®æŸååŸã
- ãµã€ããŒç¯çœªèª¿æ»;
- ã¢ãã€ã«ããã€ã¹ã®ãã©ã¬ã³ãžãã¯ã
- ãã©ã¬ã³ãžãã¯ïŒVolatility Frameworkã䜿çšããŠRAMãã³ããšãã¡ã€ã«ã·ã¹ãã ãåæããŸãã
- å°éç 究æã§ã®å®åã
RedTeamã¢ãžã¥ãŒã« -äŸµå ¥ãã¹ããæ å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ã調æ»ã®åéã§ã®ããŒã ã¯ãŒã¯ã®ãã¬ãŒãã³ã°ãç®çãšããŠããŸã
- äŸµå ¥ãã¹ãäžã®ããŒã ã¯ãŒã¯ã
- äŸµå ¥ãã¹ãäžã®ããŒã¿åŠçã·ã¹ãã ã
- åæããã³è匱æ§ç®¡çããŒã«ã䜿çšããŸãã
- 瀟äŒæè¡ãã£ã³ããŒã³ã®å®æœã
- ã€ã³ã·ãã³ãã®å¯Ÿå¿ãšèª¿æ»ã
- æªæã®ããã¢ã¯ãã£ããã£ã®åæïŒè åšã®æ€åºãšäžåã
- å°éç 究æã§ã®å®åã
Corporate Laboratoriesã®ãã1ã€ã®ç¹åŸŽã¯ãå®éšå®€ç°å¢ã®åäžã®ããããã§ããèšãæãããšãå®éšå®€ã¯ãè匱æ§ãšæ§æãšã©ãŒãåã蟌ãŸããå®éã®äŒæ¥ã®ã³ããŒã§ãããååã«æ§ç¯ãããæ»æãã¯ãã«ãå¿ èŠãšããŸãã åœç€Ÿã®ãã¬ãŒãã³ã°ããã°ã©ã ã«ã¯ããã¥ã¬ãŒã¿ãŒãå䌎ããŸãããã¥ã¬ãŒã¿ãŒã®ã¿ã¹ã¯ã¯ãã¿ã¹ã¯ã®å®äºãæ¯æŽãïŒå¿ èŠãªå ŽåïŒãå®è£ ã®æ£ç¢ºããç£èŠããããšã§ãã ã³ãŒã¹ã¯ãäŒç€ŸèšŒææžã®çºè¡ã§çµäºããŸãã

äŒæ¥ã©ããããªã¬ãã¥ãŒ
Corporate Labsã®å®å
šãªã¬ãã¥ãŒ
ã¿ã€ãã³ã°SSHæ»æ
PowerShell Empireãã¬ãŒã ã¯ãŒã¯
Webã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããè€åæ»æ
DNSã«ããæå·åãããã³ãã³ã管ç
Kali Linuxã§ã®OpenVAS9ã¹ãã£ããŒã®ãã¢
ã¿ã€ãã³ã°SSHæ»æ
PowerShell Empireãã¬ãŒã ã¯ãŒã¯
Webã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããè€åæ»æ
DNSã«ããæå·åãããã³ãã³ã管ç
Kali Linuxã§ã®OpenVAS9ã¹ãã£ããŒã®ãã¢
質åãããå Žåã¯ãã³ã¡ã³ãã§è³ªåããŠãã ããã ãã³ãã¹ãã£ããã§ãäŒãããŸãããïŒ