![](https://habrastorage.org/webt/t7/m6/3b/t7m63boloh5anssesupnqaawl4e.jpeg)
ZeroNightsäŒè°ããã°ã©ã ããã®ãã¥ãŒã¹ãå ±æããæãæ¥ãŸããã ZNã§èãããšãã§ããåã¬ããŒããä»åŸã®ã¯ãŒã¯ã·ã§ããã ã³ã³ãã¹ã ãããã³ä»å¹Žã®ã€ãããŒã·ã§ã³ã§ããWeb VillageïŒæçµçã«ïŒã«ã€ããŠèª¬æããŸãã
ç®æ¬¡
- äž»èŠè«æ
- ã¡ã€ã³ãã©ãã¯
- ãã¡ãŒã¹ããã©ãã¯
- é²åŸ¡çãªãã©ãã¯
- ã¯ãŒã¯ã·ã§ãã
- ãŠã§ãæ
äž»èŠè«æ
ä»å¹Žã¯ãåäŸã®ãªããåäŸã®ãªããå代æªèã®äœãããããŸã-ZeroNightsã®2人ã®äž»èŠã¹ããŒã«ãŒãäžåºŠã«ã 1ã€ã¯ã€ãã³ãã®åæ¥ãéãããã1ã€ã¯2æ¥ç®ã®åãã«ç¹ç¯ããŸãïŒ
ããŒãã¹ã»ããªãšã³ïŒå¥åãã«ããŒã»ãã¬ãŒã¯ïŒ
æ©æ¢°åŠç¿ãæ»æãèªååã®æªæ¥
Thomas Dallienã¯ã90幎代åã°ã«èäœæš©ä¿è·ã®ãªããŒã¹ãšã³ãžãã¢ãªã³ã°ããã³æè¡çæ段ã§æŽ»åãéå§ããŸããã ãã®åŸã圌ã¯ããã«ãªããŒã¹ãšã³ãžãã¢ãªã³ã°ææ³ã䜿çšããŠè匱æ§ã調æ»ãå§ããŸããã Thomasã¯ãWindowsã®ããŒã掻çšãããããšãã€ããªãã¡ã€ã«ã®æ¯èŒåæãããã³ä»ã®å€ãã®ãªããŒã¹ãšã³ãžãã¢ãªã³ã°ææ³ãéå§ããŸããã 2004幎ãHalvarã¯ãªããŒã¹ãšã³ãžãã¢ãªã³ã°æè¡ã«ç¹åããäŒç€Ÿzynamicsãèšç«ããŸããã äžæ¹ããªããŒã¹ãšã³ãžãã¢ãªã³ã°ã«é¢ãã圌ã®ç 究ããªããŒã¹ãšã³ãžãã¢ãªã³ã°ã«é¢é£ãããªããŒã¹ãªãªãšã³ãããããã°ã©ãã³ã°ææ³ãšãã¬ããžãããžã¡ã³ããã¯ãããžãŒã䜿çšãããšã¯ã¹ããã€ãã®éçºã¯åŒãç¶ãå ¬éãããŸããã 2011幎ã«ãGoogleãã¶ã€ãããã¯ãè²·åãããã®åŸäœå¹Žãã®éãHalvarã¯ããã°ããŒã¿ãšæ©æ¢°åŠç¿ã®ããããã³ãŒããŒã§è°è«ãããã»ãã¥ãªãã£ãã¯ãããžãŒã«é¢äžããŠããŸããã 2015幎ãHalvarã¯Pwnie Awardãåè³ããæ è¡ãèªæžããµãŒãã£ã³ã®æ³¢ã«1幎éäŒæ©ããããšã決ããŸããã
Thomas Dallienã¯ã圌ã®ã¬ããŒãã§æ©æ¢°åŠç¿ã«ã€ããŠèªããŸããä»æ¥ã®ITåéã«ãããä»åŸã®æ ¹æ¬çãªå€åã¯ãæåéãæ²é»ããŠããŸãã äžè¬çãªèªå€§å®£äŒã«ãã£ãŠçæããã誀解ãç¥è©±ãåãé€ãããšã¯å°é£ã§ãããã³ã³ãã¥ãŒã¿ãŒæè¡ããŸããŸãæœè±¡åã®ã¬ãã«ã«ç§»è¡ããŠããããšã¯æããã§ãããã®ãããåé¡åã¯åå²æŒç®åãšåããããäžè¬çã§ãã æ»æã®ç 究ã¯ã©ãã§ããïŒ åšå® ããžãã¹ã¯èªååã®åœ±é¿ãåããŸãããïŒ ãŸãã¯ããAIãïŒãã®å åã®ããããã§ïŒãããã«åœ±é¿ããŸããïŒ ãããšããã§ã«åœ±é¿ãåããŠããã®ã§ããããïŒ
ãã®ã¬ããŒãã¯ãAlphaGoãç§ãã¡ã«äœãæããããšãã§ãããã瀺ããæ©æ¢°åŠç¿ãä»åŸæ°å¹Žéã§åé²ããæ¥çã®é åã瀺ããŸãïŒå€§ããã¯èšããŸã§ããããŸãããïŒã
ã·ã§ã€ããã³
æå·åã¡ã¢ãªæ»æïŒ1ããããè¶ ããŠ
ã·ã§ã€ãžã§ãã³ã¯ããã€ãã¡å€§åŠã®æ°çç§åŠã®å©ææã§ãããAmazonã®ã¯ã©ãŠãæ å ±ã»ãã¥ãªãã£ã®ãšã³ãžãã¢ãªã³ã°ããã³æè¡ãµãŒãã¹ã®è²¬ä»»è ã§ãã ã·ã§ã€ã¯ã以åã¯ã€ã³ãã«ã®ã·ãã¢ãšã³ãžãã¢ããã³ã·ãã¢æå·äœæè ã§ããã 圌ã®é¢å¿åéã«ã¯ãæå·åãæ å ±ã»ãã¥ãªãã£ãã¢ã«ãŽãªãºã åãå«ãŸããŸãã Shayã¯ãAES-NIãPCLMULQDQãè¿ãå°æ¥ã®VPMADD52ã®ãããªããã»ããµåãã®åœä»€ã»ããã®äœæè ã§ãããæå·åã¢ã«ãŽãªãºã ã®é«éåã«è²¢ç®ããããŸããŸãªãã€ã¯ãã¢ãŒããã¯ãã£æ©èœãåããŠããŸãã 圌ã¯ããªãŒãã³ãœãŒã¹ã©ã€ãã©ãªïŒOpenSSLãNSSïŒã®éçºã«è²¢ç®ãã察称æå·åãå ¬éããŒã¢ã«ãŽãªãºã ãããã³ããã·ã¥ã®é床ãåäžãããŸããã Shay Geronã¯ãIntel Software Guard ExtensionsïŒSGXïŒãã¯ãããžã®ã¢ãŒããã¯ãã®1人ã§ããããã®å®è£ ãšæå·åãæ åœããŠããŸããã ããã«ã圌ã¯ã¡ã¢ãªæå·åãšã³ãžã³ã®äœæè ã«ãªããŸããã
圌ã®ã¬ããŒãã¯ãä»®æ³åãããã¯ã©ãŠãç°å¢ã§ã®ãŠãŒã¶ãŒããŒã¿ã»ãã¥ãªãã£ã®åé¡ã«ç¹åããŠããããŠãŒã¶ãŒãšã¯ã©ãŠããããã€ããŒã®äž¡æ¹ã«ãšã£ãŠé¢å¿ãé«ãŸã£ãŠããŸãã ãã€ããŒãã€ã¶ãŒã¯ããã¹ã管çè ã«ã²ã¹ãä»®æ³ãã·ã³ã®ã¡ã¢ãªé åãèªã¿åãæ©èœãæäŸããããã管çè ããããã®æ©èœã䜿çšããŠãŠãŒã¶ãŒããŒã¿ã«ã¢ã¯ã»ã¹ããªããšããä¿èšŒã¯ãããŸããã ãã¹ãŠã®ã¡ã¢ãªã1ã€ã®ïŒç§å¯ïŒããŒã§æå·åãããå Žåã§ãããã®è åšã¯é²æ¢ãããŸããã ã¡ã¢ãªé åãåã²ã¹ããã·ã³ã®äžæã®ããŒã§æå·åãããŠããå Žåãã²ã¹ãä»®æ³ãã·ã³ã管çè ããéé¢ã§ããŸãã åæã«ããã€ããŒãã€ã¶ãŒãã¡ã¢ãªã«ã¢ã¯ã»ã¹ããæ©èœã¯å€æŽããããä»®æ³ãã·ã³ã®ã¡ã¢ãªãèªã¿åããšãä»®æ³ãã·ã³ã®æå·åãããããŒã¿ãééã£ãããŒã§åŸ©å·åããããããæ»æè ã«ã¡ãªããã¯ãããŸããã ããããææ°ã®ããã»ããµã«çµã¿èŸŒãŸããæè¡ã®éçºè ãå°ãããã®ã§ãã
ããã«ããŠãããã®ã¬ããŒãã®äž»ãªã¢ã€ãã¢ãšã¡ãã»ãŒãžã¯ãäžæã®æå·åããŒã䜿çšããæè¡ã¯ãã²ã¹ãä»®æ³ãã·ã³ããã®ç®¡çè ã®ãã€ããŒãã€ã¶ãŒã®åé¢ãä¿èšŒããªããšããããšã§ãã è¯ãäŸãšããŠããBlinded Random Block CorruptionãïŒBRBCïŒãšåŒã°ããæ°ããã¿ã€ãã®æ»æã瀺ãããŸãã ä»®æ³ãã·ã³äžã®äžæã®æå·åããŒã䜿çšããåãã·ããªãªã§ã¯ãã¯ã©ãŠããããã€ããŒã®ç®¡çè ãïŒä¿¡é ŒãããïŒãã€ããŒãã€ã¶ãŒã®æ©èœã䜿çšããŠã²ã¹ãä»®æ³ãã·ã³ïŒæå·åãããã¡ã¢ãªãžã®ã¢ã¯ã»ã¹ã¯èšããŸã§ããªãïŒã䜿çšãããŠãŒã¶ãŒããŒã¿ã®æ©å¯æ§ãå®å šã«äŸµå®³ããããšãã§ããŸãã ããã«å ããŠãä¿è·ãããä»®æ³ãã·ã³ã§å®è¡ãããŠããããã»ã¹ã®ç¹æš©ãé«ããããã«ãããŒã«å€ä»¥å€ã§ãæ»æè ã«ãã£ãŠå¹æçã«æ»æãããããšã瀺ããŸãã
ããããŸããã¡ã¢ãªã®æå·åèªäœããèªã¿åã/æžã蟌ã¿ã¡ã¢ãªæ©èœãæã€æ»æè ããã®å€å±€é²åŸ¡ã¡ã«ããºã ã§ã¯ãªãããšã瀺åããŠããŸãã ã¡ã¢ãªæå·åã¡ã«ããºã ã«èªèšŒã¡ã«ããºã ãå«ãŸããŠãããšãã»ãã¥ãªãã£ãåäžããŸãã
ã¡ã€ã³ãã©ãã¯
ã¡ã€ã³ãã©ãã¯ã®äž»èŠãªã¬ããŒãã«å ããŠãäžçäžã®ç 究è ããã®ã¬ããŒããèãããšãã§ããŸãã äŒããŸãïŒ
ã¹ããŒã«ãŒ-Egor KarbutovãšAlexey Pertsev
ããã«ãŒãšãã£ãããã
ã¬ããŒãã®èª¬æããŸããŸãªãµãŒãã¹ã®ãªã³ã©ã€ã³ãµããŒããã£ããã¯éåžžã«äžè¬çãªãã®ã§ãã ãããããµãŒãããŒãã£ã®ãœãªã¥ãŒã·ã§ã³ãšè£œåãã©ãã ãä¿¡é ŒããŠããŸããïŒ Pentesterã®çµéšãããªã³ã©ã€ã³ãã£ãããäŒæ¥ãåŸæ¥å¡ã顧客ãããã«ã¯ãã£ãããã³ããŒèªäœãžã®æ»æ察象é åãæ¡å€§ããæ¹æ³ãå ±æããããšèããŠããŸãã XSSããRCEãWebããã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ããã¹ã¯ããããŸã§ãããŸããŸãªãã©ãããã©ãŒã ã«å¯Ÿããç¹å®ã®æ»æãæ€èšããŠãã ããã æå°éã®ãã±ããç§åŠããã€ã¯ã«é¢ããç°¡åãªã¬ããŒããå®éã®ç¶æ³ããããŠãã³ããã®äºesteræã®ããªãã¯ã
ãã€ããªããäŒæ©ããŠãå®éã®ãã³ãã¹ãã±ãŒã¹ã«ã€ããŠåŠã³ãã人ã®ããã®å Žæã
ã¹ããŒã«ãŒ-Alexey Tyurin
HTTPSã«å¯ŸããMitMæ»æã®å¥ã®èŠæ¹
ã¬ããŒãã®èª¬æTLS / HTTPSã®ç®æšã¯ãMitMæ»æããä¿è·ããããšã§ãã ç§ãã¡ã¯ãæå·åã®èŠ³ç¹ããTLS / HTTPSãžã®æ»æãèŠãããšã«æ £ããŠããŸãã ãããŠãTLSã®åºæ¬çãªã¢ãŒããã¯ãã£ãœãªã¥ãŒã·ã§ã³ãèŠãŠã¿ãŸããïŒ ããšãã°ã蚌ææžèªèšŒã¯åã ã®ãã¹ããŸãã¯ããã«åºããã¹ãã®ã°ã«ãŒãã®ã¬ãã«ãŸã§ã®ã¿å¯èœã§ãããšããäºå®ã ãããŠãTLS / HTTPSã¯ç空ã®ããçš®ã®ãšã³ãã£ãã£ã§ã¯ãªããçŸä»£ã®ã·ã¹ãã ã¯ãã¯ãããžãŒããããã³ã«ã®ç¹ã亀ãã§ãããå€ãã®ãµãŒãã¹ã§æ§æãããŠããããšãæãåºããšãå°ããªããžãã¯ãšããªãã¯ãè¿œå ããŠãæåããMitMãå®è¡ããæ©äŒãåŸãŸãhttpsãžã®æ»æïŒ
ã¹ããŒã«ãŒ- ã€ã·ã«ã»ã¹ãã«ãã³ ã ãã©ã€ã¢ã³ã» ãŽã¬ã³ã ã ã¢ããã¥ã«ã»ã¢ãžãºã»ããªãª
ãã¹ãŠã®åã®ããã«ïŒVMwareã®RPCã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããŠæ¥œãã楜ãã
ã¬ããŒãã®èª¬æä»®æ³ãã·ã³ã¯ãææ°ã®ã³ã³ãã¥ãŒãã£ã³ã°ã·ã¹ãã ã§éèŠãªåœ¹å²ãæãããŸãã 圌ãã®å©ããåããŠãå€ãã®å Žåãåãç©çãµãŒããŒäžã®è€æ°ã®ã¯ã©ã€ã¢ã³ããåé¢ããŸãã ç 究è ãšã»ãã¥ãªãã£ã®å°é家ã¯ãä»®æ³ãã·ã³ã䜿çšããŠæœåšçã«å±éºãªã³ãŒããåé¢ããããã調ã¹ãŠåæããŸãã ä»®æ³ãã·ã³ã§å®è¡ããå Žåãæœåšçã«å±éºãªã³ãŒãã¯ä»ã®ã©ãã§ãå®è¡ã§ããªããšæ³å®ãããŠããŸãã ãã ãããã®æ¹æ³ã¯å®å šã«ä¿¡é Œã§ãããã®ã§ã¯ãããŸãããä»®æ³ãã·ã³ã®ãã€ããŒãã€ã¶ãŒã®è匱æ§ãã·ã¹ãã å šäœãžã®ã¢ã¯ã»ã¹ãéãå¯èœæ§ãããããã§ãã ãã®ã·ããªãªã¯ãã€ãŠã¯ä»®èª¬ã«éããªããšèããããŠããŸããããPwn2Own 2017ã«ã³ãã¡ã¬ã³ã¹ã§ã®2ã€ã®ç¬ç«ãããã¢ã³ã¹ãã¬ãŒã·ã§ã³ã«ããããããå¯èœã§ããããšã瀺ãããŸããã ãã®ã¬ããŒãã§ã¯ãVMwareã®ããŒãéã®é¢ä¿ã«ã€ããŠè©³ãã説æããŸãã ããã«ããã¬ãŒã³ããŒã·ã§ã³ã§ã¯RPCã€ã³ã¿ãŒãã§ã€ã¹ã®æ©èœã«ã€ããŠèª¬æããŸãã ã²ã¹ãOSããã¡ã€ã³OSã«éä¿¡ãããRPCèŠæ±ãèªåçã«ååãŸãã¯åæããæ¹æ³ã«ã€ããŠèª¬æããŸãã ãŸãããã¡ãžã³ã°ã®ããã«C ++ããã³Pythonã®RPCã€ã³ã¿ãŒãã§ã€ã¹ã«ãªã¯ãšã¹ããéä¿¡ããããã®ããŒã«ãäœæããæ¹æ³ã瀺ããŸãã æåŸã«ãä¿®æ£ãããè匱æ§ãé çªã«èª¿ã¹ãããšã«ãããVMwareã®Use-After-Freeãªã©ã®è匱æ§ãæªçšããæ¹æ³ã瀺ããŸãã
ã¹ããŒã«ãŒ-Matt Ou
æè¿ã®ãšã¯ã¹ããã€ãã®åŸåã察çãããã³æ€åºæŠè¡
ã¬ããŒãã®èª¬æé«ã¬ãã«ã®æ»æ察çããŒã«ãã·ã¹ãã ã«å°å ¥ããããšãæ»æè ã¯åŸæ¥ã®æªçšæ¹æ³ããé¢ããå¿ èŠããããŸãã ããã¯Windows 10ã®ãªãªãŒã¹ã§çºçããŸãããControlFlow GuardïŒCFGïŒãªã©ã®æ»æé²æ¢æè¡ã®ææ°ã®æŽæ°ã«ãããé¢æ°ãã€ã³ã¿ãŒãæžãæããŠã³ãŒããå®è¡ããåŸæ¥ã®æ¹æ³ã¯åçŽã«æ代é ãã«ãªããŸããã ãã®ãããWindows 10ã®ãšã¯ã¹ããã€ãéçºã«ã¯3ã€ã®äž»ãªåŸåããããŸãã
ã¡ã¢ãªã®å®å šãªæŠèŠãååŸããããã®èªã¿åã/æžã蟌ã¿ããªããã£ãã®ãã³ãã
è«ççãªè匱æ§ãšãã®æªçšãæ€çŽ¢ããŸãã
ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã䜿çšããŠæªæã®ããã³ãŒããå®è¡ããã
ã¹ããŒã«ãŒ- ã¢ã¬ãã¯ã¹ããããœã
BIOSãè£åãïŒBIOSã¬ãŒãã®äœãåé¡ãªã®ã
ã¬ããŒãã®èª¬æãã®ãã¬ãŒã³ããŒã·ã§ã³ã¯ãæ©åšã®ãµãã©ã€ã€ãBIOSã»ãã¥ãªãã£ç 究è ãã»ãã¥ãªãã£å°é家ãããã³çŸåšã®UEFIã®ç 究ãšæ€åºãããè åšã«ã€ããŠç¥ãããäžçŽã®ââå©å®³é¢ä¿è ãžã®ã·ã°ãã«ãšãªãããšãç®çãšããŠããŸãã ç¶æ³ã¯æ·±å»ã§ãããé©åãªããŒã«ãšç¥èãããã°ãåã¡ãŸãã è¿å¹ŽãUEFIãã¡ãŒã ãŠã§ã¢ã®ã»ãã¥ãªãã£ç¶æ³ã¯ãŸããŸãéèŠã«ãªã£ãŠããŸãã äžæ¹ã§ã¯ãISç 究è ã®ã³ãã¥ããã£ã®äžéšã§æŽ»åãå¢å ããŸããã äžæ¹ãUEFIã®ã€ã³ãã©ã³ãã«é¢ããæ å ±ã¯ãŸããŸãå¢ããŠããŸããããšãã°ããããã¯HackingTeamããã®å·ãæ¯æŽããã€ã³ãã©ã³ãã§ãã ã»ãšãã©ã®å Žåãæ å ±ã¯ãªãŒã¯ã®ããã«å ¬éãããŸããããã¯ãUEFIã®ã€ã³ãã©ã³ããæ€åºããæ段ããªããã€ã³ãã©ã³ãèªäœãæšçåæ»æã«äœ¿çšãããããã§ãã
è¿å¹ŽãUEFIã®äžçã§ã®åœ¹å²ã¯å€§å¹ ã«æ¡å€§ããŠããŸãããã¡ãŒã ãŠã§ã¢ã¯ã³ã³ãã¥ãŒã¿ãŒãã©ããããããã¹ããŒãããã€ã¹ãè»ããããŒã³ãªã©ã§äœ¿çšãããŠããŸãã 幞ããªããšã«ãUEFIã»ãã¥ãªãã£ãå€ãã®ç¹ã§æ¹åãããŠããŸãã äŒæ¥åãã®æ©åšã®ææ°ã®ãµãã©ã€ã€ã瀺ãã»ãã¥ãªãã£ã¬ãã«ã¯å€§å¹ ã«åäžããŠããŸãã ãã ãããã¹ãŠã®ãµãã©ã€ã€ãŒãåããšããããã§ã¯ãããŸããã æ®å¿µãªããããããã®ããã€ãã¯ææ°ã®ããŒããŠã§ã¢ä¿è·ã䜿çšããŠããŸãããããšãã°ãIntelã¯äœå¹Žãåã«SMMããã³SPIïŒBLEãBWEãPRxïŒã®ä¿è·ããããå°å ¥ããŸããã ããŒããŠã§ã¢ã¬ãã«ã§ã¯ã¢ã¯ãã£ããªã¡ã¢ãªä¿è·ããªãããããããã®ã¡ãŒã«ãŒã®ããã€ã¹ã¯æ»æè ã«ãšã£ãŠç°¡åãªæšçã«ãªãã€ã€ãããŸãã ä»å¹Žã®Black Hat Asiaã§ã®è¬æŒã§ã¯ãSPIã䜿çšããŠæ°žç¶çãªã«ãŒããããããã©ãã·ã¥ã¡ã¢ãªã«ã€ã³ã¹ããŒã«ããããšã«ããããããã®è匱æ§ã瀺ããŸããïŒMicrosoft Windows 10ããã³ã¢ã¯ãã£ãã»ãã¥ã¢ããŒããå®è¡ããŠããã³ã³ãã¥ãŒã¿ãŒäžïŒã
ãã ããIntelãªã©ã®ããŒããŠã§ã¢ã¡ãŒã«ãŒã¯ãBoot GuardïŒHaswell以éïŒãBIOS GuardïŒSkylake以éïŒãªã©ã®ã»ãã¥ãªãã£ãã¯ãããžãŒãå°å ¥ããŠããŸãã ãã©ãããã©ãŒã ãèµ·åãããšãããŒãã¬ãŒãã¯ãã»ãã¥ã¢ããŒãã®ä¿¡é Œã§ããã³ã³ããŒãã³ãã®ãªã¹ãã«UEFIãå«ãŸããŠãããã©ããã確èªãããã¡ãŒã ãŠã§ã¢ã䜿çšããæ»æããUEFIãä¿è·ããŸãã BIOS Guardãã¢ã¯ãã£ãã«ãããšãä¿è·ãããã¢ãžã¥ãŒã«ã®ã¿ãSPIã䜿çšããŠãã©ãã·ã¥ã¡ã¢ãªãå€æŽã§ããæ°žç¶çãªã€ã³ãã©ã³ãããä¿è·ããŸãã äž¡æ¹ã®ãã¯ãããžãŒã¯ãACMïŒAuthenticated Code ModuleïŒãšããŠç¥ãããå¥åã®ããã»ããµãŒã§å®è¡ãããäŸµå ¥è ããããããåé¢ãã競åç¶æ ã§ã®æ»æããä¿è·ããŸãã ãã®ãããªé²åŸ¡æè¡ã¯ãUEFIã«ãŒãããããã©ãŒãšåŒã°ããããšããããŸãã ãããã®ãã¯ãããžãŒã«é¢ãã詳现æ å ±ã¯ãããŸããã
ãã®ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ãSkylakeãKaby Lakeãªã©ã®ææ°ã®Intelããã»ããµãæèŒããæ©åšã§äœ¿çšããå ·äœçãªå¯èœæ§ã«ã€ããŠèª¬æããŸãã å©çšå¯èœãªæ å ±ã®ã»ãšãã©ã¯ããªããŒã¹ãšã³ãžãã¢ãªã³ã°ã䜿çšããŠUEFIãã¡ãŒã ãŠã§ã¢ã¢ãžã¥ãŒã«ããååŸãããŸããã ãããã®ã¢ãžã¥ãŒã«ïŒDXEããã³PEIïŒã¯ãACMã³ãŒãã䜿çšããŠéå§ãæ§æãããã³ã€ã³ã¹ããŒã«ã§ããŸãã ããã«ãã¬ããŒãã§ã¯ããã®ãããªä¿è·æè¡ã®åŒ±ç¹ã«ã€ããŠè§ŠããŸãã BIOSã¬ãŒãã®äœãåé¡ã«ãªã£ãŠããŸããïŒ ãã®ãããªä¿è·ãåé¿ãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããæ°žç¶çãªã«ãŒãããããã€ã³ã¹ããŒã«ããããšã¯ã©ãã»ã©å°é£ã§ããïŒ ã¬ããŒãã§ãããã®è³ªåã«å¯ŸããåçãåãåããŸãã
ã¹ããŒã«ãŒ-Ralph-Philippe Weinmann
ARMããŒããŠã§ã¢ãã¬ãŒã¹
ã¬ããŒãã®èª¬æéã«ãããã¬ãŒã¹ã¯ãäžèŠãªãªãœãŒã¹ã³ã¹ãããããã«ãã·ã¹ãã å šäœã®ã«ãã¬ããžæ å ±ããªã¢ã«ã¿ã€ã ã§ååŸããããã®åŒ·åãªããŒã«ã§ãã ARM CoreSightã¢ãŒããã¯ãã£ã«ã¯ãEmbedded Trace Macrocellãã¯ãããžãå«ãŸããŠããŸããããã«ãããJTAGã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠãã¬ãŒã¹ã«ã¢ã¯ã»ã¹ããETMããŒããä»ããŠãšã¯ã¹ããŒããããœãããŠã§ã¢ã®ã¿ã§å®è¡ããããã«åããã°ã©ã ãããªã³ã°ãããã¡ã«ä¿åã§ããŸãã LinuxããŒãžã§ã³4.9以éã§ã¯ãARM CoreSightãããã©ãŒãã³ã¹ãµãã·ã¹ãã ã§ãµããŒããããŠãããããè¿œå èšå®ãªãã§ETMããŒã¹ã®ãã¬ãŒã¹ã䜿çšã§ããŸãã ãã ããä»ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã䜿çšããã«ã¯ãäœã¬ãã«ã®ããã°ã©ãã³ã°ãå¿ èŠã§ãã ãã®ã¬ããŒãã§ã¯ãARMv7ããã³ARMv8ã¢ãŒããã¯ãã£ã«åºã¥ãã·ã¹ãã ã§ã®ETMããŒã¹ã®ããã°ã©ã å®è¡ã®ãã¬ãŒãµããªãã£ã®å¯çšæ§ã«ã€ããŠèª¬æããŸãããŸãããœãããŠã§ã¢ãã¬ãŒã¹ãåå¥ã«æ§æããã³ãŒãã«ãã¬ããžæ å ±ã䜿çšããŠãã¡ã¶ãŒå¹çãé«ããæ¹æ³ã«ã€ããŠã説æããŸãã
ã¹ããŒã«ãŒ- ãžã§ã³ã»ãã³ã©ãã
Fence LeapïŒæ¢åã®JMPé·ç§»æåããã°ã©ãã³ã°ããŒã«ã®æ¯èŒãšå¯èœãªæ¹å
ã¬ããŒãã®èª¬æãã®ã¬ããŒãã§ã¯ãã¹ããŒã«ãŒãäœæããJOPæ»æçšããŒã«ïŒãžã£ã³ãæåããã°ã©ãã³ã°ïŒã瀺ããŸãã ä»®æ³ãã·ã³ã䜿çšããŠJumpããã€ã¹ããã¹ãããæ¹æ³ã説æããå¶éææ³ã䜿çšããŠãšã¯ã¹ããã€ããéçºããã®ã«åœ¹ç«ã€ããŒã«ã瀺ããŸãã
ã¹ããŒã«ãŒ-Tanxiang LiïŒDragonltxïŒããã³Jiashui WangïŒQuheïŒ
ã¹ããŒãããã€ã¹ã§ã®ãªã¢ãŒãã³ãŒãå®è¡ïŒ
ã¬ããŒãã®èª¬æã¹ããŒãããã€ã¹ã®æ°ã¯æ¯æ¥å¢å ããŠãããããã«ã¯ã»ãã¥ãªãã£ãžã®æ³šæãé«ããå¿ èŠããããŸãã ããã«ãŒã¯ããªã¢ãŒãã®æ»æ察象ã«æãæ¹ãããŸãã Zerodiumã¯Bug Bountyããã°ã©ã ãæŽæ°ããWeChatãViberãFB Messengerãªã©ã®ããã°ã©ã ããªã¹ãã«è¿œå ããŸããã ãããã®ã¢ããªã±ãŒã·ã§ã³ã§ãªã¢ãŒãã³ãŒãå®è¡ãå¯èœã«ããè匱æ§ã«ã€ããŠã¯ãæ倧500,000ãã«ãæ¯æãæºåãã§ããŠããŸãã
ãã®ã¬ããŒãã§ã¯ãAndroidã¢ããªã±ãŒã·ã§ã³ãšã¹ããŒããã©ã³ãããã³ã¹ããŒãããã€ã¹ã«å¯Ÿãããªã¢ãŒãæ»æã®è¡šé¢ãåæããŸãã 次ã«ããªã¢ãŒãæ»æãå®è£ ããããã®å€ãã®éèŠãªè匱æ§ã詳ããèŠãŠãããŸãã ãã®äžã«ã¯ããªã¢ãŒãã³ãŒãã®å®è¡ãã¹ããŒããã©ã³ã®å¶åŸ¡ã®ãªã¢ãŒãã€ã³ã¿ãŒã»ãããã¹ããŒãããã€ã¹ã®å®å šãªå¶åŸ¡ã®ååŸãªã©ããããŸãã ãªãŒãã³ããŒãã®è匱æ§ãéããŠããã€ã¹ãå¶åŸ¡ãããã«ãããã³ã«ã®è匱æ§ãéããŠã³ãŒããéãã«å®è¡ããããšãã§ããŸãã
ã¹ããŒã«ãŒ-Stefan Gerling
çé¢ã®æªå€¢
ã¬ããŒãã®èª¬æé»æ°æ©æ¢°åŒããã¯ã«ã€ããŠè©³ãã説æããŸãã ãã®ãããªããã¯ãã©ã®ããã«æ©èœããããç°ãªãã¡ãŒã«ãŒã®ãã¯ãããžãŒã®éãã¯äœããåŠã³ãŸãã 確èªåŸãããã¯ã®åäœã®åçãããã«è©³ãã調ã¹ãŸãã 次ã«ãRFIDéä¿¡æ©ãšäººå·¥çã«äœæãããç°å¢ã䜿çšããŠ1ã€ã®ããã¯ãéããŸãã ã¡ãã£ãšåŸ ã£ãŠ ç°¡åãããã å€ãã®äººããã§ã«ããããŠããŸãã æå¹ãªRFIDãã©ã³ã¹ããã¿ãŒãªãã§ããã¯ãéãæ¹æ³ãããã³ãããå¯èœãªçç±ãšé©åãªããŒã«ã®å ¥æå ã«ã€ããŠèª¬æããŸãã ãªã¹ããŒã¯ãè¯ãåãã©ãã§èŠã€ããããèŠã€ããŸãã å®å šãªããã€ã¹ãšèå¥ã®äŸã瀺ããŸãã
ã¹ããŒã«ãŒ- ã°ãšã³ã»ã¢ã³ã»ã¯ã€ã³
ãã€ããªãã¡ã€ã«ã®ã«ãã¬ããžã«åºã¥ãããã£ãŒãããã¯ãåããææ°ã®ãã¡ã¶ãŒã®äœæ
ã¬ããŒãã®èª¬æã³ãŒãã«ãã¬ããžã®åœ¢åŒã§ã®ãã£ãŒãããã¯ã«ãããã¡ãžã³ã°ã¯ããœãããŠã§ã¢ã®è匱æ§ãæ€åºããããã«åºã䜿çšãããŠããæ°ããæ¹æ³ã§ãã ãã®æ¹æ³ã¯ãã§ã«é«ãå¹æã瀺ããŠããŸãã ãã®çš®ã®ãã¡ã¶ãŒã¯ãã€ã³ã¹ãã«ã¡ã³ãããããã€ããªã§åäœãããããå®è¡æã«åéãããã³ãŒãã«ãã¬ããžæ å ±ã䜿çšããŠå ¥åããŒã¿ãå€æŽããã³ãŒãã«ãã¬ããžãæ倧åã§ããŸãã
ãã ããã»ãšãã©ã®ã«ãã¬ããžããŒã¹ã®ãã¡ã¶ãŒã®åºç€ã¯ããœãŒã¹ã³ãŒãã®ã€ã³ã¹ãã«ã¡ã³ããŒã·ã§ã³ã§ãã å€ãã®éåžžã«éèŠãªãœãããŠã§ã¢ããã€ããªåœ¢åŒã§ã®ã¿å©çšå¯èœãªWindowsã®äžçã«ããã®æ¹æ³ã移æ€ããããã«å€å€§ãªåªåãæãããŠããŸãã æ®å¿µãªãããææ°ã®Windowsãœãªã¥ãŒã·ã§ã³ã¯ãã¹ãŠãè匱æ§ãå¹æçã«æ€çŽ¢ããèœåãéãããŠããŸãã ãã®æ¬ ç¹ã«ã¯ãããã©ãŒãã³ã¹ã®äœäžããç¹å¥ãªããã»ããµãšææ°ããŒãžã§ã³ã®OSã䜿çšããå¿ èŠãããããšãå«ãŸããŸãã
ãããã°æ å ±ãå«ãå®éã®ãã€ããªãã¡ã€ã«ã»ããçšã®æ°ãããã¡ã¶ãŒã§ããDarkoã玹ä»ããŸãã ããã«ã¯ããã€ãã®åŠå®ã§ããªãå©ç¹ããããŸãã
巚倧ãªé床ïŒããã©ãŒãã³ã¹ãã¹ãã¯ããã¡ã¶ãŒãæ¢åã®ãœãªã¥ãŒã·ã§ã³ãããã¯ããã«é«éã§ããããšã瀺ããŠããŸãã
ã€ã³ããªãžã§ã³ã¹ïŒDarkoã¯ãéçåæãšã¿ã°ä»ãããŒã¿ã®åæãçµã¿åãããŠãã«ãã¬ããžãå€§å¹ ã«æ¡å€§ããè匱ãªã³ãŒãããã°ããèŠã€ããããšãã§ããŸãã
ãœãããŠã§ã¢ã³ã³ããŒãã³ãã®ã¿ã«åºã¥ããŠããŸãããã¡ã¶ãŒã¯ææ°ã®ããã»ããµã¢ãã«ãOSããŒãžã§ã³ãå¿ èŠãšããŸããã ãããã£ãŠãDarkoã¯ãä»®æ³ãã·ã³å ãå«ããã©ãã«ã§ãå±éã§ããŸãã
æåŸã«ãªããŸãããã åœç€Ÿã®ãœãªã¥ãŒã·ã§ã³ã¯ãWindowsã ãã§ãªãããã©ãããã©ãŒã ãšã¢ãŒããã¯ãã£ãè¶ ããŠæ©èœããŸãã Darkoã¯ãäžè¬çãªãã¹ãŠã®OSããã³ããã»ããµã¢ãã«ïŒX86ãX86_64ãARMãARM64ãMipsãPPCãSparcã®WindowsãLinuxãMacOSã* BSDãªã©ïŒããµããŒãããŠããŸãã
ãã®è¬æŒã§ã¯ãã«ãã¬ããžã«åºã¥ãããã£ãŒãããã¯ã«ãããã¡ãžã³ã°ã«ã€ããŠå°ã説æãããœãªã¥ãŒã·ã§ã³ãæ±ããåé¡ã«çŠç¹ãåœãŠãŸãã 次ã«ããããã®åé¡ãå æããããã«ãã£ãŒãããã¯ä»ãã®ãã¡ã¶ãŒãäœæããæ¹æ³ã説æããŸãã æåŸã«ãDarkoã®æå¹æ§ã瀺ãããã«ãCVEã«ç»é²ãããŠããè匱æ§ã®ãªã¹ãã衚瀺ãããŸãã ãŸããããã€ãã®ã¯ãŒã«ãªãã¢ããããŸãã
ã¹ããŒã«ãŒ- ã»ã«ã²ã€ ã»ãã ãã³ããšãŠã©ãžããŒã«ã»ãã·ã¥ãã§ã³ã³
è匱æ§ãšããã¯ãã¢ã®ãéã®åŒŸäžžãã å°ããªããŒã¯ã³ã§3äžäººä»¥äžã®ãµãã©ã€ã€ãŒãæ¢ããŸããã
ã¬ããŒãã®èª¬æãã®ã¬ããŒãã§ã¯ã人æ°ã®ããã©ã€ã»ã³ã¹ç®¡çããŒã«ã§ããããŒã¯ã³ã®ããŸããŸãªæ·±å»ãªè匱æ§ã«å¯ŸåŠããã«ã¹ãã«ã¹ããŒã®éèŠãªã€ã³ãã©ã¹ãã©ã¯ãã£ä¿è·ããŒã ã«ããææ°ã®ç 究ã«ã€ããŠèª¬æããŸãã 15ã®è匱æ§ãèŠã€ãããŸããããªã¢ãŒãã³ãŒãå®è¡ã®ããã€ããDoSã®å€ãã®è匱æ§ãããã³ãœãããŠã§ã¢ããžãã¯ã®å¥åŠãªæ©èœã®1ã€ã§ãã ãã³ããŒã¯ããããææžåãããŠããªãæ©èœããšåŒã¶ããšãæåŠãããããã¯äžè¬çãªè匱æ§ã§ãããšäž»åŒµããŸããã ãã®ã¬ããŒãã§ã¯ãäžè¬çãªã©ã€ã»ã³ã¹ããŒã¯ã³ã®è匱æ§ãšå¥åŠãªæ©èœã«é¢ããæè¡æ å ±ãæäŸããããšæããŸãã
ã¹ããŒã«ãŒ-Ido NaorãšAmihai Neiderman
ã¬ãœãªã³ã®äŸ¡æ Œãé«ãããŸãïŒ ç¡æã«ããŸãããã
ã¬ããŒãã®èª¬æãã®ã¬ããŒãã§ã¯ãããªãŒããšçæèšéã®äžçã«è¡ããŸãã ç©èªã¯ãæã ãç¡æã®ã¬ãœãªã³ãæã«å ¥ãããããã«ãŒã2人ããããšããèšèããå§ãŸããŸãã è¬æŒã«æ¥ãŠãããã€ãã®ãšã¯ã¹ããã€ãã䜿çšããŠãªã¢ãŒãã§ã¬ãœãªã³ã¹ã¿ã³ãã®å¶åŸ¡ãååŸããéèŠãªããŒã¿ãšæš©å©ã«ã¢ã¯ã»ã¹ããæ¹æ³ã確èªããŠãã ããã ãšãŠãç°¡åã§ããã
ã¹ããŒã«ãŒ- ããã¯ã¹ãŠã§ã«ã³ãããšããŒã¹ãªãŒ
ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãªãã®2èŠçŽ èªèšŒã®ããã®2FAãã€ãã¹ãšIDçé£ã 2FAssassinã®ãã¬ãŒã³ããŒã·ã§ã³ã
ã¬ããŒãã®èª¬æäºèŠçŽ èªèšŒã®æå¹æ§ã¯ããŠãŒã¶ãŒããèªåã ããæã£ãŠãããã®ããã©ãã ãä¿è·ãããã«ããã£ãŠããŸãã ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ãªãã§ç§å¯éµãçãæ¹æ³ãããå Žåã¯ã©ããªããŸããïŒ ãã®ã¬ããŒãã§ã¯ã2èŠçŽ èªèšŒãåé¿ããããã®ææ³ã瀺ããŸãã å®å šãªãµã€ãã§èªèšŒããããã«æ»æè ãã¯ã©ã€ã¢ã³ã蚌ææžãšç§å¯éµãçãæ¹æ³ã®å®äŸãšãçµæã®å¯èœãªèŠæš¡ã瀺ããŸãããã ããã«ãè匱æ§ãæªçšããŠç¬èªã®ããŒã«ïŒ2FAssassinïŒãå°å ¥ããç§å¯éµã®æŒæŽ©ãåŒãèµ·ããããã®åŸããããã¯ãŒã¯å šäœãæ¯æŽããŠäŸµå®³ããŸãã ã¬ããŒãã®æåŸã«ãç§å¯ããŒãçé£ããä¿è·ããæ¹æ³ã«é¢ããæšå¥šäºé ãšãææªã®ã·ããªãªãçºçããå Žåã®ãã³ãã瀺ããŸãã
ã¹ããŒã«ãŒ-Alexey Pertsev
äŸµå ¥è©Šéšæ©çšã®DAO
ã¬ããŒãã®èª¬æç§ãã¡ã¯æå·é貚ããŒã ã®äžçã«äœãã§ããŸãã ã¹ããŒãã³ã³ãã©ã¯ããICOãDAOãããã³çµæžã®å°æ¥ã«é¢ãã倧ããªãã€ãºã ããããã¹ãŠããããããšã¯ãèšãã«ã¯æ©ãããŸãã ããããæ»æè ã®ç®ãéããŠãããã©ã®ããã«èŠããå©çãåŸãããã«ã©ãã§åªåããããšãã§ããããèæ ®ããããã«ãããã¯ééããªãå¯èœã§ã
ã¹ããŒã«ãŒ- ãã³ã©ã€ã»ã³ãªã³ãã§ããšããã€ã«ã»ãµãã«ã
60ç§ã§æ¶ããŸã
ã¬ããŒãã®èª¬æäŒè°ã§ã¯ãçŸä»£ã®èªåè»ã®è匱æ§ã«ã€ããŠè©±ããŸãã ã©ã€ãã¢ãŒãã§ã¯ã以äžã衚瀺ããŸãã
CANãã¹ãä»ããè»äž¡å¶åŸ¡ã®ååããã¹ãžã®æ¥ç¶ãããŒã¿è»¢éãããã³ã«ã®åºæ¬ãåœã®ã³ãã³ããå¶åŸ¡ãŠãããã®ã·ãã¥ã¬ãŒã·ã§ã³ãå¶åŸ¡ãŠãããã®åäœã¢ãŒãã
CANãã¹çµç±ã§è»ã«ã¢ã¯ã»ã¹ããã³ã³ãããŒã«ãŠãããã«åœ±é¿ãäžããéåžžã®ã€ã¢ãã©ã€ã¶ãŒãããŸããã
LINãã¹ãä»ããå¶åŸ¡ãŠããããžã®åœ±é¿ããã¹ãžã®æ¥ç¶ãããŒã¿è»¢éãããã³ã«ã®åºæ¬ãå¶åŸ¡ãŠãããã®èŠæ±ãšå¿çã®æ¹ããã
GSMã¢ã©ãŒã ãä»ããCANããã³LINãã¹ãžã®ã¢ã¯ã»ã¹ãããŒããŠã§ã¢ããã¯ããŒã¯ãšããŠã®ã¢ã©ãŒã ã®äœ¿çšãè»ãæ»æããããã®ã·ã°ããªã³ã°è匱æ§ã®äœ¿çšã
ERA Glonassããã€ã¹ãä»ããCANããã³LINãã¹ãžã®ã¢ã¯ã»ã¹ãäºæ ã®å Žåã®ããŒããŠã§ã¢ããã¯ããŒã¯ãšããŠã®ç·æ¥å¯Ÿå¿ã·ã¹ãã ã®äœ¿çšãè»ãæ»æããããã®è匱æ§ã®äœ¿çšã
BlueToothæ¥ç¶æºåž¯é»è©±ã䜿çšããæšæºãã«ãã¡ãã£ã¢ã·ã¹ãã ãä»ããCANããã³LINãã¹ãžã®ã¢ã¯ã»ã¹ãã¢ãã€ã«ããã€ã¹èªäœãžã®ãªã¢ãŒãã¢ã¯ã»ã¹ã®åä¿¡ãBlueToothæ¥ç¶æºåž¯é»è©±ãä»ããŠå¶åŸ¡ãããããŒããŠã§ã¢ããã¯ããŒã¯ãšããŠæ©èœãããã«ãã¡ãã£ã¢ã·ã¹ãã ã®åæ§æ
ã¯ã€ã€ã¬ã¹æšæºGSMããã³WiFiãè£ åããæšæºãã«ãã¡ãã£ã¢ã·ã¹ãã ãè»å ã®ã¯ã€ã€ã¬ã¹ã·ã¹ãã ãžã®å€éšæ¥ç¶ãããã³è»ãæ»æããããã®ããŒããŠã§ã¢ããã¯ããŒã¯ãšããŠã®ãã«ãã¡ãã£ã¢ã®äœ¿çšãä»ããCANããã³LINãã¹ãžã®ã¢ã¯ã»ã¹ã
MOSTãªããã£ã«ã«ãã¹ããã®éèŠãªæ å ±ã®ååã客宀ã®é³ã®èãåãã座æšã®ååŸãè»ãšãã®ãã©ã€ããŒã®ã¹ãã€;
å®éã®ã³ã³ãããŒã«ãŠãããã§ã®ããŒããŠã§ã¢ããã¯ããŒã¯ã®ã·ãã¥ã¬ãŒã·ã§ã³ãããã°ã©ã ããã¯ããŒã¯ãšããŠæ©èœããã³ã³ãããŒã«ãŠãããã®ãã«ãŠã§ã¢ã®å°å ¥ã«ããå®éã®ã³ã³ãããŒã«ãŠãããã®ç¹æ» ã
ãããã®è åšã®ããã€ããå®éã®è»ïŒè»ã®çé£ããšã¢ããã°ã®ççºïŒã«å®è£ ãããããšãå®èšŒãããŸãã
ã¹ããŒã«ãŒ- ãžã§ãŒã ã¹ã»ãªãŒ
IE11ã®ActiveXã³ã³ãããŒã«ã«ãŒããã€è匱æ§ãããã²ãŒã
ã¬ããŒãã®èª¬æActiveXãã¯ãããžãŒã䜿çšãããšãå€éšãªããžã§ã¯ããå®è£ ã§ããŸãã ããã¯ããã©ãŠã¶ã®èªçããã»ãšãã©Internet Explorerã§å°å ¥ãããŸããã ãã®ãã¯ãããžãŒãæ€èšããäœæ¥äžã«ã©ã®ããã«è匱æ§ãçºèŠããããåæããŸãã
ã¹ããŒã«ãŒ- ã«ãŒã«ã¹ã¢ã
Skynetãžã®ããããã®ãããã³ã°
ã¬ããŒãã®èª¬æãããããäž»æµã«ãªãã€ã€ãããŸãã è¿ãå°æ¥ãè»ã®ä»»åãæè¡å®€ãé«å±€ãã«ã®å»ºèšãååºãç é¢ãåæ¥äŒç€Ÿãããããã¹ããŒãã家æã®å€ã¹ãªã©ãã©ãã«ã§ãããã§ãããã
ããããã®ãšã³ã·ã¹ãã ã¯æé·ããŠããã人ã ã瀟äŒãçµæžã®ç掻ããŸããŸãå€åãããŠããŸãã åæã«ãå®å šã§ãªãæè¡ã䜿çšããããšã人ã ãåç©ãçµç¹ã«æ·±å»ãªè åšãããããå¯èœæ§ããããŸãã æ»æè ãããããã®è匱æ§ãå©çšããå Žåã圌ã®ç©ççèœåã䜿çšããŠãè³ç£ã®æå·ãäŒæ¥ãžã®è³éæäŸããŸãã¯äººã ã®ç掻ãè ããç¶æ³ãäœãåºãããšãã§ããŸãã å®éãããããã¯è ãèãè»èŒªãåããã³ã³ãã¥ãŒã¿ãŒã§ãããããç°å¢ã«å¯Ÿããæœåšçãªè åšã¯ææ°é¢æ°çã«å¢å ãããã®ãããªè åšã®ãã¯ãã«ã¯ã³ã³ãã¥ãŒã¿ãŒã®ã»ãã¥ãªãã£ã§ãããŸã§è©³çŽ°ã«èæ ®ãããŠããŸããã§ããã
æè¿ã®èª¿æ»ã§ã¯ãæåãªã¡ãŒã«ãŒã®å®¶åºçšããã³ç£æ¥çšå ±æããããã«ããã€ãã®é倧ãªè匱æ§ãèŠã€ãããŸããã ãã¹ãŠã®èª¿æ»çµæãéçºè ã«åŒãæž¡ããŸããã次ã«ãå®çšçãªãšã¯ã¹ããã€ãã䜿çšããŠãããããã®ãšã³ã·ã¹ãã ã®ããŸããŸãªã³ã³ããŒãã³ãã䟵害ããæè¡çãªè©³çŽ°ãè åšãããã³æ¹æ³ãæããã«ããŸãã ã©ã€ããã¢ã³ã¹ãã¬ãŒã·ã§ã³ã§ã¯ããµã€ããŒã¹ãã€ãå±éºãªå éšè åšãç©çæ害ãªã©ãååšããããŸããŸãªæªçšã·ããªãªã瀺ããŸãã
çŸå®çãªã·ããªãªã䜿çšããŠãçŸä»£ã®ãããããã¯ãããžãŒã®å±éºæ§ãšããããã³ã°ããããããããä»ã®è匱ãªãã¯ãããžãŒãããå±éºãªçç±ã«ã€ããŠèª¬æããŸãã ç§ãã¡ã®ç®æšã¯ããããããããå®å šã«ããäŒæ¥ã顧客ãããã³ãã®åšèŸºã«æ·±å»ãªæ害ãäžããå¯èœæ§ã®ããè匱æ§ã®æªçšãé²ãããšã§ãã
ã¹ããŒã«ãŒ-Nicholas Alejandro Economow
GDIã䜿çšããŠring0ããªããã£ãã§æªæã®ããã³ãŒããå®è¡ããïŒåèµ·å
ã¬ããŒãã®èª¬æWindowsã«ãŒãã«ãæ»æã«äœ¿çšããææ°ã®æè¡ã®é²åã«ããããã³ããŒã¯ãChromeãEdgeãFirefoxãããã³ææ°ããŒãžã§ã³ã®Officeã§ãµã³ãããã¯ã¹ã䜿çšãããªã©ãæªçšãããœãããŠã§ã¢ãä¿è·ããããã®å€å€§ãªåªåãäœåãªããããŠããŸãã
åæã«ãMicrosoftã¯Windowsã«ãŒãã«ãç¹ã«Windows 10ã«ãŒãã«ãä¿è·ããããã®åãçµã¿ã匷åããåæ°ããŒãžã§ã³ã«ãšã¯ã¹ããã€ãã«å¯ŸããéèŠãªä¿è·ãè¿œå ããŸããïŒæãå®å šã«Anniversary and Creators Updateã§ïŒã 2015幎ã«ã¯ããããã³ã°ããŒã ãšã®ããç¥ãããäºä»¶ã®çµæãšããŠãGDIãªããžã§ã¯ãã䜿çšããããã®æ°ããææ³ã§ã«ãŒãã«ã®ãšã¯ã¹ããã€ãããªãŒã¯ãããŸããã
Windows 10 Anniversary UpdateïŒRS1ïŒã®ç»å Žã«ããããã®ãã¯ãããžãŒã®äžéšã¯ç¡å¹åãããŸããã 1幎åŸãåãã¬ããŒãã®2çªç®ã®ããŒãžã§ã³ã§ãGDIãªããžã§ã¯ãã䜿çšããããã®æ°ããææ³ã玹ä»ãããŸããã ä»å¹Ž4æãWindows 10 Creators UpdateïŒRS2ïŒã®ãªãªãŒã¹ã«ããããã®ææ³ã®å¥ã®éšåãç¡å¹åãããŸããã ãã®è匱æ§ãä¿®æ£ãããã€ã¯ããœããã®åªåã«ãããããããGDIãªããžã§ã¯ãã䜿çšããããã®ææ°ã®æè¡ã¯ãAnniversary UpdateïŒRS1ïŒããåã®ä»¥åã®ããŒãžã§ã³ãšåæ§ã«å¹æçã§ãã
æ°ãããã¬ãŒã³ããŒã·ã§ã³ã§ã¯ããããã®ææ³ã䜿çšããŠWindows 10 Fall Creators Updateã§ã³ãŒããå®è¡ããä¿¡é Œã§ããæ¹æ³ã«ã€ããŠèª¬æããŸãã æåŸã«ã説æããææ³ã䜿çšããŠMicrosoft Edgeãµã³ãããã¯ã¹ããæãåºãæ¹æ³ã瀺ããŸãã
ã¹ããŒã«ãŒ- ãžã§ãŒã ãºã»ãã©ãŒã·ã§ãŒ
ã¢ã¯ã»ã¹ããŒã¯ã³ã䜿çšããŠUACã·ã¹ãã ããã€ãã¹ãã
ã¬ããŒãã®èª¬æ(UAC), , Admin-Approval, , Windows Vista. UAC , . , UAC - , Microsoft , . , , , . , Microsoft Windows 10 . , , Over-The-Shoulder Windows 10.
Fast Track
Fast Track, 15 , , .
â
, , . , , . (CVSS 10) TrendMicro DDEI ( 7 2017 ), .
â
Meterpreter DNS-
DEF CON RUSSIA (DC#7812) Meterpreter. Meterpreter DNS-. ( ) . ( ).
â
callback-
callback-.
â
Heartbleed: MITM
, - ? , Heartbleed. : , , . , MITM. , . ; , ; , , «».
â
!
, , . . , . hashcat «» .
â
React
React â javascript- UI. , React-. React HTML-injection, ââ XSS-. âCSS injectionâ CSS-in-JS .
â
CSRF-
Cross-Site Request Forgery (CSRF) «» AppSec. -, - CSRF. / -, , , CSRF. , CSRF- . CSRF . Burp'a, .
â
, â . , . , , . . , USB . , Teensy Digispark.
Defensive Track
Defensive Track , . .
â e
secure by design -
, , , . â , â , .
, , , . , , , , , . â , -.
, secure-by-design .
â
:
. , .
â
Compressed signature and Public key recovery with GOST R 34.10-2012
, , , .
â
. ã¬ã€ã
â , . , , , , . , , .
â
SDL
aka Secure development lifecycle (SDL) . , , agile'a, . , , bottleneck. , SDL, , . , , .
â
Securing clouds in GCP
2016 Spotify Google Cloud Platform. :
~ 1300 Projects
~ 5000 GCS Buckets
~ 14000 Compute instances
~ 200 CloudSQL instances
~ 6400 Google Groups
~ 1000 AppEngine instances
, , , . Spotify Google Forseti, , . Forseti, , .
â
« »: do not roll your own crypto. , . - , . , , , , .
â
Windows
. , , - , .
â ,
Angine ABAC Framework
(ABAC), , (). ABAC, XACML .
DSL ALFAScript, ALFA. ALFAScript Lua, XML- (Java, Python, Scala ..), ABAC. ( XACML), Lua (runtime) . Lua- .
, , , , , , . ALFAScript Lua . HTTP MySQL.
â
Hunting for Credentials Dumping in Windows Environment
, «Credentials Dumping». , . â mimikatz/pwdump/wce .., lsass, , ârawâ- .
Windows , Windows, , Sysmon.
â
-7. , ,
-7.
â
- Burp Suite
-. . , Burp Suite - . , c -. . , , .
â
OpenSource Sandbox
Open Source . , Open Source IOC â , .
â
Content Security Policy «»
, XSS- , , «». Content Security Policy , . CSP «» . .
Workshops
ZN -, .
â
Workshop: DDoS-
Workshop'- « » (DDoS-) .
OSI , . - : (DNS, NTP, SSDP), (SYN flood), Sloworis .
, , . , . . Linux, .
â , ,
Workshop: . ( )
Workshop', , , .
Web Village
Web Village. -, , , , !
- (Client-side). , , , â .
ããŒã | |
---|---|
client-side | ã¢ã³ãã³"Bo0oM"
ãããã·ã³ |
CRLF + OpenRedirect | ãšãŽãŒã«"Shikari"
ã«ã«ããã |
CSRF / CORS / WS / PostMessage | ã»ã«ã²ã€"BeLove"
ããã ã€ã¯ã³ "igc_iv"
ãã£ãªãã³ |
Xssã Csti | ãšãŽãŒã«"Shikari"
ã«ã«ããã |
Xssã ãã£ã«ã¿ãŒã®ãã€ãã¹ãšä¿è· | ã€ãŽãŒã«"Psych0tr1a"
ãµã¯ã»ãµã³ãã¹ã㌠ã¢ã³ãã³ "Bo0oM"
ãããã·ã³ |
Xssã æäœã ããã«ãŒã®ããã®Js | ããããªãŒ"Azrael25"
ã ãªã¢ãã« |
ãã©ãŠã¶ãŒæ¡åŒµæ©èœã®ããŒã¯ãµã€ã | ã¢ã³ãã¬ã€"L1kvID"
ã³ãã¬ã |
2æ¥ç®ã®äžéšãšããŠããµãŒããŒéšåïŒãµãŒããŒåŽïŒã«å¯Ÿããæ»æãæ瀺ãããŸãã çåŸã¯ããµãŒããŒã®è匱æ§ã®æ§è³ªãç解ãããããã®ã»ãšãã©ãèŠã€ããŠæªçšããæ¹æ³ãåŠã¶ããšãã§ããŸããå žåçãªWebãµãŒããŒèšå®ãšã©ãŒããä»»æã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã³ãã³ãã®å®è¡ãŸã§ã
ããŒã | çºè¡šè |
---|---|
SQLã€ã³ãžã§ã¯ã·ã§ã³ | ãã€ã±ã«"Cyberpunkych"
å |
SSRF | ããã¹"thefaeriedragon"
ã©ã€ãã³ |
ffmpeg | ãã³ã©ã€"yngwie"
ãšã«ãã·ãã³ |
XXE | ã€ãã¹ã©ã"yarbabin"
ããã³ |
éã·ãªã¢ã«åã®èåŒ±æ§ | ã¢ã¬ã¯ã»ã€"GreenDog"
|
ããžãã¯ã®èåŒ±æ§ | ãªããŒã«"Beched"
ã¬ããšã |
ãã°ããŠã³ãã£ãšãªãŒã«ãªãŒã«ãªãŒã« | ã¢ã³ãã³"Bo0oM"
ãããã·ã³ ã»ã«ã²ã€ "BeLove"
ããã |
ãã¹ãŠã®ãããã¯ã¯ç°¡åãªäŸã§èª¬æãããã®ã§ãWebã®çµéšããªããŠããWebã®è匱æ§ã®äžçã«çªå ¥ããããšããŸã£ãã劚ããããšã¯ãããŸããïŒ
Web Villageã¯ãWebããã°ããŠã³ãã£ãã¯ãŒã«ãªçºèŠãé¢çœãç¶æ³ã«ã€ããŠè©±ãå Žæã§ãã
2017幎11æ16ã17æ¥ã«ã¢ã¹ã¯ã¯ã®ZIL CCã§1é±éåŸ ã£ãŠããŸãã