3æ5æ¥ãã16æ¥ã«ãããŠãNeoQUEST-2018ãµã€ããŒã»ãã¥ãªãã£ã³ã³ãã¹ãã®ãªã³ã©ã€ã³ã¹ããŒãžãéå¬ãããŸããã ãã³ã®äžã§ãã¿ã¹ã¯ïŒãã¹ãŠã§ã¯ãããŸããããäžéšã¯åå¥ã®è©äŸ¡ãšããŠè¡ãããŸãïŒãšãã®é²æçµ±èšãããã³ç«¶æã®11æ¥éãã¹ãŠã§åå è ã
äžè¬çãªçµæ
ãªã³ã©ã€ã³ã¹ããŒãžã«ã¯11ã®ã¿ã¹ã¯ãå«ãŸããäŒèª¬ã«ãããšãç¥ç§çãªã¢ãã©ã³ãã£ã¹ã®å®ç©ã®éµã®äžéšãå«ãŸããŠããŸããïŒ ãã¹ãŠã®ããŒãååŸããããšã«æåãã人ã¯ããŸããã§ãããã¿ã¹ã¯No. 11ãCat Fur Growsãã®2çªç®ã®ããŒã¯åŸæãããŸããã§ããïŒ
1äœã¯mityada㧠ã1527ãã€ã³ããç²åŸããã¿ã¹ã¯11ã®äžéãªããŒ2ãé€ããã¹ãŠã®ããŒãåãåããŸããïŒ ãã·ã«ããŒãã¯ãåãããŒãåéããŸãããããããã«æéã倱ããçµæ-1508ãã€ã³ããç²åŸããŸããã ãããã³ãºãã¯ããã¯ã¶ãŒãã«ãããŸãã-11以å€ã®ãã¹ãŠã®ã¿ã¹ã¯ãããã³1429ãã€ã³ãïŒ
ããã§ãšãããããŸãïŒ 1äœäºãã¯éåžžã«æ¿ãããã®ã§ããããã®ãããæ¥äžã«ãªãŒããŒã3å亀代ããŸããã äžäœ3人ã¯ã¯ãŒã«ãªã®ãããåŸ ã£ãŠããŸããå°ãªããšã1ã€ã®ã¿ã¹ã¯ããã¹ãŠå®äºãã人ã¯ãã¹ãŠãNeoQUESTããŒã ããã®ãåç£ã§ãïŒ
ã¿ã¹ã¯ãšå°ããªã€ãŒã¹ã¿ãŒãšãã°ã«ã€ããŠã®è©³çŽ°ïŒ
ã¿ã¹ã¯ã®ãããµã€ãã¯ãã°ããã®éå©çšã§ããã®ã§ãããããç解ããæ©äŒããŸã ãããŸãïŒ
ã¿ã¹ã¯çªå·1-ãã°ãªãŒã³ã¢ãœã·ãšãŒã·ã§ã³ã
ç§ã¯ç·ãèŠã-ç§ãã¡ã¯Androidã«ã€ããŠè©±ããŠããããšãç解ããŠããŸãïŒ
åå è ã«ã¯ãUnity3Dãã¬ãŒã ã¯ãŒã¯ã䜿çšããŠéçºãããã¢ããªã±ãŒã·ã§ã³ã§ããAPKãã¡ã€ã«ãæäŸãããŸããã ã¡ã€ã³ã¢ããªã±ãŒã·ã§ã³ãŠã£ã³ããŠã«ã¯ãã¯ãªãã¯ãããš2ã€ã®ã©ã³ãã ãã€ãã衚瀺ããããã¿ã³ããããŸãã
ã¢ããªã±ãŒã·ã§ã³ãéã³ã³ãã€ã«ããŠ\ asset \ bin \ Dataãã£ã¬ã¯ããªã衚瀺ãããšãUnityã®ããã±ãŒãžåãããã¢ã»ããããããUnity Assets Bundle Extractorããã°ã©ã ã䜿çšããŠè¡šç€ºã§ããŸãã
ãã£ã¬ã¯ããªã泚ææ·±ã調ã¹ããšãe4e623ca0e06d69d7d63a7daae5fb27fãšããååã®1ã€ã®GameObjectãæ€åºã§ããããã«ãªããŸãã-ããŒã®ããã«æããŸããïŒ ããã§çµããã§ãïŒ ãã®ç°¡åãªæåã®ããŒã¯ã112人ãã®åå è ãåãåããŸããã
ãŸãããã®ã¢ã»ã³ããªã§ã¯ãããŸããŸãªãã¯ã¹ãã£ãé 眮ãããããããã«1ã24ãšããååã®2ãã€ãã衚瀺ãããŸãããæããã«ãããã¯ãã©ã°ã®äžéšã«éããŸããã ãã®åãããã°ã©ã ã䜿çšããŠããããã®ãã¯ã¹ãã£ãPNG圢åŒã«ã€ã³ããŒãããããšãã§ããŸããïŒãããã¹ãã§ãïŒïŒã 次ã«ã2çªç®ã®ãã©ã°ã§ãã¹ãŠã®ããŒãã䜿çšãããŠãããã©ãããããã³ãã®é åºãç解ããå¿ èŠããããŸããïŒ
ãããè¡ãã«ã¯ãCïŒassembly \ asset \ bin \ Data \ Managed \ Assembly-CSharp.dllãéã³ã³ãã€ã«ããŸãã æ éã«åæããçµæãã©ãã«ãåŒã³åºãããªãGetSeqKeyé¢æ°ã衚瀺ãããŸãã çãããïŒ
ãã®é¢æ°ã¯æååãšé åã®XORãå®è¡ããŸãããåæã«ããœãŒã¹ã³ãŒãã«ã¯è¡ãšé åã®æ£ããå€ããããŸããã
ããããé åã«ã¯ããã¿ã³ã®æå³ããšãããã³ãããããŸãã ãã¿ã³ã泚ææ·±ãèŠããšãå¥åŠãªãã¯ã¹ãã£ãèŠããŸãïŒ
ååã®é«ãã®å€ãpxã§ååŸããŸããããã¯XORã®é åã§ãïŒ0x68ã0x5bã0x59ã0x00ã0x59ã0x58ã0x40ã0x44ã0x17ã0x58ã0x48ã0x57ã0x14ã0x47ã0x45ã0x48ã0x16ã 0x58ã0x4fã0x11ã0x5cã0x55ã0x00ã0x5bã0x49ã0x41ã0x40ã0x45ã0xcã0xeã0x11ã0x2ã0x0ã0x19ïŒã ããããããã¯éµã®äžéšã«ãããŸããïŒ
2çªç®ã®éšåãèŠã€ããããã«ãã¢ã»ãããå«ãããã±ãŒãžã®æ§æã泚ææ·±ã調ã¹ãŠãããã«ååããã¹ãã®3Dãªããžã§ã¯ãã衚瀺ãã* .obj圢åŒã§ã€ã³ããŒãããŠãPhotoshopãªã©ã§éããŸãã ãããªãã¯ç§ã®å¿ã®éµãæ¡ã£ãŠããŸã...ããšããããã¹ãã衚瀺ãããŸãã æ£ããã·ãŒã±ã³ã¹ãååŸããã«ã¯ãåä¿¡ããããŒã®XORãå®è¡ããŠã·ãŒã±ã³ã¹ãååŸããŸãã14ã17ã7ã24ã16ã11ã3ã21ã1ã7ããã©ã°ã®ãã¹ãŠã®éšåãæœåºããåä¿¡ããã·ãŒã±ã³ã¹ã«åŸã£ãŠå šäœãåéããŸãïŒ
2çªç®ã®ããŒã¯ããè€éã§ã49人ã®åå è ã®ã¿ãååŸããŸããã
ã¿ã¹ã¯çªå·2-ããã¢ãã¢ïŒã
ãã®å²ãåœãŠã§ã¯ãåå è ã«ãå ¥åããã¡ã€ã«ãäžããããŸãããããã¯ãé»è©±æ©ãšBluetoothãããã»ããéã®Bluetoothãã©ãã£ãã¯ã®ãã³ãã§ãã ãµãŒãã¹æ å ±ã«å ããŠããã©ãã£ãã¯ã«ã¯RTP / SBCãããã³ã«ãä»ããŠéä¿¡ãããé³å£°ããŒã¿ãå«ãŸããŠããŸããã åå è ã¯ãã¢ãŒã«ã¹ç¬Šå·ã䜿çšããŠã¯ãŒããæå·åããããªãŒãã£ãªããŒã¿ãæœåºããå¿ èŠããããŸãããSHA1ãããŒã§ããã
78人ã®åå è ããã®ã¿ã¹ã¯ãæ£åžžã«å®äºããŸããïŒ
ã¿ã¹ã¯çªå·3-ãã€ã¯ãã¢ã³ããŒãèŠã€ããã
ç§ãã¡ã¯OSINTã®ä»äºã倧奜ãã§ãããªãã圌ããæããŠããããšãç¥ã£ãŠããŸãïŒ åå è ã®mr_umnikããã§ã«èšäºãæžããŠããŸããããã®ã¿ã¹ã¯ã«é¢ããèå³æ·±ã詳现ã¯ç§ãã¡ã ãã§ãïŒ çµå±ã®ãšãããããªãã§ã¯ãªãã«ããŠãã芪æãªãåå è ã¯ãæ³ååã®åµãèŠããç§ãã¡ã«ã³ã¬ã¯ã·ã§ã³ããŸãšããã»ã©çŽ æŽãããåçãã¢ããããŒãããŠãããŸããïŒ
ãã®ã¿ã¹ã¯ã§äžãããããã¹ãŠã¯ãããã¯ããŒã andr_ihtiandrãš"profile"ãžã®ãªã³ã¯ã§ãã æ€çŽ¢VKontakteã¯ããã«çµæããããããŸãã ïŒ ãããã£ãŒã«åçãããçµç¹ã®ååïŒ AtlanticNeoSecurity ïŒãšæ¬¡ã«é²ãã¹ãå Žæã®ãã³ããåŸãããŸãã-ãå®å šãªã¡ãã»ã³ãžã£ãŒããã€ãŸãTelegramã«ïŒ
@andr_ihtiandrãšãã£ããããããšããŠãäœãèµ·ãããŸããã§ãããããããã£ãŒã«åçã«ã¯æ¬¡ã®ãœãŒã·ã£ã«ãããã¯ãŒã¯ã®ãã³ãããããŸããïŒAsk.fmïŒ ãããããIchthyanderãåããŠããäŒç€Ÿã®åµèšè ã®ååãèŠã€ããŸããïŒ Nobody ã
ãã ããVKontakteãããã¡ã€ã«ã«ã¯ãTelegramã®ãã³ãã ãã§ãªãããããã¹ãã¹ãã¬ãŒãžãµã€ãã«èå³æ·±ããã®ãæžãããšããããŸã=ïŒããšãããã¬ãŒãºãå«ãŸããŠããŸããã ãããŠãããã¯Pastebinãžã®ãã€ã³ã¿ã§ããã確ãã«-IchthyanderããããŸã ïŒ åœŒã®ãããã¡ã€ã«ã«ã¯ãå®éã«ã¯Base64ã§ãšã³ã³ãŒãããã.jpgç»åã§ãã1ã€ã®ã¬ã³ãŒããå«ãŸããŠããŸãïŒ
çµµã¯ãã®ããã«èŠããŸããïŒããã§ã¯åå è ã®æ³ååãä¹±æŽãªè²ã§å²ããŸããïŒã ãç¶è¡ããšã¯ãç»åãããã«åæããããšãæããŸããããã¯.jpgã§ãããããRARã¢ãŒã«ã€ããšããŠãéãããŸãã
ã¢ãŒã«ã€ãã®å 容ïŒè©³çŽ°ã«ã€ããŠã¯ãã¡ããã芧ãã ãã ïŒã¯ãããã¹ããã¡ã€ã«ãšã¡ã¢åž³ãŸãã¯HEXãšãã£ã¿ãŒã§éãããç»åã§æ§æãããåå è ã¯ããã®ç»åãäŒç€Ÿãèšç«ããã幎ãèŠã€ããã®ã«åœ¹ç«ã€ãšãããã³ããèŠã€ããŸããïŒ
å®éãåçã®Googleæ€çŽ¢ã§ã¯ã 2009幎ã«èŠã€ãã£ãã¢ãã©ã³ãã£ã¹ã®éºç©ã«é¢ãããã¥ãŒã¹ãå«ãçµæãè¿ãããŸããã
ããšã¯ãããŒãååŸããã ãã§ãããã¡ã€ã«ãã¢ããããŒãããŸãã ãããŠããã¡ã€ã«ã ãã§ãªããç§ãã¡ãç¹å¥ã«ã¢ã³ã±ãŒãã«æžããããã«ããã»ãšãã©çœé»ã®åçã«é ãã人ã®åçãã
ãããŠãã¿ã¹ã¯ãæž¡ã人ã ã®æŽ»çºãªå¿ãé»ã®äž»æš©ãšãã»ãŒé»ãšçœããšãããã¬ãŒãºãçµã³ã€ãããšããããšã¯èµ·ãããªããã°ãªããŸãã...
ãã®çµæãNeoQUESTããŒã ã¯ãã¢ããããŒããããåçã®äžã§å裞ã®ç·æ§ã®æ°ãå¢ããŠããã®ãæããŠèŠãŸããïŒ å¹žããªããšã«ããããã«å ããŠãæœè±¡çãªåçããããã€ã¯ãã¢ã³ããŒã®ããŒãã®ããªãšãŒã·ã§ã³ãããããŸããïŒ å¥åŠã ããŸãšããªãšãããããã³ã©ãŒãžã¥ãäœæããã
ãããŠããããããã€ãã«å°ç« ãçŸãå§ããŸããïŒ ã¯ããããã§ãïŒ å®éãVKontakteã®ã»ãŒçœé»ã®åçã«é»è²ã®ã¿ã¯ã·ãŒã衚瀺ããã ãcã ã ãaã ã ãTãã®æåãè²ã§åŒ·èª¿è¡šç€ºãããŸããã ç« -ç§ãã¡ãåŸ ã£ãŠããåçïŒ
ç«ããã®å€æ§æ§ã«æºè¶³ããŠãããç§ãã¡ã¯æãèå³æ·±ããã®ãéžæããã®ã«æ tooã§ã¯ãããŸããã§ããïŒ
æ£ããåçãããŠã³ããŒããããšãåå è ã¯ããŒãåãåããŸããã 76人ãã¿ã¹ã¯ã«å¯ŸåŠããŸããïŒ
ã¿ã¹ã¯çªå·4-ãé£è¡è¹ïŒ ãã¯ïŒã
åæ£ãããã¯ãŒã¯ZeroNetã¯ããã®å²ãåœãŠã®åå è ãåŸ ã£ãŠããŸããããã®å²ãåœãŠã«ã€ããŠã¯ããã§ã«Nokta_strigoããã®èšäºããããŸãã
æåã®éµãååŸããããã«ãZeroNetã®åçãç 究ããã®ã«ååç°¡åã§ããã 2çªç®ã®ãã®ãååŸããã«ã¯ãåå è ã¯æ±ããããªããã°ãªãããç·åœ¢ãã£ãŒãããã¯ãåããã·ããã¬ãžã¹ã¿ã«åºã¥ãæå·ãç ŽããŸããã
ã¿ã¹ã¯çªå·5-ããããæ·åïŒã
ãã®ã¿ã¹ã¯ãžã®å ¥åã¯ãµã€ãã¢ãã¬ã¹ã§ããããã¯ãåŒã³åºããäœæããŠPDFãã¡ã€ã«ãããŠã³ããŒãã§ããããã¯ãã«ã«ãµããŒããããŒãžã§ãã ãã°ãããããšãããŠã³ããŒããããPDFãã¡ã€ã«ã®æåã®ããŒãžãšãæåŸã«ãInternet Explorer 11ããã®åçããšãããã¬ãŒãºãå«ãå¿çãè¿ãããŸããã ããã¯ãã¹ãŠã管çè ãInternet Explorer 11ã§PDFãéãããšã瀺åããŠããŸãã
IE11ã§PDFãéãã«ã¯ãAdobe Readerãã©ã°ã€ã³ããããŸããããããŸã§ã®ãšãããããŒãèŠã€ããã®ã«äœã®å©ãã«ããªããŸããã§ããã ããŒãžã泚ææ·±ã調ã¹ãããšã§ã/ setkey.phpããŒãžã«ãªãã€ã¬ã¯ããããé ãããã¡ãã¥ãŒé ç®ãGET KEYããèŠã€ããããšãã§ããŸãã
ãã®ãã©ãŒã ã«ã¯ããŠãŒã¶ãŒãã°ã€ã³ãšãã1ã€ã®èŠçŽ ãããããŸããã ç°ãªãç¶æ³ã§ã¯ãç°ãªãã¡ãã»ãŒãžãçºè¡ãããŸãããæ£ãããã°ã€ã³ãå ¥åãããšãåå è ã¯æ¬¡ã®ã¡ãã»ãŒãžãåãåããŸããã
ã©ãããã管çè ã¯ãã®ã¢ã¯ã·ã§ã³ãå®è¡ããå¿ èŠããããŸãã ãããè¡ãæ¹æ³ïŒ
ããã§ãè匱æ§ã¹ãã£ããŒãå©ãã«ãªããŸããïŒãã¹ãŠïŒ-ãã©ãŒã ãã¹ãã£ã³ãããšã CSRFããä¿è·ãããŠããªãããšãããããŸããïŒ ããšã¯ãç¹å¥ãªPDFãã¡ã€ã«ãæºåããã ãã§ãã
å¯èœãªãªãã·ã§ã³ã®1ã€ã¯ããµã€ãã¢ãã¬ã¹ïŒ213.170.100.210ïŒã䜿çšããŠFormCalcã§POSTèŠæ±ãäœæããããšã§ãã
var b = Post("https://213/170.100.210/setkey.php", "login=test&setKey= ", "application/x-www-form-urlencoded")
ãã¹ãŠãçå®ã®ããã«æããŸããã...éµã¯ãããŸããã ããã§ã¯ããµã€ãã«ç¡å¹ãªSSL蚌ææžããã£ãããšãèŠããŠããå¿ èŠããããŸããïŒ ããã§ãã³ãã®äžéšããã¡ã€ã«ãéãããã«ã圌ã¯Adobeãã©ã°ã€ã³ãã€ã³ã¹ããŒã«ããŸããã WebãµãŒããŒãšåããµãŒããŒã§å®è¡ãããŸããã Internet Explorerã®ã»ãã¥ãªãã£èšå®ã確èªããŸã-確ãã«ïŒ localhostãµã€ãã¯å®å šã§ãã ãµã€ã213.170.100.210ã®ã¢ãã¬ã¹ãlocalhostã«å€æŽããŸã-ãããããŒã§ãïŒ
ã¿ã¹ã¯ã¯16人ã®åå è ã«ãã£ãŠæ£åžžã«å®äºããŸããã
ã¿ã¹ã¯çªå·6-ããšã³ãžãã¢ã¯èª°ã§ããïŒã
åå è ã«ã¯ã¹ããŒããã©ã³ã®å é床èšã®æž¬å®å€ã®ãã°ãæž¡ãããå¡äŸã«ããã°ãRTTY圢åŒã®ã¡ãã»ãŒãžãšRTTYãšã³ã³ãŒãã£ã³ã°ã®ãã©ã¡ãŒã¿ãŒã«ã€ããŠç¥ãããšãã§ããŸããïŒãã£ãªã¢åšæ³¢æ°-100 Hzããªãã»ãã70 Hzã
å é床èšã®ãã°ãåæããåŸãåå è ã¯ããã€ã¹ã®å é床å€ã1ç§éã«600åã®åº§æšè»žã®1ã€ã§ã®ã¿æž¬å®ãããå é床ã®æž¬å®å€ã0-60 m / s 2ãšéåžžã«é©åã§ããããšãããããŸããã
ã¿ã¹ã¯ã®äž»ãªã¢ã€ãã¢ã¯ãå©çšå¯èœãªå é床å€ã«å¿ããŠãããã€ã¹ã®äœçœ®ãèšç®ã§ããåäœæéãããã®å€ãã®å€ãã®äœçœ®æž¬å®å€ãå®å šã«èããããµãŠã³ããã©ãã¯ã§ãããšããããšã§ããïŒ ããã«ãããã¯æè¡çãªåé¡ã§ããæ°å€ç©åã®åºæ¬ãæãåºããŠãåå è ã¯ã¿ã€ã ã¹ã¿ã³ããšå Žæã®ãã¢ãå€æ°èšç®ããåä¿¡ããããŒã¿ããµãŠã³ãwavãã¡ã€ã«ã«è¿œãè¶ããªããã°ãªããŸããã§ããã æ®ã£ãã®ã¯ãé³ã®æ¯å¹ ã§å°ãéãã§ãä¿¡å·ãå¢å¹ ããŠãããŒããã£ãRTTYã¡ãã»ãŒãžããã³ãŒãããããšã ãã§ããïŒ
ãšã³ãžãã¢ã¯29åã®åå è ã§ããã
ã¿ã¹ã¯çªå·7-ãå°çã®é-ç§ã®åœ¹å²ïŒã
ã¿ã¹ã¯çªå·7ã¯ã解æŸåŸäœ¿çšã®è匱æ§ã®æ€çŽ¢ãšå©çšã«å°å¿µããããã«ã¿ã¹ã¯èªäœãLuaèšèªã®äœ¿çšã瀺åããŠããŸããã
ãã®ã¿ã¹ã¯ã®è©³çŽ°ãªåæïŒãããŠããã ãã§ã¯ãããŸããïŒïŒ GH0st3rsã«ãã£ãŠäœæãããŸã ã ã 4人ã®åå è ã®ã¿ãã¿ã¹ã¯ãå®äºããŸããïŒ
ã¿ã¹ã¯çªå·8-ããããã¯ãã§ãŒã³ã¯ã¢ãã©ã³ãã£ã¹ã«ãŸã§å°éããŸãã...ã
ãã®ã¿ã¹ã¯ã§ã¯ãåå è ã«åçŽãªãããã¯ãã§ãŒã³ãšå¯Ÿè©±ããã¯ã©ã€ã¢ã³ããäžããããŸããã ããŒãååŸããã«ã¯ãåå è ã®ããã¯ããŒã ãå«ããããã¯ãç²ç ããå¿ èŠããããŸããã ããããæšæºã®ãã€ãã³ã°ã¢ã«ãŽãªãºã ã¯é ãããŸããïŒ é床ãäžããããã«ãåå è ã¯ãããã¯ããã§ãã¯ããããã«äœ¿çšãããããã·ã¥é¢æ°ã«è匱æ§ãèŠã€ããå¿ èŠããããŸããã
ã¿ã¹ã¯ã¯ãã£ã10人ã®åå è ã«ãã£ãŠå®äºããŸããã詳现ãåæããè©äŸ¡ããåŸ ã¡ãã ããã
ã¿ã¹ã¯No. 9-ãQEMU + eCos = QECOSãããã³No. 10-ãã¹ãã¯ã¿ãŒã
ãããã®2ã€ã®ã¿ã¹ã¯ã«ã€ããŠãã¢ã¯ãã£ããªGH0st3rsãè©äŸ¡ãæžãäžããããšãã§ããŸããïŒ ããã§ããããèªãã§ãã ãã ã ã¿ã¹ã¯No.9ã¯å€ãã®äººã«ãšã£ãŠçããeCosãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã®äœæ¥ã«åœãŠãããã ãã§ã2ã€ã®ããŒãå«ãŸããŠãããæåã®ããŒã¯5人ã®åå è ã®ã¿ãåãåãã2çªç®ã¯ããã«4人ã®åå è ã§ããïŒ
ã¿ã¹ã¯No. 10ã®ã¿ã€ãã«ã¯ã ã¹ãã¯ã¿ãŒããã®è匱æ§ãªãã§ã¯ã§ããªãã£ãããšãããã«ç€ºããŸããïŒ NeoQUESTåå è ã¯ã以åã«ãšã©ãŒãèŠã€ããŠãä¿®æ£ããããããå£ããã¢ããªã±ãŒã·ã§ã³ããããŒãæœåºããå¿ èŠããããŸããïŒæ倧3åïŒïŒã
æåã®ããŒãš3çªç®ã®ããŒã¯29人ã®åå è ã«ãã£ãŠåä¿¡ããã2çªç®ã®ããŒã¯ããå°é£ã§ããããšãå€æãã19人ã®åå è ã®ã¿ãèŠã€ãããŸããã
課é¡11-ãç«ã®æ¯ç®ãæé·ããã
ãã®çããååã§ãåå è ã«ã Control Flow Guard ïŒCFGïŒãšåŒã°ããWindowsä¿è·ã¡ã«ããºã ãåé¿ããæ¹æ³ããªãããšã匷ã瀺åããŸããïŒ ã¿ã¹ã¯ã§ã¯ã/ nazfazzã®è匱æ§ãèŠã€ããReadWriteããªããã£ããååŸããŠãæåŸã®Windowsã«ãããã¹ãŠã®ãã®ïŒ DEP ã ASLR ãCFGãªã©ïŒããã€ãã¹ããå¿ èŠããããŸããã
2ã€ã®ããŒã®ãã¡æåã®ããŒãåãåã£ãåå è ã¯4人ã ãã§ãããã2çªç®ã®ããŒã¯èª°ã«ãéä¿¡ãããŸããã§ããã ããã¯ãæãé£ãããšããäºå®ã«å ããŠã圌ã«ã¯åæ Œããããã®ããã€ãã®ãªãã·ã§ã³ããã£ãããã§ãã
ã€ãŒã¹ã¿ãŒãšãã°
ã³ã³ãã¹ãçµäºã®æ°æ¥åã«ãéçºè ã®1人ãåå è ã«ã¡ãã£ãšãããµãã©ã€ãºãããããšã«æ±ºããå°ããªãšã³ãžãã¢ãªã³ã°ã€ãŒã¹ã¿ãŒãšãã°ãæãã€ããŸããã å¡äŸã®ããã¹ãã§ã¯ãäžéšã®æåã倪åã§åŒ·èª¿è¡šç€ºãããŠããŸãã
ã¯ããã«-ON ïŒæèšããšïŒ
ã¿ã¹ã¯1-LMïŒã³ã³ãã³ãïŒã ããã³ ïŒé åŸïŒ
ã¿ã¹ã¯2- ãªã³ ïŒãã ãç±³åœã®ã¿ïŒ
ã¿ã¹ã¯3- ST ïŒç§ã®ç¶æ ïŒ
ã¿ã¹ã¯5- AR ïŒå ¬éããã«ïŒ
ã¿ã¹ã¯6- T ïŒsmartTphoneïŒ
ã¿ã¹ã¯7-7ïŒIPã¢ãã¬ã¹ããïŒ
ã¿ã¹ã¯8- P ïŒãŽãŒãžã£ã¹ïŒã AZ ïŒåæïŒ
ãã¹ãŠã®ãã£ã©ã¯ã¿ãŒãéããŠãåå è ã¯æ¬¡ã®ãã¬ãŒãºãåãåããŸããïŒãã¹ã¿ãŒã7åã¯ãªãã¯ããŠãã ãããã
ã¯ããã¯ããé£è¡è¹ã®äžã«ããéåžžã«æåã«ïŒ
7åã¯ãªãã¯ãããšããã®ããŒãžãéããŸãã
ãªã³ã¯ã®æ¬ èœéšåãååŸããã«ã¯ãåå è ã¯åçéã®ãã¯ã»ã«ããšã®éããèŠã€ããå¿ èŠããããŸããã ãããè¡ãã«ã¯ååãªæ¹æ³ããããŸãããæãç°¡åãªã®ã¯ãªã³ã©ã€ã³ããŒã«ãããšãã°ãããèŠã€ããããšã§ãã圌女ã¯ãã®éããèŠã€ããŸããã
ãW3Are1n1AMMn0WïŒ11ããšãããã¬ãŒãºã¯ã SPbPUïŒNeoQUESTïŒã®ãªãŒã¬ãã€ã¶ãŒã®1人ïŒã®åºèº«éšéã§ãããã³ã³ãã¥ãŒã¿ã·ã¹ãã ã®æ å ±ã»ãã¥ãªãã£ã ãå¿çšæ°åŠç 究æã«ç§»è»¢ãããšããäºå®ã«é¢é£ããéçºè ã®åã³ã®ææ ãåæ ããŠããŸãã ããŠãå¿é¡è ãåŠå£«ã倧åŠé¢ç-ä»ãç§ãã¡ãèŠã€ããå Žæãç¥ã£ãŠããŸãïŒ ããã«ãIBSéšéã«å ¥ãéã«ã¯ãNeoQUESTãžã®æåããåå ãèæ ®ãããŸãïŒ
ããããã€ãŒã¹ã¿ãŒãšãã°ã¯ãŸã æåŸãŸã§å®æããŠããªããããååãªæè©ã§ãïŒ åä¿¡ãããªã³ã¯ãã¯ãªãã¯ããããšã«ãããåå è ã¯æ°ãããªããªããåãåããŸããã
æ¯è»ãåŒ...ããã¯æ確ã§ã¯ãããŸããã ããã«ã詳ããèŠãŠã¿ããšãåå è ã¯ãäžã®åŒããæ倧ã®ã¢ã®ã¯ããŒãæ°ãšæå°ã®ã¢ã®ã¯ããŒãæ°ã®æ¯ã«éããªãããšã«æ°ã¥ããŸããïŒ å šäœã®é£ããã¯ãã¯ããŒããæ£ç¢ºã«æ°ãïŒãããã63ããã³16ïŒã1ã€ãä»ã®ãã®ã§å²ãïŒ3.9375ïŒã10 4ãæããçµæã®å€ïŒ6246a5c59e9cd5944ab1b196dcb9d950c2172254ïŒããSHA1ãååŸããããšã§ããïŒ
46人ã®åå è ãã€ãŒã¹ã¿ãŒãšãã°ã«åæ Œãããããã10ãã€ã³ããç²åŸããŸãã-ãã®ã¿ã¹ã¯ã§ã¯åçã¹ã±ãŒã«ã¯æ©èœããŸããã§ããã
ãããŠä»-çµ±èšïŒ
1253人ãåå ãã167人ã®åå è ãå°ãªããšã1ã€ã®éµãåãåããŸããã é äœã®å€æŽ-åŸæ¥ã®GIFã®å ŽåïŒ
ãŸããã¿ã¹ã¯ã®è€éãã«é¢ããçµ±èšãåéããŸããïŒã¿ã¹ã¯ãå®å šã«å®äºããåå è ã®æ°ãèæ ®ã«å ¥ããŠïŒã
ãããŠãŸã -ããã€ãã®ããŒãæã€ã¿ã¹ã¯ã®çµ±èšïŒ ãããã®5ã€ããããŸããã
- ã¿ã¹ã¯çªå·1ããã°ãªãŒã³ã¢ãœã·ãšãŒã·ã§ã³ã-2ã€ã®ããŒã
- ã¿ã¹ã¯çªå·4ããé£è¡è¹ïŒ ããïŒã-2ã€ã®ããŒã
- ã¿ã¹ã¯çªå·9ããQEMU + eCos = QECOSã-2ã€ã®ããŒã
- ã¿ã¹ã¯çªå·10ããã¹ãã¯ã¿ãŒã-3ã€ã®ããŒã
- ã¿ã¹ã¯çªå·11ããCat Fur Growsã-2ã€ã®ããŒã
NeoQUEST-2018ã®ãªã³ã©ã€ã³ãã§ãŒãºå šäœã§ã594åã®ããŒãåä¿¡ãããŸããïŒ æãç°¡åãªã®ã¯ãAndroidã§ã®ã¿ã¹ã¯ã®æåã®ããŒã§ããïŒNo. 1ããã°ãªãŒã³ã¢ãœã·ãšãŒã·ã§ã³ãïŒã
å ã«-ã察ç«ãïŒ
ä»å¹Žãã察ç«ãã¯ãµã³ã¯ãããã«ãã«ã¯ã§ãå€ã§ã¯ãªãç§ã«ã9ææ«ã«éå¬ãããŸãã ãã ããããã¯ã²ã¹ããšåå è ãåŸ ã€ãã¹ãŠã®å€æŽã§ã¯ãããŸããïŒ
æãã¯ãŒã«ã§ãæ°ã«å ¥ãã®ã¬ããŒããã¯ãŒã¯ã·ã§ãããæ»æã®ãã¢ãæ®ããæ°ããæ»æãè¿œå ããŸãïŒ NeoQUESTã¯ãç§åŠæè¡äŒè°ãæ å ±ã»ãã¥ãªãã£ã確ä¿ããæ¹æ³ãšæè¡çæ段ããšãšãã«åããŠéå¬ãããŸãã NeoQUEST-2018ã®ã²ã¹ãã¯ãç§åŠãšãµã€ããŒã»ãã¥ãªãã£ã®å®è·µã®é¢ä¿ãæ å ±ã»ãã¥ãªãã£ã®å°é家ã«ãšã£ãŠã®ç§åŠç 究ã®éèŠæ§ãç§åŠçã«ææ°ã®æ å ±ä¿è·ã¡ã«ããºã ã®ä»çµã¿ã«ã€ããŠå€ããåŠã³ãŸãïŒ
åæã«ãåžæãã人ã¯NeoQUESTã ãã§ãªããäŒè°ã®ç§åŠã»ã¯ã·ã§ã³ã«ãåå ã§ããŸãïŒ NeoQUESTã®ã¬ããŒããŸãã¯ã¯ãŒã¯ã·ã§ãããžã®åå ã®è©³çŽ°ã«ã€ããŠã¯ãsupport @ neoquest.ruã«ãé£çµ¡ãã ãããäŒè°ãæ å ±ã»ãã¥ãªãã£ã確ä¿ããæ¹æ³ãšæè¡çæ段ãã®è©³çŽ°ã«ã€ããŠã¯ã ãŠãã€ããããµã€ããåç §ããŠãã ããã
å ã«-ããã€ãã®ã¿ã¹ã¯ã®æžã蟌ã¿ãšã察é¢ãã®ããã®ç©æ¥µçãªæºåïŒ ãšããã§ãå°ãªããšã1ã€ã®ã¿ã¹ã¯ãå®äºããåå è -ã¡ãŒã«ã確èªããŠãã ãããããã«éµéãéå§ããŸãã