DefCampã¯ãåŠçããããŸããŸãªæ¥çã®ãªãŒããŒãæ å ±ã»ãã¥ãªãã£ã®å°é家ãç 究è ãŸã§ãããŸããŸãªç¥èãšçµéšãæã€ã«ãŒããã¢ãšè¿é£è«žåœãã1800人以äžã®åå è ãéããŸããã

ã€ãã³ãã®çŽæ¥ã®äž»å¬è ã¯ãéæ¿åºçµç¹ã§ããã«ãŒããã¢ã®ãµã€ããŒã»ãã¥ãªãã£ç 究ã»ã³ã¿ãŒã§ã ã 圌ãã«ãããšãä»å¹Žã®åå åœã®æ°ã¯35ã§ããšãŒããããã¢ã¡ãªã«ãã€ã³ããUAEã60人ã®ã¹ããŒã«ãŒã400瀟ãå«ãŸããŠããŸãã
DefCamp 2018ã«ã€ããŠ

ã€ãã³ãã®åœ¢åŒã«ã¯ããã¬ãŒã³ããŒã·ã§ã³ãšCTFã³ã³ãã¹ããå«ãåŸæ¥ã®ã»ã¯ã·ã§ã³ãå«ãŸããŠããŸããã
CTFã®æåã®3ã€ã®å ŽæïŒããŒã ããã¢ãå ±ååœïŒã¡ã©ãã·ã¢ïŒãããŒã©ã³ããã¹ãŠã§ãŒãã³ã 4äœã¯ã«ãŒããã¢ã®ããŒã ã§ãã ä»å¹Žã¯ãã·ã¢ããã®ããŒã ã¯ãããŸããã§ããã å®å šãªãªã¹ãã¯ãã¡ãããå ¥æã§ããŸã ã

ä»å¹Žã®è¬çŸ©ã»ã¯ã·ã§ã³ã¯ã3ã€ã®å¹³è¡ãããã©ãã¯ã§éå¬ãããŸããã æ¯èŒã®ããã«ãæšå¹Žã¯2ã€ã®ãã©ãã¯ããããŸããã

ä»å¹ŽDefCampã«ã¯åã³HackerVillageããããæ å ±ã»ãã¥ãªãã£ããã²ãŒã ãŸã§ãããŸããŸãªãããžã§ã¯ããå±ç€ºãããŸããã æšå¹Žãšã¯ç°ãªããæ£åœåãããŠããªããããã¹ã¿ãŒãã¢ããã®ã»ã¯ã·ã§ã³ã¯åé€ãããŸããã
ä»å¹ŽããªãŒã¹ããªã¢é äºé€šã°ã«ãŒãã®åå ãç¹åŸŽã§ããïŒæšå¹Žãšåæ§ïŒããä»ã§ã¯2ã3æéã®3ã4人ã®å°ããªãã£ã¹ã«ãã·ã§ã³ããã«ã§ããã
ã€ãã³ãã®äŒè°éšåã¯ãé²æ©çã§é©æ°çãªã¢ã€ãã¢ãææ°ã®ç 究éçºã®çµæãITã»ãã¥ãªãã£ã®ãã¹ãŠã®åéã§ã®å°éççµéšã®äº€æãç®çãšããŠããŸããã å ±åã®è³ªãé«ããè¬æŒè ã®çµéšãç°ãªããã»ãã¥ãªãã£ã®åé¡ã«å¯ŸããèŠæ¹ãç°ãªã£ãŠããããšã«æ³šæããããšãéèŠã§ããããããã®æèŠãšãåœããšã«åé¡ã解決ãã詳现ãèæ ®ããŠãã ããã ããšãã°ãã€ã³ããããã¹ã¿ã³ãããã³æ±ãšãŒãããããã®è¬æŒè ã¯ãè°è«äžã®åé¡ã®æè¡çãªåŽé¢ãåãã§è©³è¿°ããŸãããã¢ã¡ãªã«äººã®ååã¯çµç¹ã®åé¡ãšãã¬ãŒãã³ã°/ãã¬ãŒãã³ã°ãŸãã¯ãã¬ãŒã·ã§ã³ã®è¯éºãªè«çã䌎ãäŸã®æ瀺ã®åé¡ã«çµã蟌ã¿ãŸãã ãã ããä»å¹Žã®ã¬ããŒãã®ã»ãšãã©ã¯ãæè¡ãããããžãã¹ããã³é«ã¬ãã«ã®åœ¢åŒã§ãããããã°ã©ã ã®ã»ãšãã©ã¯ãããžãã¹ãã§ã¯ãªããæè¡ããšããŠããŒã¯ãããŠããŸããã

å®éãäŒè°ã®ãããã¯ã¯æ¬¡ã®ãšããã§ãã
- IoTã»ãã¥ãªãã£ã¯ä»å¹Žã®ããŒãã§ãã
- ã€ã³ãã©ã¹ãã©ã¯ãã£ã®ä¿è·ã
- ãµã€ããŒã»ãã¥ãªãã£ã
- æªæã®ãããœãããŠã§ã¢ã
- ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã
- åºçŸ©ã®ã¢ãã€ã«ã»ãã¥ãªãã£ã é¢é£åéã§ã
- ãã®ä»ã®ã¬ããŒãã
DefCamp 2018ã®ã¬ããŒãã«ã€ããŠãåºåžã§ããŸãã
åœæ å ±ãäžè«ã®å€åãåœã®æã«é¢ããããããã€ã¯ã¬ã€ã
æãªããã®ãªãã©ã€ã³ã®ååãšãåœã®ãã¥ãŒã¹èšäºããç¹å¥ã«æºåãããã€ã³ã¿ãã¥ãŒãŸã§ã誀ã£ãæ å ±ãšãšãã«ãããã¯ãŒã¯ããæ å ±ãååŸããããšã«é¢ããã¬ããŒãã Kaspersky Labã®ã«ãŒããã¢é§åšå¡äºåæã®ã¹ããŒã«ãŒã§ããDan Demeterã¯ãçå®ã®ãã¥ãŒã¹ãšåœç©ãåºå¥ããæ¹æ³ã説æããããšããŸããããææ¡ãããæ¹æ³ã¯ã»ãšãã©çµéšçã§ããã枬å®åºæºãäžååã§ããã枬å®åºæºããã¯ãåãã¿ã€ãã®ãã¥ãŒã¹ïŒããã³ãããã«äœ¿çšãããŠããæèšïŒå察ã®ã³ã³ãã³ãã

æå·ã·ãŒã«ããéããŠãã£ã·ããã
Cosmin Raduã¹ããŒã«ãŒã¯ãæå·åãæ»æããBurpã®èœåã«ã€ããŠãã¬ãŒã³ããŒã·ã§ã³ãè¡ããŸããã匱ãæå·åãšãã®ãšã©ãŒãç¹å®ããããŒãæããã«ããäŸãšããŠåã ã®ã¢ããªã±ãŒã·ã§ã³ã䜿çšããŠæ¥ç¶ã確ç«ãããã¬ãŒã ã¯ãŒã¯å ã§ããŒåœ¢æã®ã¹ããããåæããŸãã äžè¬ã«ãã¬ããŒãã¯ãããŒã«ã®æ©èœã«é¢ããBurpããŒã ãŸãã¯é¢é£ããç 究è ããã®ããžãã¹ã¬ããŒããšããŠèŠãããšãã§ããŸãã
OSSTMMïŒã枬å®ãæšæž¬ããªããã»ãã¥ãªãã£ãã¹ãæ¹æ³
ã¡ããªãã¯ã®åäžæ§ãšCVSSè©äŸ¡ã®å å«ãèæ ®ããŠãã»ãã¥ãªãã£ãªã¹ã¯ææšãè©äŸ¡ããã³èšç®ããããã®æ¹æ³è«ã«ã€ããŠå ±åããŸãã ææ¡ãããæ¹æ³è«ã¯ããã¡ã«ããºã ãšå¯Ÿçã®ç·æ°ã«é¢é£ããŠãä¿è·ã¡ã«ããºã ãé©çšãããŠããªãããè匱æ§ãéããããŠããªãããšãã圢åŒã®åŒã®ããªãšãŒã·ã§ã³ã«èŠçŽãããŸãã äžè¬ã«ãæè¿ã®ISECOMã®åºçç©ã¯ããã³ããšææšã®æ®éåã«é¢é£ããŠããŸãã
ãªã¢ãŒããšãããããã³ã°
2017 Kaspersky Labã®ã¹ã¿ããã¯ãããã²ãŒã·ã§ã³ãšIoTãå«ããšãããšæ¥ç¶æ©åšã®è匱æ§ãã»ãã¥ãªãã£ãšã©ãŒãæ¢è£œããŒã«ïŒPentesterãããã«å«ãŸããïŒã䜿çšããMicrotikã«ãŒã¿ãŒã®ãã¹ã¯ãŒãã®ç·åœããããã¡ãŒã ãŠã§ã¢ããã³ãšãã管çããã°ã©ã ã®ãã¹ã¯ãŒãã®ããŒãã³ãŒããããã³ååã«ã€ããŠå ±åããŸãæå·åãããŠããªããã©ãã£ãã¯ã

ã¢ãã€ã«ä¿¡å·ã®è åšãšè匱æ§-ç§ãã¡ã®çµéšããã®å®éã®ã±ãŒã¹ãšçµ±èš
Positive Technologiesã¯ãã¢ãã€ã«ãããã¯ãŒã¯ã®è匱æ§ãã»ãã¥ãªãã£ã®çŸåšã®ç¶æ ãããã³ããã€ã¹ãæ¥åžžã®ã¢ããªãã£ã®ã¢ããªã±ãŒã·ã§ã³ãããã³ã¢ãã®ã€ã³ã¿ãŒãããéã®æ å ±äº€æã«å¯Ÿãã圱é¿ã«ã€ããŠå ±åããŠããŸãã ãã®ã¬ããŒãã¯ã Diameterè匱æ§ãšã¯ã¹ããŒãžã£ãŒã¬ããŒã2018ããã³PT Telecom Attack Discoveryã®è³æãåæ ããŠãããSS7ãããã¯ãŒã¯ã»ãã¥ãªãã£ã®ãããã¯ã«é¢ããããå€ãã®ç 究統èšã§ãã
ããªãã¯æ£ããããã®è©±ã¯æ¬åœã«ããªãã«ã€ããŠã§ã¯ãããŸããïŒ

ãã1ã€ã®ãžã§ã€ãœã³ã¹ããªãŒãã¯ãé倧ãªã»ãã¥ãªãã£åé¡ã«ã€ããŠè©±ããŸãã Jasonã¯ãäŒæ¥ã®ã»ãã¥ãªãã£ããŒã ã«ãã£ãŠãµããŒããããŠããããšã³ããŠãŒã¶ãŒã®ãšã©ãŒãšãã®åäœç¿æ £ã«é¢é£ããåŽé¢ã«å¯ŸåŠããŸããã ãããããã®ã¬ããŒãã«ã¯éçºè ã®ããã¥ãŒãã³ãšã©ãŒãã¯å«ãŸããŠããŸããã§ããããäž»ãªãã®ã¯äººã ã®ã»ãã¥ãªãã£ã®åéã«ãããèåçãåäžãããããã®ææšã§ãããšå ±åãããŸããã ããã¯ããŠãŒã¶ãŒãã¬ãŒãã³ã°ãšã»ãã¥ãªãã£ç£æ»ãµãŒãã¹ãè³Œå ¥ããäŒæ¥ã®ããŸããŸãªç¶æ³ãšã±ãŒã¹ã®äŸãå«ãããŠãŒã¶ãŒåãã®ã»ãã¥ãªãã£ãã¬ãŒãã³ã°ãšã»ãã¥ãªãã£æèã«é¢ããã¬ããŒãã§ããã
IoTãã«ãŠã§ã¢ïŒå æ¬çãªèª¿æ»ãåæãã¬ãŒã ã¯ãŒã¯ãã±ãŒã¹ã¹ã¿ãã£
IoTããã€ã¹ã®åé¡ã®åæãCVE / CVSSããŒã¿ããŒã¹ã®äžåè¡¡ãããã³IoTè匱æ§ã®ãããã¯ã«é¢ããäžè¬å ¬éãããŠããåºçç©ãIoTã®è匱æ§ãšæªæã®ããã³ãŒãã®æ©èœã«é¢ããã¬ããŒãã CVE / CVSSããŒã¿ããŒã¹ã®äžå®å šæ§ã«é¢ããåé¡ã®äžéšã¯ãCWEïŒCommon Weakness issuesïŒã«é¢ããæ å ±ãCWEïŒCommon Weakness issuesïŒããé€å€ãããŠããããšãããã³ãã®ãããªããªã¥ãŒã ã§èª°ãåæããŠããªããç¹ã«ãããããŸãšããŠããªãå€ãã®IoTããã€ã¹ã§ãããŸãã ããã§ãã®è³æãèŠã€ããããšãã§ããã¹ããŒã«ãŒã¯ãèªååé¡åæã®ããã®ããã€ãã®ããŒã«ãæäŸããŸãã ïŒ
- ã«ãã³ãŠãµã³ãããã¯ã¹ -WindowsãLinuxãMacOSãAndroidã®æªæã®ãããã¡ã€ã«ãšWebãµã€ãã®åæãè¡åã®çç¶ã®ã³ãŒã«ãã¬ãŒã¹ãšåæããããã¯ãŒã¯ãã©ãã£ãã¯ã®ãã³ããšåæ æå·åãããã³RAMåæçšã®VolatilityããŒã«ã®ãµããŒãã
- Firmware.REã¯ãããã€ã¹ãã¡ãŒã ãŠã§ã¢ã®ãã¡ã€ã«ïŒããã±ãŒãžïŒãã¹ãã£ã³ããã³åæããè匱æ§ãããã¯ãã¢ãçµã¿èŸŒã¿ïŒãã¡ãŒã ãŠã§ã¢ã¢ã»ã³ããªäžïŒã®æªæã®ããã³ãŒããè¿ éã«æ€åºããããã®ç¡æãµãŒãã¹ã§ãã
å»çã«ãããå®å šã§å®å šãªããžã¿ã«ç°å¢ã®æ§ç¯ã®èª²é¡
å»çæœèšã®å®å šæ§ã«é¢ããã»ã«ãã¢ã®å ±åã ãã®ã¬ããŒãã¯IoTã«é¢é£ãããã®ã§ã¯ãããŸããã§ããããä»äºã®è©³çŽ°ãå»çã¹ã¿ããã®ããŒãºãèæ ®ããã«ãæ¢åã®ã»ãã¥ãªãã£ãœãªã¥ãŒã·ã§ã³ã®é©çšã«ã€ããŠè°è«ããããšãç®çãšããŠããŸããã 決å®ã®è©³çŽ°åã§ã¯ããããã®æ©èœãšGDPRã®èŠä»¶ãèæ ®ã«å ¥ããå¿ èŠããããŸãïŒãããã£ãŠããããã¯ç¹ã«è¿·æã§è¿·æã§ã¯ãããŸããïŒã
ããã«ãŒãã«
HackerVillageã¯ãããŸããŸãªå€§äŒãéå¬ãããäŒè°ã®äŒçµ±çãªã€ãã³ãã«ãªããŸããã
DefCamp Capture the FlagïŒD-CTFïŒ
CTFã¯ã人工ç¥èœãšæ©æ¢°åŠç¿ããµã€ããŒæŠäºãæå·åãã¹ãã¬ãã°ã©ãã£ãŒãWebã»ãã¥ãªãã£ããããã¯ãŒã¯ã»ãã¥ãªãã£ããã©ã¬ã³ãžãã¯ããªããŒã¹ãªã©ãããŸããŸãªãããã¯ã§éå¬ãããäŒè°ã®é²è¡äžã®ã€ãã³ãã®1ã€ã§ãã åå ã®åºæ¬ã«ãŒã«ïŒ
- ããŒã ãªãŒããŒãå«ããããŒã å ã®ããã5人ã
- DoSã¯çŠæ¢ãããŠããŸãã
- CTFã€ã³ãã©ã¹ãã©ã¯ãã£ã®è匱æ§ãæ€çŽ¢ãããšãããå€ãã®ãã€ã³ããããããããŸãã
- ããã¯ã¯ãããŒã ãæåã«ãããã³ã°ãããªãã£ãå Žåã«ã®ã¿ã«ãŠã³ããããŸãã
è³é-3000ãŠãŒããšã¬ãžã§ããã
åãå®ã
競æè ã¯ãã»ãšãã©ã®æ»æãæéããããã«IPS眲åãäœæããŸããã 競äºæ¡ä»¶ïŒ
- æ£åœãªãã©ãã£ãã¯ããããã¯ããªãã§ãã ããã
- ããŒãããã³ãããã³ã«ã¿ã€ãã®çœ²åã¯äœ¿çšã§ããŸããã
- ãšã¯ã¹ããã€ãã§ãã¹ãæžã¿ã
- FalsePositiveãšã¯ã¹ããã€ãããããã¯ããªãã§ãã ããã
- éå¶å©ã®çœ²åïŒåŸã«åå©ãšããŠå ¬éïŒã
ãšã¯ã¹ããã€ããªã¹ãïŒ
- CVE-2018-3924 Foxit PDF Reader Javascript MailFormã®ãªã¢ãŒãã§ã³ãŒããå®è¡ãããè匱æ§
- CVE-2018-7600 Drupalã³ã¢ã®ãªã¢ãŒãã³ãŒãå®è¡
- CVE-2018-16509 Ghostscriptã³ãã³ãã®å®è¡
- CVE-2018-17128 MyBB Visual Editor 1.8.18-ã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°
- CVE-2018-9866 SonicWall XML-RPCãªã¢ãŒãã³ãŒãå®è¡
- CVE-2018-12895 WordPress 4.9.6ãã£ã¬ã¯ããªãã©ããŒãµã«
- CVE-2018-7745 Mikrotikã«ãŒã¿ãŒOS SMB BOF
- CVE-2018-8840 Schneider Electric induSoft RCE
- CVE-2018-7756 Dewesoft X3ãªã¢ãŒãã³ãã³ãã®å éšã¢ã¯ã»ã¹
- Atmosphere Java Framework Reflected XSS
IoTãã¬ããž
IoT VILLAGEã¯ãããã€ã¹ããããã³ã°ããããã®å®çšçãªã¢ãããŒãã瀺ãããã«èšèšãããŠãããåå è ã¯ãããã³ã°ããã¬ãžã§ããïŒã«ãŒã¿ãŒããŠã§ãã«ã¡ã©ãªã©ïŒãç²åŸã§ããŸãã ã«ãŒã«ïŒ
- ã³ã³ãã¹ãã«åå ããŠããååå è /ããŒã ã«ã¯ããããã¯ãŒã¯ã«æ¥ç¶ããæ段ãæäŸãããŸãããèªåã®ã©ããããããå¿ èŠã§ãã
- 次ã«ãååå è /ããŒã ã¯ãå©çšå¯èœãªããŒã«ãŸãã¯ã¹ã¯ãªããã䜿çšããŠãã³ã³ãã¹ãã§çºè¡šãããããã€ã¹ãæ»æãå§ããŸãã
- ãã€ã§ãã2人ãŸã§ã®åå è ãããã€ã¹ã«èš±å¯ãããŸãã
- åå è ãããã€ã¹ã®ããããã§è匱æ§ãçºèŠããå Žåããã®å Žã§å¯©å€ã«éç¥ããŸãïŒè£å€å®ã®1人ã«ïŒã
- åå è ãããããã®ããã€ã¹ã«é¢é£ããŠè匱æ§ã䜿çšããå Žåã圌ã¯ãã®ããšã審å€å¡ã«ãã®å Žã§ïŒè£å€å®ã®äžäººã«ïŒç¥ãããŸãã
- ãã¹ãŠã®è匱æ§ãäž»å¬è ã«æäŸããå¿ èŠããããŸãã
- åå©ã®ç¢ºèªã¯ãè匱æ§ãæ€åºãããªã¹ã¯ã«å¿ããŠåå è ããšã«ç°ãªãå ŽåããããŸãããã«ãŒããååŸã§ããå Žåãåå©ã¯äºãããŸããã
ã«ããŽãªå¥ã®ããã€ã¹ã®ãªã¹ã
ã«ãŒã¿ãŒ
- NETGEAR Nighthawk AC1900ãã¥ã¢ã«ãã³ãWi-Fiã®ã¬ãããã«ãŒã¿ãŒïŒR7000ïŒããªãŒãã³ãœãŒã¹ãµããŒãä»ãã Amazon Echo / Alexaãšã®äºææ§
- Zyxel Armor Z2 AC2600 MU-MIMOã¯ã€ã€ã¬ã¹ã±ãŒãã«ã«ãŒã¿ãŒ
- Synology RT2600acã¯ã€ã€ã¬ã¹ã«ãŒã¿ãŒ
ãããã¯ãŒã¯æ¥ç¶ã¹ãã¬ãŒãž
- Western Digital My Cloud EX2 Ultraã2 Bay-uriãGigabitãDual Coreã1300 MHzã1 GB DDR3ïŒãã°ã«ïŒ
- Qnap TS-251A 2ãã€TS-251AããŒãœãã«ã¯ã©ãŠãNAS / DASãUSBãã€ã¬ã¯ãã¢ã¯ã»ã¹
- Synology DS718 + 2ãã€2GBãã©ãã¯DS718 +
- åNASã«ã¯ïŒ1xïŒWD Black 1TBããã©ãŒãã³ã¹ãã¹ã¯ãããããŒããã£ã¹ã¯ãã©ã€ããè£ åãããŸã
ã»ãã¥ãªãã£ã·ã¹ãã
- ANNKEé²ç¯ã«ã¡ã©ã·ã¹ãã Smart HD 1080P Lite 4 + 1ãã£ã³ãã«DVRã¬ã³ãŒããŒ
- Vstarcam C7833-X4ã¯ã€ã€ã¬ã¹ãªã¢ãŒãHDã«ã¡ã©
家é»è£œå
- Bluesmart One-ã¹ããŒãã©ã²ãŒãž
- HoneyGuaridan S25ã¹ããŒãèªåããããã£ãŒããŒïŒããããŸãã¯ãããããŒãã¯å«ãŸããŸããïŒ
- LED TV Smart Toshibaã81 cm
ããªã³ã¿ãŒ
- Brother HL-L8260CDWã¯ã€ã€ã¬ã¹ã«ã©ãŒã¬ãŒã¶ãŒããªã³ã¿ãŒ
ã³ãŒã«ãããŒããã£ãã·ã¥
- 50ãŠãŒãïŒããããããã€ã¹ã«è€æ°ã®è匱æ§ããããŸãã
- 50ãŠãŒãïŒä»»æã®4ã€ã®ããã€ã¹ã«å¯ŸããŠè€æ°ã®è匱æ§ãèŠã€ããŸãã
- 100ãŠãŒãïŒ9å°ã®ããã€ã¹ã«1ã€ä»¥äžã®è匱æ§ããããŸãã
- 100ãŠãŒãïŒä»»æã®2ã€ã®ããã€ã¹ã®ã«ãŒããååŸããŸãã
- 200ãŠãŒãïŒ6å°ã®ããã€ã¹ã®ã«ãŒããååŸããŸãã
é倧ãªã€ã³ãã©ã¹ãã©ã¯ãã£æ»æ

ã¯ãªãã£ã«ã«ã€ã³ãã©ã¹ãã©ã¯ãã£æ»æã¿ã¹ã¯ã®äžç°ãšããŠãç£æ¥ã·ã¹ãã ã®ãããã³ã°ã®çµéšãç©ãããšãææ¡ãããŸããã ãããè¡ãã«ã¯ã4ã€ã®ãã©ãã¯ããéžæã§ããŸãã
- SCADAã¢ããªã±ãŒã·ã§ã³ïŒå¶åŸ¡ããã³ããŒã¿åéïŒã䜿çšããŠéè¡ããŒã¿ã衚瀺ããééã¹ã€ããã®èªååãå¶åŸ¡ããééã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã¬ã€ã¢ãŠããããã³åçå¯èœãšãã«ã®ãŒæºãåãã倪éœå ããã³é¢šåçºé»æã®ã¢ãã«ã
- ç¹å¥ãªãã¹ããŠããããšã®éã§ä¿¡å·ãéåä¿¡ããä¿è·ãªã¬ãŒãåããæš¡æ¬å€é»æå¶åŸ¡ã·ã¹ãã ã§ãå€é»æã®äžæ¬¡ã¹ã€ããã³ã°ããã€ã¹ã®äžéšã瀺ãåç·å³/åç·å€é»æå³ã«çŽæ¥æ¥ç¶ãããŠããŸãã
- ç£æ¥çšå¶åŸ¡ããã»ã¹ããšãã¥ã¬ãŒããããããã³ã°çšã®ããŸããŸãªPLCã
- ããããã®ç£æ¥çšã¢ãŒã ã
ICS Humla CTF
æªæã®ããããã°ã©ã ãšæ°äžä»£ã®æ»æã¯ã倧ããªçµæžçæ倱ãšäººçæ倱ãåŒãèµ·ããå¯èœæ§ã®ããç£æ¥ã·ã¹ãã ãæšçãšããŠããŸãã ç£æ¥ã·ã¹ãã ã®äŸµå ¥ãã¹ãã«ã¯ãæ·±ãç¥èãšã¹ãã«ãå¿ èŠã§ããããã®æºåã¯æ©åšã®å¯çšæ§ã«äŸåããŸãã ãã®ç«¶äºã¯ãPLCãšã·ãã¥ã¬ãŒã¿ãŒã®èšå®ããªã¢ã«ã¿ã€ã PLCãšSCADAã¢ããªã±ãŒã·ã§ã³ã䜿çšããŠã€ã³ãã©ã¹ãã©ã¯ãã£ãã·ãã¥ã¬ãŒãããåçšããŒããŠã§ã¢ããã€ã¹ã®ãã³ãã¹ãã«çŠç¹ãåœãŠãŠããŸããã
éè¡ãããã¯ãã
ATMã«å¯Ÿããå žåçãªæ»æã¯ãã»ãããŒãATMïŒdaily issuesãïŒç«¯æ«ããã®æ å ±ã®æ©å¯é瀺ãšäžæ£ãªãéã®åŒãåºãïŒã§æ瀺ãããŸããã 競äºã¯2ã€ã®ãã§ãŒãºã«åããããŸããã æåã®æ®µéã§ãåå è ã¯ããŸããŸãªçš®é¡ã®ãã©ãã£ãã¯ïŒãããã¯ãŒã¯ããã³USBïŒãååããŠåæã§ããŸããã 第äºæ®µéã§ã¯ã競æè ã¯ãATMããã€ã¹ã«ã³ãã³ããçºè¡ããããã®USBã€ã³ã¿ãŒãã§ã€ã¹ãšãMiTMæ»æãå®è¡ããããã®ãããã¯ãŒã¯ã€ã³ã¿ãŒãã§ã€ã¹ãžã®ã¢ã¯ã»ã¹ãèš±å¯ãããŸããã 競äºã®ç®çã¯ããéãåŒãåºããŠã«ãŒãããŒã¿ãååããããã®ããŸããŸãªã¢ãããŒãã瀺ãããšã§ãã
競äºæ¡ä»¶ïŒ
- ç®æšã¯ãéè¡ã«ãŒãããæ©å¯æ å ±ãåãåãããATMãããéãåŒãåºãããšã§ãã
- ã³ã³ãã¹ãã«åå ããŠããååå è /ããŒã ã«ã¯ããããã¯ãŒã¯ã«ãŒããšUSBãã©ãã£ãã¯ãåä¿¡ããããã®éè¡ã«ãŒããšè³éãæäŸãããŸããã
- ãµãŒãã¹æåŠæ»æã¯çŠæ¢ãããŠããŸãã
- æ©å¯æ å ±ãåãåãããéãåŒãåºãããã«èŠã€ãã£ãã¢ãããŒãã«ã€ããŠå¿ ãéç¥ããŠãã ããã
- ãã€ã³ãã¯é£æ床ã«åºã¥ããŠä»äžãããŸãã
- USBçµç±ã®æ»æã«å¯ŸããŠè¿œå ãã€ã³ããä»äžãããŸããã
- ããŒã«ãšã¹ã¯ãªããã¯ãåå è ã®è£éã«ãããŸãã
WiFi PWNEDããŒã
Wifi PWNED Boardã¯ã人ãã¯ã€ã€ã¬ã¹æ¥ç¶ãä¿¡é Œããå Žåã®ãªã¹ã¯ããªã¢ã«ã¿ã€ã ã§å®èšŒããŸãã DefCampããŒã ã¯ããããã¯ãŒã¯äžã®ãã©ãã£ãã¯ãèªåçã«åæããä¿è·ã¡ã«ããºã ã䜿çšããã«ã¡ãŒã«ããŠã§ããµã€ãããŸãã¯ãã®ä»ã®ãããã¯ãŒã¯ãµãŒãã¹ã«ã¢ã¯ã»ã¹ãããŠãŒã¶ãŒã®å åãæ¢ããŸããã çµæã¯ãä¿¡é Œã§ããªããããã¯ãŒã¯ã®å±éºæ§ãå šå¡ã«ç€ºãããã«ãWifi PWNEDããŒãã«ããããããæ¹æ³ã§è¡šç€ºãããŸããã ããŒã«ãšããŠã50åã®ã«ãŒã¿ãŒãåããã©ãã¯ã䜿çšãããŸãããããã¯ãŠãŒã¶ãŒã«ãšã£ãŠåœã®Wi-Fiãããã¯ãŒã¯ã§ããã

ã¿ãŒã²ãããžã§ã³
ã¿ãŒã²ãããžã§ã³ã¯ãåå è ãå®éã®ç®æšã«é¢ããããã€ãã®è©³çŽ°ãåãåãããã®ç¹å®ã®å人ãŸãã¯ã°ã«ãŒãã«é¢ããæ å ±ãèŠã€ããªããã°ãªããªã競æã§ãã 競æäžãåå è ã¯æ³å»åŠããã³ãã¹ãããããã¯ãŒã¯æ€çŽ¢ãªã©å€ãã®åéã§èªåèªèº«ã蚌æããããšãã§ããŸããã åå è ã®ã¿ã¹ã¯ã¯ãéç¥ãªãã§ç®æšã¢ã«ãŠã³ãã£ã³ã°ãããã€ãžã£ãã¯ãããããšãããã€ã¹ã®ããã¯ãã¢ãå°å ¥ããããšãªã©ã§ãã
åå ã®ã«ãŒã«ïŒ
- ã¢ãŒãã£ãã¡ã¯ããæ€çŽ¢ããæ¹æ³ã¯éèŠã§ã¯ãããŸããã
- ã¢ãŒãã£ãã¡ã¯ãã®å¯Ÿå¿ããå€ã«åºã¥ããŠãã€ã³ããä»äžãããŸããã
- ããŒãã¹ãã€ã³ãã¯ã極端ãªã¹ã¿ã€ã«ãšåµé æ§ã«å¯ŸããŠæäžãããŸããã
- ããŒã ã®æ倧人æ°ã¯1人ã§ãã
- åçãšãããªã®èšŒæ ãäž»å¬è ã«æäŸãããŸããã
ã¹ã¿ãŒãã¢ããã³ãŒããŒ
ã¹ã¿ãŒãã¢ããã³ãŒããŒã¯ã幎éã®ãªã¬ã³ãžã€ãã³ãããŒãããŒããã¹ã¿ãŒãã¢ãããµããŒããåããæ©äŒã§ãã ã¢ããªã±ãŒã·ã§ã³ã®æåºã®åªå 床ãšã¹ã¿ãŒãã¢ããã®éçºã®çšåºŠã«åºã¥ããŠãæ倧3ã€ã®ã¹ã¿ãŒãã¢ãããéžæãããŸããã
ããšãã
ã¢ãã®ã€ã³ã¿ãŒãããã®å®å šæ§ã«é¢ããçŽæ¥ã®ãã¥ãŒã¹ãèãæ©äŒãããããããã®ã€ãã³ãã¯æçšã§ããããšãããããŸããïŒã¬ããŒãã¯ã以äžã®åºçç©ã§åå¥ã«èª¬æããŸãïŒã

äžæ¹ãå€ãã®è³æã¯ã€ãã³ãããšã«æ°å¹Žã«ããã£ãŠç¹°ãè¿ãããããšãå€ããè³æã®çŠç¹ãçãå Žåã«ã¯ããæå³ã§ãã©ã¹ã«ãªããŸãã ããã©ãŒãã³ã¹ã®ãã¹ãŠã®ãã©ãã¯ã¯åçŽã«çªå·ãä»ããããŠããŸãããã¡ã€ã³ãã©ãã¯ã§ã¯èŽè¡ãåŒãä»ããããã®ããäžè¬çãªè³æã2çªç®ã®ãã©ãã¯ã§ã¯ããžãã¹ãšæè¡ã®50 / 50ã3çªç®ã®-åå¥ã®æè¡è³æãŸãã¯å¹ åºãã²ã¹ãã«èå³æ·±ãããšãå¯ãã«ç¥ã£ãŠããŸãã æ¬ ç¹ã®ãã¡ãä»å¹Žã¯15åéã®ãã¡ã¹ããã©ãã¯ã®å°å ¥ãéå§ãããå€ãã®å Žåãå®å šãªé·ãã®ã¬ããŒãã§ãããšäž»åŒµãããè³æãå«ãŸããŠããããšã«æ³šç®ã§ããŸãã