![ç»å](https://habrastorage.org/getpro/geektimes/post_images/623/ed7/e1d/623ed7e1d7675933eff53d4257c429da.png)
ããã«ã¡ã¯ãïŒ ãŠãŒã¶ãŒåïŒ ã Black Hat Europe 2010ã¯æ¬æ¥ãã«ã»ããã§éå§ãããŸãããä»åæºåããããšãç¥ãããšã¯éåžžã«èå³æ·±ãããšã§ãã ãã®ç¿»èš³ã§ã¯ãã¬ããŒãã®ãããã¯ãšãã®ç°¡åãªèª¬æã瀺ãããŸãã
äžéšã®å°åã§ã¯ã翻蚳ã¯å°ãæªããããããŸãããã圌ããèšãããã«ã圌ãã¯è£çŠã§ãã 翻蚳ã«é¢ããŠã¯ãã³ã¡ã³ã/ä¿®æ£ãæè¿ããŸãã
èè ïŒ
ã¢ã³ãã¬ã¢ãã«ã¹ãããïŒããªã³ãã¥ã¹ïŒã¿ã€ãã«ïŒ
å¿åéä¿¡ã®ããã®ã¯ã€ã€ã¬ã¹ISPã®èª€çšïŒå¿åéä¿¡ãäœæããããã®ã¯ã€ã€ã¬ã¹ãããã€ããŒã®èª€çšïŒèª¬æïŒ
ã»ãšãã©ã®ã¯ã€ã€ã¬ã¹æè¡ã¯ãæ¬è³ªçã«ç©çã¬ãã«ã§ã®åçŽãªãããŒããã£ã¹ãã§ããã€ãŸããå®éã«ã¯ãç¹å®ã®ã«ãã¬ããžãšãªã¢ã®ã©ã¡ãã®åŽã§ãä¿¡å·ãåä¿¡ã§ããŸãã å®å šãªp2pæ¥ç¶ã確ä¿ããããã«ããã®ãããªã¯ã€ã€ã¬ã¹ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯éåžžãæå·ãããã³ã«ã䜿çšããŠãæ¥ç¶ã®äž¡åŽïŒããšãã°ããŠãŒã¶ãŒãšã¹ãã¬ãŒãžã¡ãã£ã¢ïŒãã»ãã·ã§ã³ããŒã確ç«ããŸããã»ãã·ã§ã³ããŒã¯ãæ å ±ãšèªèšŒã³ãŒããæå·åããããšã«ããããã©ã€ããŒãã§èªèšŒãããæ¥ç¶ãäœæããããã«äœ¿çšãããŸãã ä»æ¥ããã®ãããªéä¿¡ãããã³ã«ã®äœæãšåæã«é¢ããèãã¯ã éšå€è ã«é¢ããæ©å¯æ§ãç¶æããå Žåãæ¥ç¶ã®äž¡åŽãæå·ãããã³ã«ã«é¢ããŠæ£ããåäœããå¿ èŠããããšããäºå®ã«åž°çããŸãããã ããã¹ãã¬ãŒãžã¡ãã£ã¢ã®åž¯åå¹ ã®å®¹é/ãªãœãŒã¹ã倧ããå ŽåããŠãŒã¶ãŒã¯æ¥ç¶ãéšå€è ããä¿è·ããããšã«é¢å¿ããªãå ŽåããããŸããã代ããã«éä¿¡ãããã³ã«ã®å éšè æ»æã«ãã£ãŠå®¹é/ãªãœãŒã¹ãæ¡å€§ããããšããå ŽåããããŸãã ãããŠãã¬ããŒãã®èè ãç¥ãéãããããã·ããã®ãã®ãããªæ°ããè åšã¯ãŸã ç¡èŠãããŠããŸãã
ãã®ã¬ããŒãã§ã¯ããªãœãŒã¹ãã£ãªã¢ã«ãã£ãŠéå§ãããå®å šãªéä¿¡ã劚害ããããã€ãã®ã¿ã€ãã®ã€ã³ãµã€ããŒæ»æã玹ä»ããŸãã è¡æã€ã³ã¿ãŒããããããã€ããŒã¯ããŠãŒã¶ãŒããµãŒãã¹ãããã€ããŒãšç·å¯ã«æ¥ç¶ããŠããäžæ¹ã§ãã€ã³ã¿ãŒããããããã€ããŒãåºå€§ãªãšãªã¢ã§ä¿¡å·ãéä¿¡ã§ãããããé®®æãªäŸãšããŠåœ¹ç«ã¡ãŸãã ãã®ããããã®ã¬ããŒãã§ã¯äž»ã«è¡æã€ã³ã¿ãŒããããããã€ããŒã«é¢é£ããæ»æã«ã€ããŠèª¬æããŠããŸãããWiMAXã«ã€ããŠã觊ããŸãã
è¡æãããŠãŒã¶ãŒã«éä¿¡ããããã¹ãŠã®ããŒã¿ãæå·åããå¿ èŠãããã«ãããããããæ瀺ãããæã匷åãªæ»æã«ããããšã³ããŠãŒã¶ãŒã¯ãããã€ããŒãéããŠã¯ãªã¢ããã¹ãã§ããŒã¿ããããŒããã£ã¹ãã§ããŸãã
æåŸã«ãèè ã¯ãæ瀺ãããçµæã䜿çšããŠéä¿¡ãã£ãã«ã確ç«ããåä¿¡è ã®å®å šãªå¿åæ§ãå®çŸããæ¹æ³ã«ã€ããŠè°è«ããäºå®ã§ãã
èè ïŒ
Iftach Ian AmitïŒã»ãã¥ãªãã£ïŒã€ãããŒã·ã§ã³ïŒã¿ã€ãã«ïŒ
ãµã€ããŒ[ç¯çœª|æŠäº]å±éºãªæ°Žãã°ã©ãåïŒCharts of Cyberââ [ç¯çœª|æŠäº]ïŒèª¬æïŒ
éå»æ°å¹Žéããµã€ããŒæŠäºã¯ããªãç©è°ãããããŠããŸããã ãã®çšèªã¯äžè¬çã«ééã£ãŠãããšèšã人ãããŸãã äžæ¹ããµã€ããŒç¯çœªã¯ã管èœæš©ãšæ³å·è¡æ©é¢ã®æ¬ åŠãçµç¹ç¯çœªããã®æé«ã®åå ¥æºã®1ã€ãšãªã£ãããã倧ããªæžå¿µææã§ããã ãã®ã¬ããŒãã§ã¯ãèè ã¯ãµã€ããŒç¯çœªãšãµã€ããŒæŠäºã®éããæ¢ããäž»ãªä¿³åªïŒäž»ã«åœå®¶åŽïŒã匷調ããéå ã«å¯Ÿããéå»ã®æ»æããµã€ããŒç¯çœªçµç¹ãšçµã³ä»ããŸãã èè ã¯ãŸãããµã€ããŒæŠäºãšåŸæ¥ã®æŠäºãšã®é¢ä¿ãããã³ãµã€ããŒã»ãã¥ãªãã£ã䜿çšããçŸä»£ã®ãã£ã³ããŒã³ã§äœ¿çšãããæ¹æ³ã調ã¹ãŸããèè ïŒ
ãããã¯ãã¹ã¢ã«ã®ããã£ã¹ïŒåœå¢èª¿æ»æ ªåŒäŒç€ŸïŒã¿ã€ãã«ïŒ
ããŒã¢ã³ã®ãã€ã³ãïŒFreeBSDã«ãŒãã«ã¹ã¿ãã¯ãšããŒãã®æŽ»çšïŒFreeBSDã«ãŒãã«ãšã¹ã¿ãã¯æäœïŒèª¬æïŒ
FreeBSDã¯ãããªãŒãœãããŠã§ã¢ãšãããã©ã€ãšã¿ãªãœãããŠã§ã¢ã®äž¡æ¹ã§å©çšå¯èœãªæãä¿¡é Œæ§ãé«ãå¹ççãªãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®1ã€ãšããŠåºãèªèãããŠããŸãã ã«ãŒãã«ã®è匱æ§ã®æªçšã¯ãWindowsããã³Linuxãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãã¬ãŒã ã¯ãŒã¯å ã§ç 究ãããŠããŸãããFreeBSDããã³BSDã·ã¹ãã ã¯äžè¬çã«ããã»ã©æ³šç®ãããŠããŸããã ãã®ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ããŸãFreeBSDã«ãŒãã«ã¹ã¿ãã¯ãªãŒããŒãããŒã®åäœã瀺ããŸãã ç¹æš©ææ Œã®ããã®ãšã¯ã¹ããã€ãéçºããã»ã¹ã¯ãCVE-2008-3531ã§ææžåãããŸãã ãã¬ãŒã³ããŒã·ã§ã³ã®2çªç®ã®éšåã§ã¯ãFreeBSD-Universal Memory AllocatorïŒUMAïŒã®ã¡ã¢ãªç®¡çã¡ã«ããºã ã®ã»ãã¥ãªãã£ã®è©³çŽ°ãªåæã瀺ããŸãã ãŸããUMAãªãŒããŒãããŒã«ãããææ°ã®å®å®ããFreeBSDã«ãŒãã«ïŒ8.0-RELEASEïŒã®ã³ã³ããã¹ãã§ä»»æã®ã³ãŒããå®è¡ãããå¯èœæ§ãããç¶æ³ãèæ ®ããŸããèè ïŒ
ãžã§ãŒã ã¹ã¢ãŒã¬ã³ïŒããã·ã¥ã¹ã¿ãã¯ã³ã³ãµã«ãã£ã³ã°ïŒã¿ã€ãã«ïŒ
ã»ãã¥ãªãã£å°é家åãã®SCADAãšICSïŒãµã€ããŒçœçŽã«ãªãã®ãé¿ããæ¹æ³ïŒã»ãã¥ãªãã£å°é家åãã®SCADAãšICSïŒãµã€ããŒéŠ¬é¹¿ã«ãªãã®ãé¿ããæ¹æ³ïŒèª¬æïŒ
ã¬ããŒãã®èè ã¯ãäœããã®çç±ã§ãäŒçµ±çãªã»ãã¥ãªãã£æ¥çããçœã銬ã®éšå£«ã®ããã«ãå®å šã§ãªããã€ãã©ã€ã³ãååŠãã©ã³ãããã®ä»ã®ã¯ãããŒå·¥å Žã®ææããå šå¡ãæãããšã決å®ããããšãäŒããããšèããŠããŸãã ããããçªç¶ããã¹ãŠã®ã³ã³ãµã«ã¿ã³ããçªç¶å°é家ã«ãªããå補åã¯SCADAã»ãã¥ãªãã£ã®åé¡ã«å¯ŸåŠããèœåãåºã宣äŒããŠããŸãã ããããäž»ã«åœŒããäœãèšã£ãŠããã®ãããããªãããã圌ãã¯ç§ãã¡å šå¡ã銬鹿ã®ããã«èŠããŸãã ãããã£ãŠãèè ã¯èª°ããå¹³åçã«åº§ããSCADAãšICSã«ã€ããŠè©±ãåãããšãææ¡ããŸãããããã£ãŠãäžç·ã«çºçããåé¡ã解決ããŸãã èè ã¯ããµã€ããŒéŠ¬é¹¿ã«ãªãã®ããããæãæ¥ããšäž»åŒµããããªãã¯å šäœçãªãœãªã¥ãŒã·ã§ã³ã«ããã€ãã®ç©æ¥µçãªè²¢ç®ãããå¿ èŠããããŸããèè ïŒ
Christiaan BeekïŒTenICT BVïŒã¿ã€ãã«ïŒ
ä»®æ³æ³å»åŠèª¬æïŒ
ãã®ã¬ããŒãã§ã¯ãä»®æ³åç°å¢ã調æ»ããéã«çŽé¢ããåé¡ã«ã€ããŠèª¬æããŸãã èè ã¯ããä»®æ³åã·ã¹ãã ãšæšæºã·ã¹ãã ã§ã®èª¿æ»æè¡ãšããŒã«ã®éããããCitrixã·ã¹ãã ãšVMWareã·ã¹ãã ã§èª¿æ»ãè¡ãéã«æãéèŠãªãã¡ã€ã«ãããVMDKãã¡ã€ã«ã·ã¹ãã ãšãã®å°æ¥ã®èª¿æ»ã«ã€ããŠããªã©ã®è³ªåãæèµ·ããŸããèè ïŒ
ãã«ã³ã»ããããã£ïŒCutaway srlïŒã¿ã€ãã«ïŒ
æºåž¯é»è©±ã®åç¶ïŒTorã䜿çšããã¢ãã€ã«éä¿¡ã®ä¿è·èª¬æïŒ
èè ã¯ãTorã¯ãå人ã®èªç±ãšé¢ä¿ã®æ©å¯æ§ãè ããç£èŠã®åœ¢æ ãªã©ããããã¯ãŒã¯ãã©ãã£ãã¯ã®åæãã身ãå®ãã®ã«åœ¹ç«ã€ãœãããŠã§ã¢è£œåã§ããããšãæãåºãããŠãããŸãã Torã¯ãäžçäžã®ãã©ã³ãã£ã¢ãç«ã¡äžãããµãŒããŒã®åæ£ãããã¯ãŒã¯å šäœã«ãããã¯ãŒã¯ãã©ãã£ãã¯ãã±ãããã«ãŒãã£ã³ã°ããããšã§ä¿è·ãæäŸããå®éã®å°ççäœçœ®ãç¥ãããšãé²ããŸããæ®å¿µãªããããã©ãŠã¶ã«çµã¿èŸŒãŸããæ°ããHTML5æ©èœãšäœçœ®æ å ±æè¡ã«ããããŠãŒã¶ãŒããã©ã€ãã·ãŒãç¶æããããšã¯ãŸããŸãé£ãããªã£ãŠããŸãã
ãã®ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ãäžèšã®ãã¹ãŠã®åé¡ãšãTorãŠãŒã¶ãŒã§ãããããå®è£ ã§ããæ¹æ³ã«ã€ããŠèª¬æããŸãã ãŸããã¢ãã€ã«ãŠãŒã¶ãŒã®ãã©ã€ãã·ãŒã®åé¡ã解決ããæ¹æ³ã«ã€ããŠã説æããŸãã
èè ïŒ
Stephan ChenetteïŒWebsense Security LabsïŒã¿ã€ãã«ïŒ
Fireshark-æªæã®ããWebããªã³ã¯ããããŒã«ïŒFireshark-ãã¹ãŠã®æªæã®ãããããã¯ãŒã¯ããã°ã©ã ãåéããïŒèª¬æïŒ
æ°åã®æ£åœãªãµã€ãããäœçŸäžãã®èšªåè ãžã®æªæã®ããã³ã³ãã³ãã®æ¡æ£ã«è²¢ç®ããŠããŸãã ãµã€ãéã®ãã¿ãŒã³ãèŠã€ããããã«ãã¹ãŠã®ç 究ãäžç·ã«çµã¿åãããããšããè©Šã¿ã¯ãããªãå°é£ãªã¿ã¹ã¯ã§ãããäžéšã®èªç±ã«é åžãããããŒã«ã䜿çšãããšè§£æ±ºã§ããªãå ŽåããããŸããèè ã¯ãFiresharkïŒfire sharkïŒãšåŒã°ããç 究ãããžã§ã¯ãã玹ä»ããŸãããã®ãããžã§ã¯ãã§ã¯ãèšå€§ãªæ°ã®ãµã€ãã蚪åããªãããããããã®ã³ã³ãã³ããå®è¡ãä¿åãåæããããšãã§ããŸãã ãã®ããã°ã©ã ã®åæã«åºã¥ããŠããµã€ãã®ã»ãã¥ãªãã£ã«é¢ããçµè«ãåŒãåºãããšãã§ããŸãã
èè ïŒ
ããªã¢ãŒãã»ããã§ã¹ã»ãã£ã»ã¯ããŒãã§ïŒONAPSISïŒã¿ã€ãã«ïŒ
SAPããã¯ãã¢ïŒããžãã¹ã®äžå¿ã«ãããŽãŒã¹ãïŒSAPããã¯ãã¢ïŒããžãã¹ã®äžå¿ã«ãããŽãŒã¹ãïŒèª¬æïŒ
ã©ã®äŒæ¥ã§ããERPïŒãšã³ã¿ãŒãã©ã€ãºãªãœãŒã¹ãã©ã³ãã³ã°ïŒã¯ããžãã¹ã®äžå¿ã§ãã ãããã®ã·ã¹ãã ã¯ã調éãè«æ±ã人äºããªãœãŒã¹ç®¡çã財åèšç»ãªã©ã®ããã»ã¹ãæŽçããããã«èšèšãããŠããŸãã ãããã®ã·ã¹ãã ã®äžã§ãSAPã¯æãéç«ã£ãŠããã120ãåœä»¥äžã«90,000人以äžã®é¡§å®¢ãããŸãããã®ãããªã·ã¹ãã ã«ä¿åãããŠããæ å ±ã¯ãäŒæ¥ã«ãšã£ãŠæãéèŠãªãã®ã§ãããäžæ£ãªæäœã¯çµæžçæ倱ãšè©å€ã®äœäžã«ã€ãªããå¯èœæ§ããããŸãã
ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ãSAPã®ããã¯ãã¢ã«çŠç¹ãåœãŠãŸããèè ã¯ãæ»æè ãSAPã·ã¹ãã ã§ããã¯ãã¢ãäœæããã³ã€ã³ã¹ããŒã«ããããã«äœ¿çšã§ããããŸããŸãªæ¹æ³ã«ã€ããŠèª¬æããŸãã ãã®åŸãèè ã¯ãã®ãããªæ»æãåé¿ããããšãç®çãšããããã€ãã®å¯Ÿçãå°å ¥ããã»ãã¥ãªãã£ãããŒãžã£ãŒãSAPã·ã¹ãã ã®äžæ£ãªå€æŽãèªåçã«æ€åºã§ããæ°ããç¡æããŒã«Onapsisãå°å ¥ããŸãã
èè ïŒ
ã¢ã³ããžã§ã»ãã¬ã¹ãŸãŠã¹ãïŒ3MïŒã¿ã€ãã«ïŒ
eMRTDã»ãã¥ãªãã£ã³ã³ãããŒã«ã®æ€èšŒèª¬æïŒ
ãšãŒãããã§ã®é»åæž¡èªææžãžã®ç§»è¡ã«äŒŽããèªèšŒæè¡ã®æ£ããå®è£ ãæ€èšŒããããšãæ¥åã§ããã ããã«åºã¥ããŠãèè ã¯é»åææžïŒeMRTD-é»åæ©æ¢°èªã¿åãå¯èœãªæ è¡ææžãçŽPerïŒã®ã»ãã¥ãªãã£ç®¡çãæ€èšããããšèããŠããã圌ã®æèŠã§ã¯ãèå¥ã¡ã«ããºã ã®æãæ£ããå®è£ ãæäŸãã誀ã£ãå®è£ ã®ãã¹ãŠã®å±éºæ§ãšãã®åŸã®ãã¹ãŠã®å±éºæ§ã瀺ããŠããŸãåé¡ã®çµæãèè ïŒ
ã©ãŠã«ã»ãã³ã¹ã¿ïŒã·ã°ãã«11ïŒã¿ã€ãã«ïŒ
æšçåæ»æïŒè¢«å®³è ããæ»æã«å¯ŸæããïŒæšçåæ»æïŒè¢«å®³è ããæ»æè ãžã®ç§»è¡ïŒèª¬æïŒ
ãã®ãã¬ãŒã³ããŒã·ã§ã³ã¯ãå€ãã®çµç¹ã«å¯ŸããŠçŸåšé²è¡äžã®æšçåæ»æã®åæã§ãã çµå±ã®ãšãããç¡æã®ãªã¢ãŒãã¢ã¯ã»ã¹ã·ã¹ãã ïŒRATïŒã¯ãäŸµå ¥ãæåããåŸã«è¢«å®³è ã®å¶åŸ¡ãç¶æããããã«ãã䜿çšãããŸãã ãã®ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ãç¹å®ã®æ»ææ¹æ³ã«çŠç¹ãåœãŠãã®ã§ã¯ãªããRATã«çŠç¹ãåœãŠãŸãããã¬ãŒã³ããŒã·ã§ã³ã§ã¯ã䜿çšãããç¹å®ã®ããã€ã®æšéŠ¬ãç¹å®ããæ¹æ³ïŒã¢ãŒããã¯ãã£ãæ©èœãã·ã¹ãã å ã®ååšãé ãæ¹æ³ïŒã«ã€ããŠèª¬æããŸãã æåŸã«ãæ»æããŒã«ã®è匱æ§ã®æ€çŽ¢ã衚瀺ãããæ»æè èªèº«ã被害è ã«ãªãå¯èœæ§ããããŸãã
èè ïŒ
ã¿ã€ã»ãºãªã³ïŒãžã¥ãªã¢ãŒãã»ãªããŸïŒVNSECURITYïŒã¿ã€ãã«ïŒ
Webã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããå®çšçãªæå·æ»æ説æïŒ
2009幎ãèè ã¯ãããããFlickrãVimeoãScribdãªã©ã®ãµã€ãã§ãããããMD5ã«å¯Ÿããæ»æã®å¯èœæ§ã瀺ããŸããã ãã®ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ãèè ã¯å¥ã®åæ§ã«åŒ·åãªæå·æ»æã察象ãšããç 究ã®ææ°çµæãæ瀺ããããšèããŠããŸããèè ã¯ãåºã䜿çšãããŠããææ°ã®Webéçºãã¬ãŒã ã¯ãŒã¯ã®å€ããæå·åã誀ã£ãŠäœ¿çšããŠãããããæ»æè ãæ©å¯ããŒã¿ãèªã¿åã£ãŠå€æŽã§ããããšã瀺ããŸãã Padding Oracleæ»æãeBayã©ãã³ã¢ã¡ãªã«ãApache MyFacesãSUN MojjaraãRuby On Railsãªã©ã®äŸãæäŸãããŸãã èè ã¯ããããã¯ãã¹ãŠãŒããã€ïŒãŒããã€ïŒè匱æ§ã§ãããšäž»åŒµããŠããŸãã
èè ïŒ
ãšãªãã¯ãã£ãªãªãŒã«ïŒESIEAïŒã¿ã€ãã«ïŒ
匱ãã¹ããªãŒã æå·ã®èª€çšãæäœçã«æ€åºããŠç Žå£ããæ¹æ³ïŒå Žåã«ãã£ãŠã¯ãããã¯æå·ãããïŒ-Office Encryption Cryptanalysisãžã®å¿çšïŒåŒ±ãã¹ããªãŒã æå·ã®äœ¿çšããã°ããæ€åºããæ¹æ³-Office cryptanalysisã¢ããªã±ãŒã·ã§ã³ïŒèª¬æïŒ
ãããã¯æå·ã¯åºã䜿çšãããŠããŸãããã¹ããªãŒã æå·ã¯è¡æéä¿¡ãæ°ééä¿¡ããœãããŠã§ã¢ãªã©ã®åéã§äŸç¶ãšããŠåºã䜿çšãããŠããŸãã ããããã¹ããªãŒã æå·ã®äœ¿çšã¯æå·åããŒã®äžé©åãªæäœã®ããã«å®å šã§ã¯ãããŸãããããã¯ãŸãã«ã¬ããŒãã®èè ã䞻匵ããŠããããšã§ãã ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ããã®ãããªãšã©ãŒãç¹å®ããããã¹ããããªãçæéã§å埩ããæ¹æ³ã説æããŸããããšãã°ãã¬ããŒãã®äœæè ã¯ãäž»ã«WordãšExcelã泚ç®ãã2003ããŒãžã§ã³ïŒRC4ïŒãŸã§ã®Officeã§äœ¿çšãããŠããæå·åã®æå·è§£æã«ã€ããŠèª¬æããŸãã æ°ç§ã§ããœãŒã¹ã³ãŒãã®90ïŒ ä»¥äžãå埩ã§ããããã«ãªããŸãã
èè ïŒ
FXïŒREcurity LabsïŒã¿ã€ãã«ïŒ
貧ãã人ã ãå®ãïŒè²§ãã人ã ãå®ãïŒèª¬æïŒ
ããã¯ããªããã€ã³ã¿ãŒãããã¢ããªã±ãŒã·ã§ã³ã³ã³ãã³ãïŒRIAïŒã³ã³ãã³ããä¿è·ããããã®ã·ã³ãã«ã ãå¹æçãªã¢ãããŒãã§ãã ãã¯ãããžãŒå šäœã«å¯Ÿããæ»æãå¯èœã«ããããã€ãã®å éšAdobe Flashã¡ã«ããºã ã«ã€ããŠèª¬æããŸãã ãããã®åŽé¢ã®ããã€ãã¯ããªããç¬é¡ã«ããä»ã®åŽé¢ã¯ããªããã²ããŸããŸãã ãããã®ã¡ã«ããºã ã®æ瀺ãšãšãã«ãä¿è·ã®ã¢ã€ãã¢ããçè«ã ãã§ãªãå®éã«ããå®è£ ãããã³ãŒãã®åœ¢ã§ããããŠå®äžçã§ã®ãã®é©çšã®çµæãšããŠç€ºãããŸããèè ïŒ
Thanassis GiannetsosïŒREcurity LabsïŒã¿ã€ãã«ïŒ
ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®æŠåšåïŒã»ã³ãµãŒãããã¯ãŒã¯ã«å¯Ÿããæ»æãéå§ããããã®æ»æããŒã«ïŒã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®æŠåšåïŒã»ã³ãµãŒãããã¯ãŒã¯ãžã®æ»æïŒèª¬æïŒ
èªåŸåã¿ããããã€ã¹ã®ãŠããã¿ã¹ãªçµã¿åããã¯ãå¹ åºãçš®é¡ã®æ°ããã¢ããªã±ãŒã·ã§ã³ãçã¿åºããŸããã ããããåæã«ãã»ã³ãµãŒããŒãã®èªåæ§ãšéããããªãœãŒã¹ã«ãããæ»æè ããããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãååŸããããã«äœ¿çšã§ããã®ãšåãæ°ã®è匱æ§ãäœæãããŸããã ãã®ãããªãããã¯ãŒã¯ãä¿è·ããããã«å€ããè¡ãããŸããããã»ã³ãµãŒãããã¯ãŒã¯ã®è匱æ§ã蚌æããããŒã«ãäœæããããã«è¡ããããã®ã¯ã¯ããã«å°ãªãã§ãããã®ãã¯ã€ãããŒããŒã§ã¯ããããã¯ãŒã¯ã§ååçãªåµå¯ãè¡ãã ãã§ãªããããŸããŸãªæ¹æ³ã§æ»æããŠãããã¯ãŒã¯ä¿è·ã®åŒ·åºŠããã¹ãã§ããããŒã«ã玹ä»ããŸãã èè ãç¥ãéãããã®ããŒã«ã¯ãã®çš®ã®ãã®ãšããŠã¯åããŠã®ãã®ã§ãã çµæã¯ããã®ããŒã«ãéåžžã«æè»ã§ãããããŸããŸãªã»ã³ãµãŒãããã¯ãŒã¯ãããŸããŸãªãããã³ã«ã¹ã¿ãã¯ã«ç°¡åã«é©å¿ã§ããããšã瀺ããŠããŸãã èè ã¯ããã®éçºãæ°ãããããã¯ãŒã¯ãããã³ã«ã®åŒ±ç¹ãç¹å®ããããã«ãã£ãŠã»ãã¥ãªãã£ã¬ãã«ãåäžãããããšãæåŸ ããŠããŸãã
èè ïŒ
ãžã§ãŒã°ã©ã³ãïŒã°ã©ã³ãã¢ã€ãã£ã¢ã¹ã¿ãžãªïŒã¿ã€ãã«ïŒ
ããŒããŠã§ã¢ã¯æ°ãããœãããŠã§ã¢ã§ã説æïŒ
æè¡ã®çå®ãªæé·ã«ããã瀟äŒã¯ç¹æ ããŠããŸãã ãšã¬ã¯ãããã¯ã¹ã¯ãç§ãã¡ã觊ãããã¹ãŠã®ãã®ã«ãã§ã«å«ãŸããŠããŸãã çŸåšãããŒããŠã§ã¢è£œåã¯ã»ãã¥ãªãã£é¢é£ã®ã¢ããªã±ãŒã·ã§ã³ã«äŸåããŠããŸãããä¿¡é Œãããªããã°ãªããŸããããå€ãã®å Žåãæ°å幎ã«ããã£ãŠç¥ãããŠããæãåçŽãªã¯ã©ã¹ã®æ»æãããããä¿è·ããŸãããDIYã®è¶£å³ãæ©åšãžã®ç°¡åãªã¢ã¯ã»ã¹ãã€ã³ã¿ãŒãããããã®å³ææ å ±æ€çŽ¢ã«ãããã³ã³ãã¥ãŒã¿ãŒã®ã»ãã¥ãªãã£ãæ€èšããéã«ããŒããŠã§ã¢ãå²ãåŒãããšã¯ã§ããªããªããŸããã ã¬ããŒãã§ã¯ãèè ã¯ãããã³ã°ããŒããŠã§ã¢ããã»ã¹ãæ瀺ããé»åããã€ã¹ã«å¯Ÿããããã€ãã®æ»æã瀺ããŸãã
èè ïŒ
Vincenzo IozzoïŒZynamics GmbHïŒã¿ã€ãã«ïŒ
0ç¥èãã¡ãžã³ã°ïŒäºåãã¬ãŒãã³ã°ãªãã®ãã¡ãžã³ã°ïŒèª¬æïŒ
ãã¡ãžã³ã°ã¯çŸåšãæ»æè ãšéçºè ã®äž¡æ¹ã䜿çšããããªãäžè¬çãªææ³ã§ãã éåžžããããã³ã«ãŸãã¯å ¥åããŒã¿ã®åœ¢åŒã«é¢ããç¥èãšããã®å ¥åãã¢ããªã±ãŒã·ã§ã³å ã§ã©ã®ããã«åŠçããããã«ã€ããŠã®äžè¬çãªç解ãå«ãŸããŸãã以åã¯ããã¡ãžã³ã°ã䜿çšããŠãããããªåŽåã§å°è±¡çãªçµæãåŸãããšãã§ããŸããã çŸåšãäžè¬çãªåºç¯å²ã®è匱æ§ãéçºè ã«ãã£ãŠãã§ã«ç¹å®ãããä¿®æ£ãããŠããããããšã©ãŒã®æ€çŽ¢ã«ã¯ã³ãŒãããã³ãŠãŒã¶ãŒã³ãŒãå ã®ãã¯ããŒã«ããå¿ èŠã§ãã
ã¬ããŒãã§ã¯ããŠãŒã¶ãŒå ¥åã®åœ¢åŒãç¥ããªããŠããã¡ãžã³ã°ã®å¹æçãªäœ¿çšã«ã€ããŠèª¬æããŸãã ç¹ã«ãã³ãŒãã«ãã¬ããžãããŒã¿ã®æ±æãã¡ã¢ãªå ã®ãã¡ãžã³ã°ãªã©ã®ææ³ã«ãããç¹å¥ãªããŒã«ãªãã§ã¹ããŒããã¡ã¶ãŒãæ§ç¯ã§ããããšãå®èšŒãããŸãã
//翻蚳è ã®ã¡ã¢
ãã¡ãžã³ã°ã¯ãäºæãããå ¥åããŒã¿ã§ã¯ãªãã©ã³ãã ããŒã¿ãããã°ã©ã ã«éä¿¡ããããšãã«ããã°ã©ã ããã¹ãããããã®æè¡ã§ãã ããã°ã©ã ãããªãŒãºãŸãã¯ã¯ã©ãã·ã¥ããå Žåãããã¯ããã°ã©ã ã®æ¬ é¥ã§ãããšã¿ãªãããè匱æ§ã®çºèŠã«ã€ãªããå¯èœæ§ããããŸãã ãã¡ãžã³ã°ã®å€§ããªå©ç¹ã¯ããã®åçŽããšèªååææ©èœã§ãã
èè ïŒ
Haifei LiïŒGuillaume LovetïŒãã©ãŒãã£ãããæ ªåŒäŒç€ŸïŒã¿ã€ãã«ïŒ
Adobe Readerã®ã«ã¹ã¿ã ã¡ã¢ãªç®¡çïŒãã©ãã«ã®å±±ïŒAdobe ReaderïŒããŒãã®ãã©ãã«ïŒèª¬æïŒ
PDFã®è匱æ§-åžžã«è±ªè¯ã§ãã 2010幎ã®äºæž¬ã§ã¯ãäžéšã®ãŠã€ã«ã¹å¯ŸçäŒæ¥ã¯ããµã€ããŒç¯çœªè ã®ãªã¯ãšã¹ãã«èµ·å ããPDFã®è匱æ§ã®æ°ã®å¢å ã«ã€ããŠè¿°ã¹ãŠããŸãã ããããããã¯äºæž¬ããããã®ãšæ¯èŒããŠã©ãã»ã©æ·±å»ã§ãããFUDïŒFUD-Fear-Uncertainty-Doubt-fear-uncertainty-doubtïŒã®ã·ã§ã¢ã¯ã©ããããã§ããïŒ æçµçã«ãå€ãã®PDFã®è匱æ§ã¯ãã¡ã€ã«æ§é ïŒåœ¢åŒïŒã«é¢é£ããŠãããããããŒãã®ç Žæç¶æ³ã«ã€ãªãããŸãã ãããŠèª°ãããããŒããã¡ãŒãžããšã¯ã¹ããã€ããèšè¿°ãããŠããæ·±å»ãªè匱æ§ã®ã«ããŽãªãŒã«å ¥ãããšã¯ã»ãšãã©ãªãããšãç¥ã£ãŠããŸãã ãã®ãããMS WindowsããŒãã¯ã»ãšãã©äºæž¬ã§ãããå®å šãªãªã³ã¯è§£é€ãªã©ã®ã¡ã«ããºã ã«ãã£ãŠä¿è·ãããŸããæã人æ°ã®ããPDFãªãŒããŒã§ããAdobe Readerã¯ã以åã®ã¹ããŒãã¡ã³ãã確èªã§ããç¹å®ã®ã¢ãŒããã¯ãã£ãåããŠããŸãã çç£æ§ãé«ããããã«ãã·ã¹ãã 1ã®äžã«ç¬èªã®ããŒã管çã·ã¹ãã ãå®è£ ããŠããŸãã ããããããã©ãŒãã³ã¹ãã»ãã¥ãªãã£ã®æµã«ãªãããšããããŸãããã®ããŒã管çã·ã¹ãã ã¯ãè匱æ§ãæªçšããæ¹ãã¯ããã«ç°¡åã§ãã ãã¬ãŒã³ããŒã·ã§ã³ã§ç°¡åã«ç€ºãããFlashã®DEPãã€ãã¹ïŒJITã¹ãã¬ãŒïŒã«é¢é£ããæè¿ã®ã€ãã³ããšäžç·ã«ãããŒãã®æäœã¯éåžžã«ç°¡åãªé€é£ã«ãªããŸãã
ãã®çµæãã¬ããŒãã§ã¯ããŒã管çã·ã¹ãã ã調æ»ããPDFã®è匱æ§ã®åé¡ãæããã«ããããã«éèŠãªåŒ±ç¹ãç¹å®ããŸãã
//翻蚳è ã®ã¡ã¢
FUD-Fear-Uncertainty-Doubt-ææ-äžç¢ºå®æ§-çãã
競åä»ç€Ÿã®è£œåã®æ¶è²»è ïŒãŸãã¯æœåšçãªæ¶è²»è ïŒã«æ£ããéžæãšæãŸãããªãçµæã®æ¬ åŠãçãããããã«èšèšããã声æã®æ®åã«ãããäžå ¬æ£ãªç«¶äºã®æ¹æ³ã®ååã 競åä»ç€Ÿã®è£œåãçãæ¶è²»è ã¯ãããç¥ãããŠããååãçã-æåŠãã«ãã£ãŠå°ãããããããç²åŸããå¯èœæ§ã¯äœããšæ³å®ãããŸãããããã£ãŠãåžå Žãã競åä»ç€ŸãæŒãåºãããã»ã¹ãä¿é²ããŸãã
å®å šãªãªã³ã¯è§£é€ã¯ãããŒãã®ä¿è·ãç®çãšããæè¡ã§ãã åæ¹åãªã¹ããã空ããããã¯ãåé€ããåã«ãååŸã®ã¡ã¢ãªãããã¯ãžã®ãã€ã³ã¿ã®ä¿¡é Œæ§ããã§ãã¯ããããšã«ãããŸãã
èè ïŒ
ããŽã£ããã»ãªã³ãŒã€ïŒãšãã¥ã¢ã«ãã»ãŽã§ã©ã»ããïŒCigitalïŒã¿ã€ãã«ïŒ
IE8s XSSãã£ã«ã¿ãŒãä»ãããŠãããŒãµã«XSSïŒIE8 XSSãã£ã«ã¿ãŒããã€ãã¹ãããŠãããŒãµã«XSSïŒèª¬æïŒ
ãåãã®ãšãããIE8ã«ã¯XSSæ€åºããã³é²æ¢ãã£ã«ã¿ãŒãçµã¿èŸŒãŸããŠããŸãã èè ã¯ããã£ã«ã¿ãŒãæ»æãæ€åºããæ¹æ³ã®è©³çŽ°ã瀺ãããã®äž»ãªå©ç¹ãšæ¬ ç¹ã«ã€ããŠèª¬æããŸãã ãŸããèè ã¯ãã£ã«ã¿ãŒã被害è ã«ãªãããã€ãã®æ¹æ³ã瀺ããè匱æ§ã®ãªããµã€ãã§XSSãèš±å¯ããŸãã ãã®è匱æ§ã«ãããã»ãšãã©ã®ãµã€ããIE8ã䜿çšããŠXSSã«å¯ŸããŠè匱ã«ãªãæ¹æ³ã瀺ããŸããèè ïŒ
ã¢ãã·ãŒã»ããŒãªã³ã¹ãã€ã¯ïŒç Žå£çç 究æ©é¢ïŒã¿ã€ãã«ïŒ
è åšã®ãã©ã€ãã·ãŒãžã®å€æŽïŒTIAããGoogleãžïŒãã©ã€ãã·ãŒã®è åšã®å€æŽïŒTIAããGoogleãžïŒèª¬æïŒ
ç§ãã¡ã¯æå·åã®ããã®æŠäºã«åã¡ãŸããããŸã å¿åã®å°äžãããã¯ãŒã¯ããããåæ£ãããã¯ãŒã¯ãçŸå®ã«ãªã£ãããã§ãã ãã®ãããªãããã¯ãŒã¯éä¿¡æŠç¥ã¯ãæãæªæ¥ãèŠè¶ããŠèæ¡ãããŸããããã©ãããããããããã®åªåã¯ãç§ãã¡å šå¡ãçŽé¢ãããã©ã€ãã·ãŒã®è åšããã®ä¿è·ã«ã€ãªãããŸããã§ããã代ããã«ãç§ãã¡ã®ãã¹ãŠã®éä¿¡ãšåãã®éäžç¶æ ããŒã¿ããŒã¹ããããçŸä»£ã®ãã©ã€ãã·ãŒã®è åšã¯ãŸããŸãäžåãªæå³åãã垯ã³ãŠããŸãã èè ã¯ããã®åéã®æ°ããåŸåã«ã€ããŠè©±ãããšãææ¡ããããã€ãã®èå³æ·±ã解決çãæ瀺ããŸãã
èè ïŒ
ã¹ãã£ãŒããªã»ããã¯ïŒãŠã§ã³ãã«G.ãšã³ãªã±ïŒTrustwaveïŒã¿ã€ãã«ïŒ
OracleãäžæïŒã»ãã·ã§ã³ãšè³æ Œæ å ±ãçãïŒOracleïŒã»ãã·ã§ã³ãšè³æ Œæ å ±ãçãïŒèª¬æïŒ
ç¡æã§åºãæ®åããŠããæå·åã©ã€ãã©ãªã®äžçã§ã¯ãå€ãã®ãã³ãã¹ã¿ãŒãéä¿¡ãã£ãã«ã§éåžžã«èå³æ·±ããã®ãèŠã€ããŠããŸãã ããŒã¿ããŒã¹ãã©ãã£ãã¯ãéä¿¡ãããå Žåã¯åé¡ãããŸããããããŒã¿ã«PANãTrackãCVVãå«ãŸããŠããå Žåã¯ãåæ¢ããŠããªããã®å šäœãããã©ã«ãã§æå·åãããªãã®ããèããŸãã ãã ããããŒã¿ããŒã¹ãç §äŒããã«ã¯èª°ããå¿ èŠã§ãã ãŸãã¯å€åããã§ã¯ãªã...èè ã¯ãæã人æ°ã®ãããªã¬ãŒã·ã§ãã«ããŒã¿ããŒã¹ã®1ã€ã§ããOracleã«æ³šæãæãããšãææ¡ããŠããŸãã ã»ãã·ã§ã³ãã€ã³ã¿ãŒã»ããããããã«èšèšãããããŠã³ã°ã¬ãŒãæ»æãšãšã¯ã¹ããã€ãã®çµã¿åããã䜿çšããŠãèè ã¯ããŒã¿ããŒã¹ã¢ã«ãŠã³ãããã€ãžã£ãã¯ããç¬èªã®ã¢ãããŒããæ瀺ããŸãã BHã«çŽæ¥å°å ¥ãããæ°ããããŒã«thicknetã䜿çšããŠãããŒã ã¯ãã€ã³ãžã§ã¯ã·ã§ã³ããŒã¹ã®èŽåœçãªæ»æãã©ã®ããã«çºçãããã瀺ããŸãã
èè ïŒ
Christian PapathanasiouïŒTrustwave SpiderlabsïŒã¿ã€ãã«ïŒ
JBossã®ä¹±çšïŒJBossã®æªçšïŒèª¬æïŒ
JBossã¢ããªã±ãŒã·ã§ã³ãµãŒããŒã¯ãJava EEãµãŒãã¹ã¹ã€ãŒãã®ãªãŒãã³ãœãŒã¹å®è£ ã§ãã 䜿ãããããšé«ãæè»æ§ã«ãããJBossã¯ãJ2EEã®åå¿è ãšã«ã¹ã¿ã ããã«ãŠã§ã¢ãã©ãããã©ãŒã ãæ¢ããŠããçµéšè±å¯ãªéçºè ã®äž¡æ¹ã«ãšã£ãŠçæ³çãªéžæè¢ã§ããäŒæ¥ã§ã®JBossã®æ®åã¯ããã©ãã¯ãããïŒã¯ã©ãã«ãŒïŒïŒãšãã³ãã¹ã¿ãŒã®äž¡æ¹ã«ãšã£ãŠã¡ãã£ãšããçç±ã«ãªããŸãã éåžžãJBossã¯SYSTEMãŠãŒã¶ãŒã«ãã£ãŠå®è¡ãããŸããããã¯ãå®è£ ãããè匱æ§ãæ€åºãããšèªåçã«ã¹ãŒããŒæš©éãååŸããããšãæå³ããŸãã
éçºããããŒã«ã䜿çšãããšãä¿è·ãããŠããªãJBossã®ã»ãã¥ãªãã£ã䟵害ã§ããŸãã Metaspleitã®ãã€ããŒããããŒããããã®çµæãJBossã®ã³ã³ããã¹ãã§å®è¡ããããšãã§ããŸãã Windowsãã©ãããã©ãŒã ã§ã¯ãMetasloitãã¬ãŒã ã¯ãŒã¯ã䜿çšããŠãå®å šãªVNCã·ã§ã«ãååŸã§ããŸãã
åäœããŠãããã©ââãããã©ãŒã ãšååŸããç¹æš©ã¬ãã«ã«å¿ããŠãéçºããããŒã«ã¯ããŠã€ã«ã¹å¯Ÿçã®ãããããŒæè¡ãšçµã¿åãããŠããã¯ãã¢ãå±éã§ããŸãã
Javaãã¯ãããžãŒã®ã¯ãã¹ãã©ãããã©ãŒã ã®æ§è³ªã«ãããèè ã¯Linux for JBossãMacOSXã§ãåãããšãã§ãããšç¢ºä¿¡ããŠããŸãã
èè ïŒ
ãšã³ãã»ã¬ã€ïŒãããšã«ã»ã¡ã³ãïŒERNWïŒã¿ã€ãã«ïŒ
Cisco Enterprise WLANã®ãããã³ã°èª¬æïŒ
ãäŒæ¥ã®ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãœãªã¥ãŒã·ã§ã³ãã®äžçã«ã¯ããããŸãããšãéæšæºãã®èŠçŽ ãšæè¡ããã£ã±ãã§ãã ã·ã¹ã³ã®ãœãªã¥ãŒã·ã§ã³ã¯ãStructured Wireless-Aware NetworkïŒSWANïŒããCisco Wireless Unified NetworkingïŒCUWNïŒã«è³ããŸã§ãã»ãã®äžéšã§ãã ã¬ããŒãã§ã¯ãèè ã¯ãããã®ãœãªã¥ãŒã·ã§ã³ã®å éšã¢ãŒããã¯ãã£ã«ã€ããŠèª¬æããè匱ãªéšåãåæããçè«çããã³å®çšçãªæ»æã«ã€ããŠè°è«ãããšãšãã«ãããã€ãã®ãã¢ã瀺ããŸãã èªåæ»æãå®è¡ããããã®æ°ããããŒã«ãæ瀺ãããŸããèè ïŒ
Manish SaindaneïŒAttackïŒDefense LabsïŒã¿ã€ãã«ïŒ
JAVAã·ãªã¢ã«éä¿¡ã®æ»æ説æïŒ
å€ãã®Javaã¢ããªã±ãŒã·ã§ã³ã¯ããªããžã§ã¯ãã®ã·ãªã¢ã«åã䜿çšããŠããªããžã§ã¯ãããããã¯ãŒã¯äžã§ãã€ãã¹ããªãŒã ãšããŠè»¢éãããããã¡ã€ã«ã·ã¹ãã ã«é 眮ãããããŸãã çŸåšãæ¢åã®Pentialãã¹ããœãããŠã§ã¢Serialized Objectsã¯ãèŠæ±ãšå¿çãååããã³å€æŽããããã®å¶éãããæ©èœãæäŸããŸãã èè ã¯ããã®ãããªã·ãªã¢ã«åãããéä¿¡ã«åœ±é¿ãäžããããã®æ°ããæè¡ãå°å ¥ããããšããŸããããããã®å€æŽã¯ãéåžžã®Webã¢ããªã±ãŒã·ã§ã³ããã¹ããããšãã«æ©èœããããšã»ã©é£ãããããŸããã èè ã¯Burp Suiteã®ãã©ã°ã€ã³ãéçºããŸãããèè ïŒ
ããŒã¿ãŒã»ã·ã«ããŒãã³ïŒãšãã»ã«ã¬ã©ïŒMANDIANTïŒSABRE SecurityïŒã¿ã€ãã«ïŒ
ãã«ãŠã§ã¢ã®ç¶æ ïŒå®¶æã®çµèª¬æïŒ
éå»æ°å¹Žã«ããã£ãŠããã«ãŠã§ã¢ã倧ããªããã¡ããªãã«èç©ããåŸåããããŸããããããã¯ä»¥åãšã¯æ ¹æ¬çã«ç°ãªããŸãã æ°çŸãŸãã¯æ°åã®Malvariæšæ¬ã®å®¶æãçãããããŸããã ãã®ãããªã°ã«ãŒãã¯ãæéã®çµéãšãšãã«ãã«ãŠã§ã¢ã®é²åãæ瀺çã«ç€ºããŠããŸãã é²åã¯ãåçŽãªä¿®æ£ãšå°ããªæ¹åããŸãã¯æ¢åã®ã³ãŒãã«åºã¥ãããã¹ãŠã®æ©èœã®ææ¬çãªå€æŽã§è¡šçŸã§ããŸãã 家æå ããã³å®¶æéã®é¢ä¿ã®ç 究ã¯ãéçºã®ããŒã¹ãæè¡æ©åšã®æ¹åçã«é¢ããæ å ±ãæäŸããŸãã 家æã®æé·çã®ç 究ã¯ããã®åºæ¬çãªæ©èœãç¹å®ãããããäœããã®åé¡ãäœæããããšãã§ããŸããèè ïŒ
Paul StoneïŒã³ã³ããã¹ãæ å ±ã»ãã¥ãªãã£ïŒã¿ã€ãã«ïŒ
次äžä»£ã¯ãªãã¯ãžã£ããã³ã°ïŒæ¬¡äžä»£ã¯ãªãã¯ãžã£ããã³ã°ïŒèª¬æïŒ
ã¯ãªãã¯ãžã£ããã³ã°-被害è ãéåžžIFRAMEå ã«é ãããŠããé ããªã³ã¯ãã¯ãªãã¯ããããã«WebããŒãžããã©ãŒãããããããšã«ããããŠãŒã¶ãŒã欺ããŠWebãµã€ãäžã§æå³ããªãã¢ã¯ã·ã§ã³ãå®è¡ããææ³ã ãã ããXSSïŒã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ïŒãCSRFïŒã¯ãã¹ãµã€ããªã¯ãšã¹ããã©ãŒãžã§ãªïŒãªã©ã®ä»ã®æ»æãšæ¯èŒãããšãã¯ãªãã¯ãžã£ããã³ã°ã¯æ©èœãå¶éãããæ»æãšèŠãªãããŸãã è¬çŸ©äžã«ãèè ã¯ãã®å£°æãééã£ãŠããããšããããŠä»æ¥ã®ã¯ãªãã¯ãžã£ãã¯ææ³ãæ¡åŒµããŠããã匷åãªæ°ããæ»æãå®è¡ã§ããããšã蚌æããããšèããŠããŸãããã®ã¬ããŒãã§ã¯ãã¯ãªãã¯ãžã£ãã¯ã®åºæ¬ãæ¢åã®æ¹æ³ãæ¹åããæ¹æ³ããŠãŒã¶ãŒãã ãŸãæ°ããæ¹æ³ã®ãããã¯ãåãäžããŸãã äŸã䜿çšããŠãèè ã¯ããã€ãã®ã¯ãã¹ãã©ãŠã¶æ»æã瀺ããŸãã
èè ïŒ
ã¯ãªã¹ããã¡ãŒã»ã¿ã«ããã¹ããŒïŒFlylogic EngineeringïŒã¿ã€ãã«ïŒ
ã¹ããŒãã«ãŒããããã®ãããã³ã°èª¬æïŒ
説æãªã:(èè ïŒ
ããšããã»ããã³ïŒããã«ãŽã¡ïŒã¿ã€ãã«ïŒ
Maltego 3.0ã®çºè¡šïŒMaltego 3.0ã®çã®å ïŒèª¬æïŒ
幎éãéããŠãPatervaããŒã ã¯2009幎3æã«ãªãªãŒã¹ããããšãªããMaltego 3.0ã§éãã«å¹³åçã«äœæ¥ããŸãããBH2009以æ¥åããŠãPatervaã¯å®å šã«ãŒãããæ§ç¯ãããMaltegoã®æ°ããããŒãžã§ã³ã玹ä»ããŸãã , , .():
Julien Tinnes & Chris Evans (Google, Inc):
Security in depth for Linux software ( Linux )説æïŒ
, , . , , vsftpd Google Chrome Linux, -, , -, ., , . , , .
, -, , ( ). , , , .
, , «», , vsftpd Google Chrome Linux.
():
Mario Vuksan, Tomislav Pericin & Brian Karney (ReversingLabs & AccessData Corporation):
Hiding in the Familiar: Steganography and Vulnerabilities in Popular Archives Formats ( - : )説æïŒ
, - : PC, Apple. , , - , 10, 20 ?, , - -. , ? ? 15 , ZIP, 7ZIP, RAR, CAB, GZIP.
ArchiveInsider â , , . , «» .