WEST-SEC#3 CTFãéããŠã»ãã¥ãªãã£ã®åºç€ç¥èãæè¡ã察çãèšå®ããæ¥œãããåŠã¶
ã€ãã³ãå 容
ããããã®ãç³èŸŒã¿ããããšãããããŸããéå¶ã®äœå¶ãæ€èšããããã§ãå®å¡ãïŒåã®ïŒïŒïŒåã«å¢ãããŸããïŒ12/24ïŒ
ã8å²è§£ããCTFããã³ã³ã»ããã«ããWEST-SEC CTFã®3åç®ãéå¬ïŒ
第1åç®ã®WEST-SEC CTFã®ã¢ã³ã±ãŒãçµæã§ããã85.6%ã®æ¹ãã圹ã«ç«ã£ããã91.3%ã®æ¹ããæºè¶³ããŠããããšãçãããã ããŸãããåå ããã ããçãããããããšãããããŸãã
3åç®ã¯ã¯ã€ãºå€§äŒãããããšæã£ãŠã¡ã³ããŒã§ãã©ã€ã¢ã«ãããŸããããã€ãã€ãã§ãããCTFããã£ãæ¹ããããšããæèŠã倧åã ã£ãã®ã§ã次åãCTFããããŸãã
WEST-SEC CTFã®å 容
WEST-SEC CTFã¯ãã»ãã¥ãªãã£ã®åºç€ç¥èã»æè¡ãç¶²çŸ
çã«åŠç¿ããããã®ã³ã³ãã³ãã§ããCTFïŒCapture The FlagïŒãšããã°ãSECCONã«ä»£è¡šããã鬌ã®ããã«ã¬ãã«ãé«ãæåãã²ãŒã ã§ããããããWEST-SECã®CTFã¯å
šãå¥ç©ã§ããCTFã®ããŒã«ã掻çšããŸãããçžæãšç«¶ããç«¶æããšããããã¯ãã¿ããªã§åŠã¶ãåŠç¿ãã§ããã»ãã¥ãªãã£ãå®ãããã«èº«ã«çããã¹ãåºæ¬ç¥èããäžéšã³ãã³ããæã€ãªã©ã®å®è·µãèžãŸããŠåŠã³ãŸãã
ãŸãã¯ã以äžã®ããã¢ãŒã·ã§ã³åç»ã§æŠèŠãã確èªãã ããã
![]()
ãªãCTFã®åœ¢åŒãªã®ã
ã»ãã¥ãªãã£ãåŠã¶ã«ã¯ãããã¹ãã®åŠç¿ãå®åãè³æ ŒååŸãªã©ãããã€ãã®æ¹æ³ããããŸãã
ã©ã®æ¹æ³ã倧äºãªåŠç¿ã§ãããã²ãŒã ã䜿ã£ãåŠç¿æ¹æ³ã§ããã²ãŒããã£ã±ãŒã·ã§ã³ãé«ãè©äŸ¡ãåããŠããŸããã²ãŒããã£ã±ãŒã·ã§ã³ã®é
åã¯ããªããšãã£ãŠããé¢çœãããæ¥œãããã§ãããã
ããšãã°ãåã«èãã ãã§ã¯ãªãçãããšããåæ¹åæ§ãæ¥åžžã§ã¯ããŸãè§Šããããšãã§ããªã宿©ã«è§Šããåã³ãæ£è§£ãäžæ£è§£ããšãããã©ãã©æãã¹ã³ã¢ãåºãŠã©ã€ãã«ãšç«¶ãåã髿æãçæéã§å
šäœåãåŠç¿ã§ããæºè¶³æãªã©ãå³ããããšãã§ããŸãã
WEST-SECã§ããCTFãšããããŒã«äœ¿ãããšã§ãçãããåçããçãã«æ£è§£ã»äžæ£è§£ã衚瀺ãããŸããããã«ãããŒã ã¹ã³ã¢ã衚瀺ãããŸããã¹ã³ã¢ãç«¶ãããšã第äžã«ãããã®ã§ã¯ãããŸããããã¢ãããŒã·ã§ã³ãé«ããŠåå ããŠããã ãããã®ã¢ã¯ã»ã³ãã«ããŠãã ããã
åºé¡ããŒãããâ ããŒãã¯ååãšåæ§ã§ãããåé¡ã¯å šåãªãã¥ãŒã¢ã«ããŸãã
ã»ãã¥ãªãã£ãåºãåŠã¹ãããã«ããŠãããäž»ãªåºé¡ããŒãã¯ä»¥äžã§ãã
ã-äŒæ¥ãã»ãã¥ãªãã£å¯ŸçãšããŠç¥ã£ãŠããã¹ãåºæ¬çšèªã
ã-æå·ãèªèšŒããã£ãžã¿ã«çœ²åãå«ãPKIã®åºæ¬æè¡
ã-SQLã€ã³ãžã§ã¯ã·ã§ã³ããã£ã¬ã¯ããªãã©ããŒãµã«ããã«ãŒããã©ãŒã¹ãªã©ã®æ»æææ³
ã-DNSãã¡ãŒã«ãµãŒããªã©ã®ãã»ãã¥ã¢ãªèšå®
ã-ãã°è§£æãâ»å®éã®ãã°ãè§£æããŠããããŸãã
ã-ITã®åºç€ç¥èãïœãã±ãããã£ããã£å«ã
ã-UTMã®èšå®ã®ç¢ºèªãâ»ååã¯PaloAltoã«ãã°ã€ã³ããŠããã ããŸããããä»åã©ããããã¯æ€èšäžã§ãã
ã-ã¯ã©ãŠãã»ãã¥ãªãã£
ã-ã€ã³ã·ãã³ã察å¿ã®èãæ¹
ã-è匱æ§ç®¡çãããŒãã¹ãã£ã³
ã-ã»ãã¥ãªãã£ã«é¢ããæ³åŸãããªã©
â»WEST-SECã§æºåããæ°ããåé¡ã®äžãããå¶éæéãšã®ãã©ã³ã¹ãèŠãŠåºé¡ããåé¡ãéžæããŸãã1åã®åºé¡ãšããŠã¯ããããå šãŠãåºé¡ãããããã§ã¯ãããŸããã
åŸæ¥ã®CTFãšã®éã
CTFdã®ããŒã«ã掻çšããŠããŸãããå
容ãé£æåºŠã¯åŸæ¥ã®CTFãšã¯ç°ãªããŸãã
éãâ é£æåºŠ
SECCONãªã©ã®CTFã¯éåžžã«é£æåºŠãé«ãã§ããäžæ¹ãWEST-SECã®CTFã¯ãé£æåºŠãããªãäœãããŸããããŒã ã§çžè«ãããã調ã¹ããããããšã§ã誰ãã8å²ãæ£è§£ã§ããããšãæèããŠäœåããŠããŸãã
ãçãæéã§ãããåé¡ã®é£æåºŠãäžãããŸããããŒã ã§çžè«ã§ãããããåé¡ãããããè§£ããŠãããããšãã§ããŸããçµæãšããŠãå¹
åºãã»ãã¥ãªãã£ã®ç¥èã«è§Šããããšãã§ããŸãã
éãâ¡å 容
CTFã¯ããã°ã©ãã³ã°æè¡ãLinuxã®ã³ãã³ããé§äœ¿ãããããŠããã©ã°ãèŠã€ãããã®ãäžå¿ã§ããWEST-SECã®CTFã§ã¯ãåºæ¬çãªã»ãã¥ãªãã£çšèªãåŠã¶ãããåçŽãªç¥èåé¡ããããããããŸãããŸããäžéšãã³ãã³ããæå
¥ãããWiresharkãèŠããããããšããããŸããããã®å Žåã§ãé«åºŠãªæè¡ã¹ãã«ãæ±ããããããã§ã¯ãããŸããã
åå 察象è
ç¹ã«å¶éã¯ãããŸãããã以äžã®æ¹ãæèããŠãããŸãã
ã»æ
å ±ã·ã¹ãã éšéã§ã»ãã¥ãªãã£å¯Ÿçã®åºç€ãæ¹ããŠå確èªãããæ¹
ã»ã»ãã¥ãªãã£ã«èå³ããããã»ãã¥ãªãã£å¯Ÿçããã£ãšæ·±ãç¥ãããæ¹ãïŒâ»åŠçãããOKïŒ
ã»ã»ãã¥ãªãã£ã®ä»äºã«æºãã£ãŠããããå®è·µçãªçµéšãå°ãªãã®ã§å°ãã§ãçµéšããŠã¿ããæ¹
ã»CTFïŒCapture The FlagïŒã«ã¯èå³ããããã©ãæ¬å®¶ã®CTFã¯æ·å±
ãé«ãããŠã»ã»ã»ãšããæ¹
ã»ãã®ç ä¿®ã§åŸãç¥èãã»ãã¥ãªãã£å¯Ÿçã®ã¿ã«æŽ»ãããæªçšããªãæ¹
å¿ èŠãªãã®
ã»ãã©ãŠã¶ïŒGoogle Chromeãªã©ãIEã¯éæšå¥šïŒãå
¥ã£ãã€ã³ã¿ãŒãããã«æ¥ç¶ã§ããPCãã¹ããŒããã©ã³ããã®åå ãå¯èœã§ãããSSHæ¥ç¶ããã°åæãªã©ãããŠããã ããããäžéšã®ç«¶æã®åå ãå³ãããšæããŸãã
ã»WebäŒè°ããŒã«ïŒCiscoWebEXãZOOMãªã©ïŒã®ç°å¢ã
ã»TeraTermãªã©ã®SSHã«æ¥ç¶ããããŒã«ïŒç¡ãå Žåã¯äžéšã®åé¡ãè§£ãããšãã§ããŸããããããŒã æŠãªã®ã§ç»é¢å
±æçã§ãäºãã«ãã©ããŒããŠããã ããšããæããããŸããïŒ
ã»ãèªèº«ã®ã°ããŒãã«IPã¢ãã¬ã¹ãäž»å¬è
ãžéç¥
ãé¡ã
ã»CTFã®ãµãŒããã®ãã®ããã³ãäžéšã®ãµãŒããžã®ã¢ã¯ã»ã¹ã¯ãéä¿¡å
IPã¢ãã¬ã¹ãå¶éãããŠããã ããŸããåå è
ã®PCã«å²ãåœãŠãããã°ããŒãã«IPã¢ãã¬ã¹ããèãããŸãã
ã»WebäŒè°ããŒã«ïŒCiscoWebEXãZOOMãªã©ïŒã§ãéå¬ã®èª¬æçãç°¡åãªè§£èª¬ãŸã§ãè¡ããŸãããäž»å¬è
ããã³ããŒã å
ã§ãè¯å¥œãªã³ãã¥ãã±ãŒã·ã§ã³ããšã£ãŠããã ããããããããããé¡ãããããŸãã
ã»ä»åŸã®ã«ãªãã¥ã©ã ãéå¶ã®åäžã®ããã«ã¢ã³ã±ãŒãããé¡ãããŸãã
åœæ¥ã®æµã
ïŒïŒïŒã¿ã€ã ã¹ã±ãžã¥ãŒã«ïŒäºå®ïŒ
| é çª | æå» | å 容 |
|---|---|---|
| Program0 | 18:40~ã | WebäŒè°ã®éšå±ã空ããŸãã |
| Program1 | 19:00 ~ 19:20 | ç«¶æã®ç°¡åãªèª¬æããfrom t_tani |
| Program2 | 19:20 ~ 20:45 | ã»ãŠãŒã¶ããã³ããŒã ç»é²ãâ»æé ã¯ïŒïŒïŒ ã»éä¿¡å ã®ã°ããŒãã«IPã¢ãã¬ã¹ãäž»å¬è ã«éç¥ ã»CTFç«¶æéå§ |
| Program3 | 20:45 ~ 21:15 | ç°¡åãªè§£èª¬ããã³ã質ç ããfrom Fiji ã¢ã³ã±ãŒãèšå ¥ |
ïŒïŒïŒProgram0ã«ã€ããŠ
ã»èªåã®ã°ããŒãã«IPã¢ãã¬ã¹ã®èª¿æ»ããé¡ãããŸããâç«¶æéå§åŸãããŒã åäœã§å ±åãããŠããããŸãã
ã»èžã¿å°ãµãŒããžã®æ¥ç¶ãã¹ãããé¡ãããŸãã
ïŒïŒïŒProgram1ã«ã€ããŠ
以äžã®ç¹ã説æããŸãã
â åé ãããã€ãè¶£æšã®èª¬æ
ãã®connpassã®ãµã€ãã«æžããŠãããããªãç«¶æã®äž»æšãç°¡åã«èª¬æããŸããâãæ¥œããããããŸãããïŒ
â¡ç«¶æã®ç°¡åãªèª¬æã
ã»ç«¶æçšã®ãµãŒãçŸ€ã®æ¥ç¶å
ãã¢ã«ãŠã³ãæ
å ±ã説æ
ãâç»é¢ã«ãŠãç«¶æçšã®ãµã€ããFortiGateãèžã¿å°ãµãŒãããAPãµãŒããžã®ãã°ã€ã³ã宿ŒããŸãã
ãâ»æ³šæç¹ïŒFortiGateãèžã¿å°ã®WebãµãŒãã¯ãè€æ°ã®äººãåæã«å
¥ããšãã£ãã·ãã£ã®é¢ä¿ã§æ¥ç¶ã§ããªãå¯èœæ§ããããŸãããã®å Žåãã°ã«ãŒãã§1人ã®ãã°ã€ã³ããé¡ãããããIPã¢ãã¬ã¹ã§å¶éãããŠãããå ŽåããããŸãã
ã»CTFã®ãµã€ãããªãŒãã³ããŸãã
ãç«¶æéå§åŸãã¿ãªããã«ã¯ããã®ããšã®ïŒïŒïŒã®æé ã«åŸãããŠãŒã¶ã¢ã«ãŠã³ããäœæããããŒã ãäœã£ãŠãã ããã
ã»Flagã®å
¥ãæ¹ã¯ãflag{abc} ãšã¯ããã«ãçããºããªå
¥ããŠãã ãããïŒããã©ã°å
¥åã®ãã¹ããåé¡ã§å®æŒããŸãïŒ
â¢ç«¶æéå§åŸã®èª¬æ
ã»1ããŒã 4åã«ããããŒã æŠã§ãã®ã§ããã¬ãŒã¯ã¢ãŠãæ©èœã§ããŒã ã®éšå±ã«åãããŠããããŸãã
ã»ããŒã å
ã§è»œãèªå·±ç޹ä»ãªã©ã®ã³ãã¥ãã±ãŒã·ã§ã³ãåã£ãŠãã ãããïŒããŒã ã§ååããŠé²ããŠããã ãããããé¡ãããŸããïŒ
ã»ãŠãŒã¶ç»é²ãããŠãããŒã ã«åå ããŠãã ãããïŒæé ã¯ãã®ããšã®ïŒïŒïŒïŒ
ã»ãã°ã€ã³ã§ããæ¹ãããCTFã®ç«¶æãéå§ããŠãã ããã
ã»äžŠè¡ããŠãããŒã å
ã§ã°ããŒãã«IPã¢ãã¬ã¹ããŸãšããããŒã åãšãšãã«å ±åããŠãã ãããïŒéäžããéä¿¡å
IPã¢ãã¬ã¹å¶éããããŸãïŒ
â£ã¹ã³ã¢ãç«¶ãããšã第äžçŸ©ãšããŠããŸããïŒ
åé ã«ãèšèŒããŠãããŸãããWEST-SECã®ç®çã¯ããçžæãšç«¶ããç«¶æããšããããã¯ãã¿ããªã§åŠã¶ãåŠç¿ããã§ããããŒã å
ã®èª°ããè§£ããåé¡ã§ãã£ãŠããçããå
šå¡ãèªåã§èããè§£ããŠããã ãããšãæåŸ
ããŠããŸãã
ããŒã ã§åé¡ãè§£ããæ¹ã¯ãè§£ããŠããªãæ¹ãžã®ãã©ããŒãã¢ããã€ã¹ããé¡ãããŸãã
â€ã¢ã³ã±ãŒãã®ãé¡ã
æç€ºããã¢ã³ã±ãŒãURLã«ãŠãã¢ã³ã±ãŒãã®ãååããé¡ãããŸãã
ïŒïŒïŒãŠãŒã¶ããã³ããŒã ã®ç»é²
â äž»å¬è
ããæ¡å
ããCTFã®URLïŒåœæ¥ã«æ¡å
ããŸãïŒã«ã¢ã¯ã»ã¹ããŠãã ããã
â¡å³äžã®Registerãã¿ã³ã§ãŠãŒã¶ç»é²ãããŠãã ããã
ãâ»ã¡ãŒã«ã¢ãã¬ã¹ã¯ãããŒããé¡ãããŸãã
â¢RegisterãããŠãŒã¶ç»é²ããŸãã
â£ãŠãŒã¶ç»é²åŸãJoin Team ã§ããŒã ã«åå ããŠãã ããã
ããŒã åã¯ãteam1ãteam2ãã»ã»ã»ãšãªã£ãŠããŸããããŒã çªå·ã¯ããã¬ã€ã¯ã¢ãŠãã«ãŒãã®éšå±çªå·ãšåãã§ããã¹ã¯ãŒãã¯æç€ºããããã®ã䜿ã£ãŠãã ããã
äž»å¬ã¡ã³ããŒ
ã»ç²æ·µ åïŒç¹æã¯UTMãšæ
å ±åŠçæè¡è
詊éšïŒ
ã»è°·å£ 貎ä¹ïŒOWASP Nagoyaæå±ãCISSPïŒ
ã»è€ç° æ¿åïŒã»ãã¥ã¢ããã°ã©ãã³ã°ã®äœåæ
åœïŒ
â»ã»ãã¥ãªãã£ã«é·å¹Žæºããã¡ã³ããŒã§ãã
åŸæŽ
ã»OWASP Nagoya Chapter
ããWebã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ãåŠã³ããæ¹ã«ã¯ãOWASP top 10ããªã¹ã¹ã¡ããŸãã
ããOWASP top 10
ã»Palo Alto Networks
ã»ãšã ãªãŒããã¯ã¹æ ªåŒäŒç€Ÿ ïŒMOTEX Inc.ïŒ
â»é äžå
泚æäºé
â» ãã¡ãã®ã€ãã³ãæ å ±ã¯ãå€éšãµã€ãããååŸããæ å ±ãæ²èŒããŠããŸãã
â» æ²èŒã¿ã€ãã³ã°ãæŽæ°é »åºŠã«ãã£ãŠã¯ãæ å ±æäŸå ããŒãžã®å 容ãšå·®ç°ãçºçããŸãã®ã§äºããäºæ¿ãã ããã
â» ææ°æ å ±ã®ç¢ºèªãåå ç³èŸŒæç¶ããã€ãã³ãã«é¢ãããåãåããçã¯æ å ±æäŸå ããŒãžã«ãŠãé¡ãããŸãã

ãåãåãã
é¢é£ããã€ãã³ã
- TOP
- ã€ãã³ã
- WEST-SEC#3 CTFãéããŠã»ãã¥ãªãã£ã®åºç€ç¥èãæè¡ã察çãèšå®ããæ¥œãããåŠã¶

