第1å ã»ãã¥ãªãã£è¥æã®äŒïŒLT&亀æµäŒïŒ
ã€ãã³ãå 容
ã€ãã³ãéå¬èšã第1å ã»ãã¥ãªãã£è¥æã®äŒïŒLT&亀æµäŒïŒã
ãã»ãã¥ãªãã£è¥æã®äŒããšã¯
ãã»ãã¥ãªãã£è¥æã®äŒããšã¯ãå°æ¥ã»ãã¥ãªãã£ãšã³ãžãã¢ã«ãªãããåŠçãã»ãã¥ãªãã£æ¥åã«æºããè¥æã»ãã¥ãªãã£ãšã³ãžãã¢ãã¡ããã»ãã¥ãªãã£ã«é¢ããæè¡ãæ¥åå 容ãé²è·¯ããã£ãªã¢ã«ã€ããŠãçŽæ¥è©±ãåããå ŽãšããŠäº€æµã»æ å ±äº€æã§ããã³ãã¥ããã£ã§ãã
â»æ¬ã³ãã¥ããã£ã®æŠèŠã¯ãWebããŒãžãã芧ãã ããã
- X: @sec_wakate
åå 察象
- åŠçïŒ15æ³ä»¥äžã®æ¹
- ç¹ã«ã»ãã¥ãªãã£åéã«èå³ã®ããæ¹
- è¥æã»ãã¥ãªãã£ãšã³ãžãã¢ïŒç€ŸäŒäººïŒïŒæ°å1~3幎ç®ã®æ¹
- ãªãã ãã®ã»ãã¥ãªãã£ã«é¢ããæ¥åã«æºããæ¹
ãããªæ¹ã«ãããã
- ã»ãã¥ãªãã£ã«èå³ããããã»ãã¥ãªãã£ãšã³ãžãã¢ã«ãªããããšæãåŠç
- ã»ãã¥ãªãã£ã«é¢ããæ¥åã«æºãã£ãŠããè¥æã»ãã¥ãªãã£ãšã³ãžãã¢ã§ãã»ãã¥ãªãã£ã«èå³ããåŠçãåäžä»£ã®ã»ãã¥ãªãã£ãšã³ãžãã¢ãšäº€æµãããæ¹
- ã»ãã¥ãªãã£æè¡ã«é¢ããæ¥åã«èå³ãããæ¹
å¹¹äº
äœç° æ·³å²ïŒãã ãã€ãïŒ
- ãŠãŒã¶ãŒäŒæ¥ã§åã24åã»ãã¥ãªãã£ãšã³ãžãã¢
- å°éåéïŒThreat Analysis, Cloud Security(AWSã»CI/CD), Corporate IT
- XïŒ asu_ para (@4su_para)
- ä¿®äºïŒã»ãã¥ãªãã£ãã£ã³ãå šåœå€§äŒ (2021), SecHack365 (2023)
森岡 åªå€ªïŒãããã ãããïŒ
- ã»ãã¥ãªãã£ãã³ããŒäŒæ¥ã§åã24åã»ãã¥ãªãã£ãšã³ãžãã¢
- å°éåéïŒWeb Security, Cloud Security, Bug Bounty, BizDev
- XïŒ morioka12 (@scgajge12)
- ä¿®äºïŒSecHack365 (2018), ã»ãã¥ãªãã£ãã£ã³ãå šåœå€§äŒ (2020)
LTçºè¡š
## LTã®ããŒã
LTã®ããŒãã¯ããã»ãã¥ãªãã£ã«é¢ããå
容ããšããç¹ã«ä»¥äžã®ãããªå
容ãæã¿ãŸãã
- è¥æã»ãã¥ãªãã£ãšã³ãžãã¢ã®æ¹
- æ®æ®µã®ã»ãã¥ãªãã£æ¥åã«é¢ãã話ãããã«è¿ã話ãªã©
- å®éã®æ¥åã«æŽ»ããããã»ãã¥ãªãã£æè¡ãã¹ãã«ã«ã€ããŠãªã©
- åŠçã®æ¹
- åãçµãã§ãããåŠãã§ããã»ãã¥ãªãã£æè¡ã«é¢ãã話ãªã©
- ã»ãã¥ãªãã£ã«é¢ããã€ã³ã¿ãŒã³ã·ããã«åå ããéã®è©±ãªã©
**å¿åããŠããã ããäžãããå¹¹éšã¡ã³ããŒã®æ¹ã§éžå®ããæçµçã«æ¡æãããæ¹ã«çºè¡šããŠããã ããŸãã**
â»ã»ãã¥ãªãã£æè¡ã«é¢ããŠãã¬ã€ã€ãŒã¯åããŸããã
## LTå¿åãã©ãŒã
- ç· ãåãæ¥ïŒ11æ8æ¥ïŒéïŒ23æ59åãŸã§
- æ¡æçµæçºè¡šæ¥ïŒäºå®ïŒïŒ11æ11æ¥ïŒæïŒãã12æ¥ïŒç«ïŒãã
- URLïŒ[å¿åãã©ãŒã ïŒGoogle FormïŒ](https://forms.gle/V3Y89NC2vU9Rzvw38)
**LTå¿åã«ã€ããŠãäžäººãè€æ°ã®ããŒãã«ã€ããŠå¿åããããšãæè¿ããå¯ããšããŸããïŒ1ãã©ãŒã ã«1ããŒããšããå¿åãåããŠåããŒãã«ã€ããŠæåºããŠãã ãããïŒ**
â»LTçºè¡šã®å¿åè
ããconnpassäžãã屿§ã«ãã£ãæ ã§åå å¿åãããŠãã ãããïŒæ¡æãããæ¹ã¯åªå
çã«åå ã§ããããã«é
æ
®ããŸããïŒ
## LTçºè¡šå
容ã®äžäŸ
- è¥æã»ãã¥ãªãã£ãšã³ãžãã¢ã®æ¹
- è匱æ§èšºæããããã¬ãŒã·ã§ã³ãã¹ããªã©ã«é¢ããå
容ãçµéšè«ã®ç޹ä»
- ã¯ã©ãŠãç°å¢ã«ãããã€ã³ã·ãã³ã調æ»ããã°åæãDevSecOpsã«é¢ããå
容ã®ç޹ä»
- ã»ãã¥ãªãã£ã«é¢ããå
補åãéçºè
ãšé£æºããŠã»ãã¥ãªãã£ãæ¹åããŠããé¡ã®å
容(PSIRTãªã©)ã®ç޹ä»
- æ¥åã§å®è·µããŠããæ»æææ³ãé²åŸ¡ææ³ãªã©ã®ç޹ä»
- å°±è·æŽ»åã®æ¯ãè¿ããäŒæ¥éžã³ã®ç®ç·æã«å¯Ÿããèªåã®èãããŸãšããŠçºè¡š
- åŠç
- ã»ãã¥ãªãã£ã«é¢ããèªäœããŒã«ãåãçµã¿ã«é¢ããçºè¡š
- ã»ãã¥ãªãã£ã«é¢ããã€ã³ã¿ãŒã³äœéšèš
- å°±æŽ»ã®æ¯ãè¿ãã就掻ã«å¯Ÿããèãæ¹ã»ã¹ã¿ã³ã¹ã«é¢ããèªåã®èãããŸãšããŠçºè¡š
â»ãããã¯ãããŸã§ããäžäŸãã®ãããå¹
åºãã»ãã¥ãªãã£ã«é¢ããããŒãã®LTå¿åããåŸ
ã¡ããŠãããŸãïŒ
é嬿¥
æ¥çš
- 12æ8æ¥ïŒæ¥ïŒ 13:00 ~ 18:30
- åä»ïŒ12:30 ~
â» éå¶ã®éœåäžã13:30以éã®åä»ã¯ã§ããŸããã
äŒå Ž
- äŒå ŽïŒæ ªåŒäŒç€Ÿã¢ã«ããã²ãŒã ã¹ïŒAkatsuki Games Inc.)
- äœæïŒã141-0021 æ±äº¬éœåå·åºäžå€§åŽ2-13-30 oak meguro 8éïŒåä»ïŒ
- ã¢ã¯ã»ã¹ïŒJRç®é»é§ ããåŸæ©3åãå°äžéã»æ±æ¥ç·ç®é»é§ ãã4åã
- Wi-Fi : ãã / 黿º : ãã
â»æ¬ã€ãã³ãã¯ããªãã©ã€ã³äŒå Žã®ã¿ã§ã®éå¬ã§ãã
æã¡ç©
- åŠç
- åŠç蚌
- è¥æã»ãã¥ãªãã£ãšã³ãžãã¢ïŒç€ŸäŒäººïŒ
- äŒç€Ÿã®ååº
- çå¹Žææ¥ã瀺ãã蚌æèšŒ
- LTçºè¡šè
- èªèº«ã®PC
å仿
- åŠç
- ãconnpassã®åä»ç¥šããšãåŠç蚌ããæç€ºããŠãã ããã
- è¥æã»ãã¥ãªãã£ãšã³ãžãã¢ïŒç€ŸäŒäººïŒ
- ãäŒç€Ÿã®ååºãã1ææåºããŠãã ããã
- ãconnpassã®åä»ç¥šããšãçå¹Žææ¥ã瀺ãã蚌æèšŒããæç€ºããŠãã ããã
åå è²»
- è¥æã»ãã¥ãªãã£ãšã³ãžãã¢ïŒ1,000åïŒçŸéïŒ
- åŠçïŒç¡æ
åå è²»ã¯ãåœæ¥ã®äº€æµäŒã§çšæãã飲ã¿ç©çã®ä»£éãšãããŠããã ããŸãã
â»åœæ¥ã®åä»ã§ããé£ããåºãªãããã«ããŠããã ããçŸéã§æ¯æãããé¡ãããŸãã
ã¿ã€ã ããŒãã«
- è¬æŒã»ããã«ãã£ã¹ã«ãã·ã§ã³ïŒ20å
- LTçºè¡šïŒ15å
| æé | æŠèŠ | ã¿ã€ãã« | ç»å£è |
|---|---|---|---|
| 12:30 ~ | åä»éå§ | ||
| 13:00 ~ 13:10 | ãªãŒããã³ã° | å¹¹éš | |
| 13:10 ~ 13:30 | è¬æŒ | ãŽãŒã«ãã¹ãã³ãµãŒã«ããè¬æŒ | |
| 13:30 ~ 13:35 | äŒæ© (5å) | ||
| 13:35 ~ 13:50 | LT1 (瀟äŒäºº) | ææ¥ããå§ãããã¯ã€ãããã¯ã¹PT | hikae |
| 13:50 ~ 13:55 | äŒæ© (5å) | ||
| 13:55 ~ 14:10 | LT2 (瀟äŒäºº) | æ°ç±³ã»ãã¥ãªãã£ãšã³ãžãã¢ã«ããRed Teamã®ä»äºçŽ¹ä» | R* |
| 14:10 ~ 14:15 | äŒæ© (5å) | ||
| 14:15 ~ 14:30 | LT3 (瀟äŒäºº) | ã¹ããã¢ããªïŒã²ãŒã ããŒã蚺æã®ãªã¢ã«ãªèåŒ±æ§ | daiki0508 |
| 14:30 ~ 14:40 | äŒæ© (10å) | ||
| 14:40 ~ 15:00 | è¬æŒ | äŒå Žã¹ãã³ãµãŒã«ããè¬æŒ | |
| 15:00 ~ 15:05 | äŒæ© (5å) | ||
| 15:05 ~ 15:20 | LT4 (åŠç) | CTFã®èª²é¡ãžã®åãçµã¿æ¹ãšãå®äžçã«å¿çšã§ããããš | keymoon |
| 15:20 ~ 15:25 | äŒæ© (5å) | ||
| 15:25 ~ 15:40 | LT5 (åŠç) | 髿 ¡çãRCEãçºèŠãããŸã§ | SakaiSec |
| 15:40 ~ 15:45 | äŒæ© (5å) | ||
| 15:45 ~ 16:00 | LT6 (瀟äŒäºº) | ã»ãã¥ãªãã£æ¥çã®æ©ãæ¹ | clone |
| 16:00 ~ 16:05 | äŒæ© (5å) | ||
| 16:05 ~ 16:20 | LT7 (瀟äŒäºº) | ãã¡ãžã³ã° ãã¢ã«ããã¢ãšå®çšã§ããããªãœãããŠã§ã¢ãã¹ãææ³ã | Nakashima |
| 16:20 ~ 16:25 | äŒæ© (5å) | ||
| 16:25 ~ 16:40 | LT8 (瀟äŒäºº) | éçºè åãããŒã«ãéæ¹é ããŠã»ãã¥ãªãã£èšºæããŒã«ãäœã£ãŠãã話 | pizzacat83 |
| 16:40 ~ 16:50 | äŒæ© (10å) | ||
| 16:50 ~ 17:10 | ããã«ãã£ã¹ã«ãã·ã§ã³ | ãã»ãã¥ãªãã£è¥æã®äŒãèšç«ã®çç±ãšä»åŸã®å±æã«ã€ã㊠| å¹¹éš |
| 17:10 ~ 17:15 | äŒæ©ã»äº€æµäŒæºå (5å) | ||
| 17:15 ~ 18:25 | 亀æµäŒ (70å) | ||
| 18:25 ~ 18:30 | ã¯ããŒãžã³ã° |
LTçºè¡šã»è¬æŒã®å 容
è¥æã»ãã¥ãªãã£ãšã³ãžãã¢æ
LT1ïŒææ¥ããå§ãããã¯ã€ãããã¯ã¹PT
æŠèŠ
é²åŸ¡åŽãæ»æè
ãããæå©ãªç¹ã¯ç€Ÿå
ã®æ§ã
ãªæ
å ±ãå©çšã§ããç¹ã ãšæããŸãã
freeeã®redteamã§ã¯ãã®ãããªç€Ÿå
ãªãœãŒã¹ãæŠåšåããåãçµã¿ãšãããçšããPTãšããçµã¿åããã§ç¶ç¶çãªæ»æãè¡ã£ãŠããŸãã
ä»åã¯ãã®äžã§ææ¥ããã§ãå§ããããåãçµã¿ã«ã€ããŠå®è·µã§ãããããªãŒãã³ãœãŒã¹ãããã¯ããçšãããã¢åœ¢åŒã§ç޹ä»ããŸãã
ç»å£è ïŒhikae
- çæ³¢å€§æ å ±ç§åŠé¡âfreee PSIRT
- è¶£å³ã¯GitHubãµãŒãã£ã³
- X: @0xhikae
LT2ïŒæ°ç±³ã»ãã¥ãªãã£ãšã³ãžãã¢ã«ããRed Teamã®ä»äºç޹ä»
æŠèŠ
äžè¬çãªRed TeamãµãŒãã¹ãšããæ¥åã®ç޹ä»ãè匱æ§èšºæã»ãããã¬ãŒã·ã§ã³ãã¹ããšã®éããç§ãå®éã«æ¥åã§åãçµãã§ãããªãã§ã³ã·ãã»ãã¥ãªãã£ã«é¢ããæè¡çãªåãçµã¿(æ°èŠC2ææ³ã®æ€èšŒã»éçº)ãªã©ã«ã€ããŠçºè¡šããŸãã
äž»ã«ãªãã§ã³ã·ãã»ãã¥ãªãã£ã«èå³ãããåŠçããªãã§ã³ã·ãã»ãã¥ãªãã£åéãžã®ãã£ãªã¢ãã§ã³ãžãèããŠããè¥æãšã³ãžãã¢ãªã©ã«åããçºè¡šãšãªããŸãã
ã¢ãžã§ã³ãã¯ä»¥äžã®äºå®ã§ãã
- èªå·±ç޹ä»
- æ®æ®µã®æ¥åå 容
- Red Teamãšã¯ïŒ
- Red TeamæŒç¿ã®ç®çãšæçŸ©
- ãããã¬ãŒã·ã§ã³ãã¹ããè匱æ§èšºæãšã®éã
- Red Teamãªãã§ã¯ã®æ»ææè¡
- Red Teamã®é£ãã
- Red Teamã®æè¡ç楜ãã
- å
·äœçã«æ¥åã®äžã§æ€èšŒããæ»ææè¡ã®ç޹ä»
- æ€ç¥ããã«ããæ°èŠC2ææ³ã®å®è£
ç»å£è ïŒR*
- éä¿¡äºæ¥äŒç€Ÿã®Red TeamãšããŠåã24åã»ãã¥ãªãã£ãšã³ãžãã¢
- X: @Raster0x2a_tech
LT3ïŒã¹ããã¢ããªïŒã²ãŒã ããŒã蚺æã®ãªã¢ã«ãªè匱æ§
æŠèŠ
Webã¢ããªã®è匱æ§ã¯è¯ãèãããã¹ããã¢ããªã«ã€ããŠã¯ã©ããªè匱æ§ãããããããŸãç¥ããªããšãã£ãæ¹ã¯æå€ãšå€ãã®ã§ã¯ãªãã§ããããã
ãŸããæ®æ®µãªã³ã©ã€ã³ã²ãŒã ãªã©ãããŠããŠééããããŒã¿ãŒãã¡ã䜿ãããŒãã«ã€ããŠãã©ããã£ãŠãã®ãïŒãããªãã®äººæ°ãå±
ããã©ãããŠãããªã«äººå£ãå€ããªãã®ãïŒãªã©ãçåã«æã£ãããšã¯ãããŸãããïŒ
ããã§æ¬LTã§ã¯ä»¥äžã®ïŒç¹ã«ã€ããŠãã¢åœ¢åŒã§ç޹ä»ããããšæããŸãã
- ã¹ããã¢ããªããŒãã§ã¯ãæ¥åã§è匱æ§èšºæãããŠããéã«å®éã«åºäŒã£ãè匱æ§ã®äžãã1ã€ãããã¯ã¢ããããŠãã¢ã亀ããªãã玹ä»ããŸãã
- ã²ãŒã ããŒãããŒãã§ã¯ãã²ãŒã ããŒã蚺æãšã¯äœãïŒãã©ããªããšãããã®ãïŒå®éã«ã©ã®ãããªè匱æ§(ããŒã)ãããã®ãïŒãªã©ããã¢ã亀ããªãã玹ä»ããŸãã
ç»å£è ïŒdaiki0508
- 2022幎ããGMOãµã€ããŒã»ãã¥ãªã㣠byã€ãšã©ãšæ ªåŒäŒç€Ÿã«ãŠã¢ã«ãã€ãå ¥ç€ŸããŠ2024å¹Žã«æ°åå ¥ç€Ÿã
- çŸåšã¯ã¯ã©ã€ã¢ã³ãã¢ããªã®è匱æ§èšºæãã²ãŒã ããŒã蚺æã瀟å ã®æ¥åå¹çåãªã©ãæ¥åãšããŠããã
- X: @otani_daiki
LT6ïŒã»ãã¥ãªãã£æ¥çã®æ©ãæ¹
æŠèŠ
瀟äŒäºº2幎ç®ãªãããå€éšã€ãã³ãã«ç»å£ãæž©æ³ã·ã³ããžãŠã åå ãªã©ãæ§ã ãªã»ãã¥ãªãã£ã€ãã³ãã«åå ããŠã³ãã¯ã·ã§ã³ãåºæ¥ãçµéšãããåŠçãä»ã®è¥æåå è åãã«ãªã¹ã¹ã¡ã®ã»ãã¥ãªãã£ã€ãã³ãã«ã€ããŠèªããŸãã
ç»å£è ïŒclone
- æç³»åŠåãCEHååŸæžãOSCPãšCISSPå匷äžã
- X: @misclone
LT7ïŒãã¡ãžã³ã° ãã¢ã«ããã¢ãšå®çšã§ããããªãœãããŠã§ã¢ãã¹ãææ³ã
æŠèŠ
ã»ãã¥ãªãã£è
åšãé«ãŸãäžããœãããŠã§ã¢ã®è匱æ§ãäžå
·åãèŠã€ããããã®ãã¹ãææ³ã§ãããã¡ãžã³ã°ã泚ç®ãããŠããŸãã
ãã¡ãžã³ã°ãšã¯ã"äºæããªãå
¥å"ã"äŸå€ãåŒãèµ·ãããããªå
¥å"ããœãããŠã§ã¢ã«äžããããšã§ã仿§æžã«æ²¿ã£ãäžè¬çãªãã¹ãã§ã¯èŠã€ãããªãè匱æ§ãäžå
·åãçºèŠããææ³ã§ãã
ãã®æå¹æ§ãããã¢ã«ããã¢ãšå®çšã®äž¡é¢ã§é¢å¿ãé«ãŸã£ãŠããŸãã
æ¬çºè¡šã§ã¯ä»¥äžã®å 容ãçºè¡šããäºå®ã§ãã
- ãã¡ãžã³ã°ã®åºæ¬æŠå¿µãšåé¡ã«ã€ããŠ
- åé¡ããšã«æŽçããŠãã¡ãžã³ã°ãã玹ä»ããŸãã
- åŠè¡åéã§ã®ãã¡ãžã³ã°ã®ç ç©¶ååã«ã€ããŠ
- å®çšãããŠãããã¡ãžã³ã°
- OSSãã¡ãžã³ã°ãããžã§ã¯ãã§ããGoogleã®OSS-Fuzzã«ã€ããŠç޹ä»ããŸãã
- ãã¡ãžã³ã°ã®å°æ¥å±æãšç ç©¶éçºæ¥åã§æ€èšããŠãããã€ããªãã¡ã€ã«åãã®ãã¡ãžã³ã°é«éåæè¡ã«ã€ããŠ
ç»å£è ïŒTomoki Nakashima
- NTTã®R&Dã§åãã修士å2幎ç®ç€ŸäŒäººã§ãã
- åŠçæä»£ã¯ç¡ç·LAN (IEEE 802.11)ã®éä¿¡å¶åŸ¡ã«é¢ããç ç©¶ããã£ãŠãŸããã
- X: ãªã
LT8ïŒéçºè åãããŒã«ãéæ¹é ããŠã»ãã¥ãªãã£èšºæããŒã«ãäœã£ãŠãã話
æŠèŠ
æåã»ãã¥ãªãã£èšºæãèªå蚺æSaaSãæäŸããFlatt Securityã«ã¯ãèšºææ¥åã®å®ååå¯èœãªéšåãã·ã¹ãã åããŠããæåãããã®ã·ã¹ãã ãå
補éçºããæåããããŸãã
å®éãWebã¹ãã£ãããèšºææ¥åã管çãã瀟å
ã·ã¹ãã ãORCAsãã¯ã¹ã¯ã©ããã§éçºããŠããŸãã
èšºææ¥åã§ã¯ãåè¿°ã®å
補ããŒã«ãBurp Suiteã®ãããªèšºæçšããŒã«ã ãã§ãªãããã©ãŠã¶ã®DevToolsãVSCodeã®ã³ãŒããžã£ã³ããªã©ãéçºè
åãã«äœãããããŒã«ãå©çšããŠããŸãã
ããããããã¯ãããŸã§éçºè
åãã§ãããå¿
ãããèšºææ¥åã«æé©ãªäœãã«ã¯ãªã£ãŠããŸããã
ããã§ãããã£ãéçºè
åãããŒã«ã®å®è£
ãèªãã§ãã®å
éšã®ä»çµã¿ãçè§£ãããããå
ã«èšºæã«ç¹åããæ©èœãèªåãã¡ã§éçºããããšãé²ããŠããŸãã
ãŸãããã®ããã«ããŠéçºããããŒã«ã瀟å
ã§å©çšããã ãã§ãªããåŒç€ŸãéçºæäŸããŠããèªå蚺æSaaSãShisho Cloudãã«çµã¿èŸŒãã§äºæ¥äŒç€Ÿã«ããå©çšããã ããããã«ããããšãç®æããŠããŸãã
LTã§ã¯ããããã®éçºè åãããŒã«ã®å éšå®è£ ãããããæŽ»ããã蚺æããŒã«ã®å®è£ ã«ã€ããŠè©±ãäºå®ã§ãã
ç»å£è ïŒpizzacat83
- 2020å¹Žã«æ ªåŒäŒç€Ÿ Flatt Security ã«ã¢ã«ãã€ããšããŠãžã§ã€ã³ãã2024å¹Žã«æ°åå ¥ç€Ÿã
- 2幎ã»ã©æåã»ãã¥ãªãã£èšºæã«åŸäºããã®ã¡ãçŸåšã¯ã»ãã¥ãªãã£ãããã¯ãäºæ¥éšã«ç§»ç±ããæå蚺æãæ¯ããããŒã«ãã»ãã¥ãªã㣠SaaSãShisho Cloudãã®éçºãæ åœã
- X: @pizzacat83b
åŠçæ
LT4ïŒCTFã®èª²é¡ãžã®åãçµã¿æ¹ãšãå®äžçã«å¿çšã§ããããš
æŠèŠ
CTFã«ã¯ãbinary exploitationããcryptoãŸã§å¹
åºããžã£ã³ã«ãåºé¡ãããŸãã
äžèŠããããã¯ããããç°ãªãã¢ãããŒããæ±ããããããã«èŠããŸãããå®ã¯å
±éããŠé©çšã§ããã¡ã¿çãªãã¯ããã¯ãååšããŸãã
ãã®ãã¯ããã¯ã¯ãCTFã®ã¿ã«çãŸããããã°ãã³ããã³ãŒãã£ã³ã°ãããã«ã¯ãããã¯ãéçºãªã©ãæ§ã
ãªåé¡è§£æ±ºã«å¿çšããããšãã§ããŸãã
æ¬LTã§ã¯ãå
·äœçãªæè¡ææ³ã«æ·±å
¥ãã¯ããã«ãããã®ãã¯ããã¯ã®æŠèŠã玹ä»ããŸãã
æ¬LTãéããŠãæ¥ã
ã®åé¡è§£æ±ºã«æŽ»ãããèŠç¹ãæäŸã§ããã°å¹žãã§ãã
ç»å£è ïŒkeymoon
- CTFãã¬ã€ã€ãŒãå人æŠCTFãã©ãããã©ãŒã "AlpacaHack"éçºã»éå¶ã奜ããªCTFã¯TSG CTFã
- X: @kymn_
LT5ïŒé«æ ¡çãRCEãçºèŠãããŸã§
æŠèŠ
ãã©ã€ãã·ãŒç³»OSSã«ãããŠãXSSããRCEã«çºå±ããå®éã®äºäŸã玹ä»ããŸãã
æåã«XSSãçºèŠãããããã©ã®ããã«ããŠRCEã«ç¹ãã£ãã®ãããæ»æã®æµãã«æ²¿ã£ãŠè§£èª¬ããŸãã
ãŸããä¿®æ£åŸã«æ®ã£ãŠããHTMLã€ã³ãžã§ã¯ã·ã§ã³ã«ãè§Šãããããã®ãªã¹ã¯ãšåœ±é¿ã解説ããã°ããŠã³ãã£ã®é
åã玹ä»ãããã©ã€ãã·ãŒãã»ãã¥ãªãã£ã®éèŠæ§ã«ã€ããŠèãããã£ãããæäŸããŸãã
ç»å£è ïŒSakaiSec
- 髿 ¡3幎çããã°ãã³ã¿ãŒãã»ãã¥ãªãã£ãã³ããŒã§ã®ã¢ã«ãã€ãçµéšãçµãŠã2025幎床ããæ°åå ¥ç€Ÿäºå®ã
- X: @sksec_
ã¹ãã³ãµãŒæ
æ ªåŒäŒç€Ÿãµã€ããŒã»ãã¥ãªãã£ã¯ã©ãŠã
æ ªåŒäŒç€Ÿã¢ã«ããã²ãŒã ã¹
ã¹ãã³ãµãŒ
ãŽãŒã«ãã¹ãã³ãµãŒ
æ ªåŒäŒç€Ÿãµã€ããŒã»ãã¥ãªãã£ã¯ã©ãŠã
äŒå Žã¹ãã³ãµãŒ
æ ªåŒäŒç€Ÿã¢ã«ããã²ãŒã ã¹ïŒAkatsuki Games Inc.)
ã¹ãã³ãµãŒäŒæ¥ã®åéã«ã€ããŠ
ä»åŸã¯ãåã€ãã³ãã«é¢ããŠãã¹ãã³ãµãŒäŒæ¥ãåéããŸãã
ã¹ãã³ãµãŒç¹å žãšããŠã以äžã®ãããªå å®¹ãæ€èšããŠããŸãã
- ãŽãŒã«ãã¹ãã³ãµãŒïŒ1æ ïŒ, äŒå Žã¹ãã³ãµãŒïŒ1æ ïŒ
- ã¹ãã³ãµãŒæ ã®ç¹å¥è¬æŒ
- äŒæ¥ç޹ä»ãæ¡çšæ ã®ç޹ä»
- çŸå°åå ã亀æµäŒãžã®ç¹å¥æåŸ
- ã·ã«ããŒã¹ãã³ãµãŒïŒæ°æ ïŒ
- äŒæ¥ç޹ä»ãæ¡çšæ ã®ç޹ä»
- çŸå°åå ã亀æµäŒãžã®ç¹å¥æåŸ
æ¬ã³ãã¥ããã£ãã€ãã³ãã«èå³ãããæ¹ã¯ã以äžã®ãã©ãŒã ãããé£çµ¡ãã ããã
â»çŸæç¹ã§ã¯ãäŒæ¥ã«ããã¹ãã³ãµãŒã®ã¿ã§ãå人ã«ããã¹ãã³ãµãŒã¯åãä»ããŠããŸããã
泚æäºé
- åœã€ãã³ãã®å 容ããã³ã¹ã±ãžã¥ãŒã«ã¯ãäºåãªã倿Žãšãªãå ŽåããããŸããäºããäºæ¿ãã ããã
- ããã°ãSNSçã§åœã€ãã³ãã«é¢ããçºä¿¡ãè¡ãéã¯ãå ¬åºè¯ä¿ã«åããå 容ã®ãªãããããååããé¡ãããŸãã
- åœæ¥æ®åœ±ããç»åã¯ãSNSçã§ã€ãã³ãã®ç޹ä»ã«å©çšãããŠããã ãå¯èœæ§ããããŸãããªããç»åæ®åœ±ãNGã®æ¹ã¯æå€§éé æ ®ããããŠããã ããŸãã®ã§ãäºãconnpassã®ã¡ãã»ãŒãžãXã®DMãªã©ã§éå¶ã¡ã³ããŒã«ãç¥ãããã ããã
- ã€ãã³ãäŒå Žã®äŒæ¥ãšæ¬ã€ãã³ãã®éå¶ã¯ç¡é¢ä¿ã§ããæ¬ã€ãã³ãã«å¯Ÿããã質åã¯éå¶ã¡ã³ããŒã«ãé¡ãããããŸããã€ãã³ãäŒå Žã®äŒæ¥ã«æ¬ã€ãã³ãã«é¢ããŠã®ãåãåããã¯ãæ§ãããã ããŸããããé¡ãããããŸãã
ãŸãããåå è ã®æ¹ã ãæå€§é楜ããã§é ãããããéå¶ãµã€ãã§åå ã«ãµãããããªããšå€æãããŠé ããæ¹ã«ã€ããŠã¯ãã€ãã³ãäžã§ããããšãéåžããé¡ãããããšãããããŸãã
çŠæ¢è¡çº
以äžã®è¡çºã¯åºãçŠããããŠããŸãïŒ
- ãã©ã¹ã¡ã³ããå·®å¥çãªèšå
- æŽåçãªè¡çºãè è¿«
- äžé©åãªèº«äœçæ¥è§Š
- æ§çãªç»åãèšèªã®äœ¿çš
- ä»è ã®ãã©ã€ãã·ãŒã䟵害ããè¡çº
- ã€ãã³ãã®é²è¡ã劚ããè¡çº
- ã€ãã³ãã®è¶£æšã«ããããªãé床ãªå¶æ¥è¡çº
çŠæ¢è¡çºã«éåããè¡çºãè¡ã£ãæ¹ã¯ã€ãã³ãã®éåºã以åŸã®ã€ãã³ãåå ããæãããããšããããŸãã
DiscordãµãŒããŒ
åå è ã«ã¯ãåŸæ¥ãã»ãã¥ãªãã£è¥æã®äŒãçšã®DiscordãµãŒããŒã«æåŸ ããŸãã
ãã¡ãã«ãŠãåœæ¥ã®æ¡å ãæ å ±å ±æã®å ŽãšããŠæŽ»çšããŸãã
泚æäºé
â» ãã¡ãã®ã€ãã³ãæ å ±ã¯ãå€éšãµã€ãããååŸããæ å ±ãæ²èŒããŠããŸãã
â» æ²èŒã¿ã€ãã³ã°ãæŽæ°é »åºŠã«ãã£ãŠã¯ãæ å ±æäŸå ããŒãžã®å 容ãšå·®ç°ãçºçããŸãã®ã§äºããäºæ¿ãã ããã
â» ææ°æ å ±ã®ç¢ºèªãåå ç³èŸŒæç¶ããã€ãã³ãã«é¢ãããåãåããçã¯æ å ±æäŸå ããŒãžã«ãŠãé¡ãããŸãã

ãåãåãã
é¢é£ããã€ãã³ã

ã¯ã©ãŠãRADIUSã§ç¡ç·LANèªèšŒãå®å šã«å®çŸ ç¡ç·AP10ãã³ããŒã®éããšã¯ïŒïŒCisco Meraki / HPE Aruba / Juniper Mist / Extreme Networks...
2026/04/16(æš) éå¬
ãWebã»ãããŒããŒããã©ã¹ãå®è£ ã®å§ãæ¹ïœOSS掻çšã§ã³ã¹ããæããŠå°å ¥ïœ
2026/04/23(æš) éå¬
ææ°ãN2WS 4.5ãã§ã¯ã©ãŠãããã¯ã¢ããããã匷åºã«ïŒEKS/S3ã®ããŒã¿ä¿è·ããAzureå¯Ÿå¿æ¡åŒµãªã©æ°æ©èœã玹ä»ïŒ
2026/04/17(é) éå¬
èè é£ããåŠã¶ãMCPã®ä»çµã¿ããAIãšãŒãžã§ã³ãæ§ç¯ãŸã§ãAWSÃAIã®å®è·µããŠããŠãLTB#6
2026/04/21(ç«) éå¬
AWSå匷äŒïœåå¿è æè¿ïœAWSè³æ Œã£ãŠäœããåãã°ããïŒçŸåœ¹ãšã³ãžãã¢ãå šäœåã解説ïŒããã£ãªã¢çžè«å¯ã
2026/04/07(ç«) éå¬- TOP
- ã€ãã³ã
- 第1å ã»ãã¥ãªãã£è¥æã®äŒïŒLT&亀æµäŒïŒ
