ã»ãã¥ãªãã£
ã¯ããã« ããã«ã¡ã¯ãã»ãã¥ãªãã£ã»ã¨ã³ã¸ãã¢ã®æ¡åã§ãã ååã®ããã°ã§ããç´¹ä»ãã¾ãããã社å ã®ãµã¤ãã¼åæãµã¼ã¯ã«ã¨ããæè¡ãµã¼ã¯ã«ã§æ´»åãã¦ãã¾ãã ãã®ãµã¼ã¯ã«ã§ã¯ããµã¤ãã¼ã»ãã¥ãªãã£ã«é¢ããç¥è¦ãæ·±ããããã社å ã«å±éãã¦ãããâ¦
ã¯ããã« æ±äº¬ç ç©¶éçºç¬¬ä¸é¨ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®ä½è¤ã§ããæ¬è¨äºã§ã¯ãPython ãã¼ã¹ã®ãã¤ããªã¨ãã¥ã¬ã¼ã·ã§ã³ãã¬ã¼ã ã¯ã¼ã¯ã§ãã Qiling Framework (以é Qiling ã¨è¡¨è¨) ã«ã¤ãã¦ç´¹ä»ãã¾ãã ãµã¤ãã¼ã»ãã¥ãªãã£æè¡ã«ã¯ãããã¸ã¡ã³ããèâ¦
ã¯ããã« ããã«ã¡ã¯ãåºç¤æè¡ç ç©¶é¨ã®ä¸å·ã§ãã9 æã«ãã«ãªã³ã§è¡ããã Nullcon Berlin 2025 ã«ç»å£ãã¦ãã¾ããããã®è¨äºã§ã¯ãç»å£ã«è³ãã¾ã§ã®çµç·¯ãçºè¡¨å 容ãããã¦å®éã«åå ãã¦æãããã¨ã主ã«ç´¹ä»ãã¾ãã Nullcon ã«ã¤ã㦠Nullcon 㯠2010â¦
ã¯ããã« 2025 å¹´ 9 æ 12 æ¥ãã 15 æ¥ã® 4 æ¥éãNFLabs. ã¨ï¼¦ï¼¦ï¼²ï¼©ã»ãã¥ãªãã£ã®å ±åã§ãµã¤ãã¼ã»ãã¥ãªãã£ã³ã³ãã¹ã FFRI à NFLabs. Cybersecurity Challenge 2025 ãéå¬ãã¾ããã connpass.com ä»å¹´ã¯éæã¨ä¸é£ä¼æéã«éå¬ãã¾ããã伿¥ã¨ããâ¦
ã¯ããã« ããã«ã¡ã¯ãåºç¤æè¡ç ç©¶é¨ã®ä¸å·ã§ãã 8 æã«ã©ã¹ãã¬ã¹ã®ãã³ãã¬ã¤ãã¤ã§éå¬ããã Black Hat USA 2025 ã«ç»å£ãã¾ããã ãã®è¨äºã§ã¯ Black Hat ã®æ¦è¦ãç°¡åã«ç´¹ä»ããå¾ãèªèº«ã®çºè¡¨å 容ãç»å£ã«è³ãçµç·¯ãç¾å°ã§è´è¬ããçºè¡¨ã«ã¤ãã¦ã¾â¦
ã¯ããã« ããã«ã¡ã¯ãåºç¤æè¡ç ç©¶é¨ã®æ¾å°¾ã§ãã 8 æã«ãã©ã¹ãã¬ã¹ã®ãã³ãã¬ã¤ãã¤ã«ã¦è¡ããã Black Hat USA 2025 ã® Briefings ã«ç»å£ãã¦ãã¾ããã ãã®è¨äºã§ã¯ç»å£ã«è³ãã¾ã§ã®çµç·¯ãããã©ãããã©ã¼ã ã»ãã¥ãªãã£åã³ä½ã¬ã¤ã¤ã¼ã«ã¾ã¤ããé¢â¦
ã¯ããã« ããã«ã¡ã¯ãã»ãã¥ãªãã£ã»ã¨ã³ã¸ãã¢ã®æ¡åã§ãã ãã®ãã³ã社å ã§ãµã¤ãã¼åæãµã¼ã¯ã«ã¨ããæè¡ãµã¼ã¯ã«ãç«ã¡ä¸ãã¾ããã ãã®ãµã¼ã¯ã«ã§ã¯ããµã¤ãã¼ã»ãã¥ãªãã£ã«é¢ããç¥è¦ãæ·±ããããã社å ã«å±éãã¦ãããã¨ãç®æãã¦ãã¾ãã ãâ¦
ã¯ããã« 2023 å¹´ 12 ææ«ãã 2024 å¹´ 12 ææ«ã«ããã¦ãOSCP+ ãåé¨ãã¾ããã ãã¬ã¼ãã³ã°ãéå§ããæç¹ã§ã¯ OSCP ã ã£ãã®ã§ãããéä¸ã§ OSCP+ ã«å¤æ´ããã¾ããã ç§ãåããã®ã¯ Learn One ã¨ãã 1 å¹´éã®ãã¬ã¼ãã³ã°ãã©ã³ã§ãã ããã¯è©¦é¨ã â¦
ã¯ããã« åºç¤æè¡ç ç©¶é¨ã®æ¾å°¾ã§ãã PC ããµã¼ãã¼ã®é»æºãå ¥ããéãã¾ãã¯ããã«å®è¡ãããã®ã Basic Input/Output System (BIOS) ã¨ããã·ã¹ãã ãã¡ã¼ã ã¦ã§ã¢ã§ãã ãã BIOS ãæ»æè ã«ä¹ã£åããããããã®å¾ã«èµ·åããã OS çã好ãåæã«æ¹ãâ¦
ã¯ããã« 1 æ¦è¦ã»è«æç·¨ 2-1 LLVM 颿°è¨è£ ç·¨ 2-2 LLVM ã¢ã¸ã¥ã¼ã«è¨è£ ç·¨ (æ¬è¨äº) åºç¤æè¡ç ç©¶é¨ã®æ«åã§ãã 第 1 åã¨ç¬¬ 2 åã®è¨äºã§ã¯ãASan ã®æ¦è¦ã説æããå¾ã«ãASan ã®é¢æ°ã«å¯¾ããè¨è£ ã§ãã©ã®ãããªå½ä»¤ã追å ããããè¦ã¦ãã¾ããã ä»åã¯ãâ¦
ã¯ããã« ããã«ã¡ã¯ãåºç¤æè¡ç ç©¶é¨ã®æ¾å°¾ã§ãã 8 æã«ãã©ã¹ãã¬ã¹ã®ãã³ãã¬ã¤ãã¤ã«ã¦è¡ããã Black Hat USA 2024 ã«ç»å£ãã¦ãã¾ããã ã¾ãã9 æã«ãå½ç¤¾ã®æ°ãã¼ã¬ã¤ã¤ã¼åå¼·ä¼ã«ã¦ç»å£ã«è³ãã¾ã§ã®çµç·¯ã«ã¤ãã¦è©±ããã¦ããã ãã¾ããã ãã®è¨â¦
ã¯ããã« 2024 å¹´ 9 æ 17 æ¥ãã 20 æ¥ã® 4 æ¥éãNFLabs. ã¨ï¼¦ï¼¦ï¼²ï¼©ã»ãã¥ãªãã£ã®å ±åã§ãµã¤ãã¼ã»ãã¥ãªãã£ã³ã³ãã¹ã FFRI Security x NFLabs. Cybersecurity Challenge for Students 2024 ãéå¬ãã¾ããã connpass.com å¹³æ¥ã®éå¬ã§ããããå¤ãã®â¦
ã¯ããã« ããã«ã¡ã¯ã製åéçºé¨ã®æ³ã§ãã ç§ã¯ãå½ç¤¾ã®ä¸»è¦ã»ãã¥ãªãã£ãããã¯ãã§ãã FFRI yarai ãéä¸ç®¡çãã FFRI AMC(以ä¸ãAMC)ã¨ãã Web ã¢ããªã±ã¼ã·ã§ã³ã®éçºã»ä¿å®æ¥åãè¡ã£ã¦ãã¾ãã ç¾å¨ AMC ã«ã¯ãã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ããç¨ããå¤è¦â¦
ã¯ããã« 1 æ¦è¦ã»è«æç·¨ 2-1 LLVM 颿°è¨è£ ç·¨ (æ¬è¨äº) 2-2 LLVM ã¢ã¸ã¥ã¼ã«è¨è£ ç·¨ åºç¤æè¡ç ç©¶é¨ã®æ«åã§ãã ååã®è¨äºã§ã¯ ASan ã®æ¦è¦ã¨ä½¿ãæ¹ãè«æã«ã¤ãã¦è§£èª¬ãã¾ããã ä»åããã¯å·çæç¹ææ°çã® 2024 å¹´ 5 æã«ãªãªã¼ã¹ããã LLVM 18.1.5 ã®â¦
Summary FFRIã»ãã¥ãªãã£ã§ã¯ãæ¢åã®ã¯ã©ã¦ãç°å¢ã«ããã Observability ãã¼ã«ãã»ã¨ãã© Linux ã³ã³ããåãã§ããäºã«æ³¨ç®ãã¾ãããããã§ Windows ã³ã³ããåãã® Eolh ãéçºã OSS ã¨ã㦠GitHub ã«å ¬éãããã¾ããã Background ã¯ã©ã¦ããâ¦
ã¯ããã« 1 æ¦è¦ã»è«æç·¨ (æ¬è¨äº) 2-1 LLVM 颿°è¨è£ ç·¨ 2-2 LLVM ã¢ã¸ã¥ã¼ã«è¨è£ ç·¨ åºç¤æè¡ç ç©¶é¨ã®æ«åã§ãã ãã°ãæ¤ç¥ãããã¼ã«ã«ãµãã¿ã¤ã¶ã¼(Sanitizer)ã¨ãããã®ãããã¾ãã è±èªã§ Sanitizer ã¯ãæ¶æ¯å¤ãã¨ããæå³ã§ãHand Sanitizer ãªãæâ¦
ã¯ããã« ããã«ã¡ã¯ãåºç¤æè¡ç ç©¶é¨ã®èæ¨ã§ãã ä»å¹´ã®å¤ã¯ä¾å¹´ä»¥ä¸ã«æãã£ãã§ãããæãã¨è¨ãã°ãæ¨å¹´ ChatGPT[1]ã OpenAI ã«ãã£ã¦å ¬éããã¦ãã AI å¨ããç±ããªã£ã¦ãã¾ããå ¬é彿ãåãã¨æãã¾ããããããã§ãããã¾ã§å¤§è¦æ¨¡ãªç¤¾ä¼ç¾è±¡ã«ãªâ¦
ã¯ããã« åºç¤æè¡ç ç©¶é¨ãªãµã¼ãã»ã¨ã³ã¸ãã¢ã®å è¤ã§ãã ä¾å¹´å¤ã«éå¬ããã Black Hat USA ãä»å¹´ãéå¬ããã¾ãããæ¬ããã°ã§ãæ¯å¹´æ³¨ç®çºè¡¨ãç´¹ä»ãã¦ãããæ¬è¨äºã§ã¯è¿å¹´æ³¨ç®ãéãã¦ãããã©ã¤ãã·ã¼ã«é¢é£ããçºè¡¨ãç´¹ä»ãã¾ãã Black Hat USA 2â¦
ã¯ããã« ã»ãã¥ãªãã£ãµã¼ãã¹é¨ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®å²¡æ¬ã§ããæ¬è¨äºã§ã¯ãWindows ã®ã¤ãã³ããã°è§£æãã¼ã«ã§ãã Hayabusa ã«ã¤ãã¦ç´¹ä»ãã¾ãã ã»ãã¥ãªãã£ã¤ã³ã·ãã³ãã«è¿ éãã¤æ£ç¢ºã«å¯¾å¿ããããã«ã¯ã䏿£ã¢ã¯ã»ã¹ããã«ã¦ã§ã¢ææãªã©ãâ¦
ã¯ããã« ç ç©¶éçºç¬¬äºé¨ãªã¼ãã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®ä¸ç¬ã§ããå æ¥ã¯ãã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ãç®æã人ã«ç¥ã£ã¦ããã¦ã»ããçµç¹ããå ¬éãã¾ãããä»åã¯ãã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ãç®æã人ã«ç¥ã£ã¦ããã¦ã»ããå¶åº¦ãã¬ã¤ãã©ã¤ã³ããµã¼ãã¹ã«ã¤ãâ¦
ã¯ããã« ç ç©¶éçºç¬¬äºé¨ãªã¼ãã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®ä¸ç¬ã§ããã»ãã¥ãªãã£ã¨ã³ã¸ãã¢å士ã®ä¼è©±ã§ã¯ãã"ã·ãµ"ãæè¿ã¾ãã¬ãã¼ãåºãã¦ãã¦â¦ãã¨ãã"ã¢ã¤ãã¼ã¨ã¼"ããæ³¨æåèµ·åºã¦ãããã¨ãã£ããåå¦è ã«ã¯è¬ã®åèªãããããåºã¦ãã¾ããæ¬è¨äºâ¦
ã¯ããã« ãä¹ ãã¶ãã§ããã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®æ¡åã§ãã è¿å¹´ãGo è¨èªã«ãã£ã¦ä½æããããã«ã¦ã§ã¢ãå¢å ãã¦ãã¾ãã Go è¨èªã®ç¹å¾´ã¨ãã¦éçºã®å®¹æããä»»æã®ç°å¢ã«åãã¦ãã«ããè¡ãã¯ãã¹ã³ã³ãã¤ã«ãå¯è½ã§ããã¨ãã£ãç¹ãããã¾ãã æ»æâ¦