ã¯ããã«
2024 å¹´ 9 æ 17 æ¥ãã 20 æ¥ã® 4 æ¥éãNFLabs. ã¨ï¼¦ï¼¦ï¼²ï¼©ã»ãã¥ãªãã£ã®å ±åã§ãµã¤ãã¼ã»ãã¥ãªãã£ã³ã³ãã¹ã FFRI Security x NFLabs. Cybersecurity Challenge for Students 2024 ãéå¬ãã¾ããã
å¹³æ¥ã®éå¬ã§ããããå¤ãã®å¦çã®æ¹ã ã«ãåå ããã ãæ¥½ããã§ããã ãã¾ããã æ¬è¨äºã§ã¯æ¬ã³ã³ãã¹ãã®ç°¡åãªéå¬å ±åã¨ãè¨äºã®æå¾ã«ã¯çãããå¾ ã¡ãããåå è ããå¿åããã ãã Writeup ã®ä¸ãã FFRI Writeup è³ãçºè¡¨ãã¾ãã
ã¤ãã³ãã«ã¤ãã¦
ãã®ã³ã³ãã¹ãã¯ãåé¡å½¢å¼èªä½ã¯ CTF ã¨åæ§ã«é ããããã©ã°ãæ¢ããã®ã§ããããã«ã¦ã§ã¢è§£æããã³ãã¹ããªã©é常㮠CTF ã§ã¯ãã¾ãè¦æããªãå®åå¯ãã®ã¸ã£ã³ã«ãåºé¡ããã¦ããç¹ãç¹å¾´ã§ãã ã¢ã³ã±ã¼ãçµæãè¦ã¦ãããä»ã® CTF ã§ã¯åºé¡ãããªããããªãã³ãã¹ãã¨ããã¸ã£ã³ã«ãããé¢ç½ããã¨ãã声ãããã¾ããã
å»å¹´ã¯ NFLabs. ã®åç¬éå¬ã§å®æ½ããã¦ããã³ã³ãã¹ãã§ãããä»å¹´ã¯å½ç¤¾ãå ãããå ±åéå¬ã¨ããå½¢ã«ãªãã¾ããã æ¥æ¬å½å ã®é«çå°é妿 ¡ãå°é妿 ¡ã大å¦ã大å¦é¢ã«æå±ããå¦çã対象ã¨ããconnpass ã§åå ãåéãã¾ãããæçµçã«ã¯å®å¡ã® 80 åãè¶ ããå¿åãããã ããæ½é¸ã宿½ãæçµçãªåå è ãæ±ºå®ãã¾ããã
åé¡ã¯ä»¥ä¸ã® 5 ã¸ã£ã³ã«ã§ãå ¨ 17 åãåè¨ 20 ãã©ã°ãåºé¡ãã¾ããã
- Web Exploitation (Web èå¼±æ§æ»æãå ¨ 3 å)
- Pentest (ãããã¬ã¼ã·ã§ã³ãã¹ããå ¨ 3 åã1 åãè¤æ°æ®µéã«åãã¦ããããåè¨ 6 ãã©ã°)
- Binary Exploitation (ãã¤ããªèå¼±æ§æ»æãå ¨ 3 å)
- Malware Analysis (ãã«ã¦ã§ã¢è§£æãå ¨ 3 å)
- Misc (ä¸è¨ 4 ã¸ã£ã³ã«ã«å±ããªãã¸ã£ã³ã«ãå ¨ 5 å)
æ¨å¹´åºé¡ãã¦ãã OSINT ããªããªãã代ããã« Binary Exploitation (ãããã Pwnable) ãæ°è¨ãã¾ããã
åºé¡æ°ãå°ãå¤ãã§åºé¡ã®ç¯å²ãå¤å²ã«ããã£ã¦ãã¾ããããã¹ã¦ã®åé¡ã«ã¤ã㦠1 人以ä¸ã®æ£è§£è ãåºã¦åºé¡è ã¨ãã¦ã¯å¬ããéãã§ãã
ã¾ããåªç§ãªæç¸¾ãåããæ¹ã«è³éãè´åãã¾ããã
- ç·åå¾ç¹ 1 ä½ è³é 7 ä¸å
- ç·åå¾ç¹ 2 ä½ è³é 5 ä¸å
- ç·åå¾ç¹ 3 ä½ è³é 3 ä¸å
- ç·åå¾ç¹ 4 ä½ è³é 2 ä¸å
- ç·åå¾ç¹ 5 ä½ è³é 1 ä¸å
- ã¸ã£ã³ã«å¥ãããè³
- Web Exploitation 1 ä½ è³é 1 ä¸å
- Pentest 1 ä½ è³é 1 ä¸å
- Malware Analysis 1 ä½ è³é 1 ä¸å
- Binary Exploitation 1 ä½ è³é 1 ä¸å
- Writeup è³ è³é 1 ä¸å Ã2 æ¬ (å½ç¤¾é¸å® 1 æ¬ãNFLabs. é¸å® 1 æ¬)
彿¥ã¯é常æ¥åãããªããªããã¹ã³ã¢ãµã¼ãã¼ãè¦ã¦å®æ³ãã¦ããã®ã§ããããªãã¨ç«¶æéå§ 5 åã§ Binary Exploitation ã®æåã®ãã©ã°ãæåºããæ¹ããããªã©ããã¤ã¬ãã«ãªæ¦ããè¦ããã¾ããã
æçµæ¥ã«ã¯å½ç¤¾ CTO éå± ããã³ NFLabs. CTO æ¾æ¨ãããåè³è ãçºè¡¨ãã¾ããã åè³è ã¯ä»¥ä¸ã®éãã§ããçæ§ããã§ã¨ããããã¾ãï¼
- 1 ä½ keymoon ãã
- 2 ä½ prime_1019 ãã
- 3 ä½ iwashiira ãã
- 4 ä½ 4equest ãã
- 5 ä½ moratorium08 ãã
- ã¸ã£ã³ã«å¥ãããè³
- Web Exploitation keymoon ãã
- Pentest prime_1019 ãã
- Malware Analysis keymoon ãã
- Binary Exploitation keymoon ãã
æä¸å¼ã®å¾ã«ã¯ãåä½åè ã«ããä¸é¨åé¡ã®è§£èª¬ãè¡ãã¾ãããDiscord ã§éæè³ªåãåãä»ããªããã®å®æ½ã§ããããå¦çå士ã§ãåé¡ã®è§£æ³ã«ã¤ãã¦è°è«ãå§ã¾ããªã©éå¸¸ã«æ´»æ³ã§ãããããã®ç®ããè¦ã¦ãé常ã«é«åº¦ãªè°è«ããã¦ãããçããã®æè¡åã®é«ãã«é©ãã¾ããã
FFRI Writeup è³
NFLabs. ããã³å½ç¤¾ã§ããããé¸å®ãããç´ æ´ãããå 容㮠Writeup ã« Writeup è³ (è³é 1 ä¸å) ãè´åãã¾ãã ã§ã¯ãå½ç¤¾é¸å®ã® FFRI Writeup è³ãçºè¡¨ãã¾ãï¼
é¸å®ã®çµæãä»åã® FFRI Writeup è³ã¯ yukichi ããã«ãéããããã¾ããããã§ã¨ããããã¾ãï¼
é¸å®çç±ã¨ãã¦ã¯ã失æãå«ãã試è¡é¯èª¤ãèãããã¨ãææ³ãè©³ç´°ã«æ¸ããã¦ãã¦ãèªãã§ãã¦ã¨ã¦ãé¢ç½ãå 容ã ã£ããã¨ãã¾ããæéå ã«è§£ããªãã£ãåé¡ã調ã¹ã¦è§£ãã¦ããç¹ãªã©ãæããã¾ããã
ãã®ä»ã«ããç´ æ´ããã Writeup ããå¿åããã ãã¾ããããããã¨ããããã¾ãããé ä¸åã«ãªãã¾ããã以ä¸ã«ãªã³ã¯ãæ²è¼ããã¦ããã ãã¾ãã ãªããNFLabs. Writeup è³ã¯ NFLabs. ã®ããã°è¨äºãã覧ãã ããã
- 4equest ãã FFRI Security x NFLabs. Cybersecurity Challenge For Students 2024 writeup
- blend-tea ãã FFRI Security x NFLabs. Cybersecurity Challenge For Students 2024 Writeup
- kk0128 ãã FFRI Security x NFLabs. Cybersecurity Challenge For Students 2024ï¼Writeup
- siro317 ãã FFRI Security x NFLabs. Cybersecurity Challenge For Students 2024 writeup
- iwashiira ãã FFRI Security x NFLabs. Cybersecurity Challenge'24 Writeup
- prime_1019 ãã FFRI Security x NFLabs. Cybersecurity Challenge For Students 2024 Writeup
ãããã«
å ±åéå¬ãããµã¤ãã¼ã»ãã¥ãªãã£ãã£ã¬ã³ã¸ã®éå¬å ±åã§ãããæ¹ãã¦ãä»ååå ããã ããçæ§ã«å¾¡ç¤¼ç³ãä¸ãã¾ãã
ä»åã®ã¤ãã³ããéãã¦ãFFRIã»ãã¥ãªãã£ã NFLabs. ã«å°ãã§ãèå³ãæã£ã¦ããã ããã幸ãã§ãã
ä»å¾ãããããã¤ãã³ãã®éå¬ãæ¤è¨ãã¦ãã¾ããæ å ±ã¯ X*1*2 ãªã©ã§éæçºä¿¡ãã¦ãã¾ãã®ã§ããã²ãã©ãã¼ãã¦ææ°ã®æ å ±ããã§ãã¯ãã¦ãã ããã
