âæ»æè ã®é¢å¿ã®å¤å å ã«æ²è¼ãããDan Kaminskyæ°ã®ã¤ã³ã¿ãã¥ã¼ã§ã触ãããã¦ããããæã®æ»æè ã¯èå³æ¬ä½ã§ä¸æ£ã¢ã¯ã»ã¹ãè¡ã£ã¦ããããæè¿ã§ã¯æããã«ééãæ±ãã¦æ»æãè¡ãæ¹é¢ã«ã·ãããã¦ãããLove LetterãCode Redã®ãããªå¤§è¦æ¨¡ãªã»ãã¥ãªãã£ã¤ã³ã·ãã³ããæè¿çºçãã¦ããªãã®ã¯ãåç¥ã®éãã ãããã®ä¸å ã«âãããªãã¨ããã¦ãéå²ãã«ãªããªãâã¨ããå´é¢ããããã¨ã¯è¦éããªãã ã¤ã³ã¿ã¼ãããã®æªç¨ãã©ã®ããã«ãéå²ãã«ç¹ããã®ãã«ã¤ãã¦èªãããArian Evansæ°ã®ä»åã®è¬æ¼ã¯ãæ¥å¸¸çã«èªããããã¨ããã¾ããªããããä¸çã®å´é¢ãæµ®ã彫ãã«ããã¨ããæå³ã§ãé常ã«èå³æ·±ãå 容ã§ãã£ãã âãã¯ã¯ã³ã³ãã¹ãã®å¿ åæ³ æåã«ç´¹ä»ãããã®ã¯ãAustin American Statesmanã¨ããæ°èç´ã主å¬ãããã¯ã¯ã³ã³ãã¹ãã§ã®ãã¨ã§ãã£ã
ä¼è¤ãèä» æ ªå¼ä¼ç¤¾ã©ã㯠2008/12/8 BHJã楽ããããã«å¿ è¦ãªãã¡ãã£ã¨ããTips ããã§ã¯ãçè ã®çµé¨ãããBHJã楽ããããã®æºåãã³ããããã¤ãç´¹ä»ããã¦ããã ãã¾ãã âãã®1ããã¼ãPCãæåãããï¼ ç¡ç·LAN対å¿ã®ãã¼ãPCã®æåããªã¹ã¹ã¡ãã¾ããå¯è½ã§ããã°ãCDï¼DVD-ROMãã©ã¤ããç¨æã§ããã¨ãã¿ã¼ãããã«é·æé対å¿ã§ããã¨ã¢ã¢ãã¿ã¼ã§ãã è¬æ¼è³æãCD-ROMã§å½æ¥é å¸ããããããCD-ROMãã©ã¤ãããªãã¨å°ãã¾ãããã¼ãPCã«CD-ROMãã©ã¤ããä»ãã¦ããªãå ´åã¯ããããããUSBã®CD-ROMãã©ã¤ããæºå¸¯ããã¨ä¾¿å©ã§ããå¨å²ã®å°ã£ã¦ãã人ã«è²¸ãã¦ããããã¨ã§ãã³ãã¥ãã±ã¼ã·ã§ã³ã®ãã£ããã«ããªãã¾ããçè ã¯CD-ROMãã©ã¤ããä»ãã¦ããªãPCãæåãã¦ãããå°ã£ã¦ãã人ãã ã£ãã®ã§ãããæ®å¿µãªããå¨å²ã«CD-ROMãã©ã¤ããæã¡åããã¦
ä¼è¤ãèä» æ ªå¼ä¼ç¤¾ã©ã㯠2008/12/8 1æ¥ç®ã®æ§åã«å¼ãç¶ããå¾ç·¨ã§ã¯2æ¥ç®ã«æ°å¤ãç»å ´ããæ¥æ¬äººã¹ãã¼ã«ã¼ã®å§¿ãããã¦ã¤ãã³ãã楽ããããã®Tipsãå¿æ§ããã¬ãã¼ããã¾ãï¼ç·¨éé¨ï¼ åç·¨ã«å¼ãç¶ãããBlack Hat Japan 2008ãï¼ä»¥ä¸BHJ 2008ï¼ãã¬ãã¼ããã¾ããä»åã¯2æ¥ç®ã«éå¬ãããã»ãã·ã§ã³ã«ãã©ã¼ã«ã¹ãã¤ã¤ãçè ã®è¦ç¹ããBHJã®æ¥½ãã¿æ¹ãç´¹ä»ããã¦ããã ãã¾ãã æ¥æ¬äººã¹ãã¼ã«ã¼ãç¶ã ç»å£ 5åç®ãè¿ããBHJ 2008ã§ã¯ãåç·¨ã§ç´¹ä»ãããããã¨ã¼ã¸ã§ã³ãã®é·è°·å·é½ä»æ°ãå«ããåè¨5人ã®æ¥æ¬äººæè¡è ãç»å£ãã¾ãããã©ã®ã¹ãã¼ã«ã¼ãåã ããã»ãã¥ãªãã£ã¨ãã¹ãã¼ãã第1åã®BHJ 2004以éãæ¥æ¬äººã¹ãã¼ã«ã¼ãæ¸å°å¾åã«ãã£ãã¨ãããä¸æ°ã«çãè¿ããæãã§ãã ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã¯æ¥æ¬ããï¼ - ã©ã㯠å·å£æ´æ° ãææ©ããããããªã«
ç§ã¯ããè¦ããBlack Hat Japan 2008ï¼åç·¨ï¼ æ¥æ¬ããä¸çã¸åºããã ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®è¼ª éååä¸ ä¸åå¼å ¸ æ ªå¼ä¼ç¤¾ã©ã㯠2008/12/4 æ¥æ¬äººãå¤æ°ç»å£ããBlack Hat Japan2008ãå°éæ§ã®é«ãã¤ãã³ãã¯ãåå ãã人ã®ç«å ´ãçµé¨ã«ãã£ã¦ãè¦ãã¦ãããã®ãç°ãªãã¯ãã§ããããã§ã³ã©ã ã§ã®ã¬ãã¼ãã«å¼ãç¶ããã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã¨ããç«å ´ã§ãBlack Hat Japanããè¦ãã¤ãã³ãã¬ãã¼ãã2åã«åãã¦ãéããã¾ãï¼ç·¨éé¨ï¼ 2008å¹´10æ8ã9æ¥ã«æ±äº¬ã»æ°å®¿ã®äº¬çãã©ã¶ããã«ã§è¡ããããBlack Hat Japan 2008ãã«åå ãã¾ãããæ¬è¨äºã§ã¯ãã®ã¤ãã³ãã®ã¬ãã¼ãã®åç·¨ã¨ãã¦ã1æ¥ç®ã®è¬æ¼ãä¼å ´é¢¨æ¯ãç´¹ä»ãã¾ãã Black Hat Japanããããã Black Hat Japanï¼ä»¥ä¸ãBHJï¼ã¯ä¸ççã«æåãªã»ã
Black Hat Japan 2008 GIFï¼JARï¼GIFARãã¡ã¤ã«ã§ãã¡ã¤ã³ãã¼ã¹ã®ä¿¡é ¼ã¯ç ´å£ãããããã¤ãµã³ã»ãã¯ãã£ã¼ã¿ã¼æ° 2008å¹´10æ10æ¥ã«éå¬ãããBlack Hat Japan 2008ã§ããã¤ã³ã¿ã¼ãããã¯å£ãã¦ãã:Document.Cookieã®ãããå´ãã¨ãããã¼ãã§ãã¤ãµã³ã»ãã¯ãã£ã¼ã¿ã¼æ°ãçºè¡¨ããããã¯ãã£ã¼ã¿ã¼æ°ã¯GIFãã¡ã¤ã«ã«æãå ãããã¨ã§ãGIFç»åãã¡ã¤ã«ã ãJARãã¡ã¤ã«ã¨ãã¦ãèªèããGIFARãã¡ã¤ã«ãç´¹ä»ããã ãã®GIFARãã¡ã¤ã«ãæ´»ç¨ãããã¨ã§ãã¤ã³ãã©ãããããã¹ã¯ããããªã©ã®ã¯ã©ã¤ã¢ã³ããµã¤ãã®æ å ±ãçããã¨ãã§ããå¯è½æ§ãããã¨çºè¡¨ããã âGIFãã¡ã¤ã«ã¨ãã¦ã¢ãããã¼ãããJARã¨ãã¦åä½ããGIFARãã¡ã¤ã« GIFARãã¡ã¤ã«ã¯ãç»åãã¡ã¤ã«ã§ããGIFå½¢å¼ã®ãã¡ã¤ã«ã®å¤è¦ããã¦ããªãããJava
ä»ããã§ãããå æBlackHat Japanã«è¡ã£ã¦ãã¾ãããä»å¹´ã¯ä¸é¨ã®ã»ãã·ã§ã³ã¨æ親åã®ã¿ã®åå ã§ããããç°¡åã«ã¬ãã¼ããã¾ãã ã»ãã·ã§ã³ Understanding Targeted Attacks with Office Documents Officeããã¥ã¡ã³ãã使ã£ãæ»æãç解ããã by Bruce Dang (ãã«ã¼ã¹ã»ãã³æ°ï¼ MS Office 2003以åã®PowerPointãExcelãWordãªã©ã®èå¼±æ§ã使ã£ãæ¨çåæ»æã¨ããæ°å¹´åé¡ã¨ãªã£ã¦ãã¾ããããã®è§£ææ¹æ³ã対çã«ã¤ãã¦ã®ã»ãã·ã§ã³ã§ãããOffice 2003ã§ã¯ãã¤ããªå½¢å¼ã®ãã¡ã¤ã«ãã©ã¼ãããã®æ§é (PowerPoint, Excel)ã解ææ¹æ³(CãPythonã§è§£æ)ã対çæ¹æ³(Office 2007, 2003 SP3, MOICE)ãExploitã®æ§é ãªã©ã«ã¤ãã¦è§£èª¬ããã¾ããã
çãããããã«ã¡ã¯ãå·å£ã§ãã2008å¹´10æ9æ¥ã10æ¥ã«äº¬çãã©ã¶ããã«ã§è¡ããããBlack Hat Japan 2008ãã§è¬æ¼ããæ©ä¼ãããã¾ãããã»ãã¥ãªãã£ã®å½éçã«ã³ãã¡ã¬ã³ã¹ã§ããBlack Hatã§è©±ããã¨ãã§ãããã¨ã¯å¤§å¤å æ ãªãã¨ã§ããä»åã¯ã¹ãã¼ã«ã¼ã¨ãã¦è¦ãBlack Hat Japan 2008ãã¬ãã¼ããã¾ãããã ãã¹ãã¼ã«ã¼ã¨ãã¦ã®åå ãã¨ããªã¹ãã¼ã¨ãã¦ã®åå ã ãã¾ã¾ã§ã¯ãªã¹ãã¼ã¨ãã¦3åãBlack Hat Japanã¸åå ãã¦ãã¾ããããªã¹ãã¼ã¨ãã¦åå ãã¦ããããã¯èªåã®èå³ã®ããåéã®ã»ãã·ã§ã³ã«åå ãã¦ãé¢ç½ãæ å ±ãéããåå è å士ã®äº¤æµããããã¨ãç®çã§ãããä¼ç¤¾ã«å ±åãã義åã¯ãããã®ã®ãèªåãçºè¡¨ãããã¨ããªãããç¹å¥ã«ç·å¼µãããã¨ã¯ããã¾ããã§ããã ããããä»åã¯ã¹ãã¼ã«ã¼ã¨ãã¦ã®åå ã§ããã¹ãã¼ã«ã¼ã«å¿åãããã¨æã£ãçç±ã¯ãæ¥
2008å¹´10æ9æ¥ã«éå¬ãããBlack Hat Japan 2008ã§ãã趣å³ã¨å®çã®æåã³ã¼ãæ»æãã¨ãããã¼ãã§ãããã¨ã¼ã¸ã§ã³ãæ ªå¼ä¼ç¤¾ã®é·è°·å·é½ä»æ°ãçºè¡¨ãããé·è°·å·æ°ã¯ã¢ããªã±ã¼ã·ã§ã³å´ã®æåã³ã¼ãå¦çã«é¢ãããã°ãå©ç¨ããããæåã³ã¼ããæåãå·§ã¿ã«æä½ãããã¨ã§ãWebã¢ããªã±ã¼ã·ã§ã³ãªã©ã«å¯¾ãã¦æ»æãè¡ããã¨ãå¯è½ã ã¨ç¤ºããã âUnicodeã¸ã®ç§»è¡æã«èµ·ãã¦ããæ··ä¹± Unicodeã¯ä¸çã§ä½¿ãããå ¨ã¦ã®æåã使ããæåã³ã¼ãã¨ããçºæ³ã§ä½ããããã®ã§ãæ¥æ¬ã§ã¯å¾æ¥ã¯EUC-JPãShift_JISãªã©ã®æåã³ã¼ãã使ããã¦ããããå¾ã ã«Unicodeã«ç§»è¡ãã¦ããããã®ç§»è¡æã§ããç¾å¨ãå¾æ¥ã®æåã³ã¼ãã¨Unicodeã¨ã®å·®éãã»ãã¥ãªãã£çãªåé¡ãçãã§ããã å®å ¨ãªæååã®ç¢ºèªãå±éºãªæååã®æ¤åºã¨ãã£ããæååãæ¯è¼ãã¦å¦çããã¨ããã»ãã¥ãªãã£ã®
æè¡ã¯è¨èã®å£ãè¶ããï¼ãBlack Hat Japan 2008ï¼AVTokyo2008ï¼åç·¨ï¼ï¼Security&Trust ã¦ã©ããï¼55ï¼ 2008å¹´10æ9ã10æ¥ã«éå¬ããããBlack Hat Japan 2008ãã¨ãç¿æ¥ã®11æ¥ã«éå¬ãããBlack Hat Japanã®ã¢ãã¿ã¼ã¤ãã³ãã¨ãã¦ãä½ç½®ä»ãããã¦ãããAVTokyo2008ãã«åå ãã¦ãã¾ããã å½éã»ãã¥ãªãã£ã«ã³ãã¡ã¬ã³ã¹ã¨ãã¦ç¥ãããBlack Hatã¨ãæ¨å¹´ã¾ã§ã¯Black Hat Japanã®åå è ã®ã¿ã®ãã©ã¤ãã¼ããã¼ãã£ã ã£ãAVTokyo2008ã«ã¤ãã¦ãåå¾ç·¨ã®2åã«åãã¦ãå±ããã¾ãã 10年以ä¸ã®æ´å²ãæã¤Black Hatï¼ãã©ãã¯ãããï¼ã¯ãæå 端ã®æè¡ãã»ãã¥ãªãã£ã®ç¾ç¶ãç¥ããã¨ãã§ããå½éã»ãã¥ãªãã£ã«ã³ãã¡ã¬ã³ã¹ã§ãæ¥æ¬ã§éå¬ãããBlack Hat Japanããã§ã«5度ç®
BHJ2008ã®ãã¬ã¼ã³è³æãé å¸ããã¦ãã¾ãããé·è°·å·æ°ã®è¶£å³ã¨å®çã®æåã³ã¼ãæ»æã¨ãç³å±±æ°ã®âFFR EXCALOCâã³ã³ãã¤ã©ã®ã»ãã¥ãªãã£æ©è½ã«åºã¥ããExploitabilityã®æ°å¤åããªã³ã¯åãï¼URLééãï¼ãªããããã®æç« ã§æ¬å½ã®ãªã³ã¯ãæãã¦ããã¾ããã¡ãªã¿ã«ä»æ¥ä¸¡æ¹ãèªã¿çµãã¾ããã"FFR EXCALOC"ã¯ãã½ããã¦ã§ã¢ã®ãã¤ããªãéç解æãã¦ããã®ã½ããã¦ã§ã¢ã«ã©ã®ç¨åº¦ã®ã»ãã¥ãªãã£å¼·åº¦ãããããæ°å¤åããã¨ãã話ã§ããä¾ãã°ããªã¼ãã¼ããã¼ãªããã®èå¼±æ§å¯¾çã«ã«ããªã¢ï¼Canaryï¼ãªã©ã使ããã¾ããããã®ã«ããªã¢ã使ç¨ããå ´åããã¤ããªã«ç¹å¾´çãªï¼ã¹ã¿ãã¯ã«ã«ããªã¢å¤ãæã¾ãï¼ã³ã¼ããå ¥ããããããããã®ãæ¤åºãã¦ããã®ã½ããã¦ã§ã¢ã¯ãããããã»ãã¥ã¢ã§ããã¨ãã£ããããªãã¨ãæ°å¤åããã¨ãã話ã§ããã»ãã¥ãªãã£å¼·åº¦ãæ°å¤åããã¨ããçºæ³ãé¢ç½ããå人çã«
Black Hat Japanã¨ã¯ 2008å¹´10æ5ï½10æ¥ã®5æ¥éãæ±äº¬ã京çãã©ã¶ããã«ã«ããã¦ãå½éã»ãã¥ãªãã£ã«ã³ãã¡ã¬ã³ã¹ãBlack Hat Japan 2008 Briefings & Trainingããéå¬ããã¾ãããBlack Hatã¯ã1997å¹´ã«ç±³å½ã§å§ã¾ã£ãã»ãã¥ãªãã£å°éã®ã«ã³ãã¡ã¬ã³ã¹ã§ãããä¸çãããã¯ã©ã¹ã®å°é家ã«ãããã¾ãã¾ãªåéã®è¬ç¾©ãåè¬ã§ãããTrainingãã¨ãæå 端ã®ç 究ææãç¥ããã¨ãã§ãããBriefingsãã«ãã£ã¦æ§æããã¦ãã¾ããããæ¥æ¬ã§ããBlack Hat Japanãã¨ããå称ã§ã2004å¹´ããæ¯å¹´éå¬ãããããã«ãªãã¾ããã ãã®ãã¡ã10æ9ï½10æ¥ã®2æ¥éã«ããã¦è¡ãããBriefingsã®è©±é¡ãä¸å¿ã«ãå±ããã¾ãã DNSã®å±æ©ï¼ï½Dan Kaminskyæ°ã®åºèª¿è¬æ¼ãã Briefingsåæ¥ã«ã¯ãIOActiv
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}