ãã¯ã¦ãªããã°ãã®èªè ãªã¹ãããããã°ã«ã¢ã¯ã»ã¹ãã¦ã¿ã㨠https://******.hatenablog.com/ ã¯éå ¬éã«è¨å®ããã¦ãã¾ãã ã¨è¡¨ç¤ºããããã¨ãããã¾ãããã®å ´åã¯ããã°ã¯åå¨ãã¾ããéå ¬éã«è¨å®ããã¦ãããã¨ãæå³ãã¦ãããããã°ã«ã¢ã¯ã»ã¹ãããã¨ã¯ã§ãã¾ããã ã¾ãæ¬å½ã«ããã°ãæ¶ããã¦ãã¦ã¢ã¯ã»ã¹åºæ¥ãªãå ´åãããã¾ãã ãããã®å ´åããããã®ããã°ã®èªè ãè¾ãããã¦ããæ®éã«ã¯ããã°ã«ã¢ã¯ã»ã¹ã§ããªãã®ã§è¾ãããã¨ãã§ãã¾ããã ãããã次ã®æ¹æ³ã«ãããèªè ãè¾ãããã¨ãã§ãã¾ãã éå ¬éããã°ã®èªè ãè¾ãã 該å½ã®ããã°ã«ã¢ã¯ã»ã¹ãã㨠"https://xxxxxx.hatenablog.com/ "ã¯éå ¬éã«è¨å®ããã¦ãã¾ãã ã¨è¡¨ç¤ºããã¾ãã "xxxxxx"é¨åã¯ç¸æã¦ã¼ã¶ã¼IDã§ã"xxxxxx.hatenablog.com"é¨åãç¸æãã¹ã«ãª
ããã¸ã§ã¯ãããã¸ã¡ã³ãã®ã¢ã³ããã¿ã¼ã³ï¼Project Management Antipatternï¼ãã¾ã¨ããï¼ åºæ¬çã«ä¸è¨ã®æ¬ãé¦è¨³ããå 容ã«ãªã£ã¦ããï¼ https://www.amazon.com/AntiPatterns-Refactoring-Software-Architectures-Projects/dp/0471197130 ããã¸ã§ã¯ãããã¸ã¡ã³ãã®ã¢ã³ããã¿ã¼ã³ã£ã¦ä½ï¼ ããã¸ã§ã¯ãããã¸ã¡ã³ãã®ã¢ã³ããã¿ã¼ã³ã¯éµã¨ãªãã·ããªãªé ã»ã£ã¦ããã¨ç ´å£çãªå½±é¿ãåã¼ã ç¾ä»£ã®ã½ããã¨ã³ã¸ãã¢ã®ä»äºã¯ï¼å¤§åã人ãç¸æã«ããã㨠ã³ãã¥ãã±ã¼ã·ã§ã³ 人ééã®åé¡è§£æ±º æè¡ç³»ããã¼ã¸ã£ã¼ã®å½¹å²ã®å¤å ãã¨ã㨠ã«ã¼ã«ã«å¯¾ããä¾å¤ã¸ã®æ¿èª ãã®æç¶ã ç¾ä»£ ããã¼ã¸ã£ã¼ã®å¹²æ¸åããã«ï¼åé¡è§£æ±ºã§ãã ããã以ä¸ã®ã¨ãªã¢ã§ã¯å½¹å²ãåç¶ãã¦ãã ã½ããããã»ã¹ç®¡ç ãªã½ã¼ã¹ç®¡ç
ã½ããã¦ã§ã¢éçºã«ããã¦ãæªãçµæã«é¥ãããããé¿ããã¹ãå ¸åä¾ããæãããã¢ã³ããã¿ã¼ã³ãã ããã¸ã§ã¯ãããã¸ã¡ã³ãã®ä¸çã«ãåå¨ããã¢ã³ããã¿ã¼ã³ã¯ãããã¸ã§ã¯ãã®é 延ãææç©ã®å質ä½ä¸ãæãåå ã¨ãªãã¾ããä»åã®ã»ããã¼ã§ã¯ãããã¸ã§ã¯ãããã¸ã¡ã³ãã®ç¾å ´ã§ããè¦ããããããã¸ã§ã¯ãããã¸ã¡ã³ãã®ã¢ã³ããã¿ã¼ã³ãã¨ããã®åé¿æ¹æ³ãç´¹ä»ãã¾ãããå ¨4åã1åç®ã¯ãã¢ã³ããã¿ã¼ã³ãã®1ãå§ç¸®ã¹ã±ã¸ã¥ã¼ã«ãã«ã¤ãã¦ã ãããã¨æã£ã¦ãã£ã¦ãããã¨ã«è¦ããããã¦ããã±ã¼ã¹ããã 西é·æºå²æ°ï¼ã¿ãªããã¯ããã¾ãã¦ãæ ªå¼ä¼ç¤¾ãã¼ã¤ã³ã°ã³ã³ãµã«ãã£ã³ã°ã§ã³ã³ãµã«ã¿ã³ãããã¦ãã西é·ã¨ç³ãã¾ãããããããé¡ããã¾ãã æ¬ç·¨ãå§ããåã«ãã¾ãå¼ç¤¾ã®ç´¹ä»ããã¾ããå¼ç¤¾ã¯ãã¼ã¤ã³ã°ã³ã³ãµã«ãã£ã³ã°ã¨ããã¾ãã¦ãäºæ¥å 容ã¯ãå¶ç´æ¡ä»¶ã®çè«ã«åºã¥ããçç£æ§åä¸ã®ã³ã³ãµã«ãã£ã³ã°ãµã¼ãã¹ã®æä¾ã§ããå¶ç´æ¡ä»¶ã®
ç®æ¨è¨å®ããããããããæ£ç´å«ãã¨ãæå³ãããããã¨è¨ã人ãå¤ãã¨æããèªåã¯é©åãªç®æ¨è¨å®ã¯å¿ è¦ãªãã®ã ã¨ããè ¹è½ã¡ã¯ãã¦ããã ãã©ããªãããããããã¨ãã¯ãã¾ã説æã§ããªãã£ãã ãããªæã« EM.FM Re8. æ¬å½ã«æå³ã®ããç®æ¨è¨å® ã§MBOã®æ´å²ããè²ã ã¨è©±ãã¦ãã¦ãããã ãªã¼é¢ç½ããªã¼ã¨æã£ãã®ã§ãèªåãããããç®æ¨ç®¡çã¨ã¯ä½ãªã®ãï¾ï½®ï½¯ï¾èª¿ã¹ã¦ã¿ããã¨ã«ããã å¦è¡çã«ãã¡ãã¨å¦ã¹ãããã§ã¯ãªãã®ã§å°ããããé¨åãããããã©ãããããã®ã¯èª°ãã®ããã«ãªããããããªããæ¸ãã¦ã¿ããããééããè£è¶³ãããã°æãã¦ããããã¨å¬ããã ç®æ¨ç®¡çã®èµ·æº ç®æ¨ç®¡çã®èµ·æºã¯æ¬§ç±³ã®ç 究è ã®ä¸ã§ã¯ããè«ãããã¦ãããã¼ãããã 諸説ããããã¢ãªã¹ããã¬ã¹ã ãæåããã«ã¯ç®çæèãæã¦ã ã¨è¨ã£ãã®ãæåã¨ãã説ããã ãã®èµ·æºã¨ã¯é¢ä¿ãªãããGoogleã§ã¯ãå¹æçãªãã¼ã ãå¯è½ã¨ããæ¡ä»¶
1. å§ãã« ããã«ã¡ã¯ãmorioka12 ã§ãã æ¬ç¨¿ã§ã¯ãAWS ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã«ç¦ç¹ãå½ã¦ããã£ãã·ã³ã°ã«ãã MFA (Multi-Factor Authentication) èªè¨¼ã®åé¿ãäºä¾ãã»ãã¥ãªãã£å¯¾çã«ã¤ãã¦ç´¹ä»ãã¾ãã 1. å§ãã« å 責äºé æ³å®èªè 2. AWS ããã¸ã¡ã³ãã³ã³ã½ã¼ã« MFA (Multi-Factor Authentication) 3. ãã£ãã·ã³ã° (Phishing) MITRE ATT&CK 4. ãã£ãã·ã³ã°ã«ãã AWS ãã°ã¤ã³ã®ä»®æ³ MFA ããã¤ã¹èªè¨¼ã®åé¿ 5. ãã£ãã·ã³ã°ã«ãã AWS ãã°ã¤ã³ã® SSO èªè¨¼ã®åé¿ 6. AWS ãã°ã¤ã³ãã¿ã¼ã²ããã«ãããã£ãã·ã³ã°ã®äºä¾ äºä¾1 (Google æ¤ç´¢) äºä¾2 (ã¡ã¼ã«) äºä¾3 (ã¡ã¼ã«) 7. ãã®ä» Web ã¢ããªã±ã¼ã·ã§ã³ã«ããã MFA èªè¨¼ã®å
1. å§ãã« ããã«ã¡ã¯ãmorioka12 ã§ãã æ¬ç¨¿ã§ã¯ããã°ãã³ãã®å ¥éã¨ãã¦ã主㫠Web ã¢ããªã±ã¼ã·ã§ã³ã® OSS ã«ç¦ç¹ããããèå¼±æ§ã®çºè¦ã»å ±åã»CVE ID ã®åå¾ã«ã¤ãã¦ç´¹ä»ãã¾ãã 1. å§ãã« å 責äºé æ³å®èªè çè ã®ããã¯ã°ã©ã¦ã³ã 2. CVE ã¨ã¯ 3. æ¢ã対象ã®é¸ã³æ¹ OSS Topic (Type) ç¹å®ã®æ¡ä»¶ã§çµã ãã°ãã¦ã³ãã£ã® OSS 4. èå¼±æ§ã®æ¤è¨¼æ¹æ³ ã¢ããã¼ãæ¹æ³ 5. èå¼±æ§ã®å ±åå 6. å ±åæ¸ã®æ¸ãæ¹ CVSS CWE 7. èå¼±æ§çºè¦ãã CVE ID ã®åå¾ã¾ã§ã®æµã 注æç¹ 8. ãã°ãã³ãåã®ã¹ãã«æºå éå»ã® CVE ID ãã¬ãã¼ã Web Security ã®å ´å 9. ãã®ä» ãã®å¾ã®ãã£ã¬ã³ã¸ ãã°ãã¦ã³ãã£å ¥é ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ãç®æã就活çã®æ¹ã¸ OSS ã®éçºè ã®æ¹ã¸ 10. çµããã« å 責äºé
1. å§ãã« ããã«ã¡ã¯ãmorioka12 ã§ãã æ¬ç¨¿ã§ã¯ããã°ãã¦ã³ãã£ã®å ¥éã¨ãã¦ã主㫠Web ã¢ããªã±ã¼ã·ã§ã³ã対象ã«ããèå¼±æ§ã®çºè¦ã»å ±åã»å ±é ¬éã®åå¾ã«ã¤ãã¦ç´¹ä»ãã¾ãã 1. å§ãã« å 責äºé æ³å®èªè çè ã®ããã¯ã°ã©ã¦ã³ã Start Bug Bounty Bug Bounty JP Podcast [Blog] Intigriti Q1 2024 ã®æ績 ã¤ã³ã¿ãã¥ã¼è¨äº 2. ãã°ãã¦ã³ãã£ã¨ã¯ ãã°ãã¦ã³ãã£ãã©ãããã©ã¼ã Program Type Private Programs VDP (Vulnerability Disclosure Program) Asset Type 3. ããã°ã©ã ã®é¸ã³æ¹ Scope OoS (Out of Scope) 4. èå¼±æ§ã®æ¢ãæ¹ (åæ調æ»ç·¨) Subdomain Google Dorks Wayback Mac
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}