2011å¹´4æ21æ¥ï¼æ¨ï¼ãã¼ãã¹ã¿ã¼ãã³ãã¥ãã±ã¼ã·ã§ã³ãºã«ã¦ãã¯ããã¦ã®åå¼·ä¼ãzsstudyããéå¬ãã¾ããã¼ï¼ï¼ 第ï¼åç®ã®ãã¼ãã¯ãDNSãã§ãï¼ï¼ã¨ã ããã£ã¦ã¿ãã®ã§ããåèã«ãªãã°ï¼ï¼ ã¾ãããããã¨æãã¾ãã®ã§ãåãä¸ãã¦ã»ãããã¼ããªã©ã#zsstudyããããã¯ã@risucomorinoãå®ã«ããæ°è»½ã«ãéããã ãã⪠ç¶ããèªã
ãã¬ã³ããã¤ã¯ãã¨è¨ãã°ãã»ãã¥ãªãã£ã½ãããã¦ã£ã«ã¹ãã¹ã¿ã¼ãã 販売ãã¦ããå½å ã®å¤§æã¡ã¼ã«ã¼ã§ããã ãããªãã¬ã³ããã¤ã¯ãããã»ãã¥ãªãã£åéã«ããã¦ç¤¾ä¼è²¢ç®ã ã³ãã¥ããã£æ¯æ´ã«åãå ¥ãã¦åãçµãã§ãããã¨ããåç¥ã ãããã ä»åã¯ããã®æ欲çãªåãçµã¿ã®ä¸ã¤ã§ãããèã®æ ¹åå¼·ä¼æ¯æ´ããã°ã©ã ãããç´¹ä»ãããã çå£ã«ã¨ã³ã¸ãã¢ã®è§£èª¬ãèãå¦çãã¡ ãèã®æ ¹åå¼·ä¼æ¯æ´ããã°ã©ã ãã¯ã ãã»ãã¥ãªãã£ã¬ãã«ã¯ãã¦ã¼ã¶xéç¨xã·ã¹ãã ã®æãç®ã ã©ããä¸ã¤ã§ã0ã«ãªã£ã¦ãã¾ãã°å ¨ä½ã0ã«ãªããã ã¨å±ããå社ãããã®ä¸ã¤ãã¦ã¼ã¶ãã®ã»ãã¥ãªãã£æè²ã«è²¢ç®ãã¹ã 2009å¹´8æã«éå§ããããã°ã©ã ãä¼æ¥ã»å人ï¼ã³ãã¥ããã£ï¼ã§ã® ç³ãè¾¼ã¿ã»åå ãå¯è½ã§ãåå è²»ã¯ä¸åããããªãã åå æ¡ä»¶ã¯ãæ¥æ¬å½å ã§æ´»åãã¦ãã5å以ä¸ã®å£ä½ãã§ãã㤠ãã¤ã³ã¿ã¼ãããã»ãã¥ãªã
ç¶ãã¨ãããããè©«ã³ãæ¸ãã¾ããã æç« ãå¤å°ä¿®æ£ãã¾ãããæè¡çãªç¹ã¯è²ã 誤ããããã¨æãã¾ãã®ã§ããã¾ãä¿¡ç¨ããªãã§ãã ããã詳ããã¯geekpageãããããã«æ¸ãã¦ãã ããã¯ãã§ãã å ¥å£ã«ãã£ããAkamaiãµã¼ãã¼ããªã¢ã«ã¿ã¤ã ã«æãã¦ãããã©ãã£ãã¯ãå¯è¦åããå°çåãæ ã£ãã¢ãã¿ã¼ãã¢ã¡ãªã«ãæ©æãªã®ã§ãã©ãã£ãã¯ã¯850Gbpsã¨å°ãªç®(ç¬) ããã§ãã¢ã¡ãªã«ã®ãã¼ã®é·ãã¯åã ããããããã¨ããæ¹ããBlogã§ã²ã£ããã¨åç¥ãã¦ããã®ããITåå¼·ä¼ã«ã¬ã³ãã¼ã«è¼ã£ã¦ãã¦ããããç®ãã¨ãè¦ã¤ãã¦è¡ã£ã¦ãã次第ãåéæ 5人ã¨ãã ã£ãã®ã§ãç¦ã£ã¦ç³ãè¾¼ãã ããå®éãããªã«åéã¯æ¥ãªãã£ãã¿ããã§æå¤ãåãªãããAkamaiãã£ã¦æ¸ãã¦ãã£ãã ãã§é£ã³ã¤ããã®ã«ãå 輪ã«è¿ãããªã ã£ãã¦ã®ãããã¨æããã©ãæ¡å¤ãAkamaiãã«ã¯è¨´æ±åãç¡ãã®ãããã¾ããã¤ã³ã¿ã¼ãããã®è£ã®æ¯é
IWDD (vol.206) / ã¢ã¤ã¼ã816é¨å± 14:00ãä¼å ´ã¢ã¤ã¼ã 816é¨å±éå¬æ¥2024.04.13 14:00 - 17:00åå 費社ä¼äºº500åå¦çç¡æä»æã®ãé¡åéä¸åå ç³ãè¾¼ã¿https://iwdd.connpass.com/event/284492/
æ å ±ã»ãã¥ãªãã£ããã¼ãã«ããåå¼·ä¼ããæ¥æ¬ã§ãããããéå¬ããã¦ãã¾ãã ãã®åå¼·ä¼ãå¤ãã®äººã«ç¥ã£ã¦ãããããããã ãæ å ±ã»ãã¥ãªãã£åå¼·ä¼ãã¼ã¿ã«ããä½æãã¾ããã åå¼·ä¼ã®ã¢ãã¦ã³ã¹ã®å ´ã¨ãã¦ãæ´»ç¨ãã¦ããã ãããã¨æãã¾ãã æ å ±ã¨ãã¦ãåç°ããã®ãã¼ã¸ããããã ãã¾ããã â 大人ã®äººæè²æãèãã - 極楽ããã ãæ¥è¨
ããµã¼ãã»ãã¥ãªãã£ãã¨ããã¿ã¤ãã«ã§ç¤¾å åå¼·ä¼ãéå¬ãã¾ãããæ®æ®µã®åå¼·ä¼ã§ã¯SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãXSSãªã©Webã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£ã®è©±é¡ãå¤ãããµã¼ãã®ã»ãã¥ãªãã£ã«ã¤ãã¦ã¯äººã«ãã£ã¦ç¥èãã¾ã¡ã¾ã¡ãªã®ã§ãç°¡åã«ã¾ã¨ãã¦ã¿ã¾ãããæ®æ®µãµã¼ããããããªããã¸ã·ã§ã³ã®äººã§ããã»ãã¥ãªãã£ãã£ãã¯ã¹ãå½ã¦ãéã«ã客ããã«èª¬æãããã¨ã¯ããã§ãããããããµã¼ãã¾ããã«ã¤ãã¦ãæ¦è¦ãç¥ã£ã¦ãããæ¹ãè¯ãã¨æãã¾ãã ã¾ã¨ã remote exploitã¯è¦æ³¨æ ã»ãã¥ãªãã£ãã£ãã¯ã¹ãåºããããé©ç¨ãã¹ã å ¬éãµã¼ãã¯å¸¸æãã¹ã¯ã¼ãç·å½ããæ»æãåãã ç°¡åãªãã¹ã¯ã¼ããã¤ããªã å¯è½ãªããã¹ã¯ã¼ããã°ã¤ã³ãç¦æ¢ãã¹ã ããã¤ã®æ¨é¦¬ã¯ç¾å®ã«ããå¾ãè å¨ ãã£ããopen proxyãä½ã£ããããªãããã« ã ã¼ãã¼ çºè¡¨è³æ ã¹ã©ã¤ã(PDF)
åå ãã¦ãã¾ããããªãã ãã²ããã¶ãã«pcapã使ã£ã¦ãªã«ãä½ããããªãã¾ããããã±ããå·¥ä½ã¯ãä»åå©ç¨ããlibpcapã¨libnetããããã°ãå²ã¨ãæ軽ã«å¤§æµã®ãã¨ãã§ããã®ã§ã¯ãªãã§ãããããä¾ãã°ãlibnetã«ã¯ä»¥ä¸ã®ãããªé¢æ°ãç¨æããã¦ãããããæ軽ã«DNSãã±ãããçæãããã¨ãã§ãã¾ããã¾ããlibnet_open_rawsockã®ãããªAPIã使ããã¨ã§RAW Socketå¨ãã®OSæ¯ã®ã·ã¹ãã ã³ã¼ã«ãæ½è±¡åãããã¨ãã§ãã¾ãã int libnet_build_dns(u_short id, u_short flags, u_short num_q, u_short num_anws_rr, u_short num_auth_rr, u_short num_addi_rr, const u_char *payload, int payload_s, u_char *
â¦ããã¾ããããã¾ããããã¾ããããã¡ããã¡ãå°æ¬ãã¦ãã人ãªã®ã§ãããããå岡ããã«ä¸è¨ã ãç³ãä¸ãã¦ãããã§ãããããã¨æ¸ããã¨æã£ãã®ã«ãæ°ãã¤ããããããªã¿ã¤ãã«ã«ãªã£ã¦ãã¾ããã ããã¯ã¨ãããã¦ã¡ã®ãã«ã©: åå¼·ä¼ã®ãã¨ãèªãã§æãã ããããããã¨ã æãã»ãã¥ãªãã£çã§ã¯ id:hideakii ãã主å¬ã«ããPort139åå¼·ä¼ã¨ããåå¼·ä¼ãå®æçã«éããã¦ãã¾ãããå½æãç§ã¯ã»ãã¥ãªãã£ã«å¯¾ããèå³ãç¥èããªãã£ãã®ã§ãããããã§ãMLã«æµãã¦ããæ¡å ãããã«ç¶ãããã¨ããè¦ã¦ããã¨ã¨ã¦ã楽ãããã§ããæ±äº¬ã£ã¦ããããã¤ãã³ãããã£ã¦æ¥½ãããã§ãããªãã¨æã£ãã®ã§ããããã°ãããã¦ãPort139 MLã®çµäºãåãã¦ã id:ripjyr ã京é½ã§åå¼·ä¼ãããã´ã«ã¡ã¨å ãã¦ããã®ã§ãããªãã ããã¾ã£ã¡ãã ããµããã£ã¦ãè¡æ£èããªãã¨æãã¤ã¤ããããã£ããã®é¢è¥¿ã§ã®ã¤ãã³ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}