ã©ããã¯ããã¾ãã¦ã ã·ã£ãã³ã§ç¤¾å ã¤ã³ãã©ãæ å½ãã¦ããma2iã§ãã å ¥ç¤¾ãã¦ããããããåå¹´ã«ãªãã®ã§ãããæéã£ã¦æ¬å½ã«æ©ãã§ããã ä»ååã®ããã°å½çªã¨ããäºã§ãä»å¹´è²·ã£ãè¼¸å ¥ç¤ãã¹ãï¼ã§ãç´¹ä»ããã㨠æã£ãã®ã§ãããæè¡ããã°ãªã®ã§ããã¯ãã¡ã ããã§ãã»ã»ã éåä¼é¡ã ä½ãæ¸ãããè¿·ã£ãã®ã§ãããå æ¥ç¤¾å ã«å°å ¥ãããGitHub Enterpriseãï¼ä»¥ä¸GHEï¼ã« ã¤ãã¦æ¸ãã¦ã¿ããã¨æãã¾ããGitHubã«ã¤ãã¦ã¯æ§ã ãªæ å ±ãããã®ã§ãããGHEã« é¢ãã¦ã¯æ¥æ¬èªã®æ å ±ãã¾ã å°ãªãæ°ããã¾ããä»åã®ä½æ¥ã®çµç·¯ãã¾ã¨ãããã¨ã§ã GHEå°å ¥ãèºèºãã¦ãã管çè ã®æ¹ã ã®åèã«ãªãã°ãããã¨æãã¾ãã â GitHub Enterpriseã¨ã¯ï¼ï¼ä¸å¿èª¬æãã¦ããã¾ãï¼ GitHubãã¯ãã¼ãºããªç°å¢ã§ä½¿ãããã«ãGitHub社ãæä¾ãã¦ããã½ããã¦ã§ã¢ã§ãã æ©è½ãã¤ã³ã¿ã
ã2021/10/15 追è¨ã ãã®è¨äºã¯æ´æ°ãåæ¢ããã¦ãã¾ããç¾å¨ã§ã¯çè ã®ææ³ãå¤åãã¦ããé¢ãããã¾ãã®ã§ï¼éå»ã®è¨äºã¨ãã¦åèç¨åº¦ã«ã覧ãã ããã èå¼±æ§ã«ã¤ã㦠åèãªã³ã¯ PHPã«ããããã¡ã¤ã«ã¢ãããã¼ãã®èå¼±æ§CVE-2011-2202 PHP 5.4.1ãªãªã¼ã¹ã®ãã¤ã³ã ä¸è¨ã«å¯¾ããè£è¶³èª¬æ PHP 5.4.1以é PHP 5.3.11以é ã©ã¡ãããæºããã¦ãããªãã°ï¼èå¼±æ§ã¯ï¼ä»ã®ã¨ããï¼ç¡ãï¼ã©ã¡ããæºããã¦ããªãã¨ï¼ $_FILES å¤æ°ã®æ§é ãå´©ãæ»æ ../ ããã¡ã¤ã«åã«å«ãã¦éä¿¡ããæ»æ (ãã£ã¬ã¯ããªãã©ãã¼ãµã«) ã®ä½ããï¼ãããã¯ä¸¡æ¹ã®èå¼±æ§ãææãã¦ãããã¨ã«ãªãã®ã§è¦æ³¨æï¼ èå¼±æ§å¯¾çã¨æ³¨æäºé $_FILES Corruption 対ç æ¹ç«ããããã©ã¼ã ããã®è¤æ°ãã¡ã¤ã«é åé信対ç èå¼±æ§ãä¿®æ£ãããç°å¢ã§ã æ¹ç«ãã©ã¼ã 対ç ãå ¼ãã¦
ã¯ã©ã¦ãã渡ãæ©ãï¼ããããÃãããã£ãååãã³ãºãªã³åå¼·ä¼ï¼ï¼ 2014å¹´7æ19æ¥(å)éå¬ã®ãDockerãã³ãºãªã³ç¨ã®è³æã§ãã ãã³ãºãªã³ã®æµã ç®ç å®éã« docker ã®ã¤ã³ã¹ãã¼ã«ãããã³ã³ããã®ä½æã»ç®¡çããã¯ã©ã¦ãéã®ç§»è¡ãåºæ¥ãããã«ã å 容 ããã㣠⦠Ubuntu 12.04 ã« Docker ãã»ããã¢ãã ããã ⦠CentOS 6.5 ã« Docker ãã»ããã¢ãã ã³ã³ãããä½æããç¸äºã«ç§»å éçã³ã³ãã³ãç·¨ ( Apache + HTML ãã¡ã¤ã« ) åçã³ã³ãã³ãç·¨ ( Apache + PHP + PukiWiki ) 1. Docker ã®ã»ããã¢ãã(Ubuntu/ãããã£ã¯ã©ã¦ãç·¨) 1.1. ãããã£ã¯ã©ã¦ãã«ãã°ã¤ã³ 対象ãµã¼ãã« SSH ã§ãã°ã¤ã³ãã¾ããLinux kernel ã®ãã¼ã¸ã§ã³ãå¤ãçºããã¼ã¸ã§ã³ã¢ããããã¾ã
ã¢ãã¤ã«ããã¤ã¹ã®æªç¥ã®èå¼±æ§ãè¦ã¤ããããã¤ã¹ã¨è³éãã²ããããã³ã³ãã¹ããPacSec2013ã§è¡ããããæ¥æ¬ã§åãã¦éå¬ãããMobile Pwn2Ownã®ææã¯ã製é å ã«ããã£ã¼ãããã¯ãããã æ±äº¬ã»éå±±ãã¤ã¤ã¢ã³ããã¼ã«ã§2013å¹´11æ13ï½14æ¥ã«éå¬ããã¦ããæ å ±ã»ãã¥ãªãã£ã«ã³ãã¡ã¬ã³ã¹ãPacSec2013ãã«ã¦ãæ¥æ¬ã§åãã¦ã®ã¢ãã¤ã«ããã¤ã¹èå¼±æ§çºè¦ã³ã³ãã¹ããMobile Pwn2Ownããè¡ããããMobile Pwn2Ownã¯ã主ã«ç±³ãã¥ã¼ã¬ããã»ããã«ã¼ãï¼HPï¼ã®èå¼±æ§ãªãµã¼ãé¨éã§ããZero Day Initiativeï¼ZDIï¼ãéå¶ããç±³ã°ã¼ã°ã«ã¨ç±³ãã©ãã¯ããªã¼ãè³éæä¾ã§åè³ãã¦ããã³ã³ãã¹ãã ã Pwn2Ownã¨ã¯ãããã¤ã¹ãä¹ã£åãï¼Pwnï¼ãã¨ãã§ãããã®ãããã®ããã¤ã¹ã¨è³éãããããï¼Ownï¼ã¨ããæ¹å¼ã®ãã»ãã¥ãªãã£æè¡ã競ãã³ã³
Android OS ã«ã¯ãä»»æã® Java ã®ã¡ã½ãããå®è¡ãããèå¼±æ§ãåå¨ãã¾ãã ãã®èå¼±æ§æ å ±ã¯ãæ å ±ã»ãã¥ãªãã£æ©æè¦æãã¼ããã¼ã·ããã«åºã¥ãä¸è¨ã®æ¹ã IPA ã«å ±åããJPCERT/CC ãéçºè ã¨ã®èª¿æ´ãè¡ãã¾ããã å ±åè : æ±å£ ç ç¾ æ°
調æ»ãè¡ãéç¨ã§ã稼åä¸ã¨æãããæ¢èª¿TOOLãçºè¦ããããã®URLãè¦ã¦åããéããã.actionãã¨ããæ¡å¼µåãç¨ãããã¦ãããããã¯æ £ç¿çã«ãApache Strutsããç¨ããã¢ããªã±ã¼ã·ã§ã³ã§æå®ãããæ¡å¼µåã§ãããããã«ãã½ã¼ã¹ã³ã¼ãã確èªããã¨ãstrutsãã¨ããæååããã¹æå®ã§ããã¤ãè¨è¼ããã¦ããã ããã¯æå®ã§ã¯ãªãã®ã ãâ¦â¦ã Apache HTTP Serverã¯10å¹´ã»ã©å¤é¨ããæ¹ãããè¡ãããããªèå¼±æ§ãããã³æ»æã³ã¼ãããªãªã¼ã¹ããã¦ããªã åå ã¨ãªã£ãæ¢èª¿ãã¼ã«ã§ã¯ã.actionãæ¡å¼µåã使ç¨ããã¦ãããã¼ã¸ããã ãã®ã½ã¼ã¹ã³ã¼ãã«ã¯strutsã®æååããã¹æå®ã§è¨è¼ããã¦ãã ã¨ããçç±ãããæ¢èª¿TOOLã§ã¯èå¼±æ§ã®å½±é¿ãåãããã¼ã¸ã§ã³ã®Apache Strutsãå©ç¨ããã¦ããããã®èå¼±æ§ãçªããã¦ãä»åã®äºä»¶ã«è³ã£ãã®ã§ã¯ãªãã ãããã¨è
ã¼ã£ãã¼ã superflipã¯1403ç¹ã24ä½ã ã£ãã ç·´ç¿åé¡ ç·´ç¿åé¡ 100ç¹ FLAG{seccon2014} ãã®ãã±ããã解æãã ãããã¯ã¼ã¯ 100ç¹ FTPéä¿¡ãFTPã¯å¶å¾¡ã¨ãã¡ã¤ã«è»¢éã¯å¥ã®ãã¼ãã§è¡ãã55çªç®ã®ãã±ããã«ã RkxBR3tGN1AgMTUgTjA3IDUzQ1VSM30=ã¨ãããã¡ã¤ã«ããããBase64ãã³ã¼ãããã¨ã FLAG{F7P 15 N07 53CUR3} ã½ã¼ã·ã£ã«ãã㯠ãããã¯ã¼ã¯ 300ç¹ ä»æµè¡ã®LINEä¹ã£åãããã¡ãã®ç¨æãããµã¤ãã«ã¢ã¯ã»ã¹ãããã¨ã MyVNCpasswordIsVNCpass123ã¨ãããªãã¡ã©ãä»ãã¦ããã®ã§ãæ¥ç¶å ã«VNCã§æ¥ç¶ããã°è¯ãã FLAG{giveMeYourWebM0n3y} decode me æå· 100ç¹ EUCã®ä¸å½èªãã¡ã¤ã«ãROT13ã«ããã¨è±èªé¨åã SECCON 2
ãã¼ã«å¸å ´ã®ç¸®å°ã«æ¯æ¢ããããããã¨ã大æãã¼ã«ã¡ã¼ã«ã¼å社ã¯ãã¤ã³ã¿ã¼ãããã®äº¤æµãµã¤ãã使ã£ã¦éããè¥è ã®æè¦ãããã«åæ ããæ°ååãçºå£²ãããªã©ãè¥è ã女æ§ã®éè¦ãæãèµ·ãããã¨ããåãçµã¿ãåºãã£ã¦ãã¾ãã ãã¼ã«ãçºæ³¡é ãªã©ãããã¼ã«ç³»é£²æãã®åºè·éã¯å»å¹´ã¾ã§ï¼å¹´é£ç¶ã§éå»æä½ã¨ãªã£ã¦ãã¦ããã®è¦å ã¨ãã¦è¥è ã女æ§ãä¸å¿ã¨ãããã¼ã«é¢ããææããã¦ãã¾ãããã®ããå社ã¯éè¦ã®æãèµ·ããã«åãå ¥ãã¦ãã¾ãã ãã®ãã¡ãããªã³ãã¼ã«ãã¯ãæ¥å¹´ã®æ¥ãæ±äº¬ã»æ¸è°·ã«å°è¦æ¨¡ã®é¸é æãæ°ãã«è¨ãããã¼ã«ã®çç£ãå§ãã¾ãã ããã§ã®ååéçºã«ããã£ã¦ã¯ãè¥è ã®å©ç¨ãå¤ãã¤ã³ã¿ã¼ãããã®äº¤æµãµã¤ãã§ã©ããªå³ãé¦ãã®ãã¼ã«ã飲ã¿ããããå°ãããã®å£°ãããã«ååã«åæ ããããã¨ã«ãã¦ãã¾ãã ã¾ããããµããããã¼ã«ãã¯ã¤ã³ã¿ã¼ãããã§éããæ¶è²»è ã®æè¦ãåºã«éçºãããã¼ã«ããããéå®ã§è²©å£²ãã¦ãã¾ãã
ã¡ã³ããã³ã¹
ãç¥ãã
é害
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}