ã¯ããã« ãã®è¨äºã¯ãNFLaboratories Advent Calendar 2024 ã® 5 æ¥ç®ã®è¨äºã§ãã ããã«ã¡ã¯ãNFLabs. CTO ã®æ¾æ¨ã§ãã ãã®è¨äºã§ã¯ãNFLabs. ãåè³ãã¦ãããç§ã社å¡ãéå¶ã«æºãã£ã¦ãã MWSï¼ãã«ã¦ã§ã¢ã¨ãµã¤ãã¼æ»æ対çç 究人æè²æã¯ã¼ã¯ã·ã§â¦
ã¯ããã« ãã®è¨äºã¯ãNFLaboratories Advent Calendar 2024 12/11 ã®è¨äºã§ãã https://adventar.org/calendars/10492 ããã«ã¡ã¯ãç 究éçºé¨ã®å ºã§ãã ä»åã¯ç§ãå人çã«åãçµãã§ããC++ã§ã¤ã³ã¿ããªã¿è¨èªãä½ã£ã¦ãã話ãæ¸ãã¦ãããã¨æãã¾ããâ¦
æ¦è¦ æ¬è¨äºã§ã¯ãQEMUã¨libvirtã使ã£ã¦ä»®æ³ãã·ã³ãCLIã§å¶å¾¡ããæ¹æ³ã解説ãã¾ããç¹ã«ä»¥ä¸ã®ãã¤ã³ãã«ç¦ç¹ãå½ã¦ã¦ãã¾ãã ã¹ãããã·ã§ããã®ä½æã»ãªãã¼ãæ¹æ³ å·®åãã£ã¹ã¯ã使ã£ãå¹ççãªç°å¢æ§ç¯ æ¦è¦ ã¯ããã« KVMã¨QEMU libvirtã使ã£ãåºæ¬â¦
ãã®è¨äºã¯ãNFLaboratories Advent Calendar 2024*1 2 æ¥ç®ã®è¨äºã§ãã ã¿ãªããããã«ã¡ã¯ãç 究éçºé¨ ç 究éçºæ å½ã®onaotoã§ãã ä»åã®è¨äºã§ã¯AWS Lambdaï¼ä»¥éLambdaï¼ã§Ansibleãå®è¡ã§ããããã«ããæ¹æ³ã«ã¤ãã¦ç´¹ä»ãããã¨æãã¾ãã çµè«ããâ¦
æ¦è¦ SECCON CTF 13 äºé¸ã§ Team Enu ã¯ãã°ãã¼ãã« 653 ãã¼ã ä¸ 36 ä½ãå½å 303 ãã¼ã ä¸ 9 ä½ã®æ績ãåãã¾ããã決åã¸é²åºãã¾ãï¼ æ¬è¨äºã§ã¯ãreversing ã¸ã£ã³ã«ã® F is for Flag åé¡ã解説ãã¾ãã ã¯ããã« ãã®è¨äºã¯ãNFLaboratories Adventâ¦
ç 究éçºé¨ ç 究éçºæ å½ã®å º ã§ãã GOAD ã¨ãã Active Directory (ä»¥ä¸ AD )ã§æ§æããããã³ãã¹ãç°å¢ãæ»ç¥ããã®ã§ããã®ç´¹ä»ã¨ walkthrough ãæ¸ãã¾ãã GOAD ã¨ã¯ GOAD ãæ§ç¯ãã GOAD ã®æ»ç¥ Recon Responder WINTERFELLã®æ»ç¥(ã¦ã¼ã¶æ¨©é) CASTâ¦
FFRI Security x NFLabs. Cybersecurity Challenge for Students 2024 ããã«ã¡ã¯ãç 究éçºé¨ã®æ«å»£ã§ããæ®æ®µã¯ã»ãã¥ãªãã£ãã¬ã¼ãã³ã°ãã©ãããã©ã¼ã ç¨ã®åé¡ä½æçãè¡ã£ã¦ãã¾ãã æ¬è¨äºã§ã¯ã9æã«ï¼¦ï¼¦ï¼²ï¼©ã»ãã¥ãªãã£ã¨NFLabs.ãååã§éå¬ããâ¦
ã¯ããã« ã¿ãªãããããã«ã¡ã¯ãæè²ã½ãªã¥ã¼ã·ã§ã³æ å½ã®æ¨ç°ãæè¤ã岡ç°ã§ãã 2024å¹´8æ8æ¥ã«é·å´å¤§å¦æ å ±ãã¼ã¿ç§å¦é¨ã®å°æç 究室ã»èäºç 究室æå±ã®å¦çã«åãã¦ããã¼ããã³ã°æ¼ç¿ãã®è¬ç¾©ãè¡ãã¾ããã æ¬è¨äºã§ã¯ããã®æ§åãå ·ä½çãªå®æ½å 容ãâ¦
ã¯ããã« ã¿ãªãããããã«ã¡ã¯ãæè²ã½ãªã¥ã¼ã·ã§ã³æ å½ã®æ¾è¤ã§ããæ©éã§ãããç§ã¯èªåã®ãã¼ã ãåãã¨ãã¦ä¼ç¤¾å ¨ä½ã®çµç¹åãæ大éã«çºæ®ãããæ¹æ³ãæ¥ã å¦ã³ãå®è·µçã«å°å ¥ããªããçµç¹æé·ã®å®ç¾ãç®æãã¦ãã¾ãã ãã®ä¸ã§ç§ã¯ä¸äººã²ã¨ããç©æ¥µâ¦
ç 究éçºé¨ ç 究éçºæ å½ã®ä¿è¦ (@takahoyo) ã§ãã ã¨ãã»ã¨ãã»ã©ãã©ããªã¼ãºã§ã¯ã2023年度ã«å¼ãç¶ããç¾å ´åãå ¥ãåã¤ã³ã¿ã¼ã³ã·ããããå®æ½ãã¾ããã 2023年度ã®æ¨¡æ§ blog.nflabs.jp blog.nflabs.jp 2024年度ã®ä»ãã¼ã ã§ã®ã¤ã³ã¿ã¼ã³ã·ããã®æ¨¡æ§â¦
ç 究éçºé¨ ã·ã¹ãã &ã»ãã¥ãªãã£æ å½ã®æ¾åã§ãã ã¨ãã»ã¨ãã»ã©ãã©ããªã¼ãºã§ã¯ã2023年度ã«å¼ãç¶ããç¾å ´åãå ¥ãåã¤ã³ã¿ã¼ã³ã·ããããå®æ½ãã¾ããã 2023年度ã®æ¨¡æ§ blog.nflabs.jp blog.nflabs.jp ã·ã¹ãã &ã»ãã¥ãªãã£æ å½ã§ã¯2åã®ã¤ã³ã¿ã¼ã³â¦
TL;DR å¼ç¤¾ç¤¾å¡ã«ãã BSides Las Vegas 2024 ã®ç»å£ã¨ DEF CON 32 ä½é¨è¨(è´è¬è è¦ç¹)ã§ãã æ¬ç¨¿ã¯ãDEF CON 32 è´è¬è è¦ç¹ã§ã®ä½é¨è¨ã§ããæµ·å¤ã«ã³ãã¡ã¬ã³ã¹ç»å£èæ¯ãçºè¡¨å 容ã«ã¤ãã¾ãã¦ã¯ãDEF CON ã«è¡ããããã¦ãBSides Las Vegas ã§ãã¬ã¼ã³ãâ¦
ã¯ããã« æè²ã½ãªã¥ã¼ã·ã§ã³æ å½ã®æ´ï¨ã»æ²æ¬ã§ããæ®æ®µã¯ã»ãã¥ãªãã£æè²ç ä¿®è¬å¸«æ¥åã«å¾äºãã¦ãããè¬å¸«ã¨ãã¦ãµã¤ãã¼ã»ãã¥ãªãã£äººææè²ç ä¿®ãæä¾ãã¦ãã¾ãã å¼ç¤¾ãæä¾ããç ä¿®ã®ä¸ã«ã¯ããWebã¢ããªã±ã¼ã·ã§ã³éçºæ¼ç¿ãã¨ãããã²ã¨ãã²ã¨ãâ¦
NFLabs. ã§åãã¦ã®æµ·å¤ç»å£ã決ã¾ããBSides Las Vegas ãã¬ã¼ã³ã¿ã¼ã¨ã㦠@strinsert1Na ãåå ãã¦ãã¾ããã æ¬ç¨¿ã¯ãã¬ã¼ã³ã¿ã¼(çºè¡¨è )è¦ç¹ã§ã® Las Vegas ä½é¨è¨ã§ãã
ç 究éçºé¨ã®ä¿è¦ (@takahoyo) ã§ãã ä»åã¯å¼ãã¼ã ã®ã³ã³ãã³ãéçºã®ã¤ã³ã¿ã¼ã³ã·ããã«åå ãã¦ããä¼æ±ããã¤ã³ã¿ã¼ã³ã·ãããéãã¦å¦ãã ãã¨ãå ±æãã¾ãã ã¯ããã« ããã«ã¡ã¯ãæ ªå¼ä¼ç¤¾ã¨ãã»ã¨ãã»ã©ãã©ããªã¼ãºï¼ä»¥ä¸NFLabs.ï¼å¦çã¤ã³ã¿ã¼ã³â¦
æè²ã½ãªã¥ã¼ã·ã§ã³æ å½ã®çå±±ã§ãã æ¨å¹´ã«å¼ãç¶ããä»å¹´ã7æ20æ¥ï¼åï¼ã«é·ä¸çºã®ããã°ã©ãã³ã°æ室ã§å°å¦çã®è¦ªåã«åãã¦ã»ãã¥ãªãã£ã®è¬ç¾©ãè¡ã£ã¦ãã¾ãããããã°ã©ãã³ã°æ室ã®æ§æã¯æ¨å¹´åº¦ã¨åæ§ã§2æéÃ3åï¼3é±ã«æ¸¡ã£ã¦å®æ½ï¼ã親å8çµã対象â¦
ã¯ããã« çæ§ãç²ãæ§ã§ããæè²ã½ãªã¥ã¼ã·ã§ã³æ å½ã®ä¸å±±ã§ãã Burp Suite Certified Practitionerï¼BSCPï¼ã«åæ ¼ã§ããã®ã§ããã®è³æ ¼ã®èª¬æãåæ ¼ã¾ã§ã®éã®ãã«ã¤ãã¦ç´¹ä»ãããã¨æãã¾ãã ç®æ¬¡ ã¯ããã« ç®æ¬¡ Burp Suite Certified Practitioner ï¼â¦
ç 究éçºé¨ã®ä¿è¦ (@takahoyo) ã§ãã ä»åã¯å¼ãã¼ã ã®ã³ã³ãã³ãéçºã®ã¤ã³ã¿ã¼ã³ã·ããã«åå ãã¦ãã濱éããã¤ã³ã¿ã¼ã³ã·ãããéãã¦å¦ãã ãã¨ãå ±æãã¾ãã ã¯ããã« ããã«ã¡ã¯ãæ ªå¼ä¼ç¤¾ã¨ãã»ã¨ãã»ã©ãã©ããªã¼ãº å¦çã¤ã³ã¿ã¼ã³ã®æ¿±éã§ãã â¦
ç 究éçºé¨ ã·ã¹ãã &ã»ãã¥ãªãã£æ å½ã®æ¾åã§ããä¸éã® DMARC 対å¿ãå éãããã¨ãã£ã¦ãéè¨ã§ã¯ãªã Gmail ã«ãããã¡ã¼ã«éä¿¡è ã®ã¬ã¤ãã©ã¤ã³ãé©ç¨éå§ããã¦ãã 3 ã¶æè¿ããçµã¡ãNFLabs. ã«å±ãã¡ã¼ã«ã§ã DMARC ããªã·ã¼ãè¨å®ããã¦ãããã¡â¦
æ¦è¦ DEF CON CTF Qualifier 2024ã§ãTeam Enuã¯22ä½ã®æ績ãåãã¾ããã æ¬è¨äºã§ã¯ãLiveCTFã®durnkã¨trickshotã®2åã解説ãã¾ãã ã¯ããã« ããã«ã¡ã¯ãç 究éçºé¨ã®æ«å»£ã§ããCTFã¤ãã³ãDEF CON CTF Qualifier 20241ã«ãNTTã°ã«ã¼ãæå¿ã¨ãåé2ã«â¦
ã¯ããã« ããã«ã¡ã¯ãæè²ã½ãªã¥ã¼ã·ã§ã³æ å½ã®å浦ã§ãã 2024å¹´3æã«OffSec社ã®OSCPãåå¾ããã®ã§ãåæ ¼ã¾ã§ã®è¨é²ãæ¸ãããã¨æãã¾ãã ç®æ¬¡ ã¯ããã« ç®æ¬¡ OSCPã¨ã¯ï¼ OSCPè©¦é¨ è©¦é¨ã¹ã±ã¸ã¥ã¼ã« åæ ¼åºæºã¨ãã¼ãã¹ãã¤ã³ã å¦ç¿ã«ã¤ã㦠åå¾ã®ãâ¦
ã¯ããã« å½ãã¼ã ã§ã®ã¤ã³ã¿ã¼ã³ ã¤ã³ã¿ã¼ã³çã®å£°ï¼ã¢ã³ã±ã¼ãããï¼ ãã®ã¤ã³ã¿ã¼ã³ãå¨å²ã«å§ããå¯è½æ§ã¯ã©ã®ç¨åº¦ããã¾ãã?ãã®çç±ã¯ï¼ ãã¸ãã£ããªæè¦ ãã¬ãã£ããªæè¦ ã¡ã³ãã¼ããã®ãµãã¼ããæå°ã¯ã¹ãã«åä¸ãããã¸ã§ã¯ãã¸ã®ç解ãæ·±ããâ¦
ã¯ããã« ã¿ãªãããããã«ã¡ã¯ãæè²ã½ãªã¥ã¼ã·ã§ã³æ å½ã®äºå²¡ã§ããæ±äº¬ã§éå¬ãããSecurity Days Spring 2024ã®Day3ã«åå ãã¦ãã¾ãããåå¾ããï¼æéã»ã©ã®åå ã§ããããé常ã«åå¼·ã«ãªã£ã楽ããã¤ãã³ãã ã£ãã®ã§ãã話ããããã¨æãã¾ããf2ff.â¦
ã¯ããã« ã¿ãªãã¾ããã«ã¡ã¯ãNFLabs. ã® @strinsert1Na ã¨é»å·ã§ãããã®åº¦ãæ ªå¼ä¼ç¤¾ã¨ãã»ã¨ãã»ã©ãã©ããªã¼ãºã¯ 2023年度 UEC Bug Bounty ã«åè³ããé»é大(UEC) ã®OBã§ããçè ãã¨CTOã®3åã表彰å¼ã«åå ãã¦ãã¾ãããå½ç¤¾ã¯ãé»æ°é信大å¦ã«ããã¦â¦
TL;DR 2024/03/09 ~ 03/14 ã«ããã¦è¡ããã Cyber Apocalypse 2024: Hacker Royale ã® Writeup è¨äºã§ã QuickScan, MazeOfPower ã® Rev. å2ã¤ããã¾ã ctf.hackthebox.com ã¯ããã« çãã¾ããã«ã¡ã¯ @strinsert1Na ã¨ãã人ã§ããHack The Box ã主å¬ãâ¦
æ¬è¨äºã§ã¯ãå æ¥NFLabs.ãéå¬ãããã»ãã¥ãªãã£æè¡ã競ãã»ãã¥ãªãã£ãã£ã¬ã³ã¸ã³ã³ãã¹ããNFLabs. Cybersecurity Challenge for Students 2023ãã®æ§åãç´¹ä»ãã¾ãã ã¾ãã競æå¾ã«åéããWriteupè³ã®çºè¡¨ãè¡ãã¾ãã
ãã®è¨äºã¯ NFLaboratories Advent Calendar 2023 14 æ¥ç®ã®è¨äºã§ãã ã¯ããã« åé¡ç´¹ä» è§£æ³ pcapãã¡ã¤ã«ã®è§£æ 80/tcp 443/tcp 21/tcp, 37039/tcp, 59847/tcp Windows ã¤ãã³ããã°ã®è§£æ PowerShellã®ã³ã¼ãã®è§£æ ã¤ãã³ããã°ããè¦ã¤ãã£ãã³ã¼ã lâ¦
ã¯ããã« ãã®è¨äºã¯ãNFLaboratories Advent Calendar 2023 - Adventar 13æ¥ç®ã®è¨äºã§ããããã«ã¡ã¯ãNFLabs. CTO/ãããã¯ãããã¼ã¸ã£ã¼ã®æ¾æ¨ã§ãããã®è¨äºã§ã¯ãå½ç¤¾ãéçºä¸ã®ã»ãã¥ãªãã£æè¡ãã¬ã¼ãã³ã°ãã©ãããã©ã¼ã ã«ã¤ãã¦ç´¹ä»ãã¾ãã ã¯â¦
2023/11/22 ~ 11/27 ã®5æ¥éã«ããã¦è¡ãããå¦çéå®ã®CTFã©ã¤ã¯ãªã»ãã¥ãªãã£ã¤ãã³ããNFLabs. Cybersecurity Challenge for Students 2023ãã®ä½åè Writeupã§ãããã£ã¬ã³ã¸ã«åå ãã¦ããªãæ¹ã§ãããã«ã¦ã§ã¢è§£æã®å¦ç¿ããã¦ããæ¹ã®åèã«ããªãã¨â¦
ã¯ããã« ãã®è¨äºã¯ãNFLaboratories Advent Calendar 2023 - Adventar 11æ¥ç®ã®è¨äºã§ãã çæ§ãæ¯æ¥ãç²ãæ§ã§ããæè²ã½ãªã¥ã¼ã·ã§ã³æ å½ã®çªå ´ã§ãã 2023å¹´11æã«OffSec社ã®æä¾ãã¦ããè³æ ¼ã§ããOSEDãåå¾ããã®ã§ãå½è³æ ¼ã®æ¦è¦ãåå¾ããã¾ã§ã®â¦