2021-01-01ãã1å¹´éã®è¨äºä¸è¦§
ããã«ã¡ã¯ãNFLabs. äºæ¥æ¨é²é¨ã®é½è¤ã§ãããã®è¨äºã¯ NFLabs. ã¢ããã³ãã«ã¬ã³ãã¼ 14 æ¥ç®ã®è¨äºã§ãã æ®æ®µã¯ Blue Team ã®ä¸ã§å©ç¨ããã·ã¹ãã ã®éçºããã¦ãã¾ãã ç§ã¯ä»ã®ãã¼ã 㧠DevSecOps ã®ä»çµã¿ããã¼ã«ãè²ã ã¨è©¦ãã¦å°å ¥ãé²ãã¦ããæä¸â¦
ã¯ããã« ããã«ã¡ã¯ãäºæ¥æ¨é²é¨ã§åºç¤éçºãç¶æéç¨ãæ å½ãã¦ããMJã§ãããã®è¨äºã¯ãNFLabs.ã¢ããã³ãã«ã¬ã³ãã¼12æ¥ç®ã§ããä»å¹´ãããæ®ãã¨ããããã9æ¥ã¨ãªãã¾ããããããéããã§ããããã çªç¶ã§ãããçãããå®æçã«æ¥åã®ãæ¯ãè¿ããâ¦
ã¯ããã« ããã«ã¡ã¯ãäºæ¥æ¨é²é¨ã§Offensive Teamãæ å½ããæ°¸äºã§ãã ä»åã¯ã¢ããã³ãã«ã¬ã³ãã¼ã®11æ¥ç®ã¨ãã¦ãååæ稿ãããmacOSã®æå·åzipãã¡ã¤ã«ã¯ãã¹ã¯ã¼ããªãã§è§£åã§ãããã¨ããè¨äºã«å¯ããããã³ã¡ã³ãã®ãã¡ãç¹çãã¹ããã®ãããã¯â¦
ããã«ã¡ã¯ãNFLabs. Offensive Teamã®å²©å´ã§ãã æ¬è¨äºã¯NFLabs. ã¢ããã³ãã«ã¬ã³ãã¼ 10æ¥ç®ã®è¨äºã¨ãªãã¾ããè¿å¹´ãå¤ãã®Webãµã¼ãã¹ã§ã¯CDN(Content Delivery Network)ã¨å¼ã°ããWebã³ã³ãã³ãé ä¿¡ãµã¼ãã¹ãå©ç¨ããã¦ããã¾ããCDNã¯ä¸çä¸ã«åæ£â¦
ããã«ã¡ã¯ãNFLabs. äºæ¥æ¨é²é¨ã®ä¸å ã§ãã ãã®è¨äºã¯ NFLabs. ã¢ããã³ãã«ã¬ã³ãã¼9æ¥ç®ã§ãã ä»åã¯ãWindowsç°å¢ã«å¯¾ãããããã¬ã¼ã·ã§ã³ãã¹ãã§å¤ç¨ãããããã¼ã¯ã³å½è£ (Token Impersonation/Theft)ãã¨ããæ»æãã¯ããã¯ã«ã¤ãã¦è§£èª¬ãããã¨â¦
ã¯ããã« ããã«ã¡ã¯ãäºæ¥æ¨é²é¨ã§æè²ç ä¿®ãæ å½ããæç°ã§ãããã®è¨äºã¯ NFLabs. ã¢ããã³ãã«ã¬ã³ãã¼8æ¥ç®ã§ããã»ãã¥ãªãã£ç ä¿®ã§OSINTï¼Open Source Intelligence : å ¬éããã¦ããæ å ±ã½ã¼ã¹ããå ¥æå¯è½ãªãã¼ã¿ãåéã»åæããæè¡ï¼ãæãããâ¦
ã¯ããã« ããã«ã¡ã¯ãNFLabs. DevOps Teamã®é¦å·ã§ãããã®è¨äºã¯NFLabs.ã¢ããã³ãã«ã¬ã³ãã¼2021ã®7æ¥ç®ã§ãã æã ã®çµç¹å ã«ã¯ããã¤ãã¹ã¯ã©ã ãã¼ã ãåå¨ããããããã§éçºãè¡ã£ã¦ãã¾ãããããªä¸ããã¼ã ã横æããçµç¹ã¨ãã¦æå¿ã«ãã£ã¦ç«ã¡ä¸â¦
ããã«ã¡ã¯ãNFLabs. äºæ¥æ¨é²é¨ã®éä¸ã§ãã æ¬è¨äºã¯NFLabs. ã¢ããã³ãã«ã¬ã³ãã¼ 6æ¥ç®ã®è¨äºã§ãã å¹³æã¯ã»ãã¥ãªãã£æè¡ã«ã¤ãã¦è¨è¼ãããã¨ã®å¤ãæ¬ããã°ã§ãããä»åã¯è¦ç¹ãå¤ãã¦ãããã¯ã¼ã¯éç¨ã®è¦³ç¹ããã®ã話ããããã¨æãã¾ãã éç¨ãâ¦
ããã«ã¡ã¯ãNFLabs. äºæ¥æ¨é²é¨ æè²ç ä¿®æ å½ã®å¡è¶ã§ãã ãã®è¨äºã¯ NFLabs. ã¢ããã³ãã«ã¬ã³ãã¼ï¼æ¥ç®ã§ããä»åã¯ãæè²ç ä¿®æ å½ã§å®æ½ãã¦ãããæè²ææ³ãã®èª¿æ»ç 究ãããã³NFLabs.ç ä¿®ã¸ã®å°å ¥ã«ã¤ãã¦ãåãçµã¿å 容ããç´¹ä»ãããã¨æãã¾ããâ¦
ããã«ã¡ã¯ãNFLabs. äºæ¥æ¨é²é¨ã®ynã§ãã ãã®è¨äºã¯NFLabs. ã¢ããã³ãã«ã¬ã³ãã¼4æ¥ç®ã§ãã ã¯ããã« 2021å¹´7æã«ã社å ã®æå¿ã§Hack The Box Business CTF 2021ã«åå ãã¾ããã詳細ã¯Hack The Box Business CTF 2021 åå è¨ã«è¨ãã¦ãã¾ãã ãã®ã»ãâ¦
ããã«ã¡ã¯ãäºæ¥æ¨é²é¨ã®å»£ç°ã§ãã NFLabs. ã¢ããã³ãã«ã¬ã³ãã¼3æ¥ç®ã¨ãããã¨ã§ã æ¬ç¨¿ã§ã¯sshæ¥ç¶æã®äºè¦ç´ èªè¨¼ã®å®è£ ã«ã¤ãã¦æ¸ãã¦ã¿ããã¨æãã¾ãã ã¯ããã« ç¾å¨ç§ã¯NTTã³ãã¥ãã±ã¼ã·ã§ã³ãºæ ªå¼ä¼ç¤¾ããNFLabs.ã«åºåãã¦ããã®ã§ãããåºåâ¦
ããã«ã¡ã¯ãNFLabs. äºæ¥æ¨é²é¨ã®æ©æ¬ã§ãã æ¬è¨äºã¯NFLabs. ã¢ããã³ãã«ã¬ã³ãã¼ 2æ¥ç®ã§ãã ã¯ããã« æ¬æ¥ã¯ã»ãã¥ãªãã£ç£æ»ãè¡ãä¸ã§éè¦ãªæ å ±ã§ããWindowsã¤ãã³ããã°ï¼ã»ãã¥ãªãã£ç£æ»ï¼ã«ã¤ãã¦è¨äºãæ¸ãã¦ãããã¨æãã¾ãã2æ¥ç®ã®ã2ãâ¦
ããã«ã¡ã¯ãNFLabs. äºæ¥æ¨é²é¨ æè²ç ä¿®æ å½ã®æ¦äºã§ãã ãã®è¨äºã¯ NFLabs. ã¢ããã³ãã«ã¬ã³ãã¼ï¼æ¥ç®ã§ãå¤ãã®æ°ç±³ããã¼ã¸ã£ãæã¤ã§ãããæ©ã¿ã¨ããã«å¯¾ããèªåãªãã®èãã«ã¤ãã¦ã話ããããã¨æãã¾ãã ã¯ããã« ä»å¹´ã®3æã«ããã¼ã¸ã£ã¨ãªâ¦
æ ªå¼ä¼ç¤¾ã¨ãã»ã¨ãã»ã©ãã©ããªã¼ãº(NFLabs.)ã®ã¨ã³ã¸ãã¢ã«ããã¢ããã³ãã«ã¬ã³ãã¼ã§ãã NFLabs.ã§ã¯ãOffensive TeamãDefensive TeamãDevOps Teamã®ã¡ã³ãã¼ãããããã®ã¹ãã«ãæ´»ããã¦ãã»ãã¥ãªãã£åéã®æåç·ã§åãã¨ã³ã¸ãã¢ã®è²æãè å¨åâ¦
ã¯ããã« ããã«ã¡ã¯ãOffensive Teamã®ä¿è¦ã§ããæ®æ®µã¯ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã¨ãã¦ãOffensive Securityã«é¢ãããã¼ã«ã®æ¤è¨¼ãTrainingãªã©ã§ä½¿ç¨ããæ¼ç¿ç°å¢ãèªåæ§ç¯ããã·ã¹ãã ã®éçºãè¡ã£ã¦ãã¾ãã NFLabs.ã§ã¯ãæ»æè ã®è¦ç¹ã§èå¼±æ§ãè¦ã¤ãâ¦
ããã«ã¡ã¯ãNFLabs. Offensive Teamã®é¿é¨ã§ãã 10/5 (ç«) ã«ãç¹å®ã®è¨å®ããªããã¦ããApache HTTP Server (以å¾Apache) 2.4.49ã®ç°å¢ã«ããã¦ãªã¢ã¼ãããã³ã¼ãå®è¡ (RCE) ãå¯è½ãªèå¼±æ§ï¼CVE-2021-41773ï¼ãçºè¦ããã¾ããã ããã«ããã®èå¼±æ§ãå¡â¦
ã¯ããã« ããã«ã¡ã¯ãäºæ¥æ¨é²é¨ã§Offensive Teamãæ å½ããæ°¸äºã§ãã å æ¥ã®Appleçºè¡¨ä¼ã§ã¯æ°åã®iPhoneãApple Watchãªã©å¿èºã製åãè²ã ã¨çºè¡¨ããã¾ããããçè ã¯ç¹ã«æ°åiPad miniãå¿ã«åºãã£ã¦ãã¾ãã ãã¦ãä»åã¯Appleé¢é£ã®è©±ã¨ãã¦ãmacOSâ¦
æ¬è¨äºã¯ãä»æ¥ããã§ãããµã¤ãã¼è å¨ã¤ã³ããªã¸ã§ã³ã¹ã®è©±-å°å ¥ç·¨-ãã®ç¶ãã§ãããå ·ä½çãªãµã¤ãã¼è å¨æ å ±ã®åéæ¹æ³ããã©ãããã©ã¼ã ã«ã¤ãã¦ç´¹ä»ããè¨äºã§ãã ããµã¤ãã¼è å¨ã¤ã³ããªã¸ã§ã³ã¹ã£ã¦ä½?ãã¨ããæ¹ãããã£ãããã°åã®è¨äºãåèã«â¦
TL;DR Windows WinRMã¯HTTP(S)ã§LISTENãã¦ãã è¸ã¿å°ãµã¼ãã«HTTP proxyãè¨ç½®ããWinRMã®ãªã¯ã¨ã¹ããä¸ç¶ãããã¨ãã§ãã Linux ãªãã·ã§ã³ãé©åã«è¨å®ããã¨å¤æ®µSSHãã§ããããã«ãªã Ansibleã§localhostã®IPã¢ãã¬ã¹ãåå¾ããæ¹æ³ {{ hostvars.locâ¦
æ¬è¨äºã§ã¯NXNSAttackã¨ããèå¼±æ§ã«ã¤ãã¦æ¤è¨¼ããçµæãç´¹ä»ãã¾ãã NXNSAttack (Nonexistent Nameservers Attack) ã¨ã¯2020å¹´5æã«å ¬è¡¨ãããDNSãªã¾ã«ãã®èå¼±æ§ã§ãããæ§ã ãªå®è£ (UnboundãBINDãPowerDNSãªã©)ã§å½±é¿ãåãã¾ããç¹å®ã®DNSãªã¾ã«ãã«â¦
ããã«ã¡ã¯ãNFLabs.ã®Defensive Teamã§ãã æ¬è¨äºã§ã¯ãæã ã®ãã¼ã ãè¡ã£ã¦ããè å¨æ å ±åéããã³åææ´»åã®ä¸é¨ãç´¹ä»ãã¾ãã ãã ãããã«ã¦ã§ã¢è§£æã»ãã°åæã¨ãã£ãæè¡çãªå 容ããã¼ã¯ã§ãã£ã¼ããªãµã¤ãç´¹ä»ã¨ãã£ãå°éçãªè©±é¡ã¾ã§ã¯æ±ãã¾â¦