ãã®è¨äºã¯ãNFLaboratories Advent Calendar 2023 - Adventar 15æ¥ç®ã®è¨äºã§ãã
ã¿ãªãããããã«ã¡ã¯ãç 究éçºé¨ã®æ åã§ããæ®æ®µã¯ã»ãã¥ãªãã£ãã¬ã¼ãã³ã°ãã©ãããã©ã¼ã ã®éçºæ¥åã«æºãã£ã¦ãã¾ããä»åã®ã¤ãã³ãã§ã¯å ¨ä½ã®çµ±æ¬ãæ å½ãã¾ããã
æ¬è¨äºã§ã¯ãå æ¥NFLabs.ãéå¬ãã NFLabs. Cybersecurity Challenge for Students 2023 ã®æ§åãç´¹ä»ãã¾ãã ã¾ãã競æå¾ã«åéããWriteupè³ã®çºè¡¨ãè¡ãã¾ãã
- ã¤ãã³ãæ¦è¦
- ã¹ã±ã¸ã¥ã¼ã«
- åé¡
- 競æçµæ
- 表彰å¼ã»åé¡è§£èª¬
- åé¡ãµã¼ãã®æä¾æ¹æ³
- Writeupè³
- ãããã«
ã¤ãã³ãæ¦è¦
2023å¹´11æ22ï½27æ¥ã«ããã¦ãCTF (Capture The Flag) ã©ã¤ã¯ãªå½¢å¼ã§ã»ãã¥ãªãã£æè¡ã競ãã»ãã¥ãªãã£ãã£ã¬ã³ã¸ã³ã³ãã¹ããNFLabs. Cybersecurity Challenge for Students 2023ããåãã¦éå¬ãã¾ããã
å½å ã®é«çå°éå¦æ ¡ãå°éå¦æ ¡ã大å¦ã大å¦é¢ã«æå±ããå¦çã対象ã«ãconnpassä¸ã§åå åéããå¿åããã£ã66åã®ä¸ããæ½é¸ã§50åã«åå ãã¦ããã ãã¾ããã 競æã¯ãªã³ã©ã¤ã³ã®å人æ¦ã§è¡ãã¾ããã ã¾ããè³ãè¤æ°ç¨æãã¦ããããã®å®åãè®ãã¦ä»¥ä¸ã®è³éãè´åãã¾ããã
- ç·åå¾ç¹1ä½ãè³é5ä¸å
- ç·åå¾ç¹2ä½ãè³é3ä¸å
- ç·åå¾ç¹3ä½ãè³é1ä¸å
- OSINT, DFIR, Malware, PenTestã¸ã£ã³ã«ã®First Bloodè³ãåè³é1ä¸å
- Writeupè³ãè³é1ä¸å
æ¬ã¤ãã³ãã®æã大ããªç¹å¾´ã¯ãé常ã®CTFã¨ç°ãªããã«ã¦ã§ã¢è§£æããããã¬ã¼ã·ã§ã³ãã¹ããã¤ã³ã·ãã³ãã¬ã¹ãã³ã¹ãªã©å®éã®ã»ãã¥ãªãã£æ¥åã§ä½¿ç¨ãããã¹ãã«ãå¿ è¦ãªåé¡ãç¨æãã¦ãããã¨ã§ãã æ®æ®µã»ãã¥ãªãã£ã®æ¥åã«æºãã£ã¦ãã社å¡ããã¹ã¦ã®åé¡ãä½åãããããå®åçµé¨ã«æ²¿ã£ãã·ããªãªã§ä½ããã¦ãã¾ãã
競æçµäºå¾ã«ã¯ãä½åãã社å¡ã«ããåé¡è§£èª¬ãè¡ããä½åã®èæ¯ãåé¡ã®è§£æ³ãå®éã®ç¾å ´ã§ä½¿ããããã¯ããã¯ãªã©ã説æãã¾ããã
ã¹ã±ã¸ã¥ã¼ã«
競ææéã¯6æ¥éè¨ããé£æ度ã®é«ãåé¡ã«ããã£ããæéãããã¦ãã£ã¬ã³ã¸ãã¦ããããããã«ãã¾ããã ã¾ããæéã«åæ¥ç¥æ¥ãå«ã¾ãã¦ãããããè¬ç¾©ãªã©ã§å¿ããå¦çããã§ãåå ããããã£ãã¨å¥½è©ã§ããã 詳ããã¹ã±ã¸ã¥ã¼ã«ã¯ä»¥ä¸ã®éãã§ãã
æ¥æ | ã¤ãã³ã |
---|---|
11/22(æ°´) 17:00 | 競æéå§ |
11/27(æ) 15:00 | 競æçµäº |
11/27(æ) 16:00 - 16:30 | è¡¨å½°å¼ |
11/27(æ) 16:30 - 18:00 | åé¡è§£èª¬ |
åé¡
åé¡ã¯ä»¥ä¸ã®6ã¸ã£ã³ã«ã§ãå ¨25åãåºé¡ãã¾ããã
- OSINT
- DFIR
- Malware (ãã«ã¦ã§ã¢è§£æ)
- Dev
- Web (Webèå¼±æ§è¨ºæ)
- PenTest (ãããã¬ã¼ã·ã§ã³ãã¹ã)
é£æ度ã¯Easy, Medium, Hardã®3段éã«åããã¦ãã¾ãã 競æãå人æ¦ã®ãããè¦æãªã¸ã£ã³ã«ã§ããã£ã¬ã³ã¸ã§ãããããé£æ度Easyã®åé¡ãç¨æãã¾ããã ä¸æ¹ã§ãé£æ度Hardã®åé¡ã¯ãé«åº¦ãªæè¡ãæ±ããããããã«ãã®åéã®ãããã§ãã·ã§ãã«ã®ç¤¾å¡ãè ã«ãããããã¦ä½æãã¾ããã ã¾ããOSINTãDFIRãMalwareãPenTestã¸ã£ã³ã«ã®é£æ度Hardã®åé¡ã«ã¯ãFirst Bloodè³ãè¨å®ãã¾ããã ããã¯ãå ¨åå è ã®ä¸ã§æãæ©ãæ£è§£ãã人ã«è³ãè´åãããã¨ãããã®ã§ãã
é ç¹ã¯ãã¤ãããã¯ã¹ã³ã¢ãªã³ã°æ¹å¼ãæ¡ç¨ãã¾ããã åæç¹ã500ç¹ãæä½ç¹ã100ç¹ã¨ãã¦æ£è§£è æ°ã«å¿ãã¦20ç¹ãã¤å¾ç¹ãä¸ããããã«è¨å®ãã¾ããã
å ¨ä½ã¨ãã¦ã»ãã¥ãªãã£ã®å®åã«è¿ãã·ããªãªã«æ²¿ã£ã¦åé¡ãä½ããã¦ããã以ä¸ã®ãããªç¹å¾´ãæã¤åé¡ãç¨æãã¾ããã
- ãã¼ã¯ã¦ã§ãããã¼ãã¨ããåé¡
- ã¤ã³ã·ãã³ãã¬ã¹ãã³ã¹ããã©ã¬ã³ã¸ãã¯æ¥åã§å¿ è¦ãªã¹ãã«ãåãåé¡
- ææ°ã®ãã«ã¦ã§ã¢ã®ååãåãå ¥ããåé¡
- ãã©ãã¯ããã¯ã¹åããããµã¼ããã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã調æ»ããæ»ææ¤è¨¼ãè¡ãåé¡
åå è ããã¯ãæ®æ®µåå ããCTFã¨åé¡ã®å¾åãç°ãªãæ°é®®ã ã£ããé¢ç½ãã£ãã¨ããã³ã¡ã³ããããã ãã¾ããã
ä¸é¨ã®åé¡ã¯ããã®ã¨ã³ã¸ãã¢ããã°ã®ã¢ããã³ãã«ã¬ã³ãã¼ä¼ç»ã§ä½åè Writeupãå ¬éãã¦ããã®ã§ãæ°ã«ãªãæ¹ã¯ãã²ã覧ãã ããã
競æçµæ
æçµçãªã¹ã³ã¢ãã¼ãã¯ä»¥ä¸ã®ããã«ãªãã¾ããã
ç·åå¾ç¹ã¯ã1ä½ keymoonããã2ä½ Tohaããã3ä½ Cyanosããã¨ããçµæã§ããã 3åã¨ãå¹ åºãã¸ã£ã³ã«ã®åé¡ã«ãã£ã¬ã³ã¸ããæ£çè ã®å°ãªãé«å¾ç¹åé¡ãããã¤ãæ£è§£ãã¦ãããéå¶ããã®ã¹ãã«ã®é«ãã«é©ãããã¾ãã...ï¼
First Bloodè³ã¯ä»¥ä¸ã®ããã«ãªãã¾ããã
- OSINTãshioãã
- DFIRãTohaãã
- Malwareã該å½è ãªã
- PenTestãbarbatos308ãã
ç¹ã«DFIRã¯ç«¶æéå§å¾ãã£ã3æéã§ç²å¾ãPenTestã¯å¯ä¸ã®æ£çè ã¨ãªã£ã¦ããããã®é常ã«é«ãã¹ãã«ã示ããã®ã¨ãªãã¾ããï¼ Malwareã¯æ£çè ã0人ã ã£ãããã該å½è ãªãã¨ãªã£ã¦ãã¾ãã¾ããã ããã¯ãåé¡ã®é£æ度調æ´ãä¸ååã§ãã£ãã¨åçãã¦ããã¾ã...ã 次ã«éå¬ããã¨ãã«ã¯ãé£æ度調æ´ãæ éã«è¡ããåå è ã®ã¿ãªããã«ãã楽ããã§åå ãã¦ããããããæ¹åãã¦ããããã¨èãã¦ãã¾ãï¼
Xã§ãæçµã¹ã³ã¢ã¨First Bloodè³ãçºè¡¨ãã¾ããï¼
ðNFLabs. Cybersecurity Challenge for Students 2023 çµäºãã¾ããï¼ð
— æ ªå¼ä¼ç¤¾ã¨ãã»ã¨ãã»ã©ãã©ããªã¼ãº (@NFLaboratories) 2023å¹´11æ27æ¥
åå ããã ããå¦çã®çããããããã¨ããããã¾ãããï¼Player nameã¯æ¬ç§°ç¥ï¼#ã»ãã¥ãªãã£ã¤ãã³ã pic.twitter.com/RPHOzmmnmQ
表彰å¼ã»åé¡è§£èª¬
競æçµäºå¾ã«ã¯ããªã³ã©ã¤ã³ã«ã¦è¡¨å½°å¼ã¨åé¡è§£èª¬ãè¡ãã¾ããã ã¯ããã«NFLabs. CEOã®å°å±±ããæ¨æ¶ãããããã®å¾ç°¡åãªä¼ç¤¾ç´¹ä»ãè¡ãã¾ããã 次ã«ãCTOã®æ¾æ¨ããç·åå¾ç¹1ä½ï½3ä½ãFirst Bloodè³ã表彰ãã¾ããã 表彰ã®éãåè³è ããã³ã¡ã³ããããã ããã®ã§ãããã¿ãªããããåé¡ãé¢ç½ãã£ãã次åãããã°ã¾ãåå ããããã¨ãããã¤ãã³ãã«æºè¶³ããæ§åãä¼ãã¦ããã ããã®ã§å®å¿ãã¾ããã
表彰å¼ã®å¾ã¯ãä½åè ã«ããåé¡è§£èª¬ãå®æ½ãã¾ããã
OSINTãDFIRãMalwareãWebãPenTestã®åé¡ã«ã¤ãã¦ãåé¡ã®èæ¯ã解ãä¸ã§ãã¤ã³ãã¨ãªãæè¡ãå®éã®æ¥åã§è¦ã¤ããèå¼±æ§ãã©ã®ãããªãã®ãããªã©ãä½åè ãã説æãã¾ããã 解説ã®éã¯Discordã使ã£ã¦è³ªåãæè¦ãåéãã¦ããã®ã§ãéä¸ããã¯åå è ããç¶ã ã¨è³ªåãå¯ããããä½åè ã¨ç´æ¥ããåãã§ããæ©ä¼ã楽ããã§ããã ããããã§ããã äºå¾ã¢ã³ã±ã¼ãã§ããåé¡è§£èª¬ãåå¼·ã«ãªã£ããã¨ã®å£°ãããç´¹ä»ãã¦ãã解æãã¼ã«ãåèã«ãªã£ããã¨ã®å£°ãå¤ãå¯ãããã¾ããã
åé¡ãµã¼ãã®æä¾æ¹æ³
ä»åã®åé¡ã§ã¯ãWebèå¼±æ§è¨ºæã¨ãããã¬ã¼ã·ã§ã³ãã¹ãã§ä½¿ç¨ããåé¡ãµã¼ãã«ã¤ãã¦ãåå è ãã¨ã«åå¥ã®ãµã¼ããæä¾ãã¾ããã é常ã®CTFã§ã¯ãWebåé¡ã§ä½¿ç¨ãããµã¼ãã¯åå è å ¨ä½ã§å ±æã®ãµã¼ãã§ãããã¨ãå¤ãã§ãã ãããããããã¬ã¼ã·ã§ã³ãã¹ãã®åé¡ã§ã¯ããµã¼ãã«ä¾µå ¥ã管çè 権éãå ¥æãããã¨ãã§ãããããåå è ãåé¡ãµã¼ãã®è¨å®ãå¤æ´ãããªã©æãå ãããã¨ãå¯è½ã«ãªã£ã¦ãã¾ãã¾ãã ã¾ããåé¡ãµã¼ãã«æ»ææ¤è¨¼ãå®æ½ããä¸ã§ããµã¼ãã®è¨å®ããã¼ã¿ããªã»ããããããã¨ããç¶æ³ã«ãªããã¨ãããã¾ãããã®ãããåå è ã®ä»»æã®ã¿ã¤ãã³ã°ã§ãµã¼ãã®è¨å®ããªã»ããã§ããå¿ è¦ãããã¾ãã
ããã§ãç 究éçºé¨ã§éçºãã¦ããã»ãã¥ãªãã£ãã¬ã¼ãã³ã°ãã©ãããã©ã¼ã ã®æ©è½ãå©ç¨ãã¦ã¤ãã³ãå°ç¨ãã©ãããã©ã¼ã ãç¨æããåå è ãã¨ã«åå¥ã®åé¡ãµã¼ããèµ·åã§ããããã«æä¾ãã¾ããã å°ç¨ãã©ãããã©ã¼ã ã«ãã°ã¤ã³ããã¨ã以ä¸ã®ãããªç»é¢ããåå è ãèªåå°ç¨ã®åé¡ãµã¼ããèµ·åã§ããããã«ãªã£ã¦ãã¾ãã åé¡ãµã¼ããä»»æã®ã¿ã¤ãã³ã°ã§ç ´æ£ã§ãããããå度起åãããã¨ã§ãªã»ãããå¯è½ã§ãã
ã¾ããèµ·åããåé¡ãµã¼ãã«ã¯OpenVPNçµç±ã§ã¢ã¯ã»ã¹ã§ããããã«ãªã£ã¦ãã¾ãã ãã®éã以ä¸ã®è¨äºã§ç´¹ä»ããVPN管çãµã¼ãã¹ãæ°ãã«éçºãã¦VPNæ¥ç¶æ©è½ãæä¾ãã¾ããã
OpenVPN管理サービスを作ってみた - NFLabs. エンジニアブログ
ä¸è¨ã«ãããåå è ã«å¿«é©ãªãã£ã¬ã³ã¸ç°å¢ãæä¾ãããã¨ãã§ãã¾ããã
Writeupè³
ãã¦ãããããã¯Writeupè³åè³è ã®çºè¡¨ã§ãã
Writeupè³ã¯ãæãç´ æ´ãããå 容ã®Writeupãä½æãã¦ããã ããæ¹ã«éãè³ã§ãã
ä»åã6件ã®å¿åãããã ãã¾ãã¦ãé¸èã®çµæãWriteupè³ã¯ãµãã°ã¨ããã«ãéããããã¨æãã¾ãã ããã§ã¨ããããã¾ãï¼
ã¤ãã³ãã«åå ã§ããªãã£ãæ¹ã«ãã¤ãã³ãã®å ¨ä½åããé¢ç½ãã£ãç¹ãåãããããªæ§æã§ä½æãã¦ããã ãããã¨ããµãã°ã¨ãããé¸å®ããçç±ã§ããå ¨ã¦ã®ã¸ã£ã³ã«ãå¤æ°ã®åé¡ã«è¨åããã¦ãããææ³ãããéå¶å´ã®æå³ãæããä¼ãã£ã¦ããã¨æãã¾ãããç®æ¬¡ãããã°æ´ã«è¯ãã£ãã§ããã ç´ æµãªWriteupãæ¸ãã¦ããã ãããããã¨ããããã¾ããã
ä»ã«ãç´ æ´ãããWriteupãå¿åãã¦ãã ãã£ãæ¹ãããã§ç´¹ä»ãããã¾ãã
- Tohaãã NFLabs. Cybersecurity Challenge for Students 2023 Writeup #Security - Qiita
- suzuki.mãã NFLabs. Cybersecurity Challenge for Students 2023 Writeup #CTF - Qiita
- rk16ãã NFLabs. Cybersecurity Challenge for Students 2023 Writeup | CTF-writeup
- shiosa1tãã NFLabs. Cybersecurity Challenge for Students 2023 WriteUp
- rand0mãã NFLabs CTF 2023: Malware編 | rand0m
Writeupè³ã«å¿åãã¦ããã ããã¿ãªãã¾ããããã¨ããããã¾ããã
ãããã«
NFLabs. åã®ã»ãã¥ãªãã£ãã£ã¬ã³ã¸ã³ã³ãã¹ããNFLabs. Cybersecurity Challenge for Students 2023ããç´¹ä»ãã¾ããã ãã®è¨äºããã£ããã«NFLabs.ã«èå³ãæã£ã¦ãã ãã£ãæ¹ãããã°å¬ããã§ãã åå è ã®ã¢ã³ã±ã¼ãã§é¢ç½ãã£ããåå¼·ã«ãªã£ããã¾ãåå ããããã¨ãã£ãã³ã¡ã³ããããã ããã¤ãã³ãã®éå¶ã¨ãã¦ã¿ãªããã楽ããã§ããã ãããã¨ã大å¤åãã§ããã¾ãã ãã®ãããªæè¡ã¤ãã³ããä»å¾ãéå¬ãã¦ããããã¨èãã¦ããã¾ãã®ã§ããã²ãæå¾ ãã ããï¼