ã¯ããã«
çæ§ãç²ãæ§ã§ããæè²ã½ãªã¥ã¼ã·ã§ã³æ
å½ã®ä¸å±±ã§ãã
Burp Suite Certified Practitionerï¼BSCPï¼ã«åæ ¼ã§ããã®ã§ããã®è³æ ¼ã®èª¬æãåæ ¼ã¾ã§ã®éã®ãã«ã¤ãã¦ç´¹ä»ãããã¨æãã¾ãã
ç®æ¬¡
Burp Suite Certified Practitioner ï¼BSCPï¼ã¨ã¯
PortSwigger社ã¯Burp Suiteãæä¾ãã¦ããä¼ç¤¾ã§ãæ¬è³æ ¼ã§ã¯Burp Suiteãæ´»ç¨ãããã¨ãåæã¨ãã¦å¹
åºãèå¼±æ§ã«åãçµãã§ããã¨ããç¹ãç¹å¾´ã§ãã
https://portswigger.net/web-security/certification
試é¨å 容
試é¨ã§ã¯èå¼±æ§ã®çºè¦ã ãã§ãªãæªç¨ã¾ã§è¡ãå¿
è¦ããããWebã¢ããªèå¼±æ§è¨ºæã¨ããããã¯Webãã³ãã¹ãå¯ããªãã®ã¨ãªã£ã¦ãã¾ãã
ãã©ãã¯ããã¯ã¹è¨ºæã®å½¢å¼ã§Webã¢ããªä¸ã®èå¼±æ§ãè¦ã¤ãããããä¸ã®é ã§æªç¨ããªããç®æ¨ãéæããå¿
è¦ãããã¾ãã
- ä»»æã®ã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ãã奪åãã
- 奪åããã¦ã¼ã¶ã¼ã¢ã«ã¦ã³ãã®æ¨©éãææ ¼ããããå¥ã®ç®¡çè ã¢ã«ã¦ã³ãã奪åãã管çè æ©è½ã«ã¢ã¯ã»ã¹ãã
- æå®ããããã¡ã¤ã«ã®å 容ãèªã¿åãæåºãã
試é¨ã§ã¯2ã¤ã®Webã¢ããªãåºé¡ããããã®ä¸¡æ¹ãæ»ç¥ã§ããã°åæ ¼ã¨ãªãã¾ãã
å¦ç¿ã®éã®ã
ãã£ãã
ç§ã¯NFLabs. ã«ã¯ä»å¹´ï¼æããæå±ãã¦ãããããã¾ã§ã¯å¥ã®å ´æã§Webã¢ããªèå¼±æ§è¨ºææ¥åã«æºãã£ã¦ãã¾ããã
ããã¦ãä½ãé¢ç½ãããªè³æ ¼ããªããæ¢ãã¦ãã¾ããã
ããã§è¦ã¤ããã®ãBSCPã§ããã
Webã»ãã¥ãªãã£ã«ã¤ãã¦å¦ã¹ãè³æ ¼ã¯ä»ã«ãããã®ã§ãããBurp Suiteãå¼·ãæ´»ç¨ãã¦ããç¹ã«ãã®è³æ ¼ãªãã§ã¯ã®é¢ç½ããæããåãçµãã§ã¿ããã¨ã«ãã¾ããã
å¦ç¿éå§æç¹ã§ã®ã¹ãã«ã¬ãã«
æ¥å
- èå¼±æ§è¨ºæ 2å¹´é
è³æ ¼
- æ å ±å¦çå®å ¨ç¢ºä¿æ¯æ´å£«ï¼æªç»é²ï¼
- GCIH
å¦ç¿æ¹æ³
PortSwigger社ãç¡æã§æä¾ãã¦ããWeb Security Academyã¨ããã³ã³ãã³ããå¦ç¿ãã¾ããã
試é¨ã¯ãã®å
容ããåºé¡ããã¾ãã
å¦ç¿æéã¨ãã¦ã¯200æéã»ã©è²»ããããã¨æãã¾ãã
ç°¡åãªã¢ã«ã¦ã³ãç»é²ãè¡ãã ãã§å¦ç¿ãéå§ã§ãã¾ãã
Webã»ãã¥ãªãã£ã«èå³ãããæ¹ã«é常ã«ããããã§ãã
Web Security Academy
30ãããã¯ã®èå¼±æ§ãåãæ±ã£ã¦ãããã©ãã¯250以ä¸ããã¾ãã
https://portswigger.net/web-security/all-labs
é£æ度ã¯é£ããæ¹ããé ã« Expert, Practitioner, Apprentice ã®3段éãããã試é¨ç¯å²ã¯Practitionerã¨Apprenticeã§ãã
ç§ã¯åé¨ããã¾ã§ã«è¨240ã»ã©ï¼ Expert ä¸é¨ + Practitioner å
¨ã¦ + Apprentice å
¨ã¦ï¼ã®ã©ãã«åãçµã¿ã¾ããã
å
容ãé常ã«å
å®ãã¦ããã楽ããå¦ç¿ã§ãã¾ããã
èå¼±æ§è¨ºæã®çµé¨ãããæ¹ã§ããPractitionerã¨Apprenticeã«ã¤ãã¦ã¯å¿µã®çºå
¨ã¦åãçµãã§ãããæ¹ãè¯ãã¨æãã¾ãã
åºæ¬çã«ä¸ã®æµãã§å¦ç¿ãè¡ãã¾ããã
- èå¼±æ§ã«ã¤ãã¦ã®èª¬æãèªã
- ã©ãã«åãçµã
- ããããªãã£ããçããè¦ãªããé²ãã
Practice Exam
PortSwigger社ã¯ç¡æã§åãããã模æ¬è©¦é¨ã2種é¡æä¾ãã¦ãã¾ãã
åå¨ããèå¼±æ§ã¯2ã¤ã¨ãåããªã®ã§ãããåºãããã¤ãã¼ããç°ãªãã¾ãã
æ¬çªã¨åãå½¢å¼ã«æ
£ãããã¨ãã§ããã®ã§åãçµããã¨ããããããã¾ãã
ã¾ããç¡æã§åé¨ã§ããã®ã§è
試ãã«åãã¦ã¿ãã®ãé¢ç½ãã¨æãã¾ãã
ã¤ã³ããã¯ã¹ããã¼ãã·ã¼ãä½æ
åå¼·ããå
容ã«ã¤ãã¦ã¯ã¤ã³ããã¯ã¹ã¨ãã¼ãã·ã¼ããä½æãã¾ããã
ã¾ããå
人ãä½ã£ã¦ãã ãã£ããã¼ãã·ã¼ããGitHubä¸ã«ãã£ãã®ã§ããããä½µãã¦æ´»ç¨ãã¾ããã
åºé¡ãããèå¼±æ§ã®å¹
ãåºãã®ã§ããããã®ããã¥ã¡ã³ãã¯å¿
é ã ã¨æãã¾ãã
使ç¨ãã¼ã«
å¿ é
- Burp Suite Professional
Burp Suiteã®Professionalã©ã¤ã»ã³ã¹ããªãã¨BSCPãåãããã¾ããã
Web Security Academyãåå¼·ããã ããªãProfessionalã©ã¤ã»ã³ã¹ããªãã¦ãåºæ¬çã«åé¡ãªãã§ãã
ãã ãããã®å ´åã§ãProfessionalã©ã¤ã»ã³ã¹ã¯é常ã«ä¾¿å©ãªã®ã§ããããã§ãã
å¿ é ã§ã¯ãªãã便å©
使ã£ããã¼ã«ã¯è²ã ããã¾ãããç¹ã«ä¾¿å©ã ã£ããã®ãåæãã¾ããã
- sqlmap
ãã¤ãã¼ããèããå¿
è¦ããªãã®ã§æ¥½ã§ããã
ãã ããsqlmapãåºãããªãå ´åãããã®ã§ãèªåã§ãã¤ãã¼ããèããè½åã¯çµ¶å¯¾ã«èº«ã«ã¤ãã¦ããå¿
è¦ãããã¾ãã
- SSTImap
sqlmapåæ§ããã¤ãã¼ããèããå¿
è¦ããªãã®ã§æ¥½ã§ããã
ãã ã対å¿ã§ããªããã³ãã¬ã¼ãã¨ã³ã¸ã³ãããã®ã§ãsqlmapã¨åæ§ã«èªåã§ãã¤ãã¼ããèããè½åã¯çµ¶å¯¾ã«èº«ã«ã¤ãã¦ããå¿
è¦ãããã¾ãã
試é¨æ¬çª
1度ç®
è½ã¡ã¾ãã...ã
1ã¤ç®ã®Webã¢ããªã¯æ»ç¥ã§ããã®ã§ãã2ã¤ç®ãæ»ç¥ã§ãã¾ããã§ããã
åçç¹ã¯ä¸ã®2ç¹ã§ãã
- ç·å¼µãããã
- ããExtensionã使ã£ãæã«ç°å¢ãå£ãã
ã©ãç°å¢ã ã¨ãã®äºè±¡ã¯çºçãã¾ããã§ããããæ¬çªã§çªç¶çºçãã¾ããã
ãã¿ãã¬ã«ãªã£ã¦ãã¾ãã®ã§è©³ããã¯æ¸ããªãã®ã§ãããããèå¼±æ§ã«ã¤ãã¦æ»æãåºããªã¯ã¨ã¹ããé£ç¶ã§éã£ã¦ãããExtensionã使ç¨ããéã«Webãµã¤ãã®æåããããããªãã¾ããã
ãã®æ»æãWebãµã¤ãã®åä½ã«å½±é¿ãä¸ãããã®ã§ãããã¨ã¯äºåã«ææ¡ãã¦ãããæ£å¸¸ãªåä½ã«æ»ãããã®æ¹æ³ãç解ãã¦ãã¾ããã
ãã ããã®æ¹æ³ã試ãã¦ãWebãµã¤ãã®åä½ã¯æ»ãããå®å
¨ã«æ³å®å¤ã§ããã
çµå±èªåã§ã¯ç´ããããã®å¾©æ§ã«2æé以ä¸ãããã¾ãããï¼2æé以ä¸çµã£ããããã§åæã«ç´ãã¾ãããï¼
試é¨æéã¯4æéãªã®ã§ãããã§å¤§ããªæéã失ã£ã¦ãã¾ã£ãã®ã¯é常ã«è¦ããã£ãã§ãã
æ»æãå®éã«åºããããªExtensionã¯Webãµã¤ãã®åä½ã«æå³ããªãå½±é¿ãä¸ããå¯è½æ§ããããããæ»æãExtensionã®æ§è³ªãè¸ã¾ããä¸ã§æ£ãã使ã£ã¦ãããã¨ãéè¦ã ã¨å¦ã³ã¾ããã
Extensionã使ããªãæ¹ãè¯ãã¨ãããã¨ã§ã¯ãªããâæ£ãã使ã£ã¦ããâãã¨ãéè¦ã ã¨ãä¼ããããã§ãã
2度ç®
ã¾ãè½ã¡ã¾ãã......ã
1度ç®ã¨åæ§ã1ã¤ç®ã®Webã¢ããªã¯æ»ç¥ã§ããã®ã§ãã2ã¤ç®ãæ»ç¥ã§ãã¾ããã§ããã
åçç¹ã¯ä¸ã®2ç¹ã§ãã
- å å ¥è¦³ãããã§ãã¯ãã¦ãªãã£ãç®æã«èå¼±æ§ããã£ã
æ°ã¥ãã®ãé ããªã£ã¦ãã¾ããå¿ä½ãªãæéã使ã£ã¦ãã¾ãã¾ããã
- ç¥ããªããã¯ããã¯ãåºã¦ãã
試é¨å¾ã«Web Security Academyãèªã¿è¿ãã¨ã端ã®æ¹ã«æ¸ããã¦ãã¾ããã
é
ã
ã¾ã§èªãã¦ããªãã£ãèªåã®çããåçãã¾ããã
3度ç®
ç¡äºã«2ã¤ã®Webãµã¤ããæ»ç¥ã§ãã¾ããã
2度ç®ã®å¤±æããããWeb Security Academyã«ããã¦ãæªç¨æ¹æ³ãããã«é¢é£ããé¨åãæ¹ãã¦é
ã
ã¾ã§èªã¿è¿ãã¦è¨ã¿ã¾ããã
3度ç®ã¯æéçã«ä½è£ãæã£ã¦æ»ç¥ãããã¨ãã§ãã¾ããã
åæ ¼ã®ããã®ãã¤ã³ã
ãã¼ãã·ã¼ããã¤ã³ããã¯ã¹ã¯é常ã«éè¦ã§ãããå½ããåã®è©±ãªã®ã§ããã¦ããã§ã¯è¨åãã¾ããã
ä¸ã®1ç¹ãé常ã«éè¦ã ã¨æãã¾ããã
ããã¦ä½ãããæ®éã«ã©ããããªãã¦ãããããå§åçã«æ¥½ããã¯ãã§ãã
ã©ãã®ã´ã¼ã«ãéæãã¦çµããã«ããªã
試é¨æ¬çªã§ã¯å¿ç¨åãé常ã«éè¦ã§ãã
ç§ã®å ´åãå¿ç¨åä¸è¶³ã«ãã£ã¦è©¦é¨æ¬çªã§ã¨ããã©ããè©°ã¾ã£ã¦ãã¾ãã¾ããã
試é¨æ¬çªã§ã¯ã¢ã«ã¦ã³ãã®å¥ªåã権éææ ¼ãä»»æã³ãã³ãå®è¡ã«ãããã¡ã¤ã«ã®èªã¿åããå
·ä½çãªæªç¨æ¹æ³ã¨ãªãã¾ãã
ãã ãã©ãã¯ããã¾ã§èå¼±æ§ã®å¦ç¿ãç®çã®ãã®ãªã®ã§ãä¸è¨ã®ãããªã´ã¼ã«ãæ¯åå®ãããã¦ãã訳ã§ã¯ããã¾ããã
ç§ãããã§ãããããããã®ããã¢ã«ã¦ã³ã奪åã権éææ ¼ãä»»æã³ãã³ãå®è¡ã®ã©ããå¯è½ãªãã®ãèªåç¬èªã®ã´ã¼ã«ã¨ãã¦å®ãã¦åãçµãæ¹æ³ã§ãã
ããã«ãããæ§ã
ãªç°å¢ã«ããã¦èå¼±æ§ãå®è·µçã«æªç¨ãã¦ããç·´ç¿ã沢山ã§ããå¿ç¨åã身ã«ã¤ãã¾ãã
ä¾ãã°ãXSS㧠alert(1) ãçºç«ããããã¨ãã´ã¼ã«ã®ã©ãããã£ãã¨ãã¾ãã
ããã«ããã¦ã被害è
ã®Cookieãèªåã«éä¿¡ãããã¨ããã´ã¼ã«ãèªåã§æ°ãã«è¨å®ãã¦åãçµããã¨ãã£ãå
·åã§ãã
ãããã«
å¦ç¿ã試é¨ãé常ã«æ¥½ããã£ãã§ãã
Webã»ãã¥ãªãã£ã®ç¥è¦ãæ·±ãããã¨ãã§ãã¾ããã
èå¼±æ§ãè¦ã¤ãã¦çµããã§ã¯ãªãããããæªç¨ãã¦ã¢ã«ã¦ã³ãã奪åãããã権éææ ¼ãããããã¡ã¤ã«ãèªã¿åã£ããããã¾ã§ãã´ã¼ã«ã§ããç¹ãæ®æ®µã®è¨ºææ¥åã¨éã£ã¦ãã¦æ°é®®ãã¤é常ã«æ¥½ããã£ãã§ãã
試é¨ã¯ããã¾ã§ã«åå¼·ããå
容ãå¿ç¨ããªããæªç¨ãã¦ããè¶
å®è·µç·¨ã¨ããæè¦ã§é常ã«æ¥½ããã£ãã®ã§ã¾ãåããããããã§ããï¼ç¬ï¼
ã¾ããWeb Security Academyã¯é常ã«åªããå¦ç¿ã³ã³ãã³ãã§ããã
Practice Examãé常ã«é¢ç½ãã£ãã§ãã
BSCPãåããäºå®ã®ãªãæ¹ã
ãä¸ã®ã³ã³ãã³ãã¯ç¡æã§éã¹ãã®ã§æ¯éåãçµãã§ã¿ã¦ãã ããã