ããã«ã¡ã¯ãç 究éçºé¨ã®æ«å»£ã§ããæ®æ®µã¯ã»ãã¥ãªãã£ãã¬ã¼ãã³ã°ãã©ãããã©ã¼ã ç¨ã®åé¡ä½æçãè¡ã£ã¦ãã¾ãã
æ¬è¨äºã§ã¯ã9æã«ï¼¦ï¼¦ï¼²ï¼©ã»ãã¥ãªãã£ã¨NFLabs.ãååã§éå¬ããFFRI Security x NFLabs. Cybersecurity Challenge for Students 2024ãç´¹ä»ãã¾ããã¾ããNFLabs.ãé¸å®ããWriteupè³ãçºè¡¨ãã¾ãã
FFRIã»ãã¥ãªãã£ãé¸å®ããWriteupè³ã®çºè¡¨è¨äºã¯ãã¡ãã®ãªã³ã¯ãã覧ãã ããã
ã¤ãã³ãæ¦è¦
09/17(ç«)10:00ï½09/20(é)15:00ã«ããã¦ãCTF (Capture The Flag) å½¢å¼ã§ã»ãã¥ãªãã£æè¡ã競ãã»ãã¥ãªãã£ãã£ã¬ã³ã¸ã³ã³ãã¹ããFFRI x NFLabs. Cybersecurity Challenge for Students 2024ããéå¬ãã¾ãããåæ§ã®ã³ã³ãã¹ãã¯ãæ¨å¹´å®æ½ã®NFLabs. Cybersecurity Challenge for Students 2023ã«ç¶ãã¦2åç®ã§ãã
æ¥æ¬å½å ã®é«çå°éå¦æ ¡ãå°éå¦æ ¡ã大å¦ã大å¦é¢ã«æå±ããå¦çã対象ã«ãconnpassã§åå ãåéãã¾ãããå¿åããã ãã83åã®ä¸ããæ½é¸ããå½é¸ãã80åã«åå ããã ãã¾ããã競ææ¹å¼ã¯ãªã³ã©ã¤ã³ã®å人æ¦ã§è¡ãã¾ãããã¾ããåé¡ã®ä¸ã«ã¯å®è¡ãã¡ã¤ã«ã解æããããã®ç°å¢ãå¿ è¦ãªåé¡ããããããflare-vmçã使ã£ã解æç°å¢ã®æ§ç¯æ¹æ³ãã競æå®æ½åã«ç´¹ä»ãã¾ããã
å®æ½ã¹ã±ã¸ã¥ã¼ã«
å¹³æ¥4æ¥éã§ããã次ã®ã¹ã±ã¸ã¥ã¼ã«ã§éå¬ãã¾ããã
æ¥æ | ã¤ãã³ã |
---|---|
09/17(ç«) 10:00 | 競æéå§ |
09/20(é) 15:00 | 競æçµäº |
09/20(é) 16:00 - 16:30 | è¡¨å½°å¼ |
09/20(é) 16:30 - 18:00 | åé¡è§£èª¬ã»æè« |
表彰å¼ã§ã¯ãNFLabs. CTOã®æ¾æ¨ã¨ãFFRIã»ãã¥ãªãã£CTOã®éå± ããåè³è ãçºè¡¨ãã¾ãããã¾ããåè³è ããã³ã¡ã³ããããã ãã¾ããã ãã®å¾ã®åé¡è§£èª¬ã§ã¯ãé£æ度ã®é«ãåé¡ãä½æãã社å¡ããä½åã®èæ¯ãå¿ è¦æè¡ãæ³å®è§£æ³çã解説ãã¾ããã
ãã ãã¹ã±ã¸ã¥ã¼ã«ã«ã¤ãã¦ã¯ã競æå¾ã¢ã³ã±ã¼ãçã§ãåæ¥ãå«ãæ¥ç¨ãè¯ãã£ããçã®å£°ãè¤æ°ããã ãã¾ããã次åå®æ½æã¯åå ããã ããããæ¥ç¨ã¨ãªãããã«ãéå¬ææ¥ãå«ãã¦æ¤è¨ãã¾ãã
åé¡ã»è³é
åé¡ã¯ä»¥ä¸ã®5ã¸ã£ã³ã«ã§ãå ¨17åãåè¨20ãã©ã°ãåºé¡ãã¾ããã
- Web Exploitation ï¼Webèå¼±æ§æ»æãå ¨3åï¼
- Pentest ï¼ãããã¬ã¼ã·ã§ã³ãã¹ããå ¨3åã1åãè¤æ°æ®µéã«åãã¦ããããåè¨6ãã©ã°ï¼
- Binary Exploitation ï¼ãã¤ããªèå¼±æ§æ»æãå ¨3åï¼
- Malware Analysis ï¼ãã«ã¦ã§ã¢è§£æãå ¨3åï¼
- Misc ï¼ä¸è¨4ã¸ã£ã³ã«ã«å±ããªãã¸ã£ã³ã«ãå ¨5åï¼
ãããã®åé¡ããå®åã§æ´»ç¨ã§ããæè¡ãæ±ããã¨ã念é ã«ä½åãã¦ãã¾ãã
Web ExploitationãPentestãBinary ExploitationãMalware Analysisã®4ã¤ã®ã¸ã£ã³ã«ã§ã¯ãæ³å®é£æ度ãEasyãMediumãHardã®3段éã®åé¡3åãç¨æãã¾ãããã¾ããå¾è¿°ãã¾ãããã«ããã4ã¸ã£ã³ã«ã§ã¯ã¸ã£ã³ã«ãããè³ãç¨æãã¾ããããã®ä»ã®Miscã¸ã£ã³ã«ã§ã¯ãæ³å®é£æ度ãEasyãMediumã®åé¡5åãç¨æãã¾ããã
é ç¹ã«ã¯ãã¤ãããã¯ã¹ã³ã¢ãªã³ã°æ¹å¼ãæ¡ç¨ãã¾ããããã®æ¹å¼ã¯ãæ£è§£è æ°ãå°ãªãåé¡ã¯é«å¾ç¹ã§ãæ£è§£è æ°ãå¢ããã«ã¤ãã¦ãã®åé¡ã®å¾ç¹ã¯ä½ããªãæ¹å¼ã§ãã
è³é
æ¨å¹´åæ§ã«ãå®åãããããè³ãè¤æ°ç¨æãã¦è³éãè´åãã¾ããã
- ç·åå¾ç¹1ä½ãè³é7ä¸å
- ç·åå¾ç¹2ä½ãè³é5ä¸å
- ç·åå¾ç¹3ä½ãè³é3ä¸å
- ç·åå¾ç¹4ä½ãè³é2ä¸å
- ç·åå¾ç¹5ä½ãè³é1ä¸å
- ã¸ã£ã³ã«å¥ãããè³
- Web Exploitation 1ä½ãè³é1ä¸å
- Pentest 1ä½ãè³é1ä¸å
- Malware Analysis 1ä½ãè³é1ä¸å
- Binary Exploitation 1ä½ãè³é1ä¸å
- Writeupè³ è³é1ä¸å Ã2æ¬ï¼ï¼¦ï¼¦ï¼²ï¼©ã»ãã¥ãªãã£é¸å®1æ¬ãNFLabs.é¸å®1æ¬ï¼
åé¡ãµã¼ãã®æä¾æ¹æ³
Web ExploitationãPentestã¸ã£ã³ã«ã§ã¯æ»æ対象ã®ãµã¼ããå¿ è¦ã§ããæ¨å¹´åæ§ã«ãNFLabs.ã®ç 究éçºé¨ã§éçºãã¦ãããã¬ã¼ãã³ã°ãã©ãããã©ã¼ã ã®æ©è½ãå©ç¨ãã¦ãåå è ãã¨ã«åå¥ã®åé¡ãµã¼ããèµ·åã§ããç°å¢ãæä¾ãã¾ããã
çç±ã¨ãã¦ãããã1ã¤ã®ãµã¼ããè¤æ°ã®åå è ã§å ±æãã¦ããã¨ããµã¼ãã®è¨å®å¤æ´ãç°å¢ãªã»ãããä»ã®äººã¸ãå½±é¿ãä¸ãã¦ãã¾ãããã§ããç¹ã«Pentestã¸ã£ã³ã«ã§ã¯ãµã¼ãã®ç®¡çè 権éåå¾ãã§ãããããããåºç¯å²ã¸å½±é¿ãä¸ããè¨å®å¤æ´ãã§ãã¾ãããã®ãããªå½±é¿ãåå è éã§åé¢ãããããåå¥ã®åé¡ãµã¼ãç°å¢ãæä¾ãã¾ããã
競æå¾ã¢ã³ã±ã¼ãã§ã¯åé¡ãµã¼ãã«ã¤ãã¦ãé«è©ä¾¡ãå¤æ°ããã ãã¾ãããå ¨ä½ã¨ãã¦ãå©ç¨ããããå¿«é©ãªç°å¢ãæä¾ã§ãã¾ããã
競æçµæ
æçµçãªé ä½ã¯ã次ã®ããã«ãªãã¾ããã
- ç·åå¾ç¹1ä½ãkeymoonãã
- ç·åå¾ç¹2ä½ãprime_1019ãã
- ç·åå¾ç¹3ä½ãiwashiiraãã
- ç·åå¾ç¹4ä½ã4equestãã
- ç·åå¾ç¹5ä½ãmoratorium08ãã
ãããã®æ¹ãæ§ã ãªåé¡ã«ãã£ã¬ã³ã¸ãæ£è§£ãã¦ãããéå¶å´ããé©ãã®å£°ãä½åº¦ãä¸ããã¾ããï¼
ã¸ã£ã³ã«å¥ãããè³ã®åè³è ã¯æ¬¡ã®æ¹ã§ãã
- Web Exploitation 1ä½ãkeymoonãã
- Pentest 1ä½ãprime_1019ãã
- Malware Analysis 1ä½ãkeymoonãã
- Binary Exploitation 1ä½ãkeymoonãã
å®åããçè ãé«é£æ度åé¡ã次ã ã«è§£ãã¦ããæ§åãå§å·»ã§ããï¼
Xã§ã競æçµæãçºè¡¨ãã¦ãã¾ãã
å¦çã»ãã¥ãªãã£ã³ã³ãã¹ã FFRI Security x NFLabs. Cybersecurity Challenge 2024
— æ ªå¼ä¼ç¤¾ã¨ãã»ã¨ãã»ã©ãã©ããªã¼ãº (@NFLaboratories) 2024å¹´9æ20æ¥
ðå ¥è³è çºè¡¨
ð¥1ä½ keymoon ãã
ð¥2ä½ prime_1019 ãã
ð¥3ä½ iwashiira ãã
ðï¸4ä½ 4equest ãã
ðï¸5ä½ moratorium08 ãã
ããã§ã¨ããããã¾ãï¼
ãåå ããã ããå¦çã®ã¿ãªããããããã¨ããããã¾ããã
å¦çã»ãã¥ãªãã£ã³ã³ãã¹ãFFRI Security x NFLabs. Cybersecurity Challenge 2024
— æ ªå¼ä¼ç¤¾ã¨ãã»ã¨ãã»ã©ãã©ããªã¼ãº (@NFLaboratories) 2024å¹´9æ20æ¥
ðã¸ã£ã³ã«å¥ãããè³çºè¡¨
Web Exploitation ãããè³ keymoon ãã
Pentest ãããè³ prime1019 ãã
Binary Exploitation ãããè³ keymoon ãã
Malware Analysis ãããè³ keymoon ãã
ããã§ã¨ããããã¾ãð
NFLabs.é¸å®Writeupè³
ããããNFLabs.é¸å®ã®Writeupåè³è ãçºè¡¨ãã¾ããWriteupè³ã¯ãæãç´ æ´ãããWriteupãä½æããã ããæ¹ã¸è´åããè³ã§ãã
ä»å7件ã®Writeupãå¿åããã ãã¾ãããé¸èã®çµæãNFLabs.ããã®Writeupè³ã¯iwashiiraããã¸è´åãã¾ãï¼ããã§ã¨ããããã¾ãï¼
é¸èçç±ã¨ãã¦ãå ¨ã¸ã£ã³ã«ã®åé¡ã«è¨åããã¦ãã¦ã¤ãã³ãã®é°å²æ°ãåãããããã£ãç¹ããPentestã¸ã£ã³ã«ã¸åãã¦åãçµãã«ããã£ã¦ç´°å¿ã®æ³¨æãæã£ã¦ããç¹ãé常ã®CTFã¨å®åã®éãçã¸è¨åãããç¹ãiwashiiraãããé¸ãã çç±ã§ããWriteupãè¨è¿°ããã ããããã¨ããããã¾ããã
åµæ工夫ãåããã¦Writeupè³ãå¿åããã ããä»ã®æ¹ã ããç´¹ä»ãã¾ãï¼é ä¸åï¼ã
- yukichiãã ベイビーらいとあっぷ(FFRI Security x NFLabs. Cybersecurity Challenge For Students 2024) - k_yukichi’s blog
- 4equestãã FFRI Security x NFLabs. Cybersecurity Challenge For Students 2024 writeup - 沈黙は金
- blend-teaãã FFRI Security x NFLabs. Cybersecurity Challenge For Students 2024 Writeup #CTF - Qiita
- kk0128ãã FFRI Security x NFLabs. Cybersecurity Challenge For Students 2024:Writeup #CTF - Qiita
- siro317ãã FFRI Security x NFLabs. Cybersecurity Challenge For Students 2024 writeup #CTF - Qiita
- prime_1019ãã FFRI Security x NFLabs. Cybersecurity Challenge For Students 2024 Writeup #CTF - Qiita
åµæ工夫ã®ä¾ãæããã¨ãä½åè ã®æ³å®è§£æ³ã¨ã¯ç°ãªãæ°ããªæ»ç¥æ¹æ³ã®è§£èª¬ããåç»å½¢å¼ã§ä½¿ç¨ãã¼ã«ã®æä½æé çãå«ãã解説ã試è¡é¯èª¤ãæèéç¨ã詳細ã«è¨è¿°ããéç¨çãå«ã¾ãã¦ãã¾ããä»ã«ããç»åãå¤æ°ç¨ãã¦GUIãã¼ã«ã®è¡¨ç¤ºã示ããã¨ãããã¼ã¸åé ã§è¦åºããè¨å®ãã¦å 容ãåããããããããªã©èªã¿ããããé æ ®ããã¦ããããconnpassãã¼ã¸ã¸è¨åãããã¨ã§èªè ãã¤ãã³ããã¼ã¸ã¸ã¢ã¯ã»ã¹ã§ããããèæ ®ããã¦ãããã¨ãæ§ã ãªå¿é£ãããªããã¦ãã¾ãããWriteupãè¨è¿°ããã ããçæ§ãæ¬å½ã«ãããã¨ããããã¾ããï¼
1ä½åè ã¨ãã¦
çè ã¯ä»åãMalware Analysisã¸ã£ã³ã«ã®Hardåé¡ã¨ãã¦ãWindowsãã«ã¦ã§ã¢ã§ãã使ãããææ³ãç¨ããåé¡ãInfectedããä½åãã¾ãããã¾ãã競æçµäºå¾ã®åé¡è§£èª¬ã§ãåé¡ãã¤ããªèªèº«ãç¨ããææ³ããããã«å¯¾æãã解æææ³ãå½¹ç«ã¤ãã¼ã«çãç´¹ä»ãã¾ããã
åå è ã®ä¸ã«ã¯ãMalware解æãWindowsç¬èªææ³ã®ç¥è¦ãã¾ã æã£ã¦ããªã人ãå¤ãããã¨äºæ³ãã¦ãããããã©ãã»ã©ã®æ£è§£è ãåºããäºæ³ãé£ããã£ãã§ããæçµçã«ãç¡äºã«1åã®æ£è§£è ãåºãæã¯å¬ããæãã¾ãããããã¨åæã«ãä»ã«å¤ãã®åé¡ãããä¸ã§1åã®é£æ度調æ´ãããé£ãããæãç¥ãã¾ããã
ããã§ããåãçµãã§ããã ããæ¹ããçµäºå¾ã®è§£èª¬ãå ã«è©¦ãã¦ããã ããæ¹ã«ãä½ãæ°ããç¥è¦ãæä¾ã§ãã¦ããã°å¹¸ãã§ããã¾ããçµäºå¾ã¢ã³ã±ã¼ãã§ãè¯ãã£ãåé¡ãåå¼·ã«ãªã£ãåé¡ãã¨ãã¦æ票ããã ããæ¹ãè¤æ°ããããé常ã«å±ã¾ããã¾ããã
çµããã«
NFLabs.ã¨ãã¦ã¯2åç®ã®ãFFRIã»ãã¥ãªãã£ã¨ã®ååéå¬ã¨ãã¦ã¯åã®ãã»ãã¥ãªãã£ãã£ã¬ã³ã¸ã³ã³ãã¹ããFFRI Security x NFLabs. Cybersecurity Challenge for Students 2024ããç´¹ä»ãã¾ãããæ¬è¨äºãä»åã®ã³ã³ãã¹ãããã£ããã«ããµã¤ãã¼ã»ãã¥ãªãã£åéã¸ã®ç解ãæ·±ããåã£æããã«ãªãã°å¬ããæãã¾ããã¾ããNFLabs.ãFFRIã»ãã¥ãªãã£ã¸ãèå³ãæã£ã¦ããã ããã°å¹¸ãã§ãã
ã¢ã³ã±ã¼ãã§ã¯ãã¤ãã³ãå ¨ä½ã§é«ãæºè¶³åº¦è©ä¾¡ãããã ãã¦ããããã¤ãã³ã³ãã¹ãå ¨ä½ãéãã¦æ¥½ããããçã®å£°ãå¤æ°ããã ãã¾ãããåæ§ã®æè¡ã¤ãã³ãããä»å¾ãéå¬äºå®ã§ããä»åã®ãªãã³ã¸ãæããããæ¹ãæ¬è¨äºã§èå³ãæã£ãæ¹ãªã©ã¯ã次åã«ãã²ãåå ãã ããï¼