ã¯ããã«
ã¿ãªãã¾ããã«ã¡ã¯ãNFLabs. ã® @strinsert1Na ã¨é»å·ã§ãããã®åº¦ãæ ªå¼ä¼ç¤¾ã¨ãã»ã¨ãã»ã©ãã©ããªã¼ãºã¯ 2023年度 UEC Bug Bounty ã«åè³ããé»é大(UEC) ã®OBã§ããçè ãã¨CTOã®3åã表彰å¼ã«åå ãã¦ãã¾ããã
å½ç¤¾ã¯ãé»æ°é信大å¦ã«ããã¦å®æ½ãããå¦çã«ãã
— æ ªå¼ä¼ç¤¾ã¨ãã»ã¨ãã»ã©ãã©ããªã¼ãº (@NFLaboratories) 2024å¹´1æ29æ¥
å¦å æ å ±ã»ãã¥ãªãã£æ¤æ»ã³ã³ãã¹ããUEC Bug Bounty 2023(2024/2/1-2/29éå¬ã3/15表彰å¼)ãã«åè³ãã¾ããhttps://t.co/xxCjTPq9R4
ç¹å¥è³ã¨ãã¦NFLabs.è³ãæä¾ãã審æ»å¡ã¨ãã¦åå äºå®ã§ãã
æ¬æ稿ã§ã¯ãã¤ãã³ãã®ææ³ã表彰å¼ã®æ§åãç´¹ä»ãããã¨æãã¾ãã
UEC Bug Bounty ã¨ã¯
UECãã°ãã¦ã³ãã£ã¯ãé»æ°é信大å¦(The University of Electro-Communications)ã®å¦å æ å ±ã·ã¹ãã ã対象ã¨ããå¦çã«ãããã¯ã¤ããããã³ã°ãã£ã¬ã³ã¸å¤§ä¼ã§ãã2019å¹´ããå§ã¾ããä»å¹´ã§ç¬¬5åç®ã®éå¬ã¨ãªãããã§ããé»é大ã®å¦çããèªãã®å¤§å¦ã®ã·ã¹ãã ãæ¤æ»ããèå¼±æ§ï¼ãã°ï¼ãè¦ã¤ããåé¡ç¹ã¨æ¹åæ¡ãã¬ãã¼ãã£ã³ã°ãããã¨ã§å ±å¥¨éï¼ãã¦ã³ãã£ï¼ãå¾ããã¨ããç¾å®ã®ãã°ãã¦ã³ãã£ã®æµããå¦ã¹ãé常ã«ææ¦çãªã¤ãã³ãã¨ãªã£ã¦ãã¾ãã
ã¤ãã³ãã®ã¹ã±ã¸ã¥ã¼ã«ã¯ä¸è¡¨ã®ã¨ããã§ããå®éã«ãã°ãã¦ã³ãã£ã«ææ¦ã§ããæéã¯ç´1ã¶æã¨çãã§ã¯ããã¾ãããäºåã«å¤§å¦å´ãããã°ãã¦ã³ãã£ã§ä½¿ãããã¼ã«ã®ç´¹ä»ããªãã§ã³ã·ãã»ãã¥ãªãã£ã«é¢ããç¥èããã³å«çã«é¢ããè¬ç¿ãè¡ãããããã§ãåå¿è ã¸ã®ãµãã¼ããé常ã«æåããªã£ã¦ãã¾ãã
ã¹ã±ã¸ã¥ã¼ã« | |
---|---|
2024/1/29 ~ 2/22 | ãã°ãã¦ã³ãã£ã®ç ä¿®ã¨å®æ½ã®ããã®èªå®è©¦é¨ |
2024/2/1 ~ 2/29 | å¦çã«ããæ¤æ»æé |
2024/3/15 | è¡¨å½°å¼ |
ãã®ä¸æ¹ã§ç¾å®ã«ç¨¼åãã¦ããå¦å
ã·ã¹ãã ã対象ã¨ãã¦ããé½åä¸ãæ£ããç¥èã¨å«ç観ãæã¤å¦çã ããåå ã§ãããããªèªå®å¶åº¦ãå°å
¥ããã¦ãããèªå®è©¦é¨ã«åæ ¼ããªããã°æ¬ã¤ãã³ãã«ã¯åå ã§ããªãä»çµã¿ã«ãªã£ã¦ããããã§ããä»åã¯8ãã¼ã ãèªå®è©¦é¨ã«åæ ¼ãããã°ãã¦ã³ãã£ã«ææ¦ãã¾ããã
å¦çã®ææå ±åãè¦ã¦
ã¾ããæ¬ã¤ãã³ãã«åå ãã8ãã¼ã ãèå¼±æ§ãçºè¦ããã¬ãã¼ãã£ã³ã°ã¾ã§ã§ãã¦ããã¨ããäºå®ã«é©ãã¾ãããã»ãã¥ãªãã£ã®æ¦å¿µã浸éãã¦ããæ¨ä»ãè¬ç¾©ã§ç¿ã£ãç¨åº¦ã®èå¼±æ§è¨ºæãã¼ã«ãã³ãã³ãã§ã¯ç°¡åã«èå¼±æ§ãªãã¦è¦ã¤ããã¾ããããæ§ã ãªä»®èª¬æ¤è¨¼ããã¨ã«èå¼±æ§ãçºè¦ããæªç¨å¯è½æ§ã¾ã§æ¤è¨¼ãã¦ãããã¼ã ãè¤æ°åå¨ãã¦ããã®ã¯é常ã«ã¬ãã«ãé«ãã§ããç´ç²ã«ä¸äººã®ã¨ã³ã¸ãã¢ã¨ãã¦ãããã¸ãåå¼·ã«ãªãã¾ããã
ç¹ã«ãä»ã¤ãã³ãã®æåªç§ããã³NFLabs.è³*1ãåè³ãããã¼ã ãPaper_Testerð»ãã¯ãæ ç»ããã©ãã§å¤ãã®äººãæãæããThe ããã«ã¼ãã®ãããªä¾µå ¥çµè·¯ãçºè¦ããã¨ã¨ãã«ã¬ãã¼ãã£ã³ã°ã®è¦³ç¹ãç´ æ´ããããä¸ä¼æ¥ã«ããèå¼±æ§è¨ºæã¬ãã¼ãã¨å·®ãæ¯ããªãã¬ãã«ã ã£ãã¨è©ä¾¡ãã¦ãã¾ãã

ãã®ä»ã«ãè¨å®ä¸åãè¶³å ´ã¨ã㦠root shell ã¾ã§åå¾ããåªç§è³ãã¼ã ã®å ±åãªã©ãããã¾ããããæ親ä¼ã§ã話ãããã¨ããåªç§è³ãç²å¾ãã2ãã¼ã ã¯å ¨å¡ãå¦é¨çã§æ§æããã¦ããã¨ç¥ãå¦çã®ã¬ãã«ã®é«ãã«ã¯æ¹ãã¦é©ãã¾ããã*2 æ親ä¼ãéãã¦å¦çãã¡ã®å¦ã³ãèããã¨ãã§ããã¨ã¨ãã«ãçè ãèªèº«ã大ããªåºæ¿ãå¾ããã¨ãã§ããããã¸ãè²´éãªæ©ä¼ã«ãªã£ãã¨æãã¾ãã
æ¬ã¤ãã³ããéããå ¨ä½çãªææ³
æ¬ã¤ãã³ããéãã¦ã»ãã¥ãªãã£ã«ç²¾éããåªç§ãªå¦çãã¡ã¨åºä¼ããã¨ãã§ãã¾ããããããã¨åæã«ä¸»å¬ã§ããé»æ°é信大å¦ãããã»ãã¥ãªãã£äººæè²æã«å¯¾ãã¦é常ã«çæ¯ã«åãçµãã§ãããã¨ãæãåãã¾ãããã¤ãã³ãå ã§ãã»ãã¥ãªãã£ã«å¤§ããæè³ãããã¨ã¯é£ãããã¨ã¯è©±ããªããããå¾æ¥ã®å¢çé²å¾¡ããè±å´ãã¦ã»ãã¥ãªãã£ãåä¸ããªããã°ãªããªããã¨ãã課é¡èªèãè¿°ã¹ããã¦ããããã®ä¸ç°ã¨ãã¦ãã°ãã¦ã³ãã£ãå ¨å¦ã·ã¹ãã ã«å¯¾ãã¦è¡ãã¨ããã®ã¯çã«éè¦æ§ãç解ãã¦ããªãã¨ã§ãããã¨ã§ã¯ããã¾ããã*3ããã¦ãå¦çã«å¯¾ããæ¯æ´ãé常ã«æåããçè ããèããä¸ã§ã
- ç¿æ¥ã«ææ¥ã§ä½¿ããããµã¼ãã¼ãDoSã§è½ã¨ãã¦ãã¾ã£ãå¦çããããã©é ããªãã«æãã復æ§ï¼
- ãå¦çã ã£ãã失æãã¦ããªãã¼ããä½ç¾ãã対å¿
- æ¬ã¤ãã³ãã§çºè¦ããã¡ã¸ã£ã¼ãªã¡ã¼ã«ã»ãã¥ãªãã£è£½åã®èå¼±æ§ãIPAã«å ±åãå¦çãJVNãåå¾ããã¾ã§ãµãã¼ã
- æ¬ã¤ãã³ãã«åå ããå¦çã¯åè³ã¾ã§ãããªãã¨ãã¬ãã¼ãã£ã³ã°ã§ããã ãã§ããã¦ã³ãã£
- ãªã®ã§ãã©ãã©ãåå ããã!!
ãªã©ãªã©é©ã話ããããããããå¦çãç©æ¥µçã«ã»ãã¥ãªãã£ã¤ãã³ãã¸åå ãã¦ããããããªåå£ãé¸æããã¦ããã¨æãã¾ãããæ£ç´ããã¾ã§ãè³ç«ã¦ããã¦ãããã°ãã¦ã³ãã£ã¤ãã³ãã¯èãããã¨ããªãããããããé»æ°é信大å¦ã®å¦çãã¡ãã©ãã©ãæé·ããã¨åæã«ããã°ãã¦ã³ãã£å°å
¥ã«ããè²»ç¨å¯¾å¹æã®é«ãã»ãã¥ãªãã£æ¦ç¥ã¢ãã«ã®ä¸ã¤ã®æåä¾ã«ãªã£ã¦ã»ããã¨åã«é¡ãã¾ãã
ãããã«
UEC Bug Bounty ã®æ§åããä¸åè³ä¼æ¥ç®ç·ã§ç´¹ä»ãã¾ãããå°æ¥ææãªå¦çãã¡ã«å°ãã§ãéå ã§ãããã®ãããã°ãé»é大ãåæ¥ãã1人ã®OBã¨ãã¦ã¯ããã¸ãåã°ããéãã§ãã
NFLabs. ã¯ãããããæ¥æ¬ã®ã»ãã¥ãªãã£äººæè²æã«è²¢ç®ãã¦ããæåã§ããä¸ç·ã«åã仲éãéæåéä¸ã§ãã®ã§ãæ¬æ稿ã«å ±æãã¦ããã ããæ¹ã®ãå¿åããã²ãå¾ ã¡ãã¦ãã¾ããããã§ã¯ð
*1:åè³ä¼æ¥ãæãåªãã¦ããå ±åã«è´ãç¹å¥è³ã§ã
*2:root ã¾ã§åå¾ãããã¼ã ã¯ãã¡ãã Boot2Root ç³»ã®ãã£ã¬ã³ã¸ãçµé¨ãã¦ãããã®ã¨æã£ã¦ãã¾ãããããã§ã¯ãªãã£ãããã§ããHackTheBox ã¨ããã£ã¦ãªãã¦ããroot ã奪ããã£ã¦ããä¸ã¤ã®å°éç¹ãç¥ã£ã¦ãããã ......ãã¨æåãã¾ãã
*3:ã¤ãã³ãèªä½ã¯2019å¹´ããå§ã¾ãå½åã¯ãã°ãã¦ã³ãã£ã®å¯¾è±¡ã¨ãªã£ã¦ããã·ã¹ãã ãéããã¦ããããã§ããã大å¦å´ã§ååãå¼ã³ããç¶ã第5åã¨ãªã£ãç¾å¨ã§ã¯å ¨å¦ã®ã·ã¹ãã ããã°ãã¦ã³ãã£ã®å¯¾è±¡ã¨ãªã£ã¦ããããã§ãã