ãã¡ãã®ã¤ãã³ãã«ãããã¾ãã¦ãã¾ããã
https://tktksec.connpass.com/event/330494/
ååããç´9ãæã¶ãã®é«æ§»åãã§ãã
è¬å¸«ã¯AWSã»ãã¥ãªãã£ã¨ãã©ãã®ç¬¬ä¸äººè
ï¼tsumetai-udonããã
2ãæåã®OWASP Kansaiã®BoFãè´è¬ããã¦ããã ãããã
å
æã®è
å¨ã¢ããªã³ã°ãã¤ãã§å°ãä¼è©±ããã¦ããã ãã¾ããã
æè¿ã¯é¢è¥¿ã®ã³ãã¥ããã£ã«åãå
¥ãããã¦ããããã§ãã
ä»åã®é¡æã¯AWSã»ãã¥ãªãã£ã
AWSã»ãã¥ãªãã£ã®ä¸è¬çãªè©±ã®èª¬æã®å¾ãAWSä¸ã«æ§ç¯ãããæ¶ç©ºã®ã·ã¹ãã
ï¼AWSã®è¨å®ã«ããã¤ãä¸åãããï¼ã使ã£ã¦ãã³ãºãªã³ããã¨ããå
容ã§ãã
ããã¡å¸°ã£ã¦ã¬ããã¾ã§ãåå¼·ä¼ã®èãã®ãã¨ã以ä¸ã¡ã¢ã§ãã
æ»æã®å
·ä½çãªæ¹æ³ã¯ãããã«ã¾ããã®ã§ãå½ããéããªãç¯å²ã§ã
座å¦
ãã®è¬ç¿å 容ã¯é常ã¯6ï½8æéã¯ãããï¼AWSãã®ãã®ã«åæããã¡ããã¡ããããæ¬æ¥ã¯ãã®èª¬æãè¡ã£ã¦ããï¼
ãããªãã¯ã¯ã©ã¦ãã®ç¹æ§
- ãªã½ã¼ã¹ã®å¤§è¦æ¨¡ãªã¹ã±ã¼ã«ã容æã§ãã
- ãã¤ãã³ã°ãæ»æè ã®è¸ã¿å°ã¤ã³ãã©æ§ç¯ã¨ãã¦å©ç¨ããã
- ã¯ã©ã¦ãã®ãµã¼ãã¹ã«å¯¾ããæä½ã¯ååAPIçµç±
- æ»æãèªååãããã¨ã容æã§æ¨ªå±éãããã
- ããã©ã«ãã®ç°å¢ã決ãã¦ã»ãã¥ã¢ã§ã¯ãªã
- ããã©ã«ãã§ãã°ã¯åããã¦ãããæå°éãè å¨æ¤ç¥ã¯ããã©ã«ãOFF
- ãªã½ã¼ã¹ã®å¤§è¦æ¨¡ãªã¹ã±ã¼ã«ã容æã§ãã
AWSã»ãã¥ãªãã£ä¸åã§ããåºã¦ãããµã¼ãã¹ï¼IAM, EC2, S3, VPC
ãããã被害
- ã³ã³ã½ã¼ã«ã¸ã®ä¸æ£ãã°ã¤ã³
- S3ã®è¨å®ä¸åã«ãããè¦ããããããªããã®ãè¦ãã¦ãã¾ã
- 第ä¸è
ã«ã¢ã¯ã»ã¹ãã¼ãåããã
- é£çµ¡ãä½ãã§ãã£ãããã¼ã«ã®ãããªãã¯ãã£ã³ãã«ã«è²¼ãä»ãã
- ä¾ï¼ãããã¬ã¼ã·ã§ã³ãã¹ããè¡ãã¨ã10å¹´åã«çºè¡ããããã®ããã£ãããã¼ã«ã«å¼µãä»ãããã¦ãã¦ããã®ãã¼ãä»ã§ã使ããã¦ãã
- ã¢ã¯ã»ã¹ãã¼ãã³ã¼ãçã«åãè¾¼ãã ãã¨ã«æ°ã¥ããã«å ¬éé åã«ç½®ãã¦ãã¾ã
- é£çµ¡ãä½ãã§ãã£ãããã¼ã«ã®ãããªãã¯ãã£ã³ãã«ã«è²¼ãä»ãã
AWSç¹æã®èå¼±æ§ã¨ãªã¹ã¯ã«ã¤ãã¦
- ãã¤ã®éã«ãAWSããæ°ãããµã¼ãã¹ããªãªã¼ã¹ããã¦ã¦ãä»ã¾ã§ã»ãã¥ã¢ã ã£ããã®ããéã«ç©´ã«ãªã£ã¦ãããã¨ããã
ãã³ãºãªã³
- S3ãã±ããã®èª¤å
¬é(è¦ãã¦ã¯ãããªããã¡ã¤ã«ãè¦ãã¦ãã¾ã£ã)
- èå¼±æ§è¨ºæã§ãè¦ã¤ãã¦ãããã¨ããã¨ããã§ãªãã¨ããããã
- 対å¦æ¹æ³
- èª¤å ¬éãæ¤åºã§ããããã«ããï¼AWS Config, CSPMï¼
- CDN
- S3 Presigned URL
- ã¢ã¯ã»ã¹ãã°ã®åå¾ï¼ããã©ã«ãã§ã¯ç¡å¹åããã¦ããï¼
- ã»ãã¥ãªãã£ã°ã«ã¼ã
- Jenkinsããã»ã»ã»
- ã¢ã¯ã»ã¹ãã¼ã®æ¼æ´©
- 対å¦æ¹æ³
- é·æçã«ä½¿ããã¢ã¯ã»ã¹ãã¼ãã§ããã ãæãåºããªã
- æ¼æ´©ããã¢ã¯ã»ã¹ãã¼ã®å©ç¨ã«æ°ã¥ããããã«ããï¼GuardDutyï¼
- æå°æ¨©éã®åå
- 対å¦æ¹æ³
- Server-Side Request Forgery(SSRF)
- åæç¥è
- EC2ã«ã¢ã¿ãããããIAMãã¼ã«
- ã¤ã³ã¹ã¿ã³ã¹ã¡ã¿ãã¼ã¿ãµã¼ãã¹ï¼IMDSï¼
- 対å¦æ¹æ³
- URLã®ããªãã¼ã·ã§ã³
- IMDS v1ã®ç¡å¹åï¼ç¾å¨ã¯æ°è¦ã«EC2ä½ãã¨ç¡å¹åããã¦ãï¼
- æ¢ååã§IMDSv2ã«å¯¾å¿ãã¦ããªãEC2ã§IMDSv1ãç¡å¹åããã¨ã¾ããããããã®å ´åã¯è¦æ¤è¨¼
- ã¢ã¯ã»ã¹ãã¼ã®æ¼æ´©å¯¾ç
- åæç¥è
- CTF
- 1ï½3ã®å 容ã使ã£ãCTF
ãã®ä»ï¼ææ³å«ãï¼
- çµå±ã¯ãé
- AWSã«ãã»ãã¥ãªãã£ãµã¼ãã¹ã¯ãããããããããã®ã«ãã£ã¦ã¯å°ã使ã£ãã ãã§ä¸æ°ã«ãéãæã£ã¦è¡ããããã¨ãããã®ã§è¦ç©ãããé常ã«ãã¥ãã
- CDNã使ãã«ãã¦ããéã¯ããã
- éå»ã«ã©ããã®è¬æ¼ã§ããã®è¾ºãã®ã»ãã¥ãªãã£ã«ããè²»ç¨ããããããªããããªãã¸ãã¹ã§ããã°ããã®ãã¸ãã¹ã¢ãã«èªä½çã£ãæ¹ããããã¨ããã®ãè´ããè¨æ¶ãããããã¾ãã«ãããªãã ãããª
- GuardDutyã¯éæ¤ç¥ã誤æ¤ç¥ãã¡ããã¡ãããã£ã¦ä¸è½ã§ã¯ãªãï¼OWASP Kansaiã§ããã£ãåã§ããï¼
- Control Towerã使ãã¨ã»ãã¥ã¢ãªè¨å®ã楽ã«ã§ãããã©ããªãããè¨å®ãå³ãããã¦ããããããã¨ãéã«ã§ããªããªããã¨ããã
- ã½ãã¼ãã¥ã¼ã¸ãã¯ã®ã«ã¼ãã¢ã¯ã»ã¹ãã¼æ¼æ´©äºä¾
- [ãã³ãºãªã³ä¸] 人åã§IAMããªã·ã¼æ¸ãæãããªãã¦ãã£ãã«ãªãw
- SSRFã®ãã³ãºãªã³ããããããã
- CTFåé¡ãããã¤ãã¯ãªã¢ãããã¹ããã«ã¼ãããã¾ãã
- ãããããã«ãã©ããåºã¦ãã¦ãã»ãã¥ãªãã£ã ãã§ãªããã©ãã®ãã¨ãåå¼·ã§ãã¦ããã¯
- äºå¾ã¢ã³ã±ã¼ãã¯ç´çã¨Webçããããããã®åå¼·ä¼ã«ã¤ãã¦ã¯ææ¸ãã§åºããããªã
- å®å®ã®ããã¤
ã
ã
ï¼æ¦å©åï¼
èé士æç¢ NEXT DIMENSION å¥çç¥è©±ï¼16ï¼
ããããæ¯ããã¶ã£ã¦ï¼37ï¼
ããã®ãã¡ã«ã¯ï¼2ï¼