2012-06-01ãã1ã¶æéã®è¨äºä¸è¦§
ããããã¨è¨äºã¨ãã¦ã¨ãããã¦ããã ãã¦ã¾ãã å¦çã»çå¾å¯¾è±¡ãã»ãã¥ãªãã£ã»ãã£ã³ããã8/15ããå¹å¼µã§ç¡æéå¬ | ãªã»ãã é«åº¦ã»ãã¥ãªãã£æè¡è è²æã®ã»ãã¥ãªãã£ã»ãã£ã³ã2012ãå¿åç· åè¿«ãï¼ã»ãã¥ãªãã£ã»ãã£ã³ã宿½åè°ä¼ï¼ | ScanNetSeâ¦
ã®ã§ããããã¼ã½(´ã¼ï½)ã ãåè°ä¼ãµã¤ããã»ãã¥ãªãã£ã»ãã£ã³ãåè°ä¼ ãFacebookãã»ãã¥ãªãã£ã»ãã£ã³ã - ãã¼ã | ãã§ã¤ã¹ãã㯠ãYouTubeãsecuritycampjapan - YouTube ãTwitterãã»ãã¥ãªãã£ã»ãã£ã³ã (@security_camp) | Twitter ä»å¹´ã¯â¦
éã«ç¾å®ã¨èæ§ã®åºå¥ãã¤ããªãä½é¨è£ ç½®ãç»å ´ - çç ã®ãSRã·ã¹ãã ã | ãã¤ãããã¥ã¼ã¹ ã¨ãã¨ããããªãã®ã¾ã§åºã¦ãããã§ãããæ´å²æ¹å¤SFã¿ããã ãªãã ã¨ãããSFã§ã¯ããªãã¿ã®ä»æãã ãã©ãå®éã«ãã®ä¸ã§ãªã¢ã«ã«çæ´»ãã人ã®åå¿ãã©ããã£â¦
å¿åéå§ã«ã¯éã«åããªãã£ããã©ãç¾å¨ãã£ã³ãã®å 容ã«é¢ãã詳細æ å ±ãå ¬éããã¦ã¾ãã ã»ãã¥ãªãã£ã»ãã£ã³ãä¸å¤®å¤§ä¼2012 ãã§ãå¿åç· ãåãã7æ9æ¥ï¼æï¼ã®17æå¿ çã¨ãããã¨ã§å»¶é·ããã¾ããããã¯ã©ã¹å¥å°éç§ç®æ å ±ãæ´æ°ããã¦ãã®ã§ãå¿åâ¦
ãããªsutegoma2ã¯ããªã§éå¬ãããNuit Du Hackã®CTFã«åæ¦ä¸ãªãã ãã©ãããã°ã£ã¦ãããªãã Nuit du Hack XVI - 30 Juin & 1er Juillet 2018 | NUIT DU HACK 16 ã¡ããåã®Secuinsideã§ã3ä½ã«å ¥ã£ã¦ã¾ãããï¼http://ctf.secuinside.com/status.phpãâ¦
å ¥éæ¸ã¯å¦å®ããªãããåªããå ¥éæ¸ã¯èªãã§ã¦æ¥½ãããããã好ããªãããã ãã©ãããã¾ãå ¥éçãªç«ã¡ä½ç½®ã®æ¸ç±ã°ããã ã¨ã¤ã¾ããã¨æããã ãã©ããæ å ±ã»ãã¥ãªãã£ã®åéã£ã¦å ¥éçãªã¨ããã䏿æãã®ãããåºã¦ãããã©ãã³ã¢ãªã³ã³ãã³ããæ±ãâ¦
ã¨ããã¤ãã³ãã«è¡ããã¨ã«ãã¾ãããæè¿ãã£ããã¤ãã³ãããé ããã£ã¦ããã ãã©ï¼ã¨ãã£ã¦ãããæ°ã¶æãããããªï¼ç¬ï¼ï¼ãæ¸ç±èªä½ããããããã ãã¤ãã³ããããããããããªã¼çã«åºå¼µã£ã¦ããããã¨æãã¾ãã ãBugãã³ã¿ã¼ã¨ããã©ããããWebâ¦
ææ¥æ°å®¿ã§å¦æ ¡èª¬æä¼ã§åãã¾ãã ã19æ¥ã大å¦èª¬æä¼éå¬ä¸ï¼ | éä¿¡å¶å¤§å¦ | ãµã¤ãã¼å¤§å¦ ææ¥ç´¹ä»ãªãã ãã©ã¾ãããã¿ã¨ãã¦ï¼ç¬ï¼ãã»ãã¥ãªãã£åºç¤ã£ã½ã話ã20åãããã
ã¾ããå·å£å çã®é²æãã£ã¦ãã¨ã§ãæéçã«ã¯åºäºæ®µã®ã¨ããã§ç»å£ãã¾ãã®ã§ï¼ç¬ï¼ã ã ããæ å ±ã¯çãããââããããã®æ å ±æ¼ãã対çã¨ã¯ ã100ï¼ ã¯é²ããªãããåæã¨ããã»ãã¥ãªãã£å¯¾ç éå±±ãã¤ã¤ã¢ã³ããã¼ã«ã§19æ¥ã«è¬æ¼ãã¾ãã è³æä½ãã§çãâ¦
æããã®ããªã¹ãã¼ã³ã§ã®è©¦åã ãã2000å¹´ããã©ã¸ã«æ¦ã®ããã«æ»å¨ãããã©ãè¡ä¸ã®ã³ã³ãããã¢ã ã¿ã¤ãã®è¯ãããã«ã§é常ã«è´ æ²¢ãªæéã ã£ãã®ã¨ã海沿ãã®å ¬åã¨ããã¨ã¦ãæ°æã¡ããã£ããã¨ãè¦ãã¦ããªãã ããã¨ããã§ãåå½¢ã®ã¹ã¿ã¸ã¢ã ã£ã¡ã ã¼â¦
ãã£ããåéæéãå»¶é·ããã¦ãã®ã§ãããæ¯å¹´è¨ã£ã¦ããã ãã©ãã®ãªã®ãªå¿åã£ã¦ãªã¹ãã¼ã ããæ¢ãã¦ãããæ¹ãè¯ãã¨æããã¼ï¼ç¬ï¼ãã¡ã¼ã«ãéããªãã¨ããããããããã¾ãããããã ã»ãã¥ãªãã£ã»ãã£ã³ãä¸å¤®å¤§ä¼2012 ã¨ã¯ããããªããªã詳ããâ¦
以åport139ã¹ãã³ãªãçã«ãã£ãåå¼·ä¼ã¯æ¸©æ³ãã¼ã¹ã ã£ããã©ãã»ãã¥æ¸©æ³ã¨ããæ¦å¿µã¯ã©ãããªï¼ç¬ï¼ï¼
審å¤ãæªç®ç«ã¡ãã試åã§ããããæ¥æ¬ã¯ãã¯ãã°ã©ã¦ã³ããæªãã¨ãã®å¯¾å¦åã«èª²é¡ããããã¨ãããã£ã¡ããã¾ãããªãããã¾ã§è¦æ¦ãã¦ããä¾ãè¦ã¦ããã¼ãã¼ãã°ã©ã¦ã³ãã£ã¦ã®ãå¤ãã£ãããããªãããªï¼ãã¹ã¹ãã¼ãå°ãèç ã§ãã¤ã³ã¿ã¼ã»ããçããâ¦
ããæ¬¡ã®è©¦åã§ããªãæ©ããã®ã ã ã¨ã«ãã³ã¨ã¯ç¸æ§ã¨ãããããã®ã¨ãã®ã³ã³ãã£ã·ã§ã³ã¨ãããããããããã®ã§ããããã£ã¨ããã¾ã¾ã§ãã£ããã¨ããæ¦ããã§ãããã¨ããªãã®ã§ãã³ã³ãã£ã·ã§ã³é¢ã§ã¯æªããªãä»åãã©ãããæ¦ããã§ãããæ¥½ãã¿ã§ã¯ãâ¦
http://www.lastfm.jp/passwordsecurity æè¿å¤ãã§ããªãã SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã¨ãã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³çãªæµããªãã ãããã©ãsaltç¡ãã®SHA-1ã¨ããæåãã³ãã£ã¼ç³»IT伿¥ã®ã»ãã¥ãªãã£ã®å¼±ãã£ãããªãããï½ãä»çµã¿ãããã¼ãã¦ããå³å¿æ§ãâ¦
ãã°ãããçµæã§ããã ååã¯å 容ã§ãå§åãã¦ã¾ãããªãããããããã¤ãã¦ãããªãã¨ãããããã¼ãã·ã§ã³ã§ãå§åããããããªãã®ããªï¼ã¨ã«ãã³ãããã«ãµã¨å¯¾å³ãããã¼ã ã¿ããã«ã©ãã©ãä½åãå¸ãåããã¦ãã£ã¦ãæ¥æ¬ã®æ»æã®ç·´ç¿ã¿ããã ã£ããâ¦
ãã¹ã¯ã¼ããæ¼æ´©ãã¦ãã¾ã£ãããã§ããªã LinkedInã®ãã¹ã¯ã¼ã650ä¸äººåãæ¼æ´©ã®ããããã¢ãããã¼ãï¼è¢«å®³ã¢ã«ã¦ã³ãã®ãã¹ã¯ã¼ãã¯å¼·å¶å¤æ´ã¸ã | TechCrunch Japan An Update on LinkedIn Member Passwords Compromised | Official LinkedIn Blog ãâ¦
Googleããå½å®¶ã徿¼ãããæ»æãã«ã¤ãã¦Gmailã¦ã¼ã¶ã¼ã«è¦å - ITmedia ã¨ã³ã¿ã¼ãã©ã¤ãº æè¿ã°ã¼ã°ã«ã£ã¦ä»®æ³æµå½ã¨ããããããããã®ãè¨å®ãã¦ãã£ã½ããã©ãããã ãããããæ¥ã¦ãã£ã¦ãã¨ãªãã§ãããããã¡ã¼ã«ã¢ã«ã¦ã³ãã®è©±ã¯JPCERTã«ããããâ¦
ããããã°ãåææ¥ã«åæããã¦æ¥ææ¥ã«æ²è¼ããã¾ããï¼æ±äº¬æ°èã å®è£½CTFã«é¢ãã¦ã®ã³ã¡ã³ãã¨ãããã¨ã«ãªã£ã¦ã¾ããããå®éã«ã¯CTFã®æ´å²ãè»½ãæ¯ãè¿ã£ãããã¡ãªãããæè²å¹æãªã©ã«ã¤ãã¦èªã£ãããã¾ãããã¼ã
ãµãã«ã¼çã¦è¨ãã°å±±æ¬"人éå"æé¦ã ããï¼ç¬ï¼ã ã ããæ å ±ã¯çãããââããããã®æ å ±æ¼ãã対çã¨ã¯ ã100ï¼ ã¯é²ããªãããåæã¨ããã»ãã¥ãªãã£å¯¾ç ã¾ã ä¸èº«ãã£ããæ±ºã¾ã£ã¦ãªãæãã§ãµããµããã¦ããã©è¬æ¼ãã¾ãã¼ããããããã
IDA Disassembler and Debuggerãèªå®è²©å£²ãµã¤ãã ããããã®ã¤ã¶ããã§ãµã¨è¦ã¦ã¿ãããæã¡æ¶ãç·ä»ãã ã¨å®ããªã£ã¦ãæãããã©ãåé«ã ããããä¸çªå®ãã©ã¤ã»ã³ã¹ã§9000åãããå¤ä¸ãããã¦ãã¿ããã§ãããã£ã¦ã»ãã¨ããªï¼ç¬ï¼ãåã®å¤æ®µè¦ãã¦ãªâ¦
ãã¤ã³ãåãã¦ãã®ã¾ãã¾ã«ãã¦ãããã¨1å¹´åãä¹ ãã¶ãã«ææãã©ã³ã«å¾©å¸°ãã¦ã¿ã¾ããã ãã®ããã°ããã£ããéçã£ã¦ãæãã ãã©ãã¾ãã¼ã¡ã¼ã¡è¡ãã¾ãããã ãã£ã¨ä¸æ¯åçè²¼ããããªã£ãã®ã§å¾©å¸°ãããã ãã©ãã·ã£ã¼ããã«æ¬ ããããããããããâ¦
ã¾ã èªã¿çµãã£ã¦ããªãã©ããããååãããã¨ããã®æåã®æ¹ã ãã©ããããããæ¬ã®äºæããã¦ããè²§ä¹äººã®çµæ¸å¦ââãããã¡ã©è²§å°åé¡ãæ ¹ã£ãããèããä½è : ã¢ãã¸ããã»Vã»ããã¸ã¼,ã¨ã¹ãã«ã»ãã¥ãã,山形浩çåºç社/ã¡ã¼ã«ã¼: ã¿ããæ¸æ¿çºå£²æ¥: 2â¦
念ãéãã¾ããããå¼ã¹ã¿ã§ã§ã£ããå æ°çä½ããããã«ã
ã¨ããæ å ±ãæ±ãããããã¨ãå¤ããªãä½ã ãã ã©ããã§ã¾ã¨ãã¦è¨äºã«ãããã¼çãªãä»åº¦éå¬ãããäºå®ã®å®è£½CTFã ãã©ãã¡ãã£ã¢ã¨ãã®æ³¨ç®ãéã¾ã£ã¦ãã¿ããã§ãããCTFã¨ããããã«è¿ãã¤ãã³ããå¢ãã¦ãã¦è¯ãæãã ã¨æããã ãã©ãåºå ´ãã人ãã¡â¦
ä¸ããä¸çªç®ã®ã¹ã³ã¢ã ä¸åè§£ãã¨å¤§ããé ä½ãå¤ããå£åå±éããªãã ããã°ãsutegoma2ã
åèµ°æä¸ä½ã«æ²ãã§ã©ããªããã¨ãã¨æã£ããã©ãçãéã«ããªãç«ã¦ç´ãã¦ãã¦ãããªãã åã£ã馬ãã¬ã³ã¼ãåã¡ããããããã¤ãã¼ã¹ã ã£ãã®ã§ãå è¡ãã¦ç²ãã¿ã¤ãã®ã¦ãã®é¦¬ã«ã¯ãããã£ããã©ã4ã³ã¼ãã¼ããæãããããã¾ã§ã¯è¦ãå ´ã¯ä½ã£ã¦ãããâ¦
ããæè¿ä»£è¡¨ã¯ããã¨ãã¼ã ã§ã¯è¦æ¦ããããæµ·å¤çµãå¢ãã¦éã¾ã£ã¦ä½ãããç¿ç度ã¿ãããªãã®ããªããªãå¢ãããªãããå人ã®è½åã®é«ãã§ä½ã¨ãåã¤ãã¿ãããªå´é¢ãç¡ãã¨ããããè¦ããããã åã¢ããªã«äºé¸ã®ã¨ãã¯ä¸æä¿è¼ã®ããªã¼ããã¯ã¨ããã¨ã¼â¦
ã«ã°ã¨ã³ã®ãªãã¼ã³ä»£è¡¨ã¯æ¥æ¬ä»£è¡¨ã¨ãã¿åãããããã¼ã ã ã£ããªã¼ãã©ã¤ã³é«ããåããã¼ã ãæ¥æ¬ã¯ãããããã¼ã ã¨ããã¨å¼·ããããæéçã«ã¯è¯ããã©ã³ã¹ã§å¾ç¹ãéãã¦å¿«åã§ããããã§ã ä»åã¯å®åãè¯ãã£ããªã¼ãã¾ããã¿åããããã¨ããã®ããâ¦
ç¾å¨3ä½ãã¾ã ã¾ã æéãããã©ãææ¥æã¾ã§ããªã ã¡ãã£ã¨å¤ä¸ã®ç¹æ°æ¨ç§»ç®ãé¢ããªãã§ãããä»ãªã¼ãã³ããã¦ããã®ã¯5000ç¹ã ãã©ãsutegoma2ã¯3600ç¹ãäºä½PPPã¨200ç¹å·®ããã4000ç¹å°ã«æ©ãä¹ãããã¨ããã ãã©ãã¼ã ããã°ãsutegoma2ï¼ åç¹3ä½ã§â¦