SECCON2013å ¨å½å¤§ä¼ã«åºå ´ãã¾ãã
SECCONå ¨å½å¤§ä¼ã«åºå ´ãã¦ãã¾ããã
ã¨ãããã¨ã§ç§ã解ããã¨ãã§ããåé¡ã®Writeupããããã¨æãã¾ãã
ä»åãç§ãåçãæåºããåé¡ã¯0åã§ããã
以ä¸ãæåºããåé¡ã®Writeupã§ãã
ã»
ã»
ã»
ã»
ã»
ã»
ã»
ã»ã»ã»ã¨ããåè«ã¯ãã¦ããã
SECCON2013å ¨å½å¤§ä¼ã«åºå ´ãã¦ãã¾ããï¼
in æ±äº¬é»æ©å¤§å¦ãä¼å ´ã大å¦èªä½ãããããã¬ã¤ã§ããããç§å¤§ã ãªãã¨ã»ã»ã»ç¾¨ã¾ãããé§ ã«ãè¿ããå¨ãã¯è²ã ãªãã®ããããããå ´æã§ãã
å°æ¹å¤§ä¼ã§ã¯Jeopadyæ¹å¼ï¼åé¡ã解ãã¦FLAGãæã«å ¥ããï¼ã§ãããæ¬æ¦ã§ã¯æ»é²æ¦ãèªåã®ãã¼ã ã®FLAGãæ¸ãè¾¼ã¿ç¶ããã°ãã®åç¹æ°ã©ãã©ãå¢ãã¦ããæãã§ãã
åºå ´ãã¼ã ã¯å°æ¹å¤§ä¼ã¨Onlineäºé¸ãééãã強豪ã°ãããä¼å ´ã®é¡ã¶ãããããã
ãããªãããã§æã¿ã¾ãããMacBook Airã¨dynabook(Win8.1)ãã¡ã¤ã³ã§ä½¿ç¨ããã®ã¯MBAã§ãã
åãã¼ã ã®ãã¼ãã«ã«ã¯ã«ã¼ã¿ã¼ã¨ã³ã³ã»ã³ãï¼3ã¤ï¼ããããããã«æ¥ç¶ãã¦åé¡ãµã¼ãã¼ã«æ¥ç¶ããã¨ãã£ãæãã«ãªã£ã¦ã¾ãããï¼http://2013.seccon.jp/seccon2013finalchallenge.htmlï¼
å¨ãã¯ææ £ããæ§åã§çã ã¨ç¨æãé²ãã¦ã¾ãããï¼ãããï¼
ä¼å ´ã¢ãã¿ã«ã¯ãããã¯ã¼ã¯å¯è¦åã·ã¹ãã ãNIRVANAæ¹ãåãã¦ãã¾ãããï¼åçæ®ãå¿ãã¦ãããããï¼
ã¤ã¡ã¼ã¸ã¯http://www.nict.go.jp/info/topics/2014/02/140228-1.htmlãã
ãã£ãããï¼ï¼ãã±ããã®é£ã³ããããããããããã£ãã§ãã
nmapã§ã¹ãã£ã³ãããããã¨ããã±ããã®ç¹ããºã©ã¼ã£ã¨é£ãªã£ã¦é£ãã§è¡ãæ§åãè¦ã¦åãã¾ããTCP, UDPã©ã¡ãããããããã«ãªã£ã¦ããã¿ããã§ããç§ã®å®¶ã«ã欲ãããªãï¼ï¼ï½
é£ã®ãã¼ã ã¸ã®ãã±ããã表示ãããã®ã§éå¶å´ã¯ä¸æ£è¡çºãè¦ã¤ããããï¼ï¼ï¼ã®ã§é常ã«è¯ãã·ã¹ãã ã ã¨æãã¾ããä¸ã®äººã¨ã軽ãã話ããã¦ãããã¾ãããããã®ã·ã¹ãã ãä½ãã®ã«é常ã«è¦å´ããããã§ã»ã»ã»ã
競æè å´ããã®NIRVANAæ¹ã¸ã®æè¦ã»è¦ç¹ãåèã«ãããã¨ãã£ããã£ã¦ã¾ãããï¼ãã ç§ã¯ç«¶æã«éä¸ãã¦ããã®ã§NIRVANAæ¹ãè¦ãä½è£ããã¾ãããã¾ããã§ãããä¸åº¦è¦³å®¢å´ããã©ããªæããè¦ãããã®ã§ãï¼
åé¡ã解ããææ³ãªã©
ç§ã¯åå ã¯ãããã®ã®ãKeyæåºã¾ã§ã«ã¯è³ããWriteupãæ¸ã人権ããªãã®ã§ããï¼è¶³å¼ã£å¼µã£ã¦ãã¾ãé常ã«ç³ã訳ãªãã§ãï¼æ°ã¥ããç¹ãªã©ãã¡ã¢ãã¦ããã¾ãã
次ååå ã§ããã°ä»åã®å ¨å½å¤§ä¼ã®çµé¨ãæ´»ããã¦ç¹æ°ç²å¾ããããªã
åé¡ã«ã¤ãã¦
äºé¸ã¨éããä¸ããããåé¡ã¯å®éã®æ»æã«è¿ãå½¢ã§ä¸ããããã®ã§ããã¼ãã³ãã§ããåé¡ãã¿ã¤ãã«ãªã©ãä¸ããããªããããåé¡ãµã¼ãã¼ã«æ¥ç¶ããã ãã§ã¯ã©ã®ã¸ã£ã³ã«ãªã®ããåãããªãç¶æ ã§ããã
ã¾ãã復å·åé¡ã大åã§ããªããªãåã£æãããè¦ã¤ãããã¨ãé£ããã£ãã§ãã
ãã£ããã¨ãªã©ç°¡åã«æ¸ãã¾ããWriteupã§ã¯ãªãã®ã§ã解æ³ãã»ããæ¹ã¯ä»ã®ãµã¤ããè¦ãã¨ããã§ãã
karin.tower
Webç³»ã®åé¡ãã¯ããã¼ãè¦ããããåå¾ã§ãããã£ã¬ã¯ããªãæ¢ãã¾ãã£ã¦ãã¾ãããããªã«ã解ãã¾ããã§ããã
ãã©ã¼ã ã«è²ã å ¥ãã¦ãMailaddressã®å ¥åãã©ã¼ã ã«XSSã§ãããã¨ããããã¾ãããããã ãã§ãããã¨ããã®ãã/image/ã®ä¸ã«ãcaptchaSt1.cgiãKey.jpg, Key2.jpg, /nothinghereãã£ã¬ã¯ããªãªã©æå³æ·±ãªãã®ã大éã«ãã£ãã®ã§ããã®è§£æãéç¹çã«ãã£ã¦ãã¾ã£ãã®ã§ããã
Adminãã¼ã¸ããããã¨ã¨ãCookieã«CGIã®SESSIONIDããã£ãã®ã§ãã©ããã§ä½¿ãã®ã ããã¨èãã¦ããã®ã§ãããXSSã§Adminã®SESSIDã奪ããªã©ã¨ããäºã¯èãã¦ãè¦ãªãã£ãã§ããçµãã£ããã¨ã«èãã¦ã¿ãã°ã確ãã«ç®¡ç人ã«å¯¾ãã¦ã¡ã¼ã«ãéããã©ã¼ã ã§ãããããAdminã®SESSIDãXSSã§å¥ªããããªãã
ããã解ããªãã¨æ¬¡ã«è¡ãã®ã¯ç¡çã¿ãããªã®ã§ã解ãããã¼ã ã¯ã©ãã©ãKeyãç²å¾ãã¦ãéã«è§£ããªãã£ããã¼ã ã¯å ¨ç¶å¾ç¹ãå¾ããã¨ãåºæ¥ãªãã¨ãããã¨ã«ãæããã
2.kaku.tower
é天é£ã¿ã¯ã¼ãã©ããªåé¡ãå¿ãããã¦ãç¨åº¦ã«ã¯æã足ãåºãªãã£ããã¤ããªç³»ã®åé¡ã
ã·ã§ã«ã³ã¼ãããã«ã ãã«ã ããåé¡ã¿ããã§ãããã¤ããªç³»ã¯å ¨ãããããªãã®ã§æãã¾ããã
ãã¤ããªãåå¼·ããäºå®ãªã®ã§ãåé¡æ¥ãã解ããããã«ãªããããªã
Pisa.tower
ããµã®æå¡ãæ²ç¤ºæ¿ã®åé¡ãhattoriãããã¤ãã£ããããã
æ²ç¤ºæ¿ã«ãã©ã°ãæ¸ãè¾¼ãã¨å¾ç¹ãå¢ãã¦ãã模æ§ãã¨ãããããããã試ãã¦ã¿ã¦ããã¾ãããããããã
éä¸ããXSSã§ãã¤ã¢ãã°ã§ãããå¼·å¶ãªãã¤ã¬ã¯ãããããã
å¤åèªååããã°ç¹ã¯å ¥ãã ããã¨æã£ã¦ãæã£ãã ãã§ãããâããããã®ãã¡ã§ãã
ãã£ã±ããããªãã¨ãã¡ã ã¨ãããã¨ãæãç¥ãããã¾ãããçµå±ããããããªãã£ããããã§å¾ç¹ã伸ã³ãã
captchaã®èªååãã©ãããã®ã ãããï¼ã¨æã£ãã®ã§ãããå®ã¯Captchaãè¦ãªãã¨ãã¼ãå¤ãããªãã¿ãããæ°ä»ããªãã£ãã
Druaga.tower
ãããã3åã¯ä¸æ¥ç®ã®æå¾ã«è¿½å ããããã®ã
ã¨ããããè½ã¨ãå§ããã®ã§ãããåç·ã¯å¤§æ··ä¹±ã80MBã®ãã¡ã¤ã«ãã¦ã³ãã¼ãã«14kb/sã¨ãç¡çã ãï¼
ã®ãªã®ãªã¾ã§ç²ãã¾ããããçµå±ãã¦ã³ãã¼ãã§ãããè½ã¨ãããã¼ã ã¯ãäºæ¥ç®ã®ã¯ããã«å³æåºã§ããã¿ãããã¤ããã
Passwordã¯ãã§ã«ä¸ãããã¦ããã®ã§TrueCryptã§ãã¦ã³ãããã¨Keyãçºè¦ã
ãã®å¾ã¯ã5ã¤ã®ãã£ã¬ã¯ããªã®ä¸ã«100ã®ãã£ã¬ã¯ããªãããããã®ä¸ã«100ã®ãã£ã¬ã¯ããªãããããã®ä¸ã«taka.jpgãããããå ¥ã£ã¦ãã¦ããã®ãã¡ã¤ã«ã¯ããããéãã¢ã»ã³ãã©çæãæ¸ããã¦ããããããè© ãã§ã0609ãåºåã§ãããã®ãæ¢ãã¨ãããã®ã
OCRãæãã¦ãã²ãããå®è¡ããã°åºãã ããã¨æã£ãã®ã§ãããã¢ã»ã³ãã©çæã®å®è¡æ¹æ³ãããããã
ãã¤ããªåå¼·ããã°ã»ã»ã»
Babel.tower
ããã«ã®å¡ã2ã¤ã®pureserverã¨jamserverã¨ããååã®ãã¤ããªãã¡ã¤ã«ãããããå¥ã®ãã¼ãã§åãã¦ãããããã«ãã®ãã¡ã¤ã«ãããããã
jamserverã®æ¹ã¯ãã¡ã³ãã¼ããã©ã¦ã¶ãããã®ãã¼ãã«ã¢ã¯ã»ã¹ããã¨ãã¼ãåºããã¨ãçºè¦ã
pureserverã®æ¹ã¯ããã©ã¼ãããã¹ããªã³ã°æ»æã ã¨ãããã¨ã¯ããã«ããã£ãã®ã§ããããã£ã±ããã¤ããªã¯(´ã»Ïã»ï½)
han01.tower
ãã°ã¤ã³ãã©ã¼ã ã¨ããã¤ã®å¡ã®Gifã¢ãã¡ããããæ´ã«id.txtãpass.txtã¸ã®ãªã³ã¯ãæãã
id.txtã®æ¹ãã¯ãªãã¯ããã¨ãdaemonã¨backupã¨æ¸ããããã¡ã¤ã«ããURLãã¿ãã¨
[bash]
http://han01.tower/readfile.php?filename=id.txt&accesscode=1bc29b36f623ba82aaf6724fd3b16718
[/bash]
ã¨ãªã£ã¦ãããaccesscodeã¯MD5ã§ããã·ã¥ããã¦ãã£ã½ããä½ã®ããã·ã¥ãªãã ããï¼ã¨æã£ã¦ãã¨ã¡ã³ãã¼ã®æ¹ãfilenameã®ããã·ã¥ã ãï¼ã¨æãã¦ãããããã£ã¦ã¿ãã¨ãããã«ããã ã
pass.txtãè¦ããããªï¼ã¨æã£ã¦ãã£ã¦ã¿ããè¦ãããdaemonã¨backupã®å¾ã«shaï½ï¼1ãªã®ã512æ¥ã¯å¿ããï¼ã®ããã·ã¥ãããã ããçµå±ããããã
readfileã§ã¯ãªãã§ãèªã¿è¾¼ãããã ã£ãã®ã§ãreadfile.phpãèªã¾ããã¨èªãããããã«index.htmlãèªãã¦ãããã«ã¯keyãããã¾ãããï¼ãã§ã«æåºæ¸ã¿ï¼
ä¸æ¥ç®ã¯ããã§çµäºãå¾ã®è©±ãåãã®æã«ãã¡ã³ãã¼ããããããã¤ã®ç»åã«IPã¢ãã¬ã¹ã¿ãããªã®ãããããã¨ã
äºæ¥ç®ã«è©¦ãã«DNSã«åãåããã¦ã¿ã¾ãããããããããçµããéã«å¥ã®ãµã¼ãã¼ãããã¨ãããã¨ãå¤æããã®ã§ã2ã¤ãã®ããã¤ã®å¡ã®ãµã¼ãã¼ã«ã¢ã¯ã»ã¹ããã¦è¦ãã¨åããããªWebãµã¤ãããåãããã«readfileã«èªã¾ãã¦ã¿ãã¨åããããªæãã«ã
ãã ä»åã¯å°ãéã£ã¦ãmenuã¨ãããã¡ã¤ã«ããããã¨ãreadfile.phpããããã£ããindex.htmlãèªãã¨ãã¹ã¯ã¼ãã¯/bin/menuã®md5ã ãï¼ã£ã¦æ¸ãã¦ãã£ãã®ã§ãreadfile.phpã«menuãèªã¾ããã¨base64ã§ã¨ã³ã³ã¼ããããæåããã£ããã³ãããã¦ãPythonã§base64ããã³ã¼ããã¦ãåºã¦ãããã¤ããªãä¿åã
fileã³ãã³ãã§è¦ã¦ã¿ãã¨SysExãã¡ã¤ã«ã¨ã®è¡¨ç¤ºããã°ã°ã£ã¦èª¿ã¹ãã¨ã©ãããMIDIé¢é£ã®ãã®ãããï¼ã¢ããªã±ã¼ã·ã§ã³ã§éãã¦æ¢ã£ã¦ã¿ã¾ãããå ¨ããããããã¿ã¤ã ã¢ãããããããããªãã¾ã¾çµãã£ã¦ãã¾ã£ãã
å¾ç¹ã«ã¤ãã¦
å ¨å½å¤§ä¼ã§ã¯å°æ¹äºé¸ã¨éãæ»é²æ¦ãªã®ã§ãKeyãæåºããç¹æ°ã¨ãèªãã¼ã ã®FLAGãæ¸ãè¾¼ã¿ãå®ããã¨ã§å¾ãããç¹æ°ã®2ã¤ãããã¾ãã
ãã®ããããã®ä¸¡æ¹ã念é ã«ç½®ãã¦æã¾ãªããã°ãªããªãã®ã§ãããæ¬æ¦ã¯FLAGãå®ããã¨ã§å¾ãããç¹æ°ãé常ã«é«ãã£ã模æ§ã
ç§ã®ãã¼ã ã¯ãã®ãã¨ãå¾åãã«ãã¦ããããã§ãå¾åã®å¨ãã®ä¼¸ã³ã«ã¤ãã¦ãããã大ããç¹æ°ãè½ã¨ãã¦ãã¾ãã¾ããã
ä¾ãã°Pisa.towerã®æ²ç¤ºæ¿ã«FLAGãæ¸ãè¾¼ãåé¡ãæåããèªåæ稿ããããã«ã¹ã¯ãªããåããã¦ãããã¼ã ã¯ããã ãã§Keyæåºæ°ååã®å¾ç¹ãå¾ã¦ããã¿ããã§ãã
ç¹æ°é åã¯ä¸å¿æ¸ãã¦ããã¿ãããªã®ã§ããããèªã¿é£ã°ããã®ãæªãã®ã§ããã
ä¸æ¥ç®ãçµãã£ã¦ã競æã¯ç¶ãã»ã»ã»
åºæ¬ä¸ã®åºæ¬ã§ããä¸æ¥ç®ãçµãã£ã¦ããã¡ã¤ã«è§£æãè½ã¨ãããã¤ããªã®ç©´æ¢ãã¯ç¶ãããã¨ãã§ãã¾ãã
Webç³»ã®åé¡ã¯ç«¶æãããã¯ã¼ã¯ãåããã¦ããã®ã§ç¡çã§ãããããã§ã話ãåãä½ã¯ã§ããã®ã§ç§ã®ãã¼ã ã¯å± é å±ã§é ã飲ã¿ãªãããã£ã¦ãã¾ããï¼ï½
ããã«ã«å°çãã¦ããããã¡ã¤ã«ã®ä¸ãè¦ãããè²ã ã¨ãã£ã¦ãã¾ãããã»ã»ã»ãã¼ããé£ããã£ãï½
å ¨ä½çã«
ãã¤ããªç³»ããªã«ãã§ããªãã£ããã¨ãè¾ãã£ãã§ããWebç³»ã®åé¡ãªã©ã解ããªãã£ãã®ã§ãã¡ã³ãã¼ããã«ç³ã訳ãªãéãã»ã»ã
æ¬æ¦å½¢å¼ã®åé¡ã¯ãæããããæ¢ããã¨ããã¯ãããªããã°ãªããªãã®ã§ãããã«æ £ãã¦ããªãç§ã«ã¯å³ãã大ä¼ã§ããããã®è¾ºãã¯çµé¨ãå¿ è¦ãªã®ããªã
åé¡èªä½ãã¹ã©ã¹ã©ã¨è§£ãããããªãã®ã§ã¯ãªãã£ãã®ã§ãè¦æ¦ãã¾ããã
ããããæ¬æ¦åºå ´ã¯é常ã«ããçµé¨ã«ãªãã¾ããããã¼ã ã¡ã³ãã¼ã«ã¯æè¬ãã¦ããããã¾ããã
æ¥å¹´ã®CTFã§æ¦ããããã«Writeupãè¦ã¦ãã¤ããªã¨Webãä¸å¿ã«åå¼·ãããã