ããããããã ããã«ã€ããŠæžããŸããããå°ã貧匱ã§é¢åã§ãã ãã®åŸãã¬ãã¥ãŒã®ããŒã«ã®ãªã¹ããæ¡åŒµããæ§é ã«èšäºã远å ããæ¹å€ãèæ
®ãïŒã¢ããã€ã¹ãããããšãã Leftyã«æè¬ããŸãïŒãSecLabã®ã³ã³ããã£ã·ã§ã³ã«éä¿¡ããŸããïŒãããŠã ãªã³ã¯ãå
¬ââéããŸããããæãããªçç±ã§èª°ãèŠãŸããã§ããïŒã ç«¶äºã¯çµãããçµæãçºè¡šãããè¯å¿ããã£ãŠHabréã«å
¬éã§ããŸãïŒèšäºïŒãç¡æã®Pentester Webã¢ããªã±ãŒã·ã§ã³ããŒã«
ãã®èšäºã§ã¯ãããã©ãã¯ããã¯ã¹ãæŠç¥ã«åŸã£ãŠWebã¢ããªã±ãŒã·ã§ã³ã®ãã³ãã¹ãïŒäŸµå
¥ãã¹ãïŒãè¡ãããã®æãäžè¬çãªããŒã«ã«ã€ããŠèª¬æããŸãã
ãããè¡ãããã«ããã®ã¿ã€ãã®ãã¹ãã«åœ¹ç«ã€ãŠãŒãã£ãªãã£ãæ€èšããŸãã æ¬¡ã®è£œåã«ããŽãªãæ€èšããŠãã ããã
- ãããã¯ãŒã¯ã¹ãã£ããŒ
- Web Scripting Scanner
- æªçš
- èªååã€ã³ãžã§ã¯ã·ã§ã³
- ãããã¬ãŒïŒã¹ããã¡ãŒãããŒã«ã«ãããã·ãªã©ïŒ
äžéšã®è£œåã«ã¯æ®éçãªãç¹æ§ãããããã
ãããè¯ãçµæãåŸãããã«ããŽãªïŒäž»èгçæèŠïŒã«é¢é£ä»ããŸãã
ãããã¯ãŒã¯ã¹ãã£ããŒã
äž»ãªã¿ã¹ã¯ã¯ãå©çšå¯èœãªãããã¯ãŒã¯ãµãŒãã¹ã®å
¬éãããŒãžã§ã³ã®ã€ã³ã¹ããŒã«ãOSã®æ±ºå®ãªã©ã§ãã
Nmap
NmapïŒããããã¯ãŒã¯ããããŒãïŒã¯ããããã¯ãŒã¯åæãšã·ã¹ãã ã»ãã¥ãªãã£ç£æ»ã®ããã®ç¡æã®ãªãŒãã³ãœãŒã¹ãŠãŒãã£ãªãã£ã§ãã ã³ã³ãœãŒã«ã®æ¿ããçžæã¯Zenmapã䜿çšã§ããŸããããã¯Nmapã®GUIã§ãã
ããã¯åãªããã¹ããŒããã¹ãã£ããŒã§ã¯ãªããæ·±å»ãªæ¡åŒµå¯èœãªããŒã«ã§ãïŒãç°åžžãªãããã
-Stuxnetã¯ãŒã ã®ååšãããŒãã§ç¢ºèªããã¹ã¯ãªããã®ååšïŒ
ããã§èª¬æ ïŒã
nmap -A -T4 localhost
-A OSããŒãžã§ã³ã®å€å¥ãã¹ã¯ãªããããã³ãã¬ãŒã¹ã䜿çšããã¹ãã£ã³
-T4æé管çèšå®ïŒããå€ã-é«éã0ã5ïŒ
localhost-ã¿ãŒã²ãããã¹ã
ãã£ãšé£ãããã®ã¯ãããŸããïŒ
nmap -sS -sU -T4 -A -v -PE -PP -PS21,22,23,25,80,113,31339 -PA80,113,443,10042 -PO --script all localhost
ããã¯ãZenmapã®ãäœéç·åã¹ãã£ã³ããããã¡ã€ã«ã®ãªãã·ã§ã³ã»ããã§ãã ããªãé·ãæéãããããŸãããæçµçã«ã¯ã¿ãŒã²ããã·ã¹ãã ã«ã€ããŠåŠç¿ã§ããããè©³çŽ°ãªæ
å ±ãæäŸããŸãã
ãã·ã¢èªã®ãªãã¡ã¬ã³ã¹ã¬ã€ã ãããã«
詳ãã説æ
ããå Žåã¯ã
åå¿è
ã¬ã€ããNmapã«ç¿»èš³ããããšããå§ã
ããŸã ã
Nmapã¯ãLinux JournalãInfo WorldãLinuxQuestions.OrgãCodetalker Digestãªã©ã®éèªãã³ãã¥ããã£ããã幎éæåªç§ã»ãã¥ãªãã£è£œåãã¹ããŒã¿ã¹ãç²åŸããŠããŸãã
è峿·±ãç¬éãNmapã¯æ ç»ãMatrixïŒReloadedãããDie Hard 4ãããBourne UltimatumãããHottabychããªã©ã§èŠãããšãã§ããŸããIPããŒã«
IP-Tools-ç°ãªãçš®é¡ã®ãããã¯ãŒã¯ãŠãŒãã£ãªãã£ã®äžçš®ã§ãWindowsãŠãŒã¶ãŒå°çšã®GUIãä»å±ããŠããŸãã
ããŒãã®ã¹ãã£ããŒãå
±æãªãœãŒã¹ïŒå
±æããªã³ã¿ãŒ/ãã©ã«ããŒïŒãWhoIs / Finger / Lookupãtelnetã¯ã©ã€ã¢ã³ããªã©ã 䟿å©ã§é«éãæ©èœçãªããŒã«ã§ãã
ãã®åéã«ã¯å€ãã®ãŠãŒãã£ãªãã£ãããããããã¯ãã¹ãŠåæ§ã®åäœåçãšæ©èœãæã£ãŠãããããä»ã®è£œåãæ€èšããããšã¯ã»ãšãã©æå³ããããŸããã ããããæãäžè¬çã«äœ¿çšãããã®ã¯nmapã§ããWeb Scripting Scanner
äžè¬çãªè匱æ§ïŒSQL injãXSSãLFI / RFIãªã©ïŒãŸãã¯ãšã©ãŒïŒåé€ãããäžæãã¡ã€ã«ãã€ã³ããã¯ã¹ãã£ã¬ã¯ããªãªã©ïŒãèŠã€ããããšãã
Acunetix Webè匱æ§ã¹ãã£ããŒ
Acunetix Web Vulnerability Scanner-ãªã³ã¯ã¯ãããã
xssã¹ãã£ããŒã§ããããšã瀺ããŠããŸãããããã¯
å®å
šã«çå®ã§ã¯ãããŸããã ãªã³ã¯ãä»ããŠå©çšå¯èœãªç¡æçã¯éåžžã«å€ãã®æ©èœãæäŸããŸãã éåžžããã®ã¹ãã£ããŒãåããŠèµ·åãããªãœãŒã¹ã«é¢ããã¬ããŒããåããŠåãåã£ã人ã¯å°ããªã·ã§ãã¯ãçµéšããŸãããããè¡ãããšã§çç±ãçè§£ã§ããŸãã ããã¯ããµã€ãäžã®ããããçš®é¡ã®è匱æ§ãåæããããã®éåžžã«åŒ·åãªè£œåã§ããã
䜿ãæ
£ãã phpãµã€ãã ãã§ãªããä»ã®èšèªã§ãæ©èœããŸãïŒãã ããèšèªã®éãã¯ææšã§ã¯ãããŸããïŒã ã¹ãã£ããŒã¯ãŠãŒã¶ãŒã®ã¢ã¯ã·ã§ã³ãåã«ãããã¯ã¢ããããããããæç€ºã説æããæå³ã¯ãããŸããã äžéšã®ãœãããŠã§ã¢ã®å
žåçãªã€ã³ã¹ããŒã«ã«ããããããã«ãããã«ãããã«ãæºåãã§ãããã«äŒŒââããã®ã
æ¥æ±
Niktoã¯ããªãŒãã³ãœãŒã¹ïŒGPLïŒWebã¹ãã£ããŒã§ãã æ¥åžžçãªæäœæ¥ãæé€ããŸãã ã¿ãŒã²ãããµã€ãïŒäžéšã®test.phpãindex_.phpãªã©ïŒãããŒã¿ããŒã¹ç®¡çããŒã«ïŒ/ phpmyadmin /ã/ pmaãªã©ïŒã§åé€ãããŠããªãã¹ã¯ãªãããæ€çŽ¢ããŸããã€ãŸããæãé »ç¹ã«ãªãœãŒã¹ããã§ãã¯ããŸããéåžžã人çèŠå ãåå ã§çºçãããšã©ãŒã
ããã«ã人æ°ã®ããã¹ã¯ãªãããèŠã€ãããšããªãªãŒã¹ããããšã¯ã¹ããã€ãïŒããŒã¿ããŒã¹ã«ããïŒããã§ãã¯ããŸãã
PUTãTRACEãªã©ã®å©çšå¯èœãªãäžèŠãªãæ¹æ³ãå ±åãã
ãŸããªã©ã ããªããç£æ»åœ¹ãšããŠåããŠãæ¯æ¥ãŠã§ããµã€ãåæãè¡ããªãã°ãããã¯éåžžã«äŸ¿å©ã§ãã
ãã€ãã¹ã®ãã¡ã誀æ€ç¥ã®å²åãé«ãããšã«æ³šæããŠãã ããã ããšãã°ã404ãšã©ãŒã®ä»£ããã«ïŒçºçããã¯ãã®ïŒãµã€ããåžžã«äž»èŠãªæ
å ±ãæäŸããå Žåãã¹ãã£ããŒã¯ããŒã¿ããŒã¹ã®ãã¹ãŠã®ã¹ã¯ãªãããšãã¹ãŠã®è匱æ§ããµã€ãã«ãããšèšããŸãã å®éã«ã¯ãããã¯ããã»ã©äžè¬çã§ã¯ãããŸããããå®éã«ã¯ãå€ãã¯ãµã€ãã®æ§é ã«äŸåããŸãã
å€å
žçãªäœ¿çšïŒ
./nikto.pl -host localhost
ãµã€ãã§èªèšŒãåããå¿
èŠãããå Žåã¯ãnikto.confãã¡ã€ã«ã§STATIC-COOKIE倿°ã«Cookieãèšå®ã§ããŸãã
ãŠã£ã¯ã
Wikto -Windowsã§ã®Niktoããã ãããšã©ãŒããã§ãã¯ããéã®ããã¡ãžãŒãããžãã¯ãGHDBã®äœ¿çšããªãœãŒã¹ã®ãªã³ã¯ãšãã©ã«ããŒã®ååŸãHTTPãªã¯ãšã¹ã/ã¬ã¹ãã³ã¹ã®ãªã¢ã«ã¿ã€ã ã¢ãã¿ãªã³ã°ãªã©ã®è¿œå ã Wiktoã¯CïŒã§èšè¿°ãããŠããã.NETãã¬ãŒã ã¯ãŒã¯ãå¿
èŠã§ãã
ã¹ããããã£ãã·ã¥
skipfishã¯ã
Michal ZalewskiïŒlcamtââufãšããŠç¥ãããïŒã«ããWebè匱æ§ã¹ãã£ããŒã§ãã ã¯ãã¹ãã©ãããã©ãŒã ã®Cã§æžãããŠããŸãïŒWinã®å Žåã¯Cygwinãå¿
èŠã§ãïŒã ååž°çã«ïŒãããŠéåžžã«é·ãæéãçŽ20ã40æéãååã¯96æéåããŠããŸãããïŒãµã€ãå
šäœãå·¡åããããããçš®é¡ã®ã»ãã¥ãªãã£ããŒã«ãèŠã€ããŸãã ãŸãã倧éã®ãã©ãã£ãã¯ãçæããŸãïŒæ°GBã®ã€ã³ããŠã³ã/ã¢ãŠãããŠã³ãïŒã ããããç¹ã«æéãšãªãœãŒã¹ãããå Žåã¯ããã¹ãŠã®ææ®µãåªããŠããŸãã
å
žåçãªäœ¿çšæ³ïŒ
./skipfish -o /home/reports www.example.com
ãã¬ããŒãããã©ã«ããŒã«ã¯ãhtmlã®ã¬ããŒãïŒ
äŸïŒããããŸãã
w3af
w3af-ãªãŒãã³ãœãŒã¹ã®Webè匱æ§ã¹ãã£ããŒã§ããWeb Application Attack and Audit Frameworkã GUIããããŸãããã³ã³ãœãŒã«ã®äžããäœæ¥ã§ããŸãã ããæ£ç¢ºã«ã¯ãããã¯å€ã
ã®ãã©ã°ã€ã³ãæã€ãã¬ãŒã ã¯ãŒã¯ã§ãã
ããªãã¯é·ãéãã®å©ç¹ã«ã€ããŠè©±ãããšãã§ããŸããããã詊ããŠã¿ãããšããå§ãããŸãïŒ]
å
žåçãªäœæ¥ã¯ããããã¡ã€ã«ãéžæããç®æšãæå®ããå®éã«ãããèµ·åããããšã§ãã
Mantraã»ãã¥ãªãã£ãã¬ãŒã ã¯ãŒã¯
ãã³ãã© ã¯å®çŸãã倢ã§ã ã Webãã©ãŠã¶ã«åã蟌ãŸããç¡æã®ãªãŒãã³ãªã»ãã¥ãªãã£ããŒã«ã®ã³ã¬ã¯ã·ã§ã³ã
ãã¹ãŠã®æ®µéã§Webã¢ããªã±ãŒã·ã§ã³ããã¹ããããšãã«éåžžã«äŸ¿å©ã§ãã
äœ¿çšæ³ã¯ããã©ãŠã¶ã®ã€ã³ã¹ââããŒã«ãšèµ·åã«åž°çããŸãã
å®éããã®ã«ããŽãªã«ã¯å€ãã®ãŠãŒãã£ãªãã£ãããããããããç¹å®ã®ãªã¹ããéžæããããšã¯éåžžã«å°é£ã§ãã ã»ãšãã©ã®å Žåãå5åŠæèªäœãå¿
èŠãªããŒã«ã®ã»ãããæ±ºå®ããŸããæªçš
ãœãããŠã§ã¢ããã³ã¹ã¯ãªããã®è匱æ§ã®èªååããã䟿å©ãªæªçšã®ããã«ãã»ãã¥ãªãã£éåãæªçšããããã«ãã©ã¡ãŒã¿ãæž¡ãã ãã§ããæªçšãäœæããŸãã ãŸãããšã¯ã¹ããã€ãã®æåæ€çŽ¢ãæé€ãããã®å Žã§ãããã䜿çšãã補åããããŸãã ãã®ã«ããŽãªã«ã€ããŠèª¬æããŸãã
Metasploitãã¬ãŒã ã¯ãŒã¯
Metasploit®ãã¬ãŒã ã¯ãŒã¯ã¯ãåœç€Ÿã®ããžãã¹ã«ãããäžçš®ã®ã¢ã³ã¹ã¿ãŒã§ãã 圌ã¯å€ãã®ããšãç¥ã£ãŠããã®ã§ããã®æç€ºã¯ããã€ãã®èšäºã§å
¬éãããŸãã èªåæŸåïŒnmap + metasploitïŒãæ€èšããŸãã èŠããã«ãNmapã¯å¿
èŠãªããŒããåæãããµãŒãã¹ãã€ã³ã¹ããŒã«ããmetasploitã¯ãµãŒãã¹ã¯ã©ã¹ïŒftpãsshãªã©ïŒã«åºã¥ããŠãšã¯ã¹ããã€ããé©çšããããšããŸãã ããã¹ãã®èª¬æã®ä»£ããã«ãautopwnã®ãããã¯ã§éåžžã«äººæ°ã®ãããããªãæ¿å
¥ããŸã
ãŸãã¯ãå¿
èŠãªãšã¯ã¹ããã€ãã®æäœãåçŽã«èªååããããšãã§ããŸãã äŸïŒ
msf > use auxiliary/admin/cisco/vpn_3000_ftp_bypass
msf auxiliary(vpn_3000_ftp_bypass) > set RHOST [TARGET IP]
msf auxiliary(vpn_3000_ftp_bypass) > run
å®éããã®ãã¬ãŒã ã¯ãŒã¯ã®æ©èœã¯éåžžã«åºç¯ãªãããããã«æ·±ãããããšã«ããå Žåã¯ã
ãªã³ã¯ãã¯ãªãã¯ããŠ
ãã ãããã¢ãŒãããŒãž
ã¢ãŒãããŒãž-Metasploit ã®ãµã€ããŒãã³ã¯ GUI
ãžã£ã³ã«ã®OVA ã ã¿ãŒã²ãããèŠèŠåãããšã¯ã¹ããã€ããæšå¥šãããã®ãã¬ãŒã ã¯ãŒã¯ã®é«åºŠãªæ©èœãæäŸããŸãã äžè¬çã«ããã¹ãŠãçŸãã壮芳ã«èŠããããšã奜ã人ã®ããã«ã
ã¹ã¯ãªãŒã³ãã£ã¹ãïŒ
TenableNessus®
TenableNessus®è匱æ§ã¹ãã£ã㌠-å€ãã®ããšãã§ããŸããããã®æ©èœã®1ã€ãå¿
èŠã§ã-ã©ã®ãµãŒãã¹ã«ãšã¯ã¹ããã€ããããããå€å¥ããŸãã 補åã®ç¡æçãããŒã ãªã³ãªãŒã
äœ¿çšæ³ïŒ
ãã°ãããããšãã¹ãã£ã³ã¬ããŒãã[ã¬ããŒã]ã¿ãã«è¡šç€ºãããŸãã
ãšã¯ã¹ããã€ãã«å¯ŸãããµãŒãã¹ã®å®çšçãªè匱æ§ã確èªããã«ã¯ãäžèšã®Metasploit Frameworkã䜿çšãããããšã¯ã¹ããã€ãïŒ
Explot-db ã
ãã±ããã¹ããŒã ã
explot searchãªã©ïŒã
èŠã€ã㊠ã
ã·ã¹ãã ã«å¯ŸããŠæåã§äœ¿çšã
ãŸããç§èŠïŒããã°ãã 圌ã¯åœŒããœãããŠã§ã¢æ¥çã®ãã®åéã®ãªãŒããŒã®äžäººãšããŠé£ããŠããŸãããå°åºèªåå
å€ãã®Webã¢ããªsecã¹ãã£ããŒã¯ã€ã³ãžã§ã¯ã·ã§ã³ãæ€çŽ¢ããŸããããŸã äžè¬çãªã¹ãã£ããŒã§ãã ãŸããã€ã³ãžã§ã¯ã·ã§ã³ã®æ€çŽ¢ãšæäœã«ç¹ã«é¢ä¿ãããŠãŒãã£ãªãã£ããããŸãã ãããã¯ä»è°è«ãããŸãã
sqlmap
sqlmapã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³ãèŠã€ããŠæäœããããã®ãªãŒãã³ãœãŒã¹ãŠãŒãã£ãªãã£ã§ãã MySQLãOracleãPostgreSQLãMicrosoft SQL ServerãMicrosoft AccessãSQLiteãFirebirdãSybaseãSAP MaxDBãªã©ã®ããŒã¿ããŒã¹ãµãŒããŒããµããŒãããŠããŸãã
å
žåçãªäœ¿çšæ³ã¯æ¬¡ã®ããã«ãªããŸãã
python sqlmap.py -u "http://example.com/index.php?action=news&id=1"
ãã·ã¢èªãå«ãååãªããã¥ã¢ã«ã ãœããã£ãã¯ããã®åéã§äœæ¥ãããšããäºå¹Žçã®ä»äºã倧ãã«ä¿é²ããŸãã
å
¬åŒãããªãã¢ã远å ããŸãã
bsqlbf-v2
bsqlbf-v2 -perlã¹ã¯ãªãããããã©ã€ã³ããSQLã€ã³ãžã§ã¯ã·ã§ã³ã®ãã«ãŒã
ãã©ãŒãµãŒ ã URLã®æŽæ°å€ãšæååïŒæååïŒã®äž¡æ¹ã§æ©èœããŸãã
DBããµããŒãïŒ
- MS-SQL
- MySQL
- PostgreSQL
- ãªã©ã¯ã«
䜿çšäŸïŒ
./bsqlbf-v2-3.pl -url www.somehost.com/blah.php?u=5 -blind u -sql "select table_name from imformation_schema.tables limit 1 offset 0" -database 1 -type 1
-url www.somehost.com/blah.php?u=5-ãã©ã¡ãŒã¿ãŒãšã®ãªã³ã¯
-blind u-ã€ã³ãžã§ã¯ã·ã§ã³ã®ãã©ã¡ãŒã¿ãŒïŒããã©ã«ãã§ã¯ãã¢ãã¬ã¹ããŒã®æåŸã®ãã©ã¡ãŒã¿ãŒãååŸãããŸãïŒ
-sql "imformation_schema.tables limit 1 offset 0ããtable_nameãéžæ" -ããŒã¿ããŒã¹ã«å¯Ÿããä»»æã®ãªã¯ãšã¹ã
-ããŒã¿ããŒã¹
1-ããŒã¿ããŒã¹ãµãŒããŒïŒMSSQL
-type 1-æ»æã®ã¿ã€ããTrueããã³ErrorïŒæ§æãšã©ãŒãªã©ïŒã®åçã«åºã¥ãããã©ã€ã³ããã€ã³ãžã§ã¯ã·ã§ã³
ãããã¬ãŒ
ãããã®ããŒã«ã¯ãäž»ã«éçºè
ãã³ãŒãå®è¡ã®çµæã«é¢ããåé¡ã®ããã«äœ¿çšããŸãã ãããããã®æ¹åã¯ãå¿
èŠãªããŒã¿ããã®å Žã§çœ®æããããå
¥åãã©ã¡ãŒã¿ãŒã«å¿çãããã®ãåæãããïŒãã¡ãžã³ã°ãªã©ã䜿çšïŒã§ãããªã©ããã³ãã¹ãã§ã圹ç«ã¡ãŸãã
ãã£ã·ã¹ã€ãŒã
Burp Suiteã¯ã䟵å
¥ãã¹ãã«åœ¹ç«ã€äžé£ã®ãŠãŒãã£ãªãã£ã§ãã Webã¯ãRaz0rã®ãã·ã¢èªã®
è¯ãã¬ãã¥ãŒã§ãïŒ2008幎ã«åœãŠã¯ãŸããŸãïŒã
ç¡æçã«ã¯ä»¥äžãå«ãŸããŸãã
- Burp Proxy-ããŒã«ã«ãããã·ããã©ãŠã¶ããæ¢ã«çæããããªã¯ãšã¹ãã倿Žã§ããŸãã
- Burp Spider-æ¢åã®ãã¡ã€ã«ãšãã£ã¬ã¯ããªãæ¢ããŠããã¯ã¢
- Burp Repeater-HTTPèŠæ±ãæåã§éä¿¡ããŸã
- Burp Sequencer-ãã©ãŒã å
ã®ã©ã³ãã å€ã®åæ
- Burp Decoder-æšæºã³ãŒããã¯ïŒhtmlãbase64ãhexãªã©ïŒããã®äžã«ã¯ãä»»æã®èšèªã§ãã°ããèšè¿°ã§ããæ°åãã®ãã®ããããŸãã
- Burp Comparer-æååç
§åã³ã³ããŒãã³ã
ååãšããŠããã®ããã±ãŒãžã¯ããã®åéã«é¢é£ããã»ãšãã©ãã¹ãŠã®ã¿ã¹ã¯ã解決ããŸãã
ãã£ãã©ãŒ
Fiddler -Fiddlerã¯ããã¹ãŠã®HTTPïŒSïŒãã©ãã£ãã¯ãèšé²ãããããã°ãããã·ã§ãã ãã®ãã©ãã£ãã¯ãæ¢çŽ¢ãããã¬ãŒã¯ãã€ã³ããèšå®ããçä¿¡ããŒã¿ãŸãã¯çºä¿¡ããŒã¿ã§ãåçãã§ããŸãã
Firesheep ãã¢ã³ã¹ã¿ãŒ
Wiresharkãªã©ããããŸããéžæã¯ãŠãŒã¶ãŒã§ãã
ãããã«
åœç¶ã®ããšãªããããããã®å€ãã¯åçŽã«ååšãããããåäºåæã«ã¯ç¬èªã®æŠåšåº«ãšç¬èªã®ãŠãŒãã£ãªãã£ã»ããããããŸãã ç§ã¯æã䟿å©ã§äººæ°ã®ãããã®ãæã£ãŠããŠã¿ãŸããã ãããããã®æ¹åã§èª°ããä»ã®ãŠãŒãã£ãªãã£ã«ç²Ÿéã§ããããã«ã以äžã®ãªã³ã¯ãæäŸããŸãã
ã¹ãã£ããŒãšãŠãŒãã£ãªãã£ã®ããŸããŸãªããã/ãªã¹ã
Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ããã§ã«å€ãã®ç°ãªããã³ãã¹ããŠãŒãã£ãªãã£ãå«ãŸããŠããŸã
upd ïŒ
Hack4SecããŒã ã«ãããã·ã¢èªã®
BurpSuiteããã¥ã¡ã³ã ïŒ
AntonKuzminã远å ïŒ
PSããªãã¯XSpiderã«ã€ããŠæ²é»ããããšã¯ã§ããŸããã 圌ã¯ã¬ãã¥ãŒã«åå ããŸããããããã¯ã·ã§ã¢ãŠã§ã¢ã§ãïŒãã®ããïŒåœŒã¯ç¥èããªããææ°ããŒãžã§ã³7.8ããªãããïŒèšäºãSecLabã«éä¿¡ãããšãã«ããããèšäºã«ãããå«ããŸããã§ããïŒã ãããŠçè«çã«ã¯åœŒã®ã¬ãã¥ãŒã¯èšç»ãããŠããŸããïŒç§ã¯åœŒã®ããã«é£ãããã¹ããçšæããŠããŸããïŒããäžçã圌ãèŠããã©ããã¯ããããŸããã
PPSèšäºã®äžéšã®è³æã¯ãQAã»ã¯ã·ã§ã³ã®
CodeFest 2012ã®ä»åŸã®ã¬ããŒãã§æå³ãããç®çã«äœ¿çšãããŸããããã§ã¯ãããã§èšåãããŠããªãããŒã«ïŒç¡æãessnoïŒãããã³äœ¿çšããé åºãæåŸ
ãããçµæãæ§æã®ã¢ã«ãŽãªãºã ããããŸãäœæ¥äžã«ããããçš®é¡ã®ãã³ããã³ãã䜿çšããŸãïŒã¬ããŒãã«ã€ããŠã»ãŒæ¯æ¥èããŠããŸãããããã¯ã«ã€ããŠæé«ã®ããšãèªåã§äŒããããšããŸãïŒ
ã¡ãªã¿ã«ããã®èšäºã«ãããšã
Open InfoSec Days ïŒ
Habréã®ã¿ã° ã
ãµã€ã ïŒã§ã¬ãã¹ã³ãããã
korovany lookã®
è³æã 奪ãããšãã§ããŸãã