5æ30æ¥ãš31æ¥ã«ãDigital Octoberãã¯ãããžãŒã»ã³ã¿ãŒã¯ãå®çšçãªå®å
šæ§åé¡ã«é¢ãã
Positive Hack Days 2012åœéãã©ãŒã©ã ãéå¬ããŸããã 1500人ãå€æ°ã®ã¬ããŒããšã¯ãŒã¯ã·ã§ããã倧èŠæš¡ãªCTF競æãè±å¯ãªç«¶æããã°ã©ã -ãããã¯ãã¹ãŠPHDaysã§ãã ããã§ãã€ã³ã¿ãŒãããã³ãã¥ããã£ã®ä»£è¡šè
ãã»ãã¥ãªãã£ã®å°é家ãäžçäžã®ããã«ãŒããã®ç¹å¥ãªã«ã¯ãã«ãäœãšãæ··åããã«ã¯ãã«ãçŸå³ãããªã£ãããšãå
šè²¬ä»»ã§å®£èšã§ããŸãã
ä»æ¥ãçŽæã©ãããPHDays 2012ã®ã¬ããŒããšã¯ãŒã¯ã·ã§ããã®èšé²ãå
¬éããŸããæ
å ±ã»ãã¥ãªãã£ã«é¢ããã®ã¬ãã€ãã®ãããªã®äžã«ã¯ãã²ãŒãã®ããã¡ãŠã¹ããããã匷åãªãã®ããããŸã-ãã«ãŒã¹ã·ã¥ãã€ã¢ãŒãäžçæå·ã®äŒèª¬ã çŽ æµãªæ¯è²ãïŒ
äž»èŠè«æ
Bruce Schneierã«ãããããªã¬ããŒãã¯ã
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ13:00ããïŒã æå·åŠã®ç¬¬äžäººè
ã¯åœŒã®ã»ãã¥ãªãã£å²åŠã«ã€ããŠèªããå€ãã®äººãé©ãããŸããã æ³ã®éåè
ïŒããã«ãŒïŒã¯ã圌ã®æèŠã§ã¯ãæ害ã§ããã ãã§ãªãæçšã§ããããŸãã
Datuk Mohd Nur Aminã¯ããµã€ããŒè
åšãšã®éããç®æããåœé£ã®å°éæ©é¢ã§ããåœéé»æ°éä¿¡é£åïŒITUïŒãšååãããåœé£äžã§ã®æåã®å
¬çæ©é¢ã§ããåœéãµã€ããŒè
åšã«å¯ŸããåœéããŒãããŒã·ããïŒIMPACTïŒã®è°é·ã§ãã ã€ã³ãã¯ãã¯ããµã€ããŒã¹ããŒã¹ã®äžçæ倧ã®ã»ãã¥ãªãã£åäŒãšããŠèªèãããŠããŸãã 137ãåœã§æ§æãããŠããŸã[
ãã㪠]ã
ãã¬ã³ã
ã¬ããŒãïŒ Sergey Gordeychikãããã¬ã³ã ãããã¯ããŠçãç¶ããæ¹æ³-2.è«æ±ã«æãå·®ã䌞ã¹ãã[
ãã㪠]ã
æè¡ãããã¯ãŒã¯ã®éµã¯ã©ãã«ä¿åãããŠããŸããïŒ äŒç€Ÿã®äžæ žäºæ¥ã«åé¡ãçããããã«è«æ±æžãå
¥æããæ¹æ³ ããã«ã€ããŠãããã³éä¿¡ãããã¯ãŒã¯ã®äŸµå
¥ããã¹ãããæ°ãã瀺åçã§æ¥œããã±ãŒã¹ã«ã€ããŠãã»ã«ã²ã€ã¯åœŒã®ã¬ããŒãã§è¿°ã¹ãã
ã»ã¯ã·ã§ã³ïŒ Eugene KlimovããRISSPAã ãã¬ã³ã 察äžæ£ïŒèª°ãåã¡ãŸããïŒã ãããªã¯
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ12:15ããïŒã
å
Œ
±éšé
å ±åæžïŒããã€ã«ã»ãšã¡ãªã¢ãã³ãããå人ããŒã¿ã«é¢ãããã·ã¢ã®æ³åŸã«éåããªãããšã¯äžå¯èœãªå Žåãšçç±ã[
åç» ]ã
ã¬ããŒãïŒãã·ã¢ã®FSTECã®ã¢ã³ãã¬ã€V.ãã§ãã£ãã§ããããªãåœå®¶ã®ç§å¯ãã€ã³ã¿ãŒãããã«çŸããã®ãïŒã[
ãã㪠]ã
ã¬ããŒãïŒã¢ã¬ã¯ã»ã€ã»ã«ã«ãããŒãããã·ã¢ã®å€§çµ±é éžæã¯æ
å ±ã»ãã¥ãªãã£åžå Žã«ã©ã®ããã«åœ±é¿ããŸããããŸãã¯èŠå¶ã¯ã©ãã«åãã£ãŠããŸããïŒããããªã¯
ãã®ãªã³ã¯ã§å©çšã§ããŸãïŒååŸ4æããïŒã
ãããã¯ãŒã¯ã»ãã¥ãªãã£
ã¬ããŒãïŒãŠã©ãžããŒã«ã»ã¹ã¿ã€ã©ã³ããèåœã«ã€ããŠã®çå®ïŒã»ãã¥ãªãã£ã®ããã®ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã[
åç» ]ã
ãã¹ã¿ãŒã¯ã©ã¹ïŒã¢ã³ãã¬ã€ããµããããããã€ã³ã¿ãŒãããäžã®ç«¶äºçæ
å ±ãã ãããªã¯
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ16:08以éïŒã
ãã¹ã¿ãŒã¯ã©ã¹ã®åå è
ã¯ãå®éã®ç«¶åã€ã³ããªãžã§ã³ã¹ã®äŸã䜿çšããŠãåææè¡ãç¹ã«æ©å¯æ
å ±ã®æŒæŽ©ãè¿
éã«æ€åºããæè¡ãããã³ãµãŒããŒã®ã»ã¯ã·ã§ã³ãéãæ¹æ³ãã»ãã¥ãªãã£ãç Žããã«FTPãµãŒããŒã«äŸµå
¥ããŠãã¹ã¯ãŒããªãŒã¯ãæ€åºããæ¹æ³ãããã³ã¢ã¯ã»ã¹ããæ¹æ³ã«ç²ŸéããŸããDLPããã€ãã¹ãã察å¿ããæš©éãªãã§ããŒãã£ã·ã§ã³ã«äŸµå
¥ããæ©å¯ææžïŒãšã©ãŒ403ïŒã ãã¢ã¯ãååã«ä¿è·ãããäŒæ¥ïŒITããã³æ
å ±ã»ãã¥ãªãã£åžå Žã®ãªãŒããŒã倧èŠæš¡ãªæ¿åºæ©é¢ãç¹å¥ãµãŒãã¹ïŒã®ããŒã¿ã«ã®äŸã§å®æœãããŸããã
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Dmitry Ryzhavskyããã¯ã€ã€ã¬ã¹LANã»ãã¥ãªãã£ïŒãããã¯ãŒã¯ãžã®äŸµå
¥æ¹æ³ãšåé¿æ¹æ³ã[
ãã㪠]ã
ãã¬ãŒã³ããŒã·ã§ã³äžã«ãWi-Fiãããã¯ãŒã¯ãžã®äžæ£ã¢ã¯ã»ã¹ãååŸããããã®æãé©åãªæ¹æ³ãæ€èšããã説æãããæ»æããä¿è·ããããã®Cisco Unified Wireless Networkã®å
æ¬çãªãœãªã¥ãŒã·ã§ã³ãæäŸããã¡ã«ããºã ãå®èšŒãããŸããã
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Sergey Lozhkinããã³ã³ãã¥ãŒã¿ãŒã€ã³ã·ãã³ãã®èª¿æ»ãã ãããªã¯
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ14:00ããïŒã
ãã®ã¯ãŒã¯ã·ã§ããã¯ãã€ã³ã¿ãŒããããªãœãŒã¹ãžã®äžæ£ã¢ã¯ã»ã¹ã«é¢é£ããã€ã³ã·ãã³ãã®èª¿æ»å°çšã§ããã ãã¹ãã¯ãªã¹ããŒã«çŸä»£ã®ããã«ãŒã®å¿ççãªèåã玹ä»ãã䟵å
¥è
ã®çš®é¡ã«ã€ããŠè©±ããŸããã æªæã®ããè¡çºã®çè·¡ãæ€åºãããããã³ã°ä¿¡å·ã«å¿çããããšãããæ³å·è¡æ©é¢ãšååããŠæ»æè
ãæ¢ãããšãŸã§ãã€ã³ã·ãã³ãã«åãçµãããã»ã¹ã調æ»ããŸããã ããã«ããã©ãŒã©ã ã®ã²ã¹ãã¯ãå®éã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«é¢ããèå³æ·±ã話ãèããŸããã
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Nikhil Mittalããå
¥åºåããã€ã¹ã®å©ããåããŠã«ãªã¹ãäœæããã[
ãã㪠]ã
ãã®ã¯ãŒã¯ã·ã§ããã§ã¯ãéåžžã«éèŠã§ãããæ®éçã«ç¡èŠãããŠããã³ã³ãã¥ãŒã¿ãŒã»ãã¥ãªãã£ã®åŽé¢ãã€ãŸã人éãšã®å¯Ÿè©±çšã«èšèšãããããã€ã¹ïŒHuman Interface DevicesãHIDïŒã®è匱æ§ã«ã€ããŠèª¬æããŸããã
ã¬ããŒãïŒ Sylvain Munotãããµã€ããŒç¯çœªè
ã«ããã«ãªããœé»è©±ã®äœ¿çšã[
ãã㪠]ã
ã¬ããŒãïŒ Andrey KostinãPostScriptïŒå±éºïŒ MFPãPCãªã©ã®ãããã³ã°â [
ãã㪠]ã
ã¬ããŒãïŒã»ã«ã²ã€ã¯ã¬ãã®ã³ããCEHã å«ççãªãããã³ã°ãšäŸµå
¥ãã¹ãã[
ãã㪠]ã
ã¯ãŒã¯ã·ã§ããã®åå è
ã¯ããããã¯ãŒã¯ãããã³ã«ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãããã³ã¢ããªã±ãŒã·ã§ã³ã®å
žåçãªè匱æ§ã«ã€ããŠåŠã³ãŸããã ã¹ããŒãã®éçšã§ãé²è¡åœ¹ã¯ã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ããã³ãããã¯ãŒã¯ã«å¯ŸããããŸããŸãªçš®é¡ã®æ»æã®ã·ãŒã±ã³ã¹ã説æããã»ãã¥ãªãã£ã匷åããããã®æšå¥šäºé
ãäœæããŸããã ãªã¹ããŒã¯å®éã®ç°å¢ã«é£ã³èŸŒã¿ãã·ã¹ãã ãå®éã«ãããã³ã°ããæ¹æ³ã確èªããŸããããã®åŸãããã«ãŒã®è¡åãäºæž¬ãããããã«ããŸã察åŠããããã§ãã
ãã¬ãŒã³ããŒã·ã§ã³ïŒ Travis GoodspeedããPackets-in-Packets Technologyã䜿çšããç¡ç·å¹²æžã®æäœããããªã¯ã
ãã®ãªã³ã¯ã§å©çšã§ããŸãïŒ15:10ããéå§ïŒã
è¬æŒè
ã¯ãPIPãšã¯ã¹ããã€ãã®æ©èœã«ã€ããŠèª¬æããIEEE 802.15.4ãããã¯ãŒã¯ãšå欧RFäœé»åç¡ç·ã¢ãžã¥ãŒã«ã®äŸã瀺ããŸããã
SAPãSCADAãERP
å ±åïŒãŠãã£ã³ã»ã¢ã¬ã¯ã»ã€ããæ»æè
ã®ç®ããèŠãERPãã ãããªã¯
ãã®ãªã³ã¯ã§å©çšã§ããŸãïŒ15:00ããïŒã
å ±åïŒã¢ã³ãã¬ã€ã»ããããŽã£ããã»ãã¥ã«ããããç£æ¥æ
å ±ã·ã¹ãã ã®ä¿è·-人é¡ã®çåèŠå ã[
ãã㪠]ã
ã¬ããŒãïŒ Evgenia Schumacherããè·å Žãé¢ããã«ååã®çµŠäžã調ã¹ãæ¹æ³ããŸãã¯SAP HR Securityã[
ãã㪠]ã
å ±åïŒã¢ã¬ã¯ãµã³ããŒã»ããã€ããŽã£ãã»ããªã€ã³ãããSAPã®
äžå®å®æ§ ïŒæ°ãããŠããè¯ãã[
ã€ã㪠]
ãã®ã¬ããŒãã¯ãæå·åã®åé¡ããèªèšŒã®ãã€ãã¹ãããããªãšã©ãŒããè€éãªæ»æãã¯ãã«ãŸã§ãSAPã·ã¹ãã ã§æãèå³æ·±ã10ã®è匱æ§ãšæ»æãã¯ãã«ã«å°å¿µããŸããã åããŠãäžè¬å€§è¡ã¯ãã¬ããŒãã«ç€ºãããè匱æ§ã®ããªãã®éšåã«ç²ŸéããŸããã
ã¯ãŒã¯ã·ã§ããïŒ Alexei Yudinããèªåã®æã§ã®SAPã»ãã¥ãªãã£ã[
ãã㪠]ã
ãã®ã¯ãŒã¯ã·ã§ããã®åå è
ã¯ãå©çšå¯èœãªããŒã«ã䜿çšããŠãSAP R / 3ããã³NetWeaverã·ã¹ãã ïŒã¢ããªã±ãŒã·ã§ã³ãµãŒããŒãšã€ã³ãã©ã¹ãã©ã¯ãã£ãå«ãïŒã®åºæ¬çãªã»ãã¥ãªãã£åæãè¡ãæ¹æ³ãåŠã³ãŸããã
ãŠã§ãã»ãã¥ãªãã£
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Vladimir LepikhinãWebã¢ããªã±ãŒã·ã§ã³ãžã®æ»æã åºæ¬ã ãããªã¯
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ09:00ããïŒã
ãã®ã¬ããŒãã¯ã䟵å
¥è
ã®Webã¢ããªã±ãŒã·ã§ã³ãããªãã¯ãããã³ããŒã«ïŒæååæäžã®äœæ¥çµæã䜿çšããç¹æ®ãªã»ãã¥ãªãã£ã¹ãã£ããŒããŠãŒãã£ãªãã£ïŒã«å¯Ÿããæ»æãå®è£
ããã¡ã«ããºã ãäœç³»çã«æ瀺ããŸããã æ»æã®å®è¡ãå¯èœã«ããWebã¢ããªã±ãŒã·ã§ã³ã®å®éçãªåŒ±ç¹ã¯ãå®éã®äŸãšã䜿çšãããä¿è·ããŒã«ã®æ¬ ç¹ããã³ããããåé¿ããæ¹æ³ã«ãã£ãŠç€ºãããŸããã
ã¬ããŒãïŒ Miroslav StamparããDNSãä»ããããŒã¿æŒæŽ©ïŒsqlmapã®äœ¿çšã[
ãã㪠]ã
ã¹ããŒã«ãŒã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³ã䜿çšããDNSæœåºæè¡ã玹ä»ãããã®é·æãšçæã«ã€ããŠè©±ããèŠèŠçãªãã¢ã³ã¹ãã¬ãŒã·ã§ã³ãè¡ããŸããã
ã¬ããŒãïŒ Vladimir VorontsovããMicrosoftãããã¯ãŒã¯ã®Webã¯ã©ã€ã¢ã³ããžã®æ»æã[
ãã㪠]ã
ãã®ã¬ããŒãã§ã¯ããŠãŒã¶ãŒãMicrosfotãããã¯ãŒã¯å
ã§Internet Explorerãæ»æã§ããæ¹æ³ã«ã€ããŠèª¬æãããªã¢ãŒããµãŒããŒïŒã¢ã¯ã»ã¹ããªã·ãŒã®å¶éãåé¿ïŒãšããŒã«ã«PCã®äž¡æ¹ã«ããæ©å¯ãŠãŒã¶ãŒããŒã¿ã®ååŸãç®çãšããæ»æãæ€èšããŸããã
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Andres RyanchoããSecurity Web 2.0ã é«åºŠãªãã¯ããã¯â [
ãã㪠]ã
ãã¹ã¿ãŒã¯ã©ã¹ã¯ãXMLãHPP / HPCã䜿çšããæ»æãããã³ã¯ãªãã¯ãžã£ããã³ã°ãã»ãã·ã§ã³ããºã«ãªã©ã®æ»æããä¿è·ããããã®ææ³ãæ€èšããŸããã
ã¬ããŒãïŒ Sergey Shcherbelãããã¹ãŠã®PHPãåãããã«åœ¹ç«ã€ããã§ã¯ãããŸãããã ãããªã¯
ãã®ãªã³ã¯ã§å©çšã§ããŸãïŒ16:00ããïŒã
ã¬ããŒãã§ã¯ããŒããã€è匱æ§ã®äŸãšåæ§ã«ããµãŒãããŒãã£ã®PHPå®è£
ã䜿çšããå Žåã®Webã¢ããªã±ãŒã·ã§ã³ã®åäœã®ç¹å®ãããã»ãã¥ãªãã£åé¡ãšæ©èœã調ã¹ãŸããã
ã¬ããŒãïŒ ThibaultKöhlenããNaxsiã¯ããžãã£ãã»ãã¥ãªãã£ã¢ãã«ã«åºã¥ãããªãŒãã³ãœãŒã¹ã®Webã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ã§ãã[
ãã㪠]ã
ã¬ããŒãïŒ Alexey MoskvinããPHPã©ãããŒã®å®å
šãªäœ¿çšã«ã€ããŠã[
ãã㪠]ã
ã¬ããŒãïŒ Vladimir KochetkovããASP.NETã®ãµã€ãããããã³ã°ããŸããïŒ é£ããããå¯èœã ïŒã[
ãã㪠]ã
ãã®ã¬ããŒãã§ã¯ãæ ¹æ¬çã«æ°ããã¿ã€ãã®ãã³ãŒãã€ã³ãžã§ã¯ã·ã§ã³ãæ»æãå«ããæ°ãããŒããã€è匱æ§ã®äŸãšãã®æªçšã®å¯èœãªãã¯ããã¯ãæ€èšŒããŸããã
ã¢ãã€ã«ã»ãã¥ãªãã£
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Manish ChastaããAndroidã®ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ã[
åç» ]ã
ãã®ã¬ããŒãã§ã¯ãAndroidã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ãæ€åºããã³æé€ããããã®ææ³ã«ã€ããŠç°¡åã«èª¬æããŸããã ããã«ããã®ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ãAndroidãã©ãããã©ãŒã ã§å®è¡ãããŠããããã€ã¹ã®ç®¡çè
æš©éãååŸããåé¡ïŒAndroidã«ãŒãã£ã³ã°ïŒãSQLiteããŒã¿ããŒã¹ã®åæãAndroid Debug BridgeïŒADBïŒã®ã¢ããªã±ãŒã·ã§ã³ãã¢ãã€ã«ãµãŒããŒã«é¢é£ããè
åšã«å¯ŸåŠããŸããã Open Web Application Security ProjectïŒOWASPïŒã³ãã¥ããã£ã«ãã£ãŠå
¬éãããã¢ãã€ã«ã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿãã10ã®æãå±éºãªè
åšã®ãªã¹ããèŽè¡ã«æ瀺ãããŸããã
ã¬ããŒãïŒ Marcus NimitzããAndroidã®ãŠãŒã¶ãŒã€ã³ã¿ãŒãã§ã€ã¹ã®ååã[
ãã㪠]ã
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Sergey Nevstroyevããã¢ãã€ã«ã»ãã¥ãªãã£ã®å®çšçåŽé¢ã[
ãã㪠]ã
ããããããã®æŠãã¬ããŒãïŒ Maria Garnayevaããããããã¹ã¿ãŒã®ãã€ãŒã«ã«ã¹ãã£ãã¯ãæ¿å
¥ããæ¹æ³ïŒKelihosãããããããã ãããªã¯
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ09:10以éïŒã
å ±åïŒã¢ã¬ã¯ãµã³ããŒã»ãŽã¹ããã ãã®å ±åæžã¯ããšããšãThe Secret of DuQuããšåŒã°ããŠããŸãããããã®åŸãçºèšè
ã¯FlameãšåŒã°ããæ°ããè
åšã«çŠç¹ãåãããããšã«ããŸããã ãããªã¯
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ14:00ããïŒã
å ±åïŒã¢ã¬ã¯ãµã³ãã«ã»ãªã¢ãã³ãDDosïŒãµãã€ãã«ã®å®è·µã¬ã€ãã ããŒã2ãã ãããªã¯
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ17:03ããïŒã
ã¬ããŒãïŒ Fedor YarochkinãVladimir Kropotovããããããããã®ã©ã€ããµã€ã¯ã«ãšãããã¯ãŒã¯ãã©ãã£ãã¯ã®åæã«ããããããããã®æ€åºã[
ãã㪠]ã
ãã¹ã¿ãŒã¯ã©ã¹ïŒããšãŒã«ãã«ã¯ãã¥ãŒããŒã ãWin32 / Georbotã ãã«ãŠã§ã¢ã®æ©èœãšãã®èªååæâ [
ãã㪠]ã ãã®ããããããäžã®äžçåã®ãã¹ã¿ãŒã¯ã©ã¹ã
ãã¹ã¯ãŒãä¿è·ã®åé¡
ã¬ããŒãïŒ Aleksey Evgenievich Zhukovãã軜éæå·åïŒãªãœãŒã¹ã«å¯ŸããèŠæ±ãå³ãããªããæ»æã«åŒ·ãã ãããªã¯
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ12:00ããïŒã
ã¬ããŒãïŒ Dmitry SklyarovãAndrey Belenkoããã¹ããŒããã©ã³çšã®å®å
šãªãã¹ã¯ãŒããããŒãžã£ãŒãšè»çšã°ã¬ãŒãã®æå·åïŒãCheãseriouslyïŒ..ããã ãããªã¯
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ10:15ããïŒã
ãã¬ãŒã³ããŒã·ã§ã³ïŒ AlexanderïŒSolar DesignerïŒPeslyakãããã¹ã¯ãŒãä¿è·ïŒéå»ãçŸåšãæªæ¥ã[
ãã㪠]ã
ãã¬ãŒã³ããŒã·ã§ã³ã®äžç°ãšããŠããã¹ã¯ãŒãä¿è·ã®åé¡ãéçºå±¥æŽãããã³èªèšŒæè¡ã®åœé¢ã®èŠéããæ€èšãããŸããã
å ±åïŒãã³ãžã£ãã³ã»ãã«ããŒããããã«ããã Windows 8ã®ãã¹ã¯ãŒããå埩ããŸããã[
ãã㪠]ã
ããã«ãŒãšãé
ã»ã¯ã·ã§ã³ïŒ Artyom Sychevãã圌ãã¯ã©ã®ããã«ãéãä¿è·ããŸããïŒã[
ãã㪠]ã
ã¬ããŒãïŒ Dmitry Gorelovãããã·ã¢ã®ã¹ããŒãã«ãŒãïŒå
¬è¡é»è©±ããUECãžãã ãããªã¯
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ10:00ããïŒã
ã¬ããŒãïŒ Alexander MatrosovãEvgeny Rodionovããææ°ã®ãã³ãã³ã°ãã«ãŠã§ã¢ã«é¢ããã¹ããŒãã«ãŒãã®è匱æ§ã ãããªã¯
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ11:07ããïŒã
ãææ°ã®ãã³ãã³ã°ãã«ãŠã§ã¢ã«é¢ããã¹ããŒãã«ãŒãã®è匱æ§ããšããã¬ããŒããäœæããã«ããããã¹ããŒã«ãŒã¯ãã®ãããªããã°ã©ã ã®æãäžè¬çãªãã®ã調æ»ãã2èŠçŽ èªèšŒãšã¹ããŒãã«ãŒãã䜿çšããå Žåã®èå³æ·±ãè匱æ§ãæããã«ããŸããã ããã«ããã®ã¬ããŒãã§ã¯ãæ³å»åŠçæ€æ»ã®å®æœã劚ããæªæã®ããèŠå ãããªãã¯ã«ã€ããŠã説æããŠããŸãã
å ±åïŒãã«ã»ããŒãã³ãããªã³ã©ã€ã³ã§ã¯ã¬ãžããã«ãŒãã§æ¯æããŸããïŒã é çã«åããŸãããã[
ãã㪠]ã
å®çšçãªå®å
šæ§
ãã¹ã¿ãŒã¯ã©ã¹ïŒ Boris RyutinãããŠã€ã«ã¹å¯Ÿçãªãã®ã»ãã¥ãªãã£ã[
åç» ]ã
ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ããã€ã®æšéŠ¬ãæ€åºããåºæ¬çãªã¹ãã«ãç¿åŸãã4æéã®ãã¹ã¿ãŒã¯ã©ã¹ã¯ãWindowsçšã®ããã€ã®æšéŠ¬ïŒSpyEyeãCarberpãDuquïŒãéçºããããã®æãé«åºŠãªæè¡ãç 究ããAndroidçšã®ããã€ã®æšéŠ¬ã調ã¹ãçŸåšã®ãšã¯ã¹ããã€ãïŒPDFãJavaïŒã®åæã«ã粟éããŸããã
ã¬ããŒãïŒãŠãŒãªã»ã°ãããããå¹²ãèã®å±±ã§è±¡ãèŠã€ããæ¹æ³ã[
ãã㪠]ã
ã¬ããŒãïŒ Dmitry Evdokimovããã³ãŒãåæããŒã«ïŒæããé¢ãšæãé¢ã[
ãã㪠]ã
Dmitryã¯ããœãŒã¹ã³ãŒãããã€ãã³ãŒãããã€ããªã³ãŒããã€ã³ã¹ãã«ã¡ã³ãããæ¹æ³ãæ€èšããŸããã
ã¬ããŒãïŒ Nikita TarakanovãAlexander Bazhanyukããèªåè匱æ§æ€çŽ¢ããŒã«ãã ãããªã¯
ãã®ãªã³ã¯ã§å©çšã§ããŸãïŒ17:00ããïŒã
ã¬ããŒãïŒ Igor KotenkoãããœãããŠã§ã¢ãšãŒãžã§ã³ãã®ãµã€ããŒæŠäºïŒã€ã³ããªãžã§ã³ããšãŒãžã§ã³ãã®ããŒã ã¯ãŒã¯ã®çè«ãå¿çšãããµã€ããŒè»éã®æ§ç¯ã[
ãã㪠]ã
ã¬ããŒãïŒ Ulrich FleckãMartin Eisnerãã人æ°ã®ãããã¬ãŒã ã¯ãŒã¯ã®äŸã§0æ¥ããAPTãžã®æ»æã[
ãã㪠]ã
ã»ã¯ã·ã§ã³ïŒãã¢ã»ã¯ã·ã§ã³ãäžåºŠèŠãã»ããããã ãããªã¯
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ17:10以éïŒã
å¿åããã³LulZ
ã¬ããŒãïŒãžã§ãªãŒã¬ã³ããªã³ããLulzSecã¹ããŒãªãŒããäœãåŠã¶ããšãã§ããŸãïŒãŸãããããã¹ããïŒã[
ãã㪠]ã
è¬æŒäžããžã§ãªãŒã¯äººã
ã®ã°ã«ãŒãã«ããããããŒãªã³ã°ãã®å¯Ÿè±¡ã«ãªããŸããããé©ããããªãŠãŒã¢ã¢ã®ã»ã³ã¹ã«åå¿ããŸãã[
ãã㪠]ã
å ±åïŒãã€ãŒã ã»ãšã«ã»ããŒã«ãããã¥ããžã¢ã¯ã©ã®ããã«å¿åã«çŽé¢ãããã ãããªã¯
ãã®ãªã³ã¯ããå
¥æã§ããŸãïŒ14:10ããïŒã
ãã®ä»ã®ãããã¯
å ±åïŒã¢ã¬ã¯ã»ã€ã»ã¢ã³ãã¬ãŒãšãïŒããŒã·ãŒã»ã·ã§ãªãŒïŒãããµã€ããŒãã³ã¯ã®éå»ãšæªæ¥ã[
åç» ]ã
ã¢ã¬ã¯ã»ã€ã¯ããã·ã¢ã®ãµã€ããŒãã³ã¯ã®çºå±ã«é¢ãã圌ã®èŠè§£ãå
±æããŸããã
å ±é
¬ïŒåè³è
ã«ã¯è³å[
ãã㪠]ãèŽãããŸãã
ã³ã³ãµãŒãïŒãã©ãŒã©ã çµäºæã®Underwoodã°ã«ãŒã[
ãã㪠]ã
PS以äžã§ã¯ãPositive Hack Days 2012ãã©ãŒã©ã ã«é¢ããã¬ãã¥ãŒãå«ãããŸããŸãªããã°ã®ãšã³ããªãžã®ãªã³ã¯ãå
¬éããŠããŸãã
sgordey.blogspot.com/2012/06/phdays.htmlandreicostin.com/index.php/brain/2012/06/08/phdays_2012_overviewsgordey.blogspot.com/2012/06/blog-post_07.htmlwww.itsec.pro/2012/06/phdays.html#moreblog.eset.com/2012/06/05/smartcard-vulnerabilities-in-modern-banking-malwarealekskrasnov.blogspot.com/2012/06/phdays-everywhere.htmlhashcat.net/forum/thread-1246.htmlxanadrel.blogspot.fr/2012/06/phd-hash-runner-contest.htmlforum.insidepro.com/viewtopic.php?p=95655#95655lexa.livejournal.com/47491.htmldevteev.blogspot.com/2012/06/phdays-2012.htmlamatrosov.blogspot.com/2012/06/phdays2012.htmlc3ret.wordpress.com/2012/06/04/positive-hack-days-2012blog.scrt.ch/2012/06/04/ctf-phdays-2012ax330d.blogspot.de/2012/06/positive-hack-days-2012-moscow.html asintsov.blogspot.de/2012/06/phdays-write-up.htmltoxa.livejournal.com/549105.htmloxod.ru/?p=367scii.ru/_shr/2012/06/phdays-2012-%D0%B2%D0%BF%D0%B5%D1%87%D0%B0%D1%82%D0%BB%D0%B5%D0%BD ïŒ
D0ïŒ
B8ïŒ
D1ïŒ
8Fvkochetkov.blogspot.de/2012/06/phdays-2012.htmljerrygamblin.com/post/24221592284/phdaysjerrygamblin.com/post/24165573828/trolled-in-russiawww.tsarev.biz/informacionnaya-bezopasnost/positive-hack-days-2012-poslevkusieraz0r.name/other/phdays-snatch-writeupi-business.ru/blogs/20371www.securitylab.ru/blog/personal/secinsight/22549.phpsecuregalaxy.blogspot.com/2012/06/dery.htmlTwitterã§ãã©ãŒã©ã ããŒããèªã¿ããïŒãŸãã¯TwitterãããŒããã£ã¹ãã
èªã¿çŽããã ïŒå Žåã¯ãããã·ã¥ã¿ã°
#PHDaysã䜿çšããŠãã ããã