
æ
å ±ã»ãã¥ãªãã£ã®å°é家ãšãããã¯ãŒã¯æ»æè
ãšã®æŠãã¯ãããªãŠããæ ç»ã ãã®çŸããã·ã§ãŒã®ããã«èŠããããšãé·ãéç¥ãããŠããŸãã ããããå®éã«ã¯ãå®éã®æ»æãšã»ãã¥ãªãã£ã³ã³ãã¹ãã®äž¡æ¹ã¯ãæ°åŠçãªãªãªã³ããã¯ã«äŒŒãŠããããšãå€ãããã®çŸããã¯ãããããããè©äŸ¡ã§ããŸããã
ããã§ããä»å¹ŽãPositive Hack Days VIIäŒè°ã®ã¡ã€ã³ã³ã³ããã£ã·ã§ã³ã§ããã
Confrontation ãã®äž»å¬è
ã¯ããã®è«äºã®çãšãªã£ãŠãã課é¡ã解決ããããã«å¯èœãªéãããããããšãè¡ããŸããã ãããŠãæåãããšæããŸãã ããã30æéã®ã³ã³ãã¹ãã§ãããã«ãŒããŒã ã¯ãç¡ç·éä¿¡ãç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®äœã¬ãã«ã®è匱æ§ãåçŽãªãã«ãŒããã©ãŒã¹ãããã³è€éãªå€æ®µé䟵å
¥ã¹ããŒã ãç©æ¥µçã«äœ¿çšããŠãè¿ä»£éœåžã®ãªããžã§ã¯ãããã³ã€ã³ãã©ã¹ãã©ã¯ãã£ã«å¯Ÿããå€ãã®æåããæ»æãå®èšŒããŸããã
ãã®èšäºã§ã¯ãäž»èŠãªã€ãã³ãã®å¹Žè¡šã埩å
ãã倧èŠæš¡ãªãµã€ããŒæ³šæã®äžéšãèŠçŽããŸãã
åæ¥ïŒåµå¯ãšãŠã©ãŒã ã¢ãã
11:00
ã察ç«ãã®åå è
ã¯èªåã®åžã«åº§ããã¹ã¿ã³ããå匷ããŸãã
æ»æããŒã ã¯æåã®ãããã¯ãŒã¯ã¹ãã£ã³ãéå§ããŸãã ãã£ãã§ã³ããŒããŒã ã¯ãåŒãç¶ãã»ãã¥ãªãã£ã·ã¹ãã ãæ§æãããã©ãã£ãã¯ã®èª¿æ»ãéå§ããŸãã
ãããŠãéä¿¡äºæ¥è
ã2ã€ã®äŒç€Ÿã®ãªãã£ã¹ãç«åçºé»æãé»æ°å€é»æãç³æ²¹ãééäŒç€Ÿãå¶æ¥ããŠããéœåžå
šäœãå®ãå¿
èŠããããŸãã ããã«ããã®éœåžã«ã¯å€æ°ã®ææ°ã®IoTããã€ã¹ããããŸãã ã察決ãã®ã«ãŒã«ã«åŸã£ãŠãé²åŸ¡ããŒã
ã¯ãªããžã§ã¯ããäºãã«
åæ£ãããŸããã
13:00
ããã«ãŒããŒã ã®1人ãé²åŸ¡åŽã®å®¿æ³ãšãªã¢ã«å
¥ãããšè©Šã¿ãã€ã³ãã©ã¹ãã©ã¯ãã£ãšãããã¯ãŒã¯ããããžã«é¢ããè³æãæ®ããŸãã
ãããã®ãªãã©ã€ã³æ»æã¯ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã䜿çšããŸãã ããŒã ã®1ã€ã¯ãäž»å¬è
ããã®åœã®ãã¹ã䜿çšããŠãé²åŸ¡è
ããããŒã¿ãååŸããããšããŠããŸãã èšè
ãè£
ã£ãå¥ã®ããŒã ã®ä»£è¡šè
ã¯ãã察決ãã®äž»å¬è
ãã瀟äŒçãã«ããŠããŸãã
ååŸ2æ
2ã€ã®ããŒã ãæåã®éèŠã§ã¯ãªãè匱æ§ããã°ããŠã³ãã£ã«éä¿¡ããŸãã è匱æ§ã®1ã€ã¯ãã¹ããŒãããŒã 管çã³ã³ãããŒã©ãŒã«èŠã€ãããŸããã
16:00
競äºã¯ãã£ãããšé²ãã§ããŸãããååŸã«ãªã£ãŠæ»æããŒã ã¯ãã€ã³ããç²åŸãå§ããŸããããã¯ãäž»ã«éœåžã®ããžã¿ã«ã€ã³ãã©ã¹ãã©ã¯ãã£ã§ã¡ãŒã«ã¢ã«ãŠã³ããšã¯ã¬ãžããã«ãŒãçªå·ãèŠã€ããããã§ãã ãããããã®ãããªçºèŠã«å¯Ÿããå ±é
¬ã¯å°ãªãã100ãã500ã®ãããªãã¯ã¢ã«ãŠã³ãã§ãã Publiã¯ã¿ã€ããã¹ã§ã¯ãªããéœåžã®ä»®æ³é貚ã§ãã BIZoneã¯ã©ã³ãã³ã°ã®ãªãŒããŒã§ãã1瀟ã®ç¡é²åãªWebãµã€ãããããã³ã°ããããã«100,000ãåãåããŸããã
ååŸ5æ
Team CARKAã¯TeamViewerã§ã¢ã«ãŠã³ããèŠã€ããŸãã
éœåžã€ã³ãã©ã®èŒžé管çã·ã¹ãã ã®é éå¶åŸ¡ã ãããã®ã¢ã«ãŠã³ãã§ãã£ã¹ãããã·ã¹ãã ã«ãã°ã€ã³ããããšã§ãããã«ãŒã¯æ¥äžã«ä¿¡å·æ©ãå€éã¢ãŒãã«åãæ¿ããŸãã ãããããã©ãã£ãã¯ã¯ããŸãå€åããããã°ãããããšãã¹ãŠãéåžžã®åäœã«æ»ããŸãã
19:00
CARKAã¯æåã®å Žæã§æ¥äžæããŠããŸããã«ã¶ãã¹ã¿ã³ã®ããã«ãŒã°ã«ãŒããåžé·èªèº«ã®SMSãååããããšãã§ããŸããã ãããã®ç§å¯ã®ã¡ãã»ãŒãžã§é倧ãªåŠ¥åã®èšŒæ ãæããã«ãªããCARKããŒã ã¯äžåºŠã«150,000件ã®åºçç©ãåãåãããšãã§ããŸããã 圌ãã¯ã©ããã£ãŠãããããŸãããïŒ ç§ãã¡ã¯ãosmocomé»è©±ãŸãã¯SDRïŒäž¡æ¹ã䜿çšïŒã䜿çšããŠã©ãžãªãèŽããŸããã
ååŸ10æ
CARKAããŒã ãšBizoneããŒã ã¯ãã¹ã¿ã³ãã§ç©ºè¥²ãçµç¹ãå§ããå©çšå¯èœãªãã¹ãŠã®ãã®ã«æ¥ç¶ããããšããŸãã
00:00
æãèŠæããŠãããã£ãã§ã³ããŒããŒã -Jet Security Team-ã¯ãéœåžéä¿¡ã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ãµãŒããŒãšã¯ã€ã€ã¬ã¹ã¢ã¯ã»ã¹ãã€ã³ããã€ã³ã¹ããŒã«ããè©Šã¿ãæåã«é»æ¢ããŸãã æ»æåŽã®VulnersããŒã ã¯ãé²åŸ¡è
ã®ãã©ãã£ãã¯ã確èªããŠã¢ã¯ã»ã¹ãã€ã³ãçµç±ã§ç®¡çã§ããããã«ããããã«ãéçããééã«ãå
¥ããããšèããŠããŸããã
02:00
ãžã§ããã»ãã¥ãªãã£ããŒã ã®é²åŸ¡ããŒã ã¯ãåžã®ç£æ¥ã·ã¹ãã ã®ã¹ã¿ã³ãã«ç©ççã«æ¥ç¶ããè€æ°ã®è©Šã¿ãé»æ¢ããŸãã ãã§ã«èšåããããŒã ã«å ããŠãããã«ãŒã°ã«ãŒãã®KanzasCityShuffleã¯ããã®ãããªæ»æã§æ³šç®ãããŸããã
åæ¥ããŒãã«2æ¥ç®ïŒãã¹ãŠãå£ããŸãïŒ
å€ã¯ããã«ãŒã®æ代ã§ãããæ»æè
ã¯ããã蚌æããŸããã ããã€ãã®ããŒã ã400äžäººä»¥äžã®åžæ°ãåžã®éè¡ããçã¿ãŸããã Rdotããã³CARKAããŒã ã¯ã以åã«çãã ãŠãŒã¶ãŒè³æ Œæ
å ±ã䜿çšããŠæ»æããããããªã¢ãŒããã³ãã³ã°ãµãŒãã¹ã·ã¹ãã ã䜿çšããŠå€§éã®è³éãåŒãåºãããšãã§ããŸããïŒ280äž-Rdotã130äž-CARKAïŒã
åæã«ãCARCAã¯éè¡èªäœã®è匱æ§ãå©çšããŠãRdotããŒã ã¢ã«ãŠã³ããããã¹ãŠã®ãéãçã¿ãŸããã ãããã圌ãã¯å¯Ÿç«ã®ã«ãŒã«ã«éåããŸãã-éè¡ããã®äžéšã§ãã察ç«ã€ã³ãã©ã¹ãã©ã¯ãã£ãå£ããªãããã§ãïŒããŒã ã«è³åãçºè¡ããããã«äœ¿çšãããŸãïŒã ãã®ããããéã¯RdotããŒã ã«è¿ãããŸããã
äžæ¹ãVulnersããŒã ã¯å¥ã®æ¹æ³ã䜿çšããŸãããç¹å¥ãªããããããåžã®äœæ°ã®å€ãã®å±æ®åããéè¡ã«ãŒãããå°éïŒå10ã«ãŒãã«ïŒãåŒãåºãå§ããŸããã åæ§ã®æ»æãã°ã«ãŒãHack.ERSã«ãã£ãŠå®è¡ãããŸããã
å®éã«ã¯ããã®ãããªæ»æã¯ã倧éã®1åéãã®çªçãããç®ç«ããªããã®ã§ãã ãã ãããã®æ¹æ³ã«ã¯æéããããããã®å Žåã¯ååã§ã¯ãªããå€ãã®ãéãåŒãåºãããšãã§ããŸããã§ããã
ããããéè¡ããã®åèš400äžä»¶ä»¥äžã®çé£ïŒç§ãã¡ã®çºã®ãéã®50ïŒ
以äžïŒã¯ãçã®çµæžå±æ©ãåŒãèµ·ãããŸããã
ãã¬ã³ã ã«å¯Ÿããæ»æã¯ååäžãç¶ããŸããã AntichatããŒã ã¯ãAsterisk WebããŒã¹ã®ç®¡çã€ã³ã¿ãŒãã§ã€ã¹ïŒVoIPãã¬ãã©ããŒãµãŒããŒïŒããããã³ã°ãããã¹ãŠã®ãŠãŒã¶ãŒã®ãã°ã€ã³ãšãã¹ã¯ãŒãããã·ã¥ãååŸããããšãã§ããŸããã ããããé»æ°éä¿¡ã®æ¯æè
ã¯ãã®ã¢ã¯ãã£ããã£ãããã«çºèŠããæ»æãé²ãããã«ããã«Webã€ã³ã¿ãŒãã§ã€ã¹ãžã®ã¢ã¯ã»ã¹ããããã¯ããŸããã
12:00
ããã«ãŒã¯ç£æ¥éšéã«åå
¥ããŸãããBIZoneããŒã ã¯ã2ã€ã®éœåžäŒæ¥ïŒç«åçºé»æãšç³æ²¹ç²Ÿè£œæïŒã®äœæ¥ãäžåºŠã«åæ¢ããŸããã ããã¯ãèŸæžãã¹ã¯ãŒãã䜿çšãããWi-Fiãããã¯ãŒã¯ãä»ããæ»æã®ãããã§å¯èœã«ãªããŸããã ç£æ¥çšãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãååŸããããã«ãŒã¯ãç«åçºé»æã®é»æ°éšåãä¿è·ããããã«äœ¿çšããããªã¬ãŒãªãŒãã¡ãŒã·ã§ã³ã·ã¹ãã ïŒRPAïŒãçºèŠããŸããã ããã«ãŒã¯ããšã³ãžãã¢ãªã³ã°ãœãããŠã§ã¢ã䜿çšããŠãã®æ©åšãåæ§æããããšããŠ1æéãè²»ãããåŸãæ»æãã¯ãã«ãå€æŽããããšã«ããŸããã å¿
èŠãªãšãã«ã®ãŒãããã³ã«ãååŸããä»ã®ãšã³ãžãã¢ãªã³ã°ãœãããŠã§ã¢ãããŠã³ããŒãããåŸãå€é»æãžã®é»æºããªãã«ããããšãã§ããŸããã ãã®çµæãCHPPã§åããšã³ãžãã¢ãªã³ã°ã¹ã¿ããã¯ããã€ã©ãŒãšã¿ãŒãã³ã®é転ãåæ¢ããªããã°ãªããŸããã§ããã CHPPã®å®å
šãªïŒäžæçã§ã¯ãããïŒã·ã£ããããŠã³ãã補油æã®é転ã«åœ±é¿ãäžããŸãããAVTã®èžçå¡ã¯éç±èžæ°ãªãã§æŸçœ®ãããŸããã
ãã®ããã«ãWi-Fiã®èŸæžãã¹ã¯ãŒãã1ã€äœ¿çšããããšã§ãBIZoneããŒã ã¯2ã€ã®ç£æ¥æœèšãäžåºŠã«éã¢ã¯ãã£ãåããããšãã§ããã©ã³ãã³ã°ã§ãããã«ãªããŸããã æ²ããããªã誰ãéœåžã®ãšãã«ã®ãŒéšéãä¿è·ããŠããŸããã ãããã£ãŠãç£æ¥æœèšãžã®æ»æãç¶ãå¯èœæ§ããããŸãã
CHPã®åæ¢ãæåŸã®ãã€ãº13:30
æããªã£ãŠããŸããïŒ CARKããŒã ã¯åã³éè¡ããæ°çŸäžãçã¿ãåã³é ç¹ã«éããŸããã ããã¯ã©ã®ããã«ããŠçããã®ã§ããïŒ å®æçãªã¡ã³ããã³ã¹äžã«ãäžæ£é²æ¢ã·ã¹ãã ãæ¥ç¶ããéãäž»å¬è
ã¯æåéãéè¡ã1åéç¡é²åã®ãŸãŸã«ããŠããå¿
èŠããããŸããã ãããŠãCARKãå€ãã®ãéãåŒãåºãããšãã§ããã®ã¯ãã®æã§ããã èªååã®å·§ã¿ãªäœ¿ãæ¹ããããŸãïŒ
15:30
CARKãšBIZoneã¯1äœäºããç¶ããŠããŸãã ã«ã¶ãã¹ã¿ã³ã®ããŒã ã¯ãçãŸãããéã§ç¯çœªè
ã®è»ãèŠã€ããããšãã§ããŸããã ããã«ãŒã¯osmocomé»è©±ã䜿çšããŠãè»ã®GPSãã©ãã«ãŒããéä¿¡ãããSMSãååããŸããã ãããã£ãŠã圌ãã¯ããªããGPSãã©ãã«ãŒãå¶åŸ¡ã§ããããã¯ã€ããã³ããŒããèšç®ãã次ã«ãã³ããŒãå€æŽãããã©ãã«ãŒã«ã³ãã³ããéä¿¡ããŠè»ã®åº§æšãäŒããŸããã
ã»ãŒåæã«ãBIZoneããŒã ã¯åã³ç²Ÿè£œæãåæ¢ããããšãã§ããŸããã 以åã¯ãå€é»æãšç«åçºé»æãžã®æ»æãéããŠãã§ã«ãããè¡ã£ãŠããŸãããããã®å Žåãçºé»æã«çŽæ¥æ»æãè¡ãããŸããã æåã«åœŒãã¯å·¥å Žã®Wi-FiïŒãã¹ã¯ãŒãéžæïŒãæ»æãã次ã«å·¥å Žã®ãããã¯ãŒã¯ã«å
¥ããçç£ã«äœ¿çšãããŠããã³ã³ãããŒã©ãŒãèŠã€ããŸããã ã€ã³ã¿ãŒãããã§èŠã€ãã£ãPLCã®æ
å ±ã調ã¹ããšãããæ»æè
ã¯æ¢ç¥ã®è匱æ§ïŒãšã¯ã¹ããã€ãïŒãçºèŠããAVTã®ã³ã³ãããŒã©ãŒãåæ¢ããããšãã§ããŸããããã®çµæãã€ã³ã¹ããŒã«ã¯å¶åŸ¡ãšç£èŠãªãã§ãã°ããã®éæ®ããŸããã
補油æïŒãã©ã°ã¡ã³ãïŒ16:00
ã察ç«ãã¯çµãã£ãã ãããã審æ»å¡ã¯ãŸã æåŸã«å®äºããã¿ã¹ã¯ããã§ãã¯ããŸãããã§ã«è¿°ã¹ããªãŒããŒïŒCARKAãšBIZoneïŒã«å ããŠãä»ã®ããŒã ãããã€ãã®æåããŸãããã競äºã®æåŸã®1æéã§ãé«äŸ¡ã§ã¯ãªããæ»æãè¡ããŸããã
ãã®ãããHack.ERSããŒã ã¯SIPãã¬ãã©ããŒãŠãŒã¶ãŒã®ãéãçãããšãã§ããŸãããã¢ã«ââãŠã³ããç Žå£ããããšã§ãããã«ãŒã¯ææã®çãçªå·ãžã®åŒã³åºãã䜿çšããŠãåçåãããŸããã ããããæ»æè
ã¯ç«¶äºã®æåŸã«ã®ã¿ãã®æ©äŒãçºèŠãããããåŒãåºããéé¡ïŒçŽ300,000ïŒã§ãªãŒããŒã«ãªãããšã¯ã§ããŸããã§ããã
ãããŠã競äºã®æåŸã®æåŸã®True0xA3ããŒã ã¯ãåçŽãªæ¹æ³ã§ãå
·äœçãªçµæã«ã€ãªããããšã蚌æããŸããã åçŽãªãŠãŒã¶ãŒã®1人ã®ããŒã ã«ãŒã¿ãŒãã¯ã©ãã¯ããæ»æè
ã¯ããããèªå®
ã®ã³ã³ãã¥ãŒã¿ãŒã«å€§äŒæ¥ã®è²¡åè«žè¡šãä¿åããäŒèšå£«ã§ããããšãçºèŠããŸããã ãã®æ»æã«ãããããŒã ã¯50äžäººã«ãªããŸããã
ãŸããKanzasCityShuffleããŒã ãã¹ããŒãããŒã ããããã³ã°ããAntichatããŒã ãWebã«ã¡ã©ã«ã¢ã¯ã»ã¹ã§ããããšãå€æããŸããã ããã«ãäžéšã®ããŒã ã¯ããã°ããŠã³ãã£ããã°ã©ã ã§ä»ã®å€ãã®é倧ãªè匱æ§ãçºèŠããŠè¿ããŸããã ãããã£ãŠããã¹ãŠã®ã¿ã¹ã¯ã®æ€èšŒã¯ãæŠéçµäºåŸ2æé以å
ã«è¡ãããŸãã
ã¹ããŒãããŒã ã¢ãã«ïŒãã©ã°ã¡ã³ãïŒçµæïŒä¿è·ã¯ã©ãã«ãããŸããïŒ
ã³ã³ãã¹ãã®æåã®3ã€ã®å Žæã¯ã
CARKA ã
BIZone ãããã³
Rdot.orgãç²åŸããŸãã ã æçµçãªè©äŸ¡ã¯
ããã«ãããŸã ã äžè¬çã«ãä»å¹Žã®ããã«ãŒã¯ãéåžžã«å¹
åºãã€ã³ããªãžã§ã³ã¹ãšæ»æããŒã«ãéåžžã«çæéã§äœ¿çšããŠããã®æ å
ã極ããŸããã
確ãã«å€ãã®äººãçåãæ±ãã§ãããããã£ãã§ã³ããŒã¯ã©ãã«ããã®ã§ããããïŒ ããã§ã¯ãçŸåšã®ã察ç«ããæºåããéã«ãäž»å¬è
ã¯æšå¹Žã®åé¡ãèæ
®ã«å
¥ããããšã説æãã䟡å€ããããŸããããã¯ãé²è¡ãããŸãã«ãæºåãããããã¹ãŠã®ããããç· ãããããšãå€æãããšãã§ãã ãããã£ãŠãçŸåšã®ç«¶äºã§ã¯ãé²åŸ¡åã匱ãã ãã§ãªããããçŸå®çã§ããã ç¹ã«ãé²åŸ¡åŽã¯ã»ãã¥ãªãã£ã³ã¹ãã®å±æ©çåæžãšããå³ããæ¡ä»¶ã«çœ®ãããŸãããåããŒã ã¯ã10,000æã®ä»®æ³ãããªãã·ã¥ã®éã§ä¿è·å
·ã賌å
¥ããããã®åºå®äºç®ãæã£ãŠããŸããã ããã«ãäžéšã®æœèšãšã€ã³ãã©ã¹ãã©ã¯ãã£ã¯å®å
šã«ä¿è·ãããã«æŸçœ®ãããŠããŸãã-å®éã®ç掻ã§èµ·ãã£ãŠããããšã§ãã
ãGSMã«å¯Ÿããæ»æã®å Žåãé²åŸ¡åŽã¯åœ±é¿ãäžããããšã¯ã§ããŸããã§ããããäœãèµ·ãã£ãŠããã®ããèŠãããšãã§ããŸããããšãPositive Technologiesã®éä¿¡ã·ã¹ãã ã»ãã¥ãªãã£ç 究ã°ã«ãŒãã®è²¬ä»»è
ã§ããã察ç«ã®äž»å¬è
ã®1人ã§ããPavel Novikovæ°ã¯è¿°ã¹ãŸããã -ç§ãã¡ã¯åœŒãã«ç¡ç·ã®ç©ºæ°ã®ãã³ããäžããŸãããã圌ãã¯äœãèŠã€ããŸããã§ããã ããã«ãç§ãã¡ã®èãã«ããã°ãé²åŸ¡è
ã¯SIPãä»ãããéã®åŒãåºããé²ãããšãã§ããŸãã ããããã圌ãã¯ç±å¿ã«é³å£°é話ãçæããç§ãã¡ã®ãã§ãã«ãŒã«ãã£ãŠæ··ä¹±ããŠããŸããïŒåç¬éã«5-10ã®åæé³å£°æ¥ç¶ããããŸãããããã®äžã§é²åŸ¡è
ããããã³ã°æŽ»åãèæ
®ããããšã¯éåžžã«å°é£ã§ããããããã¯ãŸãã«çŸå®ã®äžçã§èµ·ãã£ãŠããããšã§ãã èãããã2çªç®ã®çç±ã¯ããã®æ¹æ³ã§ãéãåŒãåºããšããæ»æè
ã«ããæ€åºã®é
ãã§ãããé²åŸ¡è
ã«ã察å¿ããæéããããŸããã§ããã äžæ¹ããã¬ã³ã ã®æ¯æè
ã¯ãã¢ã¹ã¿ãªã¹ã¯ãµãŒããŒã®ãããã³ã°ãé²ãããšãã§ããŸããã ãã®åé¡ã«ãããéåžžã«é«ãå¹çã«æ³šæããå¿
èŠããããŸããã
ã察決ãã®ããã«ç£æ¥æœèšã®ã¹ã¿ã³ããçµç¹ããèªåå¶åŸ¡ã·ã¹ãã ã®å®å
šæ§ã®å°é家ã€ãªã€ã»ã«ã«ããã¯ã補油æãžã®æ»æãçºçããå Žåãé²åŸ¡è
ã¯ãã®ãããªç¶æ³ã§ã§ããéãã®ããšãè¡ã£ããšè¿°ã¹ãŸããã ã圌ã¯ããã£ãã§ã³ããŒãã€ã³ã·ãã³ãã«å³åº§ã«å¯Ÿå¿ããããšãèš±å¯ããŸããã§ãããããã¹ã¯ãŒãããã°ããå€æŽããããšã«ãããæ»æè
ãç¹°ãè¿ãæ»æãã¿ã€ã ãªãŒã«åæ¢ããããšãèš±å¯ããŸãããã
PHDays Mikhail Levinã®çµç¹å§å¡äŒã®ã¡ã³ããŒã§ããã察ç«ãã®ããã³ããã³ã«ãããšãä»å¹Žã®ã³ã³ãã¹ãã¯æ¬åœã«æåãããããã«ãŒã®åŸ©venãã¯èšèã ãã§ãªããå®éã«ãè¡ãããŸããããã®ãããªãµã€ããŒããã«åœ¢åŒã¯ãåå è
ãšèŠ³å®¢ã®äž¡æ¹ã«ãšã£ãŠèå³æ·±ããã®ã§ãã ãããŠæãéèŠãªããšã¯ããã®ã€ãã³ãã«ãããæ
å ±ã»ãã¥ãªãã£ã®åé¡ã«äžè¬å€§è¡ã®æ³šæãåŒãããšãã§ããããšã§ãã
åå è
ã®å°è±¡
äžã«æžãããŠããã®ã¯ãäž»å¬è
ããã®ç«¶äºã®æ§åã§ãã ããã§ã¯ãåå è
èªèº«ãã察ç«ãã«ã€ããŠèããŠããããšãèããŠã¿ãŸããããæ»æè
ã®äž»èŠãªããŒã ã§ãããé²åŸ¡ã®ä»£è¡šè
ã§ããããŸãã
CARKããŒã ïŒãã©ã¯ãŒãïŒïŒãå°è±¡ã¯ãšãŠãè¯ãã§ãã å®éãç§ãã¡ã¯åå©ããæåŸ
ããŠããŸããã§ãããç§ãã¡ã«ãšã£ãŠãããã¯ã察ç«ãèªäœãžã®æåã®åå ã§ãã£ããããåå ããããšãç®æããŠè¡ããŸããã ããããæçµçã«åã€ããšãå€æããŸããã 1æ¥ç®ã®çµããã«ããªããšã1äœã«ãªã£ããšããç§ãã¡ã¯æãåæ°ãåºããŸããã ããéãããã¯ãªãã£ãã®ã§ãããŒã å
šå¡ã§å€ãéããããšã«ããŸããã ããç¬éãç§ãã¡ã¯éåžžã«å¹žéã§ãã-ç¹ã«ãéè¡ã皌ãã 5åéã®çªãã2æ¥ç®ã«ãªã£ããšããåžæ°ããåã³ãéãçãããšãã§ããŸããã SCADAã·ã¹ãã ããããã³ã°ããããšã¯å°ãå°é£ã§ããããGSMãžã®æ»æã§ãããè£ããŸããã
2æ¥ã§ã·ã¹ãã ãç解ããããããã¯ã©ãã¯ããæéãå¿
èŠãªå Žåãç§ãã¡ã¯è¯ãçµéšãåŸãŠãããŒã ãã¹ãã¬ã¹ã®å€ãç¶æ
ã§ãã¹ãããŸããã ç§ãã¡ã®å€§ããªãã©ã¹ã¯ãããŒã ã¡ã³ããŒãããŸããŸãªåéïŒGSMããªããŒã¹ãªã©ïŒãå°éã«ããŠããããšã§ãã ããšãã°ãäžéšã®ããŒã ã§ã¯ãã¬ã€ãã©ã€ã³ã¯Webãä»ããæ»æã®ã¿ã§ãããã
BIZoneããŒã ïŒãã©ã¯ãŒãïŒïŒãç§ãã¡ã¯æåã«å€§ããªä»»åãåŒãæž¡ããŸããããã®ãããç§ãã¡ã¯é·ãéãªãŒããŒãæ¡ã£ãŠããŸãããçµå±ãç§ãã¡ã«ãšã£ãŠç°åžžã«ç°¡åã§ããããã«æããŸããã
ç§ãã¡ã«è¡ãããç©ççãªæ»æã«æ³šæããå¿
èŠããããŸããåå3æãããå人ã¢ã«ãŠã³ããé€ãã²ãŒã ã€ã³ãã©ã¹ãã©ã¯ãã£å
šäœã«ã¢ã¯ã»ã¹ã§ããªããªããŸããã ã¹ã€ããã®1ã€ã«åé¡ããããšããåçãåãåã£ãç§ãã¡ã®ããŒã ã®å€ãã®ã¡ã³ããŒã¯å°±å¯ããŸããããååäžã«ç¶æ³ã¯å€ãããŸããã§ãããç§ãã¡ã¯èª°ããåé¡ãæ±ããŠãããšå€æããSCADAããã³IoTç©çã¢ã¯ã»ã¹ãµãŒãã¹ã«åãæ¿ããŸããã ããããååŸ2æããã«ã¯ããã®ãããªæ·±å»ãªåé¡ãããªãã£ãããšãå€æããäž»å¬è
ãšã®èª¿æ»ã«ãããå
éšãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ã§ãããã€ã¹ããã¢ã±ãŒãã«ãã¹ã€ããã®ééã£ãããŒãã«ããã·ã¥ãããããšãããããŸããã ãã®çµæãã»ãŒ12æéãã¡ã€ã³ã®ã²ãŒã ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã¢ã¯ã»ã¹ã§ããŸããã§ããã
ãŸããååäžã«ãã¹ãŠã®ããŒã ã®ãã€ã³ãæ°ã10åã«ãªã£ããšããéåžžã«é©ããŸããïŒéè¡ããå€ãããéé¡ãåŒãåºãããããã«çºçããéé¡ïŒã ç§ãã¡ã®ããŒã ãç¿æ¥ã«ã¿ã¹ã¯ã解決ãããšããæåã®æ¥ã¯800,000 PUBã2æ¥ç®ã¯8,000,000 PUBãšèŠç©ãããããã®çµæã2,000,000ãç§ãã¡ã«è»¢éãããŸãããç§ãã¡ã«ãšã£ãŠãã€ã³ãã¯æåã®å Žæã«ååã§ãããã ãããããã®ãããªäžéæãªã¢ãã¡ãŒã·ã§ã³ãããã€äœæããããã¯ããŸã èå³æ·±ãã§ããã
Rdot.OrgããŒã ïŒãã©ã¯ãŒãïŒïŒãäž»å¬è
ã¯é²åŸ¡åŽã«æå©ãªäžåè¡¡ã解æ¶ããã¿ã¹ã¯ãããå
·äœçã«ããããšãããããå°è±¡ã¯æšå¹ŽãããåªããŠããŸãã ãã ãã競äºã®åœ¢åŒã¯äŸç¶ãšããŠè€éãããŠãå®å
šã«å®çŸããããšã¯ã§ããŸããã ç¹ã«ããµãŒãã¹ã®å¯çšæ§ã¯äœãã£ãã æºåãããã¿ã¹ã¯ã¯é¢çœããŠå€æ§ã§ããããšãããããŸããã競äºåœ¢åŒãäžå®å
šã§ããããããããã«å¯æ¥ã«å¯ŸåŠããããšã¯ã§ããŸããã CTF圢åŒãæãç°¡æœã§å®çšçãªç«¶äºåœ¢åŒãšããŠé·å¹Žã«ããã£ãŠæ€èšŒãããŠããã®ãäžæè°ã§ã¯ãããŸããã
Jet Security TeamïŒãã£ãã§ã³ããŒïŒïŒãåããŠïŒããŒã ãšãœãªã¥ãŒã·ã§ã³ã®ã¯ã©ã¹ã®äž¡æ¹-ãããŠãç§ãã¡ã¯å€å
žçãªé²è¡ããŒã ãŸãã¯SOCã§ã¯ãããŸããïŒãç§ãã¡ã¯å¯Ÿç«ã«åå ããŸããã ãããŠããã¡ãããå°è±¡ã¯äºæ³ãäžåããŸããã ç§ãã¡ã®åå ã¯ããŸã第äžã«ãç§ãã¡èªèº«ã®éã«æçè«ãåŒãèµ·ãããããšããã§ã«èªããããšãã§ããŸãïŒæ°ãã解決çãæ°ãã圢åŒ...ããããçµæã¯ããèªäœãç©èªã£ãŠããŸãã
æ®å¿µãªããšã«ããã®ã€ãã³ãã®åœ¢åŒã§ã¯ãããã«ãŒã«ããå€éæ»æã«å¯Ÿå¿ã§ããŸããã§ãããåæ¥ãè©æ¬ºå¯Ÿçãœãªã¥ãŒã·ã§ã³ã¯ãç¶æ³ã«é¢ããäž»å¬è
ãžã®èŠ³å¯ãšéç¥ã®ã¢ãŒãã§ãããããŸããã§ããã ããããç¿æ¥ããçžåœé¡ã®è³éãåŒãåºãããšãèš±å¯ããªãããšãã課é¡ã¯110ïŒ
解決ãããŸããã ããã«ãããããæãéèŠãªããšã管çããŸãããéããããªãœãŒã¹ãšæéã§æœåšçãªç·æ¥ã®åé¡ã解決ããæºåããã¹ãããŸããã ãŸãã䜿ããããã®èŠ³ç¹ãããJet Detective補åã®éçºã«é¢ããããã€ãã®ã¢ã€ãã¢ãåŸãŸããã
ç§ãã¡ã®ã¢ã¯ãã£ããªäœæ¥ã®çãæéã®éãæ»æè
ãåæã·ã¹ãã ãåé¿ããããšããæéããªãã£ãã®ã¯æ®å¿µã§ãïŒãããŠãæ»æè
ã«ãšã£ãŠãããé£ããã²ãŒã ãã®ããã®ååãªãªãã·ã§ã³ããããŸããïŒã ãããŠãç§ãã¡ãçšæããããã€ãã®ããªãã¯ããã©ããã§ããããããã¯æ©èœããŠããŸããããçµæãé©çšããã®ã«å¿
èŠã§ã¯ãããŸããã§ããã
ããã§ããæ¥å¹Žã«åããŠæºåãé²ããŠãããšèšãããã§ãã ãããŠã2018幎ã«ã¯ãæ»æè
ã¯åæ¥ã»ã©åçŽãªç掻ãéãããšã¯ãªããšç¢ºä¿¡ããŠããŸãã 30æé以äžããããã60æéã®æ¬åœã®ã察ç«ããç§ãã¡ãåŸ
ã£ãŠããããšãé¡ã£ãŠããŸããã
SPANïŒãã£ãã§ã³ããŒãServionikaããã³Palo Alto Networksã®ä»£è¡šããŒã ïŒïŒã察ç«ãã¯ãçµ±åæ
å ±ã»ãã¥ãªãã£ã·ã¹ãã ãæ§ç¯ããããã®å
žåçãªãããžã§ã¯ããšæ¯èŒã§ããŸãã å®éã®ãããžã§ã¯ããšåæ§ã«ãç£æ»ãã¢ãŒããã¯ãã£ã®ç²Ÿç·»åãæ
å ±ä¿è·ã®å¿
èŠãªæ¹æ³ãšæ段ã®éžæããªãŒã¬ãã€ã¶ãŒãšã®ãã¹ãŠã®å€æŽã®èª¿æŽããæŠéãæ¡ä»¶ã§ã®éžæãããä¿è·æ段ã®ãã¹ããšéçšã®æ®µéãçµãŸããã äžè¬çã«ããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®å€æŽã培åºçãã€è©³çŽ°ã«ç£æ»ãããããã¯ãŒã¯ãã©ãã£ãã¯ãå®å
šã«å¶åŸ¡ããããšã«çŠç¹ãåãããŸããã ä¿è·ã·ã¹ãã æ§æã®æŠç¥ãšéžæã¯ãæè¿ã®åºæ¥äºã®åœ±é¿ãåããŸãããTheShadow Brokersã«ãããšã¯ã¹ããã€ãçºè¡ã®æ³¢ãšããã§ã«äžççã«æåãªWannaCryãŠã€ã«ã¹ã®åºçŸã§ãã
ãã®ç®æšãéæããããã«ãPalo Alto NetworksïŒNGFWïŒãPositive TechnologiesïŒPT Application FirewallãMaxPatrol8ïŒãSkyBox SecurityïŒNAãFAãVCãTMïŒãªã©ã®äŒæ¥ããå€æ°ã®ãœãªã¥ãŒã·ã§ã³ãéžæããŸããã LinuxãšWindowsãå®è¡ãããšã³ããã€ã³ãïŒãã¹ããã·ã³ïŒã®ä¿è·ã¯ãã»ãã¥ãªãã£ã³ãŒãã«ãããã©ããïŒPalo Alto NetworksïŒãšSecret Net Studioãœãªã¥ãŒã·ã§ã³ãããã³çµã¿èŸŒã¿ã®OSä¿è·ã¡ã«ããºã ã«åºã¥ããŠå®è£
ãããŸããã ããã«ãããæåãªãšã¯ã¹ããã€ãã®äœ¿çšãé²ãããšãã§ããŸããã
å€éãå«ãããªãã£ã¹ã€ã³ãã©ã¹ãã©ã¯ãã£ãç¶ç¶çã«æ»æãããããšã«æ³šæããŠãã ããã æ»æè
ãè匱ãªãµãŒãã¹ãçºèŠãããããã®è匱æ§ãæ¢ãå§ããæ¹æ³ãèŠãŸããã ã³ãŒã¹ã®ããã«ãããªãæšæºçãªæ¹æ³ã§æ»æããŸããããã¹ã¯ãŒãããœãŒãããã€ã³ã¿ãŒãããäžã§ãšã¯ã¹ããã€ããæ€çŽ¢ãããµãŒããŒããã³ã«ãŒã¿ãŒã«å¯ŸããŠãããã䜿çšããããšããŸããã åæ¥ç¶ã確èªããŠèšé²ããŸããã DMZã«å¯Ÿããæã掻çºãªæ»æã¯ãåå0æããåå4æãŸã§ã§ããã ãã®åŸãåå6æã«ãæ»æè
ã¯ãªãã£ã¹ãããã¯ãŒã¯å
ã®ãµãŒããŒã»ã°ã¡ã³ãã«åãæ¿ããŸããã ãŸãããã¹ã¯ãŒããéžæããããSQLã€ã³ãžã§ã¯ã·ã§ã³ãXSSãªã©ãèŠã€ããããšãã§ããŸãããã
SOCãããŒã¹ãã¯ãã£ãã¢ãã¿ãªã³ã°ãïŒãããã¯ãããŸããŸãªç£èŠã·ããªãªãäœæããããã®çŽ æŽããããã¬ãŒãã³ã°å Žã§ããã æ®å¿µãªãããæè¡çãªåé¡ãçºçããã察ç«ãã®åæ¥ã®19æã«ã®ã¿ã»ã³ãµãŒã«ãã©ãã£ãã¯ãéãããšãã§ããŸããã ãã©ãã£ãã¯ãšã€ãã³ããåãåããæ»æãšè匱æ§ãæªçšããè©Šã¿ãèŠãŸãããããããã¯ãã¹ãŠç°¡åã«ãããã¯ãããŸããã ç§ãã¡ã¯ãã£ãã§ã³ããŒã®ããŒã ãšè¯å¥œãªååé¢ä¿ãç¯ãããšãã§ããŸããã圌ãã¯ç§ãã¡ããã®æ
å ±ã«è¿
éã«å¯Ÿå¿ããããšããŸããã
æãäžå¿«ãªé©ãã¯ããã¹ãŠã®æ»æãéåžžã«å
žåçã§ãããåå è
å
šå¡ããã¯ããããã¯ã¯ãŒã«ã ã£ãããšèšãããšãã§ããããã«ãã€ã©ã€ãããªãã£ãããšã§ãã æ»æè
ã¯ãç§å¯ãå
±æããããªãã£ãããååãªæéãæã£ãŠããŸããã§ããã
ã²ãŒã ã®äž»ãªçµè«ïŒã察ç«ãã®åæ¥ã«ãã¹ãŠãããŸããããšããŠããããã¯ã察ç«ãã®æ¥ã®ä»äºèªäœãä¿èšŒãããã®ã§ã¯ãããŸããã ããããçå£ã«ãç§ãã¡ã¯ããžãã¹ã®æ¹æ³ãšããŒã ããã§ãã¯ãããã¡ãã¡ã§ç¹å®ã®æåãéæãããšããçµè«ã«éããŸããã ãšãŠã楜ããã§ãã æ
å ±ã®æ瀺ã®å³ããã«ãããããããèŠèŠåã¯ååã§ã¯ãããŸããã§ããã
SOCãFalse PositiveãïŒãœãŒã©ãŒJSOCããŒã ãæãããã®ããå人ããã·ã¢ã®SOCãã«ããŒïŒïŒãå°è±¡ã¯ããžãã£ãã§ãã 倧èŠæš¡ãªã€ãã³ãã®ããã«ãPHDays 7ã¯ãªãŒããŒã¬ã€ãªãã§ã¯ãããŸããã§ããããäžè¬çã«çµç¹ã®ã¬ãã«ãšåå è
ã®ã€ã³ã¹ãã¬ãŒã·ã§ã³ã®äž¡æ¹ãéåžžã«å°è±¡çã§ããã ç§ãã¡ã«ãšã£ãŠããã®ã€ãã³ãã¯ãåæã§ã¯ãããŸãããããã§ãããã®ãã³ãã¹ã¿ãŒã«ââ察ããŠèå³æ·±ãåŽåæ¡ä»¶ã§ã³ã³ãã³ãã®æå¹æ§ããã¹ãããå¥ã®æ©äŒã§ããã æšå¹Žããããã¯ãŒã¯ã·ããªãªã«çŠç¹ãåœãŠããããã®ãã¹ãã«æåããŸããããããã§ã¯ãã¹ããšã®é£æºã«çŠç¹ãåœãŠãŸããã
æ®å¿µãªããããå
éšããã®æµããšããååã¯ãæ°ããäŒæ¥ã»ãã¥ãªãã£ã«å¯ŸãããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ããã®ä»ã®åã³ãããŸããªãã£ããããå®å
šã«æ£åœåãããŸããã§ããã ããã§ããæ»æè
ãé²åŸ¡è
ãSOCã®äž¡æ¹ã§èªåãã¡ã®éšéããã¹ããããšããç¹ã§ãæ
å ±ã»ãã¥ãªãã£ã³ãã¥ããã£ã«ãšã£ãŠæçãªçµéšã§ãããšèããŠããŸãã
ãã¡ããããã®ãããªå€§èŠæš¡ãªãããžã§ã¯ãã§ã¯ããã¯ãŒã®ãã©ã³ã¹ã«éåžžã«æ³šæããå¿
èŠããããŸãã ãã®ã€ãã³ãã§ãéè¡ã¯æ»æè
ã«ãšã£ãŠæãæãŸããæšçãšãªããæ®å¿µãªããä»ã®ä¿è·ãããã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®æ³šæãäœäžãããŸããã æ¥å¹Žãç§ã¯ããã«å€ãã®ç«ãšããŒãã³ã¢ãèŠãããšæããŸããã
PSãããã³ã°ã³ã³ãã¹ãã«ããŸãã«ãç±å¿ã§ãPHDays VIIã®ã¬ããŒããäœæããæéããªãã£ã人ã®ããã«ãã»ãšãã©ã®ã¬ããŒãã¯é²ç»ã§èŠãããšãã§ããŸãã ãã¬ãŒã€ãŒã®å³åŽã«ã¯ãèå³ã®ããã»ã¯ã·ã§ã³ãéžæã§ããã¡ãã¥ãŒããããŸãã
www.phdays.ru/broadcast