
ããã«ã¡ã¯ãïŒ
ãŠãŒã¶ãŒåïŒ
ã Black Hat Europe 2010ã¯æ¬æ¥ãã«ã»ããã§éå§ãããŸãããä»åæºåããããšãç¥ãããšã¯éåžžã«è峿·±ãããšã§ãã ãã®ç¿»èš³ã§ã¯ãã¬ããŒãã®ãããã¯ãšãã®ç°¡åãªèª¬æã瀺ãããŸãã
äžéšã®å°åã§ã¯ã翻蚳ã¯å°ãæªããããããŸãããã圌ããèšãããã«ã圌ãã¯è£çŠã§ãã 翻蚳ã«é¢ããŠã¯ãã³ã¡ã³ã/ä¿®æ£ãæè¿ããŸãã
èè
ïŒ
ã¢ã³ãã¬ã¢ãã«ã¹ãããïŒããªã³ãã¥ã¹ïŒ
ã¿ã€ãã«ïŒ
å¿åéä¿¡ã®ããã®ã¯ã€ã€ã¬ã¹ISPã®èª€çšïŒå¿åéä¿¡ãäœæããããã®ã¯ã€ã€ã¬ã¹ãããã€ããŒã®èª€çšïŒ
説æïŒ
ã»ãšãã©ã®ã¯ã€ã€ã¬ã¹æè¡ã¯ãæ¬è³ªçã«ç©çã¬ãã«ã§ã®åçŽãªãããŒããã£ã¹ãã§ããã€ãŸããå®éã«ã¯ãç¹å®ã®ã«ãã¬ããžãšãªã¢ã®ã©ã¡ãã®åŽã§ãä¿¡å·ãåä¿¡ã§ããŸãã å®å
šãªp2pæ¥ç¶ã確ä¿ããããã«ããã®ãããªã¯ã€ã€ã¬ã¹ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯éåžžãæå·ãããã³ã«ã䜿çšããŠãæ¥ç¶ã®äž¡åŽïŒããšãã°ããŠãŒã¶ãŒãšã¹ãã¬ãŒãžã¡ãã£ã¢ïŒãã»ãã·ã§ã³ããŒã確ç«ããŸããã»ãã·ã§ã³ããŒã¯ãæ
å ±ãšèªèšŒã³ãŒããæå·åããããšã«ããããã©ã€ããŒãã§èªèšŒãããæ¥ç¶ãäœæããããã«äœ¿çšãããŸãã 仿¥ããã®ãããªéä¿¡ãããã³ã«ã®äœæãšåæã«é¢ããèãã¯ã
éšå€è
ã«é¢ããæ©å¯æ§ãç¶æããå Žåãæ¥ç¶ã®äž¡åŽãæå·ãããã³ã«ã«é¢ããŠæ£ããåäœããå¿
èŠããããšããäºå®ã«åž°çããŸãã
ãã ããã¹ãã¬ãŒãžã¡ãã£ã¢ã®åž¯åå¹
ã®å®¹é/ãªãœãŒã¹ã倧ããå ŽåããŠãŒã¶ãŒã¯æ¥ç¶ãéšå€è
ããä¿è·ããããšã«é¢å¿ããªãå ŽåããããŸããã代ããã«éä¿¡ãããã³ã«ã®
å
éšè
æ»æã«ãã£ãŠå®¹é/ãªãœãŒã¹ãæ¡å€§ããããšããå ŽåããããŸãã ãããŠãã¬ããŒãã®èè
ãç¥ãéãããããã·ããã®ãã®ãããªæ°ããè
åšã¯ãŸã ç¡èŠãããŠããŸãã
ãã®ã¬ããŒãã§ã¯ããªãœãŒã¹ãã£ãªã¢ã«ãã£ãŠéå§ãããå®å
šãªéä¿¡ã劚害ããããã€ãã®ã¿ã€ãã®ã€ã³ãµã€ããŒæ»æã玹ä»ããŸãã è¡æã€ã³ã¿ãŒããããããã€ããŒã¯ããŠãŒã¶ãŒããµãŒãã¹ãããã€ããŒãšç·å¯ã«æ¥ç¶ããŠããäžæ¹ã§ãã€ã³ã¿ãŒããããããã€ããŒãåºå€§ãªãšãªã¢ã§ä¿¡å·ãéä¿¡ã§ãããããé®®æãªäŸãšããŠåœ¹ç«ã¡ãŸãã ãã®ããããã®ã¬ããŒãã§ã¯äž»ã«è¡æã€ã³ã¿ãŒããããããã€ããŒã«é¢é£ããæ»æã«ã€ããŠèª¬æããŠããŸãããWiMAXã«ã€ããŠãè§ŠããŸãã
è¡æãããŠãŒã¶ãŒã«éä¿¡ããããã¹ãŠã®ããŒã¿ãæå·åããå¿
èŠãããã«ãããããããæç€ºãããæã匷åãªæ»æã«ããããšã³ããŠãŒã¶ãŒã¯ãããã€ããŒãéããŠã¯ãªã¢ããã¹ãã§ããŒã¿ããããŒããã£ã¹ãã§ããŸãã
æåŸã«ãèè
ã¯ãæç€ºãããçµæã䜿çšããŠéä¿¡ãã£ãã«ã確ç«ããåä¿¡è
ã®å®å
šãªå¿åæ§ãå®çŸããæ¹æ³ã«ã€ããŠè°è«ããäºå®ã§ãã
èè
ïŒ
Iftach Ian AmitïŒã»ãã¥ãªãã£ïŒã€ãããŒã·ã§ã³ïŒ
ã¿ã€ãã«ïŒ
ãµã€ããŒ[ç¯çœª|æŠäº]å±éºãªæ°Žãã°ã©ãåïŒCharts of Cyberââ [ç¯çœª|æŠäº]ïŒ
説æïŒ
é廿°å¹Žéããµã€ããŒæŠäºã¯ããªãç©è°ãããããŠããŸããã ãã®çšèªã¯äžè¬çã«ééã£ãŠãããšèšã人ãããŸãã äžæ¹ããµã€ããŒç¯çœªã¯ãç®¡èœæš©ãšæ³å·è¡æ©é¢ã®æ¬ åŠãçµç¹ç¯çœªããã®æé«ã®åå
¥æºã®1ã€ãšãªã£ãããã倧ããªæžå¿µææã§ããã ãã®ã¬ããŒãã§ã¯ãèè
ã¯ãµã€ããŒç¯çœªãšãµã€ããŒæŠäºã®éããæ¢ããäž»ãªä¿³åªïŒäž»ã«åœå®¶åŽïŒã匷調ããéå
ã«å¯Ÿããéå»ã®æ»æããµã€ããŒç¯çœªçµç¹ãšçµã³ä»ããŸãã èè
ã¯ãŸãããµã€ããŒæŠäºãšåŸæ¥ã®æŠäºãšã®é¢ä¿ãããã³ãµã€ããŒã»ãã¥ãªãã£ã䜿çšããçŸä»£ã®ãã£ã³ããŒã³ã§äœ¿çšãããæ¹æ³ã調ã¹ãŸãã
èè
ïŒ
ãããã¯ãã¹ã¢ã«ã®ããã£ã¹ïŒåœå¢èª¿æ»æ ªåŒäŒç€ŸïŒ
ã¿ã€ãã«ïŒ
ããŒã¢ã³ã®ãã€ã³ãïŒFreeBSDã«ãŒãã«ã¹ã¿ãã¯ãšããŒãã®æŽ»çšïŒFreeBSDã«ãŒãã«ãšã¹ã¿ãã¯æäœïŒ
説æïŒ
FreeBSDã¯ãããªãŒãœãããŠã§ã¢ãšãããã©ã€ãšã¿ãªãœãããŠã§ã¢ã®äž¡æ¹ã§å©çšå¯èœãªæãä¿¡é Œæ§ãé«ãå¹ççãªãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®1ã€ãšããŠåºãèªèãããŠããŸãã ã«ãŒãã«ã®è匱æ§ã®æªçšã¯ãWindowsããã³Linuxãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãã¬ãŒã ã¯ãŒã¯å
ã§ç ç©¶ãããŠããŸãããFreeBSDããã³BSDã·ã¹ãã ã¯äžè¬çã«ããã»ã©æ³šç®ãããŠããŸããã ãã®ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ããŸãFreeBSDã«ãŒãã«ã¹ã¿ãã¯ãªãŒããŒãããŒã®åäœã瀺ããŸãã ç¹æš©ææ Œã®ããã®ãšã¯ã¹ããã€ãéçºããã»ã¹ã¯ãCVE-2008-3531ã§ææžåãããŸãã ãã¬ãŒã³ããŒã·ã§ã³ã®2çªç®ã®éšåã§ã¯ãFreeBSD-Universal Memory AllocatorïŒUMAïŒã®ã¡ã¢ãªç®¡çã¡ã«ããºã ã®ã»ãã¥ãªãã£ã®è©³çްãªåæã瀺ããŸãã ãŸããUMAãªãŒããŒãããŒã«ãããææ°ã®å®å®ããFreeBSDã«ãŒãã«ïŒ8.0-RELEASEïŒã®ã³ã³ããã¹ãã§ä»»æã®ã³ãŒããå®è¡ãããå¯èœæ§ãããç¶æ³ãèæ
®ããŸãã
èè
ïŒ
ãžã§ãŒã ã¹ã¢ãŒã¬ã³ïŒããã·ã¥ã¹ã¿ãã¯ã³ã³ãµã«ãã£ã³ã°ïŒ
ã¿ã€ãã«ïŒ
ã»ãã¥ãªãã£å°éå®¶åãã®SCADAãšICSïŒãµã€ããŒçœçŽã«ãªãã®ãé¿ããæ¹æ³ïŒã»ãã¥ãªãã£å°éå®¶åãã®SCADAãšICSïŒãµã€ããŒéŠ¬é¹¿ã«ãªãã®ãé¿ããæ¹æ³ïŒ
説æïŒ
ã¬ããŒãã®èè
ã¯ãäœããã®çç±ã§ãäŒçµ±çãªã»ãã¥ãªãã£æ¥çããçœã銬ã®éšå£«ã®ããã«ãå®å
šã§ãªããã€ãã©ã€ã³ãååŠãã©ã³ãããã®ä»ã®ã¯ãããŒå·¥å Žã®ææããå
šå¡ãæãããšã決å®ããããšãäŒããããšèããŠããŸãã ããããçªç¶ããã¹ãŠã®ã³ã³ãµã«ã¿ã³ããçªç¶å°éå®¶ã«ãªããå補åã¯SCADAã»ãã¥ãªãã£ã®åé¡ã«å¯ŸåŠããèœåãåºã宣äŒããŠããŸãã ããããäž»ã«åœŒããäœãèšã£ãŠããã®ãããããªãããã圌ãã¯ç§ãã¡å
šå¡ã銬鹿ã®ããã«èŠããŸãã ãããã£ãŠãèè
ã¯èª°ããå¹³åçã«åº§ããSCADAãšICSã«ã€ããŠè©±ãåãããšãææ¡ããŸãããããã£ãŠãäžç·ã«çºçããåé¡ã解決ããŸãã èè
ã¯ããµã€ããŒéŠ¬é¹¿ã«ãªãã®ããããæãæ¥ããšäž»åŒµããããªãã¯å
šäœçãªãœãªã¥ãŒã·ã§ã³ã«ããã€ãã®ç©æ¥µçãªè²¢ç®ãããå¿
èŠããããŸãã
èè
ïŒ
Christiaan BeekïŒTenICT BVïŒ
ã¿ã€ãã«ïŒ
ä»®æ³æ³å»åŠ
説æïŒ
ãã®ã¬ããŒãã§ã¯ãä»®æ³åç°å¢ã調æ»ããéã«çŽé¢ããåé¡ã«ã€ããŠèª¬æããŸãã èè
ã¯ããä»®æ³åã·ã¹ãã ãšæšæºã·ã¹ãã ã§ã®èª¿æ»æè¡ãšããŒã«ã®éããããCitrixã·ã¹ãã ãšVMWareã·ã¹ãã ã§èª¿æ»ãè¡ãéã«æãéèŠãªãã¡ã€ã«ãããVMDKãã¡ã€ã«ã·ã¹ãã ãšãã®å°æ¥ã®èª¿æ»ã«ã€ããŠããªã©ã®è³ªåãæèµ·ããŸãã
èè
ïŒ
ãã«ã³ã»ããããã£ïŒCutaway srlïŒ
ã¿ã€ãã«ïŒ
æºåž¯é»è©±ã®åç¶ïŒTorã䜿çšããã¢ãã€ã«éä¿¡ã®ä¿è·
説æïŒ
èè
ã¯ãTorã¯ãå人ã®èªç±ãšé¢ä¿ã®æ©å¯æ§ãè
ããç£èŠã®åœ¢æ
ãªã©ããããã¯ãŒã¯ãã©ãã£ãã¯ã®åæãã身ãå®ãã®ã«åœ¹ç«ã€ãœãããŠã§ã¢è£œåã§ããããšãæãåºãããŠãããŸãã Torã¯ãäžçäžã®ãã©ã³ãã£ã¢ãç«ã¡äžãããµãŒããŒã®åæ£ãããã¯ãŒã¯å
šäœã«ãããã¯ãŒã¯ãã©ãã£ãã¯ãã±ãããã«ãŒãã£ã³ã°ããããšã§ä¿è·ãæäŸããå®éã®å°ççäœçœ®ãç¥ãããšãé²ããŸãã
æ®å¿µãªããããã©ãŠã¶ã«çµã¿èŸŒãŸããæ°ããHTML5æ©èœãšäœçœ®æ
å ±æè¡ã«ããããŠãŒã¶ãŒããã©ã€ãã·ãŒãç¶æããããšã¯ãŸããŸãé£ãããªã£ãŠããŸãã
ãã®ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ãäžèšã®ãã¹ãŠã®åé¡ãšãTorãŠãŒã¶ãŒã§ãããããå®è£
ã§ããæ¹æ³ã«ã€ããŠèª¬æããŸãã ãŸããã¢ãã€ã«ãŠãŒã¶ãŒã®ãã©ã€ãã·ãŒã®åé¡ã解決ããæ¹æ³ã«ã€ããŠã説æããŸãã
èè
ïŒ
Stephan ChenetteïŒWebsense Security LabsïŒ
ã¿ã€ãã«ïŒ
Fireshark-æªæã®ããWebããªã³ã¯ããããŒã«ïŒFireshark-ãã¹ãŠã®æªæã®ãããããã¯ãŒã¯ããã°ã©ã ãåéããïŒ
説æïŒ
æ°åã®æ£åœãªãµã€ãããäœçŸäžãã®èšªåè
ãžã®æªæã®ããã³ã³ãã³ãã®æ¡æ£ã«è²¢ç®ããŠããŸãã ãµã€ãéã®ãã¿ãŒã³ãèŠã€ããããã«ãã¹ãŠã®ç ç©¶ãäžç·ã«çµã¿åãããããšãã詊ã¿ã¯ãããªãå°é£ãªã¿ã¹ã¯ã§ãããäžéšã®èªç±ã«é
åžãããããŒã«ã䜿çšãããšè§£æ±ºã§ããªãå ŽåããããŸãã
èè
ã¯ãFiresharkïŒfire sharkïŒãšåŒã°ããç ç©¶ãããžã§ã¯ãã玹ä»ããŸãããã®ãããžã§ã¯ãã§ã¯ãèšå€§ãªæ°ã®ãµã€ãã蚪åããªãããããããã®ã³ã³ãã³ããå®è¡ãä¿åãåæããããšãã§ããŸãã ãã®ããã°ã©ã ã®åæã«åºã¥ããŠããµã€ãã®ã»ãã¥ãªãã£ã«é¢ããçµè«ãåŒãåºãããšãã§ããŸãã
èè
ïŒ
ããªã¢ãŒãã»ããã§ã¹ã»ãã£ã»ã¯ããŒãã§ïŒONAPSISïŒ
ã¿ã€ãã«ïŒ
SAPããã¯ãã¢ïŒããžãã¹ã®äžå¿ã«ãããŽãŒã¹ãïŒSAPããã¯ãã¢ïŒããžãã¹ã®äžå¿ã«ãããŽãŒã¹ãïŒ
説æïŒ
ã©ã®äŒæ¥ã§ããERPïŒãšã³ã¿ãŒãã©ã€ãºãªãœãŒã¹ãã©ã³ãã³ã°ïŒã¯ããžãã¹ã®äžå¿ã§ãã ãããã®ã·ã¹ãã ã¯ã調éãè«æ±ã人äºããªãœãŒã¹ç®¡çã財åèšç»ãªã©ã®ããã»ã¹ãæŽçããããã«èšèšãããŠããŸãã ãããã®ã·ã¹ãã ã®äžã§ãSAPã¯æãéç«ã£ãŠããã120ãåœä»¥äžã«90,000人以äžã®é¡§å®¢ãããŸãã
ãã®ãããªã·ã¹ãã ã«ä¿åãããŠããæ
å ±ã¯ãäŒæ¥ã«ãšã£ãŠæãéèŠãªãã®ã§ãããäžæ£ãªæäœã¯çµæžçæå€±ãšè©å€ã®äœäžã«ã€ãªããå¯èœæ§ããããŸãã
ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ãSAPã®ããã¯ãã¢ã«çŠç¹ãåœãŠãŸããèè
ã¯ãæ»æè
ãSAPã·ã¹ãã ã§ããã¯ãã¢ãäœæããã³ã€ã³ã¹ããŒã«ããããã«äœ¿çšã§ããããŸããŸãªæ¹æ³ã«ã€ããŠèª¬æããŸãã ãã®åŸãèè
ã¯ãã®ãããªæ»æãåé¿ããããšãç®çãšããããã€ãã®å¯Ÿçãå°å
¥ããã»ãã¥ãªãã£ãããŒãžã£ãŒãSAPã·ã¹ãã ã®äžæ£ãªå€æŽãèªåçã«æ€åºã§ããæ°ããç¡æããŒã«Onapsisãå°å
¥ããŸãã
èè
ïŒ
ã¢ã³ããžã§ã»ãã¬ã¹ãŸãŠã¹ãïŒ3MïŒ
ã¿ã€ãã«ïŒ
eMRTDã»ãã¥ãªãã£ã³ã³ãããŒã«ã®æ€èšŒ
説æïŒ
ãšãŒãããã§ã®é»åæž¡èªææžãžã®ç§»è¡ã«äŒŽããèªèšŒæè¡ã®æ£ããå®è£
ãæ€èšŒããããšãæ¥åã§ããã ããã«åºã¥ããŠãèè
ã¯é»åææžïŒeMRTD-é»åæ©æ¢°èªã¿åãå¯èœãªæ
è¡ææžãçŽPerïŒã®ã»ãã¥ãªãã£ç®¡çãæ€èšããããšèããŠãããåœŒã®æèŠã§ã¯ãèå¥ã¡ã«ããºã ã®æãæ£ããå®è£
ãæäŸãã誀ã£ãå®è£
ã®ãã¹ãŠã®å±éºæ§ãšãã®åŸã®ãã¹ãŠã®å±éºæ§ã瀺ããŠããŸãåé¡ã®çµæã
èè
ïŒ
ã©ãŠã«ã»ãã³ã¹ã¿ïŒã·ã°ãã«11ïŒ
ã¿ã€ãã«ïŒ
æšçåæ»æïŒè¢«å®³è
ããæ»æã«å¯ŸæããïŒæšçåæ»æïŒè¢«å®³è
ããæ»æè
ãžã®ç§»è¡ïŒ
説æïŒ
ãã®ãã¬ãŒã³ããŒã·ã§ã³ã¯ãå€ãã®çµç¹ã«å¯ŸããŠçŸåšé²è¡äžã®æšçåæ»æã®åæã§ãã çµå±ã®ãšãããç¡æã®ãªã¢ãŒãã¢ã¯ã»ã¹ã·ã¹ãã ïŒRATïŒã¯ã䟵å
¥ãæåããåŸã«è¢«å®³è
ã®å¶åŸ¡ãç¶æããããã«ãã䜿çšãããŸãã ãã®ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ãç¹å®ã®æ»ææ¹æ³ã«çŠç¹ãåœãŠãã®ã§ã¯ãªããRATã«çŠç¹ãåœãŠãŸãã
ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ã䜿çšãããç¹å®ã®ããã€ã®æšéЬãç¹å®ããæ¹æ³ïŒã¢ãŒããã¯ãã£ãæ©èœãã·ã¹ãã å
ã®ååšãé ãæ¹æ³ïŒã«ã€ããŠèª¬æããŸãã æåŸã«ãæ»æããŒã«ã®è匱æ§ã®æ€çŽ¢ã衚瀺ãããæ»æè
èªèº«ã被害è
ã«ãªãå¯èœæ§ããããŸãã
èè
ïŒ
ã¿ã€ã»ãºãªã³ïŒãžã¥ãªã¢ãŒãã»ãªããŸïŒVNSECURITYïŒ
ã¿ã€ãã«ïŒ
Webã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããå®çšçãªæå·æ»æ
説æïŒ
2009幎ãèè
ã¯ãããããFlickrãVimeoãScribdãªã©ã®ãµã€ãã§ãããããMD5ã«å¯Ÿããæ»æã®å¯èœæ§ã瀺ããŸããã ãã®ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ãèè
ã¯å¥ã®åæ§ã«åŒ·åãªæå·æ»æã察象ãšããç ç©¶ã®ææ°çµæãæç€ºããããšèããŠããŸãã
èè
ã¯ãåºã䜿çšãããŠããææ°ã®Webéçºãã¬ãŒã ã¯ãŒã¯ã®å€ããæå·åã誀ã£ãŠäœ¿çšããŠãããããæ»æè
ãæ©å¯ããŒã¿ãèªã¿åã£ãŠå€æŽã§ããããšã瀺ããŸãã Padding Oracleæ»æãeBayã©ãã³ã¢ã¡ãªã«ãApache MyFacesãSUN MojjaraãRuby On Railsãªã©ã®äŸãæäŸãããŸãã èè
ã¯ããããã¯ãã¹ãŠãŒããã€ïŒãŒããã€ïŒè匱æ§ã§ãããšäž»åŒµããŠããŸãã
èè
ïŒ
ãšãªãã¯ãã£ãªãªãŒã«ïŒESIEAïŒ
ã¿ã€ãã«ïŒ
匱ãã¹ããªãŒã æå·ã®èª€çšãæäœçã«æ€åºããŠç Žå£ããæ¹æ³ïŒå Žåã«ãã£ãŠã¯ãããã¯æå·ãããïŒ-Office Encryption Cryptanalysisãžã®å¿çšïŒåŒ±ãã¹ããªãŒã æå·ã®äœ¿çšããã°ããæ€åºããæ¹æ³-Office cryptanalysisã¢ããªã±ãŒã·ã§ã³ïŒ
説æïŒ
ãããã¯æå·ã¯åºã䜿çšãããŠããŸãããã¹ããªãŒã æå·ã¯è¡æéä¿¡ãæ°ééä¿¡ããœãããŠã§ã¢ãªã©ã®åéã§äŸç¶ãšããŠåºã䜿çšãããŠããŸãã ããããã¹ããªãŒã æå·ã®äœ¿çšã¯æå·åããŒã®äžé©åãªæäœã®ããã«å®å
šã§ã¯ãããŸãããããã¯ãŸãã«ã¬ããŒãã®èè
ã䞻匵ããŠããããšã§ãã ãã¬ãŒã³ããŒã·ã§ã³ã§ã¯ããã®ãããªãšã©ãŒãç¹å®ããããã¹ããããªãçæéã§å埩ããæ¹æ³ã説æããŸãã
ããšãã°ãã¬ããŒãã®äœæè
ã¯ãäž»ã«WordãšExcelãæ³šç®ãã2003ããŒãžã§ã³ïŒRC4ïŒãŸã§ã®Officeã§äœ¿çšãããŠããæå·åã®æå·è§£æã«ã€ããŠèª¬æããŸãã æ°ç§ã§ããœãŒã¹ã³ãŒãã®90ïŒ
以äžãå埩ã§ããããã«ãªããŸãã
èè
ïŒ
FXïŒREcurity LabsïŒ
ã¿ã€ãã«ïŒ
è²§ãã人ã
ãå®ãïŒè²§ãã人ã
ãå®ãïŒ
説æïŒ
ããã¯ããªããã€ã³ã¿ãŒãããã¢ããªã±ãŒã·ã§ã³ã³ã³ãã³ãïŒRIAïŒã³ã³ãã³ããä¿è·ããããã®ã·ã³ãã«ã ã广çãªã¢ãããŒãã§ãã ãã¯ãããžãŒå
šäœã«å¯Ÿããæ»æãå¯èœã«ããããã€ãã®å
éšAdobe Flashã¡ã«ããºã ã«ã€ããŠèª¬æããŸãã ãããã®åŽé¢ã®ããã€ãã¯ããªããç¬é¡ã«ããä»ã®åŽé¢ã¯ããªããã²ããŸããŸãã ãããã®ã¡ã«ããºã ã®æç€ºãšãšãã«ãä¿è·ã®ã¢ã€ãã¢ããçè«ã ãã§ãªãå®éã«ããå®è£
ãããã³ãŒãã®åœ¢ã§ããããŠå®äžçã§ã®ãã®é©çšã®çµæãšããŠç€ºãããŸãã
èè
ïŒ
Thanassis GiannetsosïŒREcurity LabsïŒ
ã¿ã€ãã«ïŒ
ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®æŠåšåïŒã»ã³ãµãŒãããã¯ãŒã¯ã«å¯Ÿããæ»æãéå§ããããã®æ»æããŒã«ïŒã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®æŠåšåïŒã»ã³ãµãŒãããã¯ãŒã¯ãžã®æ»æïŒ
説æïŒ
èªåŸåã¿ããããã€ã¹ã®ãŠããã¿ã¹ãªçµã¿åããã¯ãå¹
åºãçš®é¡ã®æ°ããã¢ããªã±ãŒã·ã§ã³ãçã¿åºããŸããã ããããåæã«ãã»ã³ãµãŒããŒãã®èªåæ§ãšéããããªãœãŒã¹ã«ãããæ»æè
ããããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãååŸããããã«äœ¿çšã§ããã®ãšåãæ°ã®è匱æ§ãäœæãããŸããã ãã®ãããªãããã¯ãŒã¯ãä¿è·ããããã«å€ããè¡ãããŸããããã»ã³ãµãŒãããã¯ãŒã¯ã®è匱æ§ã蚌æããããŒã«ãäœæããããã«è¡ããããã®ã¯ã¯ããã«å°ãªãã§ãã
ãã®ãã¯ã€ãããŒããŒã§ã¯ããããã¯ãŒã¯ã§ååçãªåµå¯ãè¡ãã ãã§ãªããããŸããŸãªæ¹æ³ã§æ»æããŠãããã¯ãŒã¯ä¿è·ã®åŒ·åºŠããã¹ãã§ããããŒã«ã玹ä»ããŸãã èè
ãç¥ãéãããã®ããŒã«ã¯ãã®çš®ã®ãã®ãšããŠã¯åããŠã®ãã®ã§ãã çµæã¯ããã®ããŒã«ãéåžžã«æè»ã§ãããããŸããŸãªã»ã³ãµãŒãããã¯ãŒã¯ãããŸããŸãªãããã³ã«ã¹ã¿ãã¯ã«ç°¡åã«é©å¿ã§ããããšã瀺ããŠããŸãã èè
ã¯ããã®éçºãæ°ãããããã¯ãŒã¯ãããã³ã«ã®åŒ±ç¹ãç¹å®ããããã«ãã£ãŠã»ãã¥ãªãã£ã¬ãã«ãåäžãããããšãæåŸ
ããŠããŸãã
èè
ïŒ
ãžã§ãŒã°ã©ã³ãïŒã°ã©ã³ãã¢ã€ãã£ã¢ã¹ã¿ãžãªïŒ
ã¿ã€ãã«ïŒ
ããŒããŠã§ã¢ã¯æ°ãããœãããŠã§ã¢ã§ã
説æïŒ
æè¡ã®çå®ãªæé·ã«ããã瀟äŒã¯ç¹æ ããŠããŸãã ãšã¬ã¯ãããã¯ã¹ã¯ãç§ãã¡ãè§Šãããã¹ãŠã®ãã®ã«ãã§ã«å«ãŸããŠããŸãã çŸåšãããŒããŠã§ã¢è£œåã¯ã»ãã¥ãªãã£é¢é£ã®ã¢ããªã±ãŒã·ã§ã³ã«äŸåããŠããŸãããä¿¡é Œãããªããã°ãªããŸããããå€ãã®å Žåãæ°å幎ã«ããã£ãŠç¥ãããŠããæãåçŽãªã¯ã©ã¹ã®æ»æãããããä¿è·ããŸããã
DIYã®è¶£å³ãæ©åšãžã®ç°¡åãªã¢ã¯ã»ã¹ãã€ã³ã¿ãŒãããããã®å³ææ
å ±æ€çŽ¢ã«ãããã³ã³ãã¥ãŒã¿ãŒã®ã»ãã¥ãªãã£ãæ€èšããéã«ããŒããŠã§ã¢ãå²ãåŒãããšã¯ã§ããªããªããŸããã ã¬ããŒãã§ã¯ãèè
ã¯ãããã³ã°ããŒããŠã§ã¢ããã»ã¹ãæç€ºããé»åããã€ã¹ã«å¯Ÿããããã€ãã®æ»æã瀺ããŸãã
èè
ïŒ
Vincenzo IozzoïŒZynamics GmbHïŒ
ã¿ã€ãã«ïŒ
0ç¥èãã¡ãžã³ã°ïŒäºåãã¬ãŒãã³ã°ãªãã®ãã¡ãžã³ã°ïŒ
説æïŒ
ãã¡ãžã³ã°ã¯çŸåšãæ»æè
ãšéçºè
ã®äž¡æ¹ã䜿çšããããªãäžè¬çãªææ³ã§ãã éåžžããããã³ã«ãŸãã¯å
¥åããŒã¿ã®åœ¢åŒã«é¢ããç¥èãšããã®å
¥åãã¢ããªã±ãŒã·ã§ã³å
ã§ã©ã®ããã«åŠçããããã«ã€ããŠã®äžè¬çãªçè§£ãå«ãŸããŸãã
以åã¯ããã¡ãžã³ã°ã䜿çšããŠãããããªåŽåã§å°è±¡çãªçµæãåŸãããšãã§ããŸããã çŸåšãäžè¬çãªåºç¯å²ã®è匱æ§ãéçºè
ã«ãã£ãŠãã§ã«ç¹å®ãããä¿®æ£ãããŠããããããšã©ãŒã®æ€çŽ¢ã«ã¯ã³ãŒãããã³ãŠãŒã¶ãŒã³ãŒãå
ã®ãã¯ããŒã«ããå¿
èŠã§ãã
ã¬ããŒãã§ã¯ããŠãŒã¶ãŒå
¥åã®åœ¢åŒãç¥ããªããŠããã¡ãžã³ã°ã®å¹æçãªäœ¿çšã«ã€ããŠèª¬æããŸãã ç¹ã«ãã³ãŒãã«ãã¬ããžãããŒã¿ã®æ±æãã¡ã¢ãªå
ã®ãã¡ãžã³ã°ãªã©ã®ææ³ã«ãããç¹å¥ãªããŒã«ãªãã§ã¹ããŒããã¡ã¶ãŒãæ§ç¯ã§ããããšãå®èšŒãããŸãã
//翻蚳è
ã®ã¡ã¢
ãã¡ãžã³ã°ã¯ãäºæãããå
¥åããŒã¿ã§ã¯ãªãã©ã³ãã ããŒã¿ãããã°ã©ã ã«éä¿¡ããããšãã«ããã°ã©ã ããã¹ãããããã®æè¡ã§ãã ããã°ã©ã ãããªãŒãºãŸãã¯ã¯ã©ãã·ã¥ããå Žåãããã¯ããã°ã©ã ã®æ¬ é¥ã§ãããšã¿ãªãããè匱æ§ã®çºèŠã«ã€ãªããå¯èœæ§ããããŸãã ãã¡ãžã³ã°ã®å€§ããªå©ç¹ã¯ããã®åçŽããšèªååææ©èœã§ãã
èè
ïŒ
Haifei LiïŒGuillaume LovetïŒãã©ãŒãã£ãããæ ªåŒäŒç€ŸïŒ
ã¿ã€ãã«ïŒ
Adobe Readerã®ã«ã¹ã¿ã ã¡ã¢ãªç®¡çïŒãã©ãã«ã®å±±ïŒAdobe ReaderïŒããŒãã®ãã©ãã«ïŒ
説æïŒ
PDFã®è匱æ§-åžžã«è±ªè¯ã§ãã 2010幎ã®äºæž¬ã§ã¯ãäžéšã®ãŠã€ã«ã¹å¯ŸçäŒæ¥ã¯ããµã€ããŒç¯çœªè
ã®ãªã¯ãšã¹ãã«èµ·å ããPDFã®è匱æ§ã®æ°ã®å¢å ã«ã€ããŠè¿°ã¹ãŠããŸãã ããããããã¯äºæž¬ããããã®ãšæ¯èŒããŠã©ãã»ã©æ·±å»ã§ãããFUDïŒFUD-Fear-Uncertainty-Doubt-fear-uncertainty-doubtïŒã®ã·ã§ã¢ã¯ã©ããããã§ããïŒ æçµçã«ãå€ãã®PDFã®è匱æ§ã¯ãã¡ã€ã«æ§é ïŒåœ¢åŒïŒã«é¢é£ããŠãããããããŒãã®ç Žæç¶æ³ã«ã€ãªãããŸãã ãããŠèª°ãããããŒããã¡ãŒãžããšã¯ã¹ããã€ããèšè¿°ãããŠããæ·±å»ãªè匱æ§ã®ã«ããŽãªãŒã«å
¥ãããšã¯ã»ãšãã©ãªãããšãç¥ã£ãŠããŸãã ãã®ãããMS WindowsããŒãã¯ã»ãšãã©äºæž¬ã§ãããå®å
šãªãªã³ã¯è§£é€ãªã©ã®ã¡ã«ããºã ã«ãã£ãŠä¿è·ãããŸãã
æã人æ°ã®ããPDFãªãŒããŒã§ããAdobe Readerã¯ã以åã®ã¹ããŒãã¡ã³ãã確èªã§ããç¹å®ã®ã¢ãŒããã¯ãã£ãåããŠããŸãã çç£æ§ãé«ããããã«ãã·ã¹ãã 1ã®äžã«ç¬èªã®ããŒã管çã·ã¹ãã ãå®è£
ããŠããŸãã ããããããã©ãŒãã³ã¹ãã»ãã¥ãªãã£ã®æµã«ãªãããšããããŸãããã®ããŒã管çã·ã¹ãã ã¯ãè匱æ§ãæªçšããæ¹ãã¯ããã«ç°¡åã§ãã ãã¬ãŒã³ããŒã·ã§ã³ã§ç°¡åã«ç€ºãããFlashã®DEPãã€ãã¹ïŒJITã¹ãã¬ãŒïŒã«é¢é£ããæè¿ã®ã€ãã³ããšäžç·ã«ãããŒãã®æäœã¯éåžžã«ç°¡åãªé€é£ã«ãªããŸãã
ãã®çµæãã¬ããŒãã§ã¯ããŒã管çã·ã¹ãã ã調æ»ããPDFã®è匱æ§ã®åé¡ãæããã«ããããã«éèŠãªåŒ±ç¹ãç¹å®ããŸãã
//翻蚳è
ã®ã¡ã¢
FUD-Fear-Uncertainty-Doubt-ææ-äžç¢ºå®æ§-çãã
ç«¶åä»ç€Ÿã®è£œåã®æ¶è²»è
ïŒãŸãã¯æœåšçãªæ¶è²»è
ïŒã«æ£ããéžæãšæãŸãããªãçµæã®æ¬ åŠãçãããããã«èšèšããã声æã®æ®åã«ãããäžå
¬æ£ãªç«¶äºã®æ¹æ³ã®ååã ç«¶åä»ç€Ÿã®è£œåãçãæ¶è²»è
ã¯ãããç¥ãããŠããååãçã-æåŠãã«ãã£ãŠå°ãããããããç²åŸããå¯èœæ§ã¯äœããšæ³å®ãããŸãããããã£ãŠãåžå Žããç«¶åä»ç€ŸãæŒãåºãããã»ã¹ãä¿é²ããŸãã
å®å
šãªãªã³ã¯è§£é€ã¯ãããŒãã®ä¿è·ãç®çãšããæè¡ã§ãã åæ¹åãªã¹ããã空ããããã¯ãåé€ããåã«ãååŸã®ã¡ã¢ãªãããã¯ãžã®ãã€ã³ã¿ã®ä¿¡é Œæ§ããã§ãã¯ããããšã«ãããŸãã
èè
ïŒ
ããŽã£ããã»ãªã³ãŒã€ïŒãšãã¥ã¢ã«ãã»ãŽã§ã©ã»ããïŒCigitalïŒ
ã¿ã€ãã«ïŒ
IE8s XSSãã£ã«ã¿ãŒãä»ãããŠãããŒãµã«XSSïŒIE8 XSSãã£ã«ã¿ãŒããã€ãã¹ãããŠãããŒãµã«XSSïŒ
説æïŒ
ãåãã®ãšãããIE8ã«ã¯XSSæ€åºããã³é²æ¢ãã£ã«ã¿ãŒãçµã¿èŸŒãŸããŠããŸãã èè
ã¯ããã£ã«ã¿ãŒãæ»æãæ€åºããæ¹æ³ã®è©³çްã瀺ãããã®äž»ãªå©ç¹ã𿬠ç¹ã«ã€ããŠèª¬æããŸãã ãŸããèè
ã¯ãã£ã«ã¿ãŒã被害è
ã«ãªãããã€ãã®æ¹æ³ã瀺ããè匱æ§ã®ãªããµã€ãã§XSSãèš±å¯ããŸãã ãã®è匱æ§ã«ãããã»ãšãã©ã®ãµã€ããIE8ã䜿çšããŠXSSã«å¯ŸããŠè匱ã«ãªãæ¹æ³ã瀺ããŸãã
èè
ïŒ
ã¢ãã·ãŒã»ããŒãªã³ã¹ãã€ã¯ïŒç Žå£çç ç©¶æ©é¢ïŒ
ã¿ã€ãã«ïŒ
è
åšã®ãã©ã€ãã·ãŒãžã®å€æŽïŒTIAããGoogleãžïŒãã©ã€ãã·ãŒã®è
åšã®å€æŽïŒTIAããGoogleãžïŒ
説æïŒ
ç§ãã¡ã¯æå·åã®ããã®æŠäºã«åã¡ãŸããããŸã å¿åã®å°äžãããã¯ãŒã¯ãããã忣ãããã¯ãŒã¯ãçŸå®ã«ãªã£ãããã§ãã ãã®ãããªãããã¯ãŒã¯éä¿¡æŠç¥ã¯ãæãæªæ¥ãèŠè¶ããŠèæ¡ãããŸããããã©ãããããããããã®åªåã¯ãç§ãã¡å
šå¡ãçŽé¢ãããã©ã€ãã·ãŒã®è
åšããã®ä¿è·ã«ã€ãªãããŸããã§ããã
代ããã«ãç§ãã¡ã®ãã¹ãŠã®éä¿¡ãšåãã®éäžç¶æ
ããŒã¿ããŒã¹ããããçŸä»£ã®ãã©ã€ãã·ãŒã®è
åšã¯ãŸããŸãäžåãªæå³åãã垯ã³ãŠããŸãã èè
ã¯ããã®åéã®æ°ããåŸåã«ã€ããŠè©±ãããšãææ¡ããããã€ãã®è峿·±ã解決çãæç€ºããŸãã
èè
ïŒ
ã¹ãã£ãŒããªã»ããã¯ïŒãŠã§ã³ãã«G.ãšã³ãªã±ïŒTrustwaveïŒ
ã¿ã€ãã«ïŒ
OracleãäžæïŒã»ãã·ã§ã³ãšè³æ Œæ
å ±ãçãïŒOracleïŒã»ãã·ã§ã³ãšè³æ Œæ
å ±ãçãïŒ
説æïŒ
ç¡æã§åºãæ®åããŠããæå·åã©ã€ãã©ãªã®äžçã§ã¯ãå€ãã®ãã³ãã¹ã¿ãŒãéä¿¡ãã£ãã«ã§éåžžã«è峿·±ããã®ãèŠã€ããŠããŸãã ããŒã¿ããŒã¹ãã©ãã£ãã¯ãéä¿¡ãããå Žåã¯åé¡ãããŸããããããŒã¿ã«PANãTrackãCVVãå«ãŸããŠããå Žåã¯ã忢ããŠããªããã®å
šäœãããã©ã«ãã§æå·åãããªãã®ããèããŸãã ãã ããããŒã¿ããŒã¹ãç
§äŒããã«ã¯èª°ããå¿
èŠã§ãã ãŸãã¯å€åããã§ã¯ãªã...
èè
ã¯ãæã人æ°ã®ãããªã¬ãŒã·ã§ãã«ããŒã¿ããŒã¹ã®1ã€ã§ããOracleã«æ³šæãæãããšãææ¡ããŠããŸãã ã»ãã·ã§ã³ãã€ã³ã¿ãŒã»ããããããã«èšèšãããããŠã³ã°ã¬ãŒãæ»æãšãšã¯ã¹ããã€ãã®çµã¿åããã䜿çšããŠãèè
ã¯ããŒã¿ããŒã¹ã¢ã«ãŠã³ãããã€ãžã£ãã¯ããç¬èªã®ã¢ãããŒããæç€ºããŸãã BHã«çŽæ¥å°å
¥ãããæ°ããããŒã«thicknetã䜿çšããŠãããŒã ã¯ãã€ã³ãžã§ã¯ã·ã§ã³ããŒã¹ã®èŽåœçãªæ»æãã©ã®ããã«çºçãããã瀺ããŸãã
èè
ïŒ
Christian PapathanasiouïŒTrustwave SpiderlabsïŒ
ã¿ã€ãã«ïŒ
JBossã®ä¹±çšïŒJBossã®æªçšïŒ
説æïŒ
JBossã¢ããªã±ãŒã·ã§ã³ãµãŒããŒã¯ãJava EEãµãŒãã¹ã¹ã€ãŒãã®ãªãŒãã³ãœãŒã¹å®è£
ã§ãã 䜿ãããããšé«ãæè»æ§ã«ãããJBossã¯ãJ2EEã®åå¿è
ãšã«ã¹ã¿ã ããã«ãŠã§ã¢ãã©ãããã©ãŒã ãæ¢ããŠããçµéšè±å¯ãªéçºè
ã®äž¡æ¹ã«ãšã£ãŠçæ³çãªéžæè¢ã§ãã
äŒæ¥ã§ã®JBossã®æ®åã¯ããã©ãã¯ãããïŒã¯ã©ãã«ãŒïŒïŒãšãã³ãã¹ã¿ãŒã®äž¡æ¹ã«ãšã£ãŠã¡ãã£ãšããçç±ã«ãªããŸãã éåžžãJBossã¯SYSTEMãŠãŒã¶ãŒã«ãã£ãŠå®è¡ãããŸããããã¯ãå®è£
ãããè匱æ§ãæ€åºãããšèªåçã«ã¹ãŒããŒæš©éãååŸããããšãæå³ããŸãã
éçºããããŒã«ã䜿çšãããšãä¿è·ãããŠããªãJBossã®ã»ãã¥ãªãã£ã䟵害ã§ããŸãã Metaspleitã®ãã€ããŒããããŒããããã®çµæãJBossã®ã³ã³ããã¹ãã§å®è¡ããããšãã§ããŸãã Windowsãã©ãããã©ãŒã ã§ã¯ãMetasloitãã¬ãŒã ã¯ãŒã¯ã䜿çšããŠãå®å
šãªVNCã·ã§ã«ãååŸã§ããŸãã
åäœããŠãããã©ââãããã©ãŒã ãšååŸããç¹æš©ã¬ãã«ã«å¿ããŠãéçºããããŒã«ã¯ããŠã€ã«ã¹å¯Ÿçã®ãããããŒæè¡ãšçµã¿åãããŠããã¯ãã¢ãå±éã§ããŸãã
Javaãã¯ãããžãŒã®ã¯ãã¹ãã©ãããã©ãŒã ã®æ§è³ªã«ãããèè
ã¯Linux for JBossãMacOSXã§ãåãããšãã§ãããšç¢ºä¿¡ããŠããŸãã
èè
ïŒ
ãšã³ãã»ã¬ã€ïŒãããšã«ã»ã¡ã³ãïŒERNWïŒ
ã¿ã€ãã«ïŒ
Cisco Enterprise WLANã®ãããã³ã°
説æïŒ
ãäŒæ¥ã®ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãœãªã¥ãŒã·ã§ã³ãã®äžçã«ã¯ããããŸãããšãéæšæºãã®èŠçŽ ãšæè¡ããã£ã±ãã§ãã ã·ã¹ã³ã®ãœãªã¥ãŒã·ã§ã³ã¯ãStructured Wireless-Aware NetworkïŒSWANïŒããCisco Wireless Unified NetworkingïŒCUWNïŒã«è³ããŸã§ãã»ãã®äžéšã§ãã ã¬ããŒãã§ã¯ãèè
ã¯ãããã®ãœãªã¥ãŒã·ã§ã³ã®å
éšã¢ãŒããã¯ãã£ã«ã€ããŠèª¬æããè匱ãªéšåãåæããçè«çããã³å®çšçãªæ»æã«ã€ããŠè°è«ãããšãšãã«ãããã€ãã®ãã¢ã瀺ããŸãã èªåæ»æãå®è¡ããããã®æ°ããããŒã«ãæç€ºãããŸãã
èè
ïŒ
Manish SaindaneïŒAttackïŒDefense LabsïŒ
ã¿ã€ãã«ïŒ
JAVAã·ãªã¢ã«éä¿¡ã®æ»æ
説æïŒ
å€ãã®Javaã¢ããªã±ãŒã·ã§ã³ã¯ããªããžã§ã¯ãã®ã·ãªã¢ã«åã䜿çšããŠããªããžã§ã¯ãããããã¯ãŒã¯äžã§ãã€ãã¹ããªãŒã ãšããŠè»¢éãããããã¡ã€ã«ã·ã¹ãã ã«é
眮ãããããŸãã çŸåšãæ¢åã®Pentialãã¹ããœãããŠã§ã¢Serialized Objectsã¯ãèŠæ±ãšå¿çãååããã³å€æŽããããã®å¶éãããæ©èœãæäŸããŸãã èè
ã¯ããã®ãããªã·ãªã¢ã«åãããéä¿¡ã«åœ±é¿ãäžããããã®æ°ããæè¡ãå°å
¥ããããšããŸããããããã®å€æŽã¯ãéåžžã®Webã¢ããªã±ãŒã·ã§ã³ããã¹ããããšãã«æ©èœããããšã»ã©é£ãããããŸããã èè
ã¯Burp Suiteã®ãã©ã°ã€ã³ãéçºããŸããã
èè
ïŒ
ããŒã¿ãŒã»ã·ã«ããŒãã³ïŒãšãã»ã«ã¬ã©ïŒMANDIANTïŒSABRE SecurityïŒ
ã¿ã€ãã«ïŒ
ãã«ãŠã§ã¢ã®ç¶æ
ïŒå®¶æã®çµ
説æïŒ
é廿°å¹Žã«ããã£ãŠããã«ãŠã§ã¢ã倧ããªããã¡ããªãã«èç©ããåŸåããããŸããããããã¯ä»¥åãšã¯æ ¹æ¬çã«ç°ãªããŸãã æ°çŸãŸãã¯æ°åã®Malvariæšæ¬ã®å®¶æãçãããããŸããã ãã®ãããªã°ã«ãŒãã¯ãæéã®çµéãšãšãã«ãã«ãŠã§ã¢ã®é²åãæç€ºçã«ç€ºããŠããŸãã é²åã¯ãåçŽãªä¿®æ£ãšå°ããªæ¹åããŸãã¯æ¢åã®ã³ãŒãã«åºã¥ãããã¹ãŠã®æ©èœã®ææ¬çãªå€æŽã§è¡šçŸã§ããŸãã å®¶æå
ããã³å®¶æéã®é¢ä¿ã®ç ç©¶ã¯ãéçºã®ããŒã¹ãæè¡æ©åšã®æ¹åçã«é¢ããæ
å ±ãæäŸããŸãã å®¶æã®æé·çã®ç ç©¶ã¯ããã®åºæ¬çãªæ©èœãç¹å®ãããããäœããã®åé¡ãäœæããããšãã§ããŸãã
èè
ïŒ
Paul StoneïŒã³ã³ããã¹ãæ
å ±ã»ãã¥ãªãã£ïŒ
ã¿ã€ãã«ïŒ
次äžä»£ã¯ãªãã¯ãžã£ããã³ã°ïŒæ¬¡äžä»£ã¯ãªãã¯ãžã£ããã³ã°ïŒ
説æïŒ
ã¯ãªãã¯ãžã£ããã³ã°-被害è
ãéåžžIFRAMEå
ã«é ãããŠããé ããªã³ã¯ãã¯ãªãã¯ããããã«WebããŒãžããã©ãŒãããããããšã«ããããŠãŒã¶ãŒã欺ããŠWebãµã€ãäžã§æå³ããªãã¢ã¯ã·ã§ã³ãå®è¡ããææ³ã ãã ããXSSïŒã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ïŒãCSRFïŒã¯ãã¹ãµã€ããªã¯ãšã¹ããã©ãŒãžã§ãªïŒãªã©ã®ä»ã®æ»æãšæ¯èŒãããšãã¯ãªãã¯ãžã£ããã³ã°ã¯æ©èœãå¶éãããæ»æãšèŠãªãããŸãã è¬çŸ©äžã«ãèè
ã¯ãã®å£°æãééã£ãŠããããšããããŠä»æ¥ã®ã¯ãªãã¯ãžã£ãã¯ææ³ãæ¡åŒµããŠããã匷åãªæ°ããæ»æãå®è¡ã§ããããšã蚌æããããšèããŠããŸãã
ãã®ã¬ããŒãã§ã¯ãã¯ãªãã¯ãžã£ãã¯ã®åºæ¬ãæ¢åã®æ¹æ³ãæ¹åããæ¹æ³ããŠãŒã¶ãŒãã ãŸãæ°ããæ¹æ³ã®ãããã¯ãåãäžããŸãã äŸã䜿çšããŠãèè
ã¯ããã€ãã®ã¯ãã¹ãã©ãŠã¶æ»æã瀺ããŸãã
èè
ïŒ
ã¯ãªã¹ããã¡ãŒã»ã¿ã«ããã¹ããŒïŒFlylogic EngineeringïŒ
ã¿ã€ãã«ïŒ
ã¹ããŒãã«ãŒããããã®ãããã³ã°
説æïŒ
説æãªã:(
èè
ïŒ
ããšããã»ããã³ïŒããã«ãŽã¡ïŒ
ã¿ã€ãã«ïŒ
Maltego 3.0ã®çºè¡šïŒMaltego 3.0ã®çã®å
ïŒ
説æïŒ
幎éãéããŠãPatervaããŒã ã¯2009幎3æã«ãªãªãŒã¹ããããšãªããMaltego 3.0ã§éãã«å¹³åçã«äœæ¥ããŸãããBH2009以æ¥åããŠãPatervaã¯å®å
šã«ãŒãããæ§ç¯ãããMaltegoã®æ°ããããŒãžã§ã³ã玹ä»ããŸãã , , .
():
Julien Tinnes & Chris Evans (Google, Inc)
:
Security in depth for Linux software ( Linux )
説æïŒ
, , . , , vsftpd Google Chrome Linux, -, , -, .
, , . , , .
, -, , ( ). , , , .
, , «», , vsftpd Google Chrome Linux.
():
Mario Vuksan, Tomislav Pericin & Brian Karney (ReversingLabs & AccessData Corporation)
:
Hiding in the Familiar: Steganography and Vulnerabilities in Popular Archives Formats ( - : )
説æïŒ
, - : PC, Apple. , , - , 10, 20 ?
, , - -. , ? ? 15 , ZIP, 7ZIP, RAR, CAB, GZIP.
ArchiveInsider â , , . , «» .
():
Kyle Yang (FORTINET INC)
:
Protocol, Mechanism and Encryption of Pushdo/Cutwail/Webwail Botnet ( Pushdo/Cutwail/Webwail )
説æïŒ
, () Pushdo/Cutwail/Webwail () pushdo ( : «revolution»), , «». , - . , ( , ) , « -», debug- -.