Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
P.A.K.U.R.I SECCON2019 Akihabara YOROZU
Search
Mr.Rabbit
December 21, 2019
Technology
130
1
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
P.A.K.U.R.I SECCON2019 Akihabara YOROZU
Mr.Rabbit
December 21, 2019
More Decks by Mr.Rabbit
See All by Mr.Rabbit
Azazel Series
01rabbit
0
89
Azazel System for Emergency Shelters
01rabbit
0
190
BOCCHI
01rabbit
0
50
KaliPAKU
01rabbit
0
32
Babbly
01rabbit
0
91
P.A.K.U.R.I AVTOKYO HIVE
01rabbit
0
110
The Empire Strikes Back ~MR.RABBIT 帝国の逆襲~
01rabbit
0
260
地雷探しに脆弱性を使うのは間違っているだろうか Hack a Minesweeper
01rabbit
0
220
あの日学んだ攻撃の方法を僕達はまだ知らない。
01rabbit
0
200
Other Decks in Technology
See All in Technology
Kiro Ambassador を目指す話
k_adachi_01
0
110
手塩にかけりゃいいってもんじゃない
ming_ayami
0
610
脆弱性対応、どこで線を引くか
rymiyamoto
1
420
Kubernetesにおける学習基盤とLLMOpsの概要
ry
1
320
エラーバジェットのアラートのタイミングを考える.pdf
kairim0
0
180
10年間のブログ発信を振り返って見えたWebアプリケーションエンジニアとしての軌跡
stefafafan
0
170
Bucharest Tech Week 2026 - Reinventing testing practices in the AI era
edeandrea
PRO
1
170
「勝手に広まる」人気 AI エージェントを爆速で作ろう!(AWS Summit Japan 2026講演資料)
minorun365
PRO
10
2k
【NRUG vol.18】KubernetesにおけるNew Relicデータ取得量削減の考え方
nrug_member
0
170
いまさら聞けない「仕様駆動開発入門」 〜AI活用時代の開発プロセスを考える〜
findy_eventslides
2
160
SONiC Scale-Up Working Group から探る Scale-UpやUltraEthernet機能の実装方法
ebiken
PRO
2
420
脱SaaS!FDEを支えるプロビジョニングと分離設計
knih
0
240
Featured
See All Featured
Believing is Seeing
oripsolob
1
150
Impact Scores and Hybrid Strategies: The future of link building
tamaranovitovic
0
310
What does AI have to do with Human Rights?
axbom
PRO
1
2.2k
[RailsConf 2023 Opening Keynote] The Magic of Rails
eileencodes
31
10k
技術選定の審美眼(2025年版) / Understanding the Spiral of Technologies 2025 edition
twada
PRO
118
120k
Why Your Marketing Sucks and What You Can Do About It - Sophie Logan
marketingsoph
0
170
Amusing Abliteration
ianozsvald
1
210
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
287
14k
WENDY [Excerpt]
tessaabrams
11
38k
Marketing Yourself as an Engineer | Alaka | Gurzu
gurzu
0
240
AI Search: Implications for SEO and How to Move Forward - #ShenzhenSEOConference
aleyda
1
1.3k
Art, The Web, and Tiny UX
lynnandtonic
304
22k
Transcript
1",63* SECCON 2019 Akihabara 2019/12/21 - 22 YOROZU @Mr.Rabbit 0QFSBUJPOXJUI5FOLFZ
Who am i ໊લ.S3BCCJU ࢿ֨ΞʔΫ༹ɺখܕҠಈࣜΫ Ϩʔϯɺۄֻ͚ɺେܕࣗಈंɺ 0481ɺ$*441ɺ44$1 طԟਥೋප झຯαόήʔɺΞχϝ ৬ྺݩαΠόʔσΟϑΣϯεݚڀॴ
ݚमੜ
What is PAKURI ? 1FOFUSBUJPOUFTU "DIJFWF ,OPXMFEHF 6OJUF 3BQJE *OUFSGBDF
What is PAKURI ? ϖωτϨʔγϣϯςετʹඞཁͦ͏ͳπʔϧΛدͤू Ίͯɺ୭Ͱɺ؆୯ʹɺͦΕͬΆ࣮͘ߦग़དྷΔ༷ʹߏ ͨ͠πʔϧ ͬ͘͟Γݴ͏ͱύΫͬͯΔXʢݖར৵ͯ͠·ͤΜʣ ͺ͘Δʢҟ௲ɿύΫΔʣ
ύΫύΫͱ৯Δɻେ͖ͳޱΛ։͚ͯ৯Δɻ ʢଏޠʣ伱Λ͍ͭͯۚΛ͔ͬ͞Β͏ɻۚમྉۚΛԣྖ͢Δɻ ʢଏޠʣ౪༻͢Δɻ ʢଏޠʣܯͳͲ͕ਓΛั·͑ɺัറ͢Δɻ IUUQTKBXJLUJPOBSZPSHXJLJͺ͘Δ
1",63*ͷೳྗ ใऩूٴͼྻڍ ੬ऑੑͷੳ ೝূࢼߦ &YQMPJUʢิॿʣ
ใͷՄࢹԽ
ҰൠతͳϖωτϨʔγϣϯςετͷྲྀΕ /P ςετ߲ આ໌ ϗετݕग़ *$.1Ԡ֬ೝΛ༻ͯ͠ɺରͱͳΔγεςϜ্ͷϗετ Λݕग़͢Δ 5$16%1εΩϟϯ
ٙࣅ߈ܸͷରͱͳΔϗετ͕ଘࡏ͠ϗετ্Ͱٙࣅ߈ܸର ʹͳΔαʔϏε͕Քಇ͍ͯ͠Δ͜ͱΛ֬ೝ͢Δ ੬ऑੑͷ֬ೝ ੬ऑੑεΩϟφΛར༻͠ཏతʹ੬ऑੑͷଘࡏΛ֬ೝ͢Δ ೝূࢼߦɾΞΫηεݖऔಘ ਪଌՄೳͳΞΧϯτɾύεϫʔυΛ༻͍ͯೝূࢼߦΛߦ ͍ɺαʔϏεΞϓϦέʔγϣϯͷར༻Մ൱Λ֬ೝ͢Δ ط੬ऑੑΛར༻ͨٙ͠ࣅ߈ܸ ط੬ऑੑΛར༻͠ɺ߈ܸίʔυΛ༻ͯٙ͠ࣅ߈ܸΛߦ ͍ɺ࣮ࡍʹ৵ೖٴͼใͷऔ͕Մೳ͔֬ೝ͢Δ Өڹͷ֬ೝ ٙࣅ߈ܸ͕ޭͨ͠ϗετͷݖݶϑΝΠϧΛੳ͠ଞͷ ϗετͷӨڹΛ֬ೝ͢Δ
1",63*ͰΓ͍ͨ͜ͱ /P ςετ߲ ϗετݕग़ 5$16%1εΩϟϯ ੬ऑੑͷ֬ೝ
ೝূࢼߦɾΞΫηεݖऔಘ ط੬ऑੑΛར༻ͨٙ͠ࣅ߈ܸ Өڹͷ֬ೝ ͜ͷൣғΛαϙʔτ͍ͨ͠ ใऩूٴͼྻڍ ੬ऑੑͷੳ ೝূࢼߦ &YQMPJUʢิॿʣ ใͷՄࢹԽ
ૢ࡞͕͍͠ͷͰʁ ͍͠ͷͪΐͬͱͶɾɾɾ
ςϯΩʔ͚ͩͰಈ͘Α
ը໘
جຊίϚϯυ ΤΫεϓϩΠτίϚϯυ ίϯϑΟάίϚϯυ εΩϟϯίϚϯυ ίϯϘΛܾΊͯ ίϚϯυ࣮ߦʂʂ
εΩϟϯίϯϘ Discovery Host Vulnerability Scan Well-known ports Scan(Details) AutoRecon ͳʹΛ͢Δʹ·ͣίϨ
ΦεεϝίϯϘ "VUP3FDPO %JTDPWFSZ)PTU
ΤΫεϓϩΠτίϯϘ Password Crack Create MSF DB Import to MSF DB
Start Metasploit Check the service ͚ແ༻ɺୟ͖ࠐΊʂ ΦεεϝίϯϘ 1BTTXPSE$SBDL
ίϯϑΟάίϯϘ Import data into Faraday Switch CUI mode Configure targets
Switch GUI mode ޭͷΧΪɺ४උീׂ ΦεεϝίϯϘ *NQPSUEBUBJOUP'BSBEBZ
ϥʔχϯά ͔Βͳ͍ࣄΛΔࣄ͕Ұ൪ͷֶͼ "TTJTU MFBSOUP ίϯϘͷ࠷ޙʹMFBSOUPΛબͿͱ ը໘ӈଆʹ࣮ߦ͞ΕΔίϚϯυͷ આ໌͕දࣔ͞ΕΔ "TTJTUΛબͿͱɺ֤جຊίϚϯ υͰͷಈ࡞ʹ͍ͭͯͷղઆΛද ࣔ͢Δ
1",63*ΛऔΓೖΕֶͨशαΠΫϧ ࣮ԋ ղઆ ʢϥʔχϯάʣ ࣮श ʢίϯϘʣ ޭମݧ ʢ݁ՌͷՄࢹԽʣ ͬͯΈͤɺݴͬͯฉ͔ͤͯɺͤͯ͞Έͤɺ΄ΊͯΒͶɺਓಈ͔͡ ࢁຊޒे
Your benefits ϨουνʔϜͷ߹ 1",63*Λ༻͢ΔࣄͰɺසൟʹར༻͢ΔίϚϯυΛ ೖྗ͢Δख͕ؒল͚·͢ɻ ॳ৺ऀͷϖϯςελʔɺ1",63*Λ༻ͯ͠߈ܸͷ ྲྀΕΛֶ·͢ɻ ϒϧʔνʔϜͷ߹
؆୯ͳૢ࡞Ͱɺ߈ܸऀͷߦಈΛ฿Ͱ͖·͢ɻ ˞͋͘·ͰҰྫͰ͢
ֶश͔Β࣮·ͰςϯΩʔ͚ͩͰͰ͖Δʂ
テンキーの子 Operation with Ten-key
·ͱΊ ɹϖϯςελʔखΛಈ͔͢͜ͱ͕େ͖Ͱ͢ɻ͔͠͠ɺ ໘͍͘͞࡞ۀ͖Ͱ͋Γ·ͤΜɻ1",63*ɺϖω τϨʔγϣϯςετͰසൟʹ༻͢ΔίϚϯυΛςϯΩʔ ͷૢ࡞͚ͩͰ࣮ߦ͠·͢ɻ·ΔͰ֨ಆήʔϜΛ͍ͬͯΔ Α͏ͳײ֮ͰͰ͖·͢ɻ
·ͱΊ ɹ1",63*ϖωτϨʔγϣϯςελʔͷΩϟϦΞΛ։ ࢝͢ΔͷʹʹཱͯΔͱࢥ͍·͢ɻ,BMJ5PPMTʹ४ڌ ͢ΔπʔϧΛ༻͍ͯ͠ΔͷͰඞཁҎ্ʹഁյ͢Δ͜ͱ ͠·ͤΜɻ1",63*Λ༻͢Δ͜ͱͰɺϖωτϨʔ γϣϯςετͷϑϩʔΛ؆୯ʹମݧֶ͠Ϳ͜ͱ͕ग़དྷ· ͢ɻ ɹ1",63*ΛͬͯΈͯɺϖωτϨʔγϣϯςετʹڵ ຯΛ͍࣋ͬͯͩ͘͞ɻ
Thank you! Please give me advice and feedback.
[email protected]
@PAKURI9
@01ra66it https://github.com/01rabbit/PAKURI