Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
淡路島で開催されたhardening2017fesにプレミアムサポートメンバーで参加してきたよ...
Search
delphinz
December 02, 2017
Technology
0
120
淡路島で開催されたhardening2017fesにプレミアムサポートメンバーで参加してきたよ。/20171202-go-for-hardening2017fes
2017年11月23日から3日間淡路島で開催されたhardening 2017 fesに参加してきた記録と紹介です。
次はあなたが地球を守る番ですよ!
delphinz
December 02, 2017
Tweet
Share
More Decks by delphinz
See All by delphinz
【セキュリティ競技】MINI Hardeningのご紹介 / MINI Hardneing4 introduction
delphinz
1
1.1k
20200209MINI_INFRA
delphinz
1
340
MINI Hardening Road to Taiwan(2019 HITCON CMT)
delphinz
0
850
WAFのルールである OWASP ModSecurity Core Rule Set (CRS)を 使った可視化までの苦労話/20180921_owasp_connect_crs
delphinz
2
1.6k
Other Decks in Technology
See All in Technology
プロダクト成長に対応するプラットフォーム戦略:Authleteによる共通認証基盤の移行事例 / Building an authentication platform using Authlete and AWS
kakehashi
1
150
VPC間の接続方法を整理してみた #自治体クラウド勉強会
non97
1
820
Vueで Webコンポーネントを作って Reactで使う / 20241030-cloudsign-vuefes_after_night
bengo4com
4
2.5k
物価高なラスベガスでの過ごし方
zakky
0
370
一休.comレストランにおけるRustの活用
kymmt90
3
580
プロダクトチームへのSystem Risk Records導入・運用事例の紹介/Introduction and Case Studies on Implementing and Operating System Risk Records for Product Teams
taddy_919
1
170
AIを駆使したゲーム開発戦略: 新設AI組織の取り組み / sge-ai-strategy
cyberagentdevelopers
PRO
1
130
[AWS JAPAN 生成AIハッカソン] Dialog の紹介
yoshimi0227
0
150
チームを主語にしてみる / Making "Team" the Subject
ar_tama
4
310
WINTICKETアプリで実現した高可用性と高速リリースを支えるエコシステム / winticket-eco-system
cyberagentdevelopers
PRO
1
190
新卒1年目が挑む!生成AI × マルチエージェントで実現する次世代オンボーディング / operation-ai-onboarding
cyberagentdevelopers
PRO
1
160
MAMを軸とした動画ハンドリングにおけるAI活用前提の整備と次世代ビジョン / abema-ai-mam
cyberagentdevelopers
PRO
1
110
Featured
See All Featured
[Rails World 2023 - Day 1 Closing Keynote] - The Magic of Rails
eileencodes
32
1.8k
ReactJS: Keep Simple. Everything can be a component!
pedronauck
664
120k
The Art of Programming - Codeland 2020
erikaheidi
51
13k
Practical Tips for Bootstrapping Information Extraction Pipelines
honnibal
PRO
9
680
Java REST API Framework Comparison - PWX 2021
mraible
PRO
28
7.9k
Side Projects
sachag
452
42k
Code Review Best Practice
trishagee
64
17k
CSS Pre-Processors: Stylus, Less & Sass
bermonpainter
355
29k
Designing for Performance
lara
604
68k
Typedesign – Prime Four
hannesfritz
39
2.4k
We Have a Design System, Now What?
morganepeng
50
7.2k
Into the Great Unknown - MozCon
thekraken
31
1.5k
Transcript
Copyright © 2017 delphinz All Rights Reserved. ୶࿏ౡͰ։࠵͞Εͨ IBSEFOJOHGFTʹ ϓϨϛΞϜαϙʔτϝϯόʔͰ
ࢀՃ͖ͯͨ͠Αɻ 403".".&̑ !EFMQIJO[ ᖛͤͬ͘ʹ Զ͕ ग़ு൛ 4BU
Copyright © 2017 delphinz All Rights Reserved. ࣗݾհ ໊લɿMasahiro Tabataʢ@delphinzʣ
ࣄɿγεςϜίϯαϧλϯτͯ͠·͢ɻ ηΩϡϦςΟͨ͠ͳΈఔɻ झຯओʹ֨ಆٕ؍ઓͱྉཧɻBBQͰϚάϩͦͯ͠ಲΛ͖͞·͢ɻ MINI Hardening ӡӦϝϯόʔ(ϑΝγϦςʔγϣϯʣͬͯ·͢♫ ʢඇެೝʣ ᖛͤͬ͘উखʹԠԉஂஂʂҿΈ·͠ΐ͏ʂ
Copyright © 2017 delphinz All Rights Reserved. )BSEFOJOHGFTʹߦ͖ͬͯͨ ʮHardening 2017
Fesͱ໊͚ΒΕͨ͜ͷڝٕձɺ͜ͷɺ11݄23͔ Β25·Ͱͷ̏ؒɺຊඪ४࣌ࢠޕઢͷ௨ΔౡͰ͋Δฌݿݝ୶࿏ౡͰ։ ࠵͠·͢ɻʯ ճॏͶΔ͝ͱʹਓ૿͍͖͑ͯɺԠืഒ̑ഒ͔ۙͬͨΒ͍͠ʂ ʢ16νʔϜ Ͱ1νʔϜ6,7໊ʣ
Copyright © 2017 delphinz All Rights Reserved. )FEFOJOH1SPKFDUͱ ηΩϡϦςΟɾΠϕϯτʮHardening Projectʯͱɺ࠷ߴͷʮकΔʯٕ
ज़Λ࣋ͭτοϓΤϯδχΞΛൃ۷ɾݦজ͢ΔͷͰ͋Γɺٕज़ڝٕ(ίϯ ϖςΟγϣϯ)ͷܗࣜͰ࣮ࢪ͍ͯ͠·͢ɻ Hardening ProjectͰ։࠵͢ΔڝٕɺجຊతʹνʔϜର߅Ͱɺ੬ऑੑͷ ͋ΔECαΠτͷϋʔυχϯά(ݎ࿚Խ)ྗͷڧ͞Λ૯߹తʹڝ͏ίϯϖ ςΟγϣϯͷܗΛͱΓ·͢ɻڝٕ༰ɺηΩϡϦςΟΛѻ͏ਓ͕ߩݙ ͢Δɺݱ࣮తͳΛͲͷΑ͏ʹѻ͔ͬͯ͘ʹয͕͋ͯΒΕ·͢ɻ ࢀՃνʔϜɺใ௨৴ݚڀػߏͷ༗͢ΔStarBEDʹߏங͞ΕͨɺԾ ͷωοτϫʔΫڥͰڝٕ͠·͢ɻ IUUQTXBTGPSVNKQIBSEFOJOHQSPKFDU
Copyright © 2017 delphinz All Rights Reserved. ҙ༁͢Δͱ
Copyright © 2017 delphinz All Rights Reserved. ͋ͳͨୡࠓ͔ΒγεςϜཧऀͶɻ ࠓ͔Β๊͓͑ϋοΧʔ͕̍μʔε ·ͱΊͯϋοΩϯά͠ʹ͘Δ͔Β͏ͪ
ͷECαΠτΛམͱ͞ͳ͍Α͏ʹ࣌̕ ؒ͘Β͍ɺ͍͍ײ͡Ͱक͓͍ͬͯͯͶ ♫
Copyright © 2017 delphinz All Rights Reserved. ӡӦ͢Δਓͨͪ ,630.".& •
ֳαΠόʔηΩϡϦςΟηϯλʔ • ηΩϡϦςΟاۀ ݚڀॴॴ • ηΩϡϦςΟΩϟϯϓओࠪ • ౦ژΦϦϯϐοΫҕһ ܯඋہ • ࠃ࠷ߴๆϖϯςελʔ • ݩJPCERT/CC ϚϧΣΞݚڀऀ • ૯ল ྅ ʢ͘͝Ұ෦հʣ ͳΜ͔ͦ͏ʂʂʂ
Copyright © 2017 delphinz All Rights Reserved. ڝٕ෩ܠͦͷ̍ औకձʹݺΕͯ ใ࿙Ӯࣄ݅ͷઆ໌த
ࣾཪ൪ͷ08"41 ,"/4"*ొஃத 403".".&͓ങ্͍͛ ച্ͱ4-"Λදࣔ͢Δ είΞϘʔυʹώϯτ͕ʂʁ
Copyright © 2017 delphinz All Rights Reserved. ڝٕ෩ܠͦͷ̎ Ջͱ͍͏ཧ༝Ͱ Ϧϒʔτ͞ΕΔαʔό
෮چͰ͖ͳ͍ ϚϧΣΞ෮چαʔϏε (PPHMF)PNFʹΑΔ ύεϫʔυ࿐
Copyright © 2017 delphinz All Rights Reserved. ϚʔέοτϓϨΠεΛ׆༻͠Α͏ ڝٕதνʔϜͷ֎෦͔ΒαʔϏεɾΛௐୡͰ͖ΔʮϚʔέοτϓϨΠ ε(ڝٕϦιʔεɾαʔϏεௐୡ)ʯ͕༻ҙ͞Ε·͢ɻ
͜ΕʹΑΓɺνʔϜʹෆ͍ͯ͠ΔϦιʔεɺڝٕʹඞཁͱࢥΘΕΔ༻ Λόʔ νϟϧʹʮߪೖʯ͠ɺཱͯΔ͜ͱ͕Ͱ͖·͢ɻ (Ұ෦ൈਮʣ ϚʔέοτϓϨΠεࢀՃاۀ ߽՚ͳηΩϡϦςΟاۀͷதʹ ͳ͔ͥݱΕΔl403".".&z
Copyright © 2017 delphinz All Rights Reserved. ͳΜͰ403".".&ͳͷʁ • 2016݄̎ʹWAS
ForumදͷԬాྑଠ͞Μ໊͕͚ MINI hardening ͰKuromameʹଓ͘ελʔΛൃ۷͠Α͏ʂ ʮͰԶͨͪ·ͩࠇ͘ͳ͍ʂʯ 5FBN403".".& ͦΜͳܦҢ͋ͬͯॳ৺ऀΛαϙʔτ͢ΔͨΊͷ νʔϜʹબൈ͞Ε·ͨ͠! ͦΒ౾ͷՖݴ༿ ʮಌΕʯ
Copyright © 2017 delphinz All Rights Reserved. SORAMAME5 ϓϨϛΞϜαϙʔτ
Copyright © 2017 delphinz All Rights Reserved. αʔϏε֓ཁ ▸ Hardeningͷͯ͢ΛΓਚͨ͘͠SORAMAME5ϝϯόʔ͕
͋ͳͨͷνʔϜͷڝٕӡӦΛαϙʔτʂ SORAMAME5ϝϯόʔ͕͋ͳͨͷνʔϜʹ࠷ΠϯύΫτͷ͋Δ ࢪࡦΛఏҊ͠·͢ɻ ▸ ڝٕΛڧྗʹαϙʔτ͢ΔͨΊͷπʔϧΛඪ४ఏڙ ɾ౷߹ϩάࢹڥ ɾશνʔϜͷϓϥΠενΣοΫ ɾ֎෦͔ΒݟͨECαΠτͷεΫϦʔϯγϣοτΛνΣοΫ ΤʔδΣϯτΠϯετʔϧʹ͔͔࣌ؒΓ͗ͯ͢அ೦ ࣌ؒͰΫϩʔϥॻ͍ͨʂ ॏ͗ͯ͢ಈ͔ͳ͍ɻ֎෦͔ΒͷONBQͱεΩϟϯπʔϧͰ༻ νʔϜதνʔϜʹ͓ങ্͍͖͛·ͨ͠ʂ
Copyright © 2017 delphinz All Rights Reserved. ʢ൵ใʣਓࣄҟಈͷ͓Βͤ ·͔͞ͷ͓͔ΘΓʢ̎࣌ؒԆೖΓ·͢ʂʣ ΈΜͳେ͖ɺ࡞ۀҾ͖ܧ͗࡞ۀ
ࣾΛ͠ɺϝϯόʔ ผͷνʔϜҠಈ βϫβϫ
Copyright © 2017 delphinz All Rights Reserved. ࠓޙΛߟ͑ΔΞϯΧϯϑΝϨϯε ԶͨͪͷhardeningڝٕΛ࡞Ζ͏ʂηΩϡϦςΟਓࡐͷࠓޙΛߟ͑Δʂɺ ͳͲ͍͕ٞߦΘΕ·ͨ͠ɻ
Copyright © 2017 delphinz All Rights Reserved. ΈΜͳͰߦ͜͏ʮਫ਼ਆͱ࣌ͷ෦ʯ ʮਫ਼ਆͱ࣌ͷ෦ʯອըυϥΰϯϘʔϧʹग़ͯ͘Δमߦͷͷ͜ͱɻ ֎քͰͷ1͕͜ͷ෦ͷதͰ1ʢ365ʣʹ૬͢Δɻ
ʢ࠷ۙए͍ࢠʹυϥΰϯϘʔϧݟͯͳ͍ΜͰΒͳ͍ͬ͢ɺͱݴΘΕ· ͨ͠ɻʣ աڈʹHardening Projectͷओ࠵ͷྛઌੜʹฉ͍ͨͱ͜ΖʹΑΔͱʮ2ϲ݄ ͘Β͍Ͱൃੜ͢ΔͰ͋Ζ͏ηΩϡϦςΟΠϯγσϯτΛ̔࣌ؒͷڝٕʹ٧ ΊࠐΜͩʯͱͷ͜ͱɻ ѹॖͨ࣌ؒ͠ͷΠϯγσϯτମݧ͍͢͝εϐʔυͰΛଅ͠·͢ʂ
Copyright © 2017 delphinz All Rights Reserved. ٿΛʮӴΔʯؒΛ୳͠ʹߦ͜͏ʂ ୩ढ़ଠ ʮேͷϦϨʔʯͷҰઅΑΓ
”ΒேΛϦϨʔ͢Δͷͩɺܦ͔Βܦͱ ͦ͏͍ͯ͠ΘަͰٿΛकΔ” Έͳ͞ΜؒͱҰॹʹ୭͔ͷேΛक͍͖ͬͯ·͠ΐ͏ɻ ࣍ճ͋ͳͨͷ൪Ͱ͢Αʂ
Copyright © 2017 delphinz All Rights Reserved. ΞφλͷʮӴΔʯʹدΓఴ͍͍ͨ 403".".& ͝੩ௌ͋Γ͕ͱ͏͍͟͝·ͨ͠ɻ