Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
淡路島で開催されたhardening2017fesにプレミアムサポートメンバーで参加してきたよ...
Search
delphinz
December 02, 2017
Technology
0
160
淡路島で開催されたhardening2017fesにプレミアムサポートメンバーで参加してきたよ。/20171202-go-for-hardening2017fes
2017年11月23日から3日間淡路島で開催されたhardening 2017 fesに参加してきた記録と紹介です。
次はあなたが地球を守る番ですよ!
delphinz
December 02, 2017
Tweet
Share
More Decks by delphinz
See All by delphinz
【セキュリティ競技】MINI Hardeningのご紹介 / MINI Hardneing4 introduction
delphinz
1
1.5k
20200209MINI_INFRA
delphinz
1
390
MINI Hardening Road to Taiwan(2019 HITCON CMT)
delphinz
0
980
WAFのルールである OWASP ModSecurity Core Rule Set (CRS)を 使った可視化までの苦労話/20180921_owasp_connect_crs
delphinz
2
1.7k
Other Decks in Technology
See All in Technology
「もしもデータ基盤開発で『強くてニューゲーム』ができたなら今の僕はどんなデータ基盤を作っただろう」
aeonpeople
0
250
AI との良い付き合い方を僕らは誰も知らない
asei
0
280
Authlete で実装する MCP OAuth 認可サーバー #CIMD の実装を添えて
watahani
0
200
AI with TiDD
shiraji
1
310
2025年のデザインシステムとAI 活用を振り返る
leveragestech
0
360
業務の煩悩を祓うAI活用術108選 / AI 108 Usages
smartbank
9
15k
Strands AgentsとNova 2 SonicでS2Sを実践してみた
yama3133
1
2k
_第4回__AIxIoTビジネス共創ラボ紹介資料_20251203.pdf
iotcomjpadmin
0
140
Oracle Database@Google Cloud:サービス概要のご紹介
oracle4engineer
PRO
1
770
日本Rubyの会: これまでとこれから
snoozer05
PRO
6
250
Amazon Connect アップデート! AIエージェントにMCPツールを設定してみた!
ysuzuki
0
150
MySQLとPostgreSQLのコレーション / Collation of MySQL and PostgreSQL
tmtms
1
1.3k
Featured
See All Featured
Become a Pro
speakerdeck
PRO
31
5.7k
GitHub's CSS Performance
jonrohan
1032
470k
コードの90%をAIが書く世界で何が待っているのか / What awaits us in a world where 90% of the code is written by AI
rkaga
57
41k
Claude Code どこまでも/ Claude Code Everywhere
nwiizo
61
50k
Site-Speed That Sticks
csswizardry
13
1k
Mozcon NYC 2025: Stop Losing SEO Traffic
samtorres
0
98
Exploring the relationship between traditional SERPs and Gen AI search
raygrieselhuber
PRO
2
3.5k
Crafting Experiences
bethany
0
22
How to build a perfect <img>
jonoalderson
0
4.8k
CoffeeScript is Beautiful & I Never Want to Write Plain JavaScript Again
sstephenson
162
16k
Done Done
chrislema
186
16k
Collaborative Software Design: How to facilitate domain modelling decisions
baasie
0
100
Transcript
Copyright © 2017 delphinz All Rights Reserved. ୶࿏ౡͰ։࠵͞Εͨ IBSEFOJOHGFTʹ ϓϨϛΞϜαϙʔτϝϯόʔͰ
ࢀՃ͖ͯͨ͠Αɻ 403".".&̑ !EFMQIJO[ ᖛͤͬ͘ʹ Զ͕ ग़ு൛ 4BU
Copyright © 2017 delphinz All Rights Reserved. ࣗݾհ ໊લɿMasahiro Tabataʢ@delphinzʣ
ࣄɿγεςϜίϯαϧλϯτͯ͠·͢ɻ ηΩϡϦςΟͨ͠ͳΈఔɻ झຯओʹ֨ಆٕ؍ઓͱྉཧɻBBQͰϚάϩͦͯ͠ಲΛ͖͞·͢ɻ MINI Hardening ӡӦϝϯόʔ(ϑΝγϦςʔγϣϯʣͬͯ·͢♫ ʢඇެೝʣ ᖛͤͬ͘উखʹԠԉஂஂʂҿΈ·͠ΐ͏ʂ
Copyright © 2017 delphinz All Rights Reserved. )BSEFOJOHGFTʹߦ͖ͬͯͨ ʮHardening 2017
Fesͱ໊͚ΒΕͨ͜ͷڝٕձɺ͜ͷɺ11݄23͔ Β25·Ͱͷ̏ؒɺຊඪ४࣌ࢠޕઢͷ௨ΔౡͰ͋Δฌݿݝ୶࿏ౡͰ։ ࠵͠·͢ɻʯ ճॏͶΔ͝ͱʹਓ૿͍͖͑ͯɺԠืഒ̑ഒ͔ۙͬͨΒ͍͠ʂ ʢ16νʔϜ Ͱ1νʔϜ6,7໊ʣ
Copyright © 2017 delphinz All Rights Reserved. )FEFOJOH1SPKFDUͱ ηΩϡϦςΟɾΠϕϯτʮHardening Projectʯͱɺ࠷ߴͷʮकΔʯٕ
ज़Λ࣋ͭτοϓΤϯδχΞΛൃ۷ɾݦজ͢ΔͷͰ͋Γɺٕज़ڝٕ(ίϯ ϖςΟγϣϯ)ͷܗࣜͰ࣮ࢪ͍ͯ͠·͢ɻ Hardening ProjectͰ։࠵͢ΔڝٕɺجຊతʹνʔϜର߅Ͱɺ੬ऑੑͷ ͋ΔECαΠτͷϋʔυχϯά(ݎ࿚Խ)ྗͷڧ͞Λ૯߹తʹڝ͏ίϯϖ ςΟγϣϯͷܗΛͱΓ·͢ɻڝٕ༰ɺηΩϡϦςΟΛѻ͏ਓ͕ߩݙ ͢Δɺݱ࣮తͳΛͲͷΑ͏ʹѻ͔ͬͯ͘ʹয͕͋ͯΒΕ·͢ɻ ࢀՃνʔϜɺใ௨৴ݚڀػߏͷ༗͢ΔStarBEDʹߏங͞ΕͨɺԾ ͷωοτϫʔΫڥͰڝٕ͠·͢ɻ IUUQTXBTGPSVNKQIBSEFOJOHQSPKFDU
Copyright © 2017 delphinz All Rights Reserved. ҙ༁͢Δͱ
Copyright © 2017 delphinz All Rights Reserved. ͋ͳͨୡࠓ͔ΒγεςϜཧऀͶɻ ࠓ͔Β๊͓͑ϋοΧʔ͕̍μʔε ·ͱΊͯϋοΩϯά͠ʹ͘Δ͔Β͏ͪ
ͷECαΠτΛམͱ͞ͳ͍Α͏ʹ࣌̕ ؒ͘Β͍ɺ͍͍ײ͡Ͱक͓͍ͬͯͯͶ ♫
Copyright © 2017 delphinz All Rights Reserved. ӡӦ͢Δਓͨͪ ,630.".& •
ֳαΠόʔηΩϡϦςΟηϯλʔ • ηΩϡϦςΟاۀ ݚڀॴॴ • ηΩϡϦςΟΩϟϯϓओࠪ • ౦ژΦϦϯϐοΫҕһ ܯඋہ • ࠃ࠷ߴๆϖϯςελʔ • ݩJPCERT/CC ϚϧΣΞݚڀऀ • ૯ল ྅ ʢ͘͝Ұ෦հʣ ͳΜ͔ͦ͏ʂʂʂ
Copyright © 2017 delphinz All Rights Reserved. ڝٕ෩ܠͦͷ̍ औకձʹݺΕͯ ใ࿙Ӯࣄ݅ͷઆ໌த
ࣾཪ൪ͷ08"41 ,"/4"*ొஃத 403".".&͓ങ্͍͛ ച্ͱ4-"Λදࣔ͢Δ είΞϘʔυʹώϯτ͕ʂʁ
Copyright © 2017 delphinz All Rights Reserved. ڝٕ෩ܠͦͷ̎ Ջͱ͍͏ཧ༝Ͱ Ϧϒʔτ͞ΕΔαʔό
෮چͰ͖ͳ͍ ϚϧΣΞ෮چαʔϏε (PPHMF)PNFʹΑΔ ύεϫʔυ࿐
Copyright © 2017 delphinz All Rights Reserved. ϚʔέοτϓϨΠεΛ׆༻͠Α͏ ڝٕதνʔϜͷ֎෦͔ΒαʔϏεɾΛௐୡͰ͖ΔʮϚʔέοτϓϨΠ ε(ڝٕϦιʔεɾαʔϏεௐୡ)ʯ͕༻ҙ͞Ε·͢ɻ
͜ΕʹΑΓɺνʔϜʹෆ͍ͯ͠ΔϦιʔεɺڝٕʹඞཁͱࢥΘΕΔ༻ Λόʔ νϟϧʹʮߪೖʯ͠ɺཱͯΔ͜ͱ͕Ͱ͖·͢ɻ (Ұ෦ൈਮʣ ϚʔέοτϓϨΠεࢀՃاۀ ߽՚ͳηΩϡϦςΟاۀͷதʹ ͳ͔ͥݱΕΔl403".".&z
Copyright © 2017 delphinz All Rights Reserved. ͳΜͰ403".".&ͳͷʁ • 2016݄̎ʹWAS
ForumදͷԬాྑଠ͞Μ໊͕͚ MINI hardening ͰKuromameʹଓ͘ελʔΛൃ۷͠Α͏ʂ ʮͰԶͨͪ·ͩࠇ͘ͳ͍ʂʯ 5FBN403".".& ͦΜͳܦҢ͋ͬͯॳ৺ऀΛαϙʔτ͢ΔͨΊͷ νʔϜʹબൈ͞Ε·ͨ͠! ͦΒ౾ͷՖݴ༿ ʮಌΕʯ
Copyright © 2017 delphinz All Rights Reserved. SORAMAME5 ϓϨϛΞϜαϙʔτ
Copyright © 2017 delphinz All Rights Reserved. αʔϏε֓ཁ ▸ Hardeningͷͯ͢ΛΓਚͨ͘͠SORAMAME5ϝϯόʔ͕
͋ͳͨͷνʔϜͷڝٕӡӦΛαϙʔτʂ SORAMAME5ϝϯόʔ͕͋ͳͨͷνʔϜʹ࠷ΠϯύΫτͷ͋Δ ࢪࡦΛఏҊ͠·͢ɻ ▸ ڝٕΛڧྗʹαϙʔτ͢ΔͨΊͷπʔϧΛඪ४ఏڙ ɾ౷߹ϩάࢹڥ ɾશνʔϜͷϓϥΠενΣοΫ ɾ֎෦͔ΒݟͨECαΠτͷεΫϦʔϯγϣοτΛνΣοΫ ΤʔδΣϯτΠϯετʔϧʹ͔͔࣌ؒΓ͗ͯ͢அ೦ ࣌ؒͰΫϩʔϥॻ͍ͨʂ ॏ͗ͯ͢ಈ͔ͳ͍ɻ֎෦͔ΒͷONBQͱεΩϟϯπʔϧͰ༻ νʔϜதνʔϜʹ͓ങ্͍͖͛·ͨ͠ʂ
Copyright © 2017 delphinz All Rights Reserved. ʢ൵ใʣਓࣄҟಈͷ͓Βͤ ·͔͞ͷ͓͔ΘΓʢ̎࣌ؒԆೖΓ·͢ʂʣ ΈΜͳେ͖ɺ࡞ۀҾ͖ܧ͗࡞ۀ
ࣾΛ͠ɺϝϯόʔ ผͷνʔϜҠಈ βϫβϫ
Copyright © 2017 delphinz All Rights Reserved. ࠓޙΛߟ͑ΔΞϯΧϯϑΝϨϯε ԶͨͪͷhardeningڝٕΛ࡞Ζ͏ʂηΩϡϦςΟਓࡐͷࠓޙΛߟ͑Δʂɺ ͳͲ͍͕ٞߦΘΕ·ͨ͠ɻ
Copyright © 2017 delphinz All Rights Reserved. ΈΜͳͰߦ͜͏ʮਫ਼ਆͱ࣌ͷ෦ʯ ʮਫ਼ਆͱ࣌ͷ෦ʯອըυϥΰϯϘʔϧʹग़ͯ͘Δमߦͷͷ͜ͱɻ ֎քͰͷ1͕͜ͷ෦ͷதͰ1ʢ365ʣʹ૬͢Δɻ
ʢ࠷ۙए͍ࢠʹυϥΰϯϘʔϧݟͯͳ͍ΜͰΒͳ͍ͬ͢ɺͱݴΘΕ· ͨ͠ɻʣ աڈʹHardening Projectͷओ࠵ͷྛઌੜʹฉ͍ͨͱ͜ΖʹΑΔͱʮ2ϲ݄ ͘Β͍Ͱൃੜ͢ΔͰ͋Ζ͏ηΩϡϦςΟΠϯγσϯτΛ̔࣌ؒͷڝٕʹ٧ ΊࠐΜͩʯͱͷ͜ͱɻ ѹॖͨ࣌ؒ͠ͷΠϯγσϯτମݧ͍͢͝εϐʔυͰΛଅ͠·͢ʂ
Copyright © 2017 delphinz All Rights Reserved. ٿΛʮӴΔʯؒΛ୳͠ʹߦ͜͏ʂ ୩ढ़ଠ ʮேͷϦϨʔʯͷҰઅΑΓ
”ΒேΛϦϨʔ͢Δͷͩɺܦ͔Βܦͱ ͦ͏͍ͯ͠ΘަͰٿΛकΔ” Έͳ͞ΜؒͱҰॹʹ୭͔ͷேΛक͍͖ͬͯ·͠ΐ͏ɻ ࣍ճ͋ͳͨͷ൪Ͱ͢Αʂ
Copyright © 2017 delphinz All Rights Reserved. ΞφλͷʮӴΔʯʹدΓఴ͍͍ͨ 403".".& ͝੩ௌ͋Γ͕ͱ͏͍͟͝·ͨ͠ɻ