Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
淡路島で開催されたhardening2017fesにプレミアムサポートメンバーで参加してきたよ...
Search
delphinz
December 02, 2017
Technology
0
120
淡路島で開催されたhardening2017fesにプレミアムサポートメンバーで参加してきたよ。/20171202-go-for-hardening2017fes
2017年11月23日から3日間淡路島で開催されたhardening 2017 fesに参加してきた記録と紹介です。
次はあなたが地球を守る番ですよ!
delphinz
December 02, 2017
Tweet
Share
More Decks by delphinz
See All by delphinz
【セキュリティ競技】MINI Hardeningのご紹介 / MINI Hardneing4 introduction
delphinz
1
1.2k
20200209MINI_INFRA
delphinz
1
350
MINI Hardening Road to Taiwan(2019 HITCON CMT)
delphinz
0
860
WAFのルールである OWASP ModSecurity Core Rule Set (CRS)を 使った可視化までの苦労話/20180921_owasp_connect_crs
delphinz
2
1.6k
Other Decks in Technology
See All in Technology
20241214_WACATE2024冬_テスト設計技法をチョット俯瞰してみよう
kzsuzuki
3
670
多領域インシデントマネジメントへの挑戦:ハードウェアとソフトウェアの融合が生む課題/Challenge to multidisciplinary incident management: Issues created by the fusion of hardware and software
bitkey
PRO
2
110
怖くない!ゼロから始めるPHPソースコードコンパイル入門
colopl
0
150
ゼロから創る横断SREチーム 挑戦と進化の軌跡
rvirus0817
2
280
20241220_S3 tablesの使い方を検証してみた
handy
4
680
LINEスキマニにおけるフロントエンド開発
lycorptech_jp
PRO
0
340
Yahoo! ズバトクにおけるフロントエンド開発
lycorptech_jp
PRO
0
100
KnowledgeBaseDocuments APIでベクトルインデックス管理を自動化する
iidaxs
1
280
生成AIをより賢く エンジニアのための RAG入門 - Oracle AI Jam Session #20
kutsushitaneko
4
290
UI State設計とテスト方針
rmakiyama
3
780
.NET 9 のパフォーマンス改善
nenonaninu
0
1.3k
AWS環境におけるランサムウェア攻撃対策の設計
nrinetcom
PRO
0
140
Featured
See All Featured
How to Think Like a Performance Engineer
csswizardry
22
1.2k
CSS Pre-Processors: Stylus, Less & Sass
bermonpainter
356
29k
Dealing with People You Can't Stand - Big Design 2015
cassininazir
365
25k
KATA
mclloyd
29
14k
Optimizing for Happiness
mojombo
376
70k
The Art of Programming - Codeland 2020
erikaheidi
53
13k
The Success of Rails: Ensuring Growth for the Next 100 Years
eileencodes
44
6.9k
Agile that works and the tools we love
rasmusluckow
328
21k
Designing on Purpose - Digital PM Summit 2013
jponch
116
7k
Music & Morning Musume
bryan
46
6.2k
Designing for Performance
lara
604
68k
StorybookのUI Testing Handbookを読んだ
zakiyama
27
5.3k
Transcript
Copyright © 2017 delphinz All Rights Reserved. ୶࿏ౡͰ։࠵͞Εͨ IBSEFOJOHGFTʹ ϓϨϛΞϜαϙʔτϝϯόʔͰ
ࢀՃ͖ͯͨ͠Αɻ 403".".&̑ !EFMQIJO[ ᖛͤͬ͘ʹ Զ͕ ग़ு൛ 4BU
Copyright © 2017 delphinz All Rights Reserved. ࣗݾհ ໊લɿMasahiro Tabataʢ@delphinzʣ
ࣄɿγεςϜίϯαϧλϯτͯ͠·͢ɻ ηΩϡϦςΟͨ͠ͳΈఔɻ झຯओʹ֨ಆٕ؍ઓͱྉཧɻBBQͰϚάϩͦͯ͠ಲΛ͖͞·͢ɻ MINI Hardening ӡӦϝϯόʔ(ϑΝγϦςʔγϣϯʣͬͯ·͢♫ ʢඇެೝʣ ᖛͤͬ͘উखʹԠԉஂஂʂҿΈ·͠ΐ͏ʂ
Copyright © 2017 delphinz All Rights Reserved. )BSEFOJOHGFTʹߦ͖ͬͯͨ ʮHardening 2017
Fesͱ໊͚ΒΕͨ͜ͷڝٕձɺ͜ͷɺ11݄23͔ Β25·Ͱͷ̏ؒɺຊඪ४࣌ࢠޕઢͷ௨ΔౡͰ͋Δฌݿݝ୶࿏ౡͰ։ ࠵͠·͢ɻʯ ճॏͶΔ͝ͱʹਓ૿͍͖͑ͯɺԠืഒ̑ഒ͔ۙͬͨΒ͍͠ʂ ʢ16νʔϜ Ͱ1νʔϜ6,7໊ʣ
Copyright © 2017 delphinz All Rights Reserved. )FEFOJOH1SPKFDUͱ ηΩϡϦςΟɾΠϕϯτʮHardening Projectʯͱɺ࠷ߴͷʮकΔʯٕ
ज़Λ࣋ͭτοϓΤϯδχΞΛൃ۷ɾݦজ͢ΔͷͰ͋Γɺٕज़ڝٕ(ίϯ ϖςΟγϣϯ)ͷܗࣜͰ࣮ࢪ͍ͯ͠·͢ɻ Hardening ProjectͰ։࠵͢ΔڝٕɺجຊతʹνʔϜର߅Ͱɺ੬ऑੑͷ ͋ΔECαΠτͷϋʔυχϯά(ݎ࿚Խ)ྗͷڧ͞Λ૯߹తʹڝ͏ίϯϖ ςΟγϣϯͷܗΛͱΓ·͢ɻڝٕ༰ɺηΩϡϦςΟΛѻ͏ਓ͕ߩݙ ͢Δɺݱ࣮తͳΛͲͷΑ͏ʹѻ͔ͬͯ͘ʹয͕͋ͯΒΕ·͢ɻ ࢀՃνʔϜɺใ௨৴ݚڀػߏͷ༗͢ΔStarBEDʹߏங͞ΕͨɺԾ ͷωοτϫʔΫڥͰڝٕ͠·͢ɻ IUUQTXBTGPSVNKQIBSEFOJOHQSPKFDU
Copyright © 2017 delphinz All Rights Reserved. ҙ༁͢Δͱ
Copyright © 2017 delphinz All Rights Reserved. ͋ͳͨୡࠓ͔ΒγεςϜཧऀͶɻ ࠓ͔Β๊͓͑ϋοΧʔ͕̍μʔε ·ͱΊͯϋοΩϯά͠ʹ͘Δ͔Β͏ͪ
ͷECαΠτΛམͱ͞ͳ͍Α͏ʹ࣌̕ ؒ͘Β͍ɺ͍͍ײ͡Ͱक͓͍ͬͯͯͶ ♫
Copyright © 2017 delphinz All Rights Reserved. ӡӦ͢Δਓͨͪ ,630.".& •
ֳαΠόʔηΩϡϦςΟηϯλʔ • ηΩϡϦςΟاۀ ݚڀॴॴ • ηΩϡϦςΟΩϟϯϓओࠪ • ౦ژΦϦϯϐοΫҕһ ܯඋہ • ࠃ࠷ߴๆϖϯςελʔ • ݩJPCERT/CC ϚϧΣΞݚڀऀ • ૯ল ྅ ʢ͘͝Ұ෦հʣ ͳΜ͔ͦ͏ʂʂʂ
Copyright © 2017 delphinz All Rights Reserved. ڝٕ෩ܠͦͷ̍ औకձʹݺΕͯ ใ࿙Ӯࣄ݅ͷઆ໌த
ࣾཪ൪ͷ08"41 ,"/4"*ొஃத 403".".&͓ങ্͍͛ ച্ͱ4-"Λදࣔ͢Δ είΞϘʔυʹώϯτ͕ʂʁ
Copyright © 2017 delphinz All Rights Reserved. ڝٕ෩ܠͦͷ̎ Ջͱ͍͏ཧ༝Ͱ Ϧϒʔτ͞ΕΔαʔό
෮چͰ͖ͳ͍ ϚϧΣΞ෮چαʔϏε (PPHMF)PNFʹΑΔ ύεϫʔυ࿐
Copyright © 2017 delphinz All Rights Reserved. ϚʔέοτϓϨΠεΛ׆༻͠Α͏ ڝٕதνʔϜͷ֎෦͔ΒαʔϏεɾΛௐୡͰ͖ΔʮϚʔέοτϓϨΠ ε(ڝٕϦιʔεɾαʔϏεௐୡ)ʯ͕༻ҙ͞Ε·͢ɻ
͜ΕʹΑΓɺνʔϜʹෆ͍ͯ͠ΔϦιʔεɺڝٕʹඞཁͱࢥΘΕΔ༻ Λόʔ νϟϧʹʮߪೖʯ͠ɺཱͯΔ͜ͱ͕Ͱ͖·͢ɻ (Ұ෦ൈਮʣ ϚʔέοτϓϨΠεࢀՃاۀ ߽՚ͳηΩϡϦςΟاۀͷதʹ ͳ͔ͥݱΕΔl403".".&z
Copyright © 2017 delphinz All Rights Reserved. ͳΜͰ403".".&ͳͷʁ • 2016݄̎ʹWAS
ForumදͷԬాྑଠ͞Μ໊͕͚ MINI hardening ͰKuromameʹଓ͘ελʔΛൃ۷͠Α͏ʂ ʮͰԶͨͪ·ͩࠇ͘ͳ͍ʂʯ 5FBN403".".& ͦΜͳܦҢ͋ͬͯॳ৺ऀΛαϙʔτ͢ΔͨΊͷ νʔϜʹબൈ͞Ε·ͨ͠! ͦΒ౾ͷՖݴ༿ ʮಌΕʯ
Copyright © 2017 delphinz All Rights Reserved. SORAMAME5 ϓϨϛΞϜαϙʔτ
Copyright © 2017 delphinz All Rights Reserved. αʔϏε֓ཁ ▸ Hardeningͷͯ͢ΛΓਚͨ͘͠SORAMAME5ϝϯόʔ͕
͋ͳͨͷνʔϜͷڝٕӡӦΛαϙʔτʂ SORAMAME5ϝϯόʔ͕͋ͳͨͷνʔϜʹ࠷ΠϯύΫτͷ͋Δ ࢪࡦΛఏҊ͠·͢ɻ ▸ ڝٕΛڧྗʹαϙʔτ͢ΔͨΊͷπʔϧΛඪ४ఏڙ ɾ౷߹ϩάࢹڥ ɾશνʔϜͷϓϥΠενΣοΫ ɾ֎෦͔ΒݟͨECαΠτͷεΫϦʔϯγϣοτΛνΣοΫ ΤʔδΣϯτΠϯετʔϧʹ͔͔࣌ؒΓ͗ͯ͢அ೦ ࣌ؒͰΫϩʔϥॻ͍ͨʂ ॏ͗ͯ͢ಈ͔ͳ͍ɻ֎෦͔ΒͷONBQͱεΩϟϯπʔϧͰ༻ νʔϜதνʔϜʹ͓ങ্͍͖͛·ͨ͠ʂ
Copyright © 2017 delphinz All Rights Reserved. ʢ൵ใʣਓࣄҟಈͷ͓Βͤ ·͔͞ͷ͓͔ΘΓʢ̎࣌ؒԆೖΓ·͢ʂʣ ΈΜͳେ͖ɺ࡞ۀҾ͖ܧ͗࡞ۀ
ࣾΛ͠ɺϝϯόʔ ผͷνʔϜҠಈ βϫβϫ
Copyright © 2017 delphinz All Rights Reserved. ࠓޙΛߟ͑ΔΞϯΧϯϑΝϨϯε ԶͨͪͷhardeningڝٕΛ࡞Ζ͏ʂηΩϡϦςΟਓࡐͷࠓޙΛߟ͑Δʂɺ ͳͲ͍͕ٞߦΘΕ·ͨ͠ɻ
Copyright © 2017 delphinz All Rights Reserved. ΈΜͳͰߦ͜͏ʮਫ਼ਆͱ࣌ͷ෦ʯ ʮਫ਼ਆͱ࣌ͷ෦ʯອըυϥΰϯϘʔϧʹग़ͯ͘Δमߦͷͷ͜ͱɻ ֎քͰͷ1͕͜ͷ෦ͷதͰ1ʢ365ʣʹ૬͢Δɻ
ʢ࠷ۙए͍ࢠʹυϥΰϯϘʔϧݟͯͳ͍ΜͰΒͳ͍ͬ͢ɺͱݴΘΕ· ͨ͠ɻʣ աڈʹHardening Projectͷओ࠵ͷྛઌੜʹฉ͍ͨͱ͜ΖʹΑΔͱʮ2ϲ݄ ͘Β͍Ͱൃੜ͢ΔͰ͋Ζ͏ηΩϡϦςΟΠϯγσϯτΛ̔࣌ؒͷڝٕʹ٧ ΊࠐΜͩʯͱͷ͜ͱɻ ѹॖͨ࣌ؒ͠ͷΠϯγσϯτମݧ͍͢͝εϐʔυͰΛଅ͠·͢ʂ
Copyright © 2017 delphinz All Rights Reserved. ٿΛʮӴΔʯؒΛ୳͠ʹߦ͜͏ʂ ୩ढ़ଠ ʮேͷϦϨʔʯͷҰઅΑΓ
”ΒேΛϦϨʔ͢Δͷͩɺܦ͔Βܦͱ ͦ͏͍ͯ͠ΘަͰٿΛकΔ” Έͳ͞ΜؒͱҰॹʹ୭͔ͷேΛक͍͖ͬͯ·͠ΐ͏ɻ ࣍ճ͋ͳͨͷ൪Ͱ͢Αʂ
Copyright © 2017 delphinz All Rights Reserved. ΞφλͷʮӴΔʯʹدΓఴ͍͍ͨ 403".".& ͝੩ௌ͋Γ͕ͱ͏͍͟͝·ͨ͠ɻ