Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
黑客技術,黑科技樹 II
Search
Funny Systems
February 27, 2017
Technology
870
1
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
黑客技術,黑科技樹 II
UCCU Talk
Funny Systems
February 27, 2017
More Decks by Funny Systems
See All by Funny Systems
雲端 DHCP 安全問題
funnysystems
1
1.1k
雲端資料掉光光 - GCP 事件調查真實案例
funnysystems
2
1.7k
頑固吧!GCP Cloud SQL (Why Hardening GCP Cloud SQL)
funnysystems
0
510
SMB 捲土重來 (Turning SMB Server Side Bug to Client Side)
funnysystems
0
330
跟壞鄰居想的一樣,供應鏈安全與硬體後門
funnysystems
1
810
以安全工程角度,連結實務與設計
funnysystems
0
420
FunnyPot ‐ 改造 Windows 核心,強固化、蜜罐化
funnysystems
0
760
攻擊者的視角 - 兼談匿名識別度與可追蹤性
funnysystems
1
500
黑科技樹,黑客技術
funnysystems
1
610
Other Decks in Technology
See All in Technology
Agent 時代の Kaggle 展望 / kaggle-in-the-agentic-era
upura
1
680
【Google Cloud Next Tokyo'26】Gemini Enterprise と Oracle AI Database で実現する、業務データ活用を実現する AI エージェント実装
shisyu_gaku
0
230
LanceDB入門
mocobeta
3
100
Breaking the Seal: Static Deobfuscation of Compiled V8 JavaScript Bytecode Malware
hshrzd
0
670
FORENSIA: ローカルLLMフォレンジックハーネス
sumeshi
2
350
AIは実装を速くする。では、私たちは何を今作るべきか?-立場を越えてリリースに向き合ったチーム開発の実践 / 20260801 Hiromi Nakaya and Naoki Takahashi
shift_evolve
PRO
3
450
システム思考で問題に対処する
yussak
0
210
ガバメントクラウドでのランサムウェア対策
techniczna
2
1k
【CEDEC2026】『Relink』を拡張せよ - 『GRANBLUE FANTASY: Relink - Endless Ragnarok』の開発速度と品質を守るCI運用
cygames
PRO
0
140
取引先から届く 「セキュリティチェックシート」の読み解き方
kamadamakoto
0
140
ガバメント AI 源内を地方自治体は活用できるのか可能性と課題、期待について
takeda_h
1
370
AIエージェントを前提としたプラットフォーム エンジニアリング:GKEで作るAgent-Ready Golden Path
legalontechnologies
PRO
2
220
Featured
See All Featured
Creating an realtime collaboration tool: Agile Flush - .NET Oxford
marcduiker
35
2.5k
The Curious Case for Waylosing
cassininazir
1
450
16th Malabo Montpellier Forum Presentation
akademiya2063
PRO
0
340
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
287
14k
Bioeconomy Workshop: Dr. Julius Ecuru, Opportunities for a Bioeconomy in West Africa
akademiya2063
PRO
1
210
Deep Space Network (abreviated)
tonyrice
0
250
jQuery: Nuts, Bolts and Bling
dougneiner
66
8.5k
RailsConf & Balkan Ruby 2019: The Past, Present, and Future of Rails at GitHub
eileencodes
141
35k
How to Align SEO within the Product Triangle To Get Buy-In & Support - #RIMC
aleyda
2
1.8k
YesSQL, Process and Tooling at Scale
rocio
174
15k
Building an army of robots
kneath
306
46k
Testing 201, or: Great Expectations
jmmastey
46
8.2k
Transcript
黑客、技術 黑、科技樹 2017/02/27 II
Kuon 喜歡學習,特別是「安全技術」。
None
逆向 工程 其 他 軟體 破解 惡意 程式 漏洞 攻防
硬體 軟體
硬體 Logic Analysis PCB Reversing ROM Extraction IC Reversing
Emulation Flash Dump JTAG Firmware Analysis FS Extraction Firmware Download
File ID
軟體 De- compiler IDA Pro REIL Binary Analysis Binary Diff
Analysis DBI Emulation Firmware Analysis File ID File Format Debugger
Anti-Anti- Debug Anti- Debug Anti- Dump Packer Anti-DBI Anti- Sandbox
Anti- Disasm Anti-VM Anti- Emulator Unpacker Anti-Anti- VM
Anti- Debug Packer Anti- Sandbox Anti-VM Anti-Virus Virus Anti- Rootkit
Anti-Anti- Virus Rootkit Malware Botnet Anti- Botnet Anti- Malware
ASLR Malware Anti- Malware DEP ROP UAC W^X EMET JIT
Spray GrSecurity Anti-Anti- Virus
Anti- Dump Debugger Memory Hacking Anti-Anti- Debug Anti- Debug VM
Anti-VM Anti-Anti- VM
Hooking Rootkit Malware Injection SMM VM
None
需求 架構 開發 測試 部署 API SOAP RESTful JSON Data
Format XML Authentication Cookie HTTP Header Token User Input Injection OAuth Cross-Domain Sever-side Proxy SSRF Javascript Hijacking CSP Secure Transport SSL/TLS HSTS NoSQL Cert Validation CORS CSRF JSONP Callback Resource Upload/Download Upload Enumeration CSRF CSRF Security Header Pinning XXE
None
流程、標準 Null Pointer Race Condition Dangling Pointer Data Race Double
Free Double Destruct Use-After-Free Use-After-Destruct Integer Overflow Counter Overflow Heap Overflow Pool Overflow Stack Overflow Format String JMS & JMX File Inclusion Object Injection 框 架 OGNL Injection HQL Injection 執 行 環 境 Java PHP 通 用 Web Native SQL Injection XSS Cmd Injection Path Traversal Code Injection Unserialization Template Injection Python Template Injection Race Condition CSRF YAML Evaluation Mass Assignment Spring i18n Injection OOB Read Arbitrary Write Info Leak Type Confusion Undef Behavior Uninit Memory
Q&A 問題‧討論