Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
黑客技術,黑科技樹 II
Search
Funny Systems
February 27, 2017
Technology
870
1
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
黑客技術,黑科技樹 II
UCCU Talk
Funny Systems
February 27, 2017
More Decks by Funny Systems
See All by Funny Systems
雲端 DHCP 安全問題
funnysystems
1
1.1k
雲端資料掉光光 - GCP 事件調查真實案例
funnysystems
2
1.7k
頑固吧!GCP Cloud SQL (Why Hardening GCP Cloud SQL)
funnysystems
0
510
SMB 捲土重來 (Turning SMB Server Side Bug to Client Side)
funnysystems
0
320
跟壞鄰居想的一樣,供應鏈安全與硬體後門
funnysystems
1
790
以安全工程角度,連結實務與設計
funnysystems
0
400
FunnyPot ‐ 改造 Windows 核心,強固化、蜜罐化
funnysystems
0
750
攻擊者的視角 - 兼談匿名識別度與可追蹤性
funnysystems
1
490
黑科技樹,黑客技術
funnysystems
1
600
Other Decks in Technology
See All in Technology
【NRUG vol.18】KubernetesにおけるNew Relicデータ取得量削減の考え方
nrug_member
0
170
「勝手に広まる」人気 AI エージェントを爆速で作ろう!(AWS Summit Japan 2026講演資料)
minorun365
PRO
10
2.1k
【Cyber-sec+】経営層を"動かす"ための考え方
hssh2_bin
0
200
GitHub Copilot app最速の発信の裏側
tomokusaba
1
200
サイバーエージェントにおけるAI推進戦略と変革への取り組み
shotatsuge
0
250
自分が詳しくない領域でAIを使う #プロヒス2026
konifar
18
6.2k
SONiCのLinuxベースを活かしたZabbix監視
sonic
0
240
40代で“やっとエンジニアになれた”――閉じた学びを開き、空の青さを知る / 20260628 Naoki Takahashi
shift_evolve
PRO
4
120
FPC(フレキシブル)基板にZephyr実装してみた。
iotengineer22
0
130
AWS Security Hub CSPMの成功・失敗体験
cmusudakeisuke
0
320
徹底討論!ECS vs EKS!
daitak
3
1.1k
AWS Security Agent といっしょに脅威モデリングをやってみよう
amarelo_n24
1
190
Featured
See All Featured
Connecting the Dots Between Site Speed, User Experience & Your Business [WebExpo 2025]
tammyeverts
11
950
A Tale of Four Properties
chriscoyier
163
24k
Beyond borders and beyond the search box: How to win the global "messy middle" with AI-driven SEO
davidcarrasco
3
160
WENDY [Excerpt]
tessaabrams
11
38k
Gemini Prompt Engineering: Practical Techniques for Tangible AI Outcomes
mfonobong
2
440
Measuring Dark Social's Impact On Conversion and Attribution
stephenakadiri
2
220
Bash Introduction
62gerente
615
220k
Designing Powerful Visuals for Engaging Learning
tmiket
1
420
Product Roadmaps are Hard
iamctodd
PRO
55
12k
Tips & Tricks on How to Get Your First Job In Tech
honzajavorek
1
540
It's Worth the Effort
3n
188
29k
Making Projects Easy
brettharned
120
6.7k
Transcript
黑客、技術 黑、科技樹 2017/02/27 II
Kuon 喜歡學習,特別是「安全技術」。
None
逆向 工程 其 他 軟體 破解 惡意 程式 漏洞 攻防
硬體 軟體
硬體 Logic Analysis PCB Reversing ROM Extraction IC Reversing
Emulation Flash Dump JTAG Firmware Analysis FS Extraction Firmware Download
File ID
軟體 De- compiler IDA Pro REIL Binary Analysis Binary Diff
Analysis DBI Emulation Firmware Analysis File ID File Format Debugger
Anti-Anti- Debug Anti- Debug Anti- Dump Packer Anti-DBI Anti- Sandbox
Anti- Disasm Anti-VM Anti- Emulator Unpacker Anti-Anti- VM
Anti- Debug Packer Anti- Sandbox Anti-VM Anti-Virus Virus Anti- Rootkit
Anti-Anti- Virus Rootkit Malware Botnet Anti- Botnet Anti- Malware
ASLR Malware Anti- Malware DEP ROP UAC W^X EMET JIT
Spray GrSecurity Anti-Anti- Virus
Anti- Dump Debugger Memory Hacking Anti-Anti- Debug Anti- Debug VM
Anti-VM Anti-Anti- VM
Hooking Rootkit Malware Injection SMM VM
None
需求 架構 開發 測試 部署 API SOAP RESTful JSON Data
Format XML Authentication Cookie HTTP Header Token User Input Injection OAuth Cross-Domain Sever-side Proxy SSRF Javascript Hijacking CSP Secure Transport SSL/TLS HSTS NoSQL Cert Validation CORS CSRF JSONP Callback Resource Upload/Download Upload Enumeration CSRF CSRF Security Header Pinning XXE
None
流程、標準 Null Pointer Race Condition Dangling Pointer Data Race Double
Free Double Destruct Use-After-Free Use-After-Destruct Integer Overflow Counter Overflow Heap Overflow Pool Overflow Stack Overflow Format String JMS & JMX File Inclusion Object Injection 框 架 OGNL Injection HQL Injection 執 行 環 境 Java PHP 通 用 Web Native SQL Injection XSS Cmd Injection Path Traversal Code Injection Unserialization Template Injection Python Template Injection Race Condition CSRF YAML Evaluation Mass Assignment Spring i18n Injection OOB Read Arbitrary Write Info Leak Type Confusion Undef Behavior Uninit Memory
Q&A 問題‧討論