Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
佐川急便のフィッシングサイトを調べてみた / Analysis of sagawa fishi...
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
Tomoyuki KOYAMA
August 14, 2018
Technology
200
1
Share
佐川急便のフィッシングサイトを調べてみた / Analysis of sagawa fishing site
LT会でやった内容のスライドを公開し忘れてたので載せておきます
Tomoyuki KOYAMA
August 14, 2018
More Decks by Tomoyuki KOYAMA
See All by Tomoyuki KOYAMA
イベントとリソース定義から作成した依存グラフを用いた連鎖障害の調査時間の短縮 / DPS-206
tomoyk
0
11
Query Prediction for Log Search for Distributed Tracing with External Monitoring Alerts
tomoyk
0
23
Root Cause Analysis for Middleware Issues by Kubernetes Resource Events / KST-2026
tomoyk
0
43
Reading HTTP Client Hints
tomoyk
0
130
Log message with JSON item count for root cause analysis in microservices
tomoyk
1
250
Distributed Log Search Based on Time Series Access and Service Relations
tomoyk
0
380
Webアプリを動かすまでのインフラ構築 / infra-build-for-web-app
tomoyk
0
470
コンピュータが大好きな私が大学院進学した理由 / Why I chose graduate school
tomoyk
1
1.1k
検索性能に配慮した複製による分散ログ管理 / DPS-185
tomoyk
0
15
Other Decks in Technology
See All in Technology
Discordでリモートポケカしてたら、なぜかDOを25分間動かせるようになった話
umireon
0
110
Kubernetes基盤における開発者体験 とセキュリティの両⽴ / Balancing developer experience and security in a Kubernetes-based environment
chmikata
0
220
仕様通り動くの先へ。Claude Codeで「使える」を検証する
gotalab555
8
3.1k
Oracle Cloud Infrastructure(OCI):Onboarding Session(はじめてのOCI/Oracle Supportご利⽤ガイド)
oracle4engineer
PRO
2
17k
主催・運営として"場をつくる”というアウトプットのススメ
_mossann_t
0
130
さくらのAI Engineから始める クラウドネイティブ意識
melonps
0
120
Babylon.js を使って試した色々な内容 / Various things I tried using Babylon.js / Babylon.js 勉強会 vol.5
you
PRO
0
260
見えない開発現場を、見える投資に変える
rojoudotcom
2
120
Autonomous Database - Dedicated 技術詳細 / adb-d_technical_detail_jp
oracle4engineer
PRO
5
13k
自己組織化を試される緑茶ハイを求めて、今日も全力であそんで学ぼう / Self-Organization and Shochu Green Tea
naitosatoshi
0
310
Podcast配信で広がったアウトプットの輪~70人と音声発信してきた7年間~/outputconf_01
fortegp05
0
240
GitHub Copilotを極める会 - 開発者のための活用術
findy_eventslides
6
3.6k
Featured
See All Featured
Jamie Indigo - Trashchat’s Guide to Black Boxes: Technical SEO Tactics for LLMs
techseoconnect
PRO
0
96
CSS Pre-Processors: Stylus, Less & Sass
bermonpainter
360
30k
The Psychology of Web Performance [Beyond Tellerrand 2023]
tammyeverts
49
3.4k
A Guide to Academic Writing Using Generative AI - A Workshop
ks91
PRO
1
260
Digital Projects Gone Horribly Wrong (And the UX Pros Who Still Save the Day) - Dean Schuster
uxyall
0
1k
Avoiding the “Bad Training, Faster” Trap in the Age of AI
tmiket
0
120
Technical Leadership for Architectural Decision Making
baasie
3
310
Reality Check: Gamification 10 Years Later
codingconduct
0
2.1k
Distributed Sagas: A Protocol for Coordinating Microservices
caitiem20
333
22k
Hiding What from Whom? A Critical Review of the History of Programming languages for Music
tomoyanonymous
2
680
Applied NLP in the Age of Generative AI
inesmontani
PRO
4
2.2k
Leadership Guide Workshop - DevTernity 2021
reverentgeek
1
260
Transcript
ࠤٸศϑΟογϯά αΠτΛௐͯΈͨ 2018/08/14 ηΩϡϦςΟΩϟϯϓ શࠃେձ 2018 Tomoyuki KOYAMA
ࣗݾհ • ͜· ͱΏ͖ • ౦ژՊେ 2 • શࠃେձ 2017मྃ
• NOCνϡʔλʔ • PyCon JP ελοϑ Twitter: @tmyk_kym Blog: blog.koyama.me
͖͔͚ͬ TBHBXBNNDPN
sagawa-mm.com
औಘ/ൺֱ $ curl -s http://www.sagawa-exp.co.jp/ > white # ਖ਼نαΠτ $
curl -s http://sagawa-mm.com/ > black # ِαΠτ $ vim -d white black # ൺֱ
$ vim -d black white
ൺֱ:ِαΠτʹͷΈଘࡏ <body onclick=" document.getElementById('downloadapk').click();"> <a href="sagawa.apk" id="downloadapk" css="display:none;" download="sagawa.apk"></a> ʙলུʙ
<dd class=“input"><center> <a href="sagawa.apk"> <div class="toiawaseNo jq-placeholder"> <font><b>Πϯετʔϧ</b> </div> </a> <p class="note"></p> </dd>
υϝΠϯͷௐࠪ
υϝΠϯॴ༗ऀΛௐࠪ(ൈਮ) $ whois sagawa-mm.com ߋ৽࣌: 2018-07-18T11:24:40.0Z ొ: 2018-07-18T11:24:40.0Z ొۀऀ: Chengdu
west dimension digital technology Co., LTD ొऀ໊: mengmeng li // தࠃͷঁ༏: Meng Li ొ৫: li meng meng ొॅॴ1: Tan Cheng Zhen Deng Qiao She Q ొॅॴ2: Meng Cheng Xian ొ༣ศ൪߸: 010000 ొࠃ: cn ొి൪߸: +86.13614466925 // தࠃ ٢ྛল നࢢ ొFax: +86.13614466925 ొϝʔϧ:
[email protected]
ॴ༗ऀΛௐࠪ • RISKIQ, DomainBigData, DomainWatchͰௐࠪ
102 Domains whoisใʹ
[email protected]
ؚ͕·ΕΔsagawaܥυϝΠϯ
υϝΠϯͷҰ෦ • sagawa-anu\.com // sagawa-??? • sagawa-expr\.com // expressͷදه •
saggawa-exp\.com // ΞϧϑΝϕοτॏͶ • sagawa-co-jp\.com // .Λ-Ͱදݱ • sagawajp\.com // ҧײ͕ͳ͍
APKϑΝΠϧͷௐࠪ ಈతղੳ
ݕূڥ/ݕମ • Nexus 7 2013 Wi-Fi • Android 6.0.1 •
sagawa.apk • sagawa-mm\.comΑΓऔಘ • SHA-256: 580a027109ac70b32e4423623dfff5b4c6d52220a 905125332c0af0e231e0387 ˞҆શͳڥͰ ݕূ͍ͯͩ͘͠͞ɻ ݕূ࣌ʹωοτϫʔΫ ͷִͳͲेʹҙ͠ ͍ͯͩ͘͞ɻ
APKϑΝΠϧ - ಈతղੳ(1)
APKϑΝΠϧ - ಈతղੳ(2) όοΫάϥϯυ ͰଓΛzҡ࣋z Ṗͷന͍ΞϓϦ͕ ৗற ࠤٸศ͕ফ͑ͨ
APKϑΝΠϧ - ಈతղੳ(3) Կදࣔ͞Εͣ αʔϏεEH.BJO4FSWJDFΛ ͭྨࣅ"1,ϑΝΠϧΛൃݟ 4)" BDGBEG CDCEGDEBEEGF GCECGF
APKϑΝΠϧ - ಈతղੳ(4) • tPacketCaptureͰύέοτΩϟϓνϟ ΓऔΓ͕ແ͍
APKϑΝΠϧͷௐࠪ ੩తղੳ
APKΛղੳ(1) 1. apktoolΛΠϯετʔϧ 2. apk͔ΒresσΟϨΫτϦΛऔΓग़͢ $ apktool d sagawa.apk
APKΛղੳ(2) 1. ϑΝΠϧ classes.dex ΛऔΓग़͢ $ unzip sagawa.apk 2. dex2jar
ΛΠϯετʔϧ 3. dexϑΝΠϧ͔ΒjarϑΝΠϧΛੜ $ bash d2j-dex2jar.sh ../unziped/classes.dex
APKΛղੳ(3) 1. jarϑΝΠϧΛల։ $ unzip classes-dex2jar.jar 2. JavaDecompiler ΛΠϯετʔϧ 3.
JavaDecompiler Ͱ1ͷιʔεΛ։͘
σίϯύΠϥͰιʔεΛಡΉ
ϑΝΠϧҰཡ • gfer/DhsActivity$1.java • gfer/DhsActivity.java // ΤϯτϦϙΠϯτ • tog/essMyApplication$1.java •
tog/essMyApplication$a.java • tog/vtdMyWebActivity.java • tog/essMyApplication.java • gig/dgMainService.java • a.java • goda/eeftMyReceiver.java
None
Ճ
ଞͷυϝΠϯ • ϝʔϧΞυϨε:
[email protected]