ðæŠèŠ
ã»ãã¥ãªãã£è©äŸ¡ãšãã¹ãã
- ã»ãã¥ãªãã£å¯Ÿçã®æå¹æ§ã®è©äŸ¡
- ãœãããŠã§ã¢ã®ãã¹ã
- ã»ãã¥ãªãã£ã©ã€ããµã€ã¯ã«ã«ããããè©äŸ¡ããã§ãŒãº
- ç£æ»
ðã¹ãã£ã³
ã¢ã¯ãã£ãã¹ãã£ã³ãšããã·ãã¹ãã£ã³ãããããã®ææ³ã®éããã¡ãªãããã¡ãªãããçè§£ããã
-
ã¢ã¯ãã£ãã¹ãã£ã³
- ç©æ¥µçã«ããŒã¿ãéä¿¡ããã®è¿çãè§£æããææ³
- ãªãŒãã³ããŒããåäœäžã®ãœãããŠã§ã¢ãOSçã®æ å ±ãåéãã
- ã·ã¹ãã ã«è² è·ãäžããå Žåããã
- ããŒãã¹ãã£ã³
- nmap, Nikto, Nessus
-
UDPã¹ãã£ã³
- UDPããŒãã®ã¹ãã£ã³ãUDPãªã®ã§å¿çããªãå ŽåããããICMPå°éäžèœãšã©ãŒã®å Žåã¯éããŠãããšãããã
-
TCP Connect
- 3wayãã³ãã·ã§ã€ã¯ãå®äºãããæ€ç¥ããããã
-
SYNã¹ãã£ã³
- ã³ãã¯ã·ã§ã³ãéãããèŠæ±ãããSYN/ACKãè¿ã£ãŠããããã®ããŒããéããŠããããšãããããRSTãéä¿¡ããŠäžæããã
-
ACKã¹ãã£ã³
- æ¢åæ¥ç¶ãè£ ãã察象ããŒããã©ã®ããã«åå¿ããã芳å¯ãããFWã®èŠåãªã©ã®æ§æãäºæ³ã§ããã
-
ICMPã¹ãã£ã³
- pingãããã€ã¹æ€åºããµãŒãã¹ãŸã§ã¯ããããªã
-
Xmasã¹ãã£ã³
- FIN,URG,PSHã®äžçš®é¡ã®ãã©ã°ãç«ã£ããã±ãããéä¿¡ããã®ãã©ã°ãåæã«ç«ã£ãŠããç¶æ ã¯ççŸããŠããç¶æ ã®ããããã®ãã±ãããåŠçãããããšã¯ãªããã察象ããŒãäžã§ãµãŒãã¹ãåããŠããå Žåã¯ãã±ããã¯ç Žæ£ãããµãŒãã¹ãåããŠããªãå Žåã¯RSTãã±ãããè¿ãããã
-
ãµãŒãã¹ãã£ã³ã¬ãŒããªã³ãã£ã³ã°
- ãããã¯ãŒã¯äžã®ãµãŒãã¹ããããã³ã«ãç¹å®ããããããåäœããŠããã·ã¹ãã ã®çš®é¡ãããŒãžã§ã³ãèå¥ããããã»ã¹
-
ããã·ãã¹ãã£ã³ã
-
ããŒã¿ã¯éä¿¡ãããæ®æ®µã®éä¿¡ãç£èŠããŠæ
å ±ãåéããææ³
- ãã©ãã£ãã¯ã®åæ
- Wireshark
- éä¿¡ã®ãã£ããã£
- äžæ£ãªããã€ã¹ã®ç¹å®ãªã©ã«åœ¹ç«ã€ãMACã¢ãã¬ã¹çããã£ããã£ãçµç¹ææã®ãã®ãæ¯èŒãã
- å®éã®ãŠãŒã¶ã®è¡åãç£èŠãããããã«ãã¬ããžããã®ãé£ãããã¹ãã£ã³æéãé·ãã«ãšãå¿ èŠããã
-
ããŒã¿ã¯éä¿¡ãããæ®æ®µã®éä¿¡ãç£èŠããŠæ
å ±ãåéããææ³
-
èªèšŒã¹ãã£ã³
- å€éšããã§ã¯ãªããã·ã¹ãã å ã«å ¥ã£ãŠããè匱æ§ã¹ãã£ã³ã宿œããããš
Nice to know
- è匱æ§ã¹ãã£ã³ã宿œããŠè匱æ§ãèŠã€ãã£ãå ŽåãïŒèª€æ€ç¥ã®å Žåãããã®ã§ïŒãŸã ãåŠ¥åœæ§ç¢ºèªã ãè¡ããããããå ±å â ãããé©çšãšããã
-
nmapã®ããã©ã«ãèšå®
- 1000åã®TCP/UDPããŒããã¹ãã£ã³
- Wekk-knownããŒãïŒ0-1024ïŒä»¥å€ã®ããŒããå«ãŸãã
- UDPãå«ãŸãã
- 64535åã®ããŒããã¹ãã£ã³ããã«ã¯ãªãã·ã§ã³ãå¿ èŠ
-
nmapã®çµæ
- open --- ããŒãã空ããŠãã
- closed --- ããŒãã空ããŠãããåããŠãããµãŒãã¹ããªãïŒ
- filtered --- ããŒããéããŠãã
ðª²è匱æ§
-
ããŒã«ã«è匱æ§
- äŸµå ¥åŸã®è匱æ§ïŒLinpeasçã§ã¹ãã£ã³ããïŒ
-
èªèšŒãå¿
èŠãšããè匱æ§
- èªèšŒæ å ±ãããã°æ€åºå¯èœ
- Burpsuiteã«ã¹ãã£ã³ããæ©èœããããããïŒ
-
è匱æ§ã¹ãã£ããŒ
- æ¢ç¥ã®è匱æ§ãæ€åºã§ãã
- ãã¹ãããã©ã°ã€ã³ãã·ã°ããã£ãŒã®ãªãè匱æ§ãæ€åºã§ããªã
- ãŒããã€è匱æ§ãæ€åºã§ããªã
- ã·ã°ããã£ãŒã«ã¯ãããŒãžã§ã³çªå·ãæ§æããŒã¿ããµãŒãã¹ãã£ã³ã¬ãŒããªã³ããå«ãŸãã
ðã·ã¹ãã ã¢ãã¿ãªã³ã°
ã·ã¹ãã ã®æ§èœçãã¢ãã¿ãªã³ã°ãããã¢ã¯ãã£ãã¢ãã¿ãªã³ã°ãšããã·ãã¢ãã¿ãªã³ã°ã®ææ³ã®éããã¡ãªãããã¡ãªãããçè§£ããã
-
ã¢ã¯ãã£ãã¢ãã¿ãªã³ã°
- ã·ã¹ãã ã«ç©æ¥µçã«ä»å ¥ãããŒã¿ãéä¿¡ããããšã§ã¢ãã¿ãªã³ã°ãã
- ã·ã¹ãã ã«è² è·ãäžããå Žåããã
- äºåã«åé¡ãç¹å®ã§ãã
-
ã·ã³ã»ãã£ãã¯ã¢ãã¿ãªã³ã°ïŒåæã¢ãã¿ãªã³ã°ïŒ
- <--> ActualïŒãªã¢ã«ãŠãŒã¶ïŒã¢ãã¿ãªã³ã°
- æ³å®ããããŠãŒã¶ã®è¡åããšãã¥ã¬ãŒããããã©ã³ã¶ã¯ã·ã§ã³ã䜿çšããããšã§ãã·ã¹ãã ã®å¿çæéãæ©èœçãæ€èšŒãã
- ãã©ã³ã¶ã¯ã·ã§ã³ã«ã¯ãå®éã«èšé²ãããéå»ã®ãŠãŒã¶ãã©ã³ã¶ã¯ã·ã§ã³ãå©çšãããå Žåããã
-
ã·ã³ã»ãã£ãã¯ã¢ãã¿ãªã³ã°ïŒåæã¢ãã¿ãªã³ã°ïŒ
-
ããã·ãã¢ãã¿ãªã³ã°
- ã·ã¹ãã ã«ä»å ¥ãããéçšäžã®ãã©ãã£ãã¯ãããŒã¿ã®æµããè§£æãã
- ã·ã¹ãã ã®æ§èœã«åœ±é¿ãäžããªãã¡ãªããããã
- äºåŸã«ããåé¡ãç¹å®ã§ããªã
-
ãªã¢ã«ãŠãŒã¶ã¢ãã¿ãªã³ã°ïŒRUMïŒ
- éçšäžã®ãŠãŒã¶ã®è¡åãããšã«ãããã©ãŒãã³ã¹ãã¢ããªã±ãŒã·ã§ã³åäœãç£èŠããã
-
ãªã¢ã«ãŠãŒã¶ã¢ãã¿ãªã³ã°ïŒRUMïŒ
ðãã®ã³ã°
- SIEMã§ãã°ãéããéãã·ã¹ãã ã®ãã°èšå®ãçµ±äžããã«ã¯ïŒ
- ã°ã«ãŒãããªã·ãŒ
-
syslog
- ãã°ã転éãããããã³ã«
- Linuxããšã³ã¿ãŒãã©ã€ãºãµãŒãã¹ã«ã¯æšæºæèŒãããŠããããWindowsã¯æšæºã§ã¯Windowsã®ãã®ã³ã°ãã©ãŒãããã§ãã°ãçæããã®ã§ãå¥éããŒã«ãå¿ èŠãšãªãããšã«æ³šæ
ðãã¹ã
ãœãããŠã§ã¢ã®ãã¹ããæ©èœèŠä»¶ã¯æºããããŠãããïŒ
æ³å®å€ã®ããŒã¿ã«ãã£ãŠãšã©ãŒããã°ãåŒãèµ·ãããªããïŒãã¹ãé
ç®ã¯ååãïŒ
-
Fuzzing
-
Generative fuzzing
- ã¢ããªã±ãŒã·ã§ã³ã®å ¥å圢åŒãããšã«0ããå ¥åããŒã¿ãçæãã
-
Mutation fuzzing
- æ¢åã®å ¥åããŒã¿ã«å°ããªå€æŽãå ããããšã§å€§éã®ãã¹ãããŒã¿ãçæãã
-
Fuzzer
- FuzzingãèªååããããŒã«
-
Generative fuzzing
-
ãŠãŒã¹ã±ãŒã¹ãã¹ãããã¹ãŠãŒã¹ãã¹ã
- ãã¹ãŠãŒã¹ã±ãŒã¹å³ã«ã¯ãæ»æè ãè åšãæžã蟌ã
-
äœã£ããã¹ãã¯åé¡ãªããïŒ
-
ãã¥ãŒããŒã·ã§ã³ãã¹ã
- ãã¹ãã®ããã®ãã¹ã
- 人工çãªèª€ãïŒãã¥ãŒã¿ã³ãïŒãå«ãã³ãŒããã³ãŒããã¹ã¿ãŒã«å ¥ããŠãã¡ãããšæ©èœããã確èªãã
-
ã³ãŒãã«ãã¬ããž
- Function, Statement, Branch, Conditionã®ïŒã€ïŒ
-
ãã¥ãŒããŒã·ã§ã³ãã¹ã
Nice to know
- ãã¹ãç°å¢ãšæ¬çªç°å¢ã«å·®ç°ããããšãã¬ãŒã¹ã³ã³ãã£ã·ã§ã³ãªã©ã®ã¿ã€ãã³ã°ã«é¢ããåé¡ãèŠããªããªããããããã
- ãœãããŠã§ã¢ã®æŽæ°ãè¡ããšãæ°ããé害ããå€ãé害ã®åçºçããäžè¬çã§ããããªã°ã¬ãã·ã§ã³ãã¹ããè¡ãå Žåã¯ããæ¬ é¥åçºçããææšã«ããã
ðãããã¬ãŒã·ã§ã³ãã¹ã
-
èšç»
- èš±å¯ãåãïŒgetting authorizationïŒ
- èåŒ±æ§æ å ±ããªãŒã¯ãããšãããªããªã¹ã¯ã«ç¹ãããããèåŒ±æ§æ å ±ã®ä¿ç®¡æ¹æ³ãæäŸæ¹æ³ãå ã«æ±ºå®ããŠãã
- é²å ¥çŠæ¢ã¿ãŒã²ãããæç¢ºã«ãã
-
çºèŠ
- nmap
-
è匱æ§ã¹ãã£ã³
- Nessuss, Nikto
-
䟵害
- johnã(ãã¹ã¯ãŒãã¯ã©ãã¯)
-
å ±å
- ãããã¬ãŒã·ã§ã³ãã¹ãã¬ããŒãã«å«ãŸãããã®
- ç¹å®ããè匱æ§ã®ãªã¹ã
- ãªã¹ã¯ã®ã©ã³ãã³ã°
- ãªã¹ã¯äœæžã®ããã®ã¬ã€ãã³ã¹ïŒãããªãã ïŒ
- ïŒÃïŒéããæ©å¯æ å ±ã®ãªã¹ãã
- ãããã¬ãŒã·ã§ã³ãã¹ãã¬ããŒãã«å«ãŸãããã®
ðã³ãŒãã¬ãã¥ãŒ
è²ããªäººãèªãã§ãã§ãã¯ããããŒã«ãå©çšããŠãœãŒã¹ã³ãŒãã®éçãã§ãã¯ãè¡ãã
-
ãã§ã€ã¬ã³ãã¹ã
- èšç»ãããã©ããŒã¢ãããŸã§éããŠè©³çްã«å®æœããã³ãŒãã¬ãã¥ãŒæ¹æ³
- åé¡ããã£ãå Žåãèšç»ã«åé¡ããã£ããšããŠãèšç»ã«æ»ã£ãŠããçŽã
- èšç» -> æŠèŠèª¬æ -> æºå -> ã€ã³ã¹ãã¯ã·ã§ã³ -> ã³ãŒãä¿®æ£ïŒã³ãŒãä¿®æ£åŸã¯ãèšç»ã«æ»ãïŒ -> ãã©ããŒã¢ãã
-
ãŠã©ãŒã¯ã¹ã«ãŒ
- ã³ãŒããèšèšã®æ®µéã§ãéçºããŒã ãéãŸããåé¡ãè°è«ãããã£ãŒãããã¯ãäžããéå ¬åŒãªäŒè°
-
ããã°ã©ã çè§£ãããã°ã©ã è§£é
- 人ãããã°ã©ã ãèªãã§ãçè§£ã»è§£éãããããã»ã¹
-
ãœãããŠã§ã¢ã€ã³ã¹ãã¯ã·ã§ã³
- éçºè 以å€ã®äººã ïŒãã°ãã°ãã¢ã°ã«ãŒãïŒãã³ãŒãã®å質ãè©äŸ¡ããããã«å®æœãããæ£åŒãªè©äŸ¡ããã»ã¹ããã§ãã¯ãªã¹ãã䜿çšããŠãšã©ãŒãæ¢ã
-
éçããã°ã©ã åæ
- ããã°ã©ã ãå®è¡ããã«ãœãŒã¹ã³ãŒãã®åæãè¡ãæè¡
- æ§æãšã©ãŒãæªäœ¿çšå€æ°ãã¡ã¢ãªãªãŒã¯ãã³ãŒãã£ã³ã°èŠçŽéåãªã©ãæ€åºãã
- ããŒã«ãçšããŠãœãããŠã§ã¢ã®ãã°ãè匱æ§ãã¹ã¿ã€ã«ã®éåãªã©ãèªåçã«æ€åºãã
-
ããã¥ã¢ã«ã³ãŒãã¬ãã¥ãŒ
- 人ãã³ãŒããèªãã§ã¬ãã¥ãŒãã
- éçã³ãŒãã¬ãã¥ãŒã¯ãã©ã°ã©ã ã§ãã°ãªã©ãèŠã€ããææ³ãªã®ã§ãããžãã¹ããžãã¯ãèæ ®ããŠã¬ãã¥ãŒããŠæ¬²ããå Žåã¯ãããã¥ã¢ã«ïŒäººã«ããïŒã³ãŒãã¬ãã¥ãŒãæãŸãã
ðã»ãã¥ãªãã£èšå®å ±éåæé ïŒSCAPïŒ
2002-2015幎ãããã®è©±ãå ±éèšèªã仿§ãæŽåãããŠãã£ãã
ã»ãã¥ãªãã£ã³ã³ãã©ã€ã¢ã³ã¹ãžã®æè¡ç察å¿ã«èšå€§ãªæéãšåŽåãªã©ã®ãªãœãŒã¹ãè²»ãããè€éåããã³ã³ãã©ã€ã¢ã³ã¹ãžã®ç®¡çã«å¯Ÿããè² è·ã¯å¢å€§ããŸããããŸããèšå®äœæ¥ãæäœæ¥ã§è¡ããšãèšå®ãã¹ãèšå®è ã®ã»ãã¥ãªãã£ç¥èã®çšåºŠã倿ã®çžéãªã©ããã»ãã¥ãªãã£ãæãªãããå¯èœæ§ãããäºãªã©ãããäœæ¥ãèªååããäºãå¹çç²ã»æå¹æ§ã®èгç¹ããæ±ããããããã«ãªããŸããããããã®èŠå ããNISTã«ãããŠãæ å ±ã»ãã¥ãªãã£å¯Ÿçã®èªååãšæšæºåãç®æããSCAPïŒSecurity Content Automation ProtocolïŒã»ãã¥ãªãã£èšå®å ±éåæé ïŒã®éçºãè¡ãããŸããã
- CVEïŒCommon Vulnerabilities and ExposuresïŒïŒè匱æ§ãèå¥
-
CCEïŒCommon Configuration EnumerationïŒïŒã»ãã¥ãªãã£èšå®ãèå¥
- ãã¹ã¯ãŒãã®æå¹æé
- ãã¹ã¯ãŒãã®é·ãïŒäœæå以äžãªã©ïŒ
- ãã¹ã¯ãŒãã®è€éãïŒè±æ°å以å€ã®äœ¿çšãªã©ïŒ
- ãã¹ã¯ãŒãã®å±¥æŽç®¡çïŒåããã¹ã¯ãŒãã䜿ããªãåæ°ïŒãªã©
-
CPEïŒCommon Platform EnumerationïŒïŒè£œåãèå¥
- ããŒããŠã§ã¢ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãã¢ããªã±ãŒã·ã§ã³ãªã©ã®ãã©ãããã©ãŒã ãèå¥ããããã®ãæ§é åãããåç§°äœç³»ãèŠå®ããŠããããã³ããŒãå°éå®¶éã§ã®å ±éèšèªã
- CVSSïŒCommon Vulnerability Scoring SystemïŒïŒè匱æ§ã®æ·±å»åºŠ
-
XCCDFïŒeXtensible Configuration Checklist Description FormatïŒïŒã»ãã¥ãªãã£ãã§ãã¯ãªã¹ããèšè¿°ããèšèª
- CCEãšå ±ã«å ·äœçãªé ç®ããªã¹ãã¢ããããŸãšãããã§ãã¯ãªã¹ããèšè¿°ããèšèª
- è©äŸ¡ã®èªååããµããŒãããããã«ãã¶ã€ã³ãããŠãã
- ãã§ãã¯ãªã¹ãããã³ãããŒã¯çã«å ±éã®åºç€ãæäŸããããšãç®çãšããŠãã
-
OVALïŒOpen Vulnerability and Assessment LanguageïŒïŒã»ãã¥ãªãã£èšå®ç¶æ³ãæ€æ»ããããã®ä»æ§
- ãããŸã§ææžãšæäœæ¥ã«ãããã§ãã¯ã ã£ã
- OVALã¯ãææžã«ããè匱æ§å¯Ÿçæ å ±ãæ©æ¢°åŠçå¯èœãªXMLããŒã¹ã®OVALèšèªã§èšè¿°ããããã®ä»æ§
- OVALå®çŸ©ããŒã¿ã¯ãOVALãªããžããªãšããŠããŒã¿ããŒã¹å
- è匱æ§å¯Ÿçã®ããã®ç¢ºèªäœæ¥ã®èªååã«ãã管çå·¥æ°ã®äœæžãã§ããããã«ãªã