Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
P.A.K.U.R.I SECCON2019 Akihabara YOROZU
Search
Mr.Rabbit
December 21, 2019
Technology
130
1
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
P.A.K.U.R.I SECCON2019 Akihabara YOROZU
Mr.Rabbit
December 21, 2019
More Decks by Mr.Rabbit
See All by Mr.Rabbit
Azazel Series
01rabbit
0
89
Azazel System for Emergency Shelters
01rabbit
0
190
BOCCHI
01rabbit
0
50
KaliPAKU
01rabbit
0
32
Babbly
01rabbit
0
91
P.A.K.U.R.I AVTOKYO HIVE
01rabbit
0
110
The Empire Strikes Back ~MR.RABBIT 帝国の逆襲~
01rabbit
0
260
地雷探しに脆弱性を使うのは間違っているだろうか Hack a Minesweeper
01rabbit
0
220
あの日学んだ攻撃の方法を僕達はまだ知らない。
01rabbit
0
200
Other Decks in Technology
See All in Technology
2026TECHFRESH畢業分享會 - AI 時代的人生存檔點
line_developers_tw
PRO
0
1.3k
2026TECHFRESH畢業分享會 - 葬送的通靈師:化系統與用戶雜訊成行動訊號
line_developers_tw
PRO
0
1.3k
自宅LLMの話
jacopen
1
670
「勝手に広まる」人気 AI エージェントを爆速で作ろう!(AWS Summit Japan 2026講演資料)
minorun365
PRO
10
2k
FPC(フレキシブル)基板にZephyr実装してみた。
iotengineer22
0
130
2026 TECHFRESH 畢業分享會 - 開發日常大解密!從領域驅動到企業級上線
line_developers_tw
PRO
0
1.3k
AWS Security Hub CSPMの成功・失敗体験
cmusudakeisuke
0
290
就職⽀援サービスにおけるキャリアアドバイザーのシフトスケジューリング
recruitengineers
PRO
1
150
iOS アプリの「これって不具合ですか?」を AI に調べてもらう
miichan
0
110
攻撃者視点で考えるDetection Engineering
cryptopeg
3
2k
【2026年版】 ベクトル検索とEmbedding最前線
mocobeta
21
5.5k
スタートアップにAmazon EKSは早すぎる? マルチプロダクト戦略を加速する Platform Engineeringの実践 / Is Amazon EKS Too Soon for Startups? Practical Platform Engineering to Accelerate a Multi-Product Strategy
elmodev09
1
470
Featured
See All Featured
Producing Creativity
orderedlist
PRO
348
40k
Lessons Learnt from Crawling 1000+ Websites
charlesmeaden
PRO
1
1.3k
The Curious Case for Waylosing
cassininazir
1
400
世界の人気アプリ100個を分析して見えたペイウォール設計の心得
akihiro_kokubo
PRO
71
40k
The Anti-SEO Checklist Checklist. Pubcon Cyber Week
ryanjones
0
170
Statistics for Hackers
jakevdp
799
230k
Primal Persuasion: How to Engage the Brain for Learning That Lasts
tmiket
0
370
10 Git Anti Patterns You Should be Aware of
lemiorhan
PRO
659
62k
Reality Check: Gamification 10 Years Later
codingconduct
0
2.2k
Avoiding the “Bad Training, Faster” Trap in the Age of AI
tmiket
0
180
The Director’s Chair: Orchestrating AI for Truly Effective Learning
tmiket
1
200
Save Time (by Creating Custom Rails Generators)
garrettdimon
PRO
32
3.5k
Transcript
1",63* SECCON 2019 Akihabara 2019/12/21 - 22 YOROZU @Mr.Rabbit 0QFSBUJPOXJUI5FOLFZ
Who am i ໊લ.S3BCCJU ࢿ֨ΞʔΫ༹ɺখܕҠಈࣜΫ Ϩʔϯɺۄֻ͚ɺେܕࣗಈंɺ 0481ɺ$*441ɺ44$1 طԟਥೋප झຯαόήʔɺΞχϝ ৬ྺݩαΠόʔσΟϑΣϯεݚڀॴ
ݚमੜ
What is PAKURI ? 1FOFUSBUJPOUFTU "DIJFWF ,OPXMFEHF 6OJUF 3BQJE *OUFSGBDF
What is PAKURI ? ϖωτϨʔγϣϯςετʹඞཁͦ͏ͳπʔϧΛدͤू Ίͯɺ୭Ͱɺ؆୯ʹɺͦΕͬΆ࣮͘ߦग़དྷΔ༷ʹߏ ͨ͠πʔϧ ͬ͘͟Γݴ͏ͱύΫͬͯΔXʢݖར৵ͯ͠·ͤΜʣ ͺ͘Δʢҟ௲ɿύΫΔʣ
ύΫύΫͱ৯Δɻେ͖ͳޱΛ։͚ͯ৯Δɻ ʢଏޠʣ伱Λ͍ͭͯۚΛ͔ͬ͞Β͏ɻۚમྉۚΛԣྖ͢Δɻ ʢଏޠʣ౪༻͢Δɻ ʢଏޠʣܯͳͲ͕ਓΛั·͑ɺัറ͢Δɻ IUUQTKBXJLUJPOBSZPSHXJLJͺ͘Δ
1",63*ͷೳྗ ใऩूٴͼྻڍ ੬ऑੑͷੳ ೝূࢼߦ &YQMPJUʢิॿʣ
ใͷՄࢹԽ
ҰൠతͳϖωτϨʔγϣϯςετͷྲྀΕ /P ςετ߲ આ໌ ϗετݕग़ *$.1Ԡ֬ೝΛ༻ͯ͠ɺରͱͳΔγεςϜ্ͷϗετ Λݕग़͢Δ 5$16%1εΩϟϯ
ٙࣅ߈ܸͷରͱͳΔϗετ͕ଘࡏ͠ϗετ্Ͱٙࣅ߈ܸର ʹͳΔαʔϏε͕Քಇ͍ͯ͠Δ͜ͱΛ֬ೝ͢Δ ੬ऑੑͷ֬ೝ ੬ऑੑεΩϟφΛར༻͠ཏతʹ੬ऑੑͷଘࡏΛ֬ೝ͢Δ ೝূࢼߦɾΞΫηεݖऔಘ ਪଌՄೳͳΞΧϯτɾύεϫʔυΛ༻͍ͯೝূࢼߦΛߦ ͍ɺαʔϏεΞϓϦέʔγϣϯͷར༻Մ൱Λ֬ೝ͢Δ ط੬ऑੑΛར༻ͨٙ͠ࣅ߈ܸ ط੬ऑੑΛར༻͠ɺ߈ܸίʔυΛ༻ͯٙ͠ࣅ߈ܸΛߦ ͍ɺ࣮ࡍʹ৵ೖٴͼใͷऔ͕Մೳ͔֬ೝ͢Δ Өڹͷ֬ೝ ٙࣅ߈ܸ͕ޭͨ͠ϗετͷݖݶϑΝΠϧΛੳ͠ଞͷ ϗετͷӨڹΛ֬ೝ͢Δ
1",63*ͰΓ͍ͨ͜ͱ /P ςετ߲ ϗετݕग़ 5$16%1εΩϟϯ ੬ऑੑͷ֬ೝ
ೝূࢼߦɾΞΫηεݖऔಘ ط੬ऑੑΛར༻ͨٙ͠ࣅ߈ܸ Өڹͷ֬ೝ ͜ͷൣғΛαϙʔτ͍ͨ͠ ใऩूٴͼྻڍ ੬ऑੑͷੳ ೝূࢼߦ &YQMPJUʢิॿʣ ใͷՄࢹԽ
ૢ࡞͕͍͠ͷͰʁ ͍͠ͷͪΐͬͱͶɾɾɾ
ςϯΩʔ͚ͩͰಈ͘Α
ը໘
جຊίϚϯυ ΤΫεϓϩΠτίϚϯυ ίϯϑΟάίϚϯυ εΩϟϯίϚϯυ ίϯϘΛܾΊͯ ίϚϯυ࣮ߦʂʂ
εΩϟϯίϯϘ Discovery Host Vulnerability Scan Well-known ports Scan(Details) AutoRecon ͳʹΛ͢Δʹ·ͣίϨ
ΦεεϝίϯϘ "VUP3FDPO %JTDPWFSZ)PTU
ΤΫεϓϩΠτίϯϘ Password Crack Create MSF DB Import to MSF DB
Start Metasploit Check the service ͚ແ༻ɺୟ͖ࠐΊʂ ΦεεϝίϯϘ 1BTTXPSE$SBDL
ίϯϑΟάίϯϘ Import data into Faraday Switch CUI mode Configure targets
Switch GUI mode ޭͷΧΪɺ४උീׂ ΦεεϝίϯϘ *NQPSUEBUBJOUP'BSBEBZ
ϥʔχϯά ͔Βͳ͍ࣄΛΔࣄ͕Ұ൪ͷֶͼ "TTJTU MFBSOUP ίϯϘͷ࠷ޙʹMFBSOUPΛબͿͱ ը໘ӈଆʹ࣮ߦ͞ΕΔίϚϯυͷ આ໌͕දࣔ͞ΕΔ "TTJTUΛબͿͱɺ֤جຊίϚϯ υͰͷಈ࡞ʹ͍ͭͯͷղઆΛද ࣔ͢Δ
1",63*ΛऔΓೖΕֶͨशαΠΫϧ ࣮ԋ ղઆ ʢϥʔχϯάʣ ࣮श ʢίϯϘʣ ޭମݧ ʢ݁ՌͷՄࢹԽʣ ͬͯΈͤɺݴͬͯฉ͔ͤͯɺͤͯ͞Έͤɺ΄ΊͯΒͶɺਓಈ͔͡ ࢁຊޒे
Your benefits ϨουνʔϜͷ߹ 1",63*Λ༻͢ΔࣄͰɺසൟʹར༻͢ΔίϚϯυΛ ೖྗ͢Δख͕ؒল͚·͢ɻ ॳ৺ऀͷϖϯςελʔɺ1",63*Λ༻ͯ͠߈ܸͷ ྲྀΕΛֶ·͢ɻ ϒϧʔνʔϜͷ߹
؆୯ͳૢ࡞Ͱɺ߈ܸऀͷߦಈΛ฿Ͱ͖·͢ɻ ˞͋͘·ͰҰྫͰ͢
ֶश͔Β࣮·ͰςϯΩʔ͚ͩͰͰ͖Δʂ
テンキーの子 Operation with Ten-key
·ͱΊ ɹϖϯςελʔखΛಈ͔͢͜ͱ͕େ͖Ͱ͢ɻ͔͠͠ɺ ໘͍͘͞࡞ۀ͖Ͱ͋Γ·ͤΜɻ1",63*ɺϖω τϨʔγϣϯςετͰසൟʹ༻͢ΔίϚϯυΛςϯΩʔ ͷૢ࡞͚ͩͰ࣮ߦ͠·͢ɻ·ΔͰ֨ಆήʔϜΛ͍ͬͯΔ Α͏ͳײ֮ͰͰ͖·͢ɻ
·ͱΊ ɹ1",63*ϖωτϨʔγϣϯςελʔͷΩϟϦΞΛ։ ࢝͢ΔͷʹʹཱͯΔͱࢥ͍·͢ɻ,BMJ5PPMTʹ४ڌ ͢ΔπʔϧΛ༻͍ͯ͠ΔͷͰඞཁҎ্ʹഁյ͢Δ͜ͱ ͠·ͤΜɻ1",63*Λ༻͢Δ͜ͱͰɺϖωτϨʔ γϣϯςετͷϑϩʔΛ؆୯ʹମݧֶ͠Ϳ͜ͱ͕ग़དྷ· ͢ɻ ɹ1",63*ΛͬͯΈͯɺϖωτϨʔγϣϯςετʹڵ ຯΛ͍࣋ͬͯͩ͘͞ɻ
Thank you! Please give me advice and feedback.
[email protected]
@PAKURI9
@01ra66it https://github.com/01rabbit/PAKURI