Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
P.A.K.U.R.I SECCON2019 Akihabara YOROZU
Search
Sponsored
·
Ship Features Fearlessly
Turn features on and off without deploys. Used by thousands of Ruby developers.
→
Mr.Rabbit
December 21, 2019
Technology
130
1
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
P.A.K.U.R.I SECCON2019 Akihabara YOROZU
Mr.Rabbit
December 21, 2019
More Decks by Mr.Rabbit
See All by Mr.Rabbit
Azazel Series
01rabbit
0
89
Azazel System for Emergency Shelters
01rabbit
0
190
BOCCHI
01rabbit
0
50
KaliPAKU
01rabbit
0
32
Babbly
01rabbit
0
91
P.A.K.U.R.I AVTOKYO HIVE
01rabbit
0
110
The Empire Strikes Back ~MR.RABBIT 帝国の逆襲~
01rabbit
0
260
地雷探しに脆弱性を使うのは間違っているだろうか Hack a Minesweeper
01rabbit
0
220
あの日学んだ攻撃の方法を僕達はまだ知らない。
01rabbit
0
200
Other Decks in Technology
See All in Technology
[チョークトーク資料]AWS DevOps Agent を使いこなす / AWS Dev Ops Agent Chalk Talk AWS Summit Japan 2026
kinunori
3
600
GitHub Copilot app最速の発信の裏側
tomokusaba
1
200
AI駆動開発を通して感じた、 AI時代のデザイナーの役割変化
whisaiyo
4
2.3k
AIネイティブな開発のサプライチェーンリスク対策 〜激動の開発現場でリスクに立ち向かう〜【ZennFes】
cscengineer
PRO
2
140
10年間のブログ発信を振り返って見えたWebアプリケーションエンジニアとしての軌跡
stefafafan
0
170
SONiCの統計情報を取得したい
sonic
0
230
Android の公式 Skill / Android skills
yanzm
0
160
Bucharest Tech Week 2026 - Reinventing testing practices in the AI era
edeandrea
PRO
1
170
AIのReact習熟度を測る
uhyo
2
650
AWS Security Agent といっしょに脅威モデリングをやってみよう
amarelo_n24
1
180
iOS アプリの「これって不具合ですか?」を AI に調べてもらう
miichan
0
100
AI時代のコスト管理を考えよう〜明日から使える実践AWSノウハウ~
yoshimi0227
0
320
Featured
See All Featured
GitHub's CSS Performance
jonrohan
1033
470k
Why Your Marketing Sucks and What You Can Do About It - Sophie Logan
marketingsoph
0
170
Jess Joyce - The Pitfalls of Following Frameworks
techseoconnect
PRO
1
170
Google's AI Overviews - The New Search
badams
0
1k
Exploring the relationship between traditional SERPs and Gen AI search
raygrieselhuber
PRO
2
4k
KATA
mclloyd
PRO
35
15k
Bioeconomy Workshop: Dr. Julius Ecuru, Opportunities for a Bioeconomy in West Africa
akademiya2063
PRO
1
150
Organizational Design Perspectives: An Ontology of Organizational Design Elements
kimpetersen
PRO
1
750
"I'm Feeling Lucky" - Building Great Search Experiences for Today's Users (#IAC19)
danielanewman
230
23k
How GitHub (no longer) Works
holman
316
150k
The MySQL Ecosystem @ GitHub 2015
samlambert
251
13k
How to Create Impact in a Changing Tech Landscape [PerfNow 2023]
tammyeverts
55
3.4k
Transcript
1",63* SECCON 2019 Akihabara 2019/12/21 - 22 YOROZU @Mr.Rabbit 0QFSBUJPOXJUI5FOLFZ
Who am i ໊લ.S3BCCJU ࢿ֨ΞʔΫ༹ɺখܕҠಈࣜΫ Ϩʔϯɺۄֻ͚ɺେܕࣗಈंɺ 0481ɺ$*441ɺ44$1 طԟਥೋප झຯαόήʔɺΞχϝ ৬ྺݩαΠόʔσΟϑΣϯεݚڀॴ
ݚमੜ
What is PAKURI ? 1FOFUSBUJPOUFTU "DIJFWF ,OPXMFEHF 6OJUF 3BQJE *OUFSGBDF
What is PAKURI ? ϖωτϨʔγϣϯςετʹඞཁͦ͏ͳπʔϧΛدͤू Ίͯɺ୭Ͱɺ؆୯ʹɺͦΕͬΆ࣮͘ߦग़དྷΔ༷ʹߏ ͨ͠πʔϧ ͬ͘͟Γݴ͏ͱύΫͬͯΔXʢݖར৵ͯ͠·ͤΜʣ ͺ͘Δʢҟ௲ɿύΫΔʣ
ύΫύΫͱ৯Δɻେ͖ͳޱΛ։͚ͯ৯Δɻ ʢଏޠʣ伱Λ͍ͭͯۚΛ͔ͬ͞Β͏ɻۚમྉۚΛԣྖ͢Δɻ ʢଏޠʣ౪༻͢Δɻ ʢଏޠʣܯͳͲ͕ਓΛั·͑ɺัറ͢Δɻ IUUQTKBXJLUJPOBSZPSHXJLJͺ͘Δ
1",63*ͷೳྗ ใऩूٴͼྻڍ ੬ऑੑͷੳ ೝূࢼߦ &YQMPJUʢิॿʣ
ใͷՄࢹԽ
ҰൠతͳϖωτϨʔγϣϯςετͷྲྀΕ /P ςετ߲ આ໌ ϗετݕग़ *$.1Ԡ֬ೝΛ༻ͯ͠ɺରͱͳΔγεςϜ্ͷϗετ Λݕग़͢Δ 5$16%1εΩϟϯ
ٙࣅ߈ܸͷରͱͳΔϗετ͕ଘࡏ͠ϗετ্Ͱٙࣅ߈ܸର ʹͳΔαʔϏε͕Քಇ͍ͯ͠Δ͜ͱΛ֬ೝ͢Δ ੬ऑੑͷ֬ೝ ੬ऑੑεΩϟφΛར༻͠ཏతʹ੬ऑੑͷଘࡏΛ֬ೝ͢Δ ೝূࢼߦɾΞΫηεݖऔಘ ਪଌՄೳͳΞΧϯτɾύεϫʔυΛ༻͍ͯೝূࢼߦΛߦ ͍ɺαʔϏεΞϓϦέʔγϣϯͷར༻Մ൱Λ֬ೝ͢Δ ط੬ऑੑΛར༻ͨٙ͠ࣅ߈ܸ ط੬ऑੑΛར༻͠ɺ߈ܸίʔυΛ༻ͯٙ͠ࣅ߈ܸΛߦ ͍ɺ࣮ࡍʹ৵ೖٴͼใͷऔ͕Մೳ͔֬ೝ͢Δ Өڹͷ֬ೝ ٙࣅ߈ܸ͕ޭͨ͠ϗετͷݖݶϑΝΠϧΛੳ͠ଞͷ ϗετͷӨڹΛ֬ೝ͢Δ
1",63*ͰΓ͍ͨ͜ͱ /P ςετ߲ ϗετݕग़ 5$16%1εΩϟϯ ੬ऑੑͷ֬ೝ
ೝূࢼߦɾΞΫηεݖऔಘ ط੬ऑੑΛར༻ͨٙ͠ࣅ߈ܸ Өڹͷ֬ೝ ͜ͷൣғΛαϙʔτ͍ͨ͠ ใऩूٴͼྻڍ ੬ऑੑͷੳ ೝূࢼߦ &YQMPJUʢิॿʣ ใͷՄࢹԽ
ૢ࡞͕͍͠ͷͰʁ ͍͠ͷͪΐͬͱͶɾɾɾ
ςϯΩʔ͚ͩͰಈ͘Α
ը໘
جຊίϚϯυ ΤΫεϓϩΠτίϚϯυ ίϯϑΟάίϚϯυ εΩϟϯίϚϯυ ίϯϘΛܾΊͯ ίϚϯυ࣮ߦʂʂ
εΩϟϯίϯϘ Discovery Host Vulnerability Scan Well-known ports Scan(Details) AutoRecon ͳʹΛ͢Δʹ·ͣίϨ
ΦεεϝίϯϘ "VUP3FDPO %JTDPWFSZ)PTU
ΤΫεϓϩΠτίϯϘ Password Crack Create MSF DB Import to MSF DB
Start Metasploit Check the service ͚ແ༻ɺୟ͖ࠐΊʂ ΦεεϝίϯϘ 1BTTXPSE$SBDL
ίϯϑΟάίϯϘ Import data into Faraday Switch CUI mode Configure targets
Switch GUI mode ޭͷΧΪɺ४උീׂ ΦεεϝίϯϘ *NQPSUEBUBJOUP'BSBEBZ
ϥʔχϯά ͔Βͳ͍ࣄΛΔࣄ͕Ұ൪ͷֶͼ "TTJTU MFBSOUP ίϯϘͷ࠷ޙʹMFBSOUPΛબͿͱ ը໘ӈଆʹ࣮ߦ͞ΕΔίϚϯυͷ આ໌͕දࣔ͞ΕΔ "TTJTUΛબͿͱɺ֤جຊίϚϯ υͰͷಈ࡞ʹ͍ͭͯͷղઆΛද ࣔ͢Δ
1",63*ΛऔΓೖΕֶͨशαΠΫϧ ࣮ԋ ղઆ ʢϥʔχϯάʣ ࣮श ʢίϯϘʣ ޭମݧ ʢ݁ՌͷՄࢹԽʣ ͬͯΈͤɺݴͬͯฉ͔ͤͯɺͤͯ͞Έͤɺ΄ΊͯΒͶɺਓಈ͔͡ ࢁຊޒे
Your benefits ϨουνʔϜͷ߹ 1",63*Λ༻͢ΔࣄͰɺසൟʹར༻͢ΔίϚϯυΛ ೖྗ͢Δख͕ؒল͚·͢ɻ ॳ৺ऀͷϖϯςελʔɺ1",63*Λ༻ͯ͠߈ܸͷ ྲྀΕΛֶ·͢ɻ ϒϧʔνʔϜͷ߹
؆୯ͳૢ࡞Ͱɺ߈ܸऀͷߦಈΛ฿Ͱ͖·͢ɻ ˞͋͘·ͰҰྫͰ͢
ֶश͔Β࣮·ͰςϯΩʔ͚ͩͰͰ͖Δʂ
テンキーの子 Operation with Ten-key
·ͱΊ ɹϖϯςελʔखΛಈ͔͢͜ͱ͕େ͖Ͱ͢ɻ͔͠͠ɺ ໘͍͘͞࡞ۀ͖Ͱ͋Γ·ͤΜɻ1",63*ɺϖω τϨʔγϣϯςετͰසൟʹ༻͢ΔίϚϯυΛςϯΩʔ ͷૢ࡞͚ͩͰ࣮ߦ͠·͢ɻ·ΔͰ֨ಆήʔϜΛ͍ͬͯΔ Α͏ͳײ֮ͰͰ͖·͢ɻ
·ͱΊ ɹ1",63*ϖωτϨʔγϣϯςελʔͷΩϟϦΞΛ։ ࢝͢ΔͷʹʹཱͯΔͱࢥ͍·͢ɻ,BMJ5PPMTʹ४ڌ ͢ΔπʔϧΛ༻͍ͯ͠ΔͷͰඞཁҎ্ʹഁյ͢Δ͜ͱ ͠·ͤΜɻ1",63*Λ༻͢Δ͜ͱͰɺϖωτϨʔ γϣϯςετͷϑϩʔΛ؆୯ʹମݧֶ͠Ϳ͜ͱ͕ग़དྷ· ͢ɻ ɹ1",63*ΛͬͯΈͯɺϖωτϨʔγϣϯςετʹڵ ຯΛ͍࣋ͬͯͩ͘͞ɻ
Thank you! Please give me advice and feedback.
[email protected]
@PAKURI9
@01ra66it https://github.com/01rabbit/PAKURI