2014-07-14 SITCON Camp 揭開駭客的神祕面紗
揭開駭客的神祕面紗4*5$0/$BNQ翁浩正 Allen Own[email protected]Ꮦ˃ဧٰ΅Ϟࠢʮ̡
View Slide
ᑺ٫ᔊʧॽख͍ "MMFO0XO%&7$03&Ꮦ˃ဧٰ΅Ϟࠢʮ̡ੂБڗBMMFOPXO!EFWDPSF!)*5$0/̨ᝄᎡ܄ϋึਓᐼ̜/*43"༟τྠඟ௴፬ɛ༟τҦঐږᆤᘩᒄϋڿࠏeϋԭࠏ༟τదၣ१ታ१ᚥਪ
ٷ᧼㔃க፞)*5$0/9"%"15505)&/&8&3"0'4&$63*5:5)3&"54 ˾_ ̄ٷޠΥḛ৮㑱ൽ㡴˒৴ἵ㋒̙ቢῳ፞㒔IUUQIJUDPOPSH
νОϓމ੶٫k
ኪࣧʔ݊ϞkމʡჿᒔࠅІʉрɢk
ኪࣧԃଣሞeʫ̌ ุޢྼਕeуࣛɢe؛̌
ኪࣧԃଣሞeʫ̌ ุޢྼਕeуࣛɢe؛̌๖
৷ʕɽኪӺהఱุ
৷ʕɽኪӺהఱุ為什麼?
৷ʕɽኪӺהఱุ????
৷ʕɽኪӺהఱุㄨ
ྼਕࠦ̈೯ᓘ՟ุޢeၣ༩ɪٙٝᗆԑኪࣧίྼਕɪٙʔԑ
ᜊ੶ٙږᝌjІ˴ኪ୦
老老師領領進門,修行行在個㆟人
І˴ኪ୦ഛ͜ၣ༩ɪٙኪ༟๕ʔࠅᔊʕ˖eߵ˖й፰ဲdਗ˓ਂఱ࿁əlϓఱชܘࠠࠅl
ʔࠅ̰̰ٙɛdʑ݊ኪՑ௰εٙ
ࡳԬٝᗆ݊Ңࡁ̀௪ٙճk
όႧԊ$$+BWB$໔͉ႧԊ 4DSJQUJOH-BOHVBHF4IFMM4DSJQU+BWB4DSJQU1ZUIPO3VCZ1FSMၣࠫᏐ͜όႧԊ"41/&51)1+413P3БਗༀໄόႧԊ"OESPJE +BWBJ04 0CKFDUJWF$8JOEPXT1IPOF
νО፯όႧԊk5*0#&1SPHSBNNJOH$PNNVOJUZ*OEFYIUUQXXXUJPCFDPNJOEFYQIQDPOUFOUQBQFSJOGPUQDJJOEFYIUNMરБᒈැ̙˸ՑႧԊٙᆠژܓ˸ʿุޢٙცӋ
ڐಂ༟τࠅၲ
ᒄژ᚛дj̘ϋΌଢϞᄂഅࡈ༟̮ރᒄژ᚛д௰อ*453ၣ༩τΌ۾উజѓܸ̈d̘ϋ೯͛ٙ༟τԫᜑͪdᎡ܄ҸᏘҞҸᏘᔷމڗಂᆑͿٙɓϣɽᅼҸᏘdϋΌଢߒϞᄂഅ༟̮ࣘރfί༈జѓ୕ࠇʕd̨ᝄίϋၣ༩۾উʕΤΐΌଢୋdԭݲසϣʕeΙܓfʫϞٙ০࿁ҸᏘᕁ֛ՑɛᅼٙʕɽۨΆุdҭ೯ʿႡிุމҸᏘᕁ֛ٙՇɽପุfϾ̘ϋ̨ᝄչѫඉરΤୋΤɪʺЇୋdⶋ܉ၣ༩ɰરΤୋfIUUQXXXJUIPNFDPNUXOFXT
F#BZቊල܄ɝڧ ᄂ͜˒༟̮ࣘރF#BZ˚ί֜˙ၣ१ʮ̺dʦϋ˜ֵЇ˜ڋdᄂ܄˒ٙཥඉήѧe̋ܝٙᇁë͛˚ಂʿИѧഃᅰኽೳ՟dШೳ՟ٙ˖Ѱʔўৌਕ༟ࣘfʮ̡ڮሗᄂ͜˒һҷᇁfF#BZڌͪdմۃ೯ତவԬቊᎡٙਪᕚኯᗇdމə࿏ֵݟਪᕚdה˸ٜՑ˚ʑʮ̺dШ൷ᕎ˜ڋቊල܄ɝڧࣛගʊڐࡈ˜fIUUQXXXCCDDPVL[[email protected]@IBDLFSTIUNM
"0-վוӻ୕ቊɝڧd Ꭱ܄̙ঐπ՟ɽඎԴ͜٫੮"0-ᆽႩᎡ܄͊બᛆπ՟əўϞɽඎԴ͜٫੮ٙУኜdܼ̍͜˒ٙཥɿඉ੮eήѧeஷৃe̋ٙᇁe̋ٙτΌஷᗫႧd˸ʿʈЪఊЗdϾ˲"0-ɰڦչѫᔥʊෂൟᗺඉഗߒ͜˒ٙஷৃʾɛfIUUQXXXJUIPNFDPNUXOFXT
ߕཧਯਠ*5ӻ୕Κዚ ৰə5BSHFUεཧਯਠɰቊݪ௰ڐdԨʔස˟5BSHFUɓ೯͛ࠠɽ༟̮ࣘރԫf࣬ኽ༩ீٟܸ̈dίື˚ᒅي֙ಂගdৰə5BSHFUၾ/FJNBO.BSDVTʘ̮ٙεཧਯਠdɰቊՑᎡ܄ҸᏘfɪ5BSHFUீᚣܸ̈dᎡ܄՟ə ຬഅٙᚥ܄֑Τeඉήѧeཥ༑ᇁeཥɿඉήѧၾ˕˹̔༟ࣘdШ̘ϋ˜ʕϚৎజኬ፲̰ٙഅᅰމ ຬഅfIUUQOFXTOFUXPSLNBHB[JOFDPNUXDMBTTJGJDBUJPOTFDVSJUZ
ӚϞʔτΌٙӻ୕ ̥ϞʔτΌٙɛ
A Nice Password, but….?Admin passwordAdmin.R386W
Is Your Password Safe?
ซซІʉϞӚϞਂՑτΌfໆӻ୕ʔτΌʘۃd
༟τ۾উၾᏐ࿁ԣጏ٫ԨʔᆞҸᏘ٫ٙː࿒eͦٙeҦஔഃdኬߧԫ೯͛ܝʑঐආБࡌfϾʔٝ༸ҸᏘٙҦஔၾ˙جdࡌɰසطᅺʔط͉ෂ୕ٙԣጏ˙όdܼ̍ӻ୕ࡌeԣጏe̋dேΪอҦஔɓɓॎ༆dԷνʱόஈଣeථ၌e(16e3BJOCPX5BCMF
༟τ۾উၾᏐ࿁ٝʉٝ־dϵʔݫኪ୦Ꭱ܄ٙܠၪd௰อٙҦஔdԨ˲ə༆Іʉӻ୕ٙঌࢮᓃӺίОஈ
Cyberwar݊ʡჿk
http://www.flickr.com/photos/[email protected]/5246970893/Cyberwar
ၣ༩͍ίආБʕl
Ŗϓၣ༩ගፒҸᏘԸІॴዚ೯ਗ࣬ኽϋ7FSJ[PO௰อ೯̺ٙ༟̮ࣘރሜݟజѓܸ̈dίሜݟڐٙၣ༩ගፒҸᏘԫʕdϞ݊ԸІִ݁ॴዚٙ೯ਗdՉʕऒʿ༟̮ࣘރٙҸᏘݺਗۆ݊Цəfజѓɰܸ̈dϞਗ਼ڐɓ̒ ٙၣ༩ගፒݺਗேԸІʕձՉ̴؇ԭה˴ኬd̤̮ɰϞĈۆ݊ԸІ؇ᆄήਜfʕһϞ൴ཀ̒ᅰ˸ɪٙၣ༩ගፒҸᏘ࿁݊˸ߕމ˴dՉϣ݊˚͉ ձᒵ fIUUQXXXJUIPNFDPNUXOFXT
Ꭱ܄ᜣ့ཥൖ̨ვБیᒵజኬj̏ᒵהމیᒵɪ˜ቊᎡ܄ɝڧdεཥൖ̨ձვБΌࠦᜣ့dیᒵᙆ˙ɓܓ၈Ꭱ܄ҸᏘԸІʕdܝҷɹ݊ߕʿᆄݲഃࡈdШʦ˂یᒵʮ̺͍όజѓdܸછ̏ᒵᆽމவৎҸᏘࣩٙ˴ፑdᘪࣛගڗ༺˜ʘɮfIUUQXXXBQQMFEBJMZDPNUXSFBMUJNFOFXTBSUJDMFJOUFSOBUJPOBM
Ꭱ܄त၇ඟږ㛬Έˏ͜ɓ΅̏ᒵִ݁֜˙˖༟ܸࣘ̈d̏ᒵʊ݂ჯኬɛږ͍˚ϋᒔፋІɨ˿ਗ਼ணί̻ᘎٙၣ༩त၇ඟᓒᇜЇ ɛdᒱ್༈΅˖ٙॆྼ͊ᆽႩdШږ㛬ΈኽϤౣd̏ᒵᎡ܄ɛᅰʘܝʊɽషᄣ̋dϞԬ݊ݼታʕd˸کԫသீऎ̮ၣ༩ٙਕfIUUQOFXTDIJOBUJNFTDPNXPSMEIUNM
Die Hard 4.0
ၣ༩ٙͦٙ݊ʡჿk՟ઋజᜣ့ၣ༩ਔ॰܁౮ІҢଣׂ
Ꭱ܄݊ʡჿkWhat is Hacker?
http://www.flickr.com/photos/torh/5275187124/
Ꭱ܄݊ʡჿᎡ܄ )BDLFSࡡจމ ᆠহཥ໘ӻ୕ҦஔӺٙਖ਼ɽඎႬ͜ɨᎡ܄ɓ൚੭ϞࠋࠦЍd੬މڢجెจॎᕸeɝڧӻ୕ٙɛ
Ꭱ܄݊ʡჿWhite Hat 白帽駭客 ༟τਖ਼d࿁ӻ୕τΌආБӺԨԣጏࡌfεᅰԫ༟ৃτΌᗫБุBlack Hat 黑帽駭客 ආБ͕ໆٙɝڧБމdਖ਼̡ॎᕸd˸ۃ͵̙၈މ$SBDLFS
Ꭱ܄݊ʡჿ(SFZ)BUϲసᎡ܄ʧ8IJUF)BUʿ#MBDL)BUʘග4DSJQU,JEEJFҦஔʔॱᆞאʔᏑࡡଣd̥ึԴ͜ତϞҸᏘόආБెจॎᕸٙҸᏘ٫dᏕ၈މ4DSJQU,JEEJFdͦۃεᅰెจॎᕸ٫ޫ݊
Ꭱ܄ଡ଼ᔌ֜˙ᇜՓִ݁Άุڢ֜˙ᇜՓήɨ
Ꭱ܄ҸᏘٙͦᅺͦᅺjУኜࡈɛཥ໘ెจᎡ܄މə༺ՑݔԬͦٙdึҸᏘУኜאࡈɛཥ໘fʔΝٙͦᅺึϞʔΝٙҸᏘ˓جdɰึϞഹʔΝٙͦٙf
ၣ१ɝڧٙܝ؈kᎡ܄Ցֵࠅٙ݊ʡჿk
ၣ१ɝڧٙܝ؈k՟ၣ१ʫ༟ࣘਂމ༪ؐҸᏘՉ˼˴ዚનᇁא׳ໄెจόໄ౬ࠫࠦאॎᕸ՟१ʫ੮ᇁࡈ༟
Ꭱ܄՟੮ᇁνОԴ͜০࿁ٙೳ͜ݔ੮՟၍ଣ٫ᛆࠢਗ਼ᇁᏦႡЪϓοՊᏦ
ࡈɛཥ໘ɝڧٙܝ؈kᎡ܄Ցֵࠅٙ݊ʡჿk
ࡈɛཥ໘ɝڧٙܝ؈k ՟ཥ໘ʫ༟ࣘ ՟ཥ໘ʫ੮ᇁࡈ༟ ਂމ༪ؐҸᏘՉ˼˴ዚ
㔃கሯᇜḢပᚓ㢂
⁰ഥ㉺⁔ፇሟᇌ༃༦⾬̳⳽୷⭶ё ῳ̎ഇ₁༓༶⾽̿
⁰ഥ㉺⁔ፇሟᇌ⳽୷⭶ёᖤஞቒ̳ῳ̎ഇ₁༓༶⾽̿
ሟᇌ⳽୷⭶ё⋣⳽ቛൻ#PUOFU%%P4ሯᇜ
ሟᇌ⳽୷⭶ё⋣⳽ቛൻṬᄍӴξͥ፦࠵
http://weblog.rubyonrails.org/2013/1/8/Rails-3-2-11-3-1-10-3-0-19-and-2-3-15-have-been-released/你更新了嗎?
你更新了嗎?
੬ԈτΌဍݸ࡚ؓ
ၣ१༟ৃރဍၣ१፹Ⴌৃࢹ͊ᒯᔛУኜක೯٫و͉છ၍ࠫࠦ͊ৰၣࠫУኜක઼ͦΐڌ *OEFY0GࠬᎈjഗʚᎡ܄ɝڧٙ༟ৃdܼ̍ӻ୕ৣໄeͦdޟЇ੮eᇁഃ
⊷ਘῠ໊aіa⊷ਘῠẀᇂ
ᅟℯⅴਫ਼
?
B 網站密碼:1qaz2wsxC 網站密碼:[email protected]#$%^%^*ag密碼:1qaz2wsxA 網站(遭⼊入侵)(⼊入侵)
၍ଣ٫͊းபᒯਛʔజˏ೯һᘌࠠٙԫ࿒પ՝பೌج༆Ӕਪᕚ๘ᗇኽਪᕚԱᔚπίdᎡ܄ஶჇІί
ၣ१τΌᏨνОྼЪ
ၣ१τΌᏨνОྼЪݟ༔Уኜeࢁٙو͉༟ৃᝈ࿀ၣ१ࠫࠦeʩ९eආɝᓃഗʚ͍੬ٙ፩ɝeମ੬ٙ፩ɝdᝈ࿀ၣ१ٙˀᏐʿৃࢹ5SJBMBOE&SSPS
༊ʈՈ.BOUSBIUUQXXXHFUNBOUSBDPN#VSQ4VJUFIUUQQPSUTXJHHFSOFUCVSQ'JEEMFSIUUQGJEEMFSDPN
τΌᏨʃҦ̷Ꮸၣ१݊щಀᎡIUUQXXXHPPHMFDPNTBGFCSPXTJOHEJBHOPTUJD TJUFIUUQ[POFIPSHIUUQXXXNBMXBSFEPNBJOMJTUDPNNEMQIQIUUQXXXVSMWPJEDPN
Ꭱ܄ٙܠၪ༧Ңࡁʔɓᅵ
Injection?Path?Path?
admin‘ or 1=1 --admin abc123 123456 password3939889 19831001 A1234567887468c07c02e370ef84d4b7e3a668589Try to get the passwordWordPress Vulnerability?
Ꭱ܄ҸᏘݴ3FDPOOBJTTBODF4DBOOJOH(BJOJOH"DDFTT.BJOUBJOJOH"DDFTT$MFBSJOH5SBDLTReconnaissanceScanningGaining AccessMaintaining AccessClearing Tracks
ॆྼҸᏘԫԷᎡ܄͟ၣ१ҬՑɪෂeᄳᏦഃࢮᓃdಔɝXFCTIFMMܝژஹɝ˴ዚfIUUQWJDUJNPSHTIFMMQIQ DNEPYPY၇ၣࠫτΌਪᕚޫ̙л͜dܼ̍ᄳᏦeҷᏦeɪෂᏦࣩf
ॆྼҸᏘԫԷ $POUஹɝ˴ዚܝ೯ତ੮ᛆࠢʔԑd˴ዚʫరҬ̙ٙ͜༟ৃfᛆࠢjOPCPEZOPHSPVQҬర̙͜੮FUDQBTTXEݟ༔ӻ୕̙͜༟ৃWBSMPHฤరϞೌTFUVJEGJMFT̙Զл͜
ॆྼҸᏘԫԷ $POU೯ତ˴ዚ,FSOFMو͉ཀᔚdϞ̙ᛆٙࢮᓃfᅠᄳฤర&YQMPJUҸᏘd՟SPPUᛆࠢfIUUQXXXFYQMPJUECDPN(PPHMF#ZZPVSTFMG
ॆྼҸᏘԫԷ $POU׳ໄܝژ3PPULJU˸Զ˚ܝԴ͜fFUDQBTTXEܔͭ੮FUDSDE׳ໄܝژ˾౬TTIEഃ
ॆྼҸᏘԫԷ $POUৰԑ༦jাᏦʿӻ୕ߏ_IJTUPSZ[email protected]WBSMPH
ၣ༩݊τΌٙk
8FMDPNFUPQIQ.Z"ENJO"/% $SFBUFOFXEBUBCBTFGJMFUZQFQIQ
-BC
ІҢኪ୦
༟τהცٙٝᗆߠ౻ၾҦঐ༟ৃϗණ*OGPSNBUJPO(BUIFSJOHӻ୕τΌ4ZTUFN4FDVSJUZၣ༩τΌ/FUXPSL4FDVSJUZၣ१ၾၣࠫᏐ͜ότΌ8FC4FDVSJUZ̋ၾ༆$SZQUPHSBQIZెจόᏨ.BMXBSF%FUFDUJPOΣʈ3FWFSTJOH&OHJOFFSJOHᅰЗᛠᗆ%JHJUBM'PSFOTJDTБਗༀໄ.PCJMF%FWJDFT
ІҢᇖ୦IUUQTXXXPXBTQPSHJOEFYQIQ$BUFHPSZ08"[email protected]([email protected]IUUQTQFOUFTUFSMBCDPNIUUQXXXEWXBDPVLIUUQXXXIBDLUIJTTJUFPSHIUUQIBDLBEFNJDUFJMBSHSIUUQTIBDLNFIUUQ[FSPXFCBQQTFDVSJUZDPNIUUQTPVSDFGPSHFOFUQSPKFDUTNVUJMMJEBF
2"
ᑌഖ˙ό߰ϞОٙဲਪdᛇڎᎇࣛၾҢᑌᖩf""ॽख͍"MMFO0XOIUUQEFWDPSFBMMFOPXO!EFWDPSF