Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Reviewing 2024
Search
Takahiro Yoshimura
December 10, 2024
Technology
0
23
Reviewing 2024
Reviewing chapter activities in 2024. (OWASP Saitama MTG #23, talk #1)
Takahiro Yoshimura
December 10, 2024
Tweet
Share
More Decks by Takahiro Yoshimura
See All by Takahiro Yoshimura
Repeat After Me #1
alterakey
0
20
Slaying 2FA
alterakey
0
17
Ghost Warden
alterakey
0
19
Toxic Oversight
alterakey
0
18
In The Middle Of Chatter #2
alterakey
0
29
Chaotic Channel
alterakey
0
38
In The Middle Of Chatter #1
alterakey
0
40
Shadow Runners 2
alterakey
0
9
Shadow Runners
alterakey
0
9
Other Decks in Technology
See All in Technology
Apache Spark もくもく会
taka_aki
0
140
人工衛星のファームウェアをRustで書く理由
koba789
15
8.3k
実践!カスタムインストラクション&スラッシュコマンド
puku0x
0
550
Unlocking the Power of AI Agents with LINE Bot MCP Server
linedevth
0
120
「その開発、認知負荷高すぎませんか?」Platform Engineeringで始める開発者体験カイゼン術
sansantech
PRO
2
950
品質視点から考える組織デザイン/Organizational Design from Quality
mii3king
0
210
要件定義・デザインフェーズでもAIを活用して、コミュニケーションの密度を高める
kazukihayase
0
120
KotlinConf 2025_イベントレポート
sony
1
140
未経験者・初心者に贈る!40分でわかるAndroidアプリ開発の今と大事なポイント
operando
6
750
開発者を支える Internal Developer Portal のイマとコレカラ / To-day and To-morrow of Internal Developer Portals: Supporting Developers
aoto
PRO
1
480
slog.Handlerのよくある実装ミス
sakiengineer
4
480
下手な強制、ダメ!絶対! 「ガードレール」を「檻」にさせない"ガバナンス"の取り方とは?
tsukaman
2
460
Featured
See All Featured
Improving Core Web Vitals using Speculation Rules API
sergeychernyshev
18
1.1k
The MySQL Ecosystem @ GitHub 2015
samlambert
251
13k
ピンチをチャンスに:未来をつくるプロダクトロードマップ #pmconf2020
aki_iinuma
127
53k
Connecting the Dots Between Site Speed, User Experience & Your Business [WebExpo 2025]
tammyeverts
8
530
Visualizing Your Data: Incorporating Mongo into Loggly Infrastructure
mongodb
48
9.7k
How To Stay Up To Date on Web Technology
chriscoyier
790
250k
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
285
14k
The Art of Programming - Codeland 2020
erikaheidi
56
13k
The Illustrated Children's Guide to Kubernetes
chrisshort
48
50k
Easily Structure & Communicate Ideas using Wireframe
afnizarnur
194
16k
Making the Leap to Tech Lead
cromwellryan
135
9.5k
個人開発の失敗を避けるイケてる考え方 / tips for indie hackers
panda_program
113
20k
Transcript
REVIEWING 2024 OWASP SAITAMA MTG #23, TALK #1 Image by
Secret_Cinema on flickr, CC-BY 2.0
TEXT SESSION FLAGS ▸ ըɾԻɾެ։: OK Image by Nico Kaiser
on flickr, CC-BY 2.0
TEXT WHO I AM ▸ Takahiro Yoshimura (@alterakey) https://keybase.io/alterakey ▸
Monolith Works Inc. Co-founder, CTO Security researcher ▸ ໌࣏େֶαΠόʔηΩϡϦςΟݚڀॴ ٬һݚڀһ
TEXT WHAT I DO ▸ Security research and development ▸
iOS/Android Apps →Financial, Games, IoT related, etc. (>200) →trueseeing: Non-decompiling Android Application Vulnerability Scanner [2017] ▸ Windows/Mac/Web/HTML5 Apps →POS, RAD tools etc. ▸ Network/Web penetration testing →PCI-DSS etc. ▸ Search engine reconnaissance (aka. Google Hacking) ▸ Whitebox testing ▸ Forensic analysis
TEXT WHAT I DO ▸ CTF ▸ Enemy10, Sutegoma2 ▸
METI CTFCJ 2012 Qual.: Won ▸ METI CTFCJ 2012: 3rd ▸ DEF CON 21 CTF: 6th ▸ DEF CON 22 OpenCTF: 4th ▸ ൃදɾߨԋͳͲ DEF CON 25 Demo Labs (2017) DEF CON 27 AI Village (2019) CODE BLUE (2017, 2019) CYDEF (2020) etc. Image by Wiyre Media on flickr, CC-BY 2.0
2024... Image by Marc Barrot on flickr, CC-BY-NC-ND 2.0
FEBURARY Image by osseous on flickr, CC-BY 2.0
TEXT FEBURARY ▸ 2024࠷ॳͷ։࠵ ▸ य़෦ࢢ;Ε͍͋Ωϡʔϒ4F ձٞࣨ2 ▸ ڧ෩ͱפ͞… →Ϧʔμʔ2໊ͷΈͷࢀՃ
→࠲ஊձʹͳͬͯ͠·ͬͨ Image by Jeff Sullivan on flickr, CC-BY-NC-ND 2.0
SHADOW RUNNERS FRONT Image by Neil Moralee on flickr, CC-BY-NC-ND
2.0
TEXT FRONT: SHADOW RUNNERS ▸ iOSΞϓϦ ϦϦʔε࣌ΞϓϦϨϏϡʔͰ࣭୲อ ▸ ಈతϩʔυͳͲʁ →App
Review Guidelines, 2.5.2ʹΑΓېࢭ ▸ ͳͥʁ →ϨϏϡʔͷҙຯ͕ͳ͘ͳΔͨΊ ▸ ࣮ࡍͲ͏ͳͷʁˠݕূͩʂ Image by Neil Moralee on flickr, CC-BY-NC-ND 2.0
TEXT CASE STUDY #1. FACEBOOK ▸ facebook ▸ ಈతίʔυϩʔυ ▸
Stack-based VM ▸ ϑΟʔυͷཏྻ ▸ ͞Βʹ: Ad͔Βϩʔυ͢ΔΑ͏ͳࣔࠦ
TEXT CASE STUDY #2. LINE -- BUSTED ▸ ҧͷՄೳੑ͕ߴ͍ ▸
߇͑Ίʹݴͬͯؾ࣋ͪѱ͍ ▸ syscall, fork ▸ MbedελοΫʹΑΔ҉߸ܥ࣮Λྲྀ༻ →ͱͯ҆શͱ͍͑ͳ͍࣮ Image by Cloudtail the Snow Leopard on flickr, CC-BY-NC-ND 2.0
TEXT CASE STUDY #3. GMAIL -- QUESTIONABLE ▸ JVM +
j2objcͷՄೳੑ ▸ 2.5.2͜Ε͚ͩͰҧͰͳͦ͞͏͕ͩ: 2.3.1 (no hidden feature) ͔ΒͲ͏ͳͷ͔ ▸ Ұൠͷ։ൃऀ͕ͬͨΒଟreject͞ΕΔͩΖ͏ ͍ͣͿΜҟ࣭ͳߏ Image by Bricknave on flickr, CC-BY-NC-ND 2.0
TEXT FRONT: SHADOW RUNNERS ▸ ͍ͩͿܗ֚Խ…Ͳ͜Ζ͔ →AdʹΑΔಈతίʔυ࣮ߦ →γεςϜίʔϧ࣮ߦ →VM࣮ͷൃݟ ▸
ਓྗʹΑΔϨϏϡʔͱ →ͷ͔ͨ·Γ →୯ͳΔfalse sense of security… ▸ ݕূͳ͖҆શͳͲͳ͍͜ͱΛݟͨճ Image by Gunnar Ries zwo on flickr, CC-BY-SA 2.0
APRIL Image by Ron Masters on flickr, CC-BY-NC 2.0
TEXT APRIL ▸ ͍ͨ͞·ࢢ։࠵ճ ▸ RaiBoC ूձࣨ ▸ ༐Ռͳ։࠵ ࠂ͚ΕGWͷͲ·Μͳ͔…
→ϦʔμʔؚΊ3໊ͷࢀՃ Image by Pedro Ribeiro Simões on flickr, CC-BY 2.0
SHADOW RUNNERS 2 FRONT Image by Neil Moralee on flickr,
CC-BY-NC-ND 2.0
TEXT FRONT: SHADOW RUNNERS 2 ▸ iOSͷܧଓత؍ଌʹଓ͍ͯ… ▸ Android: σετϥοϓʹΑΔ҆શੑ୲อ
▸ ಈతϩʔυͳͲͳ͠ ▸ ո͍͠ڍಈͷͷͳ͍ͣ →ݕূͩʂ Image by Neil Moralee on flickr, CC-BY-NC-ND 2.0
CASE 1: IOS Image by Janitors on flickr, CC-BY 2.0
TEXT CASE STUDY #4. GOOGLE MAPS ▸ Google Maps ▸
େྔͷre fl ection → ಈ࡞ͷൿಗͱऔΕΔ
TEXT CASE STUDY #4. GOOGLE MAPS -- QUESTIONABLE ▸ ੩తղੳճආͷՄೳੑ
▸ গʑͳΒre fl ectionී௨ʹग़ͯ͘Δ; ͭ·Γ: Ұൠͷ։ൃऀ͕͜ΕΛͯ͠ଟreject͞Εͳ͍ → API༻ύλʔϯΛ͋Δఔૢ࡞Ͱ͖Δࣔࠦ ▸ 2.3.1 (no hidden feature) ͔ΒͲ͏ͳͷ͔ →ਓྗͰશͯݟൈ͘͜ͱͰ͖ͳ͍ Image by Portraying Life, LLC on flickr, CC-BY-NC-ND 2.0
TEXT FRONT: SHADOW RUNNERS 2 ▸ iOS: ϦϦʔε࣌ΞϓϦϨϏϡʔͰ࣭୲อ ▸ ಈతίʔυϩʔυɾVMͳͲʹՃ͑
େྔͷRe fl ectionʹΑΔ੩తղੳճආ →͜ΕʹΑΓAPI༻ύλʔϯ͕ૢ࡞Մೳʹ ▸ ਓྗϨϏϡʔ҆શੑʹد༩͠ͳ͍… AppleAPI༻ύλʔϯ͚ͩͰͳ͘ίʔϧස ߟྀ͖͢ Image by Brandon Grasley on flickr, CC-BY 2.0
CASE 2: ANDROID Image by etnyk on flickr, CC-BY-NC-ND 2.0
TEXT FINDINGS ▸ ੩తղੳ ▸ ಈతdexϩʔυʢಡԽΫϥε͔Βʣ ▸ Wi-Fi BSSIDऔಘ͓Αͼ৴߸ڧܭࢉ ▸
OkhttpܥΛܦ༝͢ΔτϥϑΟοΫʹ͓͚Δ ಠࣗDNSαʔϏεͷ༻ (httpϕʔε; ॺ໊͖) ▸ ֤ݕ: σόοά/rooted/VPN/ϓϩΩγ ▸ σόοάݕϑϥάͷड͚͠
TEXT CASE STUDY #5 SHEIN -- BUSTED ▸ ेೋʹݏΒ͍͠… ▸
ϓϥΠόγʔͱ͍͏֓೦ͳ͍ͷ͔ ಛʹTrustDefender: ݻ༗ใ, Wi-Fi .. →कΒΕ͍ͯΔͷύϒϦογϟʔ ▸ ଟΫϨʔϜ্͕͕͍ͬͯͳ͍ͷͰ์ஔʁ ▸ ͜Ε͜ΕͰ͋Γ͕ͩͳӡ༻ ▸ ҰൠʹEULAʹΑΓੳͰ͖ͳ͍ͨΊ Image by Mark Freeth on flickr, CC-BY 2.0
TEXT FRONT: SHADOW RUNNERS 2 ▸ Android: มͳ͜ͱΛ͢Είϩε ▸ ͕࣮ͩଶ:
ͪ͜Βܗ֚Խ͕ஶ͍͠ →ύϒϦογϟʔͷΓ͍ͨ์, EULAͱ ▸ େྔͷใऩूɺࣥ፠ͳڥݕɺDNSͷ ૡ͍જΓɺRe fl ectionʹΑΔ੩తղੳճආ… (ClipboardΞΫηεɺτϥϑΟοΫͷ౪ௌվ ᜵ɺະॺ໊֎෦ίʔυͷϩʔυͳͲ; SDKܦ༝Ͱ ԣߦ) Image by daveoratox on flickr, CC-BY 2.0
TEXT FRONT: SHADOW RUNNERS 2 ▸ Ϟϥϧͷ͞Λ࠶֬ೝͨ͠ճ Image by Petri
Damstén on flickr, CC-BY-NC-ND 2.0
JUNE Image by Joe Penniston on flickr, CC-BY-NC-ND 2.0
TEXT JUNE ▸ य़෦ࢢ։࠵ճ ▸ य़෦ࢢ;Ε͍͋Ωϡʔϒ 4F ձٞࣨ2 ▸ ॵ͔͕֮ͬͨ͑…
Image by Zaqqy on flickr, CC-BY 2.0
CHAOTIC CHANNEL FRONT Image by Denkrahm on flickr, CC-BY-ND 2.0
TEXT FRONT: CHAOTIC CHANNEL ▸ What is Wi-Fi? ▸ ...
Wi-Fiͷ҆શੑʹ͍ͭͯऔΓѻͬͨճ ▸ ͪͳΈʹWi-Fi = Wireless Fidelity…Ͱͳ͍ ʢWiͱ͔͘ɺFiແҙຯͳޠʣ Image by Denkrahm on flickr, CC-BY-ND 2.0
TEXT SNIFFING ▸ ৴߸डʹΑΔ௨৴ड ▸ WEP: ҉߸Խ (RC4/CRC32)
TEXT WEAK CRYPTOGRAPHY ▸ ҉߸ܥͷڧෆʹΑΔ౪ௌվ᜵ ▸ WEP: ൵ࢂͳ΄Ͳͷແཧղ RC4 ..
伴ࢦఆ, IVෆ, ༌ग़ن੍etc. CRC32 .. ֎; Compensation attack (sshnuke..!) ▸ WPA: 伴ཧڧԽʴೝূ͕ೖ͕ͬͨ… RC4 .. PBKDF2-MD5, statistical bias Michael .. invertible (※), related-keys, birthday ※C = Michael(K, M)ʹ͓͍ͯC,M͔ΒKΛܾఆՄೳ ▸ WPA2: ೝূ҉߸Խ (AES-CCMP) બՄ Image by Steve Bowbrick on flickr, CC-BY 2.0
TEXT WIFI PROTECTED SETUP ▸ PINͷਪଌ →Personal Identi fi cation
Number…ͩͱʁ →ͨͬͨ7ܻͷ͔ͭΦϑϥΠϯ߈ܸՄೳʂ ▸ Pixie dust attack (Bongard 2014) ▸ WPS: PBCͷΈͷӡ༻ Image by alvinchanphotography on flickr, CC-BY 2.0
TEXT DOWNGRADE ATTACKS ▸ KRACK attacks (Vanhoef, 2017) ▸ 4-way
handshakeΛҰ෦վ᜵ɾϦϓϨΠ͠… ɾnonceΛ࠶ར༻ͤ͞Δ Image by Archetype Fotografie on flickr, CC-BY-SA 2.0
TEXT DENIAL OF SERVICE 1 ▸ ͍ΘΏΔdeauth߈ܸ ཧϑϨʔϜͷૹʹΑΔDoS ▸ ཧϑϨʔϜ͕ೝূΛཁٻ͠ͳ͍͜ͱ͕ݪҼ
▸ WPA3: Protected Management Frames (802.11w) Image by jyri on flickr, CC-BY 2.0
TEXT DENIAL OF SERVICE 2 ▸ Dragonblood (Vanhoef, 2019) ͷҰͭ
▸ ϥϯμϜͳMACΞυϨε͔ΒSAE Commitϑ ϨʔϜΛେྔʹૹ͠ɺDragonFlyॲཧίετΛ ૿෯ →ପԁۂઢܥͷΛ෮తʢHunting-and- PeckingʣʹٻΊ͍ͯΔ͜ͱͳͲ͕ݪҼ →ͱͱλΠϛϯά߈ܸରࡦ͕ͩ… Image by jyri on flickr, CC-BY 2.0
TEXT INTER-FRAME INTEGRITY FAILURE ▸ FragAttack (Vanhoef, 2021) ▸ ϑϨʔϜؒͷೝূ͕͍
ɾis aggregatedϑϥά͕ະೝূ ɾPairwise session keyߋ৽ΛڬΜͰϑϨʔϜ͕ assemble͞ΕΔ ɾΫϥΠΞϯτஅ࣌ʹfragment cache͕Ϋ ϦΞ͞Εͳ͍ ɾTKIPʹ͓͍ͯfragmentsͷMICΛݕূ͠ͳ͍ ɾetc .. Image by James Marvin Phelps on flickr, CC-BY-NC 2.0
TEXT OFFLINE CRACKING ▸ 4-way handshakeͷMIC͔ΒύεϫʔυΛਪଌ (802.11i-2004) ▸ ύεϫʔυ͔ΒPMKΛPBKDF2Ͱੜ͢Δ ▸
PMK͔ΒPTKΛɺ·ͨPTK͔ΒMICΛٻΊΔ ▸ ͭ·Γ: ύεϫʔυ͔ΒMIC͕Ұҙʹܾ·Δ →ΦϑϥΠϯ߈ܸՄೳʂGPU༻Մೳʂ Image by massdistraction on flickr, CC-BY-NC-ND 2.0
TEXT EVIL TWIN ▸ ෆਖ਼ͳAPଓͤ͞Δ߈ܸ ▸ ߈ܸऀ͕APΛ༻ҙ SSID/BSSIDΛিಥͤͯ͞ଓΛୣऔ Image by
surfzone™ on flickr, CC-BY-NC-ND 2.0
TEXT TAKEAWAYS ▸ Β͘ΨλΨλͩͬͨ… ͕WPA3Ͱରࡦ͞Ε͖ͯͨ ▸ SAEͳ͔ͳ͔ͷΫηϞϊΒ͍͠ ▸ Evil twinରࡦʹҎԼΛ༗ޮʹ
▸ SAE-PK ▸ SAE-H2Eʢ˞Wi-Fi 7/6GHzͰඞਢʣ ▸ WPA3-Enterpriseͷ߹ରࡦࠔ →ଓใΛͯ Image by letmebeyourswearword on flickr, CC-BY 2.0
TEXT FRONT: CHAOTIC CHANNEL ▸ ޓੑͱ҆શੑͷؒͰ܁Γ͛ΒΕ͖ܹͯͨಆͷྺ࢙ →WPA3Ͱ͍ͩͿ҆શʹ ▸ ҉߸ܥͷແཧղ͕… →e.g.
WEP/WPA: RC4ͱͦͷ༻๏ →e.g. WPS (PIN): 7ܻͷͦͦ →e.g. WPA/WPA2: MIC͕࿙ΕΔͱյ໓త →e.g. WPA3: ECCͳͷʹͳͥ෮తʹ (DoS) ▸ ଓใΛͯͷ݅ →…·ͩͯɻ͍ͬͯͳ͍ɻ Image by Stephen Permezel on flickr, CC-NC 2.0
IN THE MIDDLE OF CHATTER BACK Image by Quinn Dombrowski
on flickr, CC-BY-SA 2.0
TEXT BACK: IN THE MIDDLE OF CHATTER ▸ LLMͷνϟοτΞϓϦ ʢChatGPT,
GPT-4o, Claude .. ʣ ▸ ͜ΕΒͷڍಈ…Ͳ͏ͳ͍ͬͯΔͷͩΖ͏͔ ▸ Claude iOS൛Λର ▸ …ओʹख๏Λѻͬͨճ Image by Quinn Dombrowski on flickr, CC-BY-SA 2.0
TEXT DEFEATING DRM ▸ App Store͕ʹ͋ͨΓ҉߸Խ+ॺ໊ ▸ ҉߸Խ͞Ε͍ͯΔͱવಡΊͳ͍ ▸ ҉߸ͷ͍ํʹ͞΄Ͳେ͖ͳͳ͍
→ਖ਼߈๏Ͱ͍͠ ▸ ࣮ʹղಡͤ͞Δͷ͕ྑ͍ɺ͕ ▸ ղಡπʔϧ͕App Storeʹ͋Δ…Θ͚ͳ͍ ▸ ղಡʹjailbreak͕ඞਢ Image by lantzilla on flickr, CC-BY-NC-ND 2.0
TEXT NOW UNLEASHED, WHERE TO GO? ▸ ରͷΞϓϦΛղಡ͍ͨ͠ ▸ frida-ios-dump
→ϝϞϦμϯϓ͠ΞϓϦΛ࠶ߏ →frida͕ඞཁ ▸ frida: dynamic instrumentation framework! ▸ frida-serverΛattach ▸ APIݺͼग़͠ͷI/OͳͲࡉ෦͔Β੍ޚՄೳʹ Image by Mr. Littlehand on flickr, CC-BY-ND 2.0
TEXT REVERSING ▸ Ghidra: Multi-arch disassembler (NSA) radare2: Binary analysis
framework (pancake et al.) ▸ ؆୯ͷͨΊʹghidraΛ༻ Image by Simon Rankin on flickr, CC-BY-NC-ND 2.0
TEXT REVERSING TAKEAWAYS ▸ ղੳ analyzeHeadless ~/works/claude/t claude -preScript analysisopts_ios.py
-import Payload/ Claude.app/Claude ▸ औΓग़͠ analyzeHeadless ~/works/claude/t claude -postScript out.py -process Claude -noanalysis → out.asm(※) ͕ੜ͞ΕΔͷͰrename ▸ ※out.asmout.py͕উखʹܾΊ͍ͯΔϑΝΠϧ໊ Image by Thomas_H_foto on flickr, CC-BY-ND 2.0
TEXT BACK: IN THE MIDDLE OF CHATTER ▸ iOSͷjailbreak ▸
όΠφϦͷൈ͖ग़͠ʙղੳ·Ͱ ▸ ࣌ؒͱσΟεΫྖҬ͕… ▸ ͯ͞ɺ͋ͱ࣮ࡍͷղੳͩɻޤ͏͝ظɻ Image by Malcolm Murdochon flickr, CC-BY-SA 2.0
AUGUST Image by Miguel Virkkunen Carvalho on flickr, CC-BY 2.0
TEXT AUGUST ▸ ෩ͷӨڹʹΑΔߥఱ༧Ͱதࢭ ▸ ݁ہߥఱʹͳΒͳ͔ͬͨ… Image by Lisa Zins
on flickr, CC-BY 2.0
OCTOBER
TEXT OCTOBER ▸ य़෦ࢢ։࠵ճ ▸ य़෦ࢢ;Ε͍͋Ωϡʔϒ 4F ձٞࣨ2 ▸ ϋΠϒϦου։࠵࠶։
▸ ࠂ͕͘ͳͬͨΓ࣮ͯ͠ࢀՃ͠ʹ͍͘ ▸ ॴ͕ԕ͍ͱ͍͏ࢦఠ ▸ ΑΓaccessibleʹ͓ͯ͜͠͏ͱ… Image by Janne Räkköläinen on flickr, CC-BY-SA 2.0
IN THE MIDDLE OF CHATTER 2 FRONT Image by Quinn
Dombrowski on flickr, CC-BY-SA 2.0
TEXT FRONT: IN THE MIDDLE OF CHATTER 2 ▸ લճͷଓ͖
▸ ࣮ࡍͷղੳͱ… Image by Quinn Dombrowski on flickr, CC-BY-SA 2.0
Image by John Perivolaris on flickr, CC-BY-NC-ND 2.0 TEXT ANATOMY
OF IOS APP ▸ iOSΞϓϦͷߏ ▸ Info.plist: ϝλใ (_CodeSignature: ॺ໊) ▸ assets.car: Ϧιʔεྨ ▸ Frameworks: ϥΠϒϥϦྨ˞ ▸ (ΞϓϦ໊): Mach-O࣮ߦϑΝΠϧ˞
Image by eliudrosales on flickr, CC-BY-NC 2.0 TEXT TS2-IOS: AUTOMATE
THE ANALYSIS ▸ iOSΞϓϦղੳΛߦͳ͏trueseeing extension ▸ 2.2.5ͰmainϚʔδͨ͠: ipa͕ղੳՄೳʹʂ ▸ API call, URL, dynamic code loading, syscall, re fl ection, jailbreak detection, debug probe, privacy concerns, obfuscations, assertions, logging, library imports, motion sensor, url scheme, ATS, permission, device requirements, device info probes, entitilements, copyright info, XOR ciphers, statically linked libraries ..
Image by Alan Levine on flickr, CC-BY 2.0 TEXT TS2-SWIFT-DEMANGLE
▸ ໊લ͕ͻͲ͍… ▸ swiftॲཧܥdemanglerΛAPIԽ →swiftॲཧܥͷىಈ͕͗͢ΔͨΊ… ▸ ts2ͱϦϯΫ͢Δ͚ͩ (--link ts2-swift-demangle)
Image by JamesInOregon on flickr, CC-BY 2.0 TEXT TS2-DISASM-GHIDRA ▸
ipa/apkΛ͢ͱghidraͰdisasm͢Δcontainer ▸ docker run --rm -v $(pwd):/out ts2-disasm- ghidra target.ipa → ͜Ε͚ͩͰdisasm.tar.gzΛੜ ▸ streamingੜ: σΟεΫʹ༏͍͠ ▸ ͨͩແ͔͔ۤ࣌ؒΔ
Image by Thomas_H_foto on flickr, CC-BY-ND 2.0 TEXT TAKEAWAYS ▸
iOSΞϓϦੳʹ͓͍ͯݟΔ͖Օॴ ▸ Info.plist: ϝλใ Frameworks: ϥΠϒϥϦྨ˞ (ΞϓϦ໊): Mach-O࣮ߦϑΝΠϧ˞ ▸ ObjC৭͕·ͩ·ͩڧ͍: call͕จࣈྻఆͰग़ݱ ▸ SwiftC++ʹ͍ۙҹ: demangling͕༗༻ ▸ ࠷৽։ൃಈͱϥΠϒϥϦͷ͕ࣝେࣄ
TEXT FRONT: IN THE MIDDLE OF CHATTER 2 ▸ disasm:
͔͔࣌ؒΔ͕ࣗಈԽͰ͖ͨ ▸ API call ղੳࣗମ͞΄Ͳ͘͠ͳ͍ →ͳͷjailbreak͔Βͷఠग़ ▸ Claudeʹ͞΄Ͳେ͖ͳͳ͔ͬͨ →͍͍ͩͨଥͳൣғ ▸ trueseeingͱghidraͷҖ →2.2.5ͰiOSਖ਼ࣜରԠ… ͨͤͨͳɻ Image by G Menon on flickr, CC-BY-NC-ND 2.0
JSONPͷةݥੑ·ͱΊ BACK
TEXT BACK: JSONPͷةݥੑ·ͱΊ ▸ jetbee͞ΜʹΑΔߨԋ ▸ ʮJSONPͰAPIΛఏڙ͢ΔͱԿ͕ةͳ͍ͷ͔ʁ Α͘Θ͔Βͳ͔ͬͨͷͰɺ·ͱΊͯΈ·ͨ͠ɻ WEBηΩϡϦςΟͷॳาతͳ༰Ͱ͢ɻʯ
None
TEXT BACK: JSONPͷةݥੑ·ͱΊ ▸ ॳาతͱ……ɹ࣮ྫΛަ࣮͑ͨફతͳ͓ ▸ JSONPաతͳٕज़ͳͷ͕ͩɺ·ͩΘΕͯ ͍Δέʔε͕͋Γ… ▸ Web։ൃʹ͓͚ΔҰͭͷਂͱͦͷҋͷڪාΛ
֞ؒݟͨճ →jetbee͞Μ: ͋Γ͕ͱ͏͍͟͝·ͨ͠
DECEMBER Image by JLS Photography - Alaska on flickr, CC-BY-NC-ND
2.0
TEXT DECEMBER ▸ ͍ͨ͞·ࢢ։࠵ճ: 6ϲ݄ͿΓ ▸ RaiBoC ूձࣨ2: ͜͜ʂ Image
by Nikos Koutoulas on flickr, CC-BY 2.0
TEXT TAKEAWAYS: REVIEWING 2024 ▸ Keep ▸ ϋΠϒϦου։࠵ɾࣸਅೖΓ։࠵ใࠂ ▸ Problem
▸ ࠂ͕ࡶ ▸ Try ▸ ͬͱଘࡏײΛग़ͤΔΑ͏ʹ͕ΜΔ ▸ ࣗ༝ͳݚڀ͕Ͱ͖Δڥҡ࣋ʹ͚͕ΜΔ Image by Michael Mueller on flickr, CC-BY 2.0
STAY TUNED! Image by KaCey97078 on flickr, CC-BY-NC 2.0
FIN. 10.12.2024 TAKAHIRO YOSHIMURA (@ALTERAKEY) Image by Geoff Henson on
flickr, CC-BY-ND 2.0