Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Staring into chaos
Search
Takahiro Yoshimura
June 28, 2022
Technology
0
11
Staring into chaos
Quick evaluation on security postures of iOS/Android app store. (OWASP Saitama MTG #8, talk #1)
Takahiro Yoshimura
June 28, 2022
Tweet
Share
More Decks by Takahiro Yoshimura
See All by Takahiro Yoshimura
Repeat After Me #1
alterakey
0
20
Slaying 2FA
alterakey
0
17
Ghost Warden
alterakey
0
19
Toxic Oversight
alterakey
0
18
Reviewing 2024
alterakey
0
23
In The Middle Of Chatter #2
alterakey
0
29
Chaotic Channel
alterakey
0
38
In The Middle Of Chatter #1
alterakey
0
40
Shadow Runners 2
alterakey
0
9
Other Decks in Technology
See All in Technology
Firestore → Spanner 移行 を成功させた段階的移行プロセス
athug
1
500
AIの最新技術&テーマをつまんで紹介&フリートークするシリーズ:はじめてのローカルLLM
stanaka26
0
100
「何となくテストする」を卒業するためにプロダクトが動く仕組みを理解しよう
kawabeaver
0
440
複数サービスを支えるマルチテナント型Batch MLプラットフォーム
lycorptech_jp
PRO
1
990
バイブスに「型」を!Kent Beckに学ぶ、AI時代のテスト駆動開発
amixedcolor
3
590
人工衛星のファームウェアをRustで書く理由
koba789
15
8.3k
職種の壁を溶かして開発サイクルを高速に回す~情報透明性と職種越境から考えるAIフレンドリーな職種間連携~
daitasu
0
200
COVESA VSSによる車両データモデルの標準化とAWS IoT FleetWiseの活用
osawa
1
400
AI時代を生き抜くエンジニアキャリアの築き方 (AI-Native 時代、エンジニアという道は 「最大の挑戦の場」となる) / Building an Engineering Career to Thrive in the Age of AI (In the AI-Native Era, the Path of Engineering Becomes the Ultimate Arena of Challenge)
jeongjaesoon
0
260
Claude Code でアプリ開発をオートパイロットにするためのTips集 Zennの場合 / Claude Code Tips in Zenn
wadayusuke
5
2.5k
Bedrock で検索エージェントを再現しようとした話
ny7760
2
140
AIがコード書きすぎ問題にはAIで立ち向かえ
jyoshise
1
700
Featured
See All Featured
Facilitating Awesome Meetings
lara
55
6.5k
GraphQLの誤解/rethinking-graphql
sonatard
72
11k
The Cult of Friendly URLs
andyhume
79
6.6k
Why You Should Never Use an ORM
jnunemaker
PRO
59
9.5k
Designing Experiences People Love
moore
142
24k
The MySQL Ecosystem @ GitHub 2015
samlambert
251
13k
We Have a Design System, Now What?
morganepeng
53
7.8k
It's Worth the Effort
3n
187
28k
Building Applications with DynamoDB
mza
96
6.6k
Into the Great Unknown - MozCon
thekraken
40
2k
Making Projects Easy
brettharned
117
6.4k
Keith and Marios Guide to Fast Websites
keithpitt
411
22k
Transcript
STARING INTO CHAOS OWASP SAITAMA MTG #8, TALK #1 Image
by ST1138 on flickr, CC-BY-NC-ND 2.0
TEXT SESSION FLAGS ▸ ըɾԻɾެ։: OK Image by Nico Kaiser
on flickr, CC-BY 2.0
TEXT WHO I AM ▸ Takahiro Yoshimura (@alterakey) https://keybase.io/alterakey ▸
Monolith Works Inc. Co-founder, CTO Security researcher ▸ ໌࣏େֶαΠόʔηΩϡϦςΟݚڀॴ ٬һݚڀһ
TEXT WHAT I DO ▸ Security research and development ▸
iOS/Android Apps →Financial, Games, IoT related, etc. (>200) →trueseeing: Non-decompiling Android Application Vulnerability Scanner [2017] ▸ Windows/Mac/Web/HTML5 Apps →POS, RAD tools etc. ▸ Network/Web penetration testing →PCI-DSS etc. ▸ Search engine reconnaissance (aka. Google Hacking) ▸ Whitebox testing ▸ Forensic analysis
TEXT WHAT I DO ▸ CTF ▸ Enemy10, Sutegoma2 ▸
METI CTFCJ 2012 Qual.: Won ▸ METI CTFCJ 2012: 3rd ▸ DEF CON 21 CTF: 6th ▸ DEF CON 22 OpenCTF: 4th ▸ ൃදɾߨԋͳͲ DEF CON 25 Demo Labs (2017) DEF CON 27 AI Village (2019) CODE BLUE (2017, 2019) CYDEF (2020) etc. Image by Wiyre Media on flickr, CC-BY 2.0
TEXT BACKGROUND ▸ ΞϓϦͷڍಈʹ͍ͭͯશͯѲ͍ͯ͠·͔͢ʁ ▸ ඞͣ͠ਧௌ͍ͯ͠Δ௨ΓͰ͋Δඞཁͳ͍ →ॻ͖खͷࣗ༝ ▸ ͰϢʔβ͔ΒࠔΔ… Image
by Sam Azgor on flickr, CC-BY 2.0
TEXT ANDROID: STATIC ANALYSIS + DEATH TRAP ▸ ެ։࣌ʹࣗಈղੳΛࢪ͠ѱҙͷͳ͍͜ͱΛ֬ೝ ▸
Ϣʔβ͔Βͷใࠂ͋Δ͍ൈ͖ଧͪݕࠪͰ ΞΧϯτBANॲஔ → σετϥοϓ ▸ ܯࠂ΄΅͠ͳ͍ ▸ ΄΅ฉ͔ͳ͍ (HNͳͲʹࢮࢡྦྷʑ) ▸ نఆͷվఆʹԠ͢Δ·Ͱެ։ఀࢭॲஔ ▸ େখΘͣͨͩͷҰϢʔβͰ͔͠ͳ͍ Image by Daniel Arrhakis - Visual Arts on flickr, CC-BY-NC 2.0
TEXT IOS: MANUAL REVIEW ▸ ެ։࣌ʹਓ͕ؒΞϓϦΛ֬ೝ ▸ UIنఆҧͳͲ; ʮUIنఆʯͱ͍͍࣮࣭ͭͭతͳશମن ▸
ҧͨ͠߹reject ▸ ԟʑʹͯ͠ԇᅀͷࠜݯ ▸ ͋ΔఔॊೈʹରԠͯ͘͠ΕΔ Image by Giåm on flickr, CC-BY-SA 2.0
TEXT MANUAL REVIEWING IS SAFER..? ▸ iOSͷ߹Appleͷελοϑ͕ΞϓϦΛ֬ೝͯ͠ ͍ΔͷͰมͳΞϓϦೖͬͯ͜ͳ͍ʢͷͰ AndroidͳΜ͔ΑΓ҆શʣͱ͍͏Ұൠೝࣝ ▸
ຊʹʁ Image by Glen Bledsoe on flickr, CC-BY 2.0
TEXT A. REMOTE FLAGS TO CONTROL BEHAVIOR ▸ ࿈ܞ͢ΔAPIαʔόʹ͓͍ͯηʔϑͳ༰Λ͢ ͜ͱͰ৹ࠪΛΓൈ͚Δख๏
▸ ໌Β͔ͳςετڥͩͱreject͞ΕΔ →ͦΕͳΓʹ͓͑ͯ͘ඞཁ͕͋Δ ▸ ΘΓͱྑ͘ݟ͔͚Δ ▸ ৹ࠪ༻ڥ/εςʔδϯάڥ etc. Image by Vinicius | www.viniciuscvenancio.com.br on flickr, CC-BY-NC-ND 2.0
TEXT CASE #0 ▸ ອըΞϓϦ ▸ ອըѪ͞Ε͍ͯΔ͕จԽతʹ᫁Λྑ͘ੜΉ
TEXT CASE #0 ▸ ੩తղੳ * Extract: checkra1n + frida-ios-dump
* Analysis: Ghidra 10 ▸ APIαʔόΛܦ༝͢Δࣔࠦ ▸ ༨ஊ: DFUϞʔυʹೖΕΔ࣌ʹେมͳۤ࿑ →macOS͔Βͷׯব͕ଟݪҼ →checkra1n 0.12.4M1Ͱಈ࡞͠ͳ͍
TEXT CASE #0 ▸ τϥϑΟοΫղੳ * Aggregation: StrongSwan 5.8 +
iptables * Analysis: Burp Suite (transparent proxy) ※transparent proxy mode͕Ͱ͖ΕZAP/ mitmproxyͳͲͰͳ͘Ͱ͖Δ ▸ APIαʔόͷԠͰίϯτϩʔϧ͞ΕΔ؍ଌ
TEXT CASE #0 ▸ APIαʔόʹڍಈΛ੍ޚ͞Ε͍ͯΔ →ʢݴ͍ํѱ͍͕ʣӅṭՄೳ ▸ ͨΓલͱݴΘΕΕͦ͏͕ͩ… ▸ ৹ࠪظؒதʹมͳͷΛग़͢ॴҎͳ͍ͣ
TEXT CASE #1: ಠΞϓϦ ▸ Ұݟແͳɺࠂ͖ΞϓϦ ▸ ͦͦ4+
TEXT CASE #1: ಠΞϓϦ ▸ ͕… ࠂͷ༰͕… ▸ ։ൃݩ͕ࠂιʔεઃఆΛม͑ͨՄೳੑ →ཧ༝͕ͳΜͰ͋Εෆద
→ࠂ͕ݪҼͰreject͞ΕΔ͜ͱ͕વ͋Δ ▸ ࢠڙ༻ͷApple IDͰ͋Εࠂ༰ن੍͞Ε Δ͕ͣͩ… ࠅ͍ࠂओ͕ᬚ͍ͯ͠Δ
TEXT CASE #2: ਓ͚ίϯςϯπ ▸ ͍ΘΏΔແमਖ਼ίϯςϯπΛ৴͍ͯ͠Δʁ →͜Ε͓͔͍͠ ▸ ͦͦ: iOS͜͏͍͏ͷΛڐ͍ͯ͠ͳ͍
→δϣϒε࣌ΫοΫ࣌Ұ؏͍ͯ͠Δ ▸ ৹ࠪ࣌ʹӅṭͨ͠ͱߟ͑Δͷ͕ଥͰͳ͍͔
TEXT CASE #3: SNS ▸ ͔ͭͯΑΓWebίϯςϯπΛࣗ༝ʹදࣔͰ͖Δ ͷ17+ͱ͍͏ن੍͕͋Δ ▸ SNSྨʹ͓͍ͯϝοηʔδͰࢦࣔ͞ΕͨURL͕ ։͚Δ→͜ͷϧʔϧ͕ద༻ʹͳΔͷͰͳ͍
͔ʁ Image by 5kul1k flickr, CC-BY 2.0
TEXT CASE #3: SNS ▸ େ෦͕12+Ͱྲྀ௨; ࣌ྲྀʁ ▸ LINE: 12+
▸ Snapchat/Facebook/Instagram: 12+ ▸ TikTok: 12+ ▸ Twitter: 17+ (←ͳͥʁ) ▸ Telegram: 17+ (←ͳͥʁʁ)
TEXT CASE #3: SNS ▸ Kakao Talk: 4+ʁʁʁ ▸ ઌྫʹͳΒ͑12+͕ଥͰͳ͍ͷ͔
▸ ॳػೳ͋Δ͍ن੍͕গͳ͔ͬͨ࣌ظʹ4+ ͰऔΓɺͦΕ͔Βͳ่͠͠తʹདྷͨՄೳੑʁ ʢi.e. มߋਃࠂ͍ͯ͠ͳ͍ʁʣ
TEXT B. REVIEWERS MATTER ▸ ϨϏϡΞʔʮΨνϟʯΛ௨Δ·Ͱճͯ͠Γൈ͚ Δํ๏ ▸ App IDΛม͑ͯΓൈ͚ͨྫ͋Δ
▸ ϨϏϡʔࣗମٕͦͦज़తʹ ▸ େྔͷΞϓϦΛࡹ͔ͳ͍͚ͯ͘ͳ͍ ▸ ຊ֨తͳղੳΛߦͳ͏ʹ͕͔͔࣌ؒΔ ▸ ࣌ؒʹΘΕͳ͕Βେͷ࣭Λݟ͍ͯΔͱ ͢Δͷ͕ଥ Image by kleuske on flickr, CC-BY-SA 2.0
None
None
None
TEXT C. EXPEDITED REVIEW REQUESTED ▸ ಛٸϨϏϡʔΛཁٻ͠ѹྗΛֻ͚Δख๏ ▸ Ҏલ৽نΞϓϦʹ༻Ͱ͖ͳ͔ͬͨ ▸
Ӆ͠ػೳѱҙͷ͋ΔίʔυΛݟ͵͚Δ͔ʁ →࣮֬ͳݕෆೳͱԾఆ͢Δͷ͕ଥ ▸ ৽نΞϓϦͰ͋ΕؾΛ͚ͭΔͩΖ͏͕ɺ ҰΫϩʔϦϯάͨ͠ΞϓϦͰ͋ͬͨΒ… Image by foshydog on flickr, CC-BY-NC-ND 2.0
TEXT CONCLUSION ▸ ਓྗϨϏϡʔࣗಈղੳ+σετϥοϓΑΓ༗ޮͱ ܾͯ͠ݴ͑ͳ͍ ▸ iOSਓ͕ؒݟ͍ͯΔ͔Β҆શͱ͍͏େऺ৴ڼʹ શࠜ͘ڌ͕ͳ͍; Ή͠Ζةݥ (i.e.
false sense of …) ▸ ͨͩͷҰͷঢ়ଶΛݕূ͍ͯ͠Δ͚ͩ →Androidํࣜʹࢍ൱྆͋Δ͕༏ल ▸ ਓؒʹਓؒͷϛε; རͱͯ͠ײੑͷΈ →ݟམ͠ɺ৺ཧঢ়ଶͳͲ Image by chaim zvi on flickr, CC-BY-ND 2.0
TEXT CONCLUSION ▸ Stay safe! Image by ▓▒░ TORLEY ░▒▓
on flickr, CC-BY-SA 2.0
Q?
ONE MORE THING.. Image by mac-ash on flickr, CC-BY-NC-ND 2.0
TEXT TIKTOK .. ▸ TikTok…͋Ε͔ΒͲ͏ͳͬͨͷ͔ ▸ iOS.. Pasteboardؔ࿈notif.Ͳ͏ͳͬͨͷ͔… ▸ Noti
fi cationݟͳ͘ͳͬͨ
TEXT TIKTOK .. ▸ ݟͳ͘ͳͬͨཁҼ: iOS 14ʹ͓͍ͯܗࣜಛఆ༻API͕Ճ͞ΕͨͨΊ ▸ iOS 15:
Secure Pasteboard; ΞΫςΟϒͳΞϓϦҎ֎ ͔ΒPasteboardΛಡΊͳ͍Α͏ʹվળˠAndroidͰ લ͔Βۭ͋ͬͨ࣌తޚػߏ ※iOS 14Ͱಋೖ͞ΕͨΑ͏ͳ௨͕Android 12Ͱ Ճ͞Ε͍ͯΔ… ྲྀΕతʹෆཁͳ͕ͣͩʁ ▸ TikTok: ΓํΛม͍͑ͯΔՄೳੑ →ͳΜΒ͔ͷճආํࡦʁݕূ͕ඞཁ
FIN. 28.6.2022 TAKAHIRO YOSHIMURA (@ALTERAKEY)