Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Staring into chaos
Search
Takahiro Yoshimura
June 28, 2022
Technology
0
11
Staring into chaos
Quick evaluation on security postures of iOS/Android app store. (OWASP Saitama MTG #8, talk #1)
Takahiro Yoshimura
June 28, 2022
Tweet
Share
More Decks by Takahiro Yoshimura
See All by Takahiro Yoshimura
Reviewing 2025
alterakey
0
14
Repeat After Me #2
alterakey
0
36
Repeat After Me #1
alterakey
0
34
Slaying 2FA
alterakey
0
20
Ghost Warden
alterakey
0
20
Toxic Oversight
alterakey
0
24
Reviewing 2024
alterakey
0
24
In The Middle Of Chatter #2
alterakey
0
36
Chaotic Channel
alterakey
0
41
Other Decks in Technology
See All in Technology
ClickHouseはどのように大規模データを活用したAIエージェントを全社展開しているのか
mikimatsumoto
0
240
プロポーザルに込める段取り八分
shoheimitani
1
280
Frontier Agents (Kiro autonomous agent / AWS Security Agent / AWS DevOps Agent) の紹介
msysh
3
170
ブロックテーマでサイトをリニューアルした話 / 2026-01-31 Kansai WordPress Meetup
torounit
0
470
~Everything as Codeを諦めない~ 後からCDK
mu7889yoon
3
390
Azure Durable Functions で作った NL2SQL Agent の精度向上に取り組んだ話/jat08
thara0402
0
190
Oracle Cloud Observability and Management Platform - OCI 運用監視サービス概要 -
oracle4engineer
PRO
2
14k
Claude_CodeでSEOを最適化する_AI_Ops_Community_Vol.2__マーケティングx_AIはここまで進化した.pdf
riku_423
2
570
usermode linux without MMU - fosdem2026 kernel devroom
thehajime
0
230
量子クラウドサービスの裏側 〜Deep Dive into OQTOPUS〜
oqtopus
0
120
クレジットカード決済基盤を支えるSRE - 厳格な監査とSRE運用の両立 (SRE Kaigi 2026)
capytan
6
2.8k
プロダクト成長を支える開発基盤とスケールに伴う課題
yuu26
4
1.3k
Featured
See All Featured
How to make the Groovebox
asonas
2
1.9k
Rebuilding a faster, lazier Slack
samanthasiow
85
9.4k
The #1 spot is gone: here's how to win anyway
tamaranovitovic
2
940
Heart Work Chapter 1 - Part 1
lfama
PRO
5
35k
Designing for humans not robots
tammielis
254
26k
Joys of Absence: A Defence of Solitary Play
codingconduct
1
290
Java REST API Framework Comparison - PWX 2021
mraible
34
9.1k
How To Speak Unicorn (iThemes Webinar)
marktimemedia
1
380
The innovator’s Mindset - Leading Through an Era of Exponential Change - McGill University 2025
jdejongh
PRO
1
93
Game over? The fight for quality and originality in the time of robots
wayneb77
1
120
Gemini Prompt Engineering: Practical Techniques for Tangible AI Outcomes
mfonobong
2
280
Ten Tips & Tricks for a 🌱 transition
stuffmc
0
69
Transcript
STARING INTO CHAOS OWASP SAITAMA MTG #8, TALK #1 Image
by ST1138 on flickr, CC-BY-NC-ND 2.0
TEXT SESSION FLAGS ▸ ըɾԻɾެ։: OK Image by Nico Kaiser
on flickr, CC-BY 2.0
TEXT WHO I AM ▸ Takahiro Yoshimura (@alterakey) https://keybase.io/alterakey ▸
Monolith Works Inc. Co-founder, CTO Security researcher ▸ ໌࣏େֶαΠόʔηΩϡϦςΟݚڀॴ ٬һݚڀһ
TEXT WHAT I DO ▸ Security research and development ▸
iOS/Android Apps →Financial, Games, IoT related, etc. (>200) →trueseeing: Non-decompiling Android Application Vulnerability Scanner [2017] ▸ Windows/Mac/Web/HTML5 Apps →POS, RAD tools etc. ▸ Network/Web penetration testing →PCI-DSS etc. ▸ Search engine reconnaissance (aka. Google Hacking) ▸ Whitebox testing ▸ Forensic analysis
TEXT WHAT I DO ▸ CTF ▸ Enemy10, Sutegoma2 ▸
METI CTFCJ 2012 Qual.: Won ▸ METI CTFCJ 2012: 3rd ▸ DEF CON 21 CTF: 6th ▸ DEF CON 22 OpenCTF: 4th ▸ ൃදɾߨԋͳͲ DEF CON 25 Demo Labs (2017) DEF CON 27 AI Village (2019) CODE BLUE (2017, 2019) CYDEF (2020) etc. Image by Wiyre Media on flickr, CC-BY 2.0
TEXT BACKGROUND ▸ ΞϓϦͷڍಈʹ͍ͭͯશͯѲ͍ͯ͠·͔͢ʁ ▸ ඞͣ͠ਧௌ͍ͯ͠Δ௨ΓͰ͋Δඞཁͳ͍ →ॻ͖खͷࣗ༝ ▸ ͰϢʔβ͔ΒࠔΔ… Image
by Sam Azgor on flickr, CC-BY 2.0
TEXT ANDROID: STATIC ANALYSIS + DEATH TRAP ▸ ެ։࣌ʹࣗಈղੳΛࢪ͠ѱҙͷͳ͍͜ͱΛ֬ೝ ▸
Ϣʔβ͔Βͷใࠂ͋Δ͍ൈ͖ଧͪݕࠪͰ ΞΧϯτBANॲஔ → σετϥοϓ ▸ ܯࠂ΄΅͠ͳ͍ ▸ ΄΅ฉ͔ͳ͍ (HNͳͲʹࢮࢡྦྷʑ) ▸ نఆͷվఆʹԠ͢Δ·Ͱެ։ఀࢭॲஔ ▸ େখΘͣͨͩͷҰϢʔβͰ͔͠ͳ͍ Image by Daniel Arrhakis - Visual Arts on flickr, CC-BY-NC 2.0
TEXT IOS: MANUAL REVIEW ▸ ެ։࣌ʹਓ͕ؒΞϓϦΛ֬ೝ ▸ UIنఆҧͳͲ; ʮUIنఆʯͱ͍͍࣮࣭ͭͭతͳશମن ▸
ҧͨ͠߹reject ▸ ԟʑʹͯ͠ԇᅀͷࠜݯ ▸ ͋ΔఔॊೈʹରԠͯ͘͠ΕΔ Image by Giåm on flickr, CC-BY-SA 2.0
TEXT MANUAL REVIEWING IS SAFER..? ▸ iOSͷ߹Appleͷελοϑ͕ΞϓϦΛ֬ೝͯ͠ ͍ΔͷͰมͳΞϓϦೖͬͯ͜ͳ͍ʢͷͰ AndroidͳΜ͔ΑΓ҆શʣͱ͍͏Ұൠೝࣝ ▸
ຊʹʁ Image by Glen Bledsoe on flickr, CC-BY 2.0
TEXT A. REMOTE FLAGS TO CONTROL BEHAVIOR ▸ ࿈ܞ͢ΔAPIαʔόʹ͓͍ͯηʔϑͳ༰Λ͢ ͜ͱͰ৹ࠪΛΓൈ͚Δख๏
▸ ໌Β͔ͳςετڥͩͱreject͞ΕΔ →ͦΕͳΓʹ͓͑ͯ͘ඞཁ͕͋Δ ▸ ΘΓͱྑ͘ݟ͔͚Δ ▸ ৹ࠪ༻ڥ/εςʔδϯάڥ etc. Image by Vinicius | www.viniciuscvenancio.com.br on flickr, CC-BY-NC-ND 2.0
TEXT CASE #0 ▸ ອըΞϓϦ ▸ ອըѪ͞Ε͍ͯΔ͕จԽతʹ᫁Λྑ͘ੜΉ
TEXT CASE #0 ▸ ੩తղੳ * Extract: checkra1n + frida-ios-dump
* Analysis: Ghidra 10 ▸ APIαʔόΛܦ༝͢Δࣔࠦ ▸ ༨ஊ: DFUϞʔυʹೖΕΔ࣌ʹେมͳۤ࿑ →macOS͔Βͷׯব͕ଟݪҼ →checkra1n 0.12.4M1Ͱಈ࡞͠ͳ͍
TEXT CASE #0 ▸ τϥϑΟοΫղੳ * Aggregation: StrongSwan 5.8 +
iptables * Analysis: Burp Suite (transparent proxy) ※transparent proxy mode͕Ͱ͖ΕZAP/ mitmproxyͳͲͰͳ͘Ͱ͖Δ ▸ APIαʔόͷԠͰίϯτϩʔϧ͞ΕΔ؍ଌ
TEXT CASE #0 ▸ APIαʔόʹڍಈΛ੍ޚ͞Ε͍ͯΔ →ʢݴ͍ํѱ͍͕ʣӅṭՄೳ ▸ ͨΓલͱݴΘΕΕͦ͏͕ͩ… ▸ ৹ࠪظؒதʹมͳͷΛग़͢ॴҎͳ͍ͣ
TEXT CASE #1: ಠΞϓϦ ▸ Ұݟແͳɺࠂ͖ΞϓϦ ▸ ͦͦ4+
TEXT CASE #1: ಠΞϓϦ ▸ ͕… ࠂͷ༰͕… ▸ ։ൃݩ͕ࠂιʔεઃఆΛม͑ͨՄೳੑ →ཧ༝͕ͳΜͰ͋Εෆద
→ࠂ͕ݪҼͰreject͞ΕΔ͜ͱ͕વ͋Δ ▸ ࢠڙ༻ͷApple IDͰ͋Εࠂ༰ن੍͞Ε Δ͕ͣͩ… ࠅ͍ࠂओ͕ᬚ͍ͯ͠Δ
TEXT CASE #2: ਓ͚ίϯςϯπ ▸ ͍ΘΏΔແमਖ਼ίϯςϯπΛ৴͍ͯ͠Δʁ →͜Ε͓͔͍͠ ▸ ͦͦ: iOS͜͏͍͏ͷΛڐ͍ͯ͠ͳ͍
→δϣϒε࣌ΫοΫ࣌Ұ؏͍ͯ͠Δ ▸ ৹ࠪ࣌ʹӅṭͨ͠ͱߟ͑Δͷ͕ଥͰͳ͍͔
TEXT CASE #3: SNS ▸ ͔ͭͯΑΓWebίϯςϯπΛࣗ༝ʹදࣔͰ͖Δ ͷ17+ͱ͍͏ن੍͕͋Δ ▸ SNSྨʹ͓͍ͯϝοηʔδͰࢦࣔ͞ΕͨURL͕ ։͚Δ→͜ͷϧʔϧ͕ద༻ʹͳΔͷͰͳ͍
͔ʁ Image by 5kul1k flickr, CC-BY 2.0
TEXT CASE #3: SNS ▸ େ෦͕12+Ͱྲྀ௨; ࣌ྲྀʁ ▸ LINE: 12+
▸ Snapchat/Facebook/Instagram: 12+ ▸ TikTok: 12+ ▸ Twitter: 17+ (←ͳͥʁ) ▸ Telegram: 17+ (←ͳͥʁʁ)
TEXT CASE #3: SNS ▸ Kakao Talk: 4+ʁʁʁ ▸ ઌྫʹͳΒ͑12+͕ଥͰͳ͍ͷ͔
▸ ॳػೳ͋Δ͍ن੍͕গͳ͔ͬͨ࣌ظʹ4+ ͰऔΓɺͦΕ͔Βͳ่͠͠తʹདྷͨՄೳੑʁ ʢi.e. มߋਃࠂ͍ͯ͠ͳ͍ʁʣ
TEXT B. REVIEWERS MATTER ▸ ϨϏϡΞʔʮΨνϟʯΛ௨Δ·Ͱճͯ͠Γൈ͚ Δํ๏ ▸ App IDΛม͑ͯΓൈ͚ͨྫ͋Δ
▸ ϨϏϡʔࣗମٕͦͦज़తʹ ▸ େྔͷΞϓϦΛࡹ͔ͳ͍͚ͯ͘ͳ͍ ▸ ຊ֨తͳղੳΛߦͳ͏ʹ͕͔͔࣌ؒΔ ▸ ࣌ؒʹΘΕͳ͕Βେͷ࣭Λݟ͍ͯΔͱ ͢Δͷ͕ଥ Image by kleuske on flickr, CC-BY-SA 2.0
None
None
None
TEXT C. EXPEDITED REVIEW REQUESTED ▸ ಛٸϨϏϡʔΛཁٻ͠ѹྗΛֻ͚Δख๏ ▸ Ҏલ৽نΞϓϦʹ༻Ͱ͖ͳ͔ͬͨ ▸
Ӆ͠ػೳѱҙͷ͋ΔίʔυΛݟ͵͚Δ͔ʁ →࣮֬ͳݕෆೳͱԾఆ͢Δͷ͕ଥ ▸ ৽نΞϓϦͰ͋ΕؾΛ͚ͭΔͩΖ͏͕ɺ ҰΫϩʔϦϯάͨ͠ΞϓϦͰ͋ͬͨΒ… Image by foshydog on flickr, CC-BY-NC-ND 2.0
TEXT CONCLUSION ▸ ਓྗϨϏϡʔࣗಈղੳ+σετϥοϓΑΓ༗ޮͱ ܾͯ͠ݴ͑ͳ͍ ▸ iOSਓ͕ؒݟ͍ͯΔ͔Β҆શͱ͍͏େऺ৴ڼʹ શࠜ͘ڌ͕ͳ͍; Ή͠Ζةݥ (i.e.
false sense of …) ▸ ͨͩͷҰͷঢ়ଶΛݕূ͍ͯ͠Δ͚ͩ →Androidํࣜʹࢍ൱྆͋Δ͕༏ल ▸ ਓؒʹਓؒͷϛε; རͱͯ͠ײੑͷΈ →ݟམ͠ɺ৺ཧঢ়ଶͳͲ Image by chaim zvi on flickr, CC-BY-ND 2.0
TEXT CONCLUSION ▸ Stay safe! Image by ▓▒░ TORLEY ░▒▓
on flickr, CC-BY-SA 2.0
Q?
ONE MORE THING.. Image by mac-ash on flickr, CC-BY-NC-ND 2.0
TEXT TIKTOK .. ▸ TikTok…͋Ε͔ΒͲ͏ͳͬͨͷ͔ ▸ iOS.. Pasteboardؔ࿈notif.Ͳ͏ͳͬͨͷ͔… ▸ Noti
fi cationݟͳ͘ͳͬͨ
TEXT TIKTOK .. ▸ ݟͳ͘ͳͬͨཁҼ: iOS 14ʹ͓͍ͯܗࣜಛఆ༻API͕Ճ͞ΕͨͨΊ ▸ iOS 15:
Secure Pasteboard; ΞΫςΟϒͳΞϓϦҎ֎ ͔ΒPasteboardΛಡΊͳ͍Α͏ʹվળˠAndroidͰ લ͔Βۭ͋ͬͨ࣌తޚػߏ ※iOS 14Ͱಋೖ͞ΕͨΑ͏ͳ௨͕Android 12Ͱ Ճ͞Ε͍ͯΔ… ྲྀΕతʹෆཁͳ͕ͣͩʁ ▸ TikTok: ΓํΛม͍͑ͯΔՄೳੑ →ͳΜΒ͔ͷճආํࡦʁݕূ͕ඞཁ
FIN. 28.6.2022 TAKAHIRO YOSHIMURA (@ALTERAKEY)