Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Staring into chaos
Search
Takahiro Yoshimura
June 28, 2022
Technology
0
10
Staring into chaos
Quick evaluation on security postures of iOS/Android app store. (OWASP Saitama MTG #8, talk #1)
Takahiro Yoshimura
June 28, 2022
Tweet
Share
More Decks by Takahiro Yoshimura
See All by Takahiro Yoshimura
Ghost Warden
alterakey
0
13
Toxic Oversight
alterakey
0
17
Reviewing 2024
alterakey
0
22
In The Middle Of Chatter #2
alterakey
0
27
Chaotic Channel
alterakey
0
36
In The Middle Of Chatter #1
alterakey
0
38
Shadow Runners 2
alterakey
0
8
Shadow Runners
alterakey
0
7
Looking Back: 2023
alterakey
0
10
Other Decks in Technology
See All in Technology
TLSから見るSREの未来
atpons
2
200
成長し続けるアプリのためのテストと設計の関係、そして意思決定の記録。
sansantech
PRO
0
140
60以上のプロダクトを持つ組織における開発者体験向上への取り組み - チームAPIとBackstageで構築する組織の可視化基盤 - / sre next 2025 Efforts to Improve Developer Experience in an Organization with Over 60 Products
vtryo
2
650
CDK Toolkit Libraryにおけるテストの考え方
smt7174
1
400
敢えて生成AIを使わないマネジメント業務
kzkmaeda
2
500
Copilot coding agentにベットしたいCTOが開発組織で取り組んだこと / GitHub Copilot coding agent in Team
tnir
0
140
CDK Vibe Coding Fes
tomoki10
1
480
衛星運用をソフトウェアエンジニアに依頼したときにできあがるもの
sankichi92
1
220
SRE不在の開発チームが障害対応と 向き合った100日間 / 100 days dealing with issues without SREs
shin1988
1
1.3k
ABEMAの本番環境負荷試験への挑戦
mk2taiga
5
720
shake-upを科学する
rsakata
7
910
CDKTFについてざっくり理解する!!~CloudFormationからCDKTFへ変換するツールも作ってみた~
masakiokuda
1
190
Featured
See All Featured
It's Worth the Effort
3n
185
28k
BBQ
matthewcrist
89
9.7k
Faster Mobile Websites
deanohume
307
31k
No one is an island. Learnings from fostering a developers community.
thoeni
21
3.4k
Navigating Team Friction
lara
187
15k
How to Create Impact in a Changing Tech Landscape [PerfNow 2023]
tammyeverts
53
2.9k
Done Done
chrislema
184
16k
Unsuck your backbone
ammeep
671
58k
Producing Creativity
orderedlist
PRO
346
40k
Become a Pro
speakerdeck
PRO
29
5.4k
The Pragmatic Product Professional
lauravandoore
35
6.7k
Building Better People: How to give real-time feedback that sticks.
wjessup
367
19k
Transcript
STARING INTO CHAOS OWASP SAITAMA MTG #8, TALK #1 Image
by ST1138 on flickr, CC-BY-NC-ND 2.0
TEXT SESSION FLAGS ▸ ըɾԻɾެ։: OK Image by Nico Kaiser
on flickr, CC-BY 2.0
TEXT WHO I AM ▸ Takahiro Yoshimura (@alterakey) https://keybase.io/alterakey ▸
Monolith Works Inc. Co-founder, CTO Security researcher ▸ ໌࣏େֶαΠόʔηΩϡϦςΟݚڀॴ ٬һݚڀһ
TEXT WHAT I DO ▸ Security research and development ▸
iOS/Android Apps →Financial, Games, IoT related, etc. (>200) →trueseeing: Non-decompiling Android Application Vulnerability Scanner [2017] ▸ Windows/Mac/Web/HTML5 Apps →POS, RAD tools etc. ▸ Network/Web penetration testing →PCI-DSS etc. ▸ Search engine reconnaissance (aka. Google Hacking) ▸ Whitebox testing ▸ Forensic analysis
TEXT WHAT I DO ▸ CTF ▸ Enemy10, Sutegoma2 ▸
METI CTFCJ 2012 Qual.: Won ▸ METI CTFCJ 2012: 3rd ▸ DEF CON 21 CTF: 6th ▸ DEF CON 22 OpenCTF: 4th ▸ ൃදɾߨԋͳͲ DEF CON 25 Demo Labs (2017) DEF CON 27 AI Village (2019) CODE BLUE (2017, 2019) CYDEF (2020) etc. Image by Wiyre Media on flickr, CC-BY 2.0
TEXT BACKGROUND ▸ ΞϓϦͷڍಈʹ͍ͭͯશͯѲ͍ͯ͠·͔͢ʁ ▸ ඞͣ͠ਧௌ͍ͯ͠Δ௨ΓͰ͋Δඞཁͳ͍ →ॻ͖खͷࣗ༝ ▸ ͰϢʔβ͔ΒࠔΔ… Image
by Sam Azgor on flickr, CC-BY 2.0
TEXT ANDROID: STATIC ANALYSIS + DEATH TRAP ▸ ެ։࣌ʹࣗಈղੳΛࢪ͠ѱҙͷͳ͍͜ͱΛ֬ೝ ▸
Ϣʔβ͔Βͷใࠂ͋Δ͍ൈ͖ଧͪݕࠪͰ ΞΧϯτBANॲஔ → σετϥοϓ ▸ ܯࠂ΄΅͠ͳ͍ ▸ ΄΅ฉ͔ͳ͍ (HNͳͲʹࢮࢡྦྷʑ) ▸ نఆͷվఆʹԠ͢Δ·Ͱެ։ఀࢭॲஔ ▸ େখΘͣͨͩͷҰϢʔβͰ͔͠ͳ͍ Image by Daniel Arrhakis - Visual Arts on flickr, CC-BY-NC 2.0
TEXT IOS: MANUAL REVIEW ▸ ެ։࣌ʹਓ͕ؒΞϓϦΛ֬ೝ ▸ UIنఆҧͳͲ; ʮUIنఆʯͱ͍͍࣮࣭ͭͭతͳશମن ▸
ҧͨ͠߹reject ▸ ԟʑʹͯ͠ԇᅀͷࠜݯ ▸ ͋ΔఔॊೈʹରԠͯ͘͠ΕΔ Image by Giåm on flickr, CC-BY-SA 2.0
TEXT MANUAL REVIEWING IS SAFER..? ▸ iOSͷ߹Appleͷελοϑ͕ΞϓϦΛ֬ೝͯ͠ ͍ΔͷͰมͳΞϓϦೖͬͯ͜ͳ͍ʢͷͰ AndroidͳΜ͔ΑΓ҆શʣͱ͍͏Ұൠೝࣝ ▸
ຊʹʁ Image by Glen Bledsoe on flickr, CC-BY 2.0
TEXT A. REMOTE FLAGS TO CONTROL BEHAVIOR ▸ ࿈ܞ͢ΔAPIαʔόʹ͓͍ͯηʔϑͳ༰Λ͢ ͜ͱͰ৹ࠪΛΓൈ͚Δख๏
▸ ໌Β͔ͳςετڥͩͱreject͞ΕΔ →ͦΕͳΓʹ͓͑ͯ͘ඞཁ͕͋Δ ▸ ΘΓͱྑ͘ݟ͔͚Δ ▸ ৹ࠪ༻ڥ/εςʔδϯάڥ etc. Image by Vinicius | www.viniciuscvenancio.com.br on flickr, CC-BY-NC-ND 2.0
TEXT CASE #0 ▸ ອըΞϓϦ ▸ ອըѪ͞Ε͍ͯΔ͕จԽతʹ᫁Λྑ͘ੜΉ
TEXT CASE #0 ▸ ੩తղੳ * Extract: checkra1n + frida-ios-dump
* Analysis: Ghidra 10 ▸ APIαʔόΛܦ༝͢Δࣔࠦ ▸ ༨ஊ: DFUϞʔυʹೖΕΔ࣌ʹେมͳۤ࿑ →macOS͔Βͷׯব͕ଟݪҼ →checkra1n 0.12.4M1Ͱಈ࡞͠ͳ͍
TEXT CASE #0 ▸ τϥϑΟοΫղੳ * Aggregation: StrongSwan 5.8 +
iptables * Analysis: Burp Suite (transparent proxy) ※transparent proxy mode͕Ͱ͖ΕZAP/ mitmproxyͳͲͰͳ͘Ͱ͖Δ ▸ APIαʔόͷԠͰίϯτϩʔϧ͞ΕΔ؍ଌ
TEXT CASE #0 ▸ APIαʔόʹڍಈΛ੍ޚ͞Ε͍ͯΔ →ʢݴ͍ํѱ͍͕ʣӅṭՄೳ ▸ ͨΓલͱݴΘΕΕͦ͏͕ͩ… ▸ ৹ࠪظؒதʹมͳͷΛग़͢ॴҎͳ͍ͣ
TEXT CASE #1: ಠΞϓϦ ▸ Ұݟແͳɺࠂ͖ΞϓϦ ▸ ͦͦ4+
TEXT CASE #1: ಠΞϓϦ ▸ ͕… ࠂͷ༰͕… ▸ ։ൃݩ͕ࠂιʔεઃఆΛม͑ͨՄೳੑ →ཧ༝͕ͳΜͰ͋Εෆద
→ࠂ͕ݪҼͰreject͞ΕΔ͜ͱ͕વ͋Δ ▸ ࢠڙ༻ͷApple IDͰ͋Εࠂ༰ن੍͞Ε Δ͕ͣͩ… ࠅ͍ࠂओ͕ᬚ͍ͯ͠Δ
TEXT CASE #2: ਓ͚ίϯςϯπ ▸ ͍ΘΏΔແमਖ਼ίϯςϯπΛ৴͍ͯ͠Δʁ →͜Ε͓͔͍͠ ▸ ͦͦ: iOS͜͏͍͏ͷΛڐ͍ͯ͠ͳ͍
→δϣϒε࣌ΫοΫ࣌Ұ؏͍ͯ͠Δ ▸ ৹ࠪ࣌ʹӅṭͨ͠ͱߟ͑Δͷ͕ଥͰͳ͍͔
TEXT CASE #3: SNS ▸ ͔ͭͯΑΓWebίϯςϯπΛࣗ༝ʹදࣔͰ͖Δ ͷ17+ͱ͍͏ن੍͕͋Δ ▸ SNSྨʹ͓͍ͯϝοηʔδͰࢦࣔ͞ΕͨURL͕ ։͚Δ→͜ͷϧʔϧ͕ద༻ʹͳΔͷͰͳ͍
͔ʁ Image by 5kul1k flickr, CC-BY 2.0
TEXT CASE #3: SNS ▸ େ෦͕12+Ͱྲྀ௨; ࣌ྲྀʁ ▸ LINE: 12+
▸ Snapchat/Facebook/Instagram: 12+ ▸ TikTok: 12+ ▸ Twitter: 17+ (←ͳͥʁ) ▸ Telegram: 17+ (←ͳͥʁʁ)
TEXT CASE #3: SNS ▸ Kakao Talk: 4+ʁʁʁ ▸ ઌྫʹͳΒ͑12+͕ଥͰͳ͍ͷ͔
▸ ॳػೳ͋Δ͍ن੍͕গͳ͔ͬͨ࣌ظʹ4+ ͰऔΓɺͦΕ͔Βͳ่͠͠తʹདྷͨՄೳੑʁ ʢi.e. มߋਃࠂ͍ͯ͠ͳ͍ʁʣ
TEXT B. REVIEWERS MATTER ▸ ϨϏϡΞʔʮΨνϟʯΛ௨Δ·Ͱճͯ͠Γൈ͚ Δํ๏ ▸ App IDΛม͑ͯΓൈ͚ͨྫ͋Δ
▸ ϨϏϡʔࣗମٕͦͦज़తʹ ▸ େྔͷΞϓϦΛࡹ͔ͳ͍͚ͯ͘ͳ͍ ▸ ຊ֨తͳղੳΛߦͳ͏ʹ͕͔͔࣌ؒΔ ▸ ࣌ؒʹΘΕͳ͕Βେͷ࣭Λݟ͍ͯΔͱ ͢Δͷ͕ଥ Image by kleuske on flickr, CC-BY-SA 2.0
None
None
None
TEXT C. EXPEDITED REVIEW REQUESTED ▸ ಛٸϨϏϡʔΛཁٻ͠ѹྗΛֻ͚Δख๏ ▸ Ҏલ৽نΞϓϦʹ༻Ͱ͖ͳ͔ͬͨ ▸
Ӆ͠ػೳѱҙͷ͋ΔίʔυΛݟ͵͚Δ͔ʁ →࣮֬ͳݕෆೳͱԾఆ͢Δͷ͕ଥ ▸ ৽نΞϓϦͰ͋ΕؾΛ͚ͭΔͩΖ͏͕ɺ ҰΫϩʔϦϯάͨ͠ΞϓϦͰ͋ͬͨΒ… Image by foshydog on flickr, CC-BY-NC-ND 2.0
TEXT CONCLUSION ▸ ਓྗϨϏϡʔࣗಈղੳ+σετϥοϓΑΓ༗ޮͱ ܾͯ͠ݴ͑ͳ͍ ▸ iOSਓ͕ؒݟ͍ͯΔ͔Β҆શͱ͍͏େऺ৴ڼʹ શࠜ͘ڌ͕ͳ͍; Ή͠Ζةݥ (i.e.
false sense of …) ▸ ͨͩͷҰͷঢ়ଶΛݕূ͍ͯ͠Δ͚ͩ →Androidํࣜʹࢍ൱྆͋Δ͕༏ल ▸ ਓؒʹਓؒͷϛε; རͱͯ͠ײੑͷΈ →ݟམ͠ɺ৺ཧঢ়ଶͳͲ Image by chaim zvi on flickr, CC-BY-ND 2.0
TEXT CONCLUSION ▸ Stay safe! Image by ▓▒░ TORLEY ░▒▓
on flickr, CC-BY-SA 2.0
Q?
ONE MORE THING.. Image by mac-ash on flickr, CC-BY-NC-ND 2.0
TEXT TIKTOK .. ▸ TikTok…͋Ε͔ΒͲ͏ͳͬͨͷ͔ ▸ iOS.. Pasteboardؔ࿈notif.Ͳ͏ͳͬͨͷ͔… ▸ Noti
fi cationݟͳ͘ͳͬͨ
TEXT TIKTOK .. ▸ ݟͳ͘ͳͬͨཁҼ: iOS 14ʹ͓͍ͯܗࣜಛఆ༻API͕Ճ͞ΕͨͨΊ ▸ iOS 15:
Secure Pasteboard; ΞΫςΟϒͳΞϓϦҎ֎ ͔ΒPasteboardΛಡΊͳ͍Α͏ʹվળˠAndroidͰ લ͔Βۭ͋ͬͨ࣌తޚػߏ ※iOS 14Ͱಋೖ͞ΕͨΑ͏ͳ௨͕Android 12Ͱ Ճ͞Ε͍ͯΔ… ྲྀΕతʹෆཁͳ͕ͣͩʁ ▸ TikTok: ΓํΛม͍͑ͯΔՄೳੑ →ͳΜΒ͔ͷճආํࡦʁݕূ͕ඞཁ
FIN. 28.6.2022 TAKAHIRO YOSHIMURA (@ALTERAKEY)