Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Staring into chaos
Search
Takahiro Yoshimura
June 28, 2022
Technology
0
10
Staring into chaos
Quick evaluation on security postures of iOS/Android app store. (OWASP Saitama MTG #8, talk #1)
Takahiro Yoshimura
June 28, 2022
Tweet
Share
More Decks by Takahiro Yoshimura
See All by Takahiro Yoshimura
Reviewing 2024
alterakey
0
20
In The Middle Of Chatter #2
alterakey
0
26
Chaotic Channel
alterakey
0
34
In The Middle Of Chatter #1
alterakey
0
37
Shadow Runners 2
alterakey
0
6
Shadow Runners
alterakey
0
7
Looking Back: 2023
alterakey
0
9
Fill In The Blank
alterakey
0
8
Ticket To The Dark World
alterakey
0
13
Other Decks in Technology
See All in Technology
社内でKaggle部を作って初学者育成した話
daikon99
1
100
Cracking the Coding Interview 6th Edition
gdplabs
14
28k
2025/3/1 公共交通オープンデータデイ2025
morohoshi
0
120
Охота на косуль у древних
ashapiro
0
150
20250304_赤煉瓦倉庫_DeepSeek_Deep_Dive
hiouchiy
2
150
Dify触ってみた。
niftycorp
PRO
0
110
Qiita Organizationを導入したら、アウトプッターが爆増して会社がちょっと有名になった件
minorun365
PRO
1
380
Pwned Labsのすゝめ
ken5scal
2
590
プロダクト開発者目線での Entra ID 活用
sansantech
PRO
0
200
目標と時間軸 〜ベイビーステップでケイパビリティを高めよう〜
kakehashi
PRO
8
1.1k
結果的にこうなった。から見える メカニズムのようなもの。
recruitengineers
PRO
1
130
30→150人のエンジニア組織拡大に伴うアジャイル文化を醸成する役割と取り組みの変化
nagata03
0
410
Featured
See All Featured
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
280
13k
Scaling GitHub
holman
459
140k
Reflections from 52 weeks, 52 projects
jeffersonlam
348
20k
The Art of Programming - Codeland 2020
erikaheidi
53
13k
[RailsConf 2023] Rails as a piece of cake
palkan
53
5.3k
Exploring the Power of Turbo Streams & Action Cable | RailsConf2023
kevinliebholz
30
4.6k
Visualizing Your Data: Incorporating Mongo into Loggly Infrastructure
mongodb
45
9.4k
Designing on Purpose - Digital PM Summit 2013
jponch
117
7.1k
Building Flexible Design Systems
yeseniaperezcruz
328
38k
Learning to Love Humans: Emotional Interface Design
aarron
273
40k
Templates, Plugins, & Blocks: Oh My! Creating the theme that thinks of everything
marktimemedia
30
2.3k
Facilitating Awesome Meetings
lara
53
6.3k
Transcript
STARING INTO CHAOS OWASP SAITAMA MTG #8, TALK #1 Image
by ST1138 on flickr, CC-BY-NC-ND 2.0
TEXT SESSION FLAGS ▸ ըɾԻɾެ։: OK Image by Nico Kaiser
on flickr, CC-BY 2.0
TEXT WHO I AM ▸ Takahiro Yoshimura (@alterakey) https://keybase.io/alterakey ▸
Monolith Works Inc. Co-founder, CTO Security researcher ▸ ໌࣏େֶαΠόʔηΩϡϦςΟݚڀॴ ٬һݚڀһ
TEXT WHAT I DO ▸ Security research and development ▸
iOS/Android Apps →Financial, Games, IoT related, etc. (>200) →trueseeing: Non-decompiling Android Application Vulnerability Scanner [2017] ▸ Windows/Mac/Web/HTML5 Apps →POS, RAD tools etc. ▸ Network/Web penetration testing →PCI-DSS etc. ▸ Search engine reconnaissance (aka. Google Hacking) ▸ Whitebox testing ▸ Forensic analysis
TEXT WHAT I DO ▸ CTF ▸ Enemy10, Sutegoma2 ▸
METI CTFCJ 2012 Qual.: Won ▸ METI CTFCJ 2012: 3rd ▸ DEF CON 21 CTF: 6th ▸ DEF CON 22 OpenCTF: 4th ▸ ൃදɾߨԋͳͲ DEF CON 25 Demo Labs (2017) DEF CON 27 AI Village (2019) CODE BLUE (2017, 2019) CYDEF (2020) etc. Image by Wiyre Media on flickr, CC-BY 2.0
TEXT BACKGROUND ▸ ΞϓϦͷڍಈʹ͍ͭͯશͯѲ͍ͯ͠·͔͢ʁ ▸ ඞͣ͠ਧௌ͍ͯ͠Δ௨ΓͰ͋Δඞཁͳ͍ →ॻ͖खͷࣗ༝ ▸ ͰϢʔβ͔ΒࠔΔ… Image
by Sam Azgor on flickr, CC-BY 2.0
TEXT ANDROID: STATIC ANALYSIS + DEATH TRAP ▸ ެ։࣌ʹࣗಈղੳΛࢪ͠ѱҙͷͳ͍͜ͱΛ֬ೝ ▸
Ϣʔβ͔Βͷใࠂ͋Δ͍ൈ͖ଧͪݕࠪͰ ΞΧϯτBANॲஔ → σετϥοϓ ▸ ܯࠂ΄΅͠ͳ͍ ▸ ΄΅ฉ͔ͳ͍ (HNͳͲʹࢮࢡྦྷʑ) ▸ نఆͷվఆʹԠ͢Δ·Ͱެ։ఀࢭॲஔ ▸ େখΘͣͨͩͷҰϢʔβͰ͔͠ͳ͍ Image by Daniel Arrhakis - Visual Arts on flickr, CC-BY-NC 2.0
TEXT IOS: MANUAL REVIEW ▸ ެ։࣌ʹਓ͕ؒΞϓϦΛ֬ೝ ▸ UIنఆҧͳͲ; ʮUIنఆʯͱ͍͍࣮࣭ͭͭతͳશମن ▸
ҧͨ͠߹reject ▸ ԟʑʹͯ͠ԇᅀͷࠜݯ ▸ ͋ΔఔॊೈʹରԠͯ͘͠ΕΔ Image by Giåm on flickr, CC-BY-SA 2.0
TEXT MANUAL REVIEWING IS SAFER..? ▸ iOSͷ߹Appleͷελοϑ͕ΞϓϦΛ֬ೝͯ͠ ͍ΔͷͰมͳΞϓϦೖͬͯ͜ͳ͍ʢͷͰ AndroidͳΜ͔ΑΓ҆શʣͱ͍͏Ұൠೝࣝ ▸
ຊʹʁ Image by Glen Bledsoe on flickr, CC-BY 2.0
TEXT A. REMOTE FLAGS TO CONTROL BEHAVIOR ▸ ࿈ܞ͢ΔAPIαʔόʹ͓͍ͯηʔϑͳ༰Λ͢ ͜ͱͰ৹ࠪΛΓൈ͚Δख๏
▸ ໌Β͔ͳςετڥͩͱreject͞ΕΔ →ͦΕͳΓʹ͓͑ͯ͘ඞཁ͕͋Δ ▸ ΘΓͱྑ͘ݟ͔͚Δ ▸ ৹ࠪ༻ڥ/εςʔδϯάڥ etc. Image by Vinicius | www.viniciuscvenancio.com.br on flickr, CC-BY-NC-ND 2.0
TEXT CASE #0 ▸ ອըΞϓϦ ▸ ອըѪ͞Ε͍ͯΔ͕จԽతʹ᫁Λྑ͘ੜΉ
TEXT CASE #0 ▸ ੩తղੳ * Extract: checkra1n + frida-ios-dump
* Analysis: Ghidra 10 ▸ APIαʔόΛܦ༝͢Δࣔࠦ ▸ ༨ஊ: DFUϞʔυʹೖΕΔ࣌ʹେมͳۤ࿑ →macOS͔Βͷׯব͕ଟݪҼ →checkra1n 0.12.4M1Ͱಈ࡞͠ͳ͍
TEXT CASE #0 ▸ τϥϑΟοΫղੳ * Aggregation: StrongSwan 5.8 +
iptables * Analysis: Burp Suite (transparent proxy) ※transparent proxy mode͕Ͱ͖ΕZAP/ mitmproxyͳͲͰͳ͘Ͱ͖Δ ▸ APIαʔόͷԠͰίϯτϩʔϧ͞ΕΔ؍ଌ
TEXT CASE #0 ▸ APIαʔόʹڍಈΛ੍ޚ͞Ε͍ͯΔ →ʢݴ͍ํѱ͍͕ʣӅṭՄೳ ▸ ͨΓલͱݴΘΕΕͦ͏͕ͩ… ▸ ৹ࠪظؒதʹมͳͷΛग़͢ॴҎͳ͍ͣ
TEXT CASE #1: ಠΞϓϦ ▸ Ұݟແͳɺࠂ͖ΞϓϦ ▸ ͦͦ4+
TEXT CASE #1: ಠΞϓϦ ▸ ͕… ࠂͷ༰͕… ▸ ։ൃݩ͕ࠂιʔεઃఆΛม͑ͨՄೳੑ →ཧ༝͕ͳΜͰ͋Εෆద
→ࠂ͕ݪҼͰreject͞ΕΔ͜ͱ͕વ͋Δ ▸ ࢠڙ༻ͷApple IDͰ͋Εࠂ༰ن੍͞Ε Δ͕ͣͩ… ࠅ͍ࠂओ͕ᬚ͍ͯ͠Δ
TEXT CASE #2: ਓ͚ίϯςϯπ ▸ ͍ΘΏΔແमਖ਼ίϯςϯπΛ৴͍ͯ͠Δʁ →͜Ε͓͔͍͠ ▸ ͦͦ: iOS͜͏͍͏ͷΛڐ͍ͯ͠ͳ͍
→δϣϒε࣌ΫοΫ࣌Ұ؏͍ͯ͠Δ ▸ ৹ࠪ࣌ʹӅṭͨ͠ͱߟ͑Δͷ͕ଥͰͳ͍͔
TEXT CASE #3: SNS ▸ ͔ͭͯΑΓWebίϯςϯπΛࣗ༝ʹදࣔͰ͖Δ ͷ17+ͱ͍͏ن੍͕͋Δ ▸ SNSྨʹ͓͍ͯϝοηʔδͰࢦࣔ͞ΕͨURL͕ ։͚Δ→͜ͷϧʔϧ͕ద༻ʹͳΔͷͰͳ͍
͔ʁ Image by 5kul1k flickr, CC-BY 2.0
TEXT CASE #3: SNS ▸ େ෦͕12+Ͱྲྀ௨; ࣌ྲྀʁ ▸ LINE: 12+
▸ Snapchat/Facebook/Instagram: 12+ ▸ TikTok: 12+ ▸ Twitter: 17+ (←ͳͥʁ) ▸ Telegram: 17+ (←ͳͥʁʁ)
TEXT CASE #3: SNS ▸ Kakao Talk: 4+ʁʁʁ ▸ ઌྫʹͳΒ͑12+͕ଥͰͳ͍ͷ͔
▸ ॳػೳ͋Δ͍ن੍͕গͳ͔ͬͨ࣌ظʹ4+ ͰऔΓɺͦΕ͔Βͳ่͠͠తʹདྷͨՄೳੑʁ ʢi.e. มߋਃࠂ͍ͯ͠ͳ͍ʁʣ
TEXT B. REVIEWERS MATTER ▸ ϨϏϡΞʔʮΨνϟʯΛ௨Δ·Ͱճͯ͠Γൈ͚ Δํ๏ ▸ App IDΛม͑ͯΓൈ͚ͨྫ͋Δ
▸ ϨϏϡʔࣗମٕͦͦज़తʹ ▸ େྔͷΞϓϦΛࡹ͔ͳ͍͚ͯ͘ͳ͍ ▸ ຊ֨తͳղੳΛߦͳ͏ʹ͕͔͔࣌ؒΔ ▸ ࣌ؒʹΘΕͳ͕Βେͷ࣭Λݟ͍ͯΔͱ ͢Δͷ͕ଥ Image by kleuske on flickr, CC-BY-SA 2.0
None
None
None
TEXT C. EXPEDITED REVIEW REQUESTED ▸ ಛٸϨϏϡʔΛཁٻ͠ѹྗΛֻ͚Δख๏ ▸ Ҏલ৽نΞϓϦʹ༻Ͱ͖ͳ͔ͬͨ ▸
Ӆ͠ػೳѱҙͷ͋ΔίʔυΛݟ͵͚Δ͔ʁ →࣮֬ͳݕෆೳͱԾఆ͢Δͷ͕ଥ ▸ ৽نΞϓϦͰ͋ΕؾΛ͚ͭΔͩΖ͏͕ɺ ҰΫϩʔϦϯάͨ͠ΞϓϦͰ͋ͬͨΒ… Image by foshydog on flickr, CC-BY-NC-ND 2.0
TEXT CONCLUSION ▸ ਓྗϨϏϡʔࣗಈղੳ+σετϥοϓΑΓ༗ޮͱ ܾͯ͠ݴ͑ͳ͍ ▸ iOSਓ͕ؒݟ͍ͯΔ͔Β҆શͱ͍͏େऺ৴ڼʹ શࠜ͘ڌ͕ͳ͍; Ή͠Ζةݥ (i.e.
false sense of …) ▸ ͨͩͷҰͷঢ়ଶΛݕূ͍ͯ͠Δ͚ͩ →Androidํࣜʹࢍ൱྆͋Δ͕༏ल ▸ ਓؒʹਓؒͷϛε; རͱͯ͠ײੑͷΈ →ݟམ͠ɺ৺ཧঢ়ଶͳͲ Image by chaim zvi on flickr, CC-BY-ND 2.0
TEXT CONCLUSION ▸ Stay safe! Image by ▓▒░ TORLEY ░▒▓
on flickr, CC-BY-SA 2.0
Q?
ONE MORE THING.. Image by mac-ash on flickr, CC-BY-NC-ND 2.0
TEXT TIKTOK .. ▸ TikTok…͋Ε͔ΒͲ͏ͳͬͨͷ͔ ▸ iOS.. Pasteboardؔ࿈notif.Ͳ͏ͳͬͨͷ͔… ▸ Noti
fi cationݟͳ͘ͳͬͨ
TEXT TIKTOK .. ▸ ݟͳ͘ͳͬͨཁҼ: iOS 14ʹ͓͍ͯܗࣜಛఆ༻API͕Ճ͞ΕͨͨΊ ▸ iOS 15:
Secure Pasteboard; ΞΫςΟϒͳΞϓϦҎ֎ ͔ΒPasteboardΛಡΊͳ͍Α͏ʹվળˠAndroidͰ લ͔Βۭ͋ͬͨ࣌తޚػߏ ※iOS 14Ͱಋೖ͞ΕͨΑ͏ͳ௨͕Android 12Ͱ Ճ͞Ε͍ͯΔ… ྲྀΕతʹෆཁͳ͕ͣͩʁ ▸ TikTok: ΓํΛม͍͑ͯΔՄೳੑ →ͳΜΒ͔ͷճආํࡦʁݕূ͕ඞཁ
FIN. 28.6.2022 TAKAHIRO YOSHIMURA (@ALTERAKEY)