Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Black Hat USA 2026の面白かった発表を紹介

Sponsored · Your Podcast. Everywhere. Effortlessly. Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
Avatar for Arata Arata
August 21, 2026
18

Black Hat USA 2026の面白かった発表を紹介

Avatar for Arata

Arata

August 21, 2026

Transcript

  1. ! で 速 爆 Black Hat USA 2026の 面白かった発表を紹介 2026/08/10

    セキュリティ・キャンプ2026全国大会 LT ネクスト受講生 安藤慎
  2. C and Its Consequences: The Source Is Just a Suggestion

    3 https://blackhat.com/us-26/briefings/schedule/?#c-and-its-consequences-the-source-is-just-a-suggestion-54295 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  3. C and Its Consequences: The Source Is Just a Suggestion

    4 pkt->lengthをチェック直後に書き換えられれば異常なサイズのコピーが できる → TOCTOU https://blackhat.com/us-26/briefings/schedule/?#c-and-its-consequences-the-source-is-just-a-suggestion-54295 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  4. C and Its Consequences: The Source Is Just a Suggestion

    5 ローカル変数にコピーしたら安全? https://blackhat.com/us-26/briefings/schedule/?#c-and-its-consequences-the-source-is-just-a-suggestion-54295 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  5. C and Its Consequences: The Source Is Just a Suggestion

    6 ! い な ゃ じ 全 安 ローカル変数にコピーしたら安全? https://blackhat.com/us-26/briefings/schedule/?#c-and-its-consequences-the-source-is-just-a-suggestion-54295 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  6. C and Its Consequences: The Source Is Just a Suggestion

    7 • コンパイラの最適化がTOCTOUを生み出してしまう場合 がある • 例) local_lengthに保存しておくより、pkt->lengthを再度読む方が 安価だと判断したケース ◦ コンパイラはlocal_lengthの参照をpkt->lengthの参照に置き換 える可能性がある • QEMU, Linux, glibc, GitなどにTOCTOUが起こりうるコードを確認 https://blackhat.com/us-26/briefings/schedule/?#c-and-its-consequences-the-source-is-just-a-suggestion-54295 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  7. CSS: the bomb inside your inbox 8 • WebメールにおいてはCSSも強力なアタックサーフェス になりうる

    ◦ メーラーの「ピン留め」などのUIを乗っ取る ◦ 人間とAIに異なる文章を見せる ◦ HTML+CSSでキーロガーを実現する https://blackhat.com/us-26/briefings/schedule/?#css-the-bomb-inside-your-inbox-51909 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  8. Breaking Hardware CFI with Sigreturn 9 • シグナル復帰用システムコールrt_sigreturnはBTIをバイ パスできてしまう ◦

    BTI: 間接ジャンプの遷移先を制限し、不正なアドレスへのジャ ンプを防ぐ仕組み • rt_sigreturnでチェーンをうまく構成するとチューリング完全に • Ubuntu 26.04, Android 17で実証 https://blackhat.com/us-26/briefings/schedule/#breaking-hardware-cfi-with-sigreturn-52333 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  9. PLaTypus: Eliminating Code-Reuse at the Module Boundary 10 • 共有ライブラリをまたぐ不正な間接ジャンプを防ぐ手法

    • PLTのマッピングを工夫+ジャンプ先アドレスにマスクを適用 ◦ 特定の関数のPLTにしかジャンプできないようにする • Redis, SQLite, Nginxなどで攻撃に使われうるガジェットを98%削減 https://blackhat.com/us-26/briefings/schedule/?#platypus-eliminating-code-reuse-at-the-module-boundary-53201 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  10. Breaking the Seal: Static Deobfuscation of Compiled V8 JavaScript Bytecode

    Malware 11 • V8のバイトコードからJavaScriptの擬似コードを復元・ 難読化解除する手法 ◦ View8でバイトコードから難読化された擬似コードを復元 ◦ View8のIR上で変換パスを適用して難読化解除 ◦ LLMで関数の名前を推測 https://blackhat.com/us-26/briefings/schedule/?#breaking-the-seal-static-deobfuscation-of-compiled-v8-javascript-bytecode-malware-53041 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  11. GPUBreach: Privilege Escalation Attacks on GPUs Using Rowhammer 12 •

    GPUにロードしたCUDAカーネルからRowHammerを起 こしてページテーブルを書き換える攻撃 • GPU上の機密データやAIモデルのウェイトなどを窃取できる • DMA経由のホストメモリ書き換え+GPUドライバの脆弱性で権限昇格 https://blackhat.com/us-26/briefings/schedule/?#gpubreach-privilege-escalation-attacks-on-gpus-using-rowhammer-52286 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata