Upgrade to Pro — share decks privately, control downloads, hide ads and more …

Black Hat USA 2026の面白かった発表を紹介

Sponsored · Your Podcast. Everywhere. Effortlessly. Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
Avatar for Arata Arata
August 21, 2026
5

Black Hat USA 2026の面白かった発表を紹介

Avatar for Arata

Arata

August 21, 2026

More Decks by Arata

Transcript

  1. ! で 速 爆 Black Hat USA 2026の 面白かった発表を紹介 2026/08/10

    セキュリティ・キャンプ2026全国大会 LT ネクスト受講生 安藤慎
  2. C and Its Consequences: The Source Is Just a Suggestion

    3 https://blackhat.com/us-26/briefings/schedule/?#c-and-its-consequences-the-source-is-just-a-suggestion-54295 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  3. C and Its Consequences: The Source Is Just a Suggestion

    4 pkt->lengthをチェック直後に書き換えられれば異常なサイズのコピーが できる → TOCTOU https://blackhat.com/us-26/briefings/schedule/?#c-and-its-consequences-the-source-is-just-a-suggestion-54295 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  4. C and Its Consequences: The Source Is Just a Suggestion

    5 ローカル変数にコピーしたら安全? https://blackhat.com/us-26/briefings/schedule/?#c-and-its-consequences-the-source-is-just-a-suggestion-54295 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  5. C and Its Consequences: The Source Is Just a Suggestion

    6 ! い な ゃ じ 全 安 ローカル変数にコピーしたら安全? https://blackhat.com/us-26/briefings/schedule/?#c-and-its-consequences-the-source-is-just-a-suggestion-54295 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  6. C and Its Consequences: The Source Is Just a Suggestion

    7 • コンパイラの最適化がTOCTOUを生み出してしまう場合 がある • 例) local_lengthに保存しておくより、pkt->lengthを再度読む方が 安価だと判断したケース ◦ コンパイラはlocal_lengthの参照をpkt->lengthの参照に置き換 える可能性がある • QEMU, Linux, glibc, GitなどにTOCTOUが起こりうるコードを確認 https://blackhat.com/us-26/briefings/schedule/?#c-and-its-consequences-the-source-is-just-a-suggestion-54295 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  7. CSS: the bomb inside your inbox 8 • WebメールにおいてはCSSも強力なアタックサーフェス になりうる

    ◦ メーラーの「ピン留め」などのUIを乗っ取る ◦ 人間とAIに異なる文章を見せる ◦ HTML+CSSでキーロガーを実現する https://blackhat.com/us-26/briefings/schedule/?#css-the-bomb-inside-your-inbox-51909 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  8. Breaking Hardware CFI with Sigreturn 9 • シグナル復帰用システムコールrt_sigreturnはBTIをバイ パスできてしまう ◦

    BTI: 間接ジャンプの遷移先を制限し、不正なアドレスへのジャ ンプを防ぐ仕組み • rt_sigreturnでチェーンをうまく構成するとチューリング完全に • Ubuntu 26.04, Android 17で実証 https://blackhat.com/us-26/briefings/schedule/#breaking-hardware-cfi-with-sigreturn-52333 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  9. PLaTypus: Eliminating Code-Reuse at the Module Boundary 10 • 共有ライブラリをまたぐ不正な間接ジャンプを防ぐ手法

    • PLTのマッピングを工夫+ジャンプ先アドレスにマスクを適用 ◦ 特定の関数のPLTにしかジャンプできないようにする • Redis, SQLite, Nginxなどで攻撃に使われうるガジェットを98%削減 https://blackhat.com/us-26/briefings/schedule/?#platypus-eliminating-code-reuse-at-the-module-boundary-53201 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  10. Breaking the Seal: Static Deobfuscation of Compiled V8 JavaScript Bytecode

    Malware 11 • V8のバイトコードからJavaScriptの擬似コードを復元・ 難読化解除する手法 ◦ View8でバイトコードから難読化された擬似コードを復元 ◦ View8のIR上で変換パスを適用して難読化解除 ◦ LLMで関数の名前を推測 https://blackhat.com/us-26/briefings/schedule/?#breaking-the-seal-static-deobfuscation-of-compiled-v8-javascript-bytecode-malware-53041 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata
  11. GPUBreach: Privilege Escalation Attacks on GPUs Using Rowhammer 12 •

    GPUにロードしたCUDAカーネルからRowHammerを起 こしてページテーブルを書き換える攻撃 • GPU上の機密データやAIモデルのウェイトなどを窃取できる • DMA経由のホストメモリ書き換え+GPUドライバの脆弱性で権限昇格 https://blackhat.com/us-26/briefings/schedule/?#gpubreach-privilege-escalation-attacks-on-gpus-using-rowhammer-52286 2026/08/11 Black Hat USA 2026の面白かった発表を紹介 | Arata