Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
淡路島で開催されたhardening2017fesにプレミアムサポートメンバーで参加してきたよ...
Search
delphinz
December 02, 2017
Technology
0
120
淡路島で開催されたhardening2017fesにプレミアムサポートメンバーで参加してきたよ。/20171202-go-for-hardening2017fes
2017年11月23日から3日間淡路島で開催されたhardening 2017 fesに参加してきた記録と紹介です。
次はあなたが地球を守る番ですよ!
delphinz
December 02, 2017
Tweet
Share
More Decks by delphinz
See All by delphinz
【セキュリティ競技】MINI Hardeningのご紹介 / MINI Hardneing4 introduction
delphinz
1
1.1k
20200209MINI_INFRA
delphinz
1
340
MINI Hardening Road to Taiwan(2019 HITCON CMT)
delphinz
0
850
WAFのルールである OWASP ModSecurity Core Rule Set (CRS)を 使った可視化までの苦労話/20180921_owasp_connect_crs
delphinz
2
1.6k
Other Decks in Technology
See All in Technology
カメラを用いた店内計測におけるオプトインの仕組みの実現 / ai-optin-camera
cyberagentdevelopers
PRO
1
120
20241031_AWS_生成AIハッカソン_GenMuck
tsumita
0
110
visionOSでの空間表現実装とImmersive Video表示について / ai-immersive-visionos
cyberagentdevelopers
PRO
1
110
ExaDB-D dbaascli で出来ること
oracle4engineer
PRO
0
3.6k
日経電子版におけるリアルタイムレコメンドシステム開発の事例紹介/nikkei-realtime-recommender-system
yng87
1
500
ネット広告に未来はあるか?「3rd Party Cookie廃止とPrivacy Sandboxの効果検証の裏側」 / third-party-cookie-privacy
cyberagentdevelopers
PRO
1
130
Java x Spring Boot Warm up
kazu_kichi_67
2
490
GitHub Universe: Evaluating RAG apps in GitHub Actions
pamelafox
0
170
10分でわかるfreee エンジニア向け会社説明資料
freee
18
520k
リンクアンドモチベーション ソフトウェアエンジニア向け紹介資料 / Introduction to Link and Motivation for Software Engineers
lmi
4
290k
分布で見る効果検証入門 / ai-distributional-effect
cyberagentdevelopers
PRO
4
700
マネジメント視点でのre:Invent参加 ~もしCEOがre:Inventに行ったら~
kojiasai
0
460
Featured
See All Featured
Faster Mobile Websites
deanohume
304
30k
Performance Is Good for Brains [We Love Speed 2024]
tammyeverts
3
370
A Tale of Four Properties
chriscoyier
156
23k
Bootstrapping a Software Product
garrettdimon
PRO
305
110k
Making Projects Easy
brettharned
115
5.9k
A Modern Web Designer's Workflow
chriscoyier
692
190k
How to train your dragon (web standard)
notwaldorf
88
5.7k
No one is an island. Learnings from fostering a developers community.
thoeni
19
3k
Reflections from 52 weeks, 52 projects
jeffersonlam
346
20k
Let's Do A Bunch of Simple Stuff to Make Websites Faster
chriscoyier
504
140k
Exploring the Power of Turbo Streams & Action Cable | RailsConf2023
kevinliebholz
27
4.2k
GraphQLとの向き合い方2022年版
quramy
43
13k
Transcript
Copyright © 2017 delphinz All Rights Reserved. ୶࿏ౡͰ։࠵͞Εͨ IBSEFOJOHGFTʹ ϓϨϛΞϜαϙʔτϝϯόʔͰ
ࢀՃ͖ͯͨ͠Αɻ 403".".&̑ !EFMQIJO[ ᖛͤͬ͘ʹ Զ͕ ग़ு൛ 4BU
Copyright © 2017 delphinz All Rights Reserved. ࣗݾհ ໊લɿMasahiro Tabataʢ@delphinzʣ
ࣄɿγεςϜίϯαϧλϯτͯ͠·͢ɻ ηΩϡϦςΟͨ͠ͳΈఔɻ झຯओʹ֨ಆٕ؍ઓͱྉཧɻBBQͰϚάϩͦͯ͠ಲΛ͖͞·͢ɻ MINI Hardening ӡӦϝϯόʔ(ϑΝγϦςʔγϣϯʣͬͯ·͢♫ ʢඇެೝʣ ᖛͤͬ͘উखʹԠԉஂஂʂҿΈ·͠ΐ͏ʂ
Copyright © 2017 delphinz All Rights Reserved. )BSEFOJOHGFTʹߦ͖ͬͯͨ ʮHardening 2017
Fesͱ໊͚ΒΕͨ͜ͷڝٕձɺ͜ͷɺ11݄23͔ Β25·Ͱͷ̏ؒɺຊඪ४࣌ࢠޕઢͷ௨ΔౡͰ͋Δฌݿݝ୶࿏ౡͰ։ ࠵͠·͢ɻʯ ճॏͶΔ͝ͱʹਓ૿͍͖͑ͯɺԠืഒ̑ഒ͔ۙͬͨΒ͍͠ʂ ʢ16νʔϜ Ͱ1νʔϜ6,7໊ʣ
Copyright © 2017 delphinz All Rights Reserved. )FEFOJOH1SPKFDUͱ ηΩϡϦςΟɾΠϕϯτʮHardening Projectʯͱɺ࠷ߴͷʮकΔʯٕ
ज़Λ࣋ͭτοϓΤϯδχΞΛൃ۷ɾݦজ͢ΔͷͰ͋Γɺٕज़ڝٕ(ίϯ ϖςΟγϣϯ)ͷܗࣜͰ࣮ࢪ͍ͯ͠·͢ɻ Hardening ProjectͰ։࠵͢ΔڝٕɺجຊతʹνʔϜର߅Ͱɺ੬ऑੑͷ ͋ΔECαΠτͷϋʔυχϯά(ݎ࿚Խ)ྗͷڧ͞Λ૯߹తʹڝ͏ίϯϖ ςΟγϣϯͷܗΛͱΓ·͢ɻڝٕ༰ɺηΩϡϦςΟΛѻ͏ਓ͕ߩݙ ͢Δɺݱ࣮తͳΛͲͷΑ͏ʹѻ͔ͬͯ͘ʹয͕͋ͯΒΕ·͢ɻ ࢀՃνʔϜɺใ௨৴ݚڀػߏͷ༗͢ΔStarBEDʹߏங͞ΕͨɺԾ ͷωοτϫʔΫڥͰڝٕ͠·͢ɻ IUUQTXBTGPSVNKQIBSEFOJOHQSPKFDU
Copyright © 2017 delphinz All Rights Reserved. ҙ༁͢Δͱ
Copyright © 2017 delphinz All Rights Reserved. ͋ͳͨୡࠓ͔ΒγεςϜཧऀͶɻ ࠓ͔Β๊͓͑ϋοΧʔ͕̍μʔε ·ͱΊͯϋοΩϯά͠ʹ͘Δ͔Β͏ͪ
ͷECαΠτΛམͱ͞ͳ͍Α͏ʹ࣌̕ ؒ͘Β͍ɺ͍͍ײ͡Ͱक͓͍ͬͯͯͶ ♫
Copyright © 2017 delphinz All Rights Reserved. ӡӦ͢Δਓͨͪ ,630.".& •
ֳαΠόʔηΩϡϦςΟηϯλʔ • ηΩϡϦςΟاۀ ݚڀॴॴ • ηΩϡϦςΟΩϟϯϓओࠪ • ౦ژΦϦϯϐοΫҕһ ܯඋہ • ࠃ࠷ߴๆϖϯςελʔ • ݩJPCERT/CC ϚϧΣΞݚڀऀ • ૯ল ྅ ʢ͘͝Ұ෦հʣ ͳΜ͔ͦ͏ʂʂʂ
Copyright © 2017 delphinz All Rights Reserved. ڝٕ෩ܠͦͷ̍ औకձʹݺΕͯ ใ࿙Ӯࣄ݅ͷઆ໌த
ࣾཪ൪ͷ08"41 ,"/4"*ొஃத 403".".&͓ങ্͍͛ ച্ͱ4-"Λදࣔ͢Δ είΞϘʔυʹώϯτ͕ʂʁ
Copyright © 2017 delphinz All Rights Reserved. ڝٕ෩ܠͦͷ̎ Ջͱ͍͏ཧ༝Ͱ Ϧϒʔτ͞ΕΔαʔό
෮چͰ͖ͳ͍ ϚϧΣΞ෮چαʔϏε (PPHMF)PNFʹΑΔ ύεϫʔυ࿐
Copyright © 2017 delphinz All Rights Reserved. ϚʔέοτϓϨΠεΛ׆༻͠Α͏ ڝٕதνʔϜͷ֎෦͔ΒαʔϏεɾΛௐୡͰ͖ΔʮϚʔέοτϓϨΠ ε(ڝٕϦιʔεɾαʔϏεௐୡ)ʯ͕༻ҙ͞Ε·͢ɻ
͜ΕʹΑΓɺνʔϜʹෆ͍ͯ͠ΔϦιʔεɺڝٕʹඞཁͱࢥΘΕΔ༻ Λόʔ νϟϧʹʮߪೖʯ͠ɺཱͯΔ͜ͱ͕Ͱ͖·͢ɻ (Ұ෦ൈਮʣ ϚʔέοτϓϨΠεࢀՃاۀ ߽՚ͳηΩϡϦςΟاۀͷதʹ ͳ͔ͥݱΕΔl403".".&z
Copyright © 2017 delphinz All Rights Reserved. ͳΜͰ403".".&ͳͷʁ • 2016݄̎ʹWAS
ForumදͷԬాྑଠ͞Μ໊͕͚ MINI hardening ͰKuromameʹଓ͘ελʔΛൃ۷͠Α͏ʂ ʮͰԶͨͪ·ͩࠇ͘ͳ͍ʂʯ 5FBN403".".& ͦΜͳܦҢ͋ͬͯॳ৺ऀΛαϙʔτ͢ΔͨΊͷ νʔϜʹબൈ͞Ε·ͨ͠! ͦΒ౾ͷՖݴ༿ ʮಌΕʯ
Copyright © 2017 delphinz All Rights Reserved. SORAMAME5 ϓϨϛΞϜαϙʔτ
Copyright © 2017 delphinz All Rights Reserved. αʔϏε֓ཁ ▸ Hardeningͷͯ͢ΛΓਚͨ͘͠SORAMAME5ϝϯόʔ͕
͋ͳͨͷνʔϜͷڝٕӡӦΛαϙʔτʂ SORAMAME5ϝϯόʔ͕͋ͳͨͷνʔϜʹ࠷ΠϯύΫτͷ͋Δ ࢪࡦΛఏҊ͠·͢ɻ ▸ ڝٕΛڧྗʹαϙʔτ͢ΔͨΊͷπʔϧΛඪ४ఏڙ ɾ౷߹ϩάࢹڥ ɾશνʔϜͷϓϥΠενΣοΫ ɾ֎෦͔ΒݟͨECαΠτͷεΫϦʔϯγϣοτΛνΣοΫ ΤʔδΣϯτΠϯετʔϧʹ͔͔࣌ؒΓ͗ͯ͢அ೦ ࣌ؒͰΫϩʔϥॻ͍ͨʂ ॏ͗ͯ͢ಈ͔ͳ͍ɻ֎෦͔ΒͷONBQͱεΩϟϯπʔϧͰ༻ νʔϜதνʔϜʹ͓ങ্͍͖͛·ͨ͠ʂ
Copyright © 2017 delphinz All Rights Reserved. ʢ൵ใʣਓࣄҟಈͷ͓Βͤ ·͔͞ͷ͓͔ΘΓʢ̎࣌ؒԆೖΓ·͢ʂʣ ΈΜͳେ͖ɺ࡞ۀҾ͖ܧ͗࡞ۀ
ࣾΛ͠ɺϝϯόʔ ผͷνʔϜҠಈ βϫβϫ
Copyright © 2017 delphinz All Rights Reserved. ࠓޙΛߟ͑ΔΞϯΧϯϑΝϨϯε ԶͨͪͷhardeningڝٕΛ࡞Ζ͏ʂηΩϡϦςΟਓࡐͷࠓޙΛߟ͑Δʂɺ ͳͲ͍͕ٞߦΘΕ·ͨ͠ɻ
Copyright © 2017 delphinz All Rights Reserved. ΈΜͳͰߦ͜͏ʮਫ਼ਆͱ࣌ͷ෦ʯ ʮਫ਼ਆͱ࣌ͷ෦ʯອըυϥΰϯϘʔϧʹग़ͯ͘Δमߦͷͷ͜ͱɻ ֎քͰͷ1͕͜ͷ෦ͷதͰ1ʢ365ʣʹ૬͢Δɻ
ʢ࠷ۙए͍ࢠʹυϥΰϯϘʔϧݟͯͳ͍ΜͰΒͳ͍ͬ͢ɺͱݴΘΕ· ͨ͠ɻʣ աڈʹHardening Projectͷओ࠵ͷྛઌੜʹฉ͍ͨͱ͜ΖʹΑΔͱʮ2ϲ݄ ͘Β͍Ͱൃੜ͢ΔͰ͋Ζ͏ηΩϡϦςΟΠϯγσϯτΛ̔࣌ؒͷڝٕʹ٧ ΊࠐΜͩʯͱͷ͜ͱɻ ѹॖͨ࣌ؒ͠ͷΠϯγσϯτମݧ͍͢͝εϐʔυͰΛଅ͠·͢ʂ
Copyright © 2017 delphinz All Rights Reserved. ٿΛʮӴΔʯؒΛ୳͠ʹߦ͜͏ʂ ୩ढ़ଠ ʮேͷϦϨʔʯͷҰઅΑΓ
”ΒேΛϦϨʔ͢Δͷͩɺܦ͔Βܦͱ ͦ͏͍ͯ͠ΘަͰٿΛकΔ” Έͳ͞ΜؒͱҰॹʹ୭͔ͷேΛक͍͖ͬͯ·͠ΐ͏ɻ ࣍ճ͋ͳͨͷ൪Ͱ͢Αʂ
Copyright © 2017 delphinz All Rights Reserved. ΞφλͷʮӴΔʯʹدΓఴ͍͍ͨ 403".".& ͝੩ௌ͋Γ͕ͱ͏͍͟͝·ͨ͠ɻ