Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
黑客技術,黑科技樹 II
Search
Funny Systems
February 27, 2017
Technology
870
1
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
黑客技術,黑科技樹 II
UCCU Talk
Funny Systems
February 27, 2017
More Decks by Funny Systems
See All by Funny Systems
雲端 DHCP 安全問題
funnysystems
1
1.1k
雲端資料掉光光 - GCP 事件調查真實案例
funnysystems
2
1.7k
頑固吧!GCP Cloud SQL (Why Hardening GCP Cloud SQL)
funnysystems
0
510
SMB 捲土重來 (Turning SMB Server Side Bug to Client Side)
funnysystems
0
320
跟壞鄰居想的一樣,供應鏈安全與硬體後門
funnysystems
1
790
以安全工程角度,連結實務與設計
funnysystems
0
400
FunnyPot ‐ 改造 Windows 核心,強固化、蜜罐化
funnysystems
0
750
攻擊者的視角 - 兼談匿名識別度與可追蹤性
funnysystems
1
490
黑科技樹,黑客技術
funnysystems
1
600
Other Decks in Technology
See All in Technology
iOS アプリの「これって不具合ですか?」を AI に調べてもらう
miichan
0
110
OTel × Datadog で 「AI活用」を計測し、改善に繋げる
shihochan
2
470
アジャイルな経理と Claude Code と経営の未来
kawaguti
PRO
3
170
When Platform Engineering Meets GenAI
sucitw
0
140
AIはどのように 組織のアジリティを変えるのか?
junki
4
1.1k
AI時代のコスト管理を考えよう〜明日から使える実践AWSノウハウ~
yoshimi0227
0
550
Kiroで書いた 設計書 が AI レビューの 採点基準 になる
ezaki
0
140
水を運ぶ人としてのリーダーシップ
izumii19
2
190
ザ・データベース、MySQL ~ OSC 2026 Sendai ~
sakaik
0
150
SONiCのLinuxベースを活かしたZabbix監視
sonic
0
240
【セミナー資料】Claude Code をセキュアに使うための考え方と設定の勘どころ / Claude Code Webinar 20260616
masahirokawahara
2
430
AIチャット検索改善の3週間
kworkdev
PRO
2
150
Featured
See All Featured
SEO Brein meetup: CTRL+C is not how to scale international SEO
lindahogenes
1
2.7k
Design of three-dimensional binary manipulators for pick-and-place task avoiding obstacles (IECON2024)
konakalab
0
460
End of SEO as We Know It (SMX Advanced Version)
ipullrank
3
4.2k
A Modern Web Designer's Workflow
chriscoyier
698
190k
Designing for Timeless Needs
cassininazir
1
260
実際に使うSQLの書き方 徹底解説 / pgcon21j-tutorial
soudai
PRO
201
75k
A better future with KSS
kneath
240
18k
Mind Mapping
helmedeiros
PRO
1
260
Building an army of robots
kneath
306
46k
Dominate Local Search Results - an insider guide to GBP, reviews, and Local SEO
greggifford
PRO
0
200
Helping Users Find Their Own Way: Creating Modern Search Experiences
danielanewman
31
3.2k
Designing Experiences People Love
moore
143
24k
Transcript
黑客、技術 黑、科技樹 2017/02/27 II
Kuon 喜歡學習,特別是「安全技術」。
None
逆向 工程 其 他 軟體 破解 惡意 程式 漏洞 攻防
硬體 軟體
硬體 Logic Analysis PCB Reversing ROM Extraction IC Reversing
Emulation Flash Dump JTAG Firmware Analysis FS Extraction Firmware Download
File ID
軟體 De- compiler IDA Pro REIL Binary Analysis Binary Diff
Analysis DBI Emulation Firmware Analysis File ID File Format Debugger
Anti-Anti- Debug Anti- Debug Anti- Dump Packer Anti-DBI Anti- Sandbox
Anti- Disasm Anti-VM Anti- Emulator Unpacker Anti-Anti- VM
Anti- Debug Packer Anti- Sandbox Anti-VM Anti-Virus Virus Anti- Rootkit
Anti-Anti- Virus Rootkit Malware Botnet Anti- Botnet Anti- Malware
ASLR Malware Anti- Malware DEP ROP UAC W^X EMET JIT
Spray GrSecurity Anti-Anti- Virus
Anti- Dump Debugger Memory Hacking Anti-Anti- Debug Anti- Debug VM
Anti-VM Anti-Anti- VM
Hooking Rootkit Malware Injection SMM VM
None
需求 架構 開發 測試 部署 API SOAP RESTful JSON Data
Format XML Authentication Cookie HTTP Header Token User Input Injection OAuth Cross-Domain Sever-side Proxy SSRF Javascript Hijacking CSP Secure Transport SSL/TLS HSTS NoSQL Cert Validation CORS CSRF JSONP Callback Resource Upload/Download Upload Enumeration CSRF CSRF Security Header Pinning XXE
None
流程、標準 Null Pointer Race Condition Dangling Pointer Data Race Double
Free Double Destruct Use-After-Free Use-After-Destruct Integer Overflow Counter Overflow Heap Overflow Pool Overflow Stack Overflow Format String JMS & JMX File Inclusion Object Injection 框 架 OGNL Injection HQL Injection 執 行 環 境 Java PHP 通 用 Web Native SQL Injection XSS Cmd Injection Path Traversal Code Injection Unserialization Template Injection Python Template Injection Race Condition CSRF YAML Evaluation Mass Assignment Spring i18n Injection OOB Read Arbitrary Write Info Leak Type Confusion Undef Behavior Uninit Memory
Q&A 問題‧討論