ύεϫʔυΫϥοΩϯά(Dictionary Attack)
• OWASPͷSecListsʹ, ϋοΫ͞ΕΔՄೳੑͷߴ͍ύε
ϫʔυIDͷϦετ͕ࡌ͍ͬͯΔ
‣ OWASP, The Open Web Application Security
Projectͱ͍͏ηΩϡϦςΟؔ࿈ͷίϛϡχςΟ
‣ GitHub্ʹͰެ։͞Ε͍ͯΔ
https://github.com/danielmiessler/SecLists
Slide 17
Slide 17 text
ύεϫʔυΫϥοΩϯά(Dictionary Attack)
༨ஊ
• ͋Δ, “Remove my password from lists so hackers
won’t be able to hack me”ͱ͍͏Pull Request͕…
‣ ͋ΔϢʔβʔ͕ࣗͷύεϫʔυ͕ࡌ͍ͬͯΔ͜ͱ
ʹযͬͯ, আͨ͠ϑΝΠϧͰPull RequestΛૹͬ
ͨͬΆ͍
‣ ίϝϯτཝ͕େتརձʹͳͬͯ·ͨ͠
https://github.com/danielmiessler/SecLists/pull/155
CAPTCHA
• CAPTCHA
ΫϥΠΞϯτ͕ίϯϐϡʔλ͔ਓ͔Λஅ͢Δͷ
‣ Completely Automated Public Turing Test To Tell
Computers and Humans Apart(ίϯϐϡʔλͱਓؒ
Λ۠ผ͢ΔͨΊͷશʹࣗಈԽ͞Εͨެ։νϡʔϦ
ϯάςετʣͷུ