Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
艦これHacking
Search
ぽんこつ
November 10, 2013
Technology
0
3.8k
艦これHacking
艦これAPIをWiresharkで調べてみた
ぽんこつ
November 10, 2013
Tweet
Share
More Decks by ぽんこつ
See All by ぽんこつ
Cocos2dx(Ver2)が闇な話
ponkotuy
0
200
Other Decks in Technology
See All in Technology
Абьюзим random_bytes(). Фёдор Кулаков, разработчик Lamoda Tech
lamodatech
0
340
AWS CDK 実践的アプローチ N選 / aws-cdk-practical-approaches
gotok365
6
740
Snowflake Summit 2025 データエンジニアリング関連新機能紹介 / Snowflake Summit 2025 What's New about Data Engineering
tiltmax3
0
310
Node-RED × MCP 勉強会 vol.1
1ftseabass
PRO
0
140
Yamla: Rustでつくるリアルタイム性を追求した機械学習基盤 / Yamla: A Rust-Based Machine Learning Platform Pursuing Real-Time Capabilities
lycorptech_jp
PRO
3
120
Observability infrastructure behind the trillion-messages scale Kafka platform
lycorptech_jp
PRO
0
140
AIエージェント最前線! Amazon Bedrock、Amazon Q、そしてMCPを使いこなそう
minorun365
PRO
14
5.1k
AIの最新技術&テーマをつまんで紹介&フリートークするシリーズ #1 量子機械学習の入門
tkhresk
0
140
Oracle Audit Vault and Database Firewall 20 概要
oracle4engineer
PRO
3
1.7k
生成AI時代 文字コードを学ぶ意義を見出せるか?
hrsued
1
310
フィンテック養成勉強会#54
finengine
0
180
Кто отправит outbox? Валентин Удальцов, автор канала Пых
lamodatech
0
340
Featured
See All Featured
YesSQL, Process and Tooling at Scale
rocio
173
14k
Art, The Web, and Tiny UX
lynnandtonic
299
21k
RailsConf & Balkan Ruby 2019: The Past, Present, and Future of Rails at GitHub
eileencodes
138
34k
How STYLIGHT went responsive
nonsquared
100
5.6k
Making Projects Easy
brettharned
116
6.3k
A designer walks into a library…
pauljervisheath
207
24k
Navigating Team Friction
lara
187
15k
BBQ
matthewcrist
89
9.7k
Done Done
chrislema
184
16k
The Art of Delivering Value - GDevCon NA Keynote
reverentgeek
15
1.5k
Templates, Plugins, & Blocks: Oh My! Creating the theme that thinks of everything
marktimemedia
31
2.4k
Build your cross-platform service in a week with App Engine
jlugia
231
18k
Transcript
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ؋͜ΕHacking 2013 11 ݄ 09
؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ΆΜͭ͜ ΆΜͭ͜ʢ@ponkotuyʣͰ͢ ேى͖Εͳͯ͘༗څ͕Βͳ͍ఔͷࣾச ։ൃ Scala +
Play ͱ CoeeScript ڥ Emacs or IntelliJ(IDE) + Ubuntu ϓϨθϯ Emacs ͷ org-mode + TEX + Beamer ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ͖ͳ؋່རࠜ͞ΜͰ͢ E-2 ߈ུͰແͯ͘͠Ε·ͨ͠ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ؋͜Εʜͬͯ·͢ΑͶʁ ؋͜Εͱ ఇࠃւ܉ͷ܉؋່͕ʹͳͬͯ ҭͯͯΩϟ οΩϟϑϑ͠ͳ͕Β ւҬΛಥഁ͢ΔͨΊʹࢿݯཏ൫ͱઓ͏
ήʔϜͰ͢ʂ ˞࣮ࡍઓಆӡཁૉ͚ͩͳͷͰɺҭͱฤͱࢿݯྔ͕શͯ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ͱ͍͏Θ͚Ͱ ࠓճ؋͜Εͷ API Λ Hacking ͯ͠Έ·͠ΐ͏ʂ
؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ωοτϫʔΫௐࠪํ๏ ؋͜ΕʢFlashʣͷ௨৴ΛௐΔํ๏ʢࢥ͍ͨൣғʣ શύέοτ௨৴Λऔಘͯ͠ FilterʢࠓճΔํ๏ʣ ಛఆϖʔδ͚ͩ Proxy
Λט·ͤΔ .NET ͷ IE ܥϥΠϒϥϦʢʁʣ ؋͜ΕϒϥβܥԼ 2 छྨͷํ๏Ͱड ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ tcpdumpͱ CUI ಛఆωοτϫʔΫσόΠεͷύέοτௐࠪ͢Δπʔϧ ͍ํάάΕ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ͬͯΈΔ ؋͜Εͷૢ࡞Λͨ͠ͱ͖ྲྀΕΔύέοτΛղੳ 125.6.189.39 ͷ Port80 ͱ௨৴͍ͯ͠Δ͜ͱ͕͔Δ
-X ͰόΠφϦσʔλ͕ݟΕΔ ͕ͩૉਓʹ HTTP Ͱ JSON ΓͱΓ͍ͯ͠Δ༷ࢠ͠ ͔͔Βͳ͍ ͜Μͳݪ࢝తͳπʔϧͬͯΒΕΔ͔ʔʢόʔϯʂ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ Wiresharkͱ GUI ύέοτΩϟϓνϟ Filter HTTP ղੳࡁΈσʔλΛ
Export ࠓճຆͲ͜Ε͚ͩͰ͍͚·ͨ͠ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ؋͜ΕͰWireshark Ubuntu ͳΒ apt-get wireshark ཁ
root lter http and ip.addr == 125.6.189.39 ͜ͷঢ়ଶͰૢ࡞͢Δͱσʔλ͕ྲྀΕͯ͘Δ ͋ͱ͖ͳσʔλΛબΜͰ export ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ exportͨ͠ϑΝΠϧ ຊޠ͕ unicode unicode ରԠͷ JSON
ύʔα͕ඞཁ Python Ͱσίʔυͯ͠ PrettyPrint ͠·ͨ͠ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ௨৴ͷશମతͳಛ ҉߸Խ͞Εͯͳ͍ʢ͞ΕͯͨΒརࠜ͞ΜτʔΫͯͨ͠ʣ api_result Ͱ 1 ͓ͦΒ͘
Success api_result_msg ͰޭͷจࣈΛฦ͢ʢҙຯແͦ͞͏ʣ api_data ҎԼʹ༗༻ͳσʔλ͕͋Δ MP3ɻϞϊϥϧͷ 48kHzɺ56kbps ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ߓॳظը໘ ͜ͷը໘ʹભҠ͢Δ࣌ͷ௨৴ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ߓॳظը໘2 actionlog ӈԼͷԋश݁ՌͳͲͷ׆ಈ log logincheck ࢿݯ૿ྔɻೝূܥͰͳ͍
material ࢿݯྔɻࢿݯ 1 ੴ༉ 2 ༀ 3 మ߯ 4 ϘʔΩ 5 ߴݐࡐ 6 ߴम෮ࡐ 7 ։ൃࢿࡐɻlogincheck ͷฦΓԿͷҝʹ͋Δͷ͔ɻ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ deck_port ؋ୂใ api_name ؋ୂ໊ api_ship ؋່൪߸ʢೖखॱʹ
increment ͍ͯ͘͠ IDʣͷ Ϧετ api_mission ԕσʔλ [ւҬ, ԕ ID, ԕؼ࣌ؒ, ʁ] ԕσʔλ͕؋ୂใʹͳͬͯΔͷڵຯਂ͍ɻ͜ΕͰԕ νΣ οΧʔ࡞ΕΔ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ndock ೖڎใ api_complete_time ྃ࣌ؒ api_item1ʙ4 ࣋ͪใ
api_ship_id ؋່൪߸ ͜ΕͰೖڎνΣ οΧʔ࡞Ε·͢Ͷ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ship2 ؋່ͷৄࡉσʔλ HP ͷσʔλͳͲεςʔλεશ෦ ཕܸͳͲඋલޙͷ ࠷େ
HP උલޙͷ͕ແ͍ͷͰɺࠓޙඋͰ HP ্͕Δܥඋແͦ͞͏ͩͱ͔Δ api_luckey ɺྫ͑ඈཾ [40, 89]ɺརࠜ [10, 59] ͳͲ ͋ͱ deck_port ؙ͕͝ͱೖ͍ͬͯΔɻҙຯͳ͍ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ basic ઓදࣔͰݟΕΔϢʔβσʔλ+Ո۩ใͳͲ ؾʹͳΔͷ max_kagu Ո۩ͷ্ݶΛ࣮͢Δ༧ఆͩͬͨʁ play_time
͋Δͱศརͦ͏͕ͩ 0 ʹͳ͍ͬͯΔ pt_challenged ύʔςΟʔػೳ͔ʁ কདྷ࣮༧ఆ or Deprecated ͳΘΕ͍ͯͳ͍ม͋Γ ͜ͷΑ͏ͳಾม basic ͷΈݟΒΕΔ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ߓॳظը໘·ͱΊ ߓॳظը໘͚ͩͰ૬ͷใ͕ೖखՄೳ ؆୯ͳ؋͜Επʔϧ࡞ΔͳΒ͜ΕͰॆ ͨͩ؋໊͕͔Βͣ ID ͔͠ͳ͍
ˠผͰऔΔ͔ϚελʔςʔϒϧΛ༻ҙ͢Δඞཁੑ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ·ͱΊ རࠜ࢞͞Μ͔Θ͍͍ ؋͜Εͷ API ؆୯ʹ Hack
Ͱ͖Δ Wireshark ͍͢͝ ߓॳظը໘͚ͩͰେମଗ͏ ؋͜Ε API ΞΫηεແବ͕ଟ͍ʢͦΓΌೣΔΘʣ ΈΜͳ؋͜Επʔϧ࡞ͬͯΈΑ͏ ؋͜Ε Hacking