Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
艦これHacking
Search
ぽんこつ
November 10, 2013
Technology
0
3.8k
艦これHacking
艦これAPIをWiresharkで調べてみた
ぽんこつ
November 10, 2013
Tweet
Share
More Decks by ぽんこつ
See All by ぽんこつ
Cocos2dx(Ver2)が闇な話
ponkotuy
0
210
Other Decks in Technology
See All in Technology
変化するコーディングエージェントとの現実的な付き合い方 〜Cursor安定択説と、ツールに依存しない「資産」〜
empitsu
4
1.4k
セキュリティについて学ぶ会 / 2026 01 25 Takamatsu WordPress Meetup
rocketmartue
1
300
Greatest Disaster Hits in Web Performance
guaca
0
250
2026年、サーバーレスの現在地 -「制約と戦う技術」から「当たり前の実行基盤」へ- /serverless2026
slsops
2
250
会社紹介資料 / Sansan Company Profile
sansan33
PRO
15
400k
[CV勉強会@関東 World Model 読み会] Orbis: Overcoming Challenges of Long-Horizon Prediction in Driving World Models (Mousakhan+, NeurIPS 2025)
abemii
0
140
Context Engineeringが企業で不可欠になる理由
hirosatogamo
PRO
3
590
CDKで始めるTypeScript開発のススメ
tsukuboshi
1
440
AWS Network Firewall Proxyを触ってみた
nagisa53
1
230
20260208_第66回 コンピュータビジョン勉強会
keiichiito1978
0
140
予期せぬコストの急増を障害のように扱う――「コスト版ポストモーテム」の導入とその後の改善
muziyoshiz
1
1.9k
usermode linux without MMU - fosdem2026 kernel devroom
thehajime
0
230
Featured
See All Featured
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
287
14k
Introduction to Domain-Driven Design and Collaborative software design
baasie
1
590
My Coaching Mixtape
mlcsv
0
48
A Soul's Torment
seathinner
5
2.3k
Exploring the Power of Turbo Streams & Action Cable | RailsConf2023
kevinliebholz
37
6.3k
Navigating Team Friction
lara
192
16k
Marketing Yourself as an Engineer | Alaka | Gurzu
gurzu
0
130
Efficient Content Optimization with Google Search Console & Apps Script
katarinadahlin
PRO
1
320
Design and Strategy: How to Deal with People Who Don’t "Get" Design
morganepeng
133
19k
GraphQLの誤解/rethinking-graphql
sonatard
74
11k
Agile that works and the tools we love
rasmusluckow
331
21k
Let's Do A Bunch of Simple Stuff to Make Websites Faster
chriscoyier
508
140k
Transcript
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ؋͜ΕHacking 2013 11 ݄ 09
؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ΆΜͭ͜ ΆΜͭ͜ʢ@ponkotuyʣͰ͢ ேى͖Εͳͯ͘༗څ͕Βͳ͍ఔͷࣾச ։ൃ Scala +
Play ͱ CoeeScript ڥ Emacs or IntelliJ(IDE) + Ubuntu ϓϨθϯ Emacs ͷ org-mode + TEX + Beamer ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ͖ͳ؋່རࠜ͞ΜͰ͢ E-2 ߈ུͰແͯ͘͠Ε·ͨ͠ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ؋͜Εʜͬͯ·͢ΑͶʁ ؋͜Εͱ ఇࠃւ܉ͷ܉؋່͕ʹͳͬͯ ҭͯͯΩϟ οΩϟϑϑ͠ͳ͕Β ւҬΛಥഁ͢ΔͨΊʹࢿݯཏ൫ͱઓ͏
ήʔϜͰ͢ʂ ˞࣮ࡍઓಆӡཁૉ͚ͩͳͷͰɺҭͱฤͱࢿݯྔ͕શͯ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ͱ͍͏Θ͚Ͱ ࠓճ؋͜Εͷ API Λ Hacking ͯ͠Έ·͠ΐ͏ʂ
؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ωοτϫʔΫௐࠪํ๏ ؋͜ΕʢFlashʣͷ௨৴ΛௐΔํ๏ʢࢥ͍ͨൣғʣ શύέοτ௨৴Λऔಘͯ͠ FilterʢࠓճΔํ๏ʣ ಛఆϖʔδ͚ͩ Proxy
Λט·ͤΔ .NET ͷ IE ܥϥΠϒϥϦʢʁʣ ؋͜ΕϒϥβܥԼ 2 छྨͷํ๏Ͱड ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ tcpdumpͱ CUI ಛఆωοτϫʔΫσόΠεͷύέοτௐࠪ͢Δπʔϧ ͍ํάάΕ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ͬͯΈΔ ؋͜Εͷૢ࡞Λͨ͠ͱ͖ྲྀΕΔύέοτΛղੳ 125.6.189.39 ͷ Port80 ͱ௨৴͍ͯ͠Δ͜ͱ͕͔Δ
-X ͰόΠφϦσʔλ͕ݟΕΔ ͕ͩૉਓʹ HTTP Ͱ JSON ΓͱΓ͍ͯ͠Δ༷ࢠ͠ ͔͔Βͳ͍ ͜Μͳݪ࢝తͳπʔϧͬͯΒΕΔ͔ʔʢόʔϯʂ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ Wiresharkͱ GUI ύέοτΩϟϓνϟ Filter HTTP ղੳࡁΈσʔλΛ
Export ࠓճຆͲ͜Ε͚ͩͰ͍͚·ͨ͠ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ؋͜ΕͰWireshark Ubuntu ͳΒ apt-get wireshark ཁ
root lter http and ip.addr == 125.6.189.39 ͜ͷঢ়ଶͰૢ࡞͢Δͱσʔλ͕ྲྀΕͯ͘Δ ͋ͱ͖ͳσʔλΛબΜͰ export ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ exportͨ͠ϑΝΠϧ ຊޠ͕ unicode unicode ରԠͷ JSON
ύʔα͕ඞཁ Python Ͱσίʔυͯ͠ PrettyPrint ͠·ͨ͠ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ௨৴ͷશମతͳಛ ҉߸Խ͞Εͯͳ͍ʢ͞ΕͯͨΒརࠜ͞ΜτʔΫͯͨ͠ʣ api_result Ͱ 1 ͓ͦΒ͘
Success api_result_msg ͰޭͷจࣈΛฦ͢ʢҙຯແͦ͞͏ʣ api_data ҎԼʹ༗༻ͳσʔλ͕͋Δ MP3ɻϞϊϥϧͷ 48kHzɺ56kbps ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ߓॳظը໘ ͜ͷը໘ʹભҠ͢Δ࣌ͷ௨৴ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ߓॳظը໘2 actionlog ӈԼͷԋश݁ՌͳͲͷ׆ಈ log logincheck ࢿݯ૿ྔɻೝূܥͰͳ͍
material ࢿݯྔɻࢿݯ 1 ੴ༉ 2 ༀ 3 మ߯ 4 ϘʔΩ 5 ߴݐࡐ 6 ߴम෮ࡐ 7 ։ൃࢿࡐɻlogincheck ͷฦΓԿͷҝʹ͋Δͷ͔ɻ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ deck_port ؋ୂใ api_name ؋ୂ໊ api_ship ؋່൪߸ʢೖखॱʹ
increment ͍ͯ͘͠ IDʣͷ Ϧετ api_mission ԕσʔλ [ւҬ, ԕ ID, ԕؼ࣌ؒ, ʁ] ԕσʔλ͕؋ୂใʹͳͬͯΔͷڵຯਂ͍ɻ͜ΕͰԕ νΣ οΧʔ࡞ΕΔ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ndock ೖڎใ api_complete_time ྃ࣌ؒ api_item1ʙ4 ࣋ͪใ
api_ship_id ؋່൪߸ ͜ΕͰೖڎνΣ οΧʔ࡞Ε·͢Ͷ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ship2 ؋່ͷৄࡉσʔλ HP ͷσʔλͳͲεςʔλεશ෦ ཕܸͳͲඋલޙͷ ࠷େ
HP උલޙͷ͕ແ͍ͷͰɺࠓޙඋͰ HP ্͕Δܥඋແͦ͞͏ͩͱ͔Δ api_luckey ɺྫ͑ඈཾ [40, 89]ɺརࠜ [10, 59] ͳͲ ͋ͱ deck_port ؙ͕͝ͱೖ͍ͬͯΔɻҙຯͳ͍ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ basic ઓදࣔͰݟΕΔϢʔβσʔλ+Ո۩ใͳͲ ؾʹͳΔͷ max_kagu Ո۩ͷ্ݶΛ࣮͢Δ༧ఆͩͬͨʁ play_time
͋Δͱศརͦ͏͕ͩ 0 ʹͳ͍ͬͯΔ pt_challenged ύʔςΟʔػೳ͔ʁ কདྷ࣮༧ఆ or Deprecated ͳΘΕ͍ͯͳ͍ม͋Γ ͜ͷΑ͏ͳಾม basic ͷΈݟΒΕΔ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ߓॳظը໘·ͱΊ ߓॳظը໘͚ͩͰ૬ͷใ͕ೖखՄೳ ؆୯ͳ؋͜Επʔϧ࡞ΔͳΒ͜ΕͰॆ ͨͩ؋໊͕͔Βͣ ID ͔͠ͳ͍
ˠผͰऔΔ͔ϚελʔςʔϒϧΛ༻ҙ͢Δඞཁੑ ؋͜Ε Hacking
Introduction Tools ࣮ࡍʹղੳͯ͠Έͨ ·ͱΊ ·ͱΊ རࠜ࢞͞Μ͔Θ͍͍ ؋͜Εͷ API ؆୯ʹ Hack
Ͱ͖Δ Wireshark ͍͢͝ ߓॳظը໘͚ͩͰେମଗ͏ ؋͜Ε API ΞΫηεແବ͕ଟ͍ʢͦΓΌೣΔΘʣ ΈΜͳ؋͜Επʔϧ࡞ͬͯΈΑ͏ ؋͜Ε Hacking