é«ããŠé«ããããã³ã°ã®åå
¥éå£ããã£ãšäžããŸã!
ãããã³ã°å€§äŒ(CTF)åºå ŽãåããŠã§ãã?
äžã€ã®è匱æ§çè«(Buffer OverFlow)ãšåºç€åé¡ã"å®ç§ã«"çè§£ããŠè§£ã
ãããã³ã°å€§äŒ(CTF)ã«åºé¡ãããã·ã¹ãã ãããã³ã°(Pwnable)åé¡ãè§£ãã®ã«å¿
èŠãªãã¹ãŠã®ç¥èæŽç
ãããã³ã°å€§äŒ(CTF)ã®åé¡ç¶æ³ãšè§£ãã¹ãåé¡ãçè§£ãã
èªãéå¶äžã®Wargameãµã€ããéããŠ
å®éã®ãããã³ã°å€§äŒã®ç°å¢ãã®ãŸãŸã«24æéå®ç¿ã§ããŸãã
ç¡æã¹ã¯ãªãã&ããã°æçš¿æäŸ â
è¬çŸ©ã®ãã¹ãŠã®å
容ãçã蟌ãã ã¹ã¯ãªãããšããã°æçš¿ãæäŸããããŸãã
- ç¡æé»åæžç±ïŒãªã³ã¯
- ç¡æè¬çŸ©è³æ:æåã®è¬çŸ©è³æããããŠã³ããŒã(pdf)
- ç¡æã¹ã¯ãªããïŒæ¯ææ¥ã®è¬çŸ©ããŒã確èª
çèšã®å¿é
ãªãããªã©ãã¯ã¹ããŠææ¥ãšå®ç¿ã ãã«éäžããŠããã ããã°å€§äžå€«ã§ãã
ãã£ãäžã€ã®åé¡ã ãããå®ç§ã«è§£ããŸãã
ããã«ãŒãšããŠã®ããã³ãšå€¢ãæã£ãŠãããã®ã®ãé«ãåå
¥éå£ã«æ«æããæ¹ã
ã®ããšãããç¥ã£ãŠããŸãããããã³ã°ãæ¬åœã«åããŠè§Šãã人ã§ããèªãåé¡ã®ãã¹ãŠã®éçšãäœéšãã解決ã§ããããã«ããããšããä»åã®è¬çŸ©ã®ç¹åŸŽã§ãã
ãããã³ã°å€§äŒ(CTF)ã«åããŠææŠããŠã¿ãããããã³ã°ã®åµ
ã·ã¹ãã ãããã³ã°(Pwnable)ãšæ»æ(Exploitation)ã«ã€ããŠåŠç¿ãããæ¹
ã»ãã¥ãªãã£ã«èå³ãããããé«ãåå
¥éå£ã«å°é£ãæããŠããæ¹
ãåé¡ãäžã€ã ãè§£ããã§ãã?ã
ã¯ãããã£ãäžã€ã®åé¡ã ããè§£ããŸããäžã€ã®åé¡ãè§£ãããšããããšã¯ãããã«é¢é£ããæ°åãæ°çŸã®åé¡ãè§£ãããšããããšãæå³ããŸãããããã³ã°åé¡ã¯åçŽãªæèšåé¡ã§ã¯ãªããããäžã€ã®åé¡ã§ãå®ç§ã«äœåŸããããšãæ£ããæ¹æ³ã§ãã
ãå®ç§ã«è§£ãã£ãŠ?ã
ãã£ãäžã€ã®åé¡ãè§£ãã ãã§ãªããCèšèªãã³ã³ãã¥ãŒã¿ã¢ãŒããã¯ãã£ãè匱æ§çè«ããšã¯ã¹ããã€ãã³ãŒãã®äœæãªã©ããããã³ã°åé¡ãè§£ãããã«å¿
èŠãªãã¹ãŠã®ç¥èãæ±ããŸãããããéããŠé¢é£ç¥èãå®ç§ã«äœåŸã§ãããããµããŒããããã®åŸå¿çšå
容ãåŠç¿ããéã«ã匷åºãªåºç€ãšãªãã§ãããã
ð¡ 倩æã®ããã®è¬çŸ©ã§ã¯ãªããã»ãã¥ãªãã£ã«èå³ã®ããæ¹ã
ãžã®åå
¥éå£ãäžããææ¥ã§ãã
åŠç¿å
容ã
確èªããŠã¿ãŸãããã
Linuxã®åçãããã¬(GDB)ãå©çšããŠããã°ã©ã ãåæããŸãã
åæããããã°ã©ã ã«å
èµãããè匱æ§ã詳现ã«åæããŸãã
è匱æ§ãšæ»æææ³ã®åçãçè§£ããããã«ã³ã³ãã¥ãŒã¿æ§é ãåŠç¿ããŸãã
ã ããããã®è¬çŸ©ã§ã¯!
- â
ãããã³ã°å€§äŒ(CTF)ã·ã¹ãã ãããã³ã°(Pwnable)åé¡ã®è§£çãè¡ããŸãã
- â
ã¡ã¢ãªä¿è·ææ³ãšé«åºŠãªãããã³ã°æ»æææ³ã®åŠç¿ã®ããã®åºç€ç¥èãç¿åŸããŸãã
æ¬è¬åº§ã§ã¯! â
ãããã³ã°å€§äŒ(CTF)ã·ã¹ãã ãããã³ã°(Pwnable)åé¡ã®è§£èª¬ãè¡ããŸãã â
ã¡ã¢ãªä¿è·ææ³ãšé«åºŠãªãããã³ã°æ»æææ³åŠç¿ã®ããã®åºç€ç¥èãç¿åŸããŸãã
⢠KITRI BoB(Best Of the Best) è匱æ§åæãã©ãã¯ä¿®äº
⢠éåœç§åŠæè¡é¢(KAIST) æ
å ±ä¿è·å€§åŠé¢ 修士課çš
⢠äžå€®å€§åŠæ ¡ ç£æ¥ä¿å®åŠç§ 忥
Q&A ð¬
Q. ãããã³ã°ãããã«ã¯å¿
ãCèšèªãã§ããªããã°ãªããŸããã?
ã¯ãããã ããæ¬è¬çŸ©ã§ã¯çŽæ¥çã«Cèšèªã䜿çšããå
容ã¯ãããŸãããå®ç¿ããããã°ã©ã ã®ãœãŒã¹ã³ãŒããåæã§ããçšåºŠã«ãCèšèªã®åºç€å
å®¹ãæ±ããŸãã®ã§ããå¿é
ãªãã
Q. è¬çŸ©ãåããåã«ç¥ã£ãŠããã¹ãç¥èã¯ãããŸãã?
æ¬è¬çŸ©ã¯ãããæ·±åãããããã³ã°åŠç¿ã®ããã®å®ç§ãªåºç€ç¥èãç¿åŸããããšãç®æšãšããŠããŸãããããã³ã°ãCèšèªãäžåºŠãå匷ããããšããªãæ¹ã®ããã«æºåãããè¬çŸ©ã§ãã
ãããã³ã°ãåããŠå匷ãã人ãã³ã³ãã¥ãŒã¿ãèµ·åããŠããå®éã®Wargameãµã€ãã®ãããã³ã°åé¡ãè§£ããŸã§ã®ãã¹ãŠã®éçšãäžç·ã«é²ããŠãããŸãã®ã§ãæ°æ¥œã«è¬çŸ©ã ãã«éäžããŠããã ããã°å€§äžå€«ã§ãã
Q. ç°å¢èšå®ã«æéãããããããŠé£ããã§ããäœãå§ããããŠããªãã®ã§ãããç§ã«ã¯æèœããªãã®ã§ããããã
絶察ã«ãããªããšã¯ãããŸãããäœãå§ããŠããªãã ãªããŠãç°å¢èšå®(Configuration)ã¯ã·ã¹ãã ãããã³ã°ã«ãããŠéåžžã«éèŠãªç¥èã§ããå®éã«ãããã³ã°ãç¹ã«ã·ã¹ãã ãããã³ã°ã§ã¯ç®æšãšããæ»æå¯Ÿè±¡ããã°ã©ã (ãã€ããª)ã®å®è¡ç°å¢ãæ§ç¯ããããšãéåžžã«éèŠãªã®ã§ãã
åœå
å€ã®äž»èŠãããã³ã°å€§äŒã§ãã粟å¯ãªæ»æã®ããã«VM(Virtual Machine)ãdockerãéããç°å¢èšå®(Configuration)ã«åé¡è§£æ±ºäž40~50%以äžã®æéãè²»ãããªããã°ãªããªãã»ã©ãç°å¢èšå®ã¯ã·ã¹ãã ãããã³ã°ã®ããã«å¿
ãçµãŠæ
£ããã¹ãéçšãšç¥èã§ãã
ð¢ åè¬åã«ã確èªãã ãã
- è¬çŸ©ã§ã¯Ubuntu 22.04 LTS ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã䜿çšããŸãã
- VMwareãpwntoolsçã®ãããã³ã°ããŒã«ã䜿çšããå®ç¿ã®ããã«ã¯8GB以äžã®RAMãšååãªãã£ã¹ã¯å®¹éãåããPCãå¿
èŠã§ãã
- äºåã«VMwareã®ã€ã³ã¹ããŒã«ããã³ä»®æ³ç°å¢ã®æ§ç¯ãå¿
èŠã§ãã(ã€ã³ã¹ããŒã«ã¬ã€ã)
- Cèšèªã®ææ³ãç¥ããªããŠãåè¬å¯èœã§ãããç¥ã£ãŠããã°ããå°ã楜ã«ãªããŸãã
- æ¯åã®ææ¥ããšã«è¬çŸ©ã¹ã¯ãªãããšç¡æããã°æçš¿ãæäŸãããŸãã®ã§ãå¥éçèšãªãã§è¬çŸ©ã ãã«éäžããŠããã ããã°å€§äžå€«ã§ãã