ããã«ãŒã¯èª°ã§ããïŒããã°ã©ãã³ã°ããé ãé¢ããŠããã»ãšãã©ã®äººã¯ããéãçãããã«éè¡ã®ã»ãã¥ãªãã£ã·ã¹ãã ã«äŸµå ¥ããæªè³ªãªç¯çœªè ã§ãã SwordfishPasswordã®HughJackmanã®ãã£ã©ã¯ã¿ãŒã®ãããªãã®ã§ãVernamã®æå·ãç Žã£ãŠãæ¿åºã®è³éãã95åãã«ãçã¿ãŸãã
ããªãã¯åæ³çã«ããã«ãŒã«ãªãããšãã§ããŸãããã®ãããªå°é家ã¯ããã³ãã¹ã¿ãŒãŸãã¯ãå«ççããã«ãŒããšåŒã°ããŸãã浞éãã¹ãäžã«äœãã§ããããäœãã§ããªãããããç¥ãå¿ èŠããããŸããããã§ãªããã°ãããªãã¯æ³åŸã«é¢ããŠããªãçŸå®çãªåé¡ãæ±ããããšãã§ããŸããæè¿ãEthical Hackerã³ãŒã¹ãéå§ããŸããããã®èšäºã§ã¯ããããã³ã°ã®æ¹æ³ãå©çãäžããæ¹æ³ããããŠæ³åŸã«åé¡ããªãæ¹æ³ã«ã€ããŠèª¬æããŸããè¡ãã
ãã·ã¢é£éŠã®æ³åŸã®äžã§ããã«ãŒãè ãããã®
ãŸããããã«ãŒãçŽé¢ããå¯èœæ§ã®ããåé¡ã«ã€ããŠè©±ããŸããããã·ã¹ãã ãžã®äŸµå ¥ãšã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ã®ååŸã«é¢é£ããã»ãšãã©ãã¹ãŠã®éåã¯ã次ã®3ã€ã®æ³åŸã«é¢é£ããŠããŸãã
- å人ããŒã¿ã«ã€ããŠïŒNo.152-FZïŒã
- æ å ±ãæ å ±æè¡ãæ å ±ä¿è·ã«ã€ããŠïŒNo.149-FZïŒã
- èäœæš©ããã³é¢é£ããæš©å©ã«ã€ããŠïŒNo.5351-1ïŒã
ãããã®æ³åŸãžã®éåã¯ãè¡æ¿äžããã³åäºäžã®è²¬ä»»ã«çŽé¢ããå¯èœæ§ããããŸãã ã¢ãŒãã«
ãããšã 13.ãã·ã¢é£éŠã®è¡æ¿æ³ïŒéä¿¡ããã³æ å ±ã®åéã«ãããè¡æ¿éåïŒã¯ãã¢ã¯ã»ã¹ãå¶éãããæ å ±ãé瀺ããããã«ãå人ããŒã¿ã®ä¿åã䜿çšãããã³é åžã®æé ã«éåãããšã300ãã20,000ã«ãŒãã«ã®çœ°éãç§ããããå ŽåããããŸããããã¯å人åãã§ããæ³äººã®å Žåã眰éã®é¡ã¯ã¯ããã«é«ããªããŸãã
ããã¯äž»ã«ããã®ãããªæ å ±ã«ã¢ã¯ã»ã¹ã§ãã人ã ãããã³é¡§å®¢ããå人ããŒã¿ãåéããçµç¹ã«é¢ä¿ããŸãã
ããšãã°ããªã³ã©ã€ã³ã¹ãã¢ã¯ãååãé»è©±çªå·ãã¡ãŒã«ã§é¡§å®¢ããŒã¹ãåéããŸãããããŠãç¡çŸãªãããŒãžã£ãŒã¯ãããŒã¿ããŒã¹ãåéãããããã³ããŒããŠãããã«è²©å£²ããããšã«ããŸããã
ãã®ãããªè¡åãæ·±å»ãªæ害ãåŒãèµ·ãããããããŒãžã£ãŒãæ³å·è¡æ©é¢ã«èŠæ ãåãåã£ãŠããªãå Žåããã®ç¯çœªã¯ã¢ãŒãã®äžã§é©æ Œãšãªãå¯èœæ§ããããŸãã13.11ããã·ã¢é£éŠã®è¡æ¿æ³å žã®ç¬¬8é ã圌ãžã®çœ°ã¯30,000ãã60,000ã«ãŒãã«ã®çœ°éã§ãã
åæ³ã«é¢ããŠã¯ããã·ã¢é£éŠã®åæ³ã®æ¬¡ã®èšäºã¯ãã»ãšãã©ã®å Žåãããã«ãŒã®æªæã®ããè ãè ãããŠããŸãã
- . 146 « ». . , , .
- . 272 « ». , . â .
- . 273 «, ». «» â , 273.
. . , , , . , .
- . 274 « , - ». , . 2010 20 .
- ã¢ãŒãããã·ã¢é£éŠåæ³ã®274.1ããã·ã¢é£éŠã®éèŠãªæ å ±ã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®éæ³ãªåœ±é¿ããç¶æ³ã¯ã¢ãŒããšå šãåãã§ãã274.ããã«é¢ããæ³å»·æ £è¡ã¯åã«ãããŸããã
ã¢ãŒãã«ãããšã272ãš273ã§ã¯ãæ倧500,000ã«ãŒãã«ã®çœ°éãšæ倧5幎ã®å®è³ªæéãåŸãããšãã§ããŸãããããŠç¹å¥ãªå Žåã«ã¯-æé·7幎ãããã«ãæ£åŒã«ã¯ãã±ãŒã¹ãéå§ããã«ã¯ãè匱æ§ãèŠã€ããŠãç¯çœªã®æå³ããªããŠãããã䜿çšããããšããŸãã
ãã³ãã¹ã¿ãŒïŒããã«ãŒãšã®éã
ãã³ãã¹ã¿ãŒã¯ãå®å šã«åæ³çã«ãæ³ã®æ å ã§åãããã«ãŒã§ãã圌ã®ä»äºã®æ¬è³ªã¯ãã»ãã¥ãªãã£ã·ã¹ãã ã®è匱æ§ãæ¢ãããšã§ãã
ããããããã€ãã®å€§ããªéãããããŸãã
- éçºè ã¯ããã³ãã¹ã¿ãŒã®è¡åã«æ°ã¥ããŠããŸããè匱æ§ãæ€çŽ¢ããããã®ãã¹ãŠã®ã¢ã¯ã·ã§ã³ã¯ãç¹å¥ãªåæã®äžã§ããŸãã¯ãã°ããŠã³ãã£ããã°ã©ã ã䜿çšããŠå®è¡ãããŸãããããã«ã€ããŠã¯å°ãåŸã§è©±ããŸãã
- , . . â k. , , â . , , .
- â . Bug Bounty . .
åºæ¬çã«ããã³ãã¹ã¿ãŒã¯ã圌ãåŸãäžé£ã®ã«ãŒã«ã«ãã£ãŠããã«ãŒãšåºå¥ãããŸãã
ãã³ãã¹ã¿ãŒã¯ããã°ããŠã³ãã£ããã°ã©ã ã«å°å¿µããããäŒç€Ÿãšã®å¥çŽã«çœ²åããåŸã§ãã浞éè©Šéšã®ããã»ã¹èªäœãä¿è·ã®ç Žãã«é¢é£ããŠãããšããäºå®ã®ããã«ãæé ã¯éåžžã«åœ¢åŒåãããŠããŸãã
ã»ãã¥ãªãã£ã®è匱æ§ãèŠã€ããŠããã®ææè ã«ææããããšã¯ã§ããŸãããããªãã¯ããã«å¯ŸããŠéåžžã«çŸå®çãªæéãåŸãããšãã§ããããã§ãã
2017 18- BKK. â , (20 30 ). , , .
, . , . «» . .
話ã¯ããŸãçµãã£ããããã¯ã¡ãã£ã¢ã§å€§ããªåé¿ãåŒã³ããŠãŒã¶ãŒã¯åã«äŒç€Ÿã®Facebookã®è©äŸ¡ãäžããŸããããããŠãå瀟ã¯æ¯å¹ŽããŒã¿ä¿è·ã«100äžãã«ä»¥äžãè²»ãããŠãããšãããŠããã誰ããæªçšã§ãããããªæããªãã°ãèŠã€ããã ãã§ããã®è©å€ã倱ãããŸããã
ãã®ç·ã¯é«æœãªæå³ãæã£ãŠããŸãã-圌ã¯ãã±ãã販売ã·ã¹ãã ã®ç©Žãææãããããæ確ã«ç€ºãããã£ãã®ã§ãããããåæã«ã圌ã®è¡åã¯äŸç¶ãšããŠã»ãã¥ãªãã£éåãšèŠãªãããå¯èœæ§ããããŸãããããŠãããã¯åäºäºä»¶ã§ãã
æè¡çã«ã¯ãäŒç€Ÿã¯åœŒã«å¯ŸããŠèµ·èšŽããããšã«ãããŠå®å šã«æ£ããã£ãããã®ç·ã®æå³ãäœã§ããã圌ã¯æ³åŸãç Žã£ãããããŠãå ¬ã®å ±é³Žã ãã圌ãæ¬åœã®èšèããæã£ãã
ãã°ããŠã³ãã£ïŒæ£ããåå ããæ¹æ³
ã»ãšãã©ã®å€§äŒæ¥ã¯BugBountyãå®è¡ããŠããŸããããã¯ããœãããŠã§ã¢ãŸãã¯Webãµã€ãã®äŒæ¥ãèŠã€ãã£ãè匱æ§ã«å¯ŸããŠå ±é ¬ãæäŸããç¹å¥ãªããã°ã©ã ã§ããæªçšãè匱æ§ã®çµæã«å¯ŸåŠããããããèŠã€ãããã°ã«ãéãæãæ¹ãäŒæ¥ã«ãšã£ãŠããæçã§ãã
ãããã®ããã°ã©ã ã®ã»ãšãã©ã¯ãHackerOneãšBugCrowdã§ãã¹ããããŠããŸãã
ããšãã°ãGoogle APIãNginxãPayPalãGitHubãValveã®BugBountyããã°ã©ã ã¯æ¬¡ã®ãšããã§ãããããã®ããã°ã©ã ã§èŠã€ãã£ãåãã°ã®å¹³åãã¬ãã¢ã ã¯1,000ãã«ã§ãããšã©ãŒããšã«50ãã«ãã100ãã«ãæäŸããäžå°äŒæ¥ã¯æ°å€ããããŸãã
ãã³ã¿ãŽã³ã§ãããã°ããŠã³ãã£ãç«ã¡äžããŸããïŒããã«ãŒããã³ã¿ãŽã³ã®ã»ãã¥ãªãã£ã·ã¹ãã ããããã³ã°ããç±³åœæ¿åºãããéãããããã®ã¯å€¢ã§ãã
ããããå ¬éããããã°ããŠã³ãã£ã§ãããã©ãã§ãå£ããŠç©Žãæ¢ãããšãã§ãããšããæå³ã§ã¯ãããŸãããããã°ã©ã ã®èª¬æã§ã¯ãææè ã¯ã©ã®è匱æ§ãèæ ®ãããããèŠå®ããŸãã
ããšãã°ãUberã¯ããã°ããŠã³ãã£ããã°ã©ã ã«å«ãŸããŠãããã®ãšå«ãŸããŠããªããã®ã«ã€ããŠéåžžã«è©³çŽ°ã«èª¬æããŠããŸãã
å瀟ã¯ãããŒã¿ã¢ã¯ã»ã¹ããã³ã¹ãã¬ãŒãžã·ã¹ãã ããã£ãã·ã³ã°ãæ¯æãããã³è«æ±ã®æ©äŒããŠãŒã¶ãŒããã³äŒç€Ÿã®åŸæ¥å¡ã«ããäžæ£ãªã¢ã¯ã·ã§ã³ã®è匱æ§ãèŠã€ããããšèããŠããŸãããã ãããã®ããã°ã©ã ã«ã¯ãäžè¬çãªã¢ããªã±ãŒã·ã§ã³ã®ãã°ãäžæ£ã¬ããŒãããœãŒã·ã£ã«ãããã¯ãŒã¯ãé»åã¡ãŒã«ãã¥ãŒã¹ã¬ã¿ãŒã®æäœã«é¢ãããã°ã¯å«ãŸããŠããŸããã
ãããããŠãŒã¢ã¢ã®ã»ã³ã¹ãããã°ããã¹ãŠãããŸããããŸããæªæãã®ã¢ã¯ã·ã§ã³ã®äžã«ã¯æ¬¡ã®ãã®ãããããã§ãã
ããŠãŒããŒäºåæã«å ¥ãã©ãã§ãããããããã¹ãæããŠãç©ºè ¹ã®ã¢ã©ã€ã°ãã®æã解ãæŸã€ããããŠã¹ã¿ãããæ°ãåããããŠããéãããã¯è§£é€ãããã¯ãŒã¯ã¹ããŒã·ã§ã³ã«æšãŠãããã¿ãŒããã«ããã€ãžã£ãã¯
ãæ¿ç©ºè ¹ã¢ã©ã€ã°ããšçºäœç¡æã®ç«¯æ«ãŸãã¯ã¯ãŒã¯ã¹ããŒã·ã§ã³ã解æŸããã©ãã§ãããããæ£ä¹±ããŠãŒããŒãªãã£ã¹ãžã®åå ¥åŸæ¥å¡ãæ··ä¹±ããŠããéã
ãã°ããŠã³ãã£ã詳现ã«èª¬æãããŠããã»ã©ããã³ãã¹ã¿ãŒã¯ãè©Šè¡ããã³ãã¹ããã§ããããšãšå®è¡ããŠã¯ãªããªãããšãç解ãããããªããŸãã
åæã«ãéåã§ããªãäžè¬çãªã«ãŒã«ããããŸããããšãã°ããŠãŒã¶ãŒããŒã¿ããŒã¹ã«è匱æ§ãèŠã€ãã£ãå Žåãå人ããŒã¿ã®ããŠã³ããŒããè©Šã¿ãããšã¯ã§ããŸãããããã°ã©ã ã«åå ãããšããŠããæ³åŸéåãšã¿ãªãããšãã§ããŸããããã§ã¯ãŠãŒã¶ãŒã®æš©å©ã䟵害ãããŠããããããã°ããŠã³ãã£ã¯é¢ä¿ãããŸããã
ãã·ã¢ã®æµžéè©Šéšåžå Žã掻çºã«çºå±ããŠããŸãããã§ã«å€§äŒæ¥ãšååããŠããå€ãã®äž»èŠãªãã¬ãŒã€ãŒãããŸããããšãã°ãDigital SecurityãSTC VulkanãGroup-IBãBI.ZONEãKasperskyLabãããããåžå Žã§ã®ç«¶äºã¯ãŸã ããªãäœãã®ã§ãããªãã¯éåžžã«å¿«é©ã«ãããŠå人çã«åãããšãã§ããŸãã
Gazpromãéè¡çµç¹ã®ãããªäžéšã®å€§äŒæ¥ã¯ãæ©å¯ããŒã¿ã第äžè ã«é瀺ããªãããã«ããã³ãã¹ã¿ãŒã®åå¥ã®å éšéšéãäœæããŠããŸãã
ãããã£ãŠããã³ãã¹ã¿ãŒã«ââã¯ããã€ãã®å¯èœæ§ããããŸãã
- ãããã®å€§äŒæ¥ã®1ã€ã«åå ããŠãã ãããäž»ãªãã©ã¹ã¯ãå®å®ãã絊äžãšæ³åŸã«é¢ããä»®æ³çãªåé¡ãããªãããšã§ãããããåæã«ãå€ãã®ãã³ãã¹ã¿ãŒãåªåããŠããããã«ãããããã®ãéã皌ãããšã¯ããŸããããŸããã
- åã ã®èµ·æ¥å®¶ãéãããå¥çŽã®äžã§åããŸããäž»ãªå©ç¹ã¯ãã¹ãã·ã£ãªã¹ããèªåã§äŸ¡æ Œãèšå®ããããšã§ãããããåæã«ãæ³çãªåŽé¢ããä¿éºããããããã«ã¯ãåŽäœ¿é¢ä¿ã®æ çµã¿ã®äžã§åŒè·å£«ãšç·å¯ã«ååããå¿ èŠããããŸãããããŠã競äºçžæã¯ç ã£ãŠããŸããã
- Bug Bounty. â . , . , , Bug Bounty.
ãã°ããŠã³ãã£ã«åå ããã®ã¯ç°¡åã§ããå®éãæ¬è³ªçã«ãããã°ã©ã ã®éå§ã«é¢ããã¡ãã»ãŒãžã¯ããã¹ãŠã®ãŠãŒã¶ãŒãåãå ¥ããããšãã§ãããªãŒãã³ãªãã¡ãŒã§ããããã«äœæ¥ãéå§ã§ããŸããåå ããããã«è¿œå ã®åæã¯å¿ èŠãããŸããã
äžæ£ãªäŒæ¥ãé²ãããã«ãHackerOneãµã€ããšBugCrowdãµã€ããä»ããŠäœæ¥ããããšããå§ãããŸããããããä»ããŠãã°ã¬ããŒããç»é²ããŠéä¿¡ããã ãã§ãã
å¯äžã®ã«ãŒã«ã¯ãããã°ã©ã ã®èª¬æã詳现ã«èªãããšã§ããäŒç€ŸãããŒã¿ããŒã¹ã®è匱æ§ã«ãéãæããšæžããŠããå Žåã¯ãããã§æ€çŽ¢ããã ãã§æžã¿ãŸããã©ããã§ãã°ãèŠã€ãããšããŠãããã®ä»£éã¯æ¯æãããŸãããéã«ãåé¡ãçºçããå¯èœæ§ããããŸãã
2015 Instagram. Ruby-, .
, PostgreSQL. 60 Instagram Facebook. , â â «password» «instagram».
Amazon Web Services, 82 S3. : Instagram, SSL-, API-, email-, iOS Android. , Instagram.
Facebook. 2500 . , Bug bounty Facebook . , .
ãããã£ãŠãèŠå®ããããã°ããŠã³ãã£ãã€ã³ãã«åŸãããšã¯å¿ é ã§ããããã§ãªããã°ãããªãã¯ããŒãã¹ã§ã¯ãªããåçºãåããããšãã§ããŸãã
ãã³ãã¹ã¿ãŒãã§ããã¹ãããš
ãã³ãã¹ã¿ãŒã¯ãæ®éçãªå µå£«ãã§ãããé«åºŠã«å°éåãããã¹ãã·ã£ãªã¹ãã§ããããŸãã圌ã¯ããã°ã©ãã³ã°ã®å€ãã®åéã§å¹ åºãç¥èãæã¡ãåæã«1ã€ä»¥äžã®åéã§æ·±ãã¹ãã«ãæã£ãŠããå¿ èŠããããŸãã
äžè¬ã«ããžã¥ãã¢ãããã¬ãŒã¿ãŒã¯æ¬¡ã®ç¥èãæã£ãŠããå¿ èŠããããšèããããŠããŸãã
- WindowsãLinuxã®ç®¡çã
- 1ã€ä»¥äžã®ããã°ã©ãã³ã°ã®ç¥èïŒPythonãphpãPerlãRubyãJavaScriptãBash;
- HTMLã®ç¥è;
- åºæ¬çãªãããã¯ãŒã¯ãããã³ã«ïŒTCP / IPãICMPïŒ/ãããã¯ãŒã¯ãµãŒãã¹ïŒãããã·ãVPNãSambaãADïŒ;
- ãããã³ã«ïŒHTTPãFTPãDNSãSSH;
- SQLããŒã¿ããŒã¹ïŒDDLãDMLãªã©ïŒãMySQLãSQL ServerãPostgreSQLãOracleã
ãã¹ãŠãå®å šã«ç¥ãå¿ èŠã¯ãããŸããããå°ãªããšãäžèšã®PLããããã³ã«ãããã³ããŒã¿ããŒã¹ã®åºæ¬çãªç¥èãå¿ èŠã§ãã
ãŸããBurpSuiteãSqlMapãNmapãIP ToolsãAcunetixãªã©ã®äŸµå ¥ãã¹ãããã°ã©ã ã®äœ¿çšæ¹æ³ãåŠã¶å¿ èŠããããŸãã
å®éãããããéçºãŸãã¯ãã¹ãã®ç¹å®ã®ããã¯ã°ã©ãŠã³ãããã§ã«æã£ãŠããã¹ãã·ã£ãªã¹ãã®ããã«æµžéãã¹ãã«è¡ãããšãæšå¥šãããçç±ã§ãããžã¥ãã¢ã¬ãã«ã§ããå¿ èŠãªç¥èã®éã¯èšå€§ã§ãã
ãã³ãã¹ã¿ãŒãšããŠå匷ããå Žæ
ãããŠæåŸã«ããã³ãã¹ã¿ãŒã®è·æ¥ã«å¿ èŠãªãã¹ãŠã®æ å ±ãå ¥æã§ããããã€ãã®äººæ°ã®ãããªãœãŒã¹ãåéããŸããã
- Hackaday. , , . , .
- EC-Council CEH. , CEH. .
- Cybrary. . , .
- Skillfactoryã®è·æ¥å«ççããã«ãŒãç§ãã¡èªèº«ãæè¿ã倧èŠæš¡ãª10ãæã®å æ¬çãªã³ãŒã¹ãéå§ããŸããããã®ã³ãŒã¹ã§ã¯ã浞éãã¹ãã®ãã¹ãŠã®è€éããšããªãã¯ãæããŠããŸããå®éã®ãã³ãã¹ã¿ãŒã¯çµéšãå ±æããå®éã«ã¯ããœãããŠã§ã¢ãWebãããžã§ã¯ãã®è匱æ§ãèŠã€ããã®ã«åœ¹ç«ã¡ãŸãã
ãããŠãå®è·µçãªã¹ãã«ãåäžãããããšãã§ããããã€ãã®ãµã€ãïŒ
- HackThis !! -ããã§ã¯ãã²ãŒã ã¢ãŒãã§ãããã³ã°ã¹ãã«ãã¢ããã°ã¬ãŒãããåæã«ãããè¡ãæ¹æ³ãåŠã¶ããšãã§ããŸãã
- ç§ãæ ¹ä»ãããŠãã ãã-ãã³ãã¹ã¿ãŒã®ããã®380以äžã®å®çšçãªã¿ã¹ã¯ïŒåå¿è ãããããŸã§ã
- Try2Hackã¯ããã³ãã¹ãã®ç·Žç¿ã®ããã®æãå€ããªãœãŒã¹ã®1ã€ã§ããåºæ¬çãªã¬ãã«ã§ã¯ããŸãã«ããã§ãã
- Webgoatã¯ã浞éãã¹ãã®åºæ¬ãåŠã³ãããã«ãã®ç¥èãå®è·µã§ãããçŸå®çãªã¬ãã¹ã³ããŒã¹ã®ç°å¢ã§ãã
- Google Gruyere â , . , .
- OverTheWire â . 50 , .
ããã«ãŒã®èª¿æ»ã« ãããšãäŸµå ¥ãã¹ãã¯æªæã®ãããããã³ã°ãããããã«æçã§ãããšèããããŠããŸããäŒæ¥ã¯ãã·ã¹ãã ã«è匱æ§ãèŠã€ãã人ã«ååãªå ±é ¬ãæ¯æã£ãŠããŸããå€ãã®ããã«ãŒã¯ãå ¬åŒãã€åæ³çã«ãã以äžã®åå ¥ãåŸãããã°ãDarknetã«é£ã³èŸŒãå¿ èŠã¯ãããŸããã
ããªãããã³ãã¹ã¿ãŒã«ââãªãããã®ãªããéã¯éãããŠããŸããããããæã«æ°äžãã«ã皌ãè¯ããã³ãã¹ã¿ãŒã«ââãªãããšã¯ã¯ããã«å°é£ã§ããå·¥èžåãšããããã¯èžè¡ã®ããã«èŠããŸããããã®æºåã¯ã§ããŠããŸããïŒãããªãã©ããïŒ
ãŸããHABRããã¢ãŒã·ã§ã³ã³ãŒãã¯ããããŒã«ç€ºãããŠããå²åŒã«ããã«10ïŒ ãæäŸããŸãã
- Skillfactoryã«ããè·æ¥å«ççããã«ãŒ
- ããŒã¿ãµã€ãšã³ã¹ã®ãªã³ã©ã€ã³ããŒããã£ã³ã
- ããŒã¿ã¢ããªã¹ãã®è·æ¥ããŒããããã¬ãŒãã³ã°ãã
- ããŒã¿åæãªã³ã©ã€ã³ããŒããã£ã³ã
- Data Science
- «Python -»
E