Slides of my #BHUSA talk Shade BIOS has been uploaded!
blackhat.com/us-25/briefings…
Github link is below github.com/FFRI/ShadeBIOS/tr…
Thank very much for attending my presentation!
I’m sorry I wasn’t able to talk to many of you, as I was feeling unwell throughout the #BlackHatEvents
Our talk at #BHUSA @BlackHatEvents Briefings has been accepted!
This is a presentation on an initiative to make the BIOS usable even after the OS has booted, enabling malbehavior to occur solely within the BIOS, independent of the OS.
blackhat.com/us-25/briefings…
I will be presenting at #BlackHatUSA briefings on Thursday, August 8 at 11:20 in South Seas CD, Level 3.
It is about backdoors that infect via PCIe devices, so if you are interested in UEFI security, feel free to drop by!
レジストリでのキーマップ変更
regeditで
「HKLM\SYSTEM\CurrentControlSet\Control\Keyboard Layout」
を開き、バイナリ値の「Scancode Map」というキーを作成する
バリューは画像のようにセット
キーを表す値はScancodeで、
bsakatu.net/doc/scancode/
の Scancode Set 1 の Make の列を見ればいい
Railsで API-Gateway + Lambda のAPIを叩く
Controllerアクションにapi叩くpostリクエストを送るように書けばいいが、
・Content-Type: application/jsonに指定
・送る時、hash→json。受け取るときjson→hashに変換
の二つに気を付ける
#俺のRailsメモ #俺のAWS
API Gateway + Lambda
POSTのAPIの作成
1: Lambdaをyoutubeの様に作成
2: 画像のようにlambda関数をセット
3: API Gatewayを動画の様に作成(画像の所注意)
4: LambdaのトリガーにGatewayセット
5: pythonとかでリクエストして使う
※ステージ忘れずに
参考URL
youtube.com/watch?v=pSNnOC36…
#俺のAWS
HTML Injection
フィッシングの偽フォーム挿入等で使われる
・MarkdownもHTMLなので注意
・HTMLエンティティの入力に注意
・クオートの最初だけ挿入し、ユーザー入力の後に最後のクオートを追加してCSRFトークンとか盗める
コンテンツスプーフィング
テキストで"~して下さい"と騙す
#俺のカマキリ本