WHO WE ARE
➤吉村 賢哉(@ad3liae)
https://keybase.io/ad3liae
➤ 吉村 孝広(@alterakey)
https://keybase.io/alterakey
➤ Monolith Works Inc.
Founder/Co-founder
3.
WHAT WE DO
➤Security research and development
➤ iOS/Android Apps
→Financial, Games, IoT related,
etc. (>200)
→trueseeing: Non-decompiling
Android Application Vulnerability
Scanner [2017]
➤ Windows/Mac/Web/HTML5 Apps
→POS, RAD tools etc.
➤ Network/Web penetration testing
→PCI-DSS etc.
➤ Search engine reconnaissance
(aka. Google Hacking)
➤ Whitebox testing
➤ Forensic analysis
4.
WHAT WE DO
➤CTF
➤ Enemy10, Sutegoma2
➤ METI CTFCJ 2012 Qual.: 優
勝
➤ METI CTFCJ 2012: 3位
➤ DEF CON 21 CTF: 6位
➤ DEF CON 22 OpenCTF: 4位
➤ 講演:
DEF CON 25 Demo Labs
CODE BLUE 2017 etc.
DEFCON 2016 by Wiyre Media on flickr, CC-BY 2.0
5.
DEVELOPERS OFTEN VIEW...
➤Storage
➤ 専用の領域
➤ 暗号化すれば万全
➤ Keychain
➤ 究極のセキュアストレージ
➤ TLS
➤ セキュアなチャネル
摩周湖 by Sendai Blog on flickr, CC-BY 2.0
6.
DEVELOPERS OFTEN VIEW...
➤WebView
➤ 簡単なUI実現手段
➤ XSSには注意
➤ API
➤ アプリ専用
➤ IPC (URL scheme etc.)
➤ パートナーが叩くもの
➤ Binary
➤ 改竄不能
摩周湖 by Sendai Blog on flickr, CC-BY 2.0