ã¿ã¤ãã¹ã¯ã¯ããã£ã³ã° (typosquatting) ã¨ã¯URLãã¤ã¸ã£ããã³ã°ã¨ãå¼ã°ããå½¢æ ã®ãµã¤ãã¼ã¹ã¯ã¯ããã£ã³ã°ã§ãã¤ã³ã¿ã¼ãããã¦ã¼ã¶ã¼ãWebãã©ã¦ã¶ã«URLãå ¥åããéã«ç¯ãæã¡ééããå©ç¨ãããã®ã§ãããã¦ã¼ã¶ã¼ã誤ã£ãURLãå¶ç¶ã«å ¥åããã¨ããµã¤ãã¼ã¹ã¯ã¯ãã¿ã¼ãææããå¥ã®å ´æã«å°ããããæã¡ééã (ã¿ã¤ã; typo) ã¨å æ (squatting) ããã®é èª[1]ã ã¿ã¤ãã¹ã¯ã¯ããã£ã³ã°ã®ç ç²ã«ãªããµã¤ãã¯ãä¸è¬ã«è¨ªåã®å¤ãã¨ããã§ãã[1]ãã¿ã¤ãã¹ã¯ã¯ãã¿ã¼ã®URLã¯ãã©ããç ç²è ã®ãµã¤ãã®ã¢ãã¬ã¹ã«ä¼¼ãã次ã®3種é¡ã®ããããã§ããï¼æå³ãã¦ããWebãµã¤ãã"example.com"ã¨ããï¼ã æå³ãããµã¤ãã®ä¸è¬çãªã¹ãã«ãã¹ï¼exemple.com ã¿ã¤ãã³ã°ã®ã¨ã©ã¼ã«ãããã¹ã¹ãã«ï¼xample.comã¾ãã¯exxample.com ç°ãªã表
Windows 11ã¯ä¸å®ã®æ¡ä»¶ãæºãããã¼ãã¦ã§ã¢ã§ã¯ããããã¤ã¹ã®æå·åããè¨å®âãã©ã¤ãã·ã¼ã®ã»ãã¥ãªãã£ã«è¡¨ç¤ºããï¼åçå·¦ä¸ã®ã¦ã£ã³ãã¦ï¼ãããã«Pro以ä¸ã®ã¨ãã£ã·ã§ã³ã§ã¯ãã³ã³ããã¼ã«ããã«ã«BitLockerãã©ã¤ãæå·åã¢ã¤ã³ã³ï¼åçå·¦ä¸ã®ã¦ã£ã³ãã¦ï¼ãããããè¨å®ãâããã©ã¤ãã·ã¼ã®ã»ãã¥ãªãã£ãâãããã¤ã¹ã®æå·åãâãBitLockerãã©ã¤ãæå·åãã§ãéããã¨ãã§ããï¼åçå³ã®ã¦ã£ã³ãã¦ï¼ Windows 11ã«ã¯ãBitLockerã¨å¼ã°ããããã©ã¤ãæå·åãæ©è½ããããBitLockerã®æå¹åï¼æå·åï¼ãæå·åãããã©ã¤ãã®èªã¿æ¸ãã¯ããã¹ã¦ã®ã¨ãã£ã·ã§ã³ã§å¯è½ãBitLockerã®ç®¡çæ©è½ã¯ãHomeã¨ãã£ã·ã§ã³ã«ã¯ãªããPro以ä¸ã®ã¨ãã£ã·ã§ã³ã§ã®ã¿å©ç¨ã§ããã ã¾ããWindows 11ã§ã¯ããBitLockerãã©ã¤ãæå·åãã¨ãããã¤ã¹ã®æå·åãã®
Windows 11ã«ãµã¼ããã¼ãã£ã®ãã¹ãã¼ç®¡çãçµ±åã§ãããPasskey APIãæè¼ã¸ã1PasswordãBitwardenãªã©ã·ã¼ã ã¬ã¹ã«Windowsã¨çµ±åå¯è½ã« ãã¤ã¯ãã½ããã¯Windows 11ã«ããããã¹ãã¼å¯¾å¿ã®å¼·åã«åããæ½çãçºè¡¨ãã¾ããã 1ã¤ç®ã¯Windows 11ã«Passkey APIãæè¼ãããã¨ã§ãã Windowsã¨ã1PasswordãBitwardenãªã©ã®ãµã¼ããã¼ãã£ã®ãã¹ã¯ã¼ãããã¼ã¸ã£ã«ãããã¹ãã¼ç®¡çæ©è½ãçµ±åå¯è½ã«ãªãã¾ãã Windowsã«ããããã¹ãã¼ã®ç®¡çã¯åºæ¬çã«ã¯ãã¹ãã¼ãç»é²ããããã¤ã¹ã®Microsoftã¢ã«ã¦ã³ãã¨é£ä¿ãã¦ãããä¾ãã°iPhoneãChromebookãªã©ã§ã¯å©ç¨ã§ãã¾ããã 1PasswordãBitwardenã¨ãã£ããµã¼ããã¼ãã£ã®ãã¹ã¯ã¼ãããã¼ã¸ã£ã¯ããããOSãããã¤ã¹ã«ç´ä»ããã¢ã«ã¦ã³ã
ç¾å¨å¾³ä¸¸æ¬ãèªã¿é²ãã¦ããã®ã§ãããOSã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³ã«ã¤ãã¦ã以ä¸ã®â ã¨â¡ã®ã±ã¼ã¹ã®åºå¥ãä»ããæ··ä¹±ãã¦ããã¾ãã â whoamiãpowershellã cmd ãªã©ã®ã³ãã³ããå¤é¨ããå®è¡ã§ããç¶æ â¡ ã·ã§ã«ã«ããè¤æ°ã®ã³ãã³ããèµ·åããããã®æ§æãå©ç¨ãã¦ãä¸è¨ã®ãããªã³ãã³ããè¤æ°å®è¡åºæ¥ãç¶æ â ã¯ããã¾ã§Windowsã³ãã³ããã·ã§ã«ã¹ã¯ãªããã®ãã¤ãã¼ãèªä½ãæããã®ã§ãããOSã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³ã®èå¼±æ§ã¯â¡ã®ç¶æ ã¨ããèªèã§åã£ã¦ãã¾ããï¼ ããã¯éãçåã ã¨æãã¾ããâ¡ã¨ããèªèã§ãã£ã¦ãã¾ãããããå°ãè£è¶³ãããã¨æãã¾ãã ç義ã®OSã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³ï¼CWE-78ï¼ã¯ããææã®â¡ã®ã¨ãããè¤æ°ã³ãã³ããèµ·åããããã®æ§æï¼/bin/sh ã®ã»ãã³ãã³çï¼ã使ã£ã¦è¤æ°ã®ã³ãã³ããå®è¡ãããã®ã§ããããããåºç¾©ã§ã¯ã³ã¼ãå®è¡å¯è½ãªèå¼±æ§å ¨ä½ã
åç 被害 AWSã®SESãå©ç¨ãããç´5ä¸éã®ã¡ã¼ã«ãä¸æ£ã«éä¿¡ãããç´10ãã«ã®ä½¿ç¨æãçºçãã¾ãããã¾ããç¦ã£ã¦ã«ã¼ã権éã®MFAè¨å®æã«ã¢ããªï¼å¥ã®ã¢ããªç¨ã®çªå·ãé¸æãç¶ããï¼ã®é¸æã誤ããä½è¨ã«ç¦ããã¨ã«ãªãã¾ããã é ã«ããã£ãéå»ã®æªå¤¢ çç¶ DKIMè¨å®æåéç¥: ä¸å¯©ãªDKIMè¨å®å®äºã®éç¥ãåãåãã¾ããï¼9æ12æ¥ï¼æããï¼ æéã¢ã©ã¼ã: AWSããSESã®ä½¿ç¨æéãé¾å¤ã«éããã¢ã©ã¼ããéä¿¡ããã¾ããï¼9æ13æ¥9æããï¼ ä¸æ£ãªã¡ã¼ã«éä¿¡: æ°ä¸éã®ä¸æ£ã¡ã¼ã«ãéä¿¡ãããæéãæ¥å¢ãã¾ãã ãã¡ã¤ã³ã®ç»é²ã¨åé¤: ç¥ããªããã¡ã¤ã³ãAWSã«ç»é²ããã¦ãã¾ãããè³æ¥ç»é²ããã¦ãããã¡ã¤ã³ãåé¤ãã¾ãã(9æ13æ¥11æããï¼ IAMã¦ã¼ã¶ã¼ã§ã®ãã°ã¤ã³å¤±æ: ä¸æ¦åé¤ããã®ã§ããã¨ããï¼æéå¾ãIAMã¦ã¼ã¶ã¼æ¨©éã§ã®ãã°ã¤ã³ãã§ããªããªããç¦ããå¢ãã¾ããï¼9æ
by Sansec Forensics Team Published in Threat Research â June 25, 2024 The new Chinese owner of the popular Polyfill JS project injects malware into more than 100 thousand sites. Update June 28th: We are flagging more domains that have been used by the same actor to spread malware since at least June 2023: bootcdn.net, bootcss.com, staticfile.net, staticfile.org, unionadjs.com, xhsbpza.com, union.m
ç±³ååçç£æ¥å®å ¨ä¿éå±ï¼BISï¼ã¯6æ20æ¥ï¼ç¾å°æéï¼ããã·ã¢ãæ ç¹ã¨ããã¦ã¤ã«ã¹å¯¾çã½ããããã³ãµã¤ãã¼ã»ãã¥ãªãã£ä¼æ¥ã®ç±³å½æ¯ç¤¾ã§ããKaspersky Labããç±³å½å ããã³ç±³å½æ°ã«å¯¾ãã¦è£½åãæä¾ãããã¨ãç¦æ¢ããæçµæ±ºå®ãçºè¡¨ããã ããã«ããKasperskyã¯ç±³å½å ã§ã®è£½å販売ããæ¢ã«ä½¿ããã¦ãã製åã®ã¢ãããã¼ãã®æä¾ãªã©ãã§ããªããªãã ç¾å¨å社製åã使ã£ã¦ããç±³å½æ°ããã³ç±³å½ä¼æ¥ã«å¯¾ãã¦ã¯ããéããã«æ°ãããã³ãã¼ã«ç§»è¡ãããã¨ãå¼·ãå§ãããã¨ãã¦ããã使ãç¶ãããã¨ã§æ³çå¦ç½°ãåãããã¨ã¯ãªãããã¢ãããã¼ããåããããªããªãããããªã¹ã¯ãè² ããã¨ã«ãªãã¨è¦åããã 移è¡ã®ããã®ç¶äºãä¸ãããããKasperskyã¯9æ29æ¥åå12æã¾ã§ã¯ã¢ãããã¼ããå«ãæ¥åãç¶ç¶ã§ããã ç±³ååçã¯Kaspersky製åãå ¨é¢ç¦æ¢ããã®ã¯ãé·æã«ãããå¾¹åºçãªèª¿æ»ã®çµæãã§ã
æ´æ°å±¥æ´ 2024/6/28 ãããã¯ã¼ã¯é®æã®æ¯éã«ã¤ãã¦è¿½è¨ãã¾ããã ã¯ããã« ã¨ããã»ãã¥ãªãã£ã¤ã³ã·ãã³ãã«ããã¦ããµã¼ããé»æºã±ã¼ãã«ãã¨å¼ãæããã¨ãã対å¿ãè¡ãããXï¼Twitterï¼ã§ã¯ãã®å¯¾å¿ã«ã¤ãã¦è³å¦ä¸¡è«ãè¦ããã¾ããããã®ãã¡é»æºãå ¥ããã¾ã¾ã«ãã¹ãã¨ãã人ã®æè¦ã«ã¯ãããã«ã¦ã§ã¢ã®ä¸ã«ã¯ã·ã£ãããã¦ã³ãããã¨ã§èªåèªèº«ãåé¤ããææçè·¡ãåé¤ãããã®ãããããã¡ã¢ãªã調æ»ãã¹ããªã®ã§ã·ã£ãããã¦ã³ãã¹ãã§ã¯ãªããã®ãããªæè¦ãè¦ããã¾ããã æ¬è¨äºã§ã¯å®éã«ã¡ã¢ãªããã©ã®ãããªæ å ±ããããããããã¦ã¡ã¢ãªãã³ãã解æãããã¨ã®æç¨æ§ã¨èª²é¡ã«ã¤ãã¦è¨è¼ãã¾ãã ã¾ããã¤ã³ã·ãã³ãçºçæã®ç¹ã«å°ãè¾¼ããã§ã¼ãºã«ã¤ãã¦ãèå¯ãã¾ãã ã¡ã¢ãªãã©ã¬ã³ã¸ã㯠ã»ãã¥ãªãã£ã¤ã³ã·ãã³ãã«ããã¦ã¯ãã©ã¬ã³ã¸ãã¯èª¿æ»ãè¡ãããå ´åãããã¾ãããã©ã¬ã³ã¸ãã¯èª¿æ»ã«ã¯ãHDDãSS
ã8/5追è¨ã ãã¤ããæ顧ããã ããããã¨ããããã¾ãããã³ãã³éå¶ãã¼ã ã§ãã 大å¤ãå¾ ãããããã¾ããã 8æ5æ¥ï¼æï¼15æãããæ°ãã¼ã¸ã§ã³ã帰ã£ã¦ãããã³ãã³ãã¨ãã¦ãããã³ãã³ããµã¼ãã¹ãåéãããã¾ããã ãã¼ã¸ã§ã³åã®è©³ç´°ãªã©ã«ã¤ãã¦ã¯ä¸è¨ãç¥ãããã確èªãã ããã 8/5ãã³ãã³ãµã¼ãã¹ã®åéã¨æ°ãã¼ã¸ã§ã³ã帰ã£ã¦ãããã³ãã³ãã®ãç¥ãã 帰ã£ã¦ãããã³ãã³ããããããé¡ããããã¾ãã ã8/1追è¨ã ãã¤ããæ顧ããã ããããã¨ããããã¾ãããã³ãã³éå¶ãã¼ã ã§ãã 2024å¹´8æ5æ¥ï¼æï¼ããã®ãã³ãã³åç»ã»ãã³ãã³çæ¾éãã¯ããã¨ããããã³ãã³ããµã¼ãã¹ã®åéã«ããããåéç¶æ³ã®è©³ç´°ããç¥ãããããã¾ãã ã¾ãããµã¼ãã¹åéãè¨å¿µãã¦ããã³ãã³ã§ã¯8æ5æ¥ï¼æï¼ãããã¾ãã¾ã¤ãã³ããéå¬ãããã¾ãã 詳ããã¯ä¸è¨ãç¥ãããã確èªãã ããã 8/5ãã³ãã³ãµã¼ãã¹ã®
å¹³ç´ ã¯å¼ç¤¾ååããæç¨ããã ãèª ã«ãããã¨ããããã¾ãã 5æ21æ¥ãã22æ¥ã«ããã¦å ±éããã¦ããã¾ããNICTER解æãã¼ã ã«ããå¼ç¤¾ãWSR-1166DHPã·ãªã¼ãºãçã®ãããã¸ã®ææã確èªããã件ã«ã¤ãã¾ãã¦ãNICTæ§ã¨é£æºãã¦èª¿æ»ãè¡ã£ãçµæãããã50å°ç¨åº¦ã®å¼ç¤¾Wi-Fiååããªãããã®å é¨ãããã¯ã¼ã¯ãããã«ã¦ã§ã¢ãçºä¿¡ããã¨æãããéä¿¡ã確èªãã¦ããã¾ãããã¡ãã®ã客æ§ã«ã¤ãã¾ãã¦ã¯ãå¦ç½®ãªã©ã®ãæ¡å æ¹æ³ã«ã¤ãã¦NICTæ§ã¨åè°ãã¦ããã¾ãã ã¾ãNICTER解æãã¼ã ã¨ã®æ¤è¨ã®çµæã以ä¸ã®ååã»æ¡ä»¶ã«è©²å½ããå ´åã«ãææã®æãããããã¨ããããã¾ããã 該å½ã®æ¡ä»¶ã«ä¸è´ããååããå©ç¨ã®ã客æ§ã«ã¤ãã¾ãã¦ã¯ã以ä¸ã®ã«ã¼ã¿ã¼è¨å®çãã確èªããã ãã¾ããããé¡ããããã¾ãã (5/23æ´æ° ã該å½ã®ååããã³æ¡ä»¶ããã確èªããã ãè¨å®ã«ã¤ãã¦ãã«ã¤ãã¦æ°ããªäºå®ã追è¨ãã
Intro CSRF ã¨ããå¤ã®æ»æãããããã®æ»æããå¤(ãã«ãã)ãã®ãã®ã«ãããã¨ãã§ãããã©ãããã©ã¼ã ã®é²åã®èæ¯ãããCookie ã SameSite Lax by Default ã«ãªã£ãããã ãã¨ãã解説ãè¦ããã¨ãããã 確ãã«ãç¾å®çã«ããã«ãã£ã¦æ»æã®æç«ã¯é£ãããªããæããã¦ãããµã¼ãã¹ããããããããããã¯ãã©ãããã©ã¼ã ãç¨æãã対çã®æ¬è³ªããè¨ãã¨ã解éãå°ãããã¦ããã¨è¨ããã ããã ä»åã¯ããCSRF ãã©ããã¦æç«ãã¦ããã®ãããæ¯ãè¿ããã¨ã§ãæ¬å½ã«ãã©ãããã©ã¼ã ã«è¶³ãã¦ããªãã£ããã®ã¨ããããè£ã£ã¦ãã£ãçµç·¯ãæ¬å½ã«ãã¹ã対çã¯ä½ã§ãããã解説ãã¦ããã çµæã¨ãã¦è¦ãã¦ããã®ã¯ãä»ãµã¼ãã¹ãå®è£ ããä¸ã§ã®ããã¼ã¹ã(not ãã¹ã)ã¨ãªããã©ã¯ãã£ã¹ã ã¨çè ã¯èãã¦ããã CSRF æç«ã®æ¡ä»¶ ä¾ãã°ãæ»æè ãç¨æãã attack.examp
(4/14 表è¨æºããªã©ã®ã³ã¡ã³ãããã ããã®ã§ãå°ãä¿®æ£ã追è¨ãã¾ããã) ritouã§ãã ç§ã®ã¿ã¤ã ã©ã¤ã³ã«ããåºã¦ããããã®è¾ºãã®è©±ã£ã¦ãã¤ã«ãªã£ã¦ããã£ããããªã人ãå¤ãã¨æãã¾ãã OAuthèªè¨¼ð® : ã¢ããªã±ã¼ã·ã§ã³ãã¦ã¼ã¶ã¼æ å ±åå¾ãæä¾ããAPIãå©ãã¦åãåã£ãã¦ã¼ã¶ã¼èå¥åã使ã£ã¦æ°è¦ç»é²ããã°ã¤ã³ããã¦ã¯ãããªããOIDCã®IDTokenã使ã ã¦ã¼ã¶ã¼IDãåå¾ã§ããã°ãã°ã¤ã³ããã¦ããã®ã§ã¯ãªãã IDTokenã¯ã¦ã¼ã¶ã¼IDãå«ãJWTã ããã©ããã¦ããã¯è¯ãã®ã ãã¸ã¿ã«åºãé²ãããã¤ãã³ãã¼ã«ã¼ããç¨ããå人åãèªè¨¼ã¢ããªã±ã¼ã·ã§ã³(以ä¸ãèªè¨¼ã¹ã¼ãã¼ã¢ããª)ã®ç¨é ãã¤ãã³ãã¼ã«ã¼ããç¨ããæ¬äººç¢ºèªã¯æ¢ã«ããã¤ãã®æ°éãµã¼ãã¹ã§ä½¿ããã¦ãããããã°ã¤ã³ã«ä½¿ããã¨ã¯ã©ãããäºãªã®ã ãã¸ã¿ã«åºãã㯠ã¹ããç¨é»å証ææ¸æè¼ãµã¼ãã¹ãã¨ããç©ãåºã¦ããã
3æ12æ¥ç«ææ¥ã«å§ã¾ã£ãPublickeyã¸ã®DDoSæ»æã«å¯¾ãã¦ãããã¾ã§ãµã¼ãã®å¼·åãCloudflareã®å°å ¥ã¨DDoS対çã®ããã®è¨å®ãè¡ã£ã¦ãã¾ããã ãã®çµæã3æ24æ¥æ¥ææ¥ã®å¤ã«å§ã¾ã3æ27æ¥æ°´ææ¥ã®æã¾ã§3æ¥éé£ç¶ã§ç¶ããDDoSæ»æã®ããã ãWebãµã¤ãã®é²è¦§ã¨è¨äºæ´æ°ãªã©ãåé¡ãªãè¡ããç¶æ ã¨ãªããDDoSæ»æãWebãµã¤ãã®éå¶ã®å¤§ããªé害ã§ã¯ãªããªãã¾ããã ã¡ãªã¿ã«ãã以å¾DDoSæ»æã¯æ¢ãã§ãã¾ãããä»å¾ã¯ãã¤DDoSæ»æãåãã¦ãWebãµã¤ãã®éå¶ã«æ¯éãã§ããã¨ã¯ãªããªã£ãã¨èãããã¾ãããã®è¨äºã§ã¯çµå±ã©ã®ãããªå¯¾çãè¡ã£ãã®ããå®éã«å¹æãçºæ®ããDDoS対çãç´¹ä»ãã¦ããã¾ãã ããã¾ã§ã®çµç·¯ã¯ä¸è¨ã®è¨äºããåç §ãã ããã PublickeyãåããDoSæ»æãããã¾ã§ã®çµç·¯ã¨å¯¾çã¾ã¨ã ç¶ãPublickeyãåããDoSæ»æãããã¾ã§ã®çµç·¯ã¨
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}