403 Forbidden nginx/1.4.3
å æï¼Windowsã®ãã£ã¹ã¯é åã®ä½¿ãæ¹ã«é¢ããè¨äºãæ¬å®¶è±èªã®Engineering Windows 7 Blogã«æ²è¼ãããï¼ãã®è¨äºã¯é常ã«èå³æ·±ããã®ã§ï¼ç§èªèº«ï¼å¤ãã®åéãã¨èª¤è§£ã解ããã¨ãã§ãã (ã¤ãã§ã«ï¼WinHEC ã® PPTX è³æãå ¬éããã¦ããã®ã«æ°ä»ããã¨ãã§ãã)ï¼ãã£ã¨ç¿»è¨³ãå¾ ã£ã¦ããã®ã ãï¼æ¨æ¥ç¿»è¨³çãæ²è¼ãããã®ã§ç´¹ä»ãã¦ããããï¼ ãã®æ稿ã¯ãã£ã¹ã¯é å㨠Windows 7 ã«ãã£ã¦ãæ¶è²»ãããããã£ã¹ã¯é åã«ã¤ãã¦ã§ãããã£ã¹ã¯é åã¯èª°ãç¯ç´ãããã¨æã£ã¦ãããã®ã§ãããä¸è¬çã«è²»ç¨å¯¾å¹æã大ãããã®ã§ãããã¾ãããããã©ãã容éãå転å¼ã®ãã©ã¤ããããã£ã¨å°ããã½ãªãã ã¹ãã¼ã ãã©ã¤ã (SSD) ã®åºç¾ã«ãããæè¿ãç¶æ³ãå¤ãã£ã¦ãã¾ãããä¼çµ±çã«ãWindows ãå«ãã»ã¨ãã©ã®ã½ããã¦ã§ã¢ã¯ã60GB (ããã㯠1,500GB) ã®ã
ã³ã³ãã¥ã¼ã¿ã¦ã¤ã«ã¹ã®è§£æãªã©ã«æ¬ ãããªããªãã¼ã¹ã¨ã³ã¸ãã¢ãªã³ã°æè¡ã§ãããä½ã ãé£ãããã ãªãã¨ããå°è±¡ãæ±ãã¦ãã人ãå¤ãã®ã§ã¯ãªãã§ããããããã®é£è¼ã§ã¯ããã·ã§ã«ã³ã¼ãããä¾ã«ãå®è·µå½¢å¼ã§ãã®åºç¤ãç´¹ä»ãã¦ããã¾ããï¼ç·¨éé¨ï¼ Windows APIã®å¼ã³åºãæ¹æ³ã«è¿«ãï¼ ç¬¬4åãUndocumentedãªãã¼ã¿æ§é ä½ãç¥ããã«å¼ãç¶ããä»åãã·ã§ã«ã³ã¼ããWindowsã®APIãå¼ã³åºãæ¹æ³ã«ã¤ãã¦è¿«ã£ã¦ããããã¨æãã¾ãã ã·ã§ã«ã³ã¼ãã§ã¯ãèªç±ã«APIãå¼ã³åºãããã«ä»¥ä¸ã®3ã¹ãããã®å¦çãå®è¡ãã¾ãã kernel32.dllã®ãã¼ã¹ã¢ãã¬ã¹ãåå¾ãã ï¼kernel32.dllãã¨ã¯ã¹ãã¼ããã¦ããï¼LoadLibraryé¢æ°ã¨GetProcAddressé¢æ°ã®ã¢ãã¬ã¹ãåå¾ãã LoadLibraryé¢æ°ã¨GetProcAddressé¢æ°ãå©ç¨ãã¦ä»»æã®APIãå¼ã³åº
JPCERTã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ã¯2015å¹´12æ2æ¥ããæ»æè ãæªç¨ããWindowsã³ãã³ããã¨é¡ãããªãã¼ããå ¬éããã JPCERTã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ï¼JPCERT/CCï¼ã¯2015å¹´12æ2æ¥ããæ»æè ãæªç¨ããWindowsã³ãã³ããã¨é¡ãããªãã¼ããå ¬éããããããã¨ãæ®éã®å©ç¨è ã使ãWindowsã³ãã³ãã¨ã®ããããã«çç®ããå®è¡ãå¶éãããã¨ã«ãã£ã¦ãæ»æã®å½±é¿ãä½æ¸ããæå©ãã«ãããã¨ãçã£ã¦ããã æ¨çåæ»æã«ããã¦ã¯ãæåã«è¶³ãããã¨ãªã端æ«ããã«ã¦ã¨ã¢ã«ææããå¾ã«ããRATï¼Remote Administration Toolï¼ãã¨å¼ã°ããé éæä½ç¨ãã«ã¦ã¨ã¢ãã¤ã³ã¹ãã¼ã«ããããã¨ãå¤ããæ»æè ã¯RATãä»ãã¦ãªã¢ã¼ãããã³ãã³ãã·ã§ã«ãå®è¡ãã端æ«ããããã¯ã¼ã¯å ã®æ å ±åéãæ¢ç´¢ãè¡ããã·ã¹ãã å ã«ææãåºãã横å±éããªããæ©å¯æ å ±ã®åéãªã©
対象OSï¼Windows Vistaï¼Windows 7ï¼Windows 8ï¼Windows 8.1ï¼Windows Server 2008ï¼Windows Server 2008 R2ï¼Windows Server 2012ï¼Windows Server 2012 R2 解説 Windows OSã§åºã使ããã¦ããNTFSã«ã¯ã代æ¿ãã¼ã¿ã¹ããªã¼ã ï¼ADSï¼Alternate Data Streamï¼ãï¼ãå¯æ¬¡ã¹ããªã¼ã ãã¨ãå¼ã°ããï¼ã¨ããæ©è½ãããããã¡ã¤ã«ã«å¯¾ãã¦è£å©çãªãã¼ã¿ï¼ã¹ããªã¼ã ï¼ãä¿åããããã«å©ç¨ããã¦ãããä¾ãã°ãInternet Explorerãã¡ã¼ã«ã½ããã¦ã§ã¢ãªã©ã§ã¤ã³ã¿ã¼ããããããã¦ã³ãã¼ããããã¡ã¤ã«ã«ã¯ãZone.Identifierãã¨ãã代æ¿ãã¼ã¿ã¹ããªã¼ã æ å ±ãä»å ãããã¤ã³ã¿ã¼ããããããã¦ã³ãã¼ããããã¡ã¤ã«ã§ãããã¨ãåããããã«ãªã£ã¦ã
*.keicode.com ã«ã¤ã㦠2005å¹´é ããå人çã«ã½ããã¦ã§ã¢ã®æè¡è¨äºãã¾ã¨ãã¦ã å½ãµã¤ãã«æ å ±ãæ²è¼éå§ããã®å¾ããã¾ãã¾ãªãã¼ãæ¯ã«åå¿è åãã®å ¥éãµã¤ããªã©ãã¾ã¨ãã¦ãã¾ããã 主ãªå§å¦¹ãµã¤ãã¨ãã¦ã¯ ãPython å ¥éããAndroid å ¥éã ãJava å ¥éããåºç¤ããã® IoT å ¥éããªã©ãããã¾ãã æè¿ã¯ YouTube ãã£ã³ãã«ãIT ãªãã»ã© TVããéè¨ããåç»ãç¨ããæè¡è§£èª¬ãè¡ã£ã¦ããã¤ããã§ãã (ãªããªãæ´æ°ã§ãã¦ãã¾ãããããããããã§ã¯ããã¾ããã®ã§ããã²ãã£ã³ãã«ç»é²ããããããé¡ããã¾ãï¼) å½ãµã¤ãã®ã¦ã§ããã¹ãã£ã³ã°ã«ã¤ã㦠å½ãµã¤ãã¯ãã«ã¼ãã¹ãã¨ãã米系ã®ã¦ã§ããã¹ãã£ã³ã°ãå©ç¨ãã¦éç¨ãã¦ãã¾ãã åèã¾ã§ã«æ¸ã㨠2018å¹´3æã®å®ç¸¾ã§ã¯ keicode.com ãã¡ã¤ã³ã®é¢é£ãµã¤ãåããã¦ã æéç´ 25ä¸ PV ã§
ä½ã£ã¦ããã COM ã®åºç¤ ç°¡å㪠COM ã³ã³ãã¼ãã³ãã®å®è£ ä¾ãéãã¦ãCOM ã³ã³ãã¼ãã³ãã«æä½éå¿ è¦ãªè¦ç´ ã«ã¤ãã¦ã¿ã¦ããã¾ãã IUnknown ã¨ã¯ï¼ IUnknown ã¤ã³ã¿ã¼ãã§ã¤ã¹ã¯ãã¹ã¦ã® COM ã³ã³ãã¼ãã³ãã«å®è£ ããã¾ãããããä½ãã¿ã¦ã¿ã¾ãããã COM ãªãã¸ã§ã¯ãã®å¯¿å½ç®¡ç COM ãªãã¸ã§ã¯ãã¯ãã¤ã¡ã¢ãªãã解æ¾ããããã¨ãããã¨ãèãã¾ãã COM ã³ã³ãã¼ãã³ãã®ç»é²æ©è½ COM ã³ã³ãã¼ãã³ãã¯èªåãã·ã¹ãã ã«ç»é²ãããæ©è½ããããããã¨ãã§ãã¾ãã ã¯ã©ã¹ãã¡ã¯ã㪠ã¯ã©ã¹ãã¡ã¯ããªã使ã£ã¦ã¤ã³ã¹ã¿ã³ã¹åãã¾ãããã®ä»çµã¿ãè¦ã¦ã¿ã¾ãããã ç°¡å㪠COM ã³ã³ãã¼ãã³ãã®å®è£ ä¾ åç´ãª COM ã³ã³ãã¼ãã³ããå®è£ ãã¦ã¿ã¾ãã ç°¡å㪠COM ã¯ã©ã¤ã¢ã³ãã®å®è£ ä¸ã§ä½ã£ã COM ã³ã³ãã¼ãã³ããå©ç¨ããããã°ã©ã ã®å®è£ ä¾ã§ãã ããã¾ã§ã
è¶ åå¿è 対象ã®ãC/C++/C#ããã°ã©ã æ室ã§ãã ãWindows95/98/2000/XP使ãã ãã«ã¯é£½ãããã以åï¼£ããã£ããã¨ããããããã¤ã³ã¿ã¼ã§ã¤ã¾ãããã ãããã°ã©ã ã¯ãå ¨ãçµé¨ããªãããDOSã®ããã°ã©ã ã¯ãä½ãããWindowsã®ããã°ã©ã 㯠ã¡ãã£ã¨ã»ã»ã»ãã¨ããæ¹ã®ããã®ãã¼ã ã»ãã¼ã¸ã§ããä¸ç´è 以ä¸ã®æ¹ãã»ãããã®æ¹ã ããã®æ¹ãé æ ®ãã ãããMacã¦ã¼ã¶ã¼ã®æ¹ãç§ã®åä¸è¶³ã®ãããå½¹ã«ç«ã¦ã¾ããã Webmaster Yasutaka Kumei [How To Walk][ç»åã表示ãããªãæã¯] [VC++6.0ã§ãã¾ããã«ãã§ããªãæã¯] [ãªã½ã¼ã¹ããã¾ã表示ãããªãæã¯(VC++6.0)] [ãªã½ã¼ã¹ããã¾ã表示ãããªãæã¯(VC++.net)] [ã¡ãã»ã¼ã¸ã»ã«ã¼ã] [WinXP+VC++.netã§ã³ã³ãã¤ã«ã§ããªãæã¯] [.netã§ãã©ã¡ã¼ã¿ã»
Windows API ã¯ãWindows ãªãã¬ã¼ãã£ã³ã° ã·ã¹ãã ã®ä¸é¨ã§ãããã¤ããã㯠ãªã³ã¯ ã©ã¤ãã©ãª (DLL) ã§ãã ç¬èªã®åçã®ããã·ã¼ã¸ã£ãè¨è¿°ãããã¨ãå°é£ãªå ´åã¯ããããã使ç¨ãã¦ã¿ã¹ã¯ãå®è¡ãã¾ãã ãã¨ãã°ãWindows ã«ã¯ FlashWindowEx ã¨ããååã®é¢æ°ãç¨æããã¦ãã¦ãããã使ç¨ããã¨ãã¢ããªã±ã¼ã·ã§ã³ã®ã¿ã¤ãã« ãã¼ã交äºã«æããè²åãã¨æãè²åãã«ãããã¨ãã§ãã¾ãã ãèªèº«ã®ã³ã¼ã㧠Windows API ã使ç¨ããå©ç¹ã¯ãæ¢ã«è¨è¿°ããã使ç¨ãããã®ãå¾ ã£ã¦ãã便å©ãªé¢æ°ãå¤æ°å«ã¾ãã¦ãããããéçºæéãç¯ç´ã§ãããã¨ã§ãã æ¬ ç¹ã¨ãã¦ãWindows API ã¯å¦çã容æã§ãªããåé¡ãçºçããã¨ãã«å°é£ãªç¶æ³ã«ãªããã¨ãããã¾ãã Windows API ã¯ãç¸äºéç¨æ§ã®ç¹å¥ãªã«ãã´ãªã表ãã¦ãã¾ãã Windows API ã«
â»2012.03.11 Win32APIæ¤ç´¢ã¢ã㪠v1.2.0.0 å ¬éä¸ ZIPå§ç¸®ç ã«ãã´ãªã¼å¥ã«Win32APIãã¾ã¨ãã¦ãã¾ããæ¢ãã¦ããAPIãæ¢ãå½ã¦ãããã®ãã¼ã¸ã§ãã ãªã³ã¯å ã¯Microsoft社ã®MSDNãµã¤ãã§ããåAPIã®è©³ç´°ã«ã¤ãã¦ã¯ãã¡ããåç §ãã ããã å¤ãæ å ±ã誤ããªã©ããã¾ããã御ç¥ãããã ããã APIã«ãã£ã¦ã¯ãè¤æ°ã®ã«ãã´ãªã¼ã«å±ãããã®ãããã¾ãã ï¼ï¼é³é ã«ãã´ãªä¸è¦§ â ã¢ã¤ã³ã³ ArrangeIconicWindows ã¢ã¤ã³ã³åãããåã¦ã£ã³ãã¦ãæ´å CopyIcon ã¢ã¤ã³ã³ãã³ãã¼ CreateIcon ã¢ã¤ã³ã³ãä½æ CreateIconFromResource ã¢ã¤ã³ã³(ã¾ãã¯ãã¦ã¹ã«ã¼ã½ã«)ããããããããªã½ã¼ã¹ããä½æ CreateIconFromResourceEx ã¢ã¤ã³ã³(ã¾ãã¯ãã¦ã¹ã«ã¼ã½ã«)ããããããããªã½ã¼ã¹ã
æ¨æº Windows API ã¦ã£ã³ãã¦ã®çæãæç»å¦çãªã©ã®åºæ¬ç㪠API ãç´¹ä»ãã¾ãã ã³ã¢ã³ã³ã³ããã¼ã« Windows ãæä¾ããæ¨æºçãªãã¤ã¢ãã°ã³ã³ããã¼ã« API ã§ãã ãã«ãã¡ãã£ã¢ API æ åãé³æ¥½ãå¦çããããã®ãã«ãã¡ãã£ã¢ API ã§ãã Windows ã½ã±ãã ãããã¯ã¼ã¯ããã¤ã¹ãããã¼ã¿ãéåä¿¡ããããã® API ã§ãã
ãµã³ãã«ã½ã¼ã¹ã¯ C è¨èªã¨ãã¦ã³ã³ãã¤ã«ãã¦ãã ããã C++ ã¨ãã¦ã³ã³ãã¤ã«ããå ´åãã¨ã©ã¼ãçºçããå ´åãããã¾ã â»èª¤ã£ãããã°ã©ã ãå®è¡ããã¨ãWindowsãä¸å®å®ã«ãªããã¨ãããã¾ã éè¦ãªã·ã¹ãã ä¸ã§ã¯å®é¨ãè¡ããªãã§ä¸ãã ãã®è¬åº§ã¯ãCè¨èªãçç¥ãã¦ãããã¨ãåæã§ã
Windows Sysinternals ã¯ãIT æ å½è ãéçºè ããWindows ã·ã¹ãã ãã¢ããªã±ã¼ã·ã§ã³ã管çããã©ãã«ã·ã¥ã¼ãã£ã³ã°ãããã³è¨ºæããéã«å½¹ç«ã¤ç¡åã® Windows ãã©ãã«ã·ã¥ã¼ãã£ã³ã° ãã¼ã«ã®ç·ç§°ã§ãã Sysinternals Web ãµã¤ãã¯ã1996 å¹´ã« Mark Russinovich (è±èª) ã«ãã£ã¦ãå½¼ã®é«åº¦ãªã·ã¹ãã ãã¼ã«ãæè¡æ å ±ããã¹ãããããã«ãä½æããã¾ããã Windows Sysinternals ã§ã¯ãWindows ã®ããã»ã¹ããã¡ã¤ã« ã¢ã¯ã»ã¹ã®ç¶æ ãææ¡ããããã®ããã¾ãã¾ãªãã¼ã«ãç¡åã§æä¾ããã¦ãã¾ããä¾ãã° Windows æ¨æºã®ã¿ã¹ã¯ ããã¼ã¸ã£ã¼ã§ã¯èª¿ã¹ãããªãããã詳細ãªæ å ±ãå¾ããã¾ãã ãã®ä»ã®ãªã½ã¼ã¹ Sysinternals ãã¼ã«å ¬å¼ã¬ã¤ã: The Windows Sysinternals Ad
Windows2000/XPã«ç¨æããã¦ããã管çãã¼ã«ãã¯ï¼ã·ã¹ãã ããµã¼ãã¹ã®è¨å®ã«å©ç¨ããéè¦ãªã¦ã¼ãã£ãªãã£ã ããããï¼ã³ã³ããã¼ã«ããã«ããã¤ã³ã³ãã¥ã¼ã¿ã®å³ã¯ãªãã¯ãªã©ãããã©ãã«ã¯æé ãå¤ãï¼ããã«ã¢ã¯ã»ã¹ã§ããã«ä¸ä¾¿ã«æããã¨ãå¤ãã ããããããªã¨ãã¯ããã¡ã¤ã«åãæå®ãã¦å®è¡ãã«ä»¥ä¸ã®ã³ãã³ããå ¥åããã°ãããããã«ç®çã®ç»é¢ãèµ·åãã¦ãããããã«ãªãã
é·æéãã½ã³ã³ã§ã²ã¼ã ãéã¶PCã²ã¼ãã¼ãªããæ§ã ãªå¦çãå¹çè¯ãè¡ã£ããã常ã«ãã½ã³ã³ã®åä½ãå®å®ããç¶æ ã«ãã¦ããã®ã¯å¤§å¤éè¦ãªãã¨ã§ããããã§ãã²ã¼ã ãã¡ã¤ã³ç¨éã«ãã¦ããPCã¦ã¼ã¶ã¼è¦ç¹ã§ãã¤ã³ã¹ãã¼ã«ãã¦ããããç¡æããã°ã©ã ã10åãå³é¸ãã¦ãç´¹ä»ãã¾ãã âè¬å± / çªã®æ ããããåªç§ãªPCè¨å®ã®ç·åãã¼ã«ã§ããããã両è ã¨ãæ©è½ãå¤ããããããã§ã¯é¢é£ä»ãã«çµã£ã¦èª¬æãã¾ãããè¬å±ãã¯ãWindowsã®æ¨æºãã¼ã«ãããç°¡åã»è»½å¿«ã«æ¡å¼µåãã¨ã«éãããã°ã©ã ãå¤æ´å¯è½ã§ãããçªã®æãã§ã¯ãä¸æãªããã°ã©ã ãä¸å¾ã§åãããã°ã©ã ã§éããã¨ãåºæ¥ãæ©è½ã«æ³¨ç®ãcfgãã¡ã¤ã«ãªã©ãç´æ¥ç·¨éãããã¨ãå¤ããã¬ã¤ã¤ã¼ã«ããããã§ãã âDefraggler ãDefragglerãã¯é«æ©è½ãªããã©ã°ã½ããã§ããæå®ãããã¡ã¤ã«ããã©ã«ãããã©ã¤ãã®ã¿ã®ããã©ã°æ©è½ãããæçåãããã¡
å¤ãã®äººãæºå¸¯é»è©±ãå©ç¨ãã¦ããç¾ä»£ã«ããã¦ãä»ä½¿ã£ã¦ããæºå¸¯é»è©±ã«é£½ãã¦ãã¦ãè²·ãæ¿ãããããããã©ãæ¬ä½ã®æéãé«ãã¦ãæ©ç¨®å¤æ´ã«äºã®è¶³ãè¸ãã§ãã人ã¯å¤ãããã¨æãã¾ãã èªåããã®ä¸äººã§ããã ããããã¹ããã®æ¥æ¿ãªæ®åã¨åæã«ã使ç¨ããããæºå¸¯é»è©±ã®è²·åãè¡ããä¸å¤æºå¸¯ã¨ãã¦å¤æ®µãä¸ãã¦ã販売ãè¡ãæ¥è ããã·ã§ãããå¢ãã¦ãã¾ããã æºå¸¯è²·åãè¡ã£ã¦ãããæ¥è ããã·ã§ãããå¢ãã¦ãããã¨ã«ãã£ã¦ãèªåãã¡æ¶è²»è ã¯ãéãè¯ããã°ãèªåã®æ¬²ããã£ãæ©ç¨®ããå®ãè³¼å ¥ãããã¨ãã§ããããã«ãªã£ã¦ãã¾ããã æºå¸¯è²·åãè¡ã£ã¦ãããã®ã¯ããããä¸ã ãã§ã¯ãªããèªåãã¡ã®å²ã¨èº«è¿ã«ãåå¨ãã¾ãã 身è¿ãªã·ã§ããã§ããã°ãä¸å¤å½¢æ ã®è³¼å ¥ãããéããå®éã«ç®ã§è¦ã¦ãæã§è§¦ã£ã¦è³¼å ¥ã§ããã®ã§ã¡ãªãããå¤ããé常ã«æºè¶³åº¦ãé«ãã§ãã å®éã«èªåãã身è¿ãªã·ã§ããã§ä¸å¤ã®ã¹ãããè³¼å ¥ãã¾ããããèªåã®ç®
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}