ã¦ã¯ã©ã¤ãæ±é¨ã®çºããªã³ãã éåä½å® ã®çãè·¯å°ãæ¦è£ ããææ»å¡ããé§ãå ¥ã£ã¦ããã ï¼ã¤ã®é¨å±ã®ãã¢ããã¼ã«ã§ãããããè¹´ç ´ã£ã¦çªå ¥ããã ææ»å¡ãç®ã«ããã®ã¯ãæ°åå°ã¯ããã¨æãããã³ã³ãã¥ã¼ã¿ã¼ããã¼ããã£ã¹ã¯ã ããã¦ã大éã®ç´å¹£ã¨éå¡ã ä¸çä¸ã§çå¨ãæ¯ãã£ã¦ããã³ã³ãã¥ã¼ã¿ã¼ã¦ã¤ã«ã¹ãã¨ã¢ãããã®ãããã¯ã¼ã¯ã®æ ç¹ã ã£ãã ç¿1æ27æ¥ãã¦ã¼ããã¼ã«ï¼æ¬§å·åäºè¦å¯æ©æ§ã¯ããªã©ã³ãã¨ãã¤ãããã©ã³ã¹ããªãã¢ãã¢ãã«ãããã¢ã¡ãªã«ãã¤ã®ãªã¹ãã¦ã¯ã©ã¤ãã®8ãå½ã®æ²»å®å½å±ãªã©ã¨ã®ååææ»ã§ãã¨ã¢ããããæ¡æ£ããããããã¯ã¼ã¯ã®æ å ±åºç¤ã«ä¾µå ¥ãã¦å¶å§ãå é¨ããåæ¢ãããã¨çºè¡¨ããã ä½æ¦åã¯ãOperation LadyBirdãï¼ãã³ãã¦ã ã·ä½æ¦ï¼ã ã¨ã¢ããããé ä¿¡ãã¦ããç¯ç½ªã°ã«ã¼ãããMealybugï¼ã³ãã«ã¤ã¬ã©ã ã·ï¼ãã¨å¼ã°ãã¦ãããã¨ããã天æµã§ãããã³ãã¦ã ã·ã®ååãã¤
ç®ç å°ããã¤å®éã®ã½ãªã¥ã¼ã·ã§ã³ãç»å ´ãã¤ã¤ããã¼ããã©ã¹ããããã¯ã¼ã¯ã«ã¤ãã¦ããã®æãç«ã¡ãè¨è¨ææ³ãã»ãã¥ãªãã£ã®æ§æãå®éç¨ã®èª²é¡ã«ã¤ãã¦è§£èª¬ããããã¼ããã©ã¹ããããã¯ã¼ã¯ãã®è¦ç´ããã¦ã¿ã¾ãã ç¹ã«ãçµç¹ã®ãããã¯ã¼ã¯æ§ç¯ãéç¨ãæ å½ããæ å ±ã·ã¹ãã é¨éã®æ å½ã§ããã°ãä»å¾ã®ãããã¯ã¼ã¯ã®å¨ãæ¹ãèããä¸ã§æéã«ãªãä¸åã ã¨æãã¾ãã https://www.oreilly.co.jp/books/9784873118888/ ã¼ããã©ã¹ããããã¯ã¼ã¯ã®æãç«ã¡ã¨æ¦è¦ 1967å¹´ã¾ã§é¡ãã主ã«è»äºã»å¦è¡ç®çã§éä¿¡ããããã«ãåãã¼ãããã±ããã交æãããARPANETã¨ãããããã¯ã¼ã¯è¨è¨ãèæ¡ããã¾ãããä»ã®ã¤ã³ã¿ã¼ãããã®å身ã§ãã è¨ç«ããå½åã¯ãããã¯ã¼ã¯ä¸ã®ãã¼ãã®èº«å ãã»ã¨ãã©å¤å¥ã§ããç¶æ ã ã£ãã®ã§æ å ±ã®æ¼ãããæ¹ãããæ°ã«ããå¿ è¦ããªãã£ãã®ã§ããããããã¯ã¼
Googleãã»ãã¥ãªãã£ã¹ãã£ãã¼ãTsunamiãããªã¼ãã³ã½ã¼ã¹ã§å ¬éããã¼ãã¹ãã£ã³ãªã©ã§èªåçã«èå¼±æ§ãæ¤åºãããã¼ã« Announcing the release of the Tsunami security scanning engine to the open source communities to protect their usersâ data, and foster collaboration.https://t.co/qrvmilHm1r â Google Open Source (@GoogleOSS) June 18, 2020 Tsunamiã¯ãã¢ããªã±ã¼ã·ã§ã³ã«å¯¾ãã¦ãããã¯ã¼ã¯çµç±ã§èªåçã«ã¹ãã£ã³ãè¡ããèå¼±æ§ãçºè¦ãã¦ããããã¼ã«ã§ãã Googleã¯ãç¾å¨ã§ã¯æ»æè ãèªååãããæ»æãã¼ã«ã¸ã®æè³ãç¶ãã¦ããããããä¸ã«å ¬éããããµã¼ãã¹ãæ»
English version è¦ç´ dockerã¯ããã©ã«ãã§ã»ãã¥ãªãã£æ©æ§ï¼Spectreèå¼±æ§ã®å¯¾çï¼ãæå¹ã«ãã¾ãããã®å½±é¿ã§ãRubyãPythonã®ãããªã¤ã³ã¿ããªã¿ã¯é度ãå£åãã¾ããç¹ã«CPUå¾éãªããã°ã©ã ã§é¡èã«é ããªãã¾ãï¼å®è¡æéãåãããã«ãªããã¨ãããã¾ãï¼ã ç¾è±¡ Rubyã§1ååã«ã¼ãããã³ã¼ãããç´æ¥ãã¹ãä¸ã§å®è¡ããå ´åã¨ãdockerä¸ã§å®è¡ããå ´åã§å®è¡æéãæ¯è¼ãã¦ã¿ã¾ãã ç´æ¥ãã¹ãä¸ã§å®è¡ããå ´åï¼ $ ruby -ve 't = Time.now; i=0;while i<100_000_000;i+=1;end; puts "#{ Time.now - t } sec"' ruby 2.7.1p83 (2020-03-31 revision a0c7c23c9c) [x86_64-linux] 1.321703922 sec docker
ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã«ãªãããããã2å¹´éåã®åå¼·å 容ã¨åèã«ãªã£ãè³æã¨ã èªåã®æ¯ãè¿ããå ¼ãã¦2å¹´åã®åå¼·å 容ã¨ãããã£ããã¾ã¨ãããã¨æãã¾ãã æ°åããããã¯ã¨ã³ãéçºã2å¹´ç¨è¡ãããã®å¾ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã¨ãã¦æ¨ªæã»ãã¥ãªãã£é¨éã«ç°åãã¾ããã ããããæ´ã«2å¹´ãçµã¡ãæ¥æããã»ãã¥ãªãã£ãµã¼ãã¹ã®éçºã¨ãããããã¨ã«ãªã£ãã®ã§ã ããåããããªäººãå± ãéã«ãªãã¨ãªãåèã«ãªãã°ããããªã¨ããæå³ã§æ¸ãã¦ã¾ãã ã¡ãªã¿ã«ã»ãã¥ãªãã£é¨éã«ç°åããã¾ã§ã®ã»ãã¥ãªãã£ã®ç¥èã¬ãã«ã¯ã徳丸æ¬ã2åéãã§èªãã§ããç¨åº¦ã§ãã ã»ãã¥ãªãã£é¨éã«ç§»ã£ã¦ããã¯èå¼±æ§è¨ºæã»ãã°ç£è¦ã»éçºã¬ã¤ãã©ã¤ã³å¨ãã»èå¼±æ§ç®¡çã¨ãããã£ã¦ã¾ããã æ¬è¨äºã§ã¯èªåèªèº«ãã¦ã¼ã¶ç³»ã®ä¼æ¥ã«å±ãã¦ããã®ã§ããã³ãã¼ã¨ããã¡ãå¯ãã®å 容ã§ã¯ãªãã§ãã ãã¨ã§ããéã社å ã®äºæ ãè¨è¼ãã¾ãããä½ãåé¡ã«ãªã
å¼ç¤¾ã¯ã©ã¹ã¡ã½ããæ ªå¼ä¼ç¤¾ä¸»å¬ã®ã¤ãã³ããDevelopers.IO 2019 TOKYOãã§ã®ç»å£è³æã§ãã ã»ãã¥ãªãã£å¯¾çã¡ã¬çãããã¯ã¹ ããã°: https://dev.classmethod.jp/cloud/aws/developers-io-2019-tokyo-all-securiâ¦
2019å¹´6æ8æ¥å¤ãã¯ã¬ã¸ããã«ã¼ãã®æ å ±çªåãç®çã¨ãããã¼ã¸ã稼åãã¦ããã¨æ å ±ãããã ãã¾ãããå½ãã¼ã¸ã稼åãã¦ãããã¡ã¤ã³ãIPã¢ãã¬ã¹ã調ã¹ãã¨ãããããã¤ãèå³æ·±ãæ å ±ã確èªã§ããããã調ã¹ãå 容ãããã§ã¯ã¾ã¨ãã¾ãã å½æ±ºæ¸ç»é¢ã ããã®ãµã¼ãã¼ æ å ±æä¾é ããURLã§ã¯ã¯ã¬ã¸ããã«ã¼ãæ å ±ãçªåãããã¨ãç®çã¨ããå½æ±ºæ¸ç»é¢ã稼åãã¦ããã ãµããã¡ã¤ã³ã«ã¯æ±ºæ¸ä»£è¡ãµã¼ãã¹ã®ãã¤ã¸ã§ã³ãã«ä¼¼ããæååãç¨ãããã¦ããã å½æ±ºæ¸ç»é¢ã¯ã¯ã¤ã³è²©å£²ãè¡ã£ã¦ããä¼ç¤¾åããã©ã¼ã ä¸é¨ï¼ã¢ã¶ã¤ã¯é¨ï¼ã«æ²è¼ã ãã®ä¼ç¤¾ã¯2019å¹´2æã«Webãµã¤ãã®æ¹ä¿®ãç®çã¨ãã¦ä¸æééããã¨æ¡å ã 6æã«æ°ãã¡ã¤ã³ã§ECãµã¤ãåéãæ°ãã¡ã¤ã³ã¸ç§»è¡ããçç±ã¯ã諸äºæ ã«ãããã¨ã®ã¿èª¬æã åé¡ã®ãã¡ã¤ã³search-hot.comã調ã¹ã åé¡ã®ãã¼ã¸ã稼åãã¦ãããã¡ã¤ã³search-hot.co
æ¯æ¥ã®ããã«ä¼æ¥ãçµç¹ãçã£ããµã¤ãã¼æ»æãç¹°ãè¿ããããã®æ¹æ³ã次ã ã¨æ°ãããªã£ã¦ãã¾ããçããã®ä¸ã«ã¯ã²ãã£ã¨ãã¦ãå°ããªä¼æ¥ãååå®ãã ãã®ã»ãã¥ãªãã£ã®ç¥èã身ã«ä»ããã«ã¯ãããç¨åº¦ãéããããã¯ããã¨æã£ã¦ããæ¹ãããã®ã§ã¯ãªãã§ããããï¼ãå®ã¯ããããªãã¨ã¯ããã¾ããï¼ å é£ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã³ã¿ã¼ï¼NISCï¼ã¯2019å¹´4æ19æ¥ãæ°ãã«ãå°ããªä¸å°ä¼æ¥ã¨NPOåãæ å ±ã»ãã¥ãªãã£ãã³ããã㯠åçï¼Ver.1.00ï¼ããå ¬éãã¾ããããã®å 容ã¯ãã»ãã¥ãªãã£æ¬ãä¸æ¢ãã¦ããçè ãããã¬ã¬ãã¨ããªã£ãã»ã©ã§ããããã¯ãç´ æ´ãããï¼ ãã©ããã¦ãã®äººã¯ãä»äººã®æ¬ãããã¾ã§æ¨ãã®â¦â¦ï¼ãã¨é¢é£ãã£ãèªè ãããããããã¾ããããã®æ¬ãèªãã§ã»ããã¨ç§ãèããæ ¹æ ãããããã詳ãã説æãã¦ããã¾ãããã NISCã¯ããã¾ã§ããå人åãã«é»è²ã表ç´ã®ãã¤ã³ã¿ã¼ãããã®å®å ¨ã»å®å¿ãã³
ã¯ããã« èªåã使ã£ã¦ããAWSç°å¢ã®ã»ãã¥ãªãã£ã«åé¡ããªããã¨å¿é ã«ãªããã¨ã¯ãªãã§ããããï¼ç§ã¯ããããã¾ããããã§CIS Amazon Web Service Foundations Benchmark ã¨ããAWSã®ã»ãã¥ãªãã£ã®ã¬ã¤ãã©ã¤ã³ã«æ²¿ã£ã¦ä½¿ã£ã¦ããAWSã¢ã«ã¦ã³ãã®ã»ãã¥ãªãã£ã®ç¶æ³ããã§ãã¯ãã¦ã¿ã¾ããããã§ãã¯é ç®ã¯å ¨é¨ã§52ããã¾ããå 容ãä¸éã確èªããã¨ããç¥ããªãã£ãAWSã®ã»ãã¥ãªãã£ã®æ©è½ããã¦ãã¦ãç¥ããã¨ãã§ããè¦ãã ãã§ãã¨ã¦ãåå¼·ã«ãªãã¾ãããç°¡åã«ãã§ãã¯ããæ¹æ³ãä½µãã¦ç´¹ä»ãã¾ãã®ã§ãã²ä½¿ã£ã¦ããAWSç°å¢ã§ãã§ãã¯ãã¦ã¿ã¦ãã ããã 1 IAM 1.1 rootã¢ã«ã¦ã³ããå©ç¨ããªã rootã¢ã«ã¦ã³ãã¯å¼·åãªæ¨©éãæã¤ãããrootã¢ã«ã¦ã³ããå©ç¨ããIAMã¦ã¼ã¶ã¼ãå©ç¨ãã¦ãã ãããé常éç¨ã§rootã¢ã«ã¦ã³ããå©ç¨ããã¦ããªãã確èªã
2018å¹´ã®å¹´æããã大é¨ãã¨ãªã£ã¦ããSpectreã¨Meltdownã®èå¼±ï¼ãããããï¼æ§ããã£ããã¨è§£èª¬ãããããã»ããµã®ä½ãåé¡ã¨ãªã£ã¦èå¼±æ§ãèµ·ãã¦ããã®ã ãããï¼ é£è¼ç®æ¬¡ 2018å¹´æ£ææ©ã ãããã»ããµæ¥çã«é¨åãèµ·ãã¦ããããã§ã«ãã¡ããã¡ãã§å ±éããã¦ããã®ã§ãåãã®æ¹ãå¤ãã¨æãããSpectreï¼ã¹ãã¯ã¿ã¼ï¼ã¨Meltdownï¼ã¡ã«ããã¦ã³ï¼ã¨å¼ã°ããããã»ããµã®èå¼±æ§ã®åé¡ã§ããï¼èå¼±æ§ã®è©³ç´°ã¯ãGoogle Project Zeroã®ãReading privileged memory with a side-channel ãåç §ã®ãã¨ï¼ã èå¼±æ§ã¯ã以ä¸ã®3ã¤ã§ããããVariant 1ãã¨ãVariant 2ããSpectreã¨å¼ã°ãããã®ããVariant 3ããMeltdownã¨å¼ã°ããèå¼±æ§ã ã Variant 1: bounds check bypa
2018å¹´1æ3æ¥ã«CPUã«é¢é£ãã3ã¤ã®èå¼±æ§æ å ±ãå ¬éããã¾ãããå ±åè ã«ããã¨ãããã®èå¼±æ§ã¯MeltdownãSpectreã¨å¼ç§°ããã¦ãã¾ããããã§ã¯é¢é£æ å ±ãã¾ã¨ãã¾ãã èå¼±æ§ã®æ¦è¦ å ±åè ãèå¼±æ§æ å ±ã次ã®å°ç¨ãµã¤ãã§å ¬éããã Meltdown and Spectre (ã¾ãã¯ãã¡ã) 3ã¤ã®èå¼±æ§ã®æ¦è¦ãã¾ã¨ããã¨æ¬¡ã®éãã èå¼±æ§ã®å称 Meltdown Spectre CVE CVE-2017-5754ï¼Rogue data cache loadï¼ CVE-2017-5753ï¼Bounds check bypassï¼ CVE-2017-5715ï¼Branch target injectionï¼ å½±é¿ãåããCPU Intel IntelãAMDãARM CVSSv3 åºæ¬å¤ 4.7(JPCERT/CC) 5.6(NIST) âã«åã PoC å ±åè éå ¬é è«æä¸ã«x
ã¯ããã« AWSã®éç¨æ§ç¯ãã¾ããããã¤ã³ãã©ã¨ã³ã¸ãã¢ã®ããã«åãã¦ãã»ãã¥ãªãã£ã§èããã¹ãè¦ç¹ã¨ä»£è¡¨çãªã½ãªã¥ã¼ã·ã§ã³ããç´¹ä»ãã¾ãã AWSã§ã®ã»ãã¥ãªãã£ãèããåã«ãç§éèªèº«ã®ã»ãã¥ãªãã£ãèãã¦ã¿ã¾ãããã "å¤åºåã«éµãããã"ã"ã²ã¨ãã®ãªãéã¯ãªãã¹ãéããªã"ãªã©æä½éãã£ã¦ããã¹ã対çãããã¾ãã ããããã®ãéãããã¦ããã£ã¬ã¼ããéã£ã¦ããéµãããã¦å¤åºãã¦ã¯æå³ãããã¾ããã AWSã®ã»ãã¥ãªãã£å¯¾çãåæ§ã§ãã 追å ã®ã³ã¹ããæã£ã¦ã»ãã¥ãªãã£ã½ãªã¥ã¼ã·ã§ã³ãå°å ¥ããåã«ãæä½éãã£ã¦ããã¹ã対çãããã¾ãã ç¹ã«ä»£è¡¨çãªãã®ããç´¹ä»ãã¾ãã åºæãä¸æãªAMIã¯ä½¿ããªã EC2ã®ä½æå ã¨ãªãAMIï¼ãã·ã¼ã³ã¤ã¡ã¼ã¸ï¼ã¯èª°ã§ãå ¬éã§ãã¾ãã ä¸ã«ã¯æªæã®ããã½ããã¦ã§ã¢ãå«ã¾ããAMIãå«ã¾ãã¾ãã AWSãä¿¡é ¼ã§ãããã³ãã¼ãæä¾ããAMIã使ãã¾ãããã
注æ æ¬ä»¶è¨äºã§ãããç§ã®ä¸é©åãªè¡åï¼æ¾ã£ãã¹ã¯ãªãããæ¤è¨¼ãªãèµ°ãããï¼ãåå ã§ãããdockerã¯ï¼ç¹ã«ä½ãããªãã¨ãï¼å±éºãã¨ã®èª¤è§£ãçæ§ã«ä¸ããç¹ããè¿·æãããããããã¾ãããç³ã訳ãããã¾ããã æ¡æ£ããã¦ããè¨äºãåé¤ããã®ã¯ãããªã誤解ãæããããªãã¨æãã¾ããã®ã§ãåé ã«æ³¨æãä»è¨ãã¦ããã¾ãã以ä¸ã®è¨äºã¯ããèªåãä½ãã¦ããããã¡ãã¨æ¤è¨¼ã§ããªãã¨ã»ãã¥ãªãã£ãã¼ã«ãçã¿åºããã¨ããæå³ã§åèã«ãã¦é ããã°å¹¸ãã§ãã è¿½è¨ Twitterãã¯ã¦ãã§è¨åããã ãã¾ããçæ§ããããã¨ããããã¾ãã æ¬ä»¶ã¯pullãã¦ããã¤ã¡ã¼ã¸ãæªæããéçºè ã«ãããã®ãã©ããã«ãããããä¸é©åãªè¨å®ããã¦ããã¨èµ·ããå¾ã¾ãã â»ã³ã¡ã³ãæ¬ã«è³ªåã¸ã®åçã¨ããå½¢ã§ãç§ããã®ã¨ãã«èµ°ããã¦ããã¤ã¡ã¼ã¸ã®ä¸è¦§ãæãã¦ããã¾ãããã©ã®ã¤ã¡ã¼ã¸ãè©å¤ãããã®ã ã¨æãã¾ãã çæ§ã«ãããã¾ãã¦ã¯ãã
çµç·¯ã¨æ¦è¦ å½ç¤¾ãéå¶ããç·æ¥å¯¾å¿ãµã¼ãã¹ããµã¤ãã¼119ãã¯ãæ¨å¹´ã®å¾åããè¤æ°ã®å¤§æä¼æ¥æ§ããé éæä½ã¦ã¤ã«ã¹ã«é¢é£ãã対å¿è¦è«ãåãã調æ»ãè¡ã£ã¦ã¾ããã¾ããã ãããã®äºæ¡ã§çºè¦ãããé éæä½ã¦ã¤ã«ã¹ã調æ»ããã¨ãããæ»æè ãã¤ã³ã¿ã¼ãããå´ããä¼æ¥å ãããã¯ã¼ã¯ã§åä½ããé éæä½ã¦ã¤ã«ã¹ãæãéã«ãDNSãããã³ã«ã使ç¨ããDNSãã³ããªã³ã°ã¨ãè¨ãããæå£ãå©ç¨ãã¦ãããã¨ã確èªããã¾ããã ããã¾ã§ã®ä»£è¡¨çãªé éæä½ã¦ã¤ã«ã¹ã«ããã¦ã¯ãWebé²è¦§ã§ç¨ããããHTTPï¼Sï¼ãããã³ã«ã使ç¨ããWebãµã¼ãã模ããæ令ãµã¼ãã使ç¨ãã¦ãã¾ããããããªããä»åã¯DNSãµã¼ãã模ããæ令ãµã¼ããæ§ç¯ãã¦ãããã¨ã確èªããã¾ããã å³1ï¼Webé²è¦§ã«ãããDNSã®åã DNSãããã³ã«ã¯ã¤ã³ã¿ã¼ãããã«ããã¦ããã¡ã¤ã³åï¼FQDNï¼ããIPã¢ãã¬ã¹ãªã©ã®æ å ±ãå¾ãããã«DNSãµã¼ãã¨ã®
ï¼å ±éçºè¡¨è³æï¼ 2015å¹´9æ14æ¥ ä¸çã§åãã¦ã誤ãçç£è¦ã®ä¸è¦ãªéåæå·å®é¨ã«æå ï½æ³¢æã®å縮ã«åºã¥ããæ°åçã«ããææ³ãå®è¨¼ï½ æ¥æ¬é»ä¿¡é»è©±æ ªå¼ä¼ç¤¾ï¼æ±äº¬é½å代ç°åºã代表åç· å½¹ç¤¾é·ï¼éµæµ¦å夫ã以ä¸ãNTTï¼ã¨æ±äº¬å¤§å¦å¤§å¦é¢å·¥å¦ç³»ç 究ç§ï¼æ±äº¬é½æ京åºãç·é·ï¼äºç¥ çï¼ã¯å ±åã§ãå åä¼éã®èª¤ãçç£è¦ãè¡ããã¨ãªãã«å®å ¨æ§ã確ä¿ããéåæå·ãä¸çã§åãã¦å®ç¾ãã¾ããã æ¬ææã¯ãç·å½ããå·®åä½ç¸ã·ããï¼round-robin differential phase shiftï¼ RRDPSï¼æ¹å¼ã¨å¼ã°ããéåæå·æ¹å¼ãå®é¨ã«ããå®è¨¼ãããã®ã§ãããã®çµæã«ãããä¸ç¢ºå®æ§åçã«åºã¥ãå¾æ¥ã®æ¹å¼ã¨ç°ãªããæ³¢æã®å縮ï¼â»1ï¼ãå®å ¨æ§ã®åçã¨ããéåæå·ãä¸çã§åãã¦å®è¨¼ãããã¨ãã§ãã¾ãããæ¬å®é¨ã«ãããå¾æ¥æ¹å¼ã§å¿ é ã¨ããã¦ããéä¿¡è ã¨åä¿¡è ã¨ã®éã§ã®å®æçãªèª¤ãçç£è¦ãä¸è¦ãªéåæå·ãå®
The HTC One Maxã®æç´èªåè£ ç½®ãæç´ã誰ã§ãèªããå½¢ã§ä¿åãã¦ãããã¨ãçºè¦ åçæä¾: HTC The guardian ã®è¨äº1ã«ããã¾ãã¨ãHTCã®ã¹ãããå©ç¨è ã®æç´ç»åã誰ã§ãèªã¿åºããå½¢ã§ä¿åãã¦ãããã¨ãçºè¦ããããã§ããçºè¦ããã®ã¯FireEyeã®4人ã®ç 究è éã§ã8æ5æ¥ã«BlackHat2ã§è«æ3ãçºè¡¨ããã¾ãã ãæç´ç»åã¯Â /data/dbgraw.bmp ã«æå·åãããã World Readable ã§ããã¦ããããã§ãããããã£ã¦ãã¢ããªçããèªç±ã«èªã¿åºããã¨ã®ãã¨ã ãã®çºè¦ã®ãã¨ãHTCã®æ ªä¾¡ã¯2å²è¿ãæ¥è½ããã®æ価ç·é¡ã¯è§£æ£ä¾¡å¤ãä¸åã£ã¦ãã4ã¨ã®ãã¨ã§ãã çºè¦å¾ãHTCã®æ ªä¾¡ã¯æ¥è½ ãã®ã»ãã¥ãªãã£ãã¼ã«ã¯HTCã®ãã®ã§ãããSamsungãå«ãå¤ãã®ã¹ããã¡ã¼ã«ã¼ã¯ãARMãªã©ãæä¾ããçµã¿è¾¼ã¿ã®ã»ãã¥ãªãã£æ©è½ã使ç¨ãã¦ããªããã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}