ãªã³ãã¬ãã¹ããã¯ã©ã¦ãã¸ã®ç§»è¡ãã¯ããããã¤ããªããã¯ã©ã¦ãç°å¢ãã·ã¼ã ã¬ã¹ã«ä¿è·ããªãããã¯ã©ã¦ãã®å©ç¹ãå®ç¾ãã¾ãã 詳ããã¯ãã¡ã
IPã¢ãã¬ã¹ã¯ãELB (å½å å)ãGlobal Accelerator(æµ·å¤å) ã®IPã¢ãã¬ã¹ã§å©ç¨ä¸ã®ãã®ã§ããã $ host 75.2.71.201 201.71.2.75.in-addr.arpa domain name pointer a5b041b48e73d3807.awsglobalaccelerator.com. $ host 52.194.15.214 214.15.194.52.in-addr.arpa domain name pointer ec2-52-194-15-214.ap-northeast-1.compute.amazonaws.com. $ host dev.classmethod.jp dev.classmethod.jp has address 75.2.71.201 dev.classmethod.jp has address 99.83.1
表2 Log4jã®ã¨ã¯ã¹ããã¤ã試è¡ã®ã³ã¼ã«ããã¯URLã§è¦ãããä¸ä½ãã¡ã¤ã³ã¨IPã¢ãã¬ã¹ èå¼±ãªãµã¼ãã¼ã®çºè¦ ç§ãã¡ã観測ããã¤ã³ãã¦ã³ãã®ã¨ã¯ã¹ããã¤ã試è¡ã®å¤ãã¯ãã¨ã¯ã¹ããã¤ãæåãéä¿¡è ã«éç¥ããã¢ã¦ããã¦ã³ããªã¯ã¨ã¹ããéä¿¡ããã ãã®ãã®ã§ããããããã®è©¦ã¿ã®ãã¹ã¦ãã¹ãã£ã³ãç®çã¨ãã¦ããã®ããæªæã®ããã¢ã¯ã¿ã¼ã®åµå¯æ´»åã®ä¸ç°ã§ãã£ãã®ãã¯ç¢ºèªã§ãã¦ãã¾ããããã®ãªãã«ã¯ã³ã¼ã«ããã¯URLã¨ã®æåã®ããã¨ããèå¼±ãªãµã¼ãã¼ã§ãããã¨ã示ãã¨ããã ãã®ã¨ã¯ã¹ããã¤ã試è¡ãããããã®å¤ãã¯ã以ä¸ã®ã³ã¼ã«ããã¯URLã«è¦ããããããªãã«ããªã¢ãã¼ã¯ã³ãã使ç¨ãã¦ãã¾ããã x[hostname].l4j.2sk9753uabgse6xz75tooe5ix.canarytokens[.]com ãã ããã¢ã¯ã¿ã¼ãã³ã¼ã«ããã¯URLããJavaã¯ã©ã¹ããã¼ããã¦å®è¡ãããã¨ã«ãã
2021å¹´12æ10æ¥ãJavaãã¼ã¹ã®ãã°åºåã©ã¤ãã©ãªãApache Log4jãã®2.xç³»ãã¼ã¸ã§ã³ï¼ä»¥éã¯Log4j2ã¨è¨è¼ï¼ã§ç¢ºèªãããæ·±å»ãªèå¼±æ§ãä¿®æ£ãããã¼ã¸ã§ã³ãå ¬éããã¾ãããã»ãã¥ãªãã£é¢ä¿çµç¹ã§ã¯éå»è©±é¡ã«ãªã£ãHeartbleedãShellshockã¨åã¬ãã«ã®èå¼±æ§ã¨ãè©ä¾¡ãã¦ãã¾ããããã§ã¯é¢é£ããæ å ±ãã¾ã¨ãã¾ãã ï¼ï¼ä½ãèµ·ããã®ï¼ Javaãã¼ã¹ã®ãã°åºåã©ã¤ãã©ãªLog4j2ã§æ·±å»ãªèå¼±æ§ï¼CVE-2021-44228ï¼ãä¿®æ£ãããã¼ã¸ã§ã³ãå ¬éãããããã®å¾ãä¿®æ£ãä¸å®å ¨ã§ãã£ããã¨ãªã©ãçç±ã«2件ã®èå¼±æ§ãä¿®æ£ãããã åºãå©ç¨ããã¦ããã©ã¤ãã©ãªã§ããããå½±é¿ãåãã対象ãå¤ãåå¨ããã¨ã¿ãããæ»æã容æã§ãããã¨ãã2014å¹´ã®HeartbleedãShellshock以æ¥ã®å±éºæ§ãããã¨ã¿ãåãããããThe Apache Software
Webã»ãã¥ãªãã£è£½åãªã©ãææããç±³LunaSecã®å ±åã«ããã¨ãMinecraftã®ä»ãã²ã¼ã ãã©ãããã©ã¼ã ã®SteamãAppleã®ãiCloudãããã®èå¼±æ§ãæã¤ãã¨ãåãã£ã¦ãããå½±é¿ã¯åºç¯å²ã«åã¶ã¨èããããã¨ããã ãã®èå¼±æ§ã®å½±é¿ãããã®ã¯ãLog4jã®ãã¼ã¸ã§ã³2.0ãã2.14.1ã¾ã§ã¨å½åã¿ããã¦ããããLog4jã®GitHubä¸ã®è°è«ã§ã¯ã1.xç³»ãåæ§ã®èå¼±æ§ãæ±ãã¦ãããã¨ãå ±åããã¦ããã対çã«ã¯ãä¿®æ£æ¸ã¿ã®ãã¼ã¸ã§ã³ã§ãã2.15.0-rc2ã¸ã®ã¢ãããã¼ããæ¨å¥¨ããã¦ããã ã»ãã¥ãªãã£ãã¥ã¼ã¹ãµã¤ããCyber Kendraãã«ããã°ããã®èå¼±æ§ã«å¯¾ãã¦ä»ä¸ãããCVEçªå·ã¯ãCVE-2021-44228ãã¨ããã èå¼±æ§ã®å ±åãåããTwitterä¸ã§ã¯ITã¨ã³ã¸ãã¢ãã¡ãç¶ã åå¿ãããã°ãããããæã£ã¦ãããããã£ã¨ã²ã©ããã°ã ã£ããããªããããª
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}