2020/08/26 10:00 SecurityInsight ãã¬ã³ããã¤ã¯ãã¯8æ20æ¥ãæè¿ã2種ã®Linuxåããããåãã«ã¦ã§ã¢ã«ããã¦ãé²åºããDockerãµã¼ãã¼ãçãæ´»åã確èªãããã¨ãã»ãã¥ãªãã£ããã°ã§çºè¡¨ããã確èªããããã«ã¦ã§ã¢ã¯åæ£åãµã¼ãã¹å¦¨å®³ï¼DDoSï¼ã®å®è¡ãç®çã¨ãããXORDDoSãã¨ãKaijiãã®2種é¡ããã®æ¦è¦ã¯ä»¥ä¸ã®ã¨ããã Dockerãµã¼ãã¼ãæ»æã®å¯¾è±¡ã«å®ããã®ã¯ãXORDDoSã¨Kaijiã®ä¸¡æ¹ã«ããã¦æ°ããè¦ãããåããXORDDoSã¯ã¯ã©ã¦ãã·ã¹ãã ä¸ã®Linuxãã¹ããçããã¨ã§ç¥ããã¦ãããæè¿ç¢ºèªãããKaijiã¯IoTæ©å¨ã«å½±é¿ãä¸ãããã¨ãæåã®èª¿æ»ã§å¤æãã¦ãããæ»æè ã¯é常ããªã¼ãã³ãªã»ãã¥ã¢ã·ã§ã«ï¼SSHï¼ããã³Telnetãã¼ããã¹ãã£ã³ããå¾ããããåãã«ã¦ã§ã¢ã使ç¨ãã¦ãã«ã¼ããã©ã¼ã¹æ»æãå®è¡ããã ç¾å¨ãæ»
å°å·ãã ã¡ã¼ã«ã§éã ããã¹ã HTML é»åæ¸ç± PDF ãã¦ã³ãã¼ã ããã¹ã é»åæ¸ç± PDF ã¯ãªããããè¨äºãMyãã¼ã¸ããèªããã¨ãã§ãã¾ã ãã¬ã³ããã¤ã¯ãã¯ãDockerã³ã³ããã¼ããã¹ããããµã¼ãã¼ã«ä¾µå ¥ãåæ£åãµã¼ãã¹å¦¨å®³ï¼DDoSï¼æ»æã®å®è¡ã試ã¿ã2種é¡ã®ãã«ã¦ã§ã¢ãXORDDoSããKaijiãã®åæçµæã«ã¤ãã¦ããã°ã§å ±åããã å社ã«ããã¨ãXORDDoSã¯ã¯ã©ã¦ãç°å¢ä¸ã®Linuxãã¹ããæ¨çã«ãããä¸æ¹ãKaijiã¯æè¿ã«çºè¦ãããIoTæ©å¨ãæ¨çã«ããã¨ããããããã®ãã«ã¦ã§ã¢ã¯ãSSHãããã¯Telnetã®ãã¼ãã¹ãã£ã³ãè¡ããã¿ã¼ã²ããã®ãã¹ããè¦ã¤ããã°ããããåãã«ã¦ã§ã¢ã使ã£ã¦ãã«ã¼ããã©ã¼ã¹ï¼ç·å½ãï¼æ»æãå®è¡ããããã¼ãã¹ãã£ã³ã§å¯¾è±¡ã«ãããã¼ãã®1ã¤ããDocker APIã§æå·åããã¦ããªãæªèªè¨¼éä¿¡ã«ä½¿ããããã¼ã2375ã ã¨å¤æã
ã¿ãªããã³ã³ããã使ããã¨ã®æå³ãèªä¿¡ãã£ã¦çããããã§ããããï¼ ãã1å¹´ã»ã©ã³ã³ããé¢é£ã®ä»äºãã¡ã¤ã³ã§ãã£ã¦ããããã³ã¼ã§ãããããããªã客æ§ãããããã£ãã声ãããã ããã¨ãå¤ãããã¾ããã ãããã¯ã³ã³ããåããæå³ãããã®ï¼ã ããããªã³ã³ããéç¨ã¯å±ãªãï¼ã ãECSã®è¨å®ã¨ãå®éããã©ããdocker runããã ãï¼ã ãEKSã£ã¦ä½¿ããã®ï¼ã ãããã声ãè´ãä¸ã§ãèªåãªãã®çãã模索ãã¦ããããã§ããã岡山ã§ã®å¼ç¤¾ã¤ãã³ãAWSææ°æè¡ã®ç¥å ¸Developers.IO 2019 at 岡山åã¸ç»å£ããã«ãããããã®ãããã®ãããããèªåãªãã«æè¯ããã®ããæ¬æ¥ã®å 容ã§ãã ããã®ã¢ããªãã³ã³ããåããæå³ãããã®ããããããªãã ãã³ã³ããåãããã¨ã§ä½è¨ããã©ããããªã£ãã ãAWSã®ã³ã³ãããµã¼ãã¹ã®ä½ã使ã£ããè¯ãã®ãããããªãã ã¨ããæ©ã¿ãæ±ãã¦ããæ¹ã«ã¯ã
Windowsã³ã³ããã¯ãã¹ã¯ãããã®å¤¢ãè¦ãªãï¼ãã®ç¥èããã³ãã«æ£ããï¼ Windowsã«ã¾ã¤ããé½å¸ä¼èª¬ï¼150ï¼ Windows Server 2016ããã³Windows 10 ãã¼ã¸ã§ã³1607ããã¯ãDockerã®ãµãã¼ãã追å ããã¾ãããWindowsãDockerã«å¯¾å¿ãããã¨ã§ãâãã¹ã¯ãããã¢ããªãDockerã§ã³ã³ããåãããâã¨ãã声ãèãããã¨ãããã¾ãããå®ç¾ä¸å¯è½ãªãã¨ã§ãï¼å°ãªãã¨ãç¾æç¹ã§ã¯ï¼ããã£ã¬ã³ã¸ãããã¨ã¯æ¢ãã¾ããããç¡é§ãªåªåã«çµããã¨æãã¾ãã Windowsã«ã¾ã¤ããé½å¸ä¼èª¬ LinuxãªãGUIã¢ããªãã³ã³ããåã§ããã®ã«ãWindowsã ã¨ãªãã§ããªãã®ï¼ Dockerã®æè¡ã¯ã主ã«ã¯ã©ã¦ãã¢ããªããµã¼ãã¹ã®éçºç¾å ´ã§ãéçºã¨ãããã¤ã®ã¹ãã¼ãã¢ãããå³ãããã«ä½¿ç¨ãããæè¡ã§ããGUIãæã¤ãã¹ã¯ãããã¢ããªã®ã³ã³ããåã¯ããããæ³
7æã«ä¿®æ£ããããDockerãã®èå¼±æ§ãCVE-2019-14271ãã«é¢ããå®è¨¼ã³ã¼ããå ¬éããããããã¾ã§æ³¨ç®ãéãããã¨ãå°ãªãã£ãèå¼±æ§ã ãããã¹ãã®ã«ã¼ã権éãåå¾ããããããããããåæããPalo Alto Networksã¯ãåã½ããã«ããã¦ãããã¾ã§ã§ãã£ã¨ãæ·±å»ãªèå¼±æ§ãã¨è¡¨ç¾ãã¦ããã ãCVE-2019-14271ãã¯ããå19.03.1ããã以åã®ãã¼ã¸ã§ã³ã«åå¨ãããã³ã¼ãã¤ã³ã¸ã§ã¯ã·ã§ã³ãã®èå¼±æ§ãã³ã³ããéã§ãã¡ã¤ã«ã®ã³ãã¼ã«ç¨ããã³ãã³ããdocker cpãã«èµ·å ããã³ã³ããããèå¼±æ§ãæªç¨ãããã¨ããã¹ãã®ã«ã¼ã権éãåå¾ãããããããããã¨ããã åèå¼±æ§ã«ã¤ãã¦èª¿æ»ãè¡ã£ãPalo Alto Networksã¯ã2æã«å¤æããã³ã³ããã®ã©ã³ã¿ã¤ã ãruncãã«ãããèå¼±æ§ãCVE-2019-5736ãã¨åæ§ã«å±éºã§ããDockerãã«ããã¦ããã¾
10æ13æ¥é±ã«ããã¦çºçãããã¯ã©ã¦ãé¢é£ã®ã»ãã¥ãªãã¤ã»ãããã¯ããã¤ã¸ã§ã¹ãã§ãä¼ãããã â S3ã®è¨å®ãã¹ã«ãã20ä¸ä»¶ãè¶ ããå¿åè ã®å±¥æ´æ¸ãå ¬éããããç±³å½ã®æ±äººæ²ç¤ºæ¿Authentic Jobsã¨ã¤ã®ãªã¹ã®æ±äººã¢ããªSonicJobs AppãAuthentic Jobsã¯221,130件ã®å¿åè ã®å±¥æ´æ¸ãå ¬éãã¦ãããSonic Jobsã¯ãããªãªããããã³ã¤ã³ã¿ã¼ã³ã³ããã³ã¿ã«ã®ããã«ãã§ã¼ã³ã使ç¨ããã¤ã®ãªã¹ã®å°å£²ããã³ã¬ã¹ãã©ã³ã®æ±äººã¢ããªã§ã29,202件ã®å¿åè ã®å±¥æ´æ¸ãå ¬éãã¦ããã 両社ã¯ãAmazon Web Servicesï¼AWSï¼ãã±ããã®è¨å®ããããªãã¯ã«è¨å®ããä¿åãããå±¥æ´æ¸ãS3ãã±ããã®å ´æãç¥ã£ã¦ãã人ãªã誰ã§ãã¢ã¯ã»ã¹ã§ããããã«ãªã£ã¦ããã â Dockerãã¹ããçããã¯ãªããã¸ã£ã㯠ã¯ã¼ã Graboidãããã¢ã«ããããã¯ã¼ã¯ã¹ã®U
éç¨ç®¡çã楽ã«ãªããã¯ã©ã¦ãã¨ã®è¦ªåæ§ãé«ãââã¨ã³ã¸ãã¢ãªãã°é¿ãã¦ã¯éããªããã³ã³ãããæè¡ã®ã¡ãªããã¯ãæ¢ã«å¤ãã®ã¨ã³ã¸ãã¢ãèã§æãã¦ãããã®ã ãããã³ã³ããã¢ããªã±ã¼ã·ã§ã³ãåããã¾ã§ã«ã¯ãã³ã³ããã¤ã¡ã¼ã¸ãä½æããã¬ã¸ã¹ããªã«ã¢ãããã¼ããããã®ã¤ã¡ã¼ã¸ããããã¤å ã«ãã¦ã³ãã¼ãããã³ã³ãããå®è¡ããã¨ããããã»ã¹ãè¸ããã³ã³ããã¢ããªã±ã¼ã·ã§ã³ã®æ§æã¯Dockerfileãªã©ã®ããã¹ãã§è¡¨ç¾ã§ãããã¨ããããæ§æ管çã¯å¯èªæ§ãé«ãã ã§ã¯ãããã«âè å¨âã¯ãªãã®ã ãããï¼ãã³ã³ããæè¡ãæ®åæã«å ¥ã£ããã¨ããããæ¨ä»ã§ã¯âã³ã³ããã»ãã¥ãªãã£âã«é¢ãã¦ã注ç®ãéã¾ã£ã¦ããããããã³ã³ããã»ãã¥ãªãã£ãæããã¤ã³ãã«ã¤ãã¦ã¯ãã¾ãã¾ãªæè¦ããããããã£ããã©ããå®ãã¹ããªã®ãããã©ãã«è å¨ãããã®ãããããåãããªãã¨ããã¨ã³ã¸ãã¢ãå°ãªããªãã ããã ããã§ä»åããã¬ã³ããã¤
ã³ã³ããã¤ã¡ã¼ã¸ã¯ãèå¼±æ§ãå«ãã ã¢ããªã±ã¼ã·ã§ã³ãä¸æ£ããã°ã©ã ãå«ãã§ãããã¨ããããã·ã¹ãã ãéç¨ãã¦ããæä¸ã«ãããã®èå¼±æ§ãçºè¦ããå ´åãã·ã¹ãã ã®æ¹ä¿®ãæ¥åã®åæ¢ã«ã¤ãªãã£ã¦ãã¾ããããã·ã¹ãã éçºæã«èå¼±æ§ãä¸æ£ããã°ã©ã ãæ¤åºããä»çµã¿ãæ±ããããã Smart Checkã¯ãã·ã¹ãã éçºæã«ãã³ã³ããã¤ã¡ã¼ã¸å ã«åå¨ããèå¼±æ§ã¨ä¸æ£ããã°ã©ã ãã¯ã©ã¦ããµã¼ãã¹ã®ã¢ã¯ã»ã¹ãã¼ãªã©ãã¹ãã£ã³ãããããã«ãããåã ã®ã³ã³ããã¤ã¡ã¼ã¸ã®å±éºåº¦ãå¯è¦åãããããã«ãããä¿®æ£ããã°ã©ã ãé©ç¨ããããéç¨æã«å¯¾çãããã§ããããã«ãªãã ã¹ãã£ã³ããèå¼±æ§ã¯ãç·æ¥åº¦ã«å¿ãã¦ãCriticalãããHighãããMediumãããLowãããNegligibleãããUnknownãã®6ã¤ã®ã¬ãã«ã§è¡¨ç¤ºãããã¾ããã³ã³ããã¤ã¡ã¼ã¸ãä¸æ£ããã°ã©ã ãå«ããã©ãããããã¿ã¼ã³ãããã³ã°ãæ©æ¢°
å°å·ãã ã¡ã¼ã«ã§éã ããã¹ã HTML é»åæ¸ç± PDF ãã¦ã³ãã¼ã ããã¹ã é»åæ¸ç± PDF ã¯ãªããããè¨äºãMyãã¼ã¸ããèªããã¨ãã§ãã¾ã Kenna Securityã¯ç±³å½æé5æ20æ¥ããDocker Hubãä¸ã§åºãå©ç¨ããã¦ãã1000ã®ãDockerãã³ã³ããã®ãã¡ãããã20ï¼ ããã種ã®æ¡ä»¶ä¸ã§ã¦ã¼ã¶ã¼ã·ã¹ãã ã«å¯¾ããæ»æã許ãè¨å®ã«ãªã£ã¦ãããã¨ãæããã«ããã ããã¯ãCisco Talosã8æ¥ã«æããã«ãããå ¬å¼çã®ãAlpine Linux Dockerãã³ã³ããã«åå¨ããèå¼±æ§ã¨åãåé¡ã¨è¨ãããAlpine Linux Dockerã¤ã¡ã¼ã¸ã¯éå»3å¹´éã«ãããããã¹ã¯ã¼ãã空ç½ã«ãã管çè ã¢ã«ã¦ã³ããæå¹ãªç¶æ ã§ãªãªã¼ã¹ããã¦ããã Kenna Securityã®ä¸»å¸ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã§ããJerry Gamblinæ°ã¯ãDocker Hubä¸
ããã«ã¡ã¯ãSkyWayã®éçºã»éç¨ããã¦ãã岩ç¬ï¼@iwashi86ï¼ã§ãã ä»åã®è¨äºã§ã¯ãå¼ç¤¾ã®ç ä¿®å 容ã®ä¸é¨ãå ¬éãã¾ãã ç ä¿®ã®çã æ¯å¹´200åè¶ ã®ç¤¾å¡ãNTTã³ãã¥ãã±ã¼ã·ã§ã³ãºã°ã«ã¼ãã«å ¥ç¤¾ãã¦ãã¾ãã å ¥ç¤¾ããã ãã社å¡ã®ä¸ã«ã¯ããã¨ãã¨é«ãæè¡åãæã£ã¦ãã社å¡ãå¤ããã¾ãã ä»å¹´åº¦ãããã½ããã¦ã§ã¢ã¨ã³ã¸ãã¢ãªã³ã°ã®ã¹ãã«ã®é«ã社å¡ï¼ä»åã¯35åï¼ã対象ã¨ãã¦æ°ããªç ä¿®1ãå®æ½ãã¦ãã¾ãã ç ä¿®ã®ä¸»ãªçãã¯ä»¥ä¸ã®2ã¤ã§ãã å³æ¦åã¬ãã«ã®ã¹ãã«ç¿å¾ å®éã®ç¾å ´ã§æç¨ã¨ãªãæè¡ã»éçºã¹ãã«ã®ç¿å¾ãã¦ãç¾å ´ã§ããã«æ´»èºã§ããããã« ãããã¯ã¼ãã³ã°ã®å¼·å / ã³ãã¥ããã£å½¢æ åæã ãã§ãªããè¬å¸«ã»ã¡ã³ã¿ãå«ãå 輩ã¨ã³ã¸ãã¢ã¨ã®ãããã¯ã¼ã¯ãå½¢æããäºãã«å½±é¿ãä¸ãåãæé·ã§ããããã« ãªãã2ç¹ç®ã«ã¤ãã¦è£è¶³ããã¨ãä»åã®ç ä¿®ã§ã¯ç¤¾å¤ã®ã¨ãã¹ãã¼ãã«ããããã°ã©ã ã«å ã
2019å¹´2æã«çºè¦ããèå¼±æ§ãæªç¨ãããä»®æ³é貨ã®æ¡æã«å©ç¨ããã¦ããDockerãã¹ããå¤æ°è¦ã¤ãã£ãã¨ä¼ããã DockerãKubernetesãªã©ã«ä½¿ããã¦ãããªã¼ãã³ã½ã¼ã¹ã®ã³ã³ããã©ã³ã¿ã¤ã ãruncãã«èå¼±æ§ãè¦ã¤ãã£ãåé¡ã§ãã»ãã¥ãªãã£ä¼æ¥ã®Impervaã¯3æ4æ¥ããã®èå¼±æ§ãçªãã¦ä»®æ³é貨ã®æ¡æã«å©ç¨ããã¦ããDockerãã¹ããå¤æ°è¦ã¤ãã£ãã¨ä¼ããã 2æã«çºè¦ããruncã®èå¼±æ§ã§ã¯ãæ»æè ãrootç¹æ¨©ãç²å¾ã§ãã¦ãã¾ãå¯è½æ§ãææããã¦ãããImpervaã«ããã¨ããã®èå¼±æ§ã¨ããªã¢ã¼ãã§Dockerãã¹ããã³ã³ããã¼ã«ããããã«ä½¿ããã¦ããAPIãçµã¿åãããã°ããã¹ããå®å ¨ã«å¶å¾¡ã§ãã¦ãã¾ãæããããã å社ã«ããã°ãæ¢ã«æªç¨ããã¦ããDockerãªã¢ã¼ãAPIãå¤æ°åå¨ãã¦ããããã®å¤ãã¯ãå¶å¾¡ãããã¹ããä»®æ³é貨ã®æ¡æã«å©ç¨ãã¦ããã¨ããã Doc
ï¼»éå ±ï¼½GitHub Actionsçºè¡¨ãDockerã³ã³ããã®é£ä¿ã«ããã¯ã¼ã¯ããã¼ãèªç±ã«å®ç¾©å¯è½ãGitHub Universe 2018 GitHubã主å¬ããã¤ãã³ããGitHub Universe 2018ããããµã³ãã©ã³ã·ã¹ã³ã§éå¹ãã¾ããã åæ¥ã®åºèª¿è¬æ¼ã§å社ã¯ãPull Request以æ¥ãã£ã¨ã大ããªæ°æ©è½ãï¼å社ã·ãã¢ãã¤ã¹ãã¬ã¸ãã³ã Jason Warneræ°ï¼ã¨ããGitHubã®æ°æ©è½ãGitHub Actionsããçºè¡¨ãã¾ããã GitHub Actionsã¨ã¯ãGitHubã®ã¤ãã³ããããªã¬ã¼ã¨ãã¦ä»»æã®Dockerã³ã³ããã®å®è¡ãé£ä¿ããã¦ãããã¨ã«ãããã¦ã¼ã¶ã¼ãèªç±ã«ã¯ã¼ã¯ããã¼ãå®ç¾©ã§ããã¨ãããã®ã§ãã ã¯ã¼ã¯ããã¼å ã®ã¢ã¯ã·ã§ã³ã¨ãã¦Dockerã³ã³ãããå®è¡ã§ãããããã³ã¼ãã®ãã«ãããã¹ãã®å®è¡ãã¯ã©ã¦ãã¸ã®ãããã¤ãªã©ãGitHubã®æ©
Googleãã³ã³ããã¤ã¡ã¼ã¸å ã®OSã®èå¼±æ§ãèªåçºè¦ãã¦ããããContainer Registry vulnerability scanningãããã¼ã¿å ¬é Googleã¯ãDockerã³ã³ããããã«ãããã³ã³ããã¤ã¡ã¼ã¸ãã¹ãã£ã³ããOSã®èå¼±æ§ãçºè¦ãã¦ãããæ©è½ãContainer Registry vulnerability scanningãããã¼ã¿çã¨ãã¦å ¬éããã¨çºè¡¨ãã¾ããã Dockerã³ã³ããã¯ã¢ããªã±ã¼ã·ã§ã³ã¨ä¸ç·ã«ã«ã¼ãã«ä»¥å¤ã®OSãä¸ç·ã«ããã±ã¼ã¸ã³ã°ããã¾ãããã®ã¨ããOSã«ææ°ã®ããããé©ç¨ããã¦ããªããªã©ã®èå¼±æ§ãOSã«åå¨ããå¯è½æ§ãããã¾ãã ä¸ãä¸èå¼±æ§ãæ®ã£ãã¾ã¾ã®ã³ã³ããã¤ã¡ã¼ã¸ããããã¤ãããã¨ãå¤é¨ããã·ã¹ãã ã«å¯¾ãã¦èå¼±æ§ãçªããã¦ãã¾ããã¨ã«ãªãããã¾ããã Container Registry vulnerability scan
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}