DNS Server Tests  top The topic of Testing Your DNS Servers has been moved to a new page. It explains DNS and lists multiple websites that report on the currently in effect DNS server(s). It is never obvious, yet it is critically important, to know whose DNS servers you are using. Firewall Testers  top Level setting: Every computing device on the Internet is assigned a number. Some have two number
1. å§ãã« ããã«ã¡ã¯ãmorioka12 ã§ãã æ¬ç¨¿ã§ã¯ãAWS ããã¸ã¡ã³ãã³ã³ã½ã¼ã«ã«ç¦ç¹ãå½ã¦ããã£ãã·ã³ã°ã«ãã MFA (Multi-Factor Authentication) èªè¨¼ã®åé¿ãäºä¾ãã»ãã¥ãªãã£å¯¾çã«ã¤ãã¦ç´¹ä»ãã¾ãã 1. å§ãã« å 責äºé æ³å®èªè 2. AWS ããã¸ã¡ã³ãã³ã³ã½ã¼ã« MFA (Multi-Factor Authentication) 3. ãã£ãã·ã³ã° (Phishing) MITRE ATT&CK 4. ãã£ãã·ã³ã°ã«ãã AWS ãã°ã¤ã³ã®ä»®æ³ MFA ããã¤ã¹èªè¨¼ã®åé¿ 5. ãã£ãã·ã³ã°ã«ãã AWS ãã°ã¤ã³ã® SSO èªè¨¼ã®åé¿ 6. AWS ãã°ã¤ã³ãã¿ã¼ã²ããã«ãããã£ãã·ã³ã°ã®äºä¾ äºä¾1 (Google æ¤ç´¢) äºä¾2 (ã¡ã¼ã«) äºä¾3 (ã¡ã¼ã«) 7. ãã®ä» Web ã¢ããªã±ã¼ã·ã§ã³ã«ããã MFA èªè¨¼ã®å
1. å§ãã« ããã«ã¡ã¯ãmorioka12 ã§ãã æ¬ç¨¿ã§ã¯ãAmazon EC2 ä¸ã§åã Web ã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã«ãã£ã¦èå¼±æ§æ»æãå¯è½ã ã£ãå®éã®äºä¾ã«ã¤ãã¦ç´¹ä»ãã¾ãã 1. å§ãã« 2. Amazon EC2 ã«ãããã»ãã¥ãªãã£ãªã¹ã¯ Amazon EBS 被害ããã£ãå ¬éäºä¾ 3. Amazon EC2 ã§èµ·ããããèå¼±æ§æ»æ SSRF ãå¯è½ãªèå¼±æ§ SSRF ã«ãããåé¿æ¹æ³ 4. Amazon EC2 ã®èå¼±ãªå ±åäºä¾ ç»åèªã¿è¾¼ã¿æ©è½ã«æ½ã SSRF ãæªç¨ãã EC2 ã®ã¯ã¬ãã³ã·ã£ã«ã®ä¸æ£å ¥æãå¯è½ SAML ã¢ããªã±ã¼ã·ã§ã³ã«æ½ã SSRF ãæªç¨ãã EC2 ã®ã¯ã¬ãã³ã·ã£ã«ã®ä¸æ£å ¥æãå¯è½ Webhook æ©è½ã«æ½ã SSRF ãæªç¨ãã EC2 ã®ã¯ã¬ãã³ã·ã£ã«ã®ä¸æ£å ¥æãå¯è½ Webhook æ©è½ã«æ½ã SSRF ãæªç¨ãã EC2 ã®ã¯ã¬ã
ã¯ããã« ããã«ã¡ã¯ãæ ªå¼ä¼ç¤¾Flatt Security ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®æ£®å²¡(@scgajge12)ã§ãã æ¬ç¨¿ã§ã¯ãAmazon S3 ã®èå¼±ãªä½¿ãæ¹ã«ããã»ãã¥ãªãã£ãªã¹ã¯ã¨å¯¾çã解説ããå®éã®è¨å®ä¸åãªã©ã«é¢ããäºä¾ã«ã¤ãã¦ãç´¹ä»ãã¾ãã Flatt Security ã¯å°é家ã®è¦ç¹ã§ã»ãã¥ãªãã£ãªã¹ã¯ã調æ»ããã»ãã¥ãªãã£è¨ºæãæä¾ãã¦ãã¾ããã¯ã©ã¦ãã¨ã¢ããªã±ã¼ã·ã§ã³ã®ç·åçãªè¨ºæã®äºä¾ã¨ã㦠SmartHR æ§ã®è¨ºæäºä¾ããããã¾ãã®ã§ãæ¯éã¤ã³ã¿ãã¥ã¼è¨äºãã覧ãã ãããGCP ã®äºä¾ã§ããããã¡ããä»ååãä¸ãã AWS ã§ãåæ§ã®è¨ºæãå¯è½ã§ãã ã¯ããã« Amazon S3 ã¨ã¯ ãã±ããã»ãªãã¸ã§ã¯ã ãã±ãã ãªãã¸ã§ã¯ã ã¢ã¯ã»ã¹ããªã·ã¼ ãã±ããããªã·ã¼ ã¢ã¯ã»ã¹ã³ã³ããã¼ã«ãªã¹ã(ACL) IAM ããªã·ã¼ ç½²åä»ã URL Amazon S3 ã«
æ å½ãã¦ããITãµã¼ãã¹ãªã©ã«ä½ãããã®ã¤ã³ã·ãã³ããé害ãçºçããæã«ã対å¦å¾ã®ã¢ã¯ã·ã§ã³ã¨ãã¦å ±åæ¸ãæåºãã¦äºè±¡ã®å 容ãå ±åï¼ã¬ãã¼ãï¼ããå ´åãããã æåºå ã¯ä¼ç¤¾ã®åã人ã ã£ããã¯ã©ã¤ã¢ã³ãã ã£ãããå ´åã«ãã£ã¦ã¯ã¦ã¼ã¶ã¼åãã«çºè¡¨ããããäºã®é¡æ«ãå ±åãã¦ãä»å¾åæ§ã®ãã¨ãèµ·ãããªãããã«åªåãã¾ããããããªããããããã®ã ãã©ã®ããã«åçºé²æ¢ã®åªåããã®ããæ¸ããã®ã§ãããã 主ã«ã¯ã©ã¤ã¢ã³ãåãã®ãã¸ãã¹å 容ã§ã¯ããããèªåã使ã£ã¦ãããã³ãã¬ãã¿ã¼ã³ãå ±æããã®ã§åèã«ãã¦ããããã°ã¨æãã1 å ¨è¬çãªãã¤ã³ã å¿å¾ã®ãããªãã®ã次ã®ç¹ã¯çæãã¦ã¦æ¬²ããã æ·¡ã ã¨å·éãªèª¬æããããããã å½ç¶ã®ãã¨ãªããäºå®ã¯èè²ããªããç¡é§ãªä¿®é£¾ãè¦ããªãã客観çãªäºå®ãç°¡æ½ã«è¿°ã¹ãã ä¾ï¼ âãä¸çæ¸å½é å¼µã£ã¦å¯¾å¿ãããâ¦ã âãå¯ãªãã§å¯¾å¿ãããâ¦ã âãæ¬å½ã®åå ã¯â¦ã ã§ããã
徳島çã¤ããçºç«åç°ç é¢ ã³ã³ãã¥ã¼ã¿ã¦ã¤ã«ã¹ææäºæ¡æèè ä¼è°èª¿æ»å ±åæ¸ã«ã¤ã㦠令å3å¹´10æ31æ¥ã®æªæãã¤ããçºç«åç°ç é¢ããµã¤ãã¼æ»æãåããé»åã«ã«ããã¯ããã¨ããé¢å ã·ã¹ãã ãã©ã³ãµã ã¦ã§ã¢ã¨å¼ã°ãã身代éè¦æ±åã³ã³ãã¥ã¼ã¿ã¦ã¤ã«ã¹ã«ææããã«ã«ããé²è¦§ã§ããªããªããªã©ã®å¤§ããªè¢«å®³ãçãã¾ããã令å4å¹´1æ4æ¥ã®é常診çåéã¾ã§ã®éãæ£è ãããã¯ããé¢ä¿è ã®çãã¾ã«ã¯å¤å¤§ãªãè¿·æã¨ãå¿é ãããããããã¾ãããã¨ãæ¹ãã¦æ·±ããè©«ã³ç³ãä¸ãã¾ãã äºä»¶çºçå¾ãå½é¢ã®è·å¡ã¯ä¸ä¸¸ã¨ãªã£ã¦æ©æ復æ§ãç®æãã¾ãããå ¨å®¹è§£æãæ å ±æ¼ããæç¡ã®ç¹å®ããããã¾ãã¯ç é¢ã¨ãã¦ã®æ©è½ãä¸æ¥ãæ©ãåãæ»ãããã«ãæ£è ããã®ãã¼ã¿ãããã«å¾©å ããããã端æ«ãå©ç¨ã§ããç¶æ³ã«ã©ã®ããã«æ»ããã«ç¦ç¹ãå½ã¦ã¤ã³ã·ãã³ã対å¿ãè¡ã£ã¦ããã¾ããã幸ãã«ãã¦ã調æ»å¾©æ§ãè«ãè² ã£ãäºæ¥è ã®ä½æ¥ãé»åã«ã«ãæ¥è ã®ä»®ã·
æ¬ããã°ã¯ããã¡ãã«æ²è¼ããã¦ããè±æããã°ã®æ訳ã§ããä¸ãä¸å 容ã«ç¸éãããå ´åã¯ãåæãåªå ããã¾ããã¾ããPDFçããã¦ã³ãã¼ãããã ãã¾ãã ã¯ããã« â å ±ååµæ¥è å ¼å ±åæé«çµå¶è²¬ä»»è ãã 2022å¹´4æä¸æ¬ã«çºçããé害ã«ãããã客æ§ã¸ã®ãµã¼ãã¹æä¾ãä¸æããããã¨ããè©«ã³ç³ãä¸ãã¾ããç§ãã¡ã¯ãå½ç¤¾ã®è£½åãã客æ§ã®ãã¸ãã¹ã«ã¨ã£ã¦ããã·ã§ã³ã¯ãªãã£ã«ã«ã§ãããã¨ãç解ãã¦ããããã®è²¬ä»»ãéãåãæ¢ãã¦ãã¾ããä»åã®å ¨è²¬ä»»ã¯ç§ãã¡ã«ãããå½±é¿ãåããã客æ§ã®ä¿¡é ¼ãå復ããããã«å°½åãã¦ãã¾ãã ã¢ãã©ã·ã¢ã³ã®ã³ã¢ ããªã¥ã¼ã® 1 ã¤ã«ããªã¼ãã³ãªä¼æ¥æåããã¿ã©ã¡ã¯ç¡ã (Open company, no bullshit)ãã¨ãããã®ãããã¾ãããã®ä¾¡å¤ãå®ç¾ããåãçµã¿ã®ä¸ç°ã¨ãã¦ãã¤ã³ã·ãã³ãã«ã¤ãã¦ãªã¼ãã³ã«è°è«ããå¦ã³ã«ã¤ãªãã¦ãã¾ããããã¦ããã®ã¤ã³ãã³ãäºå¾ã¬ãã¥
ï¼ãã¡ããã覧ä¸ããï¼ é«åº¦ãµã¤ãã¼æ»æ (æ¨çåæ»æ) ã«é¢ããé£çµ¡ï¼JPCERT/CCï¼ https://www.jpcert.or.jp/incidentcall/ ï¼å¯¾å¿ã«ãã´ãªã«ã¤ãã¦ã®èª¬æ ã»PCãµã¼ãã®ãã©ã¬ã³ã¸ã㯠ã¤ã³ã·ãã³ãã®å½±é¿ããã£ã端æ«ããã«ã¦ã§ã¢ã«ææãã端æ«ãææ¡ã§ãã¦ãããææçµè·¯ãå½±é¿ç¯å²ã調æ»ãããå ´åã ã»ãã°åæ/ãããã¯ã¼ã¯ãã©ã¬ã³ã¸ã㯠影é¿ã®ãã£ã端æ«ãã·ã¹ãã ãæ確ã«ãªã£ã¦ããªãå ´åã ã¾ãã¯ããµã¤ãã®æ¹ãããæ å ±æ¼æ´©ãDDoSæ»æãªã©ã®ã¤ã³ã·ãã³ãã®èª¿æ»ãå®æ½ãããå ´åã ã»ãããã¯ã¼ã¯ãã©ã¬ã³ã¸ãã¯/EDRï¼Endpoint Detection & Responseï¼ãå©ç¨ããèª¿æ» ç¾å¨ãæ»æãåãã¦ããã®ããã»ãã¥ãªãã£ã¤ã³ã·ãã³ããçºçãã¦ããã®ã調æ»ãããå ´åã ã»ãã«ã¦ã§ã¢åæ ææãããã«ã¦ã§ã¢ãURLãIPã¢ãã¬ã¹ãªã©ãåãã£
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}