ããããåãåãããã©ã¼ã ãæä¾ãã¦ããããç¥ãã¬éã«ã¹ãã ã¡ã¼ã«ã®å 害è ã«ãªã£ã¦ãã話ã§ã ã¨ã³ã¸ãã¢ãç¥ã£ã¦ããã¹ã ã¡ã¼ã«éä¿¡ã»éç¨ãã¦ãã¦ãã¡ã¼ã«ã®èªè¨¼æè¡ãã»ãã¥ãªãã£ã«ã¤ãã¦æ稿ãããï¼ by blastengine Advent Calendar 2024 ã®8æ¥ç®ã§ãã è¦ä»¶ ãåãåããå 容ã®ä»ãååãæå±ãã¡ã¼ã«ã¢ãã¬ã¹ã®å ¥åãå¿ é åãåããå®äºå¾ãå ¥åãããã¡ã¼ã«ã¢ãã¬ã¹å®ã«èªåå¿çã¡ã¼ã«ãéã èªåå¿çã¡ã¼ã«ã«ã¯å ¥åãããåãåããå 容ãè¨è¼ãã åæ§ã«æå®ãããµã¼ãã¹æ å½è å®ã«ãåãåããéç¥ã¡ã¼ã«ãéã 以ä¸ã®è¦ä»¶ã§ä½æãã¾ããã å®ç¾æ¹æ³ ã¡ã¼ã«éä¿¡ã«ã¯AWS SESã使ç¨ãã¾ãããåãåãã確å®ãã¿ã³ãæ¼ä¸å¾ã«AWS Lambdaã«ãªã¯ã¨ã¹ããé£ã°ããSESã¨é£æºãã¦ã¡ã¼ã«ãéä¿¡ããæµãã§ãã å®è£ å¾ã®ã㨠å®è£ å¾ããã°ããæ£å¸¸ã«ç¨¼åãã¦ãã¾ããããããã
stuartschechter.org ç±³å½ç«æ¨æºæè¡ç 究æï¼NISTï¼ã®èªè¨¼ã«é¢ããã¬ã¤ãã©ã¤ã³ãNIST SP 800-63ããæ¹è¨ãããããã¹ã¯ã¼ãã¯ãè¤éããããé·ãããéè¦ãå®æçãªå¤æ´ã義åä»ãã¦ã¯ãªããªããã¨ããã®ãããããå¨ç¥ãããã ãããããè¤éãªãã¹ã¯ã¼ããã¨ãå®æçãªãã¹ã¯ã¼ãã®å¤æ´ããé·å¹´æ¨å¥¨ããã¦ããã®ãããã®æç« ã¯ããã®åå ãå大ãªç§å¦è ãã¡ãéã¡ãç¯ãããã¨ã«çç±ãæ±ãã¦ããã ãã®ç§å¦è ã¨ã¯ããã¼ãã»ã¢ãªã¹ã¨ã±ã³ã»ãã³ãã½ã³ã®äºäººã§ãããã±ã³ã»ãã³ãã½ã³ã«ã¤ãã¦ã¯èª¬æã¯ä¸è¦ã ããã Unix ã®éçºè ã§ãããããã¼ãã»ã¢ãªã¹ã¯æå·å¦è ã§ãY Combinator ã®å ±ååµæ¥è ã§ãããã¢ãªã¹ã¯ã¼ã ãã®ä½è ã¨ãã¦ç¥ãããããã¼ãã»ã¿ããã³ã»ã¢ãªã¹ã®ç¶è¦ªã§ããã ãã®äºäººã1979å¹´ã«å®éã®ã¦ã¼ã¶ãã¹ã¯ã¼ãã調æ»ãã¦çºè¡¨ãã Password Security:
ä¸è±UFJéè¡ã¯ãå è¡å¡ãã貸é庫ãã客ã®è³ç£ãçªåããäºæ¡ãçºçããã¨çºè¡¨ããã æ¬äººã¸ã®èãåãã®çµæã被害ç·é¡ã¯æ価åæ°ååç¨åº¦ã¨ã¿ãããã çªçã¯2020å¹´4æãã10æã®4å¹´åã«ãããã£ã¦è¡ããã¦ãã¦ãåºèã¯é½å ã®ç·´é¦¬æ¯åºï¼æ§æ±å¤ç°æ¯åºãå«ãï¼ã¨çå·æ¯åºãããã60人ã®å®¢ã®è²¸é庫ããçãã§ããã¨ã¿ãããã å è¡å¡ã¯èªèº«ã®è¡çºãèªãã¦ãã¦ãæ¢ã«æ²æ解éããã¦ããã å è¡å¡ã¯æ¯åºã®è²¸é庫ã®ç®¡ç責任ãæ ãç«å ´ã«ããããã®ç«å ´ãå©ç¨ãã客ã®é庫ãç¡æã§éæããè³ç£ãçªåãããã®ã ä¸è±UFJéè¡ã¯ããäºæ¡ã®å ¨å®¹è§£æã«åããè¦å¯ã«ãç¸è«ããªãããäºå®é¢ä¿ã®èª¿æ»ãé²ããã¨ã¨ãã«ãç£ç£å®åºãªã©ã«å ±åãè¡ã£ã¦ãããã¨ãã¦ããã
20å人è¿ã人ãã¡ãã°ã¼ã°ã«ã®ç¡æã¡ã¼ã«ãµã¼ãã¹Gmailãå©ç¨ãã¦ãããå½ç¶ãªãããã°ã¼ã°ã«ã¯ã¦ã¼ã¶ã¼ã®ãã©ã¤ãã·ã¼ãå®ããæªè³ªãªè¡çºããã¢ã«ã¦ã³ããä¿è·ããããã«ãã¾ãã¾ãªå¯¾çãè¬ãã¦ããã æ¯æ¥3000åé以ä¸ã®ã¡ã¼ã«ãåãµã¼ãã¹ãéãã¦è¡ã交ãä¸ãã¡ã¼ã«ã¢ãã¬ã¹ä½æã«ããããã£ã1ã¤ã®åç´ãªãã¹ã§ãããªãã®ã¡ã¼ã«ã赤ã®ä»äººã«ããããã¦ãã¾ãå¯è½æ§ããããããã«ãã®ãã¹ã¯ããªãã®ãã©ã¤ãã·ã¼ãå±éºã«ãããã ãã§ãªããGoogleã¢ã«ã¦ã³ãå ¨ä½ã«æªå½±é¿ãä¸ããå¯è½æ§ãããã®ã ã Gmailã®ã»ãã¥ãªãã£ã¯ä¸æµ ããªãã®ã¡ã¼ã«ãè ããã®ã¯ããµã¤ãã¼ç¯ç½ªè ãããã«ã¼ããããã¯å®¶æã ãã§ã¯ãªããæ大ã®æµã¯ãããªãèªèº«ãããããªããGmailã¯ä¸çã®ã¡ã¼ã«ãããã¤ãã¼ã®ä¸ã§æãå¤ã使ããã¦ãããããããªãã®ãã°ã¤ã³èªè¨¼ããå人æ å ±ã¾ã§ããããããã®ãçããã¨ãã¦ããè ã«ã¨ã£ã¦ãã®åä¿¡ãã¬ã¤ã¯æ ¼
6æã«åãããµã¤ãã¼æ»æããããä¸ã§ãã¾ãã¾ãªåé¿ãå¼ãã§ããKADOKAWAã°ã«ã¼ãã¯7æ3æ¥ç¾å¨ãã»ãã¥ãªãã£ã¨ã³ã¸ãã¢è·ã®æ±äººãæ±äººãµã¤ãã«æ²è¼ãã¦ãããåã°ã«ã¼ãã®ã¤ã³ãã©éçºã»éç¨æ¥åãªã©ãæ ãåä¼ç¤¾ã»KADOKAWA Connectedï¼æ±äº¬é½å代ç°åºï¼ã®ç¤¾å¡ãåéãã»ãã¥ãªãã£ã¨ã³ã¸ãã¢è·ã®æ大年åã¯800ä¸åã¨ããã
ç§ã¯ããã§ã¯ãªãã®ã§ããããªãã®ã§ãééã£ã¦ããã®ã¯å½ããåã ã¨æã£ã¦èªãã§ãã ããã åã 人ã®ã¨ã³ã¸ãã¢ã®è½åãã¨ãã¯ã¬ã¸ããã«ã¼ããã¨ãã¯åºæ¬é¢ä¿ãªãã¨ãã話ã§ãã ï¼é¢ä¿ãªãã¦ããã¹ã¯ã¼ãã使ãåãã¦ããå ´åã¯ãåããã¹ã¯ã¼ãã使ã£ã¦ãããµã¼ãã¹ã®ãã¹ã¯ã¼ãã¯ããå¤ããã®æ¨å¥¨ï¼ ä¸è¡VPNâãã©ã¤ãã¼ãã¯ã©ã¦ãã®ç®¡çã·ã¹ãã ã¨ãªã³ãã¬èªè¨¼âåã·ã¹ãã ã¨è¨ãæµãã§ä¾µå ¥ããã¦ããã¨æããããªã³ãã¬ã®ãã£ã¬ã¯ããªãµã¼ãã¹ã¨ã¯ã©ã¦ãã®idMãæ¥ç¶ããããªã³ãã¬ã®èªè¨¼è³æ ¼ã§SaaSã¯ä¸é¨ããããå¯è½æ§ãããç¾å¨ã¯ã©ã¦ãã«ãªããã¢ããä¸ã§ãæ°ã·ã¹ãã ã¯ã¢ãã³ãªå¯¾çãããæ¹æ³ã§ä¿è·ããã¦ããç¡äºã ã£ããããããæ ã«ãªã³ãã¬ã¸ã®å¯¾çãå¾æã ã£ãã®ã§ã¯ä¼ç¤¾ã®ã·ã¹ãã ã¯ã©ããªã£ã¦ããç§ã¯é·å¹´ç¤¾å ã·ã¹ãã ã®å¥´é·ããã£ã¦åãã¾ãããç¾å¨ã®ã¯ã©ã¦ãã«ãªãåã®ãµã¼ãã触ã£ã¦åãã¾ããã®ã§ããã®è¾ºãããã話ããã
2001å¹´ã«ãªãªã¼ã¹ãããWindows XPã¯ã2014å¹´4æã«å»¶é·ãµãã¼ããæã¡åããã¦ããè¨äºä½ææç¹ã§10å¹´ãçµéãã¦ãã¾ãããè¦æ±ã¹ããã¯ã®ä½ããå®å®æ§ãªã©ããæ ¹å¼·ãæ¯æããã¦ããã2022å¹´ã«å ¬éãããã¬ãã¼ãã§ã¯Windows 11ã«å¹æµããã·ã§ã¢çã ã£ãã¨å ±åããã¦ãã¾ãããããªWindows XPããã¡ã¤ã¢ã¦ã©ã¼ã«ãåã£ãç¶æ ã§ã¤ã³ã¿ã¼ãããã«æ¥ç¶ããåç»ãYouTuberã®ã¨ãªãã¯ã»ãã¼ã«ã¼æ°ãå ¬éããã¨ãããæ稿ããç´10æ¥ã§45ä¸åãåçããã¾ããã What happens if you connect Windows XP to the Internet in 2024? - YouTube Idle Windows XP and 2000 machines get infected with viruses within minutes of being ex
ãã¾ã»ã!! @sm_hn ããæ¥æ¬ã«ãããããã¤ãã³ãã¼ã«ã¼ãã«ãããSIMãã¤ã¸ã£ãã¯ãçºçäºæ¡ããªã®ã§æ³¨ç®ãã¹ããæ¿åºã¯ååèªã¿åãå¿ é ã«ãã¹ãã x.com/setagaya_k/sta⦠風éããã æ±äº¬é½è°ä¼è°å¡ ç«æ²æ°ä¸»å ä¸ç°è°·åºé¸åº @setagaya_k æ¨æ¥æ¼é ãã¹ããã«PayPayéç¥ã表示ããã1000åãã£ã¼ã¸ãã¾ãããã¨ãèªåãã£ã¼ã¸è¨å®ï¼ãªãã ããã¨ã¢ããªã確èªãã¦ãããããããæ¾ç½®ãï¼ãã®æã«PayPayã«ç¢ºèªãã¹ãã ã£ãï¼ï¼åå¾ã«ã¡ã¼ã«ãã§ãã¯ããã¦ããã¨ç»åã®ãããªã¡ã¼ã«ãçªç¶å±ããããã¯ãããããã¨ãã¹ã¯ã¼ãåè¨å®ãããã¨... pic.twitter.com/z81IF167aP x.com/setagaya_k/sta⦠風éããã æ±äº¬é½è°ä¼è°å¡ ç«æ²æ°ä¸»å ä¸ç°è°·åºé¸åº @setagaya_k æºå¸¯é»è©±ä¹ã£åããã¾ãããããã«æ°ã¥ãã¦ã½ããã
é£æ¥ãã¾ãã¾ãªãµã¤ãã¼ã»ãã¥ãªãã£ç¯ç½ªã®ãã¥ã¼ã¹ãå ±ããããä¸ããã¾ã ã«æ¥æ¬ã®ã»ãã¥ãªãã£ã¬ãã«ã¯é«ãã¨ã¯è¨ããªãç¶æ³ã«ããã¾ããä¸æ¹ã§ãä¼æ¥ããµã¤ãã¼ã»ãã¥ãªãã£å¯¾çãé²ããä¸ã§ã¯ã人æä¸è¶³ãçµå¶å±¤ã®æèã»é¢å¿ãã³ã¹ããå°å ¥ã«ããå©ä¾¿æ§ã®ä½ä¸ãªã©ããã¾ãã¾ãªå£ãç«ã¡ã¯ã ãã£ã¦ãã¾ãã ããã§ä»åã¯ãæ ªå¼ä¼ç¤¾ç¶²å±ã主å¬ãããSecurity BLAZE 2023ãããããµã¤ãã¼ã»ãã¥ãªãã£ã®ã¨ãã¹ãã¼ãã«ããè¬æ¼ããå±ããã¾ããæ¬è¨äºã§ã¯ãç±³éè大æã§1å人以ä¸ã®å人æ å ±ãæ¼ããããäºä»¶ã®èæ¯ãã²ãã¨ããªãããåé¡ç¹ã¨ã»ãã¥ãªãã£å¯¾çã®ãã¤ã³ãã解説ãã¾ãã Webã»ãã¥ãªãã£ã®ç¬¬ä¸äººè ãèªããå人æ å ±æµåºäºä»¶ã®è£å´ 徳丸浩æ°ï¼ãã ãã¾ãç´¹ä»ããã ãã¾ãããEGã»ãã¥ã¢ã½ãªã¥ã¼ã·ã§ã³ãºã®å¾³ä¸¸ã§ãããã¾ããæ¬æ¥ã¯ãç±³å½éèæ©é¢ã襲ã£ãå人æ å ±å¤§è¦æ¨¡æµåºäºä»¶ã®çç¸ãã¨ãããã¼ãã§ã話ãããã¦ã
NTTã®å³¶ç°æ社é·ã¯7æ¥ã®è¨è ä¼è¦ã§ãåä¸ã®NTT西æ¥æ¬ã®åä¼ç¤¾ããç´900ä¸ä»¶ã®é¡§å®¢æ å ±ãä¸æ£æµåºããåé¡ã«ã¤ãã¦ããè¿·æããããããã客ãã¾ã«ã¯èª ã«ç³ã訳ãªããã¨è¬ç½ªããã顧客æ å ±ã¯å æ´¾é£ç¤¾å¡ãUSBã¡ã¢ãªã¼ã«è¨é²ãã¦æã¡åºããã¨ã¿ãããã°ã«ã¼ãå ¨ä½ã§USBã¡ã¢ãªã¼ãæ¥åã«ä¸å使ããªããªã©ã®åçºé²æ¢çãæããã«ããã 島ç°æ°ã¯ãè¨é²åªä½ãæã¡è¾¼ã¾ãªããªã©ã®ç¤¾å ã«ã¼ã«ã¯è¨ãã¦ãããâ¦
2023.01.24 çµæ¸ç£æ¥çãå ¨ECãµã¤ãã義åå対象 ã»ãã¥ãªãã£ã¼å¯¾çã§èå¼±æ§å¯¾çã¨æ¬äººèªè¨¼å°å ¥ã義åå 0 çµæ¸ç£æ¥çã¯1æ20æ¥ãECãµã¤ãã®èå¼±æ§å¯¾çã¨æ¬äººèªè¨¼ã®ä»çµã¿ãå°å ¥ãããã¨ã義ååããæ¹éãåºããã2024å¹´3ææ«ã¾ã§ã«ãå ¨ã¦ã®ECãµã¤ããèå¼±æ§å¯¾çã¨æ¬äººèªè¨¼ãå°å ¥ãããã¨ããæ¤è¨ä¼ã®å ±åæ¸æ¡ã«çãè¾¼ãã§ããã ECãµã¤ãã¨æ¬äººèªè¨¼ã®ä»çµã¿ã®å°å ¥ã®ç¾©ååã¯ããã¯ã¬ã¸ããã«ã¼ã決æ¸ã·ã¹ãã ã®ã»ãã¥ãªãã£å¯¾çå¼·åæ¤è¨ä¼ãã®ç¬¬6åä¼åã§æåºãããå ±åæ¸æ¡ã«çãè¾¼ã¾ããã å ±åæ¸æ¡ã§ã¯ãã¯ã¬ã¸ããã«ã¼ãçªå·ã®ä¸æ£å©ç¨è¢«å®³ãå¢ãç¶ããåé¡ãèæ¯ã«ããECãµã¤ãããã¯ã¬ã¸ããã«ã¼ãæ å ±ãæ¼æ´©ãããã¨ã¸ã®å¯¾çããæ¼æ´©ããã¯ã¬ã¸ããã«ã¼ãæ å ±ãä¸æ£ã«ä½¿ããããã¨ã¸ã®å¯¾çãã®2ç¹ãçãè¾¼ãã ã å ·ä½çã«ã¯ããã¯ã¬ã¸ããã«ã¼ãçªå·çã®é©å管ç義åã®æ°´æºãå¼ãä¸ããã¹ãããµã¤ãèªä½ã®èå¼±
ãä»äºã®ããåãã§ãã¾ã«ééãã¤ã¤æ°ã«ãªã£ã¦ããã®ããã¡ã¼ã«ã§ãã¡ã¤ã«ãããåãããéã«ãã¹ã¯ã¼ããè¨å®ãããã®ãã¹ã¯ã¼ãããã¡ã¼ã«ã§å¥ééãã¾ããã¨ããããã¨ãããã¡ã¤ã«éãã®ã«æéããããã°ããã§ãã»ãã¥ãªãã£çã«ããã»ã©é«ãã¨ã¯ã¨ã¦ãæãããã§ããã®ããæ¹ããã¸ãã¹ä¸ææçºçããã®ãä¸æè°ã«æã£ã¦ããã¾ããã ãããªãã¨ããã¼ãã¼é¨ãã§ãããå¨å²ã®äººãããããæè¦ãããã ããã®ã§ãã®ã¨ã³ããªã¼ã§ç°¡åã«ã¾ã¨ããã¨ã¯ãããä»ã®ã¨ããããã¹ã¯ã¼ãã¯ã¡ã¼ã«ã§å¥ééãã¾ããã®ã¡ãªãããå ¨ç¶è¦ãã¦ãªãã£ãããããã®ã§ããâ¦â¦ã 1.誤éä¿¡é²æ¢ã®ãã ããã¹ã¯ã¼ãã¯å¥ééãã¾ããã®çç±ã¨ãã¦æåã«æããããã®ãããã1éã ã¨ééãã¦éã£ã¦ãã¾ã£ãå ´åã«ããç´ããå¹ããªãããã©ã2éã«åãã¦éããã¨ã§èª¤éä¿¡ã対å¦ã§ããã¨ã®çç±ã ã£ããã§ãããããã©ãã«ãè ã«è½ã¡ãªãã ãããããå®å ãééãããã¨ã
ãããã®VPS ã£ã¦ããã©ã«ãã§ã¯ãã¡ã¤ã¢ã¼ã¦ã©ã¼ã«ã®è¨å®ä½ãããã¦ãªãã¨ããè¨äºãã¿ã¦é©æãããã¨ãããèããã Ubuntu 10.04 LTS ãåã¤ã³ã¹ãã¼ã«ãããããã©ã£ã¡ã«ãã¦ãåæç¶æ ã ãªã ã¨ãããã確ãããã $ sudo iptables -L Chain INPUT (policy ACCEPT) target prot opt source destination Chain FORWARD (policy ACCEPT) target prot opt source destination Chain OUTPUT (policy ACCEPT) target prot opt source destination ãªã¦ããããã©ã«ãã¯ç©ºãªã®ãâ¦â¦ iptables ã®è¨å®ããã©ããããªã¼ã©ããããããªã¼ãã¨æã£ã¦ããããã©ãã Ubuntu ã§ã¯ ufw ã¨ãã
ä»æ¥ã§ã¯ã»ã¨ãã©ã®ã¦ã¤ã«ã¹å¯¾çã½ãããæ¸åº«ãã¡ã¤ã«ã«å¯¾ãã¦ã¤ã«ã¹ãã§ãã¯ãè¡ãæ©è½ãåãã¦ããããå¤ãã®ã¦ã¤ã«ã¹å¯¾çã½ããã§ãLZHæ¸åº«ãã¡ã¤ã«ã®ãããã¼é¨åã«ç´°å·¥ãæ½ããã¨ã§ã¦ã¤ã«ã¹ãã§ãã¯ãåé¿ã§ãããã¨ããèå¼±æ§ãåå¨ããã¨ã®ãã¨ï¼LZHæ¸åº«ã®ãããã¼å¦çã«ãããèå¼±æ§ã«ã¤ãã¦ï¼ã Miccoæ°ã¯ãããJVNï¼Japan Vulnerability NoteãJPCERTããã³IPAãå ±åéå¶ããèå¼±æ§æ å ±éç©ãµã¤ãï¼ã«å ±åããã¨ããããä¸åçãã¨ãªã£ãããã ãZIPã7zå½¢å¼ã®æ¸åº«ã«ãåæ§ã®åé¡ããããã®ã®ããã¡ãã¯ãèå¼±æ§ãã¨ãã¦åçããã¦ããã¨ã®ãã¨ãMiccoæ°æ°ãã ããã³ãã¼ï¼ JVN / IPA çå ±ã«ãLZH æ¸åº«ãªãã¦ç¥ãããï½ããã¨ããæ 度ããå¤ãããã¨ã¯ãªããã¨å¤æã§ãã¾ããã®ã§ï¼ UNLHA32.DLLï¼ UNARJ32.DLLï¼ LHMelt ã®éçºãä¸æ¢ã
以ä¸ã¯ãWEBããã°ã©ãã¼ç¨ã®WEBèå¼±æ§ã®åºç¤ç¥èã®ä¸è¦§ã§ãã WEBããã°ã©ãã¼ã®äººã¯ãããèªãã°WEBèå¼±æ§ã®åºç¤ããã¹ã¿ã¼ãã¦WEBããã°ã©ã ãæ¸ããã¨ãã§ããããã«ãªã£ã¦ããããã§ãã ã¾ããWEBèå¼±æ§ã®ç°¡æãªãã¡ã¬ã³ã¹ã¨ãã¦ãå°ãå©ç¨ã§ããããããã¾ããã WEBã¢ããªã±ã¼ã·ã§ã³ãéçºããã«ã¯ãéçºè¦ä»¶æ¸ãããã°ã©ã ä»æ§æ¸éãã«éçºããã°è¯ãã¨ããããã«ã¯ããã¾ããã ãããWEBèå¼±æ§ãçãæªæã®ã¦ã¼ã¶ã«ã対å¦ããªãã¨ãããªãã®ã§ãã ä»åãWEBã¢ããªã±ã¼ã·ã§ã³ãéçºã«ããã£ã¦ã®WEBèå¼±æ§ãã以ä¸ã®ä¸è¦§ã«ã¾ã¨ãã¦ã¿ã¾ããã ãã®ã¾ã¨ããWEBã¢ããªã±ã¼ã·ã§ã³éçºã®åèã«ãªãã°å¹¸ãã§ãã ã¤ã³ã¸ã§ã¯ã·ã§ã³ ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã° ã»ãã·ã§ã³ã»ãã¤ã¸ã£ã㯠ã¢ã¯ã»ã¹å¶å¾¡ãèªå¯å¶å¾¡ã®æ¬ è½ ãã£ã¬ã¯ããªã»ãã©ãã¼ãµã«(Directory Traversal) CSRFï¼
ãã¤ãAmebaããå©ç¨ããã ãã¾ãã¦ããããã¨ããããã¾ãã ä¸é¨ã®ãAmebaããªãã£ã·ã£ã«ããã°ã®ä¸æ£ã¢ã¯ã»ã¹è¢«å®³ã«ã¤ãã¾ãã¦ã ãå¿é ãããããããã¾ãã¦ç³ã訳ãããã¾ããã 2010å¹´1æ1æ¥æªæããAmebaããªãã£ã·ã£ã«ããã°ã¸ä¸æ£ã¢ã¯ã»ã¹ã®è¢«å®³ãç¢ºèª ãããã¾ãããåæã«ããªãã£ã·ã£ã«ããã°ã®IDããã¹ã¯ã¼ãç´450件çã è¨è¿°ããã¨ã¯ã»ã«ãã¡ã¤ã«ãå¤é¨ã«æµåºãããã¨ã確èªãã¦ããã¾ãã æ¬ä¸æ£ã¢ã¯ã»ã¹ã«é¢ãã¦è¿ éã«å¯¾å¿ããããç·æ¥å¯¾çãã¼ã ãçµæãã æµåºãããã¹ã¯ã¼ãã1æ¥æ£åã¾ã§ã«å¤æ´ãããªã©ã対å¿çãå®æ½ãããã¾ããã ã¾ãåããã¦ãæ¸è°·è¦å¯ç½²ã«è¢«å®³ç¶æ³ã®å ±ååã³é¢é£è³æãæåºã対å¿ãé²ã㦠ããã¾ããå°ãä»åã®ä»¶ä»¥å¤ã§ã®ä¸æ£ã¢ã¯ã»ã¹ã»æ å ±æµåºããªããã¨ã確èªãã¦ããã¾ãã ä»å¾ãããå®å ¨ãªãµã¼ãã¹ãæä¾ã§ããããã«åªãã¦ã¾ããã¾ãã
ãã¤ãAmebaããå©ç¨ããã ãã¾ãã¦ããããã¨ããããã¾ãã ä¸é¨ã®çæ§ãã質åããã ãã¾ãããå¼ç¤¾ãµã¼ãã¹ã®ã»ãã¥ãªãã£å¯¾å¿ã«ã¤ãã¦ã ãå ±åãããã¾ãã å¼ç¤¾ã§ã¯æ°è¦ãµã¼ãã¹ã®éçºæã¯ãªãªã¼ã¹åã«ã æ¢åãµã¼ãã¹ã¯å®æçã«ãå¤é¨ã»ãã¥ãªãã£ç£æ»ä¼ç¤¾ã«ãã調æ»ãå¿ ãå®æ½ãã¦ããã¾ãã 調æ»å ±åã¯æ·±å»åº¦å¥ã«åé¡ãããããã¾ã§ã¦ã¼ã¶ã¼ã®çæ§ã®ãã¼ã¿æ¼æ´©ã ç ´å£ã«ã¤ãªããå¯è½æ§ãããé¨åã«ã¤ãã¦ã¯å³æã®å¯¾å¿ãã ãã以å¤ã®é¨åã«ã¤ãã¦ã¯ä¸å®æéå ã§ã®å¯¾å¿å®æ½ãå¾¹åºãã¦åãã¾ããã ç¾å¨ãæ¨ä»ã®äºæ ãéã¿ãå½±é¿ã®å¤§ããªé¨åã«ã¤ãã¦ã¯åªå 度ãæä¸ç´ã«ãã ç·æ¥å¯¾å¿ãè¡ã£ã¦ããã¾ãã ãè¿·æãããããããã¾ããããç解ããã ãã¾ãããããé¡ããããã¾ãã
å æ¥ãAmebaãªããCSRFã¨ããé常ã«ããã¥ã©ã¼ãªèå¼±æ§ãæ«é²ãããã¨æã£ãããããæ°æ¥ã¯ã»ãã³ãããã·ã§ããã³ã°ã§XSSã®èå¼±æ§ã¨ãIDæ¨æ¸¬ã«ããä»ã¦ã¼ã¶ã®å人æ å ±é²è¦§ã®åé¡ãçºçãã¦ããã¨ããåãæµãã¦ãã¾ãã ã¦ã¼ã¶ã®æ å ±ãé ãã£ã¦ãããªãããåºæ¬çãªã»ãã¥ãªãã£ã®å¯¾çãã§ãã¦ããªãã¨ããã®ã¯ãéè¡ã«ä¾ãããªãããéãé ãããã¨ããæã«ããéã¯é ããã¾ããã¡ããã¨ä¿ç®¡ãã¾ããã§ãè¦åã¯ãã¾ãããªãã®ã§çã¾ãããã¹ã¤ãã»ã³ãã¨è¨ããããããªãã®ã ã¨æãã è¦åã«ç©´ããã£ãã¨ããã®ã§ã¯ãªããã¾ã¨ãã«è¦åãã¦ã¾ããã§ãããã¨ããã®ã¯ãããã«ããããªããã¨ã§ãã ããã§ãéè¯WEBããã°ã©ãã§ããç§ãç¥ã£ã¦ããèå¼±æ§ãåæãã¦ã¿ãã ç§ã¯ããã°ã©ãã§ãã£ã¦ã»ãã¥ãªãã£ã®å°é家ã§ã¯ãªãã§ãããããä»å¹´ã®æ¥è¾ºããããã£ã¨å¤åãã®WEBããã°ã©ã ã¯çµãã§ã¾ããã ãã®äººéãç¥ã£ã¦ãããã®ã並ã¹
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}