US-CERTã¯ãDNSãããã³ã«ããã³ä¸è¬çãªDNSå®è£ ã«ãããæ©è½æ¬ å¦ã«ãããDNSãã£ãã·ã¥ä¸æ¯æ»æ(DNS cache poisoning attacks)ãå©é·ããèå¼±æ§ã®åå¨ãå ¬è¡¨ãã(US-CERT Technical Cyber Security Alert TA08-190B, US-CERT Vulnerability Note VU#800113, CNETè¨äº)ã US-CERT TA08-1908ã«ããã¨ãå½±é¿ããã®ã¯æ¬¡ã®2ç¹ã§ããã ãã£ãã·ã³ã°DNSãªã¾ã«ã DNSã¹ã¿ããªã¾ã«ã ã® 2ã¤ã§ããããã®èå¼±æ§ãå©ç¨ããå¹æçæ»ææ³ã示ãããç¶æ ã«ããã解決ããæåã®æ¹æ³ã¨ãã¦ã¯ãã³ãã®ããããé©ç¨ãããã¨ã ããæ«å®çãªåé¿æ¹æ³ã¨ãã¦5ç¹æãããã¦ããã ã¢ã¯ã»ã¹ã®å¶é ãããã¯ã¼ã¯å¢çç¹ã«ããããã©ãã£ãã¯ã®ãã£ã«ã¿ãªã³ã° ãã¼ã«ã«ã§DNSãã£ãã·ã¥ãè¡ã å帰
2008/07/09 DNSã«ãã£ãã·ã¥æ±æãå¼ãèµ·ããæ·±å»ãªåé¡ãè¦ä»ãããBINDãç·æ¥ãªãªã¼ã¹ Dan Kaminskyæ°ãDNSã®ãããã³ã«ä¸ã®åé¡ããã»ã¼å ¨ã¦ã®ãã³ãã«ãã£ãã·ã¥æ±æãå¼ãèµ·ããæ·±å»ãªåé¡[CVE-2008-1447, CVE-2008-1454] ããããã¨ãçºè¦ããCERTãæ©æ¥ã«å¯¾å¿ããããå§åãã¦ãã(CERT Advisory)ãèå¼±æ§ã®è©³ç´°ãªå 容ã«ã¤ãã¦ã¯Kaminskyèªèº«ã8æ7æ¥ã®Black Hatã§çºè¡¨ããããã ããããåãã¦ãISCã¯BIND 9.3.5-P1ã9.4.2-P1ã9.5.0-P1ãç·æ¥ãªãªã¼ã¹ãã¦ãããBINDã§ä¿®æ£ãããã®ã¯ããã£ãã·ã¥æ±ææ»æãç·©åãããããã«ã¯ã¨ãª(åãåãã)ãã¼ãã®ä¹±æ°åãè¡ãæ©è½ã®è¿½å (ä»ã®ã¨ãããã£ãã·ã¥æ±æã®åé¡ã解決ããã«ã¯DNSSECãããªã)ã§ã9.5.0ã§è¿½å ãããã¯ã¨ãªãã¼ãããã¼ã«ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}