ä¸è±UFJãã³ã¹ã®Webãµã¤ããä¸æ£ã¢ã¯ã»ã¹ãåããä¼å¡æ å ±ãä¸æ£ã«é²è¦§ãããã¨çºè¡¨ãã¾ãããããã§ã¯é¢é£ããæ å ±ãã¾ã¨ãã¾ãã æ¦è¦ 2014å¹´4æ11æ¥ã«ä¸è±UFJãã³ã¹ãèªç¤¾Webãµã¤ãã§ä¸æ£ãªã¢ã¯ã»ã¹ãæ¤ç¥ããWebãµã¤ããåæ¢ããã®å¾è©³ç´°ãªèª¿æ»çµæã¨ãã¦ã4æ18æ¥ã«ç¬¬3å ±ãå ¬éããããã§OpenSSLã®èå¼±æ§(æããCVE-2014-0160)ãæªç¨ããä¸æ£ã¢ã¯ã»ã¹ã§ãã£ããã¨ãå ±åã ä¸è±UFJãã³ã¹ã®ä¸æ£ã¢ã¯ã»ã¹ã«é¢é£ããçºè¡¨ 2014/4/11 å¼ç¤¾Webãµã¤ãã¸ã®ä¸æ£ã¢ã¯ã»ã¹ã«ã¤ãã¦(PDF) 2014/4/12 ä¸æ£ã¢ã¯ã»ã¹ã«ä¼´ãåæ¢ããã¦ããã ããå¼ç¤¾Webãµã¼ãã¹åéã®ãç¥ããã¨ä¼å¡æ§ã¸ã®ãé¡ã(PDF) 2014/4/18 å¼ç¤¾ä¼å¡å°ç¨WEBãµã¼ãã¹ã¸ã®ä¸æ£ã¢ã¯ã»ã¹ã«ããä¸é¨ã®ã客ãã¾æ å ±ãä¸æ£é²è¦§ããã件(PDF) (1) 被害ç¶æ³ ä¸æ£é²è¦§ä¼å¡æ° 894å(
HeartBleed(CVE-2014-0160)é¢ä¿ã®ãªã³ã¯éãèªåã®ã¡ã¢ç¨ãªã®ã§ä¸æ£ç¢ºã§ãã HeartBleedã®å½±é¿å¯¾è±¡ã¨ãªãOpenSSLãã¼ã¸ã§ã³ 以ä¸ã®ãã¼ã¸ã§ã³ãå½±é¿ãåãã¾ããä½ããã·ã¹ãã ã«ãã£ã¦ã¯åå ã¨ãªã£ã¦ããheartbeatæ©è½ãç¡å¹åããã¦ããå ´åãããããããã¼ã¸ã§ã³ãä¸è´ããã ãã§å½è©²èå¼±æ§ã®å½±é¿ãåãããã¯ç¢ºå®ãã¾ããã (1) OpenSSL 1.0.1ç³» ãã¼ã¸ã§ã³å ãªãªã¼ã¹ææ CVE-2014-0160 OpenSSL 1.0.1 2012/03/14 èå¼±æ§ãã OpenSSL 1.0.1a 2012/04/19 èå¼±æ§ãã OpenSSL 1.0.1b 2012/04/26 èå¼±æ§ãã OpenSSL 1.0.1c 2012/05/10 èå¼±æ§ãã OpenSSL 1.0.1d 2013/02/05 èå¼±æ§ãã OpenSSL 1.0.1e
TOP Security å©ç¨è ã¨ãã¦ç§ãå®è·µãã¦ãHeartBleedèå¼±æ§å¯¾çããç´¹ä» ãªã¹ãã¨ChromeBleed & SSL Server Testã§ãã§ãã¯ï¼ æ¬ããã°ã§ãç´¹ä»ãã¦ãã¾ãããOpenSSLã¨ããWebãµã¼ãå´ã§ä½¿ç¨ããããªã¼ãã³ã½ã¼ã¹ã®SSLï¼TLSå®è£ ã©ã¤ãã©ãªã«é常ã«å±éºãªèå¼±æ§ãçºè¦ããã¾ããã OpenSSLã®èå¼±æ§ãHeartbleed Bugãããã§ãã¯ãããµã¤ã : I believe in technology ãªã¼ãã³ã½ã¼ã¹ã®SSLï¼TLSå®è£ ã©ã¤ãã©ãªãOpenSSLãã«æ·±å»ãªèå¼±æ§ãè¦ã¤ãããä»æãã大ããªè©±é¡ã¨ãªã£ã¦ãã¾ãã ã¨ãã£ã¦ãããµã¼ã管çè ã§ãã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã§ããªãæ¹ã«ã¨ã£ã¦ã¯ããã®èå¼±æ§ãæå³ããã¨ãããç解ããã®ã¯ãªããªãé£ããã®ã§ã¯ãªããã¨æãã¾ãã ããã§ä»åã¯ããã®èå¼±æ§ãä¸è¬çãªã¤ã³ã¿ã¼ãããå©ç¨è ã«ä¸ããå½±
å¹³ç´ ã¯ãã»ã³ã ãã¹ãã¼ãfor Webã·ãªã¼ãºããå©ç¨ããã ãèª ã«ãããã¨ããããã¾ãã æ²é¡ã®ä»¶ã«ã¤ãã¾ãã¦ãå¼ç¤¾SSLãµã¼ã証ææ¸ãå©ç¨æã«é大ãªå½±é¿ãçããæãããããã¾ãã®ã§ã以ä¸ã®å 容ãã確èªããã ãã対çãå®æ½ããã ãã¾ãããããããããé¡ãç³ãä¸ãã¾ãã ï¼ï¼å 容 OpenSSLâ»1ã®ãã¼ã¸ã§ã³1.0.1ï½1.0.1ï½ããã³1.0.2-betaã·ãªã¼ãºã«é大ãªèå¼±æ§ãçºè¦ããã¾ãããWebãµã¼ãã«ããã¦è©²å½ãããã¼ã¸ã§ã³ã使ç¨ãã¦ããå ´åãOpenSSL ã® heartbeat æ¡å¼µã®å®è£ ã«ã¯ãæ å ±æ¼ããã®èå¼±æ§ãåå¨ãã¾ããTLS ã DTLS éä¿¡ã«ãã㦠OpenSSL ã®ã³ã¼ããå®è¡ãã¦ããããã»ã¹ã®ã¡ã¢ãªå 容ãéä¿¡ç¸æã«æ¼ããããæããããã¾ãã(CSRçææã¯æ¬èå¼±æ§ã®å¯¾è±¡ã§ããã¾ãã) â»1 OpenSSLï¼éçºããã½ããã¦ã§ã¢ã«SSL/TLSã«ããæå·éä¿¡æ©è½
ã¢ããªã±ã¼ã·ã§ã³ã¨ãµã¼ãã¹ ãããã®ã¯ã©ã¦ãã¨ä½µãã¦å©ç¨ã§ããæ§ã ãªã¢ããªã±ã¼ã·ã§ã³ããµã¼ãã¹ã§ãã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}