ãã©ã¤ãã¼ãèªè¨¼å±ï¼ããã©ã¤ãã¼ãCAããããªã¬ãªã¬èªè¨¼å±ãã¨ãå¼ã°ãã¾ãï¼ã¯ãä¼ç¤¾ãªã©éãããçµç¹å ã§ã®ã¿éç¨ããèªè¨¼å±ã§ããèªè¨¼å±ã®æ§ç¯ç¨ã¹ã¯ãªããã§ãã©ã¤ãã¼ãèªè¨¼å±ãæ§ç¯éç¨ãã¦ããã®ã§ããããã©ãã«ãçºçããæã«æã足ãåºãè¦å´ãããã¨ãããã¾ãããããã§ä»åã¯OpenSSLã使ã£ã¦è¨å®ã®æå³ãç解ããªãããã©ã¤ãã¼ãèªè¨¼å±ãæ§ç¯ããæé ãã¾ã¨ãã¦ã¿ã¾ããã OpenSSLã®ãã¼ã¸ã§ã³ ä»å使ç¨ããOpenSSLã®ãã¼ã¸ã§ã³ã¯æ¬¡ã®éãã§ãããã¼ã¸ã§ã³ã«ãã£ã¦ã¯è¨å®ãã¡ã¤ã«ã§æå®ã§ãããªãã·ã§ã³ã«éããããã¾ãã®ã§ãå¿ ããã®ãã¼ã¸ã§ã³ã®ããã¥ã¢ã«ï¼manï¼ãã確èªãã ããã openssl version OpenSSL 3.0.7 1 Nov 2022 (Library: OpenSSL 3.0.7 1 Nov 2022) ã¾ãããã©ã¤ãã¼ãèªè¨¼å±ãæ§ç¯ããéã«ãOpenSSLã®
SSLã£ã¦ä½ï¼æå³ãä»çµã¿ãããããããè§£èª¬ï¼ ã¤ã³ã¿ã¼ãããéä¿¡ã®æå·åï¼httpsåï¼ãæ ãSSLã®å½¹å²ãç¨èªã®æå³ãæå·åéä¿¡ãæç«ããã¾ã§ã®éç¨ããããããã解説ãã¾ãã SSLã¨ã¯ SSLï¼Secure Sockets Layerï¼ã¨ã¯ãç°¡åã«èª¬æããã¨Webãµã¤ãã¨ãã®ãµã¤ããé²è¦§ãã¦ããã¦ã¼ã¶ã¨ã®ããåãï¼éä¿¡ï¼ãæå·åããããã®ä»çµã¿ã§ãã æå·åããã¦ããªãã¤ã³ã¿ã¼ãããã¯å±éºï¼ æå¤ã¨ç¥ããã¦ãã¾ããããã¿ãªãããå©ç¨ãã¦ããã¤ã³ã¿ã¼ãããã¯æªæã®ãã第ä¸è ãéä¿¡ã®ä¸èº«ãçã¿è¦ã¦æªç¨ãããã¨ãå¯è½ã§ããé²è¦§ãã¦ãããã¼ã ãã¼ã¸ã®ã¢ãã¬ã¹ããæ²ç¤ºæ¿ã«æ¸ãè¾¼ãã å 容ãã·ã§ããã³ã°ãµã¤ãã§å ¥åããã¯ã¬ã¸ããã«ã¼ãçªå·ããã¹ã¯ã¼ããªã©ãçã¿è¦ããã¨ãå¯è½ã§ãããããã§ã¯å®å¿ãã¦ã¤ã³ã¿ã¼ããããã§ããªãï¼ãã¨ãããã¨ã§çã¾ããã®ãSSLã¨ããä»çµã¿ã§ãã ä¾ãã°ãããªããä¼ç¤¾ã®ã
ãã¹ãã¼ã®æ¬è³ªã¯ã¦ã¼ã¶ã¼å´ã¨ãã¦ã¯ãã¹ã¯ã¼ãå ¥åæ©ä¼ã®åæ¸ããµã¼ãã¹å´ã¨ãã¦ã¯ä¼æ¥ã®ã»ãã¥ãªãã£ãªã¹ã¯ã®ã¦ã¼ã¶ã¼ã¸ã®è²¬ä»»è»¢å«ã¨ã³ã¹ãã«ããã§ããã ãµã¼ãã¹å´ ä¼æ¥ãã¦ã¼ã¶ã¼ã«ãã¹ãã¼ã使ããããã¨å¼·è¦ããã®ã¯ãã°ã¤ã³æ å ±ã®æµåºãæµåºãããã°ã¤ã³æ å ±ã«ããæ»æã®ãªã¹ã¯ã¨è²¬ä»»ã¨ã³ã¹ãããä¼æ¥ãå®ãããã«èªè¨¼ã«é¢ããåé¡ãã¦ã¼ã¶ã¼ã®è²¬ä»»ã«ãã£ã¦ããçºçããªããã責任転å«ãããããã«éããªãããã®ããèªè¨¼æ å ±ã®ç´å¤±ãçé£ãªã©ã«ããåªå¤±ãªã¹ã¯ã¨å¾©æ§ã®å°é£æ§ããã®ä»æ°ãã«çºçããåé¡ã«ã¤ãã¦ã¯é è½ã¾ãã¯ç®å°åããããä¼æ¥ã«ã¨ã£ã¦ãã¹ãã¼ã¨ã¯ãã¹ã¯ã¼ãã®å®æçå¤æ´ã®ææ°çãªã®ã§ããã¦ã¼ã¶ã¼ããã¹ãã¼ãå¼·è¦ãããã®ã¯ãã¹ã¯ã¼ãã®å®æçå¤æ´ãå¼·è¦ãããæ´å²ãç¹°ãè¿ãã¦ããã«éããªãã ã¦ã¼ã¶ã¼å´ ãã¹ãã¼ã®é©åãªå®è£ ã«ãããã¦ã¼ã¶ã¼ã®æ¬è³ªçå©çã¯ãã¹ã¯ã¼ãå ¥åæ©ä¼ãæ¸ããã¨ã«ãããã£ãã·ã³ã°è¢«å®³ãåããæ©
åæ²¢é åã¯ãä¿¡é ¼ã»ä¿¡ç¨ã¨ããéè¡ã®ãã¸ãã¹ã®æ ¹å¹¹ãæºãããäºæ¡ã ã¨å³ç²ã«åãæ¢ãã¦ãããã客æ§ãé¢ä¿è ã®çæ§ã«å¿ããããã³ç³ãä¸ãã¾ããã¨è¿°ã¹ã¦ãé³è¬ãã¾ããã ããã¦ãä»åã®è²¸é庫ã®äºæ¡ã«ããã¦ã客æ§ãã¯ããã¨ããé¢ä¿è ã®çæ§ã«å¤å¤§ãªããè¿·æã¨ãä¸å®ãä¸ãããã¨ãé常ã«éãåãæ¢ãã¦ãã¾ããéè¡ã«ã¨ã£ã¦ãã客æ§ã社ä¼ãªã©ã®ã¹ãã¤ã¯ãã«ãã¼ããã®ä¿¡é ¼ãä¿¡ç¨ãäºæ¥ã®æ ¹å¹¹ã§ãããã¨ãåèªèããã客æ§ãå®å¿ãã¦ç¤¾ä¼çæ´»ãå¶ã¿ãä¼æ¥æ´»åã«åãçµãããããå ¨è¡ãããã¦å¤±ãããä¿¡é ¼ãä¿¡ç¨ã®å復ã«åªããã¨ã¨ãã«ããã®ç¤¾ä¼ç責任ãæããã¦ããããã¨èãã¦ããã¾ããã¨è¿°ã¹ã¾ããã åæ²¢é åã¯ãçµå¶è²¬ä»»ã«ã¤ãã¦ãç¾å¨è¢«å®³ã«ããããã客æ§ã¸ã®è£åãããã¦ã¾ãã«è²¸é庫ãå©ç¨ãã¦ããã ãã¦ããã客æ§ã®ä¸å®ã®è§£æ¶ã«æåªå ã«åãçµãã§ããã¨ããã§ãããã¾ããä»å¾ãã£ããã客æ§ã«åãåãè£å対å¿ããã£ããé²ããã¨ã¨ãã«ã
I was asked a question about running users inside of a docker container: could they still get privileges? Before we begin, here is more background on Linux capabilities Weâll start with a simple container where the primary process is running as root. One can look at the capabilities of the current process via grep Cap /proc/self/status. There is also a capsh utility. # docker run --rm -ti fedora g
å«çï¼ãªã³ã´ï¼ @ringo_yakuri Jokerå çãå«ãããªã³ã©ã¤ã³æ票ã«è¯å®çãªæè¦ãæã£ã¦ããã³ã³ãã¥ã¼ã¿ã¼ã¨ã³ã¸ãã¢ã«ä¼ã£ããã¨ããªããã§ããããç§ãä¸çªç´å¾ããçç±ã¯ã人åã®ä¸æ£ã¯å¤§è¦æ¨¡åã«éçãããé¸æçµæãå·¦å³ããã»ã©ã®ä¸æ£ã¯å°é£ã§ããä¸æ¹ãé»åæ票ã®å ´åä¸æ£ä¸ã¤ã§é¸æçµæãè¦ãã¦ãã¾ãå±éºãããããã 2024-10-27 18:55:37
ãã®ã³ã¼ãã¼ã§ã¯ã2014å¹´ããå 端ãã¯ããã¸ã¼ã®ç 究ãè«æåä½ã§è¨äºã«ãã¦ããWebã¡ãã£ã¢ãSeamlessãï¼ã·ã¼ã ã¬ã¹ï¼ã主宰ããå±±ä¸è£æ¯ æ°ãå·çãæ°è¦æ§ã®é«ãç§å¦è«æãå±±ä¸æ°ãããã¯ã¢ãããã解説ããã Xï¼ ï¼ shiropen2 ãçµç¹ã¯ã¦ã¼ã¶ã¼ã«å®æçãªãã¹ã¯ã¼ãå¤æ´ãè¦æ±ãã¦ã¯ãªããªããââç±³å½æ¿åºæ©é¢ã®ç±³å½ç«æ¨æºæè¡ç 究æï¼NISTï¼ãããããªå 容ãå«ããæ°ããã¬ã¤ãã³ã¹ãSP800-63Bããçºè¡¨ããããã¹ã¯ã¼ãã®å 容ã¯ãã»ã¯ã·ã§ã³3.1.1ã«è¨ããã¦ããã å¤ãã®äººã ãæ°ãããã¹ã¯ã¼ããèãåºãããããè¦ãããã¨ã«è¦å´ãã¦ãããã»ãã¥ãªãã£ä¸ã®çç±ãããå¤ãã®çµç¹ãã¦ã¼ã¶ã¼ãå¾æ¥å¡ã«å®æçãªãã¹ã¯ã¼ãã®å¤æ´ãè¦æ±ãããããã¯ç¾©åä»ãã¦ããããããä»ãç±³å½æ¿åºã¯ã½ããã¦ã§ã¢ããªã³ã©ã¤ã³ãã¼ã«ãä½æã»éç¨ããçµç¹ã«ãã®æ £è¡ããããããå¼ã³ããã¦ããã ããã¯ãWebãµã¤ã
"Letâs use a token to secure this API call. Should I use the ID token or the access token? âð¤ The ID token looks nicer to me. After all, if I know who the user is, I can make better authorization decisions, right?" Have you ever found yourself making similar arguments? Choices based on your intuition may sound good, but what looks intuitive is not always correct. In the case of ID and access toke
ãã®åé¡ããã¾ããããé常ã«ã¾ããã Google Formã®ç·¨éç»é¢ã«ã¯ãåçã«ãã¢ã¯ã»ã¹ã§ããããã«ãªã£ã¦ããããï¼åçãªã³ã¯ãããªãã¦ãã®ãã©ã¼ã ç·¨éãã¡ã¤ã«ãããªã³ã¯ãç¥ã£ã¦ããäººå ¨å¡ãã«å ±æãã¡ããã¡ï¼ã£ã¦ãã¨ãªãã ãã ãã£ãããããªãã¨ããããããããããï¼ããã ã¦ãã¨ã§ãããGoogle Driveã§å¿ æ»ããã¦ããªã³ã¯ãç¥ã£ã¦ãã人ãã«å ±æããGoogle Formãªã©æ¢ãã¾ãã£ãã ï¼ã²ã¨æ®µè½ã¤ããï¼ ãï¼ã©ããã£ã¦æ¢ãããã£ã¦ï¼ãæããã¾ããã Google Driveããã©ã¦ã¶ã§éãã§ãã ããããæ¤ç´¢ã®ã¨ããã« ã»ãã¦ã¼ã¶ãã«ããªã³ã¯ãç¥ã£ã¦ããäººå ¨å¡ããæå®ã ã»ã種é¡ããããã®ã§ããã§ããã©ã¼ã ããæå®ã ããã¼åºã¦ãã¾ããã¼ï¼ ã¡ãªã¿ã«ããã§ã種é¡ããã¹ãã·(ã¹ãã¬ããã·ã¼ã)ã«åãæ¿ãã¦ã¿ã¦ãããªããªãå³ããæ·±ãã... ãã¨ã¯å¿ æ»ããã¦ä¸é©åãªãå ±æãã
KADOKAWAã®è¨æãã¼ã¿ã«ãµã¤ããã KADOKAWAã«ãµã¤ãã¼æ»æãè¡ã£ã¦ããã¨ã¿ããããã·ã¢ã®ããã«ã¼éå£ã¯7æ3æ¥ããã¼ã¯ã¦ã§ãä¸ã«å ¬éãã¦ããå社ã¸ã®ç¯è¡å£°æãåé¤ãããããã«ã¼éå£ã¯ãå社ã¨è¡ã£ã¦ãã身代éã«é¢ãã交æ¸ã§åæã«è³ããªããã°ããã¦ã³ãã¼ãããå社ã®æ å ±ãå ¬éããã¨ãã¦ãããã7æ1æ¥ã«æ å ±æ¼æ´©ã確èªãããããªãããã«ã¼éå£ã¯æ å ±å ¬éãã2æ¥å¾ã«çªå¦ãç¯è¡å£°æãåé¤ããã®ããã¾ããä¸é£ã®äºæ ãåããæ»æãåããä¼æ¥ã¯èº«ä»£éã®è¦æ±ã«å¿ããã¹ããå¦ãããããè°è«ãå¼ãã§ããããä¼æ¥ã¯ã©ã®ãããªåºæºã§å¤æãã¦ããã®ããå°é家ã®è¦è§£ã交ãã¦è¿½ã£ã¦ã¿ããã KADOKAWAã«å¯¾ãã¦ã©ã³ãµã ã¦ã§ã¢ãå«ããµã¤ãã¼æ»æãè¡ã£ãã¨ããç¯è¡å£°æãåºãã¦ãããBlackSuitãã¯ãå社ã®ã·ã¹ãã åºç¤ãæå·åããå¾æ¥å¡ãã¦ã¼ã¶ã®æ å ±ãªã©ãå ¥æãã¦ãããå社ã身代éã®æ¯æãã«å¿ããªããã°
2024å¹´7æ1æ¥ãOpenSSHã®éçºãã¼ã ã¯æ·±å»ãªèå¼±æ§ CVE-2024-6387 ã確èªãããã¨ãã¦ã»ãã¥ãªãã£æ å ±ãçºåºããèå¼±æ§ãä¿®æ£ãããã¼ã¸ã§ã³ãå ¬éãã¾ããããã®èå¼±æ§ãçºè¦ããQualysã«ããã°ãæ¢å®è¨å®ã§æ§æãããsshdãå½±é¿ãåããã¨ãããå½±é¿ãåããã¨ã¿ãããã¤ã³ã¿ã¼ãããæ¥ç¶å¯è½ãªãã¹ããå¤æ°ç¨¼åãã¦ããç¶æ³ã«ããã¨å ±åãã¦ãã¾ããããã§ã¯é¢é£ããæ å ±ãã¾ã¨ãã¾ãã æ¦è¦ æ·±å»ãªèå¼±æ§ã確èªãããã®ã¯OpenSSHãµã¼ãã¼ï¼sshdï¼ã³ã³ãã¼ãã³ããèå¼±æ§ãæªç¨ãããå ´åãç¹æ¨©ã§ãªã¢ã¼ãããèªè¨¼ãªãã®ä»»æã³ã¼ãå®è¡ããããæããããã æªç¨ã«ãããå ±åãªã©ã¯å ¬è¡¨æç¹ã§ããã¦ããªãããglibcãã¼ã¹ã®Linuxã«ããã¦æ»æãæåãããã¨ãæ¢ã«å®è¨¼ãããã¦ãããçºè¦è ã®Qualysã¯ãã®èå¼±æ§ã®å®è¨¼ã³ã¼ããå ¬éããªãæ¹éã¨ãã¦ããããã¤ã³ã¿ã¼ãããä¸ã§ã¯PoC
æ°å¤ä¸ã¯ãããªããã®ã®ãæå³çãªçæçã¡ã³ããã³ã¹ããæå³ããªãé害ã§ãï¼åãããã®æéãçããã°ããã®æéã«ç©ã¾ããã¯ãã ã£ã売ä¸ã¯ããã®å¾©å¸°å¾ã«å£²ãä¸ããå ´åãå¤ãã§ãããããã®è¾ºãã¯ãã¦ã¼ã¶ã¼ã®ä¿¡é ¼ãæãªããªãæ¹æ³ãéç¨ãå¿ããããã¨ã§ãååã«åããããå¯è½æ§ãå«ãæ§è³ªã§ãã ããããããããã¾ãã«é«é »åº¦ã§ãã£ããé·æéã«ãªãã¨ããã®å¾©å¸°å¾ã«åæ¢æéåãå«ãã売ãä¸ãã«ãªããããã®ã¾ã¾æ©ä¼æ失ã¨ãªãå¯è½æ§ãé«ã¾ãã¾ããããããã¦ã¼ã¶ã¼é¢ãã¨ãããã¤ã§ãããã®æ失ã ãã§æ¸ãã°ã¾ã ãã·ã§ãæ®éã«èããã°ãã®å¾ã«æ³å®ãã¦ãã売ä¸ãæ¸å°ãç¶ããå ã«æ»ãã«ã¯ç¸å¿ã®æéã¨å´åãä¼´ãã§ããããããæ°å¤ä»¥ä¸ã®çæã¨ãªãã¯ãã§ãã ããèãã¦ããã¨ãéç¨é¢ä¿è ãå¥å ¨ã§ããã°ãç¡çã«100ï¼ ã®å¯ç¨æ§ãç®æããå°ãªãã¨ãåè¨99ï¼ ä»¥ä¸ã¨ãªãåæ¢ç¶äºãæãããéç¨ã¨ããæ°æ¥ãè·¨ããããªé£ç¶ããé·æéã®åæ¢ã
åç»é ä¿¡ã®ããã³ãã³åç»ããæ¸ç±ã®åºçãªã©ã«ã·ã¹ãã é害ãèµ·ãã¦ããåºç大æKADOKAWAã«ã¤ãã¦ãBlackSuitãï¼ãã©ãã¯ã»ã¹ã¼ãï¼ã¨åä¹ãããã«ã¼éå£ãããµã¤ãã¼æ»æã«ãã£ã¦ä¼ç¤¾ã®äºæ¥è¨ç»ãã¦ã¼ã¶ã¼ãªã©ã®ãã¼ã¿ãçã¿åã£ãã¨ä¸»å¼µããç¯è¡å£°æãåºãããã¨ããããã¾ããã KADOKAWAã¯ä»æ8æ¥ã°ã«ã¼ãä¼ç¤¾ã®ãã¼ã¿ã»ã³ã¿ã¼ã®ãµã¼ãã¼ã身代éåã®ã³ã³ãã¥ã¼ã¿ã¼ã¦ã¤ã«ã¹ï¼ã©ã³ãµã ã¦ã¨ã¢ã«ãããµã¤ãã¼æ»æãåãããªã©ãã¦ã·ã¹ãã é害ãçºçããããã³ãã³åç»ããæ¸ç±ã®åºçã¨ãã£ãã°ã«ã¼ãå ¨ä½ã®äºæ¥ã«å½±é¿ãåºã¦ãã¾ãã 27æ¥åå¾ããBlackSuitããåä¹ãããã«ã¼éå£ããããä¸ã®éãµã¤ãã§KADOKAWAã®ãããã¯ã¼ã¯ã«ä¾µå ¥ãããã¼ã¿ãçã¿åã£ãã¨ä¸»å¼µããç¯è¡å£°æãåºãããã¨ããããã¾ããã ãµã¤ãã確èªããã»ãã¥ãªãã£ã¼é¢ä¿è ã«ããã¾ãã¨ããã¼ã¿ã¯äºæ¥è¨ç»ãã¦ã¼ã¶ã¼ã«é¢ããæ å ±ãª
â»ãããã¨ãããæ¬ç¨¿ã¯ãç§ã®ææã¡ã«ãã¬ã人éè¿·è·¯ãã«ã¦é ä¿¡ããã¦ããå 容ã¨åä¸ã®ãã®ã§ãããã§ã«ã¡ã«ãã¬ãåã£ã¦ããããæ¹ã¯ããå¸æ½ã§ããªãéãééã£ã¦ãè³¼å ¥ãããªããããé¡ããããã¾ãã https://yakan-hiko.com/kirik.htmlãããã¾è ããã¦ãçµç¹ã®è¨äºãæ¸ãã¡ãã£ãããç¯äººã®è¦æ±ãå©ããã ããããªãã®ãã¨è©±é¡é¨ç¶ã®æ¬ä»¶ãè¨äºãæ¸ããNewsPicksã«ãæ¹å¤ãæ¥ã¦ããã¾ãã確ãã«ä¸çãã£ã¦ãç¾å¨é²è¡å½¢ã§ã©ã³ãµã ã¦ã§ã¢ã¶ã£è¾¼ãã§ããå ã¨äº¤æ¸ãã¦ããæä¸ã«å é¨ãªã¼ã¯ã§è¨äºæ¸ããªã¨ããå·ä¸éçããã®æããç解ã¯ã§ãã¾ãã ãã ãå ·ä½çãªäººèº«ã®èªæç¯ãç«ã¦ãããç¯ãªã©ã¨éã£ã¦æ¬ä»¶äºä»¶ã®ç¸æã¯ããã«ã¼ã§ããããã³ãã³åç»ãã©ãã ãããã¯ããããã¨ç©ççã«äººã¯æ»ã«ã¾ãããåç´ã«Blacksuitçªã£è¾¼ã¾ãã¦ã·ã¹ãã ãä»ãµã¼ãã¹ãã¨å ¨é¢ãã¦ã³ãããããKADOKAWAã
ãç¥ãã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}