ãµã¤ãã¦ãºã»ã©ãã®å æã§ãã
ä»åã¯Microsoft Excelã«åå¨ããç¹å¥ãªãã¹ã¯ã¼ãã®ä»æ§ãç´¹ä»ãã¾ãã å¾åã¯ããããã¯ãã¦ã¤ã«ã¹ã¨é¢ããã¨ã©ããªãããã¡ãã£ã¨ããå®é¨ãããã®ã§ãã®ç´¹ä»ããã¾ãã
ããããã®ãã£ãã
ããã¯æµ·å¤ã®äººããã®ã¡ã¼ã«ã§ããã ç§ã¯CODE BLUE 2015ã§ãMS Officeãã¡ã¤ã«æå·åã®ãã¹ã¿ã¼éµãå©ç¨ããããã¯ãã¢ã¨ãã®å¯¾çããçºè¡¨ããéã Windows/Linuxã§Microsoft Officeãã¡ã¤ã«ã®æå·åã»å¾©å·ãã³ãã³ãã©ã¤ã³ã§ã§ãããã¼ã«msofficeãå ¬éãã¾ããã
ãã®ã¡ã¼ã«ã¯ãã¼ã«ã«ã¤ãã¦ã®è³ªåã§ããç¥äººããããã£ããã¡ã¤ã«ããã®ãã¼ã«ã§ç¢ºèªããã¨æå·åããã¦ããã®ã«ãã¡ã¤ã«ãéãã¨ãã«ãã¹ã¯ã¼ããèãããªãããªã?ãã¨ãããã®ã§ããã
æå質åã®æå³ãããããªãã£ãã®ã§ããã確èªããã¨ç¢ºãã«ãã¡ã¤ã«ãéãã¨ãã«ãã¹ã¯ã¼ããä¸è¦ãªã®ã«ä¸èº«ã¯æå·åããã¦ãã¾ãã æä½ã®ãã¼ã«ã使ãã¨æå·ã«ä½¿ããã¦ãã詳細ãã©ã¡ã¼ã¿ãåå¾ã§ãã¾ãã
bin\msoffice-crypt.exe test.xlsm -info flags = 00000024 sizeExtra = 0 algId = 0000660e algIdHash = 00008004 keySize = 128 providerType = 00000018 cspName = Microsoft Enhanced RSA and AES Cryptographic Provider (Prototype) dataSize = 72 saltSize = 16 salt = 0C:A5:... encryptedVerifier = FF:14:... ... bad password
æå·åãã©ã¼ãããã¨ãã¦ã¯ä¸èªç¶ãªã¨ããã¯ããã¾ãããã¨ããã¨ãä½ãç¹å¥ãªãã¹ã¯ã¼ãã§æå·åãã¦ããã®ã ãããã¨æ³åãã¾ããããã©ããªãã¹ã¯ã¼ããè¦å½ãã¤ãã¾ããã ãµã¨LibreOfficeã§ãéããã®ã ãããã¨è©¦ããããåé¡ãªãéããã®ã§ãã
ã¨ãããã¨ã¯LibreOfficeãä½ãç¹å¥ãªå¦çããã¦ããã¨æ¨æ¸¬ã§ãã¾ãã ããã§LibreOfficeã®ã½ã¼ã¹ã³ã¼ãã調ã¹ã¦ã¿ããã¾ãã«ããããå¦çãå ¥ã£ã¦ãã¾ããï¼filterdetect.cxxï¼ã
if( aDecryptor.readEncryptionInfo() ) { /* "VelvetSweatshop" is the built-in default encryption password used by MS Excel for the "workbook protection" feature with password. Try this first before prompting the user for a password. */ std::vector<OUString> aDefaultPasswords; aDefaultPasswords.push_back("VelvetSweatshop");
ç¹å¥ãªãã¹ã¯ã¼ãVelvetSweatshop
ã½ã¼ã¹ã³ã¼ããèªãã¨ãã©ãããVelvetSweatshop
ã¨ããç¹å¥ãªãã¹ã¯ã¼ããããããã§ããæå·åããããã¡ã¤ã«ãå¦çããå ´åãã¾ããã®ãã¹ã¯ã¼ãã§å¾©å·ãã¦ã¿ã¦é§ç®ã ã£ããé常ã®ãã¹ã¯ã¼ããæ±ããå¦çã«ç§»ã£ã¦ãã¾ããã
ããã§ç§ã®ãã¼ã«ã§ãã®ãã¹ã¯ã¼ããã¤ãã¦å
ç¨ã®ãã¡ã¤ã«ã«å¯¾ãã¦å¾©å·å¦çããããã¡ããã¨å¾©å·ã§ããã®ã§ãã
ã¡ãªã¿ã«WordãPowerPointã§ãã®ãã¹ã¯ã¼ããã¤ãã¦ä¿åããã¨ã次åéããã¨ãã«ãã¹ã¯ã¼ãå ¥åç»é¢ã表示ããã¾ããã ãã®ãã¹ã¯ã¼ãã¯Excelã®ã¿ã«æå¹ãªããã§ãããªãã¨ãå¥å¦ãªä»æ§ã§ãã
ãã¯ãã¦ã¤ã«ã¹ã¨ã¢ã³ãã¦ã¤ã«ã¹ã½ãã
ãã¦ãExcelãªã©ã®VBScriptãå©ç¨ãããã¯ãã¦ã¤ã«ã¹ã¨ãããã®ãããã¾ãã 1996å¹´é Larouxã¨å¼ã°ãããã¯ãã¦ã¤ã«ã¹ãåãã¦ç»å ´ãã¾ããã ããããã¦ã¤ã«ã¹ã®ç¨®é¡ãå¾ã ã«å¢ãã¦ãã1999å¹´ãã大æµè¡ãã¾ãããã®å¾Office 2007ãããã¯ãæ©è½ã¯ããã©ã«ãã§ãªãã«ãªããã¾ãä¼ç¤¾ã«ãã£ã¦ã¯ãã¯ããç¦æ¢ãã¦ããã¨ããããã£ã¦è¿å¹´ã§ã¯ä¸ç«ã«ãªã£ã¦ãã¾ããã ãã å»å¹´ã®è¨äºã«ããã¨2015å¹´ãããããåã³å¢å å¾åã«ããããã§ãï¼ãã¯ãã¦ã¤ã«ã¹ãç¥ããªãä¸ä»£ã®ç¤¾å¡ãçãããï¼ãOfficeææ¸ãéãã¦ææãæ»æãåã³å¢å ï¼INTERNET Watchï¼ï¼ã
ã¢ã³ãã¦ã¤ã«ã¹ã½ããã¯ãã¯ãã¦ã¤ã«ã¹ãã¡ã¤ã«ãæ¦ããã¿ã¼ã³ãããã§æ¤åºãã¾ãã ããããã¹ã¯ã¼ããã¤ãã¦æå·åãã¦ããããã¡ãã復å·ã§ãããä¸èº«ããã§ãã¯ã§ãã¾ããã
ãã VelvetSweatshop
ã¨ããç¹å¥ãªãã¹ã¯ã¼ããã¤ããå ´åãä¸èº«ã¯æå·åããã¦ãã¦ãè¦ããã¯ã¦ã¼ã¶ã«ã¨ã£ã¦æ®éã®ãã¡ã¤ã«ã¨åãã§ãã
ãã¹ã¯ã¼ããåãã£ã¦ããã®ã§æè¡çã«ã¯å¾©å·å¯è½ã§ãããã¢ã³ãã¦ã¤ã«ã¹ã½ããã¯ãã®ä¸èº«ããã§ãã¯ãã¦ããã®ã§ããããã
ããã§å®éã«Larouxã¨å¤å®ãããExcelãã¯ããã¡ã¤ã«ãä½ããVelvetSweatshop
ã§æå·åãã¦è©¦ãã¦ã¿ã¾ããã
7種é¡ã®ã¢ã³ãã¦ã¤ã«ã¹ã½ããã§ãã§ãã¯ããã¨ããæ¤åºããã®ã¯ä¸ã¤ã ãã§ããï¼2017å¹´3æ6æ¥æç¹ï¼ã
æå¤ã«ãç´ éããã¦ãã¾ãã®ãå¤ãã£ãã§ãã
æ¤åºããã½ããã¯ããæå·åExcelãã¡ã¤ã«ãè¦ã¤ãããã¨ããããVelvetSweatshop
ã§å¾©å·ããæåãããä¸èº«ããã§ãã¯ãããã¨ããå¦çããã¦ããã®ã ããã¨æãã¾ãã
å®ã¯ãã®è©±ã¯æµ·å¤ã§ã¯å²ã¨æåãªããã§ããã¨ãã°When is a password not a password?ã¨ãã2013å¹´ã®è¨äºãããã¾ãã ä»åãã¡ã¸ã£ã¼ãªã¢ã³ãã¦ã¤ã«ã¹ã½ãããæ¤ç¥ããªãã®ãèªåã§ç¢ºèªãã¦ãå人çã«ã¯ããã¯ãã§ãã¯ãã¹ãã§ã¯ã¨æãã¾ããããããã½ãããã³ãã¼ã«ã¨ã£ã¦ã¯ããã®ãªã¹ã¯ã«å¯¾ãã¦ã¹ãã£ã³ããã³ã¹ãã®å¢å ãè¦åããªãã¨ããå¤æãªã®ããããã¾ããã ãã®ä»¶ã«ã¤ãã¦MSRCï¼Microsoft Security Response Centerï¼ã«åãåãããã¦ã¿ãã®ã§ããããããã¦å½±é¿ããªãã®ã§ï¼minimal impactï¼ç¹ã«å¯¾å¿ããäºå®ã¯ãªãã¨ã®ãã¨ã§ããã
ãããã«ããæè¿ã¯å人ãçã£ãæ¨çåã¦ã¤ã«ã¹ãå¤ãããã§ãããã¡ã¤ã«ãéãã¨ãããã¯ããæå¹ã«ããã¨ãã«ãã¤ã§ã注æããªããã°ãªããªãã®ã¯å®è·µããã®ãé£ãããæ©ã¾ããåé¡ã§ããã