æ¨æ¥ã®GIEã·ã³ãã¸ã¦ã ã«ã¤ãã¦ã®ã¡ã¢
æ¨æ¥ã¯ãã¡ãã®ã·ã³ãã¸ã¦ã ã«åå ãã¦ãã¾ããã
『ソニーの個人情報流出事件をどう考えるか -サイバー攻撃に対する政府・企業・個人の対応』
(éå¬ä¸»æ¨)
ããã社ä¼ã®é²å±ã«ä¼´ããã¤ã³ã¿ã¼ããããä»ãã¦ä¼æ¥ã®ã¦ã§ããµã¤ããå ¬çæ©é¢ã®ã·ã¹ãã ãªã©ã«ä¸æ£ä¾µå ¥ãããããã³ã°ã«ãã被害ãè¿å¹´æ¥éã«æ¡å¤§ãã¦ãã¾ããæè¿ã§ã¯ã½ãã¼ã®ãããé ä¿¡ãµã¼ãã¹ãæ»æãåããè¨ï¼å件以ä¸ã®å人æ å ±ãæµåºãã¾ãããä¸æ¹ãæµ·å¤ã§ã¯æ°éä¼æ¥ã®ã¿æãããæ¿åºæ©é¢ãè»äºæ½è¨ãå½å®¶ä¸»å°ã¨æããããµã¤ãã¼æ»æãåãã¦ãããã¨ãå ±åããã¦ãã¾ãããããããµã¤ãã¼æ»æã®èå¾ã«ã¯ãç¹å®ã®æ¿æ²»çãªææ³ã«åºã¥ããå½å¢ãè¶ãã¦é£æºããã¢ãããã¹ãªã©ããã«ã¼éå£ãããã¨ããã¦ãã¾ããæ¬ã·ã³ãã§ã¯ãããããå¾ã絶ããªããµã¤ãã¼æ»æã¯ã©ãç解ãããã¹ãã§ãæ¿åºã»ä¼æ¥ã»å人ã¯ã©ã対å¿ãã¹ãããã«ã¤ãã¦è°è«ãã¾ãã(主å¬)
æ ¶æ義塾大å¦SFCç 究æ ãã©ãããã©ã¼ã ãã¶ã¤ã³ã»ã©ã(æ¥ç¨)
2011å¹´8æ29æ¥ï¼æï¼ã18:30 - 20:30(ä¼å ´)
æ ¶æç¾©å¡¾å¤§å¦ ä¸ç°ãã£ã³ãã¹ æ±é¤¨6FãG-Sec Lab ï¼æ¡å å³ï¼(ãããªã¹ã)
é´æ¨ãæ£æãæ°ããï¼æ°æ½å¤§å¦æ³ç§å¤§å¦é¢ææï¼
å «ç°ãçè¡ãæ°ããï¼é§¿æ²³å°å¤§å¦çµæ¸å¦é¨å°ä»»è¬å¸«ï¼ã
å¡è¶ãå¥å¸ãæ°ããï¼ä¸æ©å¤§å¦å¤§å¦é¢ç¤¾ä¼å¦ç 究ç§å士å¾æ課ç¨ï¼ããããããããã
å è¤ãå¹¹ä¹ããã ãï¼æ ¶æ義塾大å¦å¤§å¦é¢æ¿çã»ã¡ãã£ã¢ç 究ç§ç¹ä»»ææï¼
åé ãäºéãã ããï¼æ ¶æ義塾大å¦ç·åæ¿çå¦é¨é·ï¼ ããããããããããã¢ãã¬ã¼ã¿ã¼ï¼
ã¸ã§ã³ã»ãã ãããã ï¼æ ¶æ義塾大å¦å¤§å¦é¢æ¿çã»ã¡ãã£ã¢ç 究ç§åææï¼
é常ã«èå³æ·±ãè¦ç¹ãããã¤ããã£ã¦å¤§å¤åèã«ãªãã¾ããããããªã¹ãã®çæ§ãããã¨ããããã¾ãããUstreamã§ãè¦ãããããªã®ã§ãè¦éãããæ¹ã¯ã©ããã
Twitterã®ããã·ã¥ã¿ã° #GIE_sonyé¢é£ã®ã¾ã¨ãã¯コチラã«ããã¾ã*1ããã®ã¿ã¤ã ã©ã¤ã³ãè¦ãã¨ã主ã«æè¡è
ã¨ãã¦ãã®åé¡ã«åãçµãã§ãã人éããã®æè¦ãå¤ãã¿ããã¾ããç§ãããã¤ãã³ã¡ã³ãããã®ã§ãããããã¾ã§ã«èµ·ããäºä»¶ã«é¢ããäºå®èªèã®çããããæ°ã«ãªãã¾ããããã®ã¨ã³ããªã§ã¯æ¨æ¥ Twitterã§è§¦ããé¨åãå«ãã¦ãããã¤ãæ°ã«ãªã£ããã¤ã³ãã«ã¤ãã¦ã¾ã¨ãã¦ããã¾ã*2ã
(1) ããããã½ãã¼äºä»¶ã«ã¤ãã¦
ã¡ãã£ã¢çã§ããã½ãã¼äºä»¶ãã¨ä¸æ¬ãã«èªããããã¨ãããã®ã§ãããå°ãªãã¨ã以ä¸ã® 3ã¤ãããã«ã¯åãã¦æããã¹ãã ã¨èãã¾ãã
- Anonymousã«ãã DDoSãªã©ã®æ»æ (#OpSony, #SonyRecon) (4/3 - 4/16)
- PSN/SOEããã®å人æ å ±æ¼æ´© (4/16 - 4/19)
- Idahcã LulzSecã«ããé¢é£ä¼æ¥ã¸ã®æ»æãæ å ±æ¼æ´© (5/5 - 7/5)
1çªç®ã«ã¤ãã¦ã¯ããªãã¬ã¼ã·ã§ã³ã¯ä¸è¬ã«å
¬éããã¦ããããAnonymousããã£ããã¨ã§ééãããã¾ãããIRCãã°ã®ããã¤ãã¯ã¾ã Pastebinã§ãè¦ããããã§ã*3ã(こちらの過去記事ãåç
§ã®ãã¨ã)
2çªç®ã«ã¤ãã¦ã¯ã¡ãã£ã¢çã§å¤æ°å ±éããã¦ããã®ã§ããã§ã¯ãã¾ãè¿°ã¹ã¾ããããæ å ±æ¼æ´©ã«é¢ãã¦ã¯ã¾ã 誰ããã£ãã®ãããã£ã¦ãã¾ãããSonyã 5/1ã®è¨è ä¼è¦ã®å ´ã§ãAnonymousããã® DDoSæ»æã«å¯¾å¿ãã¦ãããã¨ã強調ãããããæ å ±æ¼æ´©ã Anonymousã®ç¯è¡ã§ããã¨æããã¦ããã¨ãããããã¾ãããå°ãªãã¨ãç¾æç¹ã«ããã¦ã¯ããã¯èª¤è§£ã§ããã¾ã米議会向けに Sonyが提出したææ¸ãããSOEã«ä¾µå ¥ããæ»æè ã "We are Legion."ã¨æ¸ããã Anonymousã¨ããååã®ãã¡ã¤ã«ãæ®ãã¦ãã£ããã¨ãããã£ã¦ãã¾ããããããããéå»ã® Anonymousã®ããæ¹ãèããã¨ãAnonymousèªèº«ããã£ãã¨ãããããææ»ãæ··ä¹±ãããç®çã§æ»æè ãããã¨æ®ããã¨èããã»ããèªç¶ã ã¨æãã¾ãããã¡ãã Anonymousããã£ãå¯è½æ§ãããã¾ãã
3çªç®ã«ã¤ãã¦ã¯ã種ã éå¤ãªæ»æãå«ã¾ãã¦ãã¾ããã1,2çªç®ã®æ»æã¨ã®ç´æ¥ã®é¢ä¿ã¯ãããããªãã¨æãã¾ãã(こちらの過去記事ãåç §ã®ãã¨ã)
ãããã¯è¡çºã®ä¸»ä½ãåæ©ãææ³ãªã©ã¿ãªãã©ãã©ãªäºä»¶ã®éããªã®ã§ãã¾ã¨ãã¦èªã£ã¦ãã¾ãã®ã¯ããç¡çãããã¾ãããã½ãã¼äºä»¶ãã«ã¤ãã¦èªãå ´åã«ã¯ãå
·ä½çã«ãªãã®äºä»¶ã«ã¤ãã¦ã®è©±ãªã®ãããã¤ã³ããçµãã¹ãã ã¨æãã¾ãã
(2) PSNã¸ã®ä¾µå ¥æ¹æ³ã«ã¤ãã¦
Sony㯠5/1ã®è¨è ä¼è¦ã«ããã¦ãã(Web)ã¢ããªã±ã¼ã·ã§ã³ãµã¼ãã®æ¢ç¥ã®èå¼±æ§ãçªããããã¨è¿°ã¹ãã«ã¨ã©ã¾ãããã®å¾ãä¾µå ¥æ¹æ³ã®è©³ç´°ã«ã¤ãã¦ã¯æããã«ãã¦ãã¾ããããã ã該å½ããæ¡ä»¶ã«ãã¦ã¯ã¾ãèå¼±æ§ã¯ããã»ã©ãªããããã»ãã¥ãªãã£æ¥çé¢ä¿è ã®éã§ã¯ Apache Struts2ã®èå¼±æ§ (CVE-2010-1870)ãæªç¨ãããã®ã§ã¯ãªããã¨æ¨æ¸¬ããã¦ãã¾ãã
ããã¯å人çãªæè¦ã§ãããä»å¾ã®æè¨ã¨ãã¦çããããã«ããSonyããã«ã¯ä¾µå
¥ã®è©³ç´°ã«ã¤ãã¦ãã²æããã«ãã¦ããã ãããã¨æãã¾ããããã»ã©é«åº¦ãªæ»æãè¡ãããã¨ã¯æãã¾ããããæ°ããªæ»æãå©é·ããã¨ã¯æããªãã®ã§ããããããæ»ææ¹æ³ãç¥ããã¨ã¯é©åãªé²å¾¡çãè¬ããããã«é常ã«æå¹ã§ããç¡çã§ãããããã
(3) PSNã®ãµã¼ãã§ç¨¼åãã¦ããã½ããã¦ã§ã¢ã®ãã¼ã¸ã§ã³ã«ã¤ãã¦
æ¨æ¥ã®ããã«ã§ããOpenSSHã®ãã¼ã¸ã§ã³ãå¤ããããã¨ããçºè¨ãããã¾ãããããã¯ãã¼ãã¹ãã£ã³ã§å¾ãããããã¼æ
å ±ã«ãã¨ã¥ããã®ã ã¨æãã¾ãããããããã¼ãå®éã®ãã¼ã¸ã§ã³ãåæ ãã¦ãããã©ããã¯ãµã¼ãã®ç°å¢ã«ä¾åãã¾ããããã¼ã ããè¦ã¦ããã¼ã¸ã§ã³ãå¤ããã¨æ±ºãã¤ãããã¨ã¯ã§ãã¾ããããããã£ã¦ãå®éã«ç¨¼åãã¦ããã½ããã¦ã§ã¢ã®ãã¼ã¸ã§ã³ãæ¬å½ã«å¤ãã£ãã®ãã©ããã¯ãSonyãããæããã«ããªãéããããã¾ããããã ããã¢ããªã±ã¼ã·ã§ã³ãµã¼ããã ããã«æ¢ç¥ã®èå¼±æ§ãæ®ã£ã¦ããã¨ã¯èãã«ããã®ã§ãä»ã®ãµã¼ãã«ããã¯ãèå¼±æ§ã¯åå¨ãã¦ããã®ã§ã¯ãªããã¨ç§ã¯èãã¦ãã¾ãã(こちらの過去記事ãåç
§ã®ãã¨ã)
(4) å é¨ç¯è¡èª¬ã«ã¤ãã¦
PSN/SOEããã®æ å ±æ¼æ´©ã«é¢ãã¦ãå é¨ç¯è¡ã¾ãã¯å é¨ã«ååè ãããã®ã§ã¯ãªãããã¨ãã話ãããã¾ããããã㯠SOEãæ¼æ´©äºä»¶ã®èµ·ããç´2é±éåã« NOC(Network Operations Center)ã®ã¹ã¿ãããå«ã人å¡æ´çãè¡ã£ãã¨ããäºå®ã«ãã©ã¥ãæ¨æ¸¬ã§ããç§ãããã¯å¤§ãã«ãããã話ã ã¨èãã¦ãã¾ãããçç¸ã¯ä»ã®ã¨ããä¸æã§ãã
(é¢é£è¨äº)
Sony laid off employees before data breach- lawsuit | Reuters
Lawsuit: Sony laid off security staff, unprepared for PS3 hacks | Ars Technica
Usave Compare and Save Online - usave.co.uk
(5) ãã㦠Anonymousã«ã¤ãã¦â¦
Anonymousã«ã¤ãã¦ã¯ãããã«ã¼éå£ãã¨ãã¦èªããããã¨ãå¤ããç§èªèº«ãé¢åãªã¨ãã«ã¯ãã説æãããã¨ãããã¾ããæ¨æ¥ã®ããã«ã®ãããªçæéã§ã¯å°åºèª¬æã¯ç¡çã ã¨æãã¾ãããå®éã® Anonymousã¯é常ã«è¤éã§ç§ã«ããããããã¾ããããã ãå°ãªãã¨ãããã¤ãè¨ãããã¨ã¯ããã¨æãã¾ãã
- ãããã«ã¼ãã¨å¼ã¹ãã®ã¯å ¨ä½ã®ä¸ã§ã¯ããããé常ã«å°æ°ã§ãããã¨(仮㫠Anonymousãä¸çä¸ã«1ä¸äººããã¨ãã¦ãããã®ãã¡æ°å人ç¨åº¦*4 )
- DDoSæ»æãæ å ±æ¼æ´©ãèµ·ããã¦ããã®ã¯ä¸»ã« AnonOpsã®äººéã§ãããã¨ã¯ç¡é¢ä¿ã«æ´»åãã¦ãã Anonymousãå¤æ°ããã㨠(ãã¨ãã°åãµã¤ã¨ã³ããã¸ã¼ãæ²ãã AnonNetãªã©ã¯ãã®ä»£è¡¨)
- å ã ãããããªäººã Anonymousã«ã¯ããããæè¿ã® AntiSecã®ã ã¼ãã¡ã³ãã«ãã£ã¦ããã«æ··æ²ã¨ãã¦ããããã¯ããAnonymousã¨ã¯ãããã人éãã¨ä¸æ¬ãã§èªããã¨ã¯é£ãããªãã¤ã¤ãããã¨
Anonymousã®ä¸äººã§ãã @AnonyOpsã¯ãå¤ãã®äººã 㯠Anonymousã®ãã¨ãå¾ä½ã®ç¥ããªãè¬ã®ããã«ã¼éå£ã ã¨èãã¦ãããã(ä»ã®) Anonymousã¯å¾ä½ã®ç¥ããªãããã«ã¼éå£ã®éå£ã§ããããã¨最近語っていますãAnonymousã®ä¸ã®äºº(ç¹ã«å¤ãããã®äºº)ãç¾ç¶ã«ã¯ããããã¨å°æãã¦ããæ§åãè¦ããã¾ãã
(DDoSæ»æã«ã¤ãã¦)
Anonymous㯠Operation Payback以éãçµç¹ç㪠DDoSæ»æãæ°å¤ãè¡ã£ã¦ãã¾ãããè¡é ã§ã®å¹³åçãªãã¢æ´»åã¨å種ã®è¡çºã§ãããæ£å½ãªãã®ã ã¨ä¸»å¼µãã¦ãã¾ããRichard Stallmanæ°ãåæ§ã®æè¦ããæã¡ã®ããã§ãã
http://journal.mycom.co.jp/articles/2011/02/07/anonymous/index.html
The Anonymous WikiLeaks protests are a mass demo against control | Richard Stallman | Opinion | The Guardian
(LulzSecããã³ AntiSecã«ã¤ãã¦)
LulzSecã«ã¤ãã¦ã¯ãå½¼ãèªèº«ã®çºè¨ããªã¼ã¯ãããIRCãã°ã®å
容ãªã©ãããå
ã
3-4人ã®ã³ã¢ã¡ã³ãã¼ããå§ã¾ããæçµçã«ã¯ 6人ã®ã¡ã³ãã¼ã«ããã°ã«ã¼ãã§ãã£ããã¨ãããã£ã¦ãã¾ããå½¼ãã¯ãããã Anonymous㧠HBGary Federalへの侵入事件ã主å°ããã¡ã³ãã¼ã§ããAnonymousã¨ã¯å¥ã®æ´»åã¨ãã¦ã¹ã¿ã¼ããããã®ã®ãæçµçã«ã¯ Anonymousã¨ã®å
±éä½æ¦ Operation Anti-Security (#AntiSec)ã宣è¨ãããã¨ã« LulzSecã¨ãã¦ã®æ´»åãçµäºãã¦ãã¾ããã¡ã³ãã¼ã¯ãã®å¾ã¯ Anonymousã¨ãã¦æ´»åãç¶ç¶ãã¦ãã¾ãã(LulzSecã®æ´»åã«ã¤ãã¦ã¯å¥è¨äºãåç
§ã®ãã¨ãPart1ãPart2ãPart3ãPart4ã¾ã§ãããï¼)
ç¾å¨ã® AntiSecã®ã ã¼ãã¡ã³ãã¯å½¼ããæå³ãããã®ã§ãããå人æ
å ±ãæ¼æ´©ãããææ³ã«ã¯æ¹å¤ãå¤ããæ´»åã¸ã®æ¯æãå¾ããã¦ãããã¨ããã¨ããçåãããã¾ãããã®ä¸æ¹ã§æ´»åã«è³åãã人éãå¤ããã¦ãä¸çä¸ã§å¤æ°ã®ãµã¤ã(主ã«æ¿åºç³»)ãæ»æã«ããç¶æ³ãç¾å¨ãç¶ç¶ãã¦ãã¾ãã
Who Is LulzSec? | PCMag.com
ãã£ã¨æ°ã«ãªã£ãã¨ããã¯ãããªæãã§ãããã©ãç解ãããã¹ããã§ãã©ã対å¿ãã¹ãããã«ã¤ãã¦ã¯ãç¶ç¶ãã¦æ¤è¨ãã¦ãããªãã¨ããã¾ãããã
*1:ããããã¾ã¨ãã¯ããã¨ããåç §ããã¨ãã«é常ã«å½¹ç«ã¡ã¾ãããã¤ããããã¨ããããã¾ãï¼
*2:ã¡ãªã¿ã«ãã®è©±é¡ã«é¢ããããã«ãã£ã¹ã«ãã·ã§ã³ã®é£ããã¯すでに経験済みã§ãw
*3:ãã¼ã¯ã¼ã OpSonyã§æ¤ç´¢ãã¦ã¿ã¦ãã ãããhttp://pastebin.com/
*4:LOICã使ã£ã¦DDoSæ»æã«åå ããç¨åº¦ã®ã¬ãã«ã®äººã¯é¤ãã¨ããããããã§ã¯ãªãã§ããããã