ãªã¼ãã³ãªã¾ã«ãã¼ç¢ºèªãµã¤ã
JPCERT/CCã§ã¯ããªã¼ãã³ãªã¾ã«ãã¼(å¤é¨ã®ä¸ç¹å®ã®IPã¢ãã¬ã¹ããã®å帰çãªåãåããã許å¯ãã¦ããDNSãµã¼ãã¼)ã¨ãªã£ã¦ããDNSãµã¼ãã¼ãæ¥æ¬å½å ã«å¤ãåå¨ãã¦ãããã¨ã確èªãã¦ãã¾ãã ãªã¼ãã³ãªã¾ã«ãã¼ã¯å½å å¤ã«å¤æ°åå¨ãã大è¦æ¨¡ãªDDoSæ»æã®è¸ã¿å°ã¨ãã¦æªç¨ããã¦ããã¨ã®å ±åãããã¾ãã ã¾ããDNSãµã¼ãã¼ã¨ãã¦éç¨ãã¦ãããã¹ãã ãã§ã¯ãªããããã¼ããã³ãã«ã¼ã¿ã¼ãªã©ã®ãããã¯ã¼ã¯æ©å¨ãæå³ãããªã¼ãã³ãªã¾ã«ãã¼ã«ãªã£ã¦ããäºä¾ããããã¨ã確èªãã¦ãã¾ãã
æ¬ç¢ºèªãµã¤ãã§ã¯ãã使ãã®PCã«è¨å®ããã¦ããDNSãµã¼ãã¼ã¨ãæ¬ç¢ºèªãµã¤ãã¸ã®æ¥ç¶å ã¨ãªã£ã¦ããããã¼ããã³ãã«ã¼ã¿ã¼ãªã©ã®ãããã¯ã¼ã¯æ©å¨ããªã¼ãã³ãªã¾ã«ãã¼ã¨ãªã£ã¦ããªããã確èªãããã¨ãå¯è½ã§ãã æ¬ãµã¤ãã®è©³ç´°ã«ã¤ãã¦ã¯ãã¡ãããåç §ãã ããã
æ¬ãµã¤ãããæ´»ç¨ããã ããå¥å ¨ãªã¤ã³ã¿ã¼ãããéç¨ã«ãååããã ãã¾ããããé¡ããããã¾ãã
æ¥ç¶å IPã¢ãã¬ã¹ã¨PCã«è¨å®ããã¦ããDNSãµã¼ãã¼ã®IPã¢ãã¬ã¹ã«å¯¾ãã¦v3.openresolver.jpã®ä¸ã®ãã¡ã¤ã³åãåãåããã¾ãã
â» ã¢ã¯ã»ã¹ãéä¸ãã¦ããã¨ãã¯ã確èªã«æéãããããã¨ãããã¾ããç»é¢ãé·ç§»ããªãå ´åã«ã¯ãå度確èªãã¿ã³ãã¯ãªãã¯ãã¦ãã ããã
â» æ¬ãµã¤ãã§ã¯æ¬ãµã¤ãã«åå解決ã®ãªã¯ã¨ã¹ããéã£ã¦ãããã¼ãã®IPã¢ãã¬ã¹ããã«ãªã¾ã«ãã¼ã¨ãã¦æ±ã£ã¦ãã¾ãããUDPéä¿¡ã®æ§è³ªãªã©ã«ãã£ã¦åããã¼ãå ´åãªã©ãããå¿
ããããã¹ã¦ã®ãã«ãªã¾ã«ãã¼ã«ã¤ãã¦æ
å ±ãå¾ãããã¨ã¯éãã¾ããã
â» ãã«ãªã¾ã«ãã¼ãåå解決ãªã¯ã¨ã¹ããåãä»ããIPã¢ãã¬ã¹ã¨ã¯ç°ãªãIPã¢ãã¬ã¹ããåèµ·çãªåå解決ãè¡ãå ´åã«ã¯å¾è
ã®IPã¢ãã¬ã¹ã§è¡¨ç¤ºãã¾ãã®ã§ããæå
ã®ç°å¢ã§è¨å®ããããã«ãªã¾ã«ãã¼ã®IPã¢ãã¬ã¹ã¨ã¯ç°ãªããã®ã表示ãããå ´åãããã¾ãã
â» DNS over HTTPSãªã©ã®è¨å®ã«ãããã©ã¦ã¶ã¼ãã³ãã¼ã®ãã«ãªã¾ã«ãã¼ããåå解決ãè¡ãå ´åãªã©ã¯ãå®éã«ãªã¯ã¨ã¹ããéä¿¡ãããã«ãªã¾ã«ãã¼ã«å¯¾ãã¦ç¢ºèªããçµæã表示ãã¾ãã
ãã¹ãã£ã³ã°ãµã¼ãã¹ã§ä½¿ç¨ãã¦ãããµã¼ãã¼ãã¦ã¼ã¶ã¼ã®æå³ããªãã¾ã¾ãªã¼ãã³ãªã¾ã«ãã¼ã¨ãªã£ã¦ããäºè±¡ãå¤ãå ±åããã¦ãã¾ãã ãããã®ãã¹ã管çè ã®æ¹ãcurlã³ãã³ããªã©ã使ç¨ãã¦ã³ãã³ãã©ã¤ã³ãã確èªã§ããæ¹æ³ãç¨æãã¦ãã¾ãã
ã³ãã³ãã©ã¤ã³ããã®ç¢ºèªæ¹æ³ã¯ããã¡ãããåç §ãã ããã
â» ãã®ã°ã©ãã¯The Shadowserver Foundationãããã¼ã¿ã®æä¾ãåãã¦ä½æãã¦ãã¾ãã (注: æ¥æ¬ã®ãªã¼ãã³ãªã¾ã«ãã¼å ¨æ°ã表ããã®ã§ã¯ããã¾ãã) ã°ã©ãã®ãã¼ã¿ã¯ãã¡ãã