JPCERT-AT-2019-0033 JPCERT/CC 2019-09-02(æ°è¦) 2019-09-06(æ´æ°) I. æ¦è¦JPCERT/CC ã§ã¯ãè¤æ°ã® SSL VPN 製åã®èå¼±æ§ã«ã¤ãã¦ãèå¼±æ§ã«å¯¾ããå®è¨¼ã³ã¼ããªã©ã®è©³ç´°ãªæ å ±ãå ¬è¡¨ããã¦ãããã¨ã確èªãã¦ãã¾ãã - Palo Alto Networks (CVE-2019-1579) - Fortinet (CVE-2018-13379) - Pulse Secure (CVE-2019-11510) ãããã®èå¼±æ§ãæªç¨ãããå ´åã«ãæ»æè ããªã¢ã¼ãããä»»æã®ã³ã¼ããå®è¡ã§ããå¯è½æ§ (CVE-2019-1579) ããä»»æã®ãã¡ã¤ã«ãèªã¿åããèªè¨¼æ å ±ãªã©ã®æ©å¾®ãªæ å ±ãåå¾ããå¯è½æ§ (CVE-2018-13379, CVE-2019-11510) ãããã¾ãããªããèå¼±æ§ã®å ±åè ããã¯ãããããã®è£½åã«ã¤ãã¦ãä¸è¨
ã»ãã³ï¼ã¢ã¤ã»ãã¼ã«ãã£ã³ã°ã¹ã決æ¸ãµã¼ãã¹ã7payï¼ã»ãã³ãã¤ï¼ãã®ä¸æ£å©ç¨ãåãã¦å¤é¨ã®IDããã¢ããªã¸ã®ãã°ã¤ã³ãä¸æåæ¢ããæªç½®ã«ã¤ãã¦ãåå ã¨ãªã£ãèå¼±æ§ã®ä¸ç«¯ãæããã«ãªã£ããæ¥çµ xTECHã®åæã§2019å¹´7æ12æ¥ã¾ã§ã«åãã£ããå¤é¨IDã¨ã®èªè¨¼é£æºæ©è½ã®å®è£ ã«ä¸åãããããã¹ã¯ã¼ããªãã§ä»äººã®ã¢ã«ã¦ã³ãã«ãã°ã¤ã³ã§ããèå¼±æ§ããã£ãã¨ããã å社ã¯2019å¹´7æ11æ¥åå¾5æãFacebookãTwitterãLINEãªã©5ã¤ã®å¤é¨ãµã¼ãã¹ã®IDã使ã£ããã°ã¤ã³ãä¸æåæ¢ããããåã¢ããªå ±éã§å©ç¨ãã¦ãããªã¼ãã³IDã¨ã®æ¥ç¶é¨åã«ã»ãã¥ãªãã£ã¼ä¸ã®ãªã¹ã¯ãããæãããããããï¼åºå ±ï¼ã¨ãã¦ããã ãã®èå¼±æ§ã¯ãä¸æ£å©ç¨ãå¤æããå¾ã«å¤é¨ããã®ææã§æããã«ãªã£ããã®ã§ãã»ãã³ï¼ã¢ã¤ã®ã°ã«ã¼ãå ±éIDã7iDãã®èªè¨¼ã·ã¹ãã ã«åå¨ãããå¤é¨IDé£æºæ©è½ã使ã£ã¦ãã人ã®I
Business Insider Japanç·¨éé¨ï½¢7payï½£åæçã¯ã7payã®éçºã¹ã±ã¸ã¥ã¼ã«ãåãã¾ã¨ããå é¨è³æãå ¥æããã éçºç¾å ´ã®é¢ä¿è ã®éã§ããã¨ããããè³æã®æçµçã«è¿ããã®ã§ã2018å¹´æ«ãããµã¼ãã¹ã¤ã³ç´åã¾ã§ã®éããã©ã®ãããªã¹ã±ã¸ã¥ã¼ã«ã§åããã®ãã示ãè³æã ãç¾å ´ãããç¥ãè¤æ°ã®é¢ä¿è ã®è¨¼è¨ããã¯ãè¨è ä¼è¦ã§æ³¨ç®ãéã¾ã£ãï½¢ã»ãã¥ãªãã£ã¼ä¸åï½£ã«ã¤ãªããæ ãã ããéçºç¾å ´ã®å§¿ãæµ®ãã³ä¸ããã 7payã®ä¸æ£å©ç¨ã«é¢ãã¦ã¯ã7æ3æ¥ã«ã¢ã«ã¦ã³ãä¹ã£åãã¨ä¸æ£å©ç¨ãçºè¦ããç¶ã4æ¥ã»ãã³ï¼ã¢ã¤HDãè¨è ä¼è¦ã§è¢«å®³æ¨å®é¡ãï½¢ç´5500ä¸åï½£ã¨çºè¡¨ãåæ¥å¤ã«ä¸å½ç±ã®ç·2人ãä¸æ£å©ç¨ã«é¢ãã¦è©æ¬ºæªéã®å®¹çã§é®æãããã ã»ãã³ï¼ã¢ã¤HDã¯ã»ãã¥ãªãã£ã¼å¯¾çã®çãã¸ã®ææãåããå½¢ã§ã5æ¥ã«ã¯ã»ãã¥ãªãã£ã¼å¯¾çå¼·åãç®çã¨ããæ°çµç¹çºè¶³ã¨äºæ®µéèªè¨¼å°å ¥ã1åãããã®ãã£ã¼ã¸
æ¬ãµã¤ãã¯ã¢ãã£ãªã¨ã¤ãåºåãå©ç¨ãã¦ãã¾ãããªãæ¬è¨è¼ã¯æ¯å表示æ³æ¹æ£ã«ä¼´ãASPããã®è¦è«ã«åºã¥ã表è¨ã§ãããä¾é ¼ãããè¨äºãªã©ã¯å¥éè¨è¼ãå®æ½ãã¦ãã¾ãã 追è¨ï¼é ·ãè¨è ä¼è¦ã¨ç¡æå³ãªå¯¾ç ä»æ¥ã®14æã«è¨è ä¼è¦ãè¡ããã¾ããããããéããå£ãå¡ãããªãã©ãããããæ¯ãåºãã¬ãã«ã®é ·ãè¨è ä¼è¦ã§ããã äºæ®µéèªè¨¼ãã¾ã¨ãã«ç解ãã¦ããªãï¼ãã£ã¼ã¸ã¨ç»é²ãåæ¢ãããã決æ¸ã¯åæ¢ããªãè£åã¯ããã¨ã¯è¨ã£ãããæ¹æ³ãªã©ã¯ã¾ã æªç¢ºå® ãããã£ãã¨ãµã¼ãã¹çµäºããã»ããä»å¾ã®ãããããªãã§ãããã ãã¹ã¯ã¼ãåçºè¡ã®ä»¶ã¯å¯¾çããï¼é¢¨ã«ã¿ãããï¼ ä½äººãææãã¦ãã人ãå± ã¾ããã©ãããã¾ã詳ããè¨ãã®ã¯åé¡ã«ãªããããªãã®ã§è¨ãã¾ããããä¸è¨ã«è¨è¼ã®ãããã¹ã¯ã¼ãåçºè¡ã®ä»¶ã¯å é¨ã®å¦çã¯çµå±å¯¾çããã¦ã¾ãããããã ãã¯è¨ã£ã¦ããã¾ãããã ãªã®ã§ãä¸è¨ã®ä¼å¡IDã®å¤æ´ãªã©ã¯æ©æ¥ã«è¡ã£ã¦ãã ããã
ã«ã¼ã¿ã¼ã¸ã®ãµã¤ãã¼æ»æ ã©ããããã¤ã³ã¿ã¼ãããæ¥ç¶ç¨ã®ã«ã¼ã¿ã¼æ©å¨ã«ãµã¤ãã¼æ»æãæµè¡ãã¦ããããã§ããæ¨æ¥å¤æ¹ã®ãã¥ã¼ã¹ã§ãã www.asahi.com ç»é¢ã«ãFï½ï½ï½ ï½ï½ï½ï½æ¡å¼µãã¼ã«ããã°ãåä»ã¦å®å ¨æ§åã³ä½¿ç¨æµæ¢æ§ãåä¸ãã¾ããã¨ã®ã¡ãã»ã¼ã¸ã表示ããããããã«ã¤ãªãããªããªãã ãã®è¨äºã ãã§ã¯è©³ç´°ã¾ã§ç解ããã®ã¯é£ããã¨æãã¾ã¨ãããã¨ã«ãã¾ãã ã¹ãã³ãµã¼ãªã³ã¯ äºä¾ ãã§ã«ãªãã£ã¹ã§åãç¶æ³ã«ãªãã解決ãããæ¹ãããã£ãããã¾ãã®ã§ãç´¹ä»ãã¾ãã tips4life.me ãã¡ãã®å 容ãèªãã ãã§ãååæ¦è¦ã¯ã¤ãããã¨æãã¾ãã 以ä¸ã解説ã§ãã æ»æã®å 容 ï¼ï¼æ»æè ãã«ã¼ã¿ã¼ã«ä¾µå ¥ãDNSãµã¼ãã¼ã®ã¢ãã¬ã¹ãå¤æ´ãã ä¸ã®ä¸ã«ã¯ããããã®ã¤ã³ã¿ã¼ãããæ¥ç¶ç¨ã«ã¼ã¿ã¼ãããã¾ãããããã®ã«ã¼ã¿ã¼ã«ãããã¯ã¼ã¯ã¤ã³ã¿ã¼ãã§ã¼ã¹ã¨ããéä¿¡ç¨ã®é¨åãå¿ ãå ¥ã£ã¦ãã¦ããã®
å é±ãã¾ãèå³æ·±ããã¥ã¼ã¹ãããã¾ãããç¡ç·LANã«ã¼ã¿ã¼ãªã©ã製é ããã³ã¬ã¬ãããµãã¼ããçµäºããèªç¤¾ã®ã«ã¼ã¿ã¼ã«èå¼±ï¼ãããããï¼æ§ããããã¨ãçºè¡¨ããã¨ã¨ãã«åé¿çãéç¥ããã®ã§ãã ãã®åé¿çã¨ã¯ãå½è©²ã«ã¼ã¿ã¼ã®ä½¿ç¨ãåæ¢ããããã¨ããããèãã¦ãããããªã®ã¢ãªï¼ãã¨æå¦åå¿ã示ãã人ãå¤ãããããã¾ããããç§ã¯ãããã¯ããã§èª å®ãªå¯¾å¿ãã ã¨æã£ãã®ã§ãã ITæ©å¨ã«ã¯ãµãã¼ãæéãããããèå¼±æ§ã¯ãªããªããªã æããã«ãªã£ãèå¼±æ§ã管çããæ å ±ãã¼ã¿ã«ãJVNï¼Japan Vulnerability Notesï¼ã«ããã¨ãã³ã¬ã¬ã®ç¡ç·LANã«ã¼ã¿ã¼ãCG-WGR1200ãã«ã¯ã ä¸æ£ã«ã¡ã¢ãªé åãç ´å£ããè¨è¨è ãæå³ããªãè¡åãèµ·ããããããã¡ãªã¼ãã¼ããã¼ã æå³ããªãå½ä»¤ãå®è¡ã§ãã¦ãã¾ããOS ã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³ã ç»é²ãããå©ç¨è 以å¤ããã°ã¤ã³ã§ãã¦ãã¾ããèªè¨¼ä¸å
ç±³Intelã®èå¼±æ§å¯¾çããããã¤ã³ã¹ãã¼ã«ããä¸é¨ã®CPUæè¼ãã·ã³ã§ãªãã¼ããå¢ããä¸å ·åã確èªãããåé¡ã§ãIntelã¯1æ22æ¥ãç¾å¨åºåã£ã¦ãããããã®å°å ¥ãä¸æ¢ãããããã¡ã¼ã«ã¼ãã¨ã³ãã¦ã¼ã¶ã¼ã«å¼ã³æããã Intelã¯ãMeltdownããSpectreãã¨å¼ã°ããCPUã®èå¼±æ§ãçºè¦ãããã¨ãåãã1æä¸æ¬ã¾ã§ã«OEMãªã©ãéãã¦å¯¾çããããé ä¿¡ãããã¨ããããã®ããããåå ã§ãªãã¼ããå¢ããä¸å ·åãå ±åãããIntelã¯BroadwellãHaswellãSkylakeãKaby Lakeã®åCPUãæè¼ãããã·ã³ã§åé¡ã確èªãã¦ããã 1æ22æ¥ã®æç¹ã§ã¯ããã®ãã¡Broadwellã¨Haswellã®åé¡ã«ã¤ãã¦ãæ ¹æ¬ã®åå ãçªãæ¢ããã¢ãããã¼ãã®åæãã¼ã¸ã§ã³ãæ¥çãã¼ããã¼åãã«ãªãªã¼ã¹ãã¦ãã¹ããè¡ã£ã¦ããã¨ããããã¹ããå®äºæ¬¡ç¬¬ãæ£å¼ãªãªã¼ã¹ãäºå®ãã¦ããã
Intelã¯ããMeltdownãã¨ãSpectreãã®å½±é¿ãåããæ§åãããã«ããããé©ç¨ããã¨äºæãã¬åèµ·åãçºçããåé¡ããæ°åãããã§ãçãã¦ãããã¨ãæããã«ããã Intelã¯ç±³å½æé1æ17æ¥é ãã«å ¬éããææ°æ å ±ã§ããã¡ã¼ã ã¦ã§ã¢ãããã®é©ç¨ã«ãã£ã¦èµ·ããåé¡ããæ§åã®ãBroadwellãã¨ãHaswellãã®ãããã ãã§ãªããææ°ã®ãKaby Lakeãã¾ã§ã®ããæ°ããä¸ä»£ã®CPUã§ãçºçãã¦ãããã¨ãèªããã ãã®ãã¡ã¼ã ã¦ã§ã¢ã¢ãããã¼ãã¯ãSpectreãªã©ã®åé¡ã«ããå½±é¿ãç·©åãããããIvy BridgeããSandy BridgeããSkylakeããKaby Lakeãã®åã¢ã¼ããã¯ãã£ãæ¡ç¨ããããã»ããµãæè¼ãããã·ã³ã¯ããã¡ã¼ã ã¦ã§ã¢ãæ´æ°ããå¾ã«é常ããé »ç¹ã«åèµ·åãå¼ãèµ·ããå ´åãããã¨å社ã¯è¿°ã¹ãã Intelã¯ãMeltdown/Spectr
macOS High Sierra 10.13.1ã®èå¼±æ§ãéçºè ã®Lemi Orhan Erginãçºè¦ãããã·ã¹ãã ç°å¢è¨å®ã®ãã¦ã¼ã¶ã¨ã°ã«ã¼ããããé åã®ãã¿ã³ãã¯ãªãã¯ããç°å¢è¨å®ã®ããã¯ã解é¤ããããã«ã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ããå ¥åããå ´é¢ã§ãã¦ã¼ã¶ã¼åã«ãrootãã¨å ¥åããã¨ããã¹ã¯ã¼ããå ¥åããªãã¦ãããã¯ã解é¤ããããããã¯ã解é¤ãããã¨ã²ã¹ãã¦ã¼ã¶ã¼ãèªç±ã«è¨å®ã§ããããã«ãªãã誰ã§ããã°ã¤ã³å¯è½ã«ãªããã¢ããã«ã§ã¯åé¡ãææ¡ãã¦ããã½ããã¦ã§ã¢ã¢ãããã¼ãã®æºåãé²ãã¦ãããç¾ç¶ã®å¯¾çæ¹æ³ã¯ä»¥ä¸ã®ã¨ããã âç¾ç¶ã§ãã対ç (1)ã¢ããã«å ¬å¼ããããå¾ ã¤ã㨠(2)ã²ã¹ãã¢ã«ã¦ã³ãã¸ã®ã¢ã¯ã»ã¹ãç¡å¹ã«ããã㨠(3)ã·ã¹ãã ç°å¢è¨å®ããã«ã¼ããã¹ã¯ã¼ããå¤æ´ããã㨠ã«ã¼ããã¹ã¯ã¼ãå¤æ´æ¹æ³ã¯ä»¥ä¸ã®ã¨ããã 1.Appleã¡ãã¥ã¼ >ãã·ã¹ãã ç°å¢è¨å®ãã®é ã«é¸æããã
10æ15æ¥ãWi-Fiéä¿¡ã®ã»ãã¥ãªãã£ãããã³ã«ãWi-Fi Protected Access 2ï¼WPA2ï¼ãã«åå¨ããèå¼±æ§ãè¤æ°ç¢ºèªããããã¨ãæããã«ãªãããã®è©³ç´°ã16æ¥ã«å ¬éããã¾ããããããã®èå¼±æ§ã¯ããKey Reinstallation AttaCKsãã¨ããææ³ã«ããæªç¨ããããã¨ãããKRACKãã¨å¼ã°ããWPA2ã®æå·åã®ä»çµã¿ã侵害ããã¨ãããã®ã§ãã ä¸è¨ãåãã¦10æ16æ¥ã«æ¾éããããå°é£¼å¼¾ã®è«å¼¾ãã§ã¯ãå°é£¼å¼¾æ°ã¨å±±è·¯éä¹æ°ãä»åã®WPA2ã®èå¼±æ§ã«ã¤ãã¦ã解説ãè¡ãã¾ããã å·¦ããå°é£¼å¼¾æ°ã山路éä¹æ°ãâ人æ°è¨äºâ ãããã³ã¤ã³ å²ãããã¨ã¯ ç´ç¨ã ãâä»®æ³é貨ã®ç´ç¨âã«ã¤ãã¦å ¬èªä¼è¨å£«ã«ããããèãã¦ã¿ã ãVALUã®ä¸»å¼µããæ¥æ¬ã®æ²æ³ãåªå ãããããVALUããªã¼ãã¨ã³ã¸ãã¢ã»å°é£¼å¼¾æ°ã«ã·ã¹ãã ã«ã¤ãã¦è²ã èãã¦ã¿ã çºè¦ãããèå¼±æ§ã¯ãåæã«éµã
ç¡ç·LANã®æå·åæè¡ã§ããWPA2ã«ããã¦ããKRACKsãã¨å¼ã°ããèå¼±æ§ãããã¨ã®çºè¡¨ããããã¾ããã æ¬èå¼±æ§ã¯WPA2è¦æ ¼ã®ãåæ©ãæ©è½ã®å®è£ ã«ä¾åããèå¼±æ§ã§ãããããWPA2ããµãã¼ãããåæ©ååããã³ä¸ç¶æ©ååãã¾ã親æ©ååã§ä¸ç¶æ©è½(WBã»WDSç)ããå©ç¨æã«å½±é¿ããããã¾ãã ç¾å¨ãå¼ç¤¾ååã®èª¿æ»ãé²ãã¦ããã対象ååã対çã«ã¤ãã¾ãã¦ã¯éææ å ±ãå ¬éããã¦ããã ãã¾ãã ç¾ç¶å¤æãããã¾ããååã¯ä¸è¨ã®ã¨ããã§ãããã¾ãã (å½å 販売ååã®ã¿è¨è¼ãã¦ããã¾ã)
ã¯ããã« 2017å¹´3æãStruts2ã«ã¾ããã¦ãæ°ããªèå¼±æ§(S2-045ãS2-046)ãè¦ã¤ãããè¤æ°ã®ã¦ã§ããµã¤ãã«ããã¦æ å ±æ¼æ´©çã®è¢«å®³ãçºçãã¾ãããçè ã¯2014å¹´4æï¼ããã3å¹´åï¼ã«ãä¾ãã°ãStrutsãé¿ãããã¨ããè¨äºãæ¸ãã¾ããããä»èªã¿è¿ãã¦ã¿ãã¨ããã調æ»ä¸è¶³ã®ç¶æ ã§æ¸ãã¦ãã¾ã£ããªãã¨æããç¹ãããã¾ããä»åãè¯ãã¿ã¤ãã³ã°ãªã®ã§ããä¸åº¦Struts2ã®ã»ãã¥ãªãã£ã«ã¤ãã¦ãã£ã¨ã¾ã¨ãã¦ã¿ããã¨æãã¾ãã ãªãJavaãªã®ã«ãªã¢ã¼ãããã®ä»»æã®ã³ã¼ãå®è¡(ããããRCE)ãå¯è½ãªã®ã Struts2ã¯Javaã¢ããªã±ã¼ã·ã§ã³ã§ãããJava製ã®ã¢ããªã±ã¼ã·ã§ã³ãµã¼ãä¸ã§åä½ãã¾ããJavaã¯ããããã³ã³ãã¤ã«åã®è¨èªã§ãããããé常ã¯ã©ã³ã¿ã¤ã ã«ããã¦ä»»æã®ã³ã¼ããå®è¡ãããã¨ã¯ã§ãããRCEã¯é£ããã¯ãã§ãã Javaã®ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã§RCEãæ
2024-06-24 DomainObjectããValueObjectãèªåçæããOSSä½ã£ã¦ã¿ã ~ ts-vo-generator~
1æä¸æ¬ã®ãããã§ä¿®æ£ãããWordPressã®æ·±å»ãªèå¼±æ§ãçªãæ»æã横è¡ãã¦ããåé¡ã§ãã»ãã¥ãªãã£ä¼æ¥ã®ç±³Feedjitã¯2æ9æ¥ãåæ¥ã¾ã§ã«Feedjitãææ¡ãã¦ããã ãã§20ãã¾ãã®éå£ãå¥ã ã«æ»æãå±éããæ¹ããããããã¼ã¸ã®ç·æ°ã¯150ä¸ãè¶ ãã¦ããã¨å ±åããã ã»ãã¥ãªãã£ä¼æ¥ã®Sucuriã¯2æ6æ¥ã®æç¹ã§ããããã³ã°éå£ã¯4éå£ãæ¹ããããããã¼ã¸ã¯6ä¸6000ãã¼ã¸ã¨ä¼ãã¦ããããããæ°æ¥ã§äºæ ãä¸å±¤æ·±å»åãã¦ããæ§åããããããã Feedjitã§ã¯ãä»åã®èå¼±æ§ãçºè¦ãã¦ä»¥æ¥ãWordPressãçãæ»æã®æåçãæ¥ä¸æããã¨ææãããWordPressé¢é£ã§ã¯ææªç´ã®èå¼±æ§ãã¨ä½ç½®ä»ããã æªç¨ã横è¡ãã¦ããã®ã¯ãWordPressã1æ26æ¥ã«ãªãªã¼ã¹ããæ´æ°çã®4.7.2ã§ä¿®æ£ããèå¼±æ§ãç¹ã«æ·±å»ãªREST APIã®èå¼±æ§ã«ã¤ãã¦ã¯ã2æ1æ¥ã¾ã§å¾ ã£ã¦ãã
R6250 R6400 R6700 R6900 R7000 R7100LG R7300DST R7900 R8000 D6220 D6400 ã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³ (CWE-77) - CVE-2016-6277 éè¦ãªæ©è½ã«å¯¾ããèªè¨¼æ¬ å¦ã®åé¡ (CWE-306) ã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãª (CWE-352) NETGEAR 製ã®è¤æ°ã®ã«ã¼ã¿ã«ã¯ã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³ã®èå¼±æ§ãåå¨ãã¾ãã LAN å ã®æ»æè 㯠http://<router_IP>/cgi-bin/;COMMAND ã«ã¢ã¯ã»ã¹ãããã¨ã§ãèªè¨¼ãè¦æ±ããããã¨ãªããå½è©²è£½åã®ç®¡çè 権éã§ä»»æã®ã³ãã³ããå®è¡ãããã¨ãå¯è½ã§ãã ã¾ããå½è©²è£½åã«ã¢ã¯ã»ã¹å¯è½ãªã¦ã¼ã¶ããç´°å·¥ããããã¼ã¸ã«ã¢ã¯ã»ã¹ãããã¨ã§ãä¸ã®ãã㪠URL ã¸ã¢ã¯ã»ã¹ãããããçµæã¨ãã¦å½è©²è£½åã®ç®¡çè 権éã§ä»»æã®ã³ãã³ããå®è¡ãããããå¯
--------------------------------------------------------------------- â ï¼ç·æ¥ï¼BIND 9.xã®èå¼±æ§ï¼DNSãµã¼ãã¹ã®åæ¢ï¼ã«ã¤ãã¦ï¼CVE-2016-2776ï¼ - ãã«ãªã¾ã«ãã¼ï¼ãã£ãã·ã¥DNSãµã¼ãã¼ï¼ï¼æ¨©å¨DNSãµã¼ãã¼ã®åæ¹ã対象ã ãã¼ã¸ã§ã³ã¢ãããå¼·ãæ¨å¥¨ - æ ªå¼ä¼ç¤¾æ¥æ¬ã¬ã¸ã¹ããªãµã¼ãã¹ï¼JPRSï¼ åçä½æ 2016/09/28ï¼Wedï¼ æçµæ´æ° 2016/10/03ï¼Monï¼ ï¼PoCãå ¬éãããå±éºæ§ãé«ã¾ã£ã¦ããæ¨ã追å ï¼ --------------------------------------------------------------------- â¼æ¦è¦ BIND 9.xã«ãããå®è£ ä¸ã®ä¸å ·åã«ãããnamedã«å¯¾ããå¤é¨ããã®ãµã¼ã ã¹ä¸è½ï¼DoSï¼æ»æãå¯è½ã¨ãªãèå¼±æ§
æ»æã«å©ç¨ãããå ´åãroot権éã§ä»»æã®ã³ã¼ããå®è¡ããããµã¼ããå¶å¾¡ãããå¯è½æ§ãææããã¦ããã ç±³Oracleåä¸ã®ãªã¼ãã³ã½ã¼ã¹ãã¼ã¿ãã¼ã¹ãMySQLãã«æªè§£æ±ºã®èå¼±æ§ãè¦ã¤ãã£ãã¨ãã¦ãã»ãã¥ãªãã£ç 究è ã9æ12æ¥ã«æ¦ç¥ãã³ã³ã»ããå®è¨¼ã³ã¼ããå ¬éããããµã¤ãã¼æ»æã«å©ç¨ãããå ´åãroot権éã§ä»»æã®ã³ã¼ããå®è¡ããããµã¼ããå¶å¾¡ãããå¯è½æ§ãææããã¦ããã ç 究è ã®Dawid Golunskiæ°ãå ¬éããæ å ±ã«ããã°ãMySQLã®èå¼±æ§ã¯è¤æ°çºè¦ããããä¸ã§ãç¹ã«æ·±å»ãª1件ã«ã¤ãã¦ã¯ããªã¢ã¼ãã®æ»æè ãMySQLã®è¨å®ãã¡ã¤ã«ã«ä¸æ£ãªå 容ãä»è¾¼ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æã«å©ç¨ãããæããããã ãã®èå¼±æ§ã¯ãMySQLã®ææ°çãå«ã5.7ç³»ã5.6ç³»ã5.5ç³»ã®å ¨ãã¼ã¸ã§ã³ã«ãããã©ã«ãã®ç¶æ ã§åå¨ãããç¾æç¹ã§Oracle MySQLãµã¼ãã®èå¼±æ§ä¿®æ£ãããã¯åå¨
ã»ã¨ãã©ã®Linuxã¢ããªã±ã¼ã·ã§ã³ã«ä½¿ããã¦ããGNU Cã©ã¤ãã©ãªã®ãglibcãã«æ·±å»ãªèå¼±æ§ãè¦ã¤ãããç±³Googleã¨Red Hatã®ç 究è ãéçºãããããã2æ16æ¥ã«å ¬éãããã èå¼±æ§ã¯2008å¹´5æã«ãªãªã¼ã¹ãããglibc 2.9以éã®ãã¼ã¸ã§ã³ã«åå¨ãããGoogleã«ããã¨ãglibcã§ãgetaddrinfo()ãã©ã¤ãã©ãªæ©è½ã使ãããéã«ãã¹ã¿ãã¯ãã¼ã¹ã®ãããã¡ãªã¼ãã¼ããã¼ã®èå¼±æ§ãèªçºããããã¨ãå¤æããã®æ©è½ã使ã£ã¦ããã½ããã¦ã§ã¢ã¯ãæ»æè ãå¶å¾¡ãããã¡ã¤ã³åãDNSãµã¼ãããããã¯ä¸éè æ»æãéãã¦èå¼±æ§ãæªç¨ãããæããããã¨ããã Googleã®ç 究è ã¯ãå ã«ãã®åé¡ãçºè¦ãã¦ããRed Hatã®ç 究è ã¨å ±åã§èª¿æ»ãé²ããèå¼±æ§ãçªãã³ã¼ãã®éçºã«æåããã¨ãã¦ããããããã®å ¬éã«åããã¦ãæ»æã«ã¯å©ç¨ã§ããªãã³ã³ã»ããå®è¨¼ã³ã¼ããå ¬éãããã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}