ç±³å½ã§è²©å£²ããã¦ããAndroid端æ«ã®ãã¡ã¼ã ã¦ã§ã¢ãã»ãã¥ãªãã£ä¼æ¥ã調ã¹ãçµæãSMSã®æ¬æãé£çµ¡å ãé話履æ´ãªã©ã®æ å ±ãä¸å½ã®ãµã¼ãã«éä¿¡ããã¦ãããã¨ãåãã£ãã ç±³ã¢ãã¤ã«ã»ãã¥ãªãã£ä¼æ¥ã®Kryptowireã¯11æ15æ¥ãç±³å½ã§è²©å£²ããã¦ããè¤æ°ã®Android端æ«ã®ãã¡ã¼ã ã¦ã§ã¢ã«ãã¦ã¼ã¶ã¼ã®å人æ å ±ãåéãã¦è¨±å¯ãªãä¸å½ã®ãµã¼ãã«éä¿¡ããæ©è½ãçµã¿è¾¼ã¾ãã¦ãããã¨ãåãã£ãã¨çºè¡¨ããã Kryptowireã¯ç±³è»ãææ»å½å±åãã®ã¢ãã¤ã«ã»ãã¥ãªãã£ãã¼ã«ãææããä¼æ¥ãå社ã«ããã¨ãç±³å½ã®Amazonãªã©ã®ãããé販ã§è²©å£²ããã¦ããAndroid端æ«ã®ãã¡ã¼ã ã¦ã§ã¢ã®ã³ã¼ãããããã¯ã¼ã¯ãåæããçµæãBLU Products製ã®ç«¯æ«ãªã©ã§ã¦ã¼ã¶ã¼ãéåä¿¡ããSMSã®æ¬æãé£çµ¡å ãé話履æ´ã¨é»è©±çªå·ã端æ«ã®èå¥çªå·ãªã©ã®æ å ±ãåéããã¦ãããã¨ãåãã£ããããããæ å ±ã¯
徳丸ããã«ãæ¨è¦ãé ãã¦å æ ã§ããç«å½é¤¨å¤§å¦ã®ä¸åã§ãã ç§ãããè£è¶³ãã ã»ãã¥ãªãã£ã®åéã§ä»ãæå 端ã§æ´»èºãã¦ããããæ¹ã®ä¸ã«ã¯ãå°ãªãããã大å¦ã§ãå°éå¦æ ¡ã§ãã»ãã¥ãªãã£ã®ãã¨ãå¦ã°ãªãã£ããæ¹ããããã¾ããä¸ã«ã¯ãããããé«æ ¡ãåºã¦ãããã®ä¸çã«å ¥ã£ã¦ããããå ¨ãã®ç¬å¦ã§å¤§å¤é«ãæè¡ã身ã«ã¤ããããæ¹ãããã£ãããã¾ãããªã®ã§ããã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã¯æè¡ããããã°å¦æ´ã¯é¢ä¿ãªããã¨è¨ãããã®ã ã¨æãã¾ãã ã§ãããããããå éã®æ¹ã ã¯ãèªåã§å¤§å¤åªåããã¦ãããã¨ãã¾ããã»ãã¥ãªãã£ã®åé¡ãããã»ã©è¤éã§ãªãã£ãæ代ãããè¤éåããç¾ä»£ã¾ã§ã®çµéããã£ã¨ãªã¢ã«ã¿ã¤ã ã§è¿½ã£ã¦ããããã¨ãããè¨ãã°ãç£ã¾ããæ代ãè¯ãã£ããã¨ããç¹ã¯è¦éããªãã¨æãã¾ããããããã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ãç®æãæ¹ããã®å¢å°è¿½ãã¤ãã®ã¯å¤§å¤ã§ãããã®ããã«ã¯ãåºç¤ãããã£ã¡ãã¨ä½ç³»ç«ã¦ã¦å¦ã°ããã
ä¸çåå½ã§ä¼æ¥ã®ãµã¤ããªã©ã«å¯¾ããå¤é¨ãã大éã®ãã¼ã¿ãéãã¤ãã¦ãµã¼ãã¼ããã¦ã³ããããDDï½ï¼³ï¼ãã£ã¼ãã¹ï¼ãã¨ãããµã¤ãã¼æ»æãç¹°ãè¿ãã¦ããç¯ç½ªçµç¹ããã¦ã¼ããã¼ã«ï¼ã¨ã¼ãããåäºè¦å¯æ©æ§ã«æçºããã¦ãããã¨ãåããã¾ãããè¦å¯åºã«ããã¾ãã¨ãå½å ã®ä¼æ¥ãæ»æãåããæ¥æ¬ã®è¦å¯ãææ»ã«ååãã¦ããã¨ãããã¨ã§ãã å½å ã§ããå»å¹´ï¼æ以éãæ±äº¬é½å ã«æ¬ç¤¾ãããéè¡ã証å¸ä¼ç¤¾ãªã©ãããï¼ï¼ã®ä¼æ¥ãåãæå£ã®ãµã¤ãã¼æ»æãåããè¦è¦åºãæ»æã«ä½¿ããããµã¼ãã¼ã®éä¿¡è¨é²ã解æãã¦ãã¦ã¼ããã¼ã«ã«æ å ±æä¾ãããªã©ãææ»ã«ååãã¦ããã¨ãããã¨ã§ãã ã¦ã¼ããã¼ã«ã¯ããã¹ãã¢ã»ãã«ãã§ã´ããã§ãç¯ç½ªçµç¹ã®ä¸»è¦ã¡ã³ãã¼ãç¹å®ãã容çè ï¼äººãæ¤æããã¨çºè¡¨ãã¾ããã è¦å¯å½å±ã¯ã¦ã¼ããã¼ã«ãªã©ã¨é£æºãã¦å½å ã®äºä»¶ã®å®æ 解æãé²ããã¨ã¨ãã«ãä¼æ¥ã«å¯¾ããã»ãã¥ãªãã£ã¼å¯¾çãå¼·åãããã被害ã«ãã£ãå ´
åºä¼ãç³»ãµã¤ãéå¶è ã¨ç¹ããã®ããæ¹ããç´æ¥è©±ãèããã¨ãã§ãã¾ããã ææããªããªãããåºæ¥ãã ãå½äºè å´ããã®ç®ç·ã§è§£èª¬ãããã¨æãã¾ãã å ã«è¨ãã¾ãããæ¬ä»¶ã¯åºä¼ãç³»ãµã¤ãèªèº«ã被害è ã§ãããã¾ãã®ã§ããåºä¼ãç³»ãµã¤ããªãã¦å ¨é¨ãµã¯ã©ãµã¤ãã ã?ãã¿ãããªå å ¥è¦³ããæã¡ã®æ¹ã¯ä¸æ¦æ¨ã¦ã¦é ãã¨ç解ãããããã¨æãã¾ããçã£å½ã«éå¶ããã¦ããåºä¼ãç³»ãµã¤ãã被害è ã§ãã ã¾ãæµåºããã§ãããæ å ±ã¨ã¯ä½ãªã®ã?ãæ®é«ç §ä¼ãã¤ã¤ã«ãã¯ãå¥ç´è ãæã¤å£åº§ã®æ®é«ããé帳ã«ãå°åãããããåå¼æç´°ãé³å£°ã§ç¥ããã¨ãã§ãã¾ããä¾ãã° ã27-11-27 æ¯è¾¼ ãã°ã¿ãã¹ãª *30,000ã ã27-11-30 æ¯è¾¼ ã¤ã½ãã«ã㪠*10,000ã ãã®ãããªå ¥åºéã®åå¼ããé³å£°ã§ç¥ããã¨ãã§ãã¾ãã ãã¡ããå¥ç´è (å¥ç´å£ä½)èªèº«ããã¢ã¯ã»ã¹ã§ããªãã¯ãã®æ å ±ãªããã§ããããã®æ®é«ç §ä¼ãã¤ã¤ã«ã®æ
2018/10/22 å ¨ä½çã«åé¡ããã£ãã®ã§æ¸ãç´ãã. å 容ã¯ã»ã¼å¤ãã£ã¦ããªã. æ¬è¨äºã§ã¯, ä¸çã§æåã«ææ¡ãããå ¬ééµæå·ã§ããRSAæå·ã®åºç¤äºé ã«ã¤ãã¦è§£èª¬ãã. RSAæå·ã®åä½åçã«ã¤ãã¦ç¤ºããå¾, ç°¡åãªæ»æææ³ã®ä¸è¦§ãè¼ãã. å ¬ééµæå· æå·çè«, ç¹ã«ç¾ä»£æå·ã«ãããæå·ã¯ãç§å¯éµæå·(Secret-key Cipher)ã, ãå ¬ééµæå·(Public-key Cipher)ãã®2種é¡ã«å¤§åããã. ç§å¯éµæå·ã¯ããç¥ããã¦ããéããç§å¯ã®éµ$k$ãäºåã«å ±æãã¦ãã, ãã®éµãç¨ãã¦æå·åã»å¾©å·ãè¡ãæå·æ¹å¼ãã§ãã. ããã«å¯¾ãã¦å ¬ééµæå·ã¯ãæå·åã«ç¨ããéµ$k _ {enc}$, 復å·ã«ç¨ããéµ$k _ {dec}$ãåå¨ã, æå·åã»å¾©å·ã®ããããã§ç°ãªãéµãç¨ããæå·æ¹å¼ãã¨å®ç¾©ãã, ãã®ãã¡$k _ {enc}$ã¯ä¸è¬ã«å ¬éããããã¨ãå¤ããã¨
10æããåå人ã®ãã¨ã«ãã¤ãã³ãã¼éç¥ã«ã¼ããå±ããåæã«ãæªãããªåãåããã®é»è©±ãããªãã®ã¨ããã«ãããã£ã¦ãããããããªããå人æ å ±ã¨è²¡ç£ãå®ãããã«æ°ãä»ãã¦ãããããã¨ã ãé£ä¸ã¯çµ¶å¥½ã®ã«ã¢ã ã ããã¾ã¯ãã¤ãã³ãã¼å¶åº¦ã使ã£ã¦ãã©ããªæ¹æ³ã§ä¸å²ãã§ããããçã§ç¥æµãçµã£ã¦ããã¨ãããããã»ã©ãªã¤ã·ã¤æ å ±ã«ç´çµããå¶åº¦ã¯ä»ã¾ã§ãªãã£ããããã å¤å ¸çãªææ³ãããã¾ã£ããæ°ããæå£ã¾ã§ãããããªãã¿ã¼ã³ãåºã¦ãããã ããã¤ãã³ãã¼è©æ¬ºã¯ãééããªãä»å¾ä¸çªã®æµè¡ã«ãªããã æã«å ¥ã£ã¦ããã ããå²ããç®ç®ç¨ãã¦è奮æ°å³ã«èªãã®ã¯ãããã¾ã§ããªã¬ãªã¬è©æ¬ºãéä»éè©æ¬ºãªã©ã«é¢ãã£ã¦ããç¯ç½ªã°ã«ã¼ãã®é¢ä¿è Xæ°ã ã 9æ3æ¥ããã¤ãã³ãã¼æ¹æ£æ³ãè¡è°é¢æ¬ä¼è°ã§æç«ããããããå½æ°ç·èçªå·å¶åº¦ãããããæ¬æ ¼çã«åãåºããã¨ã決ã¾ã£ãã10æããã¯å人çªå·ãç¥ãããéç¥ã«ã¼ãããå¸åºçºæãã
LINEã«ã¦ããline://msg/text/ãã§å§ã¾ãURLãæ¡æ£ããã¦ãã¾ãããã®URLã¯ããæå®ãããæç« ãéä¿¡ããããã®URLãã§ããLINEã§éãããã¿ã³ã®ä¸èº«ã¨ãã¦å©ç¨ããã¦ããURLãªã®ã§ããããã®URLããéä¿¡ã«è³ãã¾ã§ã®ç»é¢é·ç§»ã§ãéä¿¡å 容ã®ç¢ºèªç»é¢ãç¡ãä»æ§ã®ãããèªåãä½ãéä¿¡ããã®ãã確èªã§ããªãã¾ã¾éä¿¡ãã¦ãã¾ããæå³ã¨åããæ稿ãè¡ã£ã¦ãã¾ãå±éºæ§ãããã¾ãã ä½ãéä¿¡ããã®ãã表示ãããªãã¾ã¾å ã«é²ãç»é¢ã®éä¸ã§æ¢ããå¤æãã§ããã°åé¡ã«ã¯ãªããªãã®ã§ãããLINEã®ã¦ã¼ã¶ã¼å±¤ã¨ãå®ééä¿¡ãã¦ãã¾ã£ã人ãå¤æ°è¦ã¤ãããã¨ãããã¦ãã次ããéä¿¡å 容ã®ç¢ºèªç»é¢ãåºãã ãããã¨èãã¦å ã«é²ã人ï¼â以åã®ä»æ§ã§ã¯è¡¨ç¤ºãããï¼ããªã©ãªã©ãèæ ®ããã¨ãä»å¾æªç¨ãããå ´åã«å¤§ããªå±éºãæããããªä»æ§ã§ããã¨æãã¾ããã ä»åã¦ã¼ã¶ã¼ãæå³ããéä¿¡ãã¦ãã¾ãã®ã¯ããã£ã¨åã
å°å·ãã ã¡ã¼ã«ã§éã ããã¹ã HTML é»åæ¸ç± PDF ãã¦ã³ãã¼ã ããã¹ã é»åæ¸ç± PDF ã¯ãªããããè¨äºãMyãã¼ã¸ããèªããã¨ãã§ãã¾ã ååã¯çªå·æ³ã¬ã¤ãã©ã¤ã³ã«è¨è¼ã®æè¡çå®å ¨ç®¡çæªç½®ããæ¨ä»æ¥æ¬å½å ã§èµ·ãã£ã¦ãããæ¨çåæ»æãã«å¯¾ããå ¨ãå¹åã®ãªã対çã®ä¾ç¤ºããè¨åããã¦ããªãç¹ã«ã¤ãã¦è§¦ãããã¾ããã¬ã¤ãã©ã¤ã³èªä½ãä¾ç¤ºããã¹ã¦ã§ã¯ãªããç°å¢ã«å¿ãã¦å¿ è¦ãªå¯¾çãèæ ®ããããä¿ãã¦ãããã¤ã¾ããç¾å¨ã®ã»ãã¥ãªãã£ãªã¹ã¯ã«ç §ããåããã¦èæ ®ããä¼æ¥å´ã®å¤æã§ãã¤ãã³ãã¼ãå®ã£ã¦ãããªããã°ãªããªãã å¾æ¥ã®ãå³ã«å£ããçãªã»ãã¥ãªãã£å¯¾çã§ã¯ãªãããæã«å£ããã®ã»ãã¥ãªãã£æèãæã¤å¿ è¦ããããçªå·æ³ã¬ã¤ãã©ã¤ã³ã®è¦ã¨ãªãæè¡çå®å ¨ç®¡çæªç½®ã®ãå¤é¨ããã®ä¸æ£ã¢ã¯ã»ã¹å¯¾çãã«è¨è¼ããã¦ããä¾ç¤ºã¯ãããã¡ã¤ã¢ã¦ã©ã¼ã«ã®å°å ¥ããã¢ã³ãã¦ã¤ã«ã¹å¯¾çãããããé©ç¨ãã¨ããæä½é
Hacking Teamã®ãªã¼ã¯äºæ¡ãåãã¦ãAdobe FlashPlayerã®èå¼±æ§ãæªç¨ããåããå½å ã§è¤æ°ç¢ºèªããã¾ãããããã§ã¯é¢é£æ å ±ãã¾ã¨ãã¾ãã ãã®ã¾ã¨ããèªãåã« çæ§ã®ä½¿ç¨ããPCã«ã¤ã³ã¹ãã¼ã«ãããFlash Playerãææ°çãã©ãããAdobe社ã®ãã¼ã¸ã§ã³ç¢ºèªãµã¤ãã§ç¢ºèªãè¡ã£ã¦ãã ãããææ°çã§ãªããã°ããã«FlashPlayerã®ã¢ãããã¼ããè¡ã£ã¦ãã ãããã¾ãåããã¦Windows Updateãè¡ããã¦ããã確èªããWindowsãææ°ã®ç¶æ ã«ã¢ãããã¼ããã¦ä¸ããã(Windowsã¯7æ2åã¢ãããã¼ããè¡ããã¦ãã¾ãã) Adobe - Flash Player ãã¼ã¸ã§ã³ç¢ºèª Windowsãåã³OSXã使ç¨ãã¦ããå ´åã2015å¹´7æ21æ¥ç¾å¨ã§ã18.0.0.209ãã¨è¡¨ç¤ºããã¦ããã°ææ°çãå©ç¨ãã¦ããããã®è¨äºã§åãä¸ããæªç¨ã確èªã
æ¬è³æã¯ãweb ã¢ããªã±ã¼ã·ã§ã³ã«ãããèå¼±æ§ã®ã²ã¨ã¤ãCSRF (ã¯ãã¹ãµã¤ããªã¯ã¨ ã¹ããã©ã¼ã¸ã§ãª) ã®ä»çµã¿ã¨ãã®å¯¾çã«é¢ãã説æè³æã§ãã ã¾ããCSRF 対çã®ããã®ã©ã¤ãã©ãªã®ããã¤ãã«ã¤ãã¦ããã®æ¦è¦ã¨é©ç¨ä¾ãç´¹ä»ãã¦ãã¾ãã Webã¢ããªã±ã¼ã·ã§ã³ãä½æããéçºè ã®æ¹ã ããCSRF èå¼±æ§ã«å¯¾ããç解ãæ·±ããããã»ãã¥ã¢ãªWebã¢ããªã±ã¼ã·ã§ã³ã®éçºã®ä¸å©ã¨ãªãã°å¹¸ãã§ãã èªç¿ç¨ã®è³æãåå¼·ä¼ã§ã®è³æã¨ãã¦ãæ´»ç¨ãã ããã - æ¹è¨ç+1: å³çã誤è¨ã®ä¿®æ£ (2015å¹´10æ20æ¥) â» ã³ã¡ã³ããã ãã£ãçæ§ãããã¨ããããã¾ã! - æ¹è¨ç: JPCERT/CC Web ãµã¤ãã«ã¦å ¬é (2015å¹´10æ6æ¥) - åç: OSC2015Hokkaido è¬æ¼è³æ (2015å¹´6æ13æ¥) Read less
2014å¹´10æã«æ±æ¸åã»ãã¥ãªãã£åå¼·ä¼ã§çºè¡¨ããã¦ããã ããè³æããã¼ãã¯ãã»ãã¥ãªãã£æè¡è ã«ãªãã«ã¯ãã§ããRead less
æ¨å¹´ç§ããç¶ãAPTæ»æãBLUE TERMITEã æ¥æ¬å¹´éæ©æ§ã®æ å ±æ¼æ´©äºä»¶ãåããã«ã¹ãã«ã¹ãã¼ã¯6æ4æ¥ãç¾å¨èª¿æ»ä¸ã®æ°ããªAPTæ»æãBLUE TERMITEï¼ãã«ã¼ ã¿ã¼ãã¤ãï¼ãã«ã¤ãã¦èª¬æä¼ãéå¬ãããæ¨å¹´ç§ãããæ¥æ¬ã ãããçããµã¤ãã¼æ»æãçºçãã¦ãããæ¿åºãé²è¡é¢é£ãã¨ãã«ã®ã¼ã製é æ¥ãéèæ©é¢ãå ±éæ©é¢ãªã©å¹ åºã対象ã«æ¨çåæ»æã¡ã¼ã«ãã°ãã¾ããææããçµç¹ããæ©å¯æ å ±ãçã¿åºãã¦ããã¨ããã APTæ»æã¨ã¯ãã¹ãã¤æ´»åãç¯ç½ªæ´»åãç®çã«ãç¹å®ã®ã¿ã¼ã²ããï¼ä¼æ¥ãå人ï¼ã«å¯¾ãã¦æç¶çãã¤å·æãªæ»æãè¡ãæ»æææ³ã§ãããã¡ã¼ã«ã®æ·»ä»ãã¡ã¤ã«ãªã©ãçµç±ãã¦ä¸åº¦ææããã°ãã¿ã¼ã²ããå é¨ã«é·æéæ½ä¼ãã¤ã¤ãå¤é¨ã®C&Cãµã¼ãã¼ï¼æ»ææ令ãµã¼ãã¼ï¼ã¨éä¿¡ãã¦æ°ããªãã«ã¦ã§ã¢ãéãè¾¼ãã ããçµç¹å é¨ã®èª¿æ»ãããããæ©å¯ãã¼ã¿ãçªåãããããæ»æãè¡ãã BLUE TERMIT
ãå®å ¨ãªã¦ã§ããµã¤ãã®ä½ãæ¹ãã¯ãIPAãå±åº(*1)ãåããèå¼±æ§é¢é£æ å ±ãåºã«ãå±åºä»¶æ°ã®å¤ãã£ãèå¼±æ§ãæ»æã«ããå½±é¿åº¦ã大ããèå¼±æ§ãåãä¸ããã¦ã§ããµã¤ãéçºè ãéå¶è ãé©åãªã»ãã¥ãªãã£ãèæ ®ããã¦ã§ããµã¤ããä½æããããã®è³æã§ãã ãå®å ¨ãªã¦ã§ããµã¤ãã®ä½ãæ¹ãæ¹è¨ç¬¬7çã®å 容 第1ç« ã§ã¯ããã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£å®è£ ãã¨ãã¦ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ ãOSã³ãã³ãã»ã¤ã³ã¸ã§ã¯ã·ã§ã³ ãã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã° ç11種é¡ã®èå¼±æ§ãåãä¸ããããããã®èå¼±æ§ã§çºçãããè å¨ãç¹ã«æ³¨æãå¿ è¦ãªã¦ã§ããµã¤ãã®ç¹å¾´çã解説ããèå¼±æ§ã®åå ãã®ãã®ããªããæ ¹æ¬çãªè§£æ±ºçãæ»æã«ããå½±é¿ã®ä½æ¸ãæå¾ ã§ãã対çã示ãã¦ãã¾ãã 第2ç« ã§ã¯ããã¦ã§ããµã¤ãã®å®å ¨æ§åä¸ã®ããã®åãçµã¿ãã¨ãã¦ãã¦ã§ããµã¼ãã®éç¨ã«é¢ãã対çãã¦ã§ããµã¤ãã«ããããã¹ã¯ã¼ãã®åæ±ãã«é¢ã
æªç¨ãããå ´åãæ»æè ãã²ã¹ãä»®æ³ãã·ã³ï¼VMï¼ããæãåºãã¦ãã¹ãã·ã¹ãã ã«ã¢ã¯ã»ã¹ããä»»æã®ã³ã¼ããå®è¡ã§ãã¦ãã¾ãæããããããã¹ãã·ã¹ãã ã®ä»ã«ããã®ãã¹ãä¸ã§å®è¡ããã¦ããä»ã®å ¨ã¦ã®VMã«ã¢ã¯ã»ã¹ã§ãã¦ãã¾ãå¯è½æ§ãããã¨ããã ãã®èå¼±æ§ã¯å¹ åºãä»®æ³ãã©ãããã©ã¼ã ã«å½±é¿ãåã³ãããã©ã«ãã®è¨å®ã«å¯¾ãã¦æ»æãéç¨ããä»»æã®ã³ã¼ããå®è¡ãããæããããã¨ããç¹ã§ãéå»ã«è¦ã¤ãã£ãä»ã®VMã¨ã¹ã±ã¼ãã®èå¼±æ§ã¨ã¯ç°ãªãã¨CrowdStrikeã¯ææãæªç¨ãããã°ä¼æ¥ãªã©ã®ç¥ç財ç£ãå人æ å ±ã¨ãã£ãæ å ±ã®æµåºã«ã¤ãªãããããªãã¨è¦åãã¦ããã èå¼±æ§ã¯ãã¤ãã¼ãã¤ã¶ã¼ã®ã³ã¼ããã¼ã¹ã«åå¨ãããã¨ããããã¹ãOSï¼LinuxãWindowsãMac OSï¼ã«é¢ä¿ãªãå½±é¿ãåãããã¾ããã²ã¹ãOSã«ãå·¦å³ãããªãã å½±é¿ãåãããã¨ã確èªããã¦ãããã³ãã¼ã¯QEMUãXen Project
2015å¹´ã¯ãIoTå å¹´ãã¨å¼ã°ãããç±³ã©ã¹ãã¬ã¹ã§éå¬ãããã2015 International CESãï¼CES2015ï¼ã§ãããã¬ããèªåè»ã®ã¹ãã¼ãåã大ããªæ³¨ç®ãéããï¼é¢é£è¨äºï¼ç¬¬1å IoTæ代å°æ¥ããã¬ããèªåè»ã®ã¹ãã¼ãåãè¦ãã¦ããï¼ã IoTï¼Internet of Thingsï¼ã¢ãã®ã¤ã³ã¿ã¼ãããï¼ã¨ã¯ãã¢ãããããã¯ã¼ã¯ã«æ¥ç¶ããããã¨ã«ããçã¾ããæ°ããªä¾¡å¤ããã»ã³ãµã¼ãã¹ãã¼ããã©ã³ãªã©ã®ç«¯æ«ããåéãããã¼ã¿ãæ´»ç¨ãããããããã¯ã¼ã¯ã«æ¥ç¶ãããã¢ããå¶å¾¡ããããããã¨ã§çã¿åºããããµã¼ãã¹ã表ãã IoTã¨ããè¨èèªä½ã¯æ°å¹´åãããã£ãã製é æ¥ã§ã¯æ©å¨ãè¨åã«åãä»ããã»ã³ãµã¼ããã稼åãã¼ã¿ããããçµç±ã§ã¯ã©ã¦ããµã¼ãã¹ãªã©ã«åéããéç¨ãä¿å®ã«çããã¨ãã£ãåãçµã¿ãå§ã¾ã£ã¦ããã2015å¹´ã®ç¹å¾´ã¯å®¶é»ãèªåè»ã¨ãã£ã身è¿ãªã¢ãã«ããã¦ãããããçµ
IPAï¼ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ãçäºé·ï¼è¤æ±ä¸æ£ï¼ã¯ãã¦ã§ããµã¤ãã®éçºè ãéå¶è åãã®ãå®å ¨ãªã¦ã§ããµã¤ãã®ä½ãæ¹ãã«ãã¹ã¯ã¼ããªã¹ãæ»æã¸ã®æªç¨é²æ¢å¯¾ççãæ°ãã«è¿½å ããæ¹è¨ç¬¬7çã2015å¹´3æ12æ¥ï¼æ¨ï¼ããIPAã®ã¦ã§ããµã¤ãã§å ¬éãã¾ããã URLï¼https://www.ipa.go.jp/security/vuln/websecurity.html IPAã§ã¯ãå¿ è¦ãªæè¡çé æ ®ãä¸è¶³ãã¦ããããã«èµ·ããã¦ã§ããµã¤ãã®æ å ±æ¼ãããæ¹ããçãæå³ããªã被害ãé²ããããå®å ¨ãªã¦ã§ããµã¤ãã®ä½ãæ¹ãã2006å¹´ããçºè¡ãã¦ãããããã¾ã§ã«6çãæ°ãã¦ãã¾ãããã®å 容ã«ã¯ãIPAã¸ã®å±åºä»¶æ°ãå¤ãæ»æã«ããå½±é¿åº¦ã大ããã½ããã¦ã§ã¢è£½åãã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã«é¢ããèå¼±æ§é¢é£æ å ±ãåãä¸ããé©åãªã»ãã¥ãªãã£ãèæ ®ãããã¦ã§ããµã¤ãä½æã®ããã®ãã¤ã³ããã¾ã¨ãã¦ãã¾ãã 7ç
ãä¸æ£ãªå ¥åã«å¯¾ãã¦èå¼±æ§ãçºçãããªãããã»ãã¥ãªãã£å¯¾çã¨ãã¦ããªãã¼ã·ã§ã³ãè¡ãããã¢ãããããã°ã©ããªãã»ãã¥ãªãã£å¯¾çã¨ãæ°ã«ãããªããããæ°ã«ãããªã¨ããã®ã¯è¨ãéãã ããã©ãã»ã¨ãã©ã®å ´åã«ããã¦ããªãã®æ¸ãã³ã¼ãã¯ã»ãã¥ãªãã£å¯¾çã®å¿ è¦æ§ã¯ãªãã æ»æè ã®ç´°å·¥ããå ¥åã«ãã£ã¦SQL/HTML/JavaScriptãå£ããã¨ããããã¡ãªã¼ãã¼ããã¼ãçºçããã¨ãããããã£ãèå¼±æ§ã¨å¼ã°ããã»ã¨ãã©ã®ãã®ã¯ãã ã®ãã°ã ãã»ãã¥ãªãã£å¯¾çã£ã¦ããã®ã¯ã³ã¼ãã¨ã¯åãé¢ãããé åã§è¡ãDEPã ã£ããASLRã ã£ããX-Frame-Optionsã ã£ããCSPã ã£ããiframe sandboxã ã£ããããããããã®ãã»ãã¥ãªãã£å¯¾çã ãã³ã¼ãä¸ã§æ¸ãã®ã¯ãã¢ããªã±ã¼ã·ã§ã³ã¨ãã¦æ£ããåä½ããããã®å¦çãã ãã ã ãã¡ããä¾å¤ããããããããªããã©ãããã¯ããã¾ã§ãä¾å¤ã ãæ¥å¸¸çã«æ¸ã
1. Attacking against 5 million SSH public keys å¶ç¶ã«ã500ä¸åã® SSHå ¬ééµã æã«å ¥ãã俺ãã¡ã¯ hnw æ±æ¸åã»ãã¥ãªãã£åå¼·ä¼ (2015/1/24)çºè¡¨è³æ
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}