ä¸çä¸ã®ã¸ã£ã¼ããªã¹ããã»ãã¥ãªãã£é¢é£ã«ææãªäººãããã«ã¯ã¨ãã¯ã¼ãã»ã¹ãã¼ãã³æ°ã®ãããªå é¨åçºè ã¾ã§ãã使ç¨ãã¦ãããç¡æã®ã¡ã¼ã«æå·åã½ããã¦ã§ã¢ããGNU Privacy Guard(GPG)ãã§ãããã®æå·åã½ããã1997å¹´ãããã£ãä¸äººã§éçºãã¦ããã®ãã´ã§ã«ãã¼ã»ã³ããæ°ã§ãå½¼ãç½®ããã¦ããå³ããç¾ç¶ãProPublicaãæããã¦ãã¾ãã The Worldâs Email Encryption Software Relies on One Guy, Who is Going Broke - ProPublica http://www.propublica.org/article/the-worlds-email-encryption-software-relies-on-one-guy-who-is-going-broke ã½ããã¦ã§ã¢ã¨ã³ã¸ãã¢ã®ã³ããæ°ãGPGã®é
å ¨å½ï¼åã®å¥ç¾å¤§å³¶ã®èå³åãã¡ã³ã®çãã¾ããã«ã¡ã¯ããããã®æ¨æ¥ã®ããã°ãè¦ã¦èå³åè²·ã£ã¦ãããã®ã¯ã43000人ãæ¥è¨ªè ããã£ãã®ã«ï¼åæ§ã ãã§ãããããããã¾ã§ã¢ãã£ãªã¨ã¤ãå ±é ¬12åå²ããã¾ãããæ¬æ¥ã¯èå³åè¨å¿µæ¥ãï¼äººãã¦é»ç³ç¼é ã§æ¥½ãã¿ã¾ããããç¾å³ããã£ããGoogle+ã§ãå¥ç¾èå³åãã¡ã³ãã®ã°ã«ã¼ãä½ããã ããããã¦ããã»ã»ã»ãã£ã¨Macã¨iOSä¸çã®ãããããã¤ãã«æ¬æ¥ãããªãã®ã«åºä¼ãã¾ãããAndroidã®ã¬ããYogaã¿ãã¬ããã ããããã®åä½é¨ã楽ãã¾ãã¦ããã ãã¾ãããå ã«æ¸ãã¦ããã¾ãã è©æ¬ºéé!!Kingsoftæ»ã!! ãããããTwitterã§æ©éå çã®æ稿ãè¦ããã¨ãããã¾ããã¨ããã»ã» ä¼éå¸ã®çµ¦é£ã¾ããã¨æ¤æ»H24年度ã¨H25年度ã®ã°ã©ã http://t.co/DQr4s5SZyT â ryugo hayano (@hayano) 2014,
Gunosyãç¸æ²ããç¡ãã¦ã¹ãã¼ããã¥ã¼ã¹ãã¢ã³ãããªã©ãã¬ã¤ããã¸ã§ãªãã£ãçã£ã¦ãã¬ãCMã«å¤§éã®å®£ä¼è²»ãæå ¥ããããã ãã§ã¯æ¾ããªãã¬ã¤ããã¸ã§ãªãã£ã®ã¦ã¼ã¶ã¼ãå¢ãããã®ãè¦ã¦ãã»ã»ã» ãã®ã»ã»ã» ãã®ã»ã»ã» ããã¤ã¾ã§ã!! ãã¬ãCMãå§ããããã¾ããã åºå代çåºããã¬ãå±ã®å¯©æ»ã£ã¦ãã£ããã©ããªã£ã¦ããã®ã§ãããã ãããã³ã¬ãè¦ã㨠ã¬ã¤ããã¸ã§ãªãã£ã©çãä¸!! ãããã¬ã¤ããã¸ã§ãªãã£ã¨ããããããã³ãããã¼ãºã®åä¾çã£ã¦ãã®ãã¨ããå¢ãã§ããããµãªã£ãã¼å¥½ããªæ¹ã¯å¼ã£ããããã§ãããããFacebookãã¼ã¸ã§ã¯ãã¢ãã§é£ããä½æ¦ãæä¸ãããä½ãç¥ããªãæ¹ã ãããããããããã³ã¡ã³ããä»ãã¦ããã¾ãã ãã¦ãHao123ã¨ããã®ã¯ãªã«ãã¨ããã°ãã°ã°ãã°è¢«å®³è ã®æ¨åã®å£°ãå±±ã®ããã«åºã¦ããããã§ããä¸å½ã®æ¤ç´¢ã¨ã³ã¸ã³Baiduï¼ç¾åº¦/ãã¤ãã¥ï¼ãæä¾ãããHao1
æ å ±ã»ãã¥ãªãã£ã«å¯¾ãã社ä¼çãªæ©éã®é«ã¾ããããå 端æè¡ã身ã«ã¤ããããã¨ãã人ãããã ããããã ãæè¡ã身ã«ã¤ããã ãã§ã¯é£ããã®ããã®ä¸çã ãããªãã®ææ§ãåãã質åã¨è§£èª¬ããç´¹ä»ããã ä»åã¯çè ãæ å ±ã»ãã¥ãªãã£æè²ãã³ã³ãã©ã¤ã¢ã³ã¹ã®åèæè²ã®ã»ããã¼ã®ä¸ã§ãæ¯è¼çæéã«ä½è£ã®ããå ´åã«è¡ã£ã¦ãããã¹ããå¹¾ã¤ãç´¹ä»ãã¦ã¿ãããããã¯çè ãå 輩ã«å¦ãã ãã20å¹´è¿ãã«ããã£ã¦å¾ããããç¥è¦ããèãããã®ã ãæ å ±ã»ãã¥ãªãã£ãå¦ã¶ä¸ã§ãå®ã¯å 端æè¡ã身ã«ã¤ãã以ä¸ã«æè»ãªçºæ³åã大åã§ãããé ãæãããããããã®ãã¤ã³ãã解説ãããã ä¾é¡1ï¼ããã«ã¹ã¤ã«ãããã¾ãããã®ã¹ã¤ã«ã®æå¹æ´»ç¨æ³ã2åéã§æä½30åè¨è¼ããªããï¼ãã ããé£ã¹ããã¯ç¡å¹ã¨ããï¼ã ããã¯ãããã¢ããè¦ãéã«å¤é¢çã«æèããããã®è¨ç·´ãç®çã¨ãã¦ããã4ç§ã«1ã¤ãã¤èããã ããªã®ã§ãæéçãªå¶ç´ã¯ä½ããæ £ãã
1: 風å¹ãã°åç¡ãï¼ ï¼¼(^o^)ï¼ 2014/08/14(æ¨) 12:43:41.62 ID:LqkmWn2C.net 4: 風å¹ãã°åç¡ãï¼ ï¼¼(^o^)ï¼ 2014/08/14(æ¨) 12:44:06.12 ID:nw90inMF.net ï½ï½ï½ï½ï½ï½ï½ï½ï½ï½ï½ï½ 8: 風å¹ãã°åç¡ãï¼ ï¼¼(^o^)ï¼ 2014/08/14(æ¨) 12:45:58.27 ID:boltKdWG.net ã¾ãæ¥æ¬èªããããã㪠12: 風å¹ãã°åç¡ãï¼ ï¼¼(^o^)ï¼ 2014/08/14(æ¨) 12:46:48.32 ID:CYSOml3O.net é示ããªãã å®å®³ã¯ãªãã 15: 風å¹ãã°åç¡ãï¼ ï¼¼(^o^)ï¼ 2014/08/14(æ¨) 12:47:19.08 ID:39tlq13T.net ã©ããã£ãããããªä¼è©±ã«çºå±ãããã⦠16: 風å¹ãã°åç¡ãï¼ ï¼¼(^o^)ï¼ 2014/08/14(
ãã®JPRSã®çºè¡¨ã«å¯¾ãããã®æ¬ é¥ãçºè¦ããä¸äº¬å¤§å¦ã®é´æ¨å¸¸å½¦ææãåéå¹´ç´æ°ã¯ãå±éºæ§ãããç解ãã¦å¯¾çãã¨ãã«ããã£ã¦ååãªæ å ±ãå«ã¾ãã¦ããã¨ã¯ããã¾ããããæ¸å¿µããä¸è¨ã®ããã°è¨äºçã§ãã®åé¡ã®å±éºæ§ã訴ãã¦ãã¾ãã ãã®åé¡ã¯ã¤ã³ã¿ã¼ãããã®æ ¹å¹¹ã«é¢ãããã®ã§ãããã©ããªåé¡ãåãã§ããã®ã§ããããããããç解ããããã«ãã¾ãã¯DNSã®ä»çµã¿ããè¦ã¦è¡ãã¾ãããã DNSã®ä»çµã¿ã¨DNSãã£ãã·ã¥ãµã¼ãDNSã¨ã¯ã¤ã³ã¿ã¼ãããã®æ ¹å¹¹ã«é¢ããä»çµã¿ã§ãç®çã®ãµã¼ãã«ã¢ã¯ã»ã¹ããçºã®éè¦ãªå½¹å²ãæã¡ã¾ããç°¡åã«èª¬æããã¨ã"http://www.example.jp"ã¨ããURLã®ãµã¤ããè¦ããå ´åãããã管çãããµã¼ãã®ã¤ã³ã¿ã¼ãããä¸ã®ä½æï¼IPã¢ãã¬ã¹ï¼ãå¿ è¦ã«ãªãã¾ããããã§ãDNSãµã¼ãã«ä¸è¨URLã®ã©ãã«ï¼ãã¡ã¤ã³ï¼ã«ç¸å½ãã"www.example.jp"ã管çãããµã¼
Mixiã2æ28æ¥ã«ä¸æ£ãã°ã¤ã³ã®çºçã«ã¤ãã¦éè¦ãªãç¥ãããæ²è¼ãã¾ãããããã§ã¯2æ28æ¥ã«çºçããã¨æãããMixiã®ä¸æ£ãã°ã¤ã³ã«é¢ããæ å ±ã«ã¤ãã¦èª¿ã¹ãå 容ã«ã¤ãã¦ã¾ã¨ãã¾ãã Mixiã§ä¸æ£ãã°ã¤ã³ãç«ã¦ç¶ãã«çºç Mixiã®ä¸æ£ãã°ã¤ã³ã¯2æä¸æ¬(2æ5æ¥ã10æ¥)ã«ãçºçãã¦ããããã§æåãç¥ãããè¦ãã¨ãã¯å æ¥å ±ãããã¦ããã«é¢ããç¶å ±ãªã®ãã¨æã£ã¦ããã®ã§ãããå 容ã確èªããã¨ä»æ¥ç¢ºèªãããä¸æ£ãã°ã¤ã³ã«ã¤ãã¦ã®ãç¥ããã§ããã mixiã¸ã®ä¸æ£ãã°ã¤ã³ã«é¢ãããç¥ãã å¤é¨ããã®ä¸æ£ãã°ã¤ã³ã«ã¤ãã¦(Mixiå åç¥) èå³æ·±ããã¨ã«2æä¸æ¬ã¯370件(å ±éãã¼ã¹)ã ã£ãã®ã§ãããä»åã®ä¸æ£ãã°ã¤ã³è¢«å®³ãåããã¦ã¼ã¶ã¼ã¯2æ28æ¥17ææç¹ã§16,972件ã¨ãªã£ã¦ãããããã«ä¸æ£ãã°ã¤ã³ãåããæéã2æ45åã14æã¨åæ¥ã«æºããªãçæéã®éã«è¡ããããã®ã¨ãªã£ã¦ã
JVNãJPCERT/CCã®è¨äºããã¾ãã«ãããã£ã¨æ¸ããã¦ãã¦ãå ·ä½çãªãªã¹ã¯ãæ³åãã¥ããã¨æãã®ã§èª¬æãã¾ãã ä»åç£æ¥ (ä»ãã¥ã¼ã¹è¦ã¦æ¥ãããä¸è¡ã§æãã¦æ¬²ããã¨ãã人åãã®ã¾ã¨ã) ã¤ã³ã¿ã¼ãããä¸ã®ãæå·åãã«ä½¿ããã¦ããOpenSSLã¨ããã½ããã¦ã§ã¢ã2å¹´éå£ãã¦ãã¾ããã ãã®ã½ããã¦ã§ã¢ã¯ä¾¿å©ãªã®ã§ãFacebookã ã¨ãYouTubeã ã¨ãããã¡ãã¡ã®ã¦ã§ããµã¤ãã§ä½¿ã£ã¦ãã¾ããã ä»ã®äººã®å ¥åããIDã¨ããã¹ã¯ã¼ãã¨ãã¯ã¬ã«çªå·ã¨ãããæªã人ãè¦ããã¨ãã§ãã¦ãã¾ãã¾ãã(å®éã«æ¼ãã¦ãä¾) ä»ã«ãè²ã æ¼ãã¦ã¾ãããã¨ããããã¨ã³ã¸ãã¢ä»¥å¤ã®äººãè¦ãã¦ããã¹ãã¯ããã¾ã§ã§OKã§ããããå°ãåãããããæ å ±ã以ä¸ã«ããã¾ãã OpenSSL ã®èå¼±æ§ã«å¯¾ãããã¦ã§ããµã¤ãå©ç¨è ï¼ä¸è¬ã¦ã¼ã¶ï¼ã®å¯¾å¿ã«ã¤ã㦠ã¾ã ç´ã£ã¦ããªãã¦ã§ããµã¤ããããã°ãå ã å£ãã¦ããªãã¦ã§ã
å¿ è¦ãªæ å ±ã¯ http://heartbleed.com/ ã«ã¾ã¨ã¾ã£ã¦ããã®ã§ãããè±èªã ãé·ããã£ã¦äººã®ããã«æçã«ã¾ã¨ãã¦ããã¾ãã ã©ãããã°ããã®ã OpenSSL 1.0.1ã1.0.1fã使ã£ã¦ããªããã°ã»ã¼ã ãã¦ã¯ã¾ãå ´åã«ã¯ãä¸å»ãæ©ããã¼ã¸ã§ã³ã¢ãããã¦ããµã¼ããã¨åèµ·å(ãããã²ã¨ã¯ãµã¼ãã¹åä½ã§ãOKããã ãreloadã§ã¯ã ããªãã¨ã) SSL証ææ¸ã§ãµã¼ããå ¬éãã¦ãããªããç§å¯éµããä½ãç´ãã¦è¨¼ææ¸ãåçºè¡ããéå»ã®è¨¼ææ¸ã失å¹ããã(æ«å°¾ã«é¢é£ãªã³ã¯ãã)ã ãµã¼ããå ¬éãã¦ããªãå ´åããå¤é¨ã¸ã®SSLéä¿¡ãããã°å½±é¿ãåããã®ã§ã詳ããç²¾æ»ããã PFS(perfect forward secrecy)ãå©ç¨ãã¦ããªãå ´åãéå»ã®éä¿¡å 容ã復å·ãããå¯è½æ§ãããããã詳ããç²¾æ»ããã æ¼æ´©ããæ å ±ã®å ·ä½ä¾ã¯ãOpenSSLã®èå¼±æ§ã§æ³å®ããããªã¹ã¯ã¨ãã¦
ä¸è±UFJãã³ã¹ã®Webãµã¤ããä¸æ£ã¢ã¯ã»ã¹ãåããä¼å¡æ å ±ãä¸æ£ã«é²è¦§ãããã¨çºè¡¨ãã¾ãããããã§ã¯é¢é£ããæ å ±ãã¾ã¨ãã¾ãã æ¦è¦ 2014å¹´4æ11æ¥ã«ä¸è±UFJãã³ã¹ãèªç¤¾Webãµã¤ãã§ä¸æ£ãªã¢ã¯ã»ã¹ãæ¤ç¥ããWebãµã¤ããåæ¢ããã®å¾è©³ç´°ãªèª¿æ»çµæã¨ãã¦ã4æ18æ¥ã«ç¬¬3å ±ãå ¬éããããã§OpenSSLã®èå¼±æ§(æããCVE-2014-0160)ãæªç¨ããä¸æ£ã¢ã¯ã»ã¹ã§ãã£ããã¨ãå ±åã ä¸è±UFJãã³ã¹ã®ä¸æ£ã¢ã¯ã»ã¹ã«é¢é£ããçºè¡¨ 2014/4/11 å¼ç¤¾Webãµã¤ãã¸ã®ä¸æ£ã¢ã¯ã»ã¹ã«ã¤ãã¦(PDF) 2014/4/12 ä¸æ£ã¢ã¯ã»ã¹ã«ä¼´ãåæ¢ããã¦ããã ããå¼ç¤¾Webãµã¼ãã¹åéã®ãç¥ããã¨ä¼å¡æ§ã¸ã®ãé¡ã(PDF) 2014/4/18 å¼ç¤¾ä¼å¡å°ç¨WEBãµã¼ãã¹ã¸ã®ä¸æ£ã¢ã¯ã»ã¹ã«ããä¸é¨ã®ã客ãã¾æ å ±ãä¸æ£é²è¦§ããã件(PDF) (1) 被害ç¶æ³ ä¸æ£é²è¦§ä¼å¡æ° 894å(
HeartBleed(CVE-2014-0160)é¢ä¿ã®ãªã³ã¯éãèªåã®ã¡ã¢ç¨ãªã®ã§ä¸æ£ç¢ºã§ãã HeartBleedã®å½±é¿å¯¾è±¡ã¨ãªãOpenSSLãã¼ã¸ã§ã³ 以ä¸ã®ãã¼ã¸ã§ã³ãå½±é¿ãåãã¾ããä½ããã·ã¹ãã ã«ãã£ã¦ã¯åå ã¨ãªã£ã¦ããheartbeatæ©è½ãç¡å¹åããã¦ããå ´åãããããããã¼ã¸ã§ã³ãä¸è´ããã ãã§å½è©²èå¼±æ§ã®å½±é¿ãåãããã¯ç¢ºå®ãã¾ããã (1) OpenSSL 1.0.1ç³» ãã¼ã¸ã§ã³å ãªãªã¼ã¹ææ CVE-2014-0160 OpenSSL 1.0.1 2012/03/14 èå¼±æ§ãã OpenSSL 1.0.1a 2012/04/19 èå¼±æ§ãã OpenSSL 1.0.1b 2012/04/26 èå¼±æ§ãã OpenSSL 1.0.1c 2012/05/10 èå¼±æ§ãã OpenSSL 1.0.1d 2013/02/05 èå¼±æ§ãã OpenSSL 1.0.1e
ãµã¤ãã§ã¯ã¬ã¸ããã«ã¼ãçªå·å ¥åãã¦ãéµãããããã大ä¸å¤«ãã¨ããéå»15å¹´ãããã®å®å¿æãæ ¹åºããè¦ããã°ãæ¤åºãããä¸çåå°ã§ãµã¤ã管çè ãéãä¸ãããã¦ãã¾ããããã«ä¼´ããã«ããæ¿åºã¯ç¢ºå®ç³åã®ãµã¼ãã¹ãç·æ¥ééãã¾ããããã®ä»¶ã«é¢ãã¦ãã»ãã¥ãªãã£ã®å°é家Bruce Schneieræ°ï¼Co3社CTOå ¼EFFçäºå ¼ãã¼ãã¼ã大ãã§ãã¼ï¼ã¯ãå£æ» çã10段éè©ä¾¡ã§èããã¨ãããã¯11ã¬ãã«ãã¨éçç«ã¦ã¦å«ãã§ãã¾ãããã®ããã«ä¸å½ã®å ¬å ±ãµã¼ãã¹ãåæ¢ãããé大ãªãã°ã®ååã¯ãHeartbleedããè¡ãå¹ãå¿èã¨ããæå³ã§ããããã®ä½ãã©ãæãã®ããå°ã説æãã¦ããã¾ããæå·éµã®æ¡æã¢ããã«ã®èå¼±æ§ã®æãåºãããã«ããããã§ã»ãã¥ã¢ãªåå¼ããã§ããã®ã¯æå·éä¿¡ãããã³ã«ã®ãSecure Sockets Layer ï¼SSLï¼ãã¨ãã®å¼åãTransport Layer Securit
ç¬å· æç§ æ¥çµãã¸ãã¹å¯ç·¨éé· æ¥çµãã¸ãã¹ãæ¥çµãã³ãã£ã¼ãæ¥çµãã¸ãã¹ã¢ã½ã·ã¨ãªã©ãçµã¦ãæ¥çµãã¸ãã¹ãªã³ã©ã¤ã³éè¨å¾ã¯ãªã³ã©ã¤ã³ç·¨éãã¡ã¤ã³ã®æ¥åã2012å¹´ããã¯æ¥çµBPãã¸ã§ããªã¼çµå¶ç 究æã®ç 究å¡ãå ¼åã ãã®èè ã®è¨äºãè¦ã
å¹³ç´ ã¯æ ªå¼ä¼ç¤¾ã©ã¤ããã¢ã®ãµã¼ãã¹ã ãå©ç¨ããã ããããã¨ããããã¾ãã æè¨åãã¥ã¼ã¹ãµã¤ããBLOGOSãã¯ã 2022å¹´5æ31æ¥ããã¡ã¾ãã¦ã ãµã¼ãã¹ã®æä¾ãçµäºãããã¾ããã ä¸é¨ã®ãªãªã¸ãã«è¨äºã«ã¤ãã¾ãã¦ã¯ã livedoorãã¥ã¼ã¹å ã® ãBLOGOSã®è¨äºä¸è¦§ãããã覧ããã ãã¾ãã é·ãããå©ç¨ããã ãããããã¨ããããã¾ããã ãµã¼ãã¹çµäºã«é¢ãããåãåããã¯ã ä¸è¨ã¾ã§ãé¡ããããã¾ãã ãåãåãã
ã¢ã¹ã¯ã¯ @moscow17 è¦ããããã©ãã·ã¥ã²ã¼ã ã ãã©çµå±PHPã®JSONå½¢å¼ãªãã¼ã¿ã®ããåãã ããé©å½ã«ãããã·ãã¾ãã¦ããã°è²ã è¦ãããããããã POSTããå¼æ°ããã¾ãã«ãå°ãªã(ã¨ãããå¦çã¯ã»ã¨ãã©ãµã¼ãã§ãã£ã¦ã¦ãAPIå©ãã¦çµæå¼ã³åºãç¨åº¦ãå½ç¶ã¨ããã°å½ç¶)ã ããçµé¨å¤ã®æ¹ããã¯â¦ 2013-11-21 16:46:42
ã©ã³ãã³ã°
ãç¥ãã
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}