2016å¹´3æ1æ¥(ç¾å°æé)ãOpenSSL ããã¸ã§ã¯ãã¯èå¼±æ§ã®æç§°ãDROWNãããCacheBleedããå«ã8ä»¶ã®èå¼±æ§æ å ±ãå ¬éãããããå½±é¿ãåãããã®ã®ä¿®æ£ãè¡ã£ãææ°çããªãªã¼ã¹ãã¾ãããããã§ã¯é¢é£æ å ±ãã¾ã¨ãã¾ãã èå¼±æ§æ å ±æ¦è¦ 注æåèµ· OpenSSL ã®è¤æ°ã®èå¼±æ§ã«é¢ããæ³¨æåèµ· - JPCERT/CC SSLv2 DROWN Attack - US-CERT OpenSSL Projectã®å ¬éæ å ± Forthcoming OpenSSL releases OpenSSL Security Advisory ï¼»1st March 2016ï¼½ OpenSSL version 1.0.1s published OpenSSL version 1.0.2g published An OpenSSL Userâs Guide to DROWN 2016å¹´3æ1æ¥å ¬
apache ã nginx ã®è¨å®ããããã¨ãããã°ä»¥ä¸ã®æ§ãªè¡ãè¦ããã¨ããã人ãå¤ãã®ã§ã¯ãªãã§ããããã(â» ä¸è¨ã¯ nginx ã®è¨å®ãapache ã®å ´å㯠SSLCipherSuite ã§ãã) ssl_ciphers AES128-SHA:AES256-SHA:RC4-SHA:DES-CBC3-SHA:RC4-MD5; ãããæå·ã¹ã¤ã¼ããæå®ãã¦ããç®æã§ããããã¦ãã®é¨åãããã®ããããªãæååã®ç¾ åãªã®ã§ãããåã£ã¤ãã«ããã¦ä½ãæå®ããããããããããªãã®ã§ãã³ãããã¦ãã¾ã人ãå¤ãããããªãã§ãããããããããç§ãæ°å¹´åã«è¶£å³ã§ TLS 対å¿ã® Web ãµã¼ãã¹ãä½ã£ãæã¯ã³ããã§æ¸ã¾ãã¦ãã¾ããããã®æå·ã¹ã¤ã¼ãã¯ã以ä¸ã®ãã㪠OpenSSL ã®ã³ãã³ãã使ã£ã¦å¯¾å¿ãã¦ããä¸è¦§ãè¦ããã¨ãã§ãã¾ãã $ openssl ciphers -v AES128-SH
1. ã¯ããã«ã æ¨æ¥ OpenSSLã®ãã¼ã¸ã§ã³ã¢ãããã¢ãã¦ã³ã¹ãããï¼ã¤ã®èå¼±æ§ãå ¬éããã¾ããããã¼ã¸ã§ã³ã¢ããã®æ°æ¥åã«OpenSSLã®æ¬¡æãªãªã¼ã¹äºåãã¢ãã¦ã³ã¹ããã¦ãã¾ããããã¡ããã© BlackHat éå¬åæ¥ã«ããããã¨ãããããªããã¾ãé大ãªèå¼±æ§ã®ä¿®æ£ãå ¥ãããããªããã¨ãããããã¦ãã¾ãããèãéãã¦ã¿ãã¨HeatBleedç¨ã®å¤§äºã§ã¯ãªããããã²ã¨å®å¿ã§ãã æ¨æ¥å ¬éãããOpenSSLã®ï¼ã¤ã®èå¼±æ§ã®ãã¡ãTLS ãããã³ã«ãã¦ã³ã°ã¬ã¼ãæ»æ (CVE-2014-3511)ã®ä¿®æ£ãè¦ã¦ããã¨ãããããã¯TLSãããã³ã«ãå¦ã¶ãã顿ã«ãªããªãã¨ãµã¨æãã¤ãã試ãã«ãã®Opensslã®èå¼±æ§ã®è©³ç´°ãTLSãããã³ã«ã®åºç¤ã«åããã¦æ¸ãã¦ã¿ã¾ããã ã¡ãã£ã¨é·ãã§ãããTLSãããã³ã«ã®ä»çµã¿ï¼ã®ä¸é¨ï¼ãç¥ãããæ¹ã¯ãèªã¿ãã ããã 2. OpenSSLã®èå¼±æ§
èæ± ã§ããCCS Injectionèå¼±æ§(CVE-2014-0224)çºè¦ã®çµç·¯ã«ã¤ãã¦ç´¹ä»ãã¾ãã ãã°ã®ç°¡åãªè§£èª¬ OpenSSLããã³ãã·ã§ã¼ã¯ä¸ã«ä¸é©åãªç¶æ ã§ChangeCipherSpecãåçãã¦ãã¾ãã®ãä»åã®ãã°ã§ãã ãã®ãã°ã¯OpenSSLã®æåã®ãªãªã¼ã¹ããåå¨ãã¦ãã¾ããã é常ã®ãã³ãã·ã§ã¼ã¯ã§ã¯ãå³ã®å³ã®ãããªé åºã§ã¡ãã»ã¼ã¸ã交æãã¾ã(RFC5246 The Transport Layer Security (TLS) Protocol Version 1.2 §7.3ãã使)ã ChangeCipherSpecã¯å¿ ããã®ä½ç½®ã§è¡ããã¨ã«ãªã£ã¦ãã¾ããOpenSSLãChangeCipherSpecããã®ã¿ã¤ãã³ã°ã§éä¿¡ãã¾ãããåä¿¡ã¯ä»ã®ã¿ã¤ãã³ã°ã§ãè¡ãããã«ãªã£ã¦ãã¾ããããããæªç¨ãããã¨ã§ãæ»æè ãéä¿¡ãè§£èªã»æ¹ããå¯è½ã§ãã çºè¦ã®å°é£ã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
é害
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}