2016å¹´10æ20æ¥ CODE BLUE 2016 Track1 æ©æ¢°å¦ç¿ã§Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ãè¦ã¤ããæ¹æ³Read less
2016å¹´10æ20æ¥ CODE BLUE 2016 Track1 æ©æ¢°å¦ç¿ã§Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ãè¦ã¤ããæ¹æ³Read less
OWASP BWA (Broken Web Applications Project) ãããããããããµã¤ããã¯ãããããã(Badstore,BodgeIt Store,moth,Gruyereãªã©ãªã©)ãããããããªãªã¼ãã³ã½ã¼ã¹ã®ã¢ããªã±ã¼ã·ã§ã³ãå«ã¾ãã¦ããOWASPã®ãã®ããã¸ã§ã¯ãã«ãããã®ãé¸ã¶ã®ããã¿ã¼ãã¨ã UserGuide - owaspbwa - User Guide for the OWASP BWA VM. - OWASP Broken Web Applications Project - Google Project Hosting VirtualBoxã«ã¤ã³ã¹ãã¼ã« ãã¡ã¤ã«ãã¦ã³ãã¼ã 以ä¸ã®ãµã¤ããããææ°ãã¼ã¸ã§ã³ããã¦ã³ãã¼ã OWASP Broken Web Applications Project - Browse Files at Sourc
July Tech Festa 2015ã«ã¦ç»å£ããéã®è³æã§ãã ãªãå¾æ¥ãå°æ²³ãããOpen VASã®CLIæä½ã®è§£èª¬ã«ã¤ãã¦ä»¥ä¸ã®ã¹ã©ã¤ãã追å æ稿ãã¦ããã¾ããï¼ ãããªã¼ã§ã§ããã»ãã¥ãªãã£ãã§ã㯠OpenVAS CLIç·¨ã http://www.slideshare.net/abend_cve_9999_0001/openvas-cli-51048313Read less
輸åºã°ã¬ã¼ãã®RSAæå·ããµãã¼ããã¦ãããã¨ã«èµ·å ããèå¼±æ§FREAKã«é¢ããæ å ±ã«ã¤ãã¦é¢é£æ å ±ãã¾ã¨ãã¾ãã èå¼±æ§æ¦è¦ èå¼±æ§ã®æ¦è¦æ å ±ã¯æ¬¡ã®éãã æ称 FREAK (Factoring attack on RSA-EXPORT Keysã®ç¥) 輸åºã°ã¬ã¼ãæå·ã®å¼·å¶ä½¿ç¨ã«é¢ããå¼ç§° ã¢ã¤ã³ã³ ç¡ã CVE OpenSSLï¼CVE-2015-0204 Appleï¼CVE-2015-1067 Microsoftï¼CVE-2015-1637 çºè¦è å miTLS Inria(ãã©ã³ã¹å½ç«æ å ±å¦èªåå¶å¾¡ç 究æ)ã¨Microsoft Researchã®ååãã¼ã FREAK Attackã®æ¦è¦ ä¸éè æ»æãè¡ãããã¾ã§ã®FREAK Attackã®æµãã¯æ¬¡ã®éãã(3æ6æ¥æ´æ°) MITMã®æ»ææç«æ¡ä»¶ 以ä¸ã®æ¡ä»¶ãæç«ããå ´åãéä¿¡å 容ã®çè´ãæ¹ããã®å½±é¿ãåããå¯è½æ§ãããã æ¥ç¶å ã»
glibcã®gethostbynameç³»é¢æ°ã«èå¼±æ§ã®åå ã¨ãªããã°ãçºè¦ããCVE-2015-0235(GHOST)ã¨å½åãããããã§ããæ¾ç½®ããå ´åã¯ç¸å½å¤ãã®ã¢ããªã±ã¼ã·ã§ã³ããã®èå¼±æ§ã®å½±é¿ãåãããã¨ãäºæ³ããã¾ãã glibc㯠libcã®GNUãã¼ã¸ã§ã³ã§ããlibcã¯ã¢ããªã±ã¼ã·ã§ã³ã§ã¯ãªããäºå®ä¸å ¨ã¦ã®ã¢ããªã±ã¼ã·ã§ã³ãå©ç¨ãã¦ããã©ã¤ãã©ãªã§ããOSã®ä¸ã§ã¯ã«ã¼ãã«ã«æ¬¡ãã§éè¦ãªé¨åã¨è¨ãã¾ããLinuxã·ã¹ãã ã§ã¯(ãã¨ãµã¼ãã¼ç¨éã«ããã¦ã¯)ä¾å¤ãªã glibcã使ããã¦ãã¾ãã ãã® glibcã«å«ã¾ãã gethostbynameç³»é¢æ°ã®å®è£ ã« 2000å¹´é ããåå¨ãããã°ãä»ã«ãªã£ã¦çºè¦ãããCVE-2015-0235 é称 GHOSTã¨å½åããã¾ããããããã¯ã¼ã¯ã§ä½ããã®éä¿¡ãè¡ãã¢ããªã±ã¼ã·ã§ã³ã¯å¿ ãâ»ãã®é¢æ°ã使ç¨ãã¾ãã â»è¿½è¨: åå解決ããµãã¼ã
[English] æçµæ´æ°æ¥: Mon, 16 Jun 2014 18:21:23 +0900 CCS Injection Vulnerability æ¦è¦ OpenSSLã®ChangeCipherSpecã¡ãã»ã¼ã¸ã®å¦çã«æ¬ é¥ãçºè¦ããã¾ããã ãã®èå¼±æ§ãæªç¨ãããå ´åãæå·éä¿¡ã®æ å ±ãæ¼ããããå¯è½æ§ãããã¾ãã ãµã¼ãã¨ã¯ã©ã¤ã¢ã³ãã®ä¸¡æ¹ã«å½±é¿ããããè¿ éãªå¯¾å¿ãæ±ãããã¾ãã æ»ææ¹æ³ã«ã¯å åãªåç¾æ§ããããæ¨çåæ»æçã«å©ç¨ãããå¯è½æ§ã¯é常ã«é«ãã¨èãã¾ãã 対ç åãã³ãããæ´æ°ããªãªã¼ã¹ãããã¨æãããã®ã§ããããã¤ã³ã¹ãã¼ã«ãããã¨ã§å¯¾çã§ãã¾ãã ï¼éææ´æ°ï¼ Ubuntu Debian FreeBSD CentOS Red Hat 5 Red Hat 6 Amazon Linux AMI åå OpenSSLã®ChangeCipherSpecã¡ãã»ã¼ã¸ã®å¦çã«çºè¦
å¿ è¦ãªæ å ±ã¯ http://heartbleed.com/ ã«ã¾ã¨ã¾ã£ã¦ããã®ã§ãããè±èªã ãé·ããã£ã¦äººã®ããã«æçã«ã¾ã¨ãã¦ããã¾ãã ã©ãããã°ããã®ã OpenSSL 1.0.1ã1.0.1fã使ã£ã¦ããªããã°ã»ã¼ã ãã¦ã¯ã¾ãå ´åã«ã¯ãä¸å»ãæ©ããã¼ã¸ã§ã³ã¢ãããã¦ããµã¼ããã¨åèµ·å(ãããã²ã¨ã¯ãµã¼ãã¹åä½ã§ãOKããã ãreloadã§ã¯ã ããªãã¨ã) SSL証ææ¸ã§ãµã¼ããå ¬éãã¦ãããªããç§å¯éµããä½ãç´ãã¦è¨¼ææ¸ãåçºè¡ããéå»ã®è¨¼ææ¸ã失å¹ããã(æ«å°¾ã«é¢é£ãªã³ã¯ãã)ã ãµã¼ããå ¬éãã¦ããªãå ´åããå¤é¨ã¸ã®SSLéä¿¡ãããã°å½±é¿ãåããã®ã§ã詳ããç²¾æ»ããã PFS(perfect forward secrecy)ãå©ç¨ãã¦ããªãå ´åãéå»ã®éä¿¡å 容ã復å·ãããå¯è½æ§ãããããã詳ããç²¾æ»ããã æ¼æ´©ããæ å ±ã®å ·ä½ä¾ã¯ãOpenSSLã®èå¼±æ§ã§æ³å®ããããªã¹ã¯ã¨ãã¦
Webã¢ããªã±ã¼ã·ã§ã³ã«ããã¦JSONãç¨ãã¦ãã©ã¦ã¶ - ãµã¼ãéã§ãã¼ã¿ã®ããåããè¡ããã¨ã¯ãã¯ãæ®éã®ãã¨ã§ããããã®ã¨ãJSONå ã«ç¬¬ä¸è ã«æ¼ãã¦ã¯å°ãæ©å¯æ å ±ãå«ã¾ããå ´åã¯ãå¿ ã X-Content-Type-Options: nosniff ã¬ã¹ãã³ã¹ããããã¤ããããã«ãã¾ããã(ãããæ©å¯æ å ±ãã©ããã«é¢ããããå ¨ã¦ã®ã³ã³ãã³ãã«ã¤ããã»ãããããé¢é£:X-Content-Type-Options: nosniff ã¤ãããªããã¤ã¯æ»ãã°ããã®ã«! - èã£ã±æ¥è¨)ã ä¾ãã°ãæ©å¯æ å ±ãå«ã以ä¸ã®ãããªJSONé åãè¿ããªã½ã¼ã¹(http://example.jp/target.json)ããã£ãã¨ãã¾ãã [ "secret", "data", "is", "here" ] æ»æè ã¯ç½ ãã¼ã¸ãä½æãã以ä¸ã®ããã«JSONé åãvbscriptã¨ãã¦èªã¿è¾¼ã¿ã¾ãããã¡ã
ãUPnPã«èå¼±æ§ãè¦ã¤ãããå±éºã ãã¨ãããã¥ã¼ã¹ããããããªWebãµã¤ãã«æ²è¼ããã¦ãã¾ãããä¾ã«ãã£ã¦ã¾ãä½è¨ã£ã¦ããããåãããªãé¨åãå¤ãã£ãã®ã§ã調ã¹ããã¨ãæ¸ãã¦ããã¾ãã ç®æ¬¡ 1. æ¦è¦2. æ¥æ¬èªãµã¤ãã®æ å ±æº3. ãlibupnpã®èå¼±æ§ãã¯ãUPnPãã±ããã使ã£ããããã¡ãªã¼ãããã¼ã4. ãWANããæ»æå¯è½ãã¨ãããã¥ã¼ã¹ã®æå³5. ãWANããã®SSDPãªã¯ã¨ã¹ããåãä»ãããã«ã¼ã¿ã¼ã¨ã¯ï¼6. ãlibupnpãã¨ãSSDPãªã¯ã¨ã¹ããåãä»ãã¦ãã¾ãèå¼±æ§ãã®é¢ä¿ã«ã¤ãã¦7. ãWANããã®SSDPãåãåããã¨ãèªä½ã®åé¡8. ä½ããã£ããããã¥ã¼ã¹ã«ãªã£ãï¼9. ï¼æï¼ï¼æ¥ã«ãã£ããã¨10. æ¬å½ã®ãã¥ã¼ã¹ã¯ãRapid7ã®ãã¯ã¤ããã¼ãã¼ãã®å ¬é11. ãã¯ã¤ããã¼ãã¼ã®ä¸èº«12. ãããã©ããã¦èå¼±æ§æ å ±ãåºãã®ã13. çµè«ï¼è¦ã¤ãã£ãã®ã¯ãè
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}