ãµã¼ãã¹çµäºã®ãç¥ãã NAVERã¾ã¨ãã¯2020å¹´9æ30æ¥ããã¡ã¾ãã¦ãµã¼ãã¹çµäºãããã¾ããã ç´11å¹´éãNAVERã¾ã¨ãããå©ç¨ã»ãæ顧ããã ãèª ã«ãããã¨ããããã¾ããã
OpenSSLã«åã³èå¼±æ§ãMITMæ»æã«ã¤ãªããæãï¼æåã®ãªãªã¼ã¹ãã16å¹´éåå¨ãã¦ããåé¡ãä¿®æ£çã¸ã®ã¢ãããã¼ããæ¨å¥¨ ãªã¼ãã³ã½ã¼ã¹ã®SSL/TLSå®è£ ãOpenSSLãã«ãæ°ãã«è¤æ°ã®èå¼±ï¼ãããããï¼æ§ãçºè¦ããããä¸ã«ã¯MITMæ»æã«ã¤ãªãããããã®ããåé¡ãå«ã¾ãã¦ãããä¿®æ£ç0.9.8zaï¼1.0.0mï¼1.0.1hã¸ã®ã¢ããã°ã¬ã¼ããå¼ã³æãããã¦ããã ãªã¼ãã³ã½ã¼ã¹ã®SSL/TLSå®è£ ãOpenSSLãã«ãæ°ãã«è¤æ°ã®èå¼±ï¼ãããããï¼æ§ãçºè¦ããããä¸ã«ã¯Man-in-the-Middleï¼MITMï¼æ»æã«ãã£ã¦ãæå·åéä¿¡ã®å 容ã第ä¸è ï¼ï¼æ»æè ï¼ãèªã¿åã£ãããæ¹ããããããããã¨ãã§ããæ·±å»ãªèå¼±æ§ãå«ã¾ãã¦ããã éçºå ã®OpenSSLããã¸ã§ã¯ãã¯ç±³å½æéã®2014å¹´6æ5æ¥ãã»ãã¥ãªãã£ã¢ããã¤ã¶ãªãå ¬éãã6ã¤ã®åé¡ãä¿®æ£ãããã¼ã¸ã§ã³0.9.8
ä¸å½ã§ã¯ã2008å¹´8æããç¬å ç¦æ¢æ³ãæ½è¡ããããç¬ç¦æ³ã¯ä¸æ£ãªå¸å ´ç«¶äºãé²æ¢ããå ¬å¹³ãªå¸å ´ç«¶äºãæ ä¿ããããã®æ³å¾ã§ãããå¸å ´çµæ¸ã«ã¨ã£ã¦ã®éè¦æ§ã¯è¨ãã¾ã§ããªãã ä¸å½æ¿åºãå¸å ´çµæ¸ã®æ§ç¯ãææåããã®ã¯1990年代ã®åæã ã£ããã ããå½æä¼æ¥ã«ããå¸å ´ç¬å ãç¥è²¡æ¨©ä¾µå®³ã¯åãç· ã¾ããããã¨ããªãã£ãã è¡é¦æ¿¤æ¿æ¨©ä¸ã§ã¯ãå½é²æ°éããé²ã¿ãå½æä¼æ¥ã«ããå¸å ´ç¬å ã«ãã£ã¦å ¬å¹³ãªå¸å ´ç«¶äºã妨ãããã¦ãããããã¦ãå¤ãã®å¤å½ä¼æ¥ããã¯ä¸å½ã§ç¥ç財ç£æ¨©ã侵害ããã¦ããã¨ããä¸æºãåã£ã¦ãããç¥è²¡æ¨©ã®ä¾µå®³ã¯ä¸å½ã®ç¬ç¦æ³ã®ç¬¬55æ¡ã«æµè§¦ãããã¨ã«ãªã£ã¦ããããä¸å½æ¿åºã®å¯¾çã¯ååã¨ã¯è¨ããªãã ããããç¶æ³ä¸ã§ãä¸å½æ¿åºã¯æ 度ã転æãããããã ãæ¿åºã¯ãã¤ã¯ãã½ãããã¡ã«ã»ãã¹ãã³ããªã©ã®å¤å½ç±ä¼æ¥ãç¬ç¦æ³ã«éåãã¦ããã®ã§ã¯ãªããã¨å¤§ããããªèª¿æ»ã«ä¹ãåºãã¦ãããå¤å½ã¡ãã£ã¢ã§ã¯ãããã¯å¤å½ä¼æ¥
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}