You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert
IPA/ISECï¼ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ ã»ãã¥ãªãã£ã»ã³ã¿ã¼ï¼ã¯ã æ¿åºãä¼æ¥ã®çµå¶è ãã»ãã¥ãªãã£æ å½è ãªã©ããèªçµç¹ã®æ å ±ã»ãã¥ãªãã£å¯¾çãåä¸ããããã¨ã«å½¹ç«ã¤è³æã¨ãã¦ãä¸ççã«è©ä¾¡ã®é«ãæµ·å¤ã®æ å ±ã»ãã¥ãªãã£é¢é£ææ¸çã®ç¿»è¨³ã»èª¿æ»ç 究ãNRIã»ãã¥ã¢ãã¯ããã¸ã¼ãºï¼æ ªï¼ã¨å ±åã§è¡ãããã®ææãä¸è¬ã«å ¬éãã¦ãã¾ãã ç±³å½å½ç«æ¨æºæè¡ç 究æï¼NIST: National Institute of Standards and Technologyï¼ã®çºè¡ããSP800ã·ãªã¼ãºï¼SP: Special Publicationsï¼ã¨FIPSï¼Federal Information Processing Standardsï¼ã®ä¸ãããæ¥æ¬ã«ããã¦åç §ãããã¼ãºãé«ãã¨æ³å®ãããææ¸ã®ç¿»è¨³ã»ç£ä¿®ãè¡ããå ¬éããã¨ã¨ãã«ãNISTã®ææ¸ä½ç³»ãå 容ã«ã¤ãã¦ãæ¥æ¬ã®å®æ ã«å³ãã解説ãè¡ãã
JPCERT-AT-2018-0009 JPCERT/CC 2018-02-27(æ°è¦) 2018-02-28(æ´æ°) I. æ¦è¦JPCERT/CC ã§ã¯ã2018å¹´2æ21æ¥ãããã 11211/udp ã®éä¿¡ãã¼ãã«å¯¾ããã¢ã¯ã»ã¹ãå¢å ãã¦ãããã¨ããå¤é¨çµç¹ããã®æ å ±æä¾ãããã³ã¤ã³ã¿ã¼ãããå®ç¹è¦³æ¸¬ã·ã¹ãã (TSUBAME) ã®è¦³æ¸¬ãã¼ã¿ãã確èªãã¦ãã¾ããTSUBAME ã«ã¦è¦³æ¸¬ãããã¹ãã£ã³ã¯ãå½è©²éä¿¡ãã¼ãã¸ã®ã¹ãã£ã³ãã±ãããããmemcachedã«å¯¾ãã¦è¡ããã¦ããå¯è½æ§ãèãããã¾ããmemcached ã®è¨å®ã«ãã£ã¦ã¯ãæå³ããã¤ã³ã¿ã¼ãããããã¢ã¯ã»ã¹å¯è½ãªç¶æ ã«ãªã£ã¦ãããã¹ãã£ã³ã«å¿çãã¦ããå¯è½æ§ãããã¾ãããã®ãããªå ´åã«æ»æã®è¸ã¿å°ã«ãããããmemcached ãä¿æããæ å ±ã¸ã¢ã¯ã»ã¹ããããããå¯è½æ§ãããã¾ããJPCERT/CCã§ã¯ãmemcach
1 ãCSRFãã¨ãSession Fixationã ã®è«¸åé¡ã«ã¤ã㦠ç¬ç«è¡æ¿æ³äººç£æ¥æè¡ç·åç 究æ æ å ±ã»ãã¥ãªãã£ç 究ã»ã³ã¿ã¼ é«æ¨ 浩å http://staff.aist.go.jp/takagi.hiromitsu/ æ å ±å¦çæ¨é²æ©æ§ ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ éçºè åãã»ãã¥ãªãã£å®è£ è¬åº§ 2006å¹´2æ28æ¥, 4æ4æ¥ å¾æ¥é å¸è³æ 2 ç®æ¬¡ ⢠åæç¥èã®ç¢ºèª â Webã¢ããªã«ãããã»ãã·ã§ã³è¿½è·¡ã¨èªè¨¼ã®å®è£ æ段 â ã»ãã·ã§ã³ãã¤ã¸ã£ãã¯æ»æã®åçã¨è å¨ â¢ CSRF (Cross-Site Request Forgeries) å¥å: Session Riding â æ´å²ççµç·¯ãåå ãè å¨ãæè¡ç対çãé©æ³ãªåå¨æ¨å®æ段 ⢠Session Fixation â æ´å²ççµç·¯ãåå ãè å¨ãæè¡ç対çãé©æ³ãªåå¨æ¨å®æ段 3 ã»ãã·ã§ã³è¿½è·¡ã¨èªè¨¼ã®å®è£ æ段 ⢠ã»ã
ã¯ã¬ã¸ããã«ã¼ãåå¼ã«ãããã»ãã¥ãªãã£å¯¾çã®å¼·åã«åããå®è¡è¨ç»2017ï¼ãå®è¡è¨ç»2017ãï¼ãåãã¾ã¨ãã¾ããï½å½éæ°´æºã®ã¯ã¬ã¸ããã«ã¼ã決æ¸ç°å¢ã®æ´åãé²ãã¾ãï½ æ¬æ¥ããã¯ã¬ã¸ããåå¼ã»ãã¥ãªãã£å¯¾çåè°ä¼ãï¼äºåå±ï¼ï¼ä¸ç¤¾ï¼æ¥æ¬ã¯ã¬ã¸ããåä¼ï¼ãéå¬ãã2020å¹´ã«åãã¦å½éæ°´æºã®ã¯ã¬ã¸ããã«ã¼ãåå¼ã®ã»ãã¥ãªãã£ç°å¢ãæ´åãããããã¯ã¬ã¸ããã«ã¼ãä¼ç¤¾ãå çåºãã¯ããã¨ããå主ä½ãè¬ãã¹ãæªç½®ãåãã¾ã¨ãããå®è¡è¨ç»ãï¼2016å¹´2æï¼ãæ¹è¨ãããå®è¡è¨ç»2017ãã¨ãã¦çå®ãã¾ããã 1ï¼èæ¯ ã¯ã¬ã¸ããã«ã¼ãã·ã§ããã³ã°ã¯ãæ¶è²»è ã®è³¼å ¥æ©ä¼ãæ¡å¤§ããã¨ã¨ãã«ãåæ»ãªæ±ºæ¸ãå¯è½ã¨ãããã®ãããç¾ä»£ã®æ¶è²»çæ´»ã«ããã¦éè¦ãªå½¹å²ãæ ã£ã¦ãã¾ãã ä»æ¹ãæãå½ã«ããã¦ã¯ãè¿å¹´ãã»ãã¥ãªãã£å¯¾çãä¸ååãªã¯ã¬ã¸ããã«ã¼ãå çåºãçã£ãä¸æ£ã¢ã¯ã»ã¹ã«ãã£ã¦ã«ã¼ãæ å ±ãæ¼ããããäºæ ã
ãããã¬ã¼ã·ã§ã³ã»ãã¹ã¿ã¼ã®æè¡åãè¦ãä¸ã§ããè³æ ¼ããä¸ã¤ã®åºæºã¨ãã¦å©ç¨ããã¦ãã¾ãã æ¥æ¬ã§ã¯ãSANSã®GPEN*1ãGWAPT*2ãä¸çªæåãã¨æãã¾ããããã®è¨äºã§ã¯ç±³å½ã®è³æ ¼äºæ ããç´¹ä»ãããã¨æãã¾ããï¼è©ä¾¡ã«ã¯å人ã®æè¦ãããªãå«ã¾ãã¦ãã¾ãã®ã§ããã®ç¹ã¯ã容赦ãã ãããï¼ ç±³å½ã§ããã¥ã©ã¼ã§ãããããã¬ã¼ã·ã§ã³ã»ãã¹ã¿ã¼ã®è³æ ¼ã¯å¤§ããï¼ç¨®é¡ããã¾ãã CEH : Certified Ethical Hacker GIAC : Global Information Assurance Certification OSCP : Offensive Security Certified Professional CEH : Certified Ethical Hacker ç±³å½ã§ä¸çªããã¥ã©ã¼ãªãããã¬ã¼ã·ã§ã³ã»ãã¹ã¿ã¼ã®è³æ ¼ãããã®CEHã ã¨æãã¾ããç±³å½ã§ã®ã»ãã¥ãªãã£ã»
ãã¹ãã£ã¼ãã¯ãä»®æ³é貨ã§ãéã¹ããªã³ã©ã¤ã³ã«ã¸ãã§ããä»®æ³é貨ã§ã®å ¥éã«ã¯ãBitcoinãEthereumãLitecoinãBitcoin Cashãªã©ã使ç¨ã§ãã¾ããã¾ããåºéãä»®æ³é貨ã§è¡ããã¨ãã§ãã¾ãã ã¾ãããã¹ãã£ã¼ãã§ã¯ãã¹ãããããã¼ãã«ã²ã¼ã ãã©ã¤ãã«ã¸ãããã¼ã«ã¼ããããªãã¼ã«ã¼ããã«ã©ããµã¤ã³ããªã©ãæ§ã ãªãªã³ã©ã¤ã³ã«ã¸ãã²ã¼ã ã楽ããã¾ããããã«ãã¹ãã¼ããã©ã³ãã¿ãã¬ããã§ã®ãã¬ã¤ãå¯è½ã§ãã®ã§ããã¤ã§ãã©ãã§ãã«ã¸ãã²ã¼ã ã楽ãããã¨ãã§ãã¾ãã å®éã«ãã¹ãã£ã¼ãã§éãã§ã¿ãææ³ ãã¹ãã£ã¼ãã§ã¯ãæ°è¦ç»é²ãå ¥éãªã©ã«å¿ãã¦ããã¾ãã¾ãªãã¼ãã¹ãæä¾ããã¦ãã¾ãã æ°è¦ç»é²ãã¼ãã¹ã¨ãã¦ã¯ãå ¥éä¸è¦ã§æã«å ¥ããããªã¼ã¹ãã³ããããã¾ããã¾ããå ¥éãã¼ãã¹ã¨ãã¦ã¯ãå ¥éé¡ã«å¿ãããããããã¼ãã¹ããæä¾ããããã¨ãããã¾ããããã«ããã¬ã¤ã¤ã¼ã®ã¬ãã«ãä¸ã
ãã¹ãã£ã¼ãã¯ãä»®æ³é貨ã§ãéã¹ããªã³ã©ã¤ã³ã«ã¸ãã§ããä»®æ³é貨ã§ã®å ¥éã«ã¯ãBitcoinãEthereumãLitecoinãBitcoin Cashãªã©ã使ç¨ã§ãã¾ããã¾ããåºéãä»®æ³é貨ã§è¡ããã¨ãã§ãã¾ãã ã¾ãããã¹ãã£ã¼ãã§ã¯ãã¹ãããããã¼ãã«ã²ã¼ã ãã©ã¤ãã«ã¸ãããã¼ã«ã¼ããããªãã¼ã«ã¼ããã«ã©ããµã¤ã³ããªã©ãæ§ã ãªãªã³ã©ã¤ã³ã«ã¸ãã²ã¼ã ã楽ããã¾ããããã«ãã¹ãã¼ããã©ã³ãã¿ãã¬ããã§ã®ãã¬ã¤ãå¯è½ã§ãã®ã§ããã¤ã§ãã©ãã§ãã«ã¸ãã²ã¼ã ã楽ãããã¨ãã§ãã¾ãã å®éã«ãã¹ãã£ã¼ãã§éãã§ã¿ãææ³ ãã¹ãã£ã¼ãã§ã¯ãæ°è¦ç»é²ãå ¥éãªã©ã«å¿ãã¦ããã¾ãã¾ãªãã¼ãã¹ãæä¾ããã¦ãã¾ãã æ°è¦ç»é²ãã¼ãã¹ã¨ãã¦ã¯ãå ¥éä¸è¦ã§æã«å ¥ããããªã¼ã¹ãã³ããããã¾ããã¾ããå ¥éãã¼ãã¹ã¨ãã¦ã¯ãå ¥éé¡ã«å¿ãããããããã¼ãã¹ããæä¾ããããã¨ãããã¾ããããã«ããã¬ã¤ã¤ã¼ã®ã¬ãã«ãä¸ã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}