æ°çæ å ± 2024/7/17 CRYPTRECã·ã³ãã¸ã¦ã 2024ã®éå¬ 2024/7/12 CRYPTREC Report 2023ã®å ¬é 2024/7/8 æå·æè¡æ¤è¨ä¼ 2023å¹´åº¦å ±åæ¸ã®å ¬é æ°çæ å ±ä¸è¦§ã¸
Original article:https://dev.to/dotnetsafer/rip-copy-and-paste-from-stackoverflow-trojan-source-solution-4p8f ãã®æã³ããã§ããªãæç« ã¨ãããã®ãããã¾ããã å®éã¯åã«ãã©ã³ããå¤ãã¦ããã ãã¨ãããã®ã§ããã人éã®ç®ã«è¦ããæåã¨å®éã®æåãç°ãªããã¨ãå©ç¨ããæ»æã®ä¸ç¨®ã¨è¦ããã¨ãã§ãã¾ãã ãã¦ãæè¿ã«ãªã£ã¦ä¼¼ããããªæ»æã«é¢ããè«æãå ¬éããã¾ããã 人éã«ã¯è¦ããªãæåãç¹ã交ãããã¨ã«ãã£ã¦ãä¸è¦åé¡ãªãã³ã¼ããå®ã¯èå¼±ã«ãªã£ã¦ãã¾ãã¨ãããã®ã§ãã ãã è«æã¯å è¦ããããã«é·ãã¦èªãã®ãã¤ããã®ã§ãå ·ä½çã«ä½ãã©ããªã®ããããããã¾ããã å¹³æã«è§£èª¬ãã¦ããè¨äºããã£ãã®ã§ç´¹ä»ãã¦ã¿ã¾ãã 以ä¸ã¯Dotnetsafer( Twitter / GitHub / Web
Introduction Java's architecture and components include security mechanisms that can help to protect against hostile, misbehaving, or unsafe code. However, following secure coding best practices is still necessary to avoid bugs that could weaken security and even inadvertently open the very holes that Java's security features were intended to protect against. These bugs could potentially be used t
ãå®è·µï¼ãã»ãã¥ãªãã£ããªã·ã¼éç¨ãã®é£è¼è¨äºä¸è¦§ã§ãã
ãæ å ±ã»ãã¥ãªãã£ããã¸ã¡ã³ãã·ã¹ãã åºç¤è¬åº§ãã®é£è¼è¨äºä¸è¦§ã§ãã
æ å ±ã»ãã¥ãªãã£ã«ä¿ããªã¹ã¯ã®ããã¸ã¡ã³ããå¹æçã«å®æ½ãããããã«ããªã¹ã¯ã¢ã»ã¹ã¡ã³ãã«åºã¥ãé©åãªã³ã³ããã¼ã«ã®æ´åãéç¨ç¶æ³ããæ å ±ã»ãã¥ãªãã£ç£æ»ãè¡ã主ä½ãç¬ç«ãã¤å°éçãªç«å ´ãããå½éçã«ãæ´åæ§ã®ã¨ããåºæºã«å¾ã£ã¦æ¤è¨¼åã¯è©ä¾¡ãããã£ã¦ä¿è¨¼ãä¸ããããã¯å©è¨ãè¡ãæ´»åã
æ¥å¢ãã«é«ã¾ããµã¤ãã¼æ»æã®è å¨ã¯çµå¶ãè ããã対çãæ¥åã ãã¨ã¯ããã対çç¾å ´ã¯äºç®ã人ããã¦ãã¦ã足ããªãã®ãå®æ ããªã¯ã«ã¼ãã°ã«ã¼ãå社ã«ã»ãã¥ãªãã£æ¯æ´ããããã®ä»®æ³çµç¹ãRecruit-CSIRTãã®ã¡ã³ãã¼ããå®è·µçã§å ·ä½çãªã»ãã¥ãªãã£äºæ 対å¿ã®æ¹æ³ã解説ããã ï¼»æçµåï¼½ç¾å ´ããã®æè¬ãCSIRTã®åååãçµå¶å±¤ã®ä¿¡é ¼ã¯äºæ 対å¿ã§åã¡åã ã¤ã³ã·ãã³ã対å¿ãåãä»åãCSIRTã®æ§ç¯ãç¸æ¬¡ãã§ãããæ¬é£è¼ã®æçµåã¨ãªãä»åã¯CSIRTéå¶ã®åæã解説ãããç¾å ´ããã®æè¬ãå¼ãåºãã¦å¤å¿ãªã¡ã³ãã¼ã®ã¢ããã¼ã·ã§ã³ãé«ããçµå¶å¤æã«è³ããé©åãªäºæ å ±åã§çµå¶å±¤ã®ä¿¡é ¼ãå¾ã¦ãããã 2016.11.29 [第19åï¼½åä»ãå¢ãDDoSæ»æãäºæ¥ãªã¹ã¯ã«å¿ãã¦å¯¾çãé¸ã¶ æªæã®ããåãåãããéãä»ãã¦Webãµã¤ãããã¦ã³ãããDoSæ»æãæ£è¦ã®ã¢ã¯ã»ã¹ã¨åºå¥ãã«ããããããæ»æé
Photo by Torkild Retvedt ããã«ã¡ã¯ãå岡([twitter:@yoshiokatsuneo])ã§ãã ãµã¼ã管çã§ä½¿ããªã人ã¯ããªãSSH(OpenSSH)ã§ãããSSHã¯ã©ã¤ã¢ã³ãã§ç§å¯éµãæ¼æ´©ãã å¯è½æ§ã®ããèå¼±æ§(CVE-2016-0777)ãçºè¦ããã¦ãã¾ãã åãã³ãã¼ãããªãªã¼ã¹ãããã¢ãããã¼ããé©ç¨ãã¦ããã ãã®ã§ãããã¾ã ã¢ãããã¼ãããªãªã¼ã¹ ããã¦ããªãç°å¢ãå¤ãã§ãã ãã®ãããªå ´åãå«ãã¦ãçµè«ããè¨ãã¨ã以ä¸ã®ã³ãã³ããSSHã¯ã©ã¤ã¢ã³ãã§ã«ã¼ã権éã§å®è¡ãããã¨ã§ãèå¼±æ§ã¯åé¿ã§ãã¾ãã # echo -e '\nHost *\nUseRoaming no' >> /etc/ssh/ssh_config ã«ã¼ã権éã§ä¸è¨ã³ãã³ããå®è¡ã§ããªãå ´åã以ä¸ã®ããã«ã¦ã¼ã¶åä½ã®è¨å®ãå¤æ´ãã¾ãã $ echo -e '\nHost *\n
IPAï¼ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ãçäºé·ï¼è¤æ± ä¸æ£ï¼ã¯ã2016å¹´1æ12æ¥ï¼ç±³å½æéï¼ãéãã㨠Microsoft 社ã®ã¦ã§ããã©ã¦ã¶ãInternet Explorerãï¼ä»¥å¾ãIEï¼ã®ãµãã¼ãããªã·ã¼ãå¤æ´ããããã¨ãããä¸è¬å©ç¨è ãçµç¹ã®ã·ã¹ãã æ å½è ãã«å¯¾ããææ°çã¸ã®ãã¼ã¸ã§ã³ã¢ããå®æ½ãä¿ãããããµãã¼ãçµäºã¾ã§1ã¶æãåã£ãæ¬æ¥ã注æãåèµ·ãããã¨ã¨ãã¾ããã 2016å¹´1æ12æ¥ï¼ç±³å½æéï¼ãéãã㨠Microsoft 社ãæä¾ãã IE ã®ãµãã¼ã対象ãâå Windows OSã§å©ç¨å¯è½ãªææ°çã®ã¿âã«ããªã·ã¼ãå¤æ´ããã¾ã(*1)ããµãã¼ã対象å¤ã¨ãªã IE ã¯ãã»ãã¥ãªãã£æ´æ°ããã°ã©ã ãæä¾ãããªããªããããæ°ããªèå¼±æ§ãçºè¦ããã¦ã解æ¶ãããã¨ãã§ãã¾ãããèå¼±æ§ãè¦ã¤ããæ»æè ããããæªç¨ããã¨ãã¦ã¤ã«ã¹ææã«ããããã©ã¦ã¶ãæ£å¸¸ã«å©ç¨ã§ããªããªã
ãããä¸ãé¨ããããã¨ãè¨æ¶ã«æ°ããããã¡ã¤ã«ã®æ¡å¼µåããã¹ã¦ã.vvvãã«å¤ãã¦ãã¾ãã¦ã¤ã«ã¹ãã»ãã¥ãªãã£ä¼æ¥ãã¬ã³ããã¤ã¯ã社ã«ããã¨ããã®ã¦ã¤ã«ã¹ã¯ç¹ã«æ¥æ¬ãçã£ããã®ã§ã¯ãªããæ¥æ¬ã¸ã®æµå ¥ã¯éå®çã¨ãã¦ãã¾ãããã12æ11æ¥ä»ã§æ´æ°ãããããã°ã«ã¦ããã®æå£ã«é¢é£ããä¸æ£URLã®ãããã¯æ°ãå½å ã§æ¥å¢ãã¦ãããæ¥æ¬ã«ãããç¸å½æ°ã®æµå ¥ã確èªãããã¨ãæããã«ãã¾ããã ãã«ã¦ã§ã¢ã¹ãã ã«æ·»ä»ã® JavaScriptãã¡ã¤ã«ãå®è¡ããéã«ã¢ã¯ã»ã¹ãããä¸æ£URL ãããã¯æ°æ¨ç§»ï¼ãã¬ã³ããã¤ã¯ãããã°ããï¼ ä¸è¬ã«ãvvvã¦ã¤ã«ã¹ãã¨å¼ã°ãã¦ãã¾ãããå社ã«ããã°æå·ååã©ã³ãµã ã¦ã§ã¢ãCrypTeslaãã®äºç¨®ã¨ã®ãã¨ããªããã©ã³ãµã ã¦ã§ã¢ãCrypTeslaããæ¡æ£ããããã«ã¦ã§ã¢ã¹ãã ã¯JavaScriptãã¡ã¤ã«ãæ·»ä»ãã¦ããã12æ11æ¥ã¾ã§ã®ç´¯ç©ã§11ä¸é以ä¸ã®æ¡æ£ã
3rdã«å¼ã£è¶ãã¾ããã 2010/12/31 以åï¼2023/1/1 以éã®è¨äºãéãã¨ï¼ç§å¾ã«ãªãã¤ã¬ã¯ãããã¾ãã æ®æ®µã®æ¥è¨ã¯ ãã£ã¡[http://thyrving.livedoor.biz/] ãã¡ãã«ã¯æè¡é¢ä¿ã®ã¡ãã£ã¨ããã¢ãã¯ãªè¨äºããã¥ã¼ã¹ãè¼ãã¾ãã Windows2000ãã¿ä¸å¿ã«æ¯æ¥æ´æ°ã
What Do WebLogic, WebSphere, JBoss, Jenkins, OpenNMS, and Your Application Have in Common? This Vulnerability. What? The most underrated, underhyped vulnerability of 2015 has recently come to my attention, and Iâm about to bring it to yours. No one gave it a fancy name, there were no press releases, nobody called Mandiant to come put out the fires. In fact, even though proof of concept code was re
ä¸å½ã®æ¤ç´¢ã¨ã³ã¸ã³ãç¾åº¦ï¼Baiduï¼ãã®ã½ããã¦ã§ã¢éçºãããï¼Software Develoment KitãSDKï¼ãMoplusãã«ãWormholeãã¨å¼ã°ããèå¼±æ§ã確èªããããã®èå¼±æ§ãå©ç¨ãããå ´åã®å½±é¿ã®æ·±å»ãããã«æ³¢ç´ãå¼ãã§ãã¾ãããã®èå¼±æ§ã¯ãä¸å½ã®èå¼±æ§å ±åãã©ãããã¼ã ãWooYun.ogãã«ãã確èªããã¾ããã ããããªããããã¬ã³ããã¤ã¯ãããã®èå¼±æ§ã«ã¤ãã¦èª¿æ»ãé²ããã¨ãããMoplus SDK èªä½ã«ããã¯ãã¢æ©è½ãåãã£ã¦ãããå¿ ããããããèå¼±æ§ã«ç±æ¥ã¾ãã¯é¢é£ãã¦ããããã§ã¯ãªããã¨ãæããã«ãªãã¾ãããç¾æç¹ã§ããã®åé¡ã¯ Moplus SDK ã®ã¢ã¯ã»ã¹è¨±å¯å¶å¾¡ã¨ã¢ã¯ã»ã¹ã®å¶éæ¹æ³ã«ããã¨è¦ããã¦ãã¾ãããã®ãããèå¼±æ§ãé¢ä¿ãã¦ããã¨èãããã¦ããã®ã§ãããå®éã«ã¯ããã® SDK ã®ããã¯ãã¢æ©è½ã«ãããã¦ã¼ã¶æ¨©éãªãã«ä»¥ä¸ãå®è¡ããæãã
å¤ãWebãã©ã¦ã¶ã¼ããã£ã¼ãã£ã¼ãã©ã³ï¼ã¬ã©ã±ã¼ï¼ã使ã£ã¦ãã顧客ã¯ãECãµã¤ãã§ã¯ã¬ã¸ããã«ã¼ãçªå·ãå ¥åã§ããªããªãââã 2016å¹´7æã«æ¬æ ¼é©ç¨ãããã¯ã¬ã¸ããã«ã¼ãæ å ±ä¿è·ã®ã»ãã¥ãªãã£å½éåºæºãPCI DSSï¼Payment Card Industry Data Security Standardï¼ v3.1ããããããECãµã¤ãäºæ¥è ããåçºã®å£°ãé«ã¾ã£ã¦ãããä¸é¨ã®é¡§å®¢ãECãµã¤ãã§ã¯ã¬ã¸ããã«ã¼ãçªå·ãå ¥åã§ããªããªãããµã¤ãã®å£²ãä¸ããæ¼ãä¸ããå¯è½æ§ãããããã ã åºæºçå®å£ä½ã®PCI SSCï¼Payment Card Industry Security Standards Councilï¼ããåçºã®å£°ãæ³å®å¤ã«å¤ããã¨ãããæ¬èªã®åæã«å¯¾ãã¦ãv 3.1ãããããå½±é¿ã®å®æ 調æ»ã«ä¹ãåºããï¼PCI SSC ã¤ã³ã¿ã¼ãã·ã§ãã«ãã£ã¬ã¯ã¿ã¼ã®ã¸ã§ã¬ãã¼ã»ãã³ã°æ°ï¼èã
ãä»æã®å¼ã³ãããä¸è¦§ãè¦ã 第15-17-342å· æ²è¼æ¥ï¼2015å¹´ 11æ 4æ¥ ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ æè¡æ¬é¨ãã»ãã¥ãªãã£ã»ã³ã¿ã¼ (PDFã¯ãã¡ã) IPAã«ãå人ããã®åéãªã¯ã¨ã¹ãã¨æããã¡ã¼ã«ãå±ããã®ã§æ¿èªãããããèªåã®å義ã§åæ§ã®åéãªã¯ã¨ã¹ãã®ã¡ã¼ã«ãã°ãã¾ãããããã ãã¨ããç¸è«ãã5æ以éå¯ããããããã«ãªãã¾ãããåæ§ã®ç¸è«ã¯8æ以éå¢ãã¯ããã10æã«ã¯52件ã¨åæã®5åè¿ãã¾ã§æ¥å¢ãã¾ãããï¼*1ï¼ã¾ããJPCERTã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ï¼JPCERT/CCï¼ã«ããã°ãèªçµç¹ã称ããã¡ã¼ã«ãéä¿¡ããã¦ããã¨ãã被害ã«ã¤ãã¦æ å ±å ¬éããçµç¹ãè¤æ°ç¢ºèªããã¦ãã¾ããï¼*2ï¼ ç¸è«ã«ããã¨ããã®åéãªã¯ã¨ã¹ãã¯æµ·å¤SNSã®æå¾ ã¡ã¼ã«ã§ãããç¸è«è ã®Googleã¢ã«ã¦ã³ãã«ç»é²ããã¦ããé£çµ¡å ã«éããã¦ãã¾ããããã®åå ã¯ãç¸è«è ãèªåã«å±ããåéãª
ä¼è¤ãã@éé @kingyo_roma ç§ã¯å ã¹ãã¼ã«ã¼ã§ãããã¾ããã¹ãã¼ãã³ã°ããããããããªããã ãã©ã¹ãã¼ãã³ã°ä»¥å¤ã«ææ 表ç¾ããããªãâã£ã¦ãããã¡ã®æªãã¹ãã¼ã«ã¼ã§ãããéå»ããéå»ã ä½æã¨ãè·å ´ã¨ãé»è©±çªå·ã¨ã家ææ§æå¯ãæé好ããªãã®ãå ¨é¨èª¿ã¹ãã®å¾æã§ãã ã§ãæ¨æ¥ã®å¤ãµã¨æãç«ã£ãã 2015-06-20 12:51:56 ä¼è¤ãã@éé @kingyo_roma 絡ã¿ãããããã§ã¯ãªããã©ãTLã§ãã¾ã«è¦ããã人ã§ãåä¾ã®åçãæãã£ããæãã¦ã人ããã¦â¦ ãã®äººã®ãã¨ãã¤ã³ã¿ã¼ãããã ãã使ã£ã¦ãã©ãã ã調ã¹ãããããªãï¼ã¨ã試ãã¦ã¿ã¾ããã çµæ⦠2015-06-20 12:53:54 ä¼è¤ãã@éé @kingyo_roma 以ä¸ã®ãã¨ããã¤ã³ã¿ã¼ãããã®ã¿ã§ç¹å®ãããã¨ã«æåãã¾ããã ã»æ¬äººã¨åä¾ã®æ¬å ã»ä½æ ã»é»è©±çªå· ã»åä¾ãåãçµãã§ããã¹ãã¼
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}