é¤æ²¹ãã©ã¼æ²¹ããé ¢ããèªåã¯ãé ¢ã«å°éã®é¤æ²¹ã§ãã£ã±ãã¨ããã ãããé ¢ã®é ¸å³ã¨é¤æ²¹ã®ã³ã¯ã§ãããã§ãé£ã¹ãããã
JPCERT-AT-2017-0049 JPCERT/CC 2017-12-19(æ°è¦) 2018-03-12(æ´æ°) I. æ¦è¦2017å¹´11æãããããå½å ã«ãã㦠Mirai ã®äºç¨®ã«ããæææ´»åã確èªããã¦ãã¾ããMirai ããã®äºç¨®ãªã©ã®ãã«ã¦ã¨ã¢ã«ææããæ©å¨ã¯ãããããããã«åãè¾¼ã¾ããæ»æè ã«ããé éããå½ä»¤ãããã¦ãDDoS æ»æãªã©ã«æªç¨ãããå¯è½æ§ãããã¾ãã å³1: å®ç¹è¦³æ¸¬ã·ã¹ãã TSUBAME ã«ããã Mirai äºç¨®ã¨ã¿ãããæææ´»åã«é¢ããã¹ãã£ã³è¦³æ¸¬ç¶æ³ (2017å¹´10æãã2017å¹´12æ)æ´æ°: 2018å¹´ 3æ12æ¥è¿½è¨ JPCERT/CCãæ å ±éä¿¡ç 究æ©æ§ (NICT) ãè¦å¯åºçã®èª¿æ»ã«ãããææã®æ¡å¤§ã®ã¡ã«ããºã ã«ãæ¢ç¥ã®èå¼±æ§ (CVE-2014-8361) ãæªç¨ããã¦ãããã¨ã確èªããã¦ãã¾ããã¾ãã調æ»ã®çµæãææã«è³ã£ã¦ããæ©
NVIDIA GeForce ã½ããã¦ã§ã¢ã客æ§ä½¿ç¨ã©ã¤ã»ã³ã¹ 大åãªãç¥ãã â ãããèªã¿ãã ãã: ãã® NVIDIA GeForce ã½ããã¦ã§ã¢ã客æ§ä½¿ç¨ã©ã¤ã»ã³ã¹ (ãæ¬ã©ã¤ã»ã³ã¹ã) ã¯ãNVIDIA Corporation ã¨ãã®åä¼ç¤¾ (ãNVIDIAã) ãææãããããããã¦ã³ãã¼ãã§ãã GeForce ã½ããã¦ã§ã¢ (ã³ã³ãã¥ã¼ã¿ã¼ ã½ããã¦ã§ã¢ã¨é¢é£ç´ æ(ãã½ããã¦ã§ã¢ã)ãå«ã) ã®ä½¿ç¨ã«é©ç¨ãããå¥ç´ã§ããæ¬ã½ããã¦ã§ã¢ã®ãã¦ã³ãã¼ããã¤ã³ã¹ãã¼ã«ãã³ãã¼ããã®ä»ã®ä½¿ç¨ã«ãããã客æ§ã¯æ¬ã©ã¤ã»ã³ã¹ã®ãã¹ã¦ã®è¦ç´ã«ææãåãããã¨ã«åæãããã®ã¨ã¿ãªããã¾ããæ¬ã©ã¤ã»ã³ã¹ã®è¦ç´ã«åæããªãå ´åãã½ããã¦ã§ã¢ã¯ãã¦ã³ãã¼ãããªãã§ãã ããã åè NVIDIA ã®è£½åã®ä½¿ç¨ã«ã¯ãã½ããã¦ã§ã¢ãã°ã©ãã£ãã¯ã¹ ã³ã³ããã¼ã©ã¼ ãã¼ãã®ãã¼ãã¦ã§ã¢ããã¼ã½ãã« ã³ã³
2017å¹´ã«å ¬éãããè³æã»ã¹ã©ã¤ãã§ãCSIRT/æ å ±ã»ãã¥ãªãã£æ å½è ãèªãã§ãããã»ããããã®ã§ã¯?ã¨ãããã®ãç¬æã¨åè¦ã§ã¾ã¨ãã¦ã¿ã¾ããã ããã足ããªããããªããï¼ã¨ããæè¦ãããæ¹ã¯PRãã ãããððð Note: ãã®æ稿ã¯å人ããã°ä¸ã®è¨äºã®Qiitaã¸ã®ã¯ãã¹ãã¹ãã§ãã æè¡é¢é£è³æ JPCERT/CC: ã¤ã³ã·ãã³ã調æ»ã®ããã®æ»æãã¼ã«çã®å®è¡ç跡調æ»ã«é¢ããå ±åæ¸ (2017/12/05) JPCERT/CC: ãã°ãæ´»ç¨ããActive Directoryã«å¯¾ããæ»æã®æ¤ç¥ã¨å¯¾ç (2017/07/28) FIRST: FIRST Publications 2017 人æã»çµç¹é¢é£è³æ NCA: CSIRT人æã®å®ç¾©ã¨ç¢ºä¿(Ver.1.5) (2017/03/13) CSIRT ã«æ±ããããå½¹å²ã¨å®ç¾ã«å¿ è¦ãªäººæã®ã¹ãã«ãè²æã«ã¤ãã¦ã¾ã¨ããè³æ è£è¶³æ
2017å¹´12æ13æ¥17:28 ãåããéã¯LINE PAYã«ã¼ãã«ãã£ã¼ã¸ãã¦è¿ãã ããã #俺ã®ãã³ãã£ãºã https://narumi.blog.jp/archives/73589893.htmlãåããéã¯LINE PAYã«ã¼ãã«ãã£ã¼ã¸ãã¦è¿ãã ããã #俺ã®ãã³ãã£ãºã ãLINE PAYã便å©ãããã®ã§ã¿ããªä½¿ã£ã¦ããããããã®ã«ãªãã£ã¦ãã話ã¯åã«ããã¾ãããå¿å¹´ä¼ã·ã¼ãºã³ã®ãã¾ããããªæ¬²æ±ã¯åã®ãªãã§æ¥µéã¾ã§é«ã¾ã£ã¦ãã¾ãã LINEã使ã£ã¦"å²ãå"ã§ãããLINE PAYãã便å©ãããã®ã§ã¿ããªä½¿ã£ã¦ãããªããï¼ : Blog @narumiç¨éã¨ãã¦ã¯ãåéã¨ä¸ç·ã«é£äºããã¨ãã®å²ãåã«ãããã¦ãã¤ã³ãã¬ã¼ãã®é«ãã¯ã¬ã¸ããã«ã¼ãã¨ãã¦ããã¯ãçæ´»ããåãé¢ããªããªã£ã¦ããã å人ã¨ã©ã³ãã«è¡ã£ãã¨ããæ··éããã¬ã¸ã§å¥ã ã«ãä¼è¨ããã®ã¯ã¹ãã¼ããããªããã©ã¡
2017å¹´12æ18æ¥17:52 ãé³å£°ã®ã¤ã³ã¹ã¿ãã¤ããã Radiotalkã®äºä¸ä½³å¤®éããã«èãâé³âã®å¯è½æ§ https://narumi.blog.jp/archives/73661978.htmlãé³å£°ã®ã¤ã³ã¹ã¿ãã¤ããã Radiotalkã®äºä¸ä½³å¤®éããã«èãâé³âã®å¯è½æ§ ãã¤ã¯ããæ°å¹´ã»ã©ããããã£ã¹ãï¼ã©ã¸ãªã®ãããªãã®ã§ãï¼ã«ã¯ã¾ã£ã¦ããã¾ãã¦ãiPhoneãã¤ãã£ã¦ããæ¹ãªããã¡ãããããã£ã¨å ¬å¼ããããã£ã¹ãã¢ããªã«ç»é²ã§ãã¾ãã®ã§ãã²è©¦ãã¦ã¿ã¦ãã ããã dongurifm@dongurifm dongurifmã¯iTunesã®å ¬å¼ããããã£ã¹ãã¢ããªããè¦è´ãããã¨ãã§ãã¾ãã詳細ã¯ãã¡ãã https://t.co/CEIFqPUrUk 2016/12/19 12:20:32 ããããã£ã¹ãã¯èªåã§çªçµãé ä¿¡ããã¨ãªãã¨ãã£ããè¤éãé³å£°ãé²é³ãã¦ãã©ãã
SIPã¨cronã®ä¸å ·åãå©ç¨ãmacOS 10.13.1 High Sierraã§érootã¦ã¼ã¶ã¼ãroot権éãå¾ãããèå¼±æ§ãçºè¦ãããæ§ã§ãã詳細ã¯ä»¥ä¸ããã ã¤ã®ãªã¹PosixOne Ltdã®ã¨ã³ã¸ãã¢ã§ã»ãã¥ãªãã£ç 究è ã®Mark Wadhamããã¯ããã½ããã¦ã§ã¢ã®ã»ãã¥ãªãã£èª¿æ»ãè¡ã£ã¦ããéãmacOS 10.13.1ã§ã»ãã¥ãªãã£æ´åæ§ä¿è·æ©è½(SIP:é称rootless)ã§ä¿è·ããã¦ããªããã¡ã¤ã«ã«érootã¦ã¼ã¶ã¼ã§æ¸ãè¾¼ãã¦ãã¾ãä¸å ·åãçºè¦ããããã§ãæ¸ãè¾¼ã¿ãè¡ã£ããã¡ã¤ã«ã¯ææè ãrootããå¤æ´ããã¦ãã¾ãããã§ããã Getting root on macOS High Sierra 10.13.1 (via insecure cron system) : https://t.co/i3EKDzdrP9 cc @m4rkw â Binni Shah
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}