http://secnight.connpass.com/event/30672/ http://togetter.com/li/974201 ã·ã£ãã³æè¡ããã° http://shanon-tech.blogspot.jp/ Read less
ããã > ã¬ã¸ã§ãã > ã¹ãã¼ããã©ã³æäºãã¿ã»çµ±è¨Â > ã»ãã¥ãªãã£Â > æ¤è¨¼çµæï¼é«æ¨æµ©å æ°ããç«è ¹ã®ãWiFiã·ã§ã¢ããæå·åãã¦ãã¯ãã®Wi-Fiãã¹ã¯ã¼ããå¹³æã§ä¿åãã¦ã æ¥æ¬ã®ã¯ã©ã¦ããã¡ã¦ã³ãã£ã³ã°ãµã¼ãã¹ãMakuakeãã§160ä¸åãã®è³éã調éããããWiFiã·ã§ã¢ãã9æ18æ¥ã«iOS/Androidã¢ããªããªãªã¼ã¹ãã¦ãµã¼ãã¹ãéå§ãã¾ããã ä½ããã¦ããéä¿¡åç·ï¼éä¿¡éï¼ãä»è ã«å£²ã£ããè²·ã£ãããããã¨ã§ãä½ã£ã¦ããã¨ãã¯ã·ã§ã¢ãããã足ããªãã¨ãã¯ã·ã§ã¢ãããã¨ããå½¢ã§éä¿¡ã®è²©å£²èªç±åãç®æãã¦ããããã§ãã å ·ä½çã«ã¯ã·ã§ã¢ãããå ´åã¯ãèªèº«ãã¢ã¯ã»ã¹ãããã¨ãã§ããï¼ãã¹ã¯ã¼ããç¥ã£ã¦ããï¼SSIDã¨ãã¹ã¯ã¼ãã¨ä½ç½®æ å ±ãç»é²ãã¾ããããã¨ãè¿ãã«ããã·ã§ã¢ãããã人ã¯ãã¹ã¯ã¼ããç¥ããã«ãã®ã¢ã¯ã»ã¹ãã¤ã³ããå©ç¨ãããã¨ãå¯è½ã«ãªãã¾ãããããéä¿¡ã¯
1. ã¯ããã« ã¡ããã©ä»æ OpenSSLãã¯ããã¨ããæ§ã ãªTLSå®è£ ã®èå¼±æ§ã®è©³ç´°ãå ¬è¡¨ããã¾ããã ãã® Inriaã¨MSRã®ã°ã«ã¼ãã¯ä»¥åããTLSã®ã»ãã¥ãªãã£ã«é¢ãã¦é常ã«ã¢ã¯ãã£ãã«èª¿æ»ã»æ¤è¨¼ããã¦ããã°ã«ã¼ãã§ãä»åãé©ãã®å 容ã§ããã ãã®ã°ã«ã¼ãã¯ãTLSã®ãã³ãã·ã§ã¤ã¯æã®ç¶æ é·ç§»ãå³å¯ã«ãã§ãã¯ãããã¼ã«ãéçºããæ§ã ãªTLSå®è£ ã®èå¼±æ§ãçºè¦ã»å ±åãè¡ã£ã¦ããããã§ãã ç¹ã«FREAKã¨å¼ã°ããOpenSSLã®èå¼±æ§(CVE-2015-0204)ã«é¢ãã¦ã¯ãã¡ããã©ä¿®æ£ç´å¾ã®1æåãã« Only allow ephemeral RSA keys in export ciphersuites ã§è¦ã¦ãã¾ããããå ·ä½çã«ã©ã®ããã«æ»æããã®ããã£ã±ãã¤ã¡ã¼ã¸ã§ããããã®ã°ã«ã¼ãã ããã¾ãè¶ çµ¶å¤æ ãªææ³ã ããããã¾ãããã»ã©æ·±å»ãããªãã ããã¨è¦è¾¼ãã§ãã¾ããã ä»å
ç¾å¨SSL証ææ¸ã®ç½²åã¢ã«ã´ãªãºã ãSHAâ1ããSHAâ2ã¸ã¨å¤æ´ã«ãªãé渡æã¨ãªã£ã¦ãã¾ããä»å¾ã¯SSL証ææ¸ã®æ°è¦åå¾ãæ´æ°ãè¡ãéã«ã¯SHAâ2ã®è¨¼ææ¸ãåå¾ãããã¨ã«ãªãã¨æãã¾ããããã¤ãéãã®æ £ããä½æ¥ã¨æã£ã¦ããã¨ãæãã¬ã¨ããã§ãããããç¥ãã¾ããã ä»åã¯å®éã«æ´æ°ä½æ¥ãããçµé¨ãè¸ã¾ãã¦åå¾/æ´æ°ä½æ¥ã®æ³¨æç¹ã«ã¤ãã¦ç°¡åã«ã¾ã¨ãã¦ã¿ã¾ããã ãããããªãSHAâ2ã«ç§»è¡ããå¿ è¦ãããã®ãï¼ ç½²åã¢ã«ã´ãªãºã ãSHAâ1ã®è¨¼ææ¸ã¯éæ¨å¥¨ã¨ãªããããããã¯å»æ¢ã¨ãªãæµãã¨ãªã£ã¦ãã¾ããåºæ¬çã«SHAâ1ã®è¨¼ææ¸ã¯2017å¹´1æ1æ¥ä»¥é使ããªããªãã¨èãã¦ããã§ããããããã¦2016å¹´12æ31æ¥ã¾ã§ã«SHAâ2ã«ç§»è¡ããå¿ è¦ãããã¾ãã 詳細ã¯ããã§èª¬æããã¨é·ããªãã¾ãã®ã§ã次ã®ãããªSSL証ææ¸ã®çºè¡å ã®ãµã¤ãã®è§£èª¬ãåç §ãã¦ãã ããã SHAâ1証ææ¸ã®åä»çµäºã¨S
追è¨(2015/2/6) 大å£ããããè¨æ£ä¾é ¼ã®ã³ã¡ã³ããé ãã¦ããã¾ãã®ã§åããã¦ãèªã¿ãã ããã徳丸ã¨ãã¦ã¯ç¹ã«è¨æ£ã®å¿ è¦ã¯æãã¾ããã§ããã®ã§ãæ¬æã¯ãã®ã¾ã¾ã«ãã¦ãã¾ããããæãçç±ã¯ã³ã¡ã³ãã¨ãã¦è¿½è¨ãããã¾ããã (追è¨çµãã) 大å£ããã®ããã°ã¨ã³ããªãGHOSTã使ã£ã¦æ»æã§ããã±ã¼ã¹ããèªãã ã¨ããã以ä¸ã®ãããªãã¨ãæ¸ãã¦ããã¾ããã 1. ã¦ã¼ã¶ã¼å ¥åã®IPã¢ãã¬ã¹ï¼ãããã¯ã¼ã¯å±¤ã®IPã¢ãã¬ã¹ã§ã¯ãªãï¼ã«æ»æç¨ãã¼ã¿ãéãã 2. ããªãã¼ã·ã§ã³ç¡ãã§æ»æç¨ã®ä¸æ£ãªIPã¢ãã¬ã¹ãgethostbyname()ã«æ¸¡ãããã 3. ãã¼ããªã¼ãã¼ããã¼ã§ãã¼ãé åã®ã¡ã¢ãªç®¡çç¨ã®ç©ºããµã¤ãºãæ¹ç«ããã ãä¸ç¥ã ã©ããªã½ããã¦ã§ã¢ãå±ãªãã®ãï¼ ã¦ã¼ã¶ã¼å ¥åã®IPã¢ãã¬ã¹ãããªãã¼ã·ã§ã³ããªãã§gethostbyname()ã使ç¨ãã¦ããã ã¤ã³ã¿ã©ã¯ãã£ããªåä½ãè¡ã£
â æ å ±çµæ¸èª²ã¯æ¥ãç¥ã£ã¦è§£æ£ããï¼ãã¼ã½ãã«ãã¼ã¿ä¿è·æ³å¶ã®è¡æ¹ ãã®12ï¼ ã¾ãåãéã¡ãç¹°ãè¿ãããããã£ããä½åº¦ç¹°ãè¿ãã°å¦ç¿ããã®ãã çµæ¸ç£æ¥çå§è¨äºæ¥ ãçµæ¸ç£æ¥åéã«ãããå人æ å ±ä¿è·ã¬ã¤ãã©ã¤ã³ã 説æä¼ãåå è åééå§ï¼ http://t.co/JRFplpoiWP #ãã¬ã¹ãªãªã¼ã¹ â ï¼æ ªï¼å ±åé信社 (@Kyodonews_KK) 2014, 12æ 2 ãã®ãã¬ã¹ãªãªã¼ã¹ã¯èª°ãæµãããã®ãã以ä¸ã®ç»é¢ã®ããã«åé ã«ãçµæ¸ç£æ¥çãã¨è¨è¼ãããããããè¦ã人ã¯ï¿½çµæ¸ç£æ¥çãæµãããã®ã ã¨æãã ããã*1 çµæ¸ç£æ¥çå§è¨äºæ¥ ãçµæ¸ç£æ¥åéã«ãããå人æ å ±ä¿è·ã¬ã¤ãã©ã¤ã³ã 説æä¼ãåå è åééå§ï¼, æ ªå¼ä¼ç¤¾å ±åé信社 ç³è¾¼å ã®ãªã³ã¯ã http://kojinjohohogo-guideline.jp ã¨æ¸ããã¦ããã ããã®ã¯ãããã©ã.go .jpãããªããã
èå¼±æ§ãè¦ã¤ãã¦ã»ãã¥ãªãã£å¯¾çã«è²¢ç®ãã¦ããã®ããããã°ãã³ã¿ã¼ãã¨å¼ã°ããåå¨ã ãGoogleãªã©ãã³ãã¼ã®å ±å¥¨éã§çè¨ãç«ã¦ã¦ããã¨ãããããã¬ã¯ ããµããããããããã®ãã°ãã³ã¿ã¼ã¨ãã¦ã®âæãã¿âãç´¹ä»ãã¦ãããã ã½ããã¦ã§ã¢ã®ãã°ãèå¼±æ§ã¯ã軽微ãªä¸å ·åããã»ãã¥ãªãã£ä¸ã®æ·±å»ãªåé¡ãå¼ãèµ·ãããã®ã¾ã§ãæ§ã ãªãã®ããããéçºè ãå¹¾ã注æãã¦ãèå¼±æ§ããªãããã¨ã¯é常ã«é£ããããå¤é¨ã®ç«å ´ããèå¼±æ§ãè¦ã¤ãã¦ã»ãã¥ãªãã£å¯¾çã«è²¢ç®ããããã°ãã³ã¿ã¼ãã¨ããåå¨ããåãã ãããã GoogleãMicrosoftããµã¤ãã¦ãºãªã©ä¸é¨ã®ãã³ãã¼ã¯ãèå¼±æ§ãå ±åãããã°ãã³ã¿ã¼ã«å ±å¥¨éãªã©ãæ¯æãå¶åº¦ãéå¶ããã®å ±å¥¨éã§çè¨ãç«ã¦ãããã®ä¸äººããããã¬ã¯ ããµããããã ã12æ18ã19æ¥ã«è¡ãããã»ãã¥ãªãã£ã«ã³ãã¡ã¬ã³ã¹ãCODE BLUEãã§ã¯ãããã¬ã¯ãããããã®ãã°ãã³ã¿
ãã®è¨äºã¯èå¼±æ§"&'<<>\ Advent Calendar 2014ã®17æ¥ç®ã®è¨äºã§ããä»æ¥ã¯å°ãæ話ããããã¨æãã¾ãããã¯ã¯ã ãã¤ã¦ãæ¥æ¬è£½Twitterã®ãããªWassrã¨ãããµã¼ãã¹ãããã¾ãããå½æãTwitterã¯æ°æ¥ã«ä¸åº¦ãããã¯ãµã¼ãã¹ãè½ã¡ã¦ãã¦ãTwitterã¦ã¼ã¶ã¼ããã¾ãããã¨æããªããææ ¢ãã¦ä½¿ããããªãµã¼ãã¹ã§ãããTwitterãè½ã¡ããã³ã«Wassrã¯ã¦ã¼ã¶ã¼ãå¢ããã¨ã¨ãã«ãç»åã®æ·»ä»ã®ããã«å½æTwitterã«ã¯ã¾ã ãªãã£ãæ©è½ãã©ãã©ãã¢ã°ã¬ãã·ãã«åãå ¥ãã¦ããã使ã£ã¦ãã¦æ¥½ãããµã¼ãã¹ã§ããã ãã¦ããããªWassrãããæ¥çµµæåæ©è½ãå°å ¥ãã¾ãããå½æã¯Unicodeçµµæåããªãã¹ãã¼ããã©ã³ãæ®åãã¦ãããã主ã«ã¬ã¬ã·ã¼ãªæºå¸¯é»è©±ã§ä½¿ããçµµæåããªãã¨ãWebä¸ã§ã使ããããã«ããã¨ããæãã®ãã®ã§ããã çµµæåããã¬ããããé¸æããã¨
é«æ©: ããã«ã¡ã¯ãé«æ©ã§ããä»æ¥ã¯å¾³ä¸¸ããããæããã¦ãä»è©±é¡ã®ãã¹ã¯ã¼ãã®å®æçå¤æ´ã«ã¤ãã¦ãæ¬å½ã®ã¨ããå¹æããªãã®ãããã®å¹è½ã«ã¤ãã¦ã説æããã ãã¾ãã徳丸ããããããããé¡ããã¾ãã 徳丸: 徳丸ã§ãããã¤ãã¯ãã¹ã¯ã¼ãã®å®æçå¤æ´ã«ã¯ãã¾ãæå³ããªãã¨ä¸»å¼µãã¦ãã¾ãããä»æ¥ã¯ãã¹ã¯ã¼ãã®å®æçå¤æ´ãæè·ããç«å ´ãªãã§ãããé¢ç½ããã§ãããããããé¡ããã¾ãã é«æ©: ã¾ãåé¡ã®æ´çã«ã¤ãã¦ã§ããIPAãã9æ3æ¥ã«ããIDã»ãã¹ã¯ã¼ãã®ã»ãã¥ãªãã£å¯¾çä¿é²ã«é¢ããåºåçæ¥åã ä¿ãä¼ç»ç«¶äº ãã®ä»æ§æ¸(PDF)ãå ¬éããã¾ããããã®ä»æ§æ¸ä¸ã®è¡ååèµ·ãä¿ã対çäºä¾ã®ä¸ã¤ã«ãIDã»ãã¹ã¯ã¼ãã¯å®æçã«å¤æ´ããã ããã£ãã®ã§ãã»ãã¥ãªãã£ã¯ã©ã¹ã¿ãé¨ãåºãããã®çµæãã©ããã¯åããã¾ãããã9æ9æ¥ã«åä»æ§æ¸ãæ¹å®ããããã¹ã¯ã¼ãã®å®æçå¤æ´ã¯å¯¾çä¾ããåé¤ããã¾ãããä¸é£ã®è°
æ»æææ³ãæè¡çã«ç解ããããã®é£è¼ã第2åç®ã¯ãããã¡ã¼ãªã¼ãã¼ããã¼ãçããã¹ã¿ãã¯ãã¸ã®æ»æã解説ãã¾ãã é£è¼ç®æ¬¡ ã¹ã¿ãã¯ãã¼ã¹ã®æ»æãç¥ã 第2åã§ã¯ããããã¡ã¼ãªã¼ãã¼ããã¼ã®ä»£è¡¨çãªææ³ã§ãããã¹ã¿ãã¯ãã¼ã¹ã®æ»æã«ã¤ãã¦åãä¸ãã¾ãããªããããã§åãä¸ããå 容ã¯ãç¾å¨ã¯ãã¤ã¯ãã½ããã®Security Science teamã®ä¸å¡ã§ãããMatt Millerã®ãA Brief History of Exploitation Techniques & Mitigations on Windowsãããã¼ã¹ã¨ãã¦è¨è¼ãã¦ãã¾ãã ã¹ã¿ãã¯ãã¼ã¹ã®æ»æãç¹ã«ã¹ã¿ãã¯ãªã¼ãã¼ããã¼ã¯ãç¾å¨ã§ã¯å¤å ¸çãªæ»æææ³ã§ãããã¤ã¯ãã½ãããå ¬è¡¨ãã¦ãããSecurity Intelligence Report Volume 16ãã«ããã°ãç¾å¨ã¯ã¹ã¿ãã¯ãã¼ã¹ã®æ»æã¯ã»ã¨ãã©è¦ãããªã
ããæ¥çªç¶ãå人ã®ã¢ã«ã¦ã³ããããé«é¡é¡é¢ã®ããªãã¤ãã«ã¼ãï¼â»iTunesã«ã¼ããªã©ï¼ãã³ã³ããã§ä½æãè²·ã£ã¦ãããã¾ãããããéã¯å¾ã§æãã¾ããã¨ããã¡ãã»ã¼ã¸ãæ¥ãããå®ã¯ãã®ã¢ã«ã¦ã³ãã¯å¥äººã«ããä¹ã£åããç´ ç´ã«ããªãã¤ãã«ã¼ããè²·ããç¸æã®æ示éãã«ã«ã¼ãã®æ å ±ãæããã¨ãã¾ãã¾ã¨ãéãã ã¾ãåããã¦ãã¾ãã¨ãã寸æ³ã ãæ¥æ¬èªãããæªããã§ãããã¨ããããç¯äººã¯ä¸å½ç³»ã®äººãã¡ã§ã¯ãªããã¨ããæ å ±ããæè¿ãããä¸ã§æµãã¦ããã ãã®ãªããã¾ãã¢ã«ã¦ã³ãããã®ã¡ãã»ã¼ã¸ããä¸å½äºæ ã«è©³ãããã³ãã£ã¯ã·ã§ã³ä½å®¶ã®å®ç°å³°ä¿ããã®å ã«ããã£ã¦ãããä¸å½èªãå ªè½ããã¤å ä¸å½ããã¬ã¼ã§ãã®æã®ï¼¢ç´ãã¥ã¼ã¹ã大好ããªå®ç°ããããã¤ãã«ä¿ºã®æã«ãæ¥ã¦ããããã¨åã³åãã§ãä¹ã£åãç¯ã¨ä¼è©±ã試ã¿ããã¨ã«ããã â ãªãã¹ãLINEä¹ã£åãç¯ããã¡ãã»æ¥ãããªã©ããããã¯ã¯ã¯ã¯ãã¦ãã ãªãã¹ãLINE
ã¯ã¦ãªã°ã«ã¼ãã®çµäºæ¥ã2020å¹´1æ31æ¥(é)ã«æ±ºå®ãã¾ãã 以ä¸ã®ã¨ã³ããªã®éããä»å¹´æ«ãç®å¦ã«ã¯ã¦ãªã°ã«ã¼ããçµäºäºå®ã§ããæ¨ããç¥ãããã¦ããã¾ããã 2019å¹´æ«ãç®å¦ã«ãã¯ã¦ãªã°ã«ã¼ãã®æä¾ãçµäºããäºå®ã§ã - ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãã®ãã³ãæ£å¼ã«çµäºæ¥ã決å®ãããã¾ããã®ã§ã以ä¸ã®éãã確èªãã ããã çµäºæ¥: 2020å¹´1æ31æ¥(é) ã¨ã¯ã¹ãã¼ãå¸æç³è«æé:2020å¹´1æ31æ¥(é) çµäºæ¥ä»¥éã¯ãã¯ã¦ãªã°ã«ã¼ãã®é²è¦§ããã³æ稿ã¯è¡ãã¾ãããæ¥è¨ã®ã¨ã¯ã¹ãã¼ããå¿ è¦ãªæ¹ã¯ä»¥ä¸ã®è¨äºã«ãããã£ã¦æç¶ãããã¦ãã ããã ã¯ã¦ãªã°ã«ã¼ãã«æ稿ãããæ¥è¨ãã¼ã¿ã®ã¨ã¯ã¹ãã¼ãã«ã¤ã㦠- ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãå©ç¨ã®ã¿ãªãã¾ã«ã¯ãè¿·æãããããããã¾ãããã©ãããããããé¡ããããã¾ãã 2020-06-25 è¿½è¨ ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ã®ã¨ã¯ã¹ãã¼ããã¼ã¿ã¯2020å¹´2æ28
æè¿SNSä¸ã§è©±é¡ã«ãªã£ã¦ããã®ããLINEã®ä¹ã£ã¨ãé¨åããã ãLINEã®ãµã¼ãã¹èªä½ããæ å ±ãæµåºããããã§ã¯ãªããä»ã®ãµã¼ãã¹çã¨å ±æãã¦ããã¡ã¼ã«ã¢ãã¬ã¹ã¨ãã¹ã¯ã¼ãã®çµã¿åããã§ä¸æ£ãã°ã¤ã³ãããã¦ããããã ã ããã§LINEãè¡ã£ãã®ããããã¹ã¯ã¼ãå¤æ´ããæ¹å ¨å¡ã«LINEãã£ã©ç¹è£½ã¹ã¿ã³ããã¬ã¼ã³ããã¨ããããã¡ãã®ãã£ã³ãã¼ã³ã ã¡ã¼ã«ã¢ãã¬ã¹ããã¹ã¯ã¼ããè¨å®/å¤æ´ããé¢åãããã¹ã¿ã³ãã¨ããã¤ã³ã»ã³ãã£ãã§ä¹ãè¶ããããã¨ãããLINEã«ã¨ã£ã¦ãã¦ã¼ã¶ã¼ã«ã¨ã£ã¦ãwin-winã®æ½çã ãããèãããªãï¼ â¦ã¨æã£ã¦ããã以ä¸ã®ãã¤ã¼ããè¦ãã¾ã§ã¯ã ä¸è¦æå¹ãªããã«è¦ãããã©ãLINEãã¹ã¯ã¼ãå ¥åãããã¹ã¿ã³ãããããã£ã¦æ å¼±ã«èª¤å¦ç¿ããã¦ãã¾ã£ã¦ããã£ãã·ã³ã°ãµã¤ãä¹±ç«ããæ°ããã http://t.co/XWiYWDrfed â oÊoɯıɥsÉÉ¥ oÉ¥s (@s
å¹³ç´ ã¯æ ªå¼ä¼ç¤¾ã©ã¤ããã¢ã®ãµã¼ãã¹ã ãå©ç¨ããã ããããã¨ããããã¾ãã æè¨åãã¥ã¼ã¹ãµã¤ããBLOGOSãã¯ã 2022å¹´5æ31æ¥ããã¡ã¾ãã¦ã ãµã¼ãã¹ã®æä¾ãçµäºãããã¾ããã ä¸é¨ã®ãªãªã¸ãã«è¨äºã«ã¤ãã¾ãã¦ã¯ã livedoorãã¥ã¼ã¹å ã® ãBLOGOSã®è¨äºä¸è¦§ãããã覧ããã ãã¾ãã é·ãããå©ç¨ããã ãããããã¨ããããã¾ããã ãµã¼ãã¹çµäºã«é¢ãããåãåããã¯ã ä¸è¨ã¾ã§ãé¡ããããã¾ãã ãåãåãã
æ¥æ¬èªç©ºï¼JALï¼ã¯2014å¹´2æ3æ¥ãå社ãéå¶ãããJALãã¤ã¬ã¼ã¸ãã³ã¯ï¼JMBï¼ãã®ä¼å¡Webãµã¤ãï¼ç»é¢ï¼ã¸ã®ä¸æ£ãã°ã¤ã³ãå¤æããJMBä¼å¡ã«ãªããã¾ãã第ä¸è ããã¤ã«ãç¹å ¸ã«äº¤æãããã©ãã«ãå¤æ°çºçãã¦ãããã¨ãçºè¡¨ããã JALåºå ±é¨ã®èª¬æã«ããã°ã1æ31æ¥ãã2æ2æ¥ã¾ã§ã«7人ã®JMBä¼å¡ãã³ã¼ã«ã»ã³ã¿ã¼ã«ã身ã®è¦ãã®ãªãç¹å ¸äº¤æãããããã¨ããåãåããããããJALã調æ»ããã¨ãããä¸æ£ãã°ã¤ã³ã«ãããAmazonã®ããå¸ãã¸ã®äº¤æã®å¯è½æ§ãçãããããã2æ2æ¥16æã¾ã§ã«Amazonã®ããå¸äº¤æãµã¼ãã¹ãåæ¢ãããä¸æ£äº¤æã®å¯è½æ§ãããJMBä¼å¡ã¯ç´60人ã§ãJALãåå¥ã«äºå®ç¢ºèªãé²ãã¦ããã ç¾æç¹ã§ã¯ãAmazonã®ããå¸ã以å¤ã¸ã®ç¹å ¸äº¤æã®å½±é¿ã¯ç¢ºèªããã¦ããªãã¨ãããã ããä¸æ£ãã°ã¤ã³ã«è³ã£ãçµç·¯ã®å ¨å®¹ãæããã«ãªã£ã¦ããããä»å¾å½±é¿ãåºããå¯è½æ§ã
é«æ©: ããã«ã¡ã¯ãé«æ©ã§ããä»æ¥ã¯å¾³ä¸¸ããããæããã¦ãJALã®ä¸æ£ãã°ã¤ã³äºä»¶ã«ã¤ãã¦ã話ã伺ãã¾ãã徳丸ããããããããé¡ããã¾ãã 徳丸: 徳丸ã§ãããããããé¡ããã¾ãã é«æ©: ã¾ããäºä»¶ã®æ¦è¦ã説æãã¾ããæ¥æ¬èªç©ºã®ãã¼ã ãã¼ã¸ã«ä¸æ£ã¢ã¯ã»ã¹ããããJALãã¤ã¬ã¼ã¸ãã³ã¯ï¼JMBï¼ã®ãã¤ã«ããAmazonã®ã®ããå¸ã«åæã«äº¤æããã被害ãããã¾ãããæ¥æ¬èªç©ºã®çºè¡¨ã§ã¯ã1æ31æ¥ãã2æ2æ¥ã«ããã¦ã身ã«è¦ãããªããã¤ã«äº¤æãããã¦ããã¨ããåãåãããè¤æ°ããã¾ããã調æ»ã®çµæã40人ã®å©ç¨è ã®ãã¤ã«ãã¢ãã¾ã³ã®ã®ããå¸ãæ°ç¾ä¸åç¸å½ã¨äº¤æããã¦ããã¨ãããã®ã§ãã 徳丸: ããã§åé¡ã¨ãªãã®ã¯ããã¹ã¯ã¼ãã¯æ°å6æ¡ã¨ãããã¨ãªãã§ãããã é«æ©: ãã¯ãããã§ããããã¹ã¯ã¼ããæ°å6æ¡ã ã¨ã©ã®ãããªæ»æãã§ããã®ã§ãããã? ãã«ã¼ããã©ã¼ã¹æ»æ 徳丸: ã¾ãããã«ã¼ãã
ã²ããã¾ãã (廣島ãã) ã¯ãããã¾ã§ãã£ã 1 æåã® Twitter ã¢ã«ã¦ã³ã @N ãæã£ã¦ãã¾ããã ä½æ ãæã£ã¦ãã¾ãããã¨ãéå»å½¢ãªã®ãã¨ããã¨ãã©ãããå æ¥ãå·§å¦ãªç½ ã«ãæ¬äººã§ã¯ãªã 2 社ã®æå IT é¢é£ä¼æ¥ããã¡ããããã¨ã«ãã£ã¦ãã²ããã¾ããã®ç¨å°ãªãã®ã¢ã«ã¦ã³ãã第ä¸è ã«ãã£ã¦çã¾ãã¦ãã¾ã£ããããªã®ã§ãã 2014/02/26 追è¨: è¨äºæ²è¼æç¹ã§ã¯ãæã£ã¦ãã¾ãããã¨éå»å½¢ã§è¡¨ç¾ãã¦ãã¾ãããã²ããã¾ããæ¬äººã«ãããã¤ã¼ãã§ã2014/02/25 ã®æ¼éã (æ¥æ¬æé 2014/02/26 ã®æ©æ) ã«ããã®äºä»¶ã«ãã£ã¦çã¾ãã¦ãã¾ã£ãã¢ã«ã¦ã³ã @N ãããããåãæ»ããããã¨ããããã¾ããã Order has been restored. â Naoki Hiroshima (@N) February 25, 2014 解決ã¾ã§ä¸ã¶æ以ä¸ã¨ããç¸å½ãª
å½ç¤¾ã®ç·æ¥å¯¾å¿ãã¼ã ããµã¤ãã¼ææ¥ã»ã³ã¿ã¼ãã¯ãæ¨çåæ»æã«é¢ãã調æ»ãè¡ãéç¨ã§ãæ£è¦ã®ã½ããã¦ã§ã¢ã®ã¢ãããã¼ããè£ ãã³ã³ãã¥ã¼ã¿ã¼ã¦ã¤ã«ã¹ã«ææããããè¤æ°ã®äºæ¡ã確èªãã¾ãããæ¬ä»¶ã¯å½ç¤¾ã2013å¹´10æ9æ¥ã«çºè¡¨ãããæ¥æ¬ã§ãçºçããã水飲ã¿å ´åæ»æãã«å¯¾ãã¦æ³¨æåèµ·ãã¨ã¯ç°ãªããæ°ããæ¨çåæ»æã®æå£ã¨æãã¦ãã¾ãã æ¬æ³¨æåèµ·æ å ±ã¯ãå½è©²ã½ããã¦ã§ã¢ã使ç¨ãã¦ããã客æ§ããæ¬äºæ¡ã®æªå½±é¿ãåãã¦ããªããã確èªããæ¹æ³ããä¼ãããããã«å ¬éãããã¾ããã¾ããä»å¾ãä¼æ¥å ã§ä½¿ç¨ãã¦ããæ£è¦ã½ããã¦ã§ã¢ã®ã¢ãããã¼ãã«ããã¦åæ§ã®ä»æãããªãããå±éºæ§ãããããããã¦æ³¨æåèµ·ãããã®ã§ãã 2014/03/10 æ´æ° æ¬æ³¨æåèµ·æ å ±ãå¤ãã®çæ§ã«ã覧ããã ããã¾ã100件ãè¶ ããé»åã¡ã¼ã«ããã³ãé»è©±ã§ã®ãåãåãããããã ã¾ãããæ å ±ãçºä¿¡ããä¼æ¥ã¨ãã¦ã®è²¬ä»»ã¨ãã¦ããåãåãã
2013/12/26ãã³ã¼ã¹ï¼å ç¥ãã£ã¦ã ãå ç¥ãã£ã¦ããè¨äºã¯ãããã¨ã¼ã¸ã§ã³ãæ§ããã°[netagent-blog.jp]ã«æ²è¼ããã¦ããè¨äºã§ãããç¾å¨ãããã¨ã¼ã¸ã§ã³ãã«å¨ç±ãã¦ããªãã©ã¤ã¿ã¼ã®è¨äºãå«ã¿ã¾ãã å ¥åæ å ±ãéä¿¡ããIï¼ï¼¥ IMEã®é信解æã§å©ç¨ãããSSLã®è§£ææè¡ã«é¢ã㦠NHKãªã©ã§å ±éããã¦ããããã½ã³ã³ç¨ã®æ¥æ¬èªå ¥åã½ããBaidu IMEã Androidç¨ã®æ¥æ¬èªå ¥åã½ãã Simejiã®éä¿¡ãã¼ã¿ã解æãã件ã«é¢ãã¦è©³ç´°ãã説æãã¾ãã æ¤è¨¼è§£æç°å¢ ï¼ï¼³ï¼³ï¼¬ã«ããæå·åéä¿¡ã解æã§ããç°å¢ï¼ 解æã®çµæãæ¥æ¬èªå ¥åã®æååããSSLã§æå·åããéä¿¡ããã¦ãããã¨ããããã¾ããã Baidu IME ,ãSimejiã§ã¯ãå ¨è§å ¥åã®å ´åã®ã¿æ å ±ãéä¿¡ããã¦ãã¾ãã ã¯ã©ã¦ãå ¥åOffã®å ´åã§ãå ¥åæååãéä¿¡ãã¦ãã¾ããã ãã¹ã¯ã¼ããªã©åè§å ¥åã®ã¿
ã¡ã¼ã«ã¢ãã¬ã¹ã®ãã«ã¼ã«ãã«é¢ãã話é¡ãçãä¸ãã£ã¦ãã¾ããã ãã¡ã¼ã«ã¢ãã¬ã¹ã®ã«ã¼ã«ãç³»ã¾ã¨ããããã£ã¦ééã£ã¦ãã®ã§ã注æã ãã¡ã¼ã«ã¢ãã¬ã¹ã®ã«ã¼ã«ããªãã¦ä½¿ã£ã¦ã¯ãããªã3ã¤ã®çç± ãããã®ã¨ã³ããªã«ç°è«ãããããã§ããã¾ãããã¡ã¼ã«ã¢ãã¬ã¹ã«é¢ããã«ã¼ã«ã¨ããã¨RFC5322ãªã©ããããã®ã®ãç¾å®ã®éç¨ã§ã¯ç°¡æçãªä»æ§ãç¨ãã¦ããå ´åã大åã§ããâ¦ã¨ããäºæ ã¯ãç§ã以åããã°ã«æ¸ãã¾ãããã æ¬ç¨¿ã§ã¯ãã空åã®ã¡ã¼ã«ã¢ãã¬ã¹ã®ã«ã¼ã«ãã¼ã (?)ãã«ä¾¿ä¹ããå½¢ã§ãRFC5322ã«æºæ ããã¡ã¼ã«ã¢ãã¬ã¹ã§ãXSSãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã®æ»æãã§ãããã¨ãç´¹ä»ãã¾ããã¨è¨ã£ã¦ããSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã«ã¤ãã¦ã¯ãéå»ã«æ¸ãã¾ããã®ã§ãæ¬ç¨¿ã§ã¯ãRFC5322ããªãããªã¡ã¼ã«ã¢ãã¬ã¹ã§SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã¨XSSã®ä¸¡æ¹ãã§ããã¡ã¼ã«ã¢ãã¬ã¹ãç´¹ä»ãã¾ãã ã¾ããæ»æ対象ã¨ãã¦ã以ä¸
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}