æ³æ¹æ£ãé²ããããã«è³ææè¦ãæ°´å¢ããã¦ä¸å ã«å ±åããæµ·å¤ã§ã®å è¡äºä¾ãæ£æï¼ããï¼çã«é¸ãã§é½åã®ããã¨ããã ãç´¹ä»ãã¦ããââã 権å©è ã®è¨±å¯ãªãã¤ã³ã¿ã¼ãããã«ä¸ããããã¨ç¥ããªãã漫ç»ãåçãè«æãªã©ããã¦ã³ãã¼ããããã¨ãå ¨é¢çã«éæ³ã¨ããèä½æ¨©æ³æ¹æ£ãé²ãããã¨ãã¦ããæååºããèªæ°å ã«æ£ç¢ºã§ã¯ãªã説æãããã¨ææãããæ¤è¨¼ã¬ãã¼ãããï¼æ¥ãæ治大å¦ç¥ç財ç£æ³æ¿çç 究æã®ãã¼ã ãã¼ã¸ã§å ¬è¡¨ãããã èªæ°å ã®æé¨ç§å¦é¨ä¼ãªã©ã¯å æãããã説æãªã©ããã¨ã«æ³æ¹æ£ãäºæ¿ããããå対æè¦ãæ ¹å¼·ãåºã¦ãããå ã®æé«ææ決å®æ©é¢ã§ããç·åä¼ã¯ï¼æ¥ã®ä¼åã§ãé¢ä¿è ã¸ã®èª¬æä¸è¶³ãªã©ãçç±ã«ç°ä¾ã®äºæ¿å éãã決ããã°ãããä¸å ã«ä¸æ£ç¢ºãªå¤æææãæä¾ãã¦ããã¨ã®ææã¯ä»å¾ã®è°è«ã«å½±é¿ãä¸ãããã ã ä»åã®æ¤è¨¼ã¯ãéæ³ã¨ããè¡çºããã£ã¨çµãè¾¼ãããã«ç·æ¥å£°æã§æ±ãã¦ããèä½æ¨©æ³ã®å°é家ãã®ä¸é¨ãè¡
ã³ã³ãã³ãããã¸ã¡ã³ãã·ã¹ãã ï¼CMSï¼ã®ãDrupalãã«æ·±å»ãªèå¼±æ§ãè¦ã¤ãã£ãåé¡ã§ãèå¼±æ§ãçã£ãæ»æãçºçãã¦ãããã¨ãããã£ããå½åã¢ãã¦ã³ã¹ãããä¸é¨ç·©åçã«èª¤ãããã£ããã¨ãå¤æãã¦ããã åé¡ã®ãCVE 2019-6340ãã¯ãã¢ã¸ã¥ã¼ã«ãRESTful Web Servicesããæå¹åãã¦ããå ´åãä»»æã®PHPã³ã¼ããå®è¡å¯è½ã¨ãªãèå¼±æ§ã èå¼±æ§ã®å ¬éå¾ãèå¼±ãªã·ã¹ãã ãæ¢ç´¢ãã¦ããã¨è¦ãããã¢ã¯ã»ã¹ãå½å ã§ã観測ããã¦ãããDrupalã®éçºãã¼ã ã§ãã¨ã¯ã¹ããã¤ãã«é¢ããå¤æ°ã®å ±åãåãã¦ããã¨ããã Impervaã§ã¯ãè¤æ°ã®ãµã¤ãã対象ã¨ããæ»æãå±éããã¦ãããã¨ãæ¤ç¥ãå社ã«ããã°ãæ°åã«ãããå社ã®é¡§å®¢ãµã¤ãã«ããã¦ãè¤æ°å½ãè¤æ°ã®æ»æè ãçºä¿¡å ã¨ããæ»æããããã¯ããã æ»æã¯2æ23æ¥ã«éä¸ãã¦ããã100ä»¶è¶ ãæ¤ç¥ãæ»æ対象ã¨ãªã£ããµã¤ãã«ã¯ãé
å·¥å ·ã¡ã¼ã«ã¼ã®å¶æ¥ç§å¯ã«å½ããè¨è¨å³ãªã©ãã³ãã¼ããã¨ãã¦é®æãããä¸å½å½ç±ã®ç¤¾å¡ãä¼ç¤¾ã®ãµã¼ãã¼ã«ï¼æ¥ã«ï¼ï¼ï¼å以ä¸ã¢ã¯ã»ã¹ãã¦ãããã¨ãåããã¾ããã æç¥çè±ç°å¸ã®å·¥å ·ã¡ã¼ã«ã¼ãå¯å£«ç²¾å·¥ãã®ç¤¾å¡ã§ä¸å½å½ç±ã®ç³æ°¸è¼å®¹çè ï¼ï¼ï¼ï¼ã¯ä»å¹´ï¼æãä¼ç¤¾ã®ãµã¼ãã¼ã«ã¢ã¯ã»ã¹ãå¶æ¥ç§å¯ã«ãããå·¥å ·ã®è¨è¨å³ãªã©ãUSBã¡ã¢ãªã¼ã«ã³ãã¼ãæãåã£ãçãã§ï¼æ¥ãéæ¤ããã¾ããã ç³å®¹çè ã¯ãåå¼·ç®çã ã£ããã¨å®¹çã®ä¸é¨å¦èªãã¦ãã¾ãããææ»é¢ä¿è ã«ããã¾ãã¨ç³å®¹çè ãï¼æ¥ã ãã§ï¼ï¼ï¼å以ä¸ä¼ç¤¾ã®ãµã¼ãã¼ã«ã¢ã¯ã»ã¹ãããã¼ã¿ãæãåã£ã¦ããã¨ã¿ãããã¨ãããã¨ã§ãã è¦å¯ã¯ãæãåããããã¼ã¿ãå½å¤ã«æµåºããå¯è½æ§ãããã¨ã¿ã¦ææ»ãã¦ãã¾ãã
AWS EC2ç°å¢ã§ã®DNS Rebindingã«ã¤ãã¦æ¤è¨¼ããã®ã§ç´¹ä»ãã¾ãã ã¾ãã¯ããååã¾ã§ã®ãããããã§ããå æ¥ä»¥ä¸ã®è¨äºã§SSRFæ»æããã³SSRFèå¼±æ§ã«ã¤ãã¦ç´¹ä»ãã¾ããã SSRF(Server Side Request Forgery)å¾¹åºå ¥é ãã®è¨äºã®ä¸ã§ã以ä¸ã®ããã«ç´¹ä»ãã¾ããã ãã¹ãåããIPã¢ãã¬ã¹ãæ±ããéã«ã以ä¸ã®åé¡ãçºçãã¾ãã DNSãµã¼ãã¼ãè¤æ°ã®IPã¢ãã¬ã¹ãè¿ãå ´åã®å¦çã®æ¼ã IPã¢ãã¬ã¹ã®è¡¨è¨ã®å¤æ§æ§ï¼åèè¨äºï¼ IPã¢ãã¬ã¹ãã§ãã¯ã¨HTTPãªã¯ã¨ã¹ãã®ã¿ã¤ãã³ã°ã®å·®ãæªç¨ããæ»æï¼TOCTOUèå¼±æ§ï¼ ãªã¯ã¨ã¹ãå ã®Webãµã¼ãã¼ããæ»æ対象ãµã¼ãã¼ã«ãªãã¤ã¬ã¯ããã ä¸è¨ã®TOCTOU(Time of check to time of use)åé¡ã¯ãDNSã®åå解決ã®æèã§ã¯DNS Rebindingã¨ãå¼ã°ãã¾ãã DNS R
ãã»ã»ããã®ãªã³ã©ã¤ã³é販ãµã¤ãã§ååãè³¼å ¥ããã¨ããã¯ã¬ã¸ããã«ã¼ãæ å ±ãæ¼æ´©ãã¦ä¸æ£å©ç¨ããã¾ããã å¹´æ«ãã1æã«ããã¦ã®è©±ãäºå®ãã¼ã¹ã§è¨è¼ãã¾ãã â 2018/12/28 ãã»ã»ãããªã³ã©ã¤ã³é販ãµã¤ãã«ã¦ãã¸ã«ã«ã¢ã¼ãã·ã¼ãã2ç¹æ³¨æã ã¯ã¬ã¸ããã«ã¼ãæ å ±ãå ¥åããå¾ãã¨ã©ã¼è¡¨ç¤ºããã2åç®ã®ã«ã¼ãæ å ±å ¥åã éåæããããç»é¢ã®ã¹ã¯ãªã¼ã³ã·ã§ãããæ®ãã¾ããã â 2019/01/12 åç©ãå±ããã â 2019/01/13 ãã»ã»ããã«TEL æ å½è ããè³¼å ¥å¦çã確å®ãã¦ããªãã®ã§å注æããããã«è¨ããã¾ããã åèæ¬ã«å¹´æ«å²å¼ä¾¡æ ¼ã¨è¨å ¥ããããã«æ¡å ããã¾ããã â 2019/01/13 JCBã®ã»ãã¥ãªãã£æ å½ããé»è©± ã¯ã¬ã¸ããã«ã¼ãæ å ±ãä¸æ£å©ç¨ããã形跡ãããã¨ã®ãã¨ã ç¾å¨ã®ã«ã¼ãã¯åæ¢å¦çæ¸ã¿ã§æ°ããã«ã¼ããåçºè¡ä¸ã ç´è¿ã®æ³¨æãã12æååã¾ã§ã®ã«ã¼ãå±¥æ´ã®
ã³ã³ãã³ããããã¯ãæå¹ã§ãããã¨ãæ¤ç¥ãã¾ããã ãã®ãµã¤ããå©ç¨ããã«ã¯ãã³ã³ãã³ããããã¯æ©è½ï¼åºåãããã¯æ©è½ãæã¤æ¡å¼µæ©è½çï¼ãç¡å¹ã«ãã¦ãã¼ã¸ãåèªã¿è¾¼ã¿ãã¦ãã ããã â
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}