Sophosã®è¡é ã¤ã³ã¿ãã¥ã¼ã«å¿ããéè¡äººã®ãã¡ãæ°åãªã©ã®å人æ å ±ãä¸åæãããªãã£ãã®ã¯1人ã ãã ã£ãã ã»ãã¥ãªãã£ä¼æ¥ã®è±Sophosã¯10æ19æ¥ãè¡ã§éè¡äººã«ã«ã¡ã©ãåãã¦æ°åãªã©ãèãåºãå®é¨ãè¡ã£ãã¨ãããã¾ã£ããç¥ããªãç¸æã«å人æ å ±ãæãã¦ãã¾ã人ã大å¤æ°ãå ããã¨çºè¡¨ããã Sophosã¯å é±è±å½ã§å®æ½ããããå人æ å ±çé£é²æ¢é±éãã«åãããè¡ã§éè¡äººã«ã«ã¡ã©ãåãã¦ãªããã¾ãã«é¢ããè¡é ã¤ã³ã¿ãã¥ã¼ãå®æ½ããã®çµæã声ããããéè¡äººã®80ï¼ ãã¤ã³ã¿ãã¥ã¼ã«å¿ãã¦ããããã®ãã¡ä¸åå人æ å ±ãæããã¦ãããªãã£ãã®ã¯1人ã®ã¿ãã»ãã¯å ¨å¡ãæ°åãåä¹ããã»ã¨ãã©ã¯èªçæ¥ã¨é»åã¡ã¼ã«ã¢ãã¬ã¹ã¾ã§æãããã¨ããã ãã®å®é¨ã¯ãå人æ å ±çé£é²æ¢é±éã®æçµæ¥ã«å®æ½ãã¦ããããã£ã³ãã¼ã³ãåçºã®å½¹ã«ç«ã£ã¦ããªããã¨ãåãã£ãã¨Sophosã¯è§£èª¬ã質åã«å·¥å¤«ãåããã¦ãã£ã¨æéãã
ä¸æ£ãªã³ã¼ããèªã¿è¾¼ã¾ãããã¦ãï¼ã»ãã¥ãªãã£å¯¾çã½ããã§æ¤åºã§ããã®ã§ã¯ãªããã¨èãã人ãå¤ãã ãããã ãï¼æè¿ã§ã¯ãããã®ã½ããã®ç®ããã¾ããæ¹é ãåãããã¦ãããã»ãã¥ãªãã£å¯¾çã½ããã使ã£ã¦ãã¦ãï¼ããæãããã¦ãã¾ãã±ã¼ã¹ãå¢ãã¦ããã®ã ã第2åã§ã¯ï¼ããããé²å¾¡ããããããããªãã¯ã解説ããã ã³ã¼ãã®é£èªåã§æ¤åºãéãã å ¸åçãªã®ã¯ãã³ã¼ãã®é£èªåãã¨å¼ã°ãããã®ãæ»æã³ã¼ãã¨ãã¦ã®å¹æã¯å¤ããã«ï¼æååããããåã®ãã¿ã¼ã³ãå¤ãã¦ãã¾ããç°¡åã«è¨ãã°ï¼æå·åã®ä¸ç¨®ã¨èããã°ããããã½ã³ã³ã«æ¸¡ããã¼ã¿ãå¥ã®ãã¿ã¼ã³ã«å¤ãããã¨ã§ï¼ãã¿ã¼ã³ã»ãããã³ã°ã§ä¸æ£ãªã³ã¼ããè¦ã¤ããã»ãã¥ãªãã£å¯¾çã½ããã®ãã§ãã¯ããããããã é£èªåã®æ¹æ³ã¯ç¡æ°ã«ãããä¸æ£ãªã³ã¼ãã¯ã¹ã¯ãªããã®å½¢ã§éããããã¨ãå¤ããç°¡æããã°ã©ãã³ã°è¨èªã§ããã¹ã¯ãªãããªãï¼ããªãè¤éãªå¦çã§ãï¼Webãã©ã¦ã¶
æ¬å®¶/.ã®è¨äºãããHotmailãYahooã¨ãã£ãç¡æã¡ã¼ã«ã¢ã«ã¦ã³ãã®å¤§éèªåä½æã«æåããã¹ããã¼ãããããããã»ãã¥ãªãã£ä¼æ¥BitDefenderã«ããã°ããã§ã«15,000以ä¸ã®Hotmailã¢ã«ã¦ã³ããæ©æ¢°çã«ä½æããã¦ããã¨ãããHotmailãYahooãCAPTCHAãæ¡ç¨ãã¦ãããããã¹ããã¼ã¯CAPTCHAã®çªç ´ã«ä½ããã®æ段ã§æåããã¨ãããã¨ã«ãªã(TECH.BLORGE.comã®è¨äº)ãã¾ããèªåçã«ä½æãããYahooãHotmailã®ã¢ã«ã¦ã³ããã¹ãã ã¡ã¼ã«ã®éä¿¡ã«æªç¨ããããã¤ã®æ¨é¦¬ãTrojan.Spammer.HotLan.Aãç»å ´ããããã ã CAPTCHAã®çªç ´ã«é¢ãã¦ã¯ãæ¬ç©ã®äººéã使ã£ã人海æ¦è¡ããå½è£ ãµã¤ãã«ãã³ãå¯ãã人éã«ä»£ããã«CAPTCHAãçªç ´ãã¦ãããã¨ãã£ãæ¯è¼çãã¼ãã¯ãªææ³ãããAIãæ©æ¢°çç»åèªèã¢ã«ã´ãªãºã ãå©ç¨ãã
â ã±ã¼ã¿ã¤Webã¯ããããå±éº ããã¾ã§ã®èæ¯ã¨æè¿ã®ç¶æ³å¤å ãå®å ¨ãªWebãµã¤ãå©ç¨ã®éåãã«ããéãããã£ãã·ã³ã°ã«é¨ãããã«Webãå®å ¨ã«ä½¿ãåºæ¬æé ã¯ãï¼ãã¹ã¯ã¼ããã«ã¼ãçªå·ãªã©ã®ï¼éè¦ãªæ å ±ãå ¥åããç´åã«ä»è¦ã¦ãããã¼ã¸ã®ã¢ãã¬ã¹ã確èªãããã¨ãªã®ã ãããã°ãã°ãããã®ãã¼ã¸ã«ã¢ã¯ã»ã¹ããåã«ã¸ã£ã³ãå URLã確èªãããã¨ããæé ãæ²ãã人ããããããããããã¯æ¬¡ã®çç±ã§å¤±å½ã§ããã ã¸ã£ã³ãå URLã確èªããæ段ããªããã¹ãã¼ã¿ã¹ãã¼ã¯å¤æ¥ããJavaScriptã§èªç±ã«æ¸ãæãããã表示æ¬ã¨ããã¦ããã®ã§ãããã¸ã£ã³ãå ã®ç¢ºèªã«ä½¿ããªãã ã¸ã£ã³ãå URLãäºåã«ç¢ºèªããã¨ãã¦ãããããï¼ä»»æãµã¤ãã¸ã®ï¼ãªãã¤ã¬ã¯ã¿ã«ãªã£ã¦ããå ´åãæçµçã«ã©ãã¸ã¢ã¯ã»ã¹ãããã¨ã«ãªããä¸æã ãããããã¢ã¯ã»ã¹ããåãããã¢ãã¬ã¹ç¢ºèªã®å¿ è¦æ§ãäºè¦ã§ããã¨ã¯éããªããæ®éã¯ãã¢ã¯ã»
2007/06/19 å人æ å ±ãå£åº§æ å ±ã購買履æ´ã¨ãã£ãéè¦æ å ±ã«ä¸æ£ã¢ã¯ã»ã¹ã§ããWebãµã¤ãã¯å ¨ä½ã®42ï¼ ãä¾ç¶ã¨ãã¦å¤ãã®Webãµã¤ããã»ãã¥ãªãã£ä¸ã®åé¡ãæ±ãã¦ããââãã»ãã¥ãªãã£è¨ºæãµã¼ãã¹ãæä¾ããNRIã»ãã¥ã¢ãã¯ããã¸ã¼ãºã¯6æ19æ¥ã2006年度ã«å社ãåè¨ãã146ã®Webãµã¤ãã®è¨ºæçµæãåæããã¬ãã¼ããå ¬éããã ã¬ãã¼ãã¯ä»å¹´ã§3å¹´ç®ãéå»3å¹´éãéãã¦ã»ãã¥ãªãã£ä¸ã®åé¡ãæ±ããWebãµã¤ãã¯å ¨ä½ã®40ï½50ï¼ ã§æ¨ç§»ãã¦ããããã»ãã¥ãªãã£æèã¯é«ã¾ã£ã¦ãããããã®ä¸æ¹ã§ä¸æ£ã¢ã¯ã»ã¹ã®ææ³ãé«åº¦åãã¦ãããããã¡ãã£ãã®ç¶æ ãç¶ãã¦ãããéå»3å¹´éã§å®å ¨æ§ã¯ãã¾ãæ¹åãã¦ããªããï¼NRIã»ãã¥ã¢ãã¯ããã¸ã¼ãº ã³ã³ãµã«ãã£ã³ã°äºæ¥é¨ 主任ã³ã³ãµã«ã¿ã³ã é´¨å¿ç°æè¼æ°ï¼ã å é¨é¢ä¿è ã®ã¿ãã¢ã¯ã»ã¹ããæ¥åã·ã¹ãã ã«éã£ã¦ã¿ãã°ãå ¨ä½ã®74ï¼ ã§éè¦æ å ±ã¸ã®ä¸
OpenOfficeã®ããã¥ã¡ã³ããã¿ã¼ã²ããã«ãããã«ã¦ã§ã¢ããMac OSãWindowsãLinuxãå«ãè¤æ°ã®OSãéãã¦ææãåºãã¤ã¤ããã¨ãSymantecãè¦åãçºãã¦ããã Symantec Security Responseã®ã¦ã§ããµã¤ãã«ããã¨ããã®ã¯ã¼ã ã¯è¤æ°ã®OSãã©ãããã©ã¼ã ã«ææå¯è½ã§ãææã®ç¯å²ãåºããã¤ã¤ããã¨ããã Symantecã®å§åã«ã¯ããæ°ããã¯ã¼ã ã¯æªè³ªãªOpenOfficeããã¥ã¡ã³ãã¨ã¨ãã«é ä¿¡ããã¦ããããã®ã¯ã¼ã ã¯WindowsãLinuxãããã³Mac OS Xã®åã·ã¹ãã ã«ææãããç¥ããªã人ããåãåã£ãOpenOfficeãã¡ã¤ã«ã®åãæ±ãã«ã¯æ³¨æãããããã¨ããã ã¦ã¤ã«ã¹å¯¾çã®åéã«ããã¦Symantecã¨ç«¶åããSophosã®å ±ååµæ¥è ã§ãPCã¦ã¤ã«ã¹å¯¾çã®èåãã§ãããJan Hruskaå士ã¯ç±³å½æé6æ7æ¥ãZDNe
ãã·ã¢ã®ç¹å®ãµã¤ãã§çºè¦ãããå¾ã ã«ã»ãã®ãµã¤ãã¸ã¨åºãã£ã¦ããã¨ã¯ã¹ããã¤ãã®éçºãããã¯ãWebAttacker2ã§ã¯ãªããMPACKã§ãããã¨ãåãã£ããã»ãã¥ãªãã£ã½ããä¼æ¥Exploit Prevention Labsãå ¬å¼ããã°ã§å ±åãããWebAttackerã¯ãã·ã¢ã®ãµã¤ãã§è³¼å ¥ã§ããã¹ãã¤ã¦ã§ã¢éçºãããã§ããããå©ç¨ããã°ç°¡åã«æ»æãµã¤ããä½æã§ããã å社ã¯WebAttackerã¨ã¯ç°ç¨®ã®ãã«ã¦ã§ã¢éçºãããã販売ããã¦ããäºå®ã¯ææ¡ãã¦ããããã ãMPACKã¯ããµã¤ãã®ãã¸ã¿ã¼ã®IPã追跡ããåä¸ãã·ã³ããåãã¨ã¯ã¹ããã¤ããã³ãã¼ãããã¨ããã¨ãç³ã訳ããã¾ããããããªãã®IPã¯ãããã¯ããã¦ãã¾ããã¨ã¡ãã»ã¼ã¸ã表示ãããã MPACKã¯ã¨ã¯ã¹ããã¤ãã追å ããæå·ãå¤ãç¶ãããææ°çã§ã¯ãç³ã訳ããã¾ããï½ãã®ã¡ãã»ã¼ã¸ã§ã¯ãªããé¡æåã®ã¿ã表示ãããããã ã
æ¬ãã¼ã¿ãã¼ã¹ã¯ãIPA ã«å±åºãããã¦ã¤ã«ã¹ãããããªã©ãä¸å¿ã«ããããã®ä¸»ãªåä½å 容ã対å¦æ³ãªã©ã®è§£æçµæãå ¬éããã·ã¹ãã ã§ããã¦ã¤ã«ã¹ã®å称ããã¡ã¤ã«åãå©ç¨ãã¦æ¤ç´¢ãããã¨ã§ç®çã®ã¦ã¤ã«ã¹ã«é¢ããæ å ±ãè¦ããã¨ãã§ããææã®äºé²ã対çãªã©ã«æ´»ç¨ã§ãã¾ãã ç»é²æ¥ã¯ãµã³ãã«ãåãã¦è§£æãããæ¥ã表示ãã¦ãã¾ãã
ãµã¤ãã¼ã¯ãªã¼ã³ã»ã³ã¿ã¼ã¯ãã¤ã³ã¿ã¼ãããã«ãããè å¨ã¨ãªã£ã¦ãããããã¦ã¤ã«ã¹ã®ç¹å¾´ã解æãããã¨ã«ãããã¦ã¼ã¶ã®ã³ã³ãã¥ã¼ã¿ãããããã¦ã¤ã«ã¹ãé§é¤ããããã®ãããã¦ã¤ã«ã¹é§é¤ãã¼ã«ãCCCã¯ãªã¼ãã¼ããä½æããã¦ã¼ã¶ã¼ã«é å¸ããæ´»åãè¡ã£ã¦ãã¾ãã
Macããããã³ã°ããã³ã³ãã¹ããå é±éå¬ããã1å°ã®ãMacBookãããããã³ã°ããããããã«å©ç¨ãããã»ãã¥ãªãã£ãã¼ã«ã¯ãAppleã®ã¡ãã£ã¢ãã¬ã¼ã¤ã¼ãQuickTimeãã«åå¨ãã¦ããã¨ããããã®èå¼±æ§ã®çºè¦è ãç±³å½æé4æ24æ¥ã«æããã«ããã ã»ãã¥ãªãã£ç 究è ã§ããDino Dai Zoviæ°ã«ããã¨ããã®èå¼±æ§ã¯QuickTimeã«ããJavaã®å¦çã«é¢é£ãããã®ã ã¨ãããæ»æè ã¯ãSafariããããã¯ãFirefoxããéãã¦ãã®èå¼±æ§ãæªç¨ã§ããã¨ãåæ°ã¯èªã£ã¦ãããå½åã®å ±åã§ã¯ããã®èå¼±æ§ã¯Appleã®ã¦ã§ããã©ã¦ã¶ã§ããSafariã«åå¨ãããã®ã ã¨ããã¦ããã Dai Zoviæ°ã¯ãããã®èå¼±æ§ã¯QuickTimeã«åå¨ãããMac OS Xã®Safariã¨Firefoxãæ»æãåãããããªã£ã¦ãããã¨èªã£ã¦ãããåæ°ã«ããã¨ãQuickTimeã¯Wind
Web 2.0ã¨ããè¨èã§ç·ç§°ãããæ°ããªã¤ã³ã¿ã¼ãããæ代ãWebãµã¤ããã¨ã³ãã¦ã¼ã¶ã¼ã«ä»æããããæ»æãã¾ãï¼2.0ã¨å¼ã¶ã¹ãé²åãéãããã¨ãã¦ãããæ»æè ã¯Web 2.0ã®ä¸æ ¸æè¡ã§ããJavaScriptãæªç¨ãã¦ãã©ã¦ã¶ãçãã第2åç®ã¨ãªãä»åã¯ï¼ä»ããã«ããå±æ©ã«è¿«ãã Zone-Hã®å ´åï¼ç¯äººã¯èªå·±é¡ç¤ºãç®çã¨ãã¦ããããï¼è¢«å®³ã¯ãã¼ã¸æ¹ããç¨åº¦ã§æ¸ãã ããããï¼ç¯ç½ªè ã®çã次第ã§å±éºåº¦ã¯ãã£ã¨é«ã¾ãï¼å³3ï¼ã å³3âXSSã®ããå¼±æ§ãçªããã¨ã§å¯è½ã«ãªãæ»æ ãã¼å ¥åã®çé£ãä»ãµã¤ãã¸ã®æ»æãªã©ã¦ã¼ã¶ã¼ãç¥ããªããã¡ã«ï¼èå¾ã§ã®æ»æãå¯è½ã«ãªãã [ç»åã®ã¯ãªãã¯ã§æ¡å¤§è¡¨ç¤º] ä¾ãã°éè¡ã証å¸ä¼ç¤¾ã®Webãµã¤ãã«XSSã®ç©´ãããã°ï¼ã¯ããã¼ãçã¾ãï¼ä¸æ£ééãªã©ã«ã¤ãªãããããããªããçãã ã¯ããã¼ã使ã£ã¦æ¥åã§ä½¿ç¨ãã¦ããWebã¡ã¼ã«ãçã¿è¦ãããã°ï¼éçºãå¶æ¥ã®è³
æ¥ã éä¿¡ãããã¹ãã ã¡ã¼ã«ãè¿·æã¡ã¼ã«ãè©æ¬ºãµã¤ããä¸æ£ã¹ãã ãµã¤ããªã©ã®æ å ±ããªã¹ãåãã¦ã¦ã¼ã¶ã¼å士ã§å ±æãããã¨ã«ãã£ã¦ãè¿·æãªãµã¤ããæ²æ» ãããã¨ãããµã¼ãã¹ã ã¾ããAPIãå©ç¨ãã¦ã¹ãã ãã¼ã¿ãã§ãã¯ã»ãªã¹ãåå¾ãå¯è½ãªã®ã§ãããããã¨å¿ç¨ã®å¹ ãåºããããã§ãã 詳細ã¯ä»¥ä¸ã®éãã FC2ã¹ãã 対ç http://seo.fc2.com/spam/ 以ä¸ãããè¿·æã¡ã¼ã«ãµã¤ããè¿·æãã©ãã¯ããã¯ãµã¤ããããã¿è¬ã»ãã«ãã»ãããã¯ã¼ã¯ãã¸ãã¹ãµã¤ããè©æ¬ºãµã¤ããã¢ãã«ããµã¤ããåºä¼ãç³»ãµã¤ããªã©ã§æ¤ç´¢ã§ãã¾ãã ã¹ãã æ å ±æ¤ç´¢ APIã®å©ç¨ã«ã¤ãã¦ã¯ä»¥ä¸ã®éãã â APIã®å©ç¨ã«é¢ã㦠ã¹ãã ãã¼ã¿ãã§ãã¯ã»ãªã¹ãåå¾API ãã«ã ããã§å¤å°ã¯ç¾ç¶ãæ¹åããã®ã§ããããï¼ãããã¯ãAkismetã®ãããªå¼·åãªå¯¾ã¹ãã ãã©ã°ã¤ã³ãæ¥æ¬èªåãã«ä½ãããã®ããªâ¦â¦ï¼
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}