ããã³ã³ãªã©ã®ãªã³ã©ã¤ã³ã²ã¼ã ãæä¾ãã¦ãããµãã¼ãããã¯ã¼ã¯ã¹ã¯2010å¹´11æ13æ¥ãä¸æ£ã¢ã¯ã»ã¹ã«ããæ å ±æµåºã®è©³ç´°ãçºè¡¨ããï¼é¢é£è¨äºï¼ãæµåºããå人æ å ±ã¯173ä¸5841人åã§ãã²ã¼ã ãµã¤ãã®ãã°ã¤ã³IDã¨ãã¹ã¯ã¼ããã¡ã¼ã«ã¢ãã¬ã¹ã§ãããä¸æ£ã¢ã¯ã»ã¹ã®å½¢è·¡ãªã©ã確èªã§ããããããµãã¼ãããã¯ã¼ã¯ã¹ã¯ã·ã¹ãã éç¨å§è¨å ã§ããã¨ã«ããã¯ã¹ãéãã¦è¦å¯ã«è¢«å®³å±ãåºããã ãã°ã¤ã³IDãã¡ã¼ã«ã¢ãã¬ã¹ã®ã»ãã«ãå§ã®ã¿ãåã®ã¿ãéµä¾¿çªå·ã®ä¸é¨ã¨ãã£ãæ å ±ã®ä¸é¨ãæµåºããããããããåæ å ±ãç´ã¥ããããªãç¶æ ã§æµåºããã¨ãããã¯ã¬ã¸ããã«ã¼ãçªå·ã決æ¸æ å ±ã¯ã社å¤ã®æ±ºæ¸ä»£è¡ä¼ç¤¾ã®ã·ã¹ãã ã§ç®¡çãã¦ãããããä»åã®ä¸æ£ã¢ã¯ã»ã¹ã«ãã£ã¦æµåºãã¦ããªãã¨ãã¦ããã ãµãã¼ãããã¯ã¼ã¯ã¹ã®çºè¡¨ã«ãããããã¾ã§ã®çµç·¯ã¯ä»¥ä¸ã®éããã¾ããä¸æ£ã¢ã¯ã»ã¹ã®å åããã£ãã®ã¯11æ9æ¥ããªã³ã©ã¤ã³ã²ã¼ã ãµã¤ã
æ¥æ¬ã¢ã¤ã»ãã¼ã»ã¨ã æ ªå¼ä¼ç¤¾ï¼æ¥æ¬IBMï¼æ±äº¬SOCã¯11æ8æ¥ãInternet Explorerã®ã¼ããã¤èå¼±æ§ãæªç¨ãããã©ã¤ãã»ãã¤ã»ãã¦ã³ãã¼ãæ»æã確èªããã¨ãã¦ã¬ãã¼ããå ¬éãã¦ããããã®æ»æã¯ã11æ4æ¥ã«ãã¤ã¯ãã½ãã社ãå ¬éããMicrosoft Internet Explorerã«ã¼ããã¤èå¼±æ§ï¼CVE-2010-3962ï¼ãæªç¨ãããã®ã 11æ8æ¥ã«æ±äº¬SOCã確èªããæ»æã¯ããorip-dns.ruããipdnsje.ruãã®ãµã¼ãã«ãã¹ãããã¦ããããããã®ãµã¼ãã¯Internet Explorerã§ã¢ã¯ã»ã¹ããå ´åã«ã®ã¿æ¬ä»¶ã®ã¼ããã¤èå¼±æ§ãæªç¨ããæ»æãè¡ããã¾ããInternet Explorerã®èå¼±æ§ã ãã§ã¯ãªããAdobe ReaderãAdobe Flash PlayerãJavaãªã©ã®èå¼±æ§ãåæã«æªç¨ããã¦ããããã®æ»æãæåããã¨ãZeu
ã¡ã¼ã«ã»ãã¥ãªãã£ãµã¼ãã¹ä¼æ¥ã®ã¡ãã»ã¼ã¸ã©ã ã¸ã£ãã³ã¯ã10æã«ç¢ºèªãããã»ãã¥ãªãã£è å¨ã®ååãçºè¡¨ãããå°å£²æ¥çã®è¤æ°ä¼æ¥ãçãããæ¨çåæ»æãçºçãããã®æå£ã«ã¤ãã¦ç´¹ä»ãã¦ããã å社ã«ããã¨ãç¹å®ã®ä¼æ¥ãçãæ¨çåæ»æã¯æ¯ææ¥ç¨®ãå¤ãã¦çºçãã¦ããã対象ä¼æ¥æ°ã¯200ï½300社ã«ä¸ãã1æ¥ã«åºåãæ¨çåæ»æã®é»åã¡ã¼ã«ã¯å¹³å77éã¨ãªã£ã¦ããã10æã¯ããã¾ã§å ¨ä½ã®0.5ï¼ ç¨åº¦ï¼7件ï¼ã ã£ãå°å£²æ¥çãçãæ»æã25ï¼ ï¼516件ï¼ã«æ¥å¢ããã ãã®æ»æã§ã¯6社ã主ãªæ¨çã¨ããããã¡2社ãéä¸çã«çãããã¨ãããæ»æã¯1é±éãã¨ã«ç°ãªãææ³ã§3åçºçãããæåã®æ»æã§ã¯ã給ä¸ã«é¢ãã極ç§äºé ã¨ç§°ããã¡ã¼ã«ã人äºæ å½å¹¹é¨ã®ã¡ã¼ã«ã¢ãã¬ã¹ã§50人ã«éä¿¡ããããã¡ã¼ã«ã«ã¯æªè³ªãªPDFãã¡ã¤ã«ãæ·»ä»ããã¦ããã 2åç®ã®æ»æã¯ã転è·æ å ±ã¨é¡ããã¡ã¼ã«ãããããã³ãã£ã³ã°æ å½ãåä¹ã人ç©ã
Firefoxã§ãã¼ãã«å¹³åè³ã®Webãµã¤ããé²è¦§ããã¦ã¼ã¶ã¼ã¯ãç¥ããªããã¡ã«ãã«ã¦ã§ã¢ã«ææããå¯è½æ§ãããã¨ããã ãã«ã¦ã§ã¼ã®ã»ãã¥ãªãã£ä¼æ¥Normanã¯10æ26æ¥ãMozillaã®Webãã©ã¦ã¶Firefoxã®æªç¥ã®èå¼±æ§ãçªããã«ã¦ã§ã¢ãããã¼ãã«å¹³åè³ã®ãµã¤ãã«ææãã¦ããã®ãè¦ã¤ããã¨çºè¡¨ããã ãã¼ãã«å¹³åè³ãµã¤ãã®ææã¯ãNormanã®ç 究è ã26æ¥ã«çºè¦ããã¨ããããã«ã¦ã§ã¢ã¯Firefox 3.5ã¨3.6ã®èå¼±æ§ãæªç¨ããæ°æã®ããã¤ã®æ¨é¦¬ã§ããããã®Webãã©ã¦ã¶ã§åãµã¤ããé²è¦§ããå ´åãç¥ããªããã¡ã«ææããå¯è½æ§ãããã¨ãã¦ããã ãã®ããã¤ã®æ¨é¦¬ã¯å°æ¹¾ã«ãããµã¼ãã«æ¥ç¶ã試ã¿ãæ¥ç¶ã«æåããã¨æ»æè ãææå ã®ã³ã³ãã¥ã¼ã¿ã«ã¢ã¯ã»ã¹ã§ããç¶æ ã«ãªã£ã¦ãã¾ããã»ãã®Webãµã¤ãã«ãææãã¦ããå¯è½æ§ãããã¨Normanã¯è¦åãã¦ããã SANS Intern
ç´ æ´ãããã§ãããï¼ãããã§ãä¸ç¨å¿ãªã¦ã¼ã¶ã¼ã¯ãff_secure_upd.exeãããã¦ã³ãã¼ãããä¸æ£ãªAVï¼ã¢ã³ãã¦ã¤ã«ã¹ã½ããï¼ãã¤ã³ã¹ãã¼ã«ãããã¨ã«ãªããããããªãã å®éã¯â¦â¦ãã¹ã¯ãªãããWebãã©ã¦ã¶ã§è¨±å¯ãããã¨ããDownload Updatesï¼ããã¿ã³ãã¯ãªãã¯ããå¿ è¦ãããªãããã ã¦ã¼ã¶ã¼ã«ä¸æ£ãªAVããªãã¡ã¼ããã®ã ã çµå±ãã¦ã¼ã¶ã¼ã¯Firefoxãã¢ãããã¼ããã¹ãã¨ãããã¨ã ãããï¼ãããã¦ãåã¢ããªã±ã¼ã·ã§ã³ã¯ããä¸åº¦ãã¦ã³ãã¼ãããäºåº¦ç®ã®æ©ä¼ãä¸ããç¹ã§å¯å¤§ã ã ç®èãªã®ã¯ãåãã¼ã¸ããæ»æãã¼ã¸ã®ä¸ã«ã¯ãæ æã«æ害ãªã½ããã¦ã§ã¢ãé å¸ãã¦ãããã®ããããã¨ããæ¡é ãå«ãã§ãããã¨ã ããã©ã¡ããé¸æãããã以ä¸ã®ãã¿ã³ãã¯ãªãã¯ãã¦ä¸ãããã¨ããæ¡é ãå ãã¦ãè¯ãã£ããããããªãã æ°ããªç´ æ´ãããããªãã¯ã ããããªãå§æ¯ã ãããã¦ä¸æãè¡ããã
Webèµæ¸æ¤ç´¢ã·ã¹ãã ããã¦ã³ãããã¨ãã¦ãæªæã®ãªãå©ç¨è ã5æã«é®æãããæç¥ç岡å´å¸ç«ä¸å¤®å³æ¸é¤¨ãããããæ°ããªå人æ å ±æµåºäºä»¶ãçºçããã åå³æ¸é¤¨ã¯ãä¸è±é»æ©ã¤ã³ãã©ã¡ã¼ã·ã§ã³ã·ã¹ãã ãºï¼MDISï¼ã®å³æ¸é¤¨åãããã±ã¼ã¸ãMELILï¼ã¡ãªã«ï¼/CSããæ¡ç¨ãããMDISã¯åããã±ã¼ã¸ãã岡å´å¸ç«ä¸å¤®å³æ¸é¤¨ã®å©ç¨è æ å ±163人åãå«ããç¶æ ã§ãä»ã®37ã«æã®å³æ¸é¤¨ã«è²©å£²ããããã®çµæãä»ã®å³æ¸é¤¨ã®ã·ã¹ãã ãéãã¦ãå©ç¨è æ å ±ãã¤ã³ã¿ã¼ãããã«æµåºããã ããã±ã¼ã¸ã«é¡§å®¢æ å ±ãç´ãè¾¼ãå代æªèã®äºä»¶ã®åå ã¨ãæ å ±æµåºã®çµç·¯ã¯ããã ãMDISã¯MELIL/CSã®ããã±ã¼ã¸ãéçºããéã«ã岡å´å¸ç«ä¸å¤®å³æ¸é¤¨ã§ç¨¼åããASPï¼Active Server Pagesï¼å½¢å¼ã®ã¹ã¯ãªãããã¡ã¤ã«ããã¼ã¿ã使ã£ãããã®ä½æ¥ã«åé¡ããããåå³æ¸é¤¨ã«ããã2005å¹´6ææ«æç¹ã®å»¶æ»è ãã¼ã¿ãããMic
NTTæ±æ¥æ¬ã¯2010å¹´10æ19æ¥ã10æ7æ¥ã«çãããã¬ãã å ãã¯ã¹ãåç·ããã¤ã³ã¿ã¼ãããã«æ¥ç¶ã§ããªãé害ãçºçãã件ã«ã¤ãã¦ããã®åå ã¨åçºé²æ¢çã®æçµå ±ãå ¬è¡¨ããã ä»åèµ·ãã£ãé害ã¯ããã¬ãã å ãã¯ã¹ãã¦ã¼ã¶ã¼ã®ä¸é¨ã«ã¤ã³ã¿ã¼ãããã«æ¥ç¶ã§ããªãäºè±¡ãèµ·ãã£ãã¨ãããã®ï¼é¢é£è¨äºï¼ãåå ã¯ããã¬ãã å ãã¯ã¹ãç¨ã®ä¸ç¶ç¶²ãNGNãå é¨ã«è¨ç½®ãã¦ããDNSãµã¼ãã¼ã®ä¸é¨ã«é害ãçºçããããã¨ãã¦ãããã¤ã¾ãé害ã®å 容ã¯ãæ£ç¢ºã«ã¯ãã¤ã³ã¿ã¼ãããã«æ¥ç¶ãã¦ããã¨ãã«æ¥ç¶å ãµã¼ãã¼ã®åå解決ãã§ããªãã£ããã¨ãããã¨ã«ãªããä¾ãã°ã¡ã¼ã«ã½ãããªã©ã«éåä¿¡ç¨ã®ãµã¼ãã¼ãç´æ¥IPã¢ãã¬ã¹ã§æå®ãã¦ããå ´åã¯ãé害çºçä¸ã§ãã¤ã³ã¿ã¼ãããçµç±ã§ã¡ã¼ã«ã®éåä¿¡ã¯ã§ããã¨ããããã ããWebãã¼ã¸ã¸ã®ã¢ã¯ã»ã¹ãªã©ãä¸è¬ã«æ¥ç¶å ãµã¼ãã¼åãæå®ãã¦ä½¿ãã¢ããªã±ã¼ã·ã§ã³ã¯ãå©ç¨ã§ããªãç¶æ ã«
ãã£ã³ã©ã³ãã®ã»ãã¥ãªãã£ä¼æ¥ã¨ãã»ãã¥ã¢ã¯2010å¹´10æ20æ¥ãWebãã©ã¦ã¶ã¼ãFirefoxããªã©ã®ã»ãã¥ãªãã£è¦åç»é¢ã«è¦ããããæªè³ªãµã¤ãã確èªããã¨ãã¦æ³¨æãå¼ã³ãããããã©ã¦ã¶ã¼ã®ã»ãã¥ãªãã£ã¢ãããã¼ãï¼ä¿®æ£ãããï¼ã¨ç§°ãã¦ãå½ã½ããï¼å½ã»ãã¥ãªãã£ã½ããï¼ãã¤ã³ã¹ãã¼ã«ããããã¨ããã Firefoxãªã©ã®ãã©ã¦ã¶ã¼ã«ã¯ãå±éºãªãµã¤ãã¸ã®ã¢ã¯ã»ã¹ããããã¯ããæ©è½ããããå±éºãªãµã¤ãã¨ãã¦å ±åï¼ç»é²ï¼ããã¦ãããµã¤ãã«ã¢ã¯ã»ã¹ãããã¨ããã¨ãè¦åç»é¢ã表示ãã¦ããµã¤ãã表示ãããªãã ä»åå ±åãããæªè³ªãµã¤ãã¯ããã®æ©è½ãæªç¨ãããWebãã¼ã¸ã®ãã¶ã¤ã³ãè¦åç»é¢ã«é ·ä¼¼ããã¦ãã¢ã¯ã»ã¹ããã¦ã¼ã¶ã¼ã«è¦åã表示ãããã¨æãããï¼å³1ï¼ã å½ã®è¦åãã¼ã¸ã§ã¯ãæ¬ç©ã®è¦åã«ã¯åå¨ããªããDownload Updatesï¼ããã¿ã³ãç¨æããã®ãã¿ã³ãæ¼ãã¨ãFirefoxã®ã»ã
ã»ãã¥ãªãã£ä¼æ¥ã®è±ã½ãã©ã¹ã¯2010å¹´10æ14æ¥ã2010年第3ååæï¼7æãã9æï¼ã«ãããè¿·æã¡ã¼ã«ã®éä¿¡ç¶æ³ãªã©ãå ¬è¡¨ããããã®æéä¸ãå社ã観測ããè¿·æã¡ã¼ã«ã®ããã2å²ã¯ãç±³å½ã«åå¨ããã³ã³ãã¥ã¼ã¿ã¼ããéä¿¡ãããã¨ããã å社ã§ã¯ãè¿·æã¡ã¼ã«ãåéããã³ã³ãã¥ã¼ã¿ã¼ãã¤ã³ã¿ã¼ãããä¸ã«å¤æ°è¨ç½®ããè¿·æã¡ã¼ã«ã®éä¿¡ç¶æ³ãã¡ã¼ã«ã®å 容ãªã©ã調æ»ããã®çµæãéè¨ããååæãã¨ã«å ¬è¡¨ãã¦ãããä»åå ¬è¡¨ããã®ã¯2010年第3ååæåã ã½ãã©ã¹ãåæéä¸ã«è¦³æ¸¬ããè¿·æã¡ã¼ã«ã®18.6ï¼ ã¯ãç±³å½ã®ã³ã³ãã¥ã¼ã¿ã¼ããéä¿¡ï¼è»¢éï¼ããã¦ããï¼å³ï¼ãåå½ããã®è¿·æã¡ã¼ã«ã¯ã2010年第2ååæã®15.2ï¼ ããæ¥å¢ããã次ãã§ãã¤ã³ãã7.6ï¼ ããã©ã¸ã«ã5.7ï¼ ããã©ã³ã¹ã5.4ï¼ ãè±å½ã5.0ï¼ ãªã©ã ã£ãã å社ã«ããã°ãè¿·æã¡ã¼ã«ãéä¿¡ãã¦ããã®ã¯ãã¦ã¤ã«ã¹ã«ææãããã½ã³ã³ãã»ã¨ãã©ã
ãã®æãã®æã§ä»æããããæ»æã®ä¸ã«ã¯ãã¦ã¤ã«ã¹å¯¾çã½ãããããã£ã¦ä¸æ£ãªããã°ã©ã ãã¤ã³ã¹ãã¼ã«ããããã®ããããESETã¯ãå社ã®ã½ããã¦ã¨ã¢ããããå½ã½ãããåºåã£ã¦ãããã¨ãããããã°ã§ãã®å 容ã対å¦æ¹æ³ã解説ãã¦ããï¼Imitation is not always the sincerest form of flatteryï¼ã被害ãã§ããéãé¿ããããããã«ãæè¿ã®å½ã½ãããã©ã®ããã«åãã®ããç¥ã£ã¦ããã¨ããã ããã å社ã®ã»ãã¥ãªãã£è£½åãESET Smart Securityãããããå½ã½ããã®ååã¯ãSmart SecurityããESETã®ã¦ã¤ã«ã¹å¯¾çã½ããã§ã¯ãSmart Securityã¨ãã®äºç¨®ãMySecurity EngineããMySecurityShieldããªã©ããWin32/Injector.DDHãã¨ãã¦æ¤åºããããããã®ãã«ã¦ã¨ã¢ãèµ·åå¾ã«è¡¨ç¤ºã
人çºãã¹ãåå ã§è¨å®ã«ä¸åããã£ãMirosoftã®ãããã¯ã¼ã¯ãã¼ãã¦ã§ã¢ç«¯æ«2å°ãä¹ã£åãããæ»æã«å©ç¨ããã¦ããã¨ããã ç±³Microsoftã®ã³ã³ãã¥ã¼ã¿ã¼ããããã³ã°ãããå½ã®å»è¬å宣ä¼ãµã¤ãã®éå¶ãã»ãã®Webãµã¤ãã«å¯¾ãããµã¼ãã¹å¦¨å®³ï¼DoSï¼æ»æãªã©ã«ä½¿ããã¦ãããã¨ãåãã£ãã¨ãç±³ã»ãã¥ãªãã£æ å ±ããã°ã®Krebs on Securityãä¼ããã Krebs on Securityã¯ãã»ãã¥ãªãã£åé¡ãå°éã¨ããã¸ã£ã¼ããªã¹ãã®ãã©ã¤ã¢ã³ã»ã¯ã¬ããºæ°ãéå¶ãã¦ãããåæ°ã«ããã°ããã®ããã°ã9æ23æ¥ã«ãç´24æéã«ãããDoSæ»æãåããããã®å¾å¥ã®ç 究è ãããæ»æã«ä½¿ãããIPã¢ãã¬ã¹ã®ä¸ã«ãMicrosoftã®ã¢ãã¬ã¹ã¨æããããã®ããã£ãã¨ã®å ±åãå¯ããããã¨ããã ç 究è ã«ããã°ãç¯è¡ã°ã«ã¼ãã¯ãã®Microsoftã®IPã¢ãã¬ã¹ã§ãä¹ã£åã£ããã·ã³ããã¡ã¤ã³
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}