ãLINEã¤ãã¼Design å ¬å¼noteã LINEã¤ãã¼æ ªå¼ä¼ç¤¾ã®ãã¶ã¤ã³ã«é¢é£ãããã¾ãã¾ãªæ å ±ãçºä¿¡ããLINEã¤ãã¼Design å ¬å¼noteã§ãã
apache ã nginx ã®è¨å®ããããã¨ãããã°ä»¥ä¸ã®æ§ãªè¡ãè¦ããã¨ããã人ãå¤ãã®ã§ã¯ãªãã§ããããã(â» ä¸è¨ã¯ nginx ã®è¨å®ãapache ã®å ´å㯠SSLCipherSuite ã§ãã) ssl_ciphers AES128-SHA:AES256-SHA:RC4-SHA:DES-CBC3-SHA:RC4-MD5; ãããæå·ã¹ã¤ã¼ããæå®ãã¦ããç®æã§ããããã¦ãã®é¨åãããã®ããããªãæååã®ç¾ åãªã®ã§ãããåã£ã¤ãã«ããã¦ä½ãæå®ããããããããããªãã®ã§ãã³ãããã¦ãã¾ã人ãå¤ãããããªãã§ãããããããããç§ãæ°å¹´åã«è¶£å³ã§ TLS 対å¿ã® Web ãµã¼ãã¹ãä½ã£ãæã¯ã³ããã§æ¸ã¾ãã¦ãã¾ããããã®æå·ã¹ã¤ã¼ãã¯ã以ä¸ã®ãã㪠OpenSSL ã®ã³ãã³ãã使ã£ã¦å¯¾å¿ãã¦ããä¸è¦§ãè¦ããã¨ãã§ãã¾ãã $ openssl ciphers -v AES128-SH
Operators of vulnerable servers need to take action. There is nothing practical that browsers or end-users can do on their own to protect against this attack. Is my site vulnerable? Modern servers and clients use the TLS encryption protocol. However, due to misconfigurations, many servers also still support SSLv2, a 1990s-era predecessor to TLS. This support did not matter in practice, since no up
2016å¹´3æ1æ¥(ç¾å°æé)ãOpenSSL ããã¸ã§ã¯ãã¯èå¼±æ§ã®æ称ãDROWNãããCacheBleedããå«ã8件ã®èå¼±æ§æ å ±ãå ¬éãããããå½±é¿ãåãããã®ã®ä¿®æ£ãè¡ã£ãææ°çããªãªã¼ã¹ãã¾ãããããã§ã¯é¢é£æ å ±ãã¾ã¨ãã¾ãã èå¼±æ§æ å ±æ¦è¦ 注æåèµ· OpenSSL ã®è¤æ°ã®èå¼±æ§ã«é¢ãã注æåèµ· - JPCERT/CC SSLv2 DROWN Attack - US-CERT OpenSSL Projectã®å ¬éæ å ± Forthcoming OpenSSL releases OpenSSL Security Advisory ï¼»1st March 2016ï¼½ OpenSSL version 1.0.1s published OpenSSL version 1.0.2g published An OpenSSL Userâs Guide to DROWN 2016å¹´3æ1æ¥å ¬
å®å ¨ã«é£ãã¿ã¤ãã«ã§ããã©ä¸èº«ã¯çé¢ç®ã«æ¸ããã è¿å¹´ãã¦ã§ããµã¤ãã®HTTPSåãæµè¡ã®ããã«ãªã£ã¦ãããç§ã®ç¥ãéããGoogleã®å種ãµã¼ãã¹ãTwitterãFacebookãªã©ãå®å ¨ã«HTTPSã§éä¿¡ãè¡ãããã«ãªã£ã¦ãããHTTPSãã¤ã¾ãSSLã«ããéä¿¡ã®æå·åã«ãã£ã¦ãã¦ã¼ã¶ã«ããã¾ã§ãããå®å ¨ãªã¦ã§ããµã¤ããæä¾ã§ããã ããããããªããä½ã£ã¦ãããµã¤ãããµã¨æãã¤ãã§HTTPSåãã¦ãã¾ãã¨ããã¶ããããã¾ã§ããããµã¤ããé ããªããããã§ã¯ãHTTPSã§éä¿¡ããå ´åã®åé¡ã解説ããã ãªãé ããªãã®ã HTTPã§éä¿¡ããå ´åãã¯ã©ã¤ã¢ã³ãããµã¼ãã¸ã¨æ¥ç¶ããããã«ã¯TCP/IPã®3ã¦ã§ã¤ãã³ãã·ã§ã¤ã¯ã¨ããæé ãå¿ è¦ã«ãªããããã©ãããã®ã§ããã§ã¯è©³ããã¯èª¬æããªãããè¦ããã«ã¯ã©ã¤ã¢ã³ãããªã¯ã¨ã¹ããæããåã«ãã±ãããï¼å¾å¾©ãããªãã¨ãããªãã®ã§ããããã±ããã®å¾å¾©
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}