Firebaseã®ã»ãã¥ãªãã£ã«ã¼ã«ã®è¨å®ã誤ã£ã¦ãããã¨ãåå ã§æ°ç¾ã®ãµã¤ããå¹³æãã¹ã¯ã¼ããæ©å¯æ å ±ãå«ãåè¨1å2500ä¸ä»¶ã®ã¬ã³ã¼ããå ¬éãã¦ãã¾ã£ã¦ããã¨ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®ãLogykkããmrbruhããxyzevaãã¨ãã3人ãããã°ã«æ稿ãã¾ããã 900 Sites, 125 million accounts, 1 vulnerability - env.fail https://env.fail/posts/firewreck-1/ ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®3人ã¯Chattr.aiã¨ãããµã¼ãã¹ã§Firebaseã®è¨å®ãééã£ã¦ãããã¨ãçºè¦ãã¾ãããChatter.aiã§ã¯ã¦ã§ããµã¤ãä¸ã®æ£è¦ã«ã¼ãã§ç»é²ããã¨ã¢ã«ã¦ã³ãã®æ¨©å©ãé©åã«å¶éããããã®ã®ãFirebaseã®APIãç´æ¥ä½¿ç¨ãã¦ã¢ã«ã¦ã³ããä½æããã¨Firebaseä¸ã®ãã¼ã¿ãã¼ã¹å ¨ã¦ã«å¯¾ãã権éãå
2024å¹´5æ1æ¥ã太é½å çºé»æ½è¨ã®é éç£è¦æ©å¨ ç´800å°ããµã¤ãã¼æ»æãåãã¦ããã¨å ±ãããã¾ãããããã§ã¯é¢é£ããæ å ±ã調ã¹ãå 容ã«ã¤ãã¦ã¾ã¨ãã¾ãã ç£è¦æ©å¨ãçµç±ãä¸æ£éé 太é½å çºé»æ½è¨ã®é éç£è¦æ©å¨ããµã¤ãã¼æ»æãåãã¦ããã¨ãã¦ãå ±ããã®ã¯ç£çµæ°èã®æ¬¡ã®è¨äºãã³ã³ããã¯ç¤¾ã®é éç£è¦æ©å¨ãä¹ã£åãããã¤ã³ã¿ã¼ããããã³ãã³ã°ã®ä¸æ£ééã«æªç¨ããã¦ããã¨ãããã®ã www.sankei.com æ»æãåããæ©å¨ã«ã¯èå¼±æ§ï¼è¨äºã§ã¯ããµã¤ãã¼æ»æ対çã®æ¬ é¥ãã¨è¡¨è¨ï¼ãåå¨ããããæªç¨ããããã¨ã§æ©å¨ä¸ã«ããã¯ãã¢ãè¨ç½®ãããæ©å¨ãçµç±ï¼æ»æè ã身å ãé ãããã«è¸ã¿å°ã«ããã¨ã¿ãããï¼ãã¦ä¸æ£ééã«ãããæä½ãè¡ããã¦ãããå½è©²äºæ¡ã«ã¤ãã¦ã¯æ¢ã«é岡çè¦ãä¸æ£ã¢ã¯ã»ã¹ç¦æ¢æ³éåã®å®¹çã§ææ»ä¸ã¨ããã¦ããã SolarView Compactã®èå¼±æ§ãæªç¨ èå¼±æ§ãæªç¨ãããç£è¦æ©å¨
éå½ã®é²è¡æè¡ãçãããã«ãåæé®®ããã«ã¼éå£ãéå½ã®é²è¡ç£æ¥ã«å¯¾ãã¦çµç¹çãªæ»æãè¡ã£ã¦ãããã¨ãçºè¦ãã¾ããã N. Korean hackers breached 10 defense contractors in South for months, police say https://english.hani.co.kr/arti/english_edition/e_national/1137990 éå½è¦å¯ã«ããã¨ãèåãªããã«ã¼éå£ã¨ãã¦ç¥ããããLazarusããã¯ããã¨ããè¤æ°ã®åæé®®ãããã³ã°çµç¹ããéå½ã®é²è¡ç£æ¥ä¼æ¥ç´10社ã«æ»æãä»æãã¦é²è¡æè¡ãçã¿åºãã¦ããã¨ã®ãã¨ã ãããã³ã°ã«é¢ãã£ãã¨ã¿ãããçµç¹ã¯LazarusãAndarielãKimsukyã§ãããããã¢ã¡ãªã«æ¿åºãããåæé®®æ¿åºã®æ¯æ´ãåãã¦ãããã¨è¦ãªããã¦ããéå£ã§ãã æ»ææ¹æ³ã¯å¤å²ã«ãããã
FIDOã¢ã©ã¤ã¢ã³ã¹ãä»æ§ãçå®ããããã¹ãã¼ãã¯ããã¹ã¯ã¼ãã§ã¯ãªãçä½æ å ±ãç¨ãã¦èªè¨¼ãããFIDO 2.0ãããWebauthnãæ¨æºã«åºãã¦å©ç¨ãã¦å¾ãè³æ ¼èªè¨¼æ å ±ãããã¤ã¹åä½ã§ç®¡çéç¨ããæè¡ã§ãããã®ãã¹ãã¼ãæ±ããåé¡ç¹ã«ã¤ãã¦ãWebauthnæ¨æºã«é¢ãã£ãã¨ã³ã¸ãã¢ã®Firstyearãã¨ã¦ã£ãªã¢ã ã»ãã©ã¦ã³æ°ãèªèº«ã®ããã°ã§è§£èª¬ãã¦ãã¾ãã Firstyear's blog-a-log https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/ Webauthnããã¹ã¯ã¼ãã«ä»£ããèªè¨¼æè¡ã¨ãã¦å¤§ããªå¯è½æ§ãç§ãã¦ããã¨èãã¦ãããã©ã¦ã³æ°ã¯ã2019å¹´ã«ãªã¼ã¹ãã©ãªã¢ããã¢ã¡ãªã«ã«æ¸¡ããå人ã¨å ±ã«Webauthnã®Rustå®è£ ã§ããwebauthn-rsã®éçºãå§ãã¾ããããã®éç¨ã§
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}