Security Advisory Microsoft Security Advisory 2743314 Unencapsulated MS-CHAP v2 Authentication Could Allow Information Disclosure Published: August 20, 2012 Version: 1.0 General Information Executive Summary Microsoft is aware that detailed exploit code has been published for known weaknesses in the Microsoft Challenge Handshake Authentication Protocol version 2 (MS-CHAP v2). The MS-CHAP v2 protoc
ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ããè¨å®ããã¨ãä¸ãä¸ä»äººã«ãã¹ã¯ã¼ããç¥ããã¦ãã¾ã£ã¦ããä¸æ£ãã°ã¤ã³ã®å±éºãåé¿ã§ãã¾ãã ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ãã¨ã¯ï¼ ãã°ã¤ã³ã®ãã³èªè¨¼ç»é¢ã表示ãããã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ããçºè¡ããã¾ããæ¬äººã®ã¿ãåãåãã1åéãæå¹ãªæéå¶éã®ãããã¹ã¯ã¼ãã®ããçã¾ãããªã¹ã¯ãèããä½ãå®å ¨ã§ãã
ä»å·ã§ã¯ã2012å¹´4æãã6æã¾ã§ã®3ãµæéã対象ã¨ãã¦ãã»ãã¥ãªãã£ã¤ã³ã·ãã³ããè¿·æã¡ã¼ã«ãªã©ã®è¦³æ¸¬æ å ±ãã¾ã¨ããIIJãåãæ±ã£ãã¤ã³ã·ãã³ãã¨å¯¾å¿ã«ã¤ãã¦ç´¹ä»ãã¦ãã¾ããã¾ããããã¼ããã³ããã©ãã£ãã¯ã®è§£æçµæã«ã¤ãã¦è§£èª¬ãã¦ãã¾ãã
ã¤ã³ã¿ã¼ãããä¸ã® IPv4 ã¢ãã¬ã¹ãåºç¯å²ã«ã¹ãã£ã³ãã¦ãSSL/TLS, SSH ã§å©ç¨ããã¦ããå ¬ééµè¨¼ææ¸ããã³ DSA ç½²åãåéããã¨ãããSSL/TLS ã§ã¯5.57% (714,243ã¢ãã¬ã¹)ãSSH ã§ã¯9.60% (981,166ã¢ãã¬ã¹) ããæå³ããä»ã®ãµã¤ãã¨ç§å¯éµãå ±æãã¦ãããã¨ãå ±åããã¦ãã¾ãããã®åå ã¯æ©å¨åºè·æã®ããã©ã«ãéµãå©ç¨ãã¦ããã±ã¼ã¹ã¨ãéµçææã«æ¬ä¼¼ä¹±æ°çæã¢ã¸ã¥ã¼ã«ã®ã¨ã³ãããã¼ä¸è¶³ã§ãããã¨ãææããã¦ãã¾ããåæã§æä¾ããã¦ãããªã³ã©ã¤ã³éµãã§ãã¯ãµã¼ãã¹ã«ããå ¬ééµãèå¼±ãã©ãããã§ãã¯ã§ãã¾ãã®ã§ãå¿ è¦ãªå ´åã«ã¯æ©æ¥ã«å¯¾çãå®æ½ãã¦ãã ããã USENIX Security Symposium ã¯ãæ¯å¹´å®è·µçãªç 究çºè¡¨ãè¡ãããå ´ã§ãæ¬å¹´ã¯8æ6æ¥ãã10æ¥ã«ããã¦ãç±³å½ Redmond ã«ã¦ä»ã®ã¯ã¼ã¯ã·ã§ããã¨ã¨ãã«éå¬ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}