ãã¼ãä¸...
æ¿åºã調éããæ°éä¼æ¥ã®ã¯ã©ã¦ããµã¼ãã¹ã«ã¤ãã¦ãã»ãã¥ãªãã£ã¼ãæ ä¿ããªããåæ»ã«å°å ¥ã§ããããã«ãããæ¿åºæ å ±ã·ã¹ãã ã®ããã®ã»ãã¥ãªãã£è©ä¾¡å¶åº¦ï¼ISMAPãã¤ã¹ãããï¼ãã2021å¹´3æ12æ¥ã«å§ã¾ã£ããéç¨ãæ ãæ å ±å¦çæ¨é²æ©æ§ï¼IPAï¼ã¯å¯©æ»ãçµã¦ç»é²ãã10åã®ã¯ã©ã¦ããµã¼ãã¹ã®ãªã¹ããå ¬éãããå ·ä½çãªãµã¼ãã¹ã¨äºæ¥è ã¯æ¬¡ã®éãã OpenCanvasï¼IaaSï¼ï¼NTTãã¼ã¿ï¼ FUJITSU Hybrid IT Service FJcloudï¼å¯å£«éï¼ Apigee Edgeï¼ç±³Googleï¼ Google Cloud Platformï¼ç±³Googleï¼ Google Workspaceï¼ç±³Googleï¼ Salesforce Servicesï¼ã»ã¼ã«ã¹ãã©ã¼ã¹ã»ãããã³ã ï¼ Heroku Servicesï¼ã»ã¼ã«ã¹ãã©ã¼ã¹ã»ãããã³ã ï¼ Amazon Web Serv
Container Security Book â ï¸ãã®ææ¸ã¯è£½ä½ä¸ã®ãã®ã§ã About ãããã Linux ã³ã³ããã®ã»ãã¥ãªãã£ãå¦ã³ãã人ã®ããã®ææ¸ã§ãã æ®æ®µããã³ã³ãããæ±ã£ã¦ããããã³ã³ããã®åºç¤æè¡ãã»ãã¥ãªãã£ã«ã¤ãã¦ã¯åãããªãã¨ãã人ããããããç解ã§ãã足ãããã«ãªãããã«æ¸ããã¦ãã¾ãã 誤åè±åãééããªã©ããã° https://github.com/mrtc0/container-security-book ã« Issue ããã㯠Pull Request ãç«ã¦ã¦ãã ããã ãæè¦ããææ³ç㯠Twitter ããã·ã¥ã¿ã° #container_security ã§ãã¤ã¼ãããé¡ããã¾ãã License ãã®æ¸ç±ã«è¨è¿°ããã¦ãããã¹ã¦ã®ã½ã¼ã¹ã³ã¼ã㯠MIT ã©ã¤ã»ã³ã¹ã¨ãã¾ãã ã¾ããæç« ã¯ Creative Commons Attribution
å æ¥ã®ä»¥ä¸ã®åå¼·ä¼ã§çºè¡¨ããå 容ã«ã¤ãã¦è¨äºã«ãã¦ããã¾ãã 第28åã¼ãããå§ããã»ãã¥ãªãã£å ¥é åå¼·ä¼ CISèªä½ãç¥ããªãæ¹ãå¤ãã£ãã®ã§ãèå³ãããæ¹ã¯èªãã§ãã£ã¦ããã ããã°ã¨æãã¾ãã ãªããå 容ã«ã¤ãã¦ã¯å人çãªè¦è§£ãå¤ãå«ã¿ã¾ãã®ã§äºããäºæ¿ãã ããã CISï¼Center for Internet Securityï¼ãã©ãæ´»ç¨ããã CISï¼Center for Internet Securityï¼ã«ã¤ãã¦ã¯ä»¥åã®è¨äºã«è¨è¼ãã¦ãã¾ãã®ã§ããã¡ããã覧ãã ããã 社ä¼äººããã£ã¦ããã¨ä»¥ä¸ã®ãããªäºè±¡ã«ééãããã¨ã¯ãªãã§ããããï¼ ãã¿ã¼ã³A ä¸å¸ï¼Aåãä»åº¦ãã¡ã§AWSã§ã¢ããªã±ã¼ã·ã§ã³ãä½ããã¨æã£ã¦ãããã ãã©ãã»ãã¥ãªãã£é¢ä¿ãè¯ãæãã«ãããã®ã§ããããããï¼ Aåï¼ã»ã»ã»ã» ãããã丸æãã§ããã ã¾ããããªãã¨ããã£ãããããã¨ãããã§ãããã ãã¿ã¼ã³B
by Sean MacEntee HTTPSéä¿¡ã«å¿ è¦ãªãµã¼ãã¼è¨¼ææ¸ãç¡æã§çºè¡ããèªè¨¼å±ãLet's Encryptãããã½ããã¦ã§ã¢ã®ãã°ã«ãã£ã¦å®å ¨ã«è¨¼ææ¸ãçºè¡ã§ãã¦ããªãã£ãã¨ãã¦ããã°ã®å½±é¿ãåããã¨èãããã証ææ¸ã2020å¹´3æ4æ¥(æ°´)ã«å¤±å¹ããããã¨ãçºè¡¨ãã¾ããã 2020.02.29 CAA Rechecking Bug - Incidents - Let's Encrypt Community Support https://community.letsencrypt.org/t/2020-02-29-caa-rechecking-bug/114591 Revoking certain certificates on March 4 - Help - Let's Encrypt Community Support https://community.letsen
æ å ±å¦çæ¨é²æ©æ§ï¼IPAï¼ã¯ã1æã«çºè¡¨ãããæ å ±ã»ãã¥ãªãã£10大è å¨2020ãã®è§£èª¬è³æãå ¬éããã ãæ å ±ã»ãã¥ãªãã£10大è å¨2020ãã¯ã2019å¹´ã«ãå人ãããçµç¹ãã«ã¨ã£ã¦å½±é¿ã大ããã£ãã»ãã¥ãªãã£ä¸ã®è å¨ãã»ãã¥ãªãã£ç 究è ãå®åè ã«ãã£ã¦é¸åºã決å®ãããã®ã ã©ã³ãã³ã°ãã®ãã®ã¯1æã«çºè¡¨æ¸ã¿ã ããããããã®è å¨ã«ã¤ãã¦è§£èª¬ããè³æãPDFãã¡ã¤ã«ã«ã¦ãããã«ç¨æãåæ©æ§ã®ã¦ã§ããµã¤ãã§å ¬éããã åè å¨ã«ããã¦æ³å®ãããæ»æè ãæå£ã被害è ã被害ã«ããå½±é¿ãå®éã«çããäºä¾ã対çãªã©ãã¤ã©ã¹ããã¾ãããªãããããããã説æãã¦ããã ï¼Security NEXT - 2020/02/28 ï¼ ãã¤ã¼ã
æ°åã³ããã¦ã¤ã«ã¹ããããããä¸å®ã«ä¾¿ä¹ããããã¹ã¯ãç¡æéä»ããä¿å¥æã®éç¥ããªã©ã¨ç§°ããæ»æã¡ã¼ã«ãç¸æ¬¡ãã§ç¢ºèªãããã¨ããã¬ã³ããã¤ã¯ãã注æåèµ·ãã¦ãã¾ãã ãä»ã®ç»åãæ»æã¡ã¼ã«ã®ä¾ æå£ã®1ã¤ã¯ãæ°åã³ããã¦ã¤ã«ã¹ã«ããèºçãåºãã£ã¦ããåé¡ã§ããã¹ã¯ãç¡æéä»ãã¨ãã£ãå 容ã§ã2æ3æ¥ããããæºå¸¯é»è©±ã®SMSã§ç¢ºèªããã¦ããããã§ããè¨è¼ãããURLã«ã¢ã¯ã»ã¹ããã¨ãAndroid端æ«ã®å ´åã¯ãä¸æ£ã¢ããªãXloaderãã®ãã¦ã³ãã¼ããã¯ããå½è£ ãµã¤ãã¸ãiOS端æ«ã®å ´åã¯ãApple IDãã¯ã¬ã¸ããã«ã¼ãæ å ±ãªã©ã®è©åãçããµã¤ãã¸èªå°ãããã¨ã®ãã¨ã§ãã ãã1ã¤ã®æå£ã¯ä¿å¥æããããé»åã¡ã¼ã«ã§ã1æ28æ¥åå¾ããæ¡æ£ãæé¢ã«ã¯ããã¤ãããªã¨ã¼ã·ã§ã³ããããã®ã®ããä¸å½æ¦âæâå¸ãã¨ããç¹å¾´çãªèª¤åãããå¥æ·»éç¥ãã®ç¢ºèªãæ示ãã¦æ·»ä»ãã¡ã¤ã«ãéããããã¨ããã¨ãã£
iOS 13 ããã³ macOS 10.15 ã«ãããä¿¡é ¼æ¸ã¿è¨¼ææ¸ã®è¦ä»¶ iOS 13 ããã³ macOS 10.15 ã§ã¯ãTLS ãµã¼ã証ææ¸ã«å¯¾ããã»ãã¥ãªãã£è¦ä»¶ãæ°ãããªãã¾ãã詳ããã説æãã¾ãã iOS 13 ããã³ macOS 10.15 ã§ã¯ã以ä¸ã«ç´¹ä»ããæ°ããªã»ãã¥ãªãã£è¦ä»¶ããã¹ã¦ã® TLS ãµã¼ã証ææ¸ã«èª²ããã¾ãã RSA éµãå©ç¨ãã TLS ãµã¼ã証ææ¸ããã³çºè¡å ã® CA ã¯ãéµé· 2048 ããã以ä¸ã®éµãç¨ããå¿ è¦ãããã2048 ãããæªæºã®éµé·ã® RSA éµãç¨ãã証ææ¸ã¯ãTLS éä¿¡ã«ããã¦ä¿¡é ¼ãããªããªãã¾ãã TLS ãµã¼ã証ææ¸ããã³çºè¡å ã® CA ã¯ãSHA-2 ãã¡ããªã¼ã®ããã·ã¥ã¢ã«ã´ãªãºã ãç½²åã¢ã«ã´ãªãºã ã«ç¨ããå¿ è¦ããããSHA-1 ã§ç½²åããã証ææ¸ã¯ãTLS éä¿¡ã§ã¯ä¿¡é ¼ãããªããªãã¾ãã TLS ãµã¼ã証ææ¸ã¯ã証ææ¸
ã¦ã£ã«ã¹å¯¾çã½ããã¦ã§ã¢ã¡ã¼ã«ã¼AvastããJumpshotã¨ããåä¼ç¤¾ãéãã¦ãæ©å¯æ§ã®é«ããã¦ã§ãé²è¦§ãã¼ã¿ã販売ãã¦ããã¨å ±ãããã¦ãããMotherboardã¨PCMagãç±³å½æé1æ27æ¥ã«å ¬éãã調æ»çµæã«ããã¨ãå社ã®ã½ããã¦ã§ã¢ã¯ãã¦ã¼ã¶ã¼ã®ã¯ãªãã¯æä½ãã¦ã§ãã§ã®åãã追跡ãããGoogleãããGoogleããããã§ã®æ¤ç´¢å 容ãã訪åããå ·ä½çãªãLinkedInããã¼ã¸ããYouTubeãåç»ããã«ããµã¤ããªã©ã®ãã¼ã¿ãåéãã¦ããããã ãAvastã®ç¡æã¦ã¤ã«ã¹å¯¾çã½ããã¯ä¸çä¸ã§å¤ãã®ã¦ã¼ã¶ã¼ã«ä½¿ç¨ããã¦ããã åéããããã¼ã¿ã¯ãJumpshotã«ãã£ã¦åããã±ã¼ã¸ããã販売ããã¦ããã¨ãããJumpshotã®ã¦ã§ããµã¤ãã§ã¯ããã¤ã³ã¿ã¼ãããã®æãè²´éãªã¦ã©ã¼ã«ãã¬ã¼ãã³ãå ã®ã¦ã¼ã¶ã¼ã®è¡åã«é¢ãããã¼ã¿ãæä¾ã§ããã¨èª¬æããã¦ãããè¨äºã«ããã¨ãJumps
DockerAPI ãæ¨çã¨ããæ¢ç´¢è¡çºã®å¢å ãªã¢ã¼ããã¹ã¯ãããã®èå¼±æ§ï¼CVE-2019-0708ï¼ãæ¨çã¨ããã¢ã¯ã»ã¹ã®å¢å å®å ãã¼ã26/TCP ã«å¯¾ããMirai ãããã®ç¹å¾´ãæããã¢ã¯ã»ã¹ã®å¢å â»æ¬è³æã«ããããçä¿¡å å½ã»å°åãã«ã¤ãã¦ã¯ãå¤æããçä¿¡å ï¼éä¿¡å ï¼IP ã¢ãã¬ã¹ãå½è©²å½ã»å°åã«å²ãå½ã¦ããã¦ãããã¨ãæãã¦ãããè¸ã¿å°ã¨ãªã£ã¦ãããªã©ã«ãããéä¿¡è ã®æå¨ã¨ä¸è´ãã¦ããªãå ´åãããã¾ãã 詳細 DockerAPI ãæ¨çã¨ããæ¢ç´¢è¡çºã®å¢å çã«ã¤ãã¦(PDFå½¢å¼ï¼684KB)
ãªã¼ãã³ã½ã¼ã¹ã®ããã¯ã·ã½ããã¦ã§ã¢ãEnvoyãã«æ·±å»ãªèå¼±æ§ãæããã¨ãªã£ããåã½ãããå©ç¨ãããIstioãã«ãå½±é¿ããããããããã¢ãããã¼ãããªãªã¼ã¹ããã¦ããã åã½ããã¦ã§ã¢ã«3件ã®èå¼±æ§ãæããã¨ãªã£ããã®ããKuberenetesãã§ãã¤ã¯ããµã¼ãã¹ãæä¾ãããIstioãã«ã¤ãã¦ããåã½ãããã³ã¢ã³ã³ãã¼ãã³ãã¨ãã¦å©ç¨ãã¦ãããèå¼±æ§ã®å½±é¿ãåããã ãCVE-2019-18801ãã¯ããHTTP/1ãã¸å¯¾å¿ããæ§æã§ãã¼ããªã¼ãã¼ããã¼ãçããèå¼±æ§ãå ±éèå¼±æ§è©ä¾¡ã·ã¹ãã ã§ãããCVSSv3ãã®ã¹ã³ã¢ã¯ã9.8ããèå¼±æ§ã®éè¦åº¦ã¯ãã£ã¨ãé«ããã¯ãªãã£ã«ã«ï¼Criticalï¼ãã¨ã¬ã¼ãã£ã³ã°ããã¦ããã ããã«NULLãã¤ã³ã¿ãåç §ããèå¼±æ§ãCVE-2019-18838ããããªã·ã¼ã®ãã¤ãã¹ãçãããCVE-2019-18802ãã«ãªã©ãéè¦åº¦ãé«ï¼Highï¼ã
å æ¥ãæ¥æ¯è°·å ¬åã«ã»ã©è¿ãä¼å ´ã§ã¯ãªã¨ã¼ã·ã§ã³ã©ã¤ã³æ ªå¼ä¼ç¤¾æ§ä¸»å¬ã®Aqua Securityã³ã³ããã»ããã¼ã«åå ãã¦ãã¾ããã 2019å¹´11æ20æ¥ Aqua Securityã³ã³ããã»ããã¼ ãéå¬ãã¾ã - ã¯ãªã¨ã¼ã·ã§ã³ã©ã¤ã³æ ªå¼ä¼ç¤¾ åºæ¬ã¯ãå¼ç¤¾ã§ãæ±ã£ã¦ããAqua Container Securityã«ã¤ãã¦ã®è©±ã主ã ã£ãã®ã§ããã製åä»æ§ä»¥å¤ã«ãã«ã«ã¯ã³ã æ§ã§ã®Kuberneteséç¨ã®GitOpsã®è©±ã§ãã£ããã決æ¸ãµã¼ãã¹Paidyã«ãããã³ã³ããéç¨ã®è©±ã§ãã£ãããæè¿è©±é¡ã®OSSãªèå¼±æ§ã¹ãã£ã³ãã¼ã«ã®Trivyã®ä½è ãç¦ç°ãããã¤ã¹ã©ã¨ã«ãããªã³ã©ã¤ã³ã»ããã¼ãã£ãããã³ã³ããçéã®å¹ åºã話é¡ãã¦ããçãã§ã楽ããä¸æ¥ã§ããã ããã§ã¯ããããªä¸æ¥ã®å 容ãç´¹ä»ãã¾ãã ï¼ç¥ï¼ ⧠⧠Yã ( ï¾Ðï¾) Φ[_ソ__ï½_lã    コï¾ï¾ï¾ セキï½ï¾ï¾ï½¨ï½°ï¾ï¾
èNLnet Labsãéçºãããªã¼ãã³ã½ã¼ã¹ã®ãã£ãã·ã¥DNSãµã¼ããUnboundãã«ããã¦ãä»»æã®ã·ã§ã«ã³ã¼ããå®è¡ãããããããããèå¼±æ§ãå¤æããã èå¼±æ§ãCVE-2019-18934ããå¤æãããã®ãç¹å®ã®ç°å¢ã§ç´°å·¥ãããIPSECKEYã¬ã³ã¼ãããåãåãã¨ä»»æã®ã·ã§ã«ã³ã¼ããå®è¡ãããããããããã¨ããã NLnet Labsã§ã¯ãèå¼±æ§ãä¿®æ£ãããå1.9.5ãããªãªã¼ã¹ãæ¥æ¬ã¬ã¸ã¹ããªãµã¼ãã¹ï¼JPRSï¼ãªã©é¢é£æ©é¢ãªã©ãå©ç¨è ã¸æ³¨æãå¼ã³ããã¦ããã ï¼Security NEXT - 2019/11/20 ï¼ ãã¤ã¼ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}