ç®æ¬¡
- ç®æ¬¡
- ã¯ããã«
- ã¤ã³ã¿ã¼ã³ã«ã¤ãã¦
- DNSãã£ãã·ã¥ãã¤ãºãã³ã°ã®æ¦è¦
- æ¤è¨¼ã«ä½¿ç¨ããç°å¢ãæé
- Let's ãã±ãã解æ
- ãããã«
- æ´æ°å±¥æ´
ã¯ããã«
ããã«ã¡ã¯ãæ ªå¼ä¼ç¤¾ã¨ãã»ã¨ãã»ã©ãã©ããªã¼ãº å¦çã¤ã³ã¿ã¼ã³ã®æã§ããå¼ç¤¾ã§ã¯ã»ãã¥ãªãã£ãã¬ã¼ãã³ã°ãã©ãããã©ã¼ã ã®éçºãè¡ã£ã¦ãã¾ããç§ã¯ãã©ãããã©ã¼ã ã®ããã³ãã¨ã³ããããã¯ã¨ã³ãã®éçºãæè²ã³ã³ãã³ãã®éçºã«æºãã£ã¦ãã¾ãã
ç§ã¯å¤§å¦ã§ãããã¯ã¼ã¯ã»ãã¥ãªãã£ã«é¢ããææ¥ã®ãã£ã¼ãã³ã°ã¢ã·ã¹ã¿ã³ãããã¦ããããã®ææ¥ã§ã触ãããã¦ããDNSãã£ãã·ã¥ãã¤ãºãã³ã°ã«é¢ããåé¡ãä½åãã¾ãããä»åã¯æ»ææã«çºçãããã±ãããåç §ããªããDNSãã£ãã·ã¥ãã¤ãºãã³ã°ã¨ã¯ã©ã®ãããªæ»æãªã®ãã解説ãã¦ããããã¨æãã¾ãã
ã¤ã³ã¿ã¼ã³ã«ã¤ãã¦
æ¬é¡ã«å ¥ãåã«ã¤ã³ã¿ã¼ã³ã§ã®åãæ¹ã«ã¤ãã¦ãç´¹ä»ãã¾ããç¾å¨ãç§ã¯å¤§å¦é¢ä¿®å£«1å¹´ã§ããå¼ç¤¾ã®ã¤ã³ã¿ã¼ã³ã«ã¯2022å¹´ã®11æé ããåå ãã¦ãã¾ããææ¥ã®ãªãæ¥ãææ¥ã³ãæ°ãå°ãªãæ¥ã«é±2åãå°æ¹ãããã«ãªã¢ã¼ãã§å¤åããã¦ãã¾ããææ¥ãå人çãªç¨äºãªã©ãå ¥ã£ã¦ãã¦ãè¨æ©å¿å¤ã«æéãå¤åæ¥ã®å¤æ´ãã§ãããããããªãåããããã§ããã¾ããåãããªããã¨ããã£ã¦ãã¡ã³ã¿ã¼ã®æ¹ã«ãµãã¼ããã¦ããã ããããã大å¤å¿å¼·ãã§ãããæ§ã ãªãã¨ã«ãã£ã¬ã³ã¸ã§ããç°å¢ã®ãããèªåã«ã¨ã£ã¦ã¨ã¦ãããåºæ¿ã¨ãªã£ã¦ãã¾ãã
DNSãã£ãã·ã¥ãã¤ãºãã³ã°ã®æ¦è¦
DNSãã£ãã·ã¥ãã¤ãºãã³ã°ã¨ã¯DNSãã£ãã·ã¥ãµã¼ãã«ãã£ãã·ã¥ããããã¡ã¤ã³åã¨IPã¢ãã¬ã¹ã®çµãå½è£ ããæ»æã§ãããã®æ»æãåããèå¼±ãªDNSãã£ãã·ã¥ãµã¼ãã®å©ç¨è ã¯æ£è¦ãã¡ã¤ã³ã§ã¢ã¯ã»ã¹ãã¦ããã«ãé¢ããããå½ãµã¤ããªã©æªæã®ãããµã¤ãã«èªå°ããã¾ãã
ä»åã¯DNSãã£ãã·ã¥ãã¤ãºãã³ã°ã®ä¸ã§ãç¹ã«ã«ãã³ã¹ãã¼å(CVE-2008-1447ãKaminsky bug)ã«ã¤ãã¦è§£èª¬ãã¾ãã
ã«ãã³ã¹ãã¼åã®DNSãã£ãã·ã¥ãã¤ãºãã³ã°ã¯ä¸è¨ã®æé ã§DNSãã£ãã·ã¥ãµã¼ãã«èª¤ã£ãæ å ±ãç»é²ãããæ»æææ³ã§ãã
- æ»æè 端æ«ããDNSãã£ãã·ã¥ãµã¼ãã«å¯¾ãã¦ãã£ãã·ã¥ãåå¨ããå¯è½æ§ã®ä½ããã¡ã¤ã³åãåãåããããªã¯ã¨ã¹ããéåºãã (ä¾ï¼6zd8ttqzld3xgwyw4.example.com )
- DNSãã£ãã·ã¥ãµã¼ããã¬ã¹ãã³ã¹ãåä¿¡ããåã«æ»æè 端æ«ããå¿çãå½è£ ããã¬ã¹ãã³ã¹ãéåºãã
- DNSãã£ãã·ã¥ãµã¼ããå½è£ ãããã¬ã¹ãã³ã¹ãæ£è¦ã®å¿çã¨ã¿ãªã
- 以éãåå解決ãè¡ãã¨ããã£ãã·ã¥ãããå½ã®IPã¢ãã¬ã¹ãè¿çããã
æ¤è¨¼ã«ä½¿ç¨ããç°å¢ãæé
ã¿ã¼ã²ããã¨ãªããã¡ã¤ã³
sushi.example.com
ãã·ã³ä¸è¦§(ã«ãã³å ã¯IPã¢ãã¬ã¹)
- ã¯ã©ã¤ã¢ã³ããã·ã³ (10.236.179.182)
- curlã³ãã³ããã¤ã³ã¹ãã¼ã«æ¸ã¿
- DNSãã£ãã·ã¥ãµã¼ã (10.236.179.159)
- BIND9.3.2ã53/udpã§åä½ä¸
- named.confã§query-sourceã®port(DNS権å¨ãµã¼ãã«åå解決ãªã¯ã¨ã¹ããéä¿¡ããéã®éä¿¡å port)ã53/udpã§åºå®ãã¦ãã
- DNS権å¨ãµã¼ã å
¼ æ£è¦Webãµã¼ã (10.236.179.58)
- BINDã53/udpã§åä½ä¸
- Apache HTTP Serverã80/tcpã§åä½ä¸
- æ»æè
ãã·ã³ (10.236.179.131)
- Metasploit Frameworkãã¤ã³ã¹ãã¼ã«æ¸ã¿
- å½Webãµã¼ã (10.236.179.237)
- Apache HTTP Serverã80/tcpã§åä½ä¸
æé
- ã¯ã©ã¤ã¢ã³ããã·ã³ããcurlã³ãã³ãã使ã£ã¦sushi.example.comã«ã¢ã¯ã»ã¹(æ£è¦ã®Webãã¼ã¸ã表示ããããã¨ã確èª)
- æ»æè ãã·ã³ã®Metasploit Framework(bailiwicked_hostã¢ã¸ã¥ã¼ã«)ã使ã£ã¦DNSãã£ãã·ã¥ãã¤ãºãã³ã°ãè¡ã
- ã¯ã©ã¤ã¢ã³ããã·ã³ããcurlã³ãã³ãã使ã£ã¦sushi.example.comã«ã¢ã¯ã»ã¹(å½ã®Webãã¼ã¸ã表示ããããã¨ã確èª)
Let's ãã±ãã解æ
ã©ã®ããã«DNSãã£ãã·ã¥ãæ±æãããããå®éã®ãã±ãããWiresharkã§ç¢ºèªããªãã追ã£ã¦ããã¾ãã
解æãããã±ããã¯ãã¯ã©ã¤ã¢ã³ããã·ã³ããDNSãã£ãã·ã¥ãµã¼ãããDNS権å¨ãµã¼ã å ¼ æ£è¦Webãµã¼ããã¨æ¥ç¶ããã¦ãããããã¯ã¼ã¯æ©å¨ã§åå¾ãããã®ã¨ãã¾ãã
ã¾ããWiresharkã®ãã£ã¹ãã¬ã¤ãã£ã«ã¿ã§ http
ã¨å
¥åãçµãè¾¼ãã¨ãæ£è¦ã®Webãã¼ã¸(é常ã®HTML)ã¨å½ã®Webãã¼ã¸(ãHacked by Anonymous!!ãã¨æ¸ããããã¼ã¿)ã®ä¸¡æ¹ã®ãã±ããã表示ããã¾ãã
ä¸è¨ãã±ããããå½Webãµã¼ãã®IPã¢ãã¬ã¹ã 10.236.179.237
ã ã¨åãã£ãããã次ã«ã©ã®ãããªDNSéä¿¡ãçºçããããè¦ã¦ããã¾ãã
Wiresharkã®ãã£ã¹ãã¬ã¤ãã£ã«ã¿ã§ dns.a eq 10.236.179.237
ã¨çµãè¾¼ã¿ã¾ãã
ããã¨ã(ã©ã³ãã æåå).example.comã®ã¯ã¨ãªã大éã«è¡¨ç¤ºããã¾ãã
ãã®ãã¡ã®ä¸ã¤(ä¸è¨ç»åã§ã¯ 6ZD8Ttqzld3XgwYW4.example.com
ã®ã¯ã¨ãª)ã調ã¹ãã¨ãAdditional recordsã« sushi.example.com
ã®ã¢ãã¬ã¹ã 10.236.179.237
(å½Webãµã¼ã) ã§ããã¨æ¸ããã¦ãã¾ãã
(ã©ã³ãã æåå).example.comã®ã¯ã¨ãªãããå°ã詳細ã«ç¢ºèªããããWiresharkã®ãã£ã¹ãã¬ã¤ãã£ã«ã¿ã« dns.qry.name == (ã©ã³ãã æåå).example.com
ã¨å
¥åããçµãè¾¼ãã§ã¿ã¾ãã
ä»å㯠6ZD8Ttqzld3XgwYW4.example.com
ã対象ã¨ã㦠dns.qry.name == 6ZD8Ttqzld3XgwYW4.example.com
ã¨ãã¦ãã¾ãã
ä¸è¨ç»åãããæåã« 10.236.179.159
(DNSãã£ãã·ã¥ãµã¼ã) ã«åã㦠6ZD8Ttqzld3XgwYW4.example.com
ã®Aã¬ã³ã¼ããå¼ããã¦ãããã¨ãåããã¾ãããã®å¾ã10.236.179.159
(DNSãã£ãã·ã¥ãµã¼ã)ã 10.236.179.58
(DNS権å¨ãµã¼ã)ã«å¯¾ãã¦åå解決ãªã¯ã¨ã¹ããéä¿¡ãã¦ãã¾ããããã«ç¶ãã¦10.236.179.58
(DNS権å¨ãµã¼ã)ããTransaction IDãã£ã¼ã«ãã®å¤ãç°ãªãã¬ã¹ãã³ã¹ãã±ããã大éã«çºçãã¦ãã¾ãã
ãããã®ãã±ããã®Source Address㯠10.236.179.58
(DNS権å¨ãµã¼ã) ã¨ãªã£ã¦ãã¾ãããããã¯æ»æè
ãè©ç§°ãããã®ã§ãã
æ£è¦ã®DNS権å¨ãµã¼ããè¿ãTransaction IDã¨ä¸è´ãããã±ãããå
ã«DNSãã£ãã·ã¥ãµã¼ãã«å±ããã¨ã§ãAdditional recordsããã£ãã·ã¥ããæ»æãæç«ãã¾ãã
ãããã«
ä»åã¯ã«ãã³ã¹ãã¼åã®DNSãã£ãã·ã¥ãã¤ãºãã³ã°(CVE-2008-1447ãKaminsky bug)ã«ã¤ãã¦ãå®éã®ãã±ãããWiresharkã§ç¢ºèªããªãã解説ãã¦ããã¾ããã
æ»ææã«å®éä½ãèµ·ãã£ã¦ããããç解ã§ãããã¨æãã¾ããæè²ã³ã³ãã³ãã¨ãã¦ä½åããåé¡ã§ã¯ãããã«ææ°äºæ ã対çã«ã¤ãã¦ã触ãã¦ãã¾ãã
æ¬è¨äºã®å 容ãDNSãã£ãã·ã¥ãã¤ãºãã³ã°ã«ã¤ãã¦ç¥ããå¦ã¶ãã£ããã¨ãªã£ã¦ããã°å¹¸ãã§ãã
æ´æ°å±¥æ´
- 2023-05-10: DNSãã£ãã·ã¥ãµã¼ãã®ãã¼ã¸ã§ã³çªå·ãKaminsky bugã¨ããæè¨ã追è¨