GMO ããªãããä¸æ£ã¢ã¯ã»ã¹é¨åãã¾ã¨ãã¦ã¿ããï¼ã¡ã¢ï¼
æ¨æ¥ãããWordpressé¢ä¿ã®Webæ¹ç«ãJPãã¡ã¤ã³ã«å¯¾ãã¦è¡ããã¦ãã¾ããä½ä¾¡æ ¼ã®blogãµã¼ãã¹ãæä¾ãã¦ãããµã¤ãã®ããªããããGMOã®InterQãªã©ã被害ãåãã¦ããããã§ãã
åå ã¯.htaccessã¨wp-config.phpã®åæãã¼ããã·ã§ã³ã
â.htaccess â 644
âwp-config.php â 444
ã ã£ããããªã®ã§ãåä¸ãµã¼ãå
ã®ã¦ã¼ã¶ãä¾µå
¥ãããå ´åãä»ã®ã¦ã¼ã¶ã®æ
å ±ãé²è¦§å¯è½ã§ãã£ããããwp-config.phpããDBæ
å ±ï¼tableåãã¦ã¼ã¶IDããã¹ã¯ã¼ãï¼ãåå¾ãã¦åã¦ã¼ã¶ã®DBã«ä¸æ£ã¢ã¯ã»ã¹ããã®ã§ã¯ãªããã¨æããã¾ãã
å ¬å¼è¦è§£ãåºã¦ããªããããããã¾ã§æ¨æ¸¬ã§ãã
æçµçã«
â.htaccess â 644â604â600
âwp-config.php â 444â404â400
ã¸ã¢ã¯ã»ã¹æ¨©ãå¤æ´ããããã§ãããããã§ããä¸æ£ã¢ã¯ã»ã¹ãåãã¦ããã®ã¯ãDBæ
å ±ï¼tableåãã¦ã¼ã¶IDããã¹ã¯ã¼ãï¼ãã ã ãããã¦ãããã«ã¼ãµã¤ãã«æ
å ±ãæ¼æ´©ãã¦ãä¸è¯ãåæ¦ãã¦ãããæ¾é¡ãªã®ããä»ã®ç¾ç¶ããªï¼
å½åããã¹ãã£ã³ã°ä¼ç¤¾ã¨ãã¦ã¯ã被害ãåããã®ã¯ãããã¾ã§ã¦ã¼ã¶ã®è¨å®ãã¹ï¼æ¬å½ã¯ãã·ã¹ãã å´ã®åæè¨å®ãã¹ã ã¨æãï¼ã¨ããç«å ´ã®ããã§ãããæ¨ä»ã¾ãã«è¦ãååã®å¤±æã§ããã
ã©ãããããªãããã¯MySQLã®DBã¸ã¤ã³ã¿ã¼ãããããæ¥ç¶ãæ¾é¡ã ã£ãããã§ãããå½åã®ããªããããæå°ãã¦ããæ¬äºæ¡ã®ã»ãã¥ãªãã£å¯¾çããã³ãã¯ããã ã£ããã被害è ã«ã¯ããããããªãã§ããããã®ããããä»å¹´åº¦ã代表ããäºä¾ã¨ãªã£ã¦ãã¾ãã¾ããã
æ¨æ¥ãfacebookã®ã»ãã«ã¾ã¨ãã¦ãã¾ãããããã¾ãã«è¢«å®³ãåºãã£ã¦ããã®ã§ãæ å ±æä¾ã®ä¸å©ã¨ãªãã°ã¨ãã¯ã¦ãª ã®æ¹ã«å ¬éãã¦ããã¾ãã
ã¡ãªã¿ã«ãAWSãªããã¸ã®æ°æ大移åãèµ·ãã¦ããã¿ãããªãã§ãããªãããããã¯ãæ¬å½ã«ã¡ããã¨ãããªãã¨ãã¦ã¼ã¶ãã¿ããªéãã¡ããã¨æãã¾ãããã»ãã¨ã
æ°ãã¤ããæ å ±ã¯ã¾ã追è¨ãã¦ããã¾ãã
ã追è¨ï¼ã
å½ç¤¾ãµã¼ãã¹ãããªãããï¼ã¬ã³ã¿ã«ãµã¼ãã¼ãã¦ã¼ã¶ã¼ãµã¤ãã¸ã®ç¬¬ä¸è
ã«ãã大è¦æ¨¡æ»æã«ã¤ãã¦
http://lolipop.jp/info/news/4149/
[2013/08/30 19:13 追è¨]ãããWordPressã®ãã©ã°ã¤ã³ã®èå¼±æ§ãããç¹å®ã¦ã¼ã¶ã«ä¾µå ¥ããã®å¾ãwp-config.phpã®ãã¼ããã·ã§ã³ãã¹ããããã¹ã¦ã®ã¦ã¼ã¶ã®wp-config.phpãã¡ã¤ã«ã®ä¸èº«ãæããã¦ã対çå¾ã¯ãæ¼æ´©ããDBæ å ±ãå ã«ä¸æ£ã¢ã¯ã»ã¹ãç¶ãã¦ããããã§ãã
æ¨æ¥ã®æ¼ä»¥éã®å¯¾å¿ã¯ãæªãç¡ãã¨æãã¾ããããã¡ã¼ã¹ããµã¼ãã®äºä¾ã¨åãããæªæ¤è¨¼ã®è¨å®ãæµãè¾¼ãã§ãã¾ã£ã¦ã被害ãæ¡å¤§ãããã¨ãç·æ¥å¯¾å¿ã®æºåãå ¨ã足ãã¦ããªãã£ããã¨ã§2æ被害ãåºã¦ãã¾ã£ã¦ãã¾ãããããã¾ããè¯ãäºä¾ã«ãªã£ã¦ãã¾ãã¾ããããä»å±±ã®ç³ã¨ãã¦ãçãããäºå対çãéè¦ã ã¨ãããã¨ãå¦ã³ã¾ãããã
ã2次被害ãããªããããµã¼ãã¼ã®äºåç¡ããã«ãã¹å¤æ´ã§å½±é¿ãåºã人ç¶åº
http://matome.naver.jp/odai/2137777056565722101
ããªãããã®MySQLãµã¼ãã®ã¤ã³ã¿ã¼ãããå¤é¨ã¸ã®ãã¼ãéæ¾ãã対çããããã§ãããï¼
å
¬å¼çºè¡¨ã¯ãªãããã§ããã»ã»ã»
[MySQL] ããªãããã¯ãMySQLãµã¼ãã«ã°ãã¼ãã«ããæ¥ç¶ã§ãã(ãã®ããã)?
http://d.hatena.ne.jp/ozuma/20120503/1335975957
â Webæ¹ç«æ å ± ä¸è¨ã®URLåç §ã¯å¤§ä¸å¤«ã§ãããããããããã©ã¼é²è¦§æ³¨æãã¦ã£ã«ã¹ææããå¯è½æ§ãããã¾ãã Zone-H http://zone-h.org/archive wp-login.php ãè»ä¸¦ã¿ãããã¦ãã¾ãã JPãã¡ã¤ã³ãWebæ¹ç«éå ± http://izumino.jp/Security/def_jp.html ãã¤ãã¿ã¼ã¢ã«ã¦ã³ã https://twitter.com/def_jp â é¢é£è¨äº ãç·æ¥è¦å ±!!ãããªãããã¨GMOã®interQã®WordPressãè»ä¸¦ã¿ä¹ã£åããã¦ã¾ã http://www.landerblue.co.jp/blog/?p=8402 ç¶) ããªãããã®WordPress大éä¹ã£åãã«ã¤ãã¦ã®æ¨æ¸¬ã¨å¯¾å¿ http://www.landerblue.co.jp/blog/?p=8416 ããªãããé¨åãããAWS移è¡ã§æ»ãã æ¥ http://www.landerblue.co.jp/blog/?p=8448 ãµã¤ãæ¹ããè¦å ±ï¼WordPress ã§ã®ãã¼ããã·ã§ã³è¨å®ã«æ°ãã¤ããï¼ http://blogs.itmedia.co.jp/sakamoto/2013/08/wordpress-f918.html ã2次被害ãããªããããµã¼ãã¼ã®äºåç¡ããã«ãã¹å¤æ´ã§å½±é¿ãåºã人ç¶åº http://matome.naver.jp/odai/2137777056565722101 ãã¨ãã¨ãWordpressãçã£ãæ»æã¯ï¼æãå¤çºãã¦ãã¾ãã WordPresså©ç¨è ã¯è³æ¥ç¢ºèªãï¼ 19ä¸5åãµã¤ããæ¹ããããããããStealratãã®ææ確èªæ¹æ³ http://reynotch.blog.fc2.com/blog-entry-583.html â ãã¹ãã£ã³ã°ä¼ç¤¾ã®è¦è§£ å½ç¤¾ãµã¼ãã¹ãããªãããï¼ã¬ã³ã¿ã«ãµã¼ãã¼ãã¦ã¼ã¶ã¼ãµã¤ãã¸ã®ç¬¬ä¸è ã«ãã大è¦æ¨¡æ»æã«ã¤ã㦠http://lolipop.jp/info/news/4149/ ï¼ï¼ã»ãã¥ãªãã£é¢ã®å¼·åã®çºãä¸è¨ã®ã客æ§ã®ãµã¼ãã¼é åã«è¨ç½®ããã¦ããWordPressã«ããã¦ãwp-config.php ã®ãã¼ããã·ã§ã³ãã400ãã«å¤æ´ãããã¾ããã ï¼ï¼å ¨ãã¡ã¤ã«ã«å¯¾ãã¦ã¦ã£ã«ã¹ã¹ãã£ã³ãå®è¡ããä¸æ£ãªãã¡ã¤ã«ãæ¤ç¥ããå ´åããã¼ããã·ã§ã³ãã000ãã«å¤æ´ãããã¾ãã ããªãããï¼ã¬ã³ã¿ã«ãµã¼ãã¼ãããã»ãã¥ãªãã£ã«é¢ããéè¦ãªãç¥ããã§ã https://lolipop.jp/security/ 対çã«adminã¦ã¼ã¶ã®ã¦ã¼ã¶IDåã¨ãã¹ã¯ã¼ãå¤æ´ãæãã¦ããæ°ããã¾ãã ãã¨ãDBã®IDããã¹ã¯ã¼ãå¤ããã¨ããã®ãæãã¦ããæ°ãããã â Wordpressã®ã»ãã¥ãªãã£å¯¾ç HASHã³ã³ãµã«ãã£ã³ã°æ ªå¼ä¼ç¤¾ä»£è¡¨ã®å¾³ä¸¸æµ©ãæ¸ãä¼ç¤¾å ¬å¼ããã°ã§ãã http://blog.hash-c.co.jp/2012/12/how-to-protect-your-wordpress-on-lolipop.html å®å¿ã®å¾³ä¸¸å°ã ãWordPressã®å®ããåºãããã®ã¾ã¨ãã®ç« ã®è¨³ http://ja.naoko.cc/2013/04/13/wordpress-brute-force-attack/ WordPress使ããªãããã ãã¯ãã£ã¦ããããæ¬å½ã®ã»ãã¥ãªãã£å¯¾ç10é ç® http://wp-d.org/2012/10/18/806/ WordPress ã®ã¦ã¼ã¶ã¼å admin ãå¤æ´ãã¦ã¿ã http://8bitodyssey.com/archives/4007 æ°è¦ã«Admin権éã®ã¦ã¼ã¶ãä½ã£ã¦ã移è¡ããå ´å WordPressã®adminã¦ã¼ã¶ã¼åãå¤æ´ãããã©ã°ã¤ã³ http://five-four.co.jp/design0003/ ãã©ã°å¡ã使ã£ã¦ãadminã¦ã¼ã¶åãå¤æ´ WordPressã¸ã®ä¸æ£ã¢ã¯ã»ã¹ãã°ãè¨é²ãã¦è¦ãã¦ããããã©ã°ã¤ã³ Crazy Bone http://www.msng.info/archives/2013/05/wordpress-crazy-bone.php WordPressã®ã»ãã¥ãªãã£ãå¾¹åºå¼·å http://csspro.digitalskill.jp/ãã¥ã¼ããªã¢ã«/ã¯ã¼ããã¬ã¹/wordpressã®ã»ãã¥ãªãã£å¼·å/ WordPressåå¿è åããã»ãã¥ãªãã£å¼·åº¦ãã§ããéãä¸ããæ¹æ³ http://www.landerblue.co.jp/blog/?p=7410 WordPressã®ã»ãã¥ãªãã£å¯¾çãã©ã°ã¤ã³10é¸ http://netaone.com/wp/wordpress-security/ WordPressã§ã®ã»ãã¥ãªãã£å¯¾ç http://matome.naver.jp/odai/2133777080336131701 WordPressã®ã»ãã¥ãªãã£ãè¦ç´ãã¦ãâï¼ã¤âå°å ¥ãã¦ã¿ãï¼ï¼ http://andask.net/create/review-the-wordpress-security.html