ethna.jpãjp2.php.netã«çºçãããã©ãã«ã«ã¤ãã¦
æ¬æ¥èµ·ãã£ããethna.jp ããjp2.php.net ã®ãµã¤ãã«ãActiveX ã Flash ã®èå¼±æ§ãã¤ããæ»æããã html ãèªã¿è¾¼ã iframeãå·®ãè¾¼ã¾ããã¨ãããã©ãã«ãçºçãã¾ããã
ã¡ãã£ã¨ãããã£ãã®ã§ãæµããè¨é²ã¨ãã¦æ®ãã¦ãããã¨æãã¾ãã
ethna.jpã®ç¬¬ä¸å ±
10:30ããã%Ethna ã®IRCãã£ã³ãã«ã§ãmikaponãããããmlã®ä¿åæ¸åº«ã«ä¸æ£ãª iframe ãå·®ãè¾¼ã¾ãã¦ããã¨ããå ±åãããã¾ããã
10:31 (mikapon) ãã¯ãããããã¾ã
10:32 (mikapon) ethnaã®ãµã¤ããªãã§ãã
10:32 (mikapon) mlã®ä¿åæ¸åº«ã®æã«iframeåãè¾¼ã¾ãã¦ã¾ãããï¼
ã¡ããã©åºç¤¾ä¸ã®æéã§ããã®çºè¨ããªã¢ã«ã¿ã¤ã ã§ã¯è¦ããªãã£ãã®ã§ãããåææ¥ã« tiarra ãå
¥ãããããã§ãçºè¨ãè¦ããã¨ãåºæ¥ã¾ããã
firefoxã§éããã¨ãããhtmlã®å
é 㧠iframeã®éå§ã¿ã°ã®ã¿ãããã®ã§ããã¼ã¸ãçã£ç½ã«ãªã£ã¦ãã¾ã£ã¦ãã¾ããã
ä¿®æ£ã調æ»ããã権éã¯ç¡ãã®ã§ãMLã«å ±åãæãã¾ããã
10:39 (maru_cc) ã»ãã¨ã ããªããå¤ã http://ethna.jp/pipermail/users/ãï¼éããªãã»ãããããã
10:39 (maru_cc) å é ã«å¤ãªã®ãå ¥ã£ã¦ã
10:39 (maru_cc)
â»pp.cool0.bizã¯çµ¶å¯¾ã«éããªãã§ä¸ãã! ãªã³ã¯ã«ãªããªãããã«ãã¦ãã¾ã
Firefoxã§ãFlash Playerãææ°ã ã£ããããã§ãªãã¨ããªãã£ãã®ã§ããããã®æ®µéã§ãä¸ç¨æã«éããèªåã«åçã
ããã£ã¦åããããªç¾è±¡ã«ãã£ã¦ããã¨ãã 2chã®ã¹ã¬ãããããã¾ããã
http://namidame.2ch.net/test/read.cgi/news/1212288872/66-67
ãã ãããã®æ®µéã§ã¯ã¾ã 詳細ã¯ä¸æã
jp2.php.netã§ã¯
IRCã®ãã°ã追ã£ãã¨ããã%PHPStudy ã®ãã£ã³ãã«ã§ãä¸å ±ãããã¾ããã
10:07 (nazo) jp2.php.netãã¯ã©ãã¯ããã¦ãã®ã§ãã
10:09 (nazo) http://bloggers.ja.bz/sunouchi/
10:09 (nazo) ã®äººã«å ±åããã°ããã®ã§ãããã
IRCãã¼ã¹ã§ã対å¿ãé²ãã§ããããã§ãã
ethna.jpã§ã®å¯¾å¿
ethna.jpã®ãµã¼ãã¹ãæ¢ãã¦èª¿æ»ãéå§
http://ml.ethna.jp/pipermail/users/2008-June/000970.html
http://ml.ethna.jp/pipermail/users/2008-June/000971.html
IEããã³Flashã®èå¼±æ§çªãã¦ãã¾ãã®ã§æ±ºãã¦è¸ã¾ãªãã§ãã ããã
http://namidame.2ch.net/test/read.cgi/news/1212288872/918-919
ãã¡ãã«æ£ç¢ºãã©ãããããã¾ããããç¾è±¡ããããã¦ãã¾ããã
http://namidame.2ch.net/test/read.cgi/news/1212288872/918-919
918 ï¼ ãã¼ãã¥(ç¦å²¡ç)ï¼2008/06/02(æ) 07:34:44.02 id:fDXxYyKb0
æ¶æ¸¬ã交ãã¦ããã¡ãã£ã¨ãé·ããªãã®ã§åãã¾ãppâ cool0â biz/bmw/am1â htm?34-8681
ããããã½ããã®ãµã¤ãã«iframeã§ä»è¾¼ã¾ãã¦ããURLã以ä¸ã®å種URLãå¼ã³åºããppâ cool0â biz/ax14â htm
ããVBScriptã³ã¼ããçæãããIE以å¤ã¯é¢ä¿ãªãã
ããActiveXã³ã³ããã¼ã«ã®èå¼±æ§ãã¤ããã®ã
ãã2006å¹´ã®èå¼±æ§ã§ãããWindows Updateãè¡ã£ã¦ããã°ææãããã¨ã¯ãªãã
ããâåèURL
ããhttp://www.microsoft.com/japan/technet/security/bulletin/MS06-014.mspxppâ cool0â biz/re10â htm
ããJavaScriptã³ã¼ããçæãããIE6ãããã¯IE7ã§ãªããã°ä½ãããçµäºããã
ããRealPlayerã®ActiveXã³ã³ããã¼ã«ï¼IERPCtl.IERPCtl.1ï¼ã®èå¼±æ§ãã¤ããã®ã
ããIEã¦ã¼ã¶ã¼ã§RealPlayerãã¤ã³ã¹ãã¼ã«ãã¦ããã
ãã2007/10/25以éã¢ãããã¼ããè¡ã£ã¦ããªãå ´åææã®å¯è½æ§ãããã
ããâåèURL
ããhttp://pc.nikkeibp.co.jp/article/NEWS/20071022/285084/?ST=pc_newswwwâ tongji123â org/axfsâ htm
ããIEã®å ´åã¯4561.swfãå¼ã³åºããFirefoxãªã©ã®å ´å4562.swfãå¼ã³åºãã
ããFlashãã©ã°ã¤ã³ã®èå¼±æ§ãã¤ãããã®ã§ããã©ã¦ã¶ã«ä¾åããªãã
ããFlashãã©ã°ã¤ã³ã®ãã¼ã¸ã§ã³ã9.0.124.0(ææ°ç)æªæºã§ããã°ææã®çããããã
ããâåèURL
ããhttp://blog.trendmicro.co.jp/archives/1380ç¶ã
919 ï¼ ãã¼ãã¥(ç¦å²¡ç)ï¼2008/06/02(æ) 07:35:28.09 id:fDXxYyKb0
ç¶ãppâ cool0â biz/axlzâ htm
ããActiveXã³ã³ããã¼ã«ãå¼ã³åºããªããã°å¼ã°ããªãã®ã§IE以å¤ã«ã¯é¢ä¿ãªãã
ããActiveXã³ã³ããã¼ã«Ourgame 'GLIEDown2.dll'ã®èå¼±æ§ãã¤ããã®ã
ããOurgameã¯ä¸å½ã®ãªã³ã©ã¤ã³ã²ã¼ã ãµã¤ãã§ãããã§ä½¿ããã¦ããActiveXã³ã³ããã¼ã«ã
ããæ¥æ¬äººã«ã¯ã»ã¨ãã©é¢ä¿ãªãã¨æãããã
ããâåèURL
ããhttp://www.symantec.com/avcenter/attack_sigs/s22935.htmlppâ cool0â biz/re11â htm
ããActiveXã³ã³ããã¼ã«ãå¼ã³åºããªããã°å¼ã°ããªãã®ã§IE以å¤ã«ã¯é¢ä¿ãªãã
ããRealPlayerã®ActiveXã³ã³ããã¼ã«ã®èå¼±æ§ãã¤ããã®ã
ããIEã¦ã¼ã¶ã¼ã§ãããRealPlayerã®ãã¼ã¸ã§ã³ã11.0.2æªæºã®å ´åææã®å¯è½æ§ãããã
ããâåèURL
ããhttp://japan.cnet.com/news/sec/story/0,2000056024,20369230,00.htmjsâ usersâ 51â la/1564751â js
ããã¢ã¯ã»ã¹è§£æ
ãµããã¨ããã調æ»ãã¦ãã ãã£ã調æ»çµæ第ä¸å ±ã
http://ml.ethna.jp/pipermail/users/2008-June/000972.html
1 (ethna.jpã®ãµã¼ãã«ä¿åããã¦ãã)ã³ã³ãã³ãã®æ¹ç«ã¯è¡ããã¦ãã¾ãã
* ãé£çµ¡ããã ããMLã¢ã¼ã«ã¤ãçãHTMLèªä½ã¯ãã¬ã¤ãªãã®ã§ãã
* è¨ãæããã¨ã*.htmlãã¹ã¦ã§ç¾è±¡ãåç¾ãã¦ãã¾ã2 user landã¾ã§ã¯ãæ£ãããã³ã³ãã³ããåºåããã¦ãããã¨ã確èªãã¾ãã
* strace /usr/sbin/apache2 -Xã¨ããã¦socketãªfdã«æ£ãã(iframeã¿ã°ãªã
ã§)write()ãçºè¡ããã¦ãããã¨ãapacheãã°ã§è¨é²ããã¦ããã³ã³ãã³ããµã¤
ãºãªã©ãªã©ãããããæ¤è¨¼ãã¾ãããééããªãããã§ã
* ãã®å ´åã§ãclientã«ã¯iframeãä»å ããã¦è¿ã£ã¦æ¥ã¦ããã®ã§ãkernel
landããããã¦ããããethna.jp <-> clientã®ã©ããã§ãããã¦ããã¨èãã
ãã¾ã3 ethna.jpå¨è¾ºã®IP帯åã®80çªãå©ããã¦ããã ããã¨ããè»ä¸¦ã¿ãã¡ãªæãã§
ã(ãæ°ãã¤ããã ããï¼)
* ã¡ãªã¿ã«ãããã®jp2.php.netããã(digããã°åãã£ã¡ããã®ã§æ¸ãã¾ã
ã)ethna.jpã®å²ã¨ãã°ã«ããã¾ã(ipçã«)4 ããã ãã ã¨ãããªãã ãIPé£çªã§ãããã¦ãã ãããããã¨èããããã®ã§ãã
* ethna.jpã¨è¿ãIPãæã¤ãµã¼ãã§
* å¤ã®ãµã¼ãããwgetã¨ãã§ç¢ºèªããã¦ããã ãã¨iframeãä»å ããã¦ãã¾ã
ãµã¼ãã§ã
* ethna.jpã®ãµã¼ã*ãã*ãw3mãwgetã§ã¢ã¯ã»ã¹ããã¨ç¾è±¡ãåç¾ãã¾ãã
(ã¤ã¾ãethna.jpããlocalã§w3mã¨ãã§ç¢ºèªããã¨iframeã¨ãã¯ã¤ãã¦ãã¾ãã)
ã¨ãããã¨ããããã¾ããã¨ãããã¨ã§ãç¾ç¶ã§ã¯1-4ããå¤æãã¦
* ethna.jpãç´ã§crackãããããã§ã¯ãªããã(ã¾ã æ²¹æã¯ã§ãã¾ããã...å
人çã«ã¯ãã®ä»ãã°ã¨ããè¦ãã«ééããªãããã¨ãæã£ã¦ãã¾ã)
* ã©ããããã®å ã§ãªããããã¦ãããããªããã¨èãã¦ãã¾ãããã(ãã¹ãã£ã³ã°å ã«ã¯å¥éåãåããã¾ãã)ãããã«ãã¦
ãç¾ç¶ã®ethna.jpã®ãµã¼ãã§httpãªãµã¼ãã¹ãè¡ãã®ã¯ãããã®å ´åã§ã(ãã
ããéã£ãäºæ ã§)å³ããããªãã¨æãã¾ãã
ãã以å¤ã«ã対å¿ãéæ %Ethna ã®IRCãã£ã³ãã«ã§è©±ããã¦ãã¾ããã
ethna.jpãsf.jpã¸ç§»è¡
ethna.jpã®ã³ã³ãã³ãããã®æ©ä¼ã«ã以åãã話ãåºã¦ãã sf.jpã¸ç§»è¡ãã¦ãã¾ããã¨ããå¤æã«ãªãã¾ããã
ãã®å¤æã決å®ããã®ãã16æéãã§ããã
ãããããã³ã³ãã³ãã®ç§»è¡ãDNSã®åãæ¿ãçããã¦ã復æ§ãå®äºããã®ãã20æã
http://ml.ethna.jp/pipermail/users/2008-June/000975.html
ãã¡ãã«ãæ¸ããã¦ãã¾ããããããã¤ã³ã¿ã¼ãããã§é害ã®å ±åãããã£ã¦ãã¾ããã
http://support.sakura.ad.jp/page/news/20080602-001.news
çºçæ¥æ : 2008å¹´6æ1æ¥(æ¥)01æ52å ã 6æ2æ¥(æ)17æ23å
å½±é¿ç¯å² : å°ç¨ãµã¼ã 10M ã¹ã¿ã³ãã¼ãä¸é¨
ããããã 219.94.145.0 ã 219.94.145.127
é害å 容 : çºçæé帯ã«ããããµã¼ãã¸ã®æ¥ç¶ã«ããã¦æç¶çã«ä¸å®å®ãª
ããããã ç¶æ³ãçºçãã¦ããã¾ããã
è£è¶³äºé ï¼ç¾å¨ãé害ã¯è§£æ¶ãã¦ããã¾ãã
ä¸å®å®ï¼ã¨ãã話ã¯ããã¾ããããããã¯ã¼ã¯ã®ä¸ä½ã§ä½ããã£ãã®ã¯ééããªãããã§ãã
大ä¹
ä¿ãããæ¸ããã¦ãã
http://ml.ethna.jp/pipermail/users/2008-June/000974.html
ãã»ãã¥ãªãã£ãã¼ã« memoãããã§ã話é¡ã«ãªã£ã¦ã¾ããã
ãµããã¨ããã®è§£æçµæã¨åãããã¨ARP Spoofingã£ã½ãã§ããã
http://www.st.ryukoku.ac.jp/~kjm/security/memo/2007/10.html#20071005_ARP
ARP Spoofingã¨ããã®ãå§ãã¦ç¥ãã¾ããã
ãã®å¾
ã¨ãããããé害ã¯åã¾ã£ãããããjp2.php.netã¯å¾©æ§ãã¦ãã¾ãããethna.jpã¯ãµã¼ãã®ç§»è¡ãè¡ãã¾ããã
ãµã¤ãã§ãåç¥ããã¦ãã¾ãã
http://ethna.jp/
http://ethna.jp/ethna-news.html#u03a0183
2008/06/02 ã®ååä¸ã«ãethna.jp ã®ã³ã³ãã³ãã«ä¸æ£ãªiframeã¿ã°ãåãè¾¼ã¾ãã¦ããã®ã§ã¯ãªããã¨ã¡ã¼ãªã³ã°ãªã¹ãã«å ±åãããã¾ãããããã¯è¤æ°ã®èå¼±æ§ãçªããã«ã¦ã§ã¢ã¸ã¨èªå°ãããã®ã§ããã
ããããã®æéå
ã«ããµã¤ããé²è¦§ãã人ã¯ãPCãææãã¦ããªãã確èªãããã»ããããããããã¾ããã
追è¨
ãã¡ãã®MLã§ããããã«åãåãããããåçãæ¸ããã¦ããæ¹ããã¾ããã
http://memo.st.ryukoku.ac.jp/archive/200806.month/9458.html
ãã¡ãããããã«åãåããã¾ããã1å°ã«ã¼ã¿ã¨åãIPãåä¹ããã·ã³ããã
ããã§ãã
éé¢ãã¿ã¨ã®ãã¨ã§ãããHTTPæ¹ç«ããã¦ãããã¨ã¯ã©ããèªèãã¦ãªãã£ãæ°é ï¼
ã§ãæ°ããæ å ±ãå¤æ次第æ¡å ããã¨ã®ãã¨ã§ããã
ãããèªåã®ãµã¼ãããã£ãããã£ã¦ããä¸ä½ãæå±ãããããã¯ã¼ã¯å
ã§ããããã£ããã¨ãçºçããã¨é²ãããããªãã§ããã
äºå¾çãªå¯¾å¿çã¨ãã¦ã¯ãå¥ã®ãããã¯ã¼ã¯ã«ããã¯ã¢ãããµã¼ããç¨æãã¦ããã¦ãåãæ¿ãããããã§ããããï¼
追è¨(2008-06-03)
ãããã¤ã³ã¿ã¼ãããã®ãé害çºçã®ãç¥ãããã«è¿½è¨ãããã¾ããã
[6æ3æ¥è¿½è¨]
ãããåä¸ãããã¯ã¼ã¯å ã«å容ãããä¸é¨ãµã¼ãã«ããã¦ãããã¯ã¼ã¯è¨å®
ãããã®èª¤ãã«ãããæ¬é害ãå¼ãèµ·ãããã¾ããã
ããã該å½ã®ãµã¼ããéé¢ãããã¨ã«ãããé害ã¯è§£æ¶ãã¦ããã¾ãã
ãµã¨æãã¤ããã®ã ããiframeã¿ã°ãéå§ã¿ã°ã ãã ããç»é¢ãçã£ç½ã«ãªãåé¡ãçºè¦ããããæ®éã«éãã¿ã°ã¾ã§ãã£ãããä¸è¬ã®äººã¯æ°ã¥ããªãã®ã§ã¯ãªãã ãããï¼
追è¨(2008-06-03)
ãµããã¨ããã®ä¸æ調æ»çµæãã¡ã¼ã«ããã®å¼ç¨ã ãã ã£ãã®ã§ãåå¾ã«ã¡ãã£ã¨æç« è¿½è¨
追è¨(2008-06-03)
ãããã¤ã³ã¿ã¼ãããã®ãé害çºçã®ãç¥ãããã«ããã«è¿½è¨ãããã¾ããã
[6æ3æ¥è¿½è¨2]
ãããå¼ç¤¾æè¡è ã«ãã該å½ã®ãµã¼ãã調æ»ãã¾ããã¨ãããä¸è¨ãµã¼ãã«ã¦
ãããã¯ã©ããã³ã°ããã¦ãããã¨ãå¤æãããã¾ããããã®ãããå½±é¿ç¯å²
ãããã®ã客æ§ãµã¼ã㸠WEBã«ããã¢ã¯ã»ã¹ãè¡ã£ãå ´åãæ¹ç«ãããã¦ã§ã
ããããã¼ã¸ã表示ãããäºè±¡ããããã¾ãããç¶æ³ã«ãã£ã¦ã¯ãã¦ã¤ã«ã¹ç
ãããã«ãã被害ããããããå¯è½æ§ããããã¾ããããããå½±é¿ãåããããã客æ§ã¸ã¯ãå¥éç¶æ³ã®é£çµ¡ãããã¦ããã ãã¾ãã
追è¨(2008-06-04)
é«æ¨ãããBlogã«ä»åã®ãã¨ãæ¸ããã¦ãã¾ããã
ã高木浩光@自宅の日記 - 通信路上の改竄攻撃発生に、Webサイト運営者が説明責任を負うのか?ã
URLã«typoããã£ããã¨ã«ãã¾ãããªããæ°ã¥ããorz
ã¯ããããã»ã»ã»
追è¨(2008-06-05)
åã被害ãããã¦ããããããã®ã¡ã¼ã«ã®å
¨æãå
¬éããã¦ãã¾ãã
ã(続)ホスティングでは同一セグメントのマシンのセキュリティと一蓮托生 - mmasudaのはてな日記ã