ãã¯ããã°ãã«ã¡ã¯ãããã¨ã§ãã
ãã¤ããèå¼±æ§å¯¾å¿ã«ã¤ãã¦ã®è¨äºãæ¸ããã¨æã£ã¦ããããBINDãããã¾ã
èå¼±æ§ãçºè¡¨ãã¦ããã¾ãããï¼CVE-2015-8704,CVE-2015-8705)
ååã®çºè¡¨ããï¼ã¶æãç«ã£ã¦ããªãã®ã«ãæµç³BINDããã ãªãã¨æãã¾ãããï¼é ãç®ï¼
Â
ä»æ¥ã¯ãBINDã«ç¦ç¹ããã¦ã¦ãèå¼±æ§å¯¾å¿ã¨ã¯ã©ããããã¨ãå¿ è¦ãªã®ãã¾ã¨ãã¦ãããã¨æãã¾ãããã§ã«æ¥å¸¸çã«èå¼±æ§å¯¾å¿ããã¦ããæ¹ã¨ããããã¯ãããªããããããã©DNSãµã¼ãã®ç®¡çè ã«ãªã£ã¦ãããã¨ããããBINDã¨ããã½ããã¦ã§ã¢ã§åãã¦ãããã¨ã¯ç¥ã£ã¦ãããã¨ããæ¹åãã ã¨æãã¾ãã
Â
ï¼ï¼BINDã®èå¼±æ§ã®çºè¡¨ããã£ãããã
BINDã®èå¼±æ§ã«ã¤ãã¦ãä¸ã®ä¸ã§ä¸çªæ©ãçºä¿¡ããã®ã¯BINDã®ãµãã¼ããè¡ã£ã¦ããISCæ¬å®¶ï¼BIND | Internet Systems Consortiumï¼ã ã¨æãã¾ããæ å ±ããã£ãããã主ãªæ段ã¨ãã¦ã¯ä»¥ä¸ãããããã¾ãã
ã»ISCãæä¾ãã¦ããã¡ã¼ãªã³ã°ãªã¹ãã¸ã®ç»é²
ã»ISCãæä¾ãã¦ããRSSãå©ç¨ãã
ã»ISCå ¬å¼twitterããã§ãã¯ãã
è±èªãªã®ã§ããã¨è¦ãããã«ããã§ãããå人çã«ã¯ISCæ¬å®¶ã«ã¤ãã¦å¿ ãããã³ãã³ãã«ã¢ã³ãããå¼µã£ã¦ããªãã¦ãããããããªãããªã¨æãã¾ããçç±ã¯å¾è¿°ãã¾ãã
Â
BINDã®èå¼±æ§ã«ã¤ãã¦ã次ã«çºä¿¡ãã¦ãããã®ã¯JPRSã§ããæ¥æ¬ã®.jpãã¡ã¤ã³ã®ç®¡çããã¦ããä¼ç¤¾ã§ããç·æ¥æ§ã®é«ãBINDã®èå¼±æ§ãçºè¡¨ãããã¨è¿ éã«ã¢ãã¦ã³ã¹ãåºãã¦ããã¾ãã
CVE-2015-8704,CVE-2015-8705ã®æã¯ãISCããã®çºè¡¨ãï¼ï¼æ¥ã®11:54ï¼æ¥æ¬æéã¨ã®æå·®ã¯ï¼ï¼æéã§ãããæ¥æ¬æéã«ç´ãã¨20æ¥ã®4:54)ã ã£ãã®ã«å¯¾ãï¼
JPRSããã®ã¢ãã¦ã³ã¹(ï¼ç·æ¥ï¼BIND 9.xã®èå¼±æ§ï¼DNSãµã¼ãã¹ã®åæ¢ï¼ã«ã¤ãã¦ï¼CVE-2015-8704ï¼)ãï¼ï¼æ¥ã®11:00ã§ããã大ä½ï¼æéã§ãããããããã¾ã¨ã¾ã£ãæ¥æ¬èªã§ã¢ãã¦ã³ã¹ãã¦ãã ããã®ã§ã¨ã¦ããããããéãã§ããä¸å¸ã客å ã«èª¬æããã¨ãã«ãJPRSã®ã¢ãã¦ã³ã¹ãå°å·ãã¦æã£ã¦è¡ãã¨èª¬æãããããã§ããJPRSã¯BIND以å¤ã®DNSã®ã½ããã¦ã§ã¢ã«ã¤ãã¦ãã¢ãã¦ã³ã¹ãåºãã¦ãã¾ãã
Â
 ãã®ä»JPCERT/CCãåºãã¢ãã¦ã³ã¹ãããã¾ããJPCERT/CCã¯DNSé¢ä¿ã ãã§ã¯ãªãèå¼±æ§å ¨è¬ã«ã¤ãã¦åãæ±ã£ã¦ããã®ã§ãæ®æ®µãããã§ãã¯ãã¦ããã¦æã¯ãªãã¨æãã¾ãã
ISCæ¬å®¶ã«ã¤ãã¦å¿ ããããã³ãã³ã«ã¢ã³ãããå¼µã£ã¦ããå¿ è¦ã¯ãªããã¨è¨ã£ãã®ã¯ããã®JPRSã®ã¢ãã¦ã³ã¹ãããããã§ãã
Â
ï¼ï¼å¯¾å¿ãããã©ããã決ãã
ããã¯ãç°å¢ã«ãã£ã¦ç°ãªãã®ã§ãªãã¨ãè¨ããªãã®ã§ãããç§ã®å ´åã¯JPRSãåå¿ãã¦ãããã®ã¯å³ã対å¿ã®å¯¾è±¡ã«ããã¨æ±ºãã¦ãã¾ããç·æ¥æ§ã®é«ããã®ã¯ã¿ã¤ãã«ã«ï¼ç·æ¥ï¼ã¨ã¤ãã¦ãã¾ãã
ãã¨ã¯ä»¥ä¸ã®è¦³ç¹ããå¤æãã¦ãã¾ãã
ã»å¯¾è±¡ã®ãµã¼ããå¤ã«åºã¦ãããã©ãã
âFWã§å®ããã¦ãããã©ãããå¤ã«åºã¦ãããã®ã§ããã°ãä¸å»ãæ©ã対å¦ããªãã¨ãããªãã§ãããªã¢ã¼ãã§æ»æå¯è½ãªèå¼±æ§ã ã¨ãã¤æ»æãåããããããã¾ãããã
ã»èå¼±æ§ã«ãã£ã¦åããå½±é¿ã大ãããã©ãã
âJPRSã®ã¢ãã¦ã³ã¹ãèªãã¨ãã©ã®ãããªæ¡ä»¶ã§ã©ã®ãããªå½±é¿ãåãããããããã¾ãããµã¼ãã¹åæ¢ãªã©ã ã¨ãä¼ç¤¾ã®ãµã¼ãã¹ã®ç¶ç¶ã«é¢ããã®ã§å³å¯¾å¦ããªãã¨è¡ããªãã¨æã£ã¦ãã¾ããï¼BINDã«éã£ã¦è¨ãã°å人æ å ±æ¼æ´©ãªã©ã¯ããã¾ãèããããªãã§ããã©ã»ã»ã»ã¾ã¼ã³ãã¾ãã¾ãåããããã¨ãããã¨ãåä½ãã¦ãããµã¼ãã¹ãäºæ¸¬ãããã®ã§è¯ããªãã§ããï¼
Â
åºæ¬çã«ã¯èå¼±æ§ã«ã¯ãã¹ã¦å¯¾å¿ãã¹ãã ã¨æã£ã¦ãã¾ãããã ããå®éã«å¯¾å¿ãããã©ããã¯å®éã®ç°å¢ãã対å¿ã«ãããå·¥æ°ã¨ãªã¹ã¯ã天秤ã«ããã¦ãä¸å¸ã客å ã¨ç¸è«ãã¦å¤æãã¦ãã¾ãã
Â
3.対å¿ä½æ¥ãå®æ½ãã
ç§ã¯linuxç³»ã®OSã§ããDNSãµã¼ããéç¨ãããã¨ããªãã®ã§ãlinuxç³»ã«éã£ã¦æ¸ãã¾ãã
Â
BINDãã½ã¼ã¹ã§ã¤ã³ã¹ãã¼ã«ããå ´åãISCãæä¾ãã¦ããä¿®æ£çã®ã½ã¼ã¹ãè½ã¨ãã¦ãã¦ãconfigureâmakeâmake installã®ãã¤ãã®æµãã§ä¿®æ£çãã¤ã³ã¹ãã¼ã«ãã¾ããmake installãããåã«ãnamed.confãªã©ã®è¨å®ãã¡ã¤ã«ã®ããã¯ã¢ãããã¨ã£ã¦ãããä¿®æ£çã®ã½ã¼ã¹ãå±éãããã¨ã«ãä¿®æ£çã®named-checkconfã使ã£ã¦åä½ä¸ã®BINDã®named.confã®ã³ã³ãã£ã°ãã§ãã¯ãå®æ½ããã¨ããå®å¿ã§ãã
è足ãªãã§ããããã®ä¿®æ£çã®named-checkconfã使ãæ¹æ³ã¯å 輩ããæããã¾ãããèããæã¯é ãããªãã¨æãã¾ãã(ã½'Ï`)
Â
以åã®èå¼±æ§å¯¾å¿ã§ãmake installãããã¨ã«ãBINDãèµ·åãã¦ããªãã¦ç¦ã£ãçµé¨ãããã¾ãããã®å ´ã§åãã¼ã¸ã§ã³ã®ã½ã¼ã¹ãmake installããªããã¦å¾©æ´»ããã¾ã§æ±ãã ãã ãã§ããããã¼ã¸ã§ã³ã¢ããã«ããåä½ãå¤ãããæ°ãã¼ã¸ã§ã³ã§ã¯ä»ã¾ã§ä½¿ç¨ãã¦ããnamed.confã®è¨å®ãåãä»ããªããªã£ããã¨ãåå ã§ãããå 輩ã«named.confãä¿®æ£ãã¦ããã£ã¦ããã¼ã¸ã§ã³ã¢ãããå®æ½ãã¾ãã(ï½ï¼Ïï¼Â´)
Â
BINDãããã±ã¼ã¸ã§ã¤ã³ã¹ãã¼ã«ããå ´åããã£ã¹ããªãã¥ã¼ã·ã§ã³ãä¿®æ£çããªãªã¼ã¹ããã¾ã§å¾ ã¤ãã¨ã«ãªãã¾ãããªãªã¼ã¹ããããããã±ã¼ã¸ã®ã¢ãããã¼ããããã°OKã ã¨æãã¾ãããã ããããã®ããã«ãnamed.confãªã©ã®è¨å®ãã¡ã¤ã«ã¨ãã¯ããã¯ã¢ãããã¨ã£ã¦ãããã»ããããããããã¾ããã
ï¼ããã±ã¼ã¸ã®ã¢ãããã¼ãã§ããä¿®æ£çã½ã¼ã¹ã®named-checkconfãå®è¡ããã®ã£ã¦æå¹ãªãã§ããããããã®ã¸ãã¯ãã£ããã¨ãªãã®ã§ä¸æã§ãã»ã»ã»(ã_ã)ï¼
 修æ£çã½ã¼ã¹ãå±éãã¦named-checkconfãå®è¡ãã以å¤ã«ãããã±ã¼ã¸çãªãã§ã¯ã®ã³ã³ãã£ã°ãã§ãã¯ããããã£ã¨è¯ãæ¹æ³ãããã°æãã¦ããã ãããã§ãã
Â
ãªãããªãã¾ããããç§ã¯ãããªæãã§BINDã®èå¼±æ§å¯¾å¿ããã¦ãã¾ãã
ä¸ã®ä¸ã«ããDNSãµã¼ã管çè ï¼å¹´çã®æ¹ã®å½¹ã«çµã¦ã°ã¨ã£ã¦ãå¬ããã§ãã
ééã£ãç¹ãªã©ããã¾ãããã@infragirl755 ã¾ã§ç¥ããã¦ãã ããã¨ããããã¾ãã
Â
ããã§ã¯ãããã¿ãªããã¾ã (´-Ï-ï½)
Â
以ä¸ã追è¨
ã»JPCERTã®æ£å¼å称ã¯JPCERTã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ã ã¨ææãããã ããè¨è¼ãJPCERT/CCã«ä¿®æ£ãã¾ããã
ã»BINDããã±ã¼ã¸çã®ã¢ãããã¼ãã®ãã ãã«ã¤ãã¦ãå°ãæ¥æ¬èªããããã«ããã®ã§ä¿®æ£ãã¾ããã
ã»ISCçºè¡¨ããJPRSã®ã¢ãã¦ã³ã¹ã¾ã§ã®æå·®ã«ã¤ãã¦ä¿®æ£ãã¾ãããï¼æ¥æ¬æéã®ããããªãã®ã«çæ¨ã®ãã¹ï¼
Â
ã»RHELåãã®æé ãä½æãããæ¹ãããã£ãããã¾ããï¼
ã¾ãã´(@makopicut)ããããããã¨ããããã¾ãã
@infragirl755 ããã¨ããã«åºæ¿ããã¦ãèªåã® BIND ãã¼ã¸ã§ã³ã¢ããæé ã¾ã¨ãã¦ã¿ã¾ããã RHEL äºæOSåãï¼Ver5以éï¼ ã®æé ã§ãã https://t.co/os7iu1QXEk
â ã¾ãã´ (@makopicut) 2016, 1æ 23
Â
ã»ããããããã±ã¼ã¸çã¨ã½ã¼ã¹ã©ã¡ããç¨ãããã¨ãã話ã«ã¤ãã¦ãã¤ã¼ãããã¦ããã®ã§å¼ç¨ããã¦ããã ãã¾ãããã½ã¼ã¹çã ã¨æãããããã§ãããã»ã»ã»ã
鳥海ãã(@sarvant_yue)ããããããã¨ããããã¾ããã
ããããè«ã§ããBINDã®ãã¼ã¸ã§ã³ç®¡çã¯rpmçã®ããã±ã¼ã¸ã§è¡ãªãã¹ããªã®ããã½ã¼ã¹ã§è¡ãªãã¹ããªã®ããç§ã®ã¨ãã§ã¯å
¨ã¦ããã±ã¼ã¸ç®¡çã§æãã¦ãã¾ããæè¡æ°´æºã®ä½ã人ã§ãyumçã§ä½ã¨ããªãã®ã§ãçµå±ã¯éç¨ãæ
å½ã«ä¾ãã®ãããã https://t.co/kz3OT52AOY
â 鳥海ãã (@servant_yue) 2016, 1æ 23
Â
Â
ãã¨ã¯ã»ã»ã»ISCã®ç¬¬ä¸å ±ããJPRSã®ã¢ãã¦ã³ã¹ãåºãã¾ã§ã®æéå·®ã®è©±ã¯ãç¾å°æéã§ã¯ãªããï¼ãã¨çªã£è¾¼ã¾ãã¦ããã®ãTLã§çºãã¦ãã¾ããããã¼æ¥ãããã(ã»_ã»;)
ä»å¾ãæ°ã«ãªããã¨ãããã°è¿½è¨ãããã¨æãã¾ãã