å
ã¡ãã£ã¨ãç³ãè¾¼ã¿ããã¿ã³ãæ¶ãã¦ã¾ãããï¼ããã¾ãã¼ãï¼ã復活ãã¾ããã ã§ãã¹ãã·ã£ã«ã²ã¹ã*1ãã±ãã¼ã¤ãã¾ãããã©ãããããã *1:ã殿æ§ã¨ããã¦ã¯ãµããï¼ç¬ï¼ï¼
æ£å¼ãªåç¥ãã¼ã¸ãã§ãã¾ãããç³ãè¾¼ã¿ã¯ææ¥ããã§ãã ãªããç·æ¥ãªãã¨ã§ããã¾ããããã¿ãªããæ¥ã¦ãã ãããã¼ãã¡ãªã¿ã«ã¹ãã·ã£ã«ã²ã¹ãã¨äº¤æ¸ä¸ï¼ã¹ãã·ã£ã«ã»ãã·ã§ã³ä¼ç»ä¸ãä¼ç»ãã²ã¹ãã®æ å ±ã¯ãåºããããã«ãªã次第ãã®æ¥è¨ï¼ä½ï¼ãããã¯â¦
KYE: The Honeywall CDROMããä½ã§ãCDROMåã§ãããã
ãªãªã¸ãã«ã¯æ®¿æ§ã¨ãã«ãå çã¨ãã®ä»è¿ã®è¥è ãã¡ãããã«é»ãå¼è·å£«ãããä½ã£ãéèªç¨è¨äºã§ããããããããªäººãæãå ¥ããããã¦ãã¾ãã ãªãªã¸ãã«è¨äºã®ã¿ã¼ã²ããã¯ãããªãã®æè¡è ãããã¡ã ã£ããããã®ã§ãç¨èªã¬ãã«ããããªãã«é«ããã®ããâ¦
ãã¾ããããçµç±ã ãã¡ãã¯ãä»ã¯ã¾ã æ°åã§æ¹åããããã¨åã¶ã®ã¯æ©ãã£ã¦æ°ããã¾ããã©ãããã¾ã ãã¾ãæ°ãåºã¦ããªããã¨ãããã¨ããç¥ãã¾ããããããã£ã±åºåãæ°ãå¢ããªãã¨ãæ¢ã人ãå¢ããªãã§ãããããã
ã¾ã ã¾ã äºç¨®ã¯åºã¦ãããããã§ããããã¾ããæ¥æ¬ã§æ¬æ ¼çã«åºã¦ããã®ã¯é±æãã¨ãã話ãããã¾ããããé£ä¼ã¯ãããã«å®¶ã§éä¿¡ããªãã£ã人ãã2æ¥ã ãåºã¦ä»äºçµãããªãæ°å³ã§é±æ«å®¶ã«æã¡å¸°ã£ã¦ããã¯ã¼ã å ¥ãè¾¼ãã£ã¦ãããã¨ã§ããããï¼ãã¾ããã©â¦
ã¢ã¡ãªã«ã¨ãã¯è¶ 大é¨ãã¿ããã§ããã©ããã é£ä¼ã ã£ãã®ã£ã¦æ¥æ¬ã ããªã®ã§ãæ¥æ¬ã¯ã¾ãããããã£ã½ãã§ãããã¢ã¸ã¢ããã£ããã¤ã©ã¬ã¦ãã£ã½ããããã ã§ããã¾ãæ¥æ¬ä»è¿ã§pingã«ãããã¦ããããã¸ãâªã¿ãããªè©±èããã¦ãã¾ããããããã£ãã大ä¸â¦
Sasserã¯ã¼ã åºã¦ã¾ããããé£ä¼æãã®ç¤¾å ã¯ããã¸ãããã¼ã æãã¦6æ¥ã«ç¤¾å ã«æã¡è¾¼ã¾ããPCããããæ¤ç«ãããã§ããã©ãããä»ã®ãã¡ã§ãªãï¼ãã®ãã¡äºç¨®ã¨ãåºã¦ããã¨éãæé ãå¿ è¦ã ãããã©ï¼ã¾ã ãã¿ã¹ã¯ããã¼ã¸ã£ã¼ããavserve.exeã¨ããããâ¦
ãæè¦åéã§ãã¼ã
443ãã¼ãã¨ã139ãã¼ãã¸ã®ã¢ã¯ã»ã¹ã£ã¦ãä»ã®ã¨ããã»ã¨ãã©å¢ãã¦ããªãé°å²æ°ã§ããã©ãæ¥ã¦ã¾ããããï¼ æMVPã®ã¨ããã«ã¯ä¸å½æ¹é¢ããä¸çºæ¥ã¦ããããã§ããã©ã ã£ã¦ãããã139or445ï¼LSASSã®ãã¤ãã話ã ã¨æããã ãã©ãªã¼ãã¿ããªãããå½ã¦ã¦â¦
ãã£ã¨èãç¶ãã¦ãã¾ãã æãä¼ç¤¾å¡ã¨ããç«å ´ããã£ã¨å®å®çã ã£ãããã¯ãå é¨ã®äººã¯å«ç観ããã£ã¨é«ãã£ãã¨æããã§ãããã©ãã§ããããããï¼ã転è·ãã¨ããå®å主義ãã¨ããããããæ代ã«ãªã£ã¦ããå é¨ç¯è¡ã¯å¢ãã¦ãããããªæ°ããã¾ããããã¯â¦
ãã¼ã¼ãã«ãªã£ãã«ã¼ã¿ã¼ãããããã¨ãã§ãã¯ãã¦ããã¨ããã¼ã¼ã以éããããªæéã«ãããªã¢ã¯ã»ã¹ãã ICMP,port 0 TCP,port 80 UDP,port 1434 TCP,port 139 UDP,port 53 TCP,port 445 TCP,port 1753 TCP,port 3127 TCP,port 445 TCP,port 135 UDP,portâ¦
ããã¾ããããã®ã¨ããã§ããã«ããã³ããå ¥ã£ã¦ã¾ãããã£ã¦ãããã¿ãªããã®å»ºè¨çãªè°è«ã¯å±ã¿ã«ãªãã¾ã¤ããã£ã¨ãã£ã¨ããã³ãããªãããã¾ã¤ã
ãã°ãããããã³ããå ¥ã£ã¦ã¾ããï¼ç¬ï¼ãã§ããé¡ããã°ããã²ã¨ããã³ã欲ããã§ãããã ããããå ±åæ¸ã®æ¸ãæ¹ã«ãªããããå¾ãªãã£ãåé¡ã®æ¬è³ªã¯ã©ãã«ããã®ãï¼ã£ã¦ããã¨ããã«çªã£è¾¼ãã§æ¬²ãããªãã
人éã®å¼±ããããªãã 人ã¯å¼±ããã®ã ããæ«ãããã®ã ãã楽ãªã»ããé¸ã¶ãã®ã ããéãå·®ããã®ã ããç®ã®åã«ãã éå¡ã転ãã£ã¦ãã¦èª°ãè¦ã¦ããªãã¨ãããããã¨ããªã人ã®æ¹ãçããã ããã ã§ããã ããã¨ãã£ã¦ãããã人ã®å¼±ãã«ãã管çããããâ¦
æ¯æ¥ã®ããã«çµéå ±åä¸ãããããªããã ãããã¡ã³ãµã¤ãã¸ãæ¿å±ã®ã¡ã¼ã«ã100éãå±ããã ãããªãã2ã¶æ以å ã«æéããªãã¨ã ãï¼æ¼æ´©ãããã©ãã確èªãããµã¤ããã¢ã¬ã²ãªæBBã¨ãï¼ç¬ï¼ãä»ã®æ¼æ´©äºä»¶ã¨ã¯ä¸ç·ãç»ãã¦å°åçäºãéãç´ã£ã¦ããæå ¬â¦
ã¨ãããä¹ ä¿ç°å°åçäºããã ä»ã¾ã§ç¹ã«çç±ã¯ç¡ãï¼ã¦ã½ï¼ã³ã¡ã³ããã¦ãã¾ããã§ãããã©ããã®ã¤ã³ã¿ãã¥ã¼è¨äºãèªãã§æ°ãå¤ããã¾ãããä»åã®ä¸ä»¶ã誰ãã©ã責任ãåãã¹ããªã®ãããããã話ã¯ãã¡ããéè¦ãªã®ã§ããããã®ã¤ã³ã¿ãã¥ã¼ã§èªã¿åãâ¦
ãã©ã¬ã³ã¸ãã¯ï¼ç¬ï¼ãæè¿ããã²ã«ç¸ãããããªãã½(´ã¼`)ãã ã§ããã©ã¬ã³ã¸ãã¯ã£ã¦æéã¨ã®æ¦ãã ã£ããããã®ã ãã©ãæéããããªãã¨è¯ããã¿åããªããããªãããã©ã³ã¹é£ãããªãã
å´å±±ãããããããæ å ±ã«ããã°ã16æ¥15æããã®çäºä¼ã§åãæ±ããåè°ãã18æ¥ã«è¡è°é¢å¤åå§å¡ä¼ã§æ¹åã®æ¡æ±ºãè¡ãã¨ãã æ¡ç´èªä½ã¾ã ã¾ã åé¡ãå¤ãã®ã«ããã£ã¨ããéã®ãã®æ¡æ±ºãããã®ãã¼ï¼
ããããã°å»ççµæ¸å¦ã¨ããã®ãããã¾ããããã»ãã¥ãªãã£çµæ¸å¦ã¨ããã®ãä¸çµç¹ã«éãã¦ããã¨ãªãèããå¿ è¦ããããã§ããããããããããã
ããããã¤ã¯ãã½ãããããã¯ç®èããã¦ããããä½ãç¡ããç´ ç´ã«æãã¾ãã
ããããã°æ¨æ¥ã®ãããéç©ãã¿ã§ãããããã·ããã£ãã¯ã·ã§ã³ã¨ãnmapç³»åã«ãã®æã®ãã¿ããã£ããã¨ãæãåºããããã¨ã§æã£ã¦ã¿ãã£ã¨ã
TCPã¨ãIPã®ããããªã©ãªã©ã«å ¥ã£ã¦ããæ å ±ã§ãä½ãéããã¨é¢ç½ããããªãï¼ ã¡ãªã¿ã«TCPãããã¯ãã½ã¼ã¹ãã¼ãããã£ã¹ãã£ãã¼ã·ã§ã³ãã¼ããã·ã¼ã±ã³ã¹çªå·ã確èªå¿ççªå·ããã¼ã¿ãªãã»ãããäºç´é åãã³ã¼ãããããã¦ã£ã³ãã¦ãµã¤ãºãç·æ¥ãã¤ã³ã¿â¦
ãããããããã²ã¨ã¨ããã®å¤æãåºããã¨ããæãã§ãããããã¦ãã©ããããã¨ã«ãªãã®ãã ãä¸æ£ã¢ã¯ã»ã¹ãã¨ãããã¨ã«ãªãã®ãï¼ ã§ã¯ãä½ããã¤ã©ããã£ã¦è¦ãï¼è¦ãã ãï¼ï¼ãã¨ããä¸æ£ã¢ã¯ã»ã¹ãã¨ãããã®ãï¼ ãä¸æ£ã¢ã¯ã»ã¹ãã§ãããã¨ããçâ¦
officeããã®ä»¶ããããããªæè¦ã解éãåºã¦ãã¾ãããã£ã¨ã¿ãªãããæãããã¨ã ã¨æããã§ãããç¹ã«ãã¬ãã®ãåæãã§è¨ãã¨NHKã¨ãã®å ±éãé ·ãããã£ã¦æ°ããããã§ããã©ãã§ããããï¼é£ç¶æ®ºäººç¯ãããªããã ããï¼è¦ç¬ï¼ãã£ã¦è¦ãªããæã£ãã£ãâ¦
ã¤ã´ã¡ã¤ããããããã¡ã¤ã¢ã¦ã©ã¼ã«ããªã¢ã¼ãã¨ã¯ã¹ããã¤ã¿ãã«ã£ã¦ã©ããã¨ãï¼ http://www.eeye.com/html/Research/Upcoming/20040213.html http://www.eeye.com/html/Research/Upcoming/20040213-2.html èªåæ¡æ£åä¸æ£æ令é»ç£çè¨é²ã¨ããåºã¦ãããâ¦
ã»ãã¥ãªãã£ã¹ã¿ã¸ã¢ã ã»ããã¼ã§ããã£ã¨ãã®ãã¿ï¼ç¬ï¼ã ããããã¨ããhttp://ensi.tdiary.net/20040211.html#p01ã¨ããã®å ã®ãããã¾ããã®ã¨ããhttp://d.hatena.ne.jp/mozuyama/20040209#p6ã§ã®ã¾ã¨ãã¨æè¦ãèªãã ææã§ã®ä¼è©±ã§ã¯ããã¾ãããâ¦
é®æã¨ããäºæ ã«ãªã£ã¦ãã¾ã£ããããªã®ã§ãããèµ·ãã£ã¦ãã¾ã£ããã¨ã¯ä»æ¹ãªãã®ã§ããã¨ã¯ããããä½ãããããã§ããããã ãªãé®æããã¦ãã¾ã£ãã®ããã©ããæªãã£ãã®ãï¼ ã»ãã¨ãã«å½¼ã®ãã£ããã¨ã¯è¨±ãããªããã¨ã ã£ãã®ãï¼ ããã¨ãããããâ¦
é®æã§ããããã¼ãã ãã®ä»¶ã«é¢ãã¦ã¯ãã¨ã§ã³ã¡ã³ããããã£ã¨ã ã»ã»ã»ããããããã¹ãã¨æããã¨ãå¤ããã¦ãã¾ã æ´çã§ãã¦ã¾ããï¼ç¬ï¼ã ã§ãã²ã¨ã¤ã ãããã£ã¨ã©ããã§ãã§ã«è¨ããã¦ãããã¨ã ã¨ã¯æãã¾ããã ä»åã®ä»¶ã被害è ã£ã¦èª°ãªãã§ãâ¦
SysAdminã®è¨äºãããSOHOåãã®ãªã¼ã«ã¤ã³ã¯ã³ããã±ã¼ã¸çã½ããã¦ã¨ã¢ã ã¨ãã 1. Linux Netfilter -- Stateful packet inspection (firewall) with NAT/PAT and full logging capabilities 2. Snort -- The community standard for real-time network IDâ¦