Google Safe Browsing API ãå©ç¨ãã¦ã¹ãã ãã³ã¡ã³ãã¹ãã 対çããã¢ã¤ãã¢
Safe Browsing API - Safe Browsing API
ã«ã¦ãGoogleãphishingãmalwareã®ææã«ä½¿ããã¦ããã¨æãããURLãé
å¸ãã¦ããããµã¼ãã¹ãéå§ããã
ããã¯ç´æ¥URLãæ¸ãã¦ãããããããªãã¦ãMD5ã«ã¨ã³ã³ã¼ãããããªã¹ãããã¦ã³ãã¼ãããã¦ããããã¨ãããã®ã«ãªã£ã¦ããã
APIã¨ããã®ã§ãæªããURLãéã£ãããåããããããããããããªãããè¿ãã¦ãããã®ãã¨æã£ãã®ã ããMD5ã«ããå
¨ãªã¹ããè¿ãããããã£ã¡ã§ãããã³ã°ããã¦ãããã¨ãããã®ã ã£ãã
ãªã®ã§ãã´ãåã£ãããããã¤ãã®ãã¿ã¼ã³ã§è©¦ããããã¨ãããããªå®è£
ã¯ãã¡ãã§ããå¿
è¦ãããã
詳ããã¯ãã¡ããåç
§ã
Safe Browsing API - Safe Browsing API
ã§ããããæ²ç¤ºæ¿ã¸ã®ã¹ãã ã³ã¡ã³ã対çããã¹ãã ã¡ã¼ã«ã¸ã®å¯¾çã«ãå©ç¨ã§ããã¨æãã
URLBLã®ãããªä½¿ãæ¹ãããããã§ãã
phishingã®ã¡ã¼ã«ã«ã¯ãã®URLãæ¸ãã¦ããããå¼¾ããã ããããããªãã æã£ãbiglobe-ne.comã®ä»¶ãªããããGoogleçµç±ã§è¡ãã¨è¦åãåºããããã³ã¡ã³ãã¹ãã ã®ãã£ã«ã¿ã¨ãã¦å©ç¨ããã°å¹ããã¯ãã ã¨æãã
次ã«åºã¦ããã®ã¯ãURLç縮転éãµã¼ãã¹ãçµç±ãã¦ä½¿ããã¨ãããã®ã ã¨æããã©ããã®æã®ãµã¼ãã¹ããªã¹ãã¢ãããããã¨ã¯å¯è½ã ããããã転éãµã¼ãã¹ã®URLã ã£ããããã®å
ã®URLã¾ã§ã¿ã¦ãããã§å¤å¥ããã°ããã ããã
ã¡ãªã¿ã«ã転éå
ãããã«è»¢éã ã£ããããã®æç¹ã§ååæªããããæå¦ãã¦ãã¾ãã°ããã
ã¾ã ã©ãã«ããµã³ãã«ããã°ã©ã ã転ãã£ã¦ãªãã®ã§ãDigest::MD5::Perl使ã£ã¦ã¼ã¡ã¼ã¡ãµã³ãã«æ¸ãã¦ã¿ããã
(追è¨)
ä¾ã®ä¸è¯ã¹ããã¼ã®URLãä¾ãã° www.din-or.com/bbs/ ã¨ãã§ãããã¨
www.din-or.com/bbs/
ããã®ãµã¤ãã¯ã³ã³ãã¥ã¼ã¿ã«æ害ãä¸ããå¯è½æ§ãããã¾ãã
ã¨åºã¦ããã®ã§ããã®URLã¯ç»é²ããã¦ãããã¨ããããã¾ãã
ç°¡åã«è©¦ãã«ã¯ãä¸è¨ãµã¤ãã§APIãã¼ããã£ã¦ãgoogle-black-hash.txt google-malware-hash.txt ã¨ããMD5ããã·ã¥åããããªã¹ããã¡ã¤ã«ããã¦ã³ãã¼ããã¾ãã
ãã ãä¸èº«ã®ãªã¹ãã¯ãããªæãã®MD5ããã·ã¥ãªã®ã§ãå®éã«ã©ããªãµã¤ãããªã¹ãã¢ããããã¦ãã®ãã¯ãããã¾ããã
<BODY>[goog-malware-hash 1.85] +0000a2e9842085e75a57282eff0e7832=20 +0001849970ec2acd0b73bfa18eb91ac8 +0001b67cc3f39afdb2a2acb71cd7f869=20 +00023d5c9707dbe4bece6a215e725f96 +0002ca1961f3581c298757fd999c9be4=20
ã§ãperlã§Digest::MD5ã®ã¢ã¸ã¥ã¼ã«çªã£è¾¼ãã§ã以ä¸ã®ãããªãµã³ãã«ããã°ã©ã ãæ¸ãã¾ãã
use Digest::MD5 'md5_hex'; print 'Digest is ', md5_hex('www.din-or.com/'), "\n";
ããã¨MD5åãããããã·ã¥ãè¿ã£ã¦ãã¾ãã
Digest is 182106c5015f43e144c4e3f8d19e6fdc
ãããgrepã§æ¤ç´¢ããã¨
grep 182106c5015f43e144c4e3f8d19e6fdc google-*.txt
google-malware-hash.txt:+1820ed98bdbf3f94d0997d6c99f0b236 +182106c5015f43e144c4e3f8d19e6fdc=20
ã¨ããæãã«ããããã¦ãã¾ãã
ãã®æµããã³ã¼ãã«ãã¦ããã°OKã§ãã
ãã¶ãURLãæ£è¦åãã¦ããã®ãä¸çªããã©ãããããªã¨ããã§ãã
(ããã«è¿½è¨)
URLã®æ£è¦åã ã¨ãã«ã¤ãã¦ã¯ä¸è¨ã®å ´æã«ããããªæãã«ããããã¨ããGoogleã®å
¬å¼æ
å ±ããããã§ãããæ®å¿µãªãããµã³ãã«ããã°ã©ã ã¨ãã¯ç¡ãã
Safe Browsing API - Safe Browsing API
ãã ãDiscussion Groupã«ãã£ãæ
å ±ãããMozilla(FireFox)ã§å©ç¨ãã¦ãéã«ãã©ããªãµãã«å¦çãã¦ããããã¡ãã«æ¸ãã¦ããã¾ããã
Phishing Protection: Server Spec - MozillaWiki
ããããããèªãã§èªåã§å®è£
ãããªãã該å½ã®ã½ã¼ã¹èªãã§PHPãªãPerlãªãã«ç§»æ¤ããã»ããæã£åãæ©ãããªã®ã§ãæ¢ãã¦ã¿ããã¨æãã¾ãã
ãããâ¦ãããããµã¤ãºãã§ãããã ããã該å½ç®ææ¢ãã ãã§ã大å¤ããã§ããã
(ã¾ãã¾ã追è¨)
ãã¾ãã«ã½ã¼ã¹ãã§ããã¦ãã¨ã¦ãæ¢ãããããã£ãã®ã§ãid:nyama ããã«ã¡ã¼ã«ã§æããè«ãã¾ããã
ããããã¨ããã
Phishing Protection - MozillaWiki
http://wiki.mozilla.org/Phishing_Protectionhttp://dl.google.com/firefox/google-safebrowsing.xpi
(æ¡å¼µå xpi ãzip ã«å¤æ´ããã°è§£åã§ãã)
ã¨ãããããªã¢ããã¤ã¹ãããã ããè¦äºè©²å½ç®æã®ã½ã¼ã¹ãè¦ããã¨ãåºæ¥ã¾ããããããã¨ããããã¾ãã
ä¸ã®FireFoxæ¬ä½ã«çµã¿è¾¼ã¾ãããã®ã¯C++ã§æ¸ãã¦ããã½ã¼ã¹ã§ãä¸ã®ã¨ã¯ã¹ãã³ã·ã§ã³ã®ãã®ã¯Javascriptã®ã½ã¼ã¹ã¨ãªã£ã¦ãã¾ãã
ã¨ãããããJavascriptã®ã»ããPHP/Perlã«ç§»æ¤ããæ¹åã§é²ãããã¨æã£ã¦ãã¾ãã
(ããã«è¿½è¨)
ãã£ã±ãSpamAssassinåãã«ãããããã©ã°ã¤ã³æ¸ãã¦ã人ãåºã¦ãã¦ã¦ãNet::Google::Safebrowsingã¨ããã¢ã¸ã¥ã¼ã«æ¸ãã¦ãããã§ãã
ã¢ã¼ã°ã«ã¨ã«ãã¨ãã¦ãã¼ã®æ¥è¨ - SpamAssassinåãGoogle Safe Browsingãã©ã°ã¤ã³
ã¨ããããã§ãPukiWikiç¨ã®ã¹ãã ãã£ã«ã¿æ¸ãã®ã¯ãã£ã¡ãã§ããããã¾ã§å¾
ã¤ãã¨ã«ãã¾ããã