ã¯ããã«
ãã£ã¶ãã©ãããã ã¼ãã¾ãã§ãã
ãã®è¨äºã¯ã本番環境でやらかしちゃった人 Advent Calendar 2019 - Qiitaã®11æ¥ç®ã®è¨äºã§ãã
ããã¯ãä¸éå端ãªç¥èã§ãµã¼ãã¹ãéç¨ãã¦ããçµæãã¿ã¤ãã«éãã®å¤§å¤±æããã¦ãã¾ã£ãã話ã§ããå人éçºã§ã®åºæ¥äºãªã®ã§ãæ¥åã§èµ·ãããã¨ãã¨èè¬ãæ¡ããã¦ããæ¹ã¯ãå®å¿ãã ããã
èªãã®ããããæ¥ããããã¬ãã«ã§ãããæãã®ããã«æãã¦ããã¾ãã
ãã®è¨äºãèªãã§ã»ãã人
- åãã¦ã¤ã³ã¿ã¼ãããä¸ã«ãµã¼ãã¹ãå ¬éãããã¨ãã¦ãã人
- å太éã®å©ç¨è æ§(ãã®å ´ããåããã¦ãæ¹ãã¦ãè©«ã³ç³ãä¸ãã¾ããæ¬å½ã«ç³ã訳ãããã¾ããã§ããã)
èæ¯ã¨ã
- Discordèªã¿ä¸ãBot ãå太éãã«ã¦ããããã¾ãã
- å©ç¨è ãç´10ä¸äºº
- ãããã®VPSã«ã¦Appãµã¼ã2å°ãDBãµã¼ã1å°ã§éç¨
- åãµã¼ãã®æ»æ´»ç£è¦ã«mackerelãå©ç¨
- 被害ããã£ãã®ãDBãµã¼ã
- åºæ¬çã«ã ã¼ãã¾ã1人ã§éç¨
- å¾ææã¯æ空ã®æªã¿(大å¦3å¹´ç2å¨ç®)
åé¡çºç
- DBã®æ¥ç¶å¦çã«ä¸å
·åããããä¿®æ£ã®ããã«ãµã¼ãã¹ãåæ¢ãããæéããã£ã
- ãã®æãDBãµã¼ããAppãµã¼ãå ±ã«èµ·åããã¾ã¾
- ä¿®æ£ã®ããã®åæ¢æéã¯20æ¥ã»ã©
- ããã¯ããã§ãã©ã§ãããããããªã®ã§ã¯...?(åå ã¯ãµãã)
- 15æ¥ç®ãããã§mackerelããDBãµã¼ããè½ã¡ããç´ã£ããã¨ç¹°ãè¿ãã¢ã©ã¼ã
- ãããæ®éã«sshæ¥ç¶ã§ãã
- è²ã 試ããã¨ãããéä¿¡ãå¤ã¸åºãããªãããã ã£ã(pingã¨ãã¿ã¤ã ã¢ã¦ãã«ãªã)
- ãµã¼ãèªä½ã®åèµ·åã§ã¨ããããã¯æ²»ã£ã
- ãããã°ããããã¨åçºãã
- ã¡ã¼ã«ãããããã®ã§ãµã¼ããã·ã£ãããã¦ã³ãã
- ä¿®æ£ä½æ¥ãçµãããDBãµã¼ãã¨ã¢ããªã±ã¼ã·ã§ã³ãèµ·å
- ã¨ããããããã¼ãã«ãåå¨ããªããã¨ã¨ã©ã¼
- ã¯??????ã¨æã£ã¦DBãµã¼ãã«SSHãã¦psqlã³ãã³ãã§DBã«ãã°ã¤ã³
- åå¨ãã¦ãããã¼ãã«ãæ¶ãå»ã£ã¦ãa_a_warningãã¨ãããã¼ãã«ãä¸åã ã
- ãã¼ãã«ãè¦ããã«ãããã®DBã®ownerã§éããªã
- ã¯ã¦?ã¨æã£ã¦postgresã¦ã¼ã¶ã«åãæ¿ãã¦ãã¼ãã«ãè¦ã
- ã¬ã³ã¼ããä¸ä»¶ã ãå ¥ã£ã¦ãããããããã£ãã ãªæååãå ¥ã£ã¦ãã
Hello. You may be surprised to see this message, but it was your bad security practices that allowed us to steal your database. If you want to restore your data, and continue using it, send 0.075000 Bitcoin to [ããããBitCoinã®ã¦ã©ã¬ããã¢ãã¬ã¹] and go to the page using tor browser [è¬ã®URL]. In return, you will get the copy we have of your database. You can download the tor browser on the official website https://www.torproject.org/download/ | [ããããBitCoinã®ã¦ã©ã¬ããã¢ãã¬ã¹] | [è¬ã®URL]
(æ訳)(æªæãã·ãã·)
ããã£ãwwwwwé©ããï¼wwwwã¬ãã¬ãã»ãã¥ãªãã£ã®ãããã§wwwwãã¼ã¿çãããwwwwè¿ãã¦æ¬²ããã£ããwwwウェwwwããã«ãããã³ã¤ã³wwwwæ¯ãè¾¼ã¿ããwwwwwã
ãããã
ã¨ããããç¾å¨é²è¡å½¢ã§è¸ã¿å°ã«ããã¦ããå¯è½æ§ãããã®ã§ãå¿ è¦ã¨æããããã°ãè¨å®ãã¡ã¤ã«ãã¾ã¨ãã¦ã¡ã¤ã³PCã«ä¿å(ãããå®å ¨ãªã®ãã£ã¦ãã)ããã®å¾ãDBãµã¼ããã·ã£ãããã¦ã³ã èªåã ãã§ã¯ãã°ã®èªã¿æ¹ããã¾ãã¡ããããªãã£ãããã詳ããå人ããå 輩ã«èª¿æ»ã®ãé¡ããããã
æ¨åã¯ãªãããã£ã¦ãã¾ã£ãã®ã
ç´æ¥çãªåå
ã¾ããpostgresã®è¨å®ãã©ã®ããã«ãªã£ã¦ããã®ã
- 2ã¤ã®ãã¹ããæå®ãã¦ã¢ã¯ã»ã¹ã許å¯
- ã¤ã³ã¿ã¼ããããä»ãã¦æ¥ç¶
- Portã¯5432
- postgresã¦ã¼ã¶ã®ãã¹ã¯ã¼ãããpostgresã(èªè¨¼ã¯md5)
ä»æãã¨ç´ æµãªè¨å®ãã¦ã¾ãããçé¢ã®éµãéããªãã¿ã¤ããï¼
ããã§ã¯ãè¨å®ãã¡ã¤ã«(pg_hba.conf)ã®æ¥ç¶å¯è½ãã¹ãã確èªãã¦ã¿ããã(IPã¢ãã¬ã¹ã¯æ¶ç©ºã®ãã®)
# TYPE DATABASE USER ADDRESS METHOD [çç¥] host all all 184.14.25.76/0 md5 host all all 184.14.133.122/0 md5
ãµãããããã¹ã¯ã0ã«ãªã£ã¦ãããããã¯IPã¢ãã¬ã¹ã®ä»çµã¿ãããç解ãã¦ãããããªãã¨ãªãã°ã°ã£ã¦ãã®ãããªè¨å®ãè¦ã¤ããã®ã§çä¼¼ããçµæã(ãIPã¢ãã¬ã¹ ä¸ã¤ æå®ãã¿ãããªæ¤ç´¢ãããæ°ããã)
追è¨
ãµãããããã¹ã¯ã0ã§ãããã¨ã®ä½ãã¾ãããã
IPã¢ãã¬ã¹ãã©ã®ãããªå¤ã«ããã¨ããã§ã 0.0.0.0
ãã¤ã¾ããªä»»æã®IPã¢ãã¬ã¹ã¨ããæå³ã«ãªããä¸è¨ã®è¨å®ã®å ´åãæ¥ç¶ãã¹ããå¶éããã©ãããããããããã¹ãã®æ¥ç¶ã許å¯ãããã¨ã«ãªããèªå®
ãå
Œ
±æ½è¨ã«ãªã£ã¦ãã¾ã£ãã
ãã®è©±ãããããããªãã¨ãã人ã¯ããµã¼ãã¹ã®å
¬éãããåã«ãããã¯ã¼ã¯ãåå¼·ããããªãã ã¼ãã¾ãã®äºã®èã«ãªããã
ã¬ãã¬ãã®ã¬ãããã°ã¨ããã£ã¡ãæ»æããã足跡ãã£ãã
ã©ãããã®éãçªãã¦ãä»»æã®ã³ãã³ããå®è¡ãæªæã®ããã¹ã¯ãªããããã¦ã³ãã¼ãã»å®è¡ããããããããããã°ãã¡ã¤ã«ã«ãã¦ã³ãã¼ãã®çè·¡ã¨ãè¦è¦ãã®ãªããã¡ã¤ã«ã/var/lib/pgsql/11/data/
以ä¸ã«åå¨ãã¦ããã
mackerelããä¸èªç¶ãªã¢ã©ã¼ããèµ·ããã¨ãã«ãããã«å¯¾å¿ããã«æ¾ç½®ããã®ãBadãã¤ã³ãã
éæ¥çãªåå
ããããä¸è¨ã®äºé
ã¯å¤§å¦ã®è¬ç¾©ã§å±¥ä¿®ããå
容ã§ããã®ã§ãããã«é©å½ã«åä½ãã¨ã£ã¦ãããã伺ããçµæãããçå¹´ãããã
ãããã®VPSã¯ç¡æã§ãã¼ã«ã«ãããã¯ã¼ã¯ãçµããã¨ç¥ããªãã£ãã®ã§ããµã¼ãå士ã®éä¿¡ãã°ãã¼ãã«IPã¢ãã¬ã¹ãç¨ãã¦è¡ããã¦ããã
çé£ã«ãã£ããã¼ã¿
- ã¦ã¼ã¶ãã¼ã ã¨ã¦ã¼ã¶IDãèªã¿ä¸ãé³å£°è¨å®
- åã®ã«ã*1ã®ååã¨IDãBotã®å©ç¨ä¸ã®è¨å®
- ã¦ã¼ã¶è¾æ¸
- å©ç¨ç¶æ³ã®çµ±è¨
ã¡ã¼ã«ã¢ãã¬ã¹ãªã©ãç´æ¥çã«å人ã¨çµã³ã¤ããããªæ å ±ã¯ä¿åãã¦ããªã(ã§ããªã)ãããæµåºããªãã£ããã¦ã¼ã¶ãã¼ã ãã¦ã¼ã¶è¾æ¸ã«å人æ å ±ãæ¸ããã¦ããå ´åã¯ã©ããããããªã...ã
äºåº¦ã¨æ¨åãèµ·ãããªãããã«ã©ãããã®ã
è¡åãããã¨
- 被害ã«ãã£ããµã¼ãã¯ä¸åº¦çç ´ãã¦OSãåã¤ã³ã¹ãã¼ã«
- ãããã¯ã¼ã¯ã®æç§æ¸ãèªã¿ç´ãã
- æç§æ¸ä»¥å¤ã«ãã°ã°ã£ã¦ç´å¾ãããã¾ã§å¦ç¿ãã
- ãã¼ã«ã«ãããã¯ã¼ã¯ãæ§ç¯
- postgresãlistenãããã¼ãã¯ãã¼ã«ã«ãããã«åãã¦éæ¾
- DBã¸ã®ã¢ã¯ã»ã¹ã¯localhostãããã¼ã«ã«ãããã¯ã¼ã¯ã®æ©å¨ã«ã®ã¿è¨±å¯
- ãã¼ã«ã«ãããã¯ã¼ã¯ããã®æ¥ç¶å¯è½ã¦ã¼ã¶ã¯DBã®ownerã«éå®
- å人ã«ä¾é ¼ãããã¼ããã§ãã¯ãªã©ãã¨ããããåºæ¥ãããªæ»æã試ãã¦ããã
ãã®ä»åçäºé
- ãããã¹ãæ©é¢(è¦å¯ãIPAã¨ãJPCERT/CC)ã«ç¸è«ããã«ãµã¼ããçç ´ãããã¨
- ã¦ã¼ã¶ã¸ã®è¬ç½ªãè¡ã£ããã®ã®ãæ å ±ãã¾ã¨ã¾ãåã«å ¬è¡¨ãã¦ãã¾ã£ãã®ã§ãããã£ã¦æ··ä¹±ãæãã¦ãã¾ã£ã
æè¨
- ã¤ã³ã¿ã¼ãããã¯æªäººãè·æãã¦ãã
- ã»ãã¥ãªãã£ãã¬ãã¬ãã§ããµã¼ãã¹ã¯åã
- ãµã¼ãã¹ãåãããã¨ãã£ã¦ç©äºããã³ãã³é²ãã¦ã¯ãããªã
- ããããããªããã¨ã¯èª¿ã¹ã¦ããåãã
- å¨ãã®äººãé ¼ã
- ææ¥ã§å¾ãç¥èã¯å¤§äºã«ããã¹ã
ãããªãã°ãä¿¡ç¨ã失ãä¸ã«å人ããä¸çç ½ããããã¨ã«ãªãã¾ãã
ãµãããããã¹ã¯ãééããã ããªã®ã«ã»ã»ã»
— ãããã (@eakonnsamui) 2019å¹´11æ12æ¥
主æ¼:ã ã¼ãã¾ããæ¥å¹´æ¥ å ¬é
ã ã¼ãã¾ã/0ã¯ãªã
— ãããã (@eakonnsamui) 2019å¹´11æ14æ¥
è¿½è¨ 2019/12/11
æ©éãããã¤ãåå¿ãããã ããã®ã§è£è¶³ãããã¾ãã
ãµãããããã¹ã¯ã®ä¸åã¨ãããããã®ã ãããããç ´ãããªããã
ããã§ãããpostgresã¦ã¼ã¶ãããã©ã«ããã¹ã¯ã¼ãã®ã¾ã¾md5ã«ãªã£ã¦ã¾ãããæ¸ãã®å¿ãã¦ã¾ãã...(ä»ã¯å¤æ´ãã¦ã¾ã)
ãã¡ã¤ã¢ã¦ã©ã¼ã«ã¨ã使ã£ã¦ãªãã®ï¼
使ã£ã¦ã¾ãããã被害ã«ãã£ãæã¯sshç¨ã®ãã¼ã(ãã£ã¡ã¯å¤æ´ãã¦ãã)ã¨ã5432ãã¼ããã¤ã³ã¿ã¼ãããã«åãã¦éãã¦ã¾ããã
ãªãã§/0ãã ããªã®ãæ¸ããæ¹ãããããããªãããª
è¨äºä¸ã«è¿½è¨ãã¾ããã
åæãã¹ã¯ã¼ãã£ã¦ã©ã³ãã ãããªãã£ãã£ã
ãããããããèªåã§ãpostgresãã«ããã®ããããDBã®ownerã¯è¤éãªãã¤ã«ãã¦ãããå²ã¨ã¾ãã§å¤§é¦¬é¹¿æ¡ä»¶...?
å¦çã®ãã¡ã§å¹¸éã ã£ãã
ã»ãã¾ã§ããå°±è·ãã¦ãããããæ´è½ã«ãªããªããã¨ã«ãªã£ã¦ã¾ããã
*1:Discordã§ã¯1ã¤ã®ã³ãã¥ããã£ããµã¼ãã¨è¡¨è¨ããããæ··ä¹±ãé²ãããã«ããã§ã¯ã®ã«ãã¨è¡¨è¨