OpenIDã¨ãã£ãã·ã³ã°
wiki.openid.netã®OpenID Wiki / OpenID_Phishing_Brainstormããã
ãã£ãã·ã³ã°ã®æµã
- ã¦ã¼ã¶ã¼ã¯æªæã®ããRP(Consumer)ãµã¤ãã«è¡ãã¨OpenIDã£ã½ããã°ã¤ã³ãã©ã¼ã ããã
- ã¦ã¼ã¶ã¼ã¯ãã®ãã°ã¤ã³ãã©ã¼ã ã«èªåã®Identifier URLãå ¥å
- æªæã®ããRPã¯ã¦ã¼ã¶ã¼ã®OP(IdP)ã«è¯ãä¼¼ãFake OPã«ãªãã¤ã¬ã¯ãããã
- Fake OPã¯ã¦ã¼ã¶ã¼ã«ã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ããæ±ãã
- ã¦ã¼ã¶ã¼ã¯ãã¤ãã®OPã¨ã®éãã«æ°ã¥ãããã¹ã¯ã¼ãå ¥ãã¡ãã
- Fake OPã¯ã¦ã¼ã¶ã¼ã®ã¢ã«ã¦ã³ãæ å ±ãå ¥æåºæ¥ã
ãããåºæ¬çãªãã£ãã·ã³ã°ã®æµãã¨èª¬æããã¦ãã
OpenID Realm Spoofing
OpenIDã§è¨ãã¨ããã®realmã¯trust_rootã®äºã(ソースから読むOpenID (1) - Yet Another Hackadelicã§è§£èª¬ãã¦ã¾ãã)
ãã®spoofingã¯ã©ãããäºãã¨è¨ãã°ã
- æ¯è¼çä¿¡é ¼ããã¦ãããµã¤ã
- ãªã¼ãã³ãªãªãã¤ã¬ã¯ã¿ãæã£ã¦ããµã¤ã
ãOpenIDã®RP(Consumer)ã ã£ãå ´åã«æãç«ã¤ä»çµã¿ã ã¨æãã
ããããæ¡ä»¶ãæã¤ãµã¤ãã®ãã¡ã¤ã³ãtrusted.comã ã¨ãã¦ããªãã¤ã¬ã¯ã¿ã¯http://trusted.com/redirect?url=http://foo.com/ã¿ãããªæãã ã¨ããã¨ãæªæããRPã®ãã¡ã¤ã³ãmalicious.netã ã¨ãã¦ã
- trust_root
- http://trusted.com/
- return_to
- http://trusted.com/redirect?url=http://maricios.net/
ã®ããã«ãã¦èªè¨¼ãªã¯ã¨ã¹ããéã£ã¦ãããã¨ã
ããã¦ã¼ã¶ã¼ãOPã§ãã°ã¤ã³ããéã«ã許å¯ãä¸ãããã¡ã¤ã³ã¨ãã¦è¡¨ç¤ºããã¦ããã®ã¯trusted.comã«å¯¾ãã¦ã¨è¨ã風ã«è¡¨ç¾ããã¦ããã ãããããã¤ãã¤ã許å¯ãã¦ãã¾ãã¨è¨ãå ·åã
ãªãã¤ã¬ã¯ã¿ã«ã¯èªè¨¼çµæãä¼´ã£ããã¼ã¿ãéãããã®ã§ãå 容ã«ãã£ã¦ã¯é常ã«ã¾ãããã¼ã¿ãæªæããRPã«çã¾ããããªãçµæã«ãªãã
Attribute Exchangeãªããã使ã£ã¦ãå ´åã ã¨ãã©ããªå±æ§æ å ±ããªã¯ã¨ã¹ããã¦ããåãããªãããä»®ã«trusted.comã«ç¸å½ã»ã³ã·ãã£ããªå±æ§æ å ±ã®èªã¿åãã許å¯ãã¦ãããç¸å½ã¾ããã§ããã
対æçã£ã¦ä½ããããã ããã