åé¡
GNU / LinuxãœãããŠã§ã¢ã«ã¯ãä»ã®OSãœãããŠã§ã¢ãšåæ§ã«è匱æ§ãå«ãŸããŠãããããã«ã€ããŠäœãããããšã¯ãããŸããã å°ãåãç§ã¯ïŒç§ã¯é¢ä¿ãããŸãããèŠããŠããªãïŒä»»æã®ãã¬ãŒã€ãŒãã³ãŒããã¯ã©ã€ãã©ãªã§èŠã€ãã£ãè匱æ§ã«ã€ããŠã®ãã¥ãŒã¹ã«åºããããŸããã ãã®è匱æ§ã«ãããç¹å¥ã«çŽ°å·¥ããããã¡ã€ã«ãåŠçãããšãã«ä»»æã®ã³ãŒããå®è¡ãããå¯èœæ§ããããŸããã ãããããããŸã§ã®ãšãããFlashãäŸã«åãããšãã§ããŸãããããã¯éèŠã§ã¯ãããŸããã
ç¹å¥ãªãã¡ã€ã«ãéããšããã®äžã«ä»»æã®ã³ãŒããå®è¡ããããéåžžã«è匱ãªãã¬ãŒã€ãŒããããšããŸãã ãã®ãããªã³ãŒãã¯äœãã§ããŸããïŒ æš©å©ãåäžãããã«ãŒãã«å ïŒãŸãã¯ãã®ä»ã®éèŠãªéšåã§ïŒããããã®è匱æ§ãããå Žåã¯ãããããã¯ã圌ãå¯äžã®ããŒã ãã£ã¬ã¯ããªå ã®ã§ããã ããããæã䟡å€ãããã®ã¯ããŒã ãã£ã¬ã¯ããªã«ãããŸãïŒã¯ããããã¯ã¢ããã«ã€ããŠèŠããŠããŸãïŒã ã€ãŸã æå·ã®å¯èœæ§/貎éãªæ å ±ïŒãã¹ã¯ãŒããææžãªã©ïŒãããŒãžããããããããã®PCãŠãŒã¶ãŒã®åæ¢ãªå µå£«ãä»ããŠãŠãŒã¶ã®ãã¡ã€ã«ãåé€ããŸãã ã·ã¹ãã ã®æ®ãã®éšåãå°ç¡ãã«ããä»ã®ãŠãŒã¶ãŒãå·ã€ããæ·±å»ãªLinLockïŒç°¡åã«åé€ã§ããªãïŒãäœæããããšã¯å€±æããŸãã
ã³ãŒããã·ã¹ãã ã«æ®ãããšã¯ã§ããŸããïŒ / execãnoexecãªãã·ã§ã³ã§ããŠã³ãããŸãããæ»æè ã¯ã¹ã¯ãªããã䜿çšããæ©äŒããããŸãã æªæã®ããã³ãŒããã/ .config / long / path / hard / to / find / zlovred.pyãã¡ã€ã«ãäœæãããã®èªåå®è¡ã.profileãã¡ã€ã«ã«è¿œå ããã®ãæ¢ãããã®ã¯äœããããŸããã ãŸãããã«ãŠã§ã¢ãã/ .config / autostartãŸãã¯ä»ã®å Žæã«ç»é²ããããšãã§ããŸããå ŽæãèŠã€ããããšãã§ãããšæããŸãã
ã€ãŸã ããããšäžåºŠããŒã ãã£ã¬ã¯ããªã«ããã®ãããªUSBãã©ã€ããšããŠããŸãã«ãé »ç¹ã«ãå¯èœãªéãã®èµ·åãšããããšã«ç»é²ããããšãã§ããŸãã ãã©ãã·ã¥ãã©ã€ããšããã°ã ã¬ããè匱æ§ã¯ããã¬ã€ã€ãŒã§ããã€thumbnailer'omã®preveshekãããªãäœæããæ¹æ³ãä»ã®ãã®ã®éã§äœ¿çšãããŠããã©ã€ãã©ãªãã§ã¯ãããŸããã ãŠãŒã¶ãŒã¯ãããªãã¡ãUSBãã©ãã·ã¥ãã©ã€ããæ¿å ¥ããã·ã¹ãã äžã§...ããã¯nautilus'omããªãŠã ã¬ã€ã¯ãã¬ãã¥ãŒãäœæããããã«ããã«ããŒããã»ã¹ãèµ·åãããã¹ãŠã®ãã«ãŠã§ã¢ãéããŸã ã©ãã§ãã¯ãªãã¯ããå¿ èŠã¯ãããŸãããUSBãã©ãã·ã¥ãã©ã€ããæ¿å ¥ããŸãã-ãŠã€ã«ã¹ã«ææããŸããã
ç§ãäœããèŠéããããèæ ®ã«å ¥ããªãã£ãå Žåãã³ã¡ã³ãããé¡ãããŸãã äžèšã倱æããå ŽåããŠãŒã¶ãŒãFlashã®è匱æ§ãä»ããŠæµã®ãµã€ãã«ã¢ã¯ã»ã¹ããããšã§å¹žããªç掻ãå°ç¡ãã«ããã®ãé²ãã«ã¯ã©ãããã°ããã§ããïŒ
ã¯ããLinuxã¯åç©åã®ååžãšãŠã€ã«ã¹äœæè ã¯ãã¢ã«ãŠã³ãã«ããããã®ãã¥ã¢ã³ã¹ãåãå¿ èŠããããŸãããããªãããããå Žåã¯ããã®åŸã®ããšãã§ããŸãããããããã»ã©äžè¬çã§ã¯ãããŸããã Linuxã¯ããŸã人æ°ããããŸãããã人æ°ã«ãªããšã©ããªããŸããïŒ ããããããã®ææè ã¯ãLinuxã®å Žåããã«ãŠã§ã¢ãäœæããã®ãå°ãé£ãããšããäºå®ã®ããã«ããã®æ°ãå¢ããããšãæåŠããŸããïŒ ããã¯æããŸãã
ã©ããã
Linuxçšã®ã¢ã³ããŠã€ã«ã¹ïŒ ãŸããïŒ
ãã¹ãŠã®ããã°ã©ã ã¯æå°éã®ç¹æš©ã§å®è¡ããå¿ èŠããããŸãã ããã°ã©ã ãå®è¡ããŠãããŠãŒã¶ãŒã®ç¹æš©ã¯åé·ã§ãã ã¯ããããã¯ç§ã®ãã£ãšåã«ãã§ã«çºæãããŠããŸãããç§ã¯ãããã©ã®ããã«æ©èœãããã«ã€ããŠç§ã®èããè¡šçŸãããã ãã§ãã
ãã¬ãŒã€ãŒã«ã¯äœãå¿ èŠã§ããïŒã§ããŸããïŒïŒ 圌ã¯ãã¡ã€ã«ãèªã¿ãã/ .config / playerã«æžã蟌ã¿ãå¿ èŠã§ããã°URLãéãã ãã§ãã ä»ã®ãã¹ãŠã¯å¿ èŠã§ã¯ãªãããããnizyaaaaaïŒPoluninã®å£°ã§ïŒã ãã©ãã·ã¥ã¯ããã«å°ããããããã¯ãŒã¯ãšãäœããã®çš®é¡ã®ã/ .config / adobe / flashïŒãŸãã¯ããã¯ã©ãã«ãããŸããïŒïŒã§ãã ããããäžæãã¡ã€ã«çšãªã©ãããã«ããã€ãã®ãã£ã¬ã¯ããªãå¿ èŠã§ãããããã¯ãã¹ãŠæããã«å¶éãããŠããŸãã
ããã§ã¯ã©ãããŸããïŒ åŒ·å¶ã¢ã¯ã»ã¹å¶åŸ¡ããŒã«ã¯ãã§ã«ååšããŸã-SELinuxããã³AppArmorã ç§ã®ããã«ãããããå€æŽããŠã害ã¯ãããŸããã ããšãã°ãAppArmorïŒç§ã¯è¡šé¢çã«ã¯SELinuxã«ç²ŸéããŠããŸã...ãã¶ããã¹ãŠãããã«ããã®ã§ããããïŒïŒãããã«æš©å©ãããªãã³ã°ããå¿ èŠãããã¢ããªã±ãŒã·ã§ã³ããšã«ãç¹å¥ãªæ§æãèšè¿°ããŠ/etc/apparmor.d/ã«é 眮ããå¿ èŠããããŸãã ãã®ã¢ãããŒãã¯ååã«æè»ã§ã¯ãªãããã«æããŸãïŒç§ãç¥ãéããSELinuxãæè»ã§ã¯ãããŸããïŒã ã¹ãŒããŒãŠãŒã¶ãŒã®æš©éãªãã«ããã®ãããªãããã¡ã€ã«ããã®å Žã§äœæããååãªæ©äŒã¯ãããŸããã ããªãã¡ïŒ
- ã¢ããªã±ãŒã·ã§ã³èªäœããã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãããã¡ã€ã«ãäœæããããã®ã€ã³ã¿ãŒãã§ã€ã¹
- æå®ããããããã¡ã€ã«ã§ã¢ããªã±ãŒã·ã§ã³ãèµ·åããããã®ã€ã³ã¿ãŒãã§ãŒã¹
- ãã®å Žã§ä»ã®ã¢ããªã±ãŒã·ã§ã³ã®ãããã¡ã€ã«ãç·šéããããã®ç¹æš©ãã¢ããªã±ãŒã·ã§ã³ã«å²ãåœãŠãæ©èœã æ¢ã«é©çšãããŠãããããã¡ã€ã«ãå€æŽãã
- ãããã¡ã€ã«ãã³ãã¬ãŒããå®è¡å¯èœãã¡ã€ã«ã®åœ¢åŒã®å€æŽãããã±ãŒãžã®å€æŽãå¯èœ
ããšãã°ãåããªãŒããŒãã¬ãŒã€ãŒãèµ·åããŸãã ãŸããç¹å¥ãªAPIãä»ãããã¬ãŒã€ãŒããã»ã¹ã¯ãèªèº«ã«å¶éçãªãããã¡ã€ã«ãé©çšããŸãã ã€ãŸã ãã¬ãŒã€ãŒã®éçºè ãæ瀺çã«å¿ èŠãªã¢ããªã±ãŒã·ã§ã³ã®æš©éã®ãªã¹ãã«é©åãªã³ãŒããè¿œå ããå¿ èŠããããŸãã ããã¹ãŠã®ãã¡ã€ã«ãèªãããšãã§ããŸããããªãã¯ãã®èšå®ã«æžã蟌ãããšãã§ãããããäœãããããšã¯ã§ããŸããããã®ãããªãã® ã€ãŸã ãã®æ¹æ³ã¯ãã¢ããªã±ãŒã·ã§ã³ã«ãã°ãå«ãŸããŠããå¯èœæ§ããããããã°ã©ã ã®åäœããã·ã¹ãã ãå¶éãããããšãç¥ã£ãŠããéçºè åãã§ãã ãŸãã¯ãé©åãªã³ãŒããé åžã®äžéšãšããŠè¿œå ã§ããŸãã ã¯ããã³ãŒããç·šéããå¿ èŠããããŸãããå€ãã®ç·šéã¯ãããŸããã ïŒAppArmorã®äžã®ããã«ïŒãã®ããã«ãã»ãã«ããã®æ©æ§ã¯ãåäžã®ã¢ããªã±ãŒã·ã§ã³ãããã¡ã€ã«ãããªãã¡ãèš±å¯ããå¿ èŠããããæš©å©ãåæžããããšã¯å¯èœã§ãã£ãŠãããããå¢å ããŸãã ã¢ããªã±ãŒã·ã§ã³ããããã³ã°ãããå Žåãäœãå€æŽã§ããŸããã ãã®ãããªå®å šæ§ãããã¡ã€ã«ã¯ããããªãäœæ¥ãäžèŠã«ãªã£ããã¹ãŠã®ãã¡ã€ã«ãèªã¿åºã/æžã蟌ã¿ã§ããã¢ããªã±ãŒã·ã§ã³ã䜿çšããããã«ãäŸãã°ãå§åçŽåŸããã«é©çšããŸãã¯ããããšãã§ããŸãã
ãããã¡ã€ã«ããã€é©çšãããã¯ãéçºè ã決å®ããŸãã
ããªãã¯ãåé¡ãšã¯ããŒãºããœãŒã¹ã®ã¢ããªã±ãŒã·ã§ã³ã§ãããšãã°ããããã¡ã€ã«ãé©çšããããšãã§ããŸãã®ã§ãå¿ ããããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ã ããã«ãèµ·åã®ã³ã³ããã¹ãã«å¿ããŠãç°ãªããããã¡ã€ã«ãé©çšããå¿ èŠãããå Žåã«ç¶æ³ãçºçããå ŽåããããŸãã ãã®ããã«ãã¡ã«ããºã çªå·2ãå¿ èŠã§ãã ããã䜿çšãããšãã¢ããªã±ãŒã·ã§ã³ã¯ãããã¡ã€ã«ã䜿çšããŠå¥ã®ã¢ããªã±ãŒã·ã§ã³ãèµ·åã§ããŸãã ç§ã®æèŠã§ã¯ãæãé©åãªäŸã¯ãã©ãŠã¶ãšãã©ã°ã€ã³ã§ãã FlashãJavaã¢ãã¬ãããSilverlightãããã³ãã®ä»ã®ãã©ã°ã€ã³ã¯ãèµ·åæã«æš©éãå¶éããã»ãã¥ãªãã£ãããã¡ã€ã«ãååŸããŸãã Flashã«3åã®ç©Žã空ãããã¡ã€ã«ã·ã¹ãã ã«ã¢ã¯ã»ã¹ããããã®ActionScript APIãæãããŠãã ãããäœãã§ããŸããã
ãã¹ãŠãããŸãããããã§ããã€ãŸã ã»ãšãã©ã®ã¢ããªã±ãŒã·ã§ã³ã¯ãã®æ¹æ³ã§å¶éã§ããŸãã ããããããã€ãã®åé¡ããããããããŸããã æœåšçã«ãã¡ã€ã«ã®èªã¿åã/æžã蟌ã¿ãå¿ èŠãªã¢ããªã±ãŒã·ã§ã³ã®åŠçã
ãã©ãŠã¶ã«ã¯ãããŠã³ããŒããããã¡ã€ã«ãä¿åããæ©èœãå¿ èŠã§ãã ããªãã¯å¥ã®ãã£ã¬ã¯ããªã/ããŠã³ããŒãã«ãããå¶éããããšãã§ããŸãããããã¯å®å šã®å©äŸ¿æ§ãç ç²ã«ãªããŸãã äžéšã®ãšãã£ã¿ãŒã«ã¯ãååãšããŠãä»»æã®ãã¡ã€ã«ã®èªã¿åãããã³æžã蟌ã¿æ©èœãå¿ èŠã§ãã ãã®å Žåãã¢ã€ãã çªå·3ã圹ç«ã¡ãŸãã ãã¡ã€ã«ãéããŠä¿åããããã®ãã€ã¢ãã°ã¯ãå¥ã®ããã»ã¹ã«ç§»åããå¿ èŠããããŸããããšãã°ã/ etc / apparmor / trusted_programsã§ã¯ã/ usr / bin / gtk-open-dialogããã³/ usr / bin / gtk-save-dialogãããªã³ã¶ãã©ã€ãã§å€æŽã§ããããšãèšè¿°ããŸã»ãã§ã«å®è¡äžã®ä»ã®ã¢ããªã±ãŒã·ã§ã³ã®ãããã¡ã€ã«ïŒããšãã°ã/ proc / [pid] / aa_profileçµç±ïŒã åœç¶ãç¹å¥ãªããã°ã©ã èªäœãèµ·åãããåããŠãŒã¶ãŒã®ã¢ããªã±ãŒã·ã§ã³ãããã¡ã€ã«ã®ã¿ãç·šéã§ããŸãïŒãã€ã¢ãã°ãéãããä¿åãããããïŒã
ãã©ãŠã¶ãèµ·åãããããã¡ã€ã«ãé©çšããããã¹ãŠãå¶éãããŸãã ããŠã³ããŒããããã¡ã€ã«ãä¿åããå¿ èŠãããå Žåããã©ãŠã¶ã¯gtk-save-dialogãèµ·åããŸãïŒåœç¶ãkdeã«ã¯ç¬èªã®ã®ãºã¢ãå¿ èŠã§ãïŒã ãŠãŒã¶ãŒã¯ãä¿åãããã¡ã€ã«åãæ瀺çã«éžæããŸãã Gtk-save-dialogã¯ããã©ãŠã¶ããã»ã¹ã®ãããã¡ã€ã«ã«å¯Ÿå¿ããäŸå€ãäœæãããã¡ã€ã«åããã©ãŠã¶ã«è¿ããŸãã ãããã£ãŠãã¢ããªã±ãŒã·ã§ã³ã¯ããŠãŒã¶ãŒãæ瀺çã«èš±å¯ãããã¡ã€ã«ã®ã¿ãèªã¿æžãã§ããŸãã ã¢ããªã±ãŒã·ã§ã³ã¯ãïŒãã ãããã¡ã€ã«ã®ãªã¹ããååŸããããšã¯ååã«å®å šã§ãããç§ã¯æãïŒãã¡ã€ã«ã®ãªã¹ããååŸããããšãã§ããªãã£ããšãããã£ã¬ã¯ããªãã®ãã®ãçŠæ¢ããããã«èªãããšãã§ããŸãã ãªãã£ã¹ããã°ã©ã ïŒããã³ä»ã®å€ãïŒã§ãåãããšãã§ããŸãã ãã¹ãŠã®ãã¯ãããã®ä»ã®å®å šã§ãªããã®ãã¯ãŒãããã»ããµã§èš±å¯ãããŠããå Žåããããããªãã£ã¹ã®ããã¥ã¡ã³ãèªäœãšããã®æç¹ã§æ¢ã«éããŠããããã¥ã¡ã³ãã®ã¿ãé€ããŠãäœãå°ç¡ãã«ããããšã¯ã§ããŸããã ãŠãŒã¶ãŒã«ãšã£ãŠã¯ããã¹ãŠãåããŸãŸã§ãåãããã°ã©ã ãåããã€ã¢ãã°ãæ°ãããã®ã¯äœããªããäžäŸ¿ã¯ãããŸããã ããã°ã©ãã®ããã«ãããŸãã«ããå€æŽãå ããããšãªãããã¹ãŠåãã³ãŒã«ãã€ã¢ãã°ããã¯ã¹ã®æ©èœè¡šç€ºãè¡ãããšãã§ããŸãã ãŠã£ãžã§ããã©ã€ãã©ãªïŒGtkãQtãªã©ïŒãä¿®æ£ããå¿ èŠãããã ãã§ãã
4çªç®ã®ãã€ã³ããæ®ã£ãã ãªãå¿ èŠãªã®ã§ããïŒ æªæ€èšŒã®ãœãŒã¹ããã¢ããªã±ãŒã·ã§ã³ãå®å šã«èµ·åããããã«å¿ èŠã§ãã ä»ã§
ãªããããæžããã®ã§ããïŒ
ç§ã¯èªåã®èããè¡šæããã°ããã§ãGNU / Linuxã®ã»ãã¥ãªãã£ã®ãããã¯ã«ã€ããŠè°è«ããããšã«èå³ããããŸãã ãã¡ãããç§ã¯æ ¹æ¬çã«æ°ããäœãã説æããŠããŸããã§ããããããã§èª¬æããããã€ãã®ã¢ã€ãã¢ã¯ãç§ã¯äŒã£ãããšããªãïŒäŸãã°ã察話ã®ãªãŒãã³ã®åé¡ãä»ã®ããã»ã¹ã§ä¿åïŒãå€åããã¯æ¬åœã«äŸ¿å©ãªã¢ã€ãã¢ã§ãã ã«ãŒãã«ã®ããããæ¥ãã§äœæããªãã£ãã®ã«ãHabréã«ã€ããŠã®ãããã¯ãæžããã®ã¯ãªãã§ããïŒ æ®å¿µãªãããCã«ã€ããŠã®ç§ã®ç¥èãããã«ã¯ã³ã¢ã«ã€ããŠã®ç¥èã«ã¯ãå€ãã®èŠæãæ®ãããŠããŸãã ããã«ãæ瀺ãããã¢ã€ãã¢ãè°è«ããUbuntu Brainstormã§ããã«ã€ããŠæžãããšãèããããŸãïŒãã®ãããã¯ã«ã€ããŠã¯2ã3ã®è¡ãæžããŸããããè±èªããŸããŸããããããšã誰ãå¿ èŠãããŸããããªã³ã¯ãèŠã€ããŸã-ããã«è¿œå ããŠãã ããïŒãŸãã¯åæ§ã®ãªãœãŒã¹ã
PSãã®ãããã¯ãæžãã®ã«é©ããããã°ãéžãã ãã©ããã¯ããããŸããã 圌ãããã«å±ããŠããªãå Žåã¯ãç§ãè² æ ããŸãã
[æŽæ°1]
å°ããªè¿œå 1ïŒ
ç§ã¯ããã§èª¬æããã©ã®ãã㪠- æ¢åã®AppArmorãè£è¶³ããŸãã ã¢ããªã±ãŒã·ã§ã³èªäœãããããã¡ã€ã«ãäœæããããã®APIã¯ãçŸåšããã¹ããã¡ã€ã«ã«ååšããAppArmorãããã¡ã€ã«ã«ä»£ãããã®ã§ã¯ãªããè¿œå ããããã®ã§ãã
ããã€ãã®å Žåã«åœ¹ç«ã€ãšæãããŸãïŒ
- 1ã€ã®çšéã¯ãçšéã«å¿ããŠç°ãªããããã¡ã€ã«ã§ã®äœæ¥ãããªãã¡ãæŽã£ãŠãŸã ããŸããŸãªæ¹æ³ã§èªåã®æš©å©ãåæžããŸãã
- éå§çŽåŸã«ã¯ã§ããŸããèé¢å³åŽã«ã«ããããå°ãåŸã
ããšãã°ã倧ããªæš©å©ãå¿ èŠãšããã³ãŒãã®å®å šã«ãã¹ãããããªããããã»ã¯ã·ã§ã³ãäœæããå Žåãã¢ããªã±ãŒã·ã§ã³ã¯æš©å©ãå¿ èŠãšããããããã¯ã«ãããããŸãã
ã€ãŸã ããã¯ãæè»æ§ãè¿œå ããã¢ããªã³ã§ããã代æ¿ã§ã¯ãããŸããã
å°ããªè¿œå 2ïŒ
æš©å©ã¯ãã€ã§ãæžããããšãã§ããŸãã ãã©ã°ã©ã3ã§ã®ã¿ãçŠæ¢äºé ãèš±å¯ã§ããŸãã
ç¹æš©ããã°ã©ã ãšæ¢ã«å®è¡äžã®å¥ã®ããã»ã¹ã®ã¿ãèš±å¯ã§ããŸãã
äžèšã«ã€ããŠè©³ãã説æããŸãã®ã§ãããäžåºŠãèªã¿ãã ããã
å°ããªè¿œå 3ïŒ
å€å žçãªAppArmorã®å Žåã®ããã«ããã®æš©å©ã·ã¹ãã ã¯å€å žçãªæš©å©ã·ã¹ãã ãããåªå 床ãäœããªããŸãã ã€ãŸã ãŠãŒã¶ãŒèªèº«ã«ãšã£ãŠäœããäžå¯èœãªå Žåããããã¡ã€ã«ã«é¢ä¿ãªãããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ã§ããã¯äžå¯èœã§ãã
[æŽæ°2]
Mac OS Xãåæ§ã®ãã®ãéçºããŠããããšãããããŸããã
techjournal.318.com/security/a-brief-introduction-to-mac-os-x-sandbox-technology
developer.apple.com/library/ios/#DOCUMENTATION/Security/Conceptual/Security_Overview/Security_Services/Security_Services.html
ãªã³ã¯ã®int80hã«æè¬ããŸãã
ãšããã§ãç§ã®èšäºã§èª¬æãããŠããããã«ããŸããå¿ èŠãªãããšããã³ã¡ã³ãã§è¿°ã¹ãããŠããããã«ãç¹å¥ãªAPIãä»ããŠã¢ããªã±ãŒã·ã§ã³èªäœããã®æš©å©ãå¶éããæ©äŒããããŸãã
èå³æ·±ãããšã«ãWindowsã«ã¯ãã§ã«äŒŒããããªãã®ããããŸããïŒ