ãŸããã
芪æãªãhabravchanãžã®æšæ¶ã
Habrahabrã§ã¯ãäžæ£ã¢ã¯ã»ã¹ïŒNSDïŒããã®æ å ±ã»ãã¥ãªãã£ããŒã«ïŒISSïŒã«é¢ããèšåã¯ãæ€çŽ¢ã«ãããšããªããŸãã§ãã ããšãã°ã ãã©ã¹ã®èŠè«ã§ã 26件ã®ãããã¯ãš2件ã®è³ªåãåãåããŸãããããã®ãã¡ããµã³ã¯ãããã«ãã«ã¯ã®äŒç€ŸCONFIDENT LLCã® NSDãã©ã¹ããã¯ããSZIãç¹ã«èšåãããããã¯ã¯1ã€ã ãã§ããã ä»ã®æ¹æ³ã§ã¯ãç»åã¯äŒŒãŠããŸãã ãã®æçš¿ã§ã¯ããã®ãããªããŒã«ã䜿çšããçµéšãšãããŒã«ã䜿çšããéã®æãäžè¬çãªééã/誀解ãå ±æããããšæããŸãã
ã³ã¢ããŒã«
åœç€Ÿã§ã¯ãã客æ§ã«ãœãããŠã§ã¢ããã³ããŒããŠã§ã¢æ å ±ä¿è·ã®3ã€ã®ãªãã·ã§ã³ãæäŸãããŠããŸãã
- ã»ãã¥ãªãã£ã³ãŒãããã®ã·ãŒã¯ã¬ããããã
- NPCãã¢ãžã¥ãŒã«ãããNTãä¿è·
- åè¿°ã®ãã©ã¹ããã¯
ãã¹ãŠã®è£œåã®ç¹æ§ã¯ã»ãŒåãã§ãïŒç¹ã«ãã©ã¹ããã¯ã®ããŒãžã§ã³7.7ã§ã®USBããã€ã¹ã®å¶åŸ¡ã®åºçŸã«ããïŒãç¹å®ã®ããŒã«ã䜿çšãããšããåé¡ã¯ãã¿ãŒã²ããã·ã¹ãã ãžã®ã€ã³ã¹ããŒã«ã®å¯èœæ§ã«åºã¥ããŠããŸãã¯ãµãã©ã€ã€ãŒãšã®é¢ä¿ã®ã¬ãã«ã«åºã¥ããŠè§£æ±ºãããŸãã
ã€ã³ã¹ããŒã«ããèœåã«ãããSPIã®ã¢ãŒããã¯ãã£ãšããŒããŠã§ã¢ã®å¯çšæ§ã®èŠä»¶ã®éããç解ããŠããŸãã ããšãã°ããã©ã¹ããã¯ïŒãŸãã¯NT SentinelïŒã¯ãããŒã段éã§ã³ã³ãã¥ãŒã¿ãŒå¶åŸ¡ãã€ã³ã¿ãŒã»ãããããŠãŒã¶ãŒããã¹ã¯ãŒããå ¥åããŠèå¥åãæ瀺ãããŸã§ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãèµ·åããªãããã«ããŸãã ãã®ã¡ã«ããºã ã®å®è£ ã®éãã¯ãNT Sentinelããã®ããã«PCIæ¡åŒµã«ãŒãã䜿çšããããšã§ããããã¯PCå ã«ã€ã³ã¹ããŒã«ããå¿ èŠããããŸãïŒããã¯æ°ããããŒãžã§ã³ã§ã¯å¿ èŠãããŸãããããŒãžã§ã³2.5ã«ãèšèŒãããŠ
ãµãã©ã€ã€ãŒãšã®é¢ä¿ã®ã¬ãã«ã§ã¯ããå販ã®å¯èœãªå²åããèªãå¿ èŠããããŸãã æè¿ããæè¡ãµããŒãã®è³ªãããæäœã®ãããããã®ç¹ã§åœå±ã説åŸããããšãå¯èœã«ãªããŸããã
ç³èŸŒã¿
ã»ãšãã©ãã¹ãŠã®æ³šæã«ã¯ãããŒã«ã«ã¯ãŒã¯ã¹ããŒã·ã§ã³ïŒAWSïŒã®èªèšŒãå¿ èŠã§ãã ãããã£ãŠãã»ãã¥ãªãã£ãœãããŠã§ã¢ã®ãªã³ã©ã€ã³ããŒãžã§ã³
ãããã¯ãŒã¯ããŒãžã§ã³ïŒãããããSecret NetãšDallas Lockã®ã¿ãæ€èšïŒã§ã¯ãç¶æ³ã¯éã§ãã ãããŠãããã»ã©åçŽã§ã¯ãããŸããã äžæ¹ã§ãSecret Netã®èšå®ã®å©äŸ¿æ§ã¯å€±ãããŠããŸããã ã¯ããActiveDirectoryã«åã蟌ã¿ãOSã®ã¡ã«ããºã ã䜿çšããŠäœæ¥ããã®ã¯éåžžã«ç°¡åã§ç解ãããããã®ã§ãã äžæ¹ããããã¯ãŒã¯ããŒãžã§ã³ã®ãã¹ãŠã®æ©èœïŒå ·äœçã«ã¯ãSecret Netã®çšèªã«ãããšã»ãã¥ãªãã£ãµãŒããŒïŒã¯ãªã¢ãŒããã°åéã§æ§æããããã©ã¹ããã¯ã»ãã¥ãªãã£ç®¡çè ã¯ãŒã¯ã¹ããŒã·ã§ã³ã§ã¯ãæ¥ç¶ãããŠããåã¯ã©ã€ã¢ã³ãã®ãã¹ãŠã®ã»ãã¥ãªãã£èšå®ããªã¢ãŒãæäœã§ããŸãã å€ãã®å Žåãããã¯SZIã®éžæã«ããã決å®çãªèŠå ã§ãã ãã€ãŠãæŽæ°ãããäžåç£ãèŠããšãã顧客ã®ç®¡çè ããå€ãã®é©ããšå€±æãèããªããã°ãªããŸããã§ããã æ®å¿µãªããã顧客ã¯Informzashchitaã«çžãããŠãããConfident補åãè³Œå ¥ããããšã¯äžå¯èœã§ããã
åé¡
å€ãã®ãšã©ãŒã¯ãåã«ç¹å®ã®SISã®åäœåçã®äžæ³šæãŸãã¯èª€è§£ã«ããçºçããŸãã 蚌ææž/ã¬ã€ã
å§ããŸãããã
ã·ãŒã¯ã¬ããããã
ãæ°ã«å ¥ã-圌ã¯ã©ãã§ããæ°ã«å ¥ãã§ã
ã€ã³ã¹ããŒã«ãããSZIã®ã»ãŒåºæ¬çãªããããã£ãç¡èŠãããããå€ãã®åé¡ãçºçããŸãããã¹ãŠã®ãã©ã«ããŒã¯åžžã«ãã¡ã€ã«ã·ã¹ãã ã§åé¡ãããã çŸåšã®ã»ãã·ã§ã³æ©å¯ã¬ãã«ã®ãã¡ã€ã«ã¯ãããã¢ãããŠã£ã³ããŠã§ç¢ºèªã§ããŸãã
å€ãã®å Žåããªãã£ã¹ã¹ã€ãŒãïŒWordãExcelïŒã®åäœäžèœã®åé¡ããããŸãã ãšããã§ãSZIã¯OpenOffice.orgã§åäœããªãããšãå¿ããªãã§ãã ããã ãšã©ãŒã¯å€§ããç°ãªãå¯èœæ§ããããŸãããçç±ã¯èª°ã§ãåãã§ããå ¬åŒã®æäœã«å¿ èŠãªãã©ã«ããŒã¯ã匷å¶ã¢ã¯ã»ã¹å¶åŸ¡çšã«æ£ããæ§æãããŠããŸããã ãã©ã«ãã®å®å šãªãªã¹ãã¯ããã¥ã¡ã³ãã«èšèŒãããŠãããç¹å®ã®åé¡ã¯ãã€ã§ãSecret Netãã°ã§èšºæã§ããŸããããã°ã©ã ã¢ã¯ã·ã§ã³ã«é¢ããæ å ±ã¯ãã°ã«è¡šç€ºãããŸãã Secret Netã§ã¯ããã©ã«ããŒã®çœ²åã¹ã¿ã³ã以äžã®çœ²åã¹ã¿ã³ããæã€ãã¡ã€ã«ããã©ã«ããŒã«ä¿åã§ããããããã¡ã€ã«ããã³ãã©ã«ããŒã«è³æ Œæ å ±ããŒã¯ãå²ãåœãŠããšãã¯ããã©ã«ããŒã®çœ²åã¹ã¿ã³ããç¹å®ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã§èš±å®¹ãããæ倧å€ã§ããããšãèŠããŠããå¿ èŠããããŸãã ãããã£ãŠãMicrosoft Wordãã·ãŒã¯ã¬ããã»ãã·ã§ã³ã§å®è¡ãããŠããå Žåãèªåä¿åãã¡ã€ã«ãæžã蟌ãã«ã¯ãç¹å®ã®ãã©ã«ããŒã«ãã·ãŒã¯ã¬ããã眲åãå¿ èŠã§ãã
ãœãããŠã§ã¢ããéå ¬éã以å€ã®ã¢ãŒãã§ã€ã³ã¹ããŒã«ãããå ŽåããããŸãã ãã¡ããããã¹ãŠãæ©èœããããã«ããã°ã€ã³ããŠéã·ãŒã¯ã¬ããã»ãã·ã§ã³ãéžæãã䟡å€ããããŸãã
ã¯ãŒã¯ã¹ããŒã·ã§ã³ã§USBãã©ãã·ã¥ãã©ã€ãã䜿çšããããšãèš±å¯ãããŠããå Žåããã©ã«ããŒã«ãœãŒãããã倧éã®ããŒã¿ãã³ããŒã§ããªãå ŽåããããŸãã ããã§ã¯ãã¹ãŠåãã§ã-æ°ããäœæããããã©ã«ããŒã¯æªåé¡ã«ãªãããã¡ã€ã«ã¯èªåçã«çŸåšã®çœ²åã¹ã¿ã³ããåãåããŸãã ãã©ãã·ã¥ãã©ã€ãã®äœ¿çšãçŠæ¢ãããŠããå Žåããã®ãããªPCãæ¥ç¶ããããšãããšãããã¯ãããŸãããããŒããã«èšå®ããã2ã€ã®éžæããããã©ã¡ãŒã¿ãŒããããæ åœããŸãã
ãŠãŒã¶ãŒãã³ã³ãã¥ãŒã¿ãŒã®åäœãé ãããšã«ã€ããŠçµ¶ããèŠæ ãèšããçµç¹ãKasperskyã¢ã³ããŠã€ã«ã¹ã䜿çšããŠããå ŽåãããŒãžã§ã³ã確èªããå¿ èŠããããŸããããŒãžã§ã³6.0.3ã¯SecretNet 5.xãšäºææ§ããªãããšããããããŸãã ãããã£ãŠããã¬ãŒãã¯ç¢ºå®ã«æ¶ããŸãã
æåŸã«ãã¬ãžã¹ããªãã©ã³ãHKLM \ System \ CurrentControlSet \ Services \ SNMC5xx \ Params ïŒ5.xããŒãžã§ã³ã®å ŽåïŒãèŠããšãMessageBoxSuppressionïŒããã³2ã€ç®ã¯ByDirïŒã§ããããªãœãŒã¹ã®ãã©ã€ãã·ãŒã«ããŽãªãå¢ããããšã«é¢ãããã€ã¢ãã°ããã¯ã¹ã衚瀺ãããªããã¡ã€ã«æ¡åŒµåãŸãã¯ãã©ã«ãã瀺ãããŸãã
ã»ã³ããã«NT
ãããè¡ãããã«ãåé¡ã¯ïŒå°ãªããšãã客æ§ã®éã§ã¯ïŒããŸãäžè¬çã§ã¯ãªãããã䜿ããããä¿è·ã¡ã«ããºã ã瀺ããŠããå¯èœæ§ããããŸãã
ãã®ãœãããŠã§ã¢ã®å Žåã®èª€è§£ã¯ãåã¢ããªã±ãŒã·ã§ã³ã®æ©å¯ã¬ãã«ãåå¥ã«éžæããå¿ èŠããããæšæºã³ã³ãã¯ã¿ãŒã«æš©å©ãå§ä»»ã§ããªãããšã«ãããã®ã§ãã ãããã£ãŠãAWPãUSBãã©ãã·ã¥ãã©ã€ããç»é²ããŠããŠãããããç§å¯ã§ããå Žåããšã¯ã¹ãããŒã©ãŒã§ããããéãããšãããšãã¢ã¯ã»ã¹ãšã©ãŒãçºçããŸãã èµ·åæã«ãã©ãã·ã¥ãã©ã€ãã®ã»ãã¥ãªãã£ã«å¯Ÿå¿ãããã¬ã©ã³ã¹ã¹ã¿ã³ããéžæããŠãã€ã³ã¹ããŒã«ãããŠãããã¡ã€ã«ãããŒãžã£ãŒãéžæããå¿ èŠããããŸãã
ãŸããWord / Excelããã¥ã¡ã³ããéããšããã©ã€ãã·ãŒã©ãã«ãéžæããããã®ãŠã£ã³ããŠãæåã«è¡šç€ºããããã®åŸã察å¿ãããšãã£ã¿ãŒã®ãŠã£ã³ããŠãèŠæ±ãããããã¥ã¡ã³ããªãã§å±éãããŸã-ããã¯æ£åžžã§ãã Officeã¢ããªã±ãŒã·ã§ã³èªäœã䜿çšããŠãã¡ã€ã«ãå床éãå¿ èŠããããŸãã
ãã©ã¹ããã¯
Sentinelã®å Žåãšåæ§ã«ããšã©ãŒã¯ã»ãšãã©ãããŸãã-ãã¹ã¯ãŒããé©åããªãã£ããããã©ã€ãã·ãŒã«ããŽãªããã©ã¡ãŒã¿ãŒããã°ã€ã³ãŠã£ã³ããŠããæ¶ããé»åèå¥åããã€ã³ããããšã©ãŒãçºçããŸããã
æåã®ãšã©ãŒã¯ã2ã€ã®ãã¹ã¯ãŒãã®äœ¿çšã«é¢é£ããŠããŸã-ãã©ã¹ããã¯ãšWindowsã§ã¯ãå¶ç¶ïŒããšãã°ã管çè ããã¹ã¯ãŒããå€æŽãããªã©ïŒãå«ããŠãç°ãªããã¹ã¯ãŒããèšå®ã§ããŸãã ãã®å ŽåãWindowsãããããŠã£ã³ããŠãããŒãããåŸããã©ã¹ããã¯ãã¹ã¯ãŒããå ¥åãããã€ã¢ãã°ã§SZIãšOSãã¹ã¯ãŒããäžèŽããªãããšã瀺ããOKããã¯ãªãã¯ããWindowsãŠãŒã¶ãŒãã¹ã¯ãŒããå ¥åããŠããã©ã¹ããã¯ã§äœ¿çšããã§ãã¯ããã¯ã¹ããªã³ã«ããŸãã
2çªç®ã¯ãã»ãã·ã§ã³ããã¯ã®ããã©ã«ãã®é ã眲åããã¯ã¹ã«é¢é£ä»ããããŠããŸãã ãŠãŒã¶ãŒããã®ããšãå¿ããŠããŸãããããããŒãã®çœ²åã¹ã¿ã³ããä»ãããã©ã«ããŒã«å ¥ããããšããã§ããªããšäžå¹³ãèšãããšããããŸãã
ãã®æäœã管çè ã«å¯ŸããŠè¡ãããå ŽåããŸãã¯äœ¿çšãããããŒã¯ã³ãããŒãžã§ã³ã«é©ããŠããªãå Žåãé»åèå¥åã¯çµã³ä»ããããªãå ŽåããããŸãã ãããã£ãŠãããŒãžã§ã³7.5ã§ã¯ãeToken RTEãã©ã€ããŒãåããeToken 64kãé©çšå¯èœã§ãã ããšãã°ãeToken 72k Javaãšåæ§ã«ãé·å¹Žã®eToken PKIã¯æ©èœããŸããã
ããšãã
ãã®æçš¿ãã³ãã¥ããã£ã«åœ¹ç«ã€ããåãªãåèã«ãªãããšãé¡ã£ãŠããŸãã ãæž èŽããããšãããããŸããïŒ