
ããã§ãã¯ãšã¹ããèŠçŽããã©ã®ããã«ãããããããã©ã®ãããªå°é£ã«ééãããã«ã€ããŠè©±ãããšãã§ããŸãã ãããŠããã¡ãããã¯ãšã¹ãèªäœãšããã®äœæãšãããã°ã®äž¡æ¹ã«åå ãããã¹ãŠã®äººã«æè¬ããŸãã
æçµçµæ
ã¯ãšã¹ããå ¬åŒã«çµäºããæ¥ã«ãç»é²ãããåå è ã®æ°ã¯1,480人ã«éããŸããã ãããããå°ããã¯ããªã次第ã§ãã ç§ãã¡ã«ãšã£ãŠå¥ã®æ¥œããç¬éã¯ã競æã®éå§åŸã«éåžžã«å€ãã®åå è ãç»é²ãããšããäºå®ã§ããã ããã¯ãã¯ãšã¹ãã«é¢ããæ å ±ãé ä¿¡ããããã®é¢å¿ãåæã®é ã ãã§ã¯ãªãã£ãããšãæå³ããŸãã
åè³ããè³åïŒ
- ã¹ã¢ãŒã¯ãªãŒãããã³
- BECHEDïŒAndrey1800ã
- ki11obyte ã
More Smoked Leet ChickenããŒã ã¯ããã¹ãŠã®ã¿ã¹ã¯ãå®äºããã ãã§ãªããæçæéã§å®äºããŸããã 圌ãã¯ç§ãã¡ã®ç«¶äºã®äž»ãªè³ãåè³ããŠããŸãã BECHEDïŒAndrey1800ãškillobyteã®åå è ã«ã¯ãã³ã³ãã¹ãã®2äœãš3äœã®è³ãæäžãããŸãã ããã«ãã¯ãšã¹ãã®æåã®æ®µéãå®äºãããã¹ãŠã®åå è ã«ã¯ãæãåºã«æ®ãèŽãç©ãèŽãããŸãã ã¯ãšã¹ãã®æåããããšã©ãŒãè匱æ§ãèŠã€ããã¯ã©ãã¯ããããã®ãã¯ã©ãã¯ããããã®ãã¹ãŠããããã³ã°ãããšããããªãã®æŽ»åã«é©ããŸããã ããªãã¯ãç§ãã¡ã決ããŠç¥ããªãã£ããã®ãããªåããèŠã€ããç§ãã¡ã以åã«ééããããšããªããããã®é åãç±å¿ã«ç解ããŸããã
ã¡ã¢ãæž¡ã
ã¯ãšã¹ããæ£åŒã«å®äºãããšããäºå®ã«ãããããããã¿ã¹ã¯ã®ããã«2é±éãå®äºã§ããããã«ãªããŸãã èªåã§è©ŠããŠã¿ããå Žåã¯ããã®ã»ã¯ã·ã§ã³ãã¹ãããããããšããå§ãããŸãã
ãã¡ãããã¿ã¹ã¯ãå®äºããããã®èª¬æãããæ¹æ³ã ããå¯èœãªæ¹æ³ã§ã¯ãããŸããã åå è æ°-åæ Œããããã®éåžžã«å€ãã®ãªãã·ã§ã³ã
NeoQUESTãäœæããéã次ã®ç®æšãè¿œæ±ããŸããã
- è€éããšæ è¡æéã®éã§åŠ¥åç¹ãèŠã€ããŸãã ã¯ãšã¹ãã¯ãçµéšè±å¯ãªããã®ãã¬ã€ã€ãŒã®ããŒã ã ãã§ãªããé¢é£ããå°éåéã®äžçŽåŠçãå«ãè³æ Œã®ããã³ã³ãã¥ãŒã¿ãŒã»ãã¥ãªãã£ã¹ãã·ã£ãªã¹ãã«ãã£ãŠãæ£åžžã«å®äºããå¿ èŠããããŸãã èšç®ã«ãããšããã¹ãŠã®ã¿ã¹ã¯ãæž¡ãããã®æ£å³æéã¯çŽ10ã12æéã§ããã
- äžè¬çãªWebã»ãã¥ãªãã£ã¯ãšã¹ãããé¢ããã
- ããã®æŽ»åââã§ããééããç¶æ³ã«ã¿ã¹ã¯ãè¿ã¥ããŸãã ã¯ãšã¹ãã¯ãèžè¡ã®ããã®èžè¡ãã§ãã£ãŠã¯ãªããŸããã
- æ å ±ã»ãã¥ãªãã£ã®ããŸããŸãªåŽé¢ãã«ããŒããŸããSCADAã·ã¹ãã ã®ä¿è·ããã¹ãã¬ãã°ã©ãã£ããã³ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®èŠçŽ ãŸã§ã
- ã¿ã¹ã¯ãå ±éã®åºæ¿çãªãããããšçµã¿åãããŠãå šäœçã«èå³æ·±ãã²ãŒã ãäœæããŸãã
ãã®çµæãèŠãŠã¿ãŸãããã ã¯ãšã¹ãã¯è«ççã«5ã€ã®ã»ã¯ã·ã§ã³ã«åãããŠããŸãã
- Webã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ïŒã¿ã¹ã¯1ã2ïŒã
// - !
- æå·åïŒã¿ã¹ã¯3ïŒã
// , ?
- SCADAã·ã¹ãã ã®ã»ãã¥ãªãã£ïŒã¿ã¹ã¯4ïŒã
// âŠ
- Windowsã»ãã¥ãªãã£ïŒã¿ã¹ã¯5ã6ïŒã
// âŠ
- ã³ã³ããå
ã®æ
å ±ãæ€çŽ¢ããŸãïŒã¿ã¹ã¯7ã8ïŒã
// âŠ
ã»ã¯ã·ã§ã³1ïŒã¿ã¹ã¯1ã2ïŒã WebãµãŒããŒïŒ
ãã®ã»ã¯ã·ã§ã³ã®ã¿ã¹ã¯ãå®äºããã«ã¯ãWebã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ãç¹ã«SQLã€ã³ãžã§ã¯ã·ã§ã³ãç¹å®ããæªçšããããšãã§ããã°ååã§ãã WebãµãŒããŒãšããŠãå€æ°ã®Mint + lamppã䜿çšãããŸããããã«ã¯ãããŒã¿ããŒã¹ãæäœããããŒãã«ã®å 容ã衚瀺ããããã®è€æ°ã®phpã¹ã¯ãªããããããŸãã ãããã®äžéšã«ã¯ãããšãã°è匱ãªããŒã¿ããŒã¹ã¯ãšãªãªã©ã®ãšã©ãŒãå«ãŸããŸãã
$id = str_replace( array('_', ']', '[', ')', '(', '$', 'http://', 'ftp://', '/', '.', '+', '=', 'data', 'base64', 'cmd', 'phpinfo()', 'union', 'select', 'from', 'where', 'UNION', 'SELECT', 'FROM', 'WHERE' ), '', $id ); $id = htmlspecialchars($id); $query = "SELECT * FROM news WHERE id=$id";
åé¡ã解決ããæãç°¡åãªã¯ãšãªã¯æ¬¡ã®ãšããã§ãã
httpïŒ//***/news/comments.phpïŒid = 1 uNion sElect 1ãååããã¹ã4 fRomãŠãŒã¶ãŒ
ãŸãããµãŒããŒã«ã¯æ¬äŒŒç®¡çè ããããããã¯1人ã®ãŠãŒã¶ãŒã«ã®ã¿è¡šç€ºãããFreeBSDä»®æ³ãã·ã³ã§ã€ã¡ãŒãžãããŠã³ããŒãã§ããŸãã 管çããã«ãžã®ãã¹ã¯ãrobots.txtãã¡ã€ã«ããååŸã§ããŸãããã®å 容ã¯æ¬¡ã®ãšããã§ãã
User-agent: *
Disallow: /cgi-bin/
Disallow: /administrador/
ã»ã¯ã·ã§ã³2ïŒã¿ã¹ã¯3ïŒã ãã°ã®è§£èªã FreeBSD +ãããã·ïŒ
ãã®ã¿ã¹ã¯ã§ã¯ãåå è ãRC4ããã³RSAæå·åã¢ã«ãŽãªãºã ãç¹ã«æå·åãã©ã¡ãŒã¿ãŒã®éžæãšæå·è§£æã®åºç€ã«ã€ããŠã®ç¥èãæã£ãŠããå¿ èŠããããŸããã
FreeBSDä»®æ³ãã·ã³ã¯ãRC4ã¢ã«ãŽãªãºã ã§ä»¥åã«æå·åããããã°ããåŸã§RSAã§æå·åãããããŒã«ä¿åããŸãã RSAã®å ¬éææ°ã®å€ã¯ãã¡ãã»ãŒãžãæ°ç§ã§åŸ©å·åãããããã«ãæå°ïŒ3ã«çããïŒã«éžæãããŸãã çªå·NïŒRSAã¢ã«ãŽãªãºã ã®ããŒã¢ãžã¥ãŒã«ïŒã®å±éãååŸããã«ã¯ãããŒã¬ã¹ã¡ãã»ãŒãžåŸ©å·åã¡ãœããã䜿çšããæ»æã䜿çšããå¿ èŠããããŸãïŒ http : //algolist.manual.ru/defence/attack/rsa.php#RSA1 ã 察称æå·éµãåãåã£ãããããšãã°ã http ïŒ//www.crypo.com/tools/eng_rc4.phpã®ããã«ãRC4ã¢ã«ãŽãªãºã ã䜿çšããŠãã°ã埩å·åããå¿ èŠããããŸã ã
ãã°ã«ã¯ããªã¢ã¯ã¿ãšãã€ããŒã®2ã€ã®ã¢ãã¬ã¹ã«é¢ãããšã³ããªãå«ãŸããŠããŸãã
ã»ã¯ã·ã§ã³3ïŒã¿ã¹ã¯4ïŒã SCADAã ããã©ã«ãã®ãã¹ã¯ãŒãã¯æ¬¡ã®ãšããã§ãã
WinCCãã¹ã«ãããšããŠéžæãããšããã®ã·ã¹ãã ã«åºæã§ã¯ãªãããã€ãã®åé¡ã«ééããŸããã WinCCã¯ãNeoQUESTãžã®åå ãæåºãšããŠæãã§ããŸããã§ãããç¹ã«ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®æŽæ°ãå®å šã«æåŠãããéåžžã«æçœãªãè匱æ§ãæªè§£æ±ºã®ãŸãŸã«ããŠããŸããã äžéšã®åå è ã¯ãããã®è匱æ§ã䜿çšããŠã¹ã«ããããç Žå£ãããŸãããããããäºæ³ããŠãããã€ãã³ãã®ãã®ãããªå±éã«åããŠããŸããã
ã¹ããŒã ã¯WinCCã«å±éãããŠããïŒäŒèª¬ã«ãããšãLNPPãªã¢ã¯ã¿ãŒïŒãã¢ã¯ã»ã¹ããããšãWebã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠå¿ èŠãªãã©ã°ãçºè¡ãããŸãã Webã¢ã¯ã»ã¹çšã«ããã©ã«ãã®ãã¹ã¯ãŒããèšå®ãããŠããŸããããã¯ãWinCCã®ããã¥ã¡ã³ãã«èšèŒãããŠããŸãã
ã»ã¯ã·ã§ã³4ïŒã¿ã¹ã¯5ã6ïŒã WindowsïŒ
ãã®ã»ã¯ã·ã§ã³ã®ã¿ã¹ã¯ã§ã¯ãWindowsã®ã«ã¹ã¿ã ããŒãžã§ã³ã®ã»ãã¥ãªãã£é¢ã«ã€ããŠèª¬æããŸããã åå è ãåæ Œããã«ã¯ãWindowsããã¡ã€ã«ã¢ã¯ã»ã¹æš©ã決å®ããæ¹æ³ïŒç¹ã«ãææè ç¹æš©ãäžãããã®ïŒããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ãå¢ããæ¹æ³ïŒç¹æš©ãšã¹ã«ã¬ãŒã·ã§ã³ã®è匱æ§ãªã©ïŒãç¥ãå¿ èŠããããŸãã ä»®æ³ãã·ã³ïŒ800ã¡ãŒãã«ïŒïŒã®ã€ã¡ãŒãžãé åžããããã«ãp2pãããã¯ãŒã¯ïŒãã¬ã³ãïŒã䜿çšããããšã決å®ãããŸãããããã«ããããã¬ãŒã€ãŒã«ãšã£ãŠãã䟿å©ã«ãªããããããæ¡ä»¶ã§éåžžã®é床ãç¶æã§ããŸãã æåã®éšåã§ã¯ãã·ã¹ãã 管çè ã®ã¿ãã¢ã¯ã»ã¹ã§ãããã©ã«ããŒãããã¡ã€ã«ãéãå¿ èŠããããŸãã ãã®ããã«ãç¹æš©ãšã¹ã«ã¬ãŒã·ã§ã³ãšã¯ã¹ããã€ããèµ·åããå¿ èŠããããšèšç»ãããŠããŸããããå¥ã®æ¹æ³ïŒã¯ããã«ç°¡åïŒããããŸãã-LiveCDããèµ·åããããä»®æ³ãã£ã¹ã¯ãå¥ã®ä»®æ³ãã·ã³ã«æ¥ç¶ããŸãã 2çªç®ã®æ¹æ³ïŒLiveCDã䜿çšïŒãè€éã«ããåå è ãïŒãšã¯ã¹ããã€ãã䜿çšããŠïŒæåã®æ¹æ³ã«ããã·ã¥ããããã«ãããããæ¹æ³ã§è©Šã¿ãŸããã ãããè¡ãã«ã¯ããã«ãã€ã³ç®¡çè ã¢ã«ãŠã³ããç¡å¹ã«ããŸãã ç¹æš©ãšã¹ã«ã¬ãŒã·ã§ã³ãšã¯ã¹ããã€ããåºãç¥ãããŠãããçµéšè±å¯ãªãŠãŒã¶ãŒããäœæããŸããã æå·åãããTrueCryptããŒãã£ã·ã§ã³ãäœæããèŠçããåé€ããŸããã 管çè ãšããŠãã°ã€ã³ãããšãã«ã®ã¿èªåçã«ããŠã³ããããããã«ããŸãã ãããŠãæªçšããããœãŒã¹ïŒãã¡ãããå°ããšã©ãŒããããŸãããããã§ãã¿ã¹ã¯ã¯ãã£ãšç°¡åã«ãªããŸãïŒããã¹ã¯ãããã«æãåºãããŸããã
管çè æš©éãååŸããåŸãã³ã³ããã«ã¢ã¯ã»ã¹ããã«ã¯ã確ç«ããããã¡ã€ã«æš©éãå°ãè©Šãå¿ èŠããããŸãã
ã»ã¯ã·ã§ã³5ïŒã¿ã¹ã¯7ã8ïŒã ã³ã³ããåæïŒ
ãããã®ã¿ã¹ã¯ãå®äºããã«ã¯ãå°ããµãã¢ã»ã³ãã«ãããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã«å°ã觊ããŠãè«ççã«æšè«ããå¿ èŠããããŸãã çµæã®ãã©ã°ã¯ãã³ã³ããå ã«é ãããŠããexeãã¡ã€ã«ãçæããŸãã å³ã¯ãã³ã³ããå³ã瀺ããŠããŸãã

æå·åãããã»ã¯ã·ã§ã³ã®ãã£ã¬ã¯ããªå ã«ã¯ãvk.comããã®ãŠãŒã¶ãŒIDã瀺ãPNGãã¡ã€ã«ããããŸãã ãã®ããŒãžã«ã¯ããã€ãã®ãã³ãããããŸãã ã¢ãŒã«ã€ãã¯PNGã®æåŸã«è¿œå ããããã¡ã€ã«æ¡åŒµåãPNGããRARã«å€æŽãããšãã¢ãŒã«ã€ããšããŠéããŸãã ããŒã¿ã¯ãã¹ã¯ãŒãã§ã¢ãŒã«ã€ãããããã®ã¢ã«ãŽãªãºã ã¯VKããŒãžã®ãŠãŒã¶ãŒã¹ããŒã¿ã¹ã§ç€ºãããŸãã ã¢ãŒã«ã€ãå ã«ã¯WAVãã¡ã€ã«ã®ããã«èŠãããã¡ã€ã«ããããŸãïŒèŽãããšããã§ããŸãïŒããå®éã«ã¯WAVããã®ããããŒãæã€è©°ãŸã£ãexeã§ãïŒããã«é¢ãããã³ããVKã«ãããŸãïŒã xorã®ããŒã¯ãPNGç»åã§åœè£ ãããŠããŸãã å®è¡å¯èœãã¡ã€ã«ã¯ããŒãå ¥åãšããŠåãå ¥ããæåŸã®ãã©ã°ãçºè¡ããŸãã
åé¿ãã¹ãçµç¹äžã®åé¡
ç§ãã¡ã®ããŒã ã«ãšã£ãŠãããã¯ãã®ãããªã€ãã³ããéå¬ããæåã®çµéšã§ããããä»ãè¡ãããäœæ¥ã®çµæã«å¿ããŠãç§ãã¡ã¯ã©ã®ããã«ç°ãªã£ãŠãããªããã°ãªããªãã£ãããèšãããšãã§ããŸãã äž»ãªçµè«ã¯ããããã次ã®ãšããã§ãã
- ãŠã§ããã¹ãã£ã³ã°ãªãïŒãŸãã¯ã¿ã€ã ãã¹ãæžã¿ïŒã NeoQUEST-2012ã®éçºãéå§ãããšããç»é²ãã©ãŒã ãäžéšã®ãã¹ãã£ã³ã°ã«æããã¹ãã ãšå€æããŸããã 圌ãã¯ãåçŽãªãµã€ãã§ã¯åé¡ã¯ãªãã¯ãã ãšèããŸããã ããã§ç§ãã¡ã¯ééã£ãŠããŸããã ã¡ã€ã³ãããã¯ããã®ç¹å®ã®åé¡ã«é¢é£ä»ããããŠããŸããã ãã¹ãã£ã³ã°ã¯ãåçŽãªç»é²ãµã€ãã«ãèããããŸããã§ããã 圌ã¯çµ¶ããcrashèœããåé¡ããã°ããæŽçããããšãããšããã¹ãåŽã®ããŸããŸãªäººã ãšã®é»è©±ãšèª¿æŽã®ç¡éã®å®åçãªãã§ãŒã³ãåãåããŸããã圌ãã¯è¿œå ã®è²¬ä»»ãè² ããããããŸããã§ããã ããµãŒããŒãåèµ·åã§ããã®ã¯ç®¡çè ã®ã¿ã§ãããæææ¥ããåã«ã¯ãªããŸãããã ããããäŒç€Ÿãç解ã§ããŸããç§ãã¡ã¯åœŒãã®å¯äžã®é¡§å®¢ã§ã¯ãªãã圌ãã¯ãŸã åé¡ã解決ããŠããŸãã é©åã§ã¿ã€ã ãªãŒãªçµæãå¿ èŠãªå Žåã¯ãå€ä»£ã®ã«ãŒã«ãèŠããŠãããšããã§ãããããäœããããŸãããããã®ãªããèªåã§ãããã
- ãµãŒããŒãã¬ã³ã¿ã«ãããšãã¯ååã«æ³šæããå¿ èŠããããŸãã ãµãŒããŒã¬ã³ã¿ã«ã«ã¯é·æãšçæããããŸãã ãã®ãµã€ãã§ã¯ã24æéãµãŒããŒãžã®ç©ççãªã¢ã¯ã»ã¹ãèš±å¯ããŠããªãããããµãŒããŒã暪ã«åããããšã«ããŸããã ãã®ãœãªã¥ãŒã·ã§ã³ã®å©ç¹ã¯æããã§ããããã«æãããŸã-ã¡ã€ã³ãµã€ãã§çªç¶çºçããå¯èœæ§ã®ããå°é£ïŒé±æ«ã®åé»ãªã©ïŒã«äŸåããŠããªãããããã®ãµãŒããŒã®24æéäœå¶ã§å€åããå¿ èŠã¯ãããŸããã ãããããããããããŠäºæãã¬é©ããç§ãã¡ãåŸ ã£ãŠããŸããã ããšãã°ãç¥ããããŠããªããããã¯ãŒã¯ãåæ§æãããšãããµãŒããŒãã³ããŒã«ããçªç¶ã®æ±ºå®ã çµè«ã¯åã®æ®µèœãšåãã§ãã
ç»é²æéå šäœãéããŠãããã§Habréãšä»ã®ãµã€ãã®äž¡æ¹ã§è¡ãããã³ã¡ã³ããšã³ã¡ã³ãã泚ææ·±ãç£èŠãã劚害ããã°ããä¿®æ£ããããšããŸããã ãããã«ã€ããŠç§ãã¡ã«ç¥ãããŠããããã¹ãŠã®äººã«æè¬ããŸãã
çµè«ãšè¬èŸ
ããã¯ã¯ãšã¹ãã¯ãå ¥éè ã«ãšã£ãŠã¯äžçš®ã®äŒæ¯ãšåš¯æ¥œã§ãã ãããŠã宣èšãããéèŠãªç®æšïŒããã³äžéšã®ã³ã¡ã³ããŒã¿ãŒãç§ãã¡ã«åž°ããäžåãªç§å¯ã®ç®æšïŒã«ãããããããããŒã å šäœã«ãšã£ãŠãNeoQUESTã¯ããããèå³æ·±ãããã«ãŒã²ãŒã ãäœæããæ©äŒãšãªããŸããã ã¯ãšã¹ãã®ééäžã«ãç§ãã¡ãæºåãããšããšåããããã®åã³ãåŸãããšãé¡ã£ãŠããŸãã ãã§ã«è¿°ã¹ãããã«ãããã¯åœç€Ÿã«ãšã£ãŠãã®ãããªäœæ¥ã®æåã®çµéšã§ããããã®çµéšã¯çãããæçšã§ãåºæ¿çã§ãããããã§æ¢ãŸãã€ããã¯ãããŸããã
åœç€Ÿã代衚ããŠãå¿ããæè¬ããŸãã
- ãããžã§ã¯ãã®äœæãšãµããŒãã«æéã®å€§éšåãè²»ãããããã©ãšããœã³ã
- ãããªã®æ®åœ±ã«åå ãããã¹ãŠã®äººã
- ããŒãã®ãããã¯ãŒã¯ãªãœãŒã¹ã«é¢ããå人ãååããã¯ãšã¹ãã®éåœã«ç¡é¢å¿ã§ã¯ãªããWebã§ã®ã¯ãšã¹ãã«ã€ããŠè©±ãåã£ãïŒãšãã©ãéåžžã«æããããªãããšããããŸããïŒïŒ
- ãããHabréãããã³ä»ã®ãªãœãŒã¹ã§åçãããã¹ãŠã®äººãããã³ãµããŒãã®ãšã©ãŒã誀ç®ã«ã€ããŠç§ãã¡ã«æžãããã¹ãŠã®äºº-ããã¯ãæéå ã«å€§ããªãžã£ã ããã£ãããïŒç»é²ãã©ãŒã ã®åŽ©å£ïŒãå°ããªãã®ããã°ããã¬ã¿ããããŸããïŒæéåäœãèæ ®ããŠããªãã«ãŠã³ãããŠã³ã¿ã€ããŒãªã©ïŒãã«ãããŸãã¯éœåžå ¥åãã£ãŒã«ãã®ç¡å¹ãªæåãªã©ïŒ
- ãããŠããã¡ããããã¹ãŠã®åå è ãšåè³è ã¯ãããªããNeoQUESTã«èå³ãæã¡ãããªãã®å¿èãšæŽ»åã®ããã«ããºã«ã解ãããã«æéãå²ããªãã£ããšããäºå®ã®ããã«ã
ç§ãã¡ã¯ããŸãååããçæ§ã«ãããªãååããé¡ãããŸãïŒ
ã¿ããªã«æè¬ãã次ã®NeoQUESTã§ãäŒãããŸãããïŒ