æåã«ãåªããè匱æ§åæãè¡ã£ãRobert Grahamã®ããã°ããæ å ±ãå ±æãããŠãã ããã 次ã®HTTPèŠæ±ãæ€èšããŠãã ããã
target = 0.0.0.0/0 port = 80 banners = true http-user-agent = shellshock-scan (http://blog.erratasec.com/2014/09/bash-shellshock-scan-of-internet.html) http-header = Cookie:() { :; }; ping -c 3 209.126.230.74 http-header = Host:() { :; }; ping -c 3 209.126.230.74 http-header = Referer:() { :; }; ping -c 3 209.126.230.74
è匱ãªIPã®ç¯å²ã«é©çšãããå Žåã次ã®çµæãåŸãããŸãã
ç°¡åã«èšãã°ããããŒãã¯ãç¹å¥ã«çŽ°å·¥ãããªã¯ãšã¹ãããããã¯ãŒã¯ã«éä¿¡ããã ãã§ãäžé£ã®ãªã¢ãŒããã·ã³ã«pingãéä¿¡ããŸããã äžå®ã¯ã圌ããããã®ãã·ã³ã«ä»»æã®ã³ãã³ãïŒãã®å Žåã¯ç¡å®³ãªpingïŒãå®è¡ããããã«åŒ·å¶ãããšããäºå®ã«ãã£ãŠåŒãèµ·ããããŸãã
Bashãšã¯äœã§ããããªãå¿ èŠãªã®ã§ããïŒ
ãã§ã«ãããã¯ã«ããå Žåã¯ããã®ã»ã¯ã·ã§ã³ãã¹ãããã§ããŸãã ãã ãã Bashã«æ £ããŠããªãå Žåã¯ã以äžã®æ å ±ãèªãã§å šäœåãç解ããããšããå§ãããŸãã Bashã¯ãéåžžSSHãŸãã¯Telnetæ¥ç¶ã§Linuxããã³Unixã·ã¹ãã ã§åºã䜿çšãããŠããã³ãã³ãã·ã§ã«ïŒã€ã³ã¿ãŒããªã¿ãŒïŒã§ãã Bashã¯ãApacheãªã©ã®WebãµãŒããŒäžã®CGIã¹ã¯ãªããã®ããŒãµãŒãšããŠãæ©èœããŸãã Bashã¯1980幎代ã«ãŸã§ããã®ãŒãã以åã®ã·ã§ã«å®è£ ïŒååã¯Bourneã·ã§ã«ã«ç±æ¥ïŒããé²åããä¿¡ããããªãã»ã©äººæ°ãââãããŸãã ãã¡ãããä»ã®ã€ã³ã¿ãŒããªã¿ãŒããããŸãããLinuxããã³Mac OS Xã«ã¯ããã©ã«ãã§Bashãä»å±ããŠããããåãã®ããã«éåžžã«æ®åããŠããŸãã ãã®ã€ã³ã¿ããªã¿ã¯ã ãLinuxã·ã¹ãã ã§æãäžè¬çãªãŠãŒãã£ãªãã£ã®1ã€ã ãšããŠèªèãããŠããŸãã Shellshockãéåžžã«å±éºãªäž»ãªçç±ã¯ãBashã®valence延ã§ãããã®ã°ã©ãã¯ãBashã®éåšæ§ãèŠèŠçã«è¡šããŠããŸãã
ã€ã³ã¿ãŒãããã®ååã¯ãApacheïŒéåžžã¯Linuxã«ã€ã³ã¹ããŒã«ãããŸãïŒã§å®è¡ãããŸãããããã¯æ¬åœã«éåžžã«å€ãã®ããšã§ãã åãèšäºã§ã¯ããã§ã«10åã®æ¢åã®Webãµã€ãã®å¢çãè¶ããŠããããããã®å€ãã倧èŠæš¡ãªãã¹ãã£ã³ã°ã«çœ®ãããŠãããããèšå€§ãªæ°ã®Bashã®ã€ã³ã¹ããŒã«ãããã³ããŒãæ±ã£ãŠããŸãã ãŸããWebãµãŒããŒä»¥å€ã«ããLinuxãå®è¡ããŠããä»ã®å€ãã®ãµãŒããŒãããã€ã¹ãå¿ããªãã§ãã ããã ããããåŸã§ããã«æ»ããŸãã
Bashã¯ãWebãµã€ãã®æ§æãããWebã«ã¡ã©ãªã©ã®åšèŸºæ©åšã®ãã¡ãŒã ãŠã§ã¢ã®ç®¡çãŸã§ãå¹ åºãã·ã¹ãã ã¿ã¹ã¯ã«äœ¿çšãããŸãã ãã®ãããªæ©äŒã¯ãã¹ãŠã®æ¥èšªè ã«éãããã¹ãã§ã¯ãªããçè«çã«ã¯ç¹å®ã®ã¢ã¯ã»ã¹æš©ãæã€èš±å¯ãŠãŒã¶ãŒã®ã¿ãå©çšã§ããããã«ããå¿ èŠããããŸãã çè«çã«ã
è匱æ§ã®æ¬è³ªã¯äœã§ããïŒ
ç¶æ³ã®é倧床ã¯ã NISTè匱æ§ããŒã¿ããŒã¹ããã®æ¬¡ã®åŒçšã«ããæšå®ã§ããŸã ãGNU Bashãã4.3ã¯ãç°å¢å€æ°ã®å€ã®é¢æ°å®çŸ©ã®åŸã®æ«å°Ÿã®æååãåŠçããŸããããã«ããããªã¢ãŒãæ»æè ã¯çŽ°å·¥ããç°å¢ãä»ããŠä»»æã®ã³ãŒããå®è¡ã§ããŸã ãOpenSSHsshdã®ForceCommandæ©èœãApacheã®mod_cgiããã³mod_cgidã¢ãžã¥ãŒã«HTTPãµãŒããŒãäžç¹å®ã®DHCPã¯ã©ã€ã¢ã³ãã«ãã£ãŠå®è¡ãããã¹ã¯ãªãããããã³ç°å¢ã®èšå®ãBashã®å®è¡ããç¹æš©å¢çãè¶ããŠè¡ããããã®ä»ã®ç¶æ³ã
è匱æ§ã«ã¯ã10ã®ãã¡10ãã®ã¬ãã«ãå²ãåœãŠãããŸããã€ãŸããã©ãã«ãæªãããšã¯ãããŸããã ããã«ãæ»æã®ããããïŒã¢ã¯ã»ã¹ã®è€éãã¯äœãïŒãããã«éèŠãªããšã«ã CGIã¹ã¯ãªããã䜿çšããŠBashã䜿çšããããã«å¿ èŠãªèªèšŒã®æ¬ åŠãè¿œå ããŸãã ãã°èªäœã®æ¬è³ªãç解ããŸãããã
äž»ãªå±éºæ§ã¯ãé¢æ°ãå®çŸ©ããBashã€ã³ã¿ãŒããªã¿ãŒå ã§ç°å¢å€æ°ãä»»æã«èšå®ã§ããå¯èœæ§ã«ãããŸãã é¢æ°ãå®çŸ©ããåŸãBashãã€ã³ã¿ãŒããªã¿ãŒã³ãã³ããåŠçãç¶ãããšåé¡ãå§ãŸããŸããããã«ãããã³ãŒãã€ã³ãžã§ã¯ã·ã§ã³ã«ããæ»æãå¯èœã«ãªããŸãã ãããŒãã®äŸãã1è¡ã ããèŠãŠã¿ãŸãããã
http-header = Cookie:() { :; }; ping -c 3 209.126.230.74
é¢æ°ã®å®çŸ©ã¯
() { :; };
() { :; };
ãã€ã³ã¿ãŒããªã¿ãŒã³ãã³ãã¯pingãšãã®ãã©ã¡ãŒã¿ãŒã§ãã ãã®è¡ãBashã€ã³ã¿ãŒããªã¿ãŒã§åŠçããå Žåãä»»æã®ã³ãã³ããå®è¡ã§ããŸãã Webã®ã³ã³ããã¹ãã§ã¯ãããã¯CGIã¹ã¯ãªãããªã©ã®ã¡ã«ããºã ãéããŠããªãã·ã§ã³ã§ãªã¯ãšã¹ãããããŒãéããŠå®è¡ã§ããŸãã 詳现æ å ±ã¯seclists.orgããŒãžã«ãããŸããããã¹ãšã¯ãšãªæååãæœåšçãªæ»æãã¯ãã«ã«ãªãå¯èœæ§ãããããšãããããŸãã
ãã¡ããã CGIã®æ©èœãç¡å¹ã«ããã ãã§ç¶æ³ãç·©åã§ããŸãã ããããå€ãã®å Žåãããã¯Webãµã€ãã«é倧ãªåœ±é¿ãäžããå°ãªããšããåäœããããšã確èªããããã«åºç¯ãªãã¹ããå¿ èŠã«ãªããŸãã
äžèšã®HTTPãªã¯ãšã¹ãã¯åçŽã§å¹ççã§ããããã®ãããã³ã«ã®å€ãã®å¯èœãªçšéã®1ã€ã«ãããŸããã TelnetãšSSHããããŠæããã«DHCPãèæ ®ã«å ¥ãããšãWebãµãŒããŒãžã®æ»æã«ã€ããŠã®ã¿è©±ããŠãããšããäºå®ã«ãããããããåé¡ã®èŠæš¡ã¯äœåºŠã倧ãããªããŸãã ãããŸã§ã®ãšããã SSHã§ã®èªèšŒåŸã«ã®ã¿å±éºããããŸãããå°æ¥ãä»ã®æ»æãã¯ãã«ãèŠã€ããã§ãããã
ãããŒãã®äŸã®ããã«ãæ»æè ã®èœåã¯ç¹å®ã®ã¢ãã¬ã¹ã®pingãã¯ããã«è¶ ããŠããããšãèŠããŠããå¿ èŠããããŸããããã¯ããªã¢ãŒããã·ã³ãå¶åŸ¡ãããŸãã«ãã®èœåã®ã»ãã®äžäŸã§ãã ããã§ã®è³ªåã¯ããªã¢ãŒããã·ã³ã®ã€ã³ã¿ãŒããªã¿ãŒã§ããŸããŸãªã³ãã³ããå®è¡ããããšã«ãããäŸµå ¥è ãã©ã®ãããªå®³ãåãŒãå¯èœæ§ãããããšããããšã§ãã
æœåšçãªçµæã¯äœã§ããïŒ
ã€ã³ã¿ããªã¿ãžã®ã¢ã¯ã»ã¹ãååŸããããšã¯ãæ»æè ã«ãšã£ãŠåžžã«å€§ããªåå©ã§ãããããã¯ãé©åãªæš©éãæã€ãµãŒããŒã®å¶åŸ¡ãååŸããããšã«çããããã§ãã å éšããŒã¿ãžã®ã¢ã¯ã»ã¹ãç°å¢ã®åæ§æããã«ãŠã§ã¢ã®æ¡æ£ãªã©ã å¯èœæ§ã¯ã»ãŒç¡éã§ãããèªååãããŠããŸãã å€æ°ã®ãã·ã³ã«å¯ŸããŠç°¡åã«é©çšã§ãããšã¯ã¹ããã€ãã®äŸã¯ãã§ã«éåžžã«å€ããããŸããæ®å¿µãªãããã€ã³ã¿ãŒãããWebãµãŒããŒã®ååã®ã³ãã³ãã€ã³ã¿ãŒããªã¿ãŒã§ä»»æã®ã³ãŒããå®è¡ããããšã«ãªããšãå¯èœæ§ã¯éåžžã«å€§ãããªããŸãã æããã§æãåä»ãªã®ã¯ã å éšãã¡ã€ã«ã«ã¢ã¯ã»ã¹ããããšã§ã ã ãã¹ã¯ãŒããšæ§æãå«ããã¡ã€ã«ãæãéèŠã§ãããäžè¬çã«ãã¹ãŠã®ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããŸãã
åãããšã¯ããªã¢ãŒããã·ã³ã«ãã¡ã€ã«ãæžã蟌ãæ©èœã«ãåœãŠã¯ãŸããŸãã ããã¯ããã«ãŠã§ã¢ã®æ¡æ£ã¯èšããŸã§ããªããããŒãžãä»ã®äººã®ãŠã§ããµã€ãã«çœ®ãæããæãç°¡åãªæ¹æ³ã®1ã€ã§ãã ãŸãã¯ãããã¯ã©ãã§ããïŒ
ã¯ãŒã ã«é¢ããŠèšãã°ãã¿ãŒã²ããã·ã¹ãã äžã«ç¬èªã®ã³ããŒãäœæããæªæã®ãããœãããŠã§ã¢ãæå³ããŸãã éåžžã«å¹æçãªã¯ãŒã ã®äŸã¯ã1æ¥ä»¥å ã«äœçŸäžãã®WebããŒãžã«ææããSamy XSSã¯ãŒã ã§ãã
Shellshockã®å±éºæ§ã¯ãã»ãšãã©ã®ãã·ã³ã§ãã®è匱æ§ã解決ããããŸã§ãç¹ã«åæ段éã§ææçã®æµè¡ãå§ãŸãå¯èœæ§ããããšããäºå®ã«ããããŸãã ææãããã·ã³èªäœãæ°ããç ç²è ãæ¢ããŠææããŸãã ãããŠä»ããã¹ãŠã®å ¬å ±ã®ãã·ã³ãå±éºã«ãããããŠãããäŒæ¥ã®ãã¡ã€ã¢ãŠã©ãŒã«ã貫éãããšããä¿åããå Žæã¯ãããŸããã 人ã ã¯ãã§ã«ããããã§ã«å©çšããŠããŸãã çŸåšãå®éã®è»æ¡ç«¶äºã¯ãã®ã£ãããéæããã人ãšã®ã£ãããåããã人ã®éã§æ¬æ Œçã§ãã
圱é¿ãåããBashã®ããŒãžã§ã³ã¯äœã§ããïŒ
4.3ãå«ãéå»25幎éã®ãã¹ãŠã®ããŒãžã§ã³ã éå»2幎éOpenSSLã«ãããããŠããHeartbleedãšæ¯èŒããŠãã ããã ã¯ãã人ã ã¯ããŒãžã§ã³ãæŽæ°ããŠããŸãããããã¯äœç³»çã«è¡ãããŠããŸããããšã«ãããShellshockã¯Heartbleedãããã¯ããã«å€ãã®ãã·ã³ãè ããŠããŸããæ®å¿µãªããããã®è匱æ§ã¯å°æ¥ã®ããŒãžã§ã³ã§ãæç¶ããå¯èœæ§ããããŸãã ãããã«é¢ããæ å ±ã¯ãã§ã«ãããŸãããããŸãå¹æçã§ã¯ãããŸããã§ãã ã ãããã£ãŠããã®è匱æ§ã¯éåžžã«æ éã«ç£èŠããå¿ èŠããããŸãããããããã€ã³ã¹ããŒã«ããåŸã«å¿ããããšãã§ãããã®ã®1ã€ã§ã¯ãããŸããã
è匱æ§ã¯ãã€çºèŠãããŸãããïŒ
ç§ãèŠã€ããæåã®èšåã¯ãæ°Žææ¥ã®ååŸ2æïŒã°ãªãããžæšæºæïŒã«çºè¡ãããseclists.orgã®éåžžã«çãèšäºã«ãããŸãã ã 1æéåŸã«è©³çŽ°æ å ±ãåããªãœãŒã¹ã«æçš¿ãããŸãã ã ãããã£ãŠãããã¯éåžžã«ãæ°é®®ãªããã¥ãŒã¹ã§ããããéçãã§ã®ãšã¯ã¹ããã€ãã®å€§èŠæš¡ãªåºçŸã«ã€ããŠè©±ãã®ã¯ææå°æ©ã§ãã ããããããã¯ããã«èµ·ããå¯èœæ§ãããã確çã¯1æéããšã«å¢å ããŸããåè¿°ã®ããã«ããã®è匱æ§ã¯éå»25幎éã«äœæãããBashã®ãã¹ãŠã®ããŒãžã§ã³ã«ååšããŸãã ãã®ãããçè«çã«ã¯ããããŸã§ãã£ãšãç¥èã®ãã人ã ãããã䜿çšã§ããŸããã
ããã€ã¹ã¯å±éºã«ãããããŠããŸããïŒ
Bashã䜿çšããå¯èœæ§ã®ããå€ãã®ããã€ã¹ãããããã質åã¯èå³æ·±ããã®ã§ãã ãã©ã°ãããã¢ãã㯠ã é»çã«è³ããŸã§ãããããå°ããªãã®ã®IPã¢ãã¬ã¹ã®å²ãåœãŠãæ®åãã€ã€ãããšããç§ã¯ãã¢ãã®ã€ã³ã¿ãŒããããïŒIoTïŒãæå³ããŸãã å€ãã®ãã€ã³ã¿ãŒãããé¢é£ãã§ã¯ãçµã¿èŸŒã¿ã®LinuxããŒãžã§ã³ãšBashã䜿çšããŠããŸãã åãããã€ã¹ããã§ã«æ·±å»ãªã»ãã¥ãªãã£ããŒã«ã瀺ããŠããŸããããšãã°ã LIFXé»çããWi-Fièå¥ããŒã¿ãååŸã§ããŸã ã ãã®ãããShellshockã®ãããªè匱æ§ããªããŠããããããçš®é¡ã®ããã€ã¹ãšãªããžã§ã¯ãããããã¯ãŒã¯ã«æ¥ç¶ããããšã§ã以åã¯çµ¶å¯Ÿã«å®å šã§ãã£ãé åã§å€ãã®æ°ããè匱æ§ãçºçããç¶æ³ã«ãªããŸãããããã¯ç§ãã¡ã«å€ãã®æ°ãã課é¡ãæ瀺ããŸãã ããšãã°ãé»çã«å®æçã«ãããã貌ãããšãèããŠãã人ã¯ããŸããïŒ ãã®ãããªããã€ã¹ã®ãèä¹ æ§ããèãããšã誰ãããã¡ãŒã ãŠã§ã¢ã®ãµããŒãã«åŸäºããããšã¯ãŸããããŸããã æ°å¹Žåã«èµ·ãã£ãTrendnetã«ã¡ã©ã®è©±ãæãåºããŠãã ããã ééããªããèšå€§ãªæ°ã®ãœãããŠã§ã¢ããŸã ãããã¯ãŒã¯ã«æ¥ç¶ããããŸãŸã«ãªã£ãŠããŸãããœãããŠã§ã¢ãæŽæ°ãããšãã芳ç¹ããããã°ã眮ãå¿ããæ¹ãã¯ããã«ç°¡åã ããã§ãã ææè ãèªåãæ®åœ±ãããŠããããšããç¥ããªãå Žåããã®ãããªã«ã¡ã©ããã®åçã®å ¬éã«å®å šã«å°å¿µããTwitterã¢ã«ãŠã³ãããããŸãã ããã¯å€§ããªåé¡ã§ããåšèŸºæ©åšã®ãœãããŠã§ã¢ãæŽæ°ããã®ã¯é£ããå Žåãå€ããããæéã®çµéãšãšãã«ãããããçš®é¡ã®è匱æ§ãæã€ããå€ãã®æ©åšããªããžã§ã¯ãã«åãå²ãŸããŸãã
ããããBashã€ã³ã¿ãŒããªã¿ãŒã¯ãããŒã ã«ãŒã¿ãŒãªã©ã®å€ãã®äœ¿ãæ £ããããã€ã¹ã«ãæ¢ã«ååšããŠããŸãã æåŸã«ãã¡ãŒã ãŠã§ã¢ãæŽæ°ããã®ã¯ãã€ã§ããïŒ ãã¡ããããã®ããã¹ããèªãã°ããããããã®ãããªããšãå®æçã«è¡ã£ãŠãã人ã®äžäººã§ãããã ããããäžè¬ãŠãŒã¶ãŒã¯ããã«ã€ããŠãèããŠããŸããã
ãã€ã¯ããœããã®ãœãããŠã§ã¢ã§ãã¹ãŠãæ©èœããŸããå¿é ããå¿ èŠããããŸããïŒ
çãçãã¯ããŒãé·ãçãã¯ã€ãšã¹ã§ãã Bash for Windowsã®ããŒãžã§ã³ãååšãããšããäºå®ã«ããããããããã®ãŠãŒãã£ãªãã£ã¯ãã®ãšã³ã·ã¹ãã ã§ã¯æ®åããŠããŸããã Shellshockã®WindowsããŒãžã§ã³ã®Bashãè匱ãã©ãããäžæã§ãããã ããWindowsç°å¢ã®ã¿ã§äœæ¥ããŠãããšããäºå®ã¯ããããã¯ãŒã¯äžã®ç¹å®ã®ã¿ã¹ã¯ãåŠçãããã·ã³ã§Bashãå©çšã§ããªãããšãæå³ãããã®ã§ã¯ãããŸããã 説æåçãšããŠã Nick Craverã®æçš¿ããã€ã©ã¹ããæããããšæããŸãã
ã芧ã®ãšããããã©ãã£ãã¯ã¯Windowsç°å¢ããWindows以å€ã®ããã€ã¹ãçµç±ããŠæµããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã«å¯Ÿããæš©éãæã€ã³ã³ããŒãã³ãããããŸãããããã¯Shellshockã䜿çšããŠå®è¡ã§ããŸããïŒ
ç§ã¯ã·ã¹ãã 管çè ã§ãããäœãã§ããŸããïŒ
ãŸããå±éºã«ãããããŠãããã©ãããå€æããã®ã¯éåžžã«ç°¡åã§ãã ã€ã³ã¿ããªã¿ã§ãã®ã³ãã³ããå®è¡ããã ãã§ãïŒå ã®ã³ãã³ã-çŽPkruglovãå°ãå€æŽããããšãã§ããŸããïŒïŒ env X="() { :;} ; echo busted" bash -c "echo stuff"
ãç¡å¹ãã衚瀺ãããå Žåãè匱æ§ãååšããŠããŸãã
ãã¡ãããæåã«ç©Žãéããå¿ èŠããããŸãã ãã®ãããã«ãããBashé¢æ°ã®æåŸã«ä»ã®äººã®ã³ãŒããå®è¡ããããªã¹ã¯ãå€§å¹ ã«åæžãããŸãã Red Hatãªã©ã®å€ãã®Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã®æé ã¯ãã§ã«ç»å ŽããŠããã®ã§ãã§ããã ãæ©ããããè¡ããŸãïŒå®éãã»ãšãã©ã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã®ãããã¯ãã§ã«ãªãªãŒã¹ãããŠããŸã-pkruglovã«æ³šæããŠãã ããïŒã
äŸµå ¥æ€ç¥ã·ã¹ãã ïŒIDSïŒãæŽæ°ããããã®æé ã¯ãã§ã«ç»å ŽããŠãããç¹ã«ããããã€ã³ã¹ããŒã«ããåã«é·æéã®ãã¹ããå¿ èŠãªçµç¹ã§ã¯ãããã«ããããæ¡çšããå¿ èŠããããŸãã Qualysãããã€ããŒã¯ãæ»æãç¹å®ããç¬èªã®æ¹æ³ãææ¡ããŠãããããããä»ã®å€ãã®IDSãããã€ããŒããã®åé¡ã«åãçµãã§ããŸãã
ããåçãªæ¹æ³ã«ã¯ãBashãå¥ã®ã€ã³ã¿ãŒããªã¿ãŒã«çœ®ãæãããããªã¹ã¯ã®ããã·ã¹ãã ããããã¯ããããšãå«ãŸããŸãã ã©ã¡ãã®æ¹æ³ãåºç¯å²ã«åœ±é¿ããå¯èœæ§ãããããã軜çã«äœ¿çšããªãã§ãã ããã ããããããããŸãã«Shellshockã®äž»ãªæ©èœã«ãªãå¯èœæ§ããããŸãã å®éã®ããžãã¹ã«æ·±å»ãªåœ±é¿ãäžããå¯èœæ§ã®ããå°é£ãªæ±ºå®ãè¿ éã«æ¡çšããæœåšçã«ã¯ããã«å€§ããªæ害ãåé¿ããŸãã
ãã1ã€ã®è³ªåã¯ãã£ãšæ·±å»ã§ããShellshockã¯ä»¥åã«èª°ããæäœããããšããããŸããïŒ æ»æãã¯ãã«ãä¿®æ£ãããªãã£ããã©ãããå€æããããšã¯å°é£ã§ãã ãããŠãæ»æãHTTPãŸãã¯POSTãªã¯ãšã¹ããä»ããŠå®è¡ãããå Žåãããã¯ãã°ãã°èµ·ãããŸããã ãShellshockãä»ããŠæ»æãããã®ãããšå°ããããå Žåãæãäžè¬çãªçãã¯æ¬¡ã®ãšããã§ãããã®è匱æ§ãéãããšãã蚌æ ã¯ãããŸããã ããã«ãããWebãµã€ããä»ã®ã·ã¹ãã ã®ææè ã¯ããããã䟵害ããããã©ããã«ã€ããŠäžæå¿«ãªç念ãæ±ãããã«ãªããŸãã
ç§ã¯ãŠãŒã¶ãŒã§ãããäœãã§ããŸããïŒ
ç¹å®ã®ç¶æ³ã«äŸåããŸãã Mac OS Xã䜿çšããŠããå Žåããã®è匱æ§ã¯æšæºã®æŽæ°ã¡ã«ããºã ã䜿çšããŠç°¡åã«ïŒã§ããã°ããã«ïŒçµäºããŸãã ããªããå±éºã«ãããããŠãããã©ããããã¹ãããããšã¯ç°¡åã§ãïŒããã¯åçŽãªãã¹ãã§ãããå¹³åçãªMacãŠãŒã¶ãŒã¯ç°¡åã«ã¢ããã€ã¹ã«åŸã£ãŠBashãåã³ã³ãã€ã«ã§ãããšã¯æããŸããã
ããå¿é ãªã®ã¯ãã«ãŒã¿ãŒãªã©ããœãããŠã§ã¢ã®æŽæ°ãé£ããããã€ã¹ã§ãã ãã®åé¡ã¯ãã«ãŒã¿ãŒããããã€ããŒã«ãã£ãŠã¬ã³ã¿ã«ãããããšãå€ãããŠãŒã¶ãŒãã³ã³ãããŒã«ããã«ã«ã¢ã¯ã»ã¹ã§ããªããšããäºå®ã«ãã£ãŠæªåããŸãã ããã«èšå€§ãªæ°ã®ã¢ãã«ãæããŸãã åæã«ãã«ãŒã¿ãŒã®ãã©ãã·ã¥ãå¹³åçãªãŠãŒã¶ãŒã®éåžžã®ã¿ã¹ã¯ã®ãªã¹ãã«å«ãŸããŠããŸããã
èŠããã«ããŠãŒã¶ãŒåãã®ãã³ãã¯æ¬¡ã®ãšããã§ããã»ãã¥ãªãã£æŽæ°ããã°ã©ã ãã€ã³ã¹ããŒã«ãããã¡ãŒã ãŠã§ã¢ã§äœ¿çšããæ©åšã®ãããã€ããŒããã³ãµãã©ã€ã€ãŒã®ã¢ããã€ã¹ãç¡èŠããªãã§ãã ããã ãã®ãããªã¡ãã»ãŒãžã¯ãå€ãã®å Žåãããã¡ãã·ã§ããã«ãªããŠãŒã¶ãŒã®ææãæªçšãããã£ãã·ã³ã°æ»æäžã«å±ããæ å ±ãæ±ããã¡ãŒã«ããœãããŠã§ã¢ã®èµ·åæ¹æ³ã«é¢ããæ瀺ãäžããã¡ãŒã«ã«æ³šæããŠãã ããã
ãŸãšã
ã©ããããç§ãã¡ã¯ãã®è匱æ§ã®æ·±ãã«ã€ããŠã®ç 究ã®ãŸãã«å§ãŸãã«éããŸããã ãã¡ãããå€ãã®é¡äŒŒç¹ãHeartbleedã§æãããããã€ãã®ç¹ã§ç§ãã¡ãå©ããŸããã Heartbleedã®äŸã䜿çšãããšãç¶æ³ãéåžžã«æ¥éã«æªåããå¯èœæ§ãããããšãããã£ãŠãããçµæãéåžžã«é·ãéããéããŠããŸãããããããã®å Žåããã¹ãŠãHeartbleedãããã¯ããã«æªãå¯èœæ§ããããŸãã ãã®è匱æ§ã«ãããææãããã·ã³ã®ã¡ã¢ãªå ã®å°éã®ããŒã¿ãžã®ãªã¢ãŒãã¢ã¯ã»ã¹ãèš±å¯ãããå ŽåãShellshockã¯ä»»æã®ã³ãŒããæ¿å ¥ããããšãå¯èœã«ããŸããããã¯æœåšçã«ã¯ããã«å±éºã§ãã ãã®ç¹ã§ãç§ã¯ãããŒãã«åæããŸãã
1æ¥ã2æ¥çµã€ãšæããŸããããããã¯åãªãè±ã§ããããšãããããŸãã
UPDã ç¶ç¶äž-bash www.linux.org.ru/news/security/10892232ã§æ°ããè匱æ§ãçºèŠãããŸãã
è匱æ§ããã§ãã¯ããããã®æ±çšã¹ã¯ãªããgithub.com/hannob/bashcheck