äœæ¥çšèªã§ã¯ã確ç«ãããè±èªè¡šçŸãè
åšã®é¢šæ¯ãã1ã€ãããŸãã éåžžããã·ã¢èªã«ç¿»èš³ãããŠããŸããïŒè
åšã®é¢šæ¯ã§ãïŒã ãã¹ãŠãéåžžã«ç°¡çŽ åãããŠããå Žåãããã¯ãäŒæ¥ãéžæãè¡ãçš®é¡ã«åºã¥ãããã®ã§ããéãè¿œå 賌å
¥ããããæ¢åã®ã€ã³ãã©ã¹ãã©ã¯ãã£ãä¿è·ããããã«ãéã䜿ããã§ãã ããã§ã®äŸåã¯çŽæ¥çãªãã®ã§ããåè»ã絶ããã¬ãŒã«ããå€ããŠããå Žåãããã¯æ°ããæ©é¢è»ã®è³Œå
¥ã«ãã£ãŠæ±ºå®ãããŸããã
ããŸããŸãªæ¹æ³ã§ãææ³ã®è¯ããã®ããæ²èŠ³çãªãã®ãŸã§ã®ã¹ã±ãŒã«ã§æ¯èŠ³ãè©äŸ¡ããããšãã§ããŸãïŒç¹°ãè¿ããŸãïŒã ããšãã°ãã»ãã¥ãªãã£ã®å°é家ã«ããããŒãžã§ã³ã¯æ¬¡ã®ãšããã§ãã2014幎ã®çµæã 2015幎ã®äºæž¬ ã æ°åã®ãã¡ã³ã®å Žåã¯ã æ°åã§ãã äŒæ¥èªäœã¯ã©ãæããŸããïŒ ç§ãã¡ã¯å®æçã«ããã«ã€ããŠåœŒãã«å°ããŸãïŒè©³çŽ°ã¯ãã¡ã ïŒããä»å¹Žã¯å¥ã®éæšæºã®æ¹æ³ã䜿çšããããšã«ããŸããã
ITã»ãã¥ãªãã£ã®åéã«ããããã¹ãŠã®éèŠãªãã¥ãŒã¹ã远跡ããããã Threatpost Webãµã€ãã®ç·šéå§å¡äŒã«åå ããŠããŸãã é¢é£ããèšäºã®äººæ°ãšããåäžã®åºæºã«åŸã£ãŠãçºä¿¡å¹Žã®10ã®ã€ãã³ãïŒ è±èªçã®ãµã€ãããŒãžã§ã³ïŒãéžæããããšã«ããŸããã ãŸããITæ
åœè
ãçŸåšããã³å°æ¥ã®é¡§å®¢ãã»ãã¥ãªãã£ã«é¢é£ããèå³æ·±ããã¥ãŒã¹ãåãåããŸããã æ¿æ²»ïŒã€ãŸããã¹ããŒãã³ãšNSAã«ã€ããŠã®è©±ïŒã¯ãŸã£ãããªããæŠç¥èšç»ã®ããªãã®æ°ã®ãããã¯ããããŸãã ããããä»ãŸãã«ãã®ç¶æ³ãè©äŸ¡ããéã«èæ
®ããå¿
èŠãããåé¡ãåé¢ã«åºãŠããŸããã 詳现-ã«ããã®äžã
10äœã TrueCryptïŒ5æã®å€§å€±æã®åŸã®æåã®ïŒæ¡ä»¶ä»ãïŒæ€èšŒæžã¿é
åž
ãã¥ãŒã¹ ã ãã©ãã¯è©³çŽ°ã«ãããŸãã
ããããªããšããããŸãã TrueCryptã¯å®å
šã§ã¯ãããŸããããçç±ã説æããŸããã Windowsã§æšæºæå·åã䜿çšããŸãã ãããŠç§ãã¡ã¯å¥ããåããŸããã ç¡æã®è§£éã§ã¯ã人æ°ã®ããTrueCryptæå·åã·ã¹ãã ã®éçºè
ã®Webãµã€ãäžã®ã¡ãã»ãŒãžã¯ããã®ããã«èãããŸããïŒãããŠããŸã ããã«ãã³ã°ããŠããŸãïŒã ã»ãã¥ãªãã£ã·ã¹ãã ãéžæãããšïŒææãç¡æããæå·åããŠã€ã«ã¹å¯Ÿçãã¯é¢ä¿ãããŸããïŒãç¹å®ã®ã»ãã¥ãªãã£ã¢ãããŒãã®æå¹æ§ã«é¢ããå©äŸ¿æ§ãæ©èœãããã³åŒæ°ãè©äŸ¡ããŸãã ããããæåã«ã圌女ãä¿¡é Œããå¿
èŠããããŸããã³ãŒããå人çã«ç£æ»ããã«ã¯é«ãããã®ã§ïŒå©çšå¯èœã§ãã£ãŠãïŒã
TrueCryptã®å Žåãç§ãã¡ã¯éåžžã«å¹æçã§ã·ã³ãã«ã§ç¡æã®æå·åããŒã«ãæ±ã£ãŠããŸãããããã¯åæã«å¿åã®èè
ã°ã«ãŒãã«ãã£ãŠéçºãããŸããã æ£ç¢ºã«äœãèµ·ãã£ãã®ãã¯ãŸã æ確ã§ã¯ãããŸãããäžæ²»ã®ãã°ãå®éã«çºèŠãããããåœå±ãåºãéããããšãæšå¥šããããåã«ã³ãŒãã£ã³ã°ã«ããããããŸããã ãããžã§ã¯ãã®ééãã6ãæ以äžãçµéããŸããããã©ãããå®å
šãªçå®ãèŠã€ããããšã¯ã§ããŸããã
ãã¹ãŠã®æã¿ã¯ã Open Crypto Audit Projectã®éåçãªã€ãã·ã¢ããã®ã¿ã§ããTrueCryptã«é¢é£ããç®çã¯ããŸãã«ã³ãŒãç£æ»ã§ãïŒã ãã§ã¯ãããŸããïŒã 6ææ«ã«ãæ€èšŒæžã¿ã®TrueCryptããŒãžã§ã³7.1aãã£ã¹ããªãã¥ãŒã·ã§ã³ãGitHubã«æçš¿ãããŸããã ããã¯ãç©ŽãèŠã€ãããããã¹ãŠãæ£åžžã§ããããšãæå³ããŸããïŒ ããããããããã¯ãŸã é·ãéã®ãã§ãã ãããŸã§ã®ãšããããã®ããŒãžã§ã³ã®ãœãŒã¹ãšãã«ããããã®ããŒãžã§ã³ã®ãœãŒã¹ãšãã«ãã§ããããšã確èªããŠããŸãã ããŒãžã§ã³7.1aã³ãŒãã¯ãç£æ»ã®æåã®éšåã§èª¿æ»ãããŸããïŒçµæã¯4æã«å
¬éãããŸããïŒã ããšãã°ã ãã¡ãã§ãã©ããŒã§ããã¢ããããŒãããåŸ
ã¡ããŠããŸãã
9äœã UltraDNSã«å¯ŸããDDoSæ»æ
ãã¥ãŒã¹ ã
DNS Amplificationã¡ãœããã䜿çšããæ倧100ã®ã¬ããã/ç§ã®å®¹éãæã€UltraDNSãµãŒãã¹ã«å¯Ÿãã4æã®æ»æã«ãããæ°æéã«ããã£ãŠäŒç€Ÿã®é¡§å®¢ïŒForbesãã¬ãžã³ã®Webãµã€ããªã©ïŒãã¢ã¯ã»ã¹ã§ããªããªããŸããã ç¹ã«ä»å¹Žã®ãã®ä»ã®DDoSæ»æãšæ¯èŒãããšãç¹å¥ãªãã®ã§ã¯ãªãããã§ããæ倧400 Gb / sã®å®¹éïŒæ¢ã«NTPãããã³ã«ã®è匱æ§ã䜿çšããŠããŸãïŒã åé¡ã¯ããã®ãããªæ»æãæšæºã«ãªã£ãŠããããšã§ãã åäžã®ã¿ãŒã²ãããçãããšãããæãè€éãªæ»æïŒããšãã°ãææ°ã®Reginãã£ã³ããŒã³ã¬ããŒã ã27人ã®è¢«å®³è
ãåç
§ïŒãšã¯ç°ãªããDDoSã¯æ®éçãªåé¡ã§ãã ããŒã¿ã«ãããšãå°ãªããšã18ïŒ
ã®äŒæ¥ããã§ã«DDoSã«ééããŠããŸãã ãŸããããšãã°ãã¹ãã ïŒåé¡çªå·1ïŒãéæ¥çãªæ害ãåŒãèµ·ããå ŽåãWebãµã€ããžã®ã¢ã¯ã»ã¹äžèœã«ããæ倱ã¯çŽæ¥çã§ããã販売ã®æ倱ãšè©å€ã®æ倱ã«åæ ãããŸãã ä»å¹Žã®ãã¬ã³ãã¯ãåºæ¬çãªãããã¯ãŒã¯ãããã³ã«ã«ç©Žãéããã ãã§ãªããDDoSãšAKAã«å¯Ÿããæšçåæ»æãçµã¿åãããŠè²¡åžãã¹ã¿ã³ãããŠçããè©ã䜿ã£ãæ»æã®ã¿ã§ããã ä»æ¥ã¯ãã®ãããã¯ã«æ»ããŸãã
ãããã¯ïŒLinuxçšã® DDoSããã€ã®æšéŠ¬ã®è©³çŽ°ãªèª¬æ ã
Dark Hotelã®æšçåæ»æã¯ãåºåŒµäžã«åŸæ¥å¡ããããŒã¿ãçãããã®éèŠãªæ¹æ³ã§ãã
8äœã iOS 7.1.1ã®ããã¯ãã€ãã¹
ãã¥ãŒã¹ ã
iOS 7.1.1ã®4æã®æŽæ°ãšMac OS Xã®ãããã¯ãå®éã«ã¯Appleã®SSLãããã³ã«ã®å®è£
ã«é倧ãªç©ŽãéããŸããïŒãã ãã ããã¯ããã§ã¯ãããŸããïŒã ããããããšã§ãããå€ããã°ã¯æ°ãããã®ã«çœ®ãæããããŸããããã®ãã¡ã®1ã€ã¯ãApple iPhone 5 / 5sã®ãããã¯ã·ã¹ãã ãéšåçã«åé¿ããã¢ãã¬ã¹åž³ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸããã ãã®ãããªãããã³ã°ã®åŸæ¥ã®ã¹ããŒã ã§ã¯ããããŸããŸãªãã¿ã³ããã°ããæŒããŠç»é¢äžãããŸããŸã«çªããããšã¯ä»åãé³å£°ã¢ã·ã¹ã¿ã³ãSiriã§ãã£ãããšã¯æ³šç®ã«å€ããŸãã
誰ããç¥ã£ãŠããããã«ãAppleã«é¢ãããã¥ãŒã¹ã¯åŒ·åãªãã©ãã£ãã¯ãžã§ãã¬ãŒã¿ãŒã§ãããããAppleããã€ã¹ã®ç©Žã¯åã«è©äŸ¡ã«å
¥ããå¿
èŠããããŸããã UltraDNSã®å Žåã®ããã«ãè匱æ§èªäœã¯ææšã§ã¯ãããŸããããæ¥çã®ã¢ãã€ã«ããã€ã¹ãžã®æ³šç®ïŒäŒæ¥ã¯ãã¢ãã€ã«ããã€ã¹ãè
åšãšèŠãªããŠããŸããããããè·å Žã§ã¹ããŒããã©ã³ã®äœ¿çšããçŠæ¢ãããããšã¯äžå¯èœã ãšç解ããŠããŸãã
ããŒã¿ã«ãããšãäŒæ¥ã®22ïŒ
ã§æºåž¯é»è©±ã®çé£ãçŽå€±ã«é¢é£ããã»ãã¥ãªãã£ã®åé¡ã«æ¢ã«çŽé¢ããŠããŸãã ãã®ãããªç°å¢ã§ã®ã»ãã¥ãªãã£ãã€ãã¹ã¯åé¡ã§ãã ç¹ã«ãäŒæ¥ã®ã¹ããŒããã©ã³ãå®éã«ä¿è·ãããŠããªãå Žåã ãŸãã¯ãä¿è·ã·ã¹ãã ãæ©èœããªãã£ãå Žåã åãããŒãžã§ã³ã®iOSã§ããã¯ããã€ãã¹ããããšã«å ããŠãå¥ã®åé¡ãçºèŠãããŸãããã¡ãŒã«ã®æå·åã¯æ·»ä»ãã¡ã€ã«ã«é©çšãããŸããã§ããã é»è©±ã®ãã¡ã€ã«ã·ã¹ãã ãžã®ã¢ã¯ã»ã¹ã¯ãæ·»ä»ãã¡ã€ã«ãžã®ã¢ã¯ã»ã¹ãæäŸããŸããããããã¯äœããã®åœ¢ã§ééã£ãŠããŸãã
Epic Turla-ç°ãªãAPTéã®è€éãªé¢ä¿ã®3æã®ç 究 ã
7äœã å£ããããã€ã³ã¿ãŒããããããã«å¿ããŠåäœ
ãã¥ãŒã¹ ã
2ã€ã®ãã¥ãŒãžãã¯ãããªã®å©ããåããŠãã€ã³ã¿ãŒãããäžã§ã»ãã¥ãªãã£ã®ç¶æ
ãéèšèªçã«äŒããããã«æ±ããããå Žåã¯ããã®ããã«ããŸãïŒã³ã¡ã³ãã§Wellcomeã®ãªãã·ã§ã³ãéžæããŸããé³æ¥œãšã¢ãœã·ãšãŒã·ã§ã³ã«ã€ããŠã説æããŸãïŒã
æãŸããç¶æ³ïŒ
å®éã®ç¶æ³ïŒ
å£é ã§èšããšãã€ã³ã¿ãŒãããã»ãã¥ãªãã£ã®çŸç¶ã¯ãä»å¹Ž2æã«ç§ãã¡ã®å°é家ããŒã ã§ããKostin Raiuã®é·ã«ããè¡šæãããŸãããã€ã³ã¿ãŒãããã¯å£ããŠããŸãã ããã¯åŠæ³ã§ã¯ãªããFUDã§ã¯ãªããåºåã§ããããŸããã ã©ããèŠãŠãã倧èŠæš¡ã§æ±ãã«ããåé¡ãè³ãæã§èŠãããŸããéèŠãªãããã¯ãŒã¯ãããã³ã«ãæå·åãã¡ãŒã«ããŠã§ãããããŠãã¹ãŠã®ãã®ã§ãã
ã©ããã ã¿ã€ãã©ã€ã¿ãŒããã®ä»ã®ãµã€ããŒãã³ã¯ã«æ»ã£ãŠãå©ãã«ã¯ãªããŸããããŸãã§èªåè»ããŒã ã®ofææã«éŠ¬ãåŒãçœåŒåã«è³ãããããªãã®ã§ãã ãã®äºå®ãèæ
®ããããã«å¿ããŠé²è¡æŠç¥ãæ§ç¯ããå¿
èŠããããŸãã ãããã¯éããŠããŸããããéãã骚æã§ãïŒã ãã®æ²ããäºå®ãèæ
®ããŠã詳现ã«æ»ããŸãã
6äœã æªæã®ããTorããŒã
ãã¥ãŒã¹ ã
ãã®å Žåã®ã»ãã¥ãªãã£ã·ã¹ãã ã«ãããä¿¡é Œã®ãããã¯ã«é¢ãããã1ã€ã®èå³æ·±ã話ã¯ãå¿åããŒã«ã§ãã 10ææ«ã«ãç 究è
ã®Josh PittsãTorãããã¯ãŒã¯ã®åºåããŒããçºèŠããŸãããããã«ããããŠãŒã¶ãŒãããŠã³ããŒãããå®è¡å¯èœãã¡ã€ã«ã«æªæã®ããã³ãŒãããªã³ã¶ãã©ã€ã§è¿œå ãããŸããã ãã·ã¢ã«ããããŒãã¯ããããã¯ãŒã¯ç®¡çã«ãã£ãŠããã«ãããã¯ãããŸããã ãã®ãããªãããã³ã°ããä¿è·ããæ¹æ³ã¯æããã§ãã誰ãä¿¡çšããªãã§ãã ããã ããå
·äœçã«ã¯ãæå·åã®å¥ã®ã¬ã€ã€ãŒã¯æ±ºããŠçãããšã¯ãããŸããã HTTPSãã©ãã£ãã¯ã¯ãåœç¶ãã®ããã¯ã®åœ±é¿ãåããŸããã§ããã
ã¯ãã¹ãã©ãããã©ãŒã ïŒWindowsãMax OS XãLinuxãiOSïŒ Mask / Caretoã¹ãã€ãŠã§ã¢ãã£ã³ããŒã³ã
5äœã DDoS +æšçåæ»æã ã³ãŒãã¹ããŒã¹ãã¹ããã·ã¥
ãã¥ãŒã¹ ã
7000äžäººã®é¡§å®¢ããã®ããŒã¿ãã¢ã¡ãªã«ã®å°å£²æ¥è
ã§ããTargetããçãŸãããšããããã¯äžå¿«ã§ããããåºèãšååã¯ãã®ãŸãŸã§ããã ããžãã¹ã100ïŒ
ãããã¯ãŒã¯åãããŠããå Žåãæšçåæ»æã¯äžæ©ã§å®å
šã«ç Žå£ããå¯èœæ§ããããŸãã ããã¯ãç¬èªã®å
±åéçºããã³ããŒãžã§ã³è¿œè·¡ã·ã¹ãã ã販売ããCode Spacesã§ä»å¹Ž6æã«èµ·ãã£ãããšãšãŸã£ããåãã§ãã
å瀟ã®ãµãŒããŒã«å¯Ÿããæåã®DDoSæ»æã«ç¶ããŠAmazon EC2ã³ã³ãããŒã«ããã«ããããã³ã°ããããµãŒãã¹ã®äœæè
ãééã匷èŠãå§ããŸããã ã¢ã¯ã»ã¹ãåãæ»ãè©Šã¿ã¯å€±æããŸãããã¯ã©ãã«ãŒã¯å¶åŸ¡ãåãæ»ããã»ãšãã©ãã¹ãŠã®ããŒã¿ãåé€ããŸããã 12æé以å
ã«ãäŒç€Ÿã¯ç Žå£ãããŸãããããŒã¿ã埩å
ããæ倱ãå埩ããããšããããŠæãéèŠãªããš-è©å€ãå埩ããããšã¯äžå¯èœã§ããã
ã³ãŒãã¹ããŒã¹ã®å€ãããŒãžã§ã³ã§ã¯ãããŒã¿ããã¯ã¢ããã®ä¿¡é Œæ§ã«ç¹å¥ãªæ³šæãæãããŠããŸããã ãåçŽãªããã¯ã¢ããã¯ãé害ããã®å埩ã®ããã®æ確ãªèšç»ããªããã°æå³ããããŸãããå®éã«ãã¹ãããç¹°ãè¿ãæ©èœããããšãå®èšŒãããŠããŸããã é»éã®èšèïŒ
4äœã ããã¡
ãã¥ãŒã¹ ã
ãã«ãŠã§ã¢ã ãã§ãªããè匱æ§ãç¹å®ã®æ»æã·ããªãªã®ããã«éæšæºã®ååãèŠã€ããããšã¯ãä»å¹Žã®ITã»ãã¥ãªãã£ã§æµè¡ã®åŸåã«ãªããŸããã ãã®å ŽåãPOODLEã¯ãããŠã³ã°ã¬ãŒããããã¬ã¬ã·ãŒæå·åã®ããã£ã³ã°Oracleã®ç¥ã§ãã æ»æã®æ¬è³ªïŒã¯ã©ã€ã¢ã³ããšãµãŒããŒã«åŒ·å¶çã«ã»ãã¥ã¢ãªæ¥ç¶ã確ç«ããã»ãã¥ã¢ãªãããã³ã«ïŒTLSïŒããã»ãã¥ã¢ã§ãªãæ§åŒïŒSSL 3.0ãä»å¹Žã®å°æ¥ãåããïŒã«ããŠã³ã°ã¬ãŒãããããšã ãã®çµæãç¹å®ã®æ¡ä»¶äžã§ãå®å
šãªãã©ãã£ãã¯ãååããããšãã°Cookieãçãã§ããã»ãã·ã§ã³ãååããããšãå¯èœã«ãªããŸãã æ»æã®æ¡ä»¶ã¯éåžžã«éå®çã§ãããããæªçšã®å®éã®äºäŸã¯èšé²ãããŠããŸããã ãã ãã10æäžã«ãäž»èŠãªãã©ãŠã¶ãŒã®éçºè
ã¯SSLv3ãå®å
šã«ç¡å¹ã«ããããšã§ã¢ããããŒãããªãªãŒã¹ããåé¡ã解決ããŸããã 2014幎ã®ãã¹ãŠã®äžå¿«ãªãã¥ãŒã¹ã®äžã§ãããã¯æãããžãã£ãã«èŠããŸãã圌ãã¯ç©ŽãèŠã€ããããã«ç©ŽãéããŸããã
3äœã ã·ã§ã«ã·ã§ãã¯
ãã¥ãŒã¹ ã èæ¯ ã€ãã³ãã®éçº ã ãããã質å
$ env 'x =ïŒïŒ{ïŒ;}; ãšã³ãŒã®èåŒ±æ§ '' BASH_FUNC_xïŒïŒ=ïŒïŒ{ïŒ;}; ãšã³ãŒã®èåŒ±æ§ 'bash -c "ãšã³ãŒãã¹ã"
ã¯ãªãšã€ãã£ãããŒãã³ã°ã®ãã1ã€ã®ç ç²è
ïŒãã ããShellshockã¯CVE-2014-6271ããããããããããã«èãããŸãïŒãä»å-UnixããŒã¹ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãŠãããŒãµã«ã³ãã³ãã·ã§ã«ã®é倧ãªãã°ã§ãã OpenSSLã®ãã°ã«ç¶ã2çªç®ã®ã±ãŒã¹ã¯ããã©ã®ã·ã¹ãã ããããããŠãããããšãã質åã«ãã¯ãããã¹ãŠããšçããããšãã§ããå®éã«ã¯ããŸãåãã€ããŠããªãå Žåã§ãã Shellshockã¯ç©æ¥µçã«æªçšãããè匱ãªã·ã¹ãã ã®æ€çŽ¢ã¯å®å
šã«æ¡åŒµããã圱é¿ãåãããµãŒããŒã®ç®¡çè
ã¯åã³ããã¹ãŠãä¿®æ£ããäœãå£ããªãæ¹æ³ããšããã²ãŒã ããã¬ã€ããæ©äŒãåŸãŸããã
ShellshockãšHeartbleedã®æŽå²ã«ç¶ããŠãç§ãã¡ã¯ã客æ§ããå€ãã®ãã£ãŒãããã¯ãåãåããŸãããç¹ã«ããã®ãããªè匱æ§ã§äžå°äŒæ¥ãçµéšããå°é£ã«æ³šç®ããããšæããŸããã 倧äŒæ¥ãè匱ãªããŒããæ€çŽ¢ããŠæŽæ°ããããã®æ³šç®ãã¹ããªãœãŒã¹ãå²ãåœãŠãå Žåãå°èŠæš¡äŒæ¥ã§ã¯å€ãã®å Žåã1人ã®ITã¹ãã·ã£ãªã¹ãããã¹ãŠã«çããããç¶æ
ã«ã管çè
ããããŸããã ãããã£ãŠããã®ãããªäŒæ¥ã®ææè
ãå°ããå
žåçãªè³ªåã¯ããbashbugïŒheartbleedãªã©ïŒãç§ã®ããžãã¹ãã©ãã ãè
ããããã§ãã
ããã¯å®éã«ã¯éèŠãªè³ªåã§ãã é·ãéèšå®ããŠãããªãã£ã¹ã¡ãŒã«ãµãŒããŒã¯åäœããŸããïŒ ãã¡ã€ã«ãµãŒã㌠ãµãŒãããŒãã£äŒæ¥ããã¬ã³ã¿ã«ããã¯ã©ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ã¯ã©ãã§ããïŒ ãããã¯ãŒã¯ã«ãŒã¿ãŒ ä»ã«äœïŒ ãããããã³ããŒã«ãã£ãŠãªãªãŒã¹ãããããããå®éã«ç©Žãå¡ããªãããšãçªç¶å€æããå Žåã¯ã©ããªããŸããïŒ Bashã®è匱æ§ã¯ãããã·ã§ã³ã¯ãªãã£ã«ã«ãªã·ã¹ãã ã®ãªãã¬ãŒã¿ãŒã«å€ãã®åé¡ããããããŸããããã¢ããã°ã¬ãŒãããããšã¯ã§ããŸããããå察åŽã«ã¯ãçªç¶ãéå奜çã§æ··ä¹±ããå±éºãªITç°å¢ã«å¯ŸåŠããªããã°ãªããªãå°ããªäŒæ¥ãæ°å瀟ãããŸãã
2äœã ããŒãããªãŒã
ãã¥ãŒã¹ ã èæ¯ çµè«
ãã°ã説æããæéããç¡é§ã«ããŸããããšã«ããXKCDãããåªããŠããŸãã
ãããã¯ãŒã«ãªãã®-HeartbleedãŸãã¯Shellshock ãã«ã€ããŠå€ãã®è°è«ããããŸãããïŒ äžæ¹ã§ã¯ãBashã®è匱æ§ã¯ä»»æã®ã³ãŒãã®å®è¡ãæããŸãããOpenSSLã®ç©Žã¯ããŒã¿ãžã®ã¢ã¯ã»ã¹ã®ã¿ãèš±å¯ããŸãã äžæ¹ãHeartbleedã®ç©èªã¯èãã倧ããªé¢å¿ãåŒã³èµ·ãããŸããã ãããããã€ã³ãã¯ãè匱æ§ã«é¢ããããŒã¿ã®å
¬éæç¹ã§ã®çµ¶å¯Ÿçãªäžç¢ºå®æ§ã§ãã 誰ã圱é¿ãåããŸããïŒ ãããã³ã°ãããã®ã¯èª°ã§ããïŒ ããŒã¿ãšã©ã®ããŒã¿ãçãããšãã§ããŸããïŒ è¢«å®³è
ã¯èª°ã§ãã-ã€ããŒããªã³ã©ã€ã³ãã³ãã³ã°ã§ã®ã¡ãŒã«ã§ããïŒ ããŠããµãŒããŒã«ããããé©çšããŸããããè«è² æ¥è
ã¯ãããè¡ããŸãããïŒ ããŒãããŒïŒ ããŒã¿ãä¿¡é Œã§ããŸããïŒ ç§ã¯ã€ã³ã¿ãŒããããå£ããŠãããšèšã£ãããã§ããïŒ :)
1äœã PNG圢åŒã®ç»åã¡ã¿ããŒã¿å
ã®æªæã®ããã³ãŒãã®é èœã
ãã¥ãŒã¹ ã Redditã«ã€ããŠã®è°è« ã
ãã®...
ããã¯å®éã«èå³æ·±ãWebæ»ææ¹æ³ã§ãã ç¡å®³ãªç»åãPNG圢åŒã§èªã¿èŸŒã¿ãããããã¡ã¿ããŒã¿ãæœåºããŸãããããã«ã¯æªæã®ããã³ãŒããé ãããŠããŸãã ãã®çµæãç®ã«èŠããªãiframeã¯ãæ¢ã«æ»æãè¡ãããŠããå¥ã®ãµã€ããžã®ãªãã€ã¬ã¯ããšãšãã«ãææãããµã€ããžã®èšªåè
ã«ãªãã€ã¬ã¯ããããŸãã èå³æ·±ãããšã«ãæªæã®ããã³ãŒããé£èªåãããã1ã€ã®æ¹æ³ã¯ãã©ããããããã»ã³ã»ãŒã·ã§ã³ã«ã¯ååã§ã¯ãããŸããããããã¯éå»1幎ã§æãå€ã蚪åãããThreatpostã®è±èªçã«é¢ããèšäºã§ãã
ã©ãããŠïŒ äžã®ãªã³ã¯ã§Redditã«é¢ããè°è«ã«æè¬ããªããã°ãªããŸããã ããã«éèŠãªããšã¯ããPNG found zero dayïŒ111 AAAAAïŒããšããã¹ã¿ã€ã«ã®å
ã®ãã¥ãŒã¹ã¬ã¿ãŒã®å
ã®è§£éã§ãã åçŽãªç»åãèªã¿èŸŒãããšã§æ»æãããå¯èœæ§ã¯ãæ¬åœã«æ°ãé ããªãããã§ãã 幞ããªããšã«ãä»åã¯æ¢ã«å£ããã€ã³ã¿ãŒããããå®å
šã«ç Žãããšãã§ããŸããã§ããã
ãã®ãããä»å¹Žã®æã人æ°ã®ããã¹ããŒãªãŒã¯ããã¯ãããžãŒã«é¢ãããã®ã§ã¯ãªããèªèã«é¢ãããã®ã§ããããšãå€æããŸããã ãã®ãã¥ãŒã¹ã§èµ·ãã£ãããšã¯ãæ ç»éèªã§ãè°è«ãããŠãããœããŒãã¯ãã£ãŒãºãšã³ã¿ãŒãã€ã³ã¡ã³ãã®ããã¯ãšæ¯èŒããããšãã§ããéäžã§æè¡çãªè©³çŽ°ã¯å®å
šã«å€±ãããŸããããããã¯ãŒã¯ã»ãã¥ãªãã£å
šè¬ã«ã€ããŠèããããã«ãªããŸãã ãµã€ããŒæ»æãåºãŸã£ãŠãããããããã1人ãã ãã泚ç®ãéããªããªããç®ããŒãããŠèŠçãèœã¡ãŠããŸãã æãèå³æ·±ãã®ã¯ãSony HackãShellshockã®ãããªéåžžã«çµæ«è«çãªãã¥ãŒã¹ã§ãããã1ã€ã®ç»åã§å
šäžçã«ææãããã ãã§ãã 2014幎ã«ã¯ãããããããŸããããããã¯æªãããšã§ãã ãããã®æ³šç®åºŠã®é«ãã€ãã³ãã®çµæã«åºã¥ããŠãäŒæ¥ãéèŠãªããŒã¿ã®ä¿è·ã«é¢ãã圌ãã®èŠè§£ãåèããããšãé¡ã£ãŠããŸãã ãããŠããã¯è¯ãã§ãããã