ã¿ãªããããã«ã¡ã¯ïŒ 2014幎ã®ãã¥ãŒã¹ãã€ãžã§ã¹ããæåããåŸããã®ã³ã©ã ãå®æçã«ããŸãã¯æ¯æäœæããããšã«ããŸããã ä»æ¥ã¯1æã®æãéèŠãªæ
å ±ã»ãã¥ãªãã£ãã¥ãŒã¹ã§ãã ãã¥ãŒã¹ãéžæããæ¹æ³ãå°ãå€æŽãããŸããã ç§ãã¡ã¯ã Threatpost Webãµã€ãããæã蚪åããããã¥ãŒã¹ãåŒãç¶ãååŸãããã®ãããªæ³šç®ãéããçç±ãç解ããããšããŸãã ããããæ¯æã®ãã¥ãŒã¹ãã€ãžã§ã¹ãã«ã¯5ã€ãããŸãã Threatpostã§ã¯ãæ
å ±ã»ãã¥ãªãã£æ¥çããã®ãã¹ãŠã®ãã¥ãŒã¹ãåéããŠããŸãã ã©ãç¬èªã®ç 究ã¯ã Securelist Webãµã€ãã§å
¬éãããŠããŸãã
èŠçŽ ïŒglibcã®ç©Žãšãç©çåŠè
ãæè©ãåæé®®ã®ãã©ãŠã¶ãŒã課éããŒãã¬ãŒãšããŒããŒãããŒã«ãæå·æèšäžè¬ãç¹ã«ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã§WiFiããããã³ã°ããããšãšç©çåŠè
ãåéã§ã¯ãªãçç±ã
5. WifiphisherïŒãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®åãã¬ã€ã€ãŒã§WiFiããããã³ã°ãã
ãã¥ãŒã¹ ã Stackexchangeã®ããŒãã¹ã¬ãã ã3幎åã«åé¡ãå®åŒåãããŸããã
åã®ãã€ãžã§ã¹ãã§ã¯ãã€ã³ã¿ãŒããããå£ããŠãããšããäºå®ã«ã€ããŠè©±ããŸãã ã ãã®ãããã€ã³ã¿ãŒãããäžããŸãã¯äžè¬çã«ã³ã³ãã¥ãŒã¿ãŒãããã¯ãŒã¯å
ã§ç ŽæããŠãããã¹ãŠã®äžã§ãã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ãæãç ŽæããŠããŸãã WEPãããã³ã«ã®ç¥èãªã·ã³ãã«ããäžè²«ããŠçµéšããä¿è·ãããŠããªãå
¬è¡ç¡ç·ãããã¯ãŒã¯ãæªãããšãç¹°ãè¿ã確信ããŠããã®ã§ ãWPSãšåŒã°ããåºãªãã®ã»ãã¥ãªãã£ããŒã«ã調æ»ããŸããã çŸåšãã«ãŒã¿ãŒã®ãã¡ãŒã ãŠã§ã¢ã§ãã°ã®æŽ¥æ³¢ãçºçããŠããŸãããã¡ãŒã ãŠã§ã¢ã§ããã©ã«ãã®ãã¹ã¯ãŒãïŒãŸãã¯åæ§ã®ããŒã« ïŒãèŠã€ãã次ã«æ²ãã£ã NATãªã©ãèŠã€ããŸãã ã€ãŸããããã§ã¯ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã ããæ¬ ããŠããŸããã
ååã§ã¯ãããŸãã-å
¥æããŠãã ããã ãã¹ãŠãéåžžã«åçŽã§ãã被害è
ã®åä¿¡ãšãªã¢ã«ãŸã£ããåãSSIDã§ã¢ã¯ã»ã¹ãã€ã³ããäœæããã ãã§ãã 被害è
ãæ¥ç¶ããããšãããšã被害è
ã«ãã®å®éã®ã¢ã¯ã»ã¹ãã€ã³ãã®ãã¹ã¯ãŒããèŠæ±ããæ
éã«ä¿åããŸãã ããã ãã§ããMITMæ»æãå®è¡ããããã®ã¢ã¯ã»ã¹ãšèœåããããŸãã ãããããã¹ãŠã§ã¯ãããŸããã ãŸãã被害è
ã®ã³ã³ãã¥ãŒã¿ãŒãŸãã¯ã¹ããŒããã©ã³ã説åŸããŠãç§ãã¡ã®ãã€ã³ãã«æ¥ç¶ããŠã¿ãŠãã ããã ãããŠãèªèšŒè§£é€ãã±ããã§ãšãŒãã«ãè©°ãŸãããããšã§ãããè¡ããŸãïŒãããã¯æ£åœãªã¯ã©ã€ã¢ã³ãã®åæã«ã€ãªããããã®åŸåœã®ã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ã§ããŸãã
Stackexchange ã«é¢ããå¥ã®èª¬æã§ã¯ãåé¡ãé·ãéç¥ãããŠããããšãããã³ïŒdeauthãã±ããã®èŠ³ç¹ããïŒåé¡ãé©åã«åŠçãããŠããªããããŸã£ããåŠçãããŠããªãããšãæããã«ãªããŸããã ã§ã¯ããã¥ãŒã¹ã¯äœã§ããïŒ ãããŠãæå®ãããæ¹æ³ã§ãã¹ã¯ãŒããçãããã»ã¹ãèªååããã察å¿ããWifiphisherãŠãŒãã£ãªãã£ãGithubã«æçš¿ããããšããäºå®ã é埳æ§ïŒèª°ããŸãã¯äœããïŒã©ãã«ããŠãïŒãã¹ã¯ãŒããèŠæ±ãããšããå
¥ãåã«ããèããŠãã ããã é埳2ïŒäžéè
æ»æããé²åŸ¡ããããšã¯äžå¯èœã§ããããã®è¡çºã®å¯èœæ§ãæé€ããŸãã å°ãªããšããã®ã€ã³ã¿ãŒãããäžã§ã¯ãé€å€ããããšã¯ã§ããŸããã
ãšããã§ãããªãªããããã«ãã§ãŒã³ã¯äžåºŠã«èªèšŒè§£é€ããã±ãŒãžã«æãåºããã²ã¹ããæã¡èŸŒãã ã¯ã€ã€ã¬ã¹ã¢ã¯ã»ã¹ãã€ã³ãããããã¯ããããã«ãããã䜿çšããŸããã ãããŠã圌女ã¯ããã«ã€ããŠç±³åœã®RoskomnadzorãããŸãšããªçœ°éãåãåã£ãã
4.æå·ããã«ãŒã é ãããè
åšã¯æ確ãªè
åšãšã©ã®ããã«éããŸããïŒ
ãã¥ãŒã¹ ã ããäžã€ã®ãã¥ãŒã¹ ã çš®ãšããŠã®æå·æèšã®è©³çŽ°ãªç 究 ã
äŒæ¥ã«æãé »ç¹ã«çŽé¢ãããµã€ããŒè
åšã®çš®é¡ãã€ã³ã¿ãã¥ãŒãããšãã¹ãã ãæåã«æ¥ãå¯èœæ§ãé«ããšãã§ã«æžããŠããŸãã ããããã¹ãã ã¯ãã®ãããªãã®ã§ããããã®æ害ã¯æããã§ã¯ãããŸããã 圌ã¯ããã§ãããæ°ããã®ã¯é£ããã§ãã èšç®ãé£ããå Žåã¯ãã¹ãã ãšæŠãããã®ã³ã¹ããã©ãã»ã©åççããè©äŸ¡ããããšã容æã§ã¯ãããŸããã ããã«ãã¹ãã 察çæè¡ã¯ååã«éçºãããé
åžãããã¢ã¯ã»ã¹å¯èœã§ãã
æå·ããã«ãŒã¯ãŸã£ããå¥ã®è©±ã§ãã ã¹ãã ãšã¯ç°ãªãããããããã®æ害ãè©äŸ¡ããã®ã¯ç°¡åã§ãã ããªãã®äŒç€Ÿã¯æ»æãããéèŠãªããŒã¿ã«ãã£ãŠæå·åãããã¢ã¯ã»ã¹ã§ããªããªãã身代éãå¿
èŠã«ãªããŸãã ããªãã¯ãéã倱ã£ãŠããŸãã ããªãã¯æéãç¡é§ã«ããŠããã ããã«ã1ã€ã®ã€ã³ã·ãã³ãã§äŒç€Ÿãå®å
šã«æ®ºãå¯èœæ§ããããŸã ãäŸã次ã«ç€ºããŸã ã æå·ããã«ãŒãã身ãå®ãå¿
èŠãããããšã¯æããã§ãã
ç¯çœªã®èŠ³ç¹ããèŠããšãæå·ããã«ãŒã¯å®æãªç掻ãéã£ãŠããŸãã ããã¯ããããããã§ã¯ãããŸãããããããããã¯æåã«æ§ç¯ãã次ã«ä»ã®èª°ãã«è²©å£²ããå¿
èŠããããŸãã ãããã£ãŠãæ®å¿µãªãããæå·ããã«ãŒã¯ç©æ¥µçã«éçºãå¢æ®ãæ¡æ£ããŠããŸãã
å®éããã¥ãŒã¹ã¯äœã§ããïŒ ã¯ããç¹å¥ãªããšã¯äœããããŸãã:)æšå¹Žã®å€ãæå·æèšã®éçºã®äž»ãªåŸåã説æããŸããïŒãããŠããããã®ç 究ãç¶ããŠããŸãïŒã MicrosoftãCiscoãªã©ãã»ãšãã©ãã¹ãŠã®ã»ãã¥ãªãã£ãã³ããŒããããè¡ã£ãŠããŸãã 誰ã«ãšã£ãŠãååãªä»äºããããããããŸãã ããšãã°ãéæ³è¡çºãé ãçŸä»£ã®æè¡ã¯ãã¹ãŠãã©ã³ãµã ãŠã§ã¢ã«é¢äžããŠããŸãããããã³ã€ã³ã«ããæ¯æããTorããã³I2Pãä»ããéä¿¡ãç 究è
ããã®å€è£
ã§ãã
ããããããã¯ãã€ã³ãã§ã¯ãããŸããã æãèå³æ·±ãã®ã¯ã被害è
ã®ã³ã³ãã¥ãŒã¿ãŒã«äŸµå
¥ããããã®ãã¯ãããžãŒã§ãã 2æã®ã·ã¹ã³ã®èª¿æ»ã§ã¯ãCryptowallããªã¢ã³ãã®ããããã®äœæè
ããšã¯ã¹ããã€ããããã«è³ããŠããããšã瀺ãããŸããã ããžãã¹ã«ãšã£ãŠãããã¯ãäŒç€Ÿã®ã€ã³ãã©ã¹ãã©ã¯ãã£å
ã®åŒ±ããªã³ã¯ãè匱ãªãœãããŠã§ã¢ã§ããããšãæå³ããŸãã äžçŽã®å¹éãã§ã¯ãããŸãããããã®ãããã¯ã¯éåžžã«éèŠã§ããæå·ããã«ãŒã«é¢ããã»ãŒãã¹ãŠã®ãã¥ãŒã¹ãéåžžã«èå³æ·±ããšããäºå®ã¯ããããåã³èšŒæããŠããŸãã
3.çµã¿èŸŒã¿ã®ããŒãã¬ãŒã«ããUSBå
é»ã
ãã¥ãŒã¹ ã
ã¯ã€ã€ã¬ã¹éä¿¡ãå¶åŸ¡ããããšãããã«é£ããããšããå¥ã®è©±ã¯ãMicrosoftã¯ã€ã€ã¬ã¹ããŒããŒãã®ã»ãã¥ãªãã£ãåæããããšã決ãã3人ã®ç 究è
ã®ç 究ããå§ãŸããŸããã ãããã®ããŒããŒãã®ããŒã±ãã£ã³ã°è³æã®ã©ããã«ãããããããã€ã¹ãšUSBã¬ã·ãŒããŒéã®æ
å ±ã®æµãã¯å®å
šã«æå·åãããŠãããšæžãããŠããŸãã ã¯ãããã ããä¿¡é Œæ§ã«ã€ããŠè³ªåããããŸãã
èŠããã«ãæå·åãããæåã®ããŒã¯ããŒããŒãã®MACã¢ãã¬ã¹ã§ããããã¯ãæåã«ã¹ãã€ããã次ã«ããŒã¿è»¢éãæ
åœãããããã®æ©èœã䜿çšããŠãªã¢ãŒãã§çãããšãã§ããŸãïŒãããŠoopsãå«ãããŸããŸãªããã€ã¹ã§äœ¿çšãããŸãïŒå»çïŒã çãããšã¯ã§ããŸããããã¹ãŠã®ããŒããŒãã®MACã¢ãã¬ã¹ã®æåã®ãã€ãã¯åãã§ããããã«ãŒããã©ãŒã¹ã倧å¹
ã«ä¿é²ããŸãã
å®æçã«ããŒã¹ãããŒã¯ãååããã®ã«ååãªã»ã©ããŒããŒãã«è¿ã¥ãæ¹æ³ãç解ããããšã¯æ®ã£ãŠããŸãã ãããŠãããã§ãç 究è
ã®ãµãã»ã«ã ã«ãŒã¯ç¬èªã®æŠå¿µå®èšŒãææ¡ããŸããã ã¹ããŒããã©ã³ãšã¿ãã¬ããã®éåžžã®USBå
é»ã䜿çšããé©åã«ã¹ããããããArduinoãæ¿å
¥ãããšãé»åããã€ã®æšéŠ¬ãæã«å
¥ããŸãã ã¡ãªã¿ã«ãå
é»ãæ¥ç¶ãããŠããªããŠãæ©èœããŸããå°ããªããããªãŒãé©åããŸãã ããã€ã¹ã®ã³ã¹ãã¯ãã£ãã®10ãã«ã§ããããããïŒä»ã®ãšããïŒæŠå¿µã«éããªãã®ã¯è¯ãããšã§ãã
ãã€ã¯ããœããã¯ãã®èª¿æ»ã«ã€ããŠã¯äžåã³ã¡ã³ãããããããã åé¡ã調æ»ããŠãã ããšè¿°ã¹ãã ãããŠãåé¡ã¯èå³æ·±ãã§ããããã¯ãã©ãã·ã¥ã«ãã£ãŠè§£æ±ºãããããšãçããŸãïŒãããŠããã¯äžè¬çã«å¯èœã§ãïŒã ããã€ã¹ã®ã¿ã亀æããŠãã ããã èå³æ·±ãããšã«ããã®ãããªãäžæ²»ã®ããã°ãããŒããŒãã§40ãã«ã§ã¯ãªããè»ã§70,000ãã«ã§èŠã€ãã£ãå Žåã¯ã©ãã§ããããã ããããæ°ãæ£ããŸããã
2.åæé®®ã®ãã©ãŠã¶ã§ããã¯ãã¢ãèŠã€ãããŸãã
ãã¥ãŒã¹ ã
ãœããŒãã¯ãã£ãŒãºãšã³ã¿ãŒãã€ã³ã¡ã³ãã®ãããã³ã°ã¹ããŒãªãŒã«æéãåããç 究è
ã®ãããŒããã³ã»ã³ã¯ãåæé®®ã®ã€ã³ã¿ãŒãããã®æ©èœãæ
éã«ç 究ããããšã«ããŸããã ãããããåæé®®ïŒããããå±æ§ã¯å€§ããªåé¡ã§ãïŒãæ»æã®ã€ãã·ãšãŒã¿ãŒã§ããããããã圌ãããã®ãªãŒããŒã«ã€ããŠ2014幎ã®æãæããªã³ã¡ãã£ãŒãæã£ããšããäºå®ãæ»æããŠããããšãæãåºãããŠãã ããã
åæé®®ã¯ãPulginnböölSaönjöngcheheãŸãã¯åã«ãRed StarããšããŠç¥ãããç¬èªã®LinuxããŒã¹ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã䜿çšããŠããŸãã ãã©ãŠã¶ã¯ãNenaraïŒãç§ã®åœãïŒãšããååã®Firefoxã®ãã©ãŒã¯ã§ãã ãã³ã»ã³ã¯ããã©ãŠã¶ã調ã¹ããšãèµ·åãããã³ã«ãå€ç«ããåæé®®ã®ãããã¯ãŒã¯ã®ããŒã«ã«IPã¢ãã¬ã¹ãããã¯ããããšãããããŸããã ããã«ãäŒç€Ÿã®ãããã¯ãŒã¯ãéåžžæ§ç¯ããããšãå
šåœã®ãããã¯ãŒã¯å
šäœãç·šæãããŸããå
éšã¢ãã¬ã¹ãå€çããã®ã»ãŒå®å
šãªåé¢ãããã³ãããã·ãä»ããéä¿¡ã®ã¿ã§ãã ãããããæå·åããããã®ãå«ããã¹ãŠã®ãã©ãã£ãã¯ã远跡ããæ©èœããããŸãããã©ãŠã¶ã¯åäžã®èšŒææžãåãå
¥ããŸããç¶æ
蚌ææžã¯ãããããããçš®ã®ããã³ããã¯ãªååãæã£ãŠããŸãã
ã€ãŸããåäžã®ãããã€ããŒãæã€åœã®ãŠãŒã¶ãŒã远跡ããããã«å¿
èŠãªãã¹ãŠã®ããŒã«ã¯ã䜿çšå¯èœãªå¯äžã®OSã«æ¢ã«çµã¿èŸŒãŸããŠããŸãã ãããŠãããã¯åæé®®ã§èµ·ãããŸãã ããïŒ éå ±ïŒ
ãã¡ããããã®ãã¥ãŒã¹ã®äººæ°ã¯ããœããŒãã¯ãã£ãŒãºãšã³ã¿ãŒãã€ã³ã¡ã³ããžã®æ»æãšãåæé®®ã®ãã®å·šå€§ãªããã¯ãžã®é¢äžã«ã®ã¿é¢é£ããŠããŸãã ããããããã ãã§ã¯ãããŸããã ãããŒãã»ãã³ã»ã³ã¯ãã€ã³ã¿ãŒãããã ãã§ãªããäžè¬çãªãã¹ãŠãçŠæ¢ããã³å¶éããæ¹æ³ãå®éã«ç¥ã£ãŠãã人ã«ãã£ãŠéçºãããããã€ãã®ããªãã¯ãæããã«ããŸããã ç¹ã«ã€ã³ã¿ãŒãããã èªãã§ïŒ
1. GLIBCã®è匱æ§ãŸãã¯ããããé©çšããããšãéèŠã§ããçç±
ãã¥ãŒã¹ ã CVEã¬ã³ãŒãã Red Hatããã®å©èš ã
åæ
çãªäœè«ã æšå¹Žã®ãã€ã©ã€ãã®1ã€ã¯ãçŸåšHeartbleedãšããŠç¥ãããŠããOpenSSLã®ç©Žã§ããã ã€ãã³ãã®çºå±ã芳å¯ããããšã¯éåžžã«èå³æ·±ãããšã§ããã絶察ã«æè¡çãªãããã¯ãæåã«æè¡ã³ãã¥ããã£ãåºçç©ã§è°è«ããããããå®å
šã«éæè¡çãªã¡ãã£ã¢ã«æ³šãããæ¹æ³ã§ãã ç¡é§ã§ã¯ãããŸããïŒ ãã®åé¡ã¯ã ããžãã¹ææè
ã管çè
ãéçºè
ããŠãŒã¶ãŒãªã©ããã¹ãŠã®äººã«æ¬åœã«åœ±é¿ãäžããŸããã äžè¬çã«ãèšå€§ãªæ°ã®äººãšäŒç€Ÿã ãŸããæè¡è
以å€ã®äººïŒããšãã°ãäŒç€Ÿã®çµå¶è
ãçµå¶è
ïŒã«ãç°¡åã§ç解ããããæ¹æ³ã§èª¬æããå¿
èŠããããŸãããåé¡ã¯äœã§ãä»äœããã¹ããïŒ
ãããŠãããªãã¯ãã®éæè¡è
ã«æ¥ãŠã次ã®ãããªããšãèšããŸãïŒHeartbleedã¯éèŠã§ãããªããªããç©Žãæ€åºãããOpenSSLã¯ã©ãã§ã䜿ãããŠããããã§ãã ããªãã®ãµã€ãã¯è匱ã§ãããããããŸãããããªãã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã¯è匱ã§ãããããããŸãããã€ããŒã®ããªãã®ãã©ã€ããŒãã¡ãŒã«ã§ããè匱ãããããŸããã ãè匱ããšã¯ã©ãããæå³ã§ããïŒ åœŒãã¯ããªãã®ãã¹ã¯ãŒããšã¡ãŒã«ãçãããšãã§ããŸãã ãµã€ãã«ææããå¯èœæ§ããããŸãã æ©å¯ããŒã¿ãçãå¯èœæ§ããããŸãã ã©ããã ããã¯ãã®èŠæš¡ã®æåã®ç©Žã§ãæåŸã®ç©Žã§ããªãããããã¹ãŠã«ããããåœãŠããã¹ãŠããã§ãã¯ãããã¹ã¯ãŒããå€æŽããã€ã³ãã©ã¹ãã©ã¯ãã£ä¿è·ã匷åããŸãã
ãããŠããã¥ãŒããã¹ãã®äººã¯ããã«åå¿ããŠæµžéããç解ããèšããŸãïŒããªãã¯ããããã©ãã«ããã®ã§ããïŒ ã¢ã©ãŒã ã鳎ãããŠã¿ãŸãããïŒ ã¿ã€ã ãºçŽãšãã©ãŠãçŽã«åºåãæ²èŒããŸããã§ãããïŒ ãããŠã»ãšãã©ã®å Žåãã¯ãã圌ãã¯èŠåããè°è«ãã調æ»ããããšãããããŸãã ãããã圌èªèº«ã®æè¡çãªã¹ã¿ã€ã«ã§ã çå£ã«ïŒ ç¹å®ã®è匱æ§ã®èŠæš¡ãè©äŸ¡ããã«ã¯ãå®éã«é²åŸ¡ããŒã«ãšã¯äœããç解ããæ»æã·ããªãªãäœã§ããããç¥ããæœåšçãªæ害ïŒçé£ãããå¯èœæ§ã®ãããã®ãšèŠæš¡ïŒãè©äŸ¡ã§ããå¿
èŠããããŸã ã ãããŠããããã¯éåžžã«ç°ãªãã¿ã¹ã¯ã§ãããååãšããŠãç°ãªãå°é家ããããã«åŸäºããŠãããããšãå
šå¡ãåªåãçµã¿åãããŠããéåžžã¯å¹
åºãèŽè¡ã«åé¡ã®æ¬è³ªã説æããæéãèŠã€ããããŸããã
ãããã£ãŠãéæè¡è
ã«ãšã£ãŠã¯ãHeartbleedã®ãããªåé¡ã¯ã©ããããšããªãçºçããããšãããããŸãã
ãã®ãããGNU Cã©ã€ãã©ãªã®ç©Žã¯ãæè¡æ®µéãã«ãããŸãã ã€ãŸãã圌ãã¯è匱æ§ãçºèŠãããããå®éã«ã»ãã¥ãªãã£ã«åœ±é¿ããããšãçºèŠããããã«ããã€ãã®æ»æã·ããªãªãææ¡ããŸããã ãããããããå®éã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã§å®éã«ã©ã®ããã«å€ããå¯èœæ§ããããã©ã®ãããªæ害ãçºçããå¯èœæ§ãããã®ãââã¯ããŸã æããã§ã¯ãããŸããã äžè¬çã«ãæºåãã§ããŠããªã人ã«ã¯ã次ã®ãããªè匱æ§ã®èª¬æã衚瀺ãããŸãã
GLIBCã§äœãèµ·ãã£ãã®ããã§ããã ãç°¡åã«èª¬æããããšããŸãã ç§ã¯ããã«èšããªããã°ãªããŸããïŒç§ã¯ããã°ã©ããŒã§ã¯ãããŸããã ç§ã®ä»äºã¯ãè€éãªããšãååã«å¹
åºãèŽè¡ã«èª¬æããããšã§ãã Habrã¯ãGLIBCã䜿çšããéã®åŸ®åŠãªéããç解ããå¿
èŠãããå Žæã§ã¯ãªãããšã¯æããã§ãã äžã®ããã¹ãã«ã€ããŠã®ã³ã¡ã³ãããåŸ
ã¡ããŠããŸãã ã説æãããããã¿ã¹ã¯ãã©ã®ããã«è§£æ±ºããŸããïŒ å¥ã®èšãæ¹ãããŸããïŒ ãã¹ãŠãæ£ãã説æããŸãããïŒ :)ããŒã±ãã£ã³ã°æ
åœè
ã¯ãã®ãããªã·ã³ãã«ãªããŒã«ã䜿çšããŠããŸããéèŠãªèãã3åäœæããŸãã ãããŠãç¶æ³ã«å¿ããŠããã®ãã¡ã®1ã€ã䜿çšããŸãã ã ããç§ã¯ãã®ããã«ããŠã¿ãŸãã
ã·ã§ãŒãããŒãžã§ã³ïŒ
ã³ã³ãã¥ãŒã¿ãŒããã³ãµãŒããŒäžã®ãœãããŠã§ã¢ãå®æçã«æŽæ°ããå¿
èŠããããŸããããã«ãããã»ãã¥ãªãã£ãåäžããŸãã æè¿ãLinuxã«é倧ãªããŒã«ãçºèŠãããŸãããLinuxã䜿çšããŠããå Žåã¯ãããããé©çšããå¿
èŠããããŸãã
ããå°ãïŒ
GLIBCã®è匱æ§ã¯ãã»ãŒãã¹ãŠã®LinuxããŒã¹ã®ã·ã¹ãã ã«åœ±é¿ããçè«çã«ã¯ä»»æã®ã³ãŒãã®å®è¡ãèš±å¯ãããããéåžžã«å±éºã§ãã çŸå®çã§å®éã«è
åšãšãªãæ»æã·ããªãªã¯ãããŸããããããã¯å°æ¥ããããåºçŸããããšãæå³ãããã®ã§ã¯ãããŸããã ãããã£ãŠããœãããŠã§ã¢ãå®æçã«æŽæ°ããå¿
èŠããããŸãã
ãããŠéåžžã«é·ãããŒãžã§ã³ïŒ
GLIBCã¯ããã¹ãŠã®LinuxããŒã¹ã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã çšã®æšæºCã©ã€ãã©ãªã§ãã ããã«ã¯ãç»é¢ã«äœãã衚瀺ããããã¢ããªã±ãŒã·ã§ã³ã«ã¡ã¢ãªé åãå²ãåœãŠãããããªã©ãæšæºçãªã¢ã¯ã·ã§ã³ãå®è¡ããå€æ°ã®ããã°ã©ã ãå«ãŸããŠããŸãã ã€ãŸããLinuxçšã®ããã°ã©ã ãäœæãã人ã䜿çšããŸããåã¿ã¹ã¯ããšã«ç¬èªã®ã³ãŒããäœæãã代ããã«ãGNU Cã©ã€ãã©ãªããå¿
èŠãªããã°ã©ã ããååŸãããŸãã ãããã£ãŠãéçºè
ã¯æéã倧å¹
ã«ç¯çŽããäžè¬çãªåé¡ã解決ããããã®æšæºåãããã¢ãããŒããæäŸããŸãã
ã€ãŸãããŸããGLIBCãèšå€§ãªæ°ã®ããã°ã©ã ã«åœ±é¿ãäžããããšãç解ããå¿
èŠããããŸããã©ã€ãã©ãªã«æ ŒçŽãããŠããã³ãŒãã«ãšã©ãŒãããå Žåããã®ã³ãŒãã䜿çšããããã°ã©ã ã®ããã©ãŒãã³ã¹ã«åœ±é¿ãäžããå¯èœæ§ããããŸãã ã³ãŒãã«è匱æ§ãããå Žåãããã䜿çšããããã°ã©ã ãæœåšçã«è匱ã«ãªããŸãã ãïŒ
ããã«é²ã¿ãŸãã ãã®è匱æ§ã¯ãgethostbynameé¢æ°ãã¡ããªã§çºèŠãããŸããã ãããã¯ã1ã€ã®ç°¡åãªã¿ã¹ã¯ãå®è¡ããGLIBCã³ã¬ã¯ã·ã§ã³ã®ãã®ãããªå°ããªããã°ã©ã ã§ããåºåã§ãµã€ãåïŒwww.kaspersky.comïŒãåä¿¡ãããšã123.123.123.123ãšãã圢åŒã®IPã¢ãã¬ã¹ãæäŸãããŸãã ããã°ã©ã ã§ãã®ãããªæäœãå®è¡ããå¿
èŠãããå ŽåïŒããã³ããã¯ããããã¯ãŒã¯ã§åäœããã»ãšãã©ãã¹ãŠã®ããã°ã©ã ã«å¿
èŠã§ãïŒããã®æ©èœã䜿çšããŸãã
åé¡ã¯ãé¢æ°ãå
¥åã§äžãããããã®ãååã«ãã§ãã¯ããªãããšã§ãã ãããéåžžèµ·ããããã«ãããã°ã©ã ã¯å
¥åã§ããŒã¿ãåãåãããã®ããžãã¹ã®ããã«ç¹å¥ã«å²ãåœãŠãããç¹å®ã®ãµã€ãºã®ã¡ã¢ãªé åã«ãããæžããããšæã£ãŠããŸãã ãŸããããŒã¿ããã®åãé åã«åãŸããã©ããã¯ãŸã£ãããã§ãã¯ããŸããã ãªã«ïŒ ããŒã¿ã¯æå®ãããé åå€ã«æžã蟌ãŸããŸãã ãªããããæªãã®ã§ããïŒ ãŸããæåã«ãåããŸãã¯å¥ã®ããã°ã©ã ã®ä»ã®ããŒã¿ãç®çã®ã¡ã¢ãªé åã®å€åŽã«é
眮ãããåŸè
ãåäœãåæ¢ããå ŽåããããŸãã æè¯ã®å Žåã ææªã®å Žåãå®è¡ããå¿
èŠãããã³ãŒãã®ä»£ããã«ããŒã¿ãæžã蟌ãŸããŸãã ãããŠãã³ãŒãã®äžéšããæŒãããããããã°ã©ã ã«éã蟌ã¿ããããããã¹ãå Žæã«ããããã«æžãçããããšãã§ããå Žåãã³ã³ãã¥ãŒã¿ãŒã«äœããã®ããã°ã©ã ïŒããæ£ç¢ºã«ã¯ãä»»æã®ã³ãŒãïŒãå®è¡ããããšãã§ããŸãã
ã¯ããç§ã¯ãã®åçãæ¬åœã«å¥œãã§ã:)
ããã§ãåé¡ã®ã¹ããŒãã¡ã³ãã決å®ããŸããã æ»æã·ããªãªã¯äœã§ããïŒ Qualysã®ç 究è
㯠ãEximã®ã¡ãŒã«ããã°ã©ã ãgethostbynameé¢æ°ã«ã¢ã¯ã»ã¹ãããšãã«ããã®è匱æ§ã䜿çšããŠä»»æã®ã³ãŒããå®è¡ããæ¹æ³ã瀺ããŸãã ã ãããã£ãŠãçè«çã«ã¯Eximã䜿çšããŠäŒç€Ÿã®ã¡ãŒã«ãµãŒããŒãæ»æãããã®ãµãŒããŒäžã§ä»»æã®ã³ãŒããå®è¡ã§ããŸãã äŒç€Ÿã®ã¡ãŒã«ãçãã ããéèŠãªããã¥ã¡ã³ãã«ã¢ã¯ã»ã¹ããããäœããã®åœ¢ã§æ¬åœã®æ害ãäžãããããããšã¯ã§ããŸããïŒ çè«çã«ã¯ã§ããŸãã ãããããã¹ãŠã®åŸ®åŠãªç¹ãäºçŽïŒããã§ã¯èšåããŸããïŒãèãããšãè匱æ§ã䜿çšããŠçŸå®äžçã®ããŒã¿ãçãå±éºæ§ããŸã è©äŸ¡ããããšã¯ã§ããŸããã
ãããŠãããã¯GLIBCè匱æ§ãšHeartbleedã®éãã§ãã ããã«ã¯æ確ãªè
åšããããŸããããã®è
åšã¯çè«äžã®ãã®ã§ãã è匱æ§ã«ã€ããŠã¯ãå€ãã®éèŠãªæ³šæäºé
ãçç¥ããŸããïŒgethostbynameé¢æ°èªäœã¯ãã§ã«å€ããªã£ãŠããããããã¡ãŒãªãŒããŒãããŒç¶æ³ãäœæããããã®æ¡ä»¶ã¯éåžžã«å
·äœçã§ããããã®é¢æ°ã䜿çšããããã°ã©ã ã®è匱æ§ããè©Šããå§ãããšããã¹ãŠãè€éã«ãªããŸãã
ãããã ä»ã®ãšãã ã 誰ãïŒãããŠããµã€ããŒç¯çœªè
ã§ã¯ãªãç 究è
ã®å ŽåïŒã¯ããã®è匱æ§ã䜿çšããŠå€æ°ã®LinuxãµãŒããŒãè¿
éãã€ç°¡åã«ç Žå£ããæ¹æ³ãèŠã€ããå¯èœæ§ããããŸãã ãããŠããã®ãšãã ãããã©ãŒãã¹èªãæ°èã©ã€ãã¯è匱æ§ã«ã€ããŠæžãããã£ã³ãã«1ã®ãããããåé€ããŸãã 誰ããããã®ããã«ã2000幎以éã«ç©Žãååšãã誰ãæ°ã¥ããŠããªããšèšãã§ãããã ããããæé
ãã«ãªããŸãã ãããã£ãŠãçµè«ïŒãããã¯éèŠã§ãã ãŸããçŽæ¥çãªå±éºããªããŠããèªåã®ãµãŒããŒã§çºèŠãããè匱æ§ãéããããšãéèŠã§ãã