èŠããã«ãææ°ã®iPhone 164ã¯ç§ãã¡ã®ãã¹ãŠãå®å šã«ç¥ã£ãŠããã§ãããã Googleã¯34ã®ãã©ã³ãå€æŽãš8ã®ãªã¹ãã©ãçã延ã³ããã®ããŒã¿ãä¿åããå°çã®è¡šé¢ã®2ïŒ ä»¥äžãå ããããŒã¿ã»ã³ã¿ãŒã§ããã«åŠçããŸãã ãããŠããã®ãšãåããŠãæè¡ã®é©ãã¹ãé²æ©ãéããŠã圌ãã¯ãã®ããŒã¿ãä¿è·ããæ¹æ³ã«ã€ããŠèãå§ããã§ãããã ãã³ã³ã¯ã®éåžå Žã§çãããšãç¥ããªãåžæ°ãšå¥³æ§ã®ãšããã£ãã¯ãªå€¢ã®ã³ã¬ã¯ã·ã§ã³ãåããŠç»å ŽããåŸã ç³è«æã«éè¡ãããŒã³åå人ã®å¿ãèªãã§ããã¹ãã£ã³ãã«ã®åŸã®ã¿ã ãããŠãããªãã¯çå£ã«ç解ããå¿ èŠããããŸã-ã©ããªçš®é¡ã®ããŒã¿ãåéããŠããŸããïŒ ä¿ç®¡æ¹æ³
ããããããã¯ãã¹ãŠåŸã§è¡ãããŸãã èå³æ·±ãããšã«ãä»ã誰ããææè ãæºåž¯é»è©±ããã®ãžã£ã€ã枬å®å€ã®ã¢ãŒã«ã€ãã®ææè ãã©ã®ãããé ã£ãŠãããã«ã€ããŠèããŠããŸããïŒ ã»ãã¥ãªãã£ç 究ã¯åžžã«æè¡ãåžå Žã«ç»å ŽããåŸã«è¡ãããŸãããæè¡ã¡ãŒã«ãŒã¯ã»ãã¥ãªãã£ã«ã€ããŠã»ãšãã©èããŸããã ä»é±ã®éèŠãªæ å ±ã»ãã¥ãªãã£ãã¥ãŒã¹ã®ä»æ¥ã®ãã€ãžã§ã¹ã-äœçŸäžäººãã®äººã ãé·ãé䜿çšããŠããä»æ¥ã®ãœãããŠã§ã¢ãšããã€ã¹ã®å ±åäŒã ã«ãŒã«ãæãåºããŠãã ãããThreatpostãã¥ãŒã¹ãµã€ãã®ç·šéå§å¡äŒã¯ã3ã€ã®æãéèŠãªãã¥ãŒã¹ãæ¯é±éžæããŸããããã«ã¯ãæ¡åŒµããã容赊ãªãã³ã¡ã³ããè¿œå ãããŠããŸãã ã·ãªãŒãºã®ãã¹ãŠã®ãšããœãŒãã¯ããã§èŠã€ããããšãã§ããŸã ã
åçã®é ã«5ãã«ããš12ãã«ããäŸçµŠãããã®ã¯ãªãã§ããïŒ ããããªãïŒ
ãžã§ã€ã«ãã¬ã€ã¯ãããiPhoneããããŒã¿ãçãããã€ã®æšéŠ¬
ãã¥ãŒã¹ ã ããã¢ã«ããããã¯ãŒã¯ã¹ã«ããç 究 ã
è匱æ§ãçé£ã®ãã¹ãŠã®ã¬ããŒããç°¡åãªèšèã§åãäžããŠå販ã§ããããã§ã¯ãããŸããã ããã¯å¯èœã§ãã äžåœã§ã¯ãAppleã®ãµãŒããŒãšçµ±åããiTunes Storeãããã¹ã¯ãŒããçãiPhoneã¢ããªãçºèŠããŸããã ãµã€ããµã€ã³ã§çºèŠïŒã¢ã«ãŠã³ãããã®ãéã®çªçã«é¢ãããŠãŒã¶ãŒã®å€§éã®èŠæ -ãã¹ãŠã®AppleãŠãŒã¶ãŒã®ã«ãŒãã¯å ãçµã³ç®ã§ã¢ã«ãŠã³ãã«çµã³ä»ããããŠãããéåžžããã¹ã¯ãŒãã以å€ã®ãé³¥ãã®æ¯æãã«ã¯äœãå¿ èŠãããŸããã
ãã£ãããïŒ ããã§ããªãã ãžã§ã€ã«ãã¬ã€ã¯ãããããã€ã¹ã®ææè ã®ã¿ãæ»æãããŸããã WeipTechãšåŒã¶ããã«é Œãã äžåœã®ç¬ç«ããç 究è ã¯ãç¯çœªè ã®CïŒCãµãŒããŒã誀ã£ãŠç ŽããããŠãŒã¶ãŒåããã¹ã¯ãŒããããã€ã¹GUIDãã®åœ¢åŒã§22äž5,000人ãè¶ ãããŠãŒã¶ãŒããããªãã¯ãã¡ã€ã³ã«ããããšã«æ°ä»ããŸããïŒãžã§ã€ã«ãã¬ã€ã¯ã®æ¯æè ãéåžžã«å€ãããšã¯ç¥ããŸããã§ããïŒã æªæã®ããã¢ããªã±ãŒã·ã§ã³ã¯ã代æ¿ã®Cydiaã¹ãã¢ã®æµ·è³è²šç©è¹ãä»ããŠé ä¿¡ãããäžéè æè¡ã䜿çšããŠããã€ã¹ãšAppleéã®éä¿¡ã«çµã¿èŸŒãŸããçãŸãããã®ããµãŒããŒã«éä¿¡ããŸãã Cherry on the cakeïŒãã¹ã¯ãŒããæå·åããããã®ããŒã¯éçã§ããã¬ãŒãºãmischa07ãã䜿çšããŸãã
Mischa07ã¯ãŠãŒã¶ãŒãã¹ã¯ãŒããçã¿ãŸã
ãã®ããã·ã£ããããŒã¬ã€ããŒã®æ»æã§çå£ã«çšŒãããšãã§ãããã©ããã¯äžæã§ãããããã¯ãã€ã³ãã§ã¯ãããŸããã ãã®ãã¥ãŒã¹ã®äž»ãªãã®ã¯ããã§ãïŒã»ãã¥ãªãã£ã®é¢ã§ãžã§ã€ã«ãã¬ã€ã¯ãããiPhoneã¯Androidãããæªãã§ãã iOSã®ïŒéåžžã«åŒ·åãªïŒä¿è·ãç Žã£ãå Žåããã以äžã®ãã§ãã¯ã¯ãããŸãããïŒ ããªãããããããšãããŸããïŒ ã¡ãªã¿ã«ã匷åãªãã¡ã€ã¢ãŠã©ãŒã«ãç©ççãªä¿è·ããã¹ãŠãã€ã³ã¿ãŒãããããåæãããŠãããããããšãåšèŸºãé£ã³åãããšã¯ãããŸããã å éš-4çªç®ã®åãæ ªã«ãããWindows XPã2003幎以éã«ããããããŠããªãã³ã³ãã¥ãŒã¿ãŒã ãããŠãå¢çç·ãåé¿ã§ããå Žåã¯ã©ããªããŸããïŒ å®éãiOSã®ã³ã³ããã¹ãã§ã¯ãåãåé¡ãçºçããŸããåçŽã§æå¹ãªå€§èŠæš¡ãªã«ãŒããšã¯ã¹ããã€ããçªç¶è¡šç€ºãããå Žåãã©ããªããŸããïŒ ãã³ããŒã«ã¯ãã©ã³BããããŸããïŒ ãããšãããã®ãããªç¶æ³ã§Androidã倧ããªå©ç¹ãæã£ãŠããããšãçªç¶å€æããã®ã¯ããã¹ãŠãå£ããå¯èœæ§ãããããšãé·ãéæããã«ãªã£ãŠãããéçºãããã«å¿ããŠè¡ãããŠããããã§ããïŒ
GoogleãMozillaãããã³ïŒä»¥åã®ïŒMicrosoftã¯2016幎ã«RC4ã«å¥ããåããŸã
ãã¥ãŒã¹ ã
åã®ã·ãªãŒãº ïŒGitHubã§ã®man-on-the-side DDoSæ»æã«é¢é£ããŠïŒã§ã¯ãHTTPSã䜿çšããããšã¯ãWebãµãŒãã¹ã®ãŠãŒã¶ãŒãšææè ã®äž¡æ¹ã«é©ããŠãããšããäºå®ã«çŠç¹ãåœãŠãŸããã ãããŠãããã¯ããã§ããå¯äžã®åé¡ã¯ããã¹ãŠã®HTTPSå®è£ ãåçã«åœ¹ç«ã€ããã§ã¯ãªããå€ä»£ã®æå·åæ¹æ³ã䜿çšããŠãããã®ã¯æ害ã§ãããããšããããšã§ãã äŸã¯ã POODLEæ»æã§ã®SSLv3ãããã³äžè¬ã«RC4æå·ã䜿çšãããã¹ãŠã§ãã SSLv3ãæè¿18åšå¹Žãè¿ããã¢ã«ã³ãŒã«ãåæ³çã«è³Œå ¥ã§ããããã«ãªã£ãå ŽåãRC4ã®ã«ãŒãã¯åäžçŽã®80幎代ã«ãããŸãã Webã«é¢ããŠã¯ãRC4ã䜿çšããæ¥ç¶ã劥åããæ¥ç¶ãä¿èšŒãããšä»ã®ãšããèšãããšã¯ã§ããŸããã 以åãã€ã³ã¿ãŒããããšã³ãžãã¢ãªã³ã°ã¿ã¹ã¯ãã©ãŒã¹ã¯ ãRC4ã«å¯Ÿããçè«çãªæ»æã¯ãå®è¡ããã寞åãã§ããããšãææããŸããã
å®éãããã«æè¿ã®ç 究ã®äŸããããŸãããµã€ãã«æ¥ç¶ãããšãã«éåžžã®æå·ããRC4ã«ããŒã«ããã¯ãããšãéä¿¡ãããCookieã解èªã§ããŸãïŒã»ãã·ã§ã³ããã€ãžã£ãã¯ããããšãæå³ããŸãïŒã ãããè¡ãã«ã¯ãããã€ãã®Cookieãã€ã³ã¿ãŒã»ããããåºåãããå 容ã倧ãŸãã«ç解ããå¿ èŠããããŸããéåžžããããããã«é«ãæå確çã§ãã«ãŒããã©ãŒã¹ã§ãã ãã¶ãïŒ ã¯ãããã ãäºçŽããã å®éã«äœ¿çšããŸããïŒ ãããã誰ãç¥ã£ãŠããŸããïŒ ãªãŒã¯ã§ã¯ãSnowdenã¯ã»ãã¥ãªãã£ãµãŒãã¹ãRC4ãé«ãä¿¡é Œæ§ã§ç Žãããšãã§ãããšç€ºåããŸããã
äžè¬ã«ããã®ãã¥ãŒã¹ã¯å¥œæçã§ããæœåšçã«è匱ãªæå·åã¢ã«ãŽãªãºã ã¯æåŸãŸã§ç ŽãããŠããŸããïŒå°ãªããšããã«ã¯ã§ã¯ãããŸããïŒããããã«å®å šã«ãããã¯ãããŸãã ã¯ããçŸåšã§ã¯ã»ãšãã©äœ¿çšãããŠããŸãã
ç§ã¯ãæçè«ã®äœäžã§æ¥œèŠ³äž»çŸ©ã匱ããããšã¯ã§ããŸããã ãã®ãããªã¢ããã°ã¬ãŒãã®è¢«å®³è ã¯ãéåžžãæ²ãã£ãŠãµã€ããå¿ èŠãšãã人ãã»ãšãã©ããªãããäœããå€æŽããããšãå°é£ãªã¿ã€ã ã¯ãªãã£ã«ã«ãªWebãµãŒãã¹ã§ãã 2æã«ã¯ããã©ãŠã¶ãæŽæ°ããåŸããŠãŒã¶ãŒãã»ãã¥ãªãã£ã§ä¿è·ãããã€ã³ã¿ãŒããããã³ã¯ã«ã¢ã¯ã»ã¹ã§ããªãããšã«ã€ããŠããã©ãŒã©ã ã§æ¿ããè°è«ãè¡ãããå¯èœæ§ããããŸãã èŠãŠã¿ãŸãããã
Belkin N600ã«ãŒã¿ãŒã®è匱æ§
ãã¥ãŒã¹ ã CERTã¢ããã€ã¶ãªãŒ ã
ç§ã¯ã«ãŒã¿ãŒã®è匱æ§ã«é¢ãããã¥ãŒã¹ãæ¬åœã«å¥œãã§ãã ç§ãã¡ãæ¯æ¥äœ¿çšããã³ã³ãã¥ãŒã¿ãŒãã¹ããŒããã©ã³ããã®ä»ã®ããã€ã¹ãšã¯ç°ãªããã«ãŒã¿ãŒã¯éåžžãé ã®ã©ããã«ã»ãããéããŸããç¹ã«ãã«ãŒã¿ãŒãè¯å¥œã§æ éãªãåäœããå Žåãé·å¹Žç¡èŠãããŠããŸãã åæã«ãæ£çŽã«èšããšããã®ãã©ãã¯ããã¯ã¹ã§å®éã«äœãèµ·ãã£ãŠããã®ã誰ã«ãããããŸããã OpenWRTã«åºã¥ããŠã«ã¹ã¿ã ãã¡ãŒã ãŠã§ã¢ãå人çã«ããŒã«ããå Žåã§ãã ç¹ã«ãæè¡è ã§ã¯ãªããããããã€ããŒãã«ãŒã¿ãŒãã€ã³ã¹ããŒã«ããŠæ§æããŠããå Žåã åæã«ãã«ãŒã¿ãŒã«ã¯ãã¹ãŠã®ããŒã¿ãžã®ããŒãå«ãŸããŠããŸã-ããŒã ãã¡ã€ã«å ±æã«è¡ãããå Žåãå¿ èŠã«å¿ããŠ-ãã©ãã£ãã¯ãååããã€ã³ã¿ãŒããããã³ãã³ã°ããŒãžã眮ãæããGoogleæ€çŽ¢çµæã«åºåãæ²èŒããŸãã åäžã®è匱æ§ããŸãã¯å€ãã®å Žåãè匱æ§ã§ã¯ãªããã¡ãŒã«ãŒã®æ¹Ÿæ²ããæ§æãä»ããŠäžåºŠã ãã¢ã¯ã»ã¹ããã°ååã§ãã
æçš¿ã®æåŸã«ãã«ãŒã¿ãŒã®ãã¡ãŒã ãŠã§ã¢ã®æŽæ°ã®èŠåæ§ã«é¢ãã調æ»ãè¿œå ããŸããã ãããŠãç§èªèº«ããæ°ããã¢ããããŒãããªãªãŒã¹ããããšããã«ãã«ãŒã¿ãŒã®ãã¡ãŒã ãŠã§ã¢ãé »ç¹ã«ã¢ããããŒããããšçãããã®ã§ãããããã§ã¯ãããŸããã æè¯ã®å Žåã¯ã6ãæã«1åã§ããããã¯ãã«ãŒã¿ãŒã®Webã€ã³ã¿ãŒãã§ã€ã¹ã«ãªãã€ã³ããŒã衚瀺ãããããã§ãã é »ç¹ã«ä»¥åã®ã«ãŒã¿ãŒãæŽæ°ããŸããããããã¯ãäžå®ã®ããªãŒãºãç¡å¹ã«ããããšããããã§ãã ãŸãããã°ããã®éãç§ã®ã«ãŒã¿ãŒã¯ãªã¢ãŒãã¢ã¯ã»ã¹ãèš±å¯ãããã®è匱æ§ã«å人çã«ãããããŠããŸããã
ããã§ã¯ãBelkinã«ãŒã¿ãŒã§äœãèµ·ãã£ãã®ã§ããããïŒ åœŒãã¯ããã«ãã»ãã¥ãªãã£ã«äœããã®åœ±é¿ãäžãã5ã€ã®è匱æ§ãçºèŠããŸããã äŸïŒ
- DNSã«ç §äŒãããšãã®äºæž¬å¯èœãªãã©ã³ã¶ã¯ã·ã§ã³IDãçè«äžã¯ãããšãã°ãã¡ãŒã ãŠã§ã¢æŽæ°ãµãŒããŒãèŠæ±ãããšããªã©ãå¿çãšããŠå¥ã®ãµãŒããŒã代çšã§ããŸãã ããã»ã©æããªãã
- åããã¡ãŒã ãŠã§ã¢æŽæ°èŠæ±ãªã©ã®éèŠãªæäœã®ããã©ã«ãHTTPã æãã
- Webã€ã³ã¿ãŒãã§ã€ã¹ã®ããã©ã«ããã¹ã¯ãŒãã¯ãããŸããã æ¢ã«ããŒã«ã«ãããã¯ãŒã¯å ã«ãããã®ã®ãäœã§ãå€æŽã§ããŸãã ææã®å¹³åã¬ãã«ã
- Webã€ã³ã¿ãŒãã§ãŒã¹ã«ã¢ã¯ã»ã¹ããéã®ãŠãŒã¶ãŒãã¹ã¯ãŒãèªèšŒã®ãã€ãã¹ã èå¿ãªã®ã¯ã ãã©ãŠã¶ããã°ã€ã³ããŠãããã©ãããã«ãŒã¿ãŒã«äŒããéããŸãåæ§ã§ãã ã«ãŒã¿ã«éä¿¡ãããæ å ±ã®ãã©ã¡ãŒã¿ã®ãã¢ã®å€ã眮ãæããŸãããã¹ã¯ãŒãã¯çç¥ã§ããŸãã 76ïŒ æãã
- CSRF æºåããããªã³ã¯ãã¯ãªãã¯ããããã«ãŠãŒã¶ãŒã«åŒ·å¶ããå Žåãã«ãŒã¿ãŒã®èšå®ã§äœãããªã¢ãŒãã§å€æŽã§ããŸãã Webã€ã³ã¿ãŒãã§ã€ã¹ã®ãã¹ã¯ãŒããèšå®ãããŠããªãå Žåãããã¯ç¹ã«ç°¡åã§ãã æãããããææã
ããŠãããŠãããŸãäžè¬çã§ã¯ãªãã«ãŒã¿ãŒã«ããããã®ç©ŽãèŠã€ããŸããã åé¡ã¯ãã«ãŒã¿ãŒã®è匱æ§ãæ¢ããŠãã人ãããŸãå€ããªãããšã§ãããŸããBelkinã§è匱æ§ãçºèŠããããä»ã®ã¡ãŒã«ãŒã§ã¯çºèŠã§ããªãã£ããšããäºå®ã¯ãä»ã®ã¡ãŒã«ãŒã®ä¿¡é Œæ§ãé«ããšããæå³ã§ã¯ãããŸããã 圌ã®æããŸã 圌ã«å±ããŠããªããšããã ãã§ãã ãã®ãã¥ãŒã¹ã®éžæã«ãã ããã®åéã®ãã¹ãŠãéåžžã«æªãããšãæããã«ãªããŸãã çµè«ã¯ïŒ ããŒã«ã«ãããã¯ãŒã¯ãå°ãªããšã以äžã®æ段ã§ä¿è·ããå¿ èŠããããŸãïŒWebã€ã³ã¿ãŒãã§ãŒã¹ã®ãã¹ã¯ãŒããWEPã䜿çšããWiFiãªããWPSããã³FTPãµãŒããŒãtelnet / SSHã¢ã¯ã»ã¹ãªã©ã®æªââ䜿çšæ©èœãç¡å¹ã«ããŸããç¹ã«å€éšããã
ä»ã«äœãèµ·ãã£ãïŒ
ç±³åœã¯ ããµã€ããŒã¹ãã€ã«å¯Ÿããäžåœã«å¯Ÿããå¶è£ãèšç»ããŠããŸãã ä»é±ã®æã人æ°ã®ãããã¥ãŒã¹ã®1ã€ã§ãããç¹ç°æ§ããããŸãããµã€ããŒã»ãã¥ãªãã£ã«åœ±é¿ãäžããããšã¯ãããŸããã å å®ãªããªã·ãŒã
ã«ãŒã¿ãŒã¯æãå±éºãªããã€ã¹ã§ã¯ãããŸããã ãããŒã¢ãã¿ãŒããã®ä»ã®ãŠãŒã¶ãŒãã¬ã³ããªãŒãªç£èŠè£ 眮ã¯ããã«æªãã§ãã æå·åãæ¿èªããã®ä»ã®ãã©ãã«ã®æ¬ åŠã
Pages Managerã¢ããªã±ãŒã·ã§ã³ã䜿çšããŠãFacebookã®ææè ããã°ã«ãŒããéžæããæ¹æ³ãèŠã€ããŸããã è匱æ§ã¯éããããç 究è ã¯çŽæããããã°å ±å¥šéãåãåããŸããã
å€ç©ïŒ
家æãã¢ã³ããªã¥ãŒã·ã¥ã«ã
éåžžã«å±éºãªåžžé§ããŽãŒã¹ãããŠã€ã«ã¹ã COMããã³EXEãã¡ã€ã«ã¯ãCOMMAND.COMãé€ããææãã¡ã€ã«ã®éå§æïŒãã£ã¬ã¯ããªå ã§ã®æ€çŽ¢ïŒããã³ãããã®TSRã³ããŒïŒãªãŒãã³ãå®è¡ãååå€æŽãªã©ïŒãã圱é¿ãåããŸãã Andryushka-3536ã¯ãææãããšEXEãã¡ã€ã«ãCOM圢åŒã«å€æããŸãïŒVASCINAãŠã€ã«ã¹ãåç §ïŒã ãŠã€ã«ã¹ã¯ãã¡ã€ã«ã®äžå€®ã«å°å ¥ãããŸããããŠã€ã«ã¹ãèšé²ãããŠããææãã¡ã€ã«ã®éšåã¯æå·åãããææãã¡ã€ã«ã®æ«å°Ÿã«è¿œå ãããŸãã
ãã£ã¹ã¯ã®ããŒãã»ã¯ã¿ãŒã«ã«ãŠã³ã¿ãŒãç·šæãããã®å€ã«å¿ããŠãCïŒãã©ã€ãäžã®ããã€ãã®ã»ã¯ã¿ãŒãç Žå£ããå¯èœæ§ããããŸãã åæã«ãã¡ããã£ãåçããŠããã¹ãã衚瀺ããŸãã
ãã¡ã¢ãªäžè¶³ããšããããã¹ããå«ãŸããŠããŸãã å²ã蟌ã¿ãã³ãã©ãŒã䜿çšããã®ã¯éåžžã«å°é£ã§ããint25hãã³ãã©ãŒã®äžéšãæ¬äœã«ä¿åããã³ãŒãã空ãé åã«æžã蟌ã¿ãŸãïŒint 21hãåŒã³åºããŸãïŒã int 25hãåŒã³åºããšãint 25hãã³ãã©ãŒã埩å ãããŸãã
Eugene Kasperskyèã®æ¬ãMS-DOSã®ã³ã³ãã¥ãŒã¿ãŒãŠã€ã«ã¹ãããã®åŒçšã 1992幎ã 23ããŒãž
å 責äºé ïŒãã®ã³ã©ã ã¯ãèè ã®å人çãªæèŠã®ã¿ãåæ ããŠããŸãã ã«ã¹ãã«ã¹ããŒã®äœçœ®ãšäžèŽããå Žåãããã°ãäžèŽããªãå ŽåããããŸãã ããã¯å¹žéã§ãã