
å€ãã®ææ°ã®ã³ã³ãã¥ãŒã¿ãŒã·ã¹ãã ïŒPCã®ãã¶ãŒããŒããã¹ããŒããã©ã³ããããã¯ãŒã¯æ©åšãªã©ïŒã¯ãç¹å®ã®ããŒããŠã§ã¢åãã«éçºãããå©çšå¯èœãªããŒããŠã§ã¢ãªãœãŒã¹ã®å šç¯å²ã䜿çšã§ããæé«ã®ç¹æš©ãæã€ãã¡ãŒã ãŠã§ã¢ã®å¶åŸ¡äžã§åäœããŸãã ãã¡ãŒã ãŠã§ã¢ã®ä¿è·ã«ã¯ç¹ã«æ³šæãæãå¿ èŠããããŸããããããªããšãã·ã¹ãã ã®ã»ãã¥ãªãã£ã«ãããçã®ã¢ãã¬ã¹è ±ã«ãªããŸãã
ãã®åé¡ã«ã€ããŠã¯ãå°æ°ã®èšäºã§åãäžããŸãããå®éã®äŸã䜿çšããŠããã¡ãŒã ãŠã§ã¢ã»ãã¥ãªãã£ã®åŒ±ãã¢ãã«ãšåŒ·ãã¢ãã«ã瀺ããŸãã
ã¡ãªã¿ã«ããã®èšäºã¯ç£æ¥çšãããã¯ãŒã¯ã¹ã€ããã®ã»ãã¥ãªãã£ã«é¢ããç§ãã¡ã®ç 究ã«åºã¥ããŠããŸããããã¯ãç§ãZeroNights 2015ã®å®åè åãæ å ±ã»ãã¥ãªãã£äŒè°ã§çºè¡šãããã®ã§ãïŒã¬ããŒããç£æ¥çšã¹ã€ãããã¡ãŒã ãŠã§ã¢ã®å€æŽãããã¬ãŒã³ããŒã·ã§ã³ã¯ãã¡ãã§ã ïŒã
ã¯ããã«
æåã«ã調æ»ã®ç®çã§ããç£æ¥çšã¹ã€ããã«ã€ããŠèª¬æããŸãããã
ææ°ã®ICSã€ã³ãã©ã¹ãã©ã¯ãã£ã®äžå¿ã¯ããŒã¿åªäœã§ãã ã»ãšãã©ã®å Žåãããã¯ç£æ¥çšã€ãŒãµããããªã©ã®ç£æ¥çšãããã¯ãŒã¯ã§ãã ã€ãŒãµããããã¯ãããžãŒãã¡ããªã«åºã¥ããŠããŸãã ãã®ãããªãããã¯ãŒã¯ã¯ãäž»ã«ãªã¢ã«ã¿ã€ã ãããã³ã«ïŒããšãã°ãProfinetãEtherCATãEthernet / IPãªã©ïŒã®äœ¿çšã«ãããŠéåžžã®ãããã¯ãŒã¯ãšç°ãªããŸãã
ç£æ¥çšãããã¯ãŒã¯ã®äŸ[ ããããã®åç]ïŒ

ããŸããŸãªçš®é¡ã®ããã€ã¹ïŒPLCãHMIããã«ãå¶åŸ¡PCããã£ãŒã«ãããã€ã¹ãªã©ïŒã¯ãç£æ¥çšã¿ã€ãã®ãããã¯ãŒã¯ã¹ã€ããïŒã¹ã€ããïŒãä»ããŠãããã¯ãŒã¯ã«æ¥ç¶ãããŸãã åŸæ¥ã®ã¹ã€ãããšã¯ç°ãªããåäœæ¡ä»¶ïŒæ¡åŒµåäœæž©åºŠç¯å²ããµãŒãžä¿è·ãèè¡ææ§ãDINã¬ãŒã«ãžã®åãä»ãå¯èœæ§ãªã©ïŒã«å¯ŸããèŠæ±ãå°ãªããç£æ¥çšãããã¯ãŒã¯ãããã³ã«ããµããŒãããŸãã
ãããã£ãŠãç£æ¥çšã¹ã€ããã¯ãç£æ¥çšãããã¯ãŒã¯ã®æ§é ã«ãããŠéèŠãªèŠçŽ ã§ãã ãããã¯ãŒã¯äžã®ä»ã®ããã€ã¹ã®äŸµå®³ãPLCãšSCADAã®éãã²ãŒããŠã§ã€ãšPLCã®éã®ç°ãªãæ¥ç¶å ã®ããŒã¿ã®å¹²æžãšå€æŽãããŒã¿ã®åœé ã HMIããã³ãžã£ãŒããªã³ã°ã·ã¹ãã ãªã©ã«è»¢éãããŸãã ããã¯ãã¹ãŠãæè¡ããã»ã¹ã®å®éã®ç¶æ ã«å¯Ÿãããªãã¬ãŒã¿ãŒã«ããå¶åŸ¡ã®åªå€±ããã®çµæãåæ¢ãŸãã¯äºæ ã䌎ãå¯èœæ§ããããŸãã
ãããé²ãã«ã¯ïŒ
- ãŸããã¹ã€ããã®é åã®å Žæã¯ãã¹ã€ãããžã®äžæ£ãªç©çã¢ã¯ã»ã¹ã®å¯èœæ§ãæå°éã«æããå¿ èŠããããŸãã
- 次ã«ãã¹ã€ããã®ãœãããŠã§ã¢ããã³ããŒããŠã§ã¢ã¢ãŒããã¯ãã£ã«ã¯ãçŸä»£ã®è åšãèæ ®ããæ å ±ã»ãã¥ãªãã£ã¢ãã«ãå¿ èŠã§ãã
åŸè ã«ã€ããŠèª¬æããŸãã
ç 究ã®å¯Ÿè±¡
ç 究ã®ããã«ãç£æ¥çšãããã¯ãŒã¯æ©åšã®2ã€ã®æãäžè¬çãªã¡ãŒã«ãŒãã管çãããç£æ¥çšã¹ã€ããã®1ã€ã®ã¢ãã«ãåããŸããã
- ãã«ã·ã¥ãã³RS20
- Phoenix Contact FL SWITCH MM HS
ãããã®ã¹ã€ããã®åäœã¯ãCOMããŒãïŒäž¡æ¹ãšãRS-232ã³ãã¯ã¿ã䜿çšïŒãŸãã¯ãããã¯ãŒã¯ã¬ãã«ã§å¶åŸ¡ã§ããŸãã
COMããŒããä»ããŠäœæ¥ããå Žåãã³ãã³ããå ¥åããããã®ã³ã³ãœãŒã«ãæ±ã£ãŠããŸãã

ã³ã³ãœãŒã«ãžã®ã¢ã¯ã»ã¹ã«ã¯ããŠãŒã¶ãŒåãšãã¹ã¯ãŒããå¿ èŠã§ãã ããã§ããèªèšŒç»é¢ã®åã«ã¯ãããŒããŠã§ã¢ãšãã¡ãŒã ãŠã§ã¢ã«é¢ããæ å ±ã®è¡šç€ºããã¡ãŒã ãŠã§ã¢ã®æŽæ°ãªã©ãããã€ãã®ãªãã·ã§ã³ãå©çšã§ããŸãã
ãããã¯ãŒã¯ãä»ããŠã¹ã€ãããæäœããå ŽåãWebã€ã³ã¿ãŒãã§ãŒã¹ã«ïŒIPã¢ãã¬ã¹ã§ïŒã¢ã¯ã»ã¹ã§ããŸãã

ã¢ã¯ã»ã¹ããã«ã¯èªèšŒãå¿ èŠã§ãã
ãããã¯ãŒã¯ã¬ãã«ã§ã¹ã€ããã管çããããã®ãã1ã€ã®ãªãã·ã§ã³ã¯ãèªèšŒãããSNMPïŒSimple Network Management ProtocolïŒã§ãã ãã ãã調æ»ããã¹ã€ããã§ã®SNMPãµããŒãã«ã¯ãããã€ãã®æ¬ ç¹ããããŸãã
- ããã©ã«ãã§ã¯ïŒãããã»ãšãã©ã®ãããã¯ãŒã¯ããã€ã¹ã®æããæ°ã«å ¥ãã®æ§æã§ãïŒããã®ãããã³ã«ã®æãå®å šã§ãªãããŒãžã§ã³ã䜿çšãããŸã-SNMP v1ã
- SNMP v1ã§ã¯ããããã®ããã€ã¹ã®ãã³ããŒã¯ããã©ã«ãã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããå€æŽããªãããšã匷ããå§ãããŸãã
- SNMP v1ããã³SNMP v2cã®ããŒãžã§ã³ã¯æå·åã䜿çšããŸãããã€ãŸãããããã³ã«ã¯MITMïŒäžéè ïŒãªã©ã®æ»æã«å¯ŸããŠè匱ã§ãã
ãŸããHirschmann RS20ã¹ã€ããã®ç 究ã«ã€ããŠèª¬æãã次ã«ãã®ã¹ã€ãããšæ¯èŒããŠPhoenix Contact FL SWITCH MM HSã®æ©èœã®æŠèŠã説æããŸãã
Hirschmann RS20ç£æ¥çšã¹ã€ããã®ç 究
ãã¡ãŒã ãŠã§ã¢
ãŸãããã¡ãŒã ãŠã§ã¢ãå ¥æããå®è¡ããŠããããã»ããµã®çš®é¡ãç解ããããã°ã©ã/ãããã¬ãæ¥ç¶ããæ©èœãè©äŸ¡ããå¿ èŠããããŸãã ãããè¡ãããã«ãç§ãã¡ã¯äžãèŠãŠãèŠãŸããïŒ
- CPU Digi NET + ARM NS9360B-0-I155ã32ãããARM9ãå éšã¡ã¢ãªãªãïŒãããã£ãŠããã¡ãŒã ãŠã§ã¢ã¯å€éšã¡ã¢ãªã«ä¿åããå¿ èŠããããŸãïŒã
- 16 MB RAM Micron MT48LC8M16A2 SDRAM;
- 8 MB Intel 28F640JD3D75ãã©ãã·ã¥ã¡ã¢ãªïŒã»ãšãã©ã®å Žåããã¡ãŒã ãŠã§ã¢ã¯ãã¡ãïŒã
- CPLD Marvell 88E6095F-LG01ã¯ãã€ãŒãµãããã¹ã€ããã®æ©èœãå®è¡ããå éšæ§æã¡ã¢ãªãåããŠããŸãã
ãã©ãã·ã¥ã¡ã¢ãªãããã¯BGAããã±ãŒãžã§äœãããŠããŸãã åãå€ããšãèµ€å€ç·ã¯ãã ä»ãã¹ããŒã·ã§ã³ãªãã§ã¯ãã ä»ãããããšã¯éåžžã«å°é£ã«ãªããŸãã ãããã£ãŠããã®ã¹ã€ããã®ãã¡ãŒã ãŠã§ã¢ïŒããŒãžã§ã³8.0.07ïŒã¯ã ãªãŒãã³ãªHirschmann ftpãµãŒããŒããããŒãžãããŸããã
ããŠã³ããŒãããã¢ãŒã«ã€ãå ã®ãã¡ã€ã«ã®1ã€ã¯rsL2E.binãã€ããªïŒçŽ4 MBïŒã§ããããã¯ãã¡ãŒã ãŠã§ã¢ã€ã¡ãŒãžã§ãã 調ã¹ãŠã¿ããšã2ã€ã®ã¢ãžã¥ãŒã«ã§æ§æãããŠããããšãããããŸããã åã¢ãžã¥ãŒã«ã«ã¯ãããããŒïŒæ§é ã¯åãïŒãšå§çž®ãããæ¬æããããŸãã

æåã®ã¢ãžã¥ãŒã«ã¯zlibå§çž®ïŒRFC 1951ïŒã§ãã å®è¡å¯èœã³ãŒããå«ãŸããŠããŸãã é梱æã®ã¢ãžã¥ãŒã«ã®ééã¯çŽ7 MBã§ãã
2çªç®ã®ã¢ãžã¥ãŒã«ã¯gzipã¢ã«ãŽãªãºã ïŒRFC 1952ïŒã䜿çšããŠå§çž®ããã解ååŸãããã€ã¹ã®Webã€ã³ã¿ãŒãã§ãŒã¹ã®å®è£ ã§ããJARïŒJava ArchiveïŒãã¡ã€ã«ãååŸããpack200ã¢ãŒã«ã€ããå«ãŸããŸãã é梱åŸãã¢ãžã¥ãŒã«ã®ééã¯çŽ3 MBã§ãã ãšããã§ããã®ãã¡ã€ã«ã¯ãIPã¢ãã¬ã¹ã§ã¹ã€ããã«ã¢ã¯ã»ã¹ãããšãïŒã€ãŸããããã€ã¹ã®Webã€ã³ã¿ãŒãã§ãŒã¹ã«ã¢ã¯ã»ã¹ããããšãããšãïŒã«ãã¹ãïŒå¶åŸ¡PCïŒã«è»¢éããããã¹ãäžã§å®è¡ãããŸãã
é梱ãããã¢ãžã¥ãŒã«ã®ç·å®¹éã¯10 MBã§ãããã€ã¹ã®ã·ã¹ãã ããŒãã®ãã©ãã·ã¥ã¡ã¢ãªã¯8 MBã§ããããšãããããŸãã ãããã£ãŠããã¡ãŒã ãŠã§ã¢ã€ã¡ãŒãžã¯ããã¯åœ¢åŒã§ä¿åããããšæ³å®ããŸããã ãã®ããããã®ãã¡ãŒã ãŠã§ã¢ãå±éããŠèµ·åããããŒãããŒããŒãå¿ èŠã§ãã ããããããŒãããŒããŒã«ã€ããŠã¯åŸã§ã
åã¢ãžã¥ãŒã«ããããŒã®ãµã€ãºã¯256ãã€ãã§ãã ãã®æ§é ã¯ã©ãã«ãææžåãããŠããªãã®ã§ãç§åŠçãªæ¹æ³ã§å解ããå¿ èŠããããŸããã 泚ç®ãéãããã£ãŒã«ãïŒ
- ã¢ãžã¥ãŒã«çœ²å
- ã¢ãžã¥ãŒã«ã®ã¿ã€ãã
- ã¢ãžã¥ãŒã«ãµã€ãº;
- ã¢ãžã¥ãŒã«ãã§ãã¯ãµã ïŒCRC32ïŒ;
- ãã¡ã€ã«ã®æåŸãŸã§ã®ãªãã»ããïŒeofãªãã»ããïŒã
- ã¢ãžã¥ãŒã«ã®ãã§ãã¯ãµã ïŒç¹°ãè¿ãïŒïŒCRC32ïŒ;
- ããããŒãã§ãã¯ãµã ïŒCRC32ïŒã

ããã«åºã¥ããŠããã¡ãŒã ãŠã§ã¢ã®æŽåæ§ã®å¶åŸ¡ããããšçµè«ä»ããããšãã§ããŸãã ãã ããéåžžã¯é»åããžã¿ã«çœ²åïŒããžã¿ã«çœ²åïŒã§ããèªèšŒã¯ãããŸããã
ãããã®ãã¡ãŒã ãŠã§ã¢ãåœé ããæ©èœã確èªããå¿ èŠããããŸãããã®ããããã¡ãŒã ãŠã§ã¢ã€ã¡ãŒãžããäž¡æ¹ã®ã¢ãžã¥ãŒã«ããã°ããæœåºããããããå€æŽããåŸãå®æããã€ã¡ãŒãžã«æ»ãããšãã§ããå°ããªã¹ã¯ãªãããäœæããŸããã

ããããå€æŽãå ããåã«ãããã«ã€ããŠèããå¿ èŠããããŸãã ãããŠåããå€ããã
ãã¡ãŒã ãŠã§ã¢ã®å éšã«ã¯RTOSã³ãŒãïŒãªã¢ã«ã¿ã€ã ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒVxWorksããããããã«ããªãå€ãããŒãžã§ã³5.4.2ïŒ1998幎é ïŒãããããšãå€æããŸããã å·çæç¹ã§ã¯ãææ°ããŒãžã§ã³ã¯7ã§ãã
äžåœèªã®ãã€ã³ã¿ãŒããããã§VxWorks 5.5ã®ãœãŒã¹ãèŠã€ããŸãããããã«ãããããŸããŸãªOSæ©èœãlibcããã·ãŒãžã£ãªã©ã®èå¥ãå€§å¹ ã«å®¹æã«ãªããŸããã VxWorksã³ãŒãã®åæã¿ã¹ã¯ã«çŽé¢ããŠãã人ãªã誰ã§ãããVxWorksã®ç»åã«ã¯åžžã«ã·ã³ãã«ããŒãã«ããããŸãïŒããšæãã§ãããã ããã¯ãããŸããããã®åœ¢åŒã§ã¯ã»ãšãã©åœ¹ã«ç«ã¡ãŸããïŒ

VxWorksã¯ã¢ãžã¥ã©ãŒè£œåã§ãããã¢ãžã¥ãŒã«ã®æ§æã¯é¡§å®¢ããœãŒã¹ãè³Œå ¥ãããšãã«æ±ºå®ããŸãã ãã®å Žåãåºæ¬çãªã³ã³ããŒãã³ãã«å ããŠãWebãµãŒããŒã¢ãžã¥ãŒã«ïŒEmWebïŒãSnmpOverHttpïŒã¯ãããã£ããã£ããããã©ãã£ãã¯ã®HTTPãªã¯ãšã¹ãå ã®SNMPãã±ãããèŠãŸããïŒãªã©ãèŠãŸããã
ãã³ããŒã¯ééããªãè©°ãç©ã®äžè©±ãããŸããã
ããããã»ãã¥ãªãã£ã«ã€ããŠ-ããã§ã¯ãããŸããã ããã§ãç·åœ¢ã¢ãã¬ã¹ç©ºéãã³ãŒãå®è¡ã¯ã¡ã¢ãªå ã®ã©ãããã§ãå®è¡ã§ããã¹ã¿ãã¯ã®ãªãŒããŒãããŒãªã©ã«å¯Ÿããä¿è·ã¯ãããŸããã ãã€ããªè匱æ§ã®æªçšã«å¯Ÿããåºæ¬çãªä¿è·ã¡ã«ããºã ã¯å®å šã«ãããŸããã ãã¶ãããããã¯å¿ èŠãããŸãããïŒ ãããããã®ããŒãžã§ã³ã®VxWorksã«ã¯å€ãã®ç»é²ãããè匱æ§ããããŸãã
- CVE-2015-3963ã¹ããŒãã£ã³ã°TCPã»ãã·ã§ã³ã
- CVE-2010-2968ãã«ãŒããã©ãŒã¹;
- CVE-2010-2967ã¢ã¯ã»ã¹ãååŸããŸãã
- CVE-2010-2966ã¢ã¯ã»ã¹ãååŸããŸãã
- CVE-2010-2965 RCE;
- CVE-2008-2476 DoS;
- ...
DoSïŒãµãŒãã¹æåŠïŒãRCEïŒãªã¢ãŒãã³ãŒãå®è¡ïŒããã«ãŒããã©ãŒã¹æ©èœãèªèšŒãã€ãã¹ãªãã·ã§ã³ãªã©ããããã奜ã¿ã«åãããŠéžæããŸãã ãªã¹ãã¯å®å šã§ã¯ãããŸããã
ããããåæºããªãã§ãã ããïŒ å®éããã¡ãŒã ãŠã§ã¢ã®åæäžã«ãéåžžã«èå³æ·±ãã³ãŒãã®æçãèŠã€ãããŸããã
- SNMPèŠæ±ãã³ãã©ãŒ
- ã³ã³ãœãŒã«ã³ãã³ãã®ãã³ãã©ãŒã
- ãã©ãã·ã¥ã¡ã¢ãªã®èªã¿åããšæžãæãã
- Marvell CPLDæ§æã¡ã¢ãªã®èªã¿åããšäžæžãïŒ
å転ãä»ãããªãã¯æããããšãã§ããŸãã
ãããè¡ãã«ã¯ãå°å ¥ããã³ãŒãã®å Žæãæ£ããéžæããå¿ èŠããããŸããã¹ã€ããã®éåžžã®æ©èœã劚ããªãããã«ãããªã³ããã³ãã§åŒã³åºãã®ãæé©ã§ãã
æãããªéžæã¯ãã³ã³ãœãŒã«ã³ãã³ããã³ãã©ã®1ã€ã§ããã å ·äœçã«ã¯ããã°ã¢ãŠãã³ãã³ããã³ãã©ãŒã ãã¡ãŒã ãŠã§ã¢ã®ä»£ããã«ãæå®ãããã¢ãã¬ã¹ã§æå®ããããµã€ãºã®ã¡ã¢ãªãèªã¿åãïŒæ¿å ¥ããããã©ã°ã¡ã³ãã®æåŸã«ããå€æ°ã§ãã¹ãŠãèšå®ãããŸãïŒãCOMããŒãã§åé€ããããã³ãã衚瀺ããã³ãŒããèšè¿°ããŸããã

æ¢è£œã®ã€ã¡ãŒãžãäœæããããã§ã¹ã€ãããæŽæ°ããŸããïŒCOMããŒããšWebã€ã³ã¿ãŒãã§ãŒã¹ã®äž¡æ¹ã§ãã¡ãŒã ãŠã§ã¢ãæŽæ°ã§ããŸãïŒã æåïŒ å®éããã°ã¢ãŠãã®ä»£ããã«logoutã³ãã³ããå ¥åããåŸãã¡ã¢ãªãã³ããåºåãããããã«ãªããŸããã

ãããã£ãŠããã¡ãŒã ãŠã§ã¢ãåœé ããæ©èœã確èªãããŸããã
ããããæ»æè ãå®éã«å·¥æ¥çšãµã€ãã§äœ¿çšãããŠããã¹ã€ããã«ãã¡ãŒã ãŠã§ã¢ãæ¿å ¥ããæ¹æ³ã¯ãããŸããïŒ
COMããŒããä»ããŠïŒã€ãŸããã³ã³ãœãŒã«ã€ã³ã¿ãŒãã§ã€ã¹ãä»ããŠïŒæŽæ°ããå¯èœæ§ãèæ ®ããŠãã ããã ãã§ã«è¿°ã¹ãããã«ãã¹ã€ããã®ãã¡ãŒã ãŠã§ã¢ãæŽæ°ããã«ã¯ããŠãŒã¶ãŒåãšãã¹ã¯ãŒããç¥ãå¿ èŠã¯ãããŸããããããã€ã¹ã«ç©ççã«ã¢ã¯ã»ã¹ããå¿ èŠããããŸãïŒRS-232ã«æ¥ç¶ããããïŒã ããã€ã¹ãæ¢ã«æœèšã§äœ¿çšãããŠããå Žåããã®ãªãã·ã§ã³ã¯ä¿¡ããããŸããã
ãã ããå·¥å Žããã¯ãã¹ã€ããã¯ããã«å·¥æ¥æœèšã«ãããããŸããã 顧客ãžã®é ä¿¡ã¹ããŒã ã«ã¯ãç¡æã®ããŒãã¹ãšããŠããªãªãžãã«ã§ã¯ãªããã¡ãŒã ãŠã§ã¢ãã¹ã€ããã«ããŠã³ããŒãã§ããäžéçµç¹ãåžžã«ååšããŸãã
å¥ã®ãªãã·ã§ã³ïŒããã¯æ¢ã«é åžãã¯ãã«ã§ããïŒïŒCOMããŒããä»ããŠã¹ã€ããã«æ¢ã«æ¥ç¶ãããŠããã以åã«äŸµå®³ãããå¶åŸ¡PCããã¹ã€ãããã¡ãŒã ãŠã§ã¢ã«ææããããšãã§ããŸãã
ã¹ã€ããã®ãã¡ãŒã ãŠã§ã¢ããªã¢ãŒãã§å€æŽããããšã¯ããå°é£ã§ãããæ»æ察象ã¯ã¯ããã«åºããªããŸãã ã¹ã€ããã®Webã€ã³ã¿ãŒãã§ã€ã¹ã«ã¢ã¯ã»ã¹ããã«ã¯èªèšŒãå¿ èŠã§ããããšãæãåºããŠãã ããã äœãã§ããŸããïŒ è©Šãã«ã¯ïŒ
- ããã©ã«ãã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããå ¥åããŸãã
- æ¢ç¥ã®ãã¹ã¯ãŒãå¶éã«åºã¥ããŠéžæããŸãã 幞ããªããšã«ããã«ãŒããã©ãŒã¹æ»æã«å¯Ÿããä¿è·ã¯ãããŸããã
- ãã€ããªã®è匱æ§ïŒæ¢ç¥ãŸãã¯æ£çŽãªçºèŠïŒãæªçšããŸãããåã³ããã€ããªã®è匱æ§ã®æªçšã«å¯Ÿããä¿è·ã¯ãããŸããã
ãšããã§ããªã¢ãŒã-ããã¯ãã¹ã€ããã«æ¥ç¶ãããPCããã ãã§ã¯ãããŸããã ãŸãããã£ãŒã«ãããã€ã¹ã®1ã€ããããæã«ã¯ä¿è·ãããŠããªãé åã«é 眮ãããŸãã ãããã£ãŠãå¿ ãé»è©±ãåãå¿ èŠããããŸãïŒ
çµè«ã¯æ¬¡ã®ãšããã§ãã æœåšçãªæ»æè ã¯ãã³ãŒããã¹ã€ããã®ãã¡ãŒã ãŠã§ã¢ã«æ¿å ¥ãããšã次ã®ããšãå¯èœã«ãªããŸãã
- ã¹ã€ããCPUã§ã³ãŒããå®è¡ããŸãïŒããŒããŠã§ã¢ãªãœãŒã¹ã®å šç¯å²ã䜿çšïŒã
- ãã¹ãïŒå¶åŸ¡PCïŒãŸãã¯ã¹ã€ããã®IPã¢ãã¬ã¹ã«èª€ã£ãŠã¢ã¯ã»ã¹ããä»ã®ã¯ã©ã€ã¢ã³ãPCã®åŽã§ã³ãŒããå®è¡ããŸãã ãã¡ããããã®ã³ãŒãã¯Javaãã·ã³ã§å®è¡ãããŸããããåãã®ãšãããããã¯ã»ãã¥ãªãã£ã®é²æ³¢å €ã§ã¯ãããŸããã
䟵害ãããã¹ã€ããã¯ãéåžžã®ãã¡ãŒã ãŠã§ã¢æŽæ°æé ã«ãã£ãŠãæ²»çãã§ããããšã«æ³šæããŠãã ããã äž»ãªãã®ã¯ãæ°ããã€ã¡ãŒãžã®ä¿¡é Œæ§ã確信ããŠããããšã§ãã
ãããã«ãããããã¯ããã«ããã€ã¹ãä¿®æ£ããå¯èœæ§ã®åé¡ã«ã€ãªããããã¡ãŒã ãŠã§ã¢ã«å ããããå€æŽããã¹ãŠã®æŽæ°ããçãæ®ãããŸãã ãããŠãããŒãããŒããŒãæãåºããŸãããããã«ã¯ãã³ãããããŸããã§ããã
ããŒãããŒããŒ
ããŒãããŒããŒãRAMã«ãã¬ãŒã¹ãæ®ãããšãæåŸ ããŠãïŒäžèšã®ã³ãŒããã©ã°ã¡ã³ãã䜿çšããŠïŒå¥ã®å Žæã«ãã³ãããŸããããäœãèŠã€ãããŸããã§ããã ãããŠãã¹ã€ããã®ãã©ãã·ã¥ã¡ã¢ãªããååŸããŠããã©ãã·ã¥ã¡ã¢ãªãèªã¿åãããã®ä»¥åã«èŠã€ãã£ãæé ãåŒãåºãããšã«ããŸããã ãããŠåã³æåã
ãã®ããããã©ãã·ã¥ã¡ã¢ãªã®å 容ã¯3ã€ã®é åã«åå²ã§ããŸãã
- ããŒããããã¯ãæåã®80000hãã€ãã ããã¯ããŒãé åã§ããããã«ã¯ããŒãããŒããŒãããã3ã€ã®éšåã§æ§æãããŠããŸãã
- éå§ã³ãŒã;
- ã¡ã€ã³ã³ãŒãïŒãããã³ã¢ã«ãŽãªãºã ã«åŸã£ãŠå§çž®ïŒ;
- ããããŒïŒæ§é ã¯ãåè¿°ã®ãã¡ãŒã ãŠã§ã¢ã¢ãžã¥ãŒã«ã®ããããŒæ§é ãšåãã§ãïŒã
- æ倧ã®é åã§ããã¢ããªã±ãŒã·ã§ã³ãã¡ãŒã ãŠã§ã¢ã¯ãäºæ³ã©ãããããã±ãŒãžåããã圢åŒã§ããã«ä¿åãããŸãã
- ã¹ãã¬ãŒãžããµãŒãã¹æ å ±ãæ§æããã°ãªã©ãä¿åããããã®é å

ããŒãããŒããŒã³ãŒãã«ãããã¹ã€ããããŒãããã»ã¹ã®åæ段éãåæ§ç¯ã§ããŸããã
éå§æã«ããã©ãã·ã¥ã¡ã¢ãªã®æåã®4 KBïŒããã³ããã¯éå§ã³ãŒãã®ãµã€ãºã§ãïŒãCPUã®ã¢ãã¬ã¹0ã®ã¢ãã¬ã¹ç©ºéã«æ圱ãããŸãããã®ã¢ãã¬ã¹ããå®è¡ãéå§ãããŸãã
ããŒãããŒããŒã®éå§éšåã®ã¿ã¹ã¯ã¯ãã¡ã¢ãªã«ãŒããæ§æããããŒãããŒããŒã®äž»èŠéšåãã¡ã¢ãªã«å±éããå¶åŸ¡ã転éããããšã§ãã
ã¡ã€ã³ããŒãããŒããŒã³ãŒãã¯æ¬¡ã®ããã«ããå¿ èŠããããŸãã
- CPUããŒããŠã§ã¢ãªãœãŒã¹ãåæåããŸãã
- å²ã蟌ã¿ã¢ãã«ãæ§æããŸãã
- ãã¡ãŒã ãŠã§ã¢ãé梱ããå¶åŸ¡ã転éããŸãã

ããŒãããŒããŒãå€æŽããæ¹æ³ãããã«æãæµ®ãã³ãŸãã ã¹ã€ããã¯ããã©ãã·ã¥ã¡ã¢ãªãæäœããããã®æšæºæé ã䜿çšããŠãããŒããããã¯ãšãªã¢ãäžæžããããã¡ãŒã ãŠã§ã¢ã®ä¿®æ£ããŒãžã§ã³ã§æŽæ°ãããŸãã

å°æ¥ãä¿®æ£ãããããŒãããŒããŒã¯ãèµ·åãããã³ã«ã解åããããã¡ãŒã ãŠã§ã¢ã€ã¡ãŒãžãå€æŽã§ããããã«ãªããŸãã ãã®ããã«äŸµå®³ãããã䟵害ããããã¹ã€ããã¯ããã¯ãããã»ã©åçŽã§ã¯ãããŸããã

éåžžã®æ段ã䜿çšããŠã¹ã€ãããã硬åããããããšã¯å¯èœã§ããïŒ ãããè¡ãã«ã¯ããã¡ãŒã ãŠã§ã¢ãšããŒãããŒããŒã®äž¡æ¹ãå ã®ãã¡ãŒã ãŠã§ã¢ã«æŽæ°ããå¿ èŠããããŸãã
ã³ã³ãœãŒã«ã€ã³ã¿ãŒãã§ã€ã¹ã§ããŒãããŒããŒãæŽæ°ããå¯èœæ§ã¯ãããŸãããããã¡ãŒã ãŠã§ã¢ã®æŽæ°ãšåãæ¹æ³ã§ããŒããããã¯é åãæŽæ°ããããã®æé ããã¡ãŒã ãŠã§ã¢ã³ãŒãã«èŠã€ãããŸããã ãã ãããããã®é¢æ°ã¯ã©ãã§ãåŒã³åºãããªããããããã¯ææžåãããŠããªããããã°æ©èœã§ãã
ããããã¹ã€ããã®Webã€ã³ã¿ãŒãã§ã€ã¹ã§ã¯ãããŒãããŒããŒãæŽæ°ããããã®å®å šã«æšæºçãªãªãã·ã§ã³ãèŠã€ãããŸããã

å¯äžã®è³ªåã¯æŽæ°æ¹æ³ã§ããïŒ ããããäœãïŒ
ããã€ã¹ã®å€ãã®ã¢ãã«ã®ãã¡ãŒã ãŠã§ã¢ã€ã¡ãŒãžãå«ãã¢ãŒã«ã€ãã§ã¯ãHirschmannã¯ããŒãããŒããŒã€ã¡ãŒãžãé©çšããŸããã ãããŠããããã®éã§èª¿æ»ãããã¢ãã«ã
ãã¯ãã«ã«ãµããŒãã«é£çµ¡ããŠããŒãããŒããŒã€ã¡ãŒãžãååŸããããšãã§ããŸããã è©ŠããŠã¿ããšãããããŒãããŒããŒã€ã¡ãŒãžã¯é åžãããŠããªããšã®çããåŸãŸããã 圌ãããåŸãããšãã§ããå¯äžã®ããšã¯ãRMAãã©ãŒã ã䜿çšããŠåœŒãã«ããã€ã¹ãéä¿¡ããææ¡ã§ããã ãããã圌ãã¯ããããæ¹æ³ã§ãããè¡ãããšãæããšã©ãŸãããã§ãããã
ãããã£ãŠãæœåšçãªæ»æè ã¯ããã¡ãŒã ãŠã§ã¢ã®å€æŽã«ããããã€ã¹ããŒããŒã§ä¿®æ£ããããšãã§ããŸãã ãããŠã圌ãå®æçãªæ段ã§ããããè¿œãåºãããšã¯ã»ãšãã©äžå¯èœã§ãã
ããã«æ·±ãæãããšã¯å¯èœã§ããïŒ
çŸæç¹ã§ã¯ããã®è³ªåã«å¯Ÿããåçã¯ãããŸããããã¢ã€ãã¢ã¯è¡šæãããŸãã
ãã®ããã€ã¹ã«ã¯ãäœããã®æ¹æ³ã§ç¬èªã®ãã¡ãŒã ãŠã§ã¢ãåããå¥ã®å®è¡å¯èœç°å¢ãããããšãæãåºããŠãã ããã ããã¯ãäžæ®çºæ§æ§æã¡ã¢ãªãå èµããããŒãã«CPLDã¿ã€ãã®FPGAïŒããã°ã©ããã«ããžãã¯éç©åè·¯ïŒã§ãã
ãããã®ããã°ã©ã ã¯ãããžãã¯èšè¿°èšèªïŒVHDLãVerilog-æãäžè¬çïŒã§èšè¿°ãããŠããŸãã ã¹ã€ããã®ãã¡ãŒã ãŠã§ã¢ã³ãŒãã§ããã®æ§æã¡ã¢ãªã®èªã¿åããšäžæžãã®ããã®é¢æ°ãèŠã€ããããšãæãåºããŠãã ããã
ç£æ¥çšã¹ã€ããPhoenix Contact FL SWITCH MM HSã®ç 究
ãã®ã¹ã€ãããæ¢çŽ¢ãããšããåãæ¹æ³ã§ãããé«éã«ãªããŸããã å éšã®èå³æ·±ããã®ïŒ
- CPU PMC RM5231Aã32ãããMIPS IVãå éšã¡ã¢ãªãªãã
- RAM SDRAM Micron MT48LC8M16A2 16 MBã2åã
- Inteläžæã¢ãã«ã®ãã©ãã·ã¥ã¡ã¢ãªã
- ãããã»ããã¬ãªã¬ãªGT-64115ã
ãã®ã¹ã€ããã®ãã¡ãŒã ãŠã§ã¢ã€ã¡ãŒãžããã³ããŒã®å ¬åŒWebãµã€ãããããŠã³ããŒãããåæ§ã«ãã®æ§é ãå解ããŸããã ããããŒãšzlibå§çž®ïŒRFC 1951ïŒæ¬äœããããŸãïŒ

ããããŒæ§é ã®äž»ãªãã£ãŒã«ãã¯æ¬¡ã®ãšããã§ãã
- 眲å
- ããããŒãã§ãã¯ãµã ïŒADLER32ïŒ
- 解åãããããã£ãã§ãã¯ãµã ïŒADLER32ïŒ;
- é梱ãããæ¬äœã®ãµã€ãºã
- ããã¯ããã£ãã§ãã¯ãµã ïŒADLER32ïŒ;
- ããã±ãŒãžåãããæ¬äœãµã€ãºã

ããã«ã¯ãã¡ãŒã ãŠã§ã¢ã®èªèšŒããããŸããããããå®éšçã«æ€èšŒããŸããã
VxWorksãããã«ãããŸããããããã«æ°ããããŒãžã§ã³6.1ã«ãåãåé¡ããããŸãããã€ããªã®è匱æ§ã®æªçšã«å¯Ÿããä¿è·ã¡ã«ããºã ã®æ¬ åŠãšç»é²æžã¿ã®CVEã®æã§ãã
åãæ¹æ³ã§ãã¡ãŒã ãŠã§ã¢ãæŽæ°ã§ããŸãã
- COMããŒãçµç±ã§ãèªèšŒãå¿ èŠãããŸãã
- Webã€ã³ã¿ãŒãã§ãŒã¹çµç±ã ã¢ã¯ã»ã¹ããã«ã¯ããã°ã€ã³ãšãã¹ã¯ãŒããå ¥åããå¿ èŠã¯ãããŸããããèšå®ãå€æŽãããšãïŒãŸãã¯ãã¡ãŒã ãŠã§ã¢ãæŽæ°ãããšãïŒããã¹ã¯ãŒããç¥ã£ãŠããå¿ èŠããããŸãã
ãã¹ã¯ãŒããšããã°ã ããã¥ã¡ã³ãã«ãããšãçŸåšã®ãã¹ã¯ãŒãã倱ãããå ŽåïŒãŸãããŸãã¯ããã«ãŒã®å Žåã¯æ±ºããŠååŸãããªãïŒã«åããŠããšã³ãžãã¢ãªã³ã°ãã¹ã¯ãŒãããããŸãã ãããè¡ãã«ã¯ãã¹ã€ããã®MACã¢ãã¬ã¹ãšã·ãªã¢ã«çªå·ãæäŸããŠãã¯ãã«ã«ãµããŒãã«é£çµ¡ããå¿ èŠããããŸãã
ããã¯ããããã®æ°å€ããšã³ãžãã¢ãªã³ã°ãã¹ã¯ãŒãã«å€æããã¢ã«ãŽãªãºã ãããããšã瀺åããŠããŸãã
ãã®ã¹ã€ããã«ã¯ãäžæžãå¯èœãªããŒãããŒããŒããããŸãã ãããŠãããã¯å®éšçã«èšŒæãããŠããŸãã ããŒãããŒããŒãæŽæ°ããããã®éåžžã®æ©èœã¯ãŸã£ãããããŸããã
ãããã«
ãã®èª¿æ»ã®çµæãç£æ¥çšã¹ã€ããã®ã¢ãŒããã¯ãã£ã«æ¬¡ã®æ¬ é¥ãç¹å®ãããŸããã
- ãã¡ãŒã ãŠã§ã¢ãäžæ£ã«æŽæ°ããæ©èœïŒäžéšã®éåžžã®æé ã§ã¯ãèªèšŒã¯äžèŠã§ãïŒã
- ããã€ã¹ã®ãã¡ãŒã ãŠã§ã¢ã€ã¡ãŒãžãåœé ããæ©èœïŒããŒãããŒããŒãCPLDãã¡ãŒã ãŠã§ã¢ãªã©ïŒ ã³ãŒãèªèšŒã®æ¬ åŠ;
- ãã€ããªè匱æ§ã®æªçšã«ããã¡ã«ããºã ã¯ãããŸãããããã«ãããã¹ã€ããã§ã®ãªã¢ãŒãã³ãŒãå®è¡ã®å¯èœæ§ãããã«åºãããŸãã
調æ»ã®éçšã§ãã¹ã€ãããã¡ãŒã ãŠã§ã¢ãåœé ããæ©èœãšãããŒãããŒããŒãžã®å€æŽãåºå®ããæ©èœã瀺ããŸããã
èŠããã«ãçŽ æŽãããã
æ£ããããã¡ãŒã ãŠã§ã¢ã®ã»ãã¥ãªãã£ã¢ãã«ã®å®éã®äŸã¯ã次ã®èšäºã§æ€èšããŸãã