以äžã§äœ¿çšããããã¹ãŠã®ãªã³ã¯ã¯ãã©ããééã£ãå Žæã«ã€ãªããå Žåã®äŸãšããŠäœ¿çšãããŸãã
ãã®èšäºã¯ã forxakep.ucoz.ru / publ / 3-1-0-16ãããå ¥æã§ããŸãã
forum.netall.ru/index.php?showtopic=125182&st=0&p=1573116&#entry1573116
www.inattack.ru/article/402.html
é£ãïŒãŸãã¯ãã£ãã·ã³ã°ïŒã
éåžžã«åºãæŠå¿µã ãã®æå³ã¯ããŠãŒã¶ãŒïŒãã¹ã¯ãŒããã¯ã¬ãžããã«ãŒãçªå·ãªã©ïŒãŸãã¯ãéããæ å ±ãååŸããããšã§ãã ãã®ææ³ã¯ã1人ã®ãŠãŒã¶ãŒã§ã¯ãªããå€ãã®ãŠãŒã¶ãŒã察象ãšããŠããŸãã ããšãã°ãæè¡ãµããŒãããã®æçŽãéè¡ã®ãã¹ãŠã®æ¢ç¥ã®é¡§å®¢ã«éä¿¡ãããŸãã éåžžãæçŽã«ã¯ãæè¡çãªäœæ¥ã®ããã«ãã¢ã«ãŠã³ãã«ãã¹ã¯ãŒããéä¿¡ãããªã¯ãšã¹ããå«ãŸããŠããŸãã åŸæ¥å¡ã¯èª°ããã®ãããªæ å ±ãèŠæ±ããããšã¯ã§ããããã®æ å ±ãé瀺ãã¹ãã§ã¯ãªããšãŠãŒã¶ãŒã«èŠåãããŠããã«ãããããããçªå·ããã¹ã¯ãŒããªã©ããäžãããããšã«æºè¶³ããŠãã人ã¯åžžã«ããŸãã ãã®ãããªæçŽã¯éåžžéåžžã«ä¿¡ããããŠãããæ§æããããã ãŸããããããŠãŒã¶ãŒãè²·åããå¯èœæ§ããããŸãã ãã£ãã·ã³ã°ã«ã¯ãæåã«å ããŠããã€ãã®æ¹æ³ãããããšã«æ³šæããŠãã ããã 以äžã®ææ³ã®äžéšã¯ãæ£ãã䜿çšãããå Žåããã£ãã·ã³ã°ã«é©ããŠããŸãïŒååãšããŠãææ³ã®èª¬æã§ãããèšåããŠããŸãïŒã
æšå¥šäºé ïŒãã©ãã€ã¢ãæè¯ã®é²åŸ¡ã§ããããšãå¿ããªãã§ãã ããã çããããã®ãä¿¡é Œããªãã§ãã ãããããŒã¿ã誰ãšãå ±æããªãã§ãã ããã ãã¹ã¯ãŒãããµãŒããŒã«ã¢ã¯ã»ã¹ããããã«èšèšãããŠããå Žåã管çè ã¯ãã¹ã¯ãŒããç¥ãå¿ èŠã¯ãããŸããã ãµãŒããŒãå®å šã«å¶åŸ¡ãããã¹ã¯ãŒãèªäœã確èªããããå€æŽãããã§ããŸãã
ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°
æè¡çã§ã¯ãªããå¿ççãªãã¯ããã¯ã§ãã ã€ã³ãã³ããªäžã«ååŸããããŒã¿ã䜿çšããŠãã¯ã©ãã«ãŒã¯ç®¡çè ã«ä»£ãã£ãŠäžéšã®ãŠãŒã¶ãŒïŒäŒæ¥ãããã¯ãŒã¯ãªã©ïŒã«é»è©±ãããããã¹ã¯ãŒããªã©ãèŠã€ããããšããŸãã ããã¯ã倧èŠæš¡ãªãããã¯ãŒã¯ã§ãŠãŒã¶ãŒããã¹ãŠã®åŸæ¥å¡ãææ¡ããŠããªãå Žåã«å¯èœã«ãªããããã«ã¯ãé»è©±ã§åžžã«æ£ç¢ºã«èªèã§ããªãå ŽåããããŸãã ããã«ãè€éãªå¿ççææ³ã䜿çšããããããæåã®å¯èœæ§ãå€§å¹ ã«é«ãŸããŸãã
æšå¥šäºé ïŒåãã æ¬åœã«å¿ èŠãããå Žåã¯ãå¿ èŠãªããŒã¿ãçŽæ¥æäŸããŠãã ããã ãã¹ã¯ãŒããçŽã«æžãçããå Žåã¯ããã¹ã¯ãŒããã©ãã«ãæ®ããªãã§ãå¯èœã§ããã°ç Žæ£ãããŽãç®±ã«æšãŠãã ãã§ã¯ãããŸããã
ãŠã€ã«ã¹ã
æãåçŽãªãŠãŒã¶ãŒã®åé¡ã«ç¥ãããŠããŸãã äžçªäžã®è¡ã¯ããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒãžã®ãã«ãŠã§ã¢ã®å°å ¥ã§ãã çµæã¯ç°ãªãå Žåããããã³ã³ãã¥ãŒã¿ãŒãææããŠãããŠã€ã«ã¹ã®çš®é¡ã«ãã£ãŠç°ãªããŸãã ããããäžè¬çã«ã¯-æ å ±ã®ççšããã¹ãã ã®éä¿¡ãDDoSæ»æã®çµç¹åãã³ã³ãã¥ãŒã¿ãŒã®å®å šãªå¶åŸ¡ã®ååŸãŸã§ã ã¬ã¿ãŒã«æ·»ä»ããããã¡ã€ã«ã«å ããŠããŠã€ã«ã¹ã¯OSã®è匱æ§ãä»ããŠã³ã³ãã¥ãŒã¿ãŒã«äŸµå ¥ããå¯èœæ§ããããŸããããã«ã€ããŠã¯ãèšäºãWindows Vulnerability Ratingãã§èª¬æããŠããŸãã å€ãã®ãŠã€ã«ã¹ããããŸãããããããåé¡ããããšã¯ãŸã å¯èœã§ãã è»èŒªãåçºæããããªãã®ã§ããã®ããŒãžschool8.uriit.ru/people/av/class.htmlã®æ å ±ã䜿çšããŠã説æä»ãã®ãŠã€ã«ã¹ã®åé¡ã瀺ããŸãã ãã®ãããã¯ã®è©³çŽ°ã«ã€ããŠã¯ã fivt.krgtu.ru / kafedri / mo / site / ANTIVIRUS / pages / 02.htmãã芧ãã ããã
æšå¥šäºé ïŒãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã䜿çšããŸãã DrWEBãŸãã¯Kaspersky Anti-VirusïŒã¬ãžã¹ããªããã§ãã¯ããªãããïŒã®ã¿ã«éå®ãããAd-AwareãSpyBotãXSpyãªã©ã®ãã«ãŠã§ã¢ã«å¯Ÿããç¹å¥ãªãŠã€ã«ã¹å¯Ÿçã䜿çšããŠãã ããã ãŸããçãããæ·»ä»ãã¡ã€ã«ãéããããæªç¥ã®éä¿¡è ããã®ããã°ã©ã ãéãããããªãã§ãã ããã éä¿¡è ãããç¥ã£ãŠããŠããæåã«ãŠã€ã«ã¹å¯Ÿçããã§ãã¯ããŠãã ããã ããã§ã¯ãå»åŠã®ããã«ãåŸã§æ²»ããããé¿ããã»ããç°¡åã§ãã
DoSïŒãµãŒãã¹æåŠãŸãã¯ãµãŒãã¹æåŠïŒã
ããã¯å¥ã®æ»æã§ã¯ãªããæ»æã®çµæã§ãããšèšãããã£ãã®ã§ãã ã·ã¹ãã ãŸãã¯åã ã®ããã°ã©ã ãç¡å¹ã«ããããã«äœ¿çšãããŸãã ãããè¡ãããã«ãã¯ã©ãã«ãŒã¯ç¹å¥ãªæ¹æ³ã§ããã°ã©ã ãžã®ãªã¯ãšã¹ããäœæãããã®åŸæ©èœãåæ¢ããŸãã ããã°ã©ã ãåäœç¶æ ã«æ»ãã«ã¯ãåèµ·åãå¿ èŠã§ãã DoSã¯Floodã¿ã€ãã®æ»æãšåãã§ãããäžè¬ã«ãDoSãšããäžè¬åã§ã·ã¹ãã ã®é害ã«ã€ãªãããã¹ãŠã®æ»æãçµã¿åãããå¿ èŠããããšèããããŠããŸãã ããã«èšåãã䟡å€ããããŸãïŒ
-äžè¬çãªçšèªã¯ãªããæ»æãåé¡ããããã®ããªãæé»ã®ã«ãŒã«ããããŸãããã®ããããã®èšäºã®ãã¬ãŒã ã¯ãŒã¯å ã§ããããçšåºŠäžè¬çãªåé¡ãè¡ããŸãã
-æ¢ã«è¿°ã¹ãããã«ãFloodã ãã§ãªããããšãã°ãBuffer Overflowã¯ããµãŒãã¹æåŠã«ã€ãªããå¯èœæ§ããããŸãã
ãããã£ãŠãDoSã¯æ»æã®çµæãšããŠèª¬æã§ããŸãã äŸïŒããµãŒãã¹æåŠã®åœ±é¿ã¯ããã©ããæ»æã䜿çšããŠéæãããŸããã
措氎ïŒæŽªæ°ŽãŸãã¯æ²³å·/措氎ïŒ
ãã®ã¿ã€ãã¯ããªãè°è«ã®äœå°ããããäžéšã¯DoSã«èµ·å ããå¯èœæ§ããããŸãããå¥é匷調ããããšæããŸãã å€ãã®ãã·ã³ããïŒãã®å Žåãæ»æã¯DDoSåæ£ãµãŒãã¹æåŠæ»æãšåŒã°ããŸããåæ£ãµãŒãã¹æåŠæ»æãšåŒã°ããŸãïŒãååãšããŠããŸã³ãã¯è¢«å®³è ã«å¯èœãªéãæ倧æ°ã®èŠæ±ïŒæ¥ç¶èŠæ±ãªã©ïŒãéä¿¡ããŸãã ãã®ããšããã被害è ã¯åãªã¯ãšã¹ãã«å¿çããæéããªãããã®çµæããŠãŒã¶ãŒã®ãªã¯ãšã¹ãã«å¿çããŸããã æ£åžžã«æ©èœããªããªã£ããšèšããŸãã 泚ïŒãã®ã¿ã€ãã®æ»æã¯ãããšãã°ãã©ãŒã©ã ãç¡æå³ãªã¡ãã»ãŒãžã§ãã£ã±ãã«ãªã£ãŠããå ŽåãããŒãªã¬ã³äž»çŸ©ãšåŒã°ããŸãã 次ã®Floodã¿ã€ããåºå¥ã§ããŸãã
--SYN Flood-æ»æãããã³ã³ãã¥ãŒã¿ãŒãSYNãã±ããã§ãã©ããã£ã³ã°ããŸãã ãåãã®ããã«ãã³ã³ãã¥ãŒã¿ã¯ãã®ãããªãã±ããã«SYN / ACKã¿ã€ãã®ãã±ããã§å¿çããå¿ èŠããããŸãã SYNãã±ãããå€ãããå Žåãã³ã³ãã¥ãŒã¿ãŒã¯ããããã«å¿çããæéããªããä»ã®ã³ã³ãã¥ãŒã¿ãŒãããã±ãããåä¿¡ã§ããŸããã
--ICMP FloodãŸãã¯Ping Flood-åãããšãICMPãã±ããã®ã¿ã ã·ã¹ãã ã¯ãã®ãããªãã±ããã«å¿çããå¿ èŠããããŸããããã«ããããã£ãã«ã®ããã©ãŒãã³ã¹ïŒåž¯åå¹ ïŒãäœäžãããå€æ°ã®ãã±ãããäœæãããŸãã
--Identification FloodïŒIdent FloodïŒã ICMP Floodã«äŒŒãŠããŸãããã¿ã€ãidentdã®ããŒã113ã«å¯ŸããèŠæ±ãžã®å¿çã«ã¯ã·ã¹ãã ããã®æéãããããããæ»æã¯ããå¹æçã§ãã
--DNS Flood-æ»æã¯DNSãµãŒããŒã«åããããŸãã ãµãŒããŒã«ã¯å¿çããæéããªãDNSã¯ãšãªã殺å°ããŠãããããã¯ãšãªã«ãå¿çã§ããŸããã ãã®çµæãã€ã³ã¿ãŒããããµã€ãã«ã¢ã¯ã»ã¹ã§ããªããªããŸãã
--DDoS DNS-æ»æã¯ãŸã£ããæ°ãããã®ã§ããããå®è©ã®ãããååãæºãããŠããŸããã§ããã å®éããã®ææ³ã¯ä»¥åã®ææ³ãšã»ãŒåãã§ãããå¯äžã®éãã¯ããªã¯ãšã¹ããå€æ°ã®ãã·ã³ããéä¿¡ãããããšã§ãïŒä»¥åã®ã¿ã€ãã¯ãããé€å€ããŸããïŒã DNSãµãŒããŒããããã®èŠæ±ã«å¿çããã¢ãã¬ã¹ã¯ãDNSãµãŒããŒèªäœã®ã¢ãã¬ã¹ãšåãã§ãã 圌ã¯DNSã¯ãšãªã§ããµããŠããã ãã§ãªãã圌èªèº«ã«ãããããéä¿¡ããŸãã ãããã£ãŠãåä¿¡ã¯åã®åä¿¡ãããå¹æçã§ãããå®è£ ããã®ãããå°é£ã§ãã
--BoinkïŒBonkãTeardropïŒ-éåžžã«æçåãããèšå€§ãªæ°ã®ãã±ããã被害è ã«éä¿¡ãããŸãããæçã¯å€§ãããªããŸãã æçåããããã±ããããšã«ãåŸã§ä»ã®ãã©ã°ã¡ã³ããé 眮ã§ããããã«ãåŸã§ä»ã®ãã©ã°ã¡ã³ããé 眮ãããç¹å¥ãªãããã¡ãå²ãåœãŠãããŸãã èšå€§ãªæ°ã®å€§ããªãã©ã°ã¡ã³ãããããã¡ããªãŒããŒãããŒããããªãŒãºãŸãã¯ã¯ã©ãã·ã¥ãåŒãèµ·ããå¯èœæ§ããããŸãã
--Pongã¯äžèšã®ä»ã®ã¿ã€ããšåãã§ãããå¯äžã®éãã¯éä¿¡è ã¢ãã¬ã¹ãåœç©ã§ããããšã§ãã ããã«ãããã¯ã©ãã«ãŒã«å¿åæ§ãäžããããŸãã
æšå¥šäºé ïŒOSãŸãã¯ã«ãŒã¿ãŒããšã ãããã¯éåžžãæè¡ææžã«èšèŒãããŠããŸãã ããããç¡èŠããªãã§ãã ãããæå¹ãªãã±ããã®æ°ãæ確ã«å¶éããŠãã ããã æ®å¿µãªãããäžéšã®çš®ã¯ç©ççãªåæ以å€ã«ã¯åæ ã§ããŸããã é©åã«æ§æããããã¡ã€ã¢ãŠã©ãŒã«ïŒãŸãã¯ãã¡ã€ã¢ãŠã©ãŒã«ïŒã¯ãå€ãã®å Žåãäžèœè¬ã§ãã
SmurfïŒTCP-IPãããã³ã«ã®å®è£ ãšã©ãŒãçã£ãæ»æïŒ
çŸåšããã®ã¿ã€ãã®æ»æã¯ãšããŸããã¯ãšèŠãªãããŠããŸããã以åã¯ãTCP-IPãããã³ã«ãããªãæ°ãããã®ã§ãã£ããããããšãã°IPã¢ãã¬ã¹ã眮ãæããããšãã§ããå€ãã®ãšã©ãŒãå«ãŸããŠããŸããã ãã ãããã®ã¿ã€ãã®æ»æã¯åŒãç¶ãé©çšãããŸãã äžéšã®å°é家ã¯ãTCP SmurfãUDP SmurfãICMP SmurfãææããŠããŸãã ãã¡ããããã®åºåã¯ããã±ãŒãžã®ã¿ã€ãã«åºã¥ããŠããŸãã
æšå¥šäºé ïŒCISCOã¹ã€ããã¯ãä»ã®å€ãã®è£œåãšåæ§ã«ãæ°ãããœãããŠã§ã¢ãšãã¡ã€ã¢ãŠã©ãŒã«ã ãã§ãªããåªããä¿è·ãæäŸããŸãã ãããŒããã£ã¹ãèŠæ±ããããã¯ããå¿ èŠããããŸãã
Ping-of-DeathïŒãŸãã¯JoltãSSPingïŒ
æ»æã¯ããã©ã°ã¡ã³ãåãããICMPãã±ããã被害è ã«éä¿¡ããããããã©ã°ã¡ã³ããµã€ãºãéåžžã«å€§ããïŒ64kBïŒãšããããšã§ãã Windows 95ãªã©ã®å€ãããŒãžã§ã³ã®OSããã³ã°ããŸãã ãã®æ»æã¯ãã·ã£ããŠã»ãã¥ãªãã£ã¹ãã£ããŒã䜿çšããŠå®è¡ã§ããŸãã
æšå¥šäºé ïŒOSãæŽæ°ããå€ãããŒãžã§ã³ãæŸæ£ããã®ãæãç°¡åã§ãã
UDPã¹ããŒã ïŒUDPã¹ããŒã ïŒ
被害è ã§å°ãªããšã2ã€ã®UDPããŒããéããŠããããããããéä¿¡è ã«å¿çãéä¿¡ããå Žåã«äœ¿çšãããŸãã ããšãã°ãã¿ã€ã ãµãŒããŒã®ããããŒã37ã¯ãçŸåšã®æ¥ä»ãšæå»ãèŠæ±ã«éä¿¡ããŸãã ã¯ã©ãã«ãŒã¯ã被害è ã®ããŒãã®1ã€ã«UDPãã±ãããéä¿¡ããŸãããéä¿¡è ã¯è¢«å®³è ã®ã¢ãã¬ã¹ãšè¢«å®³è ã®2çªç®ã«éããŠããUDPããŒãã瀺ããŸãã ãã®åŸãããŒãã¯äºãã«ç¡éã«å¿çãå§ããããã©ãŒãã³ã¹ãäœäžããŸãã ã¹ããŒã ã¯ããã±ããã®1ã€ãæ¶ãããšããã«åæ¢ããŸãïŒããšãã°ããªãœãŒã¹ã®éè² è·ã®ããïŒã
æšå¥šäºé ïŒå¯èœã§ããã°ãUDPãã±ãããåãå ¥ãããµãŒãã¹ã®äœ¿çšãé€å€ãããããã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããŠå€éšãããã¯ãŒã¯ããåæããŸãã
UDPãã
ã¯ã©ãã«ãŒã¯ãäžæ£ãªãµãŒãã¹ããŒã¿ãã£ãŒã«ããå«ãUDPãã±ãããUDPã·ã¹ãã ã«éä¿¡ããŸãã å¿ èŠã«å¿ããŠããŒã¿ã«éåããå¯èœæ§ããããŸãïŒããšãã°ããã£ãŒã«ãé·ãæ§é ãæ£ãããªãïŒã ããã«ãããã¯ã©ãã·ã¥ããå¯èœæ§ããããŸãã
æšå¥šäºé ïŒãœãããŠã§ã¢ãæŽæ°ããŸãã
åå°
ãã±ããã¯ç¹å®ã®ããŒãã§è¢«å®³è ã«éä¿¡ãããŸãããéä¿¡è ã®ã¢ãã¬ã¹ã¯è¢«å®³è ãšåãã¢ãã¬ã¹ã«èšå®ãããéä¿¡è ã®ããŒãã¯åä¿¡è ã®ããŒããšçãããªããŸãã ïŒäŸïŒåä¿¡è ïŒ1.1.1.1ããŒã111éä¿¡è ïŒ1.1.1.1ããŒã111ïŒã 被害è ã¯èªåãšã®æ¥ç¶ã確ç«ããããšããŠãããããã·ã¹ãã ããã³ã°ããå¯èœæ§ããããŸãã åæ§ã®æ»æã¯ãäžéšã®ã«ãŒã¿ãŒã«å¯ŸããŠã100ïŒ å¹æçã§ãã
ã¡ãŒã«çæ
æ»æãããã³ã³ãã¥ãŒã¿ãŒã«ã¡ãŒã«ãµãŒããŒãããå Žåããããç¡å¹ã«ããããã«èšå€§ãªæ°ã®ã¡ãŒã«ã¡ãã»ãŒãžãéä¿¡ãããŸãã äžæ¹ã§ãããã¯Floodãé£æ³ãããŸãããäžæ¹ã§ããµãŒããŒã®ãŠã€ã«ã¹å¯ŸçãœãããŠã§ã¢ã«ãã£ãŠã¹ãã£ã³ããã倧ããªæ·»ä»ãã¡ã€ã«ãã¡ãã»ãŒãžã«å«ãŸããŠããå Žåããã®ãããªå€æ°ã®çä¿¡æ·»ä»ãã¡ã€ã«ã®ã¹ãã£ã³ã¯ãããã©ãŒãã³ã¹ãå€§å¹ ã«äœäžããããããŸãã¯äœãæžããããšãã§ããŸããã ããã«ããã®ãããªã¡ãã»ãŒãžã¯ãµãŒããŒã®ããŒããã£ã¹ã¯ã«ä¿åããããªãŒããŒãããŒããå¯èœæ§ããããDoSãåŒãèµ·ããå¯èœæ§ããããŸãã ãã¡ãããä»ã§ã¯ãã®æ»æã¯åãªãç©èªã«éããŸããããå Žåã«ãã£ãŠã¯äŸç¶ãšããŠäœ¿çšã§ããŸãã
æšå¥šäºé ïŒã¡ãŒã«ãµãŒããŒã®é©åãªæ§æã
ã¹ãããã£ã³ã°
ãããã¯ãŒã¯å ã®ã¹ã€ããã®ä»£ããã«ãããã€ã³ã¹ããŒã«ãããŠããå Žåãåä¿¡ãããã±ããã¯ãããã¯ãŒã¯äžã®ãã¹ãŠã®ã³ã³ãã¥ãŒã¿ãŒã«éä¿¡ãããã³ã³ãã¥ãŒã¿ãŒã¯ãããã®ããã±ãŒãžã決å®ããŸãã ã¯ã©ãã«ãŒããã®ãããªãããã¯ãŒã¯ã«å«ãŸããã³ã³ãã¥ãŒã¿ãŒã«ã¢ã¯ã»ã¹ãããããããã¯ãŒã¯ã«çŽæ¥ã¢ã¯ã»ã¹ãããšããã¹ã¯ãŒããå«ããããã¯ãŒã¯ã»ã°ã¡ã³ãã®åé åžã§éä¿¡ããããã¹ãŠã®æ å ±ãå©çšå¯èœã«ãªããŸãã æ»æè ã¯åã«ãããã¯ãŒã¯ã«ãŒãããªã¹ãã³ã°ã¢ãŒãã«ããæå³ãããŠãããã©ããã«é¢ä¿ãªããã¹ãŠã®ãã±ãããåãå ¥ããŸãã TcpDumpïŒãã«ãã€ã³* NIXã·ã¹ãã ïŒãWinDumpïŒWindowsããã«ãã€ã³ã§ã¯ãªãïŒãªã©ã®ã³ã³ãœãŒã«ã¹ããã¡ãŒãšããŠäœ¿çšã§ããã ãã§ãªããIrisãªã©ã®èŠèŠåãããã€ã³ã¿ãŒãã§ã€ã¹ã§ã䜿çšã§ããŸãã
æšå¥šäºé ïŒããã®ä»£ããã«ã¹ã€ããã䜿çšãããã©ãã£ãã¯ãæå·åããŸãã
IPãã€ãžã£ãã¯
ãããã¯ãŒã¯ãžã®ç©ççãªã¢ã¯ã»ã¹ãããå Žåãã¯ã©ãã«ãŒã¯ãããã¯ãŒã¯ã±ãŒãã«ã«ãã¯ã©ãã·ã¥ããããã±ããã®éä¿¡ã®ä»²ä»è ãšããŠåäœããããã2å°ã®ã³ã³ãã¥ãŒã¿ãŒéã®ãã¹ãŠã®ãã©ãã£ãã¯ããªãã¹ã³ããŸãã ä»ã®ã¡ãœãããå®è£ ã§ããªãå Žåãé€ããŠããã°ãã°ããèªäœãæ£åœåããªãéåžžã«äžäŸ¿ãªã¡ãœããã ãã®ãããªçµã¿èŸŒã¿èªäœã¯äžäŸ¿ã§ããããã®ã¿ã¹ã¯ãå°ãç°¡çŽ åããããã€ã¹ããããŸãããç¹ã«ãé害ããã£ãã«ãžã®äŸµå ¥ã®æ€åºãåé¿ããããã«ãã±ããã®çªå·ä»ããç£èŠããŸãã ãã®æ¹æ³ã¯ATMãã ãŸãããã«äœ¿çšãããŸãããéè¡ãšATMéã®æ¥ç¶ã¯åãå ¥ããããªãããããã®ã±ãŒã¹ã¯æè¡çã«é£ããããã£ãã«ãäžæããã«ãçªå ¥ãããã®ã¯é«åºŠãªè³æ Œãæã€å°é家ã®ã¿ã§ãã ããã«ãATMã®ã€ã³ã¹ããŒã«ãå€§å¹ ã«æ¹åãããã±ãŒãã«ãžã®ç©ççãªã¢ã¯ã»ã¹ãç¡æã«ãªãå¯èœæ§ããªããªããŸããã
æšå¥šäºé ïŒããã¯ã¹ãžã®ã¢ã¯ã»ã¹ãªã©ãã±ãŒãã«ãžã®ã¢ã¯ã»ã¹ã«æ³šæããŠãã ããã ãã©ãã£ãã¯ãæå·åããŸãã
ãããŒARPïŒFalse ARPïŒ
ARPãµãŒããŒãã«ãŒã¿ãŒããŸãã¯ã¹ã€ããã¯ãMACã¢ãã¬ã¹ïŒãããã¯ãŒã¯ã«ãŒããªã©ïŒã«å±ããIPãèªèããŠããŸãã ãããã¯ãŒã¯ãžã®ç©ççãªã¢ã¯ã»ã¹ãå¯èœãªå Žåãæ»æè ã¯ARPå¿çãåœè£ ããIPãåãåã£ãŠãããã¯ãŒã¯äžã®å¥ã®ã³ã³ãã¥ãŒã¿ãŒã«ãªãããŸãããšãã§ããŸãã ãããã£ãŠããã®ã³ã³ãã¥ãŒã¿ãŒå®ãŠã®ãã¹ãŠã®ãã±ããã¯åœŒã«ãã£ãŠåä¿¡ãããŸãã ããã¯ããã®ã³ã³ãã¥ãŒã¿ãŒããªãã«ãªã£ãŠããå Žåã«å¯èœã§ããããããªããšããã®ã¢ã¯ã·ã§ã³ã«ããIPã¢ãã¬ã¹ã®ç«¶åãçºçããŸãïŒåããããã¯ãŒã¯äžã«åãIPã¢ãã¬ã¹ãæã€ã³ã³ãã¥ãŒã¿ãŒã2å°ååšããããšã¯ã§ããŸããïŒã
æšå¥šäºé ïŒIPã®MACã¢ãã¬ã¹ã®å€æŽã«ã€ããŠéç¥ãããœãããŠã§ã¢ã䜿çšããARPãµãŒããŒã®ãã°ãã¡ã€ã«ãç£èŠããŸãã
ãããŒDNSãµãŒããŒïŒåœã®DNSãµãŒããŒïŒ
ãããã¯ãŒã¯èšå®ãèªåã¢ãŒãã«èšå®ãããŠããå Žåããããã¯ãŒã¯ã«æ¥ç¶ãããšãã³ã³ãã¥ãŒã¿ãŒã¯DNSãµãŒããŒã«ãªããèŠæ±ãïŒã€ãŸãããããŒããã£ã¹ããã±ãããéä¿¡ïŒããŸããDNSãµãŒããŒã¯åŸã§DNSã¯ãšãªãéä¿¡ããŸãã ãããã¯ãŒã¯ãžã®ç©çã¢ã¯ã»ã¹ãããå Žåãã¯ã©ãã«ãŒã¯ãã®ãããªãããŒããã£ã¹ãèŠæ±ãååããèªåã®ã³ã³ãã¥ãŒã¿ãŒãDNSãµãŒããŒã«ãªãããšãå¿çã§ããŸãã ãã®åŸã圌ã¯ã ãŸããã被害è ãä»»æã®ã«ãŒãã«æ²¿ã£ãŠéãããšãã§ããŸãã ããšãã°ã被害è ãéè¡ã®ãŠã§ããµã€ãã«ã¢ã¯ã»ã¹ããŠãéãééãããå Žåãã¯ã©ãã«ãŒã¯ãããèªåã®ã³ã³ãã¥ãŒã¿ãŒã«éä¿¡ããããã§ãã¹ã¯ãŒãå ¥åãã©ãŒã ãäœæãããŸãã ãã®åŸããã¹ã¯ãŒãã¯ã¯ã©ãã«ãŒã«å±ããŸãã æ»æè ã¯DNSãµãŒããŒãããæ©ã被害è ã«å¯Ÿå¿ããå¿ èŠããããããããã¯ããªãè€éãªæ¹æ³ã§ãã
æšå¥šäºé ïŒå¯èœã§ããã°ãèŠç¥ãã¬äººã®ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãå¶éããŸãã
ãã¡ãžãŒ
UDPãªã©ã®ç¹å®ã®ã¿ã€ãã®ãã±ããããããã¯ããããã«ãã£ã«ã¿ãŒãæ§æã§ããŸãã æ»æè ã¯ããã®UDPãã±ããããã£ã«ã¿ãªã³ã°ããªãããšããã£ã«ã¿ãŒãç解ããªãããã«ãã±ãããäœæããå®å ã«å°éããããšãã§ããŸãã ãã®ããã«ããŠãæ»æè ã¯ãã±ãããã£ã«ã¿ããã€ãã¹ã§ããŸãã ãã®ææ³ã¯éåžžã«çããç¹å¥ãªå Žåãããæ£ç¢ºã«ã¯æ¥ç¶ãåæ¹åã§ããå¿ èŠããªãå Žåã察象ãšããŠããŸãã ã»ãšãã©ã®å Žåãåæ¹åéä¿¡ã¯äžå¯èœã§ãããªããªãã åºæ¬çã«ãç¹å®ã®ã¿ã€ãã®çä¿¡ãã±ãããããŒãã§ãããã¯ããããšãçºä¿¡ãã±ããããããã¯ãããŸãã 補é ããããã±ããããã£ã«ã¿ãŒãééããå Žåã§ãïŒããšãã°ãUDPããŒãã«ïŒããµãŒããŒã¯åãã¿ã€ãã®ãã±ããã§å¿çããŸãã UDPããããåæã«åœŒã¯ã¯ã©ãã«ãŒã®äŸã«åŸã£ãŠããã補é ããŸããã T.O. ãã®çºä¿¡ãã±ããã¯é€å€ãããã¯ã©ãã«ãŒã«å°éããŸããã ãšã«ããããã®çš®ã®æ»æãã身ãå®ã䟡å€ã¯ãŸã ãããŸãã
æšå¥šäºé ïŒéåžžãæ°ããããŒãžã§ã³ã®ãã¡ã€ã¢ãŠã©ãŒã«ã¯ããã®ææ³ã«å¯Ÿããååãªä¿è·ãæäŸããŸãã
ãã±
ã¯ã©ãã«ãŒã¯ICMPå°éäžèœå¿çïŒãªã¢ãŒãã·ã¹ãã ãšã©ãŒïŒãäœæããŸããããã«ãããã¯ã©ã€ã¢ã³ãã¯ãµãŒããŒããåæãããŸãã æ»æã®ããã«ã¯ã©ã€ã¢ã³ãããµãŒããŒããåæããå¿ èŠãããå Žåãè£å©ããŒã«ãšããŠäœ¿çšãããå¯èœæ§ãé«ããªããŸãã
åœã®å°éäžèœ-ã¯ã©ãã«ãŒã¯ããã±ãŒãžãé ä¿¡ã§ããªãïŒå°éäžèœïŒãšããã¡ãã»ãŒãžãäœæããããããµãŒããŒã¯ã¯ã©ã€ã¢ã³ãã«é害ããããããã±ãŒãžãæå³ãããšããã«é ä¿¡ãããŠããªããšå€æããŸãã ããã«ããããµãŒããŒãã¯ã©ã€ã¢ã³ããåæããå ŽåããããŸãã ãŸããNoã17ãšåæ§ã®è£å©ããŒã«ã¯ãã¯ã©ã€ã¢ã³ãã§ã¯ãªããµãŒããŒã«åããããŠããŸãã
IPã¹ããŒãã£ã³ã°ïŒã¹ããŒãã£ã³ã°ãŸãã¯IP眮æïŒ
æ»æè ã¯èªåã®å®éã®IPãæ¶ç©ºã®IPã«çœ®ãæããŸãã ããã¯ãç¹å®ã®IPã¢ãã¬ã¹ã®ã¿ããªãœãŒã¹ã«ã¢ã¯ã»ã¹ã§ããå Žåã«å¿ èŠã§ãã æ»æè ã¯ãã¢ã¯ã»ã¹ããããã«å®éã®IPããç¹æš©ããŸãã¯ãä¿¡é Œãã«å€æŽããå¿ èŠããããŸãã ãã®æ¹æ³ã¯ç°ãªãæ¹æ³ã§äœ¿çšã§ããŸãã 2å°ã®ã³ã³ãã¥ãŒã¿ãŒããã¹ã¯ãŒãã確èªããŠçžäºã®æ¥ç¶ã確ç«ããåŸãã¯ã©ãã«ãŒã¯è¢«å®³è ã«ç¹å¥ã«çæããããã±ããã§ãããã¯ãŒã¯ãªãœãŒã¹ãéè² è·ã«ããå¯èœæ§ããããŸãã ãããã£ãŠã圌ã¯ãã©ãã£ãã¯ãèªåèªèº«ã«ãªãã€ã¬ã¯ãããŠãèªèšŒæé ããã€ãã¹ã§ããŸãã
æšå¥šäºé ïŒå€ãã®ææ³ãããããããããã®å€ããååšããå¯èœæ§ããããŸãã ãã ããSYNããã³ACKãã©ã°ãèšå®ããŠå¿çãã±ããæéãççž®ãããã¥ãŒã§æ¥ç¶ã確ç«ããSYNãªã¯ãšã¹ãã®æ倧æ°ãå¢ããïŒtcp_max_backlogïŒããšã§ãè åšã軜æžãããïŒãã ããæ£åœãªæ¥ç¶ã§ã¯å°é£ã«ãªãå¯èœæ§ãããïŒããšã«æ³šæããŠãã ããã SYN-Cookieã䜿çšããããšãã§ããŸãã
ãã¹ãã®ãªãããŸãã ãããã¯ãŒã¯ãžã®ç©çã¢ã¯ã»ã¹ãå¿ èŠãšããéåžžã«é«åºŠãªææ³ã åã³ã³ãã¥ãŒã¿ãŒã¯ããã¹ãŠã®ãã±ãããéä¿¡ããã«ãŒã¿ãŒãèªèããŠããŸãããã¹ãŠã®ãã±ããã¯ãã«ãŒã¿ãŒã«ãã£ãŠå®å ã«é ä¿¡ãããŸãã ã«ãŒã¿ãŒãå€æŽããããšããªãã€ã¬ã¯ãéç¥ãåã³ã³ãã¥ãŒã¿ãŒã«éä¿¡ããããã®åŸã³ã³ãã¥ãŒã¿ãŒã¯æ°ããã«ãŒã¿ãŒã«ãã±ãããéä¿¡ãå§ããŸãã æ»æè ã¯ãã®ãããªéç¥ãäœæããã«ãŒã¿ãŒãåœè£ ããŠããããã¯ãŒã¯ã»ã°ã¡ã³ãå ã®ãã©ãã£ãã¯ãå¶åŸ¡ã§ããããã«ããŸãã
æšå¥šäºé ïŒãããã¯ãŒã¯ã¢ã¯ã»ã¹ãšã«ãŒã¿ãŒãå€æŽãããç¬éãå¶åŸ¡ããŸãã ããšãã°ãéå»ã®ãã¹ãŠã®ãã©ãã£ãã¯ïŒã€ãŸããå€ãæ¥ç¶ïŒãæ°ããã«ãŒã¿ãŒã«ã衚瀺ããããŠãããã©ãããç£èŠã§ããŸãã
ãã¹ã¯ãŒãæšæž¬ã
ã¢ã«ãŠã³ãã®ãã¹ã¯ãŒããéžæããŠã·ã¹ãã ã«ç»é²ããããã«äœ¿çšãããŸãã 2ã€ã®ã¿ã€ãããããŸãïŒæåã®ãã¹ãŠã®å¯èœãªçµã¿åããã®éžæïŒBruteForceïŒããã³èŸæžã«ããéžæã æåã®æ¹æ³ã¯ããå¹æçã§ãããªããªã ããŒããŒããããã¹ã¯ãŒããšããŠå ¥åããæåã®çµã¿åããã¯ãŸã ãããŸããããã®æ¹æ³ã¯ãç¹ã«å¥èªç¹ãèæ ®ããå Žåãªã©ãéåžžã«é ããªããŸãã 2çªç®ã®æ¹æ³ã¯ç°¡åã§ãããããšãã°ãMy-New-Passwordããªã©ã®èŸæžã«ãªãåèªãå ¥åããå ŽåãèŸæžããéžæããããšã¯ã§ããŸããã ãã¹ã¯ãŒããéžæããã®ã«åœ¹ç«ã€ããã°ã©ã ã¯ããããããã®ã§ãç¹å®ã®ååãä»ããã®ã¯çã«ããªã£ãŠããªããšæããŸãã ååãšããŠãããã°ã©ã ãOSãªã©ã¯æå·åããã圢åŒã§ãã¹ã¯ãŒããä¿åãããããæ»æè ããã¡ã€ã«ã«ã¢ã¯ã»ã¹ãããšããŠãããã¹ã¯ãŒãã解èªããå¿ èŠããããŸãã 圌ã¯ãããèªå® ã®ã³ã³ãã¥ãŒã¿ãŒã§æ°æ¥éè¡ãããšãã§ããŸãã
æšå¥šäºé ïŒè€éãªãã¹ã¯ãŒãã䜿çšããã§ããã°å¥èªç¹ã䜿çšããŠãã ããã ãã¹ã¯ãŒãã®è©Šè¡åæ°ãå¶éããŸãã ãã¹ã¯ãŒãã®åŸ©å·åã«å¯ŸããŠã¯ããã®è€éãã®ã¿ã圹ç«ã¡ãŸãã
ããã¯ã³ãã¯ã/ãã€ã/ãªããŒã¹
ããã¯è£å©çãªææ³ã§ãããããèªäœãéåžžã«èå³æ·±ããã®ã§ãã ããšãã°ãæ»æè ã¯æ¯å1ã€ã®ã³ãã³ãã®ããã«å€ãã®ã¢ã¯ã·ã§ã³ãå®è¡ããããšãæã¿ãŸããã 圌ã¯ãã®ææ³ã䜿çšããŠã¿ã¹ã¯ãç°¡çŽ åã§ããŸãã ãã®æ¬è³ªã¯ãã¯ã©ãã«ãŒãæ»æãããã³ã³ãã¥ãŒã¿ãŒãã¯ã©ãã«ãŒã®ã³ã³ãã¥ãŒã¿ãŒã«åŒ·å¶çã«æ¥ç¶ãããããšã§ãã ããšãã°ãæ»æãããã³ã³ãã¥ãŒã¿ãŒã§ã¯ãtelnet [ip.addresser] [port]ã³ãã³ããå®è¡ã§ããŸãã ãã®åŸãã¯ã©ãã«ãŒã¯å®éãæ»æãããã³ã³ãã¥ãŒã¿ãŒã§ã³ãã³ãã©ã€ã³ïŒã³ãã³ãã·ã§ã«ãŸãã¯ã·ã§ã«/ã·ã§ã«ïŒãåãåããŸãã
ãœãããŠã§ã¢ã®è匱æ§
ãœãããŠã§ã¢ã®ãã°ã䜿çšããã å¹æã¯ç°ãªãå ŽåããããŸãã éèŠã§ã¯ãªãæ å ±ã®åä¿¡ãããã·ã¹ãã ãå®å šã«å¶åŸ¡ãããŸã§ã ãœãããŠã§ã¢ã®ãã°ã«ããæ»æã¯ãåžžã«æã人æ°ããããŸãã å€ããã°ã¯æ°ããããŒãžã§ã³ã§ä¿®æ£ãããŸãããæ°ãããã°ã¯åã³äœ¿çšã§ããæ°ãããã°ããããããŸãã ããã«ãæ»æã®çš®é¡ã§ã¯ãªãããœãããŠã§ã¢ãšã©ãŒãæ»æããæ¹æ³ã«ã€ããŠèª¬æããŸãã æšå¥šäºé ïŒæšå¥šäºé ã¯äžè¬çãªãã®ã§ãããããããã«ãã¹ãŠã®äººã«æäŸããŸãããå®å šã«ãæžãããããã°ã©ã ã³ãŒãã®ã¿ã圹ç«ã¡ãŸãã ãã®ãããã¯ã§ã¯ãã€ã³ã¿ãŒãããäžã§å€§éã®è³æãèŠã€ããããšãã§ããŸãã
ãããã¡ãªãŒããŒãããŒ
éåžžã«å±éºãªã¿ã€ãã®æ»æã¯ããªã¯ãšã¹ããå²ãåœãŠãããã¡ã¢ãªãã¬ãŒã ããªãŒããŒãããŒããããããªæ¹æ³ã§ãªã¯ãšã¹ãã圢æããããªã¯ãšã¹ãå ã®ã瞫補ãã³ãã³ããã¹ã¿ãã¯ã«å°çããããã»ããµã«ãã£ãŠå®è¡ãããå Žåã§ãã ã¯ã©ãã«ãŒãæ»æãããã³ã³ãã¥ãŒã¿ãŒã§ããã°ã©ã ãå®è¡ã§ããå Žåãããã¯ãªã¢ãŒããšããŒã«ã«ã®äž¡æ¹ã§å®è¡ã§ããŸãã ããã¯ãã³ã³ãã¥ãŒã¿ãŒã§ã³ãŒããå®è¡ãããããšãæš©éãäžããããã®äž¡æ¹ã«äœ¿çšã§ããŸãã ãããã¡ãªãŒããŒãããŒæ»æã«ã¯ããã€ãã®ãµãã¿ã€ãããããŸãã ããããã«ã€ããŠã¯èª¬æããŸããããªããªãã ååã説æããããã«ãããã°ã©ãã³ã°ã«äžæ £ããªäººã ã«ã¯ç解ã§ããªãã³ãŒãã®äŸãæäŸããå¿ èŠããããŸãã 以äžã®åé¡ã¯ãAndrey KolishchakïŒandr [at] sandy.ruïŒã«å±ãã圌ã®èšäºãAttacks on buffer overflowãã«ãããŸãã ãã®ããããã®èšäºã§ãã®èª¬æãäŸãæšå¥šäºé ãçŽæ¥èŠã€ããããšãã§ããŸãã 審æ»ã®ããã ãã«æäŸããŸãã
---ãã¹ã¿ãã¯é害ããæ»æãã
---ãã©ã¡ãŒã¿åã«ãããã¹ã¿ãã¯é害ãã®æ»æ
---å¶åŸ¡ã®ç§»åã«ãããã¹ã¿ãã¯é害ãã®æ»æ
---é¢æ°ãã€ã³ã¿ã®æªã¿
---é¢æ°ãã€ã³ã¿ãžã®æ»æ
---ãã©ã¡ãŒã¿åã«ããé¢æ°ãã€ã³ã¿ãžã®æ»æ
---ã³ã³ãããŒã«è»¢éã«ããé¢æ°ãã€ã³ã¿ãŒãžã®æ»æ
---é·ç§»è¡šã®æªã¿
---å€æããŒãã«ã«å¯Ÿããæ»æ
---ãã©ã¡ãŒã¿åã«ããé·ç§»ããŒãã«ãžã®æ»æ
---ã³ã³ãããŒã«è»¢éã«ããé·ç§»ããŒãã«ãžã®æ»æ
---ããŒã¿ãã€ã³ã¿ãŒã®æªã¿
---ããŒã¿ãã€ã³ã¿ãŒãã£ã¹ããŒã·ã§ã³æ»æ
---ãã©ã¡ãŒã¿ãŒåã«ããããŒã¿ãã€ã³ã¿ãŒã®æªã¿ã䌎ãæ»æ
---å ã®ã³ãŒãã§ã®ããŒã¿ãã€ã³ã¿ãŒã®æªã¿ã«ããæ»æã
äžèšã®åé¡ã«ãã1ã€ã®ã¿ã€ããæŽæ°ãªãŒããŒãããŒïŒæŽæ°ãªãŒããŒãããŒïŒãè¿œå ããããšæããŸãã 詳现ã«ã€ããŠã¯ãBleximã®èšäºãæŽæ°ãªãŒããŒãããŒïŒæ»æãããã³ãæŽæ°ãªãŒããŒãããŒïŒä¿è·ããŸãã¯ãåºæ¬æŽæ°ãªãŒããŒãããŒããåç §ããŠãã ããã
ç²ç
ããŒã«ã«ã§ã®ã¿äœ¿çšå¯èœãªWindowsã·ã¹ãã ã®è匱æ§ã ããã¯ãããã¡ãªãŒããŒãããŒãšéåžžã«ãã䌌ãŠããŸãããåãçµæã«ãªããŸããã¯ã©ãã«ãŒã³ãã³ããã¹ã¿ãã¯ã«ãããããŸãã ããã¯ãå ¥åãã£ãŒã«ããæã€Windowsã®ãã¹ãŠã®ãŠã£ã³ããŠãå ¥åå€ã®æ倧é·ãæã£ãŠãããšããäºå®ã«åºã¥ããŠããŸãã ããã°ã©ã éçºã®æ®µéã§ã€ã³ã¹ããŒã«ãããŸããå°ããªãã£ãŒã«ãã®å Žåãããšãã°50æåã§ããããŒããŒããã50æåãè¶ ããæåæ°ãå ¥åããããšã¯ã§ããŸããããWindowsãŠã£ã³ããŠã®æäœã¯ã¡ãã»ãŒãžã«åºã¥ããŠããŸãã ããããŒïŒããããŒãŸãã¯ããããŒïŒç¹å¥ãOSå°çšïŒïŒå ¥åãã£ãŒã«ããç°¡åã«ååŸããå ¥åãã£ãŒã«ãã«ïŒãã®ããããŒã䜿çšããŠïŒSETTEXTïŒããã¹ãèšå®ïŒã¡ãã»ãŒãžãéä¿¡ã§ããŸãã ã¡ãã»ãŒãžã«ã¯ããããã50æå以äžã®ããã¹ããã€ã³ã¹ããŒã«ããå¿ èŠãããããšã瀺ãå¿ èŠããããŸãã50æåç®ä»¥éã«çºçãããã¹ãŠã®åŠçã¯ã¹ã¿ãã¯ã«ç§»åããããã»ããµã«ãã£ãŠå®è¡ãããŸãã ããã«å¯Ÿããä¿è·ã¯ãããŸããã å¯äžã®äžèœè¬ã¯ãAMD Athlon 64ããã»ããµã§ãããããã®ããã»ããµã«ã¯ä¿è·æ©èœãçµã¿èŸŒãŸããŠãããã¹ã¿ãã¯ããã³ãã³ããå®è¡ããŸããã
NukeïŒWinNukeãŸãã¯NukeïŒ
ä»ãããã¯ç©èªã®è©³çŽ°ã§ãã Windowsã¯ãããã©ã«ãã§NetBIOSãããã³ã«ã䜿çšããŠããããã¯ãŒã¯äžã®ãã¡ã€ã«ãšããªã³ã¿ãŒãå ±æããŸãã ãããè¡ãããã«ãOSã¯3ã€ã®TCPããŒãïŒ137ã138ã139ïŒãéããŸãã å€ãããŒãžã§ã³ã®Windowsã§ã®ãã®ãããã³ã«ã®å®è£ ã«ã¯è匱æ§ãå«ãŸããŠããŸããã äžçªäžã®è¡ã¯ãããŒã139ãéãããã«è€æ°ã®OutOfBand "ã¡ãã»ãŒãž"ãé£ç¶ããŠéä¿¡ã§ããããšã§ãã ã·ã¹ãã ã¯ãã®ãããªããŒã¿ãæ£ããåŠçã§ãããã·ã¹ãã ããã³ã°ããŸããã ãã®ãããªæ»æã®ããã®å€ãã®ããã°ã©ã ãäœæãããŠããŸãããSSPingã®ããŒã«ãšããŠãã§ã«ååãä»ããShadow Security Scannerã«ã€ããŠã®ã¿èšåããŸãã
ã¯ãã¹ãŠãŒã¶ãŒæ»æ
ç§ãã¡ã®æèŠã§ã¯ãããªããããŸããªååããªããªã æåã®æ¹æ³ã¯æ»æã®æ¬è³ªãåæ ããŠããããã§ã¯ãããŸããããããã§ããã®æåãªååãå®ããŸãã Squid 2.4ããã³ISA / 2000ã§ã¯ããŠãŒã¶ãŒã¯ãµãŒããŒãšTCPæ¥ç¶ãå ±æã§ããŸãã HRSïŒåŸè¿°ïŒã䜿çšãããšããµãŒããŒãã2ã€ã®å¿çãåŒãèµ·ããããã®ãã¡ã®1ã€ã¯ã¯ã©ãã«ãŒã«ãã£ãŠå¶åŸ¡ããããŠãŒã¶ãŒãåä¿¡ããæ å ±ãæ¹ããããããšãã§ããŸãã
CGIã«å¯Ÿããæ»æã ã»ãšãã©ã®WWWïŒWebïŒãµãŒããŒã¯ãã¹ã¯ãªããã䜿çšããŠãŠãŒã¶ãŒã«è¿œå ã®ãµãŒãã¹ãæäŸããããè¿œå ã®æ©èœãæäŸãããããŸãã ããšãã°ãmail.ruãªã©ã®ã¡ãŒã«ãµãŒããŒå€ãã®ãµãŒããŒã«ã¯ããèªå·±äœæãCMSïŒã³ã³ãã³ã管çã·ã¹ãã ãŸãã¯ã³ã³ãã³ã管çã·ã¹ãã ïŒãµã€ãïŒïŒããããŸãã ããã°ã©ããŒã¯ããŠãŒã¶ãŒãå ¥åããå€ããã§ãã¯ããããã«åžžã«ã¹ã¯ãªããã匷å¶ããããã§ã¯ãããŸãããããã«ããããã®ãããªèŠèœãšããããŸããŸãªç®çã«äœ¿çšããããšãã§ããŸãã ãããã¡ãªãŒããŒãããŒæ»æã¯ãCGIã¹ã¯ãªãããšã©ãŒãä»ããŠå®è¡ããããšãã§ããŸãã äŸïŒ httpïŒ// host / cgi-bin / helloworldïŒType = A * 100 ïŒã€ãŸããæåAã¯100åã«ãªããŸãïŒã åªããèšäºã¯http://www.opennet.ru/base/sec/linux_sec_guide.txt.htmlã«ãããŸãã2çªç®ã®éšåã§ã¯ãCGIããã°ã©ããŒã«ãã£ãŠéåžžç¡èŠãããã»ãã¥ãªãã£åé¡ã«ã€ããŠèª¬æããŠããŸãã å€ãã¯ãããã³ã°æ¹æ³ã§ã¯ãããŸãããããããã³ã°ã«åœ¹ç«ã€ã ããªã®ã§ãè¯ãã³ãŒããæžãããã«ã¯èšäºãèªãããšããå§ãããŸãã ãã®èšäºã®ç¯å²ã§ã¯ãå®å šãªã³ãŒããæžããšãããããã¯ãæãäžããããšã¯ã§ããŸããããã®ãããå°ãªããšããåä¿¡ããããŒã¿ãããã¹ãŠã®ãµãŒãã¹æåããã£ã«ã¿ãŒããå¿ èŠããããšã®ã¿èšããŸãã
SQLã€ã³ãžã§ã¯ã·ã§ã³
ãŠãŒã¶ãŒãå ¥åããããŒã¿ãæ€èšŒãªãã§çæãããSQLã¯ãšãªã§äœ¿çšãããå Žåãã¯ã©ãã«ãŒã¯ããŒã¿ãå ¥åããŠSQLããŒã¿ããŒã¹ããæ å ±ãååŸã§ããŸãã äŸïŒãSELECTãã°ã€ã³ãemail = '$ email'ã®ã¡ã³ããŒããã®ãã¹ã¯ãŒãFROM;ããšãããªã¯ãšã¹ãããããŸãã$ã¡ãŒã«ããŠãŒã¶ãŒã«ãã£ãŠããŒãã«ã«å ¥åããããšããªã¯ãšã¹ããåŠçãããçµæãããŒãžã«è¡šç€ºãããŸãã æ»æè ã¯ããŒã¿ãå€æŽãããmy@mail.ru 'OR login LIKE'ïŒ adminïŒ ããšãããã©ãŒã ã«å ¥åã§ããŸãã ãããã£ãŠãçæãããSQLã¯ãšãªã¯æ¬¡ã®ããã«ãªããŸãããSELECT loginãpassword FROM members where email='my@mail.ru 'OR login LIKE'ïŒ adminïŒ ';ãã ãããã£ãŠãã¯ã©ãã«ãŒã¯adminãå«ããã°ã€ã³ãæã€ãŠãŒã¶ãŒãããã¹ã¯ãŒããåãåããŸãã
HRSïŒHTTPãªãœãŒã¹åå²ïŒ
ããªãè¥ããç§ãã¡ã®æèŠã§ã¯è€éãªããªãã¯ã§ãïŒXSSã«ã®ã¿äœ¿çšããªãå ŽåïŒãããã«ããããã€ãžã£ãã¯ããŒãžãã¯ãã¹ãŠãŒã¶ãŒæ¹ãããWebãã£ãã·ã¥ãã€ãºãã³ã°ããã©ãŠã¶ãŒãã£ãã·ã¥ãã€ãºãã³ã°ãXSSãªã©ã®æ»æãå®è£ ã§ããŸãïŒä»¥äžã§èª¬æããŸãïŒã æ»æã®æ¬è³ªã¯ãç¹å¥ã«æºåãããHTTPãªã¯ãšã¹ãã䜿çšããæ»æè ããHRSã«å¯ŸããŠè匱ãªWebãµãŒããŒã«ã2ã€ã®åå¥ã®HTTPã¬ã¹ãã³ã¹ïŒéåžžã®ç¶æ³ã§ã¯1ã€ã§ã¯ãªãïŒã§ç ç²è ïŒæ»æè ã§ã¯ãªãïŒã«å¿çãããããšã§ãã HTTP , ! , , . - , - (, - ). ãããïŒ HTTP ( ) HTTP ( )! , , «» - , ( ). , , , , , cookie . , HRS, , HRS.
Cross User Defacement
«» , , â . â . , HRS. , IP , -, «» . .
Web Cache Poisoning
, , . , , , , -. , . , , .
Browser Cache Poisoning. , . , Web Cache Poisoning, , .
Hijacking Pages
, «» , -, , -, . , , . . , TCP ( «»), TCP («») TCP - («»). ã¹ããŒã ã¯æ¬¡ã®ãšããã§ãã
--- «» ( «») , - «» «1» «2» ( HRS).
--- «» «» -.
---- «1» «2» «».
â , «1» «» «».
--- «» «». «», .
--- «» - «», «2» -.
--- «» «2» «».
â «2» «».
â - «» «».
--- «2» - «», «» «2».
â «» «». T.O. , , .
, , . , , , . , , , , .
CSS/XSS (Cross-Site Scripting )
, Microsoft , Java Script . , Java , «» , . , . , cookie . , . , cookie ! : «», snf.jpg, document.cookie . , , , (, ), «» cookie, . , , ( , JPG) . , (: «photo.jpg») JAVA . XSS, , Java Script . , .
SiXSS (SQL Injection Cross Site Scripting)
SQL Injection XSS, .. XSS SQL Injection. , MySQL ( 0) . , SQL , «» «3C7363726970743E616C6572742822536958535322293B3C2F7363726970743E». SQL Injection , : www.victim.com/vuln_script.php ? vuln_variable=1+union+select+0x3C7363726970743E616C6572742822536958535322293B3C2
F7363726970743E , vuln_variable vuln_script , . SiXSS, , . , . , . XSS , . , , «» , , « ». , , , SQL , «UNION», : , . , %F1%F1%FB%EB%EA%E0 , . , , . , , , SQL . , , , JAVA. . , , «» «Apex Bank PLC», apexbnkplcc@yahoo.co.uk , , . !
SiHRSïŒSQLã€ã³ãžã§ã¯ã·ã§ã³HTTPãªãœãŒã¹åå²ïŒ
ã¬ã»ãã·ã§ã³ã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³ã«å¯Ÿããã¹ã¯ãªããã®è匱æ§ãä»ããŠHTTPãªãœãŒã¹åå²ãå®è£ ããŸããããã¯ãããšãã°ã€ã³ããã¯ã¹ã«ããã¹ã¯ãªããããæåã«HTTPã¢ãã¬ã¹ã®SQLããŒã¿ããŒã¹ã«ã¢ã¯ã»ã¹ãã次ã«HTTPèŠæ±ãçæããSQLããŒã¿ããŒã¹ããåä¿¡ããHTTPã¢ãã¬ã¹ã䜿çšããŠãLocationïŒããã£ãŒã«ãã®HTTPèŠæ±ã眮ãæããå Žåã«å¯èœã«ãªããŸããããã¯ããµã€ãã®ã€ã³ã¿ãŒããããã£ã¬ã¯ããªã§ãã䜿çšãããŸããSiHRSã«16é²æ°ã§äœ¿çšã§ããHTTPããããŒã®äŸãæããããšãã§ããŸãã
HEXã³ãŒããéžæïŒ 'i.php'
Content-LengthïŒ0
HTTP / 1.1 200 OK
Content-Ty