ãããªãã¯Webã¢ããªã±ãŒã·ã§ã³ã¯ãæ»æè ã«ãšã£ãŠé åçãªæšçã§ãã Webã¢ããªã±ãŒã·ã§ã³ãžã®æ»æã¯ãäŒæ¥ã®å éšãªãœãŒã¹ãžã®ã¢ã¯ã»ã¹ãæ©å¯æ å ±ãã¢ããªã±ãŒã·ã§ã³ã®äžæãããžãã¹ããžãã¯ã®ãã€ãã¹ãªã©ãWebã¢ããªã±ãŒã·ã§ã³ã«å€§ããªãã£ã³ã¹ããããããŸããã»ãšãã©ã®æ»æã¯ãææè ã«ééçããã³è©å€ã®äž¡æ¹ã®ééçå©çããããããŸãã Webã¢ããªã±ãŒã·ã§ã³ã ããã«ãæ»æã«æåãããšãè³æ Œæ å ±ãçãã ãããŠãŒã¶ãŒã«ä»£ãã£ãŠãµã€ãã§ã¢ã¯ã·ã§ã³ãå®è¡ããããã¯ãŒã¯ã¹ããŒã·ã§ã³ã«ãã«ãŠã§ã¢ãææããããããããšãã§ãããããWebã¢ããªã±ãŒã·ã§ã³ã®ãŠãŒã¶ãŒãå±éºã«ãããããŸãã
Webã¢ããªã±ãŒã·ã§ã³ãžã®æ»æã調æ»ããå ŽåããŸããæ»æè ã®éã§ã©ã®æ»æãæã人æ°ãããã®ãââãæ»æè ã®è¡åã®å¯èœæ§ã®ããåæ©ã¯äœãããããŠããŸããŸãªæ¥çã®è åšã®äž»ãªåå ãç¹å®ããã¿ã¹ã¯ãèšå®ããŸãã ãã®ããŒã¿ã«ãããWebã¢ããªã±ãŒã·ã§ã³ãä¿è·ãããšãã«èæ ®ãã¹ãåŽé¢ãç解ã§ããŸãã ããã«ãäŒç€Ÿã®ç¯å²ã«å¿ããæ»æã®çš®é¡ãšæ»æè ã®æŽ»åã®ååžãããã³å¹Žéã®æ»æã®æ§è³ªã®ãã€ããã¯ã¹ãèæ ®ããŸãã
æ»æã«é¢ããåæããŒã¿ãåéããããã«ã2016幎ã®PT Application FirewallïŒPT AFïŒã®å®è£ ã®ããã®ãã€ããããããžã§ã¯ãäžã«ååŸããããŒã¿ã䜿çšããŸããã ãã€ããããããžã§ã¯ãã«ã¯ãæ¿åºæ©é¢ãæè²ãéèã茞éãç£æ¥ãITã®åéã®çµç¹ãåå ããŸããã æ€èšäžã®ã·ã¹ãã ã«ã¯ããã·ã¢äŒæ¥ãšå€åœäŒæ¥ã®äž¡æ¹ããããŸãã ãã®èª¿æ»ã§åŒçšãããæ»æã®äŸã¯ãã¹ãŠãæåã§èª€æ€ç¥ã確èªãããŠãããä¿¡é Œã§ãããã®ã§ãã
æ¥çã®æ»æã®äººæ°
ãã€ããããããžã§ã¯ãã§æãäžè¬çãªã®ã¯ãSQLã¹ããŒãã¡ã³ãã®å®è£ ããšãOSã³ãã³ãã®å®è¡ãã§ããã®ãããªæ»æã¯ã·ã¹ãã ã®80ïŒ ä»¥äžã§PT AFã«ãã£ãŠæ€åºãããŸããã ãã¹ãã©ããŒãµã«ã¯ãç¹å®ãããæ»æã®äžã§äººæ°ã2äœã§ãã æããã«ãæåã«ãæ»æè ã¯å®è¡ã«ç¹å¥ãªæ¡ä»¶ãå¿ èŠãšããªãæãåçŽãªæ»æã䜿çšããããšããŸãã åºæ¬çã«ãæ»ææ€åºã®å²åãäœãããšã¯ãè€é床ãé«ãããšããŸãã¯ãã®å®è£ ã«ç¹å¥ãªæ¡ä»¶ãå¿ èŠã§ããããšã瀺ããŸããããšãã°ãWebã¢ããªã±ãŒã·ã§ã³ã§ãã¡ã€ã«ãããŠã³ããŒãããæ©èœãããŠãŒã¶ãŒåŽã§ç¹å®ã®ã¢ã¯ã·ã§ã³ãå®è¡ããæ©èœããããŸãã
æã人æ°ã®ããæ»æã®è©äŸ¡ãã³ã³ãã€ã«ãããšããè匱æ§ã®Webã¢ããªã±ãŒã·ã§ã³ã®èªåã¹ãã£ã³çšã®ç¹å¥ãªãœãããŠã§ã¢ïŒAcunetixãsqlmapãªã©ïŒã«ãã£ãŠå®è¡ãããæ»æãé€å€ããŸããã
æãäžè¬çãªæ»æïŒWebã¢ããªã±ãŒã·ã§ã³ã®ã·ã§ã¢ïŒã®è©äŸ¡
ãã®è©äŸ¡ã®ã»ãšãã©ã®æ»æã¯ãé倧ãªè匱æ§ãæªçšããWebã¢ããªã±ãŒã·ã§ã³ãšãµãŒããŒã®å®å šãªäŸµå®³ã«ã€ãªããå¯èœæ§ããããæ»æè ãããŒã«ã«ãããã¯ãŒã¯ã®ãªãœãŒã¹ã«ã¢ã¯ã»ã¹ããå¯èœæ§ããããŸãã
PT AFã®éã«èšé²ãããæ»æã¿ã€ãã®å²åãšãã®æ°ã¯ã調æ»å¯Ÿè±¡ã®ã·ã¹ãã ãå±ããæ¥çã«ãã£ãŠç°ãªããŸãã æ»æè ã®ç®æšã¯ç°ãªããŸãããæ»æè ã®ã¹ãã«ã¬ãã«ãšæè¡çèœåãç°ãªããŸãã 以äžã®å³ã¯ãã·ã¹ãã ããšã®1æ¥ãããã®å¹³åæ»ææ°ãšãæåã§å®è¡ãããèªåã¹ãã£ã³ã®ãŠãŒãã£ãªãã£ã䜿çšããæ»æã®æ°ã®æ¯çã瀺ããŠããŸãã
ã·ã¹ãã ããšã®1æ¥ãããã®å¹³åæ»ææ°
èªåã¹ãã£ã³ãšæåæ»æã®æ¯ç
æ¿åºæ©é¢ããªã³ã©ã€ã³ã¹ãã¢ãé€ããã¹ãŠã®æ¥çã«å¯Ÿããæ»æã®ã»ãšãã©ã¯ãç¹æ®ãªè匱æ§æ€çŽ¢ãœãããŠã§ã¢ã䜿çšããŠå®è¡ãããæ»æã§ãã èªåã¹ãã£ã³ã«ã¯ãã»ãã¥ãªãã£åæçšã®æ¢æã®ãœãããŠã§ã¢ããŒã«ã䜿çšãããSQLã¹ããŒãã¡ã³ãã®å°å ¥ããã¹ãã©ããŒãµã«ãªã©ãããŸããŸãªçš®é¡ã®æ»æã®è©Šè¡ãå«ãŸããŸãã æ»æè ã¯ã¹ãã£ã³ã®çµæã䜿çšããŠãè匱æ§ãæªçšããæ©å¯æ å ±ãããŒã«ã«ãããã¯ãŒã¯ãªãœãŒã¹ãéèŠãªã·ã¹ãã ã«ã¢ã¯ã»ã¹ããåã«æ»æãã¯ãã«ãããã«éçºãããããŠãŒã¶ãŒã«å¯ŸããŠæ»æãå®è¡ãããã§ããŸãã
以äžã®å³ã¯ãsqlmapãŠãŒãã£ãªãã£ã䜿çšããèªåã¹ãã£ã³æ€åºã®äŸã瀺ããŠããŸãã PT AFã¯ãUser-Agent HTTPããããŒã®äžèŠãªã³ã³ãã³ããšãSQLã¹ããŒãã¡ã³ãã€ã³ãžã§ã¯ã·ã§ã³ãå«ãã¯ãšãªãæ€åºããŸããã
èªåã¹ãã£ã³æ€åºã®äŸ
1æ¥ãããã®æ倧æ»ææ°-çŽ3,500件ã®æ»æ-ã¯ãæ¿åºæ©é¢ã§ã®ãã€ããããããžã§ã¯ãäžã«èšé²ãããŸããã èªååãããè匱æ§æ€çŽ¢ã¯ãæ»æã®ç·æ°ã®ããã18ïŒ ãå ããŠããŸãã ãã®è©äŸ¡ã§ã¯ããªã³ã©ã€ã³ã¹ãã¢ã2äœã«ã©ã³ã¯ãããŠããŸãã1æ¥ãããçŽ2200件ã®æ»æãèšé²ããããããã®ã»ãšãã©ãã¹ãŠãèªåã¹ãã£ã³ããŒã«ã䜿çšããã«å®è¡ãããŸããã
éèã»ã¯ã¿ãŒã§ã¯ãPT AFã1æ¥ã«çŽ1,400件ã®æ»æãèšé²ãããã®ãã¡èªååãããè匱æ§æ€çŽ¢ãæ®åããŸããã 茞éãªãœãŒã¹ãšITäŒæ¥ã¯ã1æ¥ã«å¹³åçŽ680ã®æ»æãå ããŠããããã®ã»ãšãã©ã¯èªååãããè匱æ§æ€çŽ¢ã§ããããŸãã
æè²éšéã®1æ¥ãããã®å¹³åæ»ææ°ã®èšç®ãããæ å ±ããã³åæã»ã³ã¿ãŒã¯é€å€ãããŸããããã®æ©èœã«ã¯å·ã®è©Šéšçµæã®åŠçãå«ãŸããŸãã ãã®ã»ã³ã¿ãŒã®ãã€ããããããžã§ã¯ãã¯ãå€ã«åŠæ ¡ã®çåŸãçµ±äžåœå®¶è©Šéšãšåœå®¶å®å šæ€æ»å±ã«åæ Œãããšãã«è¡ãããŸããããã®çµæãWebã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããæ»æãéåžžã«å€ãã1æ¥ããã20,000件ãè¶ ããŸããã ãã ããæãäžè¬çãªã®ã¯ãè匱æ§ã®ã¹ãã£ã³ããŒã«ã䜿çšããæ»æã§ãã æ å ±ã»ãã¥ãªãã£ã®åºæ¬çãªç¥èãšã»ãã¥ãªãã£ã¡ã«ããºã ã®ãã€ãã¹æ¹æ³ãç¿åŸããŠããåŠçã¯ãå ¬éãããŠãããœãããŠã§ã¢ã䜿çšããŠã·ã¹ãã ãã¹ãã£ã³ã§ããŸãã ããã¯ããã®ã¿ã€ãã®æ»æã®ã»ãšãã©ãç±³åœããæ¥ããšããäºå®ã説æããŠããŸããå ¬çäºæ¥ããªã³ã©ã€ã³ãµãŒãã¹ãç±³åœã«ãããããã·ã䜿çšããå¯èœæ§ããããŸãã æ å ±ããã³åæã»ã³ã¿ãŒã«å¯Ÿããæ»æã®ç®æšã¯ãè©Šéšçµæããã³è©Šéšè³æãžã®ã¢ã¯ã»ã¹ã§ããå¯èœæ§ãæãé«ãã£ãã ããããåŠçã¯ããã®æ¹æ³ã§è©Šéšã®ããã«åŸãããã¹ã³ã¢ãå€æŽã§ãããšèããŸããã ããã«ãæ»æè ãè匱æ§ãèŠã€ããããšãããšæ³å®ã§ããŸããè匱æ§ãæªçšãããšããã®åŸã®éæ³é åžã®ããã«è©Šéšè³æã®ããŒã¿ããŒã¹ã«ã¢ã¯ã»ã¹ã§ããŸãã
ç£æ¥ã·ã¹ãã ã®å ŽåãPT AFã¯1æ¥ãããçŽ50ã®æ»æãèšé²ããã»ãšãã©ãã¹ãŠãèªååãããè匱æ§æ€çŽ¢ã§ãããæåã§å®è¡ãããã®ã¯1ïŒ ã ãã§ããã
次ã®å³ã¯ãåæ¥çã®æ»æè ã«ãã£ãŠå®è¡ãããæ»æã®çš®é¡ã®é¢ä¿ã瀺ããŠããŸããè匱æ§ã®èªåã¹ãã£ã³ã®äžéšãšããŠå®è¡ãããæ»æã¯ãç¹å®ã®æ¥çã«åºæã§ã¯ãªããããèšç®ããé€å€ãããŸããã
æåã§å®è¡ãããæ»æã®çš®é¡ã®å²å
æ¿åºæ©é¢ã®å Žåã70ïŒ ä»¥äžããã¹ãã©ããŒãµã«æ»æã§ããããã®å©ãã«ãããæ»æè ã¯ãã¡ã€ã«ã·ã¹ãã ã®çŸåšã®ãã£ã¬ã¯ããªãè¶ ããŠããµãŒããŒäžã®ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ããŠæ©å¯æ å ±ãçãããšããŸããã
ãã¹ãã©ããŒãµã«æ»ææ€åºã®äŸã以äžã«ç€ºããŸãã æ»æè ã¯ããµãŒããŒã®ã«ãŒããã£ã¬ã¯ããªã«ç§»åããã·ã¹ãã ã®ãŠãŒã¶ãŒã¢ã«ãŠã³ãã®ãªã¹ããå«ã/ etc / passwdãã¡ã€ã«ã«ã¢ã¯ã»ã¹ããããšãæå³ããŠããŸããã
ãã¹ãã©ããŒãµã«æ»æã®æ€åºäŸ
æ»æã®çŽ17ïŒ ã¯ãSQLã¹ããŒãã¡ã³ããå®è£ ããããšããè©Šã¿ã§ãã å°ããªéšåïŒçŽ8ïŒ ïŒã¯ãå ¬å ±ãµãŒãã¹ããŒã¿ã«ã®ãŠãŒã¶ãŒã察象ãšããã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°æ»æã§æ§æãããŠããŸãã æ»æè ã¯ã2ïŒ ã®ã±ãŒã¹ã§OSã³ãã³ããå®è¡ããããšããŸããã
ãªã³ã©ã€ã³ã¹ãã¢æ»æã®4åã®3è¿ãããã¹ãã©ããŒãµã«æ»æã®åå ãšãªã£ãŠããŸãã æ»æè ã¯ãå ¬å ±ãµãŒãã¹ãæäŸããããŒã¿ã«ãšåæ§ã«ããã¡ã€ã«ã·ã¹ãã ã®çŸåšã®ãã£ã¬ã¯ããªãè¶ããããšè©Šã¿ãŸããã ããªãã®å²åïŒ14ïŒ ïŒããµãŒãã¹æåŠæ»æã§ãã ãªã³ã©ã€ã³ã¹ãã¢ã«ãšã£ãŠãWebã¢ããªã±ãŒã·ã§ã³ã®ã¢ã¯ã»ã·ããªãã£ã®è åšã¯éèŠã§ãã ãŠãŒã¶ãŒã«å¯Ÿããæ»æïŒãã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ãããã³ãã¯ãã¹ãµã€ããªã¯ãšã¹ããã©ãŒãžã§ãªãïŒã¯4ïŒ ã§ãã 4ïŒ ã®å ŽåãSQLã¹ããŒãã¡ã³ãã®å®è£ ãçºçããŸãã
éèã»ã¯ã¿ãŒã§ã¯ãå šäœã®çŽ65ïŒ ãã·ã¹ãã ãŠãŒã¶ãŒã察象ãšãããã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ãããã³ãã¯ãã¹ãµã€ããªã¯ãšã¹ããã©ãŒãžã§ãªãæ»æã§ããã ãã®ãããªæ»æã¯ãéèæ¥çã§åºãæ®åããŠãããCookieã®å€ãšãŠãŒã¶ãŒã®è³æ Œæ å ±ãïŒãã£ãã·ã³ã°ã䜿çšããŠïŒçã¿åºããæ£åœãªãŠãŒã¶ãŒã«ä»£ãã£ãŠã¢ã¯ã·ã§ã³ãå®è¡ã§ãããããç¹å¥ãªå±éºããããããŸãã
ãã®å³ã¯ããã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ãæ»æãèå¥ããäŸã瀺ããŠããŸãã æ»æè ã¯ããã®æ»æã«å¯ŸããWebã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ã確èªããããã«Cookieå€ã衚瀺ããããšããŸããã
ã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°æ»ææ€åºã®äŸ
æ»æè ã¯ããã¹ãã©ããŒãµã«æ»æïŒå šäœã®15ïŒ ïŒãšSQLã¹ããŒãã¡ã³ãã®å®è£ ïŒå šäœã®7ïŒ ïŒã䜿çšããŠãæ©å¯æ å ±ã«ã¢ã¯ã»ã¹ããããšããŸããã ãä»»æã®ãã¡ã€ã«ãããŠã³ããŒããããæ»æã®å²åã¯7ïŒ ã§ããã ãã®ãããªæ»æã¯ãOSã³ãã³ãã®å®è¡ã«ã¢ã¯ã»ã¹ããããã«ãã䜿çšãããŸãããOSã³ãã³ãã®çŽæ¥å®è¡ã¯3ïŒ ã®ã±ãŒã¹ã§èšé²ãããŸããã äžè¬ã«ãæ»æã®æ§è³ªãšè€éãã¯ãæ€èšäžã®ä»ã®æ¥çãšæ¯èŒããŠãæ»æè ã®é«åºŠãªæè¡ãã¬ãŒãã³ã°ã瀺ããŠããŸãã
ITéšéã§ã¯ãå ±åãããæ»æã®åå以äžãSQLã¹ããŒãã¡ã³ãã®å®è£ ã®è©Šã¿ã§ãã ãã¹ãã©ããŒãµã«æ»æãååšããŸãïŒå šäœã®20ïŒ ïŒã ããã«ã16ïŒ ã¯OSã³ãã³ããå®è¡ããããšããè©Šã¿ã§ãããITäŒæ¥ã®Webã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããæ»æã®12ïŒ ã¯ã·ã¹ãã ãŠãŒã¶ãŒãæšçãšããŠããŸãã
茞éäŒç€Ÿã®Webã¢ããªã±ãŒã·ã§ã³ã®å ŽåããSQLã¹ããŒãã¡ã³ãã€ã³ãžã§ã¯ã·ã§ã³ãæ»æã®æ°ã¯50ïŒ ãè¶ ããçŽ38ïŒ ã¯æ å ±æŒæŽ©ã6ïŒ ã¯OSã³ãã³ãã®å®è¡ã§ãã
æè²åéã§ã¯ãæåæ»æã®çŽ70ïŒ ããSQLã¹ããŒãã¡ã³ãã€ã³ãžã§ã¯ã·ã§ã³ãã§ããã å€ãã®å Žåããã®æ»æã¯éåžžã«ç°¡åã«å®è¡ã§ãããŠãŒã¶ãŒã®å人ã¢ã«ãŠã³ããŸãã¯ããŒã¿ããŒã¹ã®ã³ã³ãã³ãã«ã¢ã¯ã»ã¹ããããã«äœ¿çšã§ããŸãã æ»æã®çŽ30ïŒ ã¯ããæ å ±æŒãããè匱æ§ã®æªçšã§ãããæ»æè ãæ©å¯ããŒã¿ãååŸããããã·ã¹ãã ã«é¢ããè¿œå æ å ±ãå ¥æãããããå¯èœæ§ããããŸãã
å³ã§ã¯ãSQLã¹ããŒãã¡ã³ãã®å°å ¥ãæ€åºããäŸãèŠãããšãã§ããŸã;æ»æè ã¯id GETãã©ã¡ãŒã¿ãŒã«ããŒã¿ããŒã¹ã¯ãšãªãå ¥åããŠãè匱æ§ã®æªçšã確èªããŸããã
SQLã€ã³ãžã§ã¯ã·ã§ã³æ»ææ€åºã®äŸ
ç£æ¥çšãšã³ã¿ãŒãã©ã€ãºã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããæ»æã®3åã®2è¿ãããµãŒãã¹æåŠïŒDDoSïŒæ»æã§ããã 次ã®å³ã¯ãDDoSãå«ã3ã€ã®æ»æãã§ãŒã³ãæ€åºããäŸã瀺ããŠããŸãã PT AFãã¡ã€ã¢ãŠã©ãŒã«ã¯ãæéééã空ããŠãããåäžã®æ»æã®äžéšã§ãããã€ãã³ãéã®çžé¢ãèå¥ããããšã«ããããã®ãããªãã§ãŒã³ãèªåçã«æ§ç¯ããŸãã
DDoSãå«ãé¢é£ã€ãã³ããæ€åºããäŸ
æ»æå
æ»æã®ãœãŒã¹ã®åæã¯ããã€ããããããžã§ã¯ãã«åå ãããã·ã¢ã®ã·ã¹ãã ã«å¯ŸããŠã®ã¿å®æœãããŸããã èšé²ãããæ»æã®æ倧æ°ã¯ãã·ã¢èªåã®åœã ããæ¥ãŠããããã·ã¢ãšãŠã¯ã©ã€ãã第äžäœã§ãã ãªã©ã³ããšç±³åœããçºä¿¡ãããæ»æã®å²åã¯éåžžã«é«ãã§ãããããã®åœã«ã¯ãããã·ãµãŒããŒãµãŒãã¹ãæäŸãããããã€ããŒãå€æ°ååšããããã§ãã
æ¥çå¥ã®å€éšæ»ææº
ãã·ã¢ã®çµç¹ã«å¯Ÿããå€éšæ»æã®ãœãŒã¹ã¯ãæ¥çã«ãã£ãŠç°ãªããŸãã æ¿åºæ©é¢ã«å¯Ÿããæ»æã®ã»ãšãã©ã¯ãã·ã¢ã®IPã¢ãã¬ã¹ããå®è¡ãããçŽ3åã®1ã¯ãŠã¯ã©ã€ãã®ãããã€ããŒã«å±ããIPã¢ãã¬ã¹ããå®è¡ãããŸãã6ïŒ ã®å Žåãéä¿¡å ã¯ãªã©ã³ãã§ãã
ã»ãŒçããã·ã§ã¢ïŒåèšã®çŽ4åã®1ïŒã®ãªã³ã©ã€ã³ã¹ãã¢ã«å¯Ÿããæ»æã®ãœãŒã¹ã¯ããã·ã¢ãšãŠã¯ã©ã€ãã§ãã æ»æã®3åã®1以äžã¯ãªã©ã³ãã®IPã¢ãã¬ã¹ãééããŸãã
äžèšã§ç€ºããããã«ãæè²éšéãžã®æ»æã§ã¯ãè匱æ§ã«ã€ããŠWebã¢ããªã±ãŒã·ã§ã³ãã¹ãã£ã³ããããã«å ¬å ±ãµãŒãã¹ãšãŠãŒãã£ãªãã£ãåºã䜿çšãããŠããŸãã ãã®ãããªãœãããŠã§ã¢ã¯ãæ»æå ã®å®éã®IPã¢ãã¬ã¹ãé ãããã«ãäž»ã«ç±³åœã«ãããµãŒããŒã䜿çšããŸãã æ»æã®5çªç®ã¯ãã·ã¢ã®IPã¢ãã¬ã¹ããã®ãã®ã§ãã
èå³æ·±ãããšã«ã倧åŠã®Webã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããæ»æã®3åã®1以äžã¯ãå éšäŸµå ¥è ïŒæè²éšéã§å¹³å8ïŒ ïŒã§ããããšã«æ³šæããŠãã ããã ããããããããã¯æè²æ©é¢ã®ç¡ç·ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãšãæ宀å ã®ããŒã«ã«ãããã¯ãŒã¯ãžã®ã¢ã¯ã»ã¹ãæã€åŠçã§ãã
å€éšãšå éšã®éåè ã®å²å
éèã»ã¯ã¿ãŒã§ã¯ãæ»æã®çŽ10ïŒ ãå éšã®äŸµå ¥è ã«ãããã®ã§ãã å Žåã«ãã£ãŠã¯ãé²åŸ¡ã¡ã«ããºã ããã¹ãããã·ã¹ãã 管çè ãäŸµå ¥è ã«ãªãå¯èœæ§ããããŸãã
ãããã«
PT AFãã€ããããããžã§ã¯ãã®çµæã«åºã¥ããŠãæ»æè ã«ãã£ãŠå®è¡ãããæ»æã®ã»ãšãã©ã¯ãå®è¡ããã³WAFã¿ã€ãã®ã»ãã¥ãªãã£æ©åšã«ããæ€åºã®äž¡æ¹ã§éåžžã«åçŽã§ãããšçµè«ä»ããããšãã§ããŸãã
åæã«ã2016幎ã®åŸåã«ã¯ãäž»ã«ãŠã¯ã©ã€ããšãã«ã³ã®IPã¢ãã¬ã¹ããã®WebãªãœãŒã¹ã«å¯Ÿããæ»æã®æ°ãå€§å¹ ã«å¢å ããŸããã èšç»ããããµã€ããŒæ»æã«é¢ããé£éŠä¿å®å±ã®å ±åãèæ ®ã«å ¥ããŠããã·ã¢ã®äŒæ¥ãç¹ã«éèæ©é¢ã¯ãéèŠãªã³ã³ããŒãã³ããä¿è·ãã䜿çšããä¿è·å ·ã®æå¹æ§ãæ€èšŒããããã«ãäºåã«é©åãªæªçœ®ãåãããšããå§ãããŸãã
åçŽãªæ»æã¯å€æ°ãããŸãããçŸä»£ã®æ»æè ã®æè¡çãã¬ãŒãã³ã°ã®ã¬ãã«ã«ãããããŸããŸãªæç¹ã§çºçããäžèŠçžäºã«é¢é£ããŠããªãå€ãã®ã¢ã¯ã·ã§ã³ãå¿ èŠãšããé«ã¬ãã«ã®æ»æãå®è£ ã§ããããšãèæ ®ã«å ¥ããå¿ èŠããããŸãã é·æçãªæšçåæ»æã®æ€åºãã€ã³ã·ãã³ãã®èª¿æ»ãªã©ãããããæ»æã®é£éãç¹å®ããã«ã¯ãçžé¢åæããŒã«ã䜿çšããå¿ èŠããããŸãã
調æ»ã®å®å šçã¯ãã¡ãããå ¥æã§ããŸã ã
èè ïŒãšã«ããªãŒãã»ããªã¥ã·ã§ã¯ããšãã²ããŒã»ã°ããã£ã³
PS 4æ27æ¥ïŒæšïŒ 14:00ã«ã Positive Technologiesã®ã·ãã¢ãšãã¹ããŒãVsevolod Petrovãç¡æã®ãŠã§ãããŒãéå¬ãããã®éã«ããã«ãŒãWebã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããæ»æãæåãããçç±ãšããããé²ãæ¹æ³ã«ã€ããŠèª¬æããŸãã
ããã«ãåŸæ¥ã®å¢çã»ãã¥ãªãã£ããŒã«ã匷åããããããé¢ã§ã»ãã¥ãªãã£ãæäŸããã®ã«åœ¹ç«ã€PTã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ã®ã¢ããªã±ãŒã·ã§ã³ã¬ãã«ã®ãã¡ã€ã¢ãŠã©ãŒã«ã®æè¡çèœåã«ã€ããŠèª¬æããŸãã
ãŠã§ãããŒãžã®åå ã¯ç¡æã§ããwww.ptsecurity.com/ ru-ru / research / webinar / 226999 /ã§ç»é²ã§ããŸãã