ãããè¡ãããã«ãHacker Newsã§å ¬éãããæãè©äŸ¡ã®é«ãè³æãšãHabrahabrããã³Geektimes.ruã®WannaCryãããã¯ã§å ¬éããããã¹ãŠã®ãã®ãåãäžããããšã«ããŸããã ITMO倧åŠã®å°é家ã®ã³ã¡ã³ãã§æçµçãªããŒãéžæãè£è¶³ããŸããã
Flickr / Michele MF / CC
圌ããèšãã圌ãã
WannaCryã«å ¬éãããããã€ã¹ã®éžæ
ç§ãã¡ã¯ããŠãŒã¶ãŒã®ã¹ããŒããã©ã³ã®ã¬ã³ãºã«åãŸãé©åãªããã€ã¹ã®ã³ã¬ã¯ã·ã§ã³ããå§ããããšã«ããŸããã èè ã¯ãããŸããŸãªäŸãåéããããšãã§ããŸããïŒèªå® ã®PCãããªãã£ã¹ã·ã¹ãã ãæ¯æãåä»ãã€ã³ããŸã§ã ãã§ã«WannaCryã®èªå€§åºåã«ããããããŠãã人ã®ããã«ãè³æã®æåŸã«ç¹å¥ãªã»ã¯ã·ã§ã³ããããŸã ã
ã€ã³ã¿ãŒããããæã£ããã¯ã€ããããã®ããã®1幎éã®ç¡æãã¶ãš1äžãã«
äž»äººå ¬ã®èº«å ãã¡ãã£ã¢ã§æããã«ãããçŽåŸãå€ãã®äŒæ¥ãã€ãã·ã¢ãããåããITã³ãã¥ããã£ã«ãµãŒãã¹ãæäŸããããã®éžæè¢ãæäŸããŸããã ãå¯å€§ãªãäŒæ¥ã®å ¬æ£ãªå ±é ¬ãŸãã¯èªå·±å®£äŒã¯ããªã次第ã§ãã
WannaCryãWcryãWannaCryptã«é¢ãããã¹ãŠã®å¿ èŠãªæ å ±
ãã€ã¯ããœãããšçŽæ¥é¢ä¿ã®ããã»ãã¥ãªãã£ã®å°é家ã§ããããã€ãã³ãã¯ã5æ13æ¥ããWannaCryã«é¢ããããŒã¿ã®åéãéå§ããŸããã ã€ãã³ããçºçããã«ã€ããŠãè³æã«ã¯æè¡çãªè©³çŽ°ãšããŸããŸãªåæïŒã©ã³ãµã ãŠã§ã¢ãšã©ã³ãµã ãŠã§ã¢ã®ãäœæ¥ãã®è²¡åçµæãå«ãïŒãè¿œå ãããŸããã ãšããããTroyã¯OSã®æŽæ°ãæåŠãã¹ãã§ãªãçç±ã«é¢ããå¥ã®èšäºãæžããŸããã
WannaCryïŒå²äžæã人æ°ã®ããã©ã³ãµã ãŠã§ã¢ãŠã€ã«ã¹
ãã€ã¯ããœããã®MVPã®1ã€ã¯ãã©ã³ãµã ãŠã§ã¢ãšã©ã³ãµã ãŠã§ã¢ããªããšãããŠãå®è¡ããããã¹ãŠã®ããŒãã«é¢ããWikiããŒãžããŸãšããŸããã ããã§ã¯ãææãã©ã®ããã«çºçãããã«ã€ããŠã®æ å ±ãèŠã€ããããšãã§ããäºé²æªçœ®ã®æšå¥šäºé ãååŸã§ããŸãã ãããªã¢ã«ã«ã¯ãèšå€§ãªæ°ã®æçšãªãªã³ã¯ãå«ãŸããŠããŸãïŒãšãã¹ããŒãã®ã¹ããŒãªãŒã®æ¬¡ã®3ã€ã®éšåãå«ãïŒã
æ°ããWannaCryããªãšãŒã·ã§ã³ãçºèŠãããŸãã
WannaCryã®æ°ããåçš®ãšã¯äœãã«é¢ããç°¡åãªã¡ã¢ã killã¹ã€ããã䜿çšããå Žåãšäœ¿çšããªãå Žåã®æ©èœãšäŸã å°é家ã¯ã圌ã®ããã°ã®æçš¿ã«å ããŠãNYtimesããŒãèšäºã§ç°¡åãªè§£èª¬ãè¡ããããã€ãã®äŸãšæ¯èŒãåéããŠãWannaCryãšLazarus Groupã®é¢ä¿ã確èªããŸããã
WannaCryïŒWanaKiwi +ãã¢ã䜿çšãã埩å·å
WannaCryã«ãã£ãŠå ¬éãããããŒã¿ã解èªããããã®å®çšçãªã¬ã€ãã Windows XPïŒx86ïŒããWindows 7ïŒx86ïŒãWindows 2003ïŒx86ïŒãVistaã2008ããã³2008 R2ãŸã§ã®ããŒãžã§ã³ã§ãã¹ãæžã¿ã
圌ãããç§ãã¡ãšããšèšãããš
WannaCryptã®æmailããã°ã©ã ã¯ãæŽæ°ãããŠããªãã·ã¹ãã ãæ»æããŸã
ãã®ãããã¯ã«é¢ããäž»èŠãªå°éç¥èããè匱æ§èªäœãŸãã¯ISã®åé¡ã«é¢é£ããäœããã®æ¹æ³ã§ã倧äŒæ¥ã«ä»£ãã£ãŠæäŸãããããšã¯é©ãããšã§ã¯ãããŸããã ãã€ã¯ããœãããäŸå€ã§ã¯ãªããç¶æ³ãåæããèšäºã®ç¿»èš³çãçšæããŸãããããã¯5æ12æ¥ãå瀟ã®å ¬åŒããã°ã§å ¬éãããŸããã
WannaCryïŒåæã䟵害ã®ææšãããã³äºé²ã®ããã®æšå¥šäºé
ã·ã¹ã³ã¯ãæå·åããã°ã©ã ã®èª¿æ»çµæãè¡å人ãšå ±æããŠããŸãã ã³ã¢è³æã¯ãCisco Talosã®å°çšéšéã«ãã£ãŠæºåãããŸããã è±èªçã¯ãã¡ãã§ã芧ããã ããŸã ã
WannaCryã©ã³ãµã ãŠã§ã¢ãã¡ããªãŒæ»æïŒç¶æ³åæãšæ¬¡ã®æ»æãžã®æºå
Panda Securityã¯ã5æ12æ¥ã«äœãèµ·ãã£ãã®ãã«ã€ããŠã®èŠè§£ã瀺ããWannaCryãšä»¥åã«èŠãä»ã®æ»æãšã®éãã«ã€ããŠè©±ããŸããã 次ã®åºæºãèšèŒãããŠããŸãïŒææã®æ¹åãè匱ãªã·ã¹ãã ãšã®çžäºäœçšãé åžããã³æå·åããã»ã¹ã ããã«ãå瀟ã¯æçšãªæšå¥šäºé ãšé¢é£ãªã³ã¯ãæäŸããŸããã
Wannacry-X-Teamãã¢ãŠã§ã€
CROCã¯ãå©ããæ±ãã顧客ãšã®ã³ãã¥ãã±ãŒã·ã§ã³ãã©ã®ããã«ãããããããã«é¢ããå®è·µçãªè³æãæžããŸããã ããã«ãå°é家ã¯ããã®å Žã§å¯Ÿå¿ãããšèããè¡åã®éžæè¢ãæããŸããã ãããäœããããããã®ãã圌ãã¯ã»ãšãã©ããã«Wannacryãæ¢ãã-è³æãèªãã§ãã ããã
Wana Decrypt0r 2.0ã©ã³ãµã ãŠã§ã¢åæ
Wana Decrypt0r 2.0ã©ã³ãµã ãŠã§ã¢æ©èœïŒWannaCryã®2çªç®ã®ããŒãžã§ã³ïŒã®èå³æ·±ãåæã¯ãTïŒT SecurityãšPentestitã®å°é家ã«ãã£ãŠæºåãããŸããã å®å šãªã»ããã¯æ¬¡ã®ãšããã§ããçµ±èšãæè¡çãªãã¥ã¢ã³ã¹ãåæäžã®èæ ®äºé ã
WannaCry 2.0ïŒããã¯ã¢ããã絶察ã«å¿ èŠã§ããããšã®æ確ãªç¢ºèª
WannaCryã®ç°¡åãªçŽ¹ä»ããã®åäœåçãããã³èªè ã«åœ¹ç«ã€å¯èœæ§ã®ããã¢ã¯ããã¹è£œåã«å ããŠãå瀟ã¯ãç ç²è ãã®èå³æ·±ããªã¹ããæäŸããŠããŸãã
ãã®ç·ã¯ãæå·ã©ã³ãµã ãŠã§ã¢WannaCryptã®ã°ããŒãã«ãªé åžã誀ã£ãŠåæ¢ããŸãã
ãªããžã§ã³Geektimes.ruã¯ããããã¯ã«é¢ããææ°ãã¥ãŒã¹ãå ±åããŸãã ãã€ã³ã¿ãŒããããæã£ãããšããå¶ç¶ã®çºèŠã®ç©èªã«å ããŠã MicrosoftãNSAãæªçšã®èç©ã§éé£ããæ¹æ³ãããã³åæ¢ã¯ã¬ãŒã³ãªããå«ãæ°ããWannaCryããªãšãŒã·ã§ã³ã«ã€ããŠèªãããšãã§ããŸãã
åœã®WannaCryãHPã«ã¯fireããŒãã¬ãŒããããChromeã¯äœåãª
ã«ã¹ãã«ã¹ããŒã¯ããã«ãŠã§ã¢ã«å¯Ÿããèªå€§åºåã®çµæãåæããŸãã äŸãšããŠã¯ããœãããŠã§ã¢ã®æãåºæ¬çã§ç¡å®³ãªæ©èœãæ»æè ãæåã«äœ¿çšãããã®ã§ããããšãæ¹ããŠæãèµ·ããããææ°ãã¥ãŒã¹ãããã€ããããŸãã
CVE-2017-0263ã®Windowsæš©éææ Œã®è匱æ§ã®è§£æ
Positive Technologiesã¯ãWannaCryã«é¢ãããã¥ãŒã¹ããã©ããŒããã³ã³ããã¹ãã¡ãã¥ãŒã®è匱æ§ãšæäœãªãã·ã§ã³ã«ã€ããŠè©±ãããšã«ããŸããã
ITMO倧åŠã³ã³ãã¥ãŒã¿ãŒãã©ã¬ã³ãžãã¯ç 究ææé·ãKuzmich Pavel AlekseevichïŒ
ã»ãšãã©ã®å Žåãææãèšé²ããçµç¹ã®åŸæ¥å¡ã¯ã³ã³ãã¥ãŒã¿ãŒã䜿çšããŠã¡ãŒã«ãåä¿¡ããã€ã³ã¿ãŒãããããµãŒãã£ã³ããåãåã£ãæçŽãéããWebãµã€ãã®ã»ãã¥ãªãã£ã確信ããã«ãã«ãŠã§ã¢ãããŠã³ããŒãããŸããã
ãã®ããã«ããŠã顧客ã®æ©å¯æ å ±ã䟵害ãããå¯èœæ§ããããŸã-å¶å©çµç¹ã®å Žåãããã³æ¿åºæ©é¢ã®å Žåã倧éã®å人ããŒã¿ã ãã®ãããªæ å ±ããããã®ã³ã³ãã¥ãŒã¿ãŒã§åŠçãããªãã£ãããšãæãŸããŸãã
ã©ã³ãµã ãŠã§ã¢ã¯è©æ¬ºã®ããç¥ãããæ¹æ³ã§ããããŸã ä¿è·ã®ããã®ç¹å®ã®ã¢ãããŒãããããŸãã ãŸããWebäžã®ç¹å®ã®ãªã³ã¯ã®ã¯ãªãã¯ã«æ³šæããå¿ èŠããããŸãã åæ§ã«ãã¡ãŒã«ã§ã-ã€ã³ã¿ãŒããããããã€ããŒãŸãã¯éè¡ããã®æçŽã«æ·»ä»ããããã¡ã€ã«ã§ãŠã€ã«ã¹ãæ¡æ£ããããšãéåžžã«å€ããããŸãã 第äžã«ãå°ãªããšãæã ãéèŠãªããã¥ã¡ã³ãã®ããã¯ã¢ããã³ããŒãå¥ã®ãªã ãŒããã«ã¡ãã£ã¢ã«äœæããããšãéèŠã§ãã
ã»ãšãã©ã®å ŽåããŠã€ã«ã¹ã®ææãšã¢ã¯ãã£ããã§ãŒãºïŒããŒã¿æå·åïŒã¯ãã³ã³ãã¥ãŒã¿ãŒã®ããã©ãŒãã³ã¹ã®å€§å¹ ãªäœäžãšããŠçŸããŸãã ããã¯ãæå·åãéåžžã«ãªãœãŒã¹ãæ¶è²»ããããã»ã¹ã§ãããšããäºå®ã®çµæã§ãã ããã¯ãç解ã§ããªãæ¡åŒµåã®ãã¡ã€ã«ã衚瀺ããããšãã«ãæ°ä»ãããšãã§ããŸãããéåžžããã®æ®µéã§ã¯ã¢ã¯ã·ã§ã³ãå®è¡ããã«ã¯é ãããŸãã
ãŠã€ã«ã¹ã¢ããªã¹ããITMO倧åŠã®ITã»ãã¥ãªãã£ã®å°é家ã§ãããåœéçãªã³ã³ãã¥ãŒã¿ãŒæ å ±ä¿è·ç«¶äºã®åè ã§ããGrigory SablinïŒ
æ»æè ã¯SMBãããã³ã«MS17_010ã®è匱æ§ã䜿çšããŸã-ãããã¯æ¢ã«MicrosoftãµãŒããŒã«ãããŸãã æŽæ°ãããŠããªã人ã¯ããã£ã¹ããªãã¥ãŒã·ã§ã³ã«è©²åœããå¯èœæ§ããããŸãã ãããããããã®ãŠãŒã¶ãŒèªèº«ã®ããã ãšèšãããšãã§ããŸã-圌ãã¯æµ·è³çãœãããŠã§ã¢ã䜿çšããããWindowsãæŽæ°ããŸããã§ããã ç§èªèº«ãç¶æ³ãã©ã®ããã«çºå±ãããã«èå³ããããŸããMS08_67ã§ãåæ§ã®è©±ãããããã®åŸãKidoã¯ãŒã ãããã䜿çšããå€ãã®äººãææããŸããã
ããã¯ããããã¹ãŠã®ãã¡ã€ã«ãå埩ã§ãããšããäºå®ã§ã¯ãããŸããã å€ãã®ã³ã³ãã¥ãŒã¿ãŒããŸã æŽæ°ãããŠããªãããããã®ãŠã€ã«ã¹ã¯ã©ãã«ã§ãäŸµå ¥ããå¯èœæ§ããããŸãã ã¡ãªã¿ã«ããã®ãšã¯ã¹ããã€ãã¯ãç±³åœåœå®¶å®å šä¿éå±ïŒNSAïŒããããªãŒã¯ããããã¢ãŒã«ã€ãããååŸãããŸãããã€ãŸããããã¯ç¹å¥ãªãµãŒãã¹ãç·æ¥äºæ ã§ã©ã®ããã«æ©èœãããã®äŸã§ãã
PSèå³æ·±ããšæãããè¿œå è³æãæèŠã®ã³ã¡ã³ãã§ã®è°è«ã«æè¬ããŸãã ãã®éžæããŸãšãã:)