
ã¡ãŒã«èªèšŒãšã¯äœã§ããïŒ
éå»40幎ã®ã»ãšãã©ã®éããŠãŒã¶ãŒã¯ã¡ãŒã«ãéããã³ã«ä¿¡é ŒãåŸãå¿ èŠããããŸããã æçŽã¯æ¬åœã«éä¿¡è ã«ãªã¹ããããŠãã人ããæ¥ãŠãããšæããŸããïŒ ã»ãšãã©ã®äººã¯ç°¡åã«ãã¯ãããšçããŸããå®éãã»ãšãã©ãã¹ãŠã®éä¿¡è ããã®é»åã¡ãŒã«ãåœè£ ããããšãã©ãã»ã©ç°¡åããç¥ããšéåžžã«é©ãã§ãããã
ã€ã³ã¿ãŒããããäœæããéãéä¿¡è ã®èº«å ã確èªããæ¹æ³ã¯å ã éçºãããŠããŸããã§ããã ã³ã¢ã¡ãŒã«ãããã³ã«ã®éçºäžãã³ã³ãã¥ãŒãã£ã³ã°èœåãå®è£ ãããã³äœ¿ããããã®ã³ã¹ãã¯ãè©æ¬ºã®ãªã¹ã¯ãšãã©ã³ã¹ãåããŠããŸããã å°æ¥ã®ãã¹ãŠã®é»åã¡ãŒã«ã®84ïŒ ãæªæã®ãããã®ã§ããããã£ãã·ã³ã°ãŸãã¯ã¹ãã ã§ãããšæ³å®ããããšã¯å°é£ã§ããã
ãã®çµæãFromïŒããã³Reply-toïŒãã£ãŒã«ããå«ãã¡ãã»ãŒãžããããŒã¯éåžžã«ç°¡åã«åœé ãããŸãã å Žåã«ãã£ãŠã¯ããFromïŒããã£ãŒã«ãã«ãjohn@company.comããšå ¥åããã ãã§ç°¡åã§ãã ããã«çãã®ãªãã³ã³ãã³ãã説åŸåã®ããã°ã©ãã£ãã¯ã¹ããã©ãŒããããçµã¿åãããããšã§ãã¡ãŒã«ããã¯ã¹ã®ã¡ãã»ãŒãžãå®éã«éè¡ãé£éŠçšåå±ãç±³åœã®å€§çµ±é ãŸãã¯å€§çµ±é ããæ¥ããšæããã人ã ã欺ãããšãã§ããŸãã

é»åã¡ãŒã«ã®æ®éæ§ãèãããšãçŸåšã®æ å ±ã»ãã¥ãªãã£å±æ©ã®åºç€ãç¥ã£ãŠããŸãã é»åã¡ãŒã«ã®è匱æ§ã«ãããæªæã®ãããªã³ã¯ãã¯ãªãã¯ãããæªæã®ãããã¡ã€ã«ãããŠã³ããŒãããŠéããW-2ãã©ãŒã ïŒç±³åœã®2-NDFLã«é¡äŒŒïŒãéä¿¡ããããŸãã¯ç¯çœªè ã®ã¢ã«ãŠã³ãã«è³éã転éããããšãç®çãšãããã£ãã·ã³ã°æ»æãæ°å€ãçºçããŠããŸãã
æè¿ã§ã¯ãã·ãªã³ã³ãã¬ãŒã®äŒç€Ÿã§ããCoupaã¯ã625人ã®åŸæ¥å¡ãã¹ãŠã®çµŠäžããŒã¿ãè©æ¬ºåž«ã«éã£ãåŸã泚ç®ãéããŠããŸãã æšå¹ŽããšãŒãããæ倧ã®äŒæ¥ã®1ã€ã§ããLeoni AGã¯ãåŸæ¥å¡ãåœã®ã¡ãŒã«ã«ããäžæ£ã«è©æ¬ºåž«ã®å£åº§ã«ééããããã4500äžãã«ã倱ããŸããã FBIã«ãããšããBusiness Email CompromiseãïŒBECïŒãªã©ã®ãã£ãã·ã³ã°æ»æã¯ãç±³åœäŒæ¥ã«å¹Žé30åãã«ã®ã³ã¹ããããããŸãã
W-2圢åŒã®ãã£ãã·ã³ã°ãã¡ã¯ãã®ãªã¹ãã¯ãdatabreaches.netã«ãŸãšããããŠããŸãã ä»å¹Žã®ãªã¹ãã§ã®äœæ¥ã¯ã2016幎以éã®çäŸæ°ãå¢å ããŠããããšã瀺ããŠãããçŸæç¹ã§ã¯204ã®ã¬ããŒãã§æ§æãããŠããŸã ã ãªã¹ããããæ°å人ã®åŸæ¥å¡ããã®ããŒã¿ã®çé£ã®äºäŸãç¥ãããŠããããã®ã¿ã€ãã®è©æ¬ºãéåžžã«äžè¬çã§ããããšãç解ã§ããŸãã
æ»æè ã5åæªæºã§ã»ãšãã©èª°ããã§ãä¿è·ãããŠããªãã¡ãŒã«ãåœé ããæ¹æ³
å®éããéä¿¡å ããã£ãŒã«ãã®åœã®ã¢ãã¬ã¹ã¯ãã»ãšãã©ã®æ»æã®åºç€ãšåæ段éã§ãã åæ§ã®åœã®ãã¡ã€ã³ïŒããšãã°ãc0mpany.comïŒãç»é²ããŠäœ¿çšããããšãå¯èœãªã®ã«ãæ¡ä»¶ä»ãã®ãcompany.comãããã®é»åã¡ãŒã«ãåœé ããããšãå¿é ããã®ã¯ãªãã§ããã ãŸãã¯ãGmailã¢ã«ãŠã³ãïŒrandomaddress1347356@gmail.comïŒãäœæããäŒç€Ÿã®CEOã®ååã®ãããªããããããååãä»ããŸããïŒ å®éãå®åšã®äººç©ã®ã¢ãã¬ã¹ããã®æçŽã®éä¿¡ã¯ãåœã®ãã¡ã€ã³ãç»é²ããããGmailã¢ã«ãŠã³ããäœæããããããããç°¡åã§ãã
3ã€ã®ç°¡åãªæ¹æ³
ã€ã³ã¿ãŒãããã§ã¯ãåœã®æçŽãéä¿¡ã§ãããµã€ããç°¡åã«èŠã€ããããšãã§ããŸãã spoofbox.comãšanonymailer.netãšããæ°åã®äŸããããŸãã ãããã®å€ãã¯ç¡æã§ãããããè²»çšããããããããã®ãµãŒãã¹ã¯æ£åœãªãã®ãšããŠäœçœ®ä»ãããã䜿çšã®äž»ãªç®çã¯å人ãåŒãå¯ããããšã§ãã
䜿çšã¢ã«ãŽãªãºã ã¯ç°¡åã§ãã åä¿¡è ã®é»åã¡ãŒã«ã¢ãã¬ã¹ã[å®å ]ãã£ãŒã«ãã«å ¥åãã[éä¿¡è ]ãã£ãŒã«ãã«ä»»æã®é»åã¡ãŒã«ã¢ãã¬ã¹ãå ¥åããã ãã§ãã¡ãã»ãŒãžãäœæããåŸãéä¿¡ã確èªã§ããŸãã ãŠãŒã¶ãŒå¥çŽã®æ¡ä»¶ã§ã¯ãæ害ã«å¯Ÿãã責任ã¯å®å šã«ãµãŒãã¹ã®é¡§å®¢ã«ãããŸãã
次ã®æ¹æ³ã¯ã UNIXã³ãã³ãã©ã€ã³ã䜿çšããŠéä¿¡ããããšã§ãã ã¡ãŒã«ãµãŒãã¹ãæ§æãããã³ã³ãã¥ãŒã¿ãŒãããå Žåã¯ã次ã®ã³ãã³ããå ¥åããŸãã
mail -aFrom:whatever@anydomain.com
çµæã¯ããFromããã£ãŒã«ãã«ãany@anydomain.comããå«ãŸããã¡ãã»ãŒãžã§ãã 件åãšã¡ãã»ãŒãžã®æ®ãã®éšåãå ¥åãããšãCtrl + DãæŒããåŸãã¡ãã»ãŒãžãåä¿¡è ã«éä¿¡ãããŸãã ãã®ã¢ã€ãã¢ã®æçšæ§ã¯ãã·ã¹ãã ã®æ§ææ¹æ³ã«ãã£ãŠç°ãªããŸãã ãã ããå€ãã®å Žåã«æ©èœããŸãã
PHPã䜿çšãããšãæ°è¡ã®éåžžã«åçŽãªã³ãŒãã§ã¡ãŒã«ãäœæã§ããŸãã
<?php $to = 'nobody@example.com'; $subject = 'the subject'; $message = 'hello'; $headers = 'From: webmaster@example.com' . "\r\n" . 'Reply-To: webmaster@example.com' . "\r\n" . 'X-Mailer: PHP/' . phpversion(); mail($to, $subject, $message, $headers); ?>
å®éããããã¯ãè¿œå ã®/ããããŒããããŒãæã€ã¡ãŒã«éä¿¡ïŒïŒé¢æ°ã®ãªã³ã©ã€ã³ããã¥ã¢ã«ã§äŸãšããŠäœ¿çšãããŠããã³ãŒãè¡ã§ãã
ãããã®ãªãããŸãããŒã«ã¯å€§å¹ ã«ç°¡çŽ åãããŠããŸãã ã¡ãã»ãŒãžããããªã¢ã«ã«ããã«ã¯ãããå°ãäœæ¥ãå¿ èŠã§ãããã¡ããããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®ã¹ãã«ãå¿ èŠã§ãã ããããäž»èŠãªæè¡ã³ã³ããŒãã³ãã¯éåžžã«åçŽã§ãã ã¹ããŒãã£ã³ã°ãæ¬åœã«é²æ¢ããå¯äžã®ãã®ã¯ãSPFã¬ã³ãŒããDKIM眲åãããã³DMARCãå ±æããããšã«ããé»åã¡ãŒã«èªèšŒã§ãã 次ã«ããããã®ãã¯ãããžãŒãã©ã®ããã«æ©èœããã©ã®ããã«ç°ãªããã説æããŸãã ãããã¯æ°ãããã®ã§ã¯ãããŸãããã幞ããªããšã«è©æ¬ºåž«ã«ãšã£ãŠã¯ãã€ã³ã¿ãŒãããäžã®ã»ãšãã©ã®ãã¡ã€ã³ã¯ãŸã ä¿è·ãããŠããŸããã ããšãã°ã.govãã¡ã€ã³ã®çŽ4ïŒ ã®ã¿ãèªèšŒã䜿çšããŸãã ä»ã®96ïŒ ã¯ã©ãã§ããïŒ æ»æè ã¯ããããã®ãã¡ã€ã³ã®ã¡ãŒã«ããã¯ã¹ããéä¿¡ãããããã«è£ ã£ãã¡ãŒã«ããã€ã§ãéä¿¡ã§ããŸãã
æ å ±æºã«ãããšã.govãã¡ã€ã³ããã®4ã€ã®é»åã¡ãŒã«ã®1ã€ã¯è©æ¬ºã§ãã ãã¡ã€ã³justice.govãHouse.govãSenate.govãWhitehouse.govãããã³democrats.orgãdnc.orgãgop.comãrnc.orgã ãšDonaldJTrump.com-ãããã¯ãã¹ãŠãé»åã¡ãŒã«è©æ¬ºåž«ã«ãããªãããŸãã«ç°¡åã«äœ¿çšã§ããŸãã
ãªãããŸãããä¿è·ããæ¹æ³
äžèšã®èªèšŒãªãã§é»åã¡ãŒã«ã®è匱æ§ã䜿çšããã·ã³ãã«ããšãæ倧ã®ãµã€ããŒæ»æã®åæ段éãšããŠãããã®æ¹æ³ãåºã䜿çšããããšã«ãããITã³ãã¥ããã£ã¯é»åã¡ãŒã«èªèšŒãã¯ãããžãŒã䜿çšããå¿ èŠæ§ã«çŠç¹ãåœãŠãŠããŸãã é»åã¡ãŒã«èªèšŒãå®è£ ããããšã«ãããé»åã¡ãŒã«ãåä¿¡ãããã¹ãŠã®ãŠãŒã¶ãŒïŒåŸæ¥å¡ã顧客ããŸãã¯ããŒãããŒïŒããé»åã¡ãŒã«ãäŒç€Ÿã®æ£åœãªä»£è¡šè ã«ãã£ãŠéä¿¡ããããã©ãããå€æã§ããããã«ãªããŸãã ããã«ããŠãŒã¶ãŒã«ä»£ãã£ãŠã¡ãŒã«ãéä¿¡ãããŠãŒã¶ãŒãéæã«ããå¶åŸ¡ã§ããŸãã
ã¯ã©ãŠããµãŒãã¹ïŒ SaaS ïŒã®æ¥éãªæé·ã«ããããã®éèŠæ§ã¯åçã«é«ãŸããŸãããã¯ã©ãŠããµãŒãã¹ïŒ SaaS ïŒã®1äžäººä»¥äžãã販売ãããŒã±ãã£ã³ã°ãã«ã¹ã¿ããŒãµããŒããHRãçµçãæ³åŸããã®ä»ã®ãµãŒãã¹ã察象ã«ãã¯ã©ã€ã¢ã³ãã«ä»£ãã£ãŠã¡ãŒã«ãéä¿¡ããŠããŸãã 匷å¶èªèšŒã®ãããã§ãã¹ãã éä¿¡è ããã£ãã·ã³ã°è©æ¬ºè ãããã«ã¯æ£åœãªãã®ã®èš±å¯ãªã¹ãã«èŒã£ãŠããªããã°ã¬ãŒãã®éä¿¡è ãªã©ãããªãã«ä»£ãã£ãŠã¡ãŒã«ãéä¿¡ããããšããŠãã人ããããã¯ã§ããŸãã
ã¡ãŒã«èªèšŒåºæºã«ãããã¡ãŒã«ãµãŒããŒã¯ãå·®åºäººïŒãã£ãŒã«ãã«ãã¡ã€ã³ãå«ãã¡ãŒã«ããŠãŒã¶ãŒã«ä»£ãã£ãŠéä¿¡ã§ããããšã確èªã§ããŸãã ã¡ãã»ãŒãžãåä¿¡è ã®åä¿¡ãã¬ã€ã«å°éããåã«ãã¡ãŒã«ãµãŒããŒã¯æ¬¡ã®ããšã確èªã§ããŸãã
- SPFã¬ã³ãŒãã䜿çšããŠãéä¿¡ãµãŒããŒã¯ã¡ãã»ãŒãžããããŒã§æå®ããããã¡ã€ã³åã䜿çšããæš©å©ãæã£ãŠããŸããïŒ
- ãã¡ã€ã³ã®DNSã¬ã³ãŒãã®ãªãŒãã³ããŒãžã§ã³ã®ããŒã䜿çšããŠãæå·åãããDKIM眲åãã¡ãã»ãŒãžã«æ·»ä»ãããŠããå Žåãçä¿¡ã¡ãã»ãŒãžã®ããããŒã解èªãã宣èšãããéä¿¡è ããã®ã¡ãã»ãŒãžãã©ããã確èªã§ããŸãã
- DMARCã®ã»ããã¢ããã«ããããã¡ã€ã³ææè ã¯èªèšŒãããŠããªããã¡ã€ã³ããåä¿¡ããã¡ãŒã«ãåŠçããããã®ã«ãŒã«ãäœæããããããŒãäºãã«äžèŽãããã©ããã確èªã§ããŸãïŒããšãã°ãFromïŒããã³Reply-to :)ãã£ãŒã«ãã ã«ãŒã«ã«ã¯ãåä¿¡ãµãŒããŒãèªèšŒãããŠããªãã¡ãã»ãŒãžãã©ã®ããã«åŠçãããã«é¢ããæ瀺ãå«ãŸããŠããŸããããšãã°ãã¡ãã»ãŒãžãã¹ãããããããã¹ãã ãã©ã«ããŒã«å ¥ããããæœåšçã«å±éºãšããŒã¯ãããããŸããã é»åã¡ãŒã«èªèšŒã«ããããã¡ã€ã³ææè ã¯ã誰ã«ã§ã代ãã£ãŠéä¿¡ãããã¡ãã»ãŒãžã®åŠçãã°ããŒãã«ã«å¶åŸ¡ã§ããŸãã ããšãã°ãã¡ãŒã«éä¿¡ãã¡ã€ã³ã代衚ããæ å ±ãèŠæ±ããDMARCã¬ã³ãŒããå ¬éãããšããã¡ã€ã³ããã®è¿ä¿¡ã¢ãã¬ã¹ãä»ãããã¹ãŠã®ã¡ãŒã«ã¡ãã»ãŒãžã«é¢ããDMARCããµããŒããããã¹ãŠã®åä¿¡è ãã¡ã€ã³ããçµ±èšæ å ±ãåãåããŸãã çµ±èšã¯XMLã§æäŸããããã¡ã€ã³ã«ãã£ãŠçœ²åãããåéä¿¡è ã®IPã¢ãã¬ã¹ãåIPã¢ãã¬ã¹ããã®ã¡ãã»ãŒãžæ°ããããã®ã¡ãã»ãŒãžãDMARCã«ãŒã«ã«åŸã£ãŠåŠçããçµæãSPFçµæãDKIMçµæãå«ãŸããŸãã
ãªããããã®æè¡ã®å ±æãå¿ èŠãªã®ã§ããïŒ
ç°¡åã«èšããšãSPFã䜿çšãããšãIPã¢ãã¬ã¹ã®ãã¯ã€ããªã¹ããäœæã§ããŸãã ãªã¹ãã«ãªãIPã¢ãã¬ã¹ãæã€ã¡ãŒã«ãµãŒããŒããã¡ã€ã³ã䜿çšããŠé»åã¡ãŒã«ãéä¿¡ããããšãããšãSPFèªèšŒãã¹ãã¯å€±æããŸãã ãã ããSPFã®å€§ããªåé¡ã¯ããŠãŒã¶ãŒãå®éã«èªã¿åãFromãã£ãŒã«ãã§ã¯ãªããReturn-Pathãã£ãŒã«ãã§æå®ããããã¡ã€ã³ãèªèšŒã«äœ¿çšããããšã§ãã
ããã«æªãããšã«ããã£ãã·ã³ã°æ»æè ã¯èªåã®ãã¡ã€ã³ã«SPFã¬ã³ãŒããèšå®ã§ããŸãã ãã®åŸãä¿¡é Œã§ããäŒç€ŸãŸãã¯ãã©ã³ãããéä¿¡ãããããã«èŠããã¡ãŒã«ãéä¿¡ã§ããŸããããã®äŒç€Ÿã®ãã¡ã€ã³ã¯[å·®åºäºº]ãã£ãŒã«ãã«è¡šç€ºãããäžæ£ã®ãã¡ã€ã³ã¯Return-Pathã«è¡šç€ºãããŸãã ãã®ãããªé»åã¡ãŒã«ã¯SPFã«ãã£ãŠèªèšŒãããŸãã DMARCãããã«äœ¿çšãããšããã¡ã€ã³ææè ãã調æŽããèŠæ±ã§ããããã«ãªãããã®åé¡ã解決ãããŸããã€ãŸããæ»ãã¢ãã¬ã¹ãšéä¿¡ã¢ãã¬ã¹ã¯åãã§ãªããã°ãªããŸããã
SPFã¬ã³ãŒãã¯ããã¹ãã§ãããæ§æã¯ããªãè€éã§ãã æ€åºãé£ããã¿ã€ããã¹ã¯ç°¡åã«äœæã§ããŸãã åæã«ãSPFã¬ã³ãŒãã圹ã«ç«ããªããªããŸãã 2017幎ã®RSAäŒè°ã®62ã®ã¹ãã³ãµãŒãã¹ãŠã®SPFã¬ã³ãŒããåæããçµæãå ¬éãããSPFã¯58ã®ã¿ã§ãããããµã€ããŒã»ãã¥ãªãã£ã«é¢ããäŒè°ã®17ã®ã¹ãã³ãµãŒã«ã¯èšé²ãšã©ãŒããããŸããã ITåéã®çµéšãããŸããªãäŒæ¥ã§ã¯ãSPFãããã«è€éã«ãªãããšããããããŸãã
ãŸããDKIMã¯ãDMARCã䜿çšããªãè©æ¬ºã«å¯ŸããŠç¹ã«å¹æçã§ã¯ãããŸããã ãã£ãã·ã³ã°ãåæ¢ããã«ã¯ãæãéèŠãªã¢ãã¬ã¹ã¯[å·®åºäºº]ãã£ãŒã«ãã®ãã¡ã€ã³ã§ãã ãã ããDKIM眲åã®ã¿ããã§ãã¯ããŠãããã®ãã£ãŒã«ãã®ãã¡ã€ã³ã«ã€ããŠã¯äœãèšãããŸããã ã¡ãã»ãŒãžã®çœ²åã«äœ¿çšããããã¡ã€ã³ã¯ã[å·®åºäºº]ãã£ãŒã«ãã§æå®ããããã¡ã€ã³ãšã¯å®å šã«ç°ãªãå ŽåããããŸãã ã€ãŸããããã«ãŒã¯å¶åŸ¡ãããã¡ã€ã³ã䜿çšããŠDKIMã§çœ²åãããã¡ãã»ãŒãžãäœæã§ããŸãããéè¡ã®ã¡ãŒã«ã¯[å·®åºäºº]ãã£ãŒã«ãã«è¡šç€ºãããŸãã ã»ãšãã©ã®äººã¯ãDKIM眲åããŒã¿ãæ£åœã§ããããšã確èªããããã«ããã¹ãŠã®çä¿¡ã¡ãã»ãŒãžã®ããããŒã詳ãã調ã¹ãããšã¯ãããŸããã ãŸããéä¿¡è ã«ä»£ãã£ãŠã¡ãŒã«ãéä¿¡ã§ããå€æ°ã®æ£åœãªã¡ãŒã«ãµãŒãã¹ãšãã¡ãã»ãŒãžã®çœ²åã«äœ¿çšãããç§å¯ããŒã®æ©å¯æ§ãç¶æããåé¡ãèæ ®ãã䟡å€ããããŸãã
ãããã®2ã€ã®åæã®æšæºã¯éèŠã§ãããéèŠãªã®ã£ãããå«ãŸããŠããŸãã DMARCã¯ãããã®äžã«æ§ç¯ãããããããè£å®ããŸãã DMARCã¯ãç¬èªã®ã¡ãŒã«ãµãŒããŒããã¡ãŒã«ãåä¿¡ããããã¡ãŒã«ã®éä¿¡ãèš±å¯ããã¯ã©ãŠããµãŒãã¹ã«ããããããéä¿¡ããã¡ãŒã«ã®ä¿¡é Œæ§ãå€§å¹ ã«åäžãããŸãã

DMARCã®äž»ãªè²¢ç®ã¯æ¬¡ã®ãšããã§ãã
- èªèšŒãããŠããªãé»åã¡ãŒã«ïŒäœããæ€ç«ãŸãã¯æåŠïŒã®åŠçãåä¿¡è ã®é»åã¡ãŒã«ãµãŒããŒã«æ瀺ããããªã·ãŒã®æ§æ
- ã¬ããŒãã¡ã«ããºã ãæäŸããŸãã
ããªã·ãŒãšãã£ãŒãããã¯ã®ã¡ã«ããºã ãæã€ããšãããã¹ãŠãæ©èœããããã®ã§ãã
ãµãŒãã¹ã䜿çšããŠDMARCãæ§æãããŠããããšã確èªã§ããŸã
â mxtoolbox.com
â mail-tester.comãªã©ã
ãã®èšäºã¯ããœãŒã¹ããã®ç¿»èš³ã«åºã¥ããŠããŸãïŒ
â 5å以å ã«ã»ãŒèª°ããã§ãã¡ãŒã«ãåœè£ ããæ¹æ³
â ã¡ãŒã«èªèšŒãšã¯ïŒ
â SPFãšã¯ïŒ
â DKIMãšã¯ïŒ
â DMARCãšã¯ïŒ
Habrahabrã®é¢é£èšäºïŒ
â ãã·ã¢ã®äž»èŠéè¡ããã®æçŽãåœé
â DKIM / SPF / DMARCã¬ã³ãŒããèšå®ãããããªãããŸãããé²åŸ¡ãã
â Sberbankã«ãã¡ã€ã³ã®èª€ã£ãSPFã¬ã³ãŒããããã®ã¯ãªãã§ããïŒ
â äŒæ¥ãã¡ã€ã³ããªãããŸãããä¿è·ããããã®DMARCã®å°å ¥