ã¿ãªããããã«ã¡ã¯ã ä»æ¥ã¯ãPOSïŒä»¥äžPOSïŒã·ã¹ãã ããã®ã¢ãŒããã¯ãã£ãããã³ã»ãã¥ãªãã£ã«ã€ããŠã話ããããšæããŸãã ããããããåºã®é·ãåããã®äŒæ¥åŸã®ã·ã§ãã¯ã¯éãå»ããŸããããããŠããœãŒã·ã£ã«ã³ãã¥ãã±ãŒã·ã§ã³ã®ãã®ããŒã«ã®èåŸã«ãããã®ãèŠãæãæ¥ãŸããã 以äžã§èª¬æãã調æ»ã¯ã @ chipikãšç§ã«ãã£ãŠè¡ãããŸããã
ææ°ã®POSã·ã¹ãã ã¯ãæ¯æããã©ã³ã¶ã¯ã·ã§ã³ãå®è¡ããæ¯æ¥ã®ããžãã¹ããã»ã¹ã容æã«ãããœãããŠã§ã¢ãšãââãŒããŠã§ã¢ã®ãœãªã¥ãŒã·ã§ã³ã®çµã¿åããã§ãã POSã«ã€ããŠèšãã°ãéåžžã¯ã¬ãžãæ¯æã端æ«ãããã³å°å£²åºã®ä»ã®ããç¥ãããŠããã³ã³ããŒãã³ããæå³ããŸãã ãã ããPOSã¢ãŒããã¯ãã£ã¯ãããã®èŠçŽ ã«éå®ãããŸããã ã»ãã¥ãªãã£ã«é¢ããŠã¯ãããã¯æ°ãããããã¯ã§ã¯ãªãããã§ãã2012幎以éãBlackHat USAã®ã»ãŒãã¹ãŠã®äŒè°ã§æ¯æãã·ã¹ãã ã«é¢ããã¬ããŒãããããŸããïŒ here ã here ã here ã here ïŒã ãããããããã®ã¬ããŒãã¯ãã¹ãŠãè°è«äžã®ãããã¯ã«éåžžã«è¿ããã®ã§ããããããŸã äœãå¥ã®ããšãæ±ã£ãŠããŸãã
ããããããããããã«ãéåžžã®åºèã§ã®æ¯æãæé ãèŠãŠã¿ãŸãããã
ãŸããè²·ãæã¯ç«¯æ«ã®ãªãŒããŒã«ã«ãŒããæž¡ããè³Œå ¥ä»£éãæ¯æããŸãã ã¯ã¬ãžããã«ãŒãæ å ±ã¯ç«¯æ«ã«éä¿¡ãããããããPOSã·ã¹ãã ã«éä¿¡ãããŸãã ããã«ãPOSã·ã¹ãã ã¯PSPïŒPayment Service ProviderïŒã«é£çµ¡ããŸããPSPã¯ãã¯ã¬ãžããã«ãŒãã®çš®é¡ã«å¿ããŠãéè¡ã«é£çµ¡ããŠååŒæ¿èªæç¶ããå®äºããŸãã ãã®æç¹ã§ããã€ã€ãŒã¯PINã³ãŒããå ¥åããŠååŒã確èªããããã«æ±ããããŸãã ãã¹ãŠãããŸããã£ãå ŽåãèªèšŒã³ãŒããéè¡ãããã¯ãŒã¯ããPSPã«è¿ãããPOSã·ã¹ãã ãšç«¯æ«ã«è»¢éãããŸãã äžèšã®éä¿¡ã¯ãã¹ãŠæ°ç§ä»¥å ã«è¡ãããŸãã
æåã«èšåããã調æ»ãšæ»æã¯ãäž»ã«æ¯æ端æ«ãšè²·ãæãšã®çžäºäœçšãç®çãšããŠããŸãã ä»æ¥ãå¥ã®éšåãèæ ®ãããŸã-ãã©ã³ã¶ã¯ã·ã§ã³ããŒã¿ãééããPOSã·ã¹ãã ã
ããŸããŸãªããžãã¹ããã»ã¹ã«ã€ããŠäœåºŠã話ããŠããŸãããããã¯äœã§ããïŒ ããšãã°ãå€å žçãªãã§ãŒã³åºãèããŠã¿ãŸãããã åºå ã«ã¯ãããŒãžã£ãŒãããŸãããã»ãšãã©ã®å ŽåãããŒãžã£ãŒãããŸãã æ¯æããããŒãžã£ãŒã¯åºãéãã次ã«POS端æ«ãéãå¿ èŠããããŸãã POS端æ«ã¯æ¯æã端æ«ãšã¯ç°ãªãããšã«æ³šæããŠãã ããã æåã®ç»åã¯æ¯æã端æ«ã§ã2çªç®ã®ç»åã¯POS端æ«ã§ãã
èµ·åäžã«ãPOS端æ«ã¯æéãåæããååã®äŸ¡æ Œãåšåº«ç¶æ³ããã®ä»ã®ãµãŒãã¹ããŒã¿ãªã©ã®æŽæ°ããããã©ã¡ãŒã¿ãŒãã¹ãã¢ã®ãµãŒããŒããåä¿¡ããŸãã ãã®åŸãã¬ãžä¿ã¯èªåã®ä»äºã«ãã°ã€ã³ããŠä»äºãå§ããããšãã§ããŸãã æããã«ããã§ãã¯ã¢ãŠãæã®ãã¹ãŠã®ã¢ã¯ã·ã§ã³ããã°ã«èšé²ãããŸãã
äžæ¥ã®çµããã«ããããŒãžã£ãŒã¯éã®é åºã§æé ãç¹°ãè¿ãå¿ èŠããããŸããæåã«ãã±ãã売ãå Žãéãã次ã«åºãéããŸãã ãã®ã¢ã¯ã·ã§ã³ã®åŸãã¹ãã¢ãéããŸã§ãã©ã³ã¶ã¯ã·ã§ã³ãäœæã§ããŸããã çµäºæã«ãPOS端æ«ã¯ãã°ããµãŒããŒã«éä¿¡ããŸãã ãããã¯äžèšã®ããžãã¹ããã»ã¹ã§ãã ç°¡çŽ åããã³ä¿é²ããã®ã¯ãPOSã·ã¹ãã ã§ãã
POSã·ã¹ãã åžå Žã«ã¯éåžžã«å€ãã®ãœãªã¥ãŒã·ã§ã³ããããå°èŠæš¡ãäžèŠæš¡ã倧èŠæš¡ã®çµç¹åãã«è£œåã°ã«ãŒãã«åããããŠããŸãã
ã»ãšãã©ã®å Žåããããã®ã¢ãŒããã¯ãã£ã¯é¡äŒŒããŠããŸãã ãã®èšäºã§ã¯ãSAPãœãªã¥ãŒã·ã§ã³ãSAP Point of Saleãã詳ããèŠãŠãããŸãã ãŸããOracleã®MICROS補åã«ã€ããŠã調æ»ããŸããããã®è£œåã§ã¯ã2018幎1æïŒCVE-2018-2636ïŒã«ã¯ããŒãºãããåæ§ã®è匱æ§ãèŠã€ãããŸããã
SAPã®è©³çŽ°ã«ã€ããŠã¯ã å ¬åŒWebãµã€ããã芧ãã ãã ã ç°¡åã«èšããšãSAPã¯å€§äŒæ¥åãã®å€§èŠæš¡ãªERPãœãªã¥ãŒã·ã§ã³ãéçºããŠããŸãã 補åãšããŠã®POSã·ã¹ãã ã¯2005幎ã«SAPã«ç»å ŽããPOSãœãªã¥ãŒã·ã§ã³ã®ã¿ãæ±ãTriversity Transactionware GMãè²·åããŸããã
SAP POSã¢ãŒããã¯ãã£
ãã®ã·ã¹ãã ã®ã¢ãŒããã¯ãã£ã¯ãããã³ããªãã£ã¹ãããã¯ãªãã£ã¹ãããã³æ¬ç€Ÿã®3ã€ã®éšåã§æ§æãããŠããŸãã æåã®éšåã«ã¯ãã¯ã©ã€ã¢ã³ãéšåãã€ãŸã POSã¯ã©ã€ã¢ã³ãããã³ã¢ãã€ã«POSã¯ã©ã€ã¢ã³ãããã£ãã·ã£ãŒãåãPOS端æ«ã§ãã ããã³ããªãã£ã¹ã¯ãããŒã«ã«ã¹ãã¢ãµãŒããŒïŒXpressãµãŒããŒïŒãããŒã¿ããŒã¹ïŒããŒã¿ããŒã¹ïŒãããã³POSã·ã¹ãã ã®ããŒã«ã«ç®¡çãœãªã¥ãŒã·ã§ã³ïŒã¹ãã¢ãããŒãžã£ãŒïŒãé 眮ãããŠããããã¯ãªãã£ã¹ã«æ¥ç¶ãããŠããŸãããããã䜿çšããŠããããŒãžã£ãŒãã¹ãã¢ãšç«¯æ«ãééããŸãã
ããŒã«ã«ãœãªã¥ãŒã·ã§ã³ã«ã€ããŠèšãã°ãç¹å®ã®åºèãæå³ããŸããSAPPOSã¯å€§èŠæš¡ãªçµç¹åãã®è£œåã§ãããäžå 管çãããåºèãã§ãŒã³åãã«ã¢ãŒããã¯ãã£çã«èæ¡ãããããã§ãã ã€ãŸãããã®å ŽåãããŒã«ã«ãœãªã¥ãŒã·ã§ã³ã¯ãããã¯ãŒã¯å ã®åºèã®1ã€ã®POSã·ã¹ãã ã§ãã
åºèãããã¯ãŒã¯ã®ã°ããŒãã«ç®¡çã¯ããã¹ãŠã®åºèãµãŒããŒã«æ¥ç¶ãããŠããStore Configuratorã䜿çšããŠãæ¬ç€Ÿããå®è¡ãããŸãã
äžè¬çãªã¬ãã¥ãŒã¯å®äºããŸããã次ã«ããã¹ãŠãã©ã®ããã«æ©èœãããã詳ããèŠãŠã¿ãŸãããã ãããŠã次ã®é åºã§ç§»åããŸãã
æ¬ç€Ÿ
Store Configuratorã¯ãPOSã·ã¹ãã ã®ãã¹ãŠãå®å šã«èšå®ã§ããã¢ããªã±ãŒã·ã§ã³ã§ãã ãããã絶察ã«ãã¹ãŠã§ã¯ãããŸããããŠãŒã¶ãŒãšã¬ãžã®ç»é¢ã®å€èŠ³ããå§ãŸããæå·åããã®ä»ã®ã»ãã¥ãªãã£èšå®ã§çµãããŸãã
ããã¯ã©ã®ããã«å®è£ ãããŠããŸããïŒ Store Configuratorã«å€æŽãå ããåŸã管çè ã¯ãå€æããã¯ãªãã¯ããå¿ èŠãããããããã®ãã©ã¡ãŒã¿ãŒãæã€ç¹å¥ãªãã¡ã€ã«ããStore Configurator / data / parm /ããã©ã«ããŒå ã®ãã¡ã€ã«ã·ã¹ãã ã«äœæãããŸãã
ãã©ã¡ãŒã¿ãŒã ãã§ãªãå€ãã®ãã¡ã€ã«ãããããããã®æ¡åŒµåãç°ãªããŸãã 以äžã«äŸã瀺ããŸãã
- cnummask.cmk-顧客ã®ã«ãŒãçªå·ã®ããã¹ã¯ãã«é¢ããæ å ±ãã€ãŸã å°åæã«äœåãäœåã®æ°åãå ¥ããã«ã€ããŠã
- rcptlogo.rcp-ããã¯äŒç€Ÿã®ããŽã«é¢ããããŒã¿ã§ãå°åæã«å°å·ãããŠããŸãã
- cashier.clg-å人ããŒã¿ïŒååãç幎ææ¥ãé»è©±çªå·ïŒããã³èªèšŒããŒã¿ïŒãã°ã€ã³ããã¹ã¯ãŒãããã·ã¥ïŒãªã©ãPOSã·ã¹ãã ã®ãŠãŒã¶ãŒïŒãã£ãã·ã£ãŒããããŒãžã£ãŒãªã©ïŒã«é¢ããæ å ±ãå«ãŸããŠããŸãã
- layout.ui0-POS端æ«ã®å€èŠ³ãããŒã®äœçœ®ãèæ¯ç»åãªã©ã«é¢ããæ å ±ãå«ãŸããŠããŸãã
ãã¡ã€ã«ã®å 容ã¯ãStore Configuratorã§æå®ããããã©ã¡ãŒã¿ãŒã®ããã¹ãè¡šçŸã§ãã 以äžã®ç»åã¯ãrcptlogo.rcpãã¡ã€ã«ã§ãã
次ã«ã管çè ã¯ãããã®ãã¡ã€ã«ãåã¹ãã¢ãµãŒããŒã®ã/ Xpress Server / parm /ããã©ã«ããŒã«ã³ããŒããå¿ èŠããããŸãã Store Configuratorã«ãã£ãŠäœæããããã¡ã€ã«ã«ã¯ããç¹å¥ãªããã¡ã€ã«ã1ã€ãããŸãã ãnewparm.trgããšåŒã°ããèšå·ãZãã®ã¿ãå«ãŸããŠããŸãã XpressãµãŒããŒïŒã¹ãã¢ãµãŒããŒïŒã30ç§ããšã«ãã©ã«ããŒã/ parm /ãã§ãã®ãã¡ã€ã«ã®ååšã確èªããŸãã èŠã€ãã£ãå ŽåãããŠã³ããŒããããã¡ã€ã«ããæŽæ°ããããã©ã¡ãŒã¿ãŒãé©çšãããnewparm.trgããåé€ããŸãã ãããã£ãŠããã®ãã¡ã€ã«ã¯äžçš®ã®æŽæ°ããªã¬ãŒãšããŠæ©èœããŸãã
ããã¯ãªãã£ã¹
次ã®è¡ã¯ããã¯ãªãã£ã¹ããŸãã¯ãããããã®äžã§ã®ã³ãã¥ãã±ãŒã·ã§ã³ã§ãã åè¿°ã®ããã«ãXpressãµãŒããŒãããŒã¿ããŒã¹ãããã³ã¹ãã¢ãããŒãžã£ãŒã§æ§æãããŠããŸãã ãããã®ã³ã³ããŒãã³ãã¯ãã¹ãŠã1å°ã®ãã·ã³ãŸãã¯å¥ã®ãã·ã³ã«ã€ã³ã¹ããŒã«ã§ããŸãã Store Managerã¯ãæšæºããŒãã䜿çšããŠããŒã¿ããŒã¹ãšå¯Ÿè©±ããŸãããã®å Žåãæ©èœãå¶éãããŠããStore Configuratorãšéåžžã«ãã䌌ãŠãããå¯äžã®éãã¯ãã¹ãã¢ãããã·ãŒãžã£ã䜿çšããŠãã©ã¡ãŒã¿å€æŽãããŒã¿ããŒã¹ã«çŽæ¥æžã蟌ãããšã§ãã
ã·ã¹ãã 調æ»ã®äžç°ãšããŠãssp_insert_backdoorãšssp_delete_backdoorã®2ã€ã®æ¥œããæé ãèŠã€ãããŸããã 圌ãã®äž»ãªç®æšã¯ããbackããšããååãšãdoorããšãããã¹ã¯ãŒããšææ Œãããç¹æš©ãæã€ãŠãŒã¶ãŒãäœæããããšã§ãã ãã¡ãããããã¯POSã·ã¹ãã ã®ãã¹ãŠã®ãŠãŒã¶ãŒãèªèšŒããŒã¿ãå¿ããå Žåã«ã®ã¿è¡ãããŸãã
Store ManagerãšXpress Serveréã®çžäºäœçšã¯ããŒã2202ã§å®è¡ãããããèå³æ·±ãããã«èŠããŸãã ã¹ãã¢ãããŒãžã£ãŒã®æ©èœã調ã¹ããšãããèå³æ·±ãæ©èœãæäŸããã¹ãã¢ç®¡çã»ã¯ã·ã§ã³ãèŠã€ãããŸããã
- ãŸããæ¥ç¶ãããŠãããã¹ãŠã®POS端æ«ã衚瀺ãããŸãã
- 第äºã«ããããã¯ééã§ããŸãã
- 第äžã«ããã£ãã·ã£ãŒã®ç»é¢ã«è¡šç€ºããããã¹ãŠïŒè³Œå ¥ãšå°åæã«é¢ããæ å ±ïŒã远跡ã§ããç£èŠæ©èœããããŸãã
Store ManagerãXpressãµãŒããŒã®ããŒã2202ïŒWireSharkãªãïŒã«éä¿¡ããããã±ãŒãžã確èªããåŸããã¬ãŒã³ããã¹ãã³ãã³ããèŠãŸããã ãããã¯telnetãããã³ã«ã§ãããããŒãã¯éèŠãªæ§æã§ã¯ãªãç£èŠã«äœ¿çšãããŸãã-ããã¥ã¡ã³ãããåŠã³ãŸããã ããŠãå€éšãã·ã³ãããã®ããŒãã«æ¥ç¶ããããšãããšã©ããªããŸããïŒ
çµå±ã®ãšããããã¯ã€ããªã¹ãã¯æäŸãããŠããŸããã ããã©ã«ãã§ã¯ããã®ããŒãã¯éããŠãããã»ãã¥ãªãã£ã¬ã€ãã«ããŒããéããããšã«é¢ããæšå¥šäºé ã¯ãããŸããã åœç¶ããµãŒãããŒãã£ã®ããŒã«ã§ããŒããžã®ã¢ã¯ã»ã¹ãå¶éããããšãã§ããŸãããPOSã·ã¹ãã ã®ã»ãã¥ãªãã£ã«æ³šç®ããŠããŸãããïŒ
ããŒã2202ã§XpressãµãŒããŒã«æ¥ç¶ããåŸãPOSã·ã¹ãã ã®ããŒãžã§ã³ã«é¢ãããŠã§ã«ã«ã ã¡ãã»ãŒãžã衚瀺ãããŸãã helpã³ãã³ãã¯ã䜿çšå¯èœãªæ©èœã®ãªã¹ããè¿ããŸãã
999 *** XPRESS SERVER MOST COMMON COMMAND HELP *** 999 MONXPS [ON|OFF] 999 [SHOWTERM|TERMINAL-STATUS] [ALL|Term#] 999 [MONTERM|MONITOR-TERMINAL] [ALL|XPS|Term#] [START|STOP|ON|OFF] 999 OPEN-TERMINAL [ALL|Term#] 999 OPEN-STORE [TODAY|NumberOfSecsSinceJan1-1970] 999 CLOSE-TERMINAL [ALL|Term#] [FORCE|NO-FORCE|ABORT] 999 TERMINAL-BALANCE [Term#] [BAL|UNBAL] 999 CASHIER-BALANCE [Cashier#] [1|2|3] [ShortOver Amount] [netTenderTotal] <-- 1=BALANCED 2=UNBALANCED 3=PREVIOUS BALANCE NOW OUT OF DATE 999 UPDATE-CASHIER [Cashier#] 999 DELETE-CASHIER [Cashier#] 999 END-OF-DAY [FORCE|NO-FORCE|ABORT] 999 STORE-TOTALS [CLOSE-DAY|CLOSE-WEEK|CLOSE-PERIOD|DONE-END-OF-DAY|...] 999 STORE-TOTALS CONSOL-DAY [RTOT|SRTOT|CTOT|SPROD|...] 999 COMMS-RESET [1|2|3] <-- 1=ALL 2=REMOTE 3=MODEMS 999 FLUSH-PLUCACHE 999 TRIGGER-NEWPROMOS 999 SHUTDOWN 999 . <-- Use to repeat previous command
ãããã®é¢æ°ã®ååããããããã®ç®çã¯éåžžã«æ確ã§ãã ãã§ãã¯ããªããããPOSã¿ãŒããã«ãå¿åã§éãããéããããçºçãããã¹ãŠãç£èŠãããïŒããšãã°ãè³Œå ¥æã«ãã§ãã¯ã®å 容ãã³ã³ãœãŒã«ã«è¡šç€ºããããïŒãXpress Serverããªãã«ãããã§ããŸãã
ãããã®é¢æ°ãã³ãŒãã«ã©ã®ããã«å®è£ ãããŠããããããã³ãã¹ãŠã®ã³ãã³ããããã«ããåºåã«è¡šç€ºããããã©ããã¯éåžžã«èå³æ·±ããã®ã«ãªããŸããã çä¿¡èŠæ±ãåŠçããããã»ã¹ã¯xps.exeã§ãã å°ãéã«ãå¯èœãªããŒã ã®ãªã¹ããèŠã€ãããŸããã 74åã®ã³ãã³ãããããŸãã74åã®ã³ãã³ããããŒã2202ããXpress Serverã«ãã£ãŠåä¿¡ããã³åŠçãããŸãããã¹ãŠã説æããã«ã¯é·ãããã®ã§ãæãèå³æ·±ããã®ã«ã€ããŠèª¬æããŸãããã
APM-VALIDATE-PASSWD-ãŠãŒã¶ãŒãå ¥åããèªèšŒããŒã¿ã確èªã§ããŸãã ãã®ã³ãã³ãã¯3ã€ã®ç°ãªãã³ãŒããè¿ããŸãã0-ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããæ£ããå ¥åãããå Žåã1-ãã¹ã¯ãŒããæ£ãããªãå Žåã10-ãã®ãã°ã€ã³ãæã€ãŠãŒã¶ãŒãååšããªãå Žåã æããã«ãæœåšçãªäŸµå ¥è ãé²ããã¹ãã¢ã®ããŒã«ã«ãããã¯ãŒã¯ã«ããŠããã°ã€ã³ãšãã¹ã¯ãŒãã®å¯èœãªãã¹ãŠã®çµã¿åãããåé¡ãïŒãã°ã€ã³ã¯æ°åã®ã¿ã§æ§æã§ããŸãïŒãPOS端æ«ã«ã¢ã¯ã»ã¹ããããã®ããŒã¿ãåä¿¡ããŸãã
ãããããã«ãŒããã©ãŒã¹ã¯ããŸãã¯ãŒã«ã§ã¯ãªãããããŠãŒã¶ãŒãã¹ã¯ãŒããæ°ãããã¹ã¯ãŒãã«å€æŽããå¥ã®ã³ãã³ãReset passwordããããŸãã ç¥ã£ãŠããå¿ èŠãããã®ã¯ããã°ã€ã³ã§ããããã¯ãã«ãŒããã©ãŒã¹ã«ãã£ãŠååŸã§ããŸãã ãããŠããäžã€ã®å°ããªèª¬æã ãã®POSã·ã¹ãã ã§ã¯ããã°ã€ã³ã¯æ°åã®ã¿ã§æ§æã§ãããããä»®æ³æ€çŽ¢ãéåžžã«å®¹æã«ãªããŸãã
FILE-FIND ã FILE-OPENãããã³FILE-READã³ãã³ãã䜿çšãããšãXpress Serverãã¡ã€ã«ã·ã¹ãã äžã®ããŒã¿ãæ€çŽ¢ãéããèªã¿åãããšãã§ããŸãã ããªãã¯ãŸã ããããã¹ãŠãå¿åã§ç»é²ãšSMSãªãã§èµ·ããããšãèŠããŠããŸããïŒ å¥åŠãªããšã«ãFILE-OPENã³ãã³ãã®ãã©ã¡ãŒã¿ãŒã¯C ++é¢æ°fopenïŒïŒã«çŽæ¥æž¡ãããã¢ãŒããæ£ããæå®ãããŠããªãå ŽåãXpressãµãŒããŒã¢ããªã±ãŒã·ã§ã³ã¯ãšã©ãŒãåä¿¡ããŠââçµäºããŸãã
ã¬ãã¥ãŒã®æåŸã®éšåã«ç§»ããŸãããã
ããã³ããªãã£ã¹
POSã¿ãŒããã«ãšãåŒã°ããPOSã¯ã©ã€ã¢ã³ãã¯ãããŒã2200ã§ãµãŒããŒã«æ¥ç¶ããŸãããã¹ãŠã®æ å ±ããã¹ãŠã®ãã©ã³ã¶ã¯ã·ã§ã³ãããã³äžè¬ã«ãã¹ãŠã®éä¿¡ã¯ããã®ããŒãã§ããã®æ¹åã§ã®ã¿è¡ãããŸãã ããžãã¹ããã»ã¹ãæãåºããšããã¹ãŠã¯æ¬¡ã®ããã«çºçããŸãã 1æ¥ã®åãã«ããããŒãžã£ãŒãPOSã¿ãŒããã«ãéããšããµãŒããŒã«ãã±ãããéä¿¡ããŸããããµãŒããŒã端æ«çªå·5ãéããŠããŸããæ°ãããã©ã¡ãŒã¿ãŒãéä¿¡ããŠãæ¥ä»ãšæå»ãåæããŸããããã äžæ¥ã®çµããã«ããããŒãžã£ãŒãPOSã¿ãŒããã«ãéãããšããããŒãžã£ãŒã«ãã°ããµãŒããŒã«éä¿¡ãããŸãã ãã¡ãããåãã©ã³ã¶ã¯ã·ã§ã³ã®åŸãããã«é¢ããããŒã¿ãšååã®æ°éã®å€åã«é¢ããããŒã¿ããµãŒããŒã«éä¿¡ãããŸãã POS端æ«ãšXpress Serverã®éã®ãã©ãã£ãã¯ã調ã¹ããšããããã¡ã€ã«ãåä¿¡ããã³ããŠã³ããŒãããããã®ããã±ãŒãžã«ã¯ç¹å®ã®æ§é ãããããšãããããŸããã
Len-éä¿¡ãããã±ããã®é·ãã ã©ã-ããŒã¿ãæžã蟌ãå Žæã ããŒã¿ãååŸããå Žæã¯ã©ãã§ããã çµäº-NULLãã€ãã®ãã¢ã ã¿ã€ã-ããã±ãŒãžã§å®è¡ãããã¢ã¯ã·ã§ã³ã«å¿ããŠãããã±ãŒãžã®ã¿ã€ãã ããã±ãŒãžã«ã¯æ¬¡ã®ãã®ããããŸãã
ãããã£ãŠãããšãã°ããµãŒããŒããèšå®ãã¡ã€ã«ãååŸããããã«ãPOSã¯ã©ã€ã¢ã³ãã¯ã¿ã€ãRã®ãã±ãããããŒã2200ã«éä¿¡ããŸãã
{R0059}C:\\local_directory\poc.txt,C:\remote_directory\poc.txt,0,0;
ãã®ããã±ãŒãžã«å«ãŸãããã®ïŒ
- Rã¯ã¿ã€ãã§ãã
- 0059-ããŒã¿é·;
- CïŒ\ local_directory \ poc.txt-ãã¡ã€ã«ã®æžã蟌ã¿å ã
- CïŒ\ remote_directory \ poc.txt-ãµãŒããŒäžã®ãã¡ã€ã«ä¿åå Žæã
- 0,0ã¯ãã±ããã®çµããã§ãã
å¿çã§ã¯ãPOSã¯ã©ã€ã¢ã³ãã¯èŠæ±ããããã¡ã€ã«ã®ã³ã³ãã³ããåä¿¡ãããããç¹å¥ãªãã£ã¬ã¯ããªå ã®èªåèªèº«ã«æžã蟌ã¿ãŸãã å¥ã®ãã·ã³ããPOSã¯ã©ã€ã¢ã³ãã«ãã£ãŠéä¿¡ããããã±ãããè€è£œããããšãããšãå¿çã¯ãµãŒããŒäžã®ãã¡ã€ã«ã®å 容ãåä¿¡ããŸããã ã芧ã®ãšãããããã«ããã§ãã¯ã¯ãããŸãããXpressãµãŒããŒã®ããŒã2200ã¯ãä»»æã®ãã·ã³ããã®ãã±ãããåãå ¥ããŠåŠçããŸãã
é¢çœããã«èŠããŸãããããã¡ã€ã«ãèªãã§ãããã»ã©é ãã¯ãããŸããã ãã¡ã€ã«ããµãŒããŒã«ã¢ããããŒãããããã«äžé£ã®ããã±ãŒãžãåéããŠã¿ãŸãããã çµå±ã®ãšãããPOSã¯ã©ã€ã¢ã³ãã¯äœããã®åœ¢ã§ãµãŒããŒã«ãã°ãæžã蟌ãã®ã§ããïŒ
æåã«ãã¿ã€ãSã®ãã±ãããéä¿¡ããŸããWhereãã£ãŒã«ãã«ã¯ãããŒã¿ãæžã蟌ããµãŒããŒäžã®ãã¹ãå«ãŸããŸããWhatãã£ãŒã«ãã¯ãªãã·ã§ã³ã§ãããã¹ãŠãæåã§è¡ãããã§ãããã ããSizeãµã€ãºã¯éåžžã«éèŠã§ã次ã®2çªç®ã®ãã±ããã®ãµã€ãºã瀺ããŸãã ã¿ã€ãã¯F-FILE_DATAã§ããµã€ãºãšãµãŒããŒã«æžã蟌ãããŒã¿ïŒã³ã³ãã³ãïŒã§æ§æãããŸãã ããŠã3çªç®ã®æåŸã®ã¿ã€ãCããã±ãŒãžã¯ãã¡ã€ã«ã®çµããã§ãã ãã®åŸãXpress Serverã¯æå®ããããã£ã¬ã¯ããªã«ãã¡ã€ã«ãæžã蟌ã¿ãã¿ã€ãG-GOODã®ããã±ãŒãžãè¿ããŸãã å¥åŠãªããšã«ãééã£ããµã€ãºãã£ãŒã«ãã§ãã±ãããéä¿¡ãããšãXpress Serverã¯ãµãŒããŒäžã®ãã¡ã€ã«ãåé€ããŸãã 以äžã«ããã¡ã€ã«ã®å¿åæžã蟌ã¿ãèªã¿åããåé€ã®ãããªPOCã瀺ããŸãã
ãããã£ãŠããã§ãã¯ããªãããããã®ããŒãã«æ¥ç¶ã§ãããŠãŒã¶ãŒã¯èª°ã§ããµãŒããŒäžã®ãã¡ã€ã«ã®èªã¿åããæžã蟌ã¿ãåé€ãã§ããŸãã
ãããŠãããã¯äœãåŸãããšãã§ããŸããïŒ äžèšã®æ©èœãçµã¿åãããããšã§äœãéæã§ããããèŠãŠã¿ãŸãããã
ãã®ãããæ»æè ã¯ã¹ãã¢ã®ããŒã«ã«ãããã¯ãŒã¯ã«ã¢ã¯ã»ã¹ããå¿ èŠããããŸãã éåžžããããååŸããããšã¯é£ãããããŸããã äœéèšãå«ãåšèŸºæ©åšã¯å®æçã«ããŒã«ã«é 眮ãããŠãããããããžã®ã¢ã¯ã»ã¹ã¯ç¡å¶éã§ãã
ã·ã¹ãã ã®ç¥èãèŠçŽããŸãããã
- Store Configuratorã¯ãã·ã¹ãã ãã©ã¡ãŒã¿ãŒã䜿çšããŠç¹æ®ãã¡ã€ã«ãäœæããXpressãµãŒããŒã«ã³ããŒããŸããXpressãµãŒããŒã¯ããã¡ã€ã«ãnewparm.trgããæ€åºãããšãã©ã¡ãŒã¿ãŒãé©çšããŸãã
- æ»æè ã¯ãããŒã2200ã䜿çšããŠãXpressãµãŒããŒäžã®ä»»æã®ãã£ã¬ã¯ããªã®ä»»æã®ãã¡ã€ã«ã«ä»»æã®ããŒã¿ãæžã蟌ãããšãã§ããŸãã
- POS端æ«ã¯Xpress ServerããæŽæ°ãããèšå®ãåãåããéããåŸã«ããããé©çšããŸãã
- æ»æè ã¯ãããŒã2202ã䜿çšããŠãPOSã¯ã©ã€ã¢ã³ããå¿åã§ãªãããã³ãªã³ã«ããããšãã§ããŸãã
ãããã®æ©èœã®çµã¿åããã«ãããSAP POSã·ã¹ãã ã®ãã©ã¡ãŒã¿ãŒãå€æŽã§ããŸãã
ããšãã°ãæ»æè
ã1ãã«ã§ååãè²·ããããšããŸãã
- æ»æè ã¯æ§æãã¡ã€ã«ãXpressãµãŒããŒã®parmãã©ã«ããŒã«æžã蟌ã¿ã補åã®æ°ããäŸ¡æ Œã瀺ããŸãã
- æ»æè ã¯ããªã¬ãŒãã¡ã€ã«ãnewparm.trgããXpressãµãŒããŒã®parmãã©ã«ããŒã«æžã蟌ã¿ããµãŒããŒã®èšå®ã®æŽæ°ãã¢ã¯ãã£ãã«ããŸãã
- ãµãŒããŒã¯èšå®ãæŽæ°ããŠããŸãã
- 圌ã¯ãããã®ããã€ããããŒã¿ããŒã¹ã«æžã蟌ã¿ãŸãã
- æ»æè ã¯ã¿ãŒããã«ã¯ããŒãºã³ãã³ããéä¿¡ããŸãã
- XpressãµãŒããŒã¯ç«¯æ«ãéãã端æ«ã¯ãµãŒããŒã«ãã°ãéä¿¡ããŸãã ãã®ããã»ã¹ã«ã¯10ã30ç§ããããŸãã
- æ»æè ã¯ãéããŠãã端æ«ã«ã³ãã³ããéä¿¡ããŸãã
- ã¿ãŒããã«ãéããŸãã
- 端æ«ã¯ããµãŒããŒããæ°ãããã©ã¡ãŒã¿ãŒãããŠã³ããŒãããŠé©çšããŸãã
å®éãããããã¹ãŠã§ãã ãããããŸã äœããæ¬ ããŠããŸããã€ãŸãããµãŒããŒäžã§ã³ãã³ãããªã¢ãŒãã§å®è¡ããæ©èœã§ãã ãããã圌女ã¯äžè¬ã«ããã§ãã
XpressãµãŒããŒãèšå®ãæŽæ°ãããã³ã«ãã€ãŸã ããªã¬ãŒãã¡ã€ã«ãnewparm.trgããèŠã€ãããšããXPSPARM.BATããšãStopTN.BATãã®2ã€ã®ã.batããã¡ã€ã«ãæ€çŽ¢ããŠèµ·åããŸãã ãããŠããã¯ãæ»æè ãããããäžæžãããèªåèªèº«ã§éã·ã§ã«ããã¹ã¯ãªãããå®è¡ã§ããããšãæå³ããŸãã
æ»æè ã¯ããŒã2200ã䜿çšããŠããã¡ã€ã«ãXPSPARM.BATããèªåã®ãã®ã«çœ®ãæããŸãã ãã¡ã€ã«ãnewparm.trgããæžã蟌ã¿ãŸããããã«ããããã©ã¡ãŒã¿ãŒã®æŽæ°ãšã* .batããã¡ã€ã«ã®èµ·åãè¡ãããŸãã
æå·å
ã¯ããæå·åã¯SAP POSã§äœ¿çšãããŸãããããã©ã«ãã§ã¯ããã©ã«ãã§ç¡å¹ã«ãªã£ãŠããŸãã æå·åãèšå®ãããŠããå ŽåãéèŠãªããŒã¿ã¯ãã¹ãŠæå·æãšããŠéä¿¡ãããŸãã æå·åãããã®ã¯ããŒã¿ã§ãããã·ã¹ãã ã®èŠçŽ éã®éä¿¡ã§ã¯ãªãããšãæ確ã«ããå¿ èŠããããŸãã ããšãã°ãæå·åãæå¹ã«ãªã£ãŠãã端æ«ã§ãã©ã³ã¶ã¯ã·ã§ã³ãç£èŠãããšãã¯ã¬ãžããã«ãŒãçªå·ã®ä»£ããã«æå·æã®ã¿ãå¿çã§åä¿¡ãããæ®ãã®ããŒã¿ã¯ã¯ãªã¢ããã¹ãã§éä¿¡ãããŸãã
ãã®è¡šã¯ãæå·åæé ã«åæ Œããå¿ èŠãããããŒãã«åãšãã£ãŒã«ãã瀺ããŠããŸãã åæã«ãè¿œå ã®ããŒãã«ãCryptoRegisterãããããŸãããããã«ã¯åããã®ããªã¹ããããŠããŸãããæå·åã®ãã¬ãã«ãã瀺ãããŠããŸãã ããšãã°ããŠãŒã¶ãŒãã¹ã¯ãŒãã¯ããã·ã¥å€ãšããŠä¿åãããæå·åã¬ãã«ã¯4ã§ãã¯ã¬ãžããã«ãŒãçªå·ã¯3DESã§æå·åãããã¬ãã«ã¯3ã§ãã
SAP POSã¯ãTWSecurityããŒã«ã䜿çšããŠããŒãä¿åããã³çæããŸãã èµ·åãããšãç¹å¥ãªãã³ã³ããããäœæãããæå·åããŒãä¿åãããã¹ã¯ãŒãã®ã¿ã§ã¢ã¯ã»ã¹ã§ããŸãã 3DESã¯å¯Ÿç§°ã¢ã«ãŽãªãºã ã§ãããããããŒã¯ã·ã¹ãã ã®ãã¹ãŠã®èŠçŽ ïŒããã³ããªãã£ã¹ãããã¯ãªãã£ã¹ãããã³æ¬ç€ŸïŒã§åãã§ãªããã°ãªããŸããã ããªãã¡ ã³ã³ãããäœæããããPOSã·ã¹ãã ã®ãã¹ãŠã®éšåã«ãšã¯ã¹ããŒãããå¿ èŠããããŸãã ããŒãžã®ã¢ã¯ã»ã¹ã¯ãã¬ãžã¹ããªã«ç»é²ãããŠããããŒã¯ã³ã«ãã£ãŠã®ã¿å®è¡ãããŸãã ãããŠããã¹ãŠãã¯ãŒã«ã«ãªããŸããã1ã€ã®ãããããããããŸãã
ããŒã¿ã®æå·åã«äœ¿çšãããããŒïŒãŸãã¯ãã®ããŒã¯ã³ïŒã¯Store Configuratorã§èšå®ãããŸã...ããã¯ãä»ã®ãã©ã¡ãŒã¿ãŒãšåæ§ã«ç¹å¥ãªãã¡ã€ã«ã«å€æãããæ»æè ã空ã®å€ã«å€æŽããŠSAP POSã®æå·åãç¡å¹ã«ã§ããããšãæå³ããŸãã
ãããããé©çšããããããé©çšããæçµçã«ããããé©çšããŸããïŒã...ãŸãã¯ãã®ç¶æ³ã§äœããã¹ãã
çŸåšããã®èšäºã§èª¬æãããŠããè匱æ§ã¯è§£æ±ºãããŠããŸãã ã¯ããåããŠã§ã¯ãªããã»ãŒ2åç®ã«ãªããŸããã ãã®ãããæåã®SAPããŒã2476601ã¯2017幎7æ11æ¥ã«ãªãªãŒã¹ãããCVSS 8.1ãããããSAP POSïŒPoint of SaleïŒRetail Xpress Serverã®èªèšŒãã§ãã¯ã®æ¬ èœããšåŒã°ããŠããŸããã ããŒã2202ïŒtelnetïŒãžã®ã¢ã¯ã»ã¹ã¯ä¿®æ£ãããŸããã ããã¯ãæ°ãããã©ã¡ãŒã¿ãŒãBACKOFFICEIPADDRESSããè¿œå ããããšã§è¡ãããŸãããããã©ã«ãã¯ãlocalhostãã§ãã ããããåæã«ãããŒã2200ã®2çªç®ã®è匱æ§ã«ã€ããŠã¯èšåãããŠããŸããã§ãããæ£åžžã«æ©èœããæ»æè
ãã³ãã³ãããªã¢ãŒãã§å®è¡ã§ããããããã®ãã©ã¡ãŒã¿ãŒãå€æŽããã ãã§7æã®æ°ããããããããã€ãã¹ãã§ããŸãã ç§ãã¡ã®ããŒã ã¯ããã®æ¬ é¥ãSAP Product Security Response Teamã«å ±åãã2017幎8æ18æ¥ã«2ã€ã®å®å
šãªSAP Note-2520064ãš2520232ããªãªãŒã¹ããŸããã SAP Note 2520232ã¯ã2ã€ã®ã¹ãã¢ãããã·ãŒãžã£ssp_insert_backdoorãšssp_delete_backdoorãåé€ããŸãã SAP Note 2520064ã«ããå€ãã®å€æŽãå ããããŸããã ãã®ãããã¯ãããŸããŸãªSAP POSã¢ã€ãã ïŒPOSã¯ã©ã€ã¢ã³ããXpressãµãŒããŒãStore ConfiguratorãStore ManagerïŒã®éã§äº€æãããã»ãŒãã¹ãŠã®ããã±ãŒãžã«3DESæå·åãè¿œå ããŸããã ããªãã¡ ããŒãç¥ããªããŠãéããŠããããŒãã«æ¥ç¶ã§ããå Žåã§ããPOSã·ã¹ãã ã«åœ±é¿ãäžããæ¹æ³ã¯ãããŸããããµãŒããŒã¯ãæå·åãããŠããªããã±ãããèªèãããåã«ç Žæ£ããŸãã
ããã¯æ¬åœã«èå³æ·±ã解決çã§ãããããã€ãã®äºä»¶ããããŸããã SAP Noteã®ãªãªãŒã¹ã®ã»ãŒçŽåŸã«ãStore Managerãæ©èœããŠããªããšããå€ãã®ã¡ãã»ãŒãžããã©ãŒã©ã ã«è¡šç€ºããå§ããŸããã å®éãSAPã¯Store Managerãå¿ããŠããããŸãã¯ãããããã®ã³ã³ããŒãã³ããXpress Serverã ãã§ãªãããŒã¿ããŒã¹ãšã察話ããããšãå¿ããŠããŸããã ã¹ãã¢ãããŒãžã£ãŒãæå·åããããã±ãããããŒã¿ããŒã¹ã«éä¿¡ãããšãã¯ãªã¢ããã¹ããšã©ãŒãè¿ãããŸãããã®ãšã©ãŒã¯ãã¹ãã¢ãããŒãžã£ãŒã解èªã§ãããåã«ã¯ã©ãã·ã¥ããŸãã ãã®ç¹ã§ã以åã®ãããã®ãšã©ãŒãä¿®æ£ããæçµãããããªãªãŒã¹ãããŸããã ããã§ããã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®æœåšçãªæ»æããä¿è·ããããã®æåã®ãœãªã¥ãŒã·ã§ã³ã¯ãåžžã«æåãããšã¯éããŸããããå®æçãªæŽæ°ã§ãã
å®è©±
ãããŠããã«è¥¿ããã®èå³æ·±ããã¥ãŒã¹ããããŸãïŒForever 21ãã«ãªãã©ã«ãã¢ã«æ ç¹ã眮ãäŒç€Ÿãç±³åœã®ãã¡ãã·ã§ã³å°å£²æ¥è ã1984幎以æ¥äžçäžã§æã販売ããŠããŸãïŒ815åºèã57ãåœãç±³åœããªãŒã¹ãã©ãªã¢ããã©ãžã«ãäžåœããã©ã³ã¹ãªã©ïŒã2017幎12æ28æ¥ãPOSã·ã¹ãã ã®äžéšã4æ3æ¥ãã11æ18æ¥ãŸã§ã«äŸµå®³ããããšããæ å ±ã確èªããŸããïŒ!!!ïŒã å°é家ã«ãããšãæ»æè ã¯POSã·ã¹ãã ã®ãããã¯ãŒã¯ã«å¿åã§ã¢ã¯ã»ã¹ããããã䜿çšããŠæªæã®ããããã°ã©ã ãã€ã³ã¹ããŒã«ãã顧客ã®ã¯ã¬ãžããã«ãŒãã«é¢ããæ å ±ïŒã«ãŒãçªå·ãæå¹æéãææè ãèªèšŒã³ãŒãïŒãåéããŸããã ãããã®ã·ã¹ãã ã®éèŠãªããŒã¿ã®æå·åã4æ3æ¥ãã11æ18æ¥ãŸã§ã®æéã«ç¡å¹ã«ãªã£ãïŒãããæ©èœããªãã£ãïŒã®ã¯é¢çœãããšã§ãã æããã«ãæå·åã¯SAPã·ã¹ãã ã ãã§ãªãã倧ããªåé¡ã§ã¯ãããŸããã æ®å¿µãªãããã©ã®POSã·ã¹ãã ã䟵害ããããã«é¢ããæ£ç¢ºãªæ å ±ãèŠã€ããããšã¯ã§ããŸããã§ããã ãã¥ãŒã¹ãä¿¡ããå Žåã2017幎6æ28æ¥ã«Forever 21ã¯æ±èã°ããŒãã«ã³ããŒã¹ãœãªã¥ãŒã·ã§ã³ãºãšãã®ã·ã¹ãã ã®äŸçµŠã«é¢ããå¥çŽãç· çµããŸãããããã®æç¹ã§çŸåšã®ã·ã¹ãã ã¯ãã§ã«äŸµå®³ãããŠããŸããã