ããã°ããŒã¿æµæã®ããŒãã®ç¶ç¶1 ã dartraidenãšYourChiefããã®èšäºã«å¯Ÿããã³ã¡ã³ããèªãã åŸãç§ã¯ãã¹ãŠãæ¬åœã«è¯ãã®ãã2ipãšWhoerã®å¿åæ§ãšã»ãã¥ãªãã£ã®ãã¹ãã§ååãªã®ãããŸãã¯ãã¹ãŠãè¯ãã®ããäœãã«æ°ä»ããªãã£ããšèããŸããã ããã«ãç§ã¯ã€ã³ã¿ãŒãããäžã§å€ãã®åé¡ãçºèŠããããå·çæã«èªåã§ãããã«ééããŸããã
å°æ¬ãããŠããKhabrasocietyã®è£å€æã«ãçºèŠããã誀解ãšãããã解決ããããã®ææ¡ã®éžæãããã³ãã©ãŠã¶ãšè匱æ§ããã¹ãããããã®ããã€ãã®æ¹æ³ãæäŸããããšæããŸãã
ãŸãããã®èšäºã§ã¯ããŠãŒã¶ãŒã¬ãã«ã§ã®ã·ã³ãã«ã§ç¡æã®VPNãšå®å šãªDNSæ§æãæ€èšããããšãææ¡ããŸãã
æ§é
- ã»ãã¥ãªãã£ãã¹ã\å¿åæ§ã åã®èšäºãžã®ã³ã¡ã³ãã§ç§èŠã¯YourChiefãæ£ããæžãããã圌ããäœããéæãããšããä¿èšŒã¯ã©ãã«ãããããã§ååã§ããïŒ ãã®è³ªåã«ãèå³ããããŸããã
- äžè¬ã«ã1ã€ã®ãããã¯ã«é¢ãã倱æã¯ãå¿ ãããç®ç«ã€ãšã¯éããŸããã é©åãªãŠãŒã¶ãŒãšãŒãžã§ã³ããéžæããããšã§ãã»ãŒãã¹ãŠãäžåºŠã«ä¿®æ£ããŸããã ã»ãšãã©ãã¹ãŠã®é ç®ã«è§£æ±ºçã®ææ¡ããããŸããããããã¯åŠè¡çé¢å¿ã®èŠ³ç¹ããã®ã¿ã§ãã
- VPN +ã»ãã¥ã¢DNS-åã®èšäºãžã®è¿œå ã ãŠãŒã¶ãŒã¬ãã«ã§ååŸããã³æ§æããæ¹æ³
ééãããå§ããŸã
å€æ°ã®ãã©ãŠã¶ã»ãã¥ãªãã£ãã¹ã
IPããã©ãŠã¶ãOSãé ãå€ãã®åé¡ãèŠã€ãããŸãã
- 倱æ8ab3a24c55ad99f4e3a6e5c03cad9446ïŒFirefoxïŒ
- 倱æ-ã¿ããããããã¯ãªãã¯ããŠããŠã¹ãã¿ãã
- p0fã«å€±æãã
- æçŽãã¡ã€ã«
- WebRTCãŸãã¯ããã«ã¡ã¯
- ä»ã®ããã€ãã¯æ確ã«ããããã«å€±æããããããå¿ããªãããã«ããŸã
Mythic TheorrentãIKnowWhatYouDownloadedã«å€±æãã
ãªãã¡ãŒãæäŸããŸã
é¢çœããããããŸããã
ãœãŒã¹
ééãããå§ããŸã
æ²ããããªã眪ããªãããã§ã¯ãªãã åã®èšäºãããã°ããŒã¿ãã¯å®å šã«æåããããã§ã¯ãããŸããããã¯ãªãŒã³ãªãã¹ããããã¡ã€ã«ã§æ§é å šäœãäœæããããšãææ¡ãããŸããã åé¡ã®1ã€ã¯ãããŸããŸãªã³ã³ããŒãã³ãã®åäœã®äžæŽåã§ããããã®çµæããã·ã¢é£éŠã®ãµã€ãã«å¯ŸããŠæ確ã«æ§æãããŠããªãåãã³ã³ããŒãã³ããã¯ãªã¢ãªã³ã¯ãããã«ã¯ãã©ã€ãã·ãŒã¢ãã°ããããªãã®äººçãå°ç¡ãã«ããå¯èœæ§ããããŸãã ããããæ°åã¯ãããå€§å¹ ã«ç°¡çŽ åã§ããŸãã
AutoDelete Cookieãå«ãã¡ã€ã³Cookieãããã¯ãæé»çã«ã第1ã¬ãã«ã®åé¢ããç¡å¹ã«ããŸãïŒåŸã§ç¢ºèªãããŸãããã®ç« ã®æåŸã®èšäºçªå·2ãåç §ããŠãã ããïŒã
èå³ã®ããæ¹ã¯ãçŸæç¹ã§ããã€ãã®å€æŽãè¡ã£ãŠããŸãã ããã°ããŒã¿ã¬ãžã¹ã¿ã³ã¹1ãå床èªã¿åããFoxæ©åšã«é©åãªå€æŽãå ããå¿ èŠããããŸãã
SereverWorkersãç»å Žããå€ãã®ãµã€ãã§FireFoxã«æ°ä»ããªããã¡ã«è¿œå ããå§ããŸããã aboutïŒserviceworkersã¯youtubeãyandexãããã³å¥ã®100500ãå®å®çã«æäŸããŸããã¢ããªã³ãç»å ŽããŸããããæåéãå æ¥BlockServiceWorkers ïŒãããŸã§2人ã®ãŠãŒã¶ãŒããããŸããïŒã
ãã®ããã«åäœããŸã
ãµã€ããServerWorkersã«æ¥ç¶ããããšãããšããŠã£ã³ããŠã衚瀺ãããŸã
ãã®ãŠã£ã³ããŠãã¯ãªãã¯ããªããšãã€ã³ã¹ããŒã«ã¯è¡ãããŸããïŒã¯ãªãã¯ãããšãããŒãžããªããŒããããServiceWorkersãã€ã³ã¹ããŒã«ãããŸãïŒã çŸæç¹ã§ã¯ãäœãäžæãããŸã§ã€ã³ã¹ããŒã«ãèš±å¯ããŸããã§ããããäžéšã®ããŒã¿ãšãµã€ããšã®ããã¯ã°ã©ãŠã³ãåæãå¿ èŠãªå Žåã¯ãã€ã³ã¹ããŒã«ãèš±å¯ããå¿ èŠããããŸãã
ãã®ãŠã£ã³ããŠãã¯ãªãã¯ããªããšãã€ã³ã¹ããŒã«ã¯è¡ãããŸããïŒã¯ãªãã¯ãããšãããŒãžããªããŒããããServiceWorkersãã€ã³ã¹ããŒã«ãããŸãïŒã çŸæç¹ã§ã¯ãäœãäžæãããŸã§ã€ã³ã¹ããŒã«ãèš±å¯ããŸããã§ããããäžéšã®ããŒã¿ãšãµã€ããšã®ããã¯ã°ã©ãŠã³ãåæãå¿ èŠãªå Žåã¯ãã€ã³ã¹ããŒã«ãèš±å¯ããå¿ èŠããããŸãã
ãŸããåæããã³Webéç¥ãšãšãã«SereverWorkersãå®å šã«ç¡å¹ã«ããããšãã§ããŸãïŒåã®èšäºãuser.jsãã¡ã€ã«ïŒ
è åšãšææ決å®ãæ£åœåããïŒ å€æ°ã®ãã©ãŠã¶ã»ãã¥ãªãã£ãã¹ã
1. E-Tag CookielessCookies ã ïŒå®å šã§ãããåã®èšäºã®ã¢ããªã³ãã€ã³ã¹ããŒã«ãããä»ã®é¡äŒŒã®ã¢ããªã³ããªãå Žåãåãé€ãã®ã¯å°é£ã§ãïŒ
ãã®ããã«æè°ã§ããŸã
äœããæžããŠãã¹ãã¢ãã¿ã³ãã¯ãªãã¯ããŠããããã®ã©ãã«ãåé€ããŠãã ããã ChameleonãšCookiebroã䜿çšããŠããå Žå-åé€ããªããŠãã2ã3ååæ€åºããŠF5ãæŒããšãèªåçã«æ¶ããŸããCookieClearã§ãClear ...ããã¯ãªãã¯ããŠåé€ãããšãããã«æ¶ããŸãã
äœããæžããŠãã¹ãã¢ãã¿ã³ãã¯ãªãã¯ããŠããããã®ã©ãã«ãåé€ããŠãã ããã ChameleonãšCookiebroã䜿çšããŠããå Žå-åé€ããªããŠãã2ã3ååæ€åºããŠF5ãæŒããšãèªåçã«æ¶ããŸããCookieClearã§ãClear ...ããã¯ãªãã¯ããŠåé€ãããšãããã«æ¶ããŸãã
2.第1ã¬ãã«ã®ãã¡ã€ã³ãšã³ã³ãããŒã®åé¢
ã¢ããªã³ãåé¢ã«è¿œå ã§ããŸã
å€åºå
ã®ã³ã³ããã¯ã¿ãã«ãã¿ã³ãè¿œå ããŸã ã³ã³ããã¹ãã¡ãã¥ãŒé
ç® ã
æ°ããäžæïŒïŒïŒã³ã³ããã§ã¿ããéããŸãã ãã®ã³ã³ããã®ãã¹ãŠã®ã¿ããéãããããšãããã§çºçãããã¹ãŠïŒCookieãããŒã¿ïŒããªã»ãããããŸãã
æ°ããäžæïŒïŒïŒã³ã³ããã§ã¿ããéããŸãã ãã®ã³ã³ããã®ãã¹ãŠã®ã¿ããéãããããšãããã§çºçãããã¹ãŠïŒCookieãããŒã¿ïŒããªã»ãããããŸãã
Googleã®å人çãªäŸãšããŠããã«æäŸãããŠããä»ã®ã³ã³ãã-IMHOã¯äŸ¡å€ããããŸããããã®å€èŠ³ã¯ãããã¯ãå³ãããæµè¡ã«åãããŠã³ã³ããåãããçµæã§ããããã®æ©èœã¯çãããããã§ãã
3.éé¢ãæ£åœåããïŒ
çµéšçã«çŽç²ïŒ
-ãã¹ãŠã®å¿ èŠãã€æçšãªãµãŒãã¹ããããã©ã«ãã§ãã³ã³ããã«é 眮ãããéè¡ããã®æçŽã\ãœãŒã·ã£ã«ããæ¥ãå Žåã ãããã¯ãŒã¯ãªã© ãªã³ã¯ã䜿çšãããšããã©ãŠã¶ã®ãªã³ã¯ããã©ããšæ¬¡ã®ããã«è¡šç€ºãããŸã ã 衚瀺ãããªãå Žåã¯ãåæ ãããã®ããããŸãã
-è©æ¬ºã®ååã¯ã¯ãããŒã®çé£ãªã©ã«åºã¥ããŠããŸãã -XSSããã³ãã®ä»ã®ç¥ç§çã§æããããã®ã åæã«ããã£ãã·ã³ã°ãªã³ã¯ã
ã»ãŒçŽç²ïŒ
-ååã®èšäºã§ãEverCookieã«ã€ããŠåç §ããŠãã ããïŒã»ãšãã©ã®å Žåãåé¡ã¯åé¢ãšã³ã³ãããŒã«ãã£ãŠè§£æ±ºãããCanvasBlockerãªãã§ã¯1ãã€ã³ãããå®è¡ã§ããŸããïŒ
-ãã®ãã¹ãã匷ããå§ãããŸãïŒ BrowserAudit
ããããçš®é¡ã®è匱æ§ã確èªãã
ãã¹ãã«ã¯çŽ3åããããŸããéå±ããããšã¯ãããŸãããããã¹ãã®è©³çŽ°ãã®ããã«ãå±éããŠå¥ªãããšãã§ããã®ã§ããã¹ãã®é²è¡ç¶æ³ã確èªããŠãã ããã
test.browseraudit.com-> browseraudit.comã®ãããªèšç»ã®èŠåãäºæ³ãããŸãã åé¢ã¯ãµããã¡ã€ã³ã«ã¯é©çšãããŸããããäžæ¹ã§ãäžéšã®ãµã€ãã§ã¯ç»é²ãããã«é¢é£ä»ããããŠããŸãã
å®éã®ãã¡ã€ã«ãIMHOã®å Žåãbrowseraudit.com-> browseraudit.orgã®ãããªéä¿¡ãšã©ãŒã衚瀺ãããå Žå ããã¯äžå¹žãªè»¢éa'la XSSã§ãã
ïŒé¢å¿ã®ããæ¹ã®ããã«ãæ°ãããã¹ãã§ã¯ããã¹ããããŠããç¹å®ã®è匱æ§ã®ããã°ã©ã ã³ãŒããå«ãæ¡åŒµå¯èœãªããã«ããããŸãïŒ
ãã¹ãã«ã¯çŽ3åããããŸããéå±ããããšã¯ãããŸãããããã¹ãã®è©³çŽ°ãã®ããã«ãå±éããŠ
test.browseraudit.com-> browseraudit.comã®ãããªèšç»ã®èŠåãäºæ³ãããŸãã åé¢ã¯ãµããã¡ã€ã³ã«ã¯é©çšãããŸããããäžæ¹ã§ãäžéšã®ãµã€ãã§ã¯ç»é²ãããã«é¢é£ä»ããããŠããŸãã
å®éã®ãã¡ã€ã«ãIMHOã®å Žåãbrowseraudit.com-> browseraudit.orgã®ãããªéä¿¡ãšã©ãŒã衚瀺ãããå Žå ããã¯äžå¹žãªè»¢éa'la XSSã§ãã
ïŒé¢å¿ã®ããæ¹ã®ããã«ãæ°ãããã¹ãã§ã¯ããã¹ããããŠããç¹å®ã®è匱æ§ã®ããã°ã©ã ã³ãŒããå«ãæ¡åŒµå¯èœãªããã«ããããŸãïŒ
4.æ®ããæ£åœåããïŒ
ç¢å°ã®ç¿»èš³ã§ïŒãããæ©èœããªãå Žåã¯ãFireFoxãæŽæ°ããå¿ èŠããããŸãïŒ
1. SpectreïŒMeltdownã®çºã®ããšãïŒäžã®ãã¿ã³ãã¯ãªãã¯ããŠãã§ãã¯ããŸãïŒã
2. WITCHã確èªããŸãã ãµã€ããžã®ã¢ã¯ã»ã¹ãèš±å¯ã§ããŸãïŒãããã¯çãç¶ããç¬é¡ã¯æ¢ãŸããŸããïŒã ãããäœã§ãããã¯åé¡ã§ã¯ãããŸããïŒãããããWindows XPã§ãçªç¶ãŠãŒã¶ãŒã®äžãã管çè ã¢ã¯ã»ã¹æš©ãäžããSMBã®å¥ã®æ éïŒãããã¯åäœããªãã¯ãã§ãã ããŸããã£ãå Žå-Habréã§ã®æ²»çïŒããã³ãã¹ããµã€ã-èšäºã®èè ïŒ ã
3.è匱æ§BrowserCheckã確èªããŸãã ãªã³ã¯ããããŸãïŒ
翻蚳ç¢å°ãªã
1. æå·åããã¹ãããŸã ã
倱æããå Žå
-HTTPS EverywhereïŒåã®èšäºãåç
§ïŒ
-æ··åã³ã³ãã³ããã¹ãïŒæ··åã³ã³ãã³ããhttpsãšhttpãåæã«èš±å¯ïŒãFireFoxãgoogleã§ç¡å¹ã«ããããšãã§ããŸãããåºæ¬çã«ã¯-ç»åã§ããããµã€ããç Žå£ããå¯èœæ§ããããŸã
-ä¿¡é Œæ§ã®äœãå€ããããã³ã«ã®åé¡ã åæããããšãã«äœãå£ããã®ãããããŸããããäœããã§ããŸã
çŽïŒconfig
TLS 1.0ã®åé¡ã¯security.tls.version.min = 2ã§ã
TLS_RSA_WITH_AES_128_CBC_SHAãªã©ã®åé¡
security.ssl3.rsa_aes_128_sha = false
security.ssl3.rsa_aes_256_sha = false
security.ssl3.rsa_des_ede3_sha = false
-æ··åã³ã³ãã³ããã¹ãïŒæ··åã³ã³ãã³ããhttpsãšhttpãåæã«èš±å¯ïŒãFireFoxãgoogleã§ç¡å¹ã«ããããšãã§ããŸãããåºæ¬çã«ã¯-ç»åã§ããããµã€ããç Žå£ããå¯èœæ§ããããŸã
-ä¿¡é Œæ§ã®äœãå€ããããã³ã«ã®åé¡ã åæããããšãã«äœãå£ããã®ãããããŸããããäœããã§ããŸã
çŽïŒconfig
TLS 1.0ã®åé¡ã¯security.tls.version.min = 2ã§ã
TLS_RSA_WITH_AES_128_CBC_SHAãªã©ã®åé¡
security.ssl3.rsa_aes_128_sha = false
security.ssl3.rsa_aes_256_sha = false
security.ssl3.rsa_des_ede3_sha = false
2. BrowserSpy Webãµã€ãã§ãHTML5ã®pingãªã©ã®äž»èŠãªæªæã®ããæè¡ããªãã«ããéããåã®èšäºã®user.jsãã¡ã€ã«ã®ãã©ã¡ãŒã¿ãŒããã¹ãã§ããŸãã
3. Do I leakã§ãã©ãŠã¶ããã¹ãã§ããŸãã
-ããŒã¿ãã³ã³ãã¥ãŒã¿ãŒã«ä¿åããããšãç³ãåºãå Žå-æåŠã§ããŸãããå£ããããšã¯ãããŸãã
-ã¹ãã€ã³èªã®å Žåã VPN-ãã¬ã³ããã¹ããæå¹ã«ããããšãææ¡ããŸãïŒè¿œå ã®ãã¬ã³ããã¹ããã¢ã¯ãã£ãã«ãããéžæããŸãïŒãã¯ã©ã€ã¢ã³ãã«ç£æ°ãªã³ã¯ãäžãããµã€ããè¿ããã®ã確èªããŸãã
-ã¹ãã€ã³èªã®å Žåã ãããã·-SSLãã©ãã£ãã¯ãã©ã¡ãŒã¿ã«æ³šæããŠãã ãã
å³åŽã®ãã¹ãŠã®ç¢å°ã§ããã©ã¡ãŒã¿ãŒã®ããŒã«ããããå±éããŸãã
4. ããŒã«ã«ã®FireFoxãªããžããªãŒãžã®å€éšã¢ã¯ã»ã¹ã確èªã§ããŸã ïŒãã¬ãŒãã®äžéšã¯ç©ºã§ããµããŒããããŠããŸããïŒã
5. åºåä»ãã®Webãµã€ã ã åºåãããã«ãŒã®ãã¹ã
6.åã®èšäºã®Malwarebytesãã€ã³ã¹ããŒã«ããã³æ§æãããŠããå Žå- ãµã€ãã®ãã©ãã¯ãªã¹ã ã ããã«ããµã€ãã¯ãããã¯ãŒã¯ã»ãã¥ãªãã£ã«æ¥ç¶ãããŠããããåºåã«æ¥ç¶ãããŠããããã§ããããªã¹ãã¯ç¶æãããŠããŸãã
Malwarebytesã¯ãã¹ãŠã®ç§»è¡ããããã¯ããããã§ã¯ãããŸãããIMHOã¯ãªã¹ã¯ãåããŠã¯ãããªããã£ãã·ã³ã°ãµã€ããé€ããŸã+ããã¯RFãµã€ãã§ãããããã«å¯ŸåŠãããããŸã£ããå¿çããªãã£ãä»ã®ã¢ããªã³ããããã¯ããŸãã
æçŽæ€æ»ã«ã€ããŠã 泚æããŠãã ããïŒ
-以åã«ææ¡ãããCanvasBlockerã¢ããªã³ã¯ãããããåœé ãããã®ã§ãããæ¶å»ãããã®ã§ã¯ãããŸããã ã€ãŸã ããã¯ãã§ãããå€æŽãããŸãã CanvasBlockerã®èšå®ã§äœãå€æŽããªãå Žåãæ¯åå€æŽãããŸãã ãã¹ãããŒãžã§F5ããŒãæŒããšãå€æŽãããã¯ãã§ãã
-æšå¥šå€ãèšå®ããå ŽåïŒãã¿ãã¬ã®äžïŒãå°å·ãå€æŽããã«ã¯ãã©ãŠã¶ãåèµ·åããå¿ èŠããããŸãã
-äžéšã®ãµã€ãã¯ãã¿ããéããŠåãCookieããªã»ãããããŸã§ãCookieãå«ããã¹ãŠã®ç¹ã§å æ¬çã«æžã蟌ã¿ãŸãã
CanvasBlockerèšå®ã«ã€ããŠ
-ãªã¯ãšã¹ãããšã«æçŽã®å€æŽãèšå®ãã䟡å€ã¯ãªããšæããŸãïŒããã©ã«ãã§èšå®ïŒã
ã¢ãã€ã«ããŠãŒãã£ãªãã£ãªã©ã«æéãæ¯æãå Žå ãµã€ãããã¯ã€ããªã¹ãã«ç»é²ããããæçŽã®ãªãããŸããç¡å¹ã«ããããããšãéåžžã«çŸå®çãªåé¡ãçºçããå¯èœæ§ããããŸãã Pativenãç»å Žããå¯èœæ§ã¯äœãã§ãããããã€ãã®çåãçããå¯èœæ§ããããŸãã
èšå®ã§ã¯ããããèšå®ã§ããŸãã
æçŽã¯ããã©ãŠã¶ã®èµ·åæã«1åå€æŽãããŸãïŒã»ãã·ã§ã³ïŒã ãã ããåãã¡ã€ã³ïŒãµããã¡ã€ã³ãå«ãïŒã«ã€ããŠã¯ãã»ãã·ã§ã³äžã¯ç¬èªã®ãã¡ã€ã³ã«ãªããŸãïŒ2ã€ã®ç°ãªããã£ã³ãã¹ãã§ãã«ãŒã§åæã«ãã§ãã¯ã§ããŸãïŒã ãããŠãæçŽã®ã¿ã¹ã¯ã§ããIMHOã¯ããµã€ãã欺ãããšã§ã¯ãªãããŠãŒã¶ãŒã®å¥œã¿ãåºåã«åœ¹ç«ã€ãã®ä»ã®ãã®ã決å®ããããšã§ãäœããã®æ¹æ³ã§ãµã€ãã®ãã¹ã远跡ãããããšã§ã¯ãããŸãã-ããã§è§£æ±ºããå¿ èŠããããŸã
0ç§ïŒãŸãã¯ãã®ä»ã®æéééïŒã¯ã·ã£ããããŠã³ã§ãã ç§èŠãã¿ã€ããŒã·ãããèšå®ãã䟡å€ã¯ãããŸããã ã©ã®æç¹ã§çºçããã®ãããã®æç¹ã§äœãè¡ãã®ãã¯æ確ã§ã¯ãããŸããã
ãã¯ãªã¢ã-äžèšã®ãããªèšå®ã§ãæçŽã®åŒ·å¶å€æŽãå®è¡ããŸãã
-CanvasBlockerã§ã¯ãããªã³ãã«æå°éã®å€æŽãèšå®ãã䟡å€ããããšæããŸãïŒããæ£ç¢ºã«ã¯ãå€æŽããªãã§ãã ãããããã©ã«ãã§ã¯æå°éã§ãïŒã ãšã«ããåäœããã¯ãã§ãããäœããå£ããå¯èœæ§ã¯äœããªããŸãããªããªããæçŽã¯ãŸã ãã®ãããªç®çã®ããã«çºæãããŠããªãåŸæ¥ã®Webãã¯ãããžãŒã䜿çšããŠããããã§ãã
CanvasBlockerã¯ããã©ã°ã€ã³ããžãªãã±ãŒã·ã§ã³ãWebRTCãWebGLã¬ããŒãããã·ã¥ïŒãã³ããŒãã¬ã³ãã©ãŒïŒã«ä»£ãããã®ã§ã¯ãããŸããã ïŒãWebGL Image Hashã-眮æïŒã ãããã®ãªãã·ã§ã³ãç¡å¹ã«ããã«ã¯ãåã®èšäºãuser.jsãã¡ã€ã«ãããã³èšäºã«é¢ããã³ã¡ã³ããåç §ããŠãã ããã
ããã©ã«ãã§CanvasBlockerïŒããã¯ãããšãã¹ããŒãã¢ãŒããããã§ãã¯ããããšã§èšå®ã§å®è¡ã§ããŸãïŒïŒ
-ãã©ã³ãã眮ãæããŸããã èšå®ããªã¹ãã-ããã¯ã€ããªã¹ãããããã®åŸã家åºå ã®Google Docããã³ä»ã®æçšãªãã®ã§å°é£ãååŸããŸãã
-ä¿è·ãwindows.nameããç¡å¹ã«ããŸããã ããŠã£ã³ããŠAPIãã®èšå®ã¯ãä¿è·ããããŠã£ã³ããŠAPIãã§ããããã¯ããããããã§ã¯ãªãããšãããã£ããã£ãæ©èœããªããªãããã¹ãŠããªãã«ãããšè¡šç€ºãããŸãããç»åã®ãããŠã£ã³ããŠã¯è¡šç€ºãããªãããã§ãã ã«ã¡ã¬ãªã³ã§ã¯ãããã«äžã«ããããã®ããã«æ¡åŒµèšå®ã«è¡ãå¿ èŠããªãã®ã§ããªã³/ãªããåãæ¿ããæ¹ã䟿å©ã§ãã
ã¢ãã€ã«ããŠãŒãã£ãªãã£ãªã©ã«æéãæ¯æãå Žå ãµã€ãããã¯ã€ããªã¹ãã«ç»é²ããããæçŽã®ãªãããŸããç¡å¹ã«ããããããšãéåžžã«çŸå®çãªåé¡ãçºçããå¯èœæ§ããããŸãã Pativenãç»å Žããå¯èœæ§ã¯äœãã§ãããããã€ãã®çåãçããå¯èœæ§ããããŸãã
èšå®ã§ã¯ããããèšå®ã§ããŸãã
æçŽã¯ããã©ãŠã¶ã®èµ·åæã«1åå€æŽãããŸãïŒã»ãã·ã§ã³ïŒã ãã ããåãã¡ã€ã³ïŒãµããã¡ã€ã³ãå«ãïŒã«ã€ããŠã¯ãã»ãã·ã§ã³äžã¯ç¬èªã®ãã¡ã€ã³ã«ãªããŸãïŒ2ã€ã®ç°ãªããã£ã³ãã¹ãã§ãã«ãŒã§åæã«ãã§ãã¯ã§ããŸãïŒã ãããŠãæçŽã®ã¿ã¹ã¯ã§ããIMHOã¯ããµã€ãã欺ãããšã§ã¯ãªãããŠãŒã¶ãŒã®å¥œã¿ãåºåã«åœ¹ç«ã€ãã®ä»ã®ãã®ã決å®ããããšã§ãäœããã®æ¹æ³ã§ãµã€ãã®ãã¹ã远跡ãããããšã§ã¯ãããŸãã-ããã§è§£æ±ºããå¿ èŠããããŸã
0ç§ïŒãŸãã¯ãã®ä»ã®æéééïŒã¯ã·ã£ããããŠã³ã§ãã ç§èŠãã¿ã€ããŒã·ãããèšå®ãã䟡å€ã¯ãããŸããã ã©ã®æç¹ã§çºçããã®ãããã®æç¹ã§äœãè¡ãã®ãã¯æ確ã§ã¯ãããŸããã
ãã¯ãªã¢ã-äžèšã®ãããªèšå®ã§ãæçŽã®åŒ·å¶å€æŽãå®è¡ããŸãã
-CanvasBlockerã§ã¯ãããªã³ãã«æå°éã®å€æŽãèšå®ãã䟡å€ããããšæããŸãïŒããæ£ç¢ºã«ã¯ãå€æŽããªãã§ãã ãããããã©ã«ãã§ã¯æå°éã§ãïŒã ãšã«ããåäœããã¯ãã§ãããäœããå£ããå¯èœæ§ã¯äœããªããŸãããªããªããæçŽã¯ãŸã ãã®ãããªç®çã®ããã«çºæãããŠããªãåŸæ¥ã®Webãã¯ãããžãŒã䜿çšããŠããããã§ãã
CanvasBlockerã¯ããã©ã°ã€ã³ããžãªãã±ãŒã·ã§ã³ãWebRTCãWebGLã¬ããŒãããã·ã¥ïŒãã³ããŒãã¬ã³ãã©ãŒïŒã«ä»£ãããã®ã§ã¯ãããŸããã ïŒãWebGL Image Hashã-眮æïŒã ãããã®ãªãã·ã§ã³ãç¡å¹ã«ããã«ã¯ãåã®èšäºãuser.jsãã¡ã€ã«ãããã³èšäºã«é¢ããã³ã¡ã³ããåç §ããŠãã ããã
ããã©ã«ãã§CanvasBlockerïŒããã¯ãããšãã¹ããŒãã¢ãŒããããã§ãã¯ããããšã§èšå®ã§å®è¡ã§ããŸãïŒïŒ
-ãã©ã³ãã眮ãæããŸããã èšå®ããªã¹ãã-ããã¯ã€ããªã¹ãããããã®åŸã家åºå ã®Google Docããã³ä»ã®æçšãªãã®ã§å°é£ãååŸããŸãã
-ä¿è·ãwindows.nameããç¡å¹ã«ããŸããã ããŠã£ã³ããŠAPIãã®èšå®ã¯ãä¿è·ããããŠã£ã³ããŠAPIãã§ããããã¯ããããããã§ã¯ãªãããšãããã£ããã£ãæ©èœããªããªãããã¹ãŠããªãã«ãããšè¡šç€ºãããŸãããç»åã®ãããŠã£ã³ããŠã¯è¡šç€ºãããªãããã§ãã ã«ã¡ã¬ãªã³ã§ã¯ãããã«äžã«ããããã®ããã«æ¡åŒµèšå®ã«è¡ãå¿ èŠããªãã®ã§ããªã³/ãªããåãæ¿ããæ¹ã䟿å©ã§ãã
ããªã³ãã®ãªã¹ã
CanvasBlockerã眮ãæããããŸãïŒæçŽæ©èœã¯ã¢ã³ãæ€åºãã©ãŠã¶ãŒãšåãã§ãïŒïŒ
ãã£ã³ãã¹ ã°ã©ãã£ãã¯ã衚瀺ããããã®HTML5èŠçŽ ã¯ããããªã·ã¹ãã ã®ç¹æ§ã«äŸåããŸãã
ãªãŒãã£ãªãã£ã³ã¬ãŒããªã³ãã ãªãŒãã£ãªã·ã¹ãã ã«ãã£ãŠã³ã³ãã¥ãŒã¿ãŒãèå¥ã§ãããã¯ãããžãŒãããã¯ã°ã©ãŠã³ãã§ã¯ãå°ããªãµãŠã³ããã¡ã€ã«ãåçããããªã·ãã°ã©ã ãååŸãããŸãã
WebGLïŒWebGL Image HashïŒã OpenGLã®ãã©ãŠã¶å®è£ ã¯ããã©ãŠã¶ã®3次å ã°ã©ãã£ãã¯ã¹ã§åäœããããã«èšèšãããŠããŸãã
ã»ClientRectsã ç»åã®ã¹ã±ãŒãªã³ã°æã«ããã·ã¥ãååŸããããšã«åºã¥ãèå¥æ¹æ³ã
Ubercookies ClientRectsããã³Audiofingerprintã®ããã·ã¥ã䜿çšãããšãããã€ã¹ãé«ã確çã§èå¥ããããšãã§ããŸãã
Ubercookies以å€ã¯ãã¹ãŠBrowserLeaksã§ãã¹ãã§ããŸãïŒä»¥äžãåç §ïŒã
æè¿ãããŠã¹ã®åãããã£ã³ã¬ãŒããªã³ãããããŒããŒãã§å ¥åããæè¡ãç»å ŽããŸããã ScriptSafeã¢ããªã³ã¯å¯Ÿå¿ãããã€ãºïŒãã·ã¢èªã®ã€ã³ã¿ãŒãã§ã€ã¹ïŒãå®è¡ã§ããŸããã
ã»ãã®æ©èœã¯CanvasBlockerãNoScriptãadBlockerãçµã¿åãããŠããŸãããaïŒåæ©èœã«ã¯ããã»ã©æè»ãªèšå®ã¯ãããŸããããbïŒãŠãŒã¶ãŒã«ãšã£ãŠã¯äžå¿ èŠãªãã®ã§ãcïŒèª¬æã¯å¥ã®èšäºã§ã
ã»ç°ãªããµã€ãéã§ãŠãŒã¶ãŒã確å®ã«è¿œè·¡ã§ããããã«ããããã«ã¯ãæè¡ãæ®åããŠããå¿ èŠããããŸãããä»ã§ã¯ããã§ã¯ãªãããã§ããæ®åããã°CanvasBlockerã¯å®æããã§ãããã
ãã£ã³ãã¹ ã°ã©ãã£ãã¯ã衚瀺ããããã®HTML5èŠçŽ ã¯ããããªã·ã¹ãã ã®ç¹æ§ã«äŸåããŸãã
ãªãŒãã£ãªãã£ã³ã¬ãŒããªã³ãã ãªãŒãã£ãªã·ã¹ãã ã«ãã£ãŠã³ã³ãã¥ãŒã¿ãŒãèå¥ã§ãããã¯ãããžãŒãããã¯ã°ã©ãŠã³ãã§ã¯ãå°ããªãµãŠã³ããã¡ã€ã«ãåçããããªã·ãã°ã©ã ãååŸãããŸãã
WebGLïŒWebGL Image HashïŒã OpenGLã®ãã©ãŠã¶å®è£ ã¯ããã©ãŠã¶ã®3次å ã°ã©ãã£ãã¯ã¹ã§åäœããããã«èšèšãããŠããŸãã
ã»ClientRectsã ç»åã®ã¹ã±ãŒãªã³ã°æã«ããã·ã¥ãååŸããããšã«åºã¥ãèå¥æ¹æ³ã
Ubercookies ClientRectsããã³Audiofingerprintã®ããã·ã¥ã䜿çšãããšãããã€ã¹ãé«ã確çã§èå¥ããããšãã§ããŸãã
Ubercookies以å€ã¯ãã¹ãŠBrowserLeaksã§ãã¹ãã§ããŸãïŒä»¥äžãåç §ïŒã
æè¿ãããŠã¹ã®åãããã£ã³ã¬ãŒããªã³ãããããŒããŒãã§å ¥åããæè¡ãç»å ŽããŸããã ScriptSafeã¢ããªã³ã¯å¯Ÿå¿ãããã€ãºïŒãã·ã¢èªã®ã€ã³ã¿ãŒãã§ã€ã¹ïŒãå®è¡ã§ããŸããã
ã»ãã®æ©èœã¯CanvasBlockerãNoScriptãadBlockerãçµã¿åãããŠããŸãããaïŒåæ©èœã«ã¯ããã»ã©æè»ãªèšå®ã¯ãããŸããããbïŒãŠãŒã¶ãŒã«ãšã£ãŠã¯äžå¿ èŠãªãã®ã§ãcïŒèª¬æã¯å¥ã®èšäºã§ã
ã»ç°ãªããµã€ãéã§ãŠãŒã¶ãŒã確å®ã«è¿œè·¡ã§ããããã«ããããã«ã¯ãæè¡ãæ®åããŠããå¿ èŠããããŸãããä»ã§ã¯ããã§ã¯ãªãããã§ããæ®åããã°CanvasBlockerã¯å®æããã§ãããã
ç空äžã®çç¶ãããã¯ãããžãŒã®äŸãå°ãªããšããããŸã§ã¯çç¶
ããŠã¹ãã€ãŒã« ã ãããã»ã»ã«ã«ãã¹ã»ãã«ã ã
Sey Malevichã¯ãèµ€ãåè§ã®äžã«ã«ãŒãœã«ãåãããŠã¹ã¯ããŒã«ããããšãææ¡ããŠããŸãïŒãã¿ã³ãã¯ãªãã¯ããã ãã§æ©èœããå ŽåããããŸãïŒã ãã£ãŒãã«ããŒã¿ã衚瀺ããŸãã
圌ã®ããŒãžããã®ç¿»èš³ïŒ
ã»ãšãã©ã®ãã©ãŠã¶ïŒTorãå«ãïŒã®ããŠã¹ãã€ãŒã«ã¹ã¯ããŒã«ã€ãã³ãã¯ãã¹ã¯ããŒã«ãã«ã¿ã«é¢ããæ å ±ãæäŸããŸãã éåžžã®ããŠã¹ã®å Žåã¯3ã§ããããã©ãã¯ãããã䜿çšããå Žåããã«ã¿ã¯å¯å€ã§ããããã©ãã¯ããããšäœ¿çšãã¿ãŒã³ã«é¢é£ä»ããããŠããŸãã ãŸããæçŽã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããã³ããŒããŠã§ã¢æ©èœã®æ§æã«é¢é£ããã¹ã¯ããŒã«é床ã§ããå ŽåããããŸãã
Sey Malevichã¯ãèµ€ãåè§ã®äžã«ã«ãŒãœã«ãåãããŠã¹ã¯ããŒã«ããããšãææ¡ããŠããŸãïŒãã¿ã³ãã¯ãªãã¯ããã ãã§æ©èœããå ŽåããããŸãïŒã ãã£ãŒãã«ããŒã¿ã衚瀺ããŸãã
圌ã®ããŒãžããã®ç¿»èš³ïŒ
ã»ãšãã©ã®ãã©ãŠã¶ïŒTorãå«ãïŒã®ããŠã¹ãã€ãŒã«ã¹ã¯ããŒã«ã€ãã³ãã¯ãã¹ã¯ããŒã«ãã«ã¿ã«é¢ããæ å ±ãæäŸããŸãã éåžžã®ããŠã¹ã®å Žåã¯3ã§ããããã©ãã¯ãããã䜿çšããå Žåããã«ã¿ã¯å¯å€ã§ããããã©ãã¯ããããšäœ¿çšãã¿ãŒã³ã«é¢é£ä»ããããŠããŸãã ãŸããæçŽã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããã³ããŒããŠã§ã¢æ©èœã®æ§æã«é¢é£ããã¹ã¯ããŒã«é床ã§ããå ŽåããããŸãã
1. BrowserLeaks ã ãŸããä»ã®ãã¹ããããããŒãžã®äžéšã«æ³šæãåŒããŸãã
2. UberCookie
SSLæå·åããã³ãFireFoxã®æŽæ°ãã«é¢é£ãããã®ä»¥å€ã¯ãã¹ãŠãåã®èšäºã®æé ãééããå¿ èŠããããŸãã æ£ããç解ããŠãã ãããç§ã¯PRèšäºã§ã¯ãªããèªåã®æ¹æ³ã§ããããŸãããäœãããåæ Œããªãã£ããå Žåãçãã¯ã©ããããããæ±ãããã ãã§ãã
ãªãŒã¯ããã¹ãããããã«ãIPããã³DNSã¯ä»¥äžãææ¡ããŸãïŒçç±-以äžã®ãã¡ã€ã«ãåç §ïŒ
1. DnsLeakTest ã 衚瀺ãå«ã ããã³ISP DNSã äžéšã®ãã¹ã¿ãŒã¯åœã®ã¿ã衚瀺ããŸããããã¯ããåãã®ãšãããCloudflareãæå·åãããªãŒã¯ãçºçããå Žåã¯MGTSã«ãªããŸãã
2. IpLeak.Net ã æ°ä»ãããªãããšããããããããŸãã ãã¬ã³ãããã¹ãã§ããŸãã ããã¯äž»ã«IPãšDNSã«ç¹åããŠããŸãããå°ãªããšãããçšåºŠã®ãªãŒã¯ãããã°ãæ¬ é¥ããªãããã§ãã
3. IpLeak.Com ã å æ¬çãªåæïŒE-Tagããã³Canvasãå«ãïŒã
4. WhatLeaks以åã¯ãTCPãCookieããã³ã¹ãã¬ãŒãžããªãŒãã³ããŒãããã©ãã¯ãªã¹ãå ã®IPã®ååšãªã©ã«ããOSã®ååçåæãªã©ã2ipããã³ãã«ãããŠããŸããã
5. IPã¹ã³ã¢ã IPäžæ£é²æ¢ã®æ€åº ã ãŸãã MaxMindããã³Ip2locationãžãªããŒã¿ããŒã¹ ïŒã¹ã€ããããŒãžã®äžéšïŒãå«ãŸããŠããŸãã
[å±¥æŽ]ãã¿ã³ã¯ãIPã¢ãã¬ã¹ããã®èšªåã®å šå±¥æŽã§ãïŒé·å¹Žã«ããã£ãŠååšããå¯èœæ§ããããŸãããIPã¯ãŸã åçã§ãããããè€æ°åååšããå¯èœæ§ããããŸãïŒ
ãšãããïŒ
-ã»ã¯ã·ã§ã³ãå®IPæ€åºããã»ã¯ã·ã§ã³ã®äžéšã«ãããã¿ã³ããã¯ããŒãã³ã°ãã¹ãã®å®è¡ã
-[ãã©ãã¯ãªã¹ã]ã»ã¯ã·ã§ã³ãäžéšã«ãã[衚瀺]ãã¿ã³ïŒç°ãªããã©ãã¯ãªã¹ããšé 眮ãããŠããIPã¢ãã¬ã¹ããããã·ãVPNã«ã¢ã¯ã»ã¹ããã®ã¯äžè¬çã§ãããIPããã®å Žåã¯ãäžéšã®ãªã¹ãã«æã ãããããããšããããŸãã誰ããäœãã§ã©ã€ãã¢ããããïŒ
-ã»ã¯ã·ã§ã³ããã©ãŠã¶æ å ±ãããã¿ã³ã衚瀺ãïŒãã©ã°ã€ã³ãšããããŒïŒ
6.ãããŠãç§ãã¡ã®ãã¹ãŠïŒ 2ipãšWhoer
æ£åœåã®æ£åœåïŒ
1.ç£ç£ãããHomakïŒæ³šæãLurkaïŒïŒãçªç¶ ã ãã¹ãŠã1æ¬ã®ããã«ã«éããŸãããããã€ãã®ããã«ãããã¯3ã¹ããŒãªãŒãš3ã¹ãããã§ãïŒããããç«ã¡åŸçã§ããå Žæã«ã€ããŠã¯ãããã©ãŠã¶ãïŒããåç §ããŠãã ããïŒ
2. ãã®èšäº ã ç§èŠã¯ç°¡æœã§ãã¢ã¯ã»ã¹ãããããç解ããããã®ã§ãç§ã¯ãŠãŒã¶ãŒãå«ãããã匷ããå§ãããŸãã
3. ãã©ãŠã¶ãŒã®å¿åèå¥ ïŒHabrïŒ
å°æ¬ãããHabrasocietyã«è¬çœªããŸãã 以äžã§ææ¡ããææ³ã®ããã€ãã¯ãç¹ã«éåžžã«è¥ã人ãã¡ã«ãã£ãŠãããã«æªãããšã«ãæããããå€ããŠãããã«åºç¯å²ã®ç®çã«äœ¿çšã§ãããšããäºå®ã®ããã«ïŒ
å
責äºé
1.ãããã®èšäºã§èª¬æãããŠãããã®ã¯ãã¹ãŠãããã€ãã®äžè¬çãªåé¡ãåé¿ããæ¹æ³ã«é¢ãããªãã·ã§ã³ãæäŸããããšãç®çãšããŠãããæ°ããåé¡ãæ€çŽ¢ããããšã¯æå³ããŠããŸããã
2.ã©ã¡ãããšããã°ããã®ãã¹ããŒãã«å¿åãã¹ã¯ãŸãã¯ç¹ã«ããŒããã¹ã¯ãå«ãŸããŠããªããšããäºå®ã«é¢ä¿ãªãããIPãã¹ããŒãã«å¿ããŠåã€ããšã¯ãããŸãããã
äžè¬çã«ãç§ãã¡ã¯ãžã§ãŒãæãŸããŸãã-ã圌ããšããã©ããã®ãªãéããšãã質åãžã®çãã¯ãžã§ãŒã¯èªäœã«å«ãŸããŠããŸãã
2.ã©ã¡ãããšããã°ããã®ãã¹ããŒãã«å¿åãã¹ã¯ãŸãã¯ç¹ã«ããŒããã¹ã¯ãå«ãŸããŠããªããšããäºå®ã«é¢ä¿ãªãããIPãã¹ããŒãã«å¿ããŠåã€ããšã¯ãããŸãããã
äžè¬çã«ãç§ãã¡ã¯ãžã§ãŒãæãŸããŸãã-ã圌ããšããã©ããã®ãªãéããšãã質åãžã®çãã¯ãžã§ãŒã¯èªäœã«å«ãŸããŠããŸãã
å°Ÿãã€ããïŒ IPããã©ãŠã¶ãOSãé ãå€ãã®åé¡ãèŠã€ãããŸãã
ãœãªã¥ãŒã·ã§ã³ã®äžè¬çãªææ¡-çµå±ããã¿ãã¬ã®äžã§-解決ããããã«èå³ã®ãªããœãªã¥ãŒã·ã§ã³ã§ãããå®çšçãªèŠ³ç¹ããã§ã¯ãããŸããã
ããŠãŒã¶ãŒãšãŒãžã§ã³ããã¹ã€ããã䜿çšããç¹åŸŽã®ãªããã©ãŠã¶ãŒã¿ã€ãïŒChromeãIEãªã©ïŒãæ¿å ¥ããŠOSãå€æŽãã 2ipããã³Whoerãµã€ãã§å¿åæ§ã䜿çšãã
Chrome-foxã®å°»å°Ÿããã®ããã«èª¿çãããŠããããšã«æ°ä»ãã®ã¯åžžã«å¯èœãšã¯éããŸãã
1.Fail 8ab3a24c55ad99f4e3a6e5c03cad9446ïŒFirefoxïŒ
IPãã§ãã¯
ã¯ããããã«ãJonDonymã«ãããšã
èå³ããã人ã®ããã«
http-headersãçºè¡ããé çªã§FãçŠãããããªãããã ãã®ãã¹ãã§javaãæå¹ã«ããå ŽåãTorãã©ãŠã¶ã«ãåãããšãåœãŠã¯ãŸããŸãïŒãã®ãããªã»ããã¢ããã®PHP å®è£
ãé¢æ°createHeaderSignatureé¢æ°ïŒ
次ã®ãªãã·ã§ã³ããå§ãããŸãã
1. Simple modify header addonãã€ã³ã¹ããŒã«ããŸã
2. Accept-LanguageããããŒãåé€ããŸã
çµæ-ç®ã«èŠããªãç£ã®çè·¡
ãããããæ·±å»ãªãå®çŸ©ã§ã¯ã次ã®ããã«ãªããŸãã
次ã®ãªãã·ã§ã³ããå§ãããŸãã
1. Simple modify header addonãã€ã³ã¹ããŒã«ããŸã
2. Accept-LanguageããããŒãåé€ããŸã
çµæ-ç®ã«èŠããªãç£ã®çè·¡
ãããããæ·±å»ãªãå®çŸ©ã§ã¯ã次ã®ããã«ãªããŸãã
2.倱æ-ã¿ããããããã¯ãªãã¯ããŠããŠã¹ãã¿ãã
ãŠãŒã¶ãŒãšãŒãžã§ã³ãããã¹ã¯ãããããã¢ãã€ã«ã«ããŸãã¯ãã®éã®ã¿ãã-ããŠã¹æ€åºã«å€æŽããããšã«é¢ããŠã¯ã誰ãããã§ã«ååããæšæž¬ããŠãããšæããŸããçµæã¯ããŸã£ããéã§ããã¹ãã§ãã
èå³ããã人ã®ããã«
F12ã«ãã£ãŠåŒã³åºãããæšæºã®FirefoxããŒã«ã¯ ãé©å¿èšèšã¢ãŒããã
ïŒããã«ã¿ããã¹ã¯ãªãŒã³ã®ååšãã·ãã¥ã¬ãŒãããã¢ãã€ã«ãŠãŒã¶ãŒãšãŒãžã§ã³ããè¿œå ã§ããŸãïŒ
ããããããã¯ã¢ããªãã£ã®åé¡ã解決ããŸãã-éæ¢ããã³ã³ãã¥ãŒã¿ãŒã¯ãå é床èšããžã£ã€ãã¹ã³ãŒããããã³ãã®ä»ã®ç¹åŸŽçãªå å¡«ããªããå€éšããã®ã¢ã¯ã»ã¹ããŸã å¯èœã§ãããæºåž¯é»è©±ã®äžéšã¯ã¯ãã ããŠã«ãã£ãŠã®ã¿ãªãã«ãªããŸãã ããããããã¡ããã確èªã§ããŸãã
ïŒããã«ã¿ããã¹ã¯ãªãŒã³ã®ååšãã·ãã¥ã¬ãŒãããã¢ãã€ã«ãŠãŒã¶ãŒãšãŒãžã§ã³ããè¿œå ã§ããŸãïŒ
ããããããã¯ã¢ããªãã£ã®åé¡ã解決ããŸãã-éæ¢ããã³ã³ãã¥ãŒã¿ãŒã¯ãå é床èšããžã£ã€ãã¹ã³ãŒããããã³ãã®ä»ã®ç¹åŸŽçãªå å¡«ããªããå€éšããã®ã¢ã¯ã»ã¹ããŸã å¯èœã§ãããæºåž¯é»è©±ã®äžéšã¯ã¯ãã ããŠã«ãã£ãŠã®ã¿ãªãã«ãªããŸãã ããããããã¡ããã確èªã§ããŸãã
3. p0fã«å€±æãã
OSã¯ããã®ããŒãžã§ã³ãå«ããFoxã§ã¯ãªããTCP \ IP OSèšå®ã«ãã£ãŠæäŸãããŸãã ããã¯ããµã€ãïŒp0fããã³nmapãå«ãïŒã§ãªãã¹ã³ããŠããã¹ããã¡ãŒã«ãã£ãŠãã£ãããããŸãã
èå³ããã人ã®ããã«
Windowsãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãããã¯ãŒã¯ãèªåçã«æé©åããããã«äœ¿çšãããTCPOptimizer管çãŠãŒãã£ãªãã£ããããŸãã
çè«çã«ã¯ããã®å©ããåããŠèšå®ãã«ã¹ã¿ãã€ãºã§ããŸããå®éã«ã¯ãæ§æ¹åŒã䜿çšãããšãWindowsã足ã§æã€ããšãã§ããŸãã®ã§ããã®å®éšããå§ãããŸãããå°ãªããšã以åã®å®éšã¯ãã®ãããªçµæã¯ãããŸããã ã¯ããWindows7/10ã®ããŒãžã§ã³å ãé€ããOSãWindowsããLinuxã«å€æŽããããšã¯æåãããã«ãããŸããã
確ãã«ã以åã¯åŸ©æ§ãã€ã³ããäœæããã¹ã©ã€ããŒã§ã€ã³ã¿ãŒãããé床ã瀺ãããæé©ãªãã¢ãŒããéžæããŠããããã¯ãŒã¯ã®æé©åãè©Šã¿ãããšãã§ããŸãã ãã®æç¹ãŸã§ã倱æããŠããªãããã§ãã
çè«çã«ã¯ããã®å©ããåããŠèšå®ãã«ã¹ã¿ãã€ãºã§ããŸããå®éã«ã¯ãæ§æ¹åŒã䜿çšãããšãWindowsã足ã§æã€ããšãã§ããŸãã®ã§ããã®å®éšããå§ãããŸãããå°ãªããšã以åã®å®éšã¯ãã®ãããªçµæã¯ãããŸããã ã¯ããWindows7/10ã®ããŒãžã§ã³å ãé€ããOSãWindowsããLinuxã«å€æŽããããšã¯æåãããã«ãããŸããã
確ãã«ã以åã¯åŸ©æ§ãã€ã³ããäœæããã¹ã©ã€ããŒã§ã€ã³ã¿ãŒãããé床ã瀺ãããæé©ãªãã¢ãŒããéžæããŠããããã¯ãŒã¯ã®æé©åãè©Šã¿ãããšãã§ããŸãã ãã®æç¹ãŸã§ã倱æããŠããªãããã§ãã
4.å°å·ã§å€±æãã
ãããã远跡ããããã«ãç°ãªãæç¹ã§ã¿ã€ãã®ç°ãªãæçŽãæ¯èŒããé©åãªçœ®æãè¡ããšã12å·»ã®ãåç©ãšé³¥ã®çè·¡ãããã¥ãŒã©ã«ãããã¯ãŒã¯ã§æ€çŽ¢ããååž°ã«é¥ããã¢ã¹ãã©ã«ãã¬ãŒã³ã«èœã¡ãŸãã ãããŠãããã«ãæå®ããããŠãŒã¶ãŒãšãŒãžã§ã³ããšç¹å®ã®ãŠãŒã¶ãŒãšãŒãžã§ã³ãã®åç §ãã£ã³ã¬ãŒããªã³ããšã®æ¯èŒããããŸã-ããã§ãã誰ãããã§ã«ç解ããŠãããšæããŸãã ãã©ãŠã¶ãŒãšOSïŒ+å ·äœçã«ã¯ãããŒããŠã§ã¢ãïŒã¯ãå€æãããšãããç°ãªããŸãŸã§ãã
5. WebRTCãŸãã¯ããã«ã¡ã¯
uBlock OriginãPrivacy Badgerãã€ã³ã¹ããŒã«ãããšãIPãªãŒã¯ã®åé¡ã¯éæ³ã®ããã«æ¶ããŸãã ã©ã¡ããäžæ¹ã ãããããŸããŸãããã¢ãªã³ã°ããªãã«ããŸããããç©Žãä¿®æ£ããŸãã äžèšã®æ€èšŒãµã€ãã§ã¯çæ³çãªç¶æ³ã«ãªããŸãããVPNãããã€ããŒãDNSLeaksããããã¯ããŠããŠããç®ã«èŠããªãããšããããŠææªãªããšã«ãVPNã«åãæ¿ããåŸã«DNSãªãŒã¯ã®ããç®ç«ããªããã¡ã€ã«ãåžžã«ååšãããšã¯éããŸããã ããã§ãããã-ãããå®å šã«ç¡å¹ã«ããŸãã
6.ä»ã®ããã€ãã¯æ確ã«ããããã«å€±æããŸã
ïŒVPNãžã®çªç¶ã®åãæ¿ãïŒ
ïŒæ»æã®ããã«éããŠããããŒãïŒ
ç¥è©±ã®çè«ã倱æãã
æ³åŸã§çŠæ¢ãããŠãããã®ãããããã§ã¯ãããŸããããç¥çµè³ªã«ãªã£ãŠããŸãããå¿åãã©ããã確èªããæ¹æ³ã¯å¿ ãããæ確ã§ã¯ãããŸããã
ãªãã¡ãŒãæäŸããŸã
ãŠãŒã¶ãŒãšãŒãžã§ã³ãã«é¢é£ãããã¹ãŠã¯ãåã®èšäºã§ææ¡ãããå¶éå ã§ã®ã¿å€æŽãããã«ã¡ã¬ãªã³ãè£è¶³ããŸãã
䜿çšãããŠããªãå Žåã¯IPv6ãç¡å¹ã«ããŸã ãããã¯ã»ãšãã©ã®å ŽåïŒæ瀺ã®ããã«wi-fiã®ä»£ããã«ã€ãŒãµããããååšããã¹ããŒã¿ã¹ããæ¥ç¶æžã¿ãã§ããå¯èœæ§ãé«ãïŒã åãå Žæã§ãåæã«ãQoSïŒèªå® ã§äœ¿çšãããŠããªãã¢ã©ãŒãé ä¿¡ãµãŒãã¹ïŒãç¡å¹ã«ããããšãã§ããŸã
DNSãªãã¡ãŒ
ã·ã³ãã«DNSCryptãã€ã³ã¹ããŒã«ãã
詳现ã«ã€ããŠã¯ã ãã¡ããã芧ãã ãã ã ç¹ã«äœããæ©èœããŠããªãå Žåã åèµ·åããŸãã
ãæ¡åŒµãã¹ãããã¿ã³ãã¯ãªãã¯ããŠã DnsLeakTestããã¹ãããŸãã
ã«ã¹ã¿ãã€ãºãã
åžžã«ãã¬ã€ã«è¡šç€ºããã«ã¯-äžç·ä»ãã®ãã§ãã¯ããŒã¯ã2ã€ä»ããããšãã§ããŸãã
1.ãã¡ã€ã³ãã¿ã ïŒRussificationã®æ¹ã幞éãããããŸããïŒ
ãæ§æã-DNSãµãŒããŒã®ãã£ã«ã¿ãªã³ã°ïŒ2çªç®ã®ã¿ããåç §ïŒã
ãµãŒãã¹ãæå¹ã«ãããããã¯ãŒã¯ã«ãŒãã確èªããŠã[é©çš]ãã¯ãªãã¯ããå¿ èŠããããŸãã
2. [ãªãŸã«ããŒ]ã¿ã
èªåã¢ãŒãããªãã«ããããšãææ¡ããŸãã ãªã¹ãã«ã€ã³ã¹ããŒã«ãããŠãããã¹ãŠã®ãµãŒããŒããªã¹ãããåé€ããCloudflareã1ã€ã ãæ®ããŸãã
ã¯ããããã¯ãåçšãã§ãããæåã®ã¿ãã§ã¯ãã°ãªãã§å ¬éãããŸããã ãããŠãGoogleã¯ãã®ãªã¹ãã«èŒã£ãŠããŸããã
ä»ã®äººã«ãããããããšã¯å§ããŸããã
第äžã«ããã¹ãŠãæå·åãããŠããããã§ã¯ãªãããã¹ãŠããæŒãã®ãªããããã§ã¯ãããŸããã 第äºã«ããããã©ã®ãããªDNSã§ããããæ確ã§ã¯ãããŸããïŒãã¡ãããã€ã³ã¿ãŒãããäžã«ã¯æ å ±ããããŸãïŒã 第äžã«ãããã¯èšèã®æå³ã§ãå ¬å ±ãã§ãã å€ãã®åœã§ãã¹ãŠã®åœã§äœ¿çšãããŠãããIPã®åœãDNSãšäžèŽããŠããªããŠãCloudflareã§ããããšã瀺ããŠããŠããåé¡ã¯ãããŸããã ãã1ã€èšãã°ãåãçç±ã§ãIMHOã¯ããã ãã®äŸ¡å€ã¯ãããŸãããããã°ã©ã ã¯ãã¹ãŠã®ç¬éã«æéã®ãã®ãéžæãããªãŒã¯ãçªç¶çŸããŠãã®ãããªãã®ã«ãªããããããŸããã
3.詳现èšå®ã¿ã
ããã¯ã¢ãããªãŸã«ããŒ8.26.56.26ã®IPã¢ãã¬ã¹ãæšå¥šããŸãïŒããã¯Comodo Secure DNSã§ã ïŒ
4.ããã°ãã¿ã -ãã®ã³ã°ãç¡å¹ã«ããŸã ã
ããã¯ããã¹ãŠã®ããã°ã©ã ãå«ãã·ã¹ãã å šäœã«é©çšãããŸãã FireFoxã®å Žåãå¿ å®åºŠã®ããã«ããèšå®ããããšãã§ããŸã ã
åžžã«ãã¬ã€ã«è¡šç€ºããã«ã¯-äžç·ä»ãã®ãã§ãã¯ããŒã¯ã2ã€ä»ããããšãã§ããŸãã
1.ãã¡ã€ã³ãã¿ã ïŒRussificationã®æ¹ã幞éãããããŸããïŒ
ãæ§æã-DNSãµãŒããŒã®ãã£ã«ã¿ãªã³ã°ïŒ2çªç®ã®ã¿ããåç §ïŒã
ãµãŒãã¹ãæå¹ã«ãããããã¯ãŒã¯ã«ãŒãã確èªããŠã[é©çš]ãã¯ãªãã¯ããå¿ èŠããããŸãã
2. [ãªãŸã«ããŒ]ã¿ã
èªåã¢ãŒãããªãã«ããããšãææ¡ããŸãã ãªã¹ãã«ã€ã³ã¹ããŒã«ãããŠãããã¹ãŠã®ãµãŒããŒããªã¹ãããåé€ããCloudflareã1ã€ã ãæ®ããŸãã
ã¯ããããã¯ãåçšãã§ãããæåã®ã¿ãã§ã¯ãã°ãªãã§å ¬éãããŸããã ãããŠãGoogleã¯ãã®ãªã¹ãã«èŒã£ãŠããŸããã
ä»ã®äººã«ãããããããšã¯å§ããŸããã
第äžã«ããã¹ãŠãæå·åãããŠããããã§ã¯ãªãããã¹ãŠããæŒãã®ãªããããã§ã¯ãããŸããã 第äºã«ããããã©ã®ãããªDNSã§ããããæ確ã§ã¯ãããŸããïŒãã¡ãããã€ã³ã¿ãŒãããäžã«ã¯æ å ±ããããŸãïŒã 第äžã«ãããã¯èšèã®æå³ã§ãå ¬å ±ãã§ãã å€ãã®åœã§ãã¹ãŠã®åœã§äœ¿çšãããŠãããIPã®åœãDNSãšäžèŽããŠããªããŠãCloudflareã§ããããšã瀺ããŠããŠããåé¡ã¯ãããŸããã ãã1ã€èšãã°ãåãçç±ã§ãIMHOã¯ããã ãã®äŸ¡å€ã¯ãããŸãããããã°ã©ã ã¯ãã¹ãŠã®ç¬éã«æéã®ãã®ãéžæãããªãŒã¯ãçªç¶çŸããŠãã®ãããªãã®ã«ãªããããããŸããã
3.詳现èšå®ã¿ã
ããã¯ã¢ãããªãŸã«ããŒ8.26.56.26ã®IPã¢ãã¬ã¹ãæšå¥šããŸãïŒããã¯Comodo Secure DNSã§ã ïŒ
4.ããã°ãã¿ã -ãã®ã³ã°ãç¡å¹ã«ããŸã ã
ããã¯ããã¹ãŠã®ããã°ã©ã ãå«ãã·ã¹ãã å šäœã«é©çšãããŸãã FireFoxã®å Žåãå¿ å®åºŠã®ããã«ããèšå®ããããšãã§ããŸã ã
詳现ã«ã€ããŠã¯ã ãã¡ããã芧ãã ãã ã ç¹ã«äœããæ©èœããŠããªãå Žåã åèµ·åããŸãã
ãæ¡åŒµãã¹ãããã¿ã³ãã¯ãªãã¯ããŠã DnsLeakTestããã¹ãããŸãã
çµæã¯æ¬¡ã®ããã«ãªããŸã
ã泚æ ãµãŒããŒã¯ãCloudflareã®æå±ã瀺ããä»ã®ãµã€ãã§ã¯ãå€ãã®å ŽåãIPãšãã®ãåžæ°æš©ãã®ã¿ã瀺ããŸãã ãããŠããããããã¹ãŠããã·ã¢é£éŠã«ãªãã§ãããã , DNS â Cloudflare , , .
, , 2ip . 次ã®ããã«ãªããŸãã
( (. ), â + + IP).
ã泚æ ãµãŒããŒã¯ãCloudflareã®æå±ã瀺ããä»ã®ãµã€ãã§ã¯ãå€ãã®å ŽåãIPãšãã®ãåžæ°æš©ãã®ã¿ã瀺ããŸãã ãããŠããããããã¹ãŠããã·ã¢é£éŠã«ãªãã§ãããã , DNS â Cloudflare , , .
, , 2ip . 次ã®ããã«ãªããŸãã
( (. ), â + + IP).
VPN
1. VPN â Chameleon .
2. VPN- , .. (. ) . ã€ãŸã , «» â «».
10 â WindScribe , . , ( , 10 , â 2, â . ).
. , IP :
1. DnsLeakTest
2. IpLeak
3. WhatLeaks
4. 2ip .ru Whoer
泚æïŒ ( , , )
, . .. â VPN (. cookies). () . , «WindScribe». . â .
() ! + , IP- VPN.
2. VPN- , .. (. ) . ã€ãŸã , «» â «».
10 â WindScribe , . , ( , 10 , â 2, â . ).
1. ( FireFox ), . (, , !)
â «Automatic» , . , , .. IP
â â ,
â « Secure.Link» â - ,
2.
â « » â , , , â ().
â « » â . , ( ), , .
â VPN. , Chameleon "+1".
â «Automatic» , . , , .. IP
â â ,
â « Secure.Link» â - ,
2.
â « » â , , , â ().
â « » â . , ( ), , .
â VPN. , Chameleon "+1".
. , IP :
1. DnsLeakTest
2. IpLeak
3. WhatLeaks
4. 2ip .ru Whoer
10
泚æïŒ ( , , )
, . .. â VPN (. cookies). () . , «WindScribe». . â .
() ! + , IP- VPN.
1. ( « », « » .. â , )
2. : ( , ) Windows ( - , . ). «» « Ipv6» .
3. + , Double VPN
4. 10 , \ . , «»
2. : ( , ) Windows ( - , . ). «» « Ipv6» .
3. + , Double VPN
4. 10 , \ . , «»
1.èšå®ïŒ
çä¿¡æ¥ç¶ãçŠæ¢-ããã¯ãæå·åãããŠããªãçä¿¡ã®çŠæ¢ã§ããé床ã¯å€å°äœäžããŸãããããã§ã¯éžæããŸãã
2.ãã¹ãïŒVPNããªã³ã«ããåŸïŒïŒ
IpLeak
ç£æ°ãªã³ã¯ãååŸãããã¬ã³ãã¯ã©ã€ã¢ã³ãã«è²Œãä»ããŸãããµã€ãã«VPN IPã¢ãã¬ã¹ã衚瀺ãããŸãã
çä¿¡æ¥ç¶ãçŠæ¢-ããã¯ãæå·åãããŠããªãçä¿¡ã®çŠæ¢ã§ããé床ã¯å€å°äœäžããŸãããããã§ã¯éžæããŸãã
2.ãã¹ãïŒVPNããªã³ã«ããåŸïŒïŒ
IpLeak
ç£æ°ãªã³ã¯ãååŸãããã¬ã³ãã¯ã©ã€ã¢ã³ãã«è²Œãä»ããŸãããµã€ãã«VPN IPã¢ãã¬ã¹ã衚瀺ãããŸãã
èšäºãæžããšãã«æã«å ¥ããå€ãã®äºå®ïŒ
1.誰ããç¥ããªãå ŽåïŒç§ã¯æåŸã®ç¬éãŸã§ç¥ããŸããã§ããïŒ-FireFoxãããã¿ã€ãã¯ãããã§ã¯ãªããå°ããªïŒèµ€ïŒãã³ãã§ããã¢ããªã³ã«ã¯ãã©ã€ããŒãã¢ãã°ããããã«å€ãã®ãã©ã€ããŒããããµã ããã®ä»ã®ããããããããããããã¯èå³æ·±ã
2. Googleã§ãwhere I amããšå ¥åãããšãå ŽæïŒWi-Fiããªãå Žåã¯IPã§ã°ãããŠèšç®ãããŸãïŒããšãªã¢ã®åçãã€ã³ããã¯ã¹ïŒedblockerãã¬ãŒã ãåãåãããŠããªãå ŽåïŒã衚瀺ãããŸãã Yandexã¯ãããè¡ããŸãããã³ãŒã¹ã§ã¯ããã·ã¢é£éŠã§ã¯ãããä¿®èŸçãªè³ªåã§ããããšãããããŸããæã®èšç»ã¯åœ¹ã«ç«ããªãã®ã§ãYandex.Taxiã
3.åºåYandexã®åæã®ãããã¯ã«ã€ããŠã¯ããã¹ããŸãã¯uBlockãä»ããã©ã³ãã©ãŒã®çŠæ¢ãŸã§ãã€ã³ã¿ãŒãããäžã§å€æ°ã®ãªãã¡ãŒããããŸããç§ã«ç¥ãããŠããæ¹æ³ã®äžã§æãå°é£ã§ãã¯ã¬ã¹ããŒ-ãããäºæ³ãããæ€çŽ¢çµæãªã©ãä»ã®ãã¹ãŠããããã³ã°ãããå¯èœæ§ããããŸãããããããã®åŸãCookieãä¿åããå¿ èŠãããããã®åŸã«ç¶ããŸãã
4.ããŸããŸãªæ€çŽ¢ãšã³ãžã³ã®é ãããæ©èœã§ãæã«ã¯ãªãªãžãã«ã®æ©èœãåããŠããŸãïŒäœããã®çç±ã§Malwarebytesããããã¯ãããµã€ãã¯å®å šã§ãïŒïŒDuckDuckGoãYandexãGoogle
5 ããããã¯ãŒã¯ã
6. FireFoxã«ã¯ã¢ãã¿ãŒãµãŒãã¹ããããŸãïŒHabrã«é¢ããèšäºïŒé»åã¡ãŒã«ã¢ãã¬ã¹ã䟵害ãããŠããïŒãããã³ã°ãããŠããïŒãã©ããã調ã¹ãããšãã§ããŸãããããã瀟äŒã§åãå Žåã«åœ¹ç«ã€å¯èœæ§ããããŸããç¹ã«ãéã®ããã«èª°ããæäŸãããããã¯ãŒã¯ãããŒã¿ããŒã¹å ã®åœŒã®ã¡ãŒã«ãç¹ç¯ããå Žå-圌ã¯æä»çãªæè ã§ãã£ããããããªãè©æ¬ºã®ããã«èªåèªèº«ããããã³ã°ããŸããã
7.ãããã¯ãŒã¯ã«ã¯ããããã¯ãŒã¯å ã®Webãµã€ãTrustããããŸãããŠãŒã¶ãŒãç解ã§ãã圢åŒã§ãINFAãçºè¡ãããŸãããµã€ãã«ã€ããŠãå«ã-ãã¡ã€ã³å¹Žéœ¢ïŒæ¥æ°ïŒ+ Yandexããã³Googleã«ããããã åæ+ WOTãµãŒãã¹ã«ããåæ+ãŠãŒã¶ãŒã³ã¡ã³ãã
ããšãã°ãFireFoxã«ã¯ãå®å šã«ç¡æã®ããŒãºãçŽæããè¿œå æ©èœããããŸãããããŠã圌ã«é¢ããããŸããŸãªã¬ãã¥ãŒã確èªããŠãã ãããè©æ¬ºã«å ããŠã欧å·é£åããã³250æ¥ã®å¹Žéœ¢ããããŸãã
8.ãªãã·ã§ã³ãšããŠããµãŒãã¹ãflagfoxãã¿ã³ã«æãããšäŸ¿å©ã§ãïŒèšå®ã§ããŠã§ããµã€ãã¢ã€ã³ã³ãåä¿¡ããããç¡å¹ã«ããå¿ èŠãããã ãã§ããããããªããšãæ¯åãã¡ãã³ã³ãããŠã³ããŒãããŸãïŒã
Habrããã®ãœãŒã¹
1. ãããã¯ãŒã¯äžã®å¿åã®æ¹æ³ããã ãè€éãªçŽ
2 粟床ã§æçŽç¹å®ã®PC 99.24ããŒã»ã³ãã¯ãã䜿ãã®ãã©ãŠã¶ã«å€æŽããŠãä¿åãããŸãã
ã3. åæãã©ãã£ãã¯ãèå¥ããããã«ããã·ããã£ã³ã¬ãŒããªã³ãã
4ãããããããäœæããããã«ããµãŒãã¹åŽåè ã䜿çšãã
5. ãã§ãã¯ãªã¹ãå¿åãã§ãã¯ãµãŒãã£ã³ã