ãã€ã±ã«ïŒç§ã¯ãã€ã±ã«ã»ã©ã€ã§ããããã¯ãã·ã¥ãŒã»ãªãã£ãŒãã§ããããããŸãã¯ãªãã£ãŒããšåŒã¶ããšãã§ããŸãã圌ã«ã¯2ã€ã®ååããããŸãããåé¡ã§ã¯ãããŸããã
MattïŒä»æ¥ã®äŒè©±ã®ãããã¯ã¯ãã«ãŠã§ã¢ã®malwareç¬ã§ããããŸãã«ãããç§ãã¡ãããããšããŠããããšã§ãã
ãã®ãããã³ãŒããäœæãããã¹ãŠã®äººãããŸããããšã¯éããã人ã
ã¯å€ãã®ééããç¯ããŸãã ãããŠããŠã€ã«ã¹ã䜿çšãããã¹ãŠã®äººããããæ£ããè¡ãããã§ã¯ãããŸããã ãããã®äž¡æ¹ã®ã±ãŒã¹ã§å€±æãã人ãããŸãã ããã§ãããå¿«é©ã«åº§ã£ãŠããªã©ãã¯ã¹ããŠèããŠãã ãããããããããã®æ
å ±ã¯ããªãã«ãšã£ãŠåœ¹ã«ç«ã€ã§ãããã
念ã®ããããã¬ãŒã³ããŒã·ã§ã³ã«äºå®äžã®æè¡è³æãå«ããã®ã§ãäŒè©±ãé¢çœããªãããã§ããã°å°ãªããšãäœããåŠã¶ããšãã§ããŸãã ããã¯åãªãæèŠã§ãããéçšäž»ã®æèŠãšäžèŽããªãå Žåãããããšã«æ³šæããŠãã ããã
ãã€ã±ã«ïŒæåã®è©±ã¯ããããŒããšã³ããããŒãæžãããïŒã 圌女ã¯ãéåžžã«è€éãªæå·åã¢ã«ãŽãªãºã ã§ããSilent Bankerã®äœè
ããPRNGïŒæ¬äŒŒä¹±æ°ãžã§ãã¬ãŒã¿ãŒïŒã䜿çšããŠãšã³ããããŒãäœæããã®ãå¿ããããšã«ã€ããŠèªã£ãŠããŸãã ã¹ã©ã€ãã«ã¯ãPRNGã䜿çšããŠããã·ã¥ããŒã¹ã®æ€åºãé²ã2007幎9æã®Zeusã³ãŒãã¹ããããããããŸãã çæã¯ãddTickCountãšåŒã°ãããã®ã°ããŒãã«å€æ°ãéå§ããããšã§æ§æãããŸããæåã«ãé¢æ°ãæåã«åŒã³åºãããå ŽæããEAXã¬ãžã¹ã¿ã«é
眮ãããŸãã 次ã«ãé¢æ°ã®å€ããŒãã«çãããã©ããããã§ãã¯ããçãããªãå Žåã¯ãGetTickCountã³ãã³ãã䜿çšããŠTickCountãåŒã³åºããŠSEEDãçæããŸããã€ãŸããç䌌乱æ°ãéå§ããŸãã
2008幎2æ以éã®Silent Bankerãã€ããªãã¡ã€ã«ã«ãã®ã³ãŒããšã®é¡äŒŒç¹ãèŠããããšããç§ãã¡ã¯é©ããŸããã§ããã PRNGã䜿çšããŠäžæãã¡ã€ã«åãçæããŸãã ããã«ã¯ããŒãããããã©ããã確èªããåãã°ããŒãã«å€æ°ddTickCountããããŸãããŒããããå Žåã¯ãGetTickCountã䜿çšããŠæ¬äŒŒä¹±æ°ãéå§ãããŸãã æåã«ãmsvsrt randïŒMicrosoft C Runtime Windowsã©ã€ãã©ãªã®randïŒïŒé¢æ°ã§äœ¿çšãããæ¬äŒŒä¹±æ°ãžã§ãã¬ãŒã¿ãŒïŒãèŠãåã«ããã€ããªã«ããŒãã³ãŒãã£ã³ã°ãããHEXçªå·ã«ã®ã¿åºã¥ããŠãZeusã®äœæè
ãšSilent Bankerã®äœæè
ã®éã«æ¥ç¶ããããšæããŸããã ãããå®éã«ã¯ãã©ã¡ããmsvsrtã«éçã«ãªã³ã¯ãããŠããŸãã
ä»ãç§ãã¡ã¯çœå®³ã®ã¬ã·ãã«çããŸãã ããã¯ã2æããŒãžã§ã³ã®æ°ãæåŸã«ãªãªãŒã¹ãããã2008幎7æã®ãµã€ã¬ã³ããã³ã«ãŒããŒãžã§ã³ããã®ã³ãŒãã¹ããããã§ãã
圌ãã¯ã³ãŒããæŽæ°ããSilent Bankerã®æ°ããããŒãžã§ã³ãæçš¿ããŸããããããã¯ä»¥åèŠããã®ãšã¯å€§ããç°ãªããŸããã ãã®ããã°ã©ã ã§ã¯ãPRNGã䜿çšããŠæå·åããŒãçæããŸãã ããã§ãCurrentSeedãšããã°ããŒãã«å€æ°ããŒãã«çãããã©ããããã§ãã¯ãããããã«å¿ããŠæ¬äŒŒä¹±æ°ãçæãããããšã¯ããããããŸãããããã¯åã«ãã®ã³ãŒãã§äœ¿çšãããŸãã
ãã€ããªãã¡ã€ã«ã®ã©ããã§ããã®å Žæã®åã§ããããã®ã°ããŒãã«å€æ°ã®å€ãäœããã®ã¿ã€ãã®æ°å€ã®åœ¢åŒã§çæãããå¯èœæ§ããããŸãã ãããã£ãŠããã®ã³ãŒããéã¢ã»ã³ãã«ããŠãCurrentSeedå€ããã®randïŒïŒé¢æ°ã§äœ¿çšãããåã«ãããã°ã©ã ã§ä»ã®å Žæã§äœ¿çšãããŠãããã©ããã確èªããŸãã æåã¯ddããŒãããå§ãŸãããšãããããŸãããã®å€æ°ãžã®çžäºåç
§ã確èªããŸãã
åTã®å€wã¯ããã€ããªãã¡ã€ã«å
šäœã§ãã®ã°ããŒãã«å€æ°ã«å¯ŸããŠæå¹ãªæäœã1ã€ã ãã§ããããšãæå³ããŸããããã¯randé¢æ°ãã®ãã®ã§ãã ãããã¯æšå¹Žã®DefConã§æ¢ã«èšåãããŠããã®ã§ãæµoverã«æ€èšããŸãã ãRecipe for Disasterãã¹ã©ã€ãã®ãSeed the PRNGããŸãã¯ãInitiating a Pseudo Random Number Generatorãã¯ããµã€ã¬ã³ããã³ã«ãŒã®äœæè
ããã®éå§ãè¡ããªãã£ãããšã瀺ãç°è²ã§è¡šç€ºãããŠããŸãã
次ã®ã¹ãããã¯ã16ãã€ãã®ããŒãçæããMyRandïŒïŒé¢æ°ã1000åã·ã¹ãã ã³ãŒã«ããããšã§ãã 次ã«ã16ãã€ãã®ããŒãããç¹å®ã®åŒã䜿çšããŠ8ãã€ãã®æ°å€ïŒããŒïŒãçæããŸãã
ãã®åŸãå¥ã®8ãã€ãæ°ãçæããŠæåã®8ãã€ãæ°ãã2次ããŒãäœæããINIæ§æãã¡ã€ã«ããä»»æã®å€ãè¿œå ããŠã3次ããŒïŒ8ãã€ãæ°ïŒãååŸããŸãã æåŸã«ãä»»æã®ç²ŸåºŠã®æ°åŠé¢æ°ã䜿çšããŠã8ãã€ãããŒã32ãã€ãããŒã«å€æããŸãã
ãã®åŸãå
ã®16ãã€ãããŒã䜿çšããŠããŠãŒã¶ãŒã®ãã¹ã¯ãŒããªã©ã®çãŸããããŒã¿ãæå·åããŸãã ããããæå·åãããã¡ãã»ãŒãžãšäžç·ã«ããŒãéä¿¡ããã®ã¯åŸçã§ã¯ãªããããçãŸããããŒã¿ãšãšãã«ãã®16ãã€ãã®æ°åãã圌ãã®ãæ»æè
ã«æž¡ããŸããã 代ããã«ãSilent Bankerã®äœæè
ã¯ãçãŸããããŒã¿å
ã«32ãã€ãã®æ°åãå
¥ããŠããã®æ°åã16ãã€ãã®å
ã®ããŒã«å€æããããã°ã©ã ãå¿
èŠãªåä¿¡è
ã«éä¿¡ããŸãã ãã ãããã®ããã°ã©ã ã¯ãããŸããïŒ
次ã®ã¹ã©ã€ãã¯ããã®çœå®³ããã³ããŒ1ã§äœ¿çšããæ¹æ³ïŒPRNGãžã§ãã¬ãŒã¿ãŒã®æ¬ åŠïŒã®ã¬ã·ãã瀺ããŠããŸãã
ãŸããPRNGã®å€ããŒãã«çããããŸãã 16ãã€ãããŒã8ãã€ãããŒã次ã®8ãã€ãããŒãããã³32ãã€ãããŒãèšç®ããæ°åŒãããããããããã¬ãŒçšã®Pythonã¹ã¯ãªããã䜿çšããŠæ¬¡ã®4ã€ã®ã¹ããããèªååã§ããŸãã ãã®åŒã¯Cã³ãŒãã«ã¯ãããŸãããããããååšããSilent Bankerãã€ããªãã¡ã€ã«ã®ã³ããŒãããããããã®åŒããããŸãã
ãã®Pythonã¹ã¯ãªããã®ä»çµã¿ã®ãã¢ã玹ä»ããŸãã è¯ãã·ããªãªããããŸããããã«ã¯ããµã€ã¬ã³ããã³ã«ãŒãšãã¢ã¿ãããããŠããç¬ç«ãããããã¬ãŒãããã³ãµã€ã¬ã³ããã³ã«ãŒãå®è¡ãããŠããInternet ExplorerããããŸãã æå·åããŒãçæãã4ã€ã®æ©èœã«æ³šç®ããŸããã åã®ã¹ã©ã€ãã«ç€ºãããã®Pythonã¹ã¯ãªãããæ¥ç¶ããŠããŸããããã¯bang keygenã³ãã³ãã§åŒã³åºããŸãã ãããã¬ãŒã¯ããã®ãã¢ã§å®è¡ããããããã®ããã€ãã®æ©èœã5ååçŽã«ã倱ããããšãããããŸãã ãããå®éã«ã¯ããã®ã¢ã¯ã·ã§ã³ã5,000åå®è¡ããŠããã倧ããªããŒã»ãããååŸããŸããã
ãã°ããã«ã§ã¯ãã«ãŒãã®åå埩ã§16ãã€ãã®ãã©ã€ããªããŒã衚瀺ããã32ãã€ãã®ããŒã«é¢é£ä»ããããŠããããšãããããŸãã ã¹ã¯ãªããããã°ã«æ
å ±ãåºåãããšåæã«ã16ããã³32ãã€ãã®é¢é£ããŒã®ãã¢ãå«ãããã¹ããã¡ã€ã«ããã£ã¹ã¯äžã«äœæãããŸãã ããã¯16é²æ°ã®16é²æ°ãã¡ã€ã«ã§ãããããPythonã¹ã¯ãªããã䜿çšããŠãã®ãã¡ã€ã«ãåŠçã§ããŸãããŸããçãŸããã³ãã³ãã¢ã³ãã³ã³ãããŒã«ããŒãããå埩ãããã°ãã£ã¬ã¯ããªããããŸãã
äžéšã«ã¯æå·åãããç§å¯ããŒã®èšŒææžãããã€ã衚瀺ããããã®äžã«ã¯æå·åãããããŒã¿ãå«ãããã€ãã®ããã¹ããã¡ã€ã«ããããŸãã ãã®32ãã€ãã®ããŒãšããã«é¢é£ä»ããããŠãã16ãã€ãã®å
ã®ããŒãæœåºããããšã«ãããããã°ã©ã ãå®è¡ãããããã®ããã¹ããã¡ã€ã«å
ãæ€çŽ¢ããã ãã§ãã
ããã°ã©ã ã¯ã16ãã€ãã®ããŒãèŠã€ãããšããã«ãããã«å«ãŸããæ
å ±ã解èªããããã¹ããã¡ã€ã«ã®åœ¢åŒã§è¡šç€ºããŸãã ãã®ãã¡ã€ã«ã¯ç»é¢ã«è¡šç€ºãããèªãããšã¯ã§ããŸããã
ãããããã®åŸãèªã¿åãå¯èœãª.tmpäžæãã¡ã€ã«ãããããããããã®æ
å ±ãååŸããŠãæ£åœãªãææè
ã«è¿ãããšãã§ããŸãã ãã®ãããæ
å ±ãä¿è·ããããã®ããŒãã¯ãŒã¯ã¯ãã¹ãŠããµã€ã¬ã³ããã³ã«ãŒãç䌌乱æ°ãžã§ãã¬ãŒã¿ãŒãéå§ããã®ãå¿ããŠãããããç¡é§ã«è¡ãããŸããã
次ã«ãäžèšã®æãåªããéšåã瀺ããŸã-ããã¯ãµã€ã¬ã³ããã³ã«ãŒé¢æ°ã§ãWhy_Not_Use_ThisãšåŒã°ããŸãïŒäœ¿çšããªãã®ã¯ãªãã§ããïŒã
å®éãç¬èªã®ããã°ã©ã å
ã«ã¯ãPRNGãéå§ããããã«äœ¿çšã§ãããšã³ããããŒãçæããããã®GetCursorPosé¢æ°ïŒã«ãŒãœã«äœçœ®ã決å®ïŒããããããã°ã©ã å
ã§ãã®é¢æ°ãžã®çžäºåç
§ã確èªã§ããŸãã
ã³ãŒãå
ã®ä»ã®10ã15ç®æã§äœ¿çšãããŠããããšãããããŸãã ãããã£ãŠãSilent Bankerã®äœæè
ã¯ãããã°ã©ã ã«ç䌌乱æ°ãžã§ãã¬ãŒã¿ãŒãæ¿å
¥ããããšãå¿ãããåã«åŒã³åºãæŒç®åã䜿çšããŠæå·åããã»ã¹ã§ãã®é¢æ°ãå®è¡ããã®ãå¿ããŠããããšãããããŸãã
次ã®ã¹ã©ã€ãã¯ãããã¯æãèœã¡ã...ããšåŒã°ããèè
ãäœãå¿ããŠããªãã£ãå Žåã«ãã®ããã°ã©ã ãã©ã®ããã«æ©èœãããã瀺ããŠããŸãã
ãDESãŸãã¯not DESããšããã¿ã€ãã«ã®æ¬¡ã®ã¹ããŒãªãŒã¯ãWindowsããã°ã©ãã³ã°ã€ã³ã¿ãŒãã§ãŒã¹ãé©åã«äœ¿çšããæ¹æ³ããç¥ããªãããDESããŒã®æ倧ãµã€ãºãããããªããã«ãŠã§ã¢äœæè
ã«é¢ãããã®ã§ãã ãã®çµæããã®ããŒã®ãµã€ãºãç¡å¹ã§ããããããã®ããã€ã®æšéŠ¬ã¯ããã©ã«ãã§è«çæŒç®åxorãšãšãã«äœ¿çšãããŸãã
ãããã£ãŠãCryptDeriveKeyããã°ã©ã ã€ã³ã¿ãŒãã§ã€ã¹é¢æ°ã®å ŽåãdwFlagsãã©ã¡ãŒã¿ãŒã®2ã€ã®äžäœãã€ãïŒçµæã®URLã®å€èŠ³ãèšå®ãããã©ã°ïŒãæå·åããŒã®ãµã€ãºã決å®ããŸãã
ãããã£ãŠãäžäœãã€ãã0080ã®å ŽåãèŠæ±ããæå·åããŒã¯128ãããRC4ããŒã«ãªããŸãã ããã¯èªåã足ã§æã€ããšãšåãã§ãããã®çç±ã説æããŸãã
ã¹ã©ã€ãã«ã¯ã128ãããã®dwFlagsããŒã®ãµã€ãºãééã£ãŠããè¡ïŒ800000ïŒãšãMSCryptoAPIå€ãééã£ãŠããè¡ããããŸãã ãã®ããšã®å解ããèŠãããŸãã ãæå·åãµãã·ã¹ãã ã®åæåããšããé¢æ°ã衚瀺ãããŸãïŒããã€ã®æšéŠ¬ã¯æå·åãããã³ã³ããã¹ããåŒã³åºããMD5ããã·ã¥ã®ã³ã³ãããŒãäœæããŸãããã®åŸããã€ããªãã¡ã€ã«ã«ããŒãã³ãŒãããããã¹ã¯ãŒãã®MD5ããã·ã¥ãäœæãããã®ããã·ã¥é¢æ°ã®åºåã䜿çšããŠ128ãããDESããŒãäœæããããšããŸã ãã ãããã®å Žåã128ãããDESããŒãªã©ã¯ååšããªããããããŒã¯äœæãããŸããã
ãããã®APIé¢æ°ã®ããããã倱æãããšãé»è²ã§ããŒã¯ãããã®å Žæã«ãžã£ã³ãããããŒãåä¿¡ã§ããªããšããã¡ãã»ãŒãžã衚瀺ããŸãã ãããŠããã®å Žæã¯ããã«ãããebpã«ããå€ã移åãããã®æç¹ã§0ãã€ãŸãbUseMSCryptoAPIã®ãã®ããŒã«å€ã«ç§»åããŸãã
ããã°ã©ã ã®å®è¡äžã«ãããåŒãèµ·ãã圱é¿ãèŠãŠã¿ãŸãããã ã³ãŒãæ§é ã®ãã®èŠçŽ ã«åŸã£ãŠãããã°ã©ã å
ã§ä»ã®å Žæã§äœ¿çšãããŠããå Žæãšãé¢æ°ãtrueã§ããå Žåãšå·ãfalseã§ããå Žåã«ãã®ããã€ã®æšéŠ¬ã®åäœãã©ã®ããã«ç°ãªããã確èªããŸãã
ããŒã¿ã®æå·åãšåŒã°ããé¢æ°ã§è«çå€ããã§ãã¯ãããããšãããããŸãããããŒã¿æå·åãã§ãããããåœãŠã¯ãŸãå Žåã¯ãDESæå·åãšCryptEncrypt MSAPIã䜿çšããããã®ãããã¯ã«ãªããŸãã
ãã ãããã®å€ã0ã§ãããæ¢ç¥ã®ãšãããåžžã«åæã®ãŒãã§ããå Žåãé¢æ°ã¯ãã®ãããã¯ã«é²ã¿ãŸããããã©ã«ãã§ã¯xorã§ãã
æªæã®ããããã°ã©ã ã®äœæè
ããã®ãã¹ãŠãããã¯ã¢ããããããšã決å®ããã®ã¯ã©ã®æç¹ãªã®ãèå³ããããŸããã ãããã人ã
ã¯åœŒãäžããæŒã蟌ãã§ããã®ã§ã圌ã¯ãã«ãŠã§ã¢ãåãé€ãããšãäœåãªããããŸããããåå£å Žã§åœŒã¯åœŒã®DESãæ©èœããŠããªãããšã«æ°ã¥ããã®ã§ãããã¯ã¢ããèšé²ã«xorã䜿çšããŸããã å
šäœãšããŠãããã¯ããªãé¢çœãã£ãã®ã§ããã®è©±ã®æèšã¯åžžã«ããã¯ã¢ãããäœæããããšã§ãïŒ
次ã®ã¹ããŒãªãŒã¯ãäœãããŸãããïŒããšåŒã°ããŸãã Corefloodããã€ã®æšéŠ¬ã®æå·åãã©ã®ããã«æ©èœãããã説æããçšèªãèãåºãããšãããããããã±ãŒã·ã§ã³äŸåæå·åããšåŒã¶ããšã«ããŸããã èŠããã«ããã®ããã€ã®æšéŠ¬ã®äœè
ã¯æ°ããæå·åæ¹æ³ãçºæããŸããã å€å誰ããããã«ã€ããŠã®èšäºããã§ã«æžããŠããŠãããããã°ãŒã°ã«ãã§ããã¹ãã ãšæããŸãããïŒ Googleã¯ããäœçœ®äŸåæå·åãã®ç¹èš±ã誰ããç³è«ããç±³åœç¹èš±ãµã€ããžã®ãªã³ã¯ãæäŸããŠãããŸããã ãã®ã¹ããŒã ã¯éåžžã«çŽããããã®ã§ãç 究ããã«ã¯å€ãã®æéãããããŸãã ä»çµã¿ã¯æ¬¡ã®ãšããã§ããæå·åãããã¡ãã»ãŒãžãéä¿¡ããŸããããã解èªããŠèªã¿åãã«ã¯ãGPSããã€ã¹ã䜿çšããŠãæå®ãã緯床ãšçµåºŠã®å°ç¹ã«ç§»åããå¿
èŠããããŸãã éåžžãæå·åã¯ã»ãã¥ãªãã£ãšäœ¿ããããã®åŠ¥åç¹ã§ããããã®æ¹æ³ã«ã¯ã©ã¡ãããããŸããã
ããã¯ééããªãå®å
šã§ã¯ãªããéä¿¡è
ãã¡ãã»ãŒãžãèªãå Žæã«è¡ãå¿
èŠããããŸãã ãããã¯ãé»åã¡ãŒã«ãä»ããŠãªã³ã©ã€ã³ã§æŠããæ¬åœã«èª°ããéæ²»ãããå Žåãã€ã©ã¯ã®ã©ããã§èªãããšãã§ããæå·åãããã¡ãã»ãŒãžã圌ã«éä¿¡ããã°ãããªãã¯ããåé¡ãæ±ããããšã¯ãªããšåè«ãèšããŸããã
ãã®æ¹æ³ã¯ãCorefloodããã€ã®æšéŠ¬ã§ã©ã®ããã«äœ¿çšãããŸããïŒ ãã®ã¹ã©ã€ãã¯ãããã€ã®æšéŠ¬ããŠãŒã¶ãŒæ
å ±ãçãã åŸããããæå·åããŠãã£ã¹ã¯ã«æžã蟌ãã³ãŒããã©ã°ã¡ã³ãã瀺ããŠããŸããããã«ãããããã€ã®æšéŠ¬ã¯åŸã§ãã®æ
å ±ãåãåããã³ãã³ãã¢ã³ãã³ã³ãããŒã«ãWebãµã€ãã«ã¢ããããŒãã§ããŸãã
ãã®é¢æ°ã¯SetFilePointerïŒãã¡ã€ã«ãã€ã³ã¿ãŒãèšå®ïŒãšåŒã°ãããã®æ»ãå€ã¯dWordã§ããããã€ã³ã¿ãŒãèšå®ãããŠããå Žåã¯ããã€ã³ã¿ãŒãè¶
éããå Žåã«èšå®ããããã¡ã€ã«å
ã®ãªãã»ããã瀺ããŸãã 次ã«ãé¢æ°ã¯ãã€ãæ°ãååŸããŠnNumberOfBitesToWriteãæå·åããecxã¬ãžã¹ã¿ã«ç§»åããŸãã 次ã«ãæå·åã®ããã«ããŒã¿ãã€ã³ã¿ãååŸããedxã¬ãžã¹ã¿ã«ç§»åããŸãã
ãã®åŸãxoræŒç®åã䜿çšãããŸããããã¯ãalããã³ahãããã¡ãŒã«åãã€ããé
眮ããŸããã€ãŸããSetFilePointerããè¿ãããäžäœããã³äžäœãã€ããæå³ããŸãã ãããã£ãŠããã®ã¹ããŒã ã®æå·åããŒã¯ãããŒã¿ãååšãããã¡ã€ã«ã®ãªãã»ããã§ãã ããã¯ãããïŒ
次ã®ã¹ã©ã€ãã¯ãã³ã¢ãã³ãããªã»ããããæ¹æ³ããšåŒã°ããŸãã ããã¯ãç§ãæžããã°ããã®dumpCoreããã°ã©ã ãè¡šããŠããŸãã ããªãã¯ãããããŠã³ããŒãããããšãã§ããŸãããã¹ãŠã®ãœãŒã¹ã³ãŒãããããŸãã ãã®ããã°ã©ã ã¯ãã³ã³ãã¥ãŒã¿ãŒãCorefloodãŠã€ã«ã¹ã«ææããŠããå Žåã«åœ¹ç«ã¡ãŸããCorefloodãŠã€ã«ã¹ã¯ãäœããã®çç±ã§ã³ãã³ãã¢ã³ãã³ã³ãããŒã«ãµãŒããŒã«ã¢ã¯ã»ã¹ããŠçãŸããããŒã¿ãããŠã³ããŒãã§ããŸããã§ããã 圌ããã£ã¹ã¯ã«ä¿åãããããã®ãã¡ã€ã«ãååŸããç§ã®ããã°ã©ã ã䜿çšããŠãããã埩å·åããŠãããšãã°ã¯ã©ã€ã¢ã³ãã«ãããç¥ãããå¿
èŠãããå ŽåãããªãããçãŸãããã®ãèŠã€ããããšãã§ããŸãã
çãŸããããŒã¿ã®ãã°ã¯ãã¹ã©ã€ãäžã§èµ€ã§å²ãŸããŠããŸãã
Corefloodã§ãŸã èå³æ·±ãã®ã¯ãæå·åã¢ã«ãŽãªãºã ãããªã匱ãã«ããããããã被害è
ã®ã³ã³ãã¥ãŒã¿ãŒæ§æã«é¢ãããã¹ãŠã®çãŸããæ
å ±ãéè¡ãä¿¡çšçµåããã®ãã¹ãŠã®ã¿ãŒã²ããæ
å ±ãªã©ã転éããããšããããšã§ãã ãããã£ãŠãã³ã¢ãã³ããåé€ããå¥ã®æ¹æ³ã¯ããWiresharkã䜿çšããŠã³ã¢ãã³ããåé€ããæ¹æ³ããšåŒã°ããŸãã Wiresharkã¯ãã€ãŒãµããããããã¯ãŒã¯ãã©ãã£ãã¯ãŸãã¯TCPããŒã¿ãããŒãåæããããã°ã©ã ã§ãã
次ã®ã¹ã©ã€ãã¯ãCorefloodã®ä»çµã¿ã瀺ããŠããŸãã ãããã¯ãExplorerããã³Internet Explorerã«å
¥åãããdllã§ãã ã¬ãžã¹ããªãå€æŽããã¢ããªã±ãŒã·ã§ã³ã®åèµ·åãå¿
èŠã§ãããã·ã¹ãã ã®åèµ·åã¯å¿
èŠãããŸããã ãããã®dllãããã»ã¹ã«æ¿å
¥ããã«ã¯ããŸããŸãªæ¹æ³ããããŸãã
ãŠã€ã«ã¹ãéãã«äŸµå
¥ãããããã«ãŒã«ãšã£ãŠéèŠãªã®ã¯ããŠã€ã«ã¹ããŠãŒã¶ãŒã®ã³ã³ãã¥ãŒã¿ãŒã«å°å
¥ãããæ¹æ³ã§ãïŒãã«ãŠã§ã¢ãå¹æãçºæ®ããããã«ã·ã¹ãã ãåèµ·åããå¿
èŠããããããŠãŒã¶ãŒã¯ã¢ããªã±ãŒã·ã§ã³ïŒãã®å Žåã¯ãšã¯ã¹ãããŒã©ãŒïŒãåèµ·åããã ãã§ãã
ãããŠä»ã¯éãã«ãªã£ãŠããã®ã§ã誰ãèãããŸããïŒ
ããã¯ããªããŒã¹ãšã³ãžãã¢ãªã³ã°ã䜿çšããŠåæ§ç¯ããã³ãŒãã§ãã ããã¯ãCorefloodããšã¯ã¹ãããŒã©ãŒãæåã§ã·ã£ããããŠã³ããŠãå€æŽãããã«æå¹ã«ãªãæ¹æ³ã瀺ããŠããŸãã ããããããšã¯ã¹ãããŒã©ãŒãã³ã³ãã¥ãŒã¿ãŒã§å€±æãããšãã«äœãèµ·ãããããããåãã§ããã-ã¿ã¹ã¯ããŒãæ¶ããéããŠãããã¹ãŠã®ã¢ããªã±ãŒã·ã§ã³ã®ãŠã£ã³ããŠãæ¶ãããã¹ã¯ãããäžã®ãã¹ãŠã®ã¢ã€ã³ã³ãæ¶ããŠãããé çªã«å
ã®å Žæã«æ»ãå§ããŸãã
Corefloodã®äœæè
ã¯æããã«ãããç¥ã£ãŠããã®ã§ãOpenProcessåŒã³åºãã®çŽåã«ãšã¯ã¹ãããŒã©ãŒã®ãæ£ããããšã©ãŒã¢ãŒããèšå®ããããã«ãã·ã¹ãã åŒã³åºãããã®å Žæã«é
眮ããŸããã
SetErrorModeé¢æ°ã¯äœãããŸããïŒ å°ããªãããã¢ãããŠã£ã³ããŠãäœæããã¢ããªã±ãŒã·ã§ã³ãçµäºããããšã©ãŒã¡ãã»ãŒãžãéä¿¡ãããã·ã¹ãã ã«éä¿¡ãããéç¥ã®ç¹å®ã®å€±æãé²ããŸãã ãã®ãšã©ãŒã¡ãã»ãŒãžã§åœŒããããããšã¯ããšã¯ã¹ãããŒã©ãŒã倱æããåã«ãŠãŒã¶ãŒã«ãããã¢ãããŠã£ã³ããŠã衚瀺ãããªãããã«ããããšã ãã§ããã ãŠãŒã¶ãŒã«ãšã£ãŠããçããããã®ãæããŠãã ããïŒç»é¢ã«è¡šç€ºãããŠããåã³è¡šç€ºããããã¹ãŠã®æ¶å€±ã䌎ãå°ããªãããã¢ãããŠã£ã³ããŠããŸãã¯ãšã©ãŒã¡ãã»ãŒãžã®ãªããã¹ãŠã®æ¶å€±ãšå€èŠ³ïŒ ããªããèšã£ãã®ãèããïŒãäž¡æ¹ã®ã€ãã³ããã
次ã®ã¹ã©ã€ãã¯ããè
ãšèãããé ãªããã§ãã Corefloodã¯ãdllãšããŠããŒããããå ŽåãããŒããããã¢ãžã¥ãŒã«ã®ãªã¹ãã«è¡šç€ºãããŸããã 圌ã¯ããŒãã«å°ãã®ã¡ã¢ãªãå²ãåœãŠããã®ããŒãã®å Žæã«èªåèªèº«ãã³ããŒããŸã-ç§ã¯ãããèµ€æ ã«å
¥ããŸããã
ãã®åŸãPEããããŒãåé€ããããããã®ããã€ã®æšéŠ¬ã«ææããã³ã³ãã¥ãŒã¿ãŒã«ééããå Žåãã次ã®ã¹ãããã¯ããã®å®è¡å¯èœãã¡ã€ã«ããã³ãããåæã®ããã«IDAã«ã¢ããããŒãããããšã§ãããšèšããŸãããå®è¡å¯èœãã¡ã€ã«ããã³ãããããšã¯éåžžã«å°é£ã§ãã PEããããŒããªãå Žåã ãããã£ãŠãCorefloodãä»®æ³allocãåŒã³åºããšããmemãã©ã°ãäžããäžã«å®çŸ©ããŸããããã«ãããã·ã¹ãã ã¯ã䜿çšå¯èœãªæå°ã®ã¢ãã¬ã¹ã§ã¯ãªããæé«ã®ã¢ãã¬ã¹ãè¿ããŸãã ããã«ãããããã€ã®æšéŠ¬ã¯ãä»ã®ã·ã¹ãã dllã®äžã§ãŠãŒã¶ãŒã¢ãŒãã®ããé«ãã¡ã¢ãªé åã§éå§/çµäºåŒçšç¬Šãé ãããšãã§ããŸãã ãããã£ãŠã次ã®ãã¢ã§ã¯ããé ãããŠãããã¹ãŠã圹ã«ç«ããªããã®ã«ããæ¹æ³ããšåŒã³ãŸããã
ã¹ãã«ã¹ã䜿çšããCorefloodã®ãããªãã®ã«åºãããããã®ãããªãŠã€ã«ã¹ãæ±ãããã®æ¢è£œã®ããŒã«ããªãå Žåã¯ãç¬èªã®ããŒã«ãäœæããå¿
èŠããããŸãã
解åã«æ
£ããŠããå Žåã¯ããããã¬ãŒã䜿çšããã®ãäžè¬çã§ãã ããã¯äžè¬çãªã¢ã«ãŽãªãºã ã§ã¯ãªããããç¹ã«èªåã¢ã³ããã«ãŒããªãå Žåã ãã®å Žåããããã¬ãŒã䜿çšããŠå
ã®ãšã³ããªãã€ã³ãã«ç§»åããProcDumpãŸãã¯å¥ã®ãŠãŒãã£ãªãã£ã䜿çšããŠããã€ã®æšéŠ¬ã®ãã³ããåé€ã§ããŸãã PE Import Reconstructor, , , .
, . . Volatility, Internet Explorer . , Coreflood, , . , 7FF81000.
, HEX , Coreflood. , , . .
, , Coreflood, Volatility . , ID Internet Explorer. , , PID 1732. Malfind, , , , . VAD , , . , .
, , 7FF81000. , Fix IAT, PID 1732 Internet Explorer , Coreflood.
dll, Internet Explorer, , RBA , , .
, 7FF81000, , . , PE . , Import Reconstructor: , , . Fix IAT , PE modify viewer , .
21:15
DEFCON 17. ! ããŒã2
, . ç§ãã¡ã®èšäºã奜ãã§ããïŒ ? 泚æããããå人ã«æšèŠããããšã§ãç§ãã¡ããµããŒãããŸããç§ãã¡ãããªãã®ããã«çºæãããšã³ããªãŒã¬ãã«ã®ãµãŒããŒã®ãŠããŒã¯ãªã¢ããã°ã®HabrãŠãŒã¶ãŒã®ããã«30ïŒ
ã®å²åŒïŒ VPSïŒKVMïŒE5-2650 v4ïŒ6ã³ã¢ïŒã«ã€ããŠã®çå®20ãã«ãŸãã¯ãµãŒããŒãåå²ããæ¹æ³ïŒ ( RAID1 RAID10, 24 40GB DDR4).
VPSïŒKVMïŒE5-2650 v4ïŒ6ã³ã¢ïŒ10GB DDR4 240GB SSD 1GbpsãŸã§ 6ãæã®æéãæ¯æãå Žåã¯12æãŸã§ç¡æ㧠ã ããã§æ³šæã§ããŸã ã
Dell R730xd 2 ? 2 Intel Dodeca-Core Xeon E5-2650v4 128GB DDR4 6x480GB SSD 1Gbps 100 $249 ! . ã¯ã©ã¹Rã¯ã1ç±³ãã«ã§9,000ãŠãŒãã®Dell R730xd E5-2650 v4ãµãŒããŒã䜿çšããŠããŸããïŒ