ãã·ã§ãŒã«åååçºé»æã§çºèŠãããStuxnetã¯ãŒã ã¯ãå€ãã®ãã€ãºãçºçãããŸããã ã誰ããã®ãã¹ãŠã®èåŸã«ããã®ã§ããããïŒã-ããããããã®è³ªåã¯æ°å幎éçããããªãã§ãããã 仿¥ãå€ãã®äººã
ã«ãšã£ãŠãéèŠãªã€ã³ãã©ã¹ãã©ã¯ãã£ã®ãªããžã§ã¯ãã¯éåžžã«è峿·±ããã®ã§ããç«¶åããäŒæ¥ããå§ãŸããæŠåœã®ç¹å¥ãªãµãŒãã¹ã§çµããããšã§ãã

穎ã®å¹
ã¯ïŒ
éèŠãªã€ã³ãã©æœèšã¯æ
éã«ä¿è·ãããŠãããããããã«å°éããããå€éšã«ç©ãæã¡èŸŒãããšã¯éåžžã«å°é£ã§ãã ãã®ç¹ã§ããªã¢ãŒãæ»æã®å¯èœæ§ãæãéèŠã§ãã 仿¥ãåç¶æ
ã¯ããèªäœã§æãéèŠãªãªããžã§ã¯ãã®ãªã¹ããæ±ºå®ããŸãã ãããŠããã®ãªã¹ãã¯åœå®¶ç§å¯ã§ããããã®å
容ã¯çµ¶å¯Ÿã«æçœã§ããé»åç£æ¥ãåååããã³åååç£æ¥ãçåæ°ŽçŽ èŒžééšéãç³æ²¹ååŠè£œåãæŠç¥çè»äºæœèšã®ãªããžã§ã¯ãã§ãã åœç¶ããããã®æœèšã®å€ãã¯ãè€éãªèªåããã»ã¹å¶åŸ¡ã·ã¹ãã ïŒACS TPïŒã§ããæ
å ±æè¡ã䜿çšããŠèªååããã»ã¹ãåããŠããŸãã
äžè¬çãªç£æ¥çšå¶åŸ¡ã·ã¹ãã ã«ã¯ããã£ã¹ãããã³ã°ã·ã¹ãã ïŒSCADAïŒãé éæž¬å®ãµãã·ã¹ãã ãå©çšå¯èœãªç£æ¥çšããŒã¿è»¢éãããã³ã«ã«åºã¥ãéä¿¡ã€ã³ãã©ã¹ãã©ã¯ãã£ã®3ã€ã®äž»èŠã³ã³ããŒãã³ããå«ãŸããŸãã å€ãã®å Žåãå€åœã®æç®ã§ã¯ããACS TPããšããçšèªã¯çç¥ãããŠãããSCADAã·ã¹ãã ã®ã¿ãåç
§ããŠããŸãããã¹ã±ãžã¥ãŒãªã³ã°ã§ã¯å¶åŸ¡ã·ã¹ãã ããã»ã¹å
šäœã®ã€ã³ã¿ã©ã¯ãã£ããªå¶åŸ¡ãã§ããªãããšãçè§£ããããšãéèŠã§ãã
ã€ã³ã¹ãã«ã¡ã³ã¿ã«ãã¬ãŒãã³ã°
å¶åŸ¡ã·ã¹ãã ãšæè¡ããã»ã¹ã®ãã£ã¹ãããã«å¯ŸåŠããå¿
èŠãããå Žåãããã»ã¹å¶åŸ¡ã·ã¹ãã ã®å®å
šæ§åæã«ã¯ã©ã®ããŒã«ãå¿
èŠã§ããïŒ ããã§ã¯ãæ¢ç¥ã®ç£æ¥å¶åŸ¡ã·ã¹ãã ãšSCADAã·ã¹ãã ã®60ïŒ
ãåŸæ¥ã®ãã©ãããã©ãŒã ïŒWindowsãLinuxïŒã«å±éãããŠãããããæ¢ç¥ã®æè¡ãšåã
ã®ç¹å¥ãªãœãªã¥ãŒã·ã§ã³ã®æ¥ç¹ã§äœæ¥ããå¿
èŠããããŸãã å¿
èŠã«å¿ããŠãQNXãªã©ã®ãªã¢ã«ã¿ã€ã ãã©ãããã©ãŒã ïŒããŒãããœããïŒã䜿çšãããªã¢ã«ã¿ã€ã ïŒãªã¢ã«ã¿ã€ã ã·ã¹ãã ïŒã®æ¡ä»¶ã§ç¹å®ã®æéééã§ç¹å®ã®æäœã®å®è¡ãä¿èšŒããŸãããè»äºè£œåïŒUAVã空äžå¶åŸ¡ïŒã
çŸåšãèªåããã»ã¹å¶åŸ¡ã·ã¹ãã / SCADAã®ã»ãã¥ãªãã£ãåæããããã®é«åºŠã«å°éåããããœãããŠã§ã¢ããŒã«ã¯ããã»ã©å€ããããŸããã
- SCADA-Auditor PCïŒæè¡ãããã¯ãŒã¯ã®ã»ãã¥ãªãã£åæçšã®åœå
ã¹ãã£ããŒãACS TP / SCADAïŒ;
- Teenable NessusïŒããã€ãã®SCADAã·ã¹ãã ãã¹ãã¢ãžã¥ãŒã«ãšãåçšããŒãžã§ã³ã®å€ãã®ããã°ã©ããã«ããžãã¯ã³ã³ãããŒã©ãŒãå«ãŸããŠããŸãïŒ;
- Rapid7 Metasploit ProjectïŒããã«ã¯ãã¹ãŠãæ²ããïŒãšã¯ã¹ããã€ã/ scada /ã»ã¯ã·ã§ã³ã«ã¯ãçãç¯å²ã«çŠç¹ãçµã£ãã¹ããã€ããæ°çµãããããŸããïŒã
åœç¶ãç¹æ®ãªãœãããŠã§ã¢ã«å ããŠãnmapãããã¯ãŒã¯ã¹ãã£ããŒãªã©ã®åŸæ¥ã®ããŒã«ã䜿çšãããŸãã ã¡ãªã¿ã«ãåœŒã¯æ
å ±ã»ãã¥ãªãã£ã®ææ°ã®åŸåã«ã泚ç®ããŠããŸããæè¿ããã©ã°ã€ã³ãç»å ŽããããŒãäžã®Stuxnetææãæ€åºã§ããããã«ãªããŸããã
Stuxnetã«ææãããã¹ããèŠã€ããæ¹æ³
NMAP'aæ°ããŒãžã§ã³ïŒ5.51ïŒã«ã¯ãNMAP Scripting Engineçšã®LUAããã°ã©ãã³ã°èšèªã§æžãããè峿·±ããã©ã°ã€ã³ãå«ãŸãããã®ååã¯ãstuxnet-detectãã§ãã SMBã»ãã·ã§ã³ãä»ããŠStuxnetã¯ãŒã ã®ååšã«ã€ããŠããŒãã調æ»ããã®ã¯éåžžã«ç°¡åã§ãã
nmap --script stuxnet-detect -p 445 <host>
ããã«ããã¬ã³ããã€ã¯ãã®å°éå®¶ãäœæããã¹ãã£ããŒã䜿çšããŠãææããããŒããæ€åºã§ããŸãã
äŒç€Ÿã®ãŠã§ããµã€ãã§å
¥æã§ããŸãã ãããã®ã¹ãã£ããŒã¯ã©ã®ããã«æ©èœããStuxnetã¯ã©ã®ããã«æ©èœããŸããïŒ
Stuxnetã¯ãææããããŒããšã®å
éšããã³å€éšéä¿¡çšã«RPCãµãŒããŒãå¥ã®ããŒããšããŠç»é²ããŸãã RPCãµãŒããŒã®æ©èœã¯ãã¯ãŒã ã®ããŒãžã§ã³ãçºè¡ïŒç¢ºèªïŒãããšãšãã«ãæŽæ°æ©èœãå®è¡ïŒæ°ããã€ã³ã¹ã¿ã³ã¹ãããŠã³ããŒãïŒããããã«æ§æãããŠããŸãã ãã®ãç£æ¥çšãããããããã®ã³ã³ãããŒã«ã»ã³ã¿ãŒããã察å¿ããRPCåŒã³åºããè¡ãããšãã§ããŸãã

ã»ã³ã¿ãŒã¯ãããŒãžã§ã³ããã§ãã¯ããã³ãã³ãïŒ0x00ïŒãæäŸããŸãããå€ããå Žåã¯ãæŽæ°æ©èœãåŒã³åºãããŸãïŒ0x04ïŒã SMB-over-TCPãµãŒãã¹ïŒTCP 445ïŒã®å¯çšæ§ãäºåã«ãã§ãã¯ãããŸãããã®åŸããã®ããŒãžã§ã³ã®StuxnetïŒMS10-061ãªã©ïŒã«çµã¿èŸŒãŸããŠããè匱æ§ãæªçšãããDCE / RPCãä»ããç¹æ§ååä»ããã€ããžã®ãã€ã³ããå®è¡ãããŸãïŒã// browserãã»ãšãã©ã®å ŽåïŒãUUIDãšãã®åŸç¶ã®åæãæ€çŽ¢ããŸãã ãããïŒ

2çªç®ã®æ¹æ³ã¯ãã¿ã¹ã¯ã¹ã±ãžã¥ãŒã©ã§ãããŒãããããæªæã®ããStuxnetã³ãŒããæ€çŽ¢ããããšã§ãã ãã®ææ³ã«åºã¥ããŠãTrend Microã¹ãã£ããŒãæ©èœããŸãã
å
žåçãªè
åš
æè¡çãããã¯ãŒã¯ã®å
žåçãªããããžã«äŒŽãè
åšãæç¢ºã«èª¿ã¹ãŠã¿ãŸãããã ïŒæè¡ããã»ã¹ã®æ§è³ªã«å¿ããŠïŒ3ã€ã®ãŸãŒã³ãåå¥ã«åºå¥ããŸã-ã³ãŒãã¬ãŒãïŒç®¡çãšã¯é¢ä¿ããªããããžãã¹ããã»ã¹ã®ã¿ãæ±ãïŒããšã°ãŒã¯ãã£ãïŒæè¡ããã»ã¹ãå®è¡ãããçŽæ¥ãªã³ã¯ãããšãã°ãã¢ã³ã¢ãã¢ã®åŠçãç³æ²¹ã®ç®¡çïŒ ïŒããã³ãã£ã¹ããããŸãŒã³ïŒããã»ã¹ã®é²è¡ã«åœ±é¿ãäžããå¯èœæ§ã®ããç£æ¥çšå¶åŸ¡ã·ã¹ãã ã®ãªãã¬ãŒã¿ãŒãååšããŸãïŒã

å
žåçãªãã¯ãããžãŒãããã¯ãŒã¯ããããž
- ã¢ã¯ãã¥ãšãŒã¿ãšé éæž¬å®ãµãã·ã¹ãã
éåžžã«å€ãã®å Žåã䜿çšãããããã€ã¹ã®é»åã³ã³ããŒãã³ãããŒã¹ã§ã¯ãIPSecãSSLããŸãã¯VPNãªã©ã®äžè¬çãªãã¯ãããžãå®è£
ã§ããŸããã ãã ãããããã®ããã€ã¹ãžã®ã¢ã¯ã»ã¹ã¯åžžã«å¿
èŠã§ãã ããã«ããããã®ããã€ã¹ã®äžéšã¯ãã»ã³ãµãŒãªã©ã䜿çšããŠããã»ã¹ã®ããã©ãŒãã³ã¹ã«é¢ããæ
å ±ïŒãã¬ã¡ããªãŒïŒãåéããããã®ããã€ã¹ãšããŠæ©èœããŸãã ãããã«ã¯ãã¢ã©ãŒã ãäºæ
ã«é¢ããã¡ãã»ãŒãžãèç©ãããå¯èœæ§ããããããã¯éåžžã«éèŠã§ãã ãã®ç¹ã§ãäžè¬ã«å©çšå¯èœãªIPã¢ãã¬ã¹ãå²ãåœãŠãããšãéåžžã«éèŠã§ããããã¯ãæ®å¿µãªããéåžžã«äžè¬çã§ãã ç¶æ³ã«ãã£ãŠã¯ããããã¯ãŒã¯èšèšãšã©ãŒãèµ·ãããŠãããåé¿ããããšã¯ã§ããŸããã ããšãã°ãææ°ã®ç£æ¥çšã³ã³ãããŒã©ãŒã¯ãçŽæ¥ãŸãã¯ã¢ãã çµç±ã§æ¥ç¶ã§ããŸãã ã¢ãã ãä»ããŠæ¥ç¶ããå ŽåãGPRS / GSMã¢ãã ãšçµã¿åããããããšãå€ããããã©ã«ãã§ã¯ããã€ã¹ã«ã¢ãã€ã«ãªãã¬ãŒã¿ãŒã®IPã¢ãã¬ã¹ãäžããããŸãã ãã®æ§æã§ã¯ãå€é𿻿ã«å¯ŸããŠéåžžã«è匱ã§ãã ç¹æ®ãªãŠãŒãã£ãªãã£ã𿹿³ã䜿çšããŠãæ»æè
ã¯ãã®ãããªããã€ã¹ãæ€åºããå€ãã®æªãããšãããããšãã§ããŸãã ã¢ã¯ãã¥ãšãŒã¿ãŒèªäœã¯éåžžãã·ãªã¢ã«ã€ã³ã¿ãŒãã§ã€ã¹ïŒRS-232 / RS-485ïŒãä»ããŠMODBUSãµãŒããŒã«æ¥ç¶ãããMODBUSãµãŒããŒèªäœã«ã¯ããªãã¬ãŒã¿ãŒãšã®ã€ãŒãµããã/ç£æ¥çšã€ãŒãµããããã£ãã«ãä»ããTCP / IPå¶åŸ¡ããããŸãã - ARMãªãã¬ãŒã¿ãŒãšSCADAã·ã¹ãã ã®ããŒã¯
ãããã®åå¿ã¯æãå°é£ãªç«å Žã«ãããŸãããªããªãã圌ãã®éã®æ¿æš©ã®åé¡ã¯ãã°ãã°å°éãããªãããã§ãã 2çªç®ã®åé¡ã¯ãå€åœã®å°éå®¶ããã°ãã°åãå
¥ããããå
šãç°ãªãåæãæã£ãŠããå¯èœæ§ãããããšã§ãã ãã·ã§ãŒã«åååçºé»æã§Stuxnetã¯ãŒã ãå°å
¥ããæ
£è¡ã瀺ããããã«ããµãŒãã¹ãŠãããã®ã€ã³ãµã€ããŒãšã³ãžãã¢ãUSBãã©ã€ãããæªæã®ããããã°ã©ã ãå°å
¥ããŸããã ãã®ãããªåå¿ãäžçã®åååçºé»æãäœäººæ©ãåãã®ãã¯çåã®ãŸãŸã§ãã ãªãã¬ãŒã¿ãŒã¯ãéåžžãç°ãªãã¬ãã«ã®ç¹æš©ã§SCADAã·ã¹ãã ã«æ¥ç¶ããæ°ãããããžã§ã¯ããèšç»ããã³å®è£
ããæ¢åã®ãããžã§ã¯ãã倿Žããããšãã§ããŸãã ã·ã¹ãã ãœãããŠã§ã¢ã®ãã£ã¹ãããã«ã¯å€ãã®è匱æ§ããããŸãããã€ã³ãµã€ããŒååŒã¯äŸç¶ãšããŠäž»èŠãªè
åšã§ãã - ã³ãŒãã¬ãŒããŸãŒã³ïŒBANãŸãŒã³-ããžãã¹ãšãªã¢ãããã¯ãŒã¯ïŒ
ãã®äžã«åº§ã£ãŠãã人ã
ãããŸãã圌ãã¯ååãšããŠãç§ãã¡ãæ€èšãããã¹ãŠã®çµç¹ã®ææè
ã§ãã ãšãã«ã®ãŒãŸãã¯ç³æ²¹èŒžéçµç¹ã®åéã§ã¯ãããã¯ç¹ã«æçœã§ã-ãªãã¢ã®ãšãã«ã®ãŒçæè€åäœãŸãã¯ç³æ²¹æåè£
眮ã®ã©ã€ã³ã®åœ¢ã§ããããã®çµæžå
šäœãããŸããŸãªå€§éžã«äœçœ®ããããšãã§ãã圌ãèªèº«ã¯ç§ãã¡ã®ãããªæããç¡å®³ãªåœã«åº§ã£ãŠããŸã:) BANã¯ãå©çãäžããããšã圌ããè«æ±æžãããžãã¹ã®çµæžçããã³çµæžçåé¡ãç ç©¶ããããšã«ã»ãšãã©ã®æéãè²»ããçç±ã«çŽæ¥æžå¿µããŠããŸãã
éå§ããŸãã
äœå®
ã®ç±ãšãã«ã®ãŒæ¶è²»ã管çããããã®æŽŸé£ã·ã¹ãã ã®ç£æ»ãã©ã®ããã«å®æœãããã«ã€ããŠã®å®è·µçãªè©±ãå
±æããŸãã ç§ã®äž»ãªã¿ã¹ã¯ã¯ãã·ã¹ãã ã«ååšããè匱æ§ãæ€åºããã·ã¹ãã ã®éèŠãªèŠçŽ ã«ãªã¢ãŒãã§ã¢ã¯ã»ã¹ããããšã§ããã
ãããã¯ãŒã¯ã®ç¯å²ãæå®ãããšããã®äžã®å¢çã¢ã¯ã»ã¹ã²ãŒããŠã§ã€ãèå¥ããããšã決å®ãããŸããã é·ãéæ€çŽ¢ããå¿
èŠã¯ãããŸããã§ãããCisco7301ã«ãŒã¿äžã®Ciscoã«ãŒã¿ããã³ã»ãã¥ãªãã£ããã€ã¹ãããŒãžã£ã§ãããCISCO SDMãšããŠç¥ãããŠããŸãã å¯èœã§ããã°ããã®æ§æãã¡ã€ã«ã調ã¹ãå
éšãããã¯ãŒã¯ã®ç¯å²ãæå®ããããã§æã䟡å€ã®ãããã®ãç¹å®ããå¿
èŠããããŸããã
å¥åŠãªããšã«ãã²ãŒããŠã§ã€èªäœã«2ã€ã®è匱æ§ããããŸããã
- èš±å¯ãã€ãã¹ã¬ãã«15ã
- çµ±åãããã¢ã«ãŠã³ããciscoãïŒã²ãŒããŠã§ã€ã¯éçšéå§ãããã°ããã§ã管çè
èªèº«ãã»ãã¥ãªãã£ããŸã 確ç«ã§ããªãã£ãçç±ïŒ
ã¢ã¯ã»ã¹æš©ãåŸãŠãç§ãæåã«åã£ãã®ã¯ããã€ã¹ããã®èšå®ã§ããããã¹ã¯ãŒãããã·ã¥ãå«ãŸããŠããããã§ãã
#
show running config
ãµããããã調ã¹ãåŸãããã«å¢çã«ãŒã¿ãŒããçŽæ¥ãããã¯ãŒã¯ã®åæãå§ããŸããã åœç¶ããã®æé ã¯2ã€ã®æ¹æ³ã§å®è¡ã§ããŸãã
- ãããã¯ãŒã¯ããŒããä»ããŠå®è¡ãããæ¢ç¥ã®ããŒãã«æ¥ç¶ããŠãµãŒãã¹ã«é¢ããæ
å ±ãåéããTCLã¹ã¯ãªãããç©æ¥µçã«äœ¿çšããŸãã
- ååçã«ãããã§ã¯ãã¹ãŠãå°ãè€éã§ãããªããªããææ°ã®CISCOãã¡ãŒã ãŠã§ã¢ã¢ããããŒãã®ã¿ã«Cisco IOS Embedded Packet CaptureïŒEPCïŒãå«ãŸããŠããããã§ããããã¯ããããã¯ãŒã¯èšºæã®ãã±ããã¢ãã©ã€ã¶ãšããŠæ©èœããéåžžã«äŸ¿å©ãªãã®ã§ãã
å€ãã®ãã€ãºãçºçãããªãããã«ãç§ã¯EPCã䜿çšããã ãã§ã²ãŒããŠã§ã€ã1ã€ã®å€§ããªã¹ããã¡ãŒã«å€ããå¿
èŠããã2çªç®ã®ãã¹ã«æ²¿ã£ãŠé²ã¿ãŸããã
# EXEC
enable
# «pktrace1», 256 , 100
monitor capture buffer pktrace1 size 256 max-size 100 circular
# , FastEthernet, ,
monitor capture point ip cef ipceffa0/1 fastEthernet-type 0/1 both
#
monitor capture point associate ipceffa0/1 pktrace1
#
monitor capture point start ipceffa0/1
#
show monitor capture buffer pktrace1dump
ãã©ãã£ãã¯ã§TCPããŒã502ã瀺ãè¡ãèŠã€ããã®ã§ããã®ããŒãã¯MODBUS TCPãããã³ã«ã«å
žåçã§ãããããå€ãã®ããšãæããã«ãªããŸããã ãã±ããã«ãŒãã£ã³ã°ãšå®å
ã¢ãã¬ã¹ã«ãããã³ã³ãããŒã«ã»ã³ã¿ãŒã®å Žæã倿ã§ããŸããã å®éããã®æ¹æ³ã§ãã«ãŒãã£ã³ã°æ©åšãç¹ã«çŸåšã®ãã¡ãŒã ãŠã§ã¢ããŒãžã§ã³ãæã€CISCOã«ãŒã¿ãŒãããæ¬æ Œçãªããã·ããããã¯ãŒã¯åµå¯ãè¡ãããšãå¯èœã§ãã
ã¹ãã£ããŒãèµ·åãããšã誰ãããã§ã«çç£çã«ããã«ããããšã«æ°ä»ããŸãããããã€ãã®ããŒããã¯ãŒã ã«ææããŠããããããããæ¯masterçã«ããã¹ã¿ãŒãåŸ
ã£ãŠããŸãããšæããŠãããŸããã å€ãã®SCADAã·ã¹ãã ã®ããã©ã«ãèšå®ã§ã¯ãMicrosoft Windows DCOM OSãžã®å¿åã¢ã¯ã»ã¹ãçµç¹ããããšãæšå¥šããŠãããšããè峿·±ãäºå®ã«æ³šæããå¿
èŠããããŸãã ãŸããå€ãã®ç£æ¥çšãããã³ã«ã¯ãããã€ãã®çç±ïŒãã¬ã¡ããªæ©åšã®å®è£
ã®é£ããããã©ãã£ãã¯éã®å¢å ïŒã®ããã«æå·åããµããŒãããŠããŸããã äžæ¹ãSDMæ§æããååŸãããããã·ã¥ã¯åŸ©å·åãããŸããã ä»åã¯ããã€ãã£ãã®CISCOãsecret 7ãã®ä»£ããã«ãMD5ãããã·ã¥ã¢ã«ãŽãªãºã ãšããŠäœ¿çšãããŸããã
MODBUSãããŒã¿ã転éããæ¹æ³
MODBUSãããã¯ãŒã¯ã§ã¯ãASCIIãŸãã¯RTUã®2ã€ã®ããŒã¿éä¿¡æ¹æ³ã®ããããã䜿çšã§ããŸãã ãŠãŒã¶ãŒã¯ãåã³ã³ãããŒã©ãŒã®æ§æäžã«ãä»ã®ãã©ã¡ãŒã¿ãŒïŒããŒã¬ãŒããããªãã£ã¢ãŒããªã©ïŒãšãšãã«ç®çã®ã¢ãŒããéžæããŸãã ASCIIã¢ãŒãã䜿çšããå Žåãã¡ãã»ãŒãžã®åãã€ãã¯2ã€ã®ASCIIæåãšããŠéä¿¡ãããŸãã ãã®æ¹æ³ã®äž»ãªå©ç¹ã¯ãæåã®éä¿¡ééãæå€§1ç§ã§ãéä¿¡ãšã©ãŒãçºçããªãããšã§ãã ASCIIã¢ãŒãã§ã¯ãã¡ãã»ãŒãžã¯ã³ãã³ïŒïŒãASCII 3A 16鲿°ïŒã§å§ãŸããããã£ãªããžãªã¿ãŒã³ã©ã€ã³ãã£ãŒããã·ãŒã±ã³ã¹ïŒCRLFãASCII 0Dã0A 16鲿°ïŒã§çµãããŸãã éä¿¡ã«æå¹ãªæåã¯ã16鲿°0ã9ãAãFã§ãã ãããã¯ãŒã¯äžã®ãããã¯ãŒã¯ããã€ã¹ã®ã¢ãã¿ãŒã¯ãã³ãã³èšå·ãç¶ç¶çã«ç£èŠããŸãã åä¿¡ãããšãåããã€ã¹ã¯æ¬¡ã®ã¡ãã»ãŒãžãã£ãŒã«ãïŒã¢ãã¬ã¹ãã£ãŒã«ãïŒãªã©ããã³ãŒãããŸãã
CISCOã«ãŒã¿ãŒã®ãã¹ã¯ãŒã
äºæ³ããããç§å¯7ãããã·ã¥ã®ä»£ããã«ããCISCO 5ãïŒCISCOã¿ã€ãã5ããã¹ã¯ãŒãïŒãCISCOã«ãŒã¿ã§èŠã€ããããšããããŸãã ããã·ã¥ãã¹ã¯ãŒããååŸããããã»ã¹ã¯ããã·ãŒã¯ã¬ãã7ããããã³ã°ãšã¯ç°ãªããŸããããã¯ãããç¥ãããŠããã¹ã¯ãªããã§ããCain and Abelãä»ã®å€ãã®ããã°ã©ã ã䜿çšããŠè§£èªã§ããŸãã ãã¹ã¯ãŒãããã·ã¥ã®å€èгãšä¿åæ¹æ³ã®äŸïŒ
username jbash enable secret 5 $1$iUjJ$cDZ03KKGh7mHfX2RSbDqP.
username jbash password 7 07362E590E1B1C041B1E124C0A2F2E206832752E1A01134D
ããã·ã¥ã¢ã«ãŽãªãºã ãmd5ïŒunixïŒã«äŒŒãŠããããšã¯ç°¡åã«ããããŸãããããã£ãŠããã®å Žåããããã®ã¿ã€ãã®ããã·ã¥ãã€ãŸãPasswords ProãJohn The RipperãEGBãªã©ã埩å
ã§ããææ°ã®ãœãããŠã§ã¢ããŒã«ã䜿çšããŠãèŸæžæ»æãè¡ãããšãã§ããŸãã æ§é çã«ã¯ã次ã®ããã«ãªããŸãã
$1$FKKk$t2NOQP.vSScMbwJWERNU0/ (type "5"),
«FKKk» - (salt)
èªå®¶è£œã®ãã«ãŒããã©ãŒã¹ã¯æ¬¡ã®ããã«ãªããŸãã
openssl passwd -1 -salt FKKk ciscoïŒãciscoãã®ä»£ããã«-ãã¹ã¯ãŒãã䜿çšããŠèŸæžããåèªãç§»åããŸããæçµããã·ã¥ãèª¿æ»æžã¿ã®ãªãªãžãã«ãšäžèŽããå Žå-æåããéžæãäžåš-ç¶ç¶çãªãã«ãŒãïŒã

掟é£å¶åºŠ
ãã¹ã¯ãŒãã埩å·åããåŸããããã¯ãŒã¯ã®å¢çã®èª¿æ»ãéå§ããŸããã äžéšã®ãã¹ãã«ã¯å€éšIPã¢ãã¬ã¹ã®ãšã€ãªã¢ã¹ããããå€éšããæ¥ç¶ã§ããããã«ãªããŸããã ãããã¯ãŒã¯å
ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³ã®1ã€ã«ã¢ã¯ã»ã¹ã§ããããã«ãªã£ãã®ã§ãSCADA-AuditorãœãããŠã§ã¢ã䜿çšããŠããã¹ãŠã®ICSããã€ã¹ã®ç©æ¥µçãªåµå¯ãéå§ããŸããã ä»ã®ã¹ãã£ããŒã¯ãMODBUSã«å
žåçãªå©çšå¯èœãªTCP 502ããŒãã衚瀺ããŸããããã€ãã£ãæ¥ç¶ã確ç«ãããããããµãŒãã¹æ
å ±ãååŸããŸã-圌ãã¯ç¢ºãã«æ¹æ³ãç¥ããŸããã
SCADA-Auditorã䜿çšããŠãã¹ã±ãžã¥ãŒãªã³ã°ã·ã¹ãã ãŸãã¯ãã¬ã¡ããªèŠçŽ ã®é
眮ã®å
åãå«ããããã¯ãŒã¯ç¯å²å
ã®ããŒããèå¥ããå¿
èŠããããŸããã äœãæ¢ãã¹ãããç¥ã£ãŠããã°ãå€ãã®æšèã«å¯ŸããŠãããè¡ãããšãã§ããŸãã æ€çŽ¢ã®å¯èœãªåºæºã®1ã€ã¯ãSNMPãããã³ã«ã®ããŒãªã³ã°ã®åºåïŒäœ¿çšå¯èœãªå ŽåïŒã§ãã ãŸãããããã¯ãŒã¯èªäœã®å
éšã§ã管çããã«ãšçµã¿èŸŒã¿ã®WebãµãŒããŒãä»ããŠãSCADAèªäœãèŠã€ããŸãã-ããã¯Cascade-ACSã§ããã ãã®ãœãããŠã§ã¢ããã±ãŒãžã調ã¹ãåŸãããã€ãã®è匱æ§ãç¹å®ããŸããã
- KASKAD / Web_Clnt.dll / ShowPageïŒWeb_Clnt.iniã¯ãŒã¯ãããŒãããžã§ã¯ãã䜿çšãããã£ã¬ã¯ããªã®äžæ£ãªèªã¿åãã ãããããããŒã¹ãžã®å®å
šãªãã¹ãèŠã€ããããšãã§ããŸãïŒ
Project="C:\Program Files\Kaskad\Projects\KVisionDemoProject\kaskad.kpr"
- ãŠãŒã¶ãŒæ
å ±ã®é瀺KASKAD / Web_Clnt.dll / ShowPageïŒ../../../ Projects / KVisionDemoProject / Configurator / Events.iniã
- ããŒã¿ããŒã¹ãžã®ãã¹ã¯ãŒããšãŠãŒã¶ãŒã®èªã¿åãïŒ
UserName=sysdba
Password= ( XOR' 0x1B)
- ãµãŒãã¹æ
å ±é瀺KASKAD / Web_Clnt.dll / ShowPageïŒ../../../ Projects / KVisionDemoProject / Configurator / Stations.iniïŒ
ClntIPAdr1=127.0.01
= 3050
- TCPããŒã3050ã
\x00\x00\x00\x35\x4a\x4a\x4a\x4a\x4a\x4a\x4a\x4a\x4a\x4a\x4a\x4a\x4a
ãã®ãœã±ããã§èšé²ããããšã«ãããµãŒãã¹æåŠã è匱æ§ã¯ãFirebird DBMSã®å
žåçãªãã®ã§ãã - SCADAãŠãŒã¶ãŒã®äžæ£ãªè¿œå ïŒ
INSERT INTO USERLIST (USERNAME, USERPASSW, NAME, GRPNAME, FULLNAME, FLAGS, FLAGS_, ALLOWTIME, REGISTERTIME, LASTENTERTIME, LASTPWDCHANGETIME, PWDKEEPPERIOD, STATIONS, DROPTIMEOUT, PSPRDACCESS, PSPWRACCESS, PSPRDACCESS_, PSPWRACCESS_) VALUES ('ITD', '745F87A6B56BACAB', 'itd', '', ', 3, null, null, '2002-01-30 13:11:36.0', '2002-01-30 13:11:36.0', '2002-01-30 13:11:36.0', 0, null, null, null, null, null, null);

SCADAãã©ã¡ãŒã¿ãŒ-ã¢ã©ãŒã ãšã¢ã©ãŒããéçºããããã®å€ãã®ãªãã·ã§ã³
MODBUS'omã·ã³ã°ã«ã§ã¯ãããŸããïŒ
MODBUSã«ãã£ãŠå¶åŸ¡ããããã¬ã¡ããªããŒããçºèŠããã®ã§ãäœæ¥ãéå§ããŸããã ãããã³ã«ã詳ãã調ã¹ããšãå€ãã®è峿·±ãæ©èœãç¹å®ã§ããŸãã
- ããšãã°ãPLCããã€ã¹ããªãã¹ã³ãªã³ãªãŒã¢ãŒãã«ããããšãã§ããŸãã ãã®ã¢ãŒãã§ã¯ãç¹å®ã®æéééã§ã³ãã³ãã®åŠçããã³å®è¡ããPLCãåæã§ããŸããããã«ãããã·ã¹ãã å
šäœãã·ã£ããããŠã³ããå¯èœæ§ããããŸãã MODBUSã¢ãŒããã¯ãã£ã«ãããšã1ã€ã®ããã€ã¹ïŒãã¹ã¿ãŒïŒã®ã¿ã転éãéå§ïŒèŠæ±ãäœæïŒã§ããŸãã ä»ã®ããã€ã¹ïŒã¹ã¬ãŒãïŒã¯ãã¡ã€ã³ããã€ã¹ããèŠæ±ãããããŒã¿ãéä¿¡ããããèŠæ±ãããã¢ã¯ã·ã§ã³ãå®è¡ããŸãã äžè¬çãªãã¹ãããã€ã¹ã«ã¯ããã¹ãïŒHOSTïŒããã»ããµãšããã°ã©ãã³ã°ããã«ãå«ãŸããŸãã å
žåçãªã¹ã¬ãŒãã¯ããã°ã©ããã«ã³ã³ãããŒã©ã§ãã
PLCããã€ã¹ã¯ããããŒããã£ã¹ãèŠæ±ã䜿çšããŠç¹å®ã®ã¹ã¬ãŒãããã€ã¹ãŸãã¯ãã¹ãŠã®ã¹ã¬ãŒãããã€ã¹ã«ç¹å¥ãªãã±ãããéä¿¡ããããšã«ãããããªãã¹ã³ãªã³ãªãŒãã¢ãŒãã«åãæ¿ããããŸãã ã¹ã¬ãŒãããã€ã¹ã¯ãèªåå®ã®ãªã¯ãšã¹ãã«å¿ããŠã¡ãã»ãŒãžãè¿ããŸãã ãããŒããã£ã¹ãèŠæ±ã¯å¿çãè¿ããŸããã - ãã1ã€ã®å
žåçãªééãã¯ããããã³ã«ã®å®è£
ãšã¯äœã®é¢ä¿ããããŸããããç£æ¥çšãããã³ã«ã§åäœããããã€ã¹åŽã®å
¥åããŒã¿ã®èª€ã£ãåŠçã§ãã éçºè
ã¯ãããã±ãŒãžã®æå€§ãµã€ãºãå¶åŸ¡ããããšãå¿ããã¡ã§ããããã¯ã©ãã·ã¥ã«ã€ãªãããããã€ã¹ãæ··ä¹±ãããŸãã ããšãã°ãæåãªClearSCADAããã±ãŒãžã®Modbus SCADAPackãã©ã€ããŒã¯ã60ã260ãã€ãã®ãã±ãããåŠçã§ããŸãã ããã€ã¹ã«äœãèµ·ããããããæ¬æ Œçãªããã±ãŒãžãéä¿¡ããå Žåã¯ãèªåã§ç¢ºèªã§ããŸã:)ã
- åæ§ã®åé¡ã¯ãçµ±åWebãµãŒããŒããFTPããŒã¢ã³ãŸã§ãéåžžã®ãµãŒãã¹ããã³ã³ã³ãããŒã©ãŒã§äœ¿çšããããµãŒãã¹ã®èšèšãšã©ãŒã§ãã ããšãã°ãæåãªAppweb Embedded Web Serverã¯ãApache Benchmarking ToolïŒabïŒã«ãã£ãŠçæããããã©ããã䜿çšããŠã¯ã©ãã·ã¥ããŸããäŸïŒ
ab -n 1000 -c 50 xxx.xxx.xxx.xxx/index.html
-n â
-c â
- ç§ã¯ããªããš1ã€ã®shareãªããªãã¯ãå
±æããŸãã MODBUSãã¬ã¡ããªãŒã³ã³ãããŒã©ãŒã®1ã€ãç¡å¹ã«ãããšã管çè
ã¯ãããã¯ã«é¥ããã³ã³ãããŒã©ãŒãåèµ·åããããã«ç¢ºå®ã«ããã«ç»ãã管çããã«ã«ç§»åããŠãã¹ãŠã®èšå®ã確èªããŸãã ããã§ã¯ãARPã¹ããŒãã£ã³ã°ã䜿çšããŠLANã»ã°ã¡ã³ãã®ãã©ãã£ãã¯ãã¹ãããã£ã³ã°ããããšã«ããããã¹ã¯ãŒããååã§ããŸãã
åé¡ããããŸã
æ¢åã®èŠå¶ã®æ çµã¿ã«é¢ããåé¡ã¯æããã§ããç¹ã«ç£æ¥çšå¶åŸ¡ã·ã¹ãã ãSCADAãªã©ã®éèŠãªã·ã¹ãã ã«ã¯ãæç¢ºã§æç¢ºãªèŠä»¶ã¯ãããŸããã æè¿ãç§ãã¡ã®å°éå®¶ãæšæºã®æè¡ä»æ§ãçºèŠããåçšé»åèšæž¬ã®èªååãããæ
å ±æž¬å®ã·ã¹ãã ã®1ã€ïŒAIIS KUEïŒã§ã®å®è£
ãçºèŠããŸããã éçºè
ã«ãã£ãŠèæ
®ããããã·ã¢é£éŠã®RD FSTECã«ãããšãäžæ£ã¢ã¯ã»ã¹ã«å¯Ÿããä¿è·ã®èŠä»¶ã¯2Bã§ãã æ®å¿µãªããããã®ã¯ã©ã¹ã§ã¯ãä¿è·éåã®ä¿¡å·éä¿¡ã®è©Šè¡ãããã°ã©ã ããããã¯ãŒã¯ããŒããéä¿¡ãã£ãã«ãªã©ãžã®è¢«éšè
ã®ã¢ã¯ã»ã¹ã®å¶åŸ¡ãªã©ãå€ãã®åé¡ãèæ
®ãããŠããŸããã åé¡ïŒ

æãè峿·±ãäºä»¶
èªåããã»ã¹å¶åŸ¡ã·ã¹ãã ã®å®å
šæ§ã«æºãããã·ã¢ã®äŒç€ŸSTC "Stankoinformzaschita"ã¯ã2008ã2010幎ã®å€åœã®èªåããã»ã¹å¶åŸ¡ã·ã¹ãã ã®æ
å ±ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®åæãå«ãåæã¬ããŒããçºè¡ããŸããã ãããã®æãè峿·±ããã®ïŒ
2008幎3æ7æ¥ããããåååçºé»æïŒç±³åœãžã§ãŒãžã¢å·ïŒã®ãããã¯2ããœãããŠã§ã¢ã¢ããããŒãã®ã€ã³ã¹ããŒã«åŸ48æéã®ç·æ¥ã·ã£ããããŠã³ïŒ2006幎ã«ããã°ã©ã å¯èœãªç·æ¥æ
éã«ãããã©ãŠã³ãºãã§ãªãŒåååçºé»æã§åæ§ã®äºä»¶ãçºçããŸããïŒå®çšŒåãããã¯ãŒã¯ããç°åžžãªåºåãããã¯ãŒã¯ãã©ãã£ãã¯ãåä¿¡ããå Žåã®è«çã³ã³ãããŒã©ãŒïŒ;
2008幎5æãããã·ãŒãã¬ãŒèªèšŒå±ïŒTVAïŒïŒãšãã«ã®ãŒäŒç€Ÿã«ã¯11ã®ç³çç«åçºé»æã8ã€ã®ç«åçºé»æã3ã€ã®åååçºé»æã29ã®ç±³åœæ°Žåçºé»æããããŸãïŒãèŠå¶ã¬ãã¥ãŒïŒGAOãHHSïŒã«ãããããŸããŸãªé倧床ã®çŽ2,000ã®è匱æ§ãæããã«ãªããŸããã ã»ãã¥ãªãã£ããŒã«ã®äžã§ãã€ã³ã¿ãŒãããã«æ¥ç¶ãããå®çšŒåãããã¯ãŒã¯ã®ã»ã°ã¡ã³ããã¢ããªã±ãŒã·ã§ã³ãœãããŠã§ã¢ã®è€æ°ã®è匱æ§ãã»ãã¥ãªãã£ã¢ããããŒãã®æ¬ åŠããããã¯ãŒã¯ã¢ãŒããã¯ãã£ããã³ããŒã¿äº€æãã£ãã«ã®èšèšã®ãšã©ãŒãç¹å®ãããŸããã
2008幎8æ26æ¥ãç±³åœé£éŠèªç©ºå±ã®ãã©ã€ããã©ã³ãã³ã°ã»ã³ã¿ãŒã3ããŒã¹ã®ã¢ã¡ãªã«ã®ç©ºæž¯ã®ã³ã³ãããŒã«ã»ã³ã¿ãŒã¯ããã©ã€ããã©ã³ãã³ã°ã»ã³ã¿ãŒã§ã®ã³ã³ãã¥ãŒã¿ãŒã®èª€åäœã®çµæãšããŠç¡å¹ã«ãªããŸããã
ãã®ãããªã·ã¹ãã ãžã®ããã«ãŒäŸµå
¥ã®å€ãã®äºå®ã¯ãèå°è£ã«æ®ã£ãŠããŸãã 倧è¡ã«éãããã®ã¯ç¹å¥ãªåºç€ã«åé¡ããããã®äžã€ãRISIã§ãã
ããã«ãŒãã¬ãžã³ã 7æïŒ07ïŒ150
ãŠãŒãªã»ã«ãã³ã³ããSTCãStankoinformzashchitaãããã«ãŒã賌èªãã