HeartbleedãèŠããŠããŸããïŒ Shellshockã¯ãã¯ãŒã«ãªããŽã¯ãããŸããããåãã¹ã¿ã€ãªãã·ã¥ãªååã®åããéã¿ã«ããŽãªãã«èµ·å ããå¯èœæ§ããããŸãïŒãã®è匱æ§ã®ããŒã±ãã£ã³ã°éšéã®èª°ãããããè¡ãå¿
èŠããããŸãïŒã ããããShellshockã¯HeartbleedãšåããããéèŠãªé³¥ã«ãªãå¯èœæ§ããããŸãã ãããŠä»ãç§ã¯ãç¶æ³ã«å¯ŸåŠããäžèŠãããšããæããã§ãªãè
åšã«èµ·å ããå¯èœæ§ã®ããåé¡ãåé¿ããããã¹ãŠã®äººãå©ãããã¹ãŠã®å¿
èŠãªæ
å ±ããŸãšããããšæããŸãã
æåã«ãåªããè匱æ§åæãè¡ã£ã
Robert Grahamã®
ããã°ããæ
å ±ãå
±æãããŠãã ããã æ¬¡ã®HTTPèŠæ±ãæ€èšããŠãã ããã
target = 0.0.0.0/0 port = 80 banners = true http-user-agent = shellshock-scan (http://blog.erratasec.com/2014/09/bash-shellshock-scan-of-internet.html) http-header = Cookie:() { :; }; ping -c 3 209.126.230.74 http-header = Host:() { :; }; ping -c 3 209.126.230.74 http-header = Referer:() { :; }; ping -c 3 209.126.230.74
è匱ãªIPã®ç¯å²ã«é©çšãããå Žåãæ¬¡ã®çµæãåŸãããŸãã

ç°¡åã«èšãã°ããããŒãã¯ãç¹å¥ã«çް工ãããªã¯ãšã¹ãããããã¯ãŒã¯ã«éä¿¡ããã ãã§ãäžé£ã®ãªã¢ãŒããã·ã³ã«pingãéä¿¡ããŸããã äžå®ã¯ã圌ããããã®ãã·ã³ã«ä»»æã®ã³ãã³ãïŒãã®å Žåã¯ç¡å®³ãªpingïŒãå®è¡ããããã«åŒ·å¶ãããšããäºå®ã«ãã£ãŠåŒãèµ·ããããŸãã
Bashãšã¯äœã§ããããªãå¿
èŠãªã®ã§ããïŒ
ãã§ã«ãããã¯ã«ããå Žåã¯ããã®ã»ã¯ã·ã§ã³ãã¹ãããã§ããŸãã ãã ãã
Bashã«æ
£ããŠããªãå Žåã¯ã以äžã®æ
å ±ãèªãã§å
šäœåãçè§£ããããšããå§ãããŸãã Bashã¯ãéåžžSSHãŸãã¯Telnetæ¥ç¶ã§Linuxããã³Unixã·ã¹ãã ã§åºã䜿çšãããŠããã³ãã³ãã·ã§ã«ïŒã€ã³ã¿ãŒããªã¿ãŒïŒã§ãã Bashã¯ãApacheãªã©ã®WebãµãŒããŒäžã®CGIã¹ã¯ãªããã®ããŒãµãŒãšããŠãæ©èœããŸãã Bashã¯1980幎代ã«ãŸã§ããã®ãŒãã以åã®ã·ã§ã«å®è£
ïŒååã¯
Bourneã·ã§ã«ã«ç±æ¥ïŒããé²åããä¿¡ããããªãã»ã©äººæ°ãââãããŸãã ãã¡ãããä»ã®ã€ã³ã¿ãŒããªã¿ãŒããããŸãããLinuxããã³Mac OS Xã«ã¯ããã©ã«ãã§Bashãä»å±ããŠããããåãã®ããã«éåžžã«æ®åããŠããŸãã ãã®ã€ã³ã¿ããªã¿ã¯
ã ãLinuxã·ã¹ãã ã§æãäžè¬çãªãŠãŒãã£ãªãã£ã®1ã€ã
ãšããŠèªèãããŠããŸãã Shellshockãéåžžã«å±éºãªäž»ãªçç±ã¯ãBashã®valenceå»¶ã§ãã
ãã®
ã°ã©ãã¯ãBashã®éåšæ§ãèŠèŠçã«è¡šããŠããŸãã

ã€ã³ã¿ãŒãããã®ååã¯ãApacheïŒéåžžã¯Linuxã«ã€ã³ã¹ããŒã«ãããŸãïŒã§å®è¡ãããŸãããããã¯æ¬åœã«éåžžã«å€ãã®ããšã§ãã åãèšäºã§ã¯ããã§ã«10åã®æ¢åã®Webãµã€ãã®å¢çãè¶ããŠããããããã®å€ããå€§èŠæš¡ãªãã¹ãã£ã³ã°ã«çœ®ãããŠãããããèšå€§ãªæ°ã®Bashã®ã€ã³ã¹ããŒã«ãããã³ããŒãæ±ã£ãŠããŸãã ãŸããWebãµãŒããŒä»¥å€ã«ããLinuxãå®è¡ããŠããä»ã®å€ãã®ãµãŒããŒãããã€ã¹ãå¿ããªãã§ãã ããã ããããåŸã§ããã«æ»ããŸãã
Bashã¯ãWebãµã€ãã®æ§æãããWebã«ã¡ã©ãªã©ã®åšèŸºæ©åšã®ãã¡ãŒã ãŠã§ã¢ã®ç®¡çãŸã§ãå¹
åºãã·ã¹ãã ã¿ã¹ã¯ã«äœ¿çšãããŸãã ãã®ãããªæ©äŒã¯ãã¹ãŠã®æ¥èšªè
ã«éãããã¹ãã§ã¯ãªããçè«çã«ã¯ç¹å®ã®ã¢ã¯ã»ã¹æš©ãæã€èš±å¯ãŠãŒã¶ãŒã®ã¿ãå©çšã§ããããã«ããå¿
èŠããããŸãã çè«çã«ã
è匱æ§ã®æ¬è³ªã¯äœã§ããïŒ
ç¶æ³ã®é倧床ã¯ã
NISTè匱æ§ããŒã¿ããŒã¹ãã
ã®æ¬¡ã®åŒçšã«ããæšå®ã§ã
ãŸã ã
GNU Bashãã4.3ã¯ãç°å¢å€æ°ã®å€ã®é¢æ°å®çŸ©ã®åŸã®æ«å°Ÿã®æååãåŠçããŸããããã«ããããªã¢ãŒãæ»æè
ã¯çް工ããç°å¢ãä»ããŠä»»æã®ã³ãŒããå®è¡ã§ããŸã ãOpenSSHsshdã®ForceCommandæ©èœãApacheã®mod_cgiããã³mod_cgidã¢ãžã¥ãŒã«HTTPãµãŒããŒãäžç¹å®ã®DHCPã¯ã©ã€ã¢ã³ãã«ãã£ãŠå®è¡ãããã¹ã¯ãªãããããã³ç°å¢ã®èšå®ãBashã®å®è¡ããç¹æš©å¢çãè¶ããŠè¡ããããã®ä»ã®ç¶æ³ã
è匱æ§ã«ã¯ã10ã®ãã¡10ãã®ã¬ãã«ãå²ãåœãŠãããŸããã€ãŸããã©ãã«ãæªãããšã¯ãããŸããã ããã«ãæ»æã®ããããïŒã¢ã¯ã»ã¹ã®è€éãã¯äœãïŒãããã«éèŠãªããšã«ã
CGIã¹ã¯ãªããã䜿çšããŠBashã䜿çšããããã«å¿
èŠãªèªèšŒã®
æ¬ åŠã远å ããŸãã ãã°èªäœã®æ¬è³ªãçè§£ããŸãããã
äž»ãªå±éºæ§ã¯ã颿°ãå®çŸ©ããBashã€ã³ã¿ãŒããªã¿ãŒå
ã§ç°å¢å€æ°ãä»»æã«èšå®ã§ããå¯èœæ§ã«ãããŸãã 颿°ãå®çŸ©ããåŸãBashãã€ã³ã¿ãŒããªã¿ãŒã³ãã³ããåŠçãç¶ãããšåé¡ãå§ãŸããŸããããã«ãããã³ãŒãã€ã³ãžã§ã¯ã·ã§ã³ã«ããæ»æãå¯èœã«ãªããŸãã ãããŒãã®äŸãã1è¡ã ããèŠãŠã¿ãŸãããã
http-header = Cookie:() { :; }; ping -c 3 209.126.230.74
颿°ã®å®çŸ©ã¯
() { :; };
() { :; };
ãã€ã³ã¿ãŒããªã¿ãŒã³ãã³ãã¯pingãšãã®ãã©ã¡ãŒã¿ãŒã§ãã ãã®è¡ãBashã€ã³ã¿ãŒããªã¿ãŒã§åŠçããå Žåãä»»æã®ã³ãã³ããå®è¡ã§ããŸãã Webã®ã³ã³ããã¹ãã§ã¯ãããã¯CGIã¹ã¯ãªãããªã©ã®ã¡ã«ããºã ãéããŠããªãã·ã§ã³ã§ãªã¯ãšã¹ãããããŒãéããŠå®è¡ã§ããŸãã 詳现æ
å ±ã¯
seclists.orgããŒãžã«ãããŸããããã¹ãšã¯ãšãªæååãæœåšçãªæ»æãã¯ãã«ã«ãªãå¯èœæ§ãããããšãããããŸãã
ãã¡ããã
CGIã®æ©èœãç¡å¹ã«ããã ãã§ç¶æ³ãç·©åã§ããŸãã ããããå€ãã®å Žåãããã¯Webãµã€ãã«é倧ãªåœ±é¿ãäžããå°ãªããšããåäœããããšã確èªããããã«åºç¯ãªãã¹ããå¿
èŠã«ãªããŸãã
äžèšã®HTTPãªã¯ãšã¹ãã¯åçŽã§å¹ççã§ããããã®ãããã³ã«ã®å€ãã®å¯èœãªçšéã®1ã€ã«ãããŸããã TelnetãšSSHããããŠæããã«DHCPãèæ
®ã«å
¥ãããšãWebãµãŒããŒãžã®æ»æã«ã€ããŠã®ã¿è©±ããŠãããšããäºå®ã«ãããããããåé¡ã®èŠæš¡ã¯äœåºŠã倧ãããªããŸãã ãããŸã§ã®ãšããã
SSHã§ã®
èªèšŒåŸã«ã®ã¿å±éºããããŸãããå°æ¥ãä»ã®æ»æãã¯ãã«ãèŠã€ããã§ãããã
ãããŒãã®äŸã®ããã«ãæ»æè
ã®èœåã¯ç¹å®ã®ã¢ãã¬ã¹ã®pingãã¯ããã«è¶
ããŠããããšãèŠããŠããå¿
èŠããããŸããããã¯ããªã¢ãŒããã·ã³ãå¶åŸ¡ãããŸãã«ãã®èœåã®ã»ãã®äžäŸã§ãã ããã§ã®è³ªåã¯
ããªã¢ãŒããã·ã³ã®ã€ã³ã¿ãŒããªã¿ãŒã§ããŸããŸãªã³ãã³ããå®è¡ããããšã«ããã䟵å
¥è
ãã©ã®ãããªå®³ãåãŒãå¯èœæ§ãããããšããããšã§ããæœåšçãªçµæã¯äœã§ããïŒ
ã€ã³ã¿ããªã¿ãžã®ã¢ã¯ã»ã¹ãååŸããããšã¯ãæ»æè
ã«ãšã£ãŠåžžã«å€§ããªåå©ã§ãããããã¯ãé©åãªæš©éãæã€ãµãŒããŒã®å¶åŸ¡ãååŸããããšã«çããããã§ãã å
éšããŒã¿ãžã®ã¢ã¯ã»ã¹ãç°å¢ã®åæ§æããã«ãŠã§ã¢ã®æ¡æ£ãªã©ã å¯èœæ§ã¯ã»ãŒç¡éã§ãããèªååãããŠããŸãã 倿°ã®ãã·ã³ã«å¯ŸããŠç°¡åã«é©çšã§ãã
ãšã¯ã¹ããã€ãã®äŸã¯ãã§ã«éåžžã«å€ããããŸãã
æ®å¿µãªãããã€ã³ã¿ãŒãããWebãµãŒããŒã®ååã®ã³ãã³ãã€ã³ã¿ãŒããªã¿ãŒã§ä»»æã®ã³ãŒããå®è¡ããããšã«ãªããšãå¯èœæ§ã¯éåžžã«å€§ãããªããŸãã æããã§æãåä»ãªã®ã¯ã
å
éšãã¡ã€ã«ã«ã¢ã¯ã»ã¹ããããšã§ã ã ãã¹ã¯ãŒããšæ§æãå«ããã¡ã€ã«ãæãéèŠã§ãããäžè¬çã«ãã¹ãŠã®ãã¡ã€ã«ã«ã¢ã¯ã»ã¹ã§ããŸãã
åãããšã¯ããªã¢ãŒããã·ã³ã«ãã¡ã€ã«ãæžãèŸŒãæ©èœã«ãåœãŠã¯ãŸããŸãã ããã¯ããã«ãŠã§ã¢ã®æ¡æ£ã¯èšããŸã§ããªããããŒãžãä»ã®äººã®ãŠã§ããµã€ãã«çœ®ãæããæãç°¡åãªæ¹æ³ã®1ã€ã§ãã ãŸãã¯ãããã¯ã©ãã§ããïŒ

ã¯ãŒã ã«é¢ããŠèšãã°ãã¿ãŒã²ããã·ã¹ãã äžã«ç¬èªã®ã³ããŒãäœæããæªæã®ãããœãããŠã§ã¢ãæå³ããŸãã éåžžã«å¹æçãªã¯ãŒã ã®äŸã¯ã1æ¥ä»¥å
ã«äœçŸäžãã®WebããŒãžã«ææãã
Samy XSSã¯ãŒã ã§ãã
Shellshockã®å±éºæ§ã¯ãã»ãšãã©ã®ãã·ã³ã§ãã®è匱æ§ã解決ããããŸã§ãç¹ã«åææ®µéã§ææçã®æµè¡ãå§ãŸãå¯èœæ§ããããšããäºå®ã«ããããŸãã ææãããã·ã³èªäœãæ°ããç ç²è
ãæ¢ããŠææããŸãã ãããŠä»ããã¹ãŠã®å
Œ
±ã®ãã·ã³ãå±éºã«ãããããŠãããäŒæ¥ã®ãã¡ã€ã¢ãŠã©ãŒã«ã貫éãããšããä¿åããå Žæã¯ãããŸããã
人ã
ã¯ãã§ã«ããããã§ã«å©çšããŠããŸãã çŸåšãå®éã®è»æ¡ç«¶äºã¯ãã®ã£ãããéæããã人ãšã®ã£ãããåããã人ã®éã§æ¬æ Œçã§ãã
圱é¿ãåããBashã®ããŒãžã§ã³ã¯äœã§ããïŒ
4.3ãå«ãéå»25幎éã®ãã¹ãŠã®ããŒãžã§ã³ã éå»2幎éOpenSSLã«ãããããŠããHeartbleedãšæ¯èŒããŠãã ããã ã¯ãã人ã
ã¯ããŒãžã§ã³ãæŽæ°ããŠããŸãããããã¯äœç³»çã«è¡ãããŠããŸããããšã«ãããShellshockã¯Heartbleedããã
ã¯ããã«å€ãã®ãã·ã³ãè
ããŠ
ããŸãã
æ®å¿µãªããããã®è匱æ§ã¯å°æ¥ã®ããŒãžã§ã³ã§ãæç¶ããå¯èœæ§ããããŸãã
ãããã«é¢ããæ
å ±ã¯ãã§ã«ãã
ãŸãããããŸã广çã§ã¯ãããŸããã§ãã ã ãããã£ãŠããã®è匱æ§ã¯éåžžã«æ
éã«ç£èŠããå¿
èŠããããŸãããããããã€ã³ã¹ããŒã«ããåŸã«å¿ããããšãã§ãããã®ã®1ã€ã§ã¯ãããŸããã
è匱æ§ã¯ãã€çºèŠãããŸãããïŒ
ç§ãèŠã€ããæåã®èšåã¯ãæ°Žææ¥ã®
ååŸ2æïŒã°ãªãããžæšæºæïŒã«çºè¡ããã
seclists.orgã®éåžžã«çãèšäºã«ãã
ãŸãã ã 1æéåŸã«è©³çްæ
å ±ã
åããªãœãŒã¹ã«
æçš¿ãããŸãã ã ãããã£ãŠãããã¯éåžžã«ãæ°é®®ãªããã¥ãŒã¹ã§ããããéçãã§ã®ãšã¯ã¹ããã€ãã®å€§èŠæš¡ãªåºçŸã«ã€ããŠè©±ãã®ã¯ææå°æ©ã§ãã ããããããã¯ããã«èµ·ããå¯èœæ§ãããã確çã¯1æéããšã«å¢å ããŸãã
åè¿°ã®ããã«ããã®è匱æ§ã¯éå»25幎éã«äœæãããBashã®ãã¹ãŠã®ããŒãžã§ã³ã«ååšããŸãã ãã®ãããçè«çã«ã¯ããããŸã§ãã£ãšãç¥èã®ãã人ã
ãããã䜿çšã§ããŸããã
ããã€ã¹ã¯å±éºã«ãããããŠããŸããïŒ
Bashã䜿çšããå¯èœæ§ã®ããå€ãã®ããã€ã¹ãããããã質åã¯è峿·±ããã®ã§ãã
ãã©ã°ãã
ãã¢ãã㯠ã
é»çã«è³ããŸã§ãããããå°ããªãã®ã®IPã¢ãã¬ã¹ã®å²ãåœãŠãæ®åãã€ã€ãããšããç§ã¯ãã¢ãã®ã€ã³ã¿ãŒããããïŒIoTïŒãæå³ããŸãã å€ãã®ãã€ã³ã¿ãŒãããé¢é£ãã§ã¯ãçµã¿èŸŒã¿ã®LinuxããŒãžã§ã³ãšBashã䜿çšããŠããŸãã åãããã€ã¹ããã§ã«æ·±å»ãªã»ãã¥ãªãã£ããŒã«ã瀺ããŠããŸããããšãã°ã
LIFXé»çããWi-Fièå¥ããŒã¿ãååŸã§ããŸã ã ãã®ãããShellshockã®ãããªè匱æ§ããªããŠããããããçš®é¡ã®ããã€ã¹ãšãªããžã§ã¯ãããããã¯ãŒã¯ã«æ¥ç¶ããããšã§ã以åã¯çµ¶å¯Ÿã«å®å
šã§ãã£ãé åã§å€ãã®æ°ããè匱æ§ãçºçããç¶æ³ã«ãªããŸããã
ããã¯ç§ãã¡ã«å€ãã®æ°ãã課é¡ãæç€ºããŸãã ããšãã°ãé»çã«å®æçã«ãããã貌ãããšãèããŠãã人ã¯ããŸããïŒ ãã®ãããªããã€ã¹ã®ãèä¹
æ§ããèãããšã誰ãããã¡ãŒã ãŠã§ã¢ã®ãµããŒãã«åŸäºããããšã¯ãŸããããŸããã æ°å¹Žåã«èµ·ãã£ã
Trendnetã«ã¡ã©ã®
話ãæãåºããŠãã ããã ééããªããèšå€§ãªæ°ã®ãœãããŠã§ã¢ããŸã ãããã¯ãŒã¯ã«æ¥ç¶ããããŸãŸã«ãªã£ãŠããŸãããœãããŠã§ã¢ãæŽæ°ãããšãã芳ç¹ããããã°ã眮ãå¿ããæ¹ãã¯ããã«ç°¡åã ããã§ãã ææè
ãèªåãæ®åœ±ãããŠããããšããç¥ããªãå Žåããã®
ãããªã«ã¡ã©ããã®åçã®å
¬éã«å®å
šã«å°å¿µããTwitterã¢ã«ãŠã³ãããããŸãã ããã¯å€§ããªåé¡ã§ããåšèŸºæ©åšã®ãœãããŠã§ã¢ãæŽæ°ããã®ã¯é£ããå Žåãå€ããããæéã®çµéãšãšãã«ãããããçš®é¡ã®è匱æ§ãæã€ããå€ãã®æ©åšããªããžã§ã¯ãã«åãå²ãŸããŸãã
ããããBashã€ã³ã¿ãŒããªã¿ãŒã¯ãããŒã ã«ãŒã¿ãŒãªã©ã®å€ãã®äœ¿ãæ
£ããããã€ã¹ã«ãæ¢ã«ååšããŠããŸãã æåŸã«ãã¡ãŒã ãŠã§ã¢ãæŽæ°ããã®ã¯ãã€ã§ããïŒ ãã¡ããããã®ããã¹ããèªãã°ããããããã®ãããªããšã宿çã«è¡ã£ãŠãã人ã®äžäººã§ãããã ããããäžè¬ãŠãŒã¶ãŒã¯ããã«ã€ããŠãèããŠããŸããã
ãã€ã¯ããœããã®ãœãããŠã§ã¢ã§ãã¹ãŠãæ©èœããŸããå¿é
ããå¿
èŠããããŸããïŒ
çãçãã¯ããŒãé·ãçãã¯ã€ãšã¹ã§ãã Bash for Windowsã®ããŒãžã§ã³ãååšãããšããäºå®ã«ããããããããã®ãŠãŒãã£ãªãã£ã¯ãã®ãšã³ã·ã¹ãã ã§ã¯æ®åããŠããŸããã Shellshockã®WindowsããŒãžã§ã³ã®Bashãè匱ãã©ãããäžæã§ãã
ãã ããWindowsç°å¢ã®ã¿ã§äœæ¥ããŠãããšããäºå®ã¯ããããã¯ãŒã¯äžã®ç¹å®ã®ã¿ã¹ã¯ãåŠçãããã·ã³ã§Bashãå©çšã§ããªãããšãæå³ãããã®ã§ã¯ãããŸããã 説æåçãšããŠã
Nick Craverã®
æçš¿ããã€ã©ã¹ããæããããšæããŸãã

ã芧ã®ãšããããã©ãã£ãã¯ã¯Windowsç°å¢ããWindows以å€ã®ããã€ã¹ãçµç±ããŠæµããŸãã ãã¡ã€ã¢ãŠã©ãŒã«ã«å¯Ÿããæš©éãæã€ã³ã³ããŒãã³ãããããŸãããããã¯Shellshockã䜿çšããŠå®è¡ã§ããŸããïŒ
ç§ã¯ã·ã¹ãã 管çè
ã§ãããäœãã§ããŸããïŒ
ãŸããå±éºã«ãããããŠãããã©ããã倿ããã®ã¯éåžžã«ç°¡åã§ãã ã€ã³ã¿ããªã¿ã§ãã®ã³ãã³ããå®è¡ããã ãã§ãïŒå
ã®ã³ãã³ã-çŽPkruglovãå°ã倿Žããããšãã§ããŸããïŒïŒ
env X="() { :;} ; echo busted" bash -c "echo stuff"
ãç¡å¹ãã衚瀺ãããå Žåãè匱æ§ãååšããŠããŸãã
ãã¡ãããæåã«ç©Žãéããå¿
èŠããããŸãã ãã®ãããã«ãããBash颿°ã®æåŸã«ä»ã®äººã®ã³ãŒããå®è¡ããããªã¹ã¯ã倧å¹
ã«åæžãããŸãã
Red Hatãªã©ã®å€ãã®Linuxãã£ã¹ããªãã¥ãŒã·ã§ã³ã®æé ã¯ãã§ã«ç»å ŽããŠããã®ã§ãã§ããã ãæ©ããããè¡ããŸãïŒå®éãã»ãšãã©ã®ãã£ã¹ããªãã¥ãŒã·ã§ã³ã®ãããã¯ãã§ã«ãªãªãŒã¹ãããŠããŸã-pkruglovã«æ³šæããŠãã ããïŒã
䟵å
¥æ€ç¥ã·ã¹ãã ïŒIDSïŒãæŽæ°ããããã®æé ã¯ãã§ã«ç»å ŽããŠãããç¹ã«ããããã€ã³ã¹ããŒã«ããåã«é·æéã®ãã¹ããå¿
èŠãªçµç¹ã§ã¯ãããã«ããããæ¡çšããå¿
èŠããããŸãã Qualysãããã€ããŒã¯ãæ»æãç¹å®ããç¬èªã®æ¹æ³ã
ææ¡ããŠãããããããä»ã®å€ãã®IDSãããã€ããŒããã®åé¡ã«åãçµãã§ããŸãã
ããåçãªæ¹æ³ã«ã¯ãBashãå¥ã®ã€ã³ã¿ãŒããªã¿ãŒã«çœ®ãæãããããªã¹ã¯ã®ããã·ã¹ãã ããããã¯ããããšãå«ãŸããŸãã ã©ã¡ãã®æ¹æ³ãåºç¯å²ã«åœ±é¿ããå¯èœæ§ãããããã軜çã«äœ¿çšããªãã§ãã ããã ããããããããŸãã«Shellshockã®äž»ãªæ©èœã«ãªãå¯èœæ§ããããŸãã
å®éã®ããžãã¹ã«æ·±å»ãªåœ±é¿ãäžããå¯èœæ§ã®ããå°é£ãªæ±ºå®ãè¿
éã«æ¡çšããæœåšçã«ã¯ããã«å€§ããªæå®³ãåé¿ããŸãããã1ã€ã®è³ªåã¯ãã£ãšæ·±å»ã§ããShellshockã¯ä»¥åã«èª°ããæäœããããšããããŸããïŒ æ»æãã¯ãã«ãä¿®æ£ãããªãã£ããã©ããã倿ããããšã¯å°é£ã§ãã ãããŠãæ»æãHTTPãŸãã¯POSTãªã¯ãšã¹ããä»ããŠå®è¡ãããå Žåãããã¯ãã°ãã°èµ·ãããŸããã ãShellshockãä»ããŠæ»æãããã®ãããšå°ããããå Žåãæãäžè¬çãªçãã¯æ¬¡ã®ãšããã§ãããã®è匱æ§ãéãããšãã蚌æ ã¯ãããŸããã ããã«ãããWebãµã€ããä»ã®ã·ã¹ãã ã®ææè
ã¯ããããã䟵害ããããã©ããã«ã€ããŠäžæå¿«ãªçå¿µãæ±ãããã«ãªããŸãã
ç§ã¯ãŠãŒã¶ãŒã§ãããäœãã§ããŸããïŒ
ç¹å®ã®ç¶æ³ã«äŸåããŸãã Mac OS Xã䜿çšããŠããå Žåããã®è匱æ§ã¯æšæºã®æŽæ°ã¡ã«ããºã ã䜿çšããŠç°¡åã«ïŒã§ããã°ããã«ïŒçµäºããŸãã ããªããå±éºã«ãããããŠãããã©ããã
ãã¹ãããããšã¯ç°¡åã§ãïŒ

ããã¯åçŽãªãã¹ãã§ãããå¹³åçãªMacãŠãŒã¶ãŒã¯ç°¡åã«ã¢ããã€ã¹ã«åŸã£ãŠBashãåã³ã³ãã€ã«ã§ãããšã¯æããŸããã
ããå¿é
ãªã®ã¯ãã«ãŒã¿ãŒãªã©ããœãããŠã§ã¢ã®æŽæ°ãé£ããããã€ã¹ã§ãã ãã®åé¡ã¯ãã«ãŒã¿ãŒããããã€ããŒã«ãã£ãŠã¬ã³ã¿ã«ãããããšãå€ãããŠãŒã¶ãŒãã³ã³ãããŒã«ããã«ã«ã¢ã¯ã»ã¹ã§ããªããšããäºå®ã«ãã£ãŠæªåããŸãã ããã«èšå€§ãªæ°ã®ã¢ãã«ãæããŸãã åæã«ãã«ãŒã¿ãŒã®ãã©ãã·ã¥ãå¹³åçãªãŠãŒã¶ãŒã®éåžžã®ã¿ã¹ã¯ã®ãªã¹ãã«å«ãŸããŠããŸããã
èŠããã«ããŠãŒã¶ãŒåãã®ãã³ãã¯æ¬¡ã®ãšããã§ããã»ãã¥ãªãã£æŽæ°ããã°ã©ã ãã€ã³ã¹ããŒã«ãããã¡ãŒã ãŠã§ã¢ã§äœ¿çšããæ©åšã®ãããã€ããŒããã³ãµãã©ã€ã€ãŒã®ã¢ããã€ã¹ãç¡èŠããªãã§ãã ããã ãã®ãããªã¡ãã»ãŒãžã¯ãå€ãã®å Žåãããã¡ãã·ã§ããã«ãªããŠãŒã¶ãŒã®ææãæªçšãããã£ãã·ã³ã°æ»æäžã«å±ããæ
å ±ãæ±ããã¡ãŒã«ããœãããŠã§ã¢ã®èµ·åæ¹æ³ã«é¢ããæç€ºãäžããã¡ãŒã«ã«æ³šæããŠãã ããã
ãŸãšã
ã©ããããç§ãã¡ã¯ãã®è匱æ§ã®æ·±ãã«ã€ããŠã®ç ç©¶ã®ãŸãã«å§ãŸãã«éããŸããã ãã¡ãããå€ãã®é¡äŒŒç¹ãHeartbleedã§æãããããã€ãã®ç¹ã§ç§ãã¡ãå©ããŸããã Heartbleedã®äŸã䜿çšãããšãç¶æ³ãéåžžã«æ¥éã«æªåããå¯èœæ§ãããããšãããã£ãŠãããçµæ
ãéåžžã«é·ãéããéããŠ
ããŸãã
ãããããã®å Žåããã¹ãŠãHeartbleedãããã¯ããã«æªãå¯èœæ§ããããŸãã ãã®è匱æ§ã«ãããææãããã·ã³ã®ã¡ã¢ãªå
ã®å°éã®ããŒã¿ãžã®ãªã¢ãŒãã¢ã¯ã»ã¹ãèš±å¯ãããå ŽåãShellshockã¯ä»»æã®ã³ãŒããæ¿å
¥ããããšãå¯èœã«ããŸããããã¯æœåšçã«ã¯ããã«å±éºã§ãã ãã®ç¹ã§ãç§ã¯ãããŒãã«åæããŸãã

1æ¥ã2æ¥çµã€ãšæããŸããããããã¯åãªãè±ã§ããããšãããããŸãã
UPDã ç¶ç¶äž
-bash www.linux.org.ru/news/security/10892232ã§æ°ããè匱æ§ãçºèŠãã
ãŸããè匱æ§ããã§ãã¯ããããã®æ±çšã¹ã¯ãªãã
github.com/hannob/bashcheck