
ä»é±ã®æã人æ°ã®ãããã¥ãŒã¹ã®3ã€ã¯ãã»ãã¥ãªãã£ã€ã³ããªãžã§ã³ã¹ã®ãããã¯ã«äœããã®åœ¢ã§é¢é£ããŠããŸã-ãã1ã€ã®ç¿»èš³ãäžååã§ãæ
å ±ã»ãã¥ãªãã£æ¥çã§æ¯èŒçæ°ããçšèªã§ãã ã€ã³ããªãžã§ã³ã¹ãšã¯ããŠãŒã¶ãŒããã³äŒæ¥ããµã€ããŒè
åšããäœããã®åœ¢ã§ä¿è·ããã®ã«åœ¹ç«ã€ç¥èã®éãæããŸãã åå·ã®çµããã«åŒçšãããŠãŒãžã³ã«ã¹ãã«ã¹ããŒã®æ¬ããã®åŒçšã¯ãåäžçŽã®90幎代åé ã®ç¥èèŠä»¶ãåæ ããŠããŸãã1人ã®å°éå®¶ã¯ããµã€ããŒè
åšããä¿è·ããããã«å¿
èŠãªãã¹ãŠã念é ã«çœ®ãããšãã§ããŸãã ææã𿡿£ã®å
žåçãªæ¹æ³ãè
åšãšæ²»çã®çš®é¡ã決å®ããæ¹æ³ã«é¢ããæ
å ±ã è¯ãæä»£ããããŸãããã圌ãã¯é·ãéè¡ã£ãŠããŸããã çŸä»£ã®è
åšãçè§£ããã«ã¯ãLuaããã°ã©ãã³ã°èšèªããäžåœèªã®æ¹èšãŸã§ãããŒããã©ã€ããã¡ãŒã ãŠã§ã¢ã®æ©èœããããŒã¿æå·åã®çè«ãŸã§ãå¹
åºãç¥èãå¿
èŠã§ãã
ããã«ã誰ã«ãšã£ãŠãæ®éçã§å¹æçãªå°éç¥èã¯ãããŸããã åäŒæ¥ã«ã¯ãITã€ã³ãã©ã¹ãã©ã¯ãã£ã®ç¬èªã®èŠçŽ ã»ããããããè匱æ§ãšæœåšçãªäŸµå
¥ãã€ã³ãããããŸãã åœç¶ãä¿è·ã«é¢é£ããåäžã®ã¬ã·ãã¯ãããŸããã é«å質ã®äŒæ¥ã»ãã¥ãªãã£ã«ã¯ãäžè¬çãªãµã€ããŒè
åšã®ç¥èãšãç¹å®ã®ç¶æ³ãžã®é©ç𿹿³ãå¿
èŠã§ãã ããç°¡åãªå Žåã¯ãä¿è·ãç ŽãããïŒãŸãã¯ãã§ã«ç ŽãããïŒå Žæãç¥ãå¿
èŠããããŸããããã«ããã®ç¥èã¯ããé«äŸ¡ã«è©äŸ¡ãããŸãã æåŸã«ãéåžžã«å€ãã®è
åšãšçš®é¡ã®æ»æããããããããããã¹ãŠãæã§åæããããšãé£ãããªããŸãã æ¥åžžçãªæäœãè¡ãèªååããã³æ©æ¢°åŠç¿ã·ã¹ãã ã®
æŠéãã¥ãŒããã€ããããããæ§ç¯ããå¿
èŠããããŸãã 1992幎ã®ãŠã€ã«ã¹ã«é¢ãã120ããŒãžã®æŠã®é¡äŒŒç©ã¯ãçŸåšããã¿ãã€ãèŠæš¡ã®ããŒã¿ãå°éå®¶ã®éã¢ã«ãŽãªãºã ççµéšãšã¹ãã«ããããŠäººå·¥ç¥èœãšåŒã°ãããã®ã§ãã ãã ãã詊éšã®ãããã¯ã«ã€ããŠã¯äŸã§èª¬æããæ¹ãç°¡åã§ãã è¡ãã
ãã¹ãŠã®åé¡ã¯
ã¿ã°ã§å
¥æã§ããŸãã
Socatã®UnixãŠãŒãã£ãªãã£ã¯ãDiffie-Hellmanã®ã¢ã«ãŽãªãºã ã®è匱ãªå®è£
ã䜿çšããŠãã»ãã¥ã¢ãªæ¥ç¶ãäœæããééããçããããã«ã¯éçºè
ã®æªæãããæã¡åºããŸããããã¥ãŒã¹ ã
Socatã¯ã2ã€ã®ç°ãªããã£ãã«éã§ããŒã¿ã転éããããã«äœ¿çšããããªãŒãã³ãœãŒã¹ã®UnixãŠãŒãã£ãªãã£ã§ãã ããšãã°ããããã¯ãŒã¯ãã©ãã£ãã¯ããã¡ã€ã«ã«ãªãã€ã¬ã¯ããããããããã¯ãŒã¯éã§ãã³ãã«ã転éãããããŠããããã¯ãŒã¯ãã©ãã£ãã¯ãåæã§ããŸãã ãŠãŒãã£ãªãã£ã¯ãããã¯ãŒã¯ãšçžäºäœçšãããããç¹ã«å®å
šãªããŒã¿è»¢éããµããŒãããŸããã€ãŸãã察å¿ããæ¥ç¶ââã»ããã¢ããã¢ã«ãŽãªãºã ãå®è£
ããŸãã ç¹ã«ãç§ã®ãã€ãžã§ã¹ãã®ããŒãžã«è€æ°åç»å ŽããDiffie-Hellmanã¢ã«ãŽãªãºã ã«ãããããŒãå®å
šã«äº€æã§ããè€éãªèšç®ïŒãã®å Žåã¯1024ãããïŒã«å€§ããªé·ãã®åºæ¬çŽ æ°ã䜿çšã§ããŸãã
ãŸãããŸãããã®ãè匱æ§ãã䜿çšããŠäœãããããã³ã°ããããšã¯ãŸã æéãããããéåžžã«é«äŸ¡ã§ããããã®ã¢ã«ãŽãªãºã ã®ã³ã³ããã¹ãã§ã¯1024ãããçŽ æ°ããã§ã«å®å
šã§ãªãããšããã§ã«
蚌æã
ããŠããŸãã 第äºã«ããã¥ãŒã¹ã¯socatã§äœ¿çšãããŠããæ°åãåçŽã§ã¯ãªãã£ãããšã§ãã ããæå³ã§ã¯ãå æ°åè§£ãããŸãã ãã®ãããªãšã©ãŒã®çµæãè©äŸ¡ããã«ã¯ãããšãã°Stackexchangeã«é¢ãã
ãã®ãã°ãããè°è«ãèªãã§ãã ããã èŠããã«ã匱ããããDiffie-Hellmanã¢ã«ãŽãªãºã ã䜿çšããæå·åãããããŒã¿äº€æã®ã¯ã©ããã³ã°ã¯ããã«ç°¡åã«ãªããŸãããããã§ãããªãè€éã§æéã®ãããèšç®ã®åé¡ã§ãã
ãŠãŒãã£ãªãã£ã¯ãªãŒãã³ãœãŒã¹ã§ãããããç¹å®ã®äœæè
ã«ãšã©ãŒã®åºçŸã远跡ããããšã¯é£ãããããŸããã§ããã è匱ãªã³ãŒãã远å ããæç¹ã§ãç¹å®ã®Zhiang Wangã§ããããšã倿ãããããäžè¬çã«Oracleã®åŸæ¥å¡ã¯å¿åæ§ãç¶æããããšããŠããŸããã§ããã é ãçç±ã¯ãããŸãããïŒ ãŸããäžè¬çã«ãããã°ã©ã ã³ãŒãã«æ¢ç¥ã®è匱æ§ãå°å
¥ããããšã¯ãããã¯ãã¢ãåœè£
ãã詊ã¿ãšè§£éã§ããŸãã sorecatã®ã¡ã³ãããŒã§ããGerhard Riegerã¯ãThreatpost
ãšã®ã€ã³ã¿ãã¥ãŒã§ ãããã¯ãŸã ééãã ãšèããŠããŸãã 2ã€ã®çç±ããããŸãã 第äžã«ããã©ãã¯ãã«ããŒãã詊ã¿ã¯ãããŸããã§ããããããŠã第äºã«ã誰ããããã¯ãã¢ãåã蟌ã¿ãããšæããªãã圌ãã¯ããããããäžåšçšãªæ¹æ³ã䜿ãã§ãããã äžæ¹ãçŽ æ°ãæ¬åœã«çŽ æ°ãã©ãããïŒèšç®ã«ãã£ãŠïŒæ€èšŒããããšã¯å°é£ã§ãã ã¡ãªã¿ã«å
é±ãOpenSSLã©ã€ãã©ãªèªäœã®ããããåæ§ã®åé¡ã解決ããŸãããããã§ã¯Diffie-Hellmanããä¿¡é Œã§ããªããçŽ æ°ã䜿çšããçè«çã«æ»æãå¯èœã«ããŸããã
äžè¬ã«ããã®ãã¥ãŒã¹ã¯ã以åã®ãã®ãšåæ§ã«ããœãããŠã§ã¢éçºè
ããã³æå·åã¢ã«ãŽãªãºã ã®ç ç©¶è
ã«ãã£ãŠãªãŒãã²ãŒã ãšè§£éãããå¯èœæ§ããããŸããè匱æ§ã¯éããããŠãããå®çšåãããå¯èœæ§ã¯äœãã§ãã ç¶æ³ã®ãã®åŽé¢ã¯è峿·±ããã®ã§ããã©ããæãã°ãããããããªãå Žåããããæ€åºããã®ã¯éåžžã«é£ãããã°ã§ãã ãããããããsocatã§æãå±éºãªè匱æ§ããã®ãããªæ³šç®ã济ã³ãªãã£ãçç±ã§ãããã®ãã¥ãŒã¹ã¯Threatpostã§1é±éã§æã人æ°ããããŸããã æå·åã¯äžè¬ã«ãã»ãã¥ãªãã£ç£æ»ã«å¿
èŠãªå°éç¥èã®æ°Žæºã倧å¹
ã«åŒãäžããŸãã åé¡ã¯ãé
ããæ©ãããè€éããå¢ãããã®ãããªã¿ã¹ã¯ããåœæ°çµæžã®ä»ã®åéã«çŸããããšã§ãã ãããŸã§ã®éããã¹ãŠãæªãããã§ã¯ãããŸããããã°ã¯ã¯ããŒãºãããåºæ¬çãªçŽ æ°ã¯å®èšŒæžã¿ã®ä¿¡é Œã§ãã2048ãããã®ãã®ã«çœ®ãæããããŸããã ããããsocatã®æœåšçãªè匱æ§ã¯ãã³ãŒãã«æ£ç¢ºã«1幎éé ãããŠããŸããã
VirusTotalããã€ã¯ãã³ãŒããã§ãã«ãŒãµãŒãã¹ãå°å
¥ãã¥ãŒã¹ ã
VirusTotalãµãŒãã¹ã䜿çšãããšãããŸããŸãªã¡ãŒã«ãŒã®ã¢ã³ããŠã€ã«ã¹ãšã³ãžã³ã§çããããã¡ã€ã«ãã¹ãã£ã³ã§ããŸãã å€ãã®å Žåãã»ãã¥ãªãã£ãœãããŠã§ã¢ã®æå¹æ§ã«é¢ããçŽäºã®æåŸã®è°è«ã«ãªããããã«å€ãã®å Žåããã®ãããªãæ€åºãã®çµæã¯èªç±ã«è§£éãããå®å
šã«æ£ããè§£éãããŸããã 2012幎以éGoogleãææãããã®ãµãŒãã¹ã¯ãã»ãã¥ãªãã£ç ç©¶è
ã«ãšã£ãŠãæçšãªããŒã«ã§ãããæªæã®ãããã£ã³ããŒã³ã®æŽ»åã«é¢ãã远å ã®ãã³ãïŒããšãã°ãæªæã®ããã¢ã€ãã ããã€ã©ãã§ããŠã³ããŒãããããã«é¢ããæ
å ±ïŒãæäŸããŸãã
æ°ãããµãŒãã¹ã¯ãæšæºã®VirusTotalãªãã¬ãŒãã£ã³ã°ã¢ãã«ããã¯é¢ããŠããŸãã 圌ã¯ãã³ã³ãã¥ãŒã¿ãŒãšã©ãããããã®BIOSãå«ããã€ã¯ãã³ãŒããåæããå€ãã®ãã©ã¡ãŒã¿ãŒã«é¢ããè©æ±ºãåºããŸãã ãã®äžïŒã¿ãŒã²ãããã³ããŒïŒãã¡ãŒã ãŠã§ã¢ã®å¯Ÿè±¡ãšãªãããã€ã¹ïŒã決å®ããããã®ãã¡ãŒã ãŠã§ã¢ã«å«ãŸããè¡ã®åæãèšŒææžã®æœåºãããŒã¿ãã«å®è¡å¯èœã³ãŒãã®æœåº-ã€ãŸããããšãã°ãBIOSã«æ ŒçŽãããŠããããWindowsäžã§å®è¡ããããã«èšèšãããããã°ã©ã çè«çã«ã¯åŸè
ã¯ç¹ã«è峿·±ã-ããã¯ãBIOSã§æªæã®ããã³ãŒãã確å®ã«é ããã€ã³ã¹ããŒã«ãããã·ã¹ãã ã§äœããã®ç®çã§æš©éãé«ããŠå®è¡ããåé€ãããå Žåã¯åã€ã³ã¹ããŒã«ã§ããæ¹æ³ã§ãã
æšå¹Žãæ¹çšåŒãã£ã³ããŒã³ã«é¢ããç ç©¶æã®
ç ç©¶ã«ãã ããã¡ãŒã ãŠã§ã¢ã«æ³šç®ãéãŸããŸããã ç¹ã«ãããŒããã©ã€ãã®ãã¡ãŒã ãŠã§ã¢ã倿ŽããããŒã«ãèŠã€ãããããŒã¿ãå®å
šã«åé€ãããå Žåã§ããæ»æãããã·ã¹ãã ãžã®äžæ£ã¢ã¯ã»ã¹ã埩å
ã§ããŸãã ãã®ãããªçºèŠã ãã§ãéçºãžã®ååãªæè³ãããã°ãæ€åºããã³åæ¢ãéåžžã«å°é£ãªæ»æã¢ãã«ãäœæã§ããããšãæããã«ãªããŸããã äžè¬ã«ãçŸä»£ã®ã³ã³ãã¥ãŒã¿ãŒã®åã
ã®ã³ã³ããŒãã³ãã®BIOSããã³ãã¡ãŒã ãŠã§ã¢ã¯ã倧éšåããã©ãã¯ããŒã«ãšããŠæç€ºãããŸããããã®äžã«ã¯äœãæç¢ºã§ã¯ãããŸããã ãããŠãããã«ã¯å€ãã®ããšãèµ·ããåŸãŸãã ä»åºŠã¯BIOSã«ã€ããŠã®ãã1ã€ã®äŸã¯ã
Absolute Computraceã®çé£é²æ¢æ¹æ³ã§ãã
äžè¬çã«ãåæããå¿
èŠããããVirusTotalã¯éåžžã«åºæ¬çã§ããããã®ããã®ããŒã«ãæäŸããŸãã ããããããã§ã®ãã€ã³ãã¯ãããŒã«ã®å質ã ãã§ãªããç ç©¶ã®ããã®æ
å ±éã«ããããŸãã ãã®ãããªæ©èœã䜿çšããé »åºŠãé«ãã»ã©ãããå€ãã®ç°ãªãBIOSããã³ä»ã®ãã¡ãŒã ãŠã§ã¢ãåéãããæ¯èŒåæãè¡ãã®ã容æã«ãªããŸãã æ°ããããã¯ãã¢ãã©ããã§èŠã€ããå¯èœæ§ãé«ããªããšåæã«ãåãã¡ãŒã ãŠã§ã¢ãæåã§åè§£ããå¿
èŠããªããªããŸãã å®éãããã¯ãå°éå®¶ãäºåã«åéãã倧éã®ããŒã¿ã«åºã¥ããŠèª¿æ»ãè¡ãå Žåã®æ
å ±ã»ãã¥ãªãã£ã®çºå±ã®è¯ãäŸã§ãã ãã¡ãŒã ãŠã§ã¢ã®è§£æã®äŸã¯
ãã¡ãã§ãã
Androidã¯WiFiãã©ã€ããŒã®è匱æ§ãéããŸããã¥ãŒã¹ ã ã»ãã¥ãªãã£
éå ± ã
Nexusããã€ã¹ã®ææè
ãšãã€ãä»ã®äººãå©çšã§ããããã«ãªã£ãAndroidçšã®2æã®ãããã»ããã¯ãBroadcomã¢ãžã¥ãŒã«ã®WiFiãã©ã€ããŒã®è匱æ§ã解決ããŸãã ãã®è匱æ§ã®æœåšçãªæªçšã·ããªãªã¯æªå€¢ã®ããã«èŠããŸãã å
Œ
±ã®WiFiãããã¯ãŒã¯ãå°äžéããªãã£ã¹ããŸãã¯ããã«ã«æ¥ç¶ããŸãã åããããã¯ãŒã¯äžã®æ»æè
ã¯ãç¹å¥ã«çް工ãããããã¯ãŒã¯ãã±ãããããã€ã¹ã«éä¿¡ããã¹ããŒããã©ã³ãžã®ãã«ã¢ã¯ã»ã¹ãååŸããŸãã 幞ããªããšã«ããã®ã·ããªãªã¯æ¬åœã«çè«çãªãã®ã§ããGoogleã¯ãå®éã®æ»æã«æ°ä»ããªãã£ããšäž»åŒµããŠããŸãã
æªåé«ãMediaserverã³ã³ããŒãã³ãã«ã¯ã
StagefrightããŒã«ã以åã«çºèŠãããŠããå¥ã®è匱æ§ãéããããŠããŸãã åè¿°ããããã«ããœãããŠã§ã¢ã«å€ãã®è匱æ§ãèŠã€ãã£ãå Žåãããã¯å¿
ããããœãããŠã§ã¢ãŸãã¯ãã©ãããã©ãŒã ããå®å
šã§ãªãããšèªå®ããããã§ã¯ãããŸããã 1ã€ã®æ¡ä»¶äž-è匱æ§ãéããããŠããå Žåã Androidãšã³ã·ã¹ãã ã¯ããã¯ã€ããããã®ç ç©¶è
ãšç¯çœªè
ã®äž¡æ¹ã«ãã£ãŠãå¯èœãªéã培åºçã«ç ç©¶ãããŠããŸãã æšå¹Žã®æ¯æã®ã»ãã¥ãªãã£æŽæ°ããã°ã©ã ã®å°å
¥ã¯ååããªå€åã§ããããAndroidã®æçåãšå€æ°ã®ããã€ã¹ã«å¯Ÿãããããã®ã¢ã¯ã»ã¹äžèœæ§ã«é¢ãã質åã¯æ®ã£ãŠããŸãã ãããã£ãŠãäŒæ¥ãããã¯ãŒã¯å
ã®æºåž¯é»è©±ãªã©ã®ä¿è·æŠç¥ã¯ãå€ãã®ããã€ã¹ãè匱ã§ãããé·æã«ããã£ãŠããã§ãããšããäºå®ã«åºã¥ããŠå
éšçã«ãã¹ãã§ãã
ä»ã«äœãèµ·ãã£ãïŒOracle
㯠ããã©ãŠã¶çšã®Javaãã©ã°ã€ã³ãéçºã
ãªããªããŸãã ãã©ãŠã¶ãŒéçºè
ã¯ãé·ãéããã®ãããªãã©ã°ã€ã³ãèªåã§æé€ããããšæžåœã«åªåããŠãããããæåŸ
ããããœãªã¥ãŒã·ã§ã³ã§ãã Googleã¯ãããã©ã«ãã®NPAPIã€ã³ã¿ãŒãã§ãŒã¹ã
ãããã¯ãã
ããšã§éæããŸãããã€ãŸããå®éã«ã¯JavaãSilverlightãªã©ã®ãã©ã°ã€ã³ã®æäœãçŠæ¢ããŠããŸãã
ãŸãããã¹ããŒãããªåäŸçšç©å
·ã«å€æ°
ã®è匱æ§ãèŠã€ãããŸããã
å¿åã®ããã«ãŒãNASAãã250ã®ã¬ãã€ãã®ããŒã¿ã
çã¿ãŸãã ã ãŸãã¯ã圌ãã¯ãããçã¿ãŸããã§ããïŒNASAèªäœ
㯠ãããªãŒã¯ããå
¬ã®ã¢ã¯ã»ã¹ã®ããã«äŒç€Ÿã®ãŠã§ããµã€ãã«æçš¿ããã
ãšäž»åŒµããæ»æã§ã¯ãªããèªç±ãªPRããããŸããã
å€ç©ïŒãå¿è
-1376ã
éåžžã«å±éºãªåžžé§ãŠã€ã«ã¹ã COMMAND.COMããã³AIDSTEST.EXE以å€ã®.COMããã³.EXEãã¡ã€ã«ã«ææããŸãã ææãããšããŠã€ã«ã¹ã®ååŸã«æå€§255ãã€ãã®ã©ã³ãã ãããã¯ã远å ãããŸãã 宿çã«ãã¡ã€ã«ã匷å¶çµäºããŸãïŒèµ·åæã«ããMutant Ninja Version 2.0 Copyright©1990.91 VirusïŒWorm Softwareããšããããã¹ãã埩å·åããŠè¡šç€ºããããã°ã©ã ãéå§æã«æžã蟌ã¿ãŸãã 1992幎ã13æ¥ã®13.00ã«Cãã©ã€ãã®FATãæ¶å»ããŸãã int 24hã§ã¯æ£åžžã«åäœããŸããã ãCOMMAND.COMãããAIDSTEST.EXEããããCOMãããã³ã.EXEãã®è¡ãå«ãŸããŠããŸãã int 21hãããã¯ããŸãã
Eugene Kasperskyèã®æ¬ãMS-DOSã®ã³ã³ãã¥ãŒã¿ãŒãŠã€ã«ã¹ãããã®åŒçšã 1992幎ã 77ããŒãžå
責äºé
ïŒãã®ã³ã©ã ã¯ãèè
ã®å人çãªæèŠã®ã¿ãåæ ããŠããŸãã ã«ã¹ãã«ã¹ããŒã®äœçœ®ãšäžèŽããå Žåãããã°ãäžèŽããªãå ŽåããããŸãã ããã¯å¹žéã§ãã