Habréã®Dynã®DNSãµãŒããŒã«å¯Ÿããæè¿ã®æå€§ã®DDoSæ»æã¯èŠéããããŸããã§ãã ã ãã®ãã©ãã¯ã¢ãŠãã®æ©èœã¯ãIoTããã€ã¹ããã®http
èŠæ±ã®åºç¯ãªäœ¿çšãšã telnet
ãµãŒãã¹ã§äœ¿çšããã23çªç®ã®tcp
ããŒããéããŠããããštelnet
ã

telnetã¯çããŠãããçµã¿èŸŒã¿ã·ã¹ãã ãšããšãã«ãã£ãããšåãŸã£ãŠããããšãããããŸãã æªæããããã人éã®ç¡ç¥ã ãããæããããŸãã¯åé眪ãšã¯äœã§ããïŒ telnetããŒãã¯éããŠããŠãåé»ã®æ°ãæåã«ã èšå€§ãªæ°ã®IoTããã€ã¹ã«ãã£ãŠåŒ·åã«æãªãããŸããããé·ãæããããŸã§å¯Ÿçãè¬ããŸããã§ããã
çè«çæå°å€
Telnetã¯1960幎代åŸåã«ç»å Žãã tcp/ip
ãšä»®æ³ç«¯æ«ã®æåã®æšæºã¯1983幎ã«é¡ããŸããåœç¶ãäœææã«ã¯ãããŒã¿ããã¬ãŒã³ããã¹ã圢åŒã§éä¿¡ããããšããäºå®ãèª°ãæ°ã«ããŸããã§ããã åœæã®tcp/ip
ãããã¯ãŒã¯ãããã³ã«ã¯ãARPANETã§çæããŠããŸããã
Telnetã¯ããã¹ãïŒã€ãŸãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ïŒãšç«¯æ«éã§åäœããããã«èšèšãããŠããŸãã RFC 854 [Postel and Reynolds 1983a]ã®ä»æ§ã¯ããããã¯ãŒã¯ä»®æ³ç«¯æ«ïŒNVTïŒãšåŒã°ããæå°å
¬åæ¯ç«¯æ«ãå®çŸ©ããŠããŸãã NVTã¯ãæ¥ç¶ã®äž¡ç«¯ïŒã¯ã©ã€ã¢ã³ããšãµãŒããŒïŒãå®éã®ç«¯æ«ãšã®éã§ãããã³ã°ãè¡ãæ¶ç©ºã®ããã€ã¹ã§ãã ã€ãŸããã¯ã©ã€ã¢ã³ãã®ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¯ããŠãŒã¶ãŒã䜿çšããŠããããããçš®é¡ã®ç«¯æ«ãNVTã«ãããããå¿
èŠããããŸãã ãµãŒããŒã¯ãNVTãããµãŒããŒããµããŒããã端æ«ã¿ã€ãã«ãããããå¿
èŠããããŸãã
å€ãã®äžè¬çãªã€ã³ã¿ãŒããããããã³ã«ãšåæ§ã«ããã®ã·ã³ãã«ãã®ããã«å€é¢šã§ã·ã³ãã«ã§æ²ããŸããã ä»ã®ç®çã«ãé »ç¹ã«äœ¿çšãããŸãã
(5:574)$ grep -w ^telnet /etc/services telnet 23/tcp
å¥åŠãªäºå®ã§ããã telnets
ãããªãã®ãããããšãtelnets
ããããã©ããªå¥è·¡ã§ãããã¯èšããŸããã æ€çŽ¢ãšã³ãžã³ã§ããé©ããã
(5:575)$ grep -w ^telnets /etc/services telnets 992/tcp
ã³ãã³ãã®å®å
šãªãªã¹ãã¯æ¬¡ã®ãšããã§ãã
EOF 236 end-of-file SUSP 237 suspend current process (job control) ABORT 238 abort process EOR 239 end of record SE 240 suboption end NOP 241 no operation DM 242 data mark BRK 243 break IP 244 interrupt process AO 245 abort output AYT 246 are you there? EC 247 escape character EL 248 erase line GA 249 go ahead SB 250 suboption begin WILL 251 option negotiation WONT 252 option negotiation IX) 253 option negotiation DONT 254 option negotiation IAC 255 data byte 255
Telnetã¯åäºéãæåããšãããã³è¡ããšã®å
¥åã¢ãŒãããµããŒãããŸã;ããã©ã«ãã§ã¯ãããã°ã©ã ã¯åŸè
ã䜿çšããŸãã ããã¥ã¢ã«ããŒãžããã

æ¥ç¶ãéããããšãtelnetã¯TELNET LINEMODEãªãã·ã§ã³ãæå¹ã«ããããšããŸãã ããã倱æãããšãtelnetã¯2ã€ã®å
¥åã¢ãŒãã®ããããã«æ»ããŸãããªã¢ãŒãã·ã¹ãã ããµããŒããããã®ã«å¿ããŠããäžåºŠã«1æåããŸãã¯ãå€ãè¡ããšãã®ããããã«ãªããŸãã
垯åå
ã·ã°ããªã³ã°ã䜿çšãããŸã-ã³ãã³ããšããŒã¿ã¯1ã€ã®ã¹ããªãŒã ã§éä¿¡ãããŸãã
TelnetãããŒããã
æšå¹Žããã§ã³ã®å€§æDNSãããã€ããŒã§ããNIC.CZã®å°éå®¶ã ãããŒãããã®é€ãåºãããã©ãã£ãã¯ã®ç£èŠãéå§ããŸããã
telnet
ãã©ãã£ãã¯ã¯ ssh
ãã©ãã£ãã¯ããã3æ¡å€§ããããšã倿ããŸããã åçŽãã£ãŒãã§ã¯ã telnet
ã®ãã°ã€ã³è©Šè¡åæ°ãš ssh
ã«å¯ŸããŠssh
ããã³ãã³ã ã ã¹ã±ãŒã«ã¯å¯Ÿæ°ã§ãã ã¯ãªãã¯å¯èœ ã

äžæã®IPã®æ° ã

åœã®å°çãã¯ãªãã¯å¯èœ ã 以äžã®Shodanã®çµæãšã®äžèŽã«æ³šæããŠãã ããã

ã¡ã€ã³ããã€ã¹ã®ãã©ãããã©ãŒã ãã¯ãªãã¯å¯èœ ã

ããããã RomPager / 4.07 HTTPãµãŒããŒã¯ãå€ãã®å ŽåããŒã ã«ãŒã¿ãŒã§äœ¿çšãããæŒããããçµã¿èŸŒã¿WebãµãŒããŒã§ãã ãã®ãããAllegro Software Developmentã®ã¢ããªã¹ãã«ãããš ã 7,500äžäººã«ãªãå¯èœæ§ããããŸãã 2äœã¯äººæ°ã®ããgSOAP / 2.7ããŒã«ãããã§ãDVRãµãŒããŒãžã®H264DVR 1.0 -RTSPïŒãªã¢ã«ã¿ã€ã ã¹ããªãŒãã³ã°ãããã³ã«ïŒã¯é
ã¡ãã«ãç²åŸããŸããã
å®éãCCTVã«ã¡ã©ã¯äžåèªãªDahua RtspãµãŒããŒã«ãã£ãŠç€ºããã ã»ãã¥ãªãã£äžã®åé¡ãæ±ããŠããŸãã 2016幎5æä»¥éããããã®ããã€ã¹ã®ã¢ã¯ãã£ããã£ã¯æ¥æ¿ã«å¢å ããŠããã1æ¥ããã8,000åã®äžæã®IPã¢ãã¬ã¹ãç»é²ãããŠããŸããã
å®éšã®å°åæ§ã«ãããããããå·®ãè¿«ã£ãå€§èŠæš¡ãªIoTè
åšã«é¢ããçµè«ã¯ãããèªäœã瀺åããŠããããã«èŠããŸããã ãã§ã³ã®ã¢ããªã¹ã㯠ã 600äžãè¶
ããäžæã®IPã¢ãã¬ã¹ããã®ããŒã¿ãåŠçããŠãåŸåãæç¢ºã«ç¹å®ããŸããïŒçµã¿èŸŒã¿ã·ã¹ãã ã¯ãæãè匱ãªãã®ã§ãããç¹ã«CCTVã«ã¡ã©ã¯ãåãæ©åšãããŒããŠã§ã¢ãè匱æ§ã®ãªã¹ãã§åäžæåã«é¥ãããšããããããŸãã æåã®ãã«ã¯éãã«é³ŽããèãããŸããã§ããã
ãªã¹ãå
šäœãçºè¡šãã
Rapid7ã®å°éå®¶ã¯ãProject Sonarã®ã€ã³ãã©ã¹ãã©ã¯ãã£ã䜿çšããŠãäžçäžã§ã°ããŒãã«ããŒãã¹ãã£ã³ãå®è¡ããIPv4ç¯å²ã®ã¡ã€ã³tcp
ããŒãã確èªããŸããã ãã®ç ç©¶ã¯éåžžã«è©³çްã§è峿·±ãããšã倿ããŸããã
- telnetããŒããéããŠãã1500äžã®ãã¹ãã ïŒã«ãŒã«ïŒïŒ
- 1,100äžã®RDBMSãããªãã¯ãã¹ã
- å°å·ãµãŒãã¹ãžã®ãªãŒãã³ã¢ã¯ã»ã¹ãæã€450äžã®ãã¹ãã
ããã«ãããæåã®10åã®tcp/ip
ãããã³ã«ã®ãµã€ãºã忣ãããŸããã
Port Protocol Number Percent 80 HTTP 76,266,507 19.89% 443 HTTPS 50,507,072 13.17% 22 SSH 21,692,582 5.66% 21 FTP 20,375,533 5.31% 25 SMTP 19,888,484 5.19% 8080 http-alt0 17,477,357 4.56% 23 telnet 14,871,682 3.88% 53 DNS 12,602,272 3.29% 143 IMAP 11,467,158 2.99% 110 POP3 11,073,439 2.89%
衚ã«ãããã¹ãŠã®30ã®ãããã³ã«..

å
šäœã§7çªç®ã誰ãäºæ³ããŠããŸãããïŒ ãããŠããã¹ãŠã®http*
ã1ã€ã®ã«ããŽãªã«ãŸãšãããšãtelnetã¯5äœã«ãªããŸãïŒ ã芧ã®ãšããã ssh
ããã®é
å»¶ssh
éåžžã«å°ããã§ãã ããã¯2çªç®ã®éã§ãããã誰ããããèããŸããã§ããã
ãšã¯èšããã®ã®ãæ¬çªç°å¢ã§telnetãå®å
šã«èžã¿ã«ããããšãã§ããªãããã«æãããšããäºå®ã¯ãããããããããšãšå¿é
ã®äž¡æ¹ã§ãã ã¹ãã£ã³ã«ãããšãçŸåšã€ã³ã¿ãŒãããäžã§telnetãµãŒãã¹ãæäŸããŠããããã«èŠããããã€ã¹ã¯1400äžãè¶
ããŠããŸãã
100,500ã®è匱ãªCCTVãããªã«ã¡ã©
Flashpointã®ã¹ãã·ã£ãªã¹ãã¯ã Miraiããããããã®çè·¡ã远ã£ãŠãCCTVãããªã«ã¡ã©XiongMai Technologiesããã³Dahuaã®è峿·±ãç¹æ§ã®çºèŠãæ±ããŠã€ã³ã¿ãŒããããæ¢ãåã£ã ã ããã€ã«ã»ã¶ãã«ããã¯ãæ€
åã«ã€ããŸã£ãŠãããªããšãããªãã¯åããŸãããšèšãã®ã奜ãã§ãã

2016幎6æ10æ¥ã®ããŒã¿ã«ãããšã uc-httpd 1.0.0.0
WebãµãŒããŒãåãã515åå°ãè¶
ããããã€ã¹ãã CVE-2016-1000245ããã³CVE-2016-1000246ã®åœ±é¿ãåæã«åããŠããŸãã
è匱æ§CVE-2016-1000245ã¯åãªãã¬ãŒãã§ãã ãã¹ãŠã®ããã€ã¹ã«ã¯åãã«ãŒããã¹ã¯ãŒã xc3511ããã ãã·ã¹ãã äžã«passwd
ã³ãã³ãããªãããã 倿Žã§ããŸãã ã /etc/init.d/rcS
ããinitã¹ã¯ãªãããåé€ããªãéãã telnet
ãµãŒãã¹ã¯ãªã³ã«ãªããèšå®ãããªãã«ãªããŸããã
/etc $ cat passwd root:absxcfbgXtb3o:0:0:root:/:/bin/sh /etc $ cat passwd- root:ab8nBoH3mb8.g:0:0::/root:/bin/sh
DVR / NVR CMSãå®è¡ãããã¹ãŠã®ã€ã³ã¿ãŒããã察å¿XiongMaiãã¯ãããžãŒããŒãïŒå¥åïŒ
NetSurveillanceïŒã䜿çšãããšããã©ã€ããªã€ãŒãµãããã€ã³ã¿ãŒãã§ãŒã¹ã§telnetãµãŒãã¹ãå®è¡ã§ããŸãã ãã®ãµãŒãã¹
/ etc / rcSãä»ããŠå®è¡ãããç¡å¹ã«ããããšã¯ã§ããŸããã ãŠãŒã¶ãŒãrootãã«ã¯ãããŒãã³ãŒãã£ã³ã°ãããäžå€ã®
xc3511ã®ãã¹ã¯ãŒãã ãããã®ã·ã¹ãã ã«ã¯ãpasswdãããŒã«ãã€ã³ã¹ããŒã«ãããŠããããã«ãŒã
ãã¹ã¯ãŒãã¯ãã³ãã³ãã©ã€ã³ãããWebã€ã³ã¿ãŒãã§ã€ã¹ããã倿Žã§ããŸããã
è匱æ§CVE-2016-1000246ã¯æåã®ãã®ããå£ããŸããã http://<IP>/DVR.htm
ããhttp://<IP>/DVR.htm
ããããšã«ãããã¢ã«ãŠã³ããšãã¹ã¯ãŒãããã€ãã¹ã§ããŸãã
å€ãã®æ¢ç¥ã®XiongMai DVRãNVRãããã³IPã«ã¡ã©ã¯ãXM Technologiesã«ãã£ãŠæ§ç¯ããããCMSãïŒNetSurveillanceãšãåŒã°ããŸãïŒãå®è¡ããŸãã ãã®ãœãããŠã§ã¢ã¯ãXiongMai Technologiesã®ãã¹ãŠã®ããŠã³ã¹ããªãŒã ãã³ããŒã§ã䜿çšãããŠããŸãã httpïŒ//_IP_/Login.htmãhttpïŒ//_IP_/DVR.htmã«å€æŽããã ãã§ããããã®ããã€ã¹ã®ãã°ã€ã³ããŒãžããã€ãã¹ã§ããŸãã ããã«ãããèªèšŒãªãã§ãã¹ãŠã®ã«ã¡ã©ã·ã¹ãã ã«ã¢ã¯ã»ã¹ã§ããŸãã ããã«ãã·ã¹ãã ã«ãã°ãèšé²ãããªãããããŠãŒã¶ãŒç®¡çã¯ã§ããŸããã 圱é¿ãåãããã¹ãŠã®è£œåã®WebãµãŒããŒããŒãžã§ã³ã¯åãã§ãã ãUc-httpdãã çŸåšCVE-2016-1000245ã®åœ±é¿ãåãããã¹ãŠã®è£œåã¯ãèªèšŒãã€ãã¹ã«å¯ŸããŠãè匱ã§ãã
ãããã®åãXiongMaiãšDahuaã空枯ã«èšçœ®ãããŠããªãããšãé¡ã£ãŠããŸãã
ãŸãšã
Telnetã¯éåžžã«ç²ã匷ãã ssh
ã®ç»å Žããæ°å幎ãã£ãŠããæ¥ãã§çŸå Žãå»ãããšãã§ããŸããã ã¯ã©ã€ã¢ã³ããšãµãŒããŒã®éã®èŠéãå
ã§ãæå³ããç®çã«äœ¿çšããå Žåã§ããéåžžã«é©ããŠããŸãã ãã ããããã«ããã®éç¥ã®ããã«ãTelnetããµãŒããŒã«ãŒã ããèªç±ã«å£ãããã§ã«ããããããå§ããŠãããšããããšã§ãã ããã¯èª°ã®ããã§ããïŒ
ç§ã®ãã§ã³ã¹ããããèŠããã ãŸã ãæŒããããIoTââããã€ã¹ãšçµã¿èŸŒã¿ã·ã¹ãã ã®å±±å²³ã¡ãŒã«ãŒã®äž»ãªæ¬ ç¹ã§ãã ãããã¯ãã¹ãŠXiongMaiãšDahuaã§ãã é
ããæ©ããããããè£œé æ¥è
ã¯IPã«ã¡ã©ã®è²©å£²ããæ€åããŸãã ãããããã¥ãŒã¹ã®ç°¡åãªã¬ãã¥ãŒã¯ãäžåœäŒæ¥ã®PRéšéãšååçã®åŸæ¥å¡ããã³ãç¡æã§é£ã¹ãŠããããšã瀺ããŠããŸãã
ãã®éšçœ²ãç¥ã£ãŠããŸãïŒ èª°ãããã¹ããŒããååŸããŸãïŒ [1]
第äºã«ããã¡ãããèŠå¶åœå±ã¯éé£ããããšã§ã-ããããèªèšŒããè¯å®çãªçµè«ãåºãè
ã Rapid7ã¬ããŒãããã
ãããã®çµæã¯ãã¹ãŠãçŸä»£ã®ã€ã³ã¿ãŒããããšã³ãžãã¢ãªã³ã°ã«ãããæ ¹æ¬çãªå€±æãç©èªã£ãŠããŸãã ã€ã³ã¿ãŒãããã¢ãŒããã¯ãã£å§å¡äŒãã€ã³ã¿ãŒããããšã³ãžãã¢ãªã³ã°ã¿ã¹ã¯ãã©ãŒã¹ãããã³å°çäžã®ã»ãŒãã¹ãŠã®ã»ãã¥ãªãã£äŒç€Ÿããã³ã»ãã¥ãªãã£æè·å£äœããã®èŠè«ã«ãããããããåŒ·å¶æå·åã¯ã€ã³ã¿ãŒããããããã³ã«èšèšã®ããã©ã«ãã®æšæºæ©èœã§ã¯ãããŸããã ã¯ãªã¢ããã¹ããããã³ã«ã¯ãæ©èœããã ããã§ãããã»ãã¥ãªãã£äžã®æžå¿µã¯ã²ãããäºæ¬¡çã§ãã [2]
第äžã« ããããã®CCTVã«ã¡ã©ãå
šäžçã«æ€ããè«è² æ¥è
ãšã€ã³ãã°ã¬ãŒã¿ãŒã
ã€ã³ã¿ãŒãããã¢ã€ãã³ããããªã«ã¡ã©ã®ITã»ãã¥ãªãã£ãèŠå¶ããããã®æ³çæªçœ®ãè¬ããªããšãæªç£ãšããŠåé»ããŸããŸãæ¥æ¿ã«ãªããŸãã

PSç§ãå
¥åããŠããéã«ãåŒ·ãæ¬²æ±ãçããŸãã-nmapãšä»ã®ããŒã«ã§ããŒã ã«ãŒã¿ãŒããã§ãã¯ããããšã ãã§ãã¯ããŠèœã¡çããããæããã«é·ãã¯ãªãã£ãã
äœ¿çšææ
- W.ãªãã£ãŒãã¹ãã£ãŒãã³ã¹ TCP / IP Illustratedã第1å·»ããããã³ã«ã1994幎ã
- TCP / IPã®ã¯ããŒãºã¢ãã
- TelnetstáleÅŸije-alespoÅnaâchytrÜchâzaÅÃzenÃch
- â M.ãã«ã¬ã³ãã®å°èª¬ããã¹ã¿ãŒãšãã«ã¬ãªãŒã¿ãããã
- âçµæã¯ããèªäœãç©èªã£ãŠããŸãã IABãIETFãããã³ã»ãŒãã¹ãŠã®ã»ãã¥ãªãã£å°éå®¶ã®ãã¹ãŠã®åŒã³ããã«ãããããããåŒ·å¶æå·åã¯ãŸã ã€ã³ã¿ãŒãããæšæºã®éçºã«ãããæšæºã«ãªããŸããã§ããã ãã¬ãŒã³ããã¹ãããæ©èœããã ãããããã³ãã®ãããã»ãã¥ãªãã£èŠä»¶ã¯ç¡èŠãããŸãã