
ãµã€ããŒç¯çœªè
ã¯ãéèæ©é¢ããããã³ã°ããããã«ãæå
端ã®ãŠã€ã«ã¹ãç¹å¥ãªãµãŒãã¹ã®ååããã®ãšã¯ã¹ããã€ããããã³æšçãçµã£ããã£ãã·ã³ã°ãªã©ããŸããŸãé«åºŠãªæè¡ã䜿çšãããšèããããŠããŸãã å®éãæ
å ±ã·ã¹ãã ã®ã»ãã¥ãªãã£ãåæãããšãç©æ¥µçãªåœ±é¿ãã€ãŸãç®ã«èŠããªãæ»æã䜿ããã«ãç¡æã®å
¬çã«å©çšå¯èœãªæ段ã䜿çšããŠãéè¡ã«å¯Ÿããæšçåæ»æãæºåã§ããããšãããããŸãã ãã®èšäºã§ã¯ãäž»ã«ãããã¯ãŒã¯ãµãŒãã¹ã®éå°ãªãªãŒãã³æ§ã«åºã¥ããŠæ§ç¯ãããåæ§ã®ããã«ãŒææ³ãæ€èšãããã®ãããªæ»æããä¿è·ããæ¹æ³ã«é¢ããæšå¥šäºé
ãæäŸããŸãã
ã¹ããã1.ç®æšãå®çŸ©ãã
ãªãã©ã€ã³ã®äžçã§ã¯ãã©ã®ãµãŒãã¹ãšãããã¯ãŒã¯ãç¹å®ã®çµç¹ã«å±ããŠããããææ¡ããã®ã¯ç°¡åã§ã¯ãããŸããã ãã ããã€ã³ã¿ãŒãããäžã«ã¯ãé¢å¿ã®ããäŒæ¥ã管çããŠãããããã¯ãŒã¯ãç°¡åã«èå¥ããåæã«ãããã®åã«èŒããªãããã«ããå€ãã®ç¹å¥ãªããŒã«ããããŸãã ããã·ãã€ã³ããªãžã§ã³ã¹ã®å Žåãéèæ©é¢ã®ãããã¯ãŒã¯å¢çã«é¢ããçµ±èšæ
å ±ãåéãããã¬ãŒã ã¯ãŒã¯ã§ã次ã䜿çšããŸããã
- æ€çŽ¢ãšã³ãžã³ïŒGoogleãYandexãShodanïŒã
- éèã»ã¯ã¿ãŒã®æ¥çãµã€ã-banki.ru ã rbc.ruã
- WhoisãµãŒãã¹2ip.ruã nic.ruã
- ã€ã³ã¿ãŒãããã¬ãžã¹ãã©ã®ããŒã¿ããŒã¹ã®æ€çŽ¢ãšã³ãžã³-Hurricane Electric BGPããŒã«ããããRIPE ã
- ãµã€ãã®ãã¡ã€ã³åã®ããŒã¿èŠèŠåãµãŒãã¹-Robtex
- ãã¡ã€ã³ãŸãŒã³ã®å±¥æŽããŒã¿ïŒIPã¢ãã¬ã¹ã®å€æŽïŒãå«ãdnsdumpsterãã¡ã€ã³ãŸãŒã³ãåæããããã®ãµãŒãã¹ãããŒã¿ã®åéã«éåžžã«åœ¹ç«ã¡ãŸãã åæ§ã®ãµãŒãã¹ã¯æ°å€ããããæãæåãªé¡äŒŒç©ã®1ã€ã¯domaintools.comã§ãã
ãã®èª¿æ»ã§ã¯ãã¢ã¯ãã£ãã¹ãã£ã³ããã¡ã€ã¢ãŠã©ãŒã«ã®ããŒãžã§ã³ãšIPSã®ååšã®å€å¥ã䜿çšãããŠã€ã«ã¹å¯Ÿçããã®ä»ã®ä¿è·æ段ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ã®å€å¥ãªã©ã®æ¹æ³ã¯åãæ±ã£ãŠããŸããã å«ççããã³ãã®ä»ã®çç±ã§äœ¿çšããªãã£ããã¯ããã¯ãããã€ããããŸããããããã¯ããã«ãŒã«ãã£ãŠãã䜿çšãããŸãã
- GitHubã§ãããžã§ã¯ããæ€çŽ¢ããŸã ã GitHubã«ã¯ããã¹ããããžã§ã¯ããããã¯ã¢ããã³ãŒãããŸãã¯äœæ¥ã³ãŒããæçš¿ãããã¢ã¯ã»ã¹ãå¶éãå¿ãããã誀ã£ãŠå¶éããããããããšããããããŸãã ãã®ãããªãããžã§ã¯ãã®ç 究ã«ã¯é«ãè³æ Œãå¿
èŠã§ããã調æ»å¯Ÿè±¡ã®ã¢ããªã±ãŒã·ã§ã³ã®ãšã©ãŒãŸãã¯åã蟌ãŸããè³æ Œæ
å ±ã䜿çšããŠãã»ãŒ100ïŒ
ã®ç¢ºçã§ãããã¯ãŒã¯ã«äŸµå
¥ããŸãã
- HeartBleedãPoodleãDROWNãªã©ã®ãªã³ã©ã€ã³è匱æ§ãã§ãã¯ãµãŒãã¹ã ãããã®ãµãŒãã¹ã¯ãç¹å®ã®è匱æ§ãããã°ãããæ€åºããå¯èœæ§ãé«ãã§ããããããã®ãã§ãã¯ã«ã¯å€ãã®æéãããããŸãã
- ãã«ãŒããã©ãŒã¹DNS ãã®ææ³ã¯ç©æ¥µçãªä»å
¥ã§ãã ã·ã¹ãã ã®DNSåãå埩åŠçããŠã䜿çšå¯èœãªãã®ã決å®ã§ããŸãã ããã¯ãã¿ãŒã²ããDNSãµãŒããŒãžã®DNSã¯ãšãªãä»ããŠè¡ãããŸããããã©ãã£ãã¯ã¯ãããšãã°Google DNSãä»ããŠã«ãŒãã£ã³ã°ã§ããæ»æãããçµç¹ã®èŠ³ç¹ããã¯ããããã®ã¯ãšãªã¯æ£åœã«èŠããŸãã ãã®ãããªææ³ãå®è£
ããã«ã¯ãéåžžKaliLinuxããŒã«ãŸãã¯åæ§ã®ã¢ã»ã³ããªã䜿çšãããŸãã æ®å¿µãªãããå®éã«ã¯ãDNSãã°ã¯äœããçºçãããŸã§ããããç£èŠãããä¿æãããããŸããã
ãããã£ãŠããŸãæåã«ãã管çãããçµç¹ã®ãªã¹ãã決å®ããŸãã ãããè¡ãã«ã¯ãæ€çŽ¢ãšã³ãžã³ãå°éãµã€ããããã³å°éæ
å ±ã®ä»ã®ã¢ã°ãªã²ãŒã¿ãŒã䜿çšã§ããŸãã ããšãã°ãéèæ©é¢ã®çµ±èšæ
å ±ãåéããå Žåã¯ã
banki.ruã«ã¢ã¯ã»ã¹ã
ãŠãå®æãããããéè¡ãšä¿éºäŒç€ŸãéžæããŸãã ãªã¹ãã®åéã«ã¯ãã»ãšãã©æéãããããŸããã 次ã®ã«ããŽãªã®çµç¹ãç¹å®ããŸããã
- éè¡ïŒ1äœãã25äœãŸã§ïŒã
- éè¡ïŒ26æ¥ãã50æ¥ãŸã§ïŒã
- éè¡ïŒ51çªãã75çªãŸã§ïŒã
- éè¡ïŒ76çªãã100çªãŸã§ïŒã
- ãã€ã¯ãã¯ã¬ãžããçµç¹
- 決æžã·ã¹ãã
- ä¿éºäŒç€ŸïŒ1æ¥ãã50æ¥ãŸã§ïŒã
- ä¿éºäŒç€ŸïŒ51çªãã100çªãŸã§ïŒã
次ã«ãçµç¹ãææãããããã¯ãŒã¯ãå®çŸ©ããŸãã æ€çŽ¢ãšã³ãžã³ã§çµç¹ã®ãµã€ããèŠã€ãããã®ã¢ãã¬ã¹ãç¹å®ããããã«ã
whois WebãµãŒãã¹ã䜿çšããŸãã ãã®ãªãœãŒã¹ã䜿çšãããšããµã€ãã®ãã¡ã€ã³åã§IPã¢ãã¬ã¹ãæ€çŽ¢ãããããããã¯ãŒã¯ãæ€çŽ¢ããããã®ãã®ä»ã®éèŠãªããŒã¿ãæ€çŽ¢ãããã§ããŸãã ãã®äœæ¥ã§ã¯ãéèŠãªããŒã¿ã«ã¯æ¬¡ã®ãã®ãå«ãŸããŸãã
- ãããåïŒãããã¯ãŒã¯åãRipeããŒã¿ããŒã¹ãæ€çŽ¢ãããšãã«éåžžã«åœ¹ç«ã¡ãŸãïŒ;
- Descr ïŒèª¬æã¯æ³åââåã䜿çšããæ€çŽ¢ã«é©çšã§ããŸãïŒ;
- ã¢ãã¬ã¹ ïŒåãç©çã¢ãã¬ã¹ã«ç»é²ãããŠãããããã¯ãŒã¯ãæ€çŽ¢ïŒ;
- é£çµ¡å
ïŒRipeããŒã¿ããŒã¹ã§ã®æ€çŽ¢ã¯ããããã¯ãŒã¯ãç»é²ã§ãã人ã§ãå¯èœã§ãïŒ;
- çµç¹ãç¹å®ã§ãããã®ä»ã®æ
å ±ã
ãããã®æ
å ±ã¯ãã¹ãŠãwhois Unixã³ãã³ããããååŸã§ããŸãã 䜿çšãããã®ã¯å¥œã¿ã®åé¡ã§ãã ç¹å®ã®éè¡ãå±éºã«ããããªãããã«ãåœç€Ÿã®äŸã§ãã®æ€çŽ¢ã瀺ããŸãã

çµç¹ã«ã€ããŠåéãããæ
å ±ã䜿çšããŠãRipeã¬ãžã¹ãã©ããŒã¿ããŒã¹ã§ã¢ãã¬ã¹ç¯å²ãæ€çŽ¢ããŸããã RipeãµãŒãã¹ã§ã¯ãç»é²ãããŠãããã¹ãŠã®ãããã¯ãŒã¯ãèªç±ã«æ€çŽ¢ã§ããŸãã åœãã£ãŒã«ãã«ã泚æãæã䟡å€ããããŸãããã·ã¢ã®ãããã¯ãŒã¯ã»ã°ã¡ã³ãã®ã¿ãéžæããŸããã

ãã®äœæ¥æ®µéã§ã¯ãå€ãã®èäœåŽåãå¿
èŠã§ãããããã¯ãäžéšã®äœæãããŒãããŒã«æäŸãããããªãŒã¹ããããçµç¹ãææããŠããªãããã§ãã ãããã£ãŠãçµæã®ç²ŸåºŠãé«ããããã«ãå¿
èŠãªãããã¯ãŒã¯ãŸãã¯ãã¹ãã®ã¿ãå¯èœãªéãé«ãä¿¡é Œæ§ã§éžæããããã«ãè¿œå ã®ãã§ãã¯ãè¡ãå¿
èŠããããŸããã ãããã¯ãŒã¯ãæ€èšŒããããã«ãç±³åœã®é»æ°éä¿¡äºæ¥è
Hurricane Electricã®å
¬éãããŠãããªã³ã©ã€ã³ãµãŒãã¹ã䜿çšããŸããããã®ãµãŒãã¹ã¯ããµã€ãã®IPã¢ãã¬ã¹ã«ãã£ãŠãããã¯ãŒã¯ã®æ
å ±ãæäŸã§ããŸãã äœæ¥ã®ãã®æ®µéã§ã¯ãRobtexãµãŒãã¹ãéåžžã«åœ¹ç«ã¡ãŸããã æå®ãããã¡ã€ã³åã®ãã¹ãŠã®æ¥ç¶ã衚瀺ãããŸããããã«ãããRipeããŒã¿ããŒã¹ã®æ€çŽ¢æã«èŠã€ãããªãã£ããããã¯ãŒã¯ãèŠã€ããããšãã§ããŸããã ããã«ãRobtexã䜿çšãããšããã®IPã¢ãã¬ã¹ã«ããä»ã®ãµã€ãã衚瀺ã§ããŸãããã®æ
å ±ã圹ç«ã€å ŽåããããŸãã æ€çŽ¢äŸïŒ

æ¢ã«è¿°ã¹ãããã«ãå¿
èŠãªãããã¯ãŒã¯ã®æ±ºå®ã¯ãé¢é£ããçµæãæåã§éžæããå¿
èŠãããããããã¹ãŠã®èªååã«ãããŠææªã§ãã ããããéèã»ã¯ã¿ãŒã®ãããã¯ãŒã¯ã«é¢ããæ
å ±ãåéããã®ã«ãã£ã2æ¥ããããããŸããã§ããã ãã®æ®µéãå®äºããåŸããçµç¹-ãããã¯ãŒã¯ãã®ã¿ã€ãã®ãªã¹ããåãåããŸããã
ã¹ããã2.å©çšå¯èœãªãµãŒãã¹ãç¹å®ãã
ãããè¡ãã«ã¯ãã€ã³ã¿ãŒããããããå®å
šã«ããããã«èšèšããã2ã€ã®æãæåãªããŒã«ã®1ã€ãShodanãŸãã¯Censysã䜿çšã§ããŸãã ãããã¯é¡äŒŒã®æ©èœãæã¡ãAPIã®äœ¿çšããµããŒãããçžäºã«è£å®ããããšãã§ããŸãã å®å
šãªæ€çŽ¢ãè¡ãã«ã¯ãäž¡æ¹ã®ãµãŒãã¹ã«ç»é²ãå¿
èŠã§ãã Censysã¯ããèŠæ±ãå³ãããªããŸããæ€çŽ¢çµæã®å¶éãåãé€ãããã«ãéçºè
ã«æžé¢ãéããç 究ã®å«çãšããŒã¿ã®è²¬ä»»ãã䜿çšã説åŸããå¿
èŠããããŸãã åŒæ°ã¯ãCEHèªå®ãŸãã¯è©³çŽ°ãªç 究æ
å ±ã§ãã
ShodanãµãŒãã¹ã䜿çšããã®ã¯ããã䟿å©ã ããã§ãã ããã«ãShodanã¯ãã-sVããã©ã°ã䜿çšããNmapã¹ãã£ã³ãšåãæ¹æ³ã§ã¹ãã£ã³ããŸããããã¯ããã®èª¿æ»ã§ãã©ã¹ã«ãªããŸããçµæãåŠçããæ¹ã䜿ããããã§ãã èªååããã»ã¹ã¯ããããæãèå³æ·±ããã®ã§ããã詳现ã説æããã®ã¯æå³ããããŸãããPythonã³ãŒãã®äŸãªã©ããã¹ãŠã@achilleanãšããŠãç¥ãããäœæè
John Matherlyã«ãã£ãŠ
éåžžã«äŸ¿å©ãªåœ¢åŒã§ãã§ã«èª¬æãããŠãã
ããã§ãã ããã«ã
GitHubã«ã¯
ãªããžããªããããPythonçšã®Shodanã®å
¬åŒã©ã€ãã©ãªãç¥ãããšãã§ããŸãã
Shodanãžã®ãªã¯ãšã¹ãã«é¢ãã詳现æ
å ±ã¯
ãã¡ãã«ãããŸã ã Webã€ã³ã¿ãŒãã§ã€ã¹ãä»ãããªã¯ãšã¹ãã®äŸã¯æ¬¡ã®ããã«ãªããŸãã

äŸãšããŠãUDPããŒã53ã¯ã¢ãã¬ã¹8.8.8.8ã§äœ¿çšå¯èœã§ãããDNSãµãŒãã¹ã¯ç±³åœã«ãããGoogleãææããŠããŸãããã®IPã¢ãã¬ã¹ã§äœ¿çšãããŠãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ããŒãžã§ã³ã衚瀺ãããŠããŸãã Shodanãžã®ã¯ãšãªã¯ãã€ã³ã¿ãŒãããããã®ã¢ã¯ã»ã¹ãå¶éããããšãå¿ããããŠãããããå
·äœçãªãµãŒãã¹ãæããã«ããããšãã§ããŸããããããè¡ãå¿
èŠããããŸãã ãããã®ãµãŒãã¹ã®ããŸããŸãªãããŒãšããŒãžã§ã³ãååŸã§ãããããåä¿¡ããããŒã¿ãããŸããŸãªè匱æ§ããŒã¿ããŒã¹ãšæ¯èŒããããšãã§ããŸãã
ããããçºèŠããããã¹ãŠã®IPã¢ãã¬ã¹ãShodançµç±ã§å®è¡ããå¿
èŠãããã1ç§ã§çŽ100,000ãååŸããŸãã-æåæ€èšŒã«ã¯å€ãããŸã... APIã«ã€ããŠã¯ã©ãã§ããïŒ
ç¬èªã®æ
å ±ã³ã¬ã¯ã¿ãŒãäœæããŸããã 圌ãã¯ãããéå§ããŸãã-ãããŠã1é±éã®ä»äºã®åŸãããã°ã©ã ã¯éèã»ã¯ã¿ãŒã§å©çšå¯èœãªãµãŒãã¹ã®ååžã®åçãæã«å
¥ããŸããã ãã®æ¹æ³ã§ã€ã³ãã©ã¹ãã©ã¯ãã£ã®å€æŽã远跡ããããšã¯éåžžã«çŸå®çã§ãã ç§ãã¡ãèŠã€ãããã®ã¯æ¬¡ã®ãšããã§ãã


éèæ©é¢ã®å¢çã§æããã²ã©ãããã®ããïŒ
- DBMSïŒæ£çŸ©ã®ãããäžéšã®ãããŒã«ã¯ããã®SQLãµãŒããŒãžã®æ¥ç¶ã¯èš±å¯ãããŠããŸããããšãããšã³ããªãå«ãŸããŠããããšã«æ³šæããŠãã ããïŒ;
- ãã£ã¬ã¯ããªãµãŒãã¹ïŒãããŒã«ã€ããŠã¯ãLDAPã確èªã§ããŸãïŒ;
- FSãžã®ã¢ã¯ã»ã¹ãæäŸãããµãŒãã¹ïŒSMBãFTPãªã©ïŒã
- ããªã³ã¿ïŒããã³ããã€ããŒãã«ãã£ãŠå€æãããšãééãã¯ãããŸããïŒïŒãããã¯æãåçãªè匱æ§ãæã¡ãäžè¬çã«æãä¿è·ãããŠããªãããã€ã¹ãšããŠèªèãããŠããŸã ã ã¯ããã¯ããè匱æ§ã¯å€ãã§ãã ããããå¢çäžã®ããªã³ã¿ãŒãæåŸã«æŽæ°ããã®ã¯ãã€ã§ããïŒ
- TelnetãRDPãªã©ã®å®å
šã§ãªããªã¢ãŒã管çãµãŒãã¹ã
- RPCãµãŒãã¹ã
- ä»®æ³åã·ã¹ãã ;
- ãã«ãã¡ãã£ã¢ãµãŒãã¹ã
ãããã®ãµãŒãã¹ã¯ã次ã®ããã«çµç¹éã§åæ£ãããŸãã


åŸãããçµæã¯é©ãããšã§ã¯ãããŸããã§ãããçµç¹ã倧ãããªãã°ãªãã»ã©ããããã¯ãŒã¯å¢çã«é
眮ããããµãŒãã¹ãå¢ãããµãŒãã¹ã®æ°ãå¢ãããšãæ§æãšã©ãŒã®å¯èœæ§ãé«ããªããŸãã
ã¹ããã3.è匱ãªãµãŒãã¹ãç¹å®ãã
åŸãããçµæã¯é©ãããšã§ã¯ãããŸããã§ãããçµç¹ã倧ãããªãã°ãªãã»ã©ããããã¯ãŒã¯å¢çã«é
眮ããããµãŒãã¹ãå¢ãããµãŒãã¹ã®æ°ãå¢ãããšãæ§æãšã©ãŒã®å¯èœæ§ãé«ããªããŸãã
- IP - IPçµç±ã§æ§ç¯ãããã³ã³ãã¥ãŒã¿ãŒãããã¯ãŒã¯å
ã®ããŒãã®äžæã®ãããã¯ãŒã¯ã¢ãã¬ã¹ã
- ããŒã -ãã©ã³ã¹ããŒããããã³ã«ïŒTCPãUDPãªã©ïŒã®ãã©ã¡ãŒã¿ãŒã§ããããžã¿ã«çªå·ã
- ãããã³ã« -ç°ãªãããã°ã©ã éã®ããŒã¿äº€æãå®çŸ©ããäžé£ã®è«çã¬ãã«ã€ã³ã¿ãŒãã§ã€ã¹èŠåã
- ãã¹ãåã¯ãããŸããŸãªæ¹æ³ã§ãã®ããã€ã¹ãžã®ã¢ã¯ã»ã¹ãæŽçããããã«äœ¿çšã§ãããããã¯ãŒã¯ããã€ã¹ã«å²ãåœãŠãããã·ã³ãã«åã§ãã
- ãµãŒãã¹ -ç¹å®ã®ãµãŒãã¹ã®ååã
- 補å -ãµãŒãã¹ãå®è£
ããããœãããŠã§ã¢ã®ååã
- Product_version-ç¹å®ã®ãœãããŠã§ã¢ã®ããŒãžã§ã³ã
- ãã㌠-ãµãŒãã¹ã«æ¥ç¶ããããšãããšãã«æäŸããããŠã§ã«ã«ã æ
å ±ã
- CPE- å
±éãã©ãããã©ãŒã åæ ããœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãããŒããŠã§ã¢ãã©ãããã©ãŒã ã®æšæºçãªåœåæ¹æ³ã
- OSã¯ãªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ããŒãžã§ã³ã§ãã
éããŠãããã¹ãŠã®ããŒãã«ã€ããŠã§ã¯ãªããShodanã¯å®å
šãªæ
å ±ã»ãããæäŸã§ããŸãããæåããå ŽåãããŒã¿ïŒãã®äŸã§ã¯ãã·ã¹ãã ã§æ¢ã«åŠçãããçµæïŒã¯æ¬¡ã®ããã«ãªããŸãã

å±æ§ç©ºéå
šäœããããã®ãã¹ãã®è匱æ§ã«é¢ããæ
å ±ãèŠã€ããããšãã§ãããã£ãŒã«ããç¹å®ãããŸããã Product + Product_versionãŸãã¯CPEã®æãããã«æé©ãããããŸããã ãã®ã±ãŒã¹ã§ã¯ãProduct + Product_versionãã³ãã䜿çšããããšã«ããPositive Technologiesã®å
éšè匱æ§ããŒã¿ããŒã¹ã䜿çšããŠæ€çŽ¢ãå®è¡ããŸããã
ãããã¯ãŒã¯ã«ã¯ãè匱æ§ãæ€çŽ¢ããããã®å
¬éãããŠãããœãŒã¹ãããªããããŸããããã®äžéšã次ã«ç€ºããŸãã
â¢
SecurityLab.ru-ããã¯æ
å ±ã»ãã¥ãªãã£ãšãã©ãŒã©ã ã«é¢ãããã¥ãŒã¹ã ãã§ãªããè匱æ§ã®ããŒã¿ããŒã¹ã§ããããŸãïŒ æ
å ±åºåã®äŸïŒ
- BDU FSTEC-åœå
çç£ã®ãœãããŠã§ã¢ããã³PACã®è匱æ§ãèŠã€ããèœåãä»ã®åæ§ã®ãªãœãŒã¹ãšç°ãªãæ
å ±ã»ãã¥ãªãã£è
åšã®ããŒã¿ããŒã¹ã
- nvd.nist.govã¯ãç±³åœæšæºæè¡ç 究æã®National Vulnerability Databaseã§ãããç±³åœã§å
¬éãããŠããç±³åœã®è匱æ§ç 究ããã³åæãªãœãŒã¹ããŸãšããŠããŸãã
- vulners.com--æ
å ±ã»ãã¥ãªãã£ã³ã³ãã³ãã®å€§èŠæš¡ãªæŽæ°ãããããŒã¿ããŒã¹ãè匱æ§ããšã¯ã¹ããã€ãããããããã°å ±å¥šéã®çµæãæ€çŽ¢ã§ããŸãã
- cvedetails.comã¯ãè匱æ§ããŒã¿ã衚瀺ããããã®äœ¿ããããWebã€ã³ã¿ãŒãã§ã€ã¹ã§ãã ãã³ããŒã補åãããŒãžã§ã³ãããã³CVEé¢é£ã®è匱æ§ã®ãªã¹ãã衚瀺ã§ããŸãã
- securityfocus.comã¯ãç¹ã«ãšã¯ã¹ããã€ãããŒã¿ã®å
¥åã«é¢ããŠãå
¬éãããŠããããããœãŒã¹ã®1ã€ã§ãã
äžèšã®ãã¹ãŠã®ãªãœãŒã¹ã䜿çšãããšãCPEãå«ãããŸããŸãªçç±ã§è匱æ§ããã°ããæ€çŽ¢ã§ããŸãã ãŸãããããã®ãªãœãŒã¹ã«ãããæ€çŽ¢ããã»ã¹ãèªååã§ããŸãã ãã®çµæãè匱æ§ã®è©³çŽ°ãªèª¬æãPoCã®ååšã«é¢ããæ
å ±ããŸãã¯æªçšã®èšé²ãããäºå®ãæªçšãžã®ãªã³ã¯ãªã©ãå€ãã®æçšãªæ
å ±ãèŠã€ããããšãã§ããŸãã

ãã§ã«äžé£ã®ãµãŒãã¹ãšãã®ãããŒããããè匱æ§ããŒã¿ããŒã¹ãéããŠãã®æ
å ±ãå®è¡ããã ãã§ãã ãã¡ããããããæåã§è¡ãããšã¯ãŸã£ããæã¿ãŸããã§ããããæéãããããŸãã ãã®ãããåçŽãªã¹ã¯ãªãããäœæããŠãåãåã£ããã¹ãŠã®ãµãŒãã¹ããã°ããåŠçããè匱æ§ããŒã¿ããŒã¹ãšæ¯èŒãïŒåãããšãååä»ããµãŒãã¹ãéããŠç°¡åã«è¡ãããŸãïŒããµãŒãã¹ããšã®è匱æ§ã®ååžã«é¢ãã次ã®çµ±èšæ
å ±ãåãåããŸããïŒ


çµæã¯æ¬¡ã®ãšããã§ããShodanãçºèŠãããµãŒãã¹ã®ç·æ°ã®ãã¡ã5ïŒ
ã§è匱æ§ãæ€åºãããŸããã ãã®æ°åã¯å°ãããæ¯èŒã®ããã«ãåœç€Ÿã®èªååãããå¢çã¹ãã£ã³ã«ãããšãéåžžããµãŒãã¹ã®20ã50ïŒ
ã§è匱æ§ãèŠã€ãããŸãã ããããçè«çã«ã¯ãè匱æ§æ€åºã®å²åãå¢ããããšãã§ããŸãã ãããã©ã®ããã«è¡ãããããèŠãŠã¿ãŸãããã

ããšãã°ãROSSSHã®å ŽåïŒã¹ã¯ãªãŒã³ã·ã§ããã®4è¡ç®ä»¥äžïŒã
ROSSSHã®ãªã¢ãŒãäºåèªèšŒããŒãç Žæã®è匱æ§ã®å¯çšæ§ãæ³å®ã§ããŸãã ãã®è匱æ§ã¯ãŸã£ããæ°ãããã®ã§ã¯ãªããšããäºå®ã«ããããããããã®ãµãŒãã¹ã§ãã®è匱æ§ãæºããå¯èœæ§ã¯ãŒããããã¯ããã«é«ããªã£ãŠããŸãã ã€ã³ã¿ãŒãããããã¢ã¯ã»ã¹å¯èœãªã·ã¹ãã ã®çŽ30ïŒ
ã«5幎以äžåã®è匱æ§ãå«ãŸããŠãããšãã
以åã®ç 究ãæãåºããŠ
ãã ãã ã 調æ»ã§ã®åæ§ã®æ°å€ã¯
ã·ã¹ã³ã«ãã£ãŠæäŸãããŠãããæ¢ç¥ã®è匱æ§ã®å¹³åçãªååšã¯5幎å以äžã§ãã ãããã®çµæã¯ç§ãã¡ã®ãã®ãšåçã§ãããããããªéãã¯ç°ãªããµã³ãã«ãšç 究æ¹æ³ã«ãããã®ã§ãã
äžèšã®äŸã«ããã°ãRDPãµãŒãã¹
CVE-2015-0079 ã
CVE-2015-2373 ã
CVE-2015-2472 ã
CVE-2016-0019ã«è匱æ§ããããšæ³å®ã§ããŸãã ããã¯èããããè匱æ§ã®äžå®å
šãªãªã¹ãã§ã;ãã¹ãŠã®ãªãŒãã³ãœãŒã¹ã§ã¯ããããã®è匱æ§ã¯CPEã«ãã£ãŠOSããŒãžã§ã³ã«ãªã³ã¯ãããRDPãžã®ãã€ã³ããç¡èŠããŸãã æãé¡èãªäŸã¯ãæªçšå¯èœãªæåãªè匱æ§ã§ããããã«ã€ããŠã¯åŸã§èª¬æããŸãã ä»ã®å€ãã®ãµãŒãã¹ã«ã€ããŠã¯ãè匱æ§ã®ååšã«ã€ããŠåæ§ã®ä»®å®ãæ§ç¯ããããšãã§ããŸãã
ã¹ããã4.æ€çŽ¢ãšã¯ã¹ããã€ã
次ã®ã¹ãããã¯ãç¹å®ã®è匱æ§ã®ãšã¯ã¹ããã€ããæ€çŽ¢ããããšã§ãã äžèšã®æ€çŽ¢ãšã³ãžã³ã§ã¯ãå°æ°ã®ãšã¯ã¹ããã€ããèŠã€ããããšãã§ããŸãããPandoraã®ããã¯ã¹ããã§ã«éããŠããããããã®ããã«ç¹å¥ãªãŠãŒãã£ãªãã£ã䜿çšãã人ã¯ããŸããã ããšãã°ãç¡æã®PTEEãŠãŒãã£ãªãã£ããããŸãã 圌女ã«é¢ãã
å¥ã®èšäºã詳现ã«æžãããŠããŸãã ãããŠMetasploitããããŸãããããã¯äœãåéããŸãããã...
åœç€Ÿã«ã¯ç¬èªã®ç¥èããŒã¹ããããè匱æ§ã¯ãã§ã«ãšã¯ã¹ããã€ããšæ¯èŒãããŠããããããã®ã¹ãããã§è¿œå ã®ã¢ã¯ã·ã§ã³ã¯å¿
èŠãããŸããã§ããã åŠçã®çµæã«ãããšã次ã®ãã®ãåãåããŸããã
- 559åã®CVSSé«ãªã¹ã¯è匱æ§ã®ãã¡88åã«ã¯ãšã¯ã¹ããã€ããå©çšå¯èœã§ãã
- 733ã®äžãªã¹ã¯ã®è匱æ§ã®ãã¡178ã®è匱æ§ã«ã¯ã¢ã¯ã»ã¹å¯èœãªãšã¯ã¹ããã€ãããããŸãã
- 309ã®äœãªã¹ã¯ã®è匱æ§ã®ãã¡8ã€ã«ã¯ããšã¯ã¹ããã€ããå©çšå¯èœã§ãã
æ
å ±ã»ãã¥ãªãã£ã®å€ãããã®æèšã®1ã€ã«ãã·ã¹ãã ã®ã»ãã¥ãªãã£ã¬ãã«ã¯æã匱ããªã³ã¯ã®ã»ãã¥ãªãã£ã¬ãã«ã«çãããšãããã®ããããŸãã å®éãæ»æãèšç»ãããšããå®è·µã瀺ãããã«ãæœåšçãªæ»æè
ã¯æãå®å
šã§ãªãã·ã¹ãã ãéžæããŸãã çµæãæ
éã«æ€èšãããšããã®ãããªã·ã¹ãã ãèŠã€ããå¯èœæ§ã¯ãçµç¹ã®ãã¹ãŠã®ã«ããŽãªã§é«ãããšã¯æããã§ãã


çµæã«ã¯ç°¡åãªèª¬æããããŸããã€ã³ãã©ã¹ãã©ã¯ãã£ã®æé·ã«äŒŽããç£èŠãããå°é£ã«ãªã£ãŠããŸãã ããå€ãã®ãã¹ã-æªçšå¯èœãªãã®ãå«ããããå€ããœãããŠã§ã¢ãšããå€ãã®è匱æ§ã 倧äŒæ¥ã§ã¯ãå¢çç·ã¯éåžžã«åçã§ãã1é±é以å
ã§ããå€ãã®äººãå»ãããšãã§ããããã«ãæ倧ââã§æ°ååã®æ°ãããã¹ãããããã¯ãŒã¯å¢çã«è¡šç€ºãããããšããããŸãã ãããã®å€æŽãåãªããšã©ãŒã®çµæã§ããå Žåããããã®ããŒãã®1ã€ãããã¢ãéããå¯èœæ§ã¯éåžžã«é«ããªããŸãã ãã®ãããå¯èœãªéããªã¢ã«ã¿ã€ã ã«è¿ãã¢ãŒãã§å¢çã®ç¶æ
ãå®æçã«ç£èŠããããšã¯ãå®å
šæ§ã確ä¿ããããã«éåžžã«éèŠã§ãã
è匱æ§æ
å ±ãã€ã³ã¿ãŒãããã«ç»å Žããã°ããã®å Žåãè匱ãªãµãŒãã¹ãæ€çŽ¢ããã®ã«ã©ããããæéãããããŸããïŒ ãã®ã·ã¹ãã ã§ã¯ãæå®ãããè匱æ§ã®æ€çŽ¢ã«1ç§ãããããŸããã çµæã®åæã«ã¯ããã«æéãããããŸããããããéåžžã«é«éã§ãããã®èª¿æ»ã®æ çµã¿ã§ã¯ã1ã€ã®è匱æ§ã®åæã«15åããããããŸããã§ããã
ã¹ããã5.å®éã«æ»æãã
ãã®ãããæ»æè
ã¯ã¿ãŒã²ããã€ã³ãã©ã¹ãã©ã¯ãã£ã«é¢ããããŒã¿ãåéããè匱ãªãµãŒãã¹ãç¹å®ããŸãã è匱æ§ã«é¢ããæ
å ±ãæ¢ããããããæªçšå¯èœãªè匱æ§ãéžæããŸãã 次ã«ãã¿ãŒã²ããã€ã³ãã©ã¹ãã©ã¯ãã£ã«é¢ããç¥èãšè匱æ§ã«é¢ããããŒã¿ãæ¯èŒããããšã«ãããã·ã¹ãã å
ã®ãããã®è匱æ§ã®ååšã«ã€ããŠæšæž¬ãè¡ããŸãã æåŸã®ã¹ãããã§ãæ»æè
ã¯å©çšå¯èœãªããŒã«ã䜿çšããŠè匱ãªã·ã¹ãã ãæ»æããŸãã
ãã¡ãããç§ãã¡ã®ç 究ã§ã¯ãå®éã®æ»æã¯ãããŸããã§ããã ããããæçµæ®µéã§ããã«ãŒã®èœåãè©äŸ¡ããããšã¯ã§ããŸãã ããšãã°ãThe Shadow Brokersã«ãã£ãŠããŒãžãããæåãªãšã¯ã¹ããã€ãããã¯ã®æåŸã®éšåãèããŠã¿ãŸãããã ãã®ããã¯ã«ã¯
ãWannaCryãŠã€ã«ã¹ã®
æµè¡åŸã«æåã«ãªã£ãSMBãããã³ã°ããããªã©ãå€ãã®èå³æ·±ããšã¯ã¹ããã€ãããããŸããããµã³ãã«ã§ã¯ãââãã®ãšã¯ã¹ããã€ãã¯36ã·ã¹ãã ã«é©ããŠããŸããïŒèª¿æ»å¯Ÿè±¡ã®å¢çã«é¢ããããŒã¿ã¯ããšã¯ã¹ããã€ããå«ãã¢ãŒã«ã€ãã®å
¬éåã«åéãããŸããïŒã åœæãããã¯ã«å«ãŸãããšã¯ã¹ããã€ãã¯ãWindowsã®ãã¹ãŠã®ããŒãžã§ã³ã«é©çšãããŸããã ãã®çµæããããã³ã°ãããå¯èœæ§ãéåžžã«é«ããªããŸããã ããã¯ãŸãã«WannaCryã瀺ãããã®ã§ãã ãããŠãããã¯æ°·å±±ã®äžè§ã«éãããããã¯ã«ã¯ä»ã®èå³æ·±ããšã¯ã¹ããã€ãããããŸããã
- EsteemauditïŒRDPã®æªçšïŒ ã ACLïŒã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒãªãã§RDPãµãŒãã¹ãå¢çã«é
眮ããããšã¯ãšã©ãŒãšèŠãªããŸãã è·éããã§ããã®ãµãŒãã¹ãååšãã44ã®ã·ã¹ãã ãç¹å®ãããŸããã ãã®èª¬æã«ãããšããšã¯ã¹ããã€ãã¯å€ãããŒãžã§ã³ã®Windows Server 2003ã«ã®ã¿é©çšãããŸãããã®ãããæ°ããããŒãžã§ã³ã®Windowsã®ãããŒãæã€10åã®ã¢ãã¬ã¹ãé€å€ããŸããããšã¯ã¹ããã€ããé©çšã§ããã·ã¹ãã ã¯3ã€ã確èªãªãã§31åãããŸããã
- WebãµãŒããŒã®ãšã¯ã¹ããã€ãã»ãã ã 37ã·ã¹ãã ã«ã€ããŠã¯ãWebãµãŒããŒã®ãããã³ã°ãç®çãšãããšã¯ã¹ããã€ãã®é©çšå¯èœæ§ã«ã€ããŠæ³å®ãããŸããã
- ã¡ãŒã«ãµãŒããŒã®æªçšã®ã»ãã ã 13ã·ã¹ãã ã§ãåäœã«é©ããããŒãžã§ã³ã®ã¡ãŒã«ãµãŒããŒãçºèŠãããŸããã
ãã®çµæã3,764åã®å©çšå¯èœãªã¢ãã¬ã¹ã®ãã¡ã111åãæœåšçã«è匱ãªãµãŒãã¹ã§ãããšç¹å®ãããŸããã ãããŠããã®ãšã¯ã¹ããã€ãããã¯ã®å©ããåããŠãããã³ã°ãããå¯èœæ§ãé«ãã§ãã
調æ»éå§æãå±éºã¬ãã«ã¯åãåã£ããããäœãããã«æãããŸãããããã®åŸWannaCryãæ¥ãŠåæããŸããã§ããã é«ã¬ãã«ã®å±éºæ§ã®çç±ã¯ãçµç¹ã®å€éšå¢çã®å¶åŸ¡ã®æ¬ åŠã§ããã ããã«ãèŠåãšå°é家ã®æšå¥šäºé
ãå
¬éãããåŸã§ããã»ãã¥ãªãã£ã¬ãã«ã«å€§ããªå¢å ã¯ãããŸããã§ããã ããã¯ãåãè匱æ§ã䜿çšãã次ã®
Petya / NotPetyaæå·ããã«ãŒã®æµè¡ã«ãã£ãŠæããã«ç€ºãããŸããïŒãã ãããã®ååžãã¯ãã«ã¯ãããã¯ãŒã¯å¢çã«å±ããŠããŸããïŒã ã€ã³ãã©ã¹ãã©ã¯ãã£ã«ææããã«ã¯ãè匱ãªã·ã¹ãã ã1ã€ããã°ååã§ãããå¢çãå
æããã«ã¯ãæ»æè
ã¯è匱ãªãµãŒãã¹ã1ã€ã ãå¿
èŠãšããŸãã
ä¿è·ã®ããã®çµè«ãšæšå¥šäºé
ãŸãšãããšã è匱æ§ãæ¢ãåŸæ¥ã®ãããã¯ãŒã¯ã¹ãã£ããŒã䜿çšããå Žåãçµç¹ã®åŸæ¥å¡ã¯èª°ãããããããç£èŠãããŠãããšçãå¯èœæ§ããããŸãã ãã®ãããªã¹ãã£ã³ã®äºå®ã¯ãIDSãšãããã¯ã䜿çšããŠç°¡åã«èå¥ã§ããŸãã ãããã誰ã倧éæ€çŽ¢ãšã³ãžã³ã®äœæ¥ã远跡ããŸããïŒ ãã®èšäºã§ã¯ã次ã®ããšãå®èšŒããŸããã
- éèã»ã¯ã¿ãŒã«å¯Ÿããæšçåæ»æãæºåããããã«ãç¹å¥ãªéèè²»çšã¯å¿
èŠãããŸããã
- ãã¬ãŒãã³ã°ã¯ãæ»æãããçµç¹ãšããããé²åŸ¡ããçµç¹ã«ã¯èŠããªãå ŽåããããŸãã
- æ»æãå®è£
ããããã«ãNSAããã®ãšã¯ã¹ããã€ãããã¯ã¯å¿
èŠãããŸãããããã®ã³ã³ããŒãã³ãããªãŒãã³ã¢ã¯ã»ã¹ã«åé¡ãããŸãã
å¢çã»ãã¥ãªãã£ã¯ãåºæ¬çãªã»ãã¥ãªãã£ãã¯ãã«ã®1ã€ã§ãã ããããããªããå®ããã®ãç¥ããªãã§ä¿è·ããããšã¯ãé£ãããççŽã«èšã£ãŠãæå³ã®ãªãä»äºã§ãã ä¿è·ããŠããå¢çã®å¢çãããããªãå Žåã¯ããã®èšäºã§èª¬æãããããã¯ãŒã¯åææ¹æ³ã䜿çšã§ããŸãã ãŸããå€éšãµãããããå€æ°ããïŒããšãã°ãè€æ°ã®ã€ã³ã¿ãŒãããæ¥ç¶ã䜿çšããŠå
šåœã«åæ£ããŠããã€ã³ãã©ã¹ãã©ã¯ãã£ïŒãå¢çã®ã€ã³ãã³ããªãå°é£ãªå Žåã¯ãå°é家ã«çžè«ããããšãã§ããŸãã ããšãã°ãPositive TechnologiesïŒabc@ptsecurity.comïŒã®å°é家ã å¿
èŠãªã®ã¯ããªãã¬ãŒã¿ãŒããã®å°çšãããã¯ãŒã¯ã®ãªã¹ããšã¹ãã£ã³ãžã®åæã®ã¿ã§ãã
å¢çãäœã§æ§æãããŠãããã«ã€ããŠã®ã¢ã€ãã¢ãåãåã£ããããã®ä¿è·ã«å¯ŸåŠããŸãã æ
å ±ã·ã¹ãã ã®æãå®å
šãªæ§æãå®çŸããããšã¯å°é£ã§ãããªããªãããœãããŠã§ã¢ããã®æ§æãšä¿å®ããããŠããžãã¹ãæºè¶³ãããããã«ããªããä»®å®ãããªããã°ãªããªãå Žæãæ
åœãã人ã ããã§ãã æ
å ±ã»ãã¥ãªãã£ã¯ãåžžã«ã·ã¹ãã ã®æ©èœãšãã®ã»ãã¥ãªãã£ã®éã§ãã©ã³ã¹ãåããŸãã æ§æãšã©ãŒããããã¯ãŒã¯å¢çã«ååšããŸãã調æ»ã瀺ãããã«ãè匱ãªãµãŒãã¹ãå«ãå€ãã®äžèŠãªãµãŒãã¹ãã€ã³ã¿ãŒãããã«å
¬éãããŠãããããæ»æè
ãçµç¹ã®ãããã¯ãŒã¯ã«äŸµå
¥ãããããªããŸãã æšå¥šãããå¢çä¿è·èšç»ã¯æ¬¡ã®ããã«ãªããŸãã
- ã€ã³ã¿ãŒãããããã®ã¢ã¯ã»ã¹ãæ£åœåãããè³ç£ãç¹å®ããŸãã
- ã¢ã¯ã»ã¹æ£åœæ§ã®ãªããµãŒãã¹ã¯ãå¢çããåé€ããå¿
èŠããããŸãã
- æ°ããã·ã¹ãã ãå€éšå¢çã«é
眮ããæé ãææžåããŠå®è£
ããŸãã
- ACLãäœæãã管çã€ã³ã¿ãŒãã§ã€ã¹ããªã¢ãŒãã¢ã¯ã»ã¹ãµãŒãã¹ãããŒã¿ããŒã¹ããã®ä»ã®éèŠãªãµãŒãã¹ãžã®ã¢ã¯ã»ã¹ãæå°éã®äººã®ãªã¹ãã§å¶éããŸãã
- æŽæ°ããã°ã©ã ãã€ã³ã¹ããŒã«ããæé ã玹ä»ãããã®å®è£
ã®æåã®ã¡ããªãã¯ã決å®ããŸãã
- ç£æ»ã¢ãŒãïŒå
éšãããã¯ãŒã¯ããïŒã§ã®å°çšããŒã«ã«ããã¹ãã£ã³ãããã³ãã¹ãã¢ãŒãïŒã€ã³ãã©ã¹ãã©ã¯ãã£ãæœåšçãªäŸµå
¥è
ã«ã©ã®ããã«èŠããããç解ããããã®å€éšãµã€ãããã®ã¹ãã£ã³ïŒã§ã®è匱æ§ã®ã¹ãã£ã³ãªã©ãã»ãã¥ãªãã£åæäœæ¥ãå°ãªããšãå®æçã«å®è¡ããŸãæã«äžåºŠã
- è³ç£ã®è²¬ä»»è
ã®ãªã¹ããå®çŸ©ããŸãïŒããžãã¹åŽãšITåŽã®äž¡æ¹ããïŒã ããã«ãããç·æ¥ã®ã·ã¹ãã ã¢ããã°ã¬ãŒãäžã®äººä»¶è²»ãšåå¿æéãççž®ãããŸãã
- è匱æ§ã®é€å»ã«åªå
é äœãä»ããã«ã¯ãè³ç£ã®äŸ¡å€ãå€æããŸãã
- å¢çã«ããã·ã¹ãã ã®é倧ãªè匱æ§ãæ€åºããå Žåã®å¯Ÿå¿èšç»ãäœæããŸãã èšç»ã§ã¯ãé倧ãªè匱æ§ãžã®å¯ŸåŠæ¹æ³ãæ€èšããå¿
èŠããããŸãã ã·ã¹ãã 管çè
ããã³æ
å ±ã»ãã¥ãªãã£ã®å°é家ããšãã¹ãè¡åã ãããã®ã¢ã¯ã·ã§ã³ã¯ãã·ã¹ãã ã®ããžãã¹ãªãŒããŒãšäžèŽããŠããŸããïŒ
ãã¡ãããè
åšã«å¯Ÿæããã«ã¯ãæ
å ±ã»ãã¥ãªãã£ã確ä¿ããããã®çµ±åã¢ãããŒããå¿
èŠã§ãããããããã¯ãŒã¯å¢çãããå§ãã䟡å€ãããããšãèŠããŠããå¿
èŠããããŸãã
äœæè
ïŒPositive Technologiesã®å°é家Vladimir LapshinãMaxim FedotovãAndrey Kulikov