ð ã¯ãªããããŒãåºæ¬æäœ
ð¡ äœ¿ãæ¹
- ã¯ãªããããŒãããèªã¿åãïŒçŸåšã¯ãªããããŒãã«ä¿åãããŠããå 容ã衚瀺ããŸã
- ã¯ãªããããŒãã«æžã蟌ãïŒããã¹ããšãªã¢ã®å 容ãã¯ãªããããŒãã«ã³ããŒããŸã
- ã¯ãªããããŒããã¯ãªã¢ïŒã¯ãªããããŒãã空ã«ããŸã
ð¯ å®éã«è©ŠããŠã¿ããïŒ
ãŸãããã®ããã¹ããéžæããŠã³ããŒããŠã¿ãŸãããïŒ
ã¯ãªããããŒãã®å®éšããã¹ãã§ãð§ª
â ã¯ãªãã¯ããŠéžæ â Ctrl+Cã§ã³ããŒ
次ã«ãð ã¯ãªããããŒãããèªã¿åãããã¿ã³ãã¯ãªãã¯ããŠãã³ããŒããå 容ã確èªããŸããã
ããã¹ããšãªã¢ã«å¥œããªæåãå ¥åããŠãâïž ã¯ãªããããŒãã«æžã蟌ãããã¯ãªãã¯
ä»ã®ã¢ããªïŒã¡ã¢åž³ãªã©ïŒããã©ãŠã¶ãŒã®æ€çŽ¢æ¬ã«ãŠãCtrl+Vã§è²Œãä»ããŠç¢ºèªïŒ
ð ç£èŠã¢ãŒã
ð¡ ãã®æ©èœã«ã€ããŠ
ã¯ãªããããŒãã®å 容ã宿çã«ç£èŠããå€åãæ€åºããŸãã
â ïž ããã¯æªçšããããšããŠãŒã¶ãŒãã³ããŒããæ å ±ãçã¿èŠãããšãå¯èœã§ãã
ð¯ å®éã«è©ŠããŠã¿ããïŒ
ãŸããð¡ èªåç£èŠãæå¹ã«ããããã§ãã¯ããã¯ã¹ããªã³ã«ããŠç£èŠãéå§ããŸããã
ä»ã®ã¢ããªïŒã¡ã¢åž³ããã©ãŠã¶ãŒãªã©ïŒã§äœãããã¹ããã³ããŒããŠã¿ãŸããã
äŸïŒã¡ã¢åž³ã«ããã¹ãæååããšå ¥åããŠCtrl+AãCtrl+C ã§ã³ããŒClipThreat Studioã®ãç£èŠã¢ãŒããã¿ãã«æ»ããšãäžã®ãã°ã«ã¯ãªããããŒãå€åãèšé²ãããŠããã確èª
ð¡ ã¿ããã¢ã¯ãã£ãã§ãªããšäžéšãã©ãŠã¶ãŒã§ã¯æ€åºã§ããªãå ŽåããããŸãç°ãªãçš®é¡ã®ããŒã¿ïŒURLãã¡ãŒã«ã¢ãã¬ã¹ãªã©ïŒãã³ããŒããŠãã¿ã€ãå€å¥æ©èœã確èªããŠã¿ãŸããã
äŸïŒhttps://example.comãtest@example.com ãªã©ç£èŠééã倿ŽããŠãæ€åºã®åå¿é床ã®éããäœéšããŠã¿ãŸããã
æšå¥šïŒ0.5ç§ã«ããŠçŽ æ©ãåå¿ã確èªåŸã5ç§ã«ããŠéããäœæð pasteã€ãã³ãã¹ãããã£ã³ã°
ð¡ ãã®æ©èœã«ã€ããŠ
pasteã€ãã³ãã¹ããã£ã³ã°ã¯ããŠãŒã¶ãŒãå ¥åæ¬ã«è²Œãä»ããè¡ã£ãç¬éã«ããã®å 容ãååã»èšé²ããæè¡ã§ãã
ä»çµã¿ïŒJavaScriptã®pasteã€ãã³ãã䜿çšããŠãã¯ãªããããŒãããŒã¿ãèªã¿åããŸãã
⢠pasteã¹ããã£ã³ã°ïŒå 容ãååã»èšé²ïŒåŸã§éä¿¡ïŒ
⢠èªåéä¿¡æ»æïŒè²Œãä»ããšåæã«å³åº§ã«å€éšéä¿¡
ð¯ å®éã«è©ŠããŠã¿ããïŒ
ãŸãããã¹ãçšã®æååãã³ããŒããŸãããïŒäžã®æååãã¯ãªãã¯ããŠéžæïŒ
ãã¹ãçšãã¹ã¯ãŒã: SecretPass123!
â ã¯ãªãã¯ããŠéžæ â Ctrl+Cã§ã³ããŒ
äžã®å ¥åæ¬ã«è²Œãä»ããŠãã ããïŒCtrl+VïŒ
ð¡ 貌ãä»ããç¬éã«pasteã€ãã³ããçºçããå 容ãååãããŸããã°ãšãªã¢ã«è¡šç€ºãããååãããå 容ã確èªããŸããã
â ïž å®éã®æ»æã§ã¯ããã®æ å ±ãæ»æè ã®ãµãŒããŒã«éä¿¡ãããŸãå¥ã®çš®é¡ã®ããŒã¿ã詊ããŠã¿ãŸãããïŒã¯ã¬ãžããã«ãŒãé¢šã®æ°åïŒ
4111-1111-1111-1111
â ãã®åœã«ãŒãçªå·ãã³ããŒããŠè²Œãä»ããŠã¿ãŠãã ãã
å®éã®Webãµã€ãã§ã¯ããã®ãããªå±éºæ§ãããããšãèŠããŠãããŸããã
ð¡ïž éèŠãªæ å ±ã¯ä¿¡é Œã§ãããµã€ãã§ã®ã¿è²Œãä»ããããã«ããŠãã ããã»ãã¥ã¢ãã°ã€ã³ããŒã¿ã«ïŒä»®æ³ã®ãã£ãã·ã³ã°è©æ¬ºããŒãžïŒ
å®å šâ ïž å®éã®æ»æã·ããªãªã確èªãã
- ãã£ãã·ã³ã°ãµã€ãïŒåœã®ãã°ã€ã³ãã©ãŒã ã§ããŠãŒã¶ãŒããã¹ã¯ãŒããããŒãžã£ãŒãã貌ãä»ãããã¹ã¯ãŒããçå
- åœã®æ¯æãããŒãžïŒã¯ã¬ãžããã«ãŒãæ å ±ãæå·é貚ãŠã©ã¬ããã¢ãã¬ã¹ã®è²Œãä»ããç£èŠ
- åœã®ãã¡ã€ã«å ±æãµã€ãïŒæ©å¯ææžããã©ã€ããŒãããŒã®è²Œãä»ããåå
- ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ïŒããšã©ãŒãã°ã貌ãä»ããŠãã ãããçã®æç€ºã§ãã·ã¹ãã æ å ±ãååŸ
- åœã®ãµããŒããµã€ãïŒæè¡ãµããŒããè£ ããèšå®ãã¡ã€ã«ããã°ãã¡ã€ã«ã®è²Œãä»ããèŠæ±
- æªæããWebã¢ããªïŒäŸ¿å©ããŒã«ãè£ ãããŠãŒã¶ãŒã®ããŒã¿å ¥åãç£èŠ
ð¡ïž å¯Ÿçæ¹æ³ã確èªãã
- ãµã€ãã®ä¿¡é Œæ§ç¢ºèªïŒURLãSSLèšŒææžãå¿ ã確èªããŠãã貌ãä»ããè¡ã
- æåå ¥åã®åªå ïŒéèŠãªæ å ±ã¯å¯èœãªéãæåã§å ¥åãã
- ãã©ãŠã¶ãŒæ¡åŒµæ©èœïŒpasteã€ãã³ããå¶éããæ¡åŒµæ©èœã䜿çš
- éçºè ããŒã«ç¢ºèªïŒF12ããŒã§éçºè ããŒã«ãéããæªããJavaScriptããªãããã§ãã¯
- ãã¹ã¯ãŒããããŒãžã£ãŒã®æŽ»çšïŒèªåå ¥åæ©èœã«ãã貌ãä»ããé¿ãã
- ã³ã³ãã³ãã»ãã¥ãªãã£ããªã·ãŒïŒCSPããããŒã§JavaScriptã®å®è¡ãå¶é
- ãã©ãŠã¶ãŒã®èšå®ïŒJavaScriptãéšåçã«ç¡å¹åã§ãããã©ãŠã¶ãŒèšå®ã掻çš
ðš ClickFixæ»æã·ãã¥ã¬ãŒã·ã§ã³
ð¡ ClickFixæ»æãšã¯
ClickFixæ»æã¯ããŠãŒã¶ãŒãéšããŠæªæããã³ãã³ããå®è¡ããããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°æ»æã§ãã
ä»çµã¿ïŒåœã®ãšã©ãŒã¡ãã»ãŒãžãã修埩ããã¿ã³ã§ãå±éºãªã³ãã³ããã¯ãªããããŒãã«ã³ããŒããå®è¡ãä¿ããŸãã
ð¯ ClickFixæ»æãäœéšãããïŒ
ãŸããäžã®ClickFixæ»æã®èª¬æãèªãã§ä»çµã¿ãçè§£ããŸããã
ð¡ æ»æã®æŠèŠãšå±éºæ§ãææ¡ããŠããå®éã®äœéšã«ç§»ããŸãäžã®åœãšã©ãŒãã€ã¢ãã°ã®ä»æãã芳å¯ããåŸããð§ ä»ãã修埩ããïŒæšå¥šïŒããã¿ã³ãã¯ãªãã¯ããŠæ»æã®æµããäœéš
ð¡ æ¬ç©ã®ãšã©ãŒã¡ãã»ãŒãžã«èŠããèŠèŠçããªãã¯ïŒç¹æ» ãç·æ¥ãããžçïŒã«æ³šç®â ïž å®éã«ã¯ã¯ãªããããŒãã«å±éºãªã³ãã³ããã³ããŒãããŸã
äžã®ãã°ãšãªã¢ã§æ®µéçãªæ»æã®é²è¡ã確èªããŸããã
ð åã¹ãããã§ã®æ»æææ³ãšå±éºæ§ãåŠç¿ãâ åŸã§ä¿®åŸ©ããã¿ã³ãã¯ãªãã¯ããŠããã£ã³ã»ã«ãã¿ã³ã®çœ ã確èªããåŸãäžã®å¯Ÿçæ¹æ³ãèªã¿ãŸããã
ð¡ïž å®å šãªå¯ŸåŠæ³ãšå ·äœçãªå¯Ÿçãã¯ããã¯ãåŠç¿ã·ã¹ãã ãšã©ãŒ - ç·æ¥ä¿®åŸ©ãå¿ èŠ
ç·æ¥åœ±é¿ãã¡ã€ã«: system32\kernel.dll
æšå®ä¿®åŸ©æé: 2-3å
ð¡ïž ClickFixæ»æãžã®å¯Ÿçæ¹æ³
ðš å³åº§ã«å¯ŸåŠãã¹ãããš
- ããŒãžãéããïŒã修埩ããããã£ã³ã»ã«ããã¿ã³ãæŒããããã©ãŠã¶ãŒãéãã
- ã¯ãªããããŒãã確èªïŒæªããã³ãã³ããã³ããŒãããŠããªãããã§ãã¯
- PowerShellå®è¡ã®åé¿ïŒWin+Rãã€ã¢ãã°ã§ã¯çµ¶å¯Ÿã«ã³ãã³ããå®è¡ããªã
ð¡ïž äºé²å¯Ÿç
- çãã®ç¿æ £ïŒçªç¶ã®ãšã©ãŒã¡ãã»ãŒãžãã·ã¹ãã èŠåã¯çã
- å ¬åŒãã£ãã«ã®å©çšïŒã·ã¹ãã 修埩ã¯å ¬åŒãµããŒããWindows Updateã§è¡ã
- URLã®ç¢ºèªïŒä¿¡é Œã§ããªããµã€ãã§ã®äœæ¥ãé¿ãã
- ææ°ãã©ãŠã¶ãŒã®äœ¿çšïŒã»ãã¥ãªãã£æ©èœãåäžãããã©ãŠã¶ãŒã䜿çš
âïž æè¡ç察ç
- PowerShellå®è¡ããªã·ãŒïŒExecutionPolicyãRestrictedã«èšå®
- ã¯ãªããããŒãç£èŠããŒã«ïŒæªããã³ãã³ãã®ã³ããŒãæ€ç¥ããããŒã«äœ¿çš
- ãã©ãŠã¶ãŒæ¡åŒµæ©èœïŒæªæããã¹ã¯ãªããããããã¯ããæ¡åŒµæ©èœã®å°å ¥
- ãŠãŒã¶ãŒã¢ã«ãŠã³ãå¶åŸ¡(UAC)ïŒç®¡çè æš©éãå¿ èŠãªæäœã§ç¢ºèªãã€ã¢ãã°ã衚瀺
ð§² èªåéä¿¡æ»æã·ãã¥ã¬ãŒã·ã§ã³
ð¡ èªåéä¿¡æ»æãšã¯
ãŠãŒã¶ãŒãå ¥åæ¬ã«è²Œãä»ããè¡ã£ãç¬éã«ããã®å å®¹ãæ»æè ã®ãµãŒããŒãžå³åº§ã«èªåéä¿¡ããæ»æã§ãã
ä»çµã¿ïŒpasteã€ãã³ããšçµã¿åãããŠãå³åº§ã«fetch()ãXMLHttpRequestã§å€éšãµãŒããŒã«éä¿¡ããŸãã
⢠pasteã¹ããã£ã³ã°ïŒå 容ãååã»èšé²ïŒåŸã§éä¿¡ïŒ
⢠èªåéä¿¡æ»æïŒè²Œãä»ããšåæã«å³åº§ã«å€éšéä¿¡
ð¯ èªåéä¿¡æ»æãäœéšãããïŒ
ãŸããäžã®èªåéä¿¡æ»æã®èª¬æãèªãã§ä»çµã¿ãçè§£ããŸããã
ð¡ pasteã¹ããã£ã³ã°ãšã®éãã確èªããŠãã ãããã¹ãçšã®APIããŒãã³ããŒããŸãããïŒäžã®æååãã¯ãªãã¯ããŠéžæïŒ
sk-1234567890abcdef1234567890abcdef1234567890abcdef
â ã¯ãªãã¯ããŠéžæ â Ctrl+Cã§ã³ããŒ
äžã®éçºè ã³ã³ãœãŒã«ã®å ¥åæ¬ã«è²Œãä»ãããŠèªåéä¿¡æ»æãäœéš
â ïž è²Œãä»ããç¬éã«å€éšãµãŒããŒãžèªåéä¿¡ãããŸããã°ã§æ®µéçãªæ»æé²è¡ã確èªãããªã¢ã«ã¿ã€ã éä¿¡ã®å±éºæ§ãåŠç¿
ð éä¿¡ã¿ã€ãã³ã°ãšåœ±é¿ã«ã€ããŠçè§£ãæ·±ããŸãããð¡ïž èªåéä¿¡æ»æã®å¯Ÿçæ¹æ³
ð§ æè¡ç察ç
- CSP (Content Security Policy)ïŒå€éšãžã®äžæ£éä¿¡ããããã¯
- CORSèšå®ïŒä¿¡é Œã§ãããªãªãžã³ããã®éä¿¡ã®ã¿èš±å¯
- å ¥åå€ãµãã¿ã€ãŒãŒã·ã§ã³ïŒå±éºãªæååãã¿ãŒã³ã®æ€åºãšé€å»
- Rate LimitingïŒçæéã§ã®å€§éãªã¯ãšã¹ããå¶é
- HTTPS匷å¶ïŒéä¿¡ã®æå·åã§MITMæ»æã鲿¢
ð€ ãŠãŒã¶ãŒå¯Ÿç
- ä¿¡é Œã§ããªããµã€ãã§ã®è²Œãä»ãåé¿ïŒAPIããŒãèšå®æ å ±ã¯æ éã«
- ãã©ãŠã¶ã®ã»ãã¥ãªãã£èšå®ïŒã¯ãªããããŒãæš©éã®ç¢ºèª
- éçºè ããŒã«ã§ã®æ€èšŒïŒNetworkã¿ãã§ã®éä¿¡ç£èŠ
- ãã¹ã¯ãŒããããŒãžã£ãŒæŽ»çšïŒæåã³ããã®åæž
- 宿çãªAPIããŒæŽæ°ïŒæŒæŽ©ãªã¹ã¯ã®æå°å
ð¢ çµç¹ç察ç
- ã»ãã¥ãªãã£æè²ïŒéçºè åãã®ã¯ãªããããŒãæ»æåçº
- ã³ãŒãã¬ãã¥ãŒïŒpasteã€ãã³ããã³ãã©ãŒã®ç£æ»
- ç£èŠã·ã¹ãã ïŒç°åžžãªå€éšéä¿¡ã®æ€ç¥
- ã€ã³ã·ãã³ã察å¿ïŒæ å ±æŒæŽ©æã®è¿ éãªå¯ŸåŠããã»ã¹
- 宿çç£æ»ïŒWebã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ãã§ãã¯
ðš ç·æ¥æå¯Ÿå¿
- APIããŒå³åº§ç¡å¹åïŒæŒæŽ©çããããå Žåã®ç·æ¥åæ¢
- ã¢ã¯ã»ã¹ãã°ç¢ºèªïŒäžæ£äœ¿çšã®ç跡調æ»
- éä¿¡ãã°åæïŒããŒã¿éä¿¡å ãšå 容ã®ç¹å®
- 被害ç¯å²ç¹å®ïŒåœ±é¿ãåããã·ã¹ãã ãšããŒã¿ã®èª¿æ»
- é¢ä¿è éç¥ïŒã»ãã¥ãªãã£ããŒã ã管çè ãžã®å ±å
𧪠UnicodeæåçŽ°å·¥æ»æ
ð¡ UnicodeæåçŽ°å·¥æ»æãšã¯
èŠãç®äžã¯æ£åžžã«èŠããããå®éã¯äžæ£ãªæåïŒãŒãå¹ æåãå¶åŸ¡æåãRTLæåãªã©ïŒãå«ãæååã䜿ã£ãæ»æææ³ã§ãã
å±éºæ§ïŒãã¡ã€ã«ååœè£ ããã£ãã·ã³ã°è©æ¬ºãã»ãã¥ãªãã£æ€èšŒã®åé¿ãªã©ã«æªçšãããå¯èœæ§ããããŸãã
ð¯ Unicodeæ»æãäœéšãããïŒ
ãŸãåºæ¬çãªãŒãå¹ ã¹ããŒã¹æ»æãäœéšããŸããã
äžèŠæ®éã®ãã¡ã€ã«åã«èŠããŸãããé ãããæåãå«ãŸããŠããŸããŒãå¹ ã¹ããŒã¹æ··å ¥ãã¡ã€ã«åãã³ããŒããŠäœéšããŠãã ãã
ð¡ äžã®ãã¿ã³ãã¯ãªãã¯ããŠããããã¹ããšãã£ã¿ã«è²Œãä»ããŠã¿ãŠãã ããä»åºŠã¯RTLïŒå³ããå·ŠïŒæåã«ãããã¡ã€ã«æ¡åŒµååœè£ ãäœéšããŸããã
â ïž å®è¡ãã¡ã€ã«ãç»åãã¡ã€ã«ã«èŠããããªãã¯ã§ããã¹ãŠã®æ»æãã¿ãŒã³ãçè§£ã§ããŸãã
ð ãããã®ææ³ãã©ã®ããã«æªçšããããã確èªããŸãããð¯ æ»æå®æŒãã¢
â ïž å®éã®æ»æã·ããªãªè©³çް
ð ãŒãå¹ ã¹ããŒã¹æ»æ
- ãã¡ã€ã«ååœè£ ïŒflag.txt ãå®é㯠fla[ZWSP]g.txt ãšãªã£ãŠãã
- æ€çŽ¢åé¿ïŒã·ã¹ãã ã®æ€çŽ¢æ©èœã§èŠã€ãããªããã¡ã€ã«åãäœæ
- éè€ãã¡ã€ã«äœæïŒèŠãç®äžåãååã§è€æ°ãã¡ã€ã«ãäœæ
- ã»ãã¥ãªãã£ããŒã«åé¿ïŒãã©ãã¯ãªã¹ãã«èŒã£ããã¡ã€ã«åã®æ€åºåé¿
ð RTLæåæ»æ
- æ¡åŒµååœè£ ïŒevil[RTL]gnp.exe ã exe.png ã«èŠãã
- URLåœè£ ïŒæªæãããã¡ã€ã³ãä¿¡é Œã§ãããµã€ãã«èŠããã
- ãã£ãã·ã³ã°è©æ¬ºïŒæ£èŠãµã€ããã£ããã®URLãäœæ
- ãã«ãŠã§ã¢é åžïŒå®è¡ãã¡ã€ã«ãç¡å®³ãªãã¡ã€ã«ã«åœè£
ð¥ å圢ç°çŸ©æåæ»æ
- ãã¡ã€ã³ãªãããŸãïŒÐ°pple.comïŒããªã«æåã®Ð°ïŒã§apple.comãåœè£
- IDNåœè£ æ»æïŒåœéåãã¡ã€ã³åã®è匱æ§ãæªçš
- èªèšŒæ å ±è©åïŒæ£èŠãµã€ããšèŠåããã€ããªãåœãµã€ãäœæ
- ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ïŒä¿¡é Œæ§ã®é«ãäŒæ¥åãæš¡å£
ð¡ïž Unicodeæ»æã®å¯Ÿçæ¹æ³
ð§ æè¡ç察ç
- æå忣èŠåïŒUnicodeæ£èŠåïŒNFCãNFDïŒã§ãŒãå¹ æåãé€å»
- æåçš®å¶éïŒèš±å¯ããæåã»ãããæç¢ºã«å®çŸ©
- IDN衚瀺ïŒãã©ãŠã¶ãŒã§Punycodeã衚瀺ãããèšå®
- ãã¡ã€ã«åæ€èšŒïŒå¶åŸ¡æåãRTLæåã®æ··å ¥ãæ€åº
- ãã©ã³ãèšå®ïŒãŒãå¹ æåãå¯èŠåãããã©ã³ã䜿çš
ð€ ãŠãŒã¶ãŒå¯Ÿç
- URL確èªïŒã¢ãã¬ã¹ããŒãæ³šææ·±ã確èªãã
- ãã¡ã€ã«æ€èšŒïŒããŠã³ããŒããããã¡ã€ã«ã®æ¡åŒµåã確èª
- ããã¯ããŒã¯æŽ»çšïŒéèŠãªãµã€ãã¯æåå ¥åã§ã¯ãªãããã¯ããŒã¯ãã
- ã»ãã¥ãªãã£ãœããïŒææ°ã®ã¢ã³ããŠã€ã«ã¹ãœããã䜿çš
- ããããããŒããŒã«æŽ»çšïŒçããããã¡ã€ã«åãã³ããŒããŠæ€èšŒ
ð¢ ã·ã¹ãã 察ç
- å ¥å倿€èšŒïŒWebã¢ããªã±ãŒã·ã§ã³ã§ã®å³å¯ãªæåçš®ãã§ãã¯
- ãã¡ã€ã«ã¢ããããŒãå¶éïŒäžæ£æåãå«ããã¡ã€ã«åã®æåŠ
- ã¡ãŒã« ãã£ã«ã¿ãªã³ã°ïŒäžæ£ãªUnicodeæåãå«ãã¡ãŒã«ã®æ€åº
- DNSèšå®ïŒIDNåœè£ æ»æã«å¯ŸããDNSãã£ã«ã¿ãªã³ã°
- å®æç£æ»ïŒã·ã¹ãã å ã®äžæ£ãã¡ã€ã«åã®å®æãã§ãã¯
ð ã¯ãªããããŒãã»ãã¥ãªãã£å®å šã¬ã€ã
ð¡ ãã®ã¬ã€ãã«ã€ããŠ
ãã®ã¿ãã§ã¯ãã¯ãªããããŒãé¢é£ã®è åšã«å¯Ÿããå æ¬çãªã»ãã¥ãªãã£å¯ŸçããŸãšããŠããŸãã
察象ïŒäžè¬ãŠãŒã¶ãŒãéçºè ãã·ã¹ãã 管çè ãæ å ±ã»ãã¥ãªãã£æ åœè
ð€ äžè¬ãŠãŒã¶ãŒåãã»ãã¥ãªãã£å¯Ÿç
ð åºæ¬çãªå®å šå¯Ÿç
- ä¿¡é Œã§ããªããµã€ãã§ã®è²Œãä»ãåé¿ïŒãã¹ã¯ãŒããAPIããŒãå人æ å ±ã¯ä¿¡é Œã§ãããµã€ãã§ã®ã¿è²Œãä»ã
- ãã©ãŠã¶ãŒã®æš©é確èªïŒã¯ãªããããŒãã¢ã¯ã»ã¹èš±å¯ãã€ã¢ãã°ã¯æ éã«å€æ
- ãã¹ã¯ãŒããããŒãžã£ãŒæŽ»çšïŒèªåå ¥åæ©èœã§ã³ããã®ãªã¹ã¯ãåæž
- 貌ãä»ãåã®ç¢ºèªïŒéèŠãªæ å ±ã¯è²Œãä»ãåã«å 容ã確èª
- 宿çãªã¯ãªããããŒãã¯ãªã¢ïŒæ©å¯æ å ±äœ¿çšåŸã¯ã¯ãªããããŒãã空ã«ãã
â ïž å±éºãªè¡åãã¿ãŒã³
- ãã£ãã·ã³ã°ãµã€ãã§ã®è²Œãä»ãïŒURLã確èªãããã¹ã¯ãŒãã貌ãä»ã
- å ¬å ±ç«¯æ«ã§ã®æ©å¯æ å ±ã³ããŒïŒå ±æPCã§ã®ãã¹ã¯ãŒããã«ãŒãæ å ±ã®äœ¿çš
- ã¡ãŒã«ã»ãã£ããã§ã®çŽæ¥è²Œãä»ãïŒæå·åãããŠããªãéä¿¡ã§ã®æ©å¯æ å ±å ±æ
- äžæãªãµã€ãã§ã®ã修埩ããã¿ã³ã¯ãªãã¯ïŒClickFixæ»æãžã®å¯Ÿå¿
- ãã¡ã€ã«åã®èŠãç®ã ãã§å€æïŒUnicodeæ»æã«ããåœè£ ã®èŠèœãšã
ð¡ïž æšå¥šããŒã«ãšèšå®
- ãã©ãŠã¶ãŒèšå®ïŒäžèŠãªãµã€ãããã®ã¯ãªããããŒãã¢ã¯ã»ã¹ãå¶é
- ã»ãã¥ãªãã£æ¡åŒµæ©èœïŒã¯ãªããããŒãä¿è·æ©èœãæã€æ¡åŒµæ©èœã®å°å ¥
- ã¢ã³ããŠã€ã«ã¹ãœããïŒã¯ãªããããŒãç£èŠæ©èœãæã€è£œåã®éžæ
- 2èŠçŽ èªèšŒïŒãã¹ã¯ãŒãæŒæŽ©æã®ãªã¹ã¯è»œæž
- 宿çãªãã¹ã¯ãŒãæŽæ°ïŒæŒæŽ©ãªã¹ã¯ãèæ ®ããéçš
ð» éçºè åãã»ãã¥ãªãã£å®è£
ð§ æè¡ç察çã®å®è£
- CSP (Content Security Policy)ïŒå€éšãžã®äžæ£éä¿¡ããããã¯ããããããŒèšå®
- å ¥å倿€èšŒïŒpasteã€ãã³ãã§ååŸããããŒã¿ã®å³å¯ãªããªããŒã·ã§ã³
- Rate LimitingïŒçæéã§ã®å€§éãªã¯ãšã¹ããå¶éããAPIèšèš
- ãã°èšé²ïŒç°åžžãªã¯ãªããããŒãæäœãpaste ã€ãã³ãã®ç£èŠ
- æå·åïŒæ©å¯ããŒã¿ã®æå·åä¿åãšéä¿¡
ð å®å šãªã³ãŒãã£ã³ã°æ £è¡
- pasteã€ãã³ãã®æå°é䜿çšïŒå¿ èŠæå°éã§ã®å©çšãšãŠãŒã¶ãŒãžã®éææ§ç¢ºä¿
- ããŒã¿ãµãã¿ã€ãŒãŒã·ã§ã³ïŒãŠãŒã¶ãŒå ¥åã®é©åãªç¡å®³ååŠç
- HTTPS匷å¶ïŒå šéä¿¡ã®æå·åãšMITMæ»æå¯Ÿç
- ãšã©ãŒãã³ããªã³ã°ïŒæ©å¯æ å ±ãå«ãŸãªããšã©ãŒã¡ãã»ãŒãž
- ã»ãã¥ãªãã£ãã¹ãïŒå®æçãªè匱æ§ã¹ãã£ã³ãšãããã¬ãŒã·ã§ã³ãã¹ã
ð ã»ãã¥ã¢ãªéçºäŸ
- Clipboard API ã®é©åãªäœ¿çšïŒæš©éãã§ãã¯ãšãšã©ãŒãã³ããªã³ã°
- ããã³ããšã³ãä¿è·ïŒéèŠãªåŠçã¯ãµãŒããŒãµã€ãã§å®è¡
- ç£æ»ãã°ïŒã»ãã¥ãªãã£ã€ãã³ãã®èšé²ãšåæ
- äŸåé¢ä¿ç®¡çïŒãµãŒãããŒãã£ã©ã€ãã©ãªã®è匱æ§ç®¡ç
- ã»ãã¥ãªãã£ããããŒïŒå æ¬çãªHTTPã»ãã¥ãªãã£ããããŒã®èšå®
ð¢ ã·ã¹ãã 管çè åãéçšå¯Ÿç
ð¡ïž çµç¹ã¬ãã«ã§ã®å¯Ÿç
- ããªã·ãŒçå®ïŒã¯ãªããããŒã䜿çšã«é¢ããã»ãã¥ãªãã£ããªã·ãŒã®å¶å®
- åŸæ¥å¡æè²ïŒå®æçãªã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°
- æè¡çå¶åŸ¡ïŒãšã³ããã€ã³ãä¿è·ãœããã«ããã¯ãªããããŒãç£èŠ
- ãããã¯ãŒã¯ç£èŠïŒç°åžžãªå€éšéä¿¡ã®æ€åºãšåæ
- ã€ã³ã·ãã³ã察å¿ïŒã¯ãªããããŒãé¢é£ã®æ å ±æŒæŽ©å¯Ÿå¿æé
ð ç£èŠãšåæ
- ãã°åæïŒWebã¢ããªã±ãŒã·ã§ã³ãã°ã§ã®ç°åžžæ€åº
- ãããã¯ãŒã¯åæïŒDLP (Data Loss Prevention) ããŒã«ã®æŽ»çš
- ãšã³ããã€ã³ãç£èŠïŒäžå¯©ãªã¯ãªããããŒãæäœã®æ€åº
- è åšã€ã³ããªãžã§ã³ã¹ïŒææ°ã®æ»æææ³æ å ±ã®åé
- 宿çç£æ»ïŒã»ãã¥ãªãã£å¯Ÿçã®æå¹æ§è©äŸ¡
ðš ã€ã³ã·ãã³ã察å¿
- åå察å¿ïŒã¯ãªããããŒãæ»æãçãããå Žåã®ç·æ¥æé
- 蚌æ ä¿å šïŒãã©ã¬ã³ãžãã¯èª¿æ»ã®ããã®ããŒã¿ä¿å
- 圱é¿è©äŸ¡ïŒæŒæŽ©ããããŒã¿ã®ç¯å²ãšåœ±é¿åºŠã®è©äŸ¡
- åŸ©æ§æé ïŒã·ã¹ãã ãšããŒã¿ã®å®å šãªåŸ©æ§ããã»ã¹
- äºåŸå¯ŸçïŒåçºé²æ¢ã®ããã®æ¹åæœç
ðš ç·æ¥æå¯Ÿå¿ã¬ã€ã
â¡ ã¯ãªããããŒãæ»æãåããå Žå
- å³åº§ã«åæïŒçããããµã€ãããããã«é¢ãã
- ã¯ãªããããŒãã¯ãªã¢ïŒæ©å¯æ å ±ãã¯ãªããããŒãããåé€
- ãã¹ã¯ãŒã倿ŽïŒåœ±é¿ãåããå¯èœæ§ã®ããã¢ã«ãŠã³ã
- 2èŠçŽ èªèšŒç¢ºèªïŒäžå¯©ãªãã°ã€ã³è©Šè¡ããã§ãã¯
- ãããã¯ãŒã¯é®æïŒå¿ èŠã«å¿ããŠãããã¯ãŒã¯æ¥ç¶ãåæ
- ã»ãã¥ãªãã£ããŒã é£çµ¡ïŒçµç¹å ã§ã®å ±åãšé£æº
- 蚌æ ä¿å šïŒã¹ã¯ãªãŒã³ã·ã§ããããã°ã®ä¿å
- 圱é¿èª¿æ»ïŒæŒæŽ©ããå¯èœæ§ã®ããããŒã¿ã®ç¹å®
ð 被害確èªã®æ¹æ³
- ãã©ãŠã¶ãŒã®éçºè ããŒã«ïŒNetworkã¿ãã§äžå¯©ãªéä¿¡ã確èª
- ã¢ã«ãŠã³ã掻åãã°ïŒåãµãŒãã¹ã§ã®ç°åžžãªã¢ã¯ã»ã¹å±¥æŽããã§ãã¯
- ã¯ã¬ãžããã«ãŒãæçްïŒäžæ£å©çšããªããã®ç¢ºèª
- ã·ã¹ãã ãã°ïŒäŒæ¥ç°å¢ã§ã®ç°åžžãªã¢ã¯ã»ã¹ãã¿ãŒã³æ€åº
- ã¡ãŒã«ç¢ºèªïŒã¢ã«ãŠã³ã倿Žéç¥ãªã©ã®æç¡
ð é£çµ¡å ãšå ±å
- çµç¹å ã»ãã¥ãªãã£ããŒã ïŒç€Ÿå CSIRT oræ å ±ã·ã¹ãã éšé
- é¢é£ãµãŒãã¹æäŸè ïŒåœ±é¿ãåããå¯èœæ§ã®ãããµãŒãã¹
- æ³å·è¡æ©é¢ïŒé倧ãªè¢«å®³ã®å Žåã¯ãµã€ããŒç¯çœªçžè«çªå£
- ã»ãã¥ãªãã£ãã³ããŒïŒã€ã³ã·ãã³ãå¯Ÿå¿æ¯æŽã®èŠè«
- ä¿éºäŒç€ŸïŒãµã€ããŒä¿éºå å ¥æã®é£çµ¡
ð ææ°è åšååãšå¯Ÿçãã¬ã³ã
ð 2024幎ã®ã¯ãªããããŒãæ»æãã¬ã³ã
- AIçæãã£ãã·ã³ã°ïŒããå·§åŠåãããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ææ³
- ã¢ãã€ã«ç«¯æ«ãžã®æ¡å€§ïŒã¹ããŒããã©ã³ã»ã¿ãã¬ããã§ã®æ»æå¢å
- ãŒãã¯ãªãã¯æ»æïŒãŠãŒã¶ãŒæäœãå¿ èŠãšããªãé«åºŠãªæ»æ
- ãµãã©ã€ãã§ãŒã³æ»æïŒä¿¡é Œã§ãããœãããŠã§ã¢ã®æªçš
- æå·è³ç£çãæã¡ïŒãŠã©ã¬ããã¢ãã¬ã¹ãã·ãŒããã¬ãŒãºã®çãæã¡
ð¡ïž æ°ããé²åŸ¡æè¡
- æ©æ¢°åŠç¿ããŒã¹ã®æ€ç¥ïŒç°åžžãªè²Œãä»ããã¿ãŒã³ã®èªåæ€åº
- ãŒããã©ã¹ãã¢ãŒããã¯ãã£ïŒãã¹ãŠã®éä¿¡ãæ€èšŒããèšèš
- è¡ååæïŒãŠãŒã¶ãŒã®æ£åžžãªè¡åãã¿ãŒã³ãšã®æ¯èŒ
- ãªã¢ã«ã¿ã€ã è åšã€ã³ããªãžã§ã³ã¹ïŒææ°æ»æææ³ã®å³åº§ãªå¯Ÿå¿
- åé¢å®è¡ç°å¢ïŒä»®æ³ç°å¢ã§ã®å®å šãªæäœ
ð¯ ä»åŸäºæ³ãããè åš
- éåã³ã³ãã¥ãŒãã£ã³ã°å¯Ÿå¿ïŒæ¢åæå·åã®çªç Žãšå¯Ÿç
- IoTããã€ã¹é£æºæ»æïŒè€æ°ããã€ã¹éã§ã®ã¯ãªããããŒãå ±ææªçš
- VR/ARç°å¢ã§ã®æ»æïŒæ°ããã€ã³ã¿ãŒãã§ãŒã¹ã§ã®è åš
- çäœèªèšŒã®åé¿ïŒãã€ãªã¡ããªã¯ã¹æè¡ãžã®å¯Ÿå¿
- ã¯ã©ãŠããµãŒãã¹æªçšïŒåæ³çãµãŒãã¹ã䜿ã£ãæ»æææ³