ã¯ããæãèãããç°å¢ã«åªãããã€ã³ã¿ãŒããããããå®å šã«ãªã£ããšããWebããŒã¹ã®ãšã³ã¿ãŒãã©ã€ãºç®¡çïŒWBEMïŒã€ãã·ã¢ãããITã§çãŸããŸãããããšããšã¯1996幎ã«CiscoSystemsãIntelãMicrosoftãªã©ã®äŒæ¥ã«ãã£ãŠåŸæŽãããŸããããMAC OSããRedhatãŸã§ã®ãã©ãããã©ãŒã ã§åºãæ¡çšãããå®è£ ãããŠããŸãã WBEMã¯ãã€ã³ã¿ãŒãããæšæºã«åºã¥ããŠæç¢ºã«ææžåãããŠãããããšãã°ãSNMPãšã¯ç°ãªãã·ã¹ãã 管çã¢ãããŒããæäŸããŸãã
WBEM for Windowsã®é©å¿ã¯ãWMIïŒWindows管çã€ã³ã¿ãŒãã§ã€ã¹ïŒãšåŒã°ããWindowsXPã§æåã«å°å ¥ãããŸãããã·ã¹ãã ã¯ã³ã³ããŒãã³ããããéãæŽæ°ããã以åã¯äŸ¿å©ãªç®¡çããŒã«ã§ãã£ãå€ãã®è匱æ§ãããŒãžã§ã³éã§ç§»è¡ããããšãç§ãã¡ã¯ç¥ã£ãŠããŸãããã®èšäºã§ã¯ãWMIã¿ã¹ã¯ãã©ã®ããã«å®è¡ãããæœåšçãªãªã¹ã¯ãåé¿ããæ¹æ³ã«ã€ããŠèª¬æããããšæããŸãã
WMIã¯ããã®èœåã«ãããç¹å¥ãªãŠãŒãã£ãªãã£ãã¹ã¯ãªããã䜿çšããŠãéèŠãªãµãŒãã¹ã®åæ¢ãã³ã³ãã¥ãŒã¿ã®ã·ã£ããããŠã³ãªã©ãPCäžã§ããŸããŸãªæœåšçã«å±éºãªã¢ã¯ã·ã§ã³ãå®è¡ã§ããŸããããšãã°ã次ã®ããã«ãªããŸãã
ïŒGet-WmiObject Win32_OperatingSystem -EnableAllPrivilegesïŒ.Win32ShutdownïŒ5ïŒ
ïŒGWMI -Class Win32_Service -Filter "name = 'WinRM'" -ComputerName ServerïŒ.StopServiceïŒïŒ
ããã«ããããã®ã¢ã¯ã·ã§ã³ããªã¢ãŒããã·ã³ã§åãæ¹æ³ã§å®è¡ããŸããããŒã«ã«ã®ãã®ãšåãããã«ãWMIãªããžã§ã¯ããžã®ãã¹ã«å¿ èŠãªãã·ã³ã®ååãæžã蟌ãã ãã§ãã
WMIããŒã ã¹ããŒã¹ã¯ãWMIãªããžããªã®ã»ã¯ã·ã§ã³ã§ãããç®çããšã«WMIã¯ã©ã¹ãšãªããžã§ã¯ããã°ã«ãŒãåãããã®ãããªåã³ã³ããå ã®ã¯ã©ã¹ãšãªããžã§ã¯ãã«ã¢ã¯ã»ã¹ãããšãã«ã»ãã¥ãªãã£å±æ§ãå®çŸ©ããããã«èšèšãããŠããŸãããã¹ãŠã®åååã¯rootã§å§ãŸããŸããããã¯ãWMIã§ã¯ããŒã¯ãŒãrootã§ç€ºãããŸããåååã®åŸã«ã¯ãã«ãŒãåã®åŸã«ã¹ã©ãã·ã¥ãç¶ããŸããåå空éã¯ãã¹ãã§ããŸããè峿·±ãã¯ã©ã¹ãšãªããžã§ã¯ãã®ã»ãšãã©ã¯ãã«ãŒã/ CIMv2åååã«ãããŸãã
æ¢åã®WindowsWMIããŒã ã¹ããŒã¹ã®1ã€ãããã©ã«ããšããŠéžæã§ããŸããã€ãŸããåååãæå®ããã«ãã®ãã¹ãã«æ¥ç¶ããããšãããšãããã©ã«ãã§éžæãããŠãããã¹ãã«èªåçã«æ¥ç¶ãããŸããæšæºã®Windowsã€ã³ã¹ããŒã«ã§ã¯ãããã©ã«ãã®ã¹ããŒã¹ã¯root \ cimv2ã§ãã
WMIãã¯ãããžãŒã¯Windows管çè åãã«èšèšãããŠãããWMIã®ã»ãã¥ãªãã£ã·ã¹ãã å šäœã¯ãWMIã¹ã¯ãªããã䜿çšããŠãç¹å®ã®PCã®ãŠãŒã¶ãŒããã¢ã¯ã»ã¹èš±å¯/ç¹æš©ãä»äžãããã¢ã¯ã·ã§ã³ã®ã¿ãå®è¡ã§ããããã«èšèšãããŠããŸãããããã¯ãããããããã©ã«ãã®ç¹æš©ã§ããããã¯ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¬ãã«ã§WMIã»ãã¥ãªãã£ãå®è£ ããæ¹æ³ã§ãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã¬ãã«ã®ãŠãŒã¶ãŒã«ã³ã³ãã¥ãŒã¿ãŒãåèµ·åããæš©éãäžããããŠããªãå ŽåãWMIã䜿çšããŠãããè¡ãããšã¯ã§ããŸããã
WMIã®è¿œå ã®ã»ãã¥ãªãã£ããªã·ãŒã¯ã忣ã³ã³ããŒãã³ããªããžã§ã¯ãã¢ãã«ã§ãã忣COMïŒDCOMïŒãããã³ã«åå空éã¬ãã«ã§å®è£ ãããŸãããããã®ã¿ã€ãã®WMIã»ãã¥ãªãã£ã詳ãã調ã¹ãããã«ãWindowsã®ã»ãã¥ãªãã£ã«é¢é£ããåºæ¬çãªäžè¬çãªæŠå¿µãç°¡åã«æãåºããŸãããããŠããã®ã»ãã¥ãªãã£ã¯ãŠãŒã¶ãŒåãšãã®ãã¹ã¯ãŒãã«åºã¥ããŠããŸãã
WMIæš©éã«ã€ããŠ
ãŠãŒã¶ãŒãWindowsã§äœæããããšããã®ã·ã¹ãã ã¢ã«ãŠã³ãã«ã¯äžæã®ã»ãã¥ãªãã£èå¥åïŒã»ãã¥ãªãã£IDentifierããŸãã¯SIDïŒãå²ãåœãŠãããŸãã SIDã«åºã¥ããŠããŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ããŒã¯ã³ãçæããããŠãŒã¶ãŒãã¡ã³ããŒã«ãªã£ãŠããã°ã«ãŒãã®ãªã¹ããšããŠãŒã¶ãŒãæã£ãŠããç¹æš©ã®ãªã¹ãïŒããšãã°ããµãŒãã¹ã®åæ¢ãã³ã³ãã¥ãŒã¿ãŒã®ã·ã£ããããŠã³ïŒã远å ãããŸãããã®ã¢ã¯ã»ã¹ããŒã¯ã³ã¯ããŠãŒã¶ãŒãéå§ãããã¹ãŠã®ããã»ã¹ã«ãå²ãåœãŠãããŸããçŸæç¹ã§ã¯ãã»ãã¥ãªãã£ã·ã¹ãã ã«ãã£ãŠã¢ã¯ã»ã¹ã決å®ããããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã®ãã¹ãŠã®ãªããžã§ã¯ãïŒãã¡ã€ã«ãããã»ã¹ããµãŒãã¹ããŸãã¯ãã®ä»ïŒã«ã¯ãã»ãã¥ãªãã£èšè¿°åïŒSDïŒããããŸãããã®èšè¿°åã¯ããã®ãªããžã§ã¯ãã®ã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒACLïŒãæ ŒçŽããŸãã
ãããã£ãŠããŠãŒã¶ãŒãŸãã¯ãã®ãŠãŒã¶ãŒã«ãã£ãŠèµ·åãããããã»ã¹ããªããžã§ã¯ãã«ã¢ã¯ã»ã¹ãããšããã®ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ããŒã¯ã³ãã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ããšæ¯èŒãããŸããçµæã«å¿ããŠããªããžã§ã¯ãã«å¯ŸããŠèŠæ±ãããã¢ã¯ã·ã§ã³ãå®è¡ããããã®èš±å¯/ç¹æš©ãçºè¡ãŸãã¯æåŠãããŸãã
åååã¬ãã«ã§ã¯ãWMIã»ãã¥ãªãã£ã¡ã«ããºã ã¯äžè¬çãªWindowsã»ãã¥ãªãã£ã¢ãã«ã«åŸããŸããååååã«ã¯ãã¢ã¯ã»ã¹å¶åŸ¡ãªã¹ãïŒACLïŒãæ ŒçŽããç¬èªã®ã»ãã¥ãªãã£èšè¿°åãå«ããããšãã§ããŸãã
åã¢ã¯ã»ã¹å¶åŸ¡ãšã³ããªïŒACEïŒãšã³ããªã«ã¯ãç¹å®ã®ãŠãŒã¶ãŒããã®åååã§ããŸããŸãªæäœãå®è¡ãããšãã«æã€ã¢ã¯ã»ã¹èš±å¯ã«é¢ããæ å ±ãå«ãŸããŠããŸãã
ãŸããåååãæäœãããšãã®ã¢ã¯ã»ã¹èš±å¯ã®ãªã¹ãã¯æ¬¡ã®ãšããã§ã
ãã¡ãœããã®å®è¡ãç¹å®ã®åååããã¯ã©ã¹ã®ã¡ãœãããåŒã³åºãããšãã§ããŸããã¡ãœãããæåããã倱æãããã¯ããŠãŒã¶ãŒãã·ã¹ãã ã§æäœãå®è¡ããæš©éãæã£ãŠãããã©ããã«ãã£ãŠç°ãªããŸãã
ãã«ã©ã€ãããµãããŒã ã¹ããŒã¹ãã·ã¹ãã ã¯ã©ã¹ãããã³ã¯ã©ã¹ã€ã³ã¹ã¿ã³ã¹ã®äœæãšå€æŽãèš±å¯ããŸãã
éšåæžã蟌ã¿ãéã·ã¹ãã ã¯ã©ã¹ã®éçã¯ã©ã¹ããã³ã€ã³ã¹ã¿ã³ã¹ãäœæããã³å€æŽããæ©èœãéããŸãã
ãããã€ããŒæžã蟌ã¿ãWMIãããã€ããŒã¯ã©ã¹ãšãããã®ã¯ã©ã¹ã®ã€ã³ã¹ã¿ã³ã¹ãCIMãªããžããªã«æžã蟌ãããšãã§ããŸãã
ã¢ã«ãŠã³ããæå¹ã«ããŸãã WMIåååãžã®èªã¿åãã¢ã¯ã»ã¹ãèš±å¯ããŸãããã®æš©éãæã€ãŠãŒã¶ãŒã¯ãWMIããŒã¿ãèªã¿åãããŒã«ã«ã³ã³ãã¥ãŒã¿ãŒã§ã¹ã¯ãªãããå®è¡ã§ããŸãã
ãªã¢ãŒãã§æå¹ã«ããŸãïŒãªã¢ãŒãæå¹ïŒããŠãŒã¶ãŒããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒäžã®WMIåå空éã«ã¢ã¯ã»ã¹ã§ããããã«ããŸããããã©ã«ãã§ã¯ã管çè ã®ã¿ããã®æš©éãæã£ãŠããŸããæšæºãŠãŒã¶ãŒã¯ãªã¢ãŒããã·ã³ããWMIããŒã¿ãååŸã§ããŸããã
ã»ãã¥ãªãã£ãèªãã§ãã ããã倿Žããã«WMIåååã®ã»ãã¥ãªãã£èšè¿°åãèªã¿åãæš©å©ãä»äžããŸãã
ã»ãã¥ãªãã£ã«ãŒã«ã倿ŽããŸãïŒã»ãã¥ãªãã£ã®ç·šéïŒãWMIåååã®ã»ãã¥ãªãã£èšè¿°åã倿Žã§ããŸãã
ãããã®ACLãšã³ããªã¯ãã¹ãŠãWMIãªããžããªã«ä¿åãããŸããç¹å®ã®åå空éã«å¯ŸããWMIæš©éã¯ããã®åå空éã§å®çŸ©ãããŠããïŒç¶æ¿å ã®ïŒãã¹ãŠã®ãµãåå空éãšã¯ã©ã¹ã«é©çšãããŸããåã ã®WMIã¯ã©ã¹ã«ç¬èªã®ã»ãã¥ãªãã£æš©éãå®çŸ©ããããšã¯ã§ããŸããã
ããã©ã«ãèšå®ã«ã€ããŠ
ïŒWindowsã§ã¯ã管çè ã°ã«ãŒãã¯ãäžèšã®è¡šãããã¹ãŠã®æš©éãæã¡ãä»ã®ãŠãŒã¶ãŒã®ã¢ã«ãŠã³ããæå¹ã«ãªã£ãŠãã ã¢ã«ãŠã³ãã®æå¹åïŒãæ¹æ³ïŒåŒã³åºãããšãèš±å¯ãããŠãã ã¡ãœããã®å®è¡SïŒãšCIMïŒã«ãããã€ãã¯ã©ã¹ã®æžã蟌ã¿ã€ã³ã¹ã¿ã³ã¹ã« ãããã€ãã«ããæžã蟌ã¿ãïŒã
管çè ã¯ãWMIèšå®ãŠãŒãã£ãªãã£ïŒMMC管çã³ã³ãœãŒã«wmimgmt.mscã¹ãããã€ã³ïŒã䜿çšããŠãç¹å®ã®ãŠãŒã¶ãŒã®æš©éã倿Žã§ããŸãã
ã¹ã¯ãªãŒã³ã·ã§ãã1ã
äžèšã®DCOMãããã³ã«ã¯ããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒäžã®WMIã€ã³ãã©ã¹ãã©ã¯ãã£ã«ã¢ã¯ã»ã¹ããããã«äœ¿çšãããŸãããŠãŒã¶ãŒã¯ã¹ã¯ãªãããå®è¡ããããç¹å¥ãªãŠãŒãã£ãªãã£ã䜿çšããŠWMIã«æ¥ç¶ããã¯ã©ã€ã¢ã³ããšããŠæ©èœããŸããã¢ã¯ã»ã¹ãããWMIãªããžã§ã¯ãã¯ãµãŒããŒã§ããæšæºã®DCOMåœè£ ã¬ãã«ã¯ããªã¢ãŒãã³ã³ãã¥ãŒã¿ãŒã§WMIãæäœãããšãã«äœ¿çšãããã¢ã¯ã»ã¹ããŒã¯ã³ã決å®ããããã«äœ¿çšãããŸãã
ãªãããŸããŸãã¯ãªãããŸãã¬ãã«ã«ã€ããŠ
ãã·ã¢èªã§ã¯ãããã¯ããäžåšçšã«èãããŸãããªãããŸããšã¯äœã§ããïŒãªããããå¿ èŠãªã®ã§ããïŒããã¯ãããã»ã¹ãŸãã¯ã·ã¹ãã ããªãœãŒã¹ã«æ¥ç¶ããããã«ãç¬èªã®ã»ãã¥ãªãã£ã³ã³ããã¹ãã§ã¯ãªããå¥ã®ã»ãã¥ãªãã£ããªã³ã·ãã«ã®è³æ Œæ å ±ã䜿çšããå¿ èŠãããææ³ã§ãã
æ³åããŠã¿ãŠãã ãã-LocalSystemã»ãã¥ãªãã£ã³ã³ããã¹ãã§èµ·åãããç¹å®ã®ãµãŒãã¹ã¯ãå¥ã®ã¢ã«ãŠã³ãã«ä»£ãã£ãŠïŒããšãã°ãã³ã³ãã¥ãŒã¿ã«ãã°ãªã³ããŠããçŸåšã®ãŠãŒã¶ãŒã«ä»£ãã£ãŠïŒã¢ã¯ã·ã§ã³ãå®è¡ããå¿ èŠããããŸãããã®å ŽåããµãŒãã¹ã¯ãæå®ãããã¢ã¯ã·ã§ã³ãå®è¡ããã¢ã«ãŠã³ãã®ã»ãã¥ãªãã£ã³ã³ããã¹ãã説æããç¹å¥ãªã¢ã¯ã»ã¹ããŒã¯ã³ãäœæããå¿ èŠããããŸãã
ãã®ãããªã¢ã¯ã»ã¹ããŒã¯ã³ãäœæããã«ã¯ããµãŒãã¹ã¯ãã®ãŠãŒã¶ãŒã®è³æ Œæ å ±ãç¥ã£ãŠããå¿ èŠãããããã®ããã»ã¹ãããŒã«ã«ãã·ã³ã§çºçããå Žåã¯ã以åã«ç»é²ãããããŒã«ã«ãŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ããŒã¯ã³ã®ã³ããŒãååŸããŸãã
ãããè¡ãã«ã¯ããµãŒãã¹ã®ã»ãã¥ãªãã£ã³ã³ããã¹ãã«ã¢ã¯ã»ã¹ããŒã¯ã³ãäœæããæš©éãå¿ èŠã§ãã
ããè€éãªããŒãžã§ã³ã®ãªãããŸããã€ãŸãå§ä»»ããããŸãããã®ãªãã·ã§ã³ã¯ãã¿ãŒã²ãããªãœãŒã¹ãžã®æ¥ç¶ããã»ãã¥ãªãã£ããªã³ã·ãã«èªäœïŒäžèšã®äŸã§ã¯ããŠãŒã¶ãŒã«ä»£ãã£ãŠãµãŒãã¹ã«ãã£ãŠïŒã§ã¯ãªãã仲ä»è ïŒããšãã°ãäžéãµãŒããŒïŒãä»ããŠå®è¡ãããå Žåã«å¿ èŠã§ãã
æ³åããŠã¿ãŠãã ããããŠãŒã¶ãŒã¯ããŒã¿ããŒã¹ã«çŽæ¥æ¥ç¶ããã®ã§ã¯ãªãã3çªç®ã®ãµãŒããŒäžã®Webã¢ããªã±ãŒã·ã§ã³ãä»ããŠæ¥ç¶ããŸãããã®ãããªæ¥ç¶ã確ç«ããã«ã¯ãWebã¢ããªã±ãŒã·ã§ã³ãã»ãã¥ãªãã£ããªã³ã·ãã«ïŒåœç€Ÿã®ãµãŒãã¹ïŒããããªã²ãŒãã¢ã¯ã»ã¹ããŒã¯ã³ãåä¿¡ããå¿ èŠããããŸããããã«ãããWebã¢ããªã±ãŒã·ã§ã³ã¯ããŒã¿ããŒã¹ã«æ¥ç¶ãããšãã«ã»ãã¥ãªãã£ããªã³ã·ãã«ã®ã¢ã¯ã»ã¹ããŒã¯ã³ã䜿çšã§ããããã«ãªããŸãã
WMIã®å Žåãå§ä»»ã¯æ¬¡ã®ããã«ãªããŸãã管çè ã¹ããŒã·ã§ã³ã§äœæ¥ããWMIãä»ããŠç¹å®ã®ãµãŒããŒã«æ¥ç¶ããWin32_Processã¯ã©ã¹ã®Executeã¡ãœããã䜿çšããŠãã®ãµãŒããŒã§ããã»ã¹ãéå§ããŸãããã®ããã»ã¹ã¯ãäœããã®ã¢ã¯ã·ã§ã³ãå®è¡ããããã«ãããã¯ãŒã¯äžã®å¥ã®ãã¹ãã«æ¥ç¶ããå¥ã®WMIã¹ã¯ãªããã«ãããŸãããå§ä»»ã䜿çšããªãå Žåãã¿ãŒã²ãããã·ã³ã§ã¯ãã¹ã¯ãªããã¯äžéãµãŒããŒã¢ã«ãŠã³ãã®ã»ãã¥ãªãã£ã³ã³ããã¹ãã§èµ·åãããŸãããããã¯åžžã«æãŸãããšã¯èšããŸãããäžæ¹ãå®ç掻ã§ã®å§ä»»ã«é¢ããåæ§ã®ç¶æ³ã¯ãã£ãã«çºçããŸããã
ãªãããŸãã¬ãã«ã«ã€ããŠ
å¿åã¢ã¯ã»ã¹ïŒå¿åïŒããµãŒããŒãªããžã§ã¯ãã«ã¯ããã®ãªããžã§ã¯ãã«ã¢ã¯ã»ã¹ããŠãããŠãŒã¶ãŒãŸãã¯ããã»ã¹ã«é¢ããæ å ±ãååŸããæš©å©ããããŸããïŒã€ãŸãããªããžã§ã¯ãã¯ã¯ã©ã€ã¢ã³ãã«ãªãããŸãããšã¯ã§ããŸããïŒããã®ã¬ãã«ã®ãªãããŸãã¯ãWMIã§ã¯äœ¿çšãããŸããã
èå¥ããµãŒããŒãªããžã§ã¯ãã¯ãã¯ã©ã€ã¢ã³ãã«é¢é£ä»ããããã¢ã¯ã»ã¹ããŒã¯ã³ãèŠæ±ã§ããŸãããåœè£ ããããšã¯ã§ããŸããã
ãã®ã¬ãã«ã®åœè£ ãWMIã¹ã¯ãªããã§äœ¿çšãããããšã¯ãã£ãã«ãããŸããããã®å Žåããªã¢ãŒããã·ã³ã§WMIã¹ã¯ãªãããå®è¡ããããšã¯ã§ããŸããã
ãªãããŸãããµãŒããŒãªããžã§ã¯ãã¯ãã¯ã©ã€ã¢ã³ããæã€ãã¹ãŠã®æš©éãšç¹æš©ã䜿çšã§ããŸãã WMIã¹ã¯ãªããã§ã¯ããã®ã¬ãã«ã®åœè£ ã䜿çšããããšããå§ãããŸããããã«ããããªã¢ãŒããã·ã³ã®WMIã¹ã¯ãªããã¯ãã¹ã¯ãªãããå®è¡ãããŠãŒã¶ãŒãå®è¡ã§ãããã¹ãŠã®ã¢ã¯ã·ã§ã³ãå®è¡ã§ããããã«ãªããŸãã
å§ä»»ã¯ã©ã€ã¢ã³ããã¢ã¯ã»ã¹ããŠãããµãŒããŒäžã®ãªããžã§ã¯ãã¯ãã¯ã©ã€ã¢ã³ãã«ä»£ãã£ãŠå¥ã®ãµãŒããŒäžã®å¥ã®ãªããžã§ã¯ããåç §ã§ããŸããå§ä»»ã«ãããã¹ã¯ãªããã¯ãªã¢ãŒããã·ã³ã§ã¹ã¯ãªãããå®è¡ããŠãããŠãŒã¶ãŒã®ã¢ã¯ã»ã¹ããŒã¯ã³ã䜿çšã§ããŸããåãããŒã¯ã³ã䜿çšããŠãä»ã®ã¯ãŒã¯ã¹ããŒã·ã§ã³äžã®WMIãªããžã§ã¯ãã«ã¢ã¯ã»ã¹ããŸãããã®ã¬ãã«ã®åœè£ ã«ã¯æœåšçãªãªã¹ã¯ããããŸããWMIã¹ã¯ãªããã§ã®å§ä»»ã¯ãå³å¯ã«å¿ èŠãªå Žåã«ã®ã¿äœ¿çšããå¿ èŠããããŸãã
ããã©ã«ãã®åœè£ ã¬ãã«ã¯ãã¿ãŒã²ããã³ã³ãã¥ãŒã¿ãŒã®WMIã®ããŒãžã§ã³ã«ãã£ãŠç°ãªããŸãã 1.5æªæºã®ããŒãžã§ã³ã®WMIã§ã¯ãããã©ã«ãã¬ãã«ã¯Identifyã§ãããWMI1.5以éã®ããŒãžã§ã³ã§ã¯-Impersonateã§ããå¿ èŠã«å¿ããŠãã¬ãžã¹ããªããŒ
HKEY_LOCAL_MACHINE \ Software \ Microsoft \ Wbem \ Scripting \ Default Impersonation Levelã«å¿ èŠãªã¬ãã«ã®ååïŒããšãã°ãimpersonateãŸãã¯DelegateïŒãæžã蟌ãããšã«ãããããã©ã«ãã®åœè£ ã¬ãã«ã倿Žã§ã ãŸãã
ã¹ã¯ãªãŒã³ã·ã§ãã
2.DCOMãããã³ã«ã¯ãWMIæ¥ç¶ã«å¯ŸããŠç¹å®ã®ã¬ãã«ã®èªèšŒïŒèªèšŒïŒãšãã©ã€ãã·ãŒãèŠæ±ããæ©èœãæäŸããŸã
ããªããèªèšŒãªãã
ããã©ã«ãïŒããã©ã«ãïŒãèªèšŒã¬ãã«ã®éžæã«ã¯ãæšæºã®ã»ãã¥ãªãã£èšå®ã䜿çšãããŸããã¯ã©ã€ã¢ã³ãã«ã¯ãµãŒããŒæå®ã®èªèšŒã¬ãã«ãå²ãåœãŠãããããããããæšå¥šã¬ãã«ã§ãã
æ¥ç¶ïŒæ¥ç¶ïŒãã¯ã©ã€ã¢ã³ãã¯ããµãŒããŒã«æ¥ç¶ãããšãã«ã®ã¿èªèšŒãããŸããæ¥ç¶ã確ç«ãããåŸã远å ã®ãã§ãã¯ã¯å®è¡ãããŸããã
åŒã³åºããŸããã¯ã©ã€ã¢ã³ãã¯ååŒã³åºãã®éå§æã«èªèšŒããããµãŒããŒã¯èŠæ±ãåãå ¥ããŸãããã®å Žåããã±ããããããŒã¯çœ²åãããŠããŸãããã¯ã©ã€ã¢ã³ããšãµãŒããŒéã§éä¿¡ãããããŒã¿èªäœïŒãã±ããã®å 容ïŒã¯çœ²åãæå·åããããŠããŸããã
ããã±ãŒãžïŒPktïŒãã¯ã©ã€ã¢ã³ããããµãŒããŒã«éä¿¡ããããã¹ãŠã®ããŒã¿ãã±ãããèªèšŒãããŸããã³ãŒã«ã¬ãã«ã®èªèšŒãšåæ§ã«ããã±ããããããŒã¯çœ²åãããŸãããæå·åãããŸãããããã±ãŒãžèªäœã¯çœ²åãæå·åããããŠããŸããã
ããã±ãŒãžã®æŽåæ§ïŒPktlntegrityïŒããã¹ãŠã®ããŒã¿ãã±ããã¯ãä¿¡é Œæ§ãšæŽåæ§ããã§ãã¯ãããŸããã¯ã©ã€ã¢ã³ããããµãŒããŒãžã®éä¿¡äžã«ãããã±ãŒãžã®å 容ã倿ŽãããŠããªãããšã確èªããŸãããã®å ŽåãããŒã¿ã¯çœ²åãããŠããŸãããæå·åãããŠããŸããã
ç¹æš©ïŒPktPrivacyïŒããã¹ãŠã®ããŒã¿ãã±ããã®ä¿¡é Œæ§ãšæŽåæ§ããã§ãã¯ãããéä¿¡ãããããŒã¿ã®æ©å¯æ§ã確ä¿ããããã«ããŒã¿ã眲åããã³æå·åãããŸãã
Windows管çè ã¯ãã·ã¹ãã ã»ãã¥ãªãã£ã³ã³ãœãŒã«ãšãã¡ã€ã³ã°ã«ãŒãããªã·ãŒãããã³ãŠãŒã¶ãŒæš©å©ã®å²ãåœãŠã»ã¯ã·ã§ã³ã§äœ¿çšã§ããã·ã¹ãã ã»ãã¥ãªãã£èšå®ãããç¥ã£ãŠããŸãããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ã§ã®å€ãã®ã¢ã¯ã·ã§ã³ã¯ã圌ãå±ãããŠãŒã¶ãŒãŸãã¯ã°ã«ãŒãã1ã€ãŸãã¯å¥ã®ç¹æš©ãæã£ãŠããå Žåã«ã®ã¿å®è¡ã§ããŸãããã®ãããªã¢ã¯ã·ã§ã³ã«ã¯ãããšãã°ãã·ã¹ãã ã®åèµ·åïŒäœæ¥ã®ã·ã£ããããŠã³ïŒãããã¯ã¢ããããã®ã·ã¹ãã ã®ç¶æ ã®åŸ©å ããŸãã¯ã·ã¹ãã æéã®å€æŽãå«ãŸããŸãã
WMIã¯ããããã¹ãŠã®ã¢ã¯ã·ã§ã³ãå®è¡ã§ãããããWMIéçºè ã¯è¿œå ã®ã»ãã¥ãªãã£ã¡ã«ããºã ãæäŸããŸããããŠãŒã¶ãŒã¢ã«ãŠã³ããã·ã¹ãã ã§ã®æäœã«å¿ èŠãªç¹æš©ãæã£ãŠããå Žåã§ããã¢ã¯ã·ã§ã³ãå®è¡ããåã«ç¹æš©ãæç€ºçã«ã¢ã¯ãã£ãåãããŸã§ããã®ã¢ã¯ã·ã§ã³ãå®è¡ã§ããŸãããç¹ã«ã管çè ãã·ã¹ãã ã®åèµ·åãèŠæ±ããWMIã¹ã¯ãªãããå®è¡ããå Žåããã®ç¹æš©ãã¹ã¯ãªããã§æç€ºçã«ã¢ã¯ãã£ãåããããŸã§ãããã¯çºçããŸããã
æŠèŠ
WMIæ¥ç¶ã®ã»ãã¥ãªãã£ã確ä¿ããããã«æšå¥šãããããšïŒ
- éèŠãªãµãŒãã¹ã®ãªãããŸãã®ã¬ãã«ã倿ŽããŸãïŒã¹ã¯ãªãŒã³ã·ã§ãã2ïŒã
- æš©éwmimgmt.mscãæ§æããŸãïŒã¹ã¯ãªãŒã³ã·ã§ãã1ïŒã
- ããã©ã«ãã®ãªããžããªã倿ŽããŸããããã«ããããã¿ãŒã³æ»æã®ã·ããªãªãç Žãããå¯èœæ§ããããŸãã
4.DCOMCNFGãŠãŒãã£ãªãã£ãä»ããŠãªã¢ãŒãèµ·åããã³WMIã¢ã¯ãã£ããŒã·ã§ã³æ©èœã
æã€ãŠãŒã¶ãŒã®ã°ã«ãŒãã倿ŽããŸãã5ãWMI ãèµ·åããã«ã¯ããŠãŒã¶ãŒã¯ç®¡çè ãŸãã¯DCOMãŠãŒã¶ãŒã°ã«ãŒãã®ã¡ã³ããŒã§ããå¿ èŠããããŸãããªã¢ãŒãã¬ãžã¹ããªãµãŒãã¹ãå©çšå¯èœã§ããå¿ èŠããããŸãã
6.ãã¡ã€ã¢ãŠã©ãŒã«ãæ§æããŸã-DCOMãžã®çä¿¡æ¥ç¶ã¯TCPããŒã135ããã³ïŒæã£ãŠããŸããïŒïŒRPCåçç¯å²ãçµç±ããŸãã
çµè«ãšããŠãç§ã¯æ¬¡ã®ããã«èšããããšæããŸããWMIã¯ãªã¢ãŒããã¹ãã§ã³ãã³ããå®è¡ããé床ããã¯ãŒãããã³å®¹æããæäŸããSQLããŒã¹ã®ã³ãã³ãã»ãã³ãã£ã¯ã¹ã¯åŠç¿ã容æã«ããŸãã
ã€ã³ã¿ãŒãããäžã«ã¯ããããã³ã°ãšWMIæ»æã«é¢ããå€ãã®æ å ±ããããŸãããããã¯ãtelnet NTPãšDNSãšãšãã«ãçŸåšã®æ»æåŸåïŒãã€ãã£ãã·ã¹ãã ãããã³ã°ããŒã«ã®äœ¿çšïŒã«é©åããŠããããã§ããç§ãã¡ã®ä»äºã¯ããã®åŸåãæããã·ã¹ãã ã«ãã§ã«çµã¿èŸŒãŸããŠããåäœçšã®æ¹æ³ãèŠã€ããããšã§ãã
èè ïŒã¬ãªãŠãªã³ãã£ã ãŒã« GTRch