ե奢֥ : ȯ

ե奢֥

ȯ

ɵMicrosoftMS10-025פ겼

2010ǯ423˥ݥȤ줿ҥꥢꥢεMicrosoftMS10-025פ겼פɵܤޤΤǤΤ餻ޤ

һ󡧥ե奢֥СҲ

֤߷ʡˤĤŤơե奢֥οե륳ơ򤴾Ҳ𤤤ޤ

ݡ륵ȤWebƥ̳˷ȤäƤäһˡ֥Υե륳ơȤƤä뤳Ȥˤʤޤ

ե륳ơϡե奢ҳ饲ȥ֥ȤƤäƤ볧ͤǤ

äһΤҲ򿽤夲Ȼפޤ

4ܡһΥեǤäʹ뤳ȤǤޤ

һ

һʤޡޤΤ
ȳ άӥͥ Ĺ

ΰ衧
Żҷѡޡƥ󥰡Webƥƥ೫ȯ󥵥ƥ

Ƶ
2008 饤󥲡
2007
ʤ

ֱӡ
APWG CeCOS II
饤󥲡ߥ˥ƥӥե 2008 ʤʣ

ƥξ󸻤ȤƤ֥Webȡ
ScanNetSecurity
¾

ե꡼ȡ
ȱļԤȤơŪWebƥλŻ˽ƤޤWebƥȷкѤδϢʬϤʤɤդȤƤޤɤơΥޥ륦ήԤäƤΤʤɤ⤷ȻפäƤޤɤꤤޤ


ɵʵʾι

2010ǯ325˥ݥȤ줿硼εʾιפɵܤޤΤǤΤ餻ޤ

ɵPDF١ɸŪ⤬á

2010ǯ310˥ݥȤ줿硼εPDF١ɸŪ⤬פ˵ܤƤդοͤθ꤬ޤΤǤΤ餻ޤ

ե奢᡼ޥ¸ΤǤ

ϡե奢᡼ޥפۿǤ³ɤ

ե奢̵ޥ륦ġ֥饤󥹥4.2פOperaGoogle Chromeˤб

ե奢̵󶡤Ƥ饤󥹥ϡ󥹥ȥåפ륹䥹ѥʤɤΥޥ륦򸡽Сġǡǯ5ǯܤޤޤ

³ɤ

СȺȤ襤ꥢ

СȺԤ䥵СƥȤ襤ͥåۿDzͽԤ餫ˤʤޤ
³ɤ

ɵMicrosoftȼ

121˥ݥȤ줿Microsoftȼפʸ4ܤˡޥեȥƥ MS10-002ؤΥɵޤ

ɵʵդƤ館ƴ򤷤

112˥ݥȤ줿ֵդƤ館ƴ򤷤ɵƤޤ

2010ǯޤˤä

͡ʥ٥Ȥ䡢¿餷а˷äޤ줿2009ǯ⡢ȿ֤Ĥ2010ǯޤޤ³ɤ

ʡ󡧥ե奢֥СҲ

֤߷ˤĤŤơWebץꥱ󥻥ƥȤǤäʡˡ֥Υե륳ơȤƤäƤޤ

ե륳ơϡե奢ҳ饲ȥ֥ȤƤäƤ볧ͤǤ

äʡΤҲ򿽤夲Ȼפޤ

11ܡĤʡΥեǤäʹޤ

ʡ

ʡ ʤդꡡ
ҥСǥե󥹸 ʬϴ

ꥻƥ٥IDSIRT˽塢WebץꥱΥƥӥΩ夲롣θ塢Webƥ٥㡼Ω2009ǯꥵСǥե󥹸˻á


ΰ衧
Webƥڥͥȥ졼ƥȡޥ륦

ޡ
2007ǯ 3 IPAޡʾ󥻥ƥ
2009ǯ Native Client ƥƥ 4

Ƶ
ʤWeb2.0ƥסgihyo.jp
ƥɤ߲Web2.0סʷٻģ@police
饹٥DEFCON CTF辡ס@IT
ʤ

ֱӡ
2007ǯ412ƥ塼եʡWeb 2.0ϴäѤס
2007ǯ426RSA CONFERENCE JAPANʡWebƥϤʤˤΤס
2008ǯ1011AVTokyo 2008ʡFlash޲𤷤XSSβǽס
2007ǯ1115POC Korea 2007ʡAttacking Web 2.0ס
2008ǯ11Email Security Expo & Conference 2008ʡSQL󥸥δܤȱѡס
2009ǯ422Shibuya Perl Mongers ƥ˥ȡʡNative Client Hacksס
ʤ

ˡ͸ СΤҲ2

³Ǥ

ͽ̤ꡢϡȼɡפȤǽˤĤƤҲ𤷤Ȼפޤ

ȼɤϡ֥饦ݸտ路ư뵡ǽǡޤ桼˰ʥͥåȥեʸŤáˤڤǤ餦ΤΤǤ
## ;̤ǤͥåȥեΤ褦ʹ԰٤򼨤θդϤǤ礦

ȼɤϡ̤̾ꡢWeb˴Ϣ륢ץꥱȼν󶡤ޤ

exploit_shield_db

Internet ExplorerFireFoxδΤȼӥ֥饦ǥץ饰ȤưAdobe AcrobatMicrosoft Media PlayerʤɤΥץꥱȼˤĤơץꥱư˥˽ѥåŸޤ

ˤäơץꥱΥåץǡȤԤäƤʤ桼ˤĤƤ⡢ȼѤ褦ʹ⤫뤳ȤǤޤ
ޤȼѤ褦ʥɤ򸫤Ĥˤϡ桼˷ٹ̤ɽޤ

ǰʤ顢ٹ̤ˤĤƤΥץϼʤäǤ

ȼȯ줿ϡѥեɲäޤ


ϡVer9ǤβˤĤƤäȻפޤ

ˡ͸ СΤҲ1

ɤ⥨ե奢 ٰ¤Ǥ
ƤʬФäƤޤޤϤ⤦äûֳ֤ƽ褦˴ĥꤿȻפޤ

ϤƤˡ͸WindowsʤοС꡼ޤΤǡС󤫤ѹ/ɲä줿ǽ濴ˤҲ𤷤Ȼפޤ

꡼ΤϡWindows XPΥơɥݥʤΥե奢 饤ȥƥ Ver9.00 / ե奢 륹 ơ Ver9.00ȡ뤿Υݥꥷޥ͡ Ver9.00ˤʤޤ

ϡե奢 饤ȥƥ Ver9.00ɲä줿֥饦ݸεǽˤĤƾҲ𤷤Ȼפޤ

Ԥƥ꡼ޤ󥷥塼޸Υե奢 󥿡ͥåȥƥ2010ˤϴܤƤ뵡ǽǤοСˡ͸Υե奢 饤ȥƥ Ver9.00ˤܤޤ


֥饦ݸϡ桼WebȤ˥ʤ褦ˤ뤿εǽǤ
饤ȥƥ򥤥󥹥ȡ뤷Ƶǽͭˤȡ֥饦˥ɥȤƥ֥饦ݸΥġСɲäޤ

browsing_protection_toolbar

ɾ: פȡɾ: פWebȤ˥ˤϡ̤̾WebȤɽޤ

ɾ: פξϡWebȤɽˡʲβ̤ɽ륹δ褦ʥȤ򳫤ʤ褦ˤƤޤ

browsing_protection_danger


ޤ֥饦ݸľܴʥȤ˥ȤǤϤʤgoogleYahooMSNθ̤䡢

browsing_protection_search


GmailHotmailʤɤWeb᡼뤫Υ󥯤ˤĤơɾ̤򤢤餫ɽޤ

browsing_protection_webmail

ϲ٤ޤ⤯ʤΤǡåƸƤ

֥饦ݸбƤWeb֥饦ϡʲ/СǤ
Internet Explorer Ver6 ʹ
Firefox Ver2 ʹ

̤ɾɽǤ륵󥸥ϡʲˤʤޤ
Google
Yahoo
MSN

󥯤ɾɽǤWeb᡼ϡʲˤʤޤ
Gmail
Hotmail

WebȤɾϡΥե奢Υ饤󥵡Ф˥ǡ١Ȥ¸졢饦ɤȤƥ桼˾󶡤ޤ
ޤǡ١ϥ桼⸵ˤƹޤΤǡɾWebȤ򸫤Ĥϡ֥ե奢ΤפΥܥ󤫤顢ɾĺޤȹǤ


ϡȼɡפȤǽˤĤƾҲ𤷤Ȼפޤ

СޥǡΥƥк

ե奢3֤Ƥ륻ƥΤҤȤġΥθ꤬ۥǡ˾褸饤󺾵˴ؤٹФޤ
³ɤ

Ĥ˱Dz貽ե奢饤Ⱥμ¾Dz˶

󥿡ͥåȾۿƤDz å - οά*٤ؤե奢ȥͥåۿDzƱ뤳Ȥˤʤޤե奢ϡ饤Ⱥ䥵СƥȤƮ˴ؤΥϥ󶡤뤳ȤǡΥץȤ򥵥ݡȤޤ
³ɤ

ɵʤޤ򼨤ʤTwitter

109˥ݥȤ줿ޤ򼨤ʤTwitterפɵƤޤ

ΤɤˤƤ

եɹҶϡѼԤФӥͥץ饤١Ȥˤ餺ǽʸ¤꿮ι⤤ʥȥ٥ ڥꥨ󥹤󶡤ܻؤƤޤ³ɤ

ܤܤ

Υե奢 ƥˤˤ⤢ޤޥ 㥯ե եåȡľǤϥѥȥå ʤɤΥ֥ƥλѤѥबԤƤޤ³ɤ

ե奢

֤60︺줿֥ե奢 󥿡ͥå ƥ2010꡼줿ǤߥåƤ餴⿽夲̤ե奢Υ֥ɥޤޤѤ륨ե奢ˤɤԲ

ɵʥޥ졼WebȤؤΥС

92˥ݥȤ줿Ƶޥ졼WebȤؤΥСפɵ2Ƥޤ
ХåʥС
ǥطԤγͤ
ե奢֥С
ե奢֥С
ߥåҥåݥͥ
ե奢 CROʥƥʸˡʥإ륷󥭡
(Twitter)
(Twitter)
硼󡦥Х
ե奢 ƥɥХʥإ륷󥭡
(Twitter)
ŵ
᥿ɽ
(֥)
(Twitter)
߷ ͵
ҥ奢֥쥤 ǹ⵻Ǥ
(֥)
(ʪҲ)
ǥ ȡޥ ꥹӥ (2013ǯ3 ҥå) 󥻥ƥرءҰ
(Twitter)

(ʪҲ)
ʡ
ҥСǥե󥹸 ʬϴ
CDI-CIRTС
(ʪҲ)
͵
FFRI ɽĹ
(ʪҲ)
ʡܡ
ŷ

OWASP Japan
ɥХ꡼ܡ
Rakuten-CERT representative
(ʪҲ)
ե奢 ץȥ롼 Ĺ
ٰ β
ե奢 ץȥ롼
ݥ졼ȥ륹
ե奢
(ե奢֥Twitter)


ҥ᡼ɡ
ե奢᡼ޥ

֥˺ܤʤޥ䡢Ѽԥ󥿥ӥ塼ʾ󡢵ѲǺܤۿޤɥ쥹ΤߤϿǹ̵

ե奢֥ѣҥ
QR