ե奢֥ : byʡ

ե奢֥

byʡ

ޤޤ롢BECμ

BEC(Business Email Compromise)ŵŪʼҲ𤷤ĤġմԤޤ
ե奢֥ : ĹΥ᡼Ͽ˼ʡ

Υ֥Τ褦˼ĹΥ᡼Ǥ̵뤷ƤкѤǤBECȤΤϡ뺾Ǥ顢ԤϼؤʤؤμꤳμǽäƤޤ˹ԤϤ餬᡼̵ǤʤȤΩ򹪤ߤѤ뤳Ȥ⤢ޤ

ޤԤϴȤΥ֥ˤ䤤碌եफåޤ䤤碌ƤϡָҤοʤ˶̣ΤǡäƤۤפȤǤ

Contact Form
[Ū䤤碌ե]

äåäȤϴֿͦǤ礦

Scheme1
[ԤȤֿȤ]

ǡԤϼåإץ饤ޤκݤ˥ޥ륦źդޤ
Scheme2
[Ԥޥ륦դ᡼ƤȤ]

ޥ륦ȤϤΤ褦˼¹ԥե(bat,exeʤ)ˤʤäƤޤ
Scheme3
[źեե]

ôԤϼʬä᡼ФֿʤΤǡĤäźեե򳫤Ƥޤǽ⤯ʤȤΤμǤ

к
¹ԥե֥륯åʤ褦դȤǤϤɤƤ³ޤΤǡ¿θܵҤ䤤碌դͤüǤϡ¹ԥեμ¹Ԥ򥷥ƥŪ¤ƤȤ򤪤ᤷޤ
ŪˡϲεǾҲ𤷤Ƥޤ

ĹΥ᡼Ͽ˼ʡ

BEC(Business Email Compromise)ȤСȺμǯ龯ˤʤϤᡢFBIƻϤäմФƤޤơȤȤפﳲۤ31ɥĶǤ

Business E-mail Compromise: The 3.1 Billion Dollar Scam
Internet Crime Complaint Center (IC3) | Business E-mail Compromise: The 3.1 Billion Dollar Scam

ܤǤϥӥͥ᡼뺾ȸƤФƤޤμñ˾Ҳ𤷤ޤ

ȿͤϼĹ(ޤϷôԤʤ)ˤʤꤹޤȰ˥᡼ޤ
ʤɡäƤ̳Ȥηǻޤθ¤300⤷Ƥ졪

̤ʥ᡼ä¨ѥեԤǤ礦
Ȥ⤷ºݤä¸ߤƤꡢνȰĹ顢
٤νĥȷ500ǸĤ롣꼡̤Ϣ롣
Ȥ᡼˼äƤȤɤǤ礦

ȿͤϤ餫ޥ륦եå󥰤ʤɤѤĹΥ᡼ܥå߸ƤޤΤǡβƤİ꡼ȤȤǽʤǤ

ָˤϡ
ĹημʤǤ
ҡ⡩Ρ
á
ҡá
ȤʤꤽǤȿͤϥ᡼ܥåδƻ³ʤꤹޤŬˤʤޥ͡󥰤Τλ֤Ԥޤ

Stalling
ȿͤ᡼Ƥͻ


ﳲԡԤ˳ǧޤޤ⤵ƤޤǤٶԤ˳ǧޤΤǡ˻Ȥäԥɤ򶵤Ƥ

ȿ͡Ǥ䤫ˤᤴΤȤȻפޤ
ͤޤǤˤƤȡޤǵٲˤ򤤤Ƥޤơ̳ȤǤ˴ؤƤϾ򤤤ȹǤ

꤬饿꡼̩ͤΤäƤ뤫ȤäơѤƤϤޤ
Ĺʳˤ⡢٥ô۸Τʤɤˤʤꤹޤѥ⤢ޤ
ŵŪʼȤơ۵޻֤ͳˤƥե꡼᡼Ϣ뤳Ȥ¿ǤǵŤФ褤ΤǤŪбȤơֿѹפֿοפʤɤ᡼ǻؼ줿ȤƤɬäǤǧ롢ȤȤ򤪤ᤷޤ

ΤȤϤޤѸǤκήǤΤǡȤΤȤ꤬¿ȤäդǤ

륹кեȤ軰ɾ

륹кեȤˤ¿ȻפޤΤᡢ軰ɾȤȤǤĤεؤɾ̤ФƤޤɾؤʣäơɤɾؤΤΤѤƤ狼ʤȤΤ¾Ȼפޤ

ˡΤȤʤƼҤΥޡƥ󥰤ϼʬԹɤ̤ФƤɾտŪǻȤᡢɡƼҤȤˡּʬȥåספȤդФƤޤ

ThirdParty_Symantec ThirdParty_Trendmicro ThirdParty_Kaspersky
軰Եؤɾåޥƥåȥ ɥݥȥƥʡʸĿ͸ˤεɾ | ȥɥޥ ڥ륹ʡ2015ǯ軰ɾؤΥƥȤ94󻲲ä60Υȥåɾ | ڥ륹

桢ե奢֥εե奢֥ : AV-Comparativesˤ븽Υƥȷϰ̣㤤ޤ
ThirdParty_FSecure
ե奢֥ : AV-Comparativesˤ븽Υƥȷ

褯ȤϡּʬȥåספȤդǤϤʤƽ̤񤭽ФƤߤȡ
̡ڥ륹
̡ȥɥޥ
̡ե奢
ȤʤäƤΤǤ

ϳΤ˿ѤǤǤ͡

PetyaǥŹ沽󥵥०פ˴ޥ

ե奢֥ˤȡPetya˴ȥޥ줹ˡϰĤ̵Ƚ񤫤Ƥޤ

ե奢֥ : PetyaǥŹ沽󥵥०ȴ
ФΥإ̵ǥޥ줹ͣˡϡǥХåȤäƴץsalsa20Υª뤳Ȥ̾Υԥ塼桼ˤȤäƤϡޤ̥ŪйʤǤϤʤ:)
ʬ꤫Ȼפޤϥե奢֥ήΥ硼Ǥꡢºݤˤϡˡ̵פȤ̣ʸϤǤ

θ塢leostone᤬ޥ줹ˡȯޤ(hack-petya mission accomplished!!!)
ϤPetya˿ʧɬפϤޤ󤷡ǥХåȤɬפ⤢ޤ

ޤǤƻΤñ˾Ҳ𤷤ޤ
³ɤ

餫ˤʤʬ

ټ٤Ƥ뤳Ȥǿ͵Ƥ륨ե奢֥ǤѼΤ뵭Ƥޤ

ե奢֥ : Locky餫ˤʤѡ
ҤΥեȥDeepGuard¹ԤƤ硢ӥإӥΥ󥸥󤬡LockyѤ빶޲᡼ȡޥ륦ο񤤤˻ߤ롣ǤˤʤĹȤ⸡ΤƤ롣
(ά)
LockyӤΥХꥢȤ˴Ϣ밭դ뿶񤤤ϡʲ3ĤθΤˤ֥å롣
  •     Trojan-Dropper:W32/Agent.D!DeepGuard
  •     Trojan:W32/Pietso.A!DeepGuard
  •     Trojan:W32/TeslaCrypt.PE!DeepGuard
(ά)
⤷JavaScript¹ԤȡLockyμ¹ԥեɤ¹Ԥ롣ΥХꥢȤTrojan-Downloader:JS/Dridex.WȤƸΤ롣

פˡLockyȤ󥵥०TeslaCryptDridexȤ̾ΤǸΤ롢ȡ
ۤȤɤϰ̣ǤƤʤȻפޤTeslaCryptDridexLockyȤۤʤޥ륦ɡΤޤ󡢤Ȥ֥Ǥ
ºݤΤȤ륹кեȤϥޥ륦Τƴ򿩤ߤ뤳ȤǤꡢ򤫹ȽǤְäƤʤOKȤ󥹤ʤΤǡˤȤƴְäƤϤʤ櫓ǤեɴȤ줿᡼餹ȤäȰճǤ
(ͤΥ󥷥ǥбΩ줫餹ȡ󥵥०ȥХ󥭥󥰥ޥ륦ȤǤбۤʤޤΤǡäȺΤǤ)

Τ绨ĤøϤƼҤӤƤߤ򤤤Ǥ

Lockyμ¹ԥե (1fd40a253bab50aed41c285e982fca9c)
2016/2/16 2016/3/24
ե奢 Τ Trojan.GenericKD.3048336
ڥ륹 Τ Trojan-Ransom.Win32.Locky.d
ޥե Τ Ransom:Win32/Locky!rfn
ޥƥå Suspicious.Cloud.5 Trojan.Cryptolocker.AF
ȥɥޥ Τ Ransom_LOCKY.A

JavaScriptǽ񤫤줿LockyΥ (6288aee880e2775046f1388b28b87ea0)

2016/3/23 2016/3/28
ե奢
Trojan-Downloader:JS/Dridex.W Trojan-Downloader:JS/Dridex.W
ڥ륹
HEUR:Trojan-Downloader.Script.Generic Trojan-Downloader.JS.Agent.jkb
ޥե Τ Τ
ޥƥå Τ Τ
ȥɥޥ Τ JS_LOCKY.KB
ǤϰդȽǤǤʤΤǡָΤפϸƨ̣ΤǤϤʤ

ˤǤˤʤĹȤ⸡ΤƤפȤΤŪˤɤ줯餤δ֤ʤΤ狼ޤ͡

ǯ٤CTF̵Фڹࡢζ̩

DEFCONͥβ˻ϤޤꡢHITCONSECCONƤڹCTFCyKorǤΤBoB(Best of the Best)ȤСƥ꡼ȵѼȤΤͭ̾äǤ

ʤΤδܥ󥻥ץȤǡǯͤαԤ椫Ф줿100̾;μФƶ󶡤ˤơˤäͥ10ͤˤޤǺäƤȤ׻뤵ƤΤǤĹʸ򤹤Сäǽ140̾ФƤǤӤȡ˥Ӥˤʤޤ

bob1
BoBWeb˵ܤƤŪʥ󥻥ץ

˹ֻդȤƸƤФ졢ϻֵ֤̹򤹤뵡˷äޤޤΤǡΰüҲ𤷤Ȼפޤ䤬ôΤ30ͤ10ͤ˹ʤॹơǤ
³ɤ

ܥåȥͥåȥƥ۶

饤Х󥭥󥰤ɸŪȤܥåȥͥåDridexƥ˿ꤨ򸫤ɤƤȤȤ(Dridexβ, Botnets spreading Dridex still active)ˤʤäƤޤ

ƥˤĤƤΤ黿ξޤơȤ褯蘆Ƥޤ
üŪ˸С֤ɤ褹뤫顢̣ʤפȤȽ褯ˤΤǤ

ͤޤǤˡǶΥܥåȥͥåȥƥоݤˡVirusTotal˥åץɤƤޥ륦οƥ»ǤɤѲƤ뤫Ĵ٤Ƥߤޤ

ϸΤѥ뤵줿(Ĥޤ긡Τ줿Ǥ)ļϥåץɤƤ븡οǡդȤ꤬ۤʤΤաѥϵǽʤΤǡޤǻ;Ȥơ

Ramnit

ɽƤ봶ü320
ƥ»ܻ2015ǯ2
Ƴء桼ݡ
;Ȥ֥å륦륹
Takedown_Ramnit
Simda

ɽƤ봶ü77
ƥ»ܻ2015ǯ4
Ƴء󥿡ݡ
;SimdaܥåȤͤ3ܤ
Takedown_Simda
Beebone

ɽƤ봶ü10
ƥ»ܻ2015ǯ4
Ƴء桼ݡ
Takedown_Beebone
Vawtrak

ɽƤ봶ü82000
ƥ»ܻ2015ǯ4
Ƴءٻģ

Takedown_Vawtrak
Dridex

ɽƤ봶ü
ƥ»ܻ2015ǯ10
ƳءFBINCA
;Dridexβ
Takedown_Dridex

SimdaΤ褦˥ƥ򶭤ȤƳưŲ⤢СDridexRamnitΤ褦˵դ˳ȯƤޤä⤢Ȥ̤Ǥ

Ҥγ˴ؤŪʼĥȤơּҲؤϳͥϤʤפȤʸϤWikipediaˤϺܤäƤޤּҲؤϥܥåȥͥåȥƥͥϤʤפȤ褦Ǥ

ǤĿŪˤϥܥåȥͥåȤΥƥ˻ɤäꤷޤȤΤϡƥȤ̣ǤϤʤƥܥåȥͥåȰݺΰȤͭȤ̣Ǥºݡƥ򤭤äȤܺŸ뤳ȤϤ褯ޤ

ȥ桼

ΤȤˤʤޤCyber3 Conference Okinawa 2015ȤݲĤ˻ٲˤƤ黲äƤޤ

c3
(С饤ΥåǤϡ󥿡ݡIGCIؤδԤι⤵ȩǴ)


ΥåˤϡܤȤŤ졢
ʤͥʵѼԤϥ䥢åץΤ褦ʴȤ˹ԤΤϵ⤤ǤϤʤѼԤõ濴ĶäƤ뤫Ʊ褦ܤεѼԤ⡢Ҳ׸ȤΤˡ¤ǴĥäƤۤ
Ȥݤȯޤ

ΤäȯǡܤˤϡŪͭ̾ʥСƥȤбĤȤŤޤΥȤ椫ȥåץ٥ΥƥѼԡʥϥåˤ򤫤Ƥ뤳ȤǤΤ졢륹ȳΥȤޤǸ줿ꡢʤäꤷޤ
桼ϡ
ʬʿΥƥѼԤƤʤõƤɤˤʤɤɤ񤷤ơ餷ưƤʤФʤʤʤ餳ˤեåȥܡץ쥤䡼¤ߤε뤬ȤˤܤˤޤޤƥѼԤɬפȤƤ롣
ȯޤ
ʤʤ⤢ϥåǯꤹΩˤбļԤθդ϶ϫȳи礬äƤޤ˥󥸥˥пȤηбļԤȤäơƥѼԤο褯򤷤Ƥޤ

Сƥȳ֤γ󡢥꡼ѥ˥硼ʥڥץå꡼ˤʿǯ27ߡץߥ꡼Ǥ3ߤǤ衣

;ڥϥ른ѥ2015ǯ󥭥󥰤ճww

ȥޥ륦 vs. EMET 5.2

դΤեɤ߹ळȤδˤĤմԤޤ򺣤ɸŪμϰ̯ΰӤ򤿤ɤꡢ륨󥸥˥󥰤Ȥˡ졢Ϥְդ뤫ɤȽǡפ뤳ȤˤʤĤĤޤĤޤꡢԿʿե򳫤ʤפȤΤкȤƵǽʤʤäƤΤǤ

ǶǯܤƤΤޥեȤ󶡤EMETɽ褦ȼɸ()եȥǤ
®EMETͭˤ֤ǿȥޥ륦(Τ˸ȿExploit)Ȥäƹ⤷Ƥߤޤ礦
ǥեȤ3ĤΥƥ٥뤬ѰդƤޤΤǡǹ٥ΡMaximum security settingsפ򤷤Ƽ¸򳫻Ϥޤ

SudokuExploitWithEmet52

ʤۤɡΤ˹Τɸ椷Ƥޤ

ǤϼˡEMETˤɸХѥƤߤޤ礦EMETβɤ¤Ǥϡ˻ȤŵŪʿ񤤤ѥ󲽤Ƥ褦Ǥǡľ˹˸ΤǤϤʤ虜虜򤷤ƹ⤷Ƥߤޤ㤨ƸȡAŪB˸˸䤬롣äٷͳC̤äƤŪB˸ȤäƥץʺǤ
פ
A -> B
Ȥ̿
A -> C
C -> B
Ȥʳ֤̿ޤ

⥳ɤ¹ԤưǤ



ȼɸ楽եȥϡƤܤιԤˤȤäƤͭǤ˹⤵ȤޤޤХѥǽȤʳΤ褦Ǥ

ޤμ¸EMETǤʤ¾ɸŪкեȤФƤƱͤ˥ХѥǽǤ

Կʿե򳫤ʤפȤ̵ϡ̳PCȿPCʬ뤳Ȥ򤪤ᤷޤ

2015/10/06ɵ: EMET 5.5 BetaǤ̤ƱǤ

ȥåץۤƤ椱

NHKΥץեåʥȤƥȤǡ"СƥѼԤǤǹεѤĥȥåץ"ȤȤǡ֤Ρ̾¤о줷ޤ

̾ˡ2015ǯ914| ޤǤ | Σȣ ץեåʥ Żή

ä˥ޥ륦ϥǤͤùߤɤ󤢤ޤƥӤȤȤܤ˸Ƥ餦ȤơѼԤ򤷤ޤޤǤϥޥȻפȤ

פǤΥޥ륦ϤκݤˡVirusTotalǤθ̤ǡb1ef92??פȤʸ󤬽ФƤȤ顢IPɥ쥹177.239.146.???פȽǤƥᥭΥФͳǤǽ롢ȤäˤʤäƤޤ
b1ef92??פ1ХȤĤʬ򤷤ơ16ʿ10ʿѴΤǤ礦

16ʿɽ b1 ef 92
10ʿɽ 177 239 146

Ȥ⤽⤳ͤVirusTotalȼΥϥåͤǤΤǡä׻IPɥ쥹ФȤϤǤޤ󡣤äơᥭȤΤϸǤ礦

ǤϡɤιͳʤΤϥޥ륦μΤϤΤֳμ¤Ǥ

ޥ륦Ȥ򸫤ȡФΥɥ쥹ϰŹ沽Ƥޤå渰ޥ륦μȤäƤޤΤǡѤ椹ȥޥ륦̿褬狼ޤ

malwareanalysis

̿褫顢ܤΥФ˴ؤŹ沽줿ǼǤޤΤǡƱͤ椹ȹԤΥФIPɥ쥹狼ޤ
ΥФ˥̤Ǥ

iisrdp

餫˥ᥭʳιǤǤ͡

դΤեɤ߹ळȤǤդΥޥɤ¹Ԥȼ


󥬥ݡμ꡼ˤäƳȯ줿Sudoku solverˤϡХåեСեȼ¸ߤޤ

sudoku-2015-000001

ƶ륷ƥ
Sudoku solverȤ߹ƥ

ܺپ
Sudoku solverˤϥǡν˵ХåեСե (CWE-121) ȼ¸ߤޤ



ꤵƶ
ٹ줿եɤ߹ळȤǡǤդΥɤ¹Ԥǽޤ

кˡ
Կʿե򳫤ʤ褦ˤƤ

;ռ
ITʹܻؤȤΥ꡼򼫤ιưǼ꡼Фհդɽޤ

ǯⵡ򽱤äޥ륦˴Ƥ뤫1ʬdzǧˡ

˹ǽʥե󥸥åեȤȤдñ˸Ĥ褦Ǥ

focus-s
ҥեƥॺ
ǯⵡؤɸŪѤ줿EmdiviפResponder Proˤ븡ΤȲ


̤ˤƤߤФäȥСڥå⤷ޤΤǡäȴñ˳ǧˡҲ𤷤ޤ

ޥ͡㡼򳫤оݥץ򱦥å֥ץեκפ򤷤ޤ
taskmanager_emdivi

Ȥϡ줿ץե뤫C2ФΥɥᥤ򸡺Ǥ
嵭ΥȤˤԹˤ볤ȤΥɥᥤϡpפǽ褦ǤΤǡp.co.jpפǸޤ
cmd_emdivi

Ȥäݤ̾ФƤ鴶Ƥޤ

ºݤˤϳȰʳC2ФȤƻȤƤޤΤǡ⤦äŪʥɤΤۤ⤷ޤ
cmd_emdivi2

󥵥०Ȥ뤿΢略

ե奢֥Ǥˤ˼夲Ƥ褦ǥ󥵥०԰Ҥ򿶤äƤޤ
PCΥեŹ沽Ȥʤ뤳Ȥǡפʥեͼ˼ꡢᤷߤп(󥵥)ʧȤĤǤ

TorLocker

ɤΥ륹٥ƻٹ𤷤ƤΤˤؤ餺ﳲϸ뵤ۤʤɤǤ
ͳϡ륹٥Ȱ̥桼δ֤ˤϼΤ褦ʹ¤뤫Ȼפޤ

³ɤ

SimdaܥåȤͤ3ܤ

󥿡ݡ롢ޥեȡڥ륹ȥɥޥȶϤSimdaܥåȥͥåȤΥƥԤޤ
ڥ륹иƤƱν褦ˡΥޥ륦¿β˸ǽ뤿ᡢ륹٥ΥɥܥåǤϤޤΤ뤳ȤǤƤޤǤ

ǡСǥե󥹸꤬ưDzϤ»ܤβϷ̤򸵤ˤѥåȰŹ沽줿̿եġޥեȤ䥢륹٥󶡤Ƥβ˶Ϥޤ

ޤǤ˴Ƥ桼ؤбȤơ3(3ܤ)Ѱդޤ
ˤϡΤ褦ɽޤ
Simda Botnet DetectorSimda Check

μϰϤϼɽΤ褦ˤʤäƤޤ

No. Ķʤ IP Scanner
륹ե ư hosts check ư hosts check
1
ʾ()
2
ʾǸ
3
ƥΥޥ륦ư
4
ƥΥޥ륦ư
5
ؤб
6
ޥ륦ư
7
ưŪIPɥ쥹ĶǤδ
8
ץ饤١IPɥ쥹ĶǤδ
͡ʾˤꡢޥ륦μȤȤʤ礬

ǴԿ¿Τ2֤3֤Ȼפޤ
ĿŪ˥ּ᤹ü᤯Ƴμ¤ʳǧˡhostsեμưǧǤ

ǶξʬϼԤܻؤ

ôԤȾʬôԡɤŬ뤫ɾƤ륵ȡINTELLIGENCE SKILLS CHALLENGEפĴģߤޤ

Сǥե󥹸ξʬȤƤŪʾʬϼŬäƤɬפޤ
ǡޤǰ˾ʬϤʤ100%ξʬôԤܻؤޤ

ISC1

Ƕ¤򤻤ʤ⤢ޤ100%ãޤη̤褯ŬγǤϤʤɽ褦Ǥ20050餤Ƥʤ褦ǡǤϾʬʤǤ

Ǥϼϡ200ܻؤƤߤޤ礦

ISC2

200줿ΤϤǤ٤ϵդŬγ礬礭äƤޤޤ

Сǥե󥹸ʬ˵ǽϤϤʤΤǤϤޤ󡣾ǽϡʬǽϤȤľʬϼŬ100%Ǥɬפޤ

ȤΥȤǤϡǽϤ⤱й⤤ۤɾʬϼŬʾŬ夬ˤȤåˤʤäƤ褦Ǥ
ξǽϤʬϼԤ¸ߤʤΤǤ礦

ʤϤϤޤ͡ɤ˸ȤƤ󤬤ϤȤȤǡƶޤǾʬϤľΥå̷ĩ路̵̡ξľʬϼŬ100%ã뤳ȤǤޤ

ISC3

Ʊ褦Ƚꤵ줿ϤҥСǥե󥹸ˤ礯

󥿡ݡ륵Сܳʻư

󥬥ݡڷιȤȤ⤢ꡢ11()ΤۤȤäǤΤǡ褦䤯ǯޤǤ
Ҳ٤ޤ󥿡ݡοӥܴۤǤ˶̳򳫻ϤƤޤ

BEFORE(2014ǯ4):
IGCI

AFTER():
IGCI1

IGCI2


ǯ¿ˤϤƼϡϤλޤ뤳ȤǤ礦
ǯꤤޤ

ѹΥ֥륹ɡѹΤ褦˥ϥå󥰤

ʲϡѹ񤬥ϥå󥰤ȤƤȤ
Hacked_by_UK

Υ٥륮òҤѹ񤬥ϥå󥰤ͳϤʤ

Ӥäİ뤿

—————

Ǥϥ֥륹ɤȤϤɤȤǤ礦
DZѹΥСƥά(PDF)򸫤Ƥߤޤ礦(ɮԤˤΡ)

CyberSecurityStrategyUKCyberSecurityStrategyUK2

4ĤιܤȤƵ󤲤Ƥޤ
  • ѹΥС֤ǺǤ⥻奢ˤ
  • ѹ򥵥СФ٤
  • ץǡϤꤷС֤η
  • ѹΥСƥ˴ؤμ롢ǽϤ򶯲
EUϢϥå󥰤άȤΤʤ褦ʡԵΤ褤ϲ¤٤ƤΤǤ

ǤϵľܤΥСƥά(PDF)򸫤Ƥߤޤ礦

CyberSecurityStrategyJPCyberSecurityStrategyJP2

ֶ٤ʡסֳϤΤסֿͺסΨ
ԥڤǺäΤȻפۤɻ̤äϲǤ

ʤޥեȤϥС˼夤Τ

ȼĤ뤿ӤˡޥեȤϥƥ򶯲ʲ뤲Ƥޤкˤȡ˥ƥ򶯲ƿʲޤ
դθ򤹤Хƥ򶯲ƤˤƤ롢ȸȤǤޤ

ޥեȤϡƥȯ饤ե(SDL)ȤϩȤȤߤȯȤ߹Ǥ褦Ǥơɤ¤ǤϹԤդϤʤǤǰʤɤ餫ˤƤΤϻ¤Ǥ

ͤ͡λ𤬤ΤǤ礦֤ɤΤ褦ˤΤפλΰü򤦤Τ뤿ΰĤڤȤơѼԸˤϤʤޤˤȤߤ򥢥֥٥θƤCodeIQ˻ϤƤߤޤ

MsIsVulnerable

ޥեʤˤϥǥեȤǥƥΤλȤߤȤ߹ޤޤ򤤤ˤ뤳ȤǤ뤫ʤǤˤθ뤫Ȼפޤ(ˤSDLä⤢ޤ)

ɸŪƤ롩


ޥ륦ΥեӥΥץåȥեѤΥեȥ¹ԤƤޥΤߤäΤȲꤷƤְ㤤ʤ

䤤䡢ְ㤤NCRʳATM򤪻ȤζȼԤ¿ƤϤޤ

ȤʤäƤWOSA/XFSȤʤϡڥǥǤˤȡ٥ȤˤФФäATMεʤ줹뤿˺줿ʤǤWOSAOOpenOǤΤǡ虜虜ɴ١ʥХɥˤϤڤʤƤïǤ⥽ɥ٥Ǽ뤳ȤǤޤNCRҤäơXFSȤäƤ뤳ȤƲȥץƤޤ

櫓ǤΤǡNCR APTRA XFSեȥפ󥹥ȡ뤵ƤʤƤޥ륦ưޤºݤmsxfs.dll򥤥󥹥ȡ뤷μ긵ˤWindowsǤưƤޤ



ǰʤ긵Windowsˤϸ⤬äƤʤΤǡ⤬뤫Τ褦˥ߥ졼ȤƤޤ
ʥߥ졼ʬҥ󥸥˥(op)ˤޤ

פˡ쵬ʤǤXFSѤƤATMǤﳲǽȤȤǤ

㤢ܤǤϤɤѤƤΤȤȡڥǥXFSΥڡˤϼΤ褦˽񤫤Ƥޤ
ܹμATMڤ̲߽᡼ϡۤƤζͻϢʤܵʡʵǤޤˤѤƤ

ʹ񥷥󥬥ݡ٤뵻

ä󥬥ݡ˽ǤޤΤǡüξ󲽼Ҳ¸ȸ륷󥬥ݡγ¤Ȥ˳ָ󲽼Ҳ٤뵻Ѥ򤴾Ҳ𤷤ޤ礦
³ɤ
ХåʥС
ǥطԤγͤ
ե奢֥С
ե奢֥С
ߥåҥåݥͥ
ե奢 CROʥƥʸˡʥإ륷󥭡
(Twitter)
(Twitter)
硼󡦥Х
ե奢 ƥɥХʥإ륷󥭡
(Twitter)
ŵ
᥿ɽ
(֥)
(Twitter)
߷ ͵
ҥ奢֥쥤 ǹ⵻Ǥ
(֥)
(ʪҲ)
ǥ ȡޥ ꥹӥ (2013ǯ3 ҥå) 󥻥ƥرءҰ
(Twitter)

(ʪҲ)
ʡ
ҥСǥե󥹸 ʬϴ
CDI-CIRTС
(ʪҲ)
͵
FFRI ɽĹ
(ʪҲ)
ʡܡ
ŷ

OWASP Japan
ɥХ꡼ܡ
Rakuten-CERT representative
(ʪҲ)
ե奢 ץȥ롼 Ĺ
ٰ β
ե奢 ץȥ롼
ݥ졼ȥ륹
ե奢
(ե奢֥Twitter)


ҥ᡼ɡ
ե奢᡼ޥ

֥˺ܤʤޥ䡢Ѽԥ󥿥ӥ塼ʾ󡢵ѲǺܤۿޤɥ쥹ΤߤϿǹ̵

ե奢֥ѣҥ
QR