éœå ã§éå¬äžã®RSA Conference Japan 2007ã®åæ¥ãããããèªãæ å ±ã»ãã¥ãªãã£ã®çå®ããšé¡ããããã«ãã£ã¹ã«ãã·ã§ã³ãéããããã»ãã¥ãªãã£æ¥çã®æåç·ã«ãã4人ããçŸç¶ã®ã»ãã¥ãªãã£ã®èª²é¡ãªã©ã«ã€ããŠè©±ãåã£ãã話é¡ã¯ãããããããæšçåæ»æãè匱æ§ãP2Pãããã¯ãŒã¯ãšãçŸåšã®åé¡ã«æ ¹ããããããã¯ãšãªã£ãã
ãã£ã¹ã«ãã·ã§ã³ã«åå ããã®ã¯ã©ãã¯ã®æ°äºæ æ°ãJPCERT ã³ãŒãã£ããŒã·ã§ã³ã»ã³ã¿ãŒã®äŒè€åéæµæ°ããã€ã¯ããœããã®å¥¥å€©éœåžæ°ãTelecom-ISAC Japanã®å°å±±èŠæ°(NTTã³ãã¥ãã±ãŒã·ã§ã³ãº)ãšãæ¥çã§ã¯ããªãã¿ã®4人ãã¢ãã¬ãŒã¿ãŒã¯æ¥çµBP瀟 æ¥çµããœã³ã³èªã®å¯ç·šéé·ã»åæå¹žåæ°ã ã£ãã
ããã«èŠã€ããã«ãããå·§åŠåãããããããã
ãŸããã©ãã¯ã®æ°äºæ°ãããããããã«é¢ããŠèª¬æããããã¯ãHerderãšåŒã°ããããããããã®ææè ãIRCãµãŒãçµç±ã§ãããææãã·ã³ã«æä»€ãéãããããåããææãã·ã³ãäžæã«DoSæ»æã仿ãããªã©ã®æ»æãè¡ãã
ãšããããæè¿ã®ããããããã調æ»ããããã«ãããããåéããŠä»®æ³çãªã€ã³ã¿ãŒãããç°å¢ã§èµ·åããããšãããèµ·åããŠ3ç§ä»¥å ã«åŒ·å¶çµäºãããããããã£ããšããããã®ãããã¯ææåäœãè¡ããªãã£ãããã調æ»ç ç©¶ãç¶ç¶ãããšããããããããããã¯IRCãµãŒãã§ã¯ãªãWebãµãŒãã«æ¥ç¶ããããšããŠããããã£ã¬ã³ãžã»ã¬ã¹ãã³ã¹ãªã©ã§èªèšŒãè¡ã£ãäžã§æŽ»åãè¡ãããã«ããã®WebãµãŒãã«ã¢ã¯ã»ã¹ã§ããªãä»®æ³ç°å¢äžã§ã¯èªåçµäºããŠããã®ã ãšããã
æææŽ»åãè¡ããªãããããŠã€ã«ã¹å¯Ÿçãã³ããŒãªã©ã§å®éã®åäœãåæã§ããã察å¿ã§ããªãããšãæåŸ ããä»çµã¿ãšèããããããããµãŒãããã®æä»€ãæå·åãããŠãããéäžçµè·¯ã§åœä»€ãèªã¿åãããªããããªæ©èœãå«ãŸããŠããããã ã
ãããã®äž»æµã¯ãŸã IRCãµãŒãã ãšèšãããå šäœã®1ïœ2å²çšåºŠã§WebãµãŒãã䜿ããå§ããŠãããšã®ããšã§ããæ°ããããããããã(ããããããã)é²åããŠããããšãåãã£ãã(æ°äºæ°)ã
ãŸãããããããããã¯åæ©èœã§æŽ»åå 容ãéãããæ©èœãå°ãªãããèŠã€ãã«ãããªã£ãŠãããšãããWebãµãŒããšHTTPéä¿¡ã§ãããšããããããéåžžã®Webé²èЧãšåæ§ã«ãã¡ã€ã¢ãŠã©ãŒã«ã§ã®å¶åŸ¡ãããæããŠããŸããæ°äºæ°ã¯ãéä¿¡ã«HTTPã䜿ãããã以å€ã®ãã«ãŠã§ã¢ã®ååšãææãHTTPã䜿ã£ãŠããã«å¥ã®ãã«ãŠã§ã¢ãããŠã³ããŒãããããŠã³ããŒããŒã®æ°ãå¢ããŠãããšè©±ãã
æ°äºæ°ã«ããã°ãã»ãã®ãã«ãŠã§ã¢ãåã蟌ãããšããã·ãŒã±ã³ã·ã£ã«åäœããšãããSPAM ProxyãRootkitãã¢ããããŒããŒãªã©ãåã蟌ãŸããããšãå€ãããã ãããããHTTPã䜿ã£ãŠåã蟌ãŸããæ°äºæ°ã¯ããããã«éããããã«ãŠã§ã¢ã®åäœãWebã«åããããŠãããããªæããããããšããã
ãªãæ°äºæ°ã¯ãæè¿ãP2Pãããããç»å ŽããŠãããšããããããã¯ä»ã®ããããšåæ§ã«IRCãµãŒãã䜿ãããããèªäœã®èªå·±æŽæ°æ©èœã«P2Pãå©çšããŠããã ãã ããã ãIRCãµãŒãã¯åæã«è€æ°ã®ç«¯æ«ã«æä»€ãåºãããšããã¡ãªããããããHerderã«ãšã£ãŠã¯ãå®çžŸããã£ãŠããæå³æ¯ããŠããæè¡ãªã®ã§ããããŠ(ã»ãã®æè¡ã䜿ããããª)ãã£ã¬ã³ãžãããªããŠãååã(å)ãšããèªèããããšæšæž¬ããã
ããããããããªã©ã®ãã«ãŠã§ã¢ã¯ãWebã䜿ã£ãããããã»ã¹ã€ã³ãžã§ã¯ã·ã§ã³ã䜿ã£ãŠååšãé ããããšãæè¡çã«ã¯ããå·§åŠåããŠããã
ããã«å¯ŸããŠå°å±±æ°ã¯ããå·§åŠåããã®ã¯åœç¶ããšææãããæ»æè ã«ãšã£ãŠããããããã¯ç¯çœªåçãäžããããã®ã€ã³ãã©ã§ããããèŠã€ããããªãããã«ãæ¥ã 嵿工倫ããã®ã¯åœç¶ã(å°å±±æ°)ã ããã ãæ»æåŽã¯æ¥ã é²åããŠããã®ã«ãé²åŸ¡åŽã¯ã以åã®ããã察çã®ãŸãŸã§ããããå€åããè åšã«è¿œãã€ããªããã察çã¯ã§ããªããŸã§ããçŸç¶ãææ¡ããã®ã倧äºã(å)ãšãç¶ç¶çãªèª¿æ»ç ç©¶ã®å¿ èŠæ§ã蚎ããã
äŒè€æ°ããJPCERT/CCã«å¯ããããã€ã³ã·ãã³ãå ±åãããæ»æåŽã®æå£ãã©ãã©ãå€ãã£ãŠããŠããã®ãèŠããŠããŠãããšãããããããªã©ã«ææããŠãã端æ«ã¯ãäžçäžã§å€§éã®æ°ã«äžã£ãŠããããã«ããã«ãŠã§ã¢ã¯æ€ç¥ãã«ãããªã£ãŠãããäŒè€æ°ã¯ä»åŸããã«æå£ã¯å·§åŠåããŠãããšèŠãã
奥倩æ°ã¯ãåããŠããã察å¿ãããã®ã4幎ã»ã©åã§ããã以æ¥ãåãç¶æ³ãç¶ããŠããã®ãåé¡ã ãšææããããŸããWindows Vistaã«ã¯UAC(ãŠãŒã¶ãŒã¢ã«ãŠã³ãå¶åŸ¡)ãæèŒãããããããPCã«(ã²ããã«)ã€ã³ã¹ããŒã«ãããããšããŠããèŠåã衚瀺ãããããã«ãªã£ãŠããããããã«ãŠã§ã¢ãã¡ã¢ãªäžã§åäœãããã®ãå¢ãããšäºæž¬ããã