ããžãã¹ã«ãããŠãããã¯ãŒã¯ã¯ãã§ã«æ¬ ãããªãã€ã³ãã©ã®1ã€ãšãªã£ãŠããããããäžæ¹ã§ããããã¯ãŒã¯äžã«ã¯ããŸããŸãªè åšãååšããããµã€ããŒç¯çœªè ã¯ãæãããããªãæå£ã§çµç¹å ã®æ å ±ãå人ã®ééãçã£ãŠããããã®æ°ã¯ãªããŠãã瀟å¡ãæ¥åçšã®ã¹ããŒãããã€ã¹ãçŽå€±ããããåºæ¥å¿ã§æ å ±ãæŒããããããããšããããšãèããããã
JPCERT/CCã¯åœéçãªã»ãã¥ãªãã£å¯Ÿçã®çªå£
![]() |
è¬æŒãè¡ãJPCERT/CC çäº åæã»ã³ã¿ãŒé· çéæ¬å£«æ° |
2013幎9æ27æ¥ã«éå¬ãããã»ãããŒããããã¯ãŒã¯ã»ã»ãã¥ãªãã£ã»ã€ã³ãã©ã®å šè²ãã§ã¯ããããã課é¡ã«å¯ŸããŠã©ããã¹ãããã»ãã¥ãªãã£ãã³ããŒã®ãšã³ãžãã¢ãæ¥çèå人ãè¬åž«ã«æããå ·äœçãªå¯Ÿçæ¹æ³ã«ã€ããŠ4ã€ã®è¬æŒãè¡ããããååã®åºèª¿è¬æŒã§ã¯ãJPCERTã³ãŒãã£ããŒã·ã§ã³ã»ã³ã¿ãŒïŒJPCERT/CCïŒã®çäºã§ããåæã»ã³ã¿ãŒé·ãåããç鿬士æ°ãç»å£ããããµã€ããŒæ»æããããåã«ã§ããããšããããŠããã§ããããšããšé¡ããŠãçµç¹ãšããŠã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«ã©ãåããã¹ãããã©ã察åŠãã¹ããã解説ããã
2013幎9æ27æ¥ã«éå¬ãããã»ãããŒããããã¯ãŒã¯ã»ã»ãã¥ãªãã£ã»ã€ã³ãã©ã®å šè²ãã§ã¯ããããã課é¡ã«å¯ŸããŠã©ããã¹ãããã»ãã¥ãªãã£ãã³ããŒã®ãšã³ãžãã¢ãæ¥çèå人ãè¬åž«ã«æããå ·äœçãªå¯Ÿçæ¹æ³ã«ã€ããŠ4ã€ã®è¬æŒãè¡ããããååã®åºèª¿è¬æŒã§ã¯ãJPCERTã³ãŒãã£ããŒã·ã§ã³ã»ã³ã¿ãŒïŒJPCERT/CCïŒã®çäºã§ããåæã»ã³ã¿ãŒé·ãåããç鿬士æ°ãç»å£ããããµã€ããŒæ»æããããåã«ã§ããããšããããŠããã§ããããšããšé¡ããŠãçµç¹ãšããŠã»ãã¥ãªãã£ã€ã³ã·ãã³ãã«ã©ãåããã¹ãããã©ã察åŠãã¹ããã解説ããã
ãŸãçéæ°ã¯ãJPCERT/CCã®åœ¹å²ã«ã€ããŠç°¡åã«ãŸãšããèŽè¬è ã«ååãããªããããJPCERT/CCã¯ãæ¥æ¬ã®ã»ãã¥ãªãã£ã€ã³ã·ãã³ã察å¿ã®åœéçãªçªå£ãšãªãçµç¹ã§ãããã»ãã¥ãªãã£ã€ã³ã·ãã³ãã¯ãåœå¢ããŸããã§å®è¡ãããã±ãŒã¹ãã»ãšãã©ã§ããã®è§£æ±ºã«ã¯åœéçãªååãéèŠãšãªãããã®æ©æž¡ã圹ãšãªãã®ãJPCERT/CCã ããŸãåã»ã³ã¿ãŒã¯ãã»ãã¥ãªãã£æ å ±ãèåŒ±æ§æ å ±ãåéã»åæããŠå ¬éããåœå ã®ã»ãã¥ãªãã£ã¬ãã«ã®åäžãç®æããŠããããçµç¹ã®ã»ãã¥ãªãã£ã¬ãã«åäžã«ã¯ãã€ã³ã·ãã³ãããã³ããªã³ã°ããCSIRTïŒComputer Security Incident Response TeamïŒãéèŠãªåœ¹å²ãæ ããŸããJPCERT/CCã¯ãæ¥æ¬åœã®CSIRTã«åœãããŸããCSIRTããªãçµç¹ã¯ãã€ã³ã·ãã³ãã誰ã«äŒããã¹ããé£çµ¡ç³»çµ±ãã¯ã£ããããªãããã«å¯Ÿå¿ãé ããŸããCSIRTã¯ããã¹ãŠã®ã€ã³ã·ãã³ãã®çªå£ãšããŠæ©èœãããŸãä»çµç¹ã®CSIRTãšã飿ºããŠæ å ±äº€æãè¡ããŸãããã®é£æºãããã»ãã¥ãªãã£ã¬ãã«ã®åäžã«ã€ãªãããŸããïŒçéæ°ïŒã
çéæ°ã«ããã°ãCSIRTã®èšçœ®ããã®æ°å¹Žã§ããŒã ã«ãªãã€ã€ãããšãããæ¥æ¬ã«ãããŠãããæ¥æ¬ã·ãŒãµãŒãåè°äŒããçµç¹å CSIRTã®èšç«ãä¿é²ã»æ¯æŽãè¡ãã課é¡è§£æ±ºã®ããã«ç©æ¥µçã«æŽ»åããŠãããšã®ããšã ã
çéæ°ã¯ç¶ããŠãæè¿ã®ãµã€ããŒæ»æã®åŸåã«ã€ããŠãŸãšããã倧ããã¯ãæªæ§Webãä»ããæ»æããšãæšçåæ»æãã®2ã€ãããæ°å¹Žã®äž»æµã§ãããšãããæªæ§Webãä»ããæ»æãšã¯ãäž»ã«æ¹ãããããWebãµã€ããã¡ãŒã«ãèµ·ç¹ãšãããã«ãŠã§ã¢ãä»èŸŒãããã®Webãµã€ããžèªå°ãããšããæå£ã ãæšçåæ»æã¯ããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ææ³ãèµ·ç¹ãšããã¿ãŒã²ãããšããçµç¹ãå人ã培åºããŠçãæå£ã§ããããåæ¹ã«å ±éããŠèšããããšã¯ãæ¢ç¥ã®è匱æ§ãæªçšããæ»æãã»ãšãã©ã ãšããããšã§ãããããããŒããã€ã¢ã¿ãã¯ïŒè匱æ§ãå ¬è¡šãããåã«ãããå©çšããŠæ»æããããšïŒã¯ãããããªæ°ããæ€åºãããŠããŸãããæ¢ç¥ã§æªä¿®æ£ã®è匱æ§ãç©æ¥µçã«æªçšãããŠããããšã瀺ãäºå®ã§ããïŒçéæ°ïŒã
å€éšCSIRTãšã®æ å ±äº€æãã€ã³ã·ãã³ãã®æ©æè§£æ±ºã»äºé²ã«å¹ã
çéæ°ã¯ãå®éã®ãã«ãŠã§ã¢ãæªçšããã»ãã¥ãªãã£ã€ã³ã·ãã³ããšãã®å¯Ÿå¿ã«ã€ããŠãå ·äœçãªäºäŸããããŠç޹ä»ããã詳现ã¯çãããåœå ã®è€æ°ã®çµç¹ã«ãã«ãŠã§ã¢ãä»èŸŒãŸããŠãããšããæµ·å€ããã®æ å ±ãçºç«¯ãšããJPCERT/CCã被害çµç¹ãžæ å ±ãæäŸããŠãåããŠè¢«å®³ã«æ°ã¥ããšãããã®ã ã£ãããã®ãšãããã被害çµç¹ã¯ãJPCERT/CCã®æ å ±æäŸãåºã«æ°éã®ã»ãã¥ãªãã£å¯Ÿå¿ãµãŒãã¹äºæ¥è ãšååããŠäºæ ã®åæŸã«åããããã®çµç¹ã§ã¯ãæåã®å¯Ÿå¿ã§ææã³ã³ãã¥ãŒã¿ãçºèŠããäŸµå ¥ã«ãŒããæœ°ãããšã«æåãããã«èŠããããšãããæ»æè ã¯ãå¥ã®ã«ãŒããäºåã«çšæããŠãããåã³äŸµå ¥ããŠããã®ã ã管çè ããäžå¯©ãªåããããã·ã¹ãã ã«æ°ã¥ããŠçºèŠããã
ãæšçåæ»æã®æããããšããã¯ãç®çãéæããããã«äœéãã®æå£ã䜿ã£ãŠããããšã§ãããã®äºäŸã¯ãŸã 軜å·ãªã»ãã§ããããã¯ãŒã¯ãè€éã«ãªãã°ãªãã»ã©ãäŸµå ¥çµè·¯ãå¢ããããšã§ãããããçéæ°ã¯ãããããã€ã³ã·ãã³ã察å¿ã®éã«ã¯ãæ å ±ãç©æ¥µçã«å€éšãšå ±æããŠã»ãããšåŒ·èª¿ããããããããããåãæ»æãåããçµç¹ãããã詳ããæ å ±ãæã£ãŠãããããããªãããããã¯åè¿°ã®è¢«å®³çµç¹ã®ããã«ãæ ¹çµ¶ã§ããªãã£ãè åšãçºèŠã§ãããããããªãããããããå€éšããã®æ å ±ã§ã€ã³ã·ãã³ããçºèŠããã±ãŒã¹ã¯å€ããäºãã®é£æºãéèŠã ãšããã
ãã®ããã«ããäºåæºåãšããŠçµç¹å CSIRTã®èšçœ®ãéèŠãšãªããCSIRTãçªå£ãšãªã£ãŠãæ å ±ã®åæŸãšå ±æã宿œããããã®æ å ±ãåºã«ãã²ãŒããŠã§ã€ïŒãµãŒã察çããŠãŒã¶ãŒæè²ãªã©ãéããŠç€Ÿå ã匷åãæ»æè ã¯ãã¿ãŒã²ããã«å¯çããè«ã®ãããªãã®ã§ãããããå ±åããŠããèãæ¹ãå¿ èŠãïŒçéæ°ïŒãšããããâ察çãããªããã°ãªããªãâã®ã§ã¯ãªããâæµãèŠã€ãããã£ã³ã¹ãäœãââçµç¹ãå®ããã£ã³ã¹ãäœãâãšãã芳ç¹ã§ãå€éšãšç©æ¥µçã«é£æºããç¥èŠã®éçŽã«å±ãã§ã»ãããïŒçéæ°ïŒã
