Security Affairsã¯2æ12æ¥(çŸå°æé)ãã9 Possible Ways Hackers Can Use Public Wi-Fi to Steal Your Sensitive Dataãã«ãããŠããµã€ããŒæ»æè ãå ¬è¡ç¡ç·LAN(ããªãŒWi-Fi)ãæªçšãã9ã€ã®ææ³ã解説ãããæ»æè ã¯ãããã®ææ³ã«ãããå人æ å ±ãçªåããå¯èœæ§ãããã
å ¬è¡ç¡ç·LANãçãæ»æææ³
è åšã¢ã¯ã¿ãŒãæªçšããå ¬è¡ç¡ç·LANã«é¢ãã9ã€ã®æ»æææ³ã¯æ¬¡ã®ãšããã
äžéè æ»æ(MITM: Man-in-the-middle attack)
2è éã®éä¿¡ãäžéã§ååãæ¹ããããæ»æææ³ãå ¬è¡ç¡ç·LANã§ã¯éä¿¡ããŒã¿ãæå·åãããŠããªãããšããããè åšã¢ã¯ã¿ãŒã¯å®¹æã«äžæ£ã¢ã¯ã»ã¹ã§ããã
åœã®Wi-Fiæ¥ç¶
å¥åãæªéã®åå(Evel Twin)ããæ»æè ã«ãã£ãŠèšçœ®ãããæ¬ç©ãšã»ãŒåäžã®å ¬è¡ç¡ç·LANç°å¢ããŠãŒã¶ãŒã¯ç¡æèã®ãã¡ã«åœã®ç°å¢ã«æ¥ç¶ããéä¿¡ããã¹ãŠååãããå¯èœæ§ãããã
ãã±ããã¹ãããã£ã³ã°
å ¬è¡ç¡ç·LANãééããéä¿¡ãã±ãããäžæ£ã«ãã£ããã£ãŒããææ³ãéä¿¡ããŒã¿ãä¿åããåŸããåæããããšãã§ããããã®ææ³ã¯åœãå°åã«ãã£ãŠå¿ ãããäžæ³è¡çºãšã¯ãããŠããªãã
ãµã€ããžã£ãã¯(ã»ãã·ã§ã³ãã€ãžã£ãã¯)
äžæ£ã«å ¥æããã»ãã·ã§ã³æ å ±ãçšããŠãæ¥ç¶ããã€ãžã£ãã¯ããããã¹ã¯ãŒããªã©ã®èªèšŒæ å ±ãçŽæ¥æŒæŽ©ããããã§ã¯ãªãããæ¬äººã«ãªãããŸããŠããŸããŸãªæäœãå®è¡ããããšãã§ããã
ã·ã§ã«ããŒãµãŒãã£ã³
æ©å¯æ å ±ãè©è¶ãã«èŠãèŠãŠçªåããææ³ãå€å žçã ã广çãšããããå ¬è¡ç¡ç·LANã®èšçœ®ãããã€ã³ã¿ãŒãããã«ãã§ãå ¬å ±ã®ç©ºéã§è¢«å®³ã«éãå¯èœæ§ãããã
DNSã¹ããŒãã£ã³ã°
DNSã«ããåå解決ã®çµæãäžæ£ã«æ¹ããããææ³ããã®æ»æã«ããéä¿¡å ãã¹ããæªæã®ãããã¹ãã«å€æŽãããå¯èœæ§ãããã
Wi-Fiãã£ãã·ã³ã°
ãã£ãã·ã³ã°è©æ¬ºãšåæ§ããŠãŒã¶ãŒãæªæã®ããWi-Fiç°å¢ãžèªå°ããããã®æ»æã«ã¯äžèšã®ãåœã®Wi-Fiæ¥ç¶ããå«ãŸããããšãããã
äžæ£ãªã¢ã¯ã»ã¹ãã€ã³ã
æ»æè ã¯å ¬å ±ã®ç°å¢ã«æªæã®ããã¢ã¯ã»ã¹ãã€ã³ããèšçœ®ããããšãããã
ããŒãã¬ãŒ
æ»æè ã¯å ¬å ±ã®ã³ã³ãã¥ãŒã¿ãã¢ãã€ã«ããã€ã¹ã«ããŒãã¬ãŒãã€ã³ã¹ããŒã«ããããšãããããã®ãããªããã€ã¹ã䜿çšãããšèªèšŒæ å ±ãçªåãããå¯èœæ§ãããã
äžéšã¯å ¬è¡ç¡ç·LANãšçŽæ¥é¢ä¿ã®ãªãæ»æææ³ã ããå ¬è¡ç¡ç·LANã®èšçœ®ãããç°å¢ã§è¢«å®³ãããããå¯èœæ§ããããæ»æè ã¯ããããææ®µãé§äœ¿ããŠèªèšŒæ å ±ãçªåããããšãããããåžžã«ãããæ»æã«æ³šæããããšãæãŸããŠããã
å ¬è¡ç¡ç·LANãå®å šã«äœ¿ãããã®å¯Ÿç
Security Affairsã¯ãäžèšã®å ¬è¡ç¡ç·LANãæªçšããæ»æææ³ã«ã€ããŠã次ã®ããã«å¯Ÿçãè¬ããããšãæšå¥šããŠããã
- httpsæ¥ç¶ã䜿çšããããã©ãŠã¶ãŒããµã€ãã®ä¿¡é Œæ§ã«é¢ããèŠåã衚瀺ããå Žåã¯ããŒã¿ãå ¥åããªã
- 2ã€ä»¥äžã®äŒŒãååã®Wi-Fiã¢ã¯ã»ã¹ãã€ã³ãã衚瀺ãããå Žåã¯æ³šæããã1ã€ãé€ããŠããŸãã¯ãã¹ãŠæªæã®ããæ¥ç¶ã®å¯èœæ§ããããå®å šãªæ¥ç¶ãèå¥ã§ããªãå Žåã¯ãå ¬è¡ç¡ç·LANã管çããã¹ã¿ããã«å°ããããšãæšå¥šããã
- ä¿¡é Œã§ããä»®æ³ãã©ã€ããŒããããã¯ãŒã¯(VPN: Virtual Private Network)ã䜿çšããŠéä¿¡ããã¹ãŠæå·åãã
- ãªã³ã©ã€ã³ãµã€ããå©çšããåŸã¯ãå¿ ããµã€ã³ã¢ãŠã(ãã°ã¢ãŠã)ãããã¢ã¯ãã£ããªã»ãã·ã§ã³ãæ®ããªãããã«è¡åãã身ã«èŠãã®ãªãã»ãã·ã§ã³ãååšããå Žåã¯ãã¹ãŠåŒ·å¶çã«éãã
- æ©å¯æ å ±ã®å ¥åæã¯åšå²ã®ç®ã確èªãã
- DNSæå·åãæäŸããä¿¡é Œã§ãããµãŒãã¹ãå©çšããããä¿¡é Œã§ããä»®æ³ãã©ã€ããŒããããã¯ãŒã¯ã䜿çšãã
- å人æ å ±ã®å ¥åãæ±ããå ¬è¡ç¡ç·LANã¯äœ¿çšããªã
- ä¿¡é Œã§ããä»®æ³ãã©ã€ããŒããããã¯ãŒã¯ã䜿çšãã
- æ©å¯æ å ±ãå ¥åããäœæ¥ã«å ¬å ±ã®ã³ã³ãã¥ãŒã¿ãã¢ãã€ã«ããã€ã¹ã䜿çšããªããã©ãããŠã䜿çšãé¿ããããªãå Žåã¯ãä»®æ³ããŒããŒãã䜿çšãã
Security Affairsã¯å®å šãªéä¿¡ã確ä¿ããããã«ãä¿¡é Œã§ããä»®æ³ãã©ã€ããŒããããã¯ãŒã¯ãä»ããŠå ¬è¡ç¡ç·LANãå©çšããããšãæšå¥šããŠãããä»®æ³ãã©ã€ããŒããããã¯ãŒã¯ã¯éä¿¡ãæå·åããããšã«å ããŠããã€ã¹ã®IPã¢ãã¬ã¹ãé èœã§ãããããæœåšçãªè åšãé ãããããšãã§ããããã€ã©ã®ãããªåœ¢ã§ãµã€ããŒæ»æãåãããããããªãããã®ãããã€ã³ã¿ãŒãããã®å©çšè ã«ã¯åžžã«æ»æãèŠæãããšãšãã«ãç©æ¥µçãªã»ãã¥ãªãã£å¯ŸçãæãŸããŠããã
