Showing posts with label security. Show all posts
Showing posts with label security. Show all posts

May 12, 2022

身代金 平均額 約17万米ドル

支払った身代金の平均額は約17万米ドル、復元できた割合は65% - ランサムウェア被害の現実 (01/17)

https://japan.zdnet.com/paper/20013085/30005356/


メモ、Log4j

今更だが、メモが出てきたので書き留めておく。

Apache Log4jの脆弱性に関する対応について (2021/12/20)
https://help.dstmp.com/news/01211220/

『2021年12月14日までに弊社サービスの本脆弱性に関する対応は完了しております。』


「Apache Log4j」の脆弱性問題によるリコー製品への影響について (2021/12/15-24)
https://jp.ricoh.com/info/notice/2021/1215_1

複合機、プリンター、ソフトウェアなど概ね『影響なし』とのこと。

「RICOH カンタン文書活用 タイプZ」のエージェントソフトに影響あり。V1.7.1にアップデートすれば良い


関連

CVE-2022-22965 Spring4shell

CVE-2022-22965: Spring Coreにリモートコード実行脆弱性(SpringShell)、
すでに実際のエクスプロイトも
(paloalto networks, 2022.03.31)
https://unit42.paloaltonetworks.jp/cve-2022-22965-springshell/

Spring Frameworkの脆弱性 CVE-2022-22965(Spring4shell)についてまとめてみた (piyolog, 2022.04.01)
https://piyolog.hatenadiary.jp/entry/2022/04/01/065946


Jul 11, 2021

Vulnerability Summary for the Week of June 28

US-CERTの先週の脆弱性サマリーから、いくつかピックアップする。


以下、次の順に

Primary Vendor -- Product, Description, Published, CVSS Score, Source & Patch Info


adobe -- after_effects

Adobe After Effects version 18.1 (and earlier) is affected by an Uncontrolled Search Path element vulnerability. An unauthenticated attacker could exploit this to to plant custom binaries and execute them with System permissions. Exploitation of this issue requires user interaction.

2021-06-28
9.3
CVE-2021-28570 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-28570
MISC https://helpx.adobe.com/ee/security/products/after_effects/apsb21-33.html


adobe -- robohelp_server

Adobe RoboHelp Server version 2019.0.9 (and earlier) is affected by a Path Traversal vulnerability when parsing a crafted HTTP POST request. An authenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue does not require user interaction.

2021-06-28
9
CVE-2021-28588 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-28588
MISC https://www.zerodayinitiative.com/advisories/ZDI-21-660/


fidelissecurity -- deception

Vulnerability in the CommandPost, Collector, and Sensor components of Fidelis Network and Deception enables an attacker with user level access to the CLI to inject root level commands into the component and neighboring Fidelis components. The vulnerability is present in Fidelis Network and Deception versions prior to 9.3.7 and in version 9.4. Patches and updates are available to address this vulnerability.

2021-06-25
9
CVE-2021-35047 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-35047
CONFIRM https://support.fidelissecurity.com/hc/en-us/categories/360001842694-Advisories-News-and-Policies


helpu -- helpu

A remote code execution vulnerability exists in helpUS(remote administration tool) due to improper validation of parameter of ShellExecutionExA function used for login.

2021-06-29
CVE-2020-7868 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2020-7868
MISC https://www.boho.or.kr/krcert/secNoticeView.do?bulletin_writing_sequence=36088


huawei -- anyoffice

There is a deserialization vulnerability in Huawei AnyOffice V200R006C10. An attacker can construct a specific request to exploit this vulnerability. Successfully exploiting this vulnerability, the attacker can execute remote malicious code injection and to control the device.

AnyOfficeは、BYODを視野に入れたセキュリティ管理ツールで、MDMコンポーネントも含まれるらしい。  https://forum.huawei.com/enterprise/en/huawei-anyoffice-v200r002c10-deployment-guide-contents/thread/416297-867

2021-06-29
9.3
CVE-2021-22439 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-22439
MISC https://www.huawei.com/en/psirt/security-advisories/huawei-sa-20210619-01-injection-en


inkdrop -- inkdrop

Inkdrop versions prior to v5.3.1 allows an attacker to execute arbitrary OS commands on the system where it runs by loading a file or code snippet containing an invalid iframe into Inkdrop.

Takuyaさんという日本のクリエイターが開発したノートアプリとのこと。  https://webdesign-trends.net/entry/4163

2021-06-28
9.3
CVE-2021-20745 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-20745
MISC https://www.inkdrop.app/
MISC https://docs.inkdrop.app/releases/5.3.1
MISC https://jvn.jp/en/jp/JVN29949691/index.html


mcafee -- mvision_edr

A command injection vulnerability in MVISION EDR (MVEDR) prior to 3.4.0 allows an authenticated MVEDR administrator to trigger the EDR client to execute arbitrary commands through PowerShell using the EDR functionality 'execute reaction'.

2021-06-29
9
CVE-2021-31838 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-31838
CONFIRM https://kc.mcafee.com/corporate/index?page=content&id=SB10342


securepoint -- openvpn-client

Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as privileged user.

ローカルの非特権ユーザが、設定変更により、外部スクリプトを特権ユーザとして実行できる。最新版にupdateすれば良い。

2021-06-28
7.2
CVE-2021-35523 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-35523
MISC https://github.com/Securepoint/openvpn-client/security/advisories/GHSA-v8p8-4w8f-qh34
MISC https://bogner.sh/2021/04/local-privilege-escalation-in-securepoint-ssl-vpn-client-2-0-30/
FULLDISC http://seclists.org/fulldisclosure/2021/Jun/59
MISC http://packetstormsecurity.com/files/163320/Securepoint-SSL-VPN-Client-2.0.30-Local-Privilege-Escalation.html


tenable -- nessus

Nessus versions 8.13.2 and earlier were found to contain a privilege escalation vulnerability which could allow a Nessus administrator user to upload a specially crafted file that could lead to gaining administrator privileges on the Nessus host.

2021-06-29
7.2
CVE-2021-20079 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-20079
MISC https://www.tenable.com/security/tns-2021-07


以下「Severity Not Yet Assigned」からピックアップしたもの。


apache -- traffic_server

Incorrect handling of url fragment vulnerability of Apache Traffic Server allows an attacker to poison the cache. This issue affects Apache Traffic Server 7.0.0 to 7.1.12, 8.0.0 to 8.1.1, 9.0.0 to 9.0.1.

caching proxy server "Apache Traffic Server"への潜在的リモート攻撃脆弱性

2021-06-29
not yet calculated
CVE-2021-27577 https://nvd.nist.gov/vuln/detail/CVE-2021-27577
 ← Base Score:  7.5 HIGH とされている。
MISC https://lists.apache.org/thread.html/ra1a41ff92a70d25bf576d7da2590575e8ff430393a3f4a0c34de4277%40%3Cusers.trafficserver.apache.org%3E


google -- chrome

Use after free in WebGL in Google Chrome prior to 91.0.4472.114 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

2021-07-02
not yet calculated
CVE-2021-30554 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-30554
 ← Base Score:  8.8 HIGH  となっている。
MISC https://crbug.com/1219857
MISC https://chromereleases.googleblog.com/2021/06/stable-channel-update-for-desktop_17.html


hitachi -- virtual_file_platform_versions

Hitachi Virtual File Platform Versions prior to 5.5.3-09 and Versions prior to 6.4.3-09, and NEC Storage M Series NAS Gateway Nh4a/Nh8a versions prior to FOS 5.5.3-08(NEC2.5.4a) and Nh4b/Nh8b, Nh4c/Nh8c versions prior to FOS 6.4.3-08(NEC3.4.2) allow remote authenticated attackers to execute arbitrary OS commands with root privileges via unspecified vectors.

2021-06-28
not yet calculated
CVE-2021-20740 https://nvd.nist.gov/vuln/detail/CVE-2021-20740
 ← Base Score:  8.8 HIGH とされている。
MISC https://www.hitachi.co.jp/products/it/storage-solutions/global/sec_info/2021/2021_306.html
MISC https://jpn.nec.com/security-info/secinfo/nv21-011.html
MISC https://jvn.jp/en/jp/JVN21298724/index.html


huawei -- smartphone

There is a Memory Buffer Improper Operation Limit Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause the device to crash and restart.

2021-06-30
not yet calculated
CVE-2021-22350 https://nvd.nist.gov/vuln/detail/CVE-2021-22350
 ← Base Score:  7.5 HIGH とされている。
MISC https://consumer.huawei.com/en/support/bulletin/2021/5/


huawei -- smartphone

There is a Configuration Defect Vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may allow attackers to hijack the device and forge UIs to induce users to execute malicious commands.

2021-06-30
not yet calculated
CVE-2021-22352 https://nvd.nist.gov/vuln/detail/CVE-2021-22352
 ← Base Score:  7.8 HIGH とされている。
MISC https://consumer.huawei.com/en/support/bulletin/2021/5/


ibm -- security_identity_manager_adapters

IBM Security Identity Manager Adapters 6.0 and 7.0 could allow a remote authenticated attacker to conduct an LDAP injection. By using a specially crafted request, an attacker could exploit this vulnerability and takeover other accounts. IBM X-Force ID: 199252.

2021-06-28
not yet calculated
CVE-2021-20574 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-20574
 ← Base Score:  8.8 HIGH (CVSS:3.1 ...) とされている。
CONFIRM https://www.ibm.com/support/pages/node/6465875
XF https://exchange.xforce.ibmcloud.com/vulnerabilities/199252


jenkins -- jenkins

Jenkins 2.299 and earlier, LTS 2.289.1 and earlier does not invalidate the previous session on login.

2021-06-30
not yet calculated
CVE-2021-21671 https://nvd.nist.gov/vuln/detail/CVE-2021-21671
 ← Base Score:  7.5 HIGH とされている。
CONFIRM https://www.jenkins.io/security/advisory/2021-06-30/#SECURITY-2371
MLIST http://www.openwall.com/lists/oss-security/2021/06/30/1


libressl -- libressl

LibreSSL 2.9.1 through 3.2.1 has a heap-based buffer over-read in do_print_ex (called from asn1_item_print_ctx and ASN1_item_print).

2021-07-01
not yet calculated
CVE-2019-25048 https://nvd.nist.gov/vuln/detail/CVE-2019-25048
 ← Base Score:  7.1 HIGH とされている。
MISC https://github.com/libressl-portable/portable/commit/17c88164016df821df2dff4b2b1291291ec4f28a
MISC https://bugs.chromium.org/p/oss-fuzz/issues/detail?id=13914
MISC https://github.com/google/oss-fuzz-vulns/blob/main/vulns/libressl/OSV-2020-1923.yaml


mediawiki -- mediawiki

An issue was discovered in the CentralAuth extension in MediaWiki through 1.36. The Special:GlobalRenameRequest page is vulnerable to infinite loops and denial of service attacks when a user's current username is beyond an arbitrary maximum configuration value (MaxNameChars).

2021-07-02
not yet calculated
CVE-2021-36125 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-36125
 ← Base Score:  7.5 HIGH とされている。
MISC https://phabricator.wikimedia.org/T260865
MISC https://gerrit.wikimedia.org/r/q/I97d8b3236b5abed8ba9a9c4d3ab5050c2e782c22


microsoft -- windows

Windows Print Spooler Remote Code Execution Vulnerability

2021-07-02
not yet calculated
CVE-2021-34527 https://nvd.nist.gov/vuln/detail/CVE-2021-34527
 ← Base Score:  8.8 HIGH (CVSS 3.1)とされている。Criticalじゃないのか?
   ※ PrintNightmare 過去記事 
MISC https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2021-34527


netgear -- wac104_devices

NETGEAR WAC104 devices before 1.0.4.15 are affected by an authentication bypass vulnerability in /usr/sbin/mini_httpd, allowing an unauthenticated attacker to invoke any action by adding the &currentsetting.htm substring to the HTTP query, a related issue to CVE-2020-27866. This directly allows the attacker to change the web UI password, and eventually to enable debug mode (telnetd) and gain a shell on the device as the admin limited-user account (however, escalation to root is simple because of weak permissions on the /etc/ directory).

2021-06-30
not yet calculated
CVE-2021-35973 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-35973
 ← Base Score:  9.8 CRITICAL とされている。
MISC https://gynvael.coldwind.pl/?lang=en&id=736
MISC https://kb.netgear.com/000063785/Security-Advisory-for-Authentication-Bypass-on-WAC104-PSV-2021-0075


nvidia -- mb2

Bootloader contains a vulnerability in NVIDIA MB2 where a potential heap overflow could cause memory corruption, which might lead to denial of service or code execution.

2021-06-30
not yet calculated
CVE-2021-34384 https://nvd.nist.gov/vuln/detail/CVE-2021-34384
 ← Base Score:  7.8 HIGH (CVSS:3.1)とされている。
CONFIRM https://nvidia.custhelp.com/app/answers/detail/a_id/5205


torproject -- tor

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-006. The v3 onion service descriptor parsing allows out-of-bounds memory access, and a client crash, via a crafted onion service descriptor

2021-06-29
not yet calculated
CVE-2021-34550 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-34550
 ← Base Score:  7.5 HIGH とされている。
MISC https://gitlab.torproject.org/tpo/core/tor/-/issues/40392
CONFIRM https://blog.torproject.org/node/2041


torproject -- tor

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-005. Hashing is mishandled for certain retrieval of circuit data. Consequently. an attacker can trigger the use of an attacker-chosen circuit ID to cause algorithm inefficiency.

2021-06-29
not yet calculated
CVE-2021-34549 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-34549
 ← Base Score:  7.5 HIGH とされている。
MISC https://gitlab.torproject.org/tpo/core/tor/-/issues/40391
CONFIRM https://blog.torproject.org/node/2041


torproject -- tor

An issue was discovered in Tor before 0.4.6.5, aka TROVE-2021-003. An attacker can forge RELAY_END or RELAY_RESOLVED to bypass the intended access control for ending a stream.

2021-06-29
not yet calculated
CVE-2021-34548 https://nvd.nist.gov/nvd.cfm?cvename=CVE-2021-34548
 ← Base Score:  7.5 HIGH とされている。
MISC https://gitlab.torproject.org/tpo/core/tor/-/issues/40389
CONFIRM https://blog.torproject.org/node/2041


xen -- xen

Guest triggered use-after-free in Linux xen-netback A malicious or buggy network PV frontend can force Linux netback to disable the interface and terminate the receive kernel thread associated with queue 0 in response to the frontend sending a malformed packet. Such kernel thread termination will lead to a use-after-free in Linux netback when the backend is destroyed, as the kernel thread associated with queue 0 will have already exited and thus the call to kthread_stop will be performed against a stale pointer.

2021-06-29
not yet calculated
CVE-2021-28691 https://nvd.nist.gov/vuln/detail/CVE-2021-28691
 ← Base Score:  7.8 HIGH とされている。
MISC https://xenbits.xenproject.org/xsa/advisory-374.txt


出典

Bulletin (SB21-186) Vulnerability Summary for the Week of June 28, 2021 (07/05)
https://us-cert.cisa.gov/ncas/bulletins/sb21-186


Apr 5, 2020

zoomいろいろ

FBI Warns of Teleconferencing and Online Classroom Hijacking During COVID-19 Pandemic (03/30)

https://www.fbi.gov/contact-us/field-offices/boston/news/press-releases/fbi-warns-of-teleconferencing-and-online-classroom-hijacking-during-covid-19-pandemic

事件報告
 2020年3月下旬、マサチューセッツ州の高校で、教師がテレビ会議ソフトウェアZoomを使用してオンラインクラスを行っている間に、身元不明の個人が教室にダイヤルしたと報告しました。 この個人は冒とく的な言葉を叫び、それから指導の途中で先生の自宅の住所を叫びました。
 マサチューセッツにある2番目の学校は、身元不明の個人がZoomミーティングにアクセスしていることを報告しました。 この事件では、個人はビデオカメラで見ることができ、卍の入れ墨が表示されていました。

電話会議の乗っ取りの脅威を軽減するには、次の手順を実行
・会議や教室を公開しない。ミーティングパスワードを要求するか、待合室機能を使用してゲストの許可を制御する。
・SNSで、テレビ会議や教室へのリンクを共有しない。
・画面共有オプションを管理。画面共有を「ホストのみ」に変更する。
・最新のバージョンを使用する。
・最後に、組織のテレワークポリシーまたはガイドが物理的および情報セキュリティの要件に対応していることを確認してください。 
他に『更新プログラムでは、電話会議ソフトウェアプロバイダーはデフォルトで会議のパスワードを追加し、参加する会議をランダムにスキャンする機能を無効にしました』ってアレゲだ。

Zoomに複数の脆弱性が判明 Web会議の「乗っ取り」被害、全米で相次ぐ (04/02)

https://www.itmedia.co.jp/enterprise/articles/2004/02/news058.html
技術情報サイトの「Bleeping Computer」は2020年3月31日、Zoom Windowsクライアントのチャット機能にUNCパス関連の脆弱性が見つかったと伝えた。悪用された場合、不正なリンクをクリックしたユーザーのWindows認証情報が盗まれる恐れがある。

ユーザーがこのUNCパスのリンクをクリックすると、WindowsはSMBファイル共有プロトコルを使ってリモートのサイトに接続し、指定されたファイルを開こうとする。その際にWindowsはデフォルトで、ユーザーのログイン名とNTLMパスワードハッシュを送信する。これを「Hashcat」のような無料ツールでクラッキングすれば、ユーザーのパスワードを見破ることが可能だという。

セキュリティ専門家はこれについて「UNCリンクをクリックさせてプログラムを起動させることも可能だ」と指摘している。

Zoomについては、ユーザーの情報がFacebookに送られていたことが発覚するなど、セキュリティやプライバシーを巡る問題が立て続けに浮上している。

Zoom : Security Vulnerabilities 

https://www.cvedetails.com/vulnerability-list/vendor_id-2159/Zoom.html
ここの一覧が見やすい。以下、CVE情報を挙げておく。

CVE-2019-13567 

https://www.cvedetails.com/cve/CVE-2019-13567/
CVSS Score 6.8
macOSの4.4.53932.0709以前のZoom Clientでは、CVE-2019-13450とは異なる脆弱性であるリモートコードの実行が可能です。ZoomOpener デーモン(別名:隠しウェブサーバ)が実行されているにもかかわらず、Zoom Client がインストールされていないか、または開くことができない場合、攻撃者は悪意を持って細工された起動 URL を使ってリモートでコードを実行することができます。注意: ZoomOpenerは、このツールが有効で2019-07-10 MRTConfigDataを持っている場合、Apple Malware Removal Tool (MRT)によって削除されます。
発行日 : 2019-07-12 最終更新日 : 2019-08-30 

↑ 注意。「macOSの」とされているが、下の方の『Products Affected By CVE-2019-13567』の一覧には、それ以外のOS向けも色々含まれている。

CVE-2019-13450 

https://www.cvedetails.com/cve/CVE-2019-13450/
CVSS Score 4.3
macOS上のZoom Client 4.4.4.4~RingCentral 7.0.136380.0312 では、リモート攻撃者がビデオカメラをアクティブにした状態でユーザーにビデオ通話に強制的に参加させることができます。これは、任意の Web サイトがローカルホストポート 19421 または 19424 で Zoom Web サーバーと対話できるために発生します。注: Zoom クライアントが過去にインストールされた後にアンインストールされた場合、マシンは脆弱なままです。悪用をブロックするには、ZDisableVideo環境設定および/またはWebサーバーを殺す、~/.zoomusディレクトリを削除する、~/.zoomusプレーンファイルを作成するなどの追加の手順が必要です。
公開日 : 2019-07-09 最終更新日 : 2019-07-16 

CVE-2018-15715 

https://www.cvedetails.com/cve/CVE-2018-15715/
CVSS Score 7.5
Windows (バージョン 4.1.34814.1119 以前)、Mac OS (バージョン 4.1.34801.1116 以前)、および Linux (2.4.129780.0915 以下) の Zoom クライアントは、不正なメッセージ処理に対して脆弱です。リモートの認証されていない攻撃者は、ターゲット クライアントの機能を呼び出すために、会議の出席者または Zoom サーバからの UDP メッセージを詐称することができます。これにより、攻撃者は会議の出席者を削除したり、ユーザーからのメッセージを詐称したり、共有画面を乗っ取ったりすることが可能になります。
公開日 : 2018-11-30 最終更新日 : 2019-10-09 

CVE-2014-5811 

https://www.cvedetails.com/cve/CVE-2014-5811/
CVSS Score 5.4
Android用アプリ「ZOOM Cloud Meetings (aka.us.zoom.videomeetings)」の@7F060008は、SSLサーバーからのX.509証明書を検証していないため、中間者攻撃者がサーバーになりすまし、細工された証明書を介して機密情報を取得することができます。
公開日 : 2014-09-09 最終更新日 : 2014-09-20 

Zoom あれこれ(various)  (04/02)

http://www.st.ryukoku.ac.jp/~kjm/security/memo/2020/04.html#20200402_zoom

Zoom爆撃と予防策についてまとめてみた (04/02)

https://piyolog.hatenadiary.jp/entry/2020/04/03/154449
--> 04/07 追記

危なっかしさが良く分かる記事(↓)

Linux用zoomパッケージ:お粗末なメンテナスクリプト (04/06)

https://security.sios.com/guest/linuxzoom.html
--> 04/08 追記

Zoom、北米のWeb会議の暗号キーを誤って中国データセンター経由にした問題について説明 (04/05)

https://www.itmedia.co.jp/news/articles/2004/05/news010.html

 Zoomは米国に拠点を置く企業だが、中国にも拠点がある。もし中国政府がZoomの中国拠点に対し、ユーザー情報の開示を求めれば、Zoomはこれを拒否できず、データが中国政府にわたる可能性があるとCitizen Labは指摘した。

 また、エンドツーエンドの暗号化を主張していることに関しも、Citizen Labは政府や医療関係者、機密情報を持つ企業など、強力なプライバシーと機密性を必要とする場合は、現時点ではZoomを利用しないことを強く勧めた。

Mar 12, 2020

信頼していたVPNが悪用された場合に何が起きるのか、記事

https://www.fujitsu.com/jp/solutions/business-technology/security/secure/column/202002-1/index.html

Pulse Secureの「情報漏えいの脆弱性(CVE-2019-11510)」や「コマンドインジェクションの脆弱性(CVE-2019-11539)」などは、実証コードを含む情報が公開されており、これら脆弱性を組み合わせることで遠隔の攻撃者から製品が動作する機器をroot権限にて乗っ取ることも可能という非常に大きなリスクとなっています。

最近の被害事例として、大手外貨両替サービスを提供するTravelex社がREvil(Sodinokibi)ランサムウェアに大規模感染した

VPN製品にもセキュリティ修正が含まれる最新のアップデートを適用するための組織ポリシーが不可欠です。
しかしながら、VPN製品へのアップデート適用は、多くの場合クライアントソフトウェアのアップデートなどが伴うことで利用者への負担が大きくなったり、製品ベンダーからのアップデート提供が遅れ、いわゆる0day脆弱性の期間が発生する可能性もないとは言えません。

即時のアップデート適用が難しい場合には、製品ベンダーが提供しているワークアラウンド(緩和策)があればそれを実施したり、IPSや次世代ファイアウォールなどのセキュリティ製品を予めネットワーク内に組み込んでおくことで脆弱性を突く攻撃を検知・防御できる可能性があるため、これらをアップデート適用までの暫定対処として実施いただくことを強く推奨します。


Feb 22, 2020

記事いろいろ、VPN hack, http-methods, enum4linux, cudahushcat

Fox Kitten Campaign (2020.02)

Widespread Iranian Espionage-Offensive Campaign

サマリー (02/16)
https://www.clearskysec.com/fox-kitten/

フルレポート
https://www.clearskysec.com/wp-content/uploads/2020/02/ClearSky-Fox-Kitten-Campaign.pdf


Iranian hackers have been hacking VPN servers to plant backdoors in companies around the world (02/16)

https://www.zdnet.com/article/iranian-hackers-have-been-hacking-vpn-servers-to-plant-backdoors-in-companies-around-the-world/
Pulse Secure、Palo Alto Networks、Fortinet、Citrixの企業VPNサーバ等へのハックについて。

イラン政府支援ハッキングユニットは「IT、通信、石油およびガス、航空、政府、およびセキュリティの各セクターの企業」を標的に。実力はロシア、中国、北朝鮮などと並びうる。

本APTグルーブは1-day vulnerabilityの悪用能力や、カスタマイズドマルウェア開発能力がある。2019年、Pulse Secure「Connect」VPN(CVE-2019-11510)、Fortinet FortiOS VPN(CVE-2018-13379)、およびPalo Alto Networksの「Global Protect」で開示された脆弱性を迅速に武器化した。後にCitrix "ADC" VPNで公開された脆弱性であるCVE-2019-19781も。
。。。だそうです。


Iranian Hackers Exploiting VPN Flaws to Backdoor Organizations Worldwide (02/18)

https://thehackernews.com/2020/02/iranian-hackers-vpn-vulnerabilities.html

最初の足場を獲得すると、C2サーバーと通信して、バックドアを植えるために使用できる一連のカスタムVBScriptファイルをダウンロードする

さらに、ウイルス対策ソフトウェアによる検出を回避するために、バックドアコード自体をチャンクでダウンロードする。これらの個々のファイルをつなぎ合わせて実行可能ファイルを作成するのは、「combine.bat」。

これらのタスクを実行して持続性を実現するために、Juicy PotatoやInvoke the Hashなどのツールを悪用して、高レベルの特権を獲得し、ネットワークを横切って移動する。

攻撃者が開発した他のツールには次のものがある。
・STSRCheck-ターゲットネットワークのデータベース、サーバー、および開いているポートをマッピングし、デフォルトの資格情報でログ記録することでブルートフォースするツール。
・Port.exe-定義済みのポートとサーバーをスキャンするツール。

攻撃者がlateral movement能力を獲得すると、攻撃者は最終段階に移動します:関連情報について、侵害されたシステムをスキャンし、(POWSSHNETと呼ばれる自己開発ツールを使用して)リモートデスクトップ接続を確立して、またはハードコードされたIPアドレスへのソケットベースの接続を開いて、ファイルを盗み出します。
The Hacker News はCVEへのリンクなど、使いやすい印象。

http-methods

https://nmap.org/nsedoc/scripts/http-methods.html
nmapのスクリプトでのhttp-methodsの検出について

enum4linux Package Description

https://tools.kali.org/information-gathering/enum4linux
Windows やSambaの概況調査ツール。
以前は www.bindview.comで enum.exeで同様の事が出来たのだそうだ。

Kali Linux 1.0.4リリースとenum4linux

https://ozuma.hatenablog.jp/entry/20130730/1375196315
enum4linuxの続き。Perlとのこと。

cudahashcat

https://books.google.co.jp/books?id=6XS3DwAAQBAJ&pg=PA298&lpg=PA298&dq=cudahashcat&source=bl&ots=2YKMJ-Expf&sig=ACfU3U0E6vl6xX8LmFP8eWNUda353EFAfQ&hl=ja&sa=X&ved=2ahUKEwjLv-GcgtvnAhUVzmEKHetdDqU4FBDoATACegQICRAB

Amazon EC2のGPUインスタンスでハッシュ解読をやってみる (2016-05-20)

http://inaz2.hatenablog.com/entry/2016/05/20/011353

Feb 1, 2020

Tick、Daserf、RAT Loader

三菱電機 情報漏えいの件(過去記事)の背後にいるとされるTickグループと関連マルウェアについて、記事から以下に抜粋します。

・日本の製造業を狙うTickグループ

https://www.macnica.net/mpressioncss/feature_05.html/
 『
TTP(Tactics, Techniques and Procedures)より考察する脅威の検出と緩和策
マルウェアの配送について

海外拠点向けには、日本とは異なる現地文化を考慮したメール訓練や注意喚起が必要であると思われます。又、マルウェアの配送よりも後フェーズの攻撃、侵入拡大フェーズで使われるTickのテクニックが検知できるかの確認も有効と考えられます。
攻撃について
Officeのゼロデイ攻撃や新しい脆弱性を悪用した攻撃は観測されていませんが、攻撃者の侵入し易さをコントロールするという点で、日常的なパッチマネージメントは有効な緩和策になると思われます。特にインターネットからアクセス可能な機器の脆弱性は優先して対応する必要があります。
インストールされるRAT、遠隔操作(C&Cについて)
検出が困難になっています。メモリ上でのみ悪性コードが動くタイプのローダーには、メモリスキャンによる検出が可能です。
正規サイトを改ざんしC&Cとして悪用するため、シグネチャベースのネットワークセンサーでは検出が困難になっています。
但し、攻撃者の変更が難しい(もしくは注意が行き届いていない)と思われるケースもあり、固定のユーザエージェントを使う検体も存在します。その場合は、その特徴を踏まえたルールで検出が可能です。
ネットワーク検出観点でいうと、アノマリな通信を検出するNDR(Network Detection & Response)製品に効果が期待できます。
侵入拡大・目的実行
特に標的型攻撃がEDR製品の導入前に始まっていたケースでは、足場をつくるフェーズが完了しているため、製品が持つ検知パターンでの検出漏れが懸念されます。
EDR群の製品を導入した場合には、定期的に収集したログに含まれる正規コマンドの実行状況やそのコマンドがIT技術者以外の所有する端末によって頻繁に実行されていないかどうかといった視点で分析して、攻撃の検出漏れがないように注意...


・CYBER GRID VIEW Vol.2 (2016.08.02)

  https://www.lac.co.jp/lacwatch/report/20160802_000385.html
  ラックの研究開発部門であるサイバー・グリッド・ジャパンによるマルウェアDaserfのレポート(PDF)から抜粋。
 『
Daserfの検出方法 
Daserf は C2 サーバとの通信を確立するために、10 秒間に 1 回程度の頻度で C2 サーバ上にある特定の ASP ファイルに向け、HTTP POST 通信を発生させます。
プロキシログには同一の PC から発生した大量の POST 通信が記録されることになる ...
通信を行う際に HTTP ヘッダに付与される User-Agent は、マルウェアの中にハードコードされており、最近の Daserf のバージョンでは "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; SV1)"
Autoruns6などを利用して Windows 起動時に自動実 行するスタートアップやサービスのレジストリ値を確認する方法です。
図 10では、Daserf がAdobe ARMというファイル名を利用し、スタートアップ時に AdobeARM.exeが実行するよう設定されていることが見て取れます。
Daserf を利用する攻撃者の手口
季節のグリーティングメールに見せかけた標的型メールにファイルを添付し、それを開かせるように誘導してマルウェアに感染させます。
メールの受信者が添付ファイルを開くと、図 16のような Flash アニメーションが現れますが、その裏ではマルウェア ( ダウンローダ ) が実行されることになります。
攻撃者は、クリスマスやお正月というイベントに乗じて標的型メールを送り付けていると見られます。
Microsoft Office の脆弱性であるCVE-2015-2545 を突いた手法も利用されている可能性が高い ...
おわりに
Daserf による被害範囲や漏えいした可能性のあるデータはある程度、特定することができます。事案対応から痕跡として見つかったマルウェアを解析し、マルウェアによって暗号化された通信をデコードすることで特定しますが、そのためにもプロキシサーバの通信ログはもちろん、DNS サーバの通信ログも日常的に記録しておくことを推奨します。加えて、ディスク容量やシステムの負荷などの問題もありますが、通信パケットについてもスイッチングハブやルータのミラーポートを利用して記録しておくとなお良いでしょう。


・標的型攻撃の実態と対策アプローチ日本を狙うサイバーエスピオナージの動向 2018年度下期

https://www.macnica.net/file/mpressioncss_ta_report_2019.pdf
 『
エグゼクティブサマリー
機密情報を窃取するサイバーエスピオナージの被害は、即座に影響が出ない上、技術盗用などの実被害との因果関係が表面化しづらいため、経営者の耳に届かず、現場のマネージャーで処理されてしまうことが多々あります。しかしながら、窃取された機密情報は中国政府や中国企業の手に渡ることで、結果として日本企業の産業競争力を徐々に低下させていくことになります。
2018年度に観測された標的業種と目的
メディア、シンクタンク by APT10, DarkHote: 政治、外交上の機密情報の入手
製造業(主に化学、重工、海洋技術)by Tick, WINNTI, BlackTech: 設計図、製造技術など知的財産の入手
テレコム by Taidoor: 顧客情報、将来の攻撃インフラ情報の入手

RAT Loader
RATローダーは、DLLファイルで、攻撃者によりサービスプログラムとして登録され、rundll32.exe経由で起動する ...
下記パラメータで起動されるものがありました。
rundll32.exe "c:\program files\google\googletoolbarnotifier\5.12.11510.1228\swg32.dll", win7load SCPolicys
このDLL自体はRAT機能を有しておらず、通信先からダウンロードするコードをメモリ上で実行するローダータイプのマルウェアである
TTPsより考察する脅威の検出と緩和策
攻撃について
Officeのゼロデイ攻撃や新しい脆弱性を悪用した攻撃は観測されていませんが、攻撃者の侵入し易さをコントロールするという点で、日常的なパッチマネージメントは有効な緩和策になると思われます
インストールされるRAT、遠隔操作 (C&Cについて)
現在のところ、インシデントレスポンスや脅威の検出においては、攻撃者の変更が難しい (もしくは注意が行き届いていない)と思われる、TickグループDatperのMutex値やUser-Agent値、DragonOKのUser-Agent値などがあり、攻撃者のRATやC&C通信の特徴を利用する事で脅威の検出が可能です
侵入拡大・目的実行
EDRの監視ログを積極的に分析するハンティングにより攻撃が発見されました。
スレットハンティングの必要性
センサーによるパターンドリブンな検出が悪性(Malicious)な攻撃痕跡だけを拾い上げるのに対し、ヒューマンドリブン、つまり人間(アナリスト)による検出は、パターンドリブンなアプローチでは誤検知のリスクがあって検出対象とならない痕跡を、分析対象として積極的に拾い上げることからスタートします。


Jan 31, 2020

SB, NEC 記事

piyokangoさんとこの、まとめ記事リンク

ロシア職員関与と報じられたソフトバンク元社員の社外秘情報持ち出しについてまとめてみた (01/27)


・防衛装備品情報も影響を受けたNECへの不正アクセスについてまとめてみた (01/31)

これも手口が詳らかになれば、大いに参考になる。続報期待案件。プレス発表あり(↓)


当社の社内サーバへの不正アクセスについて (01/31)

 https://jpn.nec.com/press/202001/20200131_01.html
 『 2016/12、初期侵入では検知できなかったが、
   2017/06、感染PCの隔離・調査、不正通信先の検知・遮断、
   2018/07、不正通信の暗号解読し、事実判明』
 検知までに半年余り、解読に一年余り掛かったものの、
 ほぼ状況は制御下にあった、と読める。
 他に未発表/未検出の重大事実が無ければ、封じ込め成功事例と言っても良さそう。
--> 02.01 追記ここから
NECにサイバー攻撃 防衛省関連ファイル約2万7000件に不正アクセス (01/31)
『NECは「不正ログインを受けたことについては18年7月以降、防衛省に説明し了解を得た。NECと防衛省の1対1の話であり、情報が流出した証拠もなく、被害が出ているわけでもないので発表しなかった」と説明した』
 1/31現在で他の重大ニュースに紛れて逃げ切った格好か
 --> 02.01 追記ここまで

ここからは別件。"NEC hack"でググるとSIP PBXのこんな記事が!?(↓)

Best Practices to Avoid Getting Hacked on the NEC SL2100 and SL1100

ベストプラクティスとして、ファイアウォールで分離、関連ポートブロック等が紹介されている。
興味深い。

NEC SV9100 Hacked?

WeChatSkype等の電話的ネットサービスが使いにくい地域では、安価な長距離電話(の転送の)サービス需要があるという事だろうか。

攻撃ツール”SIPVicious”でググると、こんな記事も(↓)

SIP サーバの不正利用に関する注意喚起 (2013/09/06)

  

Jan 23, 2020

メモ、Microsoftが過去14年間・2億5000万件分の露出

Microsoftが過去14年間・25000万件分のカスタマーサービスの記録をネット上に流出させてしまったことが判明 (01/23)


Report: 250 million Microsoft customer service and support records exposed on the web (01/22)


タイムラインは、
『 December 28, 2019 – The databases were indexed by search engine BinaryEdge
December 29, 2019 – Diachenko discovered the databases and immediately notified Microsoft.
December 30-31, 2019 – Microsoft secured the servers and data. Diachenko and Microsoft continued the investigation and remediation process.
Jan 21, 2020 – Microsoft disclosed additional details about the exposure as a result of the investigation.
で、通知~基本対応済まで2日、通知~発表まで約3週間。

Microsoft Security Shocker As 250 Million Customer Records Exposed Online (01/22)


※機械翻訳から抜粋、編集(↓)
『 巨大なテクノロジー企業でさえ、データとストレージを正しく管理することがどれだけ難しいかを示している
他の組織が同様状況に陥ることを、どのように避けられるでしょうか。
データが保存されている環境ではよくある間違い。
セキュリティグループは、誰がどこから(またはどのデバイス)にアクセスできるかを決定するファイアウォールルールを設定します。
これらはすべて、セキュリティグループが意図したとおりに機能するようにするために、定期的に監査する必要がある。
そうでない場合、構成の誤りを検出するメカニズムを導入する必要がある。
構成の誤りが検出された場合は、修正できるようにセキュリティスタッフにすぐに通知する必要がある。

Jan 22, 2020

メモ、三菱電機 情報漏えいの件

--> 01/23追記・編集
piyokangoさんのまとめ(↓)

・ログ消去もされていた三菱電機の不正アクセスについてまとめてみた (01/20~)

https://piyolog.hatenadiary.jp/entry/2020/01/20/172436

まだ報道からは見えてこない、個人的興味は次の三点
①セキュリティ製品のupdateを行っていれば、どの程度拡大を防げたか?
 これだけの規模なら、複数の脆弱性を個々のkill chain突破で段階的に悪用と推察。
 それぞれ、どのような内容だったか?
②三菱関連会社が販売するセキュリティ製品だとどうだったか?
③PCの不審な動作で気づいた、とはどんな動作か?

ラック、企業を狙う標的型攻撃について注意喚起、無償の痕跡調査ツール「FalconNest」の利用を推奨 (01/22)

攻撃対象になりうるドメインコントローラーやサーバーを対象に、FalconNestによる調査を定期的に実施することで、標的型攻撃の痕跡を初期段階で発見できる可能性が高まる...

なお、FalconNestの利用にあたっては、ユーザー登録が必要になる。 』

--> 01/22

・三菱電機へのサイバー攻撃にみる、正確な報道の困難さ (01/21)

https://news.yahoo.co.jp/byline/yamamotoichiro/20200121-00159790/
 本報道検証が分かりやすい。
『その大手メーカーを単独で狙うようなハッキングに対しては無力であり、万全とはとても言えない』と言って経営が納得するか?
『「社内調査に時間がかかった」というより「流出してしまった情報が何であるかすら把握できないぐらい、気づくのが遅れた」ことを意味するならば、この問題を報じる側も相当なリテラシーの高さでないと正確な報道はむつかしいのでは』
不正アクセスの原因となった製品名は「ノーコメント」とする日経BP、
他には「トレンドマイクロ」としている記事も見られます。

・【まとめ】トレンドマイクロ・三菱電機 不正アクセス年表(URL付き) (01/15)

http://blog.livedoor.jp/blackwingcat/archives/1993184.html

 トレンドマイクロが複数回侵入され、脆弱性修正は後手になり、
 (それが決定的かハッキリしないが)三菱電機事件が起きた経過のまとめ

・CVE-2019-18187 Detail (2019/10/28-31)

https://nvd.nist.gov/vuln/detail/CVE-2019-18187
『トレンドマイクロのOfficeScanバージョン11.0およびXG(12.0)は、ディレクトリトラバーサルの脆弱性を利用して、任意のzipファイルからウイルスバスターCorp.サーバー上の特定のフォルダにファイルを抽出する攻撃者によって悪用される可能性があり、リモートコード実行(RCE)につながる可能性があります。 リモートプロセスの実行はWebサービスアカウントにバインドされており、使用するWebプラットフォームによっては、許可が制限されている場合があります。 攻撃を試みるには、ユーザー認証が必要です。
... Base Score: 7.5 HIGH 』(機械翻訳)
HIGH以上のものは原則対応、というのがベストプラクティス。
万一対応できない場合、リスク分析・判断~決裁~次善策 等、どの程度やってたのか?

・ウイルスバスターに脆弱性情報、悪用攻撃が発生 (2019/10/28)

https://japan.zdnet.com/article/35144536/
『管理サーバーにアクセスできるクライアント端末を操作できることも条件 ...
 攻撃者が外部から遠隔で直接的に該当製品のサーバーにあるファイルを変更できるものではない』
でも、ここまでの侵害が起きた。社内のシステム管理PCが先に侵害され、さらにそこに至るための他の侵害もあった、と考えるのが自然だろう。それぞれ公表されれば、大いに参考になると思うのだが。。。
 --> 02/13 追記

・不正アクセスによる個人情報と企業機密の流出可能性について(3報)(02/12)


・複数の Trend Micro 製品におけるパストラバーサルの脆弱性 (2019/09/11)

CVSS v3, v2から抜粋、、
攻撃条件の複雑さ
攻撃前の認証要否不要
攻撃に必要な特権レベル不要
利用者の関与不要


Jan 15, 2020

スマートテレビをNessusでスキャンしてみた

手元のTVをNessusでスキャンしてみた。
SSL関連のものは、オレオレ証明書だったり、暗号強度が不十分だったりで、外との通信に使われない限り、問題視することもないだろう。

他も一つ一つググりながら対策を見ると、『ベンダーからupdate入手・適用せよ』の他に『外部との通信を適切にブロックせよ』というのもあって、「ホームIoTのセキュリティ対策」が必要ですね。

◆その他、関連の読み物

・スマートテレビに犯罪者はどうやって侵入しようとしているのか (2019.12.04)

 具体策、こっち(↓)が参考になった              
・Top tips for protecting your Smart TV (2018/10/01)
機械翻訳 https://translate.google.com/translate?sl=en&tl=ja&u=https%3A%2F%2Fwww.welivesecurity.com%2F2018%2F10%2F01%2Fprotecting-your-smart-tv%2F
1–ルーターの資格情報を保護する
2-ネットワークとデバイスを並べ替える
3-スマートTVの構成
4-最新のアップデートをインストールする
5-完全なセキュリティソリューションを使用する
6-注意してアプリケーションをダウンロードする
7-ストリーミングを注意して使用する

・Androidはウイルスに狙われやすい?必要なセキュリティ対策は? (2019.11.07)

・スマートフォンがマルウェア感染した場合の5つの兆候 (2016.02.16)
 『多くの不正アプリはシステムコンポーネントを偽装する』
 
やはりベンダーさんが「工場出荷時のシステムコンポーネントの一覧」を提供してほしいなぁ。
前述TVはOS Versionでググっても情報が限られているようです。

Jan 13, 2020

Xiaomi端末から不要アプリを削除する

カメラは評判通りの素晴らしさです。これまで私が使ってきた旧世代的スマホでは、こんなに奇麗には撮れませんでした。
なのにbloatwareと呼ぶのもなんですが、アプリの削除について、以下にメモしておきます。
文中のカッコ書き番号は、「参考サイト」で見出し番号から辿れるようにしておきます。

◆準備

Xiaomiデバイスで以下の順に
1.設定→デバイス情報→MIUIバージョンを7回タップ
 すると「今あなたは"開発者"になりました」の旨、表示。

2.設定→システムとデバイス:追加設定→開発者向けオプション
 USBデバッグを On。
 ※途中 MI Cloudの利用は回避

3.適当なVMとデバイスをUSB接続し、
 Xiaomi ADB/Fastboot Tools(*2)を起動。
 ※アンインストーラーにアンインストール可能なリストが現れる

◆アンインストール

いきなりアンインストールは行わず、disableして様子を見る事に。
参考サイト(*1)のアプリが無い事をダブルチェック。

図、残りのEnabledなApp一覧(2/15更新) 
WMServiceもDisableして様子見中。
---> 01/18 追記ここから
Games, Facebook, WPS Office, Netflix も画面タップでアンインストール。

次の無効化済みソフトが、アップデート後 復活していたので、アンインストール
 Mi Video  com.miui.videoplayer
 Weather   com.miui.weather2
---> 01/18 追記ここまで

アンインストールすべきでないものを参考サイト(*4)に書いておいた。

◆disable設定後、トラヒックモニタリング

上位にraspi APを配して、tcpdumpで記録。

・操作とアクセス先
 と言っても偶然その時にアクセスが発生している可能性も残るのですが、、、

  • セキュリティスキャン
  •  05:28:27.911212 IP 9tpro.40576 > 161.117.97.169.443:
  •  05:31:53.863714 IP 9tpro.47980 > 161.117.96.220.443:
  • アプリを管理
  •  05:32:41.040942 IP 9tpro.49908 > 31.13.82.1.443:(edge-star-shv-01-nrt1.facebook.com):
  • テーマ
  •  05:36:13.615951 IP 9tpro.38778 > 47.88.216.202.443:
  • アプリ情報
  •  05:38:51.270767 IP 9tpro.48287 > 172.217.161.74.443: UDP (nrt20s09-in-f10.1e100.net)
  • プライバシーポリシー
  •  05:44:45.376614 IP 9tpro.38920 > 172.217.25.106.443: (nrt13s51-in-f106.1e100.net)
  • SIM挿入
  •  05:50:49.604603 IP 9tpro.38930 > 172.217.25.106.443: (nrt13s51-in-f106.1e100.net)
  • システムアプリアップデーター
  •  05:55:08.934297 IP 9tpro.37536 > 47.74.233.137.443:
  • 壁紙 
  •  05:59:12.892563 IP 9tpro.38990 > 47.88.216.202.443: 
  • 壁紙
  •  05:59:12.893150 IP 9tpro.47566 > 103.208.1.44.80: 
  • SIM挿入&指紋追加登録後の電源オフ→オン時
  •  06:02:57.562357 IP 9tpro.42352 > 161.117.71.89.443:   
  • SIM挿入&指紋追加登録後の電源オフ→オン時
  •  06:02:59.997131 IP 9tpro.37478 > 47.74.170.156.5222:  
  • Gmail設定
  •  06:44:30.442075 IP 9tpro.41684 > 172.217.25.77.443:
 名前解決(逆引き)したdestination host名をカッコ書きした。
 逆引きが定義されていないdestinationが多い。
 06:02:59に発生したport:5222へのアクセスも気味悪い。

・名前解決
 手元のデバイスがdnsに照会したリストと件数(Xiaomi関連のみ抜粋)
  1 t3.market.mi-img.com.
  1 thm.market.intl.xiaomi.com.
  2 sa.api.intl.miui.com.
  3 find.api.micloud.xiaomi.net.
  4 privacy.mi.com.
  7 t5.market.mi-img.com.
  8 api.zhuti.intl.xiaomi.com.
  8 global.market.xiaomi.com.
  8 www.miui.com.
30 api.ad.intl.xiaomi.com.
40 data.mistat.intl.xiaomi.com.

 最後の「40」のサイトへは
 数分おきに HTTPS CONNECTメソッドで通信している。

 Gmail アカウント設定後に三度、HTTP POSTメソッドもやらかしている。

 対処については、参考サイト(*3)に詳しいが、今日はここまでとしておきます(01/13)

◆参考にしたところ、一覧

https://akasaka-taro.blogspot.com/2020/01/xiaomi.html

Jan 4, 2020

Xiaomi端末から不要アプリを削除する為の参考サイト

手順まとめ(↓)
Xiaomi端末から不要アプリを削除する (2020/01/13)

以下、対象アプリ、ツール等の参考サイトメモ

*1 Preinstalled Malware

・Preinstalled Malware Targeting Mobile Users
 https://blog.checkpoint.com/2017/03/10/preinstalled-malware-targeting-mobile-users/ 
 
The malicious apps were not part of the official ROM supplied by the vendor, and were added somewhere along the supply chain.
Six of the malware instances were added by a malicious actor to the device’s ROM using system privileges, meaning they couldn’t be removed by the user and the device had to be re-flashed.
… snip …
Xiaomi Redmi : com.yongfu.wenjianjiaguanli
Xiaomi Mi 4i : com.sds.android.ttpod

・マルウェア警告:ほとんどの40スマートフォンにプリインストールされています (2017/11)
 https://ja.xiaomitoday.it/allerta-malware-preinstallato-su-quasi-40-smartphone.html

・Vulnerability in Xiaomi Pre-Installed Security App (2019.04.04)
   it was the pre-installed security app,Guard Provider (com.miui.guardprovider) ...
Briefly put, due to the unsecured nature of the network traffic to and from Guard Provider, a threat actor could connect to the same Wi-Fi network as the victim and carry out a Man-in-the-Middle (MiTM) attack. Then, as part of a third-party SDK update, he could disable malware protections and inject any rogue code he chooses such to steal data, implant ransomware or tracking or install any other kind of malware.

Check Point responsibly disclosed this vulnerability to Xiaomi, which released a patch shortly after.


・Xiaomi Mi 9 いろいろ
 https://akasaka-taro.blogspot.com/2019/08/xiaomi-mi-9.html
https://bey.jp/?p=37414adups(バックドアを仕掛けている会社)のIPアドレスは(略)』 
https://forum.xda-developers.com/redmi-note-3/help/discussions-plz-dev-look-analyst-t3463321AnalyticsCore.apk = com.miui.analytics』

サイトの中には、ショッキングな見出しも有る気もするが、心配になってきたので、不要なプリインストールソフトは削除しておこう、と考えた次第。

*2 Xiaomi ADB/Fastboot Tools

アンインストールの為のツールと、アンインストール対象アプリについて

・Androidでプリインストールアプリを強制的に削除する方法! 消せない標準ソフトもアンインストール/無効化できる (2018/09/04-2019/05/30)
 https://sp7pc.com/google/android/31027#toc1

・Androidアプリのパッケージ名を調べる方法! Google PlayやapkのアプリケーションID確認しよう (2018/05/26-2019/05/26)
 https://sp7pc.com/google/android/31029

・Xiaomiデバイスでシステムアプリをアンインストールする方法(ルートなし)(2019/11/04)
 https://ja.xiaomitoday.it/come-disinstallare-app-di-sistema-su-dispositivi-xiaomi-no-root.html
 削除アプリ例が豊富。ADBで削除する際、便利そうなコマンド一覧もある。
 この方が標準的アプリの削除対象としているのは、次の通り。
>find "pm " tmp-web.txt | find /v ".xiaomi." | find /v ".miui." | find /v ".mi" 
---------- TMP-WEB.TXT
pm uninstall -k-ユーザー0 com.android.browser
pm uninstall -k-ユーザー0 com.android.calendar
pm uninstall -k-ユーザー0 com.android.email
pm uninstall -k --user 0 com.android.soundrecorder
pm uninstall -k --user 0 com.google.android.apps.docs
pm uninstall -k --user 0 com.google.android.gm
pm uninstall -k-ユーザー0 com.google.android.music
pm uninstall -k-ユーザー0 com.google.android.videos
pm uninstall -k-ユーザー0 com.google.android.apps.photos
pm uninstall -k-ユーザー0 com.google.android.marvin.talkback
pm uninstall -k --user 0 com.facebook.appmanager
pm uninstall -k --user 0 com.facebook.services
pm uninstall -k --user 0 com.facebook.system
ここまでやるか。


More apps to remove #69 (2019/09/11)
さらに削除可能なアプリ例
WMService is some kind of analytics thing.
Weather is useless if you remove their default widget and don't use the Weather app.

『 "Gallery;com.miui.gallery",                      
 "WMService;com.miui.wmsvc",
 "Weather;com.miui.weather2",
 "NextPay;com.miui.nextpay",
 "MiSound;com.miui.misound",
 "MiPlayClient;com.xiaomi.miplay_client",
 "mi_connect_service;com.xiaomi.mi_connect_service",
 "XiaomiAccount;com.xiaomi.account"


・New Removable and Non-Removable Bloatware in MIUI 11 (2019.11)
 https://www.reddit.com/r/Xiaomi/comments/dseq28/new_removable_and_nonremovable_bloatware_in_miui/

・How to get rid of the Mi Bloatware pre-installed without flashing/root? (2019/09/29)
 https://forum.xda-developers.com/k20-pro/help/how-to-rid-mi-bloatware-pre-installed-t3975121
 com.google.android.musicまでもアンインストール。
 そこまでするかなぁ。参考リスト的に挙げておく。

・Xiaomi端末の便利な管理ツール「Xiaomi ADB/Fastboot Tools」(2019/09/19)
 https://ahogehopping.hatenablog.com/entry/xiaomi-adb-fastboot-tools

・Szaki/XiaomiADBFastbootTools
 https://github.com/Szaki/XiaomiADBFastbootTools

一応チェックすると、
https://www.virustotal.com/gui/url/a3616b17f297ef3ecbf764644b71394b297124d0ee141fd7797c22af8bcbe6b5/detection   unratedな6件を除き、目下 100%のベンダーで clean との評価 

*3 その他

事後策など

・Calls Home.. (to The Maintainers) (2018/03/22)
 https://xiaomi.eu/community/threads/calls-home-to-the-maintainers.43699/
 data.mistat.intl.xiaomi.com と ccc.sys.miui.com への定期通信を止める。
 Netguard(rootの要らないfirewall app)の紹介と、
 hostsファイルへの書き込みアイデア。参考になります。

*4 アンインストールすべきでないApp

・「セキュリティ~」はアンインストールするとブート時に無限ループするとの記載が多い

「パッケージインストーラー安易にアンインストールするべからず。

Disabled package installer, stuck in bootloop (2017/08/25)

How do I disable App Vault in MIUI? (2018/08/09)

ここに記載の「アプリ保管庫」は無効化しようとすると、「アップデートの受信ができなくなる」旨の警告表示。有効なままにして思案中。
--> 12.02追記

・Power detector: com.xiaomi.powerchecker は削除しない
Xiaomi Super bloatware List 2020
https://lucacesarano.medium.com/xiaomi-super-bloatware-list-2020-db38ace9e9e1
『But since this is Miui and there are eternal troubles, with the application settings configured in the background. I will not touch and do not advise you.』

・System Apps Updater: com.xiaomi.discover は削除しない
Debloating (removing bloatware) applications from MIUI
https://devcondition.com/article/removing-unneeded-miui-applications/
『URGENT CLEAR_DATA + FREEZ com.xiaomi.discover System app updater Gizmo, for updating, first of all, MIUI applications: browser, downloads, notes, etc., etc. But it can hook other applications. Decide for yourself. I do not delete, but FREEZe. Periodically including, to check for updates.』

・Battery & performance: com.miui.powerkeeper



Jan 3, 2020

Windows7 や2008のESU (Extended Security Updates)について

◆正攻法

こちら
 ↓
・Windows7 ESUのアクティベーション方法が公開されていました (2019/12/18)
 http://mitomoha.hatenablog.com/entry/2019/12/18/013521

元記事はこちら
 ↓
・How to get Extended Security Updates for eligible Windows devices (2019/10/17)
 https://techcommunity.microsoft.com/t5/windows-it-pro-blog/how-to-get-extended-security-updates-for-eligible-windows/ba-p/917807

◆0patchのmicropatch

・0patch、Windows 7/Server 2008のサポート終了後もサードパーティーパッチを提供する計画 (09/22)
 https://security.srad.jp/story/19/09/22/1037218/

『0patchのマイクロパッチは常駐プログラム「0patch Agent」により、実行中のプロセスに対して直接適用される。パッチ適用に再起動は必要なく、適用の有無も切り替え可能だ。』
と、『仮想パッチ記事』よりも、動作原理が明快に示されている点は好印象。
安定性や、ライセンス上問題無いのか、これからの記事を待つ。

『0patchのパッチ作成計画としては、Windowsの月例更新に合わせて出されるMicrosoftのセキュリティアドバイザリからWindows 7/Server 2008にも適用されそうな脆弱性を特定し、Windows 10の更新プログラムの変更部分から同じコードがWindows 7/Server 2008にも存在するかどうかを確認する。あとはPOCの収集とマイクロパッチの作成を行い、POCによるテストとその他の副作用に関するテストを経てパッチをリリースするとのこと。』

本家はこちら
 ↓
・0patch
 https://0patch.com/

MS17-010の頃 既に、こんな記事も
 ↓
 https://twitter.com/0patch/status/864819472615571456
『We've just produced a micropatch for #shadowbrokers EsteemAudit! Organizations with Windows Server 2003 and Windows XP, we got your back.』

ホームIoTのセキュリティ対策

◆目的

1.自宅で TV、スマホ、PC、その他まとめて Sophos UTMの傘で保護。
2.直結ISPやマンションのスーパーマニアからのプライバシ保護(クラウドSPからの保護は残課題)。

◆環境

こんな環境整備をやってみた。



◆前提

1. ラズパイ起動時に、Sophos UTMとの間で、SSL-VPNセッションを自動的に確立し、
 ラズパイがSSL-VPNクライアントとして動作済みとします。
関連
・OpenVPN linux client automatically at boot、メモ
 https://akasaka-taro.blogspot.com/2019/12/openvpn-linux-client-automatically-at.html

2. さらにラズパイををAccess Point化して
 各ホームデバイスからインターネットアクセス可能とします。
関連
・raspberry pi を access point 化 (2018/01/09)
 https://akasaka-taro.blogspot.com/2018/06/raspiap.html
3. ラズパイに有線LANアダプタを追加、eth1として稼働済みとします。
 TVは やはり有線接続することにしました。
関連
・有線LANアダプタ、ラズパイ(Debian系)用
 https://akasaka-taro.blogspot.com/2020/01/landebian.html

◆起動スクリプト

『前提』が整ったら、残るはmasquerading等の設定。
raspberry pi を access point 化』でも触れた起動スクリプトを、以下の通り変更。

iw phy0 interface add mon0 type monitor; ifconfig mon0 up

dnsmasq --interface=eth1  --except-interface=lo --bind-interfaces --dhcp-range=$DHCP-ETH01,12h --server=$DNS-ETH01

dnsmasq --interface=wlan0 --except-interface=lo --bind-interfaces --dhcp-range=$DHCP-WLAN0,12h --server=$DNS-WLAN0

sudo sh -c "echo 1 > /proc/sys/net/ipv4/ip_forward"

iptables -t nat -A POSTROUTING -o tun0 -j MASQUERADE

iptables -A FORWARD -i tun0  -o wlan0 -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A FORWARD -i wlan0 -o tun0  -j ACCEPT

iptables -A FORWARD -i tun0  -o eth1  -m state --state RELATED,ESTABLISHED -j ACCEPT
iptables -A FORWARD -i eth1  -o tun0  -j ACCEPT

sudo sh -c "iptables-save > /etc/iptables.ipv4.nat"

sysctl -w net.ipv6.conf.all.disable_ipv6=1 && sysctl -w net.ipv6.conf.default.disable_ipv6=1

/usr/sbin/route add    -net $UTM-NET gw $MANSION-ROUTER eth0
/usr/sbin/route delete default gw $MANSION-ROUTER eth0
/usr/sbin/route add    default gw $SSL-VPN-ADDR-IN-UTM tun0

cat /etc/resolv.conf.new > /etc/resolv.conf

※上記変数について
$DHCP-ETH01: ケーブル接続クライアント向けにeth1で割り当てるDHCPレンジ
$DNS-ETH01: 上記レンジのDNSサーバIP
$DHCP-WLAN0: Wi-Fiクライアント向けにwlan0で割り当てるDHCPレンジ
$DNS-WLAN0: 上記レンジのDNSサーバIP
$MANSION-ROUTER: マンションの(直結・上位の)ルータIP
$SSL-VPN-ADDR-IN-UTM: UTM自身に割り当てられたSSL-VPNのIP

◆その他、追加設定

/etc/resolv.conf が書き換わらないようにする(今回の環境では、dnsmasqのDNS設定がクライアントに反映されるので、必須でもないのだが、念のため)。

1. # vi /etc/NetworkManager/NetworkManager.conf
[main]
plugins=ifupdown,keyfile
dns = none # この行を追加

2. # systemctl restart NetworkManager

参考
・[RHEL7]/etc/resolv.conf 強制上書き無効 (2017/10/20)
 https://qiita.com/a-hiroyuki/items/559ccde6d948d31af939