Dec 29, 2021

Log4j スキャナー

すでに色々出てるのでメモ。

CISAやCrowdStrike、「Log4j」向けスキャナーを提供--限界があるとの指摘も (12/24)

https://japan.zdnet.com/article/35181344/

『最大の課題は、本番環境にあるパッケージソフトウェア内のLog4Shellを検出することだ。(Log4jのような)Javaファイルは、その他のファイルの何層か下にネストされていることがあり、浅い検索では見つけられない』


CISAのスキャナー(↓)は、リモートスキャンも出来るみたい。

cisagov/log4j-scanner (12/21-28)

https://github.com/cisagov/log4j-scanner

手元でフルアップデート済みのものに試してみた(当然、何も出なかった)。
CUIだが、使いやすいし、表示も分かり易い。




Dec 23, 2021

Log4jのヤバさ

まず、Log4jのヤバさを会話形式で易しくまとめた記事(↓)

「Log4j」のトラブルってどうヤバいの? 非エンジニアにも分かるように副編集長に解説させた (12/16)

https://www.itmedia.co.jp/news/articles/2112/16/news128.html


piyokangoさんの硬派な まとめ(↓)

Log4jの深刻な脆弱性CVE-2021-44228についてまとめてみた (12/13)

https://piyolog.hatenadiary.jp/entry/2021/12/13/045541

『.. 既にサポートが終了している1.xバージョンも脆弱性の影響を受けることが検証で確認されている*3が予め構成を変更している必要があり、2.xと比較して相当にリスクは低い..』

だそうだ。さらに幾つか興味本位でピックアップ(↓)

・Red Hat
 https://access.redhat.com/security/vulnerabilities/RHSB-2021-009

『The following products are NOT affected by this flaw and have been explicitly listed here for the benefit of our customers.

    ・Red Hat Enterprise Linux

    ・Red Hat Advanced Cluster Management for Kubernetes 

 (注、その他 多数)

』 

な一方で

Technical summary

A flaw was found in the Java logging library Apache Log4j in versions from 2.0.0 and before 2.15.0. A remote attacker who can control log messages or log message parameters can execute arbitrary code on the server via the JNDI LDAP endpoint. Refer to CVE-2021-44228 for more details.

Mitigation

For Log4j versions 2.10 and later:

  • set the system property log4j2.formatMsgNoLookups or the environment variable LOG4J_FORMAT_MSG_NO_LOOKUPS to true

For Log4j versions between 2.7 and 2.14.1:

  • all PatternLayout patterns can be modified to specify the message converter as %m{nolookups} instead of just %m

For Log4j versions between 2.0-beta9 and 2.10.0:

  • remove the JndiLookup class from the classpath. For example: 

zip -q -d log4j-core-*.jar org/apache/logging/log4j/core/lookup/JndiLookup.class

On OpenShift 4 and in OpenShift Logging, the above mitigation can be applied by following the steps in this article: https://access.redhat.com/solutions/6578421

On OpenShift 3.11, mitigation to the affected Elasticsearch component can be applied by following the steps in this article: https://access.redhat.com/solutions/6578441

とも。

 

・Oracle
 Oracle Security Alert Advisory - CVE-2021-44228

・VMware
 https://www.vmware.com/security/advisories/VMSA-2021-0028.html

VMware Horizon, vCenter Server, HCX, NSX-T Data Center, vCenter Cloud Gateway .. その他多数

 

・IBM
 https://www.ibm.com/support/pages/node/6525706

Affected Products and Versions
WebSphere Application Server 9.0
WebSphere Application Server 8.5

元IBM製品に、こんなのもあったな(↓)

・HCL Technologies

Log4J 2 / Log4Shell の脆弱性に関するNotes、Domino、Verse、Traveler への影響 (CVE-2021-44228、CVE-2021-45046、CVE-2021-45105、CVE-2021-44832)
https://support.hcltechsw.com/csm?id=kb_article&sysparm_article=KB0095594


・Fortinet

 https://www.fortiguard.com/psirt/FG-IR-21-245

 Tuesday December 15, 8:50 PM Pacific Time現在、下記状況

『The following products are NOT impacted:

 .. FortiOS (includes FortiGate & FortiWiFi) .. 

The following products are impacted and fixes are being worked on. This advisory will be updated as soon as ETAa are available:

FortiAIOps - Fixed in version 1.0.2
FortiAnalyzer BigData - Fixed on 2021-12-10 in 6.4.7 & 7.0.2
FortiCASB - Fixed on 2021-12-10
FortiConverter Portal - Fixed on 2021-12-10
FortiCWP - Fixed on 2021-12-10
FortiEDR Cloud - Not exploitable. Additional precautionary mitigations put in place on 2021-12-10
FortiInsight - Not exploitable. Additional precautionary mitigations being investigated.
FortiIsolator - Fix scheduled for version 2.3.4
FortiMonitor - Mitigations for NCM & Elastiflow available
FortiPortal - Fixed in 6.0.8 and 5.3.8
FortiSIEM - Mitigation available
ShieldX - Fix scheduled for versions 2.1 and 3.0 - ETA 2021/12/17


・AMD

 https://www.amd.com/en/corporate/product-security/bulletin/amd-sb-1034

『Currently, no AMD products have been identified as affected.』


・Intel

 https://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-00646.html

Datacenter Manager, Secure Device Onboard, Computer Vision Annotation Tool, Optimized Analytics Package, Intel QAT Codec, Edge Insights for Autonomous Mobile Robots, oneAPI各種 

.. Clear Linux Project」なんてのもあるんですね。

.. 他にも多数。意識せず使ってたって事もあるかも。ご自分で確認されたし。

 

・NVIDIA 

 https://nvidia.custhelp.com/app/answers/detail/a_id/5294

 01/04現在で、

Remediated NVIDIA Products 

The following sections list the NVIDIA products affected, versions affected, and the updated versions  available or mitigations that require customer action.

  CUDA Toolkit Visual Profiler and Nsight Eclipse Edition
  DGX Systems
  NetQ
  vGPU Software License Server


・Palo Alto Networks

 https://security.paloaltonetworks.com/CVE-2021-44228

『We have determined that some configurations of Panorama appliances with PAN-OS 9.0, PAN-OS 9.1, and PAN-OS 10.0 are impacted by CVE-2021-44228 and CVE-2021-45046 through the use of Elasticsearch. Fixes were released on December 20, 2021 to address both vulnerabilities on impacted PAN-OS versions. Panorama appliances are not impacted by CVE-2021-45105. 

 PAN-OS for Panorama < 9.0.15, < 10.0.8-h8, < 9.1.12-h3  .. affected

 Exact Data Matching CLI < 1.2 .. affected


Oct 9, 2021

memo: SAPFPAYM output to file system

あたりから気になったものを、いくつか下にピックアップした。

Positive Pay file creation using Payment Medium Workbench(PMW) and Automatic Payment Program(F110) (2019/09/17)


Henri LOISEAU Feb 01, 2010 at 12:52 PM
 ・・・
In OBPM4 you define which variant of program SAPFPAYM you are using. 
In the parameters of program SAPFPAYM you have a checkbox 'Output to the file system' (PAR_XFIL) 
and you can give the filename (PAR_FILE).
I want to donwload Payment File using program SAPFPAYM using a background job. I want to download file to specified folder in a server.

Already set :Run Date, Identification, Payment Medium Format, Electronic file.

I check the "output to file system" check box and already specify the folder directory and file name.

While I execute it, file not directly downloaded to specific folder. It appear in DME administration and the status already exported 
・・・

Best Answer
Former Member Apr 09, 2012 at 09:37 AM
・・・
1.In F110,one tab "print program"is thr,here we can define variant with program "ZRFFOUSC",at the time of creating variant one field option"payment summary",check this entry and along this it also ask for on which printer we want this entry.

2.Last time i got similar type of issue when i was not able to download the file because some msoffice version update version problem.Try with first create one folder in particular location and then give the path(mention ur new created folder thr).
・・・

Former Member Apr 05, 2012 at 06:26 AM

For that issue, you need to specify the file place in F110 print variant.

Go to F110 transaction > Select the relevant payment run and ID> Go to printout data medium tab> Select variant and press Maintain variant button> check the Output control tab and file name path.

Change layout of payments summary 2014/02/24

↑ スクショ豊富。今、探しているイメージとは異なるが、メモ代わりに。

Testing and recreation of the Electronic payments file for the Bank 

↑ 全体を俯瞰しやすい。

Payment Medium Creation のスクショ ↓ 





Sep 25, 2021

2021年 データ侵害のコストに関する調査レポート (IBM Security) ほか

2021年データ侵害のコストに関する調査レポート (IBM Security)

https://www.ibm.com/downloads/cas/RBANYX1Q

462万ドル: ランサムウェアによるデータ侵害にかかる平均総コスト (p.8)

ランサムウェアや破壊的な攻撃は、 他のタイプのデータ侵害よりもコスト がかかりました。

ランサムウェア攻撃に伴うコストは平均462万ドルで、平均的なデータ侵害時のコスト(424万ドル)よりも高額です。これらのコストには、エスカレーション、通知、損失したビジネス、対応にかかるコストなども含まれていましたが、ランサムウェアの身代金コストは含まれていませんでした。ワイパー型の悪意のある攻撃でデータが破壊された場合のコストは平均469万ドルです。ランサムウェアがデータ侵害の要因となった企業の割合は7.8 %でした。 


424万ドル: データ侵害にかかる世界の平均総コスト (p.11)

データ侵害の平均総コストは、7年間で大幅に増加しました。

2021年のレポートを2020年のレポートと比較すると、データ侵害のコストは 2020年の386万ドルから2021年の424万ドルへと大幅に増加しています。38万ドルの増加は、9.8%の増加に相当します。これに対し、2019年から2020年のレポートを見ると、データ侵害にかかるコストは1.5%減少しています。データ侵害のコストは、2015年以降で11.9%増加しました。


金融サービスの機密データ侵害 (p.56)

財務損失の規模: 特定の銀行がランサムウェアの攻撃を受けるセキュリティー・リスクの数値化は、その銀行の強固なセキュリティー管理を鑑み、イベントが発生する確率が30%であることを示しています。平均的な財務損失は1,890万ドルで、これは対応コスト、ビジネスの損失、規制上の罰金で構成されています。


国または地域別のデータ侵害にかかる平均総コスト (p.14)

データ侵害にかかる平均総コストの上位5か国と地域は、以下の通りでした。

    1. 米国   $8.64M → $9.05M (左:2020 → 右:2021。以下同様)
    2. 中東   $6.52M → $6.94M
    3. カナダ  $4.50M → $5.40M
    4. ドイツ  $4.45M → $4.89M
    5. 日本  $4.19M → $4.69M

2020年のレポートでも、上位 5か国はこの5か国で、順位も同じでした。


業界別データ侵害の平均総コスト (p.15)

  • 医療/ヘルスケア $9.23M
  • 製造  $4.24M


侵害されたレコードのタイプ  各カテゴリーでデータを含む侵害の割合 (p.17)

  • 顧客の個人情報 44%
  • 匿名化された顧客データ 28%
  • 知的財産  27%
  • 従業員の個人情報  26%
  • その他の機密性の高いデータ  12%


侵害されたデータのタイプ別レコード当たり平均コスト (p.18)

  • 顧客の個人情報 $180M
  • 従業員の個人情報  $176M
  • 知的財産  $169M
  • その他の機密性の高いデータ  $165M
  • レコード当たりのグローバル・コスト  $161M
  • 匿名化された顧客データ  $157M


バラクーダの注目する脅威「ランサムウェアの傾向」について調査結果を発表

〜ランサムウェアのインシデントは、前年比64%増加し、身代金要求額も増加傾向に〜 (08/23)

バラクーダネットワークスジャパン株式会社・・・は、2020年8月から2021年7月の間に発生したランサムウェア攻撃を分析しました。

ハイライト: 

  • 過去12ヶ月間にバラクーダの調査担当者が確認および分析したランサムウェアのインシデントは121件で、前年比で64%増加。
  • インフラ、旅行、金融サービスなどを含む企業への攻撃は、ランサムウェア攻撃全体の57%を占める。
  • 身代金要求額が1,000万ドル未満のインシデントはわずか18%で、3,000万ドル以上のインシデントは30%
  • ランサムウェアの攻撃は世界中に拡大


今週のセキュリティニュース - 2021年8月27日 

https://www.cloudgate.jp/security-news/weekly-20210827.html


関連

サイバー身代金、支払い5割 金額急増し攻撃に拍車 (09/25)

https://akasaka-taro.blogspot.com/2021/09/5.html


サイバー身代金、支払い5割 金額急増し攻撃に拍車

1社あたり平均ランサム支払額。上半期で約6千万円に。このペースだと、『近年 指数関数的増加』とも言えそう。

欧米は、ランサム支払に応じる場合が多い(↓)。

日本が突出して支払いに応じないのは、どういった事情だろうか? 『応じれば、ますます日本中がターゲットにされるので、断固拒否』と言えば聞こえは良いが、実態は、社内政治の結果 日経に支払い申告するに至らなかった? 予算無し、人員無し、復旧作業残業代無し、責任問題恐怖感マシマシで疲弊する現場を想像してもやっとする。


出典

サイバー身代金、支払い5割 金額急増し攻撃に拍車 (09/20)

https://www.nikkei.com/article/DGXZQOUC107FU0Q1A610C2000000/


関連

FBI IC3 ネット犯罪報告書 (03/23)

https://akasaka-taro.blogspot.com/2021/03/fbi-ic3.html

こちら(↑)は、一般ユーザも含めた全体的傾向の記事。


Aug 7, 2021

Podcast for IT Security / English

 朝起きて朦朧としている間、podcastで英語耳をウォームアップするのが日課である。以下、最近のお気に入りをご紹介。これらの多くは、Transcriptが用意されていて、後で内容チェックできるのも、嬉しい。


1.Cyber Security Today

https://www.itworldcanada.com/podcasts#cyber-security-today

Howardがゆっくりしゃべってくれるので、朝一番の耳慣らしに丁度良い。


2.WSJ Tech News Briefing

https://www.wsj.com/podcasts/tech-news-briefing

音声は、右の「Google Podcasts」から、直近3週間分程のリストで、選べる。


3.Cyber Security Headlines

https://cisoseries.com/subscribe-podcast/

これはPodcast版のみで、トランスクリプトも無いようだ。
こっち↓に、vodcast があるので、時間が有る時は眺めてみる事にする。
https://www.crowdcast.io/cisoseries


4.CyberWire Daily

https://thecyberwire.com/podcasts/daily-podcast

昔は主に これだけを聞いていたが、次第に他の IT Security系podcastも聞くようになった。それは次の理由である。

・同様のニュース数分を、違う言い回しで複数の人から聞くのが、私には効率的と思われる事が一つ。
・the cyberwire daily版は 20分超で、後半の著名人インタビューは集中が続かない事が一つ。


➄番外編 Hak5 ThreatWire 

https://www.youtube.com/watch?v=5ofYqjC1s40&list=PLW5y1tjAOzI0Sx4UU2fncEwQ9BQLr5Vlu

私のWebを見ている人なら、ご存じの方も多いだろう。
Shannonちゃんのvodcastで、ほのぼのするのもお薦めです。


6.#セキュリティのアレ

https://www.tsujileaks.com/


7.バイリンガルニュース

https://ja.wikipedia.org/wiki/%E3%83%90%E3%82%A4%E3%83%AA%E3%83%B3%E3%82%AC%E3%83%AB%E3%83%8B%E3%83%A5%E3%83%BC%E3%82%B9


過去記事

Podcasts for bleeding-edge security (2019/03/07)

https://akasaka-taro.blogspot.com/2019/03/podcasts-for-bleeding-edge-security.html


Aug 4, 2021

Zoomの暗号化、エンドツーエンドでは無かった? FB, Googleに無断情報共有も!?

 ビジネスユーザにとって『安全な通信』は必須条件。経営陣が理解していないとしたら、まずい。同社の先日発表の決算は良かったようだが、さて、世間にはどう評価されるか。


Zoomのプライバシーと「Zoom爆撃」めぐる集団訴訟、約93億円で和解へ (08/03)

https://japan.cnet.com/article/35174700/

『Zoomは、ユーザーの同意を得ることなく個人情報をFacebook、Google、LinkedInと共有していたことや、ハッカーらが「Zoom爆撃」によってオンラインミーティングを妨害する行為を放置していたことが、ユーザーのプライバシー侵害にあたるとして起こされていた集団訴訟について、8500万ドル(約93億円)の和解金を支払うことで合意した。

 ・・・

 この和解に伴い、集団訴訟の対象となる顧客には、サブスクリプション料金の15%または25ドルが返金される可能性がある。』

お詫びに一部の利用料金を返金します、と言われても失われた情報は取り返せない。


Zoom to pay $85M for lying about encryption and sending data to Facebook and Google (08/02)

https://arstechnica.com/tech-policy/2021/08/zoom-to-pay-85m-for-lying-about-encryption-and-sending-data-to-facebook-and-google/

『Zoomは、エンドツーエンド暗号化の提供について嘘をついたという主張を解決するために8500万ドルを支払うことに同意

・・・

2021年5月に提出された修正集団訴訟の苦情は、Zoomがエンドツーエンド(E2E)暗号化を誤って約束したにもかかわらず、「各会議の暗号化キーは、クライアントデバイスではなくZoomのサーバーによって生成される」と述べています。』

つまり事業者が中間者として通信内容を解読できる、との主張である。