2008年7月14日

[openoffice:11179] DNS ¥­¥ã¥Ã¥·¥å¥Ý¥¤¥º¥Ë¥ó¥°

¤É¤¦¤â¡£¤³¤ó¤Ë¤Á¤Ï¡£
¥»¥­¥å¥ê¥Æ¥£¤Í¤¿¤Ç¤¹¡£

¤¹¤Ç¤Ë¤´Â¸ÃΤÎÊý¤â¿¤¤¤Î¤Ç¤Ï¤Ê¤¤¤«¤È»×¤¤¤Þ¤¹¤¬¡¢
¤è¤ê°ÂÁ´¤ÊÂкö¤Î¤¿¤á¤Ë¤È»×¤¤¡¢¤´°ìÊ󤤤¿¤·¤Þ¤¹¡£

==============================================================================

DNS (Domain Name System) ¤Ë¤ª¤±¤ëÀȼåÀ­¡Ê¤­¤¸¤ã¤¯¤»¤¤¡Ë¤Ë´Ø¤¹¤ë
·Ù¹ð¤¬½Ð¤Æ¤¤¤Þ¤¹¤Î¤Ç¡¢Å¬µ¹¡¢É¬ÍפÊÂбþ¤ò¤Ê¤µ¤ì¤ë¤È¤è¤¤¤«¤È»×¤¤¤Þ¤¹¡£

Windows ¤Ë¤ª¤¤¤Æ¤Ï¡¢Microsoft Update ¤ÎŬÍÑ¡£
Linux ¤Ê¤É¤Ë¤ª¤¤¤Æ¤Ï¡¢bind ¤Î¥Ð¡¼¥¸¥ç¥ó¥¢¥Ã¥×¡¢¤ª¤è¤Ó¡¢
¤½¤Î¸å¤ÎÀßÄêÊѹ¹¤Ê¤É¤¬¿ä¾©¤µ¤ì¤Æ¤¤¤ë¤è¤¦¤Ç¤¹¡£

Ê£¿ô¤Î DNS ¥µ¡¼¥ÐÀ½Éʤˤª¤±¤ë¥­¥ã¥Ã¥·¥å¥Ý¥¤¥º¥Ë¥ó¥°¤ÎÀȼåÀ­
http://www.jpcert.or.jp/at/2008/at080013.txt

Microsoft MS08-037
DNS ¤ÎÀȼåÀ­¤Ë¤è¤ê¡¢¤Ê¤ê¤¹¤Þ¤·¤¬¹Ô¤ï¤ì¤ë (953230)
http://www.microsoft.com/japan/technet/security/bulletin/MS08-037.mspx

==============================================================================

¤É¤Î¤è¤¦¤Ê´í¸±¤¬¤¢¤Ã¤¿¤«¤È¹Í¤¨¤Æ¤ß¤Þ¤¹¤È¡¢Î㤨¤Ð¡¢°Ê²¼¤Î¤è¤¦¤Ê URL ¤«¤é
OpenOffice.org ¤Î¥¤¥ó¥¹¥È¡¼¥é¡¼¤ò¥À¥¦¥ó¥í¡¼¥É¤·¤è¤¦¤È¤·¤Æ¤¤¤ë¤È¤·¤Þ¤¹¡£
http://www.xxx.yyy.jp/openoffice/localized/ja/2.4.1/OOo_2.4.1_LinuxIntel_install_wJRE_ja.tar.gz

¤³¤Î www.xxx.yyy.jp ¤È¤¤¤¦Ê¸»úÎ󤫤顢¥¤¥ó¥¿¡¼¥Í¥Ã¥È¾å¤ÎIP¥¢¥É¥ì¥¹¤Ø
ÊÑ´¹¤¹¤ëµ¡¹½¤È¤·¤Æ DNS ¤¬¤¢¤ê¤Þ¤¹¡£¤³¤Î DNS ¾å¤Î¥Ç¡¼¥¿¤ò±øÀ÷¤¹¤ë¡Êº¹¤·
ÂØ¤¨¤ë¡Ë¤³¤È¤¬Èæ³ÓÅªÍÆ°×¤Ë¤Ç¤­¤Æ¤·¤Þ¤Ã¤Æ¤¤¤¿¤È¤¤¤¦ÀȼåÀ­¤Î¤è¤¦¤Ç¤¹¡£

www.xxx.yyy.jp ¤¬Áê¼êÀè¤Î²ñ¼Ò̾¤È¤·¡¢IP¥¢¥É¥ì¥¹¤¬¤½¤Î²ñ¼Ò¤ÎÌä¹ç¤»¤Î
ÅÅÏÃÈֹ桢ÅÅÏÃÈÖ¹æ°ÆÆâ¤¬ DNS ¤À¤Èª¤¨¤Æ¤ß¤Æ¤¯¤À¤µ¤¤¡£

ÅÅÏÃÈÖ¹æ°ÆÆâ¤ÇÁê¼êÀè¤Î²ñ¼Ò¤ÎÅÅÏÃÈÖ¹æ¤òÄ´¤Ù¤Æ¤â¤é¤Ã¤Æ¡¢¤½¤Î¶µ¤¨¤é¤ì¤¿
ÅÅÏÃÈÖ¹æ¤ËÅÅÏäò³Ý¤±¤¿¤é¡¢¼Â¤ÏËÜʪ¤Ç¤Ï¤Ê¤¯º¾µ½¤Î¿Í¤ÎÅÅÏä˳ݤ«¤Ã¤Æ¤·
¤Þ¤Ã¤Æ¤¤¤¿¡£¤½¤Îº¾µ½¤Î¿Í¤ÏËÜʪ¤Î²ñ¼Ò¤ÎôÅö¼Ô¤Î¿¶¤ê¤ò¤·¤Æ±þÂФ·¤¿¤¿¤á¡¢
ÅÅÏäò³Ý¤±¤¿ËܿͤϺ¾µ½¤Ë´¬¤­¹þ¤Þ¤ì¤¿¤³¤È¤Ë¤Þ¤Ã¤¿¤¯µ¤¤¬ÉÕ¤«¤Ê¤«¤Ã¤¿¡£
ÅÅÏÃÈÖ¹æ°ÆÆâ¤Ç°ÆÆâ¤·¤¿¿Í¤â¡¢¤½¤Î¼ê¸µ¤Î¥Ç¡¼¥¿¤¬±øÀ÷¤µ¤ì¤Æ¤¤¤¿¡Êº¹¤·ÂØ
¤¨¤é¤ì¤Æ¤¤¤¿¡Ë¤³¤È¤Ë¤Ï¤Þ¤Ã¤¿¤¯µ¤¤¬ÉÕ¤¤¤Æ¤¤¤Ê¤«¤Ã¤¿¡£

¤Ä¤Þ¤ê¡¢URL ¤ÏÀµ¤·¤¤¤Î¤Ë¡¢Àµ¤·¤¯¤Ê¤¤¥Õ¥¡¥¤¥ë¤ò¥À¥¦¥ó¥í¡¼¥É¤µ¤»¤é¤ì¤Æ
¤¤¤¿¤«¤â¤·¤ì¤Ê¤¤¡£¤È¤¤¤¦¤³¤È¤¬Èæ³ÓÅªÍÆ°×¤Ë¤Ç¤­¤Æ¤·¤Þ¤Ã¤¿¤È¤¤¤¦¤è¤¦¤Ê
ÀȼåÀ­¤À¤Ã¤¿¤È¤¤¤¨¤ë¤«¤â¤·¤ì¤Þ¤»¤ó¡£

¤Þ¤¿¡ http://xxx.yyy.bank.co.jp/login ¤ß¤¿¤¤¤ÊÀµ¤·¤¤ URL ¤Ç¤¢¤ë¤Ë¤â
¤«¤«¤ï¤é¤º¡¢¤Þ¤Ã¤¿¤¯Ê̤κ¾µ½¤Î¥µ¥¤¥È¤ØÀܳ¤µ¤»¤é¤ì¤Æ¤¤¤¿¤«¤â¤·¤ì¤Ê¤¤¡£
¤È¤¤¤¦²ÄǽÀ­¤â¤¢¤Ã¤¿ÀȼåÀ­¤À¤Ã¤¿¤Èª¤¨¤ë¤³¤È¤â¤Ç¤­¤ë¤È»×¤¤¤Þ¤¹¡£

»ä¤¬ÍøÍѤ·¤Æ¤¤¤ë¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥Ð¥ó¥­¥ó¥°¤Î¥í¥°¥¤¥ó²èÌ̤Ǥϡ¢¤³¤Î¤è¤¦¤Ê
ÀȼåÀ­¤¬°­ÍѤµ¤ì¤¿¤È¤·¤Æ¤âÈæ³ÓÅªÍÆ°×¤Ë¸«Çˤì¤ë¤Î¤Ç¤Ï¤Ê¤¤¤«¤È»×¤ï¤ì¤ë
¤è¤¦¤ÊÂкö¤¬¤¹¤Ç¤Ë¤Ê¤µ¤ì¤Æ¤¤¤Þ¤·¤¿¡£

==============================================================================
°Ê²¼¡¢µ»½ÑŪ¤Ê¦Ì̤ˤĤ¤¤Æ½ñ¤¤¤Æ¤ß¤Þ¤·¤¿¤¬¡¢ÆÉ¤ßÈô¤Ð¤·¤Æ¤¯¤À¤µ¤Ã¤Æ¹½¤¤¤Þ¤»¤ó¡£

¤³¤Î¤è¤¦¤Ê www.xxx.yyy.jp (Î㤨¤Ð www.openoffice.org) ¤«¤é¥¤¥ó¥¿¡¼¥Í¥Ã¥È
¾å¤ÎIP¥¢¥É¥ì¥¹(204.16.104.2 ¤Ê¤É) ¤Ø¤ÎÊÑ´¹¤ò¹Ô¤¦ DNS ¥µ¡¼¥Ð¡¼¤ÎÆâÉô¤Ë¤Ï¡¢
PC¤Ê¤É¤«¤é¼õ¤±¼è¤Ã¤¿Ì䤤¹ç¤ï¤»Í×µá¤ò¤µ¤é¤Ë¾å°Ì¤Î¥µ¡¼¥Ð¡¼¤ËÂФ·¤ÆÌ䤤¹ç¤ï¤»¡¢
¤½¤Î¾å°Ì¤Î¥µ¡¼¥Ð¡¼¤«¤é¼õ¤±¼è¤Ã¤¿±þÅú·ë²Ì¤ò°ì»þŪ¤Ë¼«¿È¤ÎÆâÉô¤Ë¥­¥ã¥Ã¥·¥å
¤·¤Æ¤ª¤¯¤³¤È¤Ë¤è¤Ã¤Æ¡¢¼¡²ó°Ê¹ß¤Ë²¼°Ì¤ÎPC¤Ê¤É¤«¤éƱ¤¸Ì䤤¹ç¤ï¤»Í×µá¤ò¼õ¤±
¼è¤Ã¤¿¾ì¹ç¤Ë¤Ï¾å°Ì¤Ø¤ÎÌ䤤¹ç¤ï¤»¤òÄê¤á¤é¤ì¤¿»þ´Ö¤¬·Ð²á¤¹¤ë¤Þ¤Ç¤Ï¾Êά¤·¡¢
¤½¤Î¤«¤ï¤ê¤Ë¥­¥ã¥Ã¥·¥å¤·¤Æ¤ª¤¤¤¿¥Ç¡¼¥¿¤ò»È¤Ã¤ÆPC¤Ø±þÅú¤òÊÖ¤¹¡£¤È¤¤¤¦»ÅÁȤß
¤¬¼ÂÁõ¤µ¤ì¤Æ¤¤¤Þ¤¹¡£¤³¤Î»ÅÁȤߤˤè¤Ã¤Æ¡¢¤è¤Ã¤Æ¥¤¥ó¥¿¡¼¥Í¥Ã¥È¾å¤Ê¤É¤Î¥Í¥Ã¥È
¥ï¡¼¥¯Éé²Ù¤Î·Ú¸º¤ä¡¢PC¤Ê¤É¤«¤é¤ÎÌ䤤¹ç¤ï¤»Í×µá¤ËÂФ¹¤ë±þÅú»þ´Ö¤Îû½Ì¤ò¹Ô¤¦
¤È¤¤¤¦¤ï¤±¤Ç¤¹¡£

Á°½Ò¤Î¥µ¡¼¥Ð¡¼´Ö¤ÎÄÌ¿®¤Î¤ä¤ê¼è¤ê¤ÎÃæ¤Ç¡¢DNS¥µ¡¼¥Ð¡¼¤¬¾å°Ì¥µ¡¼¥Ð¡¼¤Ø
Ì䤤¹ç¤ï¤»Í×µá¤ò½Ð¤·¤¿Ä¾¸å¤Ë¡¢¾å°Ì¤Î¥µ¡¼¥Ð¡¼¤«¤é¤Î±þÅú¤¬ÊÖ¤µ¤ì¤ë¤è¤ê
¤âÀè¤Ë¡¢°­°Õ¤Î¤¢¤ë¿Í¤¬¼«Ê¬¤Î°­°Õ¤Î¤¢¤ë¥Ç¡¼¥¿¤ò¤½¤ÎDNS¥µ¡¼¥Ð¡¼¤ØÁ÷¤ê
¤Ä¤±¤ë¤È¡¢¼«¿È¤Î¥Ç¡¼¥¿¤ò¤½¤ÎDNS¥µ¡¼¥Ð¡¼¤Î¥­¥ã¥Ã¥·¥å¤ËǦ¤Ó¹þ¤Þ¤»¤ë¤³¤È
¤¬Èæ³ÓÅªÍÆ°×¤Ë¼Â¸½²Äǽ¤À¤Ã¤¿¤È¤¤¤¦¤è¤¦¤Ê¤³¤È¤Î¤è¤¦¤Ç¤¹¡£

¤â¤Á¤í¤ó¡¢DNS¥µ¡¼¥Ð¡¼¤Ï¡¢Âç´ë¶È¤äÂç³Ø¤Ê¤É¤Î¤è¤¦¤Ê¿¤¯¤Î¥æ¡¼¥¶¡¼¤Ë¤è¤Ã¤Æ
»È¤ï¤ì¤ë¤³¤È¤¬ÂçÁ°Äó¤È¤Ê¤Ã¤Æ¤¤¤Þ¤¹¤Î¤Ç¡¢DNS¥µ¡¼¥Ð¡¼¤Ë¤Ï¡¢Æ±»þ¤ËÊ£¿ô¤Î
Ì䤤¹ç¤ï¤»Í×µá¤ò¾å°Ì¥µ¡¼¥Ð¡¼¤ØÁ÷¤ë¤³¤È¡¢¤ª¤è¤Ó¡¢Ê£¿ô¤ÎÊ֤äƤ­¤¿±þÅú¤Î
Ãæ¤«¤é¼«¿È¤¬Í׵ᤷ¤¿¥È¥é¥ó¥¶¥¯¥·¥ç¥óID¤È°ìÃפ·¤Æ¤¤¤ë²óÅú¤òȽÄꤷ¤ÆÅ¬ÀÚ¤Ë
½èÍý¤¹¤ë¤Ê¤É¤Îµ¡¹½¤¬È÷¤ï¤Ã¤Æ¤¤¤Þ¤¹¤«¤é¡¢Ä̾ï¤Ç¤¢¤ì¤Ð¡¢°­°Õ¤Î¤¢¤ë¥Ç¡¼¥¿¤Ï
¥È¥é¥ó¥¶¥¯¥·¥ç¥óID¤Ê¤É¤¬°ìÃפ·¤Ê¤¤¤Ê¤É¤Î¾ò·ïȽÄê¤Ë¤è¤Ã¤Æ´üÂÔÄ̤êµñÀ䡦
ÇÑ´þ¤µ¤ì¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤è¤¦¤Ç¤¹¡£

¤·¤«¤·¤Ê¤¬¤é¡¢º£²ó¤ÎÀȼåÀ­¤Ë¤ª¤¤¤Æ¤Ï¡¢¤½¤Î¥È¥é¥ó¥¶¥¯¥·¥ç¥óID¤Ê¤É¤òÈæ³ÓŪ
ÍÆ°×¤Ë¿ä¬¤¹¤ë¤³¤È¤¬²Äǽ¤Ç¤¢¤Ã¤¿¤½¤¦¤Ç¡¢¤½¤Î¿ä¬¤·¤¿ID¤Ê¤É¤ò»È¤Ã¤Æ¾å°Ì
¥µ¡¼¥Ð¡¼¤Ë¤Ê¤ê¤¹¤Þ¤·¡¢°­°Õ¤Î¤¢¤ë¥Ç¡¼¥¿¤ò¥­¥ã¥Ã¥·¥å¤Ë³Ð¤¨¤³¤Þ¤µ¤»¤Æ¤·¤Þ¤¦
¤È¤¤¤¦¤³¤È¤¬²Äǽ¤Ç¤¢¤Ã¤¿¤È¤Î¤³¤È¤Ç¤¹¡£

¾ÜºÙ¤Ë¤Ä¤¤¤Æ¤Ï¡¢°Ê²¼¤Ê¤É¤Ë½Ò¤Ù¤é¤ì¤Æ¤¤¤Þ¤¹¡£

Windows DNS Server Cache Poisoning
http://www.trusteer.com/microsoftdns

BIND 9 DNS Cache Poisoning
http://www.trusteer.com/bind9dns

Microsoft Update ¤Ç¤Ï¡¢¤½¤Î¥È¥é¥ó¥¶¥¯¥·¥ç¥óID¤Î¿ä¬¤¬¤è¤êº¤Æñ¤Ë¤Ê¤ë¤è¤¦¤Ê
Âкö¤Ê¤É¤ò¹Ô¤ï¤ì¤¿¤è¤¦¤Ç¤¹¡£

Bind (Berkeley Internet Name Daemon)
http://www.isc.org/index.pl?/sw/bind/index.php

¤ò»È¤ï¤ì¤Æ¤¤¤ë¤è¤¦¤Ê¥·¥¹¥Æ¥à´ÉÍý¼Ô¤Ë¤ª¤«¤ì¤Þ¤·¤Æ¤Ï¡¢bind ¤Î¥Ð¡¼¥¸¥ç¥ó
¥¢¥Ã¥×¤Ë²Ã¤¨¤Æ¡¢¤µ¤é¤Ë¡¢US-CERT ¤Ê¤É¤«¤é¤Î¾ðÊó¤Ê¤É¤â»²¾È¤·¤Æ¡¢¥Í¥Ã¥È
¥ï¡¼¥¯¤Ê¤É¤òŬÀÚ¤ËÀßÄꤵ¤ì¤¿¤Û¤¦¤¬¤è¤¤¤è¤¦¤Ç¤¹¡£

Multiple DNS implementations vulnerable to cache poisoning
http://www.kb.cert.org/vuls/id/800113

Tora

¡ÚML¥³¥ß¥å¥Û¡¼¥à¥Ú¡¼¥¸¡ http://www.freeml.com/openoffice

--[PR]------------------------------------------------------------------
¤¢¤Ê¤¿¤â¡Ö¤Ñ¤¯¤Ã¡×¤È¤¤¤Ã¤Á¤ã¤Ã¤Æ¤¯¤À¤µ¤¤¡£¤Á¤ç¤Ã¤È¤ª¤Ê¤«¤¬¤¹¤¤¤Æ¤¯¤ë
æÎÏ·Ï¥Ö¥í¥°¥Ñ¡¼¥Ä¡Ö¹ñ»º¾®Çþ¥·¥ê¡¼¥º¡×¡ª
Áᮺ£Æü¤â¡¢¤¿¤¤¤ä¤­¤µ¤ó¡¢¤¿¤³¤ä¤­¤µ¤ó¡¢¤ò¤ª»ýµ¢¤ê¤¯¤À¤µ¤¤¤Ã¢ö
¡¡
http://ad.freeml.com/cgi-bin/sa.cgi?id=cl96h
------------------------------------------------------------------[PR]--
¢£GMO INTERNET GROUP¢£ GMO INTERNET www.gmo.jp


Åê¹Æ¼Ô xml-rpc : 2008年7月14日 18:42
Ìò¤ËΩ¤Á¤Þ¤·¤¿¡©¡§
²áµî¤Î¥Õ¥£¡¼¥É¥Ð¥Ã¥¯ Ê¿¶Ñ:(0) Áí¹ç:(0) Åêɼ²ó¿ô:(0)
Ëܵ­»ö¤Ø¤ÎTrackback: http://hoop.euqset.org/blog/mt-tb2006.cgi/75256
¥È¥é¥Ã¥¯¥Ð¥Ã¥¯
¥³¥á¥ó¥È
¥³¥á¥ó¥È¤¹¤ë




²èÁü¤ÎÃæ¤Ë¸«¤¨¤ëʸ»ú¤òÆþÎϤ·¤Æ¤¯¤À¤µ¤¤¡£