è匱æ§é瀺ããã°ã©ã
ãŠãã€ãããã«ãšã£ãŠãã客æ§ã®å®å šãã»ãã¥ãªãã£ãããã³ãã©ã€ãã·ãŒã¯æéèŠäºé ã§ãããŠãã€ãããã§ã¯ããã¹ããã©ã¯ãã£ã¹ã掻çšããŠã確å®ã«ã·ã¹ãã ã®å®å šæ§ã確ä¿ããŠããŸãããŠãã€ãããã§ã¯ããã©ã€ãã·ãŒãšã客æ§ããåãåã£ãå人æ å ±ã®ä¿è·ã«éäžçã«åãçµãã§ããŸãããã®åãçµã¿ããããèªç©ºæ¥çåã®ããšãšããŠãè匱æ§é瀺ããã°ã©ã ã宿œããçç±ã§ãããŠãã€ãããã§ã¯ããã®ããã°ã©ã ã«ããã»ãã¥ãªãã£ãå€§å¹ ã«åäžããåªãããµãŒãã¹ãæäŸãç¶ããããšãã§ãããšèããŠããŸãããŠãã€ãããã®ãŠã§ããµã€ããã¢ããªããªã³ã©ã€ã³ããŒã¿ã«ã§è匱æ§ã®å¯èœæ§ã®ããåé¡ãèŠã€ããããå Žåã¯ããŠãã€ããããŸã§ãç¥ãããã ããããç¥ããããã ããå 容ããŠãã€ãããã®æ¡ä»¶ãæºãããŠããå Žåãã客æ§ã®ãååãžã®ã瀌ãšããŠç¹å žãã€ã«ãé²åããããŸãã
ã»ãã¥ãªãã£äžã®è匱æ§ãå ±åããåã«ãããŠãã€ãããã®èŠçŽããã確èªãã ãããè匱æ§é瀺ããã°ã©ã ã«åå ãããšãã客æ§ã¯ãããã®èŠçŽãšãããã«èšèŒãããèŠä»¶ããã³ã¬ã€ãã©ã€ã³ã«åæããããšã«ãªããŸãã
è匱æ§é瀺ããã°ã©ã ãšã¯äœã§ããïŒ
è匱æ§é瀺ããã°ã©ã ã§ã¯ã瀟å€ã®èª¿æ»å®æœè ããã客æ§ãäŒæ¥ã®æ å ±ã®æ©å¯æ§ãæŽåæ§ãå¯çšæ§ã«åœ±é¿ããåé¡ãæ€åºãå ±åããããšãã§ããŸããããã«è匱æ§ãæåã«çºèŠããæ¹ã«ã¯å ±å¥šãã€ã«ãé²åããããŸãã
ããã°ã©ã 察象èŠä»¶
å ±åãšå ±å¥šãã€ã«ã®é²åãå ¬æ£ãã€æå¹ã«å®æœãããããã«ã察象ãšãªã調æ»å®æœè ããã³è匱æ§ã¯ã以äžã®èŠä»¶ãªã©ãå«ããŠãã€ãããè匱æ§é瀺ããã°ã©ã èŠçŽã«åŸããã®ãšããŸãã
- è匱æ§ã¯æ°ãã«çºèŠããããã®ã§ããå¿ èŠããããŸããç¹å žãã€ã«ã¯ãç¹å®ã®è匱æ§ãæåã«å ±åãã調æ»å®æœè ã®ã¿ã«é²åãããŸãã
- 調æ»å®æœè ã¯ã18æ³ä»¥äžã®åªè¯ãªãã€ã¬ãŒãžãã©ã¹äŒå¡ã§ããå¿ èŠããããŸãããŸã äŒå¡ã§ãªãæ¹ã¯ãä»ãããã€ã¬ãŒãžãã©ã¹ããã°ã©ã ã«ãç»é²ãã ããã
- ç±³åœã®çŸè¡ã®å¶è£ãªã¹ãã«èšèŒãããŠããåœã«å± äœã®æ¹ã¯ããã®ããã°ã©ã ã«ãåå ããã ããŸããã
- ãŠãã€ãããèªç©ºãã¹ã¿ãŒã¢ã©ã€ã¢ã³ã¹å çèªç©ºäŒç€ŸããŸãã¯ä»ã®ææºèªç©ºäŒç€ŸããŠãã€ãããèªç©ºã®å§èšæ¥è ã®çŸåšãŸãã¯éå»ã®åŸæ¥å¡ããããã¯ãŠãã€ãããèªç©ºãŸãã¯ææºèªç©ºäŒç€Ÿã®åŸæ¥å¡ã®å®¶æãŸãã¯åäžäžåž¯ã®æ¹ã¯ãè匱æ§é瀺ããã°ã©ã ã«ãåå ããã ããŸããã
- è匱æ§ãèŠã€ãã£ãã³ãŒãã®äœæè æ¬äººãŸãã¯ãã®ã³ãŒãã«é¢ä¿ããããšã®ããæ¹ããè匱æ§é瀺ããã°ã©ã ã§ãã®è匱æ§ãå ±åããããšã¯ã§ããŸããã
調æ»ã®å¯Ÿè±¡
察象ãšãªãè匱æ§ã®å 容ã¯ããŠãã€ããããéææ±ºå®ã§ãããã®ãšããŸããå ±åãããè匱æ§ã«ã€ããŠãŠãã€ãããã確èªãããã¹ãŠã®å¯Ÿè±¡ã以äžã«ãŸãšããŸããã
- ãŠãã€ãããèªç©ºã®åæ¥çšãŠã§ããµã€ãïŒunited.comïŒ
- ãŠãã€ãããã®iOSããã³Androidã¢ããª
- ãŠãã€ãããã®iOSã¢ããªã¯Appleã®App StoreããããŠã³ããŒãã§ããŸãã
- ãŠãã€ãããã®Androidã¢ããªã¯Google Playã¹ãã¢ããããŠã³ããŒãã§ããŸãã
- ãŠãã€ããããã€ã¬ãŒãžãã©ã¹Xã®iOSããã³Androidã¢ããª
- ãã€ã¬ãŒãžãã©ã¹Xã®iOSã¢ããªã¯Appleã®App StoreããããŠã³ããŒãã§ããŸãã
- ãã€ã¬ãŒãžãã©ã¹Xã®Androidã¢ããªã¯Google Playã¹ãã¢ããããŠã³ããŒãã§ããŸãã
è匱æ§é瀺ããã°ã©ã ã®å¯Ÿè±¡ç¯å²ãšå¯Ÿè±¡å€ã¯æ¬¡ã®ãšããã§ãã
察象ç¯å²
- *.united.com - ãŠã§ããµã€ããã¹ã
- ãŠãã€ãããã¢ãã€ã«ã¢ããªiOSç - ã¢ãã€ã«ãã¹ã
- ãŠãã€ãããã¢ãã€ã«ã¢ããªAndroidç - ã¢ãã€ã«ãã¹ã
- ãã€ã¬ãŒãžãã©ã¹Xã¢ããªiOSç - ã¢ãã€ã«ãã¹ã
- ãã€ã¬ãŒãžãã©ã¹Xã¢ããªAndroidç - ã¢ãã€ã«ãã¹ã
察象å€
ãŠãã€ãããã¯æ¬ããã°ã©ã ã®å¯Ÿè±¡å€ãšããããµãŒãããŒãã£ã®ãµã€ãããµãŒãã¹ã倿°äœ¿çšããŠããŸãããŸãã察象ç¯å²ãªã¹ãã¯å€æŽãããå ŽåããããŸãã以äžã¯å¯Ÿè±¡å€ãšèŠãªãããŸãã
- æ©å Wi-Fiããšã³ã¿ãŒãã€ã¡ã³ãã·ã¹ãã ãèªç©ºé»åæ©åš
- äŒç€Ÿã®ã¡ãŒã«
- ãµãŒãããŒãã£ã®ã¢ããªã±ãŒã·ã§ã³ããµãŒãã¹
- 鿬çªç°å¢
- hotels.united.com
- vacations.united.com
- united.jobs
- newsroom.united.com
- ir.united.com
- hub.united.com
- jobs.united.com
- opinions.united.com
- globallinks.united.com
- dutyfree.united.com
- bigmetalbird.united.com
- globalservices.united.com
- uatp.united.com
- thanksamillion.united.com
- unitedmileageplus.com
- secure.unitedmileageplus.com
- newspaper-miles.com
- *.ual.com
- *.mileageplus.com
- cruises.united.com
- ualmiles.com
- unitedshop.summitmg.com
- united-veterans.jobs
- clubconferencerooms.united.com/unit
- theexplorercard.com
- mpclubcard.com
- myexplorercard.com
- unitedexplorecard.com
- unitedexplorer.com
- unitedexplorercard.com
- mileageplusawards.com
- mpdining.rewardsnetwork.com
- m.mpdining.rewardsnetwork.com
- news.united.com/responsys
- survey.continental.com/vovici.net
- booking.unitedcargo.com
- chargerback.com
åå èŠå
- å ±åãã©ãŒã ã§ãè匱æ§ã®åçŸãšç¢ºèªã«å¿ èŠãªæ å ±ãå«ããè匱æ§çºèŠã®è©³çްããç¥ãããã ããã
- ã»ãã¥ãªãã£äžã®è åšãããããè匱æ§ã®ã¿ãå ±å¥šãã€ã«ã®å¯Ÿè±¡ãšããŸããåé¡ã®æ·±å»åºŠã®æ±ºå®ã¯ããŠãã€ãããããã®æçµçãªè²¬ä»»ãè² ããŸãã
- çºèŠããè匱æ§ãŸãã¯è匱æ§ã®å¯èœæ§ãå ¬éãããããµãŒãããŒãã£ã«é瀺ãããããããšã¯çŠããããŠããŸããå ¬éãé瀺ãè¡ã£ãå Žåãç¹å žãã€ã«ã¯é²åãããŸããã
- ããŒã¿ã®æ¹å€ãç Žå£ããŠãã€ãããã®ãµãŒãã¹ã®åŠšå®³ãå£åæ»æãªã©ã®ãã¹ããšã¯ã¹ããã€ããŒã·ã§ã³ã詊ã¿ãªãã§ãã ããã
- ãã«ãŒããã©ãŒã¹æ»æãDoSïŒãµãŒãã¹æåŠïŒæ»æãèªåã®ã¢ã«ãŠã³ãã§ã¯ãªããŠãã€ãããã®ã¢ã«ãŠã³ãã®äŸµå®³ããã¹ãã詊ã¿ãªãã§ãã ããã
- æ©å ãšã³ã¿ãŒãã€ã¡ã³ããæ©å Wi-Fiãªã©ãèªç©ºæ©ãŸãã¯èªç©ºæ©ã·ã¹ãã ã«å¯Ÿãããã¹ãã詊ã¿ãªãã§ãã ããã
- ãŠãã€ãããã®ç€Ÿå¡ãã客æ§ãæšçãšããŠããœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°æ»æããã£ãã·ã³ã°æ»æãç©çæ»æãªã©ã®è¡çºã詊ã¿ãªãã§ãã ããã
- ãŠãã€ãããã®ç©ºæž¯æœèšã«å¯Ÿããç©çæ»æãè¡ããªãã§ãã ããã
- èªåã¹ãã£ããŒïŒããŒã«ã䜿çšããªãã§ãã ããã
å ±åã®å¯Ÿè±¡ãšãªãè匱æ§ïŒ
- ã³ãŒãã®ãªã¢ãŒãå®è¡
- SQLã€ã³ãžã§ã¯ã·ã§ã³
- XXE
- XSS
- ãµãŒããŒãµã€ããªã¯ãšã¹ããã©ãŒãžã§ãª
- ãã£ã¬ã¯ããªãã©ããŒãµã« â ããŒã«ã«ãã¡ã€ã«ã€ã³ã¯ã«ãŒãžã§ã³
- èªèšŒïŒæ¿èªãã€ãã¹ïŒã¢ã¯ã»ã¹å¶åŸ¡ã®äžåïŒ
- æš©éææ Œ
- å®å šã§ãªãçŽæ¥ãªããžã§ã¯ãåç §
- äžé©åãªèšå®
- ãŠã§ããã£ãã·ã¥è©ç§°
- äžé©åãªCORSèšå®
- CRLFã€ã³ãžã§ã¯ã·ã§ã³
- ã¯ãã¹ãµã€ããªã¯ãšã¹ããã©ãŒãžã§ãª
- ãªãŒãã³ãªãã€ã¬ã¯ã
- æ å ±æŒæŽ©
- ãªã¯ãšã¹ãã¹ãã°ãªã³ã°
- æ··åã³ã³ãã³ã
å ±åã®å¯Ÿè±¡ãšãªããªãè匱æ§ïŒ
- ã»ãã¥ãªãã£ããããŒãªã©ãã»ãã¥ãªãã£äžã®ãã¹ããã©ã¯ãã£ã¹
- ãœãŒã·ã£ã«ãšã³ãžãã¢ãªã³ã°ããã£ãã·ã³ã°
- ç©çæ»æ
- ã¯ãããŒäžæã®ãã©ã°
- ãã°ã€ã³æã®CSRFããã°ã¢ãŠãæã®CSRFãªã©ã圱é¿ã®å°ããCSRF
- ã³ã³ãã³ãã¹ããŒãã£ã³ã°
- ã¹ã¿ãã¯ãã¬ãŒã¹ããã¹æŒæŽ©ããã£ã¬ã¯ããªãªã¹ãã£ã³ã°
- SSL/TLSã®ãã¹ããã©ã¯ãã£ã¹
- ãããŒã°ã©ãã³ã°
- CSVã€ã³ãžã§ã¯ã·ã§ã³
- åå°åãã¡ã€ã«ããŠã³ããŒã
- æ§åŒãã©ãŠã¶ã«é¢ããã¬ããŒã
- DOS/DDOS
- æãããªåœ±é¿ã®ãªãHOSTããããŒã€ã³ãžã§ã¯ã·ã§ã³
- ã¹ãã£ããŒã®åºå
- ãµãŒãããŒãã£è£œåã®è匱æ§
- ãŠãŒã¶ãŒåæ
- ãã¹ã¯ãŒãã®è€éã
- HTTP TRACEã¡ãœãã
- DMARC
- ã¯ãªãã¯ãžã£ããã³ã°
- SPFã¬ã³ãŒã
- äžååãªèªåå鲿¢
- ã¬ãŒãå¶éæ»æ
- ã»ã«ãXSS
å ±åãããè匱æ§ã®æ·±å»åºŠ
察象ãšãªãè匱æ§ã®å ±åã«å¯Ÿããå ±å¥šãã€ã«ã¯ãè匱æ§ã®æ·±å»åºŠã«ãã£ãŠæ±ºãŸããŸãããŠãã€ãããã®ã»ãã¥ãªãã£ããŒã ããå ±åå 容ã®ç¢ºèªåŸã«å ±éè匱æ§è©äŸ¡ã·ã¹ãã ïŒCVSSïŒãšOWASPãªã¹ã¯æ Œä»ææ³ãçµã¿åãããŠè匱æ§ã®æ·±å»åºŠã倿ããŸããå ±åå 容ã®åŠ¥åœæ§ãèªãããããšã調æ»å®æœè ã«å ±å¥šãã€ã«ãé²åãããŸãã æ·±å»åºŠã®é«ãè€æ°ã®å ±åããŠãã€ãããã®è£éã§1ä»¶ã®è匱æ§ãšèŠãªãå ŽåããããŸãã
è匱æ§ã®æ·±å»åºŠã«å¿ããŠé²åãããæå€§ç¹å žãã€ã«æ°
é倧床 | é²åãããæå€§ç¹å žãã€ã« | |
---|---|---|
éèŠ | 1,000,000ãã€ã« |
|
ã〠| 500,000ãã€ã« |
|
äžçšåºŠ | 250,000ãã€ã« |
|
ã㌠| 50,000 \'83\'7dã€ã« |
|
åèæ å ± | 0ãã€ã« |
éä¿¡å 容
ãã¡ãã®å ±åãã©ãŒã ã§ãããªã·ãŒãšé©çšæ¡ä»¶ãçè§£ãåæããäžã§ããŠãã€ãããè匱æ§é瀺ããã°ã©ã ã«å ±åããŠãã ããã