ãã®ããã°ã¯ãProofpoint Protect Globalã§ãå€èŠçŽ èªèšŒ (MFA) ãåé¿ããäžè¬çææ³ã«ã€ããŠè§£èª¬ããå 容ããŸãšãããã®ã§ãããã®ã«ã³ãã¡ã¬ã³ã¹ã§ã¯ãMFA ãããæããæ°ããè匱æ§ã«ã€ããŠèª¬æããMicrosoft 365/Azure ã®éçºç°å¢ãšå®çšŒåç°å¢ãã¡ãŒã«ãã¡ãŒã«ã«ãŒã«ãã¯ã©ãŠãã¢ããªãªã©ãžã®ãã«ã¢ã¯ã»ã¹ãæ»æè ãã©ã®ããã«æªçšãããã説æããŸããããŸãè€æ°ã®ã¢ã€ãã³ãã£ã㣠ãããã€ã㌠(IdP) ãœãªã¥ãŒã·ã§ã³ã®ãã¹ããéããŠãOkta ãš OneLogin ã®è匱æ§ãæ€èšŒããŸãã (ãããã®ã»ãã¥ãªãã£åé¡ã¯è§£æ±ºæž)ããã®ããã°ã§ã¯ãMFA ãããæããææ³ãæè¡çã«è§£èª¬ããŸãã
WS-Trustã«ãã©ãçããŸã§ã®éã®ã
MFA ã®åé¿ææ³ã«ã€ããŠå€ãã®ãããã³ã«ãã¢ããªã±ãŒã·ã§ã³ããã£ã¬ã¯ã·ã§ã³ã調ã¹ããšããã1ã€æ³šç®ãã¹ãç¹ããããŸããã
Skype for Business (SfB) ã¯åºãå©çšãããŠããã¢ããªã±ãŒã·ã§ã³ã§ãããããããµãŒããŒã IdP ãšã©ãéä¿¡ããŠãããããã¹ããããšããäžè²«æ§ãæ¬ åŠããŠããã®ã§ããäžéšã® IdP ã®ã·ããªãªã§ã¯ãMFA ãåžžææå¹ã«ãªã£ãŠããå Žåã§ããSkype for Business ãã°ã€ã³æã« MFA ã®å®è¡ãæ±ããããŸããã§ãããããã¯å±éºãªä¿¡å·ã§ããããã§ã䜿çšãããŠãããããã³ã«ãå®è£ æ¹æ³ããšã³ããã€ã³ãéã®ããŒã¿ãããŒã«ã€ããŠæãäžããŠèª¿ã¹ãŸãããç§ã¯ Skype for Business ãããã³ã«ããã®åéã«ã¯ç²ŸéããŠããªãã£ãã®ã§ãã®äœæ¥ã«ã¯äœæ¥ãããããŸããã
ããã»ã¹ãžã®ã³ãŒã ã€ã³ãžã§ã¯ã·ã§ã³ãã¹ãããã£ã³ã°ãæå·ã®äžéšè§£èªãªã©ã詊ãããšãããSkype ããŠãŒã¶ãŒãšã³ãã¥ãã±ãŒã·ã§ã³ãããã³ãæ å ±ãæœåºããããŒã¯ã³ããMFA ãªãã§ååŸããããšã«æåããŸãããããã§ç§ã¯ãããŒã¯ã³ã®ãªãªãžã³ãšãããŒã®èª¿æ»ãå§ããŸãããSkype ã¯ããŒã¯ã³ãã©ã®ããã«ååŸããã©ããã£ãŠ MFA ãåé¿ã§ããã®ãã確èªãããã£ãããã§ããããã®çµæ WS-Trust ãããã³ã«ãšã¢ã¯ãã£ã ãšã³ããã€ã³ãã«ãã©ãçããŸããã
WS-Trust ãããã³ã«ãšã¯?
ãŠã£ãããã£ã¢ã«ãããšãWS-Trust 㯠WS-Security ã®æ¡åŒµæ©èœãæäŸãã WS-* 仿§ããã³ OASIS ã¹ã¿ã³ããŒãã§ãã»ãã¥ãªãã£ããŒã¯ã³ã®çºè¡/æŽæ°/æ€èšŒããããŸãå®å šãªã¡ãã»ãŒãžã³ã°ã®ããã®åå è éã®ä¿¡é Œé¢ä¿ã®ç¢ºç«/è©äŸ¡/仲ä»ãããŸãã
Web Services Security (WS-SecurityãWSS) 㯠SOAP ã®æ©èœåŒ·åãèšè¿°ãããã®ã§ãWeb ãµãŒãã¹ã®ã»ãã¥ãªãã£ã«çšããããŸããWeb ãµãŒãã¹ä»æ§ã®äžéšã§ãOASIS ãèŠæ Œãçºè¡šããŸããããã®ãããã³ã«ã¯ã¡ãã»ãŒãžã®å®å šæ§ãšæ©å¯æ§ãä¿æããããã®ä»æ§ãå«ã¿ãSecurity Assertion Markup Language (SAML)ãã±ã«ããã¹ãX.509 ãªã©ã®ããŸããŸãªã»ãã¥ãªãã£ããŒã¯ã³èŠæ Œã®éä¿¡ãå¯èœã«ããŸãããã®äž»ãªç®çã¯ãXML 眲åãš XML æå·åãçšããŠãšã³ãããŒãšã³ãã®ã»ãã¥ãªãã£ãæäŸããããšã«ãããŸãã
ãããã®ãããã³ã«ã«ã€ããŠã¯éåžžã«å€ãã®æ å ±ãæäŸãããŠããã®ã§ãããã§ã¯ãã®æ»æã®çè§£ã«å¿ èŠãªæ å ±ã ããã玹ä»ããŸããWS-Trust ã¯ã¢ã¯ãã£ã ãšã³ããã€ã³ãã§çšããããŸããWS-Federation ã¯ããã·ã ãšã³ããã€ã³ãã§çšããããŸããã¢ã¯ãã£ã ãšã³ããã€ã³ãã¯éåžžãã¬ã¬ã·ãŒ ãããã³ã«ã®èªèšŒã«äœ¿çšãããŸããããã·ã ãšã³ããã€ã³ãã¯éåžžããã©ãŠã¶ãææ°ã¯ã©ã€ã¢ã³ãã«çšããããŸããäžè¬çã«ããããã®ãšã³ããã€ã³ã㯠IdP åŽã«ããããã°ã€ã³æ€èšŒãè¡ããŸãã
éåžžã®å¯Ÿçã§ã¯ä¿è·ãäžåå
âThe best way to protect your account from malicious authentication requests made by legacy protocols is to block these attempts altogether.â âMicrosoft
(ã¬ã¬ã·ãŒãããã³ã«ããã®æªæããã¢ã«ãŠã³ãèªèšŒèŠæ±ã黿¢ããã«ã¯ãããããå®å
šã«ãããã¯ããŠããŸãããšããã¹ãã§ããâMicrosoft)
ãã® MFA åé¿ã¯éåžžã®å¯Ÿçã§ã¯é²ããŸãããAzure ã§ã¬ã¬ã·ãŒãããã³ã«ãç¡å¹åããŠããæ»æè ã¯ææ°ã®èªèšŒã«ããããã§ããã®ã§å¹æããããŸããããããããããšãAzure ã¯ããã®ã»ãã·ã§ã³ã¯ææ°ã®èªèšŒæ¹æ³ã§ãã°ã€ã³ããããšã¿ãªããŸãããã®ãã管çè ãããã®ã»ãã·ã§ã³ã¯ MFA ãéããŠããã®ã§å®å šã ãšåéãããŠããŸããŸãã
WS-Trust ïŒ2007幎3æã«æ¿èªïŒ 㯠MFA ãèæ ®ã«å ¥ããŠèšèšãããŠããªãã®ã§ãMFA ã®ãã€ãã£ããµããŒãã¯ããŠããŸããããã®ãã IdP 㯠MFA çšã«ãœãªã¥ãŒã·ã§ã³ãéçº (ãŸã㯠MFA ããããã¯) ããªããã°ãªããŸããã
æ°ããè匱æ§ã䜿ã£ãŠ MFA ãåé¿ããæ»æ
ãã®æ»æã¯äž»ã«ä»¥äžã®ãããªæ¹æ³ã§è¡ãããŸãã
- ãšã³ããã€ã³ã ã¢ãã¬ã¹ãæ€çŽ¢
- IdP ã«çŽæ¥ SAML ãªã¯ãšã¹ããéä¿¡
- SAML V1 ããŒã¯ã³ãååŸ
- Microsoft ãµãŒãã¹ã䜿ã£ãŠææ°ã®ããŒã¯ã³ã«å€æ
- OAuth 2 ããŒã¯ã³\Cookie ã䜿çšããŠã¢ã«ãŠã³ããå®å šã«å¶åŸ¡
ããšãã°ããã¢ãªã¹ãã Microsoft 365 ã§æ§åã®ããããã«ã¡ãŒã«ãéä¿¡ããããšããŸãã(泚: Microsoft 365 ããã³ãã¯ãIdP ãæäŸãããMFA ãæå¹åããããã§ãã¬ãŒã·ã§ã³ããã³ SSO ãµãŒãã¹ã䜿çšããŸãã) ã¢ãªã¹ã¯èªåã®èªèšŒæ å ±ã Microsoft 365 ã«éãã®ã§ã¯ãªããoutlook.office.com ã«ã¢ã¯ã»ã¹ããŠãã°ã€ã³ããŸãããããããšãã®ãã°ã€ã³æ å ±ã¯ IdP ã«è»¢éãããããã·ã ãšã³ããã€ã³ãçµç±ã§èªèšŒãããŸããã¢ãªã¹ãæ£ããèªèšŒæ å ±ãæäŸããåŸãMFA ã§ã®èªèšŒãè¡ããŸãããããš Microsoft 365 ã«æ»ããã°ã€ã³ã§ããŸãã
次ã«è匱æ§ãæªçšãããäŸã説æããŸãããããªã¹ã«ãŒã¯ã¢ãªã¹ã®ã¢ã«ãŠã³ãããããã«ã¡ãŒã«ãéä¿¡ããããšäŒãã§ããŸããããã§ãŸããªã¹ã«ãŒã¯ããã£ãã·ã³ã°ã§ã¢ãªã¹ã®èªèšŒæ å ±ãçã¿ãŸãããã®åŸãoutlook.office.com ã«ã¢ã¯ã»ã¹ããã®ã§ã¯ãªãããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã®ã¿ãå«ã¿ãããããŒãå å·¥ãããªã¯ãšã¹ããã¢ã¯ãã£ã\ã¬ã¬ã·ãŒ ãšã³ããã€ã³ãã«éããŸãããããè匱æ§ã®åœ±é¿ãåãããšã³ããã€ã³ãã ã£ãå ŽåãIdP 㯠Microsoft ãã§ãã¬ãŒã·ã§ã³ã«æå¹ãª SAML 1ããŒã¯ã³ãè¿ããŸãããªã¹ã«ãŒã¯ã以äžã«èª¬æãããæ¹æ³ã§ãã®ããŒã¯ã³ãææ°ããŒã¯ã³ã«ããããããŸãããããããš MFA ã§èªèšŒããããã«èŠããããŠãã¢ãªã¹ãšããŠãã°ã€ã³ããŠã¡ãŒã«ã®éåä¿¡ãã§ããããã«ãªããŸãã
次ã«ãªã¹ã«ãŒã¯ã¢ãªã¹ã® Azure ã¢ã«ãŠã³ããæªçšããŠãœãŒã¹ã³ãŒããçã¿ããŸããæªæã®ããããµãŒãããŒã㣠(OAuth) ã¢ããªãã€ã³ã¹ããŒã«ããŸãããããããšã¢ãªã¹ããã¹ã¯ãŒãã倿ŽããŠãæ°žç¶çã«ã¢ã«ãŠã³ããæªçšã§ããããã«ãªããMFA ãå¿ èŠãªããªããŸãã
æ»æãããŒã®è©³çް
以äžã¯ãæ»æè ã«ããå žåç㪠SAML ãªã¯ãšã¹ãã®äŸã§ãã

ã€ã¡ãŒãž1: æ»æè ã«ãã SAML ãªã¯ãšã¹ã
å¿ èŠãªæ å ±ã¯ãŠãŒã¶ãŒåãšãã¹ã¯ãŒãã ãã§ããæ®ãã®æ å ±ã¯ãæ»æè ã Microsoft ãªã³ã©ã€ã³ ãã§ãã¬ãŒã·ã§ã³å šäœãžã®ã¢ã¯ã»ã¹ãèŠæ±ããé (以äžã®ã調æ»ãã§èª¬æ) ã«ç°¡åã«å ¥æã§ããŸãã
èªèšŒæ
å ±ç¢ºèªåŸã« WS-TRUST ãšã³ããã€ã³ãããæ»æè
ã«éããããªãã©ã€äŸã以äžã«ç€ºããŸãã

ã€ã¡ãŒãž2: WS-Trust ãšã³ããã€ã³ãããã®ãªãã©ã€
email@domain.com ã«ã¯çœ²åä»ããŒã¯ã³ãäžããããææ°ããŒã¯ã³ã«ããããã§ããããã«ãªã£ãŠããŸãã
SAML 1ããŒã¯ã³ãææ°ããŒã¯ã³ã«ããããããã«ã¯ POST ãªã¯ãšã¹ããhttps://login.Microsoftonline.com/login.srfã«éããŸãããããããš ESTSAUTH ãšãã Cookie ãååŸã§ããããã䜿ã£ãŠããã©ãŠã¶ãžã® Cookie ã€ã³ãžã§ã¯ã·ã§ã³ã§ Microsoft ãã§ãã¬ãŒã·ã§ã³ã«ã¢ã¯ã»ã¹ã§ããããã«ãªããŸãã
åµå¯
ãã®è匱æ§ã¯ç°¡åã«èª¿ã¹ããããŸãèªååã容æã§ããããšãã°ããšã³ããã€ã³ã ã¢ãã¬ã¹ã¯èªèšŒæ å ±ããªããšãç°¡åã«æã«å ¥ããŸããhttps://login.microsoftonline.com/getuserrealm.srf?login=demo@somedomainname&xml=1 ã® demo@somedomainname ãå¿ èŠãªãã¡ã€ã³åã§çœ®ãæããã ãã§ãã
ã¯ãšãªçµæã¯ä»¥äžã®ãããªãã®ã«ãªããŸãã

ã€ã¡ãŒãž3: DNS ã¯ãšãª ã¹ã¯ãªãŒã³ã·ã§ãã
STSAuthURL ã¯ç§ãæ»æã§ããã¢ã¯ãã£ã ãšã³ããã€ã³ãã§ãProtect Global Conference ã§ã®ãã¬ãŒã³ããŒã·ã§ã³ã§ã玹ä»ãããã®ã§ãã
ãã®ä»ã®è匱æ§
IP ã¹ããŒãã£ã³ã°
X-MS-FORWARDED-CLIENT-IP ããªã¯ãšã¹ãããããŒãšããŠçšãããšã³ããã€ã³ãã® IP å¶éãåé¿ã§ããããšããããŸãã
äžéšã®çµç¹ã§ã¯ããŠãŒã¶ãŒã® IP ã¢ãã¬ã¹ãããšã«ããŠãVPN ã䜿çšããŠãããã確èªããŠããŸããVPN å©çšã® IP ã¬ã³ãžã¯éçã§ãåœé ã§ããªããšæ³å®ããŠããããã§ããVPN ã® IP ã¢ãã¬ã¹ãä¿¡ãããšãMFA ããã§ã«å®è¡ãããŠãããšåéãããŠããŸãããšããããŸããåœã®ããããŒãç¡èŠããæ©èœãæããªã IdP ã¯ãäžèšã®ãããªããããŒã䜿ãã°éšãããšãã§ããŸãã
Proofpoint Protect Conference ã§ãã®æ»æã®ãã¢ããèŠãããŸããããã®ãã¢ã§ã¯ IdP åŽã§ IP ã®èš±å¯ãªã¹ãã127.0.0.1 (localhost) ã®ã¿ã«å¶éããŸãããçè«äžããã®èšå®ã¯ããŒã«ã« IdP ãã·ã³å€ã®ãŠãŒã¶ãŒã«ã¯ãšã³ããã€ã³ã ã¢ã¯ã»ã¹ããããã¯ã§ããã¯ãã§ãããããããŒãçšããŠãããåé¿ããããšã§ãMFA ãªãã§ã¢ã«ãŠã³ããžã®ã¢ã¯ã»ã¹ã«æåããŸããã
æ»æè ã¯ãšã³ããã€ã³ãã® IP å¶éãã©ããªã£ãŠãããããªãç¥ãããšãã§ãããŸãã©ããã£ãŠãããååŸããã®ããäžæè°ã«æãããæ¹ãããã§ãããã圌ãã¯èªèšŒæ å ±ããã£ãã·ã³ã°ãããšãã«äžç·ã«ã»ãã·ã§ã³ IP ãæœåºããŠä¿åããåŸã§æ»æã«äœ¿çšããã®ã§ãã
ãšã³ãã㣠ãŠãŒã¶ãŒ ãšãŒãžã§ã³ããšãªãã·ã§ã³ã®æ¬ åŠ
ç§ã®èª¿æ»ã§ã¯ãããã±ãŒã¹ã§ã¯ IdP ã¯ã¢ã¯ãã£ã ãšã³ããã€ã³ããç¡å¹ã«ãããªãã·ã§ã³ãæäŸããŠãããããŸãããã±ãŒã¹ã§ã¯ç¡å¹ã«ããŠãæ»æã®é»æ¢ã«ã¯äžååã§ããããšã³ãã㣠ãŠãŒã¶ãŒ ãšãŒãžã§ã³ãã§ãªã¯ãšã¹ããéã£ããšããã察çãåé¿ã§ããç¡å¹åããã WS-Trust ã¢ã¯ãã£ã ãšã³ããã€ã³ãã«ã¢ã¯ã»ã¹ã§ããŸãããããã¯éçºç°å¢ã§ãã¹ããããã®ã§ãããã®ãã°ã¯å®çšŒåç°å¢ã§ã¯çºçããªããšã®ããšã§ããã
ã¹ã©ãã·ã¥ã§å¯èœã«
å®çšŒåç°å¢ã§ã¯ããšã³ãã㣠ãŠãŒã¶ãŒ ãšãŒãžã§ã³ãã§ã¯ããã»ã¹ãå®è¡ã§ããŸããã§ããããäœæéã詊ãããšããä»ã®ãã°ãèŠã€ãããŸãããå®çšŒåç°å¢ã®ãšã³ããã€ã³ãã¢ãã¬ã¹ã®æ«å°Ÿã«ã¹ã©ãã·ã¥ãå ãããšãç¡å¹åãããŠããŠãã¬ã¬ã·ãŒç°å¢ã«å ¥ããã®ã§ãã
ãã°ã®äžåš
WS-Trust ãšã³ããã€ã³ããžã®çŽæ¥ã¢ã¯ã»ã¹ã¯ IdP ã®ãã°ã«èšé²ãããªãããšããããŸãã ãã®å Žåãã»ãã¥ãªãã£ã·ã¹ãã ãå°éå®¶ãæ»æãææã§ããŸããã
ãããã£ãæ»æã¯èªååãå¯èœã§ãããã¢ã«ãŠã³ãã®ä¹ã£åãã«1ç§ãããããªãããæ³šæãå¿ èŠã§ãã
æ»æãããŒã®æŠèŠ
æ»æã¯ãPython ã³ãŒããpostmanããŸãã¯ã«ã¹ã¿ã ããããŒãšæ¬æã§ POST ãªã¯ãšã¹ããéä¿¡ããããŒã«ãçšããŠè¡ãããŸãããããŠäžèšã§çºèŠããè匱æ§ã®ãã WS-Trust ãšã³ããã€ã³ãã«ãã«ã¹ã¿ã ãã€ããŒã (ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããå«ã) ãéãããŸãã
è匱ãªãšã³ããã€ã³ã㯠MFA ãæ±ããããšãªã SAML 1ããŒã¯ã³ãè¿ããŸããæ»æè ã¯ãã®ããŒã¯ã³ãååŸãããªã¯ãšã¹ãã«ããããŒã远å ãã以åå ¥æãã Web ãµã€ãã«éä¿¡ããŸãã
Microsoft ã¯æå¹ãªããŒã¯ã³ãåãåããšãESTSAUTH ãšãã Cookie ãæäŸããŸãããã® Cookie ããã©ãŠã¶ããŸãã¯é¢é£ããèªååããŒã«ã§äœ¿ããšã¢ã«ãŠã³ããä¹ã£åãããšãã§ããŸãããŸãèªååããŒã«ã§ã¢ã«ãŠã³ããžã® OAuth ããŒã¯ã³ãå
¥æããããšãå¯èœã§ãã
æå¹ãªå¯Ÿç
- è匱æ§ã¯å¿ ãæ»æè ã«çºèŠãããŸããä»ã®ã»ãã¥ãªãã£å¯Ÿçãçªç ŽãããŠããŸã£ãå Žåãã¢ã«ãŠã³ãäŸµå®³ã®æ€ç¥ãšä¿®åŸ©ã圹ç«ã¡ãŸãã
- ããŒã¯ã³ã®ãœãŒã¹ã®è¿œè·¡ã¯èª¿æ»ã«åœ¹ç«ã¡ãŸãã
- èšå®ãæ£åžžã«æ©èœããŠããããšãå確èªããŠãã ããã
- å¯èœãªå Žå㯠X-Forwarded-For ããããŒãç¡å¹åããŠãã ããã
- ã¬ã¬ã·ãŒã¯ãããŸã§ãã¬ã¬ã·ãŒãªã®ã§ãå¯èœãªéã䜿çšããªãããã«ããŠãã ããã
- MFAã¯ãã¯ã©ãŠãã»ãã¥ãªãã£ã§å¹æã¯ãããŸãããäžèœã§ã¯ãããŸãããæ»æè ã¯ãã®ãããªè匱æ§ãã以åã®ããã°ã§èª¬æãããã®ä»ã®æ¹æ³ãå¿ ãèŠã€ããŸããäžæŠçºèŠãããšã圌ãã¯ãããèªååããŠæŠåšåãããã®åŸãã£ãšãããŸããŸãªçµç¹ãžã®äŸµå ¥ã«å©çšããŸããã»ãã¥ãªãã£ã®åŒ·åã«ã¯ãæå¹ãªã¯ã©ãŠã ã»ãã¥ãªã㣠ãœãªã¥ãŒã·ã§ã³ ã¹ã€ãŒã (è åšæ€åºã«åŒ·ã CASB ãªã©) ãš MFA ã®äœµçšãæšå¥šããŸãã
ããã«è©³çްïŒ
ãœãªã¥ãŒã·ã§ã³ã®è©³çްã«ã€ããŠã¯ã以äžã®CASB ã¹ã¿ãŒãã¬ã€ããã¯ã€ãããŒããŒãåèã«ããŠãã ããã
- CASBã¹ã¿ãŒãã¬ã€ãïŒCASBã«ããä¿è·ïŒå ¥éç·šïŒ
- CASBã¹ã¿ãŒãã¬ã€ãïŒã·ã£ããŒITã®åœ±
- CASBã¹ã¿ãŒãã¬ã€ãïŒã¯ã©ãŠãã®èª²é¡ãä¹ãè¶ãã
- CASBã¹ã¿ãŒãã¬ã€ãïŒCASBãšé²ããã¯ã©ãŠãã®æããæªæ¥
æ¬ããã°ã¯è±èªçããã°ãTechnical Deep Dive: Vulnerabilities Bypass Multi-Factor Authentication for Microsoft 365ãã®ç¿»èš³ã§ãã