äž»ãªãã€ã³ã
- å€èŠçŽ èªèšŒãæšæºçãªã»ãã¥ãªãã£ææ³ã«ãªãã«ã€ããå€èŠçŽ èªèšŒã®ããŒã¯ã³ãçã¿ããã®ã»ãã¥ãªãã£å±€ãåé¿ããããã®ãã£ãã·ã³ã°ããããæä»£ãšãšãã«é²å
- è åšãšãªã人ç©ã¯ãééåãªããŒã¹ãããã·ãå©çšããŠããã©ãŠã¶ã»ãã·ã§ã³ã®äžéè ïŒMitMïŒãšãªããèªèšŒæ å ±ãã»ãã·ã§ã³ã¯ãããŒããªã¢ã«ã¿ã€ã ã§çãããšãå¯èœã«ãããã£ãã·ã³ã°ãããã䜿çš
- ä»åŸããã®ãããªMitMåã®ãã£ãã·ã³ã°ã»ããããå©çšããè åšè ãå¢ããããšãäºæ³ããã
æŠèŠ
1961幎ã«MITïŒããµãã¥ãŒã»ããå·¥ç§å€§åŠïŒã®Compatible Time-Sharing SystemïŒäºææ§ã®ããæéå ±æã·ã¹ãã ïŒã«åããŠãã¹ã¯ãŒããå°å ¥ãããŠä»¥æ¥ã人ã ã¯æ å ±ã»ãã¥ãªãã£ãæèããŠããŸãããå€èŠçŽ èªèšŒïŒMFAïŒãç»å Žããã®ã¯ããã®æ°å¹ŽåŸã®1986幎ãæåã®RSAããŒã¯ã³ãç»å ŽããŠããã§ãããæè¿ã§ã¯ã³ã³ã·ã¥ãŒãåãã«ãåºãæ®åããŠããŸããMFAããžã¿ã«èªèšŒã·ã¹ãã ãæäŸããDuoç€Ÿãæ¯å¹Žçºè¡šãããState of the Auth Report ãã«ãããšã2017幎ã«ã¯28ïŒ ã«éããªãã£ã2/å€èŠçŽ èªèšŒïŒ2FA/MFAïŒãã2021幎ã«ã¯78ïŒ ã®åçè ãå©çšããŠããŸããDuoãRSAã®ãããªå€ãã®äŒæ¥ããMFAããããŠããã¿ã¹ã§ãŠãŒã¶ãŒãã¬ã³ããªãŒãªãã®ã«ããŠããäžæ¹ã§ãæ»æè ã¯MFAãã¿ãŒã²ããã«ããããé²åãããã£ãã·ã³ã°ãããã䜿ã£ãŠMFAããã€ãã¹ããæ¹æ³ã暡玢ãããããŠããŸãã

å³1. Duo State of the Auth Report 2021ã§ã¯ãMFAã®äœ¿çšçãå¢å
MFAãã£ãã·ã³ã°ãããã®é²å
ãã£ãã·ã³ã°ã»ãããã¯ãæ»æè ãèªèšŒæ å ±ãååŸãããããçŽ æ©ãå©çšããããã«éçºããããœãããŠã§ã¢ã§ãããããã®ãããã®å€ãã¯ãã³ãŒããŒ1æ¯å以äžã®å€æ®µã§è³Œå ¥ããããšãã§ããŸããããã®å€ãã¯ãè åšã®ãã人ç©ãææããå°çšãµãŒããŒã«ã€ã³ã¹ããŒã«ãããããäžéãªåäººãææããå±éºãªãµãŒããŒã«å¯ãã«ã€ã³ã¹ããŒã«ããããããŸãããã«ãŒããã€ã³ãã®è åšãªãµãŒãã£ãŒã¯ã人éãèªããã³ãŒããšæ©èœãåããã·ã³ãã«ãªãªãŒãã³ãœãŒã¹ã»ãããããããŠãŒã¶ãŒåããã¹ã¯ãŒããMFAããŒã¯ã³ã瀟äŒä¿éçªå·ãã¯ã¬ãžããã«ãŒãçªå·ãçãããšãã§ãããäœå±€ãã®é£èªåãšå èµã¢ãžã¥ãŒã«ãå©çšããé«åºŠãªããããŸã§ãæ°å€ãã®MFAãã£ãã·ã³ã°ã»ãããã確èªããŠããŸãããããã®ãããã®ç®çã¯ããŠãŒã¶ãŒåãšãã¹ã¯ãŒãã®ã¿ãçãåŸæ¥ã®ããããšåãæè¡ã䜿ã£ãŠèªèšŒæ å ±ãçªåããããšã§ãã

å³2. èªèšŒæ å ±ãããããšåããŠã§ããµãŒãã«ä¿åãããªãŒãã³ã»ãã£ã¬ã¯ããªãå©çšããã·ã³ãã«ãªãã£ãã·ã³ã°ã»ããã
è¿å¹Žããã«ãŒããã€ã³ãã®ç ç©¶è ã¯ãæšçãšãªãWebãµã€ãã®åçŸã«é Œããªãæ°ããã¿ã€ãã®ãããã®åºçŸã確èªããŠããŸãããããã®ãããã¯ãééåãªããŒã¹ãããã· ã䜿çšããŠãå®éã®Webãµã€ãã被害è ã«æç€ºããŸããæè¿ã®WebããŒãžã¯åçã§ãé »ç¹ã«å€åããŸãããã®ãããè€è£œã§ã¯ãªãå®éã®ãµã€ããæç€ºããããšã§ãå人ãå®å šã«ãã°ã€ã³ããŠãããã®ãããªé¯èŠãäžããããšãã§ããŸãããªããŒã¹ãããã·ã®ãã1ã€ã®å©ç¹ã¯ãã»ãã·ã§ã³ããã³ã€ã³ã¶ããã«ïŒMitMïŒæ»æã«ããããŠãŒã¶ãŒåããã¹ã¯ãŒãã ãã§ãªããã»ãã·ã§ã³ã¯ãããŒããªã¢ã«ã¿ã€ã ã§ååŸã§ããããšã§ãã

å³ 3. MitMã®ééåãªããŒã¹ãããã·
ãã®åŸãã»ãã·ã§ã³ã»ã¯ãããŒïŒå³4åç §ïŒãå©çšããŠããŠãŒã¶ãŒåããã¹ã¯ãŒããMFAããŒã¯ã³ãå¿ èŠãšããã«ãæ»æè ã¯æšçãšãªãã¢ã«ãŠã³ãã«ã¢ã¯ã»ã¹ããããšãã§ããŸãã

å³4. Evilginx2ã®LinkedInã»ãã·ã§ã³ã¯ãããŒã®äŸ
ãã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒã¯ããããã®ãã£ãã·ã³ã°ã»ãããã®äœ¿çšããããã«å¢å ããŠããããšãææããŠãããMFAã®é©å¿ãäœåãªããããŠããããšãããæ»æè ããã®ããããããã«æ»æã«æ¡çšããããšãäºæ³ããŠããŸããå ·äœçã«ã¯ã3ã€ã®éæåãªããŒã¹ãããã·ã®ããããç»å ŽããŠããããšã確èªããŠããŸãã
ãªããŒã¹ãããã·ã®ãã£ãã·ã³ã°ããã
Modlishka: ããŒã©ã³ãã®ã»ãã¥ãªãã£ç ç©¶è ã§ããPiotr DuszyÅskiæ°ãModliskaãéçºãã2018幎12æã«github.comã§å ¬éããŸããããã®æ¯èŒçã·ã³ãã«ãªããŒã«ã¯ãäžåºŠã«1ã€ã®ãµã€ãããã£ãã·ã³ã°ããããšãã§ããã³ãã³ãã©ã€ã³ã€ã³ã¿ãŒãã§ã€ã¹ãåããŠãããæ»æè ã«èªèšŒæ å ±ãã»ãã·ã§ã³æ å ±ãååŸããããã®äŸ¿å©ãªGUIãæäŸããŸãïŒå³5åç §ïŒããŸããModlishkaã¯Let's Encryptãçµ±åããŠããããã©ãã£ãã¯ãæå·åãããããŠã§ãããŒã«å°ããªå京é ã衚瀺ãããããããšã§ãåœãã¡ã€ã³ã®ã©ã³ãã£ã³ã°ããŒãžã®ä¿¡é Œæ§ãé«ããŠããŸããModlishka ã¯ããã®ããã°ã§åŸè¿°ããä»ã® 2 ã€ã®ãããã»ã©é«åºŠã§ã¯ãªããããããŸããããDuo ã®ããã·ã¥éç¥ã®ãã㪠èªèšŒã䜿ãããŠããå Žåã§ãã被害è ã®ã»ãã·ã§ã³ãçªåããããšãã§ããŸãã

å³5ïŒModliskaã®ã°ã©ãã£ã«ã«ã»ãŠãŒã¶ãŒã»ã€ã³ã¿ãŒãã§ãŒã¹ïŒGUIïŒ
Muraena/Necrobrowser: Muraena/Decrobrowserã¯ãã»ãã·ã§ã³ã¯ãããŒãã¯ã¬ãã³ã·ã£ã«ãªã©ããã£ãã·ã³ã°ããããã®2ã€ã®ããŒã«ã§ãã2019幎ã«Giuseppe Trottaæ°ãšMichele Orrùæ°ã«ãã£ãŠäœæãããMuraenaã¯ããµãŒããŒãµã€ãã§åäœããã¯ããŒã©ãŒã䜿çšããŠã¿ãŒã²ãããµã€ããã¹ãã£ã³ãã被害è ã«èŠåãäžããªãããã«å¿ èŠãªãã¹ãŠã®ãã©ãã£ãã¯ãé©åã«æžãæããããããã«ããŸãã被害è ã®èªèšŒæ å ±ãšã»ãã·ã§ã³ã»ã¯ãããŒãååŸããåŸã¯ãNecrobrowserãå±éããŸããNecrobrowserã¯ãèªååã«äœ¿ãããGUIãæããªããããã¬ã¹ã»ãã©ãŠã¶ã§ãçãã ã»ãã·ã§ã³ã»ã¯ãããŒãå©çšããŠæšçãµã€ãã«ãã°ã€ã³ãããã¹ã¯ãŒãã®å€æŽãGoogle Workspaceã®éç¥ã®ç¡å¹åãã¡ãŒã«ã®ãã³ããGitHubã®SSHã»ãã·ã§ã³ã»ããŒã®å€æŽããã¹ãŠã®ã³ãŒãã»ãªããžããªã®ããŠã³ããŒããªã©ãè¡ããŸãã
Evilginx2: Evilginx2ã¯ãã»ãã¥ãªãã£ç ç©¶è ã§ããéçºè ã§ãããKuba Gretzkyæ°ã«ãã£ãŠGolangã§æžãããã䜿ããããééåãªããŒã¹ãããã·ã§ãïŒå³6ïŒããã®ããŒã«ã¯ãç¬èªã«éçºãã "Phishlets"ã䜿çšããŠç°¡åã«ã»ããã¢ãããèšå®ãã§ãããããã¬ããããŒã ãæ»æè ã®éã§äººæ°ã®é«ãããŒã«ã§ãã"phishlets"ãšã¯ããšã³ãžã³ãã¿ãŒã²ãããµã€ããžã®ãããã·ãèšå®ããéã«äœ¿çšããyamlã®èšå®ãã¡ã€ã«ã§ãããã® "phishlets"ãå©çšããããšã§ãè€æ°ã®ãã©ã³ããäžåºŠã«ãã£ãã·ã³ã°ããããã«ãµãŒããèšå®ããããšãã§ããŸããEvilginx2ã§ã¯ãããããã«ã«ã¹ã¿ã ãµããã¡ã€ã³ãšã©ã³ãã£ã³ã°ããŒãžã®URLãèšå®ããããšãã§ããŸãããã®ãããã«ã¯ããã€ãã®ããªã€ã³ã¹ããŒã«ããã "phishlets"ãå«ãŸããŠããŸãããããã«è¿œå ã§äœæããããšãç°¡åã§ãã被害è ãæªæã®ãããªã³ã¯ãã¯ãªãã¯ãããšãã¿ãŒã²ãããµã€ããšåãããã«ãªãœãŒã¹ã衚瀺ãããå®å šãªããŒãžã«ç§»åããŸãã被害è ããã°ã€ã³ãããšãMFAã³ãŒããå«ãèªèšŒæ å ±ãšã»ãã·ã§ã³ã¯ãããŒããªã¢ã«ã¿ã€ã ã§ãµãŒãã«éä¿¡ããã被害è ã¯å¥ã®ããŒãžã«ãªãã€ã¬ã¯ãããããããã®ããŒãžãžã®ã¢ã¯ã»ã¹ãèš±å¯ãããŸããæ»æè ã¯ãçãã ã»ãã·ã§ã³ã»ã¯ãããŒã䜿çšããŠè¢«å®³è ãšããŠãã°ã€ã³ãããã¹ã¯ãŒãã®å€æŽãããŒã¿ã®ã³ããŒã被害è ãžã®ãªãããŸããªã©ã®è€æ°ã®ã¢ã¯ã·ã§ã³ãå®è¡ããããšãã§ããŸãã

å³6. Evilginx2ã®ã³ãã³ãã©ã€ã³ã³ã³ãœãŒã«
Outlook
ãããã®ãããã®ã»ãšãã©ã¯äœå¹ŽãåããååšããŠããŸããããªãåã³æ³šç®ãããŠããã®ã§ããããïŒ Stony Brook倧åŠãšããã¢ã«ããããã¯ãŒã¯ã¹ã®ç ç©¶è ïŒKondracki et alïŒã¯ãæè¿ã®è«æã®äžã§ãMitMãã£ãã·ã³ã°ãããã培åºçã«èª¿æ»ããMitMãã£ãã·ã³ã°ããŒãžãæ¥çã®ç²ç¹ã§ããããšãçºèŠããŸãããç ç©¶è ãã¡ã¯ãPhocaãšåŒã°ããæ©æ¢°åŠç¿ããŒã«ãéçºããçããããã£ãã·ã³ã°ããŒãžãã¹ãã£ã³ããŠãMitMã®èªèšŒæ å ±ã«å¯ŸããŠééåãªããŒã¹ãããã·ã䜿çšããŠãããã©ããã倿ããŸããããã®çµæã1200以äžã®MitMãã£ãã·ã³ã°ãµã€ããç¹å®ããããšãã§ããŸããããã®1200以äžã®ãµã€ãã®ãã¡ãVirusTotalã®ãããªäžè¬çãªãããã¯ãªã¹ãã«ç»é²ãããŠããã®ã¯ããã¡ã€ã³ã§43.7%ãIPã¢ãã¬ã¹ã§18.9%ã§ãããããã«ãæšæºçãªãã£ãã·ã³ã°ãµã€ãã®å¯¿åœã¯24æé匱ã§ããã®ã«å¯ŸããMitMãã£ãã·ã³ã°ãµã€ãã¯ãããããé·ãã15%ã¯20æ¥ä»¥äžã§ããããšãããããŸãããæè¿ã§ã¯ã2021幎1ææ«ã«ããã«ãŒããã€ã³ãã®ãªãµãŒãã£ãŒãã72æéä»¥äžæŽ»åããŠããMitMãªããŒã¹ãããã·ãµã€ãã確èªããŠããŸãã

å³ 7. MitM O365ã®ããŒãž (ãã«ãã¹ã§ãªãå ŽåNSFWã³ã³ãã³ãã«ãªãã€ã¬ã¯ããããããããã¡ã€ã³ãç·šéããŠããŸãïŒ
2021幎5æãGoogleã¯ããã°ã§ã2021幎åŸåãã2022幎ååã®éã«ãGoogleã¢ã«ãŠã³ããžã®ãã°ã€ã³æã«MFAãå¿ èŠãšããããã«ãªãã ãããšè¿°ã¹ãŸããïŒGoogle Workspaceãå©çšããŠããå Žåã¯ãªãã·ã§ã³ïŒãçŸåšã¯2022幎ã§ããããã³ãããã¯ã¯ãŸã çåšãæ¯ãããå€ãã®åŸæ¥å¡ã¯ãŸã èªå® ã§ä»äºãããŠãããå€ãã®åŽåè ããªãã£ã¹ã«æ»ãããšã¯ãªããããããŸãããGoogle瀟ã«ç¶ããMFAã®å°å ¥ã矩åä»ããäŒæ¥ãå¢ããã°ãè åšãšãªãäŒæ¥ã¯ãã®MitMãããã®ãããªãœãªã¥ãŒã·ã§ã³ã«æ¥éã«ç§»è¡ããã§ããããMitMãããã¯ãå°å ¥ã容æã§ãç¡æã§äœ¿çšã§ããæ€åºãåé¿ãã广ãããããšãå®èšŒãããŠããŸããæ¥çã¯ãäºæãã¬æ°ããæ¹åã«é²åããåã«ããã®ãããªç²ç¹ã«å¯ŸåŠããæºåãããå¿ èŠããããŸãã
â»æ¬ããã°ã®æ å ±ã¯ãè±èªã«ããåæãMFA PSA, Oh My!ãã®ç¿»èš³ã§ããè±èªåæãšã®éã§å 容ã®éœéœ¬ãããå Žåã«ã¯ãè±èªåæãåªå ããŸãã