$B%;%-%e%j%F%#%[!<%k(B memo - 2008.10

Last modified: Sat Nov 7 20:17:33 2009 +0900 (JST)


$B!!$3$N%Z!<%8$N>pJs$rMxMQ$5$l$kA0$K!"(B$BCm0U=q$-(B$B$r$*FI$_$/$@$5$$!#(B


$B"#(B 2008.10.31

$B"#(B $BDI5-(B

Microsoft 2008 $BG/(B 10 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!%H%l%s%I%^%$%/%m@=IJ(B + MS08-064 patch $B$N4D6-$G!":F5/F0$;$:$K;HMQ$7B3$1$k$H%V%k!<2hLL$K$J$k$3$H$,$"$kLOMM!#>\:Y$K$D$$$F$O!"(BMicrosoft$B$B$r;2>H!#(B

$B!!(BMS08-067 $B$D$E$-!#(B

$B"#(B $B!V(BOpenOffice.org 2.4.2$B!W8x3+!"(B2$B7o$N@H
(Internet Watch, 2008.10.30)

$B!!(BOpenOffice.org 2.x $B$K7g4Y!#(BWMF / EMF $B%U%!%$%k$N07$$$K7g4Y$,$"$j(B heap buffer overflow $B$,H/@8!"96N,(B StarOffice/StarSuite $BJ8=q$K$h$C$FG$0U$N%3!<%I$rCVE-2008-2237 CVE-2008-2238

$B!!(BOpenOffice.org 2.4.2 $B$G=$@5$5$l$F$$$k!#$^$?!"(BOpenOffice.org 3 $B$K$O$3$N7g4Y$O$J$$!#(BOpenOffice.org Security Team Bulletin $B$b;2>H!#(B

$B"#(B $B!V(BGoogle Chrome$B!W:G?7HG8x3+!"@H
(Internet Watch, 2008.10.31)

$B!!$@$=$&$G$9!#$^$!&B$G$9$+$i!"$J$s$G$b$"$j$G$7$g$&!#(B

$B"#(B $B!V0lIt(BPC$B%a!<%+!<$K$h$k%N!<%H%V%C%/7?%3%s%T%e!<%?!
(SONY, 2008.10.31)

$B!!(BSONY $B@=%P%C%F%j$N(B OEM $B@h(B Note PC $B%Y%s%@!<$,!"A4@$3&$G9g7W(B 10 $BK|8D$N%P%C%F%j!<$N2s<}$r3+;O!#(B

$B!!:#2s$N;v8N860x$K$D$-$^$7$F$O!"(B2004$BG/(B10$B7n$+$i(B2005$BG/(B6$B7n$NFCDj4|4V$N@=B$%i%$%sD4@0$,!"0lIt$NEECS%;%k$NIJ $B!!$5$i$K!"$4$/>/?t$G$O$"$j$^$9$,!"0lItIt:`ITNI$K$h$k$H;W$o$l$k;v8N$b4^$^$l$F$$$^$9!#(B

$B!!>0!"$3$NJ@]$H$J$C$F$$$kEECS%;%k$H$O0[$J$k%?%$%W$NEECS%;%k$G$9!#(B

$B!!$^$?!"J@]$H$J$kEECS%;%k$r;HMQ$7$F$*$i$:!"!H(BVAIO$B!I$K4XO"$9$k2s<}$N$40FFb$O$4$6$$$^$;$s!#(B

$B!!4XO"(B:

$B"#(B Opera 9.62 for Windows Changelog
(Opera, 2008.10.30)

$B!!(B$B=54)(B Opera$B!":#=59f$O(B 2 $B$D$N7g4Y$r=$@5$7$FFC@=%P%$%s%@!<$D$-$G(B 380 $B1_(B Opera 9.62 $BEP>l!#(B2 $B$D$N7g4Y$,=$@5$5$l$F$$$k!#(B

$B!!$J$s$@$+(B Opera 9.61 $B$N;~$bF1$8$h$&$J$3$H$r8@$C$F$$$?$h$&$J5$$,!D!D!#(B

$B"#(B Microsoft$B
($B%H%l%s%I%^%$%/%m(B, 2008.10.31)

$B!!%H%l%s%I%^%$%/%m@=IJ(B + MS08-064 patch $B$N4D6-$G!":F5/F0$;$:$K;HMQ$7B3$1$k$H%V%k!<2hLL$K$J$k$3$H$,$"$kLOMM!#BP>]@=IJ$O0J2<$@$=$&$G!#(B

$B@=IJL>(B $B%P!<%8%g%s(B
$B%&%$%k%9%P%9%?!<(B $B%3!<%]%l!<%H%(%G%#%7%g%s(B 8.0
Trend Micro $B%S%8%M%9%;%-%e%j%F%#(B 5.0
Trend Micro $B%&%$%k%9%P%9%?!<(B $B%S%8%M%9%;%-%e%j%F%#(B 3.6 / 3.5
$B%&%$%k%9%P%9%?!<(B 2009 17.x
$B%&%$%k%9%P%9%?!<(B 2008 16.x
$B%&%$%k%9%P%9%?!<(B2007 $B%H%l%s%I(B $B%U%l%C%/%9(B $B%;%-%e%j%F%#(B 15.x

$B!!?9ED$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!$7$+$7!"$5$-$[$IN.$l$F$-$?%a!<%k%^%,%8%s!V%H%l%s%I%^%$%/%m(B $B%;%-%e%j%F%#%l%]!<%H!W$K$O!"$3$N>pJs$O$J$$$s$@$h$J$"!#(B


$B"#(B 2008.10.30

$B"#(B $B=q@R!V$O$8$a$F$N(BPHP$B%W%m%0%i%_%s%04pK\JT(B5.3$BBP1~!W$K(BSQL$B%$%s%8%'%/%7%g%s@H
($BFA4]9@$NF|5-(B, 2008.10.29)

$B!!=q@R!V(B$B$O$8$a$F$N(BPHP$B%W%m%0%i%_%s%04pK\JT(B5.3$BBP1~(B$B!W$G5-=R$5$l$F$$$k(B dbescape $B4X?t$K7g4Y$,$"$j!"(BSQL $B%$%s%8%'%/%7%g%s$,2DG=!#(B

$B;W$&$K!"%P%$%s%I5!9=$K;w$?5!G=$r<+:n$7$h$&$H$$$&$N$,4V0c$$$G!"$=$s$J$K4JC1$K$G$-$k$b$N$G$O$J$$!#(BPHP$B$N(Bsqlite_xxxx$B7O$N4X?t$K$O%P%$%s%I5!9=$,MQ0U$5$l$F$$$J$$$h$&$@$,!"(B

$B!!(BSQLite $B$C$F$=$s$J$b$s$J$s$@!D!D!#$3$NK\!"=i?4

$B$"$k$$$O!"(BSQLite$B$N;HMQ$r$"$-$i$a!"(BMySQL$B$r;H$C$F$b$h$+$C$?!#(B($BCfN,(B) MySQL$B$G$"$l$P!"(Bmysql_xxxx$B7O$N4X?t$G%P%$%s%I5!9=$,MxMQ$G$-$k!#(B

$B"#(B $BDI5-(B

$B!Z(BCSL$B![(BCSL$B6[5^Cm0U4-5/%l%]!<%H!A?7


$B"#(B 2008.10.29


$B"#(B 2008.10.28

$B"#(B $BDI5-(B

$B"#(B $B$$$m$$$m(B (2008.10.28)
(various)


$B"#(B 2008.10.27

$B"#(B $BDI5-(B

$B$$$m$$$m(B (2008.10.17)

$B9TF0%?!<%2%F%#%s%09-9p$O$I$3$^$G5v$5$l$k$N$+(B

$B$$$m$$$m(B (2008.10.25)

$B!!(BExcel $B$O1GA|G[?.$K$^$G;H$($k$N$G$9$M!#(B$B@$3&=i!"!X(BExcel$B!Y$G2;3Z%S%G%*$rG[?.!'!X(BAC/DC$B!Y$N6J(B (WIRED VISION, 2008.10.27)

Clandillon$B;a$H(BSteve Milbourne$B;a$,2;3Z%S%G%*$H$7$F$O0lHLE*$G$J$$(BExcel$B%U%)!<%^%C%H$rA*$s$@M}M3$O!"$3$N>e$J$/87$7$$4k6H$N%U%!%$%"!<%&%)!<%k$5$(DL$jH4$1$k%S%G%*$r:n$j$?$+$C$?$3$H$K$"$k!#$H$j$"$($:!"(BExcel$B$N%9%W%l%C%I%7!<%H$r

$B!!$"$i!"%;%-%e%j%F%#$M$?$KLa$C$?!#(B


$B"#(B 2008.10.26

$B"#(B $BDI5-(B


$B"#(B 2008.10.25

$B"#(B $BDI5-(B

Microsoft 2008 $BG/(B 10 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!(BMS08-067 $B$D$E$-(B:

$B"#(B $B$$$m$$$m(B (2008.10.25)
(various)

2008.10.27 $BDI5-(B:

$B!!(BExcel $B$O1GA|G[?.$K$^$G;H$($k$N$G$9$M!#(B$B@$3&=i!"!X(BExcel$B!Y$G2;3Z%S%G%*$rG[?.!'!X(BAC/DC$B!Y$N6J(B (WIRED VISION, 2008.10.27)

Clandillon$B;a$H(BSteve Milbourne$B;a$,2;3Z%S%G%*$H$7$F$O0lHLE*$G$J$$(BExcel$B%U%)!<%^%C%H$rA*$s$@M}M3$O!"$3$N>e$J$/87$7$$4k6H$N%U%!%$%"!<%&%)!<%k$5$(DL$jH4$1$k%S%G%*$r:n$j$?$+$C$?$3$H$K$"$k!#$H$j$"$($:!"(BExcel$B$N%9%W%l%C%I%7!<%H$r

$B!!$"$i!"%;%-%e%j%F%#$M$?$KLa$C$?!#(B


$B"#(B 2008.10.24

$B"#(B Multiple problems in Wireshark versions 0.10.3 to 1.0.3
(Wireshark.org, 2008.10.20)

$B!!(BWireshark 0.10.3 $B!A(B 1.0.3 $B$KJ#?t$N7g4Y$,$"$j!"(B1.0.4 $B$G=$@5$5$l$?$=$&$G!#(B CVE-2008-4685 CVE-2008-4684 CVE-2008-4683 CVE-2008-4682 CVE-2008-4681 CVE-2008-4680

$B"#(B $BDI5-(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2008 $BG/(B 10 $B7n(B ($BDjNc30(B)

$B!!(BMS08-067 $B$,6[5^$KDI2C8x3+$5$l$^$7$?!#>\:Y$K$D$$$F$O!"(B Microsoft 2008 $BG/(B 10 $B7n$N%;%-%e%j%F%#>pJs(B$B$N!V(B2008.10.24 $BDI5-(B$B!W$r!#(B

Microsoft 2008 $BG/(B 10 $B7n$N%;%-%e%j%F%#>pJs(B

$B!!(BMS08-067 $B$,6[5^$KDI2C8x3+$5$l$^$7$?!#(B

MS08-067 - $B6[5^(B: Server $B%5!<%S%9$N@H

$B!!(BWindows 2000 / XP / Server 2003 / Vista / Server 2008 $B$K7g4Y!#(BServer $B%5!<%S%9$K7g4Y$,$"$j!"96N,(B RPC $B%j%/%(%9%H$K$h$C$FG$0U$N%3!<%I$rCVE-2008-4250

$B!!(BExploitability Index ($B0-MQ2DG=@-;XI8(B): 1

$B!!$3$N7g4Y$rMxMQ$9$k%&%$%k%9$,4{$KB8:_$9$k!#(B

$B!!4XO"(B:

$B!!!D!D(B Microsoft Server $B%5!<%S%9$N@H ($B%H%l%s%I%^%$%/%m(B, 2008.10.24) $B$K$h$k$H!"(BTSPY_GIMMIV.A $B$O$"$/$^$G967b$N7k2L$H$7$FAw$j9~$^$l$k%Z%$%m!<%I$K$9$.$:!"(BMS08-067 $B7g4Y$X$N967b%3!<%I$O4^$^$l$F$$$J$$$=$&$G$9!#(B


$B"#(B 2008.10.23

$B"#(B $BDI5-(B

$B"#(B Secunia Research: Trend Micro OfficeScan CGI Parsing Buffer Overflows
(secunia, 2008.10.23)

$B!!$3$N7o(B:

$B!!(BCVE-2008-3862

$B!!BP1~$9$kF|K\8lHG(B ($B%&%$%k%9%P%9%?!<(B $B%3!<%]%l!<%H%(%G%#%7%g%s!"%&%$%k%9%P%9%?!<(B $B%S%8%M%9%;%-%e%j%F%#(B) $BMQ(B patch $B$O$^$@$J$$!#(B2 $B=54V8e$/$i$$$K!"(B$B%&%$%k%9%P%9%?!<(B $B%3!<%]%l!<%H%(%G%#%7%g%s(B$B!"(B$B%&%$%k%9%P%9%?!<(B $B%S%8%M%9%;%-%e%j%F%#(B$B$G8x3+$5$l$k$H;W$o$l!#(B

2008.11.19 $BDI5-(B:

$B!!(BOfficeScan 7.0 $BMQ!"(BClient Server Messaging Security 3.5 / 3.6 $BMQ$b=P$F$$$?$h$&$G(B:

$B!!F|K\8lHGMQ(B:

$B!!(B7.0 $BMQ$@$1$^$@$_$?$$!#(B

$B"#(B F-Secure$B%;%-%e%j%F%#4+9p(B FSC-2008-3 RPM$B2r@O$K$*$1$k@H
(F-Secure, 2008.10.22)

$B!!(BF-Secure $B$N%"%s%A%&%$%k%9@=IJ$K7g4Y!#(BRPM $B%U%!%$%k$N=hM}$K$*$$$F(B integer overflow $B$9$k7g4Y$,$"$j!"96N,(B RPM $B%U%!%$%k$r;H$C$FG$0U$N%3!<%I$r

$B!!(BHotfix $BEy$,8x3+$5$l$F$$$k$N$GE,MQ$9$l$P$h$$!#(B

$B"#(B VideoLAN Security Advisory 0809: Buffer overflow in VLC TiVo demuxer
(videolan.org, 2008.10.21)

$B!!(BVLC media player 0.9.0 $B!A(B 0.9.4 $B$K7g4Y!#(BTY $B%U%!%$%k$N%X%C%@$N=hM}$K7g4Y$,$"$j!"96N,(B TY $B%U%!%$%k$K$h$C$F(B stack buffer overflow $B$,H/@8!"G$0U$N%3!<%I$rCVE-2008-4686

$B!!(BVLC media player 0.9.5 $B$GBP1~$5$l$kM=Dj(B ($B8=;~E@$G$O%j%j!<%9$5$l$F$$$J$$(B)$B!#(B TY demux plugin (libty_plugin.*) $B$r:o=|$9$k$3$H$G2sHr$G$-$k!#(B

$B!!4XO"(B:

2008.11.02 $BDI5-(B:

$B!!(BVLC media player 0.9.5 $B$,EP>l$7$F$$$^$9!#$?$@$7!"(BWindows $BHG$N%P%$%J%j$O$^$@B8:_$7$J$$$h$&$G$9!#(B

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2008 $BG/(B 10 $B7n(B ($BDjNc30(B)
(Microsoft, 2008.10.23)

$B!!$&%)%C!"$3$l$O%!%C(B! $BL@F|%j%j!<%9M=Dj$@$=$&$G$9!#(B

2008.10.24 $BDI5-(B:

$B!!(BMS08-067 $B$,6[5^$KDI2C8x3+$5$l$^$7$?!#>\:Y$K$D$$$F$O!"(B Microsoft 2008 $BG/(B 10 $B7n$N%;%-%e%j%F%#>pJs(B$B$N!V(B2008.10.24 $BDI5-!W$r!#(B


$B"#(B 2008.10.22

$B"#(B No School Like The Old School
(doxpara.com, 2008.10.21)

$B!!(Blibspf2 < 1.2.8 $B$K7g4Y!#(BSPF $B%l%3!<%I$N07$$$K7g4Y$,$"$j!"(Bremote $B$+$iG$0U$N%3!<%I$rCVE-2008-2469

$B!!(Blibspf2 1.2.8 $B$G=$@5$5$l$F$$$k!#(B

2008.11.05 $BDI5-(B:

$B!!4XO"(B: JVNVU#183657 - libspf2 $B$N(B DNS TXT $B%l%3!<%I2r@O=hM}$K$*$1$k%P%C%U%!%*!<%P!<%U%m!<$N@H


$B"#(B 2008.10.21

$B"#(B Opera 9.61 for Windows Changelog
(Opera, 2008.10.21)

$B!!(BOpera 9.61 $BEP>l!#(B3 $B$D$N7g4Y$,=$@5$5$l$F$$$k!#(B

$B"#(B $B%-!<%\!<%IBG80;~$NEE<'GH$G>pJsO3$($$!"%9%$%9$N8&5fZ(B
(Internet Watch, 2008.10.21)

$B!!(BTEMPEST $B$H$$$&$H!V%G%#%9%W%l%$!W$,DjHV$@$,!"!VM-@~%-!<%\!<%IBG80;~$KH/@8$9$kHypJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!85$M$?(B: COMPROMISING ELECTROMAGNETIC EMANATIONS OF WIRED KEYBOARDS

$B"#(B Winny$B:n
(Internet Watch, 2008.10.21)

$B!!$d$C$H$O$8$^$k$=$&$G!#(B2009.01.19$B!#85$M$?(B: Winny$B;v7o95AJ?3Bh0l2s4|F|7hDj(B ($BCEJ[8n;N$N;vL3<<(B, 2008.10.21)$B!#(B

$B$&!<$s!"%$%s%?!<%M%C%H%&%)%C%A!#8@$C$?$3$H$H$A$g$C$H0c$&$>$)!#(B

$B"#(B $BDI5-(B

Jack C. Louis and Robert E. Lee to talk about New DoS Attack Vectors

$B!!4XO"(B:

  • CVE-2008-4609

  • CERT-FI Statement on the Outpost24 TCP Issues (CERT-FI)$B!#(B2008.10.17 $BIU$G2~D{$5$l$F$$$k!#(B

    Oct 17. The TCP issue reported by Outpost24 is being coordinated by CERT-FI. We are in a process of determining the impact of the techniques and principles described by the reporters of the issue. We are researching and handling the issue with several vendors from all potentially affected branches of network equipment and software. Once we are fully aware of what types of network equipments and services are most possibly affected, we will make more vendor contacts. Based on previous experience from similar coordination projects, we estimate that the full publication of the details of the issue may take until next year. CERT-FI will publish more information on the developments of the issue coordination as the coordination progresses.
  • Cisco Security Response: Cisco Response to Outpost24 TCP State Table Manipulation Denial of Service Vulnerabilities (Cisco, 2008.10.17)

    Cisco PSIRT research indicates an attacker must complete a TCP three-way handshake to a device to successfully exploit the DoS vulnerabilities. This requirement makes spoofing the source of an attack more challenging. The TCP vulnerabilities that Outpost24 announced are an extension of well-known weaknesses in the TCP protocol.

    It is possible to mitigate the risk of these vulnerabilities by allowing only trusted sources to access TCP-based services. This mitigation is particularly important for critical infrastructure devices. PSIRT recommends the implementation of infrastructure access control lists (IACLs) and control plane policing (CoPP) to protect core network functionality.
  • TCP Resource Exhaustion and Botched Disclosure (insecure.org)$B!#(Bnmap $B$J?M$K$h$k2r@b!#(B

$B"#(B $B$$$m$$$m(B (2008.10.21)
(various)

$B"#(B Google Webmaster Tools warning about hackable sites
(SANS ISC, 2008.10.20)

$B!!(BGoogle $B%&%'%V%^%9%?!<(B $B%D!<%k(B$B$K$*$$$F%F%9%H$rl9g$K$O7Y9p$rH/$9$k$3$H$r8!F$Cf$@$=$&$@!#(B

2008.10.26 $BDI5-(B:

$B!!(BMalware? We don't need no stinking malware! (Google Online Security Blog, 2008.10.24)


$B"#(B 2008.10.20

$B"#(B Changes with Apache 2.2.10
(Apache.org, 2008.10.14)

$B!!(BApache 2.2.10 $BEP>l!#(Bmod_proxy_ftp $B$N(B XSS $B7g4Y(B CVE-2008-2939 $B$,=$@5$5$l$F$$$k!#(Biida $B$5$s!"F#0f$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B"#(B $B9TF0%?!<%2%F%#%s%09-9p$O$I$3$^$G5v$5$l$k$N$+(B
($BF|7P(B, 2008.10.16)

$B!!%f!<%6$N9TF0$r!"=>Mh$h$j$b9-$/DI@W$9$k$h$&$J!V9-9p!Wl$7$F$$$k$H$$$&OC!#(B

  • Web $B%V%i%&%6$G$O!"K,Ld$7$?$3$H$N$"$k%j%s%/$N?'$,JQ2=$9$k!#$3$l$rMxMQ$9$k$H!"(Bbrute force $BE*

    $B$3$NLdBj$O:#$K$O$8$^$C$?$b$N$G$O$J$$$,!"0lN'$J5;=QE*BP1~$O:$Fq$JLOMM!#(B $B9M;!Nc(B: visited$B5?;w%/%i%9$N%S!<%3%s$r=&$&%5!<%S%9$,EP>l(B ($B?eL57n$P$1$i$N$($SF|5-(B, 2008.10.17)

    $B0lN'$J5;=QE*BP1~$,:$Fq$G$"$k$N$J$i!"8D?ME*$K$O!"(BHisotry $B$N@)8f5!G=$rA}$d$7$FMxMQH(B: #1440854 (slashdot.jp)

  • $B7HBSEEOC$G$O!"!V8DBN<1JLHV9f!W$r;H$C$F%f!<%6$N1\MwMzNr$r<}=8$G$-$k!#(B $BF|K\$N%$%s%?!<%M%C%H$,=*N;$9$kF|(B$B$G<($5$l$F$$$k7o!#(B

    $B@$3&$N>o<1$G$O!"$3$N$h$&$J!V%9!<%Q!<(B cookie$B!W$OITE,@Z$G$"$k$H9-$/G'<1$5$l$F$$$k$,!"F|K\$N>o<1$O@$3&$NHs>o<1!#(B

$B!!$3$l$i$O!V8D?M>pJsJ]8nK!!W$K$*$1$k!V8D?M>pJs!W$K$O3:Ev$7$J$$$?$a!"Bh;0

$B!!4XO"(B: $B3ZE7!&%I%j%3%`$N9TF0%?!<%2%C%F%#%s%09-9p!"(BHTML/CSS$B;EMM$NITHw$rFM$$$FK,Ld@h%5%$%H$rD4::(B (slashdot.jp, 2008.10.20)

2008.10.27 $BDI5-(B:

$B!!(B$B!VBh;0 ($BIpED7=;K(B, 2008.10.21)

$B"#(B $BDI5-(B

$B"#(B Microsoft 2008 $BG/(B 10 $B7n$N%;%-%e%j%F%#>pJs(B
(Microsoft, 2008.10.15)

$B!!7W(B 11 $B8D!#(B

MS08-056 - $B7Y9p(B: Microsoft Office $B$N@HpJs$NO3$($$$,5/$3$k(B (957699)

$B!!(BOffice XP $B$K7g4Y!#(BContent-Disposition: attachment $B$,;XDj$5$l$?>l9g$K$O!"$=$NFbMF$r=hM}$;$:%@%&%s%m!<%I%@%$%"%m%0$rI=<($7$J$1$l$P$J$i$J$$(B (KB260519) $B$,!"(Bcdo: $B%W%m%H%3%k%O%s%I%i$G$O$=$N$h$&$J=hM}$,$5$l$F$$$J$+$C$?!#(B CVE-2008-4020$B!"(B cdo$B%W%m%H%3%k%O%s%I%i$rMxMQ$7$?%/%m%9%5%$%H%9%/%j%W%F%#%s%0(B ($BMU$C$QF|5-(B, 2008.10.18)

$B!!(BExploitability Index ($B0-MQ2DG=@-;XI8(B): 2

MS08-057 - $B6[5^(B: Microsoft Excel $B$N@H

$B!!(BExcel 2000 / 2002 (XP) / 2003 / 2007$B!"(BExcel Viewer 2003$B!"(BWord/Excel/PowerPoint 2007 $B%U%!%$%k7A<0MQ(B Microsoft Office $B8_495!G=%Q%C%/!"(BSharePoint Server 2007 (Standard $BHG$r=|$/(B)$B!"(BOffice 2004 for Mac$B!"(BOffice 2008 for Mac$B!"(BOpen XML File Format Converter for Mac $B$K(B 3 $B$D$N7g4Y!#(B

MS08-058 - $B6[5^(B: Internet Explorer $BMQ$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B (956390)

$B!!(BIE 5.01 / 6 / 7 $B$K(B 6 $B$D$N7g4Y!#(B

  • $B%&%#%s%I%&%m%1!<%7%g%s%W%m%Q%F%#$N%/%m%9%I%a%$%s$N@HCVE-2008-2947

    Exploitability Index ($B0-MQ2DG=@-;XI8(B): N/A ($B4{$K96N,%W%m%0%i%`$,B8:_(B)

  • HTML $B%(%l%a%s%H$N%/%m%9%I%a%$%s$N@HCVE-2008-3472

    Exploitability Index ($B0-MQ2DG=@-;XI8(B): 1

  • $B%$$Y%s%H=hM}$N%/%m%9%I%a%$%s$N@HCVE-2008-3473

    Exploitability Index ($B0-MQ2DG=@-;XI8(B): 1

  • $B%/%m%9%I%a%$%s$N>pJs$NO3$($$$N@HCVE-2008-3474

    Exploitability Index ($B0-MQ2DG=@-;XI8(B): 3

  • $B=i4|2=$5$l$F$$$J$$%a%b%j$NGKB;$N@HCVE-2008-3475

    Exploitability Index ($B0-MQ2DG=@-;XI8(B): 2

  • HTML $B%*%V%8%'%/%H$N%a%b%j$NGKB;$N@HCVE-2008-3476

    Exploitability Index ($B0-MQ2DG=@-;XI8(B): 3

$B!!!V6[5^!W$J$N$O(B IE 5.01 / 6 $B$N$_!#(BIE 7 $B$O:GBg$G$b!V=EMW!W!#(B

$B!!$"$H!"(BMS08-058 patch $B$K4^$^$l$k!"%;%-%e%j%F%#$G$O$J$$=$@5(B (KB955832):

MS08-059 - $B6[5^(B: Host Integration Server $B$N(B RPC $B%5!<%S%9$N@H

MS08-060 - $B6[5^(B: Active Directory $B$N@H

MS08-061 - $B=EMW(B: Windows $B%+!<%M%k$N@H:3J$5$l$k(B (954211)

$B!!(BWindows 2000 / XP / Server 2003 / Vista / Server 2008 $B$N(B kernel $B$K(B 3 $B$D$N7g4Y!#(B

  • Windows $B%+!<%M%k$N%&%#%s%I%&:n@.$N@HCVE-2008-2250

    Exploitability Index ($B0-MQ2DG=@-;XI8(B): 1

  • Windows $B%+!<%M%k$NNc30L$=hM}$N@HCVE-2008-2251

    Exploitability Index ($B0-MQ2DG=@-;XI8(B): 3

  • Windows $B%+!<%M%k$N%a%b%jGKB;$N@HCVE-2008-2252

    Exploitability Index ($B0-MQ2DG=@-;XI8(B): 1

$B!!$$$:$l$b!"(Blocal user $B$K$h$k8"8B>e>:$r>7$/!#(B

$B!!$J$*!"$3$N(B patch $B$O(B Windows XP $B$G$O(B 2 $BEY%$%s%9%H!<%k$9$k$3$H$K$J$k>l9g$,$"$k!#>\:Y$K$D$$$F$O(B KB954211 $B$r;2>H!#(B

$B!!4XO"(B: MS08-061 : The case of the kernel mode double-fetch (Microsoft Security Vulnerability Research & Defense, 2008.10.14)

MS08-062 - $B=EMW(B: Windows $B%$%s%?!<%M%C%H0u:~%5!<%S%9$N@H

MS08-063 - $B=EMW(B: SMB $B$N@H

MS08-064 - $B=EMW(B: $B2>A[%"%I%l%95-=R;R$N=hM}$N@H:3J$5$l$k(B (956841)

$B!!(BWindows XP / Server 2003 / Vista / Server 2008 $B$K7g4Y!#(B $B!V%a%b%j(B $B%^%M!<%8%c!<$,%a%b%j$N3d$jEv$F$*$h$S2>A[%"%I%l%95-=R;R(B (VAD) $B$r=hM}$9$kJ}K!$K!W7g4Y$,$"$j!"8"8B>e>:$r5v$9!#(B CVE-2008-4036

$B!!(BExploitability Index ($B0-MQ2DG=@-;XI8(B): 2

MS08-065 - $B=EMW(B: $B%a%C%;!<%8(B $B%-%e!<$N@H

MS08-066 - $B=EMW(B: Microsoft Ancillary Function $B%I%i%$%P!<$N@H:3J$5$l$k(B (956803)

$B!!(BWindows XP / Server 2003 $B$K7g4Y!#(BAncillary Function $B%I%i%$%P!<(B (afd.sys) $B$K7g4Y$,$"$j!"(Blocal user $B$K$h$k8"8B>e>:$r>7$/!#(B CVE-2008-3464$B!"(BMS Windows XP/2003 AFD.sys Privilege Escalation Exploit (K-plugin) (milw0rm)$B!"(B MS08-066 : Catching and fixing a ProbeForRead / ProbeForWrite bypass (Microsoft Security Vulnerability Research & Defense, 2008.10.14)

$B!!(BExploitability Index ($B0-MQ2DG=@-;XI8(B): 1

$B!!4XO"(B:

2008.10.24 $BDI5-(B:

$B!!(BMS08-067 $B$,6[5^$KDI2C8x3+$5$l$^$7$?!#(B

MS08-067 - $B6[5^(B: Server $B%5!<%S%9$N@H

$B!!(BWindows 2000 / XP / Server 2003 / Vista / Server 2008 $B$K7g4Y!#(BServer $B%5!<%S%9$K7g4Y$,$"$j!"96N,(B RPC $B%j%/%(%9%H$K$h$C$FG$0U$N%3!<%I$rCVE-2008-4250

$B!!(BExploitability Index ($B0-MQ2DG=@-;XI8(B): 1

$B!!$3$N7g4Y$rMxMQ$9$k%&%$%k%9$,4{$KB8:_$9$k!#(B

$B!!4XO"(B:

$B!!!D!D(B Microsoft Server $B%5!<%S%9$N@H ($B%H%l%s%I%^%$%/%m(B, 2008.10.24) $B$K$h$k$H!"(BTSPY_GIMMIV.A $B$O$"$/$^$G967b$N7k2L$H$7$FAw$j9~$^$l$k%Z%$%m!<%I$K$9$.$:!"(BMS08-067 $B7g4Y$X$N967b%3!<%I$O4^$^$l$F$$$J$$$=$&$G$9!#(B

2008.10.26 $BDI5-(B:

$B!!(BMS08-067 $B$D$E$-(B:

2008.10.28 $BDI5-(B:

$B!!(BMS08-067 $B$D$E$-!#(B

2008.10.31 $BDI5-(B:

$B!!%H%l%s%I%^%$%/%m@=IJ(B + MS08-064 patch $B$N4D6-$G!":F5/F0$;$:$K;HMQ$7B3$1$k$H%V%k!<2hLL$K$J$k$3$H$,$"$kLOMM!#>\:Y$K$D$$$F$O!"(BMicrosoft$B$B$r;2>H!#(B

$B!!(BMS08-067 $B$D$E$-!#(B

2008.11.04 $BDI5-(B:

$B!!(BMS08-067 $B$D$E$-!#$D$$$KMh$?$h$&$G$9!#!V=`Hw$G$-$F$k(B?$B!W(B

2008.11.05 $BDI5-(B:

$B!!(BMS08-067 $B$D$E$-!#(B

2008.11.07 $BDI5-(B:

$B!!(BMS08-067 $B$D$E$-!#(B

2008.11.12 $BDI5-(B:

$B!!(BMS08-067 $B$D$E$-!#(B

2008.11.17 $BDI5-(B:

$B!!(BMS08-067 $B$D$E$-!#(B

2008.11.26 $BDI5-(B:

$B!!(BMS08-067 $B$D$E$-!#(B

2008.11.28 $BDI5-(B:

$B!!(BMS08-067 $B$D$E$-!#(B

2008.12.05 $BDI5-(B:

$B!!(BMS08-066 patch $B$K$O!"(BCheckpoint ZoneAlarm Pro 6.5.645.000$B!A(B7.0.482.000 $B$J$I$HIT@09g$r5/$3$9LdBj$,$"$C$?$=$&$J$N$G$9$,!"(B KB958752 patch $B$rE,MQ$9$k$3$H$G$3$NLdBj$KBP1~$G$-$k$=$&$G$9!#(B $B$b$C$H$b!"(BZoneAlarm Pro 7.0.483.00 $B0J9_$rMxMQ$9$k$3$H$G$bBP1~$G$-$k$=$&$G$9$,!#(B

2008.12.08 $BDI5-(B:

$B!!(BMS08-067 $B$D$E$-!#(B

2008.12.18 $BDI5-(B:

$B!!(BMS08-067 $B$rFM$/%o!<%`$,4k6HFb%M%C%H%o!<%/$GN.9T$C$?;vNc$,$$$/$D$+=P$?$i$7$$!#(B

2009.04.18 $BDI5-(B:

$B!!(BHow Conficker makes use of MS08-067? (milw0rm, 2009.04.14)

2009.11.07 $BDI5-(B:

$B!!4XO"(B:


$B"#(B 2008.10.19


$B"#(B 2008.10.18

$B"#(B $BDI5-(B

$B%"%I%S(B $B%7%9%F%`%:!"(B Adobe Flash Player 10$B$NDs6!$r3+;O(B

$B!!%P!<%8%g%sHV9f$,(B 2 $B7e$K$J$C$?$;$$$G!"3FCO$G%o%C%7%g%$$K$J$C$F$$$k$h$&$G$9!#(B


$B"#(B 2008.10.17

$B"#(B $BDI5-(B

$B%/%j%C%/%8%c%C%-%s%0!'8&5f

$B!!(BFlash Player $B$K$D$$$F$O!"(BFlash Player 10 $B$GBP1~$5$l$?$=$&$G!#(B

$B!!$"$H!"4XO"(B:

  • Clickjacking (McAfee blog, 2008.10.15)$B!#8D?ME*$K$O!"$3$N@bL@"-$,$$$A$P$s$o$+$j$d$9$+$C$?!#(B

    To explain this, let's use an example. You have a web page A controlled by an attacker. A contains an element B. In a clickjack attack, B would be set to transparent and the z-index property of the layer set to higher than other elements of page A via CSS. B will also need to be so big so that the user can click it's content. The attacker can then place any button to do anything he wants in B. Then the attacker can place some buttons on page A. The location of the buttons in B must match the buttons in A. So when the user clicks on a button on page A, they are actually clicking the button in B because the z-index property of B's buttons are higher than A's buttons. This attack uses DHTML, does not require Javascript, so disabling Javascript will not help.
  • Clickjacking Details (ha.ckers.org, 2008.10.07)$B!#$^$@D>$C$F$J$$$H$5$l$F$$$k9`L\$b$$$m$$$m$"$k$h$&$G!#(B

    Source to generic clickjacking code available here.

    $B$3$N(B generic clickjacking code $B$K$O(B Flash $B$O;H$o$l$F$$$J$$$h$&$K8+$($k!#(B

  • Malicious camera spying using ClickJacking (GUYA.NET, 2008.10.07)$B!#$3$A$i$O(B Flash $B$r;H$&Nc$J$N$+$J!#(B

  • $B%f!<%6$N%/%j%C%/$r>h$C (slashdot.jp, 2008.09.27)$B!"(B CSS + Flash (slashdot.jp, 2008.09.27)

  • Adobe$B$d(BNoScript$B$+$i%/%j%C%/%8%c%C%-%s%0BP:vH/I=$5$l$k(B (slashdot.jp, 2008.10.13)$B!#(Bgeneric $B$H$$$&$N$O!"(Bbrowser generic $B$H$$$&$3$H$J$N$G$O!#(BIE $B$G$b(B Firefox $B$G$b(B Opera $B$G$bF0$/$h!"$H$$$&46$8!#(B MS-DOS generic $B$H$$$&8@$$J}!"@N$O$h$/;H$C$?$1$I$J!#(B

  • $B$3$l$b4XO"$+$J$"(B: Ending Expressions (IEBlog, 2008.10.16)$B!#(BIE8 standards mode $B$G$O(B CSS expression $B$r%5%]!<%H$7$J$$$3$H$K$7$?OC!#(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (951306) Windows $B$N@H:3J$,9T$o$l$k(B

$B!!4XO"(B:

$B"#(B $B$$$m$$$m(B (2008.10.17)
(various)


$B"#(B 2008.10.16

$B"#(B $B%N!<%H%s!&%*%s%4!<%$%s%0%W%m%F%/%7%g%s$KCm0U(B
(amazon.co.jp, 2008.09.19)

$B!!(BNorton Internet Security 2009 (amazon.co.jp) $B$rH/Cm$7$h$&$H$7$F%"%/%;%9$7$?$i!"%+%9%?%^!$B8@$C$F$$$k?M(B$B$,$$$k!#(B

$B%Q%C%1!<%8HG$r9XF~$7$F#1G/8e$K%5!<%S%94|8B1dD9$K$J$k?M$H!"%@%&%s%m!<%IHG$r9XF~$7$??M$OK\Ev$K5$$r$D$1$?J}$,$$$$$G$9!#!V%N!<%H%s!&%*%s%4!<%$%s%0%W%m%F%/%7%g%s!W$H$O!"%Q%=%3%s$+$i%N!<%H%s$r%"%s%$%s%9%H!<%k$7$h$&$,!"B>h$j49$($h$&$,!"%Q%=%3%s$r;H$o$J$/$J$m$&$,!"$*$+$^$$$J$/!VKhG/99?7NA$r%/%l%8%C%H0z$-Mn$H$7$7B3$1$^$9$h!W$H$$$&$3$H$G$9$+$i!#(B
$B%5!<%S%999?7;~$K$=$&$$$&%7%9%F%`$KF10U$7$?$3$H$K$5$l$F$7$^$&$h$&$J$N$G!"I,$:!V%N!<%H%s!&%*%s%4!<%$%s%0%W%m%F%/%7%g%s!W$r2r=|$9$k$h$&$K$7$^$7$g$&!#(B

$B!!$&$X$'!#(B

$B$b$C$H$b!"2r=|$NJ}K!$O%7%^%s%F%C%/

$B!!$J$s$8$c$=$j$c!"$H;W$C$F!V(B$B99?7%5!<%S%94|8B<+F01dD9!J%N!<%H%s!&%*!<%H%^%A%C%/%j%K%e!<%"%k%5!<%S%9!K$K$D$$$F(B$B!W(B ($B%7%^%s%F%C%/(B) $B$r8+$k$H!"3N$+$K2r=|J}K!$O$I$3$K$b=q$+$l$F$$$J$$!D!D!#2?$3$l!D!D!#(B $B$B<+F01dD9%5!<%S%9$NDd;_%U%)!<%`(B ($B%7%^%s%F%C%/(B) $B$+$i$N%-!<%o!<%I(B: $B%N!<%H%s(B $B%*%s%4!<%$%s%0%W%m%F%/%7%g%s(B $B:>5=(B $B%N!<%H%s(B $B%*%s%4!<%$%s%0%W%m%F%/%7%g%s(B $B2rLs!W$H=P$F$/$k$N$b!"$J$+$J$+$9$4$$$b$N$,$"$j$^$9$M!D!D!#(B

$B!!%H%i%V%k;vNc$OKg5s$K$$$H$^$,$J$$$h$&$G(B:

$B!!%7%^%s%F%C%/$N%5%]%;%s$NBP1~$b$R$I$$$J$"!#$3$l$G$O!"$$$/$i@-G=$,$h$/$F$b?M$K4+$a$i$l$J$$$h!D!D!#(B

$B"#(B Oracle Critical Patch Update Advisory - October 2008
(Oracle, 2008.10.14)

$B!!(BOracle 2008.10 $BHG=P$F$$$^$9!#%G!<%?%Y!<%9%=%U%H$@$1$G$O$J$/!"(BOracle WebLogic Server $B$d(B Oracle Workshop for WebLogic $B$N=$@5$b4^$^$l$F$$$^$9$N$GCm0U!#(B

$B"#(B $BDI5-(B

$B%"%I%S(B $B%7%9%F%`%:!"(B Adobe Flash Player 10$B$NDs6!$r3+;O(B

$B!!(BAPSB08-18 $B$,8x3+$5$l$^$7$?!#(BAPSA08-08 $B$b2~D{$5$l$F$^$9!#(B

$B!!(BFlash Player 10 $B$G$O!"(BClickjacking $B$NB>$K$b!"(B$B%/%j%C%W%\!<%I$N7o(B$B$J$IJ#?t$N7g4Y$KBP1~$5$l$F$$$k$=$&$G$9!#(B

$B"#(B CORE-2008-1010: VLC media player XSPF Memory Corruption
(CORE Security Technologies, 2008.10.15)

$B!!(BVLC media player 0.9.2 ($B0JA0(B?) $B$K7g4Y!#(BXSPF $B%W%l%$%j%9%H%U%!%$%k$N07$$$K7g4Y$,$"$j!"%a%b%jGK2u$,H/@8!#96N,(B XSPF $B%U%!%$%k$r;H$C$FG$0U$N%3!<%I$r

$B!!(BVLC media player 0.9.3 $B0J9_$G=$@5$5$l$F$$$k!#:G?7HG$O(B 0.9.4$B!#(B


$B"#(B 2008.10.15

$B"#(B $B%"%I%S(B $B%7%9%F%`%:!"(B Adobe Flash Player 10$B$NDs6!$r3+;O(B
(Adobe, 2008.10.15)

$B!!$3$s$J$3$H$,=q$+$l$F$$$^$9!#(B

$B$h$j%;%-%e%"$J4D6-$r(BFlash Player $BFb$Gl9g$,$"$j$^$9!#$^$?!"%;%-%e%j%F%#%k!<%k$NJQ99$KH<$C$F!"0JA0$O;HMQ$G$-$J$+$C$?5!G=$d@)8B$5$l$F$$$?5!G=$K%"%/%;%9$G$-$k>l9g$b$"$j$^$9!#0J2<$N(BAdobe Developer Connection $B$N5-;v$r3NG'$N>e!"99?7$r9T$&$3$H$G!"4{B8%3%s%F%s%D$,%;%-%e%"$J4D6-$G!"@5$7$/F0$/$3$H$,3NG'$G$-$^$9!#(B

Flash Player 9$B$*$h$S(BFlash Player 10$B%Y!<%?$N%]%j%7!<%U%!%$%kJQ99E@$X$NBP1~(B
http://www.adobe.com/jp/devnet/flashplayer/articles/fplayer9-10_security.html

2008.10.16 $BDI5-(B:

$B!!(BAPSB08-18 $B$,8x3+$5$l$^$7$?!#(BAPSA08-08 $B$b2~D{$5$l$F$^$9!#(B

$B!!(BFlash Player 10 $B$G$O!"(BClickjacking $B$NB>$K$b!"(B$B%/%j%C%W%\!<%I$N7o(B$B$J$IJ#?t$N7g4Y$KBP1~$5$l$F$$$k$=$&$G$9!#(B

2008.10.19 $BDI5-(B:

$B!!%P!<%8%g%sHV9f$,(B 2 $B7e$K$J$C$?$;$$$G!"3FCO$G%o%C%7%g%$$K$J$C$F$$$k$h$&$G$9!#(B

2008.11.07 $BDI5-(B:

$B!!(BFlash Player 9.0.151.0 $B$,8x3+$5$l$^$7$?!#(B Flash Player 10.0.12.36 / 9.0.151.0 $B$K6&DL$7$F=$@5$5$l$F$$$k7g4Y$,J#?t$"$k$=$&$G$9!#(B

$B!!(BFlash Player $B%@%&%s%m!<%I(B (Adobe)$B!#$?$@$7!"?d>)$5$l$F$$$k$N$O(B Flash Player 10.0.12.36 $B$X$N0\9T!#(B

2008.11.18 $BDI5-(B:

$B!!(BFlash Player 10.0.12.36 / 9.0.151.0 $B$K$O(B CVE-2008-4824 $B$H$$$&7g4Y$b$"$C$?$N$@$=$&$G$9!#(B $B$3$N7g4Y$O(B AIR 1.1 $B0JA0$K$b$"$j!"(BAIR 1.5 $B$N%j%j!<%9$K$h$C$F=$@5$5$l$k$^$G8x3+$5$l$^$;$s$G$7$?!#(B

$B"#(B SYM08-017: $B%7%^%s%F%C%/$N%G%P%$%9%I%i%$%P(B $B$K%m!<%+%k$G$NFC8">:3J$N@H
($B%7%^%s%F%C%/(B, 2008.10.07)

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (956391) ActiveX $B$N(B Kill Bit $B$NN_@QE*$J%;%-%e%j%F%#99?7%W%m%0%i%`(B
(Microsoft, 2008.10.15)

$B"#(B Microsoft Exploitability Index ($B0-MQ2DG=@-;XI8(B)
(Microsoft, 2008.10.14)

$B!!(B3 $B

  1. $B0BDj$7$?0-MQ%3!<%I$N2DG=@-(B

  2. $BIT0BDj$J0-MQ%3!<%I$N2DG=@-(B

  3. $B5!G=$9$k8+9~$_$N$J$$0-MQ%3!<%I(B

$B!!$"$/$^$G0BDj$9$k$+$I$&$+$@$1$J$N$@$1$I!"0BDj$7$J$$$b$N$h$j$b0BDj$9$k$b$N$NJ}$,3+H/$OMF0W$G8z2LE*$J$N$G$7$g$&!#(B

$B"#(B $BDI5-(B

nVIDIA$B$N(BGPU$B$GBg5,LO$J%j%3!<%k!"@8;:9)Dx$KIT6q9g$,H/@8$+!)(B

$B!!4XO"(B:

$B"#(B [SA32226] CUPS Multiple Vulnerabilities
(secunia, 2008.10.11)

$B!!(BCUPS < 1.3.9 $B$KJ#?t$N7g4Y!#(B

$B!!(BCUPS 1.3.9 $B$G=$@5$5$l$F$$$k!#(B

$B"#(B Security Notice for CA ARCserve Backup
(CA, 2008.10.09)

$B!!(BCA ARCserve Backup r11.1 / r11.5 / r12.0 Windows, CA Server Protection Suite r2 $B$J$I$K(B 4 $B$D$N7g4Y!#(B

  • CVE-2008-4397$B!#(BRPC $B$G%G%#%l%/%H%j%H%i%P!<%5%k7j!"(Bremote $B$+$iG$0U$N%3%^%s%I$rCA BrightStor ARCServe BackUp Message Engine Remote Command Injection Vulnerability

  • CVE-2008-4398$B!#(Btape engine $B%5!<%S%9$K$*$1$k8!>Z$K7g4Y!"(Bcrash $B$G$-$k!#(B

  • CVE-2008-4399$B!#(Bdatabase engine $B%5!<%S%9$K$*$1$k8!>Z$K7g4Y!"(Bcrash $B$G$-$k!#(B

  • CVE-2008-4400$B!#G'>Z%/%l%G%s%7%c%k$N8!>Z$K7g4Y!"J#?t$N%5!<%S%9$r(B crash $B$G$-$k!#(B

$B!!(Bpatch $B$,$"$k$N$GE,MQ$9$l$P$$$$$_$?$$(B (typo fixed: iida $B$5$s46

$B!!4XO"(B: CA ARCserve Backup Multiple Vulnerabilities (eEye)

$B"#(B About Security Update 2008-007
(Apple, 2008.10.10)

$B!!(BMac OS X 10.4.11 / 10.5.5 $BMQ$N(B Security Update 2008-007 $BEP>l!#(B $BNc$K$h$C$F$$$m$$$mD>$C$F$$$k$N$G$9$,!"$J$s$8$c$3$j$c!D!D(B

Postfix
CVE-ID: CVE-2008-3646
Available for: Mac OS X v10.5.5
Impact: A remote attacker may be able to send mail directly to local users
Description: An issue exists in the Postfix configuration files. For a period of one minute after a local command-line tool sends mail, postfix is accessible from the network. During this time, a remote entity who could connect to the SMTP port may send mail to local users and otherwise use the SMTP protocol. This issue does not cause the system to be an open mail relay. This issue is addressed by modifying the Postfix configuration to prevent SMTP connections from remote machines. This issue does not affect systems prior to Mac OS X v10.5 and does not affect Mac OS X Server. Credit to Pelle Johansson for reporting this issue.

$B!!$o$1$o$+$a$J@_Dj$,$5$l$F$$$?$H$$$&$3$H$J$N$+(B? $B

$B!!9b66$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B


$B"#(B 2008.10.14

$B"#(B $BDI5-(B


$B"#(B 2008.10.10

$B"#(B $B$$$m$$$m(B (2008.10.10)
(various)

$B"#(B Watch that .htaccess file on your web site
(SANS ISC, 2008.10.09)

$B!!$K$;%"%s%A%&%$%k%9Gd>l$X$NM6F3=j$K$"$j$,$A$JFbMF$NNc!#(B.htaccess $B$K5$$r$D$1$^$;$&!#(B

$B"#(B $BDI5-(B

$B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#(B $B%"%I%P%$%6%j(B (951306) Windows $B$N@H:3J$,9T$o$l$k(B

$B!!(B$B1Q8lHG%"%I%P%$%6%j(B$B$,2~D{$5$l$F$$$^$9!#(BPoC $B$,8x3+$5$l$?$=$&$G$9!#(B $BF|K\8lHG%"%I%P%$%6%j(B$B$b$=$N$&$A2~D{$5$l$k$G$7$g$&!#(B

$B!!;2>H(B: Token Kidnapping Windows 2003 PoC exploit (No More Root, 2008.10.07)

$B"#(B $B%^%$%/%m%=%U%H(B $B%;%-%e%j%F%#>pJs$N;vA0DLCN(B - 2008 $BG/(B 10 $B7n(B
(Microsoft, 2008.10.10)

$B!!:#7n$O@9$j$@$/$5$s!#6[5^(B x 4$B!"=EMW(B x 6$B!"7Y9p(B x 1$B!#(B IE $B$d(B Excel $B$N=$@5(B ($B$I$A$i$b6[5^(B) $B$b4^$^$l$F$$$^$9!#(B

$B!!$3$s$J%Z!<%8$,$"$C$?$N$+(B:


$B"#(B 2008.10.09

$B"#(B $B$$$m$$$m(B (2008.10.09)
(various)

$B"#(B Microsoft PicturePusher ActiveX (PipPPush.DLL 7.00.0709) remote Cross Site File Upload attack POC (IE6)
(milw0rm, 2008.10.08)

$B!!(BMicrosoft Digital Image 2006 $B$KIUB0$9$k(B ActiveX $B%3%s%H%m!<%k$K7g4Y$,$"$k$h$&$G!#(BDigital Image 2006 $B$O(B$BHNGdBG$A@Z$jIJ(B$B$@$+$i$J$"!D!D!#%5%]!<%H$C$F$I$&$J$C$F$k$s$@$m$&!#(B


$B"#(B 2008.10.08

$B"#(B $BDI5-(B

$B%/%j%C%/%8%c%C%-%s%0!'8&5f

$B!!(B2 $BBj!#(BFlash $B$H(B NoScript $B$K$D$$$F!#(B

  1. Adobe $B$+$i(B workaround $B=P$^$7$?(B: Flash Player workaround available for "Clickjacking" issue (Adobe, 2008.10.07)$B!#(BFlash $B$K$*$1$k!"30It$+$i$N%+%a%i!&%^%$%/$NA`:n$r6X;_$9$kOC(B ($B%G%U%)%k%H$O5v2D$J$N(B?)$B!#4XO"(B: $B%"%I%S!"(BFlash Player$B$N!V%/%j%C%/>h$C ($BF|7P(B IT Pro, 2008.10.08)

    • $B0lHL%f!<%6(B: $B$^$:$O!"(B [$B%0%m!<%P%k%W%i%$%P%7!<@_Dj(B] $B%Q%M%k(B (macromedia.com) $B$G(B [$B>o$K5qH](B...] ($B1Q8lHG(B: [Always deny...]) $B$r%/%j%C%/!#(B $B$=$N>e$G!"FCDj$N%5%$%H$K$O%+%a%i!&%^%$%/$X$N%"%/%;%9$r5v2D$7$?$$>l9g$K$O!"(B[Web $B%5%$%H$N%W%i%$%P%7!<@_Dj(B] $B%Q%M%k(B (macromedia.com) $B$+$i@_Dj$9$k!#(B

    • IT $B4IM}e5-$N%f!<%6@_Dj$h$j$b(B mms.cfg $B$K$h$k@_Dj$NJ}$,M%@h$5$l$k!#(B mms.cfg $B$O0J2<$N>l=j$K@_CV$9$k$N$@$=$&$@(B:

      • Windows: %WINDIR%\system32\Macromed\Flash

      • Mac OS X: /Library/Application Support/Macromedia

      • Linux Flash 9: /etc/adobe/

      mms.cfg $B$O(B Flash Player 8 $B0J9_$G%5%]!<%H$5$l$F$$$k!#(Bmms.cfg $B$NJ8;z%3!<%I$O!"(BOS $B$N%G%U%)%k%H%3!<%I%Z!<%8!"$"$k$$$O(B BOM $B$D$-$N(B UTF-8 / UTF-16$B!#(B

    $B:,K\E*$JBP1~$K$D$$$F$O!"(B10 $B7nKv$^$G$KEP>l$9$kM=Dj$N(B Flash Player $B$N?7HG$G9T$o$l$k$N$@$=$&$@!#(B

  2. NoScript $B$G$9$,!"(B1.8.2.1 $B0J9_$K%"%C%W%G!<%H$7$?J}$,$$$$$_$?$$(B: Hello ClearClick, Goodbye Clickjacking! (ackademix.net, 2008.10.08)

$B"#(B Opera 9.6 for Windows Changelog
(Opera.com, 2008.10.08)

$B!!(BOpera 9.60 $BEP>l!#(B2 $B7o$N%;%-%e%j%F%#7g4Y$,=$@5$5$l$F$$$k!#(B


$B"#(B 2008.10.07

$B"#(B $BDI5-(B


$B"#(B 2008.10.06

$B"#(B $B$$$m$$$m(B (2008.10.06)
(various)

$B"#(B $BDI5-(B

VMSA-2008-0014: Workstation, VMware Player, VMware ACE, VMware Server, VMware ESX address information disclosure, privilege escalation and other security issues.

$B!!99?7HG%"%I%P%$%6%j(B VMSA-2008-0014.2 $B$,=P$F$$$k!#(B

$B!!(BESX 3.5 / ESXi 3.5 $B$N(B patch $B$,(B 2008.09.18 $BIU$G=P$F$$$k!#(B

VMware ESX / ESXi $B%P!<%8%g%s(B patch
ESXi 3.5 ESXe350-200808501-I-SG
ESX 3.5 ESX350-200808401-BG, ESX350-200808409-SG

$B!!$^$?(B VMware Consolidated Backup (VCB) 1.1 $B$N99?7HG!"(BVCB 1.1 Update 1 build 118380 $B$,(B 2008.10.03 $BIU$G=P$F$$$k!#(B


$B"#(B 2008.10.04


$B"#(B 2008.10.03

$B"#(B Yahoo! JAPAN$B!"0lItMxMQ
(Internet Watch, 2008.10.03)

$B!!(B10/1 $B$+$iL57Y9p$G$$$-$J$j;O$a$F$$$kLOMM!#$=$l$[$I6[5^;vBV$J$N$@$m$&$1$I!"$=$N$o$j$K$O%d%U%*%/$N(B top $B%Z!<%8$K$b2?$b$J$$$7$J$!!D!D!#(B

$B"#(B iPhone$BMQ%a!<%k!&%"%W%j$K%U%#%C%7%s%0(B/$B%9%Q%`Ho32$K$D$J$,$k%;%-%e%j%F%#!&%[!<%k(B
($BF|7P(B IT Pro, 2008.10.03)

$B!!(B2008.07.23 $B$KH/8+(B$B$7$F(B Apple $B$KDLJs$7$?$1$I$<$s$<$s=$@5$5$l$J$$$N$G>\:Y$r8x3+$@$=$&$G$9!#(B

$B"#(B Trend Micro$B$N4k6H8~$1%;%-%e%j%F%#@=IJ$K@H
(ITmedia, 2008.10.03)

$B!!$3$N7o(B:

$B!!BP1~$9$kF|K\8lHG(B ($B%&%$%k%9%P%9%?!<(B $B%3!<%]%l!<%H%(%G%#%7%g%s!"%&%$%k%9%P%9%?!<(B $B%S%8%M%9%;%-%e%j%F%#(B) $BMQ(B patch $B$O$^$@$J$$!#(B2 $B=54V8e$/$i$$$K!"(B$B%&%$%k%9%P%9%?!<(B $B%3!<%]%l!<%H%(%G%#%7%g%s(B$B!"(B$B%&%$%k%9%P%9%?!<(B $B%S%8%M%9%;%-%e%j%F%#(B$B$G8x3+$5$l$k$H;W$o$l!#(B

2008.10.23 $BDI5-(B:

$B!!(B2008.10.22 $BIU$GF|K\8lHG=P$F$^$9!#(B

$B!!(Bpatch $BK\BN$O(B $B%&%$%k%9%P%9%?!<(B $B%3!<%]%l!<%H%(%G%#%7%g%s(B$B!"(B$B%&%$%k%9%P%9%?!<(B $B%S%8%M%9%;%-%e%j%F%#(B$B$+$i$I$&$>!#(B

$B"#(B $BDI5-(B

[SA31342] Trend Micro OfficeScan Server "cgiRecvFile.exe" Buffer Overflow

$B!!(B2008.10.01 $BIU$G!"(B$B%&%$%k%9%P%9%?!<(B $B%3!<%]%l!<%H%(%G%#%7%g%s(B$B$G0J2<$,8x3+$5$l$F$$$^$9!#(B

  • $B%&%$%k%9%P%9%?!<(B $B%3!<%]%l!<%H%(%G%#%7%g%s(B 8.0 $BMQ(B Critical Patch(Build_1361)

  • $B%&%$%k%9%P%9%?!<(B $B%3!<%]%l!<%H%(%G%#%7%g%s(B 8.0 Service Pack 1 $BMQ(B Critical Patch(Build_2424)

  • $B%&%$%k%9%P%9%?!<(B $B%3!<%]%l!<%H%(%G%#%7%g%s(B 7.3 $BMQ(B Critical Patch(Build_1367)

  • $B%&%$%k%9%P%9%?!<(B $B%3!<%]%l!<%H%(%G%#%7%g%s(B 7.0 $BMQ(B Critical Patch(Build_1400)

$B!!(B2008.10.01 $BIU$G!"(B$B%&%$%k%9%P%9%?!<(B $B%S%8%M%9%;%-%e%j%F%#(B$B$G0J2<$,8x3+$5$l$F$$$^$9!#(B

  • Trend Micro $B%&%$%k%9%P%9%?!<(B $B%S%8%M%9%;%-%e%j%F%#(B 3.6 $BMQ(BCritical Patch (Build_1195)

  • Trend Micro $B%&%$%k%9%P%9%?!<(B $B%S%8%M%9%;%-%e%j%F%#(B 3.5 $BMQ(BCritical Patch (Build_1169)

Vulnerability Note VU#800113 - Multiple DNS implementations vulnerable to cache poisoning

$B%4%k%U%@%$%8%'%9%H!&%*%s%i%$%s$GIT@5%"%/%;%9Ho32H/@8(B

$B!!(B2008.10.02 19:30 $B;~E@$G!":F$SA4LLDd;_$K$J$C$F$$$k!#(B

$B!!(BGDO $B<+?H$K$h$k7P0^@bL@$O0J2<$N$H$*$j!#(B

9$B7n(B30$BF|!'8aA0(B11$B;~:"!!%5!<%P!<$N0lIt$KIT@52~$6$s$rH/8+(B
9$B7n(B30$BF|!'8a8e(B2$B;~H>!!%5!<%S%9$r0l;~E*$KJD:?(B
10$B7n(B1$BF|!'8aA0(B9$B;~!!I|5l(B
10$B7n(B1$BF|!'%5!<%S%9I|5l8e!"%"%/%;%9=8Cf$K$h$j!"%5%$%H$,IT0BDj$J>u67$,7QB3(B
10$B7n(B1$BF|!'8a8e(B6$B;~!!:FEY%5!<%S%9Dd;_(B
10$B7n(B2$BF|!'8aA0(B1$B;~$9$.!!A4LLI|5l$K8~$1$?%F%9%H1?MQ$N$?$aCGB3E*$K%5%$%H$r:F3+(B
10$B7n(B2$BF|!'%F%9%H1?MQ$r7QB3!"A4LLI|5l$K$`$11T0UD4::!"3NG'(B
10$B7n(B2$BF|!'8a8e(B6$B;~!!%F%9%H1?MQ$N7k2L!":FEY=$@5$N$?$a%5!<%S%9A4LLDd;_(B

$B!!$J$*!"8D?M>pJs$K$D$$$F$O!VK\;v>]$K$*$$$F:YIt$K$o$?$jD4::8!>Z$7$?7k2L!"(BGDO$B$+$i$N8D?M>pJsO31L$N;v


$B"#(B 2008.10.02

$B"#(B $B!Z(BCSL$B![(BCSL$B6[5^Cm0U4-5/%l%]!<%H!A?7
(LAC, 2008.10.02)

$B!!(BASPROX mutant (SANS ISC, 2008.09.29) $B$HF1MM$N7o$J$N$@$=$&$G$9!#(B

$B$3$N967b$O!"%^%$%/%m%=%U%He$G3+H/$5$l$?(BWeb$B%5%$%H$rA@$C$F%G!<%?%Y!<%9$N2~$6$s$r9T$$$^$9!#(B

$B!!$=$&$$$($P!"(B$B%4%k%U%@%$%8%'%9%H!&%*%s%i%$%s(B$B$b(B IIS + ASP $B$G$9$M!#(B

$B:#2s$N(BSQL$B%$%s%8%'%/%7%g%s967b$K$O!"(B2$B$D$NFCD'$,$"$j$^$9!#(B
  1. Cookie$B$r;HMQ$7$F(BSQL$B%$%s%8%'%/%7%g%s$r9T$&!#(B
  2. $B%$%s%8%'%/%7%g%s$5$l$k967b%3!<%I!J(BSQL$BJ8!K$,!"(BIDS/IPS/WAF$B$J$I$NKI8f%7%9%F%`$K$h$C$F8!CN$5$l$J$$$h$&$K$5$l$F$$$k!#(B

$B!!(B$B!Z(BCSL$B![(BCSL$B6[5^Cm0U4-5/%l%]!<%H(B $B!A?7 $B$G$O!"%"%/%;%9%m%0$NNc$b8r$($F>e5-$,>\2r$5$l$F$$$^$9!#(B 1. $B$r8!CN$9$k(B snort $B%7%0%M%A%c$b7G:\$5$l$F$$$^$9!#(B

$B$^$?!":#2s$N(BSQL$B%$%s%8%'%/%7%g%s967b$KFC2=$7$?BP:v$H$7$F$O!"2<5-$r$"$2$^$9!#$4;29M$K$J$l$P9,$$$G$9!#(B
  1. GET$B$*$h$S(BPOST$B$G$NJQ?t ($BCfN,(B)
  2. $B%"%/%;%9%m%0$X$N(BCookie$B>pJs$N5-O?!J(BL$B!K(B
    ($BCfN,(B)
  3. $B967b85(BIP$B$N@)8B!J(BF$B!K(B
    $B;CDjE*$JBP:v$H$J$j$^$9$,!":#2s$N967b85(BIP$B$O8=:_$N4QB,$G$O0J2<$N#2$D$N(BIP$B%"%I%l%9$G$9!#%U%!%$%"%&%)!<%k$J$I$G@)8f$7$F$/$@$5$$!#(B
    61.152.246.157$B!JCf9q!K(B
    211.144.133.161$B!JCf9q!K(B
    211.154.163.43$B!JCf9q!K(B
    $B!J"(>e5-(BIP$B%"%I%l%9$K$O!"7h$7$F%"%/%;%9$7$J$$$G$/$@$5$$!K(B
  4. $B%G!<%?%Y!<%9%H%j%,$r3hMQ$7$?2~$6$s%3%^%s%I$N%m!<%k%P%C%/!J(BB$B!K(B
    ($BCfN,(B)
  5. WAF$B$NF3F~!J(BF$B!K(B
    ($BCfN,(B)
  6. $B%;%-%e%"$J(BWeb$B%"%W%j%1!<%7%g%s!J(BW$B!K(B
    ($BCfN,(B)

$B!!>e5-$K$D$$$F$b!"(B$B!Z(BCSL$B![(BCSL$B6[5^Cm0U4-5/%l%]!<%H(B $B!A?7 $B$G>\2r$5$l$F$$$^$9!#FC$K!"(BCookie $B$K$D$$$F$O(B IIS $B$N%G%U%)%k%H>uBV$G$O%m%0$r$B$=$&$G!"%+%9%?%^%$%:$7$F$$$J$$>l9g$K$O@_Dj$NJQ99$,I,MW$@$=$&$G$9!#(B $B:#$9$0FI$s$G$*$-$^$;$&!#(B

$B!!>e5-$N(B IP $B%"%I%l%9$G(B Web $B8!:w$9$k$H!"$$$m$$$m=P$F$-$^$9$M!D!D!#(B

2008.10.30 $BDI5-(B:

$B!!(B$B!Z(BCSL$B![(BCSL$B6[5^Cm0U4-5/%l%]!<%H(B $B!A?7 (LAC) $B$O(B 2008.10.06 $BIU$G=$@5$5$l$F$$$^$7$?!#(B

10$B7n(B2$BF|$K8x3+$7$?K\%l%]!<%HCf$K$*$$$F!"@H $B6qBNE*$K$O!"FCD'(B2$B$N5-:\FbMF$K$*$$$F!"(BASP.Net$B$G$O(B%$B$KB3$/J8;z$,(B16$B?J?tI=5-$G$-$J$$J8;zNs$,B3$$$?>l9g!"(B%$B$r=|5n$;$:$K$=$N$^$^(BWeb$B%"%W%j%1!<%7%g%s$K0z$-EO$7$^$9!#$D$^$j!"(BASP.Net$B$G$OFCD'(B2$B$K$O3:Ev$7$^$;$s!#(B

$B!!(BASP.NET $B$O$5$9$,$K%^%H%b$@$C$?LOMM!#(B

$B"#(B $B%4%k%U%@%$%8%'%9%H!&%*%s%i%$%s$GIT@5%"%/%;%9Ho32H/@8(B
(various)

$B!!%4%k%U%@%$%8%'%9%H!&%*%s%i%$%s(B (GDO) $B$GIT@5%"%/%;%9Ho32$,H/@8!#Ho325,LO!&Ho32HO0O$O$^$@ITL@!#J!K\$5$s>pJs$"$j$,$H$&$4$6$$$^$9!#(B

$B!!(BGDO $B$,$I$s$J%5%$%H$+$H$$$&$H!"(B$B7n4V(BPV1$B2/(B2000$BK|$N%4%k%UAm9g%]!<%?%k$,@.D9$9$k$?$a$KI,MW$@$C$?$b$N$H$O!=!=(BGDO$B!&LZB<6G;a(B (bizmakoto.jp, 2007.07.09) $B$K$h$k$H(B

$B!!$=$&$$$C$?Am9gE*$JE83+$r$7$F$$$k%5%$%H$N(B1$B$D$,!"%4%k%U%@%$%8%'%9%H!&%*%s%i%$%s!J(BGDO$B!K$@!#(BE$B%3%^!<%9!JJ*HN!K$@$1$G$J$/!"(BE$B%V%C%-%s%0!J%4%k%U>l$J$I$N%M%C%HM=Ls!K!"%a%G%#%"!J%4%k%U%l%C%9%s$d9qFb30$N%H!<%J%a%s%H>pJs!K$N(B3$B$D$N;v6H$rCl$K$7$F$*$j!"%4%k%U$K4X$9$k>pJs!&>&IJ!&%5!<%S%9$r9-$/07$&Am9g%]!<%?%k%5%$%H$H$J$C$F$$$k!#(B
$B!!%4%k%U$K4X$9$kAm9g%]!<%?%k$H$$$&@-e!"(BGDO$B$X$N%"%/%;%9$O!"%4%k%U$N%*%s%7!<%:%s$K$J$k$HA}$($F$/$k!#(B2006$BG/$N%*%s%7!<%:%s$K$O!"%Z!<%8%S%e!<$O7n4VLs(B1$B2/(B2000$BK|!"%f%K!<%/%f!<%6! $B!!$^$?2q0w@)$N!V(BGDO$B%/%i%V!W$r1?1D$7$F$*$j!"(B2007$BG/(B1$B7n$G2q0w$O(B100$BK|?M$rFMGK$7$?!#CK=wHf$O(B87$B!'(B13$B$HCK@-$,B?$$$,!":G6a$N798~$H$7$F!"=w@-2q0w$,@j$a$kN($,A}$($F$-$F$$$k$H$$$&!J(B2002$BG/$N=w@-2q0w$N3d9g$O(B7.8$B!s!K!#$^$?2q0w$NCf?4$,(B30$BBe0J>e!"9b=jF@

$B!!2q0w>pJs$,1L$l$?$H$J$k$H!"(B100 $BK|?M5,LO$NHo32$,H/@8$9$k2DG=@-$,$"$k!#(B

$B!!0J2<$N>pJs$r$^$H$a$k$H!"(B

$B!!$3$&$$$&>u67$_$?$$!#(B

2008$BG/(B9$B7n(B30$BF|(B 11$B;~:"(B $B%5!<%P!<$N0lIt$KIT@52~$6$s$rH/8+(B (GDOSHOP.com $B$+(B?)
14$B;~(B30$BJ,(B $B%&%'%V%5%$%H$r0l;~E*$KJD:?(B
10$B;~!A(B21$B;~(B $B8\5R$K%&%$%k%9$r4^$`(B Web $B%Z!<%8$N(B URL $B$r%a!<%kG[?.(B
2008$BG/(B10$B7n(B1$BF|(B $B8aA0(B9$B;~(B $B%5!<%S%9I|5l(B
18$B;~(B $B%5%$%H$,IT0BDj$J$?$a!":FEYA4LLDd;_(B
2008$BG/(B10$B7n(B2$BF|(B $B8aA0(B1$B;~(B $B%F%9%H1?MQ$H$7$F!"CGB3E*$K%5%$%H$r:F3+(B

$B!!(BSQL $B%$%s%8%'%/%7%g%s$K$h$k$b$N$J$N$+$I$&$+$O$^$@ITL@!#8\5R$K%&%$%k%9(B URL $B%a!<%k$rG[?.$7$F$$$?$H$$$&$N$O!"$3$l$^$GJ9$$$?$3$H$,$J$$>u67$@$J$"!#(B

$B!!8=:_!"(BGDO$BA4%5!<%S%9$K$*$1$k6[5^%7%9%F%`%a%s%F%J%s%9$r (GDO$B!"(BLast Modified: Wed, 01 Oct 2008 17:31:56 GMT) $B$J$N$G!"!VCGB3E*$K%5%$%H$r:F3+!W$H$$$C$F$b!"%5!<%S%9$O8B$i$l$F$$$k$H;W$o$l!#(B

$B!Z%a%s%F%J%s%9BP>]![(B
$B!&(BGDO$BA4%5!<%S%9!J%b%P%$%k%5%$%H4^$`!K(B

* GDOSHOP.com
* $B%4%k%U>lM=Ls(B
* $B%4%k%U%^%,%8%s!u%4%k%U%9%?%$%k(B
* $B%4%k%U%!!<%:%V%m%0!"%9%3%"4IM}!"(BGDO$B%5!<%/%k(B
* MY GDO$B!J%4%k%U>lM=LsFbMFJQ99!u%-%c%s%;%k!"8D?M>pJsJQ99!"%]%$%s%HMzNr1\MwB>!K(B
* $B$=$NB>%5!<%S%9A4$F(B

$B!!(Bstay tuned.

2008.10.03 $BDI5-(B:

$B!!(B2008.10.02 19:30 $B;~E@$G!":F$SA4LLDd;_$K$J$C$F$$$k!#(B

$B!!(BGDO $B<+?H$K$h$k7P0^@bL@$O0J2<$N$H$*$j!#(B

9$B7n(B30$BF|!'8aA0(B11$B;~:"!!%5!<%P!<$N0lIt$KIT@52~$6$s$rH/8+(B
9$B7n(B30$BF|!'8a8e(B2$B;~H>!!%5!<%S%9$r0l;~E*$KJD:?(B
10$B7n(B1$BF|!'8aA0(B9$B;~!!I|5l(B
10$B7n(B1$BF|!'%5!<%S%9I|5l8e!"%"%/%;%9=8Cf$K$h$j!"%5%$%H$,IT0BDj$J>u67$,7QB3(B
10$B7n(B1$BF|!'8a8e(B6$B;~!!:FEY%5!<%S%9Dd;_(B
10$B7n(B2$BF|!'8aA0(B1$B;~$9$.!!A4LLI|5l$K8~$1$?%F%9%H1?MQ$N$?$aCGB3E*$K%5%$%H$r:F3+(B
10$B7n(B2$BF|!'%F%9%H1?MQ$r7QB3!"A4LLI|5l$K$`$11T0UD4::!"3NG'(B
10$B7n(B2$BF|!'8a8e(B6$B;~!!%F%9%H1?MQ$N7k2L!":FEY=$@5$N$?$a%5!<%S%9A4LLDd;_(B

$B!!$J$*!"8D?M>pJs$K$D$$$F$O!VK\;v>]$K$*$$$F:YIt$K$o$?$jD4::8!>Z$7$?7k2L!"(BGDO$B$+$i$N8D?M>pJsO31L$N;v

2008.10.20 $BDI5-(B:

$B!!(B2008.10.10 $B;~E@$GA4LL:F3+$7$F$$$?$=$&$G!#(B

2009.06.13 $BDI5-(B:

$B!!4XO"(B: RSA Conference 2009 JAPAN$B!'IT@5%"%/%;%9$K$h$k%5!<%S%9Dd;_!=!=;vNc$+$i3X$V%;%-%e%j%F%#BP:v(B (ITmedia, 2009.06.12)

$B"#(B IT$B%;%-%e%j%F%#M=KI@\
(JPCERT/CC, 2008.10.02)


$B"#(B 2008.10.01

$B"#(B DELL Dimension 2400c / 4600c ($B7W(B 14$BK|(B7000$BBf(B) $B$NEE8;%f%K%C%H$KH/1l$rH<$&IT6q9g$N2DG=@-(B
(DELL, 2008.09.30)

$B!!(BDELL Dimension 2400c 6$BK|Bf$H!"(BDimension 4600c 8$BK|(B7$B@iBf$N9g7W(B 14$BK|(B7$B@iBf$K$*$$$FEE8;%f%K%C%H(B (PSU) $B$KIT6q9g$,$"$j!"%7%9%F%`$,Dd;_$7$F5/F0$7$J$/$J$C$?$j!"H/1l$7$?$j$9$k>l9g$,$"$kLOMM!#H/1l;v>]$O4{$K(B 13 $B7o3NG'$5$l$F$$$kLOMM!#(B

$B!!$3$&$$$&OC$N>l9g!"$U$D$&$O!VL5=~8r49$r3+;O$7$F$$$k$N$G!D!D!W$HB3$/$N$@$,!"$=$s$JF0$-$O0l@Z$J$$!#(B$B%G%k!"0lIt$N%G%9%/%H%C%W(BPC$BIT6q9g$K$D$$$F%5%]!<%H>pJs$r7G<((B (DELL, 2008.09.30) $B$K$"$k$N$O$3$s$JJ86g!#(B

$B%G%k$O$3$NLdBj$rD4::$N7k2L!"(BPSU$BIT6q9g$O$$$:$l$b6bB0%1!<%9FbIt$N%W%j%s%H4pHD>e$GH/@88e!"C;;~4V$G=*7k$7$F$$$k$?$a!"@=IJ$N0BA4@-$K1F6A$,$J$$$3$H$r3NG'$7$F$*$j$^$9!#(B

$BEv3:@=IJ(BPSU$B$KIT6q9g$,5/$-$?>l9g$K$O!"8N>c$7$?ItIJ$rL5=~$G8r49$5$;$F$$$?$@$-$^$9!#%5%]!<%H>pJs$N>\:Y$K$D$$$F$O!"%G%k!&%F%/%K%+%k%5%]!<%H!J%&%(%V%5%$%H(Bhttp://Support.jp.dell.com$B$^$?$O%U%j!<%@%$%d%k(B 0120-198-499 $Be$2$^$9!#(B

$B!!(Bhttp://supportapp.jp.dell.com/jp/jp/psu/confirm.asp $B$K$*$$$F!"IT6q9g$N$"$kEE8;$rEc:\$7$F$$$k$+H]$+$r3NG'$G$-$k!#(BDimension 2400c / 4600c $BMxMQ

$B!!4XO"(B: Dimension 2400c/4600c$B$r$40&MQ$N$*5RMM$X$40FFb(B (DELL, 2008.09.30)

$B"#(B $B$$$m$$$m(B (2008.10.01)
(various)

$B"#(B EC-CUBE $B$KJ#?t$N7g4Y(B
(JVN, 2008.10.01)

$B"#(B $BDI5-(B

$B$$$m$$$m(B (2008.09.24)

$B0lB@O:$N@H

$B!!;0;MO:(B 2008 $B$K$b7g4Y$r4^$`%b%8%e!<%k$NB8:_$,L@$i$+$H$J$j!"(B$B%"%C%W%G!<%H%b%8%e!<%k(B$B$,8x3+$5$l$F$$$k!#$7$+$7!"!V;0;MO:(B2008$B$GH/@8$7$F$$$k8=>]$r2sHr$7$^$9!W$H$$$&@bL@$O$J$s$H$+$J$i$J$$$N$+!#%;%-%e%j%F%#99?7$,4^$^$l$F$$$k$N$K!#(B

$B"#(B Jack C. Louis and Robert E. Lee to talk about New DoS Attack Vectors (Sockstress)
(t2.fi, 2008.08.27)

$B!!(BSockstress $B$H8@$&$N$@$=$&$G$9!#(B

Jack C. Louis and Robert E. Lee from Outpost24 will divulge new technical details about TCP state table manipulation vulnerabilities that affect availability.

Specifically this talk will showcase new attacks that will render a remote system unavailable using a very low bandwidth attack stream. Attacks against Windows, BSD, Linux, and embedded systems TCP/IP stack implementations will be discussed and demonstrated.

$B!!4{CN$NBP(B TCP $B967b$H$O0[$J$k!"$H$$$&$3$H$J$N$+$J$!!D!D!#(B2008.10.17 $B8x3+M=Dj!#(B

2008.10.07 $BDI5-(B:

$B!!4XO"(B:

$B!!$$$:$l$K$;$h!"(Bpatch $BBT$A$J$N$OJQ$o$i$J$$!#(B

2008.10.21 $BDI5-(B:

$B!!4XO"(B:

  • CVE-2008-4609

  • CERT-FI Statement on the Outpost24 TCP Issues (CERT-FI)$B!#(B2008.10.17 $BIU$G2~D{$5$l$F$$$k!#(B

    Oct 17. The TCP issue reported by Outpost24 is being coordinated by CERT-FI. We are in a process of determining the impact of the techniques and principles described by the reporters of the issue. We are researching and handling the issue with several vendors from all potentially affected branches of network equipment and software. Once we are fully aware of what types of network equipments and services are most possibly affected, we will make more vendor contacts. Based on previous experience from similar coordination projects, we estimate that the full publication of the details of the issue may take until next year. CERT-FI will publish more information on the developments of the issue coordination as the coordination progresses.
  • Cisco Security Response: Cisco Response to Outpost24 TCP State Table Manipulation Denial of Service Vulnerabilities (Cisco, 2008.10.17)

    Cisco PSIRT research indicates an attacker must complete a TCP three-way handshake to a device to successfully exploit the DoS vulnerabilities. This requirement makes spoofing the source of an attack more challenging. The TCP vulnerabilities that Outpost24 announced are an extension of well-known weaknesses in the TCP protocol.

    It is possible to mitigate the risk of these vulnerabilities by allowing only trusted sources to access TCP-based services. This mitigation is particularly important for critical infrastructure devices. PSIRT recommends the implementation of infrastructure access control lists (IACLs) and control plane policing (CoPP) to protect core network functionality.
  • TCP Resource Exhaustion and Botched Disclosure (insecure.org)$B!#(Bnmap $B$J?M$K$h$k2r@b!#(B

2009.09.09 $BDI5-(B:

$B!!(BSockstress $B$N7o!"$h$&$d$/3F

2009.09.10 $BDI5-(B:

$B!!B3Js!#(B

2009.09.28 $BDI5-(B:

$B!!4XO"(B:

$B"#(B lighttpd $B$KJ#?t$N7g4Y(B
(lighttpd.net, 2008.09.30)

$B!!7ZNL(B Web $B%5!<%P(B lighttpd $B$K(B 4 $B$D$N7g4Y!#(B

$B!!$$$:$l$b(B lighttpd 1.4.0 $B$G=$@5$5$l$F$$$k!#(B


[$B%;%-%e%j%F%#%[!<%k(B memo]
$B;d$K$D$$$F(B