Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Beta Programs
Bugtraq in Japanese
Firewire/IEEE1394にç?©ç?ç??ã?»ã?­ã?¥ã?ªã??ã?£ä¾µå®³ã«ã¤ãªã?ã??è??å¼±æ?§ Oct 21 2004 02:16AM
Dragos Ruiu (dr kyx net)
Firewire/IEEE1394にç?©ç?ç??ã?»ã?­ã?¥ã?ªã??ã?£ä¾µå®³ã«ã¤ãªã?ã??è??å
¼±æ?§
Firewire/IEEE 1394 Considered Harmful to Physical Security

Advisory URL: http://pacsec.jp/advisories.html

�要�

ã??IEEE1394規格(é??ç§°Firewire)ã??使ã?とã?ã?¯ã?©ã?¤ã?¢ã?³ã??æ©?å?¨
ã?OSにã??ã??å?¶é?ã??æ?¦ã??æ??ã?てã?ã??ã?¹ã??のã?¡ã?¢ã?ªã«ç?´æ?¥ã
?¢ã?¯ã?»ã?¹ã§ãã??ã??ã?になã??ã??ã?ã??ã??æ?ª
ç?¨ã?ã??とã?ã?¯ã?©ã?¤ã?¢ã?³ã??æ©?å?¨ã??ç?¨ã?てã?ã??ã?¹ã??に保å­?
ã?ã??ã?æ©?å¯?æ??å ±ã??読みå?ºã?てå¤?æ?´ã?ã?æ¨©é?æ??æ ¼ã?æ??å ±
漏ã?ã?ã?ã?·ã?¹ã??ã? ã®ä¸æ­£ä½¿ç?¨ãªã©ã??å®?è¡?できã??ã??å®?å?¨
でなã?å ´æ??
にã?ã??ã?æ©?å¯?æ??å ±ã?保å­?ã?ã??ã?ã?·ã?¹ã??ã? ã?ç?¹ã«ä¸?è?¬ã?
ã??のã?¢ã?¯ã?»ã?¹ã?可è?½ãªã?·ã?¹ã??ã? ã«ã?Firewireã?ã?¼ã??ã?設ç
½®ã?ã??てã?ã??å ´å?はã?ã?·ã?¹ã??ã? ã®ã?»ã?­ã?¥ã?ªã??ã?£ã??ä»?ä¸?
度è©?価ã?てã?ç?©ç?ç??なã?»ã?­ã?¥ã?ªã??ã?£æ?ªç½®ã®è¿½å? ã??æ¤?è¨?
ã?ã??å¿?要ã?ã?ã??ã??Firewireã?ã?¼ã??はã?Sony製å?ã®ä¸?é?¨ã§ã¯
ã??iLinkã?ã¨å?¼ã°ã??ã??ã?とã??ã?ã??ã??

詳細�

ã??RWTH Aachenå·¥ç§?大学のé«?ä¿¡é ¼æ?§å??æ?£å??ã?·ã?¹ã??ã? ç ?究室にæ??å±?
ã?ã??Maximilian Dornseif氏はã?11æ??12æ?¥ã«æ±äº¬ã§é??å?¬ã?ã??ã??ã??
PacSec.jpã?ã?«ã?³ã??ã?¡ã?¬ã?³ã?¹ã§è¡?ã?äº?å®?のã??Owned by an iPodã?ã¨é¡?ã?ã?ç ?ç©¶ç?ºè¡¨ã®ä¸­ã§ã?ã??ã?¼ã??ã??ã??ã?¹ã?¯ã??ã??ã?
?ã?ã?ã??びä¸?é?¨ã®ã?µã?¼ã?ã??ã?·ã?³ã«
åº?く搭è¼?ã?ã??てã?ã??IEEE1394ã?¤ã?³ã?¿ã?¼ã??ã?§ã?¼ã?¹ã«é?¢é?£ã?ã
?æ?°ã?ã?ã??ã?¯ã??ã??ã?¯ã??ã?くつã?æ?«é?²ã?ã??äº?å®?でã?ã??ã??

ã??ã?ã??ã??のã??ã?¯ã??ã??ã?¯ã¯ã?æ?ªè³ªãªç?¨é??ã?ã??びæ??ç??なç?¨
é??の両面にå¿?ç?¨ã?可è?½ã§ã?ã??ã??æ??ç??なç?¨é??にはã?ã?·ã?¹
ã??ã? ã??ã?©ã?¬ã?³ã?¸ã??ã?¯ã??å¤?é?¨ã??ã?ã??ã?°ãªã©ã®å??é??へのå¿?
ç?¨ã?ã?ã??ã??だ
ã?ã?æ?ªè³ªãªç?¨é??にæ?ªç?¨ã?ã??とã?ã?·ã?¹ã??ã? ã®firewireã?ã?¼ã
??にç?©ç?ç??にã?¢ã?¯ã?»ã?¹å¯è?½ã§ã?ã??ばã?é?»æºã®å?¥ã??ç?´ã?ã
??å?èµ·å??などã??è¡?ã?ãªãã¦ã??ã?ã?·ã?¹ã??ã? é?ç?¨ã??不正に
å¤?æ?´ã?ã?ã?»ã?­ã?¥ã?ªã??ã?£ã??侵害できã??可è?½æ?§ã?ã?ã??ã??

ã??ã?ªã?»ã??ã??ã??é?»æºã®ã?¹ã?¤ã??ã?ã??æ?ä½?できなã?ã??ã?にã?
ã??ç?©ç?ç??なå?¶é?æ?ªç½®ã??ã?å?èµ·å??などのæ??é ?ã??ç?¨ã?ã?ã?·
ã?¹ã??ã? ã®ä¸æ­£ä½¿ç?¨ã??å?¶é?ã?ã??ã?ã?ã®ãã®ä»?の対ç­?に依
��てき��
ã?¹ã??ã? ã¯ã?ã?»ã?­ã?¥ã?ªã??ã?£ã??å?æ¤?è¨?ã?ã??å¿?要ã?ã?ã??ã??

ã??å¾?来ã??ã??ã?ã?³ã?³ã??ã?¥ã?¼ã?¿ã«ç?©ç?ç??にã?¢ã?¯ã?»ã?¹å¯è?½ã§
ã?ã??ã?とはã?ã?てã?の場å?ã?ä¸æ­£ä½¿ç?¨ã?可è?½ãªã?とã??
æ?å?³ã?ã??ã??だã?ã?のæ?°ã?ã?ã??ã?¯ã??ã??ã?¯ã??使ã?とã?ç?¹æ®?
なã?½ã??ã??ã?¦ã?§
ã?¢ã??ç?¨ã?てæ?ªæ?ã®ã?ã??Firewire/1394ã?¯ã?©ã?¤ã?¢ã?³ã??æ©?å?¨ã«æ?
¥ç¶?ã?ã??だã?でã?ã?¿ã?¼ã?²ã??ã??ã??不正にæ?¹ã?ã??できã??ã??ç?
©ç?ç??ã?¢ã?¯ã?»ã?¹ã¨
Firewire/1394ã?¤ã?³ã?¿ã?¼ã??ã?§ã?¼ã?¹ã¨ã??çµ?みå?ã?ã?て使ã?ã??å 
´å?はã?ã?ã??に容æ??にã?»ã?­ã?¥ã?ªã??ã?£ã??侵害できã??ã??ã?ã
«ãªã??ã??

ã??å¿?要にå¿?ã?てã?ã?»ã?­ã?¥ã?ªã??ã?£ã?ã?ªã?·ã?¼ã??æ??é ?ã??å?è©?
価ã?ã?ã?のæ?°ã?ã?æ??報につã?てæ¤?è¨?ã?べきでã?ã??ã??

å½±é?¿ã??å?ã?ã??ã?·ã?¹ã??ã? ï¼?

ã??IEEE1394ã?¤ã?³ã?¿ã?¼ã??ã?§ã?¼ã?¹ã??搭è¼?ã?ã?ã?べてのOSã?ã??ã
³ã??ã?­ã?»ã??ã?µã??ã?©ã??ã??ã??ã?©ã?¼ã? ã??まã?å ´å?にã??ってはã?
å?é¡?のOSã?1394ã?¤ã?³ã?¿ã?¼ã??ã?§ã?¼ã?¹ã??ã?µã?ã?¼ã??
ã?てã?なã?å ´å?でã??ã?ã?ã?¼ã??ã?¦ã?§ã?¢ã«é?»æºã?å?¥ã£ã¦ã?
ã??ばã?ä¸æ­£ä½¿ç?¨ã?可è?½ãªå ´å?ã??ã?ã??ã??

対��

ã??信頼できなã?/認証ã?ã??てã?なã?ç?©ç?ç??ã?¢ã?¯ã?»ã?¹ã??å¿
?要とã?ã?ãªã?ã?つå?¶é?ã??設ã?ã?é?ç?¨ã??è¡?ã?å¿?要ã?ã?ã?
?ã?·ã?¹ã??ã? ã§ã¯ã?å¤?ã?±ã?¼ã?¹ã®firewireã?¸ã?£ã??ã?¯ã«æ?¥ç¶?ã?て

ã?ã??ã?¯ã?¤ã?¤ã??ã??ã??ã??å?ã??å¤?ã?ã?とã?é?¨å??ç??なå??避ç­?に
なã??å ´å?ã??ã?ã??ã??

ã??ã?©ã??ã??ã??ã??ã??ではã?æ©?è?½ã?失ã?ã??てã??æ§?ã?ãªã?のな
ã??ã?ã?¨ã?ã?­ã?·æ¨¹è??ã??使ってå¤?é?¨ã?¸ã?£ã??ã?¯ã??æ°¸ä¹?に使ç?¨
不可è?½ã«ã§ãã??ã??

ã??第ä¸?のäº?é?²ç­?とã?てã?æ©?å¯?æ??å ±ã??保å­?ã?ã?ã?³ã?³ã??ã?¥
ã?¼ã?¿ã«æ?ªç?¥ã®/信頼できなã?firewireã??ã?ã?¤ã?¹ã??æ?¥ç¶?ã?な
ã?ã??ã?ã?å¾?業å?¡ã«è­¦å??ã??ç?ºã?てã?くå¿?要ã?ã?ã??ã??

ã??ã?のæ©?è?½ã¯ã?ã?ã?¼ã??ã?¦ã?§ã?¢ã?¬ã??ã?«ã®ä»?æ§?ã??ã?ã??ã??ã?»
ã??ã??にçµ?み込まã??てã?ã??のでã?ã?½ã??ã??ã?¦ã?§ã?¢ã«ã??ã??ä¿®
正にé?¢ã?てはã?ã?まだæ¤?è¨?中の段é??にã?ã??ã??ä»?å??のç?º
表では��の
å?é¡?ã??è­°è«?ã?ã??ã??äº?å®?でã?ã??ã??ã??
--
World Security Pros. Cutting Edge Training, Tools, and Techniques
Tokyo, Japan Nov 11-12 2004 http://pacsec.jp
pgpkey http://dragos.com/ kyxpgp

[ reply ]







 

Privacy Statement
Copyright 2009, SecurityFocus