¤¤¤Ä¤Ç¤âµ§¤ì¤ë¥¹¥Þ¡¼¥È¥í¥¶¥ê¥ªÍÑ¥¢¥×¥ê¤ÏĶÀä´Êñ¤Ë¥Ï¥Ã¥¥ó¥°¤Ç¤¤¿¤³¤È¤¬È½ÌÀ

¥«¥È¥ê¥Ã¥¯¶µ²ñ¤òÅý¼£¤¹¤ë¥í¡¼¥Þ¶µ¹ÄÄ£¤¬¥ê¥ê¡¼¥¹¤·¤¿¤ªµ§¤êÍѤΥ¹¥Þ¡¼¥È¥Ç¥Ð¥¤¥¹¡ÖeRosary¡×¤ª¤è¤ÓÀìÍÑ¥¢¥×¥ê¤Î¡ÖClick To Pray¡×¤Ë¡¢¤µ¤Ã¤½¤¯ÀȼåÀ¤¬È¯¸«¤µ¤ì¤Æ¤·¤Þ¤¤¡¢·ÉéÊ(¤±¤¤¤±¤ó)¤Ê¿®¼Ô¤¬¥Ï¥Ã¥«¡¼¤Î±Â¿©¤Ë¤Ê¤ë²ÄǽÀ¤¬Ê󤸤é¤ì¤Æ¤¤¤Þ¤¹¡£
ClickToPray eRosary Account Takeover - Fidus
https://fidusinfosec.com/clicktopray-erosary-account-takeover/
https://www.theregister.co.uk/2019/10/18/vatican_erosary_insecure/
2019ǯ10·î18Æü¤Ë¡¢¥«¥È¥ê¥Ã¥¯¶µ²ñ¤òÅý¼£¤¹¤ë¥í¡¼¥Þ¶µ¹ÄÄ£¤¬¡¢¤¤¤Ä¤Ç¤â½½»ú¤òÀڤäƵ§¤ê¤òÊû¤²¤ë¤³¤È¤¬¤Ç¤¤ë¥¹¥Þ¡¼¥È¥í¥¶¥ê¥ª¤Î¡ÖeRosary¡×¤òȯɽ¤·¤Þ¤·¤¿¡£ÈÎÇä²Á³Ê¤Ï110¥É¥ë(Ìó1Ëü2000±ß)¤Ç¡¢¥¤¥¿¥ê¥¢¤ÎAmazon¤Ç¤âÈÎÇ䤵¤ì¤Æ¤¤¤Þ¤¹¡£

¤³¤Î¥¹¥Þ¡¼¥È¥í¥¶¥ê¥ª¤ÈÏ¢·È¤·¤Æ»ÈÍѤ¹¤ë¤ªµ§¤êÀìÍÑ¥¢¥×¥ê¤Î¡ÖClick To Pray¡×¤ËÀȼåÀ¤¬Â¸ºß¤·¤Æ¤ª¤ê¡¢¤ªµ§¤ê¤Î¤¿¤á¤Ë¥¢¥×¥ê¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤¿¥æ¡¼¥¶¡¼¤¬¥Ï¥Ã¥¥ó¥°¤µ¤ì¤ë²ÄǽÀ¤¬»ØÅ¦¤µ¤ì¤Æ¤¤¤Þ¤¹¡£

¥»¥¥å¥ê¥Æ¥£´ë¶È¤ÎFidus InfoSecurity¤Ï¡¢¸ø¼°Twitter¥¢¥«¥¦¥ó¥È¾å¤Ç¡Ö²æ¡¹¤Î¸¦µæ¥Á¡¼¥à¤¬eRosary¤ÎÀìÍÑ¥¢¥×¥ê(Click To Pray)¤òÄ´¤Ù¤À¤·¤Æ5ʬ̤Ëþ¤Ç¡¢´°Á´¤Ê¥¢¥«¥¦¥ó¥È¾è¤Ã¼è¤ê¥¨¥¯¥¹¥×¥í¥¤¥È¤ò³«È¯¤¹¤ë¤³¤È¤ËÀ®¸ù¤·¤Þ¤·¤¿¡£¥¨¥¯¥¹¥×¥í¥¤¥È¤ò»È¤¨¤Ð¥á¡¼¥ë¥¢¥É¥ì¥¹¡¦ÅÅÏÃÈֹ桦(¥æ¡¼¥¶¡¼¤Î)¿ÈĹ¡¦Âνš¦¤½¤Î¾¤Î¸Ä¿Í¾ðÊó¤òÅð¤ß½Ð¤¹¤³¤È¤â¤Ç¤¤Þ¤¹¡£¹¬¤¤¤Ê¤³¤È¤Ë¡¢È¯¸«¤·¤¿ÀȼåÀ¤Ï´û¤ËÊó¹ð¤µ¤ì¤Æ¤ª¤ê¡¢¤Þ¤ÀÀȼåÀ¤òÍѤ¤¤¿¥¨¥¯¥¹¥×¥í¥¤¥È¤Ï¸«¤é¤ì¤Þ¤»¤ó¡×¤È¥Ä¥¤¡¼¥È¤·¡¢´Êñ¤Ë¥Ï¥Ã¥¥ó¥°¤Ç¤¤¿¤³¤È¤òÊó¹ð¤·¤Æ¤¤¤Þ¤¹¡£
Less than 5 minutes into looking at the eRosary application our research team has developed a full account takeover exploit. Can obtain e-mails, phone numbers, height, weight and other personal data. This has been reported. Luckily it's so new it's not in the wild yet. pic.twitter.com/XpqYqDpgC2— Fidus InfoSecurity (@FidusInfoSec) 2019ǯ10·î17Æü
¾åµ¤Î¥Ä¥¤¡¼¥È¤òÅê¹Æ¤·¤¿ºÝ¡¢Fidus InfoSecurity¤ÏClick To Pray¤Ë¸ºß¤¹¤ëÀȼåÀ¤Î¾ÜºÙ¤òÌÀ¤é¤«¤Ë¤·¤Æ¤¤¤Ê¤«¤Ã¤¿¤Î¤Ç¤¹¤¬¡¢¤½¤ÎÍâÆü¤ËTwitter¤òºÆ¤Ó¹¹¿·¤·¤Æ¡¢¡ÖÀèÆü¤Î¥»¥¥å¥ê¥Æ¥£Êó¹ð¤Î¸å¡¢eRosary¤ÎÀìÍÑ¥¢¥×¥ê¤ÎÇØ¸å¤Ë¤¢¤ë¥Á¡¼¥à¤¬½¤Àµ¥×¥í¥°¥é¥à¤òȯ¹Ô¤·¤¿¤Î¤Ç¡¢¤è¤ê¿¤¯¤Î¾ðÊó¤ò³«¼¨¤Ç¤¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤·¤¿¡×¤È¥Ä¥¤¡¼¥È¡£¤½¤·¤Æ¡¢¸ø¼°¥µ¥¤¥È¾å¤ÇÀȼåÀ¤Ë´Ø¤¹¤ë°ìÉô¤Î¸ø³«¤Ç¤¤ë¾ðÊó¤ò³«¼¨¤·¤Æ¤¤¤Þ¤¹¡£
After our security report yesterday, the team behind the eRosary application have already issued a fix and we can disclose more: https://t.co/mrYuPJFNeO— Fidus InfoSecurity (@FidusInfoSec) 2019ǯ10·î18Æü
Click To Pray¥¢¥×¥ê¤òÍøÍѤ¹¤ë¾ì¹ç¡¢¼«¿È¤Î¥á¡¼¥ë¥¢¥É¥ì¥¹¤òÆþÎϤ·¤Æ¥¢¥«¥¦¥ó¥È¤òºîÀ®¤¹¤ë¤«¡¢Google¡¦Facebook¥¢¥«¥¦¥ó¥È¤ÈÏ¢·È¤·¤Æ¥¢¥«¥¦¥ó¥È¤òºîÀ®¤¹¤ëÊýË¡¤Î2¤Ä¤¬ÁªÂò¤Ç¤¤Þ¤¹¡£

¼«¿È¤Î¥á¡¼¥ë¥¢¥É¥ì¥¹¤òÆþÎϤ¹¤ë¾ì¹ç¡¢¥Ñ¥¹¥ï¡¼¥É¤òÀßÄꤹ¤ë¤Î¤Ç¤Ï¤Ê¤¯4·å¤ÎPIN¥³¡¼¥É¤Ç¥¢¥«¥¦¥ó¥È¤òÊݸ¤Þ¤¹¡£PIN¥³¡¼¥É¤Ç¥¢¥«¥¦¥ó¥È¤òÊݸ¡¢¥æ¡¼¥¶¡¼¥¢¥«¥¦¥ó¥È¤ò¥ê¥»¥Ã¥È¤·¤¿¾ì¹ç¡¢ÅÐÏ¿¤·¤¿¥á¡¼¥ë¥¢¥É¥ì¥¹°¸¤Ë¥á¡¼¥ë¤¬Á÷¿®¤µ¤ì¤ë¤½¤¦¤Ç¤¹¡£

¥¢¥×¥ê¤ÎAPI¤Ï¥Ð¥Ã¥¯¥¨¥ó¥É¥·¥¹¥Æ¥à¤ÈÄÌ¿®¤¹¤ë¤Î¤Ç¤¹¤¬¡¢ÀȼåÀ¤Ë¤è¤êAPI·Ðͳ¤Ç¥æ¡¼¥¶¡¼¤ÎÍøÍѤ·¤Æ¤¤¤ëüËö¾ðÊ󡢥᡼¥ë¥¢¥É¥ì¥¹¾ðÊó¡¢Ãϰè¾ðÊó¤Ê¤É¤òÁ÷¿®¤·¤Æ¤·¤Þ¤Ã¤Æ¤¤¤¿¤³¤È¤¬ÌÀ¤é¤«¤Ë¤Ê¤Ã¤Æ¤ª¤ê¡¢API¤ÎÁ÷¿®¤¹¤ë¾ðÊó¤Ï°Å¹æ²½¤µ¤ì¤Æ¤¤¤Ê¤¤¤¿¤á´Êñ¤ËÆÉ¤ß¼è¤ê¤Ç¤¤Æ¤·¤Þ¤Ã¤¿¤È¤Î¤³¤È¡£

API¤Î4·å¤ÎPIN¥³¡¼¥É¤â¤·¤Ã¤«¤êÌÀµ¤µ¤ì¤Æ¤¤¤Þ¤¹¡£

¤³¤ÎPIN¥³¡¼¥É¤òÍѤ¤¤Æ¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ë¥í¥°¥¤¥ó¤¹¤ì¤Ð¡¢¥æ¡¼¥¶¡¼¥¢¥«¥¦¥ó¥È¤Î¥×¥í¥Õ¥£¡¼¥ë²èÌ̤«¤é¿ÈĹ¡¦Âνš¦ÀÊÌ¡¦À¸Ç¯·îÆü¤Ê¤É¤Î¾ðÊó¤òÃΤ뤳¤È¤¬²Äǽ¡£

¤Ê¤ª¡¢Fidus InfoSecurity¤Ï¡Ö4·å¤ÎPIN¥³¡¼¥É¤ò»ÈÍѤ¹¤ë¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤È¤¤¤¦¤Î¤Ï¶½Ì£¿¼¤¤¤â¤Î¤Ç¤¹¡£API¤Î¥ì¡¼¥ÈÀ©¸Â¤â¤Ê¤¤¤¿¤á¡¢²æ¡¹¤¬¸«¤Ä¤±¤¿ÀȼåÀ¤¬¤Ê¤¯¤Æ¤â¥¢¥«¥¦¥ó¥È¤Ë¥¢¥¯¥»¥¹¤¹¤ë¤³¤È¤ÏÈæ³ÓŪ´Êñ¤Ç¤·¤¿¡×¤Èµ¤·¤Æ¤¤¤Þ¤¹¡£
¤Þ¤¿¡¢IT·Ï¥Ë¥å¡¼¥¹¥á¥Ç¥£¥¢¤ÎThe Register¤¬¥À¥ß¡¼¥¢¥«¥¦¥ó¥È¤òºîÀ®¤·¤¿¤È¤³¤í¡¢Fidus InfoSecurity¤ÎÄ´ºº¥Á¡¼¥à¤¬´Êñ¤Ë¥¢¥«¥¦¥ó¥È¤ò¥Ï¥¤¥¸¥ã¥Ã¥¯¤¹¤ë¤³¤È¤ËÀ®¸ù¤·¤¿¤È¤âÊ󤸤é¤ì¤Æ¤¤¤Þ¤¹¡£¥¢¥«¥¦¥ó¥È¤Ë¤Ï¥æ¡¼¥¶¡¼¸Ä¿Í¤Îºâ̳¾ðÊó¤Ê¤É¤ÏµÏ¿¤µ¤ì¤Æ¤¤¤Þ¤»¤ó¤¬¡¢¥Ï¥Ã¥¥ó¥°¤Ë¤è¤ëϳ±Ì¤Î²ÄǽÀ¤¬¤¢¤ë¸Ä¿Í¾ðÊó¤Ï¡ÖÃæ¹ñ¤Î¤è¤¦¤Ê¹ñ¤Ç¸ø³«¤µ¤ì¤ì¤Ð¥æ¡¼¥¶¡¼¤Ë»³²¤òÍ¿¤¨¤ë²ÄǽÀ¤¬¤¢¤ë¡×¤ÈThe Register¤Ïµ¤·¤Æ¤¤¤Þ¤¹¡£
Fidus InfoSecurity¤¬ÀȼåÀ¤òÊó¹ð¤·¤¿¸å¡¢36»þ´Ö°ÊÆâ¤ËÌäÂê¤Ï½¤Àµ¤µ¤ì¤¿¤½¤¦¤Ç¡¢Fidus InfoSecurity¤ÎÁÏÀ߼ԤǤ¢¤ëAndrew Mabbitt»á¤Ï¡ÖClick To Pray¤ÎAPIÌäÂê¤ò½¤Àµ¤·¤Æ¤ª¤ê¡¢¤½¤ÎÊýË¡¤ÏÈó¾ï¤ËÊ£»¨¤Ç¤·¤¿¡×¤È¥³¥á¥ó¥È¡£¤µ¤é¤Ë¡¢ÀȼåÀ¤ò½¤Àµ¤·¤¿·ë²Ì¡¢¡ÖAPI¤Î¸Æ¤Ó½Ð¤·¤«¤é4·å¤ÎPIN¥³¡¼¥É¤òÃê½Ð¤¹¤ë¤³¤È¤Ï¤Ç¤¤Ê¤¯¤Ê¤ê¤Þ¤·¤¿¡£¤·¤«¤·¡¢PIN¥³¡¼¥É¤Ï4·å¤Ê¤Î¤ÇÁíÅö¤¿¤ê¹¶·â¤ËÂФ¹¤ëÀȼåÀ¤Ï¤½¤Î¤Þ¤Þ¤Ç¡¢¤³¤ì¤Ï´Ö°ã¤¤¤Ê¤¯ÌäÂê¤Ç¤¹¡×¤È¤â¸ì¤Ã¤Æ¤¤¤Þ¤¹¡£
¤Ê¤ª¡¢¥í¡¼¥Þ¶µ¹ÄÄ£¤Ë¤è¤ë¤ÈºÇ½é¤ËClick To Pray¤ÎÀȼåÀ¤òȯ¸«¤·ÌäÂê¤òÊó¹ð¤·¤Æ¤¤¿¤Î¤Ï¡¢¥»¥¥å¥ê¥Æ¥£¸¦µæ¼Ô¤ÎElliot Alderson»á¤À¤½¤¦¤Ç¡¢Æ±»á¤Î¤Þ¤È¤á¤¿PDF¥Õ¥¡¥¤¥ë¤ÎÄ´ºº¥ì¥Ý¡¼¥È¤Ï¥¤¥ó¥¿¡¼¥Í¥Ã¥È¾å¤Ç¸ø³«¤µ¤ì¤Æ¤¤¤Þ¤¹¡£
