¥«¥È¥ê¥Ã¥¯¶µ²ñ¤òÅý¼£¤¹¤ë¥í¡¼¥Þ¶µ¹ÄÄ£¤¬¥ê¥ê¡¼¥¹¤·¤¿¤ªµ§¤êÍѤΥ¹¥Þ¡¼¥È¥Ç¥Ð¥¤¥¹¡ÖeRosary¡×¤ª¤è¤ÓÀìÍÑ¥¢¥×¥ê¤Î¡ÖClick To Pray¡×¤Ë¡¢¤µ¤Ã¤½¤¯ÀȼåÀ­¤¬È¯¸«¤µ¤ì¤Æ¤·¤Þ¤¤¡¢·ÉéÊ(¤±¤¤¤±¤ó)¤Ê¿®¼Ô¤¬¥Ï¥Ã¥«¡¼¤Î±Â¿©¤Ë¤Ê¤ë²ÄǽÀ­¤¬Ê󤸤é¤ì¤Æ¤¤¤Þ¤¹¡£

ClickToPray eRosary Account Takeover - Fidus

https://fidusinfosec.com/clicktopray-erosary-account-takeover/

Deus ex hackina: It took just 10 minutes to find data-divulging demons corrupting Pope's Click to Pray eRosary app • The Register

https://www.theregister.co.uk/2019/10/18/vatican_erosary_insecure/

2019ǯ10·î18Æü¤Ë¡¢¥«¥È¥ê¥Ã¥¯¶µ²ñ¤òÅý¼£¤¹¤ë¥í¡¼¥Þ¶µ¹ÄÄ£¤¬¡¢¤¤¤Ä¤Ç¤â½½»ú¤òÀڤäƵ§¤ê¤òÊû¤²¤ë¤³¤È¤¬¤Ç¤­¤ë¥¹¥Þ¡¼¥È¥í¥¶¥ê¥ª¤Î¡ÖeRosary¡×¤òȯɽ¤·¤Þ¤·¤¿¡£ÈÎÇä²Á³Ê¤Ï110¥É¥ë(Ìó1Ëü2000±ß)¤Ç¡¢¥¤¥¿¥ê¥¢¤ÎAmazon¤Ç¤âÈÎÇ䤵¤ì¤Æ¤¤¤Þ¤¹¡£



¤³¤Î¥¹¥Þ¡¼¥È¥í¥¶¥ê¥ª¤ÈÏ¢·È¤·¤Æ»ÈÍѤ¹¤ë¤ªµ§¤êÀìÍÑ¥¢¥×¥ê¤Î¡ÖClick To Pray¡×¤ËÀȼåÀ­¤¬Â¸ºß¤·¤Æ¤ª¤ê¡¢¤ªµ§¤ê¤Î¤¿¤á¤Ë¥¢¥×¥ê¤ò¥¤¥ó¥¹¥È¡¼¥ë¤·¤¿¥æ¡¼¥¶¡¼¤¬¥Ï¥Ã¥­¥ó¥°¤µ¤ì¤ë²ÄǽÀ­¤¬»ØÅ¦¤µ¤ì¤Æ¤¤¤Þ¤¹¡£



¥»¥­¥å¥ê¥Æ¥£´ë¶È¤ÎFidus InfoSecurity¤Ï¡¢¸ø¼°Twitter¥¢¥«¥¦¥ó¥È¾å¤Ç¡Ö²æ¡¹¤Î¸¦µæ¥Á¡¼¥à¤¬eRosary¤ÎÀìÍÑ¥¢¥×¥ê(Click To Pray)¤òÄ´¤Ù¤À¤·¤Æ5ʬ̤Ëþ¤Ç¡¢´°Á´¤Ê¥¢¥«¥¦¥ó¥È¾è¤Ã¼è¤ê¥¨¥¯¥¹¥×¥í¥¤¥È¤ò³«È¯¤¹¤ë¤³¤È¤ËÀ®¸ù¤·¤Þ¤·¤¿¡£¥¨¥¯¥¹¥×¥í¥¤¥È¤ò»È¤¨¤Ð¥á¡¼¥ë¥¢¥É¥ì¥¹¡¦ÅÅÏÃÈֹ桦(¥æ¡¼¥¶¡¼¤Î)¿ÈĹ¡¦Âνš¦¤½¤Î¾¤Î¸Ä¿Í¾ðÊó¤òÅð¤ß½Ð¤¹¤³¤È¤â¤Ç¤­¤Þ¤¹¡£¹¬¤¤¤Ê¤³¤È¤Ë¡¢È¯¸«¤·¤¿ÀȼåÀ­¤Ï´û¤ËÊó¹ð¤µ¤ì¤Æ¤ª¤ê¡¢¤Þ¤ÀÀȼåÀ­¤òÍѤ¤¤¿¥¨¥¯¥¹¥×¥í¥¤¥È¤Ï¸«¤é¤ì¤Þ¤»¤ó¡×¤È¥Ä¥¤¡¼¥È¤·¡¢´Êñ¤Ë¥Ï¥Ã¥­¥ó¥°¤Ç¤­¤¿¤³¤È¤òÊó¹ð¤·¤Æ¤¤¤Þ¤¹¡£



¾åµ­¤Î¥Ä¥¤¡¼¥È¤òÅê¹Æ¤·¤¿ºÝ¡¢Fidus InfoSecurity¤ÏClick To Pray¤Ë¸ºß¤¹¤ëÀȼåÀ­¤Î¾ÜºÙ¤òÌÀ¤é¤«¤Ë¤·¤Æ¤¤¤Ê¤«¤Ã¤¿¤Î¤Ç¤¹¤¬¡¢¤½¤ÎÍâÆü¤ËTwitter¤òºÆ¤Ó¹¹¿·¤·¤Æ¡¢¡ÖÀèÆü¤Î¥»¥­¥å¥ê¥Æ¥£Êó¹ð¤Î¸å¡¢eRosary¤ÎÀìÍÑ¥¢¥×¥ê¤ÎÇØ¸å¤Ë¤¢¤ë¥Á¡¼¥à¤¬½¤Àµ¥×¥í¥°¥é¥à¤òȯ¹Ô¤·¤¿¤Î¤Ç¡¢¤è¤ê¿¤¯¤Î¾ðÊó¤ò³«¼¨¤Ç¤­¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤·¤¿¡×¤È¥Ä¥¤¡¼¥È¡£¤½¤·¤Æ¡¢¸ø¼°¥µ¥¤¥È¾å¤ÇÀȼåÀ­¤Ë´Ø¤¹¤ë°ìÉô¤Î¸ø³«¤Ç¤­¤ë¾ðÊó¤ò³«¼¨¤·¤Æ¤¤¤Þ¤¹¡£



Click To Pray¥¢¥×¥ê¤òÍøÍѤ¹¤ë¾ì¹ç¡¢¼«¿È¤Î¥á¡¼¥ë¥¢¥É¥ì¥¹¤òÆþÎϤ·¤Æ¥¢¥«¥¦¥ó¥È¤òºîÀ®¤¹¤ë¤«¡¢Google¡¦Facebook¥¢¥«¥¦¥ó¥È¤ÈÏ¢·È¤·¤Æ¥¢¥«¥¦¥ó¥È¤òºîÀ®¤¹¤ëÊýË¡¤Î2¤Ä¤¬ÁªÂò¤Ç¤­¤Þ¤¹¡£



¼«¿È¤Î¥á¡¼¥ë¥¢¥É¥ì¥¹¤òÆþÎϤ¹¤ë¾ì¹ç¡¢¥Ñ¥¹¥ï¡¼¥É¤òÀßÄꤹ¤ë¤Î¤Ç¤Ï¤Ê¤¯4·å¤ÎPIN¥³¡¼¥É¤Ç¥¢¥«¥¦¥ó¥È¤òÊݸ¤Þ¤¹¡£PIN¥³¡¼¥É¤Ç¥¢¥«¥¦¥ó¥È¤òÊݸ¡¢¥æ¡¼¥¶¡¼¥¢¥«¥¦¥ó¥È¤ò¥ê¥»¥Ã¥È¤·¤¿¾ì¹ç¡¢ÅÐÏ¿¤·¤¿¥á¡¼¥ë¥¢¥É¥ì¥¹°¸¤Ë¥á¡¼¥ë¤¬Á÷¿®¤µ¤ì¤ë¤½¤¦¤Ç¤¹¡£



¥¢¥×¥ê¤ÎAPI¤Ï¥Ð¥Ã¥¯¥¨¥ó¥É¥·¥¹¥Æ¥à¤ÈÄÌ¿®¤¹¤ë¤Î¤Ç¤¹¤¬¡¢ÀȼåÀ­¤Ë¤è¤êAPI·Ðͳ¤Ç¥æ¡¼¥¶¡¼¤ÎÍøÍѤ·¤Æ¤¤¤ëüËö¾ðÊ󡢥᡼¥ë¥¢¥É¥ì¥¹¾ðÊó¡¢Ãϰè¾ðÊó¤Ê¤É¤òÁ÷¿®¤·¤Æ¤·¤Þ¤Ã¤Æ¤¤¤¿¤³¤È¤¬ÌÀ¤é¤«¤Ë¤Ê¤Ã¤Æ¤ª¤ê¡¢API¤ÎÁ÷¿®¤¹¤ë¾ðÊó¤Ï°Å¹æ²½¤µ¤ì¤Æ¤¤¤Ê¤¤¤¿¤á´Êñ¤ËÆÉ¤ß¼è¤ê¤Ç¤­¤Æ¤·¤Þ¤Ã¤¿¤È¤Î¤³¤È¡£



API¤Î4·å¤ÎPIN¥³¡¼¥É¤â¤·¤Ã¤«¤êÌÀµ­¤µ¤ì¤Æ¤¤¤Þ¤¹¡£



¤³¤ÎPIN¥³¡¼¥É¤òÍѤ¤¤Æ¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ë¥í¥°¥¤¥ó¤¹¤ì¤Ð¡¢¥æ¡¼¥¶¡¼¥¢¥«¥¦¥ó¥È¤Î¥×¥í¥Õ¥£¡¼¥ë²èÌ̤«¤é¿ÈĹ¡¦Âνš¦À­ÊÌ¡¦À¸Ç¯·îÆü¤Ê¤É¤Î¾ðÊó¤òÃΤ뤳¤È¤¬²Äǽ¡£



¤Ê¤ª¡¢Fidus InfoSecurity¤Ï¡Ö4·å¤ÎPIN¥³¡¼¥É¤ò»ÈÍѤ¹¤ë¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤È¤¤¤¦¤Î¤Ï¶½Ì£¿¼¤¤¤â¤Î¤Ç¤¹¡£API¤Î¥ì¡¼¥ÈÀ©¸Â¤â¤Ê¤¤¤¿¤á¡¢²æ¡¹¤¬¸«¤Ä¤±¤¿ÀȼåÀ­¤¬¤Ê¤¯¤Æ¤â¥¢¥«¥¦¥ó¥È¤Ë¥¢¥¯¥»¥¹¤¹¤ë¤³¤È¤ÏÈæ³ÓŪ´Êñ¤Ç¤·¤¿¡×¤Èµ­¤·¤Æ¤¤¤Þ¤¹¡£

¤Þ¤¿¡¢IT·Ï¥Ë¥å¡¼¥¹¥á¥Ç¥£¥¢¤ÎThe Register¤¬¥À¥ß¡¼¥¢¥«¥¦¥ó¥È¤òºîÀ®¤·¤¿¤È¤³¤í¡¢Fidus InfoSecurity¤ÎÄ´ºº¥Á¡¼¥à¤¬´Êñ¤Ë¥¢¥«¥¦¥ó¥È¤ò¥Ï¥¤¥¸¥ã¥Ã¥¯¤¹¤ë¤³¤È¤ËÀ®¸ù¤·¤¿¤È¤âÊ󤸤é¤ì¤Æ¤¤¤Þ¤¹¡£¥¢¥«¥¦¥ó¥È¤Ë¤Ï¥æ¡¼¥¶¡¼¸Ä¿Í¤Îºâ̳¾ðÊó¤Ê¤É¤Ïµ­Ï¿¤µ¤ì¤Æ¤¤¤Þ¤»¤ó¤¬¡¢¥Ï¥Ã¥­¥ó¥°¤Ë¤è¤ëϳ±Ì¤Î²ÄǽÀ­¤¬¤¢¤ë¸Ä¿Í¾ðÊó¤Ï¡ÖÃæ¹ñ¤Î¤è¤¦¤Ê¹ñ¤Ç¸ø³«¤µ¤ì¤ì¤Ð¥æ¡¼¥¶¡¼¤Ë»³²¤òÍ¿¤¨¤ë²ÄǽÀ­¤¬¤¢¤ë¡×¤ÈThe Register¤Ïµ­¤·¤Æ¤¤¤Þ¤¹¡£

Fidus InfoSecurity¤¬ÀȼåÀ­¤òÊó¹ð¤·¤¿¸å¡¢36»þ´Ö°ÊÆâ¤ËÌäÂê¤Ï½¤Àµ¤µ¤ì¤¿¤½¤¦¤Ç¡¢Fidus InfoSecurity¤ÎÁÏÀ߼ԤǤ¢¤ëAndrew Mabbitt»á¤Ï¡ÖClick To Pray¤ÎAPIÌäÂê¤ò½¤Àµ¤·¤Æ¤ª¤ê¡¢¤½¤ÎÊýË¡¤ÏÈó¾ï¤ËÊ£»¨¤Ç¤·¤¿¡×¤È¥³¥á¥ó¥È¡£¤µ¤é¤Ë¡¢ÀȼåÀ­¤ò½¤Àµ¤·¤¿·ë²Ì¡¢¡ÖAPI¤Î¸Æ¤Ó½Ð¤·¤«¤é4·å¤ÎPIN¥³¡¼¥É¤òÃê½Ð¤¹¤ë¤³¤È¤Ï¤Ç¤­¤Ê¤¯¤Ê¤ê¤Þ¤·¤¿¡£¤·¤«¤·¡¢PIN¥³¡¼¥É¤Ï4·å¤Ê¤Î¤ÇÁíÅö¤¿¤ê¹¶·â¤ËÂФ¹¤ëÀȼåÀ­¤Ï¤½¤Î¤Þ¤Þ¤Ç¡¢¤³¤ì¤Ï´Ö°ã¤¤¤Ê¤¯ÌäÂê¤Ç¤¹¡×¤È¤â¸ì¤Ã¤Æ¤¤¤Þ¤¹¡£

¤Ê¤ª¡¢¥í¡¼¥Þ¶µ¹ÄÄ£¤Ë¤è¤ë¤ÈºÇ½é¤ËClick To Pray¤ÎÀȼåÀ­¤òȯ¸«¤·ÌäÂê¤òÊó¹ð¤·¤Æ¤­¤¿¤Î¤Ï¡¢¥»¥­¥å¥ê¥Æ¥£¸¦µæ¼Ô¤ÎElliot Alderson»á¤À¤½¤¦¤Ç¡¢Æ±»á¤Î¤Þ¤È¤á¤¿PDF¥Õ¥¡¥¤¥ë¤ÎÄ´ºº¥ì¥Ý¡¼¥È¤Ï¥¤¥ó¥¿¡¼¥Í¥Ã¥È¾å¤Ç¸ø³«¤µ¤ì¤Æ¤¤¤Þ¤¹¡£