Google¤Î¥Ð¥°Ê󾩶⥤¥Ù¥ó¥È¡ÖLLM bugSWAT¡×¤Ç740Ëü±ßĶ¤ò²Ô¤¤¤À¥Ï¥Ã¥«¡¼¤¿¤Á
Google¼çºÅ¤Î¥Ð¥°È¯¸«¥¤¥Ù¥ó¥È¡ÖLLM bugSWAT¡×¤Ç¡¢5Ëü¥É¥ë(Ìó740Ëü±ß)¤ò³ÍÆÀ¤·¤¿¤È¤¤¤¦¥µ¥¤¥Ð¡¼¥»¥¥å¥ê¥Æ¥£¥¨¥ó¥¸¥Ë¥¢¤Î¥í¥Ë¡¦¥«¥ë¥¿»á¤¬¡¢¥¤¥Ù¥ó¥È¤Ç¤Î½ÐÍè»ö¤ò¼«¿È¤Î¥Ö¥í¥°¤Ë¤Þ¤È¤á¤Æ¤¤¤Þ¤¹¡£
We Hacked Google A.I. for $50,000 - Lupin & Holmes
https://www.landh.tech/blog/20240304-google-hack-50000/
À¸À®AI¤äÂ絬ÌϸÀ¸ì¥â¥Ç¥ë(LLM)¤Ï¶áǯ¤Î¥Æ¥¯¥Î¥í¥¸¡¼¶È³¦¤Î¥È¥ì¥ó¥É¤È¤Ê¤Ã¤Æ¤ª¤ê¡¢ChatGPT¤Î³«È¯¸µ¤Ç¤¢¤ëOpenAI¤À¤±¤Ç¤Ê¤¯¡¢Meta¤äMicrosoft¡¢Google¤È¤¤¤Ã¤¿Âç¼ê¥Æ¥¯¥Î¥í¥¸¡¼´ë¶È¤âÀ¸À®AI¤äLLM¤Î³«È¯¤ò¿Ê¤á¤Æ¤¤¤Þ¤¹¡£AI¥Æ¥¯¥Î¥í¥¸¡¼¤ÎȯŸ¤Ë¤è¤ê¡¢Â¿¤¯¤Î¿Í¡¹¤¬Æü¡¹¤Î¥¿¥¹¥¯¤ò´ÊÁDz½¤¹¤ë¤Ù¤¯AI¥Ä¡¼¥ë¤òÍøÍѤ·¤Æ¤¤¤Þ¤¹¤¬¡¢¤½¤Î²áÄø¤Ç´ë¶È¦¤¬´ðËÜŪ¤Ê¥»¥¥å¥ê¥Æ¥£¸¶Â§¤ò¸«Íî¤È¤·¡¢¿·¤·¤¤¼ïÎà¤Î¥»¥¥å¥ê¥Æ¥£ÌäÂ꤬ȯÀ¸¤¹¤ë¤È¤¤¤¦¥±¡¼¥¹¤â¤¢¤ë¤½¤¦¤Ç¤¹¡£
¤³¤Î¤¿¤á¡¢AI´ØÏ¢¥»¥¥å¥ê¥Æ¥£¤ÏºÇÀèü¤Î¡Ö¶½Ì£¿¼¤¤¸¦µæʬÌî¡×¤È¤Ê¤Ã¤Æ¤¤¤Æ¡¢Google¤¬¤¤¤ÁÁ᤯ȿ±þ¤·¡¢ÀȼåÀÊó½·¥×¥í¥°¥é¥à¤Ê¤É¤ò¼çƳ¤¹¤ë¥Á¡¼¥à¤Ë¤è¤Ã¤Æ¡ÖLLM bugSWAT¡×¤¬³«ºÅ¤µ¤ì¤ë¤è¤¦¤Ë¤Ê¤Ã¤¿¤È¤Î¤³¤È¡£
LLM bugSWAT¤Ï¡Ö¥È¥Ã¥×¥Ï¥Ã¥«¡¼¤òͶ¤Ã¤Æ»²²Ã¤·¤Æ¤âOK¡×¤È¤¤¤¦¥¤¥Ù¥ó¥È¤Ç¡¢Àè¤Ë»²²Ã¤ò·è¤á¤Æ¤¤¤¿¥¸¥ç¥»¥Õ»á¤È¥¸¥ã¥¹¥Æ¥£¥ó»á¤ËͶ¤ï¤ë·Á¤Ç¡¢¥«¥ë¥¿»á¤â¥¤¥Ù¥ó¥È¤Ë»²²Ã¤¹¤ë¤³¤È¤Ë¤Ê¤ê¤Þ¤·¤¿¡£Ï¢ÍíÀè¸ò´¹¤ò¹Ô¤Ã¤¿¤È¤¡¢¥«¥ë¥¿»á¤Ï¥¸¥ç¥»¥Õ»á¤«¤é¡ÖGoogle¤ò¥Ï¥Ã¥¥ó¥°¤·¤¿¤¤¤Ç¤¹¤«¡©¡×¤È¿Ò¤Í¤é¤ì¤¿¤½¤¦¤Ç¤¹¡£
LLM bugSWAT¤Ç¤Ï»²²Ã¼Ô¤¬Google¤Î³«È¯¼Ô¤ËÂФ·¤Æ¡Ö¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤¬¤É¤Î¤è¤¦¤ËÆ°ºî¤¹¤ë¤Î¤«¡×¤Ê¤É¤Ë¤Ä¤¤¤Æ¼ÁÌä¤Ç¤¤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤ª¤ê¡¢»²²Ã¼Ô¤¬Í¥¤ì¤¿È¯¸«¤òÊó¹ð¤Ç¤¤ë¤è¤¦¤Ê²¼ÃϤ¬·ÁÀ®¤µ¤ì¤Æ¤¤¤ë¤È¤Î¤³¤È¡£°Ê²¼¤Ï»²²Ã¼Ô¤ËÇÛÉÛ¤µ¤ì¤¿¥Ñ¡¼¥«¡¼¤Ç¡¢ÇØÃæ¤Ë¤ÏAI¤¬½ÐÎϤ·¤¿¥¤¥é¥¹¥È¤¬¥×¥ê¥ó¥È¤µ¤ì¤Æ¤¤¤Þ¤¹¡£¤¿¤À¤·¡¢¥Ñ¡¼¥«¡¼¤ò¼õ¤±¼è¤Ã¤¿Ãʳ¬¤Ç¤ÏGoogle¤Î²èÁüÀ¸À®AI¤Ïȯɽ¤µ¤ì¤Æ¤¤¤Ê¤«¤Ã¤¿¤¿¤á¡¢AI¤Ë¤è¤ë¥¤¥é¥¹¥È¤«Èݤ«¤òȽÃǤ¹¤ë¤³¤È¤Ï¤Ç¤¤Ê¤«¤Ã¤¿¤½¤¦¤Ç¤¹¡£
¥¤¥Ù¥ó¥È¤Ë»²²Ã¤·¤¿»þÅÀ¤Ç¡¢¤¹¤Ç¤Ë¥¸¥ç¥»¥Õ»á¤ÏGemini(Åö»þ¤ÎBard)¤Î¥Ó¥¸¥ç¥óµ¡Ç½Æâ¤Ë¸ºß¤·¤¿¡Ö°ÂÁ´¤Ç¤Ê¤¤Ä¾ÀÜ¥ª¥Ö¥¸¥§¥¯¥È»²¾È¤ÎÀȼåÀ(IDOR¡§Insecure Direct Object Reference)¡×¤òȯ¸«¤·¤Æ¤¤¤¿¤½¤¦¤Ç¤¹¡£¥Ó¥¸¥ç¥óµ¡Ç½¤Ï¥¢¥Ã¥×¥í¡¼¥É¤µ¤ì¤¿²èÁü¤ò½èÍý¤·¤Æµ½Ò¤¹¤ë¤è¤¦¤ËÀ߷פµ¤ì¤¿¤â¤Î¤Ç¤¹¤¬¡¢¥¸¥ç¥»¥Õ»á¤Îȯ¸«¤·¤¿IDOR¤ò°ÍѤ¹¤ë¤È¡¢¥æ¡¼¥¶¡¼¤Îµö²Ä¤ä¸¡¾Ú¥×¥í¥»¥¹¤Ê¤·¤ÇÊ̥桼¥¶¡¼¤Î²èÁü¤Ë¥¢¥¯¥»¥¹¤¹¤ë¤³¤È¤¬²Äǽ¤È¤Ê¤Ã¤Æ¤·¤Þ¤Ã¤¿¤½¤¦¤Ç¤¹¡£
¤³¤ÎIDOR¤òÍøÍѤ¹¤ë¤³¤È¤Ç¡¢Bard¤ò¤À¤Þ¤·¤ÆÊ̥桼¥¶¡¼¤¬ÆþÎϤ·¤¿²èÁü¤òÀâÌÀ¤µ¤»¤ë¤³¤È¤¬¤Ç¤¤ë¤¿¤á¡¢¹¶·â¼Ô¤ÏÆÃÄê¤Î¥æ¡¼¥¶¡¼¤¬¥¢¥Ã¥×¥í¡¼¥É¤·¤¿¤¢¤é¤æ¤ë¼Ì¿¿¤ËÉÔÀµ¤Ë¥¢¥¯¥»¥¹¤Ç¤¤ë¤è¤¦¤Ë¤Ê¤ê¤Þ¤¹¡£¤µ¤é¤Ë¡¢Bard¤Î¸÷³Øʸ»úǧ¼±(OCR)¤ÎÀºÅÙ¤ò¹Í¤¨¤ë¤È¡¢²èÁü¤Ë¼Ì¤ê¤³¤ó¤À¼ýÆþ¡¦¥á¡¼¥ë¤Ê¤É¤Îµ¡Ì©¾ðÊó¤¬Ï³¤¨¤¤¤¹¤ë²ÄǽÀ¤â¤¢¤Ã¤¿¤È¥«¥ë¥¿»á¤Ïµ¤·¤Æ¤¤¤Þ¤¹¡£
¥«¥ë¥¿»á¤Ï¼«Ê¬¤Ç¤â¥Ð¥°¤òȯ¸«¤·¤¿¤¤¤È¹Í¤¨¡¢¤¹¤Ù¤Æ¤Î¥×¥í¥¥·¤òµ¯Æ°¤·¤Æ¥Õ¥í¥ó¥È¥¨¥ó¥É¤È¥Ð¥Ã¥¯¥¨¥ó¥É¤Î´Ö¤Î¤¹¤Ù¤Æ¤Î¤ä¤ê¼è¤ê¤ò¥Á¥§¥Ã¥¯¤·¤¿¤½¤¦¤Ç¤¹¡£¤½¤ÎÃæ¤Ç¡¢API¥¨¥ó¥É¥Ý¥¤¥ó¥È¤Î¤Ò¤È¤Ä¤È¤·¤Æ¼Â¹Ô¤µ¤ì¤ëGraphQL¤ËÌܤòÉÕ¤±¡¢¥µ¡¼¥Ó¥¹µñÈÝ(DoS)¤òľÀܸ«¤Ä¤±¤è¤¦¤È¤·¤¿ÌÏÍÍ¡£
¤³¤ÎÃæ¤Ç¡¢¥«¥ë¥¿»á¤é¤ÏGraphQL¤Î´ûÃΤÎÀßÄê¥ß¥¹¤Ç¤¢¤ë¥Ç¥£¥ì¥¯¥Æ¥£¥Ö¥ª¡¼¥Ð¡¼¥í¡¼¥É¤òȯ¸«¤·¤Þ¤¹¡£¥Ç¥£¥ì¥¯¥Æ¥£¥Ö¥ª¡¼¥Ð¡¼¥í¡¼¥É¤Ï²á¾ê¤Ê¿ô¤Î¥Ç¥£¥ì¥¯¥Æ¥£¥Ö¤ò»ÈÍѤ·¤Æ¥¯¥¨¥ê¤¬°Õ¿ÞŪ¤ËºîÀ®¤µ¤ì¤¿¾ì¹ç¤ËȯÀ¸¤¹¤ë¤¿¤á¡¢¥µ¡¼¥Ð¡¼¤Î³Æ¥Ç¥£¥ì¥¯¥Æ¥£¥Ö¤Î½èÍý¤ò°ÍѤ¹¤ë·Á¤Çµ¯¤¤ë¤½¤¦¤Ç¤¹¡£
¥«¥ë¥¿»á¤é¤ÏGoogle Cloud¤¬¥Ç¥£¥ì¥¯¥Æ¥£¥Ö¥ª¡¼¥Ð¡¼¥í¡¼¥É¤ËÂФ·¤ÆÀȼå¤Ê²ÄǽÀ¤¬¤¢¤ë¤È¹Íθ¤·¥Æ¥¹¥È¤ò¼Â»Ü¡£¤¹¤ë¤È¡¢¥Ç¥£¥ì¥¯¥Æ¥£¥Ö¤òÄɲ乤ì¤Ð¤¹¤ë¤Û¤É¥Ð¥Ã¥¯¥¨¥ó¥É¤¬¥ê¥¯¥¨¥¹¥È¤Ë±þÅú¤¹¤ë¤Þ¤Ç¤Ë¤«¤«¤ë»þ´Ö¤¬Ä¹¤¯¤Ê¤ë¤³¤È¤¬È½ÌÀ¤·¤Þ¤·¤¿¡£
¾¤Ë¤â¥«¥ë¥¿»á¤é¤ÏBard¤Î¥³¥ó¥Æ¥ó¥Ä¥»¥¥å¥ê¥Æ¥£¥Ý¥ê¥·¡¼(CSP)¤ò¥Ð¥¤¥Ñ¥¹¤·¡¢Bard¤«¤é¥æ¡¼¥¶¡¼¤Î¸Ä¿Í¾ðÊó¤òÈ´¤½Ð¤¹¼êË¡¤òȯ¸«¤·¤Æ¤¤¤Þ¤¹¡£Bard¤ËCSP¤¬ºÎÍѤµ¤ì¤Æ¤¤¤ë¤Î¤Ï¡¢¥Ö¥é¥¦¥¶¤Ç¼Â¹Ô²Äǽ¤Ê¥¹¥¯¥ê¥×¥È¡¦²èÁü¡¦¥¹¥¿¥¤¥ë¤Ê¤É¤Î͸ú¤Ê¥½¡¼¥¹¤È¤·¤Æ¹Íθ¤¹¤Ù¤¥É¥á¥¤¥ó¤ò¥Ð¥Ã¥¯¥¨¥ó¥É¥µ¡¼¥Ð¡¼¤¬»ØÄê¤Ç¤¤ë¤è¤¦¤Ë¤¹¤ë¤³¤È¤Ç¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤ä¥Ç¡¼¥¿¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó¹¶·â¤ò»Å³Ý¤±¤é¤ì¤ë¤³¤È¤ò²óÈò¤¹¤ë¤¿¤á¤Ç¤¹¡£¥«¥ë¥¿»á¤é¤Ï¥É¥á¥¤¥ó¤Î°ìÉô¤òURL¥¨¥ó¥³¡¼¥É¤¹¤ë¤Ê¤É¤·¤Æ¡¢CSP¤ò¥Ð¥¤¥Ñ¥¹¤¹¤ë¤³¤È¤ËÀ®¸ù¤·¤Æ¤ª¤ê¡¢ÆÃÄê¥æ¡¼¥¶¡¼¤Î¥á¡¼¥ë¤òÈ´¤½Ð¤¹¤³¤È¤ËÀ®¸ù¤·¤Æ¤¤¤Þ¤¹¡£
¤³¤ì¤é¤ÎÀ®²Ì¤È¤·¤Æ¡¢¥«¥ë¥¿»á¤é¤Ï¹ç·×¤Ç5Ëü¥É¥ë¤ÎÊ󾩶â¤ò³ÍÆÀ¤·¤Æ¤¤¤Þ¤¹¡£