¥»¥­¥å¥ê¥Æ¥£¸¦µæ¼Ô¤ÎSam Curry»á¤Ï6·î3Æü(Êƹñ»þ´Ö)¡¢¡ÖHacking Millions of Modems (and Investigating Who Hacked My Modem)¡×¤Ë¤ª¤¤¤Æ¡¢Êƹñ¤Î¥±¡¼¥Ö¥ë¥Æ¥ì¥Ó¥×¥í¥Ð¥¤¥À¡¼¡ÖCox Communications¡×¤¬¥¤¥ó¥¿¡¼¥Í¥Ã¥È²óÀþ²ÃÆþ¼Ô¤ËÂߤ·½Ð¤·¤Æ¤¤¤ë̵ÀþLAN¥ë¡¼¥¿¤Î¥ê¥â¡¼¥È´ÉÍý¥¤¥ó¥¿¥Õ¥§¡¼¥¹¤ËÀȼåÀ­¤¬Â¸ºß¤·¤¿¤ÈÅÁ¤¨¤¿¡£¤³¤ì¤Ï¡¢Æ±¼Ò¤Î¤¹¤Ù¤Æ¤Î¸ÜµÒ¤¬´í¸±¤Ë¤µ¤é¤µ¤ì¤¿¤³¤È¤ò°ÕÌ£¤·¤Æ¤ª¤ê¡¢¿ôÉ´Ëü¤Î¥ë¡¼¥¿¤¬¿¯³²¤Î´íµ¡¤Ë¤µ¤é¤µ¤ì¤Æ¤¤¤¿¤³¤È¤Ë¤Ê¤ë¡£

Hacking Millions of Modems (and Investigating Who Hacked My Modem)

¡ûSam Curry»á¤¬·Ð¸³¤·¤¿¿¯³²

Sam Curry»á¤Ï3ǯÁ°¡¢¥»¥­¥å¥ê¥Æ¥£´ØÏ¢ºî¶È¤ò¹Ô¤¦¤¿¤á³°Éô¤Ë´Êñ¤ÊHTTP(Hypertext Transfer Protocol)¥µ¡¼¥Ð¤òΩ¤Á¾å¤²¡¢ÄÌ¿®¥í¥°¤ò³Îǧ¤·¤Æ¤¤¤¿¡£¤¹¤ë¤È¼«¿È¤¬¥¢¥¯¥»¥¹¤·¤¿Àµ¾ï¤Ê¥í¥°¤Îľ¸å¤Ë³°Éô¤ÎIP¥¢¥É¥ì¥¹¤«¤éƱ¤¸URL¤Ø¤Î¥¢¥¯¥»¥¹¥í¥°¤¬µ­Ï¿¤µ¤ì¡¢¿¯³²¤Î²ÄǽÀ­¤Ëµ¤¤Å¤¤¤¿¤È¤¤¤¦¡£

ÂðÆâ¤Î¾¤Î¥Ç¥Ð¥¤¥¹¤Ê¤É¤«¤é¥¢¥¯¥»¥¹¤·¤Æ¤âƱÍÍ¤Î¥í¥°¤¬µ­Ï¿¤µ¤ì¤¿¤³¤È¤«¤é¡¢¹¶·â¼Ô¤Ï²¿¤é¤«¤ÎÌÜŪ¤ÇÄÌ¿®¤ò˵¼õ¤·¤Æ¥¢¥¯¥»¥¹¤ò¥ê¥×¥ì¥¤¤·¤¿¤È¤ß¤é¤ì¤Æ¤¤¤ë¡£Sam Curry»á¤Ïͧ¿Í¤Î¶¨ÎϤòÆÀ¤Æ¥í¥°¤Ëµ­Ï¿¤µ¤ì¤¿¹¶·â¼Ô¤ÎIP¥¢¥É¥ì¥¹¤òÄ´ºº¤·¡¢¤½¤ì¤¬¥Õ¥£¥Ã¥·¥ó¥°¥µ¥¤¥È¤ä¥á¡¼¥ë¥µ¡¼¥Ð¤Î¥É¥á¥¤¥ó¤È°ìÃפ¹¤ë¤³¤È¤ò³Îǧ¤·¤Æ¤¤¤ë¡£

Sam Curry»á¤Ï¹¶·â¼Ô¤¬¤É¤³¤ÇÄÌ¿®¤ò˵¼õ¤·¤Æ¤¤¤ë¤Î¤«³Îǧ¤¹¤ë¤¿¤á¡¢¤¤¤¯¤Ä¤«¤ÎÄÌ¿®·ÐÏ©¤ò¸¡¾Ú¡£¤½¤Î·ë²Ì¡¢Cox Communications¤«¤éÂߤ·½Ð¤µ¤ì¤¿ÌµÀþLAN¥ë¡¼¥¿¤Ë¸¶°ø¤¬¤¢¤ë¤³¤È¤òÆͤ­»ß¤á¤¿¡£

¿¯³²¤µ¤ì¤¿¥Ç¥Ð¥¤¥¹¤¬È½ÌÀ¤·¤¿¤¿¤á¡¢Sam Curry»á¤Ï®¤ä¤«¤Ë¥ë¡¼¥¿¤ÎÅŸ»¤òÈ´¤¤¤ÆÈï³²¤Î³ÈÂç¤òËɻߡ£¤·¤«¤·¡¢¤³¤Î¤Þ¤Þ¤Ç¤Ï¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤ËÀܳ¤Ç¤­¤Ê¤¤¤¿¤á¡¢Cox Communications¤Ëµ¡´ï¤Î¸ò´¹¤ò¿½ÀÁ¤·¤¿¡£¸ò´¹¤Ë¤Ï¿¯³²¤µ¤ì¤¿¸Å¤¤¥ë¡¼¥¿¤ò°ú¤­ÅϤ¹É¬Íפ¬¤¢¤ê¡¢Ä´ºº¤Ï¤³¤³¤Ç°ìöÂǤÁÀÚ¤ê¤È¤Ê¤Ã¤¿¡£

¡ûÄ´ºº¤ÎºÆ³«

¿¯³²¤Î»ö°Æ¤«¤é3ǯ¸å¤Î2024ǯ½é¤áº¢¡¢Sam Curry»á¤Ïͧ¿Í¤Î°ú¤Ã±Û¤·¤ò¼êÅÁ¤¤¡¢Cox Communications¤Î¥ë¡¼¥¿¤òÀßÃÖ¤¹¤ëºî¶È¤ò¼Â»Ü¤·¤¿¡£¤³¤Î¤È¤­¡¢Cox Communications¤Î¥ª¥Ú¥ì¡¼¥¿¡¼¤¬¥ê¥â¡¼¥È¤«¤éWi-Fi¥Ñ¥¹¥ï¡¼¥É¤ò´Þ¤à¥ë¡¼¥¿¤ÎÀßÄê¤òÊѹ¹¤·¤¿¤³¤È¤ò³Îǧ¡£Sam Curry»á¤ÏCox Communications¤Î¥ë¡¼¥¿¤Ë¥ê¥â¡¼¥È´ÉÍýµ¡Ç½¤¬¤¢¤ë¤³¤È¤òÃΤꡢ¤³¤Îµ¡Ç½¤Ë¶½Ì£¤ò»ý¤ÁÄ´ºº¤òºÆ³«¡£

Cox Communications¤Î̵ÀþLAN¥ë¡¼¥¿¤ËÅëºÜ¤µ¤ì¤¿¥ê¥â¡¼¥È´ÉÍýµ¡Ç½¤Ï¡Ö¥Æ¥¯¥Ë¥«¥ë¥ì¥Ý¡¼¥È069(TR-069)¡×¤È¸Æ¤Ð¤ì¤ë¸ÜµÒÂðÆⵡ´ï¤Î¥ê¥â¡¼¥È´ÉÍý¤ª¤è¤Ó¥×¥í¥Ó¥¸¥ç¥Ë¥ó¥°¤Î¤¿¤á¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥óÁØ¥×¥í¥È¥³¥ë¤ò¼ÂÁõ¤·¤¿¤â¤Î¡£ÆâÉô¤Ç¤ÏCPE WAN Management Protocol(CWMP)¤ò»ÈÍѤ¹¤ë¡£

Ä´ººÂоݤϴë¶È¸þ¤±¤Ë¥ê¥â¡¼¥È´ÉÍýµ¡Ç½¤òÄ󶡤¹¤ëCox Communications¤Î¥Ó¥¸¥Í¥¹¥Ý¡¼¥¿¥ë¥µ¥¤¥È¡£¤³¤Î¥Ý¡¼¥¿¥ë¥µ¥¤¥È¤«¤é¤ÏÌó700¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¡¦¥×¥í¥°¥é¥ß¥ó¥°¡¦¥¤¥ó¥¿¡¼¥Õ¥§¥¤¥¹(API: Application Programming Interface)¤¬Ä󶡤µ¤ì¤Æ¤¤¤ë¡£

Sam Curry»á¤Ï¥Ý¡¼¥¿¥ë¥µ¥¤¥È¤Î¥¢¥«¥¦¥ó¥È¤ò»ý¤Ã¤Æ¤¤¤Ê¤«¤Ã¤¿¤¿¤á¡¢¸ø³«¤µ¤ì¤Æ¤¤¤ëAPI¤ÎÄ´ºº¤«¤é³«»Ï¤·¤¿¡£¤½¤·¤ÆAPI¤Î±þÅú¤òÄ´¤Ù¤Æ¤¤¤ë¤¦¤Á¤Ë¡¢¥ê¥¯¥¨¥¹¥È¤òºÆ¼Â¹Ô¤¹¤ë¤À¤±¤ÇAPI¤Îǧ¾Ú¤ò²óÈò¤Ç¤­¤ë¤È¤¤¤¦½ÅÂç¤ÊÉÔ¶ñ¹ç¤òȯ¸«¤·¤¿¡£¤Þ¤¿¡¢¸ÜµÒ¾ðÊó¤Î¸¡º÷¡¢¥Ç¥Ð¥¤¥¹¾ðÊó¤Î¼èÆÀ¡¢¥¢¥«¥¦¥ó¥È¾ðÊó¤Î¼èÆÀ¤â´Êñ¤Ë¤Ç¤­¤ë¤³¤È¤ò³Îǧ¤·¤¿¡£

¤¿¤À¡¢´Î¿´¤Î¥Ç¥Ð¥¤¥¹ÀßÄê¤ÎÊѹ¹¤Ë¤ÏÊ£¿ô¤Î¾ðÊó¤ò°Å¹æ²½¤·¤¿½ð̾¤òɬÍפȤ¹¤ë¤³¤È¤¬È½ÌÀ¤·¤¿¡£°Å¹æ²½¤ª¤è¤ÓÉü¹æ¤Î´Ø¿ô¤ÏJavaScript¤Ç¼ÂÁõ¤µ¤ì¤Æ¤ª¤êï¤Ç¤âÍøÍѲÄǽ¤Ç¤¢¤Ã¤¿¤¬¡¢½ð̾¤ËɬÍפʾðÊó¤Î¼ý½¸¤Ë²ÝÂ꤬»Ä¤Ã¤¿¡£¤·¤«¤·¤Ê¤¬¤é¡¢¼Â¸³¤Î·ë²Ì¡¢MAC¥¢¥É¥ì¥¹¤À¤±Àµ³Î¤Ç¤¢¤ì¤Ð¾¤Î¾ðÊó¤Ï¥Ç¥¿¥é¥á¤Ç¤âÌäÂê¤Ê¤¤¤³¤È¤¬È½ÌÀ¤·¤¿¡£

°Ê¾å¤òÁí¹ç¤¹¤ë¤È¡¢Ç§¾Ú¤µ¤ì¤Æ¤¤¤Ê¤¤¥ê¥â¡¼¥È¤Î¹¶·â¼Ô¤Ï¡¢¸ÜµÒ¾ðÊó¤ò¸¡º÷¤·¡¢¸ÜµÒ¾ðÊ󤫤é¥Ç¥Ð¥¤¥¹¾ðÊó¡¢¥¢¥«¥¦¥ó¥È¾ðÊó¤ò¼ý½¸¤¹¤ë¤À¤±¤ÇɸŪ¤Î¥Ç¥Ð¥¤¥¹ÀßÄê¤òÊѹ¹¤Ç¤­¤ë¤³¤È¤Ë¤Ê¤ë¡£Sam Curry»á¤Ï¤³¤Î¼ê½ç¤ò»ÈÍѤ·¤Æ¼«¿È¤Î¥ë¡¼¥¿¤ÎSSID¤òÊѹ¹¤¹¤ë¤³¤È¤ËÀ®¸ù¤·¤Æ¤¤¤ë¡£

¡ûÂкö

Sam Curry»á¤Ï2024ǯ3·î4Æü¡¢Cox Communications¤ËÀȼåÀ­¤òÊó¹ð¤·¤¿¡£Cox Communications¤ÏÊó¹ð¤ò¼õ¤±¡¢3·î5Æü¤Þ¤Ç¤ËÀȼåÀ­¤ò½¤Àµ¤·¤¿¡£

¤Ê¤ª¡¢º£²ó³Îǧ¤µ¤ì¤¿ÀȼåÀ­¤Ï3ǯÁ°¤Î¿¯³²¤È¤Ï´Ø·¸¤Ê¤¤¤È¤¤¤¦¡£º£²óÄ´ººÂоݤȤʤä¿¥ê¥â¡¼¥È´ÉÍýµ¡Ç½¤Ï2023ǯ¤«¤éÄ󶡤µ¤ì¤Æ¤ª¤ê¡¢3ǯÁ°¤Ë¤Ï¸ºß¤·¤Æ¤¤¤Ê¤«¤Ã¤¿¡£¤½¤Î¤¿¤á¡¢Åö»þ¤Î¿¯³²·ÐÏ©¤ÏÉÔÌÀ¤Î¤Þ¤Þ¤È¤Ê¤Ã¤Æ¤¤¤ë¡£

¤³¤Î»ö°Æ¤Ï¥¤¥ó¥¿¡¼¥Í¥Ã¥È¥µ¡¼¥Ó¥¹¥×¥í¥Ð¥¤¥À¡¼(ISP: Internet Service Provider)¤Î¥·¥¹¥Æ¥à¤ËÀȼåÀ­¤¬Â¸ºß¤·¡¢¤¹¤Ù¤Æ¤Î¸ÜµÒ¤¬´í¸±¤Ë¤µ¤é¤µ¤ì¤¿¤³¤È¤ò°ÕÌ£¤·¤Æ¤¤¤ë¡£¥«¥¹¥¿¥Þ¡¼¥µ¥Ý¡¼¥È¤Î¤¿¤á¤ËƱÍͤΥ·¥¹¥Æ¥à¤òºÎÍѤ·¤Æ¤¤¤ë¥×¥í¥Ð¥¤¥À¡¼¤Ï¿¤¤¤È¤ß¤é¤ì¤ë¤¬¡¢¤³¤Î¤è¤¦¤ÊÌäÂê¤ò²óÈò¤¹¤ë¤¿¤á¤ËAPI¤Î¥»¥­¥å¥ê¥Æ¥£¥Æ¥¹¥È¤ò¼Â»Ü¤·¡¢¥»¥­¥å¥ê¥Æ¥£ÀȼåÀ­¤Î̵ͭ¤òÄê´üŪ¤Ë¸¡ºº¤¹¤ë¤³¤È¤¬Ë¾¤Þ¤ì¤Æ¤¤¤ë¡£