AI¥Ç¥Ð¥¤¥¹¡ÖRabbit R1¡×¤Ë¥æ¡¼¥¶¡¼¥Ç¡¼¥¿¤¬¥À¥Àϳ¤ì¤Ë¤Ê¤ë¥»¥¥å¥ê¥Æ¥£ÌäÂ꤬¤¢¤ë¤³¤È¤¬È¯³Ð
AI¥Ç¥Ð¥¤¥¹¡ÖRabbit R1¡×¤Î¥³¡¼¥É¤Ë¡¢½ÅÍפÊAPI¥¡¼¤¬Ä¾Àܽñ¤¹þ¤Þ¤ì¤Æ¤¤¤¿¤Î¤òȯ¸«¤·¤¿¤È¡¢R1¤Î¥ê¥Ð¡¼¥¹¥¨¥ó¥¸¥Ë¥¢¥ê¥ó¥°¤ò¹Ô¤Ã¤Æ¤¤¤ë¸¦µæ¼Ô¥°¥ë¡¼¥×¤¬È¯É½¤·¤Þ¤·¤¿¡£¤³¤ÎAPI¥¡¼¤ò»ÈÍѤ¹¤ì¤Ð¡¢¥æ¡¼¥¶¡¼¤Î¸Ä¿Í¾ðÊó¤ò´Þ¤àÆâÉôŪ¤Ê¥Ç¡¼¥¿¤Ë¼«Í³¤Ë¥¢¥¯¥»¥¹¤Ç¤¤Æ¤·¤Þ¤¦¤È¡¢¸¦µæ¥°¥ë¡¼¥×¤Ï½Ò¤Ù¤Æ¤¤¤Þ¤¹¡£
Updates on investigation on r1 SaaS API keys
rabbit failed to properly reset all keys: emails can be sent from rabbit.tech domains
https://rabbitu.de/articles/security-disclosure-2
Researchers Prove Rabbit AI Breach By Sending Email to Us as Admin
https://www.404media.co/researchers-prove-rabbit-ai-breach-by-sending-email-to-us-as-admin/
Rabbit R1¤Ï¡¢µ»½Ñ·Ï¥¹¥¿¡¼¥È¥¢¥Ã¥×¤ÎRabbit¤¬³«È¯¤·¤¿AI¥Ç¥Ð¥¤¥¹¤Ç¤¹¡£ChatGPT¤òÅëºÜ¤·¤¿¥Ñ¡¼¥½¥Ê¥ë¥¢¥·¥¹¥¿¥ó¥È¥Ç¥Ð¥¤¥¹¤È¤·¤ÆÌĤêʪÆþ¤ê¤Ç¥ê¥ê¡¼¥¹¤µ¤ì¤¿R1¤Ç¤¹¤¬¡¢¤½¤Î¼ÂÂ֤ϴûÀ®API¤ò»ÈÍѤ·¤¿Android¥¢¥×¥ê¤òÆ°ºî¤µ¤»¤Æ¤¤¤ë¤Ë²á¤®¤º¡¢µ¡Ç½¤ä¥Ñ¥Õ¥©¡¼¥Þ¥ó¥¹¤â´üÂÔ³°¤ì¤À¤Ã¤¿¤È¤·¤Æ¡¢¥æ¡¼¥¶¡¼¤ä¥ì¥Ó¥å¡¼¥¢¡¼¤«¤éÉÔɾ¤òÇã¤Ã¤Æ¤¤¤Þ¤¹¡£
AI¥Ç¥Ð¥¤¥¹¡Örabbit r1¡×¤òÇã¤Ã¤¿¤é¡Ö¤½¤Îµ¡Ç½¤Ï½àÈ÷Ãæ¡×¤òϢȯ¤¹¤ëº¾µ½ÅªÀ½ÉʤÀ¤Ã¤È¤¤¤¦Êó¹ð - GIGAZINE
¤µ¤é¤Ë¡¢R1¤Î¥¸¥§¥¤¥ë¥Ö¥ì¥¤¥¯¤È¥ê¥Ð¡¼¥¹¥¨¥ó¥¸¥Ë¥¢¥ê¥ó¥°¤ò¹Ô¤Ã¤Æ¤¤¤ë¥³¥ß¥å¥Ë¥Æ¥£¡Örabbitude¡×¤Ï¡¢R1¤Î¥³¡¼¥É¥Ù¡¼¥¹¤Ë½ÅÍפÊAPI¥¡¼¤¬¥Ï¡¼¥É¥³¡¼¥Ç¥£¥ó¥°¡¢¤Ä¤Þ¤êľÀܽñ¤¹þ¤Þ¤ì¤Æ¤¤¤¿¤Î¤ò¸«¤Ä¤±¤¿¤Èȯɽ¤·¤Þ¤·¤¿¡£
API¥¡¼¤Ï¡¢¥µ¡¼¥Ó¥¹¤Î¥×¥í¥Ð¥¤¥À¡¼¤¬API¤ò³èÍѤ·¤Æ¤¤¤ëÀ½Éʤò¼±Ê̤·¡¢¤½¤Î»ÈÍѾõ¶·¤òÄÉÀפ¹¤ë¤Î¤Ë»ÈÍѤµ¤ì¤ë¤¿¤á¡¢Èó¾ï¤Ëµ¡Ì©À¤Î¹â¤¤¤â¤Î¤Ç¤¹¡£½¾¤Ã¤Æ¡¢¥½¡¼¥¹¥³¡¼¥É¤ËAPI¥¡¼¤¬¤½¤Î¤Þ¤Þ¥Ï¡¼¥É¥³¡¼¥Ç¥£¥ó¥°¤µ¤ì¤ë¤³¤È¤Ï´ðËÜŪ¤Ë¤¢¤ê¤Þ¤»¤ó¡£
rabbitude¤¬¸«¤Ä¤±¤¿API¥¡¼¤ÏElevenLabs(¥Æ¥¥¹¥ÈÆɤ߾夲¥µ¡¼¥Ó¥¹ÍÑ)¡¢Azure(¸Å¤¤²»À¼¥Æ¥¥¹¥ÈÊÑ´¹¥·¥¹¥Æ¥àÍÑ)¡¢Yelp(¥ì¥Ó¥å¡¼¸¡º÷ÍÑ)¡¢Google¥Þ¥Ã¥×(°ÌÃ֤θ¡º÷ÍÑ)¤Î¤â¤Î¤Ç¤¹¡£
Æäˡ¢ElevenLabs¤ÎAPI¥¡¼¤ò»È¤¦¤È´ÉÍý¼Ô¸¢¸Â¤òÆÀ¤é¤ì¤ë¤¿¤á¡¢rabbitude¤Ï¤³¤ì¤é¤ÎAPI¥¡¼¤ò»È¤¦¤³¤È¤Ç¡Ö¸Ä¿Í¾ðÊó¤ò´Þ¤à¡¢R1¤¬¤³¤ì¤Þ¤Ç¤Ë¥æ¡¼¥¶¡¼¤Ë¹Ô¤Ã¤¿¤¹¤Ù¤Æ¤ÎÊÖÅú¤Î±ÜÍ÷¡×¡Ö¤¹¤Ù¤Æ¤ÎR1¤òʸÄò½¤µ¤»¤ë¤³¤È¡×¡Ö¤¹¤Ù¤Æ¤ÎR1¤Î±þÅú¤òÊѹ¹¤¹¤ë¤³¤È¡×¡Ö¤¹¤Ù¤Æ¤ÎR1¤Î²»À¼¤òÊѹ¹¤¹¤ë¤³¤È¡×¤¬²Äǽ¤À¤È¤·¤Æ¤¤¤Þ¤¹¡£
rabbitude¤Î¥á¥ó¥Ð¡¼¤Î¤Ò¤È¤ê¤Ï¡¢³¤³°¥á¥Ç¥£¥¢¤Î404 Media¤Ë¡Öµ¡Ì©´ÉÍý¤Î°ìÈÌŪ¤Ê¼êË¡¤Ï¡¢¥³¡¼¥É¼«ÂΤËÈëÌ©¤Î¥¡¼¤äÃͤò¥Ï¡¼¥É¥³¡¼¥Ç¥£¥ó¥°¤·¤¿¤ê¤»¤º¡¢¼Â¹Ô»þ¤Ë²¿¤é¤«¤Î·Á¼°¤Ç¥¡¼¤òÁÞÆþ¤¹¤ë¤³¤È¤Ç¤¹¡£¤·¤«¤·¡¢¶½Ì£¿¼¤¤¤³¤È¤Ë¡¢Rabbit¤Ï¤¹¤Ù¤Æ¤Î¥³¡¼¥É¤òKubernetes¤È¤¤¤¦¥·¥¹¥Æ¥à¤Ç´ÉÍý¤µ¤ì¤¿¥³¥ó¥Æ¥Ê¤Ë¥Ç¥×¥í¥¤¤·¤Æ¤¤¤Þ¤¹¡£Kubernetes¤ÏÁ°½Ò¤Îµ¡Ì©´ÉÍý¤ÎÊýË¡¤ò¥Í¥¤¥Æ¥£¥Ö¤Ç¥µ¥Ý¡¼¥È¤·¤Æ¤¤¤ë¤Î¤Ç¡¢ÉáÄ̤Ϥ½¤¦¤¹¤ë¤Î¤¬Åö¤¿¤êÁ°¤Î¤Ï¤º¤Ç¤¹¡×¤ÈÏä·¤Þ¤·¤¿¡£
¼Â¤Ï¡¢rabbitude¤Ï2024ǯ5·î¤Ë¤³¤ÎÌäÂê¤òȯ¸«¤·¡¢¥Ö¥í¥°¤ÇÊó¹ð¤·¤Æ¤¤¤Þ¤·¤¿¡£¤·¤«¤·¡¢Rabbit¤ÏAPI¥¡¼¤¬Ï³¤¨¤¤¤·¤¿»ö¼Â¤òǧ¼±¤·¤Ä¤Ä¡¢¤³¤ì¤Þ¤Ç¶ñÂÎŪ¤Ê¹ÔÆ°¤ò¼è¤Ã¤Æ¤¤¤Ê¤«¤Ã¤¿¤È¤Î¤³¤È¡£
¤½¤·¤Æ¡¢1¥«·î°Ê¾å¤¬·Ð²á¤·¤¿6·î26Æü¤Ë¤Ê¤Ã¤ÆRabbit¤Ï¡ÖºòÆü¡¢Åö¼Ò¤ÏÂè»°¼Ô¤¬API¥¡¼¤Ë¥¢¥¯¥»¥¹¤·¤¿²ÄǽÀ¤¬¤¢¤ë¤È¤¤¤¦ÄÌÃΤò¼õ¤±¤Æ¡¢API¥¡¼¤ò¥í¡¼¥Æ¡¼¥·¥ç¥ó¤·¡¢¤³¤ì¤Ë¤è¤Ã¤ÆR1¤Çû»þ´Ö¤Î¥À¥¦¥ó¥¿¥¤¥à¤¬È¯À¸¤·¤Þ¤·¤¿¡£Åö¼Ò¤Î¥Á¡¼¥à¤ÏÄ´ºº¤ò³¤±¤Æ¤¤¤Þ¤¹¤¬¡¢¸½»þÅÀ¤Ç¤ÏÅö¼Ò¤Î½ÅÍפʥ·¥¹¥Æ¥à¤ä¸ÜµÒ¥Ç¡¼¥¿¤Î°ÂÁ´À¤¬¿¯³²¤µ¤ì¤¿¤³¤È¤Ï³Îǧ¤µ¤ì¤Æ¤¤¤Þ¤»¤ó¡×¤È¤ÎÀ¼ÌÀ¤òȯɽ¤·¤Þ¤·¤¿¡£
rabbitude¤Ë¤è¤ë¤È¡¢Rabbit¤¬È¯É½¤·¤¿¤È¤ª¤ê¡¢¼ÂºÝ¤ËÁ°½Ò¤Î4¤Ä¤ÎAPI¥¡¼¤¬¥í¡¼¥Æ¡¼¥·¥ç¥ó¤µ¤ì¤Æ¤¤¤¿¤È¤Î¤³¤È¡£¤·¤«¤·¡¢rabbitude¤Ï¥Ï¡¼¥É¥³¡¼¥Ç¥£¥ó¥°¤µ¤ì¤¿5¤ÄÌܤÎAPI¥¡¼¤È¤·¤Æ¡¢ÅŻҥ᡼¥ë¥µ¡¼¥Ó¥¹¡ÖSendGrid¡×¤ÎAPI¥¡¼¤òȯ¸«¤·¤Æ¤ª¤ê¡¢¤³¤ì¤ò»È¤Ã¤ÆRabbit¤Î¼ÒÆâ¥á¡¼¥ë¥¢¥É¥ì¥¹¤«¤éÁ÷¿®¤µ¤ì¤¿¥á¡¼¥ë¤ò±ÜÍ÷¤·¤¿¤ê¡¢¼ÒÆâ¥á¡¼¥ë¥¢¥É¥ì¥¹¤«¤é¥á¡¼¥ë¤òÁ÷¤Ã¤¿¤ê¤¹¤ë¤³¤È¤¬¤Ç¤¤Þ¤·¤¿¡£
404 Media¤Ï¡¢¼ÂºÝ¤Ërabbitude¤¬Rabbit¤Î¥á¡¼¥ë¥¢¥É¥ì¥¹¤«¤éÁ÷¤Ã¤¿¡Ö¤¹¤ß¤Þ¤»¤ó¡¢¥Ï¥Ã¥¥ó¥°¤µ¤ì¤Þ¤·¤¿¤¬¡¢»ä¤¿¤Á¤Ï²²É¼Ԥν¸¤Þ¤ê¤Ê¤Î¤Ç¡¢¤½¤ì¤òÈÝÄꤷ³¤±¤Æ¤¤¤Þ¤¹¡£ÁíÀª1̾¤ÎRabbit¥»¥¥å¥ê¥Æ¥£¡¼¥Á¡¼¥à¤è¤ê¡×¤È¤¤¤¦¥á¡¼¥ë¤ò¼õ¤±¼è¤Ã¤¿¤³¤È¤ò³Îǧ¤·¤Æ¤¤¤Þ¤¹¡£
rabbitude¤ÏRabbit¤ÎÀ¼ÌÀ¤Ë¤Ä¤¤¤Æ¡ÖΨľ¤Ë¸À¤¦¤È¡¢À¼ÌÀ¤Ï¤¦¤½¤À¤È»×¤¤¤Þ¤¹¡£³Î¤«¤Ë¡¢»ä¤¿¤Á¤Ï¥æ¡¼¥¶¡¼¥Ç¡¼¥¿¤òÅð¤ó¤Ç¤¤¤Þ¤»¤ó¤Î¤Ç¡¢¡Ø¸ÜµÒ¥Ç¡¼¥¿¤Ïϳ¤¨¤¤¤·¤Æ¤¤¤Ê¤¤¡Ù¤È¤¤¤¦À¼ÌÀ¤Ï¡¢¸·Ì©¤ËÄêµÁ¤¹¤ì¤Ð¿¿¼Â¤Ç¤¹¤¬¡¢¤â¤·»ä¤¿¤Á¤¬¤½¤Îµ¤¤Ë¤Ê¤ì¤ÐËÜÍ襢¥¯¥»¥¹¤µ¤ì¤ë¤Ù¤¤Ç¤Ê¤¤¤â¤Î¤Ë¥¢¥¯¥»¥¹¤Ç¤¤¿¤Ç¤·¤ç¤¦¡×¤È½Ò¤Ù¤Þ¤·¤¿¡£