ÁëÊդξ®ÀÐ Âè175²ó Stream form Outer Network
Web¥Ö¥é¥¦¥¶¤Ç¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤«¤é¥À¥¦¥ó¥í¡¼¥É¤·¤¿¥Õ¥¡¥¤¥ë¤Ë¤Ï¡¢Zone.Identifier¤È¤¤¤¦¡¢ÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¡ÊAlternate Data Stream¡£ADS¡Ë¤¬ÉÕ¤¯¡£Windows XP SP2¤ÇÅëºÜ¤µ¤ì¤¿Windows SmartScreen¤¬¤³¤Î¾ðÊó¤ò»È¤Ã¤Æ¡¢¥Õ¥¡¥¤¥ë¤ò³«¤³¤¦¤È¤·¤¿¤È¤¤Ë·Ù¹ð¤Ê¤É¤òɽ¼¨¤·¤Æ¤¤¤¿¡£
¤·¤«¤·¡¢Windows 11¤Ç¤Ï¡¢¤³¤Îµ¡Ç½¤ÏMicrosoft Defender SmartScreen¤Ë°ú¤·Ñ¤¬¤ì¤Æ¤¤¤ë¡£¤³¤ì¤Ï¡¢Microsoft¤¬ºîÀ®¤·¤¿¥Ç¡¼¥¿¥Ù¡¼¥¹¤ò¸µ¤Ë¡¢¥µ¥¤¥È¤ä¥Õ¥¡¥¤¥ë̾¤Ê¤É¤«¤é´í¸±À¤òȽÃǤ¹¤ë¤â¤Î¡£¤Ê¤Î¤Ç¡¢Windows 11¤Ç¤Ï¡¢¤³¤ÎÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¼«ÂΤÏÍøÍѤµ¤ì¤Æ¤¤¤Ê¤¤¡£¤·¤«¤·¡¢¤³¤ì¤òÉÕ¤±¤ë¤Î¤Ï¡¢¥Ö¥é¥¦¥¶¡Ê¥À¥¦¥ó¥í¡¼¥É¤¹¤ë¥×¥í¥°¥é¥à¡Ë¤Ç¤¢¤ë¡£Ä´¤Ù¤¿¤È¤³¤íChrome¡¢Edge¡¢Firefox¤Ï¡¢Îã³°¤Ï¤¢¤ë¤â¤Î¤Î¥À¥¦¥ó¥í¡¼¥É¤·¤¿¥Õ¥¡¥¤¥ë¤Ë¡¢Zone.Identifier¤òÉÕ¤±¤ë¤è¤¦¤À¡Ê¸å½Ò¡Ë¡£
¥Õ¥¡¥¤¥ë¤ËÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤¬ÉÕ¤¤¤Æ¤¤¤ë¤«¤É¤¦¤«¤Ï¡¢cmd.exe¤ÎÆâÉô¥³¥Þ¥ó¥Édir¤Î/r¥ª¥×¥·¥ç¥ó¤ò»È¤Ã¤Æɽ¼¨¤Ç¤¤ë¡£PowerShell¤«¤é¤Ê¤é¡Ècmd.exe /c dir /r¡É¤È¤¹¤ë¡Ê¼Ì¿¿01¡Ë¡£
¼Ì¿¿01: cmd.exe¤ÎÆâÉô¥³¥Þ¥ó¥Édir /r¤ò»È¤¦¤È¥Õ¥¡¥¤¥ë¤ÈÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤òɽ¼¨¤Ç¤¤ë¡Ê¡¡Ë¡£PowerShell¥³¥Þ¥ó¥É¤Ê¤é¡¢¢¤Î¤è¤¦¤ËÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤Î¤ßɽ¼¨¤Ç¤¤ë¡£¥Ñ¥¤¥×¥é¥¤¥ó¤ÎÃæ±ûÉôʬ¤Ï¡¢ÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à°Ê³°¤òɽ¤¹¡£gi¤Ï¡¢Get-Item¥³¥Þ¥ó¥É¤Î¥¨¥¤¥ê¥¢¥¹¡£¤Þ¤¿¡¢¥«¥ì¥ó¥È¥Ç¥£¥ì¥¯¥È¥ê¤ÇZone.IdentifierÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤ò»ý¤¿¤Ê¤¤¥Õ¥¡¥¤¥ë¤Ï¡¢¥³¥Þ¥ó¥É¤Î¥¨¥é¡¼¤ò»È¤Ã¤Æ£¤Î¤è¤¦¤Ê¥³¥Þ¥ó¥É¤Çɽ¼¨²Äǽ¡£ÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤ÎÃæ¿È¤òɽ¼¨¤¹¤ë¤Ê¤é¡¢cat¡ÊGet-Content¥³¥Þ¥ó¥É¤Î¥¨¥¤¥ê¥¢¥¹¡Ë¤Î-Stream¥ª¥×¥·¥ç¥ó¤ò»È¤¦¡Ê¤¡Ë¡£ÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤òºï½ü¤¹¤ë¤Ê¤é¡¢Remove-Item¥³¥Þ¥ó¥É¤ò»È¤¦¡Ê¥¡Ë¡£digital.svg¤ÎÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤¬ºï½ü¤µ¤ì¤¿¤Î¤Ç¡¢¦¤Î¥³¥Þ¥ó¥É¤Ï¡¢»Ä¤Ã¤¿testfile.txt¤À¤±¤òɽ¼¨¤¹¤ë¡Ê¢¤ÈÈæ³Ó¡Ë
PowerShell¤Î¥³¥Þ¥ó¥É¤À¤±¤ò»È¤¦¤Ê¤é¡¢
Get-Item * -Stream * | ? stream -ne ':$DATA' | select PSchildname
¤È¤¹¤ë¤³¤È¤Ç¡¢¥«¥ì¥ó¥È¥Ç¥£¥ì¥¯¥È¥ê¤Ë¤¢¤ë¥Õ¥¡¥¤¥ë¤Î¤¦¤Á¡¢ÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤ò»ý¤Ä¥Õ¥¡¥¤¥ë¤ò½ÐÎϤǤ¤ë¡£¥Õ¥¡¥¤¥ë̾¤Î¸å¤í¤Î¥³¥í¥ó¡È:¡É°Ê¹ß¤¬ÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à̾¤Ç¤¢¤ë¡£Windows¤Ç¤Ï¥³¥í¥ó¤ò¥Õ¥¡¥¤¥ë̾¤Ë»È¤¨¤Ê¤¤¤¿¤á¡¢¤³¤Îɽµ¤¬²Äǽ¤Ë¤Ê¤ë¡£
¥Õ¥¡¥¤¥ë¤ËÂФ·¤ÆÆÃÄê¤Î̾Á°¤ÎÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤¬¡Ö¤Ê¤¤¡×¤³¤È¤òÄ´¤Ù¤ëľÀܤΥ³¥Þ¥ó¥É¤Ï¤Ê¤¤¤¬¡¢¥¨¥é¡¼¥á¥Ã¥»¡¼¥¸¤ò»È¤¦ÊýË¡¤¬¤¢¤ë¡£
Get-Item * -Stream "Zone.Identifier" | out-null
¤È¤¹¤ë¤³¤È¤Ç¡¢¥¨¥é¡¼¥á¥Ã¥»¡¼¥¸¤«¤é¥«¥ì¥ó¥È¥Ç¥£¥ì¥¯¥È¥ê¤Ë¤¢¤ëZone.Identifier¤ò´Þ¤Þ¤Ê¤¤¥Õ¥¡¥¤¥ë¤òÃΤ뤳¤È¤¬¤Ç¤¤ë¡£
ÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤ÎÆâÍƤϡ¢
Get-Content ¥Õ¥¡¥¤¥ë¥Ñ¥¹ -Stream ¥¹¥È¥ê¡¼¥à̾
¤È¤¹¤ë¤³¤È¤Çɽ¼¨¤Ç¤¤ë¡£
WSL¤Î¥í¡¼¥«¥ë¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¤ËÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤Î¤¢¤ë¥Õ¥¡¥¤¥ë¤ò¥³¥Ô¡¼¤¹¤ë¤È¡¢ÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤¬ÊÌ¥Õ¥¡¥¤¥ë¤È¤·¤Æ¥³¥Ô¡¼¤µ¤ì¤Æ¤·¤Þ¤¦¡£ÂåÂؤȤ¤¤¦Ì¾Á°¤Ç¤Ï¤¢¤ë¤¬¡¢¥Õ¥¡¥¤¥ëÆâÍƤˤÏÊѤï¤ê¤Ê¤¤¤¿¤á¡¢¾¡¼ê¤ËÍî¤È¤·¤Æ¤·¤Þ¤¦¤è¤¦¤Ê¤³¤È¤Ï¹Ô¤ï¤ì¤Ê¤¤¡£¤·¤«¤·¡¢Linux¤«¤é°·¤¦¤È¤¤Ë¤Ï¡¢¼ÙËâ¤Ë¤Ê¤ë¤³¤È¤¬¤¢¤ë¡£¤â¤Á¤í¤ó¡¢Linux¦¤Çºï½ü¤·¤Æ¤·¤Þ¤¦¤³¤È¤¬¤Ç¤¤ë¤¬¡¢Win32¦¥Õ¥¡¥¤¥ë¥·¥¹¥Æ¥à¡ÊNTFS¡Ë¤Ë¤¢¤ë¤Ê¤é¡¢PowerShell¤Ç¡¢
remove-item ¥Õ¥¡¥¤¥ë¥Ñ¥¹ -stream *
¤È¤¹¤ë¤³¤È¤Ç¡¢ÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤òÁ´¤Æºï½ü¤Ç¤¤ë¡£¥Õ¥¡¥¤¥ë̾¤Ë¤Ï¥ï¥¤¥ë¥É¥«¡¼¥É¤¬ÍøÍѤǤ¤ë¡£
¸½ºß¤Ç¤Ï¤Û¤È¤ó¤É»È¤ï¤ì¤Æ¤¤¤Ê¤¤Zone.Identifier¤À¤¬¡¢Web¥Ö¥é¥¦¥¶¤Ï¡¢¥À¥¦¥ó¥í¡¼¥É»þ¤ËÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤òÉղ乤ë¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤ë¡£Chrome¤Î¥½¡¼¥¹¥³¡¼¥É¤Ë¤¢¤ëcomponents/services/quarantine/quarantine_win.cc¤ä¡¢Firefox¤Î¥½¡¼¥¹¥³¡¼¥É¤Îtoolkit/components/downloads/DownloadIntegration.sys.mjs¤Ê¤É¤Ç¥À¥¦¥ó¥í¡¼¥É»þ¤ËÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥àZone.Identifier¤ò½ñ¤¹þ¤ó¤Ç¤¤¤ë¡£
¤³¤ì¤ò¸«¤ë¸Â¤ê¡¢¸½ºß¤Ç¤Ï¡¢Zone.Identifier¤Ë¤Ï¡¢1¤Ä¤Î¥»¥¯¥·¥ç¥ó̾¡È[ZoneTransfer]¡É¤È°Ê²¼¤Î3¤Ä¤ÎÍ×ÁǤ·¤«½ñ¤¹þ¤Þ¤ì¤Æ¤¤¤Ê¤¤¤è¤¦¤À¡£
ZoneId ¥À¥¦¥ó¥í¡¼¥É¤·¤¿¥¾¡¼¥ó¤ÎID
ReferrerUrl ¥À¥¦¥ó¥í¡¼¥É¤·¤¿¥µ¥¤¥È¤ÎURL¡Ê¥ê¥Õ¥¡¥é¡¼¡Ë
HostUrl ¥À¥¦¥ó¥í¡¼¥É¥ê¥ó¥¯
¤«¤Ä¤Æ¤Ï¡¢Â¾¤ÎÍ×ÁǤâ»È¤ï¤ì¤Æ¤¤¤¿¤è¤¦¤À¤¬¡¢Á°µ¤Î¥½¡¼¥¹¥³¡¼¥É¤ò¸«¤ë¸Â¤ê¡¢¤³¤Î3¤Ä¤ÎÍ×ÁǤ·¤«»È¤ï¤ì¤Æ¤¤¤Ê¤¤¡£ReferrerURL¤Ï¡¢HTTP¥Ø¥Ã¥À¤Î¥ê¥Õ¥¡¥é¡¼¤Ç¡¢°ÊÁ°¤Ï¥À¥¦¥ó¥í¡¼¥É¥ê¥ó¥¯¤Î¤¢¤Ã¤¿¥Ú¡¼¥¸¤ÎURL¤À¤Ã¤¿¤¬¡¢¥×¥é¥¤¥Ð¥·¡¼Âкö¤Ê¤É¤Î¤¿¤á¡¢¤¤¤Þ¤Ç¤Ï¡¢Ã±¤Ë¥µ¥¤¥È¤Î¥È¥Ã¥×¥Ú¡¼¥¸¤ÎURL¤Ë¤Ê¤Ã¤Æ¤¤¤ë¡£¤³¤ì¤ËÂФ·¤ÆHostURL¤Ë¤Ï¡¢¥À¥¦¥ó¥í¡¼¥É¥ê¥ó¥¯¤¬µ½Ò¤µ¤ì¤Æ¤¤¤ë¡£ÂåÂإǡ¼¥¿¥¹¥È¥ê¡¼¥à¤Ê¤Î¤Ç¡¢¥Õ¥¡¥¤¥ë¤ò¼Â¹Ô¤¹¤ë¤³¤È¤Ê¤¯¾ðÊó¤òÆÀ¤é¤ì¤ë¡£¤Ê¤ª¡¢ZoneId¤Ï¡¢¥¤¥ó¥¿¡¼¥Í¥Ã¥È¤òɽ¤¹3°Ê¾å¤Î¿ôÃͤȤʤäƤ¤¤ë¡£0¡Á2¤Ï¡¢¥í¡¼¥«¥ë¤ä¥¤¥ó¥È¥é¥Í¥Ã¥È¤òɽ¤·¡¢Windows SmartScreen¤ÎÂоݤǤϤʤ«¤Ã¤¿¤¿¤á¡¢Zone.Identifier¤ÏÉÕ¤«¤Ê¤¤¡£Windows SmartScreen¤¬»È¤ï¤ì¤Ê¤¯¤Ê¤Ã¤¿¤Î¤Ï¡¢IE¤¬»È¤Ã¤Æ¤¤¤¿¥¾¡¼¥ó¤Ë¤è¤ë¥»¥¥å¥ê¥Æ¥£´ÉÍý¤¬Çѻߤµ¤ì¤¿¤«¤é¤Ç¤â¤¢¤ë¡£
¥À¥¦¥ó¥í¡¼¥É¤·¤¿¥Õ¥¡¥¤¥ë¤Ï»Ä¤Ã¤Æ¤¤¤ë¤¬¡¢¤É¤³¤«¤é¥À¥¦¥ó¥í¡¼¥É¤·¤Æ¤¤¿¤Î¤«¡¢setup.exe¤¸¤ã²¿¤Î¥×¥í¥°¥é¥à¤À¤«¤ï¤«¤é¤Ê¤¤¡¢¤È¤¤¤Ã¤¿¤È¤¡¢¤³¤Î¾ðÊó¤ò¼ê³Ý¤«¤ê¤Ë¤¹¤ë¤³¤È¤¬¤Ç¤¤ë¡£
º£²ó¤Î¥¿¥¤¥È¥ë¥Í¥¿¤Ï¡¢1957ǯ¤Î±Ç²è¡ÖPlan 9 from Outer Space¡×¡£ÆâÍƤϤȤ⤫¤¯¡¢²¿¤È¤¤¤Ã¤Æ¤â¥¿¥¤¥È¥ë¤¬½¨°ï¡£¤½¤Î¤¿¤á¡¢¥Ù¥ë¸¦¤Î¥ª¥Ú¥ì¡¼¥Æ¥£¥ó¥°¥·¥¹¥Æ¥à¤Î̾Á°¤Ê¤É¡¢ÍÍ¡¹¤Ê¡Ö¥Í¥¿¡×¤Ë¤Ê¤Ã¤¿±Ç²è¡£