1.ã¯ããã«
ãªã¢ãŒãã¢ã¯ã»ã¹ã·ã¹ãã ãå°å ¥ããŠããªãã£ãäŒæ¥ã¯ãæ°ã¶æåããç·æ¥ã«å°å ¥ãé²ããŠããŸããããããããã¹ãŠã®ç®¡çè ããããããç±ãã«åããããŠããããã§ã¯ãªããçµæãšããŠã»ãã¥ãªãã£ã®ã£ãããçããŸããããµãŒãã¹ã®èšå®ãã¹ããè匱æ§ã倿ããŠããå€ãããŒãžã§ã³ã®ãœãããŠã§ã¢ã®ã€ã³ã¹ããŒã«ãªã©ã§ããããããã®ã£ãããããŒã¡ã©ã³ã®ããã«åã³çŸããäŒæ¥ãããã°ããã幞éã ã£ãäŒæ¥ããããŸããã誰ããçµè«ãå°ãåºãã¹ãã§ãããªã¢ãŒãã¯ãŒã¯ãžã®å¿ èª å¿ã¯ãããŸã§ä»¥äžã«é«ãŸãããŸããŸãå€ãã®äŒæ¥ããªã¢ãŒãã¯ãŒã¯ãæä¹ çãªåãæ¹ãšããŠåãå ¥ããŠããŸãã
ãªã¢ãŒãã¢ã¯ã»ã¹ãæäŸããããã®éžæè¢ã¯æ°å€ããããŸããæ§ã ãªVPNãRDSãVNCãTeamViewerãªã©ã§ãã管çè ã¯ãäŒæ¥ãããã¯ãŒã¯ã®æ§ç¯ç¶æ³ããããã¯ãŒã¯å ã®ããã€ã¹ã«å¿ããŠãå€ãã®éžæè¢ããéžã¶ããšãã§ããŸããVPNãœãªã¥ãŒã·ã§ã³ã¯äŸç¶ãšããŠæã人æ°ããããŸãããå€ãã®äžå°äŒæ¥ã¯ãå°å ¥ãç°¡åã§è¿ éãªRDSïŒãªã¢ãŒããã¹ã¯ããããµãŒãã¹ïŒãéžæããŠããŸãã
ãã®èšäºã§ã¯ãRDSã®ã»ãã¥ãªãã£ã«ã€ããŠãã詳现ã«è§£èª¬ããŸããæ¢ç¥ã®è匱æ§ã«ã€ããŠç°¡åã«æŠèª¬ããActive DirectoryããŒã¹ã®ãããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®æ»æã仿ããã·ããªãªãããã€ãèå¯ããŸãããã®èšäºãããšã©ãŒã®ä¿®æ£ãã»ãã¥ãªãã£åäžã«åãçµãçæ§ã®ã圹ã«ç«ãŠãã°å¹žãã§ãã
2. æè¿ã®RDS/RDPã®è匱æ§
ã©ã®ãœãããŠã§ã¢ã«ããæ»æè ã«æªçšããããã°ãè匱æ§ãååšããŸããRDSãäŸå€ã§ã¯ãããŸãããMicrosoftã¯æè¿ãæ°ããªè匱æ§ãé »ç¹ã«å ±åããŠãããããç°¡åã«æŠèŠã説æããããšã«ããŸããã
ãã®è匱æ§ã«ããã䟵害ããããµãŒããŒã«æ¥ç¶ãããŠãŒã¶ãŒã¯å±éºã«ãããããŸããæ»æè ã¯ãŠãŒã¶ãŒã®ããã€ã¹ãå¶åŸ¡ããããã·ã¹ãã ã«äŸµå ¥ããŠæ°žç¶çãªãªã¢ãŒãã¢ã¯ã»ã¹ã確ç«ãããããå¯èœæ§ããããŸãã
- / /
ãã®è匱æ§çŸ€ã¯ãäžæ£ãªæ»æè ãç¹å¥ãªåœ¢åŒã®ãªã¯ãšã¹ããçšããŠãRDS ãå°å ¥ãããµãŒããŒäžã§ä»»æã®ã³ãŒãããªã¢ãŒãããå®è¡ããããšãå¯èœã«ããŸãããŸããã¯ãŒã ïŒãããã¯ãŒã¯äžã®é£æ¥ããããã€ã¹ã«ææãããã«ãŠã§ã¢ïŒã®äœæã«ãå©çšãããå¯èœæ§ããããŸãããããã£ãŠããããã®è匱æ§ã¯äŒæ¥ãããã¯ãŒã¯å šäœãå±éºã«ãããå¯èœæ§ããããé©åãªã¿ã€ãã³ã°ã§ã¢ããããŒãã宿œããããšã§ã®ã¿ããããã®è åšãã身ãå®ãããšãã§ããŸãã
ãªã¢ãŒã ã¢ã¯ã»ã¹ ãœãããŠã§ã¢ã¯ç ç©¶è ãšæ»æè ã®äž¡æ¹ããæ³šç®ãéããŠãããããè¿ããã¡ã«ãã®ãããªè匱æ§ã«é¢ãããã¥ãŒã¹ãããã«å¢ããå¯èœæ§ããããŸãã
è¯ããã¥ãŒã¹ãšããŠã¯ããã¹ãŠã®è匱æ§ã«ãšã¯ã¹ããã€ããå ¬éãããŠããããã§ã¯ãªããæªããã¥ãŒã¹ãšããŠã¯ãå°éç¥èãæã€æ»æè ã¯ãè匱æ§ã®èª¬æã«åºã¥ããŠããããã¯ãããå·®åãªã©ã®æè¡ã䜿ã£ãŠãç°¡åã«ãšã¯ã¹ããã€ããäœæã§ãããšããããšã ïŒããã«ã€ããŠã¯ãååãèšäºãæžããŠããïŒã ãããã£ãŠããœãããŠã§ã¢ã宿çã«æŽæ°ããçºèŠãããè匱æ§ã«é¢ããæ°ããã¬ããŒããç£èŠããããšããå§ãããŸãã
3. æ»æ
èšäºã®åŸåã«é²ã¿ãActive Directory ã«åºã¥ããããã¯ãŒã¯ ã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®æ»æãã©ã®ããã«å§ãŸããã説æããŸãã
ããã§èª¬æããææ³ã¯ã以äžã®æ»æè ã¢ãã«ã«é©çšå¯èœã§ããæ»æè ã¯ãŠãŒã¶ãŒã¢ã«ãŠã³ããæã¡ããªã¢ãŒããã¹ã¯ãããã²ãŒããŠã§ã€ïŒã¿ãŒããã«ãµãŒããŒãäŸãã°å€éšãããã¯ãŒã¯ããã¢ã¯ã»ã¹å¯èœãªå Žåãå€ãïŒã«ã¢ã¯ã»ã¹ã§ããŸãããããã®ææ³ãçšããããšã§ãæ»æè ã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®æ»æãç¶ç¶ãããããã¯ãŒã¯å ã§ã®ãã¬ãŒã³ã¹ã匷åããããšãã§ããŸãã
ãããã¯ãŒã¯æ§æã¯ããããã®ã±ãŒã¹ã§ç°ãªãå ŽåããããŸããã説æãããŠããææ³ã¯éåžžã«æ®éçã§ãã
å¶éãããç°å¢ããæãåºããæš©éãææ ŒããäŸ
ãªã¢ãŒããã¹ã¯ãããã²ãŒããŠã§ã€ã«ã¢ã¯ã»ã¹ããå Žåãæ»æè ã¯éãããç°å¢ã«ééããå¯èœæ§ãé«ããªããŸããã¿ãŒããã«ãµãŒããŒã«æ¥ç¶ãããšããµãŒããŒäžã§ã¢ããªã±ãŒã·ã§ã³ãèµ·åããŸãããªã¢ãŒããã¹ã¯ããããããã³ã«ãä»ããŠå éšãªãœãŒã¹ã«æ¥ç¶ããããã®ãŠã£ã³ããŠããšã¯ã¹ãããŒã©ãŒããªãã£ã¹ã¹ã€ãŒãããã®ä»ã®ãœãããŠã§ã¢ãªã©ã§ãã
æ»æè ã®ç®çã¯ãã³ãã³ãå®è¡æš©éãã€ãŸãcmdãPowerShellãèµ·åããæš©éãååŸããããšã§ããããã«ã¯ãããã€ãã®å€å žçãªãµã³ãããã¯ã¹è±åºãã¯ããã¯ã圹ç«ã¡ãŸãã Windowsããããããã«æ€èšããŠã¿ãŸãããã
ãªãã·ã§ã³1æ»æè ã¯ããªã¢ãŒã ãã¹ã¯ããã ã²ãŒããŠã§ã€å ã®ãªã¢ãŒã ãã¹ã¯ãããæ¥ç¶ãŠã£ã³ããŠã«ã¢ã¯ã»ã¹ã§ããŸãã

ããªãã·ã§ã³ã衚瀺ãã¡ãã¥ãŒãéããŸããæ¥ç¶èšå®ãã¡ã€ã«ãæäœããããã®ãªãã·ã§ã³ã衚瀺ãããŸãã

ãã®ãŠã£ã³ããŠããããéãããŸãã¯ãä¿åããã¿ã³ã®ãããããã¯ãªãã¯ãããšããšã¯ã¹ãããŒã©ãŒã«ç°¡åã«ã¢ã¯ã»ã¹ã§ããŸãã

ãšã¯ã¹ãããŒã©ãŒãéããŸãããã¢ãã¬ã¹ããŒãã§ã¯ãèš±å¯ãããå®è¡ãã¡ã€ã«ãå®è¡ãããããã¡ã€ã«ã·ã¹ãã ã®äžèЧã衚瀺ãããã§ããŸããããã¯ãã·ã¹ãã ãã©ã€ããé ãããŠããŠçŽæ¥ã¢ã¯ã»ã¹ã§ããªãå Žåã«ãæ»æè ã«ãšã£ãŠäŸ¿å©ãªæ©èœã§ãã

â
ããšãã°ãMicrosoft Office ããã±ãŒãžã® Excel ããªã¢ãŒã ãœãããŠã§ã¢ãšããŠäœ¿çšããå Žåããåæ§ã®ã·ããªãªãåçŸã§ããŸãã
â
ããã«ããã®ãªãã£ã¹ã¹ã€ãŒãã§äœ¿çšããããã¯ãã«ã€ããŠãå¿ããªãã§ãã ãããç§ãã¡ã®ååã¯ããã®ãªãã£ã¹ã¹ã€ãŒãã«ããããã¯ãã®ã»ãã¥ãªãã£ã®åé¡ãæ€èšããŸããã .
ãªãã·ã§ã³2æ»æè ã¯ã以åã®äºçš®ãšåãå ¥åæ¹æ³ã§ãåãã¢ã«ãŠã³ãã§ãªã¢ãŒããã¹ã¯ããããžã®è€æ°ã®æ¥ç¶ãéå§ããŸãã忥ç¶ãããšãæåã®æ¥ç¶ã¯éãããããšã©ãŒéç¥ãŠã£ã³ããŠãç»é¢ã«è¡šç€ºãããŸãããã®ãŠã£ã³ããŠã®ãã«ããã¿ã³ãã¯ãªãã¯ãããšããµãŒããŒäžã®Internet ExplorerãåŒã³åºããããã®åŸãæ»æè ã¯Internet Explorerã«ã¢ã¯ã»ã¹ã§ããŸãã
â
ãªãã·ã§ã³3å®è¡å¯èœãã¡ã€ã«ã®å®è¡ã«å¶éãèšå®ãããŠããå Žåãæ»æè ã¯ã°ã«ãŒã ããªã·ãŒã«ãã£ãŠç®¡çè ã«ãã cmd.exe ã®å®è¡ãçŠæ¢ãããç¶æ³ã«ééããå¯èœæ§ããããŸãã
ãããåé¿ããã«ã¯ããªã¢ãŒããã¹ã¯ãããã§ãcmd.exe /K <ã³ãã³ã>ãã®ãããªå 容ã®batãã¡ã€ã«ãå®è¡ããŸããäžã®å³ã¯ãcmdå®è¡æã®ãšã©ãŒãšbatãã¡ã€ã«ã®å®è¡æåäŸã§ãã

ãªãã·ã§ã³4å®è¡å¯èœãã¡ã€ã«åã«ãããã©ãã¯ãªã¹ãã䜿çšããŠã¢ããªã±ãŒã·ã§ã³ã®èµ·åããããã¯ããããšã¯äžèœè¬ã§ã¯ãªããåé¿ãããå¯èœæ§ããããŸãã
次ã®ãããªã·ããªãªãèããŠã¿ãŸããããã³ãã³ãã©ã€ã³ãžã®ã¢ã¯ã»ã¹ããããã¯ããã°ã«ãŒãããªã·ãŒã䜿çšããŠInternet ExplorerãšPowerShellã®å®è¡ããããã¯ããŠããŸããæ»æè ã¯ãã«ããåŒã³åºãããšããŸãããå¿çããããŸãããShiftããŒãæŒããªããåŒã³åºãããã¢ãŒãã«ãŠã£ã³ããŠã®ã³ã³ããã¹ãã¡ãã¥ãŒããPowerShellãå®è¡ããããšããŸããã管çè ãèµ·åããããã¯ããŠãããšããã¡ãã»ãŒãžã衚瀺ãããŸããã¢ãã¬ã¹ããŒããPowerShellãå®è¡ããããšããŸããããã¯ãå¿çããããŸãããã©ãããã°ãã®å¶éãåé¿ã§ããã§ããããïŒ
Cãã©ã€ãã®ãã©ã«ãããpowershell.exeãã³ããŒããã ãã§ããWindowsSystem32WindowsãŠãŒã¶ãŒãã©ã«ãã«ãã PowerShellv1.0 ã®ååã powershell.exe 以å€ã®ååã«å€æŽãããšãå®è¡ãããªãã·ã§ã³ã衚瀺ãããŸãã
ããã©ã«ãã§ã¯ããªã¢ãŒã ãã¹ã¯ãããã«æ¥ç¶ãããšãã¯ã©ã€ã¢ã³ãã®ããŒã«ã« ãã£ã¹ã¯ãžã®ã¢ã¯ã»ã¹ãæäŸãããæ»æè ã¯ãããã powershell.exe ãã³ããŒããååã倿ŽããŠå®è¡ããããšãã§ããŸãã
â
ããã§ã¯å¶éãåé¿ããæ¹æ³ãããã€ãã玹ä»ããŸããããä»ã«ãå€ãã®ã·ããªãªãèããããŸããããããããããã¹ãŠã«å ±éããŠããã®ã¯ããšã¯ã¹ãããŒã©ãŒã«ã¢ã¯ã»ã¹ããããšã§ãã WindowsæšæºããŒã«ã䜿çšããã¢ããªã±ãŒã·ã§ã³ Windows ãã¡ã€ã«ãæ±ãæ¹æ³ã¯æ°å€ããããéãããç°å¢ã«çœ®ãå Žåã§ããåæ§ã®ææ³ãçšããããšãã§ããŸãã
4. å§åãšçµè«
ã芧ã®ãšãããéãããç°å¢ã§ãã£ãŠãæ»æãå±éããäœå°ã¯ãããŸããããããæ»æè ã®è¡åãå°é£ã«ããããšã¯å¯èœã§ããããã§ã¯ãããã§æ€èšããéžæè¢ã ãã§ãªããä»ã®ã±ãŒã¹ã«ã圹ç«ã€äžè¬çãªæšå¥šäºé ãããã€ãã玹ä»ããŸãã
- ã°ã«ãŒã ããªã·ãŒã䜿çšããŠããã©ãã¯/ãã¯ã€ã ãªã¹ãã§ããã°ã©ã ã®èµ·åãå¶éããŸãã
ã»ãšãã©ã®å Žåãã³ãŒããå®è¡ããããšã¯å¯èœã§ãããããžã§ã¯ãã«æ £ããŠããããšããå§ãããŸãã ãã·ã¹ãã äžã§ãã¡ã€ã«ãæäœãããã³ãŒããå®è¡ãããããããã®ææžåãããŠããªãæ¹æ³ã«ã€ããŠã®æŽå¯ãåŸãŸãã
äž¡æ¹ã®çš®é¡ã®å¶éãçµã¿åãããããšããå§ãããŸããããšãã°ãMicrosoft ã«ãã£ãŠçœ²åãããå®è¡å¯èœãã¡ã€ã«ã®èµ·åãèš±å¯ããcmd.exe ã®èµ·åãå¶éããããšãã§ããŸãã - Internet Explorer ã®èšå®ã¿ããç¡å¹ã«ããŸã (ã¬ãžã¹ããªã§ããŒã«ã«ã«å®è¡ã§ããŸã)ã
- ã¬ãžã¹ããªãšãã£ã¿ã䜿çšããŠçµã¿èŸŒã¿ãã«ããç¡å¹ã«ãã Windows.
- ãã®å¶éããŠãŒã¶ãŒã«ãšã£ãŠéèŠã§ãªãå Žåã¯ããªã¢ãŒãæ¥ç¶çšã«ããŒã«ã« ãã©ã€ããããŠã³ãããæ©èœãç¡å¹ã«ããŸãã
- ãªã¢ãŒã ãã·ã³ã®ããŒã«ã« ãã£ã¹ã¯ãžã®ã¢ã¯ã»ã¹ãå¶éãããŠãŒã¶ãŒ ãã©ã«ããŒãžã®ã¢ã¯ã»ã¹ã®ã¿ãæ®ããŸãã
ãã®èšäºãçæ§ã«ãšã£ãŠå°ãªããšãè峿·±ããã®ãšãªãããããŠçæ§ã®äŒç€Ÿã®ãªã¢ãŒãã¯ãŒã¯ãããå®å šã«ããäžå©ãšãªãã°å¹žãã§ãã
åºæïŒ habr.com
