1.ã¯ããã«
ãªã¢ãŒã ã¢ã¯ã»ã¹ ã·ã¹ãã ãå°å ¥ããŠããªãäŒæ¥ã¯ãæ°ãæåã«ç·æ¥ã«ãªã¢ãŒã ã¢ã¯ã»ã¹ ã·ã¹ãã ãå°å ¥ããŸããã ãã¹ãŠã®ç®¡çè ããã®ãããªãç±ãã«åããŠããããã§ã¯ãªãããã®çµæããµãŒãã¹ã®èšå®ãééã£ãŠãããã以åã«çºèŠãããè匱æ§ãæã€å€ãããŒãžã§ã³ã®ãœãããŠã§ã¢ãã€ã³ã¹ããŒã«ãããããããªã©ãã»ãã¥ãªãã£äžã®æ¬ é¥ãçºçããŸããã äžéšã®äººã«ãšã£ãŠããããã®çç¥ã¯ãã§ã«ããŒã¡ã©ã³ç¶ã«ãªã£ãŠãããä»ã®äººã«ãšã£ãŠã¯ãã幞éã§ãããã誰ããééããªãçµè«ãå°ãåºãå¿ èŠããããŸãã ãªã¢ãŒãã¯ãŒã¯ãžã®å¿ èª åºŠã¯é£èºçã«é«ãŸããç¶ç¶çã«ãªã¢ãŒãã¯ãŒã¯ã蚱容å¯èœãªåœ¢åŒãšããŠåãå ¥ããäŒæ¥ãå¢ããŠããŸãã
ãããã£ãŠããªã¢ãŒã ã¢ã¯ã»ã¹ãæäŸããã«ã¯ãããŸããŸãª VPNãRDS ãš VNCãTeamViewer ãªã©ãå€ãã®ãªãã·ã§ã³ããããŸãã 管çè ã¯ãäŒæ¥ãããã¯ãŒã¯ãšãã®ãããã¯ãŒã¯å ã®ããã€ã¹ã®æ§ç¯ã®è©³çŽ°ã«åºã¥ããŠãå€ãã®éžæè¢ããéžæã§ããŸãã VPN ãœãªã¥ãŒã·ã§ã³ãäŸç¶ãšããŠæã人æ°ããããŸãããå€ãã®äžå°äŒæ¥ã¯ãããç°¡åãã€è¿ éã«å°å ¥ã§ãã RDS (ãªã¢ãŒã ãã¹ã¯ããã ãµãŒãã¹) ãéžæããŠããŸãã
ãã®èšäºã§ã¯ãRDS ã®ã»ãã¥ãªãã£ã«ã€ããŠè©³ãã説æããŸãã æ¢ç¥ã®è匱æ§ã®ç°¡åãªæŠèŠã説æããActive Directory ã«åºã¥ããŠãããã¯ãŒã¯ ã€ã³ãã©ã¹ãã©ã¯ãã£ã«æ»æãéå§ããããã®ããã€ãã®ã·ããªãªãæ€èšããŠã¿ãŸãããã ç§ãã¡ã®èšäºã誰ãã®ãã°ã«åãçµã¿ãã»ãã¥ãªãã£ãåäžãããã®ã«åœ¹ç«ã€ããšãé¡ã£ãŠããŸãã
2. æè¿ã® RDS/RDP ã®è匱æ§
ã©ã®ãœãããŠã§ã¢ã«ããæ»æè ã«ãã£ãŠæªçšãããå¯èœæ§ã®ãããšã©ãŒãè匱æ§ãå«ãŸããŠãããRDS ãäŸå€ã§ã¯ãããŸããã Microsoft ã¯æè¿ãæ°ããè匱æ§ãé »ç¹ã«å ±åããŠããããããããã®æŠèŠãç°¡åã«èª¬æããããšã«ããŸããã
ãã®è匱æ§ã«ããã䟵害ããããµãŒããŒã«æ¥ç¶ãããŠãŒã¶ãŒãå±éºã«ãããããŸãã æ»æè ã¯ãŠãŒã¶ãŒã®ããã€ã¹ãå¶åŸ¡ããããã·ã¹ãã å ã«è¶³å Žãç¯ããŠæ°žç¶çãªãªã¢ãŒã ã¢ã¯ã»ã¹ãååŸãããããå¯èœæ§ããããŸãã
ãã®äžé£ã®è匱æ§ã«ãããèªèšŒãããŠããªãæ»æè ããç¹å¥ã«äœæããããªã¯ãšã¹ãã䜿çšããŠãRDS ãå®è¡ããŠãããµãŒããŒäžã§ãªã¢ãŒãããä»»æã®ã³ãŒããå®è¡ããããšãå¯èœã«ãªããŸãã ãŸãããããã¯ãŒã¯äžã®é£æ¥ããããã€ã¹ã«ç¬ç«ããŠææãããã«ãŠã§ã¢ã§ããã¯ãŒã ãäœæããããã«äœ¿çšãããããšããããŸãã ãããã£ãŠããããã®è匱æ§ã¯äŒæ¥ã®ãããã¯ãŒã¯å šäœãå±éºã«ãããå¯èœæ§ããããã¿ã€ã ãªãŒãªã¢ããããŒãã®ã¿ãè匱æ§ãæãããšãã§ããŸãã
ãªã¢ãŒã ã¢ã¯ã»ã¹ ãœãããŠã§ã¢ã¯ç 究è ãšæ»æè ã®äž¡æ¹ãããŸããŸã泚ç®ãéããŠãããããè¿ããã¡ã«ããã«å€ãã®åæ§ã®è匱æ§ã«ã€ããŠèãããšã«ãªããããããŸããã
è¯ããã¥ãŒã¹ã¯ããã¹ãŠã®è匱æ§ãå
¬éãšã¯ã¹ããã€ããå©çšã§ããããã§ã¯ãªããšããããšã§ãã æªããã¥ãŒã¹ã¯ãå°éç¥èãæã€æ»æè
ã«ãšã£ãŠã説æã«åºã¥ããŠããŸãã¯ãããã®å·®åãªã©ã®æè¡ã䜿çšããŠè匱æ§ã®ãšã¯ã¹ããã€ããäœæããã®ã¯é£ãããªããšããããšã§ã (ç§ãã¡ã®ååã¯ãã®ä»¶ã«ã€ããŠæ¬¡ã®èšäºã§æžããŠããŸã)
3. æ»æ
èšäºã®ç¬¬ XNUMX éšã«é²ã¿ãActive Directory ã«åºã¥ãããããã¯ãŒã¯ ã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®æ»æãã©ã®ããã«å§ãŸããã説æããŸãã
説æãããŠããæ¹æ³ã¯ã次ã®æ»æè ã¢ãã«ã«é©çšã§ããŸã: ãŠãŒã¶ãŒ ã¢ã«ãŠã³ããæã¡ããªã¢ãŒã ãã¹ã¯ããã ã²ãŒããŠã§ã€ - ã¿ãŒããã« ãµãŒã㌠(å€ãã®å Žåãå€éšãããã¯ãŒã¯ããã¢ã¯ã»ã¹å¯èœ) ã«ã¢ã¯ã»ã¹ã§ããæ»æè ã ãããã®æ¹æ³ã䜿çšããããšã§ãæ»æè ã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ãžã®æ»æãç¶ç¶ãããããã¯ãŒã¯äžã§ã®ååšã匷åããããšãã§ããŸãã
ããããã®ç¹å®ã®ã±ãŒã¹ã«ããããããã¯ãŒã¯æ§æã¯ç°ãªãå ŽåããããŸããã説æãããŠããæè¡ã¯éåžžã«æ®éçã§ãã
å¶éãããç°å¢ãçµäºããæš©éãå¢ããäŸ
æ»æè ããªã¢ãŒã ãã¹ã¯ããã ã²ãŒããŠã§ã€ã«ã¢ã¯ã»ã¹ãããšãäœããã®å¶éãããç°å¢ã«ééããå¯èœæ§ããããŸãã ã¿ãŒããã« ãµãŒããŒã«æ¥ç¶ãããšãã¿ãŒããã« ãµãŒããŒäžã§ã¢ããªã±ãŒã·ã§ã³ãèµ·åããŸããããã¯ãå éšãªãœãŒã¹ããšã¯ã¹ãããŒã©ãŒããªãã£ã¹ ããã±ãŒãžããŸãã¯ãã®ä»ã®ãœãããŠã§ã¢ã«ãªã¢ãŒã ãã¹ã¯ããã ãããã³ã«ãä»ããŠæ¥ç¶ããããã®ãŠã£ã³ããŠã§ãã
æ»æè ã®ç®æšã¯ãã³ãã³ããå®è¡ããããã®ã¢ã¯ã»ã¹æš©ãååŸããããšãã€ãŸã cmd ãŸã㯠powershell ãèµ·åããããšã§ãã ããã«ã¯ãããã€ãã®å€å žç㪠Windows ãµã³ãããã¯ã¹ ãšã¹ã±ãŒãææ³ã圹ç«ã¡ãŸãã ããã«è©³ããèããŠã¿ãŸãããã
ãªãã·ã§ã³1ã æ»æè ã¯ããªã¢ãŒã ãã¹ã¯ããã ã²ãŒããŠã§ã€å ã®ãªã¢ãŒã ãã¹ã¯ãããæ¥ç¶ãŠã£ã³ããŠã«ã¢ã¯ã»ã¹ã§ããŸãã
ããªãã·ã§ã³ã®è¡šç€ºãã¡ãã¥ãŒãéããŸãã æ¥ç¶æ§æãã¡ã€ã«ãæäœããããã®ãªãã·ã§ã³ã衚瀺ãããŸãã
ãã®ãŠã£ã³ããŠããããéãããŸãã¯ãä¿åããã¿ã³ã®ãããããã¯ãªãã¯ããããšã§ããšã¯ã¹ãããŒã©ãŒã«ç°¡åã«ã¢ã¯ã»ã¹ã§ããŸãã
ãšã¯ã¹ãããŒã©ãŒãéããŸãã ãã®ãã¢ãã¬ã¹ ããŒãã«ãããèš±å¯ãããå®è¡å¯èœãã¡ã€ã«ãèµ·åãããããã¡ã€ã« ã·ã¹ãã ãäžèŠ§è¡šç€ºãããããããšãã§ããŸãã ããã¯ãã·ã¹ãã ãã©ã€ããé èœãããŠãããçŽæ¥ã¢ã¯ã»ã¹ã§ããªãå Žåã«ãæ»æè ã«ãšã£ãŠåœ¹ç«ã¡ãŸãã
â
ããšãã°ãMicrosoft Office ã¹ã€ãŒãã® Excel ããªã¢ãŒã ãœãããŠã§ã¢ãšããŠäœ¿çšããå Žåãåæ§ã®ã·ããªãªãåçŸã§ããŸãã
â
ããã«ããã®ãªãã£ã¹ ã¹ã€ãŒãã§äœ¿çšããããã¯ããå¿ããªãã§ãã ããã ç§ãã¡ã®ååã¯ããã¯ãã»ãã¥ãªãã£ã®åé¡ã次ã®ããã«èå¯ããŸããã
ãªãã·ã§ã³2ã æ»æè ã¯ãåã®ããŒãžã§ã³ãšåãå ¥åã䜿çšããŠãåãã¢ã«ãŠã³ãã§ãªã¢ãŒã ãã¹ã¯ããããžã®è€æ°ã®æ¥ç¶ãéå§ããŸãã åæ¥ç¶ãããšãæåã®æ¥ç¶ãéãããããšã©ãŒéç¥ãå«ããŠã£ã³ããŠãç»é¢ã«è¡šç€ºãããŸãã ãã®ãŠã£ã³ããŠã®ãã«ã ãã¿ã³ã¯ãµãŒããŒäžã® Internet Explorer ãåŒã³åºãããã®åŸæ»æè 㯠Explorer ã«ç§»åããããšãã§ããŸãã
â
ãªãã·ã§ã³3ã å®è¡å¯èœãã¡ã€ã«ã®èµ·åã«å¯Ÿããå¶éãæ§æãããŠããå Žåãæ»æè ã¯ã°ã«ãŒã ããªã·ãŒã«ãã£ãŠç®¡çè ã«ãã cmd.exe ã®å®è¡ãçŠæ¢ãããŠããç¶æ³ã«ééããå¯èœæ§ããããŸãã
ãããåé¿ããã«ã¯ãcmd.exe /K <command> ã®ãããªã³ã³ãã³ããå«ãããã ãã¡ã€ã«ããªã¢ãŒã ãã¹ã¯ãããã§å®è¡ããŸãã cmd èµ·åæã®ãšã©ãŒãšãbat ãã¡ã€ã«ã®å®è¡ã«æåããäŸã次ã®å³ã«ç€ºããŸãã
ãªãã·ã§ã³4ã å®è¡å¯èœãã¡ã€ã«ã®ååã«åºã¥ããŠãã©ãã¯ãªã¹ãã䜿çšããŠã¢ããªã±ãŒã·ã§ã³ã®èµ·åãçŠæ¢ããããšã¯äžèœè¬ã§ã¯ãããŸããããåé¿ããããšã¯å¯èœã§ãã
次ã®ã·ããªãªãèããŠã¿ãŸããããã³ãã³ã ã©ã€ã³ãžã®ã¢ã¯ã»ã¹ãç¡å¹ã«ããã°ã«ãŒã ããªã·ãŒã䜿çšã㊠Internet Explorer ãš PowerShell ã®èµ·åãçŠæ¢ããŸããã æ»æè ã¯å©ããæ±ããããšããŸãããå¿çã¯ãããŸããã Shift ããŒãæŒããªããåŒã³åºãããã¢ãŒãã« ãŠã£ã³ããŠã®ã³ã³ããã¹ã ã¡ãã¥ãŒãã PowerShell ãèµ·åããããšãããšã管çè ã«ãã£ãŠèµ·åãçŠæ¢ãããŠããããšã瀺ãã¡ãã»ãŒãžã衚瀺ãããŸãã ã¢ãã¬ã¹ ããŒãã PowerShell ãèµ·åããããšããŸããããã¯ãå¿çããããŸããã å¶éãåé¿ããã«ã¯ã©ãããã°ããã§ãã?
C:WindowsSystem32WindowsPowerShellv1.0 ãã©ã«ããŒãã powershell.exe ããŠãŒã¶ãŒ ãã©ã«ããŒã«ã³ããŒããååã powershell.exe 以å€ã®ååã«å€æŽããã ãã§ãèµ·åãªãã·ã§ã³ã衚瀺ãããŸãã
ããã©ã«ãã§ã¯ããªã¢ãŒã ãã¹ã¯ãããã«æ¥ç¶ãããšãã¯ã©ã€ã¢ã³ãã®ããŒã«ã« ãã£ã¹ã¯ãžã®ã¢ã¯ã»ã¹ãæäŸãããæ»æè ã¯ãããã powershell.exe ãã³ããŒããååãå€æŽããŠå®è¡ã§ããŸãã
â
å¶éãåé¿ããæ¹æ³ã¯ããã€ãæããã ãã§ãããä»ã«ãããŸããŸãªã·ããªãªãèããããŸããããããã«å ±éããŠããã®ã¯ãWindows ãšã¯ã¹ãããŒã©ãŒãžã®ã¢ã¯ã»ã¹ã§ãã æšæºã® Windows ãã¡ã€ã«æäœããŒã«ã䜿çšããã¢ããªã±ãŒã·ã§ã³ã¯æ°å€ããããéãããç°å¢ã«é 眮ãããå Žåã§ããåæ§ã®ææ³ã䜿çšã§ããŸãã
4. æšå¥šäºé ãšçµè«
ã芧ã®ãšãããéãããç°å¢ã§ãã£ãŠãæ»æãéçºããäœå°ã¯ãããŸãã ãã ããæ»æè ã®ç掻ãããã«å°é£ã«ããããšã¯ã§ããŸãã ç§ãã¡ãæ€èšãããªãã·ã§ã³ãšä»ã®å Žåã®äž¡æ¹ã«åœ¹ç«ã€äžè¬çãªæšå¥šäºé ãæäŸããŸãã
- ã°ã«ãŒã ããªã·ãŒã䜿çšããŠãããã°ã©ã ã®èµ·åããã©ãã¯/ãã¯ã€ã ãªã¹ãã«å¶éããŸãã
ãã ããã»ãšãã©ã®å Žåãã³ãŒããå®è¡ããããšã¯å¯èœã§ãã ãããžã§ã¯ãã«ã€ããŠããç解ããŠããããšããå§ãããŸããã«ãã¹ ãã·ã¹ãã äžã§ãã¡ã€ã«ãæäœããã³ãŒããå®è¡ããææžåãããŠããªãæ¹æ³ã«ã€ããŠã®ã¢ã€ãã¢ãåŸãã
äž¡æ¹ã®ã¿ã€ãã®å¶éãçµã¿åãããããšããå§ãããŸããããšãã°ãMicrosoft ã«ãã£ãŠçœ²åãããå®è¡å¯èœãã¡ã€ã«ã®èµ·åãèš±å¯ããcmd.exe ã®èµ·åãå¶éããããšãã§ããŸãã - Internet Explorer ã®èšå®ã¿ããç¡å¹ã«ããŸã (ã¬ãžã¹ããªã§ããŒã«ã«ã«å®è¡ã§ããŸã)ã
- regedit ã䜿çšã㊠Windows ã®çµã¿èŸŒã¿ãã«ããç¡å¹ã«ããŸãã
- ãã®ãããªå¶éããŠãŒã¶ãŒã«ãšã£ãŠéèŠã§ãªãå Žåã¯ããªã¢ãŒãæ¥ç¶çšã«ããŒã«ã« ãã£ã¹ã¯ãããŠã³ãããæ©èœãç¡å¹ã«ããŸãã
- ãªã¢ãŒã ãã·ã³ã®ããŒã«ã« ãã©ã€ããžã®ã¢ã¯ã»ã¹ãå¶éãããŠãŒã¶ãŒ ãã©ã«ããŒãžã®ã¢ã¯ã»ã¹ã®ã¿ãæ®ããŸãã
ãã®èšäºãå°ãªããšãèå³ãæã£ãŠããã ããã°å¹žãã§ãããæ倧éãäŒç€Ÿã®ãªã¢ãŒãã¯ãŒã¯ãããå®å šã«ããã®ã«åœ¹ç«ã¡ãŸãã
åºæïŒ habr.com