ãã°å ±å¥šéããã°ã©ã ã¯ãçµç¹ãå«ççãªããã«ãŒãã»ãã¥ãªãã£ç ç©¶è ããã®ä»ã®ãµã€ããŒã»ãã¥ãªãã£å°éå®¶ã«ããœãããŠã§ã¢ãã·ã¹ãã ããŸãã¯ã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£è匱æ§ãç¹å®ããŠå ±åãããã奚å±ãããåºãæ¡çšãããŠããã»ãã¥ãªã㣠ã€ãã·ã¢ããã§ããçµç¹ã¯ããã®åªåã®èŠè¿ãã«ãééçãªå ±é ¬ããèšå¿µåãäžéã§ã®è©äŸ¡ããã£ãªã¢ã®æ©äŒãªã©ã®ãã®ä»ã®ã€ã³ã»ã³ãã£ããæäŸããŸãã
ã»ãã¥ãªãã£ãšã³ã³ãã©ã€ã¢ã³ã¹ã®æèã§ã¯ããã°å ±å¥šéããã°ã©ã ã¯è¿œå ã®é²åŸ¡å±€ãšããŠæ©èœãããã¡ã€ã¢ãŠã©ãŒã«ãäŸµå ¥æ€ç¥ã·ã¹ãã ãäŸµå ¥ãã¹ããªã©ã®åŸæ¥ã®ã»ãã¥ãªãã£å¯Ÿçãè£å®ããŸããã°ããŒãã«ãªãµã€ããŒã»ãã¥ãªã㣠ã³ãã¥ããã£ã®éåçãªã€ã³ããªãžã§ã³ã¹ãšã¹ãã«ã掻çšããããšã§ãçµç¹ã¯ã瀟å ã®ã»ãã¥ãªã㣠ããŒã ãèªååããŒã«ã«ãã£ãŠèŠèœãšãããŠããå¯èœæ§ã®ããæœåšçãªã»ãã¥ãªãã£ã®åŒ±ç¹ã«ã€ããŠè²ŽéãªæŽå¯ãåŸãããšãã§ããŸãã
倧æãã°å ±å¥šéãã©ãããã©ãŒã ã§ãã HackerOne ã®ã¬ããŒãã«ãããšããã©ãããã©ãŒã ã®éå§ä»¥æ¥ãå«ççãªããã«ãŒã«æ¯æãããå ±å¥šéã®ç·é¡ã¯ 1 åãã«ãè¶ ããŠããŸããããã¯ãã»ãã¥ãªã㣠ãªã¹ã¯ã®ç¹å®ãšè»œæžã«ããããã°å ±å¥šéããã°ã©ã ã®éèŠæ§ãšæå¹æ§ãé«ãŸã£ãŠããããšã瀺ããŠããŸãã
ãã°å ±å¥šéããã°ã©ã ã®å®è£ ãæåãããã«ã¯ãéåžžãæ¬¡ã®éèŠãªãã§ãŒãºãå«ãŸããŸãã
- ç¯å²ã®å®çŸ©: çµç¹ã¯ãå€éšã®ã»ãã¥ãªãã£ç ç©¶è ã«ãããã¹ããåãå ¥ããã·ã¹ãã ãã¢ããªã±ãŒã·ã§ã³ãã¿ãŒã²ããã®ç¯å²ãæç¢ºã«å®çŸ©ããå¿ èŠããããŸããããã¯ãæç¢ºãªæåŸ ãèšå®ããæ³çããã³éçšäžã®ãªã¹ã¯ãæå°éã«æããã®ã«åœ¹ç«ã¡ãŸãã
- å ±åã¬ã€ãã©ã€ã³ã®ç¢ºç«: ç ç©¶è ãè匱æ§å ±åãæåºããããã®éææ§ã®ããæšæºåãããããã»ã¹ (å¿ èŠãªæ å ±ãå ±å圢åŒãé£çµ¡ãã£ãã«ãªã©) ãäœæããŸãã
- å ±å¥šéé¡ã®èšå®: å ±åãããè匱æ§ã®é倧床ãšåœ±é¿ã«åºã¥ããŠå ±å¥šéã®æ§é ãæ±ºå®ããŸããå€ãã®å ŽåãCommon Vulnerability Scoring System (CVSS) ãªã©ã®æ¥çæšæºã®ãã¬ãŒã ã¯ãŒã¯ã䜿çšãããŸãã
- ã¬ããŒãã®ããªã¢ãŒãžãšæ€èšŒ: å ±åãããã»ãã¥ãªãã£åé¡ãåçŸããŠæ€èšŒããããšã«ãã£ãŠè匱æ§ã¬ããŒãã®æå¹æ§ãè©äŸ¡ããããããããããæœåšçãªãªã¹ã¯ã«åºã¥ããŠä¿®æ£ã®åªå é äœãä»ããŸãã
- è匱æ§ã®ä¿®åŸ©: 瀟å ã®éçºããŒã ãšç·å¯ã«é£æºããŠãç¹å®ãããã»ãã¥ãªãã£åé¡ã«å¯ŸåŠãã圱é¿ãåããã·ã¹ãã ã«ããããã¢ããããŒãããªãªãŒã¹ããŸãã
- å ±å¥šéã®æ¯æã: ééçãªæ¯æãããã®ä»ã®åœ¢åŒã®ã€ã³ã»ã³ãã£ããéããŠãã»ãã¥ãªãã£åé¡ã®ä¿®åŸ©ã«æåããå ±åãè¡ã£ãç ç©¶è ã®åªåã衚地ããå ±ããã
- åŠç¿ãšå埩: åŠãã æèšãç ç©¶è ããã®ãã£ãŒãããã¯ãé²åãããµã€ããŒã»ãã¥ãªãã£ç¶æ³ã«åºã¥ããŠãã°å ±å¥šéããã°ã©ã ãæ¹è¯ããŸãã
ãã°å ±å¥šéããã°ã©ã ã¯ãµã€ããŒã»ãã¥ãªãã£åéã§ã¯å®çªãšãªã£ãŠããŸãããçµç¹ã¯å®æœããåã«ç¹å®ã®èª²é¡ãšãªã¹ã¯ãèæ ®ããå¿ èŠããããŸãã
- æ³çããã³èŠå¶äžã®åœ±é¿: çµç¹ã¯ãæœåšçãªæ³ççŽäºãã身ãå®ããé¢é£ããããŒã¿ä¿è·ããã³ãã©ã€ãã·ãŒèŠå¶ã®éµå®ã確ä¿ããããã«ãæç¢ºãªå¥çŽæ¡ä»¶ãçå®ããå¿ èŠããããŸãã
- å éšããã³å€éšã®åãçµã¿ã®èª¿æŽ: ãã°å ±å¥šéããã°ã©ã ã«ã¯å éšã»ãã¥ãªã㣠ããŒã ãéçºè ãå€éšç ç©¶è ãªã©ã®è€æ°ã®é¢ä¿è ãé¢äžãããããæåã«ã¯å¹æçãªã³ãã¥ãã±ãŒã·ã§ã³ãšã³ã©ãã¬ãŒã·ã§ã³ãäžå¯æ¬ ã§ãã
- æåŸ ã®ç®¡ç: ç ç©¶è ã®ã¢ãããŒã·ã§ã³ãé«ããé åçãªå ±é ¬ã®æäŸãšæç¶å¯èœãªäºç®ã®ç¶æã®éã§ãã©ã³ã¹ãåããšåæã«ããã°å ±å¥šéããã°ã©ã ãå®ç§ãªã»ãã¥ãªãã£ãéæããããã®ç¹å¹è¬ã§ã¯ãªãããšãçè§£ããŸãã
HackerOneãBugcrowdãSynack ãªã©ã®æ³šç®ãã¹ããã©ãããã©ãŒã ãšãµãŒãã¹ã¯ãæåºãã¬ããŒãã®ããªã¢ãŒãžãå ±å¥šéã®æ¯æããã³ãã¥ããã£ç®¡çã®ããã®åçåãããã€ã³ã¿ãŒãã§ã€ã¹ãæäŸããããšã§ãçµç¹ããã°å ±å¥šéããã°ã©ã ãç«ã¡äžããŠç®¡çããã®ã«åœ¹ç«ã¡ãŸãã
AppMasterãã©ãããã©ãŒã ã®ã³ã³ããã¹ãã§ã¯ããã°å ±å¥šéããã°ã©ã ã¯ããã©ãããã©ãŒã èªäœã ãã§ãªããçæãããã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£ãšå ç¢æ§ã確ä¿ããäžã§ç¹ã«æçã§ãã AppMaster ãããåºç¯ãªãµã€ããŒã»ãã¥ãªã㣠ã³ãã¥ããã£ãšé£æºããããšã§ãæœåšçãªã»ãã¥ãªãã£ã®åŒ±ç¹ãç¹å®ããŠå¯ŸåŠããéã«å€éšã®å°éç¥èãšèŠç¹ã掻çšã§ããŸããããã«ããã AppMasterã®è£œåã®ã»ãã¥ãªãã£ãšä¿¡é Œæ§ãåäžããã ãã§ãªãããã©ãããã©ãŒã å šäœã®åäžã«ãè²¢ç®ããçµæãšããŠé¡§å®¢æºè¶³åºŠããã€ã€ã«ãã£ãåäžããŸãã
çµè«ãšããŠããã°å ±å¥šéããã°ã©ã ã¯çŸä»£ã®ãµã€ããŒã»ãã¥ãªãã£æŠç¥ã«äžå¯æ¬ ãªèŠçŽ ãšãªã£ãŠãããã·ã¹ãã ãã¢ããªã±ãŒã·ã§ã³ãã€ã³ãã©ã¹ãã©ã¯ãã£ã®ã»ãã¥ãªãã£è匱æ§ãçºèŠããŠä¿®åŸ©ããããã®ããã¢ã¯ãã£ããã€ã³ã¹ãå¹çã®é«ãæ¹æ³ãçµç¹ã«æäŸããŸããå«ççãªããã«ãŒãšã»ãã¥ãªãã£ç ç©¶è ã®äžççãªããŒã«ã掻çšããããšã§ãçµç¹ã¯é²åãç¶ãããµã€ããŒã»ãã¥ãªãã£ç°å¢ã§åªäœæ§ãç²åŸããããžã¿ã«è³ç£ãšé¡§å®¢ããŒã¿ã®å®å šæ§ãšã»ãã¥ãªãã£ã確ä¿ã§ããŸãã