åºæ¬çãªVoIPãããã³ã«
Tip
AWSãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training AWS Red Team Expert (ARTE)
GCPãããã³ã°ãåŠã³ãå®è·µããïŒHackTricks Training GCP Red Team Expert (GRTE)
Azureãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training Azure Red Team Expert (AzRTE)
HackTricksããµããŒããã
- ãµãã¹ã¯ãªãã·ã§ã³ãã©ã³ã確èªããŠãã ããïŒ
- **ð¬ Discordã°ã«ãŒããŸãã¯ãã¬ã°ã©ã ã°ã«ãŒãã«åå ããããTwitter ðŠ @hacktricks_liveããã©ããŒããŠãã ããã
- HackTricksããã³HackTricks Cloudã®GitHubãªããžããªã«PRãæåºããŠãããã³ã°ããªãã¯ãå ±æããŠãã ããã
ã·ã°ããªã³ã°ãããã³ã«
SIP (ã»ãã·ã§ã³éå§ãããã³ã«)
ããã¯æ¥çæšæºã§ãã詳现ã«ã€ããŠã¯ä»¥äžã確èªããŠãã ããïŒ
SIP (Session Initiation Protocol)
MGCP (ã¡ãã£ã¢ã²ãŒããŠã§ã€å¶åŸ¡ãããã³ã«)
MGCP (ã¡ãã£ã¢ã²ãŒããŠã§ã€å¶åŸ¡ãããã³ã«) ã¯ãRFC 3435ã§æŠèª¬ãããã·ã°ããªã³ã°ããã³ã³ãŒã« å¶åŸ¡ãããã³ã«ã§ããããã¯ã3ã€ã®äž»èŠãªã³ã³ããŒãã³ããããªãéäžåã¢ãŒããã¯ãã£ã§åäœããŸãïŒ
- ã³ãŒã«ãšãŒãžã§ã³ããŸãã¯ã¡ãã£ã¢ã²ãŒããŠã§ã€ã³ã³ãããŒã©ãŒ (MGC): MGCPã¢ãŒããã¯ãã£ã®ãã¹ã¿ãŒã²ãŒããŠã§ã€ã¯ãã¡ãã£ã¢ã²ãŒããŠã§ã€ã®ç®¡çãšå¶åŸ¡ãæ åœããŸããã³ãŒã«ã®ã»ããã¢ããã倿Žãçµäºããã»ã¹ãåŠçããŸããMGCã¯MGCPãããã³ã«ã䜿çšããŠã¡ãã£ã¢ã²ãŒããŠã§ã€ãšéä¿¡ããŸãã
- ã¡ãã£ã¢ã²ãŒããŠã§ã€ (MG) ãŸãã¯ã¹ã¬ãŒãã²ãŒããŠã§ã€: ãããã®ããã€ã¹ã¯ãç°ãªããããã¯ãŒã¯éã§ããžã¿ã«ã¡ãã£ã¢ã¹ããªãŒã ã倿ããŸããäŸãã°ãåŸæ¥ã®å路亀æé»è©±ãšãã±ãã亀æIPãããã¯ãŒã¯ã®éã§ãããããã¯MGCã«ãã£ãŠç®¡çãããåä¿¡ããã³ãã³ããå®è¡ããŸããã¡ãã£ã¢ã²ãŒããŠã§ã€ã«ã¯ããã©ã³ã¹ã³ãŒãã£ã³ã°ããã±ããåããšã³ãŒãã£ã³ã»ãªã³ã°ãªã©ã®æ©èœãå«ãŸããå ŽåããããŸãã
- ã·ã°ããªã³ã°ã²ãŒããŠã§ã€ (SG): ãããã®ã²ãŒããŠã§ã€ã¯ãç°ãªããããã¯ãŒã¯éã§ã·ã°ããªã³ã°ã¡ãã»ãŒãžã倿ãã責任ããããŸããããã«ãããåŸæ¥ã®é»è©±ã·ã¹ãã ïŒäŸïŒSS7ïŒãšIPããŒã¹ã®ãããã¯ãŒã¯ïŒäŸïŒSIPãŸãã¯H.323ïŒéã§ã·ãŒã ã¬ã¹ãªéä¿¡ãå¯èœã«ãªããŸããã·ã°ããªã³ã°ã²ãŒããŠã§ã€ã¯ãçžäºéçšæ§ã確ä¿ããç°ãªããããã¯ãŒã¯éã§ã³ãŒã«å¶åŸ¡æ å ±ãé©åã«éä¿¡ãããããšãä¿èšŒããããã«éèŠã§ãã
èŠçŽãããšãMGCPã¯ã³ãŒã«å¶åŸ¡ããžãã¯ãã³ãŒã«ãšãŒãžã§ã³ãã«éäžãããã¡ãã£ã¢ããã³ã·ã°ããªã³ã°ã²ãŒããŠã§ã€ã®ç®¡çãç°¡çŽ åããéä¿¡ãããã¯ãŒã¯ã«ãããã¹ã±ãŒã©ããªãã£ãä¿¡é Œæ§ãããã³å¹çãåäžãããŸãã
SCCP (ã¹ãããŒã¯ã©ã€ã¢ã³ãå¶åŸ¡ãããã³ã«)
ã¹ãããŒã¯ã©ã€ã¢ã³ãå¶åŸ¡ãããã³ã« (SCCP) ã¯ãCisco Systemsãææããç¬èªã®ã·ã°ããªã³ã°ããã³ã³ãŒã«å¶åŸ¡ãããã³ã«ã§ããäž»ã«Cisco Unified Communications ManagerïŒä»¥åã®CallManagerïŒãšCisco IPé»è©±ãŸãã¯ä»ã®Ciscoé³å£°ããã³ãããªãšã³ããã€ã³ãéã®éä¿¡ã«äœ¿çšãããŸãã
SCCPã¯ãã³ãŒã«å¶åŸ¡ãµãŒããŒãšãšã³ããã€ã³ãããã€ã¹éã®éä¿¡ãç°¡çŽ åãã軜éãããã³ã«ã§ãããã¹ãããŒããšåŒã°ããã®ã¯ãä»ã®VoIPãããã³ã«ïŒäŸïŒH.323ãSIPïŒã«æ¯ã¹ãŠããããªã¹ãã£ãã¯ãªèšèšãšåž¯åå¹ èŠä»¶ãå°ãªãããã§ãã
SCCPããŒã¹ã®ã·ã¹ãã ã®äž»ãªã³ã³ããŒãã³ãã¯æ¬¡ã®ãšããã§ãïŒ
- ã³ãŒã«å¶åŸ¡ãµãŒããŒ: éåžžã¯Cisco Unified Communications Managerã§ããã®ãµãŒããŒã¯ã³ãŒã«ã®ã»ããã¢ããã倿Žãçµäºããã»ã¹ãããã³ã³ãŒã«è»¢éãã³ãŒã«è»¢éãã³ãŒã«ããŒã«ããªã©ã®ä»ã®é»è©±æ©èœã管çããŸãã
- SCCPãšã³ããã€ã³ã: ãããã¯ãIPé»è©±ããããªäŒè°ãŠãããããŸãã¯SCCPã䜿çšããŠã³ãŒã«å¶åŸ¡ãµãŒããŒãšéä¿¡ããä»ã®Ciscoé³å£°ããã³ãããªãšã³ããã€ã³ããªã©ã®ããã€ã¹ã§ãããããã¯ãµãŒããŒã«ç»é²ããã·ã°ããªã³ã°ã¡ãã»ãŒãžãéåä¿¡ããã³ãŒã«å¶åŸ¡ãµãŒããŒããæäŸãããæç€ºã«åŸããŸãã
- ã²ãŒããŠã§ã€: ãããã®ããã€ã¹ïŒé³å£°ã²ãŒããŠã§ã€ãã¡ãã£ã¢ã²ãŒããŠã§ã€ãªã©ïŒã¯ãåŸæ¥ã®å路亀æé»è©±ãšãã±ãã亀æIPãããã¯ãŒã¯ã®ãããªç°ãªããããã¯ãŒã¯éã§ã¡ãã£ã¢ã¹ããªãŒã ã倿ãã責任ããããŸãããŸãããã©ã³ã¹ã³ãŒãã£ã³ã°ããšã³ãŒãã£ã³ã»ãªã³ã°ãªã©ã®è¿œå æ©èœãå«ãå ŽåããããŸãã
SCCPã¯ãCiscoã³ãŒã«å¶åŸ¡ãµãŒããŒãšãšã³ããã€ã³ãããã€ã¹éã®ã·ã³ãã«ã§å¹ççãªéä¿¡æ¹æ³ãæäŸããŸãããã ããSCCPã¯ç¬èªã®ãããã³ã«ã§ãããããéCiscoã·ã¹ãã ãšã®çžäºéçšæ§ãå¶éãããå¯èœæ§ããããŸãããã®ãããªå ŽåãSIPã®ãããªä»ã®æšæºVoIPãããã³ã«ãããé©ããŠãããããããŸããã
H.323
H.323ã¯ãé³å£°ããããªãããŒã¿äŒè°ãå«ããã«ãã¡ãã£ã¢éä¿¡ã®ããã®ãããã³ã«ã¹ã€ãŒãã§ããã±ãã亀æãããã¯ãŒã¯ïŒIPããŒã¹ã®ãããã¯ãŒã¯ãªã©ïŒäžã§åäœããŸããããã¯åœé黿°éä¿¡é£åïŒITU-TïŒã«ãã£ãŠéçºããããã«ãã¡ãã£ã¢éä¿¡ã»ãã·ã§ã³ã管çããããã®å æ¬çãªãã¬ãŒã ã¯ãŒã¯ãæäŸããŸãã
H.323ã¹ã€ãŒãã®ããã€ãã®äž»èŠãªã³ã³ããŒãã³ãã¯æ¬¡ã®ãšããã§ãïŒ
- 端æ«: ãããã¯ãH.323ããµããŒããããã«ãã¡ãã£ã¢éä¿¡ã»ãã·ã§ã³ã«åå ã§ããIPé»è©±ããããªäŒè°ã·ã¹ãã ããŸãã¯ãœãããŠã§ã¢ã¢ããªã±ãŒã·ã§ã³ãªã©ã®ãšã³ããã€ã³ãããã€ã¹ã§ãã
- ã²ãŒããŠã§ã€: ãããã®ããã€ã¹ã¯ãåŸæ¥ã®å路亀æé»è©±ãšãã±ãã亀æIPãããã¯ãŒã¯ã®ãããªç°ãªããããã¯ãŒã¯éã§ã¡ãã£ã¢ã¹ããªãŒã ã倿ããH.323ãšä»ã®éä¿¡ã·ã¹ãã éã®çžäºéçšæ§ãå¯èœã«ããŸãããŸãããã©ã³ã¹ã³ãŒãã£ã³ã°ããšã³ãŒãã£ã³ã»ãªã³ã°ãªã©ã®è¿œå æ©èœãå«ãå ŽåããããŸãã
- ã²ãŒãããŒããŒ: ãããã¯ãH.323ãããã¯ãŒã¯å ã§ã³ãŒã«å¶åŸ¡ããã³ç®¡çãµãŒãã¹ãæäŸãããªãã·ã§ã³ã®ã³ã³ããŒãã³ãã§ããã¢ãã¬ã¹å€æã垯åå¹ ç®¡çãå ¥å Žå¶åŸ¡ãªã©ã®æ©èœãå®è¡ãããããã¯ãŒã¯ãªãœãŒã¹ã®ç®¡çãšæé©åãæ¯æŽããŸãã
- ãã«ããã€ã³ãå¶åŸ¡ãŠããã (MCU): ãããã®ããã€ã¹ã¯ãè€æ°ã®ãšã³ããã€ã³ãããã®ã¡ãã£ã¢ã¹ããªãŒã ã管çããã³ããã·ã³ã°ããããšã«ããããã«ããã€ã³ãäŒè°ãä¿é²ããŸããMCUã¯ããããªã¬ã€ã¢ãŠãå¶åŸ¡ãé³å£°ã¢ã¯ãã£ãã¹ã€ããã³ã°ãç¶ç¶çãªãã¬ãŒã³ã¹ãªã©ã®æ©èœãå¯èœã«ããè€æ°ã®åå è ãšã®å€§èŠæš¡ãªäŒè°ãéå¬ããããšãå¯èœã«ããŸãã
H.323ã¯ãé³å£°ããã³ãããªã³ãŒããã¯ã®ç¯å²ããªãã³ã«ã³ãŒã«è»¢éãã³ãŒã«è»¢éãã³ãŒã«ããŒã«ããã³ãŒã«åŸ æ©ãªã©ã®ä»ã®è£å©ãµãŒãã¹ããµããŒãããŸããVoIPã®åæã«åºãæ¡çšãããŸããããH.323ã¯ã**ã»ãã·ã§ã³éå§ãããã³ã« (SIP)**ã®ãããªããçŸä»£çã§æè»ãªãããã³ã«ã«åŸã ã«çœ®ãæããããŠããŸããSIPã¯ãããè¯ãçžäºéçšæ§ãšç°¡åãªå®è£ ãæäŸããŸããããããH.323ã¯å€ãã®ã¬ã¬ã·ãŒã·ã¹ãã ã§äœ¿çšããç¶ããŠãããããŸããŸãªæ©åšãã³ããŒã«ãã£ãŠãµããŒããããŠããŸãã
IAX (ã€ã³ã¿ãŒã¢ã¹ã¿ãªã¹ã¯ãšã¯ã¹ãã§ã³ãž)
IAX (ã€ã³ã¿ãŒã¢ã¹ã¿ãªã¹ã¯ãšã¯ã¹ãã§ã³ãž) ã¯ãäž»ã«Asterisk PBXïŒãã©ã€ããŒããã©ã³ã亀æïŒãµãŒããŒãšä»ã®VoIPããã€ã¹éã®éä¿¡ã«äœ¿çšãããã·ã°ããªã³ã°ããã³ã³ãŒã«å¶åŸ¡ãããã³ã«ã§ããããã¯ãAsteriskãªãŒãã³ãœãŒã¹PBXãœãããŠã§ã¢ã®äœæè ã§ããMark Spencerã«ãã£ãŠãSIPãH.323ãªã©ã®ä»ã®VoIPãããã³ã«ã®ä»£æ¿ãšããŠéçºãããŸããã
IAXã¯ããã®ã·ã³ãã«ããå¹çæ§ãããã³å®è£ ã®å®¹æãã§ç¥ãããŠããŸããIAXã®ããã€ãã®äž»èŠãªæ©èœã¯æ¬¡ã®ãšããã§ãïŒ
- åäžUDPããŒã: IAXã¯ãã·ã°ããªã³ã°ãšã¡ãã£ã¢ãã©ãã£ãã¯ã®äž¡æ¹ã«åäžã®UDPããŒãïŒ4569ïŒã䜿çšãããã¡ã€ã¢ãŠã©ãŒã«ãNATã®ãã©ããŒãµã«ãç°¡çŽ åããããŸããŸãªãããã¯ãŒã¯ç°å¢ã§ã®å±éã容æã«ããŸãã
- ãã€ããªãããã³ã«: SIPã®ãããªããã¹ãããŒã¹ã®ãããã³ã«ãšã¯ç°ãªããIAXã¯ãã€ããªãããã³ã«ã§ããã垯åå¹ ã®æ¶è²»ãæžå°ãããã·ã°ããªã³ã°ããã³ã¡ãã£ã¢ããŒã¿ã®éä¿¡ãããå¹ççã«ããŸãã
- ãã©ã³ãã³ã°: IAXã¯ãã©ã³ãã³ã°ããµããŒãããŠãããè€æ°ã®ã³ãŒã«ãåäžã®ãããã¯ãŒã¯æ¥ç¶ã«çµåããããšãã§ãããªãŒããŒããããåæžãã垯åå¹ ã®å©çšãæ¹åããŸãã
- ãã€ãã£ãæå·å: IAXã¯ãRSAã䜿çšããéµäº€æãAESã䜿çšããã¡ãã£ã¢æå·åãªã©ã®æ¹æ³ã§æå·åããµããŒãããŠããããšã³ããã€ã³ãéã®å®å šãªéä¿¡ãæäŸããŸãã
- ãã¢ããŒãã¢éä¿¡: IAXã¯ãäžå€®ãµãŒããŒãå¿ èŠãšããã«ãšã³ããã€ã³ãéã§çŽæ¥éä¿¡ããããã«äœ¿çšã§ããããã·ã³ãã«ã§å¹ççãªã³ãŒã«ã«ãŒãã£ã³ã°ãå¯èœã«ããŸãã
å©ç¹ã«ãããããããIAXã«ã¯ããã€ãã®å¶éããããŸããäž»ã«Asteriskãšã³ã·ã¹ãã ã«çŠç¹ãåœãŠãŠãããSIPã®ãããªãã確ç«ããããããã³ã«ã«æ¯ã¹ãŠåºãæ¡çšãããŠããŸããããã®ãããéAsteriskã·ã¹ãã ãããã€ã¹ãšã®çžäºéçšæ§ã«ã¯æé©ã§ã¯ãªããããããŸãããããããAsteriskç°å¢å ã§äœæ¥ãã人ã ã«ãšã£ãŠãIAXã¯VoIPéä¿¡ã®ããã®å ç¢ã§å¹ççãªãœãªã¥ãŒã·ã§ã³ãæäŸããŸãã
äŒéããã³èŒžéãããã³ã«
SDP (ã»ãã·ã§ã³èšè¿°ãããã³ã«)
SDP (ã»ãã·ã§ã³èšè¿°ãããã³ã«) ã¯ãIPãããã¯ãŒã¯äžã§ã®é³å£°ããããªããŸãã¯ããŒã¿äŒè°ãªã©ã®ãã«ãã¡ãã£ã¢ã»ãã·ã§ã³ã®ç¹æ§ãèšè¿°ããããã«äœ¿çšãããããã¹ãããŒã¹ã®ãã©ãŒãããã§ããããã¯**ã€ã³ã¿ãŒãããæè¡è ã¿ã¹ã¯ãã©ãŒã¹ (IETF)**ã«ãã£ãŠéçºãããRFC 4566ã§å®çŸ©ãããŠããŸããSDPã¯å®éã®ã¡ãã£ã¢äŒéãã»ãã·ã§ã³ã®ç¢ºç«ãåŠçããã**SIP (ã»ãã·ã§ã³éå§ãããã³ã«)**ã®ãããªä»ã®ã·ã°ããªã³ã°ãããã³ã«ãšçµã¿åãããŠãã¡ãã£ã¢ã¹ããªãŒã ãšãã®å±æ§ã«é¢ããæ å ±ã亀æžããã³äº€æããããã«äœ¿çšãããŸãã
SDPã®ããã€ãã®éèŠãªèŠçŽ ã¯æ¬¡ã®ãšããã§ãïŒ
- ã»ãã·ã§ã³æ å ±: SDPã¯ãã»ãã·ã§ã³åãã»ãã·ã§ã³ã®èª¬æãéå§æå»ãçµäºæå»ãªã©ããã«ãã¡ãã£ã¢ã»ãã·ã§ã³ã®è©³çްãèšè¿°ããŸãã
- ã¡ãã£ã¢ã¹ããªãŒã : SDPã¯ãã¡ãã£ã¢ã¿ã€ãïŒé³å£°ããããªããŸãã¯ããã¹ãïŒã茞éãããã³ã«ïŒäŸïŒRTPãŸãã¯SRTPïŒãããã³ã¡ãã£ã¢ãã©ãŒãããïŒäŸïŒã³ãŒããã¯æ å ±ïŒãªã©ãã¡ãã£ã¢ã¹ããªãŒã ã®ç¹æ§ãå®çŸ©ããŸãã
- æ¥ç¶æ å ±: SDPã¯ãã¡ãã£ã¢ãéä¿¡ãŸãã¯åä¿¡ãããã¹ããããã¯ãŒã¯ã¢ãã¬ã¹ïŒIPã¢ãã¬ã¹ïŒããã³ããŒãçªå·ã«é¢ããæ å ±ãæäŸããŸãã
- 屿§: SDPã¯ãã»ãã·ã§ã³ãŸãã¯ã¡ãã£ã¢ã¹ããªãŒã ã«é¢ãã远å ã®ãªãã·ã§ã³æ å ±ãæäŸããããã«å±æ§ã®äœ¿çšããµããŒãããŸãã屿§ã¯ãæå·åããŒã垯åå¹ èŠä»¶ããŸãã¯ã¡ãã£ã¢å¶åŸ¡ã¡ã«ããºã ãªã©ã®ããŸããŸãªæ©èœãæå®ããããã«äœ¿çšã§ããŸãã
SDPã¯éåžžãæ¬¡ã®ããã»ã¹ã§äœ¿çšãããŸãïŒ
- éå§ããåœäºè ããã¡ãã£ã¢ã¹ããªãŒã ãšãã®å±æ§ã®è©³çްãå«ãææ¡ããããã«ãã¡ãã£ã¢ã»ãã·ã§ã³ã®SDPèšè¿°ãäœæããŸãã
- SDPèšè¿°ã¯ãéåžžãSIPãRTSPã®ãããªã·ã°ããªã³ã°ãããã³ã«ã¡ãã»ãŒãžå ã«åã蟌ãŸããŠåä¿¡è ã«éä¿¡ãããŸãã
- åä¿¡è ã¯SDPèšè¿°ãåŠçãããã®èœåã«åºã¥ããŠãææ¡ãããã»ãã·ã§ã³ãåãå ¥ãããæåŠããããŸãã¯å€æŽããããšããããŸãã
- æçµçãªSDPèšè¿°ã¯ãã·ã°ããªã³ã°ãããã³ã«ã¡ãã»ãŒãžã®äžéšãšããŠéå§ããåœäºè ã«è¿éããã亀æžããã»ã¹ãå®äºããŸãã
SDPã®ã·ã³ãã«ããšæè»æ§ã¯ãããŸããŸãªéä¿¡ã·ã¹ãã ã§ãã«ãã¡ãã£ã¢ã»ãã·ã§ã³ãèšè¿°ããããã®åºãæ¡çšãããæšæºãšãªã£ãŠãããIPãããã¯ãŒã¯äžã§ãªã¢ã«ã¿ã€ã ã®ãã«ãã¡ãã£ã¢ã»ãã·ã§ã³ã確ç«ããã³ç®¡çããäžã§éèŠãªåœ¹å²ãæãããŸãã
RTP / RTCP / SRTP / ZRTP
- RTP (ãªã¢ã«ã¿ã€ã ãã©ã³ã¹ããŒããããã³ã«): RTPã¯ãIPãããã¯ãŒã¯äžã§é³å£°ããã³ãããªããŒã¿ããŸãã¯ä»ã®ãªã¢ã«ã¿ã€ã ã¡ãã£ã¢ãé ä¿¡ããããã«èšèšããããããã¯ãŒã¯ãããã³ã«ã§ããIETFã«ãã£ãŠéçºãããRFC 3550ã§å®çŸ©ãããŠããRTPã¯ãSIPãH.323ã®ãããªã·ã°ããªã³ã°ãããã³ã«ãšäžè¬çã«äœ¿çšããããã«ãã¡ãã£ã¢éä¿¡ãå¯èœã«ããŸããRTPã¯ãã¡ãã£ã¢ã¹ããªãŒã ã®åæãã·ãŒã±ã³ã·ã³ã°ãããã³ã¿ã€ã ã¹ã¿ã³ãã®ã¡ã«ããºã ãæäŸããã¹ã ãŒãºã§ã¿ã€ã ãªãŒãªã¡ãã£ã¢åçã確ä¿ããŸãã
- RTCP (ãªã¢ã«ã¿ã€ã ãã©ã³ã¹ããŒãå¶åŸ¡ãããã³ã«): RTCPã¯RTPã®è£å®ãããã³ã«ã§ããµãŒãã¹å質ïŒQoSïŒãç£èŠããã¡ãã£ã¢ã¹ããªãŒã ã®äŒéã«é¢ãããã£ãŒãããã¯ãæäŸããããã«äœ¿çšãããŸããRTPãšåãRFC 3550ã§å®çŸ©ãããŠããRTCPã¯ãRTPã»ãã·ã§ã³ã®åå è éã§å¶åŸ¡ãã±ããã宿çã«äº€æããŸãããã±ãããã¹ããžãã¿ãŒãåŸåŸ©æéãªã©ã®æ å ±ãå ±æãããããã¯ãŒã¯æ¡ä»¶ã«é©å¿ããå šäœçãªã¡ãã£ã¢åè³ªãæ¹åããã®ã«åœ¹ç«ã¡ãŸãã
- SRTP (ã»ãã¥ã¢ãªã¢ã«ã¿ã€ã ãã©ã³ã¹ããŒããããã³ã«): SRTPã¯ãã¡ãã£ã¢ã¹ããªãŒã ã«å¯ŸããŠæå·åãã¡ãã»ãŒãžèªèšŒãããã³åçä¿è·ãæäŸããRTPã®æ¡åŒµã§ããããã«ãããæ©å¯ã®é³å£°ããã³ãããªããŒã¿ã®å®å šãªäŒéã確ä¿ãããŸããRFC 3711ã§å®çŸ©ãããŠããSRTPã¯ãAESã®ãããªæå·åã¢ã«ãŽãªãºã ãšHMAC-SHA1ã®ãããªã¡ãã»ãŒãžèªèšŒã䜿çšããŸããSRTPã¯ãSIP over TLSã®ãããªå®å šãªã·ã°ããªã³ã°ãããã³ã«ãšçµã¿åãããŠäœ¿çšããããã«ãã¡ãã£ã¢éä¿¡ã«ããããšã³ãããŒãšã³ãã®ã»ãã¥ãªãã£ãæäŸããŸãã
- ZRTP (ãžããŒãã³ãªã¢ã«ã¿ã€ã ãã©ã³ã¹ããŒããããã³ã«): ZRTPã¯ãRTPã¡ãã£ã¢ã¹ããªãŒã ã«å¯ŸããŠãšã³ãããŒãšã³ãã®æå·åãæäŸããæå·éµåæãããã³ã«ã§ããPGPã®äœæè ã§ããPhil Zimmermannã«ãã£ãŠéçºãããRFC 6189ã§èª¬æãããŠããŸããZRTPã¯ãéµäº€æã®ããã«ã·ã°ããªã³ã°ãããã³ã«ã«äŸåããSRTPãšã¯ç°ãªããã·ã°ããªã³ã°ãããã³ã«ãšã¯ç¬ç«ããŠæ©èœããããã«èšèšãããŠããŸããZRTPã¯ãDiffie-Hellmanéµäº€æã䜿çšããŠãéä¿¡ããåœäºè éã§å ±æç§å¯ã確ç«ããäºåã®ä¿¡é Œãå ¬ééµã€ã³ãã©ã¹ãã©ã¯ãã£ïŒPKIïŒãå¿ èŠãšããŸãããZRTPã«ã¯ããã³ã€ã³ã¶ããã«æ»æããä¿è·ããããã®**çãèªèšŒæåå (SAS)**ãªã©ã®æ©èœãå«ãŸããŠããŸãã
ãããã®ãããã³ã«ã¯ãIPãããã¯ãŒã¯äžã§ã®ãªã¢ã«ã¿ã€ã ãã«ãã¡ãã£ã¢éä¿¡ã®é ä¿¡ãšã»ãã¥ãªãã£ã«ãããŠéèŠãªåœ¹å²ãæãããŸããRTPãšRTCPã¯å®éã®ã¡ãã£ã¢äŒéãšå質ç£èŠãåŠçããSRTPãšZRTPã¯ãéä¿¡ãããã¡ãã£ã¢ãçèŽãæ¹ãããåçæ»æããä¿è·ãããããšãä¿èšŒããŸãã
Tip
AWSãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training AWS Red Team Expert (ARTE)
GCPãããã³ã°ãåŠã³ãå®è·µããïŒHackTricks Training GCP Red Team Expert (GRTE)
Azureãããã³ã°ãåŠã³ãå®è·µããïŒ
HackTricks Training Azure Red Team Expert (AzRTE)
HackTricksããµããŒããã
- ãµãã¹ã¯ãªãã·ã§ã³ãã©ã³ã確èªããŠãã ããïŒ
- **ð¬ Discordã°ã«ãŒããŸãã¯ãã¬ã°ã©ã ã°ã«ãŒãã«åå ããããTwitter ðŠ @hacktricks_liveããã©ããŒããŠãã ããã
- HackTricksããã³HackTricks Cloudã®GitHubãªããžããªã«PRãæåºããŠãããã³ã°ããªãã¯ãå ±æããŠãã ããã


