åã¯ä»å¹´ã«å ¥ã£ã¦ãããã¾ãã¾çºè¦ããã»ãã¥ãªãã£èå¼±æ§ãç©æ¥µçã«å ±åããããã«ãã¯ããã¾ãããå½ç¶ãæ¤è¨¼ã®éã«ã¯æ³ãéµå®ããããå¿ããã¦ãã¾ãããä»ã«ããæ¤è¨¼ã®éç¨ã§èª¤ã£ã¦è¢«å®³ãä¸ãã¦ãã¾ããã¨ããªãããã«ããã¨ãã° SQL Injection èå¼±æ§ã®çºè¦ã¯é¿ãããªã©ã®èªåã«ã¼ã«ã決ãã¦ãç´ äººãªãã«ç´°ã ã¨ãã£ã¦ãã¾ãã
ãã¦æè¿ã
- æ¨ä»ã®å¦æ ¡ã®ã»ãã¥ãªãã£äºæ ã第ä¸ç« 妿 ¡ã®PC(çå¾ä½¿ç¨PC)ã«ã¤ãã¦ã - toriimiyukkiã®æ¥è¨
- http://d.hatena.ne.jp/toriimiyukki/20110907/1315406102
ã¨ããã¨ã³ããªãè¦ã¤ãã¾ãã¦ãããããµããµãã¨èªãã§ããã¨ããã:
ãµã¨ãèªåã®å¦æ ¡ã®ã¦ã¼ã¶ã¼ãªã¹ã(ä¸è¨ã®ã³ãã³ãã§åå¾)ãè¦ã¦ãã¨ãtestuserããªãè ããã£ãã net group [ã°ã«ã¼ãå] ã§ã試ããã¨ããã****ãã¨ãããã¹ã¯ã¼ãã§ééããã£ã¦ãããããå¼ç¨è 註: ãã¹ã¯ã¼ãã«ã¤ãã¦ã¯ä¼ãåã«ãã¾ããã
ã¨ããè¨è¿°ãããã®ãè¦ã¤ãã¾ãããä»äººã®èå¥ç¬¦å·ã使ç¨ãã¦ããã¨ãããã¨ã¯ããã¯è¨ãã¾ã§ããªã䏿£ã¢ã¯ã»ã¹è¡çºã§ãããã
ããã§ã®ã§ãã¨ãã¾ãã¦ãç¶ãã®ã¨ã³ããªãæèªããã®ã§ããããã¡ãã«ãæ³ã«æµè§¦ããã¨æãããå 容ãè¨ããã¦ãã¾ããã
ã¨ããããã¯ã¦ãªããã¯ãã¼ã¯ã®ã³ã¡ã³ãçãè¦ã¦ãã¦ããéæ³æ§ãææãããããªå£°ã¯å°ãªããã©ã¡ããã¨ãã㨠100 % è³è³ã¨ãã£ã声ãç®ç«ã£ã¦ãã¦ã
- ãã®ã¨ã³ããªã®ä½è ã¯å«ççãªå顿èãæãã¦ãããããããªãããéæ³æ§ã«ã¤ãã¦ã¯èªèãã¦ããªãã®ã§ã¯ãªããï¼èªèãã¦ããã¨ããããããªãã¨ããã°ã«æ¸ããªãã®ã§ã¯ã¨ããèãã®ä¸ã§ï¼ãã¾ãããã¯ãã¼ã¯ã³ã¡ã³ããªã©ãè¦ã¦ãããã§ã¯èªèãæ¹ããããªãã®ã§ã¯ãªãã
- ãã®ã¨ã³ããªã®èªè ã¯ãããèªãã§ãã®ãããªæ¤è¨¼ã«å¯¾ããéæ³æ§ãèªèããªãã®ã§ã¯ãªãã
ã¨ããç¹ãå¿é ã«ãªããæ¬å½ã¯ãã£ã¨åãªããããã詳ãã人ãããºããªã¨è¨ã£ã¦ããããã°ã¨ãæããã§ããããã®ã¨ã³ããªãæ¸ããã¨ã«ãã¾ããã
SQL Injection èå¼±æ§ã®æ¤è¨¼ã«ã¤ãã¦
- æ¨ä»ã®å¦æ ¡ã®ã»ãã¥ãªãã£äºæ ã第äºç« 妿 ¡ã®Webãµã¤ãã«ã¤ãã¦-SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãã追å ããã - toriimiyukkiã®æ¥è¨
- http://d.hatena.ne.jp/toriimiyukki/20110908/1315483176
ã¨ããã¨ã³ããªã«ã¯ã:
ã¾ãããã¿ã¤ãã«ã«ãæ¸ãã¦ããã®ã§ãåããã§ãããã
https://www.gakkou/****.php?ID=****&CHAIN=' OR 'a'='a ãå¼ç¨è
註: ã¹ã¯ãªãããã¡ã¤ã«å㨠ID ãä¼ãåã«ãã¾ããã
ã¨ããã°ã©ã®ã¹ã¬ããã§ãè¦ãã¦ãã¾ãã¾ãã
IDãã¡ã¼ã«ã®ã¦ãã¼ã¯ãªã¡ã¼ã«IDãªã®ã§ããããå¤ããã°èª°ããã®ã¡ã¼ã«ãåãããªãã§ããã¡ã¼ã«ã®å
容ãé¤ããã¨ãåºæ¥ã¾ããã
ã¨ããè¨è¿°ãããã¾ãã
CHAIN ã¨ãããã®ã¯åç´ãªã¦ã¼ã¶ ID ã®ããã·ã¥ã¨ãããã¨ã§ãã¾ããç²æ«ãªãã¨ã¯ç¢ºããªã®ã§ãããããã¯ãã䏿£ã¢ã¯ã»ã¹è¡çºã®ç¦æ¢çã«é¢ããæ³å¾ãã«ããããã¢ã¯ã»ã¹å¶å¾¡æ©è½ã«ä¿ãä»äººã®èå¥ç¬¦å·ãã¨è§£éãããã¨ãã§ããã®ã§ã¯ãªãããªã¨æãã¾ãããã®è§£éãæ£ãããã°ããã® SQL Injection æ»æã«ãã£ã¦æ¬æ¥ã®èªè¨¼æ©æ§ãåé¿ãã¦ä»äººã«ãªããã¾ããã¨ãããã¨ã«ãªããããã¯ä¸æ£ã¢ã¯ã»ã¹è¡çºã«ãããã®ã§ã¯ãªããã¨æãã¾ãã
ãã®å ´åãèªåå®ã®ã¡ã¼ã«ã® URL ãã CHAIN ãçãã¦ã¢ã¯ã»ã¹ããããªããªããã¨ã確èªããã®ã¡ã«ã å¼ç¨æä¸ã® URLï¼ãã ããã¡ããèªåã®ã¡ã¼ã« ID ãæå®ããä¸ã§ï¼ã«ã¢ã¯ã»ã¹ããã¡ãã»ã¼ã¸ãé²è¦§ã§ãããã©ãã確èªãããã¨ã§ãèå¼±æ§ãå®éã«åå¨ãããã¨ã確èªã§ããã¯ãã§ããããããä»äººã®ã¡ã¼ã«ãè¦ãå¿ è¦ã¯ãªãã£ãã¯ãã§ãã
# ã¡ãªã¿ã«ãï¼å ã»ã©ããã¨ãã° SQL Injection ã¯é¿ãããã¨ãè¨ã£ã¦ããã¦ã¢ã¬ãªãã§ããï¼å®ã¯ SQL Injection èå¼±æ§ã®å±ãåºã¯ãããã¨ããã£ã¦ï¼ã ã£ã¦ãªã³ã¯ã¯ãªãã¯ãããè¦ã¤ãã£ããã ãã®â¦â¦ï¼ããã®æã¯ MySQL ã® SLEEP() 颿°ãä»è¾¼ãã§ãæå®ããç§æ°ã¶ãã¬ã¹ãã³ã¹ãé å»¶ãããã¨ã確èªããèå¼±ã§ããå¯è½æ§ãé«ãã¨å¤æãã¦å±ãåºã¾ããã
CHAIN ãã©ã¡ã¼ã¿ã®çææ¹æ³èªä½ãèå¼±ã§ãããã¨ã®æ¤è¨¼ã«ã¤ãã¦
ãã®ã¨ã³ããªã§ã¯ä»äººã®ã¦ã¼ã¶ ID ã®ããã·ã¥å¤ãå®éã«ãªã¯ã¨ã¹ãã«å«ãã§ï¼CHAIN ãã©ã¡ã¼ã¿ã®å¤ã¨ãã¦ã»ãããã¦ï¼è©¦è¡ãããã©ããã«ã¤ãã¦ã¯ã¯ã£ããã¨ã¯æ¸ããã¦ãã¾ããã
ãããã®ãããªè¡çºãããã®ã§ããã°ãå ã»ã©ã¨åãããã«ããä»äººã®èå¥ç¬¦å·ããå©ç¨ãã¦èªè¨¼æ©æ§ãåé¿ãããã¨ã«ãªãã確å®ã«ã¢ã¦ãã¨è¨ããã¨æãã¾ãã
ãã®å ´åãåã ã£ãããèªåã®ã¦ã¼ã¶ ID ã®ããã·ã¥å¤ãåºãã¦ãã·ã¹ãã ããéããã URL ã«å«ã¾ããå¤ã¨ä¸è´ãã¦ããã°ããããã®æ®µéã§èå¼±æ§ã ã¨æå®ãã¦å±ãåºãã¨æãã¾ãããã®å ã«ã¯çµ¶å¯¾ã«è¸ã¿è¾¼ã¿ã¾ããã
ãã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³ãã®æ¤è¨¼ã«ã¤ãã¦
- æ¨ä»ã®å¦æ ¡ã®ã»ãã¥ãªãã£äºæ ã第ä¸ç« 妿 ¡ã®Webãµã¤ãã«ã¤ãã¦-ã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³/ãã®ä»ã - toriimiyukkiã®æ¥è¨
- http://d.hatena.ne.jp/toriimiyukki/20110909/1315580347
ã«ã¯ã:
æªæã®ããçå¾ãªããã®ãããªãã¡ã¤ã«ãç½®ãã¦å®¶ã«å¸°ãã¯ã...
<?php
print('<pre>' . shell_exec($_GET['cmd']) . '</pre>');
ããããã®ãã£ã¬ã¯ããªã«ã¯å®è¡ãã¡ã¤ã«ã®ç¦æ¢ãªã©ããªã誰ã§ãèªç±ã«ãã¡ã¤ã«ãç½®ããã¨ãã§ããã
ã¨æ¸ããã¦ãã¾ããããããã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³ãã¨å¼ãã§ããããã§ããããããã ãOS ã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æã ãæãã¦ããã®ã ã¨æãã¾ãããã ããã®ç¶æ ããããä¸éã§è¨ãå½è©²èå¼±æ§ã«ãããã¨è¨ãããã©ããã¯ãããããã¾ããï¼ããã ã£ã¦ãã¤ã³ã¸ã§ã¯ã·ã§ã³ãâ¦â¦ï¼ï¼ã
ã¾ããããã¯ã¨ãããã¨ãã¦ãããµã¼ãæ©ã®èªè¨¼ãåé¿ãã¦ä»»æã®ã³ãã³ããå®è¡ãããã¨ãã¦ããããã§ããããã¢ã¦ããªãããªæ°ããã¾ãããã»ã¼ãã®å¯è½æ§ããããããªï¼ãã©ããªãã§ãããããã¯ã
åããã®èå¼±æ§ãè¦ã¤ãããã©ã証æãããâ¦â¦ãã¼ãããã¯ã¡ãã£ã¨ã©ããããããã®ãããããªãã§ããä»»æã® PHP ã¹ã¯ãªãããç½®ããã¨ãããã¨ãªã®ã§ããã®ãã£ã¬ã¯ããªã«é©å½ãªãã¡ã¤ã«ã§ãæ¸ãåºãã¦ã¿ãï¼ãçèã®æ«é©æ³ãªèªä¿¡ãæã¦ãªããã°ãæ¤è¨¼ã¯ããã«å±éºã£ã½ããã¨ãããã¨ã®ã¿ä¼ããããããã¾ããã
MySQL ã® root ã¢ã«ã¦ã³ããçºè¦ããå ´åã®æ¤è¨¼ã«ã¤ãã¦
ãããã¦ãããã¡ã«MySQLã使ã£ãããã°ã©ã ãè¦ã¤ããããã§ããã <?php $mysqlname = 'root'; $mysqlpass = 'XXXXXX'; ï¼ç¥ï¼ Macã®MySQLBrowserã«ã¦è²ã ãªãã¼ã¿ãã¼ã¹ãè¦ã¦ã¦é¢ç½ãã§ããã æ®éã«å人æ å ±ãããã¾ããååãããã¾ãã使ãè¼ã£ã¦ã¾ããé»è©±çªå·ãã®ã£ã¦ã¾ãã ãããªå人æ å ±ãæ±ã£ã¦ããã®ã«ãã®ã»ãã¥ãªãã£ã®ä½ãã«ã¯ã¤ã©ãã¨ãã¾ãã
ã¨ãããã¨ã§ã MySQL ã® root ã¢ã«ã¦ã³ãã¸ã®ãã°ã¤ã³ããããªã£ãããã§ãããã¯ééããªãã¢ã¦ãã ã¨æãã¾ãã
MySQLã§rootã®ãã¹ã¯ã¼ããæã«å ¥ããã誰ããã¢ã¯ã»ã¹ããããªãã¾ãããããªãã¾ãããã
ãªãã¾ããã
ã¨ããããã§ãã㯠root ã¢ã«ã¦ã³ãã®ãã¹ã¯ã¼ãã§ãããã¨ã¯æãããªã®ã§ããã¾ãã¾çºè¦ãã¦ãã¾ã£ãã¨ãã¦ãå®éã«ãã°ã¤ã³ãã¦ã¿ããã¨ã¯åã ã£ãããªãã§ãããããã ã root ã¢ã«ã¦ã³ãã§ã®ä»»æã®ãã¹ãããã®ãã°ã¤ã³ã許ããã¦ãããã©ããã¯ãå®éã«ãã°ã¤ã³ãã¦ã¿ãªãã¨ããããªãã§ããããã¶ãï¼ãã®ãããã¨ãã¡ããã¨ããæ¤è¨¼æ¹æ³ã£ã¦ãããã§ããããâ¦â¦ï¼ï¼ããããããã¹ã¯ã¼ããè¦ã¤ãã¦ãã¾ã£ãäºå®ã®å ±åã¨ãããã¤ãã®ææ¡ãããã«ã¨ã©ãã¦ããããããã¾ãããã¡ãã£ã¨éç¶ã¨ããªãã§ãããã§ãåã®ã¹ãã«ãªã仿¹ããªãããªã¼ãããé度ã ãªã¼ã
妿 ¡å´ã®å¯¾å¿ã¨åã¨ã³ããªã®åå¿ã«ã¤ãã¦
â¦â¦ã§ã¾ãã
- æ¨ä»ã®å¦æ ¡ã®ã»ãã¥ãªãã£äºæ ã第åç« ã¾ã¨ãã - toriimiyukkiã®æ¥è¨
- http://d.hatena.ne.jp/toriimiyukki/20110910/1315666497
ã«ã¦ãã®å¾ã®é¡æ«ã«ã¤ãã¦ã¾ã¨ãããã¦ããã®ã§ããã:
ã§ãããå人çã«ã¯ä½ããã®è¬ç½ªã¨ä¸é±éã®èªå® 謹æ ãåãããã¨ã«ã 第ä¸ç« ã«ã¦ãæ°ç¾åãç³ãè¾¼ãã ã¤ãã³ãã®å人æ å ±(ååã使ãé»è©±çªå·)ãããã¾ããã èªå® 謹æ ã«é¢ãã¦ã¯ãèªåã§ãä¸ç·ãè¶ ããæãããããã人æ§ã®å人æ å ±ãè¦ãã®ã§ãããã¯ãªãã¨ãããã¨ãã¾ãã ãããã妿 ¡å´ã¨ãã¦ä¸åããããã¨ããã¨ããè¨èã¯ä½¿ããã ä»å¾ä¸åèå¼±æ§ãçªããªã¨ããæãã®ã¹ã¿ã³ã¹ãªãã§ãã ããã¡ã®å¦æ ¡ã¯ãã©ã¤ãã·ã¼ãã¼ã¯ãåå¾ãã¦ããã®ã§ãããããã¨ããã¦ã¯å°ãã®ã§ãã
ã¨ãããã¨ã§å¦æ ¡å´ã®å¯¾å¿ãã¾ã£ããã©ããã¨æãã®ã§ããã http://b.hatena.ne.jp/entry/d.hatena.ne.jp/toriimiyukki/20110910/1315666497 ããé²è¦§ã§ããã¯ã¦ãªããã¯ãã¼ã¯ã®ã³ã¡ã³ããè¦ãã«ããã®åé¡ãåã«å«ççãªåé¡ã¨ãã¦åãåã£ã¦ããåããå¤ãããã¾ãã確ãã«ãèå¼±æ§ãè¦ã¤ãã¦å ±åããã¨ãããã¨ã¯è©ä¾¡ãããã¹ãã§ããã©ã¤ãã·ã¼ãã¼ã¯ãã©ãããã¨è¨³ã®ããããªãè¨ã訳ã§éãããã¦ããªãã¨ã¯æãã¾ãããã ããã®æ¹ããã£ã¦ãããã¨ã¯æ³ã«æµè§¦ãããã¨ã§ããããã¯ãã³ã¡ã³ãã§ã»ã¨ãã©ããã«è§¦ãããã¦ããªãã©ããã䏿£ã¢ã¯ã»ã¹ããããªãçãªçºè¨ãè¦ãããï¼ç¾å¨ï¼ã®ã¯ãã£ããã©ããããã¨ãªãã§ããããããâ¦â¦ã
åãåå¼·ä¸ã®èº«ã§ããããã¾ãåãããªãã¨ã¯è¨ããããªãã®ã§ããããã¨ãåæã®èå¼±æ§æ¤æ»ã§ãã£ãã¨ãã¦ãæ³ãéµå®ãã¦ãã®ç¯å²ã§å®æ½ããã¨ããã®ã¯å½ããåã®ãã¨ãããªãããªã¨æãã¾ãï¼è£ãè¿ãã°æ³ãéµå®ããä¸ã§ã®æ¤æ»ã§ããã°æå¥ãè¨ãããçåãã¯ãªãããã§ï¼ããã®æ¹ãéæ³è¡çºã§ãããã¨ãèªèã®ä¸ã§ãã£ã¦ããã®ãã©ãããããã¨ãç¥ããªãã£ããã©ããã¯ãããã¾ããããããããããã«ãã¦ãå¨ãã®äººéãæãã¦ãããªããã°ãªããªããã¨ã§ããã¨ããã妿 ¡å´ã¯ãããããã¨ãã¡ããã¨æè²ã§ãã¦ããªãããã ããã¨ã³ããªã®ã³ã¡ã³ããããã¯ãã¼ã¯ã®ã³ã¡ã³ããè¦ã¦ãã¦ãã妿 ¡ã®å¯¾å¿ã«æ¤ã£ã¦è¦è½ã¨ãã¦ããã®ãåã«ï½¸ï¾ï½¯ï½¶ï½°ï½¶ï½ºï½²ï½²ã¨ããã価å¤è¦³ã§è³è³ãã¦ããã®ããããã¾ããããããããã¡ããã¨ããææãã»ã¨ãã©è¦å½ããã¾ããããããªããã¨ã ã¨æãã¾ããã
# ä»®ã«éæ³è¡çºã ã¨èªèããä¸ã§ããã°ãæ¸ãã¦ããã®ã ã¨ãããããã®ã¨ã³ããªã¯åã®å£®å¤§ãªãç¯ä»ã ã£ãã¨ãããã¨ã«ãªãããã§ããï¼ï¼ããªãã¨ãªãããã°ã SNS ã«ãããããããç¯ç½ªèªæ ¢äºä¾ï¼ãã¨ãã°æªæå¹´ã®é£²é èªæ ¢ï¼ã¨ããã«ç¾¤ãã人ãã¡ãã¨ããå³ã¨ä¼¼ããããªãã®ã«ãæãããã¾ããããã®ãããã®è©±ã¯èå³ããªãã®ã§ããã§ã¯è§¦ãã¾ããã
ã¨ãããã¨ã§ããã£ããä½ãéæ³è¡çºã«ããããããã¨ãããã¨ã®ææã¨ãåèã¾ã§ã«åã ã£ããã©ããããã¨ãããã¨ãæ¸ããã¦ãããã¾ããã
åã¯ç´ 人ãªã®ã§ããã®ææã«ãééããå«ã¾ãã¦ããããããããéã«æææ¼ãããããããããªãã®ã§ããããã®ã¨ã³ããªãå½è©²ã¨ã³ããªã®ä½è ã®æ¹ããèªè ã®æ¹ã«ã¨ã£ã¦ãä½ãèãããã£ããã«ã§ããªãã°ã¨é¡ã£ã¦ãã¾ãã