UNIX/Linux ã®é¨å± ã«ãbash ã®å é¨ã³ãã³ã select ã³ãã³ã ã追å ãã¾ãããã¡ãã¥ã¼å½¢å¼ã®é¸æè¢ãæç¤ºããã¦ã¼ã¶ã«é¸ã°ãããã¨ãã§ããã³ãã³ãã§ãã
UNIX/Linux ã®é¨å± ã«ãbash ã®å é¨ã³ãã³ã select ã³ãã³ã ã追å ãã¾ãããã¡ãã¥ã¼å½¢å¼ã®é¸æè¢ãæç¤ºããã¦ã¼ã¶ã«é¸ã°ãããã¨ãã§ããã³ãã³ãã§ãã
2014/09/26ãã³ã¼ã¹ï¼å ç¥ãã£ã¦ã ãå ç¥ãã£ã¦ããè¨äºã¯ãããã¨ã¼ã¸ã§ã³ãæ§ããã°[netagent-blog.jp]ã«æ²è¼ããã¦ããè¨äºã§ãããç¾å¨ãããã¨ã¼ã¸ã§ã³ãã«å¨ç±ãã¦ããªãã©ã¤ã¿ã¼ã®è¨äºãå«ã¿ã¾ãã bashã«ãããèå¼±æ§ãShellshockãã«ã¤ã㦠LinuxãMac OS Xãªã©ã®UNIXç³»OSã§åºã使ç¨ããã¦ããbashã«è¦ã¤ãã£ãèå¼±æ§(Shellshockã¨å¼ã°ãã¦ãã¾ã)ãå æ¥ãã話é¡ã«ãªã£ã¦ãã¾ãã å¼ç¤¾ã§ããã®bashã®èå¼±æ§ã«ã¤ãã¦èª¿æ»ãè¡ãã¾ããã â æ¦è¦ ç°å¢å¤æ°ã«ç¹å®ã®æååãè¨å®ããã ãã§ãã®ç°å¢å¤æ°å ã®æååãã·ã§ã«ã颿°ã¨ãã¦å®è¡ãã¦ãã¾ãã¾ãã ã·ã§ã«ãéãã¦ã³ãã³ãçãå®è¡ããå¹ åºãç°å¢ã§å½±é¿ãããã¾ãããç¹ã«é¡èã«å½±é¿ãåããã®ã¯CGIçã®Webã¢ããªã±ã¼ã·ã§ã³ç°å¢ã§ãã CGIãã¯ããã¨ããWebã¢ããªã±ã¼ã·ã§ã³ã§ã¯Webãã©
ç°å¢å¤æ°ã«ä»è¾¼ã¾ããã³ã¼ããå®è¡ãã¦ãã¾ãBASHã®èå¼±æ§ã CGIã¹ã¯ãªããã«å½±é¿ãä¸ããã試ãã¦ã¿ããçµæã¯æ²æ¨ãªæãã« Tweet 2014å¹´9æ25æ¥ å¶ç°å¤§è²´ ãã®è¨äºã¯2014å¹´ã®ãã®ã§ã æãã Bash specially-crafted environment variables code injection attack ãªããã®ã§é¨ãã«ãªã£ã¦ããã®ã§ããã£ããæå ã® Apacheã§è©¦ãã¦ã¿ã¾ããã /hoge.cgiã¨ããURIã§å®è¡ãããããã«ãä¸è¡ã®ã¡ãã»ã¼ã¸ãåºåããã ãã® CGIã¹ã¯ãªãããè¨ç½®ãã¾ãããã£ããããªãã®å ¥åãã¯ã©ã¤ã¢ã³ãå´ããåãä»ãã¦ããªãããå±éºã®ããããããªãè¦ãã¾ãã #!/bin/sh echo "Content-type: text/plain" echo echo "Hi! I'm an ordinary CGI script w
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}