ç²åã¯æ¬å½ã«å°ããªç©ä½ã¨ãã¦ãããã«ãããã®ããæç©ºã¯ãç©ä½ãå ¥ã£ã¦ããåºå®ããã容å¨ãªã®ããå éãæéã§ãããã¨ã¯ãåãªãæ°å¤çãªç©ç宿°ãªã®ããããã¨ããã©ã®åºæ¥äºãã©ã®åºæ¥äºã¸å½±é¿ã§ããããå®ãããä¸çã®å ææ§é ã ⦠ç¶ããèªã
ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼ 仿¥ã¯CSRFèå¼±æ§ã®ã¡ãã£ã¨ãã話ã§ãï¼ ãã®CSRFã£ã¦ãªã«ãã£ã¦ããã¨ã ãµã¼ãã¼ã¸ã®ãªã¯ã¨ã¹ããã誰ãã«åæã«éããããã£ã¦ããã»ãã¥ãªãã£ããã¿ã®æ»æææ³ã®ã²ã¨ã¤ã ããããããä¾ã ã¨ã HTMLã®ç»åã¿ã°ã以ä¸ã®ããã«ãããã¼ã¸ã誰ãã«æããã <img src="ä½ã SNSã®è¶³è·¡.php" width="1" height="1"> ããããã¨ããã®ãã¼ã¸ããè¦ã人ããä½ã SNSã®è¶³è·¡.phpã«ã¢ã¯ã»ã¹ãããã¨ã«ãªãã â»è©³ããã¯ãã¡ãã®ãã³ã¬ã§ â ï¼»ã¯ã¾ã¡ã¡ããã®ã»ãã¥ãªãã£è¬åº§ï¼½ãããããã®èå¼±ãªã¨ããâ¦ï¼ ï¼ ç¬¬2å ãã¼ãã¼ãµã£ã¦ä½ã§ããï¼ CSRFã£ã¦ãããªé¢¨ã«ã ããã°ã¤ã³æ¸ã¿ã®äººã«ä½ãæä½ããããã£ã¦ã¤ã¡ã¼ã¸ãå¼·ãã¦ã 対çããå´ãã¾ãããæ¢ã«ãã°ã¤ã³æ¸ã¿ã®äººãå®ãããããªèããå¼·ããã ããã ä¾ãã°ãåæã«æ¥è¨ã«æç¨¿ãããªãããã«å¯¾
[Mac] Macã®ã»ãã¥ãªãã£ã½ããã¾ã¨ããã20æ¬ã1.Norton AntiVirusï¼ã¤ã³ã¿ã¼ãããã»ãã¥ãªã㣠http://jp.norton.com/products/charts/comparison.jsp?pcid=ma735 ï¼å¿æ³å¸ãLv=14,xxx ç¶ããèªãâ¦
ã¯ããã« Linux ã®ã»ãã¥ãªãã£è¨å®ã£ã¦ãªããªãã¾ã¨ã¾ã£ããã®ããªãã®ã§ãããããªãµã¤ããåèã«ããªããè¨å®ãã¾ã¨ãã¦ã¿ã¾ãããæ³å®ã¯Web ãµã¼ãã¼ã§ã使ç¨ãã¦ãã Linux 㯠CentOS 6.2 ã§ãã è¨å®å 容ã¯ä»¥ä¸ã®ããã«ãªãã¾ãã å ¨ããã±ã¼ã¸ã®ã¢ãããã¼ã ãªã¢ã¼ãããã® root ãã°ã¤ã³ãç¡å¹ã«ãã å ¬é鵿巿¹å¼ã使ç¨ãã SSH ãã°ã¤ã³è¨å® iptables è¨å® SSH ãã¼ãçªå·ã®å¤æ´ ä¸è¦ãªãµã¼ãã¹ã忢 ãã°ç£è¦è¨å® ãã¡ã¤ã«æ¹ããæ¤ç¥ãã¼ã«è¨å® ã¦ã£ã«ã¹å¯¾çã½ããè¨å® Apache ã®è¨å® å ¨ããã±ã¼ã¸ã®ã¢ãããã¼ã æåã«ä»¥ä¸ã®ã³ãã³ããå®è¡ãã¦ãå ¨ããã±ã¼ã¸ãææ°ã®ç¶æ ã«ããã # yum ây update å¾ã¯èå¼±æ§ãçºè¦ãããæãã¾ãã¯å®æçã«ããã±ã¼ã¸ã®ã¢ãããã¼ããè¡ãã ãªã¢ã¼ãããã® root ãã°ã¤ã³ãç¡å¹ã«ãã ãªã¢ã¼ãããã¡
ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼ Webããã°ã©ãã³ã°ãã¦ã¾ããï¼ ãããPHPã¯ã»ãã¥ãªãã£ããã¡ãã¨ãè¨ããã¦ãããã ã§ãããã£ã¦ãã¹ã¤ã«PHPãæªãããããªãã¦ã ãã¶ããã»ãã¥ãªãã£ã¨ãããã¾ã ããããããªã人ãå¤ãã ããªããããªãããªã ããã°ã£ã¦åå¼·ãããã¨æã£ã¦ãããªãã ãé£ããçå±ã並ãã§ãããããããâ¦ã ãªã®ã§ä»æ¥ã¯ãã»ãã¥ãªãã£å¯¾çã«ã¤ãã¦ã ãããã ããã£ã¨ãã°ãããã¨å®å ¨ã«ãªãããã£ã¦ãã¨ããåå¿è ããã«ã大éæã«æ¸ãã¦ã¿ã¾ãï¼ çå±ãããããªãã¦ããæåã¯ã³ããã§ãã ãªã«ããããªãããããã£ãã»ãããã£ã¨ãã·ã«ãªãï¼ 1. XSS対ç åçãªãã®ã表示ããã¨ããå ¨é¨ã¨ã¹ã±ã¼ãããã°okã§ãï¼ (NG) ããªãã®åå㯠<?= $name ?> ã§ããï¼ â (OK) ããªãã®åå㯠<?= htmlspecialchars($name, ENT_QUOTES) ?>
ããã«ã¼ã¯ãããã¦çã¾ããâ¦ãããã³ã°ã®æ´å² ãããã³ã°ãããã«ã¼ã¨ããè¨èã使ãããããã«ãªã£ã¦ããªãçµã¡ã¾ããããæªã å®ç¾©ããã¦ããæ¬æ¥ã®æå³ï¼æ·±ãæè¡çç¥èãæã¤ãªã©ï¼ã ãã§ã¯ãªããç¹ã«æ¥æ¬ã§ã¯ã¯ã©ãã«ã¼ã«ç¸å½ãã䏿£å©ç¨è ãç¯ç½ªè ã®æå³ã§ä½¿ããããã¨ãå¤ãããã§ãã ããã§ã¯ç¯ç½ªã®æç¡ãåãããæè¡çã«ã»ãã¥ãªãã£ããããããã³ã³ãã¥ã¼ã¿ã¼ã«ä¾µå ¥ããæå³ãå«ãã ãããã³ã°ã®æ´å²ããç´¹ä»ãã¾ãã 1960年代 åãã¦ã³ã³ãã¥ã¼ã¿ã¼ããããã³ã°ãããã®ã¯ããµãã¥ã¼ã»ããå·¥ç§å¤§å¦ï¼MITï¼ããã¨ãã¨ã¯é鿍¡åã®ã¹ãã¼ãããããæ¹é ã®ãã¨ãhackã¨å¼ã°ãã¦ãã¦ãããããã½ããã¦ã§ã¢æ¹é ï¼ã³ã³ãã¥ã¼ã¿ã®å¦çé度ãåä¸ããç®çï¼ã®å¼ã³åã¨ãã¦ã使ãããããã«ãªãã¾ããããã®å¹´ä»£ã§ã¯ã¾ã ãããã³ã°ã¨ããããã¯ããªã¼ãã³ã°ã¨ãããé»è©±åç·ç¶²ã®ä¸æ£ä½¿ç¨ï¼é»è©±ã®ã¿ãæãï¼ã主ã ã£ãããã§ãã 197
æ±äº¬ã©ã¼ã¡ã³ã·ã§ã¼2011 ããã¦ã¼ã¼ã¼ï¼ã¿ãªããããã«ã¡ã¯ãnakamura ã§ãã 仿¥ã¯ããã°ã©ãã ã£ãããµã¼ã管çè ã ã£ããï¼ãããã¯ãã®ä¸¡æ¹ã ã£ããï¼ããæ¹ã«ãå§ãããããµã¤ãã¨ãã¼ã«ãããã¤ããç´¹ä»ãã¾ããç´°ããèå¼±æ§ã®ãã§ãã¯çã©ããã¦ãæéãæãããã®ãå¤ãã§ãããä»åãç´¹ä»ãããã¼ã«ããã¾ã使ãã¨ãã®è¾ºãã ãã¶å¹çããã§ããã¨æãã¾ããï¼ WEB ã¢ããªã±ã¼ã·ã§ã³é¢é£ XSS Me XSS Me :: Add-ons for Firefox XSS ã®ãã¹ããããç¨åº¦èªååãã¦ããã Firefox ã®ã¢ããªã³ã§ããæ®å¿µãªãã Firefox3.0.* ç³»ã®é ã«éçºãæ¢ã¾ã£ã¦ãã¾ã£ã¦ããããã§ãããåã®ç°å¢ã§ã¯ install.rdf ã®æ¸ãæãã§åé¡ãªãåä½ãã¦ãã¾ããï¼Windows7 64bit + Firefox7.0.1ï¼ SQL Inject Me SQL I
æ´æ°: 2011å¹´7æ9æ¥23æ0åé ã¨ããã·ã¹ãã ã§å¾³ä¸¸æ¬ã®ã¹ãã¬ããã³ã°ãæ¡ç¨ãããã¨ã«ããã¨ãã話ãããã¾ãããããã®å®è£ ãä½³å¢ã«å ¥ã£ã¦ãã¾ãããç§ã¯æç¤ºã ãåºãã¦ãå®è£ ã¯ãä»»ãâ¦â¦ã¨æã£ã¦ããã®ã§ãããåºæ¬çãªé¨åãä½ã£ã¦ããã£ãã¨ããã§ããã³ã¿ãããããç§ãå¼ãç¶ãå½¢ã§å®éã«ã³ã¼ããæ¸ããã¨ã«ãªãã¾ããã åºæ¬çã«ã¯å¾³ä¸¸æ¬ (www.amazon.co.jp)ã®ãªã¹ã¹ã¡ã©ããã®å®è£ ã«ããã¨ããæ¹éãªã®ã§ãããå®éã«ã³ã¼ããæ¸ãã¦ã¿ãã¨ãããããã¨æ°ã«ãªã£ããè¿·ã£ããããäºãåºã¦ãã¾ããããã®ããããç°¡åã«ã¡ã¢ãã¦ããã¾ãã â»ã¡ãªã¿ã«ããã®ã·ã¹ãã ã¯Ruby1.9.2 + Ruby on Rails3ã§ã®å®è£ ãªã®ã§ãPHPã®ã³ã¼ããµã³ãã«ããã®ã¾ã¾ä½¿ã£ã¦ããããã§ã¯ããã¾ããã ã¹ãã¬ããåæ°ãã©ã決ããã®ã徳丸æ¬327ãã¼ã¸ã«ããã³ã¼ãä¾ãåèã«ãã¦å®è£ ãã¢ããªã±ã¼ã·ã§ã³ãã¨
æ¯å¹´æä¾ã®è¨ºæåæºåã¨ãã¦éçºè åãã«ããåå¿è Webã¢ããªã±ã¼ã·ã§ã³éçºè ããã§ãã¯ãã¹ãæ å ±æºããéãã¦ããã®ã§ãçããã«ããç´¹ä»ãä»ã«è¿½å ããæ¹ãè¯ãæ å ±æºããã£ãå ´åã¯ãææããã ããã¨å©ããã¾ãã ä¸ããéè¦ãªé ãâ ãã¨ããããèªãã©ããã®å¿ é ãå¿ é ã®ãã¤ã³ãã¯ãçæéã§å¤§éæã«ç¶²ç¾ çã«ãã¤ã³ããæ´çããã¦ãããã®ã 徳丸æ¬ãå¿ é ã«å ¥ãããè¿·ã£ããã©ããã®åãã¯ãä¸äººã¯èªããªãã®ã§ãä¸ä½ã©ã³ã¯ã ãã©å¿ é ããã¯ã¯ãããã â Webãµã¤ãæ§ç¯ å®å ¨ãªã¦ã§ããµã¤ãã®ä½ãæ¹ æ¹è¨ç¬¬5ç http://www.ipa.go.jp/security/vuln/websecurity.html æºå¸¯ã¦ã§ããµã¤ãã®å®è£ æ¹æ³ã追å ã»ãã¥ãªãã£å®è£ ãã§ãã¯ãªã¹ãï¼Excelå½¢å¼ã33KBï¼ å®å ¨ãªSQLã®å¼ã³åºãæ¹ï¼å ¨40ãã¼ã¸ã714KBï¼ â çºæ³¨ä»æ§ çºæ³¨è ã®ããã®Webã·ã¹ãã ï¼Webã¢ã
ãã°ãã°ããã¹ã¯ã¼ãã¯âæ¥ãã¨ã«å¤æ´ãã¾ããããã¨ããããããã©ãããã§æ¬å½ã«ã¯ã©ãã¯ã®å±éºæ§ã¯æ¸ãã®ï¼ ãããã¬ã¼ã·ã§ã³ãã¹ãã®ç¾å ´ããæ¤è¨¼ãã¾ãï¼ç·¨éé¨ï¼ â»ãæ³¨æ æ¬è¨äºã«æ²è¼ããè¡çºãèªèº«ã®ç®¡çä¸ã«ãªããããã¯ã¼ã¯ã»ã³ã³ãã¥ã¼ã¿ã«è¡ã£ãå ´åã¯ãæ»æè¡çºã¨å¤æãããå ´åããããææªã®å ´åãæ³çæªç½®ãåãããå¯è½æ§ãããã¾ããã¾ããä»åç´¹ä»ãããã¼ã«ã®ä¸ã«ã¯ãæ»æè¡çºã«å©ç¨ãããã¨ãã観ç¹ãããã¢ã³ãã¦ã¤ã«ã¹ã½ããã«ã¦ã¤ã«ã¹ã¨ãã¦æ¤åºããããã®ãåå¨ãã¾ãããã®ãããªèª¿æ»ãè¡ãå ´åã¯ãããããã許å¯ãåã£ãããã§ãèªèº«ã®ç®¡çä¸ã«ãããããã¯ã¼ã¯ããµã¼ãã«å¯¾ãã¦ã®ã¿è¡ã£ã¦ãã ãããã¾ããæ¬è¨äºãå©ç¨ããè¡çºã«ããåé¡ã«é¢ãã¾ãã¦ã¯ãçè ããã³ã¢ã¤ãã£ã¡ãã£ã¢æ ªå¼ä¼ç¤¾ã¯ä¸å責任ãè² ãããã¾ãããäºæ¿ãã ããã ä»åã¯ä¹ ãã¶ãã«ããããã¬ã¼ã·ã§ã³ãã¹ãã®ç¾å ´ã®è©±ããå§ãããã ãããã¬ã¼ã·ã§
以ä¸ã¯ãWEBããã°ã©ãã¼ç¨ã®WEBèå¼±æ§ã®åºç¤ç¥èã®ä¸è¦§ã§ãã WEBããã°ã©ãã¼ã®äººã¯ãããèªãã°WEBèå¼±æ§ã®åºç¤ããã¹ã¿ã¼ãã¦WEBããã°ã©ã ãæ¸ããã¨ãã§ããããã«ãªã£ã¦ããããã§ãã ã¾ããWEBèå¼±æ§ã®ç°¡æãªãã¡ã¬ã³ã¹ã¨ãã¦ãå°ãå©ç¨ã§ããããããã¾ããã WEBã¢ããªã±ã¼ã·ã§ã³ãéçºããã«ã¯ãéçºè¦ä»¶æ¸ãããã°ã©ã 仿§æ¸éãã«éçºããã°è¯ãã¨ããããã«ã¯ããã¾ããã ãããWEBèå¼±æ§ãçãæªæã®ã¦ã¼ã¶ã«ã対å¦ããªãã¨ãããªãã®ã§ãã ä»åãWEBã¢ããªã±ã¼ã·ã§ã³ãéçºã«ããã£ã¦ã®WEBèå¼±æ§ãã以ä¸ã®ä¸è¦§ã«ã¾ã¨ãã¦ã¿ã¾ããã ãã®ã¾ã¨ããWEBã¢ããªã±ã¼ã·ã§ã³éçºã®åèã«ãªãã°å¹¸ãã§ãã ã¤ã³ã¸ã§ã¯ã·ã§ã³ ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã° ã»ãã·ã§ã³ã»ãã¤ã¸ã£ã㯠ã¢ã¯ã»ã¹å¶å¾¡ãèªå¯å¶å¾¡ã®æ¬ è½ ãã£ã¬ã¯ããªã»ãã©ãã¼ãµã«(Directory Traversal) CSRFï¼
ããªãããªãã ãã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã EC-Council æ å ±ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢è²æãã¬ã¼ãã³ã°ã³ã¼ã¹ã "ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢" ã«! ã...
2025å¹´å¤ã»æ è¡ã«çã¦è¡ã£ããã®æã£ã¦è¡ã£ããã®ï¼åå¤å±ãä¼å¢ä¸æ³äºæ¥ï¼ æ¯å¹´ãæ è¡ã«ä½ãæã£ã¦è¡ã£ãã®ãå¿ãã¦ãã¾ããæ è¡ã®ãããã³ã°ã¯è¦æã ããããããä½ãçã¦è¡ã£ããèªåãå¿«é©ã§æ¥½ããã®ãï¼ãããããªããããããããå¤ã®æ è¡ãªãå°æ´ã ãæ±ã¨æãã§ã©ãã«ããªãããã«ãªãããªã®ã§ãä¸å¿æ¸ãã¦ãããã¨ã«ãããæ¥å¹´ç§ãæ è¡â¦
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}