(Last Updated On: 2018å¹´8æ4æ¥)IPAã¯ãå®å ¨ãªSQLã®å¼ã³åºãæ¹ãï¼PDFï¼ã以ä¸ã®URLããå ¬éãã¦ãã¾ãã http://www.ipa.go.jp/security/vuln/websecurity.html ãå®å ¨ãªSQLã®å¼ã³åºãæ¹ãã¯å±éºã§ãããã¨ããã¨ã³ããªãæ¸ãããã¨æããå 容ã確èªããã¨ããã§ãããã¾ããã§ããã è¨æ£ï¼ãã¤ãã¿ã¼ã§å¾³ä¸¸æ°ã«ç¢ºèªããã¨ããã徳丸æ°ãã¨ã¹ã±ã¼ããå«ããSQLã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾çãå¿ è¦ã§ããã¨èãããã¦ããããã¨ã確èªãã¾ããã徳丸æ°ã«ã¯ã»ãã¥ãªãã£å°éå®¶ã¨ãã¦å¤§å¤ä¸åèªãªè¨è¿°ã§ãã£ãäºãè¨æ£ããæ·±ããè©«ã³ãããã¾ããå 容ã«ã¤ãã¦ã®ä¿®æ£ã¯ãèå¥åã¨ã¹ã±ã¼ãã«ã¤ãã¦ããã°ã«æ¸ãã¨ã®äºã§ããã®ã§ããã°ã®å 容ã確èªãã¦ããä¿®æ£ãã¾ãã å¥åã®ãå®å ¨ãªSQLã®å¼ã³åºãæ¹ãã¯åºæ¬ä¸ã®åºæ¬ã§ãããæ£ç¢ºãªããã¹ãã®çµã¿ç«ã¦ãã«ããã»
2ï¼ å ´æï¼ ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ã15 éãä¼è°å®¤ 3ï¼ ç®çï¼ æ¬ã»ããã¼ã§ã¯ã製åã®å質åä¸ã«ã¤ãªããã»ãã¥ãªãã£ãã¹ãããã¡ã¸ã³ã°ããç¥ã£ã¦ããã ããã¨ãç®çã¨ã㦠ãã¾ãã 製åéçºã«ããã¦ããã¡ã¸ã³ã°ããæ´»ç¨ããã¨ããã°ãèå¼±æ§ãçºè¦ã§ããä¿®æ£ãããã¨ã«ãããå質åä¸ãè¦è¾¼ã ã¾ããããããããã¡ã¸ã³ã°ããæ´»ç¨ãã¦ãã伿¥ã¯å°æ°ã§ããããã§ãå¤ãã®æ¹ã«ããã¡ã¸ã³ã°ããç¥ã£ã¦ããã ã ãããã»ããã¼ãéå¬ãã¾ãã å¤ãã®æ¹ããã®åå ãç³è¾¼ããå¾ ã¡ãã¦ããã¾ãã 4ï¼ ããã°ã©ã ï¼ï¼ä»®ï¼â» ãã¡ã¸ã³ã°ã®æ¦è¦ã製åéçºã«ãããæ´»ç¨ ãã¡ã¸ã³ã°ãã¼ã«ã®ä½¿ãæ¹ ã¾ã¨ãã質çå¿çã»ã¢ã³ã±ã¼ã â» ããã°ã©ã ã¿ã¤ãã«ã¯å¤æ´ããå¯è½æ§ãããã¾ãã 5ï¼ è¬å¸«ï¼ ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ãæè¡æ¬é¨ ã»ãã¥ãªãã£ã»ã³ã¿ã¼ è·å¡ 6ï¼ å®å¡ï¼ 30 å (å çé ãå®å¡ã«éãæ¬¡ç¬¬ãç³ãè¾¼ã¿
é嬿 å ± IPA/SECã2013å¹´3æã«å ¬éãããã¢ã¸ã£ã¤ã«åéçºã«ããããã©ã¯ãã£ã¹æ´»ç¨ãªãã¡ã¬ã³ã¹ã¬ã¤ããã«ã¤ãã¦ããã®å å®¹ã¨æ´»ç¨æ¹æ³ã解説ãã¾ããåã¬ã¤ãã¯æ¥æ¬ã§å®éã«ã¢ã¸ã£ã¤ã«éçºã«åãçµãã§ãã伿¥ã§è¡ããã¦ããæ´»åå 容ãç¶²ç¾ çã«åãã¾ã¨ãããã®ã§ãã IPA/SECã§ã¯éå»4å¹´éã«ããã£ã¦ã¢ã¸ã£ã¤ã«éçºã«é¢ããèª¿æ»æ¤è¨ã«åãçµãã§ãã¦ãããæãå½ã«ããããã®å°å ¥çã¯æ¡å¤§ãã¦ãã¾ããããããã»ããã¼ã§ã®ã¢ã³ã±ã¼ãã«ããã°ãã¢ã¸ã£ã¤ã«éçºãå°å ¥ãããã¨èãã¦ãããå®ç¾ãã¦ããªãã¨ããåçãç¾æç¹ã§ãããªãã®å²åãå ãã¦ãã¾ããæ¬ã»ããã¼ã¯ããã®ãããªæ¹ã ã®ããã«ãã¢ã¸ã£ã¤ã«éçºãå®éã«ã©ã®ããã«é²ããã°ãããã«ã¤ãã¦å ·ä½çã«èª¬æãã¾ãã â»å½æ¥ã¯ãã¢ã¸ã£ã¤ã«åéçºã«ããããã©ã¯ãã£ã¹æ´»ç¨ãªãã¡ã¬ã³ã¹ã¬ã¤ããããã¦ã³ãã¼ããã¦ãæåä¸ããã¾ããããé¡ããã¾ãã è¬æ¼è³æãå ¬éãã¾ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}