ãµããªã¼ Webãµã¤ãã®å®å ¨æ§ã¯ããµã¤ãã¼æ»æã®çããè¦æãæ´å¯åã«ããã£ã¦ãã¾ããLoggolï¼ãã´ã«ï¼ã¯ãWebã¢ã¯ã»ã¹ãã°ãèªåçã«è§£æããé ãããæ»æã®è¶³è·¡ãçºè¦ãã¾ããããªãã®ãµã¤ãã¯ãã¤ã誰ã«ãã©ã®ããã«æ»æããã¦ããã®ã§ããããã èª²é¡ Webãµã¤ãã®ã¢ã¯ã»ã¹ãã°ã«ã¯ãæ§ã ãªã»ãã¥ãªãã£çãªæ å ±ãå«ã¾ãã¦ãã¾ããããããªããããããã®ãã°ãæ£ããåæããã«æ¾ç½®ãã¦ããã±ã¼ã¹ãå¤ãè¦åãããã¾ãããã®çµæãæªç¥ã®è å¨ããµã¤ãã¼æ»æã®å åãè¦è½ã¨ãããå¯è½æ§ããããWebãµã¤ãã®ã»ãã¥ãªãã£ã確ä¿ãããã¨ãé£ãããªã£ã¦ãã¾ããã¾ããåæãè¡ã£ã¦ããã·ã¼ã³ã§ããWebã®ã¢ã¯ã»ã¹ãã°ç¹æã®å§åçãªéã®åã«ãä½æ¥ã追ãã¤ããªãå ´åãããã§ããããLoggolã¯ãããã課é¡ã«ã¢ããã¼ãããWebã¢ã¯ã»ã¹ãã°ã®ã»ãã¥ãªãã£åæãæ軽ã«è¡ãããã®ã½ãªã¥ã¼ã·ã§ã³ãæä¾ãã¾ãã ãµã¼ãã¹å 容紹ä»
23æ°åæè¡ç ä¿®ã§å®æ½ããã»ãã¥ãªãã£ç ä¿®ã®è¬ç¾©è³æã§ãã è³æã®å©ç¨ã«ã¤ãã¦ å ¬éãã¦ããè³æã¯åå¼·ä¼ãä¼æ¥ã®ç ä¿®ãªã©ã§èªç±ã«ãå©ç¨é ãã¦å¤§ä¸å¤«ã§ããã以ä¸ã®å½¢ã§ã®å©ç¨ã ããé æ ®ãã ããã ã»åè¬è ããåå è²»ãææ¥æãªã©ãéããå½¢ã§ã®å©ç¨ï¼ä¼å ´è²»ã飲é£è²»ãªã©â¦
ã¯ãã㫠対象ã¤ãã³ã èªã¿æ¹ã使ãæ¹ Remote Code Execution(RCE) 親ãã£ã¬ã¯ããªæå®ã«ããopen_basedirã®ãã¤ãã¹ PHP-FPMã®TCPã½ã±ããæ¥ç¶ã«ããopen_basedirã¨disable_functionsã®ãã¤ãã¹ Javaã®Runtime.execã§ã·ã§ã«ãå®è¡ Cross-Site Scripting(XSS) nginxç°å¢ã§HTTPã¹ãã¼ã¿ã¹ã³ã¼ããæä½ã§ããå ´åã«CSPãããã¼ãç¡å¹å Googleã®ClosureLibraryãµãã¿ã¤ã¶ã¼ã®XSSèå¼±æ§ Webã®Proxyæ©è½ãä»ããService Workerã®ç»é² æ¬å¼§ã使ããªãXSS /è¨å·ã使ç¨ããã«é·ç§»å URLãæå® SOME(Same Origin Method Execution)ãå©ç¨ãã¦document.writeãé 次å®è¡ SQL Injection MySQ
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}