ã»ãã¥ãªãã£ã»ãã£ã³ãå ¨å½å¤§ä¼2016 éä¸è¬ç¾©
ã»ãã¥ãªãã£ã»ãã£ã³ãå ¨å½å¤§ä¼2016 éä¸è¬ç¾©
Linuxã¯ä¼æ¥ã®ãµã¼ãã¨ãã¦å©ç¨ããããã¨ãå¤ãã ãã®ãããLinuxã®ã»ãã¥ãªãã£å¯¾çã¯ã¨ã¦ãéè¦ãªãã¤ã³ãã ã ãã®ãã¼ã¸ã§ã¯Linuxã®ã»ãã¥ãªãã£ã®åºç¤å¯¾çã«ã¤ãã¦æ¦è¦ããç´¹ä»ãããå ¨ä½åããã£ããã¨ææ¡ããã«ã¯ã¡ããã©è¯ãå 容ã«ãªã£ã¦ããã ãããåèã«ãã¦é ããã°ã¨æãã Linuxã®ã»ãã¥ãªãã£å¯¾ç ãªã¼ãã³ã½ã¼ã¹ã¨ã»ãã¥ãªãã£ã«ã¤ã㦠ãªã¼ãã³ã½ã¼ã¹ã§å¤§ä¸å¤«ï¼ Linuxã¯ãªã¼ãã³ã½ã¼ã¹ã§éçºããã¦ãããã¤ã¾ãã½ã¼ã¹ã³ã¼ããå ¬éããã¦ãã訳ã ã ãã½ã¼ã¹ãå ¬éããã¦ãããªããæªæã®ããã¦ã¼ã¶ãå¼±ç¹ãè¦ã¤ããããã®ã§ã¯ï¼ã ã¨ããçåã¯ãã£ã¨ãã ãå®éã誰ããèå¼±æ§ãè¦ã¤ãã¦ããããå ±åããªããã°ããã®äººããç¥ããªãèå¼±æ§ãæ®ãã¨ãããã¨ã«ãªãã ã¾ããå¤ãã®äººãããããè¦æ±ã«å¯¾ãã¦ãå¤æ°ã®æ©è½ã追å ãããã¨ããããããã½ã¼ã¹ã³ã¼ããã©ãã©ãè¨ããã§ããããããªãã¨ãå¤æ©è½
apache ã nginx ã®è¨å®ããããã¨ãããã°ä»¥ä¸ã®æ§ãªè¡ãè¦ããã¨ããã人ãå¤ãã®ã§ã¯ãªãã§ããããã(â» ä¸è¨ã¯ nginx ã®è¨å®ãapache ã®å ´å㯠SSLCipherSuite ã§ãã) ssl_ciphers AES128-SHA:AES256-SHA:RC4-SHA:DES-CBC3-SHA:RC4-MD5; ãããæå·ã¹ã¤ã¼ããæå®ãã¦ããç®æã§ããããã¦ãã®é¨åãããã®ããããªãæååã®ç¾ åãªã®ã§ãããåã£ã¤ãã«ããã¦ä½ãæå®ããããããããããªãã®ã§ãã³ãããã¦ãã¾ã人ãå¤ãããããªãã§ãããããããããç§ãæ°å¹´åã«è¶£å³ã§ TLS 対å¿ã® Web ãµã¼ãã¹ãä½ã£ãæã¯ã³ããã§æ¸ã¾ãã¦ãã¾ããããã®æå·ã¹ã¤ã¼ãã¯ã以ä¸ã®ãã㪠OpenSSL ã®ã³ãã³ãã使ã£ã¦å¯¾å¿ãã¦ããä¸è¦§ãè¦ããã¨ãã§ãã¾ãã $ openssl ciphers -v AES128-SH
Nginxã§HTTPSï¼ã¼ãããå§ãã¦SSLã®è©ä¾¡ãA+ã«ããã¾ã§ Part 2 â è¨å®ãCiphersuiteãããã©ã¼ãã³ã¹ ä»æ¥ã®ã¤ã³ã¿ã¼ãããã®ä¸çã§ã¯ãä¸è¬çãªéçWebãµã¤ããå«ãã å ¨ã¦ã®Webãµã¤ã ã«ãå¼·åºã§å®å ¨ãªHTTPSã®ã»ããã¢ãããå¿ è¦ã¨ãªãã¾ãããã®è¨äºã¯ãNginxã»ãã¥ãªãã£ãã©ã®ããã«ã»ããã¢ããããã®ãã«é¢ããã·ãªã¼ãºã®ãã¼ã2ã§ãã ãã¼ã1 ã¯ãWebãµã¼ãã«æå¹ãªç½²å証ææ¸ãã»ããã¢ãããã話ã§çµäºãã¾ããããããããã«ã¯ãæé©ãªè¨å®ã¨ã¯è¨ãé£ããããã©ã«ãã®Nginxã®è¨å®ã使ç¨ãã¦ãã¾ããã ãã®è¨äºãèªã¿çµããã°ãSSL Labsã®ã¬ãã¼ãã§ãA+ã®è©ä¾¡ãç²å¾ã§ããå®å ¨ãªHTTPSã®è¨å®ãã§ãã¾ããããã ãã§ãªãã追å ã§ããã¤ãã®å¾®èª¿æ´ãè¡ããããã©ã¼ãã³ã¹ããã¦UXãåä¸ããã¦ããã¾ãã ããã«æ²è¼ããè¨è¿°ãã³ã¼ãã®æç²ã®ä»ã«ããããã«ä½¿
ããããã¨ååè«ã¯ãããã§ãããæ¨ä»ã®ã¢ããªã±ã¼ã·ã§ã³ã¯è¤éåããæ±ãæ å ±ã¯ããã»ã³ã·ãã£ãã«ãªããããã¦ããå¹ åºã使ãããããã«ãªã£ã¦ãã¾ãããã£ã¦ãå®å ¨ãªãã¢ããªã±ã¼ã·ã§ã³ãä½ãããã«å¿ è¦ãªç¥èã¯ã¾ãã¾ãå¢ããå¾åã«ããã¾ãã ããåãã£ã¦ãªã人ã¯ä»¥ä¸ã®ãã¨ã«ã¨ããããæ°ãã¤ãã¾ããã 1. ãªãã¹ãèªåã§ä½ããªã ããã¯æãéè¦ãªãã¨ã§ããæ¤ç´¢ãããä»äººã«èããèªåã§èããªããããã¯éè¦ã§ãã大æµã®åé¡ã¯ä»äººãä½ã£ã¦ããã解決çãé©ç¨ã§ãã¾ãã ä¾ãã°ã»ãã¥ã¢ãªååããã©ã¼ã ãä½ããã¨ã«ãã¾ããããæ°ãã¤ããã¹ããã¨ã¯ä»¥ä¸ã®ãã¨ãããã§ããããã éä¿¡å 容ã®ç¢ºèªç»é¢ã表示ããå ´åãã¦ã¼ã¶ã¼ã®å ¥åããå¤ã¯é©åã«ã¨ã¹ã±ã¼ãããããã« éä¿¡å 容ãã¢ããªã±ã¼ã·ã§ã³ã® DB ã«æ ¼ç´ããå ´åã«ã¯ SQL ã¤ã³ã¸ã§ã¯ã·ã§ã³ãé²ããªããã°ãªããªãã®ã§ãããªãã¢ãã¹ãã¼ãã¡ã³ããç¨ãã CSRF 対ç
ãã¤ã³ãã¯ä¸è¨ã®éãã§ãã X社ï¼ååï¼ã¯ã»ãã¥ãªãã£å¯¾çã«ã¤ãã¦ç¹ã«æ示ã¯ãã¦ããªãã£ã æå®³è³ åã«ã¤ãã¦åå¥å¥ç´ã«å®ããå¥ç´éé¡ã®ç¯å²å ã¨ããæå®³è³ å責任å¶éããã£ã å½åã·ã¹ãã ã¯ã«ã¼ã決æ¸ãå¤é¨å§è¨ãç´æ¥ã«ã¼ãæ å ±ãæ±ã£ã¦ããªãã£ã X社ããã«ã¼ãä¼ç¤¾æ¯ã®æ±ºæ¸éé¡ãç¥ããããã¨Y社ã«ä¾é ¼ããã¦ããã®çµæã«ã¼ãæ å ±ããã£ããDBã«ä¿åããä»æ§ã¨ãªã£ãï¼2010å¹´1æ29æ¥ï¼ X社ããã®åãåããã«å¯¾ãã¦Y社ã¯ãã«ã¼ãæ å ±ãä¿æããªãæ¹å¼ã«å¤æ´ãããã¨ãå¯è½ã§ããã®ã»ããå®å ¨ã¨ãªããè²»ç¨ã¯20ä¸åç¨åº¦ã§ããæ¨ãä¼ããï¼2010å¹´9æ27æ¥ï¼ãããã®å¾X社ã¯æ¹è¯ã®æ示ãããªãã£ã 以ä¸ã®èå¼±æ§ãã®ä»ãèªãããã ã·ã¹ãã 管çæ©è½ã®IDã¨ãã¹ã¯ã¼ãã admin/password ã§ãã£ã å人æ å ±ãè¨è¼ããããåãåãããã°ãã¡ã¤ã«ã®é²è¦§ãå¯è½ï¼ãã£ã¬ã¯ããªãªã¹ãã£ã³ã°ã¨æå³ããªããã¡ã¤
Hiromitsu Takagi @HiromitsuTakagi ããããããã¹ã¯ã¼ããã¨ã¯ä½ãããã¹ã¯ã¼ãã¨ã¯äººãè¦ãã¦ä½¿ããã®ã§ãããå¿ ç¶çã«è¤æ°ã®ãã°ã¤ã³ãµã¼ãã¹ã§åããã®ã使ããå¾ãã®ãåæã¨ãªããæ ã«ã管çè ããå©ç¨è ãã¹ã¯ã¼ããç¥ãå¾ãªãããæè¡ç対çããå©ç¨è ã«ã¯èªç±ã«ãã¹ã¯ã¼ãè¨å®ã§ããããã«ããã®ãå½ç¶ã§ãã£ãããããä»æ¥ã⦠2014-12-06 14:57:34 Hiromitsu Takagi @HiromitsuTakagi â¦ä»æ¥ãå¹¾ã¤ãã®ç®¡çè ãããã¹ã¯ã¼ãï¼åã¯ãã®å¼±ãããã·ã¥å¤ï¼ãæµåºããäºæ ãç¸æ¬¡ãããªã¹ãæ»æã横è¡ãããã¨ããããã°ã¤ã³ãµã¼ãã¹æ¯ã«ç°ãªããã¹ã¯ã¼ããä»ããã¨ããæè¦ãå¼·ã¾ã£ãã管çè ãå©ç¨è ã«å¯¾ãã¦ãå½ãµã¼ãã¹å°ç¨ã®ãã¹ã¯ã¼ããè¨å®ãã¦ãã ãããã¨æ示ããä¾ãåºã¦ããã⦠2014-12-06 15:01:26 Hiromitsu T
å æ¥ããµã¼ãã¼ã®ã»ãã¥ãªãã£è¨å®ããªã«ããã°ãããããããªããã¨ç¸è«ãããã¾ãã¦ã èªåãåå¿è ã®æã©ãã¾ã§ããã°ãããããããæå½ãããã ãã«ãã£ã¦æ²¼ã«å ¥ã£ã¦ããã®ãæãåºããªããèªé¯æ§ç¯ããã¨ãã®ã¡ã¢ãå ã«ã¾ã¨ãã¦ã¿ã¾ããã 注æ ã»ãã¥ãªãã£å¯¾çã¯ç¨éãå ´åãªã©ã«ãã£ã¦éãã¾ãã èªåã§ç解ããããã§èªå·±è²¬ä»»ã§ãããããã¾ãã 対象èªè Linuxã®ãµã¼ãã¼ã建ã¦æ £ãã¦ããªã人 Linuxã¯ããç¨åº¦ãããã人(èªåã§ããã±ã¼ã¸ãå ¥ãããããµã¼ãã¹ãæ¢ãããã§ãã) ã©ã¤ã³ããã âã¯å°å ¥ã®éè¦åº¦ã¨å°å ¥ã®å®¹æãããå人çåè¦ããã¤ããå¤ã§ãã 4ã¤ä»¥ä¸ã"æä½éãããã¨"ã ã¨æã£ã¦ãã ããã sshd
å æ¥ããµã¼ãã¼ã®ã»ãã¥ãªãã£è¨å®ããªã«ããã°ãããããããªããã¨ç¸è«ãããã¾ãã¦ã èªåãåå¿è ã®æã©ãã¾ã§ããã°ãããããããæå½ãããã ãã«ãã£ã¦æ²¼ã«å ¥ã£ã¦ããã®ãæãåºããªããèªé¯æ§ç¯ããã¨ãã®ã¡ã¢ãå ã«ã¾ã¨ãã¦ã¿ã¾ããã 注æ ã»ãã¥ãªãã£å¯¾çã¯ç¨éãå ´åãªã©ã«ãã£ã¦éãã¾ãã èªåã§ç解ããããã§èªå·±è²¬ä»»ã§ãããããã¾ãã 対象èªè Linuxã®ãµã¼ãã¼ã建ã¦æ £ãã¦ããªã人 Linuxã¯ããç¨åº¦ãããã人(èªåã§ããã±ã¼ã¸ãå ¥ãããããµã¼ãã¹ãæ¢ãããã§ãã) ã©ã¤ã³ããã âã¯å°å ¥ã®éè¦åº¦ã¨å°å ¥ã®å®¹æãããå人çåè¦ããã¤ããå¤ã§ãã 4ã¤ä»¥ä¸ã"æä½éãããã¨"ã ã¨æã£ã¦ãã ããã sshd
2013-12-07 ãWindowsãç§éã§ãã±ãããçè´ããæ¡ä»¶[ARP] ãã¿ ç§éã§ãã±ããã¯çè´ã§ãã 以ä¸ã®2ã¤ã®æé ã§åä¸LANå ã«ãã誰ãã®PCãã©ãã¨ä½ãéä¿¡ãã¦ããã(ãã¨ãã°ãµã¤ãURLã¨ã)ãç¥ããã¨ãã§ãã¾ãã ARPã¹ãã¼ãã£ã³ã°ãã èªåã®PCãéä¿¡ãããã±ãããè¦ã ã©ã£ã¡ãã¡ãã£ã¡ãã£ç°¡åãªã®ã§ç§éã§ã§ãã¾ããä»ã©ãããããã¯ãªãã¯ãã¦ããã°ã§ãã¦ãã¾ãã¾ããã¤ã¾ãå°å¦çã§ãçè´ãã§ãã¦ãã¾ãã®ã§ãããã¼ãPCã§ãã¹ããã§ãã¿ãã¬ããã§ãçè´ããã¡ããã¾ãã ARPã¹ãã¼ãã£ã³ã°ãã æ©éãã£ã¦ããã¾ããããããã«ãªããªã解説ã¯é£ã°ãã¦ããæ¹ãè¦ã¦ãã ããã ARPã¹ãã¼ãã£ã³ã°ã«ã¤ã㦠ããã¼ã解説ã§ããè¦ããªãæ¹ã¯é£ã°ãã¦ããæ¹ãè¦ã¦ãã ããã æ®æ®µã®éä¿¡ ã¿ã¼ã²ããããå¼ãã¨ãã¾ããããå¼ã¯ãã¤ããããªæãã§ãã³ãã³åç»ã¨ãLOLã¨ããã£ã¦ãã¨ãã¾ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}