If you're using the HTTP protocol in everday Internet use you are usually only using two of its methods: GET and POST. However HTTP has a number of other methods, so I wondered what you can do with them and if there are any vulnerabilities. One HTTP method is called OPTIONS. It simply allows asking a server which other HTTP methods it supports. The server answers with the "Allow" header and gives
[L]ã¨æ¸ãã¨ãRewriteã¯æ¢ã«çµäºãã¦ãã¾ãã®ã§ããã®å¾ãªã«æ¸ãã¦ãå¹ããªãããã§ãã RewriteCond ã§å度å®ç¾©ããªããã°ãæ¡ä»¶ãªãã¨ãªãã¾ãã åºæ¬ã®é¨åããã¡ãã¨ã¿ãã®ã¯éè¦ã§ãã \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\ [L] last(last rule) Rewriteæ©è½ã«ããURLå¤æãçµäºãã¾ãã \\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\\
第5åãããããã¯ã«ã³ãã¡ã¬ã³ã¹ãã¤ã³ãã©ã¨ã³ã¸ãã¢å¤§ç¹éã ã§çºè¡¨ããè³æã§ã http://pepabo.connpass.com/event/30348/
æ¦è¦ æ¬ã¢ã¸ã¥ã¼ã«ã«ã¯ mod_proxy ãå¿ è¦ã§ãã Apache JServ Protocol version 1.3 (以é AJP13) ããµãã¼ããã¾ãã AJP13 ãããã³ã«ãæ±ããããã«ããã«ã¯ mod_proxy 㨠mod_proxy_ajp ããµã¼ãã«çµã¿è¾¼ãå¿ è¦ãããã¾ãã ãããã³ã«ã®æ¦è¦ AJP13 ãããã³ã«ã¯ãã±ããæåã§ãã å¯èªãªãã¬ã¼ã³ããã¹ãå½¢å¼ã§ã¯ãªããã¤ããªå½¢å¼ã«ãªã£ãã®ã¯ã ããããããã©ã¼ãã³ã¹ä¸ã®çç±ã«ããã¾ãã ã¦ã§ããµã¼ãã¯ãµã¼ãã¬ããã³ã³ãã㨠TCP ã³ãã¯ã·ã§ã³ã§éä¿¡ãã¾ãã ã½ã±ããçæã¯éãå¦çãªã®ã§ãè² è·ãæ¸ããããã«ããµã¼ãã¬ããã³ã³ããã¨ã® TCP æ¥ç¶ãç¶æããè¤æ°ã®ãªã¯ã¨ã¹ãã»ã¬ã¹ãã³ã¹å¦çãµã¤ã¯ã«ã«å¯¾ãã¦ä¸ã¤ã® ã³ãã¯ã·ã§ã³ã使ãã¾ããããã«ãªã£ã¦ãã¾ãã ãããªã¯ã¨ã¹ãã«ã³ãã¯ã·ã§ã³ãå²ãå½ã¦ãããã¨ããã®å¦ç
ãåé¡ã anicatch.netã¨ãããã¡ã¤ã³ã§åãã¦ããã¦ã§ãã¢ããªã§HTML+JavaScriptãçæãã¦ãã©ã¦ã¶ã«è¿ãã帰ã£ã¦æ¥ãJavaScriptã®ä¸ã«ããã¦ãXMLHttpRequestãç¨ããå¥ãã¡ã¤ã³ï¼ä»å㯠api.anicatch.netã¨ãããã¡ã¤ã³ï¼ä¸ã§åãã¦ããAPIãµã¼ãã®apiãå©ãããã ã§ãAccess-Control-Allow-Originã§è¨±ããã¦ãªããã£ï¼çãªãã©ã¦ã¶ã®ã¨ã©ã¼ãå°ããã¤ã¥ããã JavaScriptææ¸ããapi.anicatch.netãå©ãã¦ããã®ã¯anicatch.netã§çæããããã®ã ãã«å¶éãããã ã調æ»1ã Ajaxã®ã¯ãã¹ãã¡ã¤ã³åé¡ã«ã¤ã㦠HTTP access control (CORS) Access-Control-Allow-Origin試ãã¦ã¿ãã jquery - Cross-Domain AJ
Web ãµã¤ãå ã§ãã£ã¬ã¯ããªãã¨å ´æãå¤ããå ´åã«ä½¿ããè¨å®ã RewriteEngine On RewriteRule ^/old/foo/(.*)$ /new/bar/$1 [R=301,L,NE] R=301: redirect 301 Moved Permanently (æä¹ çãªãªãã¤ã¬ã¯ã転é) L: last ãã®ã«ã¼ã«ã«ãããããããã®å¾ã®ã«ã¼ã«ã¯è©ä¾¡ããªã NE: noescape ç¹æ®æåãã¨ã¹ã±ã¼ãããªã(æ¥æ¬èªã®ã¯ã¨ãªæååãå«ã¾ããå ´åãªã©ã«æååããé²ãããã«æå®ãã) ref. Apache mod_rewrite - Apache HTTP Server Version 2.4 RewriteRule Flags - Apache HTTP Server Version 2.4 mod_rewriteã¾ã¨ãï¼3ï¼mod_rewriteã§ä½¿ãããã©ã° ãã©ã¡
ä»åã®ç°å¢ã $ uname -mrsv Linux 3.16.0-4-amd64 #1 SMP Debian 3.16.7-ckt11-1+deb8u3 (2015-08-04) x86_64 $ cat /etc/debian_version 8.1 $ lsb_release -a No LSB modules are available. Distributor ID: Debian Description: Debian GNU/Linux 8.1 (jessie) Release: 8.1 Codename: jessie Apache ã®ã½ã¼ã¹ã³ã¼ãããã¦ã³ãã¼ããã¦ããã«ãããã $ wget http://www.apache.org/dist/httpd/httpd-2.2.31.tar.gz $ tar zxvf ./httpd-2.2.31.tar.gz $ cd
ã¯ãã¹ãã¡ã¤ã³å¶ç´ã«ããFirefoxã§Font Awesomeãªã©ã®WEBãã©ã³ãã表示ã§ããªãå ´åã®è¨å®by Tech Topics2013å¹´11æ21æ¥2016å¹´1æ13æ¥1件ã®ã³ã¡ã³ã ããã®è¨äºãèªãã®ã«å¿ è¦ãªæéã¯ç´ 4 åã§ãã Font Awesome ãªã©ã®WEBãã©ã³ããå©ç¨ããéã«ããã©ã³ããå©ç¨ãããµã¤ãã®ãã¡ã¤ã³ã¨WEBãã©ã³ããé ç½®ãããµã¼ãã®ãã¡ã¤ã³ãç°ãªãå ´åã使ç¨ãããã©ã¦ã¶ã¨ãã®ãã¼ã¸ã§ã³ã«ãã£ã¦ã¯ã¯ãã¹ãã¡ã¤ã³å¶ç´ã®ããWEBãã©ã³ãã«ã¢ã¯ã»ã¹ã§ããããã©ã³ããæ£å¸¸ã«è¡¨ç¤ºãããªããã¨ãããã¾ãã ãã®å ´åãWEB ãã©ã³ããé ç½®ãããµã¼ãå´ã«ä»ã®ãã¡ã¤ã³ããã®ã¢ã¯ã»ã¹ã許å¯ããããè¨å®ã追å ãããã¨ã§ãWEB ãã©ã³ãã表示ã§ããããã«ãªãã¾ãã Firefoxãªã©ã®ææ°ãã©ã¦ã¶ã§ã¯ã¯ãã¹ãã©ã¦ã¶ã許å¯ããªã 以ä¸ã§ã¯ããªã¹ãã®ãã¼ã«ã¼ã¨ã㦠<i c
TLSæ¡å¼µï¼RFC4366ï¼ä»æ§ã®ä¸ã¤ Server Name Indicationï¼SNIï¼ã«ãã£ã¦ååãã¼ã¹ã®ãã¼ãã£ã«ãã¹ãã§ãSSLã使ãã¾ããããããããªããååãã¼ã¹ã®ãã¼ãã£ã«ãã¹ãã§SSLã使ããªãã®ããã®çç±ã¨ãSNIã®ä»çµã¿ã¨è¨å®æ¹æ³ã«ã¤ãã¦èª¿ã¹ã¦ã¿ã¾ããã 以åãWEBãã£ã¬ã¯ã¿ã¼ã®æ¹ãããSSLã使ã£ã¦ãããµã¤ãã®ãã¼ãã£ã«ãã¹ãã®è¨å®ä¾é ¼ãåãã¦ãSSL使ã£ã¦ãã¨ãã¼ãã£ã«ãã¹ãã¯ä½¿ããªãã£ãããã¨ãã¤é¡ã§çãã¦ãã¾ããå°ãæ¥ããããæãããã¾ããã(^^;) æã®ä¸å¸ã®è¨èã常ã«ã¢ã³ãããå¼µã£ã¦ããï¼ããæãåºãã¾ãã SNIã®ä»çµã¿ SSLã使ã£ã¦ããã¨å½ç¶ã§ããHTTPãããã¯æå·åããã¦ããã®ã§ãã¯ã©ã¤ã¢ã³ããã©ã®ãã¹ãåãæå®ãã¦ããã®ãå¤æã§ããªããããå é ã®ãã¼ãã£ã«ãã¹ãï¼å³ã®å ´å㯠lamp-svï¼ã表示ããã¦ãã¾ãã¾ãã SNIã§ã¯SSL/TL
ã¬ã³ã¿ã«ãµã¼ãã¼ãªã©ã§ä¸è¬çã«ä½¿ç¨ããã¦ããApacheã§åãåºããããã°ã管çã»è§£æããçºã®ãã¼ã«ã4種é¡ç´¹ä»ãã¾ãã ãã¤ãã¯ãèªåã§è©¦ãããã®ãç´¹ä»ãããã¹ã¿ã¤ã«ãåã£ã¦ãã¾ãããä»åã¯ããããã試ãããã®ã®ç´¹ä»ã§ãå ¨ã試ãã¦ãã¾ããã å®çªãªãã®ã»ããã¯ä½¿ãããã¨æã£ããã®ãæãã¦ãã¾ãã ApacheLogViewer ã¡ã¸ã£ã¼ã»åºæ¬ãGUI ã§è¦è¦çã«è©³ç´°ãªãã¼ã¿ãé²è¦§å¯è½ãããªã¼ã ãã¦ã³ãã¼ãï¼ApacheLogViewer ã®ãã¦ã³ãã¼ã ãWindowsç¨ãã¨ãªã£ã¦ããã®ã§ãæãããã°ããã¦ã³ãã¼ããã¦ãã¼ã«ã«ã§è§£æããã¿ã¤ãï¼ ä½è ã¯æ¥æ¬äººãGUIã¯åãããããã¦ä¸å¯§ã 解説ãµã¤ãâ ApacheLogViewer:ã¤ã³ã¹ãã¼ã«ã¨åºæ¬çãªä½¿ãæ¹ - ItsMemo::IT ãApacheLogViewerãï¼ï¼èªå® ãµã¼ãã¼æ§ç¯ããã° Visitors GIGAZINE
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}