WASCã®Web Security MLã®å°ãåã®æ稿ããã Tactical Web Application Security: Mass SQL Injection Attacks Now Targeting PHP Sites èªååãããSQL Injectionæ»æããç¾å¨ã¯PHPãµã¤ããã¿ã¼ã²ããã«ãã¦ããã¨ã®å 容ã®è¨äºã§ãã 確ãã«ãSQL Injectionã«ãã£ã¦åãè¾¼ã¾ããJSãã¡ã¤ã«ã®URLããã¼ã¯ã¼ãã«ãã¦Googleæ¤ç´¢ããã¨ãæ¡å¼µåãphpã®ãã¼ã¸ãããããã¾ãã "1000mg.cn/csrss/w.js" - Google Search å人çã«ä¸çªæ°ããããªã®ã¯ãããã¾ã§çããã¦ããSQL Server以å¤ã®ãã¼ã¿ãã¼ã¹ãæ°ãã«æ»æ対象ã«ãªã£ã¦ããã®ãï¼ãããã¯ããã§ã¯ãªãã®ãï¼ã¨ãããã¨ã§ãã ããã«ãé¢ãããããªè©±ãªã®ã§ãå¯è½ãªç¯å²ã§èª¿ã¹ã¦ã¿ã¾ããã

{{#tags}}- {{label}}
{{/tags}}