人éã¨ã¦ã§ãã®æªæ¥ï¼æ§ï¼ ãã¦ã§ãã®æ´å²ã¯äººé¡ã®æ´å²ã®ç¹°ãè¿ããã¨ãã観ç¹ããè²ã åå¼·ãã¦ãã¾ãã2014å¹´ã¾ã§ã®äººéã¨ã¦ã§ãã®æªæ¥ã®æ§ããã°ã§ãã

12æ10æ¥ã«PCçãã¹ã¿ã¼ããããµã¤ãã¼ã¨ã¼ã¸ã§ã³ãã®ããããã°ãµã¼ãã¹ãAmebaãªããã§ãããURLãã¯ãªãã¯ããã¨ããããã«ã¡ã¯ãããã«ã¡ã¯!!ãã¨ãããã¬ã¼ãºã¨ã¯ãªãã¯ããURLæååãèªåã§æ稿ããããã¯ã¾ã¡ã2ãããã®ã¢ã«ã¦ã³ããèªåã§ãã©ãã¼ãã¦ãã¾ãã¨ããç¾è±¡ãåºãã£ãã URLãã¯ãªãã¯ããã¦ã¼ã¶ã¼ãæå³ããªãæ©è½ãå®è¡ãããããWebã¢ããªã®èå¼±æ§ã®ä¸ç¨®ã»ã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªï¼CSRFï¼ãçªãããã®ãå社ã¯10æ¥å¤ãURLãã¯ãªãã¯ããªãããã¦ã¼ã¶ã¼ã«åç¥ã誤ã£ã¦ã¯ãªãã¯ããå ´åã¯æ稿ãåé¤ããã¯ã¾ã¡ã2ããã®ãã©ãã¼ãå¤ãããå¼ã³æããã11æ¥æã¾ã§ã«èå¼±æ§ãä¿®æ£ããã¨ããã mixiã§ã2005å¹´ãããURLãã¯ãªãã¯ããã¨ãã¼ãã¯ã¾ã¡ã¡ããï¼ãã¨ããæ¥è¨ãåæã«æ稿ãããã¨ãããCSRFãå©ç¨ããã¹ãã ãæµéãããã¨ããã£ããã³ãã¥ããã£ã¼ãµã¤ãæ§
Apacheãã»ãã¥ã¢ã«ããã¢ã¸ã¥ã¼ã«ã§ãmod_securityãã¨ããã®ãããããã§ãããããWeb Application Firewall (WAF)ã¨ãããã®ã«åé¡ãããä»çµã¿ãªã®ã§ãããé常ã«æ©è½ãå¼·åãããããGETãPOSTãã¬ã¹ãã³ã¹ãå«ãINã¨OUTã®å ¨ãªã¯ã¨ã¹ãï¼HTTPSå«ãï¼ã«å¯¾ãã¦ãã£ã«ã¿ãªã³ã°å¯è½ãé常ã§ã¯è¨é²ãããªãPOSTã®ãã°ãè¨é²å¯è½ã ã§ããã®æ©è½ã使ãã°ãã©ãã¯ããã¯ã¹ãã ããµã¼ãå´ã§å§æ«ã§ããã®ã§ãPHPãªã©ãåãã¦å¤å®ããåã«å¦çã§ãããã©ãã¯ããã¯ã¹ãã ã«ããè² è·ã軽ããªãã¨ããããã è¨å®ã®è©³ç´°ãªã©ã¯ä»¥ä¸ã®éããmod_securityç¨ã®ãã©ãã¯ãªã¹ãããã¦ã³ãã¼ãã§ããã®ã§è¨å®ãç°¡åã§ãã å ¬å¼ãµã¤ãã¯ä»¥ä¸ã ModSecurity (mod_security) - Open Source Web Application Firewal
ä»ã®ã¤ã³ã¿ã¼ãããã¯IPãã¼ã¸ã§ã³4ã§åä½ãã¦ãã¾ããããã®IPv4ã§åæ©å¨ãèå¥ããããã®IPv4ã¢ãã¬ã¹ãéã«äºå®ä¸æ¯æ¸ãã¾ãã(åè)ã é·å¹´ãæ¯æ¸ãããã¨è¨ããç¶ãã¦ãã¾ãããããããéã«ç¾å®ã®ç©ã¨ãªãã¾ããã ããã§ã¯ãIPv4ã¢ãã¬ã¹æ¯æ¸ã¨ã¯ä½ãã¨ãããã«ãã£ã¦ä½ãèµ·ããã®ããç´¹ä»ãã¾ãã IPv4ã¢ãã¬ã¹æ¯æ¸ã«é¢ãã¦ãã¢ããã°æ¾éã®åæ³¢ã¨å°ãã¸ã¸ã®ç§»è¡ããåæ²¹æ¯æ¸ã¨ä¼¼ããããªãã®ã§ãããããªèªèãå¤ãè¦ããã¾ãããå人çã«ã¯IPv4ã¢ãã¬ã¹æ¯æ¸å¾ã®IPv4ã¢ãã¬ã¹ã®ã¢ããã¸ã¼(é¡æ¯)ã¨ãã¦ã¯ç¸æ²ã®è¦ªæ¹æ ªã®æ¹ãè¿ãæ°ããã¦ãã¾ãã ã¾ããã¢ããã°æ¾éã®åæ³¢ã¨å°ãã¸ã¸ã®ç§»è¡ã§ãããã¢ããã°æ¾éã¯2011å¹´7æã«ä¸æã«åæ¢ãã¾ãã ããããIPv4ã¢ãã¬ã¹ã®å ´åã¯ãããæ¥çªç¶IPv4ã使ããªããªãããã§ã¯ãªããä»ã¾ã§ä½¿ã£ã¦ããIPv4ã¢ãã¬ã¹ã¯ãã®ã¾ã¾ä½¿ãç¶ããããã¨ããæå³ã§ã¢ã
ãç¥ãã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}