ãµãã¿ã¤ãº
åãåå¿ãé
ããã©ã
高木浩光@自宅の日記 - プログラミング解説書籍の脆弱性をどうするか, 「サニタイズ言うなキャンペーン」とは何か, ASPとかJSPとかPHPとかERBとか、逆だ..
æè¿ã®ããã°ã©ã å ¥éæ¸ã¯ãæåå解ææ©æ§ãããã¨ããèãæ¹ããªãã®ããªãæ¸ãã¦ã人ãããããæèããã¾ãç¡ãã®ãããããªãã
ç§ãåãã¦ããã°ã©ã ãæ¸ããã®ã¯Perlã®æ²ç¤ºæ¿ã ã£ãããã«æããï¼Cè¨èªã®å
¥éæ¸ã¯æ°åè¨ç®ã¨ãã«ã¬ã³ãã¼è¡¨ç¤ºã¨ãé¢ç½ããªãä¾ãããªãã£ãï¼
åãã«HTTPããããåºåãã¦ããªã¯ã¨ã¹ãã&ã¨=ã§åºåã£ã¦å¤æ°ã«å
¥ããåºåæã«ãã¾ãã¾ãæ£è¦è¡¨ç¾ã使ã£ã¦ < ã < ã«å¤æãã¦ãã£ããã¨ãã
ãã®ä¸ã§ä¾ãã°ãã©ã³ãã¿ã°ã使ããããªããã©ã³ãã¿ã°ã ã許å¯ããã
ãããçããã§ãã¯ã ã¨å±æ§ã使ã£ã¦ããæªæ¯ï¼ï¼ï¼ãããããæ£ç¢ºã«ãã¼ã¹ããªããã°ãªããªãã£ãã¨æãã
ç¦æ¢ããã¿ã°ã ãè¨å®ããã¨ããããä¾ãã°
<script>
ã®æååãåç´ã«ãç¦æ¢ãã¦ããããã«
< script >
ã¨ããããã¡ããã
ãã¡ã¤ã«ã«ä¿åããã¨ããå®æã«ã¿ãåºåãã«ãã¦ãã¨ãã¿ããã³ããã§å
¥åããã¦ãã°ã£ããã
ãããªããã§æååã解æãã¦æ£ããå¦çãããã¨ãããã¨ã¯æ®éã ã£ãããã§ã
åºåãæåï¼ãã¼ã¯ã³ï¼ç¹å¥ãªæå³ãããæåï¼ã«ã¤ãã¦ã¯å
¥éã®æç¹ã§è§£èª¬ããã¦ããã
ãããPHPã«ãªãã¨ãªã¯ã¨ã¹ãã$_GETã§ç°¡åã«åãåããããDBãç°¡åã«ä½¿ãããã§ããããæã«æèãåãã«ããã®ããã
DBã«ãã¦ãã·ã³ã°ã«ã¯ã©ã¼ãã¼ã·ã§ã³ããã¼ã¿ã¨ãã¦è¨é²ã§ããã¹ãã ãããã¡ã¤ã«åã«ãã¦ã../ãè¨é²ã§ããã¹ãã ã
ä¾ãã°ã¢ãããã¼ãã§ãã¡ã¤ã«åã../ã¨ãã¦ã¢ãããã¦ããã¿ã¤ãã«ä¸è¦§ã§../ã表示ã§ãã¦å
容ãè¦ããæ¹ãæ®éã ã¨ã¾ãèãããã¢ããªã±ã¼ã·ã§ã³ä¸ã®ãã¡ã¤ã«åã¨å®éã®ãã¹ã¯å¥åé¡ãå®éã®ãã¹ã¨åä¸ã«ããã®ã¯æãæãããã ã¨èããã°ããã ã®æååã¨å®éã®ãã¹ã®æ±ãæ¹ã«ã¤ãã¦èªç¶ã¨æèããã
æï¼5ï¼6å¹´åï¼ï¼ã®å ¥éæ¸ãèªãã ãèªç¶ã¨ããããèãæ¹ã«ãªã£ãæ°ããããã ãã©ããä»ã¯ç¡çãªã®ãã便å©ã§ç°¡åã«ããã°ã©ã ãæ¸ããããã«ãªã£ã¦ãé ã追ãã¤ãã¦ãããªããããããµãã¿ã¤ãºã¨ãå·ãè¾¼ã¿ãããåã ãä»ã®æ¹ãåä»ãã
ã«ã¼ãã«ã½ã¼ã¹ã®ãã¹æ¢ç´¢é¨åãè¦ã¦ãã¨Cè¨èªã§ä¸æåä¸æå解æãã¦ããã ãã©ãããããé¨åãå®éã«è¦ããæ å ±ç³»ã®ææ¥ã§ç¿ã£ãããã¦ããã¨ã ãã¶éã£ã¦ãããã ãããªã