Web Application Security Reviews
PHP Everywhere ã« Web Application Security Reviews ã¨ãããæ稿ãããã¾ããã
é常ã«èå³æ·±ãã£ãã®ã§ã訳ãã¦ã¿ã¾ãããéèæ©é¢ã§åãã Web ã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£ãã§ãã¯é
ç®ãã¾ã¨ãããã®ã ããã§ãããçµæ§å³ããã§ãã
誤訳ãªã©ãããã¾ãããææãã¦ããã ãã¾ãã¨å¹¸ãã§ãã
- å ¨ã¦ã®éè¦ãªä½æ¥éç¨ã«ããã¦ãéçºå´ã¨æ¤æ»å´ãå«ããªããã°ãªããªããè¨ãæããã¨ãããç§(éçºå´)ãéè¦ãªæ¡ä»¶ãä½æããå ´åãä»ã®èª°ã(æ¤æ»å´)ã®æ¤æ»ã¨æ¿èªãåããªããã°ãªããªãã
- åå¼ã®æ´»çºãªå£ä½ã®å ¨ã¦ã®åå¼ã«ããã¦ãã¦ãã¼ã¯ ID ã¨(åå¾ã®)å¤æ´ãã¼ã¿ãã¿ã¤ã ã¹ã¿ã³ããä¿åããªããã°ãªããªãã
- PHP ã¾ã㯠ASP ã§ä½¿ç¨ãããå ¨ã¦ã®ãã¼ã¿ãã¼ã¹ã®ãã¹ã¯ã¼ãã¯æå·åããã¦ããªããã°ãªããªãã
- ãããWeb ã¢ããªã±ã¼ã·ã§ã³ãã¤ã³ã¿ã¼ãããã«å ¬éãããå ´å㯠Tripwire(ãã¡ã¤ã«ã®æ´æ°ãæ¤åºãããã¼ã«)ãã¤ã³ã¹ãã¼ã«ããã¦ããªããã°ãªããªãã
- ãã¼ã¿ãã¼ã¹æ¥ç¶(ã¨ãã¹ã¯ã¼ãã®å¾©å·)㯠DLL ãã³ã³ãã¤ã«æ¸ã¿ã®ã¹ã¯ãªãããéãã¦è¡ããªããã°ãªããªãã
- ãã¹ã¯ã¼ãã®éµã¯ã³ã³ãã¤ã«æ¸ã¿ã®ã³ã¼ãã«ããã¦ãå¹³æã§æ ¼ç´ãããåããã«ãããããã¾ãã¯ãåå²ãã¦è¤æ°ã«åå²ãã¦æ ¼ç´ããã¹ãã§ããã
- ã¦ã¼ã¶ã¯ååãã°ã¤ã³æã«ãã¹ã¯ã¼ããå¤æ´ããªããã°ãªããªãã
- å ¨ã¦ã®ãã¼ã¿ãã¼ã¹ãã¹ã¯ã¼ãã¯éè¡ã好ãã¢ã«ã´ãªãºã (ä¾: SHA-1, 3DES, AES ãªã©)ã使ç¨ãã¦æå·åãããªããã°ãªããªãã
- å ¨ã¦ã®ã¦ã¼ã¶ã®ãã¹ã¯ã¼ãã¯éè¡ã好ãã¢ã«ã´ãªãºã (ä¾: SHA-1, 3DES, AES ãªã©)ã使ç¨ãã¦æå·åãããªããã°ãªããªãã
- ã¦ã¼ã¶ã¯ X åãã°ã¤ã³ã«å¤±æããã¨ããã¯ã¢ã¦ããããã主è¦ãªç®¡çè ã¯ä¾å¤ã¨ããã
- ã¦ã¼ã¶ã¯ãã°ã¤ã³ãç¦æ¢ãããå¯è½æ§ãããã
- é«ã権éãæã¤ã¢ã«ã¦ã³ãã®å ¨ã¦ã®éè¦ãªãã¹ã¯ã¼ãã¯2人ã§åå²ãã¦æã£ã¦ããªããã°ãªããªãã
- å ¨ã¦ã®ãã¹ã¯ã¼ãã¯ã¢ã«ãã¡ãããã¨æ°åãæ··ãã£ã¦ããªããã°ãªããªããã¾ãããã¹ã¯ã¼ãã®æå°ã®é·ããè¨å®ã§ããªããã°ãªããªãã
- ãã¹ã¯ã¼ã㯠X æ¥ãã¨ã«å¤æ´ãããªããã°ãªããªããé常ã¯30æ¥ãã90æ¥ã§ããã
- ãã¹ã¯ã¼ã㯠X å以ä¸ç¹°ãè¿ã使ç¨ãããã¨ã¯ã§ããªããä»ã¾ã§ã«è¦ãæé«ã®å¤ã¯24åã§ããã
- ãã¹ã¯ã¼ãã¨ã¦ã¼ã¶ ID ã®æåã® X æåãåãã§ãã£ã¦ã¯ãªããªãã
- ã»ãã·ã§ã³ãã¼ã¯[session_regenarate_id() ã使ç¨ãã¦]ãã°ã¤ã³ãã¨ã«åçæãããªããã°ãªããªããã»ãã·ã§ã³ãã¼ãåçæããã¦ãããã¨ã¨ã次ã®é ç®ã確èªããããã«ãæ¤æ»ãã¼ã ããã±ãããã£ããã£ãè¡ã HTTP ãããã·ãµã¼ãã使ç¨ãããã¨ããã£ãã
- Cookie ã«éè¦ãªæ å ±ãæ ¼ç´ãã¦ã¯ãªããªããä¾: ã»ãã·ã§ã³ ID ã¨ããã«é¡ããæ å ±ã®ã¿ã«ããã
- ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã¯ãã¹ãããããåãæ¤æ»ãã¼ã ãå ¥åãã©ã¼ã ã§ä¾ã¨ãã¦ã ãå ¥åãã¦ç¢ºèªããã
- ãX æ¥ä»¥ä¸ä½¿ç¨ããã¦ããªãã¢ã«ã¦ã³ãããããã°ã¤ã³è©¦è¡åæ°ã¨å¤±æåæ°ãããã¦ã¼ã¶ã®ã¢ã¯ã»ã¹æ°ã示ãã表ããªã©ã®ã¬ãã¼ããå©ç¨å¯è½ã§ãªããã°ãªããªãã
- ãã¡ã¤ã«ã®æ¨©éã«ã¤ãã¦ãæ¤æ»ãå¶éãããã
- ã¹ã¼ãã¼ã¦ã¼ã¶æ¨©éã§å®è¡ããããµã¼ãã¹ãã¸ã§ãã¯è¨±å¯ãããªãã
- ã»ãã·ã§ã³ã¿ã¤ã ã¢ã¦ãã¯è¨å®å¯è½ã§ããããã©ã¦ã¶ã¯ã¿ã¤ã ã¢ã¦ãå¾ã«ã¯ãã°ãªãããªããã°ãªããªã(PHP ã®ã»ãã·ã§ã³ã¯ããã«åé¤ãããªãã®ã§ããã㯠Javascript ã§å¦çãè¡ããªããã°ãªããªã)ã
- 管çè ã¯ãªã¢ã¼ãããå¼·å¶çã«ã¦ã¼ã¶ããã°ã¢ã¦ãããããã¨ãã§ãã(ããã¯ãæåã§ãã¼ã¿ãã¼ã¹ã«ä¿åããã¦ããã»ãã·ã§ã³æ å ±ãåé¤ãããã¨ãã§ããã¦ã¼ã¶ã¤ã³ã¿ã¼ãã§ã¼ã¹ãæä¾ããã¨ãããã¨ã§ãã)ã