Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article?

Linuxãªã©UNIXç³»OSã§ä½¿ããã¦ããã·ã§ã«ã®ãbashãã«æ¥µãã¦æ·±å»ãªèå¼±æ§ãçºè¦ããåé¡ã§ãã»ãã¥ãªãã£ä¼æ¥ã®ç±³FireEyeã¯ç¾å°æéã®10æ1æ¥ãæ¥æ¬ãéå½ãç±³å½ã®NASï¼Network Attached Storageï¼ã·ã¹ãã ãæ¨çããæ»æã確èªããã¨çºè¡¨ããã ãã®åé¡ã¯ãShellshockãã¨å¼ã°ããbashã§ç¹å®ã®ç´°å·¥ãæ½ããç°å¢å¤æ°ãå¦çããæ¹æ³ã«èµ·å ããèå¼±æ§ãè¤æ°åå¨ãããèå¼±æ§ãæªç¨ãããã¨ãã¢ããªã±ã¼ã·ã§ã³ã®æ¨©éã§ä»»æã®OSã³ãã³ããå®è¡ããã¦ãã¾ãæãããããä¸è¬çãªè¨å®ã§ãããã¯ã¼ã¯ãä»ãã¦å®¹æã«æªç¨ã§ããã¨ããã2014å¹´4æã«çºè¦ããOpenSSLã®èå¼±æ§ï¼Heartbleedï¼ãè¶ ããå±éºã ã¨ã®ææãèãããã FireEyeã確èªããæ»æã§ã¯æ¥æ¬ãéå½ãç±³å½ã®å¤§å¦ãç 究æ©é¢ã§å©ç¨ããã¦ããQNAP Systems製ã®NASãªã©ãæ¨çã«ãªã£ã¦ãã
â»(2014/10/1 追è¨) èå¼±æ§ã®çªå·ã誤ã£ã¦ CVE-2014-6721 ã¨è¡¨è¨ãã¦ãã¾ã£ã¦ãã¾ãã æ£ãã㯠"CVE-2014-6271" ã§ã 失礼è´ãã¾ãã â»(2014/10/7 追è¨) 2014/10/7 14:00æç¹ã§ Shell Shock ã¸ã®ä¿®æ£ãããã¯6å å ¬éããã¦ãã¾ã æ¢ã«å¯¾å¿æ¸ã¿ã®ã·ã¹ãã ã§ããããã®æ¼ãããªãã注æãã¦ãã ãã ã·ã§ã«ã«èå¼±æ§ãè¦ã¤ãã£ããããã§ã ãã®ã³ãã³ããå®è¡ããã¨èå¼±æ§ããããã¼ã¸ã§ã³ãã®ãã§ãã¯ãã§ããããã§ã $ env x='() { :;}; echo vulnerable' bash -c "echo this is a test" 以ä¸ã®ããã«è¡¨ç¤ºããããã¢ã¦ãã§ã vulnerable this is a test ã©ãããããã®ã³ãã³ããæ£å¸¸ã«å®è¡ã§ããã¨ããã®ããã®èå¼±æ§ã®æ£ä½ãããã echo vuln
2014-09-27: 該å½ãµã¤ãä¸ã«XSSããªãã¦ãæ»æå¯è½ã§ãããã¨ã id:mayuki ããã®ã³ã¡ã³ãã§å¤æãã¾ããã®ã§å ¨é¢çã«æ¸ãç´ãã¾ããããã¡ã¤ã¢ã¦ã©ã¼ã«å ã§ãã£ã¦ãæ»æè ã¯ãã¡ã¤ã¢ã¦ã©ã¼ã«å ã®Shellshockæ»æãéç¨ããCGIã®URLãããã£ã¦ããã ãã§æ»æå¯è½ã§ãã®ã§æ©æ¥ã«å¯¾å¿ãå¿ è¦ã§ãï¼ä¼ç¤¾ã®ããã°ã«ãæ¸ãã¦ã¾ããããã¡ã¤ã¢ã¦ã©ã¼ã«å ã«ç½®ãã¦ãããµã¼ãã§æ»æè ãç´æ¥ã¢ã¯ã»ã¹ã§ããªãããã¨ãã£ã¦bashã®æ´æ°ãæ ã£ã¦ããã¨ãæ¡ä»¶ã«ãã£ã¦ã¯æ»æãå¯è½ã¨ãªãã¾ãã æ¡ä»¶ã¨ãã¦ã¯ã ãã®ãµã¼ãã«ã¯ã·ã§ã«ãçµç±ãã¦å¤é¨ã³ãã³ããèµ·åããCGIçãåãã¦ãã(é常ã®Shellshockã®æ»æã¨åæ¡ä»¶) æ»æè ããã®URLãäºåã«ç¥ã£ã¦ãã(ãããã¯æ¨æ¸¬å¯è½) ã¨ãªãã¾ãã æ»æè ã¯ãã¦ã¼ã¶ã¼ãç½ URLã¸èªå°ãã以ä¸ã®ãããªJavaScriptãç½ ãã¼ã¸ä¸ã§åãããæ»æ対象ã®W
æ¡ä»¶1. /bin/shã®å®ä½ãbashã®ãã£ã¹ããªãã¥ã¼ã·ã§ã³ RHEL CentOS Scientific Linux Fedora Amazon Linux openSUSE Arch Linux (èªãè¨å®ããå ´å: Debian, Ubuntu) æ¡ä»¶2. åä½ç°å¢ CGI (ã¬ã³ã¿ã«ãµã¼ãã§ãããã¡ãªCGIã¢ã¼ãã®PHPçãå«ã) Passenger(Ruby) æ¡ä»¶3. ããã°ã©ã å 容 Passengerã¯å ¨æ»äº¡ *1 systemã `command`ã '| /usr/lib/sendmail' ãªã©ã§å¤é¨ã³ãã³ãå®è¡ *2 PHPã®mailãmb_send_mailããã®ä»ãã¬ã¼ã ã¯ã¼ã¯çãä»ããã¡ã¼ã«éä¿¡ *3 以ä¸ã¯æ¡ä»¶1ãä¸è¦ æ示çã«bashãå¼ã¶ å é 㧠#!/bin/bash ã #!/usr/bin/env bash ãã¦ããããã°ã©ã ãå®è¡ (rbenv
bashã«èå¼±æ§ã確èªãããã¨ãã¦é¨ãã«ãªã£ã¦ãã¾ããããã§ã¯CVE-2014-6271ã«é¢ããæ å ±ãã¾ã¨ãã¾ãã #è¨è¼å 容ã«ã¤ãã¦ã誤ã£ã¦ããã追è¨ããæ¹ãããçæ å ±ããããã¾ããã@piyokangoã¾ã§ãé£çµ¡ãé¡ããã¾ãã èå¼±æ§æ å ± èå¼±æ§ã®æ称 ShellShock Bashbug CVEçªå· Bashå¨ãã§çºè¡ããã¦ããCVEã¯6ã¤ããã®å 詳細ãä¸æãªã®ã2ã¤ã(CVE-2014-6277,CVE-2014-6278) CVE çºè¦è æ³å®è å¨ ç¹è¨ CVE-2014-6271 Stephane Chazelasæ° ä»»æã®ã³ã¼ãå®è¡ ShellShockã®çºç«¯ã¨ãªã£ããã°ã CVE-2014-7169 Tavis Ormandyæ° ä»»æã®ã³ã¼ãå®è¡ CVE-2014-6271ä¿®æ£æ¼ãã«ããèå¼±æ§ CVE-2014-7186 Redhat DoS ã¡ã¢ãªç ´å£(Out-of-Bo
è¨äºå ã«åºåãå«ã¾ãã¦ãã¾ããThis article contains advertisements. Bashã®èå¼±æ§CVE-2014-6271ãOS X ã§ä¿®æ£ããæ¹æ³ã§ãã詳細ã¯ä»¥ä¸ããã æ¨æ¥æããã«ãªã£ãBashã®èå¼±æ§ãç°å¢å¤æ°ã«ä»è¾¼ã¾ããã³ã¼ããå®è¡ãã¦ãã¾ãBASHã®èå¼±æ§ãã¯æ¢ã«Ubuntuãªã©ã§ã¯ä¿®æ£ããã¦ãã¾ãããOS X ã§ã¯ã¾ã âcommand line toolsâã«ã¢ãããã¼ããããããªãã®ã§ãself updateããæ¹æ³ãã¾ã¨ãã¾ããã ãã§ãã¯æ¹æ³ ã¿ã¼ããã«.appãèµ·åãã¦ä»¥ä¸ã®ä¸è¡ãå®è¡ env x='() { :;}; echo vulnerable' bash -c "echo hello" ãã®ç¶æ 㧠vulnerable hello ã¨èå¼±âvulnerableâã¨åºãã°èå¼±æ§ãåå¨ãã¾ãã HomebrewãMacPorts Homeb
ç°å¢å¤æ°ã«ä»è¾¼ã¾ããã³ã¼ããå®è¡ãã¦ãã¾ãBASHã®èå¼±æ§ã CGIã¹ã¯ãªããã«å½±é¿ãä¸ããã試ãã¦ã¿ããçµæã¯æ²æ¨ãªæãã« Tweet 2014å¹´9æ25æ¥ å¶ç°å¤§è²´ ãã®è¨äºã¯2014å¹´ã®ãã®ã§ã æãã Bash specially-crafted environment variables code injection attack ãªããã®ã§é¨ãã«ãªã£ã¦ããã®ã§ããã£ããæå ã® Apacheã§è©¦ãã¦ã¿ã¾ããã /hoge.cgiã¨ããURIã§å®è¡ãããããã«ãä¸è¡ã®ã¡ãã»ã¼ã¸ãåºåããã ãã® CGIã¹ã¯ãªãããè¨ç½®ãã¾ãããã£ããããªãã®å ¥åãã¯ã©ã¤ã¢ã³ãå´ããåãä»ãã¦ããªãããå±éºã®ããããããªãè¦ãã¾ãã #!/bin/sh echo "Content-type: text/plain" echo echo "Hi! I'm an ordinary CGI script w
This article was originally published on the Red Hat Customer Portal. The information may no longer be current. Update 2014-09-30 19:30 UTC Questions have arisen around whether Red Hat products are vulnerable to CVE-2014-6277 and CVE-2014-6278. We have determined that RHSA-2014:1306, RHSA-2014:1311, and RHSA-2014:1312 successfully mitigate the vulnerability and no additional actions need to be ta
ã·ã§ã«ã¹ã¯ãªããã®ãããã° ã·ã§ã«ã¹ã¯ãªããããããã°ããã«ã¯ ããã°ã©ã ã«ãã°ã¯ã¤ããã®ã§ãããããã¯ã·ã§ã«ã¹ã¯ãªãããä¾å¤ã§ã¯ãªããbash ã«ã¯ã·ã§ã«ã¹ã¯ãªããã®ãããã°ã«é常ã«æå¹ãªãªãã·ã§ã³ãç¨æããã¦ããã®ã§ããSyntax Errorãã§å®è¡ã§ããªãå ´åããå¤æ°ã«ã©ããªå¤ãè¨å®ããã¦ããã®ã確èªãããå ´åã¯ãããããªãã·ã§ã³ãæå®ããä¸ã§å®è¡ãããã¨ã§ãç°¡åã«ãããã°ãè¡ããã¨ãã§ããã ã-xããªãã·ã§ã³ã使ç¨ãã -x ãªãã·ã§ã³ã¯ãã·ã§ã«ã¹ã¯ãªããå ã§å®éã«å®è¡ãããã³ãã³ãã表示ãããªãã·ã§ã³ã§ãããå¤æ°ã使ç¨ããã¦ããå ´åã¯ããã®å¤æ°ã®å¤ãå±éãããç¶æ ã§è¡¨ç¤ºãããã â bash ã« -x ãªãã·ã§ã³ãæå®ããå¼æ°ã«ãããã°ããã·ã§ã«ã¹ã¯ãªãããæå®ããã -x ãªãã·ã§ã³ã§ã·ã§ã«ã¹ã¯ãªãããå®è¡ããã¨ãecho ã³ãã³ããªã©ã®åºåã«å ãã¦ãã¹ã¯ãªããå ã§å®éã«å®
PowerShell open source reimplementation for "others" (Mac, Linux, Solaris, etc...) and Windows (including Windows Mobile and Windows CE) About the name Pash = Posh (PowerShell) + bash(one of the Unix shells) Goals The main goal is to provide a rich shell environment for other operating systems as well as to provide a hostable scripting engine for rich applications. The user experience should be se
ã¿ãªãããshebangæ¸ãã¦ã¾ããï¼ Shebangã¨ããã®ã¯ãã¹ã¯ãªããã®æåã®ä¸è¡ç®ã«æ¸ããã#!/bin/shãã¨ãã#!/usr/bin/perlãã¨ãããããããã§ãã詳ããã¯Wikipediaããï¼ã·ãã³ (Unix)ï¼ã«èãã¦ãã ããã¾ãã Twitterè¦ã¦ãã¨ããããããããã«shebangãªãã¦ååãã¤ãã¦ãã®ç¥ããªãã£ãããã¨ããçºè¨ãè¦ãä¸æ«ãªåã§ã¯ããã®ã§ãããããã«ä½ãæ¸ãã¦ãããã§å®ã¯åä½ãéããã£ã¦ã®ãä»æ¥ã®æ¬é¡ã§ããããã§ãã¯ã¾ã£ã¦ããã®ãæè¿è¦ã¦ãã¾ããã¾ãããã§å¼ã£ããã人ã¯ããªãã¨æãã¤ã¤ããã®ç¹ãæ¸ããæ å ±ãè¦ãªãã®ã§ã¾ã¨ãã¦ã¿ã¾ããã*1 ä»æ¥åãä¸ããã®ã¯ãbashãããã©ã«ãè¨å®ã«ãªã£ã¦ããLinuxã§ã®ã#!/bin/shãã¨ã#!/bin/bashãã®ã話ã確èªã¯CentOS5, 6ã§è¡ãªã£ã¦ãã¾ãã ãã¦ãä¸è¨ã®ç°å¢ã®å ´åãã/bin
åå(bashã«ããã·ã§ã«ã¹ã¯ãªããã®å°æ(1))ã«å¼ãç¶ããã·ã§ã«ã«ãã£ã¦èªåçã«å¤ãè¨å®ãããç¹æ®ãªå¤æ°ã«ã¤ãã¦ç´¹ä»ãããç¹æ®ãªå¤æ°ãåç §ãããã¨ã«ãããæ§ã ãªæ å ±ãåå¾ãããã¨ãã§ãã(ãã ãããããã®å¤æ°ã«ã¯èªåã§ä»»æã®å¤ãè¨å®ãããã¨ã¯ã§ããªã)ã ãã¦ãã¾ãã¯ç¹æ®å¤æ°ãä¸è¦§ã§ã¾ã¨ãã¦ã¿ããã馴æã¿ã®ãã®ãå¤ãããæå¾ã®2ã¤(ç¹ã«æå¾ã®PIPESTATUS)ã«ã¤ãã¦ã¯ãã£ã¨ä»ã¾ã§ç¥ããªãã£ã人ãããããããªãã ããããã·ã§ã«ã®ä¸ã§ãã¤ãããã¨éä¸ã®ã³ãã³ãã®ãªã¿ã¼ã³ã³ã¼ããæ¾ããªãã¨ãæã£ã¦ãã¾ãããï¼ä»åã®ãã¤ã³ãã¨ãã¦ã¯ãã1. PIPESTATUSå¤æ°ã«ã¤ãã¦ãã¨ã2. ç¹æ®å¤æ° $@ã¨$*ã®éãã«ã¤ãã¦ãã®2ç¹ã主ã«èª¬æããã ç¹æ®å¤æ°ä¸è¦§è¡¨ å¤æ°å èªåçã«è¨å®ãããå¤ $? ç´åã«å®è¡ãããã³ãã³ãã®çµäºã¹ãã¼ã¿ã¹ãè¨å®ãããå¤æ°ãæ£å¸¸çµäºã®å ´åã¯ã0ããç°å¸¸çµäºã®å ´
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}