Not your computer? Use a private browsing window to sign in. Learn more
第02åã¾ã£ã¡ãï¼ï¼ï¼åå¼·ä¼(第02åã¾ã£ã¡ãï¼ï¼ï¼åå¼·ä¼ - ã¾ã£ã¡ãã ããµãã®æ¥è¨â ã¨ããã©ãµãã¼ãâ )ã§WAFã®è©±ãããã¦ããã ãã¾ãããè¬æ¼è³æã¯ãã¡ãã ç§èªèº«ã®ææ³ã¨ãã¦ãããããã¦ç«¹è¿«ãã(id:TAKESAKO)ã¯åªããæ¹ãªã®ã ãªã¨ããæããå¼·ããã¾ãããèªãã¯å¤©æããã°ã©ããªã®ã«ãåå¿è ãæ ®ã£ãè¨åãéã ã£ã¦ãã¾ããããåå¿è ããããªãã»ãã¥ã¢ããã°ã©ãã³ã°ã®å¥¥ç¾©ã示ããã¦ãã¨ã¾ã©ãã§ãããã¿ãããªãNamazuã®ã»ãã¥ãªãã£å¯¾çã®ä½é¨ãããã¦ããã®ããããã¾ããããããã«ãã¦ããã§ãã mod_waffulã¯é¢ç½ããã§ãããèªåã§ãã·ã°ããã£ãæ¸ãã¦ã¿ãããªãã¾ãããä»ã¡ãã£ã¨å¿ããã¦æãåããªãã®ã§ããããã®ãã¡æãã¤ãããã¨æãã¾ãã ãã¯ã¤ããªã¹ãã®è©±ã¯ã¾ãå¥ã®æ©ä¼ã«ã
第02åã¾ã£ã¡ã445åå¼·ä¼ (sites.google.com)ã«ã²ã£ããã¨åå ãã¦ãã¾ãããã¹ã©ã¤ãã¯ãã®ãã¡å ¬éãããã¨æãã¾ãã®ã§ã話ã®å 容ã¯ç«¯æã£ã¦ãã¤ã³ããææ³ã ãã¡ã¢ã ã©ã¤ããã³ã°ãã¼ã¯1: CVE-2008-1447ãè¸ã¾ããDNSãã¹ã®ä¹ãç¶ãã§æ®å¿µãªæããããããã«é å»ãã¦ãããæåã®ã©ã¤ããã³ã°ãã¼ã¯ã¯ã¡ããã¨èãã¾ããã§ãããç³ã訳ãªãâ¦â¦ãorz æå¾ã®æå¾ããèãã¦ããªãã®ã§ããããã¤ãã¤ããããç¡çã ãããã¨ãã話ã¨ç解ãã¦è¯ãã®ã§ãããâ¦â¦ããã©ã¼ã ã«ãæ¬å½ã«HTTPSã§ããã確èªãã¦ãã ãããã¨æ¸ããªã©ãã¦ãã¦ã¼ã¶ã«ãªãã©ã·ã身ã«ã¤ããããããç¡ãã®ã§ã¯ãªãããã¨ãã話ãåºã¦ããããã§ãã ã©ã¤ããã³ã°ãã¼ã¯2: PHP4.4.9ã®ç¾ç¶ 誰ããç¥ã£ã¦ããPHP4.4.9ã®èå¼±æ§å¤§å£ããã®ã©ã¤ããã³ã°ãã¼ã¯ãPHP4.4.9ã¯ãã¡ã ããã¨ãã話ã¨ãææ°ã®P
ï¼ã¬ã¤ã¢ã¦ããã¡ãã£ã¨æ¹è¯ãèªåçã«ã¯ã¿ããããªã£ãããªï¼ 第2åã¾ã£ã¡ã445åå¼·ä¼ã«åå ãã¦ãã¾ããã ä»åã¯ã¯ããã«ãé£ã¹ãªãããã£ãµããã£ãµãã¨ããäºãããã§ãã âæ£æã¾ã¨ã ã»å¤§éªã§ç¬¬13å Admintech.jpãåæ¥éå¬ãããã©ã¦ã¶ç¥ããã ã£ãããã§ãã ãããWebã¢ããªéçºè çã«ã¯ãã£ã¡ãããã ã£ããã ã»åå è ããã®1/3ã»ã©ã®ç®å½ã¦ã¯ãã£ãµããã£ãµãï¼çãã¦ç¾å³ããï¼ ã»ã¾ã£ã¡ãããã¨ç«¹è¿«ããã¯ãæ®å½±èªç±ãï¼å®å¸¸èªç±ãã¯ä¸æï¼ç¬)) ã»ããããããã©éçºè ã«ã¯éçãããããªãã¨åèªèãªã»ãã¥ãªãã£ã ã»yamagataããã¯ããã©21çªã ã»åå¼·ä¼ã«åå ããã¨ãã£ã±ã欲ãããªãUMPCã ã»ãã¨ã¡ã£ã¡ããããã¸ã§ã¯ã¿ã欲ãããªãã使ãéã¯ãªãã ã»Wlistã¨Blistãé£ãããªããéçºè çã«ã¯ä¸¡æ¹ä½¿ããªã㨠ã«ã£ã¡ããã£ã¡ãããªãã¨æãã¾ããã ã¹ã¿ããã®çæ§ã
第02åã¾ã£ã¡ãï¼ï¼ï¼åå¼·ä¼ ç«¹è¿«ããï¼id:TAKESAKOï¼ã«ããmod_wafful話ãèãããã ãã¨ãããã¨ã§åå 表æããåå¼·ä¼ã表æå¾ã徳丸ããï¼id:ockeghemï¼ã»å¤§å£ããã»åç°ããï¼id:sonodamï¼ãç»å£ããããã¨ã決ã¾ããé¡ã£ã¦ããªãæµãã«ã åå¼·ä¼éå§ç´å¾ã¯ãç¥ããªãæ¹ï¼ãããã¯ç§ãä¸æ¹çã«ç¥ã£ã¦ããæ¹ï¼ã°ãã60åã®ä¸ãæ£ç´ã¢ã¦ã§ã¼æãæããã«ã¯ããããªãã£ãã®ã§ãããæçµçã«ã¯æºè¶³æã»å å®æã§ãã£ã±ãã«ãªãã¾ãããã¹ã¿ããã®çæ§ãè¬å¸«ã®çæ§ãåå è ã®çæ§ãæ¬å½ã«ãããã¨ããããã¾ãã åå¼·ä¼ã¯4é¨æ§æã§ããã1é¨ã¯èªå·±ç´¹ä»ã¿ã¤ã ã2é¨ä»¥éãæ¬ç·¨ã§ãã WAFå ¥éããåçãå¹æãéçãï¼å¾³ä¸¸ããï¼ WAFï¼Webã¢ããªã±ã¼ã·ã§ã³ãã¡ã¤ã¤ã¼ã¦ã©ã¼ã«ï¼ã«ã¤ãã¦ä½ãç¥ããªãç¶æ ã§åå ããç§ã«ã¯ããããããè¬æ¼ã§ãããå®éã«WAFãåãã¦ããç°å¢ã§ã®ãã¢ãåãããã
ï¼ã¬ã¤ã¢ã¦ããã©ãã«ãããããªããæéãããã¨ãã«å®é¨å®é¨ï¼ åå ããããã«ã¯ä½ãæ¸ããªãã¨ããã¨æã£ãã®ã§ããã°ãä½ã£ã¦ã¿ãã®ã§ãã http://d.hatena.ne.jp/ripjyr/ å é±ã®åææ¥ã«ãä½æãåèã»åå¼·ããã¦ããã ãã¦ãããã¡ãã®åå¼·ä¼ã«åå ãã¦ãã¾ãããã¾ã£ã¡ã139åå¼·ä¼ã¨ãããã®ãé¢è¥¿ã§è¡ããã¦ãã¦ãã¿ã¤ãã³ã°è¦ã¦ããã«åå ããã¦ããããããªãããªã©ã¨èãã¦ããã¨ãã«ãä¸åº¦è¯ãé¢æ±ã§éå¬ï¼ï¼ãã¨ã®äºã§ãå³ç³ãè¾¼ã¿ã»ã»ã»ã¯ãã¾ããã§ããã å®ã¯å¤é¨ã®åå¼·ä¼ã¨ãããã®ã«ãä»ã¾ã§åå ãããã¨ãç¡ãã®ã§ãã ãã°ããæ©ã¿ã¾ããã ãããã®ãã£ã³ã¹ãéãããï¼ï¼ãã¨æãåæ°ãæã£ã¦ã¡ã¼ã«ã§ï¼§ï¼¯ï¼ï¼ ç¡äºã«åå ã¨ç¸æãã¾ããï¼æçµçã«ã¯ãã£ã³ã»ã«å¾ ã¡ã®ãæ¹ãå¤æ°ããã£ããã£ãããã§ãï¼ å½æ¥ããã£ãããªã®ã§æä¸ã§çªå ¥ï¼ï¼ çªå ¥ãããä¼å ´ã«å ¥ããªã ãããã«ã¡ãã¼ã¼ãã¨ã
第01åã¾ã£ã¡ãï¼ï¼ï¼åå¼·ä¼ã§è©±ããããªãã御社ã®Webãµã¤ããæ»æãããã®ããããã¦ãå®ãããã«ã¯ä½ãããã°ããã®ãããã®è³æãå ¬éãã¾ããã ãå®å ¨ãªè»ããªãã¿ããªä½ã¨ãªãããããã©ããå®å ¨ãªWebãã£ã¦ã¿ããªããããããªãããã ã¨ãã話ããå§ãã¦ãæè¿ã®Webãã¿ã¼ã²ããã¨ããèªåãã¼ã«ã«ããç¡å·®å¥æ»æã®ç¾ç¶ãã被害ã«éãWebãµã¤ãã®ã»ã¨ãã©ã¯ãã°ãæ±ãã¦ããããã ã¨ãããã¨ãããã¦å®ãããã«ã¯è¦ä»¶ã¨è¨è¨ãå¿ è¦ãªçç±ãªã©ã説æãã¦ãã¾ãã ãã¦ã³ãã¼ãã¯ãã¡ãï¼PDFãã¡ã¤ã«ï¼868 KBï¼ ç¬¬02åã«ã¯ç«¹è¿«ããã徳丸ãããç»å ´ï¼å¼ãç¶ã第2åã第3åã楽ãã¿ã«ãã¦ãã¾ãã
ãã«ã®ã¼ã«è¡ã£ã å æ¥ããã«ã®ã¼ã«è¡ãã¾ããã ãã°ãªããã®çµµã¨ã«ã¼ãã³ã¹ã®çµµãè¦ãã®ãç®çã ãã¾ãæéããªããããªã¥ãã»ã«ã¨ã¢ã³ãã¯ã¼ããé§ã足æ°å³ã§å·¡ããã¨ã«ã ãã¥ã³ãã³ããè»ã§10æéè¿ããããããªãã§ãããªç¡è¶ããã¦ãã¾ã£ãã®ãã¨ãæãã¾ããããã¨ã¼ãããã®æ¹â¦
ãããããã£ã¦ãã ãã¶ä¹ ãæ¯ãã® entry ã«ãªãã¾ããã ã¾ã£ã¡ãï¼ï¼ï¼Â ãã¡ãã«åå ãã¦ãã¾ããã 趣å³ã§ security æ±ã£ã¦ãããªã¤ã©ã¨éãæ¬è·ã®äººãçµæ§ãã¦å¤§å¤ããã«ãªãã¾ããã ã§ããã®å°é家ãç¾ç¶ã® security ã«ã¯å±æ©æãè¦ãã¦ããããã§ãæè¿ã§ã¯ application level ã®èå¼±æ§ãå¤ããã¨ããããéçºè 㨠discussion ãããã¨ããæè¦ãå¤ãã£ãã§ãã ã¨ãããã¨ã§ã10/4 ã«ã¾ã£ã¡ãï¼ï¼ï¼ã¨ãããã¾ã®åååå¼·ä¼ããããããã ãªã¤ã©ããªãã¨ã調æ´ãã¦åå ãããã¨æã£ã¦ãã¾ãã®ã§ãã¿ãªããåå ãã¾ãããï¼
ãã¤ããªããããæ°ããã¤ãã¹orz åå ãã人ãç²ãæ§ã§ããã ä¼å ´ã«äººãå¤ãã¦ããã足ããªãã£ãã¨ããããããåå è ã®æ¹ã¨è©±ããªãã£ãã¨ãå¿æ®ããããã¾ãããé常ã«é¢ç½ãã£ãã§ãã ã¾ããå 輪ã®äººãåºã¾ã£ã¦ããã®ã§ããããä»å¾ä½ã¨ãããªãã¨ãããªããªãã¨æãã¾ãã次åã¯å¾ãã®ã»ãã®å¸ã確ä¿ãããã¨ã«ãããã£ã¨ã å 容ã«ã¤ãã¦ã¯ãã¡ã¢ã£ããã®ãå¾ã»ã©ã¾ã¨ãã¦å ¬éããäºå®ã ã¿ããªæ¸ãã¦ããã®ã§ããã¾ããã¾ã£ã¡ããã¿æ¸ãã¦ã¾ãããã¹ãå¥ã«ã¾ã£ã¡ãã ããµãã®æ¥è¨â ã¨ããã©ãµãã¼ãâ ã«è¼ãããããããããªããªããã ããã!!(CV: éå®®çæµ) æ¬æ¥ã®åèè³æï¼ã»ãã¥ãªãã£&ããã°ã©ãã³ã°ãã£ã³ã2008 - xcorp::When it rains, it pours. ã¾ã£ã¡ãã®ç®è¦ã¾ãã§åºããã¿(http://d.hatena.ne.jp/hnw/20080823)ã®åèã« http://
ããã¯ã管ç人yamagataãæ¹éæªå®ã®ã¾ã¾ãä½ã¨ãªã¼ãæãã¤ãããã¨ãæãã¤ããã¾ã¾ã«ã ãã ãã¨æ¸ãä»ããæ¥è¨å¸³ã§ãããµãããã»ããããªæãã§ãé¡ããã¾ãã
é¡åã®éãã§ããããã¾ã£ã¡ãï¼ï¼ï¼åå¼·ä¼ãã«åå ãã¦ãã¾ãããå ´æã¯äº¬æ¥è²ç°ãã°ã®PiOã§ãã ããã¯ããã¾ã£ã¡ãï¼ï¼ï¼åå¼·ä¼ãã¨ããã»ãã¥ãªãã£ã®åå¼·ä¼ã大éªã§å®æéå¬ããã¦ãããã§ããããããæ±äº¬ã«é²åºãã¦ãããã®ã§ããæåã«åå è ã®èªå·±ç´¹ä»ã¿ã¤ã ããã£ããã§ãããèãã¦ããã¨ããã¾ã¾ã§å§çºã§å¤§éªã«è¡ã£ã¦ãã®ãæ±äº¬ã§éå¬ãã¦ãããã¨å©ãããã¿ãããªäººãä½äººããã¦ãç±å¿ãªäººããããããããªããã¨æãã¾ããã åå¼·ä¼æ¬ä½ã¯13:00ããã ã£ããã§ãããæ10:30ããLTã®æ ããã£ã¦ããXSSèå¼±æ§ã«å¯¾ãXHRãç¨ããæ»æãã¨ããé¡åã§åã15åã»ã©åãã¾ãããå 容ã¨ãã¦ã¯ãXSSã«å¯¾ãã¦XHRã使ãã°å¤¢ãåºãããããã¨ãããã¨ã§ãããã¾ãä»ã®äººã主張ãã¦ãã®ãè¦ãäºãç¡ãã®ã§æ°ãã¿ãããããªããã©ãã¨ããããã»ãã¥ãªãã£çéã®äººã«æ¬ã£ã¦ããããã¨æã£ã¦åã£ã¦ã¿ã¾ããã è³æ: http:
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}