ã¿ããªã§ä½¿ãããµã¤ãã¼ã»ãã¥ãªãã£ã»ãã¼ã¿ã«ãµã¤ã
ã¿ããªã§ä½¿ãããµã¤ãã¼ã»ãã¥ãªãã£ã»ãã¼ã¿ã«ãµã¤ã
(Last Updated On: 2021å¹´6æ17æ¥) CWE-20ã¨ã¯ä½ãï¼ã¨èããã¦å³çã§ããéçºè ã¯å¤ããªãã¨æãã¾ããããããCWEã¨ã¯ä½ãï¼ããã¾ãç¥ããã¦ããªãããç¥ãã¾ããã å®ã¯CWE-20 ä¸é©åãªå ¥åããªãã¼ã·ã§ã³ ã¯ã½ããã¦ã§ã¢ã»ãã¥ãªãã£ã§æãéè¦ãªèå¼±æ§ã¨ããã¦ãã¾ããCWEã®ã¿ã§ãªãæ å ±ã»ãã¥ãªãã£æ¨æºçã«æ å ±ã»ãã¥ãªãã£é¢é£æ³çã«ãã â» CWE: Common Weakness Enumeration (å ±éèå¼±æ§ã¿ã¤ã) CWEã¯èå¼±æ§èå¥åã®CVEã§æåãªMITREï¼ç±³å½ã§ã®IPAã®æ§ãªçµç¹ï¼ã管çããã½ããã¦ã¨ã¢èå¼±æ§ãã¿ã¼ã³ãåæããããã¥ã¡ã³ãï¼ãã¼ã¿ãã¼ã¹ã§ããæ¥æ¬èªåã®éããããããå ±éã®ã½ããã¦ã§ã¢èå¼±æ§ãéããç©ãCWEã§ãã CWE-20ã®è§£èª¬ â CWE/SANS Top 25 Monster Mitigation M1 å®ã¯æ ã ç§
ååããã©ãã¯ãªã¹ãåãã¡ã¤ã¤ã¼ã¦ã©ã¼ã«ã¨ãã¦ãããã¯ã¼ã¯ACLï¼NetworkACLï¼ãç´¹ä»ãã¾ãããã»ãã¥ãªãã£ã°ã«ã¼ãã¨ã®å½¹å²ã®éãã解ãé£ãã¨ãããããã®ã§ãæ¹ãã¦æ´çãã¦ã¿ããã¨æãã¾ãã ãããã¯ã¼ã¯ACLï¼NetworkACLï¼ã¨ã»ãã¥ãªãã£ã°ã«ã¼ãï¼SecurityGroupï¼ã®éã ã¾ãã»ãã¥ãªãã£ã°ã«ã¼ãã¨ãããã¯ã¼ã¯ ACLã®éãã¯ä½ã§ããããï¼ããã¯ãå ¬å¼ã®ããã¥ã¡ã³ãã«è¡¨å½¢å¼ã§ã¾ã¨ãããã¦ãã¦é常ã«è§£ããããã®ã§ãæ¯éä¸åº¦è¦ã¦é ããã°ã¨æãã¾ãã表ã転è¼ããã¨ä»¥ä¸ã®éãã§ãã ã»ãã¥ãªãã£ã°ã«ã¼ã ãããã¯ã¼ã¯ ACL ã¤ã³ã¹ã¿ã³ã¹ã¬ãã«ã§åä½ãã¾ãï¼ç¬¬ 1 ä¿è·ã¬ã¤ã¤ã¼ï¼ ãµããããã¬ãã«ã§åä½ãã¾ãï¼ç¬¬ 2 ä¿è·ã¬ã¤ã¤ã¼ï¼ ã«ã¼ã«ã®è¨±å¯ã®ã¿ããµãã¼ãããã¾ã ã«ã¼ã«ã®è¨±å¯ã¨æå¦ããµãã¼ãããã¾ã ã¹ãã¼ããã«: ã«ã¼ã«ã«é¢ä¿ãªããè¿ããããã©ãã£ãã¯ãèªåçã«
GUIã¢ããªã±ã¼ã·ã§ã³å Burp Suite ZAP zap-cli Fiddler Vex Watcher X5S ã³ã³ã½ã¼ã«ã¢ããªã±ã¼ã·ã§ã³åï¼CUIåï¼ SQLMap NoSQLMap w3af Arachni (çµäº) SCNR Scan My Server (â»æä¾çµäº) WhatWeb Skipfish Nikto Vega Grabber Wapiti WebScarab Ratproxy Wfuzz Grendel-Scan WAScan Paros SaaSå VAddyï¼ããã£ï¼ AeyeScanï¼ã¨ã¼ã¢ã¤ã¹ãã£ã³ï¼ komabatoï¼ã³ãããï¼ Securifyï¼ã»ãã¥ãªãã¡ã¤ï¼ secuasï¼ã»ãã¥ã¢ãºï¼ Walti (â»æä¾çµäº) ç¹å¾´ 診æç¨®å¥ ãWeb Serverãã®ã¹ãã£ã³çµæ Acunetix WVS Qualys - Web Application
ã¨ã°ã¼ã¯ãã£ããµã㪠èææ°è社ãéå¶ããé販ãµã¤ããSOKAãªã³ã©ã¤ã³ã¹ãã¢ããã2,481件ã®ã¯ã¬ã¸ããã«ã¼ãæ å ±ãæ¼æ´©ããããªãªã¼ã¹ã«ããã¨ãæ¼æ´©ã«ä½¿ãããæå£ã¯å¾æ¥ã¨ã¯ç°ãªããã®ã§ãæ¹æ£å²è³¦è²©å£²æ³ã®å®åä¸ã®ã¬ã¤ãã©ã¤ã³ã§ãããã¯ã¬ã¸ããã«ã¼ãæ å ±éä¿æåãã§ã¯å¯¾çã§ããªããã®ã§ãã£ãã ã¯ããã« ä»å¹´ã®9æ4æ¥ã«èææ°è社ã®é販ãµã¤ãSOKAãªã³ã©ã¤ã³ã¹ãã¢ããã¯ã¬ã¸ããã«ã¼ãæ å ±æ¼æ´©ã®å¯è½æ§ããªãªã¼ã¹ããã¾ããã以ä¸ã¯èææ°è社ããéå¶å§è¨ããã¦ãããã©ã³ã¹ã³ã¹ã¢ã¹æ ªå¼ä¼ç¤¾ã®ãªãªã¼ã¹ã§ãã ãSOKAãªã³ã©ã¤ã³ã¹ãã¢ãã®ä»¶ ãã®ãã³ãå¼ç¤¾ãèææ°è社æ§ããéå¶ãå§è¨ããã¦ãããSOKAãªã³ã©ã¤ã³ã¹ãã¢ãã«ããã¦ãã¯ã¬ã¸ããã«ã¼ãæ å ±ãå ¥åãã¦ååãã注æããã ããä¸é¨ã®ã客ãã¾ã®ã¯ã¬ã¸ããã«ã¼ãæ å ±ãã第ä¸è ã«ãã£ã¦ä¸æ£ã«åå¾ãããå¯è½æ§ããããã¨ãçºè¦ã ããã¾ããã http
ãªããªãçããã¢ã¤ãã ããã¶ã¤ã³ãããææã®ã¢ã¤ã³ã³ç´ æãã1é±ééå®ã§ç¡æã§ãã¦ã³ãã¼ãã§ããã®ã§ç´¹ä»ãã¾ãã åçé¢é£ããã¶ã¤ã³é¢é£ãããã°ã©ãã³ã°é¢é£ãã»ãã¥ãªãã£é¢é£ãã·ã§ããã³ã°é¢é£ãªã©ã260種é¡ã®ã«ã©ã¼ã¢ã¤ã³ã³ã¨260種é¡ã®ã¢ãã¯ãã¢ã¤ã³ã³ãæã£ã¦ãã¾ãã
2018å¹´ã®ãã¬ã³ãã¯ãDevOpsã«ã»ãã¥ãªãã£ãèåãããDevSecOpsãï¼å¤¢ç©èªã§çµããããªããDevOpsãï¼6ï¼ï¼1/2 ãã¼ã¸ï¼ è¿ éãªãµã¼ãã¹å±éãç¶æãã¤ã¤ãã»ãã¥ãªãã£ãã©ãæ ä¿ããã°ããã®ããDevOpsã«ããããã®èª²é¡ã¸ã®çãã¯ãDevOpsã®æ°ããªãã¬ã³ããDevSecOpsãã«ãã®çããããã®ã§ãã 2018å¹´ã¯ãDevOpsãã¨ã³ã¿ã¼ãã©ã¤ãºITã®ä¸çã«ã浸éããå¹´ã«ãªãââãååã®è¨äºã§ã¯ãããªã話ããã¾ãããã¦ã¼ã¶ã¼ä¼æ¥ãDevOpsã«å¯¾ãã¦æã¤èª²é¡ãããè¿ éæ§ã®åä¸ãã¨ãã£ããµãããã¨ãããã¼ããããè¿ éããå®ç¾ããéãå ·ä½çã«é害ã¨ãªãäºæã¸ã¨å¤ãã£ã¦ãã¦ãã¾ãã ä»åã¯ãã®ä¸ã§ããè¿ éãªãµã¼ãã¹å±éãç¶æãã¤ã¤ãã»ãã¥ãªãã£ãã©ãæ ä¿ããã®ããã¨ãããã·ã¹ãã éçºããã»ã¹ã«ãããDevOpsã®èª²é¡ã«ã¤ãã¦ãèãã¦ããã¾ãããã ã»ãã¥ãªãã£ã®ãã¹ã
ãã¡ãããèå¼±æ§ã®å 容ã«å¤§ããä¾åããã®ã§ãããå ¨ã¦ã§ã¯ããã¾ããããã 対çã確ç«ããã¦ããªãã®ã«æ»æã³ã¼ããåºåã£ã¦ãã¦ãæ»æäºä¾ãå ±åããã¦ããã®ãæãã¤ã㤠ãã£ã¦ããèªèã¯æã£ã¦ããã¹ãã§ãããã èå¼±æ§ã®å½±é¿æç¡ ä¸éãé¨ãããèå¼±æ§ããã£ãã¨ãã¦ãã該å½æ©å¨ããªããã°é¨ãå¿ è¦ãå½ç¶ãªãã§ãããæ»æãããããªãä»çµã¿ã«ãªã£ã¦ããã¨ããããããæ°ã«ããå¿ è¦ã¯ããã¾ããã ããããæå³ã§ã対象ã®èå¼±æ§ãèªã·ã¹ãã ã«å½±é¿ãããã®ãã©ããã調ã¹ãå¿ è¦ãããã¾ãã観ç¹ã¨ãã¦ã¯ä»¥ä¸ã¨ãªãã¾ãã 該å½ãã¼ã¸ã§ã³ã®æç¡ æ»ææ¡ä»¶ã®æç«å¯å¦ 該å½ãã¼ã¸ã§ã³ã®æç¡ èå¼±æ§ã¯å½±é¿ç¯å²ããã¡ã¾ããæãããã®ãã½ããã¦ã§ã¢ãã¼ã¸ã§ã³ã§ãã ãã¼ã¸ã§ã³X以é ãã§ãã£ããã ãã¼ã¸ã§ã³YããZã®é ããªã©ã¨è¡¨ç¾ãããããã¾ãã ã½ããã¦ã§ã¢ã«ãã£ã¦ã¯ããã¼ã¸ã§ã³ã®åå¾é¢ä¿ãèªã¿ã¥ããã£ããããã¨æãã®ã§ã
ä»æ¥ãã使ããã¯ã©ã¦ãå Webèå¼±æ§è¨ºæãã¼ã« Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§è¨ºæã 社å ã§å®æ½ãã¾ãããï¼ VAddyãªãã»ãã¥ãªãã£å°é家以å¤ã®æ¹ã èå¼±æ§è¨ºæãã§ãã¾ãã 1é±éç¡æãã©ã¤ã¢ã«ã§ã¯ããã ãªã³ã©ã¤ã³åå¥ç¸è«ä¼ å®æ½ä¸ï¼
ãã¹ãã£ã¼ãã¯ãä»®æ³é貨ã§ãéã¹ããªã³ã©ã¤ã³ã«ã¸ãã§ããä»®æ³é貨ã§ã®å ¥éã«ã¯ãBitcoinãEthereumãLitecoinãBitcoin Cashãªã©ã使ç¨ã§ãã¾ããã¾ããåºéãä»®æ³é貨ã§è¡ããã¨ãã§ãã¾ãã ã¾ãããã¹ãã£ã¼ãã§ã¯ãã¹ãããããã¼ãã«ã²ã¼ã ãã©ã¤ãã«ã¸ãããã¼ã«ã¼ããããªãã¼ã«ã¼ããã«ã©ããµã¤ã³ããªã©ãæ§ã ãªãªã³ã©ã¤ã³ã«ã¸ãã²ã¼ã ã楽ããã¾ããããã«ãã¹ãã¼ããã©ã³ãã¿ãã¬ããã§ã®ãã¬ã¤ãå¯è½ã§ãã®ã§ããã¤ã§ãã©ãã§ãã«ã¸ãã²ã¼ã ã楽ãããã¨ãã§ãã¾ãã å®éã«ãã¹ãã£ã¼ãã§éãã§ã¿ãææ³ ãã¹ãã£ã¼ãã§ã¯ãæ°è¦ç»é²ãå ¥éãªã©ã«å¿ãã¦ããã¾ãã¾ãªãã¼ãã¹ãæä¾ããã¦ãã¾ãã æ°è¦ç»é²ãã¼ãã¹ã¨ãã¦ã¯ãå ¥éä¸è¦ã§æã«å ¥ããããªã¼ã¹ãã³ããããã¾ããã¾ããå ¥éãã¼ãã¹ã¨ãã¦ã¯ãå ¥éé¡ã«å¿ãããããããã¼ãã¹ããæä¾ããããã¨ãããã¾ããããã«ããã¬ã¤ã¤ã¼ã®ã¬ãã«ãä¸ã
ãªã¯ã¹ããã¤ãã«ã³ãµã¤ ï½OWASPãã¼ã«ã«ãã£ãã¿ã¼ãã¼ãã£ã³ã° in é¢è¥¿ 10thï½ã§ãçºè¡¨ããã ãã æ±äº¬å¤§å¦æ å ±å¦ç°ãç¹ä»»ç 究å¡ãè¤æ¬ä¸éåããã®è³æã§ã
ããããæ°è¦ã§æ§ç¯ããéã¯ãIAMãã¹ããã©ã¯ãã£ã¹ã«æºããè¨è¨ãè¡ãã¾ããããå½ç¶ã§ãããã ã§ãããããªAWSã¢ã«ã¦ã³ãããã¾ãããï¼ çç´æãå®ç¾ããããã«ã¹ãã¼ãåªå ã§æ§ç¯ããAWSã¢ã«ã¦ã³ã ä»ã®ä¼ç¤¾ãæ§ç¯ããAWSã¢ã«ã¦ã³ããå¼ãç¶ãã§éç¨ä¸ AWSã«ç解ã®ãªãæ å½è ãåæè¨å®ãããAWSã¢ã«ã¦ã³ããå©ç¨ä¸ å®æçãªã»ãã¥ãªãã£ã®è¦ç´ãããã¦ããªã2年以ä¸åã®AWSã¢ã«ã¦ã³ã 便å©ã ãããããã¡ãã¨ããã»ãã¥ãªãã£ã®è¨è¨ã¨éç¨ãAWSã¯éè¦ã§ãã æ¡ãå²ãåã«ä¸åº¦AWSã®ã»ãã¥ãªãã£ãè¦ãªããã¦ã¿ã¾ãããï¼ â 念ã®ããã®æä½ãã°ãã§ã㯠大ä¸å¤«ã ã¨ä¿¡ãã¦çããããªãããã©ã念ã®ãããã§ãã¯ããã¾ãããã 確èª1ï¼ã«ã¼ãã¢ã«ã¦ã³ãã§é常æä½ãè¡ã£ã¦ããªã ããããããã®æ¹æ³ã§ç¢ºèªããã¦ãã ããã 確èªæ¹æ³1 CloudTrailããCloudWatch Logsã¸ãã°é ä¿¡è¨å®ãã
ãã³ã¢ã»ã¯ã©ã¦ãããã±ã¼ã¸ã«ã¤ãã¦
ã¯ããã« ããã«ã¡ã¯ãã³ã«ã³ã¼ã©ã大好ããªã«ã¸ã§ãã å½ã¨ã³ããªã¯Developers.IOã§å¼ç¤¾AWSãã¼ã ã«ãããAWS ãµã¼ãã¹å¥ åå ¥éã¢ããã³ãã«ã¬ã³ãã¼ 2015ãã®12æ¥ç®ã®ã¨ã³ããªã§ããæ¨æ¥11æ¥ç®ã®ã¨ã³ããªã¯å°å±±ã®ãAWS Directory Serviceãã§ããã ãã®ã¢ããã³ãã«ã¬ã³ãã¼ã®ä¼ç»ã¯ãæ®æ®µAWSãµã¼ãã¹ã«ã¤ãã¦ææ°ã®ãã¿ã»æ·±ã/ç´°ãããã¼ãã主ã«æ¸ãé£ãã¦ããã¡ã³ãã¼ã®æã«ãã£ã¦ãä»ä¸åº¦åå¿ã«è¿ã£ã¦ãåºæ¬çãªé¨åãè¦ã¤ãç´ãã¦ã¿ããã解説ãã¦ã¿ããã¨ããã³ã³ã»ãããå«ã¾ãã¦ãã¾ãããæ¬æ¥12æ¥ç®ã®ãã¼ãã¯ãAmazon Inspector(Preview)ãã§ããæ£å¼ãµã¼ãã¹ããã¦ããªããããäºç¿ã¨ãªãã¾ãã 2015/12/12ç¾å¨ãAmazon Inspectorã¯ãã¬ãã¥ã¼ã§ãã æ¬è¨äºã®å 容ã¯æ£å¼ãªãªã¼ã¹æã«å¤æ´ãããå¯è½æ§ãããã¾ãã ç®æ¬¡ A
西澤ã§ããå æ¥ãCIS(Center for Internet Security) Benchmarkãèªãã§ã¿ãã¨ãããã¨ã¦ãåå¼·ã«ãªã£ãã®ã§ãã»ãã¥ãªãã£ã«å¯¾ããç¥è¦ãæ·±ããçºãå°ãå¤ããã®ãªã®ã§ãããAmazon Linuxçããã£ããèªãã§ã¿ããã¨ã«ãã¾ããã CISãã³ããã¼ã¯ã®èª¬æçãååã®è¨äºã¯ãã¡ã ããªãã®AWSã»ãã¥ãªãã£ç£æ»ç¶æ³ãæ¡ç¹ãCISãã³ããã¼ã¯ãèªãã§ã¿ã ï½ Developers.IO Amazon LinuxçCISãã³ããã¼ã¯ Amazon Linuxã®ææ°çã¯ãå æ¥ãªãªã¼ã¹ãããAmazon Linux AMI 2016.03ã§ãããCISãã³ããã¼ã¯ã®å¯¾å¿ã¯2015.03ã¾ã§ã®ããã§ããå°ã å¤ããã¼ã¸ã§ã³ã«ã¯ãªãã¾ãããå¿ ãåèã«ãªãç¹ãããã¯ãã§ãã Level1ãScoredãåªå ã«èªã¿é²ãã¦è¡ãã¨ããã¯å æ¥ã®è¨äºã¨åæ§ã§ããããã§ã¯ãæ©é詳ã
ãµã¤ãã¼æ»æã®å¢å ã»é«åº¦åã«å ãã社ä¼çãªITä¾å度ã®é«ã¾ãããããµã¤ãã¼æ»æã«ãã社ä¼çè å¨ãæ¥éã«å¢å¤§ãã¦ãã¾ããããªãã¡ãµã¤ãã¼ã»ãã¥ãªãã£å¯¾çã¯ãçµå¶ãªã¹ã¯ã¨ãã¦ãããã¦ç¤¾ä¼ç責任ã¨ãã¦ãé常ã«éè¦ãªèª²é¡ã«ãªãã¤ã¤ããããã®è²¬ä»»ãæ ãã人æã®ç¢ºä¿ãæ¥åã¨ãªã£ã¦ãã¾ãããã®äººæã®ç¢ºä¿ã®ããã«2016å¹´10æã«ãæ å ±å¦çã®ä¿é²ã«é¢ããæ³å¾ããæ¹æ£ãããæ°ããªå½å®¶è³æ ¼ãèªçãã¾ãããããããæ å ±å¦çå®å ¨ç¢ºä¿æ¯æ´å£«ï¼ç¥ç§°ï¼ç»é²ã»ãã¹ãï¼ãã§ãã æ¬ãã¼ã¸ã§ã¯ããæ å ±å¦çå®å ¨ç¢ºä¿æ¯æ´å£«ï¼ç»é²ã»ãã¹ãï¼ãå¶åº¦ã«é¢ããæ å ±ãæ²è¼ãã¦ãã¾ãããã²ã覧ãã ããã æ å ±å¦çå®å ¨ç¢ºä¿æ¯æ´å£« æ°è¦ç»é²ã»æ´æ°ã®ãæ¡å 2024å¹´7æï½8æã«ãå½å®¶è³æ ¼ãæ å ±å¦çå®å ¨ç¢ºä¿æ¯æ´å£«ãããããï¼èª¬æä¼ããå®æ½ãã¾ããã å½å®¶è³æ ¼ãæ å ±å¦çå®å ¨ç¢ºä¿æ¯æ´å£«ãããããï¼èª¬æä¼(2024å¹´7æ4æ¥ï½8æ15æ¥ãªã³ããã³ãé ä¿¡
JavaScriptã«ãããã©ã¦ã¶ä¸ã§ã®å¦çéããã³ã³ã¼ãéã®å¢å ã«ä¼´ããJavaScriptä¸ã®ãã°ãåå ã§çºçããèå¼±æ§ãå¢å ãã¦ãã¾ãããã®ãããªèå¼±æ§ã®æã代表çãªãã®ããDOM-based XSSã§ããä»åããæ°åã«åãã¦ãDOM-based XSSã«ã¤ãã¦èª¬æãã¦ããã¾ãã DOM-based XSSã¨ã¯ æ¬é£è¼ç¬¬2åã§èª¬æãããããªä¸è¬çãªåå°åããã³èç©åã®XSSã®ã»ã¨ãã©ã¯ãWebã¢ããªã±ã¼ã·ã§ã³ããµã¼ãä¸ã§HTMLãçæããéã«ãæ»æè ãæå®ããæååã®ã¨ã¹ã±ã¼ããæ¼ãã¦ãããã¨ãåå ã§çºçãã¾ããä¸æ¹ãDOM-based XSSã¯ããµã¼ãä¸ã§ã®HTMLã®çææã«ã¯åé¡ã¯ãªãããã©ã¦ã¶ä¸ã§åä½ããJavaScriptä¸ã®ã³ã¼ãã«åé¡ãããããã«çºçãã¾ãã ãã¨ãã°ã以ä¸ã®ãããªJavaScriptã³ã¼ãããã£ãã¨ãã¾ãã // bad code div = docum
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}