microscannerã¯ãCVEãã¼ã¹ã§Dockerã¤ã¡ã¼ã¸ã®èå¼±æ§æ¤æ»ããããã¼ã«ã§ããç°¡åã«å°å ¥ã§ããã¤æç¨ãªã®ã§ãå°å ¥æ¹æ³ã¨å©ç¨ä¸ã®æ³¨æäºé ãªã©ãã¾ã¨ãã¾ããã å æ¥ã¬ãã¼ããããDocker漬ãã®ä¸æ¥ãå ±ã«ãDocker Meetup Tokyo #23ãã¯ãæ å ±éãã¦ããçãã§ãå¦ã³å¤ãã¦æ¥½ããã¦ã¯ãã»ãã¤ã ã£ããã§ããããã®ä¸ã§ãã¨ã(@CS_Toku)ãããLTçºè¡¨ããã¦ãããKubeConå ±åã¨microscanner試ãã¦ã¿ããã®microscannerããé¢ç½ããã ã£ãã®ã§æ©é触ã£ã¦ã¿ã¾ããã Dockerfileã«4è¡è¿½å ããã ãã§ãCVEãã¼ã¹ã®èå¼±æ§æ¤æ»ãç¡æã§å©ç¨ã§ããæ¢åã®ã¤ã¡ã¼ã¸ãã«ãã«çµãããã®ããæ軽ãããªã®ã§ãããããã³ã³ããå°å ¥ãããã¨æã£ã¦ãã人ããæ¢ã«æ¬çªã§ã¬ã³ã¬ã³ã³ã³ãã使ã£ã¦ãã人ããä¸åº¦å°å ¥ãæ¤è¨ãã¦ã¿ã¦ã¯ãããã§ããããã __ ï¼ç¥ï¼
ãã¡ãããèå¼±æ§ã®å 容ã«å¤§ããä¾åããã®ã§ãããå ¨ã¦ã§ã¯ããã¾ããããã 対çã確ç«ããã¦ããªãã®ã«æ»æã³ã¼ããåºåã£ã¦ãã¦ãæ»æäºä¾ãå ±åããã¦ããã®ãæãã¤ã㤠ãã£ã¦ããèªèã¯æã£ã¦ããã¹ãã§ãããã èå¼±æ§ã®å½±é¿æç¡ ä¸éãé¨ãããèå¼±æ§ããã£ãã¨ãã¦ãã該å½æ©å¨ããªããã°é¨ãå¿ è¦ãå½ç¶ãªãã§ãããæ»æãããããªãä»çµã¿ã«ãªã£ã¦ããã¨ããããããæ°ã«ããå¿ è¦ã¯ããã¾ããã ããããæå³ã§ã対象ã®èå¼±æ§ãèªã·ã¹ãã ã«å½±é¿ãããã®ãã©ããã調ã¹ãå¿ è¦ãããã¾ãã観ç¹ã¨ãã¦ã¯ä»¥ä¸ã¨ãªãã¾ãã 該å½ãã¼ã¸ã§ã³ã®æç¡ æ»ææ¡ä»¶ã®æç«å¯å¦ 該å½ãã¼ã¸ã§ã³ã®æç¡ èå¼±æ§ã¯å½±é¿ç¯å²ããã¡ã¾ããæãããã®ãã½ããã¦ã§ã¢ãã¼ã¸ã§ã³ã§ãã ãã¼ã¸ã§ã³X以é ãã§ãã£ããã ãã¼ã¸ã§ã³YããZã®é ããªã©ã¨è¡¨ç¾ãããããã¾ãã ã½ããã¦ã§ã¢ã«ãã£ã¦ã¯ããã¼ã¸ã§ã³ã®åå¾é¢ä¿ãèªã¿ã¥ããã£ããããã¨æãã®ã§ã
2017/9/2 OWASP Kansai ãã¼ã«ã«ãã£ãã¿ã¼ãã¼ãã£ã³ã° ãããææãµã¼ã(OWASP BWA)ãç¨ãããOWASP ZAPã®ç°¡åãªä½¿ãæ¹ç´¹ä»
ä»åã¯ãªã¼ãã³ã½ã¼ã¹ã®èå¼±æ§ã¹ãã£ãã§ãã OpenVAS ã使ã£ã¦ã¿ããã¨ã«ããã èå¼±æ§ã¹ãã£ãã¨ããã®ã¯ããã¹ãã«æ¢ç¥ã®èå¼±æ§ãå«ã¾ããªããã©ãããèªåã§ã¹ãã£ã³ãã¦ããããã¼ã«ã 注æ: èå¼±æ§ã¹ãã£ã³ã¯ãã¼ãã¹ãã£ã³ããããã¬ã¼ã·ã§ã³ãå«ãããå¤é¨ã®ãµã¼ãã«ã¯å®è¡ããªãã㨠使ã£ãç°å¢ã¯æ¬¡ã®éããOS 㯠Ubuntu 16.04 LTS ã«ããã $ lsb_release -a No LSB modules are available. Distributor ID: Ubuntu Description: Ubuntu 16.04.3 LTS Release: 16.04 Codename: xenial $ uname -r 4.4.0-89-generic ã»ãã¥ãªãã£ç¨éã 㨠Kali Linux ã使ããã¨ãå¤ãã¿ããã ã¤ã³ã¹ãã¼ã« Ubuntu 㧠OpenVA
ãµã¤ãªã¹ãã¯ããã¸ã¼ã®ã¨ã³ã¸ãã¢ã ã¯ã©ã¦ããOSSãèªè¨¼ã«é¢ããæ§ã ãªæ å ±ãæä¾ãã¾ãã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}