æ°å¹´åã§ããã°ä»æ¹ãªãã£ãã¨ããã§ããã2018å¹´ã®ä»ã¨ãªã£ã¦ã¯ããã¹ã¯ã¼ãããã·ã¥ã®æåè¨ç®ã¯ãã¯ã"æª"ã§ãã ã¾ããã°ã¤ã³èªè¨¼ã¨ç§°ãã¦md5ã¨ãsha1ã¨ãæ¸ãã¦ããã½ã¼ã¹ã¯ã´ããªã®ã§æãæ¨ã¦ã¾ãããã hashãcryptã¯ä¸è¨ã«æ¯ã¹ãã°ãã£ã¨ãã·ã§ãããä½¿ãæ¹ã«ãã£ã¦ã¯ç°¡åã«èå¼±ã«ãªããã¾ãã ãã¨ããã¹ã¯ã¼ããæå·åãããã£ã¦è¡¨ç¾ãã¦ãã¨ãããè¦ãªãã¦ããã§ãã PHPã«ã¯ãããã·ã¥ã«é¢ãã諸ã ã®è½ã¨ãç©´ãä¸çºã§è§£æ¶ãã¦ãããpassword_hashã¨ããè¶ çµ¶ä¾¿å©é¢æ°ãããã®ã§ãããã使ãã¾ãã ã¨ãããããã以å¤ã使ã£ã¦ã¯ããã¾ããã 以ä¸ã¯ãã¬ã¼ã ã¯ã¼ã¯ã使ããã«å®è£ ããéã®ä¾ç¤ºã§ãã ãã¬ã¼ã ã¯ã¼ã¯ã使ã£ã¦ããå ´åã¯å½ç¶ãã®æµåã«å¾ã£ã¦ããã¾ãããã ããã·ã¥ã®å®è£ ãã¼ã¿ãã¼ã¹ ã¦ã¼ã¶æ å ±ãä¿åãããã¼ãã«ã使ãã¾ãã ãã¹ã¯ã¼ãã«ã©ã ã®æåæ°ã¯ãã·ã¹ãã ä¸ã®ãã¹ã¯
ä¸è¨ã®æç« ã¯ãPHPã®ã»ãã·ã§ã³IDã«å¯¾ããæ»æã«ã¤ãã¦Full Disclosure MLã«2010å¹´ã«æç¨¿ãããæç« ãå訳ãããã®ã§ãã訳è ã®æè¦ã¨ãã¦ã¯ãæ»æã®æç«æ¡ä»¶ã¯æ¥µãã¦å³ãããããã¾ã§æ·±å»åº¦ã¯é«ããªãã¨èãã¦ãã¾ãã ã¨ã¯ãããç似乱æ°åã¸ã®æ»æãã©ã®ããã«è¡ãããã®ãããã®å¯è½æ§ã示ãæç« ã¯æ¯è¼ççãããã®ã®ããã«æãã¾ããæå·è«çã«å®å ¨ãªç似乱æ°ã¨ã¯ä½ãããªãå¿ è¦ãªã®ãã¨ãã£ãå 容ã鿥çã«æãã¦ãããé¢ç½ãæç« ã ã¨æãã¾ããã®ã§ãä»å翻訳ãã¦ã¿ã¾ããã ï¼ä»¥ä¸ãåæã®å訳ã§ãï¼ åæï¼http://seclists.org/fulldisclosure/2010/Mar/519 Advisory (c) 2010 Andreas Bogk <andreas () andreas org> Product:PHP Version:5.3.2 以é èå¼±æ§ã®ç¨®é¡:æå·è«çãª
11/15ã«éå¬ããããã¡ãã®åå¼·ä¼ã«åå ãããã¾ããï¼ ãããã¬ã§WordPressæ¬ä½ããã©ã°ã¤ã³ã®èå¼±æ§ã追ãããã¦ã¿ãã - connpass ãã¡ãã®åå¼·ä¼ã¯ããWordPressæ¬ä½ã¨ãã©ã°ã¤ã³ã®èå¼±æ§ããããã¬ã§è¿½è·¡ãããã¨ã«ãããèå¼±æ§ã®ä¸èº«ã«ã¤ãã¦è©³ãã追跡ããçè§£ãæ·±ãããã¨ããå 容ã®ãã®ã§ããããªãã¨ãã®å¾³ä¸¸æµ©ãããè¬å¸«ãããã¦ãã¾ãï¼ ç§å人ã¨ãã¦ã¯ãä»äºã¨ãããååè¶£å³ã§ããããèå¼±æ§ã®æ¤è¨¼ããã¦ãããä»åã®åå¼·ä¼ã¯ã¾ãã«èªåã®èå³åéã«ãã³ãã·ã£ãªå 容ã ã£ãã®ã§ãéå¸¸ã«æ¥½ããã§åå ããã¦ããã ãã¾ããï½ ç§ã¯ãã¡ãã®åå¼·ä¼ã«ããã°æ ã¨ãã¦åå ãããã¾ããã®ã§ãåå¼·ä¼ã®å 容ã«ã¤ãã¦æ¬ããã°ã«ã¦ã¬ãã¼ããããã¾ãã åæå¯¾è±¡ã®èå¼±æ§ã«ã¤ã㦠ä»ååæãã顿ã¨ãªã£ãèå¼±æ§ã¯ä»¥ä¸ã®äºã¤ã§ãã ãªããäºã¤ã®èå¼±æ§ã¨ã徳丸ããã詳細ãªè§£èª¬è¨äºãããã°ã«ã¦å ¬éããã¦ããã¾ã
WordPressã®ä»äºããã¦ããã¨ãç¨ã«PHP5.1.6ã¨ããåãã¦ãããµã¼ãã¼ã®ã客ããããä¾é ¼ãé ããã¨ããã£ããããã ã§ããã°éçºç°å¢ã¯ã客ããã®ãµã¼ãã¼ã¨ä¸ç·ã®ç¶æ ã§éçºãããã®ã§ãPHP5.1ï¼MySQL5.0ã®ç°å¢ãä¸çºã§æ§ç¯åºæ¥ãDockerãã¡ã¤ã«ãæ¸ããã 仿§ CentOS 6.6 Apache 2 PHP 5.1.6 MySQL 5.0ï¼å使ªç¢ºèªï¼ SSHã§ãã°ã¤ã³å¯ WordPressåãã«PHPã®æ¡å¼µã¢ã¸ã¥ã¼ã«ã¨ãhttpd.confã¨ãphp.iniã¨ãæä½éã®è¨å®è¾¼ã¿ WP-CLIã¨ãXdebugã¨ãComposerã¨ãã¯ç°å¢ãå¤ãã¦åããªããã ã£ãã®ã§å ¥ãã¦ããªãã Dockerfile FROM centos:6.6 MAINTAINER m.ietomi <jyokyoku@gmail.com> # TimeZoneã®è¨å® RUN echo 'ZO
2017å¹´10æã«PHP5.3.3ç°å¢ãä½ãã®ã¯ã¨ã¦ã大å¤ã§ããã PHP5.3ã¯ãã§ã«EOLãè¿ãã¦ãããããã»ãã¥ãªãã£ãã¼ã«ãä¿®æ£ãããã«æ®ãããå±éºæ§ããã£ããã¨ãããã¯ã·ã§ã³ã§ä½¿ãç¶ããã®ã¯å¤§å¤ãããããªãã§ããã大人ã®é½åã§ã©ããã¦ãå¿ è¦ã«ãªã£ã¦ãã¾ãã¾ããã PHP5.3ç°å¢ãæ§ç¯ããã«ããã£ã¦ã試ãã¦ãã¡ã ã£ããã¨ã¨ã䏿ãè¡ã£ããã¨ã¨ãæ®ãã¦ããããã¨æãã¾ãã 試ãã¦ãããªãã§ããªãã£ãã㨠Homebrewã®brew install php53 ãªãã/usr/local/bin/phpã ããä½ãããã macOSãHigh Sierraã«ã¢ãããã¼ããããããï¼ Sierraã®ã¨ãã¯ããã§è¡ããã ååããCellerå ã®php5.3.29ãã¾ãã£ã¨ããã£ãããæ¡å¼µã䏿ãå ¥ããã Docker Hubå ¬å¼ã®php:5.3-cli 5.3.29æªæºã¯æä¾ããã¦ããã
PHPãªãã¸ã§ã¯ãã¤ã³ã¸ã§ã¯ã·ã§ã³(PHP Object Injection)æ»æã«é¢ãã¦ã¾ã¨ãã¾ãããWebã®ã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æã¨ããã¨ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãOSã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³ãªã©ãå ã«æãæµ®ãã³ã¾ãããPHPã«ã¯ãªãã¸ã§ã¯ãã¤ã³ã¸ã§ã¯ã·ã§ã³ã¨å¼ã°ãããã®ãããã¾ãã PHPã«ããããªãã¸ã§ã¯ãã¤ã³ã¸ã§ã¯ã·ã§ã³ã¯ããã¼ã¿ã®ã·ãªã¢ã©ã¤ãºã«é¢ä¿ããunserialize颿°ã使ç¨ãã¦ããå ´åãå¤é¨ããå®å ¨ã§ãªãã·ãªã¢ã©ã¤ãºãããå¤ãæ³¨å ¥ããããã¨ã«ãããèå¼±æ§ã«ãªãããå¯è½æ§ãããã¾ããã©ã®ãããªå½±é¿ããããã©ããã¯ãã³ã¼ãã®æ¸ãæ¹ã«ãã£ã¦æ§ã ã§ãã æ¬ç¨¿ã¯ãç¬èªã®æ¤è¨¼ã調ã¹ã«ãããã®ã®ãããå³å¯ã«ã¯èª¤ãã§ãã£ãããããããéã£ã¦ããã¨ãããã¨ãããããããã¾ããã âèå¼±æ§ãåç¾ããã³ã¼ã ç°¡åã«èå¼±æ§ãåç¾ããã³ã¼ããç¨æãã¾ãããæ¬¡ã®æ»æã·ããªãªã¯ãã¼ã«ã«ã®hostsã
Joomla!ã«ã³ã¼ãå®è¡èå¼±æ§(CVE-2015-8562)ãããããããå ¬éåããæ»æã観測ããã¦ããã¨è©±é¡ã«ãªã£ã¦ãã¾ãã Joomlaã«æ·±å»ãªèå¼±æ§ããããå ¬é2æ¥åããæ»ææ¨ªè¡ ãJoomla!ãã«åã³æ·±å»ãªèå¼±æ§ã3.4.6ã¸ã®éãããªã¢ãããã¼ããæ¨å¥¨ ãããå ¬éã®åã«æ»æãå§ã¾ãç¶æ ããã¼ããã¤èå¼±æ§ãã¨è¨ãã¾ãããããã§ã¯ããã®èå¼±æ§ã®ã¡ã«ããºã ã¯ã©ããªãã®ã ãããã¨æãã調ã¹ã¦ã¿ã¾ããã çµè«ããè¨ãã°ããã®åé¡ã¯Joomla!å´ã«é大ãªèå¼±æ§ã¯ãªããPHPã®æ¢ç¥ã®èå¼±æ§(CVE-2015-6835)ãåå ã§ããã®ã§å ±åãã¾ãã exploitã調ã¹ã¦ã¿ã æ¢ã«ãã®åé¡ã®exploitã¯å ¬éããã¦ãã¾ãããæªãåãçä¼¼ããã¨ãããªãã®ã§URLçã¯å²æãã¾ãã以ä¸ã®ãã¼ã¸ã§ã¯æ»æã®åçã説æããã¦ãã¾ãã Vulnerability Details: Joomla! Re
hakaikosen.hateblo.jp ä¸è¨è¨äºãããã大å¤(æ£èªã¿)ãã¨ãæããªããèªãã§ããããã©ãPHP ã® BTS ã®æ¹ãèªãã§ã¿ãã確ãã«åçããåç¾æé ã¾ã§ç´°ããè¨è¼ããã¦ã㦠ããªããããã¾ããããã¨æã£ãã®ã§ãdocker ã使ã£ã¦æ¤è¨¼ãã¦ã¿ããã¨ã«ã PHP å ¥ãã® Docker ã³ã³ããã¯ãOfficial ã®ãã®ãå©ç¨ãã¾ãããregistry.hub.docker.com ä»åã®èå¼±æ§ãPOST ããªããã¼ã¸ã«ã¯é¢ä¿ãªãã®ããªï¼ã¨æã£ã¦ã¾ããããããããè¦ã㨠PHP ããåããã¼ã¸ã§ããã°ãªãã§ããããããã ã¨ãããã¨ã§ä»¥ä¸ã®ãã㪠PHP ãã¡ã¤ã«ãç¨æããããã«ã¢ã¯ã»ã¹ (æ»æ) ããã¾ãã htdocs/index.php <!DOCTYPE html> <html> <head> <title>PHP Bugs #69364</title> </he
XDRãAgentic SIEMãAgentic SOARã§åéããæ å ±ããæ»æã®ç«¯ç·ãå¯è¦åã鲿¢ãæ»æè ã«é ããä½å°ãä¸ãã¾ããã 詳ããã¯ãã¡ã
SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã¯ããªãæåã«ãªãã¾ãããããªãã¸ã§ã¯ãã¤ã³ã¸ã§ã¯ã·ã§ã³ã¯ã¾ã ãã¾ãèããªãã®ã§ãã¾ã¨ãã¦ããã¾ãã Dependency Injectionï¼DIï¼ã¨ã¯é¢ä¿ããã¾ããã ãªãã¸ã§ã¯ãã¤ã³ã¸ã§ã¯ã·ã§ã³èå¼±æ§ã¨ã¯ï¼ SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãå¤é¨ããSQLæãæ³¨å ¥ããæ»æã§ããã®ã¨åãããã«ããªãã¸ã§ã¯ãã¤ã³ã¸ã§ã¯ã·ã§ã³ã¨ã¯å¤é¨ãããªãã¸ã§ã¯ããæ³¨å ¥ããæ»æã§ãã å¤é¨ãããªãã¸ã§ã¯ããæ³¨å ¥ã§ããã°ããã®ãªãã¸ã§ã¯ãã®æ©è½ã«ãããã¾ãã¾ãªæ»æãã§ããå¯è½æ§ãããã¾ããææªã®å ´åãä»»æã®ã³ã¼ããå®è¡ã§ããèå¼±æ§ã«ãªãã¾ãã PHPã®å ´åããã®æ»æãå¯è½ãªã®ã¯ãunserialize()颿°ãæªç¨ã§ããå ´åã§ãã æ»æã®æ¹æ³ unserialize()颿°ã«å¤é¨ããä»»æã®ãã¼ã¿ã渡ãã³ã¼ãããã£ãå ´åãæ»æè ã¯èªç±ã«ã·ãªã¢ã©ã¤ãºããããã¼ã¿ãéä¿¡ãããã¨ã§ãçæããããªãã¸ã§
PHP is an open-source server-side scripting language, and it is a widely used. The Apache/Nginx/Lighttpd web server provides access to files and content via the HTTP OR HTTPS protocol. A misconfigured server-side scripting language can create all sorts of problems. So, PHP should be used with caution. Here are twenty-five php security best practices for Linux and Unix sysadmins for configuring PHP
æ¨å¤ã«ãéæ³å°å¥³ã¢ãããâãã®ã«æ»æã観測ãã¾ãããéæ³å°å¥³ã¢ãããâãã®ã«ã¨ã¯ãPoCã®ã½ã¼ã¹ã³ã¼ãã«Â Apache Magica by Kingcope ã¨ã³ã¡ã³ãããã¦ãããã¨ã«ç±æ¥ãã¦ãã¾ãï¼ã¨ããããç§ããã訳ãã¾ããwï¼ã ããã¯10æ29æ¥ã«PoCãçºè¡¨ãããPHP-CGIæ»æ(CVE-2012-1823)ã®å¤ç¨®ã§ãã徿¥ã®PHP-CGIæ»æã¯ãCGIçPHPãåä½ããç°å¢ã§ãPHPã¹ã¯ãªããï¼ä¸èº«ã¯ãªãã§ãããï¼ã«å¯¾ããæ»æã§ããããéæ³å°å¥³ã¢ããããã®ã«ã®æ¹ã¯ã/cgi-bin/ã«ç½®ãããPHPå¦çç³»ï¼php-cgiãªã©ï¼ã«ç´æ¥æ»æãããã®ã§ãã CGIçPHPãè¨ç½®ããæ¹æ³ã¯è¤æ°ããã¾ããããã使ãããæ¹æ³ã¨ãã¦Apacheã®ãªãã¤ã¬ã¯ãã«ããPHPã¹ã¯ãªãããPHPå¦çç³»ã«å®è¡ãããæ¹æ³ãããã¾ãããã®å ´åã/cgi-bin/php-cgiãªã©ã¨ãã¦PHPå¦çç³»ãå ¬é
CGIç°å¢ã§PHPãåä½ããã¦ãããµã¤ãã«ã¯ããªã¢ã¼ãããã¹ã¯ãªããå®è¡ã許ãã¦ãã¾ãèå¼±æ§ãããã¾ããphp.netããæä¾ããã¦ããä¿®æ£ãªãªã¼ã¹(PHP 5.3.12 / PHP 5.4.2)ã¯ä¸å®å ¨ãªããã該å½ãããµã¤ãã¯è³æ¥åé¿çãå°å ¥ãããã¨ãæ¨å¥¨ãã¾ãã æ¦è¦ CGIã®ä»æ§ã¨ãã¦ãã¯ã¨ãªæååã«çå·ãå«ããªãå ´åã¯ãã¯ã¨ãªæååãCGIã¹ã¯ãªããã®ã³ãã³ãã©ã¤ã³å¼æ°ã¨ãã¦æå®ããã¾ãã ä¾ãã°ãhttp://example.jp/test.cgi?foo+bar+bazã¨ããå¼ã³åºãã«å¯¾ãã¦ã¯ãtest.cgiã¯ä»¥ä¸ã®ã³ãã³ãã©ã¤ã³ã§å¼ã³åºããã¾ãã test.cgi foo bar baz ãã®ä»æ§ãæªç¨ãã¦ãCGIçã®PHPã«ã³ãã³ãã©ã¤ã³å¼æ°ã¨ãã¦PHPã®ãªãã·ã§ã³ãæå®ã§ãã¾ããä¾ãã°ãhttp://example.jp/test.php?-s ã¨ãããªã¯ã¨ã¹ãã¯ã-s
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãç¥ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}