You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert
ã¯ããã« ãã®è¨äºã¯ä¸è¨ãªã³ã¯ã®æ¥æ¬èªç¿»è¨³è¨äºã§ã 翻訳ã誤ã£ã¦ããå ´åã¯ã³ã¡ã³ãã@no1zy_secã¾ã§ãç¥ããããã ããã¨å¹¸ãã§ãã [SSRF] Server Side Request Forgery Server Side Request Forgeryã¯ãµã¼ãã¼ã«ä»»æã®ãªã¯ã¨ã¹ãã®å®è¡ãå¼·å¶ããæ»æã§ããä¾ãã°nginxã®å ´åãproxy_passãã£ã¬ã¯ãã£ãã®ç¬¬2弿°ãæ»æè ãæå®ã§ããå ´åã«æ»æãå¯è½ã«ãªãã¾ãã ã©ããã£ã¦è¦ã¤ããã ããã«ãµã¼ãã¼ãèå¼±ã«ãã2種é¡ã®ã¨ã©ã¼ãããã¾ãã internalãã£ã¬ã¯ãã£ãã®æ¬ å¦ã ããã¯å é¨ãªã¯ã¨ã¹ãã«ã®ã¿ä½¿ããã¨ãã§ãããã¨ã示ãããã«ä½¿ç¨ããã¾ã å®å ¨ã§ãªãå é¨ãªãã¤ã¬ã¯ã internalãã£ã¬ã¯ãã£ãã®æ¬ å¦ internalãã£ã¬ã¯ãã£ãã®æ¬ å¦ã§SSRFããããã¨ãã§ããå ¸åçãªè¨å®ãã¹ã§ãã
ã¯ããã« ååã®è¨äºã§ã誤ã£ã¦ã¤ã³ã¿ã¼ãããã«éæ¾ãããRedisãæä½ãã¦OSã³ãã³ãå®è¡ããã¾ã§ã®æ»ææ¹æ³ã説æãã¾ããã knqyf263.hatenablog.com ãã¡ãã®æ¹æ³ã§ã¯CONFIG SETã使ã£ã¦ããã®ã§ãããæè¿ã³ã³ãããå©ç¨ããããã¨ãå¢ããããã«åºããã«ãããªã£ã¦ãã¾ããã¾ããRedisã®å®è¡ã¦ã¼ã¶ã®æ¨©éãå¼·ãå¿ è¦ããã£ãããããã¥ã¡ã³ãã«ã¼ãã®pathãäºæ¸¬ããå¿ è¦ããã£ããã¨ãã£ãå¶ç´ãããã¾ããããããã£ãå¶ç´ãåé¿ããæ¹æ³ãçºè¡¨ããã¦ããã®ã§è©¦ãã¦ã¿ã¾ããã ããã«ãååã¯Redisãå®å ¨ã«æä½ã§ããåæãç½®ãã¦ãã¾ãããä»åã¯æ´ã«é£ããSSRFã®ã¿ã使ããç¶æ³ãæ³å®ããã¦ãã¾ããSSRFã«ã¤ãã¦ã¯èª¿ã¹ããåºãã¨æãã®ã§å²æãã¾ãããä»åã®å ´åã¯ç°¡åã«è¨ãã¨ãRedisã¯å ¬éããã¦ããªãããå ¬éããã¦ããWebãµã¼ããªã©çµç±ã§æ»æè ãå é¨ã®Redisã«
AWS EC2ç°å¢ã§ã®DNS Rebindingã«ã¤ãã¦æ¤è¨¼ããã®ã§ç´¹ä»ãã¾ãã ã¾ãã¯ããååã¾ã§ã®ãããããã§ããå æ¥ä»¥ä¸ã®è¨äºã§SSRFæ»æããã³SSRFèå¼±æ§ã«ã¤ãã¦ç´¹ä»ãã¾ããã SSRF(Server Side Request Forgery)å¾¹åºå ¥é ãã®è¨äºã®ä¸ã§ã以ä¸ã®ããã«ç´¹ä»ãã¾ããã ãã¹ãåããIPã¢ãã¬ã¹ãæ±ããéã«ã以ä¸ã®åé¡ãçºçãã¾ãã DNSãµã¼ãã¼ãè¤æ°ã®IPã¢ãã¬ã¹ãè¿ãå ´åã®å¦çã®æ¼ã IPã¢ãã¬ã¹ã®è¡¨è¨ã®å¤æ§æ§ï¼åèè¨äºï¼ IPã¢ãã¬ã¹ãã§ãã¯ã¨HTTPãªã¯ã¨ã¹ãã®ã¿ã¤ãã³ã°ã®å·®ãæªç¨ããæ»æï¼TOCTOUèå¼±æ§ï¼ ãªã¯ã¨ã¹ãå ã®Webãµã¼ãã¼ããæ»æå¯¾è±¡ãµã¼ãã¼ã«ãªãã¤ã¬ã¯ããã ä¸è¨ã®TOCTOU(Time of check to time of use)åé¡ã¯ãDNSã®ååè§£æ±ºã®æèã§ã¯DNS Rebindingã¨ãå¼ã°ãã¾ãã DNS R
SSRF(Server Side Request Forgery)ã¨ããèå¼±æ§ãªããæ»æææ³ãæè¿æ³¨ç®ããã¦ãã¾ãã以ä¸ã¯ããã3ã¶æã«SSRFã«ã¤ãã¦è¨åãããè¨äºã§ãã EC2ä¸ã®AWS CLIã§ä½¿ããã¦ãã169.254ã«ã¤ã㦠SSRFèå¼±æ§ãå©ç¨ããGCE/GKEã¤ã³ã¹ã¿ã³ã¹ã¸ã®æ»æä¾ SSRFãå©ç¨ããã¡ã¼ã«éä¿¡ãã¡ã¤ã³ã®ä¹ã£åã ãCODE BLUE 2018ãåå ã¬ãã¼ãï¼å²©éç·¨ï¼ ãã®ã空åã®SSRFãã¼ã ãã«ä¾¿ä¹ãã¦ãSSRFã¨ããæ»æææ³ããã³èå¼±æ§ã«ã¤ãã¦èª¬æãã¾ãã SSRFæ»æã¨ã¯ SSRFæ»æã¨ã¯ãæ»æè ããç´æ¥å°éã§ããªããµã¼ãã¼ã«å¯¾ããæ»æææ³ã®ä¸ç¨®ã§ããä¸å³ã«SSRFæ»æã®æ§åã示ãã¾ãã æ»æè ããã¯ãå ¬éãµã¼ãã¼ï¼203.0.113.2ï¼ã«ã¯ã¢ã¯ã»ã¹ã§ãã¾ãããå é¨ã®ãµã¼ãã¼ï¼192.168.0.5ï¼ã¯ãã¡ã¤ã¢ã¦ã©ã¼ã«ã§éé¢ããã¦ããããå¤é¨ããç´æ¥
12/9ï½12/10ã«éå¬ããSECCON 2017 Online CTFã«åå ãããã¾ããï¼ vulsã¨ãããã¼ã ã§åå ãã¦ãæçµçµæã¯46ä½ã§ããã ç§ã¯Webåãã¡ã¤ã³ã§æ å½ãã¦ãã¾ããã ä»åã¯ã¡ãã£ã¨æ¥ææ¥ã«æç¨ããã£ããããæ®å¿µãªãããã«åæ¦ã§ããªãã£ãã®ã§ãããä¹ ã ã«ãªãã©ã¤ã³ã§éã¾ã£ã¦ãæ¨å¹´ã¨åãããã«ã¬ãããã«çæã«ãã¶ãé£ã¹ãªããCTFããããã¨ãã§ãã¦ãããæ¥½ããã£ãã§ãï¼ æè§ãªã®ã§ãå°ãªãã®ã§ããç§ãè§£ããåé¡ã®Write UPã«ã¤ãã¦ä»åããã°ã«æ¸ãããã¨æãã¾ãã SqlSRF (400 points) ä»åç§ãè§£ããã®ã¯ãSqlSRFãã¨ããåé¡ã§ãã åé¡åãããã¦ãè¦ãç¬éã«å¤åSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã¨SSRFããããåé¡ãªãã ãããªã¨æ¨æ¸¬ãã¾ããããçµæçã«ããã¨ãã®éãã®åé¡ã§ããã åé¡ã«ã¯ã以ä¸ã®ãããªè¨è¼ããã£ã¦ãURLãè¨è¼ããã¦ãã¾ãã T
ã©ã³ãã³ã°
ãç¥ãã
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}