DMMã§AWSã»ãã¥ãªãã£ã¬ã¼ãã¬ã¼ã«ãä½ã£ãã®ã§ãéçºè ãAWSã»ãã¥ãªãã£ããã§ãã¯ããæåãåºãã¦ãããã
DMMã§AWSã»ãã¥ãªãã£ã¬ã¼ãã¬ã¼ã«ãä½ã£ãã®ã§ãéçºè ãAWSã»ãã¥ãªãã£ããã§ãã¯ããæåãåºãã¦ãããã
ãã¡ãã®ã¹ã©ã¤ãã¯ä»¥ä¸ã®ãµã¤ãã«ã¦é²è¦§ããã ãã¾ãã https://www.docswell.com/s/ockeghem/ZM6VNK-phpconf2021-spa-security ã·ã³ã°ã«ãã¼ã¸ã¢ããªã±ã¼ã·ã§ã³(SPA)ã«ããã¦ãã»ãã·ã§ã³IDããã¼ã¯ã³ã®æ ¼ç´å ´æã¯Cookieãããã¯localStorageã®ããããè¯ãã®ããªã©ãã»ãã¥ãªãã£ä¸ã®èª²é¡ããããä¸ã§è°è«ããã¦ãã¾ãããæ®å¿µãªããééã£ãåæã«åºã¥ããã®ãå¤ãããã§ãããã®ãã¼ã¯ã§ã¯ãSPAã®ã»ãã¥ãªãã£ãæ§æããåºç¤æè¡ã説æããå¾ãèåãªãã¬ã¼ã ã¯ã¼ã¯ãªç¶æ³ã¨ã¨ã³ã¸ãã¢ã®æè¡çè§£ã®ç¾ç¶ãè¸ã¾ããSPAã»ãã¥ãªãã£ã®ç¾å®çãªæ¹æ³ã«ã¤ãã¦èª¬æãã¾ãã åç»ã¯ãã¡ã https://www.youtube.com/watch?v=pc57hw6haXk
2020å¹´7æ16æ¥ï¼æ¥æ¬æéï¼ãTwitterä¸ã§è¤æ°ã®èåãªã¢ã«ã¦ã³ããæå伿¥ã®ã¢ã«ã¦ã³ããããããã³ã¤ã³è©æ¬ºã®æç¨¿ãè¡ããã¾ãããTwitterã¯ãã®å¾ã®èª¿æ»ã§ã社å ãµãã¼ããã¼ã ã使ç¨ãã管çãã¼ã«ã䏿£å©ç¨ããããã¨ãåå ã¨çºè¡¨ãã¾ãããããã§ã¯é¢é£ããæ å ±ãã¾ã¨ãã¾ãã ä½ãèµ·ããã®ï¼ 2020å¹´7æ16æ¥æªæããèåã¢ã«ã¦ã³ããä¸å¿ã«è©æ¬ºæç¨¿ãè¡ãããããã®å¾ã¢ã«ã¦ã³ã侵害ã®å½±é¿ã¯å¤§é¨åãå復ããã ä¸é£ã®æç¨¿ã«ã¯Twitter社å ã®ãµãã¼ããã¼ã ã使ç¨ãã管çãã¼ã«ãæªç¨ããããããã«è¤æ°ã®ã¢ã«ã¦ã³ãã§DMé²è¦§ããã¼ã¿ã®ãã¦ã³ãã¼ããè¡ãããæããããã 社å ãã¼ã«ã¯ã½ã¼ã·ã£ã«ã¨ã³ã¸ãã¢ãªã³ã°ã«ãã䏿£å©ç¨ããããSlackããã®èå°ã¨ãªã£ãã¨å ±ãããã¦ããã 1. ã¢ã«ã¦ã³ãã®ã£ã¨ãè©æ¬ºæç¨¿ 4æéç¶ã 7æ16æ¥ã«çºçãããããã³ã¤ã³è©æ¬ºã®æç¨¿ã¯å¤§ã¾ãã«2種é¡ã確èªã
ç¥å¥å·çåºãå¯å£«éãªã¼ã¹ããåãã¦ãããµã¼ãã®ãã¼ããã£ã¹ã¯ã䏿£ã«è»¢å£²ãããçµæãè¨å¤§ãªå人æ å ±ãªã©ãæ¼æ´©ããäºä»¶ãèµ·ãã¾ãããããããã£ããã«ããã¼ããã£ã¹ã¯ãªã©ã®ã¹ãã¬ã¼ã¸ãããã«å®å ¨ã«ç ´æ£ãã¹ãããã¨ããç¹ã«ä¸éã®é¢å¿ãé«ã¾ã£ã¦ãã¾ãã ãªã³ãã¬ãã¹ã§ä½¿ããã¦ããã¹ãã¬ã¼ã¸ã§ããã°ããã¼ããã£ã¹ã¯ãSSDãªã©ã®åªä½ãåãåºãã¦ç©ççã«ç ´å£ãããã¨ã§ããã¼ã¿ã第ä¸è ãèªã¿åºãä¸å¯è½ãªç¶æ ã«ãªã£ãã¨ç¢ºèªã§ãã¾ãã ã¯ã©ã¦ãã§ã¯ã©ãã§ããããï¼ ã¯ã©ã¦ãã®ã¹ãã¬ã¼ã¸ã«ä¿åãããã¼ã¿ãåé¤ããå¾ãããã第ä¸è ã«ãã£ã¦å®å ¨ã«èªã¿åºãã§ããªãç¶æ ã«ãããã¨ãã¯ã©ã¦ãã«å¯¾ãã¦ãã¹ãã¬ã¼ã¸ãç©ççã«ç ´å£ãã¦ã»ãããã¨ãã£ããªã¯ã¨ã¹ãã¯ãï¼ç¹æ®ãªå¥ç´ã§ãçµã°ãªãéãï¼ã§ãã¾ããã ã¯ã©ã¦ãã§ã¯åºæ¬çã«ãèªåã使ããªããªã£ãã¹ãã¬ã¼ã¸ã¯ãªã½ã¼ã¹ãã¼ã«ã«æ»ããå¥ã®ã¦ã¼ã¶ã¼ã«å²ãå½ã¦ãããåã³ä½¿ããããã¨
TOPICS Security , System/Network çºè¡å¹´ææ¥ 2019å¹´10æ28æ¥ PRINT LENGTH 304 ISBN 978-4-87311-888-8 忏 Zero Trust Networks FORMAT ã¼ããã©ã¹ããããã¯ã¼ã¯ã¨ã¯ããã¡ã¤ã¢ã¦ã©ã¼ã«ãVPNã«ä»£è¡¨ããã徿¥åã®ã»ãã¥ãªãã£ï¼å¢çé²å¾¡ã¢ãã«ï¼ãéç¨ããªããªã£ãç¾ç¶ãè¸ã¾ãããã¹ã¦ã®ãã©ãã£ãã¯ãä¿¡é ¼ããªããã¨ãåæã¨ããæ¤è¨¼ãããã¨ã§è å¨ãé²ãã¨ããã¢ããã¼ãã§ããè¿å¹´ãã¯ã©ã¦ããµã¼ãã¹ãã¢ãã¤ã«ã®æ®åã«ãããã»ãã¥ãªãã£ã§å®ãã¹ãå å¤ã®å¢çãããã¾ãã«ãªã£ã¦ãããã¨ã«ãããå¼·ãæ³¨ç®ãéãã¦ãã¾ããæ¬æ¸ã¯ãã¼ããã©ã¹ããããã¯ã¼ã¯ã®æ¦å¿µã¨å®è£ ããããã«å¿ è¦ãªç¥èãå¦ã¹ã解説æ¸ã§ããåºæ¬çãªæ¦å¿µã®èª¬æã«å§ã¾ããããã¤ã¹ãã¦ã¼ã¶ã¼ãã¢ããªã±ã¼ã·ã§ã³ããã©ãã£ãã¯ã®ä¿¡é ¼ãå®éã«ã©ã®ããã«ç¢ºç«ã
Backlogã«macOSã®æç´èªè¨¼ã§ãã°ã¤ã³ããæ§å ãã¼ã©ãã§ã¯2019å¹´3æã«W3Cã§æ¨æºåããããã¹ã¯ã¼ãã¬ã¹èªè¨¼ã®ãWeb Authentication APIãï¼WebAuthn: ã¦ã§ããªã¼ã¹ã³ï¼ã¨ããFIDO2ãï¼Fast IDentity Online: ãã¡ã¤ãï¼å¯¾å¿ã®ãµã¼ããå®è£ ãããã¨ã§ãBacklog / Cacoo / Typetalkä¸ã§ã®ãã¹ã¯ã¼ãã使ããªãæ°ããèªè¨¼ã«å¯¾å¿ãã¾ããã WebAuthn / FIDO2ã使ç¨ããçä½èªè¨¼ãã°ã¤ã³ã®ã¡ãªããã¯æ¬¡ã®ã¨ããã§ãã çä½èªè¨¼ã§ãã°ã¤ã³ãç´ æ©ãç°¡åã«ãªãã¾ã ç使 å ±ã¯ãããã¯ã¼ã¯ä¸ã«ã¯æµããããã¼ã«ã«ã®ã»ãã¥ãªã㣠ããã¤ã¹ã«ä¿åãããããå®å ¨ã§ã 2è¦ç´ èªè¨¼â»2ã®ããå®å ¨ã§ã ãµã¼ãã«ç»é²ããèªè¨¼æ å ±ã¯å ¬ééµã®ããããã¹ã¯ã¼ããªã¹ãåæ»æãæ å ±æ¼æ´©ã®ãªã¹ã¯ãããã¾ãã ãã¡ã¤ã³ãæ¤è¨¼ãããããããã£ã
2019å¹´7æ29æ¥ãç±³éè大æ Capital Oneã¯ä¸æ£ã¢ã¯ã»ã¹ã«ãã1å人ãè¶ ããå人æ å ±ãæµåºããã¨çºè¡¨ãã¾ãããWAFã®è¨å®ãã¹ã«èµ·å ãã¦ãServer Side Request Forgeryï¼SSRFï¼æ»æã許ãããã¨ã«ããæ å ±ãçã¾ããã¨è¦ããã¦ãã¾ããããã§ã¯é¢é£ããæ å ±ãã¾ã¨ãã¾ãã Capital Oneã«ããå ¬å¼çºè¡¨ Information on the Capital One Cyber Incidentï¼ç±³å½åãï¼ Information on the Capital One Cyber Incidentï¼ã«ããåãï¼ Frequently Asked Questions ï¼ï¼ï¼å½±é¿ç¯å² å½±é¿ãåãã 人æ°ã®å 訳ã¯ä»¥ä¸ã®éãã ç±³å½ ç´1å人 ã«ãã ç´600ä¸äºº çºè¡¨æç¹ã§Capital Oneã¯æµåºããæ å ±ãå¤é¨ã¸åºåããã¨ããè©æ¬ºã¸ã®ä½¿ç¨ã¯ç¢ºèªãã¦ããªãã
ã¯ããã« ä¸å±±ï¼é ï¼ã§ã 4å¹´ã»ã©åã«ãã®è¨äºã®ã¿ã¤ãã«ã¨åããã¼ãã§è³æã使ãããã¨ãããã®ã§ãããå¤ãå 容ããã£ããæ°ãããµã¼ãã¹ã®ãã¨ãå«ã¾ãã¦ããªãã£ããããã®ã§æ¹ãã¦ã¾ã¨ãã¦ã¿ã¾ããã令åã ãï¼ ãã®æã®è³æã¯ãã¡ãã§ãï¼ã¯ã©ã¹ã¡ã½ããã«ã¸ã§ã¤ã³ããããã2å¹´åã§ãï¼ã AWSã¢ã«ã¦ã³ããä½ã£ããæåã«ããã¹ãã㨠ãµã¤ã³ã¢ãã ï¼æ¥åå©ç¨ã®å ´åï¼éå人ã¡ã¼ã«ã¢ãã¬ã¹ã§ãµã¤ã³ã¢ãã ãµãã¼ããã©ã³ã®ç¢ºèª ID管ç / 権é管ç CloudTrailã®æå¹å ã«ã¼ãã¢ã«ã¦ã³ãã®MFAè¨å® IAM User / IAM Groupã®ä½æ ãã¹ã¯ã¼ãããªã·ã¼ã®è¨å® GuardDutyã®æå¹å Security Hubã®æå¹å è«æ± IAM Userã«ããè«æ±æ å ±ã¸ã®ã¢ã¯ã»ã¹è¨±å¯ æ¯æé貨ã®å¤æ´ Budgetã®è¨å® Cost Explorerã®æå¹å Cost Usage Report
2016-2017å¹´ã§ã®NIST SP800-63-3æ¹å®ãéãã¦ãèªè¨¼ãå«ããã¸ã¿ã«ã¢ã¤ãã³ãã£ãã£ã®ä¸çã§ã¯æ§ã ãªè°è«ãæ¹§ãèµ·ããã¾ããã ãããªæ¬ã¬ã¤ãã©ã¤ã³ã®å 容ãéãã¦ããã¸ã¿ã«ã¢ã¤ãã³ãã£ãã£ãã¬ã¼ã ã¯ã¼ã¯ãèããä¸ã§ã®å ±éè¨èªãç¹ã«ãèªè¨¼æ¹æ³ãã«ã¤ãã¦è¨è¼ããNIST SP800-6â¦
ã¨ã°ã¼ã¯ãã£ããµããª èææ°è社ãéå¶ããé販ãµã¤ããSOKAãªã³ã©ã¤ã³ã¹ãã¢ããã2,481ä»¶ã®ã¯ã¬ã¸ããã«ã¼ãæ å ±ãæ¼æ´©ããããªãªã¼ã¹ã«ããã¨ãæ¼æ´©ã«ä½¿ãããæå£ã¯å¾æ¥ã¨ã¯ç°ãªããã®ã§ãæ¹æ£å²è³¦è²©å£²æ³ã®å®åä¸ã®ã¬ã¤ãã©ã¤ã³ã§ãããã¯ã¬ã¸ããã«ã¼ãæ å ±éä¿æåãã§ã¯å¯¾çã§ããªããã®ã§ãã£ãã ã¯ããã« ä»å¹´ã®9æ4æ¥ã«èææ°è社ã®é販ãµã¤ãSOKAãªã³ã©ã¤ã³ã¹ãã¢ããã¯ã¬ã¸ããã«ã¼ãæ å ±æ¼æ´©ã®å¯è½æ§ããªãªã¼ã¹ããã¾ããã以ä¸ã¯èææ°è社ããéå¶å§è¨ããã¦ãããã©ã³ã¹ã³ã¹ã¢ã¹æ ªå¼ä¼ç¤¾ã®ãªãªã¼ã¹ã§ãã ãSOKAãªã³ã©ã¤ã³ã¹ãã¢ãã®ä»¶ ãã®ãã³ãå¼ç¤¾ãèææ°è社æ§ããéå¶ãå§è¨ããã¦ãããSOKAãªã³ã©ã¤ã³ã¹ãã¢ãã«ããã¦ãã¯ã¬ã¸ããã«ã¼ãæ å ±ãå ¥åãã¦ååããæ³¨æããã ããä¸é¨ã®ã客ãã¾ã®ã¯ã¬ã¸ããã«ã¼ãæ å ±ãã第ä¸è ã«ãã£ã¦ä¸æ£ã«åå¾ãããå¯è½æ§ããããã¨ãçºè¦ã ããã¾ããã http
ã¯ããã« ä¸å±±ã§ã å¤è¦ç´ èªè¨¼ããã¦ã¾ããï¼ æ¬æ¥ãIAMã®å¤è¦ç´ èªè¨¼ã§YubiKeyãå©ç¨ã§ããããã«ãªãã¾ããã Sign in to your AWS Management Console with YubiKey Security Key for Multi-factor Authentication (MFA) Use YubiKey security key to sign into AWS Management Console with YubiKey for multi-factor authentication YubiKey / Universal 2nd Factor (U2F)ã¨ã¯ï¼ 以ä¸ã®è¨äºã«ã ãããæ¸ãã¦ããã¾ãã®ã§ãã¡ããã覧ãã ããã Yubikeyå ¥é YubiKeyã®ããã¨ãã YubiKeyã®ããã¨ããã¨ãã¦ã¯ä»¥ä¸ã®ãããªç¹ãããã¾ããæé«ããã ã¯
ãä¹ ãã¶ãã§ããã²ãããã§ãã åã ããæ°ã«ãªã£ã¦ããAWS EC2ã®169.254.169.254ã«ã¤ãã¦å°ãéãã§ã¿ãã®ã§ã¾ã¨ãã¾ãã EC2ã§ã¯ãã¤ã³ã¹ã¿ã³ã¹å ãã http://169.254.169.254/ ã«ã¢ã¯ã»ã¹ããã¨ããã®ã¤ã³ã¹ã¿ã³ã¹ã«é¢ããæ å ±ãåå¾ã§ããããã«ãªã£ã¦ãã¾ãã docs.aws.amazon.com ãã¾ãæèãããã¨ã¯ãªãããããã¾ããããã¤ã³ã¹ã¿ã³ã¹ã«IAMãã¼ã«ãçµã³ä»ããç¶æ ã§AWS CLIã使ãã¨å é¨çã«ãã®169ã®URLãå©ãããä»çµã¿ã«ãªã£ã¦ãã¾ãã ããã¯ã¤ã³ã¹ã¿ã³ã¹å ã§--debugãªãã·ã§ã³ã使ã£ã¦AWS CLIãå®è¡ããã¨ãããã¨æãã¾ãã [ec2-user@ip-172-31-30-197 ~]$ aws s3 ls --debug ï½ï½ï½ 2018-09-03 11:11:33,898 - MainThread - boto
ã¤ã³ãã©ã¹ãã©ã¯ãã£ã¼é¨ã»ãã¥ãªãã£ã°ã«ã¼ãã®æ°´è°· (@m_mizutani) ã§ãã ç¾å¨ãã¯ãã¯ãããã®ã»ãã¥ãªãã£ã°ã«ã¼ãã§ã¯ã»ãã¥ãªãã£ç£è¦ãé«åº¦åã«å¯¾ãã¦åãçµãã§ãã¾ãããµã¼ãã¹ã«é¢é£ããé¨åã®ç£è¦ã¯ä»¥åãããã£ã¦ããã®ã§ããããããã°ããã¯ãã以å¤ã®ã¤ã³ãã©ããªãã£ã¹ã§çºçããã»ãã¥ãªãã£ä¾µå®³ãæ¤ç¥ãããã¨ãç®çã¨ããç£è¦åºç¤ã®æ§ç¯ã«åãå ¥ãã¦ãã¾ãã æã¯ä¸è¬çã«ãªãã£ã¹ãã¤ã³ãã©ã®ã»ãã¥ãªãã£ç£è¦ã¨è¨ãã°ãã¤ã³ãã©ãããå ã«éããç°å¢ã§ã®ãã°åéããåæã¾ã§å®çµãã¦ããã±ã¼ã¹ãå°ãªããªã£ãã¨èãããã¾ãããããç¾å¨ã ã¨ã¤ã³ãã©ã¨ãã¦ã¯ã©ã¦ããµã¼ãã¹ãå¤ç¨ããããæ¥åã§ä½¿ããã¼ã«ãSaaSã«ãã£ã¦æä¾ããã¨ããå ´é¢ãå¢ãã¦ãããã¨æãã¾ãããã®ãããªç¶æ³ã ã¨ã»ãã¥ãªãã£ç£è¦ã®ããã«è¦ãã¹ãç®æãã°ããã¦ãã¾ãã¨ãã£ããã¨ãèµ·ããã¾ããã¯ãã¯ãããã§ãç©æ¥µçã«SaaSãAWS
徳丸æ¬ãã¨ããä½ç³»çã«å¦ã¶ å®å ¨ãªWebã¢ããªã±ã¼ã·ã§ã³ã®ä½ãæ¹ãã¯ã2011å¹´3æã®çºå£²ä»¥é大å¤å¤ãã®æ¹ã«èªãã§ããã ãã¾ããããããã¨ããããã¾ãã ãã ãçºå£²ããæ¢ã«7å¹´ãçµéããå 容ãå¤ããªã£ã¦ããæã¯å¦ãã¾ããããã¨ãã°ãã¯ãªãã¯ã¸ã£ããã³ã°ã®èª¬æã¯ã»ã¨ãã©ãªãã§ãããOWASP Top 10 2017ã§é¸å ¥ãããå®å ¨ã§ãªããã·ãªã¢ã©ã¤ã¼ã¼ã·ã§ã³ãXXEã®èª¬æãããã¾ããããªã«ãããWeb APIãJavaScriptã®ã»ãã¥ãªãã£çãã»ã¨ãã©æ¸ããã¦ããªããã¨ã課é¡ã¨ãªã£ã¦ãã¾ããã ããã§ãçå ã®SBã¯ãªã¨ã¤ãã£ãã¨ç¸è«ãã¦ããã®åº¦æ¹è¨ãããã¨ã«ãããã¾ããã3ææ«è±ç¨¿ã6æé çºå£²ã®è¦è¾¼ã¿ã§ãã æ¹è¨ã«ãããã以ä¸ãèãã¦ãã¾ãã Web APIã¨JavaScriptã«é¢ãã説æã4ç« ã«è¿½å XHR2対å¿ã«åãã¦CORSã®èª¬æã3ç« ã«è¿½å æºå¸¯é»è©±ã®ç« ã¯ä¸¸ãã¨åé¤ãã¦ãå¥ã®å
Posted by usa on 29 Aug 2017 Ruby ã®æ¨æºæ·»ä»ã©ã¤ãã©ãªã§ãã RubyGems ã«ãè¤æ°ã®èå¼±æ§ãçºè¦ããã¾ããã RubyGems ã®å ¬å¼ããã°ã«ã¦å ±åããã¦ãã¾ãã 詳細 以ä¸ã®èå¼±æ§ãå ±åããã¦ãã¾ãã a DNS request hijacking vulnerability. (CVE-2017-0902) an ANSI escape sequence vulnerability. (CVE-2017-0899) a DoS vulnerability in the query command. (CVE-2017-0900) a vulnerability in the gem installer that allowed a malicious gem to overwrite arbitrary files. (CVE-2017-0901
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãç¥ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}