åºåã®çµé¨ãæã¡å¸°ã£ã¦ããæå±é¨ç½²ã¯ç¡é¢å¿â¦ãã¤ããã¼ã·ã§ã³ãé»ãããã£ãããªããçµç¹ã«ãããã¡ãªãã¨
ç°å¢å¤æ°ã«ä»è¾¼ã¾ããã³ã¼ããå®è¡ãã¦ãã¾ãBASHã®èå¼±æ§ã CGIã¹ã¯ãªããã«å½±é¿ãä¸ããã試ãã¦ã¿ããçµæã¯æ²æ¨ãªæãã« Tweet 2014å¹´9æ25æ¥ å¶ç°å¤§è²´ ãã®è¨äºã¯2014å¹´ã®ãã®ã§ã æãã Bash specially-crafted environment variables code injection attack ãªããã®ã§é¨ãã«ãªã£ã¦ããã®ã§ããã£ããæå ã® Apacheã§è©¦ãã¦ã¿ã¾ããã /hoge.cgiã¨ããURIã§å®è¡ãããããã«ãä¸è¡ã®ã¡ãã»ã¼ã¸ãåºåããã ãã® CGIã¹ã¯ãªãããè¨ç½®ãã¾ãããã£ããããªãã®å ¥åãã¯ã©ã¤ã¢ã³ãå´ããåãä»ãã¦ããªãããå±éºã®ããããããªãè¦ãã¾ãã #!/bin/sh echo "Content-type: text/plain" echo echo "Hi! I'm an ordinary CGI script w
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}