This domain may be for sale!
ãã£ã¹ã¯ãç ´æ£ããããè²æ¸¡ãããããå ´åã«ã¯ãããããããã£ã¹ã¯ã®å 容ãæ¶å»ãã¦ãããªãã¨æ å ±ãæ¼ããããå±éºæ§ããããåç´ã«ãã¡ã¤ã«ãåé¤ããã ãã§ã¯ããã¡ã¤ã«ã復活ããããã¨ãã§ããããã¼ã¿ãå®å ¨ã«æ¶å»ããããã«ã¯ããã£ã¹ã¯å ¨ä½ã«æ¸¡ã£ã¦ãã¼ã¿ãå®å ¨ã«ä¸æ¸ãããå¿ è¦ãããã é£è¼ç®æ¬¡ 解説 ã³ã³ãã¥ã¼ã¿ããã¼ããã£ã¹ã¯ãç ´æ£ããããä»äººã«è²æ¸¡ãããããå ´åãå é¨ã®ãã¼ã¿ãå®å ¨ã«æ¶å»ãã¦ãããªãã¨ããããã社å ã®æ©å¯æ å ±ã顧客æ å ±ãã¡ã¼ã«ã»ã¢ãã¬ã¹ãªã©ãæ¼ãããã¦ãã¾ãå±éºæ§ããããå®éãä¸å¤ã§è³¼å ¥ããã³ã³ãã¥ã¼ã¿ã®ãã¼ããã£ã¹ã¯ã«å¯¾ãã¦ãã¼ã¿å¾©å ã½ããã¦ã§ã¢ãå®è¡ããã¨ãããããå»çæ©é¢ãå¥åº·ä¿éºçµåãªã©ã«å»çè²»ãè«æ±ããããã«ä½æãã診çå ±é ¬æç´°æ¸ã®ç»åãã¼ã¿ãåãåºãããã¨ããäºä¾ãç·åçã®ãå½æ°ã®ããã®æ å ±ã»ãã¥ãªãã£ãµã¤ããã§å ±åããã¦ããã å½æ°ã®ããã®æ å ±ã»ãã¥ãªãã£ãµã¤ãï¼
SQLãç¨ãã¦ãã¼ã¿ãã¼ã¹ãæ±ãWebã¢ããªã±ã¼ã·ã§ã³ã¯ãSQLæ³¨å ¥ã許ããªãããã«ããå¿ è¦ããããSQLæ³¨å ¥æ»æ対çã®ãã¡ãã¾ãã¯å®è£ ã«ããã対çã«ã¤ãã¦è¿°ã¹ãã æèã«å¿ããç¹æ®è¨å·å¯¾çã¯ã³ãã³ãæ³¨å ¥æ»æ対çã¨åæ§ã§ãããå ãã¦ãããªãã¢ã¼ãã¹ãã¼ãã¡ã³ãã®ä½¿ç¨ãè¨èªã®é¸æã«ãã対çã説æããã ãSQLæ³¨å ¥ï¼SQL injectionï¼ãã¯ããã©ã¡ã¼ã¿ãåãè¾¼ãã§SQLæãçµã¿ç«ã¦ãå ´åããã®ãã©ã¡ã¼ã¿ã«ç¹æ®è¨å·ï¼è¨å·ï¼ãå«ã¾ããSQLã³ãã³ããä¸ãããã¨ã«ãã£ã¦ããã¼ã¿ãã¼ã¹ã®ä¸æ£æä½ãå¯è½ã¨ãªã£ã¦ãã¾ãåé¡ã§ããã åèï¼ CWE-89: Improper Neutralization of Special Elements used in an SQL Commandï¼æ¥æ¬èªè¨³ï¼ SQLæ³¨å ¥æ»æã®ã¡ã«ããºã ããã«ã次ã®ãããªSQLæã使ç¨ãããã°ã¤ã³å¤å®ããã°ã©ã ãããã¨ãã
ã»ãã·ã§ã³ã«ã¤ã㦠Java ãµã¼ãã¬ãã㯠HTTP ãããã³ã«ã使ç¨ãã¾ããHTTP ã¯ã¹ãã¼ãã¬ã¹ãããã³ã«ã§ãã ãµã¼ãã¯ããªã¯ã¨ã¹ããåãåã£ã¦ã¬ã¹ãã³ã¹ãè¿ãã¨ãã¯ã©ã¤ã¢ã³ã ( ãã©ã¦ã¶ ) ã¨ã®æ¥ç¶ãçµäºãã¾ãã ãµã¼ãã«ã¯ã¯ã©ã¤ã¢ã³ããä¸æã«èå¥ã§ããæ å ±ãæã£ã¦ããªããããã¯ã©ã¤ã¢ã³ãã®æ å ±ã¯ç¶æããã¾ããã ( ãµã¼ãã¯ã©ã®ã¯ã©ã¤ã¢ã³ããã©ã®æ å ±ãæã£ã¦ããããå¤æã§ããªãã ) ä¸è¨ã®åé¡ã解決ããããã®ä»çµã¿ãã»ãã·ã§ã³ç®¡çã¨ãªãã¾ãã ã»ãã·ã§ã³ã¨ã¯ãç°¡åã«èª¬æããã¨ã¯ã©ã¤ã¢ã³ãããµã¼ãã«æ¥ç¶ãã¦ããåæããã¾ã§ã® 1 æ¥ç¶åä½ã§ãã ä¸è¬çã«ã¯ 1 ãªã¯ã¨ã¹ãåä½ã§ã¯ãªããä¾ãã°ãã¦ã¼ã¶ããã°ã¤ã³ãã¦ãããã°ã¢ã¦ããããã¯ã ãã©ã¦ã¶ãéãããªã©ã®æä½ãè¡ãã¾ã§ã®éã表ãã¾ãã 1 ã»ãã·ã§ã³ã®éã«ã¯ãè¤æ°åã®ãªã¯ã¨ã¹ãéä¿¡ãã¬ã¹ãã³ã¹åä¿¡ã
Twitterã¨ã¯ Twitterï¼ãã¤ãã¿ã¼ï¼ã¨ã¯ã140æå以å ã®çææ å ±ãæ稿ã»é²è¦§ããã¤ã³ã¿ã¼ãããä¸ã®ã³ãã¥ãã±ã¼ã·ã§ã³ãµã¼ãã¹ã§ããï¼ç±³å½Twitter社ãéå¶ãã¦ãã¾ããï¼ ã¤ã³ã¿ã¼ããããå©ç¨ã§ããç°å¢ï¼ãã½ã³ã³ãã¹ãã¼ããã©ã³ãæºå¸¯é»è©±ãªã©ï¼ãããã°ã誰ã§ãèªããã¨ãå¯è½ã§ãã å©ç¨æ¹æ³ ä¸è¨ã®ã¢ã«ã¦ã³ãç´¹ä»ãããé·å´å¸ãçºä¿¡ããå 容ï¼ãã¤ã¼ãï¼ãé²è¦§ã§ãã¾ãï¼å¤é¨ãªã³ã¯ï¼ãã¾ããã¢ã«ã¦ã³ãããæã¡ã®æ¹ã¯ããã©ãã¼ãã¦ããã ããã¨ã§ãæ å ±ãã覧ããã ãã¾ãã ã¬ã¤ãã©ã¤ã³ã¨éç¨è¦å® é·å´å¸ã½ã¼ã·ã£ã«ã¡ãã£ã¢çã®å©ç¨ã«é¢ããã¬ã¤ãã©ã¤ã³ï¼PDFï¼89KBï¼ é·å´å¸ãã¤ãã¿ã¼ã«é¢ããéç¨è¦å®ï¼PDFï¼100KBï¼ ãé¡ã ãã¤ãã¿ã¼ãã®ãã®ã®å©ç¨æ¹æ³ã«ã¤ãã¦ãä¸æãªç¹ã¯ãTwitterãã«ãã»ã³ã¿ã¼ï¼å¤é¨ãªã³ã¯ï¼ã¾ãã¯twitterå ¬å¼ããã²ã¼ã¿ã¼ãã¤ããªã³ãï¼å¤é¨ãªã³ã¯
Javaã®ããã·ã¥å¤ãæ±ããããã«ãjava.security.MessageDigestã¯ã©ã¹ã使ã£ãããããã ã¶ã£ã¡ãããããªãæ±ããã®ã«ä¾å¤å¦çã ã¼ãã¢ã«ã´ãªãºã ã¯ï½ã ã¼ãªã㦠é¢åãããã®ã§ã©ããã³ã°ãã¦ã¿ãã packege mbs.security; import java.security.MessageDigest; import java.security.NoSuchAlgorithmException; /** * ããã·ã¥å¤çææ©è½ãæä¾ * @auther Mahny */ public class Encrypter{ /** * ã¡ãã»ã¼ã¸ãã¤ã¸ã§ã¹ãï¼MD5 */ public static final String ALG_MD5= "MD5"; /** * ã¡ãã»ã¼ã¸ãã¤ã¸ã§ã¹ãï¼SHA-1 */ public static final String
ããã·ã¥é¢æ° (Hash Function) ã¨ã¯ä»»æé·ã®ãã¤ããªãã¼ã¿ããæ°åï½æ°ç¾ ãããç¨åº¦ã®åºå®é·ãã¤ããªãç®åºããé¢æ°ã§ããå¤ããã CRC ã®ãããªã¢ã«ã´ãªãºã ã 誤ãæ¤åºã®ç¨éã§ä½¿ç¨ããã¦ãã¾ããããæå· ãªã©ã®ã»ãã¥ãªãã£ã§ä½¿ç¨ãããããã·ã¥é¢æ°ã¯ãããªç¹å¾´ãæã¡ã¾ãã åããã¤ããªãã¼ã¿ã«å¯¾ãã¦å¸¸ã«åãå¤ãç®åºãããã ç°ãªããã¤ããªãã¼ã¿ã«å¯¾ãã¦åãå¤ãç®åºããã (è¡çª) 確çã極ãã¦ä½ãã ç®åºãããå¤ããå ã®ãã¤ããªãã¼ã¿ã®æ¨æ¸¬ã極ãã¦é£ããã æè¿ã§ã¯ãã·ã³ããã©ã¼ãã³ã¹ã®åä¸ããã£ã¦ãã»ãã¥ãªãã£ã®ç¨éã§ä½¿ç¨ã§ããå¼·ã ããã·ã¥é¢æ°ããã¤ããªãã¼ã¿ã®èª¤ãæ¤åºãåä¸æ§æ¤è¨¼ (ã¤ã³ããã¯ã¹ä»ã) ãªã©ã«ã 使ç¨ããã¦ãã¾ãã Java ã§ä½¿ç¨ã§ãã ããã·ã¥ã¢ã«ã´ãªãºã ã«ã¯ Message Digest 㨠SHA ãããã¾ãã誤ãæ¤åºã®ç¨éã§ããã°ãã¼ã«çã«ã
ä»åã¯Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã«ããã3çªç®ã®ã«ãã´ãªã¼ãã»ãã·ã§ã³ä¹ã£åããã«ã¤ãã¦è§£èª¬ããã â»æ³¨æï¼ ãã®è¨äºã«ã¯Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã解説ããå¿ è¦ä¸ãæ»ææå£ã«é¢ããæ å ±ãå«ã¾ãã¦ãã¾ãããããã®æå£ãä»è ãéå¶ããWebãµã¤ãã«åãã¦ä»æããã¨ãææªã®å ´ååäºç½°ããã³æå®³è³ åè«æ±ã®å¯¾è±¡ã¨ãªãã¾ããèå¼±æ§ã®èª¿æ»ã»æ¤è¨¼ã¯ãå¿ ããèªèº«ã®ç®¡çä¸ã®ã³ã³ãã¥ã¼ã¿ã·ã¹ãã ããã³ãã¼ã«ã«ã¨ãªã¢ãããã¯ã¼ã¯ã§è¡ã£ã¦ãã ããããã®è¨äºãåèã«ããè¡çºã«ããåé¡ãçãã¦ããçè ããã³ThinkITç·¨éå±ã¯ä¸å責任ãè² ãã¾ããã Webã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã·ã§ã³ã¨ã¯ãè¤æ°ã®Webãã¼ã¸ã«ã¾ãããä¼è©±å¦çã®ãã¨ã§ããããã¨ãã°ãååãé¸ã¶ããé éå ãæå®ããããã«ã¼ãã§æ±ºæ¸ãããã¨ãã£ãä¼è©±å¦çã®æµãããã®ä¾ã§ããããããã®ãã¼ã¸éã§ã¯é©åã«æ å ±ãå¼ãç¶ããã¦ããããããã¯ä¸é£ã®HTTP
è¿å¹´ãæ¨çåæ»æã¯ããåãåã水飲ã¿å ´åã®åºç¾ã使ããããã«ã¦ã§ã¢ã®é«æ©è½åãªã©ã¾ãã¾ãå¤æ§åãã¦ããã被害ãå¾ã絶ã¡ã¾ãããåå ã®1ã¤ã«ã¯ãã¦ã¤ã«ã¹å¯¾çã½ããçã®å ¥å£å¯¾çãçªç ´ãã¦ä¾µå ¥ãæãããæ»æãæ å ±ã·ã¹ãã å é¨ã§å¯ãã«æ´»åãã¦ããã®ãæ¤ç¥ã§ãããæ å ±æµåºçã®å®å®³ãçºè¦ããã¾ã§æ»æã«æ°ä»ããªããã¨ãå¤ããã¨ãæãããã¾ãã IPAã§ã¯2010å¹´12æã«ãè å¨ã¨å¯¾çç 究ä¼ããè¨ç½®ããæ¨çåæ»æããçµç¹ã®æ å ±ã·ã¹ãã ãå®ãããã®ã·ã¹ãã è¨è¨ã¬ã¤ããå ¬éãã¦ãã¦ãããæ¬æ¸ã¯ãã®ææ°æ¹è¨çã¨ãªãã¾ããæ¬çã§ã¯ãã·ã¹ãã å é¨ã«æ·±ãä¾µå ¥ãã¦ããé«åº¦ãªæ¨çåæ»æã対象ã«ãã·ã¹ãã å é¨ã§ã®æ»æããã»ã¹ã®åæã¨å é¨å¯¾çãã¾ã¨ãã¦ãã¾ãã ã¾ããåçã«å¯¾ãããã¢ãªã³ã°çµæãæè¦ãåºã«ãããã·ã¹ãã è¨è¨ã»éç¨ç¾å ´ãå©ç¨ãããããããæ¹è¨ãã¤ã³ãã®1ã¤ã¨ãã¦ã対çã以ä¸ã®ããã«æ´çãã¾ããã ï¼çµ±å¶ç®æ¨ã®æ
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}