Code Archive Skip to content Google About Google Privacy Terms
Rubyã«DOSæ»æã®èå¼±æ§ãçºè¦ãããããã§ãã Riding Rails: DoS Vulnerability in Ruby DoS vulnerability in BigDecimal ã©ããªèå¼±æ§ã BigDecimalããFloatã«å¤æããé¨åã«åé¡ãããããããä¸è¨ã®ããã«ã大ããæ°å¤ãRubyã«ãã¼ã¹ããããã¨ã§DOSæ»æãã§ããã¿ããã§ããActiveRecordãä¸è¨ã®ãããªã³ã¼ãã使ã£ã¦ããããã§ãã»ã¨ãã©ã®Railsã¢ããªãèå¼±æ§ã®å¯¾è±¡ã«ãªã£ã¦ãã¾ãã BigDecimal("9E69999999").to_s("F") 対象 1.8.6-p368以å 1.8.7-p160以å 1.9.1ã¯åé¡ãªãããã§ãã æåã®è§£æ±ºæ¹æ³ Rubyã1.8.6-p369ã¾ãã¯ruby-1.8.7-p173ã«ã¢ããã°ã¬ã¼ãããã ã¨ããããã®è§£æ±ºæ¹æ³ Rubyã®ã¢ããã°ã¬ã¼ãã
2008/04/25 ãèå¼±æ§ã¯å¤ãã£ã¦ããªããããããããåãå·»ãä¸çã¯å¤§ããå¤åãã¦ãããââ4æ24æ¥ã®RSA Conference 2008 Japanã®åºèª¿è¬æ¼ã«ããã¦ãç±³ã°ã¼ã°ã«ã®ã¹ã³ããã»ãããªæ°ï¼ã¨ã³ã¿ã¼ãã©ã¤ãºã»ãã¥ãªãã£ããã³ã³ã³ãã©ã¤ã¢ã³ã¹æ å½ãã£ã¬ã¯ã¿ã¼ï¼ã¯ãã®ããã«èªããå¾æ¥ã¨ã¯ç°ãªãã»ãã¥ãªãã£å¯¾çãæ±ããããã¨è¿°ã¹ãã åæ°ã«ããã¨ãå¾æ¥ã®æ å ±ã·ã¹ãã ã¯ãä½ãèµ·ãããææ¡ã§ããããã¯ã¤ãããã¯ã¹ãã ã£ãããããèªç¤¾ã®ãã®ã ãã§ãªãããµã¼ããã¼ãã£ã®ãã¼ã«ããµã¼ãã¹ãæ®éã«å©ç¨ã§ããããã«ãªã£ããã¾ãã©ã®ã¦ã¼ã¶ã¼ãã©ã®ãªã½ã¼ã¹ã使ããä½ãããã®ããäºæ¸¬ãææ¡ãé£ããããã©ãã¯ããã¯ã¹ãã®æ代ã«ãªã£ã¦ãããããããç°å¢ã®å¤åã«å¯¾å¿ããã«ã¯ãæ°ãããã¼ãã¦ã§ã¢ãã½ããã¦ã§ã¢ã®è¿½å ã¨ãã£ãããæ¹ã§ã¯ãªãããã¬ã¼ãã³ã°ãã¯ããã¨ããå°éãªåãçµã¿ãéãã¦ãåºç¤ã®ä¸ã«ã»ã
ç·¨éé¨æ³¨è¨ï¼ä»åã¯ã¦ã§ãã»ãã¥ãªãã£ã®ç¾ç¶ã¨å°æ¥ã«ã¤ãã¦æ¤è¨¼ããã4åã«ãããã·ãªã¼ãºã®ç¬¬2åç®ã§ãã ã°ã¼ã°ã«ãæãããååãçµã¿ãã®å¿ è¦æ§ ããã©ãã¤ããï¼ããã¯ã¤ãã¼ã®ã»ãã¥ãªãã£ãã¼ã MSããã¹ã¯ãããããå¦ãã æè¨ åé¡ã®è§£æ±ºã¸ã®é Arturo Bejaræ°ã¯8å¹´åãYahooã®ã»ãã¥ãªãã£ãã¼ã ã«ã´ã£ããã®ååãæãã¤ããããParanoidãï¼ç çãªã¾ã§ã®å¿é æ§ï¼ã ã ãChief Paranoid Yahooãã®è©æ¸ããæã¤Bejaræ°ã¯ãèªèº«ãææ®ããé¨ç½²ã®æ称ã¨ãã¦ãå è¦ãããªããã»ãã¥ãªãã£ã®å½¹å²ã身è¿ã«æããããååãä»ãããã£ãã®ã ã ãããããã¯ãã»ãã¥ãªãã£ããã£ã¨æ°æ¥½ã«ã¨ããã¦ããããããåãçµãã§ãããã»ãã¥ãªãã£ã¯ãããã«éè¦ã ããæ·±å»ã«ãªããããªãã»ããå°å ¥ãé²ããã¨ããã®ãç§ã®èãæ¹ã ãã¨Bejaræ°ã¯è©±ãã åç ´ãã®ãã¼ãã³ã°ã¯ããã¤ã¦ãããã³
çè ã¯æè¿ï¼Apache HTTPãµã¼ãã¼ã«å¯¾ãããµã¼ãã¹æå¦æ»æãé²å¾¡ããWebãã¼ã¹ã®ã»ãã¥ãªãã£ã»ãã¼ã«ãmod_evasiveãã使ãå§ãããmod_evasiveã¯ç¹å®ã®æåãæ¢ãã¦ããããããã¯ããã¢ã¸ã¥ã¼ã«ã§ããã mod_evasiveã¯ï¼çè ãæ¨å¹´ã®12æã«ç´¹ä»ãããSuhosinãã«ä¼¼ã¦ããï¼é¢é£è¨äºï¼PHPã®ãå®è·ç¥ãSuhosinï¼ãSuhosinã¯PHPã¹ã¯ãªããã£ã³ã°ã»ã¨ã³ã¸ã³ã®å®å ¨æ§ãå¤§å¹ ã«é«ãããããã§ãããSuhosinã¯ï¼å®³ãåã¼ãå±éºæ§ãæã¤ããã¨ããããWebãã¼ã¹ã®ã³ã³ãã³ããæ¤åºãï¼ããããPHPã¨ã³ã¸ã³ãè¶ãã¦ã·ã¹ãã ããããã¯ã¼ã¯ã«å°éããã®ãé²ãä¸ã§å½¹ã«ç«ã¤ã mod_evasiveãæ©è½ããä»çµã¿ã説æããããmod_evasiveã¯ã¾ãURLãªã¯ã¨ã¹ããApacheãµã¼ãã¼ã«éä¿¡ããIPã¢ãã¬ã¹ã®è¨é²ãåãããã®å¾ï¼ãããããè¨å®ãã許
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}