OWASP APAC 2014 Tokyo Japan
int dtls1_process_heartbeat(SSL *s) { unsigned char *p = &s->s3->rrec.data[0], *pl; unsigned short hbtype; unsigned int payload; unsigned int padding = 16; /* Use minimum padding */ heartbeatã¨ããæ©è½ã®è©³ãããã¨ã¯èª¿ã¹ããã¦ããªãããã©ã©ãããã¯ã©ã¤ã¢ã³ãã¼ãµã¼ãåã®æ©è½ãæä¾ãããã®ãããã ã¤ã¾ãä½ããã®ãªã¯ã¨ã¹ããåãåã£ã¦ã¬ã¹ãã³ã¹ãè¿ããããªãµã¼ãã¹ãæä¾ãããã®ããããdtls1_process_heartbeatã§å¤§äºãªã®ã¯ ãã¤ã³ã¿pã ãããã¯ãªã¯ã¨ã¹ããã¼ã¿ãåãåã£ã¦æ ¼ç´ãã¦ããããã®ãªã¯ã¨ã¹ããã¼ã¿ã¯æ§é ä½ã«ãªã£ã¦ãã¦ã以ä¸ã®ããã«è¨è¿°ããã¦ããã typedef struct
ãã®ãããæãã¤ãã§ããã¾ããã ãã¹ã¯ã¼ãèªè¨¼ã®SSLå©ç¨ã§ç«ã¡ä¸ãããã¨æãã¾ãã yum install ircd-hybrid ## å¤æ´ç®æã ã cp /usr/share/doc/ircd-hybrid-7.2.3/simple.conf /etc/ircd/ircd.conf vi /etc/ircd/ircd.conf serverinfo { name = "irc.runeleaf.net"; # [0-9][A-Z0-9][A-Z0-9] sid = "101"; description = "IRC Server"; rsa_private_key_file = "/etc/secure/ircd/rsa.key"; ssl_certificate_file = "/etc/secure/ircd/cert.pem"; } administrator { name
nginxã«ã¯ãä¸é証ææ¸ãç´æ¥æå®ãããã£ã¬ã¯ãã£ããç¨æããã¦ããªãããããµã¼ã証ææ¸ã¨ä¸é証ææ¸ãçµåãããã®ããssl_certificateãã§æå®ãã¾ãã ãã¡ã¤ã«çµåã³ãã³ãä¾ # cat server.cer cacert.cer > cert.pem çµåãã証ææ¸ãã¡ã¤ã«ã¯ãä¸è¨ã®ãããªæ§æã«ãªãã¾ãã -----BEGIN CERTIFICATE----- [ãµã¼ã証ææ¸] -----END CERTIFICATE----- -----BEGIN CERTIFICATE----- [ä¸é証ææ¸] -----END CERTIFICATE-----
ãã£ããç§ããã¦ãã¦ãã飯ãç¾å³ããå£ç¯ã«ãªãã¾ããããshige ã§ãããã¾ãã ãã¦ãä»åã¯SSL証ææ¸ãæ´æ°ããã¨ãã«ãã§ãã¯ã«å½¹ç«ã¤ã³ãã³ããã¾ã¨ãã¦ã¿ã¾ããã ãã®æé ã«æ²¿ã£ã¦ããµã¼ãã¼ã«æ°ããSSL証ææ¸ãç½®ãæããã°ããã£ã¨è¨¼ææ¸ã¨ç§å¯éµã®ä¸æ´å㧠Apache ãèµ·åããªããªãã¦ãã©ãã«ãéããããã¯ãï¼ 1. ç§å¯éµã¨CSRã®ä½æ ã¾ããã馴æã¿ã® openssl ã³ãã³ãã§ãµã¯ãã¨ç§å¯éµã¨CSRãä½æãã¾ãã $ openssl req -new -newkey rsa:2048 -nodes -keyout www.webimpact.co.jp.key -out www.webimpact.co.jp.csr 2. èªè¨¼å±ã¸æåº æ¬¡ã«ããã¤ããä¸è©±ã«ãªã£ã¦ããèªè¨¼å±ã«CSRãæåºãã¾ãããã 3. ãµã¼ãã¼ã«è¨¼ææ¸ã¨ç§å¯éµãè¨ç½® èªè¨¼å±ãã証ææ¸ãçºè¡ãã¦ããããã
I released Furl 2.00. It contains very important and incompatible change. Furl now verify every SSL certifications by default. If your application communicates server, is using unverified SSL certs, this version breaks your application. If you want to back older behavior, you need to specify `ssl_opts` option. -Furl ã 2.00 ã§ããã©ã«ã㧠SSL 証ææ¸ããã³ãããã§ãã¯ããããã«ãªãã¾ãããããã¦ãã®æåãããã©ã«ãã¨ãªãã¾ããããªã¬ãªã¬è¨¼ææ¸ãã¤ãã£ã¦ããå ´åã«ã¯éä¿¡
å®å ¨ã«é£ãã¿ã¤ãã«ã§ããã©ä¸èº«ã¯çé¢ç®ã«æ¸ããã è¿å¹´ãã¦ã§ããµã¤ãã®HTTPSåãæµè¡ã®ããã«ãªã£ã¦ãããç§ã®ç¥ãéããGoogleã®å種ãµã¼ãã¹ãTwitterãFacebookãªã©ãå®å ¨ã«HTTPSã§éä¿¡ãè¡ãããã«ãªã£ã¦ãããHTTPSãã¤ã¾ãSSLã«ããéä¿¡ã®æå·åã«ãã£ã¦ãã¦ã¼ã¶ã«ããã¾ã§ãããå®å ¨ãªã¦ã§ããµã¤ããæä¾ã§ããã ããããããªããä½ã£ã¦ãããµã¤ãããµã¨æãã¤ãã§HTTPSåãã¦ãã¾ãã¨ããã¶ããããã¾ã§ããããµã¤ããé ããªããããã§ã¯ãHTTPSã§éä¿¡ããå ´åã®åé¡ã解説ããã ãªãé ããªãã®ã HTTPã§éä¿¡ããå ´åãã¯ã©ã¤ã¢ã³ãããµã¼ãã¸ã¨æ¥ç¶ããããã«ã¯TCP/IPã®3ã¦ã§ã¤ãã³ãã·ã§ã¤ã¯ã¨ããæé ãå¿ è¦ã«ãªããããã©ãããã®ã§ããã§ã¯è©³ããã¯èª¬æããªãããè¦ããã«ã¯ã©ã¤ã¢ã³ãããªã¯ã¨ã¹ããæããåã«ãã±ãããï¼å¾å¾©ãããªãã¨ãããªãã®ã§ããããã±ããã®å¾å¾©
ãã®ãã³ãã·ã§ã¼ã¯ã®å¾ã ã¯ã©ã¤ã¢ã³ããæå·åããã http ãªã¯ã¨ã¹ããéä¿¡ãã ãããåãã¦ãµã¼ããæå·åãããã¬ã¹ãã³ã¹ãè¿ãã https ãµã¼ãããã¼ãã£ã«ãã¡ã¤ã³æ©è½ãæã¤ã«ã¯ã https ãµã¼ãããµã¼ã証ææ¸ãéä¿¡ãã (ä¸ã®ãã³ãã·ã§ã¼ã¯å³ã® 3è¡ç®) ããåã«ã ã¯ã©ã¤ã¢ã³ãããªã¯ã¨ã¹ãããããã¹ãåãéç¥ããå¿ è¦ãããã ä¸å³ããæãããªããã«ã ãã¹ãåã®éç¥ã¯ä¸çªæåã®ãClientHelloãã§è¡ãªãããªããã°ãªããã ãã®ããã®æ¡å¼µãã ãServer Name Indicationãã¨ããããã§ããã ãã¡ãããã®æç¹ã§ã¯ãã¾ã éµã®äº¤æã¯è¡ãªããã¦ããªãã®ã§ã ãã¹ãåã¯å¹³æã§éãããã åç½®ããé·ããªã£ã¦ãã¾ã£ããã ãã® Server Name Indication (SNI) ã stone ã§ãµãã¼ããã¦ã¿ã (stone.c Revision 2
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}