é常ãsession_start()ããã¨ã¯ããã¼ã«ã»ãã·ã§ã³IDãçºè¡ããã次åã¢ã¯ã»ã¹ããæã«ã¯ããã¼ã®ä¸ã«ã»ãã·ã§ã³IDãããã°ãã»ãã·ã§ã³ãèªã¿è¾¼ãã§ãã¼ã¿ãä¿æã§ããããããï¼°ï¼£ã¨éããæºå¸¯ã§ã¯cookieï¼ã¯ããã¼ï¼ã使ããªãæ©ç¨®ããããé常ã®æ¹æ³ã§ã¯æºå¸¯ã§ã»ãã·ã§ã³ã使ããªãã®ã ã ããã解決ããæ¹æ³ã¨ãã¦URLã«ã»ãã·ã§ã³IDãåãè¾¼ãã¨ããæ¹æ³ããããã¯ããã¼ã§ã¯ãªãGETãPOSTã§ã»ãã·ã§ã³IDãæã¡ã¾ããã®ã§ããããã ãå ¨ã¦ã®ãªã³ã¯ããã©ã¼ã ã¿ã°ã«ã»ãã·ã§ã³IDãåãè¾¼ãã®ã¯éª¨ãæããã ãããããããæã¯php.iniã®session.use_trans_sidãOnã«ããã°ãããããããã¨èªåçã«å ¨ã¦ã®ç¸å¯¾ãªã³ã¯ã«ã»ãã·ã§ã³IDãåãè¾¼ã¾ããã ããããï¼°ï¼£ã¨æºå¸¯ã¨åãã¹ã¯ãªããã§åããã¦ããå ´åãï¼°ï¼£ã§ãã»ãã·ã§ã³IDãåãè¾¼ã¾ãã¦ãã¾ãã¨ã»ãã·ã§ã³IDã丸è¦ã
Webã¢ããªã±ã¼ã·ã§ã³ã®ããå¼±æ§ã示ãç¨èªã¨ãã¦ï¼ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ï¼SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã¨ãã£ãè¨èã®èªç¥åº¦ã¯ããªãé«ã¾ã£ããããã°ã»ãµã¤ããªã©ã§ãæ´»çºã«è°è«ããã¦ããããããï¼Webãµã¤ãã®å®æ ã¯ã©ãã ãããã çè ã®æå±ãã京ã»ã©ã³ãã¥ãã±ã¼ã·ã§ã³ã·ã¹ãã ã§ã¯æ¨å¹´ï¼2006å¹´ï¼ï¼ããå¼±æ§è¨ºæãå®æ½ããWebãµã¤ãã®çµ±è¨æ å ±ã2007å¹´ç Webã¢ããªã±ã¼ã·ã§ã³ããå¼±æ§å¾åããçºè¡¨ãããããã«ããã¨ï¼ãã½ã³ã³åãWebãµã¤ãã®48%ã«è´å½çãªããå¼±æ§ãè¦ã¤ãã£ãããã®ãã¡ã¯ã¼ã¹ã1ä½ã¯ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ã§56ï¼ ï¼2ä½ã¯SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã§11%ã¨ï¼ã©ã¡ããã¤ã³ã¸ã§ã¯ã·ã§ã³ï¼æ³¨å ¥ï¼ç³»ã®ããå¼±æ§ããããã®ããå¼±æ§ãæã£ãå±éºãªãµã¤ãã¯ä¾ç¶ã¨ãã¦åå¨ããã®ãå®æ ã§ããã ãããWebã¢ããªã±ã¼ã·ã§ã³ã®ããå¼±æ§ããã¾ããªããªããªãçç±ã¯ããã¤ããããï¼ä»¥åã¯ããã
ãã¼ã¸ãã¢å·ã¢ã¼ãªã³ãã³çº--ç±³å½åå®å ¨ä¿éçï¼DHSï¼ã®è³éæä¾ã«ãããã»ãã¥ãªãã£é¢é£ãã°ãåé²ããæ¨æºçãªãè¾æ¸ããä½æããè¨ç»ãå½¢ã«ãªãã¤ã¤ãããåè¨ç»ã®æ¨é²ã¡ã³ãã¼ãç±³å½æé3æ1æ¥ã«çºè¡¨ããã ãã®åãçµã¿ã¯ãCommon Weakness Enumerationï¼CWEï¼ãã¨åä»ãããããããã¡ãªã¼ãã¼ããã¼ãæ¸å¼æå®æååã®ã¨ã©ã¼ãªã©ãã½ããã¦ã§ã¢èå¼±æ§ã®æ£å¼ãªãªã¹ãã®ä½æãç®æãã¦ãããç¾å¨ä½¿ããã¦ããã½ããã¦ã§ã¢èå¼±æ§ã®ç¨èªã¯ãå¤ãã®ãã¯ããã¸ä¼æ¥ãã»ãã¥ãªãã£ä¼æ¥ã«ãã£ã¦ç°ãªããããã®ãªã¹ããæ¨æºè¨èªã¨ãã¦ç¨èªã®çµ±ä¸ã«å½¹ç«ã¦ãããã CWEè¨ç»ãçµ±æ¬ããéå¶å©å£ä½MITREã®æ å ±ã»ãã¥ãªãã£æ å½ä¸»å¸ã¨ã³ã¸ãã¢Steve Christeyæ°ã¯ããã¼ã¸ãã¢å·ã¢ã¼ãªã³ãã³ã§éå¬ããããBlack Hat DC 2007 Briefings & Trainingãã§ãã¬ã¼ã³ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}