Microsoft has a fix for preventing the next CrowdStrike fiasco, but is it a good one?Maybe giving security firms access to the Windows isnât the best idea, but freezing them out could be worse.
IPA(ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§)ã¯3æ18æ¥ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æããWebãµã¤ããé²å¾¡ããããã®å¯¾çã¨ãã¦ãWebã¢ããªã±ã¼ã·ã§ã³ã®å®å ¨ãªå®è£ æ¹æ³ã解説ããè³æãå®å ¨ãªSQLã®å¼ã³åºãæ¹ããå ¬éããã IPAã¯ãç¡åã§å ¬éãã¦ããSQLã¤ã³ã¸ã§ã¯ã·ã§ã³æ¤åºãã¼ã«ãiLogScannerãã§èå¼±æ§å¯¾çæ å ±ãã¼ã¿ãã¼ã¹ãJVN iPediaãã®ã¢ã¯ã»ã¹ãã°ã解æãã¦ããããã®çµæãWebãµã¤ããçã£ãã¨æãããæ»æã®ãã¡ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æãå ¨ä½ã®45%ãWebãµã¼ãã®ãã¹ã¯ã¼ããã¡ã¤ã«ãç°å¢è¨å®ãã¡ã¤ã«ã®æ å ±ãçã£ããã£ã¬ã¯ããªã»ãã©ãã¼ãµã«æ»æã38%ãå ãã¦ãããã¨ãããã£ãã SQLã¤ã³ã¸ã§ã¯ã·ã§ã³æ¤åºãã¼ã«ãiLogScannerãã«ããèå¼±æ§å¯¾çæ å ±ãã¼ã¿ãã¼ã¹ãJVN iPediaãã®è§£æçµæãè³æ:IPA SQLã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æãæåããå ´åãWebãµ
â ããããããã°ã¤ã³ãDNSãªãã¤ã³ãã£ã³ã°èæ§ã®ãã§ãã¯æ¹æ³ ãã®ã¨ã³ããªã§ã¯ãã±ã¼ã¿ã¤åãWebãµã¤ããDNSãªãã¤ã³ãã£ã³ã°æ»æã«å¯¾ããé²å¾¡èæ§ããããã©ããããã§ãã¯ããæ¹æ³ã説æãã¾ããã±ã¼ã¿ã¤åãã«ããããããã°ã¤ã³ãæ©è½ããã¤Webãµã¤ãããã§ãã¯å¯¾è±¡ã¨ãã¾ãã åºæ¬çãªåæã¨ãã¦ãæ¤æ»å¯¾è±¡ã®Webãµã¤ãã®ç®¡çè ãèªãæ¤æ»ãããã¨ãæ³å®ãã¦ãã¾ãã ç¨æãããã® ãã§ãã¯å¯¾è±¡ã®Webã¢ããªã±ã¼ã·ã§ã³(ãããããã°ã¤ã³æ©è½ãã) æºå¸¯é»è©±ï¼ãããããã°ã¤ã³å¯è½ãªãã®ï¼ ã¤ã³ã¿ã¼ãããæ¥ç¶ããããã½ã³ã³ ã¹ããã0:IPã¢ãã¬ã¹ã®èª¿æ» æ¤æ»å¯¾è±¡ã®Webãµã¼ãã¼ã®IPã¢ãã¬ã¹ã調ã¹ã¾ããä¸ä¾ã¨ãã¦ãæ¤æ»å¯¾è±¡ãµã¼ãã¼ã®ãã¹ãåã mobile.example.com ã®å ´åã以ä¸ã®ã³ãã³ãã§IPã¢ãã¬ã¹ã調ã¹ããã¨ãã§ãã¾ãã C:>nslookup mobile.example.
2006.03.06 è¿½è¨ ãã®åé¡ã«ã¤ãã¦ã¯ãiakioæ¥èª(2006-02-15)ã«ããã¦ãPHP ã¹ã¯ãªããã§åé¿ããæ¹æ³ã®ä¾ã¨ãPostgreSQL ã« Patch ãå½ã¦ã¦åé¿ããæ¹æ³ã示ãã¦ãããã¾ããåé¡ã®å½±é¿ãåããå ´åã¯åèã«ããã¨è¯ãã¨æãã¾ãã 1æ22æ¥ã«æ¸ãããaddslashes() ã«ãã SQL æååã®ã¨ã¹ã±ã¼ãåé¿åé¡ã®ç¶ãã§ããPostgreSQL ã§ããã«æ¤è¨¼ãã¦ã¿ã¾ããã çµè«ã¨ãã¦ã¯ãååã¨åæ§ã§ãããPostgreSQL ã«é¢ãã¦ã¯ãSJIS ã¯ä½¿ç¨ããªãæ¹ãå®å ¨ã¨ããäºã«ãªãã¾ãã ã¯ã©ã¤ã¢ã³ãã®æåã³ã¼ãã¨ãã¦ãSJIS ã使ç¨ãã¦ããå ´åãaddslashes() ã«ããã¨ã¹ã±ã¼ãã¯æ¢ã«ææããã¦ããéãã§ãããPostgreSQL ç¨ã®æååã¨ã¹ã±ã¼ãé¢æ°ã§ãããpg_escape_string() ã使ç¨ãã¦ããå ´åã§ãåé¡ãããã¾ã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}