e-Pares ã¯æ½è¨æ å ±ç®¡çã·ã¹ãã ã§ããe-Pares ã«ã¯ãã»ãã·ã§ã³åºå®ã®èå¼±æ§ãåå¨ãã¾ãã
e-Pares ã¯æ½è¨æ å ±ç®¡çã·ã¹ãã ã§ããe-Pares ã«ã¯ãã»ãã·ã§ã³åºå®ã®èå¼±æ§ãåå¨ãã¾ãã
æè¿è³¼å ¥ããPHPÃæºå¸¯ãµã¤ã å®è·µã¢ããªã±ã¼ã·ã§ã³éãèªãã§ãã¦å¦ãªæããããã®ã§ããã®æè¦ã¯ãªãã ããã¨æã£ã¦ãããããã®çç±ã«æ°ã¥ãããæ¬æ¸ã«åºã¦ããã¢ããªã±ã¼ã·ã§ã³ã¯ãPHPã®ã»ãã·ã§ã³ç®¡çæ©æ§ã使ã£ã¦ããªãã®ã ããããªé¦¬é¹¿ãªã¨æã£ãããç®æ¬¡ã«ãç´¢å¼ã«ããã»ãã·ã§ã³ãããsessionãã¨ããèªã¯åºã¦ããªãããµã³ãã«ããã°ã©ã ã®CD-ROMä¸ã§ session ãæ¤ç´¢ãã¦ãåºã¦ããªãã®ã§ãã»ãã·ã§ã³ã¯ã©ãã§ã使ã£ã¦ããªãã®ã ããã ããã¯è¨ã£ã¦ããæ¬æ¸ã«ã¯ããã°ãSNSãªã©èªè¨¼ãå¿ è¦ãªã¢ããªã±ã¼ã·ã§ã³ãç»å ´ãããæ¬æ¸ã§æ¡ç¨ãã¦ããèªè¨¼æ¹å¼ã¯ããã ã æºå¸¯é»è©±ã®åä½èå¥çªå·ãç¨ãããããããããããããã°ã¤ã³ãã®ã¿ã使ã èªè¨¼ç¶æ ãã»ãã·ã§ã³ç®¡çæ©æ§ã§ç¶æããªããå ¨ã¦ã®ãã¼ã¸ã§æ¯åèªè¨¼ãã ãã®ããããiã¢ã¼ãIDããªã©ãã¦ã¼ã¶ã«ç¢ºèªããã«èªåçã«éä¿¡ãããIDãç¨ãã ã¤ã¾ããå ¨ã¦
ãªãPHPã¢ããªã«ã»ãã¥ãªãã£ãã¼ã«ãå¤ãã®ã?ï¼ç¬¬25åãPHPã®ã¢ãã¬ã¹è ±ã«ã¦ã大å£éç·æ°ãPHPã®Session Adoptionåé¡ã«ã¤ãã¦åãä¸ãã¦ããã大å£æ°ã¯åº¦ã ãã®åé¡ãåãä¸ãã¦ããããä»ã®ã¨ããæ°ã®ä¸»å¼µã«å調ãã人ãè¦ãããªããããããã®ã¯ãã§ã大å£æ°ã®ä¸»å¼µã¯ééã£ã¦ããã¨ç§ã¯æãã 以ä¸ã大å£æ°ã®ä¸»å¼µãå®éã«è©¦ãã¦ã¿ãå½¢ã§ãé ã«èª¬æãããã 大å£æ°ã®ä¸»å¼µ 大å£æ°ã®ä¸»å¼µã¯ãPHPã«ã¯Session Adoptionèå¼±æ§ãããããã«ãæ¨æºçãªSession Fixation対çã§ããsession_regenerate_id()ãæ½ãã¦ãããã®å¯¾çã¯æå¹ã§ã¯ãªãã¨ãããã®ã ã ãããï¼å®éã«ã¯ç¾å¨ã«è³ãã¾ã§PHPã®ã»ãã·ã§ã³ã¢ã¸ã¥ã¼ã«ã®ã»ãã·ã§ã³ã¢ããã·ã§ã³èå¼±æ§ã¯ä¿®æ£ãããªãã¾ã¾ã«ãªã£ã¦ãã¾ãããã®ããã«ï¼æ¬æ¥ã¯session_regenerate_idé¢æ°ããã°ã¤ã³
PHPã«ã¯HTTPã»ãã·ã§ã³ç®¡çã¢ã¸ã¥ã¼ã«ãæ¨æºã§ä»ãã¦ãã¾ãããã®ã»ãã·ã§ã³ã¢ã¸ã¥ã¼ã«ã«ã¯é常ã«é大ãªã»ãã¥ãªãã£ä¸ã®èå¼±æ§ãä¿®æ£ãããã«æ®ã£ã¦ãã¾ãããã®èå¼±æ§ã¨ã¯ã»ãã·ã§ã³ã¢ããã·ã§ã³ã§ãã ã»ãã·ã§ã³ã¢ããã·ã§ã³ã¨ã¯ãã»ãã·ã§ã³åºå®åæ»æã«å©ç¨ãããèå¼±æ§ã§ããPHPã®ã»ãã·ã§ã³ç®¡çã¢ã¸ã¥ã¼ã«ãã»ãã·ã§ã³ã¢ããã·ã§ã³ã«èå¼±ã§ãããã¨ã¯ãããªã以åãä½å¹´ãåããç¥ããã¦ãã¾ããããããéçºè ã®ç解ä¸è¶³ããèå¼±æ§ãæ¾ç½®ãããã¾ã¾ã«ãªã£ã¦ãã¾ãã ã»ãã·ã§ã³ã¢ããã·ã§ã³ã¨ã¯ ã»ãã·ã§ã³ã¢ããã·ã§ã³ã¨ã¯ããã©ã¦ã¶çããéä¿¡ãããæªåæåã»ãã·ã§ã³IDããã®ã¾ã¾å©ç¨ãã¦ã»ãã·ã§ã³ãåæåãã¦ãã¾ãèå¼±æ§ã§ããã¦ã¼ã¶ãéä¿¡ãã¦ããIDã§ã第ä¸è ã«äºæ³ã§ããªãæååã§ããã°å¤§ä¸å¤«ãªã®ã§ã¯ï¼ã¨èããæ¹ãããã¨æãã¾ãããã®éãã§ç¬¬ä¸è ã«äºæ³ã§ããªããã°åé¡ãªãã§ãããä»®ã«äºæ³ã§ãã¦ããã°ã¤ã³ããé
ã¬ã«ã¼ã³ãOfficeã®ã°ã«ã¼ãã¦ã§ã¢è£½åã«ã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªãªã©3件ã®èå¼±æ§ãçºè¦ãããã æ å ±å¦çæ¨é²æ©æ§ï¼IPAï¼ã»ãã¥ãªãã£ã»ã³ã¿ã¼ã¨JPCERTã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ã¯6æ27æ¥ããµã¤ãã¦ãºã®ã°ã«ã¼ãã¦ã§ã¢è£½åããµã¤ãã¦ãº Officeããªã©ã«3件ã®èå¼±æ§ãçºè¦ãããã¨ãã¦ãJVN(Japan Vulnerability Notes)ã«æ å ±ãå ¬éããã çºè¦ãããèå¼±æ§ã¯ãã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªï¼CSRFï¼ã¨ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼XSSï¼ãã»ãã·ã§ã³åºå®ã®åè¨3件ã対象製åã¯ãCSRFããµã¤ãã¦ãº Office 6ããã³ãµã¤ãã¦ãº ãã㨠6.0ï¼1.0ï¼ããåã®ãã¼ã¸ã§ã³ããµã¤ãã¦ãº ã¬ã«ã¼ã³ 2.0.0ï½2.1.3ãXSSã¨ã»ãã·ã§ã³åºå®ããµã¤ãã¦ãº ã¬ã«ã¼ã³ 2.0.0ï½2.1.3ã¨ãªã£ã¦ããã CSRFã®èå¼±æ§ã§ã¯ãã¦ã¼ã¶ã¼ã該å½è£½
å¹³ç´ ãããPHPããï¼ãããæ顧ããã ããèª ã«ãããã¨ããããã¾ãã 2006å¹´ããéå¶ãã¦ã¾ããã¾ãããPHPããï¼ãã§ããããµã¼ãã¹ã®å©ç¨ç¶æ³ãéã¿ã¾ãã¦ã2018å¹´9æ25æ¥ï¼ç«ææ¥ï¼ããã¡ã¾ãã¦ãµã¼ãã¹ãçµäºããã¦ããã ããã¨ã«ãªãã¾ããã ãµã¼ãã¹çµäºã«ä¼´ãã¾ãã¦ã2018å¹´8æ28æ¥ï¼ç«ææ¥ï¼ãæã¡ã¾ãã¦ãæ°è¦ä¼å¡ç»é²ãªãã³ã«Q&Aæ²ç¤ºæ¿ã¸ã®æ°ããªè³ªåãåçã®æ稿ãåæ¢ããã¦ããã ãã¾ãã ãªãããç»é²ããã ããçæ§ã®å人æ å ±ã«ã¤ãã¾ãã¦ã¯ããµã¼ãã¹çµäºå¾ãå¼ç¤¾ã責任ããã£ã¦æ¶å»ãããã¾ãã ããã¾ã§å¤ãã®çæ§ã«ãå©ç¨ãããã ãã¾ãã¦ãèª ã«ãããã¨ããããã¾ããã ãµã¼ãã¹çµäºã«ä¼´ããçæ§ã«ã¯ãä¸ä¾¿ãããããããã¾ããã¨ãå¿ãããè©«ã³ç³ãä¸ãã¾ãã æ¬ä»¶ã«é¢ãããåãåããã¯ãã¡ããããé¡ããããã¾ãã
PHP ã«ãããã»ãã·ã§ã³ç®¡çã§ã¯ã $_GET ã§ã¯ãªãã$_POST ã§ããªãã$_COOKIE ããã»ãã·ã§ã³ID ãåãåãã ããã«ã$_COOKIE 以å¤ã§åå¸(ãã±ãã)ãåãåã£ã¦ã ã»ãã·ã§ã³ID ã¨ç §åãã¦æ£å½æ§ã確ãããã®ãå®ç³ã ã 1. $_COOKIE ã«ããåãåããå¿ è¦ãªçç±: 1.1 æªæã®ç¬¬ä¸è ã¯ãããªãã®ãªã¯ã¨ã¹ãã«å«ã¾ãã $_GET, $_POST ããèªç±èªå¨ã«å¤æ´ããç½ ãä½ããã 1.2 PHP ã§ã¯ãªã¯ã¨ã¹ãå¤æ°($_GET, $_POST, $_COOKIE)ã«ãã£ã¦ã»ãã·ã§ã³ID ãæå®ã§ããã ãããã£ã¦ã $_GET, $_POST ã§ã»ãã·ã§ã³IDãåãåããããªã·ã¹ãã ã§ã¯ã æªæã®ç¬¬ä¸è ãä»æããç½ ã«ãã£ã¦ã æªæã®ç¬¬ä¸è ãæå®ããã»ãã·ã§ã³ID ã§ã ããªãã®ã»ãã·ã§ã³ãéå§ãããå¯è½æ§ãããã 2. $_COOKIE 以å¤ã§ã®
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}