ã©ã¤ã¶ã ã¼ã³æ»æã«å¯¾ããè¡ãå±ãã解説ãèªã¿ã¾ããã 大è¦æ¨¡ã¤ã³ã¸ã§ã¯ã·ã§ã³ ãLizaMoonãæ»æã«ã¤ãã¦èª¿ã¹ã¦ã¿ãã - piyolog ããã§ç´¹ä»ããã¦ããå 容ã¯ç´ æ´ãããã¨æãã®ã§ãããä¸ç¹ãWAFã«é¢ãã以ä¸ã®è¨è¿°ãå¼ã£ãããã¾ããã SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã§ããã°æ¢ç¥ã®æ»æææ³ã§ããWAFã§é²ããã¨ã¯åºæ¥ãã®ã§ã¯ã¨ããèãæ¹ãããã¾ãããä¾ãã°ãã©ãã¯ãªã¹ãã¿ã¤ãã®WAFã§ãã®æ°å¤ãªãã©ã«åãã¤ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãé²ããã¨ãåºæ¥ã¾ãããHTTPãªã¯ã¨ã¹ãã¨ãã¦åããæååã ãã§ãæçµçã«ãã¼ã¿ãã¼ã¹ã«å¯¾ãã¦çºè¡ãããSQLã§ãã®æååãã©ã®ãããªæ±ãã«ãªãã(æ°å¤ãªãã©ã«ã«ãªãã®ãã©ãã)å¤æãããã¨ãåºæ¥ãªãããã§ãã æ¬å½ã«ãã©ãã¯ãªã¹ãã¿ã¤ãã®WAFã§é²ããã¨ãã§ããªãã®ã§ãããããIBMã®ã¬ãã¼ãã«ç´¹ä»ããã¦ãã以ä¸ã®æ»æã§èãã¦ã¿ã¾ãã /target.asp
ã¯ããã« ä¼æ¥æ å ±ã·ã¹ãã ã®å¤ãã¯ãï¼1ï¼Webã¢ããªã±ã¼ã·ã§ã³ã»ãµã¼ãã¼ï¼ç»é¢ãæ¥åãã¸ãã¯ãæ å½ããï¼ã¨ï¼2ï¼ãã¼ã¿ãã¼ã¹ã»ãµã¼ãã¼ï¼ãã¼ã¿ãæ ¼ç´ããï¼ã§æ§ç¯ããã¦ãã¾ãããããã®ãµã¼ãã¼ã»ã½ããã«å¯¾ããä¸æ£ã¢ã¯ã»ã¹ãæä½ãã¹ãé²ããã¨ããä¼æ¥ã®ãã¼ã¿ãå®ãããã§éè¦ã§ãã æ¬é£è¼ã§ã¯ã2åã«ããããWebã¢ããªã±ã¼ã·ã§ã³ã»ãµã¼ãã¼ã®ã»ãã¥ãªãã£ï¼ç¬¬1åï¼ã¨ããã¼ã¿ãã¼ã¹ã»ãµã¼ãã¼ã®ã»ãã¥ãªãã£ï¼ç¬¬2åï¼ã解説ãã¾ãã Webãµã¤ãã«ãããèå¼±æ§ã®ç¾ç¶ Webã¢ããªã±ã¼ã·ã§ã³ã»ãµã¼ãã¼ã®ã»ãã¥ãªãã£å¯¾çãèããåæã¨ãã¦ã èå¼±æ§ã®ç¾ç¶ è å¨ï¼æ»æï¼ã®ç¾ç¶ ãç¥ã£ã¦ããå¿ è¦ãããã¾ããèå¼±æ§ã¨è å¨ã®ä¸¡æ¹ãæãã¨ãä¼æ¥ã®ãã¼ã¿ã¯å®å ¨ã§ã¯ãªããªãã¾ãã ã¾ãã¯ãèå¼±æ§ã®ç¾ç¶ãã説æãã¾ãã IPAï¼ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ï¼ã®ã»ãã¥ãªãã£ã»ã³ã¿ã¼ã§ã¯ãçµæ¸ç£æ¥çã®å示ã«åºã¥ããã½ããã¦
ã¢ã«ãã¤æ ªå¼ä¼ç¤¾ã¯5æ20æ¥ãã¯ã©ã¦ããã¼ã¹ã®Webã¢ããªã±ã¼ã·ã§ã³ãã¡ã¤ã¢ã¦ã©ã¼ã«ã¢ã¸ã¥ã¼ã«ï¼ä»¥ä¸ãWAFã¢ã¸ã¥ã¼ã«ï¼ãçºè¡¨ãããã¢ã«ãã¤ã®ãµã¼ãã¼ãããã¯ã¼ã¯ãEdgePlatformãä¸ã«å®è£ ãããWAFã§ãæ»æãã©ãã£ãã¯ããã¼ã¿ã»ã³ã¿ã¼ã«å±ãåã«é²å¾¡ã§ããã®ãç¹é·ããããå©ç¨ãã¦ãã¯ã©ã¦ãä¸ã§å®å ¨ãªã¯ã¬ã¸ããã«ã¼ã決æ¸ç¨ãããã¯ã¼ã¯ãæä¾ãããPCIDSSå®å ¨æºæ ãµã¼ãã¹ãããåæ¥ããã¹ã¿ã¼ãããã WAFã¢ã¸ã¥ã¼ã«ã¯ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ãã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ãªã©ã®HTTPæ»æãããWebã¢ããªã±ã¼ã·ã§ã³ãé²ãããã®ã»ãã¥ãªãã£ã¢ã¸ã¥ã¼ã«ãä¸çä¸ã®ã¢ã«ãã¤ãããã¯ã¼ã¯ä¸ã«4ä¸å°åæ£ããããµã¼ãã¼ç¾¤ã»EdgePlatformä¸ã«å®è£ ãããããã¼ã¿ã»ã³ã¿ã¼å´ã«å°ç¨ãã¼ãã¦ã§ã¢ãè¨ç½®ããªãã¦æ¸ãã»ããä¿å®ã»éç¨ãã¢ã«ãã¤ãè¡ããããã¦ã¼ã¶ã¼ã¯WAFã®éç¨ã³ã¹ããåæ¸ã§ããã
WAF Virtual Patching Challenge: Securing WebGoat with ModSecurity Ryan Barnett Breach Security (www.breach.com) rbarnet[email protected] Revision 1 (January 20, 2009) Abstract In this paper, we present the technical details behind a virtual patch, which is a critical protection function provided by web application firewalls (WAFs). A virtual patch is a powerful, agile mitigation strategy to quickly hel
ãASPã»SaaSãããã¯ãµã¼ãã¹ã®æä¾ãçµäºãã¦ããã¾ãã å¤ãã®ã客æ§ã«ãæ顧ãè³ããèª ã«ãããã¨ããããã¾ããã ãªãããä¸æãªç¹ãã質åãªã©ããããã¾ãããä¸è¨ãããåãåãããã ããã â åãåããï¼https://www.bplats.co.jp/form/ï¼
ãããããªãæ£æ飾ã ãæ£æ飾ãã«èç¡ä¸¹ã®å¯ãæ¤ããé¢è¥¿ã¯è²ã ãªèç¡ä¸¹ãæã£ã¦ãã¦é¸ã¶ã®ã楽ãã ãã³ã»ã³ã« ããã³ãºãã¥ã¼ãã£ã¼ ãã®å¾ãéæã®ãã°ã«é£¾ãã¾ãããè¯ããã«ãªãã¾ããã ããã¦ããç¸ä½ãã æ¾ãæ°´å¼ããããç¸ã«åºã®å天ãå ãã¾ãã ãããçµã³ãããåºãçµã°ããâ¦
ãã®è¬åº§ã¯ããµã¼ãã»ãµã¤ãã§ã®Javaå©ç¨ã®ä»£è¡¨çãªææ³ã®1ã¤ã§ããJ2EEã®åºç¤ããã§ããã ãåºæ¬çãªã¨ãããã説æãããã¨ãç®çã¨ãã¦ãã¾ãããã®ãJ2EEã®åççãªèª¬æãã«ã¨ã£ã¦ã®ä¸çªã®åé¡ã¯ãJ2EEãé常ã«å¤ãã®è¦ç´ æè¡ãããªã巨大ãªã·ã¹ãã ã ã¨ãããã¨ã§ãã以ä¸ã«ãJ2EEãæ§æããåºæ¬çãªæè¡ã®ä¸è¦§ã示ãã¾ãï¼ãããã®æè¡ã«ãã¼ã¸ã§ã³çªå·ãä»ãã¦ããã®ã¯ãJ2EEèªèº«ãå¤åãç¶ãã¦ãããã¨ã示ãã¦ãã¾ãããã®ãªã¹ãã¯ããã®å稿ãæ¸ãã¦ãã2001å¹´3ææç¹ã§ã®J2EE j2sdkee-1.3betaã®æ§æãåæ ãã¦ãã¾ãï¼ã
ãã®ã¦ã§ããµã¤ãã¯è²©å£²ç¨ã§ãï¼ studyinghttp.net ã¯ãããªãããæ¢ãã®æ å ±ã®å ¨ã¦ã®ææ°ãã¤æé©ãªã½ã¼ã¹ã§ããä¸è¬ãããã¯ããããããæ¤ç´¢ã§ããå 容ã¯ãstudyinghttp.netãå ¨ã¦ã¨ãªãã¾ããããªãããæ¢ãã®å 容ãè¦ã¤ãããã¨ãé¡ã£ã¦ãã¾ãï¼
â é§ç®ãªæè¡ææ¸ã®è¦åãæ¹ ãã®1 ã¯ã¦ãªããã¯ãã¼ã¯ã®ãããã³ããªãè¦ã¦ããã¨ããã300ãè¶ ããã¦ã¼ã¶ã«ç»é²ããã以ä¸ã®è¨äºããã£ãã ä»å¤åããSQLã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾ç, ä¸é宣, @IT, 2006å¹´11æ2æ¥ ã¾ãä¸é宣ããé¡è¦ç¥ããªã®ã§ãºããªãããã¨ã«ããã ãããããã®å¯¾çã¯ã¾ã æ¬å½ã«ç解ããã¦ããªãããã«æããã ã¸ãã çµããã®æ¹ãè¦ã¦ã¿ãã¨ã Webã¢ããªã±ã¼ã·ã§ã³ã®å¯¾ç å ¥åå¤ã®SQLã®ç¹æ®æåãé©åã«ã¨ã¹ã±ã¼ã å ¥åå¤ï¼ããã°ã©ã ï¼ããã»ã¹ï¼ã«å¤é¨ããå ¥ã£ã¦ãããã® ã·ããJISã®å ´åã«ã¯1ãã¤ãæåãæ´ç SQLã®è¨è¿°ããªããããã«O/Rï¼Object/Relationalï¼ãããã³ã°ãæ´»ç¨ æ»æè ã«å½¹ç«ã¤æ å ±ãä¸ããªãããã«ãä¸è¦ãªã¨ã©ã¼ã¡ãã»ã¼ã¸ï¼ãã¼ã¿ãã¼ã¹ãåºåããã¨ã©ã¼ãªã©ï¼ã®è¡¨ç¤ºãææ¢ å¯¾çã«ãæºåãããæã(prepared statement)
â ãã°ã¤ã³åSession Fixationãã©ãããã 21æ¥ã®æ¥è¨ãSession Fixationèå¼±æ§ã®è²¬ä»»ä¸»ä½ã¯Webã¢ããªãWebãã©ã¦ã¶ããã§ããã©ã¦ã¶ãã³ãã¯Cookie Monsteråé¡ãã©ãããã®ã ãããã¨ãããã¨ã«ã¤ãã¦æ¸ããããFirefox 2.0 ã«ã¤ãã¦èª¿ã¹ã¦ã¿ãã¨ããã解決ãã¦ããªãã£ããã¾ããIE 7 ã解決ãã¦ããªãã ãã®ãããªç¶æ³ã§ã¯ãã»ãã·ã§ã³è¿½è·¡ãcookieã ãã«ãã£ã¦è¡ããã¦ããå ´åã§ãã£ã¦ããSession Fixationæ»æã«å¯¾ãã¦é æ ®ããããå¾ãªãã ããã¾ã§ãSession Fixation対çã¨ããã°ããã°ã¤ã³å¾ã®ç¶æ ãã»ãã·ã§ã³ãã¤ã¸ã£ãã¯ããããã¨ã®é²æ¢ã®ã¿ãèªããããã¨ãå¤ãã£ããããã°ã¤ã³åã«ã¤ãã¦ã¯ã©ãã ãããã ãã¨ãã°ããã°ã¤ã³åãã使ããã·ã§ããã³ã°ã«ã¼ãã«å¯¾ãã¦Session Fixationæ»æãè¡ãããã¨
â ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ãã¯ä½ã®ããã«ããã®ã å æãã¸ã£ãã³ãããéè¡ãããSecurIDããéããã¦ãããRSAã»ãã¥ãªãã£ã®ã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ãçæå¨ï¼ä»¥ä¸ããã¼ã¯ã³ãï¼ã ãã¸ã£ãã³ãããéè¡ã¯å ¨å£åº§ã®å©ç¨è ã«å¯¾ãã¦ãããé å¸ãã¦ããã å±ããéµä¾¿ç©ã«ã¯å³1ã®æ¡å ç¶ãå ¥ã£ã¦ããã ããã«æ¸ããã¦ãããã¨ã¯äºå®ã§ãªãã®ã§ãä¿¡ãã¦ã¯ãããªãã 2. ãã¼ã¯ã³ã¯ã¹ãã¤ã¦ã§ã¢ã«ç£è¦ãããªãã®ã§å®å ¨ã§ãã ãã¼ã¯ã³ã¯ãã½ã³ã³ãæºå¸¯é»è©±ãªã©ã¨ä¸åã®éä¿¡ãè¡ãã¾ãããä¸ãä¸ãã½ã³ã³ãæºå¸¯é»è©±ãã¹ãã¤ã¦ã§ã¢ï¼ä¸æ£ããã°ã©ã ï¼ã«ææãã¦ãããã¼ã¯ã³ã«è¡¨ç¤ºãããã¯ã³ã¿ã¤ã ãã¹ã¯ã¼ããç£è¦ããããã¨ããªãå®å¿ã§ãã ãããèªãã ã¦ã¼ã¶ã¯ããä»å¾ã¯ãã¦ã³ãã¼ããã .exe ãã¡ã¤ã«ãå®å¿ãã¦å®è¡ã§ãããã¨æã£ã¦ãã¾ããããããªãããããã¤ã®æ¨é¦¬ï¼ä¸æ£ããã°ã©ã ï¼ãå®è¡ãã¦ãã¾ã£ã¦ã¯ããã¨ããã®ã¯ã³ã¿ã¤ã ãã¹
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}