#LTé§å 29ã§ã®çºè¡¨ã¹ã©ã¤ã
JVMã«ããã¦ãã2ã¤ã®ã¯ã©ã¹ã¯ãåä¸ã®ã¯ã©ã¹ãã¼ãã§ãã¼ããããåä¸ã®å®å ¨ä¿®é£¾åãæã¤ã¨ããåä¸ã®ã¯ã©ã¹ï¼ããã¦åä¸ã®åï¼ã§ããã[JVMSpec 1999]ãåãååã§ãã£ã¦ãããã±ã¼ã¸åãç°ãªãã°ç°ãªãã¯ã©ã¹ã§ãããã¾ããå®å ¨ä¿®é£¾åãåä¸ã§ãã£ã¦ããç°ãªãã¯ã©ã¹ãã¼ãã«ãã£ã¦ãã¼ãããã¦ããã°ãç°ãªãã¯ã©ã¹ã§ããã ãã¨ãã°equals()ã¡ã½ãããå®è£ ããå ´åãä¸ãããããªãã¸ã§ã¯ãã®ã¯ã©ã¹åã¨2ã¤ã®ãªãã¸ã§ã¯ãã®ã¯ã©ã¹åã®åä¸æ§ãã§ãã¯ãå¿ è¦ã¨ãªãã§ãããããã®æ¯è¼ãæ£ããè¡ããªãã¨ãç°ãªãã¯ã©ã¹ã®2ã¤ã®ãªãã¸ã§ã¯ããåãã¯ã©ã¹ã®ãªãã¸ã§ã¯ãã§ããã¨ã¿ãªãã¦ãã¾ãå¯è½æ§ãããããã®ãããªæ¯è¼ãè¡ãéã«ã¯ãã¯ã©ã¹åãæ¯è¼ãã¦ã¯ãªããªãã ä¸è¨ã®ãããªåé¡ã®ããã³ã¼ãã¯ãã©ã®ãããªé¢æ°ãå®è¡ãã¦ãããã«ãããããmix-and-matchæ»æãåããå¯è½æ§ããããæ»æè ã¯ã対象ã¨ãã¦
ã¯ã¦ãªã°ã«ã¼ãã®çµäºæ¥ã2020å¹´1æ31æ¥(é)ã«æ±ºå®ãã¾ãã 以ä¸ã®ã¨ã³ããªã®éããä»å¹´æ«ãç®å¦ã«ã¯ã¦ãªã°ã«ã¼ããçµäºäºå®ã§ããæ¨ããç¥ãããã¦ããã¾ããã 2019å¹´æ«ãç®å¦ã«ãã¯ã¦ãªã°ã«ã¼ãã®æä¾ãçµäºããäºå®ã§ã - ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãã®ãã³ãæ£å¼ã«çµäºæ¥ã決å®ãããã¾ããã®ã§ã以ä¸ã®éãã確èªãã ããã çµäºæ¥: 2020å¹´1æ31æ¥(é) ã¨ã¯ã¹ãã¼ãå¸æç³è«æé:2020å¹´1æ31æ¥(é) çµäºæ¥ä»¥éã¯ãã¯ã¦ãªã°ã«ã¼ãã®é²è¦§ããã³æ稿ã¯è¡ãã¾ãããæ¥è¨ã®ã¨ã¯ã¹ãã¼ããå¿ è¦ãªæ¹ã¯ä»¥ä¸ã®è¨äºã«ãããã£ã¦æç¶ãããã¦ãã ããã ã¯ã¦ãªã°ã«ã¼ãã«æ稿ãããæ¥è¨ãã¼ã¿ã®ã¨ã¯ã¹ãã¼ãã«ã¤ã㦠- ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãå©ç¨ã®ã¿ãªãã¾ã«ã¯ãè¿·æãããããããã¾ãããã©ãããããããé¡ããããã¾ãã 2020-06-25 è¿½è¨ ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ã®ã¨ã¯ã¹ãã¼ããã¼ã¿ã¯2020å¹´2æ28
çµæ§ããã£ãã®ã§ã¡ã¢ãWindows 7ã§ã®ãã«ã³ã³ä»ä¸ã®è©±ã ãã¹ã¯ããããã«ã¹ã¿ãã¤ãºããããã«ãExplorerFrame.dllãä¸æ¸ããããã¨ããããã¢ã¯ã»ã¹è¨±å¯ãããã¾ããã¨è¨ããã¦æ¸ããªãã£ãã 管çè 権éã®ããã¦ã¼ã¶ãªã®ã«ãããããªãâ¦ã¨æã£ã¦èª¿ã¹ã¦ã¿ãããAdministratorsã°ã«ã¼ãã«ã¢ã¯ã»ã¹è¨±å¯ã®ãã«ã³ã³ããã¼ã«ããªãã ãããªããããä¼ç¤¾ã§è¦ããhostsãæ¸ãæããããªããã ãâ¦ã ï¼ã¢ã¯ã»ã¹è¨±å¯ã®èª¿ã¹æ¹ï¼ 対象ãã¡ã¤ã«ãå³ã¯ãªã㯠[ããããã£]ãéã ãã»ãã¥ãªãã£ãã¿ããéã ã°ã«ã¼ãåã¾ãã¯ã¦ã¼ã¶åãé¸æããã¨ãä¸ã®ãã¤ã³ã«ã¢ã¯ã»ã¹è¨±å¯ã®ç¶æ ã表示ããããããã§ãèªã¿åãã¨å®è¡ããèªã¿åãããããã§ãã¯ãå ¥ã£ã¦ããªãå ´åã¯ããã¡ã¤ã«ãç·¨éã§ããªãç¶æ ã ã§ã ç¶æ ã¯ããã£ããã©ããã®ä¸ã«ãã[ç·¨é]ãã¿ã³ãæ¼ãã¦æ¨©éä»ä¸ãããã¨ãã¦ããã¢ã¯ã»ã¹è¨±å¯ã
ã»ãã¥ãªãã£è¨ºæãã¼ã«æ¤è¨¼ç¨Webã¢ããªã±ã¼ã·ã§ã³ OWASP Broken Web Applications Project (OWASPBWA) ãããããããããµã¤ããã¯å¤ä»æ±è¥¿ãæ§ã ãªè¨èªãå½¢æ (ã½ã¼ã¹ã³ã¼ããVMã¤ã¡ã¼ã¸ãªã©)ã§åå¨ãã¦ãã¾ãããOWASPã®ãã®ããã¸ã§ã¯ãããã©ãã¼ããã°ååã§ãããã ããã¸ã§ã¯ãã«å«ã¾ãããããããµã¤ããä¸è¦§ https://code.google.com/p/owaspbwa/wiki/UserGuide#Training_Applications 診æãã¼ã«ã®åèãµã¤ã åå¿è Webã¢ããªã±ã¼ã·ã§ã³éçºè ããã§ãã¯ãã¹ãæ å ±æº2013 Appendix A: Testing Tools - OWASP Web Application Vulnerability Scanners - SAMATE Webã¢ããªã±ã¼ã·ã§ã³ æå AppSca
ããã§ãã¤ã³ã¹ãã¼ã«ãããã·ã³ã®8080çªãã¼ãããããã·ã¨ãã¦æå®ãã¦ããã§ãã¯ããããµã¤ãããã©ã¦ã¸ã³ã°ããã ãã§ãã 絶対ã«èªåã§ç®¡çãã¦ããªããµã¤ãã«å¯¾ãã¦å®è¡ããªãã§ãã ããã ãããã¦ã§ãããhoge.log ãå梱ã®ratproxy-report.shã§è§£æããã°ãã¬ãã¼ããHTMLã¨ãã¦åºåããã¾ãã ã¬ãã¼ãã®HTMLãã¹ã¯ãªã¼ã³ã·ã§ãããå ¬éããã¦ãã¾ãã ãã®ä»ã®ãããã·åã¹ãã£ã ãã®ä»ã«ããããã·åã®ã¹ãã£ãã¯è²ã ã¨ããã®ã§ãããRatProxyã®ããã¥ã¡ã³ããã¼ã¸ã«èªåã調ã¹ããã®ã¯å¤§ä½è¨è¿°ããã¦ãã¾ããããªã®ã§ãç°¡åã«è§¦ããã«ã¨ã©ãã¦ããã¾ãã 1. WebScarab 2. Paros 3. Burp 4. ProxMon 5. Pantera 6. Chorizo! ããããã®ããã°ã©ã ã«ã¤ãã¦ãæ¤ç´¢ããã°ä½¿ãæ¹ã¯ããã¨ç°¡åã«ãããã¨æãã¾ããã¾ããPro
ãã®ã¨ã³ããªã§ã¯ããããä¸ã§ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾çãã§Googleæ¤ç´¢ããçµæã®ä¸ä½15ã¨ã³ããªãæ¤è¨¼ããçµæãå ±åãã¾ãã SQLã¤ã³ã¸ã§ã¯ã·ã§ã³èå¼±æ§ã®å¯¾çã¯ãæ¢ã«ãå®å ¨ãªSQLã®å¼ã³åºãæ¹ãã«ãã¡ã¤ãã«ã¢ã³ãµã¼ï¼å¾è¿°ï¼ã示ãã¦ãã¾ãããã¾ã ãã®ææ¸ãç¥ããªã人ãå¤ãã ãããã¨ã¨ãããä¸ç´è åãã®ææ¸ã§ãããã¨ãããã¾ã ååã«å®è·µããã¦ã¯ããªãã¨æãã¾ãã ãã®ç¶æ³ã§ãã»ãã¥ãªãã£ã®ãã¨ãããç¥ããªã人ãSQLã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾çãããã¨ããå ´åã®è¡åãäºæ¸¬ãã¦ã¿ãã¨ãããªãã®å²åã®äººãGoogleçã§æ¤ç´¢ãã¦å¯¾å¦æ¹æ³ã調ã¹ãã¨æããã¾ããããã§ã以ä¸ã®URLã§SQLã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾çæ¹æ³ãæ¤ç´¢ããçµæã®ä¸ä½ã®ã¨ã³ããªãæ¤è¨¼ãã¦ã¿ããã¨æãç«ã¡ã¾ããã http://www.google.co.jp/search?q=SQLã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾ç ã©ãã¾ã§èª¿ã¹ããã§ããã以åNH
æ±äº¬ã©ã¼ã¡ã³ã·ã§ã¼2011 ããã¦ã¼ã¼ã¼ï¼ã¿ãªããããã«ã¡ã¯ãnakamura ã§ãã ä»æ¥ã¯ããã°ã©ãã ã£ãããµã¼ã管çè ã ã£ããï¼ãããã¯ãã®ä¸¡æ¹ã ã£ããï¼ããæ¹ã«ãå§ãããããµã¤ãã¨ãã¼ã«ãããã¤ããç´¹ä»ãã¾ããç´°ããèå¼±æ§ã®ãã§ãã¯çã©ããã¦ãæéãæãããã®ãå¤ãã§ãããä»åãç´¹ä»ãããã¼ã«ããã¾ã使ãã¨ãã®è¾ºãã ãã¶å¹çããã§ããã¨æãã¾ããï¼ WEB ã¢ããªã±ã¼ã·ã§ã³é¢é£ XSS Me XSS Me :: Add-ons for Firefox XSS ã®ãã¹ããããç¨åº¦èªååãã¦ããã Firefox ã®ã¢ããªã³ã§ããæ®å¿µãªãã Firefox3.0.* ç³»ã®é ã«éçºãæ¢ã¾ã£ã¦ãã¾ã£ã¦ããããã§ãããåã®ç°å¢ã§ã¯ install.rdf ã®æ¸ãæãã§åé¡ãªãåä½ãã¦ãã¾ããï¼Windows7 64bit + Firefox7.0.1ï¼ SQL Inject Me SQL I
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}