ã»ãã¥ãªãã£ã¯é£ããã§ãã ã§ãããããã°ã©ãã³ã°åå¦è ã®çããã¯å¿ è¦ä»¥ä¸ã«è縮ãããã©ãã©ãã¢ããªã±ã¼ã·ã§ã³ãä½ããå ¬éãããã¨ã«ãã£ã¬ã³ã¸ãã¦æ¬²ããã¨ç§ã¯æã£ã¦ãã¾ãã ä¸æ¹ãäºå®ã¨ãã¦ãèå¼±ãªã¢ããªã±ã¼ã·ã§ã³ãå ¬éããã¦ããï¼ãµã¼ãä¸ã§ã¢ã¯ã»ã¹å¯è½ãªç¶æ ã«ãªã£ã¦ããï¼ã ãã§ãå ¨ãç¡é¢ä¿ãªç¬¬ä¸è ã被害ã被ãå¯è½æ§ããããã¨ã¯ç¥ã£ã¦ããå¿ è¦ãããã¾ãã ããã¯WordPressã使ã£ãåãªãWebãµã¤ãã§ãã£ãã¨ãã¦ãåãã§ãã ã¾ããããªãã®ã¢ããªã±ã¼ã·ã§ã³ãç ´å£ããã¦å°ããªããã®ã§ãã£ããã å人æ å ±ãä¿æãã¦ããªããã®ã§ãã£ãã¨ãã¦ããã§ãã ã ãããç¥ããªãã£ããã§ã¯æ¸ã¾ãããªããã¨ãããã¾ãã ãã®è¨äºã§ã¯ãPHPã®ã½ã¼ã¹ãä¾ã«ã ç¹ã«ããã°ã©ãã³ã°åå¦è ãçã¿åºããããã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã«ã¤ãã¦ã å ·ä½çãªã³ã¼ããæããªãã解説ãã¾ãã ãªããæ¬è¨äºã®ãµã³ãã«ã³ã¼ãã¯ã
2020å¹´ã¯ãããã«9人ã®æ°åã¨ã³ã¸ãã¢ãå ¥ç¤¾ãã¾ãããä»å¹´ãæ°åã¨ã³ã¸ãã¢ã対象ã«ã3ã¶æã«åã¶ã¨ã³ã¸ãã¢ç ä¿®ãéå¬ãã¾ããã æ¬ã¨ã³ããªã§ã¯ãç ä¿®ã®å ¨ä½åã®ãç´¹ä»ããç ä¿®ã§å©ç¨ããåè³æãå ¬éãã¾ããã¾ããé åå¥ã«ç ä¿®æ å½è ããæ¦è¦ã®ç´¹ä»ããã¾ãã æ°åç ä¿®ã®è³æä½æãæ å½ãã¦ããæ¹ããæ°åã»ä¸éåãããæ°ããé åã«ãã£ã¬ã³ã¸ãããã¨ã³ã¸ãã¢ã®æ¹ã¯ãã²ã覧ãã ããï¼ GMO ãããã®ç ä¿® GMO ã¤ã³ã¿ã¼ãããã°ã«ã¼ãã§ã¯ãæ¯å¹´ GMO Technology Bootcamp(以ä¸ãGTB) ã¨é¡ãã¦ãã°ã«ã¼ãå ¨ä½ã®ã¨ã³ã¸ãã¢ã¨ã¯ãªã¨ã¤ã¿ã¼(ãã¶ã¤ã)ãéã¾ã£ã¦ãããã¯ããä½ã£ã¦ããä¸ã§å¿ è¦ã¨ãªããã¼ã¹ã©ã¤ã³ã®æè¡ãå¦ã¶ç ä¿®ãè¡ã£ã¦ãã¾ãã GMO ãããã®æ°åå ¥ç¤¾ã®ã¡ã³ãã¼ã¯ä»å¹´ããæ¬æ ¼çã« GTB ã«åå ãã¾ãããæ°åã¡ã³ãã¼ãåå ãããªããã¨è¬ç¾©ã®å 容ã®ä½æãè¬å¸«ã¨ãã¦ã®åå ã«ã¤
å¼ç¤¾ã¯ã©ã¹ã¡ã½ããæ ªå¼ä¼ç¤¾ä¸»å¬ã®ã¤ãã³ããDevelopers.IO 2019 TOKYOãã§ã®ç»å£è³æã§ãã ã»ãã¥ãªãã£å¯¾çã¡ã¬çãããã¯ã¹ ããã°: https://dev.classmethod.jp/cloud/aws/developers-io-2019-tokyo-all-securiâ¦
ã¯ããã« ä¸å±±ï¼é ï¼ã§ã 4å¹´ã»ã©åã«ãã®è¨äºã®ã¿ã¤ãã«ã¨åããã¼ãã§è³æãä½æãããã¨ãããã®ã§ãããå¤ãå 容ããã£ããæ°ãããµã¼ãã¹ã®ãã¨ãå«ã¾ãã¦ããªãã£ããããã®ã§æ¹ãã¦ã¾ã¨ãã¦ã¿ã¾ããã令åã ãï¼ ãã®æã®è³æã¯ãã¡ãã§ãï¼ã¯ã©ã¹ã¡ã½ããã«ã¸ã§ã¤ã³ããããã2å¹´åã§ãï¼ã AWSã¢ã«ã¦ã³ããä½ã£ããæåã«ããã¹ãã㨠ãµã¤ã³ã¢ãã ï¼æ¥åå©ç¨ã®å ´åï¼éå人ã¡ã¼ã«ã¢ãã¬ã¹ã§ãµã¤ã³ã¢ãã ãµãã¼ããã©ã³ã®ç¢ºèª ID管ç / 権é管ç CloudTrailã®æå¹å ã«ã¼ãã¢ã«ã¦ã³ãã®MFAè¨å® IAM User / IAM Groupã®ä½æ ãã¹ã¯ã¼ãããªã·ã¼ã®è¨å® GuardDutyã®æå¹å Security Hubã®æå¹å è«æ± IAM Userã«ããè«æ±æ å ±ã¸ã®ã¢ã¯ã»ã¹è¨±å¯ æ¯æé貨ã®å¤æ´ Budgetã®è¨å® Cost Explorerã®æå¹å Cost Usage Report
ã¤ãã¼æ ªå¼ä¼ç¤¾ã¯ã2023å¹´10æ1æ¥ã«LINEã¤ãã¼æ ªå¼ä¼ç¤¾ã«ãªãã¾ãããLINEã¤ãã¼æ ªå¼ä¼ç¤¾ã®æ°ããããã°ã¯ãã¡ãã§ããLINEã¤ãã¼ Tech Blog ããã«ã¡ã¯ã IDã½ãªã¥ã¼ã·ã§ã³æ¬é¨ã®é½çã§ãã æ°å2å¹´ç®ã§æ®æ®µã¯Yahoo! IDé£æºã®ãµã¼ãã¼ãµã¤ããiOSã®SDKã®éçºãªã©ãæ å½ãã¦ãã¾ãã ä»åã¯æè¿ã¦ã¼ã¶ã¼ãããã¤ã¹ã®èªè¨¼ã§ç¨ããããâJSON Web Tokenï¼JWTï¼âã«ã¤ãã¦ã®è§£èª¬ã¨ãYahoo! JAPANã¨ä»ç¤¾ã®æ´»ç¨äºä¾ãç´¹ä»ãããã¨æãã¾ãã JWTã¨ã¯ï¼ JWTã¨ã¯JSON Web Tokenã®ç¥ç§°ã§ãããå±æ§æ å ±ï¼Claimï¼ãJSONãã¼ã¿æ§é ã§è¡¨ç¾ãããã¼ã¯ã³ã®ä»æ§ã§ãã ä»æ§ã¯RFC7519ï¼å¤é¨ãµã¤ãï¼ã§å®ãããã¦ãã¾ãã ç¹å¾´ã¨ãã¦ãç½²åãæå·åãã§ããURL-safeã§ãããã¨ãªã©ãæãããã¾ããçºé³ã¯"ã¸ã§ãã"ã§ãã JWTã¨é¢é£ã
JWTã使ããã¨ã¯é£ããï¼ ããã«ã¡ã¯ããã¨ãã ã(@j5ik2o)ã§ããæè¿ãJWTã«é¢ãã以ä¸ã®ããã°ã話é¡ã§ã*1ã ã©ããã¦ãªã¹ã¯ã¢ã»ã¹ã¡ã³ãããã« JWT ãã»ãã·ã§ã³ã«ä½¿ã£ã¡ããããï¼ - co3k.org ãã®ããã°ã§è¨åããã¦ããã®ã¯ãJWTãã»ãã·ã§ã³ã®ä¿åå ã«é¸ã¶ãã¨ã§ãä½ãåé¡ãªã®ï¼ãã«æ¸ããã¦ãããªã¹ã¯ãããããã¨ãã話*2ã確ãã«ããã¤ãæ¤è¨ãããã¨ãããã¾ããã auth0.hatenablog.com auth0ã®ä¸ã®äººï¼ããããããªããã©ãåè«çãªããã°ã¨ã³ããªãå ¬éããã¦ãã¾ãããã®è¨äºã§ã¯ãææã®åé¡ãèµ·ãããªãããã«è¨è¨ããã®ã¯ãããåã§ã¯ï¼ã¨ããæè¦ã¿ããã§ããã¾ãããã£ã¨ãã§ã¯ãªãã§ããããã ç§ãæè¡ãã®ãã®ã¨ãããããè¦ä»¶ã«åããã¦æè¡ãçµã¿åãããè¨è¨ã®åé¡ã ã¨æã£ã¦ãã¾ããå ãã¦ãJWTãå©ç¨ãããã¨ã¯ãããªã«é£ãããã¨ãã¨ããçåããã£ã
SSHã¨ã¯ SSHã¨ã¯ãã»ãã¥ã¢ãªéä¿¡ãè¡ãããã®ãããã³ã«ã§ãã ãã¨ãã°ãHTTPãHTTPãéãã¦ãã©ã¦ã¶ããWebãµã¤ãã«ã¢ã¯ã»ã¹ãã ã³ã³ãã³ããé²è¦§ãããWebã¢ããªãå©ç¨ããããã¾ãã ãã®ãHTTPãã¨ããã®ããããã³ã«ã®ä¸ç¨®ã§ãã HTTPãSSHãOSIåç §ã¢ãã«ã¨å¼ã°ãã層ã®æä¸ä½ãã¢ããªã±ã¼ã·ã§ã³ã¬ã¤ã¤ã¼ã«ä½ç½®ãã¦ãã¾ãã ãªããããèããOpenSSHãã¨ã¯ããã®SSHã®ãããã³ã«ãå®ç¾ããããã® æåãªã½ããã¦ã§ã¢ï¼ããã°ã©ã ï¼ã®ã²ã¨ã¤ã§ãã FTPã®ãããã³ã«ã§è¨ãFileZillaã¨ãããããã£ãã¤ã¡ã¼ã¸ã§ãã ãã®SSHã使ãã¨ããªã¢ã¼ããµã¼ãã«å®å ¨ã«ãã°ã¤ã³ã§ãããã ãã¡ã¤ã«ãã»ãã¥ã¢ã«éåä¿¡ãããã¨ãã§ããããã¾ãã SSHã¯ãSecure Shellãã®è¨³ã§ããªã¢ã¼ãã·ã§ã«ã«ç¹åãã¦ãã¾ãã å ¬ééµèªè¨¼ã¨ããä»çµã¿ãç¨ãã¦ãã»ãã¥ã¢ãªéä¿¡ãå®ç¾ãã¦
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}