Webã¢ããªã±ã¼ã·ã§ã³ã®éçºã»å±éãè¡ã£ã¦ãã人ã ã«ã¨ã£ã¦ãã»ãã¥ãªãã£ç¢ºä¿ã¯å¤§ããªé¢å¿äºã®1ã¤ã ã¨ããã¾ãããã®ããã®ãã¹ããã©ã¯ãã£ã¹ããã¬ã¼ã ã¯ã¼ã¯ãã¬ã¤ãã©ã¤ã³ãæä¾ãã¦ããã®ãOWASPï¼Open Web Application Security Projectï¼ã§ããOWASPã®Wikiãµã¤ãï¼OWASP.orgï¼ã«ã¯ãWebã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£ç¢ºä¿ã®ããã®æ§ã ãªæ å ±ãããã¾ããããããã®ä¸ã§ãå³å¹æ§ã®é«ãã®ãã便å©ãªHTTPãããã®ãªã¹ãï¼List of useful HTTP headersï¼ãã ã¨ãããã§ãããã ãã®ãã¼ã¸ã«ã¯ãã¢ããªã±ã¼ã·ã§ã³ã®HTTPã¬ã¹ãã³ã¹ã«è¿½å ãããã¨ã§ãäºå®ä¸ç¡æã§ã»ãã¥ãªãã£ãå¼·åã§ããHTTPãããã7種é¡æ²è¼ããã¦ãã¾ãã ãããã®ä¸ã§ã¾ãæ´»ç¨ãããã®ãã以ä¸ã®2ã¤ã®HTTPãããã§ãã X-XSS-Protection æè¿
æ¦è¦ IAMã°ã«ã¼ãã®ããªã·ã¼ãã¡ããã¨å½¹å²ã«åãã¦ç®¡çãããã¨ãã話ã§ãã æ¹é admin, developer, operatorã®ï¼ã¤ã®å½¹å²ã§åããåã°ã«ã¼ãã«é©åãªæ¨©éãä¸ããããã«ãã¾ãã ãã ã ãã¹ã¯ã¼ãå¤æ´ MFAã®è¨å® ã¯åIAMã¦ã¼ã¶ãã§ããããã«ãã¾ãã ä»ä¸ãã権é ã°ã«ã¼ã 権é admin AdministratorAccess developer PowerUserAccess IAMUserChangePassword AllowUsersToUseMFA operator ReadOnlyAccess IAMUserChangePassword AllowUsersToUseMFA ãããã説æãã㨠権é 説æ AdministratorAccess AWSã®å ¨æ¨©é PowerUserAccess AdministratorAccessããIAMå¨ãã®
ãã¦ã¼ã¶ã¼ç®ç·ãã®ã·ã¹ãã ãç®æã㦠RDBãå¾æ¥ã®é層åDBã«æ¯ã¹ã¦åªãã¦ããç¹ã¯ããã¤ãæãããã¨ãã§ãã¾ãããã·ã§ã¢ã伸ã°ãããã§æã大ããªå½±é¿ã¯ãã¦ã¼ã¶ã¼ã使ãããããã¼ã¿æ§é ã¨ã¤ã³ã¿ãã§ã¼ã¹ã«ãã ãã£ããã¨ã§ããããªãã¡ãããã¼ãã«ãã¨ãSQLãã®çºæã§ãã RDBã§ã¯ããã¹ã¦ã®ãã¼ã¿ãããã¼ãã«ãã¨ãããã ä¸ã¤ã®ãã¼ã¿å½¢å¼ã«ãã£ã¦è¡¨ç¾ãã¾ãããã¼ãã«ã¯ãè¦ãç®ããäºæ¬¡å 表ãã«ä¼¼ã¦ãããã*3ãMicrosoft ExcelãGoogle ããã¥ã¡ã³ããªã©ã®ã¹ãã¬ããã·ã¼ãã使ãæ £ãã人ãè¦ãã¨ããã¼ã¿ãæ ¼ç´ããæ¹æ³ãç´è¦³çã«ã¤ã¡ã¼ã¸ããããã¨ããå©ç¹ãããã¾ããå®éãããããäºæ¬¡å 表ã«ãããã¼ã¿ç®¡çã¯ãExcelãªã©ã®ã½ããã¦ã§ã¢ãç»å ´ããåããä¸è¬çãªæ¹æ³ã ã£ããããRDBãç»å ´ããå½æã®äººã ã«ã¨ã£ã¦ãåãå ¥ãããããã®ã§ããã ãã¼ãã«ãç»æçã ã£ãç¹ã¯ãããä¸ã¤ããã¾ãã
ã¡ã³ããã³ã¹
ãç¥ãã
é害
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}