人éã¨ã¦ã§ãã®æªæ¥ï¼æ§ï¼ ãã¦ã§ãã®æ´å²ã¯äººé¡ã®æ´å²ã®ç¹°ãè¿ããã¨ãã観ç¹ããè²ã åå¼·ãã¦ãã¾ãã2014å¹´ã¾ã§ã®äººéã¨ã¦ã§ãã®æªæ¥ã®æ§ããã°ã§ãã
ãã®ã¨ã³ããªã§ã¯ãhashdos対çã¨ãã¦ã®mod_securityã®å°å ¥ã¨è¨å®ã®æ¹æ³ã説æãã¾ããUbuntuç°å¢ã§apt-getã«ããApacheãå°å ¥ãã¦ãããµã¤ãã«å¯¾ãã¦ãapt-getã«ããmod_securityãå°å ¥ããã¨ããã·ããªãªã§èª¬æãã¾ãã ã¯ããã«èæ¯ãªã©ã«ã¤ãã¦ã¯æ¨æ¥ã®ããã°ãåç §ãã¦ãã ããã ãã®ã¨ã³ããªã§ã¯ãhashdos対çãç®çã¨ãã¦ãUbuntuç°å¢ã«apt-getã«ããmod_securityãå°å ¥ããæ¹æ³ã説æãã¾ãããmod_securityã«å¯¾ããæ å ±ããã¾ããªãããããã£ãããã«ã®mod_securityãå°å ¥ããå¾ãhashdoså°ç¨ã®ã«ã¹ã¿ãã¤ãºãæ½ãã¨ããæµãã§èª¬æãã¾ãã Ubuntuã«apt-getã§mod_securityãå°å ¥ããModSecurity Handbookã«ããã¨ãDebianããã³Ubuntuã«å¯¾ãã¦ãmod_s
12æ10æ¥ã«PCçãã¹ã¿ã¼ããããµã¤ãã¼ã¨ã¼ã¸ã§ã³ãã®ããããã°ãµã¼ãã¹ãAmebaãªããã§ãããURLãã¯ãªãã¯ããã¨ããããã«ã¡ã¯ãããã«ã¡ã¯!!ãã¨ãããã¬ã¼ãºã¨ã¯ãªãã¯ããURLæååãèªåã§æ稿ããããã¯ã¾ã¡ã2ãããã®ã¢ã«ã¦ã³ããèªåã§ãã©ãã¼ãã¦ãã¾ãã¨ããç¾è±¡ãåºãã£ãã URLãã¯ãªãã¯ããã¦ã¼ã¶ã¼ãæå³ããªãæ©è½ãå®è¡ãããããWebã¢ããªã®èå¼±æ§ã®ä¸ç¨®ã»ã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªï¼CSRFï¼ãçªãããã®ãå社ã¯10æ¥å¤ãURLãã¯ãªãã¯ããªãããã¦ã¼ã¶ã¼ã«åç¥ã誤ã£ã¦ã¯ãªãã¯ããå ´åã¯æ稿ãåé¤ããã¯ã¾ã¡ã2ããã®ãã©ãã¼ãå¤ãããå¼ã³æããã11æ¥æã¾ã§ã«èå¼±æ§ãä¿®æ£ããã¨ããã mixiã§ã2005å¹´ãããURLãã¯ãªãã¯ããã¨ãã¼ãã¯ã¾ã¡ã¡ããï¼ãã¨ããæ¥è¨ãåæã«æ稿ãããã¨ãããCSRFãå©ç¨ããã¹ãã ãæµéãããã¨ããã£ããã³ãã¥ããã£ã¼ãµã¤ãæ§
Apache ã¢ã¸ã¥ã¼ã«ã§ãã ModSecurity*1 ã® Core Rule Setï¼CRSï¼*2ã¨ãªã£ã¦ããã 確èªãããã¼ã¸ã§ã³ modsecurity-crs v2.0.2ï¼2009å¹´10æ2æ¥ç¾å¨ï¼ CRS v2.0.2 ã® tar çããã¦ã³ãã¼ããå±éããã¨ã以ä¸ã®ãããªæ§æã¨ãªã£ã¦ããã解åãããã£ã¬ã¯ããªç´ä¸ã«ãããmodsecurity_crs_10_global_config.conf 㨠modsecurity_crs_10_config.conf ã® 2 ã¤ã®ãã¡ã¤ã«ããModSecurityå ¨ä½ã®è¨å®ãã¡ã¤ã«ã¨ãªãããã®æ¥è¨ã§ã¯ããã® 2 ã¤ã® conf ãã¡ã¤ã«ã ModSecurity Reference Manual*3 ãåºã«èªã¿è§£ãã¦ã¿ãã # tar xzvf modsecurity-crs_2.0.2.tar.gz # cd modsecuri
ä¾ãã°FacebookãTwitterãªã©ã®ã½ã¼ã·ã£ã«ãµã¼ãã¹ã¯ãå®éã«ã©ããããå½å ä¼æ¥ãããã§ä½¿ããã¦ããã®ã---ã大æãã¡ã¤ã¢ã¦ã©ã¼ã«ãã³ãã¼ã®ç±³ããã¢ã«ããããã¯ã¼ã¯ã¹ã¯ãåå¹´ã«ä¸åº¦ãä¸çä¸ã®ã¦ã¼ã¶ã¼ä¼æ¥ã対象ã«å¤§è¦æ¨¡ãªãã©ãã£ãã¯èª¿æ»ãå®æ½ããæ§ã ãªãã¼ã¿ãåéããã³åæãã¦ãããæ¥æ¥ãã調æ»æ å½è ã«ãæ¥æ¬ã®å½å ä¼æ¥ã«ããããã©ãã£ãã¯å¾åãªã©ã«ã¤ãã¦è©±ãèããã ã¾ãã¯èª¿æ»ã®æ¦è¦ã«ã¤ãã¦æãã¦ã»ããã 2008å¹´ããç´åå¹´ã«1åã®å²åã§ãä¸çä¸ã®ã¦ã¼ã¶ã¼ä¼æ¥ã対象ã«ãã©ãã£ãã¯èª¿æ»ãå®æ½ãã¦ãããææ°ã®ãã¼ã¿ã¯2011å¹´5æã«å®æ½ãã調æ»ã§å¾ããã®ã§ã調æ»å¯¾è±¡ã¨ãªã£ãä¼æ¥ã®æ°ã¯å ¨ä¸çã§åè¨1253社ããã®ãã¡æ¥æ¬ã®ä¼æ¥ã¯87ç¤¾å ¥ã£ã¦ããã調æ»å¯¾è±¡ä¼æ¥ã®æ°ã¯åãéãããã¨ã«å¤§ããå¢ãã¦ãããååï¼2010å¹´10æï¼ã¯723社ãåã åï¼2010å¹´3æï¼ã¯347社ã ã£ããå ·ä½çãªä¼
Apacheãã»ãã¥ã¢ã«ããã¢ã¸ã¥ã¼ã«ã§ãmod_securityãã¨ããã®ãããããã§ãããããWeb Application Firewall (WAF)ã¨ãããã®ã«åé¡ãããä»çµã¿ãªã®ã§ãããé常ã«æ©è½ãå¼·åãããããGETãPOSTãã¬ã¹ãã³ã¹ãå«ãINã¨OUTã®å ¨ãªã¯ã¨ã¹ãï¼HTTPSå«ãï¼ã«å¯¾ãã¦ãã£ã«ã¿ãªã³ã°å¯è½ãé常ã§ã¯è¨é²ãããªãPOSTã®ãã°ãè¨é²å¯è½ã ã§ããã®æ©è½ã使ãã°ãã©ãã¯ããã¯ã¹ãã ããµã¼ãå´ã§å§æ«ã§ããã®ã§ãPHPãªã©ãåãã¦å¤å®ããåã«å¦çã§ãããã©ãã¯ããã¯ã¹ãã ã«ããè² è·ã軽ããªãã¨ããããã è¨å®ã®è©³ç´°ãªã©ã¯ä»¥ä¸ã®éããmod_securityç¨ã®ãã©ãã¯ãªã¹ãããã¦ã³ãã¼ãã§ããã®ã§è¨å®ãç°¡åã§ãã å ¬å¼ãµã¤ãã¯ä»¥ä¸ã ModSecurity (mod_security) - Open Source Web Application Firewal
æè¿åãçºè¦ããä¿®æ£ãããTwitterã®èå¼±æ§ã3ã¤ç´¹ä»ãã¾ãã 1.æ§Twitterã®æååå¦çã«çµ¡ãã XSS å»å¹´ã®å¤ãããã«ãTwitter Webä¸ã§ € ã ÿ ã®æååç §ãå«ã¾ãããã¤ã¼ããXMLHttpRequestã§èªã¿è¾¼ãã éã«è¡¨ç¤ºãä¹±ããã¨ããåé¡ã«æ°ä»ã*1ããã®æã¯ããã¯èå¼±æ§ã«ã¯ç¹ãããªãã ããã¨ããå¤æãããã®ã ãã©ãä»å¹´ã®4æã«ãªã£ã¦æ¹ãã¦èª¿ã¹ãã¨ãã貫éãã¾ããã 表示ãä¹±ããã¨ããã®ã¯ã€ ã ÿ ã®æååç §ãå«ã¾ãããã¤ã¼ããããã¨ãä¸é¨ã®æåã\XXXXã®å½¢å¼ã«åãããããã¤ã¼ãå¨è¾ºã®ã"ããã\"ãã«ãªã£ãããããã®ã ã£ãã®ã§ãããä»åã¯ã"ããã\"ãã«ãªãç¹ãèå¼±æ§ãçºçããã¦ãã¾ããã ãã®æ¡ä»¶ã§XSSããããã¨æã£ããããã¤ã¼ããç´°å·¥ãã¦URLã@ã#ãªã©ãªã¼ããªã³ã¯ãä½æãããé¨åã«ãã¾ããã¨ã¤ãã³
ä»ã®ã¤ã³ã¿ã¼ãããã¯IPãã¼ã¸ã§ã³4ã§åä½ãã¦ãã¾ããããã®IPv4ã§åæ©å¨ãèå¥ããããã®IPv4ã¢ãã¬ã¹ãéã«äºå®ä¸æ¯æ¸ãã¾ãã(åè)ã é·å¹´ãæ¯æ¸ãããã¨è¨ããç¶ãã¦ãã¾ãããããããéã«ç¾å®ã®ç©ã¨ãªãã¾ããã ããã§ã¯ãIPv4ã¢ãã¬ã¹æ¯æ¸ã¨ã¯ä½ãã¨ãããã«ãã£ã¦ä½ãèµ·ããã®ããç´¹ä»ãã¾ãã IPv4ã¢ãã¬ã¹æ¯æ¸ã«é¢ãã¦ãã¢ããã°æ¾éã®åæ³¢ã¨å°ãã¸ã¸ã®ç§»è¡ããåæ²¹æ¯æ¸ã¨ä¼¼ããããªãã®ã§ãããããªèªèãå¤ãè¦ããã¾ãããå人çã«ã¯IPv4ã¢ãã¬ã¹æ¯æ¸å¾ã®IPv4ã¢ãã¬ã¹ã®ã¢ããã¸ã¼(é¡æ¯)ã¨ãã¦ã¯ç¸æ²ã®è¦ªæ¹æ ªã®æ¹ãè¿ãæ°ããã¦ãã¾ãã ã¾ããã¢ããã°æ¾éã®åæ³¢ã¨å°ãã¸ã¸ã®ç§»è¡ã§ãããã¢ããã°æ¾éã¯2011å¹´7æã«ä¸æã«åæ¢ãã¾ãã ããããIPv4ã¢ãã¬ã¹ã®å ´åã¯ãããæ¥çªç¶IPv4ã使ããªããªãããã§ã¯ãªããä»ã¾ã§ä½¿ã£ã¦ããIPv4ã¢ãã¬ã¹ã¯ãã®ã¾ã¾ä½¿ãç¶ããããã¨ããæå³ã§ã¢ã
åè«ãèªãã§ã³ã¡ã³ããã¤ãã¦è¿ãã¨ããä»äºããã¦ããã ç²ããã ã»ã¨ãã©åããã¨ãã©ã®å¦çã«ã¤ãã¦ãæ¸ãã¦ããããã§ããã ãåºå ¸ã®æ¸èªæ å ±ãæè¨ããªããã ãã®äºå¹´éããã¨ãããã¨ã«ã¼ãã§è¨ã£ã¦ããã®ã ããã»ã¨ãã©ã®å¦çã¯ãã®ã»ãã¨ãã®æå³ã¯ç解ãã¦ããªãã ããããã¶ãããºã«ããã¦ã¯ããã¾ãããã¨ããè¦åã®ããã«è´ãã¦ããã®ã ããã¨æãã ãã«ã³ãã³ã°ãããªãã¨ããææ¥ä¸ç§èªããããªãã¨ããæ室ã§ã«ãã麺ãé£ã¹ããªãã¨ãããããªæ³¨æã¨ååã®ãã®ã ã¨ããã¶ãæã£ã¦ããã ãã¦ããã¨ãããè¦ã¤ãã£ããå±ãããããã©ãè¦ã¤ãããªããã°ã©ãã£ã¦ãã¨ãªããã¨ãã¶ãæã£ã¦ããã ããã§ãã£ãã誰ãå°ãã¨ããã®ããã¨ãã¶ãæã£ã¦ããï¼ãã ãå³ã®ã©ã¼ã¡ã³èãæ室ã«æ¼ã£ã¦ããã¨ã次ã®ææ¥ã«æ室ã使ããã®ã¯è¦ãããï¼ã èªå·±å©çã®è¿½æ±ãåªå ããããã¨ã¯æªããã¨ã§ã¯ãªããã¨æãããã¦ããããã§ããã èªå·±
ç¾å¨ãè¤æ°å°ã®ãããã¯ã¼ã¯æ©å¨ãä¸æ¬ç®¡çããã®ã«ç¨ãããã¦ããã®ãSNMPã§ããããã®SNMPãæ¢åã®CLIã«ãã管çãç½®ãæããWebã¢ããªã±ã¼ã·ã§ã³ã«ããå¹ççãªç®¡çãå®ç¾ããã®ãããã®ã»ã©RFCåããããNETCONFãã®ä»çµã¿ã ãããã§ã¯NETCONFç»å ´ã®èæ¯ã¨ãããã¾ããªä»çµã¿ãç´¹ä»ããã CLIã¨SNMPãã¼ã¹ã®è¨å®ã管ç ãªãã¼ã¿ãããå人åãã®ã¹ã¤ããã³ã°ãããªã©ä½ã¬ã¤ã¤ã®è£½åãé¤ãã¨ãã»ã¨ãã©ã®ãããã¯ã¼ã¯æ©å¨ã¯åæè¨å®ãå¿ è¦ã«ãªããã¾ããéç¨ãå§ãã¦ããã¯è¨å®å¤æ´ãåä½ç¶æ ã®ç£è¦ããã©ãã«å¯¾å¿ã¨ãã£ãä½æ¥ãå¿ è¦ã«ãªã£ã¦ããã ããã ãããã£ãæ©å¨ã®æä½ã¯ãè¨å®ç¨ã®PCãã·ãªã¢ã«ã±ã¼ãã«ãTelnetçã§ã¤ãªããã³ãã³ãã©ã¤ã³ã¤ã³ã¿ã¼ãã§ã¤ã¹ï¼CLIï¼çµç±ã§è¡ãªãã®ãä¸è¬çã ãæè¿ã§ã¯è¨å®ã»ç®¡çãã¼ã«ã®GUIåãé²ãã§ããããæ´å²ã®ããæ©ç¨®ã»ã©CLIã®éè¦ã¯ãªããªãæ¸ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}