ã¿ãªãããããã«ã¡ã¯ã
å¶æ¥ã®ä¸å¶(@mnakajima18)ã§ãã
å
é±10æ5æ¥(é)ã«éå¬ããããNEC社主å¬ã®ãå½å
å¯ä¸ã®AWS対å¿WAFãInfoCage SiteShellãã³ãºãªã³ã»ããã¼ããã«åå ãã¦ãã¾ããã
ãInfoCage SiteShellãã¯NEC社ã®ã½ããã¦ã§ã¢åWeb Application Firewall(WAF)製åã§ãã
WAFã¨ã¯Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ãçªããæ»æããããã¯ãããã¡ã¤ã¢ã¼ã¦ã©ã¼ã«ã®ãã¨ãããã¾ãã
ã¢ãã©ã¤ã¢ã³ã¹è£½åãSaaSåã®è£½åãå¤ãä¸ããInfoCage SiteShellãã¯å¯¾è±¡ã®ãµã¼ãã¼ã«ã½ããã¦ã§ã¢ãã¤ã³ã¹ãã¼ã«ãã¦å©ç¨ãã¾ãã
WAFã¨ã¯Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ãçªããæ»æããããã¯ãããã¡ã¤ã¢ã¼ã¦ã©ã¼ã«ã®ãã¨ãããã¾ãã
ã¢ãã©ã¤ã¢ã³ã¹è£½åãSaaSåã®è£½åãå¤ãä¸ããInfoCage SiteShellãã¯å¯¾è±¡ã®ãµã¼ãã¼ã«ã½ããã¦ã§ã¢ãã¤ã³ã¹ãã¼ã«ãã¦å©ç¨ãã¾ãã
ããã¦ä»å¹´ã®5æããAWS対å¿ãçºè¡¨ããã¾ããã®ã§ããããã¯ãã£ããç解ãã¦ãããªãã¨ãã¨ãããã¨ã§ãã³ãºãªã³ã»ããã¼ã«åå ãããã¨ã«ãã¾ããã
製åç´¹ä»
ãInfoCage SiteShellãã¯ã½ããã¦ã§ã¢åWAF製åã§ãããµã¼ãã¼ã¤ã³ã¹ãã¼ã«åã¨ãããã¨ã¯ä¸è¿°ããéãã§ãã
ã»ãã«ãç¹å¾´çãªã®ã¯ãã©ãã¯ãªã¹ãã®æ´æ°ã«ã¤ãã¦ã§ãã
ã¤ã³ããä¸å½ãæ¥æ¬ã®æ ç¹ã«ã¦ããã«ã¼ãµã¤ããæ§ã
ãªæ
å ±æºããææ°æ
å ±ãéããã©ãã¯ãªã¹ããä½æãã¦ãã¾ãã ãã®ãã©ãã¯ãªã¹ãã¯å©ç¨ãã¦ãã製åã«èªåçã«æ´æ°ä½æ¥ãè¡ããã¾ãã
èªåæ´æ°ã®åæè¨å®ãã»ããã¼å ã§è¡ãã¾ããããèªåæ´æ°ã®ã·ã§ã«ã¹ã¯ãªãããåããããã¤ã質åã«çããã ãã§å®äºãã¾ãã
æ´æ°ã¯æåã«Webãµã¤ãã«ã¢ã¯ã»ã¹ããã£ãæç¹ã§é©ç¨ãããããããµã¼ãã¼ã®åèµ·åã¯ä¸åå¿ è¦ãªãã¨ããæ軽ãã
ãµã¼ãã¹ãæ¢ãããã¨ãªãå®å¿ãã¦éç¨ã§ããã®ã¯ããµã¼ãã¹éå¶å´ã«ã¨ã£ã¦ã¯é常ã«å¤§ããã¨æãã¾ãã
èªåæ´æ°ã®åæè¨å®ãã»ããã¼å ã§è¡ãã¾ããããèªåæ´æ°ã®ã·ã§ã«ã¹ã¯ãªãããåããããã¤ã質åã«çããã ãã§å®äºãã¾ãã
æ´æ°ã¯æåã«Webãµã¤ãã«ã¢ã¯ã»ã¹ããã£ãæç¹ã§é©ç¨ãããããããµã¼ãã¼ã®åèµ·åã¯ä¸åå¿ è¦ãªãã¨ããæ軽ãã
ãµã¼ãã¹ãæ¢ãããã¨ãªãå®å¿ãã¦éç¨ã§ããã®ã¯ããµã¼ãã¹éå¶å´ã«ã¨ã£ã¦ã¯é常ã«å¤§ããã¨æãã¾ãã
ããã«è©³ããæ
å ±ã¯ãã¡ãã®è£½åãµã¤ããã覧ãã ããã
http://www.nec.co.jp/soft/siteshell/
http://www.nec.co.jp/soft/siteshell/
å°å ¥ç·¨
å®éã«ã¤ã³ã¹ãã¼ã«ãä½é¨ããã¦ããã ãã¾ããããæ¬å½ã«ç°¡åã§ãï¼
ä»åã¯InfoCage SiteShellã¢ã¸ã¥ã¼ã«ãå
¥ã£ãAMIãç¨æãã¦ããã ãã¦ããã®ã§ããã®AMIããWebãµã¼ãã¼ç¨ã¨ç®¡çãµã¼ãã¼ç¨ã®ã¤ã³ã¹ã¿ã³ã¹ãç«ã¡ä¸ãã¾ããã
ã¾ããWebãµã¼ãã¼ã«InfoCage SiteShellæ¬ä½ãã¤ã³ã¹ãã¼ã«ããã«ã¯ããã¤ãã®ã³ãã³ããå©ãã¦å®äºãã¾ãã
以ä¸ãç°¡åãªæµãã§ãã
1.ãrpmãã¡ã¤ã«ã®å±é
2.ãã»ããã¢ããã·ã§ã«ã¹ã¯ãªããã®å®è¡
3.ãJavaã®ãã¹ãå ¥å
4.ãã©ã¤ã»ã³ã¹IDãå ¥å
5.ãApacheã®ãã¼ã¸ã§ã³é¸æ
6.ãApacheã®è¨å®ãã¡ã¤ã«ã®ãã¹ãå ¥å
7.ãApacheåèµ·å
2.ãã»ããã¢ããã·ã§ã«ã¹ã¯ãªããã®å®è¡
3.ãJavaã®ãã¹ãå ¥å
4.ãã©ã¤ã»ã³ã¹IDãå ¥å
5.ãApacheã®ãã¼ã¸ã§ã³é¸æ
6.ãApacheã®è¨å®ãã¡ã¤ã«ã®ãã¹ãå ¥å
7.ãApacheåèµ·å
ããããã¨ãã®ãããªã·ã§ããã³ã°ãµã¤ããä½æãããã¤ã³ã¹ãã¼ã«åã¯SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã«ãã£ã¦
å人æ
å ±ãæ¼ãã¦ãã¾ã£ã¦ãããã®ã
ã¤ã³ã¹ãã¼ã«ããå¾ã§ã¯ããããã£ãã¨ã©ã¼ãã¼ã¸ã¸é£ã°ããã¾ãã
管çã³ã³ã½ã¼ã«ã®ã¤ã³ã¹ãã¼ã«ãã»ã¼åæ§ã§ãã
æä¾ããã¦ããzipãã¡ã¤ã«ã解åããã»ããã¢ããã·ã§ã«ã¹ã¯ãªãããå®è¡ããã¨æ¬ä½ã¤ã³ã¹ãã¼ã«ã¨åããããªè³ªåã«åçãããã¨ã§ã¤ã³ã¹ãã¼ã«å®äºã§ãã
ãã©ã¦ã¶ããããã«ã¢ã¯ã»ã¹ã§ããããã«ãªãã¾ãã
æä¾ããã¦ããzipãã¡ã¤ã«ã解åããã»ããã¢ããã·ã§ã«ã¹ã¯ãªãããå®è¡ããã¨æ¬ä½ã¤ã³ã¹ãã¼ã«ã¨åããããªè³ªåã«åçãããã¨ã§ã¤ã³ã¹ãã¼ã«å®äºã§ãã
ãã©ã¦ã¶ããããã«ã¢ã¯ã»ã¹ã§ããããã«ãªãã¾ãã
å¶æ¥ã®ç§ã§ã30åç¨åº¦ã§ã¤ã³ã¹ãã¼ã«ãã§ããå°å
¥ã®æéã¯å
¨ãæãããã¾ããã§ããã
æ§ã ãªæ»æ対çæ¹æ³
ãã¡ãã«æ²è¼ãããéããInfoCage SiteShellã§ã¯10ã®æ»æããé²å¾¡ããæ©è½ãåãã£ã¦ãã¾ãã
ãã®ä¸ã§ã以ä¸ã®3ã¤ã®æ»æ対çæ¹æ³ãã»ããã¼å
ã§å®è·µãã¾ããã
1.ããã¹ãã©ãã¼ãµã«æ»æ対ç
2.ããããã¡ãªã¼ãã¼ããã¼å¯¾ç
3.ãå¼·å¶çãã©ã¦ãºå¯¾ç
2.ããããã¡ãªã¼ãã¼ããã¼å¯¾ç
3.ãå¼·å¶çãã©ã¦ãºå¯¾ç
1.ããã¹ãã©ãã¼ãµã«æ»æ対ç
ãã¹ãã©ãã¼ãµã«æ»æã¨ã¯Webãã¼ã¸ãæå®ãããã¹ã«ç´°å·¥ãè¡ããã¨ã«ãã£ã¦ãéçºè
ãã¦ã¼ã¶ã¼ã«å
¬éãã¦ããªããã£ã¬ã¯ããªããã¡ã¤ã«ãé²è¦§ã§ããèå¼±æ§ãã¾ãã¯ãããå©ç¨ããæ»æã®ãã¨ãããã¾ãã(ã»ããã¼è³æå¼ç¨)
ä»åã¯ã/etc/passwdãã®ä¸æ£åç
§ãå®æ½ãã¾ããã
ãã®ããã«ãã¹ãå©ãããã¨ãã¦ã¼ã¶ã¼ã«ã¯è¦ãã¦ã¯ãããªãã/etc/passwdããã¡ã¤ã«ã表示ããã¦ãã¾ãã¾ãã
ãã¹ãã©ãã¼ãµã«æ»æã®å ´åã¯ããã©ã«ãè¨å®ã®ã¾ã¾ã§åé¡ãªãã®ã§ãã¤ã³ã¹ãã¼ã«ããã°ããã«ãããã¯ããã¾ãã
InfoCage SiteShellã®ãã©ãã¯ãªã¹ãã«ããã../ãã¯æ»æã¨å¤æãã¦ããããã§ãã
2.ããããã¡ãªã¼ãã¼ããã¼å¯¾ç
ãããã¡ãªã¼ãã¼ããã¼ã¨ã¯ããã°ã©ã ãã¡ã¢ãªä¸ã«ç¢ºä¿ããé åãè¶
ãã大ããã®ãã¼ã¿ãéãè¾¼ããã¨ã§ãã·ã¹ãã ã誤åä½ãå¼ãèµ·ãããããæªæã®ããããã°ã©ã ãå®è¡ããããããèå¼±æ§ãã¾ãã¯ãããå©ç¨ããæ»æã®ãã¨ãããã¾ããããã°ã©ã ã®å¼·å¶çµäºãä»»æã®ã³ã¼ããå®è¡ãããã¨ãã£ãåé¡ãçºçãã¾ãã(ã»ããã¼è³æå¼ç¨)
ä»åã®ãµã³ãã«æ»æã§ã¯å½±é¿ããªããã®ã§ããããã¢ã¯ã»ã¹ãã¦ããå¤ãInfoCage SiteShellããããã¡ãªã¼ãã¼ããã¼æ»æã¨å¤æããããã¯ãã¦ãããã¨ã確èªãã¾ããã
ãµã³ãã«æ»æã®å
容ã¯ãé常ã®ãã¹ã®å¾ãã«aã200æåç¨åº¦å
¥åããã¨ãã£ããã®ã§ãã
ç¡å¹ã®å ´åã¯ç¹ã«ãã¼ã¸ã«å¤ããã¯ããã¾ããã
æå¹ã«ããããã«ã¯2ã¤ã®ãã©ã¡ã¼ã¿ãå¤æ´ãããã¨ã§å¯¾å¿ã§ãã¾ãã
管çç»é¢ã®ã¡ãã¥ã¼ç»é¢ããSiteShellæä½å®ç¾©ãã¯ãªãã¯ãã¾ãã
ãããã¡ãªã¼ãã¼ããã¼å¯¾çãæå¹ã«ãã¾ãã
ONã«å¤æ´ãã¾ãã
ç¶ãã¦ãURLã®é·ããæå®ãã¾ãã
ä»åã¯100ã«è¨å®å¤æ´ãã¾ãã
ããã§å®äºã§ãã
ãããã¡ãªã¼ãã¼ããã¼ã®å ´åãã¢ããªã±ã¼ã·ã§ã³ã«ãã£ã¦URLã®é·ãã¯å¤ããã¾ãã®ã§ãã®ããã«æåæ°ãã«ã¹ã¿ãã¤ãºãã§ããããã«ãªã£ã¦ãã¾ãã
3.ãå¼·å¶çãã©ã¦ãºå¯¾ç
å¼·å¶çãã©ã¦ãºã¨ã¯ãå
¬éããã¦ããURLããæ§ã
ãªURLãæ¨æ¸¬ãã¦åç
§ã試ã¿ããããã¨ãããã¾ãã
æ¬æ¥è¡¨ç¤ºãã¦ã¯ãããªãããã¯ã¢ãããã¡ã¤ã«ããã¹ããã¡ã¤ã«ãåç §ããã¦ãã¾ããæ»æã®ãã³ããªã©ãä¸ãã¦ãã¾ãæããããã¾ãã(ã»ããã¼è³æå¼ç¨)
æ¬æ¥è¡¨ç¤ºãã¦ã¯ãããªãããã¯ã¢ãããã¡ã¤ã«ããã¹ããã¡ã¤ã«ãåç §ããã¦ãã¾ããæ»æã®ãã³ããªã©ãä¸ãã¦ãã¾ãæããããã¾ãã(ã»ããã¼è³æå¼ç¨)
ãµã³ãã«æ»æã®å
容ã¯ãFQDNã®å¾ãã«/test/search.phpãå
¥åãæ¬æ¥ã¯ã¦ã¼ã¶ã¼ã«è¡¨ç¤ºãã¦ã¯ãããªããã¼ã¸ã«ã¢ã¯ã»ã¹ããã¨ãããã®ã§ãã
ãã®æ»æãé²ãããã«ã¯ãå
¬éããããã£ã¬ã¯ããªé
ä¸ãæå®ããè¨å®ãè¡ãã¾ãã
ã¾ãã¯ãå¼·å¶çãã©ã¦ãºå¯¾çã®è¨å®ãæå¹ã«ãã¾ãã
å¤ãONã«ãã¾ãã
ç¶ãã¦ãå
¬éãããURLã®ãã¹ãæå®ãã¾ããããã§ã¯ã¦ã¼ã¶ã¼ã«ã¼ã«å®ç¾©ãã¯ãªãã¯ãã¾ãã
ã¬ã·ã追å ãã¯ãªãã¯ãã¾ãã
Recipe Nameã¨Attack Typeã¯ä»»æã®ååãæå®ãã¾ããã«ã¼ã«ã»ããã®è¿½å ãã¯ãªãã¯ãã¾ãã
ä»åã¯FQDN/demoAP/以å¤ã®ã¢ã¯ã»ã¹ã¯ãããã¯ãã¾ãã
ããã§å®äºã§ãã
å¼·å¶çãã©ã¦ãºã®å ´åããããã¡ãªã¼ãã¼ããã¼ã¨åæ§ã«ã¢ããªã±ã¼ã·ã§ã³ã«ãã£ã¦å¤ãç°ãªãããã«ã¹ã¿ãã¤ãºãã§ããããã«ãªã£ã¦ãã¾ãã
ãã®ä»ã®è¨å®
ã¢ããªã±ã¼ã·ã§ã³ç¹æã®èå¼±æ§ãé²ãããã«ã¦ã¼ã¶ã«ã¼ã«å®ç¾©ã¨ããè¨å®ãã§ãã¾ãã
ä¾ãã°ãæååãå°ãªããã®ã¯éå°æ¤ç¥ãå¤çºããã¦ãã¾ããã¨ãããããInfoCage SiteShellã®ãã©ãã¯ãªã¹ãã®ããã©ã«ãã§ã¯ç»é²ããã¦ãã¾ããã
ããããç»é²ããã¦ããªãæååãæ»æã¨ãªã£ã¦ãã¾ãã¢ããªã±ã¼ã·ã§ã³ã®å ´åãåå¥ã«è¨å®ãããã¨ãå¯è½ã§ãã
ä¾ãã°ãæååãå°ãªããã®ã¯éå°æ¤ç¥ãå¤çºããã¦ãã¾ããã¨ãããããInfoCage SiteShellã®ãã©ãã¯ãªã¹ãã®ããã©ã«ãã§ã¯ç»é²ããã¦ãã¾ããã
ããããç»é²ããã¦ããªãæååãæ»æã¨ãªã£ã¦ãã¾ãã¢ããªã±ã¼ã·ã§ã³ã®å ´åãåå¥ã«è¨å®ãããã¨ãå¯è½ã§ãã
å対ã«ãã©ãã¯ãªã¹ãã«è¼ã£ã¦ããæååãã¢ããªã±ã¼ã·ã§ã³ã§ã¯æ£å¸¸ç³»ã®åä½ã®ãããããã¯ããªãããã«ãããããã§ãã¯å¯¾è±¡å¤å®ç¾©ãã¨ããè¨å®ãå¯è½ã¨ãªã£ã¦ãã¾ãã
ãããããã©ãã¯ãªã¹ãã¨ãã¦ç»é²ããã¦ããæ»æãéããã¨ã«ãªãã¨ã»ãã¥ãªãã£ãã¼ã«ãã§ãã¦ãã¾ãã®ã§ããªãã¹ãã¢ããªã±ã¼ã·ã§ã³å´ã®æ¹ä¿®ãè¡ã£ã¦ããã ããã¨ãæ¨å¥¨ã¨ããã¦ãã¾ããã
ãããããã©ãã¯ãªã¹ãã¨ãã¦ç»é²ããã¦ããæ»æãéããã¨ã«ãªãã¨ã»ãã¥ãªãã£ãã¼ã«ãã§ãã¦ãã¾ãã®ã§ããªãã¹ãã¢ããªã±ã¼ã·ã§ã³å´ã®æ¹ä¿®ãè¡ã£ã¦ããã ããã¨ãæ¨å¥¨ã¨ããã¦ãã¾ããã
ã¾ãããããã¯ãããå ´åã®ã¨ã©ã¼ãã¼ã¸ã¯ç®¡çç»é¢ããHTMLå½¢å¼ã§ã«ã¹ã¿ãã¤ãºãããã¨ãå¯è½ã§ãã
æ»æè ã§ã¯ãªãé常ã®ã¦ã¼ã¶ã¼ã®æ¹ã誤ã£ã¦å ¥åãã¦ãã¾ã£ãå ´åãéå°æ¤ç¥ãã¦ãã¾ã£ãå ´åãè¦è¾¼ãã§ãåãåããå çãè¨è¼ããããã«ããã»ããããã¨ã®ãã¨ã§ããã
æ»æè ã§ã¯ãªãé常ã®ã¦ã¼ã¶ã¼ã®æ¹ã誤ã£ã¦å ¥åãã¦ãã¾ã£ãå ´åãéå°æ¤ç¥ãã¦ãã¾ã£ãå ´åãè¦è¾¼ãã§ãåãåããå çãè¨è¼ããããã«ããã»ããããã¨ã®ãã¨ã§ããã
æå¾ã«ãã°ã®éè¨çµæã¯ãã®ããã«ãã¸ã¥ã¢ã«çã«ç¢ºèªã§ãã¾ãã
ã¬ãã¼ãã¨ãã¦æåºãããããã¨æãã¾ãã
ã¾ã¨ã
æå¾ã®è³ªçå¿çã®éã«ã¯ãããAWSã«é©ãããµã¼ãã¹ã«ããããã®æè¦äº¤æã¨ããæµãã§ããã
AWSã使ãè¾¼ãã§ããç§éã®ãããªã½ãªã¥ã¼ã·ã§ã³ãããã¤ãããã£ã¨ããããã»ãã使ãããããéç¨ããããã¨ãã£ãæè¦ããä¼ããããã¨ã§ããã«ãã¼ã¸ã§ã³ã¢ãããé²ãã¦ããããã¨ã®ãã¨ã§ãã
ãSIerã®ã¿ãªããã¨è£½åãè²ã¦ã¦ãããããã¨ããæ å½è ã®æ¹ã®è¨èãå°è±¡çã§ããã
AWSã使ãè¾¼ãã§ããç§éã®ãããªã½ãªã¥ã¼ã·ã§ã³ãããã¤ãããã£ã¨ããããã»ãã使ãããããéç¨ããããã¨ãã£ãæè¦ããä¼ããããã¨ã§ããã«ãã¼ã¸ã§ã³ã¢ãããé²ãã¦ããããã¨ã®ãã¨ã§ãã
ãSIerã®ã¿ãªããã¨è£½åãè²ã¦ã¦ãããããã¨ããæ å½è ã®æ¹ã®è¨èãå°è±¡çã§ããã
ã¾ããã»ããã¼ã«åå ãã¦ã¿ã¦ãã§ããã ããããã£ã製åã®å°å
¥ã¯å¿
è¦ã§ã¯ãªããã¨æãã¾ããã
ã¢ããªã±ã¼ã·ã§ã³å´ã§ã¯ãã¬ã¼ã ã¯ã¼ã¯ã使ã£ããããªãã¼ã·ã§ã³ã«ãã£ã¦é²å¾¡ããããããã¨ã大äºã§ãããé·æééç¨ããã°ããã»ã©èå¼±æ§ã¯æ¹ä¿®ã§ããªããªã£ã¦ãã¾ãã ã¾ãã¾ãå¢ãã¦ããæ»æææ³ã«å¯¾æããããã«ã¯ãå°éçã«ãã©ãã¯ãªã¹ããæ´æ°ãã¦ãããµã¼ãã¹ã使ããã¨ã§å®å ¨ãªéç¨ãå®ç¾ã§ããã®ã§ã¯ãªãã§ããããã
ãã¡ããã試ç¨çãæä¾ããã¦ããã®ã§ãæ¯éã試ãããã ãã¦ããããã¨æãã¾ãã
ã¢ããªã±ã¼ã·ã§ã³å´ã§ã¯ãã¬ã¼ã ã¯ã¼ã¯ã使ã£ããããªãã¼ã·ã§ã³ã«ãã£ã¦é²å¾¡ããããããã¨ã大äºã§ãããé·æééç¨ããã°ããã»ã©èå¼±æ§ã¯æ¹ä¿®ã§ããªããªã£ã¦ãã¾ãã ã¾ãã¾ãå¢ãã¦ããæ»æææ³ã«å¯¾æããããã«ã¯ãå°éçã«ãã©ãã¯ãªã¹ããæ´æ°ãã¦ãããµã¼ãã¹ã使ããã¨ã§å®å ¨ãªéç¨ãå®ç¾ã§ããã®ã§ã¯ãªãã§ããããã
ãã¡ããã試ç¨çãæä¾ããã¦ããã®ã§ãæ¯éã試ãããã ãã¦ããããã¨æãã¾ãã
InfoCage SiteShellã¯ä»å¾ããã«AWSã§å©ç¨ããããå½¢ã«å¤ãã£ã¦ããã¨ã®ãã¨ãªã®ã§ãå®éç¨ã«ã¦å°å
¥ããã®ã楽ãã¿ã§ãã