ãããã¨èå¼±æ§ãæãããWebã¢ããªãã§ç·´ç¿ã
http://www.atmarkit.co.jp/fsecurity/column/ueno/59.html
ãã®é¡ã®ãã¼ã«ã¯ãã¡ãã£ã¨åã«mothã試ããã®ã§ãããVMwareã«
é£ããããã®ã®èµ·åããã
åå ããããããã¾ãã§ãããä¸è¨è¨äºãèªãéããmothã®ä»ã«ã
ããã¤ãããããã§ããã
ã¨ããããã§ã試ãã«WebGoatã®ãµã¤ãã«è¡ã£ã¦ã説æãæãèªã¿ãã¦ã¿ã¾ããã
http://www.owasp.org/index.php/Category:OWASP_WebGoat_Project
ãããJavaã¨Tomcatãããã°ä½¿ãããããªã®ã§ããããã¼ã¿ãã¼ã¹ã£ã¦ã©ããã¦ããã ããï¼
Overviewã«æ¸ããã¦ããSQL Injectionç³»ã«å¿
è¦ã¨æã£ãã®ã§ããã
ãµã¤ãã«ããã£ã½ãè¨è¿°ããªãã£ãã®ã§ãã¨ãããããWARãã¡ã¤ã«ãDLãã¦ä¸èº«ãæ¼ã£ã¦ã¿ã¾ããã
å®éã«åãããã³ã¾ã§ã¯è¡ãã¦ã¾ããããã©ã¤ãã©ãªã®ãã©ã«ãã«ã¦
hsqldb.jar ãè¦ã¤ãã¾ããã
ã©ããããå
é¨ã§HSQLDB使ã£ã¦ãã¿ããã§ãããç´å¾ã
ãã©ã¯ã¨9ãæãã®ã»ãé·å¼ãã¦ã¾ãããããããå
ã®4æ¦å£«ãèããªããã°ã
äºç´éã«åãããããã¾ããããã¨ãããããææ¥ã¯ãã£ã¡ç³»ãã¼ããããããªã
ãã絶æå
çãäºç´å¿ãã¦ãã