SMTP PIPELINING
.NET Frameworkに潜む脆弱性「SMTPコマンド・インジェクション」とその対処法 - @IT
ãã®è¨äºã®ä¸»é¡ã¯ãSMTP ã«ãããã¤ã³ã¸ã§ã¯ã·ã§ã³ã®è©±ãªã®ã ãããã®å段éã®è©±ãæ°ã«ãªã£ãã
SMTP ã§éããã¨ãã¦ããå 容ããäºãããã¹ããã¡ã¤ã«ã«ä¿åãã¦ããã¦ãNetcat ã§æµããã話ãã¾ããå¥ã« Netcat ã使ããªãã¦ããTeraterm ã putty 㧠smtp ãã¼ãã¸ã¤ãªãã§ãã³ãã¼ï¼ãã¼ã¹ããã¦ãåãäºã¯åºæ¥ãããããããã¨ããµã¼ãå´ããã®ã¬ã¹ãã³ã¹ãç¡è¦ãã¦ãä¸æ¹çã«éä¿¡å 容ãæ¼ãä»ãããã¨ã«ãªãã
ä¾ããã¨ãç¸æã®è¿äºãèããã«ãä¸æ¹çã«è©±ããã¦é»è©±ãåããããªãã®ã§ãè¦ä»¶ãä¼ããä¿è¨¼ã¯ãªãã
ãã ãSMTP ã®ã²ã¨ã¤ã²ã¨ã¤ã®ã³ãã³ãã«å¯¾ããå¿çãå¾ ã¤ã¨ãã¹ã«ã¼ãããã稼ããªãã®ã§ãRFC 2920 㧠SMTP PIPELINING ã¨ããã®ãç¨æããã¦ããã
RFC 2920 - SMTP Service Extension for Command Pipelining
ããã¯ãæ¡å¼µ SMTP ã®ç¯çãªã®ã§ãæåã®ãHELOãã®ä»£ããã«ãEHLOãã使ãããEHLOãã«å¯¾ãããµã¼ãå´ã®ã¬ã¹ãã³ã¹ã§ãPIPELINING ã«å¯¾å¿ãã¦ããäºã確èªãã¦ããæµãããã®ããæ£ããããæ¹ã«ãªãã
ãªã®ã§ãå ã®è¨äºã¯ã
- ãHELOãã§å§ãã¦ããã®ã§ãSMTP ãµã¼ãããã¤ãã©ã¤ã³å¦çãããªãã¦ã OK
- ãã¨ã対å¿ãã¦ãããµã¼ãã§ãããEHLOãã¨ãã®ã¬ã¹ãã³ã¹ã確èªããã¾ã§ã¯ããã¤ãã©ã¤ã³ã§æµãè¾¼ãããå¦ãã¯å¤æåºæ¥ãªãã®ã§ããããå¦çã«ãHELOã/ãEHLOããå«ããäºã¯åºæ¥ãªãã
ã®ã§ãWindows Server 2003 R2 ã® SMTP ãµã¼ãã¹ãããã®ãããªãããå¦çã§ä¸æããããªãã®ã責ãããã¨ã¯åºæ¥ãªãããããããsendmail ã¯ããã¶ãã親åã«é å¼µã£ã¦ããªããã¨ããäºã«ãªãã
ãDATAãã®æä¸ã«ããªãªãã ãã®è¡ãã¡ãã»ã¼ã¸ã®çµäºã表ãã®ã§ãã¨ã¹ã±ã¼ãããå¿ è¦ãããã主é¡ã®æ¹ã¯è¯ãã®ã ãããããçä¼¼ãã¦ãSMTP PIPELINING ãç¡è¦ãã¦ä¸æ°ã«æµããã人ãåºã¦ããªãããã¨ã£ã¦ãå¿é ã
ã¤ãã§ã«ãSMTP ã® RFC ã¨ãã¦ã821 ãç´¹ä»ãã¦ããã®ã¯ãããããä½æã®æ代ã ããã¨ããæãã2001 å¹´ã« 2821 ã«ç½®ãæãããã¦ãããã2008 å¹´ã« 5321 ã«ç½®ãæãããã¦ãããã ãã©...ã
http://tools.ietf.org/html/rfc2821
RFC 5321 - Simple Mail Transfer Protocol