LDD13is
LDD13isï¼LOCAL DEVELOPER DAY'13/Infra & Securityï¼ã«è¡ã£ã¦ãã¾ããã
IT ã¨ã³ã¸ãã¢ã®å°æ¥ - åç° ãã¯ã
åºèª¿è¬æ¼ã¨ãã¦ãco-meeting ã®åç°ãã¯ãããï¼æ¬åã§ç´¹ä»ãããªãã£ãï¼ãããã¤ã³ãã©ã»ã¨ã³ã¸ãã¢ã®ã¯ã©ã¦ãã¨ã®ã¤ãããæ¹ã«é¢ãã¦ã話ãããã¾ããã
ã¯ã©ã¦ãã®ã¡ãªããã¯ãã¹ãã¼ãã¨ãªã¹ã¯å¯¾çã§ãã³ã¹ãã«é¢ãã¦ã¯ã±ã¼ã¹ãã¤ã±ã¼ã¹ãã¨ããã®ã¯ãç§ãæã£ã¦ããã¨ãããªã®ã§ãããéã«ããããåã®çºæ®ã©ãããã¨ããã®ã¯ããã®éãã ã¨æãã¾ããã
ã¯ã©ã¦ããã©ã使ãããã¨ããäºããã¡ãã¨èãããããã©ãããããã¤ã³ãã§ãç®ç次第ã§ã¯ã©ã¦ãã®ä½¿ãæ¹ãå¤ããããæ¢åã®ãã¹ãã£ã³ã°ã§å åã§å®ä¸ããã ã£ãããå ¨ä½ã¨ãã¦ã®ã»ãã¥ãªãã£ã»ããªã·ã¼ã«ãã£ã¦ã¯ããªã³ãã¬ãã¹ã®æ¹ãè¯ãå ´åããããã
çµå±ãåã ã®ç®çãç°å¢ã«ãã£ã¦ã©ãããã®ãé©åããå¤æããå¿ è¦ããããã¨ãããã¨ã«é¢ãã¦ã¯ãã¯ã©ã¦ãã®æç¡ã«é¢ä¿ãªãããã§ãåã«é¸æè¢ãå¢ãããã¨ãããã¨ããªãã¨ããã ããã®é¸æè¢ãç¡è¦ããäºã¯ããããªãã®ã§ããµã¼ãã¹å ¨ä½ããè¦ãã¯ã©ã¦ãã®ä½¿ãã©ãããã¨ããã®ãæèãã¦ããäºã大åãªã®ã§ã¯ãªãããã¨æãã¾ããã
ã©ã¤ãã³ã¼ãã£ã³ã°ã¨ãã¢ã§ç解ãã Web ã»ãã¥ãªãã£ã®åºç¤ - 岸谷 éä¹
SQL ã¤ã³ã¸ã§ã¯ã·ã§ã³ãã³ãã³ãã»ã¤ã³ã¸ã§ã¯ã·ã§ã³ãXSS ã¨ãã£ãèå¼±æ§ããå®éã®ãã¢ã交ãã解説ã§ãããå人çã«ã¯ãä¸å¿ãç¥ã£ã¦ãã話ã ã£ãã®ã§ãããå ·ä½çãªã³ã¼ãã¨ãå®éã®åä½ã«ãããã¢ãã¨ããã®ã¯ãããããã§ç¡ãã£ããããªæ°ããã¾ãã
ç¹ã« XSS ã¯ããalert() ãåããã¨ããã®ãå®çªã§ãããã ã¨ããä½ã大å¤ãªäºãèµ·ãã¦ãããã¨ããã®ãå®æããããã®ã§ãããã»ãã·ã§ã³ ID ãä¿æãã¦ãã Cookie ã®å¤ãçããã¨ãããã¢ã ã£ãã®ã§ãåé¡ãå®æã§ãã人ãå¤ãã£ãã®ã§ã¯ãã¨æãã¾ãã
åã ã®åé¡ã«å¯¾ãã¦ãã³ã¼ããä¿®æ£ãã¦ãå®éã«èå¼±æ§ãç¡ããªããã¨ããã¨ããããã¢ããã¦ãã¾ããããå ·ä½çãªå¯¾çã¯ããã®ã»ãã·ã§ã³ã®æå¾ã§ãç´¹ä»ããã¦ãã¾ããããã¾ãã¯ã徳丸æ¬ãã§ããã
- ä½è : 徳丸浩
- åºç社/ã¡ã¼ã«ã¼: SBã¯ãªã¨ã¤ãã£ã
- çºå£²æ¥: 2011/03/01
- ã¡ãã£ã¢: åè¡æ¬
- è³¼å ¥: 119人 ã¯ãªãã¯: 4,283å
- ãã®ååãå«ãããã° (146件) ãè¦ã
VPS ã¯ããã¦ã®ä¸æ© - é·²å è³¢
VPS ãµã¼ãã使ãä¸ã§ãããã¹ãã»ãã¥ãªãã£å¯¾çã«é¢ããã話ã§ããã
ã¨è¨ã£ã¦ããåºæ¬çã«ã¯æ®éã®ãµã¼ãã§ã®å¯¾çã¨åãã§ããSSH ã§ãPermitRootLogin ã no ã«ããããssh ã®ãã«ã¼ããã©ã¼ã¹ãé¿ããããã«ãã¼ãçªå·ãå¤æ´*1ããããå ¬ééµèªè¨¼ã使ã£ãããã¨ãã£ã ssh å¨ãã®å¯¾çããsudo ã®ãããã iptables ã®è©±ãªã©ãVPS ã«éãããä¸è¬ç㪠UNIX ãµã¼ãã§ãæ¨å¥¨ãããã話ã§ããã
ä¸ã¤ãVPS ãªãã§ã¯ãªã®ã¯ãã¾ãã¯ãroot ã®ãã¹ã¯ã¼ãã®å¤ãããããããã® VPS ã§ã¯å¥ç´ç´å¾ã¯åæ¢ç¶æ ã ãããããããã§ãããããªãã¤ã³ã¿ã¼ãããä¸ã«ããããã訳ã§ãããããªã«ã¯ã¨ãããããã¹ã¯ã¼ãã®å¤æ´ã§ããã
ã¨ã³ã¸ãã¢ã®ãä»äº å®éã®è©±
ï¼åã®æ¹ã®ããä»äºã®æ§åã®ã話ã§ãã
æ±äº¬ã®ä¼ç¤¾ã§æå¹ã§ã®å¨å® å¤åããã¦ããæ¹ãå è±å±ã®ã¤ã³ãã©ã¨ã³ã¸ãã¢ãã½ã¼ã·ã£ã«ã²ã¼ã ã®éçºè ãã¨ãã£ãä¸è ä¸æ§ã®ã¨ã³ã¸ãã¢ã»ã©ã¤ãã®ã話ãããã¾ããã
æå¾ã®è³ªåã¿ã¤ã ã§é£ã³åºããããæ JOINã*2ã¯ãç® grep ã®æ¬¡ã«ããã¨ã³ã¸ãã¢å¿ é ã®ãã¯ããã¯ã«(^^?ã
çãããæ¥æ¬ - Boris Sharov
ãªãã¨ãDr.Web ã® CEO ã§ãã Boris Sharov ããã®è¬æ¼ã§ããã¿ã¤ãã«ã¯ãçãããæ¥æ¬ãã§ããããæ¥æ¬ãç¹ã«ä½ããã¨ããããããä¸çãè¦æ¸¡ãã°é ·ãå½ã»å°åããããæ¥æ¬ãç¡é¢ä¿ã§ã¯ããããªããã¨ãã£ãäºãå°è±¡ã«æ®ãã¾ããã
ã¨ã«ããããå®å ¨ã¨æãè¾¼ããã®ãä¸çªå±éºãã¨ãããã¨ã§ãMac ã§å¤§è¦æ¨¡ãªãã«ã¦ã§ã¢ã®ææãè¦ã¤ãã£ãæã¯ãç¹ã«ç±³å½ã§ã¯å¤§ããªé¨ãã ã£ãããã§ãã
å¾åãã¯ã©ã¦ãã®ã»ãã¥ãªãã£ã«é¢ãã¦è©±ããã¦ããã®ä¸ã§å°è±¡ã«æ®ã£ãã®ã¯ãã¯ã©ã¦ãèªä½ã¯å®å ¨ã§ããæè©®ãã¢ã«ã¦ã³ãã¨ãã¹ã¯ã¼ãã§èªè¨¼ãã¦ããã ãã ãããã¢ã«ã¦ã³ãæ å ±ãæ¼ããããããã§ãæãæ¸ã¾ãäºãã§ãããã¨ãããå½ããåã ãã©å¿ããã¡ãªç¹ã«ã¤ãã¦è©±ããã¦ãããã¨ã§ããæ ã« Boris ããã¯ãã¯ã©ã¦ããå«ããã¨è¨ã£ã¦ãã¾ããããã¯ã©ã¦ãã»ãã¥ãªãã£ã®èã¯èªè¨¼ãã¨ããäºãå¼·ãæãã¾ããã
Free Software Way - å°å²© ç§å
WCIT-12 ã®è©±ããå§ã¾ã£ã¦ãé»åæ¸å¼ã§è³¼è²·å±¥æ´ã管çããã¦ãã¾ããã¨ãã£ã話ããã¯ã©ã«ãFree Software ã®è©±ãå°å²©ãããç±ãèªã£ã¦ã¾ãããå人çã«ã¯ããã®è¾ºã®è©±ã¯å²ã¨ç¥ã£ã¦ãã¦ãã¨ããå®æè«äºã«ãªãããããã ããªãããªã©ã¨æããªããèãã¦ãã¾ããã
ã©ã£ã¡ãã¨ããã¨ãStallman ãã㯠Raymondãã®èªåã¨ãã¦ã¯ããã¡ãã£ã¨è¦æããªæãããããã§ããã質çã®æã« GPL 㨠MIT ã BSD ã©ã¤ã»ã³ã¹ã¨ã®æ¯è¼ã®è©±ã§ãå°å²©ããããGPL ã¯ãã¤ããã¨è¨ããã¦ããã®ããã¡ãã£ã¨æå¤ãã¨ããããå人çã«ã¯ããã¨ããæããããã¾ããã
LT ã 6 æ¬
ããããã°ãããã ã½ãã§ã¯ããã®ã¨ãã LT ãã£ã¦ãªãã§ãããLT ã¯æ¯åº¦ã楽ãã¾ãã¦ãããå´ã§ããã¤ãã¯ææ¦ãã¦è¦ãããã ãã©ãç¬ãåããªãããªãã
ã¨ãããã¨ã§æ¬¡åã¯
ããã
ã½ã #14 㯠3/9 ã§ãå
容ã¯...ãã¨æã£ã¦ããã
ã½ãã®ãã¼ã¸ãè¦ãããã¾ã æ¸ããã¦ãªãã£ãã§ããã
ã¡ããã©ï¼å¹´åã®ãã®ææã®ããã
ã½ãã¯ãå
¥é¢ãã¦ãã¦åºãããªãã£ããã ããªããä»å¹´ã¯å¤§ä¸å¤«ããªã