ã¯ã©ã¦ãã®ãµã¼ãã¼ã®èå¼±æ§ãçªããã¦ç²ãã
æ¨æ¥ã®ååä¸ã«ãTwitterã®ã¿ã¤ã ã©ã¤ã³ãè¦ã¦ã¦ãã²ã¨ã¤ã®ãã¥ã¼ã¹ããµã¨ç®ã«çã¾ã£ãã
â« WordPressサイトの.htaccessが改ざんされている件 - CGI版PHPの脆弱性?謎のindex.bak.php | WP SEOブログ
èªåã®ãµã¤ãã§ã¯ãã¾ã WordPressã使ã£ã¦ãªããã©ãä¸å¿ãã§ãã¯ãã¨ããã¨æã£ã¦èª¿ã¹ã¦ã¿ãã
ãããããä¸ã®ããã°ã§æ¸ããã¦ãå 容ã¨ã¯éããã©ã.htaccess ãæ¹ç«ã¨ãããããã¨ãã¨ç½®ãã¦ãªãã£ãã®ã«ãåæã«ä½æããã¦ãã§ã¯ãªããï¼
ãã®âå
容㧠.htaccess ãä½ããã¦ããJoomla!ã®ãµã¤ãã¯æ¢ã«ããã®ã§ããã¡ã¤ã«ã®å
é ã«æ¿å
¥ããã¦ãã
æåãCMSã使ã£ã¦ãªã static ãªãµã¤ãä¸ http://www.satoshis.com/ ã§çºè¦ããã®ã§ãapache ã®èå¼±æ§ãçªãããã®ããªï¼ã¨ãæããapache ãææ°çã® 2.2.22 ã«ã¢ãããã¼ãããã
ããã§å¤§ä¸å¤«ããªã㨠.htaccess ãåé¤ãã¦æ§åãè¦ã¦ããã1æéãããªããã¡ã«åããã㪠.htaccess ãä½ããã¦ããlast ãã¦ã¿ããã©ä¸æ£ãªãã°ã¤ã³ã¯ãªãããps ãã¦ãå¤ãªããã»ã¹ã¯è¦å½ãããªãã®ã§ãä½ãã®ãµã¼ãã¹çµç±ã§æ¥ã¦ããã ããã¨å¤æã
httpd ã®ãã°ãè¦ãã¨ããã·ã¢ã¨ãéå½ã¨ãä¸å½ã®ã¢ãã¬ã¹ãããä¸æè°ãªãã©ã¡ã¼ã¿ã¼ä»ãã®ã¢ã¯ã»ã¹ãããã®ãçºè¦ãã§ããhtacces ã£ã¦æååã¯è¦å½ãããã
ããããã¨èª¿ã¹ã¦ã¿ãã¨ããªãã staticãªhtmlãç½®ãã¦ããã¼ãã£ã«ãã¹ãã¨ãJoomla ã®ãã¼ãã£ã«ãã¹ãã®ãã£ã¬ã¯ããªã«ã ã .htaccess ãä½ããã¦ãã£ã½ããã¨ãåãã£ãã
ããããã¦ãJoomlaã®èå¼±æ§ï¼
ãã®éã ãããJoomlaã 1.5 ãã¼ã¹ã®ææ°ç 1.5.22 ã«ã¢ãããã¼ããã¦ã¿ããããã¾ã æ¹ç«ãç¶ãã¦ããå®æçã« IE8 ã§ã¢ã¯ã»ã¹ãã¦ãã¦ã.htaccess ãä½æãããæ¸ãæããããã¦ããã¦ãã
httpd ã®ã¢ã¯ã»ã¹ãã°ã調ã¹ãã¨ãã©ããã Joomla! ã®è§£èª¬ãµã¤ããå©ç¨ãã¦ãããããJoomla!ã®è§£èª¬ãµã¤ãã£ã¦ãããããã¨ã¨ã¯ã¹ãã³ã·ã§ã³ãå ¥ãã¦ããããã¨ã¯ã¹ãã³ã·ã§ã³ã«èå¼±æ§ãããã®ãããããªããã¢ã¯ã»ã¹å URLã調ã¹ãã¨ãcom_morfeoshow ã£ã¦ã¨ã¯ã¹ãã³ã·ã§ã³ã«ã¢ã¯ã»ã¹ããã¨ãã«ãé·ãã¦å¤ãªãã©ã¡ã¼ã¿ã¼ã渡ããã¦ãã
確èªãããã©ããã®ã¨ã¯ã¹ãã³ã·ã§ã³ã¯ç¾ç¶ã§ã¯ä½¿ã£ã¦ãªãã¦ãJoomla!ã®ã·ã¹ãã ä¸ã§ã¯ã¢ã³ã¤ã³ã¹ãã¼ã«æ¸ã«ãªã£ã¦ãã
ãããããããã以é㯠.htaccess ãä½æããããæ¹ç«ãããããããã¨ã¯ãªããªã£ãã
ã§ããã²ãããåãURLã«å¯¾ãã¦ã¢ã¯ã»ã¹ãç¶ãã¦ãããããã¨ã©ã¼ãã°ã«404ã次ã ã«ç©ã¿ä¸ãããã¦ããã
ãããã¯ãã¦ããã£ã¨å¹³åã訪ããã