Webã¢ããªã±ã¼ã·ã§ã³èå¼±æ§è¨ºææ¬ãWebã»ãã¥ãªãã£æ å½è ã®ããã®èå¼±æ§è¨ºæã¹ã¿ã¼ãã¬ã¤ã ä¸é宣ãæããæ å ±æ¼ãããé²ãæè¡ããçºå£²äºå®
2016å¹´8æ2æ¥ã«3å¹´ã¶ãã«æ¸ç±ãåºãã¾ãããã¼ãã¯ãWebã¢ããªã±ã¼ã·ã§ã³èå¼±æ§è¨ºæãã§ãã
å¼ç¤¾ï¼æ ªå¼ä¼ç¤¾ãã©ã¤ã³ã¼ãï¼ã§ã¯脆弱性診断を学ぶための講座ãããã¤ãæä¾ãã¦ãããããªã¼ãã¼ãåããOWASP Japanã®脆弱性診断士スキルマッププロジェクトã§ã®ã¬ã¤ãã©ã¤ã³ä½ããªã©ã«ãã£ã¦ã診æä¼ç¤¾å社ã®è¨ºæææ³ããã¦ãã¦ãªã©ãèç©ãããã¨ãã§ãã¾ãããæ¬æ¸ã¯ãããä¸åã«ã¾ã¨ããæ¬ã¨ãªã£ã¦ãã¾ãã
- Webã»ãã¥ãªãã£æ å½è ã®ããã®èå¼±æ§è¨ºæã¹ã¿ã¼ãã¬ã¤ã ä¸é宣ãæããæ å ±æ¼ãããé²ãæè¡
- çºå£²å : ç¿æ³³ç¤¾
- ä¾¡æ ¼: ï¿¥ 3,456
- çºå£²æ¥: 2016/08/02
èå¼±æ§è¨ºæã¯ã»ãã¥ãªãã£ä¼ç¤¾ãå®æ½ãããã¨ãå¤ãã®ãç¾ç¶ã®ããã§ããããã¯èå¼±æ§è¨ºæã¨ããæè¡ãç¹æ®ãªããã«çç·´ã®ã»ãã¥ãªãã£å°é家ã§ãªãã¨å®æ½ã§ããªãã¨ãã誤解ããããããã¾ããã
å®éã¯ããã§ã¯ããã¾ãããææ³ãç¥ããæ¹æ³ãå¦ã¶ãã¨ã§èª°ã«ã§ãã§ããããã«ãªãæè¡ã§ããããã«ã¯ã·ã¹ãã ã®ä»æ§ãç¥ã£ã¦ããéçºè
ãèå¼±æ§è¨ºæãè¡ããã¨ã§ãã·ã¹ãã ã®ãã¨ãç¥ããªãã»ãã¥ãªãã£å°é家ãè¡ãããããã¾ãè¡ããå¯è½æ§ããããã®ã§ãã
æ¬æ¸ã§ã¯Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§è¨ºæãè¡ãããã«å¿
è¦ãªåºç¤ç¥èã診æã«å¿
è¦ãªãã¼ã«ãããã¦èå¼±æ§ãå¹ççã«çºè¦ããããã®è¨ºæææ³ãå ±åæ¸ã®æ¸ãæ¹ãªã©ãå¦ã¶ãã¨ãã§ãã¾ãã
ã¾ããã¬ãã¥ã¼ã¢ã¼ã«ã¯OWASP Japanãªã©ã®WGã§ãä¸ç·ããã¦é ãã¦ãã å°æ²³ å²ä¹ããï¼Burp Suite Japan User Groupï¼ãäºç° åæ©ããï¼SCSKæ ªå¼ä¼ç¤¾ï¼ãå½å è£ãããæ´²å´ ä¿ããã西æ å®æããï¼æ ªå¼ä¼ç¤¾ãªã¯ã«ã¼ããã¯ããã¸ã¼ãºï¼ãå±±å´ åå¾ããï¼æ ªå¼ä¼ç¤¾ã©ãã¯ï¼ã«ãé¡ãããã¦é ãã¾ããã
ç®æ¬¡
1.èå¼±æ§è¨ºæã¨ã¯
ãã®ç« ã§ã¯èå¼±æ§è¨ºæã¨ã¯ä½ãã¨ãããã¨ãå¦ãã§è¡ãã¾ããWebãµã¤ããWebã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã¨ã¯ã©ããã£ããã®ã§ããããçºè¦ããããã®ææ³ã§ããèå¼±æ§è¨ºæã¨ã¯ã©ããã£ããã®ããå¦ã³ã¾ãããã
- èå¼±æ§è¨ºæã¨ã¯ãèå¼±æ§ãçºè¦ããããã®ãã¹ãææ³ã
- æ¬æ¸ã®èå¼±æ§è¨ºæ対象ã¨Webãµã¤ãã®èå¼±æ§å¯¾ç
- èå¼±æ§è¨ºæ士ã«å¿ è¦ãªç¥èãæè¡
- èå¼±æ§è¨ºæ士ã«æ±ããããå«ç観
2.診æã«å¿
è¦ãªHTTPã®åºæ¬
ãã®ç« ã§ã¯Webã®ä¸»è¦ãªãããã³ã«ã§ããHTTPã®åºæ¬ã«ã¤ãã¦å¦ãã§è¡ãã¾ããWebã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§è¨ºæãè¡ãããã«ã¯ãWebã®ä¸»è¦ãªéä¿¡ãããã³ã«ã§ããHTTPã®ç解ãæ¬ ãããã¨ãã§ãã¾ããã
HTTPã¨ãããããã³ã«ã®ä»çµã¿ããéä¿¡ã§ããã¨ãããã¡ãã»ã¼ã¸ã®æ§é ãªã©ãå¦ã³ã¾ãããã
- HTTPã¨ã¯
- TCP/IPã¨HTTPã®é¢ä¿
- HTTPã¨é¢ä¿æ·±ããããã³ã« - IPã»TCPã»DNS
- URLã¨URI
- ã·ã³ãã«ãªãããã³ã« HTTP
3.Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§
ãã®ç« ã§ã¯Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã«ã¤ãã¦å¦ãã§è¡ãã¾ããWebã¢ããªã±ã¼ã·ã§ã³ã¸ã®æ»æãã©ããããã®ã§ãã©ããã£ã種é¡ã®ãã®ãããã®ããå¦ã³ã¾ãããã
- Webã¢ããªã±ã¼ã·ã§ã³ã¸ã®æ»æã¨ã¯
- ã¤ã³ã¸ã§ã¯ã·ã§ã³ - Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§
- èªè¨¼ - Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§
- èªå¯å¶å¾¡ã®ä¸åã»æ¬ è½ - Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§
- ã»ãã·ã§ã³ç®¡çã®ä¸å - Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§
- æ å ±æ¼ãã - Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§
- ãã®ä» - Webã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§
4.èå¼±æ§è¨ºæã®æµã
ãã®ç« ã§ã¯Webã¢ããªã±ã¼ã·ã§ã³èå¼±æ§è¨ºæã®æµãã«ã¤ãã¦å¦ãã§è¡ãã¾ããã¾ã診æä¼ç¤¾ãæä¾ãã¦ãããããªè¨ºææ¥åå
¨ä½ã®æµããå¦ã³ã¾ããããã¦è¨ºæå®æ½åã®æºåã«ã¯ä½ãå¿
è¦ããç¥ããèå¼±æ§è¨ºæã¯ã©ã®ããã«è¡ããã¨ããå®æ½æé ãå¦ã³ã¾ãããã
- 診ææ¥åã®æµã
- 診æå®æ½åã®æºå
- èå¼±æ§è¨ºæã®å®æ½æé
5.å®ç¿ç°å¢ã¨ãã®æºå
ãã®ç« ã§ã¯æ¬æ¸ã®å®ç¿ã«å¿
è¦ãªè¨ºæãã¼ã«ãWebãã©ã¦ã¶ãå®ç¿ç°å¢ã®ã»ããã¢ããã«ã¤ãã¦èª¬æãã¦ããã¾ãã
- 診æãã¼ã«ã®ã»ããã¢ãã
- 診æã®ããã®Webãã©ã¦ã¶ã®ã»ããã¢ãã
- å®ç¿ç°å¢ã®ã»ããã¢ãã
- å®éã®è¨ºæã®éã®æ³¨æäºé
6.èªå診æãã¼ã«ã«ããèå¼±æ§è¨ºæã®å®æ½
ãã®ç« ã§ã¯èªå診æãã¼ã«ã使ã£ãèå¼±æ§è¨ºæã®å®æ½æé ãã¯ããã¨ãã¦ãèªå診æãã¼ã«ã¨ãã¦ä½¿ç¨ããOWASP ZAPã®åºæ¬æä½ãèå¼±æ§è¨ºæã®å®æ½æ¹æ³ãªã©ã説æãã¦ããã¾ãã
- èªå診æãã¼ã«ã使ã£ãèå¼±æ§è¨ºæã®å®æ½æé
- OWASP ZAPã®åºæ¬æä½
- OWASP ZAPã«è¨ºæ対象ãè¨é²
- OWASP ZAPã§è¨ºæãå®è¡
7.æå診æè£å©ãã¼ã«ã«ããèå¼±æ§è¨ºæã®å®æ½
ãã®ç« ã§ã¯æå診æè£å©ãã¼ã«ã使ã£ãèå¼±æ§è¨ºæã®å®æ½æé ãåãã¨ãã¦ãèå¼±æ§è¨ºæã«ä½¿ç¨ããåºæºã診æãªã¹ãã®ä½ææ¹æ³ãæå診æè£å©ãã¼ã«ã¨ãã¦ä½¿ç¨ããBurp Suiteã®åºæ¬æä½ãå種ãã¼ã«ã®ä½¿ãæ¹ãèå¼±æ§è¨ºæã®å®æ½æ¹æ³ãªã©ã説æãã¦ããã¾ãã
- æå診æè£å©ãã¼ã«ã使ã£ãèå¼±æ§è¨ºæã®å®æ½æé
- Webã¢ããªã±ã¼ã·ã§ã³èå¼±æ§è¨ºæææ³: èå¼±æ§è¨ºæ士ã¹ãã«ãããããã¸ã§ã¯ãã®åºæº
- Burp Suiteã®åºæ¬æä½: æå診æã®ããã®Burp Suiteåºæ¬æä½
- 診æãªã¹ãã®ä½æ: ãã¹ãã±ã¼ã¹ã®ã·ã¼ããä½æããæé
- Burp Suiteã®å種ãã¼ã«ã®ä½¿ãæ¹
- Burp Suiteã使ã£ãèå¼±æ§è¨ºæ
- ããå¤ãã®èå¼±æ§ãçºè¦ããããã®ãã³ãé: ããå¤ãã®èå¼±æ§ãçºè¦ããããã®æå診æã®ã³ã
8.診æå ±åæ¸ã®ä½æ
ãã®ç« ã§ã¯èå¼±æ§è¨ºæãå®æ½ããçµæãã¾ã¨ãã診æå ±åæ¸ã®ä½æã«ã¤ãã¦ãå ±åæ¸ã«è¨è¼ãã¹ãäºé
ãåå¥ã®èå¼±æ§ã®å ±åæ¹æ³ããªã¹ã¯è©ä¾¡ã®ä»ãæ¹ãªã©ã説æãã¦ããã¾ãã
- 診æå ±åæ¸ã®è¨è¼äºé
- ç·åè©ä¾¡ã¨åå¥ã®èå¼±æ§ã®å ±å
- ãªã¹ã¯è©ä¾¡
9.é¢ä¿æ³ä»¤ã¨ã¬ã¤ãã©ã¤ã³
ãã®ç« ã§ã¯èå¼±æ§è¨ºæã«é¢é£ããæ³å¾ã診ææã®ã«ã¼ã«ã診æçµæã®åãæ±ããã»ãã¥ãªãã£ã«é¢ããåºæºãã¬ã¤ãã©ã¤ã³ã«ã¤ãã¦èª¬æãã¦ããã¾ãã
- èå¼±æ§è¨ºæã«é¢é£ããæ³å¾ãã«ã¼ã«ãåºæºãªã©
ä»é²: å®ç¿ç°å¢ã®ã»ããã¢ããï¼Oracle VM VirtualBoxï¼
Webã¢ããªã±ã¼ã·ã§ã³èå¼±æ§è¨ºæè¬åº§
æ¬æ¸ã使ã£ããã¬ã¼ãã³ã°ã§ããã°çè ãæããå¼ç¤¾ã®ãã¡ãããå§ãã§ãã
- èªç¤¾ã§åãçµãWebã¢ããªã±ã¼ã·ã§ã³èå¼±æ§è¨ºæ | æ ªå¼ä¼ç¤¾ãã©ã¤ã³ã¼ã
Aterm MR03LNãæµ·å¤ã§ãSIMããªã¼ã«ãªã£ã
ã¢ãã¤ã«ã«ã¼ã¿ã¼ã¨ãã¦ã¯æå¼·ã¨è¨ãããã»ã©ç³ãåãªãæ©è½ãæ㤠Aterm MR03LN ã¯ãå½åSIMããªã¼æ©ã ã¨åããã¦ãã¾ããããå½å ONLYã®DoCoMoã®MVNOã®SIMã«ãã対å¿ãã¦ãã¾ããã§ããã
æµ·å¤ã«ããè¡ãç§ã¨ãã¦ã¯ãæµ·å¤ã§ä½¿ããªãã¨ã¢ãã¤ã«ã«ã¼ã¿ã¼ã¨ãã¦ã®æå³ããªããè²·ã£ã¦ãã°ãããã¦ã¿ã³ã¹ã®è¥ããã«ãï¼è²·ã£ãçç±ã¯ãã¯ã¬ã¼ãã«ã使ããã¨ã§æç·LANã®ãããã¯ã¼ã¯ãçµããããã§ãããåºå¼µæã®ãµã¤ãã¼æ¼ç¿ã®ãã¬ã¼ãã³ã°ã«1å使ã£ãã£ãããï¼
ããã¦ãã®8æã«æå¾ ãã¦ãããã¡ã¼ã ã¦ã§ã¢2ç³»ãå ¬éããã¦ããããããã£ã¦ï¼ãã¡ã¼ã ã¦ã§ã¢2.0ã®å ¬éåæ¢ã¨ãï¼ããããAPNã®è¨å®ãèªç±ã«ã§ããããã«ï¼ããã¯æå¾ ï¼ã¨ãããã¨ã§ããã¡ã¼ã ã¦ã§ã¢ã 2.0 ã«ãã MR03LN ãä»åã®å°æ¹¾åºå¼µï¼ããã«ã¼ç³»ã«ã³ãã¡ã¬ã³ã¹ã® HITCON ã«åå ããããï¼
çµæãæ¾å±±ç©ºæ¸¯ã§è²·ã£ãä¸è¯é»ä¿¡ã®ããªãã¤ãSIMãæ¿ããAPNè¨å®ãè¡ã£ãã¨ããç¡äºã«åä½ã確èªãã¾ãããå®å®æ§ãé度ã¨ãã«ã¾ã£ããåé¡ããã¾ãããï¼å°æ¹¾ã§ã¯LTEã¯ä»å¹´éå§ãã¾ããããããªãã¤ãSIMã§ã¯LTEæªå¯¾å¿ãããï¼
2.0ã¯ä¸å
·åããã£ã¦å¿é
ãã¦ãã¾ããããå°æ¹¾æ»å¨ä¸ã®8æ19æ¥ã«2.1ãå
¬éããã¢ãããã¼ããè¡ãã¾ããã®ã§ãããã§ããããä¸å®å¿ã
ãã®ã«ã¼ã¿ã¼ã¯ä½ã¨è¨ã£ã¦ãããã¶ãªã³ã°ä½¿ç¨æã¯Bluetoothã§24æéãWi-Fiã§12æéã¨ããããããªã¼ã®æã¡ãæµ·å¤åºå¼µæã«é常ã«ä¾¿å©ã§ãã
å¨æ³¢æ°çã«ã¯å¤ãã®å½ã«å¯¾å¿ãã¦ããã®ã§ãã¢ãã¤ã«ã«ã¼ã¿ã¼æå¼·ä¼èª¬ã¨è¨ããã¦ãã Aterm MR03LN ãå人çã«ãæ¬å½ã«æå¼·ã«ãªã£ãããã
- NEC Aterm MR03LNãOCN ã¢ãã¤ã« ONE ãã¤ã¯ãSIMä»ãã»ãããã¯ã¬ãã¼ã«ä»å± LTEå¯¾å¿ SIMããªã¼ã¢ãã¤ã«ã«ã¼ã¿ã¼ æé¡900å(ç¨æ)~
- çºå£²å : NTTã³ãã¥ãã±ã¼ã·ã§ã³ãº
- ä¾¡æ ¼: ï¿¥ 22,488 (12% OFF)
- 売ä¸ã©ã³ãã³ã°ï¼ 649
Facebookã®åçã¯å ¬éç¯å²ãéå®ãã¦ãã¦ã誰ã§ãè¦ããã¨ãã§ãã
ãããURLãããããã°ãã
ã»ãã¥ãªãã£ã®è¬ç¾©ã®ãã¿ã§ãã話ãã¦ããã§ããã©ã以å¤ã¨ç¥ããã¦ããªããããªã®ã§ã
å
¬éç¯å²ã¯ èªåã®ã¿
URLãããããã°è¡¨ç¤ºãããã¨ãå¯è½ã§ããä¸è¨ã¯ãã®URLã§ãã
https://scontent-a.xx.fbcdn.net/hphotos-xpa1/t31.0-8/10363467_10203851587031224_5439857412795849561_o.jpg
ããããä»æ§ã£ã¦ããã ããªãã§ããã©ããURLã¯äºæ¸¬ãããã¨ãå°é£ããã§ãããããã¾ãæªç¨æ¹æ³ã¯æãã¤ãã¾ããã以åã®mixiãããããä»æ§ã ã£ããããªæ°ãããã
仲éå
ã«éå®å
¬éã¨ããã¦ãã¦ããã®ä»²éã®èª°ããè£åã£ã¦ãããã¤ãããªåçå
¬éãã¦ãããã¨ããããã ãããã©ãããã ã£ããURLãç´ãªã³ã¯ãããªãã¦ãããã§ãããã
ä»å¤ã¤ãã HTTPã¬ã¹ãã³ã¹ãããã¼ ï¼ã»ãã¥ãªãã£ç·¨ï¼
Webãµã¼ãã¼ãã¬ã¹ãã³ã¹ãçºè¡ããéã«ãHTTPã¬ã¹ãã³ã¹ãããã¼ã«ä»ããã¨ã»ãã¥ãªãã£ã¬ãã«ã®åä¸ã«ã¤ãªãããããã¼ãã£ã¼ã«ããç´¹ä»ãã¾ãã
å²ã¿å
ã¯æ¨å¥¨ããè¨å®ã®ä¸ä¾ã§ãããã©ã¦ã¶ã«ãã£ã¦ã¯å¯¾å¿ãã¦ããªããããã¼ãã£ã¼ã«ãããªãã·ã§ã³ãªã©ãããã¾ãã®ã§ãã¯ã©ã¤ã¢ã³ãã®ç°å¢ã«ãã£ã¦ã¯æ©è½ããªããã¨ãããã¾ãã
X-Frame-Options
ãã©ã¦ã¶ã frame ã¾ã㯠iframe ã§æå®ãããã¬ã¼ã å ã«ãã¼ã¸ã表示ãããã¨ãå¶å¾¡ããããã®ãããã¼ãã£ã¼ã«ãã§ãã主ã«ã¯ãªãã¯ã¸ã£ããã³ã°ã¨ããæ»æãé²ãããã«ç¨ãããã¾ãã
X-Frame-Options: SAMEORIGIN
- DENY ãã¬ã¼ã å ã«ãã¼ã¸ã表示ãããã¨ãç¦æ¢ï¼åããµã¤ãå ã§ãã£ã¦ãç¦æ¢ã§ãï¼
- SAMEORIGIN èªåèªèº«ã¨çæå ãåããã¬ã¼ã ã®å ´åã«ãã¼ã¸ã表示ãããã¨ã許å¯ï¼ä»ã®ãµã¤ãã«ç¦æ¢ãããå ´åã¯ä¸»ã«ããã使ç¨ãã¾ãï¼
- ALLOW-FROM origin_uri æå®ãããçæå ã®ã¿ãã¼ã¸ã表示ãããã¨ã許å¯ï¼ç¹å®ã®ãµã¤ãã®ã¿ã«è¨±å¯ãããå ´åã¯ããã使ç¨ãã¾ãï¼
X-Content-Type-Options
script ã¾ã㯠stylesheet ã§èªã¿è¾¼ããã¡ã¤ã«ã® MIME ã¿ã¤ããæ£ããï¼è¨±å¯ãããï¼ãã®ã¨ä¸è´ããªãéããã¡ã¤ã«ãèªã¿è¾¼ã¿ã¾ãããéHTMLãHTMLã¨è¦ãªããªã©ãã³ã³ãã³ãå 容ã®èª¤å¤å®ãå©ç¨ãã XSS ãªã©ã®æ»æãé²ãããã«ç¨ãããã¾ãã
X-Content-Type-Options: nosniff
機密情報を含むJSONには X-Content-Type-Options: nosniff をつけるべき - 葉っぱ日記
MIME タイプのセキュリティ リスクの軽減 (Windows)
X-XSS-Protection
ãã©ã¦ã¶ã® XSSãã£ã«ã¿ã¼ã®æ©è½ãæå¹ã«ããXSSæ»æãé²ãããã«ç¨ãããã¾ãã
X-XSS-Protection: 1; mode=block
- 0 XSSãã£ã«ã¿ã¼ãç¡å¹
- 1 XSSãã£ã«ã¿ã¼ãæå¹ï¼IE,Chromeã®å ´å㯠1; mode=block ã使ããï¼
2008/7/2 - IE8 Security Part IV: The XSS Filter
IE8 XSS Filterの仕様が微妙に変更されていた。 - 葉っぱ日記
Content-Security-Policy
å¤é¨ã®ãªã½ã¼ã¹ãä¿¡é ¼ã§ããçæå
以å¤ããèªã¿è¾¼ããªãããã«å¶éãããã¨ãã§ãã¾ããXSSããã¼ã¿ã¤ã³ã¸ã§ã¯ã·ã§ã³æ»æãæ¤åºãã¦è»½æ¸ãããã¨ãããã¾ããï¼ãã ããè¨å®ã«ãã£ã¦ã¯å¤é¨ãªã½ã¼ã¹ãèªã¿è¾¼ããªãããã«ãããã¨ã«ãã£ã¦ãç¾å¨åä½ãã¦ããã¹ã¯ãªãããåããªããªãå¯è½æ§ãããã¾ããï¼
以åã¯ã"X-Content-Security-Policy" ã¨ãããããã¼ãã£ã¼ã«ãåã使ã£ã¦ãã¾ããã
Content-Security-Policy: default-src 'self'
- default-src 'self' åããªãªã¸ã³ï¼åãURLã¹ãã¼ã ããã¹ãããã¼ãçªå·ï¼ããã¯ãã¹ã¦ã®ã³ã³ãã³ããèªã¿è¾¼ãããã«ãããå ´å
- default-src 'self' *.example.com æå®ãããã¡ã¤ã³ã¨ãã¹ã¦ã®ãµããã¡ã¤ã³ããã®ã³ã³ãã³ãã許å¯ãããå ´å
X-Permitted-Cross-Domain-Policies
ãcrossdomain.xml ãï¼Flash ã³ã³ãã³ãããå¥ãã¡ã¤ã³ã«ãããã¡ã¤ã«ãèªã¿è¾¼ãéã«å¿ è¦ã«ãªãè¨å®ãè¨è¿°ããããªã·ã¼ãã¡ã¤ã«ï¼ããµã¤ãã®ããã¥ã¡ã³ãã«ã¼ãã«ç½®ããã¨ãã§ããªãå ´åãªã©ã«ãåæ§ã®å¹æãçºæ®ãããã¨ãã§ãã¾ãã
X-Permitted-Cross-Domain-Policies: master-only
- master-only ãã¹ã¿ã¼ããªã·ã¼ãã¡ã¤ã«ï¼ /crossdomain.xmlï¼ã®ã¿ã許å¯ããã
Strict-Transport-Security
æå®ããããµã¤ãã常㫠HTTPS ãããã³ã«ã使ã£ã¦ã¢ã¯ã»ã¹ããããã«ãã©ã¦ã¶ã«æ示ãã¾ããHTTPã®ãµã¤ãããHTTPSã«ãªãã¤ã¬ã¯ãããããå®å ¨ã«èªå°ããæ¹æ³ã§ãã
Strict-Transport-Security: max-age=31536000; includeSubDomains
- max-age STSãæå¹ã«ããæéãæ³å®ãããå訪åã®æéããéãã«é·ãç®ã«è¨å®ããæ¹ããã
- includeSubDomains ãµããã¡ã¤ã³ã«ãã«ã¼ã«ãé©ç¨ããã
HTTP Strict Transport Security - The Chromium Projects
HTTP Strict Transport Security - Security | MDN
Access-Control-Allow-Origin ãªã© CORS é¢é£
XMLHttpRequestã使ã£ã¦ãä»ã®ãã¡ã¤ã³ãªã©ãããªã½ã¼ã¹ãåå¾ãããã¯ãã¹ãã¡ã¤ã³éä¿¡ããããå ´åã«æå®ãã¾ãã使ãå ´åã«ã¯è©³ããã¯CORS (Cross-Origin Resource Sharing)å§åãªã©ãåèã«ãã¦ä¸ããã
Access-Control-Allow-Origin: http://www.example.com
Access-Control-Allow-Methods: POST, GET, OPTIONS
Access-Control-Allow-Headers: X-TRICORDER
Access-Control-Max-Age: 1728000
ä¸è¨ã¯ "http://www.example.com" ããã®ã¯ãã¹ãã¡ã¤ã³éä¿¡ããããå ´åã®è¨å®ã§ãå½è©²ãªã½ã¼ã¹ã¸ã®åãåããã«ã¯ POST, GET, OPTIONS ãå®è¡å¯è½ãªã¡ã½ãããã«ã¹ã¿ã ãããã¼ã¨ã㦠"X-TRICORDER" ãä»ãããªã¯ã¨ã¹ããéä¿¡ããããªãã©ã¤ãã®ã¬ã¹ãã³ã¹ããã£ãã·ã¥ãã¦ããæéã 1,728,00 ç§ã ã¨ãããã¨ã表ãã¦ãã¾ãã
HTTP access control (CORS) | MDN
X-Download-Options
ã¦ã¼ã¶ã¼ããã¦ã³ãã¼ããããã¡ã¤ã«ãç´æ¥"éã"ãã¨ãé²æ¢ãããå ´åã«æå®ãã¾ãã
X-Download-Options: noopen
- noopen IE8以éã§ã¯ã¦ã¼ã¶ã¼ã¯ãã¡ã¤ã«ãç´æ¥éããã¨ãã§ããããã¼ã«ã«ã«ä¿åãããã¨ã«ãªãã¾ãããã¦ã³ãã¼ãã®ãã¤ã¢ãã°ãã"éã"ããªããªãã¾ãã
IE8 Security Part V: Comprehensive Protection - IEBlog - Site Home - MSDN Blogs
Set-Cookie
Cookie ãã»ãããã¾ãããµã¼ãã¼ãã¯ã©ã¤ã¢ã³ãã«å¯¾ãã¦ç¶æ 管çãå§ããéãªã©ã«ãã¾ãã¾ãªæ å ±ãä¼ãã¾ãã
- secure HTTPSã§éä¿¡ãã¦ããå ´åã«ã®ã¿ Cookie ãéä¿¡ãã
- HttpOnly Cookie ã JavaScript ããã¢ã¯ã»ã¹ã§ããªãããã«ãã
- path å±æ§ã¯ Cookie ãéåºãããã£ã¬ã¯ããªãéå®ããæå®ã§ãããåé¿ããæ¹æ³ãããã»ãã¥ãªãã£æ©æ§ã¨ãã¦ã¯æå¾ ã§ãã¾ããã
- domain å±æ§ã¯å¾æ¹ä¸è´ã«ãªãã¾ããæ示çã«è¤æ°ãã¡ã¤ã³ã«å¯¾ã㦠Cookie ãéåºããå ´åãé¤ãã¦ããã®å±æ§ã¯è¨å®ããªãæ¹ãå®å ¨ã§ãã
Cache-Control
ãã£ã¬ã¯ãã£ãã¨å¼ã°ããã³ãã³ããæå®ãããã¨ã§ããã©ã¦ã¶ã®ãã£ãã·ã³ã°åä½ãæå®ãã¾ãã
Cache-Control: no-cache, no-store, must-revalidate
- no-cache ãã£ãã·ã¥ãµã¼ãã¼ã¯ãªã½ã¼ã¹ãæ ¼ç´ãã¦ã¯ãªããªããã¾ãæå¹æ§ã®å確èªãªãã§ã¯ãã£ãã·ã¥ã使ç¨ãã¦ã¯ãªããªã
- no-store ãã£ãã·ã¥ã¯ãªã¯ã¨ã¹ãã»ã¬ã¹ãã³ã¹ã®ä¸é¨åããã¼ã«ã«ã¹ãã¬ã¼ã¸ã«ä¿åãã¦ã¯ãªããªã
- must-revalidate ãã£ãã·ã¥å¯è½ã§ãããããªãªã¸ã³ãµã¼ãã¼ã«ãªã½ã¼ã¹ã®å確èªãè¦æ±ãã
pragma
HTTP/1.0ã¨ã®å¾æ¹äºææ§ã®ããã ãã«å®ç¾©ããã¦ãããããã¼ãã£ã¼ã«ãã§ãæ¬æ¥ã¯ã¯ã©ã¤ã¢ã³ãããã®ãªã¯ã¨ã¹ãã®ã¿ã«ä½¿ç¨ããã¾ãã"Cache-Control: no-cacheâã¨ä½µè¨ããã¨ããã§ãããã
pragma: no-cache
- no-cache ã¯ã©ã¤ã¢ã³ãããã¹ã¦ã®ä¸éãµã¼ãã¼ã«å¯¾ãã¦ããã£ãã·ã¥ãããå¿çãæã¾ãªããã¨ãè¦æ±ãã
expires
ãªã½ã¼ã¹ã®æå¹æéã®æ¥æãä¼ãã¾ãããã£ãã·ã¥ããããã¨ãæã¾ãªãå ´åã«ã¯ãDate ãããã¼ãã£ã¼ã«ãã®å¤ã¨åãã«è¨å®ãããã"-1"ã¨è¨å®ãã¾ãã
expires: -1
content-type
ã¨ã³ãã£ãã£ããã£ã«å«ã¾ãããªãã¸ã§ã¯ãã®ã¡ãã£ã¢ã¿ã¤ããä¼ãã¾ããcharsetã§ã¯æåã»ãããæå®ãã¾ããæ£ããã¡ãã£ã¢ã¿ã¤ãã®è¨å®ã¨ãæ£ããæåã³ã¼ããæ£ãã表è¨ã§è¨å®ãã¾ãããã
content-type: text/html;charset=utf-8
HTTPã¬ã¹ãã³ã¹ãããã¼ã®è¨å®ã®ä»æ¹
Apache ã§è¿½å ããå ´åã«ã¯ãhttpd.conf ã®ä¸ã§ä¸è¨ã®ã¢ã¸ã¥ã¼ã«ãæå¹ã«ãªã£ã¦ããå¿ è¦ãããã¾ãã
- LoadModule headers_module modules/mod_headers.so
常ã«è¡¨ç¤ºãã HTTP ã¬ã¹ãã³ã¹ãããã¼ã追å ããã«ã¯ãä¸è¨ã®ããã«è¨å®ãè¡ãã¾ãã
Header set HeaderFieldName "value"
Header set X-XSS-Protection "1; mode=blockâ
ã¿ã¤ãã«ã¯ãæèã今夜わかるHTTPãããã§ããããHTTPの教科書ãã®æ¹ãæ°ããæ¬ã§ããã¾ããã»ãã¥ãªãã£ç·¨ã¨ãã¦ã¾ãããã¶ãå®çµã§ãã2ã«ç¶ããâ¦ï¼
ãæè¦ãªã©ãå¾
ã¡ãã¦ãã¾ãããã®ãã¡ OWASP Japan ã® OWASP Night ã§ãç´¹ä»ããããã
- HTTPã®æç§æ¸
- çºå£²å : ç¿æ³³ç¤¾
- ä¾¡æ ¼: ï¿¥ 2,730
- çºå£²æ¥: 2013/05/25
追è¨
2013/12/01 "Access-Control-Allow-Origin"ãªã©CORSé¢é£ã"X-Download-Options"ã追è¨ãã¾ããããã®ä»èª¬æã微修æ£ãã³ã¡ã³ãé ãã @hasegawayosuke ããã@kinugawamasato ããã@ockeghem ããã@hirayasu ãããããã¨ããããã¾ãã
ã¯ã¬ã¸ããã«ã¼ãã®ã»ãã¥ãªãã£ã³ã¼ãã®ä¿åã¯ç¦æ¢
ç§ãæµ·å¤ã§ãã使ã£ã¦ããã¤ã¢ãã®Wi-FiãGLOBALDATAãã®Webãµã¼ãã¼ã«ä¸æ£ã¢ã¯ã»ã¹ãããã調æ»ã®çµææ大146,701件ã®ã¯ã¬ã¸ããã«ã¼ãæ å ±ãå«ãæ å ±æ¼ããããã£ããã¨ãå¤æãã¦ãã¾ãã
ãªãªã¼ã¹ã«ããã¨æ¼ããããæ å ±ã¯ä¸è¨ã®éãã¨ããã®æ å ±ãæãã°å¤§åã®ãµã¤ãã®ãªã³ã©ã¤ã³æ±ºæ¸ã§å©ç¨ã§ããã§ãããã
- ã«ã¼ãå義人å
- ã«ã¼ãçªå·
- ã«ã¼ãæå¹æé
- ã»ãã¥ãªãã£ã³ã¼ã
- ãç³è¾¼è ä½æ
ãã®ä¸ã®ãã»ãã¥ãªãã£ã³ã¼ããã§ãããããã¯VISAãMasterã§ã¯ãCVVãããCV2ããªã©ã¨å¼ã°ãã¦ããä¸æ£ä½¿ç¨é²æ¢ã®ããã®çªå·ã§ãã«ã¼ãã®è£é¢ãªã©ã«è¨è¼ããã¦ãããã®ã§ãã
ãã®ãã»ãã¥ãªãã£ã³ã¼ããã¯ã«ã¼ãã«è¨è¼ãããçªå·ã確èªãããã¨ã§ãã«ã¼ãã®å®ç©ãæã£ãææè
ã§ãããã¨ã確ãããã»ãã¥ãªãã£å¯¾çãªã®ã§ããªã³ã©ã¤ã³æ±ºæ¸ããã¦ããå çåºã®Webãµã¼ãã¼ãä¿åãã¦ã¯ããã¾ããã
JCCA æ¥æ¬ã¯ã¬ã¸ããã«ã¼ãåä¼ãå®ãããæ°è¦ã¤ã³ã¿ã¼ãããå çåºã«ãããã¯ã¬ã¸ããã«ã¼ã決æ¸ã«ä¿ãæ¬äººèªè¨¼å°å ¥ã«ããä¸æ£ä½¿ç¨é²æ¢ã®ããã®ã¬ã¤ãã©ã¤ã³ãã«ããå çåºã«ã¦ã»ãã¥ãªãã£ã³ã¼ããä¿åãããã¨ã¯ãç¦æ¢ããããã¨ããä¸æãããã¾ãã
ã»ãã¥ãªãã£ã³ã¼ããä¿åããå®è£ ã«ãã¦ãããªã³ã©ã¤ã³æ±ºæ¸ãµã¤ãã¯ããã«ã§ãä¿®æ£ãã¾ããããã¾ããä¸è¨ã¬ã¤ãã©ã¤ã³ã«ããã3Dã»ãã¥ã¢ãªã©ã®æ¬äººèªè¨¼ãå°å ¥ãã¹ãã§ãããã
ããã«ãã¦ããã¨ã¯ã¹ã³ã ã°ãã¼ãã«ç¤¾ã¯ä¸æ£ã¢ã¯ã»ã¹ã®ä»¶ã4æ23æ¥ããææ¡ãã¦ãã¦èª¿æ»ãã¦ããããã§ãããçºè¡¨ã5æ27æ¥ã¨ããªãé ãã§ããã
ç§ã被害è ã§ãããããã¾ã§ã®æ å ±ãæ¼ããããã¨ã¯ã¬ã¸ããã«ã¼ãçªå·ã¯åçºè¡ã«ãªãããããã¾ãããâ¦ãæè¿åæã§æ¼ããäºä»¶ã®è¢«å®³è ã¨ãã¦ããããã¦ãã¾ããããã®ãã³ã«ã¯ã¬ã¸ããã«ã¼ãçªå·ãå¤æ´ã¨ãã«ãªãã¨ãããããªãµã¤ãã®æ±ºæ¸æ å ±ãå¤æ´ããªããã°ãããªãã¦æ¬å½ã«ããã©ããããã§ããã
Webã«é¢ãã人ã®ããã®ãHTTPã®æç§æ¸ããçºå£²
ã²ãã³ãã®åèã¨ãªããHTTPã®æç§æ¸ãã2013å¹´5æ24æ¥ã«çºå£²ã«ãªãã¾ãã
å
容ã¯ã¿ã¤ãã«ã®éããWebã«é¢ããå
¨ã¦ã®äººã«æ§ããHTTPãå¦ã¶ããã®æç§æ¸ã§ããåºç¤ãå¦ã³ããåå¿è
ã®æ¹ãããæºã®ä¸ã«ç½®ãã¦ãªãã¡ã¬ã³ã¹çã«ä½¿ãããæ¹ã¾ã§ã対象ã¨ãã¦ãã¾ãã
- HTTPã®æç§æ¸
- çºå£²å : ç¿æ³³ç¤¾
- ä¾¡æ ¼: ï¿¥ 2,730
- çºå£²æ¥: 2013/05/25
HTTPé¢é£ã®æ¸ç±ã¯ãä»å¤ãããHTTP (Network)ãã¨ããã¿ã¤ãã«ã®æ¬ã2004å¹´ã«åºãã¦ãã¾ãããã®é ããHTTP/1.1ã主æµã§ããã¨ããã®ã¯ãä»ã§ãå¤ããã¾ããããããåãå·»ãç°å¢ã¨ããã®ã¯å¤ããã¤ã¤ããã¾ãã
HTTPãå¦ã¶ä¸ã§ã®è¦ç¹ããããããããããã¦èªã¿ããããªã£ã¦ããã¾ããåä½ã®ãªãã¥ã¼ã¢ã«ã£ã½ãæãããã¨æãã¾ããã9å²ä»¥ä¸ã¯æ¸ãç´ãã追è¨ãã¦ããã¾ãã
ã¾ããã¬ãã¥ã¼ã¢ã¨ãã¦ãMasato Kinugawaãããå±±å´åå¾ããããããã¨ã¼ã¸ã§ã³ãæ ªå¼ä¼ç¤¾ã¯ããããããããããªã©ããè¿ããã¦ãããããä¸åã¨ãªã£ã¦ããã¾ãã
以ä¸ã¯æ¬æ¸ã®ç®æ¬¡ã«ãªãã¾ãã
第1ç« ãWeb ã¨ãããã¯ã¼ã¯ã®åºæ¬ãç¥ãã
1.1 Web ã¯HTTP ã§è¦ãã¦ãã
1.2 HTTP ã¯ãããã¦çã¾ãè²ã£ã
ã1.2.1ãWeb ã¯ç¥èå
±ç¨ã®ããã«èæ¡ããã
ã1.2.2ãWeb ãæé·ããæ代
ã1.2.3ãé²æ©ããªãHTTP
1.3 ãããã¯ã¼ã¯ã®åºæ¬ã¯TCP/IP
ã1.3.1ãTCP/IP ã¯ãããã³ã«ç¾¤
ã1.3.2ãé層ã§ç®¡çããTCP/IP
ã1.3.3ãTCP/IP ã®éä¿¡ã®æµã
1.4 HTTPã¨é¢ä¿æ·±ããããã³ã« IPã»TCPã»DNS
ã1.4.1ãé
éãæ
å½ããIP
ã1.4.2ãä¿¡é ¼æ§ãæ
å½ããTCP
1.5 åå解決ãæ
å½ããDNS
1.6 ããããã¨HTTP ã®é¢ä¿
1.7 URIã¨URL
ã1.7.1ãURI ã¯ãªã½ã¼ã¹ã®èå¥å
ã1.7.2ãURI ã®ãã©ã¼ããã
ã
第2ç« ãã·ã³ãã«ãªãããã³ã«HTTP
ã³ãã³ãã©ã¤ã³ããç»é¢å ±æãONã«ããæ¹æ³ for OS X Mountain Lion
ã·ã¹ãã ç°å¢è¨å®ããONã«ããã°ãããã§ããã©ããªããã·ã¹ãã ç°å¢è¨å®ã®ããã¯ãå¤ããªããªã£ãã®ã§ãã³ãã³ãã©ã¤ã³ããå種è¨å®å¤æ´ã模索ãã¦ã¿ã¾ããã
ã³ãã³ãã©ã¤ã³ããç»é¢å
±æãONã«ããã«ã¯ãä¸è¨ã®ã³ãã³ããã¿ã¼ããã«ããå®è¡ãã¾ãã
# sudo defaults write /var/db/launchd.db/com.apple.launchd/overrides.plist com.apple.screensharing -dict Disabled -bool false # sudo launchctl load /System/Library/LaunchDaemons/com.apple.screensharing.plist
ssh ã¨ãã§ãONã«ã§ããã®ã§ã人ã«ãã£ã¦ã¯ä¾¿å©ãããåä½ã¯ OS X Mountain Lionï¼10.8.3ï¼ ã§ç¢ºèªãã¾ããã