
ã©ãºãã¤ã¨AWSã§è©¦ãã»ãã¥ãªãã£æ¤è¨¼ç°å¢æ§ç¯ï¼åç·¨ï¼
ã¯ããã«
æè¿ã®ãã¸ã¿ã«æ¥çã«ããã¦ãArmã«é¢ãã話é¡ã¸ã®æ³¨ç®åº¦ãé«ã¾ã£ã¦ãã¾ãã
以åããã¹ãã¼ããã©ã³ãã¿ãã¬ãã端æ«åãã«ã¯Armãæ¡ç¨ããã¦ããããã身è¿ã«ãArmã¯åå¨ãã¦ãã¾ãããã§ããããã¾ã§ã¯ã©ã¡ããã¨ããã°ãã®çé»åããªã©ãããArmã¯çµã¿è¾¼ã¿ç¨éãå°å端æ«åãã®ãã®ãã¨ããã¤ã¡ã¼ã¸ã§ããã
ããããã®1ï½2å¹´ã»ã©ã®éã«ãã¢ããã«ç¤¾ããã¯Armã¢ã¼ããã¯ãã£ã®M1ã·ãªã¼ãºã®ããããæè¼ããMacãiPadããMicrosoft社ããã¯Armçã®Windows OSãArmã¢ã¼ããã¯ãã£ã®Microsoft SQ1/SQ2ããã¾ããAWSãããåæ§ã«Armã¢ã¼ããã¯ãã£ã®AWS Gravitonã·ãªã¼ãºãå©ç¨ãããµã¼ãã¹ããªãªã¼ã¹ããããªã©å社ã¨ãArmã®æ¡ç¨ãé²ã¿ãçé»åæ§è½ã ãã§ã¯ãªãå¦çæ§è½ã®é¢ã§ãæå¾
ãé«ã¾ã£ã¦ãã¾ãã
ã¨ã¯ãããããã¾ã§ã®ã¤ã¡ã¼ã¸ãããArmã¯ä½¿ãã«ããã®ã§ã¯ï¼ãããã¯ã¼ã¯ããã¼ãArmãã¼ã¹ã«å¤æ´ããã«ã¯ã¾ã æ©ãããªï¼ããªã©ã®å°è±¡ãæã£ã¦ããæ¹ãããã£ããããã¨æãã¾ãã
ãã®ããæ¬ã³ã©ã ã§ã¯ãæè¿ã®ã·ã¹ãã éçºã§å©ç¨ããããã¨ãå¤ãVS CodeãDockerãªã©ãArm端æ«ã«ã¤ã³ã¹ãã¼ã«ãã¦å®è¡ãã¦ã¿ããã¨æãã¾ããArm端æ«ã«ã¯æ¯è¼çå®ä¾¡ãªRaspberry Piã使ç¨ããã¾ãä½µãã¦AWSã®ã¯ã©ã¦ããµã¼ãã¹ãå©ç¨ãã¾ããããã¦ããããã使ã£ã¦ã»ãã¥ãªãã£æ¤è¨¼ã«å©ç¨å¯è½ãªç°å¢ã®æ§ç¯ãè¡ãã¾ãã
æ¬ã³ã©ã ã®å
容ãå®è·µããã ããã¨ã«ãããArmã使ã£ãã·ã¹ãã ã(æå¤ã¨ï¼)æ´»ç¨ã§ãããã¨ãä½é¨ããã ãããã¨æãã¾ãã
æ¦è¦
- 1. ã´ã¼ã«
æ¬ã³ã©ã ã§ã¯ãArmç°å¢(Raspberry Pi)ã«ã¦ã»ãã¥ãªãã£æ¤è¨¼ç°å¢(OWASP Juice Shop)ã®æ§ç¯ãè¡ãããã®éç¨ã®ä¸ã§è¤æ°ã®ãã¼ã«ãªã©ã試ç¨ãã¦Armç°å¢ãä½é¨ããã ããã¨ãç®çã¨ãã¦ãã¾ãã - 2. ä½¿ç¨æ©æãªã©
- âRaspberry Pi (æ¬ä½)
æ¬ã³ã©ã ã®å å®¹ã¯æ¬¡ã®æ©ç¨®ã§åä½ç¢ºèªãè¡ãªã£ã¦ãã¾ãã- ã»Raspberry Pi 400
- ã»Raspberry Pi 4(4GB)
- âmicroSDã«ã¼ããªã©ã®OSã¤ã³ã¹ãã¼ã«ç¨ã¹ãã¬ã¼ã¸
Raspberry Piã®OSãã¤ã³ã¹ãã¼ã«ããããã®ã¹ãã¬ã¼ã¸ãç¨æãã¾ãã
ç¾å¨ãRaspberry Piã¯microSDã ãã§ã¯ãªããRaspberry Piæ¬ä½ã®USBã«æ¥ç¶ããUSBã¡ã¢ãª/HDD/SSDãªã©å種ã¹ãã¬ã¼ã¸ããOSãèµ·åãããã¨ãå¯è½ã«ãªã£ã¦ãã¾ããæ¬ã³ã©ã ã®å 容ãã¨ãããã試ãã ãã§ããã°ãç¹ã«ã©ã®ã¹ãã¬ã¼ã¸ã§ããã ããå¿ è¦ã¯ããã¾ãããã容éã¨ãã¦ã¯32GBã256GBç¨åº¦ã®ãã®ã使ãããããã¨æãã¾ã(容éã大ããã¨ååèµ·åæã«æéãããããã)ã
ããå¯è½ã§ããã°ãmicroSDã«ã¼ãã®å ´åã¯A1è¦æ ¼å¯¾å¿ã®ãã®ããUSBæ¥ç¶ããã¹ãã¬ã¼ã¸ã使ç¨ããå ´åã¯SSDããã¹ã¹ã¡ã§ããâ»ã注æ
ã¹ãã¬ã¼ã¸ã¯OSæ¸ãè¾¼ã¿æã«å å®¹ãæ¶å»ããããããå¿ è¦ã«å¿ãã¦äºåã«ããã¯ã¢ãããã¨ããããæ³¨æãã ããã - âWindows 10 PC
Raspberry Piã§ä½¿ç¨ããOSãæºåããããã«ä½¿ç¨ãã¾ãããã®ãããmicroSDã«ã¼ããªã©ä¸è¿°ã®OSã¤ã³ã¹ãã¼ã«ã«ä½¿ç¨ããã¹ãã¬ã¼ã¸ã®èªã¿æ¸ããã§ããã¤ã³ã¿ã¼ãããæ¥ç¶ãã¦OSã¤ã¡ã¼ã¸ã®ãã¦ã³ãã¼ããããã³ãOSã¤ã¡ã¼ã¸ã®ä¿åãã§ããã ãã®å®¹é(ç´2G)ã®ç¢ºä¿ãå¯è½ãªç«¯æ«ããç¨æãã ããã - âAWS
使ç¨ããAWSãµã¼ãã¹ã¨ãã®å½¹å²ã¯æ¬¡ã®ã¨ããã§ãã- ã»AWS CodeCommit
ããã¼ã¸ãåã®ãã©ã¤ãã¼ããªGit ãªãã¸ããªã§ããæ¤è¨¼ã«ä½¿ç¨ããDockerã¤ã¡ã¼ã¸ã®ããã®ã³ã¼ãä¸å¼ãä¿åãã¾ãã - ã»Amazon Elastic Container Registry(ECR)
AWSãæä¾ããã³ã³ãããµã¼ãã¹ã®ä¸ã¤ã§ããã«ãããDockerã¤ã¡ã¼ã¸ãä¿åãããã©ã¤ãã¼ããªã³ã³ãããªãã¸ããªã§ãã - ã»AWS CodeBuild
AWS CodeCommitã«ä¿åãããã³ã¼ãããã¨ã«ãã«ããã¾ãã
- ã»AWS CodeCommit
- âRaspberry Pi (æ¬ä½)
æ¬ã³ã©ã ã®å 容ãå®éã«è©¦ãå ´åã«ã¯AWSã¢ã«ã¦ã³ããå¿ è¦ã«ãªããããã¾ã AWSã¢ã«ã¦ã³ããä¿æãã¦ããªãå ´åã¯AWSãµã¤ãã®æé (â»)ã«å¾ãã¢ã«ã¦ã³ãã使ãã¦ãã ããã
â» AWS ã¢ã«ã¦ã³ãä½æã®æµã(https://aws.amazon.com/jp/register-flow/)
ç°å¢
使ç¨ãã主ãªOSããã¼ã«ã¨ãã®ãã¼ã¸ã§ã³ã¯æ¬¡ã®ã¨ããã§ãã
- âKali linux 2022.1
- âRaspberry Pi Imager 1.7.1
- âAWS CLI 2.4.29
- âVisual Studio Code 1.65.2
- âOWASP Juice Shop 13.2.2
宿½æé
次ç¯ãã以ä¸ã«ç¤ºãã¹ãããã§é²ãã¾ãããåå(1ã3)ã¯OSã®ã¤ã³ã¹ãã¼ã«ãç°å¢æ§ç¯ãªã©ã®å
容ãä¸å¿ã®ãããæ¢ã«èªèæ¸ã¿ã®å
容ã®å ´åã¯é©å®èªã¿é£ã°ãã¦ãã ããã
å¾åã§ã¯æ¬ã³ã©ã ã§ä½¿ç¨ããOWASP Juice Shopãã«ã¹ã¿ãã¤ãºãããã¨ã念é ã«ãã¯ã©ã¦ã(AWS)ãæ´»ç¨ãã¦ããå¿«é©ã«ä½¿ç¨ããæ¹æ³ã試ãã¾ãã
ãªããåæé å
ã§ç»é¢ãã£ããã£ãªã©ãæ²è¼ãã¦ãã¾ãããããã¯ã³ã©ã å·çæç¹ã®ãã®ã«ãªãã¾ããäºããäºæ¿ãã ããã
- 1.Raspberry Piã¸ã®Kali Linuxã®ã¤ã³ã¹ãã¼ã«
- 2.Kali Linuxä¸ã®ç°å¢æ§ç¯
- 3.ã³ã³ããã§ã®OWASP Juice shopã®èµ·å
- 4.AWSä¸ã§Dockerã¤ã¡ã¼ã¸ã®ãã«ã
- 5.ãã«ãããã¤ã¡ã¼ã¸ã®Raspberry Piä¸ã§ã®å®è¡
1. Raspberry Piã¸ã®Kali Linuxã®ã¤ã³ã¹ãã¼ã«
â ã¤ã¡ã¼ã¸å ¥æããKali Linuxèµ·åã¾ã§
æ¬ã³ã©ã ã§ã¯ãã»ãã¥ãªãã£ã«é¢ãããã¼ã«é¡ãäºãç¨æããã¦ããKali Linux(以éãKali)ãRaspberry Piã«ã¤ã³ã¹ãã¼ã«ãã¦ä½¿ç¨ãã¾ãããã®ãããå ãã¯Kaliã®ã¤ã³ã¹ãã¼ã«æé ã示ãã¾ã(æ¬æé ã«ã¤ãã¦ã¯Windows 10 PCã使ç¨ãã¦ãã¾ã)ã
次ã®URLããKaliã®ã¤ã¡ã¼ã¸ããã¦ã³ãã¼ããã¾ãã
https://www.kali.org/get-kali/#kali-arm
ã» Kaliã®ãã¦ã³ãã¼ã
使ç¨ããã¤ã¡ã¼ã¸ã¯æ¬¡ã®ã¨ããã§ãã
Raspberry Pi 2 (v1.2), 3, 4 and 400 (64-Bit)
ã¤ã¡ã¼ã¸ã®ãã¦ã³ãã¼ãå®äºå¾ãã¹ãã¬ã¼ã¸ã¸Kaliã®æ¸ãè¾¼ã¿ãè¡ãã¾ãã
ã¤ã¡ã¼ã¸ã®æ¸ãè¾¼ã¿ã«ã¯ãRaspberry Piå
¬å¼ã®ãRaspberry Pi ImagerããããRufusãããbalena Etcherããªã©ã®ãã¼ã«ãå©ç¨å¯è½ã§ããããã§ã¯ãRaspberry Pi Imagerãã使ç¨ãã¦æ¸ãè¾¼ã¿ãè¡ãã¾ã(ä¸å³åç
§)ã
次ã®URLãããRaspberry Pi Imagerãããã¦ã³ãã¼ããã¾ãã
https://www.raspberrypi.com/software/
ã» Raspberry Pi Imagerã®ãã¦ã³ãã¼ã
ãã¦ã³ãã¼ãå®äºå¾ããRaspberry Pi Imagerããèµ·åãã¾ãã
ã» Raspberry Pi Imagerã®èµ·å
ãCHOOSE OSããã¿ã³ãæ¼ä¸ãã¾ãã
ã» ã¹ãã¬ã¼ã¸ã«æ¸ãè¾¼ãOSã¤ã¡ã¼ã¸ã®é¸æ
ã¡ãã¥ã¼ã®ä¸é¨ã«ãããUse customãã鏿ããåã®æé ã«ã¦ãã¦ã³ãã¼ãããKaliã®ã¤ã¡ã¼ã¸ãæå®ãã¾ãã
ã» æ¸ãè¾¼ãã¹ãã¬ã¼ã¸ã®é¸æ
ãCHOOSE STORAGEããã¿ã³ãæ¼ä¸ããKaliã®ã¤ã¡ã¼ã¸ãæ¸ãè¾¼ãã¹ãã¬ã¼ã¸ã®ãã©ã¤ããæå®ãã¾ãã
ãã©ã¤ãæå®å¾ããWRITEããã¿ã³ãæ¼ä¸ãããã¨ã«ãããæ¸ãè¾¼ã¿å¦çãå®è¡ããã¾ãã
æ¸ãè¾¼ã¿å®äºå¾ããã®ã¹ãã¬ã¼ã¸ã使ç¨ãã¦Raspberry Piãèµ·åãã¾ãã
ååèµ·åæã¯åæåå¦çã®ãã使ç¨ãã¦ããã¹ãã¬ã¼ã¸ã®é度ã容éã«ãã£ã¦ã¯èµ·åå®äºã¾ã§æéãããããã¨ãããã¾ãã
èµ·åããã¨ãã°ã¤ã³ç»é¢ã表示ããã¾ãã®ã§ã次ã®ã¦ã¼ã¶ã¼IDã¨ãã¹ã¯ã¼ãã§ãã°ã¤ã³ãã¾ãã
ã¦ã¼ã¶ã¼IDï¼kali
ãã¹ã¯ã¼ãï¼kali
ã» Kaliãã¹ã¯ããã
以éã«ã¯ã³ãã³ãå®è¡ã®æé ãããã¾ãããã³ãã³ãå®è¡ã¯Kaliã®ãã¹ã¯ãããç»é¢å·¦ä¸ã«ãããã¿ã¼ããã«ãããè¡ããã¨ãå¯è½ã§ãã
ã¤ã³ã¿ã¼ãããã«æ¥ç¶ããTerminalãèµ·åãã¦Kaliãã¢ãããã¼ããã¾ãã
ã¢ãããã¼ãã¯ãããã¯ã¼ã¯ã®ç¶æ³çã«ãããã¾ããå¤å°æéãããããããæ³¨æãã ãã(æ¬ã³ã©ã å·çæã«ã¯20å以ä¸ãããã¾ããâ¦)ã
ã» Kaliã®ã¢ãããã¼ã
âââ(kaliã¿kali-raspberry-pi)-[~] ââ$ sudo apt update âââ(kaliã¿kali-raspberry-pi)-[~] ââ$ sudo apt full-upgrade -y
åèï¼https://www.kali.org/docs/general-use/updating-kali/
2. Kali Linuxä¸ã§ã®ç°å¢æ§ç¯
Kaliã®ã¤ã³ã¹ãã¼ã«ãçµäºãããããå¼ãç¶ãå種ã®ãã¼ã«é¡ã®ã¤ã³ã¹ãã¼ã«ãããã³ã以éã®æé ã«ã¦ä½¿ç¨ããã½ã¼ã¹ã³ã¼ãã®ãã¦ã³ãã¼ããè¡ãã¾ãã
â Dockerã¤ã³ã¹ãã¼ã«
Kaliã«ãããDockerã®ã¤ã³ã¹ãã¼ã«ã¯æ¬¡ã®ã³ãã³ããå®è¡ãã¾ãã
âââ(kaliã¿kali-raspberry-pi)-[~] ââ$ sudo apt install -y docker.io âââ(kaliã¿kali-raspberry-pi)-[~] ââ$ sudo systemctl enable docker --now âââ(kaliã¿kali-raspberry-pi)-[~] ââ$ docker
以ä¸ã§Dockerã®ã¤ã³ã¹ãã¼ã«ã¯å®äºã§ããããã®ã¾ã¾ã§ã¯Dockerã³ãã³ããå®è¡ããéã«sudoãå¿ è¦ã§ããsudoãªãã§Dockerã³ãã³ãã使ç¨ããå ´åã¯ã次ã®ã³ãã³ããå®è¡ãã¾ãã
âââ(kaliã¿kali-raspberry-pi)-[~] ââ$ sudo usermod -aG docker $USER
ã³ãã³ãå®è¡å¾ããã°ã¢ã¦ãããå度ãã°ã¤ã³ãã¦ãã ããã以éã¯sudoãªãã§Dockerã³ãã³ãã®å®è¡ãå¯è½ã§ãã
åèï¼https://www.kali.org/docs/containers/installing-docker-on-kali/
â Visual Studio Codeã¤ã³ã¹ãã¼ã«
次ã®URLããVisual Studio Code(以ä¸ãVS Code)ããã¦ã³ãã¼ããã¾ãã
https://code.visualstudio.com/#alt-downloads
ãã¦ã³ãã¼ã対象ã¯ãã.debãã® ARM 64ã«ãªãã¾ãã
ãã¦ã³ãã¼ãå®äºå¾ã次ã®ã³ãã³ããå®è¡ãã¦ã¤ã³ã¹ãã¼ã«ãã¾ãã
ã» ã¤ã³ã¹ãã¼ã«ã³ãã³ã
âââ(kaliã¿kali-raspberry-pi)-[~]
ââ$ sudo apt install ./<file>
<file>ã«ã¯ãã¦ã³ãã¼ããããã¡ã¤ã«åãæå®ãã¦ãã ããã
ä¾ï¼ sudo apt install ./code_1.65.2-1646922911_arm64.deb
ã¤ã³ã¹ãã¼ã«ãå®äºããã¨ãKaliã®ãã¹ã¯ãããã®ç»é¢å·¦ä¸ã«ãããApplicationsãã¢ã¤ã³ã³ãªã©ããVS Codeãèµ·åã§ãã¾ãã
æ¬¡ã«æ¥æ¬èªåãè¡ãã¾ãã
VS Codeã®å·¦å´ã«ããActivity BarããVS CodeExtensionsã¢ã¤ã³ã³ã鏿ãããJapanese Language Pack for Visual Studio Codeããã¤ã³ã¹ãã¼ã«ãã¾ããã¤ã³ã¹ãã¼ã«å¾ãVS Codeãåèµ·åããæ¥æ¬èªåããã¦ãããã¨ã確èªãã¾ãã
以éãå種ã®ã³ãã³ãå®è¡ã«ã¤ãã¦ã¯VS Codeã®çµ±åã¿ã¼ããã«(VS Codeä¸ã§Ctrl + ã`ããã¼ãæ¼ä¸ããã¨è¡¨ç¤ºããã¾ã)ãå©ç¨å¯è½ã§ãã
ããã¾ã§åæ§ã«Kaliã®ã¿ã¼ããã«ã使ç¨ããã ãã¦ãåé¡ããã¾ããã®ã§ã使ããããæ¹ã§é²ãã¦ãã ããã
â AWS CLIã®ã¤ã³ã¹ãã¼ã«
AWSãã³ãã³ãã©ã¤ã³ãã使ç¨ããããã®ãã¼ã«ã§ããAWS CLIãã¤ã³ã¹ãã¼ã«ãããããæ¬¡ã®ã³ãã³ããå®è¡ãã¾ãã
âââ(kaliã¿kali-raspberry-pi)-[~] ââ$ curl "https://awscli.amazonaws.com/awscli-exe-linux-aarch64.zip" -o "awscliv2.zip" âââ(kaliã¿kali-raspberry-pi)-[~] ââ$ unzip awscliv2.zip âââ(kaliã¿kali-raspberry-pi)-[~] ââ$ sudo ./aws/install
ãã¼ã«ã®ä½¿ç¨ã«éãã¦ã¯ã¢ã¯ã»ã¹ãã¼æ å ±ãªã©ã®è¨å®ãå¿ è¦ã¨ãªãã¾ããå¾ã»ã©å¿ è¦ã¨ãªã£ãã¿ã¤ãã³ã°ã§å®æ½ãã¾ãã
åèï¼Installing or updating the latest version of the AWS CLI
https://docs.aws.amazon.com/ja_jp/cli/latest/userguide/getting-started-install.html
â ã½ã¼ã¹ã³ã¼ãã®ãã¦ã³ãã¼ã
次ã®ã³ãã³ããå®è¡ããOWASP Juice Shopã®ã½ã¼ã¹ã³ã¼ãããã¦ã³ãã¼ããã¾ããâmy-juice-shopâã¯ä»»æã®ãã©ã«ãã¼åãæå®ãã¦ãã ããã
âââ(kaliã¿kali-raspberry-pi)-[~]
ââ$ git clone https://github.com/bkimminich/juice-shop.git my-juice-shop
VS Codeãèµ·åããOWASP Juice Shopã®ãã©ã«ãã¼ãéãã¾ãã
æ¬ã³ã©ã å ã§ã¯ã½ã¼ã¹ã³ã¼ãã®é²è¦§ãã³ãã³ãã®å®è¡ã«ã¯VS Codeã使ç¨ãã¾ããä»ã®ã¨ãã£ã¿çãä½¿ãæ £ãã¦ããæ¹ã¯ãã¡ãã使ç¨ããã ãã¦åé¡ããã¾ããã
3. ã³ã³ããã§ã®OWASP Juice shopã®èµ·å
æ¬ã¹ãããã§ã¯Raspberry Piä¸ã®Dockerã§ã以ä¸ã®2ã¤ã®æ¹æ³ã使ç¨ãã¦OWASP Juice Shopãèµ·åãããããããã®æ¹æ³ã®ã¡ãªããï¼ãã¡ãªããã確èªãã¾ãã
- 1.Docker HubããOWASP Juice Shopã®Dockerã¤ã¡ã¼ã¸ãåå¾ãã¦å®è¡ãã
- 2.OWASP Juice Shopã®ã½ã¼ã¹ã³ã¼ãããDockerã¤ã¡ã¼ã¸ããã«ããã¦å®è¡ãã
ãªããæ¬ã¹ãããã®å 容ã¯ç¹ã«å®è¡ããã¨ã次ã®ã¹ãããã«å½±é¿ã¯ããã¾ãããå®è¡ã«ã¯å¤å°æéãè¦ãããã(ç°å¢ã«ãã£ã¦ã¯è¨30å以ä¸)ãåèç¨åº¦ã«çµæã ãããã§ãã¯ãã¦æ¬¡ã«é²ãã¦ããã ãã¦åé¡ããã¾ããã
1. Docker HubããOWASP Juice Shopã®Dockerã¤ã¡ã¼ã¸ãåå¾ãã¦å®è¡ãã
OWASP Juice Shopã®Dockerã¤ã¡ã¼ã¸ã¯Docker Hubã«ç»é²ããã¦ãããããdocker pullã§åå¾ãããã¨ãå¯è½ã§ãã
ãã¤ã³ãã¨ãã¦ãRaspberry Piä¸ã§åä½ããArmçã®ã¤ã¡ã¼ã¸ãåå¾ããå ´åã¯ã¿ã°ã®æå®(:latest-arm)ãå¿
è¦ã«ãªãã¾ããå®è¡ããã³ãã³ãã¯æ¬¡ã®ã¨ããã§ãã
ã» Armçã®Dockerã¤ã¡ã¼ã¸ã®åå¾
âââ(kaliã¿kali-raspberry-pi)-[~] ââ$ docker pull bkimminich/juice-shop:latest-arm
ã¤ã¡ã¼ã¸åå¾å¾ã次ã®ã³ãã³ããå®è¡ãããã¨ã§ãã©ã¦ã¶ããã¢ã¯ã»ã¹ãããã¨ãå¯è½ã§ã(ã¢ã¯ã»ã¹ããURL㯠http://localhost:3000 ã«ãªãã¾ã)ã
ã» åå¾ããDockerã¤ã¡ã¼ã¸ã®å®è¡
âââ(kaliã¿kali-raspberry-pi)-[~] ââ$ docker run --rm -p 3000:3000 bkimminich/juice-shop:latest-arm
2. OWASP Juice Shopã®ã½ã¼ã¹ã³ã¼ãããDockerã¤ã¡ã¼ã¸ããã«ããã¦å®è¡ãã
åã¹ãããã«ã¦ãã¦ã³ãã¼ãããOWASP Juice Shopã®ã½ã¼ã¹ã³ã¼ãããDockerã¤ã¡ã¼ã¸ããã«ããã¾ãã
ã» ã½ã¼ã¹ã³ã¼ããæ ¼ç´ãããã©ã«ãã¼ã¸ç§»åãããã«ãã³ãã³ããå®è¡
âââ(kaliã¿kali-raspberry-pi)-[~] ââ$ cd my-juice-shop âââ(kaliã¿kali-raspberry-pi)-[~/juice-shop] ââ$ docker build -f Dockerfile.arm . -t my-shop
â-tâãªãã·ã§ã³ã使ç¨ããã¤ã¡ã¼ã¸åã¨ãã¦âmy-shopâãä»ä¸ãã¦ãã¾ãããä»»æã®ã¤ã¡ã¼ã¸åãæå®ãã¦ããã ãã¦åé¡ããã¾ããã
ã» ãã«ãããDockerã¤ã¡ã¼ã¸ã®å®è¡
âââ(kaliã¿kali-raspberry-pi)-[~/juice-shop]
ââ$ docker run --rm -p 3000:3000 my-shop
å®è¡å¾ã1ã¨åæ§ã« http://localhost:3000 ã«ã¢ã¯ã»ã¹ãããã¨ã§OWASP Juice Shopãå©ç¨å¯è½ã§ãã
ã» OWASP Juice Shopèµ·åã¤ã¡ã¼ã¸
OWASP Juice Shopã¯ãã¾ãã¾ãªèå¼±æ§ãå«ãã Webã¢ããªã±ã¼ã·ã§ã³ã§ãããã¼ã«ã®æ¤è¨¼ãèå¼±æ§ã®çè§£ã®ããã®å¦ç¿ç°å¢ã¨ãã¦ãå©ç¨ã§ãããé¡ãä½é£æåº¦ããé«é£æåº¦ã®ãã®ã¾ã§å¤æ°ç¨æããã¦ãããããã»ãã¥ãªãã£ã®åå¦è ã®æ¹ã§ãåãçµã¿ããããã®ã«ãªã£ã¦ãã¾ããããã¾ã 触ãããã¨ããªãå ´åã¯è²ã ã¨æä½ãã¦ã¿ãã¨ãããã¨æãã¾ãã
1ã®æ¹æ³ã¯å ¬å¼ã«ããæä¾ããããã«ãæ¸ã¿ã®ã¤ã¡ã¼ã¸ãå©ç¨ãããããå®è¡ã¾ã§ã«è¦ããæéã¯ã¤ã¡ã¼ã¸ã®ãã¦ã³ãã¼ãæéã大åã§ãããã®æ¹æ³ã¯pullå®è¡æã®ã¿ã°ããæ°ãä»ããã°ãããArmç°å¢ã§OWASP Juice Shopãæè»½ã«è©¦ãã«ã¯ç°¡åã§ããã®ã§ãããã«ã¹ã¿ãã¤ãºãããæéã§ãã
2ã®æ¹æ³ã¯ã½ã¼ã¹ã³ã¼ãããDockerã¤ã¡ã¼ã¸ããã«ããã¦å®è¡ãããããã«ã¹ã¿ãã¤ãº(ã½ã¼ã¹ã³ã¼ãã®ä¿®æ£)ã¯å®¹æã§ããã§ããããã«ãã«æéãè¦ãããã(â»1)ããã«ãä¸ã¯(ç¹ã«ã©ãºãã¤ãªã©ã®ãã·ã³ãã¯ã¼ãä½ãå ´å)å½è©²ç«¯æ«ã§ä»ã®ä½æ¥ãã§ããªãã»ã©è² è·ããããå ´åãããã¾ãã
ããã§ã次ã®ã¹ãããã§ã¯ã¯ã©ã¦ã(AWS)ãæ´»ç¨ãããã·ã³ãã¯ã¼ãå¿ è¦ã¨ãããã«ã使¥(â»2)ãAWSä¸ã§å®è¡ããã¤ãDockerã¤ã¡ã¼ã¸ãAWSä¸ã«æ ¼ç´ãããã¨ã§ã1ã2ã®ããããã®æ¹æ³ã®è¯ãç¹ãæ´»ããããã¨æãã¾ãã
â»1ï¼ä»åã®ã±ã¼ã¹ã§ã¯å½æ¹ã®ç°å¢ã§ååã®ãã«ãã¯30å以ä¸ãããã¾ããããªãã2åç®ä»¥éã®ãã«ãã§ã¯ãã£ãã·ã¥ãå©ç¨ãããããããã®åãã«ãæéã¯çããªãã¾ãã
â»2ï¼ããã¸ã§ã¯ãè¦æ¨¡ã«ãã£ã¦ã¯ãã«ãèªä½ãã¡ã¢ãªä¸è¶³ãªã©ã«ããã¨ã©ã¼ã¨ãªã£ãããç¾å®çãªæéå
ã«ãã«ããçµäºããªãã£ãããªã©ãããã¾ãã
以ä¸ã§ç°å¢è¨å®ã¨OWASP Juice Shopã®èµ·å確èªã¾ã§å®äºãã¾ããã
å¾ç·¨ã§ã¯è¨å®ããç°å¢ãå©ç¨ããAWSã«ã¦ãã«ãããDockerã¤ã¡ã¼ã¸ã®èµ·åãè¡ãã¾ãã
â»æç« ä¸ã®åååãä¼ç¤¾åãå£ä½åã¯ãä¸è¬ã«å社ã®åæ¨ã¾ãã¯ç»é²åæ¨ã§ãã