Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Deep Securityの運用TIPS
Search
fnifni
November 21, 2016
Technology
1
540
Deep Securityの運用TIPS
2016年11月18日に開催された、トレンドマイクロ社主催のDIRECTIONで登壇した資料です。
fnifni
November 21, 2016
Tweet
Share
More Decks by fnifni
See All by fnifni
Azure Sentinel ~ 導入から2ヶ月間の運用の肌感 ~
fnifni21
2
860
踏み台環境におけるAmazon Maice活用の提案 #secjaws #secjaws08
fnifni21
0
2.4k
Deep Securityのホットデータを活用する ~AWS WAFの場合~
fnifni21
0
870
Other Decks in Technology
See All in Technology
KMP導⼊において、マネジャーとして考えた事
sansantech
PRO
1
220
Scale Security Programs with Scorecarding
ramimac
0
460
Agent Development Kit によるエージェント開発入門
enakai00
1
170
実践Kafka Streams 〜イベント駆動型アーキテクチャを添えて〜
joker1007
3
770
金融システムをモダナイズするためのAmazon Elastic Kubernetes Service(EKS)ノウハウ大全
daitak
0
140
AWS Lambdaでサーバレス設計を学ぼう_ベンダーロックインの懸念を超えて-サーバレスの真価を探る
fukuchiiinu
3
300
メルカリにおけるデータアナリティクス AI エージェント「Socrates」と ADK 活用事例
na0
2
920
セキュリティSaaS企業が実践するCursor運用ルールと知見 / How a Security SaaS Company Runs Cursor: Rules & Insights
tetsuzawa
1
1.3k
NW運用の工夫と発明
recuraki
2
830
Java で学ぶ 代数的データ型
ysknsid25
2
1.1k
不安定だったテストが信頼を取り戻すまで / The Road to Trustworthy Tests
katawara
0
110
ソフトウェアテストのAI活用_ver1.20
fumisuke
0
180
Featured
See All Featured
Templates, Plugins, & Blocks: Oh My! Creating the theme that thinks of everything
marktimemedia
30
2.4k
Cheating the UX When There Is Nothing More to Optimize - PixelPioneers
stephaniewalter
280
13k
Refactoring Trust on Your Teams (GOTO; Chicago 2020)
rmw
34
3k
Why Our Code Smells
bkeepers
PRO
336
57k
Performance Is Good for Brains [We Love Speed 2024]
tammyeverts
10
850
Rails Girls Zürich Keynote
gr2m
94
13k
Practical Tips for Bootstrapping Information Extraction Pipelines
honnibal
PRO
19
1.3k
GitHub's CSS Performance
jonrohan
1031
460k
Build your cross-platform service in a week with App Engine
jlugia
231
18k
Designing Experiences People Love
moore
142
24k
Mobile First: as difficult as doing things right
swwweet
223
9.6k
Chrome DevTools: State of the Union 2024 - Debugging React & Beyond
addyosmani
6
660
Transcript
cloudpack flow Deep Security operation TIPS The meaning of tuning
telling you softly
cloudpack ྲྀ Deep Security ͷӡ༻ TIPS νϡʔχϯάͷۃҙΛͦͬͱ͋ͳͨʹ
Who am I ? • ٢ాͻΖ͔ͣ ( hirokazu yoshida )
Security Engineer at cloudpack http://qiita.com/fnifni
607
ਪઃఆͷݕࡧͰ ਪ͞ΕΔ͜ͱ͕ͳ͍ϧʔϧୡ͕ ͋Γ·͢
දతͳਪ͞ΕΔ͜ͱ͕ͳ͍ϧʔϧୡ • 1000608 - Generic SQL Injection Prevention • 1000552
- Generic Cross Site Scripting(XSS) Prevention
͜ͷϧʔϧͬͯDSͷWAFػೳͰ͠ΐʁ ͳΜͰਪ͞Εͳ͍ͷʁ
ͩͬͯνϡʔχϯάେม͡ΌΜ ʢதͷਓஊʣ
ͦΜͳΘ͚Ͱ νϡʔχϯάϙΠϯτΛհ
ϧʔϧͷੑ࣭ΛΔ
ϧʔϧͷಛੑΛΔ • 1000608 Generic SQL Injection Prevention SQL ΠϯδΣΫγϣϯ߈ܸͰ Α͘ΘΕΔจࣈɾه߸Λ
ݕ͢Δϧʔϧ
ϧʔϧͷಛੑΛΔ • 1000552 Generic Cross Site Scripting(XSS) Prevention XSS߈ܸͰ Α͘ΘΕΔจࣈɾه߸Λ
ݕ͢Δϧʔϧ
߈ܸ௨৴ͱਖ਼ৗ௨৴ͷݟۃΊ
߈ܸ௨৴Λݕͨ͠έʔε GET /index.htm?mode=pc'+ORDEr+By+999+--+; HTTP/1.1 GET /?1=@ini_set(\"display_errors\", \"0\");@set_time_limit(0);@set_magic_quotes_runtime(0);echo '->|';file_put_contents(dirname(['SCRIPT_FILENAME']).'/cache/ cachee.php','<?php eval([1]);?>');echo
'|<-'; HTTP/1.1"
ਖ਼ৗ௨৴Λݕͨ͠έʔε token=uzWoZpwAFsGfXcosY86KcfWLGnMuNIonRM1+zorRM RHrRj8S2D4LbIztTXa58mT90g8U+3YnfFnEA6PNY2xLHg= token=uzWoZpwAFsGfXcosY86KcfWLGnMuNIonRM1%2Bzor RMRHrRj8S2D4LbIztTXa58mT90g8U %2B3YnfFnEA6PNY2xLHg%3D
Ͱ͜Εʁ POST /system/page/setting_tag HTTP/1.1 _method=POST&data[CompanyMaterial] [all_pages_tag]=<script>\r\n\tconsole.log('hoge');\r\n</ script>&data[CompanyMaterial][entry_complete_tag]=
ਖ਼ৗΛΒͳ͍ͱ ҟৗΛΔ͜ͱͰ͖·ͤΜ
γεςϜੜ͖ γεςϜͷݸੑΛΓ ʑͷӡ༻ͰݕΛΔ͜ͱ͕ νϡʔχϯάͷۃҙ
Thank you !