Upgrade to PRO for Only $50/Year—Limited-Time Offer! 🔥
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Deep Securityの運用TIPS
Search
fnifni
November 21, 2016
Technology
1
510
Deep Securityの運用TIPS
2016年11月18日に開催された、トレンドマイクロ社主催のDIRECTIONで登壇した資料です。
fnifni
November 21, 2016
Tweet
Share
More Decks by fnifni
See All by fnifni
Azure Sentinel ~ 導入から2ヶ月間の運用の肌感 ~
fnifni21
2
820
踏み台環境におけるAmazon Maice活用の提案 #secjaws #secjaws08
fnifni21
0
2.2k
Deep Securityのホットデータを活用する ~AWS WAFの場合~
fnifni21
0
810
Other Decks in Technology
See All in Technology
pmconf2024_UPSIDER
upsider_tech
0
7.1k
ドメインロジックで考えるテスタビリティ
leveragestech
1
280
Advancing the 3D Geospatial Ecosystem in Japan via Global Collaborations
osgeojp
0
170
まだチケットを手動で書いてるの?!GitHub Actionsと生成AIでチケットの作成を自動化してみた話 / 20241207 Yoshinori Katayama
shift_evolve
1
760
AWS認定試験の長文問題を早く解くコツ
keke1234ke
0
170
MySQL 8.0 から PostgreSQL 16 への移行と RLS 導入までの道のりと学び
baseballyama
0
850
Will Positron accelerate us?
lycorptech_jp
PRO
1
120
asumikamというカンファレンスオーガナイザの凄さを語る / The Brilliance of Asumikam
tomzoh
1
290
Classmethod_regrowth_2024_tokyo_security_identity_governance_summary
hiashisan
0
190
40歲的我會給20歲的自己,關於軟體開發的7個建議
line_developers_tw
PRO
0
2.2k
LY Accessibility Guidelines @fukuoka_a11yconf_前夜祭
lycorptech_jp
PRO
1
150
Amazon Bedrock Multi-Agent Collaboration Workshop の紹介 - ワークショップでAIエージェントを学ぼう
nasuvitz
2
140
Featured
See All Featured
Gamification - CAS2011
davidbonilla
80
5.1k
The Myth of the Modular Monolith - Day 2 Keynote - Rails World 2024
eileencodes
17
2.2k
The MySQL Ecosystem @ GitHub 2015
samlambert
250
12k
A better future with KSS
kneath
238
17k
The Cult of Friendly URLs
andyhume
78
6.1k
Fireside Chat
paigeccino
34
3.1k
CSS Pre-Processors: Stylus, Less & Sass
bermonpainter
356
29k
Responsive Adventures: Dirty Tricks From The Dark Corners of Front-End
smashingmag
251
21k
The Illustrated Children's Guide to Kubernetes
chrisshort
48
48k
Facilitating Awesome Meetings
lara
50
6.1k
ReactJS: Keep Simple. Everything can be a component!
pedronauck
665
120k
Designing Experiences People Love
moore
138
23k
Transcript
cloudpack flow Deep Security operation TIPS The meaning of tuning
telling you softly
cloudpack ྲྀ Deep Security ͷӡ༻ TIPS νϡʔχϯάͷۃҙΛͦͬͱ͋ͳͨʹ
Who am I ? • ٢ాͻΖ͔ͣ ( hirokazu yoshida )
Security Engineer at cloudpack http://qiita.com/fnifni
607
ਪઃఆͷݕࡧͰ ਪ͞ΕΔ͜ͱ͕ͳ͍ϧʔϧୡ͕ ͋Γ·͢
දతͳਪ͞ΕΔ͜ͱ͕ͳ͍ϧʔϧୡ • 1000608 - Generic SQL Injection Prevention • 1000552
- Generic Cross Site Scripting(XSS) Prevention
͜ͷϧʔϧͬͯDSͷWAFػೳͰ͠ΐʁ ͳΜͰਪ͞Εͳ͍ͷʁ
ͩͬͯνϡʔχϯάେม͡ΌΜ ʢதͷਓஊʣ
ͦΜͳΘ͚Ͱ νϡʔχϯάϙΠϯτΛհ
ϧʔϧͷੑ࣭ΛΔ
ϧʔϧͷಛੑΛΔ • 1000608 Generic SQL Injection Prevention SQL ΠϯδΣΫγϣϯ߈ܸͰ Α͘ΘΕΔจࣈɾه߸Λ
ݕ͢Δϧʔϧ
ϧʔϧͷಛੑΛΔ • 1000552 Generic Cross Site Scripting(XSS) Prevention XSS߈ܸͰ Α͘ΘΕΔจࣈɾه߸Λ
ݕ͢Δϧʔϧ
߈ܸ௨৴ͱਖ਼ৗ௨৴ͷݟۃΊ
߈ܸ௨৴Λݕͨ͠έʔε GET /index.htm?mode=pc'+ORDEr+By+999+--+; HTTP/1.1 GET /?1=@ini_set(\"display_errors\", \"0\");@set_time_limit(0);@set_magic_quotes_runtime(0);echo '->|';file_put_contents(dirname(['SCRIPT_FILENAME']).'/cache/ cachee.php','<?php eval([1]);?>');echo
'|<-'; HTTP/1.1"
ਖ਼ৗ௨৴Λݕͨ͠έʔε token=uzWoZpwAFsGfXcosY86KcfWLGnMuNIonRM1+zorRM RHrRj8S2D4LbIztTXa58mT90g8U+3YnfFnEA6PNY2xLHg= token=uzWoZpwAFsGfXcosY86KcfWLGnMuNIonRM1%2Bzor RMRHrRj8S2D4LbIztTXa58mT90g8U %2B3YnfFnEA6PNY2xLHg%3D
Ͱ͜Εʁ POST /system/page/setting_tag HTTP/1.1 _method=POST&data[CompanyMaterial] [all_pages_tag]=<script>\r\n\tconsole.log('hoge');\r\n</ script>&data[CompanyMaterial][entry_complete_tag]=
ਖ਼ৗΛΒͳ͍ͱ ҟৗΛΔ͜ͱͰ͖·ͤΜ
γεςϜੜ͖ γεςϜͷݸੑΛΓ ʑͷӡ༻ͰݕΛΔ͜ͱ͕ νϡʔχϯάͷۃҙ
Thank you !