Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Deep Securityの運用TIPS
Search
Sponsored
·
Ship Features Fearlessly
Turn features on and off without deploys. Used by thousands of Ruby developers.
→
fnifni
November 21, 2016
Technology
580
1
Share
Deep Securityの運用TIPS
2016年11月18日に開催された、トレンドマイクロ社主催のDIRECTIONで登壇した資料です。
fnifni
November 21, 2016
More Decks by fnifni
See All by fnifni
Azure Sentinel ~ 導入から2ヶ月間の運用の肌感 ~
fnifni21
2
900
踏み台環境におけるAmazon Maice活用の提案 #secjaws #secjaws08
fnifni21
0
2.6k
Deep Securityのホットデータを活用する ~AWS WAFの場合~
fnifni21
0
970
Other Decks in Technology
See All in Technology
フルカイテン株式会社 エンジニア向け採用資料
fullkaiten
0
11k
20260326_AIDD事例紹介_ULSC.pdf
findy_eventslides
0
520
TanStack Start エコシステムの現在地 / TanStack Start Ecosystem 2026
iktakahiro
1
270
Even G2 クイックスタートガイド(日本語版)
vrshinobi1
0
200
Data Intelligence Engineering Unit 部門と各ポジション紹介
sansantech
PRO
0
110
最大のアウトプット術は問題を作ること
ryoaccount
0
300
Claude Teamプランの選定と、できること/できないこと
rfdnxbro
1
180
推し活エージェント
yuntan_t
1
790
制約を設計する - 非決定性との境界線 / Designing constraints
soudai
PRO
5
1.4k
VSCode中心だった自分がターミナル沼に入門した話
sanogemaru
0
920
Databricks Lakebaseを用いたAIエージェント連携
daiki_akimoto_nttd
0
140
"まず試す"ためのDatabricks Apps活用法 / Databricks Apps for Early Experiments and Validation
nttcom
1
170
Featured
See All Featured
The innovator’s Mindset - Leading Through an Era of Exponential Change - McGill University 2025
jdejongh
PRO
1
140
Let's Do A Bunch of Simple Stuff to Make Websites Faster
chriscoyier
508
140k
Learning to Love Humans: Emotional Interface Design
aarron
275
41k
How to make the Groovebox
asonas
2
2.1k
Building Adaptive Systems
keathley
44
3k
Test your architecture with Archunit
thirion
1
2.2k
Marketing to machines
jonoalderson
1
5.1k
Visual Storytelling: How to be a Superhuman Communicator
reverentgeek
2
490
Technical Leadership for Architectural Decision Making
baasie
3
310
Design of three-dimensional binary manipulators for pick-and-place task avoiding obstacles (IECON2024)
konakalab
0
390
Gemini Prompt Engineering: Practical Techniques for Tangible AI Outcomes
mfonobong
2
350
Java REST API Framework Comparison - PWX 2021
mraible
34
9.2k
Transcript
cloudpack flow Deep Security operation TIPS The meaning of tuning
telling you softly
cloudpack ྲྀ Deep Security ͷӡ༻ TIPS νϡʔχϯάͷۃҙΛͦͬͱ͋ͳͨʹ
Who am I ? • ٢ాͻΖ͔ͣ ( hirokazu yoshida )
Security Engineer at cloudpack http://qiita.com/fnifni
607
ਪઃఆͷݕࡧͰ ਪ͞ΕΔ͜ͱ͕ͳ͍ϧʔϧୡ͕ ͋Γ·͢
දతͳਪ͞ΕΔ͜ͱ͕ͳ͍ϧʔϧୡ • 1000608 - Generic SQL Injection Prevention • 1000552
- Generic Cross Site Scripting(XSS) Prevention
͜ͷϧʔϧͬͯDSͷWAFػೳͰ͠ΐʁ ͳΜͰਪ͞Εͳ͍ͷʁ
ͩͬͯνϡʔχϯάେม͡ΌΜ ʢதͷਓஊʣ
ͦΜͳΘ͚Ͱ νϡʔχϯάϙΠϯτΛհ
ϧʔϧͷੑ࣭ΛΔ
ϧʔϧͷಛੑΛΔ • 1000608 Generic SQL Injection Prevention SQL ΠϯδΣΫγϣϯ߈ܸͰ Α͘ΘΕΔจࣈɾه߸Λ
ݕ͢Δϧʔϧ
ϧʔϧͷಛੑΛΔ • 1000552 Generic Cross Site Scripting(XSS) Prevention XSS߈ܸͰ Α͘ΘΕΔจࣈɾه߸Λ
ݕ͢Δϧʔϧ
߈ܸ௨৴ͱਖ਼ৗ௨৴ͷݟۃΊ
߈ܸ௨৴Λݕͨ͠έʔε GET /index.htm?mode=pc'+ORDEr+By+999+--+; HTTP/1.1 GET /?1=@ini_set(\"display_errors\", \"0\");@set_time_limit(0);@set_magic_quotes_runtime(0);echo '->|';file_put_contents(dirname(['SCRIPT_FILENAME']).'/cache/ cachee.php','<?php eval([1]);?>');echo
'|<-'; HTTP/1.1"
ਖ਼ৗ௨৴Λݕͨ͠έʔε token=uzWoZpwAFsGfXcosY86KcfWLGnMuNIonRM1+zorRM RHrRj8S2D4LbIztTXa58mT90g8U+3YnfFnEA6PNY2xLHg= token=uzWoZpwAFsGfXcosY86KcfWLGnMuNIonRM1%2Bzor RMRHrRj8S2D4LbIztTXa58mT90g8U %2B3YnfFnEA6PNY2xLHg%3D
Ͱ͜Εʁ POST /system/page/setting_tag HTTP/1.1 _method=POST&data[CompanyMaterial] [all_pages_tag]=<script>\r\n\tconsole.log('hoge');\r\n</ script>&data[CompanyMaterial][entry_complete_tag]=
ਖ਼ৗΛΒͳ͍ͱ ҟৗΛΔ͜ͱͰ͖·ͤΜ
γεςϜੜ͖ γεςϜͷݸੑΛΓ ʑͷӡ༻ͰݕΛΔ͜ͱ͕ νϡʔχϯάͷۃҙ
Thank you !