Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
Deep Securityの運用TIPS
Search
fnifni
November 21, 2016
Technology
1
510
Deep Securityの運用TIPS
2016年11月18日に開催された、トレンドマイクロ社主催のDIRECTIONで登壇した資料です。
fnifni
November 21, 2016
Tweet
Share
More Decks by fnifni
See All by fnifni
Azure Sentinel ~ 導入から2ヶ月間の運用の肌感 ~
fnifni21
2
820
踏み台環境におけるAmazon Maice活用の提案 #secjaws #secjaws08
fnifni21
0
2.2k
Deep Securityのホットデータを活用する ~AWS WAFの場合~
fnifni21
0
820
Other Decks in Technology
See All in Technology
Wantedly での Datadog 活用事例
bgpat
2
690
.NET 9 のパフォーマンス改善
nenonaninu
0
1.3k
Storage Browser for Amazon S3
miu_crescent
1
290
メンタル面でもつよつよエンジニアになる/登壇資料(井田 献一朗)
hacobu
0
120
[Ruby] Develop a Morse Code Learning Gem & Beep from Strings
oguressive
1
190
Opcodeを読んでいたら何故かphp-srcを読んでいた話
murashotaro
0
320
React Routerで実現する型安全なSPAルーティング
sansantech
PRO
2
280
Fanstaの1年を大解剖! 一人SREはどこまでできるのか!?
syossan27
2
180
1等無人航空機操縦士一発試験 合格までの道のり ドローンミートアップ@大阪 2024/12/18
excdinc
0
180
株式会社ログラス − エンジニア向け会社説明資料 / Loglass Comapany Deck for Engineer
loglass2019
3
32k
多様なメトリックとシステムの健全性維持
masaaki_k
0
120
怖くない!ゼロから始めるPHPソースコードコンパイル入門
colopl
0
160
Featured
See All Featured
Imperfection Machines: The Place of Print at Facebook
scottboms
266
13k
Automating Front-end Workflow
addyosmani
1366
200k
RailsConf 2023
tenderlove
29
940
BBQ
matthewcrist
85
9.4k
Rails Girls Zürich Keynote
gr2m
94
13k
Site-Speed That Sticks
csswizardry
2
190
What's in a price? How to price your products and services
michaelherold
244
12k
How To Stay Up To Date on Web Technology
chriscoyier
789
250k
The Invisible Side of Design
smashingmag
298
50k
Refactoring Trust on Your Teams (GOTO; Chicago 2020)
rmw
32
2.7k
Fantastic passwords and where to find them - at NoRuKo
philnash
50
2.9k
The Power of CSS Pseudo Elements
geoffreycrofte
73
5.4k
Transcript
cloudpack flow Deep Security operation TIPS The meaning of tuning
telling you softly
cloudpack ྲྀ Deep Security ͷӡ༻ TIPS νϡʔχϯάͷۃҙΛͦͬͱ͋ͳͨʹ
Who am I ? • ٢ాͻΖ͔ͣ ( hirokazu yoshida )
Security Engineer at cloudpack http://qiita.com/fnifni
607
ਪઃఆͷݕࡧͰ ਪ͞ΕΔ͜ͱ͕ͳ͍ϧʔϧୡ͕ ͋Γ·͢
දతͳਪ͞ΕΔ͜ͱ͕ͳ͍ϧʔϧୡ • 1000608 - Generic SQL Injection Prevention • 1000552
- Generic Cross Site Scripting(XSS) Prevention
͜ͷϧʔϧͬͯDSͷWAFػೳͰ͠ΐʁ ͳΜͰਪ͞Εͳ͍ͷʁ
ͩͬͯνϡʔχϯάେม͡ΌΜ ʢதͷਓஊʣ
ͦΜͳΘ͚Ͱ νϡʔχϯάϙΠϯτΛհ
ϧʔϧͷੑ࣭ΛΔ
ϧʔϧͷಛੑΛΔ • 1000608 Generic SQL Injection Prevention SQL ΠϯδΣΫγϣϯ߈ܸͰ Α͘ΘΕΔจࣈɾه߸Λ
ݕ͢Δϧʔϧ
ϧʔϧͷಛੑΛΔ • 1000552 Generic Cross Site Scripting(XSS) Prevention XSS߈ܸͰ Α͘ΘΕΔจࣈɾه߸Λ
ݕ͢Δϧʔϧ
߈ܸ௨৴ͱਖ਼ৗ௨৴ͷݟۃΊ
߈ܸ௨৴Λݕͨ͠έʔε GET /index.htm?mode=pc'+ORDEr+By+999+--+; HTTP/1.1 GET /?1=@ini_set(\"display_errors\", \"0\");@set_time_limit(0);@set_magic_quotes_runtime(0);echo '->|';file_put_contents(dirname(['SCRIPT_FILENAME']).'/cache/ cachee.php','<?php eval([1]);?>');echo
'|<-'; HTTP/1.1"
ਖ਼ৗ௨৴Λݕͨ͠έʔε token=uzWoZpwAFsGfXcosY86KcfWLGnMuNIonRM1+zorRM RHrRj8S2D4LbIztTXa58mT90g8U+3YnfFnEA6PNY2xLHg= token=uzWoZpwAFsGfXcosY86KcfWLGnMuNIonRM1%2Bzor RMRHrRj8S2D4LbIztTXa58mT90g8U %2B3YnfFnEA6PNY2xLHg%3D
Ͱ͜Εʁ POST /system/page/setting_tag HTTP/1.1 _method=POST&data[CompanyMaterial] [all_pages_tag]=<script>\r\n\tconsole.log('hoge');\r\n</ script>&data[CompanyMaterial][entry_complete_tag]=
ਖ਼ৗΛΒͳ͍ͱ ҟৗΛΔ͜ͱͰ͖·ͤΜ
γεςϜੜ͖ γεςϜͷݸੑΛΓ ʑͷӡ༻ͰݕΛΔ͜ͱ͕ νϡʔχϯάͷۃҙ
Thank you !