Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
応募課題(’25広島)
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
BocchiMan
March 22, 2026
Education
1.6k
0
Share
応募課題(’25広島)
BocchiMan
March 22, 2026
More Decks by BocchiMan
See All by BocchiMan
セキュリティ・キャンプミニ@26in東京 Aトラック応募課題
forget1900
0
8
セキュリティ・キャンプミニ@26in東京 Bトラック応募課題
forget1900
0
7
Other Decks in Education
See All in Education
【セーフィー】テクニカルライティング&コミュニケーション実践講座(26新卒エンジニア向け研修資料)
ymzaki_m4
0
190
[2026前期火5] 論理学(京都大学文学部 前期 第1回)「ハルシネーションを外部世界との対応を考えずに見分ける方法」
yatabe
0
1k
Curso de Consagração ao Sagrado Coração de Jesus - O Sagrado Coração na História (Aula 01)
cm_manaus
0
200
Science Tokyo国際卓越研究大学計画_202604
sciencetokyo
PRO
0
3.6k
Padlet opetuksessa
matleenalaakso
12
15k
AWS Certified Generative AI Developer - Professional Beta 不合格体験記
amarelo_n24
1
310
事業紹介資料(トレーナー養成講座)
kentaro1981
0
430
勝手にCULTIBASE で広げよう、探究の輪! - CULTIVAL 2026
hiroc_sk
1
210
Visualisation Techniques - Lecture 8 - Information Visualisation (4019538FNR)
signer
PRO
1
3.1k
Course Review - Lecture 13 - Next Generation User Interfaces (4018166FNR)
signer
PRO
0
2.3k
Data Processing and Visualisation Frameworks - Lecture 6 - Information Visualisation (4019538FNR)
signer
PRO
1
3.1k
良い塩梅を実現する、AWSネットワーク3分クッキング
masakiokuda
1
260
Featured
See All Featured
The Illustrated Guide to Node.js - THAT Conference 2024
reverentgeek
1
370
Bootstrapping a Software Product
garrettdimon
PRO
307
120k
Money Talks: Using Revenue to Get Sh*t Done
nikkihalliwell
0
240
Lightning talk: Run Django tests with GitHub Actions
sabderemane
0
190
AI Search: Implications for SEO and How to Move Forward - #ShenzhenSEOConference
aleyda
1
1.3k
How To Stay Up To Date on Web Technology
chriscoyier
790
250k
Jamie Indigo - Trashchat’s Guide to Black Boxes: Technical SEO Tactics for LLMs
techseoconnect
PRO
0
160
JAMstack: Web Apps at Ludicrous Speed - All Things Open 2022
reverentgeek
1
460
Building Better People: How to give real-time feedback that sticks.
wjessup
370
20k
Efficient Content Optimization with Google Search Console & Apps Script
katarinadahlin
PRO
1
590
Rebuilding a faster, lazier Slack
samanthasiow
85
9.5k
Max Prin - Stacking Signals: How International SEO Comes Together (And Falls Apart)
techseoconnect
PRO
0
170
Transcript
ηΩϡϦςΟɾΩϟϯϓϛχ'25 ౡ։࠵ Ԡื՝ࡽ͠ ΅ͬͪ·Μ/ @forget1900
ʲ̍ʳ Ԡืಈػʹ͍ͭͯ
ճ ɹࢲ౷ܭղੳݚڀࣨʹॴଐ͠ɺ౷ܭֶͷࣝPythonɾRΛ༻͍ ͨσʔλੳΛֶश͍ͯ͠·͢ɻͱͱֶʹؔ৺͕͋Γࣗओ ֶशΛਐΊ͓ͯΓ·͕ͨ͠ɺେֶͷߨٛͰɺֶ͕҉߸ ཧූ߸ཧΛհͯ͠ใཧͱີʹ݁ͼ͍͍ͭͯΔ͜ͱΛ Γ·ͨ͠ɻಛʹɺֶతͳཧ͕͍͔ʹͯ͠ใͷ҆ఆ͔ͭਖ਼֬ͳ ୡΛ࣮ݱ͍ͯ͠Δͷ͔ͱ͍͏Έʹڧ͍ح৺Λ๊͍͍ͯ· ͢ɻɹຊϛχΩϟϯϓͷࢀՃΛ௨͡ɺ͜Ε·ͰֶΜͰ͖ͨཧ͕ ࣮ࣾձʹٕज़ͱͯ͠ͲͷΑ͏ʹ׆༻͞Ε͍ͯΔͷ͔Λਂֶ͘ͼͨ ͍ͱߟ͑ɺԠื͍ͨ͠·ͨ͠ɻ
ʲ͖̍ͭͮʳ ͜ͷߨٛͰֶΜͩ͜ͱΛԿʹཱ͍͔ͯͨ
ճ ɹຊߨٛΛ௨ͯ͡ɺใཧͷநతͳ֓೦͕ɺ࣮ࡍͷ௨৴σʔ λॲཧͷݱͰ۩ମతʹͲͷΑ͏ʹ׆༻͞Ε͍ͯΔͷ͔Λֶͼ͍ͨ ͱߟ͍͑ͯ·͢ɻ·ͨɺཧΛ࣮ʹམͱ͠ࠐΉࡍͷٕज़తͳ ɺݱࡏ໘͍ͯ͠Δ՝ͱͦͷରॲ๏ΛֶͿ͜ͱͰɺଟ֯తͳࢹ Λཆ͍͍ͨͰ͢ɻকདྷɺ͜͜ͰಘͨݟΛࣗͷݚڀʹ׆͔͢ ͱͱʹɺΑΓݎ࿚ͳ҉߸ٕज़ͷൃలʹߩݙͰ͖ΔਓࡐΛࢦ͠ ͍ͨͱߟ͍͑ͯ·͢ɻ
ʲ2ʳ TLS௨৴ʹ͓͍ͯɺΫϥΠΞϯταʔόʔ͔Βૹ৴͞Ε Δূ໌ॻͷݕূΛߦ͍·͢ɻ ͜ͷূ໌ॻݕূͷΈʹ͍ͭͯௐɺαʔόʔͷਖ਼ੑΛͲͷΑ ͏ͳखॱͰ֬ೝ͍ͯ͠Δͷ͔ɺॱংཱͯͯઆ໌͍ͯͩ͘͠͞ɻ
ճ(1/3) ɹTLS௨৴ʹ͓͍ͯɺΫϥΠΞϯτʢWebϒϥβʣଓઌͷ αʔόʔ͕ਅਖ਼ͳͷͰ͋Δ͔Λ֬ೝ͢ΔͨΊɺʮެ։伴ূ໌ॻʯ Λ༻͍ͨݕূΛߦ͍·͢ɻݕূͷྲྀΕʹ͍ͭͯҎԼͰઆ໌͢Δɻ 1. ূ໌ॻͷडྖͱ༗ޮੑͷ֬ೝ αʔόʔ͔Βૹ৴͞Εͨʮαʔόʔূ໌ॻʯΛड͚औΓɺ·ͣ༗ ޮظݶʢNot Before ʙ
Not AfterʣͰ͋Δ͜ͱΛ֬ೝ͠·͢ɻ ͋Θͤͯɺূ໌ॻ͕ࣦޮϦετʢCRLOCSPʣʹؚ·Ε͍ͯͳ͍ ͔νΣοΫ͠·͢ɻ
(2/3) 2. ॺ໊ͷݕূͱ৴པͷ࿈ͷ֬ೝ ূ໌ॻʹ༩͞Εͨσδλϧॺ໊ΛɺൃߦݩͰ͋ΔೝূہʢCAʣ ͷެ։伴Λ༻͍ͯݕূ͠·͢ɻ͜ͷࡍɺதؒೝূہ͔ΒɺOSϒ ϥβʹϓϦΠϯετʔϧ͞Ε͍ͯΔʮϧʔτCAূ໌ॻʯ·Ͱḷ Γɺ৴པͷ࿈ཱ͕͍ͯ͠Δ͔Λ֬ೝ͠·͢ɻ 3. υϝΠϯͷ߹ੑ֬ೝ ଓ͠Α͏ͱ͍ͯ͠ΔURLͷϗετ໊͕ɺূ໌ॻͷʮSubject
Alternative Name (SAN)ʯ·ͨʮCommon Name (CN)ʯʹه ࡌ͞Ε͍ͯΔ໊લͱҰக͢Δ͔Λর߹͠·͢ɻ
(3/3) 4. ݕূྃͱ҉߸Խ௨৴ͷ։࢝ ্هͷݕূ͕ͯ͢ޭͨ͠߹ɺΫϥΠΞϯταʔόʔΛਖ਼ ͳͷͱஅ͠·͢ɻͦͷޙɺڞ௨伴ͷڞ༗ʢTLSϋϯυγΣ ΠΫʣΛܧଓ͠ɺ҆શͳ҉߸Խ௨৴Λཱ֬͠·͢ɻ
ʲ3ʳ OWASP ASVSͱɺιϑτΣΞWebϓϩμΫτʹ͓͍ ͯɺͲͷΑ͏ͳׂΛͨ͢ϦετͰ͠ΐ͏͔ʁ LLMͳͲΛ༻͍ͳ͕Βௐɺࣗͷݴ༿Ͱ500จࣈҎ্Ͱ͑ͯ͘ ͍ͩ͞ɻ
ճ(1/4) OWASP ASVSʢApplication Security Verification Standardʣɺ ຊޠͰʮΞϓϦέʔγϣϯηΩϡϦςΟݕূඪ४ʯͱ༁͞Εɺ WebΞϓϦέʔγϣϯͷ҆શੑΛ٬؍తʹධՁɾ୲อ͢ΔͨΊͷ ʮڞ௨ͷͷ͞͠ʯͱͯ͠ͷׂΛՌͨ͠·͢ɻੈքతͳηΩϡϦ ςΟίϛϡχςΟͰ͋ΔOWASP͕ࡦఆ͓ͯ͠Γɺ։ൃऀηΩϡϦ
ςΟΤϯδχΞ͕ࢀর͖͢۩ମతͳཁ͕݅ମܥతʹ·ͱΊΒΕͯ ͍·͢ɻͦͷओͳׂҎԼͷ3ʹू͞Ε·͢ɻ
(2/4) ୈҰʹɺʮηΩϡϦςΟཁ݅ͷཏతͳΨΠυϥΠϯʯ ͱͯ͠ͷ ׂͰ͢ɻASVS୯ͳΔ੬ऑੑஅͷνΣοΫϦετʹཹ·Γ·ͤ ΜɻೝূɺΞΫηε੍ޚɺσʔλͷ҉߸ԽɺΤϥʔॲཧͳͲଟذʹ ΘͨΔ߲ʢϨϕϧ1Ͱ131߲ɺϨϕϧ3Ͱ286߲ʹٴͼ·͢ʣ Λཏ͓ͯ͠Γɺ͜ΕΒΛ։ൃͷઃܭஈ֊͔Βࢀর͢Δ͜ͱͰɺη ΩϡϦςΟΛޙ͚Ͱͳ͘ʮઃܭஈ֊͔ΒΈࠐΉʢSecurity by Designʣʯ͜ͱ͕ՄೳʹͳΓ·͢ɻ
(3/4) ୈೋʹɺʮϦεΫʹԠͨ͡ஈ֊తͳηΩϡϦςΟࢦඪʯ ͷఏڙͰ ͢ɻASVSͰɺΞϓϦέʔγϣϯͷॏཁʹԠͯ͡3ͭͷϨϕϧΛ ఆ͍ٛͯ͠·͢ɻશͯͷΞϓϦ͕࠷ݶຬ͖ͨ͢ʮϨϕϧ1ʯɺػ ີσʔλΛѻ͏ҰൠతͳϏδωεΞϓϦʹదͨ͠ʮϨϕϧ2ʯɺͦ͠ ͯॏཁΠϯϑϥ܉ࣄϨϕϧͷߴͳ৴པੑ͕ٻΊΒΕΔʮϨϕϧ 3ʯͰ͢ɻϨϕϧ্͕͕ΔʹͭΕɺݕূ߲͕૿͑Δ͚ͩͰͳ͘ɺ ݕূख๏มԽ͠·͢ɻྫ͑Ϩϕϧ1ͰϒϥοΫϘοΫεܗࣜͷ DASTʢಈతղੳʣ͕த৺Ͱ͕͢ɺϨϕϧ2Ҏ্ͰϗϫΠτϘοΫ
εܗࣜͷSASTʢ੩తղੳʣίʔυϨϏϡʔΛΈ߹ΘͤͨɺΑΓ ଟతͳݕূ͕ٻΊΒΕ·͢ɻ
(4/4) ୈࡾʹɺʮ৫֎ʹ͓͚Δίϛϡχέʔγϣϯͷඪ४Խʯ Ͱ͢ɻ ։ൃνʔϜͱஅϕϯμʔɺ͋Δ͍ൃݩͱडऀͷؒͰʮͲ͜ ·Ͱରࡦ͖͔͢ʯͱ͍͏߹ҙܗࠔΛۃΊ·͢ɻ͔͠͠ɺ ASVSΛڞ௨ݴޠͱͯ͠ಋೖ͢Δ͜ͱͰɺʮࠓճASVS Ϩϕϧ1ʹ ४ڌ͢Δʯͱ͍ͬͨ໌֬ͳඪઃఆ͕ՄೳʹͳΓɺ৫શମͷη ΩϡϦςΟϓϩηεͷಁ໌ੑͱ࣭Λ্ͤ͞ΔׂΛ୲͍·͢ɻ ͜ͷΑ͏ʹASVSɺٕज़తͳνΣοΫϦετͰ͋Δͱಉ࣌ʹɺ։
ൃɾӡ༻ɾධՁͷϥΠϑαΠΫϧશମΛ௨ͯ͡ιϑτΣΞͷ৴པ ੑΛࢧ͑ΔɺۃΊͯॏཁͳϑϨʔϜϫʔΫͰ͋Δͱݴ͑·͢ɻ