Upgrade to PRO for Only $50/Year—Limited-Time Offer! 🔥
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
WordPressのセキュリティについて / gifuwpm20-wordpress-secu...
Search
Koji Kuno
March 14, 2020
Programming
0
78
WordPressのセキュリティについて / gifuwpm20-wordpress-security
Gifu WordPress Meetup #20 での登壇資料です。
Koji Kuno
March 14, 2020
Tweet
Share
More Decks by Koji Kuno
See All by Koji Kuno
unitoneが楽しくなるまでの道のり
oleindesign
0
91
WordPress 6.5 の新機能紹介
oleindesign
0
130
How to deal with WordPress themes in the future
oleindesign
0
1.7k
WordPress(再)入門 - 運用・学習編
oleindesign
0
230
WordPress(再)入門 - カスタマイズ編
oleindesign
0
260
WordPress(再)入門 - コンテンツ作成方法編
oleindesign
0
210
WordPress(再)入門 - テーマ・プラグイン編 / introduction-to-wordpress-again-theme-plugin
oleindesign
0
230
WordPress(再)入門 - 基本設定編 / introduction-to-wordpress-again-basic-settings
oleindesign
0
470
WordPress(再)入門 - 基礎知識・環境編
oleindesign
2
1k
Other Decks in Programming
See All in Programming
Go コードベースの構成と AI コンテキスト定義
andpad
0
140
Findy AI+の開発、運用におけるMCP活用事例
starfish719
0
1.7k
re:Invent 2025 のイケてるサービスを紹介する
maroon1st
0
150
Deno Tunnel を使ってみた話
kamekyame
0
240
AIエンジニアリングのご紹介 / Introduction to AI Engineering
rkaga
8
3.3k
ZJIT: The Ruby 4 JIT Compiler / Ruby Release 30th Anniversary Party
k0kubun
0
270
Combinatorial Interview Problems with Backtracking Solutions - From Imperative Procedural Programming to Declarative Functional Programming - Part 2
philipschwarz
PRO
0
110
AI前提で考えるiOSアプリのモダナイズ設計
yuukiw00w
0
190
新卒エンジニアのプルリクエスト with AI駆動
fukunaga2025
0
230
Graviton と Nitro と私
maroon1st
0
130
Cap'n Webについて
yusukebe
0
150
GISエンジニアから見たLINKSデータ
nokonoko1203
0
180
Featured
See All Featured
The agentic SEO stack - context over prompts
schlessera
0
560
Kristin Tynski - Automating Marketing Tasks With AI
techseoconnect
PRO
0
110
Unlocking the hidden potential of vector embeddings in international SEO
frankvandijk
0
130
RailsConf & Balkan Ruby 2019: The Past, Present, and Future of Rails at GitHub
eileencodes
141
34k
Building Better People: How to give real-time feedback that sticks.
wjessup
370
20k
Navigating the moral maze — ethical principles for Al-driven product design
skipperchong
1
210
Everyday Curiosity
cassininazir
0
110
Visualizing Your Data: Incorporating Mongo into Loggly Infrastructure
mongodb
48
9.8k
Max Prin - Stacking Signals: How International SEO Comes Together (And Falls Apart)
techseoconnect
PRO
0
49
Exploring the Power of Turbo Streams & Action Cable | RailsConf2023
kevinliebholz
37
6.2k
A better future with KSS
kneath
240
18k
The Invisible Side of Design
smashingmag
302
51k
Transcript
8PSE1SFTTͷηΩϡϦςΟʹ ͍ͭͯ (JGV8PSE1SFTT.FFUVQ ݄ʢʣʙ
ࣗݾհ w 8FC੍࡞ܥϑϦʔϥϯε w ࠷ۙʮσʔλɾαΠΤϯεʯʹ͍ͭͯڵຯʑ w ग़άϥϑΟοΫσβΠϯɻ8FCશಠֶɻ w ಈը৴ʹखΛग़࢝͠Ίͨɻ
8PSE1SFTTͷηΩϡϦςΟʹ ͍ͭͯ
ใηΩϡϦςΟͷ̏ྨ w ਓతڴҖ ˠใΛ౪Ήɾෆਖ਼ར༻ɾޡૢ࡞ͳͲਓ͕ى͜͢ͷ w ٕज़తڴҖ ˠෆਖ਼ΞΫηεɾվ͟ΜɾΫϥοΩϯά w ཧతڴҖ ˠαʔόʔ͕ཧతʹյΕΔͳͲ
8PSE1SFTTૂΘΕ͍͢ʁ w ʮૂΘΕ͍͢ʯͱࢥ͏ʢݸਓతײʣ w γΣΞ͔Βߟ͑ͯ8PSE1SFTTΛૂ͑खͬऔΓૣ͍ͱߟ ͑Δͷ͕ଥ w ΦʔϓϯιʔεͳͷͰத୭ͰݟΔ͜ͱ͕Ͱ͖Δ
ຊʹ8PSE1SFTT͡Όͳ͍ͱμϝʁ w ͦͷΣϒαΠτ͕8PSE1SFTTͰ͋Δ͖ཧ༝ʁ w ଞͷແྉɾ༗ྉϒϩάαʔϏεͰͩΊʁ w ੩తΣϒαΠτͰྑ͍ͷͰʁ
ޮՌ͕ߴ͍ʢͱߟ͑ΒΕΔʣ ରࡦ ύεϫʔυͷཧ ΞοϓσʔτΛ͢Δ ϩάΠϯ63-Λมߋ͢Δ 44-Խ 8"'ಋೖ Θͳ͍ςʔϚɾϓϥάΠϯͷແޮԽআ
ύεϫʔυͷཧ w ೦ͷͨΊॳظύεϫʔυ͔Βมߋ͓ͯ͜͠͏ w ҆શͳύεϫʔυͱʁʢ૯লࢀরʣ ໊લͳͲͷݸਓใ͔ΒਪଌͰ͖ͳ͍͜ͱ ӳ୯ޠͳͲΛͦͷ··༻͠ͳ͍͜ͱ ΞϧϑΝϕοτͱࣈ͕ࠞࡏ͍ͯ͠Δ͜ͱ దͳ͞ͷจࣈྻͰ͋Δ͜ͱ ྨਪ͍͢͠ฒͼํͦͷ༰қͳΈ߹Θͤʹ͠ͳ͍͜ͱ
ύεϫʔυͷ࠷େղಡ࣌ؒ https://www.ipa.go.jp/security/txt/2008/10outline.html
ΞοϓσʔτΛ͢Δ w 8PSE1SFTTίΞͷߋ৽ʢϚΠφʔࣗಈʣ w ϓϥάΠϯςʔϚͷߋ৽ w ίΞWFSʹରԠ͍ͯ͠Δ͔֬ೝ͢Δ͖
ϓϥάΠϯͷબͼํ
όοΫΞοϓΛऔಘ͠Α͏ w ΞοϓσʔτΛ࣮ߦͯ͠ը໘͕ਅͬനʹʜ w ͦΜͳ࣌ʹɺόοΫΞοϓσʔλͰ෮ݩ͠·͢ w "MMJO0OF81.JHSBUJPO͕ʢݸਓతʹʣ͓͢͢Ί ˠόοΫΞοϓऔಘͱ෮ݩ͕؆୯ w ීஈ͔ΒఆظతͳόοΫΞοϓΛεέδϡʔϧԽ͢Δ
ϩάΠϯ63-Λมߋ͢Δ IUUQTTBNQMFDPNXQMPHJOQIQ
ϩάΠϯ63-Λมߋ͢Δ w खಈͰରԠՄೳ ˠϋʔυϧ͕ߴ͍ͷͰϓϥάΠϯͰػೳՃ͕Φεεϝ w 4JUF(VBSE811MVHJO w ʲҙʳ༗ޮԽͨ͠Βඪ४ઃఆͰϩάΠϯ63-͕มߋ ͞Εͯ͠·͏ͷͰѻ͍ʹҙ w
Ճ͑ͯϩάΠϯը໘ʹ#"4*$ೝূΛ͚Δͱ͍͏ख
44-Խ w 4FDVSF4PDLFUT-BZFSͷུ w ΣϒαΠτͱσόΠεʢ1$ͳͲʣͱͷؒͰΓऔΓ͢ ΔσʔλΛ҉߸Խͯ͠౪Έʹ͘͘͢ΔΈ w IUUQTʙͰΞΫηεͰ͖ΔΣϒαΠτରԠࡁΈ w (PPHMF$ISPNFͳͲͰରԠ͍ͯ͠ͳ͍ͱʮอޢ͞Εͯ
͍ͳ͍௨৴ʯͱදࣔ͞ΕͨΓ͢Δ
44-Խͷํ๏ w ར༻͍ͯ͠ΔαʔϏεαʔόʔʹΑ༷ͬͯʑͳͷͰҰ ֓ʹํ๏ΛఏࣔͰ͖ͳ͍ w طଘΣϒαΠτΛରԠ͢Δ߹ɺαΠτʹઃஔ͞Ε ͍ͯΔϦϯΫશ͕ͯIUUQTʙʹͳ͍ͬͯͳ͍ͱશͳ 44-ԽʹͳΒͳ͍ʢNJYFEDPOUFOUʣ w దʹΒͣʹ༗ࣝऀʹ૬ஊ͢Δ͜ͱΛ͓קΊ͠·͢
8"'ಋೖ w 8FC"QQMJDBUJPO'JSFXBMMͷུ w αʔόʔଆPSϓϥάΠϯͰͷಋೖ͕Ұൠత w 9TFSWFSϩϦϙTBLVSBར༻Մೳ w 8PSEGFODF4FDVSJUZ'JSFXBMM.BMXBSF4DBOͳͲ w
81ɾϓϥάΠϯͷػೳʹΑΔΞΫηεΛޡͬͯःஅͯ͠ ͠·͏͜ͱ͕͋Δˠνϡʔχϯά͕ඞཁͳ߹͋Δ
Θͳ͍ςʔϚɾϓϥάΠϯͷ ແޮԽআ w ඪ४Ͱ5XFOUZʙςʔϚ͕ෳΠϯετʔϧ͞Ε͍ͯΔ͕ ෆཁͳΒআʢఆظతʹߋ৽͍ͯ͠Ε0,ʣ w Θͳ͍PSݹ͍ϓϥάΠϯɺআPSΓ͑ʢஔ͖ ͑ʣΛݕ౼͢Δ w ఆظతʹ֬ೝ͢Δश׳Λ࣋ͭͱϕλʔ
·ͱΊ w *%ͱ18ΦϦδφϦςΟΛ࣋ͭ w ߋ৽͠ͳ͍ͳΒ8PSE1SFTTΘͳ͍ʢ͘Β͍ͷؾ࣋ͪͰʣ w όοΫΞοϓඞਢʢ෮ݩ࿅शͯ͠ΈΑ͏ʣ w ϩάΠϯ63-Λมߋͯ͠#"4*$ೝূซͤΔͱ٢ w
44-ԽࠓৗࣝʢඞਢʣϨϕϧ