Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
WordPressのセキュリティについて / gifuwpm20-wordpress-secu...
Search
Koji Kuno
March 14, 2020
Programming
0
78
WordPressのセキュリティについて / gifuwpm20-wordpress-security
Gifu WordPress Meetup #20 での登壇資料です。
Koji Kuno
March 14, 2020
Tweet
Share
More Decks by Koji Kuno
See All by Koji Kuno
unitoneが楽しくなるまでの道のり
oleindesign
0
91
WordPress 6.5 の新機能紹介
oleindesign
0
130
How to deal with WordPress themes in the future
oleindesign
0
1.7k
WordPress(再)入門 - 運用・学習編
oleindesign
0
230
WordPress(再)入門 - カスタマイズ編
oleindesign
0
260
WordPress(再)入門 - コンテンツ作成方法編
oleindesign
0
210
WordPress(再)入門 - テーマ・プラグイン編 / introduction-to-wordpress-again-theme-plugin
oleindesign
0
230
WordPress(再)入門 - 基本設定編 / introduction-to-wordpress-again-basic-settings
oleindesign
0
480
WordPress(再)入門 - 基礎知識・環境編
oleindesign
2
1k
Other Decks in Programming
See All in Programming
Kotlin Multiplatform Meetup - Compose Multiplatform 외부 의존성 아키텍처 설계부터 운영까지
wisemuji
0
150
Claude Codeの「Compacting Conversation」を体感50%減! CLAUDE.md + 8 Skills で挑むコンテキスト管理術
kmurahama
1
690
生成AIを利用するだけでなく、投資できる組織へ
pospome
2
430
AtCoder Conference 2025「LLM時代のAHC」
imjk
2
620
実は歴史的なアップデートだと思う AWS Interconnect - multicloud
maroon1st
0
290
AI 駆動開発ライフサイクル(AI-DLC):ソフトウェアエンジニアリングの再構築 / AI-DLC Introduction
kanamasa
11
4.7k
Canon EOS R50 V と R5 Mark II 購入でみえてきた最近のデジイチ VR180 事情、そして VR180 静止画に活路を見出すまで
karad
0
140
CSC307 Lecture 01
javiergs
PRO
0
650
PC-6001でPSG曲を鳴らすまでを全部NetBSD上の Makefile に押し込んでみた / osc2025hiroshima
tsutsui
0
200
CSC307 Lecture 02
javiergs
PRO
1
730
Navigating Dependency Injection with Metro
l2hyunwoo
1
200
新卒エンジニアのプルリクエスト with AI駆動
fukunaga2025
0
240
Featured
See All Featured
Code Reviewing Like a Champion
maltzj
527
40k
How to Create Impact in a Changing Tech Landscape [PerfNow 2023]
tammyeverts
55
3.2k
Optimising Largest Contentful Paint
csswizardry
37
3.5k
Scaling GitHub
holman
464
140k
Paper Plane (Part 1)
katiecoart
PRO
0
2.6k
Designing Dashboards & Data Visualisations in Web Apps
destraynor
231
54k
How to Think Like a Performance Engineer
csswizardry
28
2.4k
Ecommerce SEO: The Keys for Success Now & Beyond - #SERPConf2024
aleyda
1
1.8k
How to Grow Your eCommerce with AI & Automation
katarinadahlin
PRO
0
81
Game over? The fight for quality and originality in the time of robots
wayneb77
1
73
Have SEOs Ruined the Internet? - User Awareness of SEO in 2025
akashhashmi
0
220
Navigating the moral maze — ethical principles for Al-driven product design
skipperchong
1
210
Transcript
8PSE1SFTTͷηΩϡϦςΟʹ ͍ͭͯ (JGV8PSE1SFTT.FFUVQ ݄ʢʣʙ
ࣗݾհ w 8FC੍࡞ܥϑϦʔϥϯε w ࠷ۙʮσʔλɾαΠΤϯεʯʹ͍ͭͯڵຯʑ w ग़άϥϑΟοΫσβΠϯɻ8FCશಠֶɻ w ಈը৴ʹखΛग़࢝͠Ίͨɻ
8PSE1SFTTͷηΩϡϦςΟʹ ͍ͭͯ
ใηΩϡϦςΟͷ̏ྨ w ਓతڴҖ ˠใΛ౪Ήɾෆਖ਼ར༻ɾޡૢ࡞ͳͲਓ͕ى͜͢ͷ w ٕज़తڴҖ ˠෆਖ਼ΞΫηεɾվ͟ΜɾΫϥοΩϯά w ཧతڴҖ ˠαʔόʔ͕ཧతʹյΕΔͳͲ
8PSE1SFTTૂΘΕ͍͢ʁ w ʮૂΘΕ͍͢ʯͱࢥ͏ʢݸਓతײʣ w γΣΞ͔Βߟ͑ͯ8PSE1SFTTΛૂ͑खͬऔΓૣ͍ͱߟ ͑Δͷ͕ଥ w ΦʔϓϯιʔεͳͷͰத୭ͰݟΔ͜ͱ͕Ͱ͖Δ
ຊʹ8PSE1SFTT͡Όͳ͍ͱμϝʁ w ͦͷΣϒαΠτ͕8PSE1SFTTͰ͋Δ͖ཧ༝ʁ w ଞͷແྉɾ༗ྉϒϩάαʔϏεͰͩΊʁ w ੩తΣϒαΠτͰྑ͍ͷͰʁ
ޮՌ͕ߴ͍ʢͱߟ͑ΒΕΔʣ ରࡦ ύεϫʔυͷཧ ΞοϓσʔτΛ͢Δ ϩάΠϯ63-Λมߋ͢Δ 44-Խ 8"'ಋೖ Θͳ͍ςʔϚɾϓϥάΠϯͷແޮԽআ
ύεϫʔυͷཧ w ೦ͷͨΊॳظύεϫʔυ͔Βมߋ͓ͯ͜͠͏ w ҆શͳύεϫʔυͱʁʢ૯লࢀরʣ ໊લͳͲͷݸਓใ͔ΒਪଌͰ͖ͳ͍͜ͱ ӳ୯ޠͳͲΛͦͷ··༻͠ͳ͍͜ͱ ΞϧϑΝϕοτͱࣈ͕ࠞࡏ͍ͯ͠Δ͜ͱ దͳ͞ͷจࣈྻͰ͋Δ͜ͱ ྨਪ͍͢͠ฒͼํͦͷ༰қͳΈ߹Θͤʹ͠ͳ͍͜ͱ
ύεϫʔυͷ࠷େղಡ࣌ؒ https://www.ipa.go.jp/security/txt/2008/10outline.html
ΞοϓσʔτΛ͢Δ w 8PSE1SFTTίΞͷߋ৽ʢϚΠφʔࣗಈʣ w ϓϥάΠϯςʔϚͷߋ৽ w ίΞWFSʹରԠ͍ͯ͠Δ͔֬ೝ͢Δ͖
ϓϥάΠϯͷબͼํ
όοΫΞοϓΛऔಘ͠Α͏ w ΞοϓσʔτΛ࣮ߦͯ͠ը໘͕ਅͬനʹʜ w ͦΜͳ࣌ʹɺόοΫΞοϓσʔλͰ෮ݩ͠·͢ w "MMJO0OF81.JHSBUJPO͕ʢݸਓతʹʣ͓͢͢Ί ˠόοΫΞοϓऔಘͱ෮ݩ͕؆୯ w ීஈ͔ΒఆظతͳόοΫΞοϓΛεέδϡʔϧԽ͢Δ
ϩάΠϯ63-Λมߋ͢Δ IUUQTTBNQMFDPNXQMPHJOQIQ
ϩάΠϯ63-Λมߋ͢Δ w खಈͰରԠՄೳ ˠϋʔυϧ͕ߴ͍ͷͰϓϥάΠϯͰػೳՃ͕Φεεϝ w 4JUF(VBSE811MVHJO w ʲҙʳ༗ޮԽͨ͠Βඪ४ઃఆͰϩάΠϯ63-͕มߋ ͞Εͯ͠·͏ͷͰѻ͍ʹҙ w
Ճ͑ͯϩάΠϯը໘ʹ#"4*$ೝূΛ͚Δͱ͍͏ख
44-Խ w 4FDVSF4PDLFUT-BZFSͷུ w ΣϒαΠτͱσόΠεʢ1$ͳͲʣͱͷؒͰΓऔΓ͢ ΔσʔλΛ҉߸Խͯ͠౪Έʹ͘͘͢ΔΈ w IUUQTʙͰΞΫηεͰ͖ΔΣϒαΠτରԠࡁΈ w (PPHMF$ISPNFͳͲͰରԠ͍ͯ͠ͳ͍ͱʮอޢ͞Εͯ
͍ͳ͍௨৴ʯͱදࣔ͞ΕͨΓ͢Δ
44-Խͷํ๏ w ར༻͍ͯ͠ΔαʔϏεαʔόʔʹΑ༷ͬͯʑͳͷͰҰ ֓ʹํ๏ΛఏࣔͰ͖ͳ͍ w طଘΣϒαΠτΛରԠ͢Δ߹ɺαΠτʹઃஔ͞Ε ͍ͯΔϦϯΫશ͕ͯIUUQTʙʹͳ͍ͬͯͳ͍ͱશͳ 44-ԽʹͳΒͳ͍ʢNJYFEDPOUFOUʣ w దʹΒͣʹ༗ࣝऀʹ૬ஊ͢Δ͜ͱΛ͓קΊ͠·͢
8"'ಋೖ w 8FC"QQMJDBUJPO'JSFXBMMͷུ w αʔόʔଆPSϓϥάΠϯͰͷಋೖ͕Ұൠత w 9TFSWFSϩϦϙTBLVSBར༻Մೳ w 8PSEGFODF4FDVSJUZ'JSFXBMM.BMXBSF4DBOͳͲ w
81ɾϓϥάΠϯͷػೳʹΑΔΞΫηεΛޡͬͯःஅͯ͠ ͠·͏͜ͱ͕͋Δˠνϡʔχϯά͕ඞཁͳ߹͋Δ
Θͳ͍ςʔϚɾϓϥάΠϯͷ ແޮԽআ w ඪ४Ͱ5XFOUZʙςʔϚ͕ෳΠϯετʔϧ͞Ε͍ͯΔ͕ ෆཁͳΒআʢఆظతʹߋ৽͍ͯ͠Ε0,ʣ w Θͳ͍PSݹ͍ϓϥάΠϯɺআPSΓ͑ʢஔ͖ ͑ʣΛݕ౼͢Δ w ఆظతʹ֬ೝ͢Δश׳Λ࣋ͭͱϕλʔ
·ͱΊ w *%ͱ18ΦϦδφϦςΟΛ࣋ͭ w ߋ৽͠ͳ͍ͳΒ8PSE1SFTTΘͳ͍ʢ͘Β͍ͷؾ࣋ͪͰʣ w όοΫΞοϓඞਢʢ෮ݩ࿅शͯ͠ΈΑ͏ʣ w ϩάΠϯ63-Λมߋͯ͠#"4*$ೝূซͤΔͱ٢ w
44-ԽࠓৗࣝʢඞਢʣϨϕϧ