Slide 1

Slide 1 text

cloudpack flow Deep Security operation TIPS The meaning of tuning telling you softly

Slide 2

Slide 2 text

cloudpack ྲྀ Deep Security ͷӡ༻ TIPS νϡʔχϯάͷۃҙΛͦͬͱ͋ͳͨʹ

Slide 3

Slide 3 text

Who am I ? • ٢ాͻΖ͔ͣ ( hirokazu yoshida )
 Security Engineer at cloudpack http://qiita.com/fnifni

Slide 4

Slide 4 text

607

Slide 5

Slide 5 text

ਪ঑ઃఆͷݕࡧͰ͸ ਪ঑͞ΕΔ͜ͱ͕ͳ͍ϧʔϧୡ͕ ͋Γ·͢

Slide 6

Slide 6 text

୅දతͳਪ঑͞ΕΔ͜ͱ͕ͳ͍ϧʔϧୡ • 1000608 - Generic SQL Injection Prevention • 1000552 - Generic Cross Site Scripting(XSS) Prevention

Slide 7

Slide 7 text

͜ͷϧʔϧͬͯDSͷWAFػೳͰ͠ΐʁ ͳΜͰਪ঑͞Εͳ͍ͷʁ

Slide 8

Slide 8 text

ͩͬͯνϡʔχϯάେม͡ΌΜ ʢதͷਓஊʣ

Slide 9

Slide 9 text

ͦΜͳΘ͚Ͱ νϡʔχϯάϙΠϯτΛ঺հ

Slide 10

Slide 10 text

ϧʔϧͷੑ࣭Λ஌Δ

Slide 11

Slide 11 text

ϧʔϧͷಛੑΛ஌Δ • 1000608
 Generic SQL Injection Prevention SQL ΠϯδΣΫγϣϯ߈ܸͰ Α͘࢖ΘΕΔจࣈɾه߸Λ ݕ஌͢Δϧʔϧ

Slide 12

Slide 12 text

ϧʔϧͷಛੑΛ஌Δ • 1000552
 Generic Cross Site Scripting(XSS)
 Prevention XSS߈ܸͰ Α͘࢖ΘΕΔจࣈɾه߸Λ ݕ஌͢Δϧʔϧ

Slide 13

Slide 13 text

߈ܸ௨৴ͱਖ਼ৗ௨৴ͷݟۃΊ

Slide 14

Slide 14 text

߈ܸ௨৴Λݕ஌ͨ͠έʔε GET /index.htm?mode=pc'+ORDEr+By+999+--+; HTTP/1.1 GET /?1=@ini_set(\"display_errors\", \"0\");@set_time_limit(0);@set_magic_quotes_runtime(0);echo '->|';file_put_contents(dirname(['SCRIPT_FILENAME']).'/cache/ cachee.php','');echo '|<-'; HTTP/1.1"

Slide 15

Slide 15 text

ਖ਼ৗ௨৴Λݕ஌ͨ͠έʔε token=uzWoZpwAFsGfXcosY86KcfWLGnMuNIonRM1+zorRM RHrRj8S2D4LbIztTXa58mT90g8U+3YnfFnEA6PNY2xLHg= token=uzWoZpwAFsGfXcosY86KcfWLGnMuNIonRM1%2Bzor RMRHrRj8S2D4LbIztTXa58mT90g8U %2B3YnfFnEA6PNY2xLHg%3D

Slide 16

Slide 16 text

Ͱ͸͜Ε͸ʁ POST /system/page/setting_tag HTTP/1.1 _method=POST&data[CompanyMaterial] [all_pages_tag]=\r\n\tconsole.log('hoge');\r\n</ script>&data[CompanyMaterial][entry_complete_tag]=

Slide 17

Slide 17 text

ਖ਼ৗΛ஌Βͳ͍ͱ ҟৗΛ஌Δ͜ͱ͸Ͱ͖·ͤΜ

Slide 18

Slide 18 text

γεςϜ͸ੜ͖෺ γεςϜͷݸੑΛ஌Γ ೔ʑͷӡ༻Ͱݕ஌܏޲Λ஌Δ͜ͱ͕ νϡʔχϯάͷۃҙ

Slide 19

Slide 19 text

Thank you !