Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
2017/08/25
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
tanakata
August 25, 2017
0
46
2017/08/25
tanakata
August 25, 2017
Tweet
Share
More Decks by tanakata
See All by tanakata
20171201
tanakata
0
37
20171110
tanakata
0
47
1013
tanakata
0
50
徳丸0922
tanakata
0
75
0901
tanakata
0
42
0802徳丸.pdf
tanakata
0
50
徳丸20170721.pdf
tanakata
0
39
Featured
See All Featured
VelocityConf: Rendering Performance Case Studies
addyosmani
333
24k
JavaScript: Past, Present, and Future - NDC Porto 2020
reverentgeek
52
5.8k
A Modern Web Designer's Workflow
chriscoyier
698
190k
DevOps and Value Stream Thinking: Enabling flow, efficiency and business value
helenjbeal
1
92
Art, The Web, and Tiny UX
lynnandtonic
304
21k
Jamie Indigo - Trashchat’s Guide to Black Boxes: Technical SEO Tactics for LLMs
techseoconnect
PRO
0
56
GitHub's CSS Performance
jonrohan
1032
470k
SEO for Brand Visibility & Recognition
aleyda
0
4.2k
[SF Ruby Conf 2025] Rails X
palkan
1
740
Facilitating Awesome Meetings
lara
57
6.8k
Practical Orchestrator
shlominoach
191
11k
Public Speaking Without Barfing On Your Shoes - THAT 2023
reverentgeek
1
300
Transcript
2017/08/25 ಙؙຊྠಡձ ϑΝΠϧΞοϓϩʔυʹ·ͭΘΔ
ϑΝΠϧΞοϓϩʔυʹ·ͭΘΔ
ϑΝΠϧΞοϓϩʔυʹର͢Δ߈ܸ ɾΞοϓϩʔυػೳʹର͢ΔDOS߈ܸʢాʣ ɾαʔόʔ্ͷϑΝΠϧΛεΫϦϓτͱ࣮ͯ͠ߦ͢Δ߈ܸʢాʣ ɾֻ͚ΛؚΉϑΝΠϧΛར༻ऀʹμϯϩʔυͤ͞Δ߈ܸʢXSSʣʢຢʣ ϑΝΠϧΞοϓϩʔυʹ·ͭΘΔ:࣮ʹෆඋ͕͋Δͱ༷ʑͳ੬ऑੑ͕ੜ·ΕΔ
ϑΝΠϧΞοϓϩʔυʹର͢Δ߈ܸ ɾΞοϓϩʔυػೳʹର͢ΔDOS߈ܸ→DOS߈ܸͱʁ ɾαʔόʔ্ͷϑΝΠϧΛεΫϦϓτͱ࣮ͯ͠ߦ͢Δ߈ܸ
ϑΝΠϧΞοϓϩʔυʹର͢ΔDOS߈ܸ ˕DOS(DENIAL OF SERVICE)߈ܸ αʔόʔʹରͯ͠ڊେͳϑΝΠϧΛ࿈ଓͯ͠ૹ৴͢Δ͜ͱʹΑ ΓWEBαΠτʹաେͳෛՙΛ͔͚Δ ˕Өڹ ɾӨڹԠͷԼ ɾ࠷ѱͷ߹ɺαʔόͷఀࢭ
ϑΝΠϧΞοϓϩʔυʹର͢ΔDOS߈ܸ ˕ରࡦ ΞοϓϩʔυϑΝΠϧͷ༰ྔ੍ݶ͕༗ޮ PHPͷ߹ PHP.INI Ͱઃఆ͢Δ͜ͱ͕Ͱ͖Δɻ
ϑΝΠϧΞοϓϩʔυʹର͢Δ߈ܸ ɾΞοϓϩʔυػೳʹର͢ΔDOS߈ܸ ɾαʔόʔ্ͷϑΝΠϧΛεΫϦϓτͱ࣮ͯ͠ߦ͢Δ߈ܸ ɾֻ͚ΛؚΉϑΝΠϧΛར༻ऀʹμϯϩʔυͤ͞Δ߈ܸ
αʔόʔ্ͷϑΝΠϧΛεΫϦϓτͱ࣮ͯ͠ߦ͢Δ߈ܸ ˕֓ཁ Ξοϓϩʔμͷதʹར༻ऀ͕Ξοϓϩʔυͨ͠ϑΝΠϧΛWEBαʔόͷ ެ։σΟϨΫτϦʹอଘ͢Δͷ͕͋ΔɻϑΝΠϧͷ֦ுࢠ͕PHPͷΑ͏ ͳεΫϦϓτݴޠ͕ΞοϓϩʔυͰ͖ͯ͠·͏ͱWEBαʔό্Ͱ࣮ߦͰ͖ ͯ͠·͏ɻ ˕Өڹ ֎෦͔ΒεΫϦϓτ͕࣮ߦ͞ΕΔ͜ͱͰOSίϚϯυɾΠϯδΣΫγϣϯͷةݥ͕͋Δɻ WEBαʔό্ͷϑΝΠϧͷӾཡɾվ͟Μɾআ ֎෦αʔόͷϝʔϧૹ৴
ϑΝΠϧ QIQͳͲ ެ։σΟϨΫτϦ
αʔόʔ্ͷϑΝΠϧΛεΫϦϓτͱ࣮ͯ͠ߦ͢Δ߈ܸ ˕߈ܸख๏ ߈ܸͰը૾ϑΝΠϧͷมΘΓʹεΫϦϓτΛΞοϓϩʔυ͢Δɻྫͱͯ͠ҎԼͷPHPεΫϦ ϓτΛΞοϓϩʔυ͢Δɻ Ξοϓϩʔυ͞ΕͨϑΝΠϧը૾Ͱͳ͍͕IMGཁૉͷ෦ʹɺ×ϚʔΫ͕දࣔ͞ΕΔɻ ϦϯΫΛΫϦοΫ͢ΔͱεΫϦϓτ͕࣮ߦ͞Εͯ /ETC/PASSWD ͕දࣔ͞ΕΔɻ ˕ରࡦ ֦ுࢠΛνΣοΫ͢Δ
Ξοϓϩʔυ͞ΕͨϑΝΠϧެ։σΟϨΫτϦʹஔ͔ͣɺεΫϦϓτܦ༝ͰӾ ཡͤ͞Δ HACK.PHP IUUQFYBNQMFKQPQFO@EJS)"$,QIQ
·ͱΊ ϑΝΠϧΞοϓϩʔυʹର͢Δ߈ܸ ɾΞοϓϩʔυػೳʹର͢ΔDOS߈ܸ →Ξοϓϩʔυ࣌ɺ༰ྔ੍ݶ ɾαʔόʔ্ͷϑΝΠϧΛεΫϦϓτͱ࣮ͯ͠ߦ͢Δ߈ܸ →֦ுࢠʢJPGɾPNGʣνΣοΫɾεΫϦϓτܦ༝ͰӾཡʢ࣮ߦͰ͖ͳ͍Α͏ʹʣ ɾֻ͚ΛؚΉϑΝΠϧΛར༻ऀʹμϯϩʔυͤ͞Δ߈ܸʢXSSʣʢຢʣ
͋Γ͕ͱ͏͍͟͝·ͨ͠ ϑΝΠϧΞοϓϩʔυʹ·ͭΘΔ
ֻ͚ΛؚΉϑΝΠϧΛར༻ऀʹμϯϩʔυͤ͞Δ߈ܸ ˕֓ཁ ߈ܸ༻ʢֻ͚ʣϑΝΠϧΞοϓϩʔυˠར༻ऀ͕ϑΝΠϧΛӾཡˠJSͷ ࣮ߦɺϚϧΣΞײછ ˕Өڹ ֎෦͔ΒεΫϦϓτ͕࣮ߦ͞ΕΔ͜ͱͰOSίϚϯυɾΠϯδΣΫγϣϯͷةݥ͕͋Δɻ WEBαʔό্ͷϑΝΠϧͷӾཡɾվ͟Μɾআ ֎෦αʔόͷϝʔϧૹ৴ ˕ରࡦ Ξοϓϩʔυ͞ΕͨϑΝΠϧެ։σΟϨΫτϦʹஔ͔ͣɺ
εΫϦϓτܦ༝ͰӾཡͤ͞Δ ϑΝΠϧ