Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Features
Speaker Deck
PRO
Sign in
Sign up for free
Search
Search
2017/08/25
Search
tanakata
August 25, 2017
0
46
2017/08/25
tanakata
August 25, 2017
Tweet
Share
More Decks by tanakata
See All by tanakata
20171201
tanakata
0
37
20171110
tanakata
0
47
1013
tanakata
0
50
徳丸0922
tanakata
0
75
0901
tanakata
0
42
0802徳丸.pdf
tanakata
0
50
徳丸20170721.pdf
tanakata
0
39
Featured
See All Featured
Beyond borders and beyond the search box: How to win the global "messy middle" with AI-driven SEO
davidcarrasco
1
49
Building a Scalable Design System with Sketch
lauravandoore
463
34k
Facilitating Awesome Meetings
lara
57
6.8k
Thoughts on Productivity
jonyablonski
74
5k
What does AI have to do with Human Rights?
axbom
PRO
0
2k
AI Search: Implications for SEO and How to Move Forward - #ShenzhenSEOConference
aleyda
1
1.1k
DevOps and Value Stream Thinking: Enabling flow, efficiency and business value
helenjbeal
1
92
Music & Morning Musume
bryan
47
7.1k
The B2B funnel & how to create a winning content strategy
katarinadahlin
PRO
0
270
Lightning Talk: Beautiful Slides for Beginners
inesmontani
PRO
1
440
Utilizing Notion as your number one productivity tool
mfonobong
3
220
Faster Mobile Websites
deanohume
310
31k
Transcript
2017/08/25 ಙؙຊྠಡձ ϑΝΠϧΞοϓϩʔυʹ·ͭΘΔ
ϑΝΠϧΞοϓϩʔυʹ·ͭΘΔ
ϑΝΠϧΞοϓϩʔυʹର͢Δ߈ܸ ɾΞοϓϩʔυػೳʹର͢ΔDOS߈ܸʢాʣ ɾαʔόʔ্ͷϑΝΠϧΛεΫϦϓτͱ࣮ͯ͠ߦ͢Δ߈ܸʢాʣ ɾֻ͚ΛؚΉϑΝΠϧΛར༻ऀʹμϯϩʔυͤ͞Δ߈ܸʢXSSʣʢຢʣ ϑΝΠϧΞοϓϩʔυʹ·ͭΘΔ:࣮ʹෆඋ͕͋Δͱ༷ʑͳ੬ऑੑ͕ੜ·ΕΔ
ϑΝΠϧΞοϓϩʔυʹର͢Δ߈ܸ ɾΞοϓϩʔυػೳʹର͢ΔDOS߈ܸ→DOS߈ܸͱʁ ɾαʔόʔ্ͷϑΝΠϧΛεΫϦϓτͱ࣮ͯ͠ߦ͢Δ߈ܸ
ϑΝΠϧΞοϓϩʔυʹର͢ΔDOS߈ܸ ˕DOS(DENIAL OF SERVICE)߈ܸ αʔόʔʹରͯ͠ڊେͳϑΝΠϧΛ࿈ଓͯ͠ૹ৴͢Δ͜ͱʹΑ ΓWEBαΠτʹաେͳෛՙΛ͔͚Δ ˕Өڹ ɾӨڹԠͷԼ ɾ࠷ѱͷ߹ɺαʔόͷఀࢭ
ϑΝΠϧΞοϓϩʔυʹର͢ΔDOS߈ܸ ˕ରࡦ ΞοϓϩʔυϑΝΠϧͷ༰ྔ੍ݶ͕༗ޮ PHPͷ߹ PHP.INI Ͱઃఆ͢Δ͜ͱ͕Ͱ͖Δɻ
ϑΝΠϧΞοϓϩʔυʹର͢Δ߈ܸ ɾΞοϓϩʔυػೳʹର͢ΔDOS߈ܸ ɾαʔόʔ্ͷϑΝΠϧΛεΫϦϓτͱ࣮ͯ͠ߦ͢Δ߈ܸ ɾֻ͚ΛؚΉϑΝΠϧΛར༻ऀʹμϯϩʔυͤ͞Δ߈ܸ
αʔόʔ্ͷϑΝΠϧΛεΫϦϓτͱ࣮ͯ͠ߦ͢Δ߈ܸ ˕֓ཁ Ξοϓϩʔμͷதʹར༻ऀ͕Ξοϓϩʔυͨ͠ϑΝΠϧΛWEBαʔόͷ ެ։σΟϨΫτϦʹอଘ͢Δͷ͕͋ΔɻϑΝΠϧͷ֦ுࢠ͕PHPͷΑ͏ ͳεΫϦϓτݴޠ͕ΞοϓϩʔυͰ͖ͯ͠·͏ͱWEBαʔό্Ͱ࣮ߦͰ͖ ͯ͠·͏ɻ ˕Өڹ ֎෦͔ΒεΫϦϓτ͕࣮ߦ͞ΕΔ͜ͱͰOSίϚϯυɾΠϯδΣΫγϣϯͷةݥ͕͋Δɻ WEBαʔό্ͷϑΝΠϧͷӾཡɾվ͟Μɾআ ֎෦αʔόͷϝʔϧૹ৴
ϑΝΠϧ QIQͳͲ ެ։σΟϨΫτϦ
αʔόʔ্ͷϑΝΠϧΛεΫϦϓτͱ࣮ͯ͠ߦ͢Δ߈ܸ ˕߈ܸख๏ ߈ܸͰը૾ϑΝΠϧͷมΘΓʹεΫϦϓτΛΞοϓϩʔυ͢Δɻྫͱͯ͠ҎԼͷPHPεΫϦ ϓτΛΞοϓϩʔυ͢Δɻ Ξοϓϩʔυ͞ΕͨϑΝΠϧը૾Ͱͳ͍͕IMGཁૉͷ෦ʹɺ×ϚʔΫ͕දࣔ͞ΕΔɻ ϦϯΫΛΫϦοΫ͢ΔͱεΫϦϓτ͕࣮ߦ͞Εͯ /ETC/PASSWD ͕දࣔ͞ΕΔɻ ˕ରࡦ ֦ுࢠΛνΣοΫ͢Δ
Ξοϓϩʔυ͞ΕͨϑΝΠϧެ։σΟϨΫτϦʹஔ͔ͣɺεΫϦϓτܦ༝ͰӾ ཡͤ͞Δ HACK.PHP IUUQFYBNQMFKQPQFO@EJS)"$,QIQ
·ͱΊ ϑΝΠϧΞοϓϩʔυʹର͢Δ߈ܸ ɾΞοϓϩʔυػೳʹର͢ΔDOS߈ܸ →Ξοϓϩʔυ࣌ɺ༰ྔ੍ݶ ɾαʔόʔ্ͷϑΝΠϧΛεΫϦϓτͱ࣮ͯ͠ߦ͢Δ߈ܸ →֦ுࢠʢJPGɾPNGʣνΣοΫɾεΫϦϓτܦ༝ͰӾཡʢ࣮ߦͰ͖ͳ͍Α͏ʹʣ ɾֻ͚ΛؚΉϑΝΠϧΛར༻ऀʹμϯϩʔυͤ͞Δ߈ܸʢXSSʣʢຢʣ
͋Γ͕ͱ͏͍͟͝·ͨ͠ ϑΝΠϧΞοϓϩʔυʹ·ͭΘΔ
ֻ͚ΛؚΉϑΝΠϧΛར༻ऀʹμϯϩʔυͤ͞Δ߈ܸ ˕֓ཁ ߈ܸ༻ʢֻ͚ʣϑΝΠϧΞοϓϩʔυˠར༻ऀ͕ϑΝΠϧΛӾཡˠJSͷ ࣮ߦɺϚϧΣΞײછ ˕Өڹ ֎෦͔ΒεΫϦϓτ͕࣮ߦ͞ΕΔ͜ͱͰOSίϚϯυɾΠϯδΣΫγϣϯͷةݥ͕͋Δɻ WEBαʔό্ͷϑΝΠϧͷӾཡɾվ͟Μɾআ ֎෦αʔόͷϝʔϧૹ৴ ˕ରࡦ Ξοϓϩʔυ͞ΕͨϑΝΠϧެ։σΟϨΫτϦʹஔ͔ͣɺ
εΫϦϓτܦ༝ͰӾཡͤ͞Δ ϑΝΠϧ