OKDT-IW02T6-JPNICdist.ppt



Similar documents
about Speaker! 岡田良太郎 1989 年神戸市立神戸工業高等専門学校電気工学科卒業 1999 年日本 Linux 協会運営委員 2001 年有限会社テューンビズ代表取締役就任 Allabout Linux ガイド担当 2002 年株式会社テックスタイル代表取締役就任 PHP カンファレ


10/ / /30 3. ( ) 11/ 6 4. UNIX + C socket 11/13 5. ( ) C 11/20 6. http, CGI Perl 11/27 7. ( ) Perl 12/ 4 8. Windows Winsock 12/11 9. JAV

shio_ PDF

集中講義 インターネットテクノロジー 第5回

内閣官房情報セキュリティセンター(NISC)

第3回_416.ppt

TCP/IP Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.3 Internet Week 2002 [2002/12/17] Japan Registry Service Co., Ltd. No.4 2

1 Linux UNIX-PC LAN. UNIX. LAN. UNIX. 1.1 UNIX LAN. 1.2 Linux PC Linux. 1.3 studenta odd kumabari studentb even kumabari studentc odd kumabari student

25 About what prevent spoofing of misusing a session information

2004 SYN/ACK SYN Flood G01P014-6

untitled

1 ARENA DNS CSR ID ( ).. I

ii II Web Web HTML CSS PHP MySQL Web Web CSS JavaScript Web SQL Web

今企業が取るべきセキュリティ対策とは策


IW2002-B5 1 Internet Week ( ) 9:30 12:30 ( ) Copyright 2002 All Rights Reserved, by Seiji Kumagai ADSL FTTH 24 IP LAN

main.dvi

¥Í¥Ã¥È¥ï¡¼¥¯¥×¥í¥°¥é¥ß¥ó¥°ÆÃÏÀ

5-5_arai_JPNICSecSemi_XssCsrf_CM_ PDF

MySQLにおけるシステム運用時のポイント

Copyright

WebSphere Application Server V5.0 for Linux Ver. 1.11

Mac OS X Server QuickTime Streaming Server 5.0 の管理(バージョン 10.3 以降用)

shibasaki(印刷用)

Si-R30取扱説明書

untitled

IW2001-B2 1 Internet Week 2001 ( ) Copyright 2001 All Rights Reserved, by Seiji Kumagai IW2001-B2 2 CodeRed Copyright 2001 All Rights

¥Í¥Ã¥È¥ï¡¼¥¯¥×¥í¥°¥é¥ß¥ó¥°ÆÃÏÀ

第2回_416.ppt

2

main.dvi

etrust Access Control etrust Access Control UNIX(Linux, Windows) 2

目次

スライド 1

FirePass Edge Client TM Edge Client LAN Edge Client 7.0 Edge Client Edge Client Edge Client Edge Client Edge Client Edge Client LAN Edge Client VPN Wi

超初心者用

2 Java 35 Java Java HTML/CSS/JavaScript Java Java JSP MySQL Java 9:00 17:30 12:00 13: 項目 日数 時間 習得目標スキル Java 2 15 Web Java Java J

Microsoft Word - Document forADMIN.doc

PowerGres on Linuxマニュアル

IP Windows Word Excel Web Web Word Excel XHTML CSS Web Windows Word Excel Web XHTML CSS

WIDE 1

WEBサービス超入門 mask.key

IT講習会


untitled

johokiso-internet

Web Web ( (SOAP (SOAP/http (WSDL UDDI 1. 2.XML 3. (XDoS http, https SOAP XML Web/App ( App

untitled

PowerGres on Linux HAマニュアル

インストール取扱説明書

10

プレゼンテーション

Microsoft PowerPoint - 情報システム pptx


"CAS を利用した Single Sign On 環境の構築"

Si-R180 ご利用にあたって

Vol. 9 No. 2 DNS. DNS IP.... leopard.loc. DNS. Mac OS X Server. Web Mac OS X Server Mac OS X Server.. DNS DNS DNS example.com DNS

FileMaker Server Getting Started Guide

konicaminolta.co.jp PageScope Net Care

(O) (N) (V) (N) kuins-pptp (N) 2


ohp.mgp

Web SOAP Internet Web REST SOAP REST 3 REST SOAP 4

1. 2

FileMaker WebDirect Guide

橡C16.PDF

07_経営論集2010 小松先生.indd

Northern Lights Server

CAS Yale Open Source software Authentication Authorization (nu-cas) Backend Database Authentication Authorization Powered by A

Mac OS X Server Windows NTからの移行

ORCA (Online Research Control system Architecture)

Installation and New Features Guide for FileMaker Pro 10 and FileMaker Pro 10 Advanced

dvi

総セク報告書(印刷発出版_.PDF

untitled

- 1 -

FileMaker 15 WebDirect ガイド

ホスティングサービス案内(CPI)

FileMaker Server 8 Administrator’s Guide

PostgreSQLによる データベースサーバ構築技法

<95F18D908F91955C8E862E707562>

untitled

Microsoft Word - # _Quick_Install_Guide_Final.doc

スライド 0

08+11Extra

C:/Temp/magicpot.dvi

クララパンフレット2011冬1P-P40

FileMaker Server Getting Started Guide

22 (266) / Web PF-Web Web Web Web / Web Web PF-Web Web Web Web CGI Web Web 1 Web PF-Web Web Perl C CGI A Pipe/Filter Architecture Based Software Gener

54 5 PHP Web hellow.php 1:<?php 2: echo "Hellow, PHP!Y=n"; 3:?> echo PHP C 2: printf("hellow, PHP!Y=n"); PHP (php) $ php hellow.php Hellow, PHP! 5.1.2

PDF


A B ( +A+B) H g H27 H28 H29 H30 189, , , , , , , , ,

ScreenOS 5.0 ScreenOS 5.0 Deep Inspection VLAN NetScreen-25/-50/-204/-208 HA NetScreen-25 HA Lite NetScreen-25 NetScreen-50) ALG(Application Layer Gat


Shonan Institute of Technology MEMOIRS OF SHONAN INSTITUTE OF TECHNOLOGY Vol. 41, No. 1, 2007 Ships1 * ** ** ** Development of a Small-Mid Range Paral

untitled

3. XML, DB, DB (AP). DB, DB, AP. RDB., XMLDB, XML,.,,.,, (XML / ), XML,,., AP. AP AP AP 検索キー //A=1 //A=2 //A=3 返却 XML 全体 XML 全体 XML 全体 XMLDB <root> <A

RouteMagic Controller RMC-MP200 / MP Version

Transcription:

Internet Week 2002 tutorial - T6 http://techstyle.jp/ riotaro@techstyle.jp

about Speaker 1989 1999 Linux 2001 Allabout Linux http://allabout.co.jp/computer/linux/ 2002 PHP 2002 CISA http://okdt.org/ riotaro@techstyle.jp

Web

cf.

:STRIDE Spoofing identity Tampering with data Repudiation Information disclosure Denial of Service attack Elevation of Privilege

IDC: HW: CPU ISP DNS ip FTP www smtp configuration logrotate ssh

1. Port Scan 20,22,80,8080, 2. Exploit Linux(ICMP), telnet, OpenSSH, Apache, DoS/DDoS, / HEAD GET 3. HTTP/HTTPS FORM FORM URL ( ) WWW DNS DB Admin

1. DNS JPNIC DNS DNS A 2. Cookie Cookie (/ ) XSS Cookie WWW DNS DB Admin

FORM URL ex. http://www.yahooo.co.jp?cmd=jump&url=http://foo.com&... (D)DoS DB 2 WWW DNS DB Admin

strcpy nervous

strcpy(d,s); if(strlen(s)< sizeof(d)){ strcpy(s, d); } strcpy/strncpy strncpy(d,s,n); s NULL d[sizeof(d)-1] = 0 ; strncpy(d, s, sizeof(d)); // s if(d[sizeof(d)-1]!= 0 ){ // s }

CR/LF gets/fgets

format string printf(inputbuf); // inputbuf prinft(%s, inputbuf); // sprintf

strcpy strcat strncpy strncat memcpy sprintf printf strlen gets, scanf, include, readfile, fopen, file, link, unlink, symlink, rename, rmdir, chmod, chown, chgrp, exec, system, passthru, popen ( ) p TechStyle WEB 2002

FORM WEB SQL include URL HTML Referer

XSS JavaScriptCookie Not Found SQL Error HTML exploit Cookie disable Cookie input validation

Cookie Spoofing Cookie RFC2965 7.2 Cookie Spoofing 1. victim.cracker.edu victim.cracker.edu session_id= 1234 2. spoof.cracker.edu session-id= 1111 Domain=.cracker.edu 3. victim.cracker.edu Cookie: $Version="1"; session_id="1234", $Version="1"; session_id="1111"; $Domain=".cracker.edu" victim.cracker.edu Cookie

input validation input validation, data cleaning URL HTML

%( ) GET URL %HH(H: ) URL ex. URL validation 1 ex. %00 (NULL), %0A( ), %20( ), %25( ) %2500 %00 NULL cf.url

(bang) ; (semi-colon) backslash) (colon), (comma) (minus) ex.!/bin/bash -f /etc/passwd ex.../../../../ *.png

<(lesser than) >(grater than) (double quote) (single quote) exploit Cookie ex. ex. ><script>alert(window.location);</script> ;alert(document.cookie); onmouseover= alert(document.cookie); ><script> alert(document.cookie);</script> ></a> <script> alert(document.cookie);</script> ;cat /etc/passwd >>/home/html/htdocs/index.html

HTML <p>,<bold>,<i>,<em>,<strong>,<pre>,<br> Well-formed exploit Javascript ex. <b onmouseover=[code]> </b> <img src= javascript:[code]> <style type= text/javascript >[code]</style>

PHP ereg_replace( [^0-9],,$data) addslashes($data) addcslashes (string str, string charlist) single,double, NULL slashing( ) quotemeta($data).+?[^](*)$ quote escapeshellcmd($data) escape nl2br ( $str ) <br /> htmlspecialchars ("<a href='test'>test</a>", ENT_QUOTES); HTML

WEB apache DB mysql / postgresql DB ID ACL IP

ID / Password hash hash DB ID WEB invisible /tmp/ WEB pay SQL DELETE unlink

XOR rand MD5 /

DoS DoS CPU WEB slashdot/ec NAT

Lim, John, Tuning Apache and PHP for Speed on Unix

...

... TCP/IP, Intel DoS ipchains Apache, SSH

OS UNIX, Linux (Debian,RedHat,Turbo,Miracle)

7.2? 7.3? rpm rebuilddb rpm -qa CVS, RCS

VMware

ab webalizer...

ML WEB TechStyle

WEB

Saltzer, J.H., and M.D. Schroeder, "The Protection of Information in Computer Systems," Proc. IEEE, Vol. 63, No. 9, Sept. 1975, pp. 1278-1308. Wall, Larry and Schwartz, Randal L. "Programming Perl" : Sebastopol, California : O'Reilly And Associates, 1992. Al-Herbish, Thamer, Secure UNIX Programming FAQ,1999 Wheeler, David A. Secure Programming for Linux and Unix HOWTO, 2002 Howard, M. and LeBlanc, David, WRITING SECURE CODE, 2002 RFC 2396, 2965 Lim, John, Tuning Apache and PHP for Speed on Unix,2001( http://php.weblogs.com/tuning_apache_unix )

Sier PR TechStyle Linux UNIX PHP Apache Postgres MySQL Linux Apache PHP MySQL PostgreSQL Ruby PHP Perl JavaScript HTML Flash IT RFC Ietf-draft W3C ODL BS7799...

Thank You Please feel free to mail me riotaro@techstyle.jp