ã©ãã«ããªãã£ãSQLã€ã³ãžã§ã¯ã·ã§ã³é«åºŠ/å¿çšæ»æææ³ïŒ
æš¡æ¬ãããã³ã°æ»æã®æ°ããæ¹åãæç€ºããŸãã
ðæš¡æ¬ãããã³ã°å®åè
ãç¥ããããSQLã€ã³ãžã§ã¯ã·ã§ã³æ»æã·ãªãŒãºïŒ
- PART(1) : åºç€ / å®åæ»æ / ã»ãã¥ã¢ã³ãŒãã£ã³ã°âååã®è¬çŸ©
SQL Injection æ»æã§æãéèŠãªå
å®¹ãæ±ããã¬ãŒãã³ã°ã§ãåºç€ããå®åã§äœ¿çšãããæ»æææ³ããããŸããŸãªå¯Ÿå¿çãã»ãã¥ã¢ã³ãŒãã£ã³ã°ãåŠã¶ããšãã§ããŸãã以åŸè¡ãããæè²ã®åºæ¬ãšãªãå¿
é æè²ã§ãã
- PARTïŒ2ïŒïŒå¿çš/æ·±å/äžçŽâçŸåšã®è¬çŸ©
PART(1) ã§æ±ã£ãŠããªãå¿çšæ»æææ³ãšé«åºŠãªæ»æææ³ã«ã€ããŠã®æè²ã§ãã
- PART(3) : èªååããŒã«ã®è£œäœâ補äœäºå®
åŠãã æ»ææè¡ãèªååããŒã«ã«ãã®ãŸãŸé©çšããŠãPythonããŒã¹ã®èªååããŒã«ãäœæãããã¬ãŒãã³ã°ã§ãã
ð SQL Injection Part 1&2ã®éãïŒ
以åã®ã¬ãã¹ã³PartïŒ1ïŒã¯ãæ»æã®åºç€ãšååããããŠæ»æã®éèŠãªçè«ãšå®è·µã«ã€ããŠã®ã¬ãã¹ã³ã ã£ãå Žåããã®ã¬ãã¹ã³ã¯SQLã€ã³ãžã§ã¯ã·ã§ã³æ»æã®ãã¯ããã¯éšåãã«ããŒããŸãããããã£ãŠãPart(1)ã¯æ¬è¬çŸ©ã®éªšæ Œãšãªãè¬çŸ©ã§ããŸãPart(1)è¬çŸ©ãåè¬ããŠããPart(2)è¬çŸ©ãèãããšããå§ãããŸãã
ð SQL Injectionæ»æãã©ãããã®ïŒ
以äžã®é
ç®ã«è©²åœããå Žåã¯ãæ¬è¬çŸ©ãéããŠæ¶Œãã解決ãå¯èœã§ãïŒ
- æ²ç€ºæ¿ã«æçš¿ããªãç°å¢ã§æ»æã§ããªãã£ãããTime-Basedæ»æãé²ãããããŸããã§ãããïŒ
- Error-Based, Union-Based æ»ææã«äžã€äžã€ãã€ããŒã¿æœåºãããŸããã§ãããïŒ
- Blind-Basedæ»ææã«1ã€ã®æåæšè«ã®ããã«å°ãªããšã7åèŠæ±ããŸããã§ãããïŒ
- DBãšé£åãããã¡ã€ã«ããŠã³ããŒãæ©èœã«å¯ŸããŠãã¡ã€ã«ããŠã³ããŒãã®èåŒ±æ§æ»æãå¯èœã§ããããšããåç¥ã§ãããïŒ
- DBãšé£åãããã¡ã€ã«ããŠã³ããŒãæ©èœã«å¯ŸããŠãUnion-Basedæ»æã«ããããŒã¿æ€çŽ¢æ»æãå¯èœã§ããããšããåç¥ã§ãããïŒ
ð¡ãã®è¬çŸ©ãå¿
ãåè¬ããªããã°ãªããªãçç±ïŒ
æ¬è¬çŸ©ã§ã¯åŸæ¥ç¥ãããŠããæ»æææ³ãåãäžããŠããŸãããããç¥ãããæ»æææ³ã§ã¯ãªããçŽæ¥ç ç©¶ãéããŠèª¿ã¹ãææ³ã«ã€ããŠãåãäžããŠããŸããããã¯ãBlind-Based SQL Injectionæ»æã«å¯Ÿããæ°ããæ¹åæ§ãæç€ºããæ»ææè¡ã§ãïŒ
ãã®æ»æææ³ã«ãããåŸæ¥ç¥ãããŠããæ»æææ³ããããããé«éã§å¹æçã«ããŒã¿ãç
§äŒã§ããæ¹æ³ã«ã€ããŠãè¬çŸ©ã§åãäžããŠããŸãïŒ
ããã§âŠå®åè
ãã¡ã¯å¿
ããã®è¬çŸ©ãèããªããã°ãªããŸããïŒ
ðåDBMSã®PHPããŒã¹ã®ç·Žç¿æ²ç€ºæ¿ãæäŸïŒ
PHP-MYSQLãPHP-MSSQLãPHP-ORACLEããŒã¹ã®ç·Žç¿æ²ç€ºæ¿ãæäŸããããã«ããæ§ã
ãªDBMSå¥SQLã€ã³ãžã§ã¯ã·ã§ã³å®ç¿ãå¯èœã§ãã
ðð»ââïž è³ªå Q&A
Q. Part(1)è¬çŸ©ãåè¬ããŠããŸããããPart(2)è¬çŸ©ãçè§£ã§ããŸããïŒ
A. Part(1)è¬çŸ©ãå¿
ãåè¬ããããšããå§ãããŸãããããŠãSQLã€ã³ãžã§ã¯ã·ã§ã³æ»æã®çè§£ãååã«ãªã£ãç¶æ
ã§ããã®è¬çŸ©ãèãããšããå§ãããŸããããPart(1)ã®åè¬ã¯ããŠããªããSQL Injectionæ»æã«ã€ããŠã®ç¥èãååããã°Part(2)ã®åè¬ã«å€§ããªåé¡ã¯ãªããã䜿çšãããåç§°ãåãããªãå
容ããããããããªãã®ã§ãPart(1)ã®è¬çŸ©ãåè¬ããããšããããããé¡ãããŸãã
Q. å®åã§ããã«é©çšã§ããæ»ææè¡ã§ããïŒ
A. ã¯ããåœç¶ã§ãïŒããã«é©çšã§ããåŸæ¥æè¡ãããå¹ççã«æ»æãå¯èœã§ãã
Q. å¯Ÿå¿æ¹æ¡ã«ã€ããŠã®å
容ããããŸããïŒ
A. ãããããããŸãããå¯Ÿå¿æ¹æ¡ã®éšåã¯Part(1)è¬çŸ©ãåç
§ããŠãã ããã
ð¡å¿
é èŠèŽè¬åº§
â»æ¬æè²PPTã«ã¯ãã€ããŒãæäŸããå
±æãã©ã³ããé©çšãããŠããŸãã