Webéçºè
ãæ
å ±ã»ãã¥ãªãã£å
¥éè
ã®ããã®Webãããã³ã°åŠç¿ïŒ
ãã€ã§ããã©ããªå±éºç¶æ³ã«ãæ£ç¢ºã«å¯Ÿå¿ããŠãã ããã
ðãªãWebããã¯ãç¥ãå¿
èŠããããŸããïŒ
æ»æãç¥ããªããã°é²åŸ¡ãèŠããŸãïŒé²åŸ¡è
ã®èгç¹ããWebãµãŒãã¹ãèŠãããããæ»æè
ã®èгç¹ããWebãµãŒãã¹ãèŠããšãããå€ãã®è匱æ§ãèŠããŸãïŒãŸããåã«å¯Ÿå¿çãç¥ããããæ»æãæ£ç¢ºã«ç¥ã£ãŠãããç¶æ³ã«ãµããããæ£ç¢ºãªå¯Ÿå¿çãåºãŠããŸãïŒ
WebãµãŒãã¹ã¯ä»ãã®ç¬éã«ãæ°ããäœæãããä¿®æ£ãããç¶ç¶çã«æ©èœãäœãããŠããŸãã Webãããã³ã°ã®ç¥èã¯éžæã§ã¯ãªãå¿
é ã§ãïŒ
ð¡Webéçºè
ãšæ
å ±ã»ãã¥ãªãã£å
¥éè
ã®ããã®è¬çŸ©ïŒ
Webéçºè
ãšæ
å ±ã»ãã¥ãªãã£å
¥éè
ã®ããã®Webãããã³ã°å
¥éè¬çŸ©ãšããŠãä»¥åŸæåè匱仮æ³ç°å¢ã§ããWebGoat/DVWA/ãããã¯ã¹(bWAPP)ã«ã€ããŠãè¬çŸ©ãéèšãããäºå®ã§ãããã®ã¬ãã¹ã³ã§ãŠã§ãããã¯å
¥éãå§ããŸãããïŒ
ïŒâ»éèšãããè¬çŸ©ã®è匱仮æ³ç°å¢ã¯ä»¥é倿ŽãããããšããããŸããïŒ
ðè¬çŸ©ãéããŠåŠã¶ããšãã§ãããã®ïŒ
æ¬è¬çŸ©ã§åŠã¶äž»ãªç®æ¬¡ã§ãã
- æ»æã®æŠå¿µ
- æ»æåäœåç
- æ»æå®ç¿
- 察å¿ç
- ã»ãã¥ã¢ã³ãŒãã£ã³ã°å®ç¿
ðè¬çŸ©ãéããŠåŠã¶ããšãã§ããWebãããã³ã°æ»æã¢ã€ãã ïŒ
æ¬è¬çŸ©ãéããŠåŠã¹ãWebãããã³ã°æ»æé
ç®ã¯åèš9åã§ãïŒ
- SQL Injection
- OS Command Injection
- XXE Injection
- XSS
- CSRF
- ãã¡ã€ã«ã®ããŠã³ããŒãã®è匱æ§
- ãã¡ã€ã«ã¢ããããŒãã®è匱æ§
- ãã©ã¡ãŒã¿å€èª¿ã®è匱æ§
- URLã¢ã¯ã»ã¹å¶éã®äžååãªè匱æ§
ðè©³çŽ°ãªæ»æåçåæãéããŠèŠããWebãããã³ã°æ»æã®äžæ žïŒ
Webãããã³ã°ã®è匱æ§é
ç®ããšã«è©³çŽ°ãªæ»æåçåæã«ãããããç°¡åã«åŠç¿ãå¯èœã«ãªããæ»æãšé²åŸ¡ã®èгç¹ããéåžžã«éèŠãªæ»æã®æ žå¿ãææ¡ã§ããŸãã
ðã©ã³ãã ã«åŸããªããåŠã¶ãWebãããã³ã°æ»æãšã»ãã¥ã¢ã³ãŒãã£ã³ã°ïŒ
ãã©ããŒããããå®ç¿ãé²è¡ãã倧éã®å®ç¿ãéããŠãŠã§ããããã³ã°æ»æã容æã«çè§£ããæ»æã ãã§ãªãçŽæ¥ã»ãã¥ã¢ã³ãŒãã£ã³ã°é©çšå®ç¿ãéããŠé²åŸ¡ãŸã§ããŠã¿ãå®ç¿ãé²ããŸãïŒ

ð§°å®è·µã®ããã®ä»®æ³ç°å¢ãæäŸïŒ
ç·Žç¿æã«äœ¿çšãããè匱ãªä»®æ³ç°å¢ã®Webãµã€ããæäŸãããŠããŸãã
ð¡ä»ã®Webãããã³ã°æè²ãšã¯ç°ãªãç¹åŸŽïŒè¬çŸ©ãèãã¹ãçç±ïŒ
ã¯ãªãã¯ãã£ãæè²ã®ç¹é·ã¯ãæ»æã®è©³çްãªåââåãããŸããŸãªæ»æã®å®è·µããããŠã»ãã¥ã¢ã³ãŒãã£ã³ã°ã®å®è·µã§ãã
ãããïŒã¯ãªãã¯ãã£ãã®æè²ã¯æ»æããã»ãã¥ã¢ã³ãŒãã£ã³ã°ãŸã§ãã¹ãŠã®ã³ãŒã¹ãå®ç¿ããåç°å¢ã«åãããŠå¯Ÿå¿ã§ããã¹ãã«ãŸã§è²ãŠãããšãã§ããŸãïŒ
ð¡å¿
é èŠèŽè¬åº§