Submit Search
Kobe sec#7 summary
0 likes
738 views
Yukio NAGAO
1 of 18
Download now
Download to read offline
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
More Related Content
ODP
ã©ã€ãã³ãŒãã£ã³ã°ãšãã¢ã§çè§£ããWebã»ãã¥ãªãã£ã®åºç€
Takahisa Kishiya
Â
PDF
130821 owasp zed attack proxyãã¶ãåã
Minoru Sakai
Â
PDF
Proxy War EPISODEâ ¡
zaki4649
Â
PPTX
SecurityCamp2015ããã°ãã³ãã£ã³ã°å ¥éã
Masato Kinugawa
Â
PPTX
ã€ã³ã¹ããŒã«ããã¢ãã¯ã¹ãŠãOSSã®è匱æ§ãããããèŠã€ããã
Yuji Kazan
Â
PDF
ãœãŒã¹ã§åŠã¶è匱æ§èšºæ - SmartTechGeeks #2
tobaru_yuta
Â
PDF
Webã¢ããªã±ãŒã·ã§ã³è匱æ§èšºæã«ã€ããŠ
tobaru_yuta
Â
PDF
MongoDBã®è匱æ§èšºæ - smarttechgeeks
tobaru_yuta
Â
ã©ã€ãã³ãŒãã£ã³ã°ãšãã¢ã§çè§£ããWebã»ãã¥ãªãã£ã®åºç€
Takahisa Kishiya
Â
130821 owasp zed attack proxyãã¶ãåã
Minoru Sakai
Â
Proxy War EPISODEâ ¡
zaki4649
Â
SecurityCamp2015ããã°ãã³ãã£ã³ã°å ¥éã
Masato Kinugawa
Â
ã€ã³ã¹ããŒã«ããã¢ãã¯ã¹ãŠãOSSã®è匱æ§ãããããèŠã€ããã
Yuji Kazan
Â
ãœãŒã¹ã§åŠã¶è匱æ§èšºæ - SmartTechGeeks #2
tobaru_yuta
Â
Webã¢ããªã±ãŒã·ã§ã³è匱æ§èšºæã«ã€ããŠ
tobaru_yuta
Â
MongoDBã®è匱æ§èšºæ - smarttechgeeks
tobaru_yuta
Â
Viewers also liked
(7)
PPTX
Practical security
Ron van der Molen
Â
PPT
Practical Network Security
Sudarsun Santhiappan
Â
PDF
Tybsc it sem5 advanced java_practical_soln_downloadable
Ajit Vishwakarma
Â
PPSX
Informática educação 1ª aula
jhecioosaki
Â
PPT
Tools for Designing Distance Learning Instruction
Marsha J. Chan
Â
PPT
The role of dissolution in the demonstration of bioequivalence
inemet
Â
PDF
2572008184802manual medicamentos injetaveis
karol_ribeiro
Â
Practical security
Ron van der Molen
Â
Practical Network Security
Sudarsun Santhiappan
Â
Tybsc it sem5 advanced java_practical_soln_downloadable
Ajit Vishwakarma
Â
Informática educação 1ª aula
jhecioosaki
Â
Tools for Designing Distance Learning Instruction
Marsha J. Chan
Â
The role of dissolution in the demonstration of bioequivalence
inemet
Â
2572008184802manual medicamentos injetaveis
karol_ribeiro
Â
Ad
Similar to Kobe sec#7 summary
(20)
PDF
Security issue201312
Riotaro OKADA
Â
PPTX
HTML5 Web ã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£
地 æå°
Â
PPTX
æ¥ã®è匱æ§ç¥ã 2017/06/13
dcubeio
Â
PPTX
ãšãã¹ã¿!!å匷äŒ#26 ã»ãã¥ãªãã£ãšéçºãš
Haga Takeshi
Â
PPTX
ã»ãã¥ã¢éçºã®<s>3ã€ã®</s>æµ
Riotaro OKADA
Â
PPT
ã»ãã¥ã¢ããã°ã©ãã³ã°è¬åº§
minoru-ito
Â
PDF
埳䞞æ¬ãã§ãããŸã§
Hiroshi Tokumaru
Â
PDF
Webã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£
Tokai University
Â
PDF
OWASPã®æ©ãæ¹ïŒHow to walk_the_owaspïŒ
Sen Ueno
Â
PDF
å®å šãªWebã¢ããªæ§ç¯1å
Project Samurai
Â
PPTX
20170408 securiy-planning
hogehuga
Â
PPTX
Browser andsecurity2015
地 æå°
Â
PDF
ãšãã蚺æå¡ãšè²ã åä»ãªè匱æ§é
zaki4649
Â
PPT
SEããèŠãæ å ±ã»ãã¥ãªãã£ã®èª²é¡
Katsuhide Hirai
Â
PDF
ãããµã2013ã15-C-8ãã»ãã¥ãªãã£èŠæ±ä»æ§ã¢ãã«ãã©ã³ã§æ¥æ¬ã¯å€ãããïŒïŒçŸç¬æå¹žæ°ïŒ
Developers Summit
Â
PDF
PHPã«ã³ãã¡ã¬ã³ã¹2014ã»ãã¥ãªãã£å¯Ÿè«è³æ
Yasuo Ohgaki
Â
PDF
ãœãŒã¹ã³ãŒãæ€æ»ã«èããã³ãŒããšã¯ïŒ
Yasuo Ohgaki
Â
PPTX
ä»äººäºã§ã¯ãªãWebã»ãã¥ãªãã£
Yosuke HASEGAWA
Â
PPTX
äžåžãä¿¡çšã§ããªãäŒç€Ÿã®å éšçµ±å¶ïœç¬¬32åWebSigäŒè°ã䟿å©ããšãæããšãå¿åŒ·ããšãæŠãäŒç€Ÿã®ããã®ç€Ÿå ã»ãã¥ãªã㣠2013幎ã®ã¹ã¿ã³ããŒããšã¯ïŒïŒ...
WebSig24/7
Â
PPTX
第32åWebSigäŒè°ãªãŒããã³ã°ã»ãã·ã§ã³
WebSig24/7
Â
Security issue201312
Riotaro OKADA
Â
HTML5 Web ã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£
地 æå°
Â
æ¥ã®è匱æ§ç¥ã 2017/06/13
dcubeio
Â
ãšãã¹ã¿!!å匷äŒ#26 ã»ãã¥ãªãã£ãšéçºãš
Haga Takeshi
Â
ã»ãã¥ã¢éçºã®<s>3ã€ã®</s>æµ
Riotaro OKADA
Â
ã»ãã¥ã¢ããã°ã©ãã³ã°è¬åº§
minoru-ito
Â
埳䞞æ¬ãã§ãããŸã§
Hiroshi Tokumaru
Â
Webã¢ããªã±ãŒã·ã§ã³ã®ã»ãã¥ãªãã£
Tokai University
Â
OWASPã®æ©ãæ¹ïŒHow to walk_the_owaspïŒ
Sen Ueno
Â
å®å šãªWebã¢ããªæ§ç¯1å
Project Samurai
Â
20170408 securiy-planning
hogehuga
Â
Browser andsecurity2015
地 æå°
Â
ãšãã蚺æå¡ãšè²ã åä»ãªè匱æ§é
zaki4649
Â
SEããèŠãæ å ±ã»ãã¥ãªãã£ã®èª²é¡
Katsuhide Hirai
Â
ãããµã2013ã15-C-8ãã»ãã¥ãªãã£èŠæ±ä»æ§ã¢ãã«ãã©ã³ã§æ¥æ¬ã¯å€ãããïŒïŒçŸç¬æå¹žæ°ïŒ
Developers Summit
Â
PHPã«ã³ãã¡ã¬ã³ã¹2014ã»ãã¥ãªãã£å¯Ÿè«è³æ
Yasuo Ohgaki
Â
ãœãŒã¹ã³ãŒãæ€æ»ã«èããã³ãŒããšã¯ïŒ
Yasuo Ohgaki
Â
ä»äººäºã§ã¯ãªãWebã»ãã¥ãªãã£
Yosuke HASEGAWA
Â
äžåžãä¿¡çšã§ããªãäŒç€Ÿã®å éšçµ±å¶ïœç¬¬32åWebSigäŒè°ã䟿å©ããšãæããšãå¿åŒ·ããšãæŠãäŒç€Ÿã®ããã®ç€Ÿå ã»ãã¥ãªã㣠2013幎ã®ã¹ã¿ã³ããŒããšã¯ïŒïŒ...
WebSig24/7
Â
第32åWebSigäŒè°ãªãŒããã³ã°ã»ãã·ã§ã³
WebSig24/7
Â
Ad
More from Yukio NAGAO
(8)
PPT
Neta 20161119-after
Yukio NAGAO
Â
PPT
Kobe sec#14 study
Yukio NAGAO
Â
PDF
THK_ITS #5 2010.11.13
Yukio NAGAO
Â
PDF
Atrandom.20101030
Yukio NAGAO
Â
PDF
Matcha445.20101023
Yukio NAGAO
Â
PDF
Kobe sec#8 summary
Yukio NAGAO
Â
PDF
Kobe sec#11 summary
Yukio NAGAO
Â
PDF
Kobe sec#12 summary
Yukio NAGAO
Â
Neta 20161119-after
Yukio NAGAO
Â
Kobe sec#14 study
Yukio NAGAO
Â
THK_ITS #5 2010.11.13
Yukio NAGAO
Â
Atrandom.20101030
Yukio NAGAO
Â
Matcha445.20101023
Yukio NAGAO
Â
Kobe sec#8 summary
Yukio NAGAO
Â
Kobe sec#11 summary
Yukio NAGAO
Â
Kobe sec#12 summary
Yukio NAGAO
Â
Kobe sec#7 summary
1.
第 7 å
ç¥æžæ å ±ã»ãã¥ãªãã£ååŒ·äŒ (ã»ãã¥ã¡ã) ãŸãšã 2009幎01æ10æ¥
2.
ã¹ã±ãžã¥ãŒã« 1. èªå·±ç޹ä»
ï§ ãä»å¹Žã®ã»ãã¥ãªãã£ã®æ±è² ãã¯ïŒ ï§ ä»åã®ããŒããWeb ã¢ããªã±ãŒã·ã§ã³ã®è匱æ§ããžã®èå³ã 2. Web AP è匱æ§ã®å®è·µ ï§ ç°¡åãªã¬ãã¹ã³ (ããŒã¯ãŒã玹ä») ï§ ã¹ããŒãž 1 : Web æ²ç€ºæ¿ã®æ¹ãã ï§ ã¹ããŒãž 2 : èšå®ãããŠããªããŠãŒã¶ã§ãã°ã€ã³ 3. ã°ã«ãŒããã£ã¹ã«ãã·ã§ã³ 1. çºæ³šã»ç®¡çã®åŽãããã©ã®ããã«è¡åããã°ãããïŒ 2. éçºè ãšããŠã©ãããã°ãããïŒ 3. ãã®ä»ãäž»ã«ãŠãŒã¶ãµã€ããšããŠæ°ã«ããããšããã¯ïŒ 4. éçšã»ä¿å®ãµã€ãã§ãã©ãè¡åãã¹ããïŒ
3.
èªå·±ç޹ä»#1 ï§ ååå 7
åã§ããããããšãããããŸãïŒïŒ ï§ ä»å¹Žã®ã»ãã¥ãªãã£æ±è² ï§ ãã»ãã¥ãªãã£ãããã³ããªåã ããã ï§ ãã¢ãåå¿èããããã©ã (ãã©ãã¯ãã³ããŒïœ) ãšéããã ï§ ä»å¹Žã¯ãã»ãã¥ãªãã£ãšãšã³ã¿ãŒãã€ã¡ã³ãããããŒãã«ïŒïŒ ï§ ãã»ãã¥ãªãã£ããã¯ã«ã«ã¿ ã¹ã¯ãªãŒã³ã»ã€ããŒããïŒ ï§ ã»ãã¥ãªãã£ã®æ®å ï§ åãããªãäººã«æšã説æã§ããããã«ãªãããã ï§ åã©ããçãŸãããïŒå±éºã«ããããããªããã ï§ ãéãããããã¯ãŒã¯ã®ã»ãã¥ãªãã£åŒ±ç¹ããææãããã ï§ å°æ¹ããã®æ å ±çºä¿¡ãïŒïŒ èªåããæ å ±çºä¿¡ããåŽãã«åãããã ï§ ãFirewall ç£èŠç«¯æ«ã®ç§çå©çšããšããäºä»¶ããããâãªãâ ããªã·ãŒ ãå®ããªããã°ãªããªãã®ããã«ã€ããŠèããã ï§ å¶çŽã ããããªããã¡ãªãããæäŸããªããšã
4.
èªå·±ç޹ä»#2 ï§ ä»å¹Žã®ã»ãã¥ãªãã£æ±è² ï§
ã¬ãã«ã¢ãã ï§ è©³ãããšãããç¥ããããäœéš (æ»æ) ããŠã¿ããïŒ ï§ P ããŒã¯ååŸãçæããç®ã§èŠã€ã€ãæ¬è³ªãèŠæ¥µããããè³æ Œãã ï§ ã»ãã¥ãªãã£ã®å匷ãç¶ãããã ï§ éçºã«ãŒã«ãäœã£ãŠããã©ãèªå㯠AP éçºããŠãªãã ï§ ç¥èã®ç¡ãç¶æ ã§éçšããäžå®ã ï§ Web AP ã¯äžéããã£ãã®ã§ãäœå±€ (NW) ã¬ã€ã€ã«ã ï§ ç§ã®ã¢ããªã¹ã詊éšãåæ Œããããã«ãæ¥åçµéšãç©ã¿ããã ï§ çŠå²¡ããæ¥ãŸãããè¥¿æ¥æ¬ã¯å¶èŠããã®ã§ãããã«ããããªå匷äŒã«ã ï§ ãã®ä» ï§ ã¹ãã ã¡ãŒã«ãæ²æ» ãããïŒïŒ ï§ ã€ã³ã·ãã³ããèµ·ãããªãããã ï§ Office ç³» AP ãã»ãã¥ãªãã£ã¯ïŒ
5.
èªå·±ç޹ä»#3 ï§ Web ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãžã®èå³
ï§ ç¥ããªã : 9% ï§ äœéšãªã : 82% (ããŒã¯ãŒãçšåºŠã¯ç¥ã£ãŠã) ï§ é²åŸ¡ã§ãã : 3% ï§ ãã¢ã§ãã : 6% ï§ æåŸ ãããšãã #1 ï§ å匷äŒã¹ã¿ããã§ãæãåãããããšç¡ããããããããã£ãŠãªããã ï§ æ¥œã«ãSecure AP ãäœãããã ï§ æ¬äŒŒç°å¢ãäœã£ãŠè·å Žã§äœéšãããŠã¿ããã-> ãã㯠OKã ï§ èšºæåãããããããããšããã ï§ AP äœã£ãŠããã©ãç¥ããªããçæŽ»ããæ¥ã ããæ»æã®æ€ç¥ããããã ï§ èªäœ AP ã«ãå€éšã«ãããããšããå®å šãªã®ïŒããšããäžå®ãããã
6.
èªå·±çŽ¹ä» #4 ï§ Web
ã¢ããªã±ãŒã·ã§ã³ã»ãã¥ãªãã£ãžã®èå³ ï§ æåŸ ãããšãã #2 ï§ PHP éçºããŠããXSS ããããšèšããããã©ãå®éã©ãããã°ïŒ ï§ è·å Žã§ã·ã¹ãã 管çãäœéšåã®æè²ã®ææ¬ãšãããã ï§ Web ãã¬ãŒããžã®äŸµå ¥ãã©ããã£ãŠæ€ç¥ããã®ïŒ ï§ æåœã®äŒå¡ãµã€ãã§å§èšæ¥è ã® AP ã®èšºæããŠããã£ããããã¯ãäž å®ãããã ï§ é²åŸ¡ã®ç¥èã身ã«ã€ãããã ï§ ãå®å šãªãŠã§ããµã€ãã®äœãæ¹ (IPA)ãã¯èŠãã ï§ ãæ»æãã人ããèŠãããšãç¡ããåäœéšïŒïŒ ï§ AP éçºã®äžéšããããã®ã®ããã ï§ ãã®ä» ï§ æçŽèªèšŒãç Žããã(ããŒã)å°æ¹ç©ºæž¯ã®ã»ãã¥ãªãã£ãçãçç±ïŒ ï§ "WordPress (PHP&MySQL ã®ããã°ããŒã«)" ãæ®åãããã!
7.
Web AP è匱æ§ã®å®è·µ
: ç°¡åãªã¬ãã¹ã³ ï§ æ¬æ¥ã¯ 110 çªã®æ¥ã§ãïœ çµ¶å¯ŸæªçšçŠæ¢ïŒïŒ ï§ ç°¡åãªçšèªèª¬æ ï§ ã ãããã以äžã®ããŒã¯ãŒãã¯çãããåç¥ã§ããã ï§ SQL ã€ã³ãžã§ã¯ãã§ã³ ï§ æ³šå ¥(injection) ãèªæºãSQL ã«éã£ãããŒã¯ãŒãã§ã¯ãªãã ï§ XSS (Cross Site Scripting) ï§ åäœåç : å ¥åããŒã¿ããšã¹ã±ãŒããããªããŸãŸ HTML äžã«åºåããã ã¿ã°æåãªã©ã HTML ãšè§£éããã¹ã¯ãªãããšããŠèµ·åãããã ï§ OS ã³ãã³ãã€ã³ãžã§ã¯ã·ã§ã³ ï§ OS ã®ã³ãã³ããæ³šå ¥ããã ã ï§ ããããµãŒã ï§ LAMP Appliance Linux ãããŒã¹ã«ã ï§ Apache + Perl + MySQL ã®æ²ç€ºæ¿ãµã€ã
8.
Web AP è匱æ§ã®å®è·µ
: ã¹ããŒãž 1 ï§ Web æ²ç€ºæ¿ã®æ¹ããã«ææŠ ï§ http://hostname.domain/~user/board/board.cgi ï§ ãŠãŒã¶ãšãã¹ã¯ãŒããæç€º ï§ ãããç°å¢ã¯ Packet Black Hole ã§ç£èŠïœ ï§ OS ã³ãã³ãã€ã³ãžã§ã¯ã·ã§ã³ ï§ éå§ 20 åã§ãã³ããåºãã ï§ ã¡ãŒã«ã¢ãã¬ã¹æ¬ ï§ å ¥åå€ãâ| echoã ï§ åã®æ¹ããã¯ãã³ãæç€ºåŸ 5 åã§ã ï§ 1 çªã®äººããã解説ã ï§ ãLinux ç°å¢ããOS ã³ãã³ãããéµ ï§ ãuser@domain;echo abc > index.htmlã ï§ sendmail ã³ãã³ãã®å ¥åå€ãã§ãã¯ãçãã ï§ OSã€ã³ãžã§ã¯ã·ã§ã³ãå¯èœ -> cgi ã®ãœãŒã¹ãèŠããŠããŸãã
9.
Web AP è匱æ§ã®å®è·µ
: ã¹ããŒãž 2 ï§ ç°å¢æºåããŠãæäžã«ããã¹ããŒãž 1 ã®æ»æãç¶ã ïœ ï§ ã¹ããŒãž 1 ã§äœ¿ã£ããã®ãšéããID ãšãã¹ã¯ãŒãã§ãã° ã€ã³ããŠã¿ããïŒ ï§ ã¹ããŒãž 1 ã§ã²ãããããboard.cgi ã«ãã³ããã ï§ éå§ 10 åã§ãã³ãæç€ºã ï§ ãã¹ã¯ãŒãæ¬ã« SQL ã€ã³ãžã§ã¯ã·ã§ã³ã ï§ ãâ (ã·ã³ã°ã«ã³ãŒããŒã·ã§ã³)ãããã€ã³ãã ï§ ãabc â or 1=â1ãã ï§ ãªã¢ã«ã¿ã€ã ã§ãSQL ã衚瀺ãããïœ ï§ å®éã«æãåãããŠäœéšããã€ãã³ãããããŸã ï§ Capture The Flag (CTF) æ±äº¬ã§å匷äŒãã£ãŠãŸãïŒïŒ ï§ æ¬¡åã»ãã¥ã¡ããããã§ãããŸãããïŒ
10.
ã°ã«ãŒããã£ã¹ã«ãã·ã§ã³çºè¡š #1 çºæ³šã»ç®¡ç ï§ ãåå ¥æ€æ»ãããŠãªããã管çã§ããŠãªããã®ãäžçªåé¡ ï§
çºæ³šåŽã®åé¡ ï§ ãèŠãç®éèŠãã§ããã®ä»ã¯åŸåãããšããæèã ï§ ã¹ãã«é¢ã§ãå ·äœçãªæè¡ã¯æããŠããªãã ï§ ç®¡çé¢ã§ãçŽæã®å³ãããã»ãã¥ãªãã£ã«æ°ãé ãäœè£ã奪ãã ï§ åæ³šåŽã®åé¡ ï§ æèãã¹ãã«ããã³ããããªãŸã§ããããã ï§ ç€ŸäŒç°å¢çã«ã¯ïŒ ï§ éçšæ¹é ï§ ããªãã¥ãŒã¢ã«ããªã©ã®ã€ãã³ãã奿©ãšããŠãæ€æ»ããããšãã ï§ ããã§ãã¯ãã€ã³ãããåŠäœã«èšãããã ï§ ãã®ä» ï§ ããµãŒãã¹å¯¿åœãã®èŠç¹ã§èãããã建ç¯ã«ãªããããã ï§ ãè¯ã Web AP æ€æ»ããŒã«ããããã°å£²ããïŒïŒ
11.
ã°ã«ãŒããã£ã¹ã«ãã·ã§ã³çºè¡š #1 çºæ³šã»ç®¡ç ï§ çºè¡šã§äœ¿ããããã€ã³ãããã
12.
ã°ã«ãŒããã£ã¹ã«ãã·ã§ã³çºè¡š #2 éçº ï§ ã³ãŒãã£ã³ã°ã«ãŒã«ã§æ±ºãŸãïŒ
ï§ èŠçŽã®ã»ãã¥ãªãã£ã¬ãã«ã¯ã©ã決ããïŒ ï§ å°éã®éšçœ²ã§å€æãã¡ãžã£ãŒãªã¢ã€ãã ã¯åæ ããæ¹éã§ã ï§ æ€æ»ã«ã€ããŠ ï§ çžäºãã§ãã¯ãã§ããã°è¯ããããäžäººã ãšäœè£ãç¡ã ï§ æ€æ»ããŒã«ã䜿ãã倧ãŸãã©ã€ã³ãæºãããããã«ããã°ããïŒ ï§ å®è£ ï§ ç¹æ®æåãã¯ãããå°çšã®ã¿ã°ã䜿ãã ï§ æ£èŠåã«äœ¿ãã¢ãžã¥ãŒã«ã§ã¯ãå¿ èŠ (èŠä»¶) ã«å¿ããŠç©Žãéããã ï§ ãŸãšãïŒ ï§ ãã¬ãŒã ã¯ãŒã¯æ¡çšã§ãã«ãŒã«ã«æ²¿ãã°ã(ã ããã) åé¡ã¯ãã ãªãã®ã§ã¯ïŒ ï§ ã¢ããªã±ãŒã·ã§ã³ã®ãããééãçããã©ãããã°ã£ãŠé©çšããïŒ
13.
ã°ã«ãŒããã£ã¹ã«ãã·ã§ã³çºè¡š #2 éçº ï§ QA
ï§ Q1. éçºæã«èŠããªãåé¡ç¹ã¯ã©ããã©ããŒããïŒ ï§ A1. ä¿å®ã¡ãã¥ãŒã«ãã¢ããªã±ãŒã·ã§ã³æ¹çã ãã§ãªããã€ã³ãã© é¢ã§ã®ãã©ããŒãå ããïŒ ï§ Q2. ãããé©çšã«äŒŽãã³ã¹ãã¯ã©ãèããïŒ ï§ A2. 圱é¿ç¯å²ãšã³ã¹ãèŠåãã§ãé©çšå¯åŠã決ããïŒ
14.
ã°ã«ãŒããã£ã¹ã«ãã·ã§ã³çºè¡š #3 ãã®ä» ï§ ããŒãèªäœãå®ãŸã£ãŠããªãã ï§
ã¡ã³ããŒã¯ IT ç³»ãäžåŠç(ãããçºè¡šè ïŒ)ã蟲æ¥ã®æ¹ïŒ ï§ çºè¡šå 容ã¯å€§å€ãã£ãããšãããã®ã§ããã ï§ ãŠãŒã¶ãšããŠä¿¡é Œã§ãããµã€ãã®æ±ºãæ¹ ï§ æè¡ã¬ãã«ãçµç¹ã®ä¿¡é Œæ§ïŒ ï§ åŠæ ¡ã§æããŠãããªããå ·äœäŸãã ããŠã¿ããïŒ ï§ J-SOX ã¯äŒæ¥ãã察å¿ããŠãªãã ï§ äºº (ã¹ãã«ã¬ãã«) äŸåã®ã»ãã¥ãªãã£ã ï§ æ®é (å°èŠæš¡) ã®ç°å¢ã§ã¯ããã ï§ ã»ãã¥ãªãã£ã«èå³ãé¢å¿ãããã ï§ ã§ãã宿 ãã€ããŠããªãã ï§ ãæ®éã®äººãã®æèãäžããã«ã¯ïŒ
15.
ã°ã«ãŒããã£ã¹ã«ãã·ã§ã³çºè¡š #4 éçš ï§ ã¡ã³ãã®å°ã£ãããš
ï§ ãŠãŒã¶ (ç¥ããªã人) ã«å®å šã«äœ¿ã£ãŠãããå¿ èŠãããã ï§ éçšãšéçºãåãããããŒã æ§æã«åé¡ã ï§ äžåœããããã¡ã³ããŒã¯ãæ å ±ããã¹ãŠæã¡åž°ããããã ï§ æ»æãç¥ã ï§ ãæ»æããããã倿ããã«ã¯ãæ¢åã®æ»æãç¥ããããªãã ï§ ãã°ããŒã¹ã§ã¯ãäºè±¡ãåŸãã远ãããšããã§ããªãã ï§ é²ãã«ã¯ ï§ æ»æãç¡ããã被害 (èŠãã广) ããªãã ï§ åµãå ããé¶ãå ãã ï§ è²»çšå¯Ÿå¹æã説æã§ããªãã ï§ ããã (æŽæ°ããã°ã©ã ) ãåœãŠã (é©çšãã) é »åºŠ ï§ ãåºããåœãŠãããåœãŠãŠããèãããã®æ¹éãšãã¹ãã§ã¯ïŒ ï§ ãããã®èŠåŠãã©ã倿ããã®ïŒ
16.
ã°ã«ãŒããã£ã¹ã«ãã·ã§ã³çºè¡š #4 éçš ï§ ã·ã¹ãã ã®ããŒãžã§ã³ã¢ãã
ï§ éçšããŠãã以äžãäžããå¿ èŠã¯ãããã ï§ é¢ããããŒãžã§ã³ã®ã¢ããã°ã¬ãŒãã«æ©ã ï§ äŸãã°ãWindows 2000 Server ãã Windows Server 2008 ï§ æ å ±ã®åé ï§ æ å ±ã®æš¹æµ·ãããã©ãä¿¡é Œã«è¶³ããã®ãéžã³åºãã®ãã ï§ ãã»ãã¥ãªãã£ããŒã« memoããèåã ãã©ãç²ä¿¡ãããã®ã§ã¯ ãªãã ï§ è£œåã®æŽæ°æ å ±ã¯ïŒ ï§ Windows ã¯æ å ±æäŸãããŠããããOSS ã®å Žåã¯ïŒ ï§ æåãµããŒããæäŸããäŒæ¥ã¯ãããã©ãå°èŠæš¡ã®ãšããã§ã¯å¥çŽ ãèŸãã ï§ çµå±ããµã€ããŒããŒã¬ãŒãæŠæ³ïŒ
17.
ã°ã«ãŒããã£ã¹ã«ãã·ã§ã³çºè¡š #4 éçš ï§ ãŸãšã
ï§ èšèªã®å£ã¯èŸããè±èªãäžåœèªã ï§ æ å ±åéãè¡ãããæ å ±ãå ±æãããã ï§ ä»®æ³ç°å¢ãæå¹ã« (ãã¹ãã«) 䜿ããïŒïŒ ï§ VMware ESXi Server ã Hyper-V ãªã©ãç¡åã§æäŸãããŠãããã ï§ QA ï§ Windows Update, Linux ã® yum ã«ããèªåã¢ããããŒãã¯ïŒ ï§ å®éã«ãµãŒãç°å¢ãèªåã¢ããããŒãã«ããŠãããšããããããã ãããŸã§åé¡ãèµ·ããããšããªãïŒïŒïŒ
18.
æåŸã« ï§ äŒå Žããçšæããã ãããã²ãããæ å ±æè²æ©æ§(CMU æ¥
æ¬æ ¡) ã®çããããã€ãæè¬ããŠããŸãã ï§ ã¹ããŒã«ã®ãŸã£ã¡ãã ããµããããæ¬åœã«ããããšããã ããŸãã ï§ ãããŠãåå ãããçããããããšãããããŸãïŒïŒ
Download