RSS2.0 SiteMap °õºþ
Á°¤Ø   Ìá¤ë   ¼¡¤Ø

phf ¤È Count.cgi

CERT Coordination Center ¤È¤¤¤¦Êƹñ¤ÎÃÄÂΤ¬¤¢¤ê¡¢CERT Advisory¡¢CERT bulletin ¤È¤¤¤¦¡¢¥»¥­¥å¥ê¥Æ¥£¤Ë´Ø¤¹¤ë´«¹ð¤ò¿ï»þȯ¹Ô¤·¤Æ¤¤¤Þ¤¹¡£ºòǯ¤«¤éº£Ç¯¤Ë¤«¤±¤ÆºÆ»°È¯¹Ô¤µ¤ì¤Æ¤¤¤ë¤â¤Î¤Ë¡¢CGI´ØÏ¢¤Î¥»¥­¥å¥ê¥Æ¥£¤¬¤¢¤ê¤Þ¤¹¡£

¤³¤³¤Ç¤Ï¤â¤Ï¤ä¸ÅŵŪ¤È¤â¸À¤¨¤ë phf ¤Ë¤è¤ë¥Ñ¥¹¥ï¡¼¥ÉÀà¼è¡¢ºÇ¶á¤ÎÏÃÂê¤Ç¤¢¤ë Count.cgi ¤Î¥»¥­¥å¥ê¥Æ¥£¡¦¥Û¡¼¥ë¤ò¾Ò²ð¤·¤Þ¤·¤ç¤¦¡£¤Þ¤¿Ãí°Õ¿¼¤¤CGI½ñ¤­¤Ë¤Ï¾ï¼±¤«¤â¤·¤ì¤Þ¤»¤ó¤¬¡¢¥Õ¥©¡¼¥à¤Î½èÍý¤Ë´Ø¤¹¤ëÃí°Õ»ö¹à¤â½ñ¤¤¤Æ¤ª¤­¤Þ¤¹¡£

¡ü phf¤ò¤á¤°¤ëÏÃÂê

NCSA httpd ¤ä APACHE ¤Î phf ¥µ¥ó¥×¥ë CGI ¥¹¥¯¥ê¥×¥È¤Ï¡¢/etc/passwd¤ÎÀà¼è¤Ê¤É¤Ë°­ÍѤµ¤ì¤ë²ÄǽÀ­¤¬¶Ë¤á¤Æ¹â¤¤¤³¤È¤¬ÃΤé¤ì¤Æ¤¤¤Þ¤¹¡£¤ß¤Ê¤µ¤ó¤Î WWW¥µ¡¼¥Ð¤Îcgi-bin¥Ç¥£¥ì¥¯¥È¥ê¤Ë phf ¤¬Æþ¤Ã¤Æ¤¤¤¿¤é¡¢Â¨¹ïºï½ü¤¹¤ë¤«¼Â¹Ô²Äǽ°À­¤ò¼è¤ê¾Ã¤¹¤Ù¤­¤Ç¤·¤ç¤¦¡£¤Þ¤¿¡¢¼ÂºÝ¤Ë phf ¤òÍøÍѤ·¤¿¥¢¥¿¥Ã¥¯¤ò¼õ¤±¤¿¤³¤È¤¬¤¢¤ë¤«¤É¤¦¤«¤Ï¡¢access_log¥Õ¥¡¥¤¥ë¤Ë "/phf" ¤È¤¤¤¦Ê¸»ú¤¬Æþ¤Ã¤Æ¤¤¤ë¤«¤É¤¦¤«¤ò grep ¤ÇÄ´¤Ù¤ì¤Ð¤ï¤«¤ê¤Þ¤¹¡£¤â¤·¡¢¤½¤Î¹Ô¤¬¼¡¤Î¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤ì¤Ð¡¢

¥Û¥¹¥È̾ -- [ÆüÉÕ] "GET /cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd" 404 -

¥¢¥¿¥Ã¥¯¤ò¼õ¤±¤¿¤³¤È¤¬¤ï¤«¤ê¤Þ¤¹¡£¥¹¥Æ¡¼¥¿¥¹¥³¡¼¥É(¾å¤ÎÎã¤Ç¤Ï404)¤¬200¤À¤Ã¤¿¤é¡¢¥¢¥¿¥Ã¥¯¤¬À®¸ù¤·¤¿²ÄǽÀ­¤¬¤¢¤ê¤Þ¤¹¡£

¡üCount.cgi ¤Î¥»¥­¥å¥ê¥Æ¥£¥Û¡¼¥ë

¤â¤¦¤Ò¤È¤Ä¤Î Count.cgi ¤ÎÌäÂêÅÀ¤Ï¡¢CERT advisory ¤Ë CA-97.24 ¤È¤·¤Æ¸ø³«¤µ¤ì¤Æ¤¤¤Þ¤¹¡£Count.cgi ¤Ï¥¢¥¯¥»¥¹¥«¥¦¥ó¥¿¤Î¥×¥í¥°¥é¥à¤È¤·¤Æ¹­¤¯»È¤ï¤ì¤Æ¤¤¤ë¤â¤Î¤Î¤Ò¤È¤Ä¤Ç¤¹¡£¤³¤Î¥×¥í¥°¥é¥à¤Î¥»¥­¥å¥ê¥Æ¥£¥Û¡¼¥ë¤ò°­ÍѤ¹¤ë¤È¡¢httpd ¤¬CGI¥¹¥¯¥ê¥×¥È¤ò¸Æ¤Ó½Ð¤¹»þ¤Î¥æ¡¼¥¶¡¼(nobody¤¬¥Ç¥£¥Õ¥©¥ë¥È)¸¢¸Â¤ÇǤ°Õ¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤­¤Þ¤¹¡£

/etc/passwd¤Ê¤É¤Î¥»¥­¥å¥ê¥Æ¥£¾å½ÅÍפʥե¡¥¤¥ë¤ÎÀà¼è¤Ê¤É¤¬²Äǽ¤È¤Ê¤ë¤ï¤±¤Ç¤¹¡£Count.cgi ¤ÎºÇ¿·ÈÇ(97ǯ12·î7Æü¸½ºß2.4¤¬ºÇ¿·¤Ç¤¹)¤Ç¤Ï¡¢¤³¤Î¥Û¡¼¥ë¤ÏºÉ¤¬¤ì¤Æ¤¤¤Þ¤¹¡£ºÇ¿·ÈǤ˥С¼¥¸¥ç¥ó¥¢¥Ã¥×¤¹¤ë¤«¡¢ÉÔ²Äǽ¤Ê¾ì¹ç¤Ï¼Â¹Ô²Äǽ°À­¤ò¼è¤ê¾Ã¤·¡¢¥¢¥¯¥»¥¹¥«¥¦¥ó¥¿¤Î±¿ÍѤòÄä»ß¤¹¤Ù¤­¤Ç¤¹¡£

¡ü¥Õ¥©¡¼¥à¤Î¥»¥­¥å¥ê¥Æ¥£

¤½¤Î¾¤Ë¤â¡¢CGI´ØÏ¢¤Ç¤Ï¤µ¤Þ¤¶¤Þ¤Ê¥»¥­¥å¥ê¥Æ¥£Âкö¤¬É¬ÍפÀ¤È»ØÅ¦¤µ¤ì¤Æ¤¤¤Þ¤¹¡£¤¿¤È¤¨¤Ð¡¢¥Õ¥©¡¼¥à¤Ç¥æ¡¼¥¶¡¼¥á¡¼¥ë¥¢¥É¥ì¥¹¤òÆþÎϤ·¤â¤é¤¤¡¢¤½¤Î¥¢¥É¥ì¥¹¤Ë¥á¡¼¥ë¤òÁ÷¤ë¤è¤¦¤ÊCGI¥¹¥¯¥ê¥×¥È¤¬¤¢¤ë¤È¤·¤Þ¤¹¡£¥á¡¼¥ë¤òÁ÷¤ë¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤¹¤ë¤Ë¤Ï¡¢Perl¤Ç¤Ï¼¡¤Î¤è¤¦¤Ê¹Ô¤òÍѰդ¹¤ë¤³¤È¤Ë¤Ê¤ê¤Þ¤¹¡£ÊÑ¿ô $mailto ¤Ï¥æ¡¼¥¶¤¬ÆþÎϤ·¤¿¥á¡¼¥ë¥¢¥É¥ì¥¹¤Ç¤¹¡£

'cat ¥Õ¥¡¥¤¥ë̾ | /bin/mail $mailto';

¤â¤·°­°Õ¤Î¥æ¡¼¥¶¤¬

foo@bar.co.jp; cat/etc/passwd

¤ÈÆþÎϤ·¤¿¤é¤É¤¦¤Ê¤ë¤Ç¤·¤ç¤¦¤«¡© ¥·¥§¥ë¤Ç¥»¥ß¥³¥í¥ó¤ÏÊ£¿ô¤Î¥³¥Þ¥ó¥É¤ò¶èÀÚ¤ëÆ¯¤­¤ò»ý¤Á¤Þ¤¹¡£¥æ¡¼¥¶¤¬ÆþÎϤ·¤¿Ãͤò¤½¤Î¤Þ¤Þ»È¤Ã¤Æ¤·¤Þ¤Ã¤¿¤é¡¢¥æ¡¼¥¶¤Î¥Ö¥é¥¦¥¶¤Ë¤Ï /etc/passwd ¤ÎÆâÍÆ¤¬É½¼¨¤µ¤ì¤³¤È¤Ë¤Ê¤ê¤Þ¤¹¡£

¤³¤¦¤¤¤¦¥¢¥¿¥Ã¥¯¤òËɤ°¤Ë¤Ï¡¢¥·¥§¥ë¤äHTML¥Õ¥¡¥¤¥ë¤Ç°ÕÌ£¤ò»ý¤Äµ­¹æ(";"¡¢"<"¤Ê¤É)¤ò "_" ¤Ê¤É¡Ö̵³²¡×¤Êʸ»ú¤ËÃÖ¤­´¹¤¨¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£¤³¤ÎɬÍ×À­¤Ï¡¢CERT Advisory CA-97,25¤Ê¤É¤ÇÎÏÀ⤵¤ì¤Æ¤¤¤Þ¤¹¡£¤¿¤À¤·¡¢JIS¤Ç¤ÏÂè2¥Ð¥¤¥È¤¬0x40¡Á0x7e¤Ë¤Ê¤ëʸ»ú¤â¤¢¤ê¤Þ¤¹¡£¤¤¤Ã¤¿¤óEUC¤ËÊÑ´¹¤·¤Æ¤«¤éÃÖ¤­´¹¤¨¤ë¤Ê¤É¡¢Ê¸»ú¥³¡¼¥É¤Ë¤âÃí°Õ¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£CGI¥×¥í¥°¥é¥à¤ò»È¤Ã¤Æ¤¤¤ëÊý¤Ï¡¢Ãæ¿È¤ò°ìÅÙÅÀ¸¡¤·¤Æ¤¯¤À¤µ¤¤¡£

¡ÚLinux Japan Vol.6 ·ÇºÜµ­»ö¤ò²ÃÉ®½¤Àµ¡Û

Á°¤Ø   Ìá¤ë   ¼¡¤Ø

²áµîµ­»ö¤Î¥¢¡¼¥«¥¤¥Ö

´ØÏ¢¥ê¥ó¥¯

¡÷La Mail¥À¥¦¥ó¥í¡¼¥É
¥¢¥é¥á¡¼¥ë|@La Mail

¤ªÃΤ餻

´ØÀ¾¥ª¡¼¥×¥ó¥½¡¼¥¹2011/¥³¥ß¥å¥Ë¥Æ¥£Âç·èÀï¤Ë½ÐŸ

2011.11.10  ¾ÜºÙ¤Ï¤³¤Á¤é

[¥×¥ì¥¹¥ê¥ê¡¼¥¹] ¥µ¡¼¥É¥¦¥§¥¢¤ÈLINBIT ¤¬¹ñÆâÁíÂåÍýŹ·ÀÌó¤òÄù·ë

2011.10.04  ¾ÜºÙ¤Ï¤³¤Á¤é

DRBD¥¯¥é¥¹¥¿¥¹¥¿¥Ã¥¯¥µ¥Ý¡¼¥ÈÅù ÎÁ¶âÂηÏÊѹ¹¤Î¤ªÃΤ餻

2011.09.28  ¾ÜºÙ¤Ï¤³¤Á¤é

Lotus Knows Expo2011 ½ÐŸ¤Î¤´°ÆÆâ

2011.09.10  ¾ÜºÙ¤Ï¤³¤Á¤é

¹ñÆâ³°¤ÎÊ£¿ô¥Ç¡¼¥¿¥»¥ó¥¿¤òÍøÍѤ·¤¿¥Ç¥£¥¶¥¹¥¿¥ê¥«¥Ð¥ê¥µ¡¼¥Ó¥¹Ä󶡤Τ´°ÆÆâ

2011.09.08  ¾ÜºÙ¤Ï¤³¤Á¤é