CERT Coordination Center ¤È¤¤¤¦Êƹñ¤ÎÃÄÂΤ¬¤¢¤ê¡¢CERT Advisory¡¢CERT bulletin ¤È¤¤¤¦¡¢¥»¥¥å¥ê¥Æ¥£¤Ë´Ø¤¹¤ë´«¹ð¤ò¿ï»þȯ¹Ô¤·¤Æ¤¤¤Þ¤¹¡£ºòǯ¤«¤éº£Ç¯¤Ë¤«¤±¤ÆºÆ»°È¯¹Ô¤µ¤ì¤Æ¤¤¤ë¤â¤Î¤Ë¡¢CGI´ØÏ¢¤Î¥»¥¥å¥ê¥Æ¥£¤¬¤¢¤ê¤Þ¤¹¡£
¤³¤³¤Ç¤Ï¤â¤Ï¤ä¸ÅŵŪ¤È¤â¸À¤¨¤ë phf ¤Ë¤è¤ë¥Ñ¥¹¥ï¡¼¥ÉÀà¼è¡¢ºÇ¶á¤ÎÏÃÂê¤Ç¤¢¤ë Count.cgi ¤Î¥»¥¥å¥ê¥Æ¥£¡¦¥Û¡¼¥ë¤ò¾Ò²ð¤·¤Þ¤·¤ç¤¦¡£¤Þ¤¿Ãí°Õ¿¼¤¤CGI½ñ¤¤Ë¤Ï¾ï¼±¤«¤â¤·¤ì¤Þ¤»¤ó¤¬¡¢¥Õ¥©¡¼¥à¤Î½èÍý¤Ë´Ø¤¹¤ëÃí°Õ»ö¹à¤â½ñ¤¤¤Æ¤ª¤¤Þ¤¹¡£
¡ü phf¤ò¤á¤°¤ëÏÃÂêNCSA httpd ¤ä APACHE ¤Î phf ¥µ¥ó¥×¥ë CGI ¥¹¥¯¥ê¥×¥È¤Ï¡¢/etc/passwd¤ÎÀà¼è¤Ê¤É¤Ë°ÍѤµ¤ì¤ë²ÄǽÀ¤¬¶Ë¤á¤Æ¹â¤¤¤³¤È¤¬ÃΤé¤ì¤Æ¤¤¤Þ¤¹¡£¤ß¤Ê¤µ¤ó¤Î WWW¥µ¡¼¥Ð¤Îcgi-bin¥Ç¥£¥ì¥¯¥È¥ê¤Ë phf ¤¬Æþ¤Ã¤Æ¤¤¤¿¤é¡¢Â¨¹ïºï½ü¤¹¤ë¤«¼Â¹Ô²Äǽ°À¤ò¼è¤ê¾Ã¤¹¤Ù¤¤Ç¤·¤ç¤¦¡£¤Þ¤¿¡¢¼ÂºÝ¤Ë phf ¤òÍøÍѤ·¤¿¥¢¥¿¥Ã¥¯¤ò¼õ¤±¤¿¤³¤È¤¬¤¢¤ë¤«¤É¤¦¤«¤Ï¡¢access_log¥Õ¥¡¥¤¥ë¤Ë "/phf" ¤È¤¤¤¦Ê¸»ú¤¬Æþ¤Ã¤Æ¤¤¤ë¤«¤É¤¦¤«¤ò grep ¤ÇÄ´¤Ù¤ì¤Ð¤ï¤«¤ê¤Þ¤¹¡£¤â¤·¡¢¤½¤Î¹Ô¤¬¼¡¤Î¤è¤¦¤Ë¤Ê¤Ã¤Æ¤¤¤ì¤Ð¡¢
¥Û¥¹¥È̾ -- [ÆüÉÕ] "GET /cgi-bin/phf?Qalias=x%0a/bin/cat%20/etc/passwd" 404 -
¥¢¥¿¥Ã¥¯¤ò¼õ¤±¤¿¤³¤È¤¬¤ï¤«¤ê¤Þ¤¹¡£¥¹¥Æ¡¼¥¿¥¹¥³¡¼¥É(¾å¤ÎÎã¤Ç¤Ï404)¤¬200¤À¤Ã¤¿¤é¡¢¥¢¥¿¥Ã¥¯¤¬À®¸ù¤·¤¿²ÄǽÀ¤¬¤¢¤ê¤Þ¤¹¡£
¤â¤¦¤Ò¤È¤Ä¤Î Count.cgi ¤ÎÌäÂêÅÀ¤Ï¡¢CERT advisory ¤Ë CA-97.24 ¤È¤·¤Æ¸ø³«¤µ¤ì¤Æ¤¤¤Þ¤¹¡£Count.cgi ¤Ï¥¢¥¯¥»¥¹¥«¥¦¥ó¥¿¤Î¥×¥í¥°¥é¥à¤È¤·¤Æ¹¤¯»È¤ï¤ì¤Æ¤¤¤ë¤â¤Î¤Î¤Ò¤È¤Ä¤Ç¤¹¡£¤³¤Î¥×¥í¥°¥é¥à¤Î¥»¥¥å¥ê¥Æ¥£¥Û¡¼¥ë¤ò°ÍѤ¹¤ë¤È¡¢httpd ¤¬CGI¥¹¥¯¥ê¥×¥È¤ò¸Æ¤Ó½Ð¤¹»þ¤Î¥æ¡¼¥¶¡¼(nobody¤¬¥Ç¥£¥Õ¥©¥ë¥È)¸¢¸Â¤ÇǤ°Õ¤Î¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤Ç¤¤Þ¤¹¡£
/etc/passwd¤Ê¤É¤Î¥»¥¥å¥ê¥Æ¥£¾å½ÅÍפʥե¡¥¤¥ë¤ÎÀà¼è¤Ê¤É¤¬²Äǽ¤È¤Ê¤ë¤ï¤±¤Ç¤¹¡£Count.cgi ¤ÎºÇ¿·ÈÇ(97ǯ12·î7Æü¸½ºß2.4¤¬ºÇ¿·¤Ç¤¹)¤Ç¤Ï¡¢¤³¤Î¥Û¡¼¥ë¤ÏºÉ¤¬¤ì¤Æ¤¤¤Þ¤¹¡£ºÇ¿·ÈǤ˥С¼¥¸¥ç¥ó¥¢¥Ã¥×¤¹¤ë¤«¡¢ÉÔ²Äǽ¤Ê¾ì¹ç¤Ï¼Â¹Ô²Äǽ°À¤ò¼è¤ê¾Ã¤·¡¢¥¢¥¯¥»¥¹¥«¥¦¥ó¥¿¤Î±¿ÍѤòÄä»ß¤¹¤Ù¤¤Ç¤¹¡£
¤½¤Î¾¤Ë¤â¡¢CGI´ØÏ¢¤Ç¤Ï¤µ¤Þ¤¶¤Þ¤Ê¥»¥¥å¥ê¥Æ¥£Âкö¤¬É¬ÍפÀ¤È»ØÅ¦¤µ¤ì¤Æ¤¤¤Þ¤¹¡£¤¿¤È¤¨¤Ð¡¢¥Õ¥©¡¼¥à¤Ç¥æ¡¼¥¶¡¼¥á¡¼¥ë¥¢¥É¥ì¥¹¤òÆþÎϤ·¤â¤é¤¤¡¢¤½¤Î¥¢¥É¥ì¥¹¤Ë¥á¡¼¥ë¤òÁ÷¤ë¤è¤¦¤ÊCGI¥¹¥¯¥ê¥×¥È¤¬¤¢¤ë¤È¤·¤Þ¤¹¡£¥á¡¼¥ë¤òÁ÷¤ë¥³¥Þ¥ó¥É¤ò¼Â¹Ô¤¹¤ë¤Ë¤Ï¡¢Perl¤Ç¤Ï¼¡¤Î¤è¤¦¤Ê¹Ô¤òÍѰդ¹¤ë¤³¤È¤Ë¤Ê¤ê¤Þ¤¹¡£ÊÑ¿ô $mailto ¤Ï¥æ¡¼¥¶¤¬ÆþÎϤ·¤¿¥á¡¼¥ë¥¢¥É¥ì¥¹¤Ç¤¹¡£
'cat ¥Õ¥¡¥¤¥ë̾ | /bin/mail $mailto';
¤â¤·°°Õ¤Î¥æ¡¼¥¶¤¬
foo@bar.co.jp; cat/etc/passwd
¤ÈÆþÎϤ·¤¿¤é¤É¤¦¤Ê¤ë¤Ç¤·¤ç¤¦¤«¡© ¥·¥§¥ë¤Ç¥»¥ß¥³¥í¥ó¤ÏÊ£¿ô¤Î¥³¥Þ¥ó¥É¤ò¶èÀÚ¤ëÆ¯¤¤ò»ý¤Á¤Þ¤¹¡£¥æ¡¼¥¶¤¬ÆþÎϤ·¤¿Ãͤò¤½¤Î¤Þ¤Þ»È¤Ã¤Æ¤·¤Þ¤Ã¤¿¤é¡¢¥æ¡¼¥¶¤Î¥Ö¥é¥¦¥¶¤Ë¤Ï /etc/passwd ¤ÎÆâÍÆ¤¬É½¼¨¤µ¤ì¤³¤È¤Ë¤Ê¤ê¤Þ¤¹¡£
¤³¤¦¤¤¤¦¥¢¥¿¥Ã¥¯¤òËɤ°¤Ë¤Ï¡¢¥·¥§¥ë¤äHTML¥Õ¥¡¥¤¥ë¤Ç°ÕÌ£¤ò»ý¤Äµ¹æ(";"¡¢"<"¤Ê¤É)¤ò "_" ¤Ê¤É¡Ö̵³²¡×¤Êʸ»ú¤ËÃÖ¤´¹¤¨¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£¤³¤ÎɬÍ×À¤Ï¡¢CERT Advisory CA-97,25¤Ê¤É¤ÇÎÏÀ⤵¤ì¤Æ¤¤¤Þ¤¹¡£¤¿¤À¤·¡¢JIS¤Ç¤ÏÂè2¥Ð¥¤¥È¤¬0x40¡Á0x7e¤Ë¤Ê¤ëʸ»ú¤â¤¢¤ê¤Þ¤¹¡£¤¤¤Ã¤¿¤óEUC¤ËÊÑ´¹¤·¤Æ¤«¤éÃÖ¤´¹¤¨¤ë¤Ê¤É¡¢Ê¸»ú¥³¡¼¥É¤Ë¤âÃí°Õ¤¹¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£CGI¥×¥í¥°¥é¥à¤ò»È¤Ã¤Æ¤¤¤ëÊý¤Ï¡¢Ãæ¿È¤ò°ìÅÙÅÀ¸¡¤·¤Æ¤¯¤À¤µ¤¤¡£
¡ÚLinux Japan Vol.6 ·ÇºÜµ»ö¤ò²ÃÉ®½¤Àµ¡Û

´ØÀ¾¥ª¡¼¥×¥ó¥½¡¼¥¹2011/¥³¥ß¥å¥Ë¥Æ¥£Âç·èÀï¤Ë½ÐŸ
2011.11.10 ¾ÜºÙ¤Ï¤³¤Á¤é
[¥×¥ì¥¹¥ê¥ê¡¼¥¹] ¥µ¡¼¥É¥¦¥§¥¢¤ÈLINBIT ¤¬¹ñÆâÁíÂåÍýŹ·ÀÌó¤òÄù·ë
2011.10.04 ¾ÜºÙ¤Ï¤³¤Á¤é
DRBD¥¯¥é¥¹¥¿¥¹¥¿¥Ã¥¯¥µ¥Ý¡¼¥ÈÅù ÎÁ¶âÂηÏÊѹ¹¤Î¤ªÃΤ餻
2011.09.28 ¾ÜºÙ¤Ï¤³¤Á¤é
Lotus Knows Expo2011 ½ÐŸ¤Î¤´°ÆÆâ
2011.09.10 ¾ÜºÙ¤Ï¤³¤Á¤é
¹ñÆâ³°¤ÎÊ£¿ô¥Ç¡¼¥¿¥»¥ó¥¿¤òÍøÍѤ·¤¿¥Ç¥£¥¶¥¹¥¿¥ê¥«¥Ð¥ê¥µ¡¼¥Ó¥¹Ä󶡤Τ´°ÆÆâ
2011.09.08 ¾ÜºÙ¤Ï¤³¤Á¤é