• 検索結果がありません。

䉶䉨䊠䊥䊁䉞䈮㈩ᘦ䈚䈢䉟䊮䉺䊷䊈䉾䊃ᔕ↪䉲䉴䊁䊛䈱᭴▽

N/A
N/A
Protected

Academic year: 2021

シェア "䉶䉨䊠䊥䊁䉞䈮㈩ᘦ䈚䈢䉟䊮䉺䊷䊈䉾䊃ᔕ↪䉲䉴䊁䊛䈱᭴▽"

Copied!
6
0
0

読み込み中.... (全文を見る)

全文

(1)

䉶䉨䊠䊥䊁䉞䈮㈩ᘦ䈚䈢䉟䊮䉺䊷䊈䉾䊃ᔕ↪䉲䉴䊁䊛䈱᭴▽

* **

᧻ᧄືᆎ ጟ↰ ᱜ

Construction of the Internet Application Systems Designed in Consideration of Security

ATSUMOTO KADA

Satoshi M and Tadashi O

When designing the Internet application systems, it is important to consider in security. This paper deals with causes and measures where security holes happen. On the basis of our experience of constructing the systems, we report our practices such as a note in regard to Web-based programming, a code review for programs developed, an adoption of safe mechanisms.

, Security, Web-based system Keywords. Internet application system

㧝㧚ߪߓ߼ߦ

ᚒޘߩ⎇ⓥቶߢߪ㧘એ೨߆ࠄ࿾ၞડᬺߣ౒หߢࠗ

ࡦ࠲࡯ࡀ࠶࠻ࠍ೑↪ߒߚ⒳ޘߩࠪࠬ࠹ࡓ㐿⊒ࠍⴕߞ ߡ޿ࠆ

1-4

㧚ᦨㄭ㐿⊒ߒߚࠪࠬ࠹ࡓߪࠗࡦ࠲࡯ࡀ࠶

࠻ߦᏱᤨធ⛯ߢ౏㐿ㆇ↪ߐࠇߡ߅ࠅ㧘࠮ࠠࡘ࡝࠹ࠖ

㕙ߩ⢿ᆭߦᏱߦߐࠄߐࠇߡ޿ࠆ㧚ߐࠄߦ㧘⸳⟎వߩ ડᬺߦᖱႎㅢାߦ㑐ߔࠆ㜞ᐲߥ⍮⼂ࠍᜬߞߚᛛⴚ⠪

߇޿ࠆ႐วߪዋߥߊ㧘࿾ၞߣㅪ៤ߒߚࠪࠬ࠹ࡓ㐿⊒

ߦ߅޿ߡ㧘࠮ࠠࡘ࡝࠹ࠖߩ⏕଻ߣ቟ోߥ଻቞߳ߩ㈩ ᘦߪ㊀ⷐߥ⺖㗴ߢ޽ࠆ㧚

ᧄ⺰ᢥߢߪ㧘࿾ၞડᬺߣ౒หߢ቟ోߥࠪࠬ࠹ࡓࠍ

቟ଔߦ㐿⊒ߔࠆߚ߼ߩᚻᴺߣታ〣଀ࠍขࠅ਄ߍߡ޿

ࠆ㧚ࠗࡦ࠲࡯ࡀ࠶࠻ࠍ೑↪ߒߚࠪࠬ࠹ࡓߪ㧘ਛᩭߣ ߥࠆࡀ࠶࠻ࡢ࡯ࠢࠨ࡯ࡃߣߘߩ਄ߢേ૞ߔࠆࡊࡠࠣ

࡜ࡓ߇㊀ⷐߥߩߢ㧘ߎࠇࠄߩ቟ోᕈࠍ㜞߼ࠆᣇᴺࠍ ᬌ⸛ߔࠆ㧚ߐࠄߦߎࠇࠄߩᬌ⸛⚿ᨐ߇㧘ታ㓙ߩࠪࠬ

࠹ࡓߦ߅޿ߡߤߩࠃ߁ߦᵴ߆ߐࠇߡ޿ࠆ߆ࠍౕ૕⊛

ߦႎ๔ߒߚ޿㧚

ߢߪ቟ోᕈࠍ଻ߟ਄ߢ㊀ⷐߥ࠮ࠠࡘ࡝࠹ࠖࡎ 㧞㧚

࡯࡞ߩ⊒↢ⷐ࿃ࠍᢛℂߒ㧘㧟㧚ߦ߅޿ߡ࠮ࠠࡘ࡝࠹

ࠖߦ㈩ᘦߒߚࠪࠬ࠹ࡓ㐿⊒ߩⷐὐࠍㅀߴࠆ㧚㧠㧚ߢ

࿾ၞડᬺߣ౒หߢ㐿⊒ߒߚࠪࠬ࠹ࡓߦ߅޿ߡ㧘࠮ࠠ

ේⓂฃઃ ᐔᚑ㧝㧥ᐕ㧤᦬㧟㧝ᣣ

*

ኾ᡹⑼㔚ሶ࡮ᖱႎࠪࠬ࠹ࡓᎿቇኾ᡹⑼ୃੌ↢ ᐔᚑ㧝㧤ᐕᐲ ᖱႎᎿቇ⑼

**

ࡘ࡝࠹ࠖኻ╷߇ߤߩࠃ߁ߦㆡ↪ߐࠇߡ޿ࠆ߆ౕ૕⊛

ߦㅀߴࠆ㧚

㧞㧚࠮ࠠࡘ࡝࠹ࠖࡎ࡯࡞ߩߢ߈ࠆⷐ࿃

࠮ࠠࡘ࡝࠹ࠖࡎ࡯࡞ߣߪ㧘૗ࠄ߆ߩⷐ࿃ߦࠃࠅ↢

ߓࠆࠪࠬ࠹ࡓߩ࠮ࠠࡘ࡝࠹ࠖ਄ߩᒙὐߩߎߣࠍ޿߁ 㧚࠮ࠠࡘ࡝࠹ࠖࡎ࡯࡞ߪ㧘ਇᱜⴕὑߩ♻ญߣߒߡ

5

૶ࠊࠇࠆߎߣ߇ᄙߊ㧘․ߦ࠰ࡈ࠻࠙ࠚࠕߩᰳ㒱ߦࠃ

ࠆ࠮ࠠࡘ࡝࠹ࠖࡎ࡯࡞ߩ႐ว ୃᱜߦᤨ㑆߇߆߆ࠅ ߘߩ㑆ή㒐஻ߣߥߞߡߒ߹߁ߎߣ߇ᄙ޿ߚ߼໧㗴ߢ

޽ࠆ㧚ߎߎߢߪ㧘࠮ࠠࡘ࡝࠹ࠖࡎ࡯࡞ߩߢ߈ࠆ৻⥸

⊛ⷐ࿃ߣ㧘ᚒޘ߇᭴▽ߔࠆࠪࠬ࠹ࡓߢ㊀ⷐߥ

Web

ࠕࡊ࡝ࠤ࡯࡚ࠪࡦߦኻߔࠆ໧㗴ࠍᬌ⸛ߔࠆ㧚

৻⥸⊛ߥ࠮ࠠࡘ࡝࠹ࠖࡎ࡯࡞

䋲䋮䋱

࠮ࠠࡘ࡝࠹ࠖࡎ࡯࡞ߩߢ߈ࠆ৻⥸⊛ⷐ࿃ߣߒߡ㧘

ᰴߩ㧟ߟ߇㊀ⷐߢ޽ࠆ㧚 ⸳ቯߩࡒࠬ

1

࠮ࠠࡘ࡝࠹ࠖᗧ⼂ߩਇ⿷

2

ࠪࠬ࠹ࡓߩᰳ㒱߿ࡔ࡯ࠞߩኻᔕߩਇ஻

3

࠮ࠠࡘ࡝࠹ࠖଚኂߩਥߥේ࿃߇ ߩ⸳ቯࡒࠬߦ

1

ࠃࠆ߽ߩߢ㧘⚂ඨᢙߪ⸳ቯࡒࠬߦ⿠࿃ߔࠆߣ⸒ࠊࠇ ߡ޿ࠆ㧚⸳ቯࡒࠬࠍߥߊߔߚ߼ߦ㧘࠮ࠠࡘ࡝࠹ࠖᯏ

⢻ࠍߔߴߡ૶߃߫቟ోߥࠦࡦࡇࡘ࡯࠲ߣߥࠆ㧚ߒ߆ ߒ㧘૶޿ൎᚻ߇ᖡߊߥࠆߎߣ߇ᄙ޿ߩߢ㧘ᐢߊ૶ࠊ ࠇߡ޿ࠆࡄ࠰ࠦࡦߢߪ࠺ࡈࠜ࡞࠻ߢ೙㒢ࠍ߆ߌߡ޿

ߥ޿㧚ߘߩߚ߼㧘ήᗧ⼂ߩ߁ߜߦ⢿ᆭߦߐࠄߐࠇߚ ࠅ㧘೙㒢ࠍ߆ߌࠆߣ߈ߦ⸳ቯࡒࠬࠍᒁ߈⿠ߎߒ߿ߔ

޿㧚޿ߕࠇߦߒߡ߽㧘࠮ࠠࡘ࡝࠹ࠖኻ╷ߣ૶޿ൎᚻ

(2)

ߩࡃ࡜ࡦࠬࠍߣࠆߎߣ߇ᄢಾߣߥࠆ㧚

ᰴߦ㧘 ߩ࠮ࠠࡘ࡝࠹ࠖᗧ⼂ߩਇ⿷߇޽ࠆ㧚ߎ

2

ࠇߪ࠰࡯ࠪࡖ࡞ࠛࡦࠫ࠾ࠕ࡝ࡦࠣߣ޿ࠊࠇࠆ߽ߩ ߢ㧘㔚⹤ߢ▤ℂ⠪ߦߥࠅߔ߹ߒߡࡄࠬࡢ࡯࠼ࠍ⡞߈

಴ߔߣ޿ߞߚᚻญ߇޽ࠆ㧚㔚⹤એᄖߦ߽㧘ࠧࡒ⟎߈ ႐ߦⓍࠎߢ޽ࠆࠧࡒߩਛ߿ࠨ࡯ࡃ࡞࡯ࡓߦᔋ߮ㄟࠎ ߢࡄࠬࡢ࡯࠼ߩࡔࡕࠍតߒߚࠅ㧘ࡄࠬࡢ࡯࠼ࠍ౉ജ ߒߡ޿ࠆߣߎࠈࠍᓟࠈ߆ࠄߩߙ߈⷗ߚࠅߒߡ౉ᚻߔ ࠆ㧚▤ℂ↪ࡄࠬࡢ࡯࠼߇㊀ⷐߢ޽ࠆߩߪ߽ߜࠈࠎߩ ߎߣ㧘৻⥸࡙࡯ࠩߩࡄࠬࡢ࡯࠼ߢ޽ߞߡ߽౉ᚻߢ߈ ࠇ߫

LAN

߿ࠨ࡯ࡃ߳ߩࠕࠢ࠮ࠬ߇ኈᤃߦߥࠆߚ߼

ߤߩࠃ߁ߥࡄࠬࡢ࡯࠼ߢ޽ߞߡ߽ṳࠇࠆߎߣ߇޽ߞ ߡߪߥࠄߥ޿㧚ߒ߆ߒ㧘ࡄࠬࡢ࡯࠼ߩ▤ℂߪ࡙࡯ࠩ

୘ੱߦᆔߨࠄࠇࠆߚ߼㧘ฦ୘ੱߩ࠮ࠠࡘ࡝࠹ࠖᗧ⼂

ߩ໧㗴ߣߥࠅኻ╷߇㔍ߒ޿㧚

ᦨᓟߦ㧘 ߩࠪࠬ࠹ࡓߩᰳ㒱߿ࡔ࡯ࠞߩኻᔕߩ

3

ਇ஻߇޽ࠆ㧚ߎࠇߪ࠮ࠠࡘ࡝࠹ࠖ໧㗴ߩਛߢ⸳ቯࡒ

ࠬߦᰴ޿ߢᄙ޿໧㗴ߢ㧘ߒ߆߽ࠛࡦ࠼࡙࡯ࠩߢߪኻ

ಣߢ߈ߥ޿ߎߣ߽޽ࠅ࿎ߞߚ໧㗴ߢ޽ࠆ㧚ࡊࡠࠣ࡜

ࡓߦ࠮ࠠࡘ࡝࠹ࠖ໧㗴߇⊒ⷡߔࠆߣ㧘ࡔ࡯ࠞߪࡄ࠶

࠴ࠍ㈩Ꮣߒߡ໧㗴ࠍ⸃᳿ߒߡ޿ࠆ㧚ߒ߆ߒ㧘໧㗴߇

⊒⷗ߐࠇߡ߆ࠄࡄ࠶࠴߇࡝࡝࡯ࠬߐࠇࠆ߹ߢߩ㑆ߪ ή㒐஻ߥ⁁ᘒߦߐࠄߐࠇࠆ㧚ߐࠄߦ㧘ࡄ࠶࠴ࠍ౉ᚻ

ߒㆡ↪ߔࠆ૞ᬺߪ࡙࡯ࠩ߇ⴕࠊߥߌࠇ߫ߥࠄߥ޿

ࡄ࠶࠴ࠍᒰߡࠆߎߣߢ߶߆ߩਇౕว߇⿠ߎࠆߎߣ߽

޽ࠆߒ㧘ࡄ࠶࠴ࠍ౉ᚻߒߡᒰߡࠆߦߪᚻ㑆߇߆߆ࠆ ߚ߼㧘㕙ୟߊߐ߇ࠅߩ࡙࡯ࠩߥࠄߚ޿ߒߚ໧㗴ߢߪ ߥ޿ߣࡄ࠶࠴ࠍᒰߡߕ㧘࠮ࠠࡘ࡝࠹ࠖࡎ࡯࡞߇᡼⟎

ߐࠇࠆน⢻ᕈ߇޽ࠆ㧚

ࠕࡊ࡝ࠤ࡯࡚ࠪࡦ㐿⊒ߦኻߔࠆᵈᗧ 䋲䋮䋲

Web

2004 ᐕߩ⺞ᩏߢߪ

Web

ࠕࡊ࡝ࠤ࡯࡚ࠪࡦߩ⚂

6

ഀߦ⥌๮⊛ߥᰳ㒱߇޽ࠅ㧘ߘࠇએᄖߦ߽૗ࠄ߆ߩࡃ

ࠣ߇޽ࠅ㧘቟ోߥ

Web

ࠕࡊ࡝ࠤ࡯࡚ࠪࡦߪᢙ㧑ߒ ߆ߥ߆ߞߚߣ޿߁ႎ๔߇޽ࠆ 㧚ߘࠇߛߌߢߥߊ㧘

6

⣀ᒙߥ Web

ࠕࡊ࡝ࠤ࡯࡚ࠪࡦߦኻߒߡୃᱜࠍⴕߞ ߚߣߒߡ߽㧘

98 㧑ߪ⣀ᒙᕈ߇ᱷߞߡߒ߹߁ߣ޿߁

࡚ࠪ࠶ࠠࡦࠣߥ⺞ᩏ⚿ᨐ߽޽ࠆ

6

Web

ࠕࡊ࡝ࠤ

࡯࡚ࠪࡦߩ㐿⊒ߢߪ㧘ᱜߒ޿⍮⼂ߣᚻᴺࠍℂ⸃ߒߡ ߅߆ߥߌࠇ߫ߥࠄߥ޿㧚

ࠕࡊ࡝ࠤ࡯࡚ࠪࡦߦኻߔࠆઍ⴫⊛ߥ᡹᠄ᚻ

Web

ᴺߦ㧘ᰴߩࠃ߁ߥ߽ߩ߇޽ࠆ 㧚

7

Path Traversal

SQL Injection

OS Command Injection

Session Hijacking/ Replay

Buffer Overflow

Cross Site Scripting

Parameter Manipulation

Backdoor & Debug Options

Forceful Browsing

Client Side Comment

Error Codes

ߎࠇࠄߩ᡹᠄ߪᓥ᧪ߩ

OS

߿

HTTP

࠺࡯ࡕࡦ߳ߩ

᡹᠄ߣ⇣ߥࠅ

࡮ᔅߕߒ߽ࠨ࡯ࡃߩ▤ℂ⠪ᮭ㒢ࠍᅓ߁ߎߣ߇⋡⊛

ߢߪߥ޿

࡮ Web

ࠕࡊ࡝ࠤ࡯࡚ࠪࡦߏߣߦ᡹᠄ߩࡄ࠲࡯ࡦ ߇㆑߁

࡮ᔅߕߒ߽ࡈࠔࠗ࡞ࠍᡷߑࠎߔࠆࠊߌߢߪߥ޿

࡮࠙ࠗ࡞ࠬ߿ࡢ࡯ࡓࠍㅍࠅߟߌߡ޿ࠆࠊߌߢߪߥ

޿

࡮߶ߣࠎߤߩ᡹᠄߇ࡠࠣߦᱷࠄߥ޿

ߥߤߩ․ᓽ߇޽ࠅ㧘ၮᧄ⊛ߥኻ╷ߦട߃ߡ㧘೑↪Ბ

㓏ߛߌߢߥߊ㐿⊒Ბ㓏ߢ߽㧘᡹᠄ᗧ࿑ߦᔕߓߚኻ╷

ࠍߣࠆᔅⷐ߇޽ࠆ㧚

଀߃߫㧘

Cross Site Scripting

XSS 㧕ߪ㧘ߥࠅߔ߹

ߒߥߤߩ໧㗴ࠍᒁ߈⿠ߎߔ⣀ᒙᕈߩ৻ߟߢ޽ࠆ㧚ឝ

␜᧼߿ࡈࠜ࡯ࡓߩ౉ജ⏕⹺↹㕙ߢ㧘࡙࡯ࠩ߇౉ജߒ

ߚ୯ࠍߘߩ߹߹⴫␜ߒߡ޿ࠆࠕࡊ࡝ࠤ࡯࡚ࠪࡦߢ⿠

ߎࠅ߁ࠆ㧚

HTML

࠲ࠣࠍ౉ജߒߚ㓙ߦ࠲ࠣ߇᦭ല ߥ⴫␜ࠍߔࠆ૞ࠅߦߥߞߡ޿ࠆࡊࡠࠣ࡜ࡓߪ㧘㕖Ᏹ ߦෂ㒾ߢ޽ࠆߣ⹺⼂ߔߴ߈ߢ޽ࠆ㧚

XSS

ߩ⣀ᒙᕈ ࠍߟ޿ߚߥࠅߔ߹ߒ᡹᠄߇໧㗴ߣߥࠆߩߪ㧘࡙࡯ࠩ

ߪ․ߦⵍኂߦㆣ߁ࠃ߁ߥߎߣࠍⴕߞߡ޿ߥ޿ߩߦⵍ ኂߦㆣߞߡߒ߹߁ߎߣ߇޽ࠆߚ߼ߢ޽ࠆ㧚

XSS

╷ߣߒߡ㧘౉ജ୯࠴ࠚ࠶ࠢࠍࠪࠬ࠹ࡓ࡟ࡌ࡞ߢⴕࠊ ߥߌࠇ߫ߥࠄߥ޿㧚

቟ోߥࡊࡠࠣ࡜ࡓࠍ૞ᚑߔࠆߚ߼ߦߪ㧘⸳⸘Ბ㓏 ߆ࠄ࠮ࠠࡘ࡝࠹ࠖߦߟ޿ߡ⏕⹺ࠍⴕ޿㧘ߔߢߦቢᚑ ߐࠇߚ቟ోᕈߩ㜞޿ࡕࠫࡘ࡯࡞߇޽ࠆ႐ว㧘ߘࠇࠍ

ᵹ↪ߔࠆ㧚߹ߚ㧘ౣ೑↪ߢ߈ࠆࠃ߁ߥᒻߢࠨࡉ࡞࡯

࠴ࡦࠍ⸳⸘ߒ㧘࠮ࠠࡘ࡝࠹ࠖߦ㊀ὐࠍ⟎޿ߡ㐿⊒ߔ

ࠆߎߣߢ

ᓟߩ㐿⊒ߦᓎ┙ߡࠆߎߣ߇ߢ߈ࠆ ৻ᣇ

ࠪࠬ࠹ࡓࠍ৻߆ࠄ㐿⊒ߔࠆ႐วߪ㧘቟ోᕈࠍ⠨ᘦߒ ߚࡊࡠࠣ࡜ࡒࡦࠣ⸒⺆ࠍ೑↪ߔࠆߎߣߢ㧘Ყセ⊛◲

නߦ࠮ࠠࡘ࡝࠹ࠖᕈ⢻ࠍ਄ߍࠆߎߣ߇ߢ߈ࠆ㧚

ࡊࡠࠣ࡜ࡓࠍታ㓙ߦᦠߊ਄ߢߩᦨ߽㊀ⷐߥ⇐ᗧὐ ߪ㧘ࠊ߆ࠅ߿ߔ޿ࡊࡠࠣ࡜ࡓࠍᦠߎߣߢ޽ࠆ㧚⺒ߺ ߦߊ޿ࡊࡠࠣ࡜ࡓߢߪ㧘૞ߞߡ޿ࠆᧄੱ߽ࡒࠬࠍߒ

߿ߔߊߥࠆߒ㧘ᓟ߆ࠄࠦ࡯࠼࡟ࡆࡘ࡯ࠍߒߡ޿ࠆੱ

߽ಽ߆ࠅߠࠄߊ ࡃࠣࠍ⊒⷗ߔࠆߎߣ߇࿎㔍ߦߥࠆ ࠊ߆ࠅ߿ߔߊ㧘ࡃࠣࠍ૞ࠅߦߊ޿ࡊࡠࠣ࡜ࡓࠍᦠߊ ߚ߼ߩࡐࠗࡦ࠻ߣߒߡ㧘ᰴߩࠃ߁ߥ߽ߩ߇޽ࠆ㧚 ᄌᢙߦ᣿␜⊛ߦೋᦼ୯ࠍઍ౉ߔࠆ㧚

1

↢ᚑߒߚᄌᢙ߿ࠝࡉࠫࠚࠢ࠻ߪ㧘ᔅⷐ߇ߥߊߥ

2

ࠇ߫᣿␜⊛ߦ⸃᡼ߔࠆ㧚

ᄌᢙࠍት⸒ߒߡ૶↪ߒߡ޿ࠆ߆⏕⹺ߔࠆ㧚ᄌᢙ

3

ት⸒ߩᔅⷐ߇ߥ޿ Perl

ߢ޽ߞߡ߽㧘ᄌᢙฬࠍ] _ ߢ࿐ࠎߢ᣿⏕ߦߔࠆ㧚

(3)

ᔅⷐߩߥ޿ࠣࡠ࡯ࡃ࡞ᄌᢙࠍ૶ߞߡ޿ߥ޿߆⏕

4

⹺ߒߢ߈ࠆߛߌࡠ࡯ࠞ࡞ᄌᢙࠍ૶߁ࠃ߁ߦߔࠆ

ࠦࡔࡦ࠻߇ᦠ߆ࠇߡ޿ࠆ߆⏕⹺ߒ㧘ઁੱ߇⺒߻

5

ߎߣࠍᗐቯߒߡࠦࡔࡦ࠻ࠍߟߌࠆࠃ߁ߦߔࠆ㧚 ࡊࡠࠣ࡜ࡓߩ޽ߜߎߜߢቯᢙࠍቯ⟵ߒߡ޿ߥ޿

6

߆⏕⹺ߒ㧘ቯᢙߪࡊࡠࠣ࡜ࡓߩೋᦼൻㇱಽߦᄌᢙ ߦ౉ࠇߡ೑↪ߔࠆࠃ߁ߦߔࠆ㧚

ࠗࡦ࠺ࡦ࠻ߩᣇᴺ߿ᷓߐߥߤ㧘ᦠᑼߪߘࠈߞߡ

7

޿ࠆ߆⏕⹺ߔࠆ㧚

㧟㧚࠮ࠠࡘ࡝࠹ࠖߦ㈩ᘦߒߚࠪࠬ࠹ࡓ㐿⊒

቟ోߥࠪࠬ࠹ࡓࠍታ⃻ߔࠆߚ߼ߦߪ㧘ၮ⋚ߣߥࠆ ࡊࡠࠣ࡜ࡓߦ࠮ࠠࡘ࡝࠹ࠖࡎ࡯࡞߇޽ߞߡߪߥࠄߥ

޿㧚ߎߩ໧㗴ߦߪᚒޘߪ㧘ࠝ࡯ࡊࡦ࠰࡯ࠬ࠰ࡈ࠻࠙

ࠚࠕࠍᵴ↪ߔࠆߎߣߢኻᔕߒߡ޿ࠆ㧔⹦⚦ߦߟ޿ߡ ߪᢥ₂

4

ߦ⼑ࠆ 㧚

ᰴߦ㧘ࠪࠬ࠹ࡓࠍታ⃻ߔࠆߩߦᔅⷐߢㆡಾߥᛛⴚ ࠍណ↪ߒ㧘ࡊࡠࠣ࡜ࡓ૞ᚑߢߩᵈᗧࠍ቞ࠅߥ߇ࠄ㐿

⊒ߔࠆ㧚ߐࠄߦ㧘㐿⊒ߒߚࡊࡠࠣ࡜ࡓߪ㧘േ૞⏕⹺

ߛߌߢߥߊ㧘࠮ࠠࡘ࡝࠹ࠖ㈩ᘦࠍ฽߼ߚࠦ࡯࠼࡟ࡆ

ࡘ࡯ࠍⴕ߁ߴ߈ߢ޽ࠆ㧚ᦨᓟߦ㧘ታㆇ↪ߦ౉ࠆߣ߈ ߪᱜߒ޿⸳ቯࠍⴕߞߡ቟ోߥㆇ↪ࠍᆎ߼ࠆߣߣ߽

ߦ㧘ߘߩᓟߦ⊒⷗ߐࠇߚ࠮ࠠࡘ࡝࠹ࠖࡎ࡯࡞ࠍㅦ߿

߆ߦ߰ߐߋ૕೙ࠍḰ஻ߒߥߌࠇ߫ߥࠄߥ޿㧚 ߢߪᚒޘ߇ណ↪ߒߚᛛⴚߩ᭎ⷐߣࠦ࡯࠼࡟ࡆ 㧟㧚

ࡘ࡯ߩᣇᴺߦߟ޿ߡㅀߴࠆ㧚

࠮ࠠࡘ࡝࠹ࠖߦ㑐ㅪߒߚ೑↪ᛛⴚ 䋳䋮䋱

వߦ߽ㅀߴߚࠃ߁ߦ㧘ࠪࠬ࠹ࡓࠍ቟ోߦ଻ߟߚ߼

ߦߪ㧘ㆡಾߥᛛⴚࠍㆬᛯߒᱜߒߊ૶ࠊߥߌࠇ߫ߥࠄ ߥ޿㧚ߎߎߢߪ㧘ࠗࡦ࠲࡯ࡀ࠶࠻ᔕ↪ࠪࠬ࠹ࡓߩ᭴

▽ߢណ↪ߒߚᛛⴚߩ᭎ⷐࠍขࠅ਄ߍࠆ㧚

߹ߕ㧘ࠨ࡯ࡃࡑࠪࡦߩၮ⋚ߣߥࠆ

OS

ߦ㑐ㅪߒߚ ߎߣࠍㅀߴࠆ ᚒޘߪᓥ᧪߆ࠄ

OS

ߣߒߡ

FreeBSD 8

ࠍណ↪ߒߡ޿ࠆ㧚

FreeBSD

ߪ㧘ࡀ࠶࠻ࡢ࡯ࠢ߿࠮ࠠ

ࡘ࡝࠹ࠖߥߤߦ㑐ߒߡᦨᣂᯏ⢻ࠍታⵝߒ㧘߆ߟ㜞⽶

⩄ᤨߦ߽቟ቯߢᒝജߥ Unix ♽ OS

ߢ޽ࠆ㧚ࠝ࡯ࡊ ࡦ࠰࡯ࠬ࠰ࡈ࠻࠙ࠚࠕߣߒߡ࠮ࠠࡘ࡝࠹ࠖࡄ࠶࠴߽

ㄦㅦߦឭଏߐࠇࠆߚ߼㧘቟ోߢ቟ቯߥࠨ࡯ࡃࠍ᭴▽

ߔࠆߚ߼ߩၮ⋚ߦߥߞߡ޿ࠆ㧚

ߐࠄߦ㧘

FreeBSD

ߦߪ቟ోࠍ㜞߼ࠆᛛⴚ߇ታⵝߐ

chroot Unix

ࠇߡ߅ࠅ㧘ߘߩ৻ߟߦ ߇޽ࠆ㧚ߎࠇߪ

ࠪࠬ࠹ࡓࠦ࡯࡞ߩ৻ߟߢ㧘ࡈࠔࠗ࡞ࠪࠬ࠹ࡓߩ࡞࡯

࠻࠺ࠖ࡟ࠢ࠻࡝ߩ૏⟎ࠍᄌᦝߔࠆߣ޿߁߽ߩߢ޽

ࠆ㧚ߎߩᯏ⢻ࠍᵴ↪ߔࠆߎߣߢ㧘࡙࡯ࠩ߇ࠪࠬ࠹ࡓ ࡈࠔࠗ࡞߿ઁߩ࡙࡯ࠩߩ࠺ࠖ࡟ࠢ࠻࡝߳ࠕࠢ࠮ࠬߔ ࠆߎߣࠍቢోߦ㒐ᱛߢ߈ࠆ㧚ߐࠄߦ

chroot

ߩ᭎ᔨ

ࠍ᜛ᒛߒ ߡ

FreeBSD

ߦߪ

Jail

߇ታⵝߐࠇߡ޿ࠆ

9

ߣߪ㧘઒ᗐ

ࡑࠪࡦࠍታ⃻ߔࠆᯏ⢻ߢ㧘

Jail FreeBSD

ࡑࠪࡦౝߦ㧘߽߁৻ߟߩ ⅣႺࠍ

FreeBSD FreeBSD

૞ࠆߎߣ߇ߢ߈ࠆ

Jail

ߪ

chroot

ࠍ᜛ᒛߒߚ߽ߩߢ ࡀ࠶࠻ࡢ࡯ࠢࡊࡠ࠮ࠬࠍ฽߼ߡ㧘ోࡊࡠ࠮ࠬࠍቢో

ߦ㓒㔌ߢ߈ࠆࠃ߁ߦߒߚ߽ߩߢ޽ࠆ㧚

Jail

ߩ઒ᗐࡑ

ࠪࡦࠍ೑↪ߔࠆߎߣߢ㧘᡹᠄߿ࠪࠬ࠹ࡓ࠳࠙ࡦ߇޽

ߞߚ႐วߢ߽ⵍኂࠍዪᚲⓨ㑆ߦ㐽ߓߎ߼ࠆߎߣ߇น

⢻ߣߥࠆ㧚

੹࿁᭴▽ߒߚࠪࠬ࠹ࡓߪ㧘 WWW

ࠍᔕ↪ߒߚ߽

ߩߢ޽ࠆ㧚ߎߩਛᔃᛛⴚߪታ❣ࠍⓍߺ㧘቟ోߥㆇ↪

ߦ໧㗴ߪ಴ߥ޿㧚ߒ߆ߒ㧘࠺࡯࠲ࡌ࡯ࠬߣߩㅪ៤߿

ࡑ࡞࠴ࡔ࠺ࠖࠕಣℂߩઃടᯏ⢻ߥߤ㧘᜛ᒛ߇ኈᤃߥ

ߎߣ߇໧㗴ࠍᒁ߈⿠ߎߔߎߣ߇޽ࠆ㧚଀߃߫㧘

CGI

Common Gateway Interface

ߪ

Web

ࠨ࡯ࡃߩᯏ⢻ࠍ

⵬ഥߔࠆ઀⚵ߺߢ 10

WWW

ࠢ࡜ࠗࠕࡦ࠻߆ࠄ ࠨ࡯ࡃ਄ߩࡊࡠࠣ࡜ࡓࠍ⿠േߒߡಣℂࠍⴕ

WWW

߁ߎߣߦࠃࠅ㧘േ⊛

HTML

ࠦࡦ࠹ࡦ࠷ࠍ↢ᚑߢ߈ ࠆ㧚

CGI

ߪᮡḰ಴ജߩ૶߃ࠆ⸒⺆ߢ޽ࠇ߫㧘ߤߩࠃ ߁ߥ⸒⺆ࠍ૶ߞߡ߽ታ⃻น⢻ߢ޽ࠆ㧚৻⥸⊛ߦ

᳁߇㐿⊒ߒߚ

ߣ๭߫ࠇࠆ⸒⺆ߢ૶

Larry Wall Perl 11

ࠊࠇߡ߅ࠅ㧘ᚒޘ߽ߎࠇࠍ૶ߞߡ޿ࠆ㧚

ࠨ࡯ࡃߪ㧘ࠝ࡯ࡊࡦ࠰࡯ࠬ࠰ࡈ࠻࠙ࠚࠕ

WWW

ߢ޽ࠆ

Apache 12

ࠍ૶ߞߡ᭴▽ߔࠆ㧚

Apache

ߪ㧘ࡃ

࡯࠴ࡖ࡞࠼ࡔࠗࡦߣ޿߁ᯏ⢻ࠍ߽ߞߡ޿ࠆ㧚ߎߩᯏ

⢻ࠍ૶߁ߣ㧘㧝บߩࠨ࡯ࡃࡑࠪࡦߦᦨૐ৻ߟߩ

IP

ࠕ࠼࡟ࠬࠍഀࠅᝄࠆߛߌߢ㧘ⶄᢙบߩ

WWW

ࠨ࡯

ࡃߣหߓᓎഀࠍᨐߚߔߎߣ߇ߢ߈ࠆ㧚

Apace

ߩࡃ࡯

࠴ࡖ࡞࠼ࡔࠗࡦߦߪ㧞⒳㘃ߩᣇᑼ߇޽ࠆ ৻ߟߪ

IP

ࠕ࠼࡟ࠬߢࡎࠬ࠻ࠍ඙೎ߔࠆᣇᑼߢ޽ࠅ㧘߽߁৻ߟ ߪ

Web ࡉ࡜࠙ࠩ߇ࠨ࡯ࡃߦㅍାߔࠆࡎࠬ࠻ฬࠍర

ߦߒߡᔕ╵ߔࠆࡎࠬ࠻ࠍ᳿ቯߔࠆࡀ࡯ࡓࡌ࡯ࠬᣇᑼ ߢ޽ࠆ㧚

ᦨᓟߦ㧘ᥧภൻᛛⴚࠍขࠅ਄ߍࠆ㧚ࡀ࠶࠻ࡢ࡯ࠢ

ࠍ੺ߒߡ቟ోߥ࠺࡯࠲੤឵ࠍⴕ߁ߚ߼ߦߪ㧘ᥧภൻ ߒߡㅢାࠍⴕ߁ߎߣ߇ᰳ߆ߖߥ޿㧚ߎߩߚ߼ߦ৻⥸

⊛ߦ૶ࠊࠇ޿ࠆߩߪ

SSH Secure SHell

ߢ޽ࠆ

13

ࠍ૶߃߫㧘ᥧภൻߐࠇߚ቟ోߥㅢା߇ⴕ߃ࠆ

SSH

߶߆㧘ࡐ࡯࠻ࡈࠜࡢ࡯࠺ࠖࡦࠣߦࠃࠆធ⛯ߩ᜛ᒛ߇

ߢ߈㧘ᄙ᭽ߢ቟ోߥ೑↪ᣇᴺࠍኈᤃߦታ⃻ߢ߈ࠆ߽

ߩߣߥߞߡ޿ࠆ㧚ߐࠄߦ㧘ࡈࠔࠗ࡞ㅍฃାߦ৻⥸⊛

ߦ೑↪ߐࠇߡ޿ࠆ

FTP

ߪ㧘ᥧภൻ߇ⴕࠊࠇߡ߅ࠄ ߕ㧘࠺࡯࠲߇⋑⡬ߐࠇߡߒ߹߁น⢻ᕈ߇޽ࠆ㧚ߘࠇ

SFTP SSH File

ࠍᡷༀߔࠆߚ߼ߦ㐿⊒ߐࠇߚߩ߇

ߢ㧘ࡄࠬࡢ࡯࠼߿࠺࡯࠲ࠍ ߢ

Transfer Protocol SSH

ᥧภൻߒߡㅍฃାߔࠆߚ߼㧘቟ోߥࡈࠔࠗ࡞ߩㅍฃ

ା߇น⢻ߣߥࠆ㧚

ࠦ࡯࠼࡟ࡆࡘ࡯

䋳䋮䋲

࠮ࠠࡘ࡝࠹ࠖࡎ࡯࡞߿ࡃࠣࠍ⊒⷗ߔࠆߚ߼ߩᚻᲑ ߣߒߡ㧘ࠦ࡯࠼࡟ࡆࡘ࡯߇޽ࠆ㧚ࠦ࡯࠼࡟ࡆࡘ࡯ߣ

(4)

ߪ㧘࠰࡯ࠬࠦ࡯࠼ࠍ⺒ߺ㧘໧㗴ὐ߇ߥ޿߆ᬌ⸽ߔࠆ ߎߣߢ޽ࠆ

14

㧚ࠦ࡯࠼࡟ࡆࡘ࡯ߦߪ㧘࠷࡯࡞ࠍ૶

ߞߡⴕ߁⥄േᬌᩏߣ㧘ੱ߇࠰࡯ࠬࠦ࡯࠼ࠍ⺒ࠎߢ࠴

ࠚ࠶ࠢࠍⴕ߁ᚻേᬌᩏ߇޽ࠆ㧚⥄േൻ࠷࡯࡞ߦߟ޿

ߡ

੹࿁ߪ Rats 15

ࠍ૶ߞߡ⺞ᩏࠍⴕߞߚ

Rats

ߪ

̌ C

C++

PHP

Perl

Python ̍ࠦ࡯࠼ߩ⺞ᩏࠍⴕ

߁ߎߣ߇ߢ߈ࠆ࠷࡯࡞ߢ޽ࠆ㧚৻ᣇ㧘ᚻേᬌᩏߪ㧘

ੱ߇઀᭽ᦠ߿࠰࡯ࠬࠦ࡯࠼ࠍ⺒ߺ㧘࠺࡯࠲ߩᛒ޿ࠍ

࠴ࠚ࠶ࠢߔࠆ߶߆㧘޽߃ߡਇᱜߥ౉ജࠍⴕ޿㧘േ૞

ࠍ࠴ࠚ࠶ࠢߔࠆߎߣ߽ⴕࠊࠇࠆ㧚

⥄േᬌᩏߩ․ᓽߣߒߡ㧘࠴ࠚ࠶ࠢߔࠆੱߩᛛ㊂ߦ ଐሽߒߥ޿ߣ޿߁ࡔ࡝࠶࠻߇޽ࠆ৻ᣇߢ㧘ᬌᩏṳࠇ

߿ᬌᩏਇ⢻ߥ႐ว߇޽ࠆ ߘࠇߦኻߒߡᚻേ⺞ᩏߪ

࠰࡯ࠬࠦ࡯࠼ߛߌߢߪߥߊ㧘઀᭽ᦠߥߤߦၮߠߊ⹦

⚦ߥ࠴ࠚ࠶ࠢ߇น⢻ߦߥࠆ਄㧘ታ㓙ߦേ૞ߐߖߡ࠴

ࠚ࠶ࠢߔࠆߎߣ߇น⢻ߣߥࠆ㧚ߒ߆ߒ㧘ᤨ㑆߇߆߆ ࠆ਄㧘࠴ࠚ࠶ࠢߔࠆੱߩᛛ㊂ߦᄢ߈ߊᏀฝߐࠇࠆߣ

޿߁໧㗴߇޽ࠆ㧚

㧠㧚࠮ࠠࡘ࡝࠹ࠖኻ╷ߩㆡ↪੐଀

ࠦ࡯࠼࡟ࡆࡘ࡯ߩ⚿ᨐ 䋴䋮䋱

ߎࠇ߹ߢߩ⺞ᩏࠍరߦ㧘ቇౝឝ␜᧼ࠪࠬ࠹ࡓ ߩ

3

ࠦ࡯࠼࡟ࡆࡘ࡯ࠍⴕߞߚ㧚ቇౝឝ␜᧼ࠪࠬ࠹ࡓߪ㧘

ቇ↢߳ߩㅪ⛊੐㗄ࠍᓥ᧪ߩᒛࠅ⚕ߦࠃࠆ๔⍮߆ࠄ㧘 ᶧ᥏↹㕙ࠍ೑↪ߒߚ㔚ሶ⊛ߥ⴫␜ߦಾࠅᦧ߃ࠆߎߣ

ߢ㧘ឝ␜᧼▤ℂߩല₸ൻࠍ࿑ࠆࠪࠬ࠹ࡓߢ޽ࠆ㧚ߥ ߅㧘ߎߩࡊࡠࠣ࡜ࡓߪ

Perl

ߢᦠ߆ࠇߡ߅ࠅ㧘ឝ␜

᧼▤ℂࡊࡠࠣ࡜ࡓߣᣂⷙᛩⓂࡊࡠࠣ࡜ࡓߩ㧞ߟߩ

߆ࠄߥࠆว⸘ ⴕ⒟ᐲߩࡊࡠࠣ࡜ࡓߢ޽ࠆ㧚

CGI 500

ᚻേߢߩࠦ࡯࠼࡟ࡆࡘ࡯ࠍⴕߞߚ⚿ᨐ㧘ᄢ߈ߥ࠮

ࠠࡘ࡝࠹ࠖ਄ߩ໧㗴ὐߪߥ߆ߞߚ߽ߩߩ㧘ਅ⸥ߩࠃ ߁ߥዊߐߥ໧㗴ὐ߇⷗ߟ߆ߞߚߩߢ㧘ߚߛߜߦୃᱜ ߒߚ㧚

࠴ࠚ࠶ࠢ߇ਇቢోߥߚ߼

1 png

ࡈࠔࠗ࡞એᄖ߇ࠕ

࠶ࡊࡠ࡯࠼น⢻

ࠛ࡜࡯ߦߥߞߚ႐วߢ߽ࠛ࡜࡯ࡔ࠶࠮࡯ࠫߩ⴫

2

␜ߥߒ

ឃઁಣℂ߇ਇቢోߥߚ߼ࡈࠔࠗ࡞߇਄ᦠ߈ߐࠇ

3

ߡߒ߹߁น⢻ᕈ޽ࠅ

ᰴߦ㧘ࡀ࠶࠻ࡊ࡝ࡦ࠻ࠪࠬ࠹ࡓ

3

ߩ

CGI

ߦߟ޿

ߡ߽ࠦ࡯࠼࡟ࡆࡘ࡯ࠍⴕߞߚ㧚ࡀ࠶࠻ࡊ࡝ࡦ࠻ࠪࠬ

࠹ࡓߪ㧘ࠗࡦ࠲࡯ࡀ࠶࠻ࠍ೑↪ߒߚ࠺ࠫࠞࡔ↹௝ࡊ

࡝ࡦ࠻ᵈᢥࠪࠬ࠹ࡓߢ㧘㧠ߟߩ

CGI 㧔ᵈᢥࡊࡠࠣ࡜

ࡓ㧘࡙࡯ࠩ⊓㍳ࡊࡠࠣ࡜ࡓ㧘ࠨࡓࡀࠗ࡞⴫␜ࡊࡠࠣ

࡜ࡓ㧘ጁᱧ⴫␜ࡊࡠࠣ࡜ࡓ㧕߆ࠄߥࠆว⸘

2000

⒟ᐲߩࡊࡠࠣ࡜ࡓߢ޽ࠆ㧚

Rats Open

߹ߕ ߦࠃࠆ⥄േᬌᩏࠍⴕߞߚߣߎࠈ

㑐ᢙߩ⼊๔߇

15

ࠞᚲ

Mkdir

㑐ᢙߩ⼊๔߇

11

ࠞᚲ

㑐ᢙߩ⼊๔߇ ࠞᚲ⴫␜ߐࠇߚ㧚 㑐ᢙߣ

Rand 2 Open

㑐ᢙߦߟ޿ߡߪ㧘ᒁᢙߦ࡙࡯ࠩ౉ജ୯ࠍ೑↪

Mkdir

ߒߡ޿ࠆ႐ว㧘ࡄࠬߩਸ਼ࠅ⿧߃ߥߤߩ໧㗴ࠍᒁ߈⿠

ߎߔน⢻ᕈ߇޽ࠆߎߣࠍ␜ߒߡ޿ࠆ㧚৻ᣇ㧘

Rand

㑐ᢙߦߟ޿ߡߪ㧘ᮡḰߩੂᢙࠫࠚࡀ࡟࡯࠲ߪᕈ⢻߇ ᖡߊ㧘⚿ᨐ߇஍ࠅ߇ߜߦߥࠆߚ߼㧘࠮࠶࡚ࠪࡦ

ID

ࠍផ᷹ߒ߿ߔߊߥߞߡߒ߹߁ߎߣ߇ᜰ៰ߐࠇߚ㧚

ᜰ៰ߐࠇߚㇱಽࠍ࠴ࠚ࠶ࠢߒߡߺߚߣߎࠈ㧘 Open

㑐ᢙߣ

Rand

㑐ᢙߣߦߟ޿ߡ㧘࡙࡯ࠩ౉ജࠍᒁᢙߣ ߒߡ޿ࠆ߽ߩߪߥ߆ߞߚ㧚৻ᣇ㧘

Rand

㑐ᢙߩ໧㗴 ߪ㧘

FreeBSD

ߩ

Ports

߆ࠄ೎ߩੂᢙࠫࠚࡀ࡟࡯࠲ࠍ

ࠗࡦࠬ࠻࡯࡞ߔࠆߎߣߢᡷༀߒߚ㧚

⛯޿ߡࠦ࡯࠼࡟ࡆࡘ࡯ࠍᚻേߢⴕߞߚߣߎࠈ㧘 ߢᬌ಴ߐࠇߡ޿ߥ޿ 㑐ᢙ߿ 㑐ᢙ߇

Rats Open Mkdir

޿ߊߟ߽޽ߞߚ㧚⺞ߴߡߺࠆߣ㧘

open FH,filename

ߩࠃ߁ߦ᜝ᒐߢߊߊߞߡᦠ޿ߚ႐วߪ࠴ࠚ࠶ࠢߩኻ

⽎ߣߥࠅ㧘

open FH,filename

ߩࠃ߁ߦ᜝ᒐߢߊߊࠄߕߦᦠ޿ߚ႐วߪ࠴ࠚ࠶ࠢߩ ኻ⽎ߣߥߞߡ޿ߥ߆ߞߚ㧚⴫⃻ߩ⥄↱ᐲߩ㜞޿

Perl

ߩᬌᩏߦߪ㧘޽߹ࠅะ߆ߥ޿࠷࡯࡞ߣ޿߃ࠆ߆߽ߒ ࠇߥ޿㧚

ߘߩઁߩㇱಽߦߟ޿ߡ߽࠴ࠚ࠶ࠢࠍⴕ޿㧘ਇክߥ

ㇱಽߦߪታ㓙ߦਇᱜߥ౉ജࠍⴕߞߡߺߚߣߎࠈ㧘޿

ߊߟ߆ߩ໧㗴ὐ߇⷗ߟ߆ߞߚߚ߼㧘ᡷༀߢ߈ࠆㇱಽ ߪᡷ⦟ࠍⴕߞߚ㧚⷗ߟ߆ߞߚ໧㗴ὐࠍએਅߦ␜ߔ㧚 ࡙࡯ࠩ⊓㍳ߩࡔ࡯࡞ࠕ࠼࡟ࠬᰣߦᡷⴕࠦ࡯࠼ࠍ

1 ᝌ౉ߔࠆߣ㧘છᗧߩ࠲ࠗ࠻࡞࡮ᧄᢥࠍᝌ౉ߔࠆߎ

ߣ߇น⢻

ࠨ࠾࠲ࠗࠫࡦࠣᢥሼߩਇ⿷

2

ኻ╷߇ήᗧ๧

3 XSS

ࡈࠔࠗ࡞એᄖߩ߽ߩ߇ࠕ࠶ࡊࡠ࡯࠼น⢻

4 JPEG

ࡠࠣࠗࡦᄬᢌᤨߩࠛ࡜࡯ࡔ࠶࠮࡯ࠫ߇ਇㆡಾ

5

ᠲ૞↹㕙߿

6 HTML

ߩ

Hidden

ࡈࠖ࡯࡞࠼ߦࡔ࡯

࡞ࠕ࠼࡟ࠬࠍ⴫␜

ᠲ૞↹㕙ߩࠕ࠼࡟ࠬࡃ࡯߿ࠬ࠹࡯࠲ࠬࡃ࡯ߩ⴫

7

␜ߥߒ

࡙࡯ࠩ⊓㍳ᤨ࡮ࡠࠣࠝࡦᤨߩ࠺࡯࠲ࠍᐔᢥߢㅍ

8

ࠍ᦭ലߦߔࠆᔅⷐ߇޽ࠆߎߣ߇ᧂ⴫␜

9 JavaScript

ࠗࡦ࠲࡯ࡀ࠶࠻ᔕ↪ࠪࠬ࠹ࡓߣណ↪ᛛⴚ 䋴䋮䋲

ᚒޘߪ㧘࠺ࠫ࠲࡞ࠞࡔ࡜ߢ᠟ᓇߒߚ↹௝ߣᨎᢙ࡮

ࠨࠗ࠭ߩᖱႎࠍࠗࡦ࠲࡯ࡀ࠶࠻ߢㅍାߒᵈᢥࠍฃߌ

ઃߌ㧘ᵈᢥ 30 ಽᓟߦ౮⌀ࠍฃߌขࠆߎߣ߇ߢ߈ࠆ

ࡀ࠶࠻ࡊ࡝ࡦ࠻ࠪࠬ࠹ࡓࠍ㐿⊒ߒߚ㧔

Fig.1 㧕 3

㧚ߎ ߩࠪࠬ࠹ࡓߪ㧘↹௝⊓㍳߆ࠄᵈᢥ߹ߢߩ৻ㅢࠅߩᯏ

⢻ࠍቢᚑߐߖ㧘౮⌀ᐫ߳శࡈࠔࠗࡃߦࠃࠆࠗࡦ࠲࡯

ࡀ࠶࠻ធ⛯ⅣႺࠍḰ஻ߒ㧘ᐫ⥩ߦ⸳⟎ߒߚࠨ࡯ࡃߢ

(5)

ㆇ↪ߒߡ߈ߚ㧚ߘߩᓟ㧘㧝บߩࠨ࡯ࡃߢⶄᢙᐫ⥩߳

ኻᔕߔࠆߎߣ߿㧘ㆇ↪ߢ↢ߓߚ໧㗴ࠍ⸃ᶖߔࠆᯏ⢻

᜛ᒛߩⷐᦸ߇޽ࠅ㧘⒳ޘߩኻᔕࠍⴕߞߡ޿ࠆ㧚ߎߩ ㆊ⒟ߢណ↪ߒߚᛛⴚࠍ㧘ਥߦ࠮ࠠࡘ࡝࠹ࠖ⏕଻ߩⷰ

ὐ߆ࠄㅀߴࠆ㧚

Order picture of the NetPrint System Fig.1

⃻࿷ߩࠪࠬ࠹ࡓߪ 1 ␠ߩߺ߇ㆇ༡ߔࠆࠨ࡯ࡆࠬߢ

޽ࠆ㧚ߎࠇࠍ㧘ઁߩࠞࡔ࡜ᐫ߆ࠄ߽೑↪ߒߚ޿ߣ޿

߁ⷐᦸ߇޽ߞߚ㧚ߎߩߣ߈㧘ࠦࠬ࠻ࠍ೥ᷫߔࠆᔅⷐ ߇޽ࠆߚ߼㧘㧝บߩࠨ࡯ࡃࡑࠪࡦ਄ߢⶄᢙߩᐫ⥩ࠍ

Ⓙ௛ߐߖࠆߎߣߣߥߞߚ㧚㧝บߩࡑࠪࡦߢⶄᢙߩࠪ

ࠬ࠹ࡓࠍേ૞ߐߖࠆᣇᴺߣߒߡ㧘

Jail

ߣࡃ࡯࠴ࡖ࡞

࠼ࡔࠗࡦ߇⠨߃ࠄࠇࠆ㧚

Jail Jail

㐿⊒ᒰೋ ࠍ↪޿ߡࠪࠬ࠹ࡓࠍ᭴▽ߒߚ㧚 ࠍ૶߁ߣᐫ⥩ᖱႎࠍቢోߦಽ㔌ߢ߈ࠆ߽ߩߩ㧘ࡀ࠶

࠻ࡢ࡯ࠢ߇⁛┙ߒߡ޿ࠆߚ߼㧘ฦᐫ⥩ߏߣߦ

IP

࠼࡟ࠬ߇ᔅⷐߣߥࠆ㧚⃻⁁ߢߪ࿕ቯ

IP

ࠕ࠼࡟ࠬข

ᓧ⾌↪߇߆ߥࠅ⽶ᜂߣߥߞߡ޿ࠆߚ߼㧘৻ߟߩ IP

ࠕ࠼࡟ࠬߢᷣ߻ࡃ࡯࠴ࡖ࡞࠼ࡔࠗࡦࠍ೑↪ߔࠆߎߣ ߣߥߞߚ㧚ࡃ࡯࠴ࡖ࡞࠼ࡔࠗࡦߢߪ㧘

Web ࡉ࡜࠙

ࠩ߇ࡃ࡯࠴ࡖ࡞࠼ࡔࠗࡦኻᔕߢ޽ࠆᔅⷐ߇޽ࠆ㧚ߎ

ߩὐߪ㧘ᒰࠪࠬ࠹ࡓߩផᅑࡉ࡜࠙ࠩ߇ࡃ࡯࠴ࡖ࡞࠼

InternetExplorer6 Opera Ver6

ࡔࠗࡦߦኻᔕߒߚ એ਄㧘

એ਄ߣߥߞߡ޿ࠆߚ߼㧘ࡃ࡯࠴ࡖ࡞࠼ࡔࠗࡦࠍ↪޿

ߡࠪࠬ࠹ࡓߩ᭴▽ࠍⴕߞߚ㧚

ࡃ࡯࠴ࡖ࡞࠼ࡔࠗࡦࠍ೑↪ߔࠆߣ㧘หߓࠨ࡯ࡃࡑ

ࠪࡦߦⶄᢙᐫ⥩߆ࠄߩࠕࠢ࠮ࠬ߇޽ࠆ㧚ᮡḰ⁁ᘒߢ ߪઁᐫ⥩ߩᖱႎ߽߳ࠕࠢ࠮ࠬߔࠆߎߣ߇น⢻ߣߥࠆ ߚ߼㧘ኻ╷ࠍᣉߔᔅⷐ߇޽ࠆ㧚߹ߚ㧘↹௝ߩ࠳࠙ࡦ ࡠ࡯࠼ࠍⴕ߁ੱ߇ࠦࡦࡇࡘ࡯࠲ߦ⹦ߒ޿ߣߪ㒢ࠄ ߕ㧘ࠪࠬ࠹ࡓࡈࠔࠗ࡞ࠍᦠ߈឵߃ߚࠅ㧘೥㒰ߒߚࠅ ߒߡߒ߹߁ߣࠪࠬ࠹ࡓ࠻࡜ࡉ࡞ߩේ࿃ߣߥࠆ㧚

ߎߩ໧㗴ࠍㆱߌࠆߚ߼㧘

chroot

ࠍ↪޿ߡࠕࠢ࠮ࠬ

೙㒢ࠍⴕߞߚ㧚߹ߕ㧘ฦᐫ⥩ߏߣߦ

chroot

ࠍ⸳ቯ

ߒ㧘ઁᐫ⥩߳ߩࠕࠢ࠮ࠬࠍ⑌ᱛߒߚ㧚ߐࠄߦ㧘ฦᐫ

⥩㗔ၞߩਛߩ㧘ࡎ࡯ࡓࡍ࡯ࠫ࡮ଔᩰ࠺࡯࠲࡮ᵈᢥ↹

௝ߩฦ࠺ࠖ࡟ࠢ࠻࡝ߦ chroot

ࠍ⸳ቯߒ㧘↪ㅜߏߣ ߩ࡙࡯ࠩࠍ૞ᚑߔࠆߎߣߢᠲ૞ࡒࠬߦࠃࠆࠪࠬ࠹ࡓ

࠻࡜ࡉ࡞ࠍ㒐޿ߢ޿ࠆ㧚߹ߚ㧘࠺࡯࠲ォㅍߪߔߴߡ ࠍ૶޿㧘┵ᧃࡄ࠰ࠦࡦߦᔅⷐߥࡊࡠࠣ࡜ࡓ߿

SFTP

㎛ࠍ⥄േߢዉ౉ߢ߈ࠆࠃ߁㧘ࠗࡦࠬ࠻࡯࡞ CD

߽૞

ᚑߒߚ㧚

⃻࿷ࡃ࡯࠴ࡖ࡞࠼ࡔࠗࡦࠍ↪޿ߚࠪࠬ࠹ࡓࠍ᭴▽

ߒ㧘ࠗࡦ࠲࡯ࡀ࠶࠻਄ߢㆇ↪ࠍ㐿ᆎߒߚ㧚ߎߩᬌ⸛

ߣਗⴕߒߡࠦ࡯࠼࡟ࡆࡘ࡯ߦࠃࠅࡊࡠࠣ࡜ࡓࠍ⷗⋥

ߒ㧘ᄙᐫ⥩ኻᔕ߇ኈᤃߦⴕ߃ࠆࠃ߁㧘ᐫ⥩࿕᦭ᖱႎ ߩಽ㔌⛔วࠍⴕߞߚ㧚ߎߩઁߦ㧘ࡄࠬࡢ࡯࠼ߩᄌᦝ ᯏ⢻߿ฎ޿↹௝ߩ⥄േ೥㒰ᯏ⢻ߩታⵝߥߤ㧘ࠃࠅ૶

޿߿ߔߊߔࠆᯏ⢻ߩㅊട߽ⴕߞߡ޿ࠆ㧚

੹ᓟߪ㧘ᐫ⥩ࠍㅊടߒߡㆇ↪ߒߚߣ߈㧘ⶄᢙᐫ⥩

ߩࠕࠢ࠮ࠬ߇

1 บߩࡑࠪࡦߦ㓸ਛߔࠆߚ߼㧘ߤߩ⒟

ᐲ߹ߢ㧝บߩࡑࠪࡦߢኻᔕน⢻ߥߩ߆ߦߟ޿ߡᬌ⸽

ߒߥߌࠇ߫ߥࠄߥ޿㧚

㧡㧚޽ߣ߇߈

ᧄ⺰ᢥߢߪ㧘ࠗࡦ࠲࡯ࡀ࠶࠻ᔕ↪ࠪࠬ࠹ࡓࠍ᭴▽

ߔࠆߣ߈㧘࠮ࠠࡘ࡝࠹ࠖ㕙ߢ૗ߦᵈᗧߒߤ߁ᬌ⸽ߔ ࠇ߫⦟޿߆ࠍ㧘ౕ૕⊛ߥࠪࠬ࠹ࡓ᭴▽߿ᡷ⦟ߩ⚻㛎 ࠍ߽ߣߦㅀߴߚ㧚⃻࿷㧘ⶄᢙߩࠨ࡯ࡃ߇ታ㓙ߦ቟ో

ߦⒿ௛ߒߡ߅ࠅ㧘ᚒޘߩ㐿⊒߇ㆡಾߦⴕࠊࠇߡ޿ࠆ ߣ⠨߃ߡ޿ࠆ㧚

㐿⊒ߒߚࠪࠬ࠹ࡓߪ㧘ࠪࠬ࠹ࡓᧄ૕ߣ▤ℂࠍᄖㇱ ߦ⒖ォߒߡ޿ࠆ߽ߩ߽ᄙ޿

16

㧚ߎߩߚ߼㧘ߎࠇ߆ ࠄߪㆇ↪▤ℂߩ㕙߆ࠄㅪ៤వડᬺߣ౒หߒߡ㧘቟ో

ߢ቟ቯߥࠪࠬ࠹ࡓㆇ↪ߦദജߒߥߌࠇ߫ߥࠄߥ޿ߣ

⠨߃ߡ޿ࠆ㧚

⻢ ㄉ

ߎߎߢขࠅ਄ߍߚࠪࠬ࠹ࡓߩ㐿⊒ߦߪ㧘࿾రડᬺ

㑐ଥ⠪ߩᄙᄢߥߏදജࠍ޿ߚߛ߈߹ߒߚ㧚ߎߩ႐ࠍ

୫ࠅߡᷓߊᓮ␞↳ߒ਄ߍ߹ߔ㧚

ෳ ⠨ ᢥ ₂

1

ጟ↰࡮ㄭ⮮ ᵤጊᎿᬺ㜞╬ኾ㐷ቇᩞ♿ⷐ

:

No.41

1999

5-11.

2

ጟ↰࡮㊁᧛ ᵤጊᎿᬺ㜞╬ኾ㐷ቇᩞ♿ⷐ

:

No.44

2002

21- 24.

3

ችጟ࡮⴩═࡮ጟ↰ ᵤጊᎿᬺ㜞╬ኾ㐷ቇᩞ♿ⷐ

:

No.46

200 4

59-66.

No.48

4

↰ᷨ࡮૒㊁࡮ጟ↰

:

ᵤጊᎿᬺ㜞╬ኾ㐷ቇᩞ♿ⷐ

2006 55-60.

㧔ጊญ⋙⸶㧕 ࠦࡦࡇࡘ࡯࠲࠮

5 D. Russell and G.T.Gangemi Sr. :

(6)

1994 .

ࠠࡘ࡝࠹ࠖߩၮ␆㧘ࠕࠬࠠ࡯಴ ዪ

ࠕࡊ࡝ࠤ࡯࡚ࠪࡦߩ⣀ᒙᕈߪୃᓳߒߡ߽ߥ߅ 㧑ߦ⣀

6 Web 93

,http://internet.watch.impress.co.jp/cda/news/2004/

ᒙ ᕈ ߇ ᱷ ࠆ

06/30/3698.html.

ࠕࡊ࡝ࠤ࡯࡚ࠪࡦߦẜ߻࠮ࠠࡘ࡝࠹ࠖࡎ࡯࡞ ╙㧝࿁㨪

7

Web

,http://www.atmarkit.co.jp/fsecurity/rensai/Webhole

╙㧝㧞࿁

01/Webhole01.html

.

8

The FreeBSD Project: http://www.freebsd.org/

http://www.freebsd.org/doc/en_US.ISO8859-1/

9

Jails:

books/handbook/jails.html.

10

CGI

ߣߪ૗߆㧦

http://mtlab.ecn.fpu.ac.jp/scripting/about_cgi.html

http://www.perl.com/.

11

The Source for Perl:

12

The Apache HTTP Server Project: http://httpd.apache.org/.

㧔ዊፉ⋙⸶ 㧦ታ↪

13 D.J. Barrett, R.E. Silverman, R.G. Byrnes

SSH

╙  㧘ࠝ࡜ࠗ࡝࡯࡮ࠫࡖࡄࡦ

2 2006 .

㧔ᣂ੗㧘৻ἑ⸶ 㧦࠮ࠠࡘࠕࡊࡠࠣ

14 M.G. Graff, K.R. van Wyk

࡜ࡒࡦࠣ㧙ᄬᢌ߆ࠄቇ߱⸳⸘࡮ታⵝ࡮ㆇ↪࡮▤ℂ ࠝ࡜ࠗ࡝࡯

, 2004 120-137.

ࠫࡖࡄࡦ㧔

15

Secure Software: http://www.securesoftware.com/.

16)

ጟ↰㧦╙ ࿁ో࿖㜞ኾ࠹ࠢࡁࡈࠜ࡯࡜ࡓ੍Ⓜ㓸

5 (2007-8) 62-

63.

参照

関連したドキュメント

We show that a discrete fixed point theorem of Eilenberg is equivalent to the restriction of the contraction principle to the class of non-Archimedean bounded metric spaces.. We

The aim of this work is to prove the uniform boundedness and the existence of global solutions for Gierer-Meinhardt model of three substance described by reaction-diffusion

Thus, we use the results both to prove existence and uniqueness of exponentially asymptotically stable periodic orbits and to determine a part of their basin of attraction.. Let

, 6, then L(7) 6= 0; the origin is a fine focus of maximum order seven, at most seven small amplitude limit cycles can be bifurcated from the origin.. Sufficient

As an application, we present in section 4 a new result of existence of periodic solutions to such FDI that is a continuation of our recent work on periodic solutions for

In addition to the basic facts just stated on existence and uniqueness of solutions for our problems, the analysis of the approximation scheme, based on a minimization of the

This paper presents an investigation into the mechanics of this specific problem and develops an analytical approach that accounts for the effects of geometrical and material data on

II Midisuperspace models in loop quantum gravity 29 5 Hybrid quantization of the polarized Gowdy T 3 model 31 5.1 Classical description of the Gowdy T 3