**Ìܼ¡ [#x07d335b]
 
 #contents
 
 **¤³¤Î¥É¥­¥å¥á¥ó¥È¤Ï¡© [#xec7bab0]
 
 PHP¤Ë¤è¤ëWeb¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¹½ÃÛ»þ¤Î¥»¥­¥å¥ê¥Æ¥£Âкö¤Ë´Ø¤·¤Æ¼ÒÆâ¤ÎÊÙ¶¯²ñÍѤË
   ¡¦<a href="http://www.asahi-net.or.jp/~wv7y-kmr/memo/php_security.html" target="_blank">PHP ¤È Web ¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥»¥­¥å¥ê¥Æ¥£¤Ë¤Ä¤¤¤Æ¤Î¥á¥â</a>
   ¡¦<a href="http://www.ipa.go.jp/security/awareness/vendor/programming/
 " target="_blank">IPA ISEC ¥»¥­¥å¥¢¡¦¥×¥í¥°¥é¥ß¥ó¥°¹ÖºÂ</a>
   ¡¦<a href="http://www.amazon.co.jp/gp/product/4883374718/503-3339577-1535166?v=glance&n=465392&s=gateway" target="_blank">PHP¥µ¡¼¥Ð¡¼¥Æ¥í¤Îµ»Ë¡¡¡GIJOE Ãø¡¡¥½¥·¥à</a>
 ¤«¤éÆä˵¤¤Ë¤Ê¤ë¡¢Ãí°Õ¤·¤Æ¤ª¤­¤¿¤¤¡¢Ã諤äÌäÂê¡¢Âкö¤Ê¤É¤ò´Ê°×¤Ë¥á¥â¤·¤¿¤â¤Î¤Ç¤¹¡£
 
 ÊÙ¶¯²ó¤½¤Î¤â¤Î¤Ï<a href="http://www.asahi-net.or.jp/~wv7y-kmr/memo/php_security.html" target="_blank">PHP ¤È Web ¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥»¥­¥å¥ê¥Æ¥£¤Ë¤Ä¤¤¤Æ¤Î¥á¥â</a>¤òÆɤߤʤ¬¤é¿Ê¤á¤Þ¤¹¡£
 
 **¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥° [#ka10177d]
 
 -¥µ¥Ë¥¿¥¤¥º¤Î¥¿¥¤¥ß¥ó¥°¤ÏHTMLÀ¸À®»þ~
 ~
 <a href="http://www.ipa.go.jp/security/awareness/vendor/programming/
 " target="_blank">IPA ISEC ¥»¥­¥å¥¢¡¦¥×¥í¥°¥é¥ß¥ó¥°¹ÖºÂ</a>¤è¤ê
 
   ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¤Î²òÀâµ­»ö¤Ç¤è¤¯ÀâÌÀ¤µ¤ì¤ë¡ÖÆþÎϥǡ¼¥¿¥Á¥§¥Ã¥¯¤ò¸·Ì©¤Ë¡×¤È¤¤¤¦É½¸½¤«¤é¡¤¿Þ3¤Î(1) ¥Õ¥©¡¼¥à¼õÉÕ»þ¤Î¥¿¥¤¥ß¥ó¥°¤Ç¥µ¥Ë¥¿¥¤¥¸¥ó¥°¤ò¹Ô¤¦¤Î¤«¤È»×¤¤¤¬¤Á¤Ç¤¢¤ë¡£¥µ¥Ë¥¿¥¤¥¸¥ó¥°¤Ï(2)HTMLÀ¸À®»þ¤Î¥¿¥¤¥ß¥ó¥°¤Ç¹Ô¤¦¤Ù¤­¤Ç¤¢¤ë¡£¼¡¾Ï¡Ö¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°Âкö¤Î¾ÜºÙ¡×¤ÇÀâÌÀ¤¹¤ë¤¬¡¤¥Ç¡¼¥¿¤òËä¤á¹þ¤àHTMLÃæ¤Îʸ̮¤Ë¹ç¤ï¤»¤ÆŬÀڤʥµ¥Ë¥¿¥¤¥¸¥ó¥°¼êË¡¤òÁªÂò¤¹¤ëɬÍפ¬¤¢¤ë¤«¤é¤Ç¤¢¤ë¡£¤Þ¤¿·Ç¼¨ÈĤÎÎã¤Ç¤Ï¡¤¾­ÍèŪ¤Ë¥Ç¡¼¥¿¥Ù¡¼¥¹¤Ø¤Îµ­»ö¤Î½ñ¤­¹þ¤ß¼êÃʤȤ·¤Æ¡¤¥á¡¼¥ë¤Ë¤è¤ëÅê¹Æ¤¬Æ³Æþ¤µ¤ì¤¿¾ì¹ç¤Ç¤â¡¤(2)HTMLÀ¸À®»þ¤Î¥¿¥¤¥ß¥ó¥°¤Ç¥µ¥Ë¥¿¥¤¥¸¥ó¥°¤·¤Æ¤¤¤ì¤Ð¡¤¤Ê¤ó¤é¼ê¤ò²Ã¤¨¤ë¤³¤È¤Ê¤¯¡¤¤¤¤í¤ó¤ÊÆþÎϸ»¤«¤éÆþ¤ê¹þ¤ó¤Ç¤¯¤ë¥Ç¡¼¥¿¤òϳ¤ì¤Ê¤¯¥µ¥Ë¥¿¥¤¥¸¥ó¥°¤Ç¤­¤ë¡£¤Þ¤¿¡¤Æ±¤¸¥Ç¡¼¥¿¤Ë¸í¤Ã¤Æ2²ó°Ê¾å¥µ¥Ë¥¿¥¤¥¸¥ó¥°¤·¤Æ¥Ç¡¼¥¿¤Î°ÕÌ£¤¬ÊѤï¤Ã¤Æ¤·¤Þ¤¦¤È¤¤¤¦Àß·×¾å¤Î¥È¥é¥Ö¥ë¤âËɤ²¤ë¡£
   
   ¤³¤Î¤è¤¦¤Ë¥µ¥Ë¥¿¥¤¥¸¥ó¥°¤Î¥¿¥¤¥ß¥ó¥°¤Ï(1)¥Õ¥©¡¼¥à¼õÉÕ»þ¤Ç¤Ï¤Ê¤¯¡¤(2)HTMLÀ¸À®»þ¤Ç¤Ê¤±¤ì¤Ð¤Ê¤é¤Ê¤¤¡£»²¹Íʸ¸¥¡ØUnderstanding Malicious Content Mitigation for Web Developers¡Ù¤Ç¤âHTMLÀ¸À®»þ¤Î¥µ¥Ë¥¿¥¤¥¸¥ó¥°¤ò¿ä¾©¤·¤Æ¤¤¤ë¡£
 
 -style ¥¿¥°¤ä script ¥¿¥°¤ÎÆâÉô¤Ë³°Éô¤«¤é¤ÎÆþÎϤÏÁȤ߹þ¤Þ¤Ê¤¤~
 ~
 ¥æ¡¼¥¶¤ËHTML¥¿¥°¤ä¥¹¥¿¥¤¥ë¥·¡¼¥È¤òµ­½Ò¤µ¤»¤ë¾ì¹ç¤Î»²¹Í~
 ~
 <a href="http://hatenadiary.g.hatena.ne.jp/keyword/%e3%81%af%e3%81%a6%e3%81%aa%e3%83%80%e3%82%a4%e3%82%a2%e3%83%aa%e3%83%bcXSS%e5%af%be%e7%ad%96" target="_blank">¤Ï¤Æ¤Ê¥À¥¤¥¢¥ê¡¼¤ÎXSSÂкö</a>
 
 -ÆþÎϥǡ¼¥¿ÁÞÆþÉô¤Ë¤è¤Ã¤ÆÂкö¤ÎÀÚ¤êʬ¤±¤¬É¬Í×~
 ~
 Ä̾ï¤Î¥Æ¥­¥¹¥ÈÉô¡¢¥¿¥°Â°À­ÃÍ¡¢URL°À­¡¢¥¤¥Ù¥ó¥È¥Ï¥ó¥É¥é°À­¡¢<SCRIPT>¡¢<!-- -->¡¢
 ¥¹¥¿¥¤¥ë¥·¡¼¥È¤Ê¤É¤Ë¤è¤Ã¤Æ°Û¤Ê¤ëÂкö¤¬É¬Íס£~
 <a href="http://www.ipa.go.jp/security/awareness/vendor/programming/a01_02.html" target="_blank">IPA ISEC ¥»¥­¥å¥¢¡¦¥×¥í¥°¥é¥ß¥ó¥°¹ÖºÂ 1-2. ¥¯¥í¥¹¥µ¥¤¥È¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°</a>»²¾È
 
 **HTTP¥ì¥¹¥Ý¥ó¥¹Ê¬³ä¹¶·â [#rd5fc8da]
 
 -header()¡¢setcookie()¤Ë²þ¹Ô¤ò´Þ¤àÃͤò¤ï¤¿¤é¤»¤Ê¤¤¤è¤¦¤Ë¤¹¤ë
 
 -PHP 4.4.2 / PHP 5.1.2 ¤Ç¤Ï¡¢°ìÅÙ¤ÎÊ£¿ô¤Î¥Ø¥Ã¥À¤òÁ÷¤ë¤³¤È¤¬¤Ç¤­¤Ê¤¤¤è¤¦¤Ë½¤Àµ¤µ¤ì¤Æ¤¤¤ë
 
 **NULL ¥Ð¥¤¥È¹¶·â [#bdf6e920]
 
 -¥Ð¥¤¥Ê¥ê¥»¡¼¥Õ¤¸¤ã¤Ê¤¤´Ø¿ô¤Ç¥Á¥§¥Ã¥¯¤·¤¿¸å¤Ë¥Ð¥¤¥Ê¥ê¥»¡¼¥Õ¤Î´Ø¿ô¤ò»È¤¦¡£¤Þ¤¿¤Ï¤½¤ÎµÕ¤Î¥±¡¼¥¹¤ÇÁÛÄê³°¤ÎÆ°ºî¤ò¤·¤Æ¤·¤Þ¤¦ÌäÂê¡£
 
 -Àµµ¬É½¸½¤Î¥Á¥§¥Ã¥¯Åù¤ÇÃí°Õ¡£ereg·Ï¤Ï¥Ð¥¤¥Ê¥ê¥»¡¼¥Õ¤Ç¤Ï¤Ê¤¤¡£¸Ä¿ÍŪ¤Ë¤Ï¥Ð¥¤¥Ê¥ê¥»¡¼¥Õ¤Îpreg·Ï¤ÇÅý°ì¤¹¤ë¤Î¤¬¤è¤¤¤È»×¤¦¡£
 
 -¥Õ¥¡¥¤¥ë̾¤òľÀÜ°ú¿ô¤ÇÅϤ¹¤è¤¦¤ÊÀ߷פò¤·¤Ê¤¤¡ÊNULL ¥Ð¥¤¥È¹¶·â¤ÇǤ°Õ¤Î¥Õ¥¡¥¤¥ë¤¬Æɤ᤿¤ê¤¹¤ë²ÄǽÀ­¤¢¤ê¡Ë¡£¤³¤Î¾ì¹ç¤Ï²¼µ­¤Î¤è¤¦¤Ë¥Ï¥Ã¥·¥åÅù¤òÍÑ°Õ¤·¤ÆÂн褹¤ë~
 ~
         $config_file_list = array('add' => 'add.conf', 'del' => 'del.conf');
         require($config_file_list[$_GET['command']]);
 ~
 SQL¤ËÅϤ¹¥«¥é¥àÃͤʤɤ⤳¤ÎÊýË¡¤ò»È¤¤¡¢Ä¾ÀÜÅϤµ¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¤Î¤¬Ë¾¤Þ¤·¤¤¡£
 
 **Email ¥Ø¥Ã¥À¡¦¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó [#lf88be37]
 
 -HTTP¥ì¥¹¥Ý¥ó¥¹Ê¬³ä¤È°Õ¿Þ¤ÏËؤÉƱ¤¸¡£ÅǤ­½Ð¤¹¥Ø¥Ã¥À¤ò¥Á¥§¥Ã¥¯¤·¤Æ¡¢¥æ¡¼¥¶¤Î
 ÆþÎÏÃͤò¤½¤Î¤Þ¤Þ½Ð¤µ¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¡£²þ¹Ô¼þ¤ê¤ËÆäËÃí°Õ¡£
 
 **include()¡¢require() [#cd8dd501]
 
 -allow_url_fopen ¤ò Off¤Ë¤¹¤ë¤Î¤Ï´ðËÜ¡£¤Ç¤â¡¢¤³¤ì¤À¤±¤Ç¤ÏÉÔ½¼Ê¬¡£~
 php://input¤ò»ÈÍѤ¹¤ëÊýË¡¤¬¤¢¤ë¡£
 
 -Âкö¤È¤·¤Æ¤ÏNULL¥Ð¥¤¥È¹¶·â¤ÈƱ¤¸¡£¸¶Â§¥æ¡¼¥¶¤ÎÆþÎÏÃͤò¤½¤Î¤Þ¤Þinclude()¡¢require()¤Ë
 ¤ï¤¿¤µ¤º¡¢¥Ï¥Ã¥·¥å¤äÇÛÎ󡢥ơ¼¥Ö¥ë¤Ê¤É¤òÍÑ°Õ¤·¤Æ¤ª¤¤¤Æ¡¢¥æ¡¼¥¶¤ÎÆþÎÏÃͤˤè¤Ã¤Æ¡¢include()¡¢require()¤ËÍ¿¤¨¤ëÃͤò¥Ç¡¼¥¿¹½Â¤¤«¤é¼è¤ê½Ð¤¹¤è¤¦¤Ë¤¹¤ì¤Ð£Ï£Ë
 
 -eval·Ï¤ò»È¤¦»þ¤ÏÆþÎÏ¥Á¥§¥Ã¥¯¤ËËüÁ´¤ÎÃí°Õ¤ò¡Ê¥Ö¥é¥Ã¥¯¥ê¥¹¥ÈË¡¤ò»È¤¦¤³¤È¡Ë
 

¥È¥Ã¥×   ¿·µ¬ °ìÍ÷ ñ¸ì¸¡º÷ ºÇ½ª¹¹¿·   ¥Ø¥ë¥×   ºÇ½ª¹¹¿·¤ÎRSS

¥¢¡¼¥¯¥¦¥§¥Ö¤Î¥µ¡¼¥Ó¥¹¤ä¥½¥ê¥å¡¼¥·¥ç¥ó¤Ï¤³¤Á¤é