¥½¥ê¥å¡¼¥·¥ç¥ó¡¦¥µ¡¼¥Ó¥¹
PCIDSS¤Ë´ð¤Å¤¤¤¿3¥¿¥¤¥×¤ÎÀȼåÀ¸¡ºº¤¬Í¸ú
PCIDSS¤Ë´ð¤Å¤¤¤¿3¥¿¥¤¥×¤ÎÀȼåÀ¸¡ºº¤¬Í¸ú
½°µÄ±¡¥µ¡¼¥Ð¡¼¤Ø¤Î¥µ¥¤¥Ð¡¼¹¶·â¤Ç¡¢¹ñ²È¥ì¥Ù¥ë¤Îµ¡Ì©¾ðÊóϳ¤¨¤¤»ö·ï¤¬È¯À¸¤¹¤ë¤Ê¤É¡¢¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¤ä¥¦¥£¥ë¥¹¸¡ÃÎ¥½¥Õ¥È¤À¤±¤Ç¤Ï¡¢¥¦¥£¥ë¥¹¤ÎÀøÆþ¡¦Ï³¤¨¤¤¹Ôư¤òËɤ²¤Ê¤¯¤Ê¤Ã¤Æ¤¤Æ¤¤¤Þ¤¹¡£
Web¥µ¥¤¥È¤«¤éÆâÉô¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥µ¡¼¥Ð¡¼¤Þ¤Ç¡¢¤É¤Î¤è¤¦¤Ê¸¡ºº¤ò¹Ô¤¨¤Ð¡¢ÀȼåÀ¿ÇÃǤȤ·¤ÆÍ¸ú¤«¤Ä¸ÜµÒ¤Î¿®Íê¤òÆÀ¤é¤ì¤ë¤«¡£µÒ´ÑÀ¤Î¤¢¤ëÁªÄêÊýË¡¤È¤·¤Æ¡¢PCIDSS¤Ë´ð¤Å¤¤¤¿5¤Ä¤Î¥Æ¥¹¥È¤ò¤´¾Ò²ð¤·¤Þ¤¹¡£¥¯¥ì¥¸¥Ã¥È¥«¡¼¥É¾ðÊó¤È´Ø·¸¤Î¤Ê¤¤´ë¶È¤Ë¤È¤Ã¤Æ¤â¡¢¸ÜµÒ¤ÎǼÆÀÀ¤ò¹â¤¯ÆÀ¤é¤ì¤ë¸¡ººÊýË¡¤Ç¤¹¡£
¹ñ²ÈŪ¤Êµ¡Ì©¾ðÊ󤬥µ¥¤¥Ð¡¼¹¶·â¤Çϳ¤¨¤¤
½°µÄ±¡¤Î¥µ¡¼¥Ð¡¼¤¬¥¦¥£¥ë¥¹¤Ë´¶À÷¤·¡¢ÅÐÏ¿¤·¤Æ¤¤¤ëµÄ°÷Á´°÷¤ÎID¡¦¥Ñ¥¹¥ï¡¼¥É¤¬¡¢Ãæ¹ñ¹ñÆâ¤Ê¤É¤Î¥µ¡¼¥Ð¡¼¤ØÁ÷¿®¤µ¤ì¤Æ¤¤¤¿¤³¤È¤¬È½ÌÀ¤·¤Þ¤·¤¿¡£¤Þ¤¿¤½¤ÎÁ°¤Ë¤Ï¡¢ÆüËܤòÂåɽ¤¹¤ëËɱҴØÏ¢´ë¶È¤Ç¤¢¤ë¡¢M½Å¹©¼ÒÆâ¤Î¿¤¯¤ÎPC¤âƱÍͤΥµ¥¤¥Ð¡¼¹¶·â¤ò¼õ¤±¡¢ËɱҾʤ¬»ÈÍѤ·¤Æ¤¤¤ëÀï¼Ö¤Ê¤É¤Îʼ´ï¾ðÊ󤬡¢³°Éô¤«¤é¤Î±ó³ÖÁàºî¤Ë¤è¤Ã¤ÆÏ³¤¨¤¤¤µ¤ì¤Æ¤¤¤Þ¤·¤¿¡£
½°µÄ±¡¤Ø¤Î¥µ¥¤¥Ð¡¼¹¶·â¤Ï¡¢7·î²¼½Ü¤Ë1¿Í¤ÎµÄ°÷¤¬¡¢¥á¡¼¥ë¤ÇÁ÷¤ê¤Ä¤±¤é¤ì¤¿¡¢¥¦¥£¥ë¥¹Æþ¤ê¤ÎźÉÕ¥Õ¥¡¥¤¥ë¤ò³«Éõ¤·¤Æ¡¢¿¯Æþ¤µ¤ì¤¿¤³¤È¤¬È¯Ã¼¤Ç¤·¤¿¡£¤½¤ÎPC¤«¤é¡¢Â¾¤ÎµÄ°÷¤ÎPC¤Ø¤â¼¡¡¹¤È¥¦¥£¥ë¥¹¤¬ÅÁÀ÷¤·¤Æ¡¢½°±¡»ö̳¶É¤Î¥µ¡¼¥Ð¡¼¤Þ¤ÇÆþ¤ê¹þ¤ó¤Ç¤¤¤Ã¤¿¤È¤µ¤ì¤Æ¤¤¤Þ¤¹¡£
°Å¹æ²½¤µ¤ì¤¿¥¦¥£¥ë¥¹¤ÏÆþ¸ý¤ò¤¹¤êÈ´¤±¤ë
¹ñ²ñµÄ°÷¤¿¤Á¤¬¡¢³Æ¼«¤ÎPC¤Î¥¦¥£¥ë¥¹¥¹¥¥ã¥ó¤òÄê´ü¼Â»Ü¤·¤Æ¤¤¤¿¤«¤É¤¦¤«¤Ë´Ø¤ï¤é¤º¡¢¤³¤Î¡È¥È¥í¥¤¤ÎÌÚÇÏ·¿¡É¥¦¥£¥ë¥¹¤Ï¡¢Âкö¥½¥Õ¥È¤Ç¸¡ÃΤµ¤ì¤Ê¤¤¤è¤¦¤Ë¡¢°Å¹æ²½¤µ¤ì¤ÆÆþ¤ê¹þ¤ó¤À¤¦¤¨¡¢¤½¤Î¸å¤â¸¡ÃΤµ¤ì¤Ë¤¯¤¤¤è¤¦¤Ë¡¢Ê¸½ñ¥Õ¥¡¥¤¥ë¤ÎÃæ¤Ëʶ¤ì¹þ¤à¤È¤¤¤¦¡¢¹âÅ٤ʥ¦¥£¥ë¥¹À½Â¤¡¦±¿Íѵ»½Ñ¤¬»Ü¤µ¤ì¤Æ¤¤¤Þ¤·¤¿¡£
¥¦¥£¥ë¥¹¥×¥í¥°¥é¥à¤¬°Å¹æ²½¤µ¤ì¤Æ¤¤¤ì¤Ð¡¢¥¦¥£¥ë¥¹Âкö¥½¥Õ¥È¤òƳÆþ¤·¤Æ¡¢¤Ò¤ó¤Ñ¤ó¤Ë¥¹¥¥ã¥ó¤ò¤«¤±¤Æ¤¤¤Æ¤â¡¢È¯¸«¤Ç¤¤Þ¤»¤ó¡£°Å¹æ²½¤È¤¤¤¦µ»½Ñ¤Ï¡¢¤â¤È¤â¤ÈËÜÍè¤Î¥Ç¡¼¥¿¤¬ÆÉ¤Þ¤ì¤Ê¤¤¤è¤¦¤Ë¤¹¤ëµ»½Ñ¤È¤·¤Æ¡¢³«È¯¤µ¤ì¿Ê²½¤·¤Æ¤¤Æ¤¤¤Þ¤¹¤«¤é¡¢¥¦¥£¥ë¥¹¸¡ÃÎ¥½¥Õ¥È¤Ç¤Ï¿¯Æþ¤ò¸«Çˤ뤳¤È¤¬¤Ç¤¤Ê¤¤¤Î¤Ç¤¹¡£
¤³¤ì¤«¤é¤Î¥¦¥£¥ë¥¹¤Ï¡¢¤³¤¦¤·¤¿°Å¹æ²½¤ò»Ü¤µ¤ì¤¿¤â¤Î¤¬¡¢¼çή¤Ë¤Ê¤Ã¤Æ¤¯¤ë¤Î¤«¤âÃΤì¤Þ¤»¤ó¡£¤·¤¿¤¬¤Ã¤Æ¡¢¥¦¥£¥ë¥¹¤Ë´¶À÷¤·¤Æ¤¤¤ë¤³¤È¤òÄ´¤Ù¤ë¤Ë¤Ï¡¢Ëɸ椹¤ë¦¤Ï¥¦¥£¥ë¥¹Âкö¥½¥Õ¥È¤À¤±¤Ç¤Ê¤¯¡¢¥Õ¥¡¥¤¥ëÀ°¹çÀ¤äÁàºî¥í¥°¤Î´Æ»ë¤Ê¤É¡¢Ê̤ε»½Ñ¤òÊ»ÍѤ·¤Æ¤¤¤¯É¬Íפ¬¤¢¤ê¤Þ¤¹¡£
α¼éÃæ¤Îư¤¤ò´Æ»ë¤·µÏ¿¤¹¤ë

¤¿¤È¤¨¤Ð½»Âð¤ÎËÉÈȤˤ¿¤È¤¨¤Æ¤ß¤Þ¤·¤ç¤¦¡£¶õ¤ÁãÅ¥ËÀ¤ËÆþ¤é¤ì¤Ê¤¤¤è¤¦¤Ë¡¢¸ÍÄù¤ê¤ò¶¯²½¤¹¤ë¤À¤±¤Ç¤Ï¡¢¥É¥¢¤Î¥«¥®¤ò¤¢¤±¤ë¥Æ¥¯¥Ë¥Ã¥¯¤ò»ý¤Ã¤¿Å¥ËÀ¤Ë¤Ï¡¢¿¯Æþ¤µ¤ì¤Æ¤·¤Þ¤¤¤Þ¤¹¡£¤½¤·¤Æ¤½¤ÎÅ¥ËÀ¤Ï¡¢²È¿Í¤¬¤¤¤ë´Ö¤ÏÅ·°æ¥¦¥é¤Ê¤É¤Ë¤¸¤Ã¤ÈÀø¤ó¤Ç¡¢Î±¼é¤Ë¤Ê¤Ã¤¿¤éÉô²°¤Ë¹ß¤ê¤Æ¶ä¹ÔÄÌÄ¢¤Ê¤É¤òõ¤·²ó¤ë¡¢¤È¤¤¤Ã¤¿¤è¤¦¤Ê¤â¤Î¤Ç¤¹¡£
¤½¤³¤Ç¡¢¤³¤¦¤·¤¿¡È½»¤ß¹þ¤ßÅ¥ËÀ¡É¤¬Æþ¤ê¹þ¤ó¤Ç¤¤¤ë¤Î¤ò¸«¤Ä¤±¤ë¤Ë¤Ï¡¢¼«Ê¬¤¬Î±¼é¤Î´Ö¤Ë¤â¡¢¼¼Æâ¤ÎÍͻҤòÏ¿²è¤·Â³¤±¤Æ¤¤¤ë´Æ»ë¥«¥á¥é¤¬¤¢¤ë¤È¤«¡¢¥¿¥ó¥¹¤Î°ú¤½Ð¤·¤Î³«¤±ÊĤ᤬µÏ¿¤µ¤ì¤ë»ÅÁȤߤʤɤ¬¤¢¤ì¤Ð¡¢¿¯Æþ¤µ¤ì¤Æ¤¤¤ë¤³¤È¤ò¤â¤Ã¤È¹â¤¤³ÎΨ¤ÇÃΤ뤳¤È¤¬¤Ç¤¤Þ¤¹¡£
¤½¤¦¤·¤¿¥»¥¥å¥ê¥Æ¥£Âкö¤¬¡¢¥Õ¥¡¥¤¥ëÀ°¹çÀ¤ä¥í¥°´Æ»ë¤Î¥·¥¹¥Æ¥à¤Ç¤¹¡£¤½¤ì¤é¤òÊ»ÍѤ¹¤ë¤³¤È¤Ç¡¢¤³¤¦¤·¤¿°Û¾ï¤ò¸«¤Ä¤±¤ë¤³¤È¤¬¤Ç¤¤Þ¤¹¡£¸Ä¿Í¤¬PC¤ËƳÆþ¤¹¤ë¤³¤È¤Ï¾¯¤Ê¤¤¤Ç¤¹¤¬¡¢´ë¶È¤Î¾ðÊó¤ò´ÉÍý¤¹¤ë¥µ¡¼¥Ð¡¼¤Ê¤É¤Î½ÅÍפʥ·¥¹¥Æ¥à¤Ë¤Ï¡¢¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¤ä¥¦¥£¥ë¥¹¸¡ÃÎ¥½¥Õ¥È¤À¤±¤Ç¤Ê¤¯¡¢¤³¤ì¤é¤ÎÊ£¹çŪ¤ÊÂкö¤ò¹Ö¤¸¤Æ¤ª¤«¤Ê¤¤¤È¡¢¾ðÊóϳ¤¨¤¤¤òËɤ°¤Î¤ÏÆñ¤·¤¤¤È¤¤¤¨¤ë¤Ç¤·¤ç¤¦¡£
¥µ¥¤¥È¤ÎÀȼåÀ¤ò¿³ÑŪ¤Ë¸¡ºº¤¹¤ë
¤³¤Î¤è¤¦¤Ë¡¢´ë¶È¥·¥¹¥Æ¥à¤Ø¿¯Æþ¤¹¤ë°¼Á¤Ê»ö·ï¤¬Áý²Ã¤·¤Æ¤¤¤ë¤³¤È¤Ç¡¢¤Û¤È¤ó¤É¤Î´ë¶È¤¬³«Àߤ·¤Æ¤¤¤ëWeb¥µ¥¤¥È¤¬¡¢¥µ¥¤¥Ð¡¼¹¶·â¤Ë¤É¤³¤Þ¤ÇÂй³¤Ç¤¤Æ¤¤¤ë¤«¡¢Â¿³ÑŪ¤Ê¿ÇÃǤòµá¤á¤ëÌä¹ç¤»¤â¿¤¯¤Ê¤Ã¤Æ¤¤Æ¤¤¤Þ¤¹¡£ ¤Ç¤Ï¡¢¤É¤Î¤è¤¦¤Ê¥Æ¥¹¥È¤ò¡¢¤É¤³¤Þ¤Ç¹Ô¤¨¤Ð¥µ¥¤¥È¤Î°ÂÁ´À¤ò³Îǧ¤Ç¤¤ë¤Ç¤·¤ç¤¦¤«¡£Í¸ú¤Ê´ð½à¤Î¤Ò¤È¤Ä¤¬¡¢PCIDSS¡ÊPayment Card Industry Data Security Standard¡Ë¤Ç¤¹¡£PCIDSS¤Ï¡¢VISA¤äMasterCard¡¢JCB¤Ê¤É¥¯¥ì¥¸¥Ã¥È¥«¡¼¥É¤ÎÂç¼ê¥Ö¥é¥ó¥É¤¬¶¦Æ±¤ÇÄê¤á¤¿¡¢¥¯¥ì¥¸¥Ã¥È¥«¡¼¥É¾ðÊ󥻥¥å¥ê¥Æ¥£¤Ë´Ø¤¹¤ë¹ñºÝ´ð½à¤Ç¤¹¡£Web¥µ¥¤¥È¤ä¤½¤Î±ü¤Ë¤¢¤ë¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥µ¡¼¥Ð¡¼¤Ø¤ÎÉÔÀµ¥¢¥¯¥»¥¹Âкö¤È¤·¤Æ¡¢»ö¶È¼Ô¤¬¼Â»Ü¤¹¤Ù¤³Æ¼ï¤Î¸¡ºº¤Ë¤Ä¤¤¤Æ¡¢¶ñÂÎŪ¤ËÄê¤á¤Æ¤¤¤Þ¤¹¡£¤·¤¿¤¬¤Ã¤Æ¡¢¥¯¥ì¥¸¥Ã¥È¥«¡¼¥É¾ðÊó¤Ë¸Â¤é¤º¡¢½ÅÍ×¾ðÊó¤òÊÝͤ¹¤ë¤¹¤Ù¤Æ¤Î´ë¶È¤Ë¤È¤Ã¤Æ¡¢Â礤¤Ë»²¹Í¤Ë¤Ê¤ë¥»¥¥å¥ê¥Æ¥£´ð½à¤È¤¤¤¨¤ë¤Ç¤·¤ç¤¦¡£
PCIDSS¤¬Í׵᤹¤ë5¤Ä¡Ê3¥¿¥¤¥×+³°Éô¤ÈÆâÉô¡Ë¤Î¥Æ¥¹¥È
PCIDSS¤Ç¤Ï¡¢¥Í¥Ã¥È¥ï¡¼¥¯¤äWeb ¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÂФ·¤Æ¡¢¼¡¤Î¥Æ¥¹¥È¤òÄê´üŪ¤Ë¹Ô¤Ã¤Æ¡¢Àȼå¡Ê¤¼¤¤¤¸¤ã¤¯¡ËÅ٤ι⤤¤ÈȽÄꤵ¤ì¤¿Éôʬ¤Ë¤Ä¤¤¤Æ¡¢²þÁ±¤ò»Ü¤¹¤³¤È¤òÍ׵ᤷ¤Æ¤¤¤Þ¤¹¡£
[µ] <<¥Í¥Ã¥È¥ï¡¼¥¯ÀȼåÀ¥¹¥¥ã¥ó¡ÄÍ×µá»ö¹à11.2>>
ÆâÉô¤ª¤è¤Ó³°Éô¥Í¥Ã¥È¥ï¡¼¥¯¤ÎÀȼåÀ¥¹¥¥ã¥ó¤ò¡¢¾¯¤Ê¤¯¤È¤â»ÍȾ´ü¤Ë°ìÅÙ¡¢¤ª¤è¤Ó¥Í¥Ã¥È¥ï¡¼¥¯¤Ç¤ÎÂçÉý¤ÊÊѹ¹¸å¤Ë¼Â¹Ô¤¹¤ë¡£ ¤³¤Î2¤Ä¤Î¤¦¤Á¡¢³°Éô¥Í¥Ã¥È¥ï¡¼¥¯¤Î¥¹¥¥ã¥ó¥Æ¥¹¥È¤Ï¡¢PCI¹ñºÝ¶¨µÄ²ñ¡ÊPCI SSC¡Ë¤¬Ç§Äꤷ¤¿¡¢Approved Scanning Vendor(ASV)¤Ë¤è¤Ã¤Æ¼Â¹Ô¤µ¤ì¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£ASV¤Î°ìÍ÷¤Ï¡¢PCISSC¤Î¥µ¥¤¥È¤Ë¸øÉ½¤µ¤ì¤Æ¤¤¤Þ¤¹¡£
https://www.pcisecuritystandards.org/approved_companies_providers/approved_scanning_vendors.php
[¶] <<¥Ú¥Í¥È¥ì¡¼¥·¥ç¥ó(¿¯Æþ)¥Æ¥¹¥È¡ÄÍ×µá»ö¹à11.3>>
³°Éô¤ª¤è¤ÓÆâÉô¤Î¥Ú¥Í¥È¥ì¡¼¥·¥ç¥ó¥Æ¥¹¥È¤ò¾¯¤Ê¤¯¤È¤âǯ¤Ë°ìÅÙ¡¢¤ª¤è¤ÓÂçÉý¤Ê¥¤¥ó¥Õ¥é¥¹¥È¥é¥¯¥Á¥ã¤Þ¤¿¤Ï¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¥¢¥Ã¥×¥°¥ì¡¼¥É¤äÊѹ¹¸å¤Ë¼Â¹Ô¤¹¤ë¡£
¤µ¤é¤Ë¡Ö¤³¤ì¤é¤Î¥Ú¥Í¥È¥ì¡¼¥·¥ç¥ó¥Æ¥¹¥È¤Ë¤Ï°Ê²¼¤ò´Þ¤á¤ëɬÍפ¬¤¢¤ë¡×¤È¤·¤Æ¡¢
11.3.1¡Ö¥Í¥Ã¥È¥ï¡¼¥¯ÁؤΥڥͥȥ졼¥·¥ç¥ó¥Æ¥¹¥È¡×
11.3.2¡Ö¥¢¥×¥ê¥±¡¼¥·¥ç¥óÁؤΥڥͥȥ졼¥·¥ç¥ó¥Æ¥¹¥È¡×¤Î2¤Ä¤ò´Þ¤á¤ë¤³¤È¤¬Í׵ᤵ¤ì¤Æ¤¤¤Þ¤¹¡£
¥¢¥×¥ê¥±¡¼¥·¥ç¥óÁؤؤΥڥͥȥ졼¥·¥ç¥ó¡Ê¿¯Æþ¡Ë¥Æ¥¹¥È¤Ç¤Ï¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎÀȼåÀ¤ò¥Á¥§¥Ã¥¯¤¹¤ë¤¿¤á¤Ë¡¢°Ê²¼¤Îɾ²Á¥Æ¥¹¥È¤ò¹Ô¤¤¤Þ¤¹¡£
| 1 | Parameter Tampering¡¡ÉÔÀµÁàºî¤·¤Æ¤¤¤ë¥Ñ¥é¥á¡¼¥¿ ¥Ç¡¼¥¿¤äµ¡Ç½¤Ê¤É¤Ø¤ÎÉÔÀµ¤Ê¥¢¥¯¥»¥¹¤ò¥Á¥§¥Ã¥¯¤¹¤ë¤¿¤á¤Ë¡¢Query String¡¤POSY¡¡parameter¡¢hidden-field¤Ê¤É¤òÊѹ¹¤·¤Þ¤¹¡£ |
| 2 | Cookie Poisoning¡¡¥¯¥Ã¥¡¼Poisoning ÁÛÄê³°¤Î¥¯¥Ã¥¡¼¤ÎÃͤò¼õ¤±¼è¤Ã¤¿¤È¤¤Î¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¦¤ÎÂбþ¤ò¸«¤ë¤¿¤á¤Ë¡¢¥¯¥Ã¥¡¼¤ÎÃͤòÊѤ¨¤Þ¤¹¡£ |
| 3 | Session hijacking¡¡¥»¥Ã¥·¥ç¥ó¥Ï¥¤¥¸¥ã¥Ã¥¯ Ê̤Υ桼¥¶¡¼¤Ë¤Ê¤ê¤¹¤Þ¤·¤Æ¡¢¤½¤Î¥æ¡¼¥¶¡¼¤Î¥»¥Ã¥·¥ç¥ó¤ò²£¼è¤ê¤·¤Æ¤ß¤Þ¤¹¡£ |
| 4 | User privilege escalation¡¡¥æ¡¼¥¶¡¼ÆÃ¸¢¥¨¥¹¥«¥ì¡¼¥·¥ç¥ó ´ÉÍý¼Ô¤¢¤ë¤¤¤Ï¾¤Î¥æ¡¼¥¶¡¼¤ÎÆÃ¸¢¤ËÉÔÀµ¤Ê¥¢¥¯¥»¥¹¤ò»î¤ß¤Þ¤¹¡£ |
| 5 | Credential manipulation¡¡Ç§¾Ú¤Î¤´¤Þ¤«¤· ¾¤Î¥æ¡¼¥¶¡¼¤ÎÆÃ¸¢¤ØÉÔÀµ¤Ë¥¢¥¯¥»¥¹¤·¤Æ¤ß¤ë¤¿¤á¤Ë¼±Ê̤侵ǧ¤Îǧ¾Ú¥³¡¼¥É¤òÊѹ¹¤·¤Æ¤ß¤Þ¤¹¡£ |
| 6 | Forceful Browsing ÀßÄê¥ß¥¹¤Î¤¢¤ëWeb¥µ¡¼¥Ð¡¼¤Ï¡¢¥æ¡¼¥¶¡¼¤¬¥Õ¥¡¥¤¥ë̾¤µ¤¨ÃΤäƤ¤¤ì¤Ð¡¢¤É¤ó¤Ê¥Õ¥¡¥¤¥ë¤Ç¤â¥¢¥¯¥»¥¹¤Ç¤¤Æ¤·¤Þ¤¤¤Þ¤¹¡£½¾¤Ã¤Æ¡¢¥Ï¥Ã¥«¡¼¤Ï¤³¤Î¥»¥¥å¥ê¥Æ¥£¤Î·ç´Ù¤ò¹¶·â¤·¤Æ¡¢Ä¾ÀܤËɬÍפʥڡ¼¥¸¤Ø¥¸¥ã¥ó¥×¤·¤Æ¤¿¤É¤êÃ夤¤Æ¤·¤Þ¤¤¤Þ¤¹¡£ |
| 7 | Backdoors and Debug Options¡¡¥Ð¥Ã¥¯¥É¥¢¤È¥Ç¥Ð¥Ã¥°¥ª¥×¥·¥ç¥ó ¿¤¯¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ï¡¢³«È¯¼Ô¤Î¥Ç¥Ð¥Ã¥°¤Î¤¿¤á¤Î¥³¡¼¥É¡Ê¥Ð¥Ã¥¯¥É¥¢¡Ë¤ò»Ä¤·¤Æ¤¤¤Þ¤¹¤¬¡¢Ä̾ï¹â¤¤¥ì¥Ù¥ë¤Î¥¢¥¯¥»¥¹¤ÇÁö¤ë¤¿¤á¡¢¹¶·â¤ÎÌÜɸ¤Ë¤µ¤ì¤Æ¤·¤Þ¤¤¤Þ¤¹¡£¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î³«È¯¼Ô¤Ï¡¢¤³¤Î¤è¤¦¤Ê¥Ð¥Ã¥¯¥É¥¢¤ò»Ä¤·¤Æ¤âÎɤ¤¤Ç¤¹¤¬¡¢¤â¤·È¯¸«¤µ¤ì¤ë¤È¹¹¤Ê¤ë¥ì¥Ù¥ë¤Ø¤Î¥¢¥¯¥»¥¹¤ò¿¯Æþ¼Ô¤Ëµö¤·¤Æ¤·¤Þ¤¦¤³¤È¤Ë¤Ê¤ê¤Þ¤¹¡£ |
| 8 | Configuration Subversion Web¥µ¡¼¥Ð¡¼¤ä¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥µ¡¼¥Ð¡¼¤ÎÀßÄê¥ß¥¹¤Ï¡¢¤è¤¯¤¢¤ë¸í¤ê¤Ç¤¹¡£¡¡¤â¤Ã¤È¤âµ¯¤³¤·¤ä¤¹¤¤ÀßÄê¥ß¥¹¤Ï¡¢¥Ç¥£¥ì¥¯¥È¥ê¡¼¥Ö¥é¥¦¥¸¥ó¥°¤òµö¤·¤Æ¤·¤Þ¤¦¤³¤È¤Ç¤¹¡£¥Ï¥Ã¥«¡¼¤Ï¤³¤ì¤òÍøÍѤ·¤Æ¡¢¥Ç¥£¥ì¥¯¥È¥ê¡¼¤Î̾Á°¤òÆþÎϤ¹¤ë¤À¤±¤Ç¡¢´Êñ¤Ë¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥Ç¥£¥ì¥¯¥È¥ê¡¼¡Êcgi-bin¤Ê¤É¡Ë¤ò¥Ö¥é¥¦¥º¤Ç¤¤Æ¤·¤Þ¤¤¤Þ¤¹¡£ |
| 9 | Input validation bypass ¥¯¥é¥¤¥¢¥ó¥È¦¤Î¸¡¾Ú¥ë¡¼¥Á¥ó¤ä¡¢ÈϰϥÁ¥§¥Ã¥¯¤Ê¤É¤ò¤Ï¤º¤·¤Æ¤ß¤Æ¡¢¥µ¡¼¥Ð¡¼Â¦¤ÎÀ©¸æ¤¬Àµ¾ï¤Ëµ¡Ç½¤·¤Æ¤¤¤ë¤«¤É¤¦¤«¤ò¥Á¥§¥Ã¥¯¤·¤Þ¤¹¡£ |
| 10 | SQL injection¡¡SQL ¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó ¹ªÌ¯¤Ëºî¤Ã¤¿SQL¥³¥Þ¥ó¥É¤òÆþÎÏ¥Õ¥£¡¼¥ë¥É¤ËÆþ¤ì¤Æ¤ß¤Æ¡¢ÆþÎÏ¥¿¥¤¥×¤Î¥³¥ó¥È¥í¡¼¥ë¤¬¤¦¤Þ¤¯Æ¯¤¤¤Æ¤¤¤ë¤«¤ò¥Á¥§¥Ã¥¯¤·¤Þ¤¹¡£ |
| 11 | Cross-site scripting¡¡¥¯¥í¥¹¥µ¥¤¥È¡¦¥¹¥¯¥ê¥×¥Æ¥£¥ó¥° ¥æ¡¼¥¶¡¼¤ÎWeb¥Ö¥é¥¦¥¶¤ËÉÔÀµ¤Ê¥³¡¼¥É¤ò¼Â¹Ô¤µ¤»¤ë¤è¤¦¤Ë¡¢¥¢¥¯¥Æ¥£¥Ö¤ÊÆâÍÆ¤¬¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ËÁ÷¤é¤ì¤Þ¤¹¡£¤³¤Î¥Æ¥¹¥È¤Ï¡¢¥æ¡¼¥¶¡¼¤ÎÆþÎϥǡ¼¥¿¥¿¥¤¥×¤Î¸¡¾Ú¤¬¤Ç¤¤Æ¤¤¤ë¤³¤È¤ò¥Æ¥¹¥È¤¹¤ë¤â¤Î¤Ç¤¹¡£ |
¡Î·¡Ï<<OWASP¥Æ¥¹¥È¡ÄÍ×µá»ö¹à6.5>>
¤¹¤Ù¤Æ¤Î Web ¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¡ÊÆâÉô¡¢³°Éô¡¢¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Ø¤Î Web ´ÉÍý¥¢¥¯¥»¥¹¡Ë¤ò¡¢¡ÖOpen Web Application Security Project Guide¡× ¤Ê¤É¤Î°ÂÁ´¤Ê¥³¡¼¥Ç¥£¥ó¥°¥¬¥¤¥É¥é¥¤¥ó¤Ë´ð¤Å¤¤¤Æ³«È¯¤¹¤ë¡£
OWASP¡Ê¥ª¥ï¥¹¥×¡Ë¤È¸Æ¤Ð¤ì¤ë¡¢¤³¤Î¥¬¥¤¥É¥é¥¤¥ó¤Ï¡¢À¤³¦Ãæ¤Î¥Ü¥é¥ó¥Æ¥£¥¢¤Ë¤è¤ë¥×¥í¥¸¥§¥¯¥È¤Ë¤è¤Ã¤Æºî¤é¤ì¡¢¥ª¡¼¥×¥ó¥½¡¼¥¹¤Ë¤è¤ë¥Ä¡¼¥ë¤ÎÀ½ºî¡¦²þÁ±¤Ê¤É¤ò´Þ¤á¤Æ¡¢Ãμ±¤Î¶¦Í¤¬¹Ô¤ï¤ì¤Æ¤¤¤Þ¤¹¡£
6.5.2 ¥Ð¥Ã¥Õ¥¡¥ª¡¼¥Ð¡¼¥Õ¥í¡¼
6.5.3¡¡°ÂÁ´¤Ç¤Ê¤¤°Å¹æ²½Êݸ
6.5.4¡¡°ÂÁ´¤Ç¤Ê¤¤ÄÌ¿®
6.5.5¡¡ÉÔŬÀڤʥ¨¥é¡¼½èÍý
6.5.6¡¡ÀȼåÀÆÃÄê¥×¥í¥»¥¹¡ÊPCIDSSÍÑ·ï6.2¡Ë¤ÇÆÃÄꤵ¤ì¤¿¡¢¤¹¤Ù¤Æ¤Î¥Ï¥¤¥ì¥Ù¥ëÀȼåÀ
6.5.7¡¡¥¯¥í¥¹¥µ¥¤¥È¡¦¥¹¥¯¥ê¥×¥Æ¥£¥ó¥°¡ÊXSS¡Ë
6.5.8¡¡ÉÔŬÀڤʥ¢¥¯¥»¥¹À©¸æ¡Ê°ÂÁ´¤Ç¤Ê¤¤¥ª¥Ö¥¸¥§¥¯¥È¤ÎľÀÜ»²¾È¡¢URL¥¢¥¯¥»¥¹À©¸Â¤Î¼ºÇÔ¡¢¥Ç¥£¥ì¥¯¥È¥ê¥È¥é¥Ð¡¼¥µ¥ë¤Ê¤É¡Ë
6.5.9¡¡¥¯¥í¥¹¥µ¥¤¥È¡¦¥ê¥¯¥¨¥¹¥È¥Õ¥©¡¼¥¸¥§¥ê¡ÊCSRF¡Ë
¢¨6.5.7¡Á6.5.9¤Ï¡¢Web¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤È¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¥¤¥ó¥¿¡¼¥Õ¥§¥¤¥¹¡ÊÆâÉô¡¦³°Éô¤òÌä¤ï¤º¡Ë¤ËŬÍѤ·¤Þ¤¹¡£
³°Éô¥Í¥Ã¥È¥ï¡¼¥¯¤«¤é±ü¤Î¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Þ¤Ç¸¡ºº
¤³¤Î¤è¤¦¤ËPCIDSS¤Ç¤Ï¡¢¤Þ¤º¥Í¥Ã¥È¥ï¡¼¥¯¤ËÀȼåÀ¤¬¤Ê¤¤¤«¤ò¥Á¥§¥Ã¥¯¤¹¤ë¡¢¥µ¥¤¥È¥¹¥¥ã¥ó¤òÆâÉô¡¦³°Éô¤È¤â¤ËÍ׵ᤷ¤Æ¤¤¤Þ¤¹¡£¼¡¤Ë¡¢³°²ó¤ê¤Î¥¹¥¥ã¥ó¤À¤±¤Ç¤Ïʬ¤«¤é¤Ê¤¤¡¢¥Õ¥¡¥¤¥¢¥¦¥©¡¼¥ë¤ÎÃæ¤Þ¤ÇÆþ¤Ã¤ÆÀȼåÀ¤ò¸¡ºº¤¹¤ë¤è¤¦¡¢ÆâÉô¡¦³°Éô¤Î¥Ú¥Í¥È¥ì¡¼¥·¥ç¥ó¡Ê¿¯Æþ¡Ë¥Æ¥¹¥È¤òÍ׵ᤷ¤Æ¤¤¤Þ¤¹¡£¶áǯ¥Ï¥Ã¥¥ó¥°»öÎ㤬¿¤¯¤Ê¤Ã¤Æ¤¤¤ë¡¢SQL¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó¹¶·â¤ËÂФ·¤Æ¤Ï¡¢¥µ¥¤¥È¥¹¥¥ã¥ó¤Ç¤Ï¸¡ÃΤ¬Æñ¤·¤¤¤«¤é¤Ç¤¹¡£¤³¤ì¤ÇWeb¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎÀȼåÀ¤ä¡¢SQL¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó¹¶·â¤ò¤¹¤Ç¤Ë¼õ¤±¤Æ¤¤¤Ê¤¤¤«¡¢¤È¤¤¤Ã¤¿ÅÀ¤â´Þ¤á¤Æ¸¡ºº¤Ç¤¤Þ¤¹¡£
¤µ¤é¤Ë¡Î· OWASP¥Æ¥¹¥È¡Ï¤Ï¡¢Web¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎÀȼåÀ¤ò¸·¤·¤¯¸¡ºº¤¹¤ëÊýË¡¤Ç¡¢OWASP¡ÊOpen Web Application Security Project¡ËTop-10¤Ë´ð¤Å¤¤¤¿¸¡ºº¤Ç¤¹¡£
¸ÜµÒ¤«¤é¿®Íê¤òÆÀ¤ë¤¿¤á¤ËPCI´ð½à¤Î΢¤Å¤±¤¬Í¸ú
´ë¶È¤Ë¤È¤Ã¤Æ¥»¥¥å¥ê¥Æ¥£¿ÇÃǤΥá¥ê¥Ã¥È¤Ï¡¢¼«¼Ò¤ÎÊÝͤ¹¤ë½ÅÍ×¾ðÊ󤬰ÂÁ´¤Ë¼é¤ë¤³¤È¤¬¤Ç¤¤Æ¤¤¤ë¤«¤ò³Îǧ¤¹¤ë¤À¤±¤Ç¤Ï¤¢¤ê¤Þ¤»¤ó¡£Â¿¤¯¤Î¸ÜµÒ¤ËÂФ·¤Æ¡¢¼«¼Ò¤Î¥»¥¥å¥ê¥Æ¥£¤ò¿®Íꤷ¤Æ¤â¤é¤¦¤¿¤á¤Ë¡¢Â¿³ÑŪ¤Ê¸¡ºº¤ò¼Â»Ü¤·¤Æ¤¤¤ë¼ÂÀÓ¤ò¼¨¤¹¤³¤È¤¬¤Ç¤¤Þ¤¹¡£
°ÂÁ´À¤Î¿ÇÃǸ¡ºº¤ò¤·¤Æ¤¤¤ë¤È¤¤¤Ã¤Æ¤â¡¢¤É¤¦¤¤¤¦¥¬¥¤¥É¥é¥¤¥ó¤Ë´ð¤Å¤¤¤Æ¡¢¤É¤ì¤À¤±¤Î¸¡ºº¤ò¹Ô¤Ã¤¿¤Î¤«¤òÌÀ³Î¤Ë¤Ç¤¤Ê¤¤¤È¡¢¤»¤Ã¤«¤¯¸¡ºº¥³¥¹¥È¤ò¤«¤±¤Æ¤â¡¢¿®ÍÑÌ̤ǤÎÉ԰¤¬»Ä¤ê¤Þ¤¹¡£
¤½¤Î¤¿¤á¤Ë¡¢¡Ö¥¯¥ì¥¸¥Ã¥È¥«¡¼¥É¾ðÊóÊݸî¤Ë´Ø¤¹¤ë¹ñºÝ´ð½à¤Ç¤¢¤ë¡¢PCIDSS¤¬Í׵ᤷ¤Æ¤¤¤ë³Æ¼ï¤ÎÀȼåÀ¸¡ºº¤ò¼Â»Ü¤·¤Æ¡¢°ÂÁ´¤ò³Îǧ¤·¤Æ¤¤¤Þ¤¹¡×¤È¸À¤¨¤ëµÒ´ÑÀ¤Î¤¢¤ëÊýºö¤Ï¡¢¸ÜµÒ¤ËÂФ·¤ÆÀâÆÀÎϤ¬¤¢¤ë¤Ç¤·¤ç¤¦¡£
¸¡ºº¶È¼Ô¤ò¤É¤¦ÁªÄꤹ¤ë¤«
¤·¤«¤·¡¢¤Þ¤ÀÌäÂê¤â¤¢¤ê¤Þ¤¹¡£Á°½Ò¤Î¤è¤¦¤Ë¡¢¤³¤ì¤é¤Î5¤Ä¤Î¿ÇÃǥƥ¹¥È¤Î¤¦¤Á¡¢³°Éô¥Í¥Ã¥È¥ï¡¼¥¯¤Î¥¹¥¥ã¥ó¥Æ¥¹¥È¤À¤±¤Ï¡¢PCISSC¤¬Ç§²Ä¤·¤¿ASV¤È¤¤¤¦¿ÇÃǶȼԤǤ¢¤ë¤³¤È¤¬¾ò·ï¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¤¬¡¢¤¢¤È¤Î4¤Ä¤Î¿ÇÃǥƥ¹¥È¼Â»Ü¶È¼Ô¤Ï¡¢Ç§²ÄÀ©¤Ç¤Ï¤¢¤ê¤Þ¤»¤ó¡£
¿Í´Ö¤Î·ò¹¯¿ÇÃǤʤ顢¤É¤³¤Îɱ¡¤Ç¤â°å»ÕÌȵö¤¬¤Ê¤±¤ì¤Ð¼Â»Ü¤Ç¤¤Ê¤¤¤³¤È¤Ë¤Ê¤Ã¤Æ¤¤¤Þ¤¹¤«¤é¡¢°ì±þ¤½¤Î¥ì¥Ù¥ë¤ò¿®ÍѤ¹¤ë¤³¤È¤¬¤Ç¤¤Þ¤¹¡£¤·¤«¤·¥»¥¥å¥ê¥Æ¥£¿ÇÃǤξì¹ç¤Ï¡¢¸¡ºº²ñ¼Ò¤Î¼ÂÀÓ¤òÈæ³Ó¤·¤¿¤ê¡¢¤É¤Î¤è¤¦¤ÊÊýË¡¤Ç¸¡ºº¤ò¹Ô¤¦¤Î¤«¤Î¥á¥½¥Ã¥É¤òÈæ³Ó¤·¤¿¤ê¡¢¿ÇÃǶȼԤòÁªÄꤹ¤ë¦¤Ë¤â¥¹¥¥ë¤¬É¬Íפˤʤê¤Þ¤¹¡£Ã±¤Ë¸«ÀѤê³Û¤ÇÁªÂò¤¹¤ë¤ï¤±¤Ë¤â¤¤¤«¤Ê¤¤¤ï¤±¤Ç¤¹¡£
¿ÇÃÇ·ë²Ì¤Î¥µ¥ó¥×¥ë¤ò¸«¤Æ¡¢¤É¤³¤Þ¤ÇºÙ¤«¤¯¿¼¤¯Ê¬ÀϤ·¤Æ¤¤¤ë¤«¡¢¤Þ¤¿Ã±¤Ë·ë²Ì¥ì¥Ý¡¼¥È¤ÎÄó½Ð¤Ç½ª¤ï¤ë¤Î¤Ç¤Ê¤¯¡¢¼ÁÌä¤äÂкö¤Ë¤Ä¤¤¤Æ¤â¥¢¥É¥Ð¥¤¥¹¤ò¤·¤Æ¤â¤é¤¨¤ë¤«¡¢¤Ê¤É¤Î¥Ý¥¤¥ó¥È¤â´Þ¤á¤Æ¡¢ÁªÄꤷ¤Æ¤¤¤¯¤Î¤¬¤è¤¤¤Ç¤·¤ç¤¦¡£
NOS¤Ç¤Ï2007ǯ¤è¤ê¡¢PCIDSS¤ÎǧÄê´Æºº²ñ¼Ò¡ÊQSA¡Ë¤Ç¤¢¤ë¡¢ÊƹñControlCase¼Ò¤È¤ÎÄó·È¤Ë¤è¤ê¡¢PCIDSS¤¬Í׵᤹¤ë5¤Ä¤Î¸¡ºº¤òÄ󶡤·¤Æ¤ª¤ê¤Þ¤¹¡£
ÈñÍÑÌ̤Ǥâ¼ê·Ú¤Ë¼Â»Ü¤Ç¤¤ë¡¢³°Éô¥¹¥¥ã¥ó¥Æ¥¹¥È¡Ö¥Ð¥ë¥Í¥é¡¦¥¢¥»¥Ã¥µ¡¼¡×¤ò¤Ï¤¸¤á¡¢ºÇÀèü¤Î¥Ï¥Ã¥¥ó¥°¾ðÊó¤ò¤â¤È¤Ë¡¢Web¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤ÎÀȼåÀ¤ò¸¡ºº¤Ç¤¤ëOWASP¥Æ¥¹¥È¤Þ¤Ç¡¢¤ªµÒÍͤΥ·¥¹¥Æ¥à´Ä¶¤òƧ¤Þ¤¨¤¿¤ªÂǹ礻¤Î¤¦¤¨¡¢¸«ÀѤê¤òÄó½Ð¤µ¤»¤Æ¤¤¤¿¤À¤¤Þ¤¹¡£ ¤É¤¦¤¾¤´ÁêÃ̤¯¤À¤µ¤¤¡£
¡Ê²òÀâ¡§±Ä¶ÈÅý³ç ¥»¥¥å¥ê¥Æ¥£¡¦¥½¥ê¥å¡¼¥·¥ç¥óôÅö¡¦¿¹ Âç¸ã)