SQLã€ã³ãžã§ã¯ã·ã§ã³æ»æããããŒã¿ããŒã¹ãä¿è·ããæ¹æ³ãåŠã³ãŸãããããã®å æ¬çãªã¬ã€ãã¯ãã¢ããªã±ãŒã·ã§ã³ãä¿è·ããããã®å®çšçãªæé ãäžççãªäºäŸãããã³ãã¹ããã©ã¯ãã£ã¹ãæäŸããŸãã
ããŒã¿ããŒã¹ã»ãã¥ãªãã£ïŒSQLã€ã³ãžã§ã¯ã·ã§ã³ã®é²æ¢
仿¥ã®çžäºæ¥ç¶ãããäžçã«ãããŠãããŒã¿ã¯ã»ãŒãã¹ãŠã®çµç¹ã®çåœç·ã§ããéèæ©é¢ãããœãŒã·ã£ã«ã¡ãã£ã¢ãã©ãããã©ãŒã ãŸã§ãããŒã¿ããŒã¹ã®ã»ãã¥ãªãã£ã¯æéèŠã§ããããŒã¿ããŒã¹ã»ãã¥ãªãã£ã«å¯Ÿããæãäžè¬çã§å±éºãªè åšã®äžã€ãSQLã€ã³ãžã§ã¯ã·ã§ã³ïŒSQLiïŒã§ãããã®å æ¬çãªã¬ã€ãã§ã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³ã®è€éããæãäžãã貎éãªããŒã¿ãä¿è·ããããã®å®çšçãªæŽå¯ãäžççãªäºäŸãããã³ãã¹ããã©ã¯ãã£ã¹ãæäŸããŸãã
SQLã€ã³ãžã§ã¯ã·ã§ã³ãšã¯ïŒ
SQLã€ã³ãžã§ã¯ã·ã§ã³ã¯ãæ»æè ãæªæã®ããSQLã³ãŒããããŒã¿ããŒã¹ã¯ãšãªã«æ³šå ¥ã§ããã»ãã¥ãªãã£è匱æ§ã®äžçš®ã§ããããã¯éåžžãWebã¢ããªã±ãŒã·ã§ã³ãããŒã¿ããŒã¹ãšå¯Ÿè©±ããä»ã®ã€ã³ã¿ãŒãã§ãŒã¹ã®å ¥åãã£ãŒã«ããæäœããããšã«ãã£ãŠéæãããŸããæ»æè ã®ç®çã¯ãæå³ãããSQLã¯ãšãªã倿Žããæ©å¯ããŒã¿ãžã®äžæ£ã¢ã¯ã»ã¹ãããŒã¿ã®å€æŽãŸãã¯åé€ãããã«ã¯åºç€ãšãªããµãŒããŒã®å¶åŸ¡æš©ã奪ãããšã§ãã
ãã°ã€ã³ãã©ãŒã ãæã€Webã¢ããªã±ãŒã·ã§ã³ãæ³åããŠã¿ãŠãã ãããã¢ããªã±ãŒã·ã§ã³ã¯æ¬¡ã®ãããªSQLã¯ãšãªã䜿çšãããããããŸããïŒ
SELECT * FROM users WHERE username = '' + username_input + '' AND password = '' + password_input + '';
ããã¢ããªã±ãŒã·ã§ã³ããŠãŒã¶ãŒå ¥åïŒusername_inputãšpassword_inputïŒãé©åã«ãµãã¿ã€ãºããªãå Žåãæ»æè ã¯ãŠãŒã¶ãŒåãã£ãŒã«ãã«æ¬¡ã®ãããªãã®ãå ¥åããå¯èœæ§ããããŸãïŒ
' OR '1'='1
ãããŠãä»»æã®ãã¹ã¯ãŒããå ¥åããŸããçµæãšããŠã¯ãšãªã¯æ¬¡ã®ããã«ãªããŸãïŒ
SELECT * FROM users WHERE username = '' OR '1'='1' AND password = '[any password]';
'1'='1' ã¯åžžã«çã§ããããããã®ã¯ãšãªã¯å¹æçã«èªèšŒããã€ãã¹ããæ»æè ãä»»æã®ãŠãŒã¶ãŒãšããŠãã°ã€ã³ããããšãå¯èœã«ããŸããããã¯åçŽãªäŸã§ãããSQLiæ»æã¯ã¯ããã«é«åºŠã«ãªãå¯èœæ§ããããŸãã
SQLã€ã³ãžã§ã¯ã·ã§ã³æ»æã®çš®é¡
SQLã€ã³ãžã§ã¯ã·ã§ã³æ»æã«ã¯ããŸããŸãªåœ¢æ ããããããããã«ç¬èªã®ç¹åŸŽãšæœåšçãªåœ±é¿ããããŸãã广çãªé²æ¢æŠç¥ãå®è£ ããããã«ã¯ããããã®çš®é¡ãçè§£ããããšãäžå¯æ¬ ã§ãã
- ã€ã³ãã³ãSQLi: ããã¯æãäžè¬çãªã¿ã€ãã§ãæ»æè ã¯æªæã®ããã³ãŒããæ³šå ¥ããããã«äœ¿çšããã®ãšåãéä¿¡ãã£ãã«ãéããŠSQLã¯ãšãªã®çµæãçŽæ¥åãåããŸãã äž»ã«2ã€ã®ãµãã¿ã€ãããããŸãïŒ
- ãšã©ãŒããŒã¹SQLi: æ»æè ã¯SQLã³ãã³ãã䜿çšããŠããŒã¿ããŒã¹ãšã©ãŒãããªã¬ãŒããŸããããã«ãããããŒã¿ããŒã¹ã®ã¹ããŒããããŒã¿ã«é¢ããæ å ±ãæããã«ãªãããšããããããŸããäŸãã°ãæ»æè ããšã©ãŒãåŒãèµ·ããã³ãã³ãã䜿çšãããšããšã©ãŒã¡ãã»ãŒãžãããŒãã«åãã«ã©ã åãå ¬éããå¯èœæ§ããããŸãã
- UNIONããŒã¹SQLi: æ»æè ã¯UNIONæŒç®åã䜿çšããŠãæ³šå ¥ããã¯ãšãªã®çµæãå ã®ã¯ãšãªã®çµæãšçµåããŸããããã«ãããä»ã®ããŒãã«ããããŒã¿ãååŸããããåºåã«ä»»æã®ããŒã¿ãæ³šå ¥ãããããããšãå¯èœã«ãªããŸããäŸãã°ãæ»æè ã¯ããŒã¿ããŒã¹ãŠãŒã¶ãŒã®èªèšŒæ å ±ãå«ãSELECTæãæ³šå ¥ã§ããŸãã
- æšè«ïŒãã©ã€ã³ãïŒSQLi: ãã®ã¿ã€ãã§ã¯ãæ»æè ã¯æªæã®ããSQLã¯ãšãªã®çµæãçŽæ¥èŠãããšã¯ã§ããŸããã代ããã«ãã¢ããªã±ãŒã·ã§ã³ã®åäœãåæããŠããŒã¿ããŒã¹ã«é¢ããæ å ±ãæšæž¬ããŸãã äž»ã«2ã€ã®ãµãã¿ã€ãããããŸãïŒ
- ããŒã«ããŒã¹SQLi: æ»æè ã¯çãŸãã¯åœã«è©äŸ¡ãããã¯ãšãªãæ³šå ¥ããã¢ããªã±ãŒã·ã§ã³ã®å¿çã芳å¯ããããšã§æ å ±ãæšæž¬ããŸããäŸãã°ãæ¡ä»¶ãçãåœãã«ãã£ãŠã¢ããªã±ãŒã·ã§ã³ãç°ãªãããŒãžã衚瀺ããå Žåãæ»æè ã¯ãããå©çšããŠãSELECT * FROM users WHERE username = 'admin' AND 1=1ãã®ãããªã¯ãšãªã®çåœå€ã倿ã§ããŸãã
- æéããŒã¹SQLi: æ»æè ã¯ãæ¡ä»¶ã®çåœå€ã«åºã¥ããŠããŒã¿ããŒã¹ã®å¿çãé å»¶ãããã¯ãšãªãæ³šå ¥ããŸããäŸãã°ããSELECT * FROM users WHERE username = 'admin' AND IF(1=1, SLEEP(5), 0)ãã®ããã«ãæ¡ä»¶ãçã®å Žåã«å®è¡ãé å»¶ãããã¯ãšãªãæ³šå ¥ã§ããŸããããŒã¿ããŒã¹ã5ç§é忢ããå Žåãããã¯æ¡ä»¶ãçã§ããããšã瀺ããŸãã
- ã¢ãŠããªããã³ãSQLi: ãã®ããŸãäžè¬çã§ãªãã¿ã€ãã§ã¯ãæªæã®ããã³ãŒããæ³šå ¥ããããã«äœ¿çšãããã£ãã«ãšã¯ç°ãªãéä¿¡ãã£ãã«ã䜿çšããŠããŒã¿ãæãåºããŸããããã¯ãæ»æè ãçµæãçŽæ¥ååŸã§ããªãå Žåã«ãã䜿çšãããŸããäŸãã°ãæ»æè ã¯DNSãHTTPãªã¯ãšã¹ãã䜿çšããŠãèªèº«ãå¶åŸ¡ããå€éšãµãŒããŒã«ããŒã¿ãéä¿¡ããããšããããŸããããã¯ãã¿ãŒã²ããã®ããŒã¿ããŒã¹ãçŽæ¥çãªããŒã¿åºåã«å¶éãããå Žåã«ç¹ã«åœ¹ç«ã¡ãŸãã
SQLã€ã³ãžã§ã¯ã·ã§ã³ã®åœ±é¿
SQLã€ã³ãžã§ã¯ã·ã§ã³æ»æãæåããå Žåã®åœ±é¿ã¯ãäŒæ¥ãšå人ã®äž¡æ¹ã«ãšã£ãŠå£æ» çãªãã®ã«ãªãå¯èœæ§ããããŸãã圱é¿ã¯ã軜埮ãªããŒã¿äŸµå®³ããå®å šãªã·ã¹ãã 䟵害ãŸã§å€å²ã«ããããŸãã圱é¿ã¯ãä¿åãããŠããããŒã¿ã®æ©å¯æ§ãããŒã¿ããŒã¹ã®æ§æãæ»æè ã®æå³ã«ãã£ãŠç°ãªããŸãã以äžã¯äžè¬çãªåœ±é¿ã®äžéšã§ãïŒ
- ããŒã¿äŸµå®³: æ»æè ã¯ããŠãŒã¶ãŒåããã¹ã¯ãŒããã¯ã¬ãžããã«ãŒãæ å ±ãå人è奿 å ±ïŒPIIïŒãæ©å¯ããžãã¹ããŒã¿ãªã©ã®æ©å¯æ å ±ã«ã¢ã¯ã»ã¹ã§ããŸããããã¯ãééçæå€±ãè©å€ã®æå®³ãæ³ç責任ã«ã€ãªããå¯èœæ§ããããŸãã
- ããŒã¿ã®å€æŽãšåé€: æ»æè ã¯ããŒã¿ã倿ŽãŸãã¯åé€ããããŒã¿ããŒã¹ãç ŽæãããŠäºæ¥éå¶ã«éå€§ãªæ··ä¹±ãåŒãèµ·ããå¯èœæ§ããããŸããããã¯ã売äžã顧客ãµãŒãã¹ããã®ä»ã®éèŠãªæ©èœã«åœ±é¿ãäžããå¯èœæ§ããããŸããæ»æè ãäŸ¡æ Œæ å ±ã倿Žãããã顧客ã¬ã³ãŒããåé€ãããããããšãæ³åããŠã¿ãŠãã ããã
- ã·ã¹ãã 䟵害: å Žåã«ãã£ãŠã¯ãæ»æè ã¯SQLiãæªçšããŠåºç€ãšãªããµãŒããŒã®å¶åŸ¡æš©ã奪ãããšããããŸããããã«ã¯ãä»»æã®ã³ãã³ãã®å®è¡ããã«ãŠã§ã¢ã®ã€ã³ã¹ããŒã«ãã·ã¹ãã ãžã®å®å šãªã¢ã¯ã»ã¹ãå«ãŸããŸããããã«ãããå®å šãªã·ã¹ãã é害ãããŒã¿æå€±ã«ã€ãªããå¯èœæ§ããããŸãã
- ãµãŒãã¹æåŠïŒDoSïŒ: æ»æè ã¯SQLiã䜿çšããŠãããŒã¿ããŒã¹ã«æªæã®ããã¯ãšãªã倧éã«éã蟌ã¿ãæ£èŠã®ãŠãŒã¶ãŒãå©çšã§ããªãããã«ããDoSæ»æã仿ããããšãã§ããŸããããã«ããããŠã§ããµã€ããã¢ããªã±ãŒã·ã§ã³ãæ©èœäžå šã«é¥ãããµãŒãã¹ãäžæãããééçæå€±ãçºçããå¯èœæ§ããããŸãã
- è©å€ã®æå®³: ããŒã¿äŸµå®³ãã·ã¹ãã 䟵害ã¯ãçµç¹ã®è©å€ãèããæãªãã顧客ã®ä¿¡é Œã倱ããããžãã¹ã®æžå°ã«ã€ãªããå¯èœæ§ããããŸããä¿¡é Œãå埩ããã®ã¯éåžžã«å°é£ã§æéãããããŸãã
- ééçæå€±: SQLiæ»æã«é¢é£ããã³ã¹ãã¯ãã€ã³ã·ãã³ã察å¿ãããŒã¿åŸ©æ§ãåŒè·å£«è²»çšãèŠå¶äžã®çœ°éïŒäŸïŒGDPRãCCPAïŒãããã³å€±ãããããžãã¹ã«é¢é£ããè²»çšãå«ããè«å€§ãªãã®ã«ãªãå¯èœæ§ããããŸãã
SQLã€ã³ãžã§ã¯ã·ã§ã³ã®é²æ¢ïŒãã¹ããã©ã¯ãã£ã¹
幞ããªããšã«ãSQLã€ã³ãžã§ã¯ã·ã§ã³ã¯äºé²å¯èœãªè匱æ§ã§ãããã¹ããã©ã¯ãã£ã¹ãçµã¿åãããããšã§ãSQLiæ»æã®ãªã¹ã¯ãå€§å¹ ã«äœæžããããŒã¿ãä¿è·ããããšãã§ããŸãã以äžã®æŠç¥ãéèŠã§ãïŒ
1. å ¥å倿€èšŒãšãµãã¿ã€ãº
å ¥å倿€èšŒã¯ããŠãŒã¶ãŒãæäŸããããŒã¿ãæåŸ ããããã¿ãŒã³ã圢åŒã«æºæ ããŠãããã確èªããããã»ã¹ã§ããããã¯é²åŸ¡ã®ç¬¬äžç·ã§ããå ¥å倿€èšŒã¯ãã¯ã©ã€ã¢ã³ããµã€ãïŒãŠãŒã¶ãŒãšã¯ã¹ããªãšã³ã¹ã®ããïŒãšãæãéèŠãªãµãŒããŒãµã€ãïŒã»ãã¥ãªãã£ã®ããïŒã§è¡ãå¿ èŠããããŸãã以äžãæ€èšããŠãã ããïŒ
- ãã¯ã€ããªã¹ãæ¹åŒ: 蚱容ãããå ¥åå€ã®ãªã¹ããå®çŸ©ããäžèŽããªããã®ã¯ãã¹ãŠæåŠããŸããããã¯ãäºæããªãå ¥åãé²ããããäžè¬çã«ãã©ãã¯ãªã¹ãæ¹åŒãããå®å šã§ãã
- ããŒã¿åã®æ€èšŒ: å ¥åãã£ãŒã«ããæ£ããããŒã¿åïŒäŸïŒæŽæ°ãæååãæ¥ä»ïŒã§ããããšã確èªããŸããäŸãã°ãæ°å€ã®ã¿ãåãä»ããã¹ããã£ãŒã«ãã¯ãæåãç¹æ®æåãæåŠãã¹ãã§ãã
- é·ããšç¯å²ã®ãã§ãã¯: å ¥åãã£ãŒã«ãã®é·ããå¶éããæ°å€ã蚱容ç¯å²å ã«ããããšãæ€èšŒããŸãã
- æ£èŠè¡šçŸ: æ£èŠè¡šçŸïŒregexïŒã䜿çšããŠãã¡ãŒã«ã¢ãã¬ã¹ãé»è©±çªå·ãæ¥ä»ãªã©ã®å ¥å圢åŒãæ€èšŒããŸããããã¯ãããŒã¿ãç¹å®ã®ã«ãŒã«ã«æºæ ããŠããããšã確èªããã®ã«ç¹ã«åœ¹ç«ã¡ãŸãã
å ¥åå€ãµãã¿ã€ãºã¯ããŠãŒã¶ãŒãæäŸããããŒã¿ããæœåšçã«æªæã®ããæåãåé€ãŸãã¯å€æŽããããã»ã¹ã§ããããã¯ãæªæã®ããã³ãŒããããŒã¿ããŒã¹ã«ãã£ãŠå®è¡ãããã®ãé²ãããã®éèŠãªã¹ãããã§ããäž»ãªåŽé¢ã¯æ¬¡ã®ãšããã§ãïŒ
- ç¹æ®æåã®ãšã¹ã±ãŒã: SQLã¯ãšãªã§ç¹å¥ãªæå³ãæã€ç¹æ®æåïŒäŸïŒã·ã³ã°ã«ã¯ã©ãŒããããã«ã¯ã©ãŒããããã¯ã¹ã©ãã·ã¥ãã»ãã³ãã³ïŒããšã¹ã±ãŒãããŸããããã«ããããããã®æåãã³ãŒããšããŠè§£éãããã®ãé²ããŸãã
- å ¥åã®ãšã³ã³ãŒãã£ã³ã°: SQLã€ã³ãžã§ã¯ã·ã§ã³ãšçµã¿åãããŠäœ¿çšãããå¯èœæ§ã®ããã¯ãã¹ãµã€ãã¹ã¯ãªããã£ã³ã°ïŒXSSïŒæ»æãé²ãããã«ãHTMLãšã³ãã£ãã£ãšã³ã³ãŒãã£ã³ã°ãªã©ã®æ¹æ³ã§ãŠãŒã¶ãŒå ¥åããšã³ã³ãŒãããããšãæ€èšããŠãã ããã
- æªæã®ããã³ãŒãã®åé€: SQLããŒã¯ãŒããã³ãã³ããªã©ãæœåšçã«æå®³ãªã³ãŒããåé€ãŸãã¯çœ®æããããšãæ€èšããŸãããã®ã¢ãããŒãã¯ãæ éã«å®è£ ããªããšãšã©ãŒããã€ãã¹ãçºçãããããããéåžžã«æ³šæãå¿ èŠã§ãã
2. ããªãã¢ãã¹ããŒãã¡ã³ãïŒãã©ã¡ãŒã¿åã¯ãšãªïŒ
ããªãã¢ãã¹ããŒãã¡ã³ãïŒãã©ã¡ãŒã¿åã¯ãšãªãšãåŒã°ããŸãïŒã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³ã鲿¢ããããã®æã广çãªæ¹æ³ã§ãããã®æè¡ã¯ãSQLã³ãŒãããŠãŒã¶ãŒæäŸã®ããŒã¿ããåé¢ããããŒã¿ããã©ã¡ãŒã¿ãšããŠæ±ããŸããããã«ãããããŒã¿ããŒã¹ãšã³ãžã³ããŠãŒã¶ãŒã®å ¥åãå®è¡å¯èœãªSQLã³ãã³ãã§ã¯ãªãããŒã¿ãšããŠè§£éãããããæ»æè ãæªæã®ããã³ãŒããæ³šå ¥ããã®ãé²ããŸããä»çµã¿ã¯æ¬¡ã®ãšããã§ãïŒ
- éçºè ã¯ããŠãŒã¶ãŒå ¥åçšã®ãã¬ãŒã¹ãã«ããŒïŒãã©ã¡ãŒã¿ïŒãæã€SQLã¯ãšãªãå®çŸ©ããŸãã
- ããŒã¿ããŒã¹ãšã³ãžã³ã¯SQLã¯ãšãªãããªã³ã³ãã€ã«ãããã®å®è¡ãæé©åããŸãã
- ã¢ããªã±ãŒã·ã§ã³ã¯ããŠãŒã¶ãŒæäŸã®ããŒã¿ããã©ã¡ãŒã¿ãšããŠããªã³ã³ãã€ã«ãããã¯ãšãªã«æž¡ããŸãã
- ããŒã¿ããŒã¹ãšã³ãžã³ã¯ããã©ã¡ãŒã¿ãã¯ãšãªã«ä»£å ¥ããããããSQLã³ãŒãã§ã¯ãªãããŒã¿ãšããŠæ±ãããããšãä¿èšŒããŸãã
äŸïŒPythonãšPostgreSQLïŒ:
import psycopg2
conn = psycopg2.connect(database="mydatabase", user="myuser", password="mypassword", host="localhost", port="5432")
cur = conn.cursor()
username = input("Enter username: ")
password = input("Enter password: ")
sql = "SELECT * FROM users WHERE username = %s AND password = %s;"
cur.execute(sql, (username, password))
results = cur.fetchall()
if results:
print("Login successful!")
else:
print("Login failed.")
cur.close()
conn.close()
ãã®äŸã§ã¯ããã¬ãŒã¹ãã«ã㌠`%s` ããŠãŒã¶ãŒæäŸã® `username` ãš `password` ã«çœ®ãæããããŸããããŒã¿ããŒã¹ãã©ã€ãããšã¹ã±ãŒãåŠçãè¡ããå ¥åãããŒã¿ãšããŠæ±ãããããšãä¿èšŒãããããSQLã€ã³ãžã§ã¯ã·ã§ã³ã鲿¢ãããŸãã
ããªãã¢ãã¹ããŒãã¡ã³ãã®å©ç¹:
- SQLiã®é²æ¢: äž»ãªå©ç¹ã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³æ»æã广çã«é²æ¢ããããšã§ãã
- ããã©ãŒãã³ã¹: ããŒã¿ããŒã¹ãšã³ãžã³ã¯ããªãã¢ãã¹ããŒãã¡ã³ããæé©åããŠåå©çšã§ãããããå®è¡ãé«éã«ãªããŸãã
- å¯èªæ§: SQLã¯ãšãªãšããŒã¿ãåé¢ããããããã³ãŒããããèªã¿ããããä¿å®ãããããªããŸãã
3. ã¹ãã¢ãããã·ãŒãžã£
ã¹ãã¢ãããã·ãŒãžã£ã¯ãããŒã¿ããŒã¹å ã«ä¿åãããããªã³ã³ãã€ã«ãããSQLã³ãŒããããã¯ã§ããè€éãªããŒã¿ããŒã¹ããžãã¯ãã«ãã»ã«åããã¢ããªã±ãŒã·ã§ã³ããåŒã³åºãããšãã§ããŸããã¹ãã¢ãããã·ãŒãžã£ã䜿çšãããšã次ã®ããã«ã»ãã¥ãªãã£ã匷åã§ããŸãïŒ
- æ»æå¯Ÿè±¡é åã®åæž: ã¢ããªã±ãŒã·ã§ã³ã³ãŒãã¯äºåå®çŸ©ãããããã·ãŒãžã£ãåŒã³åºããããã¢ããªã±ãŒã·ã§ã³ãçŽæ¥SQLã¯ãšãªãæ§ç¯ã»å®è¡ããããšã¯ãããŸãããã¹ãã¢ãããã·ãŒãžã£ã«æž¡ããããã©ã¡ãŒã¿ã¯éåžžãããã·ãŒãžã£èªäœã§æ€èšŒããããããSQLã€ã³ãžã§ã¯ã·ã§ã³ã®ãªã¹ã¯ãäœæžããŸãã
- æœè±¡å: ããŒã¿ããŒã¹ããžãã¯ãã¢ããªã±ãŒã·ã§ã³ã³ãŒãããé èœããããããã¢ããªã±ãŒã·ã§ã³ãç°¡çŽ åãããã»ãã¥ãªãã£ã®å±€ã远å ãããŸãã
- ã«ãã»ã«å: ã¹ãã¢ãããã·ãŒãžã£ã¯ãäžè²«ããããŒã¿ã¢ã¯ã»ã¹ãšæ€èšŒã«ãŒã«ã匷å¶ããããŒã¿ã®æŽåæ§ãšã»ãã¥ãªãã£ã確ä¿ã§ããŸãã
ãã ããã¹ãã¢ãããã·ãŒãžã£èªäœãå®å šã«èšè¿°ãããå ¥åãã©ã¡ãŒã¿ãããã·ãŒãžã£å ã§é©åã«æ€èšŒãããŠããããšã確èªããŠãã ãããããã§ãªããã°ãè匱æ§ãå°å ¥ãããå¯èœæ§ããããŸãã
4. æå°æš©éã®åå
æå°æš©éã®ååã¯ããŠãŒã¶ãŒãšã¢ããªã±ãŒã·ã§ã³ã«ã¯ãã¿ã¹ã¯ãå®è¡ããããã«å¿ èŠãªæå°éã®æš©éã®ã¿ãä»äžãã¹ãã§ãããšå®ããŠããŸããããã«ãããæ»æè ãè匱æ§ãæªçšããå Žåã®æå®³ãå¶éã§ããŸãã以äžãæ€èšããŠãã ããïŒ
- ãŠãŒã¶ãŒããŒã«ãšæš©é: è·åã«åºã¥ããŠããŒã¿ããŒã¹ãŠãŒã¶ãŒã«ç¹å®ã®ããŒã«ãšæš©éãå²ãåœãŠãŸããäŸãã°ãWebã¢ããªã±ãŒã·ã§ã³ã®ãŠãŒã¶ãŒã¯ãç¹å®ã®ããŒãã«ã«å¯ŸããSELECTæš©éã®ã¿ãå¿ èŠãªå ŽåããããŸããCREATEãALTERãDROPãªã©ã®äžèŠãªæš©éãä»äžããããšã¯é¿ããŠãã ããã
- ããŒã¿ããŒã¹ã¢ã«ãŠã³ãã®æš©é: ã¢ããªã±ãŒã·ã§ã³æ¥ç¶ã«ããŒã¿ããŒã¹ç®¡çè ïŒDBAïŒã¢ã«ãŠã³ããã¹ãŒããŒãŠãŒã¶ãŒã¢ã«ãŠã³ãã䜿çšããªãã§ãã ãããå¶éãããæš©éãæã€å°çšã®ã¢ã«ãŠã³ãã䜿çšããŠãã ããã
- 宿çãªæš©éã¬ãã¥ãŒ: 宿çã«ãŠãŒã¶ãŒæš©éãã¬ãã¥ãŒããããããé©åã§ããç¶ããããšã確èªããäžèŠãªæš©éãåé€ããŠãã ããã
ãã®ååãé©çšããããšã§ãæ»æè ãæªæã®ããã³ãŒããæ³šå ¥ã§ãããšããŠãããã®ã¢ã¯ã»ã¹ã¯å¶éãããæœåšçãªæå®³ãæå°éã«æããããšãã§ããŸãã
5. 宿çãªã»ãã¥ãªãã£ç£æ»ãšäŸµå ¥ãã¹ã
宿çãªã»ãã¥ãªãã£ç£æ»ãšäŸµå ¥ãã¹ãã¯ãããŒã¿ããŒã¹ç°å¢ã®è匱æ§ãç¹å®ãã察åŠããããã«äžå¯æ¬ ã§ãããã®ç©æ¥µçãªã¢ãããŒãã«ãããæœåšçãªæ»æã®äžæ©å ãè¡ãããšãã§ããŸãã以äžãæ€èšããŠãã ããïŒ
- ã»ãã¥ãªãã£ç£æ»: ããŒã¿ããŒã¹ã®ã»ãã¥ãªãã£äœå¶ãè©äŸ¡ããããã«ã宿çãã€å å€ã®ç£æ»ã宿œããŸãããããã®ç£æ»ã«ã¯ãã³ãŒãã¬ãã¥ãŒãæ§æã¬ãã¥ãŒãè匱æ§ã¹ãã£ã³ãå«ãŸããã¹ãã§ãã
- äŸµå ¥ãã¹ãïŒå«ççãããã³ã°ïŒ: ã»ãã¥ãªãã£å°éå®¶ãéã£ãŠãå®éã®æ»æãã·ãã¥ã¬ãŒãããè匱æ§ãç¹å®ããŸããäŸµå ¥ãã¹ãã¯ã宿çãã€ã¢ããªã±ãŒã·ã§ã³ãããŒã¿ããŒã¹ã«å€§ããªå€æŽããã£ãåŸã«å®æœãã¹ãã§ããäŸµå ¥ãã¹ã¿ãŒã¯ãæªæã®ããæ»æè ãšåæ§ã®ããŒã«ãæè¡ã䜿çšããŠåŒ±ç¹ãæ¢ããŸãã
- è匱æ§ã¹ãã£ã³: èªååãããè匱æ§ã¹ãã£ããŒã䜿çšããŠãããŒã¿ããŒã¹ãœãããŠã§ã¢ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ããããã¯ãŒã¯ã€ã³ãã©ã¹ãã©ã¯ãã£ã®æ¢ç¥ã®è匱æ§ãç¹å®ããŸãããããã®ã¹ãã£ã³ã¯ãæœåšçãªã»ãã¥ãªãã£ã®ã£ãããè¿ éã«ç¹å®ãã察åŠããã®ã«åœ¹ç«ã¡ãŸãã
- ãã©ããŒã¢ãã: ç£æ»ãäŸµå ¥ãã¹ãã§ç¹å®ãããè匱æ§ã¯ãè¿ éã«ä¿®æ£ããŸãããã¹ãŠã®åé¡ã察åŠãããåãã¹ããããŠããããšã確èªããŠãã ããã
6. Webã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ïŒWAFïŒ
Webã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ïŒWAFïŒã¯ãWebã¢ããªã±ãŒã·ã§ã³ã®åã«èšçœ®ãããæªæã®ãããã©ãã£ãã¯ããã£ã«ã¿ãªã³ã°ããã»ãã¥ãªãã£ããã€ã¹ã§ããWAFã¯ãåä¿¡ãªã¯ãšã¹ããæ€æ»ããçããããã¿ãŒã³ããããã¯ããããšã§ãSQLã€ã³ãžã§ã¯ã·ã§ã³æ»æããä¿è·ããã®ã«åœ¹ç«ã¡ãŸããäžè¬çãªSQLã€ã³ãžã§ã¯ã·ã§ã³ãã€ããŒãããã®ä»ã®æ»æãæ€åºãããããã¯ããããšãã§ããŸããWAFã®äž»ãªæ©èœã¯æ¬¡ã®ãšããã§ãïŒ
- ã·ã°ããã£ããŒã¹ã®æ€åº: æ¢ç¥ã®æ»æã·ã°ããã£ã«åºã¥ããŠæªæã®ãããã¿ãŒã³ãèå¥ããŸãã
- è¡ååæ: ç°åžžãªãªã¯ãšã¹ããã¿ãŒã³ãéå°ãªãã©ãã£ãã¯ãªã©ãæ»æã瀺ãå¯èœæ§ã®ããç°åžžãªè¡åãæ€åºããŸãã
- ã¬ãŒãå¶é: åäžã®IPã¢ãã¬ã¹ããã®ãªã¯ãšã¹ãæ°ãå¶éããŠããã«ãŒããã©ãŒã¹æ»æãé²ããŸãã
- ã«ã¹ã¿ã ã«ãŒã«: ç¹å®ã®è匱æ§ã«å¯ŸåŠããããç¹å®ã®åºæºã«åºã¥ããŠãã©ãã£ãã¯ããããã¯ãããããããã®ã«ã¹ã¿ã ã«ãŒã«ãäœæã§ããŸãã
WAFã¯å®å šãªã³ãŒãã£ã³ã°ãã©ã¯ãã£ã¹ã®ä»£æ¿ã«ã¯ãªããŸããããç¹ã«ã¬ã¬ã·ãŒã¢ããªã±ãŒã·ã§ã³ãè匱æ§ã®ä¿®æ£ãå°é£ãªå Žåã«ã远å ã®é²åŸ¡å±€ãæäŸã§ããŸãã
7. ããŒã¿ããŒã¹ã¢ã¯ãã£ããã£ç£èŠïŒDAMïŒãšäŸµå ¥æ€ç¥ã·ã¹ãã ïŒIDSïŒ
ããŒã¿ããŒã¹ã¢ã¯ãã£ããã£ç£èŠïŒDAMïŒãœãªã¥ãŒã·ã§ã³ãšäŸµå ¥æ€ç¥ã·ã¹ãã ïŒIDSïŒã¯ãããŒã¿ããŒã¹ç°å¢ã§ã®äžå¯©ãªã¢ã¯ãã£ããã£ãç£èŠããã³æ€åºããã®ã«åœ¹ç«ã¡ãŸããDAMããŒã«ã¯ãããŒã¿ããŒã¹ã¯ãšãªããŠãŒã¶ãŒã¢ã¯ã·ã§ã³ãããŒã¿ã¢ã¯ã»ã¹ã远跡ããæœåšçãªã»ãã¥ãªãã£è åšã«é¢ãã貎éãªæŽå¯ãæäŸããŸããIDSã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³ã®è©Šã¿ãªã©ãç°åžžãªè¡åãã¿ãŒã³ãæ€åºããã»ãã¥ãªãã£æ åœè ã«äžå¯©ãªã€ãã³ããèŠåã§ããŸãã
- ãªã¢ã«ã¿ã€ã ç£èŠ: DAMããã³IDSãœãªã¥ãŒã·ã§ã³ã¯ãããŒã¿ããŒã¹ã¢ã¯ãã£ããã£ã®ãªã¢ã«ã¿ã€ã ç£èŠãæäŸããæ»æã®è¿ éãªæ€åºãå¯èœã«ããŸãã
- ã¢ã©ãŒãæ©èœ: äžå¯©ãªã¢ã¯ãã£ããã£ãæ€åºããããšã¢ã©ãŒããçæããã»ãã¥ãªãã£ããŒã ãè åšã«è¿ éã«å¯Ÿå¿ã§ããããã«ããŸãã
- ãã©ã¬ã³ãžãã¯åæ: ããŒã¿ããŒã¹ã¢ã¯ãã£ããã£ã®è©³çްãªãã°ãæäŸããã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®ç¯å²ãšåœ±é¿ãçè§£ããããã®ãã©ã¬ã³ãžãã¯åæã«äœ¿çšã§ããŸãã
- ã³ã³ãã©ã€ã¢ã³ã¹: å€ãã®DAMããã³IDSãœãªã¥ãŒã·ã§ã³ã¯ãçµç¹ãããŒã¿ã»ãã¥ãªãã£ã®ã³ã³ãã©ã€ã¢ã³ã¹èŠä»¶ãæºããã®ã«åœ¹ç«ã¡ãŸãã
8. 宿çãªããã¯ã¢ãããšçœå®³åŸ©æ§
宿çãªããã¯ã¢ãããšå ç¢ãªçœå®³åŸ©æ§èšç»ã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³æ»æãæåããå Žåã®åœ±é¿ã軜æžããããã«äžå¯æ¬ ã§ããå¿ èŠãªãã¹ãŠã®äºé²æªçœ®ãè¬ããŠããæ»æãæåããå¯èœæ§ã¯æ®ããŸãããã®ãããªå Žåãããã¯ã¢ãããããã°ããŒã¿ããŒã¹ãã¯ãªãŒã³ãªç¶æ ã«åŸ©å ã§ããŸãã以äžãæ€èšããŠãã ããïŒ
- 宿çãªããã¯ã¢ãã: 宿çãªããã¯ã¢ããã¹ã±ãžã¥ãŒã«ãå®è£ ããŠãããŒã¿ããŒã¹ã®ãã€ã³ãã€ã³ã¿ã€ã ã³ããŒãäœæããŸããããã¯ã¢ããã®é »åºŠã¯ãããŒã¿ã®éèŠæ§ãšèš±å®¹ã§ããããŒã¿æå€±ãŠã£ã³ããŠïŒRPOïŒã«ãã£ãŠç°ãªããŸãã
- ãªããµã€ãã¹ãã¬ãŒãž: ç©ççãªæå·ã䟵害ããä¿è·ããããã«ãããã¯ã¢ãããå®å šãªãªããµã€ãã®å Žæã«ä¿ç®¡ããŸããã¯ã©ãŠãããŒã¹ã®ããã¯ã¢ãããœãªã¥ãŒã·ã§ã³ããŸããŸãæ®åããŠããŸãã
- ããã¯ã¢ããã®ãã¹ã: ããã¯ã¢ããããã¹ãç°å¢ã«åŸ©å ããŠãæ£ããæ©èœããŠããããšã宿çã«ãã¹ãããŸãã
- çœå®³åŸ©æ§èšç»: æ»æããã®ä»ã®çœå®³ãçºçããå Žåã«ããŒã¿ããŒã¹ãšã¢ããªã±ãŒã·ã§ã³ã埩å ããããã®æé ãæŠèª¬ããå æ¬çãªçœå®³åŸ©æ§èšç»ãçå®ããŸãããã®èšç»ã«ã¯ãã€ã³ã·ãã³ãã®åœ±é¿ãç¹å®ããæå®³ãå°ã蟌ããããŒã¿ãå埩ããéåžžã®éçšã埩å ããããã®æé ãå«ãŸããã¹ãã§ãã
9. ã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°
ã»ãã¥ãªãã£æèåäžãã¬ãŒãã³ã°ã¯ãåŸæ¥å¡ã«SQLã€ã³ãžã§ã¯ã·ã§ã³ããã®ä»ã®ã»ãã¥ãªãã£è åšã®ãªã¹ã¯ã«ã€ããŠæè²ããããã«äžå¯æ¬ ã§ãããã¬ãŒãã³ã°ã§ã¯ä»¥äžãã«ããŒãã¹ãã§ãïŒ
- SQLiã®æ§è³ª: SQLã€ã³ãžã§ã¯ã·ã§ã³ãšã¯äœããã©ã®ããã«æ©èœãããããããŠãã®ãããªæ»æã®æœåšçãªåœ±é¿ã«ã€ããŠåŸæ¥å¡ãæè²ããŸãã
- å®å šãªã³ãŒãã£ã³ã°ãã©ã¯ãã£ã¹: éçºè ã«ãå ¥å倿€èšŒããã©ã¡ãŒã¿åã¯ãšãªãæ©å¯ããŒã¿ã®å®å šãªä¿ç®¡ãªã©ãå®å šãªã³ãŒãã£ã³ã°ãã©ã¯ãã£ã¹ã«ã€ããŠãã¬ãŒãã³ã°ããŸãã
- ãã¹ã¯ãŒãã»ãã¥ãªãã£: 匷åãªãã¹ã¯ãŒããšå€èŠçŽ èªèšŒïŒMFAïŒã®éèŠæ§ã匷調ããŸãã
- ãã£ãã·ã³ã°ãžã®æè: åŸæ¥å¡ã«ãã£ãã·ã³ã°æ»æã«ã€ããŠæè²ããŸãããã£ãã·ã³ã°æ»æã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³æ»æãéå§ããããã«äœ¿çšã§ããèªèšŒæ å ±ãçãããã«ãã䜿çšãããŸãã
- ã€ã³ã·ãã³ã察å¿: ã»ãã¥ãªãã£ã€ã³ã·ãã³ãã®å ±åæ¹æ³ããçãããæ»æãžã®å¯Ÿå¿æ¹æ³ã«ã€ããŠåŸæ¥å¡ããã¬ãŒãã³ã°ããŸãã
宿çãªãã¬ãŒãã³ã°ãšã»ãã¥ãªãã£æŽæ°ã¯ãçµç¹å ã«ã»ãã¥ãªãã£æèã®é«ãæåãéžæããã®ã«åœ¹ç«ã¡ãŸãã
10. ãœãããŠã§ã¢ãææ°ã®ç¶æ ã«ä¿ã€
ããŒã¿ããŒã¹ãœãããŠã§ã¢ããªãã¬ãŒãã£ã³ã°ã·ã¹ãã ãWebã¢ããªã±ãŒã·ã§ã³ã宿çã«ææ°ã®ã»ãã¥ãªãã£ãããã§æŽæ°ããŸãããœãããŠã§ã¢ãã³ããŒã¯ãSQLã€ã³ãžã§ã¯ã·ã§ã³ã®æ¬ é¥ãå«ãæ¢ç¥ã®è匱æ§ã«å¯ŸåŠããããã®ããããé »ç¹ã«ãªãªãŒã¹ããŸããããã¯ãæ»æã«å¯ŸããæãåçŽã§å¹æçãªé²åŸ¡çã®äžã€ã§ãã以äžãæ€èšããŠãã ããïŒ
- ããã管ç: ããã管çããã»ã¹ãå®è£ ããŠãæŽæ°ãè¿ éã«é©çšãããããã«ããŸãã
- è匱æ§ã¹ãã£ã³: è匱æ§ã¹ãã£ããŒã䜿çšããŠãSQLã€ã³ãžã§ã¯ã·ã§ã³ããã®ä»ã®æ»æã«å¯ŸããŠè匱ãªå¯èœæ§ã®ããå€ããœãããŠã§ã¢ãç¹å®ããŸãã
- æŽæ°ã®ãã¹ã: äºææ§ã®åé¡ãåé¿ããããã«ãæ¬çªç°å¢ã«å±éããåã«ã鿬çªç°å¢ã§æŽæ°ããã¹ãããŸãã
SQLã€ã³ãžã§ã¯ã·ã§ã³æ»æãšãã®é²æ¢çã®äŸïŒã°ããŒãã«ãªèŠç¹ïŒ
SQLã€ã³ãžã§ã¯ã·ã§ã³ã¯äžççãªè åšã§ãããããããæ¥çãåœã®çµç¹ã«åœ±é¿ãäžããŠããŸãã以äžã®äŸã¯ãã°ããŒãã«ãªäºäŸãåèã«ãSQLã€ã³ãžã§ã¯ã·ã§ã³æ»æãã©ã®ããã«çºçããã©ã®ããã«é²ãããšãã§ãããã瀺ããŠããŸãã
äŸ1ïŒeã³ããŒã¹ãµã€ãïŒå šäžçïŒ
ã·ããªãª: æ¥æ¬ã®eã³ããŒã¹ãµã€ããèåŒ±ãªæ€çŽ¢æ©èœã䜿çšããŠããŸããæ»æè ã¯æ€çŽ¢ããã¯ã¹ã«æªæã®ããSQLã¯ãšãªãæ³šå ¥ããã¯ã¬ãžããã«ãŒãæ å ±ãå«ã顧客ããŒã¿ã«ã¢ã¯ã»ã¹ããŸãã
è匱æ§: ã¢ããªã±ãŒã·ã§ã³ããŠãŒã¶ãŒå ¥åãé©åã«æ€èšŒãããæ€çŽ¢ã¯ãšãªãçŽæ¥SQLã¹ããŒãã¡ã³ãã«åã蟌ãã§ããŸãã
鲿¢ç: ããªãã¢ãã¹ããŒãã¡ã³ããå®è£ ããŸããã¢ããªã±ãŒã·ã§ã³ã¯ããŠãŒã¶ãŒå ¥åãSQLã³ãŒãã§ã¯ãªãããŒã¿ãšããŠæ±ããããã©ã¡ãŒã¿åã¯ãšãªã䜿çšãã¹ãã§ãããŸãããŠã§ããµã€ãã¯ãã¹ãŠã®ãŠãŒã¶ãŒå ¥åããµãã¿ã€ãºããŠãæœåšçã«æªæã®ããæåãã³ãŒããåé€ãã¹ãã§ãã
äŸ2ïŒæ¿åºããŒã¿ããŒã¹ïŒç±³åœïŒ
ã·ããªãª: ç±³åœã®æ¿åºæ©é¢ãåžæ°ã®èšé²ã管çããããã«Webã¢ããªã±ãŒã·ã§ã³ã䜿çšããŠããŸããæ»æè ã¯SQLã³ãŒããæ³šå ¥ããŠèªèšŒããã€ãã¹ãã瀟äŒä¿éçªå·ãäœæãªã©ã®æ©å¯æ§ã®é«ãå人æ å ±ã«äžæ£ã¢ã¯ã»ã¹ããŸãã
è匱æ§: ã¢ããªã±ãŒã·ã§ã³ããé©åãªå ¥åæ€èšŒããµãã¿ã€ãºãªãã«ããŠãŒã¶ãŒå ¥åãé£çµããŠæ§ç¯ãããåçSQLã¯ãšãªã䜿çšããŠããŸãã
鲿¢ç: ããªãã¢ãã¹ããŒãã¡ã³ãã䜿çšããŠSQLã€ã³ãžã§ã¯ã·ã§ã³æ»æãé²ããŸããæå°æš©éã®ååãå®è£ ããå¿ èŠãªã¢ã¯ã»ã¹æš©ãæã€ãŠãŒã¶ãŒã«ã®ã¿æš©éãä»äžããŸãã
äŸ3ïŒéè¡ã¢ããªã±ãŒã·ã§ã³ïŒãšãŒãããïŒ
ã·ããªãª: ãã©ã³ã¹ã®éè¡ã䜿çšããéè¡ã¢ããªã±ãŒã·ã§ã³ãããã°ã€ã³ããã»ã¹ã§SQLã€ã³ãžã§ã¯ã·ã§ã³ã«å¯ŸããŠè匱ã§ããæ»æè ã¯SQLiã䜿çšããŠèªèšŒããã€ãã¹ãã顧客ã®éè¡å£åº§ã«ã¢ã¯ã»ã¹ããèªåèªèº«ã®å£åº§ã«ééããŸãã
è匱æ§: ãã°ã€ã³ãã©ãŒã ã®ãŠãŒã¶ãŒåãšãã¹ã¯ãŒããã£ãŒã«ãã®å ¥åæ€èšŒãäžååã§ãã
鲿¢ç: ãã¹ãŠã®SQLã¯ãšãªã«ããªãã¢ãã¹ããŒãã¡ã³ãã䜿çšããŸããã¯ã©ã€ã¢ã³ãåŽãšãµãŒããŒåŽã§å³æ Œãªå ¥åæ€èšŒãå®è£ ããŸãããã°ã€ã³ã«å€èŠçŽ èªèšŒãå®è£ ããŸãã
äŸ4ïŒå»çã·ã¹ãã ïŒãªãŒã¹ãã©ãªã¢ïŒ
ã·ããªãª: ãªãŒã¹ãã©ãªã¢ã®å»çæäŸè ãæ£è ã®èšé²ã管çããããã«Webã¢ããªã±ãŒã·ã§ã³ã䜿çšããŠããŸããæ»æè ã¯SQLã³ãŒããæ³šå ¥ããŠãæ£è ã®èšºæãæ²»çèšç»ãæè¬å±¥æŽãªã©ã®æ©å¯æ§ã®é«ãå»çæ å ±ãååŸããŸãã
è匱æ§: äžååãªå ¥åæ€èšŒãšãã©ã¡ãŒã¿åã¯ãšãªã®æ¬ åŠã
鲿¢ç: å ¥åæ€èšŒãæ¡çšããããªãã¢ãã¹ããŒãã¡ã³ããå®è£ ããã³ãŒããšããŒã¿ããŒã¹ã®è匱æ§ã宿çã«ç£æ»ããŸãããããã®ã¿ã€ãã®æ»æããä¿è·ããããã«Webã¢ããªã±ãŒã·ã§ã³ãã¡ã€ã¢ãŠã©ãŒã«ã䜿çšããŸãã
äŸ5ïŒãœãŒã·ã£ã«ã¡ãã£ã¢ãã©ãããã©ãŒã ïŒãã©ãžã«ïŒ
ã·ããªãª: ãã©ãžã«ã«æ ç¹ã眮ããœãŒã·ã£ã«ã¡ãã£ã¢ãã©ãããã©ãŒã ããã³ã³ãã³ãã¢ãã¬ãŒã·ã§ã³ã·ã¹ãã ã®SQLã€ã³ãžã§ã¯ã·ã§ã³è匱æ§ã«ããããŒã¿äŸµå®³ãçµéšããŸããæ»æè ã¯ãŠãŒã¶ãŒãããã¡ã€ã«ããŒã¿ãšãã©ã€ããŒãã¡ãã»ãŒãžã®å 容ãçã¿åºããŸãã
è匱æ§: ã³ã³ãã³ãã¢ãã¬ãŒã·ã§ã³ã€ã³ã¿ãŒãã§ãŒã¹ãããŠãŒã¶ãŒçæã³ã³ãã³ããããŒã¿ããŒã¹ã«æ¿å ¥ããåã«é©åã«ãµãã¿ã€ãºããŠããŸããã
鲿¢ç: ãã¹ãŠã®ãŠãŒã¶ãŒæåºã³ã³ãã³ãã®åŸ¹åºçãªãµãã¿ã€ãºãå«ããå ç¢ãªå ¥åæ€èšŒãå®è£ ããŸãããŠãŒã¶ãŒçæã³ã³ãã³ãã«é¢é£ãããã¹ãŠã®ããŒã¿ããŒã¹å¯Ÿè©±ã«ããªãã¢ãã¹ããŒãã¡ã³ããå®è£ ããWAFãå±éããŸãã
çµè«
SQLã€ã³ãžã§ã¯ã·ã§ã³ã¯äŸç¶ãšããŠããŒã¿ããŒã¹ã»ãã¥ãªãã£ã«å¯Ÿããé倧ãªè åšã§ãããäžçäžã®çµç¹ã«å€å€§ãªæå®³ãäžããå¯èœæ§ããããŸããSQLã€ã³ãžã§ã¯ã·ã§ã³æ»æã®æ§è³ªãçè§£ãããã®ã¬ã€ãã§æŠèª¬ãããã¹ããã©ã¯ãã£ã¹ãå®è£ ããããšã§ããªã¹ã¯ãå€§å¹ ã«äœæžã§ããŸããã»ãã¥ãªãã£ãžã®éå±€çã¢ãããŒããäžå¯æ¬ ã§ããããšãå¿ããªãã§ãã ãããå ¥åæ€èšŒãå®è£ ããããªãã¢ãã¹ããŒãã¡ã³ãã䜿çšããæå°æš©éã®ååãæ¡çšãã宿çãªç£æ»ã宿œããåŸæ¥å¡ããã¬ãŒãã³ã°ããŸããç°å¢ãç¶ç¶çã«ç£èŠããææ°ã®ã»ãã¥ãªãã£è åšãšè匱æ§ã«å¯Ÿå¿ãç¶ããŸããç©æ¥µçãã€å æ¬çãªã¢ãããŒãããšãããšã§ã貎éãªããŒã¿ãä¿è·ãã顧客ãå©å®³é¢ä¿è ã®ä¿¡é Œãç¶æããããšãã§ããŸããããŒã¿ã»ãã¥ãªãã£ã¯ç®çå°ã§ã¯ãªããèŠæãšæ¹åãç¶ããç¶ç¶çãªæ ã§ãã