ããã§ãå¥ã®æ¹æ³ã§ SQL ãæ³šå ¥ããŠã¿ãŸãã ããŒã¿ããŒã¹ããšã©ãŒ ã¡ãã»ãŒãžããããããç¶ãããã©ããã確èªããŠã¿ãŸãããã ãã®æ¹æ³ã¯ãé å»¶åŸ ã¡ããšåŒã°ããé å»¶èªäœã¯æ¬¡ã®ããã«èšè¿°ãããŸã: waitforé å»¶ 00:00:01'ã ããããã¡ã€ã«ããã³ããŒãããã©ãŠã¶ã®ã¢ãã¬ã¹ ããŒã«è²Œãä»ããŸãã

ããã¯ãã¹ãŠãäžæçãªãã©ã€ã³ã SQL ã€ã³ãžã§ã¯ã·ã§ã³ããšåŒã°ããŸãã ããã§ãã£ãŠããããšã¯ãã10 ç§åŸ
ã£ãŠãã ããããšèšã£ãŠããã ãã§ãã ãæ°ã¥ãããšæããŸãããå·Šäžã«ãæ¥ç¶äž...ããšããç¢æããããŸããã€ãŸãããã®ããŒãžã¯äœãããã®ã§ãããã? æ¥ç¶ãåŸ
æ©ãã10 ç§åŸã«æ£ããããŒãžãã¢ãã¿ãŒã«è¡šç€ºãããŸãã ãã®ããªãã¯ã䜿çšãããšãããã«ããã€ãã®è³ªåãã§ããããã«ããŒã¿ããŒã¹ã«èŠæ±ããŸããããšãã°ããŠãŒã¶ãŒã Joe ã®å Žåã10 ç§åŸ
ã€å¿
èŠããããŸãã ããã¯æããã ïŒ ãŠãŒã¶ãŒã dbo ã®å Žåãã10 ç§åŸ
ã¡ãŸãã ããã¯ãã©ã€ã³ã SQL ã€ã³ãžã§ã¯ã·ã§ã³ææ³ã§ãã
éçºè
ã¯ããããäœæãããšãã«ãã®è匱æ§ãä¿®æ£ããŠããªããšæããŸãã ãã㯠SQL ã€ã³ãžã§ã¯ã·ã§ã³ã§ããã以åã® SQL ã€ã³ãžã§ã¯ã·ã§ã³æ¹æ³ã®ããã«ãIDS ããã°ã©ã ã§ããããèªèããŸããã
ãã£ãšé¢çœãããšã詊ããŠã¿ãŸãããã IP ã¢ãã¬ã¹ãå«ããã®è¡ãã³ããŒãããã©ãŠã¶ã«è²Œãä»ããŸãã åºæ¥ãïŒ ããã°ã©ã ã® TCP ããŒãèµ€ã«ãªããããã°ã©ã 㯠2 ã€ã®ã»ãã¥ãªãã£äžã®è
åšã瀺ããŸããã

ããŠã次ã«äœãèµ·ãã£ãã®ãèŠãŠã¿ãŸãããã XP ã·ã§ã«ã«å¯Ÿããè
åšã XNUMX ã€ããããã XNUMX ã€ã®è
åšã¯ SQL ã€ã³ãžã§ã¯ã·ã§ã³ã®è©Šè¡ã§ãã Web ã¢ããªã±ãŒã·ã§ã³ã«å¯Ÿããæ»æã®è©Šã¿ã¯åèš XNUMX åãããŸããã

ããŠãããžãã¯ãæäŒã£ãŠãã ããã æ¹ããããŒã¿ ãã±ããããããIDS ã¯ããŸããŸãª XP ã·ã§ã«ã®æ¹ããã«å¯Ÿå¿ãããšè¿°ã¹ãŠããŸãã

äžã«é²ããšã27 鲿°ã³ãŒãã®è¡šã衚瀺ããããã®å³åŽã«ã¯ xp_cmdshell + &XNUMXping ãšããã¡ãã»ãŒãžã®ãã©ã°ããããããã¯æããã«åé¡ã§ãã

ããã§äœãèµ·ãã£ãã®ãèŠãŠã¿ãŸãããã SQL Server ã¯äœãããŸããã?

SQL ãµãŒããŒã¯ããããªãã¯ç§ã®ããŒã¿ããŒã¹ã®ãã¹ã¯ãŒããç¥ãããšãã§ããŸãããç§ã®ããŒã¿ããŒã¹ã®ã¬ã³ãŒãããã¹ãŠååŸããããšãã§ããŸããããããç§ã«å¯ŸããŠã³ãã³ããå®è¡ããããšã¯ãŸã£ããæãã§ããŸãããããã¯ãŸã£ããã¯ãŒã«ã§ã¯ãããŸãããããšèšããŸããã
ç§ãã¡ãããªããã°ãªããªãããšã¯ãããšã IDS ã XP ã·ã§ã«ã«è åšãå ±åãããšããŠãããã®è åšãç¡èŠãããããã«ããããšã§ãã SQL Server 2005 ãŸã㯠SQL Server 2008 ã䜿çšããŠããå ŽåãSQL ã€ã³ãžã§ã¯ã·ã§ã³ã®è©Šã¿ãæ€åºããããšããªãã¬ãŒãã£ã³ã° ã·ã¹ãã ã®ã·ã§ã«ãããã¯ãããäœæ¥ãç¶è¡ã§ããªããªããŸãã ãšãŠãè¿·æã§ãã ããã§ãç§ãã¡ã¯äœããã¹ãã§ããããïŒ ãµãŒããŒã«ææ ã蟌ããŠå°ããŠã¿ãŠãã ããã ããé¡ããããããã®ã¯ãããŒãé£ã¹ãŠãããã§ããïŒãã®ãããªããšãèšãã¹ãã§ããããïŒ ãããç§ããã£ãŠããããšã§ãããçå£ã«ããµãŒããŒã«éåžžã«äžå¯§ã«å°ããŸãã ããå€ãã®ãªãã·ã§ã³ãèŠæ±ããåæ§æãèŠæ±ããå¿ èŠãªããã·ã§ã«ã䜿çšã§ããããã«ããããã« XP ã·ã§ã«èšå®ã®å€æŽãèŠæ±ããŠããŸãã

IDS ããããæ€åºããããšãããããŸããããã§ã¯ãã§ã« 3 ã€ã®è
åšãææãããŠããŸãã

ãããèŠãŠãã ãã - ã»ãã¥ãªãã£ãã°ãçç ŽããŸãã! ããããã®ãã®ã食ãããŠããŠãã¯ãªã¹ãã¹ããªãŒã¿ããã§ããïŒ ã»ãã¥ãªãã£äžã®è
åšã¯ 27 åããããŸãã äžã
æ³ããã®ããã«ãŒãæãŸããŸãããæãŸããŸããïŒ

ç§ãã¡ã¯åœŒãç§ãã¡ã®ããŒã¿ãçãããšãå¿é
ããŠããŸãããã圌ãç§ãã¡ã®ãããã¯ã¹ãã§ã·ã¹ãã ã³ãã³ããå®è¡ã§ããå Žåãããã¯ãã§ã«æ·±å»ã§ãã Telnet ã«ãŒãã FTP ãåŒãããšãã§ããç§ã®ããŒã¿ãåŒãç¶ãããšãã§ããŸããããã¯çŽ æŽãããããšã§ãããããã«ã€ããŠã¯å¿é
ããŠããŸããããã ãããªãã«ç§ã®ãããã¯ã¹ãã®ã·ã§ã«ãåŒãç¶ãã§ã»ãããªãã®ã§ãã
æ¬åœã«æ°ã«ãªã£ãããšã«ã€ããŠè©±ããããšæããŸãã ç§ã¯çµç¹ã§åããŠãããé·å¹Žçµç¹ã®ããã«åããŠããŸãããã¬ãŒã«ãã¬ã³ããç§ã倱æ¥ããŠãããšæã£ãŠããã®ã§ããããèšããŸãã 圌女ã¯ãç§ãã¹ããŒãžã«ç«ã£ãŠãããã¹ãããŠããã ãã§ãããã¯ä»äºãšã¯èšããªããšèããŠããŸãã ããããç§ã¯ããèšããŸãããããããæ¬åœã«ããããã§ããç§ã¯ã³ã³ãµã«ã¿ã³ãã§ããã ãããéãã§ããç§ã¯èªåã®æèŠãçºèšãããã®å¯ŸäŸ¡ãšããŠãéãåãåããŸãã
ããèšãããŠãã ãããç§ãã¡ããã«ãŒã¯æ®»ãç Žãã®ã倧奜ãã§ããã®äžã§ãæ®»ã飲ã¿èŸŒããããšä»¥äžã®åã³ã¯ãããŸããã IDS ã¢ããªã¹ããã«ãŒã«ãäœæãããšããã·ã§ã« ãããã³ã°ããä¿è·ããæ¹æ³ã§ã«ãŒã«ãäœæããŠããããšãããããŸãã ããããããŒã¿æœåºã®åé¡ã«ã€ã㊠CIO ã«çžè«ãããšã100 ã€ã®éžæè¢ã«ã€ããŠèããããã«å§ããããã§ãããã XNUMX æéããã XNUMX åã®ãåããäœæããã¢ããªã±ãŒã·ã§ã³ããããšããŸãã ç§ã«ãšã£ãŠããã®ã¢ããªã±ãŒã·ã§ã³å ã®ãã¹ãŠã®ããŒã¿ã®ã»ãã¥ãªãã£ã確ä¿ããããšãšããããã¯ã¹ãã·ã§ã«ã®ã»ãã¥ãªãã£ã確ä¿ããããšã®ã©ã¡ããããéèŠã§ãã? ããã¯æ·±å»ãªè³ªåã§ã! ãã£ãšå¿é ãã¹ãããšã¯äœã§ããããïŒ

ãããã¯ã¹ãã·ã§ã«ãå£ããŠãããããšãã£ãŠã誰ããã¢ããªã±ãŒã·ã§ã³ã®å
éšåäœã«ã¢ã¯ã»ã¹ããããšãå¿
ãããæå³ããããã§ã¯ãããŸããã ã¯ãããã®å¯èœæ§ã¯ååã«ãããŸãããŸã èµ·ãã£ãŠããªããšããŠããããã«ãããªãå¯èœæ§ããããŸãã ãã ããå€ãã®ã»ãã¥ãªãã£è£œåã¯ãæ»æè
ããããã¯ãŒã¯ãåŸåŸããããšãåæã«æ§ç¯ãããŠããããšã«æ³šæããŠãã ããã ãããã£ãŠã圌ãã¯ã³ãã³ãã®å®è¡ãã³ãã³ãã®æ³šå
¥ã«æ³šæãæã£ãŠããŸãããããã¯é倧ãªããšã§ããããšã«æ³šæããå¿
èŠããããŸãã 圌ãã¯ãäºçްãªè匱æ§ãéåžžã«åçŽãªã¯ãã¹ãµã€ã ã¹ã¯ãªããã£ã³ã°ãéåžžã«åçŽãª SQL ã€ã³ãžã§ã¯ã·ã§ã³ãææããŠããŸãã 圌ãã¯è€éãªè
åšãæå·åãããã¡ãã»ãŒãžãªã©ã«ã¯é¢å¿ããããŸããã ãã¹ãŠã®ã»ãã¥ãªãã£è£œåã¯ãéšé³ãæ¢ããŠããããã¬ã€ã¬ã€ããšããé³ãæ¢ããŠãããè¶³éŠã«äœããåã¿ä»ãã®ãæ¢ããããšæã£ãŠãããšèšããŸãã ã»ãã¥ãªãã£è£œåãæ±ããšãã«ç§ãåŠãã ããšã¯æ¬¡ã®ãšããã§ãã ã»ãã¥ãªãã£è£œåã賌å
¥ããå¿
èŠãããã©ãã¯ãããã¯é転ããå¿
èŠããããŸããã ãã¯ãããžãŒãçè§£ããæèœã§çç·Žãã人æãå¿
èŠã§ãã ã¯ããç¥æ§ãçããïŒ ç§ãã¡ã¯ãããã®åé¡ã«äœçŸäžãã«ã泚ã蟌ã¿ãããããŸãããããã®åéã§åããããšããã人ã¯å€ããäžåžãåºåãèŠããšããã«ããããæã«å
¥ããªããã°ïŒããšå«ã³ãªããåºã«é§ã蟌ãããšãç¥ã£ãŠããŸãã ããããå®éã«ã¯ããã¯å¿
èŠãããŸãããç§ãã¡ã®èåŸã«ããæ··ä¹±ã解決ããå¿
èŠãããã ãã§ãã ãããä»åã®å
¬æŒã®åæã§ããã
é«åºŠãªã»ãã¥ãªãã£ç°å¢ã¯ãä¿è·ã¡ã«ããºã ãã©ã®ããã«æ©èœãããã®ã«ãŒã«ãçè§£ããããã«å€ãã®æéãè²»ãããŸããã ä¿è·ã®ã¡ã«ããºã ãçè§£ããã°ãä¿è·ãåé¿ããããšã¯é£ãããããŸããã ããšãã°ãç¬èªã®ãã¡ã€ã¢ãŠã©ãŒã«ã§ä¿è·ãããŠãã Web ã¢ããªã±ãŒã·ã§ã³ããããŸãã èšå®ããã«ã®ã¢ãã¬ã¹ãã³ããŒããŠãã©ãŠã¶ã®ã¢ãã¬ã¹ ããŒã«è²Œãä»ããèšå®ã«ç§»åããŠã¯ãã¹ãµã€ã ã¹ã¯ãªããã£ã³ã°ãé©çšããŠã¿ãŸãã

ãã®çµæãè
åšã«é¢ãããã¡ã€ã¢ãŠã©ãŒã« ã¡ãã»ãŒãžãåãåããŸãã - ãããã¯ãããŸããã

ããã¯ãŸãããšæããŸãããåæããŸããïŒ ããªãã¯ã»ãã¥ãªãã£è£œåã«çŽé¢ããŠããŸãã ããããæ¬¡ã®ãããªããšã詊ããŠã¿ããã©ãã§ãããã: ãã©ã¡ãŒã¿ Joe'+OR+1='1 ãæååã«å
¥ããŸã

ã芧ã®ãšãããããŸããããŸããã ééã£ãŠããå Žåã¯èšæ£ããŠãã ããããã ããSQL ã€ã³ãžã§ã¯ã·ã§ã³ãã¢ããªã±ãŒã·ã§ã³ ãã¡ã€ã¢ãŠã©ãŒã«ãç Žãã®ãèŠãŠããŸããã ããã§ãã»ãã¥ãªãã£äŒç€Ÿãèšç«ããããšèããŠããœãããŠã§ã¢ ã¡ãŒã«ãŒã®åžœåããã¶ã£ãŠã¿ãŸãããã ä»ãç§ãã¡ã¯æªãäœçŸããŠããŸããããã¯é»ãåžœåã ããã§ãã ç§ã¯ã³ã³ãµã«ã¿ã³ããªã®ã§ããœãããŠã§ã¢å¶äœè
ãšååããŠè¡ãããšãã§ããŸãã
æ°ããäŸµå ¥æ€ç¥ã·ã¹ãã ãæ§ç¯ããŠå±éãããã®ã§ãæ¹ããæ€ç¥ãã£ã³ããŒã³ãéå§ããŸãã Snort ã¯ãªãŒãã³ ãœãŒã¹è£œåãšããŠãæ°åäžã®äŸµå ¥è åšã®ã·ã°ããã£ãå«ãã§ããŸãã ç§ãã¡ã¯å«ççã«è¡åããå¿ èŠãããããããããã®çœ²åãä»ã®ã¢ããªã±ãŒã·ã§ã³ããçãã§ã·ã¹ãã ã«æ¿å ¥ããããšã¯ãããŸããã ç§ãã¡ã¯ãã 座ã£ãŠããããããã¹ãŠæžãçŽãã€ããã§ã - ãããããããã£ã ããžã§ãŒããã£ã¡ã«æ¥ãŠãããã 100 ã®çœ²åããã¹ãŠãã£ãšèª¿ã¹ãŠã¿ãŸãããã
è匱æ§ã¹ãã£ããŒãäœæããå¿
èŠããããŸãã èªåèåŒ±æ§æ€çŽ¢ããŒã«ã§ãã Nessus ã«ã¯ãè匱æ§ããã§ãã¯ãã 80 ä»¶ãã®çœ²åãšã¹ã¯ãªãããããããšã¯ãåç¥ã§ãããã ç§ãã¡ã¯åã³å«ççã«è¡åããããã°ã©ã å
ã®ãã¹ãŠãå人çã«æžãçŽããŸãã
ããžã§ãŒãããªãã¯ããããã¹ãŠã®ãã¹ãã Mod Security ã Snort ãªã©ã®ãªãŒãã³ ãœãŒã¹ ãœãããŠã§ã¢ã§è¡ã£ãŠããŸãããä»ã®ãã³ããŒã®è£œåãšã©ãããã䌌ãŠããŸãã?ããšäººã
ã¯ç§ã«å°ããŸãã ç§ã¯åœŒãã«ããçããŸãããå
šç¶äŒŒãŠãªããïŒã ãã³ããŒã¯ãªãŒãã³ãœãŒã¹ã®ã»ãã¥ãªãã£è£œåããäœããçãããšã¯ãªãã®ã§ãããããã¹ãŠã®ã«ãŒã«ãèªåãã¡ã§äœæããŸãã
ãªãŒãã³ãœãŒã¹è£œåã䜿çšããã«ç¬èªã®ã·ã°ããã£ã𿻿æååãæ©èœãããããšãã§ããã°ãããã¯å€§ããªãã£ã³ã¹ãšãªããŸãã æ£ããæ¹åã«é²ãã§åçšè£œåãšç«¶äºã§ããªãå Žåã¯ãèªåã®åéã§ã®ç¥å床ãé«ããã®ã«åœ¹ç«ã€ã³ã³ã»ãããèŠã€ããå¿ èŠããããŸãã
ç§ãé ã飲ãã§ããããšã¯èª°ããç¥ã£ãŠããŸãã ç§ããé ã飲ãçç±ãæããŠãã ããã 人çã§ãœãŒã¹ã³ãŒãç£æ»ãè¡ã£ãããšããã人ãªããééããªãé ã£æãã§ããããä¿¡ããŠãã ããããã®åŸã¯é£²ã¿å§ããã§ãããã

ãããã£ãŠãç§ãã¡ã®ãæ°ã«å
¥ãã®èšèªã¯ C++ ã§ãã ãã®ããã°ã©ã ãèŠãŠã¿ãŸããã - Web Knight 㯠Web ãµãŒããŒçšã®ãã¡ã€ã¢ãŠã©ãŒã« ã¢ããªã±ãŒã·ã§ã³ã§ãã ããã©ã«ãã®äŸå€ããããŸãã è峿·±ãããšã«ããã®ãã¡ã€ã¢ãŠã©ãŒã«ãå±éããŠããOutlook Web Access ããã¯ä¿è·ãããŸããã

çŽ æŽãããïŒ ããã¯ãå€ãã®ãœãããŠã§ã¢ ãã³ããŒãé©åãªèª¿æ»ãååã«è¡ããã«ãäžéšã®ã¢ããªã±ãŒã·ã§ã³ããã«ãŒã«ãåŒãåºããŠèªç€Ÿã®è£œåã«çµã¿èŸŒãã§ããããã§ãã ãããã£ãŠããããã¯ãŒã¯ ãã¡ã€ã¢ãŠã©ãŒã« ã¢ããªã±ãŒã·ã§ã³ãå°å
¥ãããšããWeb ã¡ãŒã«ã«é¢ãããã¹ãŠã®ããšãééã£ãŠãããšæããŸãã ã»ãšãã©ãã¹ãŠã® Web ã¡ãŒã«ãããã©ã«ãã®ã»ãã¥ãªãã£ã«éåããŠããããã§ãã ã·ã¹ãã ã³ãã³ããå®è¡ããWeb äžã§ LDAP ãŸãã¯ãã®ä»ã®ãŠãŒã¶ãŒ ããŒã¿ããŒã¹ ã¹ãã¢ã«ã¯ãšãªãå®è¡ãã Web ã³ãŒãããããŸãã
æããŠãã ãããã©ã®ææã§ãã®ãããªãã®ãå®å šã§ãããšèããããã§ãããã? èããŠã¿ãŠãã ãããOutlook Web Access ãéããŠãb Ctrl+K ãæŒãããŠãŒã¶ãŒãªã©ãæ€çŽ¢ããActive Directory ã Web ããçŽæ¥ç®¡çãããsquirrel mailãã Horde ãªã©ã䜿çšããŠããå Žå㯠Linux äžã§ã·ã¹ãã ã³ãã³ããå®è¡ããŸããäœãä»ã®ãã®ã ãããã® eval ããã®ä»ã®çš®é¡ã®å®å šã§ãªãæ©èœããã¹ãŠåãåºãããšã«ãªããŸãã ãããã£ãŠãå€ãã®ãã¡ã€ã¢ãŠã©ãŒã«ã¯ã»ãã¥ãªãã£è åšã®ãªã¹ãããããããé€å€ããŠããŸããããã«ã€ããŠã¯ãœãããŠã§ã¢ã®è£œé å ã«åãåãããŠã¿ãŠãã ããã
Web Knight ã¢ããªã±ãŒã·ã§ã³ã«æ»ããŸãããã ããããã¹ãŠã® IP ã¢ãã¬ã¹ç¯å²ãã¹ãã£ã³ãã URL ã¹ãã£ããŒããå€ãã®ã»ãã¥ãªã㣠ã«ãŒã«ãçã¿ãŸããã ãããŠãããããã¹ãŠã®ã¢ãã¬ã¹ç¯å²ãç§ã®è£œåããé€å€ãããŠããã®ã§ãã?

ãããã®ã¢ãã¬ã¹ããããã¯ãŒã¯ã«ã€ã³ã¹ããŒã«ããã人ã¯ããŸãã? ãããã¯ãŒã¯ããããã®ã¢ãã¬ã¹ã§å®è¡ããŸãã? ã¯ãããããã§ããã ããŠããã®ããã°ã©ã ãäžã«ã¹ã¯ããŒã«ããŠããã®ãã¡ã€ã¢ãŠã©ãŒã«ãå®è¡ããããªããã®ä»ã®ããšãèŠãŠã¿ãŸãããã
圌ãã¯ã1999ããšåŒã°ããWeb ãµãŒããŒãéå»ã®ãã®ã«ããããšèããŠããŸãã /scriptsã/iishelpãmsads ãšãããã ããªãããšãèŠããŠãã人ã¯ããŸãã? ããããããã®ãããªãã®ããããã³ã°ããããšãã©ãã»ã©æ¥œããã£ãããæãããæãåºã人ãããã§ãããã ãèŠããŠãããŠãã ãããç§ãã¡ãã©ãã ãåã«ãµãŒããŒããæ®ºãããããããã¯ã¯ãŒã«ã§ããïŒãã

ããŠããããã®äŸå€ãèŠããšãmsadsãããªã³ã¿ãŒãiisadmpwd ãªã©ã仿¥ã§ã¯èª°ãå¿
èŠãšããªãããããã¹ãŠã®ããšãå®è¡ã§ããããšãããããŸãã å®è¡ãèš±å¯ãããŠããªãã³ãã³ãã«ã€ããŠã¯ã©ãããã°ããã§ãããã?

ãããã¯ãarpãatãcaclsãchkdskãcipherãcmdãcom ã§ãã ããããåæãããšããããããã®ãµãŒããŒãã©ã®ããã«ä¹ã£åã£ããèŠããŠããã ããããã®é ã®ããšãèŠããŠããã ããããšæã®æãåºã«å§åãããŸãã?
ãããããããæ¬åœã«è峿·±ãç¹ã§ããããã§ WMIC ãèŠã人ãããã㯠PowerShell ãèŠã人ã¯ããŸãã? ããŒã«ã« ã·ã¹ãã äžã§ã¹ã¯ãªãããå®è¡ããããšã«ãã£ãŠæ©èœããæ°ããã¢ããªã±ãŒã·ã§ã³ããããšæ³åããŠãã ãããWindows Server 2008 ãå®è¡ãããã®ã§ããããã¯ææ°ã®ã¹ã¯ãªããã§ããWindows çšã«èšèšãããã«ãŒã«ã§ãããä¿è·ãããšããçŽ æŽãããä»äºãããã€ããã§ããæ¬¡åããã³ããŒã Web ã¢ããªã±ãŒã·ã§ã³ãæã£ãŠããªãã®ãšããã«æ¥ããšãã¯ãã管çãããã PowerShell ã³ãã³ãã®å®è¡ãªã©ã«ã€ããŠã¯çšæããŸããããä»ã®ãã¹ãŠã®ããšã¯ç¢ºèªããŸãããã DotNET ã®æ°ããããŒãžã§ã³ãæŽæ°ããŠäœ¿çšããŸãã? ããããããããã¹ãŠã¯ããã©ã«ãã§ã»ãã¥ãªãã£è£œåã«å«ãŸããŠããã¯ãã§ãã

次ã«ã話ãããã®ã¯ãè«çç誀ãã«ã€ããŠã§ãã 192.168.2.6 ã«è¡ããŸãããã ããã¯åã®ãã®ãšã»ãŒåãã¢ããªã±ãŒã·ã§ã³ã§ãã

ããŒãžãäžã«ã¹ã¯ããŒã«ã㊠[ãåãåãã] ãªã³ã¯ãã¯ãªãã¯ãããšãè峿·±ãããšã«æ°ã¥ããããããŸããã

ç§ããã€ãè¡ã£ãŠãã䟵å
¥ãã¹ãæ¹æ³ã® XNUMX ã€ã§ããããåãåãããã¿ãã®ãœãŒã¹ ã³ãŒããèŠããšã次ã®è¡ãããããšã«æ°ã¥ãã§ãããã

èããŠã¿ãŠãã ããïŒ ãããèŠãå€ãã®äººãããããïŒããšèšã£ããšèããŠããŸãã ç§ã¯ãã€ãŠãããšãã°åäžé·è
ã®éè¡ã®äŸµå
¥ãã¹ããè¡ã£ãããšããããŸãããããã§ãåæ§ã®ããšã«æ°ã¥ããŸããã ãããã£ãŠãSQL ã€ã³ãžã§ã¯ã·ã§ã³ãã¯ãã¹ãµã€ã ã¹ã¯ãªããã£ã³ã°ã¯å¿
èŠãããŸãããéèŠãªã®ã¯ãã®ã¢ãã¬ã¹ ããŒã§ãã

ã€ãŸããèªåŒµããããšãªããéè¡ã¯ãããã¯ãŒã¯å°éå®¶ãšãŠã§ãæ€æ»å®ã®äž¡æ¹ãæã£ãŠãããšç§ãã¡ã«èšããŸãããã圌ãã¯äœãçºèšããŸããã§ããã ã€ãŸãããã©ãŠã¶ãéããŠããã¹ã ãã¡ã€ã«ãéããŠèªãããšãã§ããã®ãæ£åžžã§ãããšèããããŠããŸããã
ã€ãŸãããã¡ã€ã« ã·ã¹ãã ããçŽæ¥ãã¡ã€ã«ãèªã¿åãããšãã§ããŸãã å瀟ã®ã»ãã¥ãªã㣠ããŒã ã®è²¬ä»»è ã¯ç§ã«ããã¯ããã¹ãã£ããŒã® XNUMX ã€ããã®è匱æ§ãçºèŠããŸãããã軜埮ãªãã®ã ãšèããŸãããããšèšããŸããã ããã«å¯ŸããŠç§ã¯ããåãã£ããã¡ãã£ãšåŸ ã£ãŠããšçããŸããã ã¢ãã¬ã¹ããŒã« filename=../../../../boot.ini ãšå ¥åãããšããã¡ã€ã« ã·ã¹ãã ã®ããŒã ãã¡ã€ã«ãèªã¿åãããšãã§ããŸããã

ããã«å¯ŸããŠåœŒãã¯ãããããããããããããããããã¯éèŠãªãã¡ã€ã«ã§ã¯ãããŸããããšèšããŸããã ç§ã¯çããŸãããããã㯠Server 2008 ã§ããã? 圌ãã¯ãã¯ãã圌ã§ãããšèšããŸããã ç§ã¯èšããŸããããã®ãµãŒããŒã«ã¯ãµãŒããŒã®ã«ãŒã ãã£ã¬ã¯ããªã«èšå®ãã¡ã€ã«ããããŸããã? ãããã§ãããšåœŒãã¯çããŸãã ãããããããæ»æè
ãããããã£ããã©ããªãã ããããšç§ã¯èšããã¢ãã¬ã¹ ããŒã« filename=web.config ãšå
¥åããŸããã 圌ãã¯ããèšããŸã - ããã§ãã¢ãã¿ãŒã«äœãæ ããªãã®ã§ããïŒ

ã¢ãã¿ãŒãå³ã¯ãªãã¯ããŠãããŒãžã³ãŒãã衚瀺ããªãã·ã§ã³ãéžæãããã©ããªãã§ãããã? ãããŠããã§äœãèŠã€ããã§ããããïŒ ãéèŠãªããšã¯äœããªããïŒ ãµãŒããŒç®¡çè
ã®ãã¹ã¯ãŒãã衚瀺ãããŸãã

ããã§ãããã«ã¯åé¡ããªããšèšãã®ã§ããïŒ
ããããç§ã®ãæ°ã«å ¥ãã®éšåã¯æ¬¡ã®éšåã§ãã ããã¯ã¹å ã§ã³ãã³ããå®è¡ãããããšã¯ã§ããŸããããWeb ãµãŒããŒã®ç®¡çè ãã¹ã¯ãŒããšããŒã¿ããŒã¹ãçã¿ãããŒã¿ããŒã¹å šäœã調ã¹ãããŒã¿ããŒã¹ãšã·ã¹ãã é害ã«é¢ãããã®ããã¹ãŠåãé€ãããã¹ãŠãæã¡åž°ãããšã¯ã§ããŸãã ããã¯ãæªè ããããã仿¥ã¯çŽ æŽãããæ¥ã ããšèšã£ãå Žåã§ãã

å®å
šè£œåãç
æ°ã«ãªããªãããã«ããŠãã ããã ã»ãã¥ãªãã£è£œåã§ç
æ°ã«ãªããªãããã«ããŸãããã äœäººãã®ãªã¿ã¯ãèŠã€ããŠãã¹ã¿ãŒãã¬ãã¯ã®èšå¿µåããã¹ãŠæž¡ããèå³ãæã£ãŠããããäžç·ã«ããŠãããããã«å§ããŸãããããªããªããæ¯æ¥ã·ã£ã¯ãŒã济ã³ãªããªã¿ã¯èã奎ãããããããªãã®ãããã¯ãŒã¯ã次ã®ããã«æ©èœããã人ãã¡ã ããã§ãã ãããã®äººã
ã¯ãã»ãã¥ãªãã£è£œåãé©åã«æ©èœããããæ¯æŽããŸãã
æããŠãã ããããããããã®ã¹ã¯ãªãããæ¥ãã§å°å·ããå¿ èŠããã!ããšåžžã«èšã人ãšãåãéšå±ã«é·ãéæ»åšã§ãã人ãããŸããããŸããåžžã«ãã®äœæ¥ã§å¿ãã人ã¯èª°ã§ãã? ããããã»ãã¥ãªãã£è£œåãæ©èœãããã«ã¯äººæãå¿ èŠã§ãã
ç¹°ãè¿ãã«ãªããŸãããã»ãã¥ãªãã£è£œåã¯æãã§ãããªããªããã©ã€ãã¯ãã€ãééã£ãŠããŠãåžžã«ã²ã©ãããšãããŠããã ãã§ãã»ãã¥ãªãã£ãæäŸããŠããªãã ãã§ãã å€ããå°ãªããæ£åžžã«åäœãããããã«å¿ èŠãªç®æããã©ã€ããŒã§åŸ®èª¿æŽããå¿ èŠããªããåªããã»ãã¥ãªãã£è£œåãç§ã¯èŠãããšããããŸããã ããã¯æªãããšã§ãããšããèšå€§ãªã«ãŒã«ã®ãªã¹ãã«ãããŸãããããã ãã§ãã
çãããã»ãã¥ãªãã£ãããªãã¯ããã¯ãªã©ã®æè²ã«æ³šç®ããŠã»ããã®ã§ããã»ãã¥ãªãã£åé¡ã«é¢ããç¡æã®ãªã³ã©ã€ã³ ã³ãŒã¹ãããããããããã§ãã Python ãåŠã³ãã¢ã»ã³ããªãåŠã³ãWeb ã¢ããªã±ãŒã·ã§ã³ã®ãã¹ããåŠã³ãŸãã

ãããã¯ãŒã¯ãä¿è·ããã®ã«æ¬åœã«åœ¹ç«ã€ãã®ã¯æ¬¡ã®ãšããã§ãã è³¢ã人ã¯ãããã¯ãŒã¯ãå®ããŸããããããã¯ãŒã¯è£œåã¯å®ããŸããã ä»äºã«æ»ã£ãŠããã£ãšè³¢ã人æã®ããã«ãã£ãšäºç®ãå¿
èŠã ãšäžåžã«äŒããŠãã ãããä»ã屿©ã§ããããšã¯ããã£ãŠããŸããããšã«ãã人ã
ãæè²ããããã«ãã£ãšãéãå¿
èŠã ãšäŒããŠãã ããã 補åã賌å
¥ããŠãããã®è£œåãé«äŸ¡ã§ãããšããçç±ã§ãã®äœ¿ç𿹿³ã®ã³ãŒã¹ã賌å
¥ããªãå Žåã補åã®äœ¿ç𿹿³ã人ã
ã«æããã€ããããªãã®ã§ããã°ããããããªã補åã賌å
¥ããã®ã§ãããã?
ç§ã¯å€ãã®ã»ãã¥ãªãã£è£œåãã³ããŒã§åããŠããã人çã®ã»ãŒãã¹ãŠããããã®è£œåã®å®è£ ã«è²»ãããŠããŸãããããã ããªã補åããã¹ãŠã€ã³ã¹ããŒã«ããŠå®è¡ããŠããããããããã¯ãŒã¯ ã¢ã¯ã»ã¹å¶åŸ¡ãªã©ã«ããããããŠããŸãã ããæ¥ãã¯ã©ã€ã¢ã³ãã®ãšãããžè¡ããšãã¯ã©ã€ã¢ã³ã㯠EAP ãããã³ã«ã« 802.1x æšæºãå®è£ ããããšèããŠãããããããŒãããšã« MAC ã¢ãã¬ã¹ãšã»ã«ã³ã㪠ã¢ãã¬ã¹ãå¿ èŠã§ããã ç§ã¯æ¥ãŠããããæªãããšã«æ°ã¥ããæ¯ãè¿ã£ãŠããªã³ã¿ãŒã®ãã¿ã³ãæŒãå§ããŸããã ãåç¥ã®ãšãããããªã³ã¿ã¯ãã¹ãŠã® MAC ã¢ãã¬ã¹ãš IP ã¢ãã¬ã¹ãå«ããããã¯ãŒã¯æ©åšãã¹ã ããŒãžãå°å·ã§ããŸãã ããããããªã³ã¿ãŒã 802.1x æšæºããµããŒãããŠããªãããšã倿ãããããé€å€ããå¿ èŠããããŸãã
次ã«ãããªã³ã¿ãŒã®ãã©ã°ãæããã©ãããããã® MAC ã¢ãã¬ã¹ãããªã³ã¿ãŒã® MAC ã¢ãã¬ã¹ã«å€æŽããŠã©ããããããæ¥ç¶ãããã®é«äŸ¡ãª MAC ãœãªã¥ãŒã·ã§ã³ããã€ãã¹ããŸãããèããŠã¿ãŠãã ããã ã§ã¯ã人ãããããæ©åšãåã«ããªã³ã¿ã VoIP é»è©±ãšããŠåœè£ ã§ãããšãããããã® MAC ãœãªã¥ãŒã·ã§ã³ã¯ç§ã«ãšã£ãŠäœã®åœ¹ã«ç«ã€ã§ãããã?
ãããã£ãŠã仿¥ã®ç§ã«ãšã£ãŠäŸµå ¥ãã¹ããšã¯ãã¯ã©ã€ã¢ã³ããè³Œå ¥ããã»ãã¥ãªãã£è£œåãçè§£ããããã«æéãè²»ããããšã§ãã çŸåšãç§ããããã¬ãŒã·ã§ã³ãã¹ããè¡ã£ãŠããéè¡ã«ã¯ãHIPSãNIPSãLAUGTHSãMACSããã®ä»ã®ã²ã©ãé åèªããããããããŸãã ããããç§ã¯ãããã®è£œåãäœãããããšããŠããã®ãããããŠã©ã®ããã«ãããããããšããŠããã®ããçè§£ããããšããŠããŸãã ãããŠã圌ããä¿è·ãæäŸããããã«ã©ã®ãããªæ¹æ³è«ãšããžãã¯ã䜿çšããŠããããçè§£ããã°ããããåé¿ããããšã¯ãŸã£ããé£ãããããŸããã
ç§ã®ãæ°ã«å
¥ãã®è£œåã¯ããã®ãŸãŸã«ããŠãããŸãããMS 1103 ãšåŒã°ããŸããããã¯ãHIPSããã¹ã䟵å
¥é²åŸ¡ã·ã°ããã£ããŸãã¯ãã¹ã䟵å
¥é²åŸ¡ã·ã°ããã£ãã¹ãã¬ãŒãããã©ãŠã¶ããŒã¹ã®ãšã¯ã¹ããã€ãã§ãã å®éããã㯠HIPS 眲åããã€ãã¹ããããšãç®çãšããŠããŸãã 宿Œããã®ã«æéãããããããªãã®ã§ãã©ã®ããã«æ©èœãããã¯ç€ºããŸãããããã®ä¿è·ãåé¿ããã®ã«éåžžã«åªããæ©èœãåããŠããã®ã§ããã²æ¡çšããŠããã ããããšæããŸãã
ãªãŒã±ãŒãã¿ããªãããåºçºãããã

ããã€ãã®åºå ð
ãã€ãã宿æ³ããã ãããããšãããããŸãã ç§ãã¡ã®èšäºãæ°ã«å ¥ã£ãŠããŸãã? ãã£ãšè峿·±ãã³ã³ãã³ããèŠããã§ãã? 泚æããããå人ã«å§ãããããŠç§ãã¡ããµããŒãããŠãã ããã , åœç€Ÿãããªãã®ããã«çºæããããšã³ããªãŒã¬ãã«ã®ãµãŒããŒã®ãŠããŒã¯ãªé¡äŒŒç©ã§ãã (RAID1 ããã³ RAID10ãæå€§ 24 ã³ã¢ãæå€§ 40GB DDR4 ã§å©çšå¯èœ)ã
ã¢ã ã¹ãã«ãã ã®ãšã¯ã€ãã¯ã¹ Tier IV ããŒã¿ã»ã³ã¿ãŒã§ã¯ Dell R730xd ã 2 åå®ã? ããã ã ãªã©ã³ãã§ïŒ Dell R420 - 2x E5-2430 2.2Ghz 6C 128GB DDR3 2x960GB SSD 1Gbps 100TB - 99 ãã«ãã! ã«ã€ããŠèªã
åºæïŒ habr.com
