ãã¹ã¯ãŒããçãŸããªããã°
æ å ±æŒãããªã©ãçºçããããšã§ãã¹ã¯ãŒããæµåºããŠããŸã£ãå Žåãäœãæãã®ã ãããïŒ
åœç¶ããã®æµåºãããã¹ã¯ãŒããæªçšããŠäžæ£ã¢ã¯ã»ã¹ãããŠããŸãå¯èœæ§ãããããããŠããã¹ã¯ãŒããå¥ã®ãŠã§ããµã€ãããŠã§ããµãŒãã¹ã§ã䜿ãåããŠããå Žåããã¡ããžãäžæ£ã¢ã¯ã»ã¹ãããŠããŸãå¯èœæ§ãããã
æ¡å€ãããã人ãå€ããã®ã ããããã¹ã¯ãŒããçãã ããã©ããã§çãŸãããã¹ã¯ãŒããè²·ã£ãæªæããè ãã¡ã¯ãä»ã§ãå©çšã§ããªããã®ããšä»ã®ãŠã§ããµã€ãããŠã§ããµãŒãã¹ã«ãããã®ãã¹ã¯ãŒããå ¥åããŠäžæ£ã¢ã¯ã»ã¹ã詊ã¿ãããšãå€ãããã®ãããªæ»æãããã¹ã¯ãŒãã¹ãã¬ãŒæ»æããšãåŒãã§ããã
ãã¹ã¯ãŒããçãŸããŠããŸãããšã§ãäºæ¬¡çã«ãäžæ¬¡çã«ãè¢«å®³ãæ¡å€§ããå¯èœæ§ãããããã ãã§ã¯ããã¹ã¯ãŒããçãŸããªããã°ãäžæ£ã¢ã¯ã»ã¹ãããããšãé²ãããšãã§ããã®ãïŒ
æ®å¿µãªããããã¹ã¯ãŒããçãŸããªããŠãäžæ£ã¢ã¯ã»ã¹ãã§ããŠããŸããšããããããªè©±ãä»åã¯ããŠããããã
ãµã€ããŒæ»æã®7å²
ãã¹ã¯ãŒããçãŸããªããŠãäžæ£ã¢ã¯ã»ã¹ã§ããŠããŸãæ»æã ãSQLã€ã³ãžã§ã¯ã·ã§ã³ããšåŒã°ããŠããæ»æã®ããšã ã
ãµã€ããŒæ»æã®7å²ã¯SQLã€ã³ãžã§ã¯ã·ã§ã³ã«ãããã®ã ãšããããŒã¿*1ãããã®ã§ããã®ååãç®ã«ãããããšã®ããæ¹ãå€ãã®ã§ã¯ãªãã ãããã倧æããŒã¿ã«ãµã€ããå šç±³ã代衚ããå°å£²åºãäžççã«æåãªã²ãŒã äŒç€Ÿãªã©ã被害ã«éã£ãäºä»¶ã§ã¯ãããããã®ææ³ãçšããããŠããã
ååããããã³ã°ãšã¯å®ç§ã§ã¯ãªããšãããèŠã€ãåºããŠãããã«å¯ŸããŠè©Šã¿ããšãã話ãããããã®SQLã€ã³ãžã§ã¯ã·ã§ã³ã§ãåæ§ãé¡§å®¢ã®æ å ±ãªã©ãèšé²ãããããŒã¿ããŒã¹ã«èšå®ã®äžåãäžå ·åãããã°ãããŒã¿ããŒã¹ãæäœããããã®SQLãšããèšèªã«å·¥å€«ãããããšã§äžæ£æäœãããŠããŸããã¡ãªã¿ã«ãSQLãšããåç§°ã«ã€ããŠè«žèª¬ãããã®ã®ããäœãã®ç¥èªã§ã¯ãªãããšæšæºSQLèŠæ Œã«ã¯èšãããŠããã
éæ³ã®æåå
ããŠããã®SQLã€ã³ãžã§ã¯ã·ã§ã³ã§ããããã©ã®ãããªå Žé¢ã§çšããããšãã§ããã®ã ãããã
äŸãã°ãŠã§ããµã€ãã«ãã°ã€ã³ããç»é¢ãã€ã¡ãŒãžããŠã¿ãŠããã ããããããã«ã¯ããŠãŒã¶åãå ¥åããããã¯ã¹ãšããã¹ã¯ãŒããå ¥åããããã¯ã¹ãšãããã
ãã®æããŠãŒã¶åãšãã¹ã¯ãŒãã®çµã¿åãããæ£ç¢ºã«ç¥ã£ãŠããªããã°ãã°ã€ã³ããããšã¯ã§ããªããæ¬äººãªã®ãããããšãäœããã®ææ®µãçšããŠãã¹ã¯ãŒããå ¥æããã®ãã¯å¥ã«ããŠã ã
ãšãããããã®SQLã€ã³ãžã§ã¯ã·ã§ã³ãšããæå£ãçšããããšãã§ããã°ããŠãŒã¶åãšãã¹ã¯ãŒãã®çµã¿åãããç¥ããªããã£ãŠäžæ£ã¢ã¯ã»ã¹ãã§ããŠããŸããããã§ã¯ãå ·äœçã«ã©ã®ããã«ããã°è¯ãã®ã ãããã
ããã§ã¯äžäŸãšããŠã
ãâ or 1=1 ?
ãšãã£ãæååãçšããŠSQLã€ã³ãžã§ã¯ã·ã§ã³ã仿ããå Žé¢ãèããŠã¿ãããåœç¶ãããã¯ç¹å®ã®äžåãããéã«ã®ã¿æå¹ãªæååã§ãããç¡éç¢é±ãšãã®æååãé£åŒãããšããã§åŸããããã®ã¯3ç¡ãã
ããããç¹å®ã®æ¡ä»¶ãã¯ãŸãã°éæ³ã®æååãšãªãã
ãã¹ã¯ãŒããçãŸããªããŠã
ããã§ã¯ããã®éæ³ã®æååãå®éã«äœ¿ã£ãŠã¿ããããã ããç¹å®ã®äžåãæ±ãããŠã§ããµã€ãã§ã®ã¿æå¹ãšããåæã ïŒã¡ãªã¿ã«ãæèã3åãããã³ã°ãã§ã¯å®éã«ãã¹ãç°å¢ãçšããŠå®è·µããæ¹æ³ã解説ããŠããïŒã
ããæ¹ã¯ç°¡åããŠãŒã¶åãå ¥åããããã¯ã¹ã«ãâ or 1=1 ?ããšããæååãå ¥åã ãããŠããã°ã€ã³ããã¿ã³ãæŒãã ãã
ãã£ãããã ãã§ããã°ã€ã³ãã§ããŠããŸãããã®æååã®æå³ã«ã€ããŠã¯åŸè¿°ããããããã§æ³šç®ããŠããã ãããããšã¯ãã¹ã¯ãŒããç¥ããªããŠãäžæ£ã¢ã¯ã»ã¹ã¯å¯èœã§ãããšããããšã ã
ãã¹ã¯ãŒããçãŸãããããªããŠãããŠã§ããµã€ãããŠã§ããµãŒãã¹ã®èšå®ã«äžåãäžå ·åãªã©ãããã°ãã°ã€ã³ã§ããŠããŸãããããŠããã®ãããªæ¹æ³ãçšããããšã§äžæ£ã«ãã°ã€ã³ããã ãã§ãªããããŒã¿ããŒã¹ã«èšé²ãããæ å ±ãçãã ãæ¹ããããããããšãã£ãããšãã§ããŠããŸãã
çŠ åçã®ãããªããåã
ããã§ã¯æåŸã«ããªãéæ³ã®æååã§ãã°ã€ã³ããããšãã§ããã®ãã«ã€ããŠè§£èª¬ãããã ãã°ã€ã³ç»é¢ã«ãŠãŒã¶åãšãã¹ã¯ãŒããäŒããæããã®ãŠã§ããµã€ãã¯SQLãšããèšèªãçšããŠããŒã¿ããŒã¹ã«å°ãã«ãããäŸãã°ããŠãŒã¶åã« User ããã¹ã¯ãŒãã« Password ãšå ¥åããå Žåããã®UserãšPasswordã®çµã¿åãããæããã確ããã«ãããåœç¶ããŠãŒã¶åãŸãã¯ãã¹ã¯ãŒãããããã¯ãã®äž¡æ¹ãããŒã¿ããŒã¹ã«ååšããªããã°ãã°ã€ã³ã¯èš±å¯ãããªãã
ã§ã¯ãä»åå ¥åããã â or 1=1 ?ããšå ¥åãããšã©ããªãã®ãïŒ
ãã®æçºçããåŠçãããªã倧éæãã€æ¬äººåããŠã¿ããšããã®ãããªããåããè¡ãããŠããã
ãŠã§ããµã€ãã¯ããªãã®ååã¯ãªãã§ãããšå°ããŠããã
ããã«å¯ŸããŠããªãã¯ãã1ãšã¯ããªãã¡1ã®ããšã§ããããšçŠ åçã®ãããªç¢ºèªãããã
ãããŠãããã§ãããªãã°ç§ãžã®ãã°ã€ã³ãèš±å¯ããŠãã ããããšæãäžãã€åŠå®ã®ããããç¡ãè¿çãããæŽã«ã誰ãäœãšèšãããšããèãè³ãæããªããŠããããšãŸã§å¿µæŒãããŠãããïŒâ or 1=1 ?ãã人éã«ãåããèšèã«ãããšãããªãã¡ãã®ãããªæå³ãèšãããŠããïŒ
ãã®ãããªããåãããªãäººãæ¥ãæã«ã¯ãå ¥ããŠã¯ãªããªãããšèšå®ãããŠããã°ãããã§ãã°ã€ã³ãæåŠããããšãã§ããããããããã®ãããªããåãã âåãå ¥ããŠã¯ãªããªããšã¯èšå®ãããŠããªãâ ãšãããŒã¿ããŒã¹ã¯ããããã«ã1ãšã¯1ã®ããšã§ããïŒããšåæã«çŽåŸããŠããŸãã
ãããŠãã°ã€ã³ãèš±å¯ãããŠããŸãã®ã ã
ããããŠããã¹ã¯ãŒããç¥ããªããšãããšãç°¡åã«äžæ£ã¢ã¯ã»ã¹ãèš±ããŠããŸãããšãããã
*1 https://www.akamai.com/us/en/multimedia/documents/state-of-the-internet/soti-security-financial-services-hostile-takeover-attempts-executive-summary-2020.pdfãåç §
ãèè ãè¶³ç«ç §å(ãã ã¡ãŠããã)
ãã³ãã³ãæ ç¹ã«æŽ»åãããµã€ããŒã»ãã¥ãªãã£å°éå®¶ããµã€ããŒã»ãã¥ãªãã£äŒæ¥ã®çµå¶è ãšããŠããã20幎ã®çµéšãæã¡ãåœå å€ã®éä¿¡äŒç€ŸãITäŒæ¥ãªã©ã®ãµã€ããŒã»ãã¥ãªãã£äºæ¥è ã«æè¡äŸçµŠããã³ã³ã³ãµã«ãã£ã³ã°ãæäŸãå€è³ç³»éèæ©é¢ã®ãµã€ããŒã»ãã¥ãªãã£é¡§åãªã©ãå Œä»»ããŸãããµã€ããŒã»ãã¥ãªãã£é¢é£æè¡ãžã®æè³ãçµå¶åç»ãªã©ãè¡ã£ãŠããã倧éªå€§åŠå€§åŠé¢å·¥åŠç ç©¶ç§å ±åç ç©¶å¡ãäž»ãªèæžã«ããµã€ããŒç¯çœªå ¥éã(å¹»å¬è)ããGDPR ã¬ã€ãããã¯ã(å ±è/宿¥ä¹æ¥æ¬ç€Ÿ)ãã3åãããã³ã°ãµã€ããŒæ»æãã身ãå®ãç¥èãïŒãããåºçïŒãããã

