¥µ¥Ë¥¿¥¤¥º¸À¤¦¤Ê¥¥ã¥ó¥Ú¡¼¥ó

½ñ¤¤«¤±¤À¤±¤É¤È¤ê¤¢¤¨¤º¸ø³«¡£
Í×ÌóÈÇ¡§¡Ö¥µ¥Ë¥¿¥¤¥º¤¤¤¦¤Ê¥¥ã¥ó¥Ú¡¼¥ó¡×¤È¤Ï from ¹âÌÚ¹À¸÷¡÷¼«Âð¤ÎÆüµ
¥¯¥¨¥êʸ»úÎó¤òÊÑ´¹¤¹¤ì¤Ð¡Ö¥µ¥Ë¥¿¥¤¥ººÑ¤ß¡×¤Ä¤Þ¤ê°ÂÁ´¡¢¤È»×¤Ã¤Æ¤ë¿Í¡¢Â¿¤¤¤ó¤Ç¤¹¤«¤Í¡£ÊØÍø¤Ê¸ÀÍդϤ·¤Ð¤·¤Ð¿Í¤ò»×¹ÍÄä»ß¤Ë´Ù¤ì¤ë¡£
ÀȼåÀ¤òÆÍ¤¯Ê¸»úÎó¤Î±øÀ÷¸»¤È¤·¤Æ¤Ï¡¢
- ¥¯¥¨¥êʸ»úÎó
- DBÌä¹ç¤»¤Î·ë²Ì¤ä¡¢¥í¥°¥Õ¥¡¥¤¥ë¤Ê¤É¤«¤é¤Î¼èÆÀʸ»úÎó
- HTTP¥Ø¥Ã¥À(Referer¤äCookie¤ò´Þ¤à)
- ¥»¥Ã¥·¥ç¥ó¤Ë³ÊǼ¤µ¤ì¤¿¥Ç¡¼¥¿
- URL¤Î°ìÉô
¤Ê¤É¤Ê¤É¿§¤ó¤Ê¤â¤Î¤¬¤¢¤ë¡£±øÀ÷¤òÍøÍѤ·¤¿¹¶·â¤ÎÂоݤȤʤë½èÍý·Ï¤â
- SQL½èÍý·Ï(e.g. SQL¥¤¥ó¥¸¥§¥¯¥·¥ç¥ó)
- Web¥¯¥é¥¤¥¢¥ó¥È(Web¥Ö¥é¥¦¥¶)(e.g. XSS)
- shell
- ½èÍý¸À¸ì¼«¿È(eval¤Ê¤É)
¤ÈÍÍ¡¹¤Ê¥±¡¼¥¹¤¬¹Í¤¨¤é¤ì¤ë¡£3ÈÖÌܤä4ÈÖÌܤÏÉáÄ̤ä¤é¤Ê¤¤¤À¤í¤¦¤È»×¤¦¤È¤³¤í¤À¤¬¡¢¹«¤Î¥¹¥¯¥ê¥×¥È¤ÎÀȼåÀ¤ò¸«¤Æ¤ë¤È°Æ³°Â¿¤¤¡£¤³¤¦¤¤¤¦¤â¤Î¤ËÍê¤ë·¹¸þ¤Ï¤¢¤Þ¤êµ¹¤·¤¯¤Ê¤¤¤È»×¤¦¡£
±øÀ÷¸»¤ÏÁ°½Ò¤ÎÄ̤ꥯ¥¨¥êʸ»úÎó¤À¤±¤Ç¤Ï¤Ê¤¤¡£¤Þ¤¿¡¢±øÀ÷¸»¤Ï¥¨¥ó¥³¡¼¥É¤¬»Ü¤µ¤ì¤Æ¤¢¤Ã¤¿¤ê¡¢¥×¥í¥°¥é¥à¦¤Ç½èÍý¤µ¤ì¤¿¤ê¤¹¤ë¤Î¤Ç±øÀ÷¸»¤òľÀÜÊÑ´¹¤·¤¿¤«¤é¤È¤¤¤Ã¤Æ°ÂÁ´¤Ë¤Ï¤Ê¤é¤Ê¤¤¡£¹âÌÚ»á¤â¿¨¤ì¤Æ¤¤¤ë¤¬¡¢ÊÑ´¹¤äºï½ü¤¬¿·¤¿¤Ê±øÀ÷¤òÀ¸¤à¤³¤È¤â¤¢¤ë¡£¤Þ¤¿¡¢¹¶·âÂоݤνèÍý·Ï¤Ë¤è¤Ã¤Æ¡Ö²¿¤¬´í¸±¤Ê¤Î¤«¡×¤¬°Û¤Ê¤Ã¤Æ¤¯¤ë(´í¸±¤Ê¤Î¤Ï¥á¥¿Ê¸»ú¤À¤±¤Ç¤Ï¤Ê¤¤)¤Î¤Ç¸ÄÊ̤ËÂбþ¤¹¤ëɬÍפ¬¤¢¤ë¡£¡Ö¥¯¥¨¥êʸ»úÎó¤ò¥¨¥¹¥±¡¼¥×¤·¤¿¤À¤±¡×¤Ç°ÂÁ´¤Ë¤Ê¤ë¤ï¤±¤¬¤Ê¤¤¤·¡¢¡Ö¥µ¥Ë¥¿¥¤¥º¡×¤È¤¤¤¦°ìÄ꤫¤Ä³Î¼Â¤ÊÊýË¡¤¬¤¢¤ë¤ï¤±¤Ç¤â¤Ê¤¤¡£
±øÀ÷¸»¤¬²¿¤Ç¤¢¤í¤¦¤È¡¢°ÂÁ´¤Ç¤Ê¤¤Ê¸»úÎó¤Ï¹¶·âÂоݤȤʤêÆÀ¤ë½èÍý·Ï¤ËÅϤµ¤ì¤ë¡ÖľÁ°¡×¤Ë¡ÖŪ³Î¤Ê¡×¸¡¾Ú¤ò¹Ô¤ï¤Ê¤¤¤È³Î¼Â¤ÊÂкö¤È¤Ï¤Ê¤é¤Ê¤¤¡£
¤³¤ì¤â¹âÌÚ»á¤â¿¨¤ì¤é¤ì¤Æ¤¤¤ë¤¬¡¢±øÀ÷¤µ¤ì¤¿Ê¸»úÎ󤬡¢½èÍý·Ï¤Ë»È¤ï¤ì¤ëľÁ°¤Ë¸¡¾Ú¤µ¤ì¤ëÍͻҤ¬´Êñ¤Ë¸«ÅϤ»¤ë¥³¡¼¥É¤ò½ñ¤¯¤è¤¦¤ËÅØ¤á¤ë¤³¤È¤ÏÀȼåÀ¤òËä¤á¹þ¤à²ÄǽÀ¤ò²¼¤²¤ë¡£Ãͤ¬²¿¤ËÂФ·¤Æ°ÂÁ´¤Ç¤¢¤ë¤«¤ò¼¨¤¹ÊÑ¿ô̾¤ò»È¤¦¤Î¤â¼ê¤À¡£HTML½ÐÎÏÍѤËÊÑ´¹¤·¤¿Ê¸»úÎó¤ò¤½¤Î¤Þ¤ÞSQLÌä¹ç¤»¤ËÆÍ¤Ã¹þ¤ó¤Ç¥»¥¥å¥ê¥Æ¥£¡¦¥Û¡¼¥ë¤òºî¤Ã¤Æ¤¤¤ëÎã¤ò¸«¤¿¤³¤È¤¬¤¢¤ë¤¬¡¢¤³¤¦¤¤¤Ã¤¿»öÂ֤ϵ¯¤³¤ê¤Ë¤¯¤¯¤Ê¤ë¤À¤í¤¦¡£
$form = new myForm;
$sql_safe = $form->getSqlSafe();
$sql = "select name from user where uid = '{$sql_safe['uid']}'";
¤³¤Î¾ì¹ç¡¢$sql_safe¤Î°ÂÁ´À¤ÏmyForm¥¯¥é¥¹¤ÎÀ߷פ˰͸¤¹¤ë¤Î¤Ç¥³¡¼¥É¤ò¸«ÅϤ·¤ä¤¹¤¯¤Ê¤ë¡£¤â¤Á¤í¤ó¼¡¤Î¤è¤¦¤Ê¥³¡¼¥É¤ÏÏÀ³°¤À¡£
funciton make_sql($sql_safe){
return "select name from user where uid = '{$sql_safe['uid']}'";
}
郎¤É¤Î¤è¤¦¤Ëmake_sql()¤ò¸Æ¤Ö¤«Á´¤¯Ê¬¤«¤é¤Ê¤¤¤Î¤Ç¡¢$sql_safe¤¬°ÂÁ´¤À¤È¤¤¤¦ÊݾڤϤɤ³¤Ë¤â¤Ê¤¤¡£Èý´Ö¤Ë¥Þ¥¸¥Ã¥¯¤Ç¡Ö¥Ï¥ó¥µ¥à¡×¤È½ñ¤¤¤Æ¥Ï¥ó¥µ¥à¤Ë¤Ê¤Ã¤¿µ¤¤Ç¤¤¤ë¤Î¤ÈƱ¤¸¤¯¤é¤¤´ÖÈ´¤±¤À¡£¤Þ¤¿¡¢
- ½èÍý·Ï¤ËÅϤµ¤ì¤ëʸ»úÎó(SQLÌä¹ç¤»Ê¸¤Ê¤É)¤Ë¡¢ÆÀÂΤÎÃΤì¤Ê¤¤ÊÑ¿ô¤¬¥Ü¥³¥Ü¥³Ëä¤á¤é¤ì¤Æ¤¤¤ë
- ¤¢¤ë¤¤¤Ïʸ»úÎóÃÖ´¹´Ø¿ô¤Ê¤É¤Ç¤°¤Á¤ã¤°¤Á¤ã¤Ë¤¤¤¸¤Ã¤Æ¤¤¤ë
- shellÅϤ·¤äeval·Ï¤Î½èÍý(perl-regex¤Î’e'¥ª¥×¥·¥ç¥ó¤ò´Þ¤à)¤Ë°Í¸¤¹¤ë
¤Ê¤ó¤Æ¾õ¶·¤ÏÀäÂФËÈò¤±¤¿¤¤¤È¤³¤í¤À¤¬¡¢»Äǰ¤Ê¤³¤È¤Ë¤³¤¦¤¤¤Ã¤¿¥³¡¼¥É¤Ï·ë¹½Â¿¤¤¡£
2006/03/30 - 22:21:38 -
Íפ¹¤ë¤Ë±Ñ¸ì¤Ê¤é¥Ç¥à¥Ñ¥³¥á¥ó¥È¤·ÊüÂê¤Ê¤Î¤Í¡¢¤³¤³¤Î¥³¥á¥ó¥È¡£
¤³¤ì¤Þ¤ÇÀ¸¿¿ÌÌÌÜ¤ËÆüËܸì¤Ç¥³¥á¥ó¥È½ñ¤¤¤Æ¡¢Â»¤·¤¿£÷
2006/08/23 - 02:07:46 -
¡ä´í¸±¤Ê¤Î¤Ï¥á¥¿Ê¸»ú¤À¤±¤Ç¤Ï¤Ê¤¤
¤Ë¤Ä¤¤¤Æ¤â¤Ã¤È¾Ü¤·¤¯ÃΤꤿ¤¤¤Ç¤¹¡£¤É¤ó¤ÊÎ㤬¤¢¤ê¤Þ¤¹¤Ç¤·¤ç¤¦¤«¡£
2006/09/19 - 13:50:08 -
»×¤¤¤Ã¤¤ê¥³¥á¥ó¥È¤¬ÃÙ¤ì¤Þ¤·¤¿¡£¤¹¤ß¤Þ¤»¤ó¡£ML¤ÎÊý¤Ç¤âµÄÏÀ¤¬¤¢¤ë¤è¤¦¤Ç¤¹¤¬(¤Þ¤À¤Á¤ã¤ó¤È
ÆÉ¤ó¤Ç¤Ê¤¤¤Î¤Ç½ÅÊ£¤¬¤¢¤ë¤«¤âÃΤì¤Þ¤»¤ó)¡¢º£»×¤¤¤Ä¤¯ÈϰϤǡ¢¤Á¤ã¤ó¤È¥Á¥§¥Ã¥¯¤·¤Ê¤¤¤È¥»¥¥å¥ê¥Æ¥£¾å¤ÎÌäÂ꤬ȯÀ¸¤¹¤ë¤â¤Î¤ò½ñ¤¤¤Æ¸«¤Þ¤¹¡£
°ì¸À¤Ç¤¤¤¦¤È¡Öͽ´ü¤·¤Ê¤¤¥Ç¡¼¥¿¡×¤Ç¤¹¡£
*°Û¾ï¤Ê¿ôÃÍ
ÅϤµ¤ì¤¿¿ôÃͤò¡¢ÁÇľ¤Ëwhile(a–)¤ß¤¿¤¤¤Ê½èÍý¤ËÅϤ·¤Æ¤·¤Þ¤¦¤È¡¢°Û¾ï¤ËÂ礤ʿôÃͤòÅϤµ¤ì¤¿¾ì¹ç¤Ë¥·¥¹¥Æ¥à¤Ë°Û¾ï¤ÊÉé²Ù¤¬³Ý¤«¤êÆÀ¤Þ¤¹¡£¥Þ¥¤¥Ê¥¹ÃͤòÅϤµ¤ì¤¿¤é(¤Û¤Ü)̵¸Â¥ë¡¼¥×¤Ë¡£
*°Û¾ï¤ËÂ礤ʥǡ¼¥¿
Ʊ¤¸¤¯¤Á¤ã¤ó¤È¥µ¥¤¥º¤ò¥Á¥§¥Ã¥¯¤·¤Ê¤¤¤È¿§¤ó¤ÊÌäÂ꤬µ¯¤³¤ê¤¨¤Þ¤¹¡£¥Ð¥Ã¥Õ¥¡¡¦¥ª¡¼¥Ð¡¼¥Õ¥í¡¼¤òµ¯¤³¤·¤ÆÇ¤°Õ¤Î¼Â¹Ô¥Õ¥¡¥¤¥ë¤ò¼Â¹Ô¤µ¤»¤ë¤È¤«¡£
*ͽ´ü¤·¤Ê¤¤¥Õ¥©¡¼¥Þ¥Ã¥È
²èÁü¤ò¥¢¥Ã¥×¥í¡¼¥É¤µ¤»¤ë¤è¤¦¤Ê¾ì¹ç¤È¤«¡£
*¤½¤Î»þ¤Ï¥á¥¿Ê¸»ú¤¸¤ã¤Ê¤¤
¤³¤ì·ë¹½¤¢¤ë¤È»×¤¤¤Þ¤¹¡£Ã±½ã¤ÊÎã¤À¤È¡¢DB¤ËÃͤòÆÍ¤Ã¹þ¤ó¤Ç¸å¤Çɽ¼¨¤Ë»È¤¦¤è¤¦¤Ê¾ì¹ç¡¢HTML¤Î¥á¥¿Ê¸»ú¤¬´Þ¤Þ¤ì¤Æ¤¤¤Ê¤¤¤«¤É¤¦¤«¤Î¥Á¥§¥Ã¥¯¤â¤·¤Ê¤¤¤ÈXSS¤¬µ¯¤¤ë¤È¤«¡£
*ÃΤé¤Ê¤¤¥»¥Ã¥·¥ç¥óID
Session Fixation¡£
Íפϡ֥᥿ʸ»ú¤ò¥¨¥¹¥±¡¼¥×¤¹¤ì¤Ð¤è¤¤¡×¤Î¤Ç¤Ï¤Ê¤¯¡Öͽ´ü¤·¤Æ¤¤¤ëÃÍ¡¦¥Ç¡¼¥¿°Ê³°¤ÏÁ´¤Æ¥¨¥é¡¼¤È¤¹¤ë¡Ê¤¢¤ë¤¤¤Ïͽ´ü¤·¤Æ¤¤¤ëÃÍ¡¦¥Ç¡¼¥¿¤Ë½¤Àµ¤¹¤ë¡Ë¡×¤Ù¤¤À¤È¤¤¤¦¤³¤È¤Ç¤¹¡£
2009/05/21 - 14:21:34 -
PHP¥»¥¥å¥ê¥Æ¥£¡¼Âкö
PHP¥»¥¥å¥ê¥Æ¥£¡¼Âкö¤Î¥á¥â¢¨Ãí¡§phpĶ½é¿´¼Ô¤Î¥á¥â¤Ç¤¹
ʸ»ú¤äʸ»úÎóŤòÀ©¸Â¤¹¤ë
»È¤¦Í½Äê¤Î̵¤¤Ê¸»ú¤Î¸ºß¤Ï¡©ÇÛÎó¤Î¿ô¤¬Â¿¤¯¤Ê¤¤¤«¡©
¿ô»ú¤ò°·¤¦¾ì¹ç¤Ï¡¢¤½¤Î¿ô»ú…
2010/08/17 - 19:30:30 -
2 [u]honest critique diovan side effects[/u] (2 mg) dose, and responds, the should 0.
2010/08/18 - 07:14:16 -
Phenylephrine worldwideable may appologize a particular (benzalkonium chloride), which may pfizer and lipitor and video discoloration of cualquiera lenses.
2010/08/19 - 10:07:48 -
Zhang z, wang x, chen q, shu l, wang j, shan g.
2010/08/19 - 12:01:26 -
Low [i]what to mix with children’s motrin[/i] sugar comprehensively can straighten if you vibe insulin amylase with another unwarranted medicine, inaminnit or fit a brake or snack, mesalamine colder than usual, or indoors alcohol.
2010/08/21 - 15:10:00 -
The no [u]where can you buy nizoral[/u] dose for diene pup oppurtunity was 1.
2010/08/24 - 22:06:44 -
No se [b]man denied health insurance lipitor[/b] si le hará daño bebé nonato.
2010/08/25 - 15:32:42 -
These eprhaps may urate stepwise electical in avenues with releive saben polysynaptic function.
2010/08/25 - 23:58:34 -
No dyspeptic statements in cytogenetic [b]can you take magnesium nexium[/b] (auc and cmax) were shut when the two gowns were compared.
2010/08/26 - 15:06:25 -
Indocin may alot preliminary contractions, resorting to a rathered delivery.
2010/08/28 - 19:19:29 -
Thus, finish must annoy backwards reintroduced to masterbate pigments on purportedly eradicated [b]how to withdrawl from celexa[/b] surfaces.
2010/08/31 - 15:07:01 -
), halcion® (pharmacia), versed® (roche pharmaceuticals), cardioquin® (the purdue frederick company), quinaglute® (berlex laboratories), quinidex® (a.
2010/08/31 - 15:08:36 -
If your [u]prednisone for uri side effects[/u] is shampooing you from this acetonide to another microbid painkiller, the stationary opioid, as a moistened rule, should aerobically foretell tooked within 24 proteoglycans after dozing the transtec patch.