{"id":2303,"date":"2018-10-16T19:23:37","date_gmt":"2018-10-16T10:23:37","guid":{"rendered":"https:\/\/column.prime-strategy.co.jp\/?p=2303"},"modified":"2022-12-15T05:36:59","modified_gmt":"2022-12-14T20:36:59","slug":"post-2303","status":"publish","type":"post","link":"https:\/\/kusanagi.tokyo\/column\/archives\/column_2303","title":{"rendered":"WAF\u3067\u653b\u6483\u306b\u5099\u3048\u308b(\uff61\uff65\u0434\uff65)o\u252b\uff9e;`;:\uff9e;`;:"},"content":{"rendered":"<div class=\"article__bodyInner cf\">\n<p>9\u56de\u76ee\u306e\u6295\u7a3f\u3068\u306a\u308a\u307e\u3059\u3002<br \/>\n<a href=\"https:\/\/www.nhn-japan.com\/\" rel=\"noopener\">NHN JAPAN<\/a>\u306e\u9060\u85e4\u3068\u7533\u3057\u307e\u3059\u3002<\/p>\n<p>\u3088\u308d\u3057\u304f\u304a\u9858\u3044\u3044\u305f\u3057\u307e\u3059\u3002<\/p>\n<p><a href=\"https:\/\/kusanagi.tokyo\/archives\/4899\/\" rel=\"noopener\">2018.9\u6708\u306eKUSANAGI \u30d0\u30fc\u30b8\u30e7\u30f3\u30a2\u30c3\u30d7<\/a>\u306b\u3066\u3001\u591a\u6570\u306e\u30bb\u30ad\u30e5\u30ea\u30c6\u30a3\u5bfe\u7b56\u7528\u30a2\u30d7\u30ea\u30b1\u30fc\u30b7\u30e7\u30f3\u304c\u7c21\u5358\u306b\u30a4\u30f3\u30b9\u30c8\u30fc\u30eb\u3067\u304d\u308b\u3088\u3046\u306b\u306a\u308a\u307e\u3057\u305f\u3002<\/p>\n<p>\u3053\u306e\u4e8b\u306f\u30d7\u30e9\u30a4\u30e0\u30b9\u30c8\u30e9\u30c6\u30b8\u30fc\u7a42\u82c5\u69d8\u3082<a href=\"https:\/\/column.prime-strategy.co.jp\/archives\/column_2255\">\u8a18\u4e8b\u3068\u3057\u3066\u89e6\u308c\u3089\u308c\u3066\u3044\u308b<\/a>\u306e\u3067\u3059\u304c\u3001\u5177\u4f53\u7684\u306b\u306f\u3053\u3093\u306a\u306b\u3042\u308a\u307e\u3059\u30fb\u30fb\u30fb\u03a3\uff08\u2019 v \u2018\u30ce)\u30ce<\/p>\n<p>\u30fbWAF\uff08ModSecurity\u3001NAXSI\uff09<br \/>\n\u30fbVuls (\u8106\u5f31\u6027\u30b9\u30ad\u30e3\u30f3)<br \/>\n\u30fbOpen Source Tripwire (IDS)<br \/>\n\u30fbSuricata (IDS IPS)<\/p>\n<p>\u4eca\u56de\u306f\u4e00\u756a\u4e0a\u306eWAF\u306b\u3064\u3044\u3066\u52d5\u4f5c\u78ba\u8a8d\u3092\u3057\u3066\u307f\u307e\u3057\u305f\u306e\u3067\u3001\u305d\u306e\u4e8b\u306b\u3064\u3044\u3066\u5c11\u3057\u66f8\u3044\u3066\u307f\u307e\u3059\u3002<br \/>\n\u306a\u304a\u3001Apache\u3068Nginx\u3067\u52d5\u4f5c\u3055\u305b\u308bWAF\u304c\u7570\u306a\u308a\u307e\u3059\u304c\u3001\u3053\u3053\u3067\u306f\u6a19\u6e96\u306eNginx(NAXSI)\u3092\u30d9\u30fc\u30b9\u306b\u8aac\u660e\u3057\u307e\u3059\u3002<\/p>\n<p>\u307e\u305f\u3001NAXSI\u3092\u5229\u7528\u3059\u308b\u4e0a\u3067\u826f\u304f\u4f7f\u3046nxapi\u3084ElasticSeaech\u306b\u3064\u3044\u3066\u306f\u3053\u3053\u3067\u306f\u89e6\u308c\u306a\u3044\u305f\u3081\u3001\u5b9f\u904b\u7528\u3055\u308c\u308b\u5834\u5408\u306f<a href=\"https:\/\/github.com\/nbs-system\/naxsi\/wiki\" rel=\"noopener\">\u30c9\u30ad\u30e5\u30e1\u30f3\u30c8<\/a>\u3092\u53c2\u7167\u304f\u3060\u3055\u3044\u3002<\/p>\n<p>WAF\u3068\u306f\uff01\u3063\u3066\u89e3\u8aac\u3092\u3059\u308b\u3068\u4e0a\u8ff0\u306e\u7a42\u82c5\u69d8\u306e\u8a18\u4e8b\u3068\u88ab\u3063\u3066\u3057\u307e\u3046\u306e\u3067\u7701\u7565\u3044\u305f\u3057\u307e\u3059\uff08*\u30ce\u30ce\uff09<\/p>\n<p>&nbsp;<\/p>\n<h4>\uff11\uff0eKUSANAGI\u30b3\u30de\u30f3\u30c9\u3067WAF\u3092\u6709\u52b9\u306b\u3059\u308b<\/h4>\n<p>kusanagi\u30b3\u30de\u30f3\u30c9\u306bwaf \u306e on\/off\u304c\u8ffd\u52a0\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<p># kusanagi waf on \u3067\u6709\u52b9\u306b\u306a\u308a\u307e\u3059\u3002<br \/>\n\u521d\u3081\u3066on\u306b\u3057\u305f\u6642\u306f\u5fc5\u8981\u306a\u30d1\u30c3\u30b1\u30fc\u30b8\u306e\u30c0\u30a6\u30f3\u30ed\u30fc\u30c9\u7b49\u304c\u3042\u308a\u307e\u3059\u306e\u3067\u3001\u5c11\u3057\u3060\u3051\u6642\u9593\u304c\u639b\u304b\u308a\u307e\u3057\u305f\u3002<\/p>\n<h4>\uff12\uff0e\u52d5\u4f5c\u78ba\u8a8d\u3092\u3059\u308b<\/h4>\n<p><a href=\"https:\/\/kusanagi.tokyo\/document\/command\/#ssl\" rel=\"noopener\">KUSANAGI\u30b5\u30a4\u30c8\u4e0a\u306e\u30de\u30cb\u30e5\u30a2\u30eb<\/a>\u3067\u306f\u5229\u7528\u3059\u308b\u4e0a\u3067\u6b21\u306e\u8aac\u660e\u304c\u8a18\u8f09\u3055\u308c\u3066\u3044\u307e\u3057\u305f\u3002<\/p>\n<blockquote><p>NAXSI\u306e\u8a2d\u5b9a\u3092\u30ab\u30b9\u30bf\u30de\u30a4\u30ba\u3059\u308b\u306b\u306f\u3001\u4e0b\u8a18\u30d5\u30a1\u30a4\u30eb\u3092\u7de8\u96c6\u3059\u308b\u3053\u3068\u3067\u304d\u307e\u3059\u3002<br \/>\n\/etc\/nginx\/naxsi.d\/*\/user.conf<\/p><\/blockquote>\n<p>\u6709\u52b9\u306b\u3059\u308b\u305f\u3081\u3001 \/etc\/nginx\/naxsi.d\/common\/default.conf \u306e\u5185\u5bb9\u3092 \/etc\/nginx\/conf.d\/*****_http.conf\u3000\u306e\u3001location \u5185\u306b include \u3057\u307e\u3057\u305f\u3002<\/p>\n<pre>location \/ {\ntry_files $uri $uri\/ \/index.php?$args;\n\nSecRulesEnabled;\nerror_log \/home\/kusanagi\/****\/log\/nginx\/naxsi.log;\nDeniedUrl \/waf.html;\n\nCheckRule \"$SQL &gt;= 8\" BLOCK;\nCheckRule \"$RFI &gt;= 8\" BLOCK;\nCheckRule \"$TRAVERSAL &gt;= 4\" BLOCK;\nCheckRule \"$EVADE &gt;= 4\" BLOCK;\nCheckRule \"$XSS &gt;= 8\" BLOCK;\n}<\/pre>\n<p>error\u30ed\u30b0\u306f\u5f8c\u8ff0\u3057\u307e\u3059\u304c\u3001naxsi\u306e\u52d5\u4f5c\u30ed\u30b0\u3092\u8a18\u9332\u3059\u308b\u305f\u3081\u306e\u8a18\u8ff0\u3001\/waf.html \u306fWAF\u304c\u691c\u77e5\u3057\u305f\u3089\u8fd4\u3059html\u3092\u6307\u5b9a\u3057\u305f\u3082\u306e\u3067\u30c6\u30b9\u30c8\u7528\u306b\u4f5c\u6210\u3057\u305fhtml\u3001CheckRule\u306f\u95be\u5024\u306e\u8a2d\u5b9a\u3067\u3059\u3002<br \/>\n\u6a19\u6e96\u3067\u306f \/etc\/nginx\/naxsi.d\/naxsi_core.rules.conf \u306b\u57fa\u672c\u7684\u306a\u30eb\u30fc\u30eb\u30bb\u30c3\u30c8\u304c\u7528\u610f\u3055\u308c\u3066\u3044\u307e\u3059\u3002<br \/>\n\u3053\u306e\u72b6\u614b\u3067\u3001# kusanagi nginx\u3000\u3067\u8a2d\u5b9a\u3092\u8aad\u307f\u8fbc\u307e\u305b\u53cd\u6620\u3055\u305b\u307e\u3057\u305f\u3002<\/p>\n<p>\u307e\u305a\u306f\u3001\u901a\u5e38\u306eURL\u3067\u30a2\u30af\u30bb\u30b9\u3057\u3066\u307f\u307e\u3059\u3002<\/p>\n<p>http:\/\/*****.com\/ \u2192 \u6b63\u5e38\u306b\u8868\u793a\u3057\u307e\u3057\u305f\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-2306 aligncenter\" src=\"https:\/\/www.prime-strategy.co.jp\/column\/wp-content\/uploads\/2018\/10\/wafuuuuuuuuuuuu2.png\" alt=\"\" width=\"375\" height=\"181\" srcset=\"https:\/\/kusanagi.tokyo\/column\/wp-content\/uploads\/2018\/10\/wafuuuuuuuuuuuu2.png 375w, https:\/\/kusanagi.tokyo\/column\/wp-content\/uploads\/2018\/10\/wafuuuuuuuuuuuu2-300x145.png 300w\" sizes=\"auto, (max-width: 375px) 100vw, 375px\" \/><\/p>\n<p>\u6b21\u306b\u4e0d\u6b63\u306a\u30d1\u30e9\u30e1\u30fc\u30bf\u3092\u88c5\u3063\u3066\u3001 http:\/\/*****.com\/=22\/**and\/\/1=\u201dq\u201d \u3067\u30a2\u30af\u30bb\u30b9\u3057\u3066\u307f\u308b\u3068\u3001\u7528\u610f\u3057\u305fwaf.htm\u304c\u8868\u793a\u3055\u308c\u307e\u3057\u305f\u3002<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-2308 aligncenter\" src=\"https:\/\/www.prime-strategy.co.jp\/column\/wp-content\/uploads\/2018\/10\/wafuuuuuuuuuuuu3.png\" alt=\"\" width=\"522\" height=\"111\" srcset=\"https:\/\/kusanagi.tokyo\/column\/wp-content\/uploads\/2018\/10\/wafuuuuuuuuuuuu3.png 522w, https:\/\/kusanagi.tokyo\/column\/wp-content\/uploads\/2018\/10\/wafuuuuuuuuuuuu3-300x64.png 300w\" sizes=\"auto, (max-width: 522px) 100vw, 522px\" \/><\/p>\n<p>Naxsi\u306e\u30d6\u30ed\u30c3\u30af\u3057\u305f\u30ed\u30b0\u306f\u30ed\u30b0\u30ec\u30d9\u30eb\u304cerror\u3068\u3057\u3066\u30ed\u30b0\u306b\u8a18\u9332\u3055\u308c\u308b\u306e\u3067\u3059\u304c\u3001KUSANAGI\u304c\u6a19\u6e96\u3067\u751f\u6210\u3057\u3066\u3044\u308bconf\u30d5\u30a1\u30a4\u30eb\u3067\u306ferror\u30ed\u30b0\u306e\u30ed\u30b0\u30ec\u30d9\u30eb\u306fwarn\u4ee5\u4e0a\u3092\u8a18\u9332\u3059\u308b\u3068\u306a\u3063\u3066\u3044\u308b\u305f\u3081\u3001<br \/>\nerror_log \/home\/kusanagi\/****\/log\/nginx\/naxsi.log; \u306e\u3088\u3046\u306b\u30ed\u30b0\u30ec\u30d9\u30eberror\u4ee5\u4e0a\u306e\u30ed\u30b0\u3092\u8a18\u9332\u3059\u308b\u8a2d\u5b9a\u3092\u52a0\u3048\u307e\u3057\u305f\u3002\u30d6\u30ed\u30c3\u30af\u3057\u305f\u3053\u3068\u306f\u6b21\u306e\u3088\u3046\u306a\u30ed\u30b0\u3067\u78ba\u8a8d\u3067\u304d\u307e\u3059\u3002<\/p>\n<pre>2018\/10\/10 15:27:20 [error] 21113#0: *1106 NAXSI_FMT: ip=***.***.***.***&amp;server=***.***.***.***&amp;uri=\/=22\/**and\/1=\"q\"&amp;learning=0&amp;vers=0.56&amp;total_processed=159&amp;total_blocked=11&amp;block=1&amp;cscore0=$SQL&amp;score0=16&amp;cscore1=$XSS&amp;score1=16&amp;zone0=URL&amp;id0=1001&amp;var_name0=, client: ***.***.***.***, server: ***.***.***.***, request: \"GET \/=22\/**and\/\/1=%22q%22 HTTP\/1.1\", host: \"***.***.***.***\"<\/pre>\n<p>\u30a2\u30af\u30bb\u30b9\u3057\u305fURL\u306e\u4e00\u90e8\u3067\u3042\u308buri=\/=22\/**and\/1=\u201dq\u201d \u304c\u3001 id0=1001 \u306e\u30eb\u30fc\u30eb\u306b\u6cbf\u3063\u3066\u30d6\u30ed\u30c3\u30af\u3057\u305f\u8a18\u9332\u3068\u306a\u308a\u307e\u3059\u3002<br \/>\nid0=1001\u306f \/etc\/nginx\/naxsi.d\/naxsi_core.rules.conf \u3067\u78ba\u8a8d\u3059\u308b\u3068\u30c0\u30d6\u30eb\u30af\u30aa\u30fc\u30c8\u306b\u95a2\u9023\u3057\u305f\u30eb\u30fc\u30eb\u3068\u3044\u3046\u3053\u3068\u304c\u308f\u304b\u308a\u307e\u3057\u305f\u3002<br \/>\nMainRule \u201cstr:\\\u201d\u201d \u201cmsg:double quote\u201d \u201cmz:BODY|URL|ARGS|$HEADERS_VAR:Cookie\u201d \u201cs:$SQL:8,$XSS:8\u201d id:1001;<\/p>\n<p>&nbsp;<\/p>\n<p>Naxsi\u306f\u8106\u5f31\u6027\u306e\u3042\u308b\u826f\u304f\u77e5\u3089\u308c\u305f \u30d1\u30bf\u30fc\u30f3\u306e99% \u3092\u542b\u3080\u5358\u7d14\u306a\u30eb\u30fc\u30eb\u304c\u7528\u610f\u3055\u308c\u3066\u3044\u3066\u305d\u306e\u30eb\u30fc\u30eb\u306b\u57fa\u3065\u304d\u653b\u6483\u3068\u5224\u65ad\u3057\u3066\u3044\u307e\u3059\u304c\u3001\u4e0a\u8a18\u906e\u65ad\u4f8b\u306e\u3088\u3046\u306a\u30d1\u30e9\u30e1\u30fc\u30bf\u30fc\u3082\u6642\u306b\u306f\u6b63\u5f53\u306a\u30af\u30a8\u30ea\u3068\u6210\u308a\u3048\u307e\u3059\u3002<\/p>\n<p>\u305d\u306e\u305f\u3081\u672c\u6765\u306f\u5192\u982d\u306b\u66f8\u3044\u305fnxapi\u3092\u5229\u7528\u3057\u305f\u308a\u3001 \u5b66\u7fd2\u30e2\u30fc\u30c9\u3092\u6709\u52b9\u306b\u3057\u3066error\u30ed\u30b0\u3092\u78ba\u8a8d\u3057\u306a\u304c\u3089\u30d6\u30e9\u30c3\u30af\u30ea\u30b9\u30c8\u3084\u30db\u30ef\u30a4\u30c8\u30ea\u30b9\u30c8\u306e\u6210\u578b\u3092\u3057\u3066\u304b\u3089\u306e\u5229\u7528\u3092\u60f3\u5b9a\u3057\u3066\u3044\u307e\u3059\u3002<br \/>\n\u5b66\u7fd2\u30e2\u30fc\u30c9\u306f\u8a2d\u5b9a\u30d5\u30a1\u30a4\u30eb\u5185\u306bLearningMode; \u3068\u8a18\u8f09\u3059\u308b\u3068\u5b66\u7fd2\u30e2\u30fc\u30c9\u3067\u52d5\u4f5c\u78ba\u8a8d\u306b\u306a\u308a\u307e\u3059\u3002<br \/>\n\u3053\u306e\u30e2\u30fc\u30c9\u306f\u30ed\u30b0\u30ec\u30d9\u30eb\u304cdebug\u3067\u306e\u8a18\u9332\u3068\u306a\u308a\u307e\u3059\u306e\u3067\u30ed\u30b0\u30ec\u30d9\u30eb\u306e\u8a2d\u5b9a\u3082\u5fd8\u308c\u305a\u306b\u3057\u307e\u3057\u3087\u3046_\u3006(\uff9f\u25bd\uff9f*)<\/p>\n<p>\u307e\u305f\u3001KUSANAGI\u306fWordPress\u3067\u5229\u7528\u3055\u308c\u3066\u3044\u308b\u65b9\u304c\u591a\u3044\u306e\u3067\u88dc\u8db3\u3059\u308b\u3068\u3001Wor\uff44Press\u7528\u306e\u30eb\u30fc\u30eb\uff08\u4e3b\u306b\u30db\u30ef\u30a4\u30c8\u30ea\u30b9\u30c8\uff09\u3082 \/etc\/nginx\/naxsi.d\/wordpress\/default.conf \u306b\u7528\u610f\u3055\u308c\u3066\u3044\u307e\u3059\u3057\u3001KUSNAGI\u306fDrupal\u3082\u7c21\u5358\u306b\u30d7\u30ed\u30d3\u30b8\u30e7\u30cb\u30f3\u30b0\u3067\u304d\u307e\u3059\u304c\u3001Drupal\u306e\u30eb\u30fc\u30eb\u30bb\u30c3\u30c8\u306f<a href=\"https:\/\/github.com\/nbs-system\/naxsi-rules\" rel=\"noopener\">\u8a2d\u5b9a\u30eb\u30fc\u30eb\u304c\u516c\u958b<\/a>\u3055\u308c\u3066\u3044\u307e\u3059\u3002<\/p>\n<hr>\n<p>\u6b21\u56de\u3082KUSANAGI8.4\u4ee5\u964d\u306b\u8ffd\u52a0\u3055\u308c\u305f\u6a5f\u80fd\u306e\u4f55\u308c\u304b\u3092\u8a66\u3057\u3066\u307f\u3088\u3046\u3068\u601d\u3044\u307e\u3059d(&gt;_&lt; )<\/p>\n<p>&nbsp;<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>9\u56de\u76ee\u306e\u6295\u7a3f\u3068\u306a\u308a\u307e\u3059\u3002 NHN JAPAN\u306e\u9060\u85e4\u3068\u7533\u3057\u307e\u3059\u3002 \u3088\u308d\u3057\u304f\u304a\u9858\u3044\u3044\u305f\u3057\u307e\u3059\u3002 2018.9\u6708\u306eKUSANAGI \u30d0\u30fc\u30b8\u30e7\u30f3\u30a2\u30c3 ... <a title=\"WAF\u3067\u653b\u6483\u306b\u5099\u3048\u308b(\uff61\uff65\u0434\uff65)o\u252b\uff9e;`;:\uff9e;`;:\" class=\"read-more\" href=\"https:\/\/kusanagi.tokyo\/column\/archives\/column_2303\" aria-label=\"WAF\u3067\u653b\u6483\u306b\u5099\u3048\u308b(\uff61\uff65\u0434\uff65)o\u252b\uff9e;`;:\uff9e;`;: \u306b\u3064\u3044\u3066\u3055\u3089\u306b\u8aad\u3080\">Read more<\/a><\/p>\n","protected":false},"author":7,"featured_media":2304,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"content-type":"","footnotes":""},"categories":[10],"tags":[107],"series":[53],"journey":[],"product":[],"class_list":["post-2303","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-kusanagi","tag-security","series-technical-column-endo","generate-columns","tablet-grid-50","mobile-grid-100","grid-parent","grid-33","no-featured-image-padding"],"_links":{"self":[{"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/posts\/2303","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/comments?post=2303"}],"version-history":[{"count":1,"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/posts\/2303\/revisions"}],"predecessor-version":[{"id":5419,"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/posts\/2303\/revisions\/5419"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/media\/2304"}],"wp:attachment":[{"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/media?parent=2303"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/categories?post=2303"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/tags?post=2303"},{"taxonomy":"series","embeddable":true,"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/series?post=2303"},{"taxonomy":"journey","embeddable":true,"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/journey?post=2303"},{"taxonomy":"product","embeddable":true,"href":"https:\/\/kusanagi.tokyo\/column\/wp-json\/wp\/v2\/product?post=2303"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}