¹ï©ó»í¦ë¬ì§Þ±M®×,»í¦ë¬ì§Þ±M®×¤Hû¤£Â_ª`·Nªº¥Ø«eªº§ðÀ»¤âªk§YÅܤÆ,§Æ±æ±N¨CÓ±M®×³£»s§@ªº§ó§¹¬ü¤Î¦w¥þ.
¥H¤U¬°·s»D¥þ¤å:
5¤ë¥÷Àb«È§Q¥ÎMass SQL Injection¤âªk¡A¥H¾÷¾¹¤Hµ{¦¡µo°Ê¤j¶q§ðÀ»¡A¤£¶È§ð³´¦³SQLº|¬}ªººô¯¸¦øªA¾¹¡Aªñ´Á¤S¦A§Q¥ÎFlash¼½©ñ¾¹ªºº|¬}¡Aµo°Ê²Ä¤Gªi°w¹ï¨Ï¥ÎªÌ¹q¸£ªº§ðÀ»¡C×¥¿·½½X©MWebÀ³¥Îµ{¦¡¨¾¤õÀð¡A¬O¥DnÀ³Åܤ§¹D¡C
¦b5¤ë¤¤¡A»OÆW¦³³\¦hºô¯¸¾D¨ü¤FÃz¶qªºMass SQL Injection§ðÀ»¡Aªì¨B¦ôp¦³¶W¹L10¸U»O¹q¸£¨ü®`¡C¦bµuµu¤£¨ì1©Pªº®É¶¡¡A¦P¼Ë¤@§åÀb«È¡A¤S§Q¥ÎAdobe Flash¼½©ñ¾¹ªºº|¬}¡A¦A«×µo°Ê§ðÀ»¡C
¸ê¦w±M®aªí¥Ü¡A±q³o´XªiÀb«Èªº§ðÀ»¤âªk¥i¥Hµo²{¡A³o¤@§åÀb«È¡A¨ä¹ê¬O¦b´ú¸Õ¾ãÓMass SQL Injection§ðÀ»ªº®Ä²v»P¦¨®Ä¡CÀb«Èªº¥Øªº¨ä¹ê¬On§ä¨ì¦n¥Îªº§ðÀ»¤âªk¡A¦b§óµuªº®É¶¡¤º±±¨î§ó¦h¹q¸£¡A¶i¦ÓÅѨú¹q¸£ªº¸ê®Æ¡C
¥H¾÷¾¹¤Hµ{¦¡µo°Ê¤j¶qSQL Injection§ðÀ»
4¤ë©³¡A¼Ú¬ü¦a°Ï´Nµo²{¤j¶qªºMass SQL Injection§ðÀ»¤âªk¡C5¤ë¤¤¡A¸ê¦w¤½¥qªü½X¬ì§Þªº¬ã¨s¤Hû¡A±q¦w¸Ë¦b¥ø·~ºÝªººô¸ôÀ³¥Îµ{¦¡¨¾¤õÀð¡]WAF¡^¡Aµo²{³oºØ§ðÀ»¤w¸gªi¤Î»OÆW¡A¥L̶i¤@¨B¤ÀªRµo²{¡A³æ´N5¤ë16¤é¤@¤Ñ¡A¦Ü¤Ö´N¦³1¸UÓºô¯¸³Q³oÓ§ðÀ»¤âªk´Ó¤J´c·Nµ{¦¡¡A¦Ó³Q´Ó¤J´c·N³sµ²ªººô¶«h°ª¹F10¸UÓ¡C
Àb«Èªº§ðÀ»¤âªk¡A¬O¥ý§Q¥ÎGoogle·j´M¦³SQLº|¬}ªººô¯¸¦øªA¾¹¡A¦A¥HSQL Injection¤âªk¤J«I¡Cªü½X¬ì§Þ¸ê¦wÅU°Ý¤B©Ê¦úªí¥Ü¡AGoogle·j´M¤ÞÀº·|¸T¤î¦P¤@ÓIP¨Ó·½¦bµu®É¶¡¤º¤j¶q·j´M¡A¤@¥¹¦³Ãþ¦ü¦æ¬°¡AGoogle ·j´M¤ÞÀº´N·|n¨D¨Ï¥ÎªÌ¿é¤J¹Ï§ÎÅçÃÒ½X¡]CAPTCHAs¡^©Î¸T¤î·j´M¡C¤B©Ê¦ú»¡¡AÀb«È¥i¥H¤j¶q§Q¥ÎGoogle·j´M¡A¥i¯à¬O¨Æ¥ý´x±±¤F¤j¶qªº³ÈÀw¹q¸£¡A°µ¨ì¥H¦Û°Ê¤Æµ{¦¡¤j¶q·j´M¦³SQL º|¬}ªººô¯¸¡A¨Ãµo°Ê§ðÀ»¡C
Àb«È¥ÎFlashº|¬} ´ú¸Õ§ðÀ»¤âªkºë·Ç«×
²Ä¤@ªiªºMass SQL Injection§ðÀ»¥Dn¬O°w¹ïºô¯¸¦øªA¾¹¡A§ðÀ»ºÝªºIP¨Ó·½¥X¦Û¤¤°ê¤j³°¡C´°¶§¬ì§Þ¸ê²`¸ê¦w§Þ³NÅU°Ý·¨§BÃvªí¥Ü¡A¦b²Ä¤@ªi§ðÀ»¤¤³Q´Ó¤J´c·Nµ{¦¡ªººô¯¸¦øªA¾¹¡A³QÀb«È§Q¥Î¨Óµo°Ê²Ä¤Gªi§ðÀ»¡AÀb«ÈÂê©w¤@¯ë¨Ï¥ÎªÌ¹q¸£Flash¼½©ñ¾¹ªºº|¬}¡A¥unÂsÄý³o¨Ç¨üÀbºô¯¸ªº¹q¸£¡A¨S¦³×¸ÉFlashµ{¦¡ªºº|¬}¡A¨º»ò´c·Nµ{¦¡´N¦³¥i¯à¤J«I¦¨¥\¡A¶i¦Ó±±¨î¹q¸£¡C
¼ÆÁp¸ê¦w¬ãµo³B°ÆÁ`¸g²z±i¸Î±Óªí¥Ü¡A¡u³o¤@ªiAdobe Flashªº§ðÀ»¤¤¡A¦b5¤ë30¤éâ±á¹sÂI¹s¤À´NºI¤î¡A¬O¤@Ó¦³®É®Ä©Êªº§ðÀ»¤âªk¡A¡v
±i¸Î±Ó±À´ú¡A¥Ø«e¬Ý¨ÓÀb«È¬O¦b´ú¸Õ§ðÀ»¤âªkªº¦¨®Ä»Pºë·Ç«×¡C·íÀb«È¦¨¥\ÅçÃÒ¤F¥HGoogle Hacking·f°tMass SQL Injection¤âªk¡A¥i¥H¦bµu®É¶¡¤º§ð³´¤j¶qºô¯¸¦øªA¾¹¡A¶i¦Ó±±¨î§ó¦hÂsÄýºô¯¸ªº¹q¸£¤§«á¡A¤]´N·N¨ýµÛ¡A³o§åÀb«È¹ï¨ü®`¹q¸£ªº´x´¤«×¤w¸g¨ì¡u¦p¤JµL¤H¤§¹Ò¡vªº¦a¨B¡C
±µ¤U¨Ó¡AÀb«È´N¥i¥H¦b¨ü®`¹q¸£¤j¶q¦w¸Ë»»±±ªº¾÷¾¹¤Hµ{¦¡¡A°£¤F¥i¥H§Q¥Î³o¨Ç³ÈÀw¹q¸£µo°ÊDDoS§ðÀ»¡]¤À´²¦¡ªýÂ_¦¡§ðÀ»¡^¡A§ó¥i¥H¶X¾÷ÅѨú¡B³c°â¹q¸£ùتºÓ¤H»P¥ø·~¾÷±K¸ê®Æ¸ê®Æ¹Ï§Q¡C
ÂùºÞ»ô¤U ¸Ñ¨MSQL Injection¦Ñ°ÝÃD
»OÆW¥ø·~¹ï©óSQL Injection§ðÀ»¤âªk¡A¸g±`³B©ó§ô¤âµLµ¦ªºª¬ºA¡A·¨§BÃvªí¥Ü¡A¦h¼Æ¤H³£©ê«ù¡u¥H©ì«ÝÅÜ¡vªº¤ßºA¡A¥unÓ¤H©Î¤½¥q¨S¨ü®`¡B¨S¨£³ø´N¦n¡C³o¼Ëªºª¬ªp¤£§ïÅÜ¡ASQL Injectionªº°ÝÃD´N·|Ä~Äò¦s¦b¡C
±¹ïSQL Injection§ðÀ»ªº´c©Ê´`Àô¡A´°¶§¬ì§Þ§Þ³NÅU°Ý¼B«T¶¯»{¬°¡A¤@©w±o¦hºÞ»ô¤U¤~¦³¾÷·|®Úµ´¡A¥L»¡¡A¥¿¥»²M·½¤§¹D¬O×§ïì©l½X¡A¥]¬A·½½XÀË´ú¡]Code Review¡^¡Bºô¯¸±½´y¡]Web Scan¡^¥H¤Îº¯³z´ú¸Õ¡]Penetration Testing¡^µ¥¤è¦¡¡C
YµLªk§Y¤Î×§ïì©l½X¡A«h¥i§Q¥ÎWebÀ³¥Îµ{¦¡¨¾¤õÀð¡]WAF¡^§@¬°¨¾¿m¡BÀ³«æ¤§¥Î¡C¤å¡ó¶À«Û´Ù
°§CSQL Injection§ðÀ»ªº3¤jÃöÁä
¸ê²`ªº¸ê¦w¬ã¨sû¼ÆÁp¸ê¦w¬ãµo³B°ÆÁ`¸g²z±i¸Î±Óªí¥Ü¡A»OÆW¥ø·~¨Ï¥Î·L³n.NET¥»O¤ñ¨Ò«Ü°ª¡AY¯à´x´¤ASP .NET¨¾¿mSQL Injectionªº3¤jÃöÁä¡A±N¦³§U©ó°§C³oÃþ§ðÀ»¡C
iThome°Ý¡G¦p¦ó¦³®Ä¨¾°ôSQL Injectionªº§ðÀ»¡H
±i¸Î±Óµª¡G·L³n°w¹ïASP .NET¥»O±À¥X³\¦h¦w¥þ¤å¥ó¡A±Ð¾É¶}µo¤Hû°µ¦UºØ¦w¥þ°Ñ¼Æ³]©w¡C¥Ø«e¥i¥H±qµ{¦¡¶}µo¡B»P¸ê®Æ®wµ{¦¡ªº³sµ²¥H¤ÎIIS 5.0¦øªA¾¹ªº³]©wµ¥3¤è±µÛ¤â¶i¦æ¡C
°Ý¡G¶}µoASP .NET¸Óª`·Nþ¨Ç°Ñ¼Æªº³]©w¡H
µª¡G¦bASP .NET¥»O¡A·L³n¤]´£¨Ñ¦UºØWeb UI¤¸¥ó¨Ñ¶}µo¤Hû¿ï¾Ü¡C³z¹L³]©w³o¨ÇWeb UI¤¸¥ó¡A¯à°÷À°¶}µo¤Hû¦b¶i¦æ¦UºØ¯S®í²Å¸¹¹LÂo¡B¥¿³W¤Æªí¥Ü¦¡¡]Regular Expression¡^¡A¬Æ¦Ü¬O¶Â¡B¥Õ¦W³æµ¥³]©w¡A³£¦³¤@¨Ç°Ñ¼Æ¥i¥H¤Ä¿ï¡AÁ×§K¥H«e°µASP¶}µo®É¡A©Ò¦³°Ñ¼Æ¥\¯à³£¥²¶·¦Û¤v¼g¡A¦Ó±`±`·|¥X²{±¾¤@º|¸Uªº²{¶H¡C
°Ý¡Gµ{¦¡»P«áºÝ¸ê®Æ®wªº³sµ²¤W¡A»Ýnª`·N¤°»ò¡H
µª¡GSQL Injection¥Dnµo¥Íì¦]¦b©ó¡A«eºÝ¨t²Î¥á¥XªºSQL¬d¸ß»yªk¤£°®²b©Î¦³¿ù»~¡A¾ÉP«áºÝ¦øªA¾¹°µ¤F¤£·íªº¤ÏÀ³¡C³\¦h¶}µo¤Hû¥H©¹²ßºDª½±µ³z¹LSQL »yªk¥h¬d¸ß«áºÝ¸ê®Æ®w³sµ²¡C¤ñ¸û¦nªº§@ªk«h¬O¡AÅý«eºÝSQL»yªk©Î«ü¥O¡A³z¹L°Ñ¼Æ¤Æµ{§Çªº©I¥s¤è¦¡¡A¦s¨ú«áºÝªº¸ê®Æ®w¡C¤@¥¹«eºÝSQL»yªk¤º§t´c·N²Å¸¹®É¡A«áºÝ¸ê®Æ®w´N¤£·|°µ¥ô¦ó¯S®í¤ÏÀ³¡C
°Ý¡Gºô¯¸¦øªA¾¹»Ýnª`·N¤°»ò©O¡H
µª¡G³\¦hASP .NETªº¥ø·~¥Î¤á¡A¤]³£±Ä¥Î·L³nIIS 5.0ºô¸ô¦øªA¾¹¡C¦bIIS¦øªA¾¹ºÝªº³]©w¡A¥Dn¯S§O°w¹ïWeb Config³]©wÀɰµ°Ñ¼Æ³]©w¡C³o¼Ëªº°Ñ¼Æ³]©w±qCookie¡BView_State_¨ì»{ÃÒµ¥¡A«e«á¶W¹L100¦h¶µ³]©w¡C³o¨Ç°Ñ¼Æ³]±o¦n¡A´N¥i¥H´£°ª Web Serverªº¦w¥þ©Ê¡C
°Ý¡G¤°»ò¬O¤ñ¸û¬Ù¤OªºIIS¦øªA¾¹³]©w¤è¦¡¡H
µª¡G³oÓ¬Ù¤Oªº³]©w¡A¥Dn¬O¥Ñ¤¤°ê¤j³°¦h¤H¦@¦P¶}µo¥X¨Óªº¡u³q¥Îª`¤J¹LÂo¾¹¡v¡C³o¬O¤@Ó°ò©óIIS¨t²Îªº¼Ò²Õ¡A®Ö¤ß¥ÑC++¼¶¼g¡C¥un±N¸Óµ{¦¡¦w¸Ë¦bIIS¦øªA¾¹¤W¡A´N¥i¥H«OÅ@¾ãÓ¨t²ÎÀɮסA¹w¨¾³Q¤H§Q¥ÎASPµ{¦¡º|¬}¡A¶i¦Ó³Qª`¤J´c·N»yªk¡A¤]¥i¥H¨¾¤î¸ê®Æ®w³Q¤U¸ü¡C
¥Ø«e¤¤°ê¤j³°«Ü¦hºô¯¸¡A³£¨Ï¥Î³o¼Ëªº³q¥Îª`¤J¹LÂo¾¹¡A¥H°§CSQL Injectionªº¨ü®`µ{«×¡C¤å¡ó¶À«Û´Ù
Mass SQL Injection 3¶¥¬q§ðÀ»¤è¦¡
²Ä1¶¥¬q ¥HGoogle Hacking§ä´M¦³SQLº|¬}ªººô¯¸¦øªA¾¹¡A´Ó¤J´c·Nµ{¦¡³sµ²
Àb«È³z¹L¦Û°Ê¤Æ¾÷¾¹¤Hµ{¦¡¡A§Q¥ÎGoogle·j´M¤ÞÀº§ä¥X¦³SQLº|¬}ªººô¯¸¦øªA¾¹¡A¤j¶q´Ó¤J´c·Nµ{¦¡©Î´c·N³sµ²¡C»OÆW¦ôp¦Ü¤Ö¦³¶W¹L10¸U»O¹q¸£¨ü®`¡C
²Ä2¶¥¬q ÂǥѳQ¨üÀbªººô¯¸¦øªA¾¹¡A¹ï©óÂsÄýºô¯¸ªº¹q¸£µo°ÊAdobe Flashº|¬}§ðÀ»
Àb«È¬Ý·Ç¤@¯ë¹q¸£¨Ï¥ÎªÌ¤£·|§ó·sAdobe Flashªºº|¬}¡AÂǥѲĤ@ªi¨üÀbªººô¯¸¡A¥h·P¬V§ó¦h³sºôªº¹q¸£¡C¦pªG¹q¸£ªºFlashº|¬}¨S¦³×¸É¡A´N·|¦¨¬°³QÀb«È´x±±ªº³ÈÀw¹q¸£¡C
²Ä3¶¥¬q ¤U¤@¨B¡G¤j¶q³ÈÀwºô¸ô»P¸ê®Æ¥~¬ª
¤£½×¬O¤j¶qSQL Injection§ðÀ»¡A©ÎªÌ¬O§Q¥ÎAdobe Flashº|¬}µo°Ê§ðÀ»¡A³£¥u¬OÀb«È¦b´ú¸Õ§ðÀ»¦¨®Äªº«eﯸ¦Ó¤w¡C·íÀb«È½T»{§ðÀ»¤âªk¯à¦³®Ä¹F¦¨¥Ø¼Ð«á¡A´N¯à°÷´N¥iµo°ÊDDoS¡]¤À´²¦¡ªýÂ_¦¡§ðÀ»¡^¤ÎÅѨú³c°â¸ê®Æ¡C¤å¡ó¶À«Û´Ù
Âà¸ü:¸ê¦w¤§²´
|