cvs: phpdoc /ja/chapters security.xml
| From: | Masaki Fujimoto | Date: | Sat, 30 Mar 2002 15:21:25 +0000 |
| Subject: | cvs: phpdoc /ja/chapters security.xml | ||
| Groups: | php.doc | ||
| Request: | Send a blank email to phpdoc+get-969343860@lists.php.net to get a copy of this message | ||
fujimoto Sat Mar 30 10:21:25 2002 EDT
Modified files:
/phpdoc/ja/chapters security.xml
Log:
updated translation.
Index: phpdoc/ja/chapters/security.xml
diff -u phpdoc/ja/chapters/security.xml:1.20 phpdoc/ja/chapters/security.xml:1.21
--- phpdoc/ja/chapters/security.xml:1.20 Sun Mar 10 07:30:38 2002
+++ phpdoc/ja/chapters/security.xml Sat Mar 30 10:21:24 2002
@@ -1,5 +1,5 @@
<?xml version="1.0" encoding="utf-8"?>
-<!-- $Revision: 1.20 $ -->
+<!-- $Revision: 1.21 $ -->
<chapter id="security">
<title>ã»ãã¥ãªãã£</title>
@@ -616,67 +616,68 @@
</sect2>
<sect2 id="security.database.sql-injection">
- <title>SQL Injection</title>
+ <title>SQLã®çºè¡</title>
<simpara>
- Many web developers are unaware of how SQL queries can be tampered with,
- and assume that an SQL query is a trusted command. It means that SQL
- queries are able to circumvent access controls, thereby bypassing standard
- authentication and authorization checks, and sometimes SQL queries even
- may allow access to host operating system level commands.
- </simpara>
- <simpara>
- Direct SQL Command Injection is a technique where an attacker creates or
- alters existing SQL commands to expose hidden data, or to override valuable
- ones, or even to execute dangerous system level commands on the database
- host. This is accomplished by the application taking user input and
- combining it with static parameters to build a SQL query. The following
- examples are based on true stories, unfortunately.
+
å¤ãã®éçºè
ã¯SQLã¯ã¨ãªãã©ã®ããã«æ¹ç«ããããã¨ãããã¨ãä½ã
+
æ°ã«ããã¦ããããã¾ãSQLã¯ã¨ãªã¯ä¿¡ç¨ã§ãããã®ã¨èãã¦ããããã§ãã
+
å®éã«ã¯SQLã¯ã¨ãªã¯ã¢ã¯ã»ã¹å¶éãåé¿ãããã¨ãå¯è½ã§ãå¾ã£ã¦
+
é常ã®èªè¨¼ã権éã®ãã§ãã¯ãç¡è¦ãããã¨ãã§ãã¾ããæã«ã¯ã
+
OSã¬ãã«ã®ã³ãã³ããå®è¡ã§ãã¦ãã¾ããã¨ãããã¾ãã
+ </simpara>
+ <simpara>
+ Direct SQL Command
Injection(SQLã³ãã³ãã®ç´æ¥å®è¡)ã¨ããææ³ã¯ã
+
æ»æè
ãSQLã³ãã³ããçæãããã¯æ¢åã®ã³ãã³ãã夿´ãããã¨ã§
+
é è½ãã¹ããã¼ã¿ãå
¬éããããéè¦ãªãã¼ã¿ãæ¸ãæãããããã¼ã¿ãã¼ã¹
+
ãã¹ãã§å±éºãªã·ã¹ãã ã¬ãã«ã®ã³ãã³ããå®è¡ããããããã®ã®äºã§ãã
+
ãã®ææ³ã¯ãã¦ã¼ã¶ããã®å
¥åãã¹ã¿ãã£ãã¯ãªãã©ã¡ã¼ã¿ã¨çµã¿åããã¦
+
SQLã¯ã¨ãªãçæããã¢ããªã±ã¼ã·ã§ã³ã«ããã¦ä½¿ç¨ããã¾ãã以ä¸ã®ä¾ã¯
+
ä¸å¹¸ãªãã¨ã«å®éã®äºä¾ã«åºã¥ãããã®ã§ãã
</simpara>
<para>
- Owing to the lack of input validation and connecting to the database on
- behalf of a superuser or the one who can create users, the attacker
- may create a superuser in your database.
+
å
¥åã®ãã§ãã¯ãæ ã£ã¦ãããã¹ã¼ãã¼ã¦ã¼ã¶ãããã¯ãã¼ã¿ãã¼ã¹ä½ææ¨©éã
+
æã¤ã¦ã¼ã¶ä»¥å¤ã®ã¦ã¼ã¶ã§ãã¼ã¿ãã¼ã¹ã«æ¥ç¶<emphasis>ãã¦ããªã</emphasis>
+
ããã«ãæ»æè
ã¯ãã¼ã¿ãã¼ã¹ã«ã¹ã¼ãã¼ã¦ã¼ã¶ã使ãããã¨ãåºæ¥ã¾ãã
<example>
<title>
- Splitting the result set into pages ... and making superusers
- (PostgreSQL and MySQL)
+ 表示ãããã¼ã¿ãåå²ã ...
ããã¦ã¹ã¼ãã¼ã¦ã¼ã¶ã使ãã¾ãã
+ (PostgreSQLã¨MySQLã®ä¾)
</title>
<programlisting role="php">
<![CDATA[
-$offset = argv[0]; // beware, no input validation!
+$offset = argv[0]; //
å
¥åãã§ãã¯ãè¡ããã¦ãã¾ããï¼
$query = "SELECT id, name FROM products ORDER BY name LIMIT 20 OFFSET $offset;";
-// with PostgreSQL
+// PostgreSQLã®å ´å
$result = pg_exec($conn, $query);
-// with MySQL
+// MySQLã®å ´å
$result = mysql_query($query);
]]>
</programlisting>
</example>
- Normal users click on the 'next', 'prev' links where the
<varname>$offset</varname>
- is encoded into the URL. The script expects that the incoming
- <varname>$offset</varname> is decimal number. However, someone tries to
- break in with appending <function>urlencode</function>'d form of the
- following to the URL
+
é常ã®ã¦ã¼ã¶ã¯ã<varname>$offset</varname>ãURLåãè¾¼ã¾ãã¦ãã
+
'次ã¸'ã¾ãã¯'åã¸'ãªã³ã¯ãã¯ãªãã¯ãã¾ããã¹ã¯ãªããã¯ãåãåã£ã
+
<varname>$offset</varname>ãæ°åã§ãããã¨ãæå¾
ãã¾ããããããªããã
+
æ»æè
ã¯<function>urlencode</function>ããã以ä¸ã®ãããªURLã追å
+ ãããã¨ã§æ»æã試ã¿ã¾ãã
<informalexample>
<programlisting>
<![CDATA[
-// in case of PostgreSQL
+// PostgreSQLã®å ´å
0;
insert into pg_shadow(usename,usesysid,usesuper,usecatupd,passwd)
select 'crack', usesysid, 't','t','crack'
from pg_shadow where usename='postgres';
--
-// in case of MySQL
+// MySQLã®å ´å
0;
UPDATE user SET Password=PASSWORD('crack') WHERE user='root';
FLUSH PRIVILEGES;
]]>
</programlisting>
</informalexample>
- If it happened, then the script would present a superuser access to him.
- Note that <literal>0;</literal> is to supply a valid offset to the
- original query and to terminate it.
+
ãã®ãããªãã¨ãè¡ãããã¨ãã¹ã¯ãªããã¯æ»æè
ã«ã¹ã¼ãã¼ã¦ã¼ã¶æ¨©éã§ã®
+
ã¢ã¯ã»ã¹ãæä¾ãã¦ãã¾ãã¾ãã<literal>0;</literal>ãæ£ãããªãã»ãã
+
æãã¦ããã¨åæã«ãã¯ã¨ãªãããã§çµç«¯ããã¦ãããã¨ã«æ°ãã¤ãã¦ä¸ããã
</para>
<note>
<para>