ã¯ããã« 2021å¹´12æã«çºè¦ãããLog4jã®CVE-2021-44228ã¯ãç¨ã«è¦ãã¬ãã«ãã¾ãã«è¶ 弩ç´ã®èå¼±æ§ã¨ãªã£ã¦ãã¾ããä»åãç§ã¯Twitterã主ãªè¶³ãããã¨ãã¦æ å ±åéãè¡ãã¾ãããã(è±èªã»æ¥æ¬èªã©ã¡ãã«ããã¦ã)ããªãWAFãã®ãã®ã話é¡ã«ãªã£ã¦ãããã¨ã«é©ãã¾ããããã人ã¯ãWAFãæ©é対å¿ãã¦ãããããå®å¿ã ï¼ãã¨å«ã³ãå¥ã®äººã¯ãWAFãåé¿ã§ããé£èªåã®æ¹æ³ãè¦ã¤ãã£ããWAFã¯å½¹ã«ç«ããªãï¼ãã¨ä¸»å¼µãããããã«ã¯GitHubã«ãWAFãåé¿ã§ãããã¤ãã¼ã(æ»ææåå)ä¸è¦§ããã¢ãããã¼ããããããã«ã¤ãã¦ãScutumã§ã¯ãã®ãã¿ã¼ã³ãæ¢ã¾ãã¾ããï¼ãã¨åãåãããæ¥ããªã©ãããªãWAFã§ã®é²å¾¡ã¨ãã®åé¿æ¹æ³ã«ã¤ãã¦æ³¨ç®ãéã¾ãã¾ããã å®ã¯WAFã«ããã¦ã¯ããåé¿(Evasionãããã¯Bypass)ãã¨ã®æ¦ãã¯æ°¸é ã®ãã¼ãã§ããããã¯ä»åLog4jã®ä»¶ã§
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}