ã¡ãã£ã¢èšäº
ã»ãã¥ãªãã£ã³ãŒãã¯ãçæéä¿æããŠããããã¡ã¿ããã¹äžæ£ã¢ã¯ã»ã¹åé¡ã®çµç·¯ãå瀟ã«èã
ããºãææ°ããŒã¯ 99
twitterã³ã¡ã³ã 76ä»¶äž 1ïœ76ä»¶
ä¿åãã¡ããã¡âçæéãªããšã·ïŒ
ã£ãŠèšèšããããã¡ã§ãã
ã£ãŠèšèšããããã¡ã§ãã
ã¡ã¿ããã¹ã«é»è©±ãããïŒæéãªãã»ãã¥ãªãã£ã³ãŒãã®ä¿åãããã®ã¯èš±ãããŠããã¿ãããªèª¬æãããã®ã ãã©ãæ¬åœïŒ
æ°ã«ãªã仿¥ã®ãã¥ãŒã¹
é倧ãªãµã€ããŒæ»æãåããåœã©ã³ãã³ã° ãã³ããã¯ç±³åœãæ¥æ¬ã¯äœäœïŒ
é倧ãªãµã€ããŒæ»æãåããåœã©ã³ãã³ã° ãã³ããã¯ç±³åœãæ¥æ¬ã¯äœäœïŒ
ã¯ã¬ãžããã«ãŒãã®ã»ãã¥ãªãã£ã³ãŒããä¿åããŠããçããåºãŠããŸãã
ããããã ãšãããšãµãŒãã¹å©çšäŒæ¥ã»èªæ²»äœä»¥å€ã§äžæ£å©çšããããšããå¯èœæ§ãåºãŠããã®ã§ããã
ããããã ãšãããšãµãŒãã¹å©çšäŒæ¥ã»èªæ²»äœä»¥å€ã§äžæ£å©çšããããšããå¯èœæ§ãåºãŠããã®ã§ããã
ã¿ãŠã
æ°ã«ãªã仿¥ã®ãã¥ãŒã¹
é倧ãªãµã€ããŒæ»æãåããåœã©ã³ãã³ã° ãã³ããã¯ç±³åœãæ¥æ¬ã¯äœäœïŒ
é倧ãªãµã€ããŒæ»æãåããåœã©ã³ãã³ã° ãã³ããã¯ç±³åœãæ¥æ¬ã¯äœäœïŒ
èšäºäžã®DBãæã
ã®æ³åããDBãšçãããã©ãããäžæãªã®ã§äœãããããªãã
>2ã«æåŸããã©ã«å床PCI DSS審æ»ãè¡ãäºå®
>ã¡ã¿ããã¹ãã€ã¡ã³ãã®æ±ºæžåºç€ã䜿ã£ãŠããäŒæ¥ã»å£äœäžèЧã®å ¬è¡šäºå®ã¯ãªã
>4æããã©ã«ç€Ÿå ã®ã¬ããã³ã¹äœå¶ãçµç¹äœå¶ãç€Ÿå¡æèãªã©ã«ã€ããŠãšããŸãšã
å審æ»ã®çµæãåºããŸã§åŸ©æ§ããªããªããã¯
>ã¡ã¿ããã¹ãã€ã¡ã³ãã®æ±ºæžåºç€ã䜿ã£ãŠããäŒæ¥ã»å£äœäžèЧã®å ¬è¡šäºå®ã¯ãªã
>4æããã©ã«ç€Ÿå ã®ã¬ããã³ã¹äœå¶ãçµç¹äœå¶ãç€Ÿå¡æèãªã©ã«ã€ããŠãšããŸãšã
å審æ»ã®çµæãåºããŸã§åŸ©æ§ããªããªããã¯
æ±ºæžæžã¿ã®ã¯ã¬ã«ã®CVV2/CVC2ãèªç€Ÿã«çœ®ãã®ããŸãã«é
·ãææ°ããããã¯ã¹ã§ãäŒç€Ÿã®äœè³ªã§ã¯ãã¡ã¿ããã¹ã決æžã«äœ¿ã£ãŠããæ³äººãç·ãããããªããšâŠ
èŠåºãã§ã¡ãã£ãšèª€è§£ã§ããã ãã©ãPCI DSS 3.2.1 ã®èŠä»¶3.2.2ã§ã¯"æ¿èªåŸã®ä¿å"ãNGãªã®ã§ãæ¿èªããããã«äžæçã«ä¿åããã®ã¯OKã ã£ãã¯ãããããŸã§äžæçã
ããŒãããããããªãæµåºãçŽåŸããã
ã©ããŸã§å
¬è¡šãããã®ãã¯ããããŸãããããã¯ãã¢ã®èšçœ®ååŸã§äœããã£ããã¯èå³ãããŸãããSQLã€ã³ãžã§ã¯ã·ã§ã³ã¯ããã¯ãã¢ã®èšçœ®åŸãããªãããšæããŸããæåã¯heartbreedã¿ããã«ã¡ã¢ãªãã匷å¶åãåºãããç³»ãããªãããªãšæããŸããæ³åã§ããã©èå³ãããŸãã
è匱æ§èšºæãäœãæ©èœããŠãªããŠèããšãããåéããæ°æºã
ãªã®ãæŽã«èïœ
PCI DSSçã«ã¯ã¢ãŠãã§ããâŠãŸãæããšããã¯ããããâŠ
ãããã«ãµããããªæ¡ä»¶ã ãªãã©ããªã£ã¡ãããã ããã
ããžããâŠâŠð±
POSTãããå€ãå
šéšã»ãã·ã§ã³ã«ä¿åããŠé·ç§»ããã¿ã€ãã®äœãã§ãDBã«ã»ãã·ã§ã³æ
å ±ãä¿åããããã©å€ããã®æ¶ããŠãªãã£ããšããªã®ã ãããã
å
šç¶ãã¡ããããäžçªæªãã®ã¯æ»æè
ã ãã©ãå管泚æçŸ©åéåã ãããããªãã
å¯©æ»æ©é¢ã圹ã«ç«ã£ãŠãªãã£ãã¿ããã
2ãæåŸã«PCI DSSå審æ»ã£ãŠãã£ãŠãäžæäžå€ã§çµãããªããšæãã®ã§ãå¥ã®æ±ºæžæ¥è æ¢ããæ¹ãè¯ããããã
2ãæåŸã«PCI DSSå審æ»ã£ãŠãã£ãŠãäžæäžå€ã§çµãããªããšæãã®ã§ãå¥ã®æ±ºæžæ¥è æ¢ããæ¹ãè¯ããããã
ãã¡ã¿ããã¹ãã€ã¡ã³ãã§ã¯ãæ¿èªåŠçã®éãããŒã¿ããŒã¹ã«ã»ãã¥ãªãã£ã³ãŒããçæéä¿æããŠããããšããã
審æ»éããæ¥è
ã®å»æ¥åœä»€ãå¿
èŠãªã®ã§ã¯
>
>
äºã¶æã§å¯ŸçããŠPCI DSSå審æ»ãšãçäžãããžã§ã¯ãã®åãããããªããã»ãã¥ãªãã£ã³ãŒãä¿åãã€ãããšæã£ãŠãªãã£ããªããŸãã¯äœãæ¹åãã¹ããèªèããããŒã ã«ããªããšãŸãåçºãããã ãã
æ°ã«ãªã仿¥ã®ãã¥ãŒã¹
æ¥æ¬èµ€åå瀟ã§ã¯ã¬ã«æ å ±æå€§çŽ5000ä»¶æµåºã®å¯èœæ§ ã¡ã¿ããã¹äžæ£ã¢ã¯ã»ã¹ã«å·»ã蟌ãŸã
æ¥æ¬èµ€åå瀟ã§ã¯ã¬ã«æ å ±æå€§çŽ5000ä»¶æµåºã®å¯èœæ§ ã¡ã¿ããã¹äžæ£ã¢ã¯ã»ã¹ã«å·»ã蟌ãŸã
ã€ãã
> ã¡ã¿ããã¹ãã€ã¡ã³ãã¯èšªå審æ»ãšãã¢ããªã±ãŒã·ã§ã³è匱æ§èšºæã幎ã«1åããããã¯ãŒã¯è匱æ§èšºæãååæã«1å宿œããŠãããšããã
PCI DSSã®ä¿¡é Œæ§ã®å±æ©ã§ã¯âŠ
PCI DSSã®ä¿¡é Œæ§ã®å±æ©ã§ã¯âŠ
ããPCI DSSãã§ã¯ãã»ãã¥ãªãã£ã³ãŒããå«ããæ©å¯èªèšŒããŒã¿ãã«ã€ããŠãã«ãŒãã®æ¿èªåŠçåŸã¯æå·åããŠããŠãä¿åããŠã¯ãªããªããšå®ããããŠããã
ãã¯ã¬ãžããã«ãŒã決æžåºç€ãæäŸããã¡ã¿ããã¹ãã€ã¡ã³ãïŒæ±äº¬éœæž¯åºïŒã§ãã»ãã¥ãªãã£ã³ãŒããå«ãã«ãŒãæ
å ±ãæµåºããå¯èœæ§ããä¿åããŠã¯ãããªãã¯ãã®ããŒã¿ãä¿åããŠããã®ãïŒã
æ§ããã«èšã£ãŠã¯ãœ
ã¿ãŠãïŒ
åŒçšïŒã¡ã¿ããã¹ãã€ã¡ã³ãã§ã¯ãæ¿èªåŠçã®éãããŒã¿ããŒã¹ã«ã»ãã¥ãªãã£ã³ãŒããçæéä¿æããŠããã
ã²ã§ãã
ãããPCI DSS ããã説æå¿
èŠã§ããããSQLã€ã³ãžã§ã¯ã·ã§ã³ãæ€ç¥ã§ããªãè匱æ§èšºæã£ãŠäœã®æå³ãããã®ïŒ
å¯©æ»æ©é¢ã®è²¬ä»»ã¯ïŒ
>ã¡ã¿ããã¹ãã€ã¡ã³ãã¯èšªå審æ»ãšãã¢ããªã±ãŒã·ã§ã³è匱æ§èšºæã幎ã«1åããããã¯ãŒã¯è匱æ§èšºæãååæã«1å宿œããŠãããšããã
>ã¡ã¿ããã¹ãã€ã¡ã³ãã¯èšªå審æ»ãšãã¢ããªã±ãŒã·ã§ã³è匱æ§èšºæã幎ã«1åããããã¯ãŒã¯è匱æ§èšºæãååæã«1å宿œããŠãããšããã
çæéïŒçæéïŒæ¿èªåŠçéå®ïŒ
ã§æžãäºãªã®ãïŒð€
>
ã§æžãäºãªã®ãïŒð€
>
ãã»ãã¥ãªãã£ã³ãŒãã¯çæéä¿æããŠããã
çæéã§æ¶ããããã«äœããªãéãã¯æ¶ããªãã®ã§ãä¿æããŠã¯ãããªãããšãèªèããäžã§ã®ç¢ºä¿¡ç¯çèšèšïŒ
ã¡ã¿ããã¹äžæ£ã¢ã¯ã»ã¹åé¡ã®çµç·¯ãå瀟ã«èã
çæéã§æ¶ããããã«äœããªãéãã¯æ¶ããªãã®ã§ãä¿æããŠã¯ãããªãããšãèªèããäžã§ã®ç¢ºä¿¡ç¯çèšèšïŒ
ã¡ã¿ããã¹äžæ£ã¢ã¯ã»ã¹åé¡ã®çµç·¯ãå瀟ã«èã
ä¿åããŠãçç±ãæå³äžæã
çŽ äººãããŒã¿ããŒã¹å
¥éã¿ãããªæ¬èªã¿ãªããäœã£ããµãŒãã¹ãªããïŒïŒw
çæéã§ãä¿åãã¡ãã ããªãã€ã ãã
ä¿æããŠããããããâŠ
PCIDSSã£ãŠççã§èªèšŒããããã€ã æããã
ãŸããµããããªãããªãã§ã»ãã¥ãªãã£ã³ãŒããä¿åããŠããã ãã
äžæ£å©çšãããããã«ãŒãæ¢ããªããã§ãããããªãµãŒãã¹ã§åŒãèœãšãæ å ±ã®å€æŽããªãããããªããŠãã¡ããã¡ãããã©ãã ã£ããã
ããã§PCI DSSèªèšŒå¥å¥ªãããªããªãããªãã®ããã®å¯©æ»ãªã®ãã
äžæ£å©çšãããããã«ãŒãæ¢ããªããã§ãããããªãµãŒãã¹ã§åŒãèœãšãæ å ±ã®å€æŽããªãããããªããŠãã¡ããã¡ãããã©ãã ã£ããã
ããã§PCI DSSèªèšŒå¥å¥ªãããªããªãããªãã®ããã®å¯©æ»ãªã®ãã
ã©ãã©ããããåºãã
â
æ å ±ã»ãã¥ãªãã£åºæºâŠã§ã¯ãã»ãã¥ãªãã£ã³ãŒããå«ããæ©å¯èªèšŒããŒã¿ãã«ã€ããŠãã«ãŒãã®æ¿èªåŠçåŸã¯æå·åããŠããŠãä¿åããŠã¯ãªããªã
ã¡ã¿ããã¹ãã€ã¡ã³ãã§ã¯ãæ¿èªåŠçã®éãããŒã¿ããŒã¹ã«ã»ãã¥ãªãã£ã³ãŒããçæéä¿æããŠããã
â
æ å ±ã»ãã¥ãªãã£åºæºâŠã§ã¯ãã»ãã¥ãªãã£ã³ãŒããå«ããæ©å¯èªèšŒããŒã¿ãã«ã€ããŠãã«ãŒãã®æ¿èªåŠçåŸã¯æå·åããŠããŠãä¿åããŠã¯ãªããªã
ã¡ã¿ããã¹ãã€ã¡ã³ãã§ã¯ãæ¿èªåŠçã®éãããŒã¿ããŒã¹ã«ã»ãã¥ãªãã£ã³ãŒããçæéä¿æããŠããã
ä¿åããŠã¯ãããªãã¯ãã®ããŒã¿ããªãæµåºããã®ãïŒ
ããã¯ããã
ããã¯ããã
äžæ£ã¢ã¯ã»ã¹ã«é¢ãããå ±åãšãè©«ã³
ãªããš
äžæ£ã¢ã¯ã»ã¹ã®èª¿æ»çµæãç·åçãªã©é¢ä¿çåºã«æåºããæžé¡ãã¡ã¿ããã¹ãã€ã¡ã³ãã®æ±ºæžåºç€ã䜿ã£ãŠããäŒæ¥ã»å£äœäžèЧãªã©ã®å
¬è¡šäºå®ã¯ãªãã
æ
å ±ã»ãã¥ãªãã£åºæºãPCI DSSãã§ã¯ãã»ãã¥ãªãã£ã³ãŒããå«ããæ©å¯èªèšŒããŒã¿ãã«ã€ããŠãã«ãŒãã®æ¿èªåŠçåŸã¯æå·åããŠããŠãä¿åããŠã¯ãªããªããšå®ããããŠãã
ãæ¿èªåŠçã®éãããŒã¿ããŒã¹ã«ã»ãã¥ãªãã£ã³ãŒããçæéä¿æããŠããã
ãã®ãããªç®¡çäœå¶ã§ã¯ãPCI DSSãã®ä¿¡é Œæ§ã«ãé¢ããã®ã§ã¯ïŒ
çæéãšãããããåé¡ãããªããªãïŒPCIDSSããã£ããª
ããããããšã£ãã
äžçºã¢ãŠãæ¡ä»¶ã§ã¯ïŒ
ããã§ãPCI DSSãååŸèªãããªãããã®äŸ¡å€ã¯ç¡ãã§ããã
ããã§ãPCI DSSãååŸèªãããªãããã®äŸ¡å€ã¯ç¡ãã§ããã
ã¡ã¿ããã¹ãã€ã¡ã³ãããã£ã±ãã»ãã¥ãªãã£ã³ãŒããããŒã¿ããŒã¹ã«ä¿åããŠãããã ãPCI DSSã®èªèšŒã¯åã£ãŠãããããã
ITæè¡è ã®èŠç¹ã ãšãšãã§ããªãäºä»¶ã ãšæãããæ ªäŸ¡ãç¡åå¿ãªã®ã¯ãªããšãäžæè°ããããGMOPGã ã£ãããŸãéã£ãåå¿ã«ãªã£ãŠããããªæ°ãããã
ITæè¡è ã®èŠç¹ã ãšãšãã§ããªãäºä»¶ã ãšæãããæ ªäŸ¡ãç¡åå¿ãªã®ã¯ãªããšãäžæè°ããããGMOPGã ã£ãããŸãéã£ãåå¿ã«ãªã£ãŠããããªæ°ãããã
ãä¿ææéã¯éå
¬éã ããé·æéä¿åããŠããäºå®ã¯ãªããããã®èŸºã¯ãã©ãè§£éãããã®ãæ°ã«ãªããšãã
ã€ããã â
ä¿ææéã¯éå
¬éã ããé·æéä¿åããŠããäºå®ã¯ãªãã
ãããã説æã£ãŠé¢çœãããª
éå ¬éâŠ
ã©ããŸã§ãçæéã§ã©ããããé·æéãªãã ãã
誰ãçæé·æã決ããŠããã ãã
ãããã説æã£ãŠé¢çœãããª
éå ¬éâŠ
ã©ããŸã§ãçæéã§ã©ããããé·æéãªãã ãã
誰ãçæé·æã決ããŠããã ãã
ããã»ã»ããã»ã»ð¥µ
PCI-DSSã®å¯©æ»ãããäŒæ¥ãNW/APPè匱æ§èšºæãããäŒæ¥ããã³ã³ãã ã£ãã£ãŠããšãã
ãã ãµã³ïŒïŒ
ãã ãµã³ïŒïŒ
ã¢ã«ã³ããããåãæœ°ãäžå¯é¿
"æ¿èªåŠçã®éãããŒã¿ããŒã¹ã«ã»ãã¥ãªãã£ã³ãŒããçæéä¿æããŠãã"<åŠçäžã¯ãããä¿æããŠãŸãã,ã£ãŠæå³ãªãããããããªãã ãã©,ã ã£ããã·ã¹ãã 䟵å
¥æã®ãçŽåã«ã䜿ãããã³ãŒããåç
§ã§ããªããªãïŒ
PCI DSSèªèšŒã®ååŸããŠãããã審æ»å
容ã忀æ»ããå¿
èŠããããããªãïŒ
âã¡ã¿ããã¹ãã€ã¡ã³ãã§ã¯ãæ¿èªåŠçã®éãããŒã¿ããŒã¹ã«ã»ãã¥ãªãã£ã³ãŒããçæéä¿æããŠããããšãããæ»æè
ã¯ãã·ã¹ãã 䟵å
¥æã®çŽåã«æ±ºæžã§äœ¿ãããæå·åãããã»ãã¥ãªãã£ã³ãŒããååŸã§ããç¶æ
ã«ãã£ããšã¿ãããâŠä¿ææéã¯éå
¬éâ
(ãâïœ)ïŸïœ¬ïœ°
âªããªãã
ãäžæ£ã¢ã¯ã»ã¹ã®èª¿æ»çµæãç·åçãªã©é¢ä¿çåºã«æåºããæžé¡ãã¡ã¿ããã¹ãã€ã¡ã³ãã®æ±ºæžåºç€ã䜿ã£ãŠããäŒæ¥ã»å£äœäžèЧãªã©ã®å
¬è¡šäºå®ã¯ãªããããšããããçµå±ãšã³ããŠãŒã¶ãŒã¯èªåã®ã¯ã¬ã«ã該åœãããã¯åãããªãã£ãŠããšïŒäžå®ãªãåçºè¡ããŠãã£ãŠïŒ
ç©ã¯èšãæ§ã ãã«ãŒã«éåããŠããã®ã¯çŽãããªãäºå®ãœãïœïŒãã¡ã¿ããã¹ãã€ã¡ã³ãã«ããã°ãä¿ææéã¯éå
¬éã ããé·æéä¿åããŠããäºå®ã¯ãªãããšããŠããã
ä¿åããŠã¯ãããªãããŒã¿ãä¿åããŠããã®ãïŒ
âé·æéä¿åããŠããäºå®ã¯ãªãâŠð€ïŒ
SQLã€ã³ãžã§ã¯ã·ã§ã³ïŒããŒã¿ããŒã¹ãäžæ£æäœïŒãããã¯ãã¢ã®èšçœ®çã®æ»æãåããŠãã
âé·æéä¿åããŠããäºå®ã¯ãªãâŠð€ïŒ
SQLã€ã³ãžã§ã¯ã·ã§ã³ïŒããŒã¿ããŒã¹ãäžæ£æäœïŒãããã¯ãã¢ã®èšçœ®çã®æ»æãåããŠãã
ïŒä»åã®äžæ£ã¢ã¯ã»ã¹ã§å瀟ã¯ãããŒã¿ããŒã¹ãäžæ£æäœãããSQLã€ã³ãžã§ã¯ã·ã§ã³ããããã¯ãã¢ã®èšçœ®ãªã©ã®æ»æãåããŠããã
SQLã€ã³ãžã§ã¯ã·ã§ã³ãã
SQLã€ã³ãžã§ã¯ã·ã§ã³ãã
PCI DSSèªå®ååŸã¯ç°¡åãªäºãããªããã ãã©ããâŠãSQLã€ã³ãžã§ã¯ã·ã§ã³ã ã£ãŠå çåºãªããšããã(æ¬åœã¯é§ç®ã ãã©)ãµãŒãã¹æäŸè²¬ä»»è
ãªèš³ã ããªã⊠ã
éå»åœ¢ãšããããšã¯ã»ãã¥ãªãã£ã³ãŒããä¿åããªãæ¹ä¿®ãšä¿åãããŠããã»ãã¥ãªãã£ã³ãŒãã®åé€ã¯å®äºããŠãããšããããšãªã®ããªïŒâ
ãä¿ææéã¯éå
¬éã ããé·æéä¿åããŠããäºå®ã¯ãªãããšããŠããã
CVVã®æµãããšãããæžãæãããããã¿ãŒã³ããšæã£ãŠããã©ããä¿ææéã¯éå ¬éãã§DBã«å ¥ããŠãã®ã¯å°è±¡æªãã
CVVã®æµãããšãããæžãæãããããã¿ãŒã³ããšæã£ãŠããã©ããä¿ææéã¯éå ¬éãã§DBã«å ¥ããŠãã®ã¯å°è±¡æªãã
ããããªïŒ
å
šç¢ºä¿æ¯æŽå£«NEWS
æçš¿æé:2022-03-02 14:03:03
ãIT media Newsã
ãããããããŠé£ä¿åºç€ã«äžæçã«çœ®ãããããŒã¿ã®ããšãæããŠãããã»ã»ã»ïŒ