¡Ú¡¡PHP¤ÏCGI¤«?¡¡¡Û

¡¡PHP¡ÊHyperText Preprocessor¡Ë¤ÏWEBÍѤ˳«È¯¤µ¤ì¤¿¥¹¥¯¥ê¥×¥È¸À¸ì¤Ç¡¢HTML¥Õ¥¡¥¤¥ëÆâ¤Ë¥×¥í¥°¥é¥à¤òµ½Ò¤·¡¢¥µ¡¼¥Ð¡¼¥µ¥¤¥É¤Çưºî¤·¤Þ¤¹¡£¥â¥¸¥å¡¼¥ëÈǤξì¹ç¤Ï¡¢perl¤Î¤è¤¦¤Ë³°Éô£Ã£Ç£É¤ò¸Æ¤Ó½Ð¤¹¥×¥í¥»¥¹¤¬¤Ê¤¤¤¿¤á½èÍý¤¬·Ú¤¯¡¢¤Þ¤¿£Ã£Ç£É¤È¤·¤Æ¤Ç¤Ê¤¯Apache¤Î¥â¥¸¥å¡¼¥ë¤È¤·¤ÆÆ°ºî¤¹¤ë¤³¤È¤Ç½èÍý¤¬¹â®¤Ë¤Ê¤ê¤Þ¤¹¡££×£Å£Â¥µ¡¼¥Ð¡¼¤Ç¤Îưºî¤Ë£Ã£Ç£ÉÈǤȥ⥸¥å¡¼¥ëÈǤΰ㤤¤¬¤¢¤ë¤¿¤á¡¢PHP¤Çºî¤é¤ì¤¿¥Ú¡¼¥¸¤¬°ì³µ¤ËCGI¤È¤Ï¸Æ¤Ù¤ë¤ï¤±¤Ç¤Ï¤¢¤ê¤Þ¤»¤ó¡£¡ÊÅö¥µ¥¤¥È¤Ç¤Ï±ÜÍ÷¼Ô¤Îº®Íð¤òÈò¤±¤ë¤¿¤á¤ËÁ´¤ÆCGI¤È¤¤¤¦É½µ¤ò¤·¤Æ¤¤¤Þ¤¹¡£¡Ë
¡¡ ¡ØCGI¡Ù¤È¤ÏWEB¥¢¥×¥ê¥±¡¼¥·¥ç¥ó¤Î¤³¤È¤À¤È»×¤Ã¤Æ¤¤¤ëÊý¤â¤¤¤ë¤è¤¦¤Ç¤¹¤¬¡¢¼ÂºÝ¤Ë¤ÏWEB¥µ¡¼¥Ð¡¼¤¬³°Éô¥×¥í¥°¥é¥à¤ò¸Æ¤Ó½Ð¤¹¤·¤¯¤ß¤Î¤³¤È¤ò¤¤¤¤¤Þ¤¹¡£
¡Ú¡¡WEB¥µ¡¼¥Ð¤Ë¤Ä¤¤¤Æ¡¡¡Û
¡¡PHP¤ÇºîÀ®¤µ¤ì¤¿¥Õ¥¡¥¤¥ë¤òư¤«¤¹¤Ë¤Ï¡¢¤´ÍøÍѤΥµ¡¼¥Ð¤ÇPHP¤Î»ÈÍѤ¬²Äǽ¤Ç¤¢¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£PHP¤ÏÁ°½Ò¤·¤¿¤è¤¦¤Ë¥â¥¸¥å¡¼¥ëÈǤÈCGIÈǤ¬¤¢¤ê¡¢CGIÈǤξì¹ç¤Ç¤Ï¥µ¡¼¥Ð¤Ë¤è¤Ã¤Æ¤Ï¥×¥í¥°¥é¥à¥Õ¥¡¥¤¥ë¤Î³ÈÄ¥»Ò¤ò.cgi¤Ë¤·¤ÆPHP¤Î¥Ñ¥¹¤ò³Æ¥Õ¥¡¥¤¥ë¤ËµÆþ¤¹¤ëɬÍפ¬¤¢¤ë¾ì¹ç¤¬¤¢¤ê¤Þ¤¹¡£¤Þ¤¿CGIÈǤξì¹ç¤ÇsuEXEC¤¬Æ°ºî¤·¤Æ¤¤¤ë¾ì¹ç¤Ï¥Ç¡¼¥¿¥Õ¥¡¥¤¥ë¤ä¥Õ¥©¥ë¥À¤Î¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó¤ò½êͼԤΤ߸¢¸Â¤Ç¼Â¹Ô²Äǽ¤Î¤¿¤á¥»¥¥å¥ê¥Æ¥£¤ò¹â¤á¤ë¤³¤È¤¬¤Ç¤¤Þ¤¹¡£¥µ¡¼¥Ð¡¼¤ÇsuEXEC¤¬Æ°ºî¤·¤Æ¤¤¤¿¤È¤·¤Æ¤â¥â¥¸¥å¡¼¥ëÈǤξì¹ç¤Ç¤Ï͸ú¤Ë¤Ê¤ê¤Þ¤»¤ó¡¢¤è¤Ã¤Æ¥â¥¸¥å¡¼¥ëÈǤξì¹ç¤Ï.dat¤ä.log¤Ê¤É¤Î¥Ç¡¼¥¿¥Õ¥¡¥¤¥ë¤òÂè»°¼Ô¤«¤é¤Î±ÜÍ÷¤Ç¤¤Ê¤¤¤è¤¦¤Ë¤¹¤ë¤¿¤á¤Ë.htaccess¤ÎÀßÃÖ¤¬²Äǽ¤Ç¤¢¤ì¤ÐÀßÃÖ¤¹¤ë¤³¤È¤¬Ë¾¤Þ¤·¤¤¤Ç¤·¤ç¤¦¡£
¡¡PHP¤ÇºîÀ®¤µ¤ì¤¿¥×¥í¥°¥é¥à¤ÏCGIÈǤǤâ¥â¥¸¥å¡¼¥ëÈÇ¤Ç¤âÆ°¤¤Þ¤¹¤¬¡¢¥»¡¼¥Õ¥â¡¼¥É¤ÇÀ©¸Â¤µ¤ì¤Æ¤¤¤ë¾ì¹ç¤Ï¥µ¡¼¥Ð¡¼Æâ¤Ç¥Õ¥¡¥¤¥ë¤ÎºîÀ®¤äºï½ü¤¬¤Ç¤¤Ê¤¤¤¿¤á¡¢¼Â¹Ô¤Ç¤¤ë¥×¥í¥°¥é¥à¤¬ÂçÉý¤Ë¸ÂÄꤵ¤ì¤Æ¤·¤Þ¤¤¤Þ¤¹¡£¥»¡¼¥Õ¥â¡¼¥É¤ÇÀ©¸Â¤µ¤ì¤¿¥µ¡¼¥Ð¤ÇPHP¤ò»ÈÍѤ¹¤ë¤³¤È¤ÏÂ礤ʾ㳲¤È¤Ê¤Ã¤Æ¤·¤Þ¤¦¤Ç¤·¤ç¤¦¡£

¡¡CGIÈǤȥ⥸¥å¡¼¥ëÈǤȤǤϤɤäÁ¤¬¤¤¤¤¤Î¤«¤È°ì³µ¤Ë¸À¤¨¤Þ¤»¤ó¡£¡£¥â¥¸¥å¡¼¥ëÈǤÎPHP¤Î¤Û¤¦¤¬¼Â¹Ô¤ÎÉé²Ù¤¬Ä㤯®Å٤⮤¤¤Î¤ÇÌ¥ÎÏŪ¤Ç¤¹¤¬¡¢suEXEC¤Îưºî¤·¤Æ¤¤¤ë¥µ¡¼¥Ð¤Ç¤ÎCGIÈǤÏÀßÃ֤䥻¥¥å¥ê¥Æ¥£¤ÎÌ̤ǤȤƤ⤤¤¤¤Ç¤¹¡£·Ð¸³¾å¤Ç¤¤¤¨¤ÐCGIÈǤǤâÂç¤¤Ê¥×¥í¥°¥é¥à¤Ç¤Ê¤¤¸Â¤êÃÙ¤¤¤È¤Ï´¶¤¸¤Þ¤»¤ó¡£·ë¶É¤Ï¥µ¡¼¥Ð¤Î²óÀþ®Å٤䥯¥é¥¤¥¢¥ó¥È¤Î²óÀþ®Å٤˰͸¤·¤Æ¤¤¤ëÉôʬ¤¬Â礤¤¤È»×¤¤¤Þ¤¹¡£
¡¡ÍøÍѤ·¤Æ¤¤¤ë¥µ¡¼¥Ð¡¼¤ÎPHP¤Îưºî³Îǧ¤È¤½¤Î´Ä¶¤òÄ´¤Ù¤ë¤¿¤á¤Ë¡¡<?php phpinfo() ?>¡¡¤òµÆþ¤·¤¿PHP¥Õ¥¡¥¤¥ë¡ÊÎã¡§info.php¡Ë¤ò¥µ¡¼¥Ð¡¼¾å¤ÎǤ°Õ¤Î¾ì½ê¤ØÀßÃÖ¤·É½¼¨¤µ¤»¤Æ¤¯¤À¤µ¤¤¡£phpinfo¤Î¸«Êý¤Ë¤Ä¤¤¤Æ¤ÏÊ̤ξϤÇÀâÌÀ¤·¤Þ¤¹¡£
¡Ú¡¡¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó¤ÎÀßÄê¡¡¡Û
¢¡¡¡1¡¥¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó¤ÎÀßÄê¤ÏÀßÃÖ¤¹¤ë¥Õ¥¡¥¤¥ë¤Î¼ïÎà¤ÈÍÑÅӤˤè¤Ã¤Æ°Ê²¼¤Î¤è¤¦¤ËÀßÄꤷ¤Þ¤¹¡£
¡¦³ÈÄ¥»Ò¤¬¡¡.php .css .js |
[644] |
¥¢¥¹¥¡¼¥â¡¼¥É |
¡¦³ÈÄ¥»Ò¤¬¡¡.dat |
[644] or [666] |
¥¢¥¹¥¡¼¥â¡¼¥É |
¡¦³ÈÄ¥»Ò¤¬ .gif .jpeg .jpg |
[644] |
¥Ð¥¤¥Ê¥ê¥â¡¼¥É |
¡¦¥Õ¥©¥ë¥À |
[755] or [777] |
|
¥µ¡¼¥Ð¡¼Æâ¤Î¥°¥ë¡¼¥×¤«¤é¤Î±ÜÍ÷¤òµñÈݤ¹¤ë¤¿¤á¤Ë[606][604][705][707]¤ËÀßÄꤹ¤ë¤³¤È¤ò¤ªÁ¦¤á¤·¤Þ¤¹¡£
¢¨¥µ¡¼¥Ð¡¼¤Ë¤è¤Ã¤Æ¤Ï¤³¤Î¥°¥ë¡¼¥×¸¢¸Â¤ò̵¤¯¤¹¡Ê0¤Ë¤¹¤ë¡Ë¤Èưºî¤·¤Ê¤¤¾ì¹ç¤¬¤¢¤ê¤Þ¤¹¡£
µÕ¤Ë¥°¥ë¡¼¥×¸¢¸Â¤ò̵¤¯¤µ¤Ê¤¤¤Èưºî¤·¤Ê¤¤¾ì¹ç¤â¤¢¤ê¤Þ¤¹¡£
¢¡¡¡£²¡¥£Ã£Ç£ÉÈǤΣУȣФÇsuEXEC¤¬Æ°ºî¤·¤Æ¤¤¤ë¥µ¡¼¥Ð¡¼¤Î¾ì¹ç¾åµ¤ÎÀßÄê¤Ç¤Ïư¤¤Þ¤»¤ó¡£
°Ê²¼¤Î¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó¤ËÊѹ¹¤·¤Æ¤¯¤À¤µ¤¤¡£
[666] ¢ª [600]
[644] ¢ª [604] or [600]
[755] ¢ª [700] or [701]
[777] ¢ª [705] or [700] or [701]
¢¨suEXEC¤¬Æ°ºî¤·¤Æ¤¤¤Ê¤¤´Ä¶¤Î¾ì¹ç¤Ï¥í¥°¥Õ¥¡¥¤¥ë¡Ê*.dat *.log¡Ë¤ò¸«¤é¤ì¤Ê¤¤¤è¤¦¤Ë¡¢¥Õ¥©¥ë¥ÀÆâ¤Ë.htaccess¤ò
¡¡ÀßÃÖ¤·¤Æ¤¯¤À¤µ¤¤¡£
¡Ú¡¡.htaccess¤ÎÀßÃÖ¡¡¡Û
¡¡£Ã£Ç£É¤ÇÆÉ¤ß½ñ¤¤µ¤ì¤ë¥í¥°¥Õ¥¡¥¤¥ë¤Ê¤É¤Ï¡¢¥Ö¥é¥¦¥¶¤«¤éľÀÜ¥Õ¥¡¥¤¥ë¤ò¥¢¥¯¥»¥¹¤¹¤ë¤³¤È¤Ç¸«¤ë¤³¤È¤¬¤Ç¤¤Æ¤·¤Þ¤¤¤Þ¤¹¡£¤³¤ì¤òËɻߤ¹¤ë¤¿¤á¤ÎÊýË¡¤Î¤Ò¤È¤Ä¤È¤·¤Æ.htaccess¤ÎÀßÃÖ¤¬¤¢¤ê¤Þ¤¹¡£.htaccess¤Ï¥µ¡¼¥Ð¡¼Æâ¤ËÀßÃÖ¤¹¤ë¤³¤È¤Ç¥Õ¥¡¥¤¥ë¤ä¥Õ¥©¥ë¥À¤ËÂФ¹¤ë¥¢¥¯¥»¥¹¤ÎÀ©¸Â¤ò¤«¤±¤ë¤³¤È¤¬¤Ç¤¤Þ¤¹¡£ÀßÃÖ¤µ¤ì¤¿.htaccess¤ÎÆâÍÆ¤Ï¥Õ¥©¥ë¥À¤È¤½¤Î²¼ÁØ¥Õ¥©¥ë¥ÀÆâ¤Ç͸ú¤Ë¤Ê¤ê¤Þ¤¹¡£¤µ¤é¤Ë²¼ÁØ¥Õ¥©¥ë¥À¤Ø.htaccess¤òÀßÃÖ¤·À©¸Â¤òÄɲ乤뤳¤È¤¬¤Ç¤¤Þ¤¹¡£
¢¡.htaccess¤ÎºîÀ®¤ÈÀßÃÖ
¥Æ¥¥¹¥È¥¨¥Ç¥£¥¿¤ò»ÈÍѤ·¤Æ°Ê²¼¤ÎÍ͵Æþ¤¹¤ë¤³¤È¤Ç³ÈÄ¥»Ò¤¬.dat¡¢.log¤Î¥Õ¥¡¥¤¥ë¤È.htaccess¤ò¸«¤ì¤Ê¤¤¤è¤¦¤Ë¤·¤Þ¤¹¡£¥Õ¥¡¥¤¥ë̾¤ò.htaccess¤È¤·¤ÆÊݸ¤·¡¢¥µ¡¼¥Ð¡¼¤ØÀßÃÖ¤·¤Æ¤¯¤À¤µ¤¤¡£¡Ê¥Õ¥¡¥¤¥ë̾¤Ï¥µ¡¼¥Ð¡¼¤ØÀßÃÖ¸å¤ËÊѹ¹¤·¤Æ¤â·ë¹½¤Ç¤¹¡Ë
<Files ~ "\.dat$">
deny from all
</Files>
<Files ~ "\.log$">
deny from all
</Files>
<Files ~ "^\.htaccess$">
deny from all
</Files>
¢¨¥µ¡¼¥Ð¤Ë¤è¤Ã¤Æ¤Ï¤³¤Î.htaccess¤ÎÀßÃÖ¤òÀ©¸Â¤µ¤ì¤Æ¤¤¤ë¾ì¹ç¤¬¤¢¤ê¤Þ¤¹¡£
¡Ú¡¡phpinfo()¤Î¹àÌÜ¡¡¡Û
php¤Î´Ä¶¤ò³Îǧ¤¹¤ë¤Ë¤Ï¡¡<?php phpinfo() ?>¡¡¤òµÆþ¤·¤¿PHP¥Õ¥¡¥¤¥ë¡ÊÎã¡§info.php¡Ë¤ò¥µ¡¼¥Ð¤ØÀßÃÖ¤·¥¢¥¯¥»¥¹¤·¤Þ¤¹¡£
¡Server API
¡¡£Ð£È£Ð¤Î£Ã£Ç£ÉÈǤȥ⥸¥å¡¼¥ëÈǤˤĤ¤¤Æ¤Ï¡ÖPHP¤Ï£Ã£Ç£É¡×¤Ç´û¤Ë½Ò¤Ù¤Þ¤·¤¿¤¬¡¢¤³¤Î¹àÌܤò³Îǧ¤·¤Æ¡Ö£Ã£Ç£É¡×¤Èµ¤µ¤ì¤Æ¤¤¤ë¾ì¹ç¤Ï£Ã£Ç£ÉÈǤǤ¹¡£¥â¥¸¥å¡¼¥ëÈǤǤ¢¤ì¤Ð¡ÖApache¡×¤Èµ¤µ¤ì¤Æ¤¤¤ë»ö¤È»×¤¤¤Þ¤¹¡££Ã£Ç£ÉÈǤǤâ¥â¥¸¥å¡¼¥ëÈÇ¤Ç¤âÆ±¤¸¤è¤¦¤Ë¥¹¥¯¥ê¥×¥È¤Ïưºî¤·¤Þ¤¹¤¬¡¢£Ã£Ç£ÉÈǤǤ¢¤ë¾ì¹ç¤Ï¥µ¡¼¥Ð´Ä¶¤Ë¹ç¤ï¤»¤¿¥Ñ¡¼¥ß¥Ã¥·¥ç¥ó¤Ç¤Ê¤±¤ì¤Ðưºî¤·¤Ê¤¤¤Î¤ÇÃí°Õ¤¬É¬ÍפǤ¹¡£
¡¡£Ã£Ç£ÉÈǤξì¹ç¤Ç¤ÏHTTPǧ¾Ú¤Ç»È¤¦¥°¥í¡¼¥Ð¥ëÊÑ¿ô($PHP_AUTH_USER¡¢ $PHP_AUTH_PW)¤¬»È¤¨¤Ê¤¤¤Î¤Ç¡¢´ÉÍý²èÌ̤إ¢¥¯¥»¥¹¤¹¤ë¾ì¹ç¤Ë¡¢¥Ñ¥¹¥ï¡¼¥ÉÆþÎϤΥÀ¥¤¥¢¥í¥°¤¬É½¼¨¤µ¤ì¤ë£Â£Á£Ó£É£Ãǧ¾Ú¤òÍøÍѤ·¤Æ¤¤¤ë¥¹¥¯¥ê¥×¥È¤Ï»È¤¨¤Þ¤»¤ó¡£Ê£¿ô¤Î´ÉÍý¥Õ¥¡¥¤¥ë¤Ø£±ÅÙ¤Îǧ¾Ú¤Ç¥¢¥¯¥»¥¹¤ò·«ÊÖ¤·¹Ô¤¦¾ì¹ç¤Ë°ÊÁ°¤ÏHTTPǧ¾Ú¤ò»È¤Ã¤Æ¤¤¤Þ¤·¤¿¤¬¡¢´Ä¶¤Ë¤è¤Ã¤Æ¤Ïưºî¤·¤Ê¤¤¤Î¤Ç¡¢º£¤Ç¤Ï¤Û¤È¤ó¤É¤Î¾ì¹ç¤Ë¥»¥Ã¥·¥ç¥ó¤Ë¤è¤ëǧ¾Ú¤ÇÀ©ºî¤·¤Æ¤¤¤Þ¤¹¡£Â¾¤Ë¤â¥¯¥Ã¥¡¼¤òÍøÍѤ·¤¿¤ê¡¢HTMLÆâ¤Î¥Õ¥©¡¼¥àÆâ¤Ç¤Î¼è¤ê²ó¤·¤Ê¤É¤¬¤¢¤ê¤Þ¤¹¤¬¡¢»È¤¦¤³¤È¤Ï¾¯¤Ê¤¤¤Ç¤¹¡£
¢
session.use_trans_sid
¡¡¥»¥Ã¥·¥ç¥ó¤Ï¥¯¥é¥¤¥¢¥ó¥È¤Î¥¯¥Ã¥¡¼¤¬Í¸ú¤Ê¾ì¹ç¤Ï¡¢¤½¤Î¾ðÊó¤ò¥¯¥Ã¥¡¼¤ËÊݸ¤·¡¢¥¯¥Ã¥¡¼¤¬Ìµ¸ú¤Ç¤¢¤ë¾ì¹ç¤Ï¥µ¡¼¥ÐÆâ¤ØÊݸ¤µ¤ì¤Þ¤¹¡£¥µ¡¼¥Ð¤ØÊݸ¤µ¤ì¤ë¾ì¹ç¤Ï¥»¥Ã¥·¥ç¥ó¾ðÊó¤ò£Õ£Ò£Ì¤ËÉղä·¤ÆÁ÷¤ëɬÍפ¬¤¢¤ê¤Þ¤¹¡£¤³¤Î¥¯¥Ã¥¡¼¤Î͸ú¡¦Ìµ¸ú¤ËÂФ·¤Æ¼«Æ°¤Ç£Õ£Ò£Ì¤Î½ñ¤´¹¤¨¤ò¹Ô¤¦¤«Èݤ«¤ÎÀßÄ꤬session.use_trans_sid¤Ç¤¹¡£¥Ç¥Õ¥©¥ë¥È¤Ç¤Ï͸ú¡ÊOn
Ëô¤Ï 1 ¡Ë¤Ë¤Ê¤Ã¤Æ¤¤¤ë¤Î¤Ç¡¢Í¸ú¤òÁ°Äó¤Ë¥¹¥¯¥ê¥×¥Èºî¤Ã¤Æ¤¤¤Þ¤¹¡£
¤Ä¤Å¤¯¡¥¡¥¡¥
|