FAQ¶
API ãã¹ã¶
ã©ã®ãã©ãããã©ãŒã ããµããŒããããŠããŸãã?¶
Mayhem API testing CLI (ã³ãã³ã ã©ã€ã³ ã€ã³ã¿ãŒãã§ã€ã¹) mapi
ã¯ã次ã®ãã©ãããã©ãŒã ã§åäœããŸãã
- Linux (64-bit)
- MacOS
- Windows (64-bit)
ã©ã®èšèªããµããŒããããŠããŸãã?¶
Mayhem 㯠Web API ãã¹ãã£ã³ããŸããmapi
CLI ãšåããããã¯ãŒã¯ããã¢ã¯ã»ã¹å¯èœãªããããAPI ãã©ã®èšèªã§äœæãããŠããŠãåé¡ãããŸããã
ãã詳现ãªåé¡ã«ã€ããŠã¯ãMayhem 㯠API ããè¿ãããã¹ã¿ãã¯ãã¬ãŒã¹ãåéã§ããŸãã API ããããã° ã¢ãŒãã§å®è¡ããå Žåã¯ã¹ã¿ãã¯ãã¬ãŒã¹ã®è¿åŽãæå¹åãã éçšã§ã¯ç¡å¹ã«ããã®ãäžè¬çã§ãã
ã¹ã¿ãã¯ãã¬ãŒã¹ã®è§£æãšåãã㊠SARIF çµæã¬ããŒãã䜿çšããããšã«ãã£ãŠã Mayhem 㯠GitHub / Visual Studio Code ãªã©ã®ããŒã«ãšããç·å¯ã«çµ±åã§ããŸãã
ã¹ã¿ãã¯ãã¬ãŒã¹è§£æã®ãµããŒã察象èšèªã«ã¯ä»¥äžãå«ãŸããŸãã
- python
- ruby
- java
- javascript
- go
- C#
Mayhem ã¯ã©ã®ãããªæ å ±ãåéããŸãã?¶
å人æ å ±
Mayhem ã«ãµã€ã³ã¢ãããããšãE-mail ã¢ãã¬ã¹ããã³å ¥åããããã®ä»ã®ä»»ææ å ± (ååãé»è©±çªå·ãªã©) ãåéãããŸãã
AtlassianãGitLabãGitHubãGoogle ãªã©ã®ãœãŒã·ã£ã« ãã°ã€ã³ã䜿çšã㊠ãµã€ã³ã¢ãããããšãE-mail ã¢ãã¬ã¹ãšååãèªåçã«åéãããŸãã
ã¢ã«ãŠã³ããåé€ãããšãGDPR ã³ã³ãã©ã€ã¢ã³ã¹ã«åŸã£ãŠã28 æ¥ä»¥å ã«ãã¹ãŠã® å人æ å ±ãåé€ãããŸãã
ã¢ããªã±ãŒã·ã§ã³ ããŒã¿
1 åã® Mayhem ã¹ãã£ã³äžã« mapi
CLI 㯠API ã«äœåããããã¯äœçŸäžãã®
ãªã¯ãšã¹ããè¡ããŸãã
ã©ã³ããšã«ããã¹ãŠã®ãšã³ããã€ã³ãã®å°æ°ã®ãªã¯ãšã¹ãããµã³ãã«ãšããŠååŸãã
ãã¹ãããã³ mapi
ãéä¿¡ãããªã¯ãšã¹ãã®æ
å ±ããŠãŒã¶ãŒã«æ瀺ããŸãã
åé¡ãèŠã€ãããšãAPI ã«éä¿¡ããããªã¯ãšã¹ãããã³ CLI ã«è¿ãããã¬ã¹ãã³ã¹ãåéããŸãã
èªèšŒã«äœ¿çšããããã¢ã©ãŒã®ããŒã¯ã³ãªã©ã®ä»ã®æ å ±ã¯ãã·ãŒã¯ã¬ããããšã¿ãªããã åé¡ã®è©³çŽ°ãŸãã¯ãµã³ãã« ãªã¯ãšã¹ããã¢ããããŒãããåã« ç·šéãããŸãã
Info
ãšã³ã¿ãŒãã©ã€ãº ãã©ã³ã®çµç¹ã¯ãããŒã«ã«ãã¢ãŒãã§å®è¡ã§ããŸãããã®ã¢ãŒãã§ã¯ãmapi
CLI ã¯ãã¹ãŠã®ã©ã³ã®è©³çŽ°ã mAPI API ã«éä¿¡ããŸãããçµæ㯠mapi
ãå®è¡ãããã³ã³ãã¥ãŒã¿ãŒã«ããŒã«ã«ã«ä¿åãããŸãã詳现ã«ã€ããŠã¯ãçµæãããŒã«ã«ã«ä¿åããããåç
§ããŠãã ããã
API ãã¹ãã£ã³äžã« ã429 Too Many Requestsããè¿ããŸã¶
API ã«ã¬ãŒãå¶éãèšå®ããã®ã¯ãããã©ã¯ãã£ã¹ã§ããããã¡ãžã³ã°ã«ãã¬ãã£ã㪠圱é¿ãäžããŸã Mayhem 㯠API ã«å¯ŸããŠã§ããã ãé«éã«å€ãã®ãªã¯ãšã¹ããéä¿¡ã§ããå Žåã« ãã¹ã ããã©ãŒãã³ã¹ãéæã§ããŸãã
ã©ããªçç±ã§ãããAPI ã®ã¬ãŒãå¶éãç¡å¹åã§ããªãå Žåã¯ãMayhem ã«ã¬ãŒãå¶é ããããŠå®è¡ããããšãã§ããŸãã
ããšãã°ã1 åéã« 60 ãªã¯ãšã¹ãã«å¶éããã«ã¯ãmapi run
ãµãã³ãã³ãã®
ãªãã·ã§ã³ãšã㊠--rate-limit 60
ãæå®ããŸãã
mapi run my-project 1min openapi.yaml --url http://example.com --rate-limit 60
ã³ãŒã ãã¹ã¶
Mayhem ãšã¯äœã§ãã?¶
Mayhem ã¯ãã€ã³ã¹ãã¥ã«ã¡ã³ããŒã·ã§ã³ã¬ã€ãä»ããã¡ãžã³ã°ãšããå®è©ããææ³ãšã·ã³ããªãã¯å®è¡ãšããç¬åµçæè¡ã 1 ã€ã«ããå é²çãªãã¡ã¶ãŒã§ãã
Mayhem ã¯ã©ããªåé¡ã®è§£æ±ºã«åœ¹ç«ã¡ãŸãã?¶
Mayhem ã¯å¹ åºãç¯å²ã®ã³ãŒããå®è¡ããåã«æ¢ç¥ã®ãœãããŠã§ã¢åŒ±ç¹ãŸãã¯è匱æ§ã®ãªã¹ãã«é Œãã®ã§ã¯ãªããæ°ããè匱æ§ãåçã«çºèŠããŸãããã®åŸãæ°ãã«èŠã€ãã£ãè匱æ§ã«å¯ŸããŠãã¹ããçæããããšã§ãè匱æ§ããªã¹ã¯ãããããããšã確èªããŸããMayhem ã¯ãäŸµå ¥ãã¹ããšåŒã°ããäžè¬çãªæåãã¹ãã«äŒŒãŠããŸãããããã«ããå é²çãªæ©èœãåããŠããŸãã
Mayhem ã䜿çšããå©ç¹ã¯äœã§ãã?¶
ãã¡ãº ãã¹ãã®èªååã¯èª°ã«ã§ãã§ããŸããæ¬åœã®åé¡ã¯ãé«ã粟床ã§èªååãå®è¡ã§ãããã§ããMayhem ã¯é«éãªãã¡ãº ãã¹ããšã·ã¹ãããã£ãã¯ãªã·ã³ããªãã¯å®è¡ãçµã¿åãããŸãã2 ã€ãçµã¿åãããããšã«ãã£ãŠãæå°éã®æéã§éè€ã®ãªãå ¥åå€ãçæããå¹ççã«ãœãããŠã§ã¢ ã¢ããªã±ãŒã·ã§ã³ã®æ å ±ãåéããŸããããã«ãã£ãŠãããå°ãªãæéãåŽåãã³ã¹ãã§ããå®å šãªãœãããŠã§ã¢ããªãªãŒã¹ããããšãå¯èœã«ãªããŸãã
Mayhem ã¯ãœãŒã¹ ã³ãŒããå¿ èŠãšããŸãã?¶
ããããMayhem ã¯ã¢ããªã±ãŒã·ã§ã³ã®ãã¹ãã«ãœãŒã¹ ã³ãŒããå¿ èŠãšããŸãããMayhem ã¯ãœãŒã¹ ã³ãŒããšãã€ããªã®äž¡æ¹ãåŠçããŸããMayhem ã¯ãœãããŠã§ã¢ã®ãªãªãŒã¹åã«ããªãªãŒã¹åŸã«ãè匱æ§ãæ€åºããŸãã
åã«ãªãŒãã³ ãœãŒã¹ã® honggfuzz/libfuzzer/AFL ãå®è¡ãããã Mayhem ã®ã»ããåªããŠããçç±ã¯äœã§ãã?¶
- Mayhem ã¯ãã©ãããã©ãŒã ã§ãã
- Mayhem ã¯ãã¹ãŠã®ãã¹ã ã±ãŒã¹ãä¿åããçºå±ãç¶ãããªã°ã¬ãã·ã§ã³ ãã¹ããå®è¡ããŸãã
- çµæã衚瀺ããæ§é åããã UI ããããŸãã
- ãžã§ãããŠãŒã¶ãŒããããžã§ã¯ããåŠçããããã®èªååãã¬ãŒã ã¯ãŒã¯ããããŸãã
- ããã¥ã¡ã³ãããã¥ãŒããªã¢ã«ã䜿ãããã CLIãDocker åã蟌ã¿æ©èœãã¹ã¯ãªããå¯Ÿå¿ API ããããŸãã
Mayhem ã¯ã©ã®èšèªããµããŒãããŠããŸãã?¶
CãC++ãGoãRustãJavaãAdaããã®ä»å€ãã®èšèªããµããŒããããŠããŸãã詳现ã«ã€ããŠã¯ãã¡ãã®ãœãªã¥ãŒã·ã§ã³ã®æŠèŠãŸã㯠fuzzme repo ãåç §ããŠãã ããã
Mayhem ã¯ã©ã®ãã©ãããã©ãŒã /ã¢ãŒããã¯ãã£ããµããŒãããŠããŸãã?¶
Linux x86_64 ã³ã³ãã€ã«æžã¿ãœãããŠã§ã¢ããµããŒããããŠããŸããåã ã®ã±ãŒã¹ã«ãã£ãŠã¯ãä»ã®ãã©ãããã©ãŒã ãäºææ§ãããå ŽåããããŸãã詳现ã«ã€ããŠã¯ãã¡ãã®ãœãªã¥ãŒã·ã§ã³ã®æŠèŠãåç §ããŠãã ããã
Mayhem ã¯æ¬åœã«èª€æ€åºçãŒãã§ãã?¶
Mayhem ãèŠã€ãããã¹ãŠã®æ¬ é¥ã¯ã3 åãã¹ããããæ€èšŒãè¡ãããŸãã
Mayhem ã¯ã¢ããªã±ãŒã·ã§ã³ãå€æŽããŸãã?¶
ããããMayhem ã¯ä»»æã®ãã©ã㯠ããã¯ã¹ ãã€ããªãåã蟌ãã§è§£æãå®è¡ã§ããã¢ããªã±ãŒã·ã§ã³ããŸã£ããå€æŽããŸããã
Mayhem ã¯ã©ããããã³ã¹ããããããŸãã?¶
Mayhem ã®äŸ¡æ Œã¯ã¯ã©ã¹ã¿ãŒå ã«æã€ãã£ã¢ãšã³ã¢æ°ã«ãã£ãŠæ±ºå®ãããŸãã詳现ã«ã€ããŠã¯ããã¡ãããã»ãŒã«ã¹æ åœè ã«ãåãåãããã ããã
Mayhem ã¯ãã¹ã ã±ãŒã¹ã®éè€æé€ãè¡ããŸãã?¶
Mayhem ã¯æ°ããã«ãã¬ããžãåŸãããéè€ã®ãªããã¹ã ã±ãŒã¹ã ããä¿åããŸããè€æ°ã®ãã¹ã ã±ãŒã¹ãåããã¹ãå®è¡ããå¯èœæ§ããããŸããããããã®ãã¹ã ã±ãŒã¹ããã¹ãŠä¿åããçç±ã¯ãããŸãããåæ§ã«ãè€æ°ã®ãã¹ã ã±ãŒã¹ãåãæ¬ é¥ãçºçãããå¯èœæ§ããããŸããããããã®ãã¹ã ã±ãŒã¹ããã¹ãŠä¿åããçç±ã¯ãããŸããããªã°ã¬ãã·ã§ã³ ãã¹ãã®å¹çã確ä¿ãããããéè€æé€ãè¡ã£ãŠãæãæå¹ãªãã¹ã ã±ãŒã¹ã ããä¿åããŸãã
Mayhem ã«ã¯ã©ããªãããã€æ¹æ³ããããŸãã?¶
Mayhem ã¯ãªã³ãã¬ãã¹ããã³ã¯ã©ãŠã (ãã©ã€ããŒãããã³ãããªãã¯) ã®äž¡æ¹ã®ãœãªã¥ãŒã·ã§ã³ãšããŠæäŸãããŸãããŸããã¢ã¡ãªã«åè¡åœã®é£éŠæ¿åºé¢é£é¡§å®¢åãã®æ å ±ãšããŠãMayhem 㯠TAA æºæ ã§ãã
Mayhem 㯠CI/CD ãã¬ã³ããªãŒã§ãã?¶
ã¯ããMayhem ã¯æ¢åã® CI/CD ã«çµ±åã§ããããèšèšãããŠããŸãã詳现ã«ã€ããŠã¯ãã¡ãã®ãœãªã¥ãŒã·ã§ã³ã®æŠèŠãåç §ããŠãã ãããMayhem ã¯æ¬¡ã®ãããªå€æ°ã®ãã¹ãææ³ãå®æœã§ããçšéã®åºããœãªã¥ãŒã·ã§ã³ã§ã: åäœãã¹ãããªã°ã¬ãã·ã§ã³ ãã¹ãããã¬ãã£ã ãã¹ããç¶ç¶çtestãåçãã¹ããçµç¹ã«é©ãããŠãŒã¹ ã±ãŒã¹ã«å¿ããŠãMayhem ã SDLC ã®éçºãã§ãŒãºã®äžéšãšããŠçµã¿èŸŒã¿ãDAST ããã³ãã¡ãº ãã¹ããããã«ã·ããã¬ããããããšãã§ããŸãã
Mayhem ã¯ã©ããªçš®é¡ã®æ¬ é¥ãæ€åºããŸãã?¶
CWE 㯠CVE ã«ã€ãªããå¯èœæ§ããããŸããMayhem ã¯å€æ°ã® CWE æ¬ é¥ãæ€åºã§ããŸããããšãã°ãImproper Input Validation (äžé©åãªå ¥åæ€èšŒ)ãOut-of-Bounds Read (å¢çå€èªã¿åã)ãIncorrect Calculation of Buffer Size (ãããã¡ãŒ ãµã€ãºã®èª€ã£ãèšç®)ãDivide By Zero (ãŒãé€ç®)ãFailure to Release Memory Before Removing Last Reference ('Memory Leak') (æåŸã®åç §ãåé€ããåã®ã¡ã¢ãªè§£æŸãšã©ãŒ (ãã¡ã¢ãª ãªãŒã¯ã))ãUse of Uninitialized Variable (æªåæåå€æ°ã®äœ¿çš)ãNull Pointer Dereference (Null ãã€ã³ã¿ãŒéæ¥åç §)ãFree of Memory not on the Heap (ããŒãäžã«ãªãã¡ã¢ãªã®è§£æŸ)ãRelease of Invalid Pointer or Reference (ç¡å¹ãªãã€ã³ã¿ãŒãŸãã¯åç §ã®è§£æŸ)ãOut-of-Bounds Write (å¢çå€æžã蟌ã¿)ãImproper Control of Dynamically-Managed Code Resources (åç管çãããã³ãŒã ãªãœãŒã¹ã®äžé©åãªå¶åŸ¡) ãªã©ã®æ¬ é¥ãæ€åºã§ããŸãã詳现ã«ã€ããŠã¯ãã¡ãã®ããŒã¿ã·ãŒããåç §ããŠãã ããã
Mayhem ã¯ã©ã㪠CVE ãæ€åºããŸããã?¶
ææ°ã®ãªã¹ãã¯ãã¡ãã«ãããŸã: https://forallsecure.com/vulnerabilities-lab