LINE Developer Meetup in Fukuoka #16 http://connpass.com/event/38413/
LINE Developer Meetup in Fukuoka #16 http://connpass.com/event/38413/
èå¼±æ§ãè¦ã¤ãã¦ã»ãã¥ãªãã£å¯¾çã«è²¢ç®ãã¦ããã®ããããã°ãã³ã¿ã¼ãã¨å¼ã°ããåå¨ã ãGoogleãªã©ãã³ãã¼ã®å ±å¥¨éã§çè¨ãç«ã¦ã¦ããã¨ãããããã¬ã¯ ããµããããããããã®ãã°ãã³ã¿ã¼ã¨ãã¦ã®âæãã¿âãç´¹ä»ãã¦ãããã ã½ããã¦ã§ã¢ã®ãã°ãèå¼±æ§ã¯ã軽微ãªä¸å ·åããã»ãã¥ãªãã£ä¸ã®æ·±å»ãªåé¡ãå¼ãèµ·ãããã®ã¾ã§ãæ§ã ãªãã®ããããéçºè ãå¹¾ãæ³¨æãã¦ãèå¼±æ§ããªãããã¨ã¯é常ã«é£ããããå¤é¨ã®ç«å ´ããèå¼±æ§ãè¦ã¤ãã¦ã»ãã¥ãªãã£å¯¾çã«è²¢ç®ããããã°ãã³ã¿ã¼ãã¨ããåå¨ããåãã ãããã GoogleãMicrosoftããµã¤ãã¦ãºãªã©ä¸é¨ã®ãã³ãã¼ã¯ãèå¼±æ§ãå ±åãããã°ãã³ã¿ã¼ã«å ±å¥¨éãªã©ãæ¯æãå¶åº¦ãéå¶ããã®å ±å¥¨éã§çè¨ãç«ã¦ãããã®ä¸äººããããã¬ã¯ ããµããããã ã12æ18ã19æ¥ã«è¡ãããã»ãã¥ãªãã£ã«ã³ãã¡ã¬ã³ã¹ãCODE BLUEãã§ã¯ãããã¬ã¯ãããããã®ãã°ãã³ã¿
mixiã®èå¼±æ§å ±åå¶åº¦ï¼ãã§ã«çµäºãã¦ããï¼ã§å ±åãã¦ãä¿®æ£ãããèå¼±æ§ã youbrideã®æææ©è½ãç¡æã§ä½¿ããåé¡ 2014/03/12 å ±å 2014/03/18 ä¿®æ£å®äº 2014/03/24 75,000åã®Amazonã®ãããå±ãã youbrideã¯mixiã®åä¼ç¤¾ã®æ ªå¼ä¼ç¤¾Diverseãéå¶ãã婿´»ãµã¤ãã䏿ãå¶åº¦ã®å¯¾è±¡ã ã£ãã youbrideã§ã¯ç¡æã¦ã¼ã¶ã¼ã¯ãããã£ã¼ã«ã®å ¬éæ¡ä»¶ã¯ãå ¨ä½ã«å ¬éãããé¸ã¹ãªãã Chromeã®Developer Toolã§ä»ã®é¸æè¢ãæå¹ã«ãããããå ¨ä½ã«å ¬éã以å¤ã®å ¬éæ¡ä»¶ãé¸ã¹ã¦ãã¾ã£ãã mixiã¯ã¼ãã®XSS 2014/03/31 å ±å 2014/03/31 ä¿®æ£å®äº 2014/04/09 125,000åã®Amazonã®ãããå±ãã mixiã¯ã¼ãã«XSSå¯è½ãªèå¼±æ§ããã£ãã ãç«ãã«ã¯ããã£ããã¿ã¯ã¼ããã£ãããã¼
ã¯ã¦ãªã°ã«ã¼ãã®çµäºæ¥ã2020å¹´1æ31æ¥(é)ã«æ±ºå®ãã¾ãã 以ä¸ã®ã¨ã³ããªã®éããä»å¹´æ«ãç®å¦ã«ã¯ã¦ãªã°ã«ã¼ããçµäºäºå®ã§ããæ¨ããç¥ãããã¦ããã¾ããã 2019å¹´æ«ãç®å¦ã«ãã¯ã¦ãªã°ã«ã¼ãã®æä¾ãçµäºããäºå®ã§ã - ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãã®ãã³ãæ£å¼ã«çµäºæ¥ã決å®ãããã¾ããã®ã§ã以ä¸ã®éãã確èªãã ããã çµäºæ¥: 2020å¹´1æ31æ¥(é) ã¨ã¯ã¹ãã¼ã叿ç³è«æé:2020å¹´1æ31æ¥(é) çµäºæ¥ä»¥éã¯ãã¯ã¦ãªã°ã«ã¼ãã®é²è¦§ããã³æç¨¿ã¯è¡ãã¾ãããæ¥è¨ã®ã¨ã¯ã¹ãã¼ããå¿ è¦ãªæ¹ã¯ä»¥ä¸ã®è¨äºã«ãããã£ã¦æç¶ãããã¦ãã ããã ã¯ã¦ãªã°ã«ã¼ãã«æç¨¿ãããæ¥è¨ãã¼ã¿ã®ã¨ã¯ã¹ãã¼ãã«ã¤ã㦠- ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãå©ç¨ã®ã¿ãªãã¾ã«ã¯ãè¿·æãããããããã¾ãããã©ãããããããé¡ããããã¾ãã 2020-06-25 è¿½è¨ ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ã®ã¨ã¯ã¹ãã¼ããã¼ã¿ã¯2020å¹´2æ28
ã¯ã¦ãªã°ã«ã¼ãã®çµäºæ¥ã2020å¹´1æ31æ¥(é)ã«æ±ºå®ãã¾ãã 以ä¸ã®ã¨ã³ããªã®éããä»å¹´æ«ãç®å¦ã«ã¯ã¦ãªã°ã«ã¼ããçµäºäºå®ã§ããæ¨ããç¥ãããã¦ããã¾ããã 2019å¹´æ«ãç®å¦ã«ãã¯ã¦ãªã°ã«ã¼ãã®æä¾ãçµäºããäºå®ã§ã - ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãã®ãã³ãæ£å¼ã«çµäºæ¥ã決å®ãããã¾ããã®ã§ã以ä¸ã®éãã確èªãã ããã çµäºæ¥: 2020å¹´1æ31æ¥(é) ã¨ã¯ã¹ãã¼ã叿ç³è«æé:2020å¹´1æ31æ¥(é) çµäºæ¥ä»¥éã¯ãã¯ã¦ãªã°ã«ã¼ãã®é²è¦§ããã³æç¨¿ã¯è¡ãã¾ãããæ¥è¨ã®ã¨ã¯ã¹ãã¼ããå¿ è¦ãªæ¹ã¯ä»¥ä¸ã®è¨äºã«ãããã£ã¦æç¶ãããã¦ãã ããã ã¯ã¦ãªã°ã«ã¼ãã«æç¨¿ãããæ¥è¨ãã¼ã¿ã®ã¨ã¯ã¹ãã¼ãã«ã¤ã㦠- ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãå©ç¨ã®ã¿ãªãã¾ã«ã¯ãè¿·æãããããããã¾ãããã©ãããããããé¡ããããã¾ãã 2020-06-25 è¿½è¨ ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ã®ã¨ã¯ã¹ãã¼ããã¼ã¿ã¯2020å¹´2æ28
twitterã§XSSèå¼±æ§çºç ã«ãã´ãªãã¥ã¼ã¹ 1 ï¼ çµµæ¬ä½å®¶(catv?)ï¼2010/09/21(ç«) 20:48:54.40 ID:N9k777o3iâ ?BRZ(10000) ã½ã¼ã¹ http://twitter.com/Hamachiya http://twitter.com/hapinano/status/25102437219 Web以å¤ã®ã¯ã©ã¤ã¢ã³ãã¯åé¡ãªã document.bodyã®ãã¦ã¹ãªã¼ãã¼ãå½ç¶å¯è½ãªã®ã§ãã°ã¢ã¦ãæ¨å¥¨ 3 ï¼ æ¯ç§å»å¸«(é¢è¥¿å°æ¹)ï¼2010/09/21(ç«) 20:49:22.57 ID:6PM295IO0 ã¤ã¾ãã©ããªããã ãï¼ 7 ï¼ å ¬åå¡(æ±äº¬é½)ï¼2010/09/21(ç«) 20:50:10.15 ID:6XnlGTOm0 tiwtterçµäºã®ãç¥ãã 8 ï¼ å¹¼ç¨åã®å ç(ã¢ã©ããå·)ï¼2010/09/21
(2009/04/12 6ï¼40 pm 追è¨ãã¾ãã) (2009/04/12 7ï¼24 pm å度追è¨ãã¾ãã) å ã»ã©ãã Twitterä¸ã«ã¦ XSS ã®ãã被害ãåºã¦ãã¾ãã æ¢ã«æµ·å¤ã®ããã°ãªã©ã§ãåãä¸ãããã¦ãã¾ãã HOWTO: Remove StalkDaily.com Auto-Tweets From Your Infected Twitter Profile (Twittercsm) Warning: Twitter Hit By StalkDaily Worm (TechCrunch) æ¢ã« XSS ã®é¨åã¯æ¹ä¿®ããã¦å¤§ååã¾ã£ãããã§ããã念ã®ããã«æ¸ãã¦ããã¾ãã å 容ã¨ãã¦ã¯ã 1. StalkDaily.com ã宣ä¼ããã¤ã¶ãããåæã«æç¨¿ããã 2. ãããã£ã¼ã«ã® Web ãæ¹ããããã 3. æ¹ãããããã¦ã¼ã¶ã¼ã®ãã¼ã¸ãè¦ãã¨ãèªåã®ãããã£ã¼ã«ã
æåã³ã¼ãã«é¢ããåé¡ã¯å¤§å¥ããã¨æåéåã®åé¡ã¨æåã¨ã³ã³ã¼ãã£ã³ã°ã®åé¡ã«åé¡ã§ãããååã¯æåéåã®åãæ±ãã«èµ·å ããããå¼±æ§ã«ã¤ãã¦èª¬æããã®ã§ãä»åã¯æåã¨ã³ã³ã¼ãã£ã³ã°ã«èµ·å ããããå¼±æ§ã«ã¤ãã¦èª¬æãããã æåã¨ã³ã³ã¼ãã£ã³ã°ã«ä¾åããåé¡ãããã«åé¡ããã¨2種é¡ãããï¼1ï¼æåã¨ã³ã³ã¼ãã£ã³ã°ã¨ãã¦ä¸æ£ãªãã¼ã¿ãç¨ããã¨æ»æãæç«ãã¦ãã¾ãç¹ã¨ï¼ï¼2ï¼æåã¨ã³ã³ã¼ãã£ã³ã°ã®å¦çãä¸ååãªããã«ããå¼±æ§ãçãããã¨ãããç¹ã ã 䏿£ãªæåã¨ã³ã³ã¼ãã£ã³ã°ï¼1ï¼ââåé·ãªUTF-8符å·ååé¡ ã¾ãï¼ï¼1ï¼ã®ä¸æ£ãªæåã¨ã³ã³ã¼ãã£ã³ã°ã®ä»£è¡¨ã¨ãã¦ï¼åé·ãªUTF-8符å·ååé¡ãã説æããããåã åã«è§£èª¬ããUTF-8ã®ãããã»ãã¿ã¼ã³ï¼è¡¨1ã«åæ²ï¼ãè¦ãã¨ï¼ã³ã¼ãã»ãã¤ã³ãã®ç¯å²ãã¨ã«ãããã»ãã¿ã¼ã³ãå²ãå½ã¦ããã¦ãããï¼ãããã»ãã¿ã¼ã³ä¸ã¯ï¼ããå¤ãã®ãã¤ãæ°ã使ã£ã¦ãåãã³ã¼
XSSã«CSRFã«SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã«ãã£ã¬ã¯ããªãã©ãã¼ãµã«â¦â¦Webã¢ããªã±ã¼ã·ã§ã³ã®ããã°ã©ããç¥ã£ã¦ããã¹ãèå¼±æ§ã¯ãã£ã±ãããã¾ããããã§æ¬é£è¼ã§ã¯ããã®ãããªã¡ã¸ã£ã¼ãªãã®â以å¤âãæãä¸ãã¦ããã¾ãï¼ç·¨éé¨ï¼ å°ããªè©±é¡ãé¢ç½ã çãããã¯ããã¾ãã¦ãã¯ãããããããã¨ç³ãã¾ãã ãæç§æ¸ã«è¼ããªãWebã¢ããªã±ã¼ã·ã§ã³ã»ãã¥ãªãã£ãã¨ãããã¨ã§ãWebã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£ã«é¢é£ãããæ®æ®µãã¾ãè¦æããªããããªå°ããªè©±é¡ãåãä¸ãã¦ããããã¨æãã¾ãã ã»ãã¥ã¢ãªWebã¢ããªã±ã¼ã·ã§ã³ãå®ç¾ããããã«ãéçºè ã®æ¹ã ãã§ãªããWebã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§æ¤æ»ãè¡ãæ¹ã ã«ãèªãã§ããã ãããã¨æã£ã¦ãã¾ããéç®±ã®é ãæ¥æã§ã»ããããããªå°ããªè©±é¡ã°ããã§ãããçãããããããé¡ããã¾ãã ãã¦ç¬¬1åã¯ãInternet ExplorerãHTMLãè§£éããéã®å¼ç¨
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}