CSRF, HTML Form Protocol Attack, Cross-protocol scripting attackã«ã¤ãã¦
Dropboxã¯ãã¡ã¤ã«ç½®ãå ´ä»¥å¤ã«ãã¦ã§ããµã¤ãã®æ§ç¯ã«å©ç¨ã§ããããDropPagesããå°å ¥ããã°ãèªåã®ãã½ã³ã³ã®Dropboxããµã¼ãã¼ä»£ããã«ããããã¨ã§ããµã¤ããå ¬éã§ããããã«ãªãã身å ã§é²è¦§ããããã®ãµã¤ããæè»½ã«ä½ãããã¨ã使ãããã Dropboxã¯åã«ãã¡ã¤ã«ã®å ±æãããã¯ã¢ããã«ä½¿ããã ãã§ã¯ãªãããµã¼ãã¹ãçµã¿åããããã¨ã§ã¦ã§ããµã¤ããä½ãåºããã¨ã ã£ã¦ã§ãã¦ãã¾ãã®ã ãè¤æ°ãããµã¼ãã¹ã®ä¸ã§ããDropPagesãã¯ç°¡åãªæä½ã§æ¬æ ¼çãªãµã¤ããä½ããã®ãç¹å¾´ãé常ããµã¤ããä½ãã«ã¯HTMLãCSSãªã©ã®ç¥èãFTPã«ãã転éãå¿ è¦ã ããDropPagesãªãDropboxã«çªã£è¾¼ãã ãã¼ããã¡ã¤ã«ãã¡ã¢å¸³ãªã©ã®ã¨ãã£ã¿ã§æ¸ãæããã ãã ããªã³ã¯ãå¼µã£ãããç»åãåãè¾¼ã¿è¡¨ç¤ºããã®ã¯ãMarkdownãã¨ããã·ã³ãã«ãªå ¥åæ¹æ³ã§è¡ãããããHTMLãåå¼·ããå¿
Apacheã®RewriteRuleã§ã/hoge/é ä¸ã«ã¢ã¯ã»ã¹ããã£ãã http://example.jp/fuga/ ã«301ãªãã¤ã¬ã¯ããè¡ããã£ã¦ãªå¦çãæ¸ãå ´åãå é ã«/ãå¿ è¦ãªå ´åã¨å¿ è¦ãªãå ´åãããã RewriteEngine on # ããã§ãããå ´åããã RewriteRule ^/hoge/(.*) http://example.jp/fuga/$1 [R=301,L] # ããæ¸ããªãã¨ãã¡ãªå ´åããã RewriteRule ^hoge/(.*) http://example.jp/fuga/$1 [R=301,L] ãã®å é ã«/ãå¿ è¦ä¸è¦ã®éãã¯ãªãã ãããªã¼ã¨æã£ã¦ããããå æ¥çç±ãããã£ãã Apacheã®ããã¥ã¡ã³ãã«ãã£ããæ¸ãã¦ãã£ãã RewriteRule Directive What is matched? In VirtualHost c
HTMLã¨JSã ãã§ä½ãä½ããã¨ãå¤ãã¦ï¼éçºç°å¢ãã©ãä½ããã¨ãï¼ãã¦ãã¦ã¿ãããªã®ããã¾ã£ã¦ããã¨æãï¼ ãã¼ã«ã«ã®HTMLãã¡ã¤ã«ããã©ã¦ã¶ã§éãã¨ï¼ããããªå¶ç´ãããï¼ãã¨ãã°ï¼ãã¡ã¤ã«APIã使ããªãã¨ãï¼YouTubeã®ãã¬ã¤ã¤ã¼è²¼ãä»ãã§ããªãã¨ãï¼/js/ã¿ããã«çµ¶å¯¾ãã¹ã§æå®ãããã¨ãã§ããªãï¼ãã¼ã¸1æãªãä»ã®ãã¼ã¸ã«ãªã³ã¯ã¨ããããªããã©ï¼ã¦ã§ããµã¤ããä½ã£ã¦ãã¨ãã¨ãã¯ï¼/help/ã§ãã«ããã¼ã¸ã表示ããã¨ãæ¸ããã¨ãã«ï¼ãã¼ã«ã«ã®ãã¡ã¤ã«ãè¦ã¦ãªã³ã¯ãåãã¦ãã¨ãããã¨ã«ãªãï¼éçºä¸ã¯ãªã³ã¯åãã ãã©æ¬çªãµã¼ãã¼ã«ç½®ãã¨è¦ããã¯ãã¨ãè¨ã£ã¦éçºããã®ã¯æãï¼ ãµã¼ãã¼ã§Rubyã¨ãPerlãåãã¦ãã¿ãããªã¨ãã¯ãã¼ã«ã«ã§ãµã¼ãã¼ãç«ã¦ã¦éçºãã¦ãã¨æãï¼HTMLã¨JSã ã使ãã¨ãã§ããã¼ã«ã«ã§ãµã¼ãã¼ãç«ã¦ã¦éçºããã»ããããã¨æãï¼ éçºä¸ã¯ï¼nginxã§ã
ç¾å¨ãWEBãµã¼ãã®ã·ã§ã¢ã¨ãã¦ã¯Apacheãéåæ°ãå ãã¦ãã¾ããè±å½Netcraft社ã®èª¿æ»ã«ããã¨2016å¹´4æã«ãããApacheã®ã·ã§ã¢ã¯49.15ï¼ ã§ããï¼active sitesã«ãããã·ã§ã¢ãåç §ï¼Netcraft: April 2016 Web Server Surveyyï¼ã 2ä½ã®nginxã大ããå¼ãé¢ãã¦ãã¾ãããã®ãããªä¸ççã«äººæ°ã®é«ãApacheãã¦ã§ããã¹ã¿ã¼ã¨ãã¦ä½¿ãããªãæ¹æ³ã¨ãã¦ããã®ãã¼ã ãã¼ã¸ã§ã¯.htaccessã®å©ç¨æ³ã«ã¤ãã¦è§£èª¬ãã¾ããhttpd.confã«è§¦ããã¨ã®ã§ããªãä¸è¬ã®ã¦ã§ããã¹ã¿ã¼ããã対象ã«ããã¢ã¯ã»ã¹å¶éããã«ã¹ã¿ã ã¨ã©ã¼ãã¼ã¸ã®è¨å®ããMIMEã¿ã¤ãã®è¨å®ããªã©å®ç¨åº¦ã®é«ãå©ç¨æ³ã«çµã£ã¦ç´¹ä»ãã¾ãããä½ããããããã®ããä¸å¿ã«ã.htaccessã®å©ç¨æ³ã説æããæ§æã«ãªã£ã¦ãã¾ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}