CSRF, HTML Form Protocol Attack, Cross-protocol scripting attackã«ã¤ãã¦
HTMLã¨JSã ãã§ä½ãä½ããã¨ãå¤ãã¦ï¼éçºç°å¢ãã©ãä½ããã¨ãï¼ãã¦ãã¦ã¿ãããªã®ããã¾ã£ã¦ããã¨æãï¼ ãã¼ã«ã«ã®HTMLãã¡ã¤ã«ããã©ã¦ã¶ã§éãã¨ï¼ããããªå¶ç´ãããï¼ãã¨ãã°ï¼ãã¡ã¤ã«APIã使ããªãã¨ãï¼YouTubeã®ãã¬ã¤ã¤ã¼è²¼ãä»ãã§ããªãã¨ãï¼/js/ã¿ããã«çµ¶å¯¾ãã¹ã§æå®ãããã¨ãã§ããªãï¼ãã¼ã¸1æãªãä»ã®ãã¼ã¸ã«ãªã³ã¯ã¨ããããªããã©ï¼ã¦ã§ããµã¤ããä½ã£ã¦ãã¨ãã¨ãã¯ï¼/help/ã§ãã«ããã¼ã¸ã表示ããã¨ãæ¸ããã¨ãã«ï¼ãã¼ã«ã«ã®ãã¡ã¤ã«ãè¦ã¦ãªã³ã¯ãåãã¦ãã¨ãããã¨ã«ãªãï¼éçºä¸ã¯ãªã³ã¯åãã ãã©æ¬çªãµã¼ãã¼ã«ç½®ãã¨è¦ããã¯ãã¨ãè¨ã£ã¦éçºããã®ã¯æãï¼ ãµã¼ãã¼ã§Rubyã¨ãPerlãåãã¦ãã¿ãããªã¨ãã¯ãã¼ã«ã«ã§ãµã¼ãã¼ãç«ã¦ã¦éçºãã¦ãã¨æãï¼HTMLã¨JSã ã使ãã¨ãã§ããã¼ã«ã«ã§ãµã¼ãã¼ãç«ã¦ã¦éçºããã»ããããã¨æãï¼ éçºä¸ã¯ï¼nginxã§ã
ç¾å¨ãWEBãµã¼ãã®ã·ã§ã¢ã¨ãã¦ã¯Apacheãéåæ°ãå ãã¦ãã¾ããè±å½Netcraft社ã®èª¿æ»ã«ããã¨2016å¹´4æã«ãããApacheã®ã·ã§ã¢ã¯49.15ï¼ ã§ããï¼active sitesã«ãããã·ã§ã¢ãåç §ï¼Netcraft: April 2016 Web Server Surveyyï¼ã 2ä½ã®nginxã大ããå¼ãé¢ãã¦ãã¾ãããã®ãããªä¸ççã«äººæ°ã®é«ãApacheãã¦ã§ããã¹ã¿ã¼ã¨ãã¦ä½¿ãããªãæ¹æ³ã¨ãã¦ããã®ãã¼ã ãã¼ã¸ã§ã¯.htaccessã®å©ç¨æ³ã«ã¤ãã¦è§£èª¬ãã¾ããhttpd.confã«è§¦ããã¨ã®ã§ããªãä¸è¬ã®ã¦ã§ããã¹ã¿ã¼ããã対象ã«ããã¢ã¯ã»ã¹å¶éããã«ã¹ã¿ã ã¨ã©ã¼ãã¼ã¸ã®è¨å®ããMIMEã¿ã¤ãã®è¨å®ããªã©å®ç¨åº¦ã®é«ãå©ç¨æ³ã«çµã£ã¦ç´¹ä»ãã¾ãããä½ããããããã®ããä¸å¿ã«ã.htaccessã®å©ç¨æ³ã説æããæ§æã«ãªã£ã¦ãã¾ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}