PHPã«ã³ãã¡ã¬ã³ã¹ 2021 1é±éåã¤ãã³ã ã 帰ã£ã¦ããPHPåå¼·ä¼@æ±äº¬ ã®çºè¡¨è³æã§ãã https://phpcon.connpass.com/event/224128/
CTF Advent Calendar 2019 - Adventarã®25æ¥ç®ã®è¨äºã§ãã 1ã¤åã¯@ptr-yudaiæ°ã®2019å¹´ã®pwnåãå ¨é¨è§£ããã£ã¬ã³ã¸ãå¾åæ¦ã - CTFãããã§ããã ã¯ãã㫠対象ã¤ãã³ã å顿° èªã¿æ¹ãä½¿ãæ¹ Cross-Site Scripting(XSS) SVGãã¡ã¤ã«ãå©ç¨ããCSPãã¤ãã¹ Googleãã¡ã¤ã³ã®JSONPãå©ç¨ããCSPãã¤ãã¹ ãµããªã½ã¼ã¹å®å ¨æ§(SRI)æ©è½ãå©ç¨ããå ¥åãã§ãã¯ãã¤ãã¹ Chromeæ¡å¼µæ©è½ã®ãã¹ã¯ã¼ãããã¼ã¸ã£ã¼KeePassã®æªç¨ HTML likeã³ã¡ã³ãã使ç¨ããã³ã¡ã³ãã¢ã¦ã jQuery.getJSONã®JSONPæ©è½ã使ç¨ããã¹ã¯ãªããå®è¡ DOM Clobberingã«ããã³ã¼ããã¤ã¸ã£ã㯠Service Workerãå©ç¨ããã¹ã¯ãªããå®è¡ XSS Auditoræ©è½ã®ãã¤ãã¹
ãã¼ã¸é·ç§»ã楽ããç¹ç´°ã§æ»ãããªåã CSS3ã使ã£ãæ»ãããªåãã¨å¤§èãªã¿ã¤ãã°ã©ãã£ãé åçãªãBeatrice Creationsããé»ã¨ç½ãåºèª¿ã¨ããè³ã£ã¦ã·ã³ãã«ãªãã¶ã¤ã³ãªãããã¤ãå ¨ãã¼ã¸ãè¦ã¦ã¿ãããªãã飽ãã®ããªãæ¼åºãæ½ããã¦ããã Béatrice Créationsã§ã¯ãè¤æ°ããä½åã®ãã´ã«SVGã使ããã¦ãããä½åãã¼ã¸ãç§»åãããã³ã«ç¾ããã«ã¼ããæãã軽éã§ãæ ç·ãç·ç»ã«ãã£ã¦ç¹ç´°ã§ãªãããªä¸çè¦³ãæ¼åºããã仿³¨ç®ã®SVGã¢ãã¡ã¼ã·ã§ã³ãæå¹ã«æ´»ããããµã¤ãã ã ä»åã¯ãã®ãµã¤ãããã³ãã«ãSVGã®åºæ¬ã¨ãCSS3ã¢ãã¡ã¼ã·ã§ã³ã使ã£ãåããæ¹ã解説ãããCSSã¨HTMLã®ã¿ã§æ¬¡ã®ãããªæ ç·ã¨ããã¹ããæããæçµçã«ã¯jQueryã使ã£ã¦è²ãå¤ãããã¢ãå¶ä½ããã STEP 1ï¼SVGã®ãã¹ã使ãã ã¢ãã¡ã¼ã·ã§ã³ãä½ãåã«ãIllustratorã使ã£ã¦ç´
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}