ã¯ã¦ãªããã°ã®ãã«ãã§ã
ã¯ã¦ãªããã°ã®ãã«ãã§ã
UTF-7 ã使ã£ã¦ã¹ã¯ãªãããè¨è¿° +ADw-SCRIPT+AD4-alert(\'XSS\');+ADw-+AC8-SCRIPT+AD4- IE ã¯ãæåã¨ã³ã³ã¼ãã£ã³ã°ãä¸æã§ UTF-7 ã£ã½ãæååãããã°ãèªåå¤å¥ã§ UTF-7 ã¨ãªãã
æçµæ´æ°æ¥: Wednesday, 29-Nov-2006 02:46:05 JST Webãã° CSRF (Cross Site Request Forgeries) DoS (ãµã¼ãã¹æå¦) ãµãã¿ã¤ãº ãªã¬ãªã¬è¨¼ææ¸ Cookie Monster SQL ã¤ã³ã¸ã§ã¯ã·ã§ã³ HTTP Response Splitting (ã¬ã¹ãã³ã¹åå²) HTTPã®ãã¼ã¸ã®ãã¬ã¼ã ã«HTTPSã®ãã¼ã¸ã表示 ãããã¡ãªã¼ãã¼ããã¼ ãã£ãã·ã³ã° Forceful Browsing (å¼·å¶ãã©ã¦ãº) ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã° ã¼ããã¤(0day)æ»æ ãã£ã¬ã¯ããªãã©ãã¼ãµã« ã»ãã·ã§ã³ãã¤ã¸ã£ãã¯ æ¨©éææ ¼ OS ã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³ ãªã¼ãã³ãããã· Webãã° ï¼¼ãã__ããï¼ ï¼¿ãï¼ï½ï¼ã_ãã¼ã³ã¼ã³ |ã| ï¼ ãï½Â´ã ï¼¼ ('A`
Wizard Bibleã¯2018å¹´4æ22æ¥24æã«ééãã¾ããã æç¨¿è ãèªè ã®çæ§ãããã¾ã§ã®éæ¬å½ã«ãããã¨ããããã¾ããã ã2021å¹´6æ27æ¥æ´æ°ã Wizard Bibleã®è¨ç«ããééã¾ã§ã«è³ãéç¨ã詳細ã«è¿°ã¹ãæ¬ãåºããã¨ã«ãªãã¾ããã ãWizard Bibleäºä»¶ããèãããµã¤ãã¼ã»ãã¥ãªãã£ãå·çããã¸ã§ã¯ã èå³ã®ããæ¹ã¯æ¯éèªãã§ã¿ã¦ãã ããã Security Akademeiaã«æ»ã
æ å ±ãå®ããæªæ¥ãåµé ãããã¤ãªãã¢ã¨ãã¦ã®ä¿¡é ¼ã¨èªä¿¡ã§ããã£ã¨å 㸠æé«å³°ã®ã»ãã¥ãªãã£ãµã¼ãã¹ã¨ãITãã¼ã¿ã«ã½ãªã¥ã¼ã·ã§ã³ãæä¾ãã¾ãã ãã£ã¨ç¥ã
é±3æ¥å¤åãæ®ã4æ¥ã¯è±èªããã°ã¢ã¸ã¢ã¸ã³ãThe Japan Timesçã§æ´»åãã¦ããã¾ããé£çµ¡å ã¯ãå§@gmail.comãã§ãã Googleã®ä¸è¬æ¤ç´¢ã§ãã社å¤ç§æ å ±ã®å ¥ã£ãExcelãæ¤ç´¢ãããããããåºã¦ãã(åè ã å ¬éWebãµã¼ãããæ©å¯æ å ±ãå¼ãåºããGoogleãããã³ã°ãã®è å¨ã¨ããã®å¯¾ç)ã¨ãã£ã話ãããããã¤ãæè¿ã¯Google Calendarã§æããã«å ¬éæ å ±ãããªãããããªäººã®äºå®ãæ¤ç´¢ã§ããã¨ããææã話é¡ã«ãªã£ãã ã¨ãããã¨ã§ãæ¨æ¥ãªãªã¼ã¹ãããGoogleã³ã¼ãæ¤ç´¢ã§ãããã£ããè²ã ãªãã¤ãã¤ãææãã kottke.org ã§ã¯ä»¥ä¸ã®ãããªæ¤ç´¢ä¾ã å§ç¸®ã¢ããªã±ã¼ã·ã§ã³ã®æå·çæé¨åã®ã½ã¼ã¹ ãã¹ã¯ã¼ããåãè¾¼ãã ããã°ã·ã¹ãã ã®ã½ã¼ã¹ ãããã¡ã¼ãªã¼ãã¼ããã¼èå¼±æ§ããããããªã½ã¼ã¹ å ¬éãããã¹ãã§ãªããã¨æ¸ãã¦ããã½ã¼ã¹ æç´ã£ãããç½µã£
ã304 Not Modified ã¤ã³ã¿ã¼ãããã®ã´ã¼ã«ãã³ã¿ã¤ã ã¨ãµã¤ãã®æ´æ°æéããèªãã§ã ã21:00ã24:00 ããããã¤ã³ã¿ã¼ãããã®ã´ã¼ã«ãã³ã¿ã¤ã ãã¨ããäºãªã®ã ããã ãã¾ãªãæ°ã¯ãã®ã´ã¼ã«ãã³ã¿ã¤ã ãé¿ãã¦æ´æ°ãããã¦ããããã ããç§ã®æ´æ°ã¯ãã®æé帯ã«ãã£ã¡ãå ¥ã£ã¦ãããªã ã¤ã³ã¿ã¼ãããã£ã¦çµå±ã¯èªã¿é£ã°ãã®æåã«ãªã£ã¦ãã¾ããã¡ãªãã§ããä»ã®ããã°ãæ´æ°ãããä¸ã§èªåãæ´æ°ããããä¾ãã°10åã®ä¸ã®1åã«ãªã£ã¦ãã¾ããã§ããããããä»ã®ãµã¤ããæ´æ°ãããªãæéã®ä¸ãªãã2åã®ä¸ã®1åã«ãªãã¨æããã§ãããããªã£ãããå¾è ã®æ¹ãèªåã®è¨äºããã£ããèªãã§ããããã¨æãã¾ãããï¼ ç¢ºãã«ããã ãç§ãããã¯åãã£ã¦ãããã ãããããå¤ãã®äººã«èªãã§è²°ãããã¨æã£ã¦ããããã´ã¼ã«ãã³ã¿ã¤ã ã«æ´æ°ããã®ã¯é¿ããæ¹ãããã ãããã ããæ°ãè¨ããã¦ããããã«ä¼ç¤¾å¤ãããã¦ãã
ã»ããã¼ç³ãè¾¼ã¿ãã©ã¼ã ãã¹ãã ã®è¸ã¿å°ï¼ï¼æéåã®Webã¢ããªã»ã®ã¼ã®æ¹é è¨ç»ï¼1ï¼ï¼1/4 ãã¼ã¸ï¼ æ7æããã¤ããã30åæ©ãèµ·ãããæéåã27æ³ã®ç§ã 仿¥ã¯ãæéåãããã¦å¸æãã¦ããWebæ å½ã¸é 屿¿ãã«ãªãæ¥ãæéåã®ä¼ç¤¾ã§ã¯åµç«è¨å¿µæ¥ã®ä»æ¥ãæ©ã«ãWebã«åãå ¥ããããã®æ°ãããã¼ã ãçºè¶³ããã®ã ã è¶³åãã軽ããæéåã¯ä¼ç¤¾ã¸åºç¤¾ãããã¾ã ããWebæ å½ã«ãªããã¨ãããã¨ä»¥å¤ãå ·ä½çãªãã¨ã¯ä¸åç¥ãããã¦ããªãããã¨ã¦ããããããã¦ããã ãã®ä¼ç¤¾ã§ã¯ã人äºçºä»¤ãããã¨ãã¯1人ãã¤ç¤¾é·å®¤ã«å¼ã°ãããæéåãèªå¸ã§ãããããã¦ããã¨ãä¸çªã«å£°ãæãã£ãã 社é·ããæéåãå ¥ããªããã æéåã¯2å¹´ã»ã©åã«ãã®ä¼ç¤¾ã¸è»¢è·ãã¦ãããåè·ã§ã¯ãç°¡åãªWebã¢ããªã±ã¼ã·ã§ã³ã®ä½æãFlash使ãªã©ã®ã³ã¼ãã£ã³ã°ãä¸å¿ã®Webãã¶ã¤ã³ã®ä»äºããã¦ãããWebãã¶ã¤ã³ã®ä»äºã叿
â 䏿¥ä¸å¹¼å ãã¡ã®æ åãä¸ç¹å®å¤æ°ã«å ¬è¡éä¿¡ãã¦ããä¿è²æ åã©ãå®ãIT ââ妿 ¡ã§é§ ã§è¡ã§, ææ¥ããããããã, 2005å¹´9æ28æ¥ ãããä¸ç¶ å¹¼ç¨åã§ã®ç¬é¡æºéï¼è·å ´ã§å®¶ã§è¦ªå®å¿ ï¼ç¥ï¼ããããã·ã¹ãã ã§ã¯ãä¿è·è ãã«ã¯å°ç¨ãã¹ã¯ã¼ããé å¸ãã¦æ åãè¦ãããããã«ããããæ¨©éã®ãªãé¨å¤è ã«ã¯æ åãè¦ããªãã®ãæ®éã ãããããåä¿è²æã¯ãä¿è²æã«èå³ãæã£ã¦ã»ãããã¨ãä¸è¬ã«ãæ åãå ¬éãã¦ããããã£ã¨ããåã©ãã®å®å ¨ãå®ããããã«ã¡ã©ã®ãºã¼ã ã¢ããã¯ã§ããªãããã«ãã¦ãããä¿è·è ã§ããªãéããæ åã§åã©ãã®è¦åãã¯ã§ããªãã ã¨ããè¨äºããã£ããã西èä¿è²æãã§æ¤ç´¢ãã¦ã¿ãã¨è¦ã¤ãã£ãã 社ä¼ç¦ç¥æ³äºº 西èä¿è²æ ã©ã¤ãæ å ãããã«ã誰ã§ãã©ã¤ãæ åãè¦ãããããã«ãªã£ã¦ãããä»è¦ãã¨ããããã¼ã«ããåºã女å ãã¡ãå ¨è£¸ã«ãªã£ã¦çæ¿ãã¦ããæ§åãæ ã£ã¦ããã ãæ åã§åã©ãã®
â [ruby] XSS - 表示系ãã©ã¡ã¼ã¿ã«åå¨ããç²ç¹ : Rubyã®å ´å Ruby+ERBã 㨠<a href="http://example.com/test.cgi?id=<%= id %>">hoge</a> ã¿ãããªæ¸ãæ¹ã¯å±éºã§ã <a href="http://example.com/test.cgi?id=<%=u id %>">hoge</a> ã®ããã«ãããã£ã¦ãã¨ã§ããã®ããªï¼ Ruby+ERBã§CGIãæ¸ãã¨ãã¯ã åºæ¬çã«ã<%= str %>ã§ã¯ãªã <%=h str %> ã使ãã a hrefã®URLã®ä¸ã«åãè¾¼ãã¨ã㯠<%=u str%>ã使ãã ã©ããã¦ãstrã®ä¸ã§HTMLã¿ã°ã使ãããã¨ãã ãã<%= str %> (ã¨ã¹ã±ã¼ããªã)ã使ãã ã¨ããæãã§ãã£ã¦ã¾ãã ãã©ãã¯ããã¯ããã¦ããè¨äºã«ããããã©ããã¡ãã¡ ãç¡å®³åããå¿ è¦ããã
ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼ ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã®æéã§ãï¼ XSSã¨ããã¨â¦ï¼ ã¾ã£ããã«æãã¤ãã®ããå ¥åãã¼ã¿éä¿¡ â 確èªè¡¨ç¤ºã®é¨åã§ã®ç¡å®³åæ¼ãã§ãããï¼ ãã¨ãã°ãããªæãã®ãã©ã¼ã ããåãåã£ããã©ã¡ã¼ã¿ãã 確èªã¨ãã¦è¡¨ç¤ºãããã¼ã¸ã¨ãï¼ (å ¥å) <form action="register.cgi" method="post"> ã¿ã¤ãã«ï¼<input type="text" name="title"> â ãã¼ãã¯ã¾ã¡ã¡ããï¼ããå ¥å æ¬æï¼<input type="text" name="body"> â ãããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼<script>alert(1)</script>ããå ¥å </form> (確èª) <p>ãã®å 容ã§ç»é²ãã¦ããï¼</p> <p> ã¿ã¤ãã«ï¼ ã¼ãã¯ã¾ã¡ã¡ããï¼<br> æ¬æï¼ ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼<script>alert
第1å Ajaxæè¡ã®ç®ã«è¦ããªãéä¿¡å 容ãã®ããã¦ã¿ããã§ã¯ãAjaxã®æè¡èæ¯ã解説ãã¾ãããä»åã¯ããã»ãã¥ãªãã£ãã¨ãã観ç¹ã§Ajaxãè¦ã¦ããããã¨æãã¾ãã 2åç®ã®ä»åã¯ãé常ã«å¹ åºããå¥¥ãæ·±ããAjaxã®ç¹å¾´ã«æ½ãã»ãã¥ãªãã£ãªã¹ã¯ãããå®éã®ãµã³ãã«ã¢ããªã±ã¼ã·ã§ã³ã®éä¿¡ãããã¦ã¹ã®åããåç»ã§è¦ãªãããçè§£ãã¾ããããã¹ãã¤ã¦ã§ã¢ããã¼ãã¬ã¼ã¸ã®åºæ¬çãªå¯¾çã解説ãã¾ãã é常ã®Webã¢ããªã¨ç°ãªãAjaxã®ç¹å¾´ã«æ½ããªã¹ã¯ ãAjaxã®ã»ãã¥ãªãã£ãã¨ãããªããã£ã¦ãããAjaxã¨ã¯ãããåãªãWebãã©ã¦ã¶ã§åä½ããã¢ããªã±ã¼ã·ã§ã³ãªã®ã ãããããã¾ã§ã®Webã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£ã¨ãã¾ãå¤ãããªãã®ã§ã¯ï¼ãã¨äºæ³ãããæ¹ãå¤ãã§ãããã確ãã«ãWebã¢ããªã±ã¼ã·ã§ã³ã¨ãã¦æ³¨æãã¹ãã»ãã¥ãªãã£ã®ãã¤ã³ãã¯ãAjaxã«ããã¦ãå ±éãã¦å½ã¦ã¯ã¾ãã¨èãã¦åé¡ã
ãããã³ã° Wiki â ãããã³ã°ã®é¢é£ã®ããããã«ã¤ãã¦ã¾ã¨ãã¦ã¿ããã¨æã£ã¦ããwikiã§ããæªããã¨ã«ã¯ä½¿ããªãã§ãã ããï¼ãã¶ã使ããªãã¨æãã¾ããï¼ã å 容ã¯å°ããã¤å å®ããã¦ããããã¨æã£ã¦ãã¾ãããwikiã®ä½¿ãæ¹ã¯ãã¾ãããã£ã¦ããªãã®ã§äºæ ã§æ¶ããããããã¾ããã 硬ãã®ã§æä½ããã§ãã¾ããã«ãããã¨æãã¾ãã 誰ãç·¨éããªãã®ã§ç·¨éã§ããªãããã«æ»ãã¾ãããç·¨éããã人ã¯yamamoto at bogus.jpå®ã«ã¡ã¼ã«ããããblogã«ã§ãæ¸ãè¾¼ãããé»è©±ã§ããã¦ãã ãããã â
Please Sign In No account? Create new user.
ãä¾µå ¥åæãã ãã§ã¯ããããçç±ââçå ç©¶æãåªå é ä½ä»ãã¯å¤§ä¸å¤«ï¼ãã¢ã¿ãã¯ãµã¼ãã§ã¹ç®¡çãç¡é§ã«ãªããã¤ã³ã 2025å¹´8æ27æ¥ãITmedia Security Week 2025 å¤ã§ã人æ°ã®ããããã£ã¹ããã»ãã¥ãªãã£ã®ã¢ã¬ãã主宰ãã3人ã®ãªãµã¼ãã£ã¼ããåã³ã¢ã¿ãã¯ãµã¼ãã§ã¹ç®¡çã顿ã«ããã«ãã£ã¹ã«ãã·ã§ã³ãè¡ã£ããï¼2025å¹´11æ18æ¥ï¼
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã¡ã³ããã³ã¹
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}