Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article? ãæ·»ä»ãã¡ã¤ã«ã®ãã¹ã¯ã¼ãã¯å¥ééä»ãã¾ãã çããããæ·»ä»ãããZIPãã¡ã¤ã«ã¨å ±ã«ãã©ããã§ä¸åº¦ã¯ãã®æé¢ãè¦ããã¨ãããã¨æãã¾ãã ããã¦ããã®è¡çºãç¡æå³ã§ããã¨ããäºãã¾ãããåããã¨æãã¾ãã ããããæ¥æ¬ã®ç¹ã«å¤§æä¼æ¥ã§ã¯å¤ãç¿æ £ã責任éãã¨ãã¦ãæªã ã«ä½¿ããç¶ãã¦ããã®ãç¾ç¶ã§ãã ããã¦ããã®ãããªäºãç¶ãã¦ãã伿¥ã§ã¯ãããªããã¯ã©ã¦ãã¹ãã¬ã¼ã¸ãµã¼ãã¹ã®ä½¿ç¨ãå¶éããã¦ããã®ããç´æã§ãã ä»åã¯ããããªè³æ»å¤ãæèãå¼ãæºã£ãç°å¢ã§ããå®å ¨ã§ãªãã¹ãç°¡åã«ãã¡ã¤ã«è»¢éãè¡ããã¢ããªã±ã¼ã·ã§ã³ãä½ã£ã¦ã¿ã¾ããã
ãã®è¨äºã¯ NestJS Advent Calendar 2019 12æ¥ç®ã®è¨äºã§ããæ¨æ¥ã¯ç§ @ci7lus ã® NestJS Response ãããã¼ å¤ãæ¹ ã§ããã 仿¥ã¯ NestJS ã«ãããç°¡æçãªãã¹ã¯ã¼ãèªè¨¼ã®å®è£ ãç´¹ä»ãã¾ãã NestJS ã«ãããèªå¯ã»èªè¨¼ã¯ Guards ã¨ããæ©è½ãç¨ãã¾ãã Guards ã¨ã¯ åè: Guards | NestJS - A progressive Node.js web framework Guards ã¯ãã³ã³ããã¼ã©ã¼ã«ããã¦ã¢ã¯ã»ã¹å ã®æ å ±ã«åãããèªå¯ãè¡ãä»çµã¿ã§ãã Express ãªã©ã«ããã¦èªå¯ã¯ Middleware ã®ä¸é¨ã¨ãã¦å®è£ ããã¾ãããNestJS ã«ããã¦ã¯å°ç¨ã®ã¢ã¸ã¥ã¼ã«ã¨ãã¦å®è£ ããã¦ããã®ã§ããããå©ç¨ãããã¨ã§ãã宣è¨çã§ç¢ºå®ãªèªå¯ãè¡ããã¨ãã§ãã¾ãã ä¸è¨ããã¥ã¡ã³ãã§ã¯ããã¬ã¼ã³
Intro Cookie ã¯ããã©ã¦ã¶ã«ä¸åº¦ä¿åããã°ã次ãããã®å¤ãèªåçã«éã£ã¦ããã¨ãããé常ã«é½åã®è¯ã仿§ããå§ã¾ã£ãã State Less ãåºæ¬ã ã£ã Web ã«ã»ãã·ã§ã³ã®æ¦å¿µããããããä»ã§ã¯ãããç¡ããã°å®ç¾ã§ããªãã¦ã¼ã¹ã±ã¼ã¹ã®æ¹ãå¤ãã å·éã«èããã°ãµããã¦ãã¨ãã¦æããªããããåããããããããã«ãå½åã¯ãã®ãããããããªã«éå®ãããWeb ã®ããæ¹ãå¤ãããããããªããããéè¦ãªè°è«ãå·»ãèµ·ãããã¨ã«ãªãã¨ã¯ãæåã®å®è£ è ãæã£ã¦ãªãã£ãã ããã ãã㪠Cookie ãä»ã©ã使ããã3rd Party Cookie (3rdPC) ã®ä½ãåé¡ã«ãªã£ã¦ããã®ããè¸ã¾ããããããã©ããªã£ã¦ããã®ãã«ã¤ãã¦èããã Cookie ã®ã¦ã¼ã¹ã±ã¼ã¹ Web ã«ãã API ã®ä¸ã§ã Cookie ã¯ããã¤ãã®ç¹ã§ç¹ç°ãªæåããã ä¸åº¦ä¿åããã°ã次ããèªåã§éã ç¾
å® ãµããã便ããå¹³æãã¹ã¯ã¼ããæ¼æ´©ããä»¶ãåãã¦ãããããã¦ãã¹ã¯ã¼ãã®å®å ¨ãªä¿åæ¹æ³ãé¢å¿ãéãã¦ãã¾ããç¾å¨ã®ãã¹ã¯ã¼ãä¿åã®ãã¹ããã©ã¯ãã£ã¹ã¯ããã¹ã¯ã¼ãä¿åã«ç¹åããããã·ã¥é¢æ°ï¼ã½ã«ããã¹ãã¬ããã³ã°ãç¨ããï¼ã§ããbcryptãArgon2ãªã©ãç¨ãããã¨ã§ããPHPã®å ´åã¯ãPHP5.5以éã§ä½¿ç¨ã§ããpassword_hash颿°ãé常ã«ä¾¿å©ã§ãããä»ã®è¨èªãã¢ããªã±ã¼ã·ã§ã³ãã¬ã¼ã ã¯ã¼ã¯ã§ããããããç¨æããã¦ãããã¹ã¯ã¼ãä¿è·ã®æ©è½ã使ããã¨ã¯ãã¹ã¯ã¼ãä¿è·ã®ç¬¬ä¸é¸æè¢ã¨ãªãã¾ãã ãªãã§ãbcryptã¯ãPHPã®password_hash颿°ã®ããã©ã«ãã¢ã«ã´ãªãºã ã§ããä»ãä»ã®è¨èªã§ãå®å ¨ãªããã·ã¥ä¿åæ©è½ã¨ãã¦åºãå©ç¨ããã¦ãã¾ããããã¹ã¯ã¼ããæå¤§72æåã§åãè©°ããããã¨ããå®è£ ä¸ã®ç¹æ§ãããããã®ç¹ãæ°ã«ãªã人ãããããã§ãï¼ãã®å¶éã¯DoSèå¼±æ§åé¿ã
â æ¹æ£NICTæ³ãããçä¸ãå·¥å ´åºè·æå ±éåæãã¹ã¯ã¼ããèå¥ç¬¦å·ã«å½ãããªããã¨ãçè§£ããã¦ããªã å æã®ãã¨ãNHKãã¥ã¼ã¹ããç·åç IoTæ©å¨ã«ç¡å·®å¥ä¾µå ¥ãã¨å ±ãããããã§ãä¸é¨ã®ã¡ãã£ã¢ãå¾è¿½ãããããçä¸ãã¦æ°ã®æ¯ãªãã¨ã«ãªã£ã¦ããããã®å¾ãããããã¨å»¶ç¼ããæ¨æ¥ã«ãªã£ã¦ãã²ãããæ°ãããç·åçã®ã»ãã¥ãªãã£èª¿æ»ã«ãå½ã䏿£ãã°ã¤ã³ãã¨é¨ãé ã®æªã人ãã¡ãã¨ã®ããã¡è¨äºãåºãã«è³ã£ããããã¯æåã®NHKå ±éãç´ äººèãã§ååãã¦ããã¨ããã«åå ãããã ç·åç IoTæ©å¨ã«ç¡å·®å¥ä¾µå ¥ã調æ»ã¸ åä¾ãªã調æ»ã«æ¸å¿µã, NHKãã¥ã¼ã¹, 2019å¹´1æ25æ¥ å ¨å½ã®å®¶åºã伿¥ã«ããã¤ã³ã¿ã¼ãããå®¶é»ãªã©ãããã #Iotæ©å¨ ã«å½ãç¡å·®å¥ã«ä¾µå ¥ã試ã¿ãããããªä¸çã§ãä¾ã®ãªã調æ»ãæ¥æããå§ã¾ãã¾ãã #ãµã¤ãã¼æ»æ 対çã®ä¸ç°ã ã¨ãããã¨ã§ãããå®è³ªçã«ä¸æ£ã¢ã¯ã»ã¹ã¨å¤ãããªãè¡
æ§ç¯ããã¡ã¼ã«ãµã¼ãã¼ããéä¿¡ããã¡ã¼ã«ãè¿·æã¡ã¼ã«ã¨ãã¦èå¥ããããã¨ã¯ããã¾ãããï¼ ãã®ãããªå ´åã¯ãéä¿¡ããã¡ã¼ã«ãçµç±ããã¡ã¼ã«ãµã¼ãã¼ã®ãªããã¾ãã¡ã¼ã«å¯¾çã«å¼ã£ããã£ã¦ããå ´åãæ®ã©ã§ããï¼ã¾ãã«è¿·æã¡ã¼ã«ã®ãã©ãã¯ãªã¹ãã«ç»é²ããã¦ãããã¨ãããã¾ãï¼ ååã¾ã§ã®è¨äºã§å®å ¨ãªã¡ã¼ã«ãµã¼ãã¼ã®æ§ç¯æé ãç´¹ä»ãã¦ãã¾ããããã¡ã¼ã«ãåä¿¡å´ã§éã£ãã¡ã¼ã«ãè¿·æã¡ã¼ã«ã¨å¤å®ãããå¯è½æ§ãããã¾ãã
ç¹å®ã®ä¼ç¤¾ããã©ã³ãã®ååãé¨ã£ããä¸å¯©ãªã¡ã¼ã«ãåãåã£ããã¨ãããæ¹ãå¤ãã®ã§ã¯ãªãã§ããããï¼ãããããã£ãã·ã³ã°ã¡ã¼ã«ã§ã¯ãã¡ã¼ã«åä¿¡è ã®å人æ å ±ãçãããã«ãã¡ã¤ã³ã¹ãã¼ãã£ã³ã°ï¼ãªããã¾ãï¼ãããå ´åãå¤ãããã§ããç¾å¨ã®ã¡ã¼ã«ã¤ã³ãã©ã®è¦æ ¼ã¯å®å ¨ã§ã¯ãªããæã«æªç¨ããããã¨ãããã¾ããããã§ã¯ãã©ããã£ã¦èªèº«ã®ãã¡ã¤ã³ããã©ã³ãããããã âãªããã¾ãâ ããå®ãã°è¯ãã®ã§ããããï¼ DMARCï¼Domain-based Message Authentication, Reporting & Conformanceï¼ã«åå ããã¨ããæ¹æ³ãããã¾ããDMARCã¯ããSPFã¨DKIMã®ã©ã¡ãã®èªè¨¼ã«ã失æããå ´åã«ãåä¿¡ãµã¼ãã¯ã©ããã¹ãããã示ãããã®ã§ããããã¯ã¤ã¾ããããªããã¾ãã¡ã¼ã«ãåãåã£ãæã«ãåä¿¡ãµã¼ãã¯ã©ããã¹ãããã¨ãããã¨ã§ãã SendGridã§DMARC
ãã®è¨äºã¯ What Is DMARC in Email (Understanding DMARC Records)? ã®æè¨³ã§ãã DMARCï¼Domain-based Message Authentication, Reporting & Conformanceï¼ã¨ã¯ãã¡ã¼ã«ã®èªè¨¼ãè¡ãSPFï¼Sender Policy Frameworkï¼ã¨DKIMï¼DomainKeys identified mailï¼ãå©ç¨ãã¦ãã¡ã¼ã«ã®ä¿¡é ¼æ§ã夿ãããããã³ã«ã§ããDMARCãå©ç¨ãããã¨ã§ãæ£è¦ã®çµç¹ã«ãªããã¾ããæ»æè ã®ã¡ã¼ã«ï¼ãªããã¾ãã¡ã¼ã«ï¼ããã¡ã¤ã³ç®¡çè ãææã§ããããã«ãªãã¾ãã SPF éä¿¡è ãèªèº«ã®ãã¡ã¤ã³ã®ã¡ã¼ã«éä¿¡ãµã¼ãï¼IPã¢ãã¬ã¹ï¼ãäºåã«ç»é²ãã¦ãããã¨ã§ããªããã¾ããè¦ç ´ãæè¡ã§ããåä¿¡ãµã¼ãã¯SPFã¬ã³ã¼ãããã§ãã¯ãã許å¯ããããµã¼ãããéãããã¡ã¼ã«ã§ããã
ãã¸ã»ã¡ãã£ã¢ã»ãã¼ã«ãã£ã³ã°ã¹åä¼ç¤¾ã§é販大æãã£ãã¹ã»ã»ã·ã¼ã«ãæ°ããªææ³ã«ãããµã¤ãã¼æ»æã®è¢«å®³ã«éã£ããå社ã¯2018å¹´6æ2æ¥ã«Webãµã¤ããã»ã·ã¼ã«ãªã³ã©ã¤ã³ã·ã§ãããã䏿£ã¢ã¯ã»ã¹ãåãã4æ¥å¾ã®6æ6æ¥ã«é¡§å®¢æ å ±ãæµåºããå¯è½æ§ããã£ãã¨å ¬è¡¨ããã æå£ã¯ããªã¹ãæ»æï¼ãªã¹ãåã¢ã«ã¦ã³ããããã³ã°ï¼ãã®ä¸ç¨®ã ããªã¹ãæ»æã¨ã¯ããµã¤ãã¼æ»æãéåå¼ãªã©ä½ããã®ææ®µã§å ¥æãããæ»æå¯¾è±¡ã®Webãµã¤ãã®ã¦ã¼ã¶ã¼IDã¨ãã¹ã¯ã¼ãã®ä¸è¦§ï¼ãªã¹ãããã¹ã¯ã¼ããªã¹ãã¨ãï¼ã使ã£ã¦ãæ©æ¢°çã«ãã°ã¤ã³è©¦è¡ãç¹°ãè¿ãã䏿£ãã°ã¤ã³ã試ã¿ããã®ã ããã°ã¤ã³ã§ãããå人æ å ±ãçãã ãããã¤ã³ããéåã«æãããããã ä»åããã£ãã¹ã»ã»ã·ã¼ã«ã襲ã£ãã®ã¯ãããå·§å¦ããå¢ãããæ°åãªã¹ãæ»æãã¨è¨ãããã®ã ã£ããçµæçã«ä¸æ£ãã°ã¤ã³ãæåããã®ã¯490人ã«ã¨ã©ã¾ã£ããã®ã®ãã»ãã¥ãªãã£é¢ä¿è ã«ã¯æ³¢ç´ã
Google ã¢ã«ã¦ã³ãã§ 2 段éèªè¨¼ãæå¹ã«ãã¦ããå ´åã«ã¯ã¦ã¼ã¶ã¼åã¨ãã¹ã¯ã¼ãã«å ãã¦ç¢ºèªã³ã¼ããªã©ã®èªè¨¼ãè¡ãå¿ è¦ãããã¾ããã Outlook ãªã©ä»ç¤¾ã®ãµã¼ãã¹ã製åãã Google ã¢ã«ã¦ã³ãã«ãã°ã¤ã³ãããã¨ãã㨠2 段éèªè¨¼ã«å¯¾å¿ãã¦ããªããããã°ã¤ã³ã§ããªããªã£ã¦ãã¾ãã¾ããããã§ 2 段éèªè¨¼ã«å¯¾å¿ãã¦ããªããµã¼ãã¹ã製åãããã°ã¤ã³ããããã®ææ®µã¨ãã¦ã¢ããªãã¹ã¯ã¼ããç¨æããã¦ãã¾ããããã§ã¯ã¢ããªãã¹ã¯ã¼ãã®çæã¨å®éã®å©ç¨æ¹æ³ã«ã¤ãã¦è§£èª¬ãã¾ãã (Last modified: 2023å¹´07æ10æ¥) æ°ããã¢ããªãã¹ã¯ã¼ããçæãã æ°ããã¢ããªãã¹ã¯ã¼ãã使ãã¾ãã Google ã¢ã«ã¦ã³ãã«ãã°ã¤ã³ãããã¨ãç»é¢å³ä¸ã«è¡¨ç¤ºããã¦ãããããã£ã¼ã«ç»åãã¯ãªãã¯ãã表示ãããç»é¢ã®ä¸ã®ãGoogleã¢ã«ã¦ã³ãã管çããã¯ãªãã¯ãã¦ãã ããã ãGo
2018å¹´2ææ«é ããä½è ãã«ããã«ã¼ã¿ã¼å ã®è¨å®æ å ±ãæ¸ãæãããã被害ãå ±åããã¦ãã¾ããæ¹ããã«ããã¤ã³ã¿ã¼ãããã¸æ¥ç¶ã§ããªããªã£ããããã«ã¦ã§ã¢é å¸ãµã¤ãã¸èªå°ããããããäºè±¡ãçºçããæ¥æ¬å½å ã§ã3æåã°ãããããåæ§ã®äºè±¡ãå ±åãããã£ã¦ãã¾ãã ããã§ã¯é¢é£æ å ±ãã¾ã¨ãã¾ãã 確èªããã¦ãã被害äºè±¡ (1) ã«ã¼ã¿ã¼ã®è¨å®æ å ±ãæ¹ããããã ã«ã¼ã¿ã¼å é¨ã«è¨å®ãããDNSæ å ±ãæ¹ãããããã DNSã¯ãã©ã¤ããªãã»ã«ã³ããªã¨ãã«æ¹ãããããäºä¾ãå ±åããã¦ããã (2) ãã«ã¦ã§ã¢é å¸ãµã¤ãã¸èªå°ããã æ¹ãããããDNSã¸åå解決ã®ã¯ã¨ãªãè¦æ±ããã¨ãã«ã¦ã§ã¢ãé å¸ãããµã¤ãã®IPã¢ãã¬ã¹ãè¿ããé å¸ãµã¤ãã¸èªå°ãããã ä¸é¨ãµã¤ãï¼Twitter,Facebookãªã©ï¼ã¯æ£è¦ã®IPã¢ãã¬ã¹ãè¿ãããµã¤ãã¸æ¥ç¶ã§ããã èªå°å ã®é å¸ãµã¤ãã§ã¯ãã«ã¦ã§ã¢ã®ã¤ã³ã¹ãã¼ã«ãä¿ã
ã夿´å±¥æ´ 2018å¹´2æ15æ¥ãå½åã®è¨äºã¿ã¤ãã«ã¯ããã¾ãªãHTTPSåãªã®ãï¼ æè¡è ãç¥ã£ã¦ããããSEOãããã£ã¨å¤§åãªã㨠â TLSã®æ´å²ã¨æè¡èæ¯ãã§ããããç¾è¡ã®ãã®ã«å¤æ´ãã¾ãããç¾å¨Googleã§ã¯Webãµã¤ãã®HTTPS対å¿ã¨æ¤ç´¢çµæã®é¢ä¿ã強調ãã¦ããããæ¬è¨äºã®è¶£æ¨ã®ä¸ã¤ã«ãæ¬æ¥ã¯ç¬ç«ããåé¡ã§ããSEOã¨HTTPSåãé¢é£ä»ããã¨ããæ ¹å¼·ã誤解ãè§£ããã¨ãããã¾ãããå½åã®ã¿ã¤ãã«ã§ã¯ããã£ã¦SEOã¨HTTPSãé¢é£ä»ãã¦èªã¾ãããããããããã¾ãåæ§ã®ææãããã ãããã¨ãã夿´ãããã¾ããã HTTPã¨HTTPSã¯ãå ±ã«TCPéä¿¡ä¸ã§åä½ãã¾ãããããã£ã¦ãããããTCPãã³ãã·ã§ã¤ã¯ã§éä¿¡ãéå§ãã¾ãã HTTPéä¿¡ã®å ´åã«ã¯ããã®TCPãã³ãã·ã§ã¤ã¯ç´å¾ã«ãHTTPãªã¯ã¨ã¹ãã¨ã¬ã¹ãã³ã¹ã®ããåããå§ã¾ãã¾ãããã®HTTPã®ããåãã¯å¹³æéä¿¡ã§ãããé
Chrome 61ãã使ããããã«ãªã£ãWebUSB APIã使ã£ã¦USBããã¤ã¹ã¨ä¼è©±ããæ¹æ³ã解説ãã¾ãã ããã¯2017å¹´12æ13æ¥ã«è¡ããã Shibuya.XSS techtalk #10 ã®çºè¡¨è³æã§ãã ããã¯2017å¹´9æ23æ¥ã«è¡ããã 第3å ã«ã¼ãã«ï¼VMæ¢æ¤é@åé¸ã§ã®çºâ¦
Webã¢ããªã±ã¼ã·ã§ã³ã®éçºã»å±éãè¡ã£ã¦ãã人ã ã«ã¨ã£ã¦ãã»ãã¥ãªãã£ç¢ºä¿ã¯å¤§ããªé¢å¿äºã®1ã¤ã ã¨ããã¾ãããã®ããã®ãã¹ããã©ã¯ãã£ã¹ããã¬ã¼ã ã¯ã¼ã¯ãã¬ã¤ãã©ã¤ã³ãæä¾ãã¦ããã®ãOWASPï¼Open Web Application Security...
Wi-FiãBluetoothã®ãªã³ãªãããé³éãè¼åº¦ã®èª¿ç¯ãããã«ã¯ç¹å®æ©è½ã®ã·ã§ã¼ãã«ãããé ç½®ã§ããã³ã³ããã¼ã«ã»ã³ã¿ã¼ã¯ããiOS 11ãã®ä¸ã§ãç¹ã«å¤§ããªå¤æ´ãå ãããããã®ã®ã²ã¨ã¤ã§ãããããããã®ã³ã³ããã¼ã«ã»ã³ã¿ã¼ã§Wi-FiãBluetoothããªãã«ãã¦ãWi-Fiããã³Bluetoothãå®å ¨ã«ç¡å¹ã«ãªãããã§ã¯ãªããã¨ãæããã«ãªãã¾ããã iOS 11's Control Center doesn't let you turn off Wi-Fi or Bluetooth - The Verge https://www.theverge.com/2017/9/20/16340460/apple-ios-11-control-center-wi-fi-bluetooth-tricking-users Apple clarifies why iOS 11 Contro
æ¬æ¥ã³ã¼ãã¬ã¼ããµã¤ãã§ãç¥ããããéããWebçã®ã¡ã«ã«ãªã«ããã¦ä¸é¨ã®ã客ãã¾ã®å人æ å ±ãä»è ããé²è¦§ã§ããç¶æ ã«ãªã£ã¦ãããã¨ã夿ãã¾ãããåå ã¯ãã§ã«å¤æãã¦ä¿®æ£ãå®äºãã¦ããã¾ããã¾ããå人æ å ±ãé²è¦§ãããå¯è½æ§ã®ããã客ãã¾ã«ã¯ãã¡ã«ã«ãªäºåå±ãããã¡ã«ã«ãªå ã®åå¥ã¡ãã»ã¼ã¸ã«ã¦ãé£çµ¡ããã¦ããã ãã¾ããã ã客ãã¾ã®å¤§åãªå人æ å ±ããé ãããã¦ããã«ãé¢ãããããã®ãããªäºæ ã«è³ããæ·±ããè©«ã³ãç³ãä¸ãã¾ãã æ¬ã¨ã³ããªã§ã¯æè¡ç観ç¹ãã詳細ããä¼ãããã¦ããã ãã¾ãã 2017å¹´6æ27æ¥ãCDNã®ãã£ãã·ã¥ã®åä½ã«ã¤ãã¦ãCDNãããã¤ãã¨ä»æ§ã«ã¤ãã¦ç¢ºèªãæ¤è¨¼ãè¡ãã¾ããããã®çµæä¸é¨è¨è¿°ã«å®éã¨ç°ãªãç®æããããå çä¿®æ£ãããã¾ããã æ¦è¦ ã¡ã«ã«ãªWebçã®ã³ã³ãã³ããã£ãã·ã¥ããã¦ããCDNã®ãããã¤ãåãæ¿ããè¡ãã¾ããã ãã®éæ¬æ¥ãã£ãã·ã¥ãããã¹ãã§ãªã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}