先日ã€ãªã‹ãªã‹å¼·çƒˆãªXSS攻撃手法ãŒå…¬é–‹ã•れã¦ã„ã¾ã—ãŸã€‚ DNSã¸ã®å•ã„åˆã‚ã›çµæžœã«JavaScriptを埋ã‚込んã§ã—ã¾ãŠã†ã¨ã„ã†ã‚‚ã®ã§ã™ã€‚ SkullSecurity: Stuffing Javascript into DNS names DarkReading: Researcher Details New Class Of Cross-Site Scripting Attack nCircle: Meta-Information Cross Site Scripting (PDF) 自動生æˆã•れるWebページä¸ã«ã€DNSã«ã‚ˆã‚‹åå‰è§£æ±ºçµæžœãŒã‚¨ã‚¹ã‚±ãƒ¼ãƒ—ã•れãªã„状態ã§å«ã¾ã‚Œã¦ã„ã‚‹ã¨ã€JavaScriptãŒå®Ÿè¡Œã•れã¦ã—ã¾ã†ã¨ã„ã†ä»•掛ã‘ã§ã™ã€‚ 「hogehoge.example.comã€ãŒæœ¬æ¥ãªã‚‰ã°ã€Œ198.1.100.3ã€ã¨ã„ã†ã‚ˆã†ãªIPアドレスãŒçµæžœã¨ã—ã¦è¿”ã‚‹ã¨ã“ã‚ã‚’ã€DNSã«ç´°å·¥ã‚’行ã£
{{#tags}}- {{label}}
{{/tags}}