Shibuya.XSS techtalk #7 ã®è³æã§ãã

Shibuya.XSS techtalk #7 ã®è³æã§ãã
4. å ¸åçãªXSSãµã³ãã«ã«å¯¾ãããç´ æ´ãªçåã ⢠ã¯ããã¼ã®å¤ãã¢ã©ã¼ãã§è¡¨ç¤ºããã¦ããç¹ã«å±éºæ§ã¯ãªãã ããªæ°ããã ⢠ã¯ããã¼ã®å¤ã¯ãã©ã¦ã¶ã®ã¢ããªã³ãªã©ã§ã表示ã§ãããã ⢠任æã®JavaScriptãå®è¡ãããã¨è¨ã£ã¦ãããã¼ã ãã¼ã¸ä½ ãã°ä»»æã®JavaScriptãæ¸ããããè¦ã人ã®ãã©ã¦ã¶ã§å®è¡ ããããã⦠Copyright © 2013 HASH Consulting Corp. 4 5. ããããã®çåï¼JavaScriptã¯å±éºã? ⢠å®ã¯ãJavaScriptã®å®è¡èªä½ã¯å±éºã§ã¯ãªã ⢠Webã¯ãæªç¥ã®ï¼ã²ãã£ã¨ããã¨æªæã®ãã?ï¼ãµã¤ãã訪åã ã¦ããæªããã¨ããèµ·ããªãããã«è¨è¨ããã¦ãã ⢠JavaScriptã®ããµã³ãããã¯ã¹ãã«ããä¿è· â JavaScriptãããã¼ã«ã«ãã¡ã¤ã«ã«ã¢ã¯ã»ã¹ã§ããªã â JavaScriptããã¯ãªãã
ã¯ã¦ãªã°ã«ã¼ãã®çµäºæ¥ã2020å¹´1æ31æ¥(é)ã«æ±ºå®ãã¾ãã 以ä¸ã®ã¨ã³ããªã®éããä»å¹´æ«ãç®å¦ã«ã¯ã¦ãªã°ã«ã¼ããçµäºäºå®ã§ããæ¨ããç¥ãããã¦ããã¾ããã 2019å¹´æ«ãç®å¦ã«ãã¯ã¦ãªã°ã«ã¼ãã®æä¾ãçµäºããäºå®ã§ã - ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãã®ãã³ãæ£å¼ã«çµäºæ¥ã決å®ãããã¾ããã®ã§ã以ä¸ã®éãã確èªãã ããã çµäºæ¥: 2020å¹´1æ31æ¥(é) ã¨ã¯ã¹ãã¼ãå¸æç³è«æé:2020å¹´1æ31æ¥(é) çµäºæ¥ä»¥éã¯ãã¯ã¦ãªã°ã«ã¼ãã®é²è¦§ããã³æ稿ã¯è¡ãã¾ãããæ¥è¨ã®ã¨ã¯ã¹ãã¼ããå¿ è¦ãªæ¹ã¯ä»¥ä¸ã®è¨äºã«ãããã£ã¦æç¶ãããã¦ãã ããã ã¯ã¦ãªã°ã«ã¼ãã«æ稿ãããæ¥è¨ãã¼ã¿ã®ã¨ã¯ã¹ãã¼ãã«ã¤ã㦠- ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãå©ç¨ã®ã¿ãªãã¾ã«ã¯ãè¿·æãããããããã¾ãããã©ãããããããé¡ããããã¾ãã 2020-06-25 è¿½è¨ ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ã®ã¨ã¯ã¹ãã¼ããã¼ã¿ã¯2020å¹´2æ28
html5securityã®ãµã¤ãã«ãXSSã®å種æ»æææ³ãã¾ã¨ãããã¦ããã®ãçºè¦ãã!ã¨ãããã¨ã§ãå人çã«ãã!ãã¨æã£ãæ»æããµã³ãã«ã¤ãã§ãç´¹ä»ãã¾ãã 1. CSS Expression IE7以åã«ã¯ãCSS Expressionsãã¨ããæ¡å¼µæ©è½ããããCSSå ã§JavaScriptãå®è¡ã§ããããã¾ãã <div style="color:expression(alert('XSS'));">a</div> ç¢ºèª @IT -ï¼»æè»ãããï¼½IEã®CSS解éã§èµ·ããXSS ã§è©³ãã解説ããã¦ãã¾ãããCSSã®è§£éãæè»ãªãã¨ã¨ãããã¾ã£ã¦èªåã§ç¡å®³åããã®ã¯ãªããªãå°é£ã以ä¸ã®ãããªã³ã¼ãã§ãã¹ã¯ãªãããå®è¡ããã¦ãã¾ãã¾ãã <div style="color:expr/* ã³ã¡ã³ãã®æ¿å ¥ */ession(alert('XSS'));">a</div> ç¢ºèª <div s
ã¯ã¦ãªããã¯ãã¼ã¯çµç±ã§ç¥ã£ãã®ã§ãããXSS Challenges ã¨ããXSSã®ç·´ç¿ãµã¤ããå ¬éããã¦ãã¾ããå ¨18åãåç´ãªãã®ããå§ã¾ããã ãã ãã¨é£ãããªã£ã¦ããããã§ããä¸é¨ã®åé¡ã§ã¯IEã®ã¿å¯¾å¿ã®ããã§ãããã¡ã¼ã«ã¢ãã¬ã¹ãç»é²ããã¨ã©ãã¾ã§ã¯ãªã¢ãããã®ã©ã³ãã³ã°ã表示ããããã¨ããããããä»ä¸ããã«ãªã£ã¦ãã¾ãã æ®æ®µã¯ãªããªãå®éã«XSSãä½æã§ããæ©ä¼ã¯å°ãªãã¨æãã¾ããã²ã¨ã¤è 試ãã«ãã©ã¤ãã¦ã¿ã¦ã¯ãããã§ãããããã¡ãªã¿ã«ã¿ã¬ã³ãå㯠Stage #5 ã§é³ãä¸ãã¦ãã¾ãã¾ããã
ã¯ããã« ä»åã¯XSSã®èå¼±æ§ããã§ãã¯ããPerlã¹ã¯ãªãããä½æãããã¨æãã¾ãããã¹ã¦ã®XSSã«ããèå¼±æ§ãåé¿ã§ããããã§ã¯ããã¾ãããããã¹ãã³ã¼ãä½æã®ãã³ãã«ãªãã°å¹¸ãã§ãã 対象èªè Webã¢ããªã±ã¼ã·ã§ã³éçºè ã§ãXSSã®ãã¹ãã±ã¼ã¹ãä½æãããæ¹ã å¿ è¦ãªç°å¢ Perl 5.8以ä¸ãåä½ããç°å¢ãåºæ¬åä½ã®ç¢ºèªã¯Mac OS Xãå©ç¨ãã¾ããã次ã®Perlã¢ã¸ã¥ã¼ã«ãå©ç¨ããã®ã§ããããããã¤ã³ã¹ãã¼ã«ãã¦ããã¦ãã ããã Template::Toolkit Web::Scraper Test::Base ã¾ãCGIã使ç¨ããã®ã§ãApacheãªã©ã®CGIãå®è¡ã§ããWebãµã¼ããç¨æãã¦ãã ããã 解説å 容 ã½ã¼ã¹ã³ã¼ã解説 ã¾ãæåã«ã½ã¼ã¹ã³ã¼ãã®è§£èª¬ããã¾ãã xss.pl
å æ¥å ¬éãããã¯ã¦âããã¢ã³ã±ã¼ããã«ã¦ãã¢ã³ã±ã¼ãã®èª¬ææãã¯ã¦ãªè¨æ³ã§æ¸ãããããæ©è½è¿½å ãè¡ã£ãããã®éãTemplate::Plugin::Hatenaãç¨ãããããã¯ãã¯ã¦ãªè¨æ³ãã¼ãµã§ããText::Hatenaï¼æ£ç¢ºã«ã¯ããã®ã´ã¡ã¼ã¸ã§ã³0.16以ä¸ï¼ããTemplate::Toolkitã®ãã©ã°ã¤ã³ã¨ãã¦ä½¿ããããã«ãããã®ã§ããã ã¯ã¦ãªè¨æ³ã¯ãããèªä½ã§å ¨ã¦ã®ææ¸æ§é ã表ç¾ã§ããããããã¯ãã¯ã¦ãªãã¤ã¢ãªã®ã·ã¹ãã èªä½ã¯ãã¯ã¦ãªè¨æ³ã®ã¿ãã許容ããªãã¨ãããã®ã§ã¯ãªãããã¨ãã°ç»åãè²¼ãéã«ã¯ãæ®éã«imgè¦ç´ ãæ¸ãå¿ è¦ãããããã¾ãããã®ä»ã®è¦ç´ ã«ã¤ãã¦ããè¨æ³ãç¨æããã¦ããªããã®ã«ã¤ãã¦ã¯ããã¯ã¦ãªãã¤ã¢ãªã¼ã®ãã«ã - ã¯ã¦ãªãã¤ã¢ãªã¼å©ç¨å¯è½ã¿ã°ãã«æ²è¼ããã¦ãããã®ã«éããèªåã§ã¿ã°ãæ¸ããã¨ãã§ãããããã¯èªç±åº¦ãé«ããåé¢ã§ãXSSãèªçºãå¾ãæ½å¨çãªãª
ååã¯ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ã®ããå¼±æ§ãçªãæ»æã®å¯¾çã¨ãã¦ã®HTMLã¨ã³ã³ã¼ãã®æå¹æ§ãè¿°ã¹ãããã ï¼HTMLã¨ã³ã³ã¼ãã ãã§ã¯ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°æ»æãå®å ¨ã«é²å¾¡ãããã¨ã¯ã§ããªããããã§ä»åã¯ï¼HTMLã¨ã³ã³ã¼ãã§å¯¾å¦ã§ããªãã¿ã¤ãã®ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°æ»æã®æå£ã¨ï¼ãã®å¯¾çã«ã¤ãã¦è§£èª¬ããã HTMLã¨ã³ã³ã¼ãã§å¯¾å¦ã§ããªãæ»æã«ã¯ï¼æ¬¡ã®ãããªãã®ãããã ã¿ã°æåã®å ¥åã許容ãã¦ããå ´åï¼Webã¡ã¼ã«ï¼ããã°ãªã©ï¼ CSSï¼ã«ã¹ã±ã¼ãã£ã³ã°ã»ã¹ã¿ã¤ã«ã·ã¼ãï¼ã®å ¥åã許容ãã¦ããå ´åï¼ããã°ãªã©ï¼ æåã³ã¼ããæ示ãã¦ããªãã±ã¼ã¹ã§UTF-7æåã³ã¼ãã«ããã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã° <SCRIPT>ã®å 容ãåçã«çæãã¦ããå ´å Aã¿ã°ãªã©ã®URLãåçã«çæãã¦ããå ´åæ³¨ï¼ ä»¥ä¸ã§ã¯ï¼HTMLã¿ã°ãCSSã®å ¥åã許容ãã¦ããå ´åã¨ï¼æåã³ã¼ããæ
Web 2.0ã¨ããè¨èã§ç·ç§°ãããæ°ããªã¤ã³ã¿ã¼ãããæ代ãWebãµã¤ããã¨ã³ãã¦ã¼ã¶ã¼ã«ä»æããããæ»æãã¾ãï¼2.0ã¨å¼ã¶ã¹ãé²åãéãããã¨ãã¦ãããæ»æè ã¯Web 2.0ã®ä¸æ ¸æè¡ã§ããJavaScriptãæªç¨ãã¦ãã©ã¦ã¶ãçããå¾æ¥ã®è å¨å¯¾çã¯å ¨ãéç¨ããªããä»ãã®ç¬éã«ãï¼ã¨ã³ãã¦ã¼ã¶ã¼ã¯å人æ å ±ãçã¾ããå±éºã«ããããã¦ããã ããã°/SNSãªã©ã¦ã¼ã¶ã¼çºä¿¡åã®ãµã¤ãï¼Ajaxï¼RSSââãè¯ããããã¯ãã¼ãºã¢ãããããWeb 2.0ãã¨ããããã®è£å´ã§ã¯ï¼ã¨ã³ãã¦ã¼ã¶ã¼ã«æ å ±çé£ãªã©ã®å±éºãåºãã£ã¦ããï¼å³1ï¼ãã¤ã³ã¿ã¼ãããã»ãã³ãã³ã°ãECï¼é»åååå¼ï¼ãµã¤ãã®ã¦ã¼ã¶ã¼IDããã¹ã¯ã¼ãï¼ã¯ã¬ã¸ããã«ã¼ãçªå·ã¯ãã¡ããï¼ä¼æ¥å ã®ã·ã¹ãã ã«ã¢ã¯ã»ã¹ããããã®ãã¹ã¯ã¼ããï¼ãã½ã³ã³ã«èªã¿è¾¼ãã æ©å¯ææ¸ãã¼ã¿ãªã©ï¼å¯¾è±¡ã¯ããããæ å ±ã ã 2006å¹´12ææ«ï¼ç±³å½ã®ã»ãã¥ãªã
ã©ã³ãã³ã°
ãç¥ãã
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}