ãã£ã¨ä»¥åã«ä½ãã§ããå ¬å£ä½å® ã§ã¯ãæ°´éã®èå£ï¼æ°´æ ï¼ãã¬ãã¼å¼ã«ãªã£ã¦ãã¦ãå¼ã£è¶ããå½åã¯ããã¶ãæ¸æã£ããã¨ããã®ããã¬ãã¼ãæ¼ãä¸ããã¨æ°´ãåºãã®ã§ã¯ãªããã¬ãã¼ãå¼ãä¸ããã¨æ°´ãåºãä»æ§ã ã£ãããã ã¢ãã©ã¼ãã³ã¹ãªã©ã®èªç¥ç§å¦çãªèãæ¹ãæã¡åºãã¾ã§ããªããæ¼ãã°åºããã®ãèªç¶ã§ãããã¨éåæãæ±ãç¶ãã¦ããã®ã ããããæ¥ã¢ã¤ã¢ã¤ãã¹ãããªæ¶ãã¦ãã¾ãåºæ¥äºããã£ããããã¯ã å°éãèµ·ãã£ã¦ä¸ããã¢ããè½ã¡ã¦ããã¨ãæ°´ãåºã£ã±ãªãã«ãªããªã ã¨ããçç±ãç¥ã£ããã¨ã ã£ãããã®ç¬éãç§ã®ã¢ã¿ãã®ä¸ã§ä½ããã²ã£ããè¿ããå¼ãä¸ããæ¹å¼ã®æ°´æ ããã£ããæã«ãªãããã®ã¨ãªã£ãããã®å¾ãã¾ãå¼ã£è¶ãããã¦ããã¾ã¯æ¼ãä¸ããæ¹å¼ã«ãªã£ã¦ãã¾ã£ãã®ã ãâ¦â¦ã ãã¦ãVisual Basic 2005ï¼ä»¥ä¸VB 2005ï¼ã¨Visual Basic 6.0ï¼ä»¥ä¸VB 6ï¼ã¯ãã¼ã¸ã§ã³çªå·ããé
ãµã¼ãä»®æ³åç°å¢ã¨ãã¦æå¾ ããã¦ããXenã§ããã7æã«çºè¡¨ãããSUSE Linux Enterprise Server 10ã§æ£å¼ã«ãµãã¼ãããããã¨ãå®éã®æ¥åãªã©ã§ä½¿ç¨ã§ããç°å¢ãæ´ãã¤ã¤ããã¾ããããããã®ä¸æ¹ã§ãçµ±åçã«ç®¡çã§ãããã¼ã«ã管çã½ãªã¥ã¼ã·ã§ã³ã®ä¸è¶³ãã¦ããã¨ãæ¸å¿µããããã¾ã å°å ¥ã§ããªãã¨ãã£ã声ãèãã¾ãã ãµã¼ãä»®æ³åãè¡ãããã¨ããã¦ã¼ã¶ã®ãã¼ãºã¯ãä½å°ãã®ç©çãµã¼ããçµ±åï¼ã³ã³ã½ãªãã¼ã·ã§ã³ï¼ãããã¨ãããã®ãªã®ã§ãä¸æ¬ç®¡çãè¡ãã管çã½ãªã¥ã¼ã·ã§ã³ã®å¿ è¦æ§ã¯é常ã«é«ãã¨ãããã§ãããã ããã§æ¬é£è¼ã§ã¯ãXenã管çãããã¼ã«ã®ç¾ç¶ã¨èª²é¡ãåãä¸ãã¦ããã¾ãã第1åç®ã®ä»åã¯ããããªãã§ã¯ããã¾ããXenã®å½é¢ã®ã©ã¤ãã«ã§ãããVMware Infrastructure 3ãã§å©ç¨ã§ãã管çãã¼ã«ãVMware VirtualCenter 2ããä¾ã«ããµ
AjaxãFlashã使ã£ãWebãµã¤ããç®ã«ããæ©ä¼ãå¢ãã¦ãã¦ãããWebã¢ããªã±ã¼ã·ã§ã³ã§ãªãããªUIãæä¾ã§ããããã«ãªããã¾ãã²ã¨ã¤Webã®è¡¨ç¾åãåºãã£ããä¸æ¹ã§UIã®ãªããåã¯ãããã¾ã§æ°ã ã®ããã¸ã§ã¯ããç¯ãã¦ãããã¥ã¼ã¨ãã¸ãã¯ã®åæ¥ä½å¶ãåã³ææ§ãªãã®ã«å¼ãæ»ããã¨ãã¦ããã çããããããªä¼è©±ã®çµé¨ããªãã ããã? ããã°ã©ã--ããã®ãã«ãã¦ã³ã§ãã¦ã¹é¸ææã®è²ãå¤ããã®ã§ããã°onMouseOverã¨onMouseOutã¤ãã³ããè¨å®ããå¿ è¦ãããã¾ãããããã®WYSIWYGãªã¨ãã£ã¿ã¯hogeEditorãobject idã§æå®ãã¦ãã ãã ãã¶ã¤ã--ã©ããããã¨ã§ãã? æ£ç´ãã£ã¦ããããªããåãã¯ããã¦ã³ã¶ãªã§ããã ãã¼ã¿ãã¼ã¹ã¢ããªã±ã¼ã·ã§ã³ãgrailsã³ãã³ãä¸çºã§æ§ç¯ã§ããæ代ãªãã ããããªãããªUIã ã£ã¦ç°¡åã«ä½ããããZKã¯ãããªå¸æã«å¿
ã½ããã¦ã§ã¢éçºã主æ¥åã¨ããä¼æ¥ãé¨ç½²ã«ããã¦ã¯ã常ã«ãã®æ¹é©ã»æ¹åãæ±ãããã¦ããã¯ãã ãããã§ã¯éçºæ¨æºã®å°å ¥ãæ¹åãã1ã¤ã®å¤§ããªæ¹é©ã»æ¹åé ç®ã®åè£ã«ãªããã¨ã¯æããã§ããã 1. ã½ããã¦ã§ã¢ã®éçºæ¨æºã®ç¾ç¶ ãèªç¤¾ã®éçºæ¨æºãããã52.2ï¼ ã ããã¯ãå°ã å¤ãã§ãã2003å¹´ã«æ¥çµITãããã§ãã·ã§ãã«èªãè¡ã£ãã¢ã³ã±ã¼ãï¼æ¥çµBP社çºè¡ æ¥çµITãããã§ãã·ã§ãã« 2003å¹´7æå·ããéçºããã»ã¹å¤§å ¨ãããå¼ç¨ï¼çµæã§ããããã ããè¦ãã¨ãåæ°ã¨ã¯ããæ¥æ¬ã§ãéçºæ¨æºãæ´»ç¨ããçµç¹çãªã½ããã¦ã§ã¢éçºãè¡ããã¦ããããã«ã¿ãã¾ããããããåã調æ»ã§ä»¥ä¸ã®ãããªçµæãåºã¦ãã¾ãã ãéçºæ¨æºã®ç¨®é¡ï¼ã¦ã©ã¼ã¿ã¼ãã©ã¼ã«åã82.8ï¼ ã ããã ãã§ã¯ä½ã¨ãæè¨ã§ãã¾ãããããããããããã®æ¨æºã®å¤§åããã¡ã¤ã³ãã¬ã¼ã ããªãã³ã³åãã®éçºæ¨æºã®å¯è½æ§ãããã¾ããå®éãçè ãããã
XMLã®ãæ¬å½ã®ã¡ãªãããã£ã¦ãªã«ï¼ ãã®è¨äºã¯ä¸å¿ã¯ãXMLã®ãããã«ããè¨äºãªã®ã ã¨æãã®ã ããããã§æ¹ãã¦ã¡ãªãããç´¹ä»ããã®ã«ããã®ç¨åº¦ã®ã¡ãªããããåºã¦ããªãã¨ããã®ã¯ã©ããããã¨ãªãã ãã ã§ã¯ç§ãçãããã ç§ã¯6ã¤ã®è¨èªï¼C++ãJavaãVBAãPythonãJavaScriptãC#ï¼ã§XMLã触ã£ããã¨ãããããµã³ãã«ç¨åº¦ãªããã£ã¨å¢ããããå®ç¨çãªãã®ãæ¸ããã®ã¯ä¸ã®6ã¤ã ãã ãã¾ã¨ãã«ããã°ã©ãã³ã°ãªã©ãããã¨ããªãç³ã³ã³ãµã«ã®çæ§ã¯ãä»æ¥ã®ã¨ã³ããªãã³ãããã¦ããã¨ããã ããã ã¾ãã¯å¼±ç¹ããã 1. ãã¼ã¹ãé ã æ§é çãªåºåããæ¢ãããã«1æåãã¤æåããã§ãã¯ããå¿ è¦ãããã®ã§é ããXMLã使ãã¨ãã観ç¹ããã¯ããããä¸çªã®ããã«ããã¯ã«ãªãã 2. ãã¼ã¿ã®æ ¼ç´å½¢å¼ãè¦æ ¼ã®åºç¤ã«ãã¦ãã RDBMSãå é¨ã§ã©ã®ããã«ãã¼ã¿ãæ ¼ç´ãã¦ãããã¯ãRDBMSã®
WEBã·ã¹ãã ã§ããã©ã¼ã ã®å ¥åæåã¨ãã¦ã確èªãã¦ãããæ¹ãè¯ãæåã®ãã¿ã¼ã³ãåæãã¦ã¿ã¾ãã (èªåã®åå¿é²ã¨ãã¦ãæãã¤ãããéæ追è¨ã) HTMLã¨ã¹ã±ã¼ã <>&"'å ¥åããæåããã¡ããã¨ç»é¢ã«è¡¨ç¤ºãããã確èªããã ä¾ãã°ã<hr> "' ã®ãããªæåãå ¥ãã¦ã¿ã¦ãHTMLã¨ãã¦è§£éãããªãããã«ãªã£ã¦ãããã¨ã DBã«ç»é²ããããããªé ç®ã®å ´åãDBä¸ã«ã¯ã©ã®ãããªå½¢ã§ç»é²ãããã®ã確èªã(å¿ è¦ããªãã¨ã¹ã±ã¼ããã¦DBä¸ã«ç»é²ãã¦ãããããªãããªã©) JavaScriptã¸ã®åãè¾¼ã¿æå <>&"'\HTMLã¨ã¹ã±ã¼ãã«çµ¡ãã§ããJavaScriptã®ã³ã¼ãã«å¯¾ãã¦ãHTMLã¨ã¹ã±ã¼ãã¨åæ§ã«ã¨ã¹ã±ã¼ãããæåãåãè¾¼ãã¨åé¡ãèµ·ããå¯è½æ§ãããã®ã§æ³¨æã <hr>ãã¨ã¹ã±ã¼ãããæåãåãè¾¼ãã¨ã alert("<hr>");ãã®ã¾ã¾<hr&
ITMediaã®è¨äºãæ½è±¡çããã¦åçãããããªãã£ãã®ã§ã BlackHat ã®ãã¤ã®ã½ã¼ã¹ãæãèªã¿ãã¦ã¿ãã åã¯ãã¤ãé©å½ãªã®ã§ãééããããããããã¾ããã http://www.spidynamics.com/spilabs/js-port-scan/ http://japan.cnet.com/news/sec/story/0,2000056024,20185667,00.htm ç°¡åã«ã¾ã¨ãããã¦ããã ãã¨ã IFrame 㨠Image#src ã«ãã ä»»æã®IPã¢ãã¬ã¹ã«ã¢ã¯ã»ã¹ããã ç¹å®ã®ã¿ã¤ã ã¢ã¦ãæé(ãã¼ãã³ã¼ãã£ã³ã°/ãã¸ãã¯ãã³ãã¼) ã éããããã®ãã¹ãã¯çãã¦ããªãå¤å®ããã¦ããã ããã¯ãFirebug ã§è©¦ãã¦ã¿ãããªãã¨ãªãä½æã (new Image()).src = "http://IPã¢ãã¬ã¹"; ã¨ããã¨ãã«ãæ¬å½ã«åå¨ãã㨠ä¸ç¬ã ã
ããã«ã¡ã¯ï¼ããã¾ãã¨ï¼ ãã¹ãçªé·ã§ãã å æ¥ããµãããã«æãã¦ããã£ãã®ã§ããã ãããªã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ç¨ã®ãã§ãã¯ã·ã¼ããããããã§ãã SECGURU: Web Application Testing cheatsheet ãªããªãé¢ç½ãã®ã§ã軽ãæ¥æ¬èªã«ãã¦ã¿ã¾ãããï¼Special thanks to: ã¸ã¥ã³ã¤ããï¼ â»ééã£ã¦ããããããªãããã 1. ã¢ããªã±ã¼ã·ã§ã³åã¨ãã¼ã¸ã§ã³ 2. ã³ã³ãã¼ãã³ãå 3. éä¿¡ãããã³ã«ãSSLãªãã°ãã¼ã¸ã§ã³ã¨æå·æ¹å¼ 4. ãã©ã¡ã¼ã¿ã¼ã®ãã§ãã¯ãªã¹ã URLãªã¯ã¨ã¹ã URLã¨ã³ã³ã¼ãã£ã³ã° ã¯ã¨ãªã¹ããªã³ã° ãããã¼ ã¯ããã¼ ãã©ã¼ã ãã©ã¼ã ï¼Hiddenï¼ ã¯ã©ã¤ã¢ã³ããµã¤ãã®ã´ã¡ãªãã¼ã·ã§ã³ãã§ã㯠使ç¨ãã¦ããªãä½è¨ãªãã©ã¡ã¼ã¿ã®åå¨ æååé·ã®æ大/æå°å¤ é£çµããã³ãã³ãï¼Concatenate
ä¸ã¤ï¼å¾æãã¦ãããã¨ãããã ä»å¹´ã®6æ29æ¥ï¼ããªãã¸ã§ã¯ãå¶æ¥½é¨ 2006å¤ã¤ãã³ããã«åå ããããªãã¸ã§ã¯ãå¶æ¥½é¨ã¯ï¼æ°¸åã·ã¹ãã ããã¸ã¡ã³ãã®ç¤¾å¡æå¿ãä¸å¿ã«ãªãï¼ãªãã¸ã§ã¯ãæåã®å®è·µï¼ç 究ï¼çºè¡¨ãç®çã¨ãã¦ä½ã£ãã°ã«ã¼ããå¤ã¨å¬ã«å®æçã«ã¤ãã³ããéå¬ãã¦ããã2006å¤ã¤ãã³ãã§6åç®ã¨ãªãã ãã®ã¤ãã³ãã§ï¼ã¹ã¿ã¼ãã¸ãã¯ã®ç¾½çç« æ´ç¤¾é·ãè¬æ¼ãããä»äºã§å¿ è¦ãªãã¨ã¯ããã¼ãã£ã¼ãã§å¦ãã ãã¨ããã»ãã·ã§ã³ãåè¬ãããåãæé帯ã®è£çªçµã§ã¨ã¦ãé åçãªã»ãã·ã§ã³ããã£ãã®ã ãï¼ããã¦ãã¡ããé¸æãããç¾½çæ°ã®ãã¬ã¼ã³ãã¼ã·ã§ã³ã®ãã¾ããããç¥ã£ã¦ããããã ãæ¡ã®å®ï¼ãããããã£ããç¾½çæ°ãã¿ãã¬ããPCã使ã£ã¦ãã®å ´ã§ã©ãã©ãããã¼ãã£ã¼ããæ¸ãã¦ãããè¬æ¼ã®è³æã¯ãã¡ãã§å ¬éããã¦ãããï¼ããã ãã§ã¯ã¨ã¦ãä¼ãããªãã©ã¤ãæããã£ãã è¬æ¼ã®å 容ã¯ãã¼ãã«ã¡ã¢ãããï¼è¬æ¼
bad-headæ°ãã"/.Jerã«èãããã®ã ãï¼ä»OSãèªä½ããæå³ã¯ããã®ã ãããã æè¿ã30æ¥ã§ã§ãã! OSèªä½å ¥éãããèªåã§ä½ãLinux OSãã¨ãã£ãæ¸ç±ãåºã¦ããããå¦ç¿ç¨+OSèªä½ã¸ã®ããããããã¼ãºã¯çãä¸ããã¤ã¤ããããã«æãããã¿ã¬ã³ãåãå¦çã®ã¨ãã¯ï¼ãOSãããã³ã³ãã¤ã©ãã¾ãã¯ããã¼ã¿ãã¼ã¹ãã大è¦æ¨¡ã½ããã¦ã¨ã¢ä½æã®è±å½¢ã ã£ãæ°ãããããå°ãªãã¨ãç¾å¨ã¯ããã³ã³ãã¤ã©ãä½ãããã¨ãï¼ããã¼ã¿ãã¼ã¹ãä½ãããã¨ããã®ã¯ãã¾ãèããªãæ°ããããOSèªä½ãä¾ç¶æ³¨ç®ããã¦ããã®ã¯ï¼ãã¯ããªã¼ãã¹ããã¸ã®ãããããªãã ãããã"
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}