TopicsPlaceHolder SectionTitlePlaceHolder TIME rest time current/total en
ä¸çççå¨ã奮ã£ãTwitterãã¦ã¹ãªã¼ãã¼ã»ãã°ã¯ã©ãåºã¾ã£ãï¼2010.09.22 10:305,281 satomi ããã¯ä»æä¸çä¸ãå¸å·»ããTwitterãã°ã«ãããããã©ã¦ã³å è±é¦ç¸å¤«äººã®Twitterå ¬å¼ãµã¤ãã巨大ãªè±æåï½¢hï½£ãåºã¦ãæ¥æ¬ã®ãã«ããµã¤ãã«èªåãªã³ã¯ãã¦ã¾ã...ãªãã¨ã¾ã...ã ãã¤ãã¿ã¼å ¬å¼Webã§ãªã³ã¯ããã¦ã¹ãªã¼ãã¼ããã¨ããã©ãã¯ã¼ã«ã¹ãã ããã«ãããªãã¤ã¼ãï¼RTï¼ããã¡ããããã®ï½¢ãã¦ã¹ãªã¼ãã¼ãã°ï½£ãããããã²ã©ãã£ãã²ã©ãã£ããä¸çä¸ã«ã¿ãã¿ãéç«ã®ããã«åºã¾ã£ã¦ä¸æã¯ã©ããªããã¨ãã¨æãã¾ãããã ãµã¼ããã¼ãã£ã¼ã®ã¢ããªä½¿ã£ã¦ã人ã¯å¤§ä¸å¤«ã§ãï¼ãã°ã£ãRTããã£ã¡ã§åé¤ã§ãã¾ãï¼ããtwitter.coméãã¦ãããªç¶æ ãªã£ã¦ã¦ããã¯ãªããã人ãå¤ããããï¼ ããã¯Twitterã®ãµã¤ãã«ããã¯ãã¹ã»ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ï¼XSS
html5securityã®ãµã¤ãã«ãXSSã®å種æ»æææ³ãã¾ã¨ãããã¦ããã®ãçºè¦ãã!ã¨ãããã¨ã§ãå人çã«ãã!ãã¨æã£ãæ»æããµã³ãã«ã¤ãã§ãç´¹ä»ãã¾ãã 1. CSS Expression IE7以åã«ã¯ãCSS Expressionsãã¨ããæ¡å¼µæ©è½ããããCSSå ã§JavaScriptãå®è¡ã§ããããã¾ãã <div style="color:expression(alert('XSS'));">a</div> ç¢ºèª @IT -ï¼»æè»ãããï¼½IEã®CSS解éã§èµ·ããXSS ã§è©³ãã解説ããã¦ãã¾ãããCSSã®è§£éãæè»ãªãã¨ã¨ãããã¾ã£ã¦èªåã§ç¡å®³åããã®ã¯ãªããªãå°é£ã以ä¸ã®ãããªã³ã¼ãã§ãã¹ã¯ãªãããå®è¡ããã¦ãã¾ãã¾ãã <div style="color:expr/* ã³ã¡ã³ãã®æ¿å ¥ */ession(alert('XSS'));">a</div> ç¢ºèª <div s
XSS (Cross Site Scripting) Cheat Sheet Esp: for filter evasion By RSnake Note from the author: XSS is Cross Site Scripting. If you don't know how XSS (Cross Site Scripting) works, this page probably won't help you. This page is for people who already understand the basics of XSS attacks but want a deep understanding of the nuances regarding filter evasion. This page will also not show you how to
ï¼»æè»ãããï¼½IEã®CSS解éã§èµ·ããXSSï¼æç§æ¸ã«è¼ããªãWebã¢ããªã±ã¼ã·ã§ã³ã»ãã¥ãªãã£ï¼3ï¼ï¼1/3 ãã¼ã¸ï¼ XSSã«CSRFã«SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã«ãã£ã¬ã¯ããªãã©ãã¼ãµã«â¦â¦Webã¢ããªã±ã¼ã·ã§ã³ã®ããã°ã©ããç¥ã£ã¦ããã¹ãèå¼±æ§ã¯ãã£ã±ãããã¾ããããã§æ¬é£è¼ã§ã¯ããã®ãããªã¡ã¸ã£ã¼ãªãã®â以å¤âãæãä¸ãã¦ããã¾ã ï¼ç·¨éé¨ï¼ ãªãã奥深ãIEã®XSSã®è©± çããããã«ã¡ã¯ãã¯ãããããããã§ãã 第1åãï¼»ããã¯ã²ã©ãï¼½IEã®å¼ç¨ç¬¦ã®è§£éãã¨ç¬¬2åãï¼»ç¡è¦ã§ããªãï¼½IEã®Content-Typeç¡è¦ãã§Internet Explorer(IE)ã®ç¬èªã®æ©è½ãã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼XSSï¼cross-site scriptingï¼ãå¼ãèµ·ããå¯è½æ§ãããã¨ãããã¨ã«ã¤ãã¦èª¬æãã¦ãã¾ããã 第3åã§ãå¼ãç¶ããIEç¹æã®æ©è½ãXSSãå¼ãèµ·ããä¾ã¨ãããã¨ã§ã
ããããäºåinãXSSãããã¡ãã£ããããã§ããï¼ ä½¿ãå¤ãããææ³ï¼ ãã¾ã©ãã¨ã¹ã±ã¼ãå¦çãããã¦ãªãã¦ããµãï¼ é¢é£ã®è¨äºã«å¯¾ãã¦ãã¯ã¦ãªããã¯ãã¼ã¯ã§ãè²ã è¨ããã¦ãããã http://b.hatena.ne.jp/t/%E4%BA%88%E5%91%8A.in?threshold=1 ãã¥ã¼ã¹ãµã¤ãã§ãããããªç ½ãè¨äºãæ¸ããã¦ãããããããã©â¦ ä»åã®ä»¶ã«ã¤ãã¦ITä¼æ¥ã«å¤ããã¨ã³ã¸ãã¢ã«èãã¦ã¿ãã¨ã ãããã¯åæ©ä¸ã®åæ©ãXSSã³ã¼ãæ¸ããæ¹ã10åãæãã£ã¦ãªããããããäºåã«å¯¾çãã¦ãªãã£ãäºåinã«ã¯ãã£ã¨ããã¯ãªã ãã©ãããç´ äººãªã®ï¼ã ã¨èªãã äºåinã»ãã¥ãªãã£èå¼±æ§ãçã£ãã³ã¼ã!?ããäºåinéçºè ã¯ç´ 人ã http://news.livedoor.com/article/detail/3759632/ ããã£ã¦ã©ãã ãããã GoogleãAmazo
ååã¯ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ã®ããå¼±æ§ãçªãæ»æã®å¯¾çã¨ãã¦ã®HTMLã¨ã³ã³ã¼ãã®æå¹æ§ãè¿°ã¹ãããã ï¼HTMLã¨ã³ã³ã¼ãã ãã§ã¯ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°æ»æãå®å ¨ã«é²å¾¡ãããã¨ã¯ã§ããªããããã§ä»åã¯ï¼HTMLã¨ã³ã³ã¼ãã§å¯¾å¦ã§ããªãã¿ã¤ãã®ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°æ»æã®æå£ã¨ï¼ãã®å¯¾çã«ã¤ãã¦è§£èª¬ããã HTMLã¨ã³ã³ã¼ãã§å¯¾å¦ã§ããªãæ»æã«ã¯ï¼æ¬¡ã®ãããªãã®ãããã ã¿ã°æåã®å ¥åã許容ãã¦ããå ´åï¼Webã¡ã¼ã«ï¼ããã°ãªã©ï¼ CSSï¼ã«ã¹ã±ã¼ãã£ã³ã°ã»ã¹ã¿ã¤ã«ã·ã¼ãï¼ã®å ¥åã許容ãã¦ããå ´åï¼ããã°ãªã©ï¼ æåã³ã¼ããæ示ãã¦ããªãã±ã¼ã¹ã§UTF-7æåã³ã¼ãã«ããã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã° <SCRIPT>ã®å 容ãåçã«çæãã¦ããå ´å Aã¿ã°ãªã©ã®URLãåçã«çæãã¦ããå ´åæ³¨ï¼ ä»¥ä¸ã§ã¯ï¼HTMLã¿ã°ãCSSã®å ¥åã許容ãã¦ããå ´åã¨ï¼æåã³ã¼ããæ
ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ã¨ããè¨èã¯å ã ï¼Webã¢ããªã±ã¼ã·ã§ã³ã®HTMLã¨ã³ã³ã¼ãæ¼ããªã©ãå©ç¨ãããã¨ã«ãã£ã¦ç¬¬ä¸è ã«JavaScriptãå®è¡ãããææ³ãæããåºç¾©ã§ã¯ï¼HTMLã®ã¨ã³ã³ã¼ãã«ããç»é¢æ¹å¤ãªã©ãå«ããã¨ãããã ååè¿°ã¹ãããã«ï¼ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ã®ããå¼±æ§ã¯Webã¢ããªã±ã¼ã·ã§ã³ã«è¦ä»ããããå¼±æ§ã®åå以ä¸ãå ãããæ°å¹´åããææããã¦ããã«ããããããï¼ä¸åã«ãªããªããªãããã®çç±ã¨ãã¦ï¼ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°å¯¾çãããã¯HTMLã¨ã³ã³ã¼ã注1ï¼ã«å¯¾ãããç¥è©±ããããï¼æ£ãã対çã®æ®åãé ããã¦ããããã«æãããã®ãç¥è©±ãã®æ°ã ã«ã¤ãã¦èª¬æãããã 注1ï¼å®ä½åç §ï¼entity referenceï¼ã¨ããã®ãæ£å¼ã ãï¼ãã¾ãæ®åãã¦ããªãç¨èªãªã®ã§ï¼HTMLã¨ã³ã³ã¼ãã¨ããç¨èªãç¨ãã ããã¹ãããHTMLã¨ã³ã³ã¼ããã¹ãããéå HTM
ï¼ï¼æ¦è¦ ãä»è¬ã次ã®2.a)ã®IPAã»ããã¼åä»ãã©ã¼ã ã«ããã¦ãã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°(注)ã®ããå¼±æ§ãçºè¦ããã¾ããããã®ããå¼±æ§ãæªç¨ãããå ´åãå½è©²ãã©ã¼ã ã«ã¦ç³ãè¾¼ã¿ããããã¨ããæ¹ã®ãã©ã¦ã¶ä¸ã§ä¸æ£ãªã¹ã¯ãªãããå®è¡ããã¦ãã¾ãå¯è½æ§ãããã¾ãããå½è©²èå¼±æ§ã確èªããæã«ã¯ãå½è©²ã»ããã¼ã¯ãåéå®å¡ï¼ï¼ï¼åï¼ãè¶ ãããç³ãè¾¼ã¿ã¨ãªã£ã¦ãã¾ãããåéãç· ãåããã¦ããã ãã¨ã¨ãã«ãè³æ¥ååä»ãã©ã¼ã ãç¹æ¤ããåçºé²æ¢çãè¬ãããããï¼æï¼ï¼æ¥ååï¼ï¼æã«ååä»ãã©ã¼ã ã®ãã¼ã¸ãéãããã¦ããã ãã¾ããã ãä½µãã¦ãå½è©²èå¼±æ§ãçºè¦ãããåä»ãã©ã¼ã ã®ããã°ã©ã ãå ±æããä»ã®åä»ãã©ã¼ã ã®ãã¼ã¸ã«ã¤ãã¦ããç¹æ¤ã®ãããã¼ã¸ãéãããã¦ããã ãã¾ãããç¹æ¤ã®çµæããã®åä»ãã©ã¼ã ã«ããã¦ãã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ã®èå¼±æ§ã確èªããã¾ããã®ã§ãæ¹ä¿®ããä¸ãèå¼±æ§æ¤æ»ãè¡
æè¿Webã¢ããªã±ã¼ã·ã§ã³ã«åå¨ããã»ãã¥ãªãã£ãã¼ã«ã注ç®ãæµ´ã³ã¦ããããã®ä¸ã§ããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ãã¨å¼ã°ããèå¼±æ§ãæåã§ããããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°èå¼±æ§ã«ã¤ãã¦æ£ç¢ºã«ç解ãã¦ãã人ãä¾ç¶ã¨ãã¦å°ãªãã¨æããã æ¬ç¨¿ã§ã¯ãã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã¨ã¯ã©ã®ãããªèå¼±æ§ã§ããã®ãããã®èå¼±æ§ãæã£ããµã¤ããæ»æãããã¨ã©ã®ãããªè¢«å®³ãèµ·ãå¾ãã®ãããªããã®ãããªã»ãã¥ãªãã£ãã¼ã«ãä½ãè¾¼ã¾ãã¦ãã¾ãã®ããã©ã®ããã«å¯¾çãããã°ããã®ãã解説ãã¦ããã â»ä»¥ä¸æ¬æä¸ã§ã¯ãã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°èå¼±æ§ã®ãã¨ããXSSãã¨è¡¨è¨ããããCross Site Scriptingãã®ç¥ã§ãããããCSSãã¨è¡¨è¨ãã¦ããè¨äºããããããCascading Style Sheetsãã®ç¥ããCSSãã¨ãªãç´ããããããããXSSãã¨è¡¨è¨ããå ´åãå¤ããªã£ã¦ãã¦ãããæ¬ç¨¿ã§
ã°ã©ãã®æ¯è¼ãã§ããªãä¸å ·åä¿®æ£ ã°ã©ãã®æ¯è¼æ©è½ããå©ç¨ããã ããªãä¸å ·åãçºçãã¦ãããä¿®æ£è´ãã¾ããããè¿·æãããããç³ã訳ãããã¾ããã§ããã idea:11428ã«ã¦ãææããã ããããã¨ããããã¾ããã XSS èå¼±æ§ã®ä¿®æ£ã«ã¤ã㦠ä¸é¨ã®ãµã¼ãã¹ã®ç¹å®ã®ãã¼ã¸ã§ XSSèå¼±æ§ãã¿ã¤ããã¾ããã®ã§ãä¿®æ£ãè¡ãã¾ããã ã¯ã¦ãªæ¤ç´¢ã¯ã¦ãªãããã¯ã¦ãªããã¯ãã¼ã¯ã¯ã¦ãªRSS人åæ¤ç´¢ã¯ã¦ãªã¯ã¦ãªãã¤ã¢ãªã¼ ã該å½ãµã¼ãã¹ã«ãªãã¾ãããè¿·æãããããã¾ãããã¾ãããææããã ããããã¨ããããã¾ããã ãã¤ã¼ããã
ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼ ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã®æéã§ãï¼ XSSã¨ããã¨â¦ï¼ ã¾ã£ããã«æãã¤ãã®ããå ¥åãã¼ã¿éä¿¡ â 確èªè¡¨ç¤ºã®é¨åã§ã®ç¡å®³åæ¼ãã§ãããï¼ ãã¨ãã°ãããªæãã®ãã©ã¼ã ããåãåã£ããã©ã¡ã¼ã¿ãã 確èªã¨ãã¦è¡¨ç¤ºãããã¼ã¸ã¨ãï¼ (å ¥å) <form action="register.cgi" method="post"> ã¿ã¤ãã«ï¼<input type="text" name="title"> â ãã¼ãã¯ã¾ã¡ã¡ããï¼ããå ¥å æ¬æï¼<input type="text" name="body"> â ãããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼<script>alert(1)</script>ããå ¥å </form> (確èª) <p>ãã®å 容ã§ç»é²ãã¦ããï¼</p> <p> ã¿ã¤ãã«ï¼ ã¼ãã¯ã¾ã¡ã¡ããï¼<br> æ¬æï¼ ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼<script>alert
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}