ãã®ã·ãªã¼ãºã§ã¯ãAccessãSQL Serverã®ãã¼ã¿ãã¼ã¹ãã¡ã¤ã«ããPHPã使ã£ãWebãã¼ã¸ã§å¦çããæ¹æ³ã«ã¤ãã¦èª¬æãã¾ããPHPã使ã£ã¦ãã¼ãã«ã®ãã¼ã¿ã表示ãããç·¨éãããããããã®ãåºæ¬çãªã¹ã¯ãªãããç´¹ä»ãã¾ãã AccessãSQL Serverã®ãã¼ã¿ãã¼ã¹æä½åºæã®PHPã¹ã¯ãªããã«ã¤ãã¦ã®ã¿ç´¹ä»ãã¾ããPHPã®ä¸è¬çãªææ³ãé¢æ°ãªã©ã«ã¤ãã¦ã¯è§¦ãã¾ããã®ã§ããããã«é¢ãã¦ã¯é¢é£æ¸ç±çãåèã«ãã¦ãã ããã æ¬ã·ãªã¼ãºã¯ãWindows XPãIISãPHP5.0ãAccess2003ãSQL Serever2003ãåä½ç°å¢ã¨ãã¦ãã¾ãã
ã¨ãããã㧠ããã°ã©ãã³ã°æªçµé¨ã®ç¶æ ãããmixiã¢ããªã®ãªãªã¼ã¹ã¾ã§ãªãã¨ãæ¼ãçãããã¨ãã§ãã¾ããï¼æè¿ãOpenSocialçéã¯çãä¸ãã£ã¦ãã¿ããã ããããã°ã©ãã³ã°çµé¨ã¯ãªãããã©ãèå³ããï¼ã£ã¦äººãå¤ãã¨æãã¾ããããã§ãæè¬ããç´ äººãã®ç¶æ ããããã°ã©ãã³ã°ãåå¼·ãã¦mixiã¢ããªããªãªã¼ã¹ããã«è³ãã¾ã§ã®åã®è»è·¡ã¨ãä½ãã©ãåå¼·ããã°ããã®ãï¼ã£ã¦ã®ãã¾ã¨ãã¦ã¿ã¾ãããwebã§èª¿ã¹ãããããã°ã©ãã®ç¥äººã«ç¸è«ããããã¦ããã¯è¯ãã£ãï¼ã£ã¦é¨åãæãåºãã¦ã¾ã¨ããã®ã§ãããããåå¼·ãããã£ã¦æ¹ã¯åèã«ãã¦é ããã°å¹¸ãã§ããããã§ããªããSAPï¼ã½ã¼ã·ã£ã«ã»ã¢ããªã»ãããã¤ãã¼ï¼ã«ï¼ å®æããã¢ã㪠ãä¸è¡ãªã¬ã¼å°èª¬ã http://mixi.jp/view_appli.pl?id=15525 éçºæéï¼å®è³ª3ã¶æç¨åº¦ ãªãªã¼ã¹æ¥ï¼3æ24æ¥ ç¾å¨ã®æ稿ç·æ°:7622è¡
Re:PHPã§èª°ã§ãç°¡åWebãµã¼ãã¹è£½ä½ï¼ã§ãªããä½ã£ã¦å ¬éãã奴ã¡ãã£ã¨æ¥ã ãã¿å ï¼PHPã§èª°ã§ãç°¡åWebãµã¼ãã¹è£½ä½ï¼ã§ãªããä½ã£ã¦å ¬éãã奴ã¡ãã£ã¨æ¥ã PHPã®XSSã¨SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã®è§£èª¬ãæ¸ããã¦ãã¾ããä¸å¯§ã«æ¸ããã¦ãã¾ãã®ã§ãã²ä¸èªãã ããããã ãèªãä¸ã§1ç¹æ³¨æãããã¨ãããã¾ãã XSSã¯ããã»ã©åç´ãããªãï¼ ãã¿ãã¨ã®XSS対çæ¸ã¿ã®ã½ã¼ã¹ã³ã¼ãã®ï¼è¡ç®ã§æ¬¡ã®ãããªã³ã¼ããããã¾ãã <form action="<?=$_SERVER['PHP_SELF']?>" method="get"> å®ã¯ããã«ãXSSã®èå¼±æ§ãå«ã¾ãã¦ãã¾ãã次ã®ãããªURLã§ã¢ã¯ã»ã¹ãããå ´åãä»»æã®ã¹ã¯ãªãããå®è¡ãããã¨ãåºæ¥ã¾ãã http://www.example.jp/ example.php/%22%3E%3Cscript%3Ealert(document.co
Webãµã¤ããå¶ä½ããéããã¼ãé¡ã«ä½¿ãè²ã決ããå¿ è¦ãããã¾ããè²ã®é¸æã¯ãã¦ã¼ã¶ã¼ã®å°è±¡ã大ããå·¦å³ãããããæ éã«è¡ããã¨ãéè¦ã§ããç¹ã«ãããããªã®ããããã¼ã¹ã«ã©ã¼ããã¢ã¯ã»ã³ãã«ã©ã¼ãããµãã«ã©ã¼ãã¨ãã3㤠[â¦]
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}