GMailã®ã³ã³ã¿ã¯ããªã¹ããå¤é¨ããå¼ã³åºãå¯è½ã«ãªã£ã¦ãã¾ã£ã¦ã件ã«ã¤ãã¦ã Googleå ãã©ã¤ãã¼ããªã¯ãã®ãã¼ã¿ããé¢ä¿ã®ãªãå¤é¨ã®ãµã¤ããããã¹ã¯ãªããçµç±ã§èªã¿è¾¼ã¾ãã¦ãã¾ãã¨ãããã®ã http://ajaxian.com/archives/gmail-csrf-security-flaw ã§ãããã£ã¦CSRFã£ã¦ããã®ããªï¼ãªããåé¡ãã¡ãã£ã¨éã£ã¦ããããªæ°ããããã©ãCSRFã¯æ å ±ãæãåãããã©ããã£ã¦ã¨ãã¯å¥ã«é¢ä¿ãªãã¯ãã ããå¤é¨ãµã¤ãã«ãã©ã¤ãã¼ããã¼ã¿ãçã¾ããã¨ããè å¨ã¨ãã¦ã¯CSSXSSã«è¿ããããªãï¼è¿½è¨ï¼ã©ããCSRFã®å®ç¾©ã£ã¦ã®ã¯ããã¡ãã£ã¨åºãã¿ããï¼ ãã®é¨ãã«å¼å¿ãã¦ãã¯ãã¹ãµã¤ãã®ã»ãã¥ãªãã£ã¢ãã«ã«ã¤ãã¦ã¾ã¨ãã¦ãã£ãã http://labs.cybozu.co.jp/blog/kazuho/archives/2007/01/cross
{{#tags}}- {{label}}
{{/tags}}