2024/10/5 YAPC::Hakodate 2024
2024/10/5 YAPC::Hakodate 2024
Security.Tokyo #3ã®çºè¡¨è³æã§ãã ã¯ã©ã¤ã¢ã³ããµã¤ãã®ãã¹ãã©ãã¼ãµã«ã¨ãpostMessageçµç±ã®èå¼±æ§ãåãä¸ãã¾ããã
ãã»ãã¥ãªãã£ãã¼ã ããã°ãªã¬ã¼2åç®ã ããã«ã¡ã¯ãã¨ã³ã¸ãã¢ãªã³ã°ã°ã«ã¼ãã®å±±æ¬ã§ãã ã»ãã¥ãªãã£ãã¼ã ã¯ãã¨ã³ã¸ãã¢ãªã³ã°ã°ã«ã¼ãå ¨ä½ã®ã»ãã¥ãªãã£ãåä¸ãããããã®ãã¼ãã£ã«ãã¼ã ãªã®ã§ãããåãããã¯ãéçºãã¼ã ã®ãµã¼ãã¹ããã§ãã¯ãã¦ãååããªããå ¨ä½ã®ã»ãã¥ãªãã£ãåä¸ããã¦ããã®ãããã·ã§ã³ã§ãã ãã®ãä»äºã®ä¸ç°ã¨ãã¦ããã®é¨åãã»ãã¥ãªãã£ãããã足ããªãããå ¥ãã¦ãã ããï¼ãã¨ããããã¨ããæ¥å¸¸çã«è¡ãªã£ã¦ãã¾ãã ä»æ¥ã¯ãã®ãã»ãã¥ãªãã£ããããã¨ãããã®ãä¸ä½ä½ãªã®ããä»ãã人ã«èããªãã¢ã¬ã³ã¬ãåãã¾ã¨ãã¦ã¿ããã¨æãã¾ãã ã»ãã¥ãªãã£ãããè¦å¯ã®æ¥å¸¸ã®å³(ãã¡ããåè«ã§ã) ã»ãã¥ãªãã£ããã ããããã»ãã¥ãªãã£ãããã¨ã¯ï¼ æ¯è¼çå®å ¨ãªã»ãã¥ãªãã£ããã X-Content-Type-Options X-XSS-Protection Strict-Tr
23æ°åæè¡ç ä¿®ã§å®æ½ããã»ãã¥ãªãã£ç ä¿®ã®è¬ç¾©è³æã§ãã è³æã®å©ç¨ã«ã¤ãã¦ å ¬éãã¦ããè³æã¯åå¼·ä¼ãä¼æ¥ã®ç ä¿®ãªã©ã§èªç±ã«ãå©ç¨é ãã¦å¤§ä¸å¤«ã§ããã以ä¸ã®å½¢ã§ã®å©ç¨ã ããé æ ®ãã ããã ã»åè¬è ããåå è²»ãææ¥æãªã©ãéããå½¢ã§ã®å©ç¨ï¼ä¼å ´è²»ã飲é£è²»ãªã©â¦
CSP Evaluator allows developers and security experts to check if a Content Security Policy (CSP) serves as a strong mitigation against cross-site scripting attacks. It assists with the process of reviewing CSP policies, which is usually a manual task, and helps identify subtle CSP bypasses which undermine the value of a policy. CSP Evaluator checks are based on a large-scale study and are aimed to
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}