
ITmediaã®è¨äºãå¾®å¦ã ã£ãã®ã§èª¿ã¹ã¦è¦ãã®ãã(é¢åãªã®ã§ç®æ¡æ¸ã) å ãã¿ Ruby on Railsã«cookieä¿åé¢é£ã®èå¼±æ§ã2000ãµã¤ãã§æ¾ç½®ç¶æ (ITmedia) Ruby on Rails CookieStore Vulnerability Plagues Prominent Websites (åæ) ä½ãåé¡ã¨ããã¦ããã (è¨äºã®ä¸»å¼µ) ããã©ã«ãã§ã¯ãcookieã«ã»ãã·ã§ã³ã®ããã·ã¥ (ãã¼ã¿) ãä¿æãã¦ããã(CookieStore) Rails 2-3ã®å ´åã¯ç§å¯éµã§ç½²åããã¦ãã = æ¸ãæãä¸å¯ Rails 4ã®å ´åã¯æå·åããã¦ãã = æ¸ãæãã»å 容ã®èªã¿åãä¸å¯ Cookieãèªã¿åãããå¯è½æ§ãããã XSS ã»ãã·ã§ã³ãµã¤ãã¸ã£ããã³ã°: ãã£ããSSLã§ã¯ãªãéä¿¡ããããã¨ãRails3以åã§ã¯æ©å¯æ å ±ãæ¼æ´©ããå¯è½æ§ãããã(Ki
ä»æ¥ @mad_p ããããRTæ¥ã¦ããã®ãã¤ã¼ãã«é¢ãã¦ãã¡ãã£ã¨èª¿ã¹ãã®ã§ã¾ã¨ãã¨ãã¾ãã Security Issue in Ruby on Rails Could Expose Cookies http://t.co/JlsXVEn4rZ â Ruby on Rails News (@RubyonRailsNews) September 25, 2013 åææ¡ä»¶ Railsã§ã¯ããã©ã«ãã§sessionãcookieã«ã®ã¿ä¿åãã¦ãDBãªãmemcacheãªãã®server-side storageã«ã¯ä½ãä¿åãã¾ããã ãããCookieStoreã¨ãå¼ã°ãã¦ããã¤ã§ãã ãã®å ´åã®session cookieã¯ãRailsã®session object (Hash object) ãMarshal.dumpãã¦ããã«ç½²åãä»ããtokenã§ãã rails 4ã§ã¯ç½²åä»ãã代
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}