å æ¥ããªããªãå¼·çãªXSSæ»æææ³ãå ¬éããã¦ãã¾ããã DNSã¸ã®åãåããçµæã«JavaScriptãåãè¾¼ãã§ãã¾ããã¨ãããã®ã§ãã SkullSecurity: Stuffing Javascript into DNS names DarkReading: Researcher Details New Class Of Cross-Site Scripting Attack nCircle: Meta-Information Cross Site Scripting (PDF) èªåçæãããWebãã¼ã¸ä¸ã«ãDNSã«ããåå解決çµæãã¨ã¹ã±ã¼ããããªãç¶æ ã§å«ã¾ãã¦ããã¨ãJavaScriptãå®è¡ããã¦ãã¾ãã¨ããä»æãã§ãã ãhogehoge.example.comããæ¬æ¥ãªãã°ã198.1.100.3ãã¨ãããããªIPã¢ãã¬ã¹ãçµæã¨ãã¦è¿ãã¨ããããDNSã«ç´°å·¥ãè¡ã£
{{#tags}}- {{label}}
{{/tags}}