ECMAScriptã®ä»æ§ã§ã¯ã0x0A/0x0D以å¤ã«U+2028/2029ã®æåãæ¹è¡ã¨ãããã¨ãæè¨ããã¦ãã¾ãã ããã¯ãã¾ãç¥ããã¦ããªãããã«æãã¾ãã 以ä¸ã¯ã¢ã©ã¼ããåºãã¾ãã <script> //[U+2028]alert(1) </script> ç¥ããã¦ããªãã ãã§ãªããç¥ã£ã¦ããã¨ãã¦ããã¹ã¯ãªããã§æååãå¦çããã¨ãã«ãU+2028/2029ã¾ã§èæ ®ããéçºè ãã©ãã ãããã®ãã¨ãã話ã§ãã å®éãU+2028/2029ãæ¾ãè¾¼ãã¨æååãªãã©ã«å ã«ãã®æåãçã®ã¾ã¾é ç½®ãããã¨ã©ã¼ãåºããã¼ã¸ã¯æ¬å½ã«ããããããã¾ããã¾ããã¨ã©ã¼ãã§ãã ããªãã大æµã®å ´å大ããªåé¡ã«ã¯ãªãã¾ããã ã¨ããããU+2028/2029ã«ãã£ã¦XSSãå¼ãèµ·ãããã¦ãã¾ãå ´åã¨ããã®ãæè¿å®éã«è¦ã¾ããã Googleã®ãµã¼ãã¹ã§è¦ã¤ãã2ã¤ã®ã±ã¼ã¹ãåãä¸ãããã¨æãã¾ãã ã±
ã¯ã¦ãªãã¤ã¢ãªã¼ãããã°ã®XSS対çã®äºä¾ãç´¹ä»ãã¾ã
ã¯ã¦ãªã°ã«ã¼ãã®çµäºæ¥ã2020å¹´1æ31æ¥(é)ã«æ±ºå®ãã¾ãã 以ä¸ã®ã¨ã³ããªã®éããä»å¹´æ«ãç®å¦ã«ã¯ã¦ãªã°ã«ã¼ããçµäºäºå®ã§ããæ¨ããç¥ãããã¦ããã¾ããã 2019å¹´æ«ãç®å¦ã«ãã¯ã¦ãªã°ã«ã¼ãã®æä¾ãçµäºããäºå®ã§ã - ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãã®ãã³ãæ£å¼ã«çµäºæ¥ã決å®ãããã¾ããã®ã§ã以ä¸ã®éãã確èªãã ããã çµäºæ¥: 2020å¹´1æ31æ¥(é) ã¨ã¯ã¹ãã¼ãå¸æç³è«æé:2020å¹´1æ31æ¥(é) çµäºæ¥ä»¥éã¯ãã¯ã¦ãªã°ã«ã¼ãã®é²è¦§ããã³æ稿ã¯è¡ãã¾ãããæ¥è¨ã®ã¨ã¯ã¹ãã¼ããå¿ è¦ãªæ¹ã¯ä»¥ä¸ã®è¨äºã«ãããã£ã¦æç¶ãããã¦ãã ããã ã¯ã¦ãªã°ã«ã¼ãã«æ稿ãããæ¥è¨ãã¼ã¿ã®ã¨ã¯ã¹ãã¼ãã«ã¤ã㦠- ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãå©ç¨ã®ã¿ãªãã¾ã«ã¯ãè¿·æãããããããã¾ãããã©ãããããããé¡ããããã¾ãã 2020-06-25 è¿½è¨ ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ã®ã¨ã¯ã¹ãã¼ããã¼ã¿ã¯2020å¹´2æ28
ã¯ã¦ãªããã°ã®ãã«ãã§ã
ã¯ã¦ãªã°ã«ã¼ãã®çµäºæ¥ã2020å¹´1æ31æ¥(é)ã«æ±ºå®ãã¾ãã 以ä¸ã®ã¨ã³ããªã®éããä»å¹´æ«ãç®å¦ã«ã¯ã¦ãªã°ã«ã¼ããçµäºäºå®ã§ããæ¨ããç¥ãããã¦ããã¾ããã 2019å¹´æ«ãç®å¦ã«ãã¯ã¦ãªã°ã«ã¼ãã®æä¾ãçµäºããäºå®ã§ã - ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãã®ãã³ãæ£å¼ã«çµäºæ¥ã決å®ãããã¾ããã®ã§ã以ä¸ã®éãã確èªãã ããã çµäºæ¥: 2020å¹´1æ31æ¥(é) ã¨ã¯ã¹ãã¼ãå¸æç³è«æé:2020å¹´1æ31æ¥(é) çµäºæ¥ä»¥éã¯ãã¯ã¦ãªã°ã«ã¼ãã®é²è¦§ããã³æ稿ã¯è¡ãã¾ãããæ¥è¨ã®ã¨ã¯ã¹ãã¼ããå¿ è¦ãªæ¹ã¯ä»¥ä¸ã®è¨äºã«ãããã£ã¦æç¶ãããã¦ãã ããã ã¯ã¦ãªã°ã«ã¼ãã«æ稿ãããæ¥è¨ãã¼ã¿ã®ã¨ã¯ã¹ãã¼ãã«ã¤ã㦠- ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãå©ç¨ã®ã¿ãªãã¾ã«ã¯ãè¿·æãããããããã¾ãããã©ãããããããé¡ããããã¾ãã 2020-06-25 è¿½è¨ ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ã®ã¨ã¯ã¹ãã¼ããã¼ã¿ã¯2020å¹´2æ28
æè¿ã徳丸æ¬ãããããèªãã§ããã®ã§ãããDOM based XSSã®è©±ãæ¸ãã¦ãã£ãã®ã§ãå°ãè¨åãã¦ãããã¨æãã¾ãã 徳丸æ¬ããå¼ç¨ DOM based XSSã¨å¼ã°ããXSSãããã¾ããããã¯ãJavaScriptã«ããã¯ã©ã¤ã¢ã³ãå´ã§è¡¨ç¤ºå¦çããç®æããããããã«èå¼±æ§ãããå ´åã®XSSã§ãã ãµã³ãã«æ¸ãã¦ã¿ã¾ããã <script> document.write(unescape(location.href)); </script> ããã¤ãé©å½ãªãã¡ã¤ã«åã§ä¿åãã¦ãdomxss.html#<script>alert("hello")<script>ãªã©ã®URLã§ã¢ã¯ã»ã¹ããã¨alertã表示ãããã¯ãã§ããä»»æã®ã¹ã¯ãªãããå®è¡å¯è½ãªç¶æ ã£ã¦ãã¨ã§ãããä»»æã®ã¹ã¯ãªãããå®è¡å¯è½ã£ã¦ãã¨ã¯ãã»ãã·ã§ã³ã¯ããã¼çã¿æ¾é¡ã§ãä»äººã«æãæ¸ã¾ãã¦è²·ãç©ã§ãã¡ãã£ããããã¬ãã«ã§ã
Evernoteã«ä»»æã®HTMLãæ³¨å ¥ã§ããèå¼±æ§ãããã¾ããã http://togetter.com/li/125281 Evernoteã®ã»ãã¥ãªãã£ããªã·ã¼ã¨ãã«ã¯è§¦ãããã¨ããããä½ãå¯è½ã ã£ãã®ããã©ãããç¶æ³ã ã£ãã®ããæ¸ãã¾ãã 4/18 16æãã Evernoteã®ç»é²ãã¼ã¸ã®HTMLã«ä»¥ä¸ã®ãããªè¨è¿°ãããã¾ãã <script type="text/javascript"> $(document).ready(function() { suggestedTags = []; suggestedNotebook = ""; sourceUrl = ""; providerName = ""; payload = { "user" : { ... }, ..å¾ç¥.. </script> ãã®sourceUrl = ""ã®é¨åãhttps://www.evernote.c
ã¯ã¦ãªã°ã«ã¼ãã®çµäºæ¥ã2020å¹´1æ31æ¥(é)ã«æ±ºå®ãã¾ãã 以ä¸ã®ã¨ã³ããªã®éããä»å¹´æ«ãç®å¦ã«ã¯ã¦ãªã°ã«ã¼ããçµäºäºå®ã§ããæ¨ããç¥ãããã¦ããã¾ããã 2019å¹´æ«ãç®å¦ã«ãã¯ã¦ãªã°ã«ã¼ãã®æä¾ãçµäºããäºå®ã§ã - ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãã®ãã³ãæ£å¼ã«çµäºæ¥ã決å®ãããã¾ããã®ã§ã以ä¸ã®éãã確èªãã ããã çµäºæ¥: 2020å¹´1æ31æ¥(é) ã¨ã¯ã¹ãã¼ãå¸æç³è«æé:2020å¹´1æ31æ¥(é) çµäºæ¥ä»¥éã¯ãã¯ã¦ãªã°ã«ã¼ãã®é²è¦§ããã³æ稿ã¯è¡ãã¾ãããæ¥è¨ã®ã¨ã¯ã¹ãã¼ããå¿ è¦ãªæ¹ã¯ä»¥ä¸ã®è¨äºã«ãããã£ã¦æç¶ãããã¦ãã ããã ã¯ã¦ãªã°ã«ã¼ãã«æ稿ãããæ¥è¨ãã¼ã¿ã®ã¨ã¯ã¹ãã¼ãã«ã¤ã㦠- ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ ãå©ç¨ã®ã¿ãªãã¾ã«ã¯ãè¿·æãããããããã¾ãããã©ãããããããé¡ããããã¾ãã 2020-06-25 è¿½è¨ ã¯ã¦ãªã°ã«ã¼ãæ¥è¨ã®ã¨ã¯ã¹ãã¼ããã¼ã¿ã¯2020å¹´2æ28
çºè¡¨è³æã¯ä»¥ä¸ã®ã¨ãããæ¥å±±æ§ã¯ããECããã®çæ§ããããã¨ããããã¾ããã XSSã«å¼·ãã¦ã§ããµã¤ããä½ã â ãã³ãã¬ã¼ãã¨ã³ã¸ã³ã®é¸å®åºæºã¨ã¹ããããã®çæææ³View more presentations from kazuho.
æ¨æ¥ã¯ãShibuya Perl Mongersãã¯ãã«ã«ãã¼ã¯#14 ã«åå ãã¦ãã¾ããã ããã©ã¼ã¨ãã¦ã¦ã§ããµã¤ãã®ã»ãã¥ãªãã£ã«é¢ãããã£ã¹ã«ãã·ã§ã³ã«å ãã¦ããã ãã¦ãããããä¸ããç®ç·ã§å¤§å±çãªè©±ãããããä¸æ¹ãã©ã¤ããã³ã°ãã¼ã¯ã§ã¯å ·ä½çãªäºä¾ã¨ãã¦ãæ¢ã«ããã°ã«æ¸ãã Twitter ã® XSS ã«çµ¡ãã§æ§é åããã¹ãã®å¦çææ³ã«ã¤ãã¦è©±ãããã¦ããã ãã¾ãã (åç §: æ§é åããã¹ãã®æ£ããã¨ã¹ã±ã¼ãææ³ã«ã¤ãã¦, String::Filter ã£ã¦ããã¢ã¸ã¥ã¼ã«æ¸ãã)ã ã¨ã¯ãããæ¢ã«ããã°ã«æ¸ãããã¨ãç¹°ãè¿ãã®ãè¸ããªãã®ã§ãæ£ããè¨è¨ãä½ããã¨ããåãå£ã§ã¯ãªããã©ãããè¨è¨ãããã°ãå®å ¨ãããã¨ãã話ã«ãªã£ã¦ãã¾ããã¹ã©ã¤ãã¯ä»¥ä¸ã«ããã¾ãã®ã§ãèå³ã®ããæ¹ã¯ã覧ãã ããã
è£è¶³ ãã®è¨äºã¯æ§å¾³ä¸¸æµ©ã®æ¥è¨ããã®è»¢è¼ã§ãï¼å URLãã¢ã¼ã«ã¤ããã¯ã¦ãªããã¯ãã¼ã¯1ãã¯ã¦ãªããã¯ãã¼ã¯2ï¼ã åå¿ã®ãã転è¼ãããã¾ããããã®è¨äºã¯2010å¹´9æ27æ¥ã«å ¬éããããã®ã§ãå½æã®å¾³ä¸¸ã®èãã示ããã®ããåºæ¬çã«å 容ãå¤æ´ããã«ãã®ã¾ã¾è»¢è¼ãããã®ã§ãã è£è¶³çµãã PHPã«ã³ãã¡ã¬ã³ã¹2010ã«ã¦ãæåã³ã¼ãã«èµ·å ããèå¼±æ§ã¨ãã®å¯¾çãã¨ããã¿ã¤ãã«ã§åããã¦ããã ãã¾ããããã¬ã¼ã³ãã¼ã·ã§ã³è³æãPDFå½¢å¼ã¨slideshare.netã§å ¬éãã¦ãã¾ãã æåã³ã¼ãã®ã»ãã¥ãªãã£ã¨ããã¨ããããããã¤ã¡ã¼ã¸ãå¼·ãã¦ãã¹ãã¼ã«ã¼ã®åå¤ç¥ã§ããè´è¡ã®ååã¯ç½®ãã¦ãã¼ãã«ãªãããããã¿ãããªè©±ããã¦ããã®ã§ãããæå¤ã«ããåãããããã£ããçã®å¥½æçãªåå¿ãtwitterçã§ããã ããé©ãã¨å ±ã«åãã§ãã¾ããåæã«PHPã«ã³ãã¡ã¬ã³ã¹ã«æ¥ããããããªæ¹ã¯æèãé«ãã¨ããã®
å ã®ã¨ã³ããªã(Twitter ã® XSS èå¼±æ§ã«é¢é£ãã¦) æ§é åããã¹ãã®æ£ããã¨ã¹ã±ã¼ãææ³ã«ã¤ãã¦ãã®ç¶ãã å¼¾ãããã404 Blog Not Found:DHTML - æ§é åããã¹ãã¯æ§é åããã®ããã£ã±æ£ãããã§ç¤ºããã¦ãããã㪠DOM ãã¼ã¹ã®æä½ãè¡ãã°ãåççã« XSS èå¼±æ§ãé²ããã¨ãã§ãã¾ãããã ãã¯ã©ã¤ã¢ã³ããµã¤ã JavaScript ã«ããã¬ã³ããªã³ã°ã¯ã¦ã§ãã®æ§é ãç ´å£ããã¨ããç¹ã§çãæªãï¼ãã¼ãã«ã¨ FONT ã¿ã°ãå©ç¨ãããã¼ã¸ã¬ã¤ã¢ã¦ããæ¹å¤ããã¦ããé ãè¦ãã¦ããã£ãããã¾ãã§ãããããJavaScript ã«ããã¬ã³ããªã³ã°ã¯ã¦ã§ãã®ãªã³ã¯æ§é ãç ´å£ããã®ã§ä¸å±¤ãã¡ãæªãã¨ããã®ãèªåã®èãï¼ã§ããããµã¼ããµã¤ãã§ã® DOM æä½ã¯éããã®ã§ãã§ããã°é¿ãããã¨ããã§ãã æ§é åããã¹ãã® HTML ã¸ã®å¤æã¯ããã»ã©è¤éãªè¨æ³ã§ãªãéã
æ¨æ¥ã® Twitter ã® XSS é¨ãã¯ãã¾ã çããã®è¨æ¶ã«æ°ãããã¨ã¨æãã¾ããããæ©ä¼ãªã®ã§ããã¤ã¼ãã®ãããªæ§é åããã¹ãã®ã¨ã¹ã±ã¼ãææ³ã«ã¤ãã¦è§¦ãã¦ããããã¨æãã¾ãã Twitter ã®ã¡ãã»ã¼ã¸ã¯ãåãªãå¹³æï¼ãã¬ã¤ã³ããã¹ãï¼ã§ã¯ãªããã@è±æ°åãã®ãããªä»ã®ã¦ã¼ã¶ã¼ã¸ã®è¨åã¨ãhttp://ããã®ãã㪠URL ãèªåçã«ãã¤ãã¼ãªã³ã¯åããæ§é åããã¹ãã§ãã ãã®ãããªè¤æ°ã®ã«ã¼ã«ããã¤æ§é åããã¹ãã HTML åããéã«ã¯ãã©ã®ãããªã³ã¼ããæ¸ãã°ããã®ã§ãããï¼ãã¾ãã@ããããªã³ã¯åãã¦ãããURL ããªã³ã¯åããã°ããã®ã§ããããï¼ãããã ã¨ã@ã ã®ããªã³ã¯åãã A HREF ã¿ã°ã®ä¸ã® URL ãããã«ãªã³ã¯åããã¦ãã¾ãã¾ããã ã§ã¯ãURL ããªã³ã¯åãã¦ãã @ã ããªã³ã¯åããã°ããã®ã§ããããï¼ãããã ã¨ã@ ãå«ã URL ããã£ãå ´åã«
é£ãããã¦è§£ããªããï¼ã¨ä¸æºå´åºã ã£ãåé¡ãæ¥å¹´ããã¨ãããããã£ããå¤æ´ããã®ã§å ¬éãã¡ãããã http://utf-8.jp/cgi-bin/xss1/search.cgi http://utf-8.jp/cgi-bin/xss2/search.cgi http://utf-8.jp/cgi-bin/xss3/search.cgi (追è¨) åçä¾ããã£ã³ãåè¬çã® @tyage ãããæ¸ãã¦ããã¦ãã¾ããGJ! XSSã¡ã¢æ¸ã | ãã£ã²ã£ã¦ãæ¥ã
NTTãã³ã¢ã¨ã½ãããã³ã¯ã¢ãã¤ã«ã¯ããã£ã¼ãã£ã¼ãã©ã³ï¼ããããã¬ã©ã±ã¼ï¼ã«ã¦JavaScriptã®å¯¾å¿ãå§ãã¦ãã¾ããJavaScriptã«å¯¾å¿ããã¨ãã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°(XSS)èå¼±æ§ã®æ¸å¿µãé«ã¾ãã¾ããã両社ã¯ç¬èªã®ææ³ã«ããXSS対çããã¦ããï¼ãããã¨ãã¦ããï¼æåã観測ããã¾ããã®ã§å ±åãã¾ãããã®å 容ã¯ããªã¬æ¨æºJavaScriptåå¼·ä¼ã§ãã¿ã¨ãã¦ä½¿ã£ããã®ã§ãã NTTãã³ã¢ã«å¦ã¶ãXSS対çãã¾ãããµã³ãã«ã¨ãã¦ä»¥ä¸ã®ãããªXSSèå¼±ãªã¹ã¯ãªãããç¨æãã¾ãã <?php session_start(); ?> <body> ããã«ã¡ã¯<?php echo $_GET['p']; ?>ãã </body>ããã以ä¸ã®URLã§èµ·åããã¨ãIE7ã§ã¯ä¸å³ã®ãããªè¡¨ç¤ºã«ãªãã¾ãã []http://example.com/xss01.php?p=å±±ç°<scrip
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}