2024/10/5 YAPC::Hakodate 2024

2024/10/5 YAPC::Hakodate 2024
ãæ å ±ã»ãã¥ãªãã£10大è å¨ 2024ãç°¡æ説æè³æï¼ã¹ã©ã¤ãå½¢å¼ï¼ æ å ±ã»ãã¥ãªãã£10大è å¨ 2024 [çµç¹ç·¨] 104ãã¼ã¸(PDF:3.7 MB) æ å ±ã»ãã¥ãªãã£10大è å¨ 2024 [å人編] 94ãã¼ã¸(PDF:3.7 MB) æ å ±ã»ãã¥ãªãã£10大è å¨ 2024 [å人編]ï¼ä¸è¬å©ç¨è åãï¼ 72ãã¼ã¸(PDF:3.9 MB) æ å ±ã»ãã¥ãªãã£10大è å¨ 2024 [çµç¹ç·¨]ï¼è±èªçï¼ 104ãã¼ã¸(PDF:4.2 MB) ãæ å ±ã»ãã¥ãªãã£10大è å¨ 2024ãç°¡æ説æè³æï¼è å¨åå¥çï¼ æ å ±ã»ãã¥ãªãã£10大è å¨ 2024 [çµç¹ç·¨]ï¼è å¨åå¥çï¼(ZIP:6.8 MB) æ å ±ã»ãã¥ãªãã£10大è å¨ 2024 [å人編]ï¼è å¨åå¥çï¼(ZIP:6.4 MB) 10大è å¨ã®å¼ç¨ã«ã¤ã㦠è³æã«å«ã¾ãããã¼ã¿ãã°ã©ãã»å³è¡¨ã»ã¤ã©ã¹ãçããä½æãããè³æã«å¼ç¨ã»æç²ãã¦ãå©
23å¹´3ææ«ããåå¼·æéãã¬ã¤ãã©ã¤ã³é¡ã®èªã¿è¾¼ã¿ï¼ããã°å·çã«ãã¦ã¦7ã«æãçµã¡ã¾ããã ç¹ã«è¯ãåºåãã§ããªãã®ã§ããããããã§ä¸åº¦æ¯ãè¿ãããã¨æãã¾ãã ãªãã§èªã¿å§ããã®ï¼ ã©ãã ãä½ãèªãã ã®ï¼ è²ã èªãã§ã©ãã ã£ãï¼ 1. èªåã®çºè¨ã«æ ¹æ ã¨èªä¿¡ãæã¦ã 2. æªçµé¨ã®æè¡ãã¼ãã§ãåãæ±ãããããªã 3.ãã¬ã³ããããã°ãã¼ããåãã ããããã®ã¬ã¤ãã©ã¤ã³é¡ã¯ï¼ ãªãã§èªã¿å§ããã®ï¼ ä»æ´ã®èªå·±ç´¹ä»ã§ãããç§ã¯æå±çµç¹ã®ä¸ã§3 Line of Defenseã«ããã2nd Lineã«ãããã»ãã¥ãªãã£ã®æ¦ç¥ç«æ¡ãå¼·åæ½çã®æ¨é²ããããã¯æ°ããæè¡ãå©ç¨ããéã®ã«ã¼ã«ä½ãã主ã«æ ã£ã¦ãã¾ãã ããã°ã©ã éçºããµã¼ãããããã¯ã¼ã¯ãã¯ã©ã¦ããAPIãã³ã³ãããAIãæ§ã ãªæè¡ãã¼ããããä¸ã§ããã®ãã¹ã¦ã«ã»ãã¥ãªãã£ã¯å¼·ãé¢ããã¾ããããã¦ãã»ãã¥ãªãã£æ å½ã¯ãç¾å ´ããä¸è¨ã®
ãã®è¨äºã¯ãMerpay Tech Openness Month 2023 ã®4æ¥ç®ã®è¨äºã§ãã ããã«ã¡ã¯ãã¡ã«ã³ã¤ã³ã®ããã¯ã¨ã³ãã¨ã³ã¸ãã¢ã®@goroã§ãã ã¯ããã« ãã®GitHub Actionsã®ã»ãã¥ãªãã£ã¬ã¤ãã©ã¤ã³ã¯ã社å ã§Github Actionsã®å©ç¨ã«å é§ãã社å æå¿ã«ãã£ã¦æ¤è¨ããã¾ããããGitHub Actionsã使ãã«ãããã©ããã£ãç¹ã«çæããã°æä½éã®å®å ¨æ§ã確ä¿ã§ãããå¦ç¿ãã¦ãããããããå®æçã«æ¬ããã¥ã¡ã³ããè¦è¿ãã¦ãããèªåãã¡ã®ãªãã¸ããªã¼ãå®å ¨ãªç¶æ ã«ãªã£ã¦ãããç¹æ¤ããéã«å½¹ç«ã¦ã¦ããããããã¨ããæãã«åºã¥ãã¦ä½æããã¦ãã¾ãã ä»åã¯ãããªã¬ã¤ãã©ã¤ã³ã®ä¸é¨ãã社å¤ã®æ¹ã ã«ãå½¹ç«ã¤ã¨æãå ¬éãããã¨ã«ãã¾ããã ã¬ã¤ãã©ã¤ã³ã«ãããç®æ¨ ãã®ã¬ã¤ãã©ã¤ã³ã¯äºåã«2段éã®ç®æ¨ãè¨å®ãã¦ä½æããã¦ãã¾ããã¾ã第1ã«ã常ã«éæããããã¨
1.ã¯ããã« 2020å¹´4æï¼æ¨å¹´ï¼ãå½ç¤¾ãµã¼ãã¹ãClassiãã«ä¸æ£ã¢ã¯ã»ã¹ããã£ã件ã«é¢ããéå»ä¸å¹´éãå¼ç¤¾ã¯ãããéãåãæ¢ããã客æ§ã«å®å ¨ã«Classiããå©ç¨ããã ãäºãå½ç¤¾äºæ¥ã®æåªå äºé ã¨ããå種対çãå¹´éãéãå®æ½ãã¦ã¾ããã¾ããã ä»å¹´åº¦ããæ¨å¹´åº¦ããç¶ç¶ãã¦ããµã¼ãã¹ã®ã»ãã¥ãªãã£ãéè¦ããå ¨ç¤¾çãªå¯¾çãå®è¡ãã¦ããæåã§ãããã¾ãã®ã§ã以ä¸ã«çºçç´å¾ã®å¯¾å¿ãåã³ä»æ¥ã¾ã§ã«å®è¡ãããã¾ããã»ãã¥ãªãã£å¼·å対çãå«ãã¦ãä»å¾ã®åãçµã¿ã«ã¤ãã¦ãå ±åãããã¾ãã ç¾å¨ã«è³ãã¾ã§åæ§ã®ä¸æ£ã¢ã¯ã»ã¹ã¯èµ·ãã£ã¦ããããã»ãã¥ãªãã£ç¶æ³ã«ã¤ãã¦ãå¤é¨ä¼æ¥ã®ç¬¬ä¸è 調æ»ã®çµæãä»ç¤¾ã¨æ¯è¼ãã¦æ¨æºæ°´æºä»¥ä¸ã«å¼·åã§ãã¦ããã¨è©ä¾¡ããã ãã¦ããã¾ããã¾ã2021å¹´3æã®ISO/IEC27001ã«åºã¥ãæ å ±ã»ãã¥ãªãã£ããã¸ã¡ã³ãã·ã¹ãã (ISMS)ã®ç¶ç¶å¯©æ» ã«ããã¦ããããã¸ã¡ã³ãã·ã¹ã
ãã®è¨äºã¯PHP Advent Calendar 2019ã®5æ¥ç®ã®è¨äºã§ãã ã¯ããã« ç§ã¯6å¹´åã«ãPHP Advent Calendar 2013ã¨ãã¦ãPHPã ã£ã¦ã·ã§ã«çµç±ã§ãªãã³ãã³ãå¼ã³åºãæ©è½ã欲ãããã¨ããè¨äºãæ¸ãã¾ããããã®ä¸ã§ãOSã³ãã³ãã¤ã³ã¸ã§ã¯ã·ã§ã³å¯¾çã®æ ¹æ¬çãã¤å®å ¨ãªå¯¾çã¯ãã·ã§ã«ãçµç±ããªãã³ãã³ãå¼ã³åºããã§ãããã¨ãææããä¸ã§ãæ«å°¾ã«ä»¥ä¸ã®ããã«æ¸ãã¾ããã PHPã³ããã¿ã®ã¿ãªãã¾ãPHP5.6ã®æ°æ©è½ã¨ãã¦ãã·ã§ã«ãçµç±ããªãã³ãã³ãå¼ã³åºãã®æ©è½ã追å ã§ãã¾ããã? ç¾å®ã«ã¯å½æããPCNTLé¢æ°ã«ã¦ã·ã§ã«ãçµç±ããªãã³ãã³ãå¼ã³åºãã¯ã§ããã®ã§ãããå½é¢æ°ã®ä½¿ç¨ãé£ãããã¨ã¨ãCLIçãããã¯CGIçï¼FastCGIã¯å¯ï¼ã®PHPã§ãªãã¨ãµãã¼ãããã¦ããªããªã©ã®å¶éããããpopenãproc_openãªã©ä½¿ããããã³ãã³ãå¼ã³åºãé¢æ°ã«
FRONTEND CONFERENCE 2019( https://2019.kfug.jp )ã§ã»ãã¥ãªãã£ã主ã«XSSã«ã¤ãã¦è©±ããã¾ããã demo: https://shisama.dev/xss-test # Technical Topics - 3 types of XSS ( â¦
èªç©ºèªè¡éãæä¾ããã¹ã¯ãªã¼ã³ã»ã¼ãã¼ã®ã¤ã³ã¹ãã¼ã©ã«ã¯ãDLL èªã¿è¾¼ã¿ã«é¢ããèå¼±æ§ãåå¨ãã¾ãã èªç©ºèªè¡éãæä¾ããã¹ã¯ãªã¼ã³ã»ã¼ãã¼ã®æ¬¡ã®ã¤ã³ã¹ãã¼ã©ãæ¬èå¼±æ§ã®å½±é¿ãåãã¾ãã jasdf_01.exe jasdf_02.exe jasdf_03.exe jasdf_04.exe jasdf_05.exe scramble_setup.exe clock_01_setup.exe clock_02_setup.exe
ãã¤ãã®å®¶é»ã¡ã¼ã«ã¼Mieleï¼ãã¼ã¬ï¼ã®æ¥åç¨å ¨èªåé£å¨æ´ãæ©ã®Webãµã¼ãã¼æ©è½ã«ããã£ã¬ã¯ããªãã©ãã¼ãµã«ã®èå¼±æ§ãçºè¦ãããï¼RegisterãSeclist.orgï¼ã åé¡ãçºè¦ããã製åã¯Miele Professional PG 8528ã¨ãã製åã大åã®æ¥åç¨è£½åã§ããããã¯ã¼ã¯æ¥ç¶æ©è½ãé éæä½æ©è½ãæè¼ãã¦ããã èå¼±æ§ã¯æ¨å¹´11æã«çºè¦ãããMieleå´ã«åãåãããè¡ããããã®ã®ã対å¿ãè¡ããã©ããã®åå¿ããªãã£ããã3æ23æ¥ä»ãã§èå¼±æ§ãå ¬éãããããã ãããã«ãã£ã¦ããã·ã¥åããããã¹ã¯ã¼ããè¨é²ããããã¡ã¤ã«ï¼/etc/shadowï¼ãå¤é¨ããåå¾ã§ããã¨ãã£ãåé¡ãããã¨ã®ãã¨ã ãããã«é£å¨æ´ãæ©ã«ã¯æ©å¯æ å ±ã¯è¨é²ãã¦ããªãã ããããå¤é¨ããä¸ç¹å®å¤æ°ãã¢ã¯ã»ã¹ã§ãããããªç°å¢ã«ããé£å¨æ´ãæ©ãå°ãªãã¨ã¯æããããã第ä¸è ã«ãã£ã¦é£å¨æ´ãæ©ãä¹ã£åãã
Google Chrome ã§ã·ãã³ãã㯠ï¼æ§ããªãµã¤ã³ï¼ çºè¡ SSL 証ææ¸ã®æå¹æéãå¼·å¶çã«ç縮ãããããEV ï¼æ¡å¼µèªè¨¼ï¼ ãç¡å¹ã«ãªãããã¨ãã話 æ大æã®èªè¨¼å± ï¼CAï¼Certification Authorityï¼ ã§ããã·ãã³ããã¯ï¼æ§ããªãµã¤ã³ï¼ããé©åãªèªè¨¼æç¶ããè¡ããã« SSL 証ææ¸ãçºè¡ãã¦ããã¨ãããåé¡ã§ãChrome ãã¼ã ãææ¡ãã証ææ¸æå¹æéã®æ®µéçãªç縮ã EV 証ææ¸ã®ç¡å¹åã«ã¤ãã¦ã¾ã¨ãã¾ãã é±æ«ã«æ 2ch ã¾ã¨ããµã¤ãã§åãä¸ãããã¦è©±é¡ã«ãªã£ã¦ãã¾ããããGoogle Chrome ã«ããã¦ãã·ãã³ãã㯠- Symantec ï¼æ§ããªãµã¤ã³ - Verisignï¼ çºè¡ã® SSL 証ææ¸ããããã¯ãããããã¨ãã話ã ã¾ã¨ããµã¤ãã§æ¸ããã¦ãããã㪠ãåçç¡ç¨ã§ãããã¯ã ã¨ããã®ã¯ç ½ãã¿ã¤ãã«ãªã®ã§ãã¾ãçã«åããã®ã¯ããã
â ãé½ç¨ã¯ã¬ã¸ããã«ã¼ããæ¯æãµã¤ããæµåºäºä»¶ã®è²¬ä»»ã¯èª°ãã¨ãã®ã æ®å¿µãªãã¥ã¼ã¹ãå ¥ã£ã¦ããã é½ç¨ã®ãµã¤ãã«ä¸æ£ã¢ã¯ã»ã¹ ï¼ï¼ä¸ä»¶ä½ã®å人æ å ±æµåºã, NHKãã¥ã¼ã¹, 2017å¹´3æ10æ¥ ãã®ãµã¤ãã«ã¤ãã¦ã¯ãä»å¹´ã®æ£ææ©ã ã«ä»¥ä¸ã®ä»¶ã§è©±é¡ã«ãªã£ã¦ããã ãå½ç¨ã¯ã¬ã¸ããã«ã¼ããæ¯æãµã¤ããã¯èª°ãéå¶ãããµã¤ããªã®ã, togetterã¾ã¨ã, 2017å¹´1æ5æ¥ ãã®ã¨ããã¿ã¤ãã«ã«ã¯ãå½ç¨â¦â¦ãã¨ãããããå½ç¨ã¯ã¬ã¸ããã«ã¼ããæ¯æãµã¤ããã¨ãé½ç¨ã¯ã¬ã¸ããã«ã¼ããæ¯æãµã¤ããã®ä¸¡æ¹ã話é¡ã«ãã¦ããã ããã¯ãGMOãã¤ã¡ã³ãã²ã¼ãã¦ã§ã¤æ ªå¼ä¼ç¤¾ã¨ãã¨ã¿ãã¡ã¤ãã³ã¹æ ªå¼ä¼ç¤¾ãçµãã§ãæ±äº¬é½ã¸ã®é½ç¨ã®ç´ç¨ä»£è¡ã¨ãå½ç¨åºã¸ã®å½ç¨ã®ç´ç¨ä»£è¡ããããã¯ã¬ã¸ããã«ã¼ããæ¯æããµã¤ãããéå¶ãã¦ãã*1ã®ã ãããµã¤ãã®ç»é¢æ§æãããã¦ã誰ãéå¶ä¸»ä½ãªã®ãä¸æã ã¨ãããã¨ãåé¡ã¨ãªã£ã¦ãã
å¤æ°ã®Webãµã¼ãã¹ã«CDNï¼ã³ã³ãã³ãé ä¿¡ãããã¯ã¼ã¯ï¼ãæä¾ãã¦ããç±³Cloudflareã¯2æ23æ¥ï¼ç¾å°æéï¼ãã¨ãã¸ãµã¼ãã®ã»ãã¥ãªãã£åé¡ã§é¡§å®¢ã®HTTPã¯ããã¼ãèªè¨¼ãã¼ã¯ã³ãHTTP POSTæ¬ä½ãªã©ã®æ©å¯ãã¼ã¿ãæµåºããããã«ãã®ä¸é¨ã¯GoogleãBingãªã©ã®æ¤ç´¢ã¨ã³ã¸ã³ã«ãã£ã¦ãã£ãã·ã¥ããã¦ããã¨çºè¡¨ããã ãã°ã¯æ¢ã«ä¿®æ£ãããããã£ãã·ã¥ããããã¼ã¿ã«ã¤ãã¦ã¯ãGoogleãYahooãBingãªã©ã®ååã«ãããæ¢ã«ãã¼ã¸ããããCloudflareã¯ãæµåºãããã¼ã¿ãæªç¨ãããã¨ããå ±åã¯ä»ã®ã¨ãããªãã¨ãã¦ããã Cloudflareã®ãµã¼ãã¹ã¯ãä¾ãã°UberãFitBitãFeedlyãªã©ãä¸çã®550ä¸ä»¥ä¸ã®ä¼æ¥ãå©ç¨ãã¦ããããã®åé¡ã®å½±é¿ãåããå¯è½æ§ã®ããä¼æ¥ã®ãªã¹ãã第ä¸è ãGitHubã§å ¬éãã¦ããããããã確èªããããããèªåã使ã£ã¦ãããµ
ãèå¼±æ§ä½é¨å¦ç¿ãã¼ã« AppGoat ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ç¨å¦ç¿ãã¼ã«ãã«ã¯ãä»»æã®ã³ã¼ããå®è¡å¯è½ãªèå¼±æ§ãåå¨ãã¾ãã
ã¨ã°ã¼ã¯ãã£ããµã㪠WordPress 4.7ã¨4.7.1ã®REST APIã«ãèªè¨¼ãåé¿ãã¦ã³ã³ãã³ããæ¸ãæããããèå¼±æ§ãåå¨ãããæ»æã¯æ¥µãã¦å®¹æã§ããã®å½±é¿ã¯ä»»æã³ã³ãã³ãã®æ¸ãæãã§ãããããé大ãªçµæãåã¼ãã対çã¯WordPressã®ææ°çã«ãã¼ã¸ã§ã³ã¢ãããããã¨ã§ããã æ¬ç¨¿ã§ã¯ãèå¼±æ§æ··å ¥ã®åå ã«ã¤ãã¦å ±åããã ã¯ããã« WordPressæ¬ä½ã«ä¹ ãã¶ãã«é大ãªèå¼±æ§ãè¦ã¤ãã£ãã¨çºè¡¨ããã¾ããã ãããªé¢¨ã«æ¸ãã¨ãWordPressã®èå¼±æ§ãªãã¦ããã£ã¡ã ãè¦ã¤ãã£ã¦ããã¨ããæè¦ãããããã§ãããè½åçãã¤èªè¨¼ãªãã«ãä¾µå ¥ã§ããèå¼±æ§ã¯ããæ°å¹´åºã¦ããªãããã«æãã¾ããããããã¯ã©ã¹ã®ãã®ãä¹ ãã¶ãã«è¦ã¤ãã£ãã¨ãããã¨ã§ããã WordPressãæ´æ°çã§æ·±å»ãªèå¼±æ§ãä¿®æ£ãå®å ¨ç¢ºä¿ã®ããæ å ±å ¬éãå éã Make WordPress Core Conten
a.md Chrome Extensionã®Live HTTP Headersã調æ»ãããFirefoxç¨ã®ãã®ã§ã¯ãªããFirefoxç¨ã®ãã®ã§ã¯ãªãã https://chrome.google.com/webstore/detail/live-http-headers/iaiioopjkcekapmldfgbebdclcnpgnlo 11/7è¿½è¨ é¡ä¼¼ or åæ§ã®æ¹æ³ã§é£èªåscriptãåãè¾¼ãã§ããæ¡å¼µæ©è½ã大éã«ãã£ããããGoogleã«å ±åæ¸ã¿ã https://twitter.com/bulkneets/status/795260268221636608 English version: https://translate.google.com/translate?sl=ja&tl=en&js=y&prev=_t&hl=ja&ie=UTF-8&u=https%3A%2F%
JVNVU#91485132 CGI ã¦ã§ããµã¼ããããã Proxy ã®å¤ãç°å¢å¤æ° HTTP_PROXY ã«è¨å®ããèå¼±æ§ CGI ã¾ãã¯é¡ä¼¼ã®ã³ã³ããã¹ãã§åä½ãã¦ããã¦ã§ããµã¼ãã«ã¯ãã¯ã©ã¤ã¢ã³ããæå®ããããã Proxy ã®å¤ãå é¨ã®ç°å¢å¤æ° HTTP_PROXY ã«ç»é²ãã¦ãã¾ãèå¼±æ§ãåå¨ãã¾ãããã®èå¼±æ§ã«ãã£ã¦ãå é¨ã®ãµããªã¯ã¨ã¹ãã«ä¸éè æ»æ (man-in-the-middle attack) ãåãããããµã¼ããä»»æã®ãã¹ãã«æ¥ç¶ããããããããå¯è½æ§ãããã¾ãã ä¿¡é ¼ã§ããªãå ¥åå¤ã«ããã»ãã¥ãªãã£å¤å® (CWE-807) ããã³ å¤é¨å ¥åã«ããéè¦ãªå¤æ°ã¾ãã¯ãã¼ã¿ã®åæå (CWE-454) CGI ã¾ãã¯é¡ä¼¼ã®ã³ã³ããã¹ãã§åä½ãã¦ããã¦ã§ããµã¼ãã«ã¯ãã¯ã©ã¤ã¢ã³ããæå®ããããã Proxy ã®å¤ãå é¨ã®ç°å¢å¤æ° HTTP_PROXY ã«ç»é²ããèå¼±æ§ã
ã©ã³ãã³ã°
é害
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}