Posted by Shugo Maeda on 23 Aug 2008 Rubyã®æ¨æºã©ã¤ãã©ãªã«å«ã¾ãã¦ããREXMLã«ãDoSèå¼±æ§ãçºè¦ããã¾ããã XML entity explosion attackã¨å¼ã°ããæ»æææ³ã«ãããã¦ã¼ã¶ããä¸ããã ãXMLã解æãããããªã¢ããªã±ã¼ã·ã§ã³ããµã¼ãã¹ä¸è½(DoS)ç¶æ ã«ããã㨠ãã§ãã¾ãã Railsã¯ããã©ã«ãã®ç¶æ ã§ã¦ã¼ã¶ããä¸ããããXMLã解æããããã大é¨åã® Railsã¢ããªã±ã¼ã·ã§ã³ã¯ãã®æ»æã«å¯¾ãã¦èå¼±ã§ãã å½±é¿ æ»æè ã¯ã以ä¸ã®ããã«å帰çã«ãã¹ãããå®ä½åç §ãå«ãXMLææ¸ãREXML㫠解æããããã¨ã«ããããµã¼ãã¹ä¸è½(DoS)ç¶æ ãå¼ãèµ·ãããã¨ãã§ãã¾ãã <?xml version="1.0" encoding="UTF-8"?> <!DOCTYPE member [ <!ENTITY a "&b;
{{#tags}}- {{label}}
{{/tags}}