tDiary 2.0.2(å®å®ç)ã2.1.2(éçºç)ããªãªã¼ã¹ãã¾ããã ãã®ãªãªã¼ã¹ã®ç®çã¯ã主ã«èå¼±æ§å¯¾çã§ããèå¼±æ§ã®å 容ã«ã¤ãã¦ã¯èå¼±æ§ã«é¢ããå ±å(2005-07-20)ãã覧ä¸ããã対象ã¨ãªããã¼ã¸ã§ã³ãã使ãã®æ¹ã¯ãææ°çã¸ã®ãã¼ã¸ã§ã³ã¢ãããå¼·ãæ¨å¥¨ãã¾ãã âãã¦ã³ãã¼ã CSRFæ»æ対çã«ä¼´ãªã£ã¦å¿ è¦ãªå©ç¨è ã®å¯¾å¿ (以ä¸ã®è§£èª¬ã¯ãä»åã®èå¼±æ§ã®å ±åè ã§ããç£æ¥æè¡ç·åç 究æ æ å ±ã»ãã¥ãªãã£ç 究ã»ã³ã¿ã¼ã®å¤§å²©å¯æ°ã«ããããã¥ã¡ã³ãããã¼ã¹ã«ãã¦ãã¾ã) tDiary 2.0.2ãtDiary 2.1.2以éã§ã¯ãã¯ãã¹ãµã¤ãã»ãªã¯ã¨ã¹ãã»ãã©ã¼ã¸ã§ãª(CSRF)æ»æã«å¯¾ãã対çãå°å ¥ããã¦ãã¾ãã対çå 容ã¯ä»¥ä¸ã®3ç¹ã§ã: æ¥è¨ã®æ´æ°ã»è¨å®ã®å¤æ´ãPOSTã¡ã½ããã§è¡ããã¦ããã㨠Refererã®å¤ãæ£å½ãªãã®ã§ããã㨠ãã©ã¼ã ã«åãè¾¼ã¾ãã(æ»æè ãç¥ãããª
tDiary éçºããã¸ã§ã¯ãã«ããæä¾ããã¦ãã Web æ¥è¨æ¯æ´ã½ãã tDiary ã«ã¯ãã¯ãã¹ãµã¤ãã»ãªã¯ã¨ã¹ãã»ãã©ã¼ã¸ã§ãª (Cross Site Request Forgeries, CSRFï¼ãå¯è½ãªèå¼±æ§ãåå¨ãã¾ãã
d:id:nyama:20041227:1104116475 ã¨ãã§æ¸ãã¦ããèå¼±æ§ãããããä¿®æ£ããã模æ§ã以åã¯ä»¥ä¸ã®ãããªå 容ãæ¸ããã html ãã¡ã¤ã«ã§ããã¿ã³ãã¯ãªãã¯ãªããããã¨æ¥è¨ãåæã«æ´æ°ããããã¨ãå¯è½ã ã£ãã試ãã¦ã¿ãã¨ããä»ã¯å¤§ä¸å¤«ã§ãã <form method="post" action="http://d.hatena.ne.jp/nyama/edit" enctype="multipart/form-data"> <p>10ç§çµã£ã¦ãå¤ãããªãã¨ãã¯ãã¿ã³ãã¯ãªãã¯! <input type="hidden" name="mode" value="enter" /> <input type="hidden" name="timestamp" value="20040913173912" /> <input type="hidden" name="date
id:honmal:20041226#p1 ã¨ãid:bakken:20041226#p3 ãèªãã¨ãid:bakken ããã¨ãããä½è ãã«ãã£ã¦æ¸ãæããããããã ãid:nyama:20040913#1095064759 ã§æ¸ããããªãã¡ã©ãåã£ã¦ããã¨ã¯ã¦ãªãã¤ã¢ãªã¼ã®ä¸æ£ãªèªåæä½ã«ã¤ãã¦ã®èå¼±æ§ã«ã¤ã㦠ã¯èªåã®ã¯ã¦ãªãã¤ã¢ãªã¼ã§å®é¨ãã¦ã¿ãéããã¾ã æ²»ã£ã¦ããªãããã ããããããã¦ããã ããããããããã§ããã°ããã¹ã¯ã¼ããå¤ãã¦ãæ ¹æ¬çã«è§£æ±ºã«ã¯ãªãã¾ãããï¼id:bakken ãã ããã«ãã¦ããã®ä»¶ã«ã¤ãã¦ã¯9æã«ã¯ã¦ãªå®ã«ã¡ã¼ã«ãããã§ããããã¾ã é³æ²æ±°ãç¡ããèªã¾ãã¦ããªãã®ããªããï¼ id:hatenadiary
å æ¥ãããã¯ã¦ãªåãµã¼ãã¹ã«ããã CSRF èå¼±æ§ã®å¯¾çæ¹æ³ãè¦ç´ãã¦ããã¾ããããã¾ã§ã¯ãªãã¡ã©ããã§ãã¯ããæ¹æ³ãæ¡ç¨ãã¦ããã¾ãããããã®æ¹æ³ã¯å¯¾çã¨ãã¦ã¯ä¸ååãªç¹ããããæ°ãã« POST ã«ãããã¼ã¿ã®éä¿¡æãã»ãã·ã§ã³IDãç¨ããæ¤æ»ãè¡ãæ¹æ³ãæ¡ç¨ãã¦ããã¾ãã ç¾å¨ãåãµã¼ãã¹ã§ã®å¯¾å¿ãã»ã¼å®äºãã¦ããã¾ãããµã¼ããã¼ãã£è£½ã®ãã¼ã«ãªã©ãå¤é¨ããç´æ¥ãã¼ã¿ã POST ãã¦ããã¢ããªã±ã¼ã·ã§ã³ãªã©ããä»åã®å¤æ´ã«ããåä½ãããªã£ã¦ããå¯è½æ§ããããã¾ãããã¯ã¦ãªåãµã¼ãã¹ã®å®å ¨æ§åä¸ãç®çã®å¤æ´ã¨ãªãã¾ãã®ã§ããäºæ¿ããã ããã°å¹¸ãã§ãã ãªããã»ãã·ã§ã³ID 㯠Cookie ã«ä¿åããã¦ãã rk ãã©ã¡ã¼ã¿ã®å¤ã MD5 BASE64 ã§ã·ãªã¢ã©ã¤ãºããå¤ã«ãªãã¾ããCookie ãåå¾å¯è½ãªãµã¼ããã¼ãã£è£½ãã¼ã«ã§ããã°ãrk ãã©ã¡ã¼ã¿ãã¨ã³ã³ã¼ãããå¤ã rk
Hiki is a powerful and fast wiki clone written in Ruby. The latest stable version is 0.8.8.1. 2009-08-16 Hiki 0.8.8.1 released ->Download ->This version fixes a DoS vulnerability of Wiki style's parser. Upgrade to 0.8.8.1 is highly recomended. If you already installed 0.8.8, the followings are only modified program files, and wish to contribute to this wiki, feel free to add your, just make sure t
å¯ãåã«æ°ã«ãªã£ã¦å®è¨¼ã³ã¼ãæ¸ããã©ããæ©ã¿ã¤ã¤ç¡ç è¬ã®åã«è² ãã¦å¯ã¦ãã¾ã£ãããã§ããããã£ã±ããã¡ã§ãã(è¦ç¬)ãä»æ¥ã¯å ¬è´ä¼ã ãã対å¦ã¯ãã¿ããã¨é£ä¼æããã¼ï¼ ããã¾ãããããã¯ããªãããã«ãããããã¼ãã¯ã¾ã¡ã¡ããï¼ ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼(ãã¼ ã¡ãªã¿ã«XSSèå¼±æ§ã¯ ãªãããã«è¦ãã¾ãã
ã¯ã¦ãªã¢ã¤ã㢠ãµã¼ãã¹çµäºã®ãç¥ãã å¹³ç´ ãããã¯ã¦ãªã¢ã¤ãã¢ãããå©ç¨ããã ãããããã¨ããããã¾ãã è¦æçªå£ãµã¼ãã¹ãã¯ã¦ãªã¢ã¤ãã¢ãã¯2013å¹´7æ31æ¥ï¼æ°´ï¼ããã¡ã¾ãã¦çµäºãããã¾ããã8å¹´ã«ããã試é¨éç¨ã«ãååããã ãããããã¨ããããã¾ããã ããã¾ã§ãå©ç¨ããã ãã¾ããã¦ã¼ã¶ã¼ã®çãã¾ã«æ·±ãæè¬ãããã¾ãã èª ã«ãããã¨ããããã¾ããã 詳ããã¯ä¸è¨ãã覧ãã ããã http://hatena.g.hatena.ne.jp/hatenaidea/20130731/1375250394
å é±æ«ããä¸éãé¨ããã CSRF ã£ã¦çµå±ä½ã ã£ãã®ã§ãããããããããã解説è¨äºã @IT ã«åºã¦ãã¾ããã ãã¼ãã¯ã¾ã¡ã¡ããã ââç¥ããããCSRFæ»æï¼Security&Trust ã¦ã©ããï¼33ï¼ - ï¼ IT mixiã§ã®ã¯ã¾ã¡ã¡ããã«é¢ãã¦ãããªãããããããæ¸ããã¦ãã¾ããå ·ä½çãªHTMLã®è¨è¼ããªãã®ãæ®å¿µã§ãã ãã¦ãã¯ã¾ã¡ã¡ããã®è©³ç´°ãæ¸ãã®ãã¢ã¬ã§ãã®ã§ãå®éã«ä»ã®ã¢ã³ã±ã¼ããµã¤ãã§ãã£ã CSRF ã®äºä¾ããã¨ã«ãããå°ãå ·ä½çã«CSRFã«ã¤ãã¦æ¸ãã¦ã¿ã¾ãããã ã¨ãããã¨ã«ã¤ãã¦éåæã®æç¡ãåãã¢ã³ã±ã¼ããªã®ã§ãããããã®HTMLã½ã¼ã¹ã¯æ¬¡ã®ããã«ãªã£ã¦ãã¾ããã(主è¦ãªé¨åã®ã¿) <form action=1.cgi method=post> <tr> <td>ãªã¾ãï¼</td> <td><input type=text name=n size=30>
â ã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªï¼CSRFï¼ã®æ£ãã対çæ¹æ³ ãã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªããã«ããã«æ³¨ç®ãéãã¦ãããå¤ã ããåå¨ãããã®åé¡ããªãä»ã¾ã§ãã¾ã注ç®ããã¦ããªãã£ããã«ã¤ãã¦è ãã¦ããã¨ããã ããå¼è¶ããã転å¤ããã§ãã¾ã²ã¨ã¤æ¥è¨ãæ¸ãæéããªãã ãããã @ITã®è¨äºãªã©ã®ããã«æ··ä¹±ããã解説ãæ£è¦ãããã®ã§ãä¸ç¹ã ã対ç æ¹æ³ã«ã¤ãã¦æ¸ãã¦ããã¨ããã ã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãªââCross-Site Request Forgeries (CSRF)ãé²æ¢ããç°¡æ½ã§èªç¶ãªè§£æ±ºçã¯ä»¥ä¸ã®ã¨ããã§ããã åæ ãã°ã¤ã³ãã¦ããªãWebé²è¦§è ã«å¯¾ããCSRFæ»æï¼æ²ç¤ºæ¿èããããã¦ã¼ã¶ç» é²ãä»äººã«ãããçããµã¤ãéå¶è ã«å¯¾ããæ¥å妨害è¡çºï¼ã¯ããã§ã¯å¯¾è±¡ã¨ ããªãã ãã°ã¤ã³æ©è½ãæã¤Webã¢ããªã±ã¼ã·ã§ã³ã®å ´åãä½ããã®æ¹æ³ã§ã»ãã·ã§ã³ 追
ããæ¥ã大æSNSï¼Social Networking Siteï¼ã®mixiã®æ¥è¨ã«ãã®ãããªæ¸ãè¾¼ã¿ããã£ããããã1人ã ãã§ãªããåæ¥ã«æ°å¤ãã®ã¦ã¼ã¶ã¼ã®æ¥è¨ã«åãæé¢ãæ²è¼ããã¦ããã ããã¯ãåã«ãã®ãããªæç« ãã¯ãããã¦ã¼ã¶ã¼èªèº«ãæå³ãã¦æ²è¼ããã®ã§ã¯ãªããããä»æãã«ãã£ã¦ã¦ã¼ã¶ã¼èªèº«ãæ°ä»ããªããã¡ã«å¼ãèµ·ããããç¾è±¡ãªã®ã§ããããã®ä»æãã¨ã¯ãCSRFï¼Cross-Site Request Forgeriesï¼ã¨å¼ã°ããæ»æææ³ã®ä¸ç¨®ã ã ç·¨éé¨æ³¨ï¼ ç¾å¨ããã¯ã¾ã¡ã¡ããããã©ããã¯ãmixiéå¶è ã«ãã対çããã¦ãã¾ããä¸è¨ã®ãµã³ãã«ã¯ãmixi風ã«åæ§æãããã®ã§ãã æ¬ç¨¿ã®å 容ãæ¤è¨¼ããå ´åã¯ãå¿ ãå½±é¿ãåã¼ããªãéãããç°å¢ä¸ã§è¡ã£ã¦ä¸ãããã¾ããæ¬ç¨¿ãå©ç¨ããè¡çºã«ããåé¡ã«é¢ãã¾ãã¦ã¯ãçè ããã³ã¢ã¤ãã£ã¡ãã£ã¢æ ªå¼ä¼ç¤¾ã¯ä¸å責任ãè² ãããã¾ãããäºæ¿ãã ãã
2005-04-21 ãµã¼ã¯ã«ã¯ã©ãã·ã£ã¼åç éè¨ ãµã¼ã¯ã«ã§ã¯ãªããã ããæã¨ããã³ãã¥ããã£ã§åæã«å å¼å¢ããã¢ã¬ãªå¥³ããããç¶æ³ãææ¡ã§ããªããªã£ã¦ããã®ã§å å¼ã10人ã«éãããã¡ã¼ãªã³ã°ãªã¹ãä½ãããã¨ããããªè©±ããã¦ãã(ä½ããªãã£ããã©)ãããã女ã£ã¦ã©ããã¦ãããã®ä¸ã§åã®ç·ã®ÃÃ⦠2005-04-21 mixi ã®ã»ãã¥ãªãã£ã¼ãã¼ã«(ãã®3) web [id:rna:20050420#p1] ã®è¿½è¨ã«æ¸ããããã«17:00é ã«ãæ®ã£ã¦ããç©´ã®ãã¡åãææ¡ãã¦ããåã«ã¤ãã¦ã¯å¯¾çãã¨ãããããã§ããã¾ãã¯ãç²ããã¾ã¨ãããã¨ã§ãã§ãããmixi ã®ããã¾ã§ã®å¯¾å¿ã®ãããã«ã¯çåãæ®ãã¾ãããããããåã調ã¹ã¦ãªãé¨åã®â¦
æ´æ°: 2005å¹´7æ18æ¥ ã¡ãã㨠Movable Type ã®è©±ããã¦ã㦠yuuãã (w3j.org)ã«æãã¦ããã ããã®ã§ãããMovable Type ã«ã¯ CSRFæ»æã®åé¡ãããã¿ããã§ããããMT ãã¤ã³ã¹ãã¼ã«ãããçã£å ã«è¡ãã¹ãã»ãã¥ãªãã£å¯¾ç (hxxk.jp)ã â»2005-07-18追è¨: ãªã³ã¯å ã®è¨äºã¯ãã¯ã¼ã¢ãããã¦ç§»åãã¦ããããã§ã : ãMovable Type ã«ããã CSRF ã®å¯è½æ§ã¨å種対å¦æ³ (hxxk.jp)ã ããããã¡ãã㨠CSRF ã¨ããååãããã®ã«å ¨ç¶åºã¦ããªãã¨ããã®ãâ¦â¦ããã®ååã¯ããã¾ãä¸è¬çã§ã¯ãªãã®ããªãã â»XSS ã«æ¯ã¹ãã¨éãã«ãã¤ãã¼ã ã¨ã¯æãã¾ãããã¡ãªã¿ã« CSRF ã¨ããã®ã¯ "Cross-Site Request Forgeries" ã®ç¥ã§ãè¦ããã«ãç·¨éããåé¤ããªã©ã®ã³ãã³ããå®è¡ããã
ç¨èªãCSRFãã«ã¤ãã¦CSRF (ãã¼ãããã¼ãããµ)è©±é¡ : ã»ãã¥ãªã㣠CSRF 㯠Cross Site Request Forgeries ã®ç¥ã§ãã"forgery" ã¯å½é ã®æå³ã§ããµã¤ããã¾ããã£ã¦æé ãããæ»æãªã¯ã¨ã¹ããéä¿¡ãããã¨ããç¨åº¦ã®æå³ã«ãªãã¾ãã â»ã¡ãªã¿ã«ãCSRF ã¯ãã·ã¼ãµã¼ããã¨çºé³ããã®ã ã¨ãã説ãããã¾ãããå°ãªãã¨ãæ¥æ¬ã§ã¯ããã¼ãããã¼ãããµãã¨å¼ã¶æ¹ã主æµã®ããã§ãã ãã¨ãã°ãblog ãªã©ã¯ Web ä¸ã®ç®¡çç»é¢ã§è¨äºã®åé¤ãã§ããããã«ãªã£ã¦ãã¾ããåé¤ãå®è¡ããã«ã¯ãåé¤ãè¡ããã㪠HTTP ã®ãªã¯ã¨ã¹ãããµã¼ãã«éãã°è¯ãã®ã§ããããã®ç»é¢ã¯ Cookie ãªããBasic èªè¨¼ãªãã§ã¢ã¯ã»ã¹å¶å¾¡ãããã¦ãã¾ãããã®ãããæ£è¦ã®ã¦ã¼ã¶ä»¥å¤ãåé¤ã®ãªã¯ã¨ã¹ããéã£ã¦ãä½ãèµ·ãã¾ããããã°ã¤ã³æ¸ã¿ã®æ£è¦ã®ã¦ã¼ã¶ããåé¤ãã®ãªã¯ã¨ã¹
ã¨ãããããæå ã«Webãµã¼ããç«ã¡ä¸ããªããã¨ã«ã¯é²ã¿ã¾ããã§ãã Gmailã®æ·»ä»ãã¡ã¤ã«ã§ã¯ããã¾ãåç¾ã§ãã¾ããã§ããã ã¯ã¦ãªã§ã¯ãç»åãæ¸ãæãããããããPNGãJPGãã ãã§ããã ã£ã¦ããã§ãææ¥ã«ã§ãWebãµã¼ããç¨æãã¦ã¿ãã¤ããã§ãã â¦åç¾ã§ãã¾ãããä»ããå ±åã ãã¾ãã(02:36AM) ï¼ èª°ã¨ãªãã ã«ãªã£ããæ»ã£ãããã¦ã¾ããããæ°ã«ãªãããã«ã ã®ã§ãå¯ã¾ãããããã¿ãªããã å 容ã«èª¤ããããã°è£è¶³ããé¡ããããã¾ãã å¸°å® ã
ã¡ã³ããã³ã¹
ãç¥ãã
é害
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}