ç§ã®DKåç©«ç¥ãªã©ã§é¨ããã¦ãããããããDKç¥ãã ãããã®ç§ããä»å¤åã®ç¥ãã«ã¯maitterã ç§ã®twitterãèãããã¦ããã®ã ã http://blog.livedoor.jp/dankogai/archives/50959103.html ç¾è±¡ããè¦ã¦ã»ãã·ã§ã³ãã¤ã¸ã£ãã¯ãããã¨æãããããåå ã¨ãªãèå¼±æ§ãå°é£¼å¼¾æ°ã®ä¸»å¼µã©ããCSRF(Cross Site Request Forgeries)ã ã£ãã®ãããã¹ã¯ã¼ãã¯çªåãããã®ããå ã ã®ãã¹ã¯ã¼ããé¡æ¨ãããããã®ã ã£ãã®ããªã©ãè°è«ãå¼ãã§ããã ç§ã¯ãç¾è±¡ããã¿ã¦ãåå ã¨ãªãèå¼±æ§ã¯CSRFã§ã¯ãªããXSSã ã£ãã¨æã*1ãtwitterã«XSSèå¼±æ§ãããã°ãã»ãã·ã§ã³ãã¤ã¸ã£ãã¯ã«ããã第ä¸è ãå°é£¼å¼¾æ°ã«ãªããã¾ãã¦çºè¨ããã¨ããã¾ã§ã¯å¯è½ã ãããããä¸è¬çã«ã¯XSSã§ã¯ãã¹ã¯ã¼ãã¾ã§ã¯çªåã§ããªããid:ha
{{#tags}}- {{label}}
{{/tags}}