ä¾ãã°ï¼Railsã®å ¥åã®ã»ãã¥ãªãã£å¯¾çã¯ã»ãã¥ã¢ã§ããã¨ã¯è¨ãã¾ãããRailsã®ããªãã¼ã·ã§ã³ã¯ããã¼ã¿ãã¼ã¹ã«ãã¼ã¿ãä¿åãããåãã«è¡ããã¾ãããã¼ã¿ãã¼ã¹ã«ãã¼ã¿ãä¿åããå¿ è¦ããªããããªã¢ããªã±ã¼ã·ã§ã³ã®å ´åï¼å ¥åã®ããªãã¼ã·ã§ã³ããã¬ã¼ã ã¯ã¼ã¯ã¨ãã¦è¡ãä»çµã¿ã«ãªã£ã¦ãã¾ãããæ¬æ¥å ¥åã¯ãã¼ã¿ãã¼ã¹å©ç¨ã®æç¡ã«é¢ãããå ¥åãåãå ¥ããç´å¾ã«è¡ãã¹ãã§ããå¤ãã®ãã¬ã¼ã ã¯ã¼ã¯ãRailsã®å½±é¿ãåãåæ§ã®ä»æ§ã¨ãªã£ã¦ãã¾ããRailsãèå¼±ãªä»æ§ãæ¡ç¨ãããã¨ã¯ä¸å¹¸ãªãã¨ã ã£ãã¨æãã¾ãã â¦â¦ã ã¾ããããªãã¼ã·ã§ã³ã¯ã»ãã¥ãªãã£ã®ããã«ããå¦çã§ã¯ããã¾ããããã¾ãã¾ã»ãã¥ãªãã£ã®å½¹ã«ç«ã¤ãã¨ãããã¾ãããå½¹ã«ç«ããªããã¨ãããã¾ãããã¨ãã°ãåãåãããã©ã¼ã ã«æ¬æã®å ¥åæ¬ããããä»»æã®ããã¹ããå ¥åã§ãã¦ãDBã«ã¯Textå (ä»»æã®é·ãã®ä»»æã®ããã¹ã) ã¨ãã¦ä¿å
â [rails] Rails3ã«ãããã©ã«ãã§HTMLã¨ã¹ã±ã¼ãããæ©è½ããå ¥ã£ãããã ERBã§ã¯ã<%= foo %>ããã¨ã¹ã±ã¼ããªããã<%= h foo %>ããã¨ã¹ã±ã¼ãããã§ããã Rails3ã®trunkã§ãããã©ã«ãã§HTMLã¨ã¹ã±ã¼ããè¡ãæ©è½ãå ¥ã£ãããã§ãã Riding Rails: What's New in Edge Rails å®å ¨ã®ããã«ã<%= foo %>ãã®æ¹ãã¨ã¹ã±ã¼ãããã«ãã¹ãã ããã¨ããè°è«ã¯åãããã£ã¦ã å®è£ ãErubis(ãªãã·ã§ã³ã§å¯è½)ã¨ã SafeERB*1 *2ã¨ã ãã£ãããã§ããã©ãã§ããã°Railsæ¨æºã§ãããªã£ã¦ãæ¹ãè¯ããããã®å¤æ´ãå ¥ãããªã確ãã«ãã¼ã¸ã§ã³2â3ã®ä»ãããªãæ°ããã¾ãã ã¨ã¹ã±ã¼ããç¡å¹ã«ããã«ã¯String#html_safe!ãå¼ã¶ãããã©ã°ã¤ã³ã§ã<%= raw foo %>ãã®ããã«æ¸ãã
æè¿ã®å¤§ç°ãã@mixiã®ã¨ããã§ãRubyã«ã¤ãã¦èå¯ããæ©ä¼ããã£ãã®ã¨ããããã¡ããã®èãã¨åããã¨ãæã£ã¦ããã®ã§ããã¾ã«ã¯æ¬é³ã§æ¸ãã¦ã¿ãã Railsã§ãæãè¯ãã¨ããã¯ããã¹ãã®éå½¢ãèªåçã«ä½ã£ã¦ããã¦ããã¹ãã®æ·å± ãä¸ãã¦ããã¦ãã¨ããã ã¨æãããªã®ã«ãããã«ã¤ãã¦è§¦ãã人ããã¾ãã«ãå°ãªããããªæ°ããããä¸å¿ãç§ã¯ã1å¹´å以ä¸ãã¯ã¦ãªã®ãã¼ã¯ã¼ãæ¤ç´¢ã§æ¯æ¥Railsã«ã¤ãã¦ã¯èª¿ã¹ã¦ããã®ã§ãã¯ã¦ãªã§Railsã«ã¤ãã¦æ¸ãã¦ãã人ã®è¨äºã¯ããã¦ãè¦ã¦ãã¾ãã çç±ã¯ãããã¤ãèãããã¾ãããç§ã®èªã¿ã ã¨ããã¹ããå½ããåã®äººã«ã¨ã£ã¦ã¯ãå½ããåããã¦ããããæ¸ãæå³ããªãããããã§ã¯ãªãå¤ãã®äººã«ã¨ã£ã¦ã¯ãã»ã¨ãã©ãã¹ãã¯æ¸ãã¦ããªãããããªãããªã å®ã¯ããã¹ããæ¸ãã®ã¯çµæ§å·¥æ°ããããã§ãããã¹ã¯ãªããè¨èªã¯ãã³ã³ãã¤ã©ããã¹ãæãã¦ããããã¨ã¯ãªãã®ã§ãJavaã¨æ¯
Description To json is almost only used for injecting object hashes into javascript. var client = <%= client.to_json %>; Because to_json does not escape its values, it's easy to construct a Cross Site Scripting exploit. If client has a name attribute, to_json will come up with something like: var client = {attributes: {name: "TEST"}}; If we change the name to say: TEST"}}; alert('XSS!!') ;a={{" we
_ Webã¢ããªã±ã¼ã·ã§ã³ã»ãã¥ãªãã£ãã©ã¼ã©ã ã¨ããããã§ãçºè¡¨ãã¦æ¥ãã ã¹ã©ã¤ã(PDF) ã¹ã©ã¤ãå稿(RD) èªåã®çºè¡¨ã¯ã¨ãããèå³æ·±ã話ãè²ã èãã¦ããã£ãã ã¨ãã«å¥¥ããã¨é«æ¨å çã®ããã«ãé¢ç½ãã£ãã 追è¨: ãªã¯ã¨ã¹ãããã£ãã®ã§ããã«ã®å 容ã«ã¤ãã¦å°ãã (ææ§ãªè¨æ¶ã«åºã¥ãåç¾ã§è¨ãåãã¯éãã¨æãããå 容ã«ãç§ã®åéããããããããã¾ããã念ã®ãã) é«æ¨å ç Greasemonkeyã®èª¬æã®é¨åãããèãããªãã£ããã§ããã 奥ãã (å 容ã説æ) é«æ¨å ç ããã¨ããã¯ããã¼ãæ¼æ´©ããç¨åº¦ãªã®ã§åé¡ãªããã¨èããããããªæ°ããããã§ããã ç§ã®å¿ã®å£° (æåããèããã¦ããããâ¦) 奥ãã ãã¼ã«ã«ãã¡ã¤ã«ã«ã¢ã¯ã»ã¹ã§ããããä»»æã®ã³ãã³ããå®è¡ããããããã®ã«æ¯ã¹ãã°ãã¨ãããã¨ã§ããã é«æ¨å ç ãããããã¯éãã¨æããã§ãããéè¡ãµã¤ãã®ã¯ããã¼ãæ¼æ´©
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}