é©å½ XSSããã=ãªãã§ãããæ¾é¡ã§ã¯ãªã ããã°ãµã¼ãã¹ãªã©èªç±ã«HTMLãããããããªãµã¼ãã¹ã§ã¯ã害ãåã°ãªãããã«è¡¨ç¤ºã丸ãã¨å¥ã®ãã¡ã¤ã³ã«åãã¦ãããããããã¯å¥ãã¡ã¤ã³ã®IFRAMEå ã§å®è¡ããããã¦ããã®ãæ®éã§ããå人æ å ±ãé ãã£ã¦ããµã¤ãã¯ãéè¦å人æ å ±ã«ã¤ãã¦ã¯HTTPSãããªãã¨åç §ã§ããªãã£ããããããã表示ããªãã£ãã(ãã¹ã¯ã¼ããã«ã¼ãçªå·ç)ã決æ¸ç¨ã®ãã¹ã¯ã¼ããæ証çªå·ãå ¥ããªãã¨æä½ã§ããªãã£ããããã åèã¾ã§ã« http://blog.bulknews.net/mt/archives/001274.html (2004å¹´ã®ã¢ã¡ããèå¼±æ§ã®è©±) http://d.hatena.ne.jp/yamaz/20090114 (ä¿¡é ¼ã§ããªããã¼ã¿ãåãæ±ããã¡ã¤ã³ãåãã話) 管çç¨ã¨å¥ãã¡ã¤ã³ã«åããã«ãé¢ããããscriptå®è¡ã§ãããã¨ã«å¯¾ãã¦DISãã
{{#tags}}- {{label}}
{{/tags}}