Google ã®ã¦ã§ããã°å ¬éãã¼ã«ã使ã£ã¦ãããã¹ããåçãåç»ãå ±æã§ãã¾ãã
Google ã®ã¦ã§ããã°å ¬éãã¼ã«ã使ã£ã¦ãããã¹ããåçãåç»ãå ±æã§ãã¾ãã
ä¸è¬çãªç»é²ãã©ã¼ã ã®ç»é¢é·ç§»ã¯ã å ¥åç»é¢âå ¥å確èªç»é¢âå®äºç»é¢ ã§ãããããããªããã©å¦çã®æµãã¨ãã¦ã¯ã å ¥åç»é¢è¡¨ç¤ºå¦çâå ¥å確èªç»é¢è¡¨ç¤ºå¦çâç»é²(ã¡ã¼ã«éä¿¡)å¦çâå®äºç»é¢è¡¨ç¤ºå¦ç ã«ãªãã å¦çãåãããã¨ã«ãããå®äºç»é¢ã§ãªãã¼ãããã¦ããäºåº¦ãç»é²å¦çãè¡ããããã¨ã¯ãªãã å人çã«ã¯ãå®äºç»é¢ã§ç»é²(ã¡ã¼ã«éä¿¡)å¦çãè¡ãã®ã¯ããã¾ã好ãã§ã¯ãªãã ç»é²(ã¡ã¼ã«éä¿¡)å¦çã¨å®äºç»é¢è¡¨ç¤ºå¦çãåä¸å¦çä¸ã§è¡ããã¨ããã¨ãé¢åãªãªãã¼ã対çãè¡ããªãã¦ã¯ãããªãã ããã§ä»¶ã®ãã¼ã¸ã®å 容ã«è¡ãçãã ããããªãã¼ã対ç 件ã®ãã¼ã¸ã®å 容ããããããã¨ããã®ã¯CSRF(ã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãª)対çãåæã«è¡ã£ã¦ããç¹ã§ãããã CSRFã¯ãé常ã®ããã¼ãéããã«ç»é²å¦çã ããè¡ããã¨ããæ»æã§ãããã³ã¡ã³ãã¹ãã ãªãããããä¾ã CSRF対çã¨ãã¦ã¯ãããªãã¡ã©
絶対ã«å ¬éãã¦ã¯ãããªãPHPããã°ã©ãã³ã° ãã¿å ï¼AjaxMailï¼Ajaxãæ´»ç¨ããããªã¼PHPã¡ã¼ã«ãã©ã¼ã ããã¯ã²ã©ãã®ã«èª°ãã¤ã£ãã¿ãå ¥ãã¦ããªãã®ã§ãããã³ããå ¥ãã¦ããã¾ãã ã»ãã¥ãªãã£ã¼ãã£ãã¯ã¹ãããã¾ããã AjaxMailãå©ç¨ãã¦ãããµã¤ãã¯ã¹ãã ã¡ã¼ã«ã®è¸ã¿å°ã«ããã¾ãã éä¿¡ããã°ã©ã ã§ããsendmail.phpã® 150è¡ç®ã§POSTã§åãåã£ãã¢ãã¬ã¹ããã®ã¾ã¾å¤æ°ã«å ¥ãã¦ã $reto = $_POST['email']; 168è¡ç®ã§ç´æ¥ã¡ã¼ã«é¢æ°ã«å©ç¨ãã¦ããã if($remail == 1) { mail($reto,$resbj,$rebody,$reheader); } ããããªãã mailé¢æ°ã®ç¬¬ä¸å¼æ°ã«ã¯éä¿¡å ã®ã¡ã¼ã«ã¢ãã¬ã¹ãè¨å®ã§ããã®ã§ãããã«ã³ãåºåãã§è¤æ°ã®ã¡ã¼ã«ã¢ãã¬ã¹ãæå®ã§ãã¾ãã ãªã¿ã¼ã³ã¡ã¼ã«ã®æ§è³ªä¸ããªãã¡ã©
ã¬ã³ãã©ã¼ï¼Gumblarï¼ã®çå¨ãæ¢ã¾ããªãã2009å¹´ã®æ¥ã«ä¸çä¸ã§å¤§ææãããã®ã¡ã«ãä¸æä¸ç«ã¨ãªã£ãã¦ã¤ã«ã¹ã ãã2009å¹´æ«ãã2010å¹´ã«ããã¦å½å 大æä¼æ¥ã®Webãµã¤ããç¸æ¬¡ãã§æ¹ãããããªã©ãåã³æ·±å»ãªäºæ ã¨ãªã£ã¦ããããã®ã¬ã³ãã©ã¼ã¨ã¯ã©ã®ãããªã¦ã¤ã«ã¹ã§ãã©ã®ãããªè¢«å®³ãåºãã¦ããã®ããå ±éå社ã®ãã¥ã¼ã¹è¨äºãã»ãã¥ãªãã£ãã³ãã¼ã®è§£èª¬ãµã¤ããããã«ASCII.jpã«æ²è¼ãããããã¾ã§ã®è¨äºãæ¯ãè¿ããªããç´¹ä»ãã¦ãããã å½å ã®ã¬ã³ãã©ã¼è¢«å®³ã§æåã«å¤§ããªãã¥ã¼ã¹ã¨ãªã£ãã®ãã2009å¹´4æ4æ¥é ã«çããPCã·ã§ãããéå¶ããé販ãµã¤ãæ¹ããäºä»¶ã ããããã®å½±é¿ã§ãã¬ã³ãã©ã¼ã«ã¯ãGENOï¼ã¸ã§ãï¼ã¦ã¤ã«ã¹ãã¨ããå¥åãã¤ãã¦ãã¾ã£ãããã¡ããå½å ã®ã¿ã§éç¨ããå¥åã§ãããã®ã¡ã«å¤ãã®Webãµã¤ããæ¹ãããããã«è³ã£ããããGENOã¦ã¤ã«ã¹ã¨å¼ã¶ã±ã¼ã¹ã¯æ¸ã£ã¦ãã¦ãã
ãããã¤ã³ã¹ãã¼ã«ä»£è¡¨ã®ã©ã¤ãããã¯ããã°
ã¤ã³ã¿ã¼ãããä¸ã§ã¦ã¼ã¶èªè¨¼ãã»ã³ã·ãã£ããªæ å ±ãéããéã«ã¯SSLã使ããã¨ãä¸è¬çã ãã¨ã¯è¨ãå人ãã¬ã³ã¿ã«ãµã¼ãã¬ãã«ã§ã¯è¨¼ææ¸ãåå¾ããã®ã¯ã³ã¹ãé¢ãæè¡é¢ã§é£ãããã¨ããããã ããã¨ãã£ã¦ããã®ãããªæ å ±ãå¹³æã®ã¾ã¾æµãã®ã¯æ°ã«ãªãæã ã ãã©ã¼ã ã®å 容ãæå·åãã¦éä¿¡ ç°¡åãªæå·åã ãã§ãè¯ãããè¡ãããããããªæã«ä½¿ããããªã®ãjCryptionã ã ä»åç´¹ä»ãããªã¼ãã³ã½ã¼ã¹ã»ã½ããã¦ã§ã¢ã¯jCryptionãJavaScriptãã¼ã¹ã®æå·åã©ã¤ãã©ãªã ã jCryptionã¯RSAæå·ï¼å ¬ééµæå·ï¼ã«åã£ãã¢ã«ã´ãªãºã ã使ã£ãæå·åã©ã¤ãã©ãªã ã復å·åå¯è½ãªã©ã¤ãã©ãªã§ãããjCryptionã§ã¯PHPã®ã¯ã©ã¹ãæä¾ãã¦ãããå®è£ ã¯jQueryã使ã£ã¦è¡ããã¦ããã®ã§jQueryã使ã£ãéçºã§ã¯å©ç¨ãã¨ã¦ãç°¡åã«è¡ããã å ¬ééµãéä¿¡ãã¦ããã¹ã¯ãªããé¨å éä¿¡ç´åã«ãµ
1. 8ä¸ã®ã«ã¼ãæ å ±ãå«ã65ä¸äººã®å人æ å ±ãæ¼æ´©ãï¼ã»ãã¥ãªãã£ããã¡ããè¦ç´ãã 2. æ¼æ´©ãå¤æããç´å¾ã¯å»¶ã¹20人ã3æ¥éï¼å¤ãå¾¹ãã¦ä½æ¥ã«å½ãã£ã 3. ã«ã¼ãæ å ±ã®ç®¡çã第ä¸è ã«ä»»ãï¼WAFãå°å ¥ãããªã©å®å ¨æ§ãé«ãã ãããããã¨ã«ãªã£ã¦ãã¾ã£ããè¦æããªããããªãã 2008å¹´7æ10æ¥ã®æ·±å¤ã®ãã¨ãã¢ã¦ããã¢ç¨åãé£ãå ·ã®è²©å£²ã§å¹´é40ååã売ãä¸ããECãµã¤ããããã¥ã©ã ããéå¶ããããã«ã´ã¡ã»ãã¼ã«ãã£ã³ã°ã¹ï¼å½æã®ç¤¾åã¯ããã¥ã©ã ï¼8æ1æ¥ã«æã¡æ ªä¼ç¤¾ã¨ãã¦æ¹ç§°ï¼ã®ä¸å³¶æ浩æ°ï¼ä»£è¡¨åç· å½¹ä¼é·å ¼ç¤¾é·CEOï¼ã¯ï¼åµæ¥ä»¥æ¥ã®å±æ©ã«ç´é¢ãã¦ãããããã¥ã©ã ã®ãµã¤ãããï¼ã¯ã¬ã¸ããã«ã¼ãæ å ±ãå«ãå人æ å ±ãã»ã¼ç¢ºå®ã«æ¼æ´©ãã¦ãããã¨ãå¤æããã®ã ã大éªå¸ä¸å¤®åºã®æ¬ç¤¾ä¼è°å®¤ã«éã¾ã£ãã¡ã³ãã¼ã¯çéããã¦ããã ã¾ãåãçµãã ã®ã¯è¢«å®³ã®æ¡å¤§ãé²ããã¨ï¼å³1ï¼ã丸3æ¥éã§ä¸æ°ã«å¯¾
ä¸ä½ãWebãµã¤ããæããªãçµç¹ã¯ä»ã©ããããããã§ããããã Webãµã¼ããèªåã§æã¤ããã¹ãã£ã³ã°ãµã¼ãã¹ãå©ç¨ããããªã©éç¨å½¢æ ã¯ãã¾ãã¾ã§ãããWebãµã¤ããæããªãçµç¹ã¯ã»ã¨ãã©ãªãã¨æããç¨ã« Webã¯æ®åãã¦ãã¾ãã ãã¡ã¤ã¢ã¦ã©ã¼ã«ã¯ã»ã¨ãã©ã®çµç¹ã§å°å ¥æ¸ã¿ã§ãããå¤ãã®Webãµã¼ãã¯ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®ä¸ã§éç¨ããã¦ããã®ãä¸è¬çã§ãã ããããªãããæãæ®åãã¦ãããã¡ã¤ã¢ã¦ã©ã¼ã«ã¯IPã¢ãã¬ã¹ããã¼ãã¬ãã«ã§ã®ãã£ã«ã¿ãªã³ã°ã§ãããã®æ¹æ³ã§ã®ãã£ã«ã¿ãªã³ã°ã§ã¯ã許å¯ãã¦ããªããµã¼ãã¹ãæã¤èå¼±æ§ãçã£ãæ»æãé»æ¢ã§ããããæç¨ã§ã¯ããã¾ãããHTTPã許å¯ãã¦ããå ´åWebèªä½ã¸ã®æ»æã«å¯¾ãã¦ç¡åã§ããä¸æ¹ã§ãHTTPãä¸è¨±å¯ã«ããå ´åã«ã¯Webãµã¤ãã¸ã¢ã¯ã»ã¹ã§ããªããªã£ã¦ãã¾ãããæ¬æ¥ã®ç®çãéæã§ãã¾ããããããããæ°å¹´ãWebãµã¤ããçã£ãã¯ã¼ã ãä¸æ£ã¢ã¯ã»ã¹ã¯
èªå® ã§å ¬éãµã¼ããç«ã¦ã¦ãã人ã¯ãã¡ãããããã§ãªãæ¹ãæè¿ã¯ã»ãã¥ãªãã£ã«æ°ãé£ãããã«ãªã£ã¦ãã¦ããã100%å®ç§ãªã»ãã¥ãªãã£ã¯ãªãã ããããããã§ãããç¨åº¦æ°ãã¤ããã ãã§è§£æ±ºããåé¡ã¯å¤ãã ããã§Firewallã®å°å ¥ããã¦ã¿ãã®ã¯ã©ãã ãããFreeBSDã§ä½¿ããã¦ãããã±ãããã£ã«ã¿ã®Windowsçã ã ä»åç´¹ä»ãããªã¼ãã³ã½ã¼ã¹ã»ã½ããã¦ã§ã¢ã¯wipfwãIPFWã®Windowsçã ã wipfwã§ã¯ãã¼ãã«å¯¾ãã¦ããããAcceptãRejectãè¨å®ãã¦ãããåºæ¬çã«ã¯å ¨ã¦éããä¸ã§ãå¿ è¦ãªãã®ã«ã¤ãã¦é çªã«ããã¦ããã¨ããæ¹æ³ã«ãªãã ããã CUIã§æä½ããã®ãåºæ¬ã§ã¯ããããwipfwã®ãµã¤ãã§ã¯GUIããã³ãã¨ã³ããé å¸ããã¦ãããããã使ãã°è¦ãããç»é¢ã§ãå©ç¨ã§ããè¨å®ãä¸è¦§ããªããæå®ã§ãã¦ä¾¿å©ã ã ã¤ã³ã¹ãã¼ã«èªä½ã.cmdãã¡ã¤ã«ãä»å±ãã¦ããããã
1ç« ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã»ãã¥ãªãã£ã®åºç¤ ã»HTMLã«ããå¶éã¯åé¿å¯è½ã§ãã ã»è£å´ã§ä½ãè¡ããã¦ããã®ã ã»ãã±ããã¹ãããã¡ ã»ãããã·ãã¼ã« ã»ã¦ã§ããã©ã¦ã¶ã®åå¨ãã®ãã®ãå½è£ ã§ãã ã»ãªã¯ã¨ã¹ãã®æ¸ãæãã§HTMLã®å¶éãåé¿ãã ã»JavaScriptã®å¶éãåé¿ãã ã»hiddenãã£ã¼ã«ãã®å 容ãæ¸ãæãã ã»ãã©ã¼ã ã®å¤ã®æ¸ãæãã¨GET/POST ã»Cookieãæ¸ãæãã ã»ãªãã¡ã©ãUser-Agentãæ¸ãæãã ã»ãªã¯ã¨ã¹ãã«å«ã¾ããæ å ±ã¯ä¿¡ç¨ã§ããªã 2ç« ãã¼ã¿å¦çã®ååã¨æé ã»ãã¼ã¿å¦çã®åå - åå1 - åå2 - åå3 - åå4 ã»hiddenãã£ã¼ã«ãã¨Cookieã«é¢ããæé - æé1 - æé2 - ã»ãã¥ãªãã£ã¨åæ ã»ãå ¥åæã«åã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}