Various web applications often need to work with strings of HTML on the client-side. This might take place, for instance, as part of a client-side templating solution or perhaps come to play through the process of rendering user-generated content. The key problem is that it remains difficult to perform these tasks in a safe way. This is specifically the case because the naive approach of joining s
ãªãã¡ã©ã使ã£ãXSSã®å°ãã¿ã§ãã ä»ååãä¸ããã®ã¯ãã¿ã¼ã²ããèªèº«ããç´°å·¥ãããã¼ã¸ãçµç±ãããã¨ã§ã¤ãããããªãã¡ã©ã«ãã£ã¦æ»æãåããã±ã¼ã¹ã§ãããã®ãããªæ»æã®å ´åã¯ãç¾å®ã«çµç±å¯è½ãªãã¼ã¸ããã§ããæ»ææååãéããããã¨ãã§ãã¾ããã ä¾ãã°ã以ä¸ã®ããã«ãdocument.referrerããã®ã¾ã¾document.write()ãã¦ãããã¼ã¸ãããã¨ãã¾ãã http://vulnerabledoma.in/location/ ãªãã¡ã©ãæ¸ãåºãã¦ããé¨åã§XSSã§ããã§ããããã IEã§ã¯åç´ã§ãã IEã¯URLã®ã¯ã¨ãªã«ãã¨ã³ã³ã¼ãããã«ã"<>ããªã©ãå«ãããã¨ãã§ããã®ã§ãããããå«ãURLããããªãã¡ã©ãæ¸ãåºãã¦ãããã¼ã¸ã¸é·ç§»ãããã°ãXSSãèµ·ãã¾ãã http://l0.cm/xss_referrer.html?<script>alert(1)</sc
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}