English version: http://mksben.l0.cm/2016/07/xxn-caret.html ------------------------------------------------------- 以åãCODE BLUEã§XSSãã£ã«ã¿ã¼ãå©ç¨ããXSSã®åé¡ã«ã¤ãã¦çºè¡¨ãã¾ããããåæ§ã®åé¡ã6æã®ãããã§CVE-2016-3212ã¨ãã¦ä¿®æ£ããã¾ããããã®è¨äºã§ã¯è©³ç´°ãç´¹ä»ãã¾ãã 以åå ¬éããè³æã«ãæ¸ããããã«ã以åã¾ã§ã¯ãXSSãã£ã«ã¿ã¼ã®é®æè¦åãæ»æã¨ã¯ç¡é¢ä¿ã®æèã«é©ç¨ããã.ã#ã«ç½®æããããã¨ã§ã<script>ã®srcå¤ã<link>ã®hrefå¤ãå¤æ´ãããã¨ã«ããæ»æãå¯è½ã§ããã 2015å¹´12æãMicrosoftã¯ãã®åé¡ã«å¯¾å¿ããããã«ããã®é®æè¦åã®ã¿ã#ã®ä»£ããã«^ã«ç½®æããããåä½ãå¤æ´ãã¾ãããããã«ãã確ãã«ãä¸
è£è¶³ ãã®è¨äºã¯æ§å¾³ä¸¸æµ©ã®æ¥è¨ããã®è»¢è¼ã§ãï¼å URLãã¢ã¼ã«ã¤ããã¯ã¦ãªããã¯ãã¼ã¯1ãã¯ã¦ãªããã¯ãã¼ã¯2ï¼ã åå¿ã®ãã転è¼ãããã¾ããããã®è¨äºã¯2007å¹´12æ6æ¥ã«å ¬éããããã®ã§ãå½æã®å¾³ä¸¸ã®èãã示ããã®ããåºæ¬çã«å 容ãå¤æ´ããã«ãã®ã¾ã¾è»¢è¼ãããã®ã§ãã è£è¶³çµãã æè¿ãç»åãã¡ã¤ã«ãç¨ããã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ã注ç®ããã¦ãããæ¬ç¨¿ã§ã¯ãç»åãæªç¨ããXSSã«ã¤ãã¦èª¬æããå¾ã対çæ¹æ³ã«ã¤ãã¦è§£èª¬ããã ç»åã«ããXSSã¨ã¯ã©ã®ãããªãã®ã Internet Explorer(IE)ã®ç¹æ§ã¨ãã¦ãã³ã³ãã³ãã®ç¨®é¡ãå¤å¥ããéã«ãã¬ã¹ãã³ã¹ãããå ã®Content-Typeã ãã§ãªããã³ã³ãã³ãã®å 容ãå¤æåºæºã«ãã¦ããããã®ãããContent-Typeãä¾ãã°image/gif(GIFç»å)ã¨ãªã£ã¦ãã¦ããä¸èº«ãHTMLã§ããã°HTMLã¨è§£éãã¦è¡¨ç¤ºããã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}