[NEW] 2014/09/30: ã¢ãã©ã¤ã¢ã³ã¹ã®å¯¾å¿ç¶æ³ã¾ã¨ããéææ´æ°ä¸ CVE-2014-6271åã³CVE-2014-7169ãã(Bashèå¼±æ§)ã ä¸éã§ã¯ãå¤é¨å ¬éãµã¼ãã¼(ç¹ã«Webãµã¼ãã¼)ã¸ã®å¯¾å¦ãçã ã¨é²ãããã¦ãã¾ããWebãµã¼ãã¼ã ãã§ãªããã¡ã¼ã«ãµã¼ãã¼ã¸ã®æ»æãã¿ã¼ã³ãæ©æã«è¦ä»ãã£ã¦ãã¾ããå¤é¨å ¬éãµã¼ãã¼ã«å¯¾ããç·åçãªç¹æ¤ãè¿ããã¡ã«é²ãã§ãããã®ã¨æããã¾ãã bash Shellshock through MAIL .forward / qmail-alias piping (ML program etc.) CVE-2014-6271 http://t.co/QPbSE8dppM http://t.co/AFuHudkCdh September 26, 2014ããããä¸è¬çãªãµã¼ãã¼é¡ã ãã§ãªã主ã«ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®å é¨ã«è¨ç½®ããã¦ããã¢ãã©ã¤
ã¡ãã£ã¨ããã³ã¼ãã®æ¸ãæ¹ã§ããã©ã¼ãã³ã¹ãå¤ãããã¨ãããã¾ãããªã¼ãããªãã£ãéè¦ããåãããããã°å°æå ã®ãã¯ããã¯ã«æ ãããç¥ããªãã®ã§ããããªã¼ãããªãã£ãç¶æããªããã¡ããã¨ããããã©ã¼ãã³ã¹ãåºãããã«ãããã¯ããã¯ãç¥ããã¨ã¯å¤§äºãªãã¨ã ã¨æãã®ã§ãã çµæ§éãããã§ããªã¼ ã¨ããããã§ããããªãã¯ããã¯ãã¾ã¨ããã¹ã©ã¤ããWriting Fast Rubyãè¦ã¦ãã¦åèã«ãªã£ãã®ã§ã¡ã¢ã ãã¨ãã°å¼æ°ã«&blockãã¨ã£ã¦callããããããyieldã®æ¹ã5åéããã¨ãã def slow(&block) block.call end def fast yield end mapã«ãããã¯ã渡ãããããã·ã³ãã«ã渡ãæ¹ã20%éããã¨ã (1..100).map {|i| i.to_s} (1..100).map(&:to_s) mapãã¦ããflattenãå¼ã³åºãã
Apple ã® iPhone 5s ã§ãAndroid Lãã® Developer ãã¬ãã¥ã¼çãåä½ããã¦ããæ åã Facebook ã§å ¬éããã¾ãããåç»ã®æ稿主㯠SetCPU ã¢ããªã§ããªãã¿ã® Mike Huang æ°ã彼㯠iPhone 5s ããã端æ«ã§ Android L ã®ãã¼ã ç»é¢ã®ããã«ãåãæ¿ããããAOSP ãã¼ã¹ã®WEBãã©ã¦ã¶ãæä½ãã¦ããæ§åãåç»ã«åãã¦ã·ã§ã¢ãã¦ãã¾ããåç»ã®èª¬æä¸ã«å½¼ã¯ç¬ã£ãããã¦ããã®ã§ãã³ã¡ã³ãã§ã¯ã¸ã§ã¼ã¯ã§ã¯ãªãããVNCãªã©ã®ãªã¢ã¼ããã¹ã¯ãããç³»ã¢ããªã使ã£ã¦ Android 端æ«ã®ç»é¢ã表示ããã¦ããã®ã§ã¯ãªããã¨ææãããä¸ãå½¼ã¯ã¸ã§ã¼ã¯ãããªããããã¯ãæåããã¨è¨ã£ã¦ãã¾ããSource : Facebook âï¼juggly.cnï¼è¨äºé¢é£ãªã³ã¯ Xperia Z3ãå ¬å¼ã«ã¯ãµãã¼ãããã¦ããªãã¦ããã¼ããã¼ãã¼ã®
9æ23æ¥ãåèå¸ã®å¹å¼µã¡ãã»ã§ãçµ±ä¸æä¼ï¼çµ±ä¸åä¼ï¼ä¸»å¬ã®ã¤ãã³ããã°ãã¼ãã«ã»ã¦ã¼ã¹ã»ãã§ã¹ãã£ãã«2014ãï¼GYF2014ï¼ãéå¬ããã¾ããããä¸çè²¢ç®ãç®æãéå¹´ãã¡ã®ç¥å ¸ãã¨éæã£ã¦å®æ½ãããã®ã§ãç´1ä¸äººãåå ï¼ä¸»å¬è çºè¡¨ï¼ãå±å¤ã§ã¯åºåºãã¹ãã¼ã¸ãéãããå±å ãã¼ã«ã§ã¯æç¥ã»æé®®æã®5女ã»æåé²æ°ãªã©æå£é¢ä¿è ãè¬æ¼çãè¡ãã¾ãããã¾ãèªæ°å ã次ä¸ä»£ã®å ã®å½ä¼è°å¡ãç¥è¾ãè¿°ã¹ãèªæ°å ã®ç¾è·ã»å è·ã®å½ä¼è°å¡ããã®ç¥é»ãèªã¿ä¸ãããã¾ããã â ã¡ãã³ã¼ã«ãå¹å¼µã¡ãã»ã®ã´ãç®±ãå¶å§ å±å ã¤ãã³ãã«å ç«ã£ã¦ååä¸ããè¡ãããå±å¤ä¼ç»ãããããå°çæãã§ã¯ãæ¥æ¬ãå«ãè¨35ã®å½ãå°åã§ã®çµ±ä¸æä¼é¢é£å£ä½ã»äººç©ã®æ´»åããã®å½ã®æåãç´¹ä»ãããã¼ã¹ãåºåºãããã¹ãã¼ã¸ã§ã¯åå½ã®é³æ¥½ã大éè¸ãªã©ãæ«é²ããã¾ããã ãã¼ã¹ãã³ãã¼ã1ãã¯éå½ããã®é£ã«ã¯çµ±ä¸æä¼ç³»ã®éå½ä¼æ¥ãä¸åãã®éº¦ã³ã¼ã©
2. èªå·±ç´¹ä» â¢â¯ äºè¹ãæ´è¼ï¼@goyokiï¼ ââ¯å»çæ©å¨ãèªåè»ã®çµã¿è¾¼ã¿éçºã»ãã¹ã â¢â¯ éçºå±7å²ããã¹ãå±3å² ââ¯æè¿ã¯ã³ã³ãµã«ãæè¡æ¯æ´ã«å¾äº ââ¯ç¤¾å¤ã§å種è¬æ¼ãå·çæ´»åã«å¾äº â¢â¯ ãAndroidã¢ããªãã¹ãææ³ãããã¹ãèªååæ¨æºã¬ã¤ãï¼ç¿»è¨³ä¸ï¼ã ããã¹ãé§åéçºï¼æ¯ãèãé§åéçºãå§ããããã®åºç¤ç¥èãç â¢â¯ ãã¹ãèªååç 究ä¼ã³ããã¿ãConcolic  Testingç 究ä¼ãªã© 2
2014-09-27: 該å½ãµã¤ãä¸ã«XSSããªãã¦ãæ»æå¯è½ã§ãããã¨ã id:mayuki ããã®ã³ã¡ã³ãã§å¤æãã¾ããã®ã§å ¨é¢çã«æ¸ãç´ãã¾ããããã¡ã¤ã¢ã¦ã©ã¼ã«å ã§ãã£ã¦ãæ»æè ã¯ãã¡ã¤ã¢ã¦ã©ã¼ã«å ã®Shellshockæ»æãéç¨ããCGIã®URLãããã£ã¦ããã ãã§æ»æå¯è½ã§ãã®ã§æ©æ¥ã«å¯¾å¿ãå¿ è¦ã§ãï¼ä¼ç¤¾ã®ããã°ã«ãæ¸ãã¦ã¾ããããã¡ã¤ã¢ã¦ã©ã¼ã«å ã«ç½®ãã¦ãããµã¼ãã§æ»æè ãç´æ¥ã¢ã¯ã»ã¹ã§ããªãããã¨ãã£ã¦bashã®æ´æ°ãæ ã£ã¦ããã¨ãæ¡ä»¶ã«ãã£ã¦ã¯æ»æãå¯è½ã¨ãªãã¾ãã æ¡ä»¶ã¨ãã¦ã¯ã ãã®ãµã¼ãã«ã¯ã·ã§ã«ãçµç±ãã¦å¤é¨ã³ãã³ããèµ·åããCGIçãåãã¦ãã(é常ã®Shellshockã®æ»æã¨åæ¡ä»¶) æ»æè ããã®URLãäºåã«ç¥ã£ã¦ãã(ãããã¯æ¨æ¸¬å¯è½) ã¨ãªãã¾ãã æ»æè ã¯ãã¦ã¼ã¶ã¼ãç½ URLã¸èªå°ãã以ä¸ã®ãããªJavaScriptãç½ ãã¼ã¸ä¸ã§åãããæ»æ対象ã®W
ä»åã®è»¢è·ã«ããã£ã¦ãåæ¹é¢ããããªãã§ã²ã¼ã æ¥çã«ãããªãã®ï¼ãã¨ä½åº¦ãè¨ãããã®ã§ãæ¸ãã¦ããã åã®ãã£ãªã¢ã¯ã½ã¼ã·ã£ã«ã²ã¼ã æ¥çããå§ã¾ã£ã¦ãæè²ã®ä¼ç¤¾ã«ãã£ã¦ã次ã¯xxxã ã転è·å ã«é¢ãã¦ã¯å¾æ¥ã åã¯ããããã¹ã¼ãã¼ãã¡ãã³ã³æ代ã«ã¹ã¯ã¨ãé»éæã®æ´ç¤¼ãåããå¤ãæ°è³ªã®ã²ã¼ãã¼ã§ãã½ã¼ã·ã£ã«ã²ã¼ã ãä¸å楽ãããªã人éã§ãã½ã¼ã·ã£ã«ã²ã¼ã ã«éçºã¨ãã¦é¢ãã£ã人éã§ãããããã¤ã¢ã¹ãæãã£ã¦ããã®ã¯èªããã å¤å·£ãã©ãããã£ã¦åé¡ã§ã¯ãªãã¦ãæ¥çå ¨ä½ã®åé¡ãªã®ã§ããããã¸ãã¯èª¤è§£ããªãããã«ã ã½ã¼ã·ã£ã«ã²ã¼ã æ¥ç ä»ã®ã½ã¼ã·ã£ã«ã²ã¼ã æ¥çã®éçºç¾å ´ã¯ãéçºã®ç¾å ´ããé¢ç½ãã²ã¼ã ãä½ãããã¨ããã¢ããã¼ã·ã§ã³ã«ã¯ãªãã«ããã æè¦ã¨ãã¦ãã½ã¼ã·ã£ã«ã²ã¼ã ã£ã¦ã®ã¯ã課éãããå ´ããä½ããã¨ã§ãã£ã¦ãé¢ç½ãã²ã¼ã ãä½ããã¨ã¯ãã¾ããã©ã¼ã«ã¹ãããªãã ãããè¨ãã°ã³ã³ã·ã¥ã¼ãã ã£ã¦å£²ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}