ã»ãã¥ãªãã£çã®æãæãããè«å®¢ãé«æ¨æµ©å æ°ãå®ã¯ãã¨ã³ãã¦ã¼ã¶ã¼ã«æ£ããã»ãã¥ãªãã£ç¥èãä¼ããããã«æ¥ã ããã¾ãã¾ãªæ´»åãããã¦ãã¾ããä»åã¯ãã»ãã¥ãªãã£ã®åèæ´»åã«åãçµãã«è³ãã¾ã§ã®çµç·¯ãä¸å¿ã«ã話ã伺ãã¾ãããé«æ¨æµ©å ï¼ èªå® ã®æ¥è¨ãã§ãããªãã¿ã®ã¢ã°ã¬ãã·ããªæç« ããã¯æ³åã§ããªããããªæå¤ãªä¸é¢ã...ï¼ é«æ¨æµ©å ï¼ãããã»ã²ãã¿ã¤ï¼ ç¬ç«è¡æ¿æ³äºº ç£æ¥æè¡ç·åç 究æ æ å ±ã»ãã¥ãªã㣠ç 究ã»ã³ã¿ã¼ 主任ç ç©¶å¡ 1994å¹´ãåå¤å±å·¥æ¥å¤§å¦å¤§å¦é¢å士å¾æ課ç¨ä¿®äºãå士ï¼å·¥å¦ï¼ã å大å©æãçµã¦ã1998å¹´ãéåç£æ¥çå·¥æ¥æè¡é¢é»åæè¡ç· åç 究æã«è»¢ä»»ã2001å¹´ãç¬ç«è¡æ¿æ³äººç£æ¥æè¡ç·åç 究æ ã«æ¹çµã2002å¹´ããåã°ãªããç 究ã»ã³ã¿ã¼ã»ãã¥ã¢ããã° ã©ãã³ã°ãã¼ã é·ã2005å¹´4æããç¾è·ãå°éã¯ä¸¦åå æ£ã³ã³ãã¥ã¼ãã£ã³ã°ãããã°ã©ãã³ã°è¨èªå¦çç³»ãã³ã³ãã¥ã¼ã¿ ã»ãã¥
public suffix ããã¸ã§ã¯ãã§ããã©ãDomain Name System Operations (DNSOP) ã® ML ã«ã¦è°è«ãããã®ããhttp://trombik.mine.nu/~cherry/w/index.php/2008/08/21/1355/links-roundup-400 çµç±ã§ç¥ãã¾ããã IETF | Internet Engineering Task Force ãã®ã¹ã¬ãå°ãç®ãéãããã© public suffix ã«å¯¾ãã¦å¦å®çãªæè¦ã®ããã ããã£ã¨ä¸è¨æ·»ãããã¦ãã ããªã®ã§ãèªåã§èª¿ã¹ãããç¡ã訳ã§ãããhttp://trombik.mine.nu/~cherry/w/index.php/2008/07/10/1306/dnsops-jp-bof ã«ã¦å°ã触ãããã¦ã¾ããã åæ¦ããã«ããpublic suffixãã¿ãå ãã¿ã¯DNSOP
Gervase Markham <[email protected]> Mon, 09 June 2008 10:00 UTC Return-Path: <dnsop-bounces@ietf.org> X-Original-To: dnsop-archive@lists.ietf.org Delivered-To: ietfarch-dnsop-archive@core3.amsl.com Received: from [127.0.0.1] (localhost [127.0.0.1]) by core3.amsl.com (Postfix) with ESMTP id C1D1F3A6970; Mon, 9 Jun 2008 03:00:58 -0700 (PDT) X-Original-To: dns[email protected] Delivered-To: dnsop@core
OpenID Provider ã®ã»ãã¥ãªãã£å¯¾ç (1) - ã¾ã㯠SSL ãå°å ¥ï¼è©±ã¯ããããã - Yet Another Hackadelicã®ç¶ç·¨ã§ãã ã¯ããã« RP ãèªè¨¼ã¢ãµã¼ã·ã§ã³ãªã¯ã¨ã¹ãã§ãã checkid_setup/checkid_immediate ãè¡ãéã«ã¯é常㯠return_to 㨠realm ãæå®ãã¾ãã return_to ã¨ã¯ OP ããèªè¨¼ã¢ãµã¼ã·ã§ã³ã¬ã¹ãã³ã¹ãéæ¥éä¿¡ã§åãåãéã«æ»ã£ã¦æ¥ãURLã®äºãRP ãæå®ãã¦ããã realm ã¨ã¯ return_to ã®ãã¿ã¼ã³ãã¯ã¤ã«ãã«ã¼ãã使ã£ã¦è¡¨ç¾ããã return_to 㨠realm ã®æ¤è¨¼ åºæ¬çã« return_to ã®å 㯠http://openid.art-code.org/handler ã§ããã¨ããåæã§ã便å®ä¸çªå·æ¯ãã¾ããã (1) æå¾ éãã®çµåã real
ãã£ã¨ä¸æºåçµãã£ãã®ã§æ¸ãã¦ã¿ãã OpenID ã§ã®ãããã³ã«ã¡ãã»ã¼ã¸ã§ãèªè¨¼ã¢ãµã¼ã·ã§ã³è¦æ±*1åã³å¿ç*2ã§ã®ã¡ãã»ã¼ã¸ã¯é常ãRP-OP é㧠associate æã«äº¤æãã MAC ãã¼ãæã£ã¦ç½²åãè¡ãçºãæå¾ ããç¸æã¨éä¿¡ãã¦ããéãã¯æ¹ããã¯èµ·ããã«ããã¨èãããã¾ãã ä½ãæè¿è©±é¡ã«åºã¦æ¥ã¦ãã DNS Cache Poisoning ã®ãããªæ»æãåããå ´åãä¸éè æ»æ (man-in-the-middle attack) ãæç«ããå¯è½æ§ãããã¾ãã æ»æææ³ã®ä¾ ä¾ãã°ãRP ã® DNS ãæ±æããã¦ããå ´åãèãã¾ããæ¬æ¥ OP ã§ããã¯ãã®ãã¹ããæªæã®ãã第ä¸è ã®ãµã¼ãã¼ã«å²ãå½ã¦ããã¦ããå ´åããã®ç¬¬ä¸è ã®ãµã¼ãã¼ãä¸ç¶ãè¡ãã°ãDH éµäº¤æãè¡ã£ã¦ãã¾ã£ããç¡æå³ã§ãèªè¨¼ãã¼ã¿ãçã¾ããå¯è½æ§ãããã¾ããã¤ã¾ãã RP ããè¦ã㨠OP ã«è¦ã㦠O
å¾ã«ãå ã«ãã»ãã¥ãªãã£ãã¡ã¤ã³ãã¼ãã®éãã§ã話ããäºãç¡ããã㪠id:ZIGOROu ã§ããä»ã®ã¹ãã¼ã«ãå ¨å¡ã¹ã¼ãã§æ¥ãä¸ãä¸äººç§æã§æ¥ãã¨è¨ãç·å¼µæã®ç¡ã*1ã§ããããå®éã¯æ¿ããç·å¼µãã¦ã¾ããï½ 7/5 Developers DAY â äºä»¶ã¯ç¾å ´ã§èµ·ãã£ã¦ããâ¦â¦ã»ãã¥ãªãã£ã©ã¤ããµã¤ã¯ã«ã¨ãã«ãã©ã¯ãã£ã¹ | Web Application Security Forum - WASForum ã«ã¦è¬æ¼ããã¹ã©ã¤ããå ¬éãã¾ãã The Security of OpenID Authentication 2.0 (PDF ãã¡ã¤ã«) 話ã®å 容ã§ããã OpenID ãããã³ã«ã®æ¦è¦ OpenID ã®ã»ãã¥ãªã㣠discovery association RP ã®è©ç§°ã¨ return_to, realm nonce ã®ç¢ºèª Identifier åå©ç¨åé¡ Reputatio
Web Appplication Security Forum ã¸ããããã æ¬å¹´ã®ã«ã³ãã¡ã¬ã³ã¹ã¯ã2DAYSæ§æã§ããDAY1ã¯ã7æ4æ¥(é)ã«ä¸¸ã®å ã³ã³ãã¡ã¬ã³ã¹ã¹ã¯ã¨ã¢ã¨ã ãã©ã¹ï¼Fã«ã¦ãã¾ãDAY2ã¯ï¼æï¼æ¥(å)ã¯ååãããæ±é座ãæäºéä¿¡ãã¼ã«ï¼Fã«ã¦éå¬ããã¾ãã DAY1 ã¯ãããã¡ã¯ãCIO, CTOã®çãã¾ã¸ãä¼æ¥ã®ITã·ã¹ãã ã®è²¬ä»»ããã£ã¦ããããä¸ãWEBãµã¤ãã®ã»ãã¥ãªãã£ã¨ITã¬ããã³ã¹ã®ããæ¹ã«ã¤ãã¦èãã¾ããä¸å ´ä¼æ¥ã®CIOã®ç¾å ´ã§ã®ä½é¨ããããCIOã®ããã·ã§ã³ãåæ ¼ãã«ã¤ãã¦ä¼ºãã¾ãã ã¾ããããæè¿ã®äºä¾ãå«ããã»ãã¥ãªãã£è¢«å®³ã«å¯¾å¦ ãã¦ããããä¼æ¥ããããã¤ããªããWAS Forumãªãã§ã¯ã®ãã¿ãã¼ãªãã®å 容ããæè¨ãå¼ãåºãã¦åãã¾ãã DAY2ã¯ãç¾å ´ã®ã¦ã§ãæ§ç¯é¢ä¿ã®çæ§ã¸ãããã¾ã§ããã¤ãã»ãã·ã§ã³ã¨ããå½¢ã§å®æ½ãã¦ãã¾ããããã¢ãã
(Summary in English of this entry) Utilizing Yahoo! Site Explorer, it is possible for third parties to prevent your site by being displayed in search results. The reason is that the meta tag used for administrative rights confirmation is accepted even in the the page body even if it is html escaped. 3rd parties can gain control of your site simply by adding a comment to one of your pages. ããã«ã¡ã¯ããã«
ååã¯Consumerãµã¤ããå®éã«ä½ãéã®ããã°ã©ãã³ã°ã«é¢ãã¦ã話ããã¾ããããä»åã¯OpenIDã«é¢ããã»ãã¥ãªãã£ã«ã¤ãã¦èãã¦ã¿ã¾ãã ä»ååãä¸ãããããã¯ã¨ãã¦ã¯ã ãªã©ã段éçã«èª¬æãã¦ããã¾ããIdPã®æ§ç¯æ¹æ³ãç¥ãåã«OpenIDãããã³ã«ã®ã»ãã¥ãªãã£ã«é¢ãã¦çç¥ãã¦ããã¾ãããã OpenIDãããã³ã«ã«ãããéä¿¡çµè·¯ã®ã»ãã¥ãªã㣠ããã¾ã§è©³ç´°ã«è§£èª¬ãã¦ãã¾ããã§ãããOpenIDèªè¨¼ãããã³ã«ã®ãã§ã¤ãºã«ããã¦ãã©ã®ããã«ã»ãã¥ãªãã£ä¸ã®å®å ¨æ§ãæ ä¿ãã¦ãããã解説ãã¾ãããã ã¾ãã¯associateã¢ã¼ããæ£å¸¸ã«å®è¡ããSmartã¢ã¼ãã®å ´åã§ãã Consumerã¯ã¦ã¼ã¶ã¼ããã®Claimed Identifierãåãåãã¨ãassociateã®ãã£ãã·ã¥ãåå¨ããªãå ´åã¯æ°è¦ã«IdPã«å¯¾ãã¦associateã¢ã¼ãã®ãªã¯ã¨ã¹ããè¡ãã¾ãã第3åã§ãas
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}