CSRF, HTML Form Protocol Attack, Cross-protocol scripting attackã«ã¤ãã¦

ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼ ä»æ¥ã¯CSRFèå¼±æ§ã®ã¡ãã£ã¨ãã話ã§ãï¼ ãã®CSRFã£ã¦ãªã«ãã£ã¦ããã¨ã ãµã¼ãã¼ã¸ã®ãªã¯ã¨ã¹ããã誰ãã«åæã«éããããã£ã¦ããã»ãã¥ãªãã£ããã¿ã®æ»æææ³ã®ã²ã¨ã¤ã ããããããä¾ã ã¨ã HTMLã®ç»åã¿ã°ã以ä¸ã®ããã«ãããã¼ã¸ã誰ãã«æããã <img src="ä½ã SNSã®è¶³è·¡.php" width="1" height="1"> ããããã¨ããã®ãã¼ã¸ããè¦ã人ããä½ã SNSã®è¶³è·¡.phpã«ã¢ã¯ã»ã¹ãããã¨ã«ãªãã â»è©³ããã¯ãã¡ãã®ãã³ã¬ã§ â ï¼»ã¯ã¾ã¡ã¡ããã®ã»ãã¥ãªãã£è¬åº§ï¼½ãããããã®èå¼±ãªã¨ããâ¦ï¼ ï¼ ç¬¬2å ãã¼ãã¼ãµã£ã¦ä½ã§ããï¼ CSRFã£ã¦ãããªé¢¨ã«ã ããã°ã¤ã³æ¸ã¿ã®äººã«ä½ãæä½ããããã£ã¦ã¤ã¡ã¼ã¸ãå¼·ãã¦ã 対çããå´ãã¾ãããæ¢ã«ãã°ã¤ã³æ¸ã¿ã®äººãå®ãããããªèããå¼·ããã ããã ä¾ãã°ãåæã«æ¥è¨ã«æ稿ãããªãããã«å¯¾
èè : éåº <anvil@jumperz.net> http://www.jumperz.net/ â ã¯ããã« ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³éçºè ã®ç«å ´ããè¦ãCSRF対çã«ã¤ãã¦ããã¾ãã¾ãªæ å ±ãå ¥ãä¹±ãã¦ãããçè ã2006å¹´3æã®æç¹ã«ããã¦å½å ã®ã¦ã§ããµ ã¤ããã³ã³ãã¥ã¼ã¿æ¸ç±ã»éèªãªã©ã§CSRF対çã«ã¤ãã¦æ¸ããã¦ããè¨äºã調ã¹ãçµæããã©ããã¹ããã¨ã«ããã®ã»ã¨ãã©ã誤ããå«ãã§ããããç¾å®ç ã«ã¯ä½¿ç¨ã§ããªãæ¹æ³ãç´¹ä»ããããã¦ãããããã§æ¬ç¨¿ã§ã¯ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³éçºè ã«ã¨ã£ã¦ã®æ¬å½ã«æ£ããCSRF対çã«ã¤ãã¦ã¾ã¨ãããã¨ã¨ã ããã¾ããæ¡ç¨ãã¹ãã§ãªãCSRF対çã¨ãã®çç±ãåããã¦ç´¹ä»ããã â ããããæ©è½ãã¿ã¼ã²ããã¨ãªããã ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã®æã¤å ¨ã¦ã®æ©è½ãCSRFæ»æã®å¯¾è±¡ã¨ãªããããã¾ããã®ãã¨ãèªèãã¦ããå¿ è¦ãããã Amaz
ãç¥ãã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}