ã»ãã¥ãªãã£ã»ãã£ã³ãå ¨å½å¤§ä¼2016 éä¸è¬ç¾©
ã»ãã¥ãªãã£ã»ãã£ã³ãå ¨å½å¤§ä¼2016 éä¸è¬ç¾©
[åèæ å ±] ãæ°¸ä¹ ä¿åçãOAuth 2.0 / OpenID Connect ã·ã¼ã±ã³ã¹ã¾ã¨ã URLï¼https://qiita.com/kura_lab/items/812a62b5aa3427bdb49d ã¿ã¤ãã«ï¼ ãOpenID Connect å ¥é ãã³ã³ã·ã¥ã¼ãã¼é åã«ãããIDé£æºã®ãã¬ã³ããã æ¦è¦ï¼ ã³ã³ã·ã¥ã¼ãã¼é åã«ãããIDé£æºã®ãã¬ã³ãã§ããOpenID Connectã®æ¦è¦ã¨ä»æ§ã®ãã¤ã³ãã«ã¤ãã¦ãç´¹ä»ãã¾ãã OpenID TechNight Vol.13 - IDé£æºå ¥é Aug. 26, 2015 URLï¼https://openid.doorkeeper.jp/events/29487Read less
ã»ãã¥ãªãã£ã»ãã£ã³ãå ¨å½å¤§ä¼2015ã®è¬ç¾©ããã°ãã³ãã£ã³ã°å ¥éãã§ä½¿ç¨ããã¹ã©ã¤ãã§ããRead less
1. SSL/TLSã®åºç¤ã¨ææ°åå ã»ãã¥ãªãã£ãã£ã³ã 2015 2015å¹´8æ12æ¥ IIJ 大津 ç¹æ¨¹ æ´æ°çè³æã®ç½®å ´ http://goo.gl/cX1M17 Github Repo: https://goo.gl/vRLzrj 2. èªå·±ç´¹ä» ⢠大津 ç¹æ¨¹ â¢ æ ªå¼ä¼ç¤¾ ã¤ã³ã¿ã¼ãããã¤ãã·ã¢ãã£ã ⢠ãããã¯ãæ¬é¨ ã¢ããªã±ã¼ã·ã§ã³éçºé¨ãµã¼ãã¹éçº2課 ⢠NodeJS Technical Committee ã¡ã³ã㼠⢠(主ã«TLS/CRYPTO/OpenSSLãã¤ã³ãã£ã³ã°ãæ å½ï¼ ⢠IETF httpbis WG 㧠HTTP/2ç¸äºæ¥ç¶è©¦é¨çä»æ§çå®ã«åç»ã ⢠ããã°ï¼ http://d.hatena.ne.jp/jovi0608/ 3. ã¯ãã㫠⢠TLS(Transport Layer Security)ã®ä»çµã¿ã«ã¤ãã¦å¦ãã§ããã ã ã¾ãã â¢
2. ãã®è¬ç¾©ã®ç®ç ⢠ã¯ã©ã¦ãæ代ã®Webã·ã¹ãã ã«ã¤ã㦠⢠ãµã¼ãè¨è¨ãæ§ç¯ãéç¨æè¡ã®åºç¤ ⢠ãµã¼ãã¹ã®ç¡åæ¢ã¨ã¹ã±ã¼ã©ããªãã£ãå®ç¾ããè¨è¨ ⢠æ å ±ã»ãã¥ãªãã£ã¨ãã¦å¿ è¦ãªæ½ç ⢠ID管çã¨ç£æ» ⢠æ©å¯æ å ±ã®ä¿å 2 3. èªå·±ç´¹ä» ⢠仲山æå® â¢ ããããã»ãã¥ãªãã£ã¨ã³ã¸ãã¢â¦â¦ã§ã¯ããã¾ãã ⢠ç§èåçã¾ã大æçºè²ã¡ã® æã£ã¦è¸ããæ±æ¸ã£åã¤ã³ãã©ã¨ã³ã¸ãã¢ â¢ æ ªå¼ä¼ç¤¾ãµã¤ãã¼ã¨ã¼ã¸ã§ã³ã DCã½ãªã¥ã¼ã·ã§ã³ ã¯ã©ã¦ãã¨ã³ã¸ã㢠3
Githubãå社ãµã¼ãã¹ã«å¯¾ãã¦DoSæ»æãè¡ããã¦ãããã¨ãçºè¡¨ãã¾ãããä¸é£ã®DoSæ»æã¯Greatfire.orgã«å¯¾ãã¦è¡ããã¦ãããã®ã¨èããããããã§ã¯GreatFire.orgã«é¢ä¿ããDoSæ»æã®æ å ±ãã¾ã¨ãã¾ãã å ¬å¼çºè¡¨ GreatFire.org 2015å¹´3æ19æ¥ We are under attack 2015å¹´3æ25æ¥ (PDF) Using Baidu ç¾åº¦ to steer millions of computers to launch denial of service attacks Github å ¬å¼Blog 2015å¹´3æ28æ¥ Large Scale DDoS Attack on github.com · GitHub Github å ¬å¼Twitter The attack has ramped up again, and we're evo
å®ã¯æ¨å¹´ã®å¤ããµã¤ãã¦ãºã©ãã¦ã¼ã¹ã¨ããå¶åº¦ãå©ç¨ããã¦ããã ãã¦ã3é±éç¨åº¦ãµã¤ãã¦ãºã©ãã®ãªãã£ã¹ã«åºç¤¾ãã¦ãã¾ããã ãµã¤ãã¦ãºã»ã©ãï¼äººæåéï¼ãµã¤ãã¦ãºã»ã©ãã¦ã¼ã¹ http://labs.cybozu.co.jp/recruit/youth.html ä½ããã¦ãããã¨ããã¾ãã¨ã@herumi ããã @takesako ããã«ãæå°é ããªãããã¢ã»ã³ããªè¨èªããã£ã¨èªãã§ãã¾ããã XSSãã¯ããã¨ããWebã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã¯ãããªãã«ç¥ã£ã¦ããã¤ããã§ããããããã¡ãªã¼ãã¼ããã¼ãã¯ããã¨ããã¡ã¢ãªé¢é£ã®ãã°ã¯å ¨ç¶ç解ãã¦ãã¾ããã§ããã ããã¾ã§ããã¢ããªã±ã¼ã·ã§ã³ãå¶ç¶ã¯ã©ãã·ã¥ãããã³ããããã£ãæ¹é¢ã¸ã®é¢å¿ãã§ã¦ãã¦ãã¢ã»ã³ããªãèªãã°ä½ããããã®ããªãã¨æã£ã¦ãèªãã§ã¯ã¿ããã©ãç¡æ æ²ãªãã¤ããªã®ç¾ åã«å§åãããã¨ãããã¨ãç¹°ãè¿ãã¦ãã¾ããã ãã ãã¢ã©
Google ã®ã¦ã§ããã°å ¬éãã¼ã«ã使ã£ã¦ãããã¹ããåçãåç»ãå ±æã§ãã¾ãã
7. é常ã®Webãµã¼ãã¨ã®éä¿¡ <html> <body> æ°å:vultest<BR> ã¡ã¼ã«ã¢ãã¬ã¹:vulte[email protected]<BR> æ§å¥:ç·<BR> <form action=âregisterâ method=âPOSTâ> ï¼ä»¥ä¸ç¥ï¼ </html> POST /confirm.php HTTP/1.1 Host: example.jp ï¼ä»¥ä¸ç¥ï¼ name=vultest&mail=vultest%40example.jp&gender=1 HTTP Response HTTP Request 8. å¤ãå¤æ´ããå ´åã®å¿ççµæãç¢ºèª POST /confirm.php HTTP/1.1 Host: example.jp ï¼ä»¥ä¸ç¥ï¼ name=vultest&mail=vultest%40example.jpâ>xss&gender=1 <html> <body>
æ¬è¬æ¼ã§ã¯ãshellshock(bashèå¼±æ§)ã¸ã®å¯¾å¦äºä¾ããã¨ã«ãçµç¹ã«ãããã»ãã¥ãªãã£äºæ çºçãªã¹ã¯ã¨ãã®å¯¾å¦è½åãè©ä¾¡ããæ¹æ³ãè¿°ã¹ã¾ããShellShockã¯ããµã¼ãããçµã¿è¾¼ã¿æ©å¨ã¾ã§å¤æ°ã®ã·ã¹ãã ã«å½±é¿ãä¸ãã¾ãããã¾ãããã®èå¼±æ§ã¯ãè¤æ°ã®èå¼±æ§ãéãªã£ããã®ã§ããããã®å¯¾å¦æ¹æ³ãå½±é¿ç¯å²ãäºè»¢ä¸è»¢ãããã®ã§ããããã®ãããã·ã¹ãã 管çè ã¯ãææ°ã®æ å ±ãææ¡ã«å ãã¦ãèªèº«ã®ã·ã¹ãã ãæ£ç¢ºã«ææ¡ãããããé©ç¨ã¾ã§ã®ç©ºç½æéã«ããããªã¹ã¯è©ä¾¡ãªã©ãé«åº¦ãã¤é©åãªå¯¾å¦ãæ±ãããã¾ãããæ¬çºè¡¨ã§ã¯ããã®å¯¾å¦äºä¾ã®ç´¹ä»ã¨ããã®åé¡ç¹ã»æ¹åç¹ã説æããçµç¹ã¨ãã¦ã®äºæ çºçãªã¹ã¯ã対å¦è½åãææ¡ããæ¹æ³ã説æãã¾ããRead less
Running the 'less' Linux command on files downloaded from the Internet is dangerous Using the âlessâ Linux command to view the contents of files downloaded from the Internet is a dangerous operation that can lead to remote code execution, according to a security researcher. At first glance, less appears to be a harmless command that outputs a fileâs content to a terminal window and allows the user
ç±³Symantecã¯11æ23æ¥ã極ãã¦é«åº¦ãªæ©è½ãæè¼ããã¹ãã¤ãã¼ã«ã®ãReginãããæ¿åºãå人ãªã©ã«å¯¾ããã¹ãã¤æ´»åã«ä½¿ããã¦ããã®ãçºè¦ããã¨ä¼ããã å社ã«ããã¨ãReginã¯ããã¯ãã¢æ©è½ãåããããã¤ã®æ¨é¦¬ã§ãæ¨çã«å¿ãã¦å¹ åºãã«ã¹ã¿ãã¤ãºã§ããæ©è½ããã¤ããããã»ã©ã®ãã«ã¦ã§ã¢ãéçºããã«ã¯ç¸å½ãªæéããªã½ã¼ã¹ãè¦ããã¯ãã ãã¨å社ã¯åæãããé«åº¦ãªæ©è½ããªã½ã¼ã¹ã®ã¬ãã«ããå¤æããã¨ãå½å®¶ã«ãã£ã¦ä½¿ããã¦ãã主è¦ãµã¤ãã¼ã¹ãã¤ãã¼ã«ã®1ã¤ã§ãããã¨ãããããããã¨ã®è¦æ¹ã示ãã æ»æã¯5段éã§ä»æããããå段éã«æ¤åºãå ããããã®é«åº¦ãªã¹ãã«ã¹æ©è½ãæå·åæ©è½ãå®è£ ããã¦ãããã¢ã¸ã¥ã¼ã«å¼ã®ã¢ããã¼ãã¯ãã«ã¦ã§ã¢ãFlamerãã使ã£ã¦ããæå£ã§ãå¤æ®µéæ»æã®ææ³ã¯å½å®¶ã®é¢ä¸ãææããããDuquãããStuxnetãã«ä¼¼ã¦ããã¨ããã Reginã¯å°ãªãã¨ã2008å¹´
æ´æ°æ å ± ããå¯ãããã質åã¸ã®ãªã³ã¯ã追å ãã¾ããã ã客æ§ãããåãåãããããã ãã¾ããã®ã§ãå¼ç¤¾ã§æ¤è¨¼ããç°å¢æ å ±ã追è¨ãã¾ãããæ¬æä¸ãï¼2014/04/25追è¨ï¼ãã¨ããé¨åãã覧ãã ããã æ¨å¥¨ãã対çã«å«ã¾ããæ£è¦è¡¨ç¾ã®è¨è¼ãä¿®æ£ãã¾ãããæ¬æä¸ãï¼2014/04/25ä¿®æ£ï¼ãã¨ããé¨åãã覧ãã ããã ä»åã®èå¼±æ§ãæªç¨ããæ»æãæ¤ç¥ãã¾ããã ããå¯ãããã質åã追å ãã¾ããã Struts 2ã®èå¼±æ§ãä¿®æ£ãããã¼ã¸ã§ã³2.3.16.2ããªãªã¼ã¹ããããã¨ã追è¨ãã¾ããã æ°ãã«å²ãå½ã¦ãããå ±éèå¼±æ§èå¥åCVEã追è¨ãã¾ããã æ ªå¼ä¼ç¤¾ã©ã㯠ãµã¤ãã¼ã»ã°ãªããç 究æã¯ãApache Struts 2 ã«åå¨ããã¨ãããããªã¢ã¼ãã®ç¬¬ä¸è ã«ããä»»æã®ã³ã¼ãå®è¡ã許ãèå¼±æ§(CVE-2014-0094)ã¨åæ§ã®åé¡ãApache Struts 1 ã«ããã¦ãåå¨ãã¦
Search Engine for the Internet of Everything Shodan is the world's first search engine for Internet-connected devices. Discover how Internet intelligence can help you make better decisions. Sign Up Now Beyondthe Web Websites are just one part of the Internet. Use Shodan to discover everything from power plants, mobile phones, refrigerators and Minecraft servers. MonitorNetwork Exposure Keep track
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}