tl;dr Many SQL query builders written in Perl do not provide mitigation against JSON SQL injection vulnerability. Developers should not forget to either type-check the input values taken from JSON (or any other hierarchical data structure) before passing them to the query builders, or should better consider migrating to query builders that provide API immune to such vulnerability. Note: åé¡ã®çºè¦è ã«ããæ¥
ã¾ããã ä»åã¯Macã«Goãã¤ã³ã¹ãã¼ã«ãã¦ããpecoãã¨ããGoã®ããã±ã¼ã¸ãã¤ã³ã¹ãã¼ã«ãã¦ãzshã®ãã¹ããªãããæãã«ä½¿ã£ã¦ã¿ããã£ã¨æãã¾ãã ãããªãããã®ãã¨ãã§ããããã«ãªãã¾ãã éçºç°å¢ MacOSX go 1.2.1 darwin/amd64 peco: v0.1.10 Goã¨pecoã®ã¤ã³ã¹ãã¼ã« Goã¯homebrewã§ãpecoã¯ãgo getãã³ãã³ãã使ã£ã¦ã¤ã³ã¹ãã¼ã«ãã¦ã¿ã¾ãã brew install go 次ã«ã.zshrcãã«goã®ããã±ã¼ã¸ã®ãã¹ãæ¸ãã¦ããã¾ã ####################################### # go path ####################################### export GOPATH=~/go export PATH=$PATH:$GOPATH/bin ã»ãã§
MAGES.ãæ°ä½ãã¢ã¤ãã«äºå¤ãã2014å¹´ç§ã«ãªãªã¼ã¹äºå®ãç·å¢47äººã®æ¨ãã¢ã¤ãã«è°å¡ããµãã¼ãããªããç·ç大è£ãç®æãã½ã¼ã·ã£ã«ã²ã¼ã MAGES.ã¯6æ30æ¥ãã¹ãã¼ããã©ã³åãã½ã¼ã·ã£ã«ã¢ããªãã¢ã¤ãã«äºå¤ãã2014å¹´ç§ã«ãªãªã¼ã¹ãããã¨ãçºè¡¨ãããæ¬ä½ã¯ããã¬ã¤ã¤ã¼ãã¹ãã³ãµã¼ã¨ãªã£ã¦ãæ¨ãã®ã¢ã¤ãã«è°å¡ããµãã¼ãããªããç·ç大è£ãç®æãã¦ãããã¢ã¤ãã«ã¨é©å½ãèµ·ããRPGããã¢ã¤ãã«ã¯åé½éåºçåºèº«ã®ç·å¢47人ã®ãã£ã©ã¯ã¿ã¼ãç»å ´ãä»å¾ããæ°ããã¢ã¤ãã«ãç¶ã ç»å ´äºå®ã¨ã®ãã¨ã ã â ã¹ãã¼ãªã¼ çµæ¸ãç ´ç¶»ãã度éããæ¿æ²»ä¸ä¿¡ã«æ¥æ¬ã¯å¤§ãã³ãããããªä¸ãæ°è¡ãã¡ãæç«ããã¢ã¤ãã«â䏿¥æãããâçããæ°å é£ãçºè¶³ãããã¢ã¤ãã«æ¿æ¨©ã«æ°è¡ãã¡ã¯é ãããçµæ¸å¹æã¯ç¬ãéã«å復ããã®æ¥ç¸¾ã¯ãå¾ã«ï½¢ã¢ã¤ãã«äºå¤ï½£ã¨ãã¦æ´å²ã«ãã®åãå»ã¿ãä»ã®æ¿æ²»çµæ¸ã®ç¤ã¨ãªã£ãã 以æ¥äºåä½å¹´ãä¸
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}