ãã®æ¥è¨ã¯PHP Advent Calendar 2017ã®25æ¥ç®ã§ããååã¯@watanabejunyaããã®ãPHPã§ãã¥ã¼ã©ã«ãããã¯ã¼ã¯ãå®è£ ãã¦ã¿ããã§ããã OWASP Top 10 2017ãçºè¡¨ãããã¦ã§ãã®ã»ãã¥ãªãã£æ¥çãããã¤ãã¦ãã¾ããã¨ããã®ãã2013å¹´çã¾ã§ã¯å ¥ã£ã¦ããCSRFãå¤ããã以ä¸ã®2ã¤ã®è å¨ãé¸å ¥ãããããã§ãã A4 XMLå¤é¨å®ä½åç §(XXE) A8 å®å ¨ã§ãªããã·ãªã¢ã©ã¤ã¼ã¼ã·ã§ã³ ãããã®ãã¡ããA8 å®å ¨ã§ãªããã·ãªã¢ã©ã¤ã¼ã¼ã·ã§ã³ãã«ã¤ãã¦ã¯ãéå»ã«ãå®å ¨ã§ãªããã·ãªã¢ã©ã¤ã¼ã¼ã·ã§ã³(Insecure Deserialization)å ¥éãã¨ããè¨äºãæ¸ãã¦ãã¾ãã®ã§ããã¡ããåç §ãã ããã æ¬ç¨¿ã§ã¯ãXMLå¤é¨å®ä½åç §ï¼ä»¥ä¸ãXXEã¨è¡¨è¨ï¼ã«ã¤ãã¦èª¬æãã¾ãã XXEã¨ã¯ XXEã¯ãXMLãã¼ã¿ãå¤é¨ããåãåã解æããéã«çããè
{{#tags}}- {{label}}
{{/tags}}