ã¡ã¤ã³ ã³ã³ãã³ãã«ã¹ããã false æ¤ç´¢æ¤ç´¢ãã¯ãªã¢æ¤ç´¢ãçµäºGoogle ã¢ããªã¡ã¤ã³ã¡ãã¥ã¼
ã¡ã¤ã³ ã³ã³ãã³ãã«ã¹ããã false æ¤ç´¢æ¤ç´¢ãã¯ãªã¢æ¤ç´¢ãçµäºGoogle ã¢ããªã¡ã¤ã³ã¡ãã¥ã¼
å æ¥ãã¹ãã¼ããã©ã³é¢é£ã®ãµã¤ãã¼ãã¥ã¼ã¹ã¨ãã¦ã以ä¸ã®è¨äºãæ¸ãã¾ããã micro-keyword.hatenablog.com å½è©²è¨äºã¯Androidã«ä¿ãæ»æã±ã¼ã¹ã§ããããä»åº¦ã¯SIMã«ã¼ãã«ä¿ãèå¼±æ§ã«ã¤ãã¦ã®è¨äºã§ãã ç«ã¦ç¶ãã«ã¹ãã¼ããã©ã³é¢é£ã®ãµã¤ãã¼ãããã¯ãåºã¦ããã¨ç¥èãã©ãã©ãã·ãããã¦ãããªããã°ï¼ã¨æãã¾ããã èå¼±æ§ã®çºè¡¨ã«ã¤ã㦠ä»åã®èå¼±æ§ã¯ã»ã¨ãã©ã®SIMã«ã¼ãã«ããªã¤ã³ã¹ãã¼ã«ããã¦ããS@T browserã¨ããã½ããã¦ã§ã¢ã«èµ·å ãããã®ã§ãã simjacker.com AdaptiveMobile Security社ãå ¬éãããã®ã§ãçºè¡¨è ã¯ãã®èå¼±æ§ãSIMjackerã¨åä»ãã¦ãã¾ãã æ¬çºè¡¨ã¯VirusBulletinã¨ãããä¸ççãªã»ãã¥ãªãã£ã«ã³ãã¡ã¬ã³ã¹ã§ãç´¹ä»ãããã¨ã®ãã¨ã§ãã çºè¡¨æå»ã¯ãç¾å°æéã®10æ3æ¥9æããã§ãã
æ¦è¦ ããæèªå® ã«ç¥å¥å·çè¦ãä¹ãè¾¼ãã§ããã (ãªãèªå® ã¯ç¥å¥å·çã§ã¯ãªã) ã©ããã俺ã¯Twitterã«ã¢ãç»åãæ稿ãã¦ãããããã ãééããªããã®å®¶ããæ稿ããã¦ããããããã¤ãã«ã確èªæ¸ã¿ã ãã ã(ãã³ãã«ãã¼ã )ã¨ããã¢ã«ã¦ã³ã使ã£ã¦ãã§ããã ãå¿å½ããããã§ããï¼ã ã(ãã©ã³ãå)ã®Tã·ã£ãæã£ã¦ãã§ããï¼ã ããã£ãä½ããããããã§ãã æ³å®ãããçµç·¯ èªå® ãµã¼ãã¼ã§ã¯TwiGaTen( https://twigaten.204504byse.info/ )ã¨ããWebãµã¤ãã稼åãã¦ããã ããã¦ããã¤ã¯Twitterã¢ã«ã¦ã³ãã§ãã°ã¤ã³ããã¢ã«ã¦ã³ãã®ã¿ã¤ã ã©ã¤ã³ã24æé365æ¥åéãç¶ãã¦ãããTwitterã®ä»æ§ä¸ãããã¯æã ãã°ã¤ã³å±¥æ´ã¨ãã¦è¨é²ãããã ããã¦è¦å¯ã¯ã¢ãç»åããï½ããã¢ã«ã¦ã³ãã®ãã°ã¤ã³å±¥æ´ãè¦ã¦â¦ ãåºå®åç·ãããï½ãããã«ããã ã
ãã§ã¼ãã¼æ±äº¬ãã±ãããªã³ã©ã¤ã³ããµã¼ãã¹åæ¢ã®ãè©«ã³ã¨ãå ±å 2019/3/21 3æ16æ¥(å) ææ¹é ããå¼ç¤¾ãã±ãã販売ãµã¤ãããã§ã¼ãã¼æ±äº¬ãã±ãããªã³ã©ã¤ã³ã( https://ticket.kyodotokyo.com ) ã«ããã¦ã ä¸é¨ã®ã客æ§ã®æ å ±ãå¥ã®ã客æ§ã«èª¤ã£ã¦è¡¨ç¤ºãããäºæ ãçºçãããã¾ããã çºç件æ°ã誤ã£ã¦è¡¨ç¤ºãããã客æ§ã®ç¶æ³ææ¡ãåå ã«ã¤ãã¦ã¯ç¾å¨èª¿æ»ä¸ã§ãã çæ§ã«ã¯ã大å¤ãªãè¿·æã¨ãå¿é ãããããã¦ããã¾ããã¨ããå¿ãããè©«ã³ç³ãä¸ãã¾ãã
ã©ããã証ææ¸ãã³ã¿ã¼ã§ããæè¿ãå人çã«ããããã証ææ¸ã®è©±é¡ããã³ãã³åºã¦ããã®ã§ãä½åãã«åãã¦ãç´¹ä»ãããã¨æãã¾ãã å±±è³ããã®Facebookã®ãã£ã¼ããè¦ã¦ãããã éå½æ¿åºPKIã§ã¾ãã証ææ¸ãçºè¡ããã¨ãããã¥ã¼ã¹(Google翻訳ã§èªãã§ãã ããw)ãæãã¦ããã ãã¾ãã¦ããã³ã¿ã¼ã¨ãã¦ã¯ã²ãããã¦ã³ã¬ã¯ã·ã§ã³ã«å ãã¦ããããã¨ããã ãã®åé¡ã¨ããã®ã¯ãéå½æ¿åºPKIãæ ¶å°åéæè²åºã«ä¸é©åãªã¯ã¤ã«ãã«ã¼ãSSLãµã¼ãã¼è¨¼ææ¸ãçºè¡ãã¦ãã¾ã£ãã¨ãããã®ã æ ¶å°åéã¯éå½ã®åæ±ãéå±±ã®ããåã«ããã®ã ããã§ãã éå½ã®ãµã¤ãã¯æ¥æ¬ã¨åãã§ã»ã«ã³ãã¬ãã«ãçµç¹ç¨®å¥ã¨ããå±æ§åãã¡ã¤ã³åãæ¡ç¨ãã¦ãã¦ãæ¿åºç³»ãã¡ã¤ã³ã¯ãgo.krãã®ããã«ãªã£ã¦ãã¾ããã以ä¸ã®ãã¡ã¤ã³ã«å¯¾ãã¦ã¯ã¤ã«ãã«ã¼ãSSLãµã¼ãã¼è¨¼ææ¸ãçºè¡ãã¦ãã¾ãã¾ããã *.hs.kr - é«æ ¡ *.ms.
ãã¦ãæãã¦è²°ã£ãã®ã§ãã ã¹ããã使ã£ã¦ãçããã¯ãè¯ãLINEã使ãã¾ãããã ããè¨ãã¯ã¿ã¹ãéå¡å°ç¨LINE@ã§ä½¿ã£ã¦ã¾ããã ãã¼ãã ãã®LINEã§ããã ãªãã¨æ°ã¥ãã¬éã«ãã¼ã¯ã«ã¼ã ã®å 容ãæä¾ããè¨å®ã«ãªã£ã¦ãããã§ãã ã¡ãã£ã¨é©ããã®ã§å¼µã£ã¨ãã¾ãããã æè¿ã®ã¢ãããã¼ãããã®ããã§ããã LINEã®ãã¼ã¯ã«ã¼ã ã£ã¦ã®ã¯ä»ã®äººã¨ã¡ãã»ã¼ã¸ãããåãããç»é¢ã®ãã¨ã§ãã çæ§ãèªåã®è¨å®ã確èªãã¦è¦ã¾ãããã LINEã®è¨å®ç»é¢ãéã㨠ãã©ã¤ãã·ã¼ç®¡çã®é ç®ãããã ãã®ãã©ã¤ãã·ã¼ç®¡çé ç®ã«ãæ å ±ã®æä¾ãã¨ããæ¬ãããã ãã»ãï¼ï¼ ãã¼ã¯ã«ã¼ã æ å ±ã®æä¾ã許å¯ããã¦ãï¼ï¼ ã¤ããããã æ°ã¥ããªãéã«ããããªå 容ããããªå 容ãã ãã¼ã¯ã«ã¼ã ã®å 容ãLINE社ã«æä¾ãã¦ããã®ããã 以ä¸ã¯ãã©ããªå 容ãçæãã ã£ããã®è¨äºã§ãã LINEã¯ã¦ã¼ã¶ã¼ã®ã©ããªæ å ±ã
Bugs Patterns The complete list of descriptions given when FindBugs identify potential weaknesses. äºæ¸¬å¯è½ãªæ¬ä¼¼ä¹±æ°çæå¨ Bug Pattern: PREDICTABLE_RANDOM ã»ãã¥ãªãã£ä¸éè¦ãªã³ã³ããã¹ãã§ï¼äºæ¸¬å¯è½ãªä¹±æ°ã使ç¨ãããã¨èå¼±æ§ã«ã¤ãªãããã¨ãããã¾ãããã¨ãã°ï¼ãã®ä¹±æ°ã次ã®ããã«ä½¿ç¨ãããã¨ãã§ãã CSRF ãã¼ã¯ã³:äºæ¸¬å¯è½ãªãã¼ã¯ã³ã¯ï¼æ»æè ããã¼ã¯ã³ã®ä¾¡å¤ãç¥ããã¨ã«ãªãã®ã§ï¼CSRF æ»æã«ã¤ãªããå¯è½æ§ããã ãã¹ã¯ã¼ããªã»ãããã¼ã¯ã³(é»åã¡ã¼ã«ã§éä¿¡):äºæ¸¬å¯è½ãªãã¹ã¯ã¼ããã¼ã¯ã³ã¯ï¼æ»æè ãããã¹ã¯ã¼ãå¤æ´ããã©ã¼ã ã®URLãæ¨æ¸¬ããããï¼ã¢ã«ã¦ã³ãã®ä¹ã£åãã«ã¤ãªããå¯è½æ§ããã ãã®ä»ã®ç§å¯ã®å¤ æã£åãæ©ã解決ç㯠java.util
Apache Struts 2ã«ãããèå¼±æ§ (S2-045ãCVE-2017-5638)ã®è¢«å®³æ¡å¤§ã«ã¤ã㦠JSOC ãµã¤ãã¼æ»æ èå¼±æ§ 3æ6æ¥ï¼æ¥æ¬æéï¼ã«å ¬éãããApache Struts 2ã«ãããä»»æã®ã³ã¼ããå®è¡å¯è½ãªèå¼±æ§ãæªç¨ããæ»æã大è¦æ¨¡ã«è¡ããã¦ãããJSOCã§ãå®å®³ãä¼´ãéè¦ã¤ã³ã·ãã³ãäºä¾ãè¤æ°ã®ã客æ§ã®ç°å¢ã§ç¶ç¶ãã¦çºçãã¦ãããã¨ãããããä¸å±¤ç·æ¥åº¦ãä¸ãã対å¿ã®å¼ã³æããè¡ãã¾ãã JSOCã¢ããªã¹ããã¼ã ã®å±±åã»åå·ã§ãã æ¢ã«IPAãªã©ããåºã注æåèµ·ãå¼ã³ããããã¦ããã¨ããã§ããã¾ããã3æ6æ¥ï¼æ¥æ¬æéï¼ã«Apache Struts 2 ã®æ°ããªèå¼±æ§(S2-045ãCVE-2017-5638)ãçºè¡¨ããã¾ãããä»åã¯ãæ¬èå¼±æ§ãæªç¨ããæ»æã®çºçç¶æ³ãªã©ã«ã¤ãã¦ã®æ å ±ãæ¬ããã°ã«ã¦ãç¥ãããããã¾ãã JSOCã§ã¯3æ7æ¥é ããããã®èå¼±æ§
IPAï¼ç¬ç«è¡æ¿æ³äººæ å ±å¦çæ¨é²æ©æ§ï¼ã»ãã¥ãªãã£ã»ã³ã¿ã¼ã¯ã2013å¹´ã«å ¬éããâIPAãã¯ãã«ã«ã¦ã©ããâãã¦ã§ããµã¤ãã«ãããèå¼±æ§æ¤æ»ææ³ã®ç´¹ä»ããæ´æ°ãããã¦ã§ããµã¤ãã«ãããèå¼±æ§æ¤æ»ææ³ï¼ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³æ¤æ»ç·¨ï¼ãã¨ãã¦å ¬éãã¾ããã æ¬æ¸ã§ã¯ã5種ã®ç¡åãã¼ã«ã«ããæ¤åºæ¹æ³çã®è§£èª¬ããç¡åãã¼ã«ã®æ´»ç¨ä¾ã3ç¹ææ¡ãã¦ãã¾ãã ä¸è¨ãããã¦ã§ããµã¤ãã«ãããèå¼±æ§æ¤æ»ææ³ï¼ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³æ¤æ»ç·¨ï¼ãã«ã¤ãã¦ã®ã¬ãã¼ãï¼PDFçï¼ããã¦ã³ãã¼ããã¦ãå©ç¨ããã ãã¾ãã 1.被害äºä¾ããã³èå¼±æ§æ¤æ»ãã¼ã«ã®æ´»ç¨ 2.ã¦ã§ãã¢ããªã±ã¼ã·ã§ã³èå¼±æ§æ¤æ»ãã¼ã«ã®æ¦è¦ 3.èå¼±æ§æ¤æ»ãã¼ã«ã®ã¿ã¤ãã®å®ç¾©ã¨ãã¼ã«ã®ç´¹ä» 4.èå¼±æ§æ¤æ»ãã¼ã«ã®ä½¿ç¨ä¾ 5.è©ä¾¡ã»ã¾ã¨ã 6.ãããã« 7.åè
çµç·¯ é©å½ã«å¥ã¿ããéããªã³ã¯ãjsxã§æ¸ããã eslint-plugin-react ã® jsx-no-target-blank ã§æãããã¾ããã ã»ãã¨ã«ç¥ããªãã£ãããæ°è»½ã«ã§ãã¡ãããããã°ããªãã£ã¨æã£ãã®ã§ã¡ã¢ãã¦ããã¾ãã import React from 'react'; import ReactDOM from 'react-dom'; class Index extends React.Component { render() { return ( <a href="http://example.com" target="_blank" > ã¢ã³ã«ã¼ãªã³ã¯ </a> ); } } ReactDOM.render( <Index />, document.getElementById('root') );
ãµã¼ã: ã¦ã¼ã¶ã«ãã PDF ã®ã¢ãããã¼ãã許å¯ãããã¢ãããã¼ãããã PDF ãåä¸ãªãªã¸ã³ã«æ ¼ç´ããã ã¯ã©ã¤ã¢ã³ã: Adobe PDF Plugin ãæå¹ã«ãã IE11 ããã㯠Firefox PDF ã«ã¯å ¥åãã©ã¼ã ãæã¤ããã¥ã¡ã³ããä½æããæ©è½ãããã¾ããããã®æ©è½ãå®ç¾ããããã®ä»æ§ã¨ãã¦ãPDF 1.5 以éãAdobe ãçå®ãã Adobe XML Forms Architecture (XFA) ããµãã¼ãããã¦ãã¾ããããã«ããã©ã¼ã ã«å ¥åãããå¤ã使ã£ã¦åçã«æ¼ç®çã®å¦çãè¡ãããã«ãFormCalc ã¨å¼ã°ããã¹ã¯ãªããè¨èªãç¨æããã¦ããããããç¨ãããã¨ã§ PDF ããã¥ã¡ã³ãã«ããã°ã©ã ãåãè¾¼ããã¨ãå¯è½ã§ãã FormCalc ã®æ¦è¦ãè¨èªã®ä»æ§ã¯ãAdobe ãæä¾ãã FormCalc ã¦ã¼ã¶ã¼ãªãã¡ã¬ã³ã¹ã«ã¾ã¨ãããã¦ãã¾ãã Fo
gistfile1.md CVE-2016-7401 https://www.djangoproject.com/weblog/2016/sep/26/security-releases/ https://hackerone.com/reports/26647 pythonã®cookie parserã ; 以å¤ãpairsã®åºåãæåã¨ãã¦è§£éããã®ã§ãgoogle analyticsã®referrerçµç±ã§setãããcookieã使ã£ã¦CSRF tokenãä¸æ¸ãå¯è½ã ã£ãã¨ããåé¡ã djangoå´ã§cookie parserèªåã§å®è£ ãpythonæ¬ä½ã¯ç´ã£ã¦ãªãããã https://github.com/django/django/commit/d1bc980db1c0fffd6d60677e62f70beadb9fe64a å¤ãã®cookie parserã¯ãpairsã®åº
[ãã㯠Mozilla ã®ã»ãã¥ãªãã£ã¨ã³ã¸ã㢠Tanvi Vyas æ°ã®ããã°è¨äº No More Passwords over HTTP, Please! ãåæ°ã®è¨±å¯ãå¾ã¦ç¿»è¨³ãããã®ã§ã] Firefox 46 Developer Edition ã¯ãHTTP ãã¼ã¸ä¸ã§ãã°ã¤ã³æ å ±ã®å ¥åãæ±ããããå ´åãéçºè ã«è¦åãè¡ãã¾ãã ã¦ã¼ã¶åã¨ãã¹ã¯ã¼ãã®çµã¿åããã¯ãã¦ã¼ã¶ã®å人ãã¼ã¿ã¸ã®ã¢ã¯ã»ã¹ã管çããæ段ã§ããWeb ãµã¤ãã¯ããããæ å ±ã注ææ·±ãæ±ãããã¹ã¯ã¼ã㯠HTTPS ã®ãããªå®å ¨ãª (èªè¨¼ãæå·åããã) æ¥ç¶ãéãã¦ã®ã¿è¦æ±ãã¹ãã§ãããããæ®å¿µãªãã¨ã«ãHTTP ã®ãããªå®å ¨ã§ãªãæ¥ç¶ã§ã¦ã¼ã¶ã®ãã¹ã¯ã¼ããæ±ããã¦ããä¾ã é常ã«å¤ã è¦ããã¾ãããã®ãã©ã¤ãã·ã¼ã¨ã»ãã¥ãªãã£ã®èå¼±æ§ãéçºè ã®çããã«ç¥ããããããææ°ã® Firefox Develope
ãã»åºå°å±ã¯ããã¾ã§ä¸»ã«ãç²ãªã¹ãã SMSã¡ãã»ã¼ã¸éä¿¡ç¨ã«ä½¿ããã¦ã¾ããããæè¿ãã£ãã·ã³ã°URLãå¤ãéä¿¡ãããããã«ãªãã¾ããã ä»åã®äºä¾ã§ã¯ããã£ãã·ã³ã°ãµã¤ãã§å人éè¡å£åº§ãçªåããæ´ã«è¢«å®³è ã«apk ããã¦ã³ãã¼ãããããã¨ã§ãSMSã¡ãã»ã¼ã¸ãã¤ã³ã¿ã¼ã»ãã(çªå)ãããã«ã¦ã§ã¢ãä»è¾¼ã¾ããã¨ãããã¨ããããã¾ããã ããããªã¼ã©ã³ã¹ã®ããã«ã¼ãããã¾ãã«ãã¤ãã SMS ã¹ãã ã«ã¤ã©ã¤ã©ãããã£ãã·ã³ã°ãµã¤ãããããã³ã°ããæ´ã«è½ã¡ã¦ãã apk ã解æãããã¨ã«ãã£ã¦ãå ¨è²ãæããã«ãã¦ã¾ãã â»ãã»åºå°å±ã¨ã¯ï¼è©æ¬ºéå£ãè»ã®ãã©ã³ã¯çã«å¼·åãªæºå¸¯é»è©±é»æ³¢çºå°å¨ãã»ããã¢ãããã人æµãå¤ãã¨ããã«è¨ç½®ããé»æ³¢ã«ãã¼ç¯å²å ã®ã¦ã¼ã¶ã«å¼·å¶éä¿¡ããããã¨ã§ãç¡å·®å¥SMSã¹ãã ãéä¿¡ããä»çµã¿ã thalys.hatenablog.com â»ãµã¤ã SSSãã©ã¼ã©ã ãã転è¼å¼
LINEæ ªå¼ä¼ç¤¾ã¯ã2023å¹´10æ1æ¥ã«LINEã¤ãã¼æ ªå¼ä¼ç¤¾ã«ãªãã¾ãããLINEã¤ãã¼æ ªå¼ä¼ç¤¾ã®æ°ããããã°ã¯ãã¡ãã§ãã LINEã¤ãã¼ Tech Blog saegusa2017-04-16Yoshihiro was a network engineer at LINE, responsible for all levels of LINE's infrastructure. Since being named Infra Platform Department manager, he is finding ways to apply LINE's technology and business goals to the platform. ããã«ã¡ã¯ãLINEã§ãããã¯ã¼ã¯ããã¼ã¿ã»ã³ã¿ã¼ãæ å½ãã¦ããä¸æã§ãã2017å¹´1æã«JANOG39ã§ç»å£ããæ©ä¼ãé ãã¾ããã®ã§ãä»å
Flashã使ã£ããã¡ãã£ã¨å¤ãã£ãæ å ±å¥ªåææ³ãç´¹ä»ãã¾ãã ãã®ææ³ã以åããæ¡ä»¶ã«ãã£ã¦ã¯æ»æãå¯è½ã«ãªãå ´åãããã ããã¨æ³åãã¦ãããã§ããããªããªãå®ä¾ã«ã¶ã¤ãããã2013å¹´ã«éå¬ããããµã¤ãã¦ãºã®èå¼±æ§çºè¦ã³ã³ãã¹ããcybozu.com Security Challengeãã§åãã¦æ¬å½ã«åä½ãããã®ãçºè¦ãã¾ããã å®ã¯æ¢ã«ãSECCON 2013 å ¨å½å¤§ä¼ãã§ãä¸é¨è©³ç´°ãçºè¡¨ãã¦ãã¾ããã¹ã©ã¤ãã®15ãã¼ã¸ã®è¾ºãããæ¸ãã¦ãã件ã§ãã http://www.slideshare.net/masatokinugawa/cybozu-security-challenge/15 çºè¡¨ã®æç¹ã§ã¯ãµã¤ãã¦ãºå´ã§ä¿®æ£ããã¦ããªãã£ãã®ã§ãå ·ä½çãªç®æãä¼ãã¦ãã¾ãããä»ã¯ä¿®æ£ãããã®ã§ãå ·ä½çãªç®æããããªãã説æãããã¨æãã¾ãã ãªãããã®åé¡ã¯Flashèªä½ã®èå¼±æ§ã§ã¯ãªã
ãã©ã¤ãã·ã¼ã¢ã¼ãã§ãiPhoneã§ã追跡? ã¨ã³ã¸ãã¢ãç¥ã£ã¦ããã¹ããHSTS Super Cookiesã ããã«ã¡ã¯ããã¼ã®ã§ãã ã¿ãªããã¯æ°æ¥åãã軽ã話é¡ã«ãªã£ã¦ããã¯ããã¼ã«ã¤ãã¦ãåç¥ã§ããããããã®åããHSTS Super Cookiesãã¨è¨ãã¾ãããã®ã¯ããã¼ã¯é常ã®ãã©ã¦ã¶ã¢ã¼ãã¯ãã¡ãããã¯ããã¼ãªã©ãæ®ããªãããã©ã¤ãã·ã¼ã¢ã¼ããæã¦ã¯åä¸iCloudã¢ã«ã¦ã³ãã®iPhoneã¾ã§è¿½è·¡ã§ãããã¨ããã§ã¯ãªãã§ãããªã«ãããããã ã¨ãããã¨ã§ä»æ¥ã¯ãã®ãHSTS Super Cookiesãã¨ã¯ä½è ã§ãã©ãããä»çµã¿ã§ãããªã£ã¦ããã®ããç¾æç¹ã§ã®å¯¾å¿ç¶æ³ããç´¹ä»ãã¾ãã ã¾ãã¯è¦ã¦ãã ããã ã¾ãã¯ç¾èã¯ä¸ä»¶ã«å¦ãããã¨ãããã¨ã§ãã¡ãã御覧ãã ããã ä½ãæ°åã¨æåãåããã£ããã¹ã¯ã¼ãçãªãã®ãåºã¦ãã¦ãã¾ãã§ãããããããããããããHSTS Supe
ãã®è¨äºã¯PHPã¢ããã³ãã«ã¬ã³ãã¼2014ã®22æ¥ç®ã®è¨äºã§ã ã 2002å¹´3æã«å ¬éãããIPAã®äººæ°ã³ã³ãã³ããã»ãã¥ã¢ããã°ã©ãã³ã°è¬åº§ãã2007å¹´6æã«å¤§å¹ ã«æ´æ°ããã¾ãããããã¦ããã®ä¸ç¯ãPHPerãã¡ãæ¿ããåºæ¿ãããã¨ã«ãªãã¾ãã (1) ããã°ã©ãã³ã°è¨èªã®é¸æ 1) ä¾ãã°ãPHPãé¿ãã çææ¥ã§ç´ æ©ããµã¤ããç«ã¡ä¸ãããã¨ã®ã¿ã«çç®ããã®ã§ããã°ãPHPã¯æªãå¦çç³»ã§ã¯ãªããããããããã¾ã§å¤ãã®èå¼±æ§ãçãã§ããçµç·¯ããããæ¹åãé²ãã§ããã¨ã¯ããã¾ã ååå åºã¨ã¯è¨ããªãã ã»ãã¥ã¢ããã°ã©ãã³ã°è¬åº§ï¼ã¢ã¼ã«ã¤ãï¼ããå¼ç¨ ãPHPãé¿ãããã¨ã¾ã§è¨ããã¦ãã¾ã£ãããã§ãå½ç¶ãªãããããçéã§ã¯çä¸ãèµ·ãããç¾å¨ã¯ããå°ããã¤ã«ããªè¡¨ç¾ã«å¤ãã£ã¦ãã¾ã(åç §)ã æ¬ç¨¿ã§ã¯ãå½æã®PHPã®ç¶æ³ãæ¯ãè¿ãæ段ã¨ãã¦ããã®å¾PHPã®ã»ãã¥ãªãã£æ©è½ãã©ã®ããã«å¤å
tl;dr CSP Lv.2ã®nonceã使ãã¨æå¤ã¨ç°¡åã«CSPã®æ©æµãåãããã Firefoxã¯unsafe-inlineã¨ã®æåãããããã®ã§æ³¨æ ãµã³ãã«å®è£ ã¨ãã¦Expressã§ç°¡åã«nonce対å¿ã§ããconnectãã©ã°ã¤ã³ãæ¸ããï¼ãã¢ããï¼ Violation Reportããã©ã¦ã¶ã«ãã£ã¦ç´°ããæåã®å·®ç°ãããã CSP Lv.2 nonceã®ç»å ´ã¨èæ¯ CSPã®ç¹ã«unsafe-inlineã¯XSSã«å¯¾ãã¦æçµé²è¡ç·çã«å¼·åãªå¹æãããã ãããç¹ã«ãµã¼ãã¼ããã®å¤ã®åã渡ãé¨åãªã©ã§ã©ããã¦ãinline scriptã使ããããªãã¨ããããããunsafe-inlineãç¦æ¢ããã¨DOM dataçã使ããããå¾ããã¤ããæãã ã£ãã @kazuho ã§ããããã¨ãã£ã¦DOM dataãã¼ããã¨ããæãã§ã¯ãããã§ãããCSPã§inline scriptç¦æ¢ãã¡
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}