ã·ãªã³ã³ãã¬ã¼ã§æ°åæ¡ç¨ã§ã½ããã¦ã§ã¢ã¨ã³ã¸ãã¢ã¨ãã¦åãå 輩ã¨ãã¦ï¼åãã¡ã«NâTããã·ãªã³ã³ãã¬ã¼ã§åããã¨ãå§åãããï¼çç±ã¯å¤§ãã3ã¤ããï¼ çµ¦æãé¥ãã«é«ãï¼å°±å´ç°å¢ã極ãã¦è¯ãï¼ã°ãã¼ãã«ãªäººæã«ãªããï¼ããå°ãæ£ç¢ºã«è¨ãã¨ï¼ã½ããã¦ã§ã¢ã¨ã³ã¸ãã¢ã¨ãã¦ä»äºãããã¨ãããªãï¼ä¸çä¸ã©ãã§ã§ãåããããã«ãªãï¼ä¸è¨ã§ããã¨ï¼ã·ãªã³ã³ãã¬ã¼ã§ã¨ã³ã¸ãã¢ã¨ãã¦åããã¨ã¯ã¨ã¦ã幸ãã§å å®ãã¦ãããããããããããã¨ãããã¨ãªã®ã ãï¼ä½ã«å¹¸ããè¦åºããã¯äººããããéãã®ã§ï¼ç¹ã«æãã¤ã以ä¸ã®3ã¤ã®ã¡ãªãããããå°ã詳ãã説æããã®ã§ï¼ä¸ã¤ã§ãèå³ãå½ã¦ã¯ã¾ãã®ãªãããããé»ã£ã¦è©±ãæå¾ã¾ã§èãã¦æ¬²ããï¼ çµ¦æãé¥ãã«é«ãï¼å¤§ã¾ãã«ãã£ã¦ï¼20ä¸ãã«ãã30ä¸ãã«ã®å¹´åãæå¾ ã§ããï¼ããã¯æ¥æ¬ã§ãµã©ãªã¼ãã³ã¨ãã¦åããã¨ã«æ¯ã¹ãã¨å¤§å¤é«çµ¦ã ã¨æãï¼ å¥ã«é«çµ¦ã ããåãã¨ããããã§ã¯ãªããï¼
â»ã$_SESSIONã夿°ãã®ãã®ãåé¤ããªãããã«ãã¦ä¸ããã æ¬¡ã«ãä¾ãã°ãã°ã¢ã¦ãã®å¦çãªã©ããã¦ã»ãã·ã§ã³ãã®ãã®ãç ´æ£ãããå ´åã§ãããã®å ´åã¯ã¯ã©ã¤ã¢ã³ãå´ã«ä¿åããã¦ããã»ãã·ã§ã³IDãåé¤ããå¾ã§ãã»ãã·ã§ã³ãç ´æ£ãã¾ãã ã¯ã©ã¤ã¢ã³ãå´ã«ã¯ã¯ããã¼ã§ä¿åããã¦ãã¾ãã®ã§ã¯ããã¼ãåé¤ãã¾ãã(ã¯ããã¼ã®åé¤ã«ã¤ãã¦ã¯ãã¯ããã¼ãåé¤ããããåç §ãã¦ä¸ãã)ã
PHPã§èªãã¼ã¸ããèªãã¼ã¸ã¸é·ç§»ããåä½ããããã¨ããAã¿ã°ãFORMã¿ã°ã«$_SERVER['PHP_SELF']ãä½¿ãæ¹æ³ãããã¾ãã Aã¿ã°ã«ä½¿ãå ´å <a href="<?php echo $_SERVER['PHP_SELF']; ?>"> FORMã¿ã°ã«ä½¿ãå ´å <form method="post" action="<?php echo $_SERVER['PHP_SELF']; ?>"> ããããã®ãããªç®çã§$_SERVER['PHP_SELF']ã使ãã¨ãã«ã¯æ°ãã¤ããã»ããããã§ãã XSS(ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°)ã¨ããã»ãã¥ãªãã£ã¼ãã¼ã«ã«ãªãã¾ãã CakePHPãZend Frameworkãªã©mod_rewriteã使ã£ã¦ããã¨ãã§ãã ä¾ãã°æ¬¡ã®ãããªURL http://example.com/hoge.php/"><script>alert('
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}