The Polaris Dawn crew is back on Earth after a historic mission
The Polaris Dawn crew is back on Earth after a historic mission
ç§ãã¡ãä¹ããé£è¡æ©ã¯ããã¹ã¿ã³ã®ã«ã©ã空港ã§çµ¦æ²¹ããäºåæéã»ã©ã®ãã©ã¤ãã§ãã°ããã空港ã«çããã ã¿ã©ãããéããã¨ãããç§ã¯æ¿ããæ¯è¦ãããè¦ããã ç§ãã¢ã«ãã¤ãã§ã¤ã©ã¯ã®å»ºè¨ç¾å ´ã«è¡ããã¨ã«ãªã£ãã®ã¯ã1980å¹´ã®ä¸æåã°ã®ãã¨ã ã£ãããµãã ã»ãã»ã¤ã³ã大統é ã«ãªã£ãç¿å¹´ã§ãããå½æã大å¦ãä¸éããç§ã¯ãéããªããªãã¨é«ç°é¦¬å ´ã®è·å®åã®å ¬åå ã«ã§ããå¯ãå ´ã«è¡ããæ¥éãå´åã§é£ãã¤ãªãçæ´»ããã¦ããã ãããªããæãé¡é¦´æã¿ã®æé 師ãããã«ãã¡ãããå¤å½ã®ç¾å ´ããããã ãã©ãè¡ããããããï¼éã¯ããããã¨èªã£ã¦ãããèãã¨ãå¥ç´æéã¯ä¸ææ«ããä¸ãæãæ è²»ã¯å¿è«ãè¡£é£ä½ä»ãã§ä¸ç¾ä¸åãæ¯æããä»äºã¯æ¥æ¬ã®å¤§æ建è¨ä¼ç¤¾ã建ã¦ã¦ãããã«ã«è³æãéã³å ¥ããå¤å½äººå´åè ã®ç£ç£ãããã®ãä»äºã ã¨ããã ããããªã«ãã¾ã話ãããã®ããªâ¦â¦ãã¨å¤å°çå¿æ鬼ã«ã¯ãªã£ããããåéã¨ãã¦ç¾ä¸åæã
ãªã㧠html ã® from 㯠PUT / DELETE ãã§ããªãã®ãããã»ãã¥ãªãã£ççç±ãã¨ããæ´å²ççµç·¯ãã¨ããããã£ããããªåãããªããããªèª¬æã¯ããèããã©ãå®éãªãã§ãªã®ã調ã¹ã¦ããè²ã æãã¦ããã£ã話ã ããã¾ã§ããã£ããã¨ã blog ã«ã¾ã¨ãã¾ããã / âãªã html ã® form 㯠PUT / DELETE ããµãã¼ãããªãã®ãï¼ - Block Rockinâ Codesâ http://jxck.hatenablog.com/entry/why-form-dosent-support-put-delete
注æ å 容ã«ã¤ãã¦ã¯ä¸åä¿è¨¼ãã¾ããã ããã§ã¯ã主㫠W3C ML ã§ã®è°è«ãå種ä»æ§ãªã©ã«åºã¥ãã¦æ¸ãã¦ãã¾ãã ããã«æ¸ããã¦ãããã¨ãæ£ãããã©ããã¯ãèªèº«ã§å¤æãã¦ä¸ããã äºå®ã¨ãã¦ããããã¨ãããªã©ã¯ãã³ã¡ã³ãã§ã©ãã©ãææãã¦ä¸ãããé æ ®ã¯ããã¾ããã ãã ãããã®ã¨ã³ããªã§ã¯ãform ã PUT/DELETE ããµãã¼ãããã¹ããã©ããï¼ãã®è°è«ã¯ãã¾ããã ãREST ã®æ¯éãããPUT/DELETE ã®æ義ãã«ã¤ãã¦ãè°è«ããæ°ã¯ããã¾ããã ããã§ãã£ã¦ããã®ã¯ãããã¾ã§ãã©ããã£ãè°è«ã®æ«ç¾ç¶ãããã®ãã®èª¿æ»ã§ãã ããããæè¦ãããå ´åã¯ã W3C ãªã©ã«æ稿ããã®ãæãæçã ã¨æãã¾ãã History 2014/03/29: å ¬é 2014/03/29: XForm 㨠XHTML ã®é¢ä¿ãæ確å(thanx koichik) 2014/03/29: HT
TVã¢ãã¡ãæ©åæ¦å£«Îã¬ã³ãã ãã®é®å·éº»å¼¥ãæãOPãã¼ããÎã»å»ãè¶ãã¦ãã¨EDãã¼ããæ空ã®Believeãã¯ããã¼ã«ã»ã»ãã«ï¼Neil Sedakaï¼ã®æ¥½æ²ã«æ¥æ¬èªã®æè©ãã¤ãããã®ãã»ãã«ã¯4æãããèªå® ã§æ®å½±ããããã©ã¼ãã³ã¹æ åãã»ã¼æ¯æ¥å ¬éãã¦ããããã®2æ²ã®åæ²ãæ¼å¥ãã¦ãã¾ãã ãÎã»å»ãè¶ãã¦ãã®åæ²ã¯ãBetter Days Are Comingãããæ空ã®Believeãã®åæ²ã¯ãBad And Beautifulã â "I Must Be Dreaming"/"The Miracle Song"/"Better Days Are Coming" â»ãBetter Days Are Comingãã¯5å20ç§ãã
æå¿«ãªçæ´»éã太é @hassyX ããã¼ã®è¡åããæµç³ã殺ãã®ãããã¯ä¿ºãã¡ã¨ã¯éããªâ¦ãçãªåéãã§ãã¡ãã¡æå¿ãã¾ããä¾é ¼ä¸»ã®ããã£ã¢ã¨ãå¾åæ£ä½ããã¬ãªãããã«ç¦ãç¶ããããã¼ã®å¯¾æ¯ãé¢ç½ããã´ã«ã´å¯ä¸ã®ããéãã³ã³ãåã æå¿«ãªçæ´»éã太é @hassyX ãã¨ããã®åãããã¯ãããã¨ããããã«ä¼¼ãã¦æã人ããããªãã£ãã®ãå¤å¿ã ã£ãã®ããæ®æ®µã®ã´ã«ã´ã¨ã¯ç»é¢¨ãããªãç°ãªãã主è¦ãªç»å ´äººç©ãããã¨ãæ°ã®ã¿ããã¨ã¯æããã«éãããæºã¢ãã®æ®ºå®³ã¿ã¼ã²ãããã¡ã¯å®å ¨ã«å¥æ¼«ç»ã¬ãã«ã§çµµæãéããã§ãã´ã«ã´ã¯å®å ¨ã«ãã¤ãã®ã´ã«ã´ã pic.twitter.com/zcrmeYX77J
æ¿åæ¥è§¦ã®ä¼ https://t.co/nLpqutJUby
HTTP Guides An overview of HTTP A typical HTTP session HTTP Messages MIME types (IANA media types) Compression in HTTP HTTP caching HTTP authentication Using HTTP cookies Redirections in HTTP HTTP conditional requests HTTP range requests Content negotiation Connection management in HTTP/1.x Evolution of HTTP Protocol upgrade mechanism Proxy servers and tunneling HTTP Client hints Security and priv
Nginxããªãã¼ã¹ãããã·ã¨ãã¦å©ç¨ããããã®æ¹æ³ã¨å人ç¨ã¡ã¢ ãããã·è¨å® Nginxããªãã¼ã¹ãããã·ã¨ãã¦å©ç¨ããããã«ã¯ã/etc/nginx/conf.d ã«è¨å®ãã¡ã¤ã«ãé ç½®ããã°ãã ãã¡ã¤ã«å㯠{ConfigName}.conf ä»å㯠server.conf ã¨ãã¦ãã¡ã¤ã«ãé ç½®ãã 以ä¸ã®ããã« server.conf ãç¨æã㦠Nginx ãåèµ·åãã server{ server_name example.com; proxy_set_header Host $host; proxy_set_header X-Real-IP $remote_addr; proxy_set_header X-Forwarded-Host $host; proxy_set_header X-Forwarded-Server $host; proxy_set_header X-Fo
ã¯ããã« ãããã·ã¨ãªãã¼ã¹ãããã·ã£ã¦ãããããã§ãããã ãã®è¨äºã§ã¯ãæ¦å¿µå³ã交ããªããæ··ä¹±ãããããããã·ã¨ãªãã¼ã¹ãããã·ã®éããã¾ã¨ãã¦ããã¾ãã ãããã·ã¨ã¯ ä¸è¬çã«ä½¿ããããããã·ã¨ããã°ããforward proxyãã®ãã¨ãããã¾ãã forward proxyã¨ã¯ãããå¥ã®Webãµã¤ãã¸ã®ãªã¯ã¨ã¹ããåãåããã¯ã©ã¤ã¢ã³ãã®ä»£ããã«Webãµã¤ãã¸ãªã¯ã¨ã¹ããéä¿¡ãããµã¼ãã®ãã¨ã§ãã ãã¡ãã®å³ãforward proxyã®æ¦å¿µå³ã§ãã ã¯ã©ã¤ã¢ã³ãXãã¨ããWebãµã¤ãï¼ãµã¼ãZï¼ã«ã¢ã¯ã»ã¹ããæã«ãããã·ãµã¼ãYãå©ç¨ãã¦ããä¾ã§ãã ãªã¯ã¨ã¹ã㯠ã¯ã©ã¤ã¢ã³ãX â ãããã·Y â Webãµã¼ãZ ã¨ããæµãã§ä¼ãã£ã¦ããã¾ãã ãããã·ã使ãç®ç ãã®ãããªforward proxyã使ãç®çããWebãµã¼ãZã«ç´æ¥ã¢ã¯ã»ã¹ã§ããªãã¯ã©ã¤ã¢ã³ãXããZã«ãªã¯
ãªãã¼ã¹ãããã·ï¼è±: reverse proxyï¼ã¾ãã¯éãããã·ã¯ãç¹å®ã®ãµã¼ãã¸ã®ãªã¯ã¨ã¹ããå¿ ãééããããã«è¨ç½®ããããããã·ãµã¼ãã§ãããä¸è¬çãªãããã·ã¨ã¯éã§ãä¸ç¹å®å¤æ°ã®ã¯ã©ã¤ã¢ã³ãã®ã¢ã¯ã»ã¹ã«åãã¦ç¹å®ã®ãµã¼ãã¼å°ç¨ã«è¨ãããããã¯ã©ã¤ã¢ã³ãã«åã£ã¦ã¯ãµã¼ãã¹ã®çªå£ã¨ãã¦æ©è½ããæ®éã¯ã¯ã©ã¤ã¢ã³ãããªãã¼ã¹ãããã·ãæèãããã¨ã¯ãªãã ãªãã¼ã¹ãããã·ã¯ãä¸ç¹å®å¤æ°ã®ã¯ã©ã¤ã¢ã³ãã«å¯¾ããã¢ã¯ã»ã¹å¶éãããµã¼ãã¼ã®è² è·åæ£ã®ããã«ç¨æããããå ·ä½çã«ã¯ä¸è¨ã®ç¨éãããã ã»ãã¥ãªã㣠ãªãã¼ã¹ãããã·ãµã¼ããåç½®ãããã¨ã§é²å¾¡ãä¸æ®µéå¢ããããªãã¼ã¹ãããã·ã«èªè¨¼ã»èªå¯ã®æ©è½ãæãããå ´åããããè¤æ°å°ã®ãµã¼ããããå ´åã«ãªãã¼ã¹ãããã·ã§èªè¨¼ã»èªå¯ãè¡ãã¨ã·ã³ã°ã«ãµã¤ã³ãªã³ãå®ç¾ã§ããã æå·å/SSLé«éå SSL ã«ããæå·åã§ã»ãã¥ã¢ãªWebãµã¤ããä½ãã¨ããæ
nginxããªãã¼ã¹ãããã·ã«ããå ´åã«ä½¿ç¨ããproxy_passãã£ã¬ã¯ãã£ãã¯ãURIãä¸ããããå ´åã¨ãããã§ãªãå ´åã§æåãç°ãªãã ã©ããããã¨ãã¨ããã¨ã以ä¸ã®1.ã¨2.ã¯å¥ã ã®çµæã¨ãªããproxy_passãã£ã¬ã¯ãã£ãã®å¼æ°ã«æ³¨ç®ãã¦æ¬²ããã # 1. specified with a URI location /name/ { proxy_pass http://127.0.0.1/; } 1.ã¯proxy_passãã£ã¬ã¯ãã£ãã«å®å ¨ãªURIãä¸ããä¾ã§ããããã®å ´åhttp://example.com/name/fooã¸ã®ã¢ã¯ã»ã¹ã¯ã/nameãåé¤ãããhttp://127.0.0.1/fooã¸è»¢éãããã 2.ã¯proxy_passãã£ã¬ã¯ãã£ãã«å®å ¨ãªURIãä¸ããªãã£ãä¾ã§ããããã®å ´åhttp://example.com/name/fooã¸ã®ã¢ã¯ã»ã¹ã¯ã
HTTP ã¬ã¤ã ãªã½ã¼ã¹ã¨ URI ã¦ã§ãä¸ã®ãªã½ã¼ã¹ã®èå¥ ãã¼ã¿ URL MIME ã¿ã¤ãå ¥é ãããã MIME ã¿ã¤ã www ä»ã㨠www ãªãã® URL ã®é¸æ HTTP ã¬ã¤ã HTTP ã®åºæ¬ HTTP ã®æ¦è¦ HTTP ã®é²å HTTP ã¡ãã»ã¼ã¸ å ¸åç㪠HTTP ã»ãã·ã§ã³ HTTP/1.x ã®ã³ãã¯ã·ã§ã³ç®¡ç ãããã³ã«ã®ã¢ããã°ã¬ã¼ãã®ä»çµã¿ HTTP ã»ãã¥ãªã㣠Content Security Policy (CSP) HTTP Strict Transport Security (HSTS) X-Content-Type-Options X-Frame-Options X-XSS-Protection ãµã¤ãã®å®å ¨å HTTP Observatory HTTP ã¢ã¯ã»ã¹å¶å¾¡ (CORS) HTTP èªè¨¼ HTTP ãã£ãã·ã¥ HTTP ã®å§ç¸® HTT
çå¨ããµãã£ãBlasterã¯ã¼ã ãããã大æµè¡ããã®ã¯2003å¹´ã§ãããããã¾ã ã«ãã®ã¯ã¼ã ã®çè·¡ã¯ã¤ã³ã¿ã¼ãããä¸ã«æ®ã£ã¦ãã¾ãããã®çç±ã®1ã¤ã¯ããã¾ã ã«ã»ãã¥ãªãã£ããããé©ç¨ããã¦ããªããã¹ããæ®ã£ã¦ãããã¨ã«ãããã¾ããä»åã¯èå¼±ãªãã¹ããè¨å®ãã¹ã«ãã£ã¦çºçãããç©´ãã¸ã®æ»æãè¦æãæ¹æ³ã解説ãã¾ãï¼ç·¨éé¨ï¼ â»ã注æ ä»ç¤¾ããã³ä»çµç¹ã®Webãµã¤ããªã©ã¸ã®ãã¼ãã¹ãã£ã³ããã³ãã¼ã¿ã®åå¾ãªã©ã®è¡çºã§å¾ãæ å ±ãä¾µå ¥ãªã©ã«æªç¨ããããã¾ãã¯åãç®çãæã¤ç¬¬ä¸è ã«æä¾ããæç¹ã§éæ³ã¨ãªãã¾ããã注æãã ããã æ¬ç¨¿ã®å 容ãæ¤è¨¼ããå ´åã¯ãå¿ ãå½±é¿ãåã¼ããªãéãããç°å¢ä¸ã§è¡ã£ã¦ä¸ããã ã¾ããæ¬ç¨¿ãå©ç¨ããè¡çºã«ããåé¡ã«é¢ãã¾ãã¦ã¯ãçè ããã³ã¢ã¤ãã£ã¡ãã£ã¢æ ªå¼ä¼ç¤¾ã¯ä¸å責任ãè² ãããã¾ãããäºæ¿ãã ããã ä¸æ£ä¸ç¶ãè¸ã¿å°ã¨ãã£ãèå¼±ãªãã¹ãã®æªç¨ ã¤ã³ã¿ã¼ãããä¸ã«ã¯ã
httpéä¿¡ã«ãããã»ãã¥ãªãã£é¢ä¿ã§CONNECTã¡ã½ããã¨ããè¨èãèããã¨ãçµæ§ããã¾ãã ãããã·ã§ã®httpséä¿¡ãå®ç¾ããã«ãéè¦ãªã®ã§ãä»åã¯CONNECTã¡ã½ããã«é¢ãã¦è§£èª¬ãã¾ãï¼ ãããã·ãè¦ããªããã°ãªããªããã®ã¯ï¼ CONNECTã¡ã½ããã¨ã¯ä½ãï¼ãç¥ãããã«ãå ãã¯ãããã·ã®ã話ããå§ãã¾ãã ãããã·ã¯HTTPéä¿¡ã代çãã¦ãããã¨ãã大å¤ä¾¿å©ãªå½¹å²ãããã¾ãã大ããªä»çµã¿ã¨ãã¦ã¯ãã¯ã©ã¤ã¢ã³ãã®ãªã¯ã¨ã¹ãhttpã®ãã¤ãã¼ãï¼ãã¼ã¿ã®ä¸èº«ï¼ãè¦ã¦ããªã¯ã¨ã¹ããããã¼ã¸ã®ãã¹åï¼"/"ã¹ã©ãã·ã¥ä»¥ä¸ãã¤ã¾ãFQDN以éï¼ããµã¼ãã«æ¸¡ãã¦ããããã·ã«è¿ã£ã¦ããhttpã¬ã¹ãã³ã¹ãã¯ã©ã¤ã¢ã³ãã«è¿ããã¨ãããã®ã§ãã ä¾ãã°ããhttp://itmanabi.com/connect-method/ãã¨ããURLã¸ã¢ã¯ã»ã¹ããå ´åã FQDN以éã®ã/connect-
以ä¸ã®ç»åã¯Squidã®éä¿¡ãTcpdumpãããã®ã§ãã å®å ã¯Appleã®ã©ããã®ãã¼ã¸ã§ããAppleã®ãµã¤ãã¯HTTPSã«ããã¢ã¯ã»ã¹ã«ãªã£ã¦ãããTLSã§æå·åããã¦ãã¾ãããã®ãããå®å URIã¯ãµã¼ãåã¾ã§ãã表示ãããªãã§ããããã®å¾ã¯TLSã®ããåããå§ã¾ããåé¡ãªããã°æå·åãããHTTPã®ã¢ããªã±ã¼ã·ã§ã³ãã¼ã¿ã®éä¿¡ãéå§ããã¾ãã CONNECTã¡ã½ãã ã¯ã©ã¤ã¢ã³ãããããã·çµç±ã§HTTPSéä¿¡ãããå ´åãHTTPçã«ã¯é常CONNECTã¡ã½ããã使ç¨ãã¾ããCONNECTã¡ã½ããã¯HTTP1.1ã§å®è£ ãããã¡ã½ããã§ããCONNECTã¡ã½ããã使ãã¨HTTP以å¤ã®ãããã³ã«ããã³ãã«ããããã«æ示ãåºããã¨ãã§ãã¾ãããã®å ´åã¯ãããã·ãµã¼ãã«å¯¾ãã¦TLSéä¿¡ããã³ãã«ããããã«æ示ãåºããã¨ã«ãªãã¾ããç°¡åæ¸ãã¨ä»¥ä¸ã®é åºã§å¦çãè¡ããããã¯ãã§ãã CONNE
Wizard Bibleäºä»¶ï¼ã¦ã£ã¶ã¼ãã»ãã¤ãã«ãããï¼ã¨ã¯ãã¦ã§ããµã¤ããWizard Bibleãã®ç®¡çè ãã¦ã¤ã«ã¹ã®ããã°ã©ã ãå ¬éããã¨ãã¦2018å¹´3æã«ç¥å¼èµ·è¨´ããã¦ç½°éåãåããåå¹´4æã«ãµã¤ããééãããããäºä»¶ã§ããã è¿ãææã«ãã£ãCoinhiveäºä»¶ãã¢ã©ã¼ãã«ã¼ãäºä»¶ï¼ç¡éã¢ã©ã¼ãäºä»¶ï¼ã¨ã¨ãã«ä¸æ£æ令é»ç£çè¨é²ã«é¢ãã罪ã®ãé©ç¨ç¯å²ã®ææ§ãããæ¸å¿µããã[1][2]ã ã¦ã§ããµã¤ããWizard Bibleãã¯æ å ±ã»ãã¥ãªãã£ããããã³ã°ãªã©ã«é¢ããæè¡æ å ±ãæä¾ãã管çè ãã¯ãããã¨ã³ã¸ãã¢ãç 究è ãè¤æ°ãæ稿ãã¦ãã[3]ã 2017å¹´6æ20æ¥ãåãµã¤ãã«æ稿ãã¦ããå°å¹´ãä¸æ£ã¢ã¯ã»ã¹ç¦æ¢æ³éåã®çãã§é®æãã[4]ã7æ11æ¥ã«å¦åä¿çã¨ãªã£ãããåæ¥ä¸æ£æ令é»ç£çè¨é²ä½æã®çãã§åé®æããã[5][6]ã å°å¹´ããWizard Bibleãã«æ稿ãã
ã¯ãã¹ãµã¤ããªã¯ã¨ã¹ããã©ã¼ã¸ã§ãª (cross-site request forgery) ã¯ãWebã¢ããªã±ã¼ã·ã§ã³ã®èå¼±æ§ã®ä¸ã¤[1]ãããã¯ãããå©ç¨ããæ»æãç¥ç§°ã¯CSRFï¼ã·ã¼ãµã¼ã (sea-surf) ã¨èªã¾ããäºããã[2][3]ï¼ãã¾ãã¯XSRFããªã¯ã¨ã¹ãå¼·è¦[4]ãã»ãã·ã§ã³ã©ã¤ãã£ã³ã° (session riding[3]) ã¨ãå¼ã°ããã1990年代ã¯ã¤ã¡ã¿ã°æ»æã¨ãå¼ã°ãã¦ãã[è¦åºå ¸]ãèå¼±æ§ãããªã¼åã«åé¡ããCWEã§ã¯CSRFããã¼ã¿èªè¨¼ã®ä¸ååãªæ¤è¨¼ (CWE-345) ã«ããèå¼±æ§ã®ã²ã¨ã¤ã¨ãã¦åé¡ãã¦ãã (CWE-352)[5]ã ãªãCSRFã®æ£å¼å称ã¯ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã° (XSS) ã¨ä¼¼ã¦ããããXSSã¯ä¸é©åãªå ¥åç¢ºèª (CWE-20) ã«ããã¤ã³ã¸ã§ã¯ã·ã§ã³ (CWE-74) ã®ã²ã¨ã¤ã¨ãã¦åé¡ããã¦ãã[5]ãå ¨ãç°ãªã種é¡ã®
ãªã¹ã¯ãè¦ã¤ãã ãµã¤ãã¼æ»æãé²ãæ大ã®å¯¾çã¯ãèªç¤¾ã®ã·ã¹ãã ã®èå¼±æ§ããªãããã¨ã§ããããããããè¤éåã»é«åº¦åããæ å ±æè¡ããå®ç§ãªç¶æ ã«ä¿ã¤ãã¨ã¯å°é£ã§ãã GSXã¯1997å¹´ãããããã¬ã¼ã·ã§ã³ãã¹ããã¯ããã¨ããèå¼±æ§è¨ºæãæä¾ãè±å¯ãªå®ç¸¾ã¨ãã¦ãã¦ãèç©ãã¦ãã¾ããã¾ããã»ãã¥ãªãã£äººææè²ãè¡ãã常ã«ææ°ã®ãµã¤ãã¼ãªã¹ã¯ããã£ããã¢ãããã¦ãã¾ãã è±å¯ãªçµé¨ã¨é«åº¦ãªã»ãã¥ãªãã£æè¡ãæã£ãå°é家ãã診æãã¼ã«ã¨æåãªãã¬ã¼ã·ã§ã³ãä½µç¨ãããµã¤ãã¼æ»æã®èµ·å ã¨ãªãã»ãã¥ãªãã£ã®æ¬ é¥ãçºè¦ãã¾ããçºè¦ããæ¬ é¥ï¼èå¼±æ§ï¼ã«ã¤ãã¦ãæè¡çãã¤äººçæè²ã®ç¹ããæé©ãªå種ã½ãªã¥ã¼ã·ã§ã³ããææ¡ãã¾ãã ãµã¤ãã¼æ»æãé²ãæ大ã®å¯¾çã¯ãèªç¤¾ã®ã·ã¹ãã ã®èå¼±æ§ããªãããã¨ã§ããããããããè¤éåã»é«åº¦åããæ å ±æè¡ããå®ç§ãªç¶æ ã«ä¿ã¤ãã¨ã¯å°é£ã§ãã GSXã¯1997å¹´ãããããã¬ã¼ã·ã§
â»2013/01/24 add: 徳丸å çã®æ¸ãããå®ã¯ãããªã«æããªãTRACEã¡ã½ãã | 徳丸浩ã®æ¥è¨ãå ã«è¦ã¦ããããªã¹ã¹ã¡ãã¾ããæ·±ã追æ±ã§ãã¦ããªãã¾ã¾è¨äºã«ãã¦ãã¾ãç³ã訳ããã¾ããã ã¿ã¤ãã«ã®éãã§ããHTTPã®ã¡ã½ããã«ã¯ããã使ããã®ã¨ãã¦GETãPOSTã¨ãããã®ãããã¾ãããTRACEã¡ã½ããã¨ãããã®ãããã¾ãã¦ããããæå¹ã«ãã¦ããã¨å±ãªããã¨ãã話ãã§ãã TRACEã¡ã½ããã«ã¤ã㦠ç¾èã¯ä¸è¦ã«ããããã©ããªæåããããè¦ã¦ããã¾ãããã $ telnet example.org 80 Trying example.org... Connected to example.org. Escape character is '\^]'. TRACE / HTTP/1.1 #ãã㨠HOST: example.org #ãããæã§å ¥åãã¦ãã¨ã³ã¿ã¼ãã¼äºåãã®ã
HTTPã®TRACEã¡ã½ãããæªç¨ããå¤ãæ»æææ³ã«ãCross Site Tracing(XST)ãã¨ãããã®ãããã¾ãããã®æ»æææ³ãæªç¨ããã¨ã第ä¸è ã Cross Site Scriptingï¼XSSï¼ã®èå¼±æ§ãåå¨ããWeb ãµã¤ãã¨ãã©ã¦ã¶ã®éã§ããåãããã HTTP ãªã¯ã¨ã¹ãã»ããããåå¾ã§ãã¦ãã¾ãã¾ãããã®ææ³ã¯ä¸è¬çã« HTTP ãªã¯ã¨ã¹ãã»ãããã«å«ã¾ãã Authorization ãããã Cookie ãããã奪åããããã«æªç¨ãããããã§ããã XST ã§ã¯ä¸è¬çã« JavaScript ã§XMLHttpRequest ãªãã¸ã§ã¯ããæªç¨ããããã§ãããææ°ã®ãã©ã¦ã¶ã§ã XMLHttpRequest ãªãã¸ã§ã¯ã㧠TRACE ã¡ã½ããã® HTTP ãªã¯ã¨ã¹ããéä¿¡ã§ããã®ã§ãããããã¨ããã®ããW3C ã® XMLHttpRequest ãªãã¸ã§ã¯ãã«é¢
Wizard Bibleã¯2018å¹´4æ22æ¥24æã«ééãã¾ããã æ稿è ãèªè ã®çæ§ãããã¾ã§ã®éæ¬å½ã«ãããã¨ããããã¾ããã ã2021å¹´6æ27æ¥æ´æ°ã Wizard Bibleã®è¨ç«ããééã¾ã§ã«è³ãéç¨ã詳細ã«è¿°ã¹ãæ¬ãåºããã¨ã«ãªãã¾ããã ãWizard Bibleäºä»¶ããèãããµã¤ãã¼ã»ãã¥ãªãã£ãå·çããã¸ã§ã¯ã èå³ã®ããæ¹ã¯æ¯éèªãã§ã¿ã¦ãã ããã Security Akademeiaã«æ»ã
Cross-Site Tracing(XST)ã¨ããåç³ã®ãããªæ»æææ³ãããã¾ãããåç³ãã¨æ¸ããããã«ãæ¢ã«ç¾å®çãªå±éºæ§ã¯ãªãã®ã§ãããXSTã«é¢é£ãã¦ãTRACEã¡ã½ããã¯å±éºãã¨ããã³ã¡ã³ããä»ã§ãè¦ããã¨ãããã¾ãã ãã®ã¨ã³ããªã§ã¯ãXSTã¨ããæ»æææ³ã«ã¤ãã¦èª¬æããXSTããã³TRACEã¡ã½ããã«ã¤ãã¦ã©ãèããã°ããããç´¹ä»ãã¾ãã TRACEã¡ã½ããã¨ã¯ HTTP 1.1(RFC2616)ã§ã¯ã8種é¡ã®ã¡ã½ãããå®ç¾©ããã¦ãã¾ããGETãPOSTãHEADãªã©ã¯ããªãã¿ã®ãã®ã§ããããã以å¤ã«PUTãDELETEãOPTIONSãTRACEãCONNECTã®5種ãããã¾ãã ãã®ãã¡ãTRACEã¡ã½ããã¯ãHTTPãªã¯ã¨ã¹ããããªã¦ã è¿ãã«ãHTTPã¬ã¹ãã³ã¹ã¨ãã¦è¿ããã®ã§ã以ä¸ã®ããã«GETçã®ä»£ããã«TRACEã¨ãã¦Webãµã¼ãã¼ã«ãªã¯ã¨ã¹ããã¾ãã TRACE
HTTP ã¬ã¤ã HTTP ã®æ¦è¦ å ¸åç㪠HTTP ã»ãã·ã§ã³ HTTP ã¡ãã»ã¼ã¸ MIME ã¿ã¤ãï¼IANA ã¡ãã£ã¢ç¨®å¥ï¼ HTTP ã®å§ç¸® HTTP ãã£ãã·ã¥ HTTP èªè¨¼ HTTP Cookie ã®ä½¿ç¨ HTTP ã®ãªãã¤ã¬ã¯ã HTTP æ¡ä»¶ä»ããªã¯ã¨ã¹ã HTTP ç¯å²ãªã¯ã¨ã¹ã ã³ã³ãã³ããã´ã·ã¨ã¼ã·ã§ã³ HTTP/1.x ã®ã³ãã¯ã·ã§ã³ç®¡ç HTTP ã®é²å ãããã³ã«ã®ã¢ããã°ã¬ã¼ãã®ä»çµã¿ ãããã·ãµã¼ãã¼ã¨ãã³ããªã³ã° HTTP ã¯ã©ã¤ã¢ã³ããã³ã HTTP ã»ãã¥ãªã㣠ãµã¤ãã®å®å ¨å HTTP Observatory Permissions Policy ã³ã³ãã³ãã»ãã¥ãªãã£ããªã·ã¼ (CSP) ãªãªã¸ã³éãªã½ã¼ã¹å ±æ (CORS) Cross-Origin Resource Policy (CORP) Strict-Transport-Securit
ã¿ã¤ãã«ã¯é£ãããã¤ãèªåã®ããã®åå¿é²ã§ãã ãã¤ã¯ããµã¼ãã¹ã¢ã¼ããã¯ãã£ã§ãµã¼ãã¹ãæ§ç¯ããã¨ãAPIãµã¼ãããµã¼ãã¹ãã¨ã«ç«ã¦ãããã§ããã ãã©ã¦ã¶ä¸ã®JSã¨ã³ã¸ã³ããAPIãµã¼ããå©ãæã«é¿ãã¦éããªãã®ããSame-Origin Policyï¼åä¸çæå ããªã·ã¼ï¼ã«ããCORS (Cross-Origin Resource Sharing)å¶éã§ãã ãããåé¿ããã«ã¯ãAPIãµã¼ãå´ã§Access-Control-*ããããé©åã«è¿ãå¿ è¦ãããã¾ãããã©ãè¨å®ããã¹ããã®æ å ±ãæå¤ã¨å°ãªãã®ã§ï¼èªåçï¼ããã決å®çï¼ãã¨ããè¨å®ãèãã¦ã¿ã¾ããã çµè« nginxã®å ´åã®è¨å®ä¾ã§ãã server { listen 80; server_name site.localhost; charset utf-8; root /var/www/app/public; locatio
REST APIã«ã¢ã¯ã»ã¹ããéã«ããã©ã¦ã¶ãAPIãµã¼ãã«å¯¾ãã¦HTTPï¼ãããã¯HTTPSï¼ã®OPTIONSã¡ã½ããã§ãªã¯ã¨ã¹ããæãããã¨ãããã¾ãã æ¬è¨äºã§ã¯ããã®ç¾è±¡ã®è§£èª¬ã¨ãNode.jsã§APIãµã¼ããå®è£ ãã¦ããå ´åã®OPTIONSã¡ã½ããã¸ã®å¯¾å¿æ³ãè¨è¿°ãã¾ãã HTTPã®OPTIONSã¡ã½ããã¨ã¯HTTPã§ä¸è¬ã«ä½¿ãããã¡ã½ããã¨ããã°ãGETãPOSTã§ãããREST APIãé »ç¹ã«å©ç¨ãã人ãªãã°ãPUTãDELETEãå©ç¨ãããã¨ãããã§ãããããµã¼ãã®ãã¹ãã®ããã«HEADã¡ã½ãããå©ç¨ãããã¨ããã人ãããããããã¾ããã OPTIONSã¡ã½ããã¯ããããã®ã¡ã½ããã®ãã¡ããµã¼ããã©ã®ã¡ã½ããããµãã¼ããã¦ãããã調æ»ããããã®ã¡ã½ããã§ãã æ¨ä»ã®ãã©ã¦ã¶ã§ã¯ãããã³ãã¨ã³ãJavaScriptããéããã¡ã¤ã³ã¸ã®ã¢ã¯ã»ã¹ã«å¯¾ãã¦ãCross-Origin
Amazon API Gatewayã§CORSãæå¹ã«ããã¨OPTIONSã¡ã½ããã追å ãããã®ãæ°ã«ãªã£ãã®ã§ãCORSã«ã¤ãã¦å°ã調ã¹ã¾ããã CORSã¨ã¯ ãªãªã¸ã³éãªã½ã¼ã¹å ±æCross-Origin Resource Sharing (CORS) ã¯ã追å ã® HTTP ãããã¼ã使ç¨ãã¦ããããªãªã¸ã³ (ãã¡ã¤ã³) ã§åä½ãã¦ããã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã«ãç°ãªããªãªã¸ã³ã®ãµã¼ãã¼ã«ããé¸æããããªã½ã¼ã¹ã¸ã®ã¢ã¯ã»ã¹ã許å¯ãããã¨ãã§ããä»çµã¿ã§ããã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ã¯ãèªåã®ãªãªã¸ã³ã¨ã¯ç°ãªããªãªã¸ã³ (ãã¡ã¤ã³ããããã³ã«ããã¼ãçªå·) ãããªã½ã¼ã¹ããªã¯ã¨ã¹ãããã¨ãããªãªã¸ã³é HTTP ãªã¯ã¨ã¹ããçºè¡ãã¾ãã*1 ã¯ã©ã¤ã¢ã³ããµã¤ãã®å®è£ ã¯ãæè¿ã§ã¯IEã®ããä¸é¨ã®ãã©ã¦ã¶ä»¥å¤ã§å®è£ ããã¦ãã¦ãJavaScriptã§ç°ãªããã¡ã¤ã³ã®ãµã¼ãã¸ã¢ã¯ã»ã¹ãããã¨ããæã«ã
ï¾ï½·ï¾ï½¬ï¾ @fumin_kamin èªåã®ä¸å¿«ã«ã¯ç°å¸¸ã«ç¹ç´°ã§æ³¨æãå¤ãã®ã«ä»äººã®ããã¯ã«ããããããã¨ã¯å ¨ãæ³å®ã§ãã¦ãªãæãã¨ãããã®ãã¨ã説æããã¨ãã«ããããèªåã®ä¸ç観ã®ç¨èªã使ã£ã¡ããæãã¨ãããã¢ã½å«ããå ¬è¨ããããã«çéã®ã½ã¼ã·ã£ã«ã«ã©ã£ã·ãæ²¼ã£ã¦åæã«åå±ã«ãªã£ã¦ãæãã¨ãããâ¦ããããâ¦ããâ¦
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}