You signed in with another tab or window. Reload to refresh your session. You signed out in another tab or window. Reload to refresh your session. You switched accounts on another tab or window. Reload to refresh your session. Dismiss alert
npmå²ä¸ææªã®ãµãã©ã¤ãã§ã¼ã³æ»æãShai-Hulud 2.0ããæ£è¦ããã±ã¼ã¸ã®ã¡ã³ããã¼èªè¨¼æ å ±ãçã¿ãæªæãããã¼ã¸ã§ã³ãnpmã«å ¬éããã¨ããæå£ã§ã11æ21æ¥ããæ¥éã«æ¡æ£ãã¾ããã ãã®è¨äºã§ã¯2ã¤ã®ãã¨ã解説ãã¾ãï¼ èªåã被害ã«ãã£ã¦ããªãã確èªããæ¹æ³ ä»å¾ã®è¢«å®³ãé²ãå¤å±¤é²å¾¡ã¢ããã¼ã *ãã®è¨äºã¨åãå 容ãåç»ã§ã解説ãã¦ãã¾ãã®ã§ãåç»ã®æ¹ã好ããªæ¹ã¯ä¸è¨ããã©ãã è¢«å®³ç¢ºèª - ããªãã¯å¤§ä¸å¤«ãï¼ Shai-Hulud 2.0ã¯11æ21æ¥ããæ¥éã«æ¡æ£ãã¾ããããã®æ¥ä»¥éã«npm installãå®è¡ãã人ã¯ãææã®å¯è½æ§ãããã¾ãã ãã§ãã¯1: GitHubã¢ã«ã¦ã³ãã®ç¢ºèªï¼ãã©ã¦ã¶ã§å®çµï¼ 確èªãã¤ã³ã1: è¦è¦ãã®ãªããªãã¸ã㪠ã¾ãGitHubã§èªåã®ãªãã¸ããªä¸è¦§ã確èªã Shai-Huludã¯ææããã¢ã«ã¦ã³ãã«ã©ã³ãã ãªååã®ãããªãã¯ãªã
Intro å¼ç¤¾ã§éçºãã¦ãããµã¼ãã¹ã®ããã¡ã¤ã³ã夿´ãããã¨ã«ãªã£ãã¨ãã®è©±ã ãã§ã«æ§ãã¡ã¤ã³ã§ä¸é¨é¡§å®¢ã«å©ç¨ãã¦ããã ãã¦ãããããæ§ãã¡ã¤ã³ã¯ç ´æ£ããã«æ°ãã¡ã¤ã³ã«ãªãã¤ã¬ã¯ããããããã«ãã¾ããã DNSã®è¨å®ãã³ã¼ããããããä¿®æ£ãããªãªã¼ã¹ããã¾ãããWebã¢ããªã触ã£ã¦ç»åã表示ãããããã¼ã¿ãå徿´æ°ã§ãããã¨ãé常éã使ãããã¨ã確èªãã¦ä¸å®å¿ãã¦ãã¾ããã åé¡çºç ãã§ã«ä½¿ã£ã¦ããã ãã¦ãã社å¤ã¦ã¼ã¶ã¼ãããç»åã表示ãããªããã¨é£çµ¡ãããã¾ããã ã¹ã¯ãªã¼ã³ã·ã§ãããè¦ãã¨ãããã«ç»åãåãã¦ALTããã¹ãã表示ããã¦ãã¾ããããããåãç»é¢ãèªåã®PCã§é²è¦§ããã¨æ£å¸¸ã«ç»åã表示ããã¦ãã¾ãã å æ¹ã®ãã¡ã¤ã¢ã¦ã©ã¼ã«ããã¯ã¤ããªã¹ãå¶ã«ã§ããªã£ã¦ããã®ãã¨æãããã¡ã¤ã¢ã¦ã©ã¼ã«ã®è¨å®ãã確èªãã ããã¨è¿çãã¾ãããã§ãããTCP/80(http)ã¨TCP/44
ç©é¨ãªä¸ã®ä¸ã§ããçæ§ãæ°ãã¤ããã ããã 3è¡ã§ã¾ã¨ã èªä½ã® OSSãfujiwara/apprun-cli ã®ãã«ã¦ã§ã¢å ¥ãå½ç©ãä½ãã㦠GitHub ã§å ¬éããã¾ãã å½ç©ã«ã¯å¤§éã®æ°è¦ã¢ã«ã¦ã³ããã¹ã¿ã¼ãä»ãã¦ãããããæ¤ç´¢ã§ãªãªã¸ãã«ã®ãã®ããä¸ä½ã«è¡¨ç¤ºãããç¶æ ã§ãã GitHub ã«éå ±ããã¨ãããå½ç©ãä½ã£ãã¢ã«ã¦ã³ãã¯banãããããã§ã çµç·¯ 2024å¹´æ«ã«ããããã®AppRunç¨ãããã¤ãã¼ã« apprun-cli ã¨ãã OSS ãå ¬éãã¾ããã github.com 2025å¹´2æ10æ¥ 12æéãã®ãã¨ãè¬ã®äººç©ã X ã§ apprun-cli ã宣ä¼ãã¦ããã®ãè¦ã¤ãã¾ããã ã©ãè¦ã¦ãèªåã®ç©ã¨åã(ã³ãã¼)ãªã®ã§ãããå¦ã«ã¹ã¿ã¼ãå¤ãããªãã¸ããªãã®ããã¦ã¿ãã¨ãfork ã§ã¯ãªãã³ã¼ãããã¹ã¦ commit å±¥æ´ãå¼ãç¶ããªãç¶æ ã§ã³ãã¼ãããã¹ã¿ã¼
Intro CSRF ã¨ããå¤ã®æ»æãããããã®æ»æããå¤(ãã«ãã)ãã®ãã®ã«ãããã¨ãã§ãããã©ãããã©ã¼ã ã®é²åã®èæ¯ãããCookie ã SameSite Lax by Default ã«ãªã£ãããã ãã¨ãã解説ãè¦ããã¨ãããã 確ãã«ãç¾å®çã«ããã«ãã£ã¦æ»æã®æç«ã¯é£ãããªããæããã¦ãããµã¼ãã¹ããããããããããã¯ãã©ãããã©ã¼ã ãç¨æãã対çã®æ¬è³ªããè¨ãã¨ãè§£éãå°ãããã¦ããã¨è¨ããã ããã ä»åã¯ããCSRF ãã©ããã¦æç«ãã¦ããã®ãããæ¯ãè¿ããã¨ã§ãæ¬å½ã«ãã©ãããã©ã¼ã ã«è¶³ãã¦ããªãã£ããã®ã¨ããããè£ã£ã¦ãã£ãçµç·¯ãæ¬å½ã«ãã¹ã対çã¯ä½ã§ãããã解説ãã¦ããã çµæã¨ãã¦è¦ãã¦ããã®ã¯ãä»ãµã¼ãã¹ãå®è£ ããä¸ã§ã®ããã¼ã¹ã(not ãã¹ã)ã¨ãªããã©ã¯ãã£ã¹ã ã¨çè ã¯èãã¦ããã CSRF æç«ã®æ¡ä»¶ ä¾ãã°ãæ»æè ãç¨æãã attack.examp
Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article? ã´ã¼ã«ãã³ã¦ã£ã¼ã¯ã®ã¯ããï¼4æ29æ¥ï¼ã«æç¨¿ããã以ä¸ã®ãã¤ã¼ãã§ããã5æ7æ¥20æã«ããã¦ã1,938.8ä¸ä»¶ã®è¡¨ç¤ºã¨ãããã¨ã§ãéå¸¸ã«æ³¨ç®ããã¦ãããã¨ãåããã¾ãã æãåã¯ã¢ã·ã¿ã«ï¼ã¹ã¿ãã®FreeWi-Fiã使ããªããä¼ç¤¾ã®æ©å¯æ å ±ãæ±ãä»äºããã¦ããå ¨é¨æããããã©ãããã°ããï¼ pic.twitter.com/e26L1Bj32Z â ã¹ã¿ãã§Macãéãã¨ã³ã¸ã㢠(@MacopeninSUTABA) April 29, 2023 ããã«å¯¾ãã¦ãç§ã¯ä»¥ä¸ã®ããã«ãã¤ã¼ããã¾ãããã ããå ¥ç¤¾è©¦é¨ã®åé¡ã«ãããããªãã
ã¯ããã« çããããã«ã¡ã¯ï¼3åçã®ããï¼@ran350jpï¼ã§ãï¼ æååãããã³ã°ã«ä¾¿å©ãªæ£è¦è¡¨ç¾ã§ããï¼ãããã¼ã«æ¸ãã¨èå¼±ã«ãªãå¾ãã¨ããæ å ±ãè³ã«ãã¦ããè²ã ã¨åå ã対çã調ã¹ã¦ãã¾ããï¼ ãããï¼å¤ãã®è¨äºã§ç´¹ä»ããã¦ããå¯¾çæ¹æ³ã¯ï¼ãç¬èªã®æ£è¦è¡¨ç¾ã使ç¨ããªãã¼ãã¨ãã * ã + ãªã©ã®ç¹°ãè¿ã表ç¾ã¯ãªãã¹ã使ããªãã¼ãã¨ããã ãªãã¨ããµãã£ã¨ãããã®ã§ããï¼ããã§ã¯ãããã確ãã«ãããªãããããããã©â¦ãããã訳ã«ã¯ããããããâ¦ãã¨ç´å¾ã§ãã¾ããï¼ ã¤ã¾ãï¼ãæ¬è³ªçã«ä½ãåé¡ãã§ï¼ãå ·ä½çã«ã©ããªç¹å¾´ã®ããæ£è¦è¡¨ç¾ãèå¼±ã«ãªãå¾ãã®ãããç¥ããã訳ã§ãï¼ ããã§ï¼æ§ã ãªæç®ã調æ»ãã¦ã¿ã¾ããï¼æ¬è¨äºã§ã¯èª¿æ»ãã¦æºã¾ã£ãç¥è¦ãç´¹ä»ãã¦ããã¾ãï¼ æ¬è¨äºã¯ï¼ Purdue大å¦ã®James Davisææã«ãã âThe Regular Expression Denial
ð£ï¸ Heads up! New security scoring standards apply - Your website grade may have changed. MDN Observatory will launch soon. Learn More. The Mozilla Observatory has helped over 240,000 websites by teaching developers, system administrators, and security professionals how to configure their sites safely and securely.
ã¯ã¬ã¸ããã«ã¼ãæ å ±æ¼ããäºæ ã«é¢ãï¼ãã®åå ã®ä¸ã¤ã¨èããããèå¼±æ§å¯¾å¿ãéç¨ä¿å®æ¥åã«å«ã¾ãã¦ãããå¦ããäºãããäºä¾ã äºæ¡ã®æ¦è¦ Xã¯ï¼Xã®éå¶ããé販ãµã¤ãï¼æ¬ä»¶ãµã¤ãï¼ã第ä¸è ã«éçºå§è¨ãï¼éç¨ãã¦ãããï¼ãã®å¾ï¼2013å¹´1æããã¾ã§ã«ï¼Yã«å¯¾ãï¼æ¬ä»¶ãµã¤ãã®éç¨æ¥åãæé¡20ä¸åã§å§è¨ããï¼æ¬ä»¶å¥ç´ï¼ãæ¬ä»¶ãµã¤ãã¯EC-CUBEã§ä½ããã¦ããããªãï¼XããYã¸ã®æ¥åå§è¨ã«é¢ãï¼å¥ç´æ¸ã¯ä½æããã¦ãããï¼æ³¨ææ¸ã«ã¯ãæ¬ä»¶ãµã¤ãã®éç¨ï¼ä¿å®ç®¡çããECï¼ï¼£ï¼µï¼¢ï¼¥ã«ã¹ã¿ãã¤ãºãã¨ããè¨è¼ããã¦ããªãã 2014å¹´4æã«ã¯ï¼OpenSSL*1ã®èå¼±æ§ããããã¨ãå ¬è¡¨ãããã*2ï¼æ¬ä»¶ãµã¤ãã§ã¯ï¼OpenSSLãç¨ãããã¦ããã 2015å¹´5æããï¼Xã¯ï¼æ±ºæ¸ä»£è¡ä¼ç¤¾ããæ¬ä»¶ãµã¤ãããXã®é¡§å®¢æ å ±ï¼ã¯ã¬ã¸ããã«ã¼ãæ å ±ãå«ãï¼ãæ¼ãããã¦ããæ¸å¿µãããã¨ã®é£çµ¡ãåãï¼æ¬ä»¶æ å ±æ¼ããï¼
追è¨: ãã®å¾ã®åãã«ã¤ãã¦æ¸ãã¾ãã â Let's Encryptã®è¨¼ææ¸åæ¿å¨ããã®å¾ ãã®ãµã¤ãã¯Let's Encryptã§è¨¼ææ¸çºè¡ãã¦ããã®ã§ã¿ã¤ãã«ã®ä»¶ãæ°ã«ãªã£ãã®ã ããã©ãããã¾ã話é¡ã«ãªã£ã¦ããªããæ¥ããããªããSSLå¨ã詳ãããããããªãã®ã§ã誤ã£ã¦ããããç¥ããªããèè ã®æè¦ãæ±ãã Let's Encryptã使ããã¦ãããµã¤ããAndroid7.1以åã®ãã¼ã¸ã§ã³ã§ä»å¹´ã®9æ29æ¥ä»¥éè¦ãããªããªãå¯è½æ§ããã å»¶å½çã¯ç¨æããããã ãããããæ¥å¹´ã®9æ29æ¥ã¾ã§ Let's Encryptã®ã«ã¼ãè¨¼ææ¸åãæ¿ãè¨ç»ã«èµ·å ãã¦ãã Let's Encryptã®ã«ã¼ãè¨¼ææ¸ã®å¤æ´ Let's Encryptã¯ã«ã¼ãè¨¼ææ¸ãèªèº«(ISRG)ã®èªè¨¼å±ã®ã«ã¼ãè¨¼ææ¸(ISRG Root X1)ã«åãæ¿ãããã¨ãã¦ãããç¾å¨ã¯ãIdenTrustã®ã«ã¼ãè¨¼ææ¸(DST
â»ãã®åº§è«ä¼ã¯ç·æ¥äºæ 宣è¨ä»¥åã«å®æ½ãã¾ããã ã¤ã¨ã©ã¨ã»ãã¥ãªãã£ã®é¡§åãåããå·å£æ´ããã¤ã¨ã©ã¨ã»ãã¥ãªãã£ãæ¯ããå¤å½©ãªã¡ã³ãã¼ã¨å ±ã«ããµã¤ãã¼ã»ãã¥ãªãã£ããµã¤ãã¼ãªã¹ã¯ã®ä»ãèªãåã座è«ä¼ã·ãªã¼ãºã第11åããéããã¾ãã å·å£æ´æ°ã¯ãæ ªå¼ä¼ç¤¾å·å£è¨è¨ 代表åç· å½¹ã¨ãã¦ãæ å ±ã»ãã¥ãªãã£EXPOãInteropãåé½éåºçè¦ã®ãµã¤ãã¼ãã対çåè°ä¼ãªã©ã§è¬æ¼ãå®å ¨ãªITãããã¯ã¼ã¯ã®å®ç¾ãç®æãã¦ã»ãã¥ãªãã£æ¼ç¿ãªã©ãæä¾ãã¦ãã¾ãã ã¤ã¨ã©ã¨é¡§åã¨ãã¦ããå·å£æ´ã®åº§è«ä¼ã·ãªã¼ãºãã2019å¹´ã«éå§ããµã¤ãã¼ã»ãã¥ãªãã£ãå·¡ãæ§ã ãªè©±é¡ãã社å å¤ã®ã²ã¹ãéã¨å ±ã«è«ãèªã£ã¦ãã¾ããï¼å·å£æ´ã®åº§è«ä¼ã·ãªã¼ãº)ã ä»åã²ã¹ãã¨ãã¦ç»å ´ããã®ã¯ãã¤ã¨ã©ã¨ã»ãã¥ãªãã£ã®ãããã¬ã¼ã·ã§ã³èª²ã«æå±ããé¦¬å ´å°æ¬¡ãWebãã¶ã¤ãã¼ã¨ãã¦ã®çµé¨ãããWebã«é¢ããã»ãã¥ãªãã£ã¸ã®éãè¦ç¹ãæã¤é¦¬å ´ã
å æ¥ window.open ããããã¨ããããããã¢ãããããã«ã¼ã«é»ã¾ã㦠open ãããã¨ãã§ããªãã£ãï¼ Blocked ã¾ãï¼ãããªããããããã¨ãªã®ã ãï¼ãããããèªåã®è¨æ¶ã§ã¯ onClick ã®ãããªã¦ã¼ã¶ã¼ã®ã¢ã¯ã·ã§ã³å ã§éããã window.open ã¯é»ã¾ããªããã¨ã«ãªã£ã¦ãã¨æã£ã¦ããï¼ã ãããã®ã¨ãã onClick ã®ã¤ãã³ããã³ãã©å ã§ window.open ãããã大ä¸å¤«ã ããï¼ã¨æã£ã¦ãããï¼è¦äºã«ãããã¯ããã¦ãã¾ã£ãã®ã§ãªãã ããï¼ã¨ãªã£ã¦ããï¼ æ¤è¨¼ ãªã®ã§ï¼æ¤è¨¼ããããã« 3 ã¤ã®ã±ã¼ã¹ãç¨æãã¦ã¿ã: æ¤è¨¼ãã¼ã¸ãç¨æããã®ã§ããªãã®ç°å¢ã§ã試ãã¦ã¿ã¦ã⥠ä»å試ããã©ã¦ã¶ã¯ Google Chrome ãåæã«ãã¦ã¾ã ã±ã¼ã¹1 const immediate = () => { window.open('https://www.goog
å³ã«ããã¨ä»¥ä¸ã®ããã«ãªãã¾ãã Strict å¤é¨ãµã¤ãããã®ã¢ã¯ã»ã¹ã§ã¯Cookieãéããªãã Lax å¤é¨ãµã¤ãããã®ã¢ã¯ã»ã¹ã¯GETãªã¯ã¨ã¹ãã®ã¨ãã ãCookieãéãã None 徿¥éãã®åãã ã追è¨ããªãChrome 80以éã§Secure屿§ãä»ããSameSite=Noneãæå®ããå ´åãset-cookieèªä½ãç¡å¹ã«ãªãã¾ãã ã»ãã¥ãªãã£ä¸ã®å¹æ CSRF対çã«ãªãã¾ãã CSRF (ã¯ãã¹ãµã¤ãã»ãªã¯ã¨ã¹ãã»ãã©ã¼ã¸ã§ãª) ã¨ã¯ã WEBãµã¤ããã¦ã¼ã¶ã¼æ¬äººã®æå³ããåä½ã§ãããã¨ãæ¤è¨¼ãã¦ããªãããã«ãããèå¼±ã§ãã ãã¨ãã°ä¼å¡ã®éä¼ãã¼ã¸ã https://example.com/mypage/delete/ã§ç¨æãã ãã¿ã³æä½ã§submit=1ãéä¿¡ããã¦éä¼å¦çãå®è¡ããã仿§ã®å ´åã ãã©ã¡ã¼ã¿ã誰ã§ããããã®ã§ãå¤é¨ã«ç¨æãããæªæã®ãããã©
ã¯ããã¾ãã¦ã2019å¹´1æã«å ¥ç¤¾ããSREã¹ãã·ã£ãªã¹ãã®sonotsã§ããæè¿MLOpsãã¼ã ã®ãªã¼ãã¼ã«ãªãã¾ãããä»åã®è¨äºã¯MLOpsã®æ¥åã¨ã¯é¢ä¿ããªãã®ã§ããã3æã«å¼ç¤¾ã§å®æ½ããä¼ç¤¾ç¨GitHubå人ã¢ã«ã¦ã³ãã®å»æ¢ã«ã¤ãã¦äºä¾å ±åãã¾ãã TL;DR ä¼ç¤¾ç¨GitHubã¢ã«ã¦ã³ããä½ãã¹ããå¦ãåé¡ ä¼ç¤¾ç¨GitHubã¢ã«ã¦ã³ãã®å©ç¨ã§æ±ããåé¡ 1. OSSæ´»åæã«ã¢ã«ã¦ã³ããåãæ¿ããå¿ è¦ãããé¢å 2. GitHubã®è¦ç´ã«æºæ ãã¦ããªã ä¼ç¤¾ç¨ã¢ã«ã¦ã³ãã廿¢ããå ´åã«ã»ãã¥ãªãã£ãã©ã®ããã«æ ä¿ããã GitHubã®SAML single sign-on (SSO)æ©è½ã«ã¤ã㦠ä¼ç¤¾ç¨ã¢ã«ã¦ã³ãã®å»æ¢ããã³SSOæå¹åã®å®æ½ ä¼ç¤¾ç¨GitHubã¢ã«ã¦ã³ãã使ãç¶ããå ´å ç§ç¨GitHubã¢ã«ã¦ã³ãã«åãæ¿ããå ´å Botã¢ã«ã¦ã³ãã®å ´å Outside Coll
Posted: 2019å¹´3æ14æ¥ / Last updated: 2022å¹´6æ6æ¥ / ãªã¼ã¬ããã¯åº¦: 100% / Read in English 䏿£ééãã¢ã«ã¦ã³ãã®ä¹ã£åããªã©ããã¹ã¯ã¼ããåå ã®äºä»¶ãå¾ãçµ¶ã¡ã¾ãããé«é½¢è ãªã©ãIT ãªãã©ã·ã®ä½ã人ã§ãç°¡åãã¤å®å ¨ã«èªåã®ãªã³ã©ã¤ã³ã¢ã«ã¦ã³ãã管çã§ããä¸çãçæ³ã§ãããã¾ãã¯ãã¹ã¯ã¼ãã®ä¸è¦ãªä¸çãå®ç¾ããã®ãå æ±ºã§ãããã¨ã¯ãããã¾ã§ã®ã¤ã³ã¿ã¼ãããã®æ´å²ã§è¨¼æãããã¨è¨ããã§ããããããã¦ãããã«æ¥ã¦ãã¹ã¯ã¼ãä¸è¦ãªãã°ã¤ã³ãå®ç¾ããæè¡ã¨ãã¦æ³¨ç®ããã¦ããã®ã FIDO (= Fast IDentity Online, ããã¡ã¤ãã) ã§ããããã¦ãã® FIDO ããã©ã¦ã¶ããå©ç¨ã§ããããã«ããã®ã WebAuthn (= Web Authenticationããã¦ã§ããªã¼ã¹ã³ã)ãå ±éå 容ãªã©ãããããã¯æç´
1. ã¯ããã« æè¿ãããã£ã¦Nodeã®ã»ãã¥ãªãã£èª¿æ»ããã¦ããã®ã§ãããä»å¹´ã®5æã«éå¬ããã North Sec 2018 ã§ã»ãã¥ãªãã£ç ç©¶è ã® Olivier Arteau æ°ã«ãã ãPrototype pollution attacks in NodeJS applicationsãã¨ããé¢ç½ãçºè¡¨ãè¦ã¤ãã¾ããã ãã®çºè¡¨ã®è«æãçºè¡¨è³æããã¢åç»ãªã©ãgithubã§å ¬éããã¦ãã¾ãããã¡ããã©ã¿ã¤ãã³ã°ããã»ãã·ã§ã³åç»ãæè¿å ¬éããã¾ããã github.com Olivier Arteau -- Prototype pollution attacks in NodeJS applications ãã®çºè¡¨ã§è§£èª¬ããã¦ããã®ã¯ãæªæã®ããæ»æè ããJavaScriptè¨èªåºæã®ãããã¿ã¤ããã§ã¼ã³ã®æåãå©ç¨ãã¦ãWebãµã¼ããæ»æããæ¹æ³ã§ãã çºè¡¨è ã¯ãnpmããã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãç¥ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}