[æµ·å¤ã®ä½å¦ãã®æµ·è¾ºã§ã綺éºãªè¹ãåºã¦ããã®ãè¦ã¦ã¬ãããã¼ãºãã¦ããç½äººç·æ§ã®èä¸ï¼ã®åçç´ æï¼] âããããä½ã®æå³ããªããèªåã§æ®ã£ãããã§ããªããã©ããã®ãµã¤ãããæåããã ãã®ãããªåçãæ¯åã¨ã³ããªã®é ã«ä»ããªãã¨ãããªãç¿æ £ãä½ãªã®ï¼ [ã¹ãã³ãµã¼ããªã³ã¯] âãããããã¨ã³ããªã®æ¸ãå§ãã®åã«ããªããã¢ãã£ãªã¨ã¤ããªã³ã¯ãã¤ããç¿æ £ãä½ãªã®ï¼ [ã¹ãã³ãµã¼ããªã³ã¯] âãã¨ã段è½ã®éä¸ã«ãæ¯åå ¥ãã¦ãããã¹ãã³ãµã¼ããªã³ã¯ããä½ãªã®ï¼ [ã¹ãã³ãµã¼ããªã³ã¯] ããã¾ã§ãã¦ãéãã»ããã®ï¼å¿ æ»ãªã®ï¼ã£ã¦è¨ãã¨ã決ã¾ã£ã¦ãéã«ãªãããªããªããããããªã®ã§å²ãã£ã¦ãã¨æã£ã¦ã人ã¯ä¸éç¥ããããæéã§èãããåããã»ããæ©ãããæéããã¦æ´æ°ãã¦ããã ããå¤å°ã®å¯¾ä¾¡ãçºçãã¦ããã®ã¯å½ç¶ã ãã£ã¦è¨ããããªãï¼ ããããªãã§æ¯åæ¯åããããã¨æéããã¦è¨³ã®åãããªãåçã調éãã¦ï¼ã
è¿å¹´ããã¤ãã£ãã®ã¢ããªãHTML5ã ãã§éçºã§ããOSããæ³¨ç®ãéãã¦ãã¾ããæ¬è¨äºã§ã¯ã2014å¹´å ã«æ¥æ¬ã§ã®è£½åçºå£²ãæå¾ ãããGoogleã®Chrome OSã¨Mozillaã®Firefox OSã®æ¦è¦ãç´¹ä»ãã¾ãã PCã®å©ç¨æéã®å¤§åãWebã«è²»ããã¦ãã人ããWebãã©ã¦ã¶ä»¥å¤ã®ã¢ããªã¯ä½¿ç¨ããªãã¨ãã人ã¯å°ãªãããã¾ãããChrome OSã¯ãã®ããã«ãWebã®ããã«PCãå©ç¨ããã¦ã¼ã¶ã¼ã«ã¨ã£ã¦ãæé©ãªãã©ã¦ãºç°å¢ãæä¾ãããã¨ãç®çã¨ãã¦éçºãããOSã§ããç±³NPDã®èª¿æ»ã«ããã°ãChrome OSãæè¼ãããã¼ãPCã§ããChromebookã¯ã2013å¹´å ã«ç±³å½ã§è²©å£²ããããã¼ãPCã®21ï¼ ãå ããçå®ã«ã·ã§ã¢ã伸ã°ãã¦ãã¾ãã Chrome OSã®ã¢ã¼ããã¯ã㣠Chrome OSã¯ãChromium OSã¨ãããªã¼ãã³ã½ã¼ã¹ã®OSããChromebookã«æé©å
USBã¯ããã®å½åããã®ãã¼ã¿è»¢éã®ç¨éã ãã§ãªããæºå¸¯é»è©±æ©ã®å é»ç¨éã«ãç¨ããããããã«ãªã£ããããããåããåããæè¿ã«ãªã£ã¦ãUSBã®å©ç¨ãæ¡å¤§ãããã¨ããæ°ããªè¦æ ¼ãããã¤ãå¶å®ãããããã®çµæãå é»ç¨éã®è¨è¨ãç°¡æ½ã«è¡ããããã«ãªã£ã¦ãã¦ãããæ¬ç¨¿ã§ã¯ãå é»ç¨éã®USBæ°è¦æ ¼ã¨ãããã«å¾ã£ãå é»å¨ã®æ§æä¾ãç´¹ä»ããã USBãå·¡ãæ°è¦æ ¼ USBï¼universal serial busï¼ã¯ãç¹ã«æºå¸¯åæ©å¨ã®åéã«ããã¦æãåºãæ®åããæ¥ç¶æè¡ã«ãªã£ãããã®å©ç¨ãä¸è¬åãããã¨ãåãã¦ãUSB-IFï¼USB Implementers Forumï¼ã¯2001å¹´12æã«USB-OTGï¼On-The-Goï¼ãçå®ãããããã«ãããã½ã³ã³ãçµç±ããªãã§USB対å¿ã®æ©å¨åå£«ãæ¥ç¶ãããã¨ãå¯è½ã¨ãªããããã«ãã®å©ç¨ãæ¡å¤§ãã¦ãã¦ããã ç¨éã®åºããã¯ãããªã³ãé ç·æ¿ã®çã¹ãã¼ã¹åãé¨åã®ã
OWASP AppSec APAC 2014 ã§ãMasato Kinugawaãããmalaããã¨ä¸ç·ã«ããXSS Allstars from Japanãã¨ããæ ã§ç»å£ãã¾ããã3人ãããã好ããªãã¼ãã«ã¤ãã¦çºè¡¨ãããã®ã§ãããåã¯ãMasato Kinugawaãããæ´»ç¨ãã¦ãããTabular Data Controlã«ã¤ãã¦çºè¡¨ãã¾ããã ã¹ã©ã¤ãã¯ä»¥ä¸ã§å ¬éããã¦ãã¾ãã Bypass SOP, Theft your data // Speaker Deck Masato Kinugawaããã®ã¹ã©ã¤ãã¯ãã¡ãï¼ The Complete Investigation of Encoding and Security // Speaker Deck malaããã®ã¹ã©ã¤ãã¯ãã¡ãï¼ XSS with HTML parsing confusion // Speaker Deck
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}