æ ªå¼ä¼ç¤¾ã¦ã§ããã£ãªã¢ã®äººæ°ã³ã³ãã³ããã¹ã¼ãã¼ããã«ã¼ã®ãã¼ã«ã¢ãã«ãèªããWebã¨ã³ã¸ãã¢æ¦åä¼ãã«ãµã¤ãã¦ãºã»ã©ãã§åã Shibuya.pm äºä»£ç®ç·é·ã®ç«¹è¿«è¯ç¯(TAKESAKO)æ°ã®ã¤ã³ã¿ãã¥ã¼ãå ¬éãããã ä»åã®ã¤ã³ã¿ãã¥ã¼ã¯ãåè¬æ¼ãªã©ã§ã馴æã¿ã®è§è°·æ°ã®ç´¹ä»ã«ãã£ã¦å®ç¾ãããã®ã ã¤ã³ã¿ãã¥ã¼ã§ã¯ããªããªãèããã¨ãã§ããªãçãç«ã¡ããã®è©±ã®ã»ãããæ¥æ¬ã®ITã¨ã³ã¸ãã¢ã幸ãã«ãªãããããªãã¨ãããããã¨ä»å¾ã«ã¤ãã¦ç±ãèªã£ã¦ããã
ä»åã¯ãæ¦åä¼ç¬¬26åã«åºã¦é ããè§è°·ä¿¡å¤ªéæ°ããã®ç´¹ä»ã§ããµã¤ãã¦ãºã»ã©ãï¼Cybozu Labsï¼ã®ç«¹è¿«è¯ç¯ããã«ã話ããèããã¾ããã竹迫ããã¯ããµã¤ãã¦ãºã»ã©ãã«ã¦ç 究éçºã®å®åãè¡ãåãã§ããShibuya Perl Mongersãã®ï¼ä»£ç®ãªã¼ãã¼ã¨ãã¦Perlããã°ã©ãã®ã³ãã¥ããã£æ´»åãä¼ç»ã»éå¶ãããã¨ãå¹ åºããã£ã¼ã«ãã§æ´»èºããã¦ãã¾ããä»åã¯èµ¤åã«ãããµã¤ãã¦ãºã»ã©ãããã®ãªãã£ã¹ã«ã¦ããããªç«¹è¿«ããã«ãã£ããã話ã伺ãã¾ããã竹迫ããã®ãæ¥æ¬ã®ITæ¥çã®å°æ¥åãã«ã¤ãã¦ã®ã話ã¯ç¤ºåã«å¯ãã§ãããITæ¥çã«èº«ãããè ã¨ãã¦ãã¨ã¦ãåå¼·ã«ãªãã¾ããã 竹迫 è¯ç¯(TAKESAKO)ãæ° âä¸å¦æ ¡ï¼å¹´çã®ã¨ããç¶è¦ªã®è³¼å ¥ããå¯å£«éãFM TOWNSãã«è§¦ãã¦ã³ã³ãã¥ã¼ã¿ã«èå³ãæã¤ããã«ãªãã âé«æ ¡ã®ããF-BASIC 386 ã§ããã°ã©ãã³ã°ãã¯ãããã â大å¦ã§ã¯æ
Railsã¯ï¼ ãã¬ã¼ã ã¯ã¼ã¯ã¯ï¼ãããã¾ã§ã§æããããè¨èªã«ã¯ãJavaScriptãActiveScriptã®ããã«PHPã¨è£å®ãåããè¨èªãããããä¸æ¹ã§æ©è½ããããã£ã³ã°ããè¨èªãããããã®ç¹ãå¸ä¼ã®åã ä¸çªæ°ãææããã¨ãPHPã¨ãããã£ã³ã°ããè¨èªã®ä»£è¡¨ã¨ãããããã¦ã§ãã¢ããªã±ã¼ã·ã§ã³ãã¬ã¼ã ã¯ã¼ã¯ãRailsããæããRubyã®é«æ©æ°ãããPHPããRailsã¸ç§»è¡ãã¦ããã²ã¨ãããã ããããPHPã§ä¸æããã£ã¦ãéçºãRailsã§ãããã¨ãã¦ä¸æããããªãäºä¾ããããRailsã®æåã®ãªãããé½åã®ããã¨ããã ãåãåºãããã§ã¯ä¸æããããªããPHPã«ã¯PHPã®ããããã£ã¦ããããRailsã¨è¶³ãã°ãã£ã¨ä¸æãããããããªããã¨æããã©ãããã§ããªããã¨èªãã竹迫æ°ãè¨åãããæåããç解ãããã¨ã®å¿ è¦ãèªã£ãããããã§ç«¹è¿«æ°ããRailsãã¨ããè¨èã«ã²ã£ããã¦ããã¬ã¼
Shibuya Perl Mongers 2代ç®ãªã¼ãã¼ã«ãã¦ï¼ppencodeã®ä½è ãåºå³¶å¸ç«å¤§å¦åæ¥å¾ï¼å¤§ä¼æ¥åãmod_perl製åã®éçºã«å¾äºã2005å¹´ãããµã¤ãã¦ãºã»ã©ãæ ªå¼ä¼ç¤¾ã«å ¥ç¤¾ãLL Ringã«åæ¦ãNamazu for Win32ï¼Plaggerï¼Ajajaã®ã³ããã¿ã¼ã§ãããã CGIã¨ããã°Perlããããªé¢¨ã«ãããã¦ããææãããã¾ãããã¬ã³ã¿ã«ã»ãµã¼ãã¼ã®CGIã§æ軽ã«Perlã使ãããã¨ãããï¼ã¡ãã£ã¨ããæ²ç¤ºæ¿ã®ã¹ã¯ãªãããã¢ã¯ã»ã¹ã»ã«ã¦ã³ã¿ãªã©ï¼CGIããã°ã©ã ã®å¤ããPerlã§æ¸ããã¦ãã¾ããããã®ããPerlãççºçã«æ®åããã®ã§ããPerlã¯æ¥æ¬ã®ã¤ã³ã¿ã¼ãããé»ææãæ¯ããããã°ã©ãã³ã°è¨èªã¨ãã¦ï¼åºããã®åãç¥ããã¦ãã¾ãã ãã®åé¢ï¼Perlã§æ¸ãããããã°ã©ã ã®ä¿å®æ§ã«æ©ã声ãèãããããã«ãªãã¾ãããäºå®ï¼Perlã®ããã°ã©ãã³ã°çµé¨ãå°
How to defend Apache/CGI against multibyte XSS attacks ã¹ãã¼ã«ã¼ Yoshinori TAKESAKO (âtakesakoâ) å¿åè Shibuya.pm æ¥ä»: 2008/05/16 11:35 æé: 20å è¨èª:æ¥æ¬èª è¿å¹´ã®ãã«ããã¤ãæ»æã«å¯¾ãã¦èªç¤¾ã®Webãµã¼ããã©ãå®ãã®ãã SQLã¤ã³ã¸ã§ã¯ã·ã§ã³é¨åãè¨æ¶ã«æ°ãããæ¥ã é²åããXSSæ»æ ãã身ãå®ãæ¹æ³ã«ã¤ãã¦Apacheã®ã¢ã¸ã¥ã¼ã«ãæ¸ãã¦èå¯ãã¾ãã
ã¯ã¦ãªã¼ï¼ï¼ï¼ æ®å½±è ã¯ãã©ãã ããã³ ããã£ã¡ã¾ã£ãã ãã¬ã¤ããã 奥ã§ç«¹è¿«ããã¨naoyaãããå£ãã åºãã§ã åã® ãã³ãã³ ãã©ããæ®ãã®ãã©ã¦ãã¹ï½ï½ï½ 楽ããï¼ï¼
é¢è¥¿æ¹é¢ã®ã¿ãªãã¾ã¨ä¸ç·ã«ä»¥ä¸ã®å 容ã®ã話ãã§ããã°ã¨æãã¾ãã ãå½¹ã«ç«ããªã HTML/JavaScript Hacks 4é£çºã id:TAKESAKOï¼ãµã¤ãã¦ãºã»ã©ãæ ªå¼ä¼ç¤¾ï¼ ç´20å¹´åã®GIFç»åãã©ã¼ããããç´10å¹´åã®HTML/JavaScriptã®æè¡ã ç¾å¨ã®Web2.0æ代ã«å¿ç¨ãããã¨ã§å¹ ãåºããAjaxããã¯ã®ç´¹ä»ã§ãã ã»ãã¥ãªãã£ã¨ãããã¨ã§æè¿è©±é¡ã®PHPã®èå¼±æ§ã«ã¤ãã¦ãèªãã¾ãã Webã¢ããªã®ééã§ããããªããã¯ã楽ãã¿ã¾ãããã 1. 詳細ã¤ã¡ã¼ã¸ãã¡ã¤ã - ãªãPHPã¯é¿ããããã®ãï¼ - RFIèå¼±æ§ã§ä»»æã®PHPã³ã¼ãå®è¡ - ç»åãã¡ã¤ã«ã使ã£ãæ»æä¾ - ãµãã¿ã¤GIFåä½åç - mod_imagefight PoC 2. JavaScript Binary Hacks - JS+Perl+HTML+GIF89a Polyglot -
Windowsã®å¤§è¿·æãæ¬ã å½¹ã«ç«ããªããã¨ãå¤ãEdgeã®ã¯ã¼ãã³ããã£ãæ¶ãã¦ãã¾ãã 2024.03.13
æè¡ç³»ã«ã³ãã¡ã¬ã³ã¹ã«ããããã¬ã¼ã³ä½ææ¹æ³ã®ã²ã¨ã¤ã主ã«ã©ã¤ããã³ã°ãã¼ã¯ãªã©ã®ã¹ã©ã¤ããä½ãéãå½æ¥ã¾ã§ã¾ã£ããæºåããããä¼å ´ã«ã¤ãã¦ããå¿ æ»ã«ã¹ã©ã¤ããã¤ããã¯ãããã¡ã½ãããã¾ãå½æ¥ä¼å ´ã«ããã¦æ¥½å±ãªã©ã§ä»ã®çºè¡¨è ã®å 容ãããã¿ãæ´æ°ãããªã©ãã¦ã¿ã¤ã ãªã¼ãªå 容ã§ã¦ã±ãã¨ããã¨ãç®çã¨ããï¼ãå¾è¿°ã®ããã«ä»ã®ã¹ãã¼ã«ã¼ã®çºè¡¨ãè¦ãä½è£ã¯ãªãã®ã§å¤±æãããã¨ãå¤ãï¼ãå©ç¹ã¯takesakoã¡ã½ããã«ä¼¼ã¦ããããããããçªè²«ãªã®ã§takesakoã¡ã½ããã®è¯ãã¨ãããä½ãçä¼¼åºæ¥ãã«å¤±æãããã¬ã¼ã³ã«ãªãäºããå½takesakoã¡ã½ããã¨å¼ã°ãã¦ããã id:TAKESAKO æ°ã模å£ãããã¨ãã¦æ£ãè¬å¸«ãå¢ãã¦æ¥ã¦ãæåã¨ãªã£ãã ã¡ãªã¿ã«è³æéãã«è¨å¤§ãªæéãè²»ãããå®éã®è³æä½æã¯åæ¥ãªã©ã«è¡ãæ¹æ³ã¯ããå½takesakoã¡ã½ããã¨èª¤è§£ãããããä»ã®çºè¡¨è ã®å 容ãè¦ããã¨ãã§ã
äºå®éãç¡äºã¤ãã³ããçµäºãããã¾ããããåå ããååé ãã¾ããçæ§ã«å¾¡ç¤¼ç³ãä¸ãã¾ãã æ¥ æ 2024å¹´12æ20æ¥(é)10:00-16:50(9:30éå ´) ä¼ å ´ ãã¤ããªããéå¬ ãªã³ãµã¤ã KKRããã«ç±æµ· é岡çç±æµ·å¸æ¥æ¥çº7-39 JRæ±æ¥æ¬ã»JRæ±æµ· æ±æµ·éæ¬ç· ç±æµ·é§ ããå¾æ©7å ãªã³ã©ã¤ã³ ZOOM ã¦ã§ããã¼ å® å¡ ãªã³ãµã¤ã 100å ãªã³ã©ã¤ã³ 300å åå è²» ç¡æ 対 象 æ å ±ã»ãã¥ãªãã£ããµã¤ãã¼ã»ãã¥ãªãã£ã«é¢ããæ¹ ä¸» å¬ SecurityDayéå¶å§å¡ä¼ ã»ä¸è¬ç¤¾å£æ³äºº æ¥æ¬ã¤ã³ã¿ã¼ããããããã¤ãã¼åä¼(JAIPA) ã»ç¹å®éå¶å©æ´»åæ³äººÂ æ¥æ¬ãããã¯ã¼ã¯ã»ãã¥ãªãã£åä¼(JNSA) ã»ä¸è¬ç¤¾å£æ³äºº ICT-ISAC(ICT-ISAC Japan) ã»ç¹å®éå¶å©æ´»åæ³äºº ãµãã®ãã«æ å ±ãããã¯ã¼ã¯æ©æ§ï¼FINOï¼ ã»ä¸è¬ç¤¾å£æ³äºº æ¥æ¬ãããã¯
å æ¥ã®shibuya.jsã«å¼ãç¶ãã Real UNIX MAGAZINE Day ã«åå ãã¦ãã¾ããã 以åã®ãã¬ã¼ã³ã¨éãªãé¨åãããã¾ãããè¥è¼©è ãªãããæ¨ä»ã®Ajaxã®æè¡ã®GIF89aï¼ããã¯ï¼ã«ã¤ã㦠newtype 㨠oldtype ã®è©±ã交ããªãããã©ã¤ããã³ã°ãã¼ã¯ããã¦ããã ãã¾ããã åæ¥ã®shibuya.jsã¨å¤ãã£ã¦åå è ã®å¹´é½¢å±¤ã大ããç°ãªã£ã¦ããã®ãé¢ç½ãã£ãã§ãã newtype : shibuya.js ã®åå è 層ï¼18æï½30æåå¾ãã¡ã¤ã³ï¼ oldtype : Real UNIX MAGAZINE Dayåå è 層ï¼åç°å çã¯1931å¹´çã¾ãï¼ oldtypeã®çæ§ã«ãæºè¶³ããã ããããã§ãå°ãå®å¿ãã¾ããã ãã¨ãåå è ã®çãããæã¡å¯ã£ã¦å±ç¤ºããã¦ãããã³ãã¼ã¸ã³ã¼ãã¼ã¯åãã¦è¦ããã®ã°ããã§å§å·»ã§ããã
ç¾å¨ï¼Perlã¦ã¼ã¶ã¼ã¯2極åãé²ãã§ãã¾ããåå¿è ã¯ãã¾ã ã«ãCGIã使ãããããã°ãããã¨ãã段éã§æºè¶³ãã¦ãã¾ããä¸æ¹ã§ï¼Perlããã«ã¼ã¯ç¬èªã®ä¸çãæ§ç¯ãï¼ãã¾ãåå¿è ãçã¿ã¾ãããããã§ãã®ç¹éã§ã¯ï¼åå¿è 層ã«çµ¶å¤§ãªå½±é¿åãæã¤è¦ä¸å·æ°ï¼ã¦ã§ãã¯ãªã¨ã¤ã代表åç· å½¹ï¼KENT-WEBãéå¶ããKENTæ°ã¨ãã¦æåï¼ã¨ï¼Perlã®ããã«ã¼éå£ã§ããShibuya Perl Mongersï¼Shibuya.pmï¼ã®æ°ãªã¼ãã¼ï¼ç«¹è¿«è¯ç¯æ°ï¼ãµã¤ãã¦ãºã»ã©ãï¼ã«å¯¾è«ããé¡ããã¾ããï¼ç·¨éé¨ï¼ã ã¾ãã¯ï¼Perlã¨ã®åºä¼ãããæãã¦ããã ããã§ããããã è¦ä¸ãç§ãPerlã«åºä¼ã£ãã®ã¯ã¡ããã©10å¹´ã»ã©åï¼1996ï½97å¹´ãããã§ããããã®ããã¯ã³ã³ãã¥ã¼ã¿ã»ã¡ã¼ã«ã¼ã®å¶æ¥ã§ï¼ã¾ã ããã°ã©ãã³ã°ã¯ã§ãã¾ããã§ãããèªåã®Webãã¼ã¸ã«ããªã¼ã®CGIã®æ²ç¤ºæ¿ãè¨ç½®ãããã¨ããã®ã§ããï¼ãã¾
ã©ã³ãã³ã°
ãç¥ãã
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}