Securityã¨Validationã®å¥å¦ãªé¢ä¿ããããã¯Drupalã¯ãªãValidationããããããªãã®ã
Securityã¨Validationã®å¥å¦ãªé¢ä¿ããããã¯Drupalã¯ãªãValidationããããããªãã®ã
_ã±ã¼ã¿ã¤twitter(twtr.jp)ã«ããã¦DNS Rebindingæ»æã«å¯¾ããèå¼±æ§ãçºè¦ã»éå ±ããå³åº§ã«ä¿®æ£ããã twitterã®ã±ã¼ã¿ã¤çtwtr.jpã«ããã¦ãDNS Rebindingã«ãããªããã¾ãã許ãèå¼±æ§ãçºè¦ããã1/15ã«éå ±ããã¨ããããã®æ¥ã®ãã¡ã«ä¿®æ£ãããã以ä¸ããã®çµç·¯ã«ã¤ãã¦å ±åããã çµç·¯ ä»å¹´ã®1æ12æ¥ã«èªå£²æ°èã®è¨äºãåºãã®ãåãã¦ãç¾å®ã®ãµã¤ãã¯ã©ããªã®ã ãããã¨æ¹ãã¦æ°ã«ãªã£ãã NTTãã³ã¢ã®æºå¸¯é»è©±ã®ãã¡ãã¤ã³ã¿ã¼ãããé²è¦§ã½ãããï½ã¢ã¼ããã©ã¦ã¶ï¼ã»ï¼ããæè¼ããææ°ï¼ï¼æ©ç¨®ãéãã¦ãå©ç¨è ã®å人æ å ±ã䏿£åå¾ãããæãã®ãããã¨ããå°éå®¶ã®ææã§æããã«ãªã£ãã åç¤¾ã¯æºå¸¯ãµã¤ãã®éå¶è ã«ãã¹ã¯ã¼ãèªè¨¼ãªã©ã®å®å ¨å¯¾çãå¼ã³ããã¦ãããæºå¸¯é»è©±ã®æ©è½ã髿©è½åããã«ã¤ããããããå±éºã¯å¢ãã¦ãããå©ç¨è ãæ³¨æãå¿ è¦ã«ãªã£ã¦ããã
é©å½ XSSããã=ãªãã§ãããæ¾é¡ã§ã¯ãªã ããã°ãµã¼ãã¹ãªã©èªç±ã«HTMLãããããããªãµã¼ãã¹ã§ã¯ã害ãåã°ãªãããã«è¡¨ç¤ºã丸ãã¨å¥ã®ãã¡ã¤ã³ã«åãã¦ãããããããã¯å¥ãã¡ã¤ã³ã®IFRAMEå ã§å®è¡ããããã¦ããã®ãæ®éã§ããå人æ å ±ãé ãã£ã¦ããµã¤ãã¯ãéè¦å人æ å ±ã«ã¤ãã¦ã¯HTTPSãããªãã¨åç §ã§ããªãã£ããããããã表示ããªãã£ãã(ãã¹ã¯ã¼ããã«ã¼ãçªå·ç)ãæ±ºæ¸ç¨ã®ãã¹ã¯ã¼ããæè¨¼çªå·ãå ¥ããªãã¨æä½ã§ããªãã£ããããã åèã¾ã§ã« http://blog.bulknews.net/mt/archives/001274.html (2004å¹´ã®ã¢ã¡ããèå¼±æ§ã®è©±) http://d.hatena.ne.jp/yamaz/20090114 (ä¿¡é ¼ã§ããªããã¼ã¿ãåãæ±ããã¡ã¤ã³ãåãã話) 管çç¨ã¨å¥ãã¡ã¤ã³ã«åããã«ãé¢ããããscriptå®è¡ã§ãããã¨ã«å¯¾ãã¦DISãã
HASHã³ã³ãµã«ãã£ã³ã°æ ªå¼ä¼ç¤¾ å ¬éæ¥:2009å¹´11æ24æ¥ è¿½è¨æ¥:2010å¹´1æ21æ¥ æ¦è¦ iã¢ã¼ããã©ã¦ã¶2.0ã®JavaScriptã¨DNS Rebinding(DNSãªãã¤ã³ãã£ã³ã°)åé¡ã®çµã¿åããã«ãããiã¢ã¼ãIDãå©ç¨ããèªè¨¼æ©è½ï¼ä»¥ä¸ãããããã°ã¤ã³ï¼ã«å¯¾ãã䏿£ã¢ã¯ã»ã¹ãå¯è½ã¨ãªãå ´åããããã¨ã確èªããã®ã§å ±åãããå±éºåº¦ã®é«ãæ»æææ³ã§ããã®ã§ããµã¤ãéå¶è ã«ã¯è³æ¥ã®å¯¾çãæ¨å¥¨ããã èæ¯ æºå¸¯é»è©±ã®ãããããã°ã¤ã³ã¨ã¯ãã±ã¼ã¿ã¤ãã©ã¦ã¶ï¼ãã¨ãã°iã¢ã¼ããã©ã¦ã¶ï¼ã«ç¨æãããå¥ç´è åºæIDãå©ç¨ããç°¡æçãªèªè¨¼ã§ãããã¦ã¼ã¶ãIDããã¹ã¯ã¼ããå ¥åããªãã¦ãèªè¨¼ãå¯è½ã¨ãªããiã¢ã¼ãIDã¯ãNTTãã³ã¢ã®æä¾ããå¥ç´è åºæIDã®ä¸ç¨®ã§ãURLã«guid=ONã¨ããã¯ã¨ãªã¹ããªã³ã°ãå«ãããã¨ã«ããã端æ«åºæã®7æ¡ã®IDãWebãµã¼ãã«éåºããããç¾å¨ãiã¢
ç ç©¶è ãSSLã®ä¸éè æ»æã®èå¼±æ§ãæªç¨ããä»äººã®Twitterãã¹ã¯ã¼ããå ¥æãããã¨ã«æåããã¨çºè¡¨ããã SANS Internet Storm Centerãç±³IBMåä¸ã®ã»ãã¥ãªãã£ä¼æ¥Internet Security Systemsï¼ISSï¼ã®ããã°ã«ããã¨ãTLSï¼SSLãããã³ã«ã«ä¸éè æ»æã®èå¼±æ§ãè¦ã¤ãã£ãåé¡ã§ãç ç©¶è ããã®èå¼±æ§ãæªç¨ãã¦Twitterã®ãã°ã¤ã³æ å ±ãçã¿åºããã¨ã«æåããã¨çºè¡¨ããã èå¼±æ§ã¯TLSï¼SSLã®ãªãã´ã·ã¨ã¼ã·ã§ã³ã®éç¨ã«åå¨ããçè«çã«ã¯ä¸éè æ»æã«ãã£ã¦HTTPSã»ãã·ã§ã³ã«ãã¼ã¿ãæ¿å ¥ãããã¨ãå¯è½ã«ãªãã¨ããã¦ããããå½åã®æ å ±ã§ã¯å®éã«æªç¨ããã®ã¯é£ããã¨è¦ããã¦ããã ãããISSãªã©ã«ããã°ãç ç©¶è ã¯ãã®èå¼±æ§ãçªãã¦è¢«å®³è ãTwitterãµã¼ãã«éã£ãHTTPãã±ããã«ã¢ã¯ã»ã¹ãããã¹ã¯ã¼ããªã©ã®ãã°ã¤ã³æ å ±ãåå¾ãã
å¿ããããã«è¿½è¨ API ã§ _twitter_sess ã¯çºè¡ããã¦ããããã§ãããweb ã® UI ã«ã¢ã¯ã»ã¹ã¯ã§ããªããªã£ãã¿ããã§ãï¼ã¤ã¾ã豪快ãã¯è§£æ¶ããã¦ã¾ãï¼ OAuth ã³ã³ã·ã¥ã¼ãã twitter API ã«ã¢ã¯ã»ã¹ããã¨ããã©ã¦ã¶ã§ãã°ã¤ã³ããã¨ãã¨åæ§ã®ã»ãã·ã§ã³ã¯ããã¼ãçºè¡ããã¦ããæ¨¡æ§ã§ã GET https://twitter.com/account/verify_credentials.xml Authorization: OAuth realm="", oauth_consumer_key="***", oauth_nonce="***", oauth_signature="***", oauth_signature_method="HMAC-SHA1", oauth_timestamp="1253358338", oauth_token="***",
2009-08-02 15:10:00 iPhone使ããªãæ¹æ³ãè¿½è¨ iPhoneãè²ã ããã£ã¦ãéç¨ã§ãã£ã¦ã¿ããåºæ¥ãã®ã§ã¡ã¢ããã»ã©æªãäºã¯åºæ¥ãªãã¨æããã©ãè²ã èªå·±è²¬ä»»ã§ã iPhoneã¨SBMã¬ã©ã±ã¼ã§ã¯å ¨ãå¥ã®ãããã¯ã¼ã¯ã使ç¨ãã¦ãããããé常iPhoneããã¯å ¬å¼ãµã¤ããIPã§ã¢ã¯ã»ã¹å¶éãããã¦ãåæãµã¤ãã¯è¦ãäºãåºæ¥ãªããç¹ã«è¦ãå¿ è¦ãç¡ãã®ã ããå®é¨ã¨ãã¦ãã£ã¦ã¿ãã iPhoneã¯é常 "smile.world" ã¨ããAPNã«æ¥ç¶ãã¦ããã䏿¹ãã¬ã©ã±ã¼ã¯ã°ã°ã£ã¦è¦ãã¨ãã "mailwebservice.softbank.ne.jp" ã¨ããAPNã«æ¥ç¶ãã¦ããããããã£ã¨è¨ããã¨ã¯ãiPhoneã®æ¥ç¶å ãããã«å¤ãã¦ãã¾ãã°iPhoneãSBMã¬ã©ã±ã¼å´ã®ãããã¯ã¼ã¯ã«å ¥ããã»ã»ã»ã¯ãã ç¨æããã¢ã 馿¸¯ç or SIMUnlockæ¸ã¿ã® iPhone
ã¡ãã£ã¨åã«ãApacheã«æ°ããªèå¼±æ§çºè¦ - ã¹ã©ãã·ã¥ãããã»ã¸ã£ãã³ãã§ç´¹ä»ããã¦ããèå¼±æ§ãªãã§ããã©ã»ã»ã»ä¼ç¤¾ã®ãéãã§åãµã¼ãã¹æ¯ã«ç¶æ³å ±åã£ã¦ã¤ãã³ãããã£ãã®ã§ãã¡ããã¨èå¼±æ§è©¦é¨ãã¦ã¾ããããã®ã¾ã¨ãã§ãã Apacheã«ãDoSæ»æã«ç¹ããèå¼±æ§ãæ°ãã«è¦ã¤ãã£ãããã ï¼æ¬å®¶/.è¨äºããï¼ ãã®èå¼±æ§ã¯ããããå©ç¨ããHTTP DoSãã¼ã«ãSlowlorisãããªãªã¼ã¹ããããã¨ããæããã«ãªã£ãã¨ã®ãã¨ããã®æ»æãã¼ã«ã¯Apacheã«ä¸å®å ¨ãªãªã¯ã¨ã¹ããããã¼ãéãç¶ãããã®ã§ãApacheãæå¾ã®ããããéããã¦ããã®ãå¾ ã¤éãå½ã®ããããéããã¨ã§æ¥ç¶ããªã¼ãã³ã«ãç¶ããApacheã®ããã»ã¹ã䏿¯ã«ããããã®ã ã¨ããã èå¼±æ§ã¯Apache 1.xã 2.xã dhttpdã GoAhead WebServerãããã¦Squidã«ã¦ç¢ºèªããã¦ããããIIS6
æ¢ã«çºè¡¨ããã¦ããããã«ãNTTãã³ã¢ã®å¤ã¢ãã«ããi-modeã®ä»æ§ãå¤§å¹ ã«æ¡å¼µãããJavaScriptãCookieãRefererã«å¯¾å¿ããããã«ãªã£ããããã仿§å¤æ´ã¯ã»ãã¥ãªãã£ã®é¢ãããå½±é¿ã大ãããããç§ã¯å¤ã¢ãã«ã®ä¸ãããP-07Aãçºå£²éå§æ¥(5æ22æ¥)ã«è³¼å ¥ãããããã¦ããªãªã¼ã¹ã©ããJavaScriptãCookieãRefererãåä½ãããã¨ãã宿©ã«ã¦ç¢ºèªããã ã¨ããããP-07Aã¨åæ¥ã«çºå£²éå§ãããN-06Aã¯ããã®æ¥ã®ãã¡ã«ä¸æè²©å£²åæ¢ã®ãç¥ãããåºãã ãã®åº¦ãå¼ç¤¾ã®æºå¸¯é»è©±ãN-06Aãã«ããã¦ãiã¢ã¼ãæ¥ç¶æã®ä¸å ·åã確èªããã¾ããã®ã§ã販売ã䏿è¦åããããã¦ããã ãã¾ãã ãªããæ¬äºè±¡ã«ä¼´ããæ¬æ¥çºè¡¨ãããã¾ãããN-08Aãã®è²©å£²éå§æ¥ã«ã¤ãã¾ãã¦ãã5æ28æ¥ããå»¶æã¨ãªãã¾ãã ãN-06Aãã®è²©å£²åéåã³ãN-08Aãã®è²©å£²éå§ææ
ãªãPHPã¢ããªã«ã»ãã¥ãªãã£ãã¼ã«ãå¤ãã®ã?ï¼ç¬¬25åãPHPã®ã¢ãã¬ã¹è ±ã«ã¦ã大å£éç·æ°ãPHPã®Session Adoptionåé¡ã«ã¤ãã¦åãä¸ãã¦ããã大壿°ã¯åº¦ã ãã®åé¡ãåãä¸ãã¦ããããä»ã®ã¨ããæ°ã®ä¸»å¼µã«å調ãã人ãè¦ãããªããããããã®ã¯ãã§ã大壿°ã®ä¸»å¼µã¯ééã£ã¦ããã¨ç§ã¯æãã 以ä¸ã大壿°ã®ä¸»å¼µãå®éã«è©¦ãã¦ã¿ãå½¢ã§ãé ã«èª¬æãããã 大壿°ã®ä¸»å¼µ 大壿°ã®ä¸»å¼µã¯ãPHPã«ã¯Session Adoptionèå¼±æ§ãããããã«ãæ¨æºçãªSession Fixation対çã§ããsession_regenerate_id()ãæ½ãã¦ãããã®å¯¾çã¯æå¹ã§ã¯ãªãã¨ãããã®ã ã ãããï¼å®éã«ã¯ç¾å¨ã«è³ãã¾ã§PHPã®ã»ãã·ã§ã³ã¢ã¸ã¥ã¼ã«ã®ã»ãã·ã§ã³ã¢ããã·ã§ã³èå¼±æ§ã¯ä¿®æ£ãããªãã¾ã¾ã«ãªã£ã¦ãã¾ãããã®ããã«ï¼æ¬æ¥ã¯session_regenerate_id颿°ããã°ã¤ã³
PHPã«ã¯HTTPã»ãã·ã§ã³ç®¡çã¢ã¸ã¥ã¼ã«ãæ¨æºã§ä»ãã¦ãã¾ãããã®ã»ãã·ã§ã³ã¢ã¸ã¥ã¼ã«ã«ã¯é常ã«é大ãªã»ãã¥ãªãã£ä¸ã®èå¼±æ§ãä¿®æ£ãããã«æ®ã£ã¦ãã¾ãããã®èå¼±æ§ã¨ã¯ã»ãã·ã§ã³ã¢ããã·ã§ã³ã§ãã ã»ãã·ã§ã³ã¢ããã·ã§ã³ã¨ã¯ãã»ãã·ã§ã³åºå®åæ»æã«å©ç¨ãããèå¼±æ§ã§ããPHPã®ã»ãã·ã§ã³ç®¡çã¢ã¸ã¥ã¼ã«ãã»ãã·ã§ã³ã¢ããã·ã§ã³ã«èå¼±ã§ãããã¨ã¯ãããªã以åãä½å¹´ãåããç¥ããã¦ãã¾ããããããéçºè ã®çè§£ä¸è¶³ããèå¼±æ§ãæ¾ç½®ãããã¾ã¾ã«ãªã£ã¦ãã¾ãã ã»ãã·ã§ã³ã¢ããã·ã§ã³ã¨ã¯ ã»ãã·ã§ã³ã¢ããã·ã§ã³ã¨ã¯ããã©ã¦ã¶çããéä¿¡ãããæªåæåã»ãã·ã§ã³IDããã®ã¾ã¾å©ç¨ãã¦ã»ãã·ã§ã³ãåæåãã¦ãã¾ãèå¼±æ§ã§ããã¦ã¼ã¶ãéä¿¡ãã¦ããIDã§ã第ä¸è ã«äºæ³ã§ããªãæååã§ããã°å¤§ä¸å¤«ãªã®ã§ã¯ï¼ã¨èããæ¹ãããã¨æãã¾ãããã®éãã§ç¬¬ä¸è ã«äºæ³ã§ããªããã°åé¡ãªãã§ãããä»®ã«äºæ³ã§ãã¦ããã°ã¤ã³ããé
ã¿ãªãããã¯ããã¾ãã¦ãã¯ãããããããã¨ç³ãã¾ãã æè¿ãæåã³ã¼ãã¨é¢é£ããã»ãã¥ãªãã£ã®è©±é¡ãç®ã«ãããã¨ãå¢ãã¦ãã¾ãããæåã³ã¼ããå©ç¨ããæ»æã¯æè¡çã«æªéæã¨ãããã¨ããããåèã¨ãªãæ å ±ããªããªãè¦å½ããã¾ããããã®é£è¼ã§ã¯ãæåã³ã¼ããå©ç¨ããæ»æãããã«å¯¾ãã対çã«ã¤ãã¦æ£ããç¥èã解説ãã¦ããã¾ãã æåã³ã¼ãã¨ã»ãã¥ãªãã£ãé¢é£ãããã£ã¨ã大ããªç¹ã¯ããã¯ãæååã®æ¯è¼ã§ãããããâ å±éºãªæååã®æ¤åºããâ å®å ¨ãªæååã§ãããã¨ã®ç¢ºèªãã¨ãã£ãæååã®æ¯è¼ã¯ãã»ãã¥ãªãã£ãèããããã§é¿ãã¦éããªãå¦çã ã¨æãã¾ãã æååã®æ¯è¼ã«ããã¦ã¯ãåç´ã«ãã¤ãåãæ¯è¼ããã ãã§ã¯ä¸ååã§ãæååãã¡ã¢ãªä¸ã§ã©ã®ãããªãã¤ãåã¨ãã¦æ ¼ç´ããã¦ããã®ãï¼ãã®ã«ã¼ã«ã符å·åæ¹å¼ãããã¯æåã¨ã³ã³ã¼ãã£ã³ã°ã¨è¨ãã¾ãï¼ã«æ³¨æããªããã°ãªããªããã¨ãããã§ããããæ»æè ã¯å·§ã¿ã«æå
â Bluetoothã§å±±æç·ã®ä¹éãã¿ã¼ã³ã追跡ãã¦ã¿ã ãã®æ¥è¨ãæ¸ãå§ãã¦ãããã6å¹´ã«ãªããã¨ãã¦ãããæ¸ãå§ãããã£ããã¯ãRFIDã¿ã°ã®ãã©ã¤ãã·ã¼åé¡ãçè§£ãããªããã¨ã«ç¦ããæããããã ã£ãã彿ã®ç©ºæ°ã§ã¯ãRFIDã¿ã°ã¯5å¹´å¾ãããã«æ®åãããã ãã«RFIDã®åãè¾¼ã¾ããæ¥ç¨åã§æº¢ããããããã«ãªãã10å¹´å¾ãããã«ãã©ã¤ãã·ã¼åé¡ãé¡å¨åããã¨ç®ããã¦ããããããã6å¹´çµã£ãç¾å¨ãç§ã®é´ã«RFIDã¿ã°ã¯åãè¾¼ã¾ãã¦ããªãã 彿ã®è°è«ã§æããã¦ããRFIDã¿ã°ã®åé¡ã¯ãç¡ç·LANãBluetoothã«ãå ±éãããã¨ã§ããï¼MACã¢ãã¬ã¹ãã¦ãã¼ã¯IDã¨ãªãï¼ããããã®æ¹ãå ã«æ®åãããããããªãã¨ããäºæã¯ãã£ãããç¾æç¹ã§ããç¡ç·LANæ©å¨ãæã¡æ©ãã¦ãã人ã¯ããä¸é¨ã®äººã«éããã¦ãããããããBluetoothã¯ã©ãã ããããããã¾ã§ã«ãä½åº¦ããæè¿ã®Bluetoo
æåã³ã¼ãã«é¢ããåé¡ã¯å¤§å¥ããã¨æåéåã®åé¡ã¨æåã¨ã³ã³ã¼ãã£ã³ã°ã®åé¡ã«åé¡ã§ãããååã¯æåéåã®åãæ±ãã«èµ·å ããããå¼±æ§ã«ã¤ãã¦èª¬æããã®ã§ãä»åã¯æåã¨ã³ã³ã¼ãã£ã³ã°ã«èµ·å ããããå¼±æ§ã«ã¤ãã¦èª¬æãããã æåã¨ã³ã³ã¼ãã£ã³ã°ã«ä¾åããåé¡ãããã«åé¡ããã¨2種é¡ãããï¼1ï¼æåã¨ã³ã³ã¼ãã£ã³ã°ã¨ãã¦ä¸æ£ãªãã¼ã¿ãç¨ããã¨æ»æãæç«ãã¦ãã¾ãç¹ã¨ï¼ï¼2ï¼æåã¨ã³ã³ã¼ãã£ã³ã°ã®å¦çãä¸ååãªããã«ããå¼±æ§ãçãããã¨ãããç¹ã ã 䏿£ãªæåã¨ã³ã³ã¼ãã£ã³ã°ï¼1ï¼ââåé·ãªUTF-8符å·ååé¡ ã¾ãï¼ï¼1ï¼ã®ä¸æ£ãªæåã¨ã³ã³ã¼ãã£ã³ã°ã®ä»£è¡¨ã¨ãã¦ï¼åé·ãªUTF-8符å·ååé¡ãã説æããããåã åã«è§£èª¬ããUTF-8ã®ãããã»ãã¿ã¼ã³ï¼è¡¨1ã«åæ²ï¼ãè¦ãã¨ï¼ã³ã¼ãã»ãã¤ã³ãã®ç¯å²ãã¨ã«ãããã»ãã¿ã¼ã³ãå²ãå½ã¦ããã¦ãããï¼ãããã»ãã¿ã¼ã³ä¸ã¯ï¼ããå¤ãã®ãã¤ãæ°ã使ã£ã¦ãåãã³ã¼
â Googleããã¥ã¡ã³ãã®ãæå¾ ã¡ã¼ã«ãã®å±éº ãã¨ã®å§ã¾ã å ã é±ã®è©±ã1æ23æ¥ã«æ¬¡ã®è¨äºãåºã¦ããã ãGoogle Docsãã®è¨å®ã«ãç¨å¿ï¼ç¥ããªããã¡ã«æ¸ãæããï¼, WIRED VISION, 2009å¹´1æ23æ¥ ãã®è¨äºã®è¶£æ¨ã¯ããGoogleã¹ãã¬ããã·ã¼ããã®å ±æè¨å®ã®ç»é¢ã®èª¬ææãLet people edit without signing inãã誤解ãæãããã«ã誤ã£ã¦ã誰ã«ã§ãé²è¦§ãç·¨éã許ãè¨å®ã«ãã¦ãã¾ããããªãã¨ãã話ã§ããããã®ç»é¢ã¯ãæ¥æ¬èªè¡¨ç¤ºã§ã¯å³1ã®è¡¨è¨ã¨ãªã£ã¦ããã WIRED VISIONã®è¨äºã®è¨ãåã§ã¯ããpeopleããä¸ã®æå¾ ã¡ã¼ã«éä¿¡å ã®äººã ã®ãã¨ãæãããã«èªãã¦ãä¸ã®ããã©ã¤ãã·ã¼ãè¨å®ã夿´ããªãã¨ãããªãããã«èª¤è§£ãã¦ãã¾ãã¨ããã ããããããã®æ©è½ã®æå³ããã¦ããåä½ã¯ã©ããããã®ããç§ã試ãã¦ãããã¡ã«ä¸ææ··ä¹±ã
ãããã¿ããªï¼å æ°ï¼ã¨ãã¾ãã²ããã§ãã仿¥ã¯Session Fixationæ»æã®æ¹æ³ããã£ããæãã¡ãããã ãã¤ãã¯é²å¾¡å´ã§æ¼¢åã®ååã§ãã£ã¦ããã ãã©ï¼ãããã¯æ»æå´ã¨ãããã¨ã§ï¼åä¹ããã²ãããªã«å¤ãããã ãã ã£ã¦ãï¼ä»åº¦ãããµãã§ãä¸ç·ããã¯ãããããããããã¨ãï¼ã¯ã¾ã¡ã¡ããã¨ãï¼ã²ãããªã®äººãã¡ã®æ¹ãæ ¼å¥½è¯ããããããªããã ã§ã¯å§ãããã ãã®ã¨ã³ããªã¯ãhttp://blog.tokumaru.org/2009/01/introduction-to-session-fixation-attack.html ã«ç§»è»¢ãã¾ãããæãå ¥ãã¾ãããç¶ãã¯ããã¡ããã覧ãã ããã
ã¤ãã¼ã®ç»åã¯ãªãyimg.jpãã¡ã¤ã³ãªã®ãï¼ ãµã¤ãé«éåã®ææ³ã¨ã¤ãã¼ã®å¤±æä¾ ã§ã¤ãã¼ããªããã¡ã¤ã³ãå¤ãã¦ç»åãµã¼ããéç¨ãã¦ããããæ¸ããã¦ãã.ãéçãªã³ã³ãã³ãã«å¯¾ãã¦ã¯ããã¼ããªã¼ãã¡ã¤ã³ã使ããã¨ã«ãã£ã¦é度åä¸ãçããã¨ããã®ãçç±ã¨ãã£ã¦,ããã¯ããã§ãã¡ããæ£ããã®ã ããã©,ããã¯ã©ã¡ããã¨ããã¨å¯æ¬¡çãªçç±ã§æ¬å½ã®çç±ã¯éã. ã¯ããã¼ããªã¼ãã¡ã¤ã³ã使ããã¨ã§æªæããFlashã³ã³ãã³ããªã©ããèªç¤¾ãã¡ã¤ã³ã®ã¯ããã¼ãå®ãããã¨ããã®ãæ¬å½ã®çç±ã§,ããã¯ãã¡ãã¡ã§ä½¿ããã¦ãããã¯ããã¯ã .Flashã³ã³ãã³ãã¯å¤é¨ã®æ¥è ããã«ä½ã£ã¦ããã£ãã,åºåã®å ¥ç¨¿ç´ æã¨ãã¦å ¥ã£ã¦ããã®ã§,ä¿¡é ¼ã§ããªããã¼ã¿ã¨ãã¦åãæ±ãå¿ è¦ããã,ä¸ä¸ã¾ãããã¼ã¿ãã¢ããããããã¨ããã£ã¦ã大ä¸å¤«ã«ãã¦ããå¿ è¦ããã. æè¿ã¦ã¼ã¶ããã®ä»»æã®ã³ã³ãã³ããåãã¤ãã¦åä¸ãã¡ã¤ã³ã§é ä¿¡ã
Bugtraq: WordPress XSS vulnerability in RSS Feed Generator ãè¦ã¦ã Catalyst ã§ã $c->uri_for() ã§çæãããæååã¯ãå®å ¨ãªæååã§ãã㨠(ãªãã¨ãªã) æãè¾¼ãã§ãããããã§ã¯ãªãã®ã ãªã <a href="[% c.uri_for('/') %]">ã¿ããã«ã¨ã¹ã±ã¼ãããªãã§æ¸ãã¨ãhost é¨å㯠$ENV{HTTP_HOST} (ãªã¯ã¨ã¹ããããã® Host:) ããçæããããã¨ãå¤ãã®ã§ XSS ãèµ·ããã ããã ã¨æ±æããã Host: ãéã£ãã¯ã©ã¤ã¢ã³ãã«ããå¹ããªããããªæ°ããããã ãã©ãåºåã Cache ãã¦ããã¨ä»ã®ã¯ã©ã¤ã¢ã³ãã«ãå½±é¿ãåã¼ããã¨ã ã¾ããåºåã¯ã¡ããã¨ã¨ã¹ã±ã¼ããããã¨ãã話ã ããç®æ°ããã¯ãªãã $ GET -H 'Host:"><body onload=a
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãç¥ãã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}