ããã«ã¡ã¯ã ã¯ããã¼ãã»ãã¥ã¢ã«ããå¿ è¦ãåºã¦ãããããè²ã æ¢ãããã§ãããªããªãæ å ±ãçºè¦ã§ãã¾ããã§ãããçµå±ã人ã®å©ããåãã¦è¦ã¤ããã®ã§è¨è¼ãã¾ããï¼Railsã®ãªãã¡ã¬ã³ã¹ã«ã¯è¨è¼ãã£ãã¨æãã¾ããããï¼ ã¾ããç¨èªã®èª¬æã Session Fixation ã¢ããªã±ã¼ã·ã§ã³ãçæããã»ãã·ã§ã³IDãçããã¨ãã§ããªããªãæ»æè èªèº«ãçæããã»ãã·ã§ã³IDãã¯ã©ã¤ã¢ã³ãã«ä½¿ããã¦ãã¾ãããã¨ããæ»æã ã»ãã·ã§ã³ã»ãã¤ã¸ã£ãã¯ï¼session hijackï¼ ä»äººã確ç«ããTCPã®éä¿¡è·¯ã横åãããè¡çºã ã»ãã®ã¦ã¼ã¶ã¼ã®ã»ãã·ã§ã³IDãã»ãã·ã§ã³ã»ã¯ããã¼ï¼ã»ãã·ã§ã³ç®¡çã«ä½¿ç¨ãã¦ããã¯ããã¼ï¼ãçããã¨ã§ãå¥ã®ã³ã³ãã¥ã¼ã¿ãããã®ã¦ã¼ã¶ã¼ã«ãªããã¾ãã ã¢ã¯ã»ã¹ãè¡ããå±éºæ§ããããä¾ãã°ãã»ãã·ã§ã³ã»ã¯ããã¼ãé¡æ¨å¯è½ãªç°¡åãªãã®ã§ãã£ãããã»ãã¥ã¢ã§ãªãéä¿¡çµè·¯ã§éãã
{{#tags}}- {{label}}
{{/tags}}