Deleted articles cannot be recovered. Draft of this article would be also deleted. Are you sure you want to delete this article? Webã§ã®ããã·ã¥æè¡ HTTPã¯ã¯ã©ã¤ã¢ã³ãï¼ãã©ã¦ã¶ï¼ãããªã¯ã¨ã¹ããã¦ãµã¼ãããã¬ã¹ãã³ã¹ãè¿ãä¸åä¸çåã®ãããã³ã«ãªã®ã§ãåºæ¬çã«ã¯ãµã¼ãå´ãããã©ã¦ã¶ã«æ°çæ å ±ããªã¢ã«ã¿ã¤ã ã§éç¥ï¼ããã·ã¥ï¼ã§ããããã«ã¯ã§ãã¦ãã¾ããã ãããããã§ãããã·ã¥ããããã¨ããå ´åã«ã©ããããã¨ãã話ãåºã¦ãã¾ããããæ¹ã«ã¯ä»¥ä¸ã®ãããªãã®ãããã¾ãã ãã¼ãªã³ã° ã¯ã©ã¤ã¢ã³ããããµã¼ãã«å®æçã«æ°çãåãåãããããã«ãã¾ãã æãåå§çãã¤ç¢ºå®ãªããæ¹ãæ¬ ç¹ã¯ãæ大ã§ãã¼ãªã³ã°ééã®åã ãéç¥ãé 延ããããã¨ã§ãã ãã³ã°ãã¼ãªã³ã°ï¼âC
Hacking Slack using postMessage and WebSocket-reconnect to steal your precious token TLDR; I was able to create a malicious page that would reconnect your Slack WebSocket to my own WebSocket to steal your private Slack token. Slack fixed the bug in 5 hours (on a Friday) and paid me $3,000 for it. Recently a bug I found in Slack was published on HackerOne and I wanted to explain it, and the method
WebSocket Echo Server We run a free very simple endpoint server with support for websockets and server-sent events (SSE) so that you can test your websocket and SSE clients easily. The server is designed for testing HTTP proxies and clients. It echoes information about HTTP request headers and bodies back to the client. The endpoint is https://echo.websocket.org/ Behavior Any messages sent from a
ããã«ã¡ã¯ï¼ãã¨ã¤ãã¬ããæè¡é¨åç°ã§ãï¼ ã¨ã¤ãã¬ããã§ã¯æ¯æãã¼ãã決ãã¦ãã¨ã³ã¸ãã¢ãæã¡åãã§åå¼·ä¼ãå®æ½ãã¦ãã¾ãã ä¸éããã¯ï¼é±ãããé ãã¦ãæ°ããã¾ãããå æ¥ã¯WebSocketããã¼ãã«åå¼·ä¼ã è¡ãã¾ããã®ã§ãä»åãã®å 容ããã¤ã¸ã§ã¹ãçã§ãéããã¾ãã 1ï¼WebSocketã¨ã¯ï¼ ããããWebSocketã¨ã¯ä½ãªã®ã§ããããï¼ WebSocketã¨ã¯ãã¯ã©ã¤ã¢ã³ãï¼ãã©ã¦ã¶ï¼ã¨ãµã¼ãé㧠æ¬å½ã®æå³ã§ã®å ¨äºéï¼åæ¹åï¼éä¿¡ãè¡ãããã®ãããã³ã«ã§ãã ãã¨ãã¨ã¯HTML5ã®ä¸é¨ã¨ãã¦ãä»æ§ã®çå®ãé²ãããã¦ãã¾ããã ãã®å¾ç¬ç«ããåä½ã®ãããã³ã«ã¨ãã¦ä»æ§çå®ãé²ãããã¦ãã¾ãã WebSocketã®ç¹å¾´ã¨ãã¦ã¯æ¬¡ã®ç¹ãããããã¾ãã TCPä¸ã§åä½ ããã©ã«ããã¼ã㯠80çª ã¾ã㯠443çª æ示çã«åæããªãéãæ¥ç¶ããç¶ããâå¹ççã«åæ¹åéä¿¡ã
[ITç ä¿®]注ç®ãã¼ã¯ã¼ã Python UiPath(RPA) ææ°æè¡åå Microsoft Azure Docker Kubernetes 第12åãWebSocketã§ãµã¼ãããã·ã¥ (æ¾æ°¸ç´) 2014å¹´3æ 2/18ã«Rails3.2.17ã4.0.3ãåã³4.1.0.beta2ï¼*1ï¼ããªãªã¼ã¹ããã¾ããï¼*2ï¼ããããã¯ååã®ã¢ãããã¼ãåæ§ãDoSæ»æãXSSã®èå¼±æ§ã«å¯¾ããç·æ¥åº¦ã®é«ãã»ãã¥ãªãã£ãã£ãã¯ã¹ã®ããã§ãã®ã§ãã§ããã ãæ©ãã¢ãããã¼ããããã¨ããå§ããããã¾ãã ãã¦è©±ã¯å¤ããã¾ããã1/25ï½26ã«ããã¦éå¬ããããSECCON 2013 CTF ãªã³ã©ã¤ã³äºé¸ï¼*3ï¼ãã«åå ãã¦ã¿ã¾ããããã®äºé¸ã¯ãITæè¡ãã»ãã¥ãªãã£ã«é¢ãã5ã¤ã®ã¸ã£ã³ã«ããã©ã¬ã³ã¸ãã¯ã¹ããããã°ã©ãã³ã°ã»æå·ãããã¤ããªãããããã¯ã¼ã¯ã»Webãããã®ä»ã»ããªãã¢ãããè¨2
ws-ioã¯WebSocketã¨I/Oãçµã¿åããããã¨ã§Webãã¼ã¹ã®ã¿ã¼ããã«ãå®ç¾ããã ws-ioã¯Ruby製ã®ãªã¼ãã³ã½ã¼ã¹ã»ã½ããã¦ã§ã¢ãHTML5ã§æ°ããç»å ´ããæ©è½ã¯å¹¾ã¤ããããããã®ä¸ã§ãç¹æ®ãªä½ç½®ã«ããã®ãWebSocketã§ã¯ãªãã ãããï¼ä»æ§ããã¯åãé¢ããã¦ãããï¼ãããã¾ã§ã«ãªãã£ãã½ã±ããéä¿¡ãã©ãæ´»ããããåé¡ã ã Webä¸ã§irb ãã®ãããåºã¦ãããã®ããã£ããããããã¡ã¤ã³ã§ãã¾ã ã¾ã 模索ãã¦ãã段éã ããã®ãããªææã«ã¯ã¨ã«ããè²ã ãªãã®ãä½ãããã®ä¸ã§æãããããã¦ããã¨æããããã®ãè¦æ¥µããªããã°ãªããªããä»åã¯ãã®ä¸ã¤ãws-ioãç´¹ä»ãããã ws-ioã¯WebSocketã¨ãµã¼ãã®I/Oãã¤ãªãã¦ãã¾ãã½ããã¦ã§ã¢ã ãä¾ãã°Shellã¨ã¤ãªãã¦ãã¾ããã¨ã§ãWebãã©ã¦ã¶ä¸ã«ã¿ã¼ããã«ãç«ã¡ä¸ããã¨è¨ã£ãå ·åã ãWebSocketã§ç¹ãã£ã¦
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}