CTF Advent Calendar 2019 - Adventarã®25æ¥ç®ã®è¨äºã§ãã 1ã¤åã¯@ptr-yudaiæ°ã®2019å¹´ã®pwnåãå ¨é¨è§£ããã£ã¬ã³ã¸ãå¾åæ¦ã - CTFãããã§ããã ã¯ãã㫠対象ã¤ãã³ã åé¡æ° èªã¿æ¹ã使ãæ¹ Cross-Site Scripting(XSS) SVGãã¡ã¤ã«ãå©ç¨ããCSPãã¤ãã¹ Googleãã¡ã¤ã³ã®JSONPãå©ç¨ããCSPãã¤ãã¹ ãµããªã½ã¼ã¹å®å ¨æ§(SRI)æ©è½ãå©ç¨ããå ¥åãã§ãã¯ãã¤ãã¹ Chromeæ¡å¼µæ©è½ã®ãã¹ã¯ã¼ãããã¼ã¸ã£ã¼KeePassã®æªç¨ HTML likeã³ã¡ã³ãã使ç¨ããã³ã¡ã³ãã¢ã¦ã jQuery.getJSONã®JSONPæ©è½ã使ç¨ããã¹ã¯ãªããå®è¡ DOM Clobberingã«ããã³ã¼ããã¤ã¸ã£ã㯠Service Workerãå©ç¨ããã¹ã¯ãªããå®è¡ XSS Auditoræ©è½ã®ãã¤ãã¹
{{#tags}}- {{label}}
{{/tags}}