2024/10/5 YAPC::Hakodate 2024
2024/10/5 YAPC::Hakodate 2024
Security.Tokyo #3ã®çºè¡¨è³æã§ãã ã¯ã©ã¤ã¢ã³ããµã¤ãã®ãã¹ãã©ãã¼ãµã«ã¨ãpostMessageçµç±ã®èå¼±æ§ãåãä¸ãã¾ããã
curl -c cookie01.txt -s -L -X GET "https://www.qq.pref.ehime.jp/qq38/WP0805/RP080501BL" | hxnormalize -x > qq.html CSRF=$(cat qq.html | hxselect 'input[name="_csrf"]::attr(value)' | cut -d= -f2 | tr -d '"') URL=$(cat qq.html | hxselect 'form[id="_wp0805Form"]::attr(action)' | cut -d= -f2 | tr -d '"' | sed 's;^/;https://www.qq.pref.ehime.jp/;;') curl -b cookie01.txt -X POST -d "torinBlockDetailInfo
Hi , This book is a collection of "BugBounty" Tips tweeted / shared by community people. It includes the tweets I collected over the past from Twitter , Google and Hastags and chances that few tips may be missing. I have categorized tips against each vulnerability classification and "will be updating" regularly. Each tweet has link to original tweet to read about others replies / comments. Huge "T
CTF Advent Calendar 2019 - Adventarã®25æ¥ç®ã®è¨äºã§ãã 1ã¤åã¯@ptr-yudaiæ°ã®2019å¹´ã®pwnåãå ¨é¨è§£ããã£ã¬ã³ã¸ãå¾åæ¦ã - CTFãããã§ããã ã¯ãã㫠対象ã¤ãã³ã åé¡æ° èªã¿æ¹ã使ãæ¹ Cross-Site Scripting(XSS) SVGãã¡ã¤ã«ãå©ç¨ããCSPãã¤ãã¹ Googleãã¡ã¤ã³ã®JSONPãå©ç¨ããCSPãã¤ãã¹ ãµããªã½ã¼ã¹å®å ¨æ§(SRI)æ©è½ãå©ç¨ããå ¥åãã§ãã¯ãã¤ãã¹ Chromeæ¡å¼µæ©è½ã®ãã¹ã¯ã¼ãããã¼ã¸ã£ã¼KeePassã®æªç¨ HTML likeã³ã¡ã³ãã使ç¨ããã³ã¡ã³ãã¢ã¦ã jQuery.getJSONã®JSONPæ©è½ã使ç¨ããã¹ã¯ãªããå®è¡ DOM Clobberingã«ããã³ã¼ããã¤ã¸ã£ã㯠Service Workerãå©ç¨ããã¹ã¯ãªããå®è¡ XSS Auditoræ©è½ã®ãã¤ãã¹
ããã«ã¡ã¯ãGoã§Webéçºãã¦ãã¾ããï¼ç§ã¯ãã¦ãã¾ãããGoã«éãããæ¢æã®Webã¢ããªã±ã¼ã·ã§ã³ãã¬ã¼ã ã¯ã¼ã¯ã使ããã«èªåã§Webãã©ã¼ã ãä½ãå ´åããªã«ãèããã«æ¸ã㨠CSRF (Cross Site Request Forgery) èå¼±æ§ãä½ããã¿ãä¸æ£ãªã¦ã¼ã¶ã¼æä½ãå®è¡ããã¦ãã¾ãå¯è½æ§ãããã¾ãã ãã¡ãªä¾ ä¾ãã°ä»¥ä¸ã®Goã³ã¼ãã§ä½æããããã©ã¼ã ã«ã¯CSRFèå¼±æ§ãããã¾ããSubmitSignupForm ãã³ãã©ã¯ãåãåã£ããªã¯ã¨ã¹ããèªåã®ãµã¤ãä¸ã®ãã©ã¼ã ãããµããããããããã®ããã§ãã¯ãã¦ããªãã®ã§ãæ»æè ãä»ã®ãµã¤ãä¸ã®ãã©ã¼ã ã使ãã第ä¸è ã®ã¦ã¼ã¶ã¼ã®ãã©ã¦ã¶ã§ä»»æã®æä½ãå®è¡ããããã¨ãã§ãã¦ãã¾ãã¾ãã func main() { r := mux.NewRouter() r.HandleFunc("/signup", ShowSignupF
ã¯ããã« Reactã¨Playã§èªè¨¼ã¯ã©ã®ããã«ããã°ãããã¨æã調ã¹ã¦ã¿ã¾ããã èªè¨¼ã®åºæ¬çãªæµãã«ã¤ãã¦ã¯ãã¡ããåèã«ãã¾ãããèªè¨¼ãµã¼ãã¹ã¨ãã¦APIã®ã¨ã³ããã¤ã³ããç¨æãã¦ãReactã¢ããªã±ã¼ã·ã§ã³ããèªè¨¼ããæ¹æ³ã§ãã èªè¨¼ã«ã¯JWTã使ç¨ãã¾ããã¾ãJWTå ã«ãã¼ã«ãå ¥ãããã¨ã§èªå¯æ©è½ã追å ãã¾ãã Webã¢ããªã±ã¼ã·ã§ã³ãã¬ã¼ã ã¯ã¼ã¯ã«ã¯Playã使ç¨ãã¦ãã¾ãã èªè¨¼ã¨èªå¯ã®ã©ã¤ãã©ãªã«ã¯Silhouetteã使ç¨ãã¾ããä¸ããã ã¨åããã¥ããã®ã§play-silhouette-seedã®ãã³ãã¬ã¼ãã使ç¨ãã¦ãã¾ãã ãããå°ãå¤ãã¦JWTèªè¨¼ããã¦ã¿ããã¨æãã¾ãã Silhouetteã®æ¦è¦ã«ã¤ãã¦ã¯ãã¡ããåç §ãã¾ããã 使ç¨ãããã¼ã¸ã§ã³ã§ãã Play 2.5.4 Silette 4.0 åæè¨å® Silhouetteã®ã¨ã³ããã¤ã³ãã§ä½¿ç¨ãã Ide
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}