å æ¥ããªããªãå¼·çãªXSSæ»æææ³ãå ¬éããã¦ãã¾ããã DNSã¸ã®åãåããçµæã«JavaScriptãåãè¾¼ãã§ãã¾ããã¨ãããã®ã§ãã SkullSecurity: Stuffing Javascript into DNS names DarkReading: Researcher Details New Class Of Cross-Site Scripting Attack nCircle: Meta-Information Cross Site Scripting (PDF) èªåçæãããWebãã¼ã¸ä¸ã«ãDNSã«ããåå解決çµæãã¨ã¹ã±ã¼ããããªãç¶æ ã§å«ã¾ãã¦ããã¨ãJavaScriptãå®è¡ããã¦ãã¾ãã¨ããä»æãã§ãã ãhogehoge.example.comããæ¬æ¥ãªãã°ã198.1.100.3ãã¨ãããããªIPã¢ãã¬ã¹ãçµæã¨ãã¦è¿ãã¨ããããDNSã«ç´°å·¥ãè¡ã£
5å¹´ã«ä¸åº¦ãå½ãè¡ãå½å¢èª¿æ»ãã¯ãã¾ã£ã¦ãã¾ãã ãã®å½å¢èª¿æ»ã®å é¨ä½æ¥ãè¡ãæ¥è ãæ¯æ´ããããã®ã·ã¹ãã ããã»ã¼ã«ã¹ãã©ã¼ã¹ã»ãããã³ã ã®ã¯ã©ã¦ãã«ãã£ã¦æ§ç¯ããã¦ãããã¨ãåç¤¾ç¤¾é· å®éæ 次æ°ã®ãã¤ã¼ãã§æããã«ãªãã¾ããã ã¯ããä»°ãéãã§ãããã¼ããã¼æ§çµç±ã§ããã使ã£ããã次ã¯5å¹´å¾ã§ãããããã¯ã¢ãããç½å®³å¯¾çãç¡æã§ãéçºæéãæ°é±éã§ããRT @tera3pokole: @udaeiji ä»åã®å½å¢èª¿æ»ã®ã·ã¹ãã ã御社ãè«ãè² ãããã®ã§ãããããless than a minute ago via Echofonå®éæ 次 udaeiji ãã®è¨äºã§ã¯å½åãã»ã¼ã«ã¹ãã©ã¼ã¹ã»ãããã³ã ã®ã·ã¹ãã ãæ±äº¬é½ãã¢ãã«å°åã¨ãã¦è¡ãããå½å¢èª¿æ»ã®ãªã³ã©ã¤ã³åçã«ä½¿ããããã®ã¨æ¸ãã¾ããããééãã§ããããªã³ã©ã¤ã³åçã®ãã¼ã¿ã¯ã»ã¼ã«ã¹ãã©ã¼ã¹ã»ãããã³ã ã¯ä½¿ããã¦ãããããã¼ã¿ãå½å
ãã¼ã¼ã¼ã³ã£ã¨é³ãç«ã¦ãã©ã¸ã³ã³ããªãé£ãã ãiPhoneã§æä½ãããAR.Droneãã ããCEATEC 2010ãã§10æ5æ¥ã«è¡ãããããã«ãã£ã¹ã«ãã·ã§ã³ãé²åããã¢ãã¤ã«ããã¤ã¹ã®ç¾ç¶ã¨æªæ¥ãã®åé ã®ä¸å¹ããã¾ãã¯âæªæ¥âããã¨ãAR.Droneãç´¹ä»ãããã ã»ãã·ã§ã³ã¯ãITã¸ã£ã¼ããªã¹ãæä¿¡è¡ãããå ç±³Microsoftï¼MSï¼å¯ç¤¾é·ã®å¤å·äº« æ ¶å¿ç¾©å¡¾å¤§å¦ææãã¤ãã¼ã®æä¸è£EveryWhereéçºé¨é·ã¨ãã¬ã¸ã§ãã好ãã®é¢ã ãåºå¸ãiPhoneãAndroid端æ«ãããã¦ã©ã¼ã¯ãã³ãæããã®ãã¸ã¿ã«ã«ã¡ã©ãQV-10ãã¾ã§ããããããæ´ä»£ã®ãæ°ã«å ¥ããæ¯ãè¿ããæªæ¥ã®ããã¤ã¹ã«ã¤ãã¦å±æãèªã£ããã¢ãã¬ã¼ã¿ã¼ã¯ãã¢ã¤ãã£ã¡ãã£ã¢ã®æ¾å°¾å ¬ä¹ã¢ã°ãªã²ã¼ã·ã§ã³ã¡ãã£ã¢ç·¨éé·ãåããã ãã«ã»ã²ã¤ãã絶è³ãããQV-10ã ããããã¯ã©ããªããã¤ã¹ã§è²ã£ãã®ãââæããããä¸ã®ä¸
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}