Shibuya.XSS techtalk #7 ã®è³æã§ãã
Shibuya.XSS techtalk #7 ã®è³æã§ãã
é©å½ XSSããã=ãªãã§ãããæ¾é¡ã§ã¯ãªã ããã°ãµã¼ãã¹ãªã©èªç±ã«HTMLãããããããªãµã¼ãã¹ã§ã¯ã害ãåã°ãªãããã«è¡¨ç¤ºã丸ãã¨å¥ã®ãã¡ã¤ã³ã«åãã¦ãããããããã¯å¥ãã¡ã¤ã³ã®IFRAMEå ã§å®è¡ããããã¦ããã®ãæ®éã§ããå人æ å ±ãé ãã£ã¦ããµã¤ãã¯ãéè¦å人æ å ±ã«ã¤ãã¦ã¯HTTPSãããªãã¨åç §ã§ããªãã£ããããããã表示ããªãã£ãã(ãã¹ã¯ã¼ããã«ã¼ãçªå·ç)ã決æ¸ç¨ã®ãã¹ã¯ã¼ããæ証çªå·ãå ¥ããªãã¨æä½ã§ããªãã£ããããã åèã¾ã§ã« http://blog.bulknews.net/mt/archives/001274.html (2004å¹´ã®ã¢ã¡ããèå¼±æ§ã®è©±) http://d.hatena.ne.jp/yamaz/20090114 (ä¿¡é ¼ã§ããªããã¼ã¿ãåãæ±ããã¡ã¤ã³ãåãã話) 管çç¨ã¨å¥ãã¡ã¤ã³ã«åããã«ãé¢ããããscriptå®è¡ã§ãããã¨ã«å¯¾ãã¦DISãã
Tech sovereignty has become a looming priority for a number of nations these days, and now, with the demand for compute power at its highest level yet, a startup working⦠Itâs not the sexiest of subject matters, but someone needs to talk about it: The CFO tech stack â software used by the chief financial officers of the world â is ripe for disruption. Thatâs according to Jonathan Sanders, CEO and
I bet 10 years ago none of us thought that 140 characters would change the landscape of Social Media quite so much. However, with close to 289,000,000 active users sending around 6,000 tweets every second Twitter has proven its critics wrong. Obviously,  having gotten over the fact that 10 years of Twitter makes us all feel very old, we had to do something to mark this special day and we have had
å人㮠mixi æ¥è¨ã«ã³ã¡ã³ããã¤ã㦠ãã®å¾ã©ãã話ããã¿ãããªããªãã¨æã£ãã mixi æ¥è¨ã®è¨äºãã³ã¡ã³ãã§ã¯æååç §ã使ãããã§ããã ä½ãèããã«å ¥åããããæ®éã«å¤æããã¦ãã¾ã£ã¦ãã æååç §ã¨ããã®ã¯ã ãã¼ãã¼ãããã¯ç´æ¥å ¥åã§ããªãã£ãã å®ã¯ã§ãããã©æ®éã¯ç¥ããªãã£ãããããããªæåã HTML ã®ç¹æ§ã®é½åã§ãã®ã¾ã¾æ¸ãã¦ã¯ããºãæåã å¥ã®æ¹æ³ã§åç §ããããã®ãã®ã§ããã åè ã¯ä¾ãã°ã¾ãã¨ãã«ãã¨ãã ã¾ãã¯ã¾ãã¾ãã¯ã&fraq34;ã ã«ãã¯ã«ãã¾ãã¯ã«ã 㨠HTML å ã«æ¸ãã°ãã©ã¦ã¶ã«ã¯ç®çã®æåã表示ããã¾ããã å¾è ã§ãã使ãã®ã¯ãã¨ãã°ã<ããã>ãã§ã ããã¯ãã®ã¾ã¾è¨è¿°ãã¦ãã¾ã㨠HTML ã¿ã°ã®éå§ãçµäºã¨è§£éããã¦ãã¾ããã 代ããã«ã<ããã>ãã¨æ¸ãã¾ããã ãããã<
http://www.msng.info/archives/2009/06/caracter_reference_on_mixi_diary.php ã¨è¨ãã®ãè¦ã¦ã確èªãã¦ã¿ãã mixiã§ã¯ãã³ã¡ã³ããæ¥è¨ã®æ¬æã確èªããç»é¢ãåºã¦ããããå®éã«æ¸ãè¾¼ã¿ããããã«ãhiddenãã£ã¼ã«ãã§ãã¼ã¿ã®ããåãããã£ã¦ãããããã¯ãµã¼ãã®è² è·çãèãã¦ã®ãã¨ã ããã¨æãããã ã¨ãããã¨ã§ãã³ã¡ã³ããæ¥è¨ã®æ¬æã«ã&"><&ããå ¥ãã¦ã¿ãã ããããã¨ã確èªç»é¢ã§ã¯ä»¥ä¸ã®ãããªã¬ã¹ãã³ã¹ãå¾ãããã <p>&"><&</p> : <input type="hidden" name="comment_body" value="&"><&" />表示é¨åã§ã¯ãã&ã->ã&ããã"ã->ã"ããã<ã->ã<ããã>ã->ã>ãã¨å¤æãã¦
Twitterã®ã¤ã¶ãããçããããããããããã¯æ°·å±±ã®ä¸è§ãããããªããããã ãæ¡å¤§ããTwitterã¯ãããããã©ã®ãããªæ¹åã«é²ãã§ããã®ã ãããã 2008å¹´4æ23æ¥ã«æ¥æ¬çãµã¼ãã¹ãéå§ããã¦ãã¾ããªã1å¨å¹´ãè¿ããããããã°ãµã¼ãã¹ãTwitterããç±³comScoreã®èª¿æ»ã«ããã°ãå ¨ä¸çã®Twitterã®ãã©ãã£ãã¯ã¯ããæ°ã«æã§æ¥å¢ãã2æã«ã¯ä¼¸ã³çã700ï¼ ãè¶ ããã¨ãããããããççºçãªæé·ã®èæ¯ã«ã¯ãå¾æ¥ã®ä¸»ãªã¦ã¼ã¶ã¼å±¤ã§ãã18ï½24æ³ãããã20代å¾åï½50代ã®ã¦ã¼ã¶ã¼ãæ¥å¢ãã¦ãããã¨ãããããã ã ããã¦ãã¦ã¼ã¶ã¼ãå¢ããã¨ã¨ãã«ããã¾ãã¾ãªç¯ç½ªã®æ¨çã«ããªã£ã¦ãã¦ããããã®ãã¨ã¯ã以åãä¼ããéãã ãããã®æã¯æ³åãå¾ãªãã»ã©ã®æ¥å¢ã¶ããªã®ã ã ãªã³ã¯ãããã¿ã«ã¯ãªãã¯ãã¦ã¯ãããªãï¼ 4æ12æ¥ãç±³Twitterã¯XSSèå¼±æ§ãçªããã¯ã¼ã æ»æãåãã
æ¨æ¥Twitterã使ã£ã¦ããããçªç¶ã¿ã¤ã ã©ã¤ã³ã®èªåã®çºè¨ã«ãè¦ãã®ãªãè±æãæ稿ããã¦ããã®ã«æ°ã¥ãã¾ãããã¾ãããã¹ã¯ã¼ãã§ãçã¾ããã®ãã¨æãsettingç»é¢ãè¦ã¦ã¿ãã¨ããããã£ã¼ã«æ¬ãããªãããããªãã¨ã«ãªã£ã¦ãã¾ããã ã©ãããTwitterã«XSSèå¼±æ§ãåå¨ãã¦ãã¦ããã®èå¼±æ§ãã¤ããã¹ã¯ãªãããå®è¡ããã¦ãã¾ã£ããããªã®ã§ãã ãã®æ»æã³ã¼ãã®ä»çµã¿ã¯ãããªæãã§ããã ãããã£ã¼ã«ã®ãNameãã« script ã¿ã°ã document.write ã§æ¸ãåºãã³ã¼ããè¨å® ãã®ã¦ã¼ã¶ã®ãã¼ã¸ã表示ããã¨ã¹ã¯ãªãããå®è¡ããã å®è¡ãããã¹ã¯ãªããã«ãã£ã¦ãåæã«ã¤ã¶ãããæ稿ããã ããã«ãããã£ã¼ã«ã®ãNameãããURLãããèæ¯è²ããªã©ãæ¸ãæãããã ãã®ã¦ã¼ã¶ã®ãã¼ã¸ãä»ã®ã¦ã¼ã¶ãè¦ãã¨ãããã«ææ ã©ã®ãããªãååããè¨å®ããã¦ããããã¡ã¢ãå¿ãã¦ãã
(2009/04/12 6ï¼40 pm 追è¨ãã¾ãã) (2009/04/12 7ï¼24 pm å度追è¨ãã¾ãã) å ã»ã©ãã Twitterä¸ã«ã¦ XSS ã®ãã被害ãåºã¦ãã¾ãã æ¢ã«æµ·å¤ã®ããã°ãªã©ã§ãåãä¸ãããã¦ãã¾ãã HOWTO: Remove StalkDaily.com Auto-Tweets From Your Infected Twitter Profile (Twittercsm) Warning: Twitter Hit By StalkDaily Worm (TechCrunch) æ¢ã« XSS ã®é¨åã¯æ¹ä¿®ããã¦å¤§ååã¾ã£ãããã§ããã念ã®ããã«æ¸ãã¦ããã¾ãã å 容ã¨ãã¦ã¯ã 1. StalkDaily.com ã宣ä¼ããã¤ã¶ãããåæã«æ稿ããã 2. ãããã£ã¼ã«ã® Web ãæ¹ããããã 3. æ¹ãããããã¦ã¼ã¶ã¼ã®ãã¼ã¸ãè¦ãã¨ãèªåã®ãããã£ã¼ã«ã
çããããã«ã¡ã¯ãå·å£ã§ããã³ã©ã ã®ç¬¬6åãIPSã¯âéæ³ã®ç®±âããã§ã¾ã£ã¡ãï¼ï¼ï¼ã§è¬æ¼ãããã話ãæ¸ãã¾ããããä»åº¦ã¯é¢æ±ã§ãã£ã¦ãããã¾ã£ã¡ãï¼ï¼ï¼ãã«ãæãããã ããã話ããã¦ãã¾ããã ã¾ã£ã¡ãï¼ï¼ï¼ã¯åééå§ããå®å¡ãåã¾ãã¾ã§ãã¨ã¦ãéããä»ã¾ã§åå ãããã¨ããªãã£ãã®ã§ãããä»åã¯éè¯ãï¼ï¼ï¼è¬å¸«å´ã¨ãããã¨ã§ãã£ã³ã»ã«å¾ ã¡ã«ãªããã«åå ãããã¨ãã§ãã¾ãããããã¯ãªã³ã®ç¦ç°ããããªã¼ãã³ã½ã¼ã¹ã®ECãµã¤ãæ§ç¯ã·ã¹ãã ãEC-CUBEãã«èå¼±ï¼ãããããï¼æ§ãçºè¦ãããéã®ã¤ã³ã·ãã³ããã³ããªã³ã°ã®ã話ãããã¦ãã¾ãããEC-CUBEã«SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã¨ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼ä»¥ä¸ãXSSï¼ãçºè¦ããããã¨ã®å¯¾å¿ã®ã話ã§ããJSOCã§æ¥ã ã¤ã³ã·ãã³ãã«ãããã£ã¦ããããèªåã¨ãã¦ã¯ã¨ã¦ãèå³æ·±ãå 容ã§ããã æ¥æ¬ã®ã¨ã³ã¸ãã¢ã®ã»ãã¥ãªãã£æèã¯éå°ï¼ ä»åã®ãã
Introduction Index Alphabetical Index ASVS Index MASVS Index Proactive Controls Index Top 10 Cheatsheets Cross Site Scripting Prevention Cheat Sheet¶ Introduction¶ This cheat sheet helps developers prevent XSS vulnerabilities. Cross-Site Scripting (XSS) is a misnomer. Originally this term was derived from early versions of the attack that were primarily focused on stealing data cross-site. Since t
_U+00A5ãç¨ããXSSã®å¯è½æ§ ååã®æ¥è¨ã§ã¯ãæ¨å¹´ã®Black Hat Japanã«ãããé·è°·å·é½ä»æ°ã®è¬æ¼ã«ã趣å³ã¨å®çã®æåã³ã¼ãæ»æ(è¬æ¼è³æ)ãã«åºæ¿ãããå½¢ã§ãUnicodeã®åè¨å·U+00A5ã«ããSQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã®å¯è½æ§ã«ã¤ãã¦ææããã ã¯ãããæ°ã®å è³æã§ã¯ãã¹ãã©ãã¼ãµã«ã®å¯è½æ§ãææãã¦ããããã®ã§ãæ®ãèå¼±æ§ãã¿ã¼ã³ã¨ãã¦ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°(XSS)ã®å¯è½æ§ããããã©ããããã£ã¨æ°ã«ãªã£ã¦ãããç¬èªã®èª¿æ»ã«ãããXSSæ»æã®èµ·ç¹ã¨ãªãã<ããã"ããã'ããªã©ã«ã¤ãã¦ãå¤å¯¾ä¸ã®å¤æãããããæåãæ¢ãã¦ããããç¾å®çãªWebã¢ããªã±ã¼ã·ã§ã³ã§åºç¾ããããªçµã¿åããã¯è¦ã¤ãããã¦ããªãã ä¸æ¹ãU+00A5ãå¦çç³»ã«ãã£ã¦ã¯0x5Cã\ãã«å¤æããããã¨ã«èµ·å ãã¦XSSãçºçããå¯è½æ§ã¯ãããJavaScriptããããå ´åãããã ããããã
2009å¹´03æ03æ¥19:00 ã«ãã´ãªLightweight Languages perl - Encodeã§XSSãé²ã è¯è¨äºã 第7åâ æåã¨ã³ã³ã¼ãã£ã³ã°ãçã¿åºãããå¼±æ§ãç¥ãï¼ITpro ã ãã©ãåé¡ç¹ã®ã¿å ·ä½ä¾ããã£ã¦ã対çã«ãªãã®ãçæè½ã¡ã«æããããã®ã§ããã®ç¹ãè£è¶³ã çµè«ã ãè¨ã£ã¦ãã¾ãã°ãPerlãªã以ä¸ã®ååãå®ãã ãã§ãã 404 Blog Not Found:perl - Encode å ¥é ãã§ã«OSCONã§ãYAPCã§ãããã¡ãã¡ãã¡ãã¡ã§ãã®åºæ¬æ¹éã«é¢ãã¦ã¯è©±ããã®ã§ããããã 404 Blog Not Found ã§ãæ¹ãã¦ã Perl 㧠utf8 åãããã¨ãã«ã©ããããããã - TokuLog æ¹ã ã ã¾ã£ã¦ã³ã¼ããæ¸ãããã²å ¥ãå£ã§ decode ãã¦ãå é¨ã§ã¯ãã¹ã¦ flagged utf8 ã§æ±ããåºå£ã§ encode ãããããã
ã¯ãï¼ ããã«ã¡ã¯ï¼ ä»æ¥ã¯çããã»ãã¥ãªãã£ã«ã¤ãã¦ä¸è¨ã§ãï¼ ã¿ã¤ãã«ã«ããéãã XSSã¯ãã®ãµã¤ããä¿¡é ¼ãã¦ãã人ãå¤ãã»ã©è å¨ã«ãªããã ã£ã¦ãã¨ãªãã ãã©â¦ãããã ãã ã¨ããããã¾ãã£ã½ãããã ã¾ãXSSèå¼±æ§ã£ã¦ãªã«ï¼ ã£ã¦äººã®ããã«ç°¡åã«èª¬æãã¡ããã¨ããã ãµã¤ããä½ã£ã人以å¤ã®äººã§ãã好ããªã¹ã¯ãªãããå®è¡ã§ãã¡ããç¶æ ã£ã¦ãã¨ãªãã ããã ã§ãããèãã¦ã¿ã¦ã»ããã ã¹ã¯ãªãããå®è¡ã§ãããã¸ããªã¹ã¯ãªãããå®è¡ããã¡ãããããããªããã¼ã¸ã ããã£ã¦å¥ã«ãããµã¤ãã«ã¹ã¯ãªããã許å¯ããã¦ããããããã¸ãã®ããã°ããã¼ã ãã¼ã¸ã¨åãããããªãï¼ ãããå¾®å¦ã«éãããªã éãç¹ã¯ã²ã¨ã¤ã ã¹ã¯ãªãããåãè¾¼ããã®ãããµã¤ãã®ç®¡çè ãªã³ãªã¼ããªã®ãã誰ã§ãããªã®ãã®éãããããã ããã ⦠ãããããåããªããµã¤ãã®ç®¡çè ãã¨ã誰ã§ããã®éãã£ã¦ãªãã ããï¼ ãªãã ã
ããããäºåinãXSSãããã¡ãã£ããããã§ããï¼ ä½¿ãå¤ãããææ³ï¼ ãã¾ã©ãã¨ã¹ã±ã¼ãå¦çãããã¦ãªãã¦ããµãï¼ é¢é£ã®è¨äºã«å¯¾ãã¦ãã¯ã¦ãªããã¯ãã¼ã¯ã§ãè²ã è¨ããã¦ãããã http://b.hatena.ne.jp/t/%E4%BA%88%E5%91%8A.in?threshold=1 ãã¥ã¼ã¹ãµã¤ãã§ãããããªç ½ãè¨äºãæ¸ããã¦ãããããããã©â¦ ä»åã®ä»¶ã«ã¤ãã¦ITä¼æ¥ã«å¤ããã¨ã³ã¸ãã¢ã«èãã¦ã¿ãã¨ã ãããã¯åæ©ä¸ã®åæ©ãXSSã³ã¼ãæ¸ããæ¹ã10åãæãã£ã¦ãªããããããäºåã«å¯¾çãã¦ãªãã£ãäºåinã«ã¯ãã£ã¨ããã¯ãªã ãã©ãããç´ äººãªã®ï¼ã ã¨èªãã äºåinã»ãã¥ãªãã£èå¼±æ§ãçã£ãã³ã¼ã!?ããäºåinéçºè ã¯ç´ 人ã http://news.livedoor.com/article/detail/3759632/ ããã£ã¦ã©ãã ãããã GoogleãAmazo
XSS (Cross Site Scripting) Cheat Sheet Esp: for filter evasion By RSnake Note from the author: XSS is Cross Site Scripting. If you don't know how XSS (Cross Site Scripting) works, this page probably won't help you. This page is for people who already understand the basics of XSS attacks but want a deep understanding of the nuances regarding filter evasion. This page will also not show you how to
ã¤ãã«ãã¨ãªã£ã¦ä¼ç»ããã第1åXSSç¥ãããã¿ãã¨æã£ã¦ãã¾ããããå æ¥ã®æ¥ææ¥ã«éå¬ãããç¡äºçµäºãã¾ããã XSSæ¬ã®æ´æ¸ XSS Attacks: Cross Site Scripting Exploits and Defense ãæ¥æ¬ã«å±ããã®ã§ã ãã®ã¿ã¤ãã³ã°ã«æè¿ã®XSSã®å¾åãæ´çãã¦ããããã®æ»æãé²å¾¡ããææ³ã«ã¤ãã¦ã¿ããªã§åå¼·ãã¾ããã å®éãæ¬ã®å 容ã«ã¯ããã¾ã触ããªãã£ãã§ããã©ããã¿ã§Anti-Anti-Antiã¨ãã çµå§ã¾ã£ããã¨ããé°å²æ°ã®ä¸ãåå è ã®é£ã³å ¥ããã¬ã¼ã³ãSkypeä¸ç¶ããã£ããã¨ã大å¤æ¥½ããåå¼·ä¼ã§ããã åå è ãåå è ã ãã«ãå½å ï¼ä¸ççã«ãï¼æå 端ã®è©±ãå ±æãããã¨ãã§ãã¦ãææ義ãªæéãéãããã¨ãã§ãã¾ããã ï¼è©³ç´°ã¯ãã¨ã§æ¸ããï¼ ããããããã®åå¼·ä¼ã®ããã ãã«æ°å¹¹ç·ã§ä¸äº¬ãããæ¹ãããã£ããã£ãã¨ã®ãã¨ã§ã ãã®ç±æã«ã¯æ
ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼ ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ã®æéã§ãï¼ XSSã¨ããã¨â¦ï¼ ã¾ã£ããã«æãã¤ãã®ããå ¥åãã¼ã¿éä¿¡ â 確èªè¡¨ç¤ºã®é¨åã§ã®ç¡å®³åæ¼ãã§ãããï¼ ãã¨ãã°ãããªæãã®ãã©ã¼ã ããåãåã£ããã©ã¡ã¼ã¿ãã 確èªã¨ãã¦è¡¨ç¤ºãããã¼ã¸ã¨ãï¼ (å ¥å) <form action="register.cgi" method="post"> ã¿ã¤ãã«ï¼<input type="text" name="title"> â ãã¼ãã¯ã¾ã¡ã¡ããï¼ããå ¥å æ¬æï¼<input type="text" name="body"> â ãããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼<script>alert(1)</script>ããå ¥å </form> (確èª) <p>ãã®å 容ã§ç»é²ãã¦ããï¼</p> <p> ã¿ã¤ãã«ï¼ ã¼ãã¯ã¾ã¡ã¡ããï¼<br> æ¬æï¼ ããã«ã¡ã¯ããã«ã¡ã¯ï¼ï¼<script>alert
MySpaceãçã£ãæ»æãç¸æ¬¡ãã ãã¨ãåããF-Secureãã»ãã®äººæ°SNSã調ã¹ãã¨ãããã¯ã¼ã ä½æã«å©ç¨ã§ããèå¼±æ§ãå¹¾ã¤ãè¦ã¤ãã£ãã¨ããã 人æ°ã½ã¼ã·ã£ã«ãããã¯ã¼ãã³ã°ãµã¤ãï¼SNSï¼ã®MySpaceãæ¨çã¨ããæ»æãç¸æ¬¡ãã§æµ®ä¸ããä¸ãã»ãã¥ãªãã£ä¼æ¥ã®F-Secureã¯ãã»ãã®SNSã«ãããããæ»æã«æªç¨ãããããªãèå¼±æ§ãå¤æ°åå¨ããã¨å ±åããã F-Secureã«ããã¨ãWebãµã¤ãã«åå¨ããã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼XSSï¼ã®èå¼±æ§ãçªããWebã¢ããªã±ã¼ã·ã§ã³ã¯ã¼ã ããæ°æã®ãã«ã¦ã§ã¢ã¨ãã¦æµ®ä¸ãSNSãæ ¼å¥½ã®æ¨çã«ãªã£ã¦ãããMySpaceãæ¨çã¨ããã¯ã¼ã ã¯æ¢ã«2件åºç¾ãã¦ããã¨ããã ãã®ãã¡æ¨å¹´10æã«åé¡ã«ãªã£ããSamyãã¯MySpaceã§åæã«åéãå¢ããã¦ãã¾ãã¯ã¼ã ãæ°æ¥åã«ç»å ´ãããFlashãã¯ã¼ã ã¯Flashã®èå¼±æ§ãçªãã¦ãã¦ã¼ã¶ã¼
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}