2024/11/11ã12 ã«è¡ããã JPAAWG 7th General Meeting ã§çºè¡¨ããè³æã§ã https://meetings.jpaawg.org/
ãã®è¨äºã¯æ¤è¨¼å¯è½ãªåèæç®ãåºå ¸ãå ¨ã示ããã¦ããªãããä¸ååã§ãã åºå ¸ã追å ãã¦è¨äºã®ä¿¡é ¼æ§åä¸ã«ãååãã ãããï¼ãã®ãã³ãã¬ã¼ãã®ä½¿ãæ¹ï¼ åºå ¸æ¤ç´¢?: "EICARãã¹ããã¡ã¤ã«" â ãã¥ã¼ã¹Â · æ¸ç±Â · ã¹ã«ã©ã¼Â · CiNii · J-STAGE · NDL · dlib.jp · ã¸ã£ãã³ãµã¼ã · TWL (2023å¹´1æ) EICARãã¹ããã¡ã¤ã« (EICAR Standard Anti-Virus Test File) ã¨ã¯ EICAR ãéçºããã¢ã³ãã¦ã¤ã«ã¹ (AV) ã½ããã¦ã§ã¢ã®å¿çããã¹ãããããã®ãã¡ã¤ã«ã§ããã AVã½ããã¦ã§ã¢ã®ãã¹ãã§å®éã®ã³ã³ãã¥ã¼ã¿ã¦ã¤ã«ã¹ã使ãã¨å ·ä½çãªãã¡ã¼ã¸ãçãã¦AVã½ããã¦ã§ã¢ãç ´æããæ£ããåä½ã§ããªãå¯è½æ§ãããããããã®ãããªåé¡ãèµ·ãããã«AVã½ããã¦ã§ã¢ã®ãã¹ãããããã¨ãæå³ã¨ãã¦ãããEICARã«ã
ã¯ããã« ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®é½è¤ãã¨azaraã§ããä»åã¯ãä¸å¯æè°ãªContent-Typeã®å¤ã¨ãã¯ã©ã¦ãæ代ã§ã®ã»ãã¥ãªãã£ãªã¹ã¯ã«ã¤ãã¦ã話ããã¾ãã æ¬ããã°ã¯ã2024 å¹´ 3 æ 30 æ¥ã«éå¬ããã BSides Tokyo ã§ç»å£ããéã®çºè¡¨ã«ã¤ãã¦ãã¾ã¨ãããã®ã§ãã ã¾ããããã°è³æåã«ããããContent-Type ã®åä½ãä»æ§ã«ãã©ã¼ã«ã¹ããå½¢ã§åç·¨ãè¡ããç»å£æã«å£é ã§è£è¶³ããå 容ã®è¿½è¨ãå¿ è¦ã«å¿ããè£è¶³ãè¡ãªã£ã¦ãã¾ãã ã¾ããæ¬ããã°ã§è§£èª¬ããã BSides Tokyoã§ã®çºè¡¨ã®ããä¸ã¤ã®é¡ã§ããããªãã¸ã§ã¯ãã¹ãã¬ã¼ã¸ã«ã¤ãã¦ã¯ã以ä¸ã®ããã°ãã確èªããããã¨ãå¯è½ã§ãã®ã§ãã覧ãã ããã blog.flatt.tech ãªãä»ããã®åé¡ãåãä¸ããã®ãï¼ å¾æ¥ã®ãã¡ã¤ã«ã¢ãããã¼ãã«ããã¦ãContent-Type ã®å¤ãä»»æã®å¤ã«è¨å®ãããã¨
Intro CSRF ã¨ããå¤ã®æ»æãããããã®æ»æããå¤(ãã«ãã)ãã®ãã®ã«ãããã¨ãã§ãããã©ãããã©ã¼ã ã®é²åã®èæ¯ãããCookie ã SameSite Lax by Default ã«ãªã£ãããã ãã¨ãã解説ãè¦ããã¨ãããã 確ãã«ãç¾å®çã«ããã«ãã£ã¦æ»æã®æç«ã¯é£ãããªããæããã¦ãããµã¼ãã¹ããããããããããã¯ãã©ãããã©ã¼ã ãç¨æãã対çã®æ¬è³ªããè¨ãã¨ã解éãå°ãããã¦ããã¨è¨ããã ããã ä»åã¯ããCSRF ãã©ããã¦æç«ãã¦ããã®ãããæ¯ãè¿ããã¨ã§ãæ¬å½ã«ãã©ãããã©ã¼ã ã«è¶³ãã¦ããªãã£ããã®ã¨ããããè£ã£ã¦ãã£ãçµç·¯ãæ¬å½ã«ãã¹ã対çã¯ä½ã§ãããã解説ãã¦ããã çµæã¨ãã¦è¦ãã¦ããã®ã¯ãä»ãµã¼ãã¹ãå®è£ ããä¸ã§ã®ããã¼ã¹ã(not ãã¹ã)ã¨ãªããã©ã¯ãã£ã¹ã ã¨çè ã¯èãã¦ããã CSRF æç«ã®æ¡ä»¶ ä¾ãã°ãæ»æè ãç¨æãã attack.examp
2. 徳丸浩ã®èªå·±ç´¹ä» ⢠çµæ´ â 1985å¹´ 京ã»ã©æ ªå¼ä¼ç¤¾å ¥ç¤¾ â 1995å¹´ 京ã»ã©ã³ãã¥ãã±ã¼ã·ã§ã³ã·ã¹ãã æ ªå¼ä¼ç¤¾(KCCS)ã«åºåã»è»¢ç± â 2008å¹´ KCCSéè·ãHASHã³ã³ãµã«ãã£ã³ã°æ ªå¼ä¼ç¤¾(ç¾ç¤¾å:EGã»ãã¥ã¢ã½ãªã¥ã¼ã·ã§ã³ãºæ ªå¼ä¼ç¤¾)è¨ç« ⢠çµé¨ããã㨠â 京ã»ã©å ¥ç¤¾å½æã¯CADãè¨ç®å¹¾ä½å¦ãæ°å¤ã·ãã¥ã¬ã¼ã·ã§ã³ãªã©ãæ å½ â ãã®å¾ãä¼æ¥åãããã±ã¼ã¸ã½ããã®ä¼ç»ã»éçºã»äºæ¥åãæ å½ â 1999å¹´ãããæºå¸¯é»è©±åãã¤ã³ãã©ããã©ãããã©ã¼ã ã®ä¼ç»ã»éçºãæ å½ Webã¢ããªã±ã¼ã·ã§ã³ã®ã»ãã¥ãªãã£åé¡ã«ç´é¢ãç 究ã社å å±éãå¯ç¨¿ãªã©ãéå§ â 2004å¹´ã«KCCS社å ãã³ãã£ã¼ã¨ãã¦Webã¢ããªã±ã¼ã·ã§ã³ã»ãã¥ãªãã£äºæ¥ãç«ã¡ä¸ã ⢠ç¾å¨ â EGã»ãã¥ã¢ã½ãªã¥ã¼ã·ã§ã³ãºæ ªå¼ä¼ç¤¾åç· å½¹CTO https://www.eg-secure.co.jp/ â
ããã«ã¡ã¯ã @okazu_dm ã§ãã ãã®è¨äºã¯ãCookieã®SameSiteå±æ§ã«ã¤ãã¦ã®è§£èª¬ã¨ããã®ä¸ã§ãä¾å¤çãªæåã«ã¤ãã¦ã®è§£èª¬è¨äºã§ãã ãµã¼ããã¼ãã£CookieãCSRF対çã®æèã§Cookieã®SameSiteå±æ§ã«é¢ãã¦ã¯ãåç¥ã®æ¹ãå¤ãã¨æãã¾ããæ¬è¨äºã§Cookieã®åºç¤ããæè¿ã®ãã©ã¦ã¶ä¸ã§ã®SameSiteå±æ§ã®æ±ãã«ã¤ãã¦è§¦ãã¤ã¤ãæçµçã«HSTS(HTTP Strict Transport Security)ã®ãããªæ³¨æç¹ãå«ãã¦æ¯ãè¿ãã®ã«å½¹ç«ã¦ã¦ããã ããã°ã¨æãã¾ãã åææ¡ä»¶ Cookieã«ã¤ã㦠Cookieã®å±æ§ã«ã¤ã㦠SameSiteå±æ§ã«ã¤ã㦠SameSiteå±æ§ã«é¢ããè½ã¨ãç©´ SameSiteå±æ§ãæå®ããªãã£ãå ´åã®æå SameSite: Strictã§ãæ»æãæåããã±ã¼ã¹ ä¾1: ã¹ãã¼ã ã ãéãã±ã¼ã¹ ä¾2: ãµããã¡ã¤
IETFãCAB Forumã§æå¹æéã®çã証ææ¸(Short-lived Certificate)ã«ã¤ãã¦è°è«ããããããªã®ã§è»½ãçºãã¦ãã 詳ãã人ã¯è£è¶³ããã ããã¨å¬ããã§ã èæ¯ Googleã§ã¯ãWebãããå®å ¨ã«ããããã«Web PKIã®ããªã·ã¼ã«ã¤ãã¦æ§ã ãªåãçµã¿ãè¡ã£ã¦ãã¾ãã www.chromium.org ãã®åãçµã¿ã®ãªãã«ã¯CAã証ææ¸ã®çºè¡ããªã·ã¼ã«é¢ãããã®ãããã¾ãã æå¹æéã®çã Short-lived証ææ¸ ã®å©ç¨ãä¿ããããèªååãä¿é²ããããã«ãCA/Browser Forumã®Baseline Requirementsã«å¯¾ãã¦ææ¡ãè¡ã£ã¦ãã¾ãã å ·ä½çãªProposalã§ã¯ãOCSPãOptinalã«ãããã¨ã¨ãShort-lived Certificateã§å¤±å¹(Revocation)ãä¸è¦ã§ããã¨ãããã¨ãææ¡ãã¦ãã¾ãã github.
2023å¹´1æ26æ¥ãæç¥çè¦ã¯ç¬¬ä¸è ã®SIMã«ã¼ããä¸æ£ã«åå¾ããã¨ãã¦ç·2人ãé®æããã¨å ¬è¡¨ãã¾ãããã¾ã2æ22æ¥ã«ã¯ãåå¾ããä»äººå義ã®SIMã«ã¼ããç¨ãã¦ä¸æ£ééãè¡ã£ã¦ããã¨ãã¦åé®æããã¾ãããããã§ã¯é¢é£ããæ å ±ãã¾ã¨ãã¾ãã SIMã¹ã¯ããã§4åä¸åè¶ ã®ä¸æ£ééã æçºãããã®ã¯ç¥å¥å·çã®ç·ã¨æ±äº¬é½ã®ç·ã®2åã§ãç¥å¥å·çã®ç·ãéãã¤ãã¨ãã¦å§èªãè¡ã£ã¦ãããç·2åãè¡ã£ã¦ããã®ã¯ä¸æ£ã«åå¾ããä»äººå義ã®SIMã«ã¼ãã使ç¨ãSIMã¹ã¯ããã¨å¼ã°ããæå£ã§ãè©åããä»äººå義ã®SIMã«ã¼ãã使ç¨ãã¦ä¸æ£ééãè¡ã£ã¦ãããå½å ã§åæå£ã®é®æè ãåºãã®ã¯çãã(è©åããä»äººå義ã®SIMã«ã¼ãã«ããä¸æ£ééäºæ¡ã§ã¯å ¨å½ã§åãã¦)ã¨å ±ãããã¦ããã*1 æç¥çè¦ã¯ç·2åã«å¯¾ãã¦ã2023å¹´1æ25æ¥ã«è©æ¬ºã¨å½é æå°å¸å ¬ææ¸è¡ä½¿ããã®å¾2æ22æ¥ã«ã¯ä¸æ£ã¢ã¯ã»ã¹ç¦æ¢æ³éåãé»åè¨ç®æ©ä½¿ç¨
å® ãµããã便ããå¹³æãã¹ã¯ã¼ããæ¼æ´©ãã件ãåãã¦ãããããã¦ãã¹ã¯ã¼ãã®å®å ¨ãªä¿åæ¹æ³ãé¢å¿ãéãã¦ãã¾ããç¾å¨ã®ãã¹ã¯ã¼ãä¿åã®ãã¹ããã©ã¯ãã£ã¹ã¯ããã¹ã¯ã¼ãä¿åã«ç¹åããããã·ã¥é¢æ°ï¼ã½ã«ããã¹ãã¬ããã³ã°ãç¨ããï¼ã§ããbcryptãArgon2ãªã©ãç¨ãããã¨ã§ããPHPã®å ´åã¯ãPHP5.5以éã§ä½¿ç¨ã§ããpassword_hashé¢æ°ãé常ã«ä¾¿å©ã§ãããä»ã®è¨èªãã¢ããªã±ã¼ã·ã§ã³ãã¬ã¼ã ã¯ã¼ã¯ã§ããããããç¨æããã¦ãããã¹ã¯ã¼ãä¿è·ã®æ©è½ã使ããã¨ã¯ãã¹ã¯ã¼ãä¿è·ã®ç¬¬ä¸é¸æè¢ã¨ãªãã¾ãã ãªãã§ãbcryptã¯ãPHPã®password_hashé¢æ°ã®ããã©ã«ãã¢ã«ã´ãªãºã ã§ããä»ãä»ã®è¨èªã§ãå®å ¨ãªããã·ã¥ä¿åæ©è½ã¨ãã¦åºãå©ç¨ããã¦ãã¾ããããã¹ã¯ã¼ããæ大72æåã§åãè©°ããããã¨ããå®è£ ä¸ã®ç¹æ§ãããããã®ç¹ãæ°ã«ãªã人ãããããã§ãï¼ãã®å¶éã¯DoSèå¼±æ§åé¿ã
I guess the gist of my question is: Are there cases in which CBC is better than GCM? The reason I'm asking is that from reading this post by Matthew Green, and this question on cryptography stack exchange, and this explanation of an attack on XML (since I'm encrypting json in my work, although it's not streamed anywhere, but apparently a chosen cipertext attack is possible), then I should never, e
ç¾å¨ã®Webã§ã¯ãã»ãã¥ãªãã£ä¸ã¬ã¹ãã³ã¹ãããã§è²ã ãªãã®ãæå®ãã¾ããWebãããããã¼ã¯åå¥ã«æå®ããªããã°ãªãã¾ããã ããã§ãã»ãã¥ãªãã£é¢é£ã®ããããæ¨å¥¨ããã©ã«ãå¤ã«è¨å®ã§ããããã«ãããBaseline ããã (Opt-into Better Defaults)ãããGoogleã®Mike Westæ°ã«ãã£ã¦ææ¡ããã¦ãã¾ãã ã¾ã ãããå°ã§ãããããããW3Cã®WebAppSec WGã§è°è«ããã¦ããäºå®ã«ãªã£ã¦ãã¾ãã Baseline ããã 次ã®ããã«ã¬ã¹ãã³ã¹ããããæå®ãã¾ãã Baseline: Security=2022ããã¯ã次ã®ããããéä¿¡ããã®ã¨åæ§ã§ãã Content-Security-Policy: script-src 'self'; object-src 'none'; base-uri 'none'; require-trusted-ty
ã¯ããã«ããã«ã¡ã¯ãTIG ã®å岡ã§ããç§ã®ããã°é±é 10 æ¬ç®ã®æ稿ã§ãã 2022å¹´ã® 5 æã« Apple, Google, Microsoft ãã㦠FIDO Alliance ã ãã«ãããã¤ã¹å¯¾å¿FIDOèªè¨¼è³æ ¼æ å ± ãçºè¡¨ãã¦ããããã¹ã¯ã¼ãã¬ã¹æè¡ã«å¯¾ãã注ç®ãé«ã¾ã£ã¦ãã¾ãã1 ãã¹ã¯ã¼ãã¬ã¹ã®æ¦è¦ã«ã¤ãã¦èª¿æ»ãã¦ã¾ã¨ãã¦ã¿ã¾ããã ç®æ¬¡ ç§ãã¡ã¨ãã¹ã¯ã¼ã ãã¹ã¯ã¼ãã®æ±ããåé¡ ãã¹ã¯ã¼ãããã¼ã¸ã£ å ¬ééµæå·ã®æ´»ç¨ ãã¹ã¯ã¼ãã¬ã¹ã¨ FIDO Alliance FIDO v1.0 FIDO2 FIDO ã®èªè¨¼ããã¼ Passkeys ãã¹ã¯ã¼ãã¬ã¹ãªæªæ¥ ç§ãã¡ã¨ãã¹ã¯ã¼ãä»æ¥ãç§ãã¡ã®ãã¸ã¿ã«ã¢ã¤ãã³ãã£ãã£ã¯ãã¹ã¯ã¼ãã«æ¯ãããã¦ãã¾ããç§ãã¡ã¯æ¥ã Google ã§æ¤ç´¢ããNetflix ã観ã¦ãTwitter ã§ã¤ã¶ãããAmazon ã§è²·ãç©ããã¾ãã
ãã¹ãã¼ã®ã»ãã¥ãªãã£ã«ã¤ã㦠ããããã¯ããã¹ã¯ã¼ãã«ä»£ãã£ã¦ãã¹ãã¼ãã使ããã ããããã°ãããµã¤ã³ã¤ã³ã§ãã¦ä½¿ãæ¹ãç°¡åãããã¦ä½ãããã»ãã¥ãªãã£ãä¸æ®µã¨å¼·åããã¾ãã ãã¹ãã¼ã¯ãã¹ã¯ã¼ãã«ä»£ãããã®ã¨ãã¦è¨è¨ããã¾ãããWeb ãµã¤ãã App ã«ãã¹ã¯ã¼ããªãã§ãµã¤ã³ã¤ã³ã§ããããã«ãªãã便å©ãªã ãã§ãªãå®å ¨é¢ãå¼·åããã¾ãããã¹ãã¼ã¯æ¨æºã«å³ãããã¯ããã¸ã§ãããã¹ã¯ã¼ãã¨ã¯éãããã£ãã·ã³ã°è©æ¬ºå¯¾çã«åªãã常ã«å¼·åã§ãã·ã¼ã¯ã¬ãã (ç§å¯) ãå ±æããªãè¨è¨ã«ãªã£ã¦ãã¾ããApp ã Web ãµã¤ãã«ç°¡åã«ã¢ã«ã¦ã³ãç»é²ã§ããããã«ãªãä¸ãç°¡åã«ä½¿ãã¦ããã¹ã¦ã® Apple 製ããã¤ã¹ã§æ¨ªæçã«æ©è½ãã¾ããå®éã«è¿ãã«ããã°ãApple 製以å¤ã®ããã¤ã¹ã§ã使ãã¾ãã è³æ ¼æ å ±ã®ã»ãã¥ãªã㣠ãã¹ãã¼ã¯ãå ¬ééµæå·åãç¨ãã WebAuthentication ("Web
ä¸å±±ã§ã trivyã®v0.31.0ã§AWSã¢ã«ã¦ã³ãã®ã»ãã¥ãªãã£ã¹ãã£ã³ãã§ããããã«ãªãã¾ããã feat: Add AWS Cloud scanning (#2493) Releases / v0.31.0 ãªããv0.31.0ã§ã¹ãã£ã³ãå®è¡ããã¨ã¯ã©ãã·ã¥ãããã°ããããããã«v0.31.2ããªãªã¼ã¹ããã¾ããã Releases / v0.31.2 ã©ããªæããæ°ã«ãªã£ãã®ã§ã軽ã触ã£ã¦ãããã¨æãã¾ãã ããã¥ã¡ã³ããç¢ºèª ã¾ãã¯ããã¥ã¡ã³ãã確èªãã¾ãã Amazon Web Services ãã¤ã³ãã«ãªãã¨æã£ãç¹ãã¾ã¨ãã¾ãã CIS AWS Foundations Benchmark standardã«æºæ ãããã§ãã¯ãå¯è½ èªè¨¼æ¹æ³ã¯AWS CLIã¨åã ãã¹ã¦ã®AWSãªã½ã¼ã¹ã«å¯¾ããåç §æ¨©éãå¿ è¦ (ReadOnlyAccess) ãµã¼ãã¹ã»ãªã¼ã¸ã§ã³ã»ãªã½ã¼
å æ¥ããã®ãããªãã¤ã¼ããæ¸ããã¨ãããããªãã®åé¿ãããã¾ããã JavaScript ã®æ£è¦è¡¨ç¾ã®èå¼±æ§ã®ä¾ã§ããã¨ãä¾ãã° /\s+$/ ã¯èå¼±æ§ãããã¨è¨ãã console.time(); /\s+$/.test(" ".repeat(65536) + "a"); console.timeEnd(); çµæ§æéããããã®ãããããã§ã /\s+$/ ãè¦ã¦ãããã¯å±éºã ãªãã¨ç解åºæ¥ã人ã¯ãããªã«ããªããJavaScript ã«éããªãããã©ã â Takuo Kihira (@tkihira) February 17, 2022 ããã¯ä¸è¬ã« ReDoS (Regular expression Denial of Service) ã¨å¼ã°ããèå¼±æ§ã§ããæ£ç¢ºã«ç解ããã®ãé£ããèå¼±æ§ãªã®ã§ãå°ã解説ãã¦ã¿ããã¨æãã¾ãã çµè« é·ãè¨äºã«ãªãã®ã§ãæåã«ãã¨ããããããã ãç¥ã£
â»è¿½è¨: æ¬è¨äºã®ç¶ç·¨ã¨ãã¦in-memoryæ¹å¼ããã¢ã¯ã»ã¹ãã¼ã¯ã³ã奪åããPoCãä¸è¨è¨äºã§å ¬éãã¾ããããã²ãããã¦ã覧ãã ããã ã¯ããã« ããã«ã¡ã¯ã ã»ãã¥ãªãã£ã¨ã³ã¸ãã¢ã®@okazu-dm ã§ãã ãã®è¨äºã§ã¯ãAuth0ã®SPA SDKã§ã¢ã¯ã»ã¹ãã¼ã¯ã³ã®ãã£ãã·ã¥ãæå¹åããéã®èæ ®ãã¤ã³ãã«ã¤ãã¦ç´¹ä»ãããããåãå£ã«ã¢ã¯ã»ã¹ãã¼ã¯ã³ã®ä¿åå ´æã«é¢ãã¦in-memoryæ¹å¼ã¨localStorageæ¹å¼ã®2ã¤ã«ã¤ãã¦è§£èª¬ãã¾ãã Auth0ã®ãããªIDaaSã¯æ¨ä»ããªãæ®åãé²ãã§ããã¨æãã¾ãããFlatt Securityã®æä¾ããã»ãã¥ãªãã£è¨ºæã¯Auth0ã«éããFirebase AuthenticationãAmazon Cognitoãªã©ã®IDaaSã®ã»ãã¥ã¢ãªå©ç¨ã¾ã§è¦³ç¹ã«å«ãã¦å°é家ããã§ãã¯ãããã¨ãå¯è½ã§ãã ãèå³ã®ããæ¹ã¯æ¯éIDaaSå©ç¨é¨
ãµã㪠DNSãªãã¤ã³ãã£ã³ã°ãæè¿æ³¨ç®ããã¦ãããGoogle Chromeã¯æè¿ã«ãªã£ã¦ãã¼ã«ã«ãããã¯ã¼ã¯ã¸ã®ã¢ã¯ã»ã¹å¶éæ©è½ã追å ãã¦ããããã®ç®çã®ä¸ã¤ãDNSãªãã¤ã³ãã£ã³ã°å¯¾çã«ãªã£ã¦ãããGoogleãæä¾ããWiFiã«ã¼ã¿Google Nest WiFiã¯ããã©ã«ãã§DNSãªãã¤ã³ãã£ã³ã°å¯¾çæ©è½ãæå¹ã«ãªã£ã¦ããã DNSãªãã¤ã³ãã£ã³ã°å¯¾çã¯ãæ»æ対象ã¢ããªã±ã¼ã·ã§ã³ã§è¡ãã¹ããã®ã§ãããããã©ã¦ã¶ãPROXYãµã¼ãã¼ããªã¾ã«ãçã§ãä¿è·æ©è½ãçµã¿è¾¼ã¾ãã¦ãããæ¬ç¨¿ã§ã¯ããã対çæ©è½ã®ç¶æ³ã¨å¯¾çã®èãæ¹ã«ã¤ãã¦èª¬æããã DNSãªãã¤ã³ãã£ã³ã°ï¼DNS Rebindingï¼ã¨ã¯ DNSãªãã¤ã³ãã£ã³ã°ã¯DNSåãåããã®æéå·®ãå©ç¨ããæ»æã§ããDNSã®TTLï¼ãã£ãã·ã¥æå¹æéï¼ã極ãã¦çãããä¸ã§ã1åç®ã¨2åç®ã®åãåããçµæãå¤ãããã¨ã«ãããIPã¢ãã¬ã¹ã®ã
ãCEOã«èº«ä»£éãè¦æ±ãããã ããã«ã¡ã¯ãPSIRTããã¼ã¸ã£ã®ãã ãã ãï¼tdtdsï¼ã§ãããã®è¨äºã¯freee Developers Advent Calendar 2021 18æ¥ç®ã§ãã freeeã«joinãã¦ããæ©ãã14ã¶æãããã¾ãããfreeeã§ã¯æ¯å¹´10æã«å ¨ç¤¾é害è¨ç·´ããã¦ãã¦ãæ¨å¹´ã¯å ¥ç¤¾ããã¦ã§å³ãå·¦ãããããªãã¾ã¾AWSä¸ã®æ¬çªç°å¢ï¼ã®ã¬ããªã«ï¼ã«ä¾µå ¥ãã¦DBãã¶ã£å£ãå½¹ç®ããããããã®ãè¯ãæãåºã§ã*1ã ã§ãä¸ã®ãCEOã«èº«ä»£éãè¦æ±ããããã¨ããç©é¨ãªç¸è«ã¯ãä»å¹´ã®è¨ç·´è¨ç»ã®è©±ã§ãã話ãæã¡æãã¦ããã®ã¯CIOã®åä½ãæ¨å¹´ã¯ä¸»è¦ãµã¼ãã¹ãè½ã¡ã¦ãéçºãã¼ã ã対å¿ã«ãããä¸ããã¸ãã¹ãµã¤ãã顧客対å¿ãªã©ã§è¨ç·´åå ãã¾ããããä»å¹´ã¯ããã«ãçµå¶ãµã¤ãã¾ã§å·»ãè¾¼ããã¨ããã´ã¼ã«è¨å®ããããããã§ãããè ãé³´ãã¾ãã ã´ã¼ã«ã¯ãCEOã«4BTCãè¦æ±ããã ã´ã¼
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}