ãã¹ãã¼ã¯ãã£ãã·ã³ã°ã«å¼·ãããã¯ããã¸ã¼ã«è©³ãããªãã¦ã¼ã¶ã¼ã§ã使ããããæ°ããèªè¨¼æ¹å¼ã§ãããããã¹ã¯ã¼ããç½®ãæããã¨è¨ããã¦ãã¾ãããã®è¨äºã§ã¯ããã¹ãã¼ã®åºæ¬ã¨ãããããã®ã¦ã§ãã«ã¨ã£ã¦ãã¹ãã¼ãã©ãããæå³ãæã¤ã®ãã«ã¤ãã¦ã¾ã¨ãã¦ã¿ã¾ãã ãã¹ãã¼ã¨ã¯ä½ã # 2022 å¹´ 12 æ 9 æ¥ã« Google ã Android ç Chrome ã§ãã¹ãã¼ããµãã¼ããããã¨ã®ã¢ãã¦ã³ã¹ãåºã¾ãããApple ããã§ã«ææ°çã® macOS VenturaãiOS / iPadOS 16 ã§ Safari ããã¹ãã¼ã«å¯¾å¿ãã¦ãã¾ãã ãã¹ãã¼ã¯ AppleãGoogleãMicrosoft ãå調ãã¦ä½¿ã FIDO ã¯ã¬ãã³ã·ã£ã«ã®ååã§ããã¨ã³ãã¦ã¼ã¶ã¼ã®ã¿ãªããããã¹ã¯ã¼ãã®ä»£ããã¨ãã¦èªèããç´æçã«ãã°ã¤ã³ã§ããããããã¹ãã¼ãã¨ãããã©ã³ãã¨ã¢ã¤ã³ã³ã決ã¾ãã¾ãããã¦
Metabase Qã¯2æ1æ¥(ç±³å½æé)ããImageMagick: The hidden vulnerability behind your online imagesãã«ããã¦ãå社ã®ã»ãã¥ãªãã£ãã¼ã ãçºè¦ããç»åå¦çã½ããã¦ã§ã¢ãImageMagickãã®2ä»¶ã®ã¼ããã¤èå¼±æ§ã«ã¤ãã¦å ±åããããããã®èå¼±æ§ãæªç¨ãããã¨ãæ»æè ã«ãã£ã¦æ¨çã®ã·ã¹ãã ä¸ã§ãµã¼ãã¹æå¦ï¼DoSï¼ãæ å ±æ¼æ´©ãªã©ã®æ»æãåããå¯è½æ§ãããã ImageMagick: The hidden vulnerability behind your online images - Metabase Q ImageMagickã¯ç»åã®è¡¨ç¤ºãæä½ããã©ã¼ããã夿ãªã©ãè¡ããã¨ãã§ãããªã¼ãã³ã½ã¼ã¹ã®ã½ããã¦ã§ã¢ã¹ã¤ã¼ããé常ã«å¤ãã®ç»åãã©ã¼ãããã«å¯¾å¿ãã¦ãããã¨ãããç»åãæ±ãä¸çä¸ã®Webãµã¤ãã§åºãå©ç¨ãã
2023å¹´1æ10æ¥ãECã·ã§ãã使ãµã¼ãã¹ãéå¶ããBASEã¯ãå社ã®ãµã¼ãã¹ãå©ç¨ããECã·ã§ãã管çè ã«å¯¾ãè³¼å ¥è ã«ãªããã¾ããä¸å¯©ã¡ã¼ã«ãçºçãã¦ããã¨ãã¦æ³¨æãå¼ã³ããã¾ããã被害ã«éã£ãECãµã¤ãããã¯ããã«ã¯ã¬ã¸ããã«ã¼ãæ å ±ã®çªåãçã£ãã¡ã¼ã«ããã®ECã·ã§ããã®è³¼å ¥è å®ã«éãããäºä¾ã確èªããã¦ãã¾ããããã§ã¯é¢é£ããæ å ±ãã¾ã¨ãã¾ãã ECã·ã§ããã«ä¸æ£ãã°ã¤ã³ãçãã è³¼å ¥è æ å ±ãæªç¨ ãä¸å¯©ãªãåãåããã«ã注æãã ããã ãã®ãã³ãBASE管çç»é¢ã®ãã°ã¤ã³æ å ±ã䏿£ã«å ¥æãããã¨ãç®çã¨ããããªããã¾ãã®äºæ¡ã確èªããããããæ³¨æåèµ·ã®è¨äºãå ¬éãã¾ãããéè¦ãªæ å ±ã®ããã確èªããã ããã¨å¹¸ãã§ããhttps://t.co/WTzbYCr41Zâ BASEï¼ãã¤ã¹ï¼ð»ãããã§ãåºãéããªã (@BASEec) 2023å¹´1æ10æ¥ è³¼å ¥è ã®ãªããã¾ããã¡ãã»ã¼
ãã®è¨äºã¯ãMoney Forward Engineering 1 Advent Calendar 2022 16æ¥ç®ã®æç¨¿ã§ãã Money Forward ME ãµã¼ããµã¤ãã¨ã³ã¸ãã¢ã®å³¶æ´¥ã§ãã ä»åã¯ãDependabot éç¨ã®èªååã«ã¤ãã¦ããç´¹ä»ãããã¨æãã¾ãã Dependabot ã«ã¤ã㦠Dependabot ã¯ãããã¸ã§ã¯ãã§ä½¿ç¨ããã¦ããã©ã¤ãã©ãªã®èå¼±æ§ãç£è¦ããä¾åé¢ä¿ãææ°ã®ç¶æ ã«ä¿ã¤ããã®ãGitHub ã®ãµã¼ãã¹ã§ãã ãã®ä¸ã§ãããã¤ãæ©è½ãããã¾ãããä»å㯠Dependabot version updates ã®æ©è½ã使ç¨ããéã®èªååã«ã¤ãã¦ã§ãã ãã®æ©è½ã使ãã¨ããªãã¸ããªå ã®å種ããã±ã¼ã¸ã®ãã¼ã¸ã§ã³ããã§ãã¯ããå¸¸ã«ææ°ã«ä¿ã¤ããã«èªåçã« bot ã ãã«ãªã¯ã¨ã¹ãã使ãã¦ããã¾ãã 詳ããè¨å®æ¹æ³ã¯å²æãã¾ããããªãã¸ããªå ã§ .g
ã¤ã³ã·ãã³ãã¬ã¹ãã³ã¹ãèªååã§æ¯æ´ãã Slack Bot ã§äººæ©ä¸ä½ãªã»ãã¥ãªãã£å¯¾çãå®ç¾ãã https://event.cloudnativedays.jp/cndt2021/talks/1260
2021/10/01 ISRG Root X1(2015å¹´ã)ãªãã¨ã£ãã«ä¿¡é ¼ãã¦ãã¯ãã¨æã£ãï¼æ®å¿µï¼ ããã¯ãLet's Encryptãæ¯ãããã®äºäººã®ã«ã¼ãCA㨠OpenSSLã®ç©èªã§ããã - DST Root CA X3 (2000-2021) - ISRG Root X1 (2015-2035) ## ã2021å¹´1æã ISRG Root X1ããã¾ã¾ã§ä¸ç·ã«ãã£ã¦ããDST Root CA X3ããã®å¯¿å½ãéè¿ã»ã»ã»ãã®ã¾ã¾ã ã¨åãä¿¡é ¼ãã¦ããã¦ããªãããã©ã³ã®ï¼å ·ä½çã«ããã¨2016å¹´ãããã¾ã§ã®ï¼å¤ãã¯ã©ã¤ã¢ã³ããã¡ã¯ Let's Encryptãããä¿¡ç¨ãã¦ãããªããªã£ã¡ããã»ã»ã»ã©ããããã DST Root CA X3ãã©ãããããæ»ã¬åã«(æå¹æéãåããåã«)ãåãä¿¡é ¼ã«å¤ããæ¨ãä¸çæ¸ãã¦æ®ãã°ããããããããµã©ãµã©ã ```text Issuer: O
ã¢ãã»ãã¥ãªãã£ã§è©±ããå 容ã§ãã https://mob-security.connpass.com/event/209884/ æ å ±ã®å«ççãªåãæ±ãããé¡ããã¾ãã
22 Hacking Sites To Practice Your Hacking Skills �8�U Taken from: https://hackerlists.com/hacking-sites/ 22 Hacking Sites, CTFs and Wargames To Practice Your Hacking Skills InfoSec skills are in such high demand right now. As the world continues to turn everything into an app and connect even the most basic devices to the internet, the demand is only going to grow, so itâs no surprise everyone wan
ãã¤ãã©ã¹ã®ã³ã³ã»ãã ãã ããã®ãªã«ãã«å½¹ç«ã¦ããããã¼ãã«ãWebå¶ä½è YoTaãæ°ã¾ããã«æ´æ°ãããè¶£å³ããã°ã§ããèªè ããããµãã£ã¨ç«ã¡å¯ãããªã«ãå½¹ã«ç«ã¤æ å ±ãæã¡å¸°ãããããä¸çªã®åã³ã§ãã (ç¥ï¼ç´¯è¨500ä¸PVâ)
webãµã¼ãã¼ä¸ã§laravelãåããã¦ããã°ãã¡ãã£ã¨ããè¨å®ã®ãã¹ã§èª°ã§ããã«ã¦ã§ã¢ã«ææããå¯è½æ§ãããæ¿ã¤ãã»ãã¥ãªãã£ãã¼ã«(CVE-2021-3129)ã2021å¹´1æ20æ¥ã«å ±åããã¦ãã¾ãï¼ composerã§ã¤ã³ã¹ãã¼ã«ããããã±ã¼ã¸ããã¼ã¸ã§ã³ã¢ããããã«ä½¿ã£ã¦ãã¾ãããï¼ ã¤ã³ã¿ã¼ãããä¸ã«å ¬éããã¦ãããµã¼ãã¼ãç¹ã«ã¹ãã¼ã¸ã³ã°ãéçºç°å¢ã§DEBUG=ONã«ãã¦ãã¾ãããï¼ ã¨ã©ã¼ç»é¢ããããªé¢¨ã«è¦ãã¾ããï¼ ãã®3ã¤ã®æ¡ä»¶ãæºããã¦ããã¨ãããªãã®laravelã¯ãä»ããã«ã§ããã«ã¦ã§ã¢ã«ææããå¯è½æ§ãããã¾ãã laravelã®èå¼±æ§ãã¤ããkinsing(kdevtmpfsi)ã¨ãããã«ã¦ã§ã¢ã«ææãã話 ãä½ããã¦ãªãã®ã«Laravelãä¹ã£åããã¦ã¾ããã èªåãéç¨ãã¦ãããµã¼ãã¹ã§ã¯ãlaravelã500ã¨ã©ã¼ãåºãã¨ãSlackã«éç¥ãæ¥ããã
ã»ãã¥ãªãã£ã¹ãã£ãã¼ãTsunamiããåç§°ã«é¢ããIssueãã¯ãã¼ãºãå®ã¯ãæ´¥æ³¢æ©æè¦æã·ã¹ãã ããç¥ããããã®ã ã£ãã¨éæãããã¥ã¡ã³ãã§è©³ç´°ã«èª¬æã¸ Googleãã»ãã¥ãªãã£ã¹ãã£ãã¼ãTsunamiãããªã¼ãã³ã½ã¼ã¹ã§å ¬éãããã¨ã¯ãPublickeyã®6æ23æ¥ä»ã®è¨äºã§ç´¹ä»ãã¾ããã Googleãã»ãã¥ãªãã£ã¹ãã£ãã¼ãTsunamiãããªã¼ãã³ã½ã¼ã¹ã§å ¬éããã¼ãã¹ãã£ã³ãªã©ã§èªåçã«èå¼±æ§ãæ¤åºãããã¼ã« ï¼ Publickey èªåçã«èå¼±æ§ãæ¤åºãã¦ãããã¨ãã便å©ãããªã½ããã¦ã§ã¢ã§ãããã¨ã§ãå¤ãã®èªè ããã®è¨äºã«æ³¨ç®ãã¾ããããåæã«ãã®ãTsunamiãã¨ããåç§°ã«ã¤ãã¦çåãåããèªè ãå¤ããããã¨ãããã®è¨äºã«500以ä¸ã¤ãããã¯ã¦ãªããã¯ãã¼ã¯ããåããã¾ããã ãTsunamiãï¼æ´¥æ³¢ï¼ã¨ããè¨èã¯ã2011å¹´3æ11æ¥ã«çºçããæ±æ¥æ¬å¤§éç½ãçµ
æ£è¦è¡¨ç¾ã«ããããªãã¼ã·ã§ã³çã§ãå®å ¨ä¸è´ã示ãç®çã§ ^ 㨠$ ãç¨ããæ¹æ³ãä¸è¬çã§ãããæ£ãã㯠\A 㨠\z ãç¨ããå¿ è¦ãããã¾ããRubyã®å ´å ^ 㨠$ ã使ã£ã¦å®å ¨ä¸è´ã®ããªãã¼ã·ã§ã³ãè¡ãã¨èå¼±æ§ãå ¥ããããã¯ãã¨ãªãã¾ããPerlãPHPã®å ´åã¯ãRubyç¨ã§ã¯ããã¾ãããä¸å ·åãçããã®ã§ \A 㨠\z ã使ãããã«ãã¾ãããã ã¯ãã㫠大å£ããã®ããã°ã¨ã³ããªãPHPeråããRuby/Railsã®è½ã¨ãç©´ãã«ã¯ãRubyã®è½ã¨ãç©´ã¨ãã¦ãå®å ¨ä¸è´æ¤ç´¢ã®æå®ã¨ãã¦ãæ£è¦è¡¨ç¾ã® ^ 㨠$ ãæå®ããä¾ããRuby on Rails Security Guideããã®å¼ç¨ã¨ãã¦ç´¹ä»ããã¦ãã¾ãã以ä¸ã®æ£è¦è¡¨ç¾ã¯ãXSS対çã¨ãã¦ãhttpã¹ãã¼ã ãããã¯httpsã¹ãã¼ã ã®URLã®ã¿ã許å¯ããæ£è¦è¡¨ç¾ã®ã¤ããã§ãã /^https?:\/\/[^\n]+$/
PHPã«ã³ãã¡ã¬ã³ã¹2019ããªãã®ãªãã¤ã®ã»ãã¥ãªãã£äºæ ã«å¦ã¶å®å ¨ãªãµã¼ãã¹ã®æ§ç¯æ³ ãã®ã¹ã©ã¤ãã§ãã
ã»ãã¥ãªãã£ã»ãã£ã³ããå ¨å½å¤§ä¼ 2019 éçºã¨éç¨ãã©ãã¯ã§æä¾ããè¬ç¾©ã®è³æã®ä¸é¨ã§ãã誤ãã«æ°ãã¤ãããããã² @y0n3uchy ããã㯠@lmt_swallow ã«ãç¥ãããã ããã
ãµã㪠PHPãµã¼ãã¼ãµã¤ãããã°ã©ãã³ã°ãã¼ãã§ã¯ããã¹ã¿ã¼ã«ã¯ãPHPå ¥éæ¸ã¨ãã¦ã¯çããã¯ãã¹ãµã¤ãã»ãªã¯ã¨ã¹ããã©ã¼ã¸ã§ãª(CSRF)対çã«ã¤ãã¦ã®èª¬æããããããã®æ¹æ³ã«ã¯åé¡ããããã¢ã«ã´ãªãºã ã¨ãã¦åé¡ããããã¨ã«å ãã¦ãå®è£ ä¸ã®åé¡ãããããã®ã¾ã¾ã³ãããã¦ç¨ããã¨èå¼±æ§ã¨ãªãã ã¯ããã« å¤åºè¦ªæ¹ã®ä»¥ä¸ã®ãã¤ã¼ããè¦ã¦é©ãã¾ããã CSRFç¨ã®ãã¼ã¯ã³ã®ä½æ ï¼token = password_hash(mt_rand(), PASSWORD_DEFAULT); ã£ã¦ã®ãæ¸ç±ã§è¦ãâ¦â¦â¦ãã³ã®ãã³ãããªã(è¦ç¬ æ¸ç±åã§ã°ã°ã£ã¦èª¿ã¹ãâ¦â¦è©å¤ãæªãã®ã§ãã¾ããç´å¾ã£ã¡ããç´å¾ã â ãã (@gallu) July 17, 2019 CSRFãã¼ã¯ã³ã®çæã«ãpassword_hash颿°ã使ãã§ãã¨? 親æ¹ã«æ¸ç±åãæãã¦ããã ããè³¼å ¥ããã®ãããã®è¨äºã§ç´¹ä»ãããPH
æ¯æ¥ã®ããã«ä¼æ¥ãçµç¹ãçã£ããµã¤ãã¼æ»æãç¹°ãè¿ããããã®æ¹æ³ã次ã ã¨æ°ãããªã£ã¦ãã¾ããçããã®ä¸ã«ã¯ã²ãã£ã¨ãã¦ãå°ããªä¼æ¥ãååå®ãã ãã®ã»ãã¥ãªãã£ã®ç¥èã身ã«ä»ããã«ã¯ãããç¨åº¦ãéããããã¯ããã¨æã£ã¦ããæ¹ãããã®ã§ã¯ãªãã§ããããï¼ãå®ã¯ããããªãã¨ã¯ããã¾ããï¼ å é£ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã³ã¿ã¼ï¼NISCï¼ã¯2019å¹´4æ19æ¥ãæ°ãã«ãå°ããªä¸å°ä¼æ¥ã¨NPOåãæ å ±ã»ãã¥ãªãã£ãã³ããã㯠åçï¼Ver.1.00ï¼ããå ¬éãã¾ããããã®å 容ã¯ãã»ãã¥ãªãã£æ¬ã䏿¢ãã¦ããçè ãããã¬ã¬ãã¨ããªã£ãã»ã©ã§ããããã¯ãç´ æ´ãããï¼ ãã©ããã¦ãã®äººã¯ãä»äººã®æ¬ãããã¾ã§æ¨ãã®â¦â¦ï¼ãã¨é¢é£ãã£ãèªè ãããããããã¾ããããã®æ¬ãèªãã§ã»ããã¨ç§ãèããæ ¹æ ãããããã詳ãã説æãã¦ããã¾ãããã NISCã¯ããã¾ã§ããå人åãã«é»è²ã表ç´ã®ãã¤ã³ã¿ã¼ãããã®å®å ¨ã»å®å¿ãã³
ãã®ãã©ã¦ã¶ã¼ã¯ãµãã¼ããããªããªãã¾ããã Microsoft Edge ã«ã¢ããã°ã¬ã¼ãããã¨ãææ°ã®æ©è½ãã»ãã¥ãªãã£æ´æ°ããã°ã©ã ãããã³ãã¯ãã«ã« ãµãã¼ããå©ç¨ã§ãã¾ãã Microsoft Security Response Center ã§ã¯ãæ¯å¹´ä½åãã®ã»ãã¥ãªã㣠ã¬ãã¼ãã調æ»ãã¦ãã¾ãããã®ä¸ã«ã¯ãå½ç¤¾ã®ããããã®è£½åã®åé¡ã«èµ·å ããçã®ã»ãã¥ãªãã£ã®çããææããã¬ãã¼ããããã¾ãããã®ãããªå ´åãæã ã¯ãã®ã¨ã©ã¼ãä¿®æ£ããããã®ä¿®æ£ããã°ã©ã ãã§ããã ãè¿ éã«ä½æãã¾ã (ãMicrosoft Security Response Center ãå·¡ããã¢ã¼ããåç §)ãã¾ããåã«è£½åã®ä½¿ãæ¹ã®ééããåå ã¨ãªã£ã¦çºçããåé¡ãã¬ãã¼ãããã¦ããã±ã¼ã¹ãããã¾ããããããã»ã¨ãã©ããã®ä¸éã«ä½ç½®ãã¾ããã¤ã¾ããçã®ã»ãã¥ãªãã£åé¡ãè«ãã¦ãããã®ã®ã製åã®åé¡ãåå
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}