ãã°ãã 'ã«ããã¾' ãããã¡ @Niratama 17-D-5 Java-Androidã»ãã¥ã¢ã³ã¼ãã£ã³ã°å ¥é #devsumiD ãã¬ã¼ã³ã®ã»ãã«17-E-5ã¨ãæ¸ãã¦ãã£ã¦ã¡ãã£ã¨ç¦ã£ã
ChromeãSafariã«ã¯XSS AuditorãIE 8以ä¸ã«ã¯XSSãã£ã«ã¿ã¼ã¨ãããXSSãæ¤ç¥ãã¦ãããã¯ããæ©è½ãããããããã¾ãã ä»åã¯ããããåé¿ãã¦ã¿ãè¨é²ã§ãã ã»Chromeã§ãã¤ãã¹ ã¯ãï¼ã¤ããã¨ã¨ãå ±åãããã¤ã§ãï¼ XSS Auditor bypass with U+2028/2029 https://bugs.webkit.org/show_bug.cgi?id=78732 ãªããSafariã§ã¯ãããã¯ããã(ä¸ã®äººãçç±ãããããªãã¨è¨ã£ã¦ãã)ãã ãã©ãChromeã§ã¯åãã¾ãã以ä¸ã§è©¦ãã¦ã¿ã¦ãã ããã http://vulnerabledoma.in/char_test?charset=utf-8&xss=1&body=%3Cscript%3E//%E2%80%A8alert(1)%3C/script%3E http://vulnerabled
ãªã¢ã«ã¿ã¤ã ã«æã å»ã ã¨çæããã大éã®ãã¼ã¿ãããããã«ç¥è¦ãè¦åºãã¦ãã¸ãã¹æ¦ç¥ã«çãããââãããã°ãã¼ã¿æ´»ç¨ãæ å ±ã·ã¹ãã ã®ããæ¹ã¨ä¼æ¥æ¦ç¥ã大ããå¤ãããã¨ãã¦ãããããã°ãã¼ã¿ã«æ³¨åããITãã³ãã¼ã«ãããã°ãã¼ã¿æ´»ç¨ã®éè¦æ§ããã³å¾æ¥ã®æ¦ç¥çãã¼ã¿æ´»ç¨ã¨ã®éããªã©ãèãããï¼èãæã¯äºä¸å¥å¤ªé/ç°å³¶ç¯¤ï¼ITproï¼ ãã¼ã¿ã®æ¦ç¥çæ´»ç¨ã¨ããç¹ã§BIã¨ããã°ãã¼ã¿ã®éãã¯ä½ãã BIãããããããã¦ããããBIãä¸è¨ã§ã¾ã¨ããã¨ããçç£ã»è²©å£²ã»éçºã¨ãã£ããã¾ãã¾ãªä¼æ¥æ´»åã®ãªãã§ãç¾å ´ã§ä½ãèµ·ãã¦ãããããçµå¶å±¤ãå¶æ¥é¨éããªã¢ã«ã¿ã¤ã ã«è¿ãå½¢ã§ææ¡ãã¦ããã®å ´ã®ãã¸ãã¹å¤æã«çãããã¨ãã¨ãªãã å¾æ¥ã®BIã®ä½¿ããæ¹ããããã¨ããæ¢åã®æ å ±ãéãã¦ãã¦è¡¨ç¤ºããã ããã¨æãããã¡ã ããããã ãã§ãç°¡åã§ã¯ãªããå½å ã®æ´»åã ããªãå®ç¾ã§ãã¦ãããããããªãããæµ·å¤é²åºå ã®ç¾å ´ã§
1. Finding Vulnerabilities For Fun And Profit 趣å³ã¨å®çã®èå¼±æ§çºè¦ Feb 16 2012 Yosuke HASEGAWA 2. èªå·±ç´¹ä» ã¯ããããããã ï¶ãããã¨ã¼ã¸ã§ã³ãæ ªå¼ä¼ç¤¾ ç 究éçºé¨ ï¶æ ªå¼ä¼ç¤¾ã»ãã¥ã¢ã¹ã«ã¤ã»ãã¯ããã¸ã¼ æè¡é¡§å ï¶Microsoft MVP for Consumer Security Oct 2005 - ï¶http://utf-8.jp/ ï¶é£èªåJavaScriptæ¸ãã¦ã¾ã Developers Summit 2012 NetAgent http://www.netagent.co.jp/ 4. è¨å·JavaScript JS without alnum $=~[];$={___:++$,$$$$:(![]+"")[$],__$:++$,$_$_:(![]+"")[$],_$_:+ +$,$_$$:
ï¼è¬æ¼æ¦è¦ï¼ è¿å¹´ãWebã¢ããªã±ã¼ã·ã§ã³ã«ãããèå¼±æ§ã社ä¼ã«æ·±å»ãªå½±é¿ãä¸ããã¨ã¨ãã«ãã»ãã¥ãªãã£ã«å¯¾ããæèã®é«ã¾ãããã¤ã¦ãªãã»ã©é«ã¾ã£ã¦ãã¾ããã»ãã¥ãªãã£ã®åéã¯æè¡ã®é²æ©ãæ©ãã対çã追ãã¤ããªãã¨è¨ããããã¨ãå¤ãããã¾ããã§ã¯ãªã次ã ã¨æ°ããæ»æææ³ãè¦ã¤ããã®ã§ããããã ãã®ã»ãã·ã§ã³ã§ã¯ãã©ããã£ã¦èå¼±æ§ãæ¢ãã®ãã ãã§ã¯ãªãããªã«ãç®çã«èå¼±æ§ãæ¢ãã®ãã¨ãã£ãç¹ã«ã¤ãã¦ããããã¾ã§ã«æ°ããæ»æææ³ãå¤æ°çºè¦ããå®ä½é¨ã交ããªãã話ããã¦é ãããã¨æãã¾ãã ç¶ããèªã
éãã è¨äºã¸ã®ã¢ã¯ã»ã¹æ°ã®ã»ããã§ã¤ã¹ããã¯ããã¤ãã¿ã¼ã§ã®ã·ã§ã¢åæ°ãã¡ã¼ã«ããã¨ã«WSJæ¥æ¬çã§æ³¨ç®ãéãã¦ããè¨äºãã©ã³ãã³ã°ã«ã¾ã¨ãã¦ãã¾ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}