XSSã«CSRFã«SQLã¤ã³ã¸ã§ã¯ã·ã§ã³ã«ãã£ã¬ã¯ããªãã©ãã¼ãµã«â¦â¦Webã¢ããªã±ã¼ã·ã§ã³ã®ããã°ã©ããç¥ã£ã¦ããã¹ãèå¼±æ§ã¯ãã£ã±ãããã¾ããããã§æ¬é£è¼ã§ã¯ããã®ãããªã¡ã¸ã£ã¼ãªãã®â以å¤âãæãä¸ãã¦ããã¾ã ï¼ç·¨éé¨ï¼ 次ã¯ãJSONã«ãããã»ãã¥ãªãã£å¯¾ç çããããã«ã¡ã¯ãã¯ãããããããã§ãã第4åãï¼»æ°ã«ãªãï¼½JSONPã®å®ãæ¹ãã¯JSONPã«ã¤ãã¦èª¬æãã¾ããã®ã§ãä»åã¯ãJSONãã«ã¤ãã¦ãã»ãã¥ãªãã£ä¸æ³¨æãã¹ãç¹ã«ã¤ãã¦èª¬æãã¾ãã JSONã¯ãXMLHttpRequestã§åãåããJavaScriptä¸ã§evalããã¨ãã使ãæ¹ãä¸è¬çã§ãã ã¾ãã¯ãµã¼ãå´ããéãããæ å ±ã¨ãã¯ã©ã¤ã¢ã³ãå´ã§ã®å¦çãããããã®å 容ãè¦ã¦ããã¾ãããã ï¼»ãµã¼ãå´ï¼½ HTTP/1.1 200 OK Content-Type: application/json; charset=
å ¬é: 2009å¹´7æ8æ¥16æ45åé ã»ãã¥ãªãã£ãã¼ã«memo (www.st.ryukoku.ac.jp)ãããVALUE DOMAINãã°ã¤ã³ãã¼ã¸æ¹ç« (lineage.paix.jp)ã ããã§ã ã¼ããã¤ã§ãããéã®æªããã¨ã«ãyaraiã®è©¦ç¨æéãã¡ããã©åããã°ã£ããã§è©¦ããªãâ¦â¦ããããæéå ã ã¨ãã¦ããç©æ¥µçã«è©¦ãã®ã¯åæ°ãããã¾ããã ããããã©ãããçµç·¯ã§æ¹ç«ããããç¥ãããã¨æãä¸æ¹ãVALUE DOMAINã ã£ããä½ã§ãã¢ãªã ããªãã¨ããæ°ããã¦ãã¾ãã®ãä½ã¨ãã ç§ãVALUE DOMAINã使ãå§ããé ã¯XSSã ããã ã£ãããã§ãã¦ãå°ãªãã¨ãã https://www.value-domain.com/regdom.phphttps://www.value-domain.com/signup.phphttps://www.value-domain.com
ï¼ååã®ã話ï¼ãXSSã®æ£ä½ã¯ãã¿ã°ã«ä½¿ç¨ãããç¹å®ã®è¨å·ãæ¬æ¥ã¨ã¯ç°ãªãåæã«ç¨ãããã¨ã§ããµã¼ãã®èª¤èªèãèªçºãããã¨ã¨ç¥ã£ãããã°ã¡ãããââ é£ãããªãâ âã¨ãããã®å¯¾çã¨ã¯!? ããã¦æ°ã«ãªã2人ã®ã«ã³ã±ã¤ã¯!? èªè 100ä¸äººãå·»ãè¾¼ãã ãè¡æã¨æåã®ä¸å¤§ã¹ãã¯ã¿ã¯ã«ããã¾ããã«å®çµï¼
Movable Type 4.25 ã®ã³ã¡ã³ãæ¬ã®(X)HTMLè¦ç´ ã« onclick å±æ§ã onleypress å±æ§ãé©ç¨ãããæ¹æ³ã§ãã質åãé ãã¾ããã®ã§æ¬ã¨ã³ããªã¼ã§åçãã¾ãã ï¼ï¼åºæ¬åä½ ã³ã¡ã³ãæ¬ã«æ¬¡ã®ãããª(X)HTMLãè¨è¿°ããã¨ã <a href="foo.html" onclick="foo()">foolink</a> onclick å±æ§ã¯ãµãã¿ã¤ãºããã¦ã <a href="foo.html">foolink</a> ã¨ãªãã¾ããããã¯ã³ã¡ã³ãã«æ¸ãè¾¼ã¾ãã onclick å±æ§ã«ããXSSï¼ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼å¯¾çã§ããonclick ã®ã¿ã ãã§ãªããJavaScript ã¤ãã³ãå±æ§ï¼onï½ï¼ã¯è¨±å®¹ããã¦ãã¾ããã ãªããMovable Type 4.25 ã§ã¯ãããã°ç®¡çç»é¢ã®ãè¨å®ãâãã³ã¡ã³ããã§ããHTMLã¿ã°ãå¶éãã®é ç®ã«ãJav
(2009/04/12 6ï¼40 pm 追è¨ãã¾ãã) (2009/04/12 7ï¼24 pm å度追è¨ãã¾ãã) å ã»ã©ãã Twitterä¸ã«ã¦ XSS ã®ãã被害ãåºã¦ãã¾ãã æ¢ã«æµ·å¤ã®ããã°ãªã©ã§ãåãä¸ãããã¦ãã¾ãã HOWTO: Remove StalkDaily.com Auto-Tweets From Your Infected Twitter Profile (Twittercsm) Warning: Twitter Hit By StalkDaily Worm (TechCrunch) æ¢ã« XSS ã®é¨åã¯æ¹ä¿®ããã¦å¤§ååã¾ã£ãããã§ããã念ã®ããã«æ¸ãã¦ããã¾ãã å 容ã¨ãã¦ã¯ã 1. StalkDaily.com ã宣ä¼ããã¤ã¶ãããåæã«æ稿ããã 2. ãããã£ã¼ã«ã® Web ãæ¹ããããã 3. æ¹ãããããã¦ã¼ã¶ã¼ã®ãã¼ã¸ãè¦ãã¨ãèªåã®ãããã£ã¼ã«ã
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}