ã¨ãã»ãã¥ã¢ããã°ã®XSSã«é¢ãã¦ãå ±å 2010å¹´06æ21æ¥21:50 ãã¤ã¼ã risa_ozaki æ±äº¬çºÂ byï¼å°¾å´ ãªãµ ããã³ããXSSï¼ã¯ãã¹ãµã¤ãã¹ã¯ãªããã£ã³ã°ï¼ã«é¢ãããã¹ãããã£ãã°ããã§ãããä»åã¯ã¨ãã»ãã¥ã¢ããã°ç®¡ç人ã®ç§ããããXSSã«é¢ããè¨äºããã¹ããããã¨æãã¾ãã ããã³ã®ãã¹ãã¯ãã¨ãã»ãã¥ã¢æ¬ç¤¾ã®ãf-secure.comãã«é¢ããXSSã®åé¡ã¨ãã®å¯¾å¿ã§ããããç§ããã®å ±åã¯ãä»ã覧ããã ãã¦ããã¨ãã»ãã¥ã¢ããã°ï¼blog.f-secure.jpï¼ã«é¢ããXSSã¨ãã®åé¡ã«é¢ãããã®ã§ãã ç¾å¨ããblog.f-secure.jpãã¯ãæ ªå¼ä¼ç¤¾ã©ã¤ããã¢ãæä¾ãã¦ããæ³äººåãææãã©ã³ãCMSã¨ãã¦å©ç¨ãã¦ãã¾ãï¼æä¸æ¬ç§°ç¥ï¼ã 2010å¹´1æåæ¬ãç¬ç«è¡æ¿æ³äºº æ å ±å¦çæ¨é²æ©æ§(IPA) ã»ãã¥ãªãã£ã»ã³ã¿ã¼ãããã¨ãã»ãã¥ã¢ããã°ã®We
CDã¸ã£ã±ãããã«ã¼ãã²ã¼ã ãéèªè¡¨ç´ãªã©ãããã¾ã§æä»è±è ãææãã¦ãããã¢ã¤ãã«ãã¹ã¿ã¼ãé¢é£ã®ã¤ã©ã¹ããä¸æã«åé²ã æªå ¬éã ã£ãã©ãã¤ã©ã¹ãã¯ãã¡ããã®ãã¨ãç»éã®ããã«æãä¸ããããã¤ã©ã¹ãã®æ°ã ãï¼ ãã¢ã¤ãã¹ããã¡ã³ãªãè²·ããã«ã¯ããããªããã¡ã³ã¢ã¤ãã ã®æ±ºå®çã§ãï¼ã©ããã¦ã ãããªãã 管ç人ãæä»è±è ãããã¨ãã²ã®ãã£ã©ãã¶ãææãã¦ãå «å®åä»ãã㨠ã´ããã£ã«ãã¦ãã®ã¯ã»ã»ã»ã»ã»ã»ã»ã»^^; æ¼¢ååæåã¨ããé¡ä¼¼ç¹ãããªãã®ã«ãã åéããããè©«ã³ã«ããã·ã¥ããã¦é ãã¾ãã æä»è±è ããã®ããã°ã¯ãã¡ãã http://annindouhu1.blog32.fc2.com/ ã¡ããã©ææ°ã®è¨äºã§ãã®ç»éã®è©±ãããã¦ã¾ããã ããã§ã¯æ¬é¡ã¸è¡ãã¾ãã ãã¡ï½ãæ¨æ¥ã¯ã·ã§ãã¯ã®ãã¾ãä¸è²å¯ãã¦è½ãã¾ãããç³ã訳ãªãã§ãã ãªã©ã³ãã«è² ãããã¨èªä½ã¯æ³å®å ã ã£ããã§ãã»ã¨ãã©
ä»AngelBeats!è¦ã¦ã¾ãã天使ã¡ãããã¸å¤©ä½¿ã§ããã¨æãã¾ãã ã§ãã ãã¶åã«ä½ã£ãScalaçã®ã¡ãã£ã¨èæ¤ãã¨ãã¾ããåè¨èª Grassãæ¹é ãã¦ãããã°ã©ãã³ã°è¨èª ã天使ã¡ãããã¸å¤©ä½¿ãã¨ããã°ã©ãã³ã°è¨èª ãããã¼ã©ããä½ã£ã¦ã¿ããã Grassã¯ãid:uenoB ä½ã®åç¡ãã©ã ãè¨ç®ããã¼ã¹ãããé¢æ°åè¨èªãããã§ãã(6/22追è¨) ã¡ãã£ã¨èæ¤ãã¨ãã¾ããåè¨èª Grassã«ã¤ãã¦ã¯ãã¡ãã ä¸çã§æåã®Grassããã°ã©ã - Garage uenoB ã¡ãã£ã¨èæ¤ãã¨ãã¾ããåè¨èª Grass ããã°ã©ãã³ã°è¨èª ã天使ã¡ãããã¸å¤©ä½¿ã ã¡ãã£ã¨èæ¤ãã¨ãã¾ããåè¨èª Grassã®æ´¾çè¨èªã¨ãããã¾ãã¾ã§ãã Grassã§ä½¿ç¨ããæå(ï½ï¼ï¼·ï¼ï½)ããããã(天使, ãã¸, ! )ã«ç½®ãæããã ãã§ãã wãåºåããããã°ã©ã : 天使ã¡ãããã¸ãã¸å¤©ä½¿å¤©ä½¿ã¡ã
â¦â¦æããã¦ãã®è¨äºã«ãã®ä¸æãå¿ è¦ã ã£ãã®ããã¨ãããã¨ãä¸çªæ°ã«ãªãããã§ãããããã¯ãã¦ãããã¡ãã£ã¨ä¸æè°ãããªãã§ããï¼ ä½ãã¨ããã¨ããä¸æãã£ã¦ã¨ããã ãã¨ãã°è¦ã¤ãã£ã¦é®æãããã¨ããããããç¶æ³ã ã£ãã¨ãã¾ãããã ä¸è¨ã®ãã¥ã¼ã¹ãå³ã§è¡¨ãã¨ããããä¸çªç¶æ³ã¨ãã¦ãã£ããããã¨æãã®ã§ããããããã§ããï¼ ãããªãå é ã®ÃÃÃãæå¾å°¾ã®ÃÃÃã«å ¥ã£ã¦ãªãã®ã¯çºè¦ãã人ã«ãã¦ã¿ãã°ä¸ç®ã§ããããããªãã§ããï¼ ãããè¨äºã«ããã¨ã ã¨ãªã£ã¦ããã®ã§ãå°ãªãã¨ãçºè¦æã«ä¸è¨ã®ãããªç¶æ ã§ã¯ãªãã£ãã®ã§ãã ã§ã¯ä»åº¦ã¯éã«ããæ°ç ã¤ãªãããæç«ãã¦ããå ´åãèãã¾ãããã æ®éã«èããã°ããããããã¨ã«ãªãã¾ãã 7åããããªãã®ã§ãåã«ãªããªãã¨æ°ç ã¤ãªãã¯ä¸å¯è½ã§ãããã ããããããã¾ããä¸æãã¨ããé¨åã¨ã¯ãã¾ãåè´ãã¾ããã ãªããªãããã®ç¶æ ãªãçºè¦è ããããå ¥ã£
å æ¥ Perl + AnyEvent ã§ä½ã£ã Twitterã®ChirpUserStreamsããã©æµãããWebApp ããnode.js ã§ä½ã£ã¦ã¿ã¾ããã node.js ã¨ããã®ã¯ããJavaScript V8 Engineã§ã¤ãã³ãé§åI/Oãªãããã¯ã¼ã¯ãµã¼ããæ¸ãããã®ãã¬ã¼ã ã¯ã¼ã¯(å®è¡ç°å¢)ãã¨ãããã¨ã§ãããã§ãããããã # ã¤ã³ã¹ãã¼ã«ã¯ ./configure && make && make install ã§çµããã®ã§è©³ç´°å²æ ã¤ãã³ãé§åIOã使ã£ã¦ã以ä¸ã®ãããªå¦çã1ããã»ã¹ã§è¡ãã¾ãã CharpUserStream ããæµãã¦ãã JSON ãåå¾ã㦠node.js çµã¿è¾¼ã¿ã® httpd ã®ã¬ã¹ãã³ã¹ã«æ¸¡ã ãã©ã¦ã¶ã¯ Long poll ã㦠node.js ãã JSON ãåå¾ãã¦ç»é¢æç» å®éåãã¦ãã®ãåç»ã§è¦ãã¨ãããªæãã§ããå·¦å´ã®
ãã®ã¦ã§ããµã¤ãã¯è²©å£²ç¨ã§ãï¼ twiwt.org ã¯ãããªãããæ¢ãã®æ å ±ã®å ¨ã¦ã®ææ°ãã¤æé©ãªã½ã¼ã¹ã§ããä¸è¬ãããã¯ããããããæ¤ç´¢ã§ããå 容ã¯ãtwiwt.orgãå ¨ã¦ã¨ãªãã¾ããããªãããæ¢ãã®å 容ãè¦ã¤ãããã¨ãé¡ã£ã¦ãã¾ãï¼
ITã¨ã³ã¸ãã¢ãªã³ã°ã®ç¾ç¶ï½å¸¸ã«é²åãç¶ããITã¨ã³ã¸ãã¢ãªã³ã°ã®ææ°æ å ±ããå°éåéãã¨ã«åãã¦ç´¹ä»ãã¦ããã¾ãã Johogekkan.jpã¯ãã¡ãã§ã¯å©ç¨ã§ãã¾ãããu22procon.comã¸ã®ç§»åããé¡ããããã¾ãã ITã¨ã³ã¸ãã¢ãªã³ã°ã®ç¾ç¶ 常ã«é²åãã¦ããITã¨ã³ã¸ãã¢ãªã³ã°ã®ä¸çã§ã¯ãããã§åã人ãã¡ã常ã«é²åãã¦ãããªããã°ãªãã¾ãããããã§ä»åææ°ã®ITã¨ã³ã¸ãã¢ãªã³ã°ã®ç¾ç¶ãã以ä¸ã®2ã¤ã®ãã¼ãã«åãã¦ç´¹ä»ãã¦ããã¾ãã ITã¨ã³ã¸ãã¢ãªã³ã°ã®ææ°ã®ç¶æ³ãç¥è ãã¡ãã®ãã¼ãã§ã¯ITæ¥çã®ææ°ã®ç¶æ³ãç¥èãªã©ãç´¹ä»ãã¦ããã¾ããåãããããå°éåéãã¨ã«ãã·ã¹ãã ã¨ã³ã¸ãã¢ãªã³ã°ãããããã°ã©ãã³ã°ããããµã¼ãã¼ã¨ã³ã¸ãã¢ãªã³ã°ããããã¦ããããã¯ã¼ã¯ã¨ã³ã¸ãã¢ãªã³ã°ãã®4ã¤ã«åãã¦ç´¹ä»ãã¦ããã¾ãã ITã¨ã³ã¸ãã¢ãã¡ã®ç¾ç¶ ãã¡ãã®ãã¼ãã¯ããã£ããã¯é£½åç¶æ ã¨
ã¨ãã»ãã¥ã¢ããã°ã«ã¡ããã©XSSã¨ããè¨äºãåºã¦ãã¾ããã è¨äºã§ã¯ f-secure.com ã«ãããXSSã話é¡ã«ãã¦ãã¾ãããf-secure.jp ã§ãXSSããããã¡ããã©å æ¥ä¿®æ£ãå®äºãã¾ãããã¨ãã»ãã¥ã¢ããã°ã§ã¯ãããã°å ãæ¤ç´¢ããã¨ãã«æ¤ç´¢æååãå«ãJavaScriptæååãçæãã¦ãã¾ããããã®ã¨ãã®ã¨ã¹ã±ã¼ããä¸ååã§ãã£ããããXSSãçºçãã¦ãã¾ããã 2010å¹´1æ4æ¥ å±ãåº 2010å¹´1æ25æ¥ ä¿®æ£å®äºã¨ã®é£çµ¡ãä¿®æ£ãä¸ååã§ããä¾ç¶ã¨ãã¦XSSå¯è½ã§ãã£ããããã®æ¨ãè¿ç 2010å¹´4æ1æ¥ ä¿®æ£å®äºã¨ã®é£çµ¡ãä¿®æ£ãä¸ååã§ããä¾ç¶ã¨ãã¦XSSå¯è½ã§ãã£ããããã®æ¨ãè¿ç 2010å¹´6æ18æ¥ ä¿®æ£å®äºã¨ã®é£çµ¡ã ãã®ä»¶ã«éãã¾ããããHTMLã«æ··å¨ãã¦ããJavaScriptã®æååãåçã«çæããå ´åã«XSSãçºçããã¨ããä¾ã¯å¤ãã§ããï¼ (
html5securityã®ãµã¤ãã«ãXSSã®å種æ»æææ³ãã¾ã¨ãããã¦ããã®ãçºè¦ãã!ã¨ãããã¨ã§ãå人çã«ãã!ãã¨æã£ãæ»æããµã³ãã«ã¤ãã§ãç´¹ä»ãã¾ãã 1. CSS Expression IE7以åã«ã¯ãCSS Expressionsãã¨ããæ¡å¼µæ©è½ããããCSSå ã§JavaScriptãå®è¡ã§ããããã¾ãã <div style="color:expression(alert('XSS'));">a</div> ç¢ºèª @IT -ï¼»æè»ãããï¼½IEã®CSS解éã§èµ·ããXSS ã§è©³ãã解説ããã¦ãã¾ãããCSSã®è§£éãæè»ãªãã¨ã¨ãããã¾ã£ã¦èªåã§ç¡å®³åããã®ã¯ãªããªãå°é£ã以ä¸ã®ãããªã³ã¼ãã§ãã¹ã¯ãªãããå®è¡ããã¦ãã¾ãã¾ãã <div style="color:expr/* ã³ã¡ã³ãã®æ¿å ¥ */ession(alert('XSS'));">a</div> ç¢ºèª <div s
You no longer need HTTPS Everywhere to set HTTPS by default! Major browsers now offer native support for an HTTPS only mode. Learn how to turn it on. Read more about the sunset of HTTPS Everywhere. Since we started offering HTTPS Everywhere, the battle to encrypt the web has made leaps and bounds. Now HTTPS is truly just about everywhere, and the web has largely switched from non-secure HTTP to th
ã ããã§ãã On LispOn Lisp å¾æ³¨ãã Gabriel, Richard P. Performance and Standardization. Proceedings of the First International Workshop on Lisp Evolution and Standardization, 1988, p.60ããå¦ç系㧠triangle ã試ãã¦ãã¦, Gabriel ã¯æ¬¡ã®ãã¨ãçºè¦ããï¼ãããã°ã©ãã C ã³ã³ãã¤ã©ã«ã¬ã¸ã¹ã¿å²ãå½ã¦ã®æ示ãä¸ããã¨ãã¨æ¯ã¹ã¦ã, C çã®å復ã«ããå®è£ ããã Lisp çã®ã»ãã 17% ãé«éã ã£ã.ãå½¼ã®è«æã§ã¯ Lisp ã§å®è£ ããã»ãã C ããé«éã«ãªãããã°ã©ã ãä»ã«ãããã¤ãæãã£ã¦ãã, ãªãã«ã¯ 43% ãé«éã«ãªã£ããã®ããã. Lisp:ãããã誤解Lisp:ãããã誤解 ãLisp
ã¡ã³ããã³ã¹
ãç¥ãã
é害
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}