JavaScript ã使ã£ã CSRF 対çã®æ¹æ³ã¨ãã¦ã以å Kazuho@Cybozu Labs ã§ç´¹ä»ããã¾ããã CSRF 対ç w. JavaScript CSSXSS ã«å¯¾ãã¦èå¼±ã§ãªã CSRF 対çã¨ã¯ã©ã®ãããªãã®ããã¨ããè°è«ãç¶ãã¦ããããã§ãããJavaScript ãç¨ãã¦ããã®ã§ããã°ãç°¡åãªå¯¾çææ³ãåå¨ããã¨æãã¾ãã ããã§ããã«ä¸æ©é²ãã¦ãæ¢åã® FORM è¦ç´ ã« onsubmit å±æ§ãããã³ hiddenãã£ã¼ã«ããç´æ¥è¿½å ããã«ãJavaScript ãã¡ã¤ã«ãï¼ã¤ã¤ã³ã¯ã«ã¼ããããã¨ã«ãããæ¢åã¢ããªã±ã¼ã·ã§ã³ã®æ¸ãæããããã«å°ãªãããæ¹æ³ãç´¹ä»ãããã¨æãã¾ãã 以ä¸ã® JavaScript ãã¡ã¤ã«ãHTMLã®æå¾ã§ã¤ã³ã¯ã«ã¼ãããæ¹æ³ã§ãã fight_csrf.js sessid_name = ""; scripts = docume
{{#tags}}- {{label}}
{{/tags}}