CSRF, HTML Form Protocol Attack, Cross-protocol scripting attackã«ã¤ãã¦

ãã®è¨äºã¯èå¼±æ§"&'<<>\ Advent Calendar 2015ã®16æ¥ç®ã®è¨äºã§ãã 2015å¹´ã®ã¢ããã³ãã«ã¬ã³ãã¼ã§ããã大æ(2013å¹´)ã«ãã¹ã¿ã¼ãã¼ããå ¬å¼ãã¼ã¸ã«ãã£ãXSSã®è©±ããã¾ãã 2013å¹´3æ ãã¹ã¿ã¼ãã¼ããã®å ¬å¼ãµã¤ãã¸è¡ã£ãæãå¶ç¶ã«ãæ¤ç´¢ç»é¢ã§æªããæååãçºè¦ãã¦ãã¾ãã¾ãããæè¿ã§ã¯ãã¾ãè¦ãããªããªã£ã ie=utf-8&oe=utf-8 ã®ãããªãã©ã¡ã¼ã¿ã§ãã XSSçéã®äººãªãæãããããªæãã®ãã©ã¡ã¼ã¿ãè¦ããã¡ãã£ã¨å¤ãã¦ã¿ã¦ã©ã®ãããªæåãèµ·ããã試ããããªãã¯ãã§ãã å®éã«oe=utf-8ãå¤ãããããã«å¯¾å¿ããå¤ãmetaã®charsetã«å ¥ãããã§ãããå½æã®ãã¨ã詳ããè¦ãã¦ãã¾ããããããããç´æ¥XSSãããããããªãã®ã§å¤åå¤ã¯ã¨ã¹ã±ã¼ãããã¦ããã¨æãã¾ãã ã¨ã³ã³ã¼ãã£ã³ã°å¨ãã§ã¯å½æUTF-7ãçµãããè¿ããæ
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}