http://www.nttdocomo.co.jp/service/imode/make/content/browser/browser2/index.html iã¢ã¼ã対å¿HTML7.2ãã¼ã¹ã«æ¡å¼µ ãã£ãã·ã¥500KBï¼ãã ãWindowsMediaãã¡ã¤ã«ã»ããã°ã¬ãã·ããã¦ã³ãã¼ãã®FlashVideoãã¡ã¤ã«ã¯1ãã¡ã¤ã«ãããæ大10MBï¼ Cookieå¯¾å¿ JavaScriptå¯¾å¿ Refererå¯¾å¿ å¤é¨CSSã»STYLEè¦ç´ ã«å¯¾å¿ CSSã¯marginã»paddingã«å¯¾å¿ çµµæåã¯Shift-JISã®ããã¹ãå ¥åã«ã¯å¯¾å¿ãã¦ããªã HRè¦ç´ ã§ã¯å¸¸ã«0.5emã®ãã¼ã¸ã³ãåã ãã¬ã¼ã å¯¾å¿ ãã«ãã¦ã£ã³ãã¦å¯¾å¿ BMPï¼PNGè¡¨ç¤ºå¯¾å¿ FLVï¼WindowsMediaãã¡ã¤ã«ï¼asx/wax/wvx/wma/asf/wmvï¼åç対å¿
ã¨æ¸ãã¨ããå±éºãªæåãã¨ã¿ãªããã "expression" 㨠"cookie" ããµãã¿ã¤ãºããã¦ä»¥ä¸ã®ããã«ãªãã¾ãã
å½ããã°ãæºå¸¯ãµã¤ãä½ææ³ã«é¢ããè¨äºãããã¦ãããã¨ãããèªè ã®æ¹ããã ãã¢ãã²ã¼ã®ãããªæºå¸¯ãµã¤ããä½ãããã«ã¯ã©ãããããããã§ããï¼ã ã£ã¦ãã質åãæè¿è¯ãåãã¾ãã ãããããã¢ãã²ã¼ãã¨ã¦ãæåã§ããã種ã¢ãã²ã¼ãæºå¸¯ãµã¤ãçã®ããã¡ã¯ãã¹ã¿ã³ãã¼ãã®ãã㪠ä½ç½®ã¥ãã«ãªã£ã¦ãã¦ããã®ã§ããããã 確ãã«ãæºå¸¯ãµã¤ããä½ã£ã¦ãã¦ãã身ã¨ãã¦ãã ã¢ãã²ã¼ã®ãµã¤ããã¶ã¤ã³ã«ããã«ã¯ãçµæ§é£ãããã¨ãå¤ãããå¦ã¶ãã¨ãå¤ããããããæè¿ã®æºå¸¯ãµã¤ãã¯ãå®æ©ããããã¢ã¯ã»ã¹ã§ããªãããã«ãªã£ã¦ãã¦ãPCããã³ã¼ããè¦ããã¨ãã§ããªããã¨ãå¤ããå¦ã¶ãã¨ãé£ããããã§ãã ã¨ãããã¨ã§ãä»åã¯å®éã«ã¢ãã²ã¼ã¿ã¦ã³ã«æºå¸¯ã§ã¢ã¯ã»ã¹ãã¦ãæºå¸¯ã®ç»é¢ãè¦ãªããããã¶ã¤ã³ãçä¼¼ã¦æ°ããèªåãªãã«ä½ã£ã¦ã¿ã¾ããã®ã§ãããããå¾ãçµé¨ãTipsã¨ãã¦å ¬éãããã¨æãã¾ãã ã¡ãªã¿ã«ãå·¦ã®ã¹ã¯ãª
2024å¤ä¼ã¿æ è¡ãç¥æ¸ã»2æ¥ç®ãåç·¨ã zfinchyan.hatenablog.com âï¼æ¥ç®ã¯ãã¡ã 6:50 ãããã¨å¤«ã ãå ã«èµ·åº åæ¥ã«è²·ã£ã¦ããããèã®ãã³ã§æãã¯ã æ¨æ¥ã®ç²ããããããªããªãæ¯åãã¡ãèµ·ãã¦ããªãã£ãã®ã§ããã£ããå¯ããã¦ãã10:00ã«ããã«ã®ä¸ã«ãããã¬ã¤ã¾ã¼ã³ã«è¡ã£ã¦ããã¿ã¼ã´ã«ãããã¹â¦
ååã¯ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°ã®ããå¼±æ§ãçªãæ»æã®å¯¾çã¨ãã¦ã®HTMLã¨ã³ã³ã¼ãã®æå¹æ§ãè¿°ã¹ãããã ï¼HTMLã¨ã³ã³ã¼ãã ãã§ã¯ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°æ»æãå®å ¨ã«é²å¾¡ãããã¨ã¯ã§ããªããããã§ä»åã¯ï¼HTMLã¨ã³ã³ã¼ãã§å¯¾å¦ã§ããªãã¿ã¤ãã®ã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã°æ»æã®æå£ã¨ï¼ãã®å¯¾çã«ã¤ãã¦è§£èª¬ããã HTMLã¨ã³ã³ã¼ãã§å¯¾å¦ã§ããªãæ»æã«ã¯ï¼æ¬¡ã®ãããªãã®ãããã ã¿ã°æåã®å ¥åã許容ãã¦ããå ´åï¼Webã¡ã¼ã«ï¼ããã°ãªã©ï¼ CSSï¼ã«ã¹ã±ã¼ãã£ã³ã°ã»ã¹ã¿ã¤ã«ã·ã¼ãï¼ã®å ¥åã許容ãã¦ããå ´åï¼ããã°ãªã©ï¼ æåã³ã¼ããæ示ãã¦ããªãã±ã¼ã¹ã§UTF-7æåã³ã¼ãã«ããã¯ãã¹ãµã¤ãã»ã¹ã¯ãªããã£ã³ã° <SCRIPT>ã®å 容ãåçã«çæãã¦ããå ´å Aã¿ã°ãªã©ã®URLãåçã«çæãã¦ããå ´åæ³¨ï¼ ä»¥ä¸ã§ã¯ï¼HTMLã¿ã°ãCSSã®å ¥åã許容ãã¦ããå ´åã¨ï¼æåã³ã¼ããæ
IE ã«ããã "expression" ã®éå°æ¤åºã«ãã XSS ã® èªå 2006-08-31-1: [Security] http://archive.openmya.devnull.jp/2006.08/msg00369.html IE ã§ã¯ expression(å¼) ãã¹ã¿ã¤ã«ã·ã¼ãå ã§è¨è¿°ãããã¨ã§ JavaScript ãè¨è¿°ãããã¨ãã§ããã®ã¯æåã§ããï¼ IE ã«ãã expression ã®æ¤åºããããéå°ã§ XSS ãå¼ãèµ·ãããããã¨ãããã¨ãããï¼ å®æ åç §ãã³ã¡ã³ãã®æ¿å ¥ï¼Unicode æåï¼å ¨è§æåã§è¨è¿°ãã¦ã expression ã¨ãã¦æ¤åºãããï¼ è©³ç´°ã¯ï¼ä¸è¨ãµã¤ãããå¼ç¨ï¼ IE ã§ã¯ã以ä¸ã®ãããªã¹ã¿ã¤ã«ãè¨è¿°ãããã¨ã§ãJavaScript ãåä½ããã ãã¨ãå¯è½ã§ãã 1) <style>ãããã¯å ã§ã®å®ç¾© <style>input { l
ã¯ã¦ãªããã°ã®ãã«ãã§ã
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}